Home Articles Spyware Research Support Scan Now Purchase F.A.Q.

Adware/BHO/Swizzor.bf

Alias: TrojanDownloader.Win32.Swizzor.bf, Adware-SaveNow, WhenU.SaveNow, Adware/WeatherCast

Description: From the Adware/BHO/Swizzor.bf publisher: 'SaveNow - Billions of monthly advertising opportunities. 9 billion monthly advertising opportunities. Titles can be up to 40 characters, with the description up to 190 characters. You also might want to refer to a rather technical document by N. SaveNow - 9 billion monthly advertising opportunities. Dramatic results for over 200 online advertisers. SaveNow - High-performance online marketing campaigns. Web marketing that works. It's an exercise in outsmarting search engines -- understanding their current 'rules' and providing them with an slimmed-down Web page of exactly what they're looking for. Actually, the number you come up with will be high, since it includes all the advertising expenses necessary to stimulate sales from new and existing customers, and getting that first purchase is the most expensive. SaveNow - Industry-leading clickthrough rates as high as 20%. World-leading online marketing. SaveNow - WhenU's contextual marketing technology is the most robust in the world. Performance-based contextual marketing campaigns. What good will this ever do? Evaluate the graphics on your site. (Nor does he have the ability for superior customer service, but that's another story.)A really scary development to many manufacturers is the growing temptation to sell directly on the Web and by-pass the complex distribution chain they have built over many years. Register with search engines and directories after preparing titles and META description and keyword tags for each webpage.'

Threat type:

Adware - Adware is a software application which displays advertisements on your computer. Advertisements can be displayed through pop-up / pop-under windows, additional bars or toolbars, underlined links or buttons that appear on a computer screen. Adware applications include additional code that delivers the ads. Adware authors earn money when users click on those ads. Occasionally, adware includes code that tracks user's site visits and passes it to third parties without the user's permission or knowledge.

BHO - A Browser Helper Object (BHO) is a software application that runs automatically whenever you start Internet Explorer. Browser Helper Objects are typically installed by other programs such as toolbar accessories and can track internet usage, create popup windows, display additional information on a viewed page and collect information that is transmitted by you over the internet. Malicious software that exploits this technology can replace banner advertisements with other ads, monitor your actions, change your home page, etc.


Advice: Remove This is a very high risk threat and should be removed immediately as to prevent harm to your computer or your privacy.

Detection:
SpyNoMore detects Adware/BHO/Swizzor.bf: Yes

Threat risk: Medium Risk
SpyNoMore AntiSpyware: Remove Swizzor.bf, Swizzor.bf Remover
Potentially dangerous malware. May collect sensitive user information and broadcast data back to a server with "opt-out" permission. Category includes most adware programs.

Symptoms:

Adware/BHO/Swizzor.bf displays commercial advertisements.

Adware/BHO/Swizzor.bf changes browser settings.

Adware/BHO/Swizzor.bf connects itself to the internet.

Adware/BHO/Swizzor.bf hides from the user and stays resident in background.



Adware/BHO/Swizzor.bf Signature Details: The following information includes some of the standard signatures associated with this spyware threat. Please do not attempt to manually remove these items from your computer; Removing these items incorrectly or partially can cause your computer to experience critical errors, prevent your computer from restarting or cause loss of Internet connectivity. Should you be infected with Adware/BHO/Swizzor.bf, you can clean your computer by downloading SpyNoMore now.

