<?xml version="1.0" encoding="UTF-8"?>

<rss version="2.0" xmlns:blogChannel="http://backend.userland.com/blogChannelModule">

<channel>
<title>Topic &#x27;Ad-Aware Sept. 12 Update - FP??&#x27; in forum &#x27;Security&#x27; - dslreports.com</title>
<link>http://www.dslreports.com/forum/AdAware-Sept-12-Update-FP-16887509</link>
<description></description>
<language>en</language>
<pubDate>Tue, 18 Jun 2013 03:24:49 EDT</pubDate>
<lastBuildDate>Tue, 18 Jun 2013 03:24:49 EDT</lastBuildDate>

<item>
<title>Re: Ad-Aware Sept. 12 Update - FP??</title>
<link>http://www.dslreports.com/forum/Re-AdAware-Sept-12-Update-FP-16906949</link>
<description><![CDATA[norwegian posted : <br>All good here too.  :)]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/Re-AdAware-Sept-12-Update-FP-16906949</guid>
<pubDate>Fri, 15 Sep 2006 05:34:38 EDT</pubDate>
</item>

<item>
<title>Re: Ad-Aware Sept. 12 Update - FP??</title>
<link>http://www.dslreports.com/forum/Re-AdAware-Sept-12-Update-FP-16905315</link>
<description><![CDATA[sashwa posted : No FP this time.   :D]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/Re-AdAware-Sept-12-Update-FP-16905315</guid>
<pubDate>Thu, 14 Sep 2006 22:06:14 EDT</pubDate>
</item>

<item>
<title>Re: Ad-Aware Sept. 12 Update - FP??</title>
<link>http://www.dslreports.com/forum/Re-AdAware-Sept-12-Update-FP-16901061</link>
<description><![CDATA[sashwa posted : Thanks, Janie.  I'll try it when I get home.]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/Re-AdAware-Sept-12-Update-FP-16901061</guid>
<pubDate>Thu, 14 Sep 2006 10:33:42 EDT</pubDate>
</item>

<item>
<title>Re: Ad-Aware Sept. 12 Update - FP??</title>
<link>http://www.dslreports.com/forum/Re-AdAware-Sept-12-Update-FP-16900279</link>
<description><![CDATA[CalamityJane posted : Today's latest update resolves the Diaremover false detection.<br>Check for the new reference file on the updates: SE1R123 14.09.2006<br>&raquo;<A HREF="/forum/remark,16900095">SE1R123 14.09.2006 is now availiable, new definition file for Ad</A>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/Re-AdAware-Sept-12-Update-FP-16900279</guid>
<pubDate>Thu, 14 Sep 2006 06:48:37 EDT</pubDate>
</item>

<item>
<title>Re: Ad-Aware Sept. 12 Update - FP??</title>
<link>http://www.dslreports.com/forum/Re-AdAware-Sept-12-Update-FP-16898182</link>
<description><![CDATA[anon posted : I get this FP using the September 13 2006 update.<br><br>Diaremover <br>HKEY_USERS<br>S-1-5-21-1482476501-2139871995-682003330-1004\software\microsoft\windows\currentversion\ext\stats\{72267f6a-a6f9-11d0-bc94-00c04fb67863}<br><br>Logfile of HijackThis v1.99.1<br>Scan saved at 5:47:28 PM, on 9/13/2006<br>Platform: Windows XP SP2 (WinNT 5.01.2600)<br>MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)<br><br>Running processes:<br>F:\WINDOWS\System32\smss.exe<br>F:\WINDOWS\system32\winlogon.exe<br>F:\WINDOWS\system32\services.exe<br>F:\WINDOWS\system32\lsass.exe<br>F:\WINDOWS\system32\svchost.exe<br>F:\WINDOWS\System32\svchost.exe<br>F:\WINDOWS\system32\LEXBCES.EXE<br>F:\WINDOWS\system32\spoolsv.exe<br>F:\WINDOWS\system32\winlogon.exe<br>F:\WINDOWS\Explorer.EXE<br>F:\WINDOWS\system32\lexpps.exe<br>F:\WINDOWS\system32\svchost.exe<br>G:\Program Files\Lavasoft\Ad-Aware SE Personal\Ad-Aware.exe<br>F:\WINDOWS\system32\notepad.exe<br>F:\Documents and Settings\Office Admin\My Documents\HijackThis.exe<br><br>R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = &raquo;<A HREF="http://www.yahoo.ca/" >www.yahoo.ca/</A><br>R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = &raquo;<A HREF="http://windowsupdate.microsoft.com/" >windowsupdate.microsoft.com/</A><br>O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - G:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll<br>O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - G:\Program Files\Java\jre1.5.0_06\bin\ssv.dll<br>O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - G:\Program Files\Java\jre1.5.0_06\bin\ssv.dll<br>O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - G:\Program Files\Java\jre1.5.0_06\bin\ssv.dll<br>O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - F:\Program Files\Messenger\msmsgs.exe (file missing)<br>O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - F:\Program Files\Messenger\msmsgs.exe (file missing)<br>O20 - Winlogon Notify: WgaLogon - F:\WINDOWS\SYSTEM32\WgaLogon.dll<br>O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - F:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe<br>O23 - Service: iPodService - Apple Computer, Inc. - F:\Program Files\iPod\bin\iPodService.exe<br>O23 - Service: LexBce Server (LexBceS) - Lexmark International, Inc. - F:\WINDOWS\system32\LEXBCES.EXE]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/Re-AdAware-Sept-12-Update-FP-16898182</guid>
<pubDate>Wed, 13 Sep 2006 20:50:55 EDT</pubDate>
</item>

<item>
<title>Re: Ad-Aware Sept. 12 Update - FP??</title>
<link>http://www.dslreports.com/forum/Re-AdAware-Sept-12-Update-FP-16897653</link>
<description><![CDATA[norwegian posted : <br>Thanks C.J. for the report, and no didn't delete that one either, so will leave it as is.<br><br>Antdude,<br><br>My detected key was using that update. Internal build 150 though, are you refering to a change in the internal build, or will it be a different definitions. <br><SMALL>--<br>The only thing necessary for the triumph of evil is for good men to do nothing - Edmund Burke</SMALL>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/Re-AdAware-Sept-12-Update-FP-16897653</guid>
<pubDate>Wed, 13 Sep 2006 19:19:27 EDT</pubDate>
</item>

<item>
<title>Re: Ad-Aware Sept. 12 Update - FP??</title>
<link>http://www.dslreports.com/forum/Re-AdAware-Sept-12-Update-FP-16896892</link>
<description><![CDATA[antdude posted : <div class="bquote"><SMALL>said by <a href="/profile/966177" onClick="this.blur(); return popup(event,'/uidpop?ajh=1&uid=966177');">Buddel</a>:</SMALL><br><br>~~~INFO ONLY~~~<br><br>SE1R123 13.09.2006 Is Now Available, New Definition file for Ad-Aware SE<br><br>============================================<br>Definition file Notification - Lavasoft News<br>============================================<br>SE1R123 13.09.2006</DIV>Thanks. It works fine on my home machine now. :)<br><SMALL>--<br>Ant @ The Ant Farm: &raquo;<A HREF="http://antfarm.ma.cx" >antfarm.ma.cx</A> ... Please do not IM/e-mail me for technical support. Use the forum (I check often)! Disclaimer: The views expressed in this posting are mine, and do not necessarily reflect the views of my employer.</SMALL>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/Re-AdAware-Sept-12-Update-FP-16896892</guid>
<pubDate>Wed, 13 Sep 2006 17:16:59 EDT</pubDate>
</item>

<item>
<title>Re: Ad-Aware Sept. 12 Update - FP??</title>
<link>http://www.dslreports.com/forum/Re-AdAware-Sept-12-Update-FP-16895385</link>
<description><![CDATA[CalamityJane posted : <div class="bquote"><SMALL>said by <a href="/profile/1159554" onClick="this.blur(); return popup(event,'/uidpop?ajh=1&uid=1159554');">norwegian</a>:</SMALL><br><br>Didn't know of this issue till tonight (here), only got one serious issue, but looking at the rest here, it seems relative to a similar key :-<br><br>Started registry scan<br>&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;<br><br> Diaremover Object Recognized!<br>    Type               : Regkey<br>    Data               : <br>    TAC Rating         : 10<br>    Category           : Malware<br>    Comment            : <br>    Rootkey            : HKEY_USERS<br>    Object             : S-1-5-21-1935655697-1336601894-725345543-1004\software\microsoft\windows\currentversion\ext\stats\{72267f6a-a6f9-11d0-bc94-00c04fb67863}<br> </DIV>Thanks for the reports all.  I don't think we had that one last night - but it's been reported now, so please don't delete that one either until Research has had a chance to examine it.<br><SMALL>--<br><br>It takes a disaster to make a woman out of a female</BR>Microsoft MVP/Windows Security 2003-2006</BR>Proud Member of <A HREF="http://asap.maddoktor2.com/">ASAP </A> (Alliance of Security Analysis Professionals)</SMALL>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/Re-AdAware-Sept-12-Update-FP-16895385</guid>
<pubDate>Wed, 13 Sep 2006 13:01:06 EDT</pubDate>
</item>

<item>
<title>Re: Ad-Aware Sept. 12 Update - FP??</title>
<link>http://www.dslreports.com/forum/Re-AdAware-Sept-12-Update-FP-16894402</link>
<description><![CDATA[norwegian posted : Didn't know of this issue till tonight (here), only got one serious issue, but looking at the rest here, it seems relative to a similar key :-<br><br>Started registry scan<br>&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;<br><br> Diaremover Object Recognized!<br>    Type               : Regkey<br>    Data               : <br>    TAC Rating         : 10<br>    Category           : Malware<br>    Comment            : <br>    Rootkey            : HKEY_USERS<br>    Object             : S-1-5-21-1935655697-1336601894-725345543-1004\software\microsoft\windows\currentversion\ext\stats\{72267f6a-a6f9-11d0-bc94-00c04fb67863}<br><SMALL>--<br>The only thing necessary for the triumph of evil is for good men to do nothing - Edmund Burke</SMALL>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/Re-AdAware-Sept-12-Update-FP-16894402</guid>
<pubDate>Wed, 13 Sep 2006 10:16:27 EDT</pubDate>
</item>

<item>
<title>Re: Ad-Aware Sept. 12 Update - FP??</title>
<link>http://www.dslreports.com/forum/Re-AdAware-Sept-12-Update-FP-16894266</link>
<description><![CDATA[sashwa posted : Thanks for the update.  I'll try when I get home tonight.]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/Re-AdAware-Sept-12-Update-FP-16894266</guid>
<pubDate>Wed, 13 Sep 2006 09:54:23 EDT</pubDate>
</item>

<item>
<title>Re: Ad-Aware Sept. 12 Update - FP??</title>
<link>http://www.dslreports.com/forum/Re-AdAware-Sept-12-Update-FP-16893823</link>
<description><![CDATA[jmorlan posted : Latest definitions fixed all my FPs except this one:<br><br>Tracking Cookie Object Recognized!<br>    Type               : IECache Entry<br>    Data               : xxx xxxxx@live365[1].txt<br>    TAC Rating         : 3<br>    Category           : Data Miner<br>    Comment            : Hits:5<br>    Value              : Cookie:xxx xxxxx@live365.com/<br>    Expires            : 9-15-2011 7:38:32 AM<br>    LastSync           : Hits:5<br>    UseCount           : 0<br>    Hits               : 5<br><br>Tracking cookie scan result:<br>&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;<br>New critical objects: 1<br>Objects found so far: 1<br><br>I have placed this cookie on my "ignore" list many times, but AdAware always detects it anyway. <br><br>Thanks. ]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/Re-AdAware-Sept-12-Update-FP-16893823</guid>
<pubDate>Wed, 13 Sep 2006 08:04:01 EDT</pubDate>
</item>

<item>
<title>Re: Ad-Aware Sept. 13 Update - FP??</title>
<link>http://www.dslreports.com/forum/Re-AdAware-Sept-13-Update-FP-16893728</link>
<description><![CDATA[Gianni45 posted : yep, sounds as they fixed 'old' FPs and added a NEW 1 imo... :o<br><br>Started registry scan<br>&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;<br><br> <B>Diaremover Object Recognized!</B><br>    Type               : Regkey<br>    Data               : <br>    TAC Rating         : 10<br>    Category           : Malware<br>    Comment            : <br>    Rootkey            : HKEY_USERS<br>    Object             : S-1-5-21-242286658-708711241-2795454051-1008\software\microsoft\windows\currentversion\ext\stats\{72267f6a-a6f9-11d0-bc94-00c04fb67863}<br><br>Registry Scan result:<br>&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;<br>New critical objects: 1<br>Objects found so far: 1]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/Re-AdAware-Sept-13-Update-FP-16893728</guid>
<pubDate>Wed, 13 Sep 2006 07:18:20 EDT</pubDate>
</item>

<item>
<title>Re: Ad-Aware Sept. 12 Update - FP??</title>
<link>http://www.dslreports.com/forum/Re-AdAware-Sept-12-Update-FP-16893722</link>
<description><![CDATA[Bubba posted : Just a tad more tweaking needed concerning Class ID <B>72267f6a-a6f9-11d0-bc94-00c04fb67863</B><br><br>**Yesterdays log result using definitions file:SE1R123 12.09.2006:**<br> <BLOCKQUOTE><SMALL>quote:</SMALL><HR>Adware.AdMedia Object Recognized!<br>    Type               : Regkey<br>    Data               : <br>    TAC Rating         : 10<br>    Category           : Adware<br>    Comment            : <br>    Rootkey            : HKEY_USERS<br>    Object             : S-1-5-21-1708537768-1897051121-1801674531-1003\software\microsoft\windows\currentversion\ext\stats\{72267f6a-a6f9-11d0-bc94-00c04fb67863}<HR></BLOCKQUOTE><br><br>**Todays log result using definitions file:SE1R123 13.09.2006:**<br> <BLOCKQUOTE><SMALL>quote:</SMALL><HR>Diaremover Object Recognized!<br>    Type               : Regkey<br>    Data               : <br>    TAC Rating         : 10<br>    Category           : Malware<br>    Comment            : <br>    Rootkey            : HKEY_USERS<br>    Object             : S-1-5-21-1708537768-1897051121-1801674531-1003\software\microsoft\windows\currentversion\ext\stats\{72267f6a-a6f9-11d0-bc94-00c04fb67863}<HR></BLOCKQUOTE>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/Re-AdAware-Sept-12-Update-FP-16893722</guid>
<pubDate>Wed, 13 Sep 2006 07:12:54 EDT</pubDate>
</item>

