Scan performed at: 05/04/2006 21:44:29 Scanning Log NOD32 version 1.1473 (20060405) NT Date: 5.4.2006 Time: 21:45:04 Scanned disks, folders and files: C: C:\drsmartload1.exe - a variant of Win32/TrojanDownloader.Adload.NAD trojan C:\drsmartload45a.exe - a variant of Win32/TrojanDownloader.Adload.AJ trojan C:\Installer.exe - Win32/Adware.Look2Me application C:\MTE3NDI6ODoxNg.exe - Win32/TrojanDownloader.Small.BUY trojan C:\pagefile.sys - error opening (File locked) [4] C:\sk02.exe »NSIS »DH.dll_ - Win32/TrojanClicker.Small.JF trojan C:\stub_113_4_0_4_0.exe - Win32/TrojanDownloader.TSUpdate.O trojan C:\Veracruz.exe »NSIS »DR_SudokuInstaller.exe »NSIS »Sudoku.exe - probably a variant of Win32/Adware.MediaTickets application C:\WHCC2.exe »RAR »whAgent.exe - Win32/Adware.Webhancer.A application C:\WHCC2.exe »RAR »whSurvey.exe - Win32/Adware.Webhancer.381 application C:\WHCC2.exe »RAR »webhdll.dll - Win32/Adware.Webhancer.381 application C:\WHCC2.exe »RAR »whiehlpr.dll - Win32/Adware.Webhancer.381 application C:\Documents and Settings\Administrator\NTUSER.DAT - error opening (File locked) [4] C:\Documents and Settings\Administrator\ntuser.dat.LOG - error opening (File locked) [4] C:\Documents and Settings\Administrator\Desktop\cursorcafewrap.exe »NSIS »cursorcafe.exe »NSIS »CursorCafeInst.dll - a variant of Win32/Adware.Comet application C:\Documents and Settings\Administrator\Desktop\drsmartload45a.exe - a variant of Win32/TrojanDownloader.Adload.AJ trojan C:\Documents and Settings\Administrator\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat - error opening (File locked) [4] C:\Documents and Settings\Administrator\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG - error opening (File locked) [4] C:\Documents and Settings\Administrator\Local Settings\Temp\i6C.tmp - a variant of Win32/Adware.SurfSideKick application C:\Documents and Settings\Administrator\Local Settings\Temp\tsinstall_4_0_4_0_b4.exe »WISE »TSM - Win32/TrojanDownloader.TSUpdate.N trojan C:\Documents and Settings\Administrator\Local Settings\Temp\tsinstall_4_0_4_0_b4.exe »WISE »TSL - Win32/TrojanDownloader.TSUpdate.P trojan C:\Documents and Settings\Administrator\Local Settings\Temp\tsinstall_4_0_4_0_b4.exe »WISE »TS - Win32/TrojanDownloader.TSUpdate.L trojan C:\Documents and Settings\Administrator\Local Settings\Temp\tsinstall_4_0_4_0_b4.exe »WISE »TSP - Win32/TrojanDownloader.TSUpdate.F trojan C:\Documents and Settings\Administrator\Local Settings\Temp\tsinstall_4_0_4_0_b4.exe »WISE »vocabulary - Win32/TrojanDownloader.TSUpdate.J trojan C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\Y5SX8B2P\drsmartload[1].exe - a variant of Win32/TrojanDownloader.Adload.NAD trojan C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\AlexaRelated.zip »ZIP »RELATED.HTM - error - password-protected file C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\AlexaRelated.zip »ZIP »sbRecovery.ini - error - password-protected file C:\Program Files\Aquatica Waterworlds\AQ3Helper.exe - Win32/Adware.Gator application C:\Program Files\Common Files\rrzu\rrzua.exe - Win32/TrojanDownloader.TSUpdate.L trojan C:\Program Files\Common Files\rrzu\rrzul.exe - Win32/TrojanDownloader.TSUpdate.P trojan C:\Program Files\Common Files\rrzu\rrzum.exe - Win32/TrojanDownloader.TSUpdate.N trojan C:\Program Files\Common Files\rrzu\rrzup.exe - Win32/TrojanDownloader.TSUpdate.F trojan C:\Program Files\Common Files\rrzu\rrzud\vocabulary - Win32/TrojanDownloader.TSUpdate.J trojan C:\Program Files\CursorCafe\bin\cursorcafe.exe »NSIS »CursorCafeInst.dll - a variant of Win32/Adware.Comet application C:\Program Files\CursorCafe\installer\bin\CursorCafeInst.dll - a variant of Win32/Adware.Comet application C:\Program