HijackRemote Anti-Spyware P2P Service

 

     
 
 Clean This with HijackRemote


Spyware File Details

R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = c:\secure32.html

Last Detected: 2/17/2006 12:40:00 AM
Found on 22 PCs.

Users with this object complained of the following:

"spyware detected"
"google home page "
"all sorts of rubbish from a virus"
"lot of viruses"


PCs containing this item also contained the following spyware:

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = c:\secure32.html
(More Details)

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://search.siemens.net/cgi-bin/iesearch.pl
(More Details)

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = c:\secure32.html
(More Details)

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = c:\secure32.html
(More Details)

R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = c:\secure32.html
(More Details)

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page = \blank.htm
(More Details)

R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = c:\secure32.html
(More Details)

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Microsoft Internet Explorer provided by Siemens VDO V1.0
(More Details)

R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,AutoConfigURL = http://proxyconfig01/jscripts/proxy.pac
(More Details)

R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = http=:;https=:;ftp=:;gopher=localhost:1;socks=:
(More Details)

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page = c:\secure32.html
(More Details)

R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Vnculos
(More Details)

O4 - HKLM\..\Run: [drsmartloadb] c:\\drsmartloadb.exe
(More Details)

O4 - HKLM\..\Run: [winsync] C:\WINDOWS\system32\yiqiwk.exe reg_run
(More Details)

O2 - BHO: (no name) - {75C7F7B3-6A03-17A2-279E-138338DE9BEF} - C:\WINDOWS\system32\ofrmqv.dll
(More Details)

O2 - BHO: (no name) - {C5AF2622-8C75-4dfb-9693-23AB7686A456} - C:\WINDOWS\DH.dll
(More Details)

O17 - HKLM\System\CCS\Services\Tcpip\Parameters: Domain = na.nightingaleassociates.com
(More Details)

O17 - HKLM\Software\..\Telephony: DomainName = na.nightingaleassociates.com
(More Details)

O17 - HKLM\System\CS1\Services\Tcpip\Parameters: Domain = na.nightingaleassociates.com
(More Details)

O17 - HKLM\System\CS2\Services\Tcpip\Parameters: Domain = na.nightingaleassociates.com
(More Details)

F2 - REG:system.ini: Shell=explorer.exe "C:\Program Files\Common Files\Microsoft Shared\Web Folders\ibm00001.exe"
(More Details)

O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx
(More Details)

O4 - HKLM\..\Run: [RealPlayer Ath Check] rnathchk.exe
(More Details)

O4 - HKLM\..\Run: [WINTASK] taskgmr.exe
(More Details)

F2 - REG:system.ini: Shell=explorer.exe "C:\Archivos de programa\Archivos comunes\Microsoft Shared\Web Folders\ibm00003.exe"
(More Details)

O4 - HKLM\..\Run: [PayTime] C:\WINDOWS\system32\paytime.exe
(More Details)


Back to Spyware List

 
     
 About HijackRemote | Recently Slayed Spyware | Message Board | Contact Us
 HijackRemote ©2005 (Terms of Service) Privacy Policy