The SuperAntiSpyware log is:
SUPERAntiSpyware Scan Log
http://www.superantispyware.comGenerated 10/01/2009 at 09:56 AM
Application Version : 4.29.1002
Core Rules Database Version : 4137
Trace Rules Database Version: 2069
Scan type : Complete Scan
Total Scan Time : 08:59:13
Memory items scanned : 364
Memory threats detected : 0
Registry items scanned : 4680
Registry threats detected : 33
File items scanned : 136469
File threats detected : 257
Adware.AdSponsor/ISM
HKLM\Software\Classes\CLSID\{17BFCF1A-B579-48a7-9849-719DDD11D340}
HKCR\CLSID\{17BFCF1A-B579-48A7-9849-719DDD11D340}
HKCR\CLSID\{17BFCF1A-B579-48A7-9849-719DDD11D340}
HKCR\CLSID\{17BFCF1A-B579-48A7-9849-719DDD11D340}\Implemented Categories
HKCR\CLSID\{17BFCF1A-B579-48A7-9849-719DDD11D340}\Implemented Categories\{00021493-0000-0000-C000-000000000046}
HKCR\CLSID\{17BFCF1A-B579-48A7-9849-719DDD11D340}\InprocServer32
HKCR\CLSID\{17BFCF1A-B579-48A7-9849-719DDD11D340}\InprocServer32#ThreadingModel
HKCR\CLSID\{17BFCF1A-B579-48A7-9849-719DDD11D340}\ProgID
HKCR\CLSID\{17BFCF1A-B579-48A7-9849-719DDD11D340}\VersionIndependentProgID
HKCR\GrandBar.Band.1
HKCR\GrandBar.Band
C:\PROGRAM FILES\GRANDPACK\GRANDPACK2.DLL
HKLM\Software\Microsoft\Internet Explorer\Explorer Bars\{17BFCF1A-B579-48a7-9849-719DDD11D340}
Adware.Vundo Variant
HKLM\Software\Classes\CLSID\{2D5796A2-44E0-4E50-A5A0-80BF1EE3EA73}
HKCR\CLSID\{2D5796A2-44E0-4E50-A5A0-80BF1EE3EA73}
HKCR\CLSID\{2D5796A2-44E0-4E50-A5A0-80BF1EE3EA73}\InprocServer32
HKCR\CLSID\{2D5796A2-44E0-4E50-A5A0-80BF1EE3EA73}\InprocServer32#ThreadingModel
C:\WINDOWS\SYSTEM32\TUVUSTT.DLL
HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks#{2D5796A2-44E0-4E50-A5A0-80BF1EE3EA73}
HKCR\CLSID\{2D5796A2-44E0-4E50-A5A0-80BF1EE3EA73}
Trojan.WinFixer
HKLM\Software\Classes\CLSID\{870C2829-88AB-4606-8C23-0A98795126B3}
HKCR\CLSID\{870C2829-88AB-4606-8C23-0A98795126B3}
HKCR\CLSID\{870C2829-88AB-4606-8C23-0A98795126B3}\InprocServer32
HKCR\CLSID\{870C2829-88AB-4606-8C23-0A98795126B3}\InprocServer32#ThreadingModel
C:\WINDOWS\SYSTEM32\SSQRO.DLL
HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{870C2829-88AB-4606-8C23-0A98795126B3}
HKU\S-1-5-21-2367804977-3653976795-2492523613-1006\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{870C2829-88AB-4606-8C23-0A98795126B3}
Adware.Tracking Cookie
C:\Documents and Settings\Friends\Cookies\friends@content.yieldmanager[1].txt
C:\Documents and Settings\Friends\Cookies\friends@doubleclick[1].txt
C:\Documents and Settings\Friends\Cookies\friends@atdmt[1].txt
C:\Documents and Settings\HelpAssistant\Cookies\friends@a1.interclick[1].txt
C:\Documents and Settings\HelpAssistant\Cookies\friends@a1.interclick[2].txt
C:\Documents and Settings\HelpAssistant\Cookies\friends@ad.doubleclick[1].txt
C:\Documents and Settings\HelpAssistant\Cookies\friends@ads.bridgetrack[2].txt
C:\Documents and Settings\HelpAssistant\Cookies\friends@ads.lucidmedia[1].txt
C:\Documents and Settings\HelpAssistant\Cookies\friends@ads.nba[1].txt
C:\Documents and Settings\HelpAssistant\Cookies\friends@ads.pointroll[1].txt