Running Process Signatures:
N/A

File Signatures:
%PROFILE%\local settings\temp\czvkvfkc.htm
%PROFILE%\local settings\temp\~dlfntmp9\index.html
%PROFILE%\local settings\temp\temporary internet files\content.ie5\uj8pnhsq\index_ie[1].css
%WINDOWS%\epakucmzh.exe
%PROFILE%\local settings\temp\temporary internet files\content.ie5\7bjxv3tl\adswrapperaim[1].js
%PROFILE%\local settings\temp\~dlfntmp1\index.html
%PROFILE%\local settings\temp\cd.dll
%PROFILE%\locals~1\temp\lub7cqpv.htm
%PROFILE%\local settings\temp\nyk.dll
%PROFILE%\local settings\temp\temporary internet files\content.ie5\7bjxv3tl\fphoverx[1].class
%PROFILE%\local settings\temp\kidcfz.dll
%PROFILE%\local settings\temp\temporary internet files\content.ie5\ehm9otgx\aol[1].htm
%PROFILE%\local settings\temp\temporary directory 2 for types of attachment-delaney's info.zip\notes on art therapy with adolescents.doc
%PROFILE%\local settings\temp\cbza.dll
%PROFILE%\local settings\temp\wtx.dll
%PROFILE%\locals~1\temp\notmljqt.htm
%PROFILE%\local settings\temp\thi6401.tmp\conflict.inf
%PROFILE%\local settings\temp\temporary internet files\content.ie5\ehm9otgx\cnn_allpolitics_dems.rnc[1].htm
%PROFILE%\local settings\temp\~dlfntmp2\index.html
%PROFILE%\local settings\temp\oe8yydvxm.exe
%PROFILE%\local settings\temp\temporary internet files\content.ie5\uj8pnhsq\comicbook[1].css
%PROFILE%\local settings\temp\y3e.dll
%PROFILE%\locals~1\temp\iadhide3.dll
%PROFILE%\local settings\temp\temporary internet files\content.ie5\uj8pnhsq\aol[1].htm
%PROFILE%\locals~1\temp\our36tvb.htm
%PROFILE%\locals~1\temp\kx4ceojq.htm
%PROFILE%\local settings\temp\bu.dll
%PROFILE%\local settings\temp\5tla41db.dll
%PROFILE%\local settings\temp\temporary internet files\content.ie5\uj8pnhsq\frm_readnote[1].js
%PROFILE%\local settings\temp\98n78x.dll
%PROFILE%\local settings\temp\wvzoly.dll
%PROFILE%\local settings\temp\kzcrqcdf.dll
%PROFILE%\local settings\temp\owgpjqxob.dll
%PROFILE%\local settings\temp\temporary internet files\content.ie5\ehm9otgx\keep_alive[1].htm
%PROFILE%\local settings\temp\f8vbin.dll
%PROFILE%\local settings\temp\kdt3.dll
%PROFILE%\local settings\temp\~dlfntmp8\index.html
%PROFILE%\local settings\temp\cj1tj4fwt.dll
%PROFILE%\local settings\temp\c5ry.dll
%PROFILE%\local settings\temp\temporary internet files\content.ie5\7bjxv3tl\frm_previewpane[1].js
%PROFILE%\local settings\temp\jftjjgxw.dll
%PROFILE%\local settings\temp\temporary internet files\content.ie5\ehm9otgx\broadband6[1].css
%PROFILE%\local settings\temp\temporary internet files\content.ie5\7bjxv3tl\stylesheet[1].css
%PROFILE%\local settings\temp\temporary internet files\content.ie5\oh6bkxqf\main[1].css
%PROFILE%\local settings\temp\5nmek0x2.htm
%PROFILE%\local settings\temp\wllpeqe.dll
%PROFILE%\local settings\temp\139b.html
%PROFILE%\local settings\temp\temporary internet files\content.ie5\ohiboluz\desktop.ini
%PROFILE%\local settings\temp\2ms.dll
%PROFILE%\local settings\temp\omu.dll
%PROFILE%\locals~1\temp\rhbo41ms.htm
%PROFILE%\local settings\temp\temporary internet files\content.ie5\7bjxv3tl\antispy_pie_01[1].htm
%PROFILE%\local settings\temp\lhncp3u2v.dll
%PROFILE%\local settings\temp\winupdate17.exe
%PROFILE%\local settings\temp\d2r4q2s.dll
%PROFILE%\local settings\temp\se.exe
%PROFILE%\local settings\temp\~dlfntmp7\index.html
%PROFILE%\local settings\temp\temporary internet files\content.ie5\oh6bkxqf\aol[2].htm
%PROFILE%\local settings\temp\aw2.dll
%PROFILE%\local settings\temp\temporary internet files\content.ie5\oh6bkxqf\track1[1].htm
%PROFILE%\local settings\temp\sta5f0.exe
%PROFILE%\local settings\temp\pp501pao.dll
%PROFILE%\local settings\temp\temporary internet files\content.ie5\ehm9otgx\desktop.ini
%PROFILE%\locals~1\temp\rvyn1n7u.htm
