HijackRemote Anti-Spyware P2P Service

 

     
 
 Clean This with HijackRemote


Spyware File Details

O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE

Last Detected: 6/24/2006 3:44:00 PM
Found on 8 PCs.

Users with this object complained of the following:

"spaware"
"Windows firewall detected suspicious"
"popups slow"


PCs containing this item also contained the following spyware:

O4 - HKLM\..\Run: [UpdReg] C:\WINDOWS\UpdReg.EXE
(More Details)

O4 - HKLM\..\Run: [links] links.exe
(More Details)

O4 - HKLM\..\Run: [WinHound] C:\Program Files\WinHound\WinHound.exe
(More Details)

O4 - HKCU\..\Run: [Windows installer] C:\winstall.exe
(More Details)

O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
(More Details)

O2 - BHO: (no name) - AutorunsDisabled - (no file)
(More Details)

O2 - BHO: Class - {AA17060B-41AF-88EC-D24D-13F4FB9C2034} - C:\WINDOWS\d3uy.dll
(More Details)

O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
(More Details)

O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre1.5.0_06\bin\jusched.exe
(More Details)

O4 - HKLM\..\Run: [TkBellExe] "realsched.exe" -osboot
(More Details)

O4 - HKLM\..\Run: [6.tmp] C:\DOCUME~1\Chris\LOCALS~1\Temp\6.tmp.exe
(More Details)

O4 - HKLM\..\Run: [sysey32.exe] C:\WINDOWS\sysey32.exe
(More Details)

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://g.msn.ca/0SEENCA/SAOS01?FORM=TOOLBR
(More Details)

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://g.msn.ca/0SEENCA/SAOS01?FORM=TOOLBR
(More Details)

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://runonce.msn.com/?v=msgrv75
(More Details)

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.mdg.ca
(More Details)

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://red.clientapps.yahoo.com/customize/ie/defaults/su/ymsgr6/*http://www.yahoo.com
(More Details)

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://red.clientapps.yahoo.com/customize/ie/defaults/sb/ymsgr6/*http://www.yahoo.com/ext/search/search.html
(More Details)

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://red.clientapps.yahoo.com/customize/ie/defaults/sp/ymsgr6/*http://www.yahoo.com
(More Details)

R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://g.msn.ca/0SEENCA/SAOS01?FORM=TOOLBR
(More Details)

R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = 127.0.0.1
(More Details)

O2 - BHO: (no name) - {549B5CA7-4A86-11D7-A4DF-000874180BB3} - (no file)
(More Details)

O4 - HKLM\..\Run: [MMTray] C:\Program Files\MUSICMATCH\MUSICMATCH Jukebox\mm_tray.exe
(More Details)

O4 - HKLM\..\Run: [TkBellExe] C:\Program Files\Common Files\Real\Update_OB\realsched.exe -osboot
(More Details)

O4 - HKLM\..\Run: [HostManager] C:\Program Files\Common Files\AOL\1136781946\ee\AOLSoftware.exe
(More Details)

O4 - HKCU\..\Run: [spc_w] C:\Program Files\JUSearch\juspc.exe -w
(More Details)

O4 - HKCU\..\Run: [PlaxoUpdate] C:\Program Files\Plaxo\2.6.2.7\PlaxoHelper.exe -a
(More Details)

O4 - HKCU\..\Run: [Aim6] C:\Program Files\Common Files\AOL\Launch\AOLLaunch.exe /d locale=en-US ee://aol/imApp
(More Details)

O4 - Global Startup: hp psc 1000 series.lnk = ?
(More Details)

O4 - HKLM\..\Run: [Mouse Suite 98 Daemon] ICO.EXE
(More Details)

O4 - Global Startup: Quicken Startup.lnk = C:\Program Files\Quicken\QWDLLS.EXE
(More Details)


Back to Spyware List

 
     
 About HijackRemote | Recently Slayed Spyware | Message Board | Contact Us
 HijackRemote ©2005 (Terms of Service)