Files\HbTools\bin\4.7.5.0\HbTools.exe »NSIS »ShopperReports.exe »NSIS »ShprRprt.dll - Win32/Adware.Toolbar.Shopper application C:\Program Files\Lavasoft\Ad-Aware SE Personal\Skins\Ad-Aware SE default.ask »ZIP »Ad-Aware SE Default.skn - error - password-protected file C:\Program Files\Lavasoft\Ad-Aware SE Personal\Skins\Ad-Aware SE default.ask »ZIP »arrow1.bmp - error - password-protected file C:\Program Files\Lavasoft\Ad-Aware SE Personal\Skins\Ad-Aware SE default.ask »ZIP »arrow2.bmp - error - password-protected file C:\Program Files\Lavasoft\Ad-Aware SE Personal\Skins\Ad-Aware SE default.ask »ZIP »bck1.bmp - error - password-protected file C:\Program Files\Lavasoft\Ad-Aware SE Personal\Skins\Ad-Aware SE default.ask »ZIP »bt11.bmp - error - password-protected file C:\Program Files\Lavasoft\Ad-Aware SE Personal\Skins\Ad-Aware SE default.ask »ZIP »bt12.bmp - error - password-protected file C:\Program Files\Lavasoft\Ad-Aware SE Personal\Skins\Ad-Aware SE default.ask »ZIP »bt13.bmp - error - password-protected file C:\Program Files\Lavasoft\Ad-Aware SE Personal\Skins\Ad-Aware SE default.ask »ZIP »bt21.bmp - error - password-protected file C:\Program Files\Lavasoft\Ad-Aware SE Personal\Skins\Ad-Aware SE default.ask »ZIP »bt22.bmp - error - password-protected file C:\Program Files\Lavasoft\Ad-Aware SE Personal\Skins\Ad-Aware SE default.ask »ZIP »bt23.bmp - error - password-protected file C:\Program Files\Lavasoft\Ad-Aware SE Personal\Skins\Ad-Aware SE default.ask »ZIP »bt31.bmp - error - password-protected file C:\Program Files\Lavasoft\Ad-Aware SE Personal\Skins\Ad-Aware SE default.ask »ZIP »bt32.bmp - error - password-protected file C:\Program Files\Lavasoft\Ad-Aware SE Personal\Skins\Ad-Aware SE default.ask »ZIP »bt33.bmp - error - password-protected file C:\Program Files\Lavasoft\Ad-Aware SE Personal\Skins\Ad-Aware SE default.ask »ZIP »bt41.bmp - error - password-protected file C:\Program Files\Lavasoft\Ad-Aware SE Personal\Skins\Ad-Aware SE default.ask »ZIP »bt42.bmp - error - password-protected file C:\Program Files\Lavasoft\Ad-Aware SE Personal\Skins\Ad-Aware SE default.ask »ZIP »bt43.bmp - error - password-protected file C:\Program Files\Lavasoft\Ad-Aware SE Personal\Skins\Ad-Aware SE default.ask »ZIP »bt51.bmp - error - password-protected file C:\Program Files\Lavasoft\Ad-Aware SE Personal\Skins\Ad-Aware SE default.ask »ZIP »bt52.bmp - error - password-protected file C:\Program Files\Lavasoft\Ad-Aware SE Personal\Skins\Ad-Aware SE default.ask »ZIP »bt53.bmp - error - password-protected file C:\Program Files\Lavasoft\Ad-Aware SE Personal\Skins\Ad-Aware SE default.ask »ZIP »bt61.bmp - error - password-protected file C:\Program Files\Lavasoft\Ad-Aware SE Personal\Skins\Ad-Aware SE default.ask »ZIP »bt62.bmp - error - password-protected file C:\Program Files\Lavasoft\Ad-Aware SE Personal\Skins\Ad-Aware SE default.ask »ZIP »checkbox1.bmp - error - password-protected file C:\Program Files\Lavasoft\Ad-Aware SE Personal\Skins\Ad-Aware SE default.ask »ZIP »checkbox2.bmp - error - password-protected file C:\Program Files\Lavasoft\Ad-Aware SE Personal\Skins\Ad-Aware SE default.ask »ZIP »checkbox3.bmp - error - password-protected file C:\Program Files\Lavasoft\Ad-Aware SE Personal\Skins\Ad-Aware SE default.ask »ZIP »checkbox4.bmp - error - password-protected file C:\Program Files\Lavasoft\Ad-Aware SE Personal\Skins\Ad-Aware SE default.ask »ZIP »defbtn1.bmp - error - password-protected file C:\Program Files\Lavasoft\Ad-Aware SE Personal\Skins\Ad-Aware SE default.ask »ZIP »defbtn2.bmp - error - password-protected file C:\Program Files\Lavasoft\Ad-Aware SE Personal\Skins\Ad-Aware SE default.ask »ZIP »defbtn3.bmp - error - password-protected file C:\Program Files\Lavasoft\Ad-Aware SE Personal\Skins\Ad-Aware SE default.ask »ZIP »glyph1.bmp - error - password-protected file C:\Program Files\Lavasoft\Ad-Aware SE Personal\Skins\Ad-Aware SE default.ask »ZIP »glyph2.bmp - error - password-protected file C:\Program Files\Lavasoft\Ad-Aware SE Personal\Skins\Ad-Aware SE default.ask »ZIP »glyph3.bmp - error - password-protected file C:\Program Files\Lavasoft\Ad-Aware SE Personal\Skins\Ad-Aware SE default.ask »ZIP »glyph4.bmp - error - password-protected file C:\Program Files\Lavasoft\Ad-Aware SE Personal\Skins\Ad-Aware SE default.ask »ZIP »glyph5.bmp - error - password-protected file C:\Program Files\Lavasoft\Ad-Aware SE Personal\Skins\Ad-Aware SE default.ask »ZIP »glyph6.bmp - error - password-protected file C:\Program Files\Lavasoft\Ad-Aware SE Personal\Skins\Ad-Aware SE default.ask »ZIP »glyph7.bmp - error - password-protected file C:\Program Files\Lavasoft\Ad-Aware SE Personal\Skins\Ad-Aware SE default.ask »ZIP »main.bmp - error - password-protected file C:\Program Files\Lavasoft\Ad-Aware SE Personal\Skins\Ad-Aware SE default.ask »ZIP »preview.bmp - error - password-protected file C:\Program Files\Lavasoft\Ad-Aware SE Personal\Skins\Ad-Aware SE default.ask »ZIP »sprite1.bmp - error - password-protected file C:\Program Files\Network Monitor\netmon.exe - Win32/Monitor.Netmon.A application C:\Program Files\SurfSideKick 3\SskBho.dll - a variant of Win32/Adware.SurfSideKick application C:\Program Files\webHancer\Programs\webhdll.dll - Win32/Adware.Webhancer.381 application C:\Program Files\webHancer\Programs\whagent.exe - Win32/Adware.Webhancer.A application C:\Program Files\webHancer\Programs\whiehlpr.dll - Win32/Adware.Webhancer.381 application C:\Program Files\webHancer\Programs\whsurvey.exe - Win32/Adware.Webhancer.381 application C:\Program Files\Yazzle Sudoku\Sudoku.exe - probably a variant of Win32/Adware.MediaTickets application C:\Program Files\Zango\zango.exe - a variant of Win32/Adware.180Solutions application C:\windows\keyboard8.exe - Win32/TrojanDownloader.VB.WG trojan C:\windows\mousepad8.exe - Win32/TrojanClicker.VB.LI trojan C:\windows\newname8.exe - Win32/TrojanDownloader.Adload.NAC trojan C:\windows\SS1001.exe - a variant of Win32/Adware.SurfSideKick application C:\WINNT\DH.dll - Win32/TrojanClicker.Small.JF trojan C:\WINNT\Downloaded Program Files\HbInstIE.dll - Win32/Adware.HotBar application C:\WINNT\system32\mlvcrt40.dll - Win32/Adware.Look2Me application C:\WINNT\system32\nntapi.dll - error opening (File locked) [4] C:\WINNT\system32\nsmkcert.dll - Win32/Adware.Look2Me application C:\WINNT\system32\repairs303169569.dll - a variant of Win32/Adware.SurfSideKick application C:\WINNT\system32\config\default - error opening (File locked) [4] C:\WINNT\system32\config\default.LOG - error opening (File locked) [4] C:\WINNT\system32\config\SAM - error opening (File locked) [4] C:\WINNT\system32\config\SAM.LOG - error opening (File locked) [4] C:\WINNT\system32\config\SECURITY - error opening (File locked) [4] C:\WINNT\system32\config\SECURITY.LOG - error opening (File locked) [4] C:\WINNT\system32\config\software - error opening (File locked) [4] C:\WINNT\system32\config\software.LOG - error opening (File locked) [4] C:\WINNT\system32\config\system - error opening (File locked) [4] C:\WINNT\system32\config\SYSTEM.ALT - error opening (File locked) [4] C:\WINNT\YUQ\asappsrv.dll - Win32/Adware.CommAd application C:\WINNT\YUQ\command.exe - Win32/Adware.CommAd application Number of scanned files: 94871 Number of threats found: 48 Time of completion: 22:23:57 Total scanning time: 2333 sec (00:38:53) Notes: [4] File cannot be opened. It may be in use by another application or operating system.