Hi
below are the 3 reports you asked for. I wanted to mention that while the ewido trojan scanner was removing the infections a pop up window came up with the following message:
" the file C:\systemvolumeinformation\_restore{9E75938D-30BD-45AO-81DC-8502D3051D98}\RP92\A0005986.exe/kansup.reg
cannot be removed because it is embedded in C:\systemvolumeinformation\_restore{9E75938D-30BD-45AO-81DC-8502D3051D98}\RP92\A0005986.exe
here are the 3 reports. thanks in advance for your help
Aditya
Destroyer report:
Look2Me-Destroyer V1.0.11
Scanning for infected files.....
Scan started at 3/16/2006 9:36:05 PM
Infected! C:\WINDOWS\system32\p66slgj716o.dll
Attempting to delete infected files...
Attempting to delete: C:\WINDOWS\system32\p66slgj716o.dll
C:\WINDOWS\system32\p66slgj716o.dll Deleted successfully!
Making registry repairs.
Removing: HKLM\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\Nls
Removing: HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved "{60294D6D-E639-4E6C-B91E-B582FCDF5FCC}"
HKCR\Clsid\{60294D6D-E639-4E6C-B91E-B582FCDF5FCC}
Removing: HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved "{46892B41-2839-47D8-820E-C66E861F174F}"
HKCR\Clsid\{46892B41-2839-47D8-820E-C66E861F174F}
Removing: HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved "{D6F7EF31-9992-471A-A68F-488E8DCDD36B}"
HKCR\Clsid\{D6F7EF31-9992-471A-A68F-488E8DCDD36B}
Removing: HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved "{04CF8A74-EE12-4D9D-B603-3DB6C741E8D4}"
HKCR\Clsid\{04CF8A74-EE12-4D9D-B603-3DB6C741E8D4}
Removing: HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved "{A178CA4E-990C-49A4-8FCC-DE78DDC20E5F}"
HKCR\Clsid\{A178CA4E-990C-49A4-8FCC-DE78DDC20E5F}
Removing: HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved "{4230DE04-8879-4498-88EC-19A47E28B3AB}"
HKCR\Clsid\{4230DE04-8879-4498-88EC-19A47E28B3AB}
Removing: HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved "{E1734460-D93A-43D5-8A9F-4EA7B0BAD075}"
HKCR\Clsid\{E1734460-D93A-43D5-8A9F-4EA7B0BAD075}
Removing: HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved "{CA1A9FFE-C2C6-4D74-AEFE-D12FE2EB263A}"
HKCR\Clsid\{CA1A9FFE-C2C6-4D74-AEFE-D12FE2EB263A}
Removing: HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved "{BD597657-B5FA-4EA3-A354-9EA8E1BBAC65}"
HKCR\Clsid\{BD597657-B5FA-4EA3-A354-9EA8E1BBAC65}
Removing: HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved "{E4131FC2-1894-46E9-821B-41BE4D4BC352}"
HKCR\Clsid\{E4131FC2-1894-46E9-821B-41BE4D4BC352}
Restoring Windows certificates.
Replaced hosts file with default windows hosts file
Restoring SeDebugPrivilege for Administrators - Succeeded
EWIDO REPORT
---------------------------------------------------------
ewido anti-malware - Scan report
---------------------------------------------------------
+ Created on: 10:08:50 PM, 3/16/2006
+ Report-Checksum: 67B42529
+ Scan result:
[2040] C:\WINDOWS\system32\CALC32.EXE -> Worm.SpyBot.gl : Cleaned with backup
C:\WINDOWS\system32\jt4207hoe.dll -> Adware.Look2Me : Cleaned with backup
C:\WINDOWS\system32\aolspywarecleaner.exe -> Worm.SpyBot.gl : Cleaned with backup
C:\WINDOWS\system32\upd32.exe/kansup.reg -> Trojan.LowZones.f : Error during cleaning
C:\WINDOWS\system32\wuyumtnrpcmxgaptt.exe -> Worm.SpyBot.gl : Cleaned with backup
C:\WINDOWS\system32\calc32.exe -> Worm.SpyBot.gl : Cleaned with backup
C:\WINDOWS\system32\ebqcon.exe -> Worm.SpyBot.gl : Cleaned with backup
C:\WINDOWS\gimmygames11.exe -> Downloader.Adload.u : Cleaned with backup
:mozilla.14:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\b9m9xcwn.default\cookies.txt -> TrackingCookie.Atdmt : Cleaned with backup
:mozilla.32:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\b9m9xcwn.default\cookies.txt -> TrackingCookie.2o7 : Cleaned with backup
:mozilla.33:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\b9m9xcwn.default\cookies.txt -> TrackingCookie.2o7 : Cleaned with backup
:mozilla.34:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\b9m9xcwn.default\cookies.txt -> TrackingCookie.2o7 : Cleaned with backup
:mozilla.35:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\b9m9xcwn.default\cookies.txt -> TrackingCookie.2o7 : Cleaned with backup
:mozilla.49:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\b9m9xcwn.default\cookies.txt -> TrackingCookie.Doubleclick : Cleaned with backup
:mozilla.55:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\b9m9xcwn.default\cookies.txt -> TrackingCookie.Valueclick : Cleaned with backup
:mozilla.56:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\b9m9xcwn.default\cookies.txt -> TrackingCookie.Valueclick : Cleaned with backup
:mozilla.57:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\b9m9xcwn.default\cookies.txt -> TrackingCookie.Advertising : Cleaned with backup
:mozilla.58:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\b9m9xcwn.default\cookies.txt -> TrackingCookie.Advertising : Cleaned with backup
:mozilla.59:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\b9m9xcwn.default\cookies.txt -> TrackingCookie.Advertising : Cleaned with backup
:mozilla.60:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\b9m9xcwn.default\cookies.txt -> TrackingCookie.Advertising : Cleaned with backup
:mozilla.62:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\b9m9xcwn.default\cookies.txt -> TrackingCookie.Tribalfusion : Cleaned with backup
