Posted 29 July 2006 - 02:00 PM
I followed the instructions to get rid of msn93.exe, but there was no such file. I assumed the file could have been invisible because both pccillin and hijack this found it. so I just typed msn93.exe while in c:/WINDOWS/ and it never promted my that the file was non-existent so it carried on to the restart. While the computer was starting up I immediately got notified of the virus in msn93 by pccillin, the notifications i get constantly every 5 minutes.
For the next step run.dll didn't have any complications, but combofix did. It continuously prompted me "16 bit MS-DOS Subsystem: Find3m c:\Docume~1\New\locals~1\temp. A temporary file needed for initialization could not be created or could not be written to. Make sure that the directory path exist, and disk space is available. Choose 'Close' to terminate Aplication." (the other option was 'Ignore.' so constantly clicked ignore until the computer restarted without warning and the same message popped up a million time, and again i clicked ignore. Reluctantly there was still a log:
----------------------------------------------------------
Start Time= Sat 07/29/2006 14:05:27.04
Running from: C:\Documents and Settings\New\Desktop
((((((((((((((((((((((((((((((((((((((((((((( Qoologic's Log )))))))))))))))))))))))))))))))))))))))))))))))))))
14:08:50.57
No infected Qoologic files found. Reg entries were fixed
(((((((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
C:\drsmartload292a.exe
C:\Documents and Settings\LocalService\Local Settings\Temporary Internet Files\Content.IE5\8Z8HAJE1\drsmartload292a[1].exe
C:\WINDOWS\keyboard1.dat
(((((((((((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))))))
(((((((((((((((((((((((((((((((((((((( Files Created - Last 30days )))))))))))))))))))))))))))))))))))))))))))
(((((((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))
*Note* empty entries are not shown
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run]
"NvCplDaemon"="RUNDLL32.EXE C:\\WINDOWS\\system32\\NvCpl.dll,NvStartup"
"CARPService"="carpserv.exe"
"srmclean"="C:\\Cpqs\\Scom\\srmclean.exe"
"Microsoft Works Portfolio"="C:\\Program Files\\Microsoft Works\\WksSb.exe /AllUsers"
"AutoLogon"=""
"FLMOFFICE4DMOUSE"="C:\\Program Files\\Browser Mouse\\mouse32a.exe"
"FLMK08KB"="C:\\Program Files\\Muiltmedia keyboard utility\\1.1\\MMKEYBD.EXE"
"pccguide.exe"="\"C:\\Program Files\\Trend Micro\\Internet Security 2005\\pccguide.exe\""
"QuickTime Task"="\"C:\\Program Files\\QuickTime\\qttask.exe\" -atboottime"
"nwiz"="nwiz.exe /install"
"UserFaultCheck"=hex(2):25,73,79,73,74,65,6d,72,6f,6f,74,25,5c,73,79,73,74,65,\
6d,33,32,5c,64,75,6d,70,72,65,70,20,30,20,2d,75,00
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run\Compaq]
"SetRefresh"="C:\\PROGRA~1\\Compaq\\SETREF~1\\SetRefresh.exe"
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run\OptionalComponents]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run\OptionalComponents\IMAIL]
"Installed"="1"
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run\OptionalComponents\MAPI]
"Installed"="1"
"NoChange"="1"
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run\OptionalComponents\MSFS]
"Installed"="1"
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\run]
"Yahoo! Pager"="\"C:\\PROGRA~1\\Yahoo!\\MESSEN~1\\YAHOOM~1.EXE\" -quiet"
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\runonceex]
"SpybotSnD"="\"C:\\Program Files\\Spybot - Search & Destroy\\SpybotSD.exe\" /autocheck"
"flags"=dword:00000008
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\runonceex\000]
[HKEY_CURRENT_USER\software\microsoft\internet explorer\desktop\components]
"DeskHtmlVersion"=dword:00000110
"DeskHtmlMinorVersion"=dword:00000005
"Settings"=dword:00000001
"GeneralFlags"=dword:00000001
[HKEY_CURRENT_USER\software\microsoft\internet explorer\desktop\components\0]
"Source"="http://www.forever21.com/images/large/27848401-01.jpg"
"SubscribedURL"="http://www.forever21.com/images/large/27848401-01.jpg"
"FriendlyName"=""
"Flags"=dword:00002001
"Position"=hex:2c,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,e8,\
03,00,00,01,00,00,00,01,00,00,00,01,00,00,00,00,00,00,00,00,00,00,00
"CurrentState"=hex:01,00,00,40
"OriginalStateInfo"=hex:18,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
00,00,01,00,00,00
"RestoredStateInfo"=hex:14,6d,51,02,41,c0,b4,74,20,10,17,00,68,de,51,02,20,6d,\
51,02,22,f0,00,00
[HKEY_CURRENT_USER\software\microsoft\internet explorer\desktop\components\1]
"Source"="About:Home"
"SubscribedURL"="About:Home"
"FriendlyName"="My Current Home Page"
"Flags"=dword:00000002
"Position"=hex:2c,00,00,00,cc,00,00,00,00,00,00,00,34,03,00,00,de,02,00,00,00,\
00,00,00,01,00,00,00,01,00,00,00,01,00,00,00,00,00,00,00,00,00,00,00
"CurrentState"=hex:04,00,00,40
"OriginalStateInfo"=hex:18,00,00,00,ff,ff,00,00,ff,ff,00,00,ff,ff,ff,ff,ff,ff,\
ff,ff,04,00,00,00
"RestoredStateInfo"=hex:18,00,00,00,6a,02,00,00,23,00,00,00,a4,00,00,00,9a,00,\
00,00,01,00,00,00
[HKEY_USERS\.default\software\microsoft\windows\currentversion\policies\explorer]
"NoDriveTypeAutoRun"=dword:00000091
[HKEY_USERS\s-1-5-18\software\microsoft\windows\currentversion\policies\explorer]
"NoDriveTypeAutoRun"=dword:00000091
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\sharedtaskscheduler]
"{438755C2-A8BA-11D1-B96B-00A0C90312E1}"="Browseui preloader"
"{8C7461EF-2B13-11d2-BE35-3078302C2030}"="Component Categories cache daemon"
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shellexecutehooks]
"{AEB6717E-7E19-11d0-97EE-00C04FD91972}"=""
"{57B86673-276A-48B2-BAE7-C6DBB3020EB8}"="ewido anti-spyware 4.0"
HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\system
DisableRegistryTools REG_DWORD 0 (0x0)
Contents of the 'Scheduled Tasks' folder
Completion time: Sat 07/29/2006 14:11:50.06
ComboFix ver 06.07.15/28 - This logfile is located at C:\ComboFix.txt
----------------------------------------------------------
Just after the log popped up a message appeared "NDP20-KB917283-X86.exe encountered a problem and needed to close." Don't know if it's significant.
