Spyware File Details O4 - HKLM\..\Run: [IMJPMIG8.1] "C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE" /Spoil /RemAdvDef /Migration32 Last Detected: 5/3/2009 3:54:00 PM Found on 3 PCs. Users with this object complained of the following: "there are always a lot of popups when i'm surfing the internet...and the number of those popups seems to be more and more.....most of those popups are adveritsments like: http://www.cli-tone.com.hk.... they keep poping up.... if there's popup, i'll close it immediately,,, but it will pop up again after a short while.... beside the popups, sometimes, there are some new icons on the desktop..... but i didn't install them.....when i saw these icons, i'll delete them, but weeks later, they may appear in my desktop again.... i can't remember the names of those icons... they were like "my cellular"..."my casino"... and something like that" "trojan" "no access to windows updates or any of the microsoft sites, no access to most of the anti spyware/virus download sites and restriction when trying to download one (page not found), cannot view hidden files (i had to fix it with a script which am not so sure was a safe one), cannot update existing anti-spyware progs on comp (hitman pro cannot update or start up any of its components), sometimes the cursor slowmotions, sum anti-spyware progs freeze when i attempt to start up e.g. adaware etc which are all components of hitmanpro, but i can access all other sites without a problem but am really sure there is somethig wrong. !!!my D:\ station icon disappeared!!!! PS: I remember b4 i had internet a while ago cuz i just got it today, i tried to check if there were any wireless unsecured networks around me with my wireless usb stick and i accessed some which looked very unsecured but couldnt get online but i think they might have infected my comp if that s possible... " PCs containing this item also contained the following spyware: R3 - URLSearchHook: (no name) - {00A6FAF6-072E-44cf-8957-5838F569A31D} - C:\Program Files\MyWebSearch\SrchAstt\1.bin\MWSSRCAS.DLL (More Details) O2 - BHO: MyWebSearch Search Assistant BHO - {00A6FAF1-072E-44cf-8957-5838F569A31D} - C:\Program Files\MyWebSearch\SrchAstt\1.bin\MWSSRCAS.DLL (More Details) O2 - BHO: mwsBar BHO - {07B18EA1-A523-4961-B6BB-170DE4475CCA} - C:\Program Files\MyWebSearch\bar\1.bin\MWSBAR.DLL (More Details) O2 - BHO: (no name) - {26115CAF-42F0-5F31-6952-24C986F0F98F} - (no file) (More Details) O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll (More Details) O2 - BHO: (no name) - {7DD2A909-DF2E-5B69-3F6B-3F2F42256143} - C:\DOCUME~1\hk\APPLIC~1\SHIMMA~1\Adminnoun.exe (More Details) O2 - BHO: IeCatch2 Class - {A5366673-E8CA-11D3-9CD9-0090271D075B} - C:\PROGRA~1\FlashGet\Jccatch.dll (More Details) O3 - Toolbar: FlashGet Bar - {E0E899AB-F487-11D5-8D29-0050BA6940E3} - C:\PROGRA~1\FlashGet\fgiebar.dll (More Details) O4 - HKLM\..\Run: [IMJPMIG8.1] "C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE" /Spoil /RemAdvDef /Migration32 (More Details) O4 - HKLM\..\Run: [MyWebSearch Email Plugin] C:\PROGRA~1\MYWEBS~1\bar\1.bin\mwsoemon.exe (More Details) O2 - BHO: (no name) - {e0103cd4-d1ce-411a-b75b-4fec072867f4} - C:\WINDOWS\system32\hpB8BE.tmp (More Details) O4 - HKLM\..\Run: [PHIME2002ASync] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /SYNC (More Details) O4 - HKLM\..\Run: [PHIME2002A] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /IMEName (More Details) O4 - HKLM\..\Run: [MyIMLite_UpDate] rundll32 C:\WINDOWS\system32\MyIMLite\Update.dll,UpdateFirst (More Details) O4 - HKLM\..\Run: [MyIMLite] C:\WINDOWS\system32\MyIMLite\MyIMLite.exe -h (More Details) O4 - HKLM\..\Run: [assistse] "C:\PROGRA~1\3721\assistse.exe" (More Details) R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://hsremove.com/done.htm (More Details) R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local (More Details) R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Koppelingen (More Details) O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll (More Details) O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file) (More Details) O3 - Toolbar: Veoh Browser Plug-in - {D0943516-5076-4020-A3B5-AEFAF26AB263} - D:\Veoh Networks\Veoh\Plugins\reg\VeohToolbar.dll (More Details) O4 - HKLM\..\Run: [ehTray] C:\WINDOWS\ehome\ehtray.exe (More Details) O4 - HKLM\..\Run: [Snelkoppeling naar eigenschappenvenster voor High Definition Audio] HDAudPropShortcut.exe (More Details) O4 - HKLM\..\Run: [RemoteControl] "C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe" (More Details) Back to Spyware List |
||||||
| About HijackRemote | Recently Slayed Spyware | Message Board | Contact Us | ||||||
| HijackRemote ©2005 (Terms of Service) Privacy Policy | ||||||