HijackRemote Anti-Spyware P2P Service

 

     
 
 Clean This with HijackRemote


Spyware File Details

R1 - HKCU\Software\Microsoft\Internet Explorer\Search,SearchAssistant = about:blank

Last Detected: 1/20/2006 12:15:00 AM
Found on 6 PCs.

Users with this object complained of the following:

"A program called SpyAxe keeps installing on my computer even if I delete it. I use SpyBot. It finds spyware - PSGuard, Smitfraud-C, SpyAxe and Vcodec. It keeps coming back even if i delete it. Have a lot of popups as well. Some of them tells me my computer is infected and I need to download and install a antimalware program."
"Computer tends to crash and come up with a blue screen saying "Microsoft had to shut down due to protection of files" I downloaded the latest video drivers from ati.com, but still nothing changed, I hoped this program could fix it."
"popups"
"slow,infected files"
"Screens freezing"


PCs containing this item also contained the following spyware:

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = about:blank
(More Details)

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = about:blank
(More Details)

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://find.tdconline.dk/google
(More Details)

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = about:blank
(More Details)

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.eniro.dk/
(More Details)

R1 - HKCU\Software\Microsoft\Internet Explorer\Search,SearchAssistant = about:blank
(More Details)

R1 - HKCU\Software\Microsoft\Internet Explorer\Search,CustomizeSearch = about:blank
(More Details)

R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = about:blank
(More Details)

R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Hyperlinks
(More Details)

O2 - BHO: HomepageBHO - {e0103cd4-d1ce-411a-b75b-4fec072867f4} - C:\WINDOWS\system32\hpC6C8.tmp
(More Details)

R1 - HKCU\Software\Microsoft\Internet Explorer,SearchURL = about:blank
(More Details)

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = about:blank
(More Details)

O2 - BHO: (no name) - {5C8B2A36-3DB1-42A4-A3CB-D426709BBFEB} - (no file)
(More Details)

O4 - HKLM\..\Run: [Windows Update Monitoring Service] winupdt.exe
(More Details)

O4 - HKLM\..\Run: [Windows Time] winmgr.exe
(More Details)

O4 - HKLM\..\Run: [vmtuner] gclib.exe
(More Details)

O4 - HKLM\..\Run: [Task Help] wualcts.exe
(More Details)

O4 - HKLM\..\Run: [MsnExplorer] C:\WINDOWS\msexploren.exe /i
(More Details)

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = res://C:\DOCUME~1\MIEKIE~1\LOCALS~1\Temp\se.dll/space.html
(More Details)

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = about:blank
(More Details)

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = res://C:\WINDOWS\system32\lbfmh.dll/sp.html#10001%resultposition.net
(More Details)

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = res://C:\DOCUME~1\MIEKIE~1\LOCALS~1\Temp\se.dll/space.html
(More Details)

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = about:blank
(More Details)

R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = about:blank
(More Details)

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,HomeOldSP = about:blank
(More Details)

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,HomeOldSP = about:blank
(More Details)

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = res://D:\DOCUME~1\Andreea\LOCALS~1\Temp\se.dll/space.html
(More Details)

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = mariuschitoiu@msn.com
(More Details)

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page = C:\WINDOWS\SYSTEM\OOBE\BLANK.HTM
(More Details)

O2 - BHO: Need2Find Bar BHO - {4D1C4E81-A32A-416b-BCDB-33B3EF3617D3} - D:\Program Files\Need2Find\bar\1.bin\ND2FNBAR.DLL
(More Details)

O2 - BHO: IE_PopupBlocker Class - {656EC4B7-072B-4698-B504-2A414C1F0037} - D:\Program Files\ClickNet Accelerator\prpl_IePopupBlocker.dll
(More Details)

O2 - BHO: QUICKfind BHO Object - {C08DF07A-3E49-4E25-9AB0-D3882835F153} - D:\PROGRA~1\TEXTware\QUICKF~1\PlugIns\IEHelp.dll
(More Details)

O2 - BHO: (no name) - {DEBD20D6-5921-4E51-A6E9-1AD0243F91DF} - blank (file missing)
(More Details)

O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - D:\WINDOWS\System32\msdxm.ocx
(More Details)

O4 - HKLM\..\Run: [Microsoft Works Update Detection] D:\Program Files\Common Files\Microsoft Shared\Works Shared\WkUFind.exe
(More Details)

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://yahoo.sbc.com/dsl
(More Details)

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://red.clientapps.yahoo.com/customize/ie/defaults/sb/sbcydsl/*http://www.yahoo.com/search/ie.html
(More Details)

R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://yahoo.sbc.com/dsl
(More Details)

R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://as.starware.com/dp/search?x=wKX1ILEOi+UdWpSlz2q9Dzn13Emww/YwbwL0QoyVdgfhAn/IJM8OXAZ8q/5QEshGRrPiPDTTpGeWedxVgc0vypFym0k5H+NTQhYgFHgom4IxokTcgqAts4de0TLyuCqQNPNsdSwUvm8=
(More Details)

R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = 127.0.0.1;
(More Details)

R3 - URLSearchHook: {FD0B1A83-4F7C-11D5-BD9C-000103C116D5} - - (no file)
(More Details)

O2 - BHO: IEHlprObj Class - {EB344780-3393-11D7-90D1-0001032044C0} - C:\WINDOWS\SYSTEM\M030106SHOP.DLL (file missing)
(More Details)

O2 - BHO: (no name) - {CA356D79-679B-4b4c-8E49-5AF97014F4C1} - (no file)
(More Details)


Back to Spyware List

 
     
 About HijackRemote | Recently Slayed Spyware | Message Board | Contact Us
 HijackRemote ©2005 (Terms of Service) Privacy Policy