CallumS
2008-02-06, 18:09
http://forums.spybot.info/showthread.php?t=23129
In response to his reply:
Scan Statistics:
Total number of scanned objects: 73328
Number of viruses found: 35
Number of infected objects: 257
Number of suspicious objects: 4
Duration of the scan process: 00:44:42
is that all you want from the KR..becuase, again, it is 60K characters.
SUPERAntiSpyware Scan Log
http://www.superantispyware.com
Generated 02/06/2008 at 02:35 PM
Application Version : 3.9.1008
Core Rules Database Version : 3396
Trace Rules Database Version: 1388
Scan type : Complete Scan
Total Scan Time : 00:42:12
Memory items scanned : 329
Memory threats detected : 9
Registry items scanned : 6447
Registry threats detected : 144
File items scanned : 37876
File threats detected : 410
Trojan.Mezzia/Resident
C:\WINDOWS\SYSTEM32\WINMXW32.DLL
C:\WINDOWS\SYSTEM32\WINMXW32.DLL
Adware.Vundo Variant
C:\WINDOWS\SYSTEM32\JKKJIGF.DLL
C:\WINDOWS\SYSTEM32\JKKJIGF.DLL
HKLM\Software\Classes\CLSID\{A88BCC1E-E3E8-4DB0-9F11-A4B399977828}
HKCR\CLSID\{A88BCC1E-E3E8-4DB0-9F11-A4B399977828}
HKCR\CLSID\{A88BCC1E-E3E8-4DB0-9F11-A4B399977828}\InprocServer32
HKCR\CLSID\{A88BCC1E-E3E8-4DB0-9F11-A4B399977828}\InprocServer32#ThreadingModel
HKCR\CLSID\{A88BCC1E-E3E8-4DB0-9F11-A4B399977828}\TreatAs
C:\WINDOWS\SYSTEM32\PMNNN.DLL
HKLM\Software\Classes\CLSID\{A95B2816-1D7E-4561-A202-68C0DE02353A}
HKCR\CLSID\{A95B2816-1D7E-4561-A202-68C0DE02353A}
HKCR\CLSID\{A95B2816-1D7E-4561-A202-68C0DE02353A}\InprocServer32
HKCR\CLSID\{A95B2816-1D7E-4561-A202-68C0DE02353A}\InprocServer32#ThreadingModel
HKCR\CLSID\{A95B2816-1D7E-4561-A202-68C0DE02353A}\TreatAs
HKLM\Software\Classes\CLSID\{FC1B64D9-3499-4791-82D5-AABAC3FAEA45}
HKCR\CLSID\{FC1B64D9-3499-4791-82D5-AABAC3FAEA45}
HKCR\CLSID\{FC1B64D9-3499-4791-82D5-AABAC3FAEA45}\InprocServer32
HKCR\CLSID\{FC1B64D9-3499-4791-82D5-AABAC3FAEA45}\InprocServer32#ThreadingModel
HKCR\CLSID\{FC1B64D9-3499-4791-82D5-AABAC3FAEA45}\TreatAs
HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{A88BCC1E-E3E8-4DB0-9F11-A4B399977828}
HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{A95B2816-1D7E-4561-A202-68C0DE02353A}
HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{FC1B64D9-3499-4791-82D5-AABAC3FAEA45}
HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks#{FC1B64D9-3499-4791-82D5-AABAC3FAEA45}
Software\Microsoft\Windows NT\CurrentVersion\WinLogon\Notify\jkkjigf
HKCR\CLSID\{A95B2816-1D7E-4561-A202-68C0DE02353A}
HKCR\CLSID\{FC1B64D9-3499-4791-82D5-AABAC3FAEA45}
C:\WINDOWS\SYSTEM32\CBXVUST.DLL
C:\WINDOWS\SYSTEM32\DDCCAXV.DLL
C:\WINDOWS\SYSTEM32\EFCYXUT.DLL
C:\WINDOWS\SYSTEM32\FCCCDBA.DLL
C:\WINDOWS\SYSTEM32\FCCYXVW.DLL
C:\WINDOWS\SYSTEM32\TUVTTSS.DLL
Adware.Vundo-Variant/PolyMorph-A
C:\WINDOWS\SYSTEM32\SSQRSRO.DLL
C:\WINDOWS\SYSTEM32\SSQRSRO.DLL
Trojan.WinFixer
C:\WINDOWS\SYSTEM32\VTUTU.DLL
C:\WINDOWS\SYSTEM32\VTUTU.DLL
HKLM\Software\Classes\CLSID\{9DC97768-C9DD-4AE9-89A5-5019C1511611}
HKCR\CLSID\{9DC97768-C9DD-4AE9-89A5-5019C1511611}
HKCR\CLSID\{9DC97768-C9DD-4AE9-89A5-5019C1511611}\InprocServer32
HKCR\CLSID\{9DC97768-C9DD-4AE9-89A5-5019C1511611}\InprocServer32#ThreadingModel
HKCR\CLSID\{9DC97768-C9DD-4AE9-89A5-5019C1511611}\TreatAs
HKLM\Software\Classes\CLSID\{E261C9EF-D274-4C40-ACF6-DA92E4D7FE78}
HKCR\CLSID\{E261C9EF-D274-4C40-ACF6-DA92E4D7FE78}
HKCR\CLSID\{E261C9EF-D274-4C40-ACF6-DA92E4D7FE78}\InprocServer32
HKCR\CLSID\{E261C9EF-D274-4C40-ACF6-DA92E4D7FE78}\InprocServer32#ThreadingModel
HKCR\CLSID\{E261C9EF-D274-4C40-ACF6-DA92E4D7FE78}\TreatAs
C:\WINDOWS\SYSTEM32\DDCCB.DLL
HKLM\Software\Classes\CLSID\{F167032B-C01C-4105-B33C-34306B228CB4}
HKCR\CLSID\{F167032B-C01C-4105-B33C-34306B228CB4}
HKCR\CLSID\{F167032B-C01C-4105-B33C-34306B228CB4}\InprocServer32
HKCR\CLSID\{F167032B-C01C-4105-B33C-34306B228CB4}\InprocServer32#ThreadingModel
HKCR\CLSID\{F167032B-C01C-4105-B33C-34306B228CB4}\TreatAs
C:\WINDOWS\SYSTEM32\DDAYV.DLL
HKLM\Software\Classes\CLSID\{F602D1A1-1242-4A39-A972-F71B5F5A8686}
HKCR\CLSID\{F602D1A1-1242-4A39-A972-F71B5F5A8686}
HKCR\CLSID\{F602D1A1-1242-4A39-A972-F71B5F5A8686}\InprocServer32
HKCR\CLSID\{F602D1A1-1242-4A39-A972-F71B5F5A8686}\InprocServer32#ThreadingModel
HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{9DC97768-C9DD-4AE9-89A5-5019C1511611}
HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{E261C9EF-D274-4C40-ACF6-DA92E4D7FE78}
HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{F167032B-C01C-4105-B33C-34306B228CB4}
Trojan.Smitfraud Variant-Gen/PushrDrv
C:\WINDOWS\SYSTEM32\DRVXAK.DLL
C:\WINDOWS\SYSTEM32\DRVXAK.DLL
Adware.Vundo-Variant/Small-A
C:\WINDOWS\SYSTEM32\EJEMSWDK.DLL
C:\WINDOWS\SYSTEM32\EJEMSWDK.DLL
HKLM\Software\Classes\CLSID\{700f95e0-8dbc-487d-b75e-25e3e94b2181}
HKCR\CLSID\{700F95E0-8DBC-487D-B75E-25E3E94B2181}
HKCR\CLSID\{700F95E0-8DBC-487D-B75E-25E3E94B2181}\InprocServer32
HKCR\CLSID\{700F95E0-8DBC-487D-B75E-25E3E94B2181}\InprocServer32#ThreadingModel
HKCR\CLSID\{700F95E0-8DBC-487D-B75E-25E3E94B2181}\TreatAs
C:\WINDOWS\SYSTEM32\VGDKHGEP.DLL
HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{700f95e0-8dbc-487d-b75e-25e3e94b2181}
C:\WINDOWS\SYSTEM32\FHJYITTE.DLL
C:\WINDOWS\SYSTEM32\TIGGBHMM.DLL
Trojan.Net-AVP/AVT
C:\WINDOWS\SHELL.EXE
C:\WINDOWS\SHELL.EXE
C:\DOCUMENTS AND SETTINGS\ALL USERS\START MENU\PROGRAMS\STARTUP\AUTORUN.EXE
C:\WINDOWS\Prefetch\AUTORUN.EXE-3088AD1E.pf
Adware.ClickSpring/Outer Info Network
C:\PROGRAM FILES\OUTERINFO\OUTERINFOUPDATE.EXE
C:\PROGRAM FILES\OUTERINFO\OUTERINFOUPDATE.EXE
C:\PROGRAM FILES\OUTERINFO\OUTERINFO.EXE
C:\PROGRAM FILES\OUTERINFO\OUTERINFO.EXE
[OuterinfoUpdate] C:\PROGRAM FILES\OUTERINFO\OUTERINFOUPDATE.EXE
[Outerinfo] C:\PROGRAM FILES\OUTERINFO\OUTERINFO.EXE
HKLM\Software\Classes\CLSID\{2E9D4C81-9F27-4c14-B804-7B0F6BC88A4F}
HKCR\CLSID\{2E9D4C81-9F27-4C14-B804-7B0F6BC88A4F}
HKCR\CLSID\{2E9D4C81-9F27-4C14-B804-7B0F6BC88A4F}\InprocServer32
HKCR\CLSID\{2E9D4C81-9F27-4C14-B804-7B0F6BC88A4F}\InprocServer32#ThreadingModel
HKCR\CLSID\{2E9D4C81-9F27-4C14-B804-7B0F6BC88A4F}\Programmable
HKCR\CLSID\{2E9D4C81-9F27-4C14-B804-7B0F6BC88A4F}\TypeLib
C:\PROGRAM FILES\OUTERINFO\OUTERINFO.DLL
HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{2E9D4C81-9F27-4c14-B804-7B0F6BC88A4F}
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Outerinfo
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Outerinfo#Publisher
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Outerinfo#DisplayName
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Outerinfo#UninstallString
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Outerinfo#DisplayIcon
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Outerinfo#HelpLink
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Outerinfo#InstallLocation
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Outerinfo#NoModify
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Outerinfo#NoRepair
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Outerinfo#DisplayVersion
HKLM\Software\Outerinfo
HKLM\Software\Outerinfo#InstallDirectory
HKLM\Software\Outerinfo#REFID
HKLM\Software\Outerinfo#PID
C:\Program Files\Outerinfo\Cache
C:\Program Files\Outerinfo\FF\chrome.manifest
C:\Program Files\Outerinfo\FF\components\FF.dll
C:\Program Files\Outerinfo\FF\components\OuterinfoAds.xpt
C:\Program Files\Outerinfo\FF\components
C:\Program Files\Outerinfo\FF\install.rdf
C:\Program Files\Outerinfo\FF
C:\Program Files\Outerinfo\OinUninstall.exe
C:\Program Files\Outerinfo\OiUninstaller.exe
C:\Program Files\Outerinfo\outerinfo.ico
C:\Program Files\Outerinfo\Terms.rtf
C:\Program Files\Outerinfo
C:\Documents and Settings\user\Start Menu\Programs\Outerinfo\Terms.lnk
C:\Documents and Settings\user\Start Menu\Programs\Outerinfo\Uninstall.lnk
C:\Documents and Settings\user\Start Menu\Programs\Outerinfo
C:\SYSTEM VOLUME INFORMATION\_RESTORE{9E67248A-F152-4710-A4B8-745CD4FFE586}\RP124\A0064434.EXE
C:\SYSTEM VOLUME INFORMATION\_RESTORE{9E67248A-F152-4710-A4B8-745CD4FFE586}\RP133\A0073941.EXE
Trojan.Downloader-Gen/CinBroom
[Printer] C:\WINDOWS\SYSTEM32\PRINTER.EXE
C:\WINDOWS\SYSTEM32\PRINTER.EXE
C:\DOCUMENTS AND SETTINGS\USER\APPLICATION DATA\PRINTER.EXE
C:\WINDOWS\Prefetch\PRINTER.EXE-0E099EB1.pf
C:\WINDOWS\Prefetch\PRINTER.EXE-329CEBE6.pf
Worm.Rbot Variant
[Spoolsv] C:\WINDOWS\SYSTEM32\SPOOLVS.EXE
C:\WINDOWS\SYSTEM32\SPOOLVS.EXE
C:\WINDOWS\Prefetch\SPOOLVS.EXE-38E6A8DF.pf
Trojan.Vundo/Variant-Installer/A
[SpybotSD TeaTimer] C:\PROGRAM FILES\SPYBOT - SEARCH & DESTROY\TEATIMER.EXE
C:\PROGRAM FILES\SPYBOT - SEARCH & DESTROY\TEATIMER.EXE
C:\PROGRAM FILES\MESSENGER\MSMSGS.EXE
HKLM\Software\Microsoft\Windows\CurrentVersion\App Paths\MSMSGS.EXE
HKLM\Software\Microsoft\Windows\CurrentVersion\App Paths\MSMSGS.EXE#Path
C:\PROGRAM FILES\TOSHIBA\TOSCDSPD\TOSCDSPD.EXE
HKLM\Software\Microsoft\Windows\CurrentVersion\App Paths\TOSCDSPD.exe
HKLM\Software\Microsoft\Windows\CurrentVersion\App Paths\TOSCDSPD.exe#Path
C:\DOCUMENTS AND SETTINGS\ALL USERS\START MENU\PROGRAMS\WINDOWS MESSENGER.LNK
C:\DOCUMENTS AND SETTINGS\USER\LOCAL SETTINGS\TEMP\RCX1D8B.TMP
C:\SYSTEM VOLUME INFORMATION\_RESTORE{9E67248A-F152-4710-A4B8-745CD4FFE586}\RP131\A0067915.EXE
C:\WINDOWS\SYSTEM32\CTFMON.EXE.TMP
Trojan.Vundo/Variant-Installer
[load] C:\WINDOWS\SYSTEM32\VTUTU.EXE
C:\WINDOWS\SYSTEM32\VTUTU.EXE
[load] C:\WINDOWS\SYSTEM32\VTUTU.EXE
[load] C:\WINDOWS\SYSTEM32\VTUTU.EXE
C:\SYSTEM VOLUME INFORMATION\_RESTORE{9E67248A-F152-4710-A4B8-745CD4FFE586}\RP131\A0067910.EXE
C:\SYSTEM VOLUME INFORMATION\_RESTORE{9E67248A-F152-4710-A4B8-745CD4FFE586}\RP131\A0067911.EXE
C:\SYSTEM VOLUME INFORMATION\_RESTORE{9E67248A-F152-4710-A4B8-745CD4FFE586}\RP131\A0067912.EXE
C:\SYSTEM VOLUME INFORMATION\_RESTORE{9E67248A-F152-4710-A4B8-745CD4FFE586}\RP131\A0067913.EXE
C:\SYSTEM VOLUME INFORMATION\_RESTORE{9E67248A-F152-4710-A4B8-745CD4FFE586}\RP131\A0067914.EXE
C:\WINDOWS\SYSTEM32\DDCCB.EXE
Unclassified.Unknown Origin
HKLM\Software\Classes\CLSID\{11A69AE4-FBED-4832-A2BF-45AF82825583}
HKCR\CLSID\{11A69AE4-FBED-4832-A2BF-45AF82825583}
HKCR\CLSID\{11A69AE4-FBED-4832-A2BF-45AF82825583}
HKCR\CLSID\{11A69AE4-FBED-4832-A2BF-45AF82825583}\InprocServer32
HKCR\CLSID\{11A69AE4-FBED-4832-A2BF-45AF82825583}\InprocServer32#ThreadingModel
C:\WINDOWS\SYSTEM32\BUQKODCE.DLL
HKLM\Software\Classes\CLSID\{2F02D978-0FF6-80F7-60BB-0426224AB7B3}
HKCR\CLSID\{2F02D978-0FF6-80F7-60BB-0426224AB7B3}
HKCR\CLSID\{2F02D978-0FF6-80F7-60BB-0426224AB7B3}\InprocServer32
HKCR\CLSID\{2F02D978-0FF6-80F7-60BB-0426224AB7B3}\InprocServer32#ThreadingModel
HKCR\CLSID\{2F02D978-0FF6-80F7-60BB-0426224AB7B3}\InprocServer32#t
C:\PROGRAM FILES\WEOFXKWT\SKWEWFXO.DLL
HKLM\Software\Classes\CLSID\{B87D203B-B43D-4af9-9E1B-9C20478CBB74}
HKCR\CLSID\{B87D203B-B43D-4AF9-9E1B-9C20478CBB74}
HKCR\CLSID\{B87D203B-B43D-4AF9-9E1B-9C20478CBB74}
HKCR\CLSID\{B87D203B-B43D-4AF9-9E1B-9C20478CBB74}\InprocServer32
HKCR\CLSID\{B87D203B-B43D-4AF9-9E1B-9C20478CBB74}\InprocServer32#ThreadingModel
HKCR\CLSID\{B87D203B-B43D-4AF9-9E1B-9C20478CBB74}\ProgID
HKCR\CLSID\{B87D203B-B43D-4AF9-9E1B-9C20478CBB74}\TypeLib
TARDEME2.DLL
HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{2F02D978-0FF6-80F7-60BB-0426224AB7B3}
HKCR\CLSID\{2F02D978-0FF6-80F7-60BB-0426224AB7B3}
Adware.E404 Helper/Variant
HKLM\Software\Classes\CLSID\{F10587E9-0E47-4CBE-84AE-7DD20B8684CC}
HKCR\CLSID\{F10587E9-0E47-4CBE-84AE-7DD20B8684CC}
HKCR\CLSID\{F10587E9-0E47-4CBE-84AE-7DD20B8684CC}
HKCR\CLSID\{F10587E9-0E47-4CBE-84AE-7DD20B8684CC}\InprocServer32
HKCR\CLSID\{F10587E9-0E47-4CBE-84AE-7DD20B8684CC}\InprocServer32#ThreadingModel
HKCR\CLSID\{F10587E9-0E47-4CBE-84AE-7DD20B8684CC}\ProgID
HKCR\CLSID\{F10587E9-0E47-4CBE-84AE-7DD20B8684CC}\Programmable
HKCR\CLSID\{F10587E9-0E47-4CBE-84AE-7DD20B8684CC}\TypeLib
HKCR\CLSID\{F10587E9-0E47-4CBE-84AE-7DD20B8684CC}\VersionIndependentProgID
C:\PROGRAM FILES\HELPER\SUPERFINDOUT.DLL
HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{F10587E9-0E47-4CBE-84AE-7DD20B8684CC}
C:\SYSTEM VOLUME INFORMATION\_RESTORE{9E67248A-F152-4710-A4B8-745CD4FFE586}\RP123\A0062365.DLL
C:\SYSTEM VOLUME INFORMATION\_RESTORE{9E67248A-F152-4710-A4B8-745CD4FFE586}\RP124\A0063425.DLL
C:\SYSTEM VOLUME INFORMATION\_RESTORE{9E67248A-F152-4710-A4B8-745CD4FFE586}\RP126\A0066582.DLL
C:\SYSTEM VOLUME INFORMATION\_RESTORE{9E67248A-F152-4710-A4B8-745CD4FFE586}\RP127\A0066693.DLL
Trojan.Downloader-FatB
Software\Microsoft\Windows NT\CurrentVersion\WinLogon\Notify\winmxw32
Adware.Tracking Cookie
C:\Documents and Settings\user\Cookies\user@www.googleadservices[8].txt
C:\Documents and Settings\user\Cookies\user@server.iad.liveperson[2].txt
C:\Documents and Settings\user\Cookies\user@gomyhit[2].txt
C:\Documents and Settings\user\Cookies\user@imrworldwide[1].txt
C:\Documents and Settings\user\Cookies\user@serving-sys[2].txt
C:\Documents and Settings\user\Cookies\user@stat.dealtime[2].txt
C:\Documents and Settings\user\Cookies\user@www.googleadservices[3].txt
C:\Documents and Settings\user\Cookies\user@www.googleadservices[1].txt
C:\Documents and Settings\user\Cookies\user@advancedcleaner[1].txt
C:\Documents and Settings\user\Cookies\user@itxt.vibrantmedia[1].txt
C:\Documents and Settings\user\Cookies\user@adtech[1].txt
C:\Documents and Settings\user\Cookies\user@209.9.174[1].txt
C:\Documents and Settings\user\Cookies\user@ads.techguy[1].txt
C:\Documents and Settings\user\Cookies\user@server.iad.liveperson[3].txt