:mozilla.70:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\b9m9xcwn.default\cookies.txt -> TrackingCookie.Burstnet : Cleaned with backup
:mozilla.71:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\b9m9xcwn.default\cookies.txt -> TrackingCookie.Fastclick : Cleaned with backup
:mozilla.72:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\b9m9xcwn.default\cookies.txt -> TrackingCookie.Fastclick : Cleaned with backup
:mozilla.73:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\b9m9xcwn.default\cookies.txt -> TrackingCookie.Burstnet : Cleaned with backup
:mozilla.74:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\b9m9xcwn.default\cookies.txt -> TrackingCookie.Fastclick : Cleaned with backup
:mozilla.75:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\b9m9xcwn.default\cookies.txt -> TrackingCookie.Tacoda : Cleaned with backup
:mozilla.76:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\b9m9xcwn.default\cookies.txt -> TrackingCookie.Tacoda : Cleaned with backup
:mozilla.77:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\b9m9xcwn.default\cookies.txt -> TrackingCookie.Tacoda : Cleaned with backup
:mozilla.94:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\b9m9xcwn.default\cookies.txt -> TrackingCookie.Yieldmanager : Cleaned with backup
:mozilla.95:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\b9m9xcwn.default\cookies.txt -> TrackingCookie.Yieldmanager : Cleaned with backup
:mozilla.96:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\b9m9xcwn.default\cookies.txt -> TrackingCookie.Yieldmanager : Cleaned with backup
:mozilla.108:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\b9m9xcwn.default\cookies.txt -> TrackingCookie.Revenue : Cleaned with backup
:mozilla.109:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\b9m9xcwn.default\cookies.txt -> TrackingCookie.Revenue : Cleaned with backup
:mozilla.110:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\b9m9xcwn.default\cookies.txt -> TrackingCookie.Revenue : Cleaned with backup
:mozilla.120:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\b9m9xcwn.default\cookies.txt -> TrackingCookie.Sexcounter : Cleaned with backup
:mozilla.121:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\b9m9xcwn.default\cookies.txt -> TrackingCookie.Sexcounter : Cleaned with backup
:mozilla.122:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\b9m9xcwn.default\cookies.txt -> TrackingCookie.Sexcounter : Cleaned with backup
:mozilla.123:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\b9m9xcwn.default\cookies.txt -> TrackingCookie.Sexcounter : Cleaned with backup
:mozilla.124:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\b9m9xcwn.default\cookies.txt -> TrackingCookie.Sexcounter : Cleaned with backup
:mozilla.125:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\b9m9xcwn.default\cookies.txt -> TrackingCookie.Sexcounter : Cleaned with backup
:mozilla.126:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\b9m9xcwn.default\cookies.txt -> TrackingCookie.Sexcounter : Cleaned with backup
:mozilla.127:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\b9m9xcwn.default\cookies.txt -> TrackingCookie.Sexcounter : Cleaned with backup
:mozilla.145:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\b9m9xcwn.default\cookies.txt -> TrackingCookie.2o7 : Cleaned with backup
:mozilla.146:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\b9m9xcwn.default\cookies.txt -> TrackingCookie.Webtrendslive : Cleaned with backup
:mozilla.152:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\b9m9xcwn.default\cookies.txt -> TrackingCookie.Ru4 : Cleaned with backup
:mozilla.153:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\b9m9xcwn.default\cookies.txt -> TrackingCookie.Questionmarket : Cleaned with backup
:mozilla.156:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\b9m9xcwn.default\cookies.txt -> TrackingCookie.Ru4 : Cleaned with backup
:mozilla.157:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\b9m9xcwn.default\cookies.txt -> TrackingCookie.Ru4 : Cleaned with backup
:mozilla.158:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\b9m9xcwn.default\cookies.txt -> TrackingCookie.Webtrendslive : Cleaned with backup
:mozilla.169:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\b9m9xcwn.default\cookies.txt -> TrackingCookie.Pointroll : Cleaned with backup
:mozilla.170:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\b9m9xcwn.default\cookies.txt -> TrackingCookie.Pointroll : Cleaned with backup
:mozilla.171:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\b9m9xcwn.default\cookies.txt -> TrackingCookie.Pointroll : Cleaned with backup
:mozilla.172:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\b9m9xcwn.default\cookies.txt -> TrackingCookie.Pointroll : Cleaned with backup
:mozilla.181:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\b9m9xcwn.default\cookies.txt -> TrackingCookie.Mediaplex : Cleaned with backup
:mozilla.189:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\b9m9xcwn.default\cookies.txt -> TrackingCookie.2o7 : Cleaned with backup
:mozilla.195:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\b9m9xcwn.default\cookies.txt -> TrackingCookie.Coremetrics : Cleaned with backup
