ComboFix 08-02.01.6 - CMoney 2008-02-02 10:02:51.4 - NTFSx86
Microsoft Windows XP Home Edition 5.1.2600.2.1252.1.1033.18.108 [GMT -6:00]
Running from: C:\Documents and Settings\CMoney\Desktop\ComboFix.exe
Command switches used :: C:\Documents and Settings\CMoney\Desktop\CFScript.txt
* Created a new restore point
WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!FILE
C:\WINDOWS\system32\ssttq.dll
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
C:\Documents and Settings\All Users\Application Data\Microsoft\Network\Downloader\qmgr0.dat
C:\Documents and Settings\All Users\Application Data\Microsoft\Network\Downloader\qmgr1.dat
C:\WINDOWS\system32\wowfx.dll . . . . failed to delete
----- BITS: Possible infected sites -----
hxxp://au.download.windowsupdate.com
.
((((((((((((((((((((((((( Files Created from 2008-01-02 to 2008-02-02 )))))))))))))))))))))))))))))))
.
2008-02-01 20:01 . 2008-02-01 20:01 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Trymedia
2008-02-01 19:05 . 2008-02-01 19:05 <DIR> d-------- C:\Program Files\Eidos Interactive
2008-02-01 16:47 . 2008-02-01 16:47 1,694 --a------ C:\WINDOWS\system32\tmp.reg
2008-02-01 16:46 . 2007-09-05 23:22 289,144 --a------ C:\WINDOWS\system32\VCCLSID.exe
2008-02-01 16:46 . 2006-04-27 16:49 288,417 --a------ C:\WINDOWS\system32\SrchSTS.exe
2008-02-01 16:46 . 2008-01-27 14:37 81,920 --a------ C:\WINDOWS\system32\IEDFix.exe
2008-02-01 16:46 . 2003-06-05 20:13 53,248 --a------ C:\WINDOWS\system32\Process.exe
2008-02-01 16:46 . 2004-07-31 17:50 51,200 --a------ C:\WINDOWS\system32\dumphive.exe
2008-02-01 16:46 . 2007-10-03 23:36 25,600 --a------ C:\WINDOWS\system32\WS2Fix.exe
2008-01-31 18:06 . 2008-01-31 18:06 <DIR> d-------- C:\Deckard
2008-01-31 17:37 . 2008-01-31 17:37 <DIR> d-------- C:\VundoFix Backups
2008-01-28 21:47 . 2008-01-28 21:47 <DIR> d-------- C:\Program Files\Trend Micro
2008-01-26 23:05 . 2004-08-27 03:54 <DIR> d-------- C:\Documents and Settings\Administrator\WINDOWS
2008-01-23 22:05 . 2008-01-23 22:05 <DIR> d-------- C:\Documents and Settings\CMoney\Application Data\MySpace
2008-01-22 20:14 . 2005-05-17 12:37 1,986,560 --a------ C:\WINDOWS\system32\NCTAudioFile2.dll
2008-01-22 20:14 . 2005-05-18 11:52 1,212,416 --a------ C:\WINDOWS\system32\NCTAudioInformation2.dll
2008-01-22 20:14 . 2005-04-15 12:08 880,640 --a------ C:\WINDOWS\system32\NCTAudioEditor2.dll
2008-01-22 20:14 . 2005-04-04 17:21 602,112 --a------ C:\WINDOWS\system32\NCTAudioTransform2.dll
2008-01-22 20:14 . 2005-03-28 15:54 479,232 --a------ C:\WINDOWS\system32\NCTAudioVisualization2.dll
2008-01-22 20:14 . 2005-04-25 13:01 458,752 --a------ C:\WINDOWS\system32\NCTAudioRecord2.dll
2008-01-22 20:14 . 2005-04-25 13:01 458,752 --a------ C:\WINDOWS\system32\NCTAudioPlayer2.dll
2008-01-22 20:14 . 2005-03-28 15:56 417,792 --a------ C:\WINDOWS\system32\NCTAudioDisplay2.dll
