SUPERAntiSpyware Scan Log
http://www.superantispyware.com
Generated 11/12/2007 at 09:28 PM
Application Version : 3.9.1008
Core Rules Database Version : 3342
Trace Rules Database Version: 1343
Scan type : Complete Scan
Total Scan Time : 01:14:55
Memory items scanned : 519
Memory threats detected : 0
Registry items scanned : 4986
Registry threats detected : 79
File items scanned : 23430
File threats detected : 51
Trojan.Smitfraud Variant
HKLM\Software\Classes\CLSID\{1977ce08-a38f-43db-a856-f4aa6122131b}
HKCR\CLSID\{1977CE08-A38F-43DB-A856-F4AA6122131B}
HKCR\CLSID\{1977CE08-A38F-43DB-A856-F4AA6122131B}\InProcServer32
HKCR\CLSID\{1977CE08-A38F-43DB-A856-F4AA6122131B}\InProcServer32#ThreadingModel
C:\WINDOWS\SYSTEM32\XOVDZZ.DLL
HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\SharedTaskScheduler#{1977ce08-a38f-43db-a856-f4aa6122131b}
Trojan.Media-Codec/V4
HKLM\Software\Classes\CLSID\{43BF8E0C-886D-4103-8DDB-2DFE0E8A0168}
HKCR\CLSID\{43BF8E0C-886D-4103-8DDB-2DFE0E8A0168}
HKCR\CLSID\{43BF8E0C-886D-4103-8DDB-2DFE0E8A0168}\InprocServer32
HKCR\CLSID\{43BF8E0C-886D-4103-8DDB-2DFE0E8A0168}\InprocServer32#ThreadingModel
C:\PROGRAM FILES\VIDEO ADD-ON\ISFMDL.DLL
HKLM\Software\Classes\CLSID\{6CA49FDD-4AEB-4F08-A394-C0A1F82CAA16}
HKCR\CLSID\{6CA49FDD-4AEB-4F08-A394-C0A1F82CAA16}
HKCR\CLSID\{6CA49FDD-4AEB-4F08-A394-C0A1F82CAA16}
HKCR\CLSID\{6CA49FDD-4AEB-4F08-A394-C0A1F82CAA16}\Implemented Categories
HKCR\CLSID\{6CA49FDD-4AEB-4F08-A394-C0A1F82CAA16}\Implemented Categories\{00021493-0000-0000-C000-000000000046}
HKCR\CLSID\{6CA49FDD-4AEB-4F08-A394-C0A1F82CAA16}\InprocServer32
HKCR\CLSID\{6CA49FDD-4AEB-4F08-A394-C0A1F82CAA16}\InprocServer32#ThreadingModel
C:\PROGRAM FILES\VIDEO ADD-ON\ICTMDL.DLL
HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{43BF8E0C-886D-4103-8DDB-2DFE0E8A0168}
HKLM\Software\Microsoft\Internet Explorer\Toolbar#{6CA49FDD-4AEB-4F08-A394-C0A1F82CAA16}
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\explorer\run#some [ C:\Program Files\Video Add-on\icthis.exe ]
C:\Program Files\Video Add-on\ot.ico
C:\Program Files\Video Add-on\ts.ico
C:\Program Files\Video Add-on\uninst.exe
C:\Program Files\Video Add-on
HKU\S-1-5-21-1214440339-854245398-1957994488-1003\Software\Online Add-on
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\IE Custom Tools
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\IE Custom Tools#DisplayName
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\IE Custom Tools#UninstallString
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\IE Safety Features
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\IE Safety Features#DisplayName
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\IE Safety Features#UninstallString
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Information Center
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Information Center#DisplayName
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Information Center#UninstallString
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Audio-Video Enhance
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Audio-Video Enhance#ProductionEnvironment
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Audio-Video Enhance#DisplayName
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Audio-Video Enhance#Publisher
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Audio-Video Enhance#UninstallString
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Audio-Video Enhance#DisplayIcon
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Audio-Video Enhance#DisplayVersion
Malware.LocusSoftware Inc/BestSellerAntivirus
HKLM\Software\Classes\CLSID\{FAAD2038-C371-473d-86F1-5B11D39C3775}
HKCR\CLSID\{FAAD2038-C371-473D-86F1-5B11D39C3775}
HKCR\CLSID\{FAAD2038-C371-473D-86F1-5B11D39C3775}
HKCR\CLSID\{FAAD2038-C371-473D-86F1-5B11D39C3775}#AppID
HKCR\CLSID\{FAAD2038-C371-473D-86F1-5B11D39C3775}\InprocServer32
HKCR\CLSID\{FAAD2038-C371-473D-86F1-5B11D39C3775}\InprocServer32#ThreadingModel
HKCR\CLSID\{FAAD2038-C371-473D-86F1-5B11D39C3775}\ProgID
HKCR\CLSID\{FAAD2038-C371-473D-86F1-5B11D39C3775}\Programmable
HKCR\CLSID\{FAAD2038-C371-473D-86F1-5B11D39C3775}\TypeLib
HKCR\CLSID\{FAAD2038-C371-473D-86F1-5B11D39C3775}\VersionIndependentProgID
C:\PROGRAM FILES\WINSPYCONTROL\TOOLS\IEFWBHO.DLL
HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{FAAD2038-C371-473D-86F1-5B11D39C3775}
HKCR\AVIEBHO.IEFW
HKCR\AVIEBHO.IEFW\CLSID
HKCR\AVIEBHO.IEFW\CurVer
HKCR\AVIEBHO.IEFW.2
HKCR\AVIEBHO.IEFW.2\CLSID
HKCR\TypeLib\{D731A77D-A816-4730-96D2-14A5F9917255}
HKCR\TypeLib\{D731A77D-A816-4730-96D2-14A5F9917255}\1.0
HKCR\TypeLib\{D731A77D-A816-4730-96D2-14A5F9917255}\1.0\0
HKCR\TypeLib\{D731A77D-A816-4730-96D2-14A5F9917255}\1.0\0\win32
HKCR\TypeLib\{D731A77D-A816-4730-96D2-14A5F9917255}\1.0\FLAGS
HKCR\TypeLib\{D731A77D-A816-4730-96D2-14A5F9917255}\1.0\HELPDIR
HKLM\Software\uga6pcw
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\UAVIEN_is1
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\UAVIEN_is1#Inno Setup: Setup Version
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\UAVIEN_is1#Inno Setup: App Path
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\UAVIEN_is1#InstallLocation
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\UAVIEN_is1#Inno Setup: Icon Group
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\UAVIEN_is1#Inno Setup: User
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\UAVIEN_is1#Inno Setup: Selected Tasks
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\UAVIEN_is1#Inno Setup: Deselected Tasks
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\UAVIEN_is1#DisplayName
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\UAVIEN_is1#UninstallString
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\UAVIEN_is1#QuietUninstallString
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\UAVIEN_is1#NoModify
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\UAVIEN_is1#NoRepair
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\UAVIEN_is1#InstallDate
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\UAVIEN_is1#InstallPath
Adware.Tracking Cookie
C:\Documents and Settings\JA\Cookies\ja@2o7[1].txt
C:\Documents and Settings\JA\Cookies\ja@atdmt[2].txt
C:\Documents and Settings\JA\Cookies\ja@stat.dealtime[2].txt
C:\Documents and Settings\JA\Cookies\ja@revsci[1].txt
C:\Documents and Settings\JA\Cookies\ja@atwola[1].txt
C:\Documents and Settings\JA\Cookies\ja@toplist[1].txt
C:\Documents and Settings\JA\Cookies\ja@toplist[2].txt
C:\Documents and Settings\JA\Cookies\ja@adrenaline[1].txt
C:\Documents and Settings\JA\Cookies\ja@please[1].txt
C:\Documents and Settings\JA\Cookies\ja@nextag[2].txt