C:\Documents and Settings\HelpAssistant\Cookies\friends@ads.pointroll[2].txt
C:\Documents and Settings\HelpAssistant\Cookies\friends@ads.verticalscope[2].txt
C:\Documents and Settings\HelpAssistant\Cookies\friends@ads.widgetbucks[2].txt
C:\Documents and Settings\HelpAssistant\Cookies\friends@adserver.adtechus[1].txt
C:\Documents and Settings\HelpAssistant\Cookies\friends@adultfriendfinder[1].txt
C:\Documents and Settings\HelpAssistant\Cookies\friends@adultfriendfinder[2].txt
C:\Documents and Settings\HelpAssistant\Cookies\friends@apmebf[1].txt
C:\Documents and Settings\HelpAssistant\Cookies\friends@apmebf[2].txt
C:\Documents and Settings\HelpAssistant\Cookies\friends@at.atwola[1].txt
C:\Documents and Settings\HelpAssistant\Cookies\friends@at.atwola[2].txt
C:\Documents and Settings\HelpAssistant\Cookies\friends@atwola[1].txt
C:\Documents and Settings\HelpAssistant\Cookies\friends@cache.trafficmp[1].txt
C:\Documents and Settings\HelpAssistant\Cookies\friends@cdn4.specificclick[2].txt
C:\Documents and Settings\HelpAssistant\Cookies\friends@chitika[1].txt
C:\Documents and Settings\HelpAssistant\Cookies\friends@cms.trafficmp[1].txt
C:\Documents and Settings\HelpAssistant\Cookies\friends@collective-media[1].txt
C:\Documents and Settings\HelpAssistant\Cookies\friends@content.yieldmanager[1].txt
C:\Documents and Settings\HelpAssistant\Cookies\friends@content.yieldmanager[2].txt
C:\Documents and Settings\HelpAssistant\Cookies\friends@content.yieldmanager[3].txt
C:\Documents and Settings\HelpAssistant\Cookies\friends@counter15.sextracker[1].txt
C:\Documents and Settings\HelpAssistant\Cookies\friends@delivery.trafficjunky[1].txt
C:\Documents and Settings\HelpAssistant\Cookies\friends@eyewonder[2].txt
C:\Documents and Settings\HelpAssistant\Cookies\friends@hearstugo.112.2o7[1].txt
C:\Documents and Settings\HelpAssistant\Cookies\friends@iacas.adbureau[1].txt
C:\Documents and Settings\HelpAssistant\Cookies\friends@icebanner[1].txt
C:\Documents and Settings\HelpAssistant\Cookies\friends@imrworldwide[2].txt
C:\Documents and Settings\HelpAssistant\Cookies\friends@insightexpressai[1].txt
C:\Documents and Settings\HelpAssistant\Cookies\friends@insightexpressai[2].txt
C:\Documents and Settings\HelpAssistant\Cookies\friends@interclick[1].txt
C:\Documents and Settings\HelpAssistant\Cookies\friends@interclick[2].txt
C:\Documents and Settings\HelpAssistant\Cookies\friends@invitemedia[1].txt
C:\Documents and Settings\HelpAssistant\Cookies\friends@invitemedia[2].txt
C:\Documents and Settings\HelpAssistant\Cookies\friends@media.brandreachsys[1].txt
C:\Documents and Settings\HelpAssistant\Cookies\friends@media.photobucket[1].txt
C:\Documents and Settings\HelpAssistant\Cookies\friends@media.photobucket[2].txt
C:\Documents and Settings\HelpAssistant\Cookies\friends@media6degrees[1].txt
C:\Documents and Settings\HelpAssistant\Cookies\friends@media6degrees[2].txt
C:\Documents and Settings\HelpAssistant\Cookies\friends@myroitracking[2].txt
C:\Documents and Settings\HelpAssistant\Cookies\friends@network.realmedia[1].txt
