I’ll be back with the other stuff later
SUPERAntiSpyware Scan Log
http://www.superantispyware.com

Generated 12/03/2007 at 09:40 PM

Application Version : 3.9.1008

Core Rules Database Version : 3354
Trace Rules Database Version: 1352

Scan type : Complete Scan
Total Scan Time : 01:11:02

Memory items scanned : 168
Memory threats detected : 0
Registry items scanned : 5992
Registry threats detected : 35
File items scanned : 32818
File threats detected : 40

Unclassified.Unknown Origin
HKLM\Software\Classes\CLSID{85B2F289-7128-4C5A-A330-F9FC01432D3A}
HKCR\CLSID{85B2F289-7128-4C5A-A330-F9FC01432D3A}
HKCR\CLSID{85B2F289-7128-4C5A-A330-F9FC01432D3A}
HKCR\CLSID{85B2F289-7128-4C5A-A330-F9FC01432D3A}\InprocServer32
HKCR\CLSID{85B2F289-7128-4C5A-A330-F9FC01432D3A}\InprocServer32#ThreadingModel
HKCR\CLSID{85B2F289-7128-4C5A-A330-F9FC01432D3A}\ProgID
HKCR\CLSID{85B2F289-7128-4C5A-A330-F9FC01432D3A}\Programmable
HKCR\CLSID{85B2F289-7128-4C5A-A330-F9FC01432D3A}\TypeLib
HKCR\CLSID{85B2F289-7128-4C5A-A330-F9FC01432D3A}\VersionIndependentProgID
C:\WINDOWS\HDTIP.DLL
HKLM\Software\Classes\CLSID{A477EBE4-ABE9-4A9D-B1B4-0EB1D0D025CE}
HKCR\CLSID{A477EBE4-ABE9-4A9D-B1B4-0EB1D0D025CE}
HKCR\CLSID{A477EBE4-ABE9-4A9D-B1B4-0EB1D0D025CE}
HKCR\CLSID{A477EBE4-ABE9-4A9D-B1B4-0EB1D0D025CE}\InprocServer32
HKCR\CLSID{A477EBE4-ABE9-4A9D-B1B4-0EB1D0D025CE}\InprocServer32#ThreadingModel
HKCR\CLSID{A477EBE4-ABE9-4A9D-B1B4-0EB1D0D025CE}\ProgID
HKCR\CLSID{A477EBE4-ABE9-4A9D-B1B4-0EB1D0D025CE}\Programmable
HKCR\CLSID{A477EBE4-ABE9-4A9D-B1B4-0EB1D0D025CE}\TypeLib
HKCR\CLSID{A477EBE4-ABE9-4A9D-B1B4-0EB1D0D025CE}\VersionIndependentProgID
C:\WINDOWS\WERBETDQW.DLL
HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects{A477EBE4-ABE9-4A9D-B1B4-0EB1D0D025CE}
HKLM\Software\Microsoft\Internet Explorer\Toolbar#{85B2F289-7128-4C5A-A330-F9FC01432D3A}
HKCR\hdtip.ToolBar.1
HKCR\hdtip.ToolBar.1\CLSID
HKCR\hdtip.ToolBar
HKCR\TypeLib{AE73C3E4-88F7-41A0-AF79-87BE6826B8DF}
HKCR\TypeLib{AE73C3E4-88F7-41A0-AF79-87BE6826B8DF}\1.0
HKCR\TypeLib{AE73C3E4-88F7-41A0-AF79-87BE6826B8DF}\1.0\0
HKCR\TypeLib{AE73C3E4-88F7-41A0-AF79-87BE6826B8DF}\1.0\0\win32
HKCR\TypeLib{AE73C3E4-88F7-41A0-AF79-87BE6826B8DF}\1.0\FLAGS
HKCR\TypeLib{AE73C3E4-88F7-41A0-AF79-87BE6826B8DF}\1.0\HELPDIR

