Spyware File Details O4 - HKLM\..\Run: [RemoteControl] "C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe" Last Detected: 5/3/2009 3:54:00 PM Found on 3 PCs. Users with this object complained of the following: "programs closing, odd startup" "My PC is so, so slow. There are many error in my PC. there is Trojan viruses and Spy Ware. " "no access to windows updates or any of the microsoft sites, no access to most of the anti spyware/virus download sites and restriction when trying to download one (page not found), cannot view hidden files (i had to fix it with a script which am not so sure was a safe one), cannot update existing anti-spyware progs on comp (hitman pro cannot update or start up any of its components), sometimes the cursor slowmotions, sum anti-spyware progs freeze when i attempt to start up e.g. adaware etc which are all components of hitmanpro, but i can access all other sites without a problem but am really sure there is somethig wrong. !!!my D:\ station icon disappeared!!!! PS: I remember b4 i had internet a while ago cuz i just got it today, i tried to check if there were any wireless unsecured networks around me with my wireless usb stick and i accessed some which looked very unsecured but couldnt get online but i think they might have infected my comp if that s possible... " PCs containing this item also contained the following spyware: O4 - HKLM\..\Run: [PCMService] "C:\Program Files\CyberLink\PowerCinema\PCMService.exe" (More Details) O4 - HKLM\..\Run: [RemoteControl] "C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe" (More Details) O4 - HKLM\..\Run: [Ptipbmf] rundll32.exe ptipbmf.dll,SetWriteCacheMode (More Details) O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup (More Details) O4 - HKLM\..\Run: [nwiz] nwiz.exe /install (More Details) O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit (More Details) O4 - HKCU\..\Run: [CTFMON.EXE] C:\windows\system32\ctfmon.exe (More Details) O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll (More Details) O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - "C:\PROGRA~1\MSNMES~1\msgrapp.dll" (file missing) (More Details) O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe (More Details) R1 - HKCU\Software\Microsoft\Internet Explorer,SearchURL = http://windiwsfsearch.com (More Details) R1 - HKLM\Software\Microsoft\Internet Explorer,SearchURL = http://windiwsfsearch.com (More Details) R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://windiwsfsearch.com (More Details) R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://windiwsfsearch.com/ie6.html (More Details) R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://windiwsfsearch.com (More Details) R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://windiwsfsearch.com/ie6.html (More Details) R1 - HKCU\Software\Microsoft\Internet Explorer\Search,SearchAssistant = http://windiwsfsearch.com (More Details) R3 - URLSearchHook: (no name) - {00A6FAF6-072E-44cf-8957-5838F569A31D} - C:\Program Files\MyWebSearch\SrchAstt\1.bin\MWSSRCAS.DLL (More Details) R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll (More Details) O2 - BHO: MyWebSearch Search Assistant BHO - {00A6FAF1-072E-44cf-8957-5838F569A31D} - C:\Program Files\MyWebSearch\SrchAstt\1.bin\MWSSRCAS.DLL (More Details) R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://hsremove.com/done.htm (More Details) R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local (More Details) R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Koppelingen (More Details) O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll (More Details) O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file) (More Details) O3 - Toolbar: Veoh Browser Plug-in - {D0943516-5076-4020-A3B5-AEFAF26AB263} - D:\Veoh Networks\Veoh\Plugins\reg\VeohToolbar.dll (More Details) O4 - HKLM\..\Run: [ehTray] C:\WINDOWS\ehome\ehtray.exe (More Details) O4 - HKLM\..\Run: [Snelkoppeling naar eigenschappenvenster voor High Definition Audio] HDAudPropShortcut.exe (More Details) O4 - HKLM\..\Run: [IMJPMIG8.1] "C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE" /Spoil /RemAdvDef /Migration32 (More Details) Back to Spyware List |
||||||
| About HijackRemote | Recently Slayed Spyware | Message Board | Contact Us | ||||||
| HijackRemote ©2005 (Terms of Service) Privacy Policy | ||||||