HijackRemote Anti-Spyware P2P Service

 

     
 
 Clean This with HijackRemote


Spyware File Details

O4 - HKCU\..\Run: [MyWebSearch Email Plugin] C:\PROGRA~1\MYWEBS~1\BAR\2.BIN\MWSOEMON.EXE

Last Detected: 4/23/2007 5:55:00 AM
Found on 8 PCs.

Users with this object complained of the following:

"Screens freezing"
"pop-ups,slow,says that has detected 200+ viruses and that malicious spyware has been detected"
"slow pc"
"popuus, like cassino something and other pop up I try everuthing to get ride of those"


PCs containing this item also contained the following spyware:

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = about:blank
(More Details)

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://yahoo.sbc.com/dsl
(More Details)

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://red.clientapps.yahoo.com/customize/ie/defaults/sb/sbcydsl/*http://www.yahoo.com/search/ie.html
(More Details)

R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://yahoo.sbc.com/dsl
(More Details)

R1 - HKCU\Software\Microsoft\Internet Explorer\Search,SearchAssistant = about:blank
(More Details)

R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://as.starware.com/dp/search?x=wKX1ILEOi+UdWpSlz2q9Dzn13Emww/YwbwL0QoyVdgfhAn/IJM8OXAZ8q/5QEshGRrPiPDTTpGeWedxVgc0vypFym0k5H+NTQhYgFHgom4IxokTcgqAts4de0TLyuCqQNPNsdSwUvm8=
(More Details)

R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = 127.0.0.1;
(More Details)

R3 - URLSearchHook: {FD0B1A83-4F7C-11D5-BD9C-000103C116D5} - - (no file)
(More Details)

O2 - BHO: IEHlprObj Class - {EB344780-3393-11D7-90D1-0001032044C0} - C:\WINDOWS\SYSTEM\M030106SHOP.DLL (file missing)
(More Details)

O2 - BHO: (no name) - {CA356D79-679B-4b4c-8E49-5AF97014F4C1} - (no file)
(More Details)

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iehome&locale=EN_US&c=Q304&bd=presario&pf=desktop
(More Details)

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iesearch&locale=EN_US&c=Q304&bd=presario&pf=desktop
(More Details)

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://us.rd.yahoo.com/customize/ycomp/defaults/sb/*http://www.yahoo.com/search/ie.html
(More Details)

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://us.rd.yahoo.com/customize/ycomp/defaults/sp/*http://www.yahoo.com
(More Details)

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iesearch&locale=EN_US&c=Q304&bd=presario&pf=desktop
(More Details)

R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iehome&locale=EN_US&c=Q304&bd=presario&pf=desktop
(More Details)

R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = http://as.starware.com/dp/search?x=wKX1ILEOi+Vh7AfA98Gm4Me69ZMbubcDBVt3B+BXausuvGJLE8j25NqLlfutzT6pM2We28iJn1enoZNmR1jice5zTRsR26rpShMAd03KjsBD2TQttreWRETS3hqFttbl6Lnr24tR18pck8Hxd7K3GL1Byx84ZEW2y/ehYAJD1hvVfG1q4zFmZgYedZFMARQ1xIcmwYFWI/A9HjhS2UwewvUskoF/PTwAWCgJyiIHaDRFX5T3fQRKrLCRCaCGfdyeMuX5khUVAIUF1F4AKTJs2rW073bFb9Tmg611PAVyTl1KhOa2+Vu6QqVuiWKf0kaqL7TQTpX7MaELUwm4K/SS3H1ALd4LpZ5bVCaYOpBT5zw=
(More Details)

R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://us.rd.yahoo.com/customize/ycomp/defaults/su/*http://www.yahoo.com
(More Details)

O2 - BHO: HomepageBHO - {e0103cd4-d1ce-411a-b75b-4fec072867f4} - C:\WINDOWS\System32\hpF43.tmp
(More Details)

O4 - HKLM\..\Run: [Reminder] "C:\Windows\Creator\Remind_XP.exe"
(More Details)

O4 - HKLM\..\Run: [MyWebSearch Email Plugin] C:\PROGRA~1\MYWEBS~1\bar\2.bin\mwsoemon.exe
(More Details)

O4 - HKLM\..\Run: [HDZKiAT] C:\WINDOWS\plktk.exe
(More Details)

O4 - HKLM\..\Run: [WT GameChannel] C:\Program Files\WildTangent\Apps\GameChannel.exe
(More Details)

O4 - HKLM\..\Run: [NI.UERS_0001_NI57M1124] "C:\Documents and Settings\Owner\Local Settings\Temporary Internet Files\Content.IE5\X7N3TXOE\ErrorSafeScannerInstall[1].exe" -nag
(More Details)

O4 - HKCU\..\Run: [MyWebSearch Email Plugin] C:\PROGRA~1\MYWEBS~1\BAR\2.BIN\MWSOEMON.EXE
(More Details)

O4 - Global Startup: GStartup.lnk = C:\Program Files\Common Files\GMT\GMT.exe
(More Details)

O8 - Extra context menu item: &Search - http://bar.mywebsearch.com/menusearch.html?p=ZS
(More Details)

R3 - URLSearchHook: (no name) - _{00A6FAF6-072E-44cf-8957-5838F569A31D} - (no file)
(More Details)

R3 - URLSearchHook: (no name) - {00A6FAF6-072E-44cf-8957-5838F569A31D} - C:\Program Files\MyWebSearch\SrchAstt\2.bin\MWSSRCAS.DLL
(More Details)

O2 - BHO: MyWebSearch Search Assistant BHO - {00A6FAF1-072E-44cf-8957-5838F569A31D} - C:\Program Files\MyWebSearch\SrchAstt\2.bin\MWSSRCAS.DLL
(More Details)

O2 - BHO: mwsBar BHO - {07B18EA1-A523-4961-B6BB-170DE4475CCA} - C:\Program Files\MyWebSearch\bar\2.bin\MWSBAR.DLL
(More Details)

O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
(More Details)

O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre1.5.0_06\bin\jusched.exe
(More Details)

O4 - Startup: MyWebSearch Email Plugin.lnk = C:\Program Files\MyWebSearch\bar\2.bin\MWSOEMON.EXE
(More Details)

O4 - Global Startup: MyWebSearch Email Plugin.lnk = C:\Program Files\MyWebSearch\bar\2.bin\MWSOEMON.EXE
(More Details)

R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = C:\WINDOWS\System\blank.htm
(More Details)

O16 - DPF: {11111111-1111-1111-1111-111191113457} - file://c:\ied_s7.cab
(More Details)

O16 - DPF: {11111111-1111-1111-1111-511111193457} - file://c:\x.cab
(More Details)

O16 - DPF: {11111111-1111-1111-1111-511111193458} - file://c:\x.cab
(More Details)

O21 - SSODL: SystemCheck2 - {54645654-2225-4455-44A1-9F4543D34546} - C:\WINDOWS\system32\vbsys2.dll
(More Details)


Back to Spyware List

 
     
 About HijackRemote | Recently Slayed Spyware | Message Board | Contact Us
 HijackRemote ©2005 (Terms of Service) Privacy Policy