|
CWS.Conyc Spyware Information
| Name: |
CWS.Conyc |
| Category: |
Spyware |
| Advice: |
Remove |
| Risk: |
Elevated Risk
Elevated threats are usually threats that fall into the range of adware in which data about a user's habits are tracked and sent back to a server for analysis without your consent or knowledge. |
| Description:
|
CWS.Conyc is a Browser Helper Object (BHO) that contacts a Web site when Internet Explorer is started.
Creates the following registry entries:
HKEY_CURRENT_USERSoftwareMicrosoftInternet ExplorerMain "Enable Browser Extensions" = "yes"
HKEY_CURRENT_USERSoftwareMicrosoftInternet ExplorerMain "Use Search Assistant" = "yes"
HKEY_CURRENT_USERSoftwareMicrosoftInternet ExplorerMain "Use Search Asst" = "no"
HKEY_CURRENT_USERSoftwareMicrosoftInternet ExplorerSearchUrl "(Default)" = "http://www.v73.us"
HKEY_CURRENT_USERSoftwareMicrosoftInternet ExplorerURLSearchHooks "{C7EDAB2E-D7F9-11D8-BA48-C79B0C409D70}"
HKEY_LOCAL_MACHINESOFTWAREMicrosoftInternet ExplorerToolbar "{815A82AE-CDEF-11D8-BA48-A6D245798277}" = "Popup Blocker 17.08.04"
Modifies the following value:
"SearchAssistant" = "http://www.v73.us/search.htm"
in the registry key:
HKEY_LOCAL_MACHINESOFTWAREMicrosoftInternet ExplorerSearch
May create the following file:
%Windir%inet10050services.exe
May create the value:
"xp_system" = "%Windir%inet10050services.exe"
in the registry keys:
HKEY_LOCAL_MACHINESOFTWAREMicrosoftWindowsCurrentVersionRun
HKEY_CURRENT_USERSoftwareMicrosoftWindowsCurrentVersionRun
May create the value:
"run" = "%Windir%inet10050services.exe"
in the registry key:
HKEY_CURRENT_USERSoftwareMicrosoftWindows NTCurrentVersionWindows
Contacts the domain conyc.com to display advertisements when Internet Explorer is started.
|
| Type: |
Spyware - Spyware's primary purpose is to collect demographic and usage information from your computer, usually for advertising purposes. Spyware usually that 'sneaks' onto a system or performs other activities hidden to the user. Spyware programs are usually bundled as a hidden component and downloaded from the Internet. These modules are almost always installed on the system secretively and try to run secretively as well. |
Top Spyware Visited Pages:
IEPlugin - Alias: IMIServer IEPlugin, Webplugin, BHO3Lib, ExplWWW, IExpl, MimarSinan, Win Server, winobject, TrojanDow - 84 visits
webHancer - Alias: Customer Companion, Webhancer Customer Companion, SpeedRank - 53 visits
Spyware.SearchAssistant - Alias: Troj/StartPa-EI - 50 visits
PowerReg Scheduler - 46 visits
007.msnnames - Alias: access.ocx, jokes.ocx, StopLiteCtrl, StopLite, 007installer - 44 visits
Aureate - Alias: Aureate Spy, Radiate - 39 visits
VX2.LocalNRD - Alias: LocalNRD - 38 visits
CWS.Cassandra - 37 visits
C2.Lop - Alias: C2 Media, Lop, LopAdvert, MP3Search, MpAdvert, TrojanClicker.Win32.Rotarran - 35 visits
Stealth Web Page Recorder v. 1.1 - 32 visits
Random Spyware Pages:
C2.Lop - Alias: C2 Media, Lop, LopAdvert, MP3Search, MpAdvert, TrojanClicker.Win32.Rotarran
Banker.TU - Alias: TrojanSpy:Win32/Banker.TU
Unclassified.Trojan.H
CommonSearch VCatch
The Money Toolbar - Alias: Money Maker Toolbar, BestToolBars.Money
CoolWebSearch.rdspclips
CoolWebSearch.WinRes
MediaTickets CDT - Alias: Adware.CDT, CDT, MediaTickets
Spw.GralicWrap
Ramdud.BHO
|