<item>
<title>Re: Ad-Aware Sept. 13 Update - FP??</title>
<link>http://www.dslreports.com/forum/Re-AdAware-Sept-13-Update-FP-16893710</link>
<description><![CDATA[Linklist posted : <div class="bquote"><SMALL>said by <a href="/profile/554504" onClick="this.blur(); return popup(event,'/uidpop?ajh=1&uid=554504');">Santori3</a>:</SMALL><br><br>DIAREMOVER<br>ArchiveData(Diaremover.bckp)Referencefile : SE1R123 13.09.2006====================================================== DIAREMOVER&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;obj[0]=Regkey : S-1-5-21-357967339-2304659736-1445258045-1005\software\microsoft\windows\currentversion\ext\stats\{72267f6a-a6f9-11d0-bc94-00c04fb67863}<br><br>I had this one too...Looks like a FP...?...<br> </DIV>I had the same thing. Probably another false positive.<br><SMALL>--<br>--<BR><A HREF="http://tinyurl.com/8n9wl">Join Red Room Forum</A><BR><A HREF="http://tkjunkmail.blogspot.com">BLOG tkjunkmail.blogspot.com</A><BR><A HREF="http://tkjunkmail.googlepages.com">My Web Page</A></SMALL>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/Re-AdAware-Sept-13-Update-FP-16893710</guid>
<pubDate>Wed, 13 Sep 2006 07:04:10 EDT</pubDate>
</item>

<item>
<title>Re: Ad-Aware Sept. 12 Update - FP??</title>
<link>http://www.dslreports.com/forum/Re-AdAware-Sept-12-Update-FP-16893650</link>
<description><![CDATA[lilhurricane posted : All fine here now..& thanks for the quick correction ]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/Re-AdAware-Sept-12-Update-FP-16893650</guid>
<pubDate>Wed, 13 Sep 2006 06:24:28 EDT</pubDate>
</item>

<item>
<title>Re: Ad-Aware Sept. 13 Update - FP??</title>
<link>http://www.dslreports.com/forum/Re-AdAware-Sept-13-Update-FP-16893643</link>
<description><![CDATA[Santori3 posted : DIAREMOVER<br>ArchiveData(Diaremover.bckp)Referencefile : SE1R123 13.09.2006====================================================== DIAREMOVER&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;obj[0]=Regkey : S-1-5-21-357967339-2304659736-1445258045-1005\software\microsoft\windows\currentversion\ext\stats\{72267f6a-a6f9-11d0-bc94-00c04fb67863}<br><br>I had this one too...Looks like a FP...?...]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/Re-AdAware-Sept-13-Update-FP-16893643</guid>
<pubDate>Wed, 13 Sep 2006 06:19:49 EDT</pubDate>
</item>

<item>
<title>Re: Ad-Aware Sept. 12 Update - FP??</title>
<link>http://www.dslreports.com/forum/Re-AdAware-Sept-12-Update-FP-16893586</link>
<description><![CDATA[maxx77 posted : Hi,<br><br>I didn't know about the trojan downloader false positive.<br><br>In panic, I deleted the quarantine file. <br>I don't use System Restore, and disabled Adaware's creation of logs since the first use.<br><br>Can anyone put in rapidshare, the quarantine file of the trojan downloader false positives? that would be the job of someone from Lavasoft, since quarantines changes from user to user. Lavasoft would be kind, if created a "master" quarantine file of all the possible trojan downloader's registry entries.<br><br>Thanks a lot.]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/Re-AdAware-Sept-12-Update-FP-16893586</guid>
<pubDate>Wed, 13 Sep 2006 05:17:01 EDT</pubDate>
</item>

<item>
<title>Re: Ad-Aware Sept. 12 Update - FP??</title>
<link>http://www.dslreports.com/forum/Re-AdAware-Sept-12-Update-FP-16893533</link>
<description><![CDATA[anon posted : I'm still a bit puzzled :)<br><br>I checked my statistics in ad-aware and it said;<br><br>Win32.Trojan.Agent ---- Total found 2 --- Total Removed 1<br><br>I know you've made a new Definition file, but why,  originally, did it only remove one of the two it found?<br><br>and on a side note... to the posted reply of ...<br><br> <BLOCKQUOTE><SMALL>quote:</SMALL><HR> mikeStrz(anon)<br>@someip<br> Same here!<br><br>I guess XP's SystemRestore would do the trick<HR></BLOCKQUOTE><br><br>I don't have SystemRestore active either :D  ]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/Re-AdAware-Sept-12-Update-FP-16893533</guid>
<pubDate>Wed, 13 Sep 2006 04:20:38 EDT</pubDate>
</item>

<item>
<title>Re: Ad-Aware Sept. 12 Update - FP??</title>
<link>http://www.dslreports.com/forum/Re-AdAware-Sept-12-Update-FP-16893532</link>
<description><![CDATA[dp posted : <div class="bquote"><SMALL>said by <a href="/profile/1323194" onClick="this.blur(); return popup(event,'/uidpop?ajh=1&uid=1323194');">Stoffe</a>:</SMALL><br><br>Thank you all for reporting this False positive.<br>This release fixes False positives in:<br>Adware.AdMedia<br>TrojanBackdoor.Serv-U<br>BargainBuddy<br>Win32.Trojan.Agent<br>Win32.Trojan.Downloader.<br> </DIV>All good here :) Thanks for the quick turnaround.<br><SMALL>--<br>Write your questions down on the back of a $20 dollar bill and send them to me<BR>Microsoft MVP/Windows Security 2004-2006</SMALL>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/Re-AdAware-Sept-12-Update-FP-16893532</guid>
<pubDate>Wed, 13 Sep 2006 04:20:19 EDT</pubDate>
</item>

<item>
<title>Re: Ad-Aware Sept. 12 Update - FP??</title>
<link>http://www.dslreports.com/forum/Re-AdAware-Sept-12-Update-FP-16893446</link>
<description><![CDATA[Buddel posted : ~~~INFO ONLY~~~<br><br>SE1R123 13.09.2006 Is Now Available, New Definition file for Ad-Aware SE<br><br>============================================<br>Definition file Notification - Lavasoft News<br>============================================<br><B>SE1R123 13.09.2006<br><br>This fixes a False Positive in Adware.AdMedia.<br>This fixes a False Positive in TrojanBackdoor.Serv-U.<br>This fixes a False Positive in BargainBuddy.<br>This fixes a False Positive in Win32.Trojan.Agent.<br>This fixes a False Positive in Win32.Trojan.Downloader.</B><br><br>The MD5 checksum for the defs.ref file is 536bea2c1749341b09b2589bf3cc0143<br><br>Additional Information<br>============================================<br>You can use Webupdate to install the new reference file, or download it manually from:<br>&raquo;<A HREF="http://download.lavasoft.de.edgesuite.net/public/defs.zip" >download.lavasoft.de.edgesuite.n&middot;&middot;&middot;defs.zip</A><br><br>If you think something needs to be sent to us for review, visit our submission site at:<br>&raquo;<A HREF="http://www.lavasofthelp.net/submit/" >www.lavasofthelp.net/submit/</A><br><br>If you have any questions, please contact us at:<br>&raquo;<A HREF="http://www.lavasoftsupport.com" >www.lavasoftsupport.com</A><br><br>Thanks to everybody who submitted us files for evaluation!<br><br>The Lavasoft Research & Development Team<br>--------------------------------------------<br><br>That was really fast. Thanks for fixing the above-mentioned false positives.]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/Re-AdAware-Sept-12-Update-FP-16893446</guid>
<pubDate>Wed, 13 Sep 2006 03:14:35 EDT</pubDate>
</item>

<item>
<title>Re: Ad-Aware Sept. 12 Update - FP??</title>
<link>http://www.dslreports.com/forum/Re-AdAware-Sept-12-Update-FP-16893437</link>
<description><![CDATA[Stoffe posted : Thank you all for reporting this False positive.<br>This release fixes False positives in:<br>Adware.AdMedia<br>TrojanBackdoor.Serv-U<br>BargainBuddy<br>Win32.Trojan.Agent<br>Win32.Trojan.Downloader.]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/Re-AdAware-Sept-12-Update-FP-16893437</guid>
<pubDate>Wed, 13 Sep 2006 03:09:33 EDT</pubDate>
</item>

