here are my logs from the steps
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 8:28:51 AM, on 2/10/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16574)
Boot mode: Normal
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\LEXBCES.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
C:\Program Files\Common Files\LightScribe\LSSrvc.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\wscntfy.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
C:\Program Files\Java\jre1.6.0_01\bin\jusched.exe
C:\Program Files\hpq\HP Wireless Assistant\HP Wireless Assistant.exe
C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\Program Files\Hp\HP Software Update\HPWuSchd2.exe
C:\Program Files\QuickTime\qttask.exe
C:\Program Files\HPQ\Quick Launch Buttons\EabServr.exe
C:\Program Files\HPQ\SHARED\HPQWMI.exe
C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe
C:\Program Files\HP\Digital Imaging\bin\hpqSRMon.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe
C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
C:\Program Files\d2\D2Loader-1.11b.exe
C:\Program Files\Diablo II\D2Loader-1.11b.exe
C:\Program Files\internet explorer\iexplore.exe
C:\WINDOWS\system32\NOTEPAD.EXE
C:\WINDOWS\system32\NOTEPAD.EXE
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://forums.d2jsp....p?showforum=169
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.serial99.com/?a
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page =
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page =
O2 - BHO: (no name) - {470C6F7E-167B-4A5D-9B52-55A05F3B2C53} - C:\WINDOWS\system32\pmkjk.dll (file missing)
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_01\bin\ssv.dll
O2 - BHO: (no name) - {a4c4f4c1-3cc3-42b6-9834-de2121474adb} - C:\WINDOWS\system32\qdtgtjy.dll (file missing)
O4 - HKLM\..\Run: [ATIPTA] C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_01\bin\jusched.exe"
O4 - HKLM\..\Run: [hpWirelessAssistant] C:\Program Files\hpq\HP Wireless Assistant\HP Wireless Assistant.exe
O4 - HKLM\..\Run: [SynTPLpr] C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
O4 - HKLM\..\Run: [HP Software Update] C:\Program Files\Hp\HP Software Update\HPWuSchd2.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [eabconfg.cpl] C:\Program Files\HPQ\Quick Launch Buttons\EabServr.exe /Start
O4 - HKLM\..\Run: [Cpqset] C:\Program Files\HPQ\Default Settings\cpqset.exe
O4 - HKLM\..\Run: [LSBWatcher] c:\hp\drivers\hplsbwatcher\lsburnwatcher.exe
O4 - HKLM\..\Run: [ISUSPM Startup] C:\PROGRA~1\COMMON~1\INSTAL~1\UPDATE~1\ISUSPM.exe -startup
O4 - HKLM\..\Run: [ISUSScheduler] "C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe" -start
O4 - HKLM\..\Run: [hpqSRMon] C:\Program Files\HP\Digital Imaging\bin\hpqSRMon.exe
O4 - HKLM\..\Run: [!AVG Anti-Spyware] "C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" /minimized
O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\MSN Messenger\MsnMsgr.Exe" /background
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [SUPERAntiSpyware] C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O8 - Extra context menu item: &AOL Toolbar search - res://C:\Program Files\AOL Toolbar\toolbar.dll/SEARCH.HTML
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~4\Office10\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_01\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_01\bin\ssv.dll
O9 - Extra button: PartyPoker.com - {B7FE5D70-9AA2-40F1-9C6B-12A255F085E1} - C:\WINDOWS\system32\shdocvw.dll
O9 - Extra 'Tools' menuitem: PartyPoker.com - {B7FE5D70-9AA2-40F1-9C6B-12A255F085E1} - C:\WINDOWS\system32\shdocvw.dll
O9 - Extra button: (no name) - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - (no file)
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O13 - WWW Prefix: http://www.serial99.com/?
