spyware removal instructions

WhenU.SaveNow removal

Spyware WhenU.SaveNow Information
Name: WhenU.SaveNow
Category: Adware
Date: 2004-01-10
Dangerous: Yes
WhenU.SaveNow is Adware - spyware.
A single process runs at startup which records open IE windows & opens adverts when it sees targeted URLs & terms inputed into forms. Some distributions of this software were bundled with a "WhenUDownload" control. One of the most pervasive pieces of piggyback software is dubbed "SaveNow," created by a company called WhenU.com. Distributed along with BearShare, iMesh & the Global DivX player that allows people to monitor many online movies, it tracks where a person goes online & then pops up separate explorer windows with targeted advertisements or special offers... continuously downloads updated data about new offers & keeps a record of where a person surfs on that person´s own computer. It runs continually--even when the application it came with is not operating. Source Collects info on user’s gender, age, what area the person resides, & his or her e-mail address which they share with others. Other info collected: referrers [HTTP Referrers, Top-level Domains, Search Engines, Keywords, Quality Index, Frequency Index, Newsgroup Referrers, & E-mail Referrers], visitor statistics [Major ISPs, Hostnames, Explorers, OSes, Countries, Timezones, Plug-Ins, Screens, Colors, Java, & JavaScript], & more. You should remove it from your system as soon as possible.
WhenU.SaveNow description by publisher:
from the web-site: ´There are a vast number of great offers & services available throughout the Internet -- the problem is finding them when you need the information most. SaveNow is a application that brings you relevant offers & tells you about deals & similar sites when you surf the Web. Additionally, we negotiate a number of exclusive offers to maximize value for our users. SaveNow´s goal is to show users information about these offers & services - right at the moment when they need it. For example, if you went to a search engine & typed in "long distance", you might get an offer for SmartPrice - a site that we found to be the best for comparing long distance plans. We show these offers infrequently so as not to be intrusive. In fact, the average is one ad shown per person per day.´Creator: ´SAVE! is a application that brings you relevant offers & tells you about great deals & similar sites when you surf the web. It´s our strict policy to distribute SAVE! only to users who´ve accepted the SAVE! license agreement. SAVE! is installed on your computer as a module that comes with WhenUShop or other software that you downloaded from the Internet. At that time, you accepted a SAVE! license agreement as part of the download process you completed. - If you believe you´ve received SAVE! without accepting the license agreement, please let us know at legal@whenu.com. There are a vast number of great offers & services available on the Internet. Additionally, we negotiate a number of exclusive offers to maximize value for our users. SAVE!´s goal is to show users information about these offers & services - right at the moment when they need it. For example, if you go to a job search site, we might show you an offer for Hotjobs - which is right now offering great value to users that post resumes at their site. If you go to Staples, you might see an offer for a $30 off coupon that will save you money when you shop there. We show these offers infrequently so as not to be intrusive. SAVE! strictly protects person privacy in the following manner: * Personally identifiable information is NOT required in order to use the software * WhenU.com does NOT transmit URLS visited by the person to WhenU.com or any 3rd-party server * WhenU.com does NOT assemble personally-identifiable surfing proany file of users * WhenU.com does NOT assemble machine-identifiable surfing proany file of users * WhenU.com does NOT track which ads & offers are seen or clicked on by individual machines SAVE! is NOT spyware - there´s no persistent communication between your desktop computer & our servers. Users have noted that the application contacts our servers every once in a while - it does so in order to retrieve content from us & store that content on your computer, to make it available to you at the right moment. There´s one daily communication sent just to let us know that the software is functioning - nothing more (i.e. no collection of surfing history, etc). The desktop program checks for the presence of new explorer windows every 3 2nds - which results in sustained (but very low) CPU usage. Typically, data sent to the desktop is done in very small chunks of less than 4K - hardly noticeable. Upon installation, there´ll be some bandwidth usage as the initial content database is loaded - this is a one-time event. Very infrequently, there might be a sustained burst of data sent to the desktop - this would only be done if we: updated the desktop software itself (which we do from time to time to improve performance) or if we updated the entire content database. Again, these are one-time events - the program does NOT use bandwidth on a sustained basis. The software steals up only slightly more RAM than your IE explorer control uses in any case (it shares RAM with it) & is designed to be non-intrusive & non-invasive.´
This Adware is also known as:
Adware/Lop - named by Panda.
Adware/SaveNow - named by Panda.
Adware/WeatherCast - named by Panda.
Adware-SaveNow - named by McAfee.
TrojanDownloader.Win32.Swizzor.bf - named by Kaspersky.
TrojanDownloader.Win32.Swizzor.br - named by Kaspersky.

>> Delete WhenU.SaveNow automatically - Download Spyware Doctor

WhenU.SaveNow Removal Instructions
Kill the following processes
648.exe, bsaveinstwm.exe, saveinstcm.exe, extra.exe, imwmkspe.exe, nowbox.exe, 26cb489e.exe, bf.exe, eantho~1.exe, fixit.exe, saveinstcm.exe, oe8yydvxm.exe, saveinstwm.exe, savenowinst.exe, se.exe, sta5f0.exe, sta70.exe, unie.tmp.exe, upd126.exe, winupdate17.exe, oi.exe, privacyurl.exe, sepinst.exe, webstats.exe, cm216prd.patch.exe, savenowinst.exe, savenow.exe, uninst.exe, save.exe, saveuninst.exe, setup_wm.exe, epakucmzh.exe, savenowinst.exe, saveinstwm.exe, viewmgrinstaller.exe, vmpremov.exe, war3_install.exe, weather.exe, wildwintracker.exe
Unregister the following DLLs and reboot
cmdlineext02.dll, cnbabe.dll, googletoolbar_en_2.0.92-big.dll, i.dll, msimmsgr.dll, msimnetc.dll, onlinechk.dll, sndbmark.dll, systra~1.dll, utdns.dll.
0jt87pl3.dll, 0l.dll, 0x6numrs.dll, 1.dll, 193tix.dll, 2hwct3u.dll, 2ms.dll, 3g4rumy.dll, 3gigj.dll, 3s.dll, 4q.dll, 4yjnjx7op.dll, 57sc.dll, 5tla41db.dll, 5vr5fawq.dll, 6d2bq.dll, 7bk.dll, 7e.dll, 7ibnw.dll, 7tfzvhjhj.dll, 8e9xkrpy.dll, 8opuz.dll, 8z8b.dll, 97.dll, 98n78x.dll, ae.dll, af74zp5m.dll, ags.dll, aizv8c.dll, as.dll, asvzm.dll, aw2.dll, ayjurejx.dll, b8he8.dll, bc0sy6wo.dll, bkcsq.dll, bpj00.dll, bu.dll, bvc.dll, c32tx.dll, c5ry.dll, cbza.dll, ccrgdqmj2.dll, cd.dll, cj1tj4fwt.dll, cqtjeyx.dll, d2r4q2s.dll, dbbjb.dll, dbh45nm.dll, dmqg00afn.dll, ds.dll, dune.dll, dwhruoy.dll, e.dll, ed3a00g.dll, eggc.dll, exmuj.dll, f5psvz.dll, f8vbin.dll, ff5ne1.dll, fuaru.dll, fuc09vc.dll, fyagg18bz.dll, giu1v.dll, gj.dll, gjh986vky.dll, gr7wpxitz.dll, gz4qozx.dll, hlx77wu.dll, i7qjx.dll, ilmdr.dll, ipxwry.dll, iqfke.dll, ir.dll, iueal.dll, jbzv2z.dll, jftjjgxw.dll, jnyl.dll, julfh.dll, jy.dll, kdt3.dll, kidcfz.dll, kk2yp62.dll, ktwjn.dll, kvp6.dll, kz.dll, kzcrqcdf.dll, l0c.dll, l0iv.dll, l2bffxx.dll, lb3d.dll, lcm.dll, lhncp3u2v.dll, lj.dll, llbepkj.dll, m5dx7rs0q.dll, m7.dll, m9gl.dll, mbxded.dll, mhzi2sa.dll, mqqk.dll, ms72xf.dll, n6oa477t.dll, n9zyim.dll, nea0wp.dll, ni.dll, njh96v.dll, no.dll, np.dll, nqnx9nu.dll, nsdtmp09.dll, nxqb.dll, nyk.dll, omu.dll, or2qc1wzm.dll, owgpjqxob.dll, oy.dll, p.dll, p6pyiax.dll, pobm2.dll, pp501pao.dll, pvf.dll, px.dll, q.dll, q1mho1rg1.dll, qaek.dll, qcblffnn.dll, qkwko.dll, qt.dll, qt4xvs.dll, qtcbmid.dll, qvpjfoevy.dll, r2jjoo.dll, r8zmm3rh.dll, rg4ohwe.dll, rhnbu.dll, rmu8.dll, roa8fve.dll, rssyu0y0.dll, rsyom2jq8.dll, sboz30w.dll, sgmomc.dll, sq188im.dll, t1or3u.dll, telfdwv9.dll, u3rfgryzl.dll, uc88.dll, ujlexzk.dll, ukds.dll, uocjrz.dll, uowsp.dll, v.dll, vhsk.dll, voxjsh.dll, vru.dll, vrzy0vj.dll, vyz.dll, vzhrpg8b.dll, w6k.dll, wcbll0.dll, we.dll, wkzd9dv.dll, wllpeqe.dll, wnust.dll, wode.dll, wtx.dll, wv.dll, wvrm.dll, wvzoly.dll, wwrcy.dll, x62nlx.dll, xepy2w.dll, xkos.dll, xmvadfv.dll, xqh.dll, xua.dll, y1r.dll, y3e.dll, y5llkd8.dll, yq20.dll, z.dll, z0mja7i84.dll, z2.dll, zb.dll, zi.dll, zo7x7bdv.dll, zroj.dll, zxy82p.dll in Documents and Settings\UserName\local settings\temp\
iadhide3.dll, m.dll in Documents and Settings\UserName\locals~1\temp\
runmsc.dll in Program Files\bearshare\
msvcp50.dll in Windows\lastgood\system32\
iehelpermiddleman.dll, windmy.dll, winnb52.dll in Windows\system32\
Delete these registry entries
HKEY_CLASSES_ROOT\clsid\{c285d18d-43a2-4aef-83fb-bf280e660a97}
HKEY_CLASSES_ROOT\clsid\{e2f2b9d0-96b9-4b25-b90c-636ecb207d18}
HKEY_CLASSES_ROOT\clsid\{fee7fd53-3356-4d4d-8978-2c4ae3a7e109}
HKEY_CLASSES_ROOT\typelib\{e2f2b9d0-96b9-4b25-b90c-636ecb207d18}
HKEY_CLASSES_ROOT\typelib\{fc327b3f-377b-4cb7-8b61-27cd69816bc3}
HKEY_CURRENT_USER\software\whenu
HKEY_LOCAL_MACHINE\software\classes\clsid\{9f95f736-0f62-4214-a4b4-caa6738d4c07}
HKEY_LOCAL_MACHINE\software\classes\interface\{c285d18d-43a2-4aef-83fb-bf280e660a97}
HKEY_LOCAL_MACHINE\software\classes\runmsc.loader.1\clsid
HKEY_LOCAL_MACHINE\software\classes\runmsc.loader\clsid
HKEY_LOCAL_MACHINE\software\classes\runmsc.loader\curver
HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\app management\arpcache\savenow\changed
HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\app management\arpcache\savenow\slowinfocache
HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\app management\arpcache\whenusearch\changed
HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\app management\arpcache\whenusearch\slowinfocache
HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\browser helper objects\{9a9c9b69-f908-4aab-8d0c-10ea8997f37e}
HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\moduleusage\c:/winnt/downloaded program files/mirarsetup.exe\.owner
HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\moduleusage\c:/winnt/downloaded program files/mirarsetup.exe\{8a0dcbda-6e20-489c-9041-c1e8a0352e75}
HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\moduleusage\c:/winnt/downloaded program files/sndbmark.dll
HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\moduleusage\c:/winnt/downloaded program files/sndbmark.dll\.owner
HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\moduleusage\c:/winnt/system32/windmy.dll\.owner
HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\moduleusage\c:/winnt/system32/windmy.dll\{8a0dcbda-6e20-489c-9041-c1e8a0352e75}
HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run\savenow
HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\runonce\remove at boot 902
HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\shareddlls\c:\winnt\downloaded program files\conflict.1\sndbmark.dll
HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\shareddlls\c:\winnt\downloaded program files\sndbmark.dll
HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\uninstall\gdivx
HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\uninstall\savenow
HKEY_LOCAL_MACHINE\software\whenu
HKEY_LOCAL_MACHINE\software\whenusave\partners\wusv
HKEY_USERS\.default\software\whenu
Remove the following files
648.exe, bad_navigation.htm, bad_navigationmain.htm, bearshare.txt, bsaveinstwm.exe, clocksync.lnk, cmdlineext02.dll, cnbabe.dll, extra.exe, favsrch.cnt, five roses.url, googletoolbar_en_2.0.92-big.dll, history.txt, hosts.dat, i.dll, iehelpermiddleman.tlb, imwmkspe.exe, ins4.tmp-2052ade5.pf, install.log, j001.nbd, make money.url, msimmsgr.dll, msimnetc.dll, nowbox.exe, nowbox.lnk, offline.htm, offlinemain.htm, onlinechk.dll, onluck.url, readme.txt, regicon.ocx, save.cch, save.db, save.exe, save.exe-010b9488.pf, save.htm, saveinstwmcm.exe-0fbee63c.pf, savenow.exe-20ebc7a1.pf, savenow.txt, savenowinst.exe-16e4b0f9.pf, savenowupdate.exe-2bd98bf5.pf, saveuninst.exe, saveupdate.exe-3b3c44d5.pf, scecomp.old, setup_wm.exe, short.acs, sndbmark.dll, sportsinteraction.com.url, systra~1.dll, unins000.dat, uninstall nowbox.lnk, utdns.dll, viewmgrinstaller.exe, vmpremov.exe, vssver.scc, war3_install.exe, weather.exe, webstats.bat, webstats.ini, wildwintracker.exe.
