HijackRemote Anti-Spyware P2P Service

 

     
 
 Clean This with HijackRemote


Spyware File Details

O4 - HKCU\..\Run: [MyWebSearch Email Plugin] C:\PROGRA~1\MYWEBS~1\bar\1.bin\mwsoemon.exe

Last Detected: 2/2/2009 5:39:00 PM
Found on 13 PCs.

Users with this object complained of the following:

"there are always a lot of popups when i'm surfing the internet...and the number of those popups seems to be more and more.....most of those popups are adveritsments like: http://www.cli-tone.com.hk.... they keep poping up.... if there's popup, i'll close it immediately,,, but it will pop up again after a short while.... beside the popups, sometimes, there are some new icons on the desktop..... but i didn't install them.....when i saw these icons, i'll delete them, but weeks later, they may appear in my desktop again.... i can't remember the names of those icons... they were like "my cellular"..."my casino"... and something like that"
"slow pc"
"kids download alot of programs"
"have spyware issues constant pop ups error messages at start up such as csrss.new.exe very slow computer also get a error message about my sub system being dos not sure what it is"
"slow"


PCs containing this item also contained the following spyware:

R3 - URLSearchHook: (no name) - {00A6FAF6-072E-44cf-8957-5838F569A31D} - C:\Program Files\MyWebSearch\SrchAstt\1.bin\MWSSRCAS.DLL
(More Details)

O2 - BHO: MyWebSearch Search Assistant BHO - {00A6FAF1-072E-44cf-8957-5838F569A31D} - C:\Program Files\MyWebSearch\SrchAstt\1.bin\MWSSRCAS.DLL
(More Details)

O2 - BHO: mwsBar BHO - {07B18EA1-A523-4961-B6BB-170DE4475CCA} - C:\Program Files\MyWebSearch\bar\1.bin\MWSBAR.DLL
(More Details)

O2 - BHO: (no name) - {26115CAF-42F0-5F31-6952-24C986F0F98F} - (no file)
(More Details)

O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
(More Details)

O2 - BHO: (no name) - {7DD2A909-DF2E-5B69-3F6B-3F2F42256143} - C:\DOCUME~1\hk\APPLIC~1\SHIMMA~1\Adminnoun.exe
(More Details)

O2 - BHO: IeCatch2 Class - {A5366673-E8CA-11D3-9CD9-0090271D075B} - C:\PROGRA~1\FlashGet\Jccatch.dll
(More Details)

O3 - Toolbar: FlashGet Bar - {E0E899AB-F487-11D5-8D29-0050BA6940E3} - C:\PROGRA~1\FlashGet\fgiebar.dll
(More Details)

O4 - HKLM\..\Run: [IMJPMIG8.1] "C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE" /Spoil /RemAdvDef /Migration32
(More Details)

O4 - HKLM\..\Run: [MyWebSearch Email Plugin] C:\PROGRA~1\MYWEBS~1\bar\1.bin\mwsoemon.exe
(More Details)

O2 - BHO: BAHelper Class - {A3FDD654-A057-4971-9844-4ED8E67DBBB8} - C:\Program Files\SideFind\sfbho.dll
(More Details)

O4 - HKLM\..\Run: [LoadQM] loadqm.exe
(More Details)

O4 - HKLM\..\Run: [webscan] "C:\Program Files\Acceleration Software\Anti-Virus\stopsignav.exe" -k
(More Details)

O4 - HKLM\..\Run: [SurfAccuracy] C:\Program Files\SurfAccuracy\SAcc.exe
(More Details)

O4 - HKCU\..\Run: [Spyware Cleaner] "C:\Program Files\Spyware Cleaner\SpywareCleaner.Exe" /boot
(More Details)

O4 - HKCU\..\Run: [MyWebSearch Email Plugin] C:\PROGRA~1\MYWEBS~1\bar\1.bin\mwsoemon.exe
(More Details)

O4 - Startup: MyWebSearch Email Plugin.lnk = C:\Program Files\MyWebSearch\bar\1.bin\MWSOEMON.EXE
(More Details)

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Microsoft Internet Explorer provided by OptusNet
(More Details)

O4 - Global Startup: MyWebSearch Email Plugin.lnk = C:\Program Files\MyWebSearch\bar\1.bin\MWSOEMON.EXE
(More Details)

O8 - Extra context menu item: &Search - http://bar.mywebsearch.com/menusearch.html?p=ZCxdm528YYAU
(More Details)

O14 - IERESET.INF: START_PAGE_URL=http://www.optusnet.com.au/
(More Details)

R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://search.yahoo.com/search?p=%s
(More Details)

R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = C:\WINDOWS\System\blank.htm
(More Details)

R3 - URLSearchHook: (no name) - {00A6FAF6-072E-44cf-8957-5838F569A31D} - (no file)
(More Details)

F3 - REG:win.ini: load=C:\WINDOWS\System32\lufajlvb\csrss.new.exe
(More Details)

F3 - REG:win.ini: run=C:\WINDOWS\System32\lufajlvb\csrss.new.exe
(More Details)

O1 - Hosts: 64.233.167.104 www.symantec.com
(More Details)

O1 - Hosts: 64.233.167.104 www.sophos.com
(More Details)

O1 - Hosts: 64.233.167.104 www.mcafee.com
(More Details)

O1 - Hosts: 64.233.167.104 www.viruslist.com
(More Details)

O1 - Hosts: 64.233.167.104 www.f-secure.com
(More Details)

O4 - HKLM\..\Run: [A Verizon App] C:\PROGRA~1\VERIZO~1\HELPSU~1\VERIZO~1.EXE
(More Details)

O4 - HKCU\..\Run: [PopularScreensaversWallpaper] rundll32 C:\PROGRA~1\MYWEBS~1\bar\1.bin\F3SCRCTR.DLL,LES
(More Details)


Back to Spyware List

 
     
 About HijackRemote | Recently Slayed Spyware | Message Board | Contact Us
 HijackRemote ©2005 (Terms of Service) Privacy Policy