Jump to content

Welcome to Geeks to Go - Register now for FREE

Geeks To Go is a helpful hub, where thousands of volunteer geeks quickly serve friendly answers and support. Check out the forums and get free advice from the experts. Register now to gain access to all of our features, it's FREE and only takes one minute. Once registered and logged in, you will be able to create topics, post replies to existing threads, give reputation to your fellow members, get your own private messenger, post status updates, manage your profile and so much more.

Create Account How it Works


  • Please log in to reply


  • Guest
Go to this site and download Registry Search Tool
(round about the middle of the page)

Enter SaveNow in the fieldbox and click "Ok".
Notepad will be opened with text in it . Post this text in your next reply.

If your antivirus warns you about a script, allow it to run.
  • 0





  • Topic Starter
  • Member
  • PipPip
  • 11 posts
hey usetobe
thanks for your reply... Excal had me do that as well and the results are... nothing found... Thats why he told me to post in the geeku..

I did run it again just in case, yet i still got the same results...

this is the only report activescan gives me

Incident Status Location

Adware:Adware/SaveNow No disinfected Windows Registry

This is my quarantine log from ad aware...
Its fresh I just uninstalled it and installed it again today..

ArchiveData(auto-quarantine- 2005-07-03 23-30-26.bckp)
Referencefile : SE1R52 30.06.2005

obj[0]=Regkey : interface\{018c5406-aee6-4a68-980f-2ceb1e9416fb}
obj[1]=Regkey : interface\{0a7fc040-f84a-4ad7-9439-798b6c0f861e}
obj[2]=Regkey : interface\{32a9d21f-f510-44dc-9ea6-0456eda04668}
obj[3]=Regkey : interface\{4562b6f3-daf8-464e-87b7-5464575f0d6a}
obj[4]=Regkey : interface\{c93cc79d-02d5-45b0-be39-7f5b0e5dda31}
obj[5]=Regkey : interface\{da4b919f-b757-4e32-8d79-dec5c2704c4b}
obj[9]=Regkey : software\microsoft\downloadmanager
obj[21]=File : C:\WINDOWS\system32\msxml3.dll
obj[22]=File : C:\WINDOWS\system32\msxml3a.dll
obj[23]=File : C:\WINDOWS\system32\msxml3r.dll
obj[24]=File : C:\WINDOWS\ISSM0064.DAT

obj[6]=Regkey : interface\{bd6f129a-08db-4cc5-a75a-f2ab79e55b6e}
obj[10]=Regkey : software\microsoft\mediaplayer\control\playbar
obj[11]=RegValue : software\microsoft\mediaplayer\control\playbar "ClrHighlight"
obj[12]=RegValue : software\microsoft\mediaplayer\control\playbar "ClrForeColor"
obj[13]=RegValue : software\microsoft\mediaplayer\control\playbar "ClrBackColor"
obj[14]=RegValue : software\microsoft\mediaplayer\control\playbar "ClrDownload"
obj[15]=RegValue : software\microsoft\mediaplayer\control\playbar "ClrViewed"
obj[16]=RegValue : software\microsoft\mediaplayer\control\playbar "ClrStatic"
obj[17]=RegValue : software\microsoft\internet explorer\main "CustomizeSearch"
obj[18]=RegValue : software\microsoft\internet explorer\main "IEWatsonEnabled"
obj[19]=RegData : software\microsoft\internet explorer\main "Use Search Asst"

obj[7]=Regkey : clsid\{86227d9c-0efe-4f8a-aa55-30386a3f5686}
obj[8]=RegValue : S-1-5-21-583907252-1563985344-854245398-1003\software\microsoft\internet explorer\toolbar\webbrowser "{86227D9C-0EFE-4f8a-AA55-30386A3F5686}"
obj[20]=Regkey : aspfile\persistenthandler

Edited by Jag8625, 04 July 2005 - 02:25 AM.

  • 0

Similar Topics

0 user(s) are reading this topic

0 members, 0 guests, 0 anonymous users

As Featured On:

Microsoft Yahoo BBC MSN PC Magazine Washington Post HP