Home Browser Helper Object Findxplorer

Findxplorer

Posted: August 8, 2011

Findxplorer is a malicious Browser Helper Object that changes default search engine when searching directly from address/URL bar in your web browser. Findxplorer returns very limited and promoted search results. Whenever an affected Internet user searches something directly from his/her web browser address bar, Findxplorer redirects him/her to findxplorer.com rogue website and gives paid search results, which are not the most important. Findxplorer also changes your online search habits. For instance, when you use Google Chrome web browser, and you search directly from the very convenient address bar, suddenly it gives you absolutely different and very often unrelated search results. It is recommended to eliminate Findxplorer as quickly as possible once you detect it.

Technical Details

File System Modifications

The following files were created in the system:



C:\Program Files\FindXplorer\findxplorer.exe File name: C:\Program Files\FindXplorer\findxplorer.exe
File type: Executable File
Mime Type: unknown/exe
C:\Program Files\FindXplorer\findxplorer.dll File name: C:\Program Files\FindXplorer\findxplorer.dll
File type: Dynamic link library
Mime Type: unknown/dll
C:\Documents and Settings\<username>\Application Data\FindXplorer\findxplorer115.exe File name: C:\Documents and Settings\<username>\Application Data\FindXplorer\findxplorer115.exe
File type: Executable File
Mime Type: unknown/exe
C:\Program Files\FindXplorer\uninstall.exe File name: C:\Program Files\FindXplorer\uninstall.exe
File type: Executable File
Mime Type: unknown/exe

Registry Modifications

The following newly produced Registry Values are:

HKEY..\..\..\..{Subkeys}HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\FindXplorerHKEY_LOCAL_MACHINE\SOFTWARE\FindXplorerHKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\FindXplorer ServiceHKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\FindXplorer ServiceHKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\Root\LEGACY_FINDXPLORER_SERVICE
Loading...