SUPERAntiSpyware Scan LogFile/Folder C:\Program Files\Uninstall Fun Web Products.dll not found.
File/Folder C:\Program Files\RXToolBar not found.
File/Folder C:\Program Files\Messenger\hoketoh not found.
File/Folder C:\WINDOWS\system32\mr9 not found.
[Custom Input]
< purity >
OTMoveIt2 v1.0.15 log created on 01272008_165751
http://www.superantispyware.comGenerated 01/27/2008 at 04:47 PM
Application Version : 3.9.1008
Core Rules Database Version : 3389
Trace Rules Database Version: 1383
Scan type : Complete Scan
Total Scan Time : 02:35:19
Memory items scanned : 558
Memory threats detected : 0
Registry items scanned : 5179
Registry threats detected : 74
File items scanned : 76654
File threats detected : 498
Adware.MyWay
HKLM\Software\Classes\CLSID\{014DA6C9-189F-421a-88CD-07CFE51CFF10}
HKCR\CLSID\{014DA6C9-189F-421A-88CD-07CFE51CFF10}
HKCR\CLSID\{014DA6C9-189F-421A-88CD-07CFE51CFF10}
HKCR\CLSID\{014DA6C9-189F-421A-88CD-07CFE51CFF10}\InprocServer32
C:\PROGRAM FILES\NEED2FIND\BAR\1.BIN\ND2FNBAR.DLL
Adware.RX Toolbar
HKLM\Software\Classes\CLSID\{25D8BACF-3DE2-4B48-AE22-D659B8D835B0}
HKCR\CLSID\{25D8BACF-3DE2-4B48-AE22-D659B8D835B0}
HKCR\CLSID\{25D8BACF-3DE2-4B48-AE22-D659B8D835B0}
HKCR\CLSID\{25D8BACF-3DE2-4B48-AE22-D659B8D835B0}\InprocServer32
HKCR\CLSID\{25D8BACF-3DE2-4B48-AE22-D659B8D835B0}\InprocServer32#ThreadingModel
HKCR\CLSID\{25D8BACF-3DE2-4B48-AE22-D659B8D835B0}\ProgID
HKCR\CLSID\{25D8BACF-3DE2-4B48-AE22-D659B8D835B0}\Programmable
HKCR\CLSID\{25D8BACF-3DE2-4B48-AE22-D659B8D835B0}\TypeLib
HKCR\CLSID\{25D8BACF-3DE2-4B48-AE22-D659B8D835B0}\VersionIndependentProgID
C:\PROGRAM FILES\RXTOOLBAR\RXTOOLBAR.DLL
HKU\S-1-5-21-766722026-832854739-3246968915-1008\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser#{25D8BACF-3DE2-4B48-AE22-D659B8D835B0}
HKCR\RXToolBar.TBInfo.1
HKCR\RXToolBar.TBInfo.1\CLSID
HKCR\RXToolBar.TBInfo
HKCR\RXToolBar.TBInfo\CLSID
HKCR\RXToolBar.TBInfo\CurVer
HKCR\TypeLib\{66B20295-DC57-42B6-ACDF-52D916E86464}
HKCR\TypeLib\{66B20295-DC57-42B6-ACDF-52D916E86464}\1.0
HKCR\TypeLib\{66B20295-DC57-42B6-ACDF-52D916E86464}\1.0\0
HKCR\TypeLib\{66B20295-DC57-42B6-ACDF-52D916E86464}\1.0\0\win32
HKCR\TypeLib\{66B20295-DC57-42B6-ACDF-52D916E86464}\1.0\FLAGS
HKCR\TypeLib\{66B20295-DC57-42B6-ACDF-52D916E86464}\1.0\HELPDIR
Unclassified.Unknown Origin
HKLM\Software\Classes\CLSID\{4D1C4E81-A32A-416b-BCDB-33B3EF3617D3}
HKCR\CLSID\{4D1C4E81-A32A-416B-BCDB-33B3EF3617D3}
HKCR\CLSID\{4D1C4E81-A32A-416B-BCDB-33B3EF3617D3}
HKCR\CLSID\{4D1C4E81-A32A-416B-BCDB-33B3EF3617D3}\InprocServer32
HKCR\CLSID\{4D1C4E81-A32A-416B-BCDB-33B3EF3617D3}\InprocServer32#ThreadingModel
HKCR\CLSID\{4D1C4E81-A32A-416B-BCDB-33B3EF3617D3}\Programmable
HKCR\CLSID\{4D1C4E81-A32A-416B-BCDB-33B3EF3617D3}\TypeLib
HKLM\Software\Classes\CLSID\{4D1C4E89-A32A-416b-BCDB-33B3EF3617D3}
HKCR\CLSID\{4D1C4E89-A32A-416B-BCDB-33B3EF3617D3}
HKCR\CLSID\{4D1C4E89-A32A-416B-BCDB-33B3EF3617D3}
HKCR\CLSID\{4D1C4E89-A32A-416B-BCDB-33B3EF3617D3}\InprocServer32
HKCR\CLSID\{4D1C4E89-A32A-416B-BCDB-33B3EF3617D3}\InprocServer32#ThreadingModel
HKCR\CLSID\{4D1C4E89-A32A-416B-BCDB-33B3EF3617D3}\Programmable
HKCR\CLSID\{4D1C4E89-A32A-416B-BCDB-33B3EF3617D3}\TypeLib
HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks#{E1759A31-E627-4758-9562-6899DF36C9C2}
C:\SYSTEM VOLUME INFORMATION\_RESTORE{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP179\A0042677.DLL
C:\SYSTEM VOLUME INFORMATION\_RESTORE{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP179\A0042686.DLL
Adware.CouponBar
HKLM\Software\Classes\CLSID\{5BED3930-2E9E-76D8-BACC-80DF2188D455}
HKCR\CLSID\{5BED3930-2E9E-76D8-BACC-80DF2188D455}
HKCR\CLSID\{5BED3930-2E9E-76D8-BACC-80DF2188D455}
HKCR\CLSID\{5BED3930-2E9E-76D8-BACC-80DF2188D455}\Implemented Categories
HKCR\CLSID\{5BED3930-2E9E-76D8-BACC-80DF2188D455}\Implemented Categories\{7DD95801-9882-11CF-9FA9-00AA006C42C4}
HKCR\CLSID\{5BED3930-2E9E-76D8-BACC-80DF2188D455}\Implemented Categories\{7DD95802-9882-11CF-9FA9-00AA006C42C4}
HKCR\CLSID\{5BED3930-2E9E-76D8-BACC-80DF2188D455}\InprocServer32
HKCR\CLSID\{5BED3930-2E9E-76D8-BACC-80DF2188D455}\InprocServer32#ThreadingModel
HKCR\CLSID\{5BED3930-2E9E-76D8-BACC-80DF2188D455}\ProgID
HKCR\CLSID\{5BED3930-2E9E-76D8-BACC-80DF2188D455}\Programmable
HKCR\CLSID\{5BED3930-2E9E-76D8-BACC-80DF2188D455}\TypeLib
HKCR\CLSID\{5BED3930-2E9E-76D8-BACC-80DF2188D455}\VersionIndependentProgID
C:\WINDOWS\COUPONBARIE.DLL
HKLM\Software\Classes\CLSID\{62960D20-6D0D-1AB4-4BF1-95B0B5B8783A}
HKCR\CLSID\{62960D20-6D0D-1AB4-4BF1-95B0B5B8783A}
HKCR\CLSID\{62960D20-6D0D-1AB4-4BF1-95B0B5B8783A}
HKCR\CLSID\{62960D20-6D0D-1AB4-4BF1-95B0B5B8783A}\InprocServer32
HKCR\CLSID\{62960D20-6D0D-1AB4-4BF1-95B0B5B8783A}\InprocServer32#ThreadingModel
HKCR\CLSID\{62960D20-6D0D-1AB4-4BF1-95B0B5B8783A}\ProgID
HKCR\CLSID\{62960D20-6D0D-1AB4-4BF1-95B0B5B8783A}\Programmable
HKCR\CLSID\{62960D20-6D0D-1AB4-4BF1-95B0B5B8783A}\TypeLib
HKCR\CLSID\{62960D20-6D0D-1AB4-4BF1-95B0B5B8783A}\VersionIndependentProgID
C:\WINDOWS\COUPON~1.DLL
HKU\S-1-5-21-766722026-832854739-3246968915-1008\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser#{5BED3930-2E9E-76D8-BACC-80DF2188D455}
HKCR\TTB000001.TTB000001.1
HKCR\TTB000001.TTB000001.1\CLSID
HKCR\TTB000001.TTB000001
HKCR\TTB000001.TTB000001\CLSID
HKCR\TTB000001.TTB000001\CurVer
HKCR\TypeLib\{9BA983B1-0C05-2DAF-9D1D-7E160077CAF4}
HKCR\TypeLib\{9BA983B1-0C05-2DAF-9D1D-7E160077CAF4}\1.0
HKCR\TypeLib\{9BA983B1-0C05-2DAF-9D1D-7E160077CAF4}\1.0\0
HKCR\TypeLib\{9BA983B1-0C05-2DAF-9D1D-7E160077CAF4}\1.0\0\win32
HKCR\TypeLib\{9BA983B1-0C05-2DAF-9D1D-7E160077CAF4}\1.0\FLAGS
HKCR\TypeLib\{9BA983B1-0C05-2DAF-9D1D-7E160077CAF4}\1.0\HELPDIR
Adware.Tracking Cookie
