SUPERAntiSpyware Scan Log
http://www.superantispyware.com
Generated 04/26/2008 at 05:13 PM
Application Version : 4.0.1154
Core Rules Database Version : 3448
Trace Rules Database Version: 1440
Scan type : Complete Scan
Total Scan Time : 01:09:05
Memory items scanned : 507
Memory threats detected : 0
Registry items scanned : 5720
Registry threats detected : 50
File items scanned : 79730
File threats detected : 77
Adware.Vundo Variant
HKLM\Software\Classes\CLSID\{57F9E23F-A439-4679-AB81-BA292405EE25}
HKCR\CLSID\{57F9E23F-A439-4679-AB81-BA292405EE25}
HKCR\CLSID\{57F9E23F-A439-4679-AB81-BA292405EE25}\InprocServer32
HKCR\CLSID\{57F9E23F-A439-4679-AB81-BA292405EE25}\InprocServer32#ThreadingModel
C:\WINDOWS\SYSTEM32\GEBYW.DLL
HKLM\Software\Classes\CLSID\{B3740027-0036-49BF-98E7-04F4F903D67B}
HKCR\CLSID\{B3740027-0036-49BF-98E7-04F4F903D67B}
HKCR\CLSID\{B3740027-0036-49BF-98E7-04F4F903D67B}\InprocServer32
HKCR\CLSID\{B3740027-0036-49BF-98E7-04F4F903D67B}\InprocServer32#ThreadingModel
C:\WINDOWS\SYSTEM32\VTUVUTU.DLL
HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{57F9E23F-A439-4679-AB81-BA292405EE25}
HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{7FFBF68E-8474-4BE1-B2C7-92B37A2D51E7}
HKCR\CLSID\{7FFBF68E-8474-4BE1-B2C7-92B37A2D51E7}
HKCR\CLSID\{7FFBF68E-8474-4BE1-B2C7-92B37A2D51E7}\InprocServer32
HKCR\CLSID\{7FFBF68E-8474-4BE1-B2C7-92B37A2D51E7}\InprocServer32#ThreadingModel
C:\WINDOWS\SYSTEM32\VTSQN.DLL
HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{B3740027-0036-49BF-98E7-04F4F903D67B}
HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks#{ B3740027-0036-49BF-98E7-04F4F903D67B}
HKCR\CLSID\{B3740027-0036-49BF-98E7-04F4F903D67B}
C:\SYSTEM VOLUME INFORMATION\_RESTORE{0B013E77-D889-406D-BC44-57183391B15C}\RP251\A0027667.DLL
Trojan.WinFixer
HKLM\Software\Classes\CLSID\{8BC8DCA6-6833-4C56-9BA8-6D7E7DB0B899}
HKCR\CLSID\{8BC8DCA6-6833-4C56-9BA8-6D7E7DB0B899}
HKCR\CLSID\{8BC8DCA6-6833-4C56-9BA8-6D7E7DB0B899}\InprocServer32
HKCR\CLSID\{8BC8DCA6-6833-4C56-9BA8-6D7E7DB0B899}\InprocServer32#ThreadingModel
C:\WINDOWS\SYSTEM32\AWVTU.DLL
HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{8BC8DCA6-6833-4C56-9BA8-6D7E7DB0B899}
Adware.HBHelper
HKLM\Software\Classes\CLSID\{CA3EB689-8F09-4026-AA10-B9534C691CE0}
HKCR\CLSID\{CA3EB689-8F09-4026-AA10-B9534C691CE0}
HKCR\CLSID\{CA3EB689-8F09-4026-AA10-B9534C691CE0}
HKCR\CLSID\{CA3EB689-8F09-4026-AA10-B9534C691CE0}\InprocServer32
HKCR\CLSID\{CA3EB689-8F09-4026-AA10-B9534C691CE0}\InprocServer32#ThreadingModel
HKCR\CLSID\{CA3EB689-8F09-4026-AA10-B9534C691CE0}\ProgID
HKCR\CLSID\{CA3EB689-8F09-4026-AA10-B9534C691CE0}\TypeLib
HKCR\CLSID\{CA3EB689-8F09-4026-AA10-B9534C691CE0}\VersionIndependentProgID
C:\PROGRAM FILES\BARUNGO\BARUNGO BAR\TBHELPER.DLL
Trojan.Smitfraud Variant
HKLM\Software\Classes\CLSID\{db763ed8-100a-481b-8913-50a2f41dcdc3}
HKCR\CLSID\{DB763ED8-100A-481B-8913-50A2F41DCDC3}
HKCR\CLSID\{DB763ED8-100A-481B-8913-50A2F41DCDC3}\InProcServer32
HKCR\CLSID\{DB763ED8-100A-481B-8913-50A2F41DCDC3}\InProcServer32#ThreadingModel
C:\WINDOWS\SYSTEM32\BUBBJ.DLL
HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\SharedTaskScheduler #{db763ed8-100a-481b-8913-50a2f41dcdc3}
Trojan.Smitfraud Variant/IE Anti-Spyware
HKLM\Software\Microsoft\Internet Explorer\Extensions\{9034A523-D068-4BE8-A284-9DF278BE776E}
Adware.Tracking Cookie
C:\Documents and Settings\WinXP\Cookies\winxp@www8.addfreestats[1].txt
C:\Documents and Settings\WinXP\Cookies\winxp@www7.addfreestats[1].txt
C:\Documents and Settings\WinXP\Cookies\winxp@ads.monster[1].txt
C:\Documents and Settings\WinXP\Cookies\winxp@server.cpmstar[2].txt
C:\Documents and Settings\WinXP\Cookies\winxp@2o7[1].txt
C:\Documents and Settings\WinXP\Cookies\winxp@socialmedia[2].txt
C:\Documents and Settings\WinXP\Cookies\winxp@casalemedia[2].txt
C:\Documents and Settings\WinXP\Cookies\winxp@msnportal.112.2o7[1].txt
C:\Documents and Settings\WinXP\Cookies\winxp@media6degrees[1].txt
C:\Documents and Settings\WinXP\Cookies\winxp@insightexpressai[2].txt
C:\Documents and Settings\WinXP\Cookies\winxp@bs.serving-sys[2].txt
C:\Documents and Settings\WinXP\Cookies\winxp@e-2dj6wjk4smdzako.stats.esomniture[2].txt
C:\Documents and Settings\WinXP\Cookies\winxp@media.adrevolver[3].txt
C:\Documents and Settings\WinXP\Cookies\winxp@videoegg.adbureau[2].txt
C:\Documents and Settings\WinXP\Cookies\winxp@ads.pointroll[1].txt
C:\Documents and Settings\WinXP\Cookies\winxp@admin.valueclickmedia[2].txt
C:\Documents and Settings\WinXP\Cookies\winxp@advertising[1].txt
C:\Documents and Settings\WinXP\Cookies\winxp@ads.cnn[1].txt
C:\Documents and Settings\WinXP\Cookies\winxp@atdmt[2].txt
C:\Documents and Settings\WinXP\Cookies\winxp@aircanada-push.worldmedia[1].txt
C:\Documents and Settings\WinXP\Cookies\winxp@www.burstnet[2].txt
C:\Documents and Settings\WinXP\Cookies\winxp@zedo[2].txt
C:\Documents and Settings\WinXP\Cookies\winxp@gostats[1].txt
C:\Documents and Settings\WinXP\Cookies\winxp@ads.addynamix[1].txt
C:\Documents and Settings\WinXP\Cookies\winxp@burstnet[1].txt
C:\Documents and Settings\WinXP\Cookies\winxp@apmebf[2].txt
C:\Documents and Settings\WinXP\Cookies\winxp@soundclick[2].txt
C:\Documents and Settings\WinXP\Cookies\winxp@statse.webtrendslive[1].txt
C:\Documents and Settings\WinXP\Cookies\winxp@rocku.adbureau[2].txt
C:\Documents and Settings\WinXP\Cookies\winxp@adrevolver[2].txt
C:\Documents and Settings\WinXP\Cookies\winxp@adbrite[1].txt
C:\Documents and Settings\WinXP\Cookies\winxp@revsci[1].txt
C:\Documents and Settings\WinXP\Cookies\winxp@imrworldwide[2].txt
C:\Documents and Settings\WinXP\Cookies\winxp@adcentriconline[2].txt
C:\Documents and Settings\WinXP\Cookies\winxp@adopt.euroclick[2].txt
C:\Documents and Settings\WinXP\Cookies\winxp@ad.yieldmanager[2].txt
C:\Documents and Settings\WinXP\Cookies\winxp@statcounter[1].txt
C:\Documents and Settings\WinXP\Cookies\winxp@www3.addfreestats[1].txt
C:\Documents and Settings\WinXP\Cookies\winxp@bluestreak[1].txt
C:\Documents and Settings\WinXP\Cookies\winxp@fastclick[2].txt
C:\Documents and Settings\WinXP\Cookies\winxp@data.coremetrics[1].txt