During the kaspersky virus scanner these all poped up on pccillin saying that they can't get rid of them:
Infected file: C:\Documents and Settings\LocalService\Local Settings\Temporary Internet Files\Content.IE5\6HWPER4N\loader[1].exe
Virus name: TROJ_ADLOAD.HW
Infected file: C:\RDFX4.exe
Virus name: ADW_SMALL.AAQ
Infected file: C:\System Volume Information\_restore{8238BFE6-44BD-4B25-B0F7-CE65B3815CC9}\RP375\A0044768.exe
Virus name: TROJ_VB.AYI (many varieties)
Infected file: C:\System Volume Information\_restore{8238BFE6-44BD-4B25-B0F7-CE65B3815CC9}\RP375\A0044818.exe
Virus name: ADW_SURFKICK.U
Infected file: C:\System Volume Information\_restore{8238BFE6-44BD-4B25-B0F7-CE65B3815CC9}\RP375\A0044773.exe
Virus name: ADW_UCMORE.E
Infected file: C:\System Volume Information\_restore{8238BFE6-44BD-4B25-B0F7-CE65B3815CC9}\RP375\A0044929.exe
Virus name: SPYW_SMALL.B
Infected file: C:\System Volume Information\_restore{8238BFE6-44BD-4B25-B0F7-CE65B3815CC9}\RP375\A0044936.exe
Virus name: ADW_LOOK2ME.Y
Infected file: C:\System Volume Information\_restore{8238BFE6-44BD-4B25-B0F7-CE65B3815CC9}\RP375\A0044939.exe
Virus name: SPYW_BISPY.A
Infected file: C:\System Volume Information\_restore{8238BFE6-44BD-4B25-B0F7-CE65B3815CC9}\RP375\A0044940.exe
Virus name: ADW_BKDSPACE.A
Infected file: C:\System Volume Information\_restore{8238BFE6-44BD-4B25-B0F7-CE65B3815CC9}\RP375\A0044942.dll
Virus name: ADW_NETPALS.B
Infected file: C:\WINDOWS\system32\clickspring.exe
Virus name: ADW_CLICKSPRNG.E
Infected file: C:\WINDOWS\system32\ezPopStub.exe
Virus name: ADW_WEBOFFER.B
Infected file: C:\WINDOWS\system32\horoscope.exe
Virus name: ADW_MYDLYSCOPE.A
----------------------------------------------------------
Here is my kaspersky log:
KASPERSKY ONLINE SCANNER REPORT
Saturday, July 29, 2006 3:59:47 PM
Operating System: Microsoft Windows XP Home Edition, Service Pack 2 (Build 2600)
Kaspersky Online Scanner version: 5.0.83.0
Kaspersky Anti-Virus database last update: 29/07/2006
Kaspersky Anti-Virus database records: 210716
Scan Settings
Scan using the following antivirus database extended
Scan Archives true
Scan Mail Bases true
Scan Target My Computer
A:\
C:\
D:\
E:\
Scan Statistics
Total number of scanned objects 62486
Number of viruses found 69
Number of infected objects 379 / 0
Number of suspicious objects 11
Duration of the scan process 01:21:02
Infected Object Name Virus Name Last Action
C:\Documents and Settings\All Users\Application Data\Microsoft\Dr Watson\user.dmp Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\CASClient1.zip/cas2stub.exe Suspicious: Password-protected-EXE skipped
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\CASClient1.zip ZIP: suspicious - 1 skipped
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\SmitfraudC2.zip/drsmartload849a7h.exe Suspicious: Password-protected-EXE skipped
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\SmitfraudC2.zip ZIP: suspicious - 1 skipped
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\SmitfraudC3.zip/drsmartload46a7h.exe Suspicious: Password-protected-EXE skipped
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\SmitfraudC3.zip ZIP: suspicious - 1 skipped
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\SmitfraudC4.zip/drsmartload45a7h.exe Suspicious: Password-protected-EXE skipped
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\SmitfraudC4.zip ZIP: suspicious - 1 skipped
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\SmitfraudC5.zip/drsmartload292a.exe Suspicious: Password-protected-EXE skipped
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\SmitfraudC5.zip ZIP: suspicious - 1 skipped
C:\Documents and Settings\LocalService\Cookies\index.dat Object is locked skipped
C:\Documents and Settings\LocalService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat Object is locked skipped
C:\Documents and Settings\LocalService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped
C:\Documents and Settings\LocalService\Local Settings\History\History.IE5\index.dat Object is locked skipped
C:\Documents and Settings\LocalService\Local Settings\Temporary Internet Files\Content.IE5\8Z8HAJE1\install[1].exe/stream/data0005 Infected: not-a-virus:AdWare.Win32.Softomate.q skipped
C:\Documents and Settings\LocalService\Local Settings\Temporary Internet Files\Content.IE5\8Z8HAJE1\install[1].exe/stream Infected: not-a-virus:AdWare.Win32.Softomate.q skipped
C:\Documents and Settings\LocalService\Local Settings\Temporary Internet Files\Content.IE5\8Z8HAJE1\install[1].exe NSIS: infected - 2 skipped
C:\Documents and Settings\LocalService\Local Settings\Temporary Internet Files\Content.IE5\index.dat Object is locked skipped
C:\Documents and Settings\LocalService\NTUSER.DAT Object is locked skipped
C:\Documents and Settings\LocalService\ntuser.dat.LOG Object is locked skipped
C:\Documents and Settings\NetworkService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat Object is locked skipped
C:\Documents and Settings\NetworkService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped
C:\Documents and Settings\NetworkService\NTUSER.DAT Object is locked skipped
C:\Documents and Settings\NetworkService\ntuser.dat.LOG Object is locked skipped
C:\Documents and Settings\New\Cookies\index.dat Object is locked skipped
C:\Documents and Settings\New\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat Object is locked skipped
C:\Documents and Settings\New\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped
C:\Documents and Settings\New\Local Settings\History\History.IE5\index.dat Object is locked skipped
C:\Documents and Settings\New\Local Settings\History\History.IE5\MSHist012006072920060730\index.dat Object is locked skipped
C:\Documents and Settings\New\Local Settings\Temporary Internet Files\Content.IE5\index.dat Object is locked skipped
C:\Documents and Settings\New\ntuser.dat Object is locked skipped
C:\Documents and Settings\New\ntuser.dat.LOG Object is locked skipped
C:\gogogo.exe Infected: Backdoor.Win32.IRCBot.ih skipped