%PROFILE%\local settings\temp\temporary internet files\content.ie5\uj8pnhsq\owastyle[1].css
%PROFILE%\local settings\temp\temporary internet files\content.ie5\7bjxv3tl\av2[1].js
%PROFILE%\locals~1\temp\pf3mc4bk.htm
%PROFILE%\local settings\temp\vru.dll
%PROFILE%\local settings\temp\temporary internet files\content.ie5\uj8pnhsq\horizontal_navbar[1].css
%PROFILE%\local settings\temp\q1mho1rg1.dll
%PROFILE%\local settings\temp\7pkvo3av.htm
%PROFILE%\local settings\temp\xqh.dll
%PROFILE%\local settings\temp\n6oa477t.dll
%PROFILE%\locals~1\temp\qrvdpjgk.htm
%PROFILE%\local settings\temp\temporary internet files\content.ie5\ehm9otgx\keep_alive[2].htm
%PROFILE%\local settings\temp\m9gl.dll
%PROFILE%\local settings\temp\ed3a00g.dll
%PROFILE%\local settings\temp\wv.dll
%PROFILE%\local settings\temp\temporary internet files\content.ie5\uj8pnhsq\dalai_llama[1].js
%PROFILE%\local settings\temp\m5dx7rs0q.dll
%PROFILE%\local settings\temp\temporary internet files\content.ie5\uj8pnhsq\blank[1].htm
%PROFILE%\local settings\temp\temporary internet files\content.ie5\oh6bkxqf\desktop.ini
%PROFILE%\local settings\temp\p6pyiax.dll
%PROFILE%\local settings\temp\temporary internet files\content.ie5\uj8pnhsq\vw_navbar[1].js
%PROFILE%\local settings\temp\kz.dll
%PROFILE%\local settings\temp\msoa15fd.doc
%PROFILE%\local settings\temp\roa8fve.dll
%PROFILE%\desktop\bonzibuddy.lnk
%PROFILE%\local settings\temp\qkwko.dll
%PROFILE%\local settings\temp\gjp8a1eb.htm
%PROFILE%\local settings\temp\vyz.dll
%PROFILE%\local settings\temp\temporary internet files\content.ie5\oh6bkxqf\exitpop[1].htm
%PROFILE%\local settings\temp\giu1v.dll
%PROGRAM_FILES%\broadjump\client foundation\updatestaging\cm216prd.patch.exe
%PROFILE%\local settings\temp\temporary internet files\content.ie5\ehm9otgx\ctrl_view[1].js
%PROFILE%\local settings\temp\wkzd9dv.dll
%PROFILE%\locals~1\temp\t3zjtccy.htm
%PROFILE%\local settings\temp\cqtjeyx.dll
%PROFILE%\local settings\temp\dbh45nm.dll
%PROFILE%\local settings\temp\ccrgdqmj2.dll
%PROFILE%\local settings\temp\temporary internet files\content.ie5\ehm9otgx\land3[1].js
%PROFILE%\local settings\temp\bpj00.dll
%PROFILE%\local settings\temp\msoecc9e.doc
%PROFILE%\local settings\temp\temporary internet files\content.ie5\oh6bkxqf\mcafee[1].css
%PROFILE%\local settings\temp\icd2.tmp\setup.inf
%PROFILE%\local settings\temp\fyagg18bz.dll
%PROFILE%\local settings\temp\np.dll
%PROFILE%\local settings\temp\gj.dll
%PROFILE%\local settings\temp\sboz30w.dll
%PROFILE%\local settings\temp\julfh.dll
%PROFILE%\local settings\temp\t1or3u.dll
%PROFILE%\local settings\temp\193tix.dll
%PROFILE%\locals~1\temp\sepinst.exe
%PROFILE%\local settings\temp\temporary internet files\content.ie5\ehm9otgx\theolympian-widget4[1].js
%PROFILE%\local settings\temp\x62nlx.dll
%PROFILE%\local settings\temp\0l.dll
%PROFILE%\local settings\temp\5vr5fawq.dll
%PROFILE%\local settings\temp\fuaru.dll
%PROFILE%\local settings\temp\bvc.dll
%PROFILE%\local settings\temp\ipxwry.dll
%PROFILE%\local settings\temp\cygj6daf.htm
%PROFILE%\locals~1\temp\ndwnhr6l.htm
%PROFILE%\local settings\temp\temporary internet files\content.ie5\uj8pnhsq\show_ads[2].js
%PROFILE%\local settings\temp\temporary internet files\content.ie5\oh6bkxqf\misc[1].js
%PROFILE%\local settings\temp\sta70.exe
%PROFILE%\local settings\temp\77b.html
%PROFILE%\local settings\temp\exmuj.dll
%PROFILE%\local settings\temp\zroj.dll
%PROFILE%\local settings\temp\temporary internet files\content.ie5\oh6bkxqf\ticker[1].js
%PROFILE%\local settings\temp\gz4qozx.dll
%PROFILE%\local settings\temp\temporary internet files\content.ie5\7bjxv3tl\front[1].htm
%PROFILE%\local settings\temp\temporary internet files\content.ie5\uj8pnhsq\adsend[1].js
