I lost the log for OTMoveIt2...
I'm still infected.
Now I can't open any folders.
SUPERAntiSpyware Scan Log
http://www.superantispyware.comGenerated 03/04/2008 at 10:23 AM
Application Version : 4.0.1154
Core Rules Database Version : 3413
Trace Rules Database Version: 1405
Scan type : Complete Scan
Total Scan Time : 00:38:17
Memory items scanned : 174
Memory threats detected : 2
Registry items scanned : 5626
Registry threats detected : 46OTMoveIt2
File items scanned : 74783
File threats detected : 74
Trojan.Unclassifed/AffiliateBundle
C:\WINDOWS\SYSTEM32\IIFFDDD.DLL
C:\WINDOWS\SYSTEM32\IIFFDDD.DLL
HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{ED120D76-BF31-412C-A99B-783C6676E128}
HKCR\CLSID\{ED120D76-BF31-412C-A99B-783C6676E128}
HKCR\CLSID\{ED120D76-BF31-412C-A99B-783C6676E128}\InprocServer32
HKCR\CLSID\{ED120D76-BF31-412C-A99B-783C6676E128}\InprocServer32#ThreadingModel
HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks#{ED120D76-BF31-412C-A99B-783C6676E128}
Software\Microsoft\Windows NT\CurrentVersion\WinLogon\Notify\iiffddd
C:\WINDOWS\SYSTEM32\VTUVTTS.DLL
Adware.Vundo Variant/Resident
C:\WINDOWS\SYSTEM32\VTSQO.DLL
C:\WINDOWS\SYSTEM32\VTSQO.DLL
Unclassified.Unknown Origin
HKLM\Software\Classes\CLSID\{11A69AE4-FBED-4832-A2BF-45AF82825583}
HKCR\CLSID\{11A69AE4-FBED-4832-A2BF-45AF82825583}
HKCR\CLSID\{11A69AE4-FBED-4832-A2BF-45AF82825583}
HKCR\CLSID\{11A69AE4-FBED-4832-A2BF-45AF82825583}\InprocServer32
HKCR\CLSID\{11A69AE4-FBED-4832-A2BF-45AF82825583}\InprocServer32#ThreadingModel
C:\WINDOWS\SYSTEM32\NJFXAETT.DLL
Adware.Vundo Variant
HKLM\Software\Classes\CLSID\{3538CEBC-7423-28A3-5713-2F00B6BDDDE9}
HKCR\CLSID\{3538CEBC-7423-28A3-5713-2F00B6BDDDE9}
HKCR\CLSID\{3538CEBC-7423-28A3-5713-2F00B6BDDDE9}\InprocServer32
HKCR\CLSID\{3538CEBC-7423-28A3-5713-2F00B6BDDDE9}\InprocServer32#ThreadingModel
HKCR\CLSID\{3538CEBC-7423-28A3-5713-2F00B6BDDDE9}\Programmable
HKCR\CLSID\{3538CEBC-7423-28A3-5713-2F00B6BDDDE9}\TypeLib
C:\WINDOWS\SYSTEM32\UAOPH.DLL
HKLM\Software\Classes\CLSID\{A88B113C-0E6E-49B1-8753-202C65FA7ADF}
HKCR\CLSID\{A88B113C-0E6E-49B1-8753-202C65FA7ADF}
HKCR\CLSID\{A88B113C-0E6E-49B1-8753-202C65FA7ADF}\InprocServer32
HKCR\CLSID\{A88B113C-0E6E-49B1-8753-202C65FA7ADF}\InprocServer32#ThreadingModel
HKLM\Software\Classes\CLSID\{A95B2816-1D7E-4561-A202-68C0DE02353A}
HKCR\CLSID\{A95B2816-1D7E-4561-A202-68C0DE02353A}
HKCR\CLSID\{A95B2816-1D7E-4561-A202-68C0DE02353A}\InprocServer32
HKCR\CLSID\{A95B2816-1D7E-4561-A202-68C0DE02353A}\InprocServer32#ThreadingModel
HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{3538CEBC-7423-28A3-5713-2F00B6BDDDE9}
HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{A88B113C-0E6E-49B1-8753-202C65FA7ADF}
HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{A95B2816-1D7E-4561-A202-68C0DE02353A}
HKCR\CLSID\{A95B2816-1D7E-4561-A202-68C0DE02353A}
Adware.Vundo-Variant/Small-A
HKLM\Software\Classes\CLSID\{3a436168-d86f-4510-b663-ab362acc0aa8}
HKCR\CLSID\{3A436168-D86F-4510-B663-AB362ACC0AA8}
HKCR\CLSID\{3A436168-D86F-4510-B663-AB362ACC0AA8}\InprocServer32