C:\Documents and Settings\user\Cookies\user@roiservice[1].txt
C:\Documents and Settings\user\Cookies\user@adtrackz[1].txt
C:\Documents and Settings\user\Cookies\user@revenue[2].txt
C:\Documents and Settings\user\Cookies\user@perf.overture[1].txt
C:\Documents and Settings\user\Cookies\user@www.googleadservices[6].txt
C:\Documents and Settings\user\Cookies\user@tribalfusion[2].txt
C:\Documents and Settings\user\Cookies\user@www.pcantiviruspro[1].txt
C:\Documents and Settings\user\Cookies\user@sale.spyguardpro[1].txt
C:\Documents and Settings\user\Cookies\user@findlaw[1].txt
C:\Documents and Settings\user\Cookies\user@208.122.40[3].txt
C:\Documents and Settings\user\Cookies\user@atdmt[1].txt
C:\Documents and Settings\user\Cookies\user@clicks.smartbizsearch[1].txt
C:\Documents and Settings\user\Cookies\user@overture[1].txt
C:\Documents and Settings\user\Cookies\user@findwhat[1].txt
C:\Documents and Settings\user\Cookies\user@dealtime[1].txt
C:\Documents and Settings\user\Cookies\user@spyguardpro[1].txt
C:\Documents and Settings\user\Cookies\user@malwarecrush[1].txt
C:\Documents and Settings\user\Cookies\user@scan.malwarecrush[2].txt
C:\Documents and Settings\user\Cookies\user@www.googleadservices[5].txt
C:\Documents and Settings\user\Cookies\user@findology[1].txt
C:\Documents and Settings\user\Cookies\user@scan.malwarecrush[1].txt
C:\Documents and Settings\user\Cookies\user@gomyhit[3].txt
C:\Documents and Settings\user\Cookies\user@tradedoubler[1].txt
C:\Documents and Settings\user\Cookies\user@bs.serving-sys[2].txt
C:\Documents and Settings\user\Cookies\user@thezirius[1].txt
C:\Documents and Settings\user\Cookies\user@ad.outerinfoads[2].txt
C:\Documents and Settings\user\Cookies\user@www.googleadservices[4].txt
C:\Documents and Settings\user\Cookies\user@doubleclick[1].txt
C:\Documents and Settings\user\Cookies\user@www.stopzilla[2].txt
C:\Documents and Settings\user\Cookies\user@shopping.112.2o7[1].txt
C:\Documents and Settings\user\Cookies\user@protect.spyguardpro[3].txt
C:\Documents and Settings\user\Cookies\user@adopt.euroclick[2].txt
C:\Documents and Settings\user\Cookies\user@bizadverts[2].txt
C:\Documents and Settings\user\Cookies\user@www.googleadservices[2].txt
C:\Documents and Settings\user\Cookies\user@protect.spyguardpro[1].txt
C:\Documents and Settings\user\Cookies\user@msnportal.112.2o7[1].txt
C:\Documents and Settings\user\Cookies\user@specificclick[1].txt
C:\Documents and Settings\user\Cookies\user@208.122.40[2].txt
C:\Documents and Settings\user\Cookies\user@www.googleadservices[7].txt
Trojan.Unknown Origin
HKLM\SOFTWARE\Microsoft\MSSMGR
HKLM\SOFTWARE\Microsoft\MSSMGR#Brnd
HKLM\SOFTWARE\Microsoft\MSSMGR#BSTV
HKLM\SOFTWARE\Microsoft\MSSMGR#SSTV
HKLM\SOFTWARE\Microsoft\MSSMGR#SCLIST
HKLM\SOFTWARE\Microsoft\MSSMGR#SSLIST
HKLM\SOFTWARE\Microsoft\MSSMGR#PSTV
HKLM\SOFTWARE\Microsoft\MSSMGR#Data
HKLM\SOFTWARE\Microsoft\MSSMGR#LSTV
HKLM\SOFTWARE\Microsoft\MSSMGR#MSLIST
HKLM\SOFTWARE\Microsoft\MSSMGR#BPTV
HKLM\SOFTWARE\Microsoft\MSSMGR#PID
HKLM\SOFTWARE\Microsoft\MSSMGR#Rid
Trojan.DNSChanger-Codec
HKCR\CLSID\E404.e404mgr
HKCR\CLSID\E404.e404mgr#UserId
Adware.E404 Helper/Hij
HKCR\E404.e404mgr
HKCR\E404.e404mgr\CLSID
HKCR\E404.e404mgr\CurVer
HKCR\E404.e404mgr.1
HKCR\E404.e404mgr.1\CLSID
HKCR\TypeLib\{E63648F7-3933-440E-B4F6-A8584DD7B7EB}
HKCR\TypeLib\{E63648F7-3933-440E-B4F6-A8584DD7B7EB}\1.0
HKCR\TypeLib\{E63648F7-3933-440E-B4F6-A8584DD7B7EB}\1.0\0
HKCR\TypeLib\{E63648F7-3933-440E-B4F6-A8584DD7B7EB}\1.0\0\win32
HKCR\TypeLib\{E63648F7-3933-440E-B4F6-A8584DD7B7EB}\1.0\FLAGS
HKCR\TypeLib\{E63648F7-3933-440E-B4F6-A8584DD7B7EB}\1.0\HELPDIR
HKCR\Interface\{F7D09218-46D7-4D3D-9B7F-315204CD0836}
HKCR\Interface\{F7D09218-46D7-4D3D-9B7F-315204CD0836}\ProxyStubClsid
HKCR\Interface\{F7D09218-46D7-4D3D-9B7F-315204CD0836}\ProxyStubClsid32
HKCR\Interface\{F7D09218-46D7-4D3D-9B7F-315204CD0836}\TypeLib
HKCR\Interface\{F7D09218-46D7-4D3D-9B7F-315204CD0836}\TypeLib#Version
Malware.LocusSoftware Inc/PCPrivacyTool
C:\Documents and Settings\user\Application Data\ultra\uninstall.bat
C:\Documents and Settings\user\Application Data\ultra
In response to his reply:
Scan Statistics:
Total number of scanned objects: 73328
Number of viruses found: 35
Number of infected objects: 257
Number of suspicious objects: 4
Duration of the scan process: 00:44:42
is that all you want from the KR..becuase, again, it is 60K characters.