C:\Documents and Settings\HelpAssistant\Cookies\friends@oasn04.247realmedia[1].txt
C:\Documents and Settings\HelpAssistant\Cookies\friends@oasn04.247realmedia[2].txt
C:\Documents and Settings\HelpAssistant\Cookies\friends@optimize.indieclick[1].txt
C:\Documents and Settings\HelpAssistant\Cookies\friends@optimize.indieclick[2].txt
C:\Documents and Settings\HelpAssistant\Cookies\friends@ordie.adbureau[1].txt
C:\Documents and Settings\HelpAssistant\Cookies\friends@pornhub[2].txt
C:\Documents and Settings\HelpAssistant\Cookies\friends@richmedia.yahoo[1].txt
C:\Documents and Settings\HelpAssistant\Cookies\friends@sexmultiplex[2].txt
C:\Documents and Settings\HelpAssistant\Cookies\friends@sixapart.adbureau[1].txt
C:\Documents and Settings\HelpAssistant\Cookies\friends@socialmedia[1].txt
C:\Documents and Settings\HelpAssistant\Cookies\friends@socialmedia[2].txt
C:\Documents and Settings\HelpAssistant\Cookies\friends@specificclick[1].txt
C:\Documents and Settings\HelpAssistant\Cookies\friends@specificclick[2].txt
C:\Documents and Settings\HelpAssistant\Cookies\friends@specificmedia[1].txt
C:\Documents and Settings\HelpAssistant\Cookies\friends@specificmedia[2].txt
C:\Documents and Settings\HelpAssistant\Cookies\friends@statcounter[1].txt
C:\Documents and Settings\HelpAssistant\Cookies\friends@statcounter[2].txt
C:\Documents and Settings\HelpAssistant\Cookies\friends@super.kitnmedia[1].txt
C:\Documents and Settings\HelpAssistant\Cookies\friends@thestreet.112.2o7[1].txt
C:\Documents and Settings\HelpAssistant\Cookies\friends@vogelbanner575[1].txt
C:\Documents and Settings\HelpAssistant\Cookies\friends@www.blogbannerexchange[1].txt
C:\Documents and Settings\HelpAssistant\Cookies\friends@www.burstbeacon[1].txt
C:\Documents and Settings\HelpAssistant\Cookies\friends@www.burstnet[1].txt
C:\Documents and Settings\HelpAssistant\Cookies\friends@www.pornhub[1].txt
C:\Documents and Settings\HelpAssistant\Cookies\friends@www.sexmultiplex[2].txt
C:\Documents and Settings\HelpAssistant\Cookies\friends@xiti[1].txt
C:\Documents and Settings\HelpAssistant\Cookies\friends@xxxblackbook[1].txt
C:\Documents and Settings\NetworkService\Cookies\system@dalenetwork.directtrack[2].txt
C:\Documents and Settings\NetworkService\Cookies\system@directtrack[1].txt
C:\Documents and Settings\TwoFour\Cookies\twofour@6144.9907793-searchingmax.com.clickshield[1].txt
C:\Documents and Settings\TwoFour\Cookies\twofour@6145.45.clickshield[1].txt
C:\Documents and Settings\TwoFour\Cookies\twofour@6149.av1.clickshield[1].txt
C:\Documents and Settings\TwoFour\Cookies\twofour@6149.red2.clickshield[1].txt
C:\Documents and Settings\TwoFour\Cookies\twofour@6403.kliktraffic.blueseek[1].txt
C:\Documents and Settings\TwoFour\Cookies\twofour@ad.zanox[2].txt
C:\Documents and Settings\TwoFour\Cookies\twofour@adecn[1].txt
C:\Documents and Settings\TwoFour\Cookies\twofour@adfarm1.adition[1].txt
C:\Documents and Settings\TwoFour\Cookies\twofour@adlegend[2].txt
C:\Documents and Settings\TwoFour\Cookies\twofour@adopt.specificclick[1].txt
C:\Documents and Settings\TwoFour\Cookies\twofour@ads.adap[2].txt
