Counterspy
Spyware Scan Details
Start Date: 05.07.2006 23:08:04
End Date: 06.07.2006 00:09:08
Total Time: 1 hrs 1 mins 4 secs
Detected spyware
AntiLeech Plugin Adware more information...
Details: Plugin is an Ad-Ware software which enables the broadcasting of advertisements, and execution of e-commerce and other internet related services on the user-interface of the software.
Status: Deleted
Infected files detected
c:\programme\anti-leech\alie_1.0.1.9\al2np.dll
c:\programme\anti-leech\alie_1.0.1.9\alhlp.exe
c:\programme\anti-leech\alie_1.0.1.9\alie.dll
c:\programme\anti-leech\alie_1.0.1.9\alie.inf
c:\programme\anti-leech\alie_1.0.1.9\iesetup2.exe
c:\programme\anti-leech\alie_1.0.2.2\al2np.dll
c:\programme\anti-leech\alie_1.0.2.2\alhlp.exe
c:\programme\anti-leech\alie_1.0.2.2\alie.dll
c:\programme\anti-leech\alie_1.0.2.2\alie.inf
c:\programme\anti-leech\alie_1.0.2.2\iesetup2.exe
c:\programme\anti-leech\alnn\al2np.dll
c:\programme\anti-leech\alnn\alhlp.exe
c:\programme\anti-leech\alnn\npalnn.dll
c:\programme\anti-leech\alnn\setup2.exe
C:\Programme\mozilla\plugins\al2np.dll
C:\Programme\mozilla\plugins\alhlp.exe
C:\Programme\mozilla\plugins\ALIE_1.0.1.9\al2np.dll
C:\Programme\mozilla\plugins\ALIE_1.0.1.9\alhlp.exe
Infected registry entries detected
HKEY_CURRENT_USER\Software\Anti-Leech\Anti-Leech Plugin
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AntiLeech.ALIE.1
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AntiLeech.ALIE.1\CLSID {056738EE-E15C-11D6-B876-0050BF5D85C7}
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AntiLeech.ALIE.1 Anti-Leech Plug-in
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AntiLeech.ALIE
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AntiLeech.ALIE\CLSID {056738EE-E15C-11D6-B876-0050BF5D85C7}
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AntiLeech.ALIE\CurVer AntiLeech.ALIE.1
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AntiLeech.ALIE Anti-Leech Plug-in
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{056738EE-E15C-11D6-B876-0050BF5D85C7}
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{056738EE-E15C-11D6-B876-0050BF5D85C7}\InprocServer32 C:\PROGRA~1\ANTI-L~1\ALIE_1~1.2\alie.dll
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{056738EE-E15C-11D6-B876-0050BF5D85C7}\InprocServer32 ThreadingModel Apartment
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{056738EE-E15C-11D6-B876-0050BF5D85C7}\ProgID AntiLeech.ALIE.1
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{056738EE-E15C-11D6-B876-0050BF5D85C7}\TypeLib {056738E1-E15C-11D6-B876-0050BF5D85C7}
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{056738EE-E15C-11D6-B876-0050BF5D85C7}\VersionIndependentProgID AntiLeech.ALIE
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{056738EE-E15C-11D6-B876-0050BF5D85C7} Anti-Leech Plug-in
HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@anti-leech.com/Anti-Leech Plugin,version=1.0.1.5\MimeTypes\application/x-al-package
HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@anti-leech.com/Anti-Leech Plugin,version=1.0.1.5\MimeTypes\application/x-al-package Description Anti-Leech Package
HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@anti-leech.com/Anti-Leech Plugin,version=1.0.1.5\MimeTypes\application/x-al-package Suffixes alp
HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@anti-leech.com/Anti-Leech Plugin,version=1.0.1.5\Suffixes
HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@anti-leech.com/Anti-Leech Plugin,version=1.0.1.5
HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@anti-leech.com/Anti-Leech Plugin,version=1.0.1.5\MimeTypes\application/x-al-package Description Anti-Leech Package
HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@anti-leech.com/Anti-Leech Plugin,version=1.0.1.5\MimeTypes\application/x-al-package Suffixes alp
HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@anti-leech.com/Anti-Leech Plugin,version=1.0.1.5 Path C:\Dokumente und Einstellungen\StephanWensel\Desktop\Stephan\ALNN\npalnn.dll
HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@anti-leech.com/Anti-Leech Plugin,version=1.0.1.5 Description Anti-Leech Plugin for Netscape, Mozilla, Opera
HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@anti-leech.com/Anti-Leech Plugin,version=1.0.1.5 Version 1.0.1.5
HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@anti-leech.com/Anti-Leech Plugin,version=1.0.1.5 Vendor Anti-Leech
HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@anti-leech.com/Anti-Leech Plugin,version=1.0.1.5 ProductName Anti-Leech Plugin
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Anti-Leech ALIE
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Anti-Leech ALIE DisplayName Anti-Leech Plugin for Internet Explorer
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Anti-Leech ALIE UninstallString C:\Programme\Anti-Leech\ALIE_1.0.2.2\iesetup2.exe uninstall
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Anti-Leech ALNN
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Anti-Leech ALNN DisplayName Anti-Leech Plugin for Netscape, Mozilla, Opera
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Anti-Leech ALNN UninstallString C:\Programme\Anti-Leech\ALNN\setup2.exe -u
NetPumper Adware Bundler more information...
