Manic Automatic Searches: 123Mania.MatrixSearch

123Mania.MatrixSearch is a recipe for a browser crashing.  It has one advertising program that runs at boot up, another that’s a search hijacker, and another that is a dropper program.  It opens multiple windows, which could lead to a browser crash.  These windows open to its home page or other mirror sites.  It targets Internet Explorer.  It is particularly hard to kill for some antispyware programs, since it has a set of “regeneration” registry values. It has spyware capabilities, so your privacy is at risk.  It can also update itself and download other software.

It is highly recommended that you remove 123Mania.MatrixSearch.  It poses a threat to your computer’s stability, privacy and performance.  SpyZooka is the best program available to remove 123Mania.MatrixSearch.

Associated Files:

GIDCAI32.dll
SIPSPI32.dll
LoadSIPS
Mshtmpre.dll
msapasrc.dll
MSAMAIL.dll
Downloaded Program Files\msapasrc.inf

Registry Info:

622CC208-B014-4FE0-801B-874A5E5E403A
9C5B2F29-1F46-4639-A6B4-828942301D3E
Software\Microsoft\Internet Explorer\URLSearchHooks\15651C7C-E812-44a2-A9AC-B467A2233E7D
AutoSearch1.BHOsrc
AutoSearch1.BHOsrc.1
AutoSearch1.SrchHook
AutoSearch1.SrchHook.1
Bho1.html
Bho1.html.1
15651C7C-E812-44a2-A9AC-B467A2233E7D
16F6A635-09F8-44E6-953E-81D037647255
34DCDBDB-60EF-4281-92C6-68C299AAB8E5
FC02833E-9FDE-4862-974F-828887716A28
B8F9DD56-4FFA-47B0-B9D7-42F45A752F4E
E9A45914-275E-4866-BB75-5D65CBC3F311
Microsoft\Code Store Database\Distribution Units\15651C7C-E812-44A2-A9AC-B467A2233E7D
Microsoft\Code Store Database\Distribution Units\9C5B2F29-1F46-4639-A6B4-828942301D3E
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion
\Explorer\Browser Helper Objects\{D879A0F1-2B3B-4409-8879-FAD6E49E1EA9}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion
\Explorer\Browser Helper Objects\{9C5B2F29-1F46-4639-A6B4-828942301D3E}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion
\Explorer\Browser Helper Objects\{622CC208-B014-4FE0-801B-874A5E5E403A}

Adds the value:

“LoadHTML” = “rundll32.exe c:\windows\system32\regsvr32.exe,MShtmpre”

to the registry subkey:

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run

Adds the following values

“html_unresident” = “res://C:\WINDOWS\System32\SIPSPI32.dll/Desinstala.htm”
“html_stopengine” = “res://C:\WINDOWS\System32\SIPSPI32.dll/Desactiva.htm”
“html_gotowork” = “res://C:\WINDOWS\System32\SIPSPI32.dll/Activa.htm”
“html_onlyone” = “res://C:\WINDOWS\System32\SIPSPI32.dll/p1.htm”
“html_reconfig3” = “res://C:\WINDOWS\System32\SIPSPI32.dll/p3.htm”
“html_reconfig5” = “res://C:\WINDOWS\System32\SIPSPI32.dll/p5.htm”
“html_reconfig9” = “res://C:\WINDOWS\System32\SIPSPI32.dll/p9.htm”

to the registry subkey:

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\AboutURLs

Adds the values:

“ppcimdnnnjbeahepfabjipfginloedkg cfcaak”
“ppcimdnnnjbeahepfabjipfginloedkg enodaj”
“goicfboogidikkejccmclpieicihhlpo ejfebp”
“goicfboogidikkejccmclpieicihhlpo imfado”
“goicfboogidikkejccmclpieicihhlpo igcdca”

to the registry subkey:

HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\WinTrust
\Trust Providers\Software Publishing\Trust Database\0

Download Free Scan

Leave a Reply

Your email address will not be published. Required fields are marked *

Products

Contact

css.php