C:\Documents and Settings\TwoFour\Cookies\twofour@ads.addynamix[1].txt
C:\Documents and Settings\TwoFour\Cookies\twofour@ads.admanage[1].txt
C:\Documents and Settings\TwoFour\Cookies\twofour@ads.bootcampmedia[1].txt
C:\Documents and Settings\TwoFour\Cookies\twofour@ads.bridgetrack[2].txt
C:\Documents and Settings\TwoFour\Cookies\twofour@ads.doubleagent[2].txt
C:\Documents and Settings\TwoFour\Cookies\twofour@ads.imarketservices[1].txt
C:\Documents and Settings\TwoFour\Cookies\twofour@ads.lucidmedia[1].txt
C:\Documents and Settings\TwoFour\Cookies\twofour@ads.pointroll[2].txt
C:\Documents and Settings\TwoFour\Cookies\twofour@ads.realtechnetwork[2].txt
C:\Documents and Settings\TwoFour\Cookies\twofour@ads.redorbit[2].txt
C:\Documents and Settings\TwoFour\Cookies\twofour@ads.specificmedia[1].txt
C:\Documents and Settings\TwoFour\Cookies\twofour@ads.traffic-o-rama[1].txt
C:\Documents and Settings\TwoFour\Cookies\twofour@ads.us.e-planning[1].txt
C:\Documents and Settings\TwoFour\Cookies\twofour@ads.widgetbucks[2].txt
C:\Documents and Settings\TwoFour\Cookies\twofour@ads2.drivelinemedia[1].txt
C:\Documents and Settings\TwoFour\Cookies\twofour@adserve.gossipgirls[1].txt
C:\Documents and Settings\TwoFour\Cookies\twofour@adserver.adtechus[1].txt
C:\Documents and Settings\TwoFour\Cookies\twofour@adserver.easyad[1].txt
C:\Documents and Settings\TwoFour\Cookies\twofour@adserving.contextualmarketplace[1].txt
C:\Documents and Settings\TwoFour\Cookies\twofour@adservr[2].txt
C:\Documents and Settings\TwoFour\Cookies\twofour@adultadworld[2].txt
C:\Documents and Settings\TwoFour\Cookies\twofour@advertising.ezanga[2].txt
C:\Documents and Settings\TwoFour\Cookies\twofour@aff.primaryads[1].txt
C:\Documents and Settings\TwoFour\Cookies\twofour@airtrafficcontrolequipment[1].txt
C:\Documents and Settings\TwoFour\Cookies\twofour@apmebf[1].txt
C:\Documents and Settings\TwoFour\Cookies\twofour@at.atwola[2].txt
C:\Documents and Settings\TwoFour\Cookies\twofour@atwola[1].txt
C:\Documents and Settings\TwoFour\Cookies\twofour@avgtechnologies.112.2o7[1].txt
C:\Documents and Settings\TwoFour\Cookies\twofour@azjmp[2].txt
C:\Documents and Settings\TwoFour\Cookies\twofour@bet.burstnet[1].txt
C:\Documents and Settings\TwoFour\Cookies\twofour@blockedclick[2].txt
C:\Documents and Settings\TwoFour\Cookies\twofour@bootcampmedia[1].txt
C:\Documents and Settings\TwoFour\Cookies\twofour@bridge2.admarketplace[2].txt
C:\Documents and Settings\TwoFour\Cookies\twofour@cache.trafficmp[1].txt
C:\Documents and Settings\TwoFour\Cookies\twofour@cdn4.specificclick[1].txt
C:\Documents and Settings\TwoFour\Cookies\twofour@cgm.adbureau[2].txt
C:\Documents and Settings\TwoFour\Cookies\twofour@chitika[2].txt
C:\Documents and Settings\TwoFour\Cookies\twofour@clickarrows[1].txt
C:\Documents and Settings\TwoFour\Cookies\twofour@clickbooth[1].txt
C:\Documents and Settings\TwoFour\Cookies\twofour@clicksmart[1].txt
C:\Documents and Settings\TwoFour\Cookies\twofour@clickthrough.kanoodle[2].txt
C:\Documents and Settings\TwoFour\Cookies\twofour@collective-media[2].txt
