Home Articles Spyware Research Support Scan Now Purchase F.A.Q.

Hijacker/FreeScratchCards

Alias: FreeScratchCards

Description: A software that resets your browser's settings to point to other sites. Hijacks may reroute your info and address requests through an unseen site, capturing that info. In such hijacks, your browser may behave normally, but be slower.

Threat type:

Hijacker - A Hijacker is a software application that takes control of your browser's settings. Usually it changes your home page and redirects it to some unknown site or modifies your search settings. It prevents you from changing back your browser's settings. An infected browser usually operates much slower.


Advice: Remove This is a very high risk threat and should be removed immediately as to prevent harm to your computer or your privacy.

Detection:
SpyNoMore detects Hijacker/FreeScratchCards: Yes

Threat risk: High Risk
SpyNoMore AntiSpyware: Remove FreeScratchCards, FreeScratchCards Remover
Very dangerous malware. Can log user's keyboard activity and take snapshots of the user's screen. Uses stealth installation and removal is very difficult. Category includes spyware programs, adware programs and trojans.

Symptoms:

Hijacker/FreeScratchCards Signature Details: The following information includes some of the standard signatures associated with this spyware threat. Please do not attempt to manually remove these items from your computer; Removing these items incorrectly or partially can cause your computer to experience critical errors, prevent your computer from restarting or cause loss of Internet connectivity. Should you be infected with Hijacker/FreeScratchCards, you can clean your computer by downloading SpyNoMore now.

Running Process Signatures:
N/A

File Signatures:
%WINDOWS%\system32\idbrilbs.exe
%WINDOWS%\temporary internet files\content.ie5\0oytyzps\loader[1].exe
%WINDOWS%\system32\fsc.ini
%WINDOWS%\system\tsdezest.exe
%WINDOWS%\system\haywuywl.exe
%WINDOWS%\system\haocside.dll
%WINDOWS%\system\fsc.ini
%WINDOWS%\system\hicvblgb.exe
%WINDOWS%\downloaded program files\install.exe
%WINDOWS%\system32\inrvvmil.exe
%WINDOWS%\system32\iniauvpe.dll
%WINDOWS%\system32\igpgtxbp.exe
%WINDOWS%\system\haocside.exe


Registered Dll (Dynamic Link Library) Signatures:
N/A

Folder Signatures:
N/A

Registry Signatures:
HKCR\clsid\{ed3adb6e-5aa9-41b0-9ddc-6f31a34552be}
HKLM\software\microsoft\code store database\distribution units\{ed3adb6e-5aa9-41b0-9ddc-6f31a34552be}

SpyNoMore Collected Residual File Signatures:
N/A


See Also:
Dialer/XLoader
Dialer/DialerActiveX
Adware/BHO/Hijacker/I-Lookup
Dialer/SexoBFAX
Dialer/Adultoweb
Dialer/MSConnect
Dialer/IEDial
BHO/Hijacker/MyPageFinder
Adware/ShopAtHomeSelect
BHO/TSADBOT

Spyware Removal Home | Support | F.A.Q. | Contact Us | Spyware Removal Database | Privacy Policy | Site Map
Copyright © 2005-2008 Illysoft LLC