Spyware File Details R3 - URLSearchHook: (no name) - _{CFBFAE00-17A6-11D0-99CB-00C04FD64497} - (no file) Last Detected: 4/20/2007 8:19:00 AM Found on 12 PCs. Users with this object complained of the following: "popups, slow pc." "I can no longer open up my firefox browser! It shows an error message saying it has to exit the program before I can start a new one!" PCs containing this item also contained the following spyware: R3 - URLSearchHook: (no name) - {67536F21-F3B8-FC6D-C1AB-858AABA4F8C8} - C:\WINDOWS\system32\vhjzfw.dll (More Details) O2 - BHO: (no name) - {8E753366-F9AA-A327-80EC-D10FD3921CC0} - (no file) (More Details) O2 - BHO: (no name) - {96F17C47-ED8A-E407-F7AB-90CB5F9B5BCC} - C:\WINDOWS\system32\agfphn.dll (More Details) O2 - BHO: (no name) - {977776CC-E057-B586-28E4-C19E8A3704C1} - (no file) (More Details) O4 - HKCU\..\Run: [CTFMON.EXE] C:\windows\system32\ctfmon.exe (More Details) O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MI1933~1\OFFICE11\REFIEBAR.DLL (More Details) O20 - Winlogon Notify: igfxcui - C:\WINDOWS\SYSTEM32\igfxdev.dll (More Details) O23 - Service: SQL Server (SQLEXPRESS) (MSSQL$SQLEXPRESS) - Unknown owner - c:\Program Files\Microsoft SQL Server\MSSQL.1\MSSQL\Binn\sqlservr.exe" -sSQLEXPRESS (file missing) (More Details) R3 - URLSearchHook: (no name) - _{CFBFAE00-17A6-11D0-99CB-00C04FD64497} - (no file) (More Details) R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = prosearching.com (More Details) R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://www.2020search.com/search/9884/search.html (More Details) R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = prosearching.com (More Details) R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://boards.gamefaqs.com/gfaqs/gentopic.php?board=915410 (More Details) R1 - HKCU\Software\Microsoft\Internet Explorer\Main,SearchURL = prosearching.com (More Details) R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = prosearching.com (More Details) R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://www.2020search.com/search/9884/search.html (More Details) R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = prosearching.com (More Details) R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = prosearching.com (More Details) R1 - HKLM\Software\Microsoft\Internet Explorer\Main,SearchURL = prosearching.com (More Details) R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page = prosearching.com (More Details) R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page_bak = prosearching.com (More Details) R1 - HKCU\Software\Microsoft\Internet Explorer\Search,SearchAssistant = http://www.2020search.com/search/9884/search.html (More Details) R3 - URLSearchHook: (no name) - {EDA1B874-56CE-0E36-B029-5A17226B779C} - C:\WINDOWS\system32\etcfvlx.dll (file missing) (More Details) O2 - BHO: Nothing - {b0398eca-0bcd-4645-8261-5e9dc70248d0} - C:\WINDOWS\system32\hp412.tmp (More Details) R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = (More Details) R3 - URLSearchHook: (no name) - _{00A6FAF6-072E-44cf-8957-5838F569A31D} - (no file) (More Details) R3 - URLSearchHook: (no name) - {00A6FAF6-072E-44cf-8957-5838F569A31D} - C:\Program Files\MyWebSearch\SrchAstt\7.bin\MWSSRCAS.DLL (More Details) O2 - BHO: MyWebSearch Search Assistant BHO - {00A6FAF1-072E-44cf-8957-5838F569A31D} - C:\Program Files\MyWebSearch\SrchAstt\7.bin\MWSSRCAS.DLL (More Details) O2 - BHO: mwsBar BHO - {07B18EA1-A523-4961-B6BB-170DE4475CCA} - C:\Program Files\MyWebSearch\bar\7.bin\MWSBAR.DLL (More Details) O4 - HKLM\..\Run: [New.net Startup] rundll32 C:\PROGRA~1\NEWDOT~1\NEWDOT~2.DLL,ClientStartup -s (More Details) O4 - HKLM\..\Run: [My Web Search Bar] rundll32 C:\PROGRA~1\MYWEBS~1\bar\7.bin\MWSBAR.DLL,S (More Details) O4 - HKLM\..\Run: [MyWebSearch Email Plugin] C:\PROGRA~1\MYWEBS~1\bar\7.bin\mwsoemon.exe (More Details) O4 - HKLM\..\Run: [PermissionResearch] c:\windows\system32\prmrsr.exe -boot (More Details) R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = http://www.mrfindalot.com/search.asp?si= (More Details) R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch = http://www.mrfindalot.com/search.asp?si= (More Details) O2 - BHO: BHObj Class - {00000010-6F7D-442C-93E3-4A4827C2E4C8} - C:\WINDOWS\nem220.dll (More Details) O2 - BHO: BHObj Class - {8F4E5661-F99E-4B3E-8D85-0EA71C0748E4} - C:\WINDOWS\wsem303.dll (More Details) O2 - BHO: ToolBar888 - {CBCC61FA-0221-4ccc-B409-CEE865CACA3A} - C:\Program Files\ToolBar888\MyToolBar.dll (More Details) O2 - BHO: Ozbyq Class - {D623BC2F-A58D-4A75-A10D-CC244A702A35} - C:\WINDOWS\System32\xeymi.dll (More Details) O2 - BHO: (no name) - {E5E2A3E7-00FE-4D31-A030-A10799DDCA66} - (no file) (More Details) O4 - HKLM\..\Run: [webHancer Agent] C:\Program Files\webHancer\Programs\whAgent.exe (More Details) Back to Spyware List |
||||||
| About HijackRemote | Recently Slayed Spyware | Message Board | Contact Us | ||||||
| HijackRemote ©2005 (Terms of Service) Privacy Policy | ||||||