C:\Documents and Settings\allen\Cookies\allen@zedo[2].txt
C:\Documents and Settings\allen\Cookies\allen@indianfriendfinder[2].txt
C:\Documents and Settings\allen\Cookies\
[email protected][1].txt
C:\Documents and Settings\allen\Cookies\
[email protected][1].txt
C:\Documents and Settings\allen\Cookies\allen@partypoker[1].txt
C:\Documents and Settings\allen\Cookies\
[email protected][1].txt
C:\Documents and Settings\allen\Cookies\
[email protected][1].txt
C:\Documents and Settings\allen\Cookies\
[email protected][1].txt
C:\Documents and Settings\allen\Cookies\allen@interclick[2].txt
C:\Documents and Settings\allen\Cookies\
[email protected][2].txt
C:\Documents and Settings\allen\Cookies\allen@apmebf[1].txt
C:\Documents and Settings\allen\Cookies\
[email protected][2].txt
C:\Documents and Settings\allen\Cookies\
[email protected][2].txt
C:\Documents and Settings\allen\Cookies\
[email protected][1].txt
C:\Documents and Settings\allen\Cookies\
[email protected][1].txt
C:\Documents and Settings\allen\Cookies\
[email protected][1].txt
C:\Documents and Settings\allen\Cookies\allen@media6degrees[2].txt
C:\Documents and Settings\allen\Cookies\allen@partner2profit[1].txt
C:\Documents and Settings\allen\Cookies\
[email protected][1].txt
C:\Documents and Settings\allen\Cookies\
[email protected][2].txt
C:\Documents and Settings\allen\Cookies\allen@adinterax[2].txt
C:\Documents and Settings\allen\Cookies\
[email protected][3].txt
C:\Documents and Settings\allen\Cookies\allen@tribalfusion[1].txt
C:\Documents and Settings\allen\Cookies\
[email protected][2].txt
C:\Documents and Settings\allen\Cookies\allen@curvyclicks[2].txt
C:\Documents and Settings\allen\Cookies\
[email protected][1].txt
C:\Documents and Settings\allen\Cookies\allen@qksrv[2].txt
C:\Documents and Settings\allen\Cookies\allen@zango[2].txt
C:\Documents and Settings\allen\Cookies\
[email protected][1].txt
C:\Documents and Settings\allen\Cookies\
[email protected][2].txt
C:\Documents and Settings\allen\Cookies\allen@overture[1].txt
C:\Documents and Settings\allen\Cookies\
[email protected][1].txt
C:\Documents and Settings\allen\Cookies\allen@xiti[1].txt
C:\Documents and Settings\allen\Cookies\allen@hitbox[1].txt
C:\Documents and Settings\allen\Cookies\
[email protected][2].txt
C:\Documents and Settings\allen\Cookies\
[email protected][1].txt
C:\Documents and Settings\allen\Cookies\allen@xxxcounter[1].txt
C:\Documents and Settings\allen\Cookies\
[email protected][2].txt
C:\Documents and Settings\allen\Cookies\
[email protected][1].txt
C:\Documents and Settings\allen\Cookies\
[email protected][1].txt
C:\Documents and Settings\allen\Cookies\
[email protected][2].txt
C:\Documents and Settings\allen\Cookies\allen@casalemedia[1].txt
C:\Documents and Settings\allen\Cookies\allen@revsci[2].txt
C:\Documents and Settings\allen\Cookies\allen@clickbank[1].txt
C:\Documents and Settings\allen\Cookies\
[email protected][2].txt
C:\Documents and Settings\allen\Cookies\
[email protected][1].txt
C:\Documents and Settings\allen\Cookies\allen@tacoda[2].txt
C:\Documents and Settings\allen\Cookies\
[email protected][1].txt
C:\Documents and Settings\allen\Cookies\allen@sextracker[1].txt
C:\Documents and Settings\allen\Cookies\
[email protected][1].txt
C:\Documents and Settings\allen\Cookies\allen@cgi-bin[2].txt
C:\Documents and Settings\allen\Cookies\
[email protected][1].txt
C:\Documents and Settings\allen\Cookies\
[email protected][1].txt
C:\Documents and Settings\allen\Cookies\
[email protected][1].txt
C:\Documents and Settings\allen\Cookies\
[email protected][1].txt
C:\Documents and Settings\allen\Cookies\allen@jamster[1].txt
C:\Documents and Settings\allen\Cookies\
[email protected][2].txt
C:\Documents and Settings\allen\Cookies\allen@advertising[2].txt
C:\Documents and Settings\allen\Cookies\allen@adlegend[2].txt
C:\Documents and Settings\allen\Cookies\
[email protected][2].txt
C:\Documents and Settings\allen\Cookies\allen@specificclick[2].txt
C:\Documents and Settings\allen\Cookies\allen@toplist[1].txt
C:\Documents and Settings\allen\Cookies\
[email protected][2].txt
C:\Documents and Settings\allen\Cookies\allen@spamblockerutility[2].txt
C:\Documents and Settings\allen\Cookies\
[email protected][1].txt
C:\Documents and Settings\allen\Cookies\
[email protected][1].txt
C:\Documents and Settings\allen\Cookies\
[email protected][2].txt
C:\Documents and Settings\allen\Cookies\
[email protected][1].txt
C:\Documents and Settings\allen\Cookies\allen@atdmt[2].txt
C:\Documents and Settings\allen\Cookies\
[email protected][1].txt
C:\Documents and Settings\allen\Cookies\
[email protected][2].txt
C:\Documents and Settings\allen\Cookies\
[email protected][1].txt
C:\Documents and Settings\allen\Cookies\allen@adrevolver[1].txt
C:\Documents and Settings\allen\Cookies\
[email protected][2].txt
C:\Documents and Settings\allen\Cookies\allen@hotbar[2].txt
C:\Documents and Settings\allen\Cookies\
[email protected][1].txt
C:\Documents and Settings\allen\Cookies\
[email protected][1].txt
C:\Documents and Settings\allen\Cookies\
[email protected][2].txt
C:\Documents and Settings\allen\Cookies\
[email protected][1].txt
C:\Documents and Settings\allen\Cookies\allen@revenue[1].txt
C:\Documents and Settings\allen\Cookies\
[email protected][2].txt
C:\Documents and Settings\allen\Cookies\allen@2o7[1].txt
C:\Documents and Settings\allen\Cookies\
[email protected][2].txt
C:\Documents and Settings\allen\Cookies\
[email protected][1].txt
C:\Documents and Settings\allen\Cookies\allen@webpower[1].txt
C:\Documents and Settings\allen\Cookies\allen@fastclick[2].txt
C:\Documents and Settings\allen\Cookies\
[email protected][2].txt
