Reply
Tue 29 Mar, 2005 01:12 pm
Two weeks ago, my PC was hijacked by a powerful spyware.
The culprit assumed the name of "System Soap" that prompted me to subscribe their antispyware products.
Later, I managed to install Lavasoft Adware SE Personal, PC-cillin and Microsoft Antispyware and removed the spywares and reset reset my browser.
---------------------------------------
Spyware Scan Details
Detected Threats
SearchAssistant Spyware more information...
Details: SearchAssistant also known as Search Extender is an Internet Explorer modifier.
Status: Removed
Severe threat - Severe-risk items have an extreme potential for harm, such as a security exploit, and should be removed.
Infected registry keys/values detected
HKEY_LOCAL_MACHINE\Software\microsoft\windows\currentversion\uninstall\SearchAssistant Uninstall
HKEY_LOCAL_MACHINE\Software\microsoft\windows\currentversion\uninstall\SearchAssistant Uninstall DisplayName
Search Assistant Uninstall
HKEY_LOCAL_MACHINE\Software\microsoft\windows\currentversion\uninstall\SearchAssistant Uninstall UninstallString regsvr32 /s /u C:\WINDOWS\System32\cmbh.dll
Possible Browser Hijack Browser Modifier more information...
Details: Possible Browser Hijack redirects Internet Explorer.
Status: Removed
High threat - High-risk items have a large potential for harm, such as loss of computer control, and should be removed unless knowingly installed.
Detected Spyware Cookies
No spyware cookies were found during this scan.
---------------------------------------
I have the following questions:
1) Is "about blank" a browser redirector?
2) Do I need this file / can I delete "se.dll"
"Microsoft AntiSpyware has detected a program trying to add itself to your startup registry. Startup programs are loaded automatically when Windows boots up.
Name: se.dll"
3) "SearchAssistant Spyware - an extreme potential for harm, such as a security exploit"
Does it steal my id, personal data and transmit them to another location/PC ? What are the harms in layman term?
Your comments will be highly appreciated.