SUPERAntiSpyware Scan Log
http://www.superantispyware.com
Generated 02/06/2008 at 02:35 PM
Application Version : 3.9.1008
Core Rules Database Version : 3396
Trace Rules Database Version: 1388
Scan type : Complete Scan
Total Scan Time : 00:42:12
Memory items scanned : 329
Memory threats detected : 9
Registry items scanned : 6447
Registry threats detected : 144
File items scanned : 37876
File threats detected : 410
Trojan.Mezzia/Resident
C:\WINDOWS\SYSTEM32\WINMXW32.DLL
C:\WINDOWS\SYSTEM32\WINMXW32.DLL
Adware.Vundo Variant
C:\WINDOWS\SYSTEM32\JKKJIGF.DLL
C:\WINDOWS\SYSTEM32\JKKJIGF.DLL
HKLM\Software\Classes\CLSID\{A88BCC1E-E3E8-4DB0-9F11-A4B399977828}
HKCR\CLSID\{A88BCC1E-E3E8-4DB0-9F11-A4B399977828}
HKCR\CLSID\{A88BCC1E-E3E8-4DB0-9F11-A4B399977828}\InprocServer32
HKCR\CLSID\{A88BCC1E-E3E8-4DB0-9F11-A4B399977828}\InprocServer32#ThreadingModel
HKCR\CLSID\{A88BCC1E-E3E8-4DB0-9F11-A4B399977828}\TreatAs
C:\WINDOWS\SYSTEM32\PMNNN.DLL
HKLM\Software\Classes\CLSID\{A95B2816-1D7E-4561-A202-68C0DE02353A}
HKCR\CLSID\{A95B2816-1D7E-4561-A202-68C0DE02353A}
HKCR\CLSID\{A95B2816-1D7E-4561-A202-68C0DE02353A}\InprocServer32
HKCR\CLSID\{A95B2816-1D7E-4561-A202-68C0DE02353A}\InprocServer32#ThreadingModel
HKCR\CLSID\{A95B2816-1D7E-4561-A202-68C0DE02353A}\TreatAs
HKLM\Software\Classes\CLSID\{FC1B64D9-3499-4791-82D5-AABAC3FAEA45}
HKCR\CLSID\{FC1B64D9-3499-4791-82D5-AABAC3FAEA45}
HKCR\CLSID\{FC1B64D9-3499-4791-82D5-AABAC3FAEA45}\InprocServer32
HKCR\CLSID\{FC1B64D9-3499-4791-82D5-AABAC3FAEA45}\InprocServer32#ThreadingModel
HKCR\CLSID\{FC1B64D9-3499-4791-82D5-AABAC3FAEA45}\TreatAs
HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{A88BCC1E-E3E8-4DB0-9F11-A4B399977828}
HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{A95B2816-1D7E-4561-A202-68C0DE02353A}
HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{FC1B64D9-3499-4791-82D5-AABAC3FAEA45}
HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks#{FC1B64D9-3499-4791-82D5-AABAC3FAEA45}
Software\Microsoft\Windows NT\CurrentVersion\WinLogon\Notify\jkkjigf
HKCR\CLSID\{A95B2816-1D7E-4561-A202-68C0DE02353A}
HKCR\CLSID\{FC1B64D9-3499-4791-82D5-AABAC3FAEA45}
C:\WINDOWS\SYSTEM32\CBXVUST.DLL
C:\WINDOWS\SYSTEM32\DDCCAXV.DLL
C:\WINDOWS\SYSTEM32\EFCYXUT.DLL
C:\WINDOWS\SYSTEM32\FCCCDBA.DLL
C:\WINDOWS\SYSTEM32\FCCYXVW.DLL
C:\WINDOWS\SYSTEM32\TUVTTSS.DLL
Adware.Vundo-Variant/PolyMorph-A
C:\WINDOWS\SYSTEM32\SSQRSRO.DLL
C:\WINDOWS\SYSTEM32\SSQRSRO.DLL
Trojan.WinFixer
C:\WINDOWS\SYSTEM32\VTUTU.DLL
C:\WINDOWS\SYSTEM32\VTUTU.DLL
HKLM\Software\Classes\CLSID\{9DC97768-C9DD-4AE9-89A5-5019C1511611}
HKCR\CLSID\{9DC97768-C9DD-4AE9-89A5-5019C1511611}
HKCR\CLSID\{9DC97768-C9DD-4AE9-89A5-5019C1511611}\InprocServer32
HKCR\CLSID\{9DC97768-C9DD-4AE9-89A5-5019C1511611}\InprocServer32#ThreadingModel
HKCR\CLSID\{9DC97768-C9DD-4AE9-89A5-5019C1511611}\TreatAs
HKLM\Software\Classes\CLSID\{E261C9EF-D274-4C40-ACF6-DA92E4D7FE78}
HKCR\CLSID\{E261C9EF-D274-4C40-ACF6-DA92E4D7FE78}
HKCR\CLSID\{E261C9EF-D274-4C40-ACF6-DA92E4D7FE78}\InprocServer32
HKCR\CLSID\{E261C9EF-D274-4C40-ACF6-DA92E4D7FE78}\InprocServer32#ThreadingModel
HKCR\CLSID\{E261C9EF-D274-4C40-ACF6-DA92E4D7FE78}\TreatAs
C:\WINDOWS\SYSTEM32\DDCCB.DLL
HKLM\Software\Classes\CLSID\{F167032B-C01C-4105-B33C-34306B228CB4}
HKCR\CLSID\{F167032B-C01C-4105-B33C-34306B228CB4}
HKCR\CLSID\{F167032B-C01C-4105-B33C-34306B228CB4}\InprocServer32
HKCR\CLSID\{F167032B-C01C-4105-B33C-34306B228CB4}\InprocServer32#ThreadingModel
HKCR\CLSID\{F167032B-C01C-4105-B33C-34306B228CB4}\TreatAs
C:\WINDOWS\SYSTEM32\DDAYV.DLL
HKLM\Software\Classes\CLSID\{F602D1A1-1242-4A39-A972-F71B5F5A8686}
HKCR\CLSID\{F602D1A1-1242-4A39-A972-F71B5F5A8686}
HKCR\CLSID\{F602D1A1-1242-4A39-A972-F71B5F5A8686}\InprocServer32
HKCR\CLSID\{F602D1A1-1242-4A39-A972-F71B5F5A8686}\InprocServer32#ThreadingModel
HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{9DC97768-C9DD-4AE9-89A5-5019C1511611}
HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{E261C9EF-D274-4C40-ACF6-DA92E4D7FE78}
HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{F167032B-C01C-4105-B33C-34306B228CB4}
Trojan.Smitfraud Variant-Gen/PushrDrv
C:\WINDOWS\SYSTEM32\DRVXAK.DLL
C:\WINDOWS\SYSTEM32\DRVXAK.DLL
Adware.Vundo-Variant/Small-A
C:\WINDOWS\SYSTEM32\EJEMSWDK.DLL
C:\WINDOWS\SYSTEM32\EJEMSWDK.DLL
