PowerStrip


· Overview ·
· Origins ·
· Distribution ·
· Operation ·
· Risks ·
· Detection and Removal ·
· Research ·



Overview

Vendor Notes:

from the web site: 'The PowerStrip becomes a part of your Internet Explorer browser so you can instantly search, check your email and get up-to-the-minute news headlines no matter where you are on the Web. It's a snap to install and even easier to use and it's free. Here are some of its exciting features:
Type-in Search - One click search on Google, the most popular search engine online.
Highlight Search - Highlight any text on the page and click "Search".
Fast Forms - Fill in forms with one click.
Email - Check any web-based email account with one click.
News - Access to the top headlines from all over the world. Click on the headline to read the entire story.'

Alias:

Adware/PortalScan [Panda], power strip psocx, TrojanDownloader.Win32.Minstaller [Kaspersky]

Category:

Toolbar: A group of buttons which perform common tasks. A toolbar for Internet Explorer is nomally located below the menu bar at the top of the form. Toolbars may be created by Browser Helper Objects.

Adware: Software that displays popup/popunder ads when the primary user interface is not visible or which do not appear to be assocaited with the product.

Variants:

  • PowerStrip/PSOCX
  • PowerStrip/PSSetup
  • Similar Pests:

    Toolbar · Adware

    Origins

    Group:

    thepowerstrip.com

    EMail:

    help@thepowerstrip.com

    URL:

    http://www.thepowerstrip.com/

    Date of Origin:

    Variants from February, 2004 to August, 2004

    Distribution

    Prevalence:

  • PowerStrip: 10.3%
  • More Info

    Clot Factor:

  • PowerStrip: 5
  • The "Clot Factor" is a measure of how much a pest "gums up" a machine by adding registry entries, files, and directories. As more objects are placed in a machine, manual removal becomes more difficult and more error-prone.

    Growth:

  • PowerStrip: Insufficient data to report growth
  • Operation

    Platform:

    Windows 95, 98, ME, NT, 2000, or XP

    Storage Required:

  • PowerStrip: at least 2585 KB
  • ScreenShot:


    PowerStrip Toolbar


    Risks

    Privacy Policy:

    None.

    Security Issues:

    Yes. Can download and install arbitrary unsigned code, as an update mechanism. Connects to its controlling server at verschk.com to ask for software and target list updates.

    Detection and Removal

    Automatic Removal:

    PestPatrol detects this.

    PestPatrol removes this.



    Manual Removal:

    1. Click on the "Start" button on your computer.
    2. Click "Settings"
    3. Click "Control Panel"
    4. Click "Add/Remove Programs"
    5. Find the "PowerStrip" and click "Remove"

    Stop Running Processes:

    Kill these running processes with Task Manager:

    Remove AutoRun Reference:

    Go To the key HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run.
    If you find the value HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run\lsvr, delete it and reboot the machine immediately.
    If you find the value HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run\ltdmgr, delete it and reboot the machine immediately.
    If you find the value HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run\pmr, delete it and reboot the machine immediately.



    Unregister DLLs:

    Unregister these DLLs with Regsvr32, then reboot:

    Clean Registry:

    Remove these registry items (if present) with RegEdit:

    Remove Files:

    Remove these files (if present) with Windows Explorer:

    Remove Directories:

    Remove these directories (if present) with Windows Explorer:

    Research

    File Analyses:

    More Info:

  • PowerStrip is an IE toolbar with a search field and link buttons. When you use a targeted merchant site, PowerStrip silently sets the afffiliate ID, so as to steal commission fees from your web shopping.
  • AllTheWeb, AltaVista, AOL Search, Ask Jeeves, Google, HotBot, Lycos, LookSmart, MSN, Yahoo!
  • Research By:

  • PestPatrol's Pest Research Center
  • Last Revised:

    April 04, 2005