Remove SearchNet. Description and removal instructions

 
Title: SearchNet

Type: Browser Hijackers
Severity scale:SearchNet severity is 36  (36 / 100)
 
SearchNet is a browser hijacker that changes the Internet Explorer default search page and modifies related settings. It also attempts to corrupt and remove all installed web browser plug-ins. The parasite uses special tools to protect own files and registry keys, and therefore make its removal more difficult.


Related files: searchnet.exe, servehost.exe, serveup.exe, snhpr.dll, srvnet32.dll, [X].dll, anfad.sys, fad.sys, [X].sys

SearchNet properties:
• Changes browser settings
• Hides from the user
• Stays resident in background

Automatic SearchNet removal:

remover for SearchNet

SearchNet manual removal:

Kill processes:
searchnet.exe, servehost.exe, serveup.exe
Delete registry values:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\cdnctr
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\SearchNet_Up
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\[X]
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Anfad
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_ANFAD
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\[X]
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_[X]
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\FAD
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_FAD
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Remote Log
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\IEHpr.InterCept
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\IEHpr.InterCept.1
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{2A0176FE-008B-4706-90F5-BBA532A49731}
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{3CE496D1-1746-41CD-9489-3C0B93DF10E2}
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{52BEA5F9-7E3F-490A-B7E8-9BD5DDDEE5DF}
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{D1AFED83-9133-4660-8C8F-DAF1B4A3D5A8}
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\TypeLib\{158919D3-4CAB-4109-9755-9AE794D5B2DE}
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\TypeLib\{E8D3778F-47D3-4F1F-9245-3D46856936E4}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{2A0176FE-008B-4706-90F5-BBA532A49731}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{3CE496D1-1746-41CD-9489-3C0B93DF10E2}
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{2A0176FE-008B-4706-90F5-BBA532A49731}
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{3CE496D1-1746-41CD-9489-3C0B93DF10E2}
HKEY_LOCAL_MACHINE\SOFTWARE\SearchNet
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\ZSXZ
Delete files:
searchnet.exe, servehost.exe, serveup.exe, snhpr.dll, srvnet32.dll, [X].dll, anfad.sys, fad.sys, [X].sys
Delete directories:
C:\Program Files\SearchNet
Misc:
[X] is a random name.

Exact file location:
servehost.exe - C:\Windows\System, C:\Windows\System32 or C:\Winnt\System32
searchet.exe, serveup.exe, snhpr.dll, srvnet32.dll - C:\Program Files\SearchNet
[X].dll - C:\Windows\Downloaded Program Files or C:\Winnt\Downloaded Program Files
anfad.sys, fad.sys, [X].sys - C:\Windows\System\Drivers, C:\Windows\System32\Drivers or C:\Winnt\System32\Drivers

Other programs to remove SearchNet:

• SUPERAntiSpyware - Review - Download
• CounterSpy - Review - Download
• Windows Defender - Review - Download

Information added: 20/07/06
Information updated: 20/07/06

Additional resources related to SearchNet:

Attention: If you know or you have a website or page about SearchNet removal, feel free to add a link to this list: add url




more resources

Post Comment:

Attention: Use this form only if you have additional information about SearchNet parasite, its removal instructions, additional resources or behavior. By clicking "post comment" button you agree not to post any copyrighted, unlawful, harmful, threatening, abusive, harassing, defamatory, vulgar, obscene, profane, hateful, racially, ethnically or otherwise objectionable material of any kind.



Enter security code:

Related news:
Similar parasites:
Related discussions: