Spyware File Details O8 - Extra context menu item: Web Rebates. - file://C:\Program Files\WebRebates4\websrebates\webtrebates\toprC0.htm Last Detected: 2/17/2006 12:28:00 AM Found on 9 PCs. Users with this object complained of the following: "popups, runs slow, reoccuring problems" "slows" PCs containing this item also contained the following spyware: O2 - BHO: (no name) - {975E3768-9A1B-B3B6-A1C0-8C7C29C2B79B} - C:\DOCUME~1\Owner\APPLIC~1\SURFSP~1\stopdefy.exe (More Details) O4 - HKLM\..\Run: [StorageGuard] "C:\Program Files\VERITAS Software\Update Manager\sgtray.exe" /r (More Details) O4 - HKCU\..\Run: [rule bolt] C:\DOCUME~1\Owner\APPLIC~1\32SHOW~1\ford user cool.exe (More Details) O8 - Extra context menu item: Download all by Free Download Manager - file://C:\Program Files\Free Download Manager\dlall.htm (More Details) O8 - Extra context menu item: Download by Free Download Manager - file://C:\Program Files\Free Download Manager\dllink.htm (More Details) O8 - Extra context menu item: Download selected by Free Download Manager - file://C:\Program Files\Free Download Manager\dlselected.htm (More Details) O8 - Extra context menu item: Download web site by Free Download Manager - file://C:\Program Files\Free Download Manager\dlpage.htm (More Details) O8 - Extra context menu item: Web Rebates. - file://C:\Program Files\WebRebates4\websrebates\webtrebates\toprC0.htm (More Details) O1 - Hosts: 82.179.166.164 lender-search.com (More Details) O1 - Hosts: 82.179.166.165 hot-searches.com (More Details) O3 - Toolbar: H&otbar - {74CC49F7-EB32-4A08-B204-948962A6E3DB} - C:\Program Files\HbTools\Bin\4.7.1.0\HbtHostIE.dll (More Details) O4 - HKLM\..\Run: [webrebates] "C:\Program Files\WebRebates4\webrebates.exe" (More Details) O4 - HKLM\..\Run: [SurfAccuracy] C:\Program Files\SurfAccuracy\SAcc.exe (More Details) O4 - HKLM\..\Run: [TopSearch] C:\Program Files\TopSearch\TopSearch.exe (More Details) O16 - DPF: {00000000-0000-0000-0000-000020040000} - http://207.234.185.217/ABoxInst_int12.exe (More Details) O16 - DPF: {14A3221B-1678-1982-A355-7263B1281987} - ms-its:mhtml:file://C:\foo.mht!http://82.179.166.130/e9xr2.chm::/file.exe (More Details) O16 - DPF: {15AD4789-CDB4-47E1-A9DA-992EE8E6BAD6} - http://static.windupdates.com/cab/DownloadsUnlimited/ie/bridge-c11.cab (More Details) R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://www.esfzhbkyvfz.biz/4JwYcCYbLFdq...c8XxB.html (More Details) O4 - HKLM\..\Run: [ObjectLoader] C:\WINDOWS\system32\20.tmp (More Details) O4 - HKCU\..\Run: [MyWebSearch Email Plugin] C:\PROGRA~1\MYWEBS~1\bar\3.bin\mwsoemon.exe (More Details) O4 - HKCU\..\Run: [Outlook Mail Services] outlook-express.exe (More Details) O4 - HKCU\..\Run: [amok roam] C:\DOCUME~1\CHELSEA\APPLIC~1\SCRBUI~1\First Plan.exe (More Details) O4 - HKCU\..\Run: [inedge] C:\WINDOWS\system32\inedge.exe (More Details) O4 - HKCU\..\Run: [CU1] C:\Program Files\Common Files\VCClient\VCClient.exe (More Details) O4 - HKCU\..\Run: [CU2] C:\Program Files\Common Files\VCClient\VCMain.exe (More Details) O9 - Extra button: WeatherBug - {AF6CABAB-61F9-4f12-A198-B7D41EF1CB52} - C:\Program Files\AWS\WeatherBug\Weather.exe (file missing) (HKCU) (More Details) Back to Spyware List |
||||||
| About HijackRemote | Recently Slayed Spyware | Message Board | Contact Us | ||||||
| HijackRemote ©2005 (Terms of Service) | ||||||