Wow... just... wow. I'm glad I had Microsoft AntiSpyware protecting me
Well, let's see. I got about 5 alert popups, telling me things about a
BHO (which I can only assume is the toolbar; even though I blocked it it's still there
), a
startup entry for something called 'Dead clock.exe', an
Internet Explorer homepage change, an
IE search page change, and something else that I can't remember right now. I'll try and find out what it is when my scan is finished
. I also got 2 icons on my desktop, 'Casino Online' and 'Poker'. Even my
Firefox start page was changed and I had a tough time setting it back.
Now I know why everyone's so pissed when they install the sponsor...
[Edit] Here's some more detailed stuff:
==================================================
Startup Registry Entry: StartUp dead clock.exe dead clock.exe
Disabled date: 3/22/2005 8:52:17 PM
Details: Startup Registry Entry deactivated
Registry Key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run jump global way open = C:\Documents and Settings\All Users.WINDOWS\Application Data\five draw jump global\Dead clock.exe deactivated on
==================================================
The Internet Explorer URL for your Search Bar is attempting to be changed from
http://www.laqssafzxdoa.net/rvYNS6HRkhu3Oev05yxku...nXx64PdBK/tADP.htm to
http://www.ozndhabtqcbovsagoyeuau.com/rvYNS6HRkhu...waK4PdBK/tADP.html.
The default URL for your Search Bar is
http://home.microsoft.com/search/lobby/search.asp.
=================================================
Browser Helper Object: BHO amenrdr.exe {20F207D9-FDDA-CAA9-C50F-18A78331EBFE}
Disabled date: 3/22/2005 8:56:28 PM
Details: Browser Helper Object deactivated
Registry Key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{20F207D9-FDDA-CAA9-C50F-18A78331EBFE} decativated on
==================================================
Microsoft AntiSpyware has detected a Browser Helper Object trying to be added. A BHO is an application that extends Internet Explorer and acts as a plug-in allowing the BHO full control of Internet Explorer.
Name: amenrdr.exe
Path: c:\docume~1\george~1.chr\applic~1\surfme~1\amenrdr.exe
=================================================
I just looked at CodeStuff Starter to see what else it had added to my startup that Microsoft AntiSpyware missed, and I found 'okay beep.exe', located at C:\DOCUME~1\GEORGE~1.CHR\APPLIC~1\FIRSTR~1\trans store.exe
In conclusion: can't the sponsor be just a toolbar?