i think just recently some more malware was unintentially installed...
-------------------------------------------------------------------------------
KASPERSKY ON-LINE SCANNER REPORT
Thursday, November 17, 2005 14:23:44
Operating System: Microsoft Windows XP Professional, Service Pack 1 (Build 2600)
Kaspersky On-line Scanner version: 5.0.67.0
Kaspersky Anti-Virus database last update: 17/11/2005
Kaspersky Anti-Virus database records: 160410
-------------------------------------------------------------------------------
Scan Settings:
Scan using the following antivirus database: extended
Scan Archives: true
Scan Mail Bases: true
Scan Target - My Computer:
C:\
D:\
Scan Statistics:
Total number of scanned objects: 34865
Number of viruses found: 12
Number of infected objects: 161
Number of suspicious objects: 0
Duration of the scan process: 1309 sec
Infected Object Name - Virus Name
C:\Program Files\Common Files\Microsoft Shared\Web Folders\ibm00002.dll Infected: Trojan-Spy.Win32.Small.dg
C:\System Volume Information\_restore{82C43A99-4545-45C5-8E82-063EAFA02D9A}\RP11\A0013295.exe Infected: not-a-virus:AdWare.Win32.BetterInternet.ac
C:\System Volume Information\_restore{82C43A99-4545-45C5-8E82-063EAFA02D9A}\RP12\A0017469.dll Infected: not-a-virus:AdWare.Win32.Look2Me.ab
C:\System Volume Information\_restore{82C43A99-4545-45C5-8E82-063EAFA02D9A}\RP12\A0017472.dll Infected: not-a-virus:AdWare.Win32.Look2Me.ab
C:\System Volume Information\_restore{82C43A99-4545-45C5-8E82-063EAFA02D9A}\RP12\A0018986.dll Infected: not-a-virus:AdWare.Win32.Look2Me.ab
C:\System Volume Information\_restore{82C43A99-4545-45C5-8E82-063EAFA02D9A}\RP12\A0019005.dll Infected: not-a-virus:AdWare.Win32.Look2Me.ab
C:\System Volume Information\_restore{82C43A99-4545-45C5-8E82-063EAFA02D9A}\RP12\A0020001.dll Infected: not-a-virus:AdWare.Win32.Look2Me.ab
C:\System Volume Information\_restore{82C43A99-4545-45C5-8E82-063EAFA02D9A}\RP12\A0021008.dll Infected: not-a-virus:AdWare.Win32.Look2Me.ab
C:\System Volume Information\_restore{82C43A99-4545-45C5-8E82-063EAFA02D9A}\RP12\A0022029.dll Infected: not-a-virus:AdWare.Win32.Look2Me.ab
C:\System Volume Information\_restore{82C43A99-4545-45C5-8E82-063EAFA02D9A}\RP12\A0023023.dll Infected: not-a-virus:AdWare.Win32.Look2Me.ab
C:\System Volume Information\_restore{82C43A99-4545-45C5-8E82-063EAFA02D9A}\RP12\A0023044.dll Infected: not-a-virus:AdWare.Win32.Look2Me.ab
C:\System Volume Information\_restore{82C43A99-4545-45C5-8E82-063EAFA02D9A}\RP12\A0025026.dll Infected: not-a-virus:AdWare.Win32.Look2Me.ab
C:\System Volume Information\_restore{82C43A99-4545-45C5-8E82-063EAFA02D9A}\RP12\A0025036.sys Infected: Rootkit.Win32.Agent.ab
C:\System Volume Information\_restore{82C43A99-4545-45C5-8E82-063EAFA02D9A}\RP12\A0025045.dll Infected: not-a-virus:AdWare.Win32.Look2Me.ab
C:\System Volume Information\_restore{82C43A99-4545-45C5-8E82-063EAFA02D9A}\RP12\A0026034.sys Infected: Rootkit.Win32.Agent.ab
C:\System Volume Information\_restore{82C43A99-4545-45C5-8E82-063EAFA02D9A}\RP12\A0026039.dll Infected: not-a-virus:AdWare.Win32.Look2Me.ab
C:\System Volume Information\_restore{82C43A99-4545-45C5-8E82-063EAFA02D9A}\RP12\A0026069.dll Infected: not-a-virus:AdWare.Win32.Look2Me.ab
C:\System Volume Information\_restore{82C43A99-4545-45C5-8E82-063EAFA02D9A}\RP12\A0026079.sys Infected: Rootkit.Win32.Agent.ab
C:\System Volume Information\_restore{82C43A99-4545-45C5-8E82-063EAFA02D9A}\RP12\A0026086.dll Infected: not-a-virus:AdWare.Win32.Look2Me.ab
