HijackRemote Anti-Spyware P2P Service

 

     
 
 Clean This with HijackRemote


Spyware File Details

O16 - DPF: {9522B3FB-7A2B-4646-8AF6-36E7F593073C} (cpbrkpie Control) - http://a19.g.akamai.net/7/19/7125/4047/ftp.coupons.com/v3123/cpbrkpie.cab

Last Detected: 3/30/2006 11:23:00 PM
Found on 2 PCs.

Users with this object complained of the following:

"junk startup pages on IE"
"movieland ad keeps popping up and won't go away"


PCs containing this item also contained the following spyware:

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = res://C:\WINDOWS\hgqxw.dll/sp.html#28129%resultposition.net
(More Details)

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = about:blank
(More Details)

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = res://C:\WINDOWS\hgqxw.dll/sp.html#28129%resultposition.net
(More Details)

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = res://C:\WINDOWS\hgqxw.dll/sp.html#28129%resultposition.net
(More Details)

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = res://C:\WINDOWS\hgqxw.dll/sp.html#28129%resultposition.net
(More Details)

R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = res://C:\WINDOWS\hgqxw.dll/sp.html#28129%resultposition.net
(More Details)

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page = \blank.htm
(More Details)

O2 - BHO: Class - {4572C182-18D0-C69A-F785-8040372D18DF} - C:\WINDOWS\mfchr32.dll
(More Details)

O4 - HKLM\..\Run: [ipda.exe] C:\WINDOWS\system32\ipda.exe
(More Details)

O16 - DPF: {9522B3FB-7A2B-4646-8AF6-36E7F593073C} (cpbrkpie Control) - http://a19.g.akamai.net/7/19/7125/4047/ftp.coupons.com/v3123/cpbrkpie.cab
(More Details)

R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://red.clientapps.yahoo.com/customize/ycomp/defaults/su/*http://www.yahoo.com
(More Details)

R1 - HKLM\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://red.clientapps.yahoo.com/customize/ycomp/defaults/su/*http://www.yahoo.com
(More Details)

O2 - BHO: (no name) - {549B5CA7-4A86-11D7-A4DF-000874180BB3} - (no file)
(More Details)

O2 - BHO: posHelp Class - {CDEEC43D-3572-4E95-A2A5-F519D29F00C0} - C:\PROGRA~1\ADVANC~1\Toolbar.dll
(More Details)

O3 - Toolbar: (no name) - {BA52B914-B692-46c4-B683-905236F6F655} - (no file)
(More Details)

O3 - Toolbar: Advanced Searchbar - {43F02779-6D88-4958-8AD3-83C12D86ADC7} - C:\Program Files\Advanced Searchbar\Toolbar.dll
(More Details)

O4 - HKLM\..\Run: [MediaPipe P2P Loader] "C:\Program Files\p2pnetworks\mpp2pl.exe" /H
(More Details)

O4 - HKLM\..\Run: [Notification Utility] "C:\Program Files\ItBill\itbill.exe"
(More Details)

O4 - HKCU\..\Run: [ares] C:\Program Files\Ares\Ares.exe -h
(More Details)

O8 - Extra context menu item: &Viewpoint Search - res://C:\Program Files\Viewpoint\Viewpoint Toolbar\ViewBar.dll/CXTSEARCH.HTML
(More Details)


Back to Spyware List

 
     
 About HijackRemote | Recently Slayed Spyware | Message Board | Contact Us
 HijackRemote ©2005 (Terms of Service)