HijackRemote Anti-Spyware P2P Service

 

     
 
 Clean This with HijackRemote


Spyware File Details

O4 - Global Startup: MyWebSearch Email Plugin.lnk = C:\Program Files\MyWebSearch\bar\1.bin\MWSOEMON.EXE

Last Detected: 3/23/2006 7:38:00 PM
Found on 7 PCs.

Users with this object complained of the following:

"pop ups "
"kids download alot of programs"
"have spyware issues constant pop ups error messages at start up such as csrss.new.exe very slow computer also get a error message about my sub system being dos not sure what it is"
"slow"
"slow comp "


PCs containing this item also contained the following spyware:

R3 - URLSearchHook: (no name) - {00A6FAF6-072E-44cf-8957-5838F569A31D} - C:\Program Files\MyWebSearch\SrchAstt\1.bin\MWSSRCAS.DLL
(More Details)

O2 - BHO: BHObj Class - {00000010-6F7D-442C-93E3-4A4827C2E4C8} - C:\WINDOWS\nem220.dll (file missing)
(More Details)

O2 - BHO: MyWebSearch Search Assistant BHO - {00A6FAF1-072E-44cf-8957-5838F569A31D} - C:\Program Files\MyWebSearch\SrchAstt\1.bin\MWSSRCAS.DLL
(More Details)

O2 - BHO: mwsBar BHO - {07B18EA1-A523-4961-B6BB-170DE4475CCA} - C:\Program Files\MyWebSearch\bar\1.bin\MWSBAR.DLL
(More Details)

O2 - BHO: BAHelper Class - {A3FDD654-A057-4971-9844-4ED8E67DBBB8} - C:\Program Files\SideFind\sfbho.dll (file missing)
(More Details)

O4 - HKLM\..\Run: [MyWebSearch Email Plugin] C:\PROGRA~1\MYWEBS~1\bar\1.bin\mwsoemon.exe
(More Details)

O4 - HKLM\..\Run: [winupdates] C:\Program Files\winupdates\winupdates.exe /auto
(More Details)

O4 - Global Startup: MyWebSearch Email Plugin.lnk = C:\Program Files\MyWebSearch\bar\1.bin\MWSOEMON.EXE
(More Details)

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Microsoft Internet Explorer provided by OptusNet
(More Details)

O4 - HKCU\..\Run: [MyWebSearch Email Plugin] C:\PROGRA~1\MYWEBS~1\bar\1.bin\mwsoemon.exe
(More Details)

O4 - Startup: MyWebSearch Email Plugin.lnk = C:\Program Files\MyWebSearch\bar\1.bin\MWSOEMON.EXE
(More Details)

O8 - Extra context menu item: &Search - http://bar.mywebsearch.com/menusearch.html?p=ZCxdm528YYAU
(More Details)

O14 - IERESET.INF: START_PAGE_URL=http://www.optusnet.com.au/
(More Details)

R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://search.yahoo.com/search?p=%s
(More Details)

R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = C:\WINDOWS\System\blank.htm
(More Details)

R3 - URLSearchHook: (no name) - {00A6FAF6-072E-44cf-8957-5838F569A31D} - (no file)
(More Details)

F3 - REG:win.ini: load=C:\WINDOWS\System32\lufajlvb\csrss.new.exe
(More Details)

F3 - REG:win.ini: run=C:\WINDOWS\System32\lufajlvb\csrss.new.exe
(More Details)

O1 - Hosts: 64.233.167.104 www.symantec.com
(More Details)

O1 - Hosts: 64.233.167.104 www.sophos.com
(More Details)

O1 - Hosts: 64.233.167.104 www.mcafee.com
(More Details)

O1 - Hosts: 64.233.167.104 www.viruslist.com
(More Details)

O1 - Hosts: 64.233.167.104 www.f-secure.com
(More Details)

O4 - HKLM\..\Run: [A Verizon App] C:\PROGRA~1\VERIZO~1\HELPSU~1\VERIZO~1.EXE
(More Details)

O4 - HKCU\..\Run: [PopularScreensaversWallpaper] rundll32 C:\PROGRA~1\MYWEBS~1\bar\1.bin\F3SCRCTR.DLL,LES
(More Details)

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://g.msn.com/0SEENUS/SAOS01
(More Details)

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.toshiba.com
(More Details)

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page = \blank.htm
(More Details)

O8 - Extra context menu item: &Search - http://bar.mywebsearch.com/menusearch.html?p=ZNxuk172DHUS
(More Details)


Back to Spyware List

 
     
 About HijackRemote | Recently Slayed Spyware | Message Board | Contact Us
 HijackRemote ©2005 (Terms of Service)