PDA

View Full Version : Cyber defender and Spyware Bot



mtlfs01
2006-12-30, 16:43
Hi on a recent scan S&D found 31 reg entries under Cyber Defender and 3 Spyware Bot tracking cookies. What are these ???Can I delete them? On research Cyber Def seems to be a a spyware program which I never installed. How did it get into my system??Any help please...Thanks

md usa spybot fan
2006-12-30, 17:41
Someone else reported finding multiple registry entries for CyberDefender during a scan after the 2006-12-29 updates:
CyberDefender
http://forums.spybot.info/showthread.php?t=10042
In that thread, leebunyard (http://forums.spybot.info/member.php?u=16388) indicated that they had installed CyberDefender and questioned if the detections were for the antispyware product CyberDefender.

Please post a log of the actual detections you are getting and perhaps someone will be able to determine what those detections are. To do that:
Run another scan.
When the scan completes, right click on the results list then select "Copy results to clipboard".
Paste (Ctrl+V) those results to a new post in this thread.
Thanks.

****************

Note: The following update announcement lists the CyberDefender updates as a PUP (Possibly Unwanted Program):
Updates: 2006-12-29
http://forums.spybot.info/showthread.php?t=10034

larrybdl
2006-12-31, 00:38
I too found cyberdefender after doing latest updates on 2 of my pc's . On the first one I thought it might have been put on by me in the past and not totally removed. I did a search of my computer but the search showed nothing and nothing in my programs or add& remove program. After some research I concluded since I didn't put it on and couldn't confirm it's existence any other way I let spybot get rid of it.
Now I went to update my 2nd computer which is a new install of XP. It also found 52 entries of cyberdefender in registry, just like on my 1st computer. Now I know it has never been installed on this 2nd computer. The only new operations I performed on this on was to update and run AD-Aware which went fine, and update and run spybot to the fore mentioned results. Only thing I can figure is :red: [cyberdefender] came in on one of these actions. Has anyone else seen this trouble????http://forums.spybot.info/images/smilies/red.gif
:red:

md usa spybot fan
2006-12-31, 01:58
larrybdl:

Please post a log of the actual detections you are getting so that we can see what is being detected as CyberDefender. To do that:
Run another scan.
When the scan completes, right click on the results list then select "Copy results to clipboard".
Paste (Ctrl+V) those results to a new post in this thread.
Thanks.

larrybdl
2006-12-31, 03:49
I'm sorry at the time of the post i had already removed cyberdefender with spybot fix, but it sounds like there will be more like me:oops: :red:

larrybdl
2006-12-31, 04:35
I did run it again and cyberdefender is back again with 52 entries to my registry. I did as you said and here are the results.

CyberDefender: Class ID (Registry key, nothing done)
HKEY_CLASSES_ROOT\CLSID\{12BAF052-264C-464B-9D58-C83B3781DD4B}

CyberDefender: Interface (Registry key, nothing done)
HKEY_CLASSES_ROOT\Interface\{12BAF050-264C-464B-9D58-C83B3781DD4B}

CyberDefender: Interface (Registry key, nothing done)
HKEY_CLASSES_ROOT\Interface\{12BAF051-264C-464B-9D58-C83B3781DD4B}

CyberDefender: Root class (Registry key, nothing done)
HKEY_LOCAL_MACHINE\Software\Classes\OEAPIINITCOM.OEAPIInit

CyberDefender: Class ID (Registry key, nothing done)
HKEY_LOCAL_MACHINE\Software\Classes\CLSID\{12BAF052-264C-464B-9D58-C83B3781DD4B}

CyberDefender: Type library (Registry key, nothing done)
HKEY_CLASSES_ROOT\TypeLib\{A4885815-462D-4D7B-895C-78FAE55AB177}

CyberDefender: Class ID (Registry key, nothing done)
HKEY_CLASSES_ROOT\CLSID\{12BAF038-264C-464B-9D58-C83B3781DD4C}

CyberDefender: Interface (Registry key, nothing done)
HKEY_CLASSES_ROOT\Interface\{12BAF037-264C-464B-9D58-C83B3781DD4C}

CyberDefender: Interface (Registry key, nothing done)
HKEY_CLASSES_ROOT\Interface\{12BAF039-264C-464B-9D58-C83B3781DD4C}

CyberDefender: Interface (Registry key, nothing done)
HKEY_CLASSES_ROOT\Interface\{12BAF040-264C-464B-9D58-C83B3781DD4C}

CyberDefender: Interface (Registry key, nothing done)
HKEY_CLASSES_ROOT\Interface\{12BAF044-264C-464B-9D58-C83B3781DD4C}

CyberDefender: Interface (Registry key, nothing done)
HKEY_CLASSES_ROOT\Interface\{12BAF055-264C-464B-9D58-C83B3781DD4C}

CyberDefender: Interface (Registry key, nothing done)
HKEY_CLASSES_ROOT\Interface\{12BAF056-264C-464B-9D58-C83B3781DD4C}

CyberDefender: Interface (Registry key, nothing done)
HKEY_CLASSES_ROOT\Interface\{12BAF057-264C-464B-9D58-C83B3781DD4C}

CyberDefender: Interface (Registry key, nothing done)
HKEY_CLASSES_ROOT\Interface\{12BAF058-264C-464B-9D58-C83B3781DD4C}

CyberDefender: Interface (Registry key, nothing done)
HKEY_CLASSES_ROOT\Interface\{12BAF05A-264C-464B-9D58-C83B3781DD4C}

CyberDefender: Interface (Registry key, nothing done)
HKEY_CLASSES_ROOT\Interface\{12BAF05B-264C-464B-9D58-C83B3781DD4C}

CyberDefender: Interface (Registry key, nothing done)
HKEY_CLASSES_ROOT\Interface\{12BAF067-264C-464B-9D58-C83B3781DD4C}

CyberDefender: Interface (Registry key, nothing done)
HKEY_CLASSES_ROOT\Interface\{12BAF068-264C-464B-9D58-C83B3781DD4C}

CyberDefender: Root class (Registry key, nothing done)
HKEY_LOCAL_MACHINE\Software\Classes\OEAPI.OEAPIObj

CyberDefender: Class ID (Registry key, nothing done)
HKEY_LOCAL_MACHINE\Software\Classes\CLSID\{12BAF038-264C-464B-9D58-C83B3781DD4C}

CyberDefender: Type library (Registry key, nothing done)
HKEY_CLASSES_ROOT\TypeLib\{54B89198-879A-4086-B082-854D3EBFDCC3}

CyberDefender: Class ID (Registry key, nothing done)
HKEY_CLASSES_ROOT\CLSID\{12BAF048-264C-464B-9D58-C83B3781DD4C}

CyberDefender: Root class (Registry key, nothing done)
HKEY_LOCAL_MACHINE\Software\Classes\OEAPI.OEButton

CyberDefender: Class ID (Registry key, nothing done)
HKEY_LOCAL_MACHINE\Software\Classes\CLSID\{12BAF048-264C-464B-9D58-C83B3781DD4C}

CyberDefender: Class ID (Registry key, nothing done)
HKEY_CLASSES_ROOT\CLSID\{12BAF070-264C-464B-9D58-C83B3781DD4B}

CyberDefender: Interface (Registry key, nothing done)
HKEY_CLASSES_ROOT\Interface\{12BAF091-264C-464B-9D58-C83B3781DD4B}

CyberDefender: Interface (Registry key, nothing done)
HKEY_CLASSES_ROOT\Interface\{12BAF0A1-264C-464B-9D58-C83B3781DD4B}

CyberDefender: Interface (Registry key, nothing done)
HKEY_CLASSES_ROOT\Interface\{12BAF0A2-264C-464B-9D58-C83B3781DD4B}

CyberDefender: Interface (Registry key, nothing done)
HKEY_CLASSES_ROOT\Interface\{12BAF0B5-264C-464B-9D58-C83B3781DD4B}

CyberDefender: Interface (Registry key, nothing done)
HKEY_CLASSES_ROOT\Interface\{12BAF0C9-264C-464B-9D58-C83B3781DD4B}

CyberDefender: Root class (Registry key, nothing done)
HKEY_LOCAL_MACHINE\Software\Classes\OESTORE.OEFolder

CyberDefender: Class ID (Registry key, nothing done)
HKEY_LOCAL_MACHINE\Software\Classes\CLSID\{12BAF070-264C-464B-9D58-C83B3781DD4B}

CyberDefender: Type library (Registry key, nothing done)
HKEY_CLASSES_ROOT\TypeLib\{A684B0CB-4EA0-4C72-8AEF-3C98D767FAD2}

CyberDefender: Class ID (Registry key, nothing done)
HKEY_CLASSES_ROOT\CLSID\{12BAF0A5-264C-464B-9D58-C83B3781DD4B}

CyberDefender: Root class (Registry key, nothing done)
HKEY_LOCAL_MACHINE\Software\Classes\OESTORE.OEFolderManager

CyberDefender: Class ID (Registry key, nothing done)
HKEY_LOCAL_MACHINE\Software\Classes\CLSID\{12BAF0A5-264C-464B-9D58-C83B3781DD4B}

CyberDefender: Class ID (Registry key, nothing done)
HKEY_CLASSES_ROOT\CLSID\{12BAF069-264C-464B-9D58-C83B3781DD4C}

CyberDefender: Root class (Registry key, nothing done)
HKEY_LOCAL_MACHINE\Software\Classes\OEAPI.OEMenu

CyberDefender: Class ID (Registry key, nothing done)
HKEY_LOCAL_MACHINE\Software\Classes\CLSID\{12BAF069-264C-464B-9D58-C83B3781DD4C}

CyberDefender: Class ID (Registry key, nothing done)
HKEY_CLASSES_ROOT\CLSID\{12BAF059-264C-464B-9D58-C83B3781DD4C}

CyberDefender: Root class (Registry key, nothing done)
HKEY_LOCAL_MACHINE\Software\Classes\OEAPI.OEMenuItem

CyberDefender: Class ID (Registry key, nothing done)
HKEY_LOCAL_MACHINE\Software\Classes\CLSID\{12BAF059-264C-464B-9D58-C83B3781DD4C}

CyberDefender: Class ID (Registry key, nothing done)
HKEY_CLASSES_ROOT\CLSID\{12BAF0B1-264C-464B-9D58-C83B3781DD4B}

CyberDefender: Root class (Registry key, nothing done)
HKEY_LOCAL_MACHINE\Software\Classes\OESTORE.OEMessage

CyberDefender: Class ID (Registry key, nothing done)
HKEY_LOCAL_MACHINE\Software\Classes\CLSID\{12BAF0B1-264C-464B-9D58-C83B3781DD4B}

CyberDefender: Class ID (Registry key, nothing done)
HKEY_CLASSES_ROOT\CLSID\{12BAF05C-264C-464B-9D58-C83B3781DD4C}

CyberDefender: Root class (Registry key, nothing done)
HKEY_LOCAL_MACHINE\Software\Classes\OEAPI.OEMsgWnd

CyberDefender: Class ID (Registry key, nothing done)
HKEY_LOCAL_MACHINE\Software\Classes\CLSID\{12BAF05C-264C-464B-9D58-C83B3781DD4C}

CyberDefender: Class ID (Registry key, nothing done)
HKEY_CLASSES_ROOT\CLSID\{12BAF045-264C-464B-9D58-C83B3781DD4C}

CyberDefender: Root class (Registry key, nothing done)
HKEY_LOCAL_MACHINE\Software\Classes\OEAPI.OEToolbar

CyberDefender: Class ID (Registry key, nothing done)
HKEY_LOCAL_MACHINE\Software\Classes\CLSID\{12BAF045-264C-464B-9D58-C83B3781DD4C}

MediaPlex: Tracking cookie (Firefox: default) (Cookie, nothing done)


MediaPlex: Tracking cookie (Firefox: default) (Cookie, nothing done)


MediaPlex: Tracking cookie (Firefox: default) (Cookie, nothing done)


MediaPlex: Tracking cookie (Firefox: default) (Cookie, nothing done)