%PROFILE%\local settings\temp\dune.dll
%PROFILE%\local settings\temp\fixit.exe
%PROFILE%\local settings\temp\sq188im.dll
%PROFILE%\local settings\temp\temporary internet files\content.ie5\ehm9otgx\track4[1].htm
%PROFILE%\local settings\temp\temporary internet files\content.ie5\gpab8tgn\desktop.ini
%PROFILE%\local settings\temp\temporary internet files\content.ie5\ehm9otgx\style30[1].css
%PROFILE%\local settings\temp\jnyl.dll
%PROFILE%\local settings\temp\temporary internet files\content.ie5\ehm9otgx\stylesheet[1].css
%PROFILE%\local settings\temp\f5psvz.dll
%PROFILE%\local settings\temp\vrzy0vj.dll
%PROFILE%\local settings\temp\i7qjx.dll
%PROFILE%\local settings\temp\temporary internet files\content.ie5\7bjxv3tl\preload[1].htm
%PROFILE%\local settings\temp\b8he8.dll
%PROFILE%\local settings\temp\af74zp5m.dll
%PROFILE%\locals~1\temp\kbcywxrn.htm
%PROFILE%\local settings\temp\wvrm.dll
%PROFILE%\local settings\temp\rhnbu.dll
%PROFILE%\local settings\temp\temporary internet files\content.ie5\op6f0t2j\desktop.ini
%PROFILE%\local settings\temp\zb.dll
%PROFILE%\locals~1\temp\k81n7qhi.htm
%PROFILE%\local settings\temp\5lpvzu07.htm
%PROFILE%\local settings\temp\temporary internet files\content.ie5\oh6bkxqf\omniture[1].js
%PROFILE%\local settings\temp\xkos.dll
%PROFILE%\local settings\temp\temporary internet files\content.ie5\uj8pnhsq\ticker[1].css
%PROFILE%\local settings\temp\temporary internet files\content.ie5\7bjxv3tl\casale-ef-apr04[1].htm
%PROFILE%\local settings\temp\temporary internet files\content.ie5\uj8pnhsq\aol[2].htm
%PROFILE%\local settings\temp\xua.dll
%PROFILE%\local settings\temp\temporary internet files\content.ie5\ehm9otgx\alttxt[1].js
c:\saveinstcm.exe
%PROFILE%\local settings\temp\4yjnjx7op.dll
%PROFILE%\local settings\temp\jy.dll
%PROFILE%\local settings\temp\108b.html
%PROFILE%\local settings\temp\6d2bq.dll
%PROFILE%\local settings\temp\temporary internet files\content.ie5\oh6bkxqf\main[1].htm
%PROFILE%\local settings\temp\vhsk.dll
%PROFILE%\local settings\temp\temporary internet files\content.ie5\oh6bkxqf\ctrl_notify[1].js
%PROFILE%\local settings\temp\temporary internet files\content.ie5\ehm9otgx\owa.seattleu[1].htm
%PROFILE%\local settings\temp\7bk.dll
%PROFILE%\local settings\temp\ds.dll
%PROFILE%\local settings\temp\temporary internet files\content.ie5\7bjxv3tl\desktop.ini
%PROFILE%\local settings\temp\rg4ohwe.dll
%PROFILE%\local settings\temp\hlx77wu.dll
%PROFILE%\local settings\temp\temporary internet files\content.ie5\ehm9otgx\util_forms[1].js
%PROFILE%\local settings\temp\temporary internet files\content.ie5\uj8pnhsq\adswrapper[1].js
%PROFILE%\local settings\temp\2hwct3u.dll
%PROFILE%\local settings\temp\mso6ffdd.doc
%PROFILE%\locals~1\temp\s0uq8sd5.htm
%PROFILE%\local settings\temp\gr7wpxitz.dll
%PROFILE%\local settings\temp\uocjrz.dll
%PROFILE%\local settings\temp\8opuz.dll
%PROFILE%\local settings\temp\temporary internet files\content.ie5\7bjxv3tl\ctrl_tree[1].js
%PROFILE%\local settings\temp\temporary internet files\content.ie5\7bjxv3tl\popup6[1].htm
%PROFILE%\local settings\temp\c32tx.dll
%PROFILE%\local settings\temp\uowsp.dll
%PROFILE%\local settings\temp\yq20.dll
%PROFILE%\local settings\temp\~dlfntmp0\index.html
%PROFILE%\local settings\temp\temporary internet files\content.ie5\ehm9otgx\util_owa[2].js
%PROFILE%\locals~1\temp\qawqijgy.htm
%PROFILE%\local settings\temp\8e9xkrpy.dll
%PROFILE%\local settings\temp\i570ufys.htm
%PROFILE%\local settings\temp\temporary internet files\content.ie5\7bjxv3tl\xuron_l[1].js
%PROFILE%\local settings\temp\ir.dll
%PROFILE%\local settings\temp\lcm.dll
%PROFILE%\local settings\temp\m7.dll
%PROFILE%\local settings\temp\dwhruoy.dll
%PROFILE%\local settings\temp\y1r.dll
