| Type |
Caption |
Section |
File name |
Description |
 |
Secret-Crush |
|
start.exe |
Hijacker that may reset your browser's home page and/or search settings to point to undesired sites |
 |
Shell |
|
open32.exe |
Added by the Troj/Small-DL TROJAN which displays a HTML page to lure a user to links. Another file, "open32.conf", may also be found in %System% folder. Read more |
 |
Shell |
|
ray.exe |
Homepage hijacker re-directing browsers to adult content websites |
 |
Shell |
|
Tray.exe |
Homepage hijacker re-directing browsers to adult content websites |
 |
SonudMan |
|
SonudMan.exe |
Added by the Trojan.Startpage.Q browser hijacker. This file hijacks the browser to open www.joyiex.com. Read more |
 |
sp |
|
se.dll,DllInstall |
Added by the Troj/StartPa-FJ TROJAN and might also install another start-page Trojan with the filename "fpid.dll". Read more |
 |
sp |
|
SE.DLL,DllInstall |
Start Page Hijacker. More information can be at this site. For help removing this infection please post a HijackThis log in our HijackThis forum. Read more |
 |
sp |
|
SE.DLL,DllInstall |
Start Page Hijacker. More information can be at this site. For help removing this infection please post a HijackThis log in our HijackThis forum. Read more |
 |
sp |
HKEY_LM\Run |
se.dll,DllInstall |
Added by the Troj/StartPa-FJ TROJAN and might also install another start-page Trojan with the filename "fpid.dll". Read more |
 |
spoolsvu |
|
SPOOLSVU.EXE |
Added by the StartPage.K TROJAN! Read more |
 |
SpyNuker |
|
Spynuker.exe |
A "spyware removal program" by TrekBlue, which is being heavily advertised through junk e-mail from its affiliates and misleading fake-dialogue-box web advertising. This is the same company as E-mail marketers ‘TrekData’ and ‘Blue Haven Media’, who distribute spyware through ActiveX drive-by-download on web pages |
 |
Spyware Nuker Installer |
|
SpywareNukerInstaller.exe |
p align=leftA "spyware removal program" by TrekBlue, which is being heavily advertised through junk e-mail from its affiliates and misleading fake-dialogue-box web advertising. This is the same company as E-mail marketers ‘TrekData’ and ‘Blue Haven Media’, who distribute spyware through ActiveX drive-by-download on web pages |
 |
SpywareGuard |
|
winproc32.exe |
Startpage adware Trojan Read more |
 |
SpywareGuardPlus |
|
winmm64.exe |
StartPage.ht homepage hijacker |
 |
SQConfigChecker |
|
cc.exe |
Xupiter SQWire variant - adware and homepage hijacker. Note - cannot be removed via the Xupiter website in the same way as other Xupiter variants Read more |
 |
SQUpdatesChecker |
|
uc.exe |
Xupiter SQWire variant - adware and homepage hijacker. Note - cannot be removed via the Xupiter website in the same way as other Xupiter variants Read more |
 |
Start |
|
windows.vbs |
Homepage hijacker |
 |
start page |
|
svcnt32.exe |
Homepage hijacker, also detected as Trojan-Downloader.Win32.Delf.ks |
 |
startpage |
|
startpage.exe |
Browser hijacker - redirecting to pages2start.com |
 |
svchost |
|
Rundll16.exe |
Added by the Troj/StartPa-PB TROJAN! Redirecting of browser start & search pages will result. DBG.EXE and RUNDLL.EXE are copied to the Windows folder to initiate the actions of this trojan. Read more |