Details: Bundles with a number of adware components such as cydoor, Save!, ClockSync, and WhenU Toolbar.
Status: Ignored
Infected files detected
c:\dokumente und einstellungen\all users\startmenü\programme\netpumper\netpumper help.lnk
c:\dokumente und einstellungen\all users\startmenü\programme\netpumper\netpumper.lnk
c:\dokumente und einstellungen\all users\startmenü\programme\netpumper\readme.lnk
c:\dokumente und einstellungen\all users\startmenü\programme\netpumper\shutdown netpumper.lnk
c:\dokumente und einstellungen\all users\startmenü\programme\netpumper\uninstall netpumper.lnk
c:\dokumente und einstellungen\all users\startmenü\programme\netpumper\anti-leech\install plugin for ms internet explorer.lnk
c:\dokumente und einstellungen\all users\startmenü\programme\netpumper\anti-leech\install plugin for netscape, mozilla, opera.lnk
c:\dokumente und einstellungen\all users\startmenü\programme\netpumper\anti-leech\license.lnk
c:\programme\netpumper\netpumper.exe
c:\programme\netpumper\npcdl.dll
d:\programme\netpumper\netpumpernnproxy.dll
Infected registry entries detected
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\NetPumperNNProxy.NetscapeInterface
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\NetPumperNNProxy.NetscapeInterface\CLSID {E19B133D-184E-4BBA-8A70-38489C9DD31B}
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\NetPumperNNProxy.NetscapeInterface NetscapeInterface Object
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\MIME\Database\Content Type\application/x-netpumper-detector
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\MIME\Database\Content Type\application/x-netpumper-detector Extension .xnpd
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\NetPumper.AddUrl
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\NetPumper.AddUrl\CLSID {1AA406AB-F581-42AB-B4D1-31D2E13819EF}
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\NetPumper.AddUrl AddUrl Object
HKEY_LOCAL_MACHINE\SOFTWARE\NetPumper
HKEY_LOCAL_MACHINE\SOFTWARE\NetPumper\Affiliated\free state 1
HKEY_LOCAL_MACHINE\SOFTWARE\NetPumper\Affiliated\free pkid
HKEY_LOCAL_MACHINE\SOFTWARE\NetPumper\Affiliated\free alid lemildi
HKEY_LOCAL_MACHINE\SOFTWARE\NetPumper\Affiliated\free iid {8E10759E-D7B9-4E23-AA41-853F041AFDD4}
HKEY_LOCAL_MACHINE\SOFTWARE\NetPumper\Affiliated\Pro state 1
HKEY_LOCAL_MACHINE\SOFTWARE\NetPumper\Affiliated\Pro pkid lemildi
HKEY_LOCAL_MACHINE\SOFTWARE\NetPumper\Affiliated\Pro alid lemildi
HKEY_LOCAL_MACHINE\SOFTWARE\NetPumper\Affiliated\Pro iid {0C24C413-72AE-42C2-85FB-B69C612F4A54}
HKEY_LOCAL_MACHINE\SOFTWARE\NetPumper VersionInfo qUtugvKIWu93mMjoMlrHw7SuGnv00G6Lgm4XQUf3fIHPXguR-tkpMU22V0izWTdekkU0tVg4Y85YSnDMZ7ykF53Ln7f-fhu4j0ony8eRCXoFwrS9d6PiGR4JqU8EoEdslj3Dwcju40stxe+LtRMCtOpQpWKMJtVNYVo5wQ-UvWqxXhDKvCK+2Vfe5l08mn15E4nQaa-C4UQc
HKEY_LOCAL_MACHINE\SOFTWARE\NetPumper Application NetPumper
HKEY_LOCAL_MACHINE\SOFTWARE\NetPumper NEWVER
http://cv.netpumper.com/
HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\MenuExt\Download with NetPumper
HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\MenuExt\Download with NetPumper D:\Programme\NetPumper\AddUrl.htm
HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\MenuExt\Download with NetPumper contexts 243
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{E19B133D-184E-4BBA-8A70-38489C9DD31B}