<item>
<title>Ad-Aware Sept. 13 Update - FP??</title>
<link>http://www.dslreports.com/forum/AdAware-Sept-13-Update-FP-16893436</link>
<description><![CDATA[Exidor posted : <div class="code"><PRE><span class="codetext">ArchiveData(Diaremover.bckp)<br>Referencefile : SE1R123 13.09.2006<br>======================================================<br> <br>DIAREMOVER<br>&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;<br>obj&#91;0&#93;=Regkey : S-1-5-21-357967339-2304659736-1445258045-1005\software\microsoft\windows\currentversion\ext\stats\{72267f6a-a6f9-11d0-bc94-00c04fb67863}</SPAN></PRE></DIV>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/AdAware-Sept-13-Update-FP-16893436</guid>
<pubDate>Wed, 13 Sep 2006 03:08:47 EDT</pubDate>
</item>

<item>
<title>Re: Ad-Aware Sept. 12 Update - FP??</title>
<link>http://www.dslreports.com/forum/Re-AdAware-Sept-12-Update-FP-16893394</link>
<description><![CDATA[Normandie posted : OK, Tested the new update and all is well, no more FP as did the other update. Thanks to all that helped.<br><br>Normandie]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/Re-AdAware-Sept-12-Update-FP-16893394</guid>
<pubDate>Wed, 13 Sep 2006 02:43:57 EDT</pubDate>
</item>

<item>
<title>Re: Ad-Aware Sept. 12 Update - FP??</title>
<link>http://www.dslreports.com/forum/Re-AdAware-Sept-12-Update-FP-16893388</link>
<description><![CDATA[kcazzie posted : <div class="bquote"><SMALL>said by <a href="/profile/1392619" onClick="this.blur(); return popup(event,'/uidpop?ajh=1&uid=1392619');">Normandie</a>:</SMALL><BR><BR>CalamityJane,<br><br>There is a new update out, this morning,(Europe Time), I am testing it now and will get back in a few minutes.<br><br>Normandie<br> </DIV>Same here in the U.S., also testing...{New update Date is 9/13/06}<br><br>Edit; Just ended testing new update and all looks just fine on my two PCs... :)]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/Re-AdAware-Sept-12-Update-FP-16893388</guid>
<pubDate>Wed, 13 Sep 2006 02:41:35 EDT</pubDate>
</item>

<item>
<title>Re: Ad-Aware Sept. 12 Update - FP??</title>
<link>http://www.dslreports.com/forum/Re-AdAware-Sept-12-Update-FP-16893380</link>
<description><![CDATA[Normandie posted : CalamityJane,<br><br>There is a new update out, this morning,(Europe Time), I am testing it now and will get back in a few minutes.<br><br>Normandie]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/Re-AdAware-Sept-12-Update-FP-16893380</guid>
<pubDate>Wed, 13 Sep 2006 02:36:21 EDT</pubDate>
</item>

<item>
<title>Re: Ad-Aware Sept. 12 Update - FP??</title>
<link>http://www.dslreports.com/forum/Re-AdAware-Sept-12-Update-FP-16893371</link>
<description><![CDATA[mers2 posted : FPs are the reason to always quarantine and not delete.  <br><SMALL>--<br><B><A HREF="/forum/disco">Team Discovery</A></B><br></SMALL>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/Re-AdAware-Sept-12-Update-FP-16893371</guid>
<pubDate>Wed, 13 Sep 2006 02:32:14 EDT</pubDate>
</item>

<item>
<title>Re: Ad-Aware Sept. 12 Update - FP??</title>
<link>http://www.dslreports.com/forum/Re-AdAware-Sept-12-Update-FP-16893177</link>
<description><![CDATA[antdude posted : Me too just now. I ignored them after reading this forum. Thank you! :)<br><br>Is it me or have there been too many FPs lately? :(]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/Re-AdAware-Sept-12-Update-FP-16893177</guid>
<pubDate>Wed, 13 Sep 2006 01:18:52 EDT</pubDate>
</item>

<item>
<title>Re: Ad-Aware Sept. 12 Update - FP??</title>
<link>http://www.dslreports.com/forum/Re-AdAware-Sept-12-Update-FP-16893134</link>
<description><![CDATA[anon posted : Same here!<br><br>I guess XP's SystemRestore would do the trick :D]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/Re-AdAware-Sept-12-Update-FP-16893134</guid>
<pubDate>Wed, 13 Sep 2006 01:07:27 EDT</pubDate>
</item>

<item>
<title>Re: Ad-Aware Sept. 12 Update - FP??</title>
<link>http://www.dslreports.com/forum/Re-AdAware-Sept-12-Update-FP-16892500</link>
<description><![CDATA[anon posted : so what if you've already deleted all these entries and don't have them in quarantine.<br><br>can they be replaced from another source?]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/Re-AdAware-Sept-12-Update-FP-16892500</guid>
<pubDate>Tue, 12 Sep 2006 23:03:57 EDT</pubDate>
</item>

<item>
<title>Re: Ad-Aware Sept. 12 Update - FP??</title>
<link>http://www.dslreports.com/forum/Re-AdAware-Sept-12-Update-FP-16891152</link>
<description><![CDATA[fulltext posted : 8 here -  Note running IE7 RC2, Norton 360 Beta<br><br>Using definitions file:SE1R123 12.09.2006<br>&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;<br><br>References detected during the scan:<br>&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;<br>BargainBuddy(TAC index:8):2 total references<br>Win32.Trojan.Agent(TAC index:10):1 total references<br>Win32.Trojan.Downloader(TAC index:10):5 total references<br>&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;<br><br>&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;<br><br> Win32.Trojan.Downloader Object Recognized!<br>    Type               : Regkey<br>    Data               : <br>    TAC Rating         : 10<br>    Category           : Malware<br>    Comment            : <br>    Rootkey            : HKEY_CLASSES_ROOT<br>    Object             : clsid\{48e59293-9880-11cf-9754-00aa00c00908}<br><br> Win32.Trojan.Downloader Object Recognized!<br>    Type               : Regkey<br>    Data               : <br>    TAC Rating         : 10<br>    Category           : Malware<br>    Comment            : <br>    Rootkey            : HKEY_CLASSES_ROOT<br>    Object             : interface\{48e59291-9880-11cf-9754-00aa00c00908}<br><br> Win32.Trojan.Downloader Object Recognized!<br>    Type               : Regkey<br>    Data               : <br>    TAC Rating         : 10<br>    Category           : Malware<br>    Comment            : <br>    Rootkey            : HKEY_CLASSES_ROOT<br>    Object             : typelib\{48e59290-9880-11cf-9754-00aa00c00908}<br><br> BargainBuddy Object Recognized!<br>    Type               : Regkey<br>    Data               : <br>    TAC Rating         : 8<br>    Category           : Malware<br>    Comment            : <br>    Rootkey            : HKEY_USERS<br>    Object             : S-1-5-21-527237240-1844237615-839522115-1003\software\microsoft\windows\currentversion\ext\stats\{d27cdb6e-ae6d-11cf-96b8-444553540000}<br><br> Win32.Trojan.Agent Object Recognized!<br>    Type               : Regkey<br>    Data               : <br>    TAC Rating         : 10<br>    Category           : Virus<br>    Comment            : <br>    Rootkey            : HKEY_USERS<br>    Object             : S-1-5-21-527237240-1844237615-839522115-1003\software\microsoft\windows\currentversion\ext\stats\{b45ff030-4447-11d2-85de-00c04fa35c89}<br><br>Registry Scan result:<br>&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;<br>New critical objects: 5<br>Objects found so far: 5<br><br>Performing conditional scans...<br>&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;<br><br> Win32.Trojan.Downloader Object Recognized!<br>    Type               : Regkey<br>    Data               : <br>    TAC Rating         : 10<br>    Category           : Malware<br>    Comment            : <br>    Rootkey            : HKEY_CLASSES_ROOT<br>    Object             : inetctls.inet<br><br> Win32.Trojan.Downloader Object Recognized!<br>    Type               : Regkey<br>    Data               : <br>    TAC Rating         : 10<br>    Category           : Malware<br>    Comment            : <br>    Rootkey            : HKEY_CLASSES_ROOT<br>    Object             : inetctls.inet.1<br><br> BargainBuddy Object Recognized!<br>    Type               : RegData<br>    Data               : no<br>    TAC Rating         : 8<br>    Category           : Malware<br>    Comment            : <br>    Rootkey            : HKEY_CURRENT_USER<br>    Object             : software\microsoft\internet explorer\main<br>    Value              : Use Search Asst<br>    Data               : no<br><br>Conditional scan result:<br>&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;<br>New critical objects: 3<br>Objects found so far: 8]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/Re-AdAware-Sept-12-Update-FP-16891152</guid>
<pubDate>Tue, 12 Sep 2006 19:45:48 EDT</pubDate>
</item>