HKLM\Software\Classes\CLSID\{700f95e0-8dbc-487d-b75e-25e3e94b2181}
HKCR\CLSID\{700F95E0-8DBC-487D-B75E-25E3E94B2181}
HKCR\CLSID\{700F95E0-8DBC-487D-B75E-25E3E94B2181}\InprocServer32
HKCR\CLSID\{700F95E0-8DBC-487D-B75E-25E3E94B2181}\InprocServer32#ThreadingModel
HKCR\CLSID\{700F95E0-8DBC-487D-B75E-25E3E94B2181}\TreatAs
C:\WINDOWS\SYSTEM32\VGDKHGEP.DLL
HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{700f95e0-8dbc-487d-b75e-25e3e94b2181}
C:\WINDOWS\SYSTEM32\FHJYITTE.DLL
C:\WINDOWS\SYSTEM32\TIGGBHMM.DLL
Trojan.Net-AVP/AVT
C:\WINDOWS\SHELL.EXE
C:\WINDOWS\SHELL.EXE
C:\DOCUMENTS AND SETTINGS\ALL USERS\START MENU\PROGRAMS\STARTUP\AUTORUN.EXE
C:\WINDOWS\Prefetch\AUTORUN.EXE-3088AD1E.pf
Adware.ClickSpring/Outer Info Network
C:\PROGRAM FILES\OUTERINFO\OUTERINFOUPDATE.EXE
C:\PROGRAM FILES\OUTERINFO\OUTERINFOUPDATE.EXE
C:\PROGRAM FILES\OUTERINFO\OUTERINFO.EXE
C:\PROGRAM FILES\OUTERINFO\OUTERINFO.EXE
[OuterinfoUpdate] C:\PROGRAM FILES\OUTERINFO\OUTERINFOUPDATE.EXE
[Outerinfo] C:\PROGRAM FILES\OUTERINFO\OUTERINFO.EXE
HKLM\Software\Classes\CLSID\{2E9D4C81-9F27-4c14-B804-7B0F6BC88A4F}
HKCR\CLSID\{2E9D4C81-9F27-4C14-B804-7B0F6BC88A4F}
HKCR\CLSID\{2E9D4C81-9F27-4C14-B804-7B0F6BC88A4F}\InprocServer32
HKCR\CLSID\{2E9D4C81-9F27-4C14-B804-7B0F6BC88A4F}\InprocServer32#ThreadingModel
HKCR\CLSID\{2E9D4C81-9F27-4C14-B804-7B0F6BC88A4F}\Programmable
HKCR\CLSID\{2E9D4C81-9F27-4C14-B804-7B0F6BC88A4F}\TypeLib
C:\PROGRAM FILES\OUTERINFO\OUTERINFO.DLL
HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{2E9D4C81-9F27-4c14-B804-7B0F6BC88A4F}
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Outerinfo
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Outerinfo#Publisher
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Outerinfo#DisplayName
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Outerinfo#UninstallString
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Outerinfo#DisplayIcon
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Outerinfo#HelpLink
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Outerinfo#InstallLocation
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Outerinfo#NoModify
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Outerinfo#NoRepair
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Outerinfo#DisplayVersion
HKLM\Software\Outerinfo
HKLM\Software\Outerinfo#InstallDirectory
HKLM\Software\Outerinfo#REFID
HKLM\Software\Outerinfo#PID
C:\Program Files\Outerinfo\Cache
C:\Program Files\Outerinfo\FF\chrome.manifest
C:\Program Files\Outerinfo\FF\components\FF.dll
C:\Program Files\Outerinfo\FF\components\OuterinfoAds.xpt
C:\Program Files\Outerinfo\FF\components
C:\Program Files\Outerinfo\FF\install.rdf
C:\Program Files\Outerinfo\FF
C:\Program Files\Outerinfo\OinUninstall.exe
C:\Program Files\Outerinfo\OiUninstaller.exe
C:\Program Files\Outerinfo\outerinfo.ico
C:\Program Files\Outerinfo\Terms.rtf
C:\Program Files\Outerinfo
C:\Documents and Settings\user\Start Menu\Programs\Outerinfo\Terms.lnk
C:\Documents and Settings\user\Start Menu\Programs\Outerinfo\Uninstall.lnk
C:\Documents and Settings\user\Start Menu\Programs\Outerinfo
C:\SYSTEM VOLUME INFORMATION\_RESTORE{9E67248A-F152-4710-A4B8-745CD4FFE586}\RP124\A0064434.EXE
C:\SYSTEM VOLUME INFORMATION\_RESTORE{9E67248A-F152-4710-A4B8-745CD4FFE586}\RP133\A0073941.EXE
Trojan.Downloader-Gen/CinBroom
[Printer] C:\WINDOWS\SYSTEM32\PRINTER.EXE
C:\WINDOWS\SYSTEM32\PRINTER.EXE
C:\DOCUMENTS AND SETTINGS\USER\APPLICATION DATA\PRINTER.EXE
C:\WINDOWS\Prefetch\PRINTER.EXE-0E099EB1.pf
C:\WINDOWS\Prefetch\PRINTER.EXE-329CEBE6.pf
Worm.Rbot Variant
[Spoolsv] C:\WINDOWS\SYSTEM32\SPOOLVS.EXE
C:\WINDOWS\SYSTEM32\SPOOLVS.EXE
C:\WINDOWS\Prefetch\SPOOLVS.EXE-38E6A8DF.pf
Trojan.Vundo/Variant-Installer/A
[SpybotSD TeaTimer] C:\PROGRAM FILES\SPYBOT - SEARCH & DESTROY\TEATIMER.EXE
C:\PROGRAM FILES\SPYBOT - SEARCH & DESTROY\TEATIMER.EXE
C:\PROGRAM FILES\MESSENGER\MSMSGS.EXE
HKLM\Software\Microsoft\Windows\CurrentVersion\App Paths\MSMSGS.EXE
HKLM\Software\Microsoft\Windows\CurrentVersion\App Paths\MSMSGS.EXE#Path
C:\PROGRAM FILES\TOSHIBA\TOSCDSPD\TOSCDSPD.EXE
HKLM\Software\Microsoft\Windows\CurrentVersion\App Paths\TOSCDSPD.exe
HKLM\Software\Microsoft\Windows\CurrentVersion\App Paths\TOSCDSPD.exe#Path
