Threat Database Browser Hijackers IdentifyPlaces.com

IdentifyPlaces.com

By Sumo3000 in Browser Hijackers

IdentifyPlaces.com is one of the many low-quality search engines that use browser hijackers in order to attract easy advertising and online traffic revenue. ESG security researchers have not identified malware in the IdentifyPlaces.com website itself. However, most computer users visiting IdentifyPlaces.com will do so because of the effects of a malware infection already existing on their computer system. While IdentifyPlaces.com will not attack your computer system directly, many of the search results and advertisements on IdentifyPlaces.com also lead to potential malware infections. Based on this, ESG security analysts highly recommend scanning a computer system with a reliable anti-virus program if it is experiencing redirects to the IdentifyPlaces.com website or if IdentifyPlaces.com has had contact with search results on this search engine.

Symptoms of an IdentifyPlaces.com-related Malware Infection

Browser hijackers will take over the infected computer system's web browser, usually by making changes to the HOSTS file, which is crucial in determining how a computer system connects to the Internet. Some common symptoms of a browser hijacker infection related to IdentifyPlaces.com include the following:

  • Computer users infected with IdentifyPlaces.com-related malware may find that their web browser's homepage has been changed to IdentifyPlaces.com. It may also be difficult, if not impossible to revert this change.
  • When navigating the Internet, an infected computer's web browser will direct the computer user to the IdentifyPlaces.com website repeatedly. This is especially common after the computer user tries to do an online search on a real search engine.
  • An infected computer system's web browser will often display pop-up windows directly linking to IdentifyPlaces.com, to advertisements that are associated with IdentifyPlaces.com or to websites similar to IdentifyPlaces.com. In some cases, these pop-up windows may even appear even if the web browser is not currently in use.

Removing IdentifyPlaces.com-related Malware from Your Computer System

It is common for browser hijackers associated with IdentifyPlaces.com to include a rootkit component. Because of this, ESG security analysts recommend using a strong anti-malware program with anti-rootkit capabilities. It is also necessary to revert the dangerous changes to the Windows registry and system settings that IdentifyPlaces.com-related malware makes, which many anti-malware applications will do automatically after removing a browser hijacker threat from the infected computer system. If your anti-malware software fails to work properly, ESG security analysts recommend restarting Windows from an external memory device or in Safe Mode.

File System Details

IdentifyPlaces.com may create the following file(s):
# File Name Detections
1. %AppData%[trojan name]toolbarlog.txt
2. %AppData%[trojan name]toolbarstats.dat
3. %Temp%[trojan name]toolbar-manifest.xml
4. %AppData%[trojan name]toolbarcouponsmerchants.xml
5. %AppData%[trojan name]toolbardtx.ini
6. %AppData%[trojan name]toolbarguid.dat
7. %AppData%[trojan name]toolbaruninstallStatIE.dat
8. %AppData%[trojan name]toolbarcouponscategories.xml
9. %AppData%[trojan name]toolbarstat.log
10. %AppData%[trojan name]toolbarpreferences.dat
11. %AppData%[trojan name]toolbaruninstallIE.dat
12. %AppData%[trojan name]toolbarversion.xml
13. %AppData%[trojan name]toolbarcouponsmerchants2.xml

Registry Details

IdentifyPlaces.com may create the following registry entry or registry entries:
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{99079a25-328f-4bd4-be04-00955acaa0a7}InprocServer32 "C:PROGRA~1WINDOW~4ToolBar[trojan name]dtx.dll"
HKEY_LOCAL_MACHINE\SOFTWARE\Classes[trojan name]IEHelper.DNSGuard
HKEY_LOCAL_MACHINE\SOFTWARE\Classes[trojan name]IEHelper.DNSGuardCLSID
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{A40DC6C5-79D0-4ca8-A185-8FF989AF1115} "UrlHelper Class"
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{A40DC6C5-79D0-4ca8-A185-8FF989AF1115}VersionIndependentProgID "[trojan name]IEHelper.UrlHelper"
HKEY_LOCAL_MACHINE\SOFTWARE\Classes[trojan name]IEHelper.DNSGuardCurVer
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar "[trojan name] Toolbar"
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{A40DC6C5-79D0-4ca8-A185-8FF989AF1115}ProgID "[trojan name]IEHelper.UrlHelper.1"
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{99079a25-328f-4bd4-be04-00955acaa0a7} "[trojan name] Toolbar"
HKEY_LOCAL_MACHINE\SOFTWARE\Classes[trojan name]IEHelper.DNSGuard.1
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects{99079a25-328f-4bd4-be04-00955acaa0a7} "[trojan name] Toolbar"

Trending

Most Viewed

Loading...