threats return after restarting the system

A

adamivie

i have attempted to remove these programs several times
after restart and scan they r still present on the system
files quarentine but still r present



Spyware Scan Details
Start Date: 3/14/2005 3:53:58 PM
End Date: 3/14/2005 3:56:07 PM
Total Time: 2 mins 9 secs

Detected Threats

WindUpdates Browser Plug-in more information...
Details: WindUpdates downloads additional adware and
displays pop-up advertising.
Status: Ignored
Severe threat - Severe-risk items have an extreme
potential for harm, such as a security exploit, and
should be removed.

Infected files detected
c:\windows\system32\ide21201.vxd


AproposMedia Browser Modifier more information...
Details: AproposMedia is a component of PeopleOnPage,
sometimes found on computers without the commonly visible
portion of the application . AproposMedia displays pop-up
advertisements, and changes browser settings.
Status: Ignored
Severe threat - Severe-risk items have an extreme
potential for harm, such as a security exploit, and
should be removed.

Infected registry keys/values detected
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersi
on\Explorer\Browser Helper Objects\{016235BE-59D4-4CEB-
ADD5-E2378282A1D9}


MoneyTree Dialer more information...
Details: MoneyTree is an ActiveX installer control that
downloads premium-rate dialers, primarily for adult
content sites. On system startup MoneyTree attempts to
connect to an adult content site.
Status: Ignored
Severe threat - Severe-risk items have an extreme
potential for harm, such as a security exploit, and
should be removed.

Infected registry keys/values detected
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersi
on\Explorer\Browser Helper Objects\{00000010-6F7D-442C-
93E3-4A4827C2E4C8}


eXact.BargainBuddy Adware more information...
Details: BargainBuddy is a Browser Helper Object that
watches the pages your browser requests and the terms you
enter into a search engine web form. If a term matches a
preset list of sites or keywords, BargainBuddy will
display an ad.
Status: Ignored
High threat - High-risk items have a large potential for
harm, such as loss of computer control, and should be
removed unless knowingly installed.

Infected registry keys/values detected
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersi
on\Explorer\Browser Helper Objects\{AEECBFDA-12FA-4881-
BDCE-8C3E1CE4B344}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersi
on\Explorer\Browser Helper Objects\{CE188402-6EE7-4022-
8868-AB25173A3E14}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersi
on\Explorer\Browser Helper Objects\{F4E04583-354E-4076-
BE7D-ED6A80FD66DA}


Zango Search Assistant Adware more information...
Details: Zango Search Assistant shows pop-up
advertisements.
Status: Ignored
Moderate threat - Moderate-risk items have some potential
for harm, but may be part of a wanted service. Users may
decide to ignore such programs after review.

Infected registry keys/values detected
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store
Database\Distribution Units\{99410CDE-6F16-42CE-9D49-
3807F78F0287}


Detected Spyware Cookies
No spyware cookies were found during this scan.
 
S

Steve Dodson [MSFT]

I would submit a suspected spyware report to spynet with as much detail as
possible so we can analyze.

--
-steve

Steve Dodson [MSFT]
MCSE, CISSP
PSS Security

--

This posting is provided "AS IS" with no warranties, and confers no rights.
Use of included script samples are subject to the terms specified at
http://www.microsoft.com/info/cpyright.htm

Note: For the benefit of the community-at-large, all responses to this
message are best directed to the newsgroup/thread from which they
originated.
 

Ask a Question

Want to reply to this thread or ask your own question?

You'll need to choose a username for the site, which only take a couple of moments. After that, you can post your question and our members will help you out.

Ask a Question

Top