spyware removal instructions

SAHAgent removal

Spyware SAHAgent Information
Name: SAHAgent
Category: Spyware
Date: 2005-07-08
Dangerous: Yes
SAHAgent is a spyware application that replaces affiliate ids in cookies and web pages with its own. This way it steals money from hard-working webmasters and indirectly reduces the quality of internet.
This Spyware is also known as:
Sah Agent

>> Delete SAHAgent automatically - Download Spyware Doctor

SAHAgent Removal Instructions
Kill the following processes
1buu2qs7.exe, 56olj8bb.exe, 70tovmto.exe, a95kfrhe.exe, ap9h4qmo.exe, apphelp3.exe, bundlelite_westfrontier1001.exe, cleansahagent.exe, installer_marketing12.exe, octj45j5.exe, plm6fu2h.exe, sahdownloader_.exe, bundle.exe, q17i9a4j.exe, qlep5ad6.exe, sahagent-cdt1004.exe, sahpackage.exe, service.exe, 1bri6flm.exe, sahagent_.exe, sahdownloader_.exe, sahhtml_.exe, sahuninstall_.exe, poh.exe, sahuninstall.exe, sahdownloader.exe, gah95on6.exe, sahagent.exe, sahagent1019.exe, sahdownloader.exe, sahhtml.exe, bundle.exe, u6f6uftuc_.exe, uabal85u.exe, ucmoreiex.exe, uvv211ra.exe, wuamgrd.exe
Unregister the following DLLs and reboot
egdaccess_1057.dll, egdaccess_1058.dll, netslv32.dll, qh4mkbv9.dll, u7tqoeep.dll, webinstaller.dll.
lsp_.dll, xmlparse_.dll, xmltok_.dll in Windows\downloaded program files\
atpartners.dll, bks.dll, lsp.dll in Windows\system32\
lsp.dll in Windows\system\
Delete these registry entries
HKEY_CLASSES_ROOT\clsid\{30402ff4-3e71-4a1c-9b4b-1cd3486a9fb2}
HKEY_CLASSES_ROOT\interface\{4828c95f-c5db-4ab6-a945-8d8ec44b98a8}
HKEY_CLASSES_ROOT\interface\{4e570f74-deee-4fcf-b960-feefa4b8c6fc}
HKEY_CLASSES_ROOT\typelib\{cde442a3-dc2c-467e-a311-b4bc775d86c5}
HKEY_CLASSES_ROOT\webinstaller.execute
HKEY_LOCAL_MACHINE\software\classes\webinstaller.execute
HKEY_LOCAL_MACHINE\software\classes\webinstaller.execute\clsid
HKEY_LOCAL_MACHINE\software\classes\webinstaller.execute\curver
HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\app management\arpcache\shopathomeselect agent\changed
HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\app management\arpcache\shopathomeselect agent\slowinfocache
HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\moduleusage\c:/winnt/downloaded program files/sahdownloader_.exe\{30402ff4-3e71-4a1c-9b4b-1cd3486a9fb2}
HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run\ap9h4qmo
HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run\gah95on6
HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run\sahagent
HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run\sahbundle
HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\uninstall\shopathomeselect agent
HKEY_LOCAL_MACHINE\software\vgroup
HKEY_LOCAL_MACHINE\software\vgroup\sahagent
Remove the following files
1buu2qs7.exe, 56olj8bb.exe, 70tovmto.exe, a95kfrhe.exe, ap9h4qmo.exe, ap9h4qmo.ini, apphelp3.exe, baur5s9q.dat, bqrufs5f.dat, bundlelite_westfrontier1001.exe, cleansahagent.dof, cleansahagent.exe, egdaccess.inf, egdaccess_1057.dll, egdaccess_1058.dll, info.txt, installer_marketing12.exe, messagebody.txt, messagehistory.txt, netslv32.dll, netslv32.inf, ntmsjrnl, octj45j5.exe, p1ratjju.ini, pestinfoimportme.txt, plm6fu2h.exe, q10pvbrv.dat, q17i9a4j.exe, qh4mkbv9.dll, qlep5ad6.exe, sahagent-cdt1004.exe, sahpackage.exe, service.exe, setup.inf, tmpmpt1.tmp, u6f6uftuc_.exe, u7tqoeep.dll, uabal85u.exe, ucmoreiex.exe, uvv211ra.exe, v.dat, vg.dat, vp.dat, webinstaller.dll, wuamgrd.exe.
sahagent.log in c:\
goldenretrievereula.txt.lnk, shopathome.lnk, shopathomememberagreement.txt.lnk, shopathomeprivacy.txt.lnk in Documents and Settings\UserName\administrator\recent\
sahdownloader_.exe in Documents and Settings\UserName\local settings\temp\sahupdate\
bundle.exe in Documents and Settings\UserName\locals~1\temp\
1bri6flm.exe, 1bri6flm.ini, poh.exe, redir.txt, sahuninstall.exe in Windows\
lsp_.dll, sahagent_.exe, sahdownloader_.exe, sahhtml_.exe, sahuninstall_.exe, xmlparse_.dll, xmltok_.dll in Windows\downloaded program files\
atpartners.dll, bks.dll, gah95on6.exe, lsp.dll, lsp.xx, sahagent.exe, sahagent1019.exe, sahdownloader.exe, sahhtml.exe in Windows\system32\
lsp.dll, sahdownloader.exe in Windows\system\
bundle.exe in Windows\temp\
Remove the following directories
Windows\system32\sahimages

Bookmark SAHAgent page

 Previous Spyware: Remove SageAnalyst Next Spyware: Remove Sailorc.mybravenet Tracking Cookie