Spyware File Details O4 - HKCU\..\Run: [LDM] C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BackWeb-8876480.exe Last Detected: 5/1/2006 4:52:00 AM Found on 5 PCs. Users with this object complained of the following: "Computer tends to crash and come up with a blue screen saying "Microsoft had to shut down due to protection of files" I downloaded the latest video drivers from ati.com, but still nothing changed, I hoped this program could fix it." "spyware detected" "there are a lot of popups when i'm surfing the net with IE.....like "adultfriendfinders.com"...and some gambling sites....." PCs containing this item also contained the following spyware: R1 - HKCU\Software\Microsoft\Internet Explorer,SearchURL = about:blank (More Details) R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = about:blank (More Details) R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = about:blank (More Details) R1 - HKCU\Software\Microsoft\Internet Explorer\Search,SearchAssistant = about:blank (More Details) O2 - BHO: (no name) - {5C8B2A36-3DB1-42A4-A3CB-D426709BBFEB} - (no file) (More Details) O4 - HKLM\..\Run: [Windows Update Monitoring Service] winupdt.exe (More Details) O4 - HKLM\..\Run: [Windows Time] winmgr.exe (More Details) O4 - HKLM\..\Run: [vmtuner] gclib.exe (More Details) O4 - HKLM\..\Run: [Task Help] wualcts.exe (More Details) O4 - HKLM\..\Run: [MsnExplorer] C:\WINDOWS\msexploren.exe /i (More Details) O4 - HKLM\..\Run: [BearShare] C:\Program Files\BearShare\BearShare.exe /pause (More Details) O4 - HKCU\..\Run: [LDM] C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BackWeb-8876480.exe (More Details) O2 - BHO: SponsorAdulto Class - {511F9316-771B-4953-A268-1C36DA667FE9} - C:\WINDOWS\DOWNLOADED PROGRAM FILES\SPONSORADULTO.DLL (More Details) O2 - BHO: MyBHO - {784aa380-13f2-422e-8540-f2280f1dd4f1} - C:\WINDOWS\SYSTEM\BHOIMPL.DLL (More Details) O4 - HKLM\..\Run: [FHPage] C:\WINDOWS\system32\shdochp.exe home (More Details) O4 - HKLM\..\RunServices: [MOSearch] C:\PROGRA~1\FICHIE~1\SYSTEM\MOSEARCH\BIN\MOSEARCH.EXE (More Details) O9 - Extra 'Tools' menuitem: Show &Related Links - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINDOWS\web\related.htm (More Details) O16 - DPF: {511F9316-771B-4953-A268-1C36DA667FE9} (SponsorAdulto Class) - http://ip.sponsoradulto.com/cab/3/fr/SysWebTelecomInt.cab (More Details) O16 - DPF: {64311111-1111-1121-1111-111191113457} - file://c:\eied_s7.cab (More Details) O2 - BHO: mwsBar BHO - {07B18EA1-A523-4961-B6BB-170DE4475CCA} - C:\Program Files\MyWebSearch\bar\1.bin\MWSBAR.DLL (More Details) O2 - BHO: (no name) - {26115CAF-42F0-5F31-6952-24C986F0F98F} - (no file) (More Details) O8 - Extra context menu item: &Search - http://bar.mywebsearch.com/menusearch.html?p=ZSzeb029YYHK_ZBzeb032YYHK (More Details) O16 - DPF: {1D4DB7D2-6EC9-47A3-BD87-1E41684E07BB} - http://ak.imgfarm.com/images/nocache/funwebproducts/ei-2/SmileyCentralFWBInitialSetup1.0.0.8-2.cab (More Details) O16 - DPF: {205FF73B-CA67-11D5-99DD-444553540006} (CInstall Class) - http://www.errorguard.com/installation/Install.cab (More Details) O20 - Winlogon Notify: igfxcui - C:\WINDOWS\SYSTEM32\igfxsrvc.dll (More Details) O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll (More Details) O23 - Service: ScsiAccess - Unknown owner - C:\WINDOWS\system32\ScsiAccess.EXE (More Details) Back to Spyware List |
||||||
| About HijackRemote | Recently Slayed Spyware | Message Board | Contact Us | ||||||
| HijackRemote ©2005 (Terms of Service) Privacy Policy | ||||||