O14 - IERESET.INF: START_PAGE_URL=http://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iehome&locale=EN_US&c=Q305&bd=presario&pf=laptop
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft....k/?linkid=39204
O16 - DPF: {49232000-16E4-426C-A231-62846947304B} (SysData Class) - http://ipgweb.cce.hp...ads/sysinfo.cab
O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - http://acs.pandasoft...free/asinst.cab
O20 - Winlogon Notify: !SASWinLogon - C:\Program Files\SUPERAntiSpyware\SASWINLO.dll
O20 - Winlogon Notify: pmnoonm - pmnoonm.dll (file missing)
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: AVG Anti-Spyware Guard - GRISOFT s.r.o. - C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
O23 - Service: HP WMI Interface (hpqwmi) - Hewlett-Packard Development Company, L.P. - C:\Program Files\HPQ\SHARED\HPQWMI.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe
O23 - Service: LexBce Server (LexBceS) - Lexmark International, Inc. - C:\WINDOWS\system32\LEXBCES.EXE
O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Unknown owner - C:\Program Files\Common Files\LightScribe\LSSrvc.exe
--
End of file - 6913 bytes
---------------------------------------------------------
AVG Anti-Spyware - Scan Report
---------------------------------------------------------
+ Created at: 2:17:54 PM 2/8/2008
+ Scan result:
C:\Documents and Settings\Todd\Application Data\SpywareBot\Quarantine\07-01-2008-07-30-12\43.qit -> Adware.Mirar : No action taken.
C:\Documents and Settings\Todd\Application Data\SpywareBot\Quarantine\07-01-2008-07-30-12\81.qit -> Downloader.Agent.fjx : No action taken.
C:\Documents and Settings\Administrator\Application Data\SpywareBot\Quarantine\24-12-2007-18-48-15\517.qit/Setup.exe -> Downloader.VB.bsa : No action taken.
C:\Documents and Settings\Todd\Application Data\SpywareBot\Quarantine\30-12-2007-08-16-55\4.qit -> Downloader.VB.cho : No action taken.
C:\Documents and Settings\Administrator\Application Data\SpywareBot\Quarantine\24-12-2007-18-48-15\516.qit -> Downloader.Wimad.l : No action taken.
C:\Documents and Settings\Todd\Desktop\backups\backup-20071216-111611-195.dll -> Not-A-Virus.Adware.Agent : No action taken.
C:\WINDOWS\system32\nsu3B2.dll -> Not-A-Virus.Adware.Agent : No action taken.
C:\WINDOWS\system32\qdtgtjy.dll -> Not-A-Virus.Adware.Agent : No action taken.
C:\Documents and Settings\Todd\Application Data\SpywareBot\Quarantine\30-12-2007-08-16-55\2.qit/Mirar_VC_Setup_876932.exe -> Not-A-Virus.Adware.Mirar : No action taken.
C:\Documents and Settings\Todd\Application Data\SpywareBot\Quarantine\30-12-2007-08-16-55\3.qit/Mirar_VC_Setup_876932.exe -> Not-A-Virus.Adware.Mirar : No action taken.
C:\Documents and Settings\Administrator\Application Data\SpywareBot\Quarantine\24-12-2007-18-48-15\523.qit/setup.exe -> Not-A-Virus.Adware.NewWeb : No action taken.
C:\Documents and Settings\Todd\Desktop\setup.exe -> Not-A-Virus.Adware.NewWeb : No action taken.
C:\Documents and Settings\Todd\Application Data\SpywareBot\Quarantine\07-01-2008-07-30-12\44.qit -> Not-A-Virus.Adware.TTC : No action taken.
C:\Documents and Settings\Todd\Application Data\SpywareBot\Quarantine\30-12-2007-08-16-55\1.qit -> Not-A-Virus.Adware.Virtumonde : No action taken.
C:\Documents and Settings\Todd\Application Data\SpywareBot\Quarantine\30-12-2007-08-16-55\5.qit -> Not-A-Virus.Adware.Virtumonde : No action taken.
C:\WINDOWS\system32\gebxwus.dll -> Not-A-Virus.Adware.Virtumonde : No action taken.
C:\WINDOWS\system32\pmnoonm.dll -> Not-A-Virus.Adware.Virtumonde : No action taken.
[256] C:\WINDOWS\system32\pmkjk.dll -> Not-A-Virus.Adware.Virtumonde : No action taken.
[872] C:\WINDOWS\system32\pmkjk.dll -> Not-A-Virus.Adware.Virtumonde : No action taken.
C:\Documents and Settings\Administrator\Application Data\SpywareBot\Quarantine\24-12-2007-18-48-15\549.qit -> Not-A-Virus.Adware.WebHancer : No action taken.
