SUPERAntiSpyware Scan Log
http://www.superantispyware.com

Generated 11/28/2008 at 03:49 PM

Application Version : 4.22.1014

Core Rules Database Version : 3654
Trace Rules Database Version: 1636

Scan type : Complete Scan
Total Scan Time : 00:44:38

Memory items scanned : 180
Memory threats detected : 3
Registry items scanned : 2131
Registry threats detected : 301
File items scanned : 31429
File threats detected : 226

Adware.DelFin Project
C:\WINDOWS\SYSTEM\NFOMON\NFOMON.EXE
C:\WINDOWS\SYSTEM\NFOMON\NFOMON.EXE
C:\WINDOWS\SYSTEM\VIDMON\VIDMON.EXE
C:\WINDOWS\SYSTEM\VIDMON\VIDMON.EXE
[Nfo] C:\WINDOWS\SYSTEM\NFOMON\NFOMON.EXE
[vidmon] C:\WINDOWS\SYSTEM\VIDMON\VIDMON.EXE
C:\PROGRAM FILES\COMMON FILES\UNINSTALL INFORMATION\REMOVEWEBDP.EXE

DateManager
C:\PROGRAM FILES\DATE MANAGER\DATEMANAGER.EXE
C:\PROGRAM FILES\DATE MANAGER\DATEMANAGER.EXE

Adware.HotBar (Low Risk)
[Hotbar] C:\PROGRAM FILES\HOTBAR\BIN\4.3.5.0\HBINST.EXE
C:\PROGRAM FILES\HOTBAR\BIN\4.3.5.0\HBINST.EXE
C:\WINDOWS\SYSTEM\HBINST.EXE
C:\PROGRAM FILES\HOTBAR\BIN\HBINST.EXE

Adware.MediaLoads
HKLM\Software\Classes\CLSID\{85A702BA-EA8F-4B83-AA07-07A5186ACD7E}
HKCR\CLSID\{85A702BA-EA8F-4B83-AA07-07A5186ACD7E}
HKCR\CLSID\{85A702BA-EA8F-4B83-AA07-07A5186ACD7E}
HKCR\CLSID\{85A702BA-EA8F-4B83-AA07-07A5186ACD7E}\ProgID
HKCR\CLSID\{85A702BA-EA8F-4B83-AA07-07A5186ACD7E}\VersionIndependentProgID
HKCR\CLSID\{85A702BA-EA8F-4B83-AA07-07A5186ACD7E}\Programmable
HKCR\CLSID\{85A702BA-EA8F-4B83-AA07-07A5186ACD7E}\InprocServer32
HKCR\CLSID\{85A702BA-EA8F-4B83-AA07-07A5186ACD7E}\InprocServer32#ThreadingModel
HKCR\CLSID\{85A702BA-EA8F-4B83-AA07-07A5186ACD7E}\TypeLib
HKCR\MP.MediaPops.1
HKCR\MP.MediaPops.1\CLSID
HKCR\MP.MediaPops
HKCR\MP.MediaPops\CLSID
HKCR\MP.MediaPops\CurVer
HKCR\TypeLib\{4767C447-EF15-42F2-8809-68ADB7FA76F1}
HKCR\TypeLib\{4767C447-EF15-42F2-8809-68ADB7FA76F1}\1.0
HKCR\TypeLib\{4767C447-EF15-42F2-8809-68ADB7FA76F1}\1.0\FLAGS
HKCR\TypeLib\{4767C447-EF15-42F2-8809-68ADB7FA76F1}\1.0\0
HKCR\TypeLib\{4767C447-EF15-42F2-8809-68ADB7FA76F1}\1.0\0\win32
HKCR\TypeLib\{4767C447-EF15-42F2-8809-68ADB7FA76F1}\1.0\HELPDIR
C:\PROGRAM FILES\MEDIALOADS ENHANCED\ME1.DLL
HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{85A702BA-EA8F-4B83-AA07-07A5186ACD7E}
HKCR\Interface\{4438A5DC-E00B-41A0-B0E6-B63FD3B86EEE}
HKCR\Interface\{4438A5DC-E00B-41A0-B0E6-B63FD3B86EEE}\ProxyStubClsid
HKCR\Interface\{4438A5DC-E00B-41A0-B0E6-B63FD3B86EEE}\ProxyStubClsid32
HKCR\Interface\{4438A5DC-E00B-41A0-B0E6-B63FD3B86EEE}\TypeLib
HKCR\Interface\{4438A5DC-E00B-41A0-B0E6-B63FD3B86EEE}\TypeLib#Version

Adware.Xupiter
HKLM\Software\Microsoft\Internet Explorer\Toolbar#{57E69D5A-6539-4d7d-9637-775DE8A385B4}
HKU\.DEFAULT\Software\Microsoft\Internet Explorer\URLSearchHooks#{6E6DD93E-1FC3-4F43-8AFB-1B7B90C9D3EB}

