Spyware File Details O4 - HKCU\..\Run: [WhenUSave] "C:\Program Files\Save\Save.exe" Last Detected: 8/22/2007 10:31:00 AM Found on 6 PCs. Users with this object complained of the following: "trojan viirus and spyware destroyer" "fast" "popup and virus" "trojan viirus and spyware destroyer" "slow pc" PCs containing this item also contained the following spyware: O2 - BHO: HomepageBHO - {e0103cd4-d1ce-411a-b75b-4fec072867f4} - C:\WINDOWS\System32\hp3C8C.tmp (More Details) O3 - Toolbar: My Search Bar - {014DA6C9-189F-421a-88CD-07CFE51CFF10} - C:\Program Files\MySearch\bar\2.bin\S4BAR.DLL (file missing) (More Details) O4 - HKLM\..\Run: [SpywareStrike] C:\Program Files\SpywareStrike\SpywareStrike.exe /h (More Details) O4 - HKCU\..\Run: [ErrorFixer] "C:\Program Files\Error Fixer\ErrorFixer.Exe" /boot (More Details) O4 - HKCU\..\Run: [WhenUSave] "C:\Program Files\Save\Save.exe" (More Details) O4 - Global Startup: palstart.exe (More Details) O4 - Global Startup: Startup.exe (More Details) R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page = \blank.htm (More Details) R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Balantlar (More Details) O2 - BHO: HomepageBHO - {27150f81-0877-42e9-af13-55e5a3439a26} - C:\WINDOWS\system32\hpA22B.tmp (More Details) O4 - HKLM\..\Run: [SMSERIAL] sm56hlpr.exe (More Details) O4 - HKLM\..\Run: [ugxazfrm] c:\windows\system32\ugxazfrm.exe ugxazfrm (More Details) O15 - Trusted Zone: http://*.billingnow.com (More Details) O15 - Trusted Zone: http://*.reliablestats.com (More Details) O15 - Trusted Zone: http://*.winantispyware.com (More Details) O15 - Trusted Zone: http://*.winantivirus.com (More Details) O4 - Global Startup: Winter Fun Wallpaper Changer.lnk = ? (More Details) O9 - Extra 'Tools' menuitem: Show &Related Links - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINDOWS\web\related.htm (More Details) O16 - DPF: {42F2C9BA-614F-47C0-B3E3-ECFD34EED658} (Installer Class) - http://www.ysbweb.com/ist/softwares/v4.0/ysb_regular.cab (More Details) O16 - DPF: {841A9192-5690-11D4-A258-0040954A01BE} (DialXSCtl Object) - http://dialxs.nl/install/dialxs.ocx (More Details) O16 - DPF: {8FCDF9D9-A28B-480F-8C3D-581F119A8AB8} (MediaGatewayX) - http://static.zangocash.com/cab/Zango/ie/bridge-c18.cab (More Details) O16 - DPF: {BFF1950D-B1B4-4AE8-B842-B2CCF06D9A1B} (Zylom Games Player) - http://game07.zylom.com/activex/zylomgamesplayer.cab (More Details) O4 - HKLM\..\Run: [XpDis0Conf] C:\PROGRA~1\Belkin\BELKIN~1\Tool\WinXPDisableZeroConfigation.exe VEN_14E4&DEV_4320&SUBSYS_70111799 /d (More Details) O4 - HKLM\..\Run: [BTUSRBDG] BtUsrBdg.exe (More Details) O4 - HKLM\..\Run: [BTSETBOOTKEY] BTSetBootKey.exe (More Details) O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file) (More Details) O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime (More Details) O4 - HKLM\..\Run: [netkitap_beta] C:\Program Files\NetKitap\netkitap_v2_0.exe (More Details) O4 - HKCU\..\Run: [Yahoo! Pager] "C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe" -quiet (More Details) O4 - HKCU\..\Run: [BitTorrent] "C:\Program Files\BitTorrent\bittorrent.exe" --force_start_minimized (More Details) O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background (More Details) O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe (More Details) O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing) (More Details) O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing) (More Details) Back to Spyware List |
||||||
| About HijackRemote | Recently Slayed Spyware | Message Board | Contact Us | ||||||
| HijackRemote ©2005 (Terms of Service) | ||||||