HKCR\CLSID\{3A436168-D86F-4510-B663-AB362ACC0AA8}\InprocServer32#ThreadingModel
C:\WINDOWS\SYSTEM32\IHOQQSTT.DLL
HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{3a436168-d86f-4510-b663-ab362acc0aa8}
C:\WINDOWS\SYSTEM32\HAJRKGIR.DLL
C:\WINDOWS\SYSTEM32\KXAHKXGG.DLL
C:\WINDOWS\SYSTEM32\MUQJTBCQ.DLL
Adware.Tracking Cookie
C:\Documents and Settings\Chris R\Cookies\chris r@avsystemcare[1].txt
C:\Documents and Settings\Chris R\Cookies\chris r@hornymatches[1].txt
C:\Documents and Settings\Chris R\Cookies\chris r@banner.nutspoker[2].txt
C:\Documents and Settings\Chris R\Cookies\chris r@webtraffic20[3].txt
C:\Documents and Settings\Chris R\Cookies\chris r@gomyhit[1].txt
C:\Documents and Settings\Chris R\Cookies\chris r@288_[3].txt
C:\Documents and Settings\Chris R\Cookies\chris r@ad.outerinfoads[3].txt
C:\Documents and Settings\Chris R\Cookies\chris r@angleinteractive.directtrack[1].txt
C:\Documents and Settings\Chris R\Cookies\chris r@banners.searchingbooth[2].txt
C:\Documents and Settings\Chris R\Cookies\chris r@burstnet[2].txt
C:\Documents and Settings\Chris R\Cookies\chris r@ex=5_[2].txt
C:\Documents and Settings\Chris R\Cookies\chris r@www.goldentigercasino[2].txt
C:\Documents and Settings\Chris R\Cookies\chris r@go[2].txt
C:\Documents and Settings\Chris R\Cookies\chris r@www.riverbelle[1].txt
C:\Documents and Settings\Chris R\Cookies\chris r@ads2.k8l[1].txt
C:\Documents and Settings\Chris R\Cookies\chris r@adsby.zwoops[1].txt
C:\Documents and Settings\Chris R\Cookies\chris r@www.levelclick[1].txt
C:\Documents and Settings\Chris R\Cookies\chris r@ads.k8l[1].txt
C:\Documents and Settings\Chris R\Cookies\chris r@288_[2].txt
C:\Documents and Settings\Chris R\Cookies\chris r@ads.domainsuite[1].txt
C:\Documents and Settings\Chris R\Cookies\chris r@ad.outerinfoads[2].txt
C:\Documents and Settings\Chris R\Cookies\chris r@adrevolver[1].txt
C:\Documents and Settings\Chris R\Cookies\chris r@ads.pointroll[1].txt
C:\Documents and Settings\Chris R\Cookies\chris r@ads3.think-adz[1].txt
C:\Documents and Settings\Chris R\Cookies\chris r@atdmt[2].txt
C:\Documents and Settings\Chris R\Cookies\chris r@atdmt[3].txt
C:\Documents and Settings\Chris R\Cookies\chris r@banners.searchingbooth[1].txt
C:\Documents and Settings\Chris R\Cookies\chris r@clicksfeed[1].txt
C:\Documents and Settings\Chris R\Cookies\chris r@collective-media[1].txt
C:\Documents and Settings\Chris R\Cookies\chris r@directtrack[1].txt
C:\Documents and Settings\Chris R\Cookies\chris r@fastclick[1].txt
C:\Documents and Settings\Chris R\Cookies\chris r@interclick[1].txt
C:\Documents and Settings\Chris R\Cookies\chris r@linksynergy[1].txt
C:\Documents and Settings\Chris R\Cookies\chris r@media.adrevolver[2].txt
C:\Documents and Settings\Chris R\Cookies\chris r@qnsr[1].txt
C:\Documents and Settings\Chris R\Cookies\chris r@questionmarket[1].txt
C:\Documents and Settings\Chris R\Cookies\chris r@realmedia[1].txt
C:\Documents and Settings\Chris R\Cookies\chris r@specificclick[1].txt
C:\Documents and Settings\Chris R\Cookies\chris r@webtraffic20[1].txt
C:\Documents and Settings\Chris R\Cookies\chris r@zedo[2].txt
