Tali_Abdn Posted February 23, 2011 Every time i scan my computer the same threats are detected. SAS removes them, then reboots the computer but when i scan again they are still detected. The log of the scan is below: Application Version : 4.48.1000 Core Rules Database Version : 6444 Trace Rules Database Version: 4256 Scan type : Complete Scan Total Scan Time : 00:58:14 Memory items scanned : 566 Memory threats detected : 0 Registry items scanned : 9112 Registry threats detected : 20 File items scanned : 38124 File threats detected : 18 Adware.Tracking Cookie C:\Users\Claire\AppData\Roaming\Microsoft\Windows\Cookies\claire@cts.metricsdirect[1].txt C:\Users\Claire\AppData\Roaming\Microsoft\Windows\Cookies\claire@content.licenseacquisition[3].txt C:\Users\Claire\AppData\Roaming\Microsoft\Windows\Cookies\claire@media.licenseacquisition[2].txt C:\Users\Claire\AppData\Roaming\Microsoft\Windows\Cookies\claire@cts.zroitracker[1].txt C:\Users\Claire\AppData\Roaming\Microsoft\Windows\Cookies\claire@media.licenseacquisition[1].txt C:\Users\Claire\AppData\Roaming\Microsoft\Windows\Cookies\claire@media.licenseacquisition[3].txt C:\Users\Claire\AppData\Roaming\Microsoft\Windows\Cookies\Low\claire@ad.yieldmanager[2].txt C:\Users\Claire\AppData\Roaming\Microsoft\Windows\Cookies\Low\claire@ads.pubmatic[1].txt C:\Users\Claire\AppData\Roaming\Microsoft\Windows\Cookies\Low\claire@adserve.tescofinance[1].txt C:\Users\Claire\AppData\Roaming\Microsoft\Windows\Cookies\Low\claire@adtech[2].txt C:\Users\Claire\AppData\Roaming\Microsoft\Windows\Cookies\Low\claire@apmebf[1].txt C:\Users\Claire\AppData\Roaming\Microsoft\Windows\Cookies\Low\claire@atdmt[2].txt C:\Users\Claire\AppData\Roaming\Microsoft\Windows\Cookies\Low\claire@bs.serving-sys[1].txt C:\Users\Claire\AppData\Roaming\Microsoft\Windows\Cookies\Low\claire@doubleclick[1].txt C:\Users\Claire\AppData\Roaming\Microsoft\Windows\Cookies\Low\claire@invitemedia[1].txt C:\Users\Claire\AppData\Roaming\Microsoft\Windows\Cookies\Low\claire@mediaplex[2].txt C:\Users\Claire\AppData\Roaming\Microsoft\Windows\Cookies\Low\claire@richmedia.yahoo[1].txt C:\Users\Claire\AppData\Roaming\Microsoft\Windows\Cookies\Low\claire@serving-sys[1].txt Adware.Zango/ShoppingReport HKCR\Interface\{30B15818-E110-4527-9C05-46ACE5A3460D} HKCR\Interface\{30B15818-E110-4527-9C05-46ACE5A3460D}\ProxyStubClsid HKCR\Interface\{30B15818-E110-4527-9C05-46ACE5A3460D}\ProxyStubClsid32 HKCR\Interface\{30B15818-E110-4527-9C05-46ACE5A3460D}\TypeLib HKCR\Interface\{30B15818-E110-4527-9C05-46ACE5A3460D}\TypeLib#Version HKCR\Interface\{618AAD04-921F-44C2-BE38-C0818AF69861} HKCR\Interface\{618AAD04-921F-44C2-BE38-C0818AF69861}\ProxyStubClsid HKCR\Interface\{618AAD04-921F-44C2-BE38-C0818AF69861}\ProxyStubClsid32 HKCR\Interface\{618AAD04-921F-44C2-BE38-C0818AF69861}\TypeLib HKCR\Interface\{618AAD04-921F-44C2-BE38-C0818AF69861}\TypeLib#Version HKCR\Interface\{B5D2ED96-62F9-4C2C-956D-E425B1F67337} HKCR\Interface\{B5D2ED96-62F9-4C2C-956D-E425B1F67337}\ProxyStubClsid HKCR\Interface\{B5D2ED96-62F9-4C2C-956D-E425B1F67337}\ProxyStubClsid32 HKCR\Interface\{B5D2ED96-62F9-4C2C-956D-E425B1F67337}\TypeLib HKCR\Interface\{B5D2ED96-62F9-4C2C-956D-E425B1F67337}\TypeLib#Version HKCR\Interface\{D3A412E8-1E4B-47D2-9B12-F88291F5AFBB} HKCR\Interface\{D3A412E8-1E4B-47D2-9B12-F88291F5AFBB}\ProxyStubClsid HKCR\Interface\{D3A412E8-1E4B-47D2-9B12-F88291F5AFBB}\ProxyStubClsid32 HKCR\Interface\{D3A412E8-1E4B-47D2-9B12-F88291F5AFBB}\TypeLib HKCR\Interface\{D3A412E8-1E4B-47D2-9B12-F88291F5AFBB}\TypeLib#Version Any advice on how i can get rid of these items for good? Share this post Link to post Share on other sites
SUPERAntiSpy Posted February 24, 2011 Are you placing a check mark next to those as they may be notifications and not checked by default. Share this post Link to post Share on other sites
Tali_Abdn Posted February 24, 2011 Yes, I have checked and the boxes are checked. They are automatically checked when the screen comes up. However, to be sure I have unchecked them and then checked them again before clicking NEXT. The process apears to quartine/remove them and then asks me to reboot to complete the removal. If i select no, it tells me the system is still infected. If i reboot and then scan again the same items appear. Share this post Link to post Share on other sites
Tali_Abdn Posted February 25, 2011 SAS managed to remove the threats yesterday. I updated (after seledting "run as admin") and rescanned. Happ Happy! Share this post Link to post Share on other sites
siliconman01 Posted February 27, 2011 SAS V4.49.1000 is available for upgrading your V4.48.1000 One thing you can do to correct the initial problem is: 1. Using Windows Explorer, navigate to the SuperAntispyware folder at C:\Program Files\Superantispyware and open the folder. 2. Right click on the file SuperAntiSpyware.exe and select Properties from the menu. 3. When the Properties window opens, select the Compatibility tab. 4. Under Privilege Level, check mark "Run this program as an administrator". 5. Click on Apply and OK 6. Shut down and then restart SuperAntiSpyware That should resolve your problem for the future. Share this post Link to post Share on other sites