Hey all,
Finally managed to find somewhere to download ada from and have just run a scan. So what goes & what stays ?
Here are the results:
180Solutions Object recognized!
Type: RegKey
Category: Data Miner
Rootkey: HKEY_LOCAL_MACHINE
Object: SOFTWARE\180solutions\msbb
Alexa Object recognized!
Type: RegKey
Category: Data Miner
Rootkey: HKEY_LOCAL_MACHINE
Object: SOFTWARE\Microsoft\Internet Explorer\Extensions\{c95fe080-8f5d-11d2-a20b-00aa003c157a}
BlazeFind Object recognized!
Type: RegKey
Category: Malware
Rootkey: HKEY_CLASSES_ROOT
Object: CLSID\{83DE62E0-5805-11D8-9B25-00E04C60FAF2}
BlazeFind Object recognized!
Type: RegKey
Category: Malware
Rootkey: HKEY_LOCAL_MACHINE
Object: SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{83DE62E0-5805-11D8-9B25-00E04C60FAF2}
WinFavorites Object recognized!
Type: RegKey
Category: Malware
Rootkey: HKEY_CLASSES_ROOT
Object: Bridge.brdg.1
WinFavorites Object recognized!
Type: RegKey
Category: Malware
Rootkey: HKEY_CLASSES_ROOT
Object: CLSID\{80bb7465-a638-43b5-9827-8e8fe38dfcc1}
Tracking Cookie Object recognized!
Type: File
Category: Data Miner
Object: C:\Documents and Settings\USER\Cookies\
Tracking Cookie Object recognized!
Type: File
Category: Data Miner
Object: C:\Documents and Settings\USER\Cookies\
Tracking Cookie Object recognized!
Type: File
Category: Data Miner
Object: C:\Documents and Settings\USER\Cookies\
Scanning Hosts file(C:\WINDOWS\System32\drivers\etc\hosts)
Hosts file scan result:
1 entries scanned.
New objects :0
Objects found so far: 9
Performing conditional scans..
Cydoor Object recognized!
Type: Folder
Category: Data Miner
Object: c:\windows\system32\AdCache
BlazeFind Object recognized!
Type: Folder
Category: Malware
Object: c:\program files\WindowsSA
BlazeFind Object recognized!
Type: File
Data: update
Category: Malware
Object: c:\program files\windowssa\
WinFavorites Object recognized!
Type: RegKey
Category: Malware
Rootkey: HKEY_LOCAL_MACHINE
Object: SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\bridge
Cheers, Dave.