Adware
IGetNet




Adware.IGetNet

weiter HijackThis

O2 - BHO: (no name) - {60E78CAC-E9A7-4302-B9EE-8582EDE22FBF} - C:\WINDOWS\System\BHO001.DLL

O2 - BHO: (no name) - {730F2451-A3FE-4A72-938C-FC8A74F15978} - C:\WINDOWS\System\BHO.DLL

O4 - HKLM\..\Run: [WinStart001.EXE] C:\WINDOWS\System\WinStart001.EXE -b

O16 - DPF: {730F2451-A3FE-4A72-938C-FC8A74F15978} - http://www.igetnet.com/downloads/nlmupgradev4.exe

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run|WinStart
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run|WinStart001.EXE

HKEY_LOCAL_MACHINE\SOFTWARE\Classes\BHO.clsUrlSearch
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{676058E4-89BD-11D6-8A8C-0050BA8452C0}
HKEY_CURRENT_USER\Software\VB and VBA Program Settings\Ie Rsp
HKEY_LOCAL_MACHINE\SOFTWARE\CLRSCH

C:\Windows\system\NLNP29.exe.tcf - Adware.IGetNet
C:\Windows\system32\NLNP13.dll - AdWare.IGetNet
C:\Windows\system32\NLNP!3.exe - AdWare.IGetNet
C:\Windows\system32\NLNP131.dll - AdWare.IGetNet
C:\Windows\system\Install_All.DLL - AdWare.IGetNet.b
C:\Windows\system\RSP001.DLL - AdWare.IGetNet
C:\Windows\system\Update_com.DLL - AdWare.IGetNet
C:\Windows\system\BHO001.DLL - AdWare.IGetNet
C:\WINDOWS\System\WinStart001.EXE
c:\Programme\ClearSearch\IE_ClrSch.DLL

weiter The hosts file is modified to redirect the following urls to a predefined ip address:

auto.search.msn.com
search.netscape.com
ieautosearch

INetBar Adware
C:\Dokumente und Einstellungen\User\Eigene Dateien\My eBooks\Neuer Ordner\inetbar15r5.exe

weiter http://www.symantec.com

HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\explorer\Browser Helper Objects\{730F2451-A3FE-4A72-938C-FC8A74F15978}

HKEY_LOCAL_MACHINE/Software/Microsoft/Internet Explorel/ActiveX Compatibility/730f2451-A3FE-4A72-938C-FC8A74F15978

HKEY_CLASSES_ROOT\BHO.clsUrlSearch
HKEY_CLASSES_ROOT\Rsp.BizLgk
HKEY_CLASSES_ROOT\CLSID\{60E78CAC-E9A7-4302-B9EE-8582EDE22FBF}
HKEY_CLASSES_ROOT\CLSID\{D5DE8D20-5BB8-11D1-A1E3-00A0C90F2731}
HKEY_CLASSES_ROOT\CLSID\{730F2451-A3FE-4A72-938C-FC8A74F15978}
HKEY_CLASSES_ROOT\CLSID\{676058E4-89BD-11D6-8A8C-0050BA8452C0}
HKEY_CLASSES_ROOT\Interface\{18333387-5082-4710-94DF-9600CF6B2D5B}
HKEY_CLASSES_ROOT\Interface\{676058E3-89BD-11D6-8A8C-0050BA8452C0}
HKEY_CLASSES_ROOT\Interface\{F94C0089-9394-4E44-B4EA-58DBA1F7B84E}
HKEY_CLASSES_ROOT\Interface\{3c8cde30-d013-4093-b00e-adbc74f33315}
HKEY_CLASSES_ROOT\TypeLib\{676058DB-89BD-11D6-8A8C-0050BA8452C0}
HKEY_CLASSES_ROOT\TypeLib\{974CC25E-D62C-4278-84E6-A806726E37BC}
HKEY_CLASSES_ROOT\TypeLib\{ACBA087F-1547-41DE-8E9E-3F0963CE4BEF}







virus-protect.org
startseite Valid HTML 4.01 Ranking-Hits antispam