saveinstcm.exe in c:\
whenusearch desktop toolbar.lnk in Documents and Settings\UserName\administrator\start menu\programs\whenusearch\
bonzibuddy.lnk, finish installing....lnk in Documents and Settings\UserName\desktop\
0ehtyh2d.htm, 0jt87pl3.dll, 0l.dll, 0x6numrs.dll, 1.dll, 108b.html, 108f.html, 139b.html, 139f.html, 193tix.dll, 26cb489e.exe, 2hwct3u.dll, 2kudarvt.htm, 2ms.dll, 3g4rumy.dll, 3gigj.dll, 3s.dll, 4q.dll, 4yjnjx7op.dll, 57sc.dll, 5bp4qeaz.htm, 5lpvzu07.htm, 5nmek0x2.htm, 5tla41db.dll, 5vr5fawq.dll, 6d2bq.dll, 77b.html, 77f.html, 7bk.dll, 7e.dll, 7ibnw.dll, 7pkvo3av.htm, 7tfzvhjhj.dll, 8e9xkrpy.dll, 8opuz.dll, 8z8b.dll, 97.dll, 98n78x.dll, ae.dll, af74zp5m.dll, ags.dll, aizv8c.dll, as.dll, asvzm.dll, aw2.dll, aydhfnh3.htm, ayjurejx.dll, b8he8.dll, bc0sy6wo.dll, bf.exe, bkcsq.dll, bpj00.dll, bu.dll, bvc.dll, c32tx.dll, c5ry.dll, cbza.dll, ccrgdqmj2.dll, cd.dll, cj1tj4fwt.dll, cqtjeyx.dll, cygj6daf.htm, czvkvfkc.htm, d2r4q2s.dll, dbbjb.dll, dbh45nm.dll, dmqg00afn.dll, ds.dll, dune.dll, dwhruoy.dll, e.dll, e0ipbie7.htm, eantho~1.exe, ed3a00g.dll, eggc.dll, exmuj.dll, f5psvz.dll, f8vbin.dll, f9blssn7.htm, ff5ne1.dll, fixit.exe, fn7w9t62.htm, fuaru.dll, fuc09vc.dll, fyagg18bz.dll, giu1v.dll, gj.dll, gjh986vky.dll, gjp8a1eb.htm, gr7wpxitz.dll, gz4qozx.dll, hcdd90rc.htm, hlx77wu.dll, i570ufys.htm, i7qjx.dll, ilmdr.dll, ipxwry.dll, iqfke.dll, ir.dll, iueal.dll, jbzv2z.dll, jftjjgxw.dll, jnyl.dll, julfh.dll, jy.dll, kdt3.dll, kidcfz.dll, kk2yp62.dll, ktwjn.dll, kvp6.dll, kz.dll, kzcrqcdf.dll, l0c.dll, l0iv.dll, l2bffxx.dll, lb3d.dll, lcm.dll, lhncp3u2v.dll, lj.dll, llbepkj.dll, m5dx7rs0q.dll, m7.dll, m9gl.dll, mbxded.dll, mhzi2sa.dll, mqqk.dll, ms72xf.dll, mso5f90b.doc, mso6ffdd.doc, msoa15fd.doc, msodc106.doc, msoecc9e.doc, n6oa477t.dll, n9zyim.dll, nea0wp.dll, ni.dll, njh96v.dll, no.dll, np.dll, nqnx9nu.dll, nsdtmp09.dll, nxqb.dll, nyk.dll, oe8yydvxm.exe, omu.dll, or2qc1wzm.dll, owgpjqxob.dll, oy.dll, p.dll, p6pyiax.dll, pobm2.dll, pp501pao.dll, pvf.dll, px.dll, q.dll, q1mho1rg1.dll, qaek.dll, qcblffnn.dll, qkwko.dll, qt.dll, qt4xvs.dll, qtcbmid.dll, qvpjfoevy.dll, r2jjoo.dll, r8zmm3rh.dll, rg4ohwe.dll, rhnbu.dll, rmu8.dll, rn1f.htm, roa8fve.dll, rssyu0y0.dll, rsyom2jq8.dll, saveinstwm.exe, savenowinst.exe, sboz30w.dll, se.exe, sgmomc.dll, sq188im.dll, sta5f0.exe, sta70.exe, t1or3u.dll, telfdwv9.dll, tzh5a5wm.htm, u3rfgryzl.dll, uc88.dll, ujlexzk.dll, ukds.dll, unie.tmp.exe, uocjrz.dll, uowsp.dll, upd126.exe, v.dll, vhsk.dll, voxjsh.dll, vru.dll, vrzy0vj.dll, vyz.dll, vzhrpg8b.dll, w6k.dll, wcbll0.dll, we.dll, winupdate17.exe, wkzd9dv.dll, wllpeqe.dll, wnust.dll, wode.dll, wtx.dll, wv.dll, wvrm.dll, wvzoly.dll, wwrcy.dll, x62nlx.dll, xepy2w.dll, xkos.dll, xmvadfv.dll, xqh.dll, xua.dll, y1r.dll, y3e.dll, y5llkd8.dll, yq20.dll, z.dll, z0mja7i84.dll, z2.dll, zb.dll, zi.dll, zo7x7bdv.dll, zroj.dll, zxy82p.dll in Documents and Settings\UserName\local settings\temp\