%PROFILE%\local settings\temp\unie.tmp.exe
%PROFILE%\local settings\temp\ff5ne1.dll
%PROFILE%\local settings\temp\0ehtyh2d.htm
%PROFILE%\local settings\temp\upd126.exe
%PROFILE%\local settings\temp\aydhfnh3.htm
%PROFILE%\local settings\temp\px.dll
%PROFILE%\local settings\temp\r8zmm3rh.dll
%PROFILE%\local settings\temp\~dlfntmp6\index.html
%PROFILE%\local settings\temp\msodc106.doc
%PROFILE%\locals~1\temp\qe6ucylp.htm
%PROFILE%\local settings\temp\qtcbmid.dll
%PROFILE%\local settings\temp\temporary internet files\content.ie5\uj8pnhsq\mm_menu[1].js
%PROFILE%\local settings\temp\bf.exe
%PROFILE%\local settings\temp\7tfzvhjhj.dll
%PROFILE%\local settings\temp\3gigj.dll
%PROFILE%\local settings\temp\77f.html
%PROFILE%\local settings\temp\w6k.dll
%PROFILE%\local settings\temp\temporary internet files\content.ie5\7bjxv3tl\popup7[1].htm
%PROFILE%\local settings\temp\temporary internet files\content.ie5\oh6bkxqf\aim_uac[1].htm
%PROFILE%\local settings\temp\~dlfntmp3\index.html
%PROFILE%\locals~1\temp\t9w1782b.htm
%PROFILE%\local settings\temp\temporary internet files\content.ie5\ehm9otgx\vw_message[1].js
%PROFILE%\local settings\temp\sgmomc.dll
%PROFILE%\local settings\temp\temporary internet files\content.ie5\ehm9otgx\feb04[1].htm
%PROFILE%\locals~1\temp\msview.inf
%PROFILE%\local settings\temp\3g4rumy.dll
%PROFILE%\local settings\temp\temporary internet files\content.ie5\uj8pnhsq\off_framer[1].htm
%PROFILE%\local settings\temp\mqqk.dll
%PROFILE%\local settings\temp\dbbjb.dll
%PROFILE%\local settings\temp\temporary internet files\content.ie5\oh6bkxqf\util_view[1].js
%PROFILE%\local settings\temp\v.dll
%PROFILE%\local settings\temp\temporary internet files\content.ie5\ehm9otgx\common[1].js
%PROFILE%\local settings\temp\wcbll0.dll
%WINDOWS%\system32\iehelpermiddleman.dll
%PROFILE%\local settings\temp\eantho~1.exe
%PROFILE%\local settings\temp\zo7x7bdv.dll
%PROFILE%\local settings\temp\26cb489e.exe
%PROFILE%\local settings\temp\rssyu0y0.dll
%PROFILE%\local settings\temp\iqfke.dll
%PROFILE%\local settings\temp\temporary internet files\content.ie5\oh6bkxqf\keep_alive[2].htm
%PROFILE%\local settings\temp\bc0sy6wo.dll
%PROFILE%\local settings\temp\temporary internet files\content.ie5\oh6bkxqf\pop[1].htm
%PROFILE%\locals~1\temp\m.dll
%PROFILE%\local settings\temp\temporary internet files\content.ie5\oh6bkxqf\aim_uac[2].htm
%WINDOWS%\temp\saveinstwm.exe
%PROFILE%\local settings\temp\temporary internet files\content.ie5\7bjxv3tl\ctrl_poll[1].js
%PROFILE%\local settings\temp\as.dll
%PROFILE%\local settings\temp\hcdd90rc.htm
%PROFILE%\local settings\temp\2kudarvt.htm
%PROFILE%\local settings\temp\~dlfntmp4\index.html
%PROFILE%\local settings\temp\temporary internet files\content.ie5\7bjxv3tl\ads[2].htm
%PROFILE%\local settings\temp\r2jjoo.dll
%PROFILE%\local settings\temp\zi.dll
%PROFILE%\local settings\temp\l0iv.dll
%PROFILE%\local settings\temp\llbepkj.dll
%PROFILE%\local settings\temp\temporary directory 1 for types of attachment-delaney's info.zip\art therapy recommendations.doc
%PROFILE%\local settings\temp\bkcsq.dll
%PROFILE%\local settings\temp\temporary internet files\content.ie5\ehm9otgx\85620_arc[1].htm
%PROFILE%\local settings\temp\temporary internet files\content.ie5\4lifodef\desktop.ini
%PROFILE%\local settings\temp\temporary internet files\content.ie5\7bjxv3tl\aol[1].htm
%PROFILE%\local settings\temp\aizv8c.dll
%PROFILE%\local settings\temp\no.dll
%PROFILE%\local settings\temp\nxqb.dll
%WINDOWS%\system32\windmy.dll
%PROFILE%\local settings\temp\telfdwv9.dll
%PROFILE%\local settings\temp\pvf.dll
%PROFILE%\local settings\temp\gjh986vky.dll
%PROFILE%\local settings\temp\temporary internet files\content.ie5\oh6bkxqf\fphover[1].class