:mozilla.201:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\b9m9xcwn.default\cookies.txt -> TrackingCookie.Liveperson : Cleaned with backup
:mozilla.202:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\b9m9xcwn.default\cookies.txt -> TrackingCookie.Hitbox : Cleaned with backup
:mozilla.203:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\b9m9xcwn.default\cookies.txt -> TrackingCookie.Hitbox : Cleaned with backup
:mozilla.204:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\b9m9xcwn.default\cookies.txt -> TrackingCookie.Liveperson : Cleaned with backup
:mozilla.205:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\b9m9xcwn.default\cookies.txt -> TrackingCookie.Hitbox : Cleaned with backup
:mozilla.206:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\b9m9xcwn.default\cookies.txt -> TrackingCookie.Liveperson : Cleaned with backup
:mozilla.216:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\b9m9xcwn.default\cookies.txt -> TrackingCookie.Sexlist : Cleaned with backup
:mozilla.217:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\b9m9xcwn.default\cookies.txt -> TrackingCookie.Sexlist : Cleaned with backup
:mozilla.229:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\b9m9xcwn.default\cookies.txt -> TrackingCookie.Zedo : Cleaned with backup
:mozilla.231:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\b9m9xcwn.default\cookies.txt -> TrackingCookie.Zedo : Cleaned with backup
:mozilla.232:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\b9m9xcwn.default\cookies.txt -> TrackingCookie.Zedo : Cleaned with backup
:mozilla.234:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\b9m9xcwn.default\cookies.txt -> TrackingCookie.Pro-market : Cleaned with backup
:mozilla.263:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\b9m9xcwn.default\cookies.txt -> TrackingCookie.Paycounter : Cleaned with backup
:mozilla.273:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\b9m9xcwn.default\cookies.txt -> TrackingCookie.Hitbox : Cleaned with backup
:mozilla.274:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\b9m9xcwn.default\cookies.txt -> TrackingCookie.Hitbox : Cleaned with backup
:mozilla.275:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\b9m9xcwn.default\cookies.txt -> TrackingCookie.Hitbox : Cleaned with backup
:mozilla.281:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\b9m9xcwn.default\cookies.txt -> TrackingCookie.Bridgetrack : Cleaned with backup
:mozilla.283:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\b9m9xcwn.default\cookies.txt -> TrackingCookie.Hitbox : Cleaned with backup
:mozilla.291:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\b9m9xcwn.default\cookies.txt -> TrackingCookie.2o7 : Cleaned with backup
:mozilla.305:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\b9m9xcwn.default\cookies.txt -> TrackingCookie.Doubleclick : Cleaned with backup
:mozilla.306:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\b9m9xcwn.default\cookies.txt -> TrackingCookie.Bluestreak : Cleaned with backup
:mozilla.308:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\b9m9xcwn.default\cookies.txt -> TrackingCookie.Valueclick : Cleaned with backup
:mozilla.309:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\b9m9xcwn.default\cookies.txt -> TrackingCookie.Valueclick : Cleaned with backup
:mozilla.310:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\b9m9xcwn.default\cookies.txt -> TrackingCookie.Overture : Cleaned with backup
C:\Documents and Settings\Owner\pwha.exe -> Not-A-Virus.PSWTool.Win32.PassView.162 : Cleaned with backup
C:\Documents and Settings\Owner\astr.exe -> Downloader.VB.na : Cleaned with backup
C:\Documents and Settings\Owner\im.exe -> Not-A-Virus.PSWTool.Win32.Messen.103 : Cleaned with backup
C:\System Volume Information\_restore{9E75938D-30BD-45A0-81DC-8502D3051D9B}\RP92\A0005986.exe/kansup.reg -> Trojan.LowZones.f : Error during cleaning
C:\System Volume Information\_restore{9E75938D-30BD-45A0-81DC-8502D3051D9B}\RP92\A0005986.exe/grimy.exe -> Downloader.VB.ws : Error during cleaning
C:\System Volume Information\_restore{9E75938D-30BD-45A0-81DC-8502D3051D9B}\RP95\A0006036.cpl -> Downloader.Qoologic.at : Cleaned with backup
C:\System Volume Information\_restore{9E75938D-30BD-45A0-81DC-8502D3051D9B}\RP95\A0006040.exe -> Downloader.Qoologic.bh : Cleaned with backup
C:\System Volume Information\_restore{9E75938D-30BD-45A0-81DC-8502D3051D9B}\RP95\A0006042.exe -> Not-A-Virus.Monitor.Win32.NetMon.a : Cleaned with backup
C:\System Volume Information\_restore{9E75938D-30BD-45A0-81DC-8502D3051D9B}\RP95\A0006046.exe -> Trojan.Pakes : Cleaned with backup
C:\System Volume Information\_restore{9E75938D-30BD-45A0-81DC-8502D3051D9B}\RP95\A0006047.dll -> Downloader.Qoologic.az : Cleaned with backup
C:\System Volume Information\_restore{9E75938D-30BD-45A0-81DC-8502D3051D9B}\RP95\A0006048.dll -> Downloader.Small : Cleaned with backup
C:\System Volume Information\_restore{9E75938D-30BD-45A0-81DC-8502D3051D9B}\RP95\A0006051.exe/kansup.reg -> Trojan.LowZones.f : Error during cleaning
C:\System Volume Information\_restore{9E75938D-30BD-45A0-81DC-8502D3051D9B}\RP95\A0006051.exe/grimy.exe -> Downloader.VB.ws : Error during cleaning
C:\System Volume Information\_restore{9E75938D-30BD-45A0-81DC-8502D3051D9B}\RP95\A0006052.exe -> Downloader.Qoologic.at : Cleaned with backup