<item>
<title>Re: Ad-Aware Sept. 12 Update - FP??</title>
<link>http://www.dslreports.com/forum/Re-AdAware-Sept-12-Update-FP-16891134</link>
<description><![CDATA[anon posted : Object : inetctls.inet<br>Object : clsid\{48e59293-9880-11cf-9754-00aa00c00908}<br><br>FP! These two are related to inetctls.inet and are totally valid for at least some VB & VB.Net applications, especially for developers.  If you remove them, I bet your VB apps won't run, compile, and/or load properly.<br><br>I do not know about the BarginBuddy entry.<br> {d27cdb6e-ae6d-11cf-96b8-444553540000}<br><br>Fortunately I was thinking FPs as soon as I saw these.  So I ran full bore Norton AV, SpyBot, Windows Defender, Hijack,etc., none of which found or reported these. <br>.]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/Re-AdAware-Sept-12-Update-FP-16891134</guid>
<pubDate>Tue, 12 Sep 2006 19:42:59 EDT</pubDate>
</item>

<item>
<title>Re: Ad-Aware Sept. 12 Update - FP??</title>
<link>http://www.dslreports.com/forum/Re-AdAware-Sept-12-Update-FP-16890159</link>
<description><![CDATA[onDvine posted : I thought it was odd that I'd picked up stuff without going anyplace unfamiliar.  Have restored the items from quarantine, as well.  Thanks.<br><SMALL>--<br>I base most of my fashion taste on what doesn't itch. &#9642;Gilda Radner</SMALL>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/Re-AdAware-Sept-12-Update-FP-16890159</guid>
<pubDate>Tue, 12 Sep 2006 16:47:16 EDT</pubDate>
</item>

<item>
<title>Re: Ad-Aware Sept. 12 Update - FP??</title>
<link>http://www.dslreports.com/forum/Re-AdAware-Sept-12-Update-FP-16890075</link>
<description><![CDATA[Buddel posted : Same problems here. Let's hope they will soon be fixed.]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/Re-AdAware-Sept-12-Update-FP-16890075</guid>
<pubDate>Tue, 12 Sep 2006 16:34:51 EDT</pubDate>
</item>

<item>
<title>Re: Ad-Aware Sept. 12 Update - FP??</title>
<link>http://www.dslreports.com/forum/Re-AdAware-Sept-12-Update-FP-16890046</link>
<description><![CDATA[johnburns posted : I seem to have a very similar problem:  After I downloaded the LavaSoft AdAware new definitions today, I got this:<br><br>ArchiveData(auto-quarantine- 2006-09-12 11-18-18.bckp)<br>Referencefile : SE1R123 12.09.2006<br>======================================================<br><br>MRU LIST<br>&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;<br>obj[0]=MRU FileReference : C:\Documents and Settings\John R Burns\recent\Desktop.ini<br>obj[2]=MRU RegReference : software\microsoft\directdraw\mostrecentapplication name<br>obj[3]=MRU RegReference : S-1-5-21-3818105423-895719299-1048318793-1006\software\microsoft\microsoft management console\recent file list<br><br>WIN32.TROJAN.DOWNLOADER<br>&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;<br>obj[3]=Regkey : clsid\{48e59293-9880-11cf-9754-00aa00c00908}<br>obj[4]=Regkey : interface\{48e59291-9880-11cf-9754-00aa00c00908}<br>obj[5]=Regkey : typelib\{48e59290-9880-11cf-9754-00aa00c00908}<br>obj[6]=Regkey : inetctls.inet<br>obj[7]=Regkey : inetctls.inet.1<br>obj[8]=Regkey : software\microsoft\windows\currentversion\policies\activedesktop]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/Re-AdAware-Sept-12-Update-FP-16890046</guid>
<pubDate>Tue, 12 Sep 2006 16:29:40 EDT</pubDate>
</item>

<item>
<title>Re: Ad-Aware Sept. 12 Update - FP??</title>
<link>http://www.dslreports.com/forum/Re-AdAware-Sept-12-Update-FP-16889994</link>
<description><![CDATA[sashwa posted : Thanks, Janie.  I restored the quarantined files and waiting to hear about a fix before I put the stuff back in quarantine.]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/Re-AdAware-Sept-12-Update-FP-16889994</guid>
<pubDate>Tue, 12 Sep 2006 16:23:05 EDT</pubDate>
</item>

<item>
<title>Re: Ad-Aware Sept. 12 Update - FP??</title>
<link>http://www.dslreports.com/forum/Re-AdAware-Sept-12-Update-FP-16889973</link>
<description><![CDATA[CalamityJane posted : <div class="bquote"><SMALL>said by <a href="/profile/299537" onClick="this.blur(); return popup(event,'/uidpop?ajh=1&uid=299537');">sashwa</a>:</SMALL><br><br>Janie, both those Dword values of those entries are 4.<br><br>Also, I'm not using Eric Howe's IESPYAD.  I do use Spybot immunization though.  So maybe Spybot has them listed too. <br> </DIV>Ok, a 4 is good.  Whatever put it there has put that site into the IE restricted zone.  :)  So don't "fix it", it's a FP, too.<br><SMALL>--<br><br>It takes a disaster to make a woman out of a female</BR>Microsoft MVP/Windows Security 2003-2006</BR>Proud Member of <A HREF="http://asap.maddoktor2.com/">ASAP </A> (Alliance of Security Analysis Professionals)</SMALL>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/Re-AdAware-Sept-12-Update-FP-16889973</guid>
<pubDate>Tue, 12 Sep 2006 16:20:43 EDT</pubDate>
</item>

<item>
<title>Re: Ad-Aware Sept. 12 Update - FP??</title>
<link>http://www.dslreports.com/forum/Re-AdAware-Sept-12-Update-FP-16889895</link>
<description><![CDATA[sashwa posted : Janie, both those Dword values of those entries are 4.<br><br>Also, I'm not using Eric Howe's IESPYAD.  I do use Spybot immunization though.  So maybe Spybot has them listed too. ]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/Re-AdAware-Sept-12-Update-FP-16889895</guid>
<pubDate>Tue, 12 Sep 2006 16:10:36 EDT</pubDate>
</item>