C:\DOCUMENTS AND SETTINGS\ALL USERS\START MENU\PROGRAMS\WINDOWS MESSENGER.LNK
C:\DOCUMENTS AND SETTINGS\USER\LOCAL SETTINGS\TEMP\RCX1D8B.TMP
C:\SYSTEM VOLUME INFORMATION\_RESTORE{9E67248A-F152-4710-A4B8-745CD4FFE586}\RP131\A0067915.EXE
C:\WINDOWS\SYSTEM32\CTFMON.EXE.TMP
Trojan.Vundo/Variant-Installer
[load] C:\WINDOWS\SYSTEM32\VTUTU.EXE
C:\WINDOWS\SYSTEM32\VTUTU.EXE
[load] C:\WINDOWS\SYSTEM32\VTUTU.EXE
[load] C:\WINDOWS\SYSTEM32\VTUTU.EXE
C:\SYSTEM VOLUME INFORMATION\_RESTORE{9E67248A-F152-4710-A4B8-745CD4FFE586}\RP131\A0067910.EXE
C:\SYSTEM VOLUME INFORMATION\_RESTORE{9E67248A-F152-4710-A4B8-745CD4FFE586}\RP131\A0067911.EXE
C:\SYSTEM VOLUME INFORMATION\_RESTORE{9E67248A-F152-4710-A4B8-745CD4FFE586}\RP131\A0067912.EXE
C:\SYSTEM VOLUME INFORMATION\_RESTORE{9E67248A-F152-4710-A4B8-745CD4FFE586}\RP131\A0067913.EXE
C:\SYSTEM VOLUME INFORMATION\_RESTORE{9E67248A-F152-4710-A4B8-745CD4FFE586}\RP131\A0067914.EXE
C:\WINDOWS\SYSTEM32\DDCCB.EXE
Unclassified.Unknown Origin
HKLM\Software\Classes\CLSID\{11A69AE4-FBED-4832-A2BF-45AF82825583}
HKCR\CLSID\{11A69AE4-FBED-4832-A2BF-45AF82825583}
HKCR\CLSID\{11A69AE4-FBED-4832-A2BF-45AF82825583}
HKCR\CLSID\{11A69AE4-FBED-4832-A2BF-45AF82825583}\InprocServer32
HKCR\CLSID\{11A69AE4-FBED-4832-A2BF-45AF82825583}\InprocServer32#ThreadingModel
C:\WINDOWS\SYSTEM32\BUQKODCE.DLL
HKLM\Software\Classes\CLSID\{2F02D978-0FF6-80F7-60BB-0426224AB7B3}
HKCR\CLSID\{2F02D978-0FF6-80F7-60BB-0426224AB7B3}
HKCR\CLSID\{2F02D978-0FF6-80F7-60BB-0426224AB7B3}\InprocServer32
HKCR\CLSID\{2F02D978-0FF6-80F7-60BB-0426224AB7B3}\InprocServer32#ThreadingModel
HKCR\CLSID\{2F02D978-0FF6-80F7-60BB-0426224AB7B3}\InprocServer32#t
C:\PROGRAM FILES\WEOFXKWT\SKWEWFXO.DLL
HKLM\Software\Classes\CLSID\{B87D203B-B43D-4af9-9E1B-9C20478CBB74}
HKCR\CLSID\{B87D203B-B43D-4AF9-9E1B-9C20478CBB74}
HKCR\CLSID\{B87D203B-B43D-4AF9-9E1B-9C20478CBB74}
HKCR\CLSID\{B87D203B-B43D-4AF9-9E1B-9C20478CBB74}\InprocServer32
HKCR\CLSID\{B87D203B-B43D-4AF9-9E1B-9C20478CBB74}\InprocServer32#ThreadingModel
HKCR\CLSID\{B87D203B-B43D-4AF9-9E1B-9C20478CBB74}\ProgID
HKCR\CLSID\{B87D203B-B43D-4AF9-9E1B-9C20478CBB74}\TypeLib
TARDEME2.DLL
HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{2F02D978-0FF6-80F7-60BB-0426224AB7B3}
HKCR\CLSID\{2F02D978-0FF6-80F7-60BB-0426224AB7B3}
Adware.E404 Helper/Variant
HKLM\Software\Classes\CLSID\{F10587E9-0E47-4CBE-84AE-7DD20B8684CC}
HKCR\CLSID\{F10587E9-0E47-4CBE-84AE-7DD20B8684CC}
HKCR\CLSID\{F10587E9-0E47-4CBE-84AE-7DD20B8684CC}
HKCR\CLSID\{F10587E9-0E47-4CBE-84AE-7DD20B8684CC}\InprocServer32
HKCR\CLSID\{F10587E9-0E47-4CBE-84AE-7DD20B8684CC}\InprocServer32#ThreadingModel
HKCR\CLSID\{F10587E9-0E47-4CBE-84AE-7DD20B8684CC}\ProgID
HKCR\CLSID\{F10587E9-0E47-4CBE-84AE-7DD20B8684CC}\Programmable
HKCR\CLSID\{F10587E9-0E47-4CBE-84AE-7DD20B8684CC}\TypeLib
HKCR\CLSID\{F10587E9-0E47-4CBE-84AE-7DD20B8684CC}\VersionIndependentProgID
C:\PROGRAM FILES\HELPER\SUPERFINDOUT.DLL
HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{F10587E9-0E47-4CBE-84AE-7DD20B8684CC}
C:\SYSTEM VOLUME INFORMATION\_RESTORE{9E67248A-F152-4710-A4B8-745CD4FFE586}\RP123\A0062365.DLL
C:\SYSTEM VOLUME INFORMATION\_RESTORE{9E67248A-F152-4710-A4B8-745CD4FFE586}\RP124\A0063425.DLL
C:\SYSTEM VOLUME INFORMATION\_RESTORE{9E67248A-F152-4710-A4B8-745CD4FFE586}\RP126\A0066582.DLL
C:\SYSTEM VOLUME INFORMATION\_RESTORE{9E67248A-F152-4710-A4B8-745CD4FFE586}\RP127\A0066693.DLL
Trojan.Downloader-FatB
Software\Microsoft\Windows NT\CurrentVersion\WinLogon\Notify\winmxw32
Adware.Tracking Cookie
C:\Documents and Settings\user\Cookies\user@www.googleadservices[8].txt
C:\Documents and Settings\user\Cookies\user@server.iad.liveperson[2].txt
C:\Documents and Settings\user\Cookies\user@gomyhit[2].txt
C:\Documents and Settings\user\Cookies\user@imrworldwide[1].txt
C:\Documents and Settings\user\Cookies\user@serving-sys[2].txt
C:\Documents and Settings\user\Cookies\user@stat.dealtime[2].txt
C:\Documents and Settings\user\Cookies\user@www.googleadservices[3].txt
C:\Documents and Settings\user\Cookies\user@www.googleadservices[1].txt
C:\Documents and Settings\user\Cookies\user@advancedcleaner[1].txt
C:\Documents and Settings\user\Cookies\user@itxt.vibrantmedia[1].txt
C:\Documents and Settings\user\Cookies\user@adtech[1].txt
C:\Documents and Settings\user\Cookies\user@209.9.174[1].txt
C:\Documents and Settings\user\Cookies\user@ads.techguy[1].txt
C:\Documents and Settings\user\Cookies\user@server.iad.liveperson[3].txt
C:\Documents and Settings\user\Cookies\user@roiservice[1].txt
C:\Documents and Settings\user\Cookies\user@adtrackz[1].txt
C:\Documents and Settings\user\Cookies\user@revenue[2].txt
C:\Documents and Settings\user\Cookies\user@perf.overture[1].txt
C:\Documents and Settings\user\Cookies\user@www.googleadservices[6].txt
C:\Documents and Settings\user\Cookies\user@tribalfusion[2].txt
C:\Documents and Settings\user\Cookies\user@www.pcantiviruspro[1].txt
C:\Documents and Settings\user\Cookies\user@sale.spyguardpro[1].txt
C:\Documents and Settings\user\Cookies\user@findlaw[1].txt
C:\Documents and Settings\user\Cookies\user@208.122.40[3].txt
C:\Documents and Settings\user\Cookies\user@atdmt[1].txt
C:\Documents and Settings\user\Cookies\user@clicks.smartbizsearch[1].txt
C:\Documents and Settings\user\Cookies\user@overture[1].txt
C:\Documents and Settings\user\Cookies\user@findwhat[1].txt
C:\Documents and Settings\user\Cookies\user@dealtime[1].txt
C:\Documents and Settings\user\Cookies\user@spyguardpro[1].txt
C:\Documents and Settings\user\Cookies\user@malwarecrush[1].txt
C:\Documents and Settings\user\Cookies\user@scan.malwarecrush[2].txt
C:\Documents and Settings\user\Cookies\user@www.googleadservices[5].txt
C:\Documents and Settings\user\Cookies\user@findology[1].txt
C:\Documents and Settings\user\Cookies\user@scan.malwarecrush[1].txt
C:\Documents and Settings\user\Cookies\user@gomyhit[3].txt
C:\Documents and Settings\user\Cookies\user@tradedoubler[1].txt
C:\Documents and Settings\user\Cookies\user@bs.serving-sys[2].txt
C:\Documents and Settings\user\Cookies\user@thezirius[1].txt
C:\Documents and Settings\user\Cookies\user@ad.outerinfoads[2].txt
C:\Documents and Settings\user\Cookies\user@www.googleadservices[4].txt
C:\Documents and Settings\user\Cookies\user@doubleclick[1].txt
C:\Documents and Settings\user\Cookies\user@www.stopzilla[2].txt
C:\Documents and Settings\user\Cookies\user@shopping.112.2o7[1].txt
C:\Documents and Settings\user\Cookies\user@protect.spyguardpro[3].txt
C:\Documents and Settings\user\Cookies\user@adopt.euroclick[2].txt
C:\Documents and Settings\user\Cookies\user@bizadverts[2].txt
C:\Documents and Settings\user\Cookies\user@www.googleadservices[2].txt
C:\Documents and Settings\user\Cookies\user@protect.spyguardpro[1].txt
C:\Documents and Settings\user\Cookies\user@msnportal.112.2o7[1].txt
C:\Documents and Settings\user\Cookies\user@specificclick[1].txt
C:\Documents and Settings\user\Cookies\user@208.122.40[2].txt
C:\Documents and Settings\user\Cookies\user@www.googleadservices[7].txt
Trojan.Unknown Origin
HKLM\SOFTWARE\Microsoft\MSSMGR
HKLM\SOFTWARE\Microsoft\MSSMGR#Brnd
HKLM\SOFTWARE\Microsoft\MSSMGR#BSTV
HKLM\SOFTWARE\Microsoft\MSSMGR#SSTV
HKLM\SOFTWARE\Microsoft\MSSMGR#SCLIST
HKLM\SOFTWARE\Microsoft\MSSMGR#SSLIST
HKLM\SOFTWARE\Microsoft\MSSMGR#PSTV
HKLM\SOFTWARE\Microsoft\MSSMGR#Data
HKLM\SOFTWARE\Microsoft\MSSMGR#LSTV
HKLM\SOFTWARE\Microsoft\MSSMGR#MSLIST
HKLM\SOFTWARE\Microsoft\MSSMGR#BPTV
HKLM\SOFTWARE\Microsoft\MSSMGR#PID
HKLM\SOFTWARE\Microsoft\MSSMGR#Rid
Trojan.DNSChanger-Codec
HKCR\CLSID\E404.e404mgr
HKCR\CLSID\E404.e404mgr#UserId
Adware.E404 Helper/Hij
HKCR\E404.e404mgr
HKCR\E404.e404mgr\CLSID
HKCR\E404.e404mgr\CurVer
HKCR\E404.e404mgr.1
HKCR\E404.e404mgr.1\CLSID
HKCR\TypeLib\{E63648F7-3933-440E-B4F6-A8584DD7B7EB}
HKCR\TypeLib\{E63648F7-3933-440E-B4F6-A8584DD7B7EB}\1.0
HKCR\TypeLib\{E63648F7-3933-440E-B4F6-A8584DD7B7EB}\1.0\0
HKCR\TypeLib\{E63648F7-3933-440E-B4F6-A8584DD7B7EB}\1.0\0\win32
HKCR\TypeLib\{E63648F7-3933-440E-B4F6-A8584DD7B7EB}\1.0\FLAGS
HKCR\TypeLib\{E63648F7-3933-440E-B4F6-A8584DD7B7EB}\1.0\HELPDIR
HKCR\Interface\{F7D09218-46D7-4D3D-9B7F-315204CD0836}
HKCR\Interface\{F7D09218-46D7-4D3D-9B7F-315204CD0836}\ProxyStubClsid
HKCR\Interface\{F7D09218-46D7-4D3D-9B7F-315204CD0836}\ProxyStubClsid32
HKCR\Interface\{F7D09218-46D7-4D3D-9B7F-315204CD0836}\TypeLib
HKCR\Interface\{F7D09218-46D7-4D3D-9B7F-315204CD0836}\TypeLib#Version
Malware.LocusSoftware Inc/PCPrivacyTool
C:\Documents and Settings\user\Application Data\ultra\uninstall.bat
C:\Documents and Settings\user\Application Data\ultra