clocksyncinst.inf, saveinstcm.exe in Documents and Settings\UserName\local settings\temp\icd1.tmp\
setup.inf in Documents and Settings\UserName\local settings\temp\icd2.tmp\
art therapy recommendations.doc in Documents and Settings\UserName\local settings\temp\temporary directory 1 for types of attachment-delaney's info.zip\
notes on art therapy with adolescents.doc in Documents and Settings\UserName\local settings\temp\temporary directory 2 for types of attachment-delaney's info.zip\
desktop.ini in Documents and Settings\UserName\local settings\temp\temporary internet files\content.ie5\4bk5wz2f\
desktop.ini in Documents and Settings\UserName\local settings\temp\temporary internet files\content.ie5\4lifodef\
aaform[2].htm, adspopup2[1].js, adswrapperaim[1].js, ads[1].htm, ads[2].htm, antispy_pie_01[1].htm, aol[1].htm, aol[2].htm, av2[1].js, casale-ef-apr04[1].htm, clips[1].htm, ctrl_poll[1].js, ctrl_tree[1].js, desktop.ini, formie[1].css, fphoverx[1].class, framer[1].htm, framer[2].htm, frm_previewpane[1].js, front[1].htm, index[1].htm, olympiansearch-atomz[1].js, owacolors[1].css, popup6[1].htm, popup7[1].htm, preload[1].htm, search0211[1].css, stylesheet[1].css, xuron_l[1].js in Documents and Settings\UserName\local settings\temp\temporary internet files\content.ie5\7bjxv3tl\
desktop.ini in Documents and Settings\UserName\local settings\temp\temporary internet files\content.ie5\c3cb0h6d\
85620_arc[1].htm, alttxt[1].js, aol[1].htm, blank[1].htm, broadband6[1].css, cnn_allpolitics_dems.rnc[1].htm, common[1].js, ctrl_view[1].js, desktop.ini, feb04[1].htm, hat100[1].js, index[1].html, keep_alive[1].htm, keep_alive[2].htm, land3[1].js, main[1].js, owa.seattleu[1].htm, style30[1].css, stylesheet[1].css, s_code[1].js, theolympian-widget4[1].js, track4[1].htm, util_buttons[1].js, util_forms[1].js, util_owa[2].js, vw_message[1].js, warwithiraq_350x350_2[1].htm, zipcode[2].htm in Documents and Settings\UserName\local settings\temp\temporary internet files\content.ie5\ehm9otgx\
desktop.ini in Documents and Settings\UserName\local settings\temp\temporary internet files\content.ie5\glyzkter\
desktop.ini in Documents and Settings\UserName\local settings\temp\temporary internet files\content.ie5\gpab8tgn\
aim_uac[1].htm, aim_uac[2].htm, aim_uac[3].htm, aol[1].htm, aol[2].htm, ctrl_notify[1].js, ctrl_reminder[1].js, desktop.ini, exitpop[1].htm, fphover[1].class, itms[1].js, keep_alive[1].htm, keep_alive[2].htm, main[1].css, main[1].htm, mcafee[1].css, misc[1].js, omniture[1].js, pop[1].htm, ticker[1].js, track1[1].htm, util_view[1].js, verbnow[1].htm, vpinet[1].css, welcome[2].htm in Documents and Settings\UserName\local settings\temp\temporary internet files\content.ie5\oh6bkxqf\
desktop.ini in Documents and Settings\UserName\local settings\temp\temporary internet files\content.ie5\ohiboluz\
