Behavior
Adware.SideBySide directs web searches to sidebysidesearch.com, and displays pop-up ads.
Symptoms
Your Symantec program detects Adware.SideBySide.
Transmission
The SideBySideSearch installer must be executed.
technical details
File names: sbss.exe
When Adware.SideBySide is executed, it performs the following actions:
1. Creates the following files:
* %ProgramFiles%\sbss\sbss.exe
* %ProgramFiles%\sbss\Stop sbss.lnk
* %ProgramFiles%\sbss\Uninstall sbss.exe
Note: %ProgramFiles% is a variable that refers to the program files folder. By default, this is C:\Program Files.
2. Creates the following registry subkeys:
HKEY_LOCAL_MACHINE\SOFTWARE\sbss
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\sbss
3. Adds the value:
"sbss Launcher" = "%ProgramFiles%\sbss\sbss.exe"
to the registry subkey:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
4. Adds the values:
"DisplayName" = "sbss"
"NoModify" = "0x00000001"
"UninstallString" = "C:\Program Files\sbss\Uninstall sbss.exe"
to the registry subkey:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\sbss
5. Adds the values:
"InstalledTo" = "C:\Program Files\sbss"
"LogURL" = "
www.sidebysidesearch.com\nextvantage"
"mQuery" = "0x00000000"
"mGUID" = "{47A2A948-AB0A-4C20-A89F-6E847EDA7314}"
"mADCODE" = "2089!ascentive"
"startupflags" = "0x00000001"
"InstalledVN" = "0x00002710"
to the registry subkey:
HKEY_LOCAL_MACHINE\SOFTWARE\sbss
6. Monitors the user's online activity, sends keyword searches to sidebysidesearch.com, then displays a pop-up window displaying the search results retrieved from sidebysidesearch.com.
7. Displays pop-up ads.
REMOVAL INSTRUCTIONSSee:
http://securityresponse.symantec.com/avcenter/venc/data/adware.sidebyside.htmlTo delete the values from the registry 1. Click Start > Run.
2. Type regedit
Then click OK.
3. Navigate to the subkey:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
4. In the right pane, delete the value:
"sbss Launcher" = "%ProgramFiles%\sbss\sbss.exe"
5. Delete the following subkeys:
HKEY_LOCAL_MACHINE\SOFTWARE\sbss
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\sbss
6. Exit the Registry Editor.