Trojan.Unclassified-Packed/Suspicious
HKLM\SOFTWARE\Microsoft\Code Store Database\Distribution Units\{DA9A0B1E-9B7B-11D3-B8A4-00C04F79641C}
HKCR\CLSID\{DA9A0B1E-9B7B-11D3-B8A4-00C04F79641C}
HKCR\CLSID\{DA9A0B1E-9B7B-11D3-B8A4-00C04F79641C}
HKCR\CLSID\{DA9A0B1E-9B7B-11D3-B8A4-00C04F79641C}\ProgID
HKCR\CLSID\{DA9A0B1E-9B7B-11D3-B8A4-00C04F79641C}\VersionIndependentProgID
HKCR\CLSID\{DA9A0B1E-9B7B-11D3-B8A4-00C04F79641C}\Programmable
HKCR\CLSID\{DA9A0B1E-9B7B-11D3-B8A4-00C04F79641C}\InprocServer32
HKCR\CLSID\{DA9A0B1E-9B7B-11D3-B8A4-00C04F79641C}\InprocServer32#ThreadingModel
HKCR\CLSID\{DA9A0B1E-9B7B-11D3-B8A4-00C04F79641C}\Control
HKCR\CLSID\{DA9A0B1E-9B7B-11D3-B8A4-00C04F79641C}\Insertable
HKCR\CLSID\{DA9A0B1E-9B7B-11D3-B8A4-00C04F79641C}\ToolboxBitmap32
HKCR\CLSID\{DA9A0B1E-9B7B-11D3-B8A4-00C04F79641C}\MiscStatus
HKCR\CLSID\{DA9A0B1E-9B7B-11D3-B8A4-00C04F79641C}\MiscStatus\1
HKCR\CLSID\{DA9A0B1E-9B7B-11D3-B8A4-00C04F79641C}\TypeLib
HKCR\CLSID\{DA9A0B1E-9B7B-11D3-B8A4-00C04F79641C}\Version
HKCR\NSUpdateLite.NSUpdateLiteCtrl.1
HKCR\NSUpdateLite.NSUpdateLiteCtrl.1\CLSID
HKCR\NSUpdateLite.NSUpdateLiteCtrl.1\Insertable
HKCR\NSUpdateLite.NSUpdateLiteCtrl
HKCR\NSUpdateLite.NSUpdateLiteCtrl\CLSID
HKCR\NSUpdateLite.NSUpdateLiteCtrl\CurVer
HKCR\TypeLib\{DA9A0B0F-9B7B-11D3-B8A4-00C04F79641C}
HKCR\TypeLib\{DA9A0B0F-9B7B-11D3-B8A4-00C04F79641C}\1.0
HKCR\TypeLib\{DA9A0B0F-9B7B-11D3-B8A4-00C04F79641C}\1.0\FLAGS
HKCR\TypeLib\{DA9A0B0F-9B7B-11D3-B8A4-00C04F79641C}\1.0\0
HKCR\TypeLib\{DA9A0B0F-9B7B-11D3-B8A4-00C04F79641C}\1.0\0\win32
HKCR\TypeLib\{DA9A0B0F-9B7B-11D3-B8A4-00C04F79641C}\1.0\HELPDIR
C:\WINDOWS\SYSTEM\NSUPDATE.DLL
HKCR\Interface\{DA9A0B1F-9B7B-11D3-B8A4-00C04F79641C}
HKCR\Interface\{DA9A0B1F-9B7B-11D3-B8A4-00C04F79641C}\ProxyStubClsid
HKCR\Interface\{DA9A0B1F-9B7B-11D3-B8A4-00C04F79641C}\ProxyStubClsid32
HKCR\Interface\{DA9A0B1F-9B7B-11D3-B8A4-00C04F79641C}\TypeLib
HKCR\Interface\{DA9A0B1F-9B7B-11D3-B8A4-00C04F79641C}\TypeLib#Version
HKCR\Interface\{DA9A0B1D-9B7B-11D3-B8A4-00C04F79641C}
HKCR\Interface\{DA9A0B1D-9B7B-11D3-B8A4-00C04F79641C}\ProxyStubClsid
HKCR\Interface\{DA9A0B1D-9B7B-11D3-B8A4-00C04F79641C}\ProxyStubClsid32
HKCR\Interface\{DA9A0B1D-9B7B-11D3-B8A4-00C04F79641C}\TypeLib
HKCR\Interface\{DA9A0B1D-9B7B-11D3-B8A4-00C04F79641C}\TypeLib#Version

