Spyware File Details R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = c:\secure32.html Last Detected: 2/17/2006 12:40:00 AM Found on 22 PCs. Users with this object complained of the following: "spyware detected" "google home page " "all sorts of rubbish from a virus" "lot of viruses" PCs containing this item also contained the following spyware: R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = c:\secure32.html (More Details) R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://search.siemens.net/cgi-bin/iesearch.pl (More Details) R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = c:\secure32.html (More Details) R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = c:\secure32.html (More Details) R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = c:\secure32.html (More Details) R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page = \blank.htm (More Details) R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = c:\secure32.html (More Details) R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Microsoft Internet Explorer provided by Siemens VDO V1.0 (More Details) R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,AutoConfigURL = http://proxyconfig01/jscripts/proxy.pac (More Details) R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = http= (More Details) R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page = c:\secure32.html (More Details) R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Vnculos (More Details) O4 - HKLM\..\Run: [drsmartloadb] c:\\drsmartloadb.exe (More Details) O4 - HKLM\..\Run: [winsync] C:\WINDOWS\system32\yiqiwk.exe reg_run (More Details) O2 - BHO: (no name) - {75C7F7B3-6A03-17A2-279E-138338DE9BEF} - C:\WINDOWS\system32\ofrmqv.dll (More Details) O2 - BHO: (no name) - {C5AF2622-8C75-4dfb-9693-23AB7686A456} - C:\WINDOWS\DH.dll (More Details) O17 - HKLM\System\CCS\Services\Tcpip\Parameters: Domain = na.nightingaleassociates.com (More Details) O17 - HKLM\Software\..\Telephony: DomainName = na.nightingaleassociates.com (More Details) O17 - HKLM\System\CS1\Services\Tcpip\Parameters: Domain = na.nightingaleassociates.com (More Details) O17 - HKLM\System\CS2\Services\Tcpip\Parameters: Domain = na.nightingaleassociates.com (More Details) F2 - REG:system.ini: Shell=explorer.exe "C:\Program Files\Common Files\Microsoft Shared\Web Folders\ibm00001.exe" (More Details) O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx (More Details) O4 - HKLM\..\Run: [RealPlayer Ath Check] rnathchk.exe (More Details) O4 - HKLM\..\Run: [WINTASK] taskgmr.exe (More Details) F2 - REG:system.ini: Shell=explorer.exe "C:\Archivos de programa\Archivos comunes\Microsoft Shared\Web Folders\ibm00003.exe" (More Details) O4 - HKLM\..\Run: [PayTime] C:\WINDOWS\system32\paytime.exe (More Details) Back to Spyware List |
||||||
| About HijackRemote | Recently Slayed Spyware | Message Board | Contact Us | ||||||
| HijackRemote ©2005 (Terms of Service) Privacy Policy | ||||||