HijackRemote Anti-Spyware P2P Service

 

     
 
 Clean This with HijackRemote


Spyware File Details

O15 - Trusted Zone: http://redirect.mirarsearch.com (HKLM)

Last Detected: 1/11/2007 11:59:00 AM
Found on 14 PCs.

Users with this object complained of the following:



PCs containing this item also contained the following spyware:

R3 - URLSearchHook: (no name) - _{9E7D2425-5E63-5AA0-0751-D0227CF78991} - (no file)
(More Details)

O4 - HKLM\..\RunServices: [LSASS Authority] lshosts32.exe
(More Details)

O15 - Trusted Zone: http://click.getmirar.com (HKLM)
(More Details)

O15 - Trusted Zone: http://click.mirarsearch.com (HKLM)
(More Details)

O15 - Trusted Zone: http://redirect.mirarsearch.com (HKLM)
(More Details)

O16 - DPF: {56336BCB-3D8A-11D6-A00B-0050DA18DE71} (RdxIE Class) - http://software-dl.real.com/1116ff6a4d9...xIE601.cab
(More Details)

O20 - Winlogon Notify: Themes - C:\WINDOWS\system32\hrps0577e.dll (file missing)
(More Details)

O23 - Service: Network Monitor - Unknown owner - C:\Program Files\Network Monitor\netmon.exe (file missing)
(More Details)

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://server224.smartbotpro.net/7search/?new-hkcu
(More Details)

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://red.clientapps.yahoo.com/customi...sb/ymsgr6/*http://www.yahoo.com/ext/search/search.html
(More Details)

R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = http://out.true-counter.com/c/?101 (obfuscated)
(More Details)

O2 - BHO: (no name) - {E0C6A9FD-381C-1F59-AF8B-D95ACFA0A8FF} - C:\windows\system\gqrznutc.dll (file missing)
(More Details)

O2 - BHO: (no name) - {DD28DD8B-0DF4-4F49-BDE6-B09FB3BEB8EB} - (no file)
(More Details)

O2 - BHO: mwsBar BHO - {07B18EA1-A523-4961-B6BB-170DE4475CCA} - C:\PROGRAM FILES\MYWEBSEARCH\BAR\1.BIN\MWSBAR.DLL (file missing)
(More Details)

O2 - BHO: MyWebSearch Search Assistant BHO - {00A6FAF1-072E-44cf-8957-5838F569A31D} - C:\PROGRAM FILES\MYWEBSEARCH\SRCHASTT\1.BIN\MWSSRCAS.DLL (file missing)
(More Details)

O2 - BHO: URLLink Class - {4A2AACF3-ADF6-11D5-98A9-00E018981B9E} - C:\Program Files\NewDotNet\newdotnet6_38.dll (file missing)
(More Details)

O2 - BHO: (no name) - {8DA5457F-A8AA-4CCF-A842-70E6FD274094} - C:\PROGRA~1\COMMON~1\WINTOOLS\WTOOLST.DLL (file missing)
(More Details)

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar =
(More Details)

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page =
(More Details)

R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page =
(More Details)

R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
(More Details)

O2 - BHO: ngsh35.clsIS - {392BAF48-A26A-45B5-9263-97128E429268} - C:\WINDOWS\system32\ngsh35.dll
(More Details)

O4 - HKLM\..\Run: [elitemedia] C:\WINDOWS\elitemediapop.exe
(More Details)

O4 - HKLM\..\Run: [sms_msn] C:\WINDOWS\system32\sms_msn.exe
(More Details)

O4 - HKLM\..\Run: [BrowserUpdateSched] C:\WINDOWS\system32\lwinksaw.exe FI002
(More Details)

O4 - Startup: Zeno.lnk = C:\WINDOWS\system32\lwinksaw.exe
(More Details)

O15 - Trusted Zone: *.elitemediagroup.net
(More Details)


Back to Spyware List

 
     
 About HijackRemote | Recently Slayed Spyware | Message Board | Contact Us
 HijackRemote ©2005 (Terms of Service) Privacy Policy