--- Spybot - Search & Destroy version: 1.4 (build: 20050523) ---

2006-08-20 unins000.exe (51.41.0.0)
2005-05-31 blindman.exe (1.0.0.1)
2005-05-31 SpybotSD.exe (1.4.0.3)
2005-05-31 TeaTimer.exe (1.4.0.2)
2005-05-31 Update.exe (1.4.0.0)
2005-05-31 aports.dll (2.1.0.0)
2005-05-31 borlndmm.dll (7.0.4.453)
2005-05-31 delphimm.dll (7.0.4.453)
2005-05-31 SDHelper.dll (1.4.0.0)
2005-05-31 UnzDll.dll (1.73.1.1)
2005-05-31 ZipDll.dll (1.73.2.0)
2006-02-06 advcheck.dll (1.0.2.0)
2006-02-20 Tools.dll (2.0.0.2)
2006-12-29 Includes\Cookies.sbi (*)
2006-12-29 Includes\Revision.sbi (*)
2005-02-17 Includes\Tracks.uti
2006-12-29 Includes\TrojansC.sbi (*)
2006-12-29 Includes\SpybotsC.sbi (*)
2006-12-29 Includes\SecurityC.sbi (*)
2006-12-29 Includes\PUPSC.sbi (*)
2006-12-29 Includes\MalwareC.sbi (*)
2006-12-29 Includes\KeyloggersC.sbi (*)
2006-12-29 Includes\HijackersC.sbi (*)
2006-11-24 Includes\Hijackers.sbi (*)
2006-10-27 Includes\Keyloggers.sbi (*)
2006-12-08 Includes\Trojans.sbi (*)
2006-12-29 Includes\DialerC.sbi (*)
2006-12-08 Includes\Dialer.sbi (*)
2006-12-22 Includes\Malware.sbi (*)
2006-12-08 Includes\Security.sbi (*)
2006-10-13 Includes\Spybots.sbi (*)
2006-10-20 Includes\PUPS.sbi (*)

larrybdl
2007-01-01, 15:59
Now this is my 3rd computer , updated spybot ran scan 52 entries cyberdefender found in registry!!! Could this possibly have any thing to do with windows defender??? Which is another program all 3 pc share as a common factor

md usa spybot fan
2007-01-01, 16:37
larrybdl:

I am not getting any CyberDefender detections and I have:
Windows Defender Version: 1.1.1593.0
Engine Version: 1.1.1904.0
Definition Version: 1.14.1948.9
According to the following undated McAfee Web page some of the same registry entries that are being detected as CyberDefender during your Spybot-S&D Scan are added by Scam Sensor for Outlook Express 2.0:
Scam Sensor for Outlook Express 2.0 (ScamSensorForOutlookExpressInstaller.exe)
http://www.siteadvisor.com/sites/scam-sensor.com/downloads/1234119/
According to that article:

In our tests, this download was free of adware, spyware and other unwanted programs.
I think that you may have to wait until someone from Team Spybot sorts out what these detections are for.

kitty
2007-01-02, 15:12
Hi. I am also experiencing the same cyber defender issues. No idea how it happened. I did note that the number of detections seems to vary after each deletion (31 versus 64). I also found reference to a file name uwcdsbho.dll on the following website: http://www.fbmsoftware.com/spyware-net/Application/Cyber-Defender/

I did a search of the files and folders on my system, found the file and deleted it however Spybot continues to detect the cyber defender entries in the registry.

I also had a couple of other "symptons" at the same time.
1. Encountered an application error in the Spam Bully software when opening Outlook Express. Fix this by unistalling / reinstalling the Spam Bully software. I have had to do this 2 - 3 times as the problem recurrs.
2. My system is set for the monitor to powersave after 15 minutes and was not doing so until I found the uwcdsbho.dll file and deleted it.

These conditions may not be related to the cyber defender problem, but I think they are as all was well prior to and I never had these conditions before then.

Hope you guys come up with a fix... its frustrating having to scan and delete all of the time.

Thanks

Kitty:red:

Yodama
2007-01-02, 16:40
it appears that CyberDefender is using modules , which are also used in other antispam software, thus those items reported in larrybdls report are considered false positives and will be removed from our detection database with the next update scheduled for friday.

md usa spybot fan
2007-01-02, 16:58
Yodama:

Thanks for looking into the problem.

kitty
2007-01-02, 18:10
Thanks for posting a reply. Looking forward to Friday's update.

Kitty

:bigthumb:

CJESRE
2007-01-03, 02:37
I am also getting the same problem. Every time I run SPybot and "fix" the problem with Cyberdefender, it pops right back up. here are the entries I received --


CyberDefender: Root class (Registry key, nothing done)
HKEY_LOCAL_MACHINE\Software\Classes\OEAPI.OEAPIObj

CyberDefender: Class ID (Registry key, nothing done)
HKEY_LOCAL_MACHINE\Software\Classes\CLSID\{8D8E99B1-42F5-45D6-8A0B-960F49AB6AB6}

CyberDefender: Root class (Registry key, nothing done)
HKEY_LOCAL_MACHINE\Software\Classes\OEAPI.OEButton

CyberDefender: Class ID (Registry key, nothing done)
HKEY_LOCAL_MACHINE\Software\Classes\CLSID\{31CC1045-35BA-47AE-AB6B-60D200F5E1F3}

CyberDefender: Root class (Registry key, nothing done)
HKEY_LOCAL_MACHINE\Software\Classes\OESTORE.OEFolder

CyberDefender: Class ID (Registry key, nothing done)
HKEY_LOCAL_MACHINE\Software\Classes\CLSID\{74F3CFB7-FA10-4ADC-8E4E-1971B8ED3F4E}

CyberDefender: Root class (Registry key, nothing done)
HKEY_LOCAL_MACHINE\Software\Classes\OESTORE.OEFolderManager

CyberDefender: Class ID (Registry key, nothing done)
HKEY_LOCAL_MACHINE\Software\Classes\CLSID\{7AA80989-472B-43C4-858A-8128C556103F}

CyberDefender: Root class (Registry key, nothing done)
HKEY_LOCAL_MACHINE\Software\Classes\OEAPI.OEMenu

CyberDefender: Class ID (Registry key, nothing done)
HKEY_LOCAL_MACHINE\Software\Classes\CLSID\{6AE4000C-91DE-4254-8745-A054D1A608D1}

CyberDefender: Root class (Registry key, nothing done)
HKEY_LOCAL_MACHINE\Software\Classes\OEAPI.OEMenuItem

CyberDefender: Class ID (Registry key, nothing done)
HKEY_LOCAL_MACHINE\Software\Classes\CLSID\{E4575CC6-6A40-47A2-9996-897248E916E1}

CyberDefender: Root class (Registry key, nothing done)
HKEY_LOCAL_MACHINE\Software\Classes\OESTORE.OEMessage

CyberDefender: Class ID (Registry key, nothing done)
HKEY_LOCAL_MACHINE\Software\Classes\CLSID\{0A7F2881-86B3-45BF-B371-1F44C8793AB9}

CyberDefender: Root class (Registry key, nothing done)
HKEY_LOCAL_MACHINE\Software\Classes\OEAPI.OEMsgWnd

CyberDefender: Class ID (Registry key, nothing done)
HKEY_LOCAL_MACHINE\Software\Classes\CLSID\{F91962CC-CBA5-40EA-B47B-48F8BE69F7BD}

CyberDefender: Root class (Registry key, nothing done)
HKEY_LOCAL_MACHINE\Software\Classes\OEAPI.OEToolbar

CyberDefender: Class ID (Registry key, nothing done)
HKEY_LOCAL_MACHINE\Software\Classes\CLSID\{31130A1D-5F17-4127-B67A-3CF97D9AFD7B}


--- Spybot - Search & Destroy version: 1.4 (build: 20050523) ---

2005-05-31 blindman.exe (1.0.0.1)
2005-05-31 SpybotSD.exe (1.4.0.3)
2005-05-31 TeaTimer.exe (1.4.0.2)
2006-08-29 unins000.exe (51.41.0.0)
2005-05-31 Update.exe (1.4.0.0)
2006-02-06 advcheck.dll (1.0.2.0)
2005-05-31 aports.dll (2.1.0.0)
2005-05-31 borlndmm.dll (7.0.4.453)
2005-05-31 delphimm.dll (7.0.4.453)
2005-05-31 SDHelper.dll (1.4.0.0)
2006-02-20 Tools.dll (2.0.0.2)
2005-05-31 UnzDll.dll (1.73.1.1)
2005-05-31 ZipDll.dll (1.73.2.0)
2006-12-29 Includes\Cookies.sbi (*)
2006-12-08 Includes\Dialer.sbi (*)
2006-12-29 Includes\DialerC.sbi (*)
2006-11-24 Includes\Hijackers.sbi (*)
2006-12-29 Includes\HijackersC.sbi (*)
2006-10-27 Includes\Keyloggers.sbi (*)
2006-12-29 Includes\KeyloggersC.sbi (*)
2006-12-22 Includes\Malware.sbi (*)
2006-12-29 Includes\MalwareC.sbi (*)
2006-10-20 Includes\PUPS.sbi (*)
2006-12-29 Includes\PUPSC.sbi (*)
2006-12-29 Includes\Revision.sbi (*)
2006-12-08 Includes\Security.sbi (*)
2006-12-29 Includes\SecurityC.sbi (*)
2006-10-13 Includes\Spybots.sbi (*)
2006-12-29 Includes\SpybotsC.sbi (*)
2005-02-17 Includes\Tracks.uti
2006-12-08 Includes\Trojans.sbi (*)
2006-12-29 Includes\TrojansC.sbi (*)

spybotsandra
2007-01-04, 10:17
Hello,

We are sorry, this has been a false positive and will be fixed in the next detection updates.

Best regards
Sandra
Team Spybot

SPIKEpilot
2007-03-14, 16:46
spybotsandra or Yodama, has anything changed yet?? I did my first scan after installing CyberDefender & got 129 entries with Spybot! Also got 8 entries on SpyBlocs, listed halfway down. I think this may be related to the toolbar they stick you with. Is it worth keeping CyberDefender or not? Here they are, split into 2 parts…

SpyBlocs: Settings (Registry key, nothing done)
HKEY_USERS\S-1-5-21-1177238915-287218729-725345543-1004\Software\WsLiveUp

SpyBlocs: Root class (Registry key, nothing done)
HKEY_LOCAL_MACHINE\Software\Classes\SssTbar.SecurityToolbar

SpyBlocs: Root class (Registry key, nothing done)
HKEY_LOCAL_MACHINE\Software\Classes\SssTbar.SecurityToolbar.1

SpyBlocs: Class ID (Registry key, nothing done)
HKEY_LOCAL_MACHINE\Software\Classes\CLSID\{68FF9E0F-2E96-4467-87FA-1A8B9734C7E7}

SpyBlocs: Browser helper object (Registry key, nothing done)
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{68FF9E0F-2E96-4467-87FA-1A8B9734C7E7}

SpyBlocs: Settings (Registry key, nothing done)
HKEY_CLASSES_ROOT\TypeLib\{EBFA54AD-64D4-4BFF-98C6-304703831D3A}

SpyBlocs: Settings (Registry key, nothing done)
HKEY_LOCAL_MACHINE\SOFTWARE\WsLiveUp

SpyBlocs: Settings (Registry value, nothing done)
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar\{68FF9E0F-2E96-4467-87FA-1A8B9734C7E7}

CyberDefender: Root class (Registry key, nothing done)
HKEY_LOCAL_MACHINE\Software\Classes\AdPresenter.AdDriver

CyberDefender: Root class (Registry key, nothing done)
HKEY_LOCAL_MACHINE\Software\Classes\AdPresenter.AdDriver.1

CyberDefender: Class ID (Registry key, nothing done)
HKEY_LOCAL_MACHINE\Software\Classes\CLSID\{DB3E7824-CF2C-4EE9-89B8-046ED4A1D937}

CyberDefender: Root class (Registry key, nothing done)
HKEY_LOCAL_MACHINE\Software\Classes\ISSHost.AdPopupExternalObject

CyberDefender: Root class (Registry key, nothing done)
HKEY_LOCAL_MACHINE\Software\Classes\ISSHost.AdPopupExternalObject.1

CyberDefender: Class ID (Registry key, nothing done)
HKEY_LOCAL_MACHINE\Software\Classes\CLSID\{F4C94434-96F2-493A-951A-7622E7AE13BE}

CyberDefender: Root class (Registry key, nothing done)
HKEY_LOCAL_MACHINE\Software\Classes\CDWebVw.AFraudExternalObject

CyberDefender: Root class (Registry key, nothing done)
HKEY_LOCAL_MACHINE\Software\Classes\CDWebVw.AFraudExternalObject.1

CyberDefender: Class ID (Registry key, nothing done)
HKEY_LOCAL_MACHINE\Software\Classes\CLSID\{7BA9DA59-959A-4E1B-A600-CE06A033415C}

CyberDefender: Root class (Registry key, nothing done)
HKEY_LOCAL_MACHINE\Software\Classes\CDWebVw.AHackerExternalObject

CyberDefender: Root class (Registry key, nothing done)
HKEY_LOCAL_MACHINE\Software\Classes\CDWebVw.AHackerExternalObject.1

CyberDefender: Class ID (Registry key, nothing done)
HKEY_LOCAL_MACHINE\Software\Classes\CLSID\{27D02595-3CBA-4743-98A4-BC7AC3B02B36}

CyberDefender: Interface (Registry key, nothing done)
HKEY_CLASSES_ROOT\Interface\{324E5453-C53C-450B-8FD9-8868B8BB1C5C}

CyberDefender: Interface (Registry key, nothing done)
HKEY_CLASSES_ROOT\Interface\{33910C6F-06BD-43FB-8FFB-416942ECF972}

CyberDefender: Interface (Registry key, nothing done)
HKEY_CLASSES_ROOT\Interface\{637FC5CA-2D56-48F6-AF67-1A4577C099A1}

CyberDefender: Interface (Registry key, nothing done)
HKEY_CLASSES_ROOT\Interface\{69FEF985-97C8-4E46-811A-BAC83EE708BE}

CyberDefender: Interface (Registry key, nothing done)
HKEY_CLASSES_ROOT\Interface\{6E56B033-0B2C-46CB-9AD1-620C5D39BE6B}

CyberDefender: Interface (Registry key, nothing done)
HKEY_CLASSES_ROOT\Interface\{ABBE333C-73E7-4373-B1C0-B1422308CEB1}

CyberDefender: Interface (Registry key, nothing done)
HKEY_CLASSES_ROOT\Interface\{BC768FF3-8079-4638-8E16-BED7CB891F3A}

CyberDefender: Interface (Registry key, nothing done)
HKEY_CLASSES_ROOT\Interface\{C57152F7-1F7B-4CB2-B4E9-E76854F24748}

CyberDefender: Interface (Registry key, nothing done)
HKEY_CLASSES_ROOT\Interface\{EDA1AE5C-75E4-4A19-A3CE-6939A9D30AC4}

CyberDefender: Interface (Registry key, nothing done)
HKEY_CLASSES_ROOT\Interface\{F6DCBA17-D2E9-430E-8D6F-83198004F674}

CyberDefender: Type library (Registry key, nothing done)
HKEY_CLASSES_ROOT\TypeLib\{85EA5F42-C785-450A-81E5-176639B8A3C9}

CyberDefender: Class ID (Registry key, nothing done)
HKEY_CLASSES_ROOT\CLSID\{883F25C2-614F-444B-B110-F2ED90E61925}

CyberDefender: Root class (Registry key, nothing done)
HKEY_LOCAL_MACHINE\Software\Classes\ISSHost.ASExternalObject

CyberDefender: Root class (Registry key, nothing done)
HKEY_LOCAL_MACHINE\Software\Classes\ISSHost.ASExternalObject.1

CyberDefender: Class ID (Registry key, nothing done)
HKEY_LOCAL_MACHINE\Software\Classes\CLSID\{883F25C2-614F-444B-B110-F2ED90E61925}

CyberDefender: Root class (Registry key, nothing done)
HKEY_LOCAL_MACHINE\Software\Classes\ISSHost.AVExternalObject

CyberDefender: Root class (Registry key, nothing done)
HKEY_LOCAL_MACHINE\Software\Classes\ISSHost.AVExternalObject.1

CyberDefender: Class ID (Registry key, nothing done)
HKEY_LOCAL_MACHINE\Software\Classes\CLSID\{CBA052B9-7988-4594-A44F-9239F9BD0B57}

CyberDefender: Application ID (Registry key, nothing done)
HKEY_CLASSES_ROOT\AppID\{F3097835-8B74-4AA4-BCDC-CFAF7DB2F8C9}

CyberDefender: Application ID (Registry key, nothing done)
HKEY_CLASSES_ROOT\AppID\cdNetAdDll.DLL

CyberDefender: Root class (Registry key, nothing done)
HKEY_LOCAL_MACHINE\Software\Classes\cdNetAdDll.CDExternalUIHandler

CyberDefender: Root class (Registry key, nothing done)
HKEY_LOCAL_MACHINE\Software\Classes\cdNetAdDll.CDExternalUIHandler.1

CyberDefender: Class ID (Registry key, nothing done)
HKEY_LOCAL_MACHINE\Software\Classes\CLSID\{4077DB6F-7798-4383-AB03-D63EE4394BBE}

CyberDefender: Interface (Registry key, nothing done)
HKEY_CLASSES_ROOT\Interface\{1DB58612-6520-4909-9086-DED483AE7794}

CyberDefender: Interface (Registry key, nothing done)
HKEY_CLASSES_ROOT\Interface\{8797B1BD-894E-4389-BA3F-794BB35BE771}

CyberDefender: Interface (Registry key, nothing done)
HKEY_CLASSES_ROOT\Interface\{FFE02EFD-5683-4DBA-B38A-13A868D49A27}

CyberDefender: Type library (Registry key, nothing done)
HKEY_CLASSES_ROOT\TypeLib\{81B6711B-EAEA-4282-AEBE-A19199FC7D2C}

CyberDefender: Root class (Registry key, nothing done)
HKEY_LOCAL_MACHINE\Software\Classes\CDWebVw.CDHtmlVw

CyberDefender: Root class (Registry key, nothing done)
HKEY_LOCAL_MACHINE\Software\Classes\CDWebVw.CDHtmlVw.1

CyberDefender: Class ID (Registry key, nothing done)
HKEY_LOCAL_MACHINE\Software\Classes\CLSID\{B114534C-B917-4289-9B5F-E1F3F050251F}

CyberDefender: Class ID (Registry key, nothing done)
HKEY_CLASSES_ROOT\CLSID\{57EC406A-23E9-4E30-85D3-2C7D1804C1F3}

CyberDefender: Root class (Registry key, nothing done)
HKEY_LOCAL_MACHINE\Software\Classes\ISSHost.CDNetwork

CyberDefender: Root class (Registry key, nothing done)
HKEY_LOCAL_MACHINE\Software\Classes\ISSHost.CDNetwork.1

CyberDefender: Class ID (Registry key, nothing done)
HKEY_LOCAL_MACHINE\Software\Classes\CLSID\{57EC406A-23E9-4E30-85D3-2C7D1804C1F3}

CyberDefender: Application ID (Registry key, nothing done)
HKEY_CLASSES_ROOT\AppID\{F5155FFD-602F-4DB7-9629-BFF3FEE49093}

CyberDefender: Application ID (Registry key, nothing done)
HKEY_CLASSES_ROOT\AppID\CDWebVw.DLL

CyberDefender: Root class (Registry key, nothing done)
HKEY_LOCAL_MACHINE\Software\Classes\CDISSHost.CISSHostExternalUIHndlr

CyberDefender: Root class (Registry key, nothing done)
HKEY_LOCAL_MACHINE\Software\Classes\CDISSHost.CISSHostExternalUIHndlr.1

CyberDefender: Class ID (Registry key, nothing done)
HKEY_LOCAL_MACHINE\Software\Classes\CLSID\{0ECF824A-5FC2-4B96-AF46-F656996DB323}

CyberDefender: Interface (Registry key, nothing done)
HKEY_CLASSES_ROOT\Interface\{1B2BBC27-951C-4C38-A0F0-9587FD586E1E}

CyberDefender: User settings (Registry key, nothing done)
HKEY_USERS\S-1-5-21-1177238915-287218729-725345543-1004\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{68FF9E0F-2E96-4467-87FA-1A8B9734C7E7}

CyberDefender: Class ID (Registry key, nothing done)
HKEY_CLASSES_ROOT\CLSID\{CEF3D8E2-7497-48d8-B574-DA1C4AB22B93}

CyberDefender: Application ID (Registry key, nothing done)
HKEY_CLASSES_ROOT\AppID\{0F0ED099-0402-4CF8-8A74-520F0ED354DF}

CyberDefender: Application ID (Registry key, nothing done)
HKEY_CLASSES_ROOT\AppID\EDCConfig.EXE

CyberDefender: Class ID (Registry key, nothing done)
HKEY_CLASSES_ROOT\CLSID\{5E53AE00-5746-475E-8F7F-4EA85A1BC7A4}

CyberDefender: Root class (Registry key, nothing done)
HKEY_LOCAL_MACHINE\Software\Classes\CyberDefender.EDCConfigWizard

CyberDefender: Root class (Registry key, nothing done)
HKEY_LOCAL_MACHINE\Software\Classes\CyberDefender.EDCConfigWizard.1

CyberDefender: Class ID (Registry key, nothing done)
HKEY_LOCAL_MACHINE\Software\Classes\CLSID\{5E53AE00-5746-475E-8F7F-4EA85A1BC7A4}

CyberDefender: Interface (Registry key, nothing done)
HKEY_CLASSES_ROOT\Interface\{95888CF7-CF1A-4CBF-86C4-467EDEDA7ECD}

CyberDefender: Type library (Registry key, nothing done)
HKEY_CLASSES_ROOT\TypeLib\{EE3739AE-27BB-48BE-BD79-E820389BD8C0}

CyberDefender: Class ID (Registry key, nothing done)
HKEY_CLASSES_ROOT\CLSID\{5AD9503F-7B90-469E-9C29-765ED10C3CE8}

CyberDefender: Root class (Registry key, nothing done)
HKEY_LOCAL_MACHINE\Software\Classes\ISSHost.ISSWinExternal

CyberDefender: Root class (Registry key, nothing done)
HKEY_LOCAL_MACHINE\Software\Classes\ISSHost.ISSWinExternal.1

CyberDefender: Class ID (Registry key, nothing done)
HKEY_LOCAL_MACHINE\Software\Classes\CLSID\{5AD9503F-7B90-469E-9C29-765ED10C3CE8}

CyberDefender: Class ID (Registry key, nothing done)
HKEY_CLASSES_ROOT\CLSID\{D197ACF1-13C9-4C0C-B1CF-E868EAF58531}

CyberDefender: Root class (Registry key, nothing done)
HKEY_LOCAL_MACHINE\Software\Classes\CybDefCom.OfficeAntiVirus

CyberDefender: Root class (Registry key, nothing done)
HKEY_LOCAL_MACHINE\Software\Classes\CybDefCom.OfficeAntiVirus.1

CyberDefender: Class ID (Registry key, nothing done)
HKEY_LOCAL_MACHINE\Software\Classes\CLSID\{D197ACF1-13C9-4C0C-B1CF-E868EAF58531}

CyberDefender: Type library (Registry key, nothing done)
HKEY_CLASSES_ROOT\TypeLib\{AD4E8864-245A-4C8D-BE59-23A6C9DD54AA}

CyberDefender: Class ID (Registry key, nothing done)
HKEY_CLASSES_ROOT\CLSID\{308193AC-E3A0-49D9-8649-7AE023F69067}

CyberDefender: Root class (Registry key, nothing done)
HKEY_LOCAL_MACHINE\Software\Classes\ISSHost.PhishExternalObject

CyberDefender: Root class (Registry key, nothing done)
HKEY_LOCAL_MACHINE\Software\Classes\ISSHost.PhishExternalObject.1

CyberDefender: Class ID (Registry key, nothing done)
HKEY_LOCAL_MACHINE\Software\Classes\CLSID\{308193AC-E3A0-49D9-8649-7AE023F69067}

CyberDefender: Class ID (Registry key, nothing done)
HKEY_CLASSES_ROOT\CLSID\{1DB58612-6520-4909-9086-DED483AE7794}

CyberDefender: Class ID (Registry key, nothing done)
HKEY_CLASSES_ROOT\CLSID\{F6DCBA17-D2E9-430E-8D6F-83198004F674}

CyberDefender: Text file (File, nothing done)
c:\CybDefInstallInfo.log

CyberDefender: Program directory (Directory, nothing done)
C:\Documents and Settings\Mark\Local Settings\Application Data\cdstbar\

CyberDefender: Text file (File, nothing done)
C:\Documents and Settings\Mark\Local Settings\Application Data\cdstbar\cdinstx.log

CyberDefender: Picture (File, nothing done)
C:\Documents and Settings\Mark\Local Settings\Application Data\cdstbar\st.ico

CyberDefender: Program directory (Directory, nothing done)
C:\Documents and Settings\Mark\Local Settings\Application Data\cdstbar\Scam Alert\

CyberDefender: Web page (File, nothing done)
C:\Documents and Settings\Mark\Local Settings\Application Data\cdstbar\Scam Alert\charset.html

CyberDefender: Web page (File, nothing done)
C:\Documents and Settings\Mark\Local Settings\Application Data\cdstbar\Scam Alert\cookie.html

CyberDefender: Web page (File, nothing done)
C:\Documents and Settings\Mark\Local Settings\Application Data\cdstbar\Scam Alert\defaultCharset.html

CyberDefender: Web page (File, nothing done)
C:\Documents and Settings\Mark\Local Settings\Application Data\cdstbar\Scam Alert\form.html

CyberDefender: Web page (File, nothing done)
C:\Documents and Settings\Mark\Local Settings\Application Data\cdstbar\Scam Alert\frame.html

CyberDefender: Web page (File, nothing done)
C:\Documents and Settings\Mark\Local Settings\Application Data\cdstbar\Scam Alert\gray.htm

CyberDefender: Web page (File, nothing done)
C:\Documents and Settings\Mark\Local Settings\Application Data\cdstbar\Scam Alert\green.htm

CyberDefender: Web page (File, nothing done)
C:\Documents and Settings\Mark\Local Settings\Application Data\cdstbar\Scam Alert\host.html

CyberDefender: Web page (File, nothing done)
C:\Documents and Settings\Mark\Local Settings\Application Data\cdstbar\Scam Alert\popup.html

CyberDefender: Web page (File, nothing done)
C:\Documents and Settings\Mark\Local Settings\Application Data\cdstbar\Scam Alert\port.html

CyberDefender: Web page (File, nothing done)
C:\Documents and Settings\Mark\Local Settings\Application Data\cdstbar\Scam Alert\protocol.html

CyberDefender: Web page (File, nothing done)
C:\Documents and Settings\Mark\Local Settings\Application Data\cdstbar\Scam Alert\red.htm

CyberDefender: Web page (File, nothing done)
C:\Documents and Settings\Mark\Local Settings\Application Data\cdstbar\Scam Alert\referrer.html

CyberDefender: Web page (File, nothing done)
C:\Documents and Settings\Mark\Local Settings\Application Data\cdstbar\Scam Alert\scamalert.htm

CyberDefender: Web page (File, nothing done)
C:\Documents and Settings\Mark\Local Settings\Application Data\cdstbar\Scam Alert\scamalert.htm1

CyberDefender: Web page (File, nothing done)
C:\Documents and Settings\Mark\Local Settings\Application Data\cdstbar\Scam Alert\script.html

CyberDefender: Web page (File, nothing done)
C:\Documents and Settings\Mark\Local Settings\Application Data\cdstbar\Scam Alert\security.html

CyberDefender: Data (File, nothing done)
C:\Documents and Settings\Mark\Local Settings\Application Data\cdstbar\Scam Alert\vssver.scc

CyberDefender: Web page (File, nothing done)
C:\Documents and Settings\Mark\Local Settings\Application Data\cdstbar\Scam Alert\yellow.htm

CyberDefender: Program directory (Directory, nothing done)
C:\Documents and Settings\Mark\Local Settings\Application Data\cdstbar\Scam Alert\images\

CyberDefender: Picture (File, nothing done)
C:\Documents and Settings\Mark\Local Settings\Application Data\cdstbar\Scam Alert\images\alertheader.gif

CyberDefender: Picture (File, nothing done)
C:\Documents and Settings\Mark\Local Settings\Application Data\cdstbar\Scam Alert\images\bt_actualsite.gif

CyberDefender: Picture (File, nothing done)
C:\Documents and Settings\Mark\Local Settings\Application Data\cdstbar\Scam Alert\images\bt_actualsite-over.gif

CyberDefender: Picture (File, nothing done)
C:\Documents and Settings\Mark\Local Settings\Application Data\cdstbar\Scam Alert\images\bt_closewindow.gif

CyberDefender: Picture (File, nothing done)
C:\Documents and Settings\Mark\Local Settings\Application Data\cdstbar\Scam Alert\images\bt_closewindow-over.gif

CyberDefender: Picture (File, nothing done)
C:\Documents and Settings\Mark\Local Settings\Application Data\cdstbar\Scam Alert\images\bt_fakesite.gif

CyberDefender: Picture (File, nothing done)
C:\Documents and Settings\Mark\Local Settings\Application Data\cdstbar\Scam Alert\images\bt_fakesite-over.gif

CyberDefender: Picture (File, nothing done)
C:\Documents and Settings\Mark\Local Settings\Application Data\cdstbar\Scam Alert\images\spacer.gif

CyberDefender: Picture (File, nothing done)
C:\Documents and Settings\Mark\Local Settings\Application Data\cdstbar\Scam Alert\images\vssver.scc

CyberDefender: Picture (File, nothing done)
C:\Documents and Settings\Mark\Local Settings\Application Data\cdstbar\Scam Alert\images\warning_bar.gif

CyberDefender: Program directory (Directory, nothing done)
C:\Documents and Settings\Mark\Local Settings\Application Data\cdstbar\UserGuide\

CyberDefender: Program group (Directory, nothing done)
C:\Documents and Settings\Mark\Start Menu\Programs\CyberDefender\

CyberDefender: Link (File, nothing done)
C:\Documents and Settings\Mark\Start Menu\Programs\CyberDefender\Early Detection Center Support.url

CyberDefender: User settings (Registry key, nothing done)
HKEY_USERS\S-1-5-21-1177238915-287218729-725345543-1004\Software\CyberDefender

CyberDefender: Settings (Registry key, nothing done)
HKEY_LOCAL_MACHINE\SOFTWARE\CyberDefender

CyberDefender: Uninstall settings (Registry key, nothing done)
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{83682B4C-B98C-4BEB-97CC-8EAD2AF9E4C6}

CyberDefender: Uninstall settings (Registry key, nothing done)
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{AA63780B-DDB7-417b-8A13-E5AFBE08E807}

CyberDefender: Uninstall settings (Registry key, nothing done)
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{AC5352DA-F4F2-4A59-A1BF-41546342746B}

CyberDefender: <enter description here> (Registry value, nothing done)
HKEY_LOCAL_MACHINE\SOFTWARE\WsLiveUp\Install Information\Path

CyberDefender: Settings (Registry key, nothing done)
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\CDAVFS

CyberDefender: Root class (Registry key, nothing done)
HKEY_LOCAL_MACHINE\Software\Classes\CDWebVw.UpsellWizard

CyberDefender: Root class (Registry key, nothing done)
HKEY_LOCAL_MACHINE\Software\Classes\CDWebVw.UpsellWizard.1

CyberDefender: Class ID (Registry key, nothing done)
HKEY_LOCAL_MACHINE\Software\Classes\CLSID\{9585D7B6-C0E9-483C-986E-740C5DE01F97}

CyberDefender: Root class (Registry key, nothing done)
HKEY_LOCAL_MACHINE\Software\Classes\cdNetAdDll.WinExternal

CyberDefender: Root class (Registry key, nothing done)
HKEY_LOCAL_MACHINE\Software\Classes\cdNetAdDll.WinExternal.1

CyberDefender: Class ID (Registry key, nothing done)
HKEY_LOCAL_MACHINE\Software\Classes\CLSID\{C3D18B79-43CE-4A88-9019-1CF60E2DEDE9}

CyberDefender: User settings (Registry key, nothing done)
HKEY_USERS\S-1-5-21-1177238915-287218729-725345543-1004\Software\Microsoft\Windows\CurrentVersion\Explorer\MenuOrder\Start Menu\Programs\CyberDefender

SPIKEpilot
2007-03-14, 16:47
...Part 2


SpyBlocs: Settings (Registry key, nothing done)
HKEY_USERS\S-1-5-21-1177238915-287218729-725345543-1004\Software\WsLiveUp

SpyBlocs: Root class (Registry key, nothing done)
HKEY_LOCAL_MACHINE\Software\Classes\SssTbar.SecurityToolbar

SpyBlocs: Root class (Registry key, nothing done)
HKEY_LOCAL_MACHINE\Software\Classes\SssTbar.SecurityToolbar.1

SpyBlocs: Class ID (Registry key, nothing done)
HKEY_LOCAL_MACHINE\Software\Classes\CLSID\{68FF9E0F-2E96-4467-87FA-1A8B9734C7E7}

SpyBlocs: Browser helper object (Registry key, nothing done)
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{68FF9E0F-2E96-4467-87FA-1A8B9734C7E7}

SpyBlocs: Settings (Registry key, nothing done)
HKEY_CLASSES_ROOT\TypeLib\{EBFA54AD-64D4-4BFF-98C6-304703831D3A}

SpyBlocs: Settings (Registry key, nothing done)
HKEY_LOCAL_MACHINE\SOFTWARE\WsLiveUp

SpyBlocs: Settings (Registry value, nothing done)
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar\{68FF9E0F-2E96-4467-87FA-1A8B9734C7E7}

CyberDefender: Root class (Registry key, nothing done)
HKEY_LOCAL_MACHINE\Software\Classes\AdPresenter.AdDriver

CyberDefender: Root class (Registry key, nothing done)
HKEY_LOCAL_MACHINE\Software\Classes\AdPresenter.AdDriver.1

CyberDefender: Class ID (Registry key, nothing done)
HKEY_LOCAL_MACHINE\Software\Classes\CLSID\{DB3E7824-CF2C-4EE9-89B8-046ED4A1D937}

CyberDefender: Root class (Registry key, nothing done)
HKEY_LOCAL_MACHINE\Software\Classes\ISSHost.AdPopupExternalObject

CyberDefender: Root class (Registry key, nothing done)
HKEY_LOCAL_MACHINE\Software\Classes\ISSHost.AdPopupExternalObject.1

CyberDefender: Class ID (Registry key, nothing done)
HKEY_LOCAL_MACHINE\Software\Classes\CLSID\{F4C94434-96F2-493A-951A-7622E7AE13BE}

CyberDefender: Root class (Registry key, nothing done)
HKEY_LOCAL_MACHINE\Software\Classes\CDWebVw.AFraudExternalObject

CyberDefender: Root class (Registry key, nothing done)
HKEY_LOCAL_MACHINE\Software\Classes\CDWebVw.AFraudExternalObject.1

CyberDefender: Class ID (Registry key, nothing done)
HKEY_LOCAL_MACHINE\Software\Classes\CLSID\{7BA9DA59-959A-4E1B-A600-CE06A033415C}

CyberDefender: Root class (Registry key, nothing done)
HKEY_LOCAL_MACHINE\Software\Classes\CDWebVw.AHackerExternalObject

CyberDefender: Root class (Registry key, nothing done)
HKEY_LOCAL_MACHINE\Software\Classes\CDWebVw.AHackerExternalObject.1

CyberDefender: Class ID (Registry key, nothing done)
HKEY_LOCAL_MACHINE\Software\Classes\CLSID\{27D02595-3CBA-4743-98A4-BC7AC3B02B36}

CyberDefender: Interface (Registry key, nothing done)
HKEY_CLASSES_ROOT\Interface\{324E5453-C53C-450B-8FD9-8868B8BB1C5C}

CyberDefender: Interface (Registry key, nothing done)
HKEY_CLASSES_ROOT\Interface\{33910C6F-06BD-43FB-8FFB-416942ECF972}

CyberDefender: Interface (Registry key, nothing done)
HKEY_CLASSES_ROOT\Interface\{637FC5CA-2D56-48F6-AF67-1A4577C099A1}

CyberDefender: Interface (Registry key, nothing done)
HKEY_CLASSES_ROOT\Interface\{69FEF985-97C8-4E46-811A-BAC83EE708BE}

CyberDefender: Interface (Registry key, nothing done)
HKEY_CLASSES_ROOT\Interface\{6E56B033-0B2C-46CB-9AD1-620C5D39BE6B}

CyberDefender: Interface (Registry key, nothing done)
HKEY_CLASSES_ROOT\Interface\{ABBE333C-73E7-4373-B1C0-B1422308CEB1}

CyberDefender: Interface (Registry key, nothing done)
HKEY_CLASSES_ROOT\Interface\{BC768FF3-8079-4638-8E16-BED7CB891F3A}

CyberDefender: Interface (Registry key, nothing done)
HKEY_CLASSES_ROOT\Interface\{C57152F7-1F7B-4CB2-B4E9-E76854F24748}

CyberDefender: Interface (Registry key, nothing done)
HKEY_CLASSES_ROOT\Interface\{EDA1AE5C-75E4-4A19-A3CE-6939A9D30AC4}

CyberDefender: Interface (Registry key, nothing done)
HKEY_CLASSES_ROOT\Interface\{F6DCBA17-D2E9-430E-8D6F-83198004F674}

CyberDefender: Type library (Registry key, nothing done)
HKEY_CLASSES_ROOT\TypeLib\{85EA5F42-C785-450A-81E5-176639B8A3C9}

CyberDefender: Class ID (Registry key, nothing done)
HKEY_CLASSES_ROOT\CLSID\{883F25C2-614F-444B-B110-F2ED90E61925}

CyberDefender: Root class (Registry key, nothing done)
HKEY_LOCAL_MACHINE\Software\Classes\ISSHost.ASExternalObject

CyberDefender: Root class (Registry key, nothing done)
HKEY_LOCAL_MACHINE\Software\Classes\ISSHost.ASExternalObject.1

CyberDefender: Class ID (Registry key, nothing done)
HKEY_LOCAL_MACHINE\Software\Classes\CLSID\{883F25C2-614F-444B-B110-F2ED90E61925}

CyberDefender: Root class (Registry key, nothing done)
HKEY_LOCAL_MACHINE\Software\Classes\ISSHost.AVExternalObject

CyberDefender: Root class (Registry key, nothing done)
HKEY_LOCAL_MACHINE\Software\Classes\ISSHost.AVExternalObject.1

CyberDefender: Class ID (Registry key, nothing done)
HKEY_LOCAL_MACHINE\Software\Classes\CLSID\{CBA052B9-7988-4594-A44F-9239F9BD0B57}

CyberDefender: Application ID (Registry key, nothing done)
HKEY_CLASSES_ROOT\AppID\{F3097835-8B74-4AA4-BCDC-CFAF7DB2F8C9}

CyberDefender: Application ID (Registry key, nothing done)
HKEY_CLASSES_ROOT\AppID\cdNetAdDll.DLL

CyberDefender: Root class (Registry key, nothing done)
HKEY_LOCAL_MACHINE\Software\Classes\cdNetAdDll.CDExternalUIHandler

CyberDefender: Root class (Registry key, nothing done)
HKEY_LOCAL_MACHINE\Software\Classes\cdNetAdDll.CDExternalUIHandler.1

CyberDefender: Class ID (Registry key, nothing done)
HKEY_LOCAL_MACHINE\Software\Classes\CLSID\{4077DB6F-7798-4383-AB03-D63EE4394BBE}

CyberDefender: Interface (Registry key, nothing done)
HKEY_CLASSES_ROOT\Interface\{1DB58612-6520-4909-9086-DED483AE7794}

CyberDefender: Interface (Registry key, nothing done)
HKEY_CLASSES_ROOT\Interface\{8797B1BD-894E-4389-BA3F-794BB35BE771}

CyberDefender: Interface (Registry key, nothing done)
HKEY_CLASSES_ROOT\Interface\{FFE02EFD-5683-4DBA-B38A-13A868D49A27}

CyberDefender: Type library (Registry key, nothing done)
HKEY_CLASSES_ROOT\TypeLib\{81B6711B-EAEA-4282-AEBE-A19199FC7D2C}

CyberDefender: Root class (Registry key, nothing done)
HKEY_LOCAL_MACHINE\Software\Classes\CDWebVw.CDHtmlVw

CyberDefender: Root class (Registry key, nothing done)
HKEY_LOCAL_MACHINE\Software\Classes\CDWebVw.CDHtmlVw.1

CyberDefender: Class ID (Registry key, nothing done)
HKEY_LOCAL_MACHINE\Software\Classes\CLSID\{B114534C-B917-4289-9B5F-E1F3F050251F}

CyberDefender: Class ID (Registry key, nothing done)
HKEY_CLASSES_ROOT\CLSID\{57EC406A-23E9-4E30-85D3-2C7D1804C1F3}

CyberDefender: Root class (Registry key, nothing done)
HKEY_LOCAL_MACHINE\Software\Classes\ISSHost.CDNetwork

CyberDefender: Root class (Registry key, nothing done)
HKEY_LOCAL_MACHINE\Software\Classes\ISSHost.CDNetwork.1

CyberDefender: Class ID (Registry key, nothing done)
HKEY_LOCAL_MACHINE\Software\Classes\CLSID\{57EC406A-23E9-4E30-85D3-2C7D1804C1F3}

CyberDefender: Application ID (Registry key, nothing done)
HKEY_CLASSES_ROOT\AppID\{F5155FFD-602F-4DB7-9629-BFF3FEE49093}

CyberDefender: Application ID (Registry key, nothing done)
HKEY_CLASSES_ROOT\AppID\CDWebVw.DLL

CyberDefender: Root class (Registry key, nothing done)
HKEY_LOCAL_MACHINE\Software\Classes\CDISSHost.CISSHostExternalUIHndlr

CyberDefender: Root class (Registry key, nothing done)
HKEY_LOCAL_MACHINE\Software\Classes\CDISSHost.CISSHostExternalUIHndlr.1

CyberDefender: Class ID (Registry key, nothing done)
HKEY_LOCAL_MACHINE\Software\Classes\CLSID\{0ECF824A-5FC2-4B96-AF46-F656996DB323}

CyberDefender: Interface (Registry key, nothing done)
HKEY_CLASSES_ROOT\Interface\{1B2BBC27-951C-4C38-A0F0-9587FD586E1E}

CyberDefender: User settings (Registry key, nothing done)
HKEY_USERS\S-1-5-21-1177238915-287218729-725345543-1004\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{68FF9E0F-2E96-4467-87FA-1A8B9734C7E7}

CyberDefender: Class ID (Registry key, nothing done)
HKEY_CLASSES_ROOT\CLSID\{CEF3D8E2-7497-48d8-B574-DA1C4AB22B93}

CyberDefender: Application ID (Registry key, nothing done)
HKEY_CLASSES_ROOT\AppID\{0F0ED099-0402-4CF8-8A74-520F0ED354DF}

CyberDefender: Application ID (Registry key, nothing done)
HKEY_CLASSES_ROOT\AppID\EDCConfig.EXE

CyberDefender: Class ID (Registry key, nothing done)
HKEY_CLASSES_ROOT\CLSID\{5E53AE00-5746-475E-8F7F-4EA85A1BC7A4}

CyberDefender: Root class (Registry key, nothing done)
HKEY_LOCAL_MACHINE\Software\Classes\CyberDefender.EDCConfigWizard

CyberDefender: Root class (Registry key, nothing done)
HKEY_LOCAL_MACHINE\Software\Classes\CyberDefender.EDCConfigWizard.1

CyberDefender: Class ID (Registry key, nothing done)
HKEY_LOCAL_MACHINE\Software\Classes\CLSID\{5E53AE00-5746-475E-8F7F-4EA85A1BC7A4}

CyberDefender: Interface (Registry key, nothing done)
HKEY_CLASSES_ROOT\Interface\{95888CF7-CF1A-4CBF-86C4-467EDEDA7ECD}

CyberDefender: Type library (Registry key, nothing done)
HKEY_CLASSES_ROOT\TypeLib\{EE3739AE-27BB-48BE-BD79-E820389BD8C0}

CyberDefender: Class ID (Registry key, nothing done)
HKEY_CLASSES_ROOT\CLSID\{5AD9503F-7B90-469E-9C29-765ED10C3CE8}

CyberDefender: Root class (Registry key, nothing done)
HKEY_LOCAL_MACHINE\Software\Classes\ISSHost.ISSWinExternal

CyberDefender: Root class (Registry key, nothing done)
HKEY_LOCAL_MACHINE\Software\Classes\ISSHost.ISSWinExternal.1

CyberDefender: Class ID (Registry key, nothing done)
HKEY_LOCAL_MACHINE\Software\Classes\CLSID\{5AD9503F-7B90-469E-9C29-765ED10C3CE8}

CyberDefender: Class ID (Registry key, nothing done)
HKEY_CLASSES_ROOT\CLSID\{D197ACF1-13C9-4C0C-B1CF-E868EAF58531}

CyberDefender: Root class (Registry key, nothing done)
HKEY_LOCAL_MACHINE\Software\Classes\CybDefCom.OfficeAntiVirus

CyberDefender: Root class (Registry key, nothing done)
HKEY_LOCAL_MACHINE\Software\Classes\CybDefCom.OfficeAntiVirus.1

CyberDefender: Class ID (Registry key, nothing done)
HKEY_LOCAL_MACHINE\Software\Classes\CLSID\{D197ACF1-13C9-4C0C-B1CF-E868EAF58531}

CyberDefender: Type library (Registry key, nothing done)
HKEY_CLASSES_ROOT\TypeLib\{AD4E8864-245A-4C8D-BE59-23A6C9DD54AA}

CyberDefender: Class ID (Registry key, nothing done)
HKEY_CLASSES_ROOT\CLSID\{308193AC-E3A0-49D9-8649-7AE023F69067}

CyberDefender: Root class (Registry key, nothing done)
HKEY_LOCAL_MACHINE\Software\Classes\ISSHost.PhishExternalObject

CyberDefender: Root class (Registry key, nothing done)
HKEY_LOCAL_MACHINE\Software\Classes\ISSHost.PhishExternalObject.1

CyberDefender: Class ID (Registry key, nothing done)
HKEY_LOCAL_MACHINE\Software\Classes\CLSID\{308193AC-E3A0-49D9-8649-7AE023F69067}

CyberDefender: Class ID (Registry key, nothing done)
HKEY_CLASSES_ROOT\CLSID\{1DB58612-6520-4909-9086-DED483AE7794}

CyberDefender: Class ID (Registry key, nothing done)
HKEY_CLASSES_ROOT\CLSID\{F6DCBA17-D2E9-430E-8D6F-83198004F674}

CyberDefender: Text file (File, nothing done)
c:\CybDefInstallInfo.log

CyberDefender: Program directory (Directory, nothing done)
C:\Documents and Settings\Mark\Local Settings\Application Data\cdstbar\

CyberDefender: Text file (File, nothing done)
C:\Documents and Settings\Mark\Local Settings\Application Data\cdstbar\cdinstx.log

CyberDefender: Picture (File, nothing done)
C:\Documents and Settings\Mark\Local Settings\Application Data\cdstbar\st.ico

CyberDefender: Program directory (Directory, nothing done)
C:\Documents and Settings\Mark\Local Settings\Application Data\cdstbar\Scam Alert\

CyberDefender: Web page (File, nothing done)
C:\Documents and Settings\Mark\Local Settings\Application Data\cdstbar\Scam Alert\charset.html

CyberDefender: Web page (File, nothing done)
C:\Documents and Settings\Mark\Local Settings\Application Data\cdstbar\Scam Alert\cookie.html

CyberDefender: Web page (File, nothing done)
C:\Documents and Settings\Mark\Local Settings\Application Data\cdstbar\Scam Alert\defaultCharset.html

CyberDefender: Web page (File, nothing done)
C:\Documents and Settings\Mark\Local Settings\Application Data\cdstbar\Scam Alert\form.html

CyberDefender: Web page (File, nothing done)
C:\Documents and Settings\Mark\Local Settings\Application Data\cdstbar\Scam Alert\frame.html

CyberDefender: Web page (File, nothing done)
C:\Documents and Settings\Mark\Local Settings\Application Data\cdstbar\Scam Alert\gray.htm

CyberDefender: Web page (File, nothing done)
C:\Documents and Settings\Mark\Local Settings\Application Data\cdstbar\Scam Alert\green.htm

CyberDefender: Web page (File, nothing done)
C:\Documents and Settings\Mark\Local Settings\Application Data\cdstbar\Scam Alert\host.html

CyberDefender: Web page (File, nothing done)
C:\Documents and Settings\Mark\Local Settings\Application Data\cdstbar\Scam Alert\popup.html

CyberDefender: Web page (File, nothing done)
C:\Documents and Settings\Mark\Local Settings\Application Data\cdstbar\Scam Alert\port.html

CyberDefender: Web page (File, nothing done)
C:\Documents and Settings\Mark\Local Settings\Application Data\cdstbar\Scam Alert\protocol.html

CyberDefender: Web page (File, nothing done)
C:\Documents and Settings\Mark\Local Settings\Application Data\cdstbar\Scam Alert\red.htm

CyberDefender: Web page (File, nothing done)
C:\Documents and Settings\Mark\Local Settings\Application Data\cdstbar\Scam Alert\referrer.html

CyberDefender: Web page (File, nothing done)
C:\Documents and Settings\Mark\Local Settings\Application Data\cdstbar\Scam Alert\scamalert.htm

CyberDefender: Web page (File, nothing done)
C:\Documents and Settings\Mark\Local Settings\Application Data\cdstbar\Scam Alert\scamalert.htm1

CyberDefender: Web page (File, nothing done)
C:\Documents and Settings\Mark\Local Settings\Application Data\cdstbar\Scam Alert\script.html

CyberDefender: Web page (File, nothing done)
C:\Documents and Settings\Mark\Local Settings\Application Data\cdstbar\Scam Alert\security.html

CyberDefender: Data (File, nothing done)
C:\Documents and Settings\Mark\Local Settings\Application Data\cdstbar\Scam Alert\vssver.scc

CyberDefender: Web page (File, nothing done)
C:\Documents and Settings\Mark\Local Settings\Application Data\cdstbar\Scam Alert\yellow.htm

CyberDefender: Program directory (Directory, nothing done)
C:\Documents and Settings\Mark\Local Settings\Application Data\cdstbar\Scam Alert\images\

CyberDefender: Picture (File, nothing done)
C:\Documents and Settings\Mark\Local Settings\Application Data\cdstbar\Scam Alert\images\alertheader.gif

CyberDefender: Picture (File, nothing done)
C:\Documents and Settings\Mark\Local Settings\Application Data\cdstbar\Scam Alert\images\bt_actualsite.gif

CyberDefender: Picture (File, nothing done)
C:\Documents and Settings\Mark\Local Settings\Application Data\cdstbar\Scam Alert\images\bt_actualsite-over.gif

CyberDefender: Picture (File, nothing done)
C:\Documents and Settings\Mark\Local Settings\Application Data\cdstbar\Scam Alert\images\bt_closewindow.gif

CyberDefender: Picture (File, nothing done)
C:\Documents and Settings\Mark\Local Settings\Application Data\cdstbar\Scam Alert\images\bt_closewindow-over.gif

CyberDefender: Picture (File, nothing done)
C:\Documents and Settings\Mark\Local Settings\Application Data\cdstbar\Scam Alert\images\bt_fakesite.gif

CyberDefender: Picture (File, nothing done)
C:\Documents and Settings\Mark\Local Settings\Application Data\cdstbar\Scam Alert\images\bt_fakesite-over.gif

CyberDefender: Picture (File, nothing done)
C:\Documents and Settings\Mark\Local Settings\Application Data\cdstbar\Scam Alert\images\spacer.gif

CyberDefender: Picture (File, nothing done)
C:\Documents and Settings\Mark\Local Settings\Application Data\cdstbar\Scam Alert\images\vssver.scc

CyberDefender: Picture (File, nothing done)
C:\Documents and Settings\Mark\Local Settings\Application Data\cdstbar\Scam Alert\images\warning_bar.gif

CyberDefender: Program directory (Directory, nothing done)
C:\Documents and Settings\Mark\Local Settings\Application Data\cdstbar\UserGuide\

CyberDefender: Program group (Directory, nothing done)
C:\Documents and Settings\Mark\Start Menu\Programs\CyberDefender\

CyberDefender: Link (File, nothing done)
C:\Documents and Settings\Mark\Start Menu\Programs\CyberDefender\Early Detection Center Support.url

CyberDefender: User settings (Registry key, nothing done)
HKEY_USERS\S-1-5-21-1177238915-287218729-725345543-1004\Software\CyberDefender

CyberDefender: Settings (Registry key, nothing done)
HKEY_LOCAL_MACHINE\SOFTWARE\CyberDefender

CyberDefender: Uninstall settings (Registry key, nothing done)
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{83682B4C-B98C-4BEB-97CC-8EAD2AF9E4C6}

CyberDefender: Uninstall settings (Registry key, nothing done)
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{AA63780B-DDB7-417b-8A13-E5AFBE08E807}

CyberDefender: Uninstall settings (Registry key, nothing done)
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{AC5352DA-F4F2-4A59-A1BF-41546342746B}

CyberDefender: <enter description here> (Registry value, nothing done)
HKEY_LOCAL_MACHINE\SOFTWARE\WsLiveUp\Install Information\Path

CyberDefender: Settings (Registry key, nothing done)
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\CDAVFS

CyberDefender: Root class (Registry key, nothing done)
HKEY_LOCAL_MACHINE\Software\Classes\CDWebVw.UpsellWizard

CyberDefender: Root class (Registry key, nothing done)
HKEY_LOCAL_MACHINE\Software\Classes\CDWebVw.UpsellWizard.1

CyberDefender: Class ID (Registry key, nothing done)
HKEY_LOCAL_MACHINE\Software\Classes\CLSID\{9585D7B6-C0E9-483C-986E-740C5DE01F97}

CyberDefender: Root class (Registry key, nothing done)
HKEY_LOCAL_MACHINE\Software\Classes\cdNetAdDll.WinExternal

CyberDefender: Root class (Registry key, nothing done)
HKEY_LOCAL_MACHINE\Software\Classes\cdNetAdDll.WinExternal.1

CyberDefender: Class ID (Registry key, nothing done)
HKEY_LOCAL_MACHINE\Software\Classes\CLSID\{C3D18B79-43CE-4A88-9019-1CF60E2DEDE9}

CyberDefender: User settings (Registry key, nothing done)
HKEY_USERS\S-1-5-21-1177238915-287218729-725345543-1004\Software\Microsoft\Windows\CurrentVersion\Explorer\MenuOrder\Start Menu\Programs\CyberDefender


--- Spybot - Search & Destroy version: 1.4 (build: 20050523) ---

2005-05-31 blindman.exe (1.0.0.1)
2005-05-31 SpybotSD.exe (1.4.0.3)
2005-05-31 TeaTimer.exe (1.4.0.2)
2006-07-30 unins000.exe (51.41.0.0)
2005-05-31 Update.exe (1.4.0.0)
2007-01-15 advcheck.dll (1.2.1.0)
2005-05-31 aports.dll (2.1.0.0)
2005-05-31 borlndmm.dll (7.0.4.453)
2005-05-31 delphimm.dll (7.0.4.453)
2005-05-31 SDHelper.dll (1.4.0.0)
2007-01-02 Tools.dll (2.0.1.0)
2005-05-31 UnzDll.dll (1.73.1.1)
2005-05-31 ZipDll.dll (1.73.2.0)
2007-03-07 Includes\Cookies.sbi (*)
2006-12-08 Includes\Dialer.sbi (*)
2007-03-07 Includes\DialerC.sbi (*)
2007-02-07 Includes\Hijackers.sbi (*)
2007-03-07 Includes\HijackersC.sbi (*)
2006-10-27 Includes\Keyloggers.sbi (*)
2007-03-07 Includes\KeyloggersC.sbi (*)
2004-11-29 Includes\LSP.sbi (*)
2007-02-14 Includes\Malware.sbi (*)
2007-03-07 Includes\MalwareC.sbi (*)
2007-01-19 Includes\PUPS.sbi (*)
2007-03-07 Includes\PUPSC.sbi (*)
2007-03-07 Includes\Revision.sbi (*)
2006-12-08 Includes\Security.sbi (*)
2007-03-07 Includes\SecurityC.sbi (*)
2007-02-02 Includes\Spybots.sbi (*)
2007-03-07 Includes\SpybotsC.sbi (*)
2005-02-17 Includes\Tracks.uti
2007-03-07 Includes\Trojans.sbi (*)
2007-03-07 Includes\TrojansC.sbi (*)

md usa spybot fan
2007-03-14, 17:23
SPIKEpilot:

FYI

You running with last weeks updates. New updates were released today (2007-03-14). I don't know if this would make a difference, but I suggest that you update and rescan.

SPIKEpilot
2007-03-16, 01:24
Considering the last response before mine (stating something would be changed to the next update) was dated Jan 4, I figured it would have been resolved by now, but I'll try again.

md usa spybot fan
2007-03-16, 05:02
SPIKEpilot:

I would assume that the original problem was fixed as Yodama (http://forums.spybot.info/member.php?u=223) indicated it would be since no one has posted otherwise in the two and a half months since then.

In addition, none of the detections you received are the same as the ones that were originally posted and confirmed as false positives.

CosmicSurfer
2007-03-29, 12:51
Hello,

We are sorry, this has been a false positive and will be fixed in the next detection updates.

Best regards
Sandra
Team Spybot

I'm having the same problem.

I do have CyberDefender running as security software on my machine. But today I started to get hits on SpyBlocs as well. I have previously not done anything to remove CyberDefender after seeing the posts saying it was a false positive and would be addressed with the next upgrade.

Today I downloaded all new upgrades and then ran a Scan. I'm still showing multiple instances of both CyberDefender and SpyBlocs.

What is happenning here?
CosmicSurfer

-------------------
Report - Part 1

SpyBlocs: Settings (Registry key, nothing done)
HKEY_USERS\S-1-5-21-484763869-1682526488-854245398-1004\Software\ebc

SpyBlocs: Settings (Registry key, nothing done)
HKEY_USERS\S-1-5-21-484763869-1682526488-854245398-1004\Software\WsLiveUp

SpyBlocs: Root class (Registry key, nothing done)
HKEY_LOCAL_MACHINE\Software\Classes\SssTbar.SecurityToolbar

SpyBlocs: Root class (Registry key, nothing done)
HKEY_LOCAL_MACHINE\Software\Classes\SssTbar.SecurityToolbar.1

SpyBlocs: Class ID (Registry key, nothing done)
HKEY_LOCAL_MACHINE\Software\Classes\CLSID\{F35CE83E-9EBF-40d5-AE87-53F982389740}

SpyBlocs: Browser helper object (Registry key, nothing done)
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{F35CE83E-9EBF-40d5-AE87-53F982389740}

SpyBlocs: Settings (Registry key, nothing done)
HKEY_CLASSES_ROOT\TypeLib\{EBFA54AD-64D4-4BFF-98C6-304703831D3A}

SpyBlocs: Settings (Registry key, nothing done)
HKEY_LOCAL_MACHINE\SOFTWARE\WsLiveUp

CyberDefender: Root class (Registry key, nothing done)
HKEY_LOCAL_MACHINE\Software\Classes\AdPresenter.AdDriver

CyberDefender: Root class (Registry key, nothing done)
HKEY_LOCAL_MACHINE\Software\Classes\AdPresenter.AdDriver.1

CyberDefender: Class ID (Registry key, nothing done)
HKEY_LOCAL_MACHINE\Software\Classes\CLSID\{DB3E7824-CF2C-4EE9-89B8-046ED4A1D937}

CyberDefender: Root class (Registry key, nothing done)
HKEY_LOCAL_MACHINE\Software\Classes\ISSHost.AdPopupExternalObject

CyberDefender: Root class (Registry key, nothing done)
HKEY_LOCAL_MACHINE\Software\Classes\ISSHost.AdPopupExternalObject.1

CyberDefender: Class ID (Registry key, nothing done)
HKEY_LOCAL_MACHINE\Software\Classes\CLSID\{F4C94434-96F2-493A-951A-7622E7AE13BE}

CyberDefender: Root class (Registry key, nothing done)
HKEY_LOCAL_MACHINE\Software\Classes\CDWebVw.AFraudExternalObject

CyberDefender: Root class (Registry key, nothing done)
HKEY_LOCAL_MACHINE\Software\Classes\CDWebVw.AFraudExternalObject.1

CyberDefender: Class ID (Registry key, nothing done)
HKEY_LOCAL_MACHINE\Software\Classes\CLSID\{7BA9DA59-959A-4E1B-A600-CE06A033415C}

CyberDefender: Root class (Registry key, nothing done)
HKEY_LOCAL_MACHINE\Software\Classes\CDWebVw.AHackerExternalObject

CyberDefender: Root class (Registry key, nothing done)
HKEY_LOCAL_MACHINE\Software\Classes\CDWebVw.AHackerExternalObject.1

CyberDefender: Class ID (Registry key, nothing done)
HKEY_LOCAL_MACHINE\Software\Classes\CLSID\{27D02595-3CBA-4743-98A4-BC7AC3B02B36}

CyberDefender: Interface (Registry key, nothing done)
HKEY_CLASSES_ROOT\Interface\{324E5453-C53C-450B-8FD9-8868B8BB1C5C}

CyberDefender: Interface (Registry key, nothing done)
HKEY_CLASSES_ROOT\Interface\{33910C6F-06BD-43FB-8FFB-416942ECF972}

CyberDefender: Interface (Registry key, nothing done)
HKEY_CLASSES_ROOT\Interface\{637FC5CA-2D56-48F6-AF67-1A4577C099A1}

CyberDefender: Interface (Registry key, nothing done)
HKEY_CLASSES_ROOT\Interface\{69FEF985-97C8-4E46-811A-BAC83EE708BE}

CyberDefender: Interface (Registry key, nothing done)
HKEY_CLASSES_ROOT\Interface\{6E56B033-0B2C-46CB-9AD1-620C5D39BE6B}

CyberDefender: Interface (Registry key, nothing done)
HKEY_CLASSES_ROOT\Interface\{ABBE333C-73E7-4373-B1C0-B1422308CEB1}

CyberDefender: Interface (Registry key, nothing done)
HKEY_CLASSES_ROOT\Interface\{BC768FF3-8079-4638-8E16-BED7CB891F3A}

CyberDefender: Interface (Registry key, nothing done)
HKEY_CLASSES_ROOT\Interface\{C57152F7-1F7B-4CB2-B4E9-E76854F24748}

CyberDefender: Interface (Registry key, nothing done)
HKEY_CLASSES_ROOT\Interface\{EDA1AE5C-75E4-4A19-A3CE-6939A9D30AC4}

CyberDefender: Interface (Registry key, nothing done)
HKEY_CLASSES_ROOT\Interface\{F6DCBA17-D2E9-430E-8D6F-83198004F674}

CyberDefender: Type library (Registry key, nothing done)
HKEY_CLASSES_ROOT\TypeLib\{85EA5F42-C785-450A-81E5-176639B8A3C9}

CyberDefender: Class ID (Registry key, nothing done)
HKEY_CLASSES_ROOT\CLSID\{883F25C2-614F-444B-B110-F2ED90E61925}

CyberDefender: Root class (Registry key, nothing done)
HKEY_LOCAL_MACHINE\Software\Classes\ISSHost.ASExternalObject

CyberDefender: Root class (Registry key, nothing done)
HKEY_LOCAL_MACHINE\Software\Classes\ISSHost.ASExternalObject.1

CyberDefender: Class ID (Registry key, nothing done)
HKEY_LOCAL_MACHINE\Software\Classes\CLSID\{883F25C2-614F-444B-B110-F2ED90E61925}

CyberDefender: Root class (Registry key, nothing done)
HKEY_LOCAL_MACHINE\Software\Classes\ISSHost.AVExternalObject

CyberDefender: Root class (Registry key, nothing done)
HKEY_LOCAL_MACHINE\Software\Classes\ISSHost.AVExternalObject.1

CyberDefender: Class ID (Registry key, nothing done)
HKEY_LOCAL_MACHINE\Software\Classes\CLSID\{CBA052B9-7988-4594-A44F-9239F9BD0B57}

CyberDefender: Application ID (Registry key, nothing done)
HKEY_CLASSES_ROOT\AppID\{F3097835-8B74-4AA4-BCDC-CFAF7DB2F8C9}

CyberDefender: Application ID (Registry key, nothing done)
HKEY_CLASSES_ROOT\AppID\cdNetAdDll.DLL

CyberDefender: Root class (Registry key, nothing done)
HKEY_LOCAL_MACHINE\Software\Classes\cdNetAdDll.CDExternalUIHandler

CyberDefender: Root class (Registry key, nothing done)
HKEY_LOCAL_MACHINE\Software\Classes\cdNetAdDll.CDExternalUIHandler.1

CyberDefender: Class ID (Registry key, nothing done)
HKEY_LOCAL_MACHINE\Software\Classes\CLSID\{4077DB6F-7798-4383-AB03-D63EE4394BBE}

CyberDefender: Interface (Registry key, nothing done)
HKEY_CLASSES_ROOT\Interface\{1DB58612-6520-4909-9086-DED483AE7794}

CyberDefender: Interface (Registry key, nothing done)
HKEY_CLASSES_ROOT\Interface\{8797B1BD-894E-4389-BA3F-794BB35BE771}

CyberDefender: Interface (Registry key, nothing done)
HKEY_CLASSES_ROOT\Interface\{FFE02EFD-5683-4DBA-B38A-13A868D49A27}

CyberDefender: Type library (Registry key, nothing done)
HKEY_CLASSES_ROOT\TypeLib\{81B6711B-EAEA-4282-AEBE-A19199FC7D2C}

CyberDefender: Root class (Registry key, nothing done)
HKEY_LOCAL_MACHINE\Software\Classes\CDWebVw.CDHtmlVw

CyberDefender: Root class (Registry key, nothing done)
HKEY_LOCAL_MACHINE\Software\Classes\CDWebVw.CDHtmlVw.1

CyberDefender: Class ID (Registry key, nothing done)
HKEY_LOCAL_MACHINE\Software\Classes\CLSID\{B114534C-B917-4289-9B5F-E1F3F050251F}

CyberDefender: Class ID (Registry key, nothing done)
HKEY_CLASSES_ROOT\CLSID\{57EC406A-23E9-4E30-85D3-2C7D1804C1F3}

CyberDefender: Root class (Registry key, nothing done)
HKEY_LOCAL_MACHINE\Software\Classes\ISSHost.CDNetwork

CyberDefender: Root class (Registry key, nothing done)
HKEY_LOCAL_MACHINE\Software\Classes\ISSHost.CDNetwork.1

CyberDefender: Class ID (Registry key, nothing done)
HKEY_LOCAL_MACHINE\Software\Classes\CLSID\{57EC406A-23E9-4E30-85D3-2C7D1804C1F3}

CyberDefender: Root class (Registry key, nothing done)
HKEY_LOCAL_MACHINE\Software\Classes\Cdaspm.SpamConfig

CyberDefender: Class ID (Registry key, nothing done)
HKEY_LOCAL_MACHINE\Software\Classes\CLSID\{C31299A6-5742-4E61-9571-4951137AA02D}

CyberDefender: Root class (Registry key, nothing done)
HKEY_LOCAL_MACHINE\Software\Classes\Cdaspm.SpamConfig.1

CyberDefender: Application ID (Registry key, nothing done)
HKEY_CLASSES_ROOT\AppID\{F5155FFD-602F-4DB7-9629-BFF3FEE49093}

CyberDefender: Application ID (Registry key, nothing done)
HKEY_CLASSES_ROOT\AppID\CDWebVw.DLL

CyberDefender: Root class (Registry key, nothing done)
HKEY_LOCAL_MACHINE\Software\Classes\CDISSHost.CISSHostExternalUIHndlr

CyberDefender: Root class (Registry key, nothing done)
HKEY_LOCAL_MACHINE\Software\Classes\CDISSHost.CISSHostExternalUIHndlr.1

CyberDefender: Class ID (Registry key, nothing done)
HKEY_LOCAL_MACHINE\Software\Classes\CLSID\{0ECF824A-5FC2-4B96-AF46-F656996DB323}

CyberDefender: Interface (Registry key, nothing done)
HKEY_CLASSES_ROOT\Interface\{1B2BBC27-951C-4C38-A0F0-9587FD586E1E}

CyberDefender: User settings (Registry key, nothing done)
HKEY_USERS\S-1-5-21-484763869-1682526488-854245398-1004\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{68FF9E0F-2E96-4467-87FA-1A8B9734C7E7}

CyberDefender: Class ID (Registry key, nothing done)
HKEY_CLASSES_ROOT\CLSID\{CEF3D8E2-7497-48d8-B574-DA1C4AB22B93}

CyberDefender: Application ID (Registry key, nothing done)
HKEY_CLASSES_ROOT\AppID\{0F0ED099-0402-4CF8-8A74-520F0ED354DF}

CyberDefender: Application ID (Registry key, nothing done)
HKEY_CLASSES_ROOT\AppID\EDCConfig.EXE

CyberDefender: Class ID (Registry key, nothing done)
HKEY_CLASSES_ROOT\CLSID\{5E53AE00-5746-475E-8F7F-4EA85A1BC7A4}

CyberDefender: Root class (Registry key, nothing done)
HKEY_LOCAL_MACHINE\Software\Classes\CyberDefender.EDCConfigWizard

CyberDefender: Root class (Registry key, nothing done)
HKEY_LOCAL_MACHINE\Software\Classes\CyberDefender.EDCConfigWizard.1

CyberDefender: Class ID (Registry key, nothing done)
HKEY_LOCAL_MACHINE\Software\Classes\CLSID\{5E53AE00-5746-475E-8F7F-4EA85A1BC7A4}

CyberDefender: Interface (Registry key, nothing done)
HKEY_CLASSES_ROOT\Interface\{95888CF7-CF1A-4CBF-86C4-467EDEDA7ECD}

CyberDefender: Type library (Registry key, nothing done)
HKEY_CLASSES_ROOT\TypeLib\{EE3739AE-27BB-48BE-BD79-E820389BD8C0}

CyberDefender: Root class (Registry key, nothing done)
HKEY_LOCAL_MACHINE\Software\Classes\Cdaspm.ExpressAddin

CyberDefender: Root class (Registry key, nothing done)
HKEY_LOCAL_MACHINE\Software\Classes\Cdaspm.ExpressAddin.1

CyberDefender: Class ID (Registry key, nothing done)
HKEY_LOCAL_MACHINE\Software\Classes\CLSID\{8C2B6D2D-543B-4736-A87D-B00FA4BCD0C1}

CyberDefender: Interface (Registry key, nothing done)
HKEY_CLASSES_ROOT\Interface\{C59D9311-C6B3-4B03-B643-8622A8C786C0}

CyberDefender: Interface (Registry key, nothing done)
HKEY_CLASSES_ROOT\Interface\{DFA23BE5-E1D7-4B12-8AAB-A2A4D0052404}

CyberDefender: Type library (Registry key, nothing done)
HKEY_CLASSES_ROOT\TypeLib\{C678C147-4CCC-462D-A75F-450FF2C017C9}

CyberDefender: Class ID (Registry key, nothing done)
HKEY_CLASSES_ROOT\CLSID\{5AD9503F-7B90-469E-9C29-765ED10C3CE8}

CyberDefender: Root class (Registry key, nothing done)
HKEY_LOCAL_MACHINE\Software\Classes\ISSHost.ISSWinExternal

CyberDefender: Root class (Registry key, nothing done)
HKEY_LOCAL_MACHINE\Software\Classes\ISSHost.ISSWinExternal.1

CyberDefender: Class ID (Registry key, nothing done)
HKEY_LOCAL_MACHINE\Software\Classes\CLSID\{5AD9503F-7B90-469E-9C29-765ED10C3CE8}

CyberDefender: Class ID (Registry key, nothing done)
HKEY_CLASSES_ROOT\CLSID\{D197ACF1-13C9-4C0C-B1CF-E868EAF58531}

CyberDefender: Root class (Registry key, nothing done)
HKEY_LOCAL_MACHINE\Software\Classes\CybDefCom.OfficeAntiVirus

CyberDefender: Root class (Registry key, nothing done)
HKEY_LOCAL_MACHINE\Software\Classes\CybDefCom.OfficeAntiVirus.1

CyberDefender: Class ID (Registry key, nothing done)
HKEY_LOCAL_MACHINE\Software\Classes\CLSID\{D197ACF1-13C9-4C0C-B1CF-E868EAF58531}

CyberDefender: Type library (Registry key, nothing done)
HKEY_CLASSES_ROOT\TypeLib\{AD4E8864-245A-4C8D-BE59-23A6C9DD54AA}

CyberDefender: Root class (Registry key, nothing done)
HKEY_LOCAL_MACHINE\Software\Classes\Cdaspm.OutlookAddin

CyberDefender: Root class (Registry key, nothing done)
HKEY_LOCAL_MACHINE\Software\Classes\Cdaspm.OutlookAddin.1

CyberDefender: Class ID (Registry key, nothing done)
HKEY_LOCAL_MACHINE\Software\Classes\CLSID\{8422A1B8-2896-40C2-B855-053864E43F1B}

CyberDefender: Class ID (Registry key, nothing done)
HKEY_CLASSES_ROOT\CLSID\{68F26CE7-2036-4610-84F4-73F3E72EFCA4}

CyberDefender: Interface (Registry key, nothing done)
HKEY_CLASSES_ROOT\Interface\{46A48490-13E9-40EC-AE07-3B4EBC41C9EA}

CyberDefender: Type library (Registry key, nothing done)
HKEY_CLASSES_ROOT\TypeLib\{F1CB3CED-0C9C-42C9-980B-66C7E96EF867}

CyberDefender: Root class (Registry key, nothing done)
HKEY_LOCAL_MACHINE\Software\Classes\Uwcdsolk.OutlookAddin

CyberDefender: Root class (Registry key, nothing done)
HKEY_LOCAL_MACHINE\Software\Classes\Uwcdsolk.OutlookAddin.1

CyberDefender: Class ID (Registry key, nothing done)
HKEY_LOCAL_MACHINE\Software\Classes\CLSID\{68F26CE7-2036-4610-84F4-73F3E72EFCA4}

CyberDefender: Class ID (Registry key, nothing done)
HKEY_CLASSES_ROOT\CLSID\{308193AC-E3A0-49D9-8649-7AE023F69067}

CyberDefender: Root class (Registry key, nothing done)
HKEY_LOCAL_MACHINE\Software\Classes\ISSHost.PhishExternalObject

CyberDefender: Root class (Registry key, nothing done)
HKEY_LOCAL_MACHINE\Software\Classes\ISSHost.PhishExternalObject.1

CyberDefender: Class ID (Registry key, nothing done)
HKEY_LOCAL_MACHINE\Software\Classes\CLSID\{308193AC-E3A0-49D9-8649-7AE023F69067}

CyberDefender: Class ID (Registry key, nothing done)
HKEY_CLASSES_ROOT\CLSID\{1DB58612-6520-4909-9086-DED483AE7794}

CyberDefender: Class ID (Registry key, nothing done)
HKEY_CLASSES_ROOT\CLSID\{F6DCBA17-D2E9-430E-8D6F-83198004F674}

End Part 1

CosmicSurfer
2007-03-29, 12:52
Report - Part 2
------------------------------

CyberDefender: Text file (File, nothing done)
c:\CDAVFSuser.log

CyberDefender: Text file (File, nothing done)
c:\CDAVFSuserBackup.log

CyberDefender: Text file (File, nothing done)
c:\CybDefInstallInfo.log

CyberDefender: Program directory (Directory, nothing done)
C:\Documents and Settings\Allan\Local Settings\Application Data\cdstbar\

CyberDefender: Text file (File, nothing done)
C:\Documents and Settings\Allan\Local Settings\Application Data\cdstbar\cdinstx.log

CyberDefender: Configuration file (File, nothing done)
C:\Documents and Settings\Allan\Local Settings\Application Data\cdstbar\ssstbar.ini

CyberDefender: Configuration file (File, nothing done)
C:\Documents and Settings\Allan\Local Settings\Application Data\cdstbar\sssTbarUpdateHost.ini

CyberDefender: Picture (File, nothing done)
C:\Documents and Settings\Allan\Local Settings\Application Data\cdstbar\st.ico

CyberDefender: Program directory (Directory, nothing done)
C:\Documents and Settings\Allan\Local Settings\Application Data\cdstbar\Ads Blocker\

CyberDefender: Program directory (Directory, nothing done)
C:\Documents and Settings\Allan\Local Settings\Application Data\cdstbar\Download\

CyberDefender: Program directory (Directory, nothing done)
C:\Documents and Settings\Allan\Local Settings\Application Data\cdstbar\Download\tmp\

CyberDefender: Program directory (Directory, nothing done)
C:\Documents and Settings\Allan\Local Settings\Application Data\cdstbar\Password Alert\

CyberDefender: Program directory (Directory, nothing done)
C:\Documents and Settings\Allan\Local Settings\Application Data\cdstbar\Patch Alert\

CyberDefender: Program directory (Directory, nothing done)
C:\Documents and Settings\Allan\Local Settings\Application Data\cdstbar\Scam Alert\

CyberDefender: Web page (File, nothing done)
C:\Documents and Settings\Allan\Local Settings\Application Data\cdstbar\Scam Alert\charset.html

CyberDefender: Web page (File, nothing done)
C:\Documents and Settings\Allan\Local Settings\Application Data\cdstbar\Scam Alert\cookie.html

CyberDefender: Web page (File, nothing done)
C:\Documents and Settings\Allan\Local Settings\Application Data\cdstbar\Scam Alert\defaultCharset.html

CyberDefender: Web page (File, nothing done)
C:\Documents and Settings\Allan\Local Settings\Application Data\cdstbar\Scam Alert\form.html

CyberDefender: Web page (File, nothing done)
C:\Documents and Settings\Allan\Local Settings\Application Data\cdstbar\Scam Alert\frame.html

CyberDefender: Web page (File, nothing done)
C:\Documents and Settings\Allan\Local Settings\Application Data\cdstbar\Scam Alert\gray.htm

CyberDefender: Web page (File, nothing done)
C:\Documents and Settings\Allan\Local Settings\Application Data\cdstbar\Scam Alert\green.htm

CyberDefender: Web page (File, nothing done)
C:\Documents and Settings\Allan\Local Settings\Application Data\cdstbar\Scam Alert\host.html

CyberDefender: Web page (File, nothing done)
C:\Documents and Settings\Allan\Local Settings\Application Data\cdstbar\Scam Alert\popup.html

CyberDefender: Web page (File, nothing done)
C:\Documents and Settings\Allan\Local Settings\Application Data\cdstbar\Scam Alert\port.html

CyberDefender: Web page (File, nothing done)
C:\Documents and Settings\Allan\Local Settings\Application Data\cdstbar\Scam Alert\protocol.html

CyberDefender: Web page (File, nothing done)
C:\Documents and Settings\Allan\Local Settings\Application Data\cdstbar\Scam Alert\red.htm

CyberDefender: Web page (File, nothing done)
C:\Documents and Settings\Allan\Local Settings\Application Data\cdstbar\Scam Alert\referrer.html

CyberDefender: Web page (File, nothing done)
C:\Documents and Settings\Allan\Local Settings\Application Data\cdstbar\Scam Alert\scamalert.htm

CyberDefender: Web page (File, nothing done)
C:\Documents and Settings\Allan\Local Settings\Application Data\cdstbar\Scam Alert\scamalert.htm1

CyberDefender: Web page (File, nothing done)
C:\Documents and Settings\Allan\Local Settings\Application Data\cdstbar\Scam Alert\script.html

CyberDefender: Web page (File, nothing done)
C:\Documents and Settings\Allan\Local Settings\Application Data\cdstbar\Scam Alert\security.html

CyberDefender: Data (File, nothing done)
C:\Documents and Settings\Allan\Local Settings\Application Data\cdstbar\Scam Alert\vssver.scc

CyberDefender: Web page (File, nothing done)
C:\Documents and Settings\Allan\Local Settings\Application Data\cdstbar\Scam Alert\yellow.htm

CyberDefender: Program directory (Directory, nothing done)
C:\Documents and Settings\Allan\Local Settings\Application Data\cdstbar\Scam Alert\images\

CyberDefender: Picture (File, nothing done)
C:\Documents and Settings\Allan\Local Settings\Application Data\cdstbar\Scam Alert\images\alertheader.gif

CyberDefender: Picture (File, nothing done)
C:\Documents and Settings\Allan\Local Settings\Application Data\cdstbar\Scam Alert\images\bt_actualsite.gif

CyberDefender: Picture (File, nothing done)
C:\Documents and Settings\Allan\Local Settings\Application Data\cdstbar\Scam Alert\images\bt_actualsite-over.gif

CyberDefender: Picture (File, nothing done)
C:\Documents and Settings\Allan\Local Settings\Application Data\cdstbar\Scam Alert\images\bt_closewindow.gif

CyberDefender: Picture (File, nothing done)
C:\Documents and Settings\Allan\Local Settings\Application Data\cdstbar\Scam Alert\images\bt_closewindow-over.gif

CyberDefender: Picture (File, nothing done)
C:\Documents and Settings\Allan\Local Settings\Application Data\cdstbar\Scam Alert\images\bt_fakesite.gif

CyberDefender: Picture (File, nothing done)
C:\Documents and Settings\Allan\Local Settings\Application Data\cdstbar\Scam Alert\images\bt_fakesite-over.gif

CyberDefender: Picture (File, nothing done)
C:\Documents and Settings\Allan\Local Settings\Application Data\cdstbar\Scam Alert\images\spacer.gif

CyberDefender: Picture (File, nothing done)
C:\Documents and Settings\Allan\Local Settings\Application Data\cdstbar\Scam Alert\images\vssver.scc

CyberDefender: Picture (File, nothing done)
C:\Documents and Settings\Allan\Local Settings\Application Data\cdstbar\Scam Alert\images\warning_bar.gif

CyberDefender: Program directory (Directory, nothing done)
C:\Documents and Settings\Allan\Local Settings\Application Data\cdstbar\Spyware Alert\

CyberDefender: Program directory (Directory, nothing done)
C:\Documents and Settings\Allan\Local Settings\Application Data\cdstbar\UserGuide\

CyberDefender: Program directory (Directory, nothing done)
C:\Documents and Settings\Allan\Local Settings\Application Data\cdstbar\Virus Alert\

CyberDefender: Program group (Directory, nothing done)
C:\Documents and Settings\Allan\Start Menu\Programs\CyberDefender\

CyberDefender: Configuration file (File, nothing done)
C:\WINDOWS\as_affiliate.ini

CyberDefender: Configuration file (File, nothing done)
C:\WINDOWS\av_affiliate.ini

CyberDefender: Configuration file (File, nothing done)
C:\WINDOWS\st_affiliate.ini

CyberDefender: File extension (Registry key, nothing done)
HKEY_CLASSES_ROOT\.hsl

CyberDefender: Root class (Registry key, nothing done)
HKEY_LOCAL_MACHINE\Software\Classes\HttpSvr.Logfile

CyberDefender: User settings (Registry key, nothing done)
HKEY_USERS\S-1-5-21-484763869-1682526488-854245398-1004\Software\CyberDefender

CyberDefender: User settings (Registry key, nothing done)
HKEY_USERS\S-1-5-21-484763869-1682526488-854245398-1004\Software\Microsoft\Office\Outlook\Addins\Uwcdsolk.OutlookAddin.1

CyberDefender: Settings (Registry key, nothing done)
HKEY_LOCAL_MACHINE\SOFTWARE\CybDefKeepSafe

CyberDefender: Settings (Registry key, nothing done)
HKEY_LOCAL_MACHINE\SOFTWARE\CyberDefender

CyberDefender: Settings (Registry key, nothing done)
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Office\Outlook\Addins\Cdaspm.OutlookAddin.1

CyberDefender: Uninstall settings (Registry key, nothing done)
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{83682B4C-B98C-4BEB-97CC-8EAD2AF9E4C6}

CyberDefender: Uninstall settings (Registry key, nothing done)
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{AA63780B-DDB7-417b-8A13-E5AFBE08E807}

CyberDefender: Uninstall settings (Registry key, nothing done)
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{AC5352DA-F4F2-4A59-A1BF-41546342746B}

CyberDefender: Settings (Registry value, nothing done)
HKEY_LOCAL_MACHINE\SOFTWARE\WsLiveUp\Install Information\Path

CyberDefender: Settings (Registry key, nothing done)
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\CDAVFS

CyberDefender: Settings (Registry key, nothing done)
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet003\Services\CDAVFS

CyberDefender: Root class (Registry key, nothing done)
HKEY_LOCAL_MACHINE\Software\Classes\CDWebVw.UpsellWizard

CyberDefender: Root class (Registry key, nothing done)
HKEY_LOCAL_MACHINE\Software\Classes\CDWebVw.UpsellWizard.1

CyberDefender: Class ID (Registry key, nothing done)
HKEY_LOCAL_MACHINE\Software\Classes\CLSID\{9585D7B6-C0E9-483C-986E-740C5DE01F97}

CyberDefender: Root class (Registry key, nothing done)
HKEY_LOCAL_MACHINE\Software\Classes\cdNetAdDll.WinExternal

CyberDefender: Root class (Registry key, nothing done)
HKEY_LOCAL_MACHINE\Software\Classes\cdNetAdDll.WinExternal.1

CyberDefender: Class ID (Registry key, nothing done)
HKEY_LOCAL_MACHINE\Software\Classes\CLSID\{C3D18B79-43CE-4A88-9019-1CF60E2DEDE9}

HitsLink: Tracking cookie (Opera 4+: Allan) (Cookie, nothing done)



--- Spybot - Search & Destroy version: 1.4 (build: 20050523) ---

2005-05-31 blindman.exe (1.0.0.1)
2005-05-31 SpybotSD.exe (1.4.0.3)
2005-05-31 TeaTimer.exe (1.4.0.2)
2005-05-31 TeaTimer_original.exe (1.4.0.2)
2006-12-07 unins000.exe (51.41.0.0)
2005-05-31 Update.exe (1.4.0.0)
2006-02-06 advcheck.dll (1.0.2.0)
2005-05-31 aports.dll (2.1.0.0)
2005-05-31 borlndmm.dll (7.0.4.453)
2005-05-31 delphimm.dll (7.0.4.453)
2005-05-31 SDHelper.dll (1.4.0.0)
2007-01-02 Tools.dll (2.0.1.0)
2005-05-31 UnzDll.dll (1.73.1.1)
2005-05-31 ZipDll.dll (1.73.2.0)
2007-03-28 Includes\Cookies.sbi (*)
2006-12-08 Includes\Dialer.sbi (*)
2007-03-28 Includes\DialerC.sbi (*)
2007-03-21 Includes\Hijackers.sbi (*)
2007-03-28 Includes\HijackersC.sbi (*)
2006-10-27 Includes\Keyloggers.sbi (*)
2007-03-28 Includes\KeyloggersC.sbi (*)
2004-11-29 Includes\LSP.sbi (*)
2007-03-21 Includes\Malware.sbi (*)
2007-03-28 Includes\MalwareC.sbi (*)
2007-03-21 Includes\PUPS.sbi (*)
2007-03-28 Includes\PUPSC.sbi (*)
2007-03-28 Includes\Revision.sbi (*)
2006-12-08 Includes\Security.sbi (*)
2007-03-28 Includes\SecurityC.sbi (*)
2007-03-21 Includes\Spybots.sbi (*)
2007-03-28 Includes\SpybotsC.sbi (*)
2005-02-17 Includes\Tracks.uti
2007-03-21 Includes\Trojans.sbi (*)
2007-03-28 Includes\TrojansC.sbi (*)