C:\gozgogo.exe Infected: Backdoor.Win32.IRCBot.ih skipped
C:\mc-110-12-0000107.exe/stream/data0005 Infected: not-a-virus:AdWare.Win32.Softomate.q skipped
C:\mc-110-12-0000107.exe/stream Infected: not-a-virus:AdWare.Win32.Softomate.q skipped
C:\mc-110-12-0000107.exe NSIS: infected - 2 skipped
C:\Program Files\Expertcity\GoToMyPC\g2hook.dll Infected: not-a-virus:RemoteAdmin.Win32.GotomyPC.a skipped
C:\Program Files\Expertcity\GoToMyPC\gotomon.dll Infected: not-a-virus:RemoteAdmin.Win32.GotomyPC.a skipped
C:\Program Files\Trend Micro\Internet Security 2005\Quarantine\1.tmp Infected: Trojan-Downloader.Win32.Adload.de skipped
C:\Program Files\Trend Micro\Internet Security 2005\Quarantine\10.tmp Infected: Trojan.Win32.P2E.bt skipped
C:\Program Files\Trend Micro\Internet Security 2005\Quarantine\11.tmp Infected: Backdoor.Win32.Agent.ec skipped
C:\Program Files\Trend Micro\Internet Security 2005\Quarantine\12.tmp Infected: Trojan.Win32.Crypt.d skipped
C:\Program Files\Trend Micro\Internet Security 2005\Quarantine\13.tmp Infected: Backdoor.Win32.Wisdoor.au skipped
C:\Program Files\Trend Micro\Internet Security 2005\Quarantine\14.tmp Infected: Backdoor.Win32.Agent.ec skipped
C:\Program Files\Trend Micro\Internet Security 2005\Quarantine\15.tmp Infected: Backdoor.Win32.Agent.ec skipped
C:\Program Files\Trend Micro\Internet Security 2005\Quarantine\16.tmp Infected: Backdoor.Win32.Agent.ec skipped
C:\Program Files\Trend Micro\Internet Security 2005\Quarantine\17.tmp Infected: Backdoor.Win32.Agent.ec skipped
C:\Program Files\Trend Micro\Internet Security 2005\Quarantine\18.tmp Infected: Backdoor.Win32.Agent.ec skipped
C:\Program Files\Trend Micro\Internet Security 2005\Quarantine\19.tmp Infected: Backdoor.Win32.Agent.ec skipped
C:\Program Files\Trend Micro\Internet Security 2005\Quarantine\193.tmp Infected: Trojan.Win32.Agent.cs skipped
C:\Program Files\Trend Micro\Internet Security 2005\Quarantine\19B.tmp Infected: Trojan-Dropper.Win32.Delf.jm skipped
C:\Program Files\Trend Micro\Internet Security 2005\Quarantine\19E.tmp Infected: Trojan.Win32.Agent.cs skipped
C:\Program Files\Trend Micro\Internet Security 2005\Quarantine\1A.tmp Infected: Backdoor.Win32.Agent.ec skipped
C:\Program Files\Trend Micro\Internet Security 2005\Quarantine\1B.tmp Infected: Backdoor.Win32.Agent.ec skipped
C:\Program Files\Trend Micro\Internet Security 2005\Quarantine\1B2.tmp/BlackBox.class Infected: Exploit.Java.ByteVerify skipped
C:\Program Files\Trend Micro\Internet Security 2005\Quarantine\1B2.tmp/VerifierBug.class Infected: Exploit.Java.ByteVerify skipped
C:\Program Files\Trend Micro\Internet Security 2005\Quarantine\1B2.tmp/Beyond.class Infected: Trojan-Downloader.Java.OpenConnection.aa skipped
C:\Program Files\Trend Micro\Internet Security 2005\Quarantine\1B2.tmp ZIP: infected - 3 skipped
C:\Program Files\Trend Micro\Internet Security 2005\Quarantine\1B2.tmp CryptFF.b: infected - 3 skipped
C:\Program Files\Trend Micro\Internet Security 2005\Quarantine\1C.tmp Infected: Backdoor.Win32.Agent.ec skipped
C:\Program Files\Trend Micro\Internet Security 2005\Quarantine\1C6.tmp Infected: Trojan.Win32.Agent.cs skipped
C:\Program Files\Trend Micro\Internet Security 2005\Quarantine\1D.tmp Infected: Backdoor.Win32.Agent.ec skipped
C:\Program Files\Trend Micro\Internet Security 2005\Quarantine\1E.tmp Infected: Backdoor.Win32.Agent.ec skipped
C:\Program Files\Trend Micro\Internet Security 2005\Quarantine\1F.tmp Infected: Backdoor.Win32.Agent.ec skipped
C:\Program Files\Trend Micro\Internet Security 2005\Quarantine\2.tmp Infected: Trojan-Downloader.Win32.Adload.de skipped
C:\Program Files\Trend Micro\Internet Security 2005\Quarantine\20.tmp Infected: Backdoor.Win32.Agent.ec skipped
C:\Program Files\Trend Micro\Internet Security 2005\Quarantine\21.tmp Infected: Backdoor.Win32.Agent.ec skipped
C:\Program Files\Trend Micro\Internet Security 2005\Quarantine\22.tmp Infected: Backdoor.Win32.Agent.ec skipped
C:\Program Files\Trend Micro\Internet Security 2005\Quarantine\23.tmp Infected: Backdoor.Win32.Agent.ec skipped
C:\Program Files\Trend Micro\Internet Security 2005\Quarantine\24.tmp Infected: Backdoor.Win32.Agent.ec skipped
C:\Program Files\Trend Micro\Internet Security 2005\Quarantine\25.tmp Infected: Backdoor.Win32.Agent.ec skipped
C:\Program Files\Trend Micro\Internet Security 2005\Quarantine\26.tmp Infected: Backdoor.Win32.Agent.ec skipped
C:\Program Files\Trend Micro\Internet Security 2005\Quarantine\27.tmp Infected: Backdoor.Win32.Agent.ec skipped
C:\Program Files\Trend Micro\Internet Security 2005\Quarantine\27A.tmp Infected: Trojan.Win32.Agent.cs skipped
C:\Program Files\Trend Micro\Internet Security 2005\Quarantine\27F.tmp Infected: Trojan.Win32.Agent.cs skipped
C:\Program Files\Trend Micro\Internet Security 2005\Quarantine\28.tmp Infected: Backdoor.Win32.Agent.ec skipped
C:\Program Files\Trend Micro\Internet Security 2005\Quarantine\29.tmp Infected: Backdoor.Win32.Agent.ec skipped
C:\Program Files\Trend Micro\Internet Security 2005\Quarantine\2A.tmp Infected: Backdoor.Win32.Agent.ec skipped
C:\Program Files\Trend Micro\Internet Security 2005\Quarantine\2B.tmp Infected: Backdoor.Win32.Agent.ec skipped
C:\Program Files\Trend Micro\Internet Security 2005\Quarantine\2C.tmp Infected: Backdoor.Win32.Agent.ec skipped
C:\Program Files\Trend Micro\Internet Security 2005\Quarantine\2D.tmp Infected: Trojan.Win32.P2E.bt skipped
C:\Program Files\Trend Micro\Internet Security 2005\Quarantine\2E.tmp Infected: Trojan-Downloader.Win32.ConHook.c skipped
C:\Program Files\Trend Micro\Internet Security 2005\Quarantine\2F.tmp Infected: Backdoor.Win32.Agent.gl skipped
C:\Program Files\Trend Micro\Internet Security 2005\Quarantine\3.tmp Infected: Backdoor.Win32.Agent.ec skipped
C:\Program Files\Trend Micro\Internet Security 2005\Quarantine\30.tmp Infected: Backdoor.Win32.Agent.gl skipped
C:\Program Files\Trend Micro\Internet Security 2005\Quarantine\31.tmp Infected: P2P-Worm.Win32.SpyBot.hd skipped
C:\Program Files\Trend Micro\Internet Security 2005\Quarantine\32.tmp Infected: P2P-Worm.Win32.SpyBot.hd skipped