C:\System Volume Information\_restore{82C43A99-4545-45C5-8E82-063EAFA02D9A}\RP12\A0026104.dll Infected: not-a-virus:AdWare.Win32.Look2Me.ab
C:\System Volume Information\_restore{82C43A99-4545-45C5-8E82-063EAFA02D9A}\RP12\A0026105.dll Infected: not-a-virus:AdWare.Win32.Look2Me.ab
C:\System Volume Information\_restore{82C43A99-4545-45C5-8E82-063EAFA02D9A}\RP12\A0026106.dll Infected: not-a-virus:AdWare.Win32.Look2Me.ab
C:\System Volume Information\_restore{82C43A99-4545-45C5-8E82-063EAFA02D9A}\RP12\A0026107.dll Infected: not-a-virus:AdWare.Win32.Look2Me.ab
C:\System Volume Information\_restore{82C43A99-4545-45C5-8E82-063EAFA02D9A}\RP12\A0026108.dll Infected: not-a-virus:AdWare.Win32.Look2Me.ab
C:\System Volume Information\_restore{82C43A99-4545-45C5-8E82-063EAFA02D9A}\RP12\A0026109.dll Infected: not-a-virus:AdWare.Win32.Look2Me.ab
C:\System Volume Information\_restore{82C43A99-4545-45C5-8E82-063EAFA02D9A}\RP12\A0026110.dll Infected: not-a-virus:AdWare.Win32.Look2Me.ab
C:\System Volume Information\_restore{82C43A99-4545-45C5-8E82-063EAFA02D9A}\RP12\A0026111.dll Infected: not-a-virus:AdWare.Win32.Look2Me.ab
C:\System Volume Information\_restore{82C43A99-4545-45C5-8E82-063EAFA02D9A}\RP12\A0026112.dll Infected: not-a-virus:AdWare.Win32.Look2Me.ab
C:\System Volume Information\_restore{82C43A99-4545-45C5-8E82-063EAFA02D9A}\RP12\A0026113.dll Infected: not-a-virus:AdWare.Win32.Look2Me.ab
C:\System Volume Information\_restore{82C43A99-4545-45C5-8E82-063EAFA02D9A}\RP12\A0026114.dll Infected: not-a-virus:AdWare.Win32.Look2Me.ab
C:\System Volume Information\_restore{82C43A99-4545-45C5-8E82-063EAFA02D9A}\RP12\A0026116.dll Infected: not-a-virus:AdWare.Win32.Look2Me.ab
C:\System Volume Information\_restore{82C43A99-4545-45C5-8E82-063EAFA02D9A}\RP12\A0026117.dll Infected: not-a-virus:AdWare.Win32.Look2Me.ab
C:\System Volume Information\_restore{82C43A99-4545-45C5-8E82-063EAFA02D9A}\RP12\A0026118.dll Infected: not-a-virus:AdWare.Win32.Look2Me.ab
C:\System Volume Information\_restore{82C43A99-4545-45C5-8E82-063EAFA02D9A}\RP12\A0026119.dll Infected: not-a-virus:AdWare.Win32.Look2Me.ab
C:\System Volume Information\_restore{82C43A99-4545-45C5-8E82-063EAFA02D9A}\RP12\A0026121.DLL Infected: not-a-virus:AdWare.Win32.Look2Me.ab
C:\System Volume Information\_restore{82C43A99-4545-45C5-8E82-063EAFA02D9A}\RP12\A0026126.sys Infected: Rootkit.Win32.Agent.ab
C:\System Volume Information\_restore{82C43A99-4545-45C5-8E82-063EAFA02D9A}\RP12\A0026127.dll Infected: not-a-virus:AdWare.Win32.Look2Me.ab
C:\System Volume Information\_restore{82C43A99-4545-45C5-8E82-063EAFA02D9A}\RP12\A0026141.dll Infected: not-a-virus:AdWare.Win32.Look2Me.ab
C:\System Volume Information\_restore{82C43A99-4545-45C5-8E82-063EAFA02D9A}\RP12\A0026160.dll Infected: not-a-virus:AdWare.Win32.Look2Me.ab
C:\System Volume Information\_restore{82C43A99-4545-45C5-8E82-063EAFA02D9A}\RP12\A0026164.dll Infected: not-a-virus:AdWare.Win32.Look2Me.ab
C:\System Volume Information\_restore{82C43A99-4545-45C5-8E82-063EAFA02D9A}\RP12\A0026170.sys Infected: Rootkit.Win32.Agent.ab
C:\System Volume Information\_restore{82C43A99-4545-45C5-8E82-063EAFA02D9A}\RP12\A0026190.dll Infected: not-a-virus:AdWare.Win32.Look2Me.ab
C:\System Volume Information\_restore{82C43A99-4545-45C5-8E82-063EAFA02D9A}\RP12\A0026199.sys Infected: Rootkit.Win32.Agent.ab
C:\System Volume Information\_restore{82C43A99-4545-45C5-8E82-063EAFA02D9A}\RP12\A0026207.dll Infected: not-a-virus:AdWare.Win32.Look2Me.ab
C:\System Volume Information\_restore{82C43A99-4545-45C5-8E82-063EAFA02D9A}\RP12\A0026209.dll Infected: not-a-virus:AdWare.Win32.Look2Me.ab