C:\Documents and Settings\allen\Cookies\
[email protected][2].txt
C:\Documents and Settings\allen\Cookies\allen@clicksmartaffiliates[1].txt
C:\Documents and Settings\allen\Cookies\
[email protected][2].txt
C:\Documents and Settings\allen\Cookies\
[email protected][1].txt
C:\Documents and Settings\allen\Cookies\allen@trafficmp[1].txt
C:\Documents and Settings\allen\Cookies\
[email protected][2].txt
C:\Documents and Settings\allen\Cookies\allen@doubleclick[1].txt
C:\Documents and Settings\allen\Cookies\allen@questionmarket[1].txt
C:\Documents and Settings\allen\Cookies\allen@mediaplex[2].txt
C:\Documents and Settings\allen\Cookies\allen@atwola[2].txt
C:\Documents and Settings\allen\Cookies\allen@spyguardpro[2].txt
C:\Documents and Settings\allen\Cookies\
[email protected][1].txt
C:\Documents and Settings\allen\Cookies\allen@bluestreak[1].txt
C:\Documents and Settings\allen\Cookies\
[email protected][1].txt
C:\Documents and Settings\allen\Cookies\
[email protected][1].txt
C:\Documents and Settings\allen\Cookies\allen@curvyclicks[3].txt
C:\Documents and Settings\allen\Cookies\allen@mywebsearch[2].txt
C:\Documents and Settings\allen\Cookies\
[email protected][1].txt
C:\Documents and Settings\allen\Cookies\allen@burstnet[1].txt
C:\Documents and Settings\allen\Cookies\allen@statcounter[2].txt
C:\Documents and Settings\allen\Cookies\
[email protected][1].txt
C:\Documents and Settings\allen\Cookies\allen@findlaw[1].txt
C:\Documents and Settings\allen\Cookies\
[email protected][2].txt
C:\Documents and Settings\allen\Cookies\
[email protected][2].txt
C:\Documents and Settings\allen\Cookies\
[email protected][1].txt
C:\Documents and Settings\allen\Cookies\allen@adserving[1].txt
C:\Documents and Settings\allen\Cookies\allen@serving-sys[2].txt
C:\Documents and Settings\allen\Cookies\
[email protected][1].txt
C:\Documents and Settings\allen\Cookies\
[email protected][1].txt
C:\Documents and Settings\allen\Cookies\
[email protected][2].txt
C:\Documents and Settings\allen\Cookies\allen@adbrite[1].txt
C:\Documents and Settings\allen\Cookies\allen@realmedia[2].txt
C:\Documents and Settings\allen\Cookies\
[email protected][1].txt
C:\Documents and Settings\allen\Cookies\
[email protected][1].txt
C:\Documents and Settings\allen\Cookies\
[email protected][2].txt
C:\Documents and Settings\allen\Cookies\
[email protected][2].txt
C:\Documents and Settings\allen\Cookies\
[email protected][1].txt
C:\Documents and Settings\allen\Cookies\
[email protected][2].txt
C:\Documents and Settings\allen\Cookies\allen@need2find[1].txt
C:\Documents and Settings\allen\Cookies\
[email protected][4].txt
C:\Documents and Settings\allen\Cookies\
[email protected][1].txt
C:\Documents and Settings\allen\Cookies\
[email protected][1].txt
C:\Documents and Settings\allen\Cookies\
[email protected][5].txt
C:\Documents and Settings\allen\Cookies\
[email protected][1].txt
C:\Documents and Settings\allen\Cookies\allen@fliptrack[1].txt
C:\Documents and Settings\allen\Cookies\
[email protected][1].txt
C:\Documents and Settings\allen\Cookies\
[email protected][1].txt
C:\Documents and Settings\allen\Cookies\
[email protected][1].txt
C:\Documents and Settings\allen\Cookies\allen@maxserving[2].txt
C:\Documents and Settings\allen\Cookies\allen@adecn[1].txt
C:\Documents and Settings\allen\Cookies\
[email protected][3].txt
C:\Documents and Settings\allen\Cookies\allen@precisionclick[2].txt
C:\Documents and Settings\allen\Cookies\
[email protected][1].txt
C:\Documents and Settings\allen\Cookies\
[email protected][1].txt
C:\Documents and Settings\allen\Cookies\allen@adultfriendfinder[2].txt
C:\Documents and Settings\allen\Cookies\
[email protected][4].txt
C:\Documents and Settings\allen\Cookies\
[email protected][2].txt
C:\Documents and Settings\allen\Cookies\allen@myadultsite[1].txt
C:\Documents and Settings\allen\Cookies\allen@teendeja[1].txt
C:\Documents and Settings\allen\Cookies\
[email protected][3].txt
C:\Documents and Settings\allen\Cookies\allen@shakingmedia[2].txt
C:\Deckard\System Scanner\20080127125142\backup\DOCUME~1\allen\LOCALS~1\Temp\Cookies\allen@atdmt[2].txt
C:\Deckard\System Scanner\20080127125142\backup\DOCUME~1\allen\LOCALS~1\Temp\Cookies\allen@doubleclick[2].txt
C:\Deckard\System Scanner\20080127125142\backup\DOCUME~1\allen\LOCALS~1\Temp\Cookies\
[email protected][1].txt
C:\Deckard\System Scanner\20080127125142\backup\DOCUME~1\allen\LOCALS~1\Temp\Cookies\allen@mediaplex[1].txt
C:\Documents and Settings\doug\Cookies\doug@2o7[1].txt
C:\Documents and Settings\doug\Cookies\
[email protected][2].txt
C:\Documents and Settings\doug\Cookies\doug@adinterax[2].txt
C:\Documents and Settings\doug\Cookies\
[email protected][2].txt
C:\Documents and Settings\doug\Cookies\
[email protected][1].txt
C:\Documents and Settings\doug\Cookies\
[email protected][1].txt
C:\Documents and Settings\doug\Cookies\
[email protected][2].txt
C:\Documents and Settings\doug\Cookies\doug@advertising[1].txt
C:\Documents and Settings\doug\Cookies\doug@apmebf[2].txt
C:\Documents and Settings\doug\Cookies\doug@atdmt[2].txt
C:\Documents and Settings\doug\Cookies\
[email protected][2].txt
C:\Documents and Settings\doug\Cookies\doug@casalemedia[2].txt
C:\Documents and Settings\doug\Cookies\doug@doubleclick[1].txt
C:\Documents and Settings\doug\Cookies\doug@imrworldwide[2].txt
C:\Documents and Settings\doug\Cookies\
[email protected][1].txt
C:\Documents and Settings\doug\Cookies\
[email protected][1].txt
C:\Documents and Settings\doug\Cookies\doug@mediaplex[1].txt
C:\Documents and Settings\doug\Cookies\
[email protected][1].txt
C:\Documents and Settings\doug\Cookies\doug@mywebsearch[1].txt
C:\Documents and Settings\doug\Cookies\
