HijackRemote Anti-Spyware P2P Service

 

     
 
 Clean This with HijackRemote


Spyware File Details

R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Vnculos

Last Detected: 2/17/2006 12:31:00 AM
Found on 10 PCs.

Users with this object complained of the following:

"google home page "
"spyware dialer"
"popups coming through to desktop"
"popups from msn"


PCs containing this item also contained the following spyware:

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = c:\secure32.html
(More Details)

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = c:\secure32.html
(More Details)

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = c:\secure32.html
(More Details)

R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = c:\secure32.html
(More Details)

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page = c:\secure32.html
(More Details)

R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = c:\secure32.html
(More Details)

R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Vnculos
(More Details)

O4 - HKLM\..\Run: [drsmartloadb] c:\\drsmartloadb.exe
(More Details)

O4 - HKLM\..\Run: [winsync] C:\WINDOWS\system32\yiqiwk.exe reg_run
(More Details)

R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = proxyhol:80
(More Details)

O17 - HKLM\System\CCS\Services\Tcpip\..\{02ED5ADB-D952-48CD-A173-52875C538A50}: NameServer = 80.58.61.250 80.58.61.254
(More Details)

O17 - HKLM\System\CS1\Services\Tcpip\..\{02ED5ADB-D952-48CD-A173-52875C538A50}: NameServer = 80.58.61.250 80.58.61.254
(More Details)

O20 - Winlogon Notify: ThemeManager - C:\WINDOWS\system32\i8060idse8060.dll
(More Details)

O23 - Service: Command Service (cmdService) - Unknown owner - C:\WINDOWS\bmlnZWwgbW95\command.exe (file missing)
(More Details)

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://g.msn.co.uk/0SEENGB/SAOS01?FORM=TOOLBR
(More Details)

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://g.msn.co.uk/0SEENGB/SAOS01?FORM=TOOLBR
(More Details)

R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://g.msn.co.uk/0SEENGB/SAOS01?FORM=TOOLBR
(More Details)

O4 - HKLM\..\Run: [AgenteADSL_15] C:\Archivos de programa\Telefonica\KitAIM\AimExDll.exe AimGestA.dll 7
(More Details)

O4 - Global Startup: Windows Desktop Search.lnk = C:\Archivos de programa\MSN Toolbar Suite\DS\02.05.0001.1119\en-gb\bin\WindowsSearch.exe
(More Details)

O8 - Extra context menu item: &MSN Search - res://C:\Archivos de programa\MSN Toolbar Suite\TB\02.05.0000.1082\en-gb\msntb.dll/search.htm
(More Details)

O8 - Extra context menu item: Open in new background tab - res://C:\Archivos de programa\MSN Toolbar Suite\TAB\02.05.0001.1119\en-gb\msntabres.dll/229?edeabc38690646d8bb3621847be5d5
(More Details)

O8 - Extra context menu item: Open in new foreground tab - res://C:\Archivos de programa\MSN Toolbar Suite\TAB\02.05.0001.1119\en-gb\msntabres.dll/230?edeabc38690646d8bb3621847be5d5
(More Details)

F2 - REG:system.ini: Shell=explorer.exe "C:\Archivos de programa\Archivos comunes\Microsoft Shared\Web Folders\ibm00003.exe"
(More Details)

O4 - HKLM\..\Run: [PayTime] C:\WINDOWS\system32\paytime.exe
(More Details)


Back to Spyware List

 
     
 About HijackRemote | Recently Slayed Spyware | Message Board | Contact Us
 HijackRemote ©2005 (Terms of Service)