<item>
<title>Re: Ad-Aware Sept. 12 Update - FP??</title>
<link>http://www.dslreports.com/forum/Re-AdAware-Sept-12-Update-FP-16889487</link>
<description><![CDATA[CalamityJane posted : I believe just the first <STRIKE>two</STRIKE> three Mokey2000.  The ones that are id'd as:<br> Win32.Trojan.Downloader <br><br>I have not seen any reports of the ones seen as Alexa being an FP<br><br><I>Edit:  Can't count :)</I>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/Re-AdAware-Sept-12-Update-FP-16889487</guid>
<pubDate>Tue, 12 Sep 2006 14:58:15 EDT</pubDate>
</item>

<item>
<title>Re: Ad-Aware Sept. 12 Update - FP??</title>
<link>http://www.dslreports.com/forum/Re-AdAware-Sept-12-Update-FP-16889445</link>
<description><![CDATA[Mokey2000 posted : Got 11 New critical objects, how many are FP's<br><br>Memory scan result:<br>&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;<br>New critical objects: 0<br>Objects found so far: 0<br><br>Started registry scan<br>&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;<br><br> Win32.Trojan.Downloader Object Recognized!<br>    Type               : Regkey<br>    Data               : <br>    TAC Rating         : 10<br>    Category           : Malware<br>    Comment            : <br>    Rootkey            : HKEY_CLASSES_ROOT<br>    Object             : clsid\{48e59293-9880-11cf-9754-00aa00c00908}<br><br> Win32.Trojan.Downloader Object Recognized!<br>    Type               : Regkey<br>    Data               : <br>    TAC Rating         : 10<br>    Category           : Malware<br>    Comment            : <br>    Rootkey            : HKEY_CLASSES_ROOT<br>    Object             : interface\{48e59291-9880-11cf-9754-00aa00c00908}<br><br> Win32.Trojan.Downloader Object Recognized!<br>    Type               : Regkey<br>    Data               : <br>    TAC Rating         : 10<br>    Category           : Malware<br>    Comment            : <br>    Rootkey            : HKEY_CLASSES_ROOT<br>    Object             : typelib\{48e59290-9880-11cf-9754-00aa00c00908}<br><br> Alexa Object Recognized!<br>    Type               : Regkey<br>    Data               : <br>    TAC Rating         : 5<br>    Category           : Data Miner<br>    Comment            : <br>    Rootkey            : HKEY_LOCAL_MACHINE<br>    Object             : software\microsoft\internet explorer\extensions\{c95fe080-8f5d-11d2-a20b-00aa003c157a}<br><br> Alexa Object Recognized!<br>    Type               : RegValue<br>    Data               : <br>    TAC Rating         : 5<br>    Category           : Data Miner<br>    Comment            : <br>    Rootkey            : HKEY_LOCAL_MACHINE<br>    Object             : software\microsoft\internet explorer\extensions\{c95fe080-8f5d-11d2-a20b-00aa003c157a}<br>    Value              : MenuStatusBar<br><br> Alexa Object Recognized!<br>    Type               : RegValue<br>    Data               : <br>    TAC Rating         : 5<br>    Category           : Data Miner<br>    Comment            : <br>    Rootkey            : HKEY_LOCAL_MACHINE<br>    Object             : software\microsoft\internet explorer\extensions\{c95fe080-8f5d-11d2-a20b-00aa003c157a}<br>    Value              : Script<br><br> Alexa Object Recognized!<br>    Type               : RegValue<br>    Data               : <br>    TAC Rating         : 5<br>    Category           : Data Miner<br>    Comment            : <br>    Rootkey            : HKEY_LOCAL_MACHINE<br>    Object             : software\microsoft\internet explorer\extensions\{c95fe080-8f5d-11d2-a20b-00aa003c157a}<br>    Value              : clsid<br><br> Alexa Object Recognized!<br>    Type               : RegValue<br>    Data               : <br>    TAC Rating         : 5<br>    Category           : Data Miner<br>    Comment            : <br>    Rootkey            : HKEY_LOCAL_MACHINE<br>    Object             : software\microsoft\internet explorer\extensions\{c95fe080-8f5d-11d2-a20b-00aa003c157a}<br>    Value              : Icon<br><br> Alexa Object Recognized!<br>    Type               : RegValue<br>    Data               : <br>    TAC Rating         : 5<br>    Category           : Data Miner<br>    Comment            : <br>    Rootkey            : HKEY_LOCAL_MACHINE<br>    Object             : software\microsoft\internet explorer\extensions\{c95fe080-8f5d-11d2-a20b-00aa003c157a}<br>    Value              : HotIcon<br><br> Alexa Object Recognized!<br>    Type               : RegValue<br>    Data               : <br>    TAC Rating         : 5<br>    Category           : Data Miner<br>    Comment            : <br>    Rootkey            : HKEY_LOCAL_MACHINE<br>    Object             : software\microsoft\internet explorer\extensions\{c95fe080-8f5d-11d2-a20b-00aa003c157a}<br>    Value              : ButtonText<br><br> Alexa Object Recognized!<br>    Type               : RegValue<br>    Data               : <br>    TAC Rating         : 5<br>    Category           : Data Miner<br>    Comment            : "{c95fe080-8f5d-11d2-a20b-00aa003c157a}"<br>    Rootkey            : HKEY_USERS<br>    Object             : .DEFAULT\software\microsoft\internet explorer\extensions\cmdmapping<br>    Value              : {c95fe080-8f5d-11d2-a20b-00aa003c157a}<br><br>Registry Scan result:<br>&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;<br>New critical objects: 11<br>Objects found so far: 11<br><br>Started deep registry scan<br>&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;<br><br>Deep registry scan result:<br>&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;<br>New critical objects: 0<br>Objects found so far: 11<br><SMALL>--<br>Hybrid System, DW3000 Modem, AOL+ Grey Dish, SatMex5 1230, Gateway 66.82.156.161,   4.2.1.10, Win98se</SMALL>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/Re-AdAware-Sept-12-Update-FP-16889445</guid>
<pubDate>Tue, 12 Sep 2006 14:51:50 EDT</pubDate>
</item>

<item>
<title>Re: Ad-Aware Sept. 12 Update - FP??</title>
<link>http://www.dslreports.com/forum/Re-AdAware-Sept-12-Update-FP-16889218</link>
<description><![CDATA[CalamityJane posted : It is the new regsitry entries you are seeing for these two:<br><br><B>Win32.Trojan.Agent<br>BargainBuddy</B><br><br>And additionally in Sashwa's log, these two which are probably from Eric Howe's IESPYAD in the restricted zone.  I had these yesterday in the beta release and reported them, but maybe they missed my report.  In any case these are FPs too, I'm pretty sure (I had the same ones)<br><br>obj[9]=Regkey : software\microsoft\windows\currentversion\internet settings\zonemap\domains\media-motor.net<br><br>obj[10]=Regkey : software\microsoft\windows\currentversion\internet settings\zonemap\domains\mmohsix.com<br><br>Check the dword value on those keys Sash and if they are a 4 then that is ok :)<br><SMALL>--<br><br>It takes a disaster to make a woman out of a female</BR>Microsoft MVP/Windows Security 2003-2006</BR>Proud Member of <A HREF="http://asap.maddoktor2.com/">ASAP </A> (Alliance of Security Analysis Professionals)</SMALL>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/Re-AdAware-Sept-12-Update-FP-16889218</guid>
<pubDate>Tue, 12 Sep 2006 14:19:19 EDT</pubDate>
</item>