[email protected][1].txt
C:\Documents and Settings\doug\Cookies\doug@partypoker[1].txt
C:\Documents and Settings\doug\Cookies\
[email protected][1].txt
C:\Documents and Settings\doug\Cookies\doug@questionmarket[2].txt
C:\Documents and Settings\doug\Cookies\doug@revenue[2].txt
C:\Documents and Settings\doug\Cookies\
[email protected][2].txt
C:\Documents and Settings\doug\Cookies\doug@serving-sys[1].txt
C:\Documents and Settings\doug\Cookies\doug@specificclick[2].txt
C:\Documents and Settings\doug\Cookies\doug@tacoda[1].txt
C:\Documents and Settings\doug\Cookies\
[email protected][1].txt
C:\Documents and Settings\doug\Cookies\doug@trafficmp[2].txt
C:\Documents and Settings\doug\Cookies\doug@zedo[1].txt
C:\Documents and Settings\Guest\Cookies\
[email protected][2].txt
C:\Documents and Settings\Guest\Cookies\guest@adbrite[2].txt
C:\Documents and Settings\Guest\Cookies\guest@adlegend[1].txt
C:\Documents and Settings\Guest\Cookies\
[email protected][2].txt
C:\Documents and Settings\Guest\Cookies\guest@adultfriendfinder[2].txt
C:\Documents and Settings\Guest\Cookies\guest@advertising[2].txt
C:\Documents and Settings\Guest\Cookies\guest@atdmt[2].txt
C:\Documents and Settings\Guest\Cookies\guest@doubleclick[1].txt
C:\Documents and Settings\Guest\Cookies\
[email protected][1].txt
C:\Documents and Settings\Guest\Cookies\
[email protected][2].txt
C:\Documents and Settings\Guest\Cookies\guest@hitbox[1].txt
C:\Documents and Settings\Guest\Cookies\guest@hotbar[2].txt
C:\Documents and Settings\Guest\Cookies\guest@imrworldwide[2].txt
C:\Documents and Settings\Guest\Cookies\
[email protected][1].txt
C:\Documents and Settings\Guest\Cookies\
[email protected][1].txt
C:\Documents and Settings\Guest\Cookies\guest@mediaplex[1].txt
C:\Documents and Settings\Guest\Cookies\guest@revsci[2].txt
C:\Documents and Settings\Guest\Cookies\
[email protected][1].txt
C:\Documents and Settings\Guest\Cookies\guest@toplist[1].txt
C:\Documents and Settings\Guest\Cookies\guest@zedo[1].txt
C:\Documents and Settings\uiser\Cookies\
[email protected][2].txt
C:\Documents and Settings\uiser\Cookies\
[email protected][1].txt
C:\Documents and Settings\uiser\Cookies\uiser@2o7[1].txt
C:\Documents and Settings\uiser\Cookies\
[email protected][1].txt
C:\Documents and Settings\uiser\Cookies\
[email protected][1].txt
C:\Documents and Settings\uiser\Cookies\
[email protected][1].txt
C:\Documents and Settings\uiser\Cookies\
[email protected][1].txt
C:\Documents and Settings\uiser\Cookies\
[email protected][2].txt
C:\Documents and Settings\uiser\Cookies\
[email protected][1].txt
C:\Documents and Settings\uiser\Cookies\
[email protected][2].txt
C:\Documents and Settings\uiser\Cookies\uiser@adbrite[2].txt
C:\Documents and Settings\uiser\Cookies\uiser@adecn[1].txt
C:\Documents and Settings\uiser\Cookies\uiser@adinterax[2].txt
C:\Documents and Settings\uiser\Cookies\uiser@adknowledge[2].txt
C:\Documents and Settings\uiser\Cookies\uiser@adlegend[2].txt
C:\Documents and Settings\uiser\Cookies\
[email protected][1].txt
C:\Documents and Settings\uiser\Cookies\
[email protected][2].txt
C:\Documents and Settings\uiser\Cookies\uiser@adprofile[1].txt
C:\Documents and Settings\uiser\Cookies\uiser@adrevolver[2].txt
C:\Documents and Settings\uiser\Cookies\
[email protected][1].txt
C:\Documents and Settings\uiser\Cookies\
[email protected][2].txt
C:\Documents and Settings\uiser\Cookies\
[email protected][1].txt
C:\Documents and Settings\uiser\Cookies\
[email protected][1].txt
C:\Documents and Settings\uiser\Cookies\
[email protected][1].txt
C:\Documents and Settings\uiser\Cookies\
[email protected][2].txt
C:\Documents and Settings\uiser\Cookies\
[email protected][2].txt
C:\Documents and Settings\uiser\Cookies\
[email protected][1].txt
C:\Documents and Settings\uiser\Cookies\
[email protected][2].txt
C:\Documents and Settings\uiser\Cookies\
[email protected][1].txt
C:\Documents and Settings\uiser\Cookies\
[email protected][1].txt
C:\Documents and Settings\uiser\Cookies\
[email protected][1].txt
C:\Documents and Settings\uiser\Cookies\
[email protected][1].txt
C:\Documents and Settings\uiser\Cookies\
[email protected][1].txt
C:\Documents and Settings\uiser\Cookies\uiser@adserver[2].txt
C:\Documents and Settings\uiser\Cookies\uiser@adtech[2].txt
C:\Documents and Settings\uiser\Cookies\uiser@adverticum[1].txt
C:\Documents and Settings\uiser\Cookies\
[email protected][1].txt
C:\Documents and Settings\uiser\Cookies\uiser@advertising[2].txt
C:\Documents and Settings\uiser\Cookies\
[email protected][1].txt
C:\Documents and Settings\uiser\Cookies\
[email protected][2].txt
C:\Documents and Settings\uiser\Cookies\
[email protected][2].txt
C:\Documents and Settings\uiser\Cookies\
[email protected][2].txt
C:\Documents and Settings\uiser\Cookies\uiser@apmebf[1].txt
C:\Documents and Settings\uiser\Cookies\uiser@atdmt[2].txt
C:\Documents and Settings\uiser\Cookies\uiser@atwola[1].txt
C:\Documents and Settings\uiser\Cookies\
[email protected][1].txt
C:\Documents and Settings\uiser\Cookies\uiser@azjmp[2].txt
C:\Documents and Settings\uiser\Cookies\uiser@azoogleads[2].txt
C:\Documents and Settings\uiser\Cookies\
[email protected][2].txt
C:\Documents and Settings\uiser\Cookies\
[email protected][1].txt
C:\Documents and Settings\uiser\Cookies\uiser@bluestreak[2].txt
C:\Documents and Settings\uiser\Cookies\
[email protected][1].txt
C:\Documents and Settings\uiser\Cookies\uiser@bravenetmedianetwork[1].txt
C:\Documents and Settings\uiser\Cookies\
[email protected][2].txt
C:\Documents and Settings\uiser\Cookies\uiser@burstnet[1].txt
C:\Documents and Settings\uiser\Cookies\uiser@casalemedia[1].txt
C:\Documents and Settings\uiser\Cookies\