%PROFILE%\local settings\temp\wwrcy.dll
%PROFILE%\local settings\temp\97.dll
%PROFILE%\local settings\temp\ukds.dll
%PROFILE%\local settings\temp\qcblffnn.dll
%PROFILE%\local settings\temp\temporary internet files\content.ie5\c3cb0h6d\desktop.ini
%PROFILE%\local settings\temp\5bp4qeaz.htm
%PROFILE%\local settings\temp\ni.dll
%PROFILE%\local settings\temp\fn7w9t62.htm
%PROFILE%\local settings\temp\jbzv2z.dll
%PROFILE%\local settings\temp\l2bffxx.dll
%PROFILE%\local settings\temp\qt4xvs.dll
%PROFILE%\local settings\temp\tzh5a5wm.htm
%PROFILE%\locals~1\temp\ptrchtxe.htm
%PROFILE%\local settings\temp\savenowinst.exe
%PROFILE%\local settings\temp\temporary internet files\content.ie5\ehm9otgx\blank[1].htm
%PROFILE%\local settings\temp\ilmdr.dll
%PROFILE%\local settings\temp\f9blssn7.htm
%PROFILE%\locals~1\temp\jg0gf6zw.htm
%PROFILE%\local settings\temp\e.dll
%PROFILE%\locals~1\temp\ihkjdx41.htm
%PROFILE%\local settings\temp\temporary internet files\content.ie5\7bjxv3tl\formie[1].css
%PROFILE%\local settings\temp\ktwjn.dll
%PROFILE%\locals~1\temp\ndr112.tmp.html
%PROFILE%\local settings\temp\xmvadfv.dll
%PROFILE%\local settings\temp\temporary internet files\content.ie5\uj8pnhsq\framer[1].htm
%PROFILE%\local settings\temp\mbxded.dll
%PROFILE%\local settings\temp\nsdtmp09.dll
%WINDOWS%\system32\winnb52.dll
%PROFILE%\local settings\temp\dmqg00afn.dll
%PROFILE%\local settings\temp\57sc.dll
%PROFILE%\local settings\temp\3s.dll
%PROFILE%\local settings\temp\oy.dll
%PROFILE%\local settings\temp\rmu8.dll
%PROFILE%\local settings\temp\108f.html
%PROFILE%\local settings\temp\temporary internet files\content.ie5\7bjxv3tl\framer[1].htm
%PROFILE%\administrator\start menu\programs\whenusearch\whenusearch desktop toolbar.lnk
%PROFILE%\local settings\temp\4q.dll
%PROFILE%\local settings\temp\temporary internet files\content.ie5\ehm9otgx\s_code[1].js
%PROFILE%\local settings\temp\kk2yp62.dll
%PROFILE%\local settings\temp\l0c.dll
%PROFILE%\local settings\temp\139f.html
%PROFILE%\local settings\temp\temporary internet files\content.ie5\7bjxv3tl\adspopup2[1].js
%PROFILE%\local settings\temp\temporary internet files\content.ie5\7bjxv3tl\aol[2].htm
%PROFILE%\local settings\temp\icd1.tmp\clocksyncinst.inf
%PROFILE%\local settings\temp\nqnx9nu.dll
%PROFILE%\local settings\temp\qaek.dll
%PROFILE%\local settings\temp\temporary internet files\content.ie5\uj8pnhsq\040804dshs3[2].htm
%WINDOWS%\lastgood\system32\msvcp50.dll
%PROFILE%\local settings\temp\temporary internet files\content.ie5\uj8pnhsq\aimtoday[1].htm
%PROFILE%\local settings\temp\saveinstwm.exe
%PROFILE%\local settings\temp\ayjurejx.dll
%PROFILE%\local settings\temp\mso5f90b.doc
%PROFILE%\locals~1\temp\privacyurl.exe
%PROFILE%\local settings\temp\y5llkd8.dll
%PROFILE%\local settings\temp\temporary internet files\content.ie5\uj8pnhsq\util_recipients[1].js
%PROFILE%\local settings\temp\pobm2.dll
%PROFILE%\local settings\temp\0jt87pl3.dll
%PROFILE%\local settings\temp\wnust.dll
%PROFILE%\local settings\temp\temporary internet files\content.ie5\7bjxv3tl\framer[2].htm
%PROFILE%\local settings\temp\temporary internet files\content.ie5\uj8pnhsq\video_donovan_04_001[1].htm
%PROFILE%\local settings\temp\temporary internet files\content.ie5\glyzkter\desktop.ini
%PROFILE%\local settings\temp\fuc09vc.dll
%PROFILE%\locals~1\temp\rt3e9jyf.htm
%PROFILE%\local settings\temp\xepy2w.dll
%PROFILE%\local settings\temp\icd1.tmp\saveinstcm.exe
%PROFILE%\local settings\temp\z0mja7i84.dll
%PROFILE%\local settings\temp\voxjsh.dll
%PROFILE%\local settings\temp\mhzi2sa.dll
%PROFILE%\local settings\temp\temporary internet files\content.ie5\7bjxv3tl\ads[1].htm
%PROFILE%\local settings\temp\ujlexzk.dll
%PROFILE%\locals~1\temp\sentry.inf