C:\Documents and Settings\LocalService\Cookies\system@enhance[1].txt
Trojan.ZenoSearch
C:\WINDOWS\system32\msnav32.ax
Trojan.Unknown Origin
HKLM\Software\xpre
HKLM\Software\xpre#execount
C:\WINDOWS\Q2HYAXMGUG\KZ1VURG0O0.VBS
Adware.ClickSpring/Outer Info Network
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Outerinfo
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Outerinfo#DisplayVersion
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Outerinfo#UninstallString
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Outerinfo#DisplayName
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Outerinfo#NoModify
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Outerinfo#NoRepair
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Outerinfo#DisplayIcon
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Outerinfo#HelpLink
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Outerinfo#Publisher
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Outerinfo#InstallLocation
C:\Documents and Settings\Chris R\Start Menu\Programs\Outerinfo\Terms.lnk
C:\Documents and Settings\Chris R\Start Menu\Programs\Outerinfo\Uninstall.lnk
C:\Documents and Settings\Chris R\Start Menu\Programs\Outerinfo
Rogue.LocusSoftware-Installer
C:\DOCUMENTS AND SETTINGS\CHRIS R\LOCAL SETTINGS\TEMPORARY INTERNET FILES\CONTENT.IE5\R6N771J4\WINVSNET[1].EXE
Adware.Yazzle-Installer
C:\DOCUMENTS AND SETTINGS\CHRIS R\LOCAL SETTINGS\TEMPORARY INTERNET FILES\CONTENT.IE5\RT98WBY7\YAZZSNET[1].EXE
Adware.Rabio Search Enhancer
C:\WINDOWS\SYSTEM32\K8\RAVECOM3.EXE
Adware.Vundo Variant/Rel
C:\WINDOWS\SYSTEM32\MCRH.TMP
C:\WINDOWS\SYSTEM32\OQSTV.INI
C:\WINDOWS\SYSTEM32\OQSTV.INI2
Adware.Unknown Origin
C:\WINDOWS\SYSTEM32\ZXDNT3D.CFG
Adware.ClickSpring
C:\_OTMOVEIT\MOVEDFILES\03042008_093013\DOCUMENTS AND SETTINGS\CHRIS R\MY DOCUMENTS\DOBE~1\MSIEXEC.EXE
C:\_OTMoveIt\MovedFiles\03042008_093013\WINDOWS\system32\STEM32~1\XPLORE~1.EXE
Adware.OuterInfo-Installer
C:\_OTMOVEIT\MOVEDFILES\03042008_093013\PROGRAM FILES\OUTERINFO\OIUNINSTALLER.EXE
Trace.Known Threat Sources
C:\Documents and Settings\Chris R\Local Settings\Temporary Internet Files\Content.IE5\RT98WBY7\ctxad-576[1].0000
C:\Documents and Settings\Chris R\Local Settings\Temporary Internet Files\Content.IE5\L8WB5LSD\ctxad-576[1].0004
C:\Documents and Settings\Chris R\Local Settings\Temporary Internet Files\Content.IE5\I5U3M1GF\ctxad-576[1].0002
C:\Documents and Settings\Chris R\Local Settings\Temporary Internet Files\Content.IE5\RT98WBY7\ctxad-576[1].0005
C:\Documents and Settings\Chris R\Local Settings\Temporary Internet Files\Content.IE5\ULI3UZGT\ctxad-576[1].0001
C:\Documents and Settings\Chris R\Local Settings\Temporary Internet Files\Content.IE5\ULI3UZGT\ctxad-576[1].sig
C:\Documents and Settings\Chris R\Local Settings\Temporary Internet Files\Content.IE5\63QF6PYV\17PHolmes[1].cmt
C:\Documents and Settings\Chris R\Local Settings\Temporary Internet Files\Content.IE5\I5U3M1GF\17PHolmes[1].cmt
C:\Documents and Settings\Chris R\Local Settings\Temporary Internet Files\Content.IE5\I5U3M1GF\checkin[1].htm