Here's some infor on your
BHO drive-by bundling perp.
Registrant:
eUniverse
(DOM-309135)
6060 Center Drive
Third Floor
Los Angeles
CA
90045
US
Domain Name: incredifind.com
Registrar Name: Alldomains.com
Registrar Whois: whois.alldomains.com
Registrar Homepage:
http://www.alldomains.com
Administrative Contact:
eUniverse Inc.
(NIC-1465646)
eUniverse
6060 Center Drive
Third Floor
Los Angeles
CA
90045
US
Domains@euniverse.com
+1.3102151001
Fax- +1.3102582758
Technical Contact, Zone Contact:
Center Network Operations
(NIC-398252)
Alldomains.com
1800 Sutter St.
Suite 100
Concord
CA
94520
US
hostmaster@alldomains.com
+1.9256859600
Fax- +1.9256859620
Created on..............: 2003-Jun-09.
Expires on..............: 2004-Jun-09.
Record last updated on..: 2003-Jun-09 16:48:52.
Domain servers in listed order:
NS1.EUNIVERSE.COM 12.129.205.221
NS2.EUNIVERSE.COM 66.201.123.29
NS3.EUNIVERSE.COM 12.129.205.222
NS4.EUNIVERSE.COM 66.201.123.30
_______________________________________________
http://www.incredifind.com your typical sleezeball affiliate running a plain text link directory site who is tired of just buying up expired domains with traffic or
SERP listings. Now they want in on hijacking the IE browser with some 3rd world developed
BHO and drive-by install script. This infestation might come from some popup hellhole freebee or porn site, P2P network download getting you with the PGate Basic strain. Guy probably has other names for this crap piece of Adware.
IncrediFind
Overview
IncrediFind is an Internet Explorer browser helper object that hijacks your error page.
From the developer: IncrediFind is a free utility for Microsoft Internet Explorer version 5 or later that provides contextually-relevant search results in place of unfound and unavailable web pages, and allows users to search the web by simply typing any keywords or search terms in their Internet Explorer address bar.
Classification
Adware
Files
incfindbho.dll
Vendor
Incredifind.com
Privacy policy
No privacy policy available
Detection
Bazooka Adware and Spyware Scanner detects IncrediFind. Bazooka is freeware and detects spyware, adware, foistware, trojan horses, viruses, worms, etc. Read more »
Uninstall procedure
Uninstall IncrediFind from "Add/Remove Programs" in the Windows® Control Panel.
Manual removal
Please follow the instructions below if you would like to remove IncrediFind manually. Please notice that you must follow the instructions very carefully and delete everything that is mentioned. In most cases the removal will fail if one single item is not deleted. If IncrediFind remains on your system after stepping through the removal instructions, please double-check by stepping through them again.
Start the registry editor. This is done by clicking Start then Run. (The Run dialog will appear.) Type regedit and click OK. (The registry editor will open.)
Delete 'HKEY_LOCAL_MACHINE \ SOFTWARE \ Classes \ CLSID \ {5D60FF48-95BE-4956-B4C6-6BB168A70310}', if it exists.
Delete 'HKEY_LOCAL_MACHINE \ SOFTWARE \ Microsoft \ Windows \ CurrentVersion \ Explorer \ Browser Helper Objects \ {5D60FF48-95BE-4956-B4C6-6BB168A70310}', if it exists.
Exit the registry editor.
Restart your computer.
Start Windows Explorer and delete:
%ProgramsDir%\IncrediFind\
BHO\incfindbho.dll
Note: %ProgramsDir% is a variable (?). By default, this is C:\Program Files.
Start Microsoft Internet Explorer.
In Internet Explorer, click Tools -> Internet Options.
Click the Programs tab -> Reset Web Settings.
_______________________________
http://www.google.com/search?hl=en&i...=Google+Search
Being this link is from this Adware installers site ...run at your own risk
http://www.pgate-basic.com/uninstall.shtml
________________________________
Our
BHO download buddies at TuCows seem to have some partnership with the perp whereby they hide domain Whois, provide some hosting to give both a download of the crap ...plus a download of various cures for the crap.