%PROFILE%\locals~1\temp\oi.exe
%PROFILE%\locals~1\temp\ougz2u1j.htm
%PROFILE%\local settings\temp\temporary internet files\content.ie5\oh6bkxqf\ctrl_reminder[1].js
%PROFILE%\local settings\temp\temporary internet files\content.ie5\7bjxv3tl\olympiansearch-atomz[1].js
%PROFILE%\local settings\temp\temporary internet files\content.ie5\ovafk967\desktop.ini
%PROFILE%\local settings\temp\temporary internet files\content.ie5\ehm9otgx\zipcode[2].htm
%PROFILE%\local settings\temp\7ibnw.dll
%PROFILE%\local settings\temp\qvpjfoevy.dll
%PROFILE%\local settings\temp\z2.dll
%PROFILE%\local settings\temp\asvzm.dll
%PROFILE%\local settings\temp\temporary internet files\content.ie5\ehm9otgx\index[1].html
%PROFILE%\local settings\temp\1.dll
%PROFILE%\local settings\temp\z.dll
%PROFILE%\local settings\temp\temporary internet files\content.ie5\oh6bkxqf\vpinet[1].css
%PROFILE%\local settings\temp\uc88.dll
%PROFILE%\local settings\temp\zxy82p.dll
%PROFILE%\local settings\temp\temporary internet files\content.ie5\7bjxv3tl\index[1].htm
%PROFILE%\local settings\temp\ms72xf.dll
%PROFILE%\local settings\temp\e0ipbie7.htm
%PROFILE%\local settings\temp\temporary internet files\content.ie5\oh6bkxqf\verbnow[1].htm
%PROFILE%\local settings\temp\temporary internet files\content.ie5\uj8pnhsq\desktop.ini
%PROFILE%\local settings\temp\7e.dll
%PROFILE%\local settings\temp\~dlfntmp5\index.html
%PROFILE%\local settings\temp\temporary internet files\content.ie5\ehm9otgx\hat100[1].js
%PROFILE%\local settings\temp\temporary internet files\content.ie5\7bjxv3tl\owacolors[1].css
%PROFILE%\desktop\finish installing....lnk
%PROFILE%\local settings\temp\qt.dll
%PROFILE%\local settings\temp\njh96v.dll
%PROFILE%\local settings\temp\eggc.dll
%PROFILE%\local settings\temp\vzhrpg8b.dll
%PROFILE%\local settings\temp\kvp6.dll
%PROFILE%\local settings\temp\n9zyim.dll
%PROFILE%\local settings\temp\temporary internet files\content.ie5\oh6bkxqf\itms[1].js
%PROFILE%\local settings\temp\temporary internet files\content.ie5\ehm9otgx\main[1].js
%PROFILE%\local settings\temp\iueal.dll
%PROFILE%\local settings\temp\ags.dll
%PROFILE%\local settings\temp\or2qc1wzm.dll
%PROFILE%\local settings\temp\rsyom2jq8.dll
%PROFILE%\locals~1\temp\sentry.ini
%PROFILE%\local settings\temp\temporary internet files\content.ie5\7bjxv3tl\clips[1].htm
%PROFILE%\local settings\temp\temporary internet files\content.ie5\7bjxv3tl\aaform[2].htm
%PROFILE%\local settings\temp\temporary internet files\content.ie5\7bjxv3tl\search0211[1].css
%PROFILE%\local settings\temp\p.dll
%PROFILE%\local settings\temp\u3rfgryzl.dll
%PROFILE%\local settings\temp\temporary internet files\content.ie5\oh6bkxqf\aol[1].htm
%PROFILE%\local settings\temp\we.dll
%PROFILE%\local settings\temp\temporary internet files\content.ie5\uj8pnhsq\index-data[1].html
%PROFILE%\local settings\temp\temporary internet files\content.ie5\ehm9otgx\util_buttons[1].js
%PROFILE%\local settings\temp\temporary internet files\content.ie5\oh6bkxqf\aim_uac[3].htm
%PROFILE%\local settings\temp\rn1f.htm
%PROFILE%\local settings\temp\temporary internet files\content.ie5\4bk5wz2f\desktop.ini
%PROFILE%\local settings\temp\8z8b.dll
%PROFILE%\local settings\temp\lj.dll
%PROFILE%\local settings\temp\nea0wp.dll
%PROFILE%\local settings\temp\temporary internet files\content.ie5\oh6bkxqf\keep_alive[1].htm
%PROFILE%\local settings\temp\temporary internet files\content.ie5\oh6bkxqf\welcome[2].htm
%PROFILE%\local settings\temp\q.dll
%PROFILE%\local settings\temp\lb3d.dll
%PROFILE%\local settings\temp\temporary internet files\content.ie5\ehm9otgx\warwithiraq_350x350_2[1].htm
%PROFILE%\local settings\temp\ae.dll
%PROFILE%\local settings\temp\0x6numrs.dll
%PROFILE%\local settings\temp\wode.dll