C:\Documents and Settings\TwoFour\Cookies\twofour@content.yieldmanager[1].txt
C:\Documents and Settings\TwoFour\Cookies\twofour@content.yieldmanager[3].txt
C:\Documents and Settings\TwoFour\Cookies\twofour@contractors.clicksmart[1].txt
C:\Documents and Settings\TwoFour\Cookies\twofour@counter.hitslink[1].txt
C:\Documents and Settings\TwoFour\Cookies\twofour@crackle[2].txt
C:\Documents and Settings\TwoFour\Cookies\twofour@dc.tremormedia[2].txt
C:\Documents and Settings\TwoFour\Cookies\twofour@directtrack[1].txt
C:\Documents and Settings\TwoFour\Cookies\twofour@dr.findlinks[1].txt
C:\Documents and Settings\TwoFour\Cookies\twofour@drivelinemedia[1].txt
C:\Documents and Settings\TwoFour\Cookies\twofour@dynamic.media.adrevolver[2].txt
C:\Documents and Settings\TwoFour\Cookies\twofour@ehg-lattelove.hitbox[1].txt
C:\Documents and Settings\TwoFour\Cookies\twofour@ehg-players.hitbox[1].txt
C:\Documents and Settings\TwoFour\Cookies\twofour@ehg-ripedigitalentertainment.hitbox[1].txt
C:\Documents and Settings\TwoFour\Cookies\twofour@ehg-traderelectronicmedia.hitbox[2].txt
C:\Documents and Settings\TwoFour\Cookies\twofour@ehg.hitbox[2].txt
C:\Documents and Settings\TwoFour\Cookies\twofour@exitexchange[1].txt
C:\Documents and Settings\TwoFour\Cookies\twofour@exitexchange[3].txt
C:\Documents and Settings\TwoFour\Cookies\twofour@exittracking[1].txt
C:\Documents and Settings\TwoFour\Cookies\twofour@finditquick[1].txt
C:\Documents and Settings\TwoFour\Cookies\twofour@googl-stats[1].txt
C:\Documents and Settings\TwoFour\Cookies\twofour@googl-stats[2].txt
C:\Documents and Settings\TwoFour\Cookies\twofour@hornymatches[1].txt
C:\Documents and Settings\TwoFour\Cookies\twofour@imediablast[2].txt
C:\Documents and Settings\TwoFour\Cookies\twofour@imrworldwide[2].txt
C:\Documents and Settings\TwoFour\Cookies\twofour@incentaclick[2].txt
C:\Documents and Settings\TwoFour\Cookies\twofour@insightexpressai[2].txt
C:\Documents and Settings\TwoFour\Cookies\twofour@interclick[2].txt
C:\Documents and Settings\TwoFour\Cookies\twofour@invitemedia[2].txt
C:\Documents and Settings\TwoFour\Cookies\twofour@kelleybluebook.112.2o7[1].txt
C:\Documents and Settings\TwoFour\Cookies\twofour@kontera[2].txt
C:\Documents and Settings\TwoFour\Cookies\twofour@login.revenueloop[2].txt
C:\Documents and Settings\TwoFour\Cookies\twofour@lulu.112.2o7[1].txt
C:\Documents and Settings\TwoFour\Cookies\twofour@lynxtrack[1].txt
C:\Documents and Settings\TwoFour\Cookies\twofour@media6degrees[2].txt
C:\Documents and Settings\TwoFour\Cookies\twofour@mediatraffic[2].txt
C:\Documents and Settings\TwoFour\Cookies\twofour@myroitracking[2].txt
C:\Documents and Settings\TwoFour\Cookies\twofour@oasn04.247realmedia[1].txt
C:\Documents and Settings\TwoFour\Cookies\twofour@partner.finditquick[1].txt
C:\Documents and Settings\TwoFour\Cookies\twofour@primetrafficsite[1].txt
C:\Documents and Settings\TwoFour\Cookies\twofour@prosecurityclicks[1].txt
C:\Documents and Settings\TwoFour\Cookies\twofour@redirect.clickshield[1].txt
C:\Documents and Settings\TwoFour\Cookies\twofour@redorbit[2].txt
