Spyware File Details R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = about:blank Last Detected: 1/7/2006 12:18:00 AM Found on 6 PCs. Users with this object complained of the following: "A program called SpyAxe keeps installing on my computer even if I delete it. I use SpyBot. It finds spyware - PSGuard, Smitfraud-C, SpyAxe and Vcodec. It keeps coming back even if i delete it. Have a lot of popups as well. Some of them tells me my computer is infected and I need to download and install a antimalware program." "Computer tends to crash and come up with a blue screen saying "Microsoft had to shut down due to protection of files" I downloaded the latest video drivers from ati.com, but still nothing changed, I hoped this program could fix it." "popups" "alot of popups " PCs containing this item also contained the following spyware: R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = about:blank (More Details) R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = about:blank (More Details) R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://find.tdconline.dk/google (More Details) R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = about:blank (More Details) R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.eniro.dk/ (More Details) R1 - HKCU\Software\Microsoft\Internet Explorer\Search,SearchAssistant = about:blank (More Details) R1 - HKCU\Software\Microsoft\Internet Explorer\Search,CustomizeSearch = about:blank (More Details) R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = about:blank (More Details) R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Hyperlinks (More Details) O2 - BHO: HomepageBHO - {e0103cd4-d1ce-411a-b75b-4fec072867f4} - C:\WINDOWS\system32\hpC6C8.tmp (More Details) R1 - HKCU\Software\Microsoft\Internet Explorer,SearchURL = about:blank (More Details) R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = about:blank (More Details) O2 - BHO: (no name) - {5C8B2A36-3DB1-42A4-A3CB-D426709BBFEB} - (no file) (More Details) O4 - HKLM\..\Run: [Windows Update Monitoring Service] winupdt.exe (More Details) O4 - HKLM\..\Run: [Windows Time] winmgr.exe (More Details) O4 - HKLM\..\Run: [vmtuner] gclib.exe (More Details) O4 - HKLM\..\Run: [Task Help] wualcts.exe (More Details) O4 - HKLM\..\Run: [MsnExplorer] C:\WINDOWS\msexploren.exe /i (More Details) R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = res://C:\DOCUME~1\MIEKIE~1\LOCALS~1\Temp\se.dll/space.html (More Details) R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = about:blank (More Details) R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = res://C:\WINDOWS\system32\lbfmh.dll/sp.html#10001%resultposition.net (More Details) R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = res://C:\DOCUME~1\MIEKIE~1\LOCALS~1\Temp\se.dll/space.html (More Details) R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = about:blank (More Details) R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = about:blank (More Details) R1 - HKCU\Software\Microsoft\Internet Explorer\Main,HomeOldSP = about:blank (More Details) R1 - HKLM\Software\Microsoft\Internet Explorer\Main,HomeOldSP = about:blank (More Details) R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://www.gwwrsjszpaghpwzoffagxpcq.com/1LDwTjr_HtJs_fqr6V8Yo_6gPN2zZCgwq3j3UhhQQnmOUVvS8Ys1wQKUqQnl2LFO.html (More Details) R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = (More Details) R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://213.159.117.134/index.php (More Details) R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://minisearch.startnow.com/ (More Details) R1 - HKLM\Software\Microsoft\Internet Explorer\Search,Default_Search_URL = http://minisearch.startnow.com/ (More Details) R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = (More Details) R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Mr.Nokia Explorer (More Details) R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = 127.0.0.1:9202 (More Details) R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = (More Details) Back to Spyware List |
||||||
| About HijackRemote | Recently Slayed Spyware | Message Board | Contact Us | ||||||
| HijackRemote ©2005 (Terms of Service) | ||||||