Adware.Tracking Cookie
C:\WINDOWS\Cookies\default@videoegg.adbureau[2].txt
C:\WINDOWS\Cookies\default@specificclick[3].txt
C:\WINDOWS\Cookies\default@ehg-proflowers.hitbox[2].txt
C:\WINDOWS\Cookies\default@ads.apn.co[2].txt
C:\WINDOWS\Cookies\default@ad[1].txt
C:\WINDOWS\Cookies\default@media.mtvnservices[2].txt
C:\WINDOWS\Cookies\default@perf.overture[3].txt
C:\WINDOWS\Cookies\default@www.windowsmedia[1].txt
C:\WINDOWS\Cookies\default@dcsew60m1oifwznbkznc6j9ix_5x7j[1].txt
C:\WINDOWS\Cookies\default@realmedia[1].txt
C:\WINDOWS\Cookies\default@atwola[2].txt
C:\WINDOWS\Cookies\default@xxxtoolbar[2].txt
C:\WINDOWS\Cookies\default@myaccount.centrelink.gov[1].txt
C:\WINDOWS\Cookies\default@0[2].txt
C:\WINDOWS\Cookies\default@www.teenagehumor[2].txt
C:\WINDOWS\Cookies\default@dealtime[1].txt
C:\WINDOWS\Cookies\default@crackle[1].txt
C:\WINDOWS\Cookies\default@bs.serving-sys[1].txt
C:\WINDOWS\Cookies\default@tracker.mediatracker.co[1].txt
C:\WINDOWS\Cookies\default@cassava[1].txt
C:\WINDOWS\Cookies\default@ads.adsag[1].txt
C:\WINDOWS\Cookies\default@qksrv[1].txt
C:\WINDOWS\Cookies\default@2[2].txt
C:\WINDOWS\Cookies\default@276[2].txt
C:\WINDOWS\Cookies\default@a.as-us.falkag[2].txt
C:\WINDOWS\Cookies\default@linksynergy[1].txt
C:\WINDOWS\Cookies\default@socialmedia[1].txt
C:\WINDOWS\Cookies\default@script[2].txt
C:\WINDOWS\Cookies\default@ehg-bskyb.hitbox[2].txt
C:\WINDOWS\Cookies\default@1070207279[1].txt
C:\WINDOWS\Cookies\default@zedo[3].txt
C:\WINDOWS\Cookies\default@ads.pointroll[1].txt
C:\WINDOWS\Cookies\default@6[1].txt
C:\WINDOWS\Cookies\default@valueclick[1].txt
C:\WINDOWS\Cookies\default@0[3].txt
C:\WINDOWS\Cookies\default@ehg-electricbusiness.hitbox[1].txt
C:\WINDOWS\Cookies\default@www.popuptraffic[2].txt
C:\WINDOWS\Cookies\default@www.ezytrack[1].txt
C:\WINDOWS\Cookies\default@tribalfusion[2].txt
C:\WINDOWS\Cookies\default@mediaplex[3].txt
C:\WINDOWS\Cookies\default@2o7[3].txt
C:\WINDOWS\Cookies\default@tracking.thunderdownloads[2].txt
C:\WINDOWS\Cookies\default@incentaclick[2].txt
C:\WINDOWS\Cookies\default@cz6.clickzs[1].txt
C:\WINDOWS\Cookies\default@www.trafficbeamer[2].txt
C:\WINDOWS\Cookies\default@websponsors[2].txt
C:\WINDOWS\Cookies\default@atdmt[1].txt
C:\WINDOWS\Cookies\default@as-us.falkag[2].txt
C:\WINDOWS\Cookies\default@clickbank[1].txt
C:\WINDOWS\Cookies\default@statcounter[4].txt
C:\WINDOWS\Cookies\default@maxserving[1].txt
C:\WINDOWS\Cookies\default@ads.x10[1].txt
C:\WINDOWS\Cookies\default@serving-sys[4].txt
C:\WINDOWS\Cookies\default@353[1].txt
C:\WINDOWS\Cookies\default@ehg-attenza.hitbox[2].txt
C:\WINDOWS\Cookies\default@as1.falkag[2].txt
C:\WINDOWS\Cookies\default@e-2dj6wflokhcjilo.stats.esomniture[2].txt
C:\WINDOWS\Cookies\default@www.burstnet[1].txt
C:\WINDOWS\Cookies\default@stat.dealtime[2].txt
C:\WINDOWS\Cookies\default@revsci[3].txt
C:\WINDOWS\Cookies\default@ad.yieldmanager[4].txt
C:\WINDOWS\Cookies\default@media.sensis.com[2].txt
C:\WINDOWS\Cookies\default@5[2].txt
C:\WINDOWS\Cookies\default@overture[4].txt
C:\WINDOWS\Cookies\default@azjmp[1].txt
C:\WINDOWS\Cookies\default@bluestreak[2].txt
C:\WINDOWS\Cookies\default@ehg-dig.hitbox[2].txt
C:\WINDOWS\Cookies\default@insightfirst[2].txt
C:\WINDOWS\Cookies\default@fastclick[1].txt
C:\WINDOWS\Cookies\default@windowsmedia[1].txt
C:\WINDOWS\Cookies\default@tracking[2].txt
C:\WINDOWS\Cookies\default@344[1].txt
C:\WINDOWS\Cookies\default@semdirector.112.2o7[1].txt
C:\WINDOWS\Cookies\default@burstnet[2].txt
C:\WINDOWS\Cookies\default@ad.sensismediasmart.com[2].txt
C:\WINDOWS\Cookies\default@casalemedia[2].txt
C:\WINDOWS\Cookies\default@adserver.adtechus[1].txt
C:\WINDOWS\Cookies\default@pacificpoker[3].txt
C:\WINDOWS\Cookies\default@msnaccountservices.112.2o7[1].txt
C:\WINDOWS\Cookies\default@etype.adbureau[1].txt
C:\WINDOWS\Cookies\default@adopt.euroclick[1].txt
C:\WINDOWS\Cookies\default@www.realcastmedia[1].txt
C:\WINDOWS\Cookies\default@3684752[2].txt
C:\WINDOWS\Cookies\default@adserver.news.com[2].txt
C:\WINDOWS\Cookies\default@adserver.easyad[1].txt
C:\WINDOWS\Cookies\default@statse.webtrendslive[3].txt
C:\WINDOWS\Cookies\default@new-pcp[1].txt
C:\WINDOWS\Cookies\default@optus.112.2o7[1].txt
C:\WINDOWS\Cookies\default@z1.adserver[1].txt
C:\WINDOWS\Cookies\default@counter.123counts[1].txt
C:\WINDOWS\Cookies\default@ads.addynamix[1].txt
C:\WINDOWS\Cookies\default@hc2.humanclick[1].txt
C:\WINDOWS\Cookies\default@ad2.pamedia.com[1].txt
C:\WINDOWS\Cookies\default@trafficvenuedirect[2].txt
C:\WINDOWS\Cookies\default@apnonline.112.2o7[1].txt
C:\WINDOWS\Cookies\default@account.live[3].txt
C:\WINDOWS\Cookies\default@trafficmp[1].txt
C:\WINDOWS\Cookies\default@cgi-bin[2].txt
C:\WINDOWS\Cookies\default@adinterax[1].txt
C:\WINDOWS\Cookies\default@track.adform[2].txt
C:\WINDOWS\Cookies\default@cz3.clickzs[2].txt
C:\WINDOWS\Cookies\default@87506651[1].txt
C:\WINDOWS\Cookies\default@888[1].txt
C:\WINDOWS\Cookies\default@cgi-bin[1].txt
C:\WINDOWS\Cookies\default@spylog[2].txt