C:\Documents and Settings\Todd\Application Data\SpywareBot\Quarantine\07-01-2008-07-30-12\3.qit -> TrackingCookie.Advertising : No action taken.
C:\Documents and Settings\Todd\Application Data\SpywareBot\Quarantine\08-02-2008-09-38-28\4.qit -> TrackingCookie.Advertising : No action taken.
C:\Documents and Settings\Todd\Application Data\SpywareBot\Quarantine\25-12-2007-09-25-56\11.qit -> TrackingCookie.Advertising : No action taken.
C:\Documents and Settings\Administrator\Application Data\SpywareBot\Quarantine\24-12-2007-18-48-15\3.qit -> TrackingCookie.Atdmt : No action taken.
C:\Documents and Settings\Todd\Application Data\SpywareBot\Quarantine\07-01-2008-07-30-12\4.qit -> TrackingCookie.Atdmt : No action taken.
C:\Documents and Settings\Todd\Application Data\SpywareBot\Quarantine\08-02-2008-09-38-28\6.qit -> TrackingCookie.Atdmt : No action taken.
C:\Documents and Settings\Todd\Application Data\SpywareBot\Quarantine\25-12-2007-09-25-56\16.qit -> TrackingCookie.Atdmt : No action taken.
C:\Documents and Settings\Todd\Application Data\SpywareBot\Quarantine\30-12-2007-08-04-05\0.qit -> TrackingCookie.Atdmt : No action taken.
C:\Documents and Settings\Todd\Application Data\SpywareBot\Quarantine\08-02-2008-09-38-28\13.qit -> TrackingCookie.Burstbeacon : No action taken.
C:\Documents and Settings\Todd\Application Data\SpywareBot\Quarantine\25-12-2007-09-25-56\20.qit -> TrackingCookie.Burstbeacon : No action taken.
C:\Documents and Settings\Todd\Application Data\SpywareBot\Quarantine\08-02-2008-09-38-28\7.qit -> TrackingCookie.Burstnet : No action taken.
C:\Documents and Settings\Todd\Application Data\SpywareBot\Quarantine\25-12-2007-09-25-56\21.qit -> TrackingCookie.Burstnet : No action taken.
C:\Documents and Settings\Todd\Application Data\SpywareBot\Quarantine\30-12-2007-08-04-05\1.qit -> TrackingCookie.Coremetrics : No action taken.
C:\Documents and Settings\Todd\Application Data\SpywareBot\Quarantine\08-02-2008-09-38-28\8.qit -> TrackingCookie.Doubleclick : No action taken.
C:\Documents and Settings\Todd\Application Data\SpywareBot\Quarantine\08-02-2008-09-38-28\3.qit -> TrackingCookie.Euroclick : No action taken.
C:\Documents and Settings\Todd\Application Data\SpywareBot\Quarantine\25-12-2007-09-25-56\2.qit -> TrackingCookie.Euroclick : No action taken.
C:\Documents and Settings\Todd\Application Data\SpywareBot\Quarantine\07-01-2008-07-30-12\6.qit -> TrackingCookie.Fastclick : No action taken.
C:\Documents and Settings\Todd\Application Data\SpywareBot\Quarantine\25-12-2007-09-25-56\22.qit -> TrackingCookie.Fastclick : No action taken.
C:\Documents and Settings\Administrator\Application Data\SpywareBot\Quarantine\24-12-2007-18-50-05\0.qit -> TrackingCookie.Mediaplex : No action taken.
C:\Documents and Settings\Todd\Application Data\SpywareBot\Quarantine\07-01-2008-07-30-12\9.qit -> TrackingCookie.Mediaplex : No action taken.
C:\Documents and Settings\Todd\Application Data\SpywareBot\Quarantine\25-12-2007-09-25-56\27.qit -> TrackingCookie.Mediaplex : No action taken.
C:\Documents and Settings\Todd\Application Data\SpywareBot\Quarantine\30-12-2007-08-04-05\3.qit -> TrackingCookie.Mediaplex : No action taken.
C:\Documents and Settings\Todd\Cookies\[email protected][2].txt -> TrackingCookie.Netflame : No action taken.
C:\Documents and Settings\Administrator\Application Data\SpywareBot\Quarantine\24-12-2007-18-48-15\4.qit -> TrackingCookie.Overture : No action taken.
C:\Documents and Settings\Todd\Application Data\SpywareBot\Quarantine\25-12-2007-09-25-56\31.qit -> TrackingCookie.Overture : No action taken.
C:\Documents and Settings\Todd\Application Data\SpywareBot\Quarantine\25-12-2007-09-25-56\32.qit -> TrackingCookie.Overture : No action taken.
C:\Documents and Settings\Todd\Application Data\SpywareBot\Quarantine\30-12-2007-08-04-05\4.qit -> TrackingCookie.Overture : No action taken.
C:\Documents and Settings\Todd\Application Data\SpywareBot\Quarantine\07-01-2008-07-30-12\10.qit -> TrackingCookie.Pointroll : No action taken.
C:\Documents and Settings\Todd\Application Data\SpywareBot\Quarantine\25-12-2007-09-25-56\33.qit -> TrackingCookie.Pointroll : No action taken.
C:\Documents and Settings\Todd\Application Data\SpywareBot\Quarantine\07-01-2008-07-30-12\11.qit -> TrackingCookie.Questionmarket : No action taken.
C:\Documents and Settings\Todd\Application Data\SpywareBot\Quarantine\08-02-2008-09-38-28\11.qit -> TrackingCookie.Questionmarket : No action taken.
C:\Documents and Settings\Todd\Application Data\SpywareBot\Quarantine\25-12-2007-09-25-56\35.qit -> TrackingCookie.Questionmarket : No action taken.
C:\Documents and Settings\Todd\Application Data\SpywareBot\Quarantine\30-12-2007-08-04-05\5.qit -> TrackingCookie.Questionmarket : No action taken.
C:\Documents and Settings\Todd\Application Data\SpywareBot\Quarantine\25-12-2007-09-25-56\36.qit -> TrackingCookie.Realmedia : No action taken.
C:\Documents and Settings\Todd\Application Data\SpywareBot\Quarantine\25-12-2007-09-25-56\37.qit -> TrackingCookie.Realtracker : No action taken.
C:\Documents and Settings\Todd\Application Data\SpywareBot\Quarantine\25-12-2007-09-25-56\38.qit -> TrackingCookie.Revenue : No action taken.
C:\Documents and Settings\Todd\Application Data\SpywareBot\Quarantine\07-01-2008-07-30-12\12.qit -> TrackingCookie.Serving-sys : No action taken.
C:\Documents and Settings\Todd\Application Data\SpywareBot\Quarantine\07-01-2008-07-30-12\5.qit -> TrackingCookie.Serving-sys : No action taken.
C:\Documents and Settings\Todd\Application Data\SpywareBot\Quarantine\25-12-2007-09-25-56\19.qit -> TrackingCookie.Serving-sys : No action taken.
C:\Documents and Settings\Todd\Application Data\SpywareBot\Quarantine\25-12-2007-09-25-56\39.qit -> TrackingCookie.Serving-sys : No action taken.
C:\Documents and Settings\Todd\Application Data\SpywareBot\Quarantine\25-12-2007-09-25-56\40.qit -> TrackingCookie.Spylog : No action taken.
C:\Documents and Settings\Todd\Application Data\SpywareBot\Quarantine\30-12-2007-08-04-05\6.qit -> TrackingCookie.Spylog : No action taken.
C:\Documents and Settings\Todd\Application Data\SpywareBot\Quarantine\07-01-2008-07-30-12\16.qit -> TrackingCookie.Tacoda : No action taken.
C:\Documents and Settings\Todd\Application Data\SpywareBot\Quarantine\25-12-2007-09-25-56\44.qit -> TrackingCookie.Tacoda : No action taken.
C:\Documents and Settings\Todd\Application Data\SpywareBot\Quarantine\30-12-2007-08-04-05\8.qit -> TrackingCookie.Tacoda : No action taken.
C:\Documents and Settings\Todd\Application Data\SpywareBot\Quarantine\07-01-2008-07-30-12\17.qit -> TrackingCookie.Trafficmp : No action taken.
C:\Documents and Settings\Todd\Application Data\SpywareBot\Quarantine\25-12-2007-09-25-56\45.qit -> TrackingCookie.Trafficmp : No action taken.
C:\Documents and Settings\Todd\Application Data\SpywareBot\Quarantine\07-01-2008-07-30-12\18.qit -> TrackingCookie.Tribalfusion : No action taken.
C:\Documents and Settings\Todd\Application Data\SpywareBot\Quarantine\08-02-2008-09-38-28\12.qit -> TrackingCookie.Tribalfusion : No action taken.
C:\Documents and Settings\Todd\Application Data\SpywareBot\Quarantine\25-12-2007-09-25-56\46.qit -> TrackingCookie.Tribalfusion : No action taken.
C:\Documents and Settings\Todd\Application Data\SpywareBot\Quarantine\25-12-2007-09-25-56\49.qit -> TrackingCookie.Valuead : No action taken.
C:\Documents and Settings\Administrator\Application Data\SpywareBot\Quarantine\24-12-2007-18-48-15\5.qit -> TrackingCookie.Webtrends : No action taken.
C:\Documents and Settings\Todd\Application Data\SpywareBot\Quarantine\25-12-2007-09-25-56\50.qit -> TrackingCookie.Webtrends : No action taken.
C:\Documents and Settings\Todd\Application Data\SpywareBot\Quarantine\25-12-2007-09-25-56\52.qit -> TrackingCookie.Webtrendslive : No action taken.
C:\Documents and Settings\Todd\Application Data\SpywareBot\Quarantine\25-12-2007-09-25-56\54.qit -> TrackingCookie.Yadro : No action taken.
C:\Documents and Settings\Administrator\Application Data\SpywareBot\Quarantine\24-12-2007-18-48-15\0.qit -> TrackingCookie.Yieldmanager : No action taken.
C:\Documents and Settings\Todd\Application Data\SpywareBot\Quarantine\07-01-2008-07-30-12\0.qit -> TrackingCookie.Yieldmanager : No action taken.
C:\Documents and Settings\Todd\Application Data\SpywareBot\Quarantine\08-02-2008-09-38-28\1.qit -> TrackingCookie.Yieldmanager : No action taken.
C:\Documents and Settings\Todd\Application Data\SpywareBot\Quarantine\25-12-2007-09-25-56\0.qit -> TrackingCookie.Yieldmanager : No action taken.
C:\Documents and Settings\Todd\Application Data\SpywareBot\Quarantine\07-01-2008-07-30-12\19.qit -> TrackingCookie.Zedo : No action taken.
C:\Documents and Settings\Todd\Application Data\SpywareBot\Quarantine\07-01-2008-07-30-12\20.qit -> TrackingCookie.Zedo : No action taken.
C:\Documents and Settings\Todd\Application Data\SpywareBot\Quarantine\07-01-2008-07-30-12\21.qit -> TrackingCookie.Zedo : No action taken.
C:\Documents and Settings\Todd\Application Data\SpywareBot\Quarantine\08-02-2008-09-38-28\14.qit -> TrackingCookie.Zedo : No action taken.
C:\Documents and Settings\Todd\Application Data\SpywareBot\Quarantine\25-12-2007-09-25-56\55.qit -> TrackingCookie.Zedo : No action taken.
C:\Documents and Settings\Todd\Application Data\SpywareBot\Quarantine\30-12-2007-08-04-05\9.qit -> TrackingCookie.Zedo : No action taken.
C:\Documents and Settings\Administrator\Application Data\SpywareBot\Quarantine\24-12-2007-18-48-15\34.qit -> Trojan.Agent : No action taken.
C:\WINDOWS\system32\mm6\ncstdb33.exe -> Trojan.Pakes.bvs : No action taken.
