Spyware File Details R3 - Default URLSearchHook is missing Last Detected: 1/11/2007 11:56:00 AM Found on 23 PCs. Users with this object complained of the following: "Popups, spyware." "slow" PCs containing this item also contained the following spyware: R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = about:blank (More Details) R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = about:blank (More Details) R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = about:blank (More Details) R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = about:blank (More Details) R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = about:blank (More Details) R3 - Default URLSearchHook is missing (More Details) O3 - Toolbar: (no name) - {E0E899AB-F487-11D5-8D29-0050BA6940E3} - (no file) (More Details) O4 - HKLM\..\Run: [RunDll] C:\windows\system32\rundll.exe (More Details) O4 - HKLM\..\Run: [Microsoft Update] C:\WINDOWS\System32\Microsoft Update.exe (More Details) O4 - HKLM\..\Run: [winlogon] C:\windows\winlogon.exe (More Details) R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://www.dzghejzpet.com/l07QSlA_VPE0/EAnMANv/7OuEh_sAhLlv1oUgWi/lLAuvHalnnkHeEM9sKmCPJgi.html (More Details) O2 - BHO: HomepageBHO - {4da4616d-7e6e-4fd9-a2d5-b6c535733e22} - C:\WINDOWS\system32\hp4502.tmp (More Details) O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - C:\Program Files\Norton AntiVirus\NavShExt.dll (file missing) (More Details) O3 - Toolbar: MSN - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\MSN Apps\MSN Toolbar\01.02.3000.1001\en-us\msntb.dll (file missing) (More Details) O4 - HKLM\..\Run: [MessengerPlus3] "C:\Program Files\MessengerPlus! 3\MsgPlus.exe" (More Details) O4 - HKLM\..\Run: [BlockChecker] C:\Program Files\Block Checker\block-checker.exe (More Details) O4 - HKLM\..\Run: [64 MEOW CREATIVE RULE] C:\Documents and Settings\All Users.WINDOWS\Application Data\Plus Meal 64 Meow\poptime.exe (More Details) O4 - HKLM\..\Run: [New.net Startup] rundll32 C:\PROGRA~1\NEWDOT~1\NEWDOT~1.DLL,ClientStartup -s (More Details) O4 - HKLM\..\Run: [SpywareStrike] C:\Program Files\SpywareStrike\SpywareStrike.exe /h (More Details) R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = (More Details) R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = about:blank (More Details) R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = (More Details) R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page = about:blank (More Details) R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = about:blank (More Details) R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Balantlar (More Details) O2 - BHO: System Process - {C2EEB4FA-B6D6-41b9-9CFA-ABA87F862BCB} - C:\WINDOWS\system32\navshext1.dll (More Details) O4 - HKLM\..\Run: [MSConfig] C:\WINDOWS\PCHealth\HelpCtr\Binaries\MSConfig.exe /auto (More Details) O4 - HKLM\..\Run: [winsync] C:\WINDOWS\system32\ppawyy.exe reg_run (More Details) O9 - Extra button: (no name) - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - (no file) (More Details) O16 - DPF: {9522B3FB-7A2B-4646-8AF6-36E7F593073C} - http://a19.g.akamai.net/7/19/7125/1441/...brkpie.cab (More Details) O16 - DPF: {DF780F87-FF2B-4DF8-92D0-73DB16A1543A} (PopCapLoader Object) - http://www.popcap.com/games/popcaploader_v6.cab (More Details) O16 - DPF: {E62A47D8-74B1-4A93-963A-E5E43B7CC5C2} - http://www.zuvio.com/opnste/UCSearch.CAB (More Details) Back to Spyware List |
||||||
| About HijackRemote | Recently Slayed Spyware | Message Board | Contact Us | ||||||
| HijackRemote ©2005 (Terms of Service) | ||||||