desktop.ini in Documents and Settings\UserName\local settings\temp\temporary internet files\content.ie5\op6f0t2j\
desktop.ini in Documents and Settings\UserName\local settings\temp\temporary internet files\content.ie5\ovafk967\
040804dshs3[2].htm, adsend[1].js, adswrapper[1].js, aimtoday[1].htm, aol[1].htm, aol[2].htm, blank[1].htm, comicbook[1].css, dalai_llama[1].js, desktop.ini, framer[1].htm, frm_readnote[1].js, horizontal_navbar[1].css, index-data[1].html, index_ie[1].css, mm_menu[1].js, off_framer[1].htm, owastyle[1].css, show_ads[2].js, ticker[1].css, util_recipients[1].js, video_donovan_04_001[1].htm, vw_navbar[1].js in Documents and Settings\UserName\local settings\temp\temporary internet files\content.ie5\uj8pnhsq\
conflict.inf in Documents and Settings\UserName\local settings\temp\thi6401.tmp\
index.html in Documents and Settings\UserName\local settings\temp\~dlfntmp0\
index.html in Documents and Settings\UserName\local settings\temp\~dlfntmp1\
index.html in Documents and Settings\UserName\local settings\temp\~dlfntmp2\
index.html in Documents and Settings\UserName\local settings\temp\~dlfntmp3\
index.html in Documents and Settings\UserName\local settings\temp\~dlfntmp4\
index.html in Documents and Settings\UserName\local settings\temp\~dlfntmp5\
index.html in Documents and Settings\UserName\local settings\temp\~dlfntmp6\
index.html in Documents and Settings\UserName\local settings\temp\~dlfntmp7\
index.html in Documents and Settings\UserName\local settings\temp\~dlfntmp8\
index.html in Documents and Settings\UserName\local settings\temp\~dlfntmp9\
iadhide3.dll, ihkjdx41.htm, jg0gf6zw.htm, k81n7qhi.htm, kbcywxrn.htm, kx4ceojq.htm, lub7cqpv.htm, m.dll, msview.inf, ndr112.tmp.html, ndwnhr6l.htm, notmljqt.htm, oi.exe, ougz2u1j.htm, our36tvb.htm, pf3mc4bk.htm, privacyurl.exe, ptrchtxe.htm, qawqijgy.htm, qe6ucylp.htm, qrvdpjgk.htm, rhbo41ms.htm, rt3e9jyf.htm, rvyn1n7u.htm, s0uq8sd5.htm, sentry.inf, sentry.ini, sepinst.exe, t3zjtccy.htm, t9w1782b.htm in Documents and Settings\UserName\locals~1\temp\
runmsc.dll, webstats.exe in Program Files\bearshare\
cm216prd.patch.exe in Program Files\broadjump\client foundation\updatestaging\
s.class in Program Files\ebatesmoemoneymaker\system\code\
savenowinst.exe in Program Files\imesh\client\
savenow.db, savenow.exe, savenow.htm, uninst.exe in Program Files\savenow\
epakucmzh.exe in Windows\
msvcp50.dll in Windows\lastgood\system32\
iehelpermiddleman.dll, windmy.dll, winnb52.dll in Windows\system32\
saveinstwm.exe in Windows\temp\
savenowinst.exe in Windows\temp\adware\
Remove the following directories
Desktop\sportsinteraction.com.url
Documents and Settings\UserName\start menu\programs\whenusearch
Program Files\savenow

Bookmark WhenU.SaveNow page

 Previous Spyware: Remove WhenU.Desktop Toolbar Next Spyware: Remove WhenU.Sidefinder