[email protected][1].txt
C:\Documents and Settings\uiser\Cookies\
[email protected][1].txt
C:\Documents and Settings\uiser\Cookies\
[email protected][1].txt
C:\Documents and Settings\uiser\Cookies\
[email protected][2].txt
C:\Documents and Settings\uiser\Cookies\uiser@clickbank[1].txt
C:\Documents and Settings\uiser\Cookies\uiser@clickondetroit[1].txt
C:\Documents and Settings\uiser\Cookies\uiser@clicksmartaffiliates[1].txt
C:\Documents and Settings\uiser\Cookies\uiser@collective-media[2].txt
C:\Documents and Settings\uiser\Cookies\uiser@consumergain[1].txt
C:\Documents and Settings\uiser\Cookies\uiser@coolsavings[2].txt
C:\Documents and Settings\uiser\Cookies\
[email protected][1].txt
C:\Documents and Settings\uiser\Cookies\
[email protected][1].txt
C:\Documents and Settings\uiser\Cookies\
[email protected][2].txt
C:\Documents and Settings\uiser\Cookies\
[email protected][2].txt
C:\Documents and Settings\uiser\Cookies\uiser@dealtime[1].txt
C:\Documents and Settings\uiser\Cookies\uiser@directtrack[1].txt
C:\Documents and Settings\uiser\Cookies\uiser@doubleclick[2].txt
C:\Documents and Settings\uiser\Cookies\uiser@drivecleaner[1].txt
C:\Documents and Settings\uiser\Cookies\
[email protected][1].txt
C:\Documents and Settings\uiser\Cookies\uiser@easyscreensavers[1].txt
C:\Documents and Settings\uiser\Cookies\
[email protected][1].txt
C:\Documents and Settings\uiser\Cookies\
[email protected][1].txt
C:\Documents and Settings\uiser\Cookies\
[email protected][1].txt
C:\Documents and Settings\uiser\Cookies\
[email protected][1].txt
C:\Documents and Settings\uiser\Cookies\
[email protected][2].txt
C:\Documents and Settings\uiser\Cookies\
[email protected][1].txt
C:\Documents and Settings\uiser\Cookies\
[email protected][1].txt
C:\Documents and Settings\uiser\Cookies\
[email protected][2].txt
C:\Documents and Settings\uiser\Cookies\
[email protected][1].txt
C:\Documents and Settings\uiser\Cookies\
[email protected][1].txt
C:\Documents and Settings\uiser\Cookies\
[email protected][1].txt
C:\Documents and Settings\uiser\Cookies\uiser@eyewonder[1].txt
C:\Documents and Settings\uiser\Cookies\uiser@ez-tracks[1].txt
C:\Documents and Settings\uiser\Cookies\
[email protected][1].txt
C:\Documents and Settings\uiser\Cookies\uiser@fastclick[1].txt
C:\Documents and Settings\uiser\Cookies\
[email protected][1].txt
C:\Documents and Settings\uiser\Cookies\uiser@findagrave[1].txt
C:\Documents and Settings\uiser\Cookies\uiser@findgrave[1].txt
C:\Documents and Settings\uiser\Cookies\
[email protected][1].txt
C:\Documents and Settings\uiser\Cookies\uiser@friendfinder[1].txt
C:\Documents and Settings\uiser\Cookies\
[email protected][2].txt
C:\Documents and Settings\uiser\Cookies\
[email protected][1].txt
C:\Documents and Settings\uiser\Cookies\uiser@hitbox[2].txt
C:\Documents and Settings\uiser\Cookies\uiser@hotbar[1].txt
C:\Documents and Settings\uiser\Cookies\
[email protected][1].txt
C:\Documents and Settings\uiser\Cookies\
[email protected][1].txt
C:\Documents and Settings\uiser\Cookies\
[email protected][2].txt
C:\Documents and Settings\uiser\Cookies\uiser@indexstats[2].txt
C:\Documents and Settings\uiser\Cookies\uiser@interclick[2].txt
C:\Documents and Settings\uiser\Cookies\
[email protected][1].txt
C:\Documents and Settings\uiser\Cookies\uiser@keywordmax[1].txt
C:\Documents and Settings\uiser\Cookies\
[email protected][2].txt
C:\Documents and Settings\uiser\Cookies\
[email protected][1].txt
C:\Documents and Settings\uiser\Cookies\uiser@linkstattrack[1].txt
C:\Documents and Settings\uiser\Cookies\uiser@linksynergy[2].txt
C:\Documents and Settings\uiser\Cookies\
[email protected][2].txt
C:\Documents and Settings\uiser\Cookies\
[email protected][2].txt
C:\Documents and Settings\uiser\Cookies\uiser@maxserving[1].txt
C:\Documents and Settings\uiser\Cookies\
[email protected][1].txt
C:\Documents and Settings\uiser\Cookies\
[email protected][2].txt
C:\Documents and Settings\uiser\Cookies\
[email protected][1].txt
C:\Documents and Settings\uiser\Cookies\
[email protected][1].txt
C:\Documents and Settings\uiser\Cookies\
[email protected][2].txt
C:\Documents and Settings\uiser\Cookies\
[email protected][2].txt
C:\Documents and Settings\uiser\Cookies\uiser@media303[1].txt
C:\Documents and Settings\uiser\Cookies\uiser@mediapartners-img[2].txt
C:\Documents and Settings\uiser\Cookies\uiser@mediaplex[1].txt
C:\Documents and Settings\uiser\Cookies\
[email protected][1].txt
C:\Documents and Settings\uiser\Cookies\
[email protected][1].txt
C:\Documents and Settings\uiser\Cookies\
[email protected][1].txt
C:\Documents and Settings\uiser\Cookies\uiser@mywebsearch[1].txt
C:\Documents and Settings\uiser\Cookies\
[email protected][1].txt
C:\Documents and Settings\uiser\Cookies\uiser@netmediagroup[1].txt
C:\Documents and Settings\uiser\Cookies\uiser@nextag[1].txt
C:\Documents and Settings\uiser\Cookies\uiser@overture[2].txt
C:\Documents and Settings\uiser\Cookies\uiser@partner2profit[1].txt
C:\Documents and Settings\uiser\Cookies\
[email protected][1].txt
C:\Documents and Settings\uiser\Cookies\
[email protected][1].txt
C:\Documents and Settings\uiser\Cookies\uiser@partypoker[2].txt
C:\Documents and Settings\uiser\Cookies\
[email protected][2].txt
C:\Documents and Settings\uiser\Cookies\
[email protected][1].txt
C:\Documents and Settings\uiser\Cookies\
[email protected][2].txt
C:\Documents and Settings\uiser\Cookies\uiser@popularscreensavers[2].txt
C:\Documents and Settings\uiser\Cookies\uiser@precisionclick[1].txt
C:\Documents and Settings\uiser\Cookies\uiser@pro-market[1].txt
C:\Documents and Settings\uiser\Cookies\
[email protected][1].txt