C:\Program Files\Trend Micro\Internet Security 2005\Quarantine\33.tmp Infected: Trojan-Downloader.Win32.Adload.de skipped
C:\Program Files\Trend Micro\Internet Security 2005\Quarantine\34.tmp Infected: Trojan-Downloader.Win32.Adload.cw skipped
C:\Program Files\Trend Micro\Internet Security 2005\Quarantine\35.tmp Infected: Trojan-Downloader.Win32.Adload.de skipped
C:\Program Files\Trend Micro\Internet Security 2005\Quarantine\36.tmp Infected: Trojan-Downloader.Win32.Adload.cw skipped
C:\Program Files\Trend Micro\Internet Security 2005\Quarantine\37.tmp Infected: P2P-Worm.Win32.SpyBot.hd skipped
C:\Program Files\Trend Micro\Internet Security 2005\Quarantine\38.tmp Infected: P2P-Worm.Win32.SpyBot.hd skipped
C:\Program Files\Trend Micro\Internet Security 2005\Quarantine\39.tmp Infected: Trojan-Downloader.Win32.Adload.cw skipped
C:\Program Files\Trend Micro\Internet Security 2005\Quarantine\3A.tmp Infected: Trojan-Downloader.Win32.Vivia.l skipped
C:\Program Files\Trend Micro\Internet Security 2005\Quarantine\3B.tmp Infected: P2P-Worm.Win32.SpyBot.hd skipped
C:\Program Files\Trend Micro\Internet Security 2005\Quarantine\3C.tmp Infected: P2P-Worm.Win32.SpyBot.hd skipped
C:\Program Files\Trend Micro\Internet Security 2005\Quarantine\3D.tmp Infected: Trojan-Downloader.Win32.Adload.de skipped
C:\Program Files\Trend Micro\Internet Security 2005\Quarantine\3E.tmp Infected: Backdoor.Win32.Wisdoor.au skipped
C:\Program Files\Trend Micro\Internet Security 2005\Quarantine\3F.tmp Infected: Trojan-Downloader.Win32.Adload.de skipped
C:\Program Files\Trend Micro\Internet Security 2005\Quarantine\4.tmp Infected: Backdoor.Win32.Agent.ec skipped
C:\Program Files\Trend Micro\Internet Security 2005\Quarantine\40.tmp Infected: Trojan-Downloader.Win32.Adload.de skipped
C:\Program Files\Trend Micro\Internet Security 2005\Quarantine\41.tmp Infected: Trojan-Downloader.Win32.Adload.cw skipped
C:\Program Files\Trend Micro\Internet Security 2005\Quarantine\42.tmp Infected: Trojan-Downloader.Win32.Small.buy skipped
C:\Program Files\Trend Micro\Internet Security 2005\Quarantine\43.tmp Infected: Trojan-Downloader.Win32.Adload.de skipped
C:\Program Files\Trend Micro\Internet Security 2005\Quarantine\44.tmp Infected: Trojan-Downloader.Win32.Adload.de skipped
C:\Program Files\Trend Micro\Internet Security 2005\Quarantine\45.tmp Infected: Trojan-Downloader.Win32.Adload.de skipped
C:\Program Files\Trend Micro\Internet Security 2005\Quarantine\46.tmp Infected: Backdoor.Win32.Wisdoor.au skipped
C:\Program Files\Trend Micro\Internet Security 2005\Quarantine\47.tmp Infected: Backdoor.Win32.Agent.ec skipped
C:\Program Files\Trend Micro\Internet Security 2005\Quarantine\48.tmp Infected: Trojan-Downloader.Win32.Adload.de skipped
C:\Program Files\Trend Micro\Internet Security 2005\Quarantine\49.tmp Infected: Trojan-Downloader.Win32.Adload.cw skipped
C:\Program Files\Trend Micro\Internet Security 2005\Quarantine\4A.tmp Infected: Trojan-Downloader.Win32.TSUpdate.o skipped
C:\Program Files\Trend Micro\Internet Security 2005\Quarantine\4B.tmp Infected: Trojan-Downloader.Win32.Adload.cw skipped
C:\Program Files\Trend Micro\Internet Security 2005\Quarantine\4C.tmp Infected: Trojan-Downloader.Win32.Small.buy skipped
C:\Program Files\Trend Micro\Internet Security 2005\Quarantine\4D.tmp Infected: P2P-Worm.Win32.SpyBot.hd skipped
C:\Program Files\Trend Micro\Internet Security 2005\Quarantine\4E.tmp Infected: Trojan-Downloader.Win32.Vivia.l skipped
C:\Program Files\Trend Micro\Internet Security 2005\Quarantine\4F.tmp Infected: P2P-Worm.Win32.SpyBot.hd skipped
C:\Program Files\Trend Micro\Internet Security 2005\Quarantine\5.tmp Infected: Trojan-Downloader.Win32.Vivia.k skipped
C:\Program Files\Trend Micro\Internet Security 2005\Quarantine\50.tmp Infected: Backdoor.Win32.Wisdoor.au skipped
C:\Program Files\Trend Micro\Internet Security 2005\Quarantine\51.tmp Infected: P2P-Worm.Win32.SpyBot.hd skipped
C:\Program Files\Trend Micro\Internet Security 2005\Quarantine\52.tmp Infected: Trojan-Downloader.Win32.Adload.de skipped
C:\Program Files\Trend Micro\Internet Security 2005\Quarantine\53.tmp Infected: Trojan.Win32.LowZones.an skipped
C:\Program Files\Trend Micro\Internet Security 2005\Quarantine\54.tmp Infected: Trojan-Downloader.Win32.Qoologic.at skipped
C:\Program Files\Trend Micro\Internet Security 2005\Quarantine\55.tmp Infected: Backdoor.Win32.Agent.ec skipped
C:\Program Files\Trend Micro\Internet Security 2005\Quarantine\56.tmp Infected: Trojan-Downloader.Win32.VB.nw skipped
C:\Program Files\Trend Micro\Internet Security 2005\Quarantine\57.tmp Infected: Trojan-Downloader.Win32.Adload.de skipped
C:\Program Files\Trend Micro\Internet Security 2005\Quarantine\59.tmp Infected: Trojan-Downloader.Win32.Agent.ala skipped
C:\Program Files\Trend Micro\Internet Security 2005\Quarantine\5A.tmp Infected: Trojan-Downloader.Win32.Adload.de skipped
C:\Program Files\Trend Micro\Internet Security 2005\Quarantine\5B.tmp/data0004 Infected: Trojan-Downloader.Win32.Small.ctp skipped
C:\Program Files\Trend Micro\Internet Security 2005\Quarantine\5B.tmp/data0005 Infected: Trojan-Downloader.Win32.Small.ajc skipped
C:\Program Files\Trend Micro\Internet Security 2005\Quarantine\5B.tmp NSIS: infected - 2 skipped
C:\Program Files\Trend Micro\Internet Security 2005\Quarantine\5B.tmp CryptFF.b: infected - 2 skipped
C:\Program Files\Trend Micro\Internet Security 2005\Quarantine\5C.tmp Infected: Trojan-Downloader.Win32.Adload.de skipped
C:\Program Files\Trend Micro\Internet Security 2005\Quarantine\5D.tmp Infected: Trojan-Downloader.Win32.Adload.de skipped
C:\Program Files\Trend Micro\Internet Security 2005\Quarantine\5E.tmp Infected: Trojan-Downloader.Win32.Adload.de skipped
C:\Program Files\Trend Micro\Internet Security 2005\Quarantine\6.tmp Infected: Backdoor.Win32.Agent.ec skipped
C:\Program Files\Trend Micro\Internet Security 2005\Quarantine\60.tmp Infected: Trojan-Downloader.Win32.Small.buy skipped
C:\Program Files\Trend Micro\Internet Security 2005\Quarantine\61.tmp Infected: Trojan-Downloader.Win32.Adload.de skipped
C:\Program Files\Trend Micro\Internet Security 2005\Quarantine\62.tmp Infected: Backdoor.Win32.Agent.ec skipped
C:\Program Files\Trend Micro\Internet Security 2005\Quarantine\63.tmp Infected: Trojan-Downloader.Win32.Small.buy skipped
C:\Program Files\Trend Micro\Internet Security 2005\Quarantine\64.tmp Infected: Trojan-Downloader.Win32.Agent.ala skipped
C:\Program Files\Trend Micro\Internet Security 2005\Quarantine\67.tmp Infected: P2P-Worm.Win32.SpyBot.hd skipped
C:\Program Files\Trend Micro\Internet Security 2005\Quarantine\68.tmp Infected: Trojan-Dropper.Win32.Agent.aie skipped
C:\Program Files\Trend Micro\Internet Security 2005\Quarantine\69.tmp Infected: P2P-Worm.Win32.SpyBot.hd skipped
C:\Program Files\Trend Micro\Internet Security 2005\Quarantine\6A.tmp Infected: Trojan-Downloader.Win32.Small.buy skipped
C:\Program Files\Trend Micro\Internet Security 2005\Quarantine\6B.tmp Infected: Backdoor.Win32.Wisdoor.au skipped
C:\Program Files\Trend Micro\Internet Security 2005\Quarantine\6C.tmp Infected: Backdoor.Win32.Wisdoor.au skipped
C:\Program Files\Trend Micro\Internet Security 2005\Quarantine\6D.tmp Infected: Trojan-Downloader.Win32.Small.buy skipped
C:\Program Files\Trend Micro\Internet Security 2005\Quarantine\6E.tmp Infected: Backdoor.Win32.Agent.ec skipped
C:\Program Files\Trend Micro\Internet Security 2005\Quarantine\7.tmp Infected: Backdoor.Win32.Agent.ec skipped
C:\Program Files\Trend Micro\Internet Security 2005\Quarantine\70.tmp Infected: Trojan-Downloader.Win32.Small.buy skipped
C:\Program Files\Trend Micro\Internet Security 2005\Quarantine\72.tmp Infected: Backdoor.Win32.Agent.ec skipped
C:\Program Files\Trend Micro\Internet Security 2005\Quarantine\73.tmp Infected: Trojan-Dropper.Win32.Agent.aie skipped
C:\Program Files\Trend Micro\Internet Security 2005\Quarantine\74.tmp Infected: Backdoor.Win32.Agent.ec skipped
C:\Program Files\Trend Micro\Internet Security 2005\Quarantine\75.tmp Infected: Trojan-Downloader.Win32.TSUpdate.o skipped
C:\Program Files\Trend Micro\Internet Security 2005\Quarantine\76.tmp Infected: Backdoor.Win32.Agent.ec skipped
C:\Program Files\Trend Micro\Internet Security 2005\Quarantine\78.tmp Infected: Trojan-Downloader.Win32.ConHook.c skipped
C:\Program Files\Trend Micro\Internet Security 2005\Quarantine\79.tmp Infected: Trojan-Downloader.Win32.Small.buy skipped
C:\Program Files\Trend Micro\Internet Security 2005\Quarantine\7A.tmp Infected: Backdoor.Win32.Agent.ec skipped
C:\Program Files\Trend Micro\Internet Security 2005\Quarantine\7B.tmp Infected: P2P-Worm.Win32.SpyBot.hd skipped
C:\Program Files\Trend Micro\Internet Security 2005\Quarantine\7C.tmp Infected: Trojan-Downloader.Win32.TSUpdate.o skipped
C:\Program Files\Trend Micro\Internet Security 2005\Quarantine\7D.tmp Infected: P2P-Worm.Win32.SpyBot.hd skipped
C:\Program Files\Trend Micro\Internet Security 2005\Quarantine\7F.tmp Infected: Trojan-Downloader.Win32.Small.buy skipped
C:\Program Files\Trend Micro\Internet Security 2005\Quarantine\8.tmp Infected: Trojan.Win32.Crypt.d skipped
C:\Program Files\Trend Micro\Internet Security 2005\Quarantine\81.tmp Infected: Trojan-Downloader.Win32.TSUpdate.o skipped
C:\Program Files\Trend Micro\Internet Security 2005\Quarantine\82.tmp Infected: P2P-Worm.Win32.SpyBot.hd skipped
C:\Program Files\Trend Micro\Internet Security 2005\Quarantine\83.tmp Infected: Trojan-Downloader.Win32.Qoologic.at skipped
C:\Program Files\Trend Micro\Internet Security 2005\Quarantine\84.tmp Infected: P2P-Worm.Win32.SpyBot.hd skipped
C:\Program Files\Trend Micro\Internet Security 2005\Quarantine\86.tmp Infected: Trojan-Downloader.Win32.TSUpdate.o skipped
C:\Program Files\Trend Micro\Internet Security 2005\Quarantine\87.tmp Infected: P2P-Worm.Win32.SpyBot.hd skipped
C:\Program Files\Trend Micro\Internet Security 2005\Quarantine\88.tmp Infected: Trojan-Downloader.Win32.Small.buy skipped
C:\Program Files\Trend Micro\Internet Security 2005\Quarantine\89.tmp Infected: P2P-Worm.Win32.SpyBot.hd skipped
C:\Program Files\Trend Micro\Internet Security 2005\Quarantine\8A.tmp Infected: Trojan-Downloader.Win32.Adload.de skipped
C:\Program Files\Trend Micro\Internet Security 2005\Quarantine\8B.tmp Infected: Trojan-Downloader.Win32.Qoologic.at skipped
C:\Program Files\Trend Micro\Internet Security 2005\Quarantine\8C.tmp Infected: P2P-Worm.Win32.SpyBot.hd skipped
C:\Program Files\Trend Micro\Internet Security 2005\Quarantine\8D.tmp Infected: Backdoor.Win32.Agent.ec skipped
C:\Program Files\Trend Micro\Internet Security 2005\Quarantine\8E.tmp Infected: P2P-Worm.Win32.SpyBot.hd skipped
C:\Program Files\Trend Micro\Internet Security 2005\Quarantine\8F.tmp Infected: Trojan-Downloader.Win32.Small.buy skipped
C:\Program Files\Trend Micro\Internet Security 2005\Quarantine\8FD.tmp Infected: Trojan-Downloader.Win32.Adload.de skipped
C:\Program Files\Trend Micro\Internet Security 2005\Quarantine\9.tmp Infected: Trojan-Downloader.Win32.Vivia.p skipped
C:\Program Files\Trend Micro\Internet Security 2005\Quarantine\90.tmp Infected: Backdoor.Win32.Agent.ec skipped
C:\Program Files\Trend Micro\Internet Security 2005\Quarantine\92.tmp Infected: Trojan-Downloader.Win32.Small.buy skipped
C:\Program Files\Trend Micro\Internet Security 2005\Quarantine\94.tmp Infected: Trojan-Downloader.Win32.Small.buy skipped
C:\Program Files\Trend Micro\Internet Security 2005\Quarantine\95.tmp Infected: Backdoor.Win32.Agent.ec skipped
C:\Program Files\Trend Micro\Internet Security 2005\Quarantine\97.tmp Infected: Backdoor.Win32.Agent.ec skipped
C:\Program Files\Trend Micro\Internet Security 2005\Quarantine\98.tmp Infected: Backdoor.Win32.SdBot.aad skipped
C:\Program Files\Trend Micro\Internet Security 2005\Quarantine\99.tmp Infected: Backdoor.Win32.Agent.ec skipped
C:\Program Files\Trend Micro\Internet Security 2005\Quarantine\9A.tmp Infected: Trojan-Downloader.Win32.Small.buy skipped
C:\Program Files\Trend Micro\Internet Security 2005\Quarantine\9B.tmp Infected: Backdoor.Win32.Agent.ec skipped
C:\Program Files\Trend Micro\Internet Security 2005\Quarantine\9D.tmp Infected: Backdoor.Win32.Agent.ec skipped
C:\Program Files\Trend Micro\Internet Security 2005\Quarantine\9F.tmp Infected: Backdoor.Win32.Agent.ec skipped
C:\Program Files\Trend Micro\Internet Security 2005\Quarantine\A.tmp Infected: Trojan-Dropper.Win32.Agent.aie skipped
C:\Program Files\Trend Micro\Internet Security 2005\Quarantine\A1.tmp Infected: Backdoor.Win32.Agent.ec skipped
C:\Program Files\Trend Micro\Internet Security 2005\Quarantine\A2.tmp Infected: Backdoor.Win32.SdBot.aad skipped
C:\Program Files\Trend Micro\Internet Security 2005\Quarantine\A3.tmp Infected: Backdoor.Win32.Agent.ec skipped
C:\Program Files\Trend Micro\Internet Security 2005\Quarantine\A5.tmp Infected: Backdoor.Win32.Agent.ec skipped
C:\Program Files\Trend Micro\Internet Security 2005\Quarantine\A6.tmp Infected: Trojan-Downloader.Win32.Qoologic.at skipped
C:\Program Files\Trend Micro\Internet Security 2005\Quarantine\A7.tmp Infected: Backdoor.Win32.Agent.ec skipped
C:\Program Files\Trend Micro\Internet Security 2005\Quarantine\AC.tmp Infected: Trojan-Downloader.Win32.Small.buy skipped
C:\Program Files\Trend Micro\Internet Security 2005\Quarantine\AE.tmp Infected: Trojan-Downloader.Win32.TSUpdate.o skipped
C:\Program Files\Trend Micro\Internet Security 2005\Quarantine\B.tmp Infected: Backdoor.Win32.Agent.ec skipped
C:\Program Files\Trend Micro\Internet Security 2005\Quarantine\C.tmp Infected: Backdoor.Win32.Wisdoor.au skipped
C:\Program Files\Trend Micro\Internet Security 2005\Quarantine\C46.tmp Infected: Trojan.Win32.Agent.cs skipped
C:\Program Files\Trend Micro\Internet Security 2005\Quarantine\C47.tmp Infected: Trojan.Win32.Agent.cs skipped
C:\Program Files\Trend Micro\Internet Security 2005\Quarantine\C48.tmp Infected: Trojan.Win32.Agent.cs skipped
C:\Program Files\Trend Micro\Internet Security 2005\Quarantine\cutil.dll Infected: Trojan.Win32.Agent.cs skipped
C:\Program Files\Trend Micro\Internet Security 2005\Quarantine\D.tmp Infected: Backdoor.Win32.Agent.ec skipped
C:\Program Files\Trend Micro\Internet Security 2005\Quarantine\E.tmp Infected: Trojan-Downloader.Win32.Vivia.k skipped
C:\Program Files\Trend Micro\Internet Security 2005\Quarantine\F.tmp Infected: Trojan-Downloader.Win32.Vivia.p skipped
C:\RDFX4.exe Object is locked skipped
C:\System Volume Information\MountPointManagerRemoteDatabase Object is locked skipped
C:\System Volume Information\_restore{8238BFE6-44BD-4B25-B0F7-CE65B3815CC9}\RP370\A0043464.exe Suspicious: Packed.Win32.CryptExe skipped
C:\System Volume Information\_restore{8238BFE6-44BD-4B25-B0F7-CE65B3815CC9}\RP375\A0044738.exe Infected: Trojan-Downloader.Win32.Adload.db skipped
C:\System Volume Information\_restore{8238BFE6-44BD-4B25-B0F7-CE65B3815CC9}\RP375\A0044767.exe Infected: Trojan-Downloader.Win32.Agent.aaf skipped
C:\System Volume Information\_restore{8238BFE6-44BD-4B25-B0F7-CE65B3815CC9}\RP375\A0044769.exe/stream/data0005 Infected: not-a-virus:AdWare.Win32.Softomate.q skipped
C:\System Volume Information\_restore{8238BFE6-44BD-4B25-B0F7-CE65B3815CC9}\RP375\A0044769.exe/stream Infected: not-a-virus:AdWare.Win32.Softomate.q skipped
C:\System Volume Information\_restore{8238BFE6-44BD-4B25-B0F7-CE65B3815CC9}\RP375\A0044769.exe NSIS: infected - 2 skipped
C:\System Volume Information\_restore{8238BFE6-44BD-4B25-B0F7-CE65B3815CC9}\RP375\A0044773.exe Object is locked skipped
C:\System Volume Information\_restore{8238BFE6-44BD-4B25-B0F7-CE65B3815CC9}\RP375\A0044800.exe Infected: Trojan-Downloader.Win32.VB.nw skipped
C:\System Volume Information\_restore{8238BFE6-44BD-4B25-B0F7-CE65B3815CC9}\RP375\A0044808.exe Infected: Trojan-Dropper.Win32.Agent.mu skipped
C:\System Volume Information\_restore{8238BFE6-44BD-4B25-B0F7-CE65B3815CC9}\RP375\A0044809.exe Infected: Trojan-Downloader.Win32.Small.cyh skipped
C:\System Volume Information\_restore{8238BFE6-44BD-4B25-B0F7-CE65B3815CC9}\RP375\A0044811.exe Infected: Trojan-Downloader.Win32.Agent.aaf skipped
C:\System Volume Information\_restore{8238BFE6-44BD-4B25-B0F7-CE65B3815CC9}\RP375\A0044812.exe Infected: Trojan-Downloader.Win32.Adload.db skipped
C:\System Volume Information\_restore{8238BFE6-44BD-4B25-B0F7-CE65B3815CC9}\RP375\A0044814.exe Infected: Trojan-Dropper.Win32.Agent.hl skipped
C:\System Volume Information\_restore{8238BFE6-44BD-4B25-B0F7-CE65B3815CC9}\RP375\A0044815.exe Infected: Trojan-Dropper.Win32.Agent.hl skipped
C:\System Volume Information\_restore{8238BFE6-44BD-4B25-B0F7-CE65B3815CC9}\RP375\A0044816.exe Infected: Trojan-Downloader.Win32.WinShow.z skipped
C:\System Volume Information\_restore{8238BFE6-44BD-4B25-B0F7-CE65B3815CC9}\RP375\A0044817.exe Infected: Trojan-Downloader.Win32.WinShow.z skipped
C:\System Volume Information\_restore{8238BFE6-44BD-4B25-B0F7-CE65B3815CC9}\RP375\A0044818.exe Object is locked skipped
C:\System Volume Information\_restore{8238BFE6-44BD-4B25-B0F7-CE65B3815CC9}\RP375\A0044819.exe Infected: Backdoor.Win32.Agent.ec skipped
C:\System Volume Information\_restore{8238BFE6-44BD-4B25-B0F7-CE65B3815CC9}\RP375\A0044820.exe Infected: Backdoor.Win32.Agent.ec skipped
C:\System Volume Information\_restore{8238BFE6-44BD-4B25-B0F7-CE65B3815CC9}\RP375\A0044821.exe Infected: Backdoor.Win32.Agent.ec skipped
C:\System Volume Information\_restore{8238BFE6-44BD-4B25-B0F7-CE65B3815CC9}\RP375\A0044822.exe Infected: Backdoor.Win32.Agent.ec skipped
C:\System Volume Information\_restore{8238BFE6-44BD-4B25-B0F7-CE65B3815CC9}\RP375\A0044823.exe Infected: Backdoor.Win32.Agent.ec skipped
C:\System Volume Information\_restore{8238BFE6-44BD-4B25-B0F7-CE65B3815CC9}\RP375\A0044824.exe Infected: Backdoor.Win32.Agent.ec skipped
C:\System Volume Information\_restore{8238BFE6-44BD-4B25-B0F7-CE65B3815CC9}\RP375\A0044825.exe Infected: Backdoor.Win32.Agent.ec skipped
C:\System Volume Information\_restore{8238BFE6-44BD-4B25-B0F7-CE65B3815CC9}\RP375\A0044826.exe Infected: Backdoor.Win32.Agent.ec skipped
C:\System Volume Information\_restore{8238BFE6-44BD-4B25-B0F7-CE65B3815CC9}\RP375\A0044827.exe Infected: Backdoor.Win32.Agent.ec skipped
C:\System Volume Information\_restore{8238BFE6-44BD-4B25-B0F7-CE65B3815CC9}\RP375\A0044828.exe Infected: Backdoor.Win32.Agent.ec skipped
C:\System Volume Information\_restore{8238BFE6-44BD-4B25-B0F7-CE65B3815CC9}\RP375\A0044829.exe Infected: Backdoor.Win32.Agent.ec skipped
C:\System Volume Information\_restore{8238BFE6-44BD-4B25-B0F7-CE65B3815CC9}\RP375\A0044830.exe Infected: Backdoor.Win32.Agent.ec skipped
C:\System Volume Information\_restore{8238BFE6-44BD-4B25-B0F7-CE65B3815CC9}\RP375\A0044831.exe Infected: Backdoor.Win32.Agent.ec skipped
C:\System Volume Information\_restore{8238BFE6-44BD-4B25-B0F7-CE65B3815CC9}\RP375\A0044832.exe Infected: Backdoor.Win32.Agent.ec skipped
C:\System Volume Information\_restore{8238BFE6-44BD-4B25-B0F7-CE65B3815CC9}\RP375\A0044834.exe Infected: Backdoor.Win32.Agent.ec skipped
C:\System Volume Information\_restore{8238BFE6-44BD-4B25-B0F7-CE65B3815CC9}\RP375\A0044835.exe Infected: Backdoor.Win32.Agent.ec skipped
C:\System Volume Information\_restore{8238BFE6-44BD-4B25-B0F7-CE65B3815CC9}\RP375\A0044836.exe Infected: Backdoor.Win32.Agent.ec skipped
C:\System Volume Information\_restore{8238BFE6-44BD-4B25-B0F7-CE65B3815CC9}\RP375\A0044837.exe Infected: Backdoor.Win32.Agent.ec skipped
C:\System Volume Information\_restore{8238BFE6-44BD-4B25-B0F7-CE65B3815CC9}\RP375\A0044838.exe Infected: Backdoor.Win32.Agent.ec skipped
C:\System Volume Information\_restore{8238BFE6-44BD-4B25-B0F7-CE65B3815CC9}\RP375\A0044839.exe Infected: Backdoor.Win32.Agent.ec skipped
C:\System Volume Information\_restore{8238BFE6-44BD-4B25-B0F7-CE65B3815CC9}\RP375\A0044840.exe Infected: Backdoor.Win32.Agent.ec skipped
C:\System Volume Information\_restore{8238BFE6-44BD-4B25-B0F7-CE65B3815CC9}\RP375\A0044842.exe Infected: Backdoor.Win32.Agent.ec skipped
C:\System Volume Information\_restore{8238BFE6-44BD-4B25-B0F7-CE65B3815CC9}\RP375\A0044844.exe Infected: Backdoor.Win32.Agent.ec skipped
C:\System Volume Information\_restore{8238BFE6-44BD-4B25-B0F7-CE65B3815CC9}\RP375\A0044845.exe Infected: Backdoor.Win32.Agent.ec skipped
C:\System Volume Information\_restore{8238BFE6-44BD-4B25-B0F7-CE65B3815CC9}\RP375\A0044846.exe Infected: Backdoor.Win32.Agent.ec skipped
C:\System Volume Information\_restore{8238BFE6-44BD-4B25-B0F7-CE65B3815CC9}\RP375\A0044847.exe Infected: Backdoor.Win32.Agent.ec skipped
C:\System Volume Information\_restore{8238BFE6-44BD-4B25-B0F7-CE65B3815CC9}\RP375\A0044849.exe Infected: Backdoor.Win32.Agent.ec skipped
C:\System Volume Information\_restore{8238BFE6-44BD-4B25-B0F7-CE65B3815CC9}\RP375\A0044850.exe Infected: Backdoor.Win32.Agent.ec skipped
C:\System Volume Information\_restore{8238BFE6-44BD-4B25-B0F7-CE65B3815CC9}\RP375\A0044851.exe Infected: Backdoor.Win32.Agent.ec skipped
C:\System Volume Information\_restore{8238BFE6-44BD-4B25-B0F7-CE65B3815CC9}\RP375\A0044852.exe Infected: Backdoor.Win32.Agent.ec skipped
C:\System Volume Information\_restore{8238BFE6-44BD-4B25-B0F7-CE65B3815CC9}\RP375\A0044853.exe Infected: Backdoor.Win32.Agent.ec skipped
C:\System Volume Information\_restore{8238BFE6-44BD-4B25-B0F7-CE65B3815CC9}\RP375\A0044854.exe Infected: Backdoor.Win32.Agent.ec skipped
C:\System Volume Information\_restore{8238BFE6-44BD-4B25-B0F7-CE65B3815CC9}\RP375\A0044855.exe Infected: Backdoor.Win32.Agent.ec skipped
C:\System Volume Information\_restore{8238BFE6-44BD-4B25-B0F7-CE65B3815CC9}\RP375\A0044856.exe Infected: Backdoor.Win32.Agent.ec skipped
C:\System Volume Information\_restore{8238BFE6-44BD-4B25-B0F7-CE65B3815CC9}\RP375\A0044857.exe Infected: Backdoor.Win32.Agent.ec skipped
C:\System Volume Information\_restore{8238BFE6-44BD-4B25-B0F7-CE65B3815CC9}\RP375\A0044858.exe Infected: Backdoor.Win32.Agent.ec skipped
C:\System Volume Information\_restore{8238BFE6-44BD-4B25-B0F7-CE65B3815CC9}\RP375\A0044859.exe Infected: Backdoor.Win32.Agent.ec skipped
C:\System Volume Information\_restore{8238BFE6-44BD-4B25-B0F7-CE65B3815CC9}\RP375\A0044860.exe Infected: Backdoor.Win32.Agent.ec skipped
C:\System Volume Information\_restore{8238BFE6-44BD-4B25-B0F7-CE65B3815CC9}\RP375\A0044861.exe Infected: Backdoor.Win32.Agent.ec skipped
C:\System Volume Information\_restore{8238BFE6-44BD-4B25-B0F7-CE65B3815CC9}\RP375\A0044862.exe Infected: Backdoor.Win32.Agent.ec skipped
C:\System Volume Information\_restore{8238BFE6-44BD-4B25-B0F7-CE65B3815CC9}\RP375\A0044863.exe Infected: Backdoor.Win32.Agent.ec skipped
C:\System Volume Information\_restore{8238BFE6-44BD-4B25-B0F7-CE65B3815CC9}\RP375\A0044864.exe Infected: Backdoor.Win32.Agent.ec skipped
C:\System Volume Information\_restore{8238BFE6-44BD-4B25-B0F7-CE65B3815CC9}\RP375\A0044865.exe Infected: Backdoor.Win32.Agent.ec skipped
C:\System Volume Information\_restore{8238BFE6-44BD-4B25-B0F7-CE65B3815CC9}\RP375\A0044866.exe Infected: Backdoor.Win32.Agent.ec skipped
C:\System Volume Information\_restore{8238BFE6-44BD-4B25-B0F7-CE65B3815CC9}\RP375\A0044868.exe Infected: Backdoor.Win32.Agent.ec skipped
C:\System Volume Information\_restore{8238BFE6-44BD-4B25-B0F7-CE65B3815CC9}\RP375\A0044869.exe Infected: Backdoor.Win32.Agent.ec skipped
C:\System Volume Information\_restore{8238BFE6-44BD-4B25-B0F7-CE65B3815CC9}\RP375\A0044870.exe Infected: Backdoor.Win32.Agent.ec skipped
C:\System Volume Information\_restore{8238BFE6-44BD-4B25-B0F7-CE65B3815CC9}\RP375\A0044871.exe Infected: Backdoor.Win32.Agent.ec skipped
C:\System Volume Information\_restore{8238BFE6-44BD-4B25-B0F7-CE65B3815CC9}\RP375\A0044872.exe Infected: Backdoor.Win32.Agent.ec skipped
C:\System Volume Information\_restore{8238BFE6-44BD-4B25-B0F7-CE65B3815CC9}\RP375\A0044873.exe Infected: Backdoor.Win32.Agent.ec skipped
C:\System Volume Information\_restore{8238BFE6-44BD-4B25-B0F7-CE65B3815CC9}\RP375\A0044874.exe Infected: Backdoor.Win32.Agent.ec skipped
C:\System Volume Information\_restore{8238BFE6-44BD-4B25-B0F7-CE65B3815CC9}\RP375\A0044875.exe Infected: Backdoor.Win32.Agent.ec skipped
C:\System Volume Information\_restore{8238BFE6-44BD-4B25-B0F7-CE65B3815CC9}\RP375\A0044876.exe Infected: Backdoor.Win32.Agent.ec skipped
C:\System Volume Information\_restore{8238BFE6-44BD-4B25-B0F7-CE65B3815CC9}\RP375\A0044877.exe Infected: Backdoor.Win32.Agent.ec skipped
C:\System Volume Information\_restore{8238BFE6-44BD-4B25-B0F7-CE65B3815CC9}\RP375\A0044878.exe Infected: Backdoor.Win32.Agent.ec skipped
C:\System Volume Information\_restore{8238BFE6-44BD-4B25-B0F7-CE65B3815CC9}\RP375\A0044879.exe Infected: Backdoor.Win32.Agent.ec skipped
C:\System Volume Information\_restore{8238BFE6-44BD-4B25-B0F7-CE65B3815CC9}\RP375\A0044880.exe Infected: Backdoor.Win32.Agent.ec skipped
C:\System Volume Information\_restore{8238BFE6-44BD-4B25-B0F7-CE65B3815CC9}\RP375\A0044882.exe Infected: Backdoor.Win32.Agent.ec skipped
C:\System Volume Information\_restore{8238BFE6-44BD-4B25-B0F7-CE65B3815CC9}\RP375\A0044883.exe Infected: Backdoor.Win32.Agent.ec skipped
C:\System Volume Information\_restore{8238BFE6-44BD-4B25-B0F7-CE65B3815CC9}\RP375\A0044884.exe Infected: Backdoor.Win32.Agent.ec skipped
C:\System Volume Information\_restore{8238BFE6-44BD-4B25-B0F7-CE65B3815CC9}\RP375\A0044885.exe Infected: Backdoor.Win32.Agent.ec skipped
C:\System Volume Information\_restore{8238BFE6-44BD-4B25-B0F7-CE65B3815CC9}\RP375\A0044886.exe Infected: Backdoor.Win32.Agent.ec skipped
C:\System Volume Information\_restore{8238BFE6-44BD-4B25-B0F7-CE65B3815CC9}\RP375\A0044887.exe Infected: Backdoor.Win32.Agent.ec skipped
C:\System Volume Information\_restore{8238BFE6-44BD-4B25-B0F7-CE65B3815CC9}\RP375\A0044888.exe Infected: Backdoor.Win32.Agent.ec skipped
C:\System Volume Information\_restore{8238BFE6-44BD-4B25-B0F7-CE65B3815CC9}\RP375\A0044889.exe Infected: Backdoor.Win32.Agent.ec skipped
C:\System Volume Information\_restore{8238BFE6-44BD-4B25-B0F7-CE65B3815CC9}\RP375\A0044890.exe Infected: Backdoor.Win32.Agent.ec skipped
C:\System Volume Information\_restore{8238BFE6-44BD-4B25-B0F7-CE65B3815CC9}\RP375\A0044891.exe Infected: Backdoor.Win32.Agent.ec skipped
C:\System Volume Information\_restore{8238BFE6-44BD-4B25-B0F7-CE65B3815CC9}\RP375\A0044892.exe Infected: Backdoor.Win32.Agent.ec skipped
C:\System Volume Information\_restore{8238BFE6-44BD-4B25-B0F7-CE65B3815CC9}\RP375\A0044893.exe Infected: Backdoor.Win32.Agent.ec skipped
C:\System Volume Information\_restore{8238BFE6-44BD-4B25-B0F7-CE65B3815CC9}\RP375\A0044894.exe Infected: Backdoor.Win32.Agent.ec skipped
C:\System Volume Information\_restore{8238BFE6-44BD-4B25-B0F7-CE65B3815CC9}\RP375\A0044895.exe Infected: Backdoor.Win32.Agent.ec skipped
C:\System Volume Information\_restore{8238BFE6-44BD-4B25-B0F7-CE65B3815CC9}\RP375\A0044897.exe Infected: Backdoor.Win32.Agent.ec skipped
C:\System Volume Information\_restore{8238BFE6-44BD-4B25-B0F7-CE65B3815CC9}\RP375\A0044899.exe Infected: Backdoor.Win32.Agent.ec skipped
C:\System Volume Information\_restore{8238BFE6-44BD-4B25-B0F7-CE65B3815CC9}\RP375\A0044900.exe Infected: Backdoor.Win32.Agent.ec skipped
C:\System Volume Information\_restore{8238BFE6-44BD-4B25-B0F7-CE65B3815CC9}\RP375\A0044901.exe Infected: Backdoor.Win32.Agent.ec skipped
C:\System Volume Information\_restore{8238BFE6-44BD-4B25-B0F7-CE65B3815CC9}\RP375\A0044902.exe Infected: Backdoor.Win32.Agent.ec skipped
C:\System Volume Information\_restore{8238BFE6-44BD-4B25-B0F7-CE65B3815CC9}\RP375\A0044903.exe Infected: Backdoor.Win32.Agent.ec skipped
C:\System Volume Information\_restore{8238BFE6-44BD-4B25-B0F7-CE65B3815CC9}\RP375\A0044904.exe Infected: Backdoor.Win32.Agent.ec skipped
C:\System Volume Information\_restore{8238BFE6-44BD-4B25-B0F7-CE65B3815CC9}\RP375\A0044905.exe Infected: Backdoor.Win32.Agent.ec skipped
C:\System Volume Information\_restore{8238BFE6-44BD-4B25-B0F7-CE65B3815CC9}\RP375\A0044906.exe Infected: Backdoor.Win32.Agent.ec skipped
C:\System Volume Information\_restore{8238BFE6-44BD-4B25-B0F7-CE65B3815CC9}\RP375\A0044907.exe Infected: Backdoor.Win32.Agent.ec skipped
C:\System Volume Information\_restore{8238BFE6-44BD-4B25-B0F7-CE65B3815CC9}\RP375\A0044908.exe Infected: Backdoor.Win32.Agent.ec skipped
C:\System Volume Information\_restore{8238BFE6-44BD-4B25-B0F7-CE65B3815CC9}\RP375\A0044910.exe Infected: Backdoor.Win32.Agent.ec skipped
C:\System Volume Information\_restore{8238BFE6-44BD-4B25-B0F7-CE65B3815CC9}\RP375\A0044911.exe Infected: Backdoor.Win32.Agent.ec skipped
C:\System Volume Information\_restore{8238BFE6-44BD-4B25-B0F7-CE65B3815CC9}\RP375\A0044912.exe Infected: Backdoor.Win32.Agent.ec skipped
C:\System Volume Information\_restore{8238BFE6-44BD-4B25-B0F7-CE65B3815CC9}\RP375\A0044913.exe Infected: Backdoor.Win32.Agent.ec skipped
C:\System Volume Information\_restore{8238BFE6-44BD-4B25-B0F7-CE65B3815CC9}\RP375\A0044914.exe Infected: Backdoor.Win32.Agent.ec skipped
C:\System Volume Information\_restore{8238BFE6-44BD-4B25-B0F7-CE65B3815CC9}\RP375\A0044915.exe Infected: Backdoor.Win32.Agent.ec skipped
C:\System Volume Information\_restore{8238BFE6-44BD-4B25-B0F7-CE65B3815CC9}\RP375\A0044916.exe Infected: Backdoor.Win32.Agent.ec skipped
C:\System Volume Information\_restore{8238BFE6-44BD-4B25-B0F7-CE65B3815CC9}\RP375\A0044917.exe Infected: Backdoor.Win32.Agent.ec skipped
C:\System Volume Information\_restore{8238BFE6-44BD-4B25-B0F7-CE65B3815CC9}\RP375\A0044918.exe Infected: Backdoor.Win32.Agent.ec skipped
C:\System Volume Information\_restore{8238BFE6-44BD-4B25-B0F7-CE65B3815CC9}\RP375\A0044919.exe Infected: Backdoor.Win32.Agent.ec skipped
C:\System Volume Information\_restore{8238BFE6-44BD-4B25-B0F7-CE65B3815CC9}\RP375\A0044920.exe Infected: Backdoor.Win32.Agent.ec skipped
C:\System Volume Information\_restore{8238BFE6-44BD-4B25-B0F7-CE65B3815CC9}\RP375\A0044921.exe Infected: Backdoor.Win32.Agent.ec skipped
C:\System Volume Information\_restore{8238BFE6-44BD-4B25-B0F7-CE65B3815CC9}\RP375\A0044922.exe Infected: Backdoor.Win32.Agent.gl skipped
C:\System Volume Information\_restore{8238BFE6-44BD-4B25-B0F7-CE65B3815CC9}\RP375\A0044923.exe Infected: Backdoor.Win32.Agent.gl skipped
C:\System Volume Information\_restore{8238BFE6-44BD-4B25-B0F7-CE65B3815CC9}\RP375\A0044924.exe Infected: Backdoor.Win32.Agent.gl skipped
C:\System Volume Information