<item>
<title>Re: Ad-Aware Sept. 12 Update - FP??</title>
<link>http://www.dslreports.com/forum/Re-AdAware-Sept-12-Update-FP-16889166</link>
<description><![CDATA[CalamityJane posted : Ok, Normandie!  We'll post here when the new update is available :)]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/Re-AdAware-Sept-12-Update-FP-16889166</guid>
<pubDate>Tue, 12 Sep 2006 14:11:18 EDT</pubDate>
</item>

<item>
<title>Re: Ad-Aware Sept. 12 Update - FP??</title>
<link>http://www.dslreports.com/forum/Re-AdAware-Sept-12-Update-FP-16889162</link>
<description><![CDATA[jmorlan posted : I got 10 plus one "tracking cookie":<br><br>Started registry scan<br>&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;<br><br> Win32.Trojan.Downloader Object Recognized!<br>    Type               : Regkey<br>    Data               : <br>    TAC Rating         : 10<br>    Category           : Malware<br>    Comment            : <br>    Rootkey            : HKEY_CLASSES_ROOT<br>    Object             : clsid\{48e59293-9880-11cf-9754-00aa00c00908}<br><br> Win32.Trojan.Downloader Object Recognized!<br>    Type               : Regkey<br>    Data               : <br>    TAC Rating         : 10<br>    Category           : Malware<br>    Comment            : <br>    Rootkey            : HKEY_CLASSES_ROOT<br>    Object             : interface\{48e59291-9880-11cf-9754-00aa00c00908}<br><br> Win32.Trojan.Downloader Object Recognized!<br>    Type               : Regkey<br>    Data               : <br>    TAC Rating         : 10<br>    Category           : Malware<br>    Comment            : <br>    Rootkey            : HKEY_USERS<br>    Object             : S-1-5-21-1710738407-720897496-4103935507-1005\software\classes\typelib\{48e59290-9880-11cf-9754-00aa00c00908}<br><br> Win32.Trojan.Downloader Object Recognized!<br>    Type               : Regkey<br>    Data               : <br>    TAC Rating         : 10<br>    Category           : Malware<br>    Comment            : <br>    Rootkey            : HKEY_CLASSES_ROOT<br>    Object             : typelib\{48e59290-9880-11cf-9754-00aa00c00908}<br><br> BargainBuddy Object Recognized!<br>    Type               : Regkey<br>    Data               : <br>    TAC Rating         : 8<br>    Category           : Malware<br>    Comment            : <br>    Rootkey            : HKEY_USERS<br>    Object             : S-1-5-21-1710738407-720897496-4103935507-1005\software\microsoft\windows\currentversion\ext\stats\{d27cdb6e-ae6d-11cf-96b8-444553540000}<br><br> Win32.Trojan.Agent Object Recognized!<br>    Type               : Regkey<br>    Data               : <br>    TAC Rating         : 10<br>    Category           : Virus<br>    Comment            : <br>    Rootkey            : HKEY_USERS<br>    Object             : S-1-5-21-1710738407-720897496-4103935507-1005\software\microsoft\windows\currentversion\ext\stats\{b45ff030-4447-11d2-85de-00c04fa35c89}<br><br>Performing conditional scans...<br>&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;<br><br>Win32.Trojan.Downloader Object Recognized!<br>    Type               : Regkey<br>    Data               : <br>    TAC Rating         : 10<br>    Category           : Malware<br>    Comment            : <br>    Rootkey            : HKEY_CLASSES_ROOT<br>    Object             : inetctls.inet<br><br> Win32.Trojan.Downloader Object Recognized!<br>    Type               : Regkey<br>    Data               : <br>    TAC Rating         : 10<br>    Category           : Malware<br>    Comment            : <br>    Rootkey            : HKEY_CLASSES_ROOT<br>    Object             : inetctls.inet.1<br><br> BargainBuddy Object Recognized!<br>    Type               : RegData<br>    Data               : no<br>    TAC Rating         : 8<br>    Category           : Malware<br>    Comment            : <br>    Rootkey            : HKEY_CURRENT_USER<br>    Object             : software\microsoft\internet explorer\main<br>    Value              : Use Search Asst<br>    Data               : no<br><br> Win32.Trojan.Agent Object Recognized!<br>    Type               : RegValue<br>    Data               : <br>    TAC Rating         : 10<br>    Category           : Virus<br>    Comment            : <br>    Rootkey            : HKEY_CURRENT_USER<br>    Object             : software\microsoft\windows\currentversion\explorer\advanced<br>    Value              : Start_ShowRun]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/Re-AdAware-Sept-12-Update-FP-16889162</guid>
<pubDate>Tue, 12 Sep 2006 14:10:56 EDT</pubDate>
</item>

<item>
<title>Re: Ad-Aware Sept. 12 Update - FP??</title>
<link>http://www.dslreports.com/forum/Re-AdAware-Sept-12-Update-FP-16889059</link>
<description><![CDATA[Normandie posted : CalamityJane,<br><br>Thanks, have restored them and now will wait and see.<br><br>Have a good day,<br>Normandie]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/Re-AdAware-Sept-12-Update-FP-16889059</guid>
<pubDate>Tue, 12 Sep 2006 13:55:28 EDT</pubDate>
</item>

<item>
<title>Re: Ad-Aware Sept. 12 Update - FP??</title>
<link>http://www.dslreports.com/forum/Re-AdAware-Sept-12-Update-FP-16889006</link>
<description><![CDATA[CalamityJane posted : Normandie and anyone else wondering or have already removed them,<br><br>Look in your quarantine list and restore them from there.  I'm pretty sure these are FPs so let's wait to see before you remove anything permanently.<br><br>Open your quarantine list from the main screen.  Locate the items removed on the last scan and rightclick the item in the list.  Then choose *Restore selected*<br><SMALL>--<br><br>It takes a disaster to make a woman out of a female</BR>Microsoft MVP/Windows Security 2003-2006</BR>Proud Member of <A HREF="http://asap.maddoktor2.com/">ASAP </A> (Alliance of Security Analysis Professionals)</SMALL><div class="borderless"><TABLE WIDTH=95% align=center border=0 CELLPADDING=4"><TR><TD ALIGN=CENTER VALIGN=CENTER BGCOLOR=#FFFFFF nwrap COLSPAN=3 WIDTH=100%><A HREF="/speak/slideshow/16889006?c=1062257&ret=L2ZvcnVtL3IxNjg4NzUwOS54bWw%3D"><IMG TITLE="17954 bytes" BORDER=0 WIDTH=406 HEIGHT=268 SRC="/r0/download/1062257~48d4a57d5ae236b7bc154565ded92aa4/quarantine%20list.gif"></A></TD></TABLE></div>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/Re-AdAware-Sept-12-Update-FP-16889006</guid>
<pubDate>Tue, 12 Sep 2006 13:49:18 EDT</pubDate>
</item>

<item>
<title>Re: Ad-Aware Sept. 12 Update - FP??</title>
<link>http://www.dslreports.com/forum/Re-AdAware-Sept-12-Update-FP-16888941</link>
<description><![CDATA[Jer03 posted : I also got the "trojan downloader" and barginbuddy on both of my computers when I scanned with AdAware. They are in quarantine. I thought they were FP, and I have scanned with BD, KAV6, F-Secure, Counterspy, Zero Spyware, and SuperAntiSpywsre without any detections.<br><br>Remove them from quarantine or just let them sit for awhile?<br><br>Thanks,<br>Jerry]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/Re-AdAware-Sept-12-Update-FP-16888941</guid>
<pubDate>Tue, 12 Sep 2006 13:41:32 EDT</pubDate>
</item>

