Spyware File Details O4 - HKLM\..\Run: [ehTray] C:\WINDOWS\ehome\ehtray.exe Last Detected: 5/3/2009 3:54:00 PM Found on 3 PCs. Users with this object complained of the following: "Slow" "there is a flashing icon on toolbar and frequent pop up message that i have a critical virus and an advert promising to clean my computer from the problem if only i purchase their product. the message is up only for 15 seconds and retreats only to pop up again minutes later" "no access to windows updates or any of the microsoft sites, no access to most of the anti spyware/virus download sites and restriction when trying to download one (page not found), cannot view hidden files (i had to fix it with a script which am not so sure was a safe one), cannot update existing anti-spyware progs on comp (hitman pro cannot update or start up any of its components), sometimes the cursor slowmotions, sum anti-spyware progs freeze when i attempt to start up e.g. adaware etc which are all components of hitmanpro, but i can access all other sites without a problem but am really sure there is somethig wrong. !!!my D:\ station icon disappeared!!!! PS: I remember b4 i had internet a while ago cuz i just got it today, i tried to check if there were any wireless unsecured networks around me with my wireless usb stick and i accessed some which looked very unsecured but couldnt get online but i think they might have infected my comp if that s possible... " PCs containing this item also contained the following spyware: R3 - URLSearchHook: ScriptInocUI Class - - (no file) (More Details) O2 - BHO: Starware - {CA356D79-679B-4b4c-8E49-5AF97014F4C1} - C:\Program Files\Starware\bin\Starware.dll (More Details) O3 - Toolbar: Starware - {D49E9D35-254C-4c6a-9D17-95018D228FF5} - C:\Program Files\Starware\bin\Starware.dll (More Details) O4 - HKLM\..\Run: [ehTray] C:\WINDOWS\ehome\ehtray.exe (More Details) O2 - BHO: DriveLetterAccess - {5CA3D70E-1895-11CF-8E15-001234567890} - C:\WINDOWS\system32\dla\tfswshx.dll (More Details) O4 - HKLM\..\Run: [nwiz] "nwiz.exe" /installquiet /keeploaded /nodetect (More Details) O4 - HKLM\..\Run: [dla] C:\WINDOWS\system32\dla\tfswctrl.exe (More Details) O4 - HKLM\..\Run: [00THotkey] C:\WINDOWS\System32\00THotkey.exe (More Details) O4 - HKLM\..\Run: [000StTHK] 000StTHK.exe (More Details) O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\ (More Details) O20 - Winlogon Notify: WRNotifier - C:\WINDOWS\SYSTEM32\WRLogonNTF.dll (More Details) O21 - SSODL: hemadynamometer - {6076d2b1-634c-4685-843b-f826045ea5dc} - C:\WINDOWS\system32\syycum.dll (More Details) R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://hsremove.com/done.htm (More Details) R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local (More Details) R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Koppelingen (More Details) O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll (More Details) O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file) (More Details) O3 - Toolbar: Veoh Browser Plug-in - {D0943516-5076-4020-A3B5-AEFAF26AB263} - D:\Veoh Networks\Veoh\Plugins\reg\VeohToolbar.dll (More Details) O4 - HKLM\..\Run: [Snelkoppeling naar eigenschappenvenster voor High Definition Audio] HDAudPropShortcut.exe (More Details) O4 - HKLM\..\Run: [RemoteControl] "C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe" (More Details) O4 - HKLM\..\Run: [IMJPMIG8.1] "C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE" /Spoil /RemAdvDef /Migration32 (More Details) Back to Spyware List |
||||||
| About HijackRemote | Recently Slayed Spyware | Message Board | Contact Us | ||||||
| HijackRemote ©2005 (Terms of Service) Privacy Policy | ||||||