Spyware File Details O4 - HKLM\..\Run: [00THotkey] C:\WINDOWS\System32\00THotkey.exe Last Detected: 12/5/2006 3:38:00 AM Found on 2 PCs. Users with this object complained of the following: "a program called "cleaner 2006" keeps trying to download itself on to my computer through popups" "there is a flashing icon on toolbar and frequent pop up message that i have a critical virus and an advert promising to clean my computer from the problem if only i purchase their product. the message is up only for 15 seconds and retreats only to pop up again minutes later" PCs containing this item also contained the following spyware: O2 - BHO: MSEvents Object - {B313D637-F405-4052-AC37-E2119AB3C8F8} - C:\WINDOWS\system32\efcax.dll (More Details) O4 - HKLM\..\Run: [00THotkey] C:\WINDOWS\System32\00THotkey.exe (More Details) O4 - HKLM\..\Run: [UpdReg] C:\WINDOWS\UpdReg.EXE (More Details) O20 - Winlogon Notify: nnnmn - C:\WINDOWS\system32\nnnmn.dll (More Details) O2 - BHO: DriveLetterAccess - {5CA3D70E-1895-11CF-8E15-001234567890} - C:\WINDOWS\system32\dla\tfswshx.dll (More Details) O4 - HKLM\..\Run: [ehTray] C:\WINDOWS\ehome\ehtray.exe (More Details) O4 - HKLM\..\Run: [nwiz] "nwiz.exe" /installquiet /keeploaded /nodetect (More Details) O4 - HKLM\..\Run: [dla] C:\WINDOWS\system32\dla\tfswctrl.exe (More Details) O4 - HKLM\..\Run: [000StTHK] 000StTHK.exe (More Details) O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\ (More Details) O20 - Winlogon Notify: WRNotifier - C:\WINDOWS\SYSTEM32\WRLogonNTF.dll (More Details) O21 - SSODL: hemadynamometer - {6076d2b1-634c-4685-843b-f826045ea5dc} - C:\WINDOWS\system32\syycum.dll (More Details) Back to Spyware List |
||||||
| About HijackRemote | Recently Slayed Spyware | Message Board | Contact Us | ||||||
| HijackRemote ©2005 (Terms of Service) Privacy Policy | ||||||