<item>
<title>Re: Ad-Aware Sept. 12 Update - FP??</title>
<link>http://www.dslreports.com/forum/Re-AdAware-Sept-12-Update-FP-16888895</link>
<description><![CDATA[sashwa posted : I ended up with 13 --<br><br>ArchiveData(auto-quarantine- 2006-09-12 09-02-23.bckp)<br>Referencefile : SE1R123 12.09.2006<br>======================================================<br><br>WIN32.TROJAN.DOWNLOADER<br>&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;<br>obj[0]=Regkey : clsid\{48e59293-9880-11cf-9754-00aa00c00908}<br>obj[1]=Regkey : interface\{48e59291-9880-11cf-9754-00aa00c00908}<br>obj[2]=Regkey : typelib\{48e59290-9880-11cf-9754-00aa00c00908}<br>obj[7]=Regkey : inetctls.inet<br>obj[8]=Regkey : inetctls.inet.1<br><br>ADWARE.ADMEDIA<br>&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;<br>obj[3]=Regkey : S-1-5-21-1348100749-3355621399-706083027-1006\software\microsoft\windows\currentversion\ext\stats\{72267f6a-a6f9-11d0-bc94-00c04fb67863}<br>obj[9]=Regkey : software\microsoft\windows\currentversion\internet settings\zonemap\domains\media-motor.net<br>obj[10]=Regkey : software\microsoft\windows\currentversion\internet settings\zonemap\domains\mmohsix.com<br><br>BARGAINBUDDY<br>&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;<br>obj[4]=Regkey : S-1-5-21-1348100749-3355621399-706083027-1006\software\microsoft\windows\currentversion\ext\stats\{d27cdb6e-ae6d-11cf-96b8-444553540000}<br>obj[11]=RegData : software\microsoft\internet explorer\main "Use Search Asst"<br><br>WIN32.TROJAN.AGENT<br>&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;<br>obj[5]=Regkey : S-1-5-21-1348100749-3355621399-706083027-1006\software\microsoft\windows\currentversion\ext\stats\{b45ff030-4447-11d2-85de-00c04fa35c89}<br>obj[12]=RegValue : software\microsoft\windows\currentversion\explorer\advanced "Start_ShowRun"<br><br>TRACKING COOKIE<br>&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;<br>obj[6]=IECache Entry : Cookie:XXXXXX@apmebf.com/<br><SMALL>--<br><A HREF="http://www.dslreports.com/forum/helix">Team Helix</A>  ~  <A HREF="http://www.dslreports.com/forum/seattle">Extended Pacific Northwest</A>  ~  <A HREF="http://www.dslreports.com/forum/sanfran">Northern California</A></SMALL>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/Re-AdAware-Sept-12-Update-FP-16888895</guid>
<pubDate>Tue, 12 Sep 2006 13:37:03 EDT</pubDate>
</item>

<item>
<title>Re: Ad-Aware Sept. 12 Update - FP??</title>
<link>http://www.dslreports.com/forum/Re-AdAware-Sept-12-Update-FP-16888769</link>
<description><![CDATA[Normandie posted : So should we restore them if we took them out! What problems might this cause if we don't restore them and shut down the computer?<br><br>Thanks,<br>Normandie (formerly "GuestFromFrance")]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/Re-AdAware-Sept-12-Update-FP-16888769</guid>
<pubDate>Tue, 12 Sep 2006 13:21:47 EDT</pubDate>
</item>

<item>
<title>Re: Ad-Aware Sept. 12 Update - FP??</title>
<link>http://www.dslreports.com/forum/Re-AdAware-Sept-12-Update-FP-16888736</link>
<description><![CDATA[Gianni45 posted : Same problem here... :o<br><br>Started registry scan<br>&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;<br><br> Win32.Trojan.Downloader Object Recognized!<br>    Type               : Regkey<br>    Data               : <br>    TAC Rating         : 10<br>    Category           : Malware<br>    Comment            : <br>    Rootkey            : HKEY_CLASSES_ROOT<br>    Object             : clsid\{48e59293-9880-11cf-9754-00aa00c00908}<br><br> Win32.Trojan.Downloader Object Recognized!<br>    Type               : Regkey<br>    Data               : <br>    TAC Rating         : 10<br>    Category           : Malware<br>    Comment            : <br>    Rootkey            : HKEY_CLASSES_ROOT<br>    Object             : interface\{48e59291-9880-11cf-9754-00aa00c00908}<br><br> Win32.Trojan.Downloader Object Recognized!<br>    Type               : Regkey<br>    Data               : <br>    TAC Rating         : 10<br>    Category           : Malware<br>    Comment            : <br>    Rootkey            : HKEY_CLASSES_ROOT<br>    Object             : typelib\{48e59290-9880-11cf-9754-00aa00c00908}<br><br> Adware.AdMedia Object Recognized!<br>    Type               : Regkey<br>    Data               : <br>    TAC Rating         : 10<br>    Category           : Adware<br>    Comment            : <br>    Rootkey            : HKEY_USERS<br>    Object             : S-1-5-21-242286658-708711241-2795454051-1008\software\microsoft\windows\currentversion\ext\stats\{72267f6a-a6f9-11d0-bc94-00c04fb67863}<br><br> BargainBuddy Object Recognized!<br>    Type               : Regkey<br>    Data               : <br>    TAC Rating         : 8<br>    Category           : Malware<br>    Comment            : <br>    Rootkey            : HKEY_USERS<br>    Object             : S-1-5-21-242286658-708711241-2795454051-1008\software\microsoft\windows\currentversion\ext\stats\{d27cdb6e-ae6d-11cf-96b8-444553540000}<br><br> Win32.Trojan.Agent Object Recognized!<br>    Type               : Regkey<br>    Data               : <br>    TAC Rating         : 10<br>    Category           : Virus<br>    Comment            : <br>    Rootkey            : HKEY_USERS<br>    Object             : S-1-5-21-242286658-708711241-2795454051-1008\software\microsoft\windows\currentversion\ext\stats\{b45ff030-4447-11d2-85de-00c04fa35c89}<br><br>Registry Scan result:<br>&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;&raquo;<br>New critical objects: 6<br>Objects found so far: 6<br><br>i didn't remove anything...THANKS for heads-up!  :)]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/Re-AdAware-Sept-12-Update-FP-16888736</guid>
<pubDate>Tue, 12 Sep 2006 13:17:09 EDT</pubDate>
</item>

<item>
<title>Re: Ad-Aware Sept. 12 Update - FP??</title>
<link>http://www.dslreports.com/forum/Re-AdAware-Sept-12-Update-FP-16888297</link>
<description><![CDATA[Chris 313 posted : <div class="bquote"><SMALL>said by <a href="/profile/679515" onClick="this.blur(); return popup(event,'/uidpop?ajh=1&uid=679515');">CalamityJane</a>:</SMALL><BR><BR>Hello GuestFromFrance,<br><br>Those are most likely false postives.  Just ignore them for now until Lavasoft Research has a chance to look at these, and then issue a corrected update.  :)<br> </DIV>I got those FPs as well and removed them. Was there any problem with that?]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/Re-AdAware-Sept-12-Update-FP-16888297</guid>
<pubDate>Tue, 12 Sep 2006 12:13:39 EDT</pubDate>
</item>

<item>
<title>Re: Ad-Aware Sept. 12 Update - FP??</title>
<link>http://www.dslreports.com/forum/Re-AdAware-Sept-12-Update-FP-16888283</link>
<description><![CDATA[CalamityJane posted : Hello GuestFromFrance,<br><br>Those are most likely false postives.  Just ignore them for now until Lavasoft Research has a chance to look at these, and then issue a corrected update.  :)]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/Re-AdAware-Sept-12-Update-FP-16888283</guid>
<pubDate>Tue, 12 Sep 2006 12:11:19 EDT</pubDate>
</item>

</channel>
</rss>