C:\System Volume Information\_restore{9E75938D-30BD-45A0-81DC-8502D3051D9B}\RP95\A0006056.exe -> Downloader.Qoologic.at : Cleaned with backup
C:\System Volume Information\_restore{9E75938D-30BD-45A0-81DC-8502D3051D9B}\RP95\A0006057.dll -> Downloader.Qoologic.az : Cleaned with backup
C:\System Volume Information\_restore{9E75938D-30BD-45A0-81DC-8502D3051D9B}\RP95\A0006063.exe/kansup.reg -> Trojan.LowZones.f : Error during cleaning
C:\System Volume Information\_restore{9E75938D-30BD-45A0-81DC-8502D3051D9B}\RP95\A0006063.exe/grimy.exe -> Downloader.VB.ws : Error during cleaning
C:\System Volume Information\_restore{9E75938D-30BD-45A0-81DC-8502D3051D9B}\RP96\A0006070.dll -> Adware.Look2Me : Cleaned with backup
C:\System Volume Information\_restore{9E75938D-30BD-45A0-81DC-8502D3051D9B}\RP96\A0006074.dll -> Adware.Look2Me : Cleaned with backup
C:\System Volume Information\_restore{9E75938D-30BD-45A0-81DC-8502D3051D9B}\RP96\A0006075.exe/kansup.reg -> Trojan.LowZones.f : Error during cleaning
C:\System Volume Information\_restore{9E75938D-30BD-45A0-81DC-8502D3051D9B}\RP96\A0006075.exe/grimy.exe -> Downloader.VB.ws : Error during cleaning
C:\System Volume Information\_restore{9E75938D-30BD-45A0-81DC-8502D3051D9B}\RP96\A0006095.exe -> Trojan.Pakes : Cleaned with backup
C:\System Volume Information\_restore{9E75938D-30BD-45A0-81DC-8502D3051D9B}\RP96\A0006188.reg -> Trojan.LowZones.f : Cleaned with backup
C:\System Volume Information\_restore{9E75938D-30BD-45A0-81DC-8502D3051D9B}\RP96\A0006189.exe -> Downloader.VB.ws : Cleaned with backup
C:\System Volume Information\_restore{9E75938D-30BD-45A0-81DC-8502D3051D9B}\RP96\A0006191.scr -> Worm.SpyBot.gl : Cleaned with backup
C:\System Volume Information\_restore{9E75938D-30BD-45A0-81DC-8502D3051D9B}\RP96\A0006199.exe -> Downloader.Adload.u : Cleaned with backup
C:\System Volume Information\_restore{9E75938D-30BD-45A0-81DC-8502D3051D9B}\RP96\A0006200.exe -> Downloader.Adload.u : Cleaned with backup
C:\System Volume Information\_restore{9E75938D-30BD-45A0-81DC-8502D3051D9B}\RP96\A0006201.exe/kansup.reg -> Trojan.LowZones.f : Error during cleaning
C:\System Volume Information\_restore{9E75938D-30BD-45A0-81DC-8502D3051D9B}\RP96\A0006201.exe/grimy.exe -> Downloader.VB.ws : Error during cleaning
C:\System Volume Information\_restore{9E75938D-30BD-45A0-81DC-8502D3051D9B}\RP96\A0006206.exe -> Downloader.Adload.u : Cleaned with backup
C:\System Volume Information\_restore{9E75938D-30BD-45A0-81DC-8502D3051D9B}\RP96\A0006207.exe/kansup.reg -> Trojan.LowZones.f : Error during cleaning
C:\System Volume Information\_restore{9E75938D-30BD-45A0-81DC-8502D3051D9B}\RP96\A0006207.exe/grimy.exe -> Downloader.VB.ws : Error during cleaning
C:\System Volume Information\_restore{9E75938D-30BD-45A0-81DC-8502D3051D9B}\RP96\A0006209.dll -> Adware.Look2Me : Cleaned with backup
C:\System Volume Information\_restore{9E75938D-30BD-45A0-81DC-8502D3051D9B}\RP96\A0006225.exe/kansup.reg -> Trojan.LowZones.f : Error during cleaning
C:\System Volume Information\_restore{9E75938D-30BD-45A0-81DC-8502D3051D9B}\RP96\A0006225.exe/grimy.exe -> Downloader.VB.ws : Error during cleaning
C:\System Volume Information\_restore{9E75938D-30BD-45A0-81DC-8502D3051D9B}\RP96\A0006237.exe/kansup.reg -> Trojan.LowZones.f : Error during cleaning
C:\System Volume Information\_restore{9E75938D-30BD-45A0-81DC-8502D3051D9B}\RP96\A0006237.exe/grimy.exe -> Downloader.VB.ws : Error during cleaning
C:\System Volume Information\_restore{9E75938D-30BD-45A0-81DC-8502D3051D9B}\RP97\A0006243.exe/kansup.reg -> Trojan.LowZones.f : Error during cleaning
C:\System Volume Information\_restore{9E75938D-30BD-45A0-81DC-8502D3051D9B}\RP97\A0006243.exe/grimy.exe -> Downloader.VB.ws : Error during cleaning
C:\System Volume Information\_restore{9E75938D-30BD-45A0-81DC-8502D3051D9B}\RP97\A0006259.exe/kansup.reg -> Trojan.LowZones.f : Error during cleaning
C:\System Volume Information\_restore{9E75938D-30BD-45A0-81DC-8502D3051D9B}\RP97\A0006259.exe/grimy.exe -> Downloader.VB.ws : Error during cleaning
C:\System Volume Information\_restore{9E75938D-30BD-45A0-81DC-8502D3051D9B}\RP98\A0006308.exe/kansup.reg -> Trojan.LowZones.f : Error during cleaning
C:\System Volume Information\_restore{9E75938D-30BD-45A0-81DC-8502D3051D9B}\RP98\A0006308.exe/grimy.exe -> Downloader.VB.ws : Error during cleaning
C:\System Volume Information\_restore{9E75938D-30BD-45A0-81DC-8502D3051D9B}\RP99\A0006312.reg -> Trojan.LowZones.f : Cleaned with backup
C:\System Volume Information\_restore{9E75938D-30BD-45A0-81DC-8502D3051D9B}\RP99\A0006313.exe -> Downloader.VB.ws : Cleaned with backup
C:\System Volume Information\_restore{9E75938D-30BD-45A0-81DC-8502D3051D9B}\RP99\A0006314.exe/kansup.reg -> Trojan.LowZones.f : Error during cleaning
C:\System Volume Information\_restore{9E75938D-30BD-45A0-81DC-8502D3051D9B}\RP99\A0006314.exe/grimy.exe -> Downloader.VB.ws : Error during cleaning
C:\System Volume Information\_restore{9E75938D-30BD-45A0-81DC-8502D3051D9B}\RP99\A0006317.dll -> Hijacker.Small.jf : Cleaned with backup
C:\System Volume Information\_restore{9E75938D-30BD-45A0-81DC-8502D3051D9B}\RP99\A0006321.exe/kansup.reg -> Trojan.LowZones.f : Error during cleaning
C:\System Volume Information\_restore{9E75938D-30BD-45A0-81DC-8502D3051D9B}\RP99\A0006321.exe/grimy.exe -> Downloader.VB.ws : Error during cleaning