Registered Dll (Dynamic Link Library) Signatures:
N/A

Folder Signatures:
%PROGRAM_FILES%\savenow
%PROFILE%\start menu\programs\whenusearch
%DESKTOPDIRECTORY%\sportsinteraction.com.url

Registry Signatures:
HKLM\software\whenu
HKLM\software\microsoft\windows\currentversion\moduleusage\c:/winnt/downloaded program files/sndbmark.dll
HKCR\acm.acmfactory.1
HKLM\software\classes\interface\{c285d18d-43a2-4aef-83fb-bf280e660a97}
HKCR\appid\{127df9b4-d75d-44a6-af78-8c3a8ceb03db}
HKCR\clsid\{e2f2b9d0-96b9-4b25-b90c-636ecb207d18}
HKCR\interface\{72a836d1-bc00-43c0-a941-17960e4fb842}
HKLM\software\classes\runmsc.loader\curver
HKCR\clsid\{c285d18d-43a2-4aef-83fb-bf280e660a97}
HKLM\software\classes\runmsc.loader.1\clsid
HKCR\clsid\{fee7fd53-3356-4d4d-8978-2c4ae3a7e109}
HKCR\appid\acm.dll
HKLM\software\classes\runmsc.loader\clsid
HKLM\software\microsoft\windows\currentversion\uninstall\gdivx
HKCR\clsid\{a9aae1ab-9688-42c5-86f5-c12f6b9015ad}
HKCR\typelib\{fc327b3f-377b-4cb7-8b61-27cd69816bc3}
HKLM\software\microsoft\windows\currentversion\explorer\browser helper objects\{9a9c9b69-f908-4aab-8d0c-10ea8997f37e}
HKLM\software\classes\clsid\{9f95f736-0f62-4214-a4b4-caa6738d4c07}
HKU\.default\software\whenu
HKCR\acm.acmfactory
HKLM\software\microsoft\windows\currentversion\uninstall\savenow
HKCR\interface\{572fb162-c0ba-4edf-8cff-e3846153b9b0}
HKCU\software\whenu
HKCR\typelib\{e2f2b9d0-96b9-4b25-b90c-636ecb207d18}
HKCR\interface\{43382522-a846-46f4-ac57-1f71ae6e1086}


SpyNoMore Collected Residual File Signatures:
N/A


See Also:
Hijacker/ISTbar.AUpdate
Hijacker/ISTbar.MSCache
Hijacker/Toolbar/Search Hijacker/ISTbar.XXXToolbar
Adware/Spyware/Hijacker/BDHelper
Backdoor/Hacker Tool/DskLite.b
RAT/Arctic
Worm/RAT/Downloader/Ashley
Hacker Tool/Ass Sniffer
RAT/Mini Asylum
RAT/Web Asylum

Spyware Removal Home | Support | F.A.Q. | Contact Us | Spyware Removal Database | Privacy Policy | Site Map
Copyright © 2005-2008 Illysoft LLC