HijackRemote Anti-Spyware P2P Service

 

     
 
 Clean This with HijackRemote


Spyware File Details

O4 - HKLM\..\Run: [winsysban] C:\windows\winsysban.exe

Last Detected: 3/12/2006 11:43:00 AM
Found on 12 PCs.

Users with this object complained of the following:

"too much ware"
"popups, slow pc"


PCs containing this item also contained the following spyware:

O4 - HKLM\..\Run: [PicasaNet] "C:\Program Files\Hello\Hello.exe" -b
(More Details)

O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
(More Details)

O4 - HKLM\..\Run: [Contextual Tool] C:\WINDOWS\z00096.exe
(More Details)

O4 - HKLM\..\Run: [NewFrn] C:\WINDOWS\newfrn.exe
(More Details)

O4 - HKLM\..\Run: [winsysban] C:\windows\winsysban.exe
(More Details)

O4 - HKLM\..\Run: [winsysupd] C:\windows\winsysupd.exe
(More Details)

O20 - Winlogon Notify: Control Panel - C:\WINDOWS\system32\jt6o07j3e.dll
(More Details)

O23 - Service: SpywareCleanerService - Unknown owner - C:\Program Files\Spyware Cleaner\SCService.exe (file missing)
(More Details)

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://searchbar.findthewebsiteyouneed.com
(More Details)

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://searchbar.findthewebsiteyouneed.com
(More Details)

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://searchbar.findthewebsiteyouneed.com
(More Details)

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://searchbar.findthewebsiteyouneed.com
(More Details)

R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = http://searchbar.findthewebsiteyouneed.com
(More Details)

O4 - HKLM\..\Run: [ntdll.dll] scvhost.exe
(More Details)

O20 - Winlogon Notify: policies - C:\WINNT\system32\fpnm0351e.dll
(More Details)

O4 - HKLM\..\Run: [Alcmtr] ALCMTR.EXE
(More Details)

O4 - HKLM\..\Run: [dmebg.exe] C:\WINDOWS\system32\dmebg.exe
(More Details)

O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\system32\Shdocvw.dll
(More Details)

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.findthewebsiteyouneed.com
(More Details)

R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,AutoConfigURL = http://www.myacc.net
(More Details)

O2 - BHO: CvgraphObj Object - {12355F3E-90C3-41AA-8705-15969AF7F210} - C:\WINDOWS\vgraph.dll
(More Details)

O4 - HKLM\..\Run: [winupdate] C:\Program Files\winupdate\winupdate.exe /auto
(More Details)


Back to Spyware List

 
     
 About HijackRemote | Recently Slayed Spyware | Message Board | Contact Us
 HijackRemote ©2005 (Terms of Service)