Spyware File Details O4 - HKLM\..\Run: [winupdates] C:\Program Files\winupdates\winupdates.exe /auto Last Detected: 7/7/2006 1:23:00 PM Found on 16 PCs. Users with this object complained of the following: "pc" "the pc is slow but also has pop-ups from ad-first and some online poker site everytime you log onto the internet and the avoid pop-up blockers and don't show up in ad or remove programs. I have also run a variety of adware removers and they don't seem to work either." "pop ups " "slow!!!" PCs containing this item also contained the following spyware: R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = http://resultsmaster.com/SmartOffers/Services/resultsmaster/ResultsMasterHomeLeftPane.htm (More Details) O2 - BHO: URLLink - {4A2AACF3-ADF6-11D5-98A9-00E018981B9E} - C:\Program Files\NewDotNet\newdotnet7_14.dll (More Details) O2 - BHO: WhenUSearch Helper - {BA2325ED-F9EB-4830-8FCE-0BC35B16969B} - C:\Program Files\WhenUSearch\search.dll (More Details) O4 - HKLM\..\Run: [winupdates] C:\Program Files\winupdates\winupdates.exe /auto (More Details) O4 - HKLM\..\Run: [New.net Startup] rundll32 C:\PROGRA~1\NEWDOT~1\NEWDOT~2.DLL,ClientStartup -s (More Details) O4 - HKLM\..\Run: [WhenUSearch] "C:\Program Files\WhenUSearch\Search.exe" (More Details) O4 - HKLM\..\Run: [WhenUSearchWHSE] "C:\Program Files\WhenUSearch\whse.exe" (More Details) O4 - HKLM\..\Run: [OSS] C:\windows\system32\rlvknlg.exe -boot (More Details) R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.dellnet.com (More Details) R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://www.yfvzblowzoesgxol.com/hmNa92bjFc_3N7481k5Jnad0CMcXmbcZ8gHo/BUENNlWk_XDJp073OTonJhFMMIQ.htm (More Details) O1 - Hosts: 207.68.176.250 auto.search.msn.com (More Details) O1 - Hosts: 64.12.152.18 search.netscape.com (More Details) O2 - BHO: (no name) - {E714C353-37B0-3F62-A1F1-97C46CEC562A} - C:\DOCUME~1\Brad\APPLIC~1\HOLDMA~1\multi five.exe (More Details) O4 - HKLM\..\Run: [UpdReg] C:\WINDOWS\UpdReg.EXE (More Details) O4 - HKLM\..\Run: [requester] "C:\WINDOWS\system32\requester.11.exe" (More Details) O4 - HKLM\..\Run: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k (More Details) R3 - URLSearchHook: (no name) - {00A6FAF6-072E-44cf-8957-5838F569A31D} - C:\Program Files\MyWebSearch\SrchAstt\1.bin\MWSSRCAS.DLL (More Details) O2 - BHO: BHObj Class - {00000010-6F7D-442C-93E3-4A4827C2E4C8} - C:\WINDOWS\nem220.dll (file missing) (More Details) O2 - BHO: MyWebSearch Search Assistant BHO - {00A6FAF1-072E-44cf-8957-5838F569A31D} - C:\Program Files\MyWebSearch\SrchAstt\1.bin\MWSSRCAS.DLL (More Details) O2 - BHO: mwsBar BHO - {07B18EA1-A523-4961-B6BB-170DE4475CCA} - C:\Program Files\MyWebSearch\bar\1.bin\MWSBAR.DLL (More Details) O2 - BHO: BAHelper Class - {A3FDD654-A057-4971-9844-4ED8E67DBBB8} - C:\Program Files\SideFind\sfbho.dll (file missing) (More Details) O4 - HKLM\..\Run: [MyWebSearch Email Plugin] C:\PROGRA~1\MYWEBS~1\bar\1.bin\mwsoemon.exe (More Details) O4 - Global Startup: MyWebSearch Email Plugin.lnk = C:\Program Files\MyWebSearch\bar\1.bin\MWSOEMON.EXE (More Details) O4 - HKLM\..\Run: [winlogons.exe] C:\Program Files\KGB Spy\winlogons.exe (More Details) O4 - HKLM\..\Run: [ug8ao03m] C:\WINDOWS\system32\ug8ao03m.exe (More Details) O4 - HKLM\..\Run: [SysMemory manager] c:\windows\system32\mdms.exe (More Details) O4 - HKLM\..\Run: [SpywareStrike] C:\Program Files\SpywareStrike\SpywareStrike.exe /h (More Details) O4 - HKLM\..\Run: [PCShield] regsvr32 /s C:\WINDOWS\system32\sfg_236b.dll (More Details) O4 - HKLM\..\Run: [PayTime] C:\WINDOWS\system32\paytime.exe (More Details) O4 - HKLM\..\Run: [Microsoft Windows System] jlldcaaa.exe (More Details) O4 - HKLM\..\Run: [AutoLoaderAproposClient] C:\WINDOWS\cxtpls_loader.exe /HideUninstall /HideDir /PC= CP.AMS /ShowLegalNote=nonbranded (More Details) Back to Spyware List |
||||||
| About HijackRemote | Recently Slayed Spyware | Message Board | Contact Us | ||||||
| HijackRemote ©2005 (Terms of Service) | ||||||