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{E19B133D-184E-4BBA-8A70-38489C9DD31B}\InprocServer32 D:\Programme\NetPumper\NetPumperNNProxy.dll
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{E19B133D-184E-4BBA-8A70-38489C9DD31B}\InprocServer32 ThreadingModel Apartment
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{E19B133D-184E-4BBA-8A70-38489C9DD31B}\ProgID NetPumperNNProxy.NetscapeInterface
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{E19B133D-184E-4BBA-8A70-38489C9DD31B}\Typelib {F7258F6E-9F60-49C0-8C82-F0A0993D68E0}
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{E19B133D-184E-4BBA-8A70-38489C9DD31B}\Version 1.0
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{E19B133D-184E-4BBA-8A70-38489C9DD31B} NetscapeInterface Object
HKEY_CLASSES_ROOT\NetPumperNNProxy.NetscapeInterface
HKEY_CLASSES_ROOT\NetPumperNNProxy.NetscapeInterface\CLSID {E19B133D-184E-4BBA-8A70-38489C9DD31B}
HKEY_CLASSES_ROOT\NetPumperNNProxy.NetscapeInterface NetscapeInterface Object
HKEY_CLASSES_ROOT\clsid\{1AA406AB-F581-42AB-B4D1-31D2E13819EF}
HKEY_CLASSES_ROOT\clsid\{1AA406AB-F581-42AB-B4D1-31D2E13819EF}\LocalServer32 D:\Programme\NetPumper\NetPumper.exe /Automation
HKEY_CLASSES_ROOT\clsid\{1AA406AB-F581-42AB-B4D1-31D2E13819EF}\LocalServer32 ThreadingModel Apartment
HKEY_CLASSES_ROOT\clsid\{1AA406AB-F581-42AB-B4D1-31D2E13819EF}\ProgID NetPumper.AddUrl
HKEY_CLASSES_ROOT\clsid\{1AA406AB-F581-42AB-B4D1-31D2E13819EF}\Typelib {1145A909-A836-44B8-B03A-48D858B0F43E}
HKEY_CLASSES_ROOT\clsid\{1AA406AB-F581-42AB-B4D1-31D2E13819EF}\Version 1.2
HKEY_CLASSES_ROOT\clsid\{1AA406AB-F581-42AB-B4D1-31D2E13819EF} AddUrl Object
HKEY_CLASSES_ROOT\clsid\{E19B133D-184E-4BBA-8A70-38489C9DD31B}
HKEY_CLASSES_ROOT\clsid\{E19B133D-184E-4BBA-8A70-38489C9DD31B}\InprocServer32 D:\Programme\NetPumper\NetPumperNNProxy.dll
HKEY_CLASSES_ROOT\clsid\{E19B133D-184E-4BBA-8A70-38489C9DD31B}\InprocServer32 ThreadingModel Apartment
HKEY_CLASSES_ROOT\clsid\{E19B133D-184E-4BBA-8A70-38489C9DD31B}\ProgID NetPumperNNProxy.NetscapeInterface
HKEY_CLASSES_ROOT\clsid\{E19B133D-184E-4BBA-8A70-38489C9DD31B}\Typelib {F7258F6E-9F60-49C0-8C82-F0A0993D68E0}
HKEY_CLASSES_ROOT\clsid\{E19B133D-184E-4BBA-8A70-38489C9DD31B}\Version 1.0
HKEY_CLASSES_ROOT\clsid\{E19B133D-184E-4BBA-8A70-38489C9DD31B} NetscapeInterface Object
HKEY_CLASSES_ROOT\NetPumper.AddUrl
HKEY_CLASSES_ROOT\NetPumper.AddUrl\CLSID {1AA406AB-F581-42AB-B4D1-31D2E13819EF}
HKEY_CLASSES_ROOT\NetPumper.AddUrl AddUrl Object
HKEY_CURRENT_USER\Software\NetPumper
HKEY_CURRENT_USER\Software\NetPumper\StephanWensel Field1 2103618047
HKEY_CURRENT_USER\Software\NetPumper\StephanWensel Field2 1662539204
HKEY_CURRENT_USER\Software\NetPumper\StephanWensel Field3 199691782
HKEY_CURRENT_USER\Software\NetPumper\StephanWensel Field4 1944369424
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{1AA406AB-F581-42AB-B4D1-31D2E13819EF}
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{1AA406AB-F581-42AB-B4D1-31D2E13819EF}\LocalServer32 D:\Programme\NetPumper\NetPumper.exe /Automation
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{1AA406AB-F581-42AB-B4D1-31D2E13819EF}\LocalServer32 ThreadingModel Apartment
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{1AA406AB-F581-42AB-B4D1-31D2E13819EF}\ProgID NetPumper.AddUrl