C:\Documents and Settings\TwoFour\Cookies\twofour@revenuehit[1].txt
C:\Documents and Settings\TwoFour\Cookies\twofour@richmedia.yahoo[1].txt
C:\Documents and Settings\TwoFour\Cookies\twofour@rotator.dex.adjuggler[2].txt
C:\Documents and Settings\TwoFour\Cookies\twofour@rotator.its.adjuggler[1].txt
C:\Documents and Settings\TwoFour\Cookies\twofour@sales.liveperson[2].txt
C:\Documents and Settings\TwoFour\Cookies\twofour@sales.liveperson[3].txt
C:\Documents and Settings\TwoFour\Cookies\twofour@servedby.onlinemediadiva[2].txt
C:\Documents and Settings\TwoFour\Cookies\twofour@server.iad.liveperson[2].txt
C:\Documents and Settings\TwoFour\Cookies\twofour@server.iad.liveperson[3].txt
C:\Documents and Settings\TwoFour\Cookies\twofour@serving.adsrevenue.clicksor[1].txt
C:\Documents and Settings\TwoFour\Cookies\twofour@serw.clicksor[2].txt
C:\Documents and Settings\TwoFour\Cookies\twofour@sexandsubmission[2].txt
C:\Documents and Settings\TwoFour\Cookies\twofour@specificclick[2].txt
C:\Documents and Settings\TwoFour\Cookies\twofour@specificmedia[2].txt
C:\Documents and Settings\TwoFour\Cookies\twofour@stats.adbrite[1].txt
C:\Documents and Settings\TwoFour\Cookies\twofour@stopzilla[1].txt
C:\Documents and Settings\TwoFour\Cookies\twofour@surfaccuracy[1].txt
C:\Documents and Settings\TwoFour\Cookies\twofour@technoratimedia[1].txt
C:\Documents and Settings\TwoFour\Cookies\twofour@thunderbolt.adjuggler[2].txt
C:\Documents and Settings\TwoFour\Cookies\twofour@toseeka[2].txt
C:\Documents and Settings\TwoFour\Cookies\twofour@trafficmp[2].txt
C:\Documents and Settings\TwoFour\Cookies\twofour@videoegg.adbureau[1].txt
C:\Documents and Settings\TwoFour\Cookies\twofour@waterfrontmedia.112.2o7[1].txt
C:\Documents and Settings\TwoFour\Cookies\twofour@windowsmedia[2].txt
C:\Documents and Settings\TwoFour\Cookies\twofour@www.adtrak[2].txt
C:\Documents and Settings\TwoFour\Cookies\twofour@www.advertising365[2].txt
C:\Documents and Settings\TwoFour\Cookies\twofour@www.advertyz[2].txt
C:\Documents and Settings\TwoFour\Cookies\twofour@www.burstbeacon[1].txt
C:\Documents and Settings\TwoFour\Cookies\twofour@www.burstnet[1].txt
C:\Documents and Settings\TwoFour\Cookies\twofour@www.clicksmart[1].txt
C:\Documents and Settings\TwoFour\Cookies\twofour@www.ebannerz[2].txt
C:\Documents and Settings\TwoFour\Cookies\twofour@www.findit-quick[2].txt
C:\Documents and Settings\TwoFour\Cookies\twofour@www.findstuff[1].txt
C:\Documents and Settings\TwoFour\Cookies\twofour@www.goaltraffic[1].txt
C:\Documents and Settings\TwoFour\Cookies\twofour@www.halstats[1].txt
C:\Documents and Settings\TwoFour\Cookies\twofour@www.icityfind[1].txt
C:\Documents and Settings\TwoFour\Cookies\twofour@www.incentaclick[2].txt
C:\Documents and Settings\TwoFour\Cookies\twofour@www.jackpotmadness[1].txt
C:\Documents and Settings\TwoFour\Cookies\twofour@www.mediatraffic[1].txt
C:\Documents and Settings\TwoFour\Cookies\twofour@www.pro-advertise[2].txt
C:\Documents and Settings\TwoFour\Cookies\twofour@www.riverbelle[1].txt