C:\WINDOWS\Cookies\default@commission-junction[1].txt
C:\WINDOWS\Cookies\default@cz8.clickzs[1].txt
C:\WINDOWS\Cookies\default@advertising[3].txt
C:\WINDOWS\Cookies\default@counter.hitslink[1].txt
C:\WINDOWS\Cookies\default@revenue[2].txt
C:\WINDOWS\Cookies\default@msnportal.112.2o7[4].txt
C:\WINDOWS\Cookies\default@doubleclick[1].txt
C:\WINDOWS\Cookies\default@hg1.hitbox[2].txt
C:\WINDOWS\Cookies\default@mywebsearch[1].txt
C:\WINDOWS\Cookies\default@ad.trackbar[2].txt
C:\WINDOWS\Cookies\default@hitbox[1].txt
C:\WINDOWS\Cookies\default@belnk[1].txt
C:\WINDOWS\Cookies\default@56081914[2].txt
C:\WINDOWS\Cookies\default@ad[2].txt
C:\WINDOWS\Cookies\default@7[2].txt
C:\WINDOWS\Cookies\default@rocku.adbureau[2].txt
C:\WINDOWS\Cookies\default@tradedoubler[1].txt
C:\WINDOWS\Cookies\default@ssm.directtrack[2].txt
C:\WINDOWS\Cookies\default@1057891207[1].txt
C:\WINDOWS\Cookies\default@tracking.foxnews[2].txt
C:\WINDOWS\Cookies\default@mediaonenetwork[2].txt
C:\WINDOWS\Cookies\default@ehg-groupernetworks.hitbox[1].txt
C:\WINDOWS\Cookies\default@adbrite[3].txt
C:\WINDOWS\Cookies\default@ads.contactmusic[2].txt
C:\WINDOWS\Cookies\default@ehg-nokiafin.hitbox[2].txt
C:\WINDOWS\Cookies\default@scan.antivirus2008scanner[1].txt
C:\WINDOWS\Cookies\default@server.cpmstar[2].txt
C:\WINDOWS\Cookies\default@www.incentaclick[2].txt
C:\WINDOWS\Cookies\default@adtech[1].txt
C:\WINDOWS\Cookies\default@edge.ru4[1].txt
C:\WINDOWS\Cookies\default@1054571031[1].txt
C:\WINDOWS\Cookies\default@insightexpressai[1].txt
C:\WINDOWS\Cookies\default@ad.lookery[1].txt
C:\WINDOWS\Cookies\default@microsoftwlmessengermkt.112.2o7[1].txt
C:\WINDOWS\Cookies\default@tacoda[2].txt
C:\WINDOWS\Cookies\default@mansion.122.2o7[1].txt
C:\WINDOWS\Cookies\default@1070847646[1].txt
C:\WINDOWS\Cookies\default@ads.cnn[2].txt
C:\WINDOWS\Cookies\default@directtrack[1].txt
C:\WINDOWS\Cookies\default@questionmarket[2].txt
C:\WINDOWS\Cookies\default@network.alluremedia.com[2].txt
C:\WINDOWS\Cookies\default@ats[1].txt
C:\WINDOWS\Cookies\default@media6degrees[1].txt
C:\WINDOWS\Cookies\default@kontera[3].txt
C:\WINDOWS\Cookies\default@ad.zanox[3].txt
c:\WINDOWS\Cookies\default@doubleclick[2].txt
c:\WINDOWS\Cookies\default@mediaplex[1].txt
c:\WINDOWS\Cookies\default@overture[1].txt
c:\WINDOWS\Cookies\default@ad.zanox[2].txt
c:\WINDOWS\Cookies\default@advertising[2].txt
c:\WINDOWS\Cookies\default@tribalfusion[1].txt
c:\WINDOWS\Cookies\default@zedo[1].txt
c:\WINDOWS\Cookies\default@webpdp.gator[1].txt
c:\WINDOWS\Cookies\default@webpdp.gator[3].txt
c:\WINDOWS\Cookies\default@webpdp.gator[4].txt
c:\WINDOWS\Cookies\default@free.pornstarunion[1].txt
c:\WINDOWS\Cookies\default@media[6].txt
c:\WINDOWS\Cookies\default@free.pornstarunion[2].txt
c:\WINDOWS\Cookies\default@trafficmp[4].txt
c:\WINDOWS\Cookies\default@questionmarket[1].txt
c:\WINDOWS\Cookies\default@edge.ru4[2].txt
c:\WINDOWS\Cookies\default@hypertracker[2].txt
c:\WINDOWS\Cookies\default@www.theteenstar[1].txt
c:\WINDOWS\Cookies\default@hotlog[1].txt
c:\WINDOWS\Cookies\default@hitbox[2].txt
c:\WINDOWS\Cookies\default@ads.specificpop[1].txt
c:\WINDOWS\Cookies\default@counter13.sextracker[1].txt
c:\WINDOWS\Cookies\default@webpdp.gator[2].txt
c:\WINDOWS\Cookies\default@webpdp.gator[5].txt
c:\WINDOWS\Cookies\default@doubleclick[3].txt
c:\WINDOWS\Cookies\default@overture[3].txt
c:\WINDOWS\Cookies\default@perf.overture[1].txt
c:\WINDOWS\Cookies\default@msnportal.112.2o7[1].txt
c:\WINDOWS\Cookies\default@adinterax[2].txt
c:\WINDOWS\Cookies\default@fastclick[2].txt
c:\WINDOWS\Cookies\default@adopt.euroclick[2].txt
c:\WINDOWS\Cookies\default@casalemedia[1].txt
c:\WINDOWS\Cookies\default@2o7[2].txt
c:\WINDOWS\Cookies\default@accounts[1].txt
c:\WINDOWS\Cookies\default@msnportal.112.2o7[3].txt
c:\WINDOWS\Cookies\default@serving-sys[2].txt
c:\WINDOWS\Cookies\default@specificclick[2].txt
c:\WINDOWS\Cookies\default@ad.yieldmanager[1].txt
c:\WINDOWS\Cookies\default@statcounter[1].txt
c:\WINDOWS\Cookies\default@mediaonenetwork[1].txt
c:\WINDOWS\Cookies\default@ads.addynamix[2].txt
c:\WINDOWS\Cookies\default@richmedia.yahoo[1].txt
c:\WINDOWS\Cookies\default@account.live[2].txt
c:\WINDOWS\Cookies\default@pacificpoker[1].txt
c:\WINDOWS\Cookies\default@bs.serving-sys[2].txt
c:\WINDOWS\Cookies\default@fastclick[3].txt
c:\WINDOWS\Cookies\default@adserver[1].txt
c:\WINDOWS\Cookies\default@serving-sys[3].txt
c:\WINDOWS\Cookies\default@statse.webtrendslive[2].txt
c:\WINDOWS\Cookies\default@adbrite[2].txt
c:\WINDOWS\Cookies\default@revsci[1].txt
c:\WINDOWS\Cookies\default@ad.yieldmanager[3].txt
c:\WINDOWS\Cookies\default@adopt.euroclick[3].txt
c:\WINDOWS\Cookies\default@2o7[1].txt
c:\WINDOWS\Cookies\default@mediaplex[2].txt
c:\WINDOWS\Cookies\default@socialmedia[2].txt
c:\WINDOWS\Cookies\default@statcounter[2].txt
c:\WINDOWS\Cookies\default@mediaonenetwork[3].txt
c:\WINDOWS\Cookies\default@tribalfusion[3].txt
c:\WINDOWS\Cookies\default@kontera[2].txt
c:\WINDOWS\Cookies\default@bs.serving-sys[3].txt