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{1AA406AB-F581-42AB-B4D1-31D2E13819EF}\Typelib {1145A909-A836-44B8-B03A-48D858B0F43E}
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{1AA406AB-F581-42AB-B4D1-31D2E13819EF}\Version 1.2
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{1AA406AB-F581-42AB-B4D1-31D2E13819EF} AddUrl Object
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\TypeLib\{1145A909-A836-44B8-B03A-48D858B0F43E}
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\TypeLib\{1145A909-A836-44B8-B03A-48D858B0F43E}\1.2\0\win32 D:\Programme\NetPumper\NetPumper.exe
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\TypeLib\{1145A909-A836-44B8-B03A-48D858B0F43E}\1.2\FLAGS 0
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\TypeLib\{1145A909-A836-44B8-B03A-48D858B0F43E}\1.2\HELPDIR D:\Programme\NetPumper\
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\TypeLib\{1145A909-A836-44B8-B03A-48D858B0F43E}\1.2 NetPumper Library
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{A8B0F390-E6BF-4027-A4D4-1E4363F5E27B}
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{A8B0F390-E6BF-4027-A4D4-1E4363F5E27B}\ProxyStubClsid {00020424-0000-0000-C000-000000000046}
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{A8B0F390-E6BF-4027-A4D4-1E4363F5E27B}\ProxyStubClsid32 {00020424-0000-0000-C000-000000000046}
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{A8B0F390-E6BF-4027-A4D4-1E4363F5E27B}\TypeLib {1145A909-A836-44B8-B03A-48D858B0F43E}
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{A8B0F390-E6BF-4027-A4D4-1E4363F5E27B}\TypeLib Version 1.2
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{A8B0F390-E6BF-4027-A4D4-1E4363F5E27B} IAddUrl
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{A9E33220-0B05-11D7-88D2-444553540000}
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{A9E33220-0B05-11D7-88D2-444553540000}\ProxyStubClsid {00020424-0000-0000-C000-000000000046}
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{A9E33220-0B05-11D7-88D2-444553540000}\ProxyStubClsid32 {00020424-0000-0000-C000-000000000046}
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{A9E33220-0B05-11D7-88D2-444553540000}\TypeLib {1145A909-A836-44B8-B03A-48D858B0F43E}
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{A9E33220-0B05-11D7-88D2-444553540000}\TypeLib Version 1.2
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{A9E33220-0B05-11D7-88D2-444553540000} IAddPackage
WhenU.SaveNow Adware more information...
Details: an advertising application that displays pop-up advertising on the desktop in response to users' surfing behavior.
Status: Deleted
Infected registry entries detected
HKEY_LOCAL_MACHINE\software\whenusave
HKEY_LOCAL_MACHINE\software\whenusave\Partners\SYNC Partner NPUM0304
HKEY_LOCAL_MACHINE\software\whenusave\Partners\SYNC InstallTime 20050103175713
HKEY_LOCAL_MACHINE\software\whenusave\Partners\SYNC PartnerDesc ClockSync
HKEY_LOCAL_MACHINE\software\whenusave\Partners\SYNC PartnerFile C:\Programme\ClockSync\Sync.exe
HKEY_LOCAL_MACHINE\software\whenusave db_script_update 1002700854
HKEY_LOCAL_MACHINE\software\whenusave InstallDir C:\PROGRA~1\Save
HKEY_LOCAL_MACHINE\software\whenusave pats_url
http://akapp.whenu.com/OffersDataGZ
HKEY_LOCAL_MACHINE\software\whenusave pat_chunks_url
http://akapp.whenu.com/DataChunksGZ