C:\Documents and Settings\TwoFour\Cookies\twofour@www.search4clicks[1].txt
C:\Documents and Settings\TwoFour\Cookies\twofour@www.sexandsubmission[1].txt
C:\Documents and Settings\TwoFour\Cookies\twofour@www.stopzilla[1].txt
C:\Documents and Settings\TwoFour\Cookies\twofour@www.toseeka[1].txt
C:\Documents and Settings\TwoFour\Cookies\twofour@xml.trafficengine[2].txt
C:\Documents and Settings\TwoFour\Cookies\twofour@yx0banners[2].txt
Trojan.ZenoSearch
C:\WINDOWS\system32\msnav32.ax
Adware.Adservs
C:\WINDOWS\system32\atmtd.dll._
Adware.Web Buying
HKU\.DEFAULT\Software\WebBuying
HKU\S-1-5-18\Software\WebBuying
Adware.Unclassified/Spruce
HKU\.DEFAULT\Software\Spruce
HKU\S-1-5-18\Software\Spruce
RootKit.TnCore/Trace
C:\WINDOWS\system32\drivers\core.cache.dsk
Rogue.Installer/Trace
C:\WINDOWS\Spyware Remover.ico
C:\WINDOWS\Casino.ico
C:\WINDOWS\Free Online Dating.ico
Adware.JavaCore/NoDNS
C:\WINDOWS\system32\cs.dat
C:\WINDOWS\system32\ps1.dat
C:\WINDOWS\system32\rc.dat
Rogue.Component/Trace
HKLM\Software\Microsoft\2C64EE46
HKLM\Software\Microsoft\2C64EE46#2c64ee46
HKLM\Software\Microsoft\2C64EE46#Version
HKLM\Software\Microsoft\2C64EE46#2c6443c6
HKLM\Software\Microsoft\2C64EE46#2c642a23
Adware.k8l
C:\DOCUMENTS AND SETTINGS\TWOFOUR\LOCAL SETTINGS\TEMPORARY INTERNET FILES\CONTENT.IE5\LQ2DGQ97\ACTDKPUBID72[1].HTM
C:\PROGRAM FILES\WINDOWS NT\CEVEPRU.HTML
Adware.Vundo/Variant-Trace
C:\WINDOWS\SYSTEM32\ACRSMNNP.INI
C:\WINDOWS\SYSTEM32\AWTXKKVN.INI
C:\WINDOWS\SYSTEM32\BVJLEEXN.INI
C:\WINDOWS\SYSTEM32\DHFAIGCM.INI
C:\WINDOWS\SYSTEM32\EBTXLMNG.INI
C:\WINDOWS\SYSTEM32\FKBVIRYM.INI
C:\WINDOWS\SYSTEM32\FXMTWLIC.INI
C:\WINDOWS\SYSTEM32\GKNNERUE.INI
C:\WINDOWS\SYSTEM32\QMJWWVEH.INI
C:\WINDOWS\SYSTEM32\QUHMILII.INI
C:\WINDOWS\SYSTEM32\TKUYMMFE.INI
C:\WINDOWS\SYSTEM32\UULPTJPV.INI
C:\WINDOWS\SYSTEM32\VWSHPELN.INI
Trojan.Agent/Gen-<NAME>
C:\WINDOWS\SYSTEM32\DLLCACHE\WINHELP.EXE
C:\WINDOWS\WINHELP.EXE
Adware.Vundo Variant/Rel
C:\WINDOWS\SYSTEM32\MCRH.TMP
C:\WINDOWS\SYSTEM32\ORQSS.INI
C:\WINDOWS\SYSTEM32\ORQSS.INI2
Trojan.Unknown Origin
C:\WINDOWS\SYSTEM32\WAPIISV.EXE
C:\WINDOWS\UNIST1.HTM
Trojan.Downloader-Gen
C:\WINDOWS\SYSTEM32\WINPFZ32.SYS
Adware.Unknown Origin
C:\WINDOWS\SYSTEM32\ZXDNT3D.CFG
Unclassified.Unknown Origin/System
C:\WINDOWS\UNINST2.HTM
The Malwarebytes log post is:
Malwarebytes' Anti-Malware 1.39
Database version: 2546
Windows 5.1.2600 Service Pack 2
10/6/2009 7:08:16 PM
mbam-log-2009-10-06 (19-08-16).txt
Scan type: Quick Scan
Objects scanned: 180280
Time elapsed: 1 hour(s), 32 minute(s), 58 second(s)
Memory Processes Infected: 0
Memory Modules Infected: 0
Registry Keys Infected: 0
Registry Values Infected: 0
Registry Data Items Infected: 0
Folders Infected: 1
Files Infected: 52
Memory Processes Infected:
(No malicious items detected)
Memory Modules Infected:
(No malicious items detected)
Registry Keys Infected:
(No malicious items detected)
Registry Values Infected:
(No malicious items detected)
Registry Data Items Infected:
(No malicious items detected)
Folders Infected:
C:\Program Files\WinAble (Trojan.Adloader) -> Not selected for removal.