2008-01-22 20:14 . 2005-04-04 15:06 348,160 --a------ C:\WINDOWS\system32\NCTWMAFile2.dll
2008-01-22 20:14 . 2006-03-23 12:56 113,486 --a------ C:\WINDOWS\system32\NCTWMAProfiles.prx
2008-01-22 20:13 . 2005-03-29 07:57 2,084,864 --a------ C:\WINDOWS\system32\NCTAudioDesign2.dll
2008-01-22 20:13 . 2004-11-04 13:31 835,584 --a------ C:\WINDOWS\system32\NCTAudioCDGrabber2.dll
2008-01-22 20:13 . 2002-01-05 14:37 344,064 --a------ C:\WINDOWS\system32\msvcr70.dll
2008-01-14 20:27 . 2008-01-14 20:27 1,751 --a------ C:\WINDOWS\system32\jsoqhmcs.dll
2008-01-13 14:53 . 2008-01-13 14:54 <DIR> d-------- C:\WINDOWS\vf_hip
2008-01-13 14:53 . 2008-01-26 19:02 <DIR> d-------- C:\Program Files\Hide IP Platinum
2008-01-13 01:26 . 2008-01-13 01:36 0 --a------ C:\WINDOWS\galaxy.ini
2008-01-06 22:34 . 2007-09-05 01:46 92,544 --a------ C:\WINDOWS\system32\drivers\mcdbus.sys
2008-01-06 22:28 . 2008-01-23 23:10 <DIR> d-------- C:\Program Files\MagicISO
2008-01-02 23:20 . 2004-08-04 00:56 116,224 --a--c--- C:\WINDOWS\system32\dllcache\xrxwiadr.dll
2008-01-02 23:20 . 2001-08-17 22:36 23,040 --a--c--- C:\WINDOWS\system32\dllcache\xrxwbtmp.dll
2008-01-02 23:18 . 2001-08-17 13:28 771,581 --a--c--- C:\WINDOWS\system32\dllcache\winacisa.sys
2008-01-02 23:17 . 2001-08-17 13:28 765,884 --a--c--- C:\WINDOWS\system32\dllcache\usrti.sys
2008-01-02 23:16 . 2001-08-17 13:28 794,654 --a--c--- C:\WINDOWS\system32\dllcache\usr1801.sys
2008-01-02 23:15 . 2001-08-17 22:36 525,568 --a--c--- C:\WINDOWS\system32\dllcache\tridxp.dll
2008-01-02 23:14 . 2004-08-04 13:00 571,392 --a--c--- C:\WINDOWS\system32\dllcache\tintlgnt.ime
2008-01-02 23:13 . 2001-08-17 14:56 172,768 --a--c--- C:\WINDOWS\system32\dllcache\t2r4disp.dll
2008-01-02 23:13 . 2001-08-17 13:50 103,936 --a--c--- C:\WINDOWS\system32\dllcache\sx.sys
2008-01-02 23:13 . 2001-08-17 22:36 94,293 --a--c--- C:\WINDOWS\system32\dllcache\sxports.dll
2008-01-02 23:13 . 2001-08-17 12:13 37,961 --a--c--- C:\WINDOWS\system32\dllcache\tdk100b.sys
2008-01-02 23:13 . 2001-08-17 12:50 36,640 --a--c--- C:\WINDOWS\system32\dllcache\t2r4mini.sys
2008-01-02 23:13 . 2001-08-17 13:49 30,464 --a--c--- C:\WINDOWS\system32\dllcache\tbatm155.sys
2008-01-02 23:13 . 2001-08-17 12:13 17,129 --a--c--- C:\WINDOWS\system32\dllcache\tdkcd31.sys
2008-01-02 23:13 . 2001-08-17 13:52 7,040 --a--c--- C:\WINDOWS\system32\dllcache\tandqic.sys
2008-01-02 23:11 . 2004-08-04 13:00 456,704 --a--c--- C:\WINDOWS\system32\dllcache\smtpsvc.dll
2008-01-02 23:10 . 2004-08-03 22:41 404,990 --a--c--- C:\WINDOWS\system32\dllcache\slntamr.sys
2008-01-02 23:09 . 2001-08-17 22:36 386,560 --a--c--- C:\WINDOWS\system32\dllcache\sgiul50.dll
2008-01-02 23:08 . 2001-08-17 22:36 495,616 --a--c--- C:\WINDOWS\system32\dllcache\sblfx.dll
2008-01-02 23:07 . 2004-08-04 00:56 397,056 --a--c--- C:\WINDOWS\system32\dllcache\s3gnb.dll