C:\System Volume Information\_restore{9E75938D-30BD-45A0-81DC-8502D3051D9B}\RP100\A0006345.reg -> Trojan.LowZones.f : Cleaned with backup
C:\System Volume Information\_restore{9E75938D-30BD-45A0-81DC-8502D3051D9B}\RP100\A0006346.exe -> Downloader.VB.ws : Cleaned with backup
C:\System Volume Information\_restore{9E75938D-30BD-45A0-81DC-8502D3051D9B}\RP100\A0006347.exe -> Downloader.Adload.u : Cleaned with backup
C:\System Volume Information\_restore{9E75938D-30BD-45A0-81DC-8502D3051D9B}\RP100\A0006349.exe/kansup.reg -> Trojan.LowZones.f : Error during cleaning
C:\System Volume Information\_restore{9E75938D-30BD-45A0-81DC-8502D3051D9B}\RP100\A0006349.exe/grimy.exe -> Downloader.VB.ws : Error during cleaning
C:\System Volume Information\_restore{9E75938D-30BD-45A0-81DC-8502D3051D9B}\RP100\A0006354.exe -> Downloader.Small.buy : Cleaned with backup
C:\System Volume Information\_restore{9E75938D-30BD-45A0-81DC-8502D3051D9B}\RP100\A0006355.exe/UCMTSAIE.DLL -> Adware.Ucmore : Error during cleaning
C:\System Volume Information\_restore{9E75938D-30BD-45A0-81DC-8502D3051D9B}\RP100\A0006355.exe/IUCMORE.DLL -> Adware.Ucmore : Error during cleaning
C:\System Volume Information\_restore{9E75938D-30BD-45A0-81DC-8502D3051D9B}\RP100\A0006356.exe -> Hijacker.VB.li : Cleaned with backup
C:\System Volume Information\_restore{9E75938D-30BD-45A0-81DC-8502D3051D9B}\RP100\A0006358.exe/kansup.reg -> Trojan.LowZones.f : Error during cleaning
C:\System Volume Information\_restore{9E75938D-30BD-45A0-81DC-8502D3051D9B}\RP100\A0006358.exe/grimy.exe -> Downloader.VB.ws : Error during cleaning
C:\System Volume Information\_restore{9E75938D-30BD-45A0-81DC-8502D3051D9B}\RP100\A0006360.exe -> Downloader.Adload.u : Cleaned with backup
C:\System Volume Information\_restore{9E75938D-30BD-45A0-81DC-8502D3051D9B}\RP100\A0006361.exe -> Downloader.Adload.v : Cleaned with backup
C:\System Volume Information\_restore{9E75938D-30BD-45A0-81DC-8502D3051D9B}\RP100\A0006362.exe -> Adware.Look2Me : Cleaned with backup
C:\System Volume Information\_restore{9E75938D-30BD-45A0-81DC-8502D3051D9B}\RP100\A0006363.exe -> Downloader.Qoologic.bh : Cleaned with backup
C:\System Volume Information\_restore{9E75938D-30BD-45A0-81DC-8502D3051D9B}\RP100\A0006368.dll -> Adware.Look2Me : Cleaned with backup
C:\System Volume Information\_restore{9E75938D-30BD-45A0-81DC-8502D3051D9B}\RP100\A0006369.exe -> Adware.CommAd : Cleaned with backup
C:\System Volume Information\_restore{9E75938D-30BD-45A0-81DC-8502D3051D9B}\RP100\A0006370.dll -> Adware.CommAd : Cleaned with backup
C:\System Volume Information\_restore{9E75938D-30BD-45A0-81DC-8502D3051D9B}\RP100\A0006371.exe -> Not-A-Virus.Monitor.Win32.NetMon.a : Cleaned with backup
C:\System Volume Information\_restore{9E75938D-30BD-45A0-81DC-8502D3051D9B}\RP100\A0006378.exe/kansup.reg -> Trojan.LowZones.f : Error during cleaning
C:\System Volume Information\_restore{9E75938D-30BD-45A0-81DC-8502D3051D9B}\RP100\A0006378.exe/grimy.exe -> Downloader.VB.ws : Error during cleaning
C:\System Volume Information\_restore{9E75938D-30BD-45A0-81DC-8502D3051D9B}\RP100\A0006380.exe -> Hijacker.VB.li : Cleaned with backup
C:\System Volume Information\_restore{9E75938D-30BD-45A0-81DC-8502D3051D9B}\RP100\A0006381.dll -> Hijacker.Small.jf : Cleaned with backup
C:\System Volume Information\_restore{9E75938D-30BD-45A0-81DC-8502D3051D9B}\RP100\A0006383.dll -> Adware.Look2Me : Cleaned with backup
C:\System Volume Information\_restore{9E75938D-30BD-45A0-81DC-8502D3051D9B}\RP100\A0006387.exe/kansup.reg -> Trojan.LowZones.f : Error during cleaning
C:\System Volume Information\_restore{9E75938D-30BD-45A0-81DC-8502D3051D9B}\RP100\A0006387.exe/grimy.exe -> Downloader.VB.ws : Error during cleaning
C:\System Volume Information\_restore{9E75938D-30BD-45A0-81DC-8502D3051D9B}\RP101\A0006395.dll -> Adware.Look2Me : Cleaned with backup
C:\System Volume Information\_restore{9E75938D-30BD-45A0-81DC-8502D3051D9B}\RP101\A0006403.exe -> Worm.SpyBot.gl : Cleaned with backup
C:\System Volume Information\_restore{9E75938D-30BD-45A0-81DC-8502D3051D9B}\RP101\A0006411.exe/kansup.reg -> Trojan.LowZones.f : Error during cleaning
C:\System Volume Information\_restore{9E75938D-30BD-45A0-81DC-8502D3051D9B}\RP101\A0006411.exe/grimy.exe -> Downloader.VB.ws : Error during cleaning
C:\System Volume Information\_restore{9E75938D-30BD-45A0-81DC-8502D3051D9B}\RP101\A0006413.exe -> Worm.SpyBot.gl : Cleaned with backup
C:\System Volume Information\_restore{9E75938D-30BD-45A0-81DC-8502D3051D9B}\RP101\A0006414.exe -> Worm.SpyBot.gl : Cleaned with backup
C:\System Volume Information\_restore{9E75938D-30BD-45A0-81DC-8502D3051D9B}\RP101\A0006448.dll -> Adware.Look2Me : Cleaned with backup
C:\System Volume Information\_restore{9E75938D-30BD-45A0-81DC-8502D3051D9B}\RP101\A0006456.exe -> Worm.SpyBot.gl : Cleaned with backup
C:\System Volume Information\_restore{9E75938D-30BD-45A0-81DC-8502D3051D9B}\RP101\A0006460.reg -> Trojan.LowZones.f : Cleaned with backup
C:\System Volume Information\_restore{9E75938D-30BD-45A0-81DC-8502D3051D9B}\RP101\A0006461.exe -> Downloader.VB.ws : Cleaned with backup
C:\System Volume Information\_restore{9E75938D-30BD-45A0-81DC-8502D3051D9B}\RP101\A0006462.exe/kansup.reg -> Trojan.LowZones.f : Error during cleaning
C:\System Volume Information\_restore{9E75938D-30BD-45A0-81DC-8502D3051D9B}\RP101\A0006462.exe/grimy.exe -> Downloader.VB.ws : Error during cleaning
C:\System Volume Information\_restore{9E75938D-30BD-45A0-81DC-8502D3051D9B}\RP101\A0006465.exe -> Downloader.Adload.u : Cleaned with backup
C:\System Volume Information\_restore{9E75938D-30BD-45A0-81DC-8502D3051D9B}\RP101\A0006468.exe -> Downloader.VB.xv : Cleaned with backup
C:\System Volume Information\_restore{9E75938D-30BD-45A0-81DC-8502D3051D9B}\RP101\A0006486.exe -> Worm.SpyBot.gl : Cleaned with backup
C:\System Volume Information\_restore{9E75938D-30BD-45A0-81DC-8502D3051D9B}\RP101\A0006489.dll -> Adware.Look2Me : Cleaned with backup
C:\System Volume Information\_restore{9E75938D-30BD-45A0-81DC-8502D3051D9B}\RP101\A0006493.exe/kansup.reg -> Trojan.LowZones.f : Error during cleaning
C:\System Volume Information\_restore{9E75938D-30BD-45A0-81DC-8502D3051D9B}\RP101\A0006493.exe/grimy.exe -> Downloader.VB.ws : Error during cleaning
C:\System Volume Information\_restore{9E75938D-30BD-45A0-81DC-8502D3051D9B}\RP101\A0006494.exe -> Worm.SpyBot.gl : Cleaned with backup
C:\System Volume Information\_restore{9E75938D-30BD-45A0-81DC-8502D3051D9B}\RP101\A0006495.dll -> Adware.Look2Me : Cleaned with backup
C:\System Volume Information\_restore{9E75938D-30BD-45A0-81DC-8502D3051D9B}\RP101\A0006498.exe/UCMTSAIE.DLL -> Adware.Ucmore : Error during cleaning
C:\System Volume Information\_restore{9E75938D-30BD-45A0-81DC-8502D3051D9B}\RP101\A0006498.exe/IUCMORE.DLL -> Adware.Ucmore : Error during cleaning
C:\System Volume Information\_restore{9E75938D-30BD-45A0-81DC-8502D3051D9B}\RP101\A0006499.exe -> Downloader.VB.xv : Cleaned with backup
C:\System Volume Information\_restore{9E75938D-30BD-45A0-81DC-8502D3051D9B}\RP101\A0006500.exe -> Worm.SpyBot.gl : Cleaned with backup
C:\System Volume Information\_restore{9E75938D-30BD-45A0-81DC-8502D3051D9B}\RP101\A0006501.exe -> Downloader.VB.xu : Cleaned with backup
C:\System Volume Information\_restore{9E75938D-30BD-45A0-81DC-8502D3051D9B}\RP101\A0006502.exe -> Downloader.Adload.u : Cleaned with backup
C:\System Volume Information\_restore{9E75938D-30BD-45A0-81DC-8502D3051D9B}\RP103\A0006506.dll -> Adware.Look2Me : Cleaned with backup
C:\System Volume Information\_restore{9E75938D-30BD-45A0-81DC-8502D3051D9B}\RP103\A0006510.dll -> Adware.Look2Me : Cleaned with backup
C:\System Volume Information\_restore{9E75938D-30BD-45A0-81DC-8502D3051D9B}\RP103\A0006513.reg -> Trojan.LowZones.f : Cleaned with backup
C:\System Volume Information\_restore{9E75938D-30BD-45A0-81DC-8502D3051D9B}\RP103\A0006514.exe -> Downloader.VB.ws : Cleaned with backup
C:\System Volume Information\_restore{9E75938D-30BD-45A0-81DC-8502D3051D9B}\RP103\A0006520.exe -> Worm.SpyBot.gl : Cleaned with backup
C:\System Volume Information\_restore{9E75938D-30BD-45A0-81DC-8502D3051D9B}\RP103\A0006521.exe -> Adware.Look2Me : Cleaned with backup
C:\System Volume Information\_restore{9E75938D-30BD-45A0-81DC-8502D3051D9B}\RP103\A0006522.exe/kansup.reg -> Trojan.LowZones.f : Error during cleaning
C:\System Volume Information\_restore{9E75938D-30BD-45A0-81DC-8502D3051D9B}\RP103\A0006522.exe/grimy.exe -> Downloader.VB.ws : Error during cleaning
C:\System Volume Information\_restore{9E75938D-30BD-45A0-81DC-8502D3051D9B}\RP103\A0006523.exe -> Downloader.VB.xv : Cleaned with backup
C:\System Volume Information\_restore{9E75938D-30BD-45A0-81DC-8502D3051D9B}\RP103\A0006524.exe -> Downloader.Adload.u : Cleaned with backup
C:\System Volume Information\_restore{9E75938D-30BD-45A0-81DC-8502D3051D9B}\RP103\A0006525.exe -> Downloader.VB.xu : Cleaned with backup
C:\System Volume Information\_restore{9E75938D-30BD-45A0-81DC-8502D3051D9B}\RP103\A0006526.exe -> Downloader.VB.xv : Cleaned with backup
C:\System Volume Information\_restore{9E75938D-30BD-45A0-81DC-8502D3051D9B}\RP104\A0006529.dll -> Adware.Look2Me : Cleaned with backup
C:\System Volume Information\_restore{9E75938D-30BD-45A0-81DC-8502D3051D9B}\RP104\A0006535.reg -> Trojan.LowZones.f : Cleaned with backup
C:\System Volume Information\_restore{9E75938D-30BD-45A0-81DC-8502D3051D9B}\RP104\A0006536.exe -> Downloader.VB.ws : Cleaned with backup
C:\System Volume Information\_restore{9E75938D-30BD-45A0-81DC-8502D3051D9B}\RP104\A0006566.exe -> Adware.Look2Me : Cleaned with backup
C:\System Volume Information\_restore{9E75938D-30BD-45A0-81DC-8502D3051D9B}\RP104\A0006567.exe/UCMTSAIE.DLL -> Adware.Ucmore : Error during cleaning
C:\System Volume Information\_restore{9E75938D-30BD-45A0-81DC-8502D3051D9B}\RP104\A0006567.exe/IUCMORE.DLL -> Adware.Ucmore : Error during cleaning
C:\System Volume Information\_restore{9E75938D-30BD-45A0-81DC-8502D3051D9B}\RP104\A0006568.exe/kansup.reg -> Trojan.LowZones.f : Error during cleaning
C:\System Volume Information\_restore{9E75938D-30BD-45A0-81DC-8502D3051D9B}\RP104\A0006568.exe/grimy.exe -> Downloader.VB.ws : Error during cleaning
C:\System Volume Information\_restore{9E75938D-30BD-45A0-81DC-8502D3051D9B}\RP104\A0006569.exe -> Downloader.Adload.u : Cleaned with backup
C:\System Volume Information\_restore{9E75938D-30BD-45A0-81DC-8502D3051D9B}\RP104\A0006570.exe -> Downloader.VB.xu : Cleaned with backup
C:\System Volume Information\_restore{9E75938D-30BD-45A0-81DC-8502D3051D9B}\RP104\A0006571.exe -> Downloader.Small.buy : Cleaned with backup
C:\System Volume Information\_restore{9E75938D-30BD-45A0-81DC-8502D3051D9B}\RP104\A0006572.exe -> Worm.SpyBot.gl : Cleaned with backup
C:\System Volume Information\_restore{9E75938D-30BD-45A0-81DC-8502D3051D9B}\RP104\A0006573.exe -> Downloader.VB.xv : Cleaned with backup
C:\System Volume Information\_restore{9E75938D-30BD-45A0-81DC-8502D3051D9B}\RP104\A0006574.exe -> Hijacker.VB.li : Cleaned with backup
C:\System Volume Information\_restore{9E75938D-30BD-45A0-81DC-8502D3051D9B}\RP104\A0006575.exe/kansup.reg -> Trojan.LowZones.f : Error during cleaning
C:\System Volume Information\_restore{9E75938D-30BD-45A0-81DC-8502D3051D9B}\RP104\A0006575.exe/grimy.exe -> Downloader.VB.ws : Error during cleaning
C:\System Volume Information\_restore{9E75938D-30BD-45A0-81DC-8502D3051D9B}\RP104\A0006576.exe -> Downloader.Adload.u : Cleaned with backup
C:\System Volume Information\_restore{9E75938D-30BD-45A0-81DC-8502D3051D9B}\RP104\A0006577.exe -> Worm.SpyBot.gl : Cleaned with backup
C:\System Volume Information\_restore{9E75938D-30BD-45A0-81DC-8502D3051D9B}\RP104\A0006578.dll -> Adware.Look2Me : Cleaned with backup
C:\System Volume Information\_restore{9E75938D-30BD-45A0-81DC-8502D3051D9B}\RP104\A0006579.dll -> Adware.Look2Me : Cleaned with backup
C:\System Volume Information\_restore{9E75938D-30BD-45A0-81DC-8502D3051D9B}\RP104\A0006581.exe -> Trojan.VB.ajo : Cleaned with backup
C:\System Volume Information\_restore{9E75938D-30BD-45A0-81DC-8502D3051D9B}\RP104\A0006585.dll -> Adware.CommAd : Cleaned with backup
C:\System Volume Information\_restore{9E75938D-30BD-45A0-81DC-8502D3051D9B}\RP104\A0006589.exe -> Worm.SpyBot.gl : Cleaned with backup
C:\System Volume Information\_restore{9E75938D-30BD-45A0-81DC-8502D3051D9B}\RP104\A0006592.exe -> Worm.SpyBot.gl : Cleaned with backup
C:\System Volume Information\_restore{9E75938D-30BD-45A0-81DC-8502D3051D9B}\RP104\A0006596.exe -> Downloader.VB.ws : Cleaned with backup
C:\System Volume Information\_restore{9E75938D-30BD-45A0-81DC-8502D3051D9B}\RP104\A0006602.exe/kansup.reg -> Trojan.LowZones.f : Error during cleaning
C:\System Volume Information\_restore{9E75938D-30BD-45A0-81DC-8502D3051D9B}\RP104\A0006602.exe/grimy.exe -> Downloader.VB.ws : Error during cleaning
C:\System Volume Information\_restore{9E75938D-30BD-45A0-81DC-8502D3051D9B}\RP104\A0006605.reg -> Trojan.LowZones.f : Cleaned with backup
C:\System Volume Information\_restore{9E75938D-30BD-45A0-81DC-8502D3051D9B}\RP104\A0006606.exe -> Downloader.VB.ws : Cleaned with backup
C:\System Volume Information\_restore{9E75938D-30BD-45A0-81DC-8502D3051D9B}\RP105\A0006634.dll -> Adware.Look2Me : Cleaned with backup
C:\System Volume Information\_restore{9E75938D-30BD-45A0-81DC-8502D3051D9B}\RP105\A0006635.exe -> Worm.SpyBot.gl : Cleaned with backup
C:\System Volume Information\_restore{9E75938D-30BD-45A0-81DC-8502D3051D9B}\RP106\A0006692.exe -> Worm.SpyBot.gl : Cleaned with backup
C:\System Volume Information\_restore{9E75938D-30BD-45A0-81DC-8502D3051D9B}\RP106\A0006696.dll -> Adware.Look2Me : Cleaned with backup
C:\System Volume Information\_restore{9E75938D-30BD-45A0-81DC-8502D3051D9B}\RP107\A0006705.exe -> Worm.SpyBot.gl : Cleaned with backup
C:\System Volume Information\_restore{9E75938D-30BD-45A0-81DC-8502D3051D9B}\RP107\A0006707.dll -> Adware.Look2Me : Cleaned with backup
C:\System Volume Information\_restore{9E75938D-30BD-45A0-81DC-8502D3051D9B}\RP108\A0006715.exe -> Worm.SpyBot.gl : Cleaned with backup
C:\System Volume Information\_restore{9E75938D-30BD-45A0-81DC-8502D3051D9B}\RP108\A0006717.dll -> Adware.Look2Me : Cleaned with backup
C:\System Volume Information\_restore{9E75938D-30BD-45A0-81DC-8502D3051D9B}\RP108\A0006718.reg -> Trojan.LowZones.f : Cleaned with backup
C:\System Volume Information\_restore{9E75938D-30BD-45A0-81DC-8502D3051D9B}\RP109\A0006721.exe -> Worm.SpyBot.gl : Cleaned with backup
C:\System Volume Information\_restore{9E75938D-30BD-45A0-81DC-8502D3051D9B}\RP110\A0006738.exe -> Worm.SpyBot.gl : Cleaned with backup
C:\System Volume Information\_restore{9E75938D-30BD-45A0-81DC-8502D3051D9B}\RP111\A0006743.exe -> Worm.SpyBot.gl : Cleaned with backup
C:\System Volume Information\_restore{9E75938D-30BD-45A0-81DC-8502D3051D9B}\RP111\A0007710.exe -> Worm.SpyBot.gl : Cleaned with backup
C:\System Volume Information\_restore{9E75938D-30BD-45A0-81DC-8502D3051D9B}\RP111\A0007713.dll -> Adware.Look2Me : Cleaned with backup
C:\System Volume Information\_restore{9E75938D-30BD-45A0-81DC-8502D3051D9B}\RP111\A0007723.exe -> Downloader.VB.ws : Cleaned with backup
C:\System Volume Information\_restore{9E75938D-30BD-45A0-81DC-8502D3051D9B}\RP112\A0007726.dll -> Adware.Look2Me : Cleaned with backup
C:\System Volume Information\_restore{9E75938D-30BD-45A0-81DC-8502D3051D9B}\RP112\A0007730.dll -> Adware.Look2Me : Cleaned with backup
C:\System Volume Information\_restore{9E75938D-30BD-45A0-81DC-8502D3051D9B}\RP112\A0007731.exe/kansup.reg -> Trojan.LowZones.f : Error during cleaning
C:\System Volume Information\_restore{9E75938D-30BD-45A0-81DC-8502D3051D9B}\RP112\A0007733.reg -> Trojan.LowZones.f : Cleaned with backup
C:\System Volume Information\_restore{9E75938D-30BD-45A0-81DC-8502D3051D9B}\RP112\A0007740.exe -> Worm.SpyBot.gl : Cleaned with backup
C:\System Volume Information\_restore{9E75938D-30BD-45A0-81DC-8502D3051D9B}\RP112\A0007742.exe -> Dropper.Agent.mf : Cleaned with backup
C:\System Volume Information\_restore{9E75938D-30BD-45A0-81DC-8502D3051D9B}\RP112\A0007745.exe/kansup.reg -> Trojan.LowZones.f : Error during cleaning
C:\System Volume Information\_restore{9E75938D-30BD-45A0-81DC-8502D3051D9B}\RP112\A0007745.exe/grimy.exe -> Downloader.VB.ws : Error during cleaning
C:\System Volume Information\_restore{9E75938D-30BD-45A0-81DC-8502D3051D9B}\RP112\A0007746.exe -> Downloader.Adload.x : Cleaned with backup
C:\System Volume Information\_restore{9E75938D-30BD-45A0-81DC-8502D3051D9B}\RP112\A0007752.dll -> Adware.Look2Me : Cleaned with backup
C:\System Volume Information\_restore{9E75938D-30BD-45A0-81DC-8502D3051D9B}\RP112\A0007753.dll -> Adware.Look2Me : Cleaned with backup
::Report End
HIJACK THIS REPORT:
Logfile of HijackThis v1.99.1
Scan saved at 10:11:26 PM, on 3/16/2006
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Windows Defender\MsMpEng.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\System32\hkcmd.exe
C:\WINDOWS\System32\igfxpers.exe
C:\WINDOWS\BCMSMMSG.exe
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\WINDOWS\System32\igfxsrvc.exe
C:\PROGRA~1\Grisoft\AVG6\avgcc32.exe
C:\Program Files\Java\jre1.5.0_06\bin\jusched.exe
C:\Program Files\Hewlett-Packard\HP Software Update\HPWuSchd.exe
C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpotdd01.exe
C:\WINDOWS\System32\spool\drivers\w32x86\3\hpztsb08.exe
C:\PROGRA~1\MUSICM~1\MUSICM~2\MMDiag.exe
C:\Program Files\Windows Defender\MSASCui.exe
C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe
C:\Program Files\Webroot\Spy Sweeper\SpySweeper.exe
C:\Program Files\Messenger\msmsgs.exe
C:\Program Files\MSN Messenger\MsnMsgr.Exe
C:\Program Files\Musicmatch\Musicmatch Jukebox\mim.exe
C:\Program Files\Google\Google Desktop Search\GoogleDesktopIndex.exe
C:\Program Files\Google\Google Desktop Search\GoogleDesktopCrawl.exe
C:\PROGRA~1\Grisoft\AVG6\avgserv.exe
C:\Program Files\Webroot\Spy Sweeper\WRSSSDK.exe
C:\WINDOWS\system32\wscntfy.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Program Files\ewido anti-malware\ewidoctrl.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\PROGRA~1\WINZIP\winzip32.exe
C:\unzipped\hijackthis\HijackThis.exe
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page =
http://go.microsoft....B_PVER}&ar=home
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll
O4 - HKLM\..\Run: [igfxtray] C:\WINDOWS\System32\igfxtray.exe
O4 - HKLM\..\Run: [igfxhkcmd] C:\WINDOWS\System32\hkcmd.exe
O4 - HKLM\..\Run: [igfxpers] C:\WINDOWS\System32\igfxpers.exe
O4 - HKLM\..\Run: [BCMSMMSG] BCMSMMSG.exe
O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
O4 - HKLM\..\Run: [AVG_CC] C:\PROGRA~1\Grisoft\AVG6\avgcc32.exe /STARTUP
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre1.5.0_06\bin\jusched.exe
O4 - HKLM\..\Run: [MimBoot] C:\PROGRA~1\MUSICM~1\MUSICM~2\mimboot.exe
O4 - HKLM\..\Run: [HP Software Update] C:\Program Files\Hewlett-Packard\HP Software Update\HPWuSchd.exe
O4 - HKLM\..\Run: [DeviceDiscovery] C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpotdd01.exe
O4 - HKLM\..\Run: [HPDJ Taskbar Utility] C:\WINDOWS\System32\spool\drivers\w32x86\3\hpztsb08.exe
O4 - HKLM\..\Run: [Windows Defender] "C:\Program Files\Windows Defender\MSASCui.exe" -hide
O4 - HKLM\..\Run: [Google Desktop Search] "C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe" /startup
O4 - HKLM\..\Run: [keyboard] c:\\keyboard.exe
O4 - HKLM\..\Run: [SpySweeper] "C:\Program Files\Webroot\Spy Sweeper\SpySweeper.exe" /startintray
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\MSN Messenger\MsnMsgr.Exe" /background
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
O4 - Global Startup: InterVideo WinCinema Manager.lnk = C:\Program Files\InterVideo\Common\Bin\WinCinemaMgr.exe
O8 - Extra context menu item: &Google Search - res://C:\Program Files\Google\GoogleToolbar1.dll/cmsearch.html
O8 - Extra context menu item: &Translate English Word - res://C:\Program Files\Google\GoogleToolbar1.dll/cmwordtrans.html
O8 - Extra context menu item: Backward Links - res://C:\Program Files\Google\GoogleToolbar1.dll/cmbacklinks.html
O8 - Extra context menu item: Cached Snapshot of Page - res://C:\Program Files\Google\GoogleToolbar1.dll/cmcache.html
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
O8 - Extra context menu item: Similar Pages - res://C:\Program Files\Google\GoogleToolbar1.dll/cmsimilar.html
O8 - Extra context menu item: Translate Page into English - res://C:\Program Files\Google\GoogleToolbar1.dll/cmtrans.html
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) -
http://update.micros...b?1139811308040
O16 - DPF: {7F4824E8-21D1-4A62-BD34-AB670833DFB6} (MSN Money Screener) -
http://moneycentral....bs/pmupd806.exe
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - "C:\PROGRA~1\MSNMES~1\msgrapp.dll" (file missing)
O20 - AppInit_DLLs: C:\PROGRA~1\Google\GOOGLE~2\GOEC62~1.DLL
O23 - Service: AVG6 Service (AvgServ) - GRISOFT© SOFTWARE s.r.o - C:\PROGRA~1\Grisoft\AVG6\avgserv.exe
O23 - Service: ewido security suite control - ewido networks - C:\Program Files\ewido anti-malware\ewidoctrl.exe
O23 - Service: hpdj - Unknown owner - C:\DOCUME~1\Owner\LOCALS~1\Temp\hpdj.exe (file missing)
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: iPodService - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: Webroot Spy Sweeper Engine (svcWRSSSDK) - Webroot Software, Inc. - C:\Program Files\Webroot\Spy Sweeper\WRSSSDK.exe