SUPERAntiSpyware Scan Log
Generated 02/08/2008 at 03:53 PM
Application Version : 3.6.1000
Core Rules Database Version : 3398
Trace Rules Database Version: 1390
Scan type : Complete Scan
Total Scan Time : 01:19:38
Memory items scanned : 331
Memory threats detected : 0
Registry items scanned : 5990
Registry threats detected : 27
File items scanned : 59884
File threats detected : 23
Adware.Vundo Variant
HKLM\Software\Classes\CLSID\{8E3FBDE2-7DBD-4040-85D9-29BBC559C129}
HKCR\CLSID\{8E3FBDE2-7DBD-4040-85D9-29BBC559C129}
HKCR\CLSID\{8E3FBDE2-7DBD-4040-85D9-29BBC559C129}\InprocServer32
HKCR\CLSID\{8E3FBDE2-7DBD-4040-85D9-29BBC559C129}\InprocServer32#ThreadingModel
C:\WINDOWS\SYSTEM32\PMNOONM.DLL
HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{8E3FBDE2-7DBD-4040-85D9-29BBC559C129}
HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks#{8E3FBDE2-7DBD-4040-85D9-29BBC559C129}
HKCR\CLSID\{8E3FBDE2-7DBD-4040-85D9-29BBC559C129}
Adware.Tracking Cookie
C:\Documents and Settings\Todd\Cookies\[email protected][1].txt
C:\Documents and Settings\Todd\Cookies\[email protected][1].txt
Unclassified.SpywareBot (Not A Threat)
HKU\S-1-5-21-951131239-1798569983-2617620097-1006\Software\SpywareBot
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\SpywareBot_is1
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\SpywareBot_is1#Inno Setup: Setup Version
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\SpywareBot_is1#Inno Setup: App Path
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\SpywareBot_is1#InstallLocation
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\SpywareBot_is1#Inno Setup: Icon Group
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\SpywareBot_is1#Inno Setup: User
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\SpywareBot_is1#Inno Setup: Selected Tasks
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\SpywareBot_is1#Inno Setup: Deselected Tasks
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\SpywareBot_is1#DisplayName
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\SpywareBot_is1#DisplayIcon
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\SpywareBot_is1#UninstallString
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\SpywareBot_is1#QuietUninstallString
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\SpywareBot_is1#DisplayVersion
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\SpywareBot_is1#Publisher
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\SpywareBot_is1#URLInfoAbout
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\SpywareBot_is1#NoModify
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\SpywareBot_is1#NoRepair
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\SpywareBot_is1#InstallDate
C:\Program Files\SpywareBot\DataBase.ref
C:\Program Files\SpywareBot\Launcher.exe
C:\Program Files\SpywareBot\license.rtf
C:\Program Files\SpywareBot\SpyCleaner.dll
C:\Program Files\SpywareBot\SpywareBot.exe
C:\Program Files\SpywareBot\SpywareBot.url
C:\Program Files\SpywareBot\TCL.dll
C:\Program Files\SpywareBot\unins000.dat
C:\Program Files\SpywareBot\unins000.exe
C:\Program Files\SpywareBot\zlib.dll
C:\Program Files\SpywareBot
C:\Documents and Settings\All Users\Start Menu\Programs\SpywareBot\SpywareBot on the Web.lnk
C:\Documents and Settings\All Users\Start Menu\Programs\SpywareBot\SpywareBot.lnk
C:\Documents and Settings\All Users\Start Menu\Programs\SpywareBot\Uninstall SpywareBot.lnk
C:\Documents and Settings\All Users\Start Menu\Programs\SpywareBot
Adware.Web Buying
HKU\S-1-5-21-951131239-1798569983-2617620097-1006\Software\WebBuying
Adware.WebBuying Assistant-Installer
C:\DOCUMENTS AND SETTINGS\ADMINISTRATOR\APPLICATION DATA\SPYWAREBOT\QUARANTINE\24-12-2007-18-48-15\33.QIT
Adware.webHancer
C:\DOCUMENTS AND SETTINGS\TODD\APPLICATION DATA\SPYWAREBOT\QUARANTINE\07-01-2008-07-30-12\80.QIT
Trojan.Unclassified/FukuRuku
C:\DOCUMENTS AND SETTINGS\TODD\DESKTOP\BACKUPS\BACKUP-20071216-111611-178.DLL
Adware.WebBuying Assistant
C:\SYSTEM VOLUME INFORMATION\_RESTORE{D5341F9C-33F7-43CF-8BD2-1AE937C9BA1B}\RP293\A0092259.DLL
Trojan.SearchTool
C:\WINDOWS\SYSTEM32\UPMEDIA\CONTENTTOOL.DLL