Spyware File Details O4 - HKLM\..\Run: [zango] c:\program files\zango\zango.exe Last Detected: 4/2/2006 8:43:00 PM Found on 2 PCs. Users with this object complained of the following: "pop-ups,slow,says that has detected 200+ viruses and that malicious spyware has been detected" "still getting spywareaxe comming up on my desktop. Cant log on to web sites that I use to be able to log on, like my online banking." PCs containing this item also contained the following spyware: R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iehome&locale=EN_US&c=Q304&bd=presario&pf=desktop (More Details) R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iesearch&locale=EN_US&c=Q304&bd=presario&pf=desktop (More Details) R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://us.rd.yahoo.com/customize/ycomp/defaults/sb/*http://www.yahoo.com/search/ie.html (More Details) R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://us.rd.yahoo.com/customize/ycomp/defaults/sp/*http://www.yahoo.com (More Details) R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iesearch&locale=EN_US&c=Q304&bd=presario&pf=desktop (More Details) R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iehome&locale=EN_US&c=Q304&bd=presario&pf=desktop (More Details) R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = http://as.starware.com/dp/search?x=wKX1ILEOi+Vh7AfA98Gm4Me69ZMbubcDBVt3B+BXausuvGJLE8j25NqLlfutzT6pM2We28iJn1enoZNmR1jice5zTRsR26rpShMAd03KjsBD2TQttreWRETS3hqFttbl6Lnr24tR18pck8Hxd7K3GL1Byx84ZEW2y/ehYAJD1hvVfG1q4zFmZgYedZFMARQ1xIcmwYFWI/A9HjhS2UwewvUskoF/PTwAWCgJyiIHaDRFX5T3fQRKrLCRCaCGfdyeMuX5khUVAIUF1F4AKTJs2rW073bFb9Tmg611PAVyTl1KhOa2+Vu6QqVuiWKf0kaqL7TQTpX7MaELUwm4K/SS3H1ALd4LpZ5bVCaYOpBT5zw= (More Details) R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://us.rd.yahoo.com/customize/ycomp/defaults/su/*http://www.yahoo.com (More Details) O2 - BHO: HomepageBHO - {e0103cd4-d1ce-411a-b75b-4fec072867f4} - C:\WINDOWS\System32\hpF43.tmp (More Details) R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page = (More Details) R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = (More Details) O2 - BHO: (no name) - {E3215F20-3212-11D6-9F8B-00D0B743919D} - (no file) (More Details) O4 - HKLM\..\Run: [CMLoader] rundll32.exe "c:\program files\crystalys media\cm.dll",MakeInjection (More Details) O4 - HKLM\..\Run: [NaviSearch] C:\Program Files\NaviSearch\bin\nls.exe (More Details) O4 - HKLM\..\Run: [SpyAxe] C:\Program Files\SpyAxe\spyaxe.exe /h (More Details) O4 - HKLM\..\Run: [SpywareStrike] C:\Program Files\SpywareStrike\SpywareStrike.exe /h (More Details) O4 - HKLM\..\Run: [WindowsUpdateNT] C:\WINDOWS\System\svwhost.exe /s (More Details) O4 - HKLM\..\Run: [winsync] C:\WINDOWS\system32\nirdnr.exe reg_run (More Details) O4 - HKLM\..\Run: [zango] c:\program files\zango\zango.exe (More Details) Back to Spyware List |
||||||
| About HijackRemote | Recently Slayed Spyware | Message Board | Contact Us | ||||||
| HijackRemote ©2005 (Terms of Service) | ||||||