(U)R0 - HKCUSoftwareMicrosoftInternet ExplorerMain,Start Page = http://bt.yahoo.com
set by user
Windows: ALL; discoverer: nasdaq (Edit)
|
(U)R0 - HKCUSoftwareMicrosoftInternet ExplorerMain,Start Page = http://www.garena.com/
set by user
Windows: ALL; discoverer: nasdaq (Edit)
|
(U)R0 - HKCUSoftwareMicrosoftInternet ExplorerMain,Start Page = http://www.google.dk/ig
set by user
Windows: ALL; discoverer: nasdaq (Edit)
|
(U)R0 - HKCUSoftwareMicrosoftInternet ExplorerMain,Start Page = http://www.itunes.com/
set by user
Windows: ALL; discoverer: nasdaq (Edit)
|
(X)R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page =
Not really malware, just clutter. Fix this to tidy things up a bit.
Fix using: HJT
Windows: ALL; discoverer: Angoid (Edit)
|
(U)R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page = c:Program FilesCommon FilesMicrosoft SharedStationeryBlank.htm
Set by user
Windows: ALL; discoverer: nasdaq (Edit)
|
(X)R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page = C:\WINDOWS\System32\search.html
Set by Troj/LowZone-AE reported by Sophos.
Fix using: HijackThis - Trojan/Virus removal tools
http://www.sophos.com/virusinfo/analyses/trojlowzoneae.html
Windows: ALL; discoverer: nasdaq (Edit)
|
(U)R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page = google.net-studio.org
Set by user
Windows: ALL; discoverer: nasdaq (Edit)
|
(X)R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page = http://81.222.131.49/index.php
Troj/StartPa-GB is a Windows Trojan which alters default Internet Explorer settings.
Fix using: HJT and Virus/trojan removal programs.
http://www.sophos.com/virusinfo/analyses/trojstartpagb.html
Windows: ALL; discoverer: Nasdaq (Edit)
|
(X)R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page = http://angelsfucked.com/se.html
Related to Hotoffers and its variants
Fix using: Check removal procedures at URL
http://spywareinfoforum.com/index.php?act=ST&f=6&t=43476
Windows: ALL; discoverer: nasdaq (Edit)
|
(U)R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page = http://bigpond.com
Set by user
Windows: ALL; discoverer: nasdaq (Edit)
|
(X)R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page = http://spywaresoftstop.com/
Rogue/Suspect software. Aggressive, deceptive advertising
Fix using: HijackThis
http://www.spywarewarrior.com/rogue_anti-spyware.htm
Windows: ALL; discoverer: nasdaq (Edit)
|
(X)R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page = http://www.bestwebslinks.com/
Smitfraud family of trojans
Fix using: See removal instructions at the link below.
http://spywareinfoforum.com/index.php?act=ST&f=6&t=52193
Windows: ALL; discoverer: nasdaq (Edit)
|
(X)R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page = http://www.findyourcouple.com
Related to Hotoffers and its variants
Fix using: Check removal procedures at URL
http://spywareinfoforum.com/index.php?act=ST&f=6&t=43476
Windows: ALL; discoverer: nasdaq (Edit)
|
(U)R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page = http://www.my.att.net
Set by user
Windows: ALL; discoverer: nasdaq (Edit)
|
(U)R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page = http://www.nuevaq.fm
set by user
Windows: ALL; discoverer: nasdaq (Edit)
|
(X)R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page = http://www.oneclicksearches.com/
Indicates the "Smitfraud" infection.
Fix using: See removal instruction at the link below.
http://spywareinfoforum.com/index.php?act=ST&f=6&t=45833&st=30
Windows: ALL; discoverer: nasdaq (Edit)
|
(X)R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page = http://www.qfind.net/
Unknown virus/trojan. Reported by HJTHelper as CWS infection. All logs reviewed on google are deleting this item with success. One reference in the link below.
Fix using: HJT, CWShredder tool.
http://spywareinfoforum.com/index.php?act=ST&f=6&t=46996&hl=qfind.net/
Windows: ALL; discoverer: nasdaq (Edit)
|
(X)R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page = http://www.qfind.net/
Unknown virus/trojan. Reported by HJTHelper as CWS infection. All logs reviewed on google are deleting this item with success. One reference in the link below.
Fix using: HJT, CWShredder tool.
http://spywareinfoforum.com/index.php?act=ST&f=6&t=46996&hl=qfind.net/
Windows: ALL; discoverer: nasdaq (Edit)
|
(X)R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page = http://www.quicknavigate.com/
Smitfraud family of trojans
Fix using: Fix if you have access: http://spywareinfoforum.com/index.php?act=ST&f=6&t=45833&st=15
http://www.sophos.com/virusinfo/analyses/trojpupere.html
Windows: ALL; discoverer: Nasdaq (Edit)
|
(X)R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page = http://www.searchmaid.com/
Searchmaid hijacker
Fix using: HijackThis
Windows: ALL; discoverer: nasdaq (Edit)
|
(X)R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page = http://www.searchzoomer.com
Hotoffers and its variants
Fix using: See fix at the suggested URL
http://spywareinfoforum.com/index.php?act=ST&f=6&t=43476
Windows: ALL; discoverer: nasdaq (Edit)
|
(X)R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page = http://www.searchzoomer.com/
Related to Hotoffers and its variants
Fix using: Check removal procedures at URL
http://spywareinfoforum.com/index.php?act=ST&f=6&t=43476
Windows: ALL; discoverer: nasdaq (Edit)
|
(X)R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page = http://www.security2k.net/
Blocked by the HOSTS file. See URL
Fix using: HijackThis
http://www.mvps.org/winhelp2002/hosts.htm
Windows: ALL; discoverer: nasdaq (Edit)
|
(U)R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page = http://www.sony.com/vaiopeople
Set by user
Windows: ALL; discoverer: nasdaq (Edit)
|