Spyware File Details O4 - HKLM\..\Run: [VVSN] C:\Program Files\VVSN\VVSN.exe Last Detected: 9/8/2006 9:08:00 AM Found on 10 PCs. Users with this object complained of the following: "slow pc" "lot of viruses" "popups " "slowpc" PCs containing this item also contained the following spyware: R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://start.earthlink.net (More Details) R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://www.earthlink.net/partner/more/msie/button/search.html (More Details) R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://mysearch.myway.com/jsp/dellsidebar.jsp?p=DE (More Details) R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = http://start.earthlink.net/AL/Search (More Details) R3 - URLSearchHook: SrchHook Class - {44F9B173-041C-4825-A9B9-D914BD9DCBB3} - C:\Program Files\EarthLink TotalAccess\ElnIE.dll (More Details) R3 - URLSearchHook: (no name) - ~4D25F926-B9FE-4682-BF72-8AB8210D6D75} - (no file) (More Details) R3 - URLSearchHook: (no name) - ~CFBFAE00-17A6-11D0-99CB-00C04FD64497} - (no file) (More Details) R3 - URLSearchHook: (no name) - {4D25F926-B9FE-4682-BF72-8AB8210D6D75} - C:\Program Files\MyWaySA\SrchAsDe\deSrcAs.dll (More Details) O2 - BHO: PnIEBrowserHelperObj Class - {4B5F2E08-6F39-479a-B547-B2026E4C7EDF} - C:\Program Files\EarthLink TotalAccess\PnEL.dll (More Details) O2 - BHO: (no name) - {4D25F921-B9FE-4682-BF72-8AB8210D6D75} - C:\Program Files\MyWaySA\SrchAsDe\deSrcAs.dll (More Details) R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = c:\secure32.html (More Details) R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = c:\secure32.html (More Details) R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = c:\secure32.html (More Details) R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = c:\secure32.html (More Details) R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page = c:\secure32.html (More Details) R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = c:\secure32.html (More Details) F2 - REG:system.ini: Shell=explorer.exe "C:\Program Files\Common Files\Microsoft Shared\Web Folders\ibm00001.exe" (More Details) O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx (More Details) O4 - HKLM\..\Run: [RealPlayer Ath Check] rnathchk.exe (More Details) O4 - HKLM\..\Run: [WINTASK] taskgmr.exe (More Details) R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = (More Details) O2 - BHO: URLLink Class - {4A2AACF3-ADF6-11D5-98A9-00E018981B9E} - C:\Program Files\NewDotNet\newdotnet3_88.dll (More Details) O4 - HKLM\..\Run: [VVSN] C:\Program Files\VVSN\VVSN.exe (More Details) O23 - Service: NTLOAD - Unknown owner - c:\windows\system32\dllcache\win32\winlogon.exe (More Details) O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot (More Details) O2 - BHO: MSEvents Object - {FC148228-87E1-4D00-AC06-58DCAA52A4D1} - C:\WINDOWS\System32\jkklk.dll (More Details) O4 - HKLM\..\Run: [t] C:\documents and settings\candice.computer\local settings\temp\t.exe (More Details) O4 - HKLM\..\Run: [dA] C:\documents and settings\candice.computer\local settings\temp\dA.exe (More Details) O4 - HKLM\..\Run: [AwP] C:\documents and settings\candice.computer\local settings\temp\AwP.exe (More Details) O4 - HKLM\..\Run: [u3FW37W] wpacedos.exe (More Details) O4 - HKLM\..\Run: [wdskctl] C:\WINDOWS\wdskctl.exe (More Details) O4 - HKLM\..\Run: [jm6lpFv3] C:\documents and settings\candice.computer\local settings\temp\jm6lpFv3.exe (More Details) O4 - HKLM\..\Run: [TvHJ] C:\documents and settings\josh\local settings\temp\TvHJ.exe (More Details) O4 - HKLM\..\Run: [u3818] u3810.exe (More Details) O4 - HKLM\..\Run: [LSASS32] BQRZUVC.EXE (More Details) Back to Spyware List |
||||||
| About HijackRemote | Recently Slayed Spyware | Message Board | Contact Us | ||||||
| HijackRemote ©2005 (Terms of Service) | ||||||