Files Infected:
c:\WINDOWS\system32\cont_globaladsolution-remove.exe (Adware.Agent) -> Not selected for removal.
C:\WINDOWS\system32\bb1.dat (Trojan.Agent) -> Not selected for removal.
C:\WINDOWS\system32\pac.txt (Malware.Trace) -> Not selected for removal.
C:\WINDOWS\system32\din.ip (Malware.Trace) -> Not selected for removal.
C:\WINDOWS\system32\alog.txt (Stolen.data) -> Not selected for removal.
C:\WINDOWS\system32\drivers\blank.gif (Malware.Trace) -> Not selected for removal.
C:\WINDOWS\system32\drivers\box_2.gif (Malware.Trace) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\drivers\button_buynow.gif (Malware.Trace) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\drivers\button_freescan.gif (Malware.Trace) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\drivers\cell_bg.gif (Malware.Trace) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\drivers\cell_footer.gif (Malware.Trace) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\drivers\cell_header_block.gif (Malware.Trace) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\drivers\cell_header_remove.gif (Malware.Trace) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\drivers\cell_header_scan.gif (Malware.Trace) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\drivers\detect.htm (Malware.Trace) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\drivers\download_btn.jpg (Malware.Trace) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\drivers\download_now_btn.gif (Malware.Trace) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\drivers\footer_back.jpg (Malware.Trace) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\drivers\header_1.gif (Malware.Trace) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\drivers\header_2.gif (Malware.Trace) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\drivers\header_3.gif (Malware.Trace) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\drivers\header_4.gif (Malware.Trace) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\drivers\header_red_bg.gif (Malware.Trace) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\drivers\header_red_free_scan.gif (Malware.Trace) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\drivers\header_red_free_scan_bg.gif (Malware.Trace) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\drivers\header_red_protect_your_pc.gif (Malware.Trace) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\drivers\infected.gif (Malware.Trace) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\drivers\main_back.gif (Malware.Trace) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\drivers\product_2_header.gif (Malware.Trace) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\drivers\product_2_name_small.gif (Malware.Trace) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\drivers\product_features.gif (Malware.Trace) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\drivers\pt.htm (Malware.Trace) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\drivers\rating.gif (Malware.Trace) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\drivers\s_detect.htm (Malware.Trace) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\drivers\screenshot.jpg (Malware.Trace) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\drivers\sep_hor.gif (Malware.Trace) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\drivers\sep_vert.gif (Malware.Trace) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\drivers\shadow.jpg (Malware.Trace) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\drivers\shadow_bg.gif (Malware.Trace) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\drivers\spacer.gif (Malware.Trace) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\drivers\star.gif (Malware.Trace) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\drivers\star_gray.gif (Malware.Trace) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\drivers\star_gray_small.gif (Malware.Trace) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\drivers\star_small.gif (Malware.Trace) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\drivers\style.css (Malware.Trace) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\drivers\v.gif (Malware.Trace) -> Not selected for removal.
C:\WINDOWS\system32\drivers\warning_icon.gif (Malware.Trace) -> Not selected for removal.
C:\WINDOWS\system32\drivers\win_logo.gif (Malware.Trace) -> Not selected for removal.
C:\WINDOWS\system32\drivers\x.gif (Malware.Trace) -> Not selected for removal.
C:\WINDOWS\system32\sznf.ascii (Fake.Dropped.Malware) -> Not selected for removal.
C:\WINDOWS\system32\dpqaqlqx.bin (Fake.Dropped.Malware) -> Not selected for removal.
C:\WINDOWS\system32\jpewocmz.ini (Fake.Dropped.Malware) -> Not selected for removal.