C:\Documents and Settings\JA\Cookies\ja@ads.pointroll[1].txt
C:\Documents and Settings\JA\Cookies\ja@doubleclick[1].txt
C:\Documents and Settings\JA\Cookies\ja@rambler[1].txt
C:\Documents and Settings\JA\Cookies\ja@please[4].txt
C:\Documents and Settings\JA\Cookies\ja@shopping.112.2o7[1].txt
C:\Documents and Settings\JA\Cookies\ja@please[2].txt
C:\Documents and Settings\JA\Cookies\ja@e-2dj6wflykidpsaq.stats.esomniture[2].txt
C:\Documents and Settings\JA\Cookies\ja@www.viruslocker[1].txt
C:\Documents and Settings\JA\Cookies\ja@winpcdoctor[2].txt
Trojan.Security Toolbar
C:\Documents and Settings\All Users\Start Menu\Online Security Guide.url
C:\Documents and Settings\All Users\Start Menu\Security Troubleshooting.url
Trojan.Media-Codec
HKCR\VideoAXObject.Chl
HKCR\VideoAXObject.Chl\CLSID
Malware.SpyLocked
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Windows Safety Alert
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Windows Safety Alert#DisplayName
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Windows Safety Alert#UninstallString
Browser Hijacker.Favorites
C:\DOCUMENTS AND SETTINGS\JA\FAVORITES\ONLINE SECURITY TEST.URL
Trace.Known Threat Sources
C:\Documents and Settings\JA\Local Settings\Temporary Internet Files\Content.IE5\0JKL45OP\shield[1].gif
C:\Documents and Settings\JA\Local Settings\Temporary Internet Files\Content.IE5\K16FW1IB\tune[1].gif
C:\Documents and Settings\JA\Local Settings\Temporary Internet Files\Content.IE5\M5UJ89AZ\_popup[1].js
C:\Documents and Settings\JA\Local Settings\Temporary Internet Files\Content.IE5\M5UJ89AZ\topbg[1].gif
C:\Documents and Settings\JA\Local Settings\Temporary Internet Files\Content.IE5\KXEVCLU3\08-z14ykr[1].htm
C:\Documents and Settings\JA\Local Settings\Temporary Internet Files\Content.IE5\KXEVCLU3\logo[1].gif
C:\Documents and Settings\JA\Local Settings\Temporary Internet Files\Content.IE5\85Y3W1QN\back[1].gif
C:\Documents and Settings\JA\Local Settings\Temporary Internet Files\Content.IE5\W3YB07WF\continue[1].gif
C:\Documents and Settings\JA\Local Settings\Temporary Internet Files\Content.IE5\W3YB07WF\popup[1].js
C:\Documents and Settings\JA\Local Settings\Temporary Internet Files\Content.IE5\0JKL45OP\check[1].gif
C:\Documents and Settings\JA\Local Settings\Temporary Internet Files\Content.IE5\K16FW1IB\graph[1].gif
C:\Documents and Settings\JA\Local Settings\Temporary Internet Files\Content.IE5\8HG1URG9\bar[1].gif
C:\Documents and Settings\JA\Local Settings\Temporary Internet Files\Content.IE5\0JKL45OP\logo[1].jpg
C:\Documents and Settings\JA\Local Settings\Temporary Internet Files\Content.IE5\KXEVCLU3\06-60wia2[1].htm
C:\Documents and Settings\JA\Local Settings\Temporary Internet Files\Content.IE5\0JKL45OP\popup[1].js
C:\Documents and Settings\JA\Local Settings\Temporary Internet Files\Content.IE5\KXEVCLU3\07-5ojme4[1].htm
C:\Documents and Settings\JA\Local Settings\Temporary Internet Files\Content.IE5\KHM3G1UR\main_right[1].jpg
C:\Documents and Settings\JA\Local Settings\Temporary Internet Files\Content.IE5\M5UJ89AZ\pre[1].js
C:\Documents and Settings\JA\Local Settings\Temporary Internet Files\Content.IE5\W3YB07WF\pc[1].gif
C:\Documents and Settings\JA\Local Settings\Temporary Internet Files\Content.IE5\K16FW1IB\clean[1].gif
C:\Documents and Settings\JA\Local Settings\Temporary Internet Files\Content.IE5\8HG1URG9\download[1].gif