C:\Documents and Settings\uiser\Cookies\uiser@questionmarket[1].txt
C:\Documents and Settings\uiser\Cookies\uiser@realmedia[1].txt
C:\Documents and Settings\uiser\Cookies\
[email protected][2].txt
C:\Documents and Settings\uiser\Cookies\
[email protected][2].txt
C:\Documents and Settings\uiser\Cookies\
[email protected][1].txt
C:\Documents and Settings\uiser\Cookies\uiser@revenue[2].txt
C:\Documents and Settings\uiser\Cookies\uiser@revsci[1].txt
C:\Documents and Settings\uiser\Cookies\
[email protected][1].txt
C:\Documents and Settings\uiser\Cookies\uiser@roiservice[2].txt
C:\Documents and Settings\uiser\Cookies\
[email protected][1].txt
C:\Documents and Settings\uiser\Cookies\
[email protected][1].txt
C:\Documents and Settings\uiser\Cookies\
[email protected][1].txt
C:\Documents and Settings\uiser\Cookies\uiser@screensaverinsanity[1].txt
C:\Documents and Settings\uiser\Cookies\
[email protected][2].txt
C:\Documents and Settings\uiser\Cookies\uiser@screensavers[1].txt
C:\Documents and Settings\uiser\Cookies\
[email protected][2].txt
C:\Documents and Settings\uiser\Cookies\
[email protected][1].txt
C:\Documents and Settings\uiser\Cookies\uiser@seniorfriendfinder[1].txt
C:\Documents and Settings\uiser\Cookies\
[email protected][2].txt
C:\Documents and Settings\uiser\Cookies\
[email protected][3].txt
C:\Documents and Settings\uiser\Cookies\
[email protected][4].txt
C:\Documents and Settings\uiser\Cookies\uiser@serving-sys[2].txt
C:\Documents and Settings\uiser\Cookies\
[email protected][1].txt
C:\Documents and Settings\uiser\Cookies\uiser@smileycentral[1].txt
C:\Documents and Settings\uiser\Cookies\uiser@specificclick[1].txt
C:\Documents and Settings\uiser\Cookies\
[email protected][1].txt
C:\Documents and Settings\uiser\Cookies\
[email protected][1].txt
C:\Documents and Settings\uiser\Cookies\
[email protected][2].txt
C:\Documents and Settings\uiser\Cookies\
[email protected][2].txt
C:\Documents and Settings\uiser\Cookies\uiser@statcounter[1].txt
C:\Documents and Settings\uiser\Cookies\
[email protected][2].txt
C:\Documents and Settings\uiser\Cookies\
[email protected][2].txt
C:\Documents and Settings\uiser\Cookies\
[email protected][1].txt
C:\Documents and Settings\uiser\Cookies\
[email protected][1].txt
C:\Documents and Settings\uiser\Cookies\
[email protected][2].txt
C:\Documents and Settings\uiser\Cookies\
[email protected][2].txt
C:\Documents and Settings\uiser\Cookies\
[email protected][2].txt
C:\Documents and Settings\uiser\Cookies\uiser@statsgod[1].txt
C:\Documents and Settings\uiser\Cookies\uiser@tacoda[2].txt
C:\Documents and Settings\uiser\Cookies\
[email protected][1].txt
C:\Documents and Settings\uiser\Cookies\uiser@thetopscreensavers[1].txt
C:\Documents and Settings\uiser\Cookies\uiser@toplist[1].txt
C:\Documents and Settings\uiser\Cookies\uiser@toseeka[1].txt
C:\Documents and Settings\uiser\Cookies\
[email protected][1].txt
C:\Documents and Settings\uiser\Cookies\
[email protected][2].txt
C:\Documents and Settings\uiser\Cookies\
[email protected][1].txt
C:\Documents and Settings\uiser\Cookies\uiser@trafficmp[1].txt
C:\Documents and Settings\uiser\Cookies\
[email protected][1].txt
C:\Documents and Settings\uiser\Cookies\uiser@tribalfusion[1].txt
C:\Documents and Settings\uiser\Cookies\uiser@usenext[2].txt
C:\Documents and Settings\uiser\Cookies\uiser@wjadserver[2].txt
C:\Documents and Settings\uiser\Cookies\
[email protected][1].txt
C:\Documents and Settings\uiser\Cookies\
[email protected][2].txt
C:\Documents and Settings\uiser\Cookies\
[email protected][1].txt
C:\Documents and Settings\uiser\Cookies\
[email protected][2].txt
C:\Documents and Settings\uiser\Cookies\
[email protected][1].txt
C:\Documents and Settings\uiser\Cookies\
[email protected][2].txt
C:\Documents and Settings\uiser\Cookies\
[email protected][2].txt
C:\Documents and Settings\uiser\Cookies\
[email protected][2].txt
C:\Documents and Settings\uiser\Cookies\
[email protected][2].txt
C:\Documents and Settings\uiser\Cookies\
[email protected][2].txt
C:\Documents and Settings\uiser\Cookies\
[email protected][1].txt
C:\Documents and Settings\uiser\Cookies\
[email protected][2].txt
C:\Documents and Settings\uiser\Cookies\
[email protected][1].txt
C:\Documents and Settings\uiser\Cookies\uiser@xiti[1].txt
C:\Documents and Settings\uiser\Cookies\
[email protected][1].txt
C:\Documents and Settings\uiser\Cookies\uiser@xtremetrack[2].txt
C:\Documents and Settings\uiser\Cookies\uiser@zedo[1].txt
C:\Documents and Settings\uiser\Local Settings\Temp\Cookies\
[email protected][1].txt
C:\Documents and Settings\uiser\Local Settings\Temp\Cookies\
[email protected][2].txt
C:\Documents and Settings\uiser\Local Settings\Temp\Cookies\
[email protected][1].txt
C:\Documents and Settings\uiser\Local Settings\Temp\Cookies\uiser@atdmt[1].txt
C:\Documents and Settings\uiser\Local Settings\Temp\Cookies\uiser@bluestreak[1].txt
C:\Documents and Settings\uiser\Local Settings\Temp\Cookies\uiser@casalemedia[2].txt
C:\Documents and Settings\uiser\Local Settings\Temp\Cookies\
[email protected][1].txt
C:\Documents and Settings\uiser\Local Settings\Temp\Cookies\uiser@doubleclick[1].txt
C:\Documents and Settings\uiser\Local Settings\Temp\Cookies\
[email protected][1].txt
C:\Documents and Settings\uiser\Local Settings\Temp\Cookies\
[email protected][2].txt
C:\Documents and Settings\uiser\Local Settings\Temp\Cookies\
[email protected][1].txt
C:\Documents and Settings\uiser\Local Settings\Temp\Cookies\uiser@fastclick[1].txt
C:\Documents and Settings\uiser\Local Settings\Temp\Cookies\uiser@findwhat[1].txt
C:\Documents and Settings\uiser\Local Settings\Temp\Cookies\uiser@hitbox[2].txt