2008-01-02 23:06 . 2001-08-17 12:19 30,720 --a--c--- C:\WINDOWS\system32\dllcache\rthwcls.sys
2008-01-02 23:06 . 2001-08-17 22:36 26,624 --a--c--- C:\WINDOWS\system32\dllcache\rw450ext.dll
2008-01-02 23:06 . 2001-08-17 22:36 24,576 --a--c--- C:\WINDOWS\system32\dllcache\rw430ext.dll
2008-01-02 23:06 . 2004-08-03 22:31 20,992 --a--c--- C:\WINDOWS\system32\dllcache\rtl8139.sys
2008-01-02 23:06 . 2001-08-17 12:12 19,017 --a--c--- C:\WINDOWS\system32\dllcache\rtl8029.sys
2008-01-02 23:06 . 2001-08-17 22:36 9,216 --a--c--- C:\WINDOWS\system32\dllcache\rsmgrstr.dll
2008-01-02 23:05 . 2004-08-03 22:59 79,104 --a--c--- C:\WINDOWS\system32\dllcache\rocket.sys
2008-01-02 23:05 . 2004-08-03 23:10 59,648 --a--c--- C:\WINDOWS\system32\dllcache\rfcomm.sys
2008-01-02 23:05 . 2001-08-17 12:12 37,563 --a--c--- C:\WINDOWS\system32\dllcache\rlnet5.sys
2008-01-02 23:05 . 2004-08-03 23:04 30,080 --a--c--- C:\WINDOWS\system32\dllcache\rndismpx.sys
2008-01-02 23:05 . 2004-08-04 13:00 26,112 --a--c--- C:\WINDOWS\system32\dllcache\romanime.ime
2008-01-02 23:05 . 2001-08-17 12:19 3,840 --a--c--- C:\WINDOWS\system32\dllcache\rpfun.sys
2008-01-02 23:04 . 2001-08-17 22:36 86,097 --a--c--- C:\WINDOWS\system32\dllcache\reslog32.dll
2008-01-02 23:04 . 2004-08-04 13:00 20,736 --a--c--- C:\WINDOWS\system32\dllcache\ramdisk.sys
2008-01-02 23:04 . 2001-08-17 13:51 19,584 --a--c--- C:\WINDOWS\system32\dllcache\rasirda.sys
2008-01-02 23:04 . 2004-08-03 22:41 13,776 --a--c--- C:\WINDOWS\system32\dllcache\recagent.sys
2008-01-02 23:02 . 2004-08-04 13:00 482,304 --a--c--- C:\WINDOWS\system32\dllcache\pintlgnt.ime
2008-01-02 23:01 . 2001-08-17 14:05 351,616 --a--c--- C:\WINDOWS\system32\dllcache\ovcodek2.sys
2008-01-02 23:00 . 2001-08-17 12:50 198,144 --a--c--- C:\WINDOWS\system32\dllcache\nv3.sys
2008-01-02 22:59 . 2004-08-03 22:31 132,695 --a--c--- C:\WINDOWS\system32\dllcache\netwlan5.sys
2008-01-02 22:58 . 2004-08-04 00:56 1,737,856 --a--c--- C:\WINDOWS\system32\dllcache\mtxparhd.dll
2008-01-02 22:57 . 2001-08-17 12:50 320,384 --a--c--- C:\WINDOWS\system32\dllcache\mgaum.sys
2008-01-02 22:57 . 2004-08-04 00:56 56,832 --a--c--- C:\WINDOWS\system32\dllcache\msdvbnp.ax
2008-01-02 22:57 . 2004-08-03 23:10 51,328 --a--c--- C:\WINDOWS\system32\dllcache\msdv.sys
2008-01-02 22:57 . 2001-08-17 14:02 35,200 --a--c--- C:\WINDOWS\system32\dllcache\msgame.sys
2008-01-02 22:57 . 2001-08-17 13:57 16,128 --a--c--- C:\WINDOWS\system32\dllcache\modemcsa.sys
2008-01-02 22:57 . 2004-08-03 23:10 15,360 --a--c--- C:\WINDOWS\system32\dllcache\mpe.sys
2008-01-02 22:57 . 2001-08-17 13:48 12,160 --a--c--- C:\WINDOWS\system32\dllcache\mouhid.sys
2008-01-02 22:57 . 2004-08-04 13:00 7,680 --a--c--- C:\WINDOWS\system32\dllcache\migregdb.exe
2008-01-02 22:57 . 2001-08-17 13:52 6,528 --a--c--- C:\WINDOWS\system32\dllcache\miniqic.sys
2008-01-02 22:57 . 2