# version=4
# OnlineScanner.ocx=1.0.0.56
# OnlineScannerDLLA.dll=1, 0, 0, 51
# OnlineScannerDLLW.dll=1, 0, 0, 51
# OnlineScannerUninstaller.exe=1, 0, 0, 49
# vers_standard_module=2818 (20080123)
# vers_arch_module=1.063 (20080117)
# vers_adv_heur_module=1.060 (20070601)
# EOSSerial=cdc7022d08b60441ad8501ec7a1df7f2
# end=finished
# remove_checked=false
# unwanted_checked=true
# utc_time=2008-01-24 08:41:51
# local_time=2008-01-24 02:41:51 (-0600, Central Standard Time)
# country="United States"
# osver=6.0.6000 NT
# scanned=224586
# found=5
# scan_time=11056
C:\Users\David\AppData\Local\Temp\cadfbfno.dll Win32/Adware.SecToolbar application 626FCED4B1DD2CC3A69EEAC6D56155A0
C:\Users\David\AppData\Local\Temp\cfrdhjjc.dll Win32/Adware.SecToolbar application 626FCED4B1DD2CC3A69EEAC6D56155A0
C:\Users\David\AppData\Local\Temp\hggff.dll Win32/Adware.Virtumonde.FP application 2B7DCCCFDAEB602C2522DC7C887C2B7F
C:\Users\David\AppData\Local\Temp\qqfpbuaq.dll Win32/BHO.G trojan 4AE3EC97E1855CDFF6D903225D99D7DC
C:\Users\David\AppData\Local\Temp\yuvswiij.dll Win32/BHO.G trojan 4AE3EC97E1855CDFF6D903225D99D7DC
_______________________________________
_________________-
SUPERAntiSpyware Scan Log
http://www.superantispyware.comGenerated 01/24/2008 at 05:17 PM
Application Version : 3.9.1008
Core Rules Database Version : 3387
Trace Rules Database Version: 1381
Scan type : Complete Scan
Total Scan Time : 00:59:13
Memory items scanned : 217
Memory threats detected : 0
Registry items scanned : 6857
Registry threats detected : 8
File items scanned : 66796
File threats detected : 78
Adware.Vundo-Variant/Small-A
HKLM\Software\Classes\CLSID\{52ceea54-971a-4e96-8c00-ded0c2a4c227}
HKCR\CLSID\{52CEEA54-971A-4E96-8C00-DED0C2A4C227}
HKCR\CLSID\{52CEEA54-971A-4E96-8C00-DED0C2A4C227}\InprocServer32
HKCR\CLSID\{52CEEA54-971A-4E96-8C00-DED0C2A4C227}\InprocServer32#ThreadingModel
C:\USERS\DAVID\APPDATA\LOCAL\TEMP\YUVSWIIJ.DLL
HKLM\Software\Classes\CLSID\{f4b408fa-c91d-45b5-99ef-d5e2470856d5}
HKCR\CLSID\{F4B408FA-C91D-45B5-99EF-D5E2470856D5}
HKCR\CLSID\{F4B408FA-C91D-45B5-99EF-D5E2470856D5}\InprocServer32
HKCR\CLSID\{F4B408FA-C91D-45B5-99EF-D5E2470856D5}\InprocServer32#ThreadingModel
C:\USERS\DAVID\APPDATA\LOCAL\TEMP\QQFPBUAQ.DLL
C:\USERS\DAVID\APPDATA\LOCAL\TEMP\APOOTQRQ.DLL
C:\USERS\DAVID\APPDATA\LOCAL\TEMP\FUTMXOYI.DLL
C:\USERS\DAVID\APPDATA\LOCAL\TEMP\NNEVCULF.DLL
Adware.Tracking Cookie
C:\Users\David\AppData\Roaming\Microsoft\Windows\Cookies\
[email protected][1].txt
C:\Users\David\AppData\Roaming\Microsoft\Windows\Cookies\
[email protected][1].txt
C:\Users\David\AppData\Roaming\Microsoft\Windows\Cookies\david@mediaplex[2].txt
C:\Users\David\AppData\Roaming\Microsoft\Windows\Cookies\david@2o7[1].txt
C:\Users\David\AppData\Roaming\Microsoft\Windows\Cookies\
[email protected][1].txt
C:\Users\David\AppData\Roaming\Microsoft\Windows\Cookies\david@advertising[2].txt
C:\Users\David\AppData\Roaming\Microsoft\Windows\Cookies\david@atdmt[1].txt
C:\Users\David\AppData\Roaming\Microsoft\Windows\Cookies\david@hitbox[2].txt
C:\Users\David\AppData\Roaming\Microsoft\Windows\Cookies\david@doubleclick[1].txt
C:\Users\David\AppData\Roaming\Microsoft\Windows\Cookies\david@atwola[1].txt
C:\Users\David\AppData\Roaming\Microsoft\Windows\Cookies\david@revsci[1].txt
C:\Users\David\AppData\Roaming\Microsoft\Windows\Cookies\
[email protected][1].txt
C:\Users\David\AppData\Roaming\Microsoft\Windows\Cookies\Low\david@2o7[2].txt
C:\Users\David\AppData\Roaming\Microsoft\Windows\Cookies\Low\
[email protected][1].txt
C:\Users\David\AppData\Roaming\Microsoft\Windows\Cookies\Low\
[email protected][1].txt
C:\Users\David\AppData\Roaming\Microsoft\Windows\Cookies\Low\david@adbrite[2].txt
C:\Users\David\AppData\Roaming\Microsoft\Windows\Cookies\Low\
[email protected][1].txt
C:\Users\David\AppData\Roaming\Microsoft\Windows\Cookies\Low\david@adrevolver[1].txt
C:\Users\David\AppData\Roaming\Microsoft\Windows\Cookies\Low\david@adrevolver[3].txt
C:\Users\David\AppData\Roaming\Microsoft\Windows\Cookies\Low\
[email protected][1].txt
C:\Users\David\AppData\Roaming\Microsoft\Windows\Cookies\Low\
[email protected][2].txt
C:\Users\David\AppData\Roaming\Microsoft\Windows\Cookies\Low\
[email protected][1].txt
C:\Users\David\AppData\Roaming\Microsoft\Windows\Cookies\Low\
[email protected][1].txt
C:\Users\David\AppData\Roaming\Microsoft\Windows\Cookies\Low\david@adultadworld[2].txt
C:\Users\David\AppData\Roaming\Microsoft\Windows\Cookies\Low\david@amsterdamlivexxx[1].txt
C:\Users\David\AppData\Roaming\Microsoft\Windows\Cookies\Low\david@babblesex[2].txt
C:\Users\David\AppData\Roaming\Microsoft\Windows\Cookies\Low\david@babblesex[3].txt
C:\Users\David\AppData\Roaming\Microsoft\Windows\Cookies\Low\
[email protected][2].txt
C:\Users\David\AppData\Roaming\Microsoft\Windows\Cookies\Low\david@dinowarez[1].txt
C:\Users\David\AppData\Roaming\Microsoft\Windows\Cookies\Low\david@dinowarez[2].txt
C:\Users\David\AppData\Roaming\Microsoft\Windows\Cookies\Low\david@doubleclick[1].txt
C:\Users\David\AppData\Roaming\Microsoft\Windows\Cookies\Low\david@doubleclick[2].txt
C:\Users\David\AppData\Roaming\Microsoft\Windows\Cookies\Low\david@doubleclick[3].txt
C:\Users\David\AppData\Roaming\Microsoft\Windows\Cookies\Low\
[email protected][1].txt
C:\Users\David\AppData\Roaming\Microsoft\Windows\Cookies\Low\
[email protected][1].txt
C:\Users\David\AppData\Roaming\Microsoft\Windows\Cookies\Low\david@fastclick[1].txt
C:\Users\David\AppData\Roaming\Microsoft\Windows\Cookies\Low\david@hitbox[1].txt
C:\Users\David\AppData\Roaming\Microsoft\Windows\Cookies\Low\david@hornymatches[1].txt
C:\Users\David\AppData\Roaming\Microsoft\Windows\Cookies\Low\
[email protected][1].txt
C:\Users\David\AppData\Roaming\Microsoft\Windows\Cookies\Low\
[email protected][1].txt