C:\Documents and Settings\uiser\Local Settings\Temp\Cookies\uiser@hotbar[2].txt
C:\Documents and Settings\uiser\Local Settings\Temp\Cookies\
[email protected][2].txt
C:\Documents and Settings\uiser\Local Settings\Temp\Cookies\
[email protected][1].txt
C:\Documents and Settings\uiser\Local Settings\Temp\Cookies\uiser@mediaplex[2].txt
C:\Documents and Settings\uiser\Local Settings\Temp\Cookies\uiser@mywebsearch[2].txt
C:\Documents and Settings\uiser\Local Settings\Temp\Cookies\uiser@overture[1].txt
C:\Documents and Settings\uiser\Local Settings\Temp\Cookies\uiser@questionmarket[2].txt
C:\Documents and Settings\uiser\Local Settings\Temp\Cookies\uiser@realmedia[1].txt
C:\Documents and Settings\uiser\Local Settings\Temp\Cookies\
[email protected][1].txt
C:\Documents and Settings\uiser\Local Settings\Temp\Cookies\
[email protected][2].txt
C:\Documents and Settings\uiser\Local Settings\Temp\Cookies\uiser@specificclick[1].txt
C:\Documents and Settings\uiser\Local Settings\Temp\Cookies\uiser@statcounter[2].txt
C:\Documents and Settings\uiser\Local Settings\Temp\Cookies\uiser@tribalfusion[2].txt
C:\Documents and Settings\uiser\Local Settings\Temp\Cookies\uiser@zedo[2].txt
Adware.Web Buying
HKU\S-1-5-21-766722026-832854739-3246968915-1008\Software\WebBuying
Adware.180solutions/ZangoSearch
C:\DOCUMENTS AND SETTINGS\UISER\LOCAL SETTINGS\TEMP\TEMPORARY INTERNET FILES\CONTENT.IE5\SBEGOLT2\SETUP[1].EXE
C:\SYSTEM VOLUME INFORMATION\_RESTORE{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP142\A0038682.DLL
C:\SYSTEM VOLUME INFORMATION\_RESTORE{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP142\A0038683.EXE
C:\SYSTEM VOLUME INFORMATION\_RESTORE{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP142\A0038684.DLL
C:\SYSTEM VOLUME INFORMATION\_RESTORE{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP142\A0038685.DLL
C:\SYSTEM VOLUME INFORMATION\_RESTORE{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP142\A0038686.EXE
C:\SYSTEM VOLUME INFORMATION\_RESTORE{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP142\A0038687.DLL
C:\SYSTEM VOLUME INFORMATION\_RESTORE{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP142\A0038689.DLL
C:\SYSTEM VOLUME INFORMATION\_RESTORE{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP142\A0038691.DLL
C:\SYSTEM VOLUME INFORMATION\_RESTORE{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP142\A0038692.EXE
C:\SYSTEM VOLUME INFORMATION\_RESTORE{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP142\A0038693.DLL
C:\SYSTEM VOLUME INFORMATION\_RESTORE{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP142\A0038694.EXE
C:\SYSTEM VOLUME INFORMATION\_RESTORE{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP142\A0038696.EXE
C:\SYSTEM VOLUME INFORMATION\_RESTORE{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP142\A0038697.DLL
C:\SYSTEM VOLUME INFORMATION\_RESTORE{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP142\A0038706.DLL
C:\SYSTEM VOLUME INFORMATION\_RESTORE{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP166\A0041001.DLL
Trojan.Unclassifed/AffiliateBundle
C:\PROGRAM FILES\TREND MICRO\HIJACKTHIS\BACKUPS\BACKUP-20080127-124330-120.DLL
C:\SYSTEM VOLUME INFORMATION\_RESTORE{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP198\A0052805.DLL
C:\SYSTEM VOLUME INFORMATION\_RESTORE{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP200\A0052912.DLL
C:\SYSTEM VOLUME INFORMATION\_RESTORE{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP200\A0052916.DLL
C:\VUNDOFIX BACKUPS\GEBYWVV.DLL.BAD
C:\VUNDOFIX BACKUPS\PMNONOP.DLL.BAD
C:\_OTMOVEIT\MOVEDFILES\01272008_124651\WINDOWS\SYSTEM32\PMNONOP.DLL
Adware.HotBar/ShopperReports (Low Risk)
C:\SYSTEM VOLUME INFORMATION\_RESTORE{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP179\A0042676.DLL
Adware.WebBuying Assistant-Installer
C:\SYSTEM VOLUME INFORMATION\_RESTORE{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP179\A0042688.EXE
C:\SYSTEM VOLUME INFORMATION\_RESTORE{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP179\A0042727.EXE
Adware.Vundo-Variant
C:\SYSTEM VOLUME INFORMATION\_RESTORE{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP197\A0052723.DLL
C:\SYSTEM VOLUME INFORMATION\_RESTORE{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP198\A0052801.DLL
C:\SYSTEM VOLUME INFORMATION\_RESTORE{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP198\A0052802.DLL
C:\SYSTEM VOLUME INFORMATION\_RESTORE{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP198\A0052803.DLL
C:\SYSTEM VOLUME INFORMATION\_RESTORE{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP198\A0052806.DLL
C:\SYSTEM VOLUME INFORMATION\_RESTORE{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP198\A0052807.DLL
C:\SYSTEM VOLUME INFORMATION\_RESTORE{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP198\A0052808.DLL
C:\SYSTEM VOLUME INFORMATION\_RESTORE{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP198\A0052809.DLL
C:\SYSTEM VOLUME INFORMATION\_RESTORE{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP198\A0052811.DLL
C:\SYSTEM VOLUME INFORMATION\_RESTORE{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP198\A0052812.DLL
C:\SYSTEM VOLUME INFORMATION\_RESTORE{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP198\A0052813.DLL
C:\SYSTEM VOLUME INFORMATION\_RESTORE{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP199\A0052878.DLL
C:\SYSTEM VOLUME INFORMATION\_RESTORE{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP199\A0052908.DLL
C:\SYSTEM VOLUME INFORMATION\_RESTORE{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP202\A0052971.DLL
C:\SYSTEM VOLUME INFORMATION\_RESTORE{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP202\A0052972.DLL