Adware.Tracking Cookie
c:\documents and settings\carol\cookies\carol@media.adrevolver[1].txt
c:\documents and settings\carol\cookies\carol@ad.yieldmanager[1].txt
c:\documents and settings\carol\cookies\carol@atdmt[2].txt
c:\documents and settings\carol\cookies\carol@advertising[2].txt
c:\documents and settings\carol\cookies\carol@msnportal.112.2o7[1].txt
c:\documents and settings\carol\cookies\carol@fastclick[2].txt
c:\documents and settings\carol\cookies\carol@ads.techguy[1].txt
c:\documents and settings\carol\cookies\carol@questionmarket[1].txt
c:\documents and settings\carol\cookies\carol@mediaplex[2].txt
c:\documents and settings\carol\cookies\carol@hearstmagazines.112.2o7[1].txt
c:\documents and settings\carol\cookies\carol@interclick[2].txt
c:\documents and settings\carol\cookies\carol@media.adrevolver[2].txt
c:\documents and settings\carol\cookies\carol@statse.webtrendslive[2].txt
c:\documents and settings\carol\cookies\carol@statcounter[2].txt
c:\documents and settings\carol\cookies\carol@media.medhelp[2].txt
c:\documents and settings\carol\cookies\carol@ads.pointroll[1].txt
c:\documents and settings\carol\cookies\carol@doubleclick[1].txt
c:\documents and settings\carol\cookies\carol@adrevolver[1].txt
c:\documents and settings\carol\cookies\carol@medhelpinternational.112.2o7[1].txt
C:\Documents and Settings\Carol\Application Data\Earthlink\6.0\cph13@earthlink.net\Cookies\carol@2o7[1].txt
C:\Documents and Settings\Carol\Application Data\Earthlink\6.0\cph13@earthlink.net\Cookies\carol@ads.pointroll[2].txt
C:\Documents and Settings\Carol\Application Data\Earthlink\6.0\cph13@earthlink.net\Cookies\carol@advertising[1].txt
C:\Documents and Settings\Carol\Application Data\Earthlink\6.0\cph13@earthlink.net\Cookies\carol@atdmt[2].txt
C:\Documents and Settings\Carol\Application Data\Earthlink\6.0\cph13@earthlink.net\Cookies\carol@counter.hitslink[1].txt
C:\Documents and Settings\Carol\Application Data\Earthlink\6.0\cph13@earthlink.net\Cookies\carol@doubleclick[1].txt
C:\Documents and Settings\Carol\Application Data\Earthlink\6.0\cph13@earthlink.net\Cookies\carol@edge.ru4[1].txt
C:\Documents and Settings\Carol\Application Data\Earthlink\6.0\cph13@earthlink.net\Cookies\carol@mediaplex[1].txt
C:\Documents and Settings\Carol\Application Data\Earthlink\6.0\cph13@earthlink.net\Cookies\carol@questionmarket[1].txt
C:\Documents and Settings\Carol\Application Data\Earthlink\6.0\cph13@earthlink.net\Cookies\carol@sales.liveperson[1].txt
C:\Documents and Settings\Carol\Application Data\Earthlink\6.0\cph13@earthlink.net\Cookies\carol@servedby.advertising[1].txt

Trojan.Net-MSV/VPS
HKCR\MSVPS.MSVPSApp
HKCR\MSVPS.MSVPSApp\CLSID
HKCR\MSVPS.MSVPSApp\CurVer

Desktop Hijacker.AboutYourPrivacy
C:\WINDOWS\privacy_danger\images\capt.gif
C:\WINDOWS\privacy_danger\images\danger.jpg
C:\WINDOWS\privacy_danger\images\down.gif
C:\WINDOWS\privacy_danger\images\spacer.gif
C:\WINDOWS\privacy_danger\images
C:\WINDOWS\privacy_danger\index.htm
C:\WINDOWS\privacy_danger

Trojan.Downloader/NMC-Rich
C:\Program Files\RichVideoCodec

Trojan.Net-MU/Gen
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\WebVideo
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\WebVideo#DisplayName
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\WebVideo#uninstallString