C:\Users\David\AppData\Roaming\Microsoft\Windows\Cookies\Low\
[email protected][1].txt
C:\Users\David\AppData\Roaming\Microsoft\Windows\Cookies\Low\
[email protected][2].txt
C:\Users\David\AppData\Roaming\Microsoft\Windows\Cookies\Low\
[email protected][3].txt
C:\Users\David\AppData\Roaming\Microsoft\Windows\Cookies\Low\
[email protected][4].txt
C:\Users\David\AppData\Roaming\Microsoft\Windows\Cookies\Low\david@mediaplex[1].txt
C:\Users\David\AppData\Roaming\Microsoft\Windows\Cookies\Low\david@mediaplex[2].txt
C:\Users\David\AppData\Roaming\Microsoft\Windows\Cookies\Low\david@oddcast[2].txt
C:\Users\David\AppData\Roaming\Microsoft\Windows\Cookies\Low\
[email protected][1].txt
C:\Users\David\AppData\Roaming\Microsoft\Windows\Cookies\Low\
[email protected][2].txt
C:\Users\David\AppData\Roaming\Microsoft\Windows\Cookies\Low\
[email protected][1].txt
C:\Users\David\AppData\Roaming\Microsoft\Windows\Cookies\Low\david@revsci[2].txt
C:\Users\David\AppData\Roaming\Microsoft\Windows\Cookies\Low\
[email protected][1].txt
C:\Users\David\AppData\Roaming\Microsoft\Windows\Cookies\Low\david@serving-sys[2].txt
C:\Users\David\AppData\Roaming\Microsoft\Windows\Cookies\Low\david@sextracker[2].txt
C:\Users\David\AppData\Roaming\Microsoft\Windows\Cookies\Low\david@specificclick[2].txt
C:\Users\David\AppData\Roaming\Microsoft\Windows\Cookies\Low\
[email protected][1].txt
C:\Users\David\AppData\Roaming\Microsoft\Windows\Cookies\Low\david@statsgod[1].txt
C:\Users\David\AppData\Roaming\Microsoft\Windows\Cookies\Low\
[email protected][1].txt
C:\Users\David\AppData\Roaming\Microsoft\Windows\Cookies\Low\david@tribalfusion[2].txt
C:\Users\David\AppData\Roaming\Microsoft\Windows\Cookies\Low\david@warezasaur[1].txt
C:\Users\David\AppData\Roaming\Microsoft\Windows\Cookies\Low\david@webpower[1].txt
C:\Users\David\AppData\Roaming\Microsoft\Windows\Cookies\Low\david@websexchat[1].txt
C:\Users\David\AppData\Roaming\Microsoft\Windows\Cookies\Low\david@worldsex[1].txt
C:\Users\David\AppData\Roaming\Microsoft\Windows\Cookies\Low\
[email protected][2].txt
C:\Users\David\AppData\Roaming\Microsoft\Windows\Cookies\Low\
[email protected][1].txt
C:\Users\David\AppData\Roaming\Microsoft\Windows\Cookies\Low\
[email protected][3].txt
C:\Users\David\AppData\Roaming\Microsoft\Windows\Cookies\Low\
[email protected][1].txt
C:\Users\David\AppData\Roaming\Microsoft\Windows\Cookies\Low\
[email protected][1].txt
C:\Users\David\AppData\Roaming\Microsoft\Windows\Cookies\Low\david@xiti[1].txt
C:\Users\David\AppData\Roaming\Microsoft\Windows\Cookies\Low\david@xxxcounter[1].txt
C:\Users\David\AppData\Roaming\Microsoft\Windows\Cookies\Low\david@zedo[2].txt
Trojan.Unclassifed/AffiliateBundle
C:\USERS\DAVID\APPDATA\LOCAL\TEMP\DDCYA.DLL
Adware.Vundo-Variant
C:\USERS\DAVID\APPDATA\LOCAL\TEMP\HGGFF.DLL
_______________________________________
_________________________________-