CommonName Toolbar/Browser Helper Object
HKCR\CLSID\{00000000-0000-0000-0000-000000000000}
HKCR\CLSID\{00000000-0000-0000-0000-000000000000}\InprocServer32
HKCR\CLSID\{00000000-0000-0000-0000-000000000000}\ProgID

Adware.WhenU
HKCR\WUSN.1
HKCR\WUSN.1#WUSN_Id

Adware.Cydoor
HKU\.DEFAULT\Software\Cydoor
HKLM\Software\Cydoor
HKLM\Software\Cydoor#AdwrCnt

Adware.GAIN/Gator
HKLM\Software\Gator.com
HKLM\Software\Gator.com\AppInfo
HKLM\Software\Gator.com\AppInfo\DateManager
HKLM\Software\Gator.com\AppInfo\DateManager#event
HKLM\Software\Gator.com\AppInfo\DateManager#timeout_secs_ui
HKLM\Software\Gator.com\AppInfo\DateManager#timeout_secs_full
HKLM\Software\Gator.com\AppInfo\DateManager#lockfiles
HKLM\Software\Gator.com\AppInfo\DateManager#restart
HKLM\Software\Gator.com\Date Manager
HKLM\Software\Gator.com\Date Manager#AppPath
HKLM\Software\Gator.com\Date Manager#LastAutoupdateCall
HKLM\Software\Gator.com\CMEII
HKLM\Software\Gator.com\CMEII#AppHist
HKLM\Software\Gator.com\CMEII#numInst
HKLM\Software\Gator.com\Gator
HKLM\Software\Gator.com\Gator\dyn
HKLM\Software\Gator.com\Gator\dyn\GCH
HKLM\Software\Gator.com\Gator\dyn\GCH\_gs
HKLM\Software\Gator.com\Gator\dyn\GCH\_gs#StartTime
HKLM\Software\Gator.com\Gator\dyn\GCH\_gs#OldestTime
HKLM\Software\Gator.com\Gator\dyn\GCH\_gs#302-12029
HKLM\Software\Gator.com\Gator\dyn\GCH\_gs#302-bytes
HKLM\Software\Gator.com\Gator\dyn\GCH\_gs#302--1
HKLM\Software\Gator.com\Gator\dyn\GCH\_gs#303-12029
HKLM\Software\Gator.com\Gator\dyn\GCH\_gs#303-bytes
HKLM\Software\Gator.com\Gator\dyn\GCH\_gs#303--1
HKLM\Software\Gator.com\Gator\dyn\GCH\_gs#304-12029
HKLM\Software\Gator.com\Gator\dyn\GCH\_gs#304-bytes
HKLM\Software\Gator.com\Gator\dyn\GCH\_gs#304--1
HKLM\Software\Gator.com\Gator\dyn\GCH\_gs#305-12029
HKLM\Software\Gator.com\Gator\dyn\GCH\_gs#305-bytes
HKLM\Software\Gator.com\Gator\dyn\GCH\_gs#305--1
HKLM\Software\Gator.com\Gator\dyn\GCH\_gs#306-12029
HKLM\Software\Gator.com\Gator\dyn\GCH\_gs#306-bytes
HKLM\Software\Gator.com\Gator\dyn\GCH\_gs#306--1
HKLM\Software\Gator.com\Gator\dyn\GCH\_gs#307-12029
HKLM\Software\Gator.com\Gator\dyn\GCH\_gs#307-bytes
HKLM\Software\Gator.com\Gator\dyn\GCH\_gs#311-12029
HKLM\Software\Gator.com\Gator\dyn\GCH\_gs#311-bytes
HKLM\Software\Gator.com\Gator\dyn\GCH\_gs#312-12029
HKLM\Software\Gator.com\Gator\dyn\GCH\_gs#312-bytes
HKLM\Software\Gator.com\Gator\dyn\GCH\_gs#313-12029
HKLM\Software\Gator.com\Gator\dyn\GCH\_gs#313-bytes
HKLM\Software\Gator.com\Gator\dyn\GCH\_gs#314-12029
HKLM\Software\Gator.com\Gator\dyn\GCH\_gs#314-bytes
HKLM\Software\Gator.com\Gator\dyn\GCH\_gs#314--1
HKLM\Software\Gator.com\Gator\dyn\GCH\_gs#315-12029
HKLM\Software\Gator.com\Gator\dyn\GCH\_gs#315-bytes
HKLM\Software\Gator.com\Gator\dyn\GCH\_gs#315--1
HKLM\Software\Gator.com\Gator\dyn\GCH\_gs#316-12029
HKLM\Software\Gator.com\Gator\dyn\GCH\_gs#316-bytes
HKLM\Software\Gator.com\Gator\dyn\GCH\_gs#316--1
HKLM\Software\Gator.com\Gator\dyn\GCH\_gs#321-12029
HKLM\Software\Gator.com\Gator\dyn\GCH\_gs#321-bytes
HKLM\Software\Gator.com\Gator\dyn\GCH\_gs#321--1
HKLM\Software\Gator.com\Gator\dyn\GCH\_gs#322--1
HKLM\Software\Gator.com\Gator\dyn\GCH\_gs#322-bytes
HKLM\Software\Gator.com\Gator\dyn\GCH\_gs#322-12029
HKLM\Software\Gator.com\Gator\dyn\GCH\_gs#323-12029
HKLM\Software\Gator.com\Gator\dyn\GCH\_gs#323-bytes
HKLM\Software\Gator.com\Gator\dyn\GCH\_gs#323--1
HKLM\Software\Gator.com\Gator\dyn\GCH\_gs#324-12029
HKLM\Software\Gator.com\Gator\dyn\GCH\_gs#324-bytes
HKLM\Software\Gator.com\Gator\dyn\GCH\_gs#324--1
HKLM\Software\Gator.com\Gator\dyn\GCH\_gs#326-12029
HKLM\Software\Gator.com\Gator\dyn\GCH\_gs#326-bytes
HKLM\Software\Gator.com\Gator\dyn\GCH\_gs#326--1