HKEY_LOCAL_MACHINE\software\whenusave script_url
http://app.whenu.com/Throttle?name=scri ... 1002700834
HKEY_LOCAL_MACHINE\software\whenusave update_url
http://app.whenu.com/Throttle?name=Save4.06
HKEY_LOCAL_MACHINE\software\whenusave ver_url
http://www.whenu.com/versions.html
HKEY_LOCAL_MACHINE\software\whenusave extra_url
http://app.whenu.com/Throttle?name=Upda ... _1.04extra
HKEY_LOCAL_MACHINE\software\whenusave extraver_url
http://www.whenudownloads.com/extraver.html
HKEY_LOCAL_MACHINE\software\whenusave ziptomsa_url
http://akapp.whenu.com/ziptomsa
HKEY_LOCAL_MACHINE\software\whenusave InstallTime 20050103175712
HKEY_LOCAL_MACHINE\software\whenusave LastPartner
HKEY_LOCAL_MACHINE\software\whenusave zip
HKEY_LOCAL_MACHINE\software\whenusave TotalPartner 2
HKEY_LOCAL_MACHINE\software\whenusave newuser_rs Y
HKEY_LOCAL_MACHINE\software\whenusave Partner NPUM0304
HKEY_LOCAL_MACHINE\software\whenusave PartnerB SYNC
HKEY_LOCAL_MACHINE\software\whenusave PartnerDesc ClockSync
HKEY_LOCAL_MACHINE\software\whenusave FullDBTime 18652948
HKEY_LOCAL_MACHINE\software\whenusave HeartbeatTime 1151678150859
HKEY_LOCAL_MACHINE\software\whenusave brandskin_url
http://offers.whenu.com/skin/
HKEY_LOCAL_MACHINE\software\whenusave brandstrip_rs 24
HKEY_LOCAL_MACHINE\software\whenusave brandstrip_url
http://offers.whenu.com/save_brand3.html
HKEY_LOCAL_MACHINE\software\whenusave bstat_rs Y
HKEY_LOCAL_MACHINE\software\whenusave himp_url
http://offers.whenu.com/himp/himp.db
HKEY_LOCAL_MACHINE\software\whenusave iptomsa_url
http://app.whenu.com/Location
HKEY_LOCAL_MACHINE\software\whenusave maxPopups_rs 2
HKEY_LOCAL_MACHINE\software\whenusave timedDBUpdate_rs Y
HKEY_LOCAL_MACHINE\software\whenusave uninstalltag_rs O
HKEY_LOCAL_MACHINE\software\whenusave db_local_update 20060625093249
HKEY_LOCAL_MACHINE\software\whenusave MSA CUS
HKEY_LOCAL_MACHINE\software\whenusave TotalPopup 142;19188797;;;45545;2;0;0;95;95;21448
HKEY_LOCAL_MACHINE\software\whenusave Version 4.06
HKEY_LOCAL_MACHINE\software\whenusave UpdateTime 20060625113305
HKEY_LOCAL_MACHINE\software\whenusave SystemParam_rs dt=WhenU Save;q=;i=1
HKEY_LOCAL_MACHINE\software\whenusave acm_rs 1.04
HKEY_LOCAL_MACHINE\software\whenusave db_ver_update 20051208162128
HKEY_LOCAL_MACHINE\software\whenusave HeartbeatCount 162
HKEY_LOCAL_MACHINE\software\whenusave CM1_xend 2
HKEY_LOCAL_MACHINE\software\whenusave CM1_status END
HKEY_LOCAL_MACHINE\software\whenusave redir3p_url
http://offers.whenu.com/skin/redirect3p.html
HKEY_LOCAL_MACHINE\software\whenusave db_stamp_rs 20060630125736
HKEY_LOCAL_MACHINE\software\whenusave db_server_update 20060630125736
HKEY_LOCAL_MACHINE\software\whenusave uninstall_cmd_rs /w /d"WhenU Save"
HKEY_LOCAL_MACHINE\software\whenusave fword_rs Y
HKEY_LOCAL_MACHINE\software\whenusave extraupdate_rs 20060630144000
HKEY_LOCAL_MACHINE\software\whenusave uninst_rs 4.008
HKEY_LOCAL_MACHINE\software\whenusave src_url
http://offers.whenu.com/pop_up/
HKEY_LOCAL_MACHINE\software\whenusave dbc_chunks_rs 33
HKEY_LOCAL_MACHINE\software\whenusave\Partners\SYNC Partner NPUM0304
HKEY_LOCAL_MACHINE\software\whenusave\Partners\SYNC InstallTime 20050103175713
HKEY_LOCAL_MACHINE\software\whenusave\Partners\SYNC PartnerDesc ClockSync
HKEY_LOCAL_MACHINE\software\whenusave\Partners\SYNC PartnerFile C:\Programme\ClockSync\Sync.exe
