Home Articles Spyware Research Support Scan Now Purchase F.A.Q.

Homepage Hijacker/PassThisOn

Alias: PassThisOn

Description: Formerly, a hijacker distributed via SPAM that encouraged visits to a web site, where machines with low security settings would experience a drive-by install. A visit to http://www.default-homepage-network.com/ or http://www.passthison.com/ shows this message: 'Due to new laws being enacted and controversy surrounding our business model, we have voluntarily decided to implement the cease of all current business practices by the end of June 2004.' passthison.com is now maintained by SmartBot.Net, Inc. - ZERO TOLERANCE SPAM POLICY! 3 COBBLESTONE CT RICHBORO, PA 18954-1374 US 215-953-7291 fax: 215-942-4338

Threat type:

Homepage Hijacker - A Homepage Hijacker is a software application that takes control over your browser's settings. Usually it changes your home page and redirects it to some other site or modifies your search settings. It prevents you to change browser's settings. In such hijacks, your browser may operate normally, but be much slower.


Advice: Remove This is a very high risk threat and should be removed immediately as to prevent harm to your computer or your privacy.

Detection:
SpyNoMore detects Homepage Hijacker/PassThisOn: Yes

Threat risk: High Risk
SpyNoMore AntiSpyware: Remove PassThisOn, PassThisOn Remover
Very dangerous malware. Can log user's keyboard activity and take snapshots of the user's screen. Uses stealth installation and removal is very difficult. Category includes spyware programs, adware programs and trojans.

Symptoms:

Homepage Hijacker/PassThisOn Signature Details: The following information includes some of the standard signatures associated with this spyware threat. Please do not attempt to manually remove these items from your computer; Removing these items incorrectly or partially can cause your computer to experience critical errors, prevent your computer from restarting or cause loss of Internet connectivity. Should you be infected with Homepage Hijacker/PassThisOn, you can clean your computer by downloading SpyNoMore now.

Running Process Signatures:
N/A

File Signatures:
%PROFILE%\administrator\my documents\spydeleter-setup.exe
%DESKTOPDIRECTORY%\spydeleter v2.0.lnk
%STARTUP%\reg.vbs
%STARTUP%\reg.hta
%STARTUP%\reg2.hta

Registered Dll (Dynamic Link Library) Signatures:
N/A

Folder Signatures:
%COMMON_PROGRAMS%\spydeleter v2.0
%PROGRAM_FILES%\spydeleter

Registry Signatures:
N/A

SpyNoMore Collected Residual File Signatures:
N/A


See Also:
Hijacker/Actual Spy
Spyware/All-In-One Spy
Hacker Tool/AMServer
Exploit/Am
Flooder/ArgoEyesV17
Dropper/HLLO.Indc.34078
Trojan/Backdoor/Hacker Tool/Ducracker
Backdoor/IRC.Djaa
Dropper/TrojanDropper.VBS.Inor.ax
Backdoor/Unexplained

Spyware Removal Home | Support | F.A.Q. | Contact Us | Spyware Removal Database | Privacy Policy | Site Map
Copyright © 2005-2008 Illysoft LLC