C:\System Volume Information\_restore{82C43A99-4545-45C5-8E82-063EAFA02D9A}\RP12\A0026218.sys Infected: Rootkit.Win32.Agent.ab
C:\System Volume Information\_restore{82C43A99-4545-45C5-8E82-063EAFA02D9A}\RP12\A0026226.dll Infected: not-a-virus:AdWare.Win32.Look2Me.ab
C:\System Volume Information\_restore{82C43A99-4545-45C5-8E82-063EAFA02D9A}\RP12\A0027217.sys Infected: Rootkit.Win32.Agent.ab
C:\System Volume Information\_restore{82C43A99-4545-45C5-8E82-063EAFA02D9A}\RP12\A0027224.dll Infected: not-a-virus:AdWare.Win32.Look2Me.ab
C:\System Volume Information\_restore{82C43A99-4545-45C5-8E82-063EAFA02D9A}\RP12\A0027226.dll Infected: not-a-virus:AdWare.Win32.Look2Me.ab
C:\System Volume Information\_restore{82C43A99-4545-45C5-8E82-063EAFA02D9A}\RP12\A0027235.sys Infected: Rootkit.Win32.Agent.ab
C:\System Volume Information\_restore{82C43A99-4545-45C5-8E82-063EAFA02D9A}\RP12\A0028229.dll Infected: not-a-virus:AdWare.Win32.Look2Me.ab
C:\System Volume Information\_restore{82C43A99-4545-45C5-8E82-063EAFA02D9A}\RP12\A0028235.sys Infected: Rootkit.Win32.Agent.ab
C:\System Volume Information\_restore{82C43A99-4545-45C5-8E82-063EAFA02D9A}\RP12\A0029234.sys Infected: Rootkit.Win32.Agent.ab
C:\System Volume Information\_restore{82C43A99-4545-45C5-8E82-063EAFA02D9A}\RP12\A0029240.dll Infected: not-a-virus:AdWare.Win32.Look2Me.ab
C:\System Volume Information\_restore{82C43A99-4545-45C5-8E82-063EAFA02D9A}\RP12\A0029245.dll Infected: not-a-virus:AdWare.Win32.Look2Me.ab
C:\System Volume Information\_restore{82C43A99-4545-45C5-8E82-063EAFA02D9A}\RP12\A0029254.sys Infected: Rootkit.Win32.Agent.ab
C:\System Volume Information\_restore{82C43A99-4545-45C5-8E82-063EAFA02D9A}\RP12\A0029260.dll Infected: not-a-virus:AdWare.Win32.Look2Me.ab
C:\System Volume Information\_restore{82C43A99-4545-45C5-8E82-063EAFA02D9A}\RP12\A0029288.dll Infected: not-a-virus:AdWare.Win32.Look2Me.ab
C:\System Volume Information\_restore{82C43A99-4545-45C5-8E82-063EAFA02D9A}\RP12\A0029298.sys Infected: Rootkit.Win32.Agent.ab
C:\System Volume Information\_restore{82C43A99-4545-45C5-8E82-063EAFA02D9A}\RP12\A0029300.dll Infected: not-a-virus:AdWare.Win32.Look2Me.ab
C:\System Volume Information\_restore{82C43A99-4545-45C5-8E82-063EAFA02D9A}\RP12\A0029326.dll Infected: not-a-virus:AdWare.Win32.Look2Me.ab
C:\System Volume Information\_restore{82C43A99-4545-45C5-8E82-063EAFA02D9A}\RP12\A0029342.dll Infected: not-a-virus:AdWare.Win32.Look2Me.ab
C:\System Volume Information\_restore{82C43A99-4545-45C5-8E82-063EAFA02D9A}\RP12\A0030335.dll Infected: not-a-virus:AdWare.Win32.Look2Me.ab
C:\System Volume Information\_restore{82C43A99-4545-45C5-8E82-063EAFA02D9A}\RP12\A0030364.dll Infected: not-a-virus:AdWare.Win32.Look2Me.ab
C:\System Volume Information\_restore{82C43A99-4545-45C5-8E82-063EAFA02D9A}\RP12\A0031364.dll Infected: not-a-virus:AdWare.Win32.Look2Me.ab
C:\System Volume Information\_restore{82C43A99-4545-45C5-8E82-063EAFA02D9A}\RP12\A0031374.dll Infected: not-a-virus:AdWare.Win32.Look2Me.ab
C:\System Volume Information\_restore{82C43A99-4545-45C5-8E82-063EAFA02D9A}\RP12\A0031379.dll Infected: not-a-virus:AdWare.Win32.Look2Me.ab
C:\System Volume Information\_restore{82C43A99-4545-45C5-8E82-063EAFA02D9A}\RP12\A0031383.dll Infected: not-a-virus:AdWare.Win32.Look2Me.ab
C:\System Volume Information\_restore{82C43A99-4545-45C5-8E82-063EAFA02D9A}\RP12\A0031401.dll Infected: not-a-virus:AdWare.Win32.Look2Me.ab
C:\System Volume Information\_restore{82C43A99-4545-45C5-8E82-063EAFA02D9A}\RP12\A0031405.dll Infected: not-a-virus:AdWare.Win32.Look2Me.ab