HKEY_LOCAL_MACHINE\software\whenusave InstallDir C:\PROGRA~1\Save
HKEY_LOCAL_MACHINE\software\whenusave pats_url
http://akapp.whenu.com/OffersDataGZ
HKEY_LOCAL_MACHINE\software\whenusave pat_chunks_url
http://akapp.whenu.com/DataChunksGZ
HKEY_LOCAL_MACHINE\software\whenusave script_url
http://app.whenu.com/Throttle?name=scri ... 1002700834
HKEY_LOCAL_MACHINE\software\whenusave update_url
http://app.whenu.com/Throttle?name=Save4.06
HKEY_LOCAL_MACHINE\software\whenusave extra_url
http://app.whenu.com/Throttle?name=Upda ... _1.04extra
HKEY_LOCAL_MACHINE\software\whenusave InstallTime 20050103175712
HKEY_LOCAL_MACHINE\software\whenusave LastPartner
HKEY_LOCAL_MACHINE\software\whenusave TotalPartner 2
HKEY_LOCAL_MACHINE\software\whenusave newuser_rs Y
HKEY_LOCAL_MACHINE\software\whenusave Partner NPUM0304
HKEY_LOCAL_MACHINE\software\whenusave PartnerB SYNC
HKEY_LOCAL_MACHINE\software\whenusave PartnerDesc ClockSync
HKEY_LOCAL_MACHINE\software\whenusave FullDBTime 18652948
HKEY_LOCAL_MACHINE\software\whenusave HeartbeatTime 1151678150859
HKEY_LOCAL_MACHINE\software\whenusave bstat_rs Y
HKEY_LOCAL_MACHINE\software\whenusave iptomsa_url
http://app.whenu.com/Location
HKEY_LOCAL_MACHINE\software\whenusave maxPopups_rs 2
HKEY_LOCAL_MACHINE\software\whenusave timedDBUpdate_rs Y
HKEY_LOCAL_MACHINE\software\whenusave uninstalltag_rs O
HKEY_LOCAL_MACHINE\software\whenusave MSA CUS
HKEY_LOCAL_MACHINE\software\whenusave TotalPopup 142;19188797;;;45545;2;0;0;95;95;21448
HKEY_LOCAL_MACHINE\software\whenusave Version 4.06
HKEY_LOCAL_MACHINE\software\whenusave UpdateTime 20060625113305
HKEY_LOCAL_MACHINE\software\whenusave SystemParam_rs dt=WhenU Save;q=;i=1
HKEY_LOCAL_MACHINE\software\whenusave HeartbeatCount 162
HKEY_LOCAL_MACHINE\software\whenusave CM1_xend 2
HKEY_LOCAL_MACHINE\software\whenusave CM1_status END
HKEY_LOCAL_MACHINE\software\whenusave uninstall_cmd_rs /w /d"WhenU Save"
HKEY_LOCAL_MACHINE\software\whenusave fword_rs Y
HKEY_LOCAL_MACHINE\SOFTWARE\WhenUSave\Partners\SYNC
HKEY_LOCAL_MACHINE\SOFTWARE\WhenUSave\Partners\SYNC Partner NPUM0304
HKEY_LOCAL_MACHINE\SOFTWARE\WhenUSave\Partners\SYNC InstallTime 20050103175713
HKEY_LOCAL_MACHINE\SOFTWARE\WhenUSave\Partners\SYNC PartnerDesc ClockSync
HKEY_LOCAL_MACHINE\SOFTWARE\WhenUSave\Partners\SYNC PartnerFile C:\Programme\ClockSync\Sync.exe
HKEY_LOCAL_MACHINE\SOFTWARE\WhenUSave msa
HKEY_LOCAL_MACHINE\SOFTWARE\WhenUSave heartbeattime
HKEY_LOCAL_MACHINE\SOFTWARE\WhenUSave himp_url
HKEY_LOCAL_MACHINE\SOFTWARE\WhenUSave db_server_update
HKEY_LOCAL_MACHINE\SOFTWARE\WhenUSave db_stamp_rs
HKEY_LOCAL_MACHINE\SOFTWARE\WhenUSave brandskin_url
HKEY_LOCAL_MACHINE\SOFTWARE\WhenUSave brandstrip_rs
HKEY_LOCAL_MACHINE\SOFTWARE\WhenUSave brandstrip_url
HKEY_LOCAL_MACHINE\SOFTWARE\WhenUSave timeddbupdate_rs
HKEY_LOCAL_MACHINE\SOFTWARE\WhenUSave uninstalltag_rs
HKEY_CLASSES_ROOT\ACM.ACMFactory
HKEY_CLASSES_ROOT\ACM.ACMFactory\CLSID {A9AAE1AB-9688-42C5-86F5-C12F6B9015AD}
HKEY_CLASSES_ROOT\ACM.ACMFactory\CurVer ACM.ACMFactory.1
HKEY_CLASSES_ROOT\ACM.ACMFactory ACMFactory Class
HKEY_CLASSES_ROOT\ACM.ACMFactory.1
HKEY_CLASSES_ROOT\ACM.ACMFactory.1\CLSID {A9AAE1AB-9688-42C5-86F5-C12F6B9015AD}
HKEY_CLASSES_ROOT\ACM.ACMFactory.1 ACMFactory Class
HKEY_CLASSES_ROOT\clsid\{A9AAE1AB-9688-42C5-86F5-C12F6B9015AD}
