Home Articles Spyware Research Support Scan Now Purchase F.A.Q.

Trojan/Hijacker/Myss

Alias: Win32.Myss, CWS.Svchost32, Trj/Tofger.A

Description: Trojan/Hijacker/Myss is the most widely known and the most annoying browser hijacker. It distributes itself by exploiting security holes in older or unpatched version of Microsoft Internet Explorer. Trojan/Hijacker/Myss has many variations, each of them with its own performance and actions.

Threat type:

Hijacker - A Hijacker is a software application that takes control of your browser's settings. Usually it changes your home page and redirects it to some unknown site or modifies your search settings. It prevents you from changing back your browser's settings. An infected browser usually operates much slower.

Trojan - A Trojans or Trojan Horse is any programs that installs itself secretly, quite often with sinister intent. Once installed, the trojan author (hacker) can gain complete control of the infected PC. Trojans are usually designed to steal sensitive information and/or destroy the system. Trojans can be distributed as unsolicited email attachments, or bundled with freeware and shareware programs.


Advice: Remove This is a very high risk threat and should be removed immediately as to prevent harm to your computer or your privacy.

Detection:
SpyNoMore detects Trojan/Hijacker/Myss: Yes

Threat risk: Very High Risk
SpyNoMore AntiSpyware: Remove Myss, Myss Remover
Extremely dangerous malware. Uses stealth installation, randomly named entries and has the capability to self update or resurrect after incomplete removal. Almost impossible to remove manually. Category mostly consists of trojans and spyware.

Symptoms:

Trojan/Hijacker/Myss protects itself from security software.

Trojan/Hijacker/Myss hides from the user and stays resident in background.

Trojan/Hijacker/Myss displays commercial advertisements.

Trojan/Hijacker/Myss changes browser settings.

Trojan/Hijacker/Myss connects itself to the internet.

Trojan/Hijacker/Myss may install other software.



Trojan/Hijacker/Myss Signature Details: The following information includes some of the standard signatures associated with this spyware threat. Please do not attempt to manually remove these items from your computer; Removing these items incorrectly or partially can cause your computer to experience critical errors, prevent your computer from restarting or cause loss of Internet connectivity. Should you be infected with Trojan/Hijacker/Myss, you can clean your computer by downloading SpyNoMore now.

Running Process Signatures:
N/A

File Signatures:
%WINDOWS%\system\svchost32.exe
%WINDOWS%\system32\svchost32.exe

Registered Dll (Dynamic Link Library) Signatures:
N/A

Folder Signatures:
N/A

Registry Signatures:
HKLM\software\microsoft\windows\currentversion\uninstall\internet connection update and homep kb234087
HKCU\software\microsoft\internet explorer\extensions\{3a944ba4-1ce6-43ac-b292-f74f8be58da7}
HKCR\interface\{c7edab2d-d7f9-11d8-ba48-c79b0c409d70}
HKLM\software\microsoft\internet explorer\extensions\{3a944ba4-1ce6-43ac-b292-f74f8be58da7}
HKCR\clsid\{145e6fb1-1256-44ed-a336-8bba43373be6}
HKCR\serch_hook.transurl.1
HKCR\clsid\{1d27210e-2da2-41e2-a103-b5fd9d6a798b}
HKCR\clsid\{c7edab2e-d7f9-11d8-ba48-c79b0c409d70}
HKCR\typelib\{c7edab21-d7f9-11d8-ba48-c79b0c409d70}
HKCR\clsid\{3a944ba4-1ce6-43ac-b292-f74f8be58da7}
HKCR\serch_hook.transurl
HKCR\clsid\{b599c57e-113a-4488-a5e9-bc552c4f1152}
HKCR\clsid\{12345678-0000-0010-8000-00aaff6d2ea4}


SpyNoMore Collected Residual File Signatures:
N/A


See Also:
Trojan/Hijacker/Homepage Hijacker/StartPage.y
Hijacker/CWS.OSLogo
Hijacker/Homepage Hijacker/Startpage.BC
Hijacker/CWS.Vrape
Hijacker/CWS.OEMSysPNP
Hijacker/CWS.DNSRelay
Hijacker/CWS.MSInfo
Hijacker/CWS.Ctfmon32
Hijacker/CWS.TapiCFG
Trojan/Backdoor/Homepage Hijacker/Sinit.c

Spyware Removal Home | Support | F.A.Q. | Contact Us | Spyware Removal Database | Privacy Policy | Site Map
Copyright © 2005-2008 Illysoft LLC