HKLM\Software\Gator.com\Gator\dyn\GCH\_gs#327-12029
HKLM\Software\Gator.com\Gator\dyn\GCH\_gs#327-bytes
HKLM\Software\Gator.com\Gator\dyn\GCH\_gs#327--1
HKLM\Software\Gator.com\Gator\dyn\GCH\_gs#328--1
HKLM\Software\Gator.com\Gator\dyn\GCH\_gs#328-bytes
HKLM\Software\Gator.com\Gator\dyn\GCH\_gs#328-12029
HKLM\Software\Gator.com\Gator\dyn\GCH\_gs#329-12029
HKLM\Software\Gator.com\Gator\dyn\GCH\_gs#329-bytes
HKLM\Software\Gator.com\Gator\dyn\GCH\_gs#329--1
HKLM\Software\Gator.com\Gator\dyn\GCH\_gs#330-12029
HKLM\Software\Gator.com\Gator\dyn\GCH\_gs#330-bytes
HKLM\Software\Gator.com\Gator\dyn\GCH\_gs#330--1
HKLM\Software\Gator.com\Gator\dyn\GCH\_gs#331-12029
HKLM\Software\Gator.com\Gator\dyn\GCH\_gs#331-bytes
HKLM\Software\Gator.com\Gator\dyn\GCH\_gs#331--1
HKLM\Software\Gator.com\Gator\dyn\GCH\_gs#332-12029
HKLM\Software\Gator.com\Gator\dyn\GCH\_gs#332-bytes
HKLM\Software\Gator.com\Gator\dyn\GCH\_gs#332--1
HKLM\Software\Gator.com\Gator\dyn\GCH\_gatortime
HKLM\Software\Gator.com\Gator\dyn\GCH\_gatortime#StartTime
HKLM\Software\Gator.com\Gator\dyn\GCH\_gatortime#OldestTime
HKLM\Software\Gator.com\Gator\dyn\GCH\_gatortime#346-12007
HKLM\Software\Gator.com\Gator\dyn\GCH\_gatortime#346-bytes
HKLM\Software\Gator.com\Gator\dyn\GCH\_gatortime#347-12007
HKLM\Software\Gator.com\Gator\dyn\GCH\_gatortime#347-bytes
HKLM\Software\Gator.com\Gator\dyn\GCH\_gatortime#348-200
HKLM\Software\Gator.com\Gator\dyn\GCH\_gatortime#348-bytes
HKLM\Software\Gator.com\Gator\dyn\GCH\_gatortime#349-12007
HKLM\Software\Gator.com\Gator\dyn\GCH\_gatortime#349-bytes
HKLM\Software\Gator.com\Gator\dyn\GCH\_gatortime#350-12007
HKLM\Software\Gator.com\Gator\dyn\GCH\_gatortime#350-bytes
HKLM\Software\Gator.com\Gator\dyn\GCH\_gatorcme
HKLM\Software\Gator.com\Gator\dyn\GCH\_gatorcme#StartTime
HKLM\Software\Gator.com\Gator\dyn\GCH\_gatorcme#OldestTime
HKLM\Software\Gator.com\Gator\dyn\GCH\_gatorcme#300-12029
HKLM\Software\Gator.com\Gator\dyn\GCH\_gatorcme#300-bytes
HKLM\Software\Gator.com\Gator\dyn\GCH\_gatorcme#301-12029
HKLM\Software\Gator.com\Gator\dyn\GCH\_gatorcme#301-bytes
HKLM\Software\Gator.com\Gator\dyn\GCH\_gatorcme#302-12029
HKLM\Software\Gator.com\Gator\dyn\GCH\_gatorcme#302-bytes
HKLM\Software\Gator.com\Gator\dyn\GCH\_gatorcme#302-200
HKLM\Software\Gator.com\Gator\dyn\GCH\_gatorcme#305-200
HKLM\Software\Gator.com\Gator\dyn\GCH\_gatorcme#305-bytes
HKLM\Software\Gator.com\Gator\dyn\GCH\_gatorcme#311-12029
HKLM\Software\Gator.com\Gator\dyn\GCH\_gatorcme#311-bytes
HKLM\Software\Gator.com\Gator\dyn\GCH\_gatorcme#312-12029
HKLM\Software\Gator.com\Gator\dyn\GCH\_gatorcme#312-bytes
HKLM\Software\Gator.com\Gator\dyn\GCH\_gatorcme#313-12029
HKLM\Software\Gator.com\Gator\dyn\GCH\_gatorcme#313-bytes
HKLM\Software\Gator.com\Gator\dyn\GCH\_gatorcme#314-12029
HKLM\Software\Gator.com\Gator\dyn\GCH\_gatorcme#314-bytes
HKLM\Software\Gator.com\Gator\dyn\GCH\_gatorcme#314-200
HKLM\Software\Gator.com\Gator\dyn\GCH\_gatorcme#321-12029
HKLM\Software\Gator.com\Gator\dyn\GCH\_gatorcme#321-bytes
HKLM\Software\Gator.com\Gator\dyn\GCH\_gatorcme#321-200
HKLM\Software\Gator.com\Gator\dyn\GCH\_gatorcme#326-12029
HKLM\Software\Gator.com\Gator\dyn\GCH\_gatorcme#326-bytes
HKLM\Software\Gator.com\Gator\dyn\GCH\_gatorcme#326-200
HKLM\Software\Gator.com\Gator\dyn\GCH\_gatorcme#330-12029
HKLM\Software\Gator.com\Gator\dyn\GCH\_gatorcme#330-bytes
HKLM\Software\Gator.com\Gator\dyn\GCH\_gatorcme#330-200
HKLM\Software\Gator.com\Gator\dyn\GUS
HKLM\Software\Gator.com\Gator\stat
HKLM\Software\Gator.com\Gator\stat#Guid
HKLM\Software\Gator.com\GInternet
HKLM\Software\Gator.com\GInternet\Proxy
HKLM\Software\Gator.com\GInternet\Proxy#Enabled