C:\SYSTEM VOLUME INFORMATION\_RESTORE{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP202\A0052973.DLL
C:\SYSTEM VOLUME INFORMATION\_RESTORE{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP202\A0052974.DLL
C:\SYSTEM VOLUME INFORMATION\_RESTORE{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP202\A0052975.DLL
C:\SYSTEM VOLUME INFORMATION\_RESTORE{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP202\A0052976.DLL
C:\SYSTEM VOLUME INFORMATION\_RESTORE{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP202\A0052977.DLL
Trojan.Unknown Origin
C:\SYSTEM VOLUME INFORMATION\_RESTORE{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP202\A0053162.EXE
Trojan.Downloader-Gen/TaLDrv
C:\SYSTEM VOLUME INFORMATION\_RESTORE{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP202\A0053163.EXE
Trojan.Downloader-Gen/BundleBase
C:\SYSTEM VOLUME INFORMATION\_RESTORE{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP202\A0053164.EXE
Adware.MyWebSearch
C:\_OTMOVEIT\MOVEDFILES\01272008_124651\PROGRAM FILES\MYWEBSEARCH\BAR\2.BIN\MWSOEMON.EXE
Trojan.XpUpdate/Fake Alert
C:\_OTMOVEIT\MOVEDFILES\01272008_124651\WINDOWS\XPUPDATE.EXE
Deckard's System Scanner v20071014.68
Run by allen on 2008-01-27 16:59:07
Computer is in Normal Mode.
--------------------------------------------------------------------------------
-- HijackThis (run as allen.exe) -----------------------------------------------
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 4:59:11 PM, on 1/27/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16574)
Boot mode: Normal
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
C:\Program Files\Alwil Software\Avast4\ashServ.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
C:\WINDOWS\system32\hkcmd.exe
C:\WINDOWS\system32\igfxpers.exe
C:\Program Files\Java\j2re1.4.2_03\bin\jusched.exe
C:\Program Files\CyberLink\PowerDVD\DVDLauncher.exe
C:\WINDOWS\system32\dla\tfswctrl.exe
C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe
C:\Program Files\BroadJump\Client Foundation\CFD.exe
C:\PROGRA~1\Yahoo!\browser\ybrwicon.exe
C:\PROGRA~1\MUSICM~1\MUSICM~3\MMDiag.exe
C:\Program Files\Yahoo!\Search Protection\SearchProtection.exe
C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
C:\PROGRA~1\Yahoo!\browser\ycommon.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\MUSICMATCH\Musicmatch Jukebox\mim.exe
C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
C:\Program Files\Digital Line Detect\DLG.exe
C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Documents and Settings\allen\Desktop\dss.exe
C:\PROGRA~1\TRENDM~1\HIJACK~1\allen.exe
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar =
http://g.msn.com/0SEENUS/SAOS01R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page =
http://www.yahoo.com/R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL =
http://go.microsoft....k/?LinkId=69157R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL =
http://go.microsoft....k/?LinkId=54896R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar =
http://us.rd.yahoo.c...rch/search.htmlR1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page =
http://go.microsoft....k/?LinkId=54896R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page =
http://go.microsoft....k/?LinkId=69157R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
http://resultsmaster...omeLeftPane.htmR3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn0\yt.dll
O2 - BHO: &Yahoo! Toolbar Helper - {02478D38-C3F9-4EFB-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn0\yt.dll
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: Yahoo! IE Services Button - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\Program Files\Yahoo!\common\yiesrvc.dll
O2 - BHO: DriveLetterAccess - {5CA3D70E-1895-11CF-8E15-001234567890} - C:\WINDOWS\system32\dla\tfswshx.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar2.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\2.1.615.5858\swg.dll
O2 - BHO: CBrowserHelperObject Object - {CA6319C0-31B7-401E-A518-A07C3DB8F777} - c:\Program Files\GoogleAFE\GoogleAE.dll
O2 - BHO: SidebarAutoLaunch Class - {F2AA9440-6328-4933-B7C9-A6CCDF9CBF6D} - C:\Program Files\Yahoo!\browser\YSidebarIEBHO.dll
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn0\yt.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar2.dll
O4 - HKLM\..\Run: [igfxtray] C:\WINDOWS\system32\igfxtray.exe
O4 - HKLM\..\Run: [igfxhkcmd] C:\WINDOWS\system32\hkcmd.exe
O4 - HKLM\..\Run: [igfxpers] C:\WINDOWS\system32\igfxpers.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\j2re1.4.2_03\bin\jusched.exe
O4 - HKLM\..\Run: [DVDLauncher] "C:\Program Files\CyberLink\PowerDVD\DVDLauncher.exe"
O4 - HKLM\..\Run: [dla] C:\WINDOWS\system32\dla\tfswctrl.exe
O4 - HKLM\..\Run: [ISUSPM Startup] "C:\Program Files\Common Files\InstallShield\UpdateService\isuspm.exe" -startup
O4 - HKLM\..\Run: [ISUSScheduler] "C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe" -start
O4 - HKLM\..\Run: [MimBoot] C:\PROGRA~1\MUSICM~1\MUSICM~3\mimboot.exe
O4 - HKLM\..\Run: [MMTray] "C:\Program Files\Musicmatch\Musicmatch Jukebox\mm_tray.exe"
O4 - HKLM\..\Run: [BJCFD] C:\Program Files\BroadJump\Client Foundation\CFD.exe
O4 - HKLM\..\Run: [YBrowser] C:\PROGRA~1\Yahoo!\browser\ybrwicon.exe
O4 - HKLM\..\Run: [NapsterShell] C:\Program Files\Napster\napster.exe /systray
O4 - HKLM\..\Run: [YSearchProtection] "C:\Program Files\Yahoo!\Search Protection\SearchProtection.exe"
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKCU\..\Run: [Yahoo! Pager] "C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe" -quiet
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOW