Watch out for Screen Savers – Adware.Starware
Windows 5.1.2600 Service Pack 3
6/2/2009 5:54:23 PM
Scan type: Quick Scan
Objects scanned: 97907
Time elapsed: 9 minute(s), 55 second(s)
Memory Processes Infected: 0
Memory Modules Infected: 0
Registry Keys Infected: 7
Registry Values Infected: 0
Registry Data Items Infected: 2
Folders Infected: 49
Files Infected: 81
Memory Processes Infected:
(No malicious items detected)
Memory Modules Infected:
(No malicious items detected)
Registry Keys Infected:
HKEY_CLASSES_ROOT\main.bho (Trojan.BHO) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\TypeLib\{8e3c68cd-f500-4a2a-8cb9-132bb38c3573} (Trojan.BHO) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\Interface\{986a8ac1-ab4d-4f41-9068-4b01c0197867} (Trojan.BHO) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\CLSID\{afd4ad01-58c1-47db-a404-fbe00a6c5486} (Trojan.BHO) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{afd4ad01-58c1-47db-a404-fbe00a6c5486} (Trojan.BHO) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\main.bho.1 (Trojan.BHO) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\starware358 (Adware.Starware) -> Quarantined and deleted successfully.
Registry Values Infected:
(No malicious items detected)
Registry Data Items Infected:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\AntiVirusDisableNotify (Disabled.SecurityCenter) -> Bad: (1) Good: (0) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\FirewallDisableNotify (Disabled.SecurityCenter) -> Bad: (1) Good: (0) -> Quarantined and deleted successfully.
Folders Infected:
c:\documents and settings\All Users\Application Data\SalesMonitor (Rogue.Multiple) -> Quarantined and deleted successfully.
c:\documents and settings\all users\application data\salesmonitor\Data (Rogue.Multiple) -> Quarantined and deleted successfully.
c:\documents and settings\all users\application data\WinAntiSpyware 2007 (Rogue.WinAntiSpyware) -> Quarantined and deleted successfully.
c:\documents and settings\all users\application data\winantispyware 2007\Data (Rogue.WinAntiSpyware) -> Quarantined and deleted successfully.
c:\program files\Starware358 (Adware.Starware) -> Quarantined and deleted successfully.
c:\program files\starware358\bin (Adware.Starware) -> Quarantined and deleted successfully.
c:\program files\starware358\icons (Adware.Starware) -> Quarantined and deleted successfully.
c:\documents and settings\all users\application data\Starware358 (Adware.Starware) -> Quarantined and deleted successfully.
c:\documents and settings\all users\application data\starware358\buttons (Adware.Starware) -> Quarantined and deleted successfully.
c:\documents and settings\all users\application data\starware358\contexts (Adware.Starware) -> Quarantined and deleted successfully.
c:\documents and settings\all users\application data\starware358\EntertainmentMarketingSP (Adware.Starware) -> Quarantined and deleted successfully.
c:\documents and settings\all users\application data\starware358\entertainmentmarketingsp\images (Adware.Starware) -> Quarantined and deleted successfully.
c:\documents and settings\all users\application data\starware358\entertainmentmarketingsp\images\active (Adware.Starware) -> Quarantined and deleted successfully.
c:\documents and settings\all users\application data\starware358\entertainmentmarketingsp\images\default (Adware.Starware) -> Quarantined and deleted successfully.
c:\documents and settings\all users\application data\starware358\Games (Adware.Starware) -> Quarantined and deleted successfully.
c:\documents and settings\all users\application data\starware358\Games\images (Adware.Starware) -> Quarantined and deleted successfully.
c:\documents and settings\all users\application data\starware358\Games\images\active (Adware.Starware) -> Quarantined and deleted successfully.
c:\documents and settings\all users\application data\starware358\Games\images\default (Adware.Starware) -> Quarantined and deleted successfully.
c:\documents and settings\all users\application data\starware358\Movies (Adware.Starware) -> Quarantined and deleted successfully.
c:\documents and settings\all users\application data\starware358\Movies\images (Adware.Starware) -> Quarantined and deleted successfully.
c:\documents and settings\all users\application data\starware358\Movies\images\active (Adware.Starware) -> Quarantined and deleted successfully.
c:\documents and settings\all users\application data\starware358\Movies\images\default (Adware.Starware) -> Quarantined and deleted successfully.
c:\documents and settings\all users\application data\starware358\ScreensaversMarketingSitePager (Adware.Starware) -> Quarantined and deleted successfully.
c:\documents and settings\all users\application data\starware358\screensaversmarketingsitepager\images (Adware.Starware) -> Quarantined and deleted successfully.
c:\documents and settings\all users\application data\starware358\screensaversmarketingsitepager\images\active (Adware.Starware) -> Quarantined and deleted successfully.
c:\documents and settings\all users\application data\starware358\screensaversmarketingsitepager\images\default (Adware.Starware) -> Quarantined and deleted successfully.
c:\documents and settings\all users\application data\starware358\SimpleUpdate (Adware.Starware) -> Quarantined and deleted successfully.
c:\documents and settings\localservice\application data\Starware358 (Adware.Starware) -> Quarantined and deleted successfully.
c:\documents and settings\localservice\application data\starware358\Manager (Adware.Starware) -> Quarantined and deleted successfully.
c:\documents and settings\Owner\application data\Starware358 (Adware.Starware) -> Quarantined and deleted successfully.
c:\documents and settings\Owner\application data\starware358\BrowserSearch (Adware.Starware) -> Quarantined and deleted successfully.
c:\documents and settings\Owner\application data\starware358\CelebrityNews (Adware.Starware) -> Quarantined and deleted successfully.
c:\documents and settings\Owner\application data\starware358\CelebritySearch (Adware.Starware) -> Quarantined and deleted successfully.
c:\documents and settings\Owner\application data\starware358\Configurator (Adware.Starware) -> Quarantined and deleted successfully.
c:\documents and settings\Owner\application data\starware358\EntertainmentMarketingSP (Adware.Starware) -> Quarantined and deleted successfully.
c:\documents and settings\Owner\application data\starware358\ErrorSearch (Adware.Starware) -> Quarantined and deleted successfully.
c:\documents and settings\Owner\application data\starware358\Games (Adware.Starware) -> Quarantined and deleted successfully.
c:\documents and settings\Owner\application data\starware358\Layouts (Adware.Starware) -> Quarantined and deleted successfully.
c:\documents and settings\Owner\application data\starware358\Manager (Adware.Starware) -> Quarantined and deleted successfully.
c:\documents and settings\Owner\application data\starware358\Movies (Adware.Starware) -> Quarantined and deleted successfully.
c:\documents and settings\Owner\application data\starware358\RelatedSearch (Adware.Starware) -> Quarantined and deleted successfully.
c:\documents and settings\Owner\application data\starware358\ScreensaversMarketingSitePager (Adware.Starware) -> Quarantined and deleted successfully.
c:\documents and settings\Owner\application data\starware358\SearchAssistPlus (Adware.Starware) -> Quarantined and deleted successfully.
c:\documents and settings\Owner\application data\starware358\SearchMatch (Adware.Starware) -> Quarantined and deleted successfully.
c:\documents and settings\Owner\application data\starware358\searchmatch\searchMatchPages (Adware.Starware) -> Quarantined and deleted successfully.
c:\documents and settings\Owner\application data\starware358\Toolbar (Adware.Starware) -> Quarantined and deleted successfully.
c:\documents and settings\Owner\application data\starware358\ToolbarLogo (Adware.Starware) -> Quarantined and deleted successfully.
c:\documents and settings\Owner\application data\starware358\ToolbarSearch (Adware.Starware) -> Quarantined and deleted successfully.
c:\documents and settings\Owner\application data\starware358\TravelSearch (Adware.Starware) -> Quarantined and deleted successfully.
Files Infected:
C:\Program Files\Common\helper.dll (Trojan.BHO) -> Quarantined and deleted successfully.
c:\WINDOWS\downloaded program files\WinAntiSpyware2007FreeInstall.exe (Rogue.Installer) -> Quarantined and deleted successfully.
c:\documents and settings\Owner\application data\winantispyware2007freeinstall[1].exe (Rogue.Installer) -> Quarantined and deleted successfully.
c:\documents and settings\all users\application data\winantispyware 2007\Data\Abbr (Rogue.WinAntiSpyware) -> Quarantined and deleted successfully.
c:\documents and settings\all users\application data\winantispyware 2007\Data\ProductCode (Rogue.WinAntiSpyware) -> Quarantined and deleted successfully.
c:\program files\starware358\brand.bmp (Adware.Starware) -> Quarantined and deleted successfully.
c:\program files\starware358\Starware358Config.xml (Adware.Starware) -> Quarantined and deleted successfully.
c:\program files\starware358\Starware358Uninstall.exe (Adware.Starware) -> Quarantined and deleted successfully.
c:\program files\starware358\bin\Starware358.dll (Adware.Starware) -> Quarantined and deleted successfully.
c:\program files\starware358\icons\star_16.ico (Adware.Starware) -> Quarantined and deleted successfully.
c:\documents and settings\all users\application data\starware358\U0637E2F3.exe (Adware.Starware) -> Quarantined and deleted successfully.
c:\documents and settings\all users\application data\starware358\buttons\celebrity_news.bmp (Adware.Starware) -> Quarantined and deleted successfully.
c:\documents and settings\all users\application data\starware358\buttons\celebrity_search.bmp (Adware.Starware) -> Quarantined and deleted successfully.
c:\documents and settings\all users\application data\starware358\buttons\FindIt.bmp (Adware.Starware) -> Quarantined and deleted successfully.
c:\documents and settings\all users\application data\starware358\buttons\FindItHot.bmp (Adware.Starware) -> Quarantined and deleted successfully.
c:\documents and settings\all users\application data\starware358\buttons\findithotxp.png (Adware.Starware) -> Quarantined and deleted successfully.
c:\documents and settings\all users\application data\starware358\buttons\finditxp.png (Adware.Starware) -> Quarantined and deleted successfully.
c:\documents and settings\all users\application data\starware358\buttons\Highlight.bmp (Adware.Starware) -> Quarantined and deleted successfully.
c:\documents and settings\all users\application data\starware358\buttons\HighlightHot.bmp (Adware.Starware) -> Quarantined and deleted successfully.
c:\documents and settings\all users\application data\starware358\buttons\highlighthotxp.png (Adware.Starware) -> Quarantined and deleted successfully.
c:\documents and settings\all users\application data\starware358\buttons\highlightxp.png (Adware.Starware) -> Quarantined and deleted successfully.
c:\documents and settings\all users\application data\starware358\buttons\logo.bmp (Adware.Starware) -> Quarantined and deleted successfully.
c:\documents and settings\all users\application data\starware358\buttons\logoxp.bmp (Adware.Starware) -> Quarantined and deleted successfully.
c:\documents and settings\all users\application data\starware358\contexts\error.xml (Adware.Starware) -> Quarantined and deleted successfully.
c:\documents and settings\all users\application data\starware358\contexts\related.xml (Adware.Starware) -> Quarantined and deleted successfully.
c:\documents and settings\all users\application data\starware358\contexts\Travel.xml (Adware.Starware) -> Quarantined and deleted successfully.
c:\documents and settings\all users\application data\starware358\entertainmentmarketingsp\images\active\EntertainmentMarketingSP0.bmp (Adware.Starware) -> Quarantined and deleted successfully.
c:\documents and settings\all users\application data\starware358\Games\images\active\Games0.bmp (Adware.Starware) -> Quarantined and deleted successfully.
c:\documents and settings\all users\application data\starware358\Movies\images\active\Movies0.bmp (Adware.Starware) -> Quarantined and deleted successfully.
c:\documents and settings\all users\application data\starware358\screensaversmarketingsitepager\images\active\ScreensaversMarketingSitePager0.bmp (Adware.Starware) -> Quarantined and deleted successfully.