Adware.MyWebSearch/FunWebProducts
HKU\.DEFAULT\SOFTWARE\FunWebProducts
HKLM\SOFTWARE\FunWebProducts
HKLM\SOFTWARE\FunWebProducts\Installer
HKLM\SOFTWARE\FunWebProducts\Installer#Dir
HKLM\SOFTWARE\FunWebProducts\Installer#CurInstall
HKLM\SOFTWARE\FunWebProducts\Installer#CheckForConnection
HKLM\SOFTWARE\FunWebProducts\Installer#CacheDir
HKLM\SOFTWARE\FunWebProducts\Installer\downloaded
HKLM\SOFTWARE\FunWebProducts\PopSwatter
HKLM\SOFTWARE\FunWebProducts\PopSwatter#enabled
HKLM\SOFTWARE\MyWebSearch
HKLM\SOFTWARE\MyWebSearch\bar
HKLM\SOFTWARE\MyWebSearch\bar#pid
HKLM\SOFTWARE\MyWebSearch\bar#un
HKLM\SOFTWARE\MyWebSearch\bar#Dir
HKLM\SOFTWARE\MyWebSearch\bar#CurInstall
HKLM\SOFTWARE\MyWebSearch\bar#sr
HKLM\SOFTWARE\MyWebSearch\bar#SettingsDir
HKLM\SOFTWARE\MyWebSearch\bar#Id
HKLM\SOFTWARE\MyWebSearch\bar#Build
HKLM\SOFTWARE\MyWebSearch\bar#CacheDir
HKLM\SOFTWARE\MyWebSearch\bar#HistoryDir
HKLM\SOFTWARE\MyWebSearch\bar#Visible
HKLM\SOFTWARE\MyWebSearch\bar#Maximized
HKLM\SOFTWARE\MyWebSearch\bar#ConfigRevisionURL
HKLM\SOFTWARE\MyWebSearch\bar#ConfigDateStamp
HKLM\SOFTWARE\MyWebSearch\SearchAssistant
HKLM\SOFTWARE\MyWebSearch\SearchAssistant#pid
HKLM\SOFTWARE\MyWebSearch\SearchAssistant#Dir
HKLM\SOFTWARE\MyWebSearch\SearchAssistant#CurInstall
HKLM\SOFTWARE\MyWebSearch\SearchAssistant#sr
HKLM\SOFTWARE\MyWebSearch\SearchAssistant#Id
HKLM\SOFTWARE\MyWebSearch\SearchAssistant#CacheDir
HKLM\SOFTWARE\MyWebSearch\SearchAssistant#ConfigDateStamp
HKLM\SOFTWARE\MyWebSearch\MWSOEPLG
HKCR\CLSID\{147A976F-EEE1-4377-8EA7-4716E4CDD239}
HKCR\CLSID\{147A976F-EEE1-4377-8EA7-4716E4CDD239}\TreatAs
HKCR\CLSID\{A4730EBE-43A6-443e-9776-36915D323AD3}
HKCR\CLSID\{A4730EBE-43A6-443e-9776-36915D323AD3}\TreatAs