C:\Documents and Settings\WinXP\Cookies\winxp@serving-sys[2].txt
C:\Documents and Settings\WinXP\Cookies\winxp@specificclick[2].txt
C:\Documents and Settings\WinXP\Cookies\winxp@focalex[2].txt
C:\Documents and Settings\WinXP\Cookies\winxp@mediaplex[1].txt
C:\Documents and Settings\WinXP\Cookies\winxp@questionmarket[2].txt
C:\Documents and Settings\WinXP\Cookies\winxp@ads.techguy[2].txt
C:\Documents and Settings\WinXP\Cookies\winxp@e-2dj6wflywjdjseo.stats.esomniture[1].txt
C:\Documents and Settings\WinXP\Cookies\winxp@media.adrevolver[2].txt
C:\Documents and Settings\WinXP\Cookies\winxp@doubleclick[1].txt
C:\Documents and Settings\WinXP\Cookies\winxp@cgm.adbureau[1].txt
C:\Documents and Settings\WinXP\Cookies\winxp@tribalfusion[2].txt
C:\Documents and Settings\WinXP\Cookies\winxp@prospect.adbureau[2].txt
Trojan.Media-Codec
C:\Documents and Settings\WinXP\Favorites\Online Security Test.url
Browser Hijacker.Deskbar
HKCR\Interface\{4897BBA6-48D9-468C-8EFA-846275D7701B}
HKCR\Interface\{4897BBA6-48D9-468C-8EFA-846275D7701B}\ProxyStubClsid
HKCR\Interface\{4897BBA6-48D9-468C-8EFA-846275D7701B}\ProxyStubClsid32
HKCR\Interface\{4897BBA6-48D9-468C-8EFA-846275D7701B}\TypeLib
HKCR\Interface\{4897BBA6-48D9-468C-8EFA-846275D7701B}\TypeLib#Version
Malware.SpyLocked
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Windows Safety Alert
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Windows Safety Alert#DisplayName
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Windows Safety Alert#UninstallString
Trojan.Media-Codec/V4
HKCR\multimediaControls.chl
HKCR\multimediaControls.chl\CLSID
Rogue.AntiSpywareShield
C:\Program Files\AntiSpywareShield\AntiSpywareShield.lic
C:\Program Files\AntiSpywareShield\AntiSpywareShield1.ad
C:\Program Files\AntiSpywareShield
C:\Documents and Settings\WinXP\Start Menu\Programs\AntiSpywareShield\AntiSpywareShield.lnk
C:\Documents and Settings\WinXP\Start Menu\Programs\AntiSpywareShield\Uninstall.lnk
C:\Documents and Settings\WinXP\Start Menu\Programs\AntiSpywareShield
C:\Documents and Settings\WinXP\Desktop\AntiSpywareShield.lnk
Malware.LocusSoftware Inc/PCPrivacyTool
HKLM\Software\Purchased Products
HKLM\Software\Purchased Products\System Error Repair
HKLM\Software\Purchased Products\System Error Repair#domain
HKLM\Software\Purchased Products\System Error Repair#pname
HKLM\Software\Purchased Products\System Error Repair#cname
Malware.LocusSoftware Inc/SystemErrorFixer
C:\Program Files\Common Files\SystemErrorFixer
Adware.Vundo-Variant
C:\SYSTEM VOLUME INFORMATION\_RESTORE{0B013E77-D889-406D-BC44-57183391B15C}\RP251\A0027668.DLL
Rogue.VirusHeat
C:\SYSTEM VOLUME INFORMATION\_RESTORE{0B013E77-D889-406D-BC44-57183391B15C}\RP264\A0030111.EXE
Trojan.Unknown Origin
C:\SYSTEM VOLUME INFORMATION\_RESTORE{0B013E77-D889-406D-BC44-57183391B15C}\RP266\A0031200.ICO
C:\SYSTEM VOLUME INFORMATION\_RESTORE{0B013E77-D889-406D-BC44-57183391B15C}\RP266\A0031207.ICO
Adware.Vundo Variant/Rel
C:\WINDOWS\SYSTEM32\NQSTV.INI
C:\WINDOWS\SYSTEM32\UTVWA.INI
C:\WINDOWS\SYSTEM32\UTVWA.INI2
C:\WINDOWS\SYSTEM32\WYBEG.INI