HKEY_CLASSES_ROOT\clsid\{A9AAE1AB-9688-42C5-86F5-C12F6B9015AD}\InprocServer32 C:\PROGRA~1\Save\ACM.dll
HKEY_CLASSES_ROOT\clsid\{A9AAE1AB-9688-42C5-86F5-C12F6B9015AD}\InprocServer32 ThreadingModel Apartment
HKEY_CLASSES_ROOT\clsid\{A9AAE1AB-9688-42C5-86F5-C12F6B9015AD}\ProgID ACM.ACMFactory.1
HKEY_CLASSES_ROOT\clsid\{A9AAE1AB-9688-42C5-86F5-C12F6B9015AD}\TypeLib {DF901432-1B9F-4F5B-9E56-301C553F9095}
HKEY_CLASSES_ROOT\clsid\{A9AAE1AB-9688-42C5-86F5-C12F6B9015AD}\VersionIndependentProgID ACM.ACMFactory
HKEY_CLASSES_ROOT\clsid\{A9AAE1AB-9688-42C5-86F5-C12F6B9015AD} ACMFactory Class
HKEY_CLASSES_ROOT\clsid\{A9AAE1AB-9688-42C5-86F5-C12F6B9015AD} AppID {127DF9B4-D75D-44A6-AF78-8C3A8CEB03DB}
HKEY_CLASSES_ROOT\TypeLib\{DF901432-1B9F-4F5B-9E56-301C553F9095}
HKEY_CLASSES_ROOT\TypeLib\{DF901432-1B9F-4F5B-9E56-301C553F9095}\1.0\0\win32 C:\PROGRA~1\Save\ACM.dll
HKEY_CLASSES_ROOT\TypeLib\{DF901432-1B9F-4F5B-9E56-301C553F9095}\1.0\FLAGS 0
HKEY_CLASSES_ROOT\TypeLib\{DF901432-1B9F-4F5B-9E56-301C553F9095}\1.0\HELPDIR C:\PROGRA~1\Save\
HKEY_CLASSES_ROOT\TypeLib\{DF901432-1B9F-4F5B-9E56-301C553F9095}\1.0 ACM 1.0 Type Library
HKEY_CLASSES_ROOT\Interface\{572FB162-C0BA-4EDF-8CFF-E3846153B9B0}
HKEY_CLASSES_ROOT\Interface\{572FB162-C0BA-4EDF-8CFF-E3846153B9B0}\ProxyStubClsid {00020424-0000-0000-C000-000000000046}
HKEY_CLASSES_ROOT\Interface\{572FB162-C0BA-4EDF-8CFF-E3846153B9B0}\ProxyStubClsid32 {00020424-0000-0000-C000-000000000046}
HKEY_CLASSES_ROOT\Interface\{572FB162-C0BA-4EDF-8CFF-E3846153B9B0}\TypeLib {DF901432-1B9F-4F5B-9E56-301C553F9095}
HKEY_CLASSES_ROOT\Interface\{572FB162-C0BA-4EDF-8CFF-E3846153B9B0}\TypeLib Version 1.0
HKEY_CLASSES_ROOT\Interface\{572FB162-C0BA-4EDF-8CFF-E3846153B9B0} IACMFactory
HKEY_CLASSES_ROOT\Interface\{43382522-A846-46F4-AC57-1F71AE6E1086}
HKEY_CLASSES_ROOT\Interface\{43382522-A846-46F4-AC57-1F71AE6E1086}\ProxyStubClsid {00020424-0000-0000-C000-000000000046}
HKEY_CLASSES_ROOT\Interface\{43382522-A846-46F4-AC57-1F71AE6E1086}\ProxyStubClsid32 {00020424-0000-0000-C000-000000000046}
HKEY_CLASSES_ROOT\Interface\{43382522-A846-46F4-AC57-1F71AE6E1086}\TypeLib {DF901432-1B9F-4F5B-9E56-301C553F9095}
HKEY_CLASSES_ROOT\Interface\{43382522-A846-46F4-AC57-1F71AE6E1086}\TypeLib Version 1.0
HKEY_CLASSES_ROOT\Interface\{43382522-A846-46F4-AC57-1F71AE6E1086} IFetchExtractor
HKEY_CLASSES_ROOT\Interface\{72A836D1-BC00-43C0-A941-17960E4FB842}
HKEY_CLASSES_ROOT\Interface\{72A836D1-BC00-43C0-A941-17960E4FB842}\ProxyStubClsid {00020424-0000-0000-C000-000000000046}
HKEY_CLASSES_ROOT\Interface\{72A836D1-BC00-43C0-A941-17960E4FB842}\ProxyStubClsid32 {00020424-0000-0000-C000-000000000046}
HKEY_CLASSES_ROOT\Interface\{72A836D1-BC00-43C0-A941-17960E4FB842}\TypeLib {DF901432-1B9F-4F5B-9E56-301C553F9095}
HKEY_CLASSES_ROOT\Interface\{72A836D1-BC00-43C0-A941-17960E4FB842}\TypeLib Version 1.0
HKEY_CLASSES_ROOT\Interface\{72A836D1-BC00-43C0-A941-17960E4FB842} IFetchData
HKEY_CLASSES_ROOT\AppID\{127DF9B4-D75D-44A6-AF78-8C3A8CEB03DB}
HKEY_CLASSES_ROOT\AppID\{127DF9B4-D75D-44A6-AF78-8C3A8CEB03DB} ACM
HKEY_CLASSES_ROOT\AppID\ACM.DLL
HKEY_CLASSES_ROOT\AppID\ACM.DLL AppID {127DF9B4-D75D-44A6-AF78-8C3A8CEB03DB}
WhenU.ClockSync Adware Bundler more information...
Details: ClockSync: a program that sits in the desktop tray and periodically synchronizes the local PC system clock with standard atomic clock time available online.
Status: Deleted
Infected registry entries detected
HKEY_LOCAL_MACHINE\SOFTWARE\WhenUSave\Partners\SYNC
HKEY_LOCAL_MACHINE\SOFTWARE\WhenUSave\Partners\SYNC Partner NPUM0304
HKEY_LOCAL_MACHINE\SOFTWARE\WhenUSave\Partners\SYNC InstallTime 20050103175713
HKEY_LOCAL_MACHINE\SOFTWARE\WhenUSave\Partners\SYNC PartnerDesc ClockSync
HKEY_LOCAL_MACHINE\SOFTWARE\WhenUSave\Partners\SYNC PartnerFile C:\Programme\ClockSync\Sync.exe
Advertising.com Cookie more information...
Status: Deleted
Infected cookies detected
c:\dokumente und einstellungen\stephanwensel\cookies\stephanwensel@advertising[2].txt
Cok.PriceBandit Cookie more information...
Status: Deleted
Infected cookies detected
c:\dokumente und einstellungen\stephanwensel\cookies\stephanwensel@apmebf[1].txt
DoubleClick Cookie more information...
Details: DoubleClick is a popular ad serving network that uses spyware cookies, to target advertising.
Status: Deleted
Infected cookies detected
c:\dokumente und einstellungen\stephanwensel\cookies\stephanwensel@doubleclick[1].txt
Mediaplex.com Cookie more information...
Details: Cookie used to track cross site advertising with the Mediaplex and value Click advertising companies.
Status: Deleted
Infected cookies detected
c:\dokumente und einstellungen\stephanwensel\cookies\stephanwensel@mediaplex[2].txt
Radar Spy 1.0 Cookie more information...
Status: Deleted
Infected cookies detected
c:\dokumente und einstellungen\stephanwensel\cookies\stephanwensel@tradedoubler[2].txt
Dr. Web
A0182164.exe;C:\Dokumente und Einstellungen\StephanWensel\DoctorWeb\Quarantine;Trojan.Swizzor;Nicht desinfizierbar.Verschoben.;
A0182165.exe;C:\Dokumente und Einstellungen\StephanWensel\DoctorWeb\Quarantine;Trojan.Swizzor;Nicht desinfizierbar.Verschoben.;
A0203762.exe\data004;C:\Dokumente und Einstellungen\StephanWensel\DoctorWeb\Quarantine\A0203762.exe;Adware.SaveNow;;
A0203762.exe;C:\Dokumente und Einstellungen\StephanWensel\DoctorWeb\Quarantine;Archiv enthält infizierte Objekte;Verschoben.;
A0203833.exe\data001;C:\Dokumente und Einstellungen\StephanWensel\DoctorWeb\Quarantine\A0203833.exe;Trojan.NtRootKit.131;;
A0203833.exe;C:\Dokumente und Einstellungen\StephanWensel\DoctorWeb\Quarantine;Archiv enthält infizierte Objekte;Verschoben.;
Folder Lock.exe\data001;C:\Dokumente und Einstellungen\StephanWensel\DoctorWeb\Quarantine\Folder Lock.exe;Trojan.NtRootKit.131;;
Folder Lock.exe;C:\Dokumente und Einstellungen\StephanWensel\DoctorWeb\Quarantine;Archiv enthält infizierte Objekte;Verschoben.;
datenbank.mdb;C:\Programme\Sybex\EURO-Fahrschule 2004;möglicherweise SCRIPT.Virus;Nicht desinfizierbar.Gelöscht.;
A0203942.exe;C:\System Volume Information\_restore{6E54630B-AD37-42EC-AA8D-B4E95CDA2081}\RP264;Trojan.Swizzor;Nicht desinfizierbar.Verschoben.;
A0203943.exe;C:\System Volume Information\_restore{6E54630B-AD37-42EC-AA8D-B4E95CDA2081}\RP264;Trojan.Swizzor;Nicht desinfizierbar.Verschoben.;
A0203944.exe\data004;C:\System Volume Information\_restore{6E54630B-AD37-42EC-AA8D-B4E95CDA2081}\RP264\A0203944.exe;Adware.SaveNow;;
A0203944.exe;C:\System Volume Information\_restore{6E54630B-AD37-42EC-AA8D-B4E95CDA2081}\RP264;Archiv enthält infizierte Objekte;Verschoben.;
A0203945.exe\data001;C:\System Volume Information\_restore{6E54630B-AD37-42EC-AA8D-B4E95CDA2081}\RP264\A0203945.exe;Trojan.NtRootKit.131;;
A0203945.exe;C:\System Volume Information\_restore{6E54630B-AD37-42EC-AA8D-B4E95CDA2081}\RP264;Archiv enthält infizierte Objekte;Verschoben.;
A0203946.exe\data001;C:\System Volume Information\_restore{6E54630B-AD37-42EC-AA8D-B4E95CDA2081}\RP264\A0203946.exe;Trojan.NtRootKit.131;;