Adware.MyWay
HKCR\TypeLib\{0494D0D0-F8E0-41AD-92A3-14154ECE70AC}
HKCR\TypeLib\{0494D0D0-F8E0-41AD-92A3-14154ECE70AC}\1.0
HKCR\TypeLib\{0494D0D0-F8E0-41AD-92A3-14154ECE70AC}\1.0\FLAGS
HKCR\TypeLib\{0494D0D0-F8E0-41AD-92A3-14154ECE70AC}\1.0\0
HKCR\TypeLib\{0494D0D0-F8E0-41AD-92A3-14154ECE70AC}\1.0\0\win32
HKCR\TypeLib\{0494D0D0-F8E0-41AD-92A3-14154ECE70AC}\1.0\HELPDIR
HKLM\Software\MyWay
HKLM\Software\MyWay\myBar
HKLM\Software\MyWay\myBar#Dir
HKLM\Software\MyWay\myBar#ShzmCurInstall
HKLM\Software\MyWay\myBar#pid
HKLM\Software\MyWay\myBar#CurInstall
HKLM\Software\MyWay\myBar#sr
HKLM\Software\MyWay\myBar#pl
HKLM\Software\MyWay\myBar#Id
HKLM\Software\MyWay\myBar#Build
HKLM\Software\MyWay\myBar#CacheDir
HKLM\Software\MyWay\myBar#HistoryDir
HKLM\Software\MyWay\myBar#Visible
HKLM\Software\MyWay\myBar#Maximized
HKLM\Software\MyWay\myBar#SettingsDir
HKLM\Software\MyWay\myBar#ConfigRevisionURL
HKLM\Software\MyWay\myBar#ConfigDateStamp
HKLM\Software\MyWay\myBar\partner
HKLM\Software\MyWay\myBar\partner#bitmap
HKLM\Software\MyWay\myBar\partner#name
HKLM\Software\MyWay\myBar\partner#test
HKLM\Software\MyWay\myBar\partner#PM-Home
HKLM\Software\MyWay\myBar\partner#PM-Points
HKLM\Software\MyWay\myBar\partner#PM-Redeem
HKLM\Software\MyWay\myBar\partner#PM-Wallet
HKLM\Software\MyWay\myBar\partner#PM-Settings
HKCR\Interface\{0494D0D6-F8E0-41AD-92A3-14154ECE70AC}
HKCR\Interface\{0494D0D6-F8E0-41AD-92A3-14154ECE70AC}\ProxyStubClsid
HKCR\Interface\{0494D0D6-F8E0-41AD-92A3-14154ECE70AC}\ProxyStubClsid32
HKCR\Interface\{0494D0D6-F8E0-41AD-92A3-14154ECE70AC}\TypeLib
HKCR\Interface\{0494D0D6-F8E0-41AD-92A3-14154ECE70AC}\TypeLib#Version
HKCR\Interface\{0494D0D4-F8E0-41AD-92A3-14154ECE70AC}
HKCR\Interface\{0494D0D4-F8E0-41AD-92A3-14154ECE70AC}\ProxyStubClsid
HKCR\Interface\{0494D0D4-F8E0-41AD-92A3-14154ECE70AC}\ProxyStubClsid32
HKCR\Interface\{0494D0D4-F8E0-41AD-92A3-14154ECE70AC}\TypeLib
HKCR\Interface\{0494D0D4-F8E0-41AD-92A3-14154ECE70AC}\TypeLib#Version
HKCR\Interface\{0494D0DA-F8E0-41AD-92A3-14154ECE70AC}
HKCR\Interface\{0494D0DA-F8E0-41AD-92A3-14154ECE70AC}\ProxyStubClsid
HKCR\Interface\{0494D0DA-F8E0-41AD-92A3-14154ECE70AC}\ProxyStubClsid32
HKCR\Interface\{0494D0DA-F8E0-41AD-92A3-14154ECE70AC}\TypeLib
HKCR\Interface\{0494D0DA-F8E0-41AD-92A3-14154ECE70AC}\TypeLib#Version
HKCR\Interface\{0494D0DC-F8E0-41AD-92A3-14154ECE70AC}
HKCR\Interface\{0494D0DC-F8E0-41AD-92A3-14154ECE70AC}\ProxyStubClsid
HKCR\Interface\{0494D0DC-F8E0-41AD-92A3-14154ECE70AC}\ProxyStubClsid32
HKCR\Interface\{0494D0DC-F8E0-41AD-92A3-14154ECE70AC}\TypeLib
HKCR\Interface\{0494D0DC-F8E0-41AD-92A3-14154ECE70AC}\TypeLib#Version

Trojan.NewDotNet
C:\WINDOWS\NEWDOTNET3_36.DLL
C:\WINDOWS\NDNUNINSTALL4_50.EXE
C:\WINDOWS\NDNUNINSTALL4_88.EXE
C:\WINDOWS\NDNUNINSTALL4_94.EXE

Trojan.Gen
C:\WINDOWS\UNIFISH3.EXE

Adware.Lop
C:\PROGRAM FILES\C2MEDIA\SETUP.EXE