C:\System Volume Information\_restore{82C43A99-4545-45C5-8E82-063EAFA02D9A}\RP12\A0032405.dll Infected: not-a-virus:AdWare.Win32.Look2Me.ab
C:\System Volume Information\_restore{82C43A99-4545-45C5-8E82-063EAFA02D9A}\RP12\A0032407.exe Infected: Backdoor.Win32.SdBot.yx
C:\System Volume Information\_restore{82C43A99-4545-45C5-8E82-063EAFA02D9A}\RP12\A0032415.dll Infected: not-a-virus:AdWare.Win32.Look2Me.ab
C:\System Volume Information\_restore{82C43A99-4545-45C5-8E82-063EAFA02D9A}\RP12\A0032419.dll Infected: not-a-virus:AdWare.Win32.Look2Me.ab
C:\System Volume Information\_restore{82C43A99-4545-45C5-8E82-063EAFA02D9A}\RP12\A0033418.dll Infected: not-a-virus:AdWare.Win32.Look2Me.ab
C:\System Volume Information\_restore{82C43A99-4545-45C5-8E82-063EAFA02D9A}\RP13\A0033429.dll Infected: not-a-virus:AdWare.Win32.Look2Me.ab
C:\System Volume Information\_restore{82C43A99-4545-45C5-8E82-063EAFA02D9A}\RP13\A0033438.dll Infected: not-a-virus:AdWare.Win32.Look2Me.ab
C:\System Volume Information\_restore{82C43A99-4545-45C5-8E82-063EAFA02D9A}\RP13\A0034437.dll Infected: not-a-virus:AdWare.Win32.Look2Me.ab
C:\System Volume Information\_restore{82C43A99-4545-45C5-8E82-063EAFA02D9A}\RP13\A0034439.dll Infected: not-a-virus:AdWare.Win32.Look2Me.ab
C:\System Volume Information\_restore{82C43A99-4545-45C5-8E82-063EAFA02D9A}\RP13\A0034443.dll Infected: not-a-virus:AdWare.Win32.Look2Me.ab
C:\System Volume Information\_restore{82C43A99-4545-45C5-8E82-063EAFA02D9A}\RP14\A0034453.dll Infected: not-a-virus:AdWare.Win32.Look2Me.ab
C:\System Volume Information\_restore{82C43A99-4545-45C5-8E82-063EAFA02D9A}\RP14\A0034462.dll Infected: not-a-virus:AdWare.Win32.Look2Me.ab
C:\System Volume Information\_restore{82C43A99-4545-45C5-8E82-063EAFA02D9A}\RP14\A0034465.dll Infected: not-a-virus:AdWare.Win32.Look2Me.ab
C:\System Volume Information\_restore{82C43A99-4545-45C5-8E82-063EAFA02D9A}\RP14\A0034469.dll Infected: not-a-virus:AdWare.Win32.Look2Me.ab
C:\System Volume Information\_restore{82C43A99-4545-45C5-8E82-063EAFA02D9A}\RP14\A0034476.dll Infected: not-a-virus:AdWare.Win32.Look2Me.ab
C:\System Volume Information\_restore{82C43A99-4545-45C5-8E82-063EAFA02D9A}\RP14\A0034480.dll Infected: not-a-virus:AdWare.Win32.Look2Me.ab
C:\System Volume Information\_restore{82C43A99-4545-45C5-8E82-063EAFA02D9A}\RP14\A0034484.dll Infected: not-a-virus:AdWare.Win32.Look2Me.ab
C:\System Volume Information\_restore{82C43A99-4545-45C5-8E82-063EAFA02D9A}\RP14\A0034497.dll Infected: not-a-virus:AdWare.Win32.Look2Me.ab
C:\System Volume Information\_restore{82C43A99-4545-45C5-8E82-063EAFA02D9A}\RP14\A0034506.dll Infected: not-a-virus:AdWare.Win32.Look2Me.ab
C:\System Volume Information\_restore{82C43A99-4545-45C5-8E82-063EAFA02D9A}\RP14\A0034508.dll Infected: not-a-virus:AdWare.Win32.Look2Me.ab
C:\System Volume Information\_restore{82C43A99-4545-45C5-8E82-063EAFA02D9A}\RP14\A0034512.dll Infected: not-a-virus:AdWare.Win32.Look2Me.ab
C:\System Volume Information\_restore{82C43A99-4545-45C5-8E82-063EAFA02D9A}\RP14\A0035511.dll Infected: not-a-virus:AdWare.Win32.Look2Me.ab
C:\System Volume Information\_restore{82C43A99-4545-45C5-8E82-063EAFA02D9A}\RP14\A0035512.dll Infected: not-a-virus:AdWare.Win32.Look2Me.ab
C:\System Volume Information\_restore{82C43A99-4545-45C5-8E82-063EAFA02D9A}\RP14\A0035513.dll Infected: not-a-virus:AdWare.Win32.Look2Me.ab
C:\System Volume Information\_restore{82C43A99-4545-45C5-8E82-063EAFA02D9A}\RP14\A0035514.dll Infected: not-a-virus:AdWare.Win32.Look2Me.ab
C:\System Volume Information\_restore{82C43A99-4545-45C5-8E82-063EAFA02D9A}\RP14\A0035515.dll Infected: not-a-virus:AdWare.Win32.Look2Me.ab
C:\System Volume Information\_restore{82C43A99-4545-45C5-8E82-063EAFA02D9A}\RP14\A0035516.dll Infected: not-a-virus:AdWare.Win32.Look2Me.ab
C:\System Volume Information\_restore{82C43A99-4545-45C5-8E82-063EAFA02D9A}\RP14\A0035517.dll Infected: not-a-virus:AdWare.Win32.Look2Me.ab
C:\System Volume Information\_restore{82C43A99-4545-45C5-8E82-063EAFA02D9A}\RP14\A0035518.dll Infected: not-a-virus:AdWare.Win32.Look2Me.ab
C:\System Volume Information\_restore{82C43A99-4545-45C5-8E82-063EAFA02D9A}\RP14\A0035519.dll Infected: not-a-virus:AdWare.Win32.Look2Me.ab
C:\System Volume Information\_restore{82C43A99-4545-45C5-8E82-063EAFA02D9A}\RP14\A0035520.dll Infected: not-a-virus:AdWare.Win32.Look2Me.ab
C:\System Volume Information\_restore{82C43A99-4545-45C5-8E82-063EAFA02D9A}\RP14\A0035521.dll Infected: not-a-virus:AdWare.Win32.Look2Me.ab
C:\System Volume Information\_restore{82C43A99-4545-45C5-8E82-063EAFA02D9A}\RP14\A0035522.dll Infected: not-a-virus:AdWare.Win32.Look2Me.ab
C:\System Volume Information\_restore{82C43A99-4545-45C5-8E82-063EAFA02D9A}\RP14\A0035523.dll Infected: not-a-virus:AdWare.Win32.Look2Me.ab
C:\System Volume Information\_restore{82C43A99-4545-45C5-8E82-063EAFA02D9A}\RP14\A0035524.dll Infected: not-a-virus:AdWare.Win32.Look2Me.ab
C:\System Volume Information\_restore{82C43A99-4545-45C5-8E82-063EAFA02D9A}\RP14\A0035525.dll Infected: not-a-virus:AdWare.Win32.Look2Me.ab
C:\System Volume Information\_restore{82C43A99-4545-45C5-8E82-063EAFA02D9A}\RP14\A0035626.dll Infected: not-a-virus:AdWare.Win32.Look2Me.ab
C:\System Volume Information\_restore{82C43A99-4545-45C5-8E82-063EAFA02D9A}\RP14\A0035631.dll Infected: not-a-virus:AdWare.Win32.Look2Me.ab
C:\System Volume Information\_restore{82C43A99-4545-45C5-8E82-063EAFA02D9A}\RP14\A0035635.dll Infected: not-a-virus:AdWare.Win32.Look2Me.ab
C:\System Volume Information\_restore{82C43A99-4545-45C5-8E82-063EAFA02D9A}\RP14\A0036641.dll Infected: not-a-virus:AdWare.Win32.Look2Me.ab
C:\System Volume Information\_restore{82C43A99-4545-45C5-8E82-063EAFA02D9A}\RP14\A0036646.dll Infected: not-a-virus:AdWare.Win32.Look2Me.ab
C:\System Volume Information\_restore{82C43A99-4545-45C5-8E82-063EAFA02D9A}\RP14\A0036650.dll Infected: not-a-virus:AdWare.Win32.Look2Me.ab
C:\System Volume Information\_restore{82C43A99-4545-45C5-8E82-063EAFA02D9A}\RP14\A0037655.dll Infected: not-a-virus:AdWare.Win32.Look2Me.ab
C:\System Volume Information\_restore{82C43A99-4545-45C5-8E82-063EAFA02D9A}\RP14\A0037656.dll Infected: not-a-virus:AdWare.Win32.Look2Me.ab
C:\System Volume Information\_restore{82C43A99-4545-45C5-8E82-063EAFA02D9A}\RP14\A0037671.dll Infected: not-a-virus:AdWare.Win32.Look2Me.ab
C:\System Volume Information\_restore{82C43A99-4545-45C5-8E82-063EAFA02D9A}\RP14\A0037672.dll Infected: not-a-virus:AdWare.Win32.Look2Me.ab
C:\System Volume Information\_restore{82C43A99-4545-45C5-8E82-063EAFA02D9A}\RP14\A0037685.dll Infected: not-a-virus:AdWare.Win32.Look2Me.ab
C:\System Volume Information\_restore{82C43A99-4545-45C5-8E82-063EAFA02D9A}\RP14\A0037686.dll Infected: not-a-virus:AdWare.Win32.Look2Me.ab
C:\System Volume Information\_restore{82C43A99-4545-45C5-8E82-063EAFA02D9A}\RP14\A0037691.dll Infected: not-a-virus:AdWare.Win32.Look2Me.ab
C:\System Volume Information\_restore{82C43A99-4545-45C5-8E82-063EAFA02D9A}\RP14\A0037695.dll Infected: not-a-virus:AdWare.Win32.Look2Me.ab
C:\System Volume Information\_restore{82C43A99-4545-45C5-8E82-063EAFA02D9A}\RP14\A0038700.dll Infected: not-a-virus:AdWare.Win32.Look2Me.ab
C:\System Volume Information\_restore{82C43A99-4545-45C5-8E82-063EAFA02D9A}\RP14\A0038703.dll Infected: not-a-virus:AdWare.Win32.Look2Me.ab
C:\System Volume Information\_restore{82C43A99-4545-45C5-8E82-063EAFA02D9A}\RP14\A0038707.dll Infected: not-a-virus:AdWare.Win32.Look2Me.ab
C:\System Volume Information\_restore{82C43A99-4545-45C5-8E82-063EAFA02D9A}\RP14\A0038716.dll Infected: not-a-virus:AdWare.Win32.Look2Me.ab
C:\System Volume Information\_restore{82C43A99-4545-45C5-8E82-063EAFA02D9A}\RP14\A0038720.dll Infected: not-a-virus:AdWare.Win32.Look2Me.ab
C:\System Volume Information\_restore{82C43A99-4545-45C5-8E82-063EAFA02D9A}\RP14\A0039738.dll Infected: not-a-virus:AdWare.Win32.Look2Me.ab
C:\System Volume Information\_restore{82C43A99-4545-45C5-8E82-063EAFA02D9A}\RP14\A0039777.dll Infected: not-a-virus:AdWare.Win32.Look2Me.ab
C:\System Volume Information\_restore{82C43A99-4545-45C5-8E82-063EAFA02D9A}\RP15\A0040876.dll Infected: not-a-virus:AdWare.Win32.Look2Me.ab
C:\System Volume Information\_restore{82C43A99-4545-45C5-8E82-063EAFA02D9A}\RP15\A0040877.dll Infected: not-a-virus:AdWare.Win32.Look2Me.ab
C:\System Volume Information\_restore{82C43A99-4545-45C5-8E82-063EAFA02D9A}\RP15\A0040878.dll Infected: not-a-virus:AdWare.Win32.Look2Me.ab
C:\System Volume Information\_restore{82C43A99-4545-45C5-8E82-063EAFA02D9A}\RP15\A0040879.dll Infected: not-a-virus:AdWare.Win32.Look2Me.ab
C:\System Volume Information\_restore{82C43A99-4545-45C5-8E82-063EAFA02D9A}\RP15\A0040880.dll Infected: not-a-virus:AdWare.Win32.Look2Me.ab
C:\System Volume Information\_restore{82C43A99-4545-45C5-8E82-063EAFA02D9A}\RP15\A0040881.dll Infected: not-a-virus:AdWare.Win32.Look2Me.ab
C:\System Volume Information\_restore{82C43A99-4545-45C5-8E82-063EAFA02D9A}\RP15\A0040882.dll Infected: not-a-virus:AdWare.Win32.Look2Me.ab
C:\System Volume Information\_restore{82C43A99-4545-45C5-8E82-063EAFA02D9A}\RP15\A0040883.dll Infected: not-a-virus:AdWare.Win32.Look2Me.ab
C:\System Volume Information\_restore{82C43A99-4545-45C5-8E82-063EAFA02D9A}\RP15\A0040884.exe Infected: Backdoor.Win32.Rbot.aea
C:\System Volume Information\_restore{82C43A99-4545-45C5-8E82-063EAFA02D9A}\RP15\A0044001.exe Infected: Backdoor.Win32.SdBot.yx
C:\System Volume Information\_restore{82C43A99-4545-45C5-8E82-063EAFA02D9A}\RP15\A0044003.exe Infected: Backdoor.Win32.Rbot.aea
C:\System Volume Information\_restore{82C43A99-4545-45C5-8E82-063EAFA02D9A}\RP15\A0044008.dll Infected: not-a-virus:AdWare.Win32.Look2Me.ab
C:\System Volume Information\_restore{82C43A99-4545-45C5-8E82-063EAFA02D9A}\RP15\A0044009.dll Infected: not-a-virus:AdWare.Win32.Look2Me.ab
C:\System Volume Information\_restore{82C43A99-4545-45C5-8E82-063EAFA02D9A}\RP15\A0044010.dll Infected: not-a-virus:AdWare.Win32.Look2Me.ab
C:\System Volume Information\_restore{82C43A99-4545-45C5-8E82-063EAFA02D9A}\RP15\A0044011.dll Infected: not-a-virus:AdWare.Win32.Look2Me.ab
C:\System Volume Information\_restore{82C43A99-4545-45C5-8E82-063EAFA02D9A}\RP15\A0044012.dll Infected: not-a-virus:AdWare.Win32.Look2Me.ab
C:\System Volume Information\_restore{82C43A99-4545-45C5-8E82-063EAFA02D9A}\RP15\A0044013.dll Infected: not-a-virus:AdWare.Win32.Look2Me.ab
C:\System Volume Information\_restore{82C43A99-4545-45C5-8E82-063EAFA02D9A}\RP15\A0044014.dll Infected: not-a-virus:AdWare.Win32.Look2Me.ab
C:\System Volume Information\_restore{82C43A99-4545-45C5-8E82-063EAFA02D9A}\RP15\A0044016.dll Infected: not-a-virus:AdWare.Win32.Look2Me.ab
C:\System Volume Information\_restore{82C43A99-4545-45C5-8E82-063EAFA02D9A}\RP15\A0044017.exe Infected: Trojan.Win32.LowZones.cq
C:\System Volume Information\_restore{82C43A99-4545-45C5-8E82-063EAFA02D9A}\RP15\A0044024.exe Infected: Backdoor.Win32.Rbot.adf
C:\System Volume Information\_restore{82C43A99-4545-45C5-8E82-063EAFA02D9A}\RP15\A0044026.sys Infected: Rootkit.Win32.Agent.ab
C:\System Volume Information\_restore{82C43A99-4545-45C5-8E82-063EAFA02D9A}\RP17\A0045104.exe Infected: Trojan.Win32.Crypt.d
C:\System Volume Information\_restore{82C43A99-4545-45C5-8E82-063EAFA02D9A}\RP18\A0047225.exe Infected: Backdoor.Win32.SdBot.yx
C:\System Volume Information\_restore{82C43A99-4545-45C5-8E82-063EAFA02D9A}\RP18\A0047248.exe Infected: Backdoor.Win32.SdBot.aig
C:\System Volume Information\_restore{82C43A99-4545-45C5-8E82-063EAFA02D9A}\RP19\A0047284.exe Infected: Trojan-Downloader.Win32.Small.bfy
C:\System Volume Information\_restore{82C43A99-4545-45C5-8E82-063EAFA02D9A}\RP19\A0047300.exe Infected: Backdoor.Win32.SdBot.aig
C:\System Volume Information\_restore{82C43A99-4545-45C5-8E82-063EAFA02D9A}\RP19\A0047302.exe Infected: Trojan-Spy.Win32.Small.dg
C:\System Volume Information\_restore{82C43A99-4545-45C5-8E82-063EAFA02D9A}\RP19\A0047303.exe Infected: Backdoor.Win32.SdBot.aig
C:\System Volume Information\_restore{82C43A99-4545-45C5-8E82-063EAFA02D9A}\RP19\A0047305.exe Infected: Backdoor.Win32.SdBot.yx
C:\System Volume Information\_restore{82C43A99-4545-45C5-8E82-063EAFA02D9A}\RP19\A0047306.exe Infected: Backdoor.Win32.Rbot.aeu
C:\System Volume Information\_restore{82C43A99-4545-45C5-8E82-063EAFA02D9A}\RP19\A0047307.exe Infected: Backdoor.Win32.Rbot.aea
C:\WINDOWS\thin-149-2-x-x.exe Infected: not-a-virus:AdWare.Win32.BetterInternet.ac
Scan process completed.
and a new hijack this log...
Logfile of HijackThis v1.99.1
Scan saved at 2:24:07 PM, on 11/17/2005
Platform: Windows XP SP1 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\System32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\ACS.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\ehome\ehtray.exe
C:\Program Files\TOSHIBA\E-KEY\CeEKey.exe
C:\WINDOWS\ehome\ehmsas.exe
C:\Program Files\TOSHIBA\Power Management\CePMTray.exe
C:\WINDOWS\System32\ctfmon.exe
C:\Program Files\TOSHIBA\TouchPad\TPTray.exe
C:\WINDOWS\System32\ezSP_Px.exe
C:\Program Files\Drag'n Drop CD+DVD\BinFiles\DragDrop.exe
C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
C:\Program Files\Apoint2K\Apoint.exe
C:\Program Files\TOSHIBA\Battery Checker\BtryChkr.exe
C:\Program Files\EzButton\EzButton.EXE
C:\Program Files\ltmoh\Ltmoh.exe
C:\Program Files\Winamp\winampa.exe
C:\Program Files\Webroot\Spy Sweeper\SpySweeper.exe
C:\Program Files\TOSHIBA\TOSCDSPD\toscdspd.exe
C:\Program Files\MSN Messenger\MsnMsgr.Exe
C:\Program Files\Apoint2K\Apntex.exe
C:\WINDOWS\system32\RAMASST.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgemc.exe
C:\Program Files\TOSHIBA\ConfigFree\CFSvcs.exe
C:\WINDOWS\System32\DVDRAMSV.exe
C:\WINDOWS\ehome\ehSched.exe
C:\Program Files\ewido\security suite\ewidoctrl.exe
C:\Program Files\Webroot\Spy Sweeper\WRSSSDK.exe
C:\Program Files\Common Files\Softwin\BitDefender Communicator\xcommsvr.exe
C:\Program Files\Common Files\Softwin\BitDefender Scan Server\bdss.exe
C:\WINDOWS\system32\cmd.exe
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\Program Files\Hijackthis\HijackThis.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page =
http://www.google.ca/R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page =
http://www.google.ca/O4 - HKLM\..\Run: [ehTray] C:\WINDOWS\ehome\ehtray.exe
O4 - HKLM\..\Run: [CeEKEY] C:\Program Files\TOSHIBA\E-KEY\CeEKey.exe
O4 - HKLM\..\Run: [CeEPOWER] C:\Program Files\TOSHIBA\Power Management\CePMTray.exe
O4 - HKLM\..\Run: [TPNF] C:\Program Files\TOSHIBA\TouchPad\TPTray.exe
O4 - HKLM\..\Run: [ezShieldProtector for Px] C:\WINDOWS\System32\ezSP_Px.exe
O4 - HKLM\..\Run: [Drag'n Drop CD+DVD] C:\Program Files\Drag'n Drop CD+DVD\BinFiles\DragDrop.exe /StartUp
O4 - HKLM\..\Run: [ATIModeChange] Ati2mdxx.exe
O4 - HKLM\..\Run: [ATIPTA] C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
O4 - HKLM\..\Run: [Apoint] C:\Program Files\Apoint2K\Apoint.exe
O4 - HKLM\..\Run: [Battery Checker] C:\Program Files\TOSHIBA\Battery Checker\BtryChkr.exe
O4 - HKLM\..\Run: [EzButton] C:\Program Files\EzButton\EzButton.EXE
O4 - HKLM\..\Run: [LtMoh] C:\Program Files\ltmoh\Ltmoh.exe
O4 - HKLM\..\Run: [WinampAgent] C:\Program Files\Winamp\winampa.exe
O4 - HKLM\..\Run: [SpySweeper] "C:\Program Files\Webroot\Spy Sweeper\SpySweeper.exe" /startintray
O4 - HKCU\..\Run: [TOSCDSPD] C:\Program Files\TOSHIBA\TOSCDSPD\toscdspd.exe
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\System32\ctfmon.exe
O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\MSN Messenger\MsnMsgr.Exe" /background
O4 - Global Startup: RAMASST.lnk = C:\WINDOWS\system32\RAMASST.exe
O8 - Extra context menu item: &Google Search - res://C:\Program Files\Google\GoogleToolbar1.dll/cmsearch.html
O8 - Extra context menu item: &Translate English Word - res://C:\Program Files\Google\GoogleToolbar1.dll/cmwordtrans.html
O8 - Extra context menu item: Backward Links - res://C:\Program Files\Google\GoogleToolbar1.dll/cmbacklinks.html
O8 - Extra context menu item: Cached Snapshot of Page - res://C:\Program Files\Google\GoogleToolbar1.dll/cmcache.html
O8 - Extra context menu item: Similar Pages - res://C:\Program Files\Google\GoogleToolbar1.dll/cmsimilar.html
O8 - Extra context menu item: Translate Page into English - res://C:\Program Files\Google\GoogleToolbar1.dll/cmtrans.html
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\j2re1.4.2\bin\npjpi142.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\j2re1.4.2\bin\npjpi142.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O16 - DPF: {0EB0E74A-2A76-4AB3-A7FB-9BD8C29F7F75} (CKAVWebScan Object) -
http://www.kaspersky...can_unicode.cabO16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) -
http://acs.pandasoft...free/asinst.cabO23 - Service: Atheros Configuration Service (ACS) - Unknown owner - C:\WINDOWS\System32\ACS.exe
O23 - Service: Ati HotKey Poller - Unknown owner - C:\WINDOWS\System32\Ati2evxx.exe
O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
O23 - Service: AVG E-mail Scanner (AVGEMS) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgemc.exe
O23 - Service: BitDefender Scan Server (bdss) - Unknown owner - C:\Program Files\Common Files\Softwin\BitDefender Scan Server\bdss.exe" /service (file missing)
O23 - Service: ConfigFree Service (CFSvcs) - TOSHIBA CORPORATION - C:\Program Files\TOSHIBA\ConfigFree\CFSvcs.exe
O23 - Service: DVD-RAM_Service - Matsushita Electric Industrial Co., Ltd. - C:\WINDOWS\System32\DVDRAMSV.exe
O23 - Service: ewido security suite control - ewido networks - C:\Program Files\ewido\security suite\ewidoctrl.exe
O23 - Service: Webroot Spy Sweeper Engine (svcWRSSSDK) - Webroot Software, Inc. - C:\Program Files\Webroot\Spy Sweeper\WRSSSDK.exe
O23 - Service: BitDefender Communicator (XCOMM) - Unknown owner - C:\Program Files\Common Files\Softwin\BitDefender Communicator\xcommsvr.exe" /service (file missing)