Home
Articles
Spyware Research
Support
Scan Now
Purchase
F.A.Q.
Top 25 Spyware:
Glossary Latest Detections ![]() |
Search Hijacker/P2P/XoloXAlias: XoloX
Description: W32.HLLW.Repsan is a worm that spreads through file-sharing networks. Attempts to spread itself through KaZaA, KaZaA Lite, KaZaA Lite K++, KMD, Morpheus, eDonkey2000, Limewire, Bearshare, Overnet, Gnucleus, Grokster, Shareaza, Tesla, Rapigator, WinMX, Xolox file-sharing networks, as well as ICQ. Threat type: P2P - P2P is any peer-to-peer file swapping program. The following software applications are typical examples: Audiogalaxy, Bearshare, Blubster, E-Mule, Gnucleus, Grokster, Imesh, KaZaa, KaZaa Lite, Limewire, Morpheus, Shareaza, WinMX, Xolox, etc. P2P software may pose security issues because outsiders are granted access to you files. P2P can degrade network performance, consume vast amounts of storage and be bundled with adware and/or spyware programs. Search Hijacker - A Search Hijacker is a software application that takes control of your browser's default search engine. The search results may not necessarily be the best fit as those usually come from paid advertisements, as issued to you by the Hijacker authors. Search hijackers prevent you from changing your browser's default search engine, and they tend to slow down PC performance. Advice: Remove This is a very high risk threat and should be removed immediately as to prevent harm to your computer or your privacy. Detection: SpyNoMore detects Search Hijacker/P2P/XoloX: Yes Threat risk: High Risk Very dangerous malware. Can log user's keyboard activity and take snapshots of the user's screen. Uses stealth installation and removal is very difficult. Category includes spyware programs, adware programs and trojans. Symptoms: Running Process Signatures: N/A File Signatures: %COMMON_PROGRAMS%\xolox\xolox.lnk %COMMON_PROGRAMS%\xolox\uninstall xolox.lnk %DESKTOPDIRECTORY%\xolox.lnk %DESKTOPDIRECTORY%\xolox download folder.lnk %COMMON_PROGRAMS%\xolox\downloads.lnk %STARTUP%\xolox.lnk Registered Dll (Dynamic Link Library) Signatures: N/A Folder Signatures: %PROFILE%\local settings\temp\xolox %PROFILE%\start menu\programs\xolox %PROGRAM_FILES%\xolox Registry Signatures: HKLM\software\microsoft\windows\currentversion\uninstall\xolox HKCU\software\xolox HKCR\typelib\{2850bdc7-2330-4e31-9fa0-88268846539a} HKCR\gnutella HKCR\clsid\{f02c0ae1-d796-42c9-81e1-084d88f79b8e} SpyNoMore Collected Residual File Signatures: N/A
| ||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
|
||||