c:\documents and settings\all users\application data\starware358\simpleupdate\ProductMessagingConfig.xml (Adware.Starware) -> Quarantined and deleted successfully.
c:\documents and settings\all users\application data\starware358\simpleupdate\ProductMessagingConfig.xml.backup (Adware.Starware) -> Quarantined and deleted successfully.
c:\documents and settings\all users\application data\starware358\simpleupdate\SimpleUpdateConfig.xml (Adware.Starware) -> Quarantined and deleted successfully.
c:\documents and settings\all users\application data\starware358\simpleupdate\SimpleUpdateConfig.xml.backup (Adware.Starware) -> Quarantined and deleted successfully.
c:\documents and settings\all users\application data\starware358\simpleupdate\TimerManagerConfig.xml (Adware.Starware) -> Quarantined and deleted successfully.
c:\documents and settings\all users\application data\starware358\simpleupdate\TimerManagerConfig.xml.backup (Adware.Starware) -> Quarantined and deleted successfully.
c:\documents and settings\localservice\application data\starware358\Manager\ManagerOptions.xml (Adware.Starware) -> Quarantined and deleted successfully.
c:\documents and settings\localservice\application data\starware358\Manager\ManagerOptions.xml.backup (Adware.Starware) -> Quarantined and deleted successfully.
c:\documents and settings\Owner\application data\starware358\browsersearch\BrowserSearch.xml (Adware.Starware) -> Quarantined and deleted successfully.
c:\documents and settings\Owner\application data\starware358\browsersearch\BrowserSearch.xml.backup (Adware.Starware) -> Quarantined and deleted successfully.
c:\documents and settings\Owner\application data\starware358\celebritynews\CelebrityNewsOptions.xml (Adware.Starware) -> Quarantined and deleted successfully.
c:\documents and settings\Owner\application data\starware358\celebritynews\CelebrityNewsOptions.xml.backup (Adware.Starware) -> Quarantined and deleted successfully.
c:\documents and settings\Owner\application data\starware358\celebritysearch\CelebritySearchOptions.xml (Adware.Starware) -> Quarantined and deleted successfully.
c:\documents and settings\Owner\application data\starware358\celebritysearch\CelebritySearchOptions.xml.backup (Adware.Starware) -> Quarantined and deleted successfully.
c:\documents and settings\Owner\application data\starware358\configurator\Configurator.xml (Adware.Starware) -> Quarantined and deleted successfully.
c:\documents and settings\Owner\application data\starware358\configurator\Configurator.xml.backup (Adware.Starware) -> Quarantined and deleted successfully.
c:\documents and settings\Owner\application data\starware358\entertainmentmarketingsp\EntertainmentMarketingSPOptions.xml (Adware.Starware) -> Quarantined and deleted successfully.
c:\documents and settings\Owner\application data\starware358\entertainmentmarketingsp\EntertainmentMarketingSPOptions.xml.backup (Adware.Starware) -> Quarantined and deleted successfully.
c:\documents and settings\Owner\application data\starware358\errorsearch\ErrorSearchOptions.xml (Adware.Starware) -> Quarantined and deleted successfully.
c:\documents and settings\Owner\application data\starware358\errorsearch\ErrorSearchOptions.xml.backup (Adware.Starware) -> Quarantined and deleted successfully.
c:\documents and settings\Owner\application data\starware358\Games\GamesOptions.xml (Adware.Starware) -> Quarantined and deleted successfully.
c:\documents and settings\Owner\application data\starware358\Games\GamesOptions.xml.backup (Adware.Starware) -> Quarantined and deleted successfully.
c:\documents and settings\Owner\application data\starware358\Layouts\PitchLayout.xml (Adware.Starware) -> Quarantined and deleted successfully.
c:\documents and settings\Owner\application data\starware358\Layouts\PitchLayout.xml.backup (Adware.Starware) -> Quarantined and deleted successfully.
c:\documents and settings\Owner\application data\starware358\Layouts\PreferencesLayout.xml (Adware.Starware) -> Quarantined and deleted successfully.
c:\documents and settings\Owner\application data\starware358\Layouts\PreferencesLayout.xml.backup (Adware.Starware) -> Quarantined and deleted successfully.
c:\documents and settings\Owner\application data\starware358\Layouts\ToolbarLayout.xml (Adware.Starware) -> Quarantined and deleted successfully.
c:\documents and settings\Owner\application data\starware358\Layouts\ToolbarLayout.xml.backup (Adware.Starware) -> Quarantined and deleted successfully.
c:\documents and settings\Owner\application data\starware358\Manager\ManagerOptions.xml (Adware.Starware) -> Quarantined and deleted successfully.
c:\documents and settings\Owner\application data\starware358\Manager\ManagerOptions.xml.backup (Adware.Starware) -> Quarantined and deleted successfully.
c:\documents and settings\Owner\application data\starware358\Movies\MoviesOptions.xml (Adware.Starware) -> Quarantined and deleted successfully.
c:\documents and settings\Owner\application data\starware358\Movies\MoviesOptions.xml.backup (Adware.Starware) -> Quarantined and deleted successfully.
c:\documents and settings\Owner\application data\starware358\relatedsearch\RelatedSearchOptions.xml (Adware.Starware) -> Quarantined and deleted successfully.
c:\documents and settings\Owner\application data\starware358\relatedsearch\RelatedSearchOptions.xml.backup (Adware.Starware) -> Quarantined and deleted successfully.
c:\documents and settings\Owner\application data\starware358\screensaversmarketingsitepager\ScreensaversMarketingSitePagerOptions.xml (Adware.Starware) -> Quarantined and deleted successfully.
c:\documents and settings\Owner\application data\starware358\screensaversmarketingsitepager\ScreensaversMarketingSitePagerOptions.xml.backup (Adware.Starware) -> Quarantined and deleted successfully.
c:\documents and settings\Owner\application data\starware358\searchassistplus\SearchAssistPlusOptions.xml (Adware.Starware) -> Quarantined and deleted successfully.
c:\documents and settings\Owner\application data\starware358\searchassistplus\SearchAssistPlusOptions.xml.backup (Adware.Starware) -> Quarantined and deleted successfully.
c:\documents and settings\Owner\application data\starware358\searchmatch\SearchMatchOptions.xml (Adware.Starware) -> Quarantined and deleted successfully.
c:\documents and settings\Owner\application data\starware358\searchmatch\SearchMatchOptions.xml.backup (Adware.Starware) -> Quarantined and deleted successfully.
c:\documents and settings\Owner\application data\starware358\Toolbar\TBProductsOptions.xml (Adware.Starware) -> Quarantined and deleted successfully.
c:\documents and settings\Owner\application data\starware358\Toolbar\TBProductsOptions.xml.backup (Adware.Starware) -> Quarantined and deleted successfully.
c:\documents and settings\Owner\application data\starware358\toolbarlogo\ToolbarLogoOptions.xml (Adware.Starware) -> Quarantined and deleted successfully.
c:\documents and settings\Owner\application data\starware358\toolbarlogo\ToolbarLogoOptions.xml.backup (Adware.Starware) -> Quarantined and deleted successfully.
c:\documents and settings\Owner\application data\starware358\toolbarsearch\ToolbarSearchOptions.xml (Adware.Starware) -> Quarantined and deleted successfully.
c:\documents and settings\Owner\application data\starware358\toolbarsearch\ToolbarSearchOptions.xml.backup (Adware.Starware) -> Quarantined and deleted successfully.
c:\documents and settings\Owner\application data\starware358\travelsearch\TravelSearchOptions.xml (Adware.Starware) -> Quarantined and deleted successfully.
c:\documents and settings\Owner\application data\starware358\travelsearch\TravelSearchOptions.xml.backup (Adware.Starware) -> Quarantined and deleted successfully.
c:\documents and settings\Owner\local settings\Temp\WinAntiSpyware2007Setup.exe (Heuristics.Malware) -> Quarantined and deleted successfully.
C:\Program Files\Common\helper.sig (Trojan.Agent) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\dsound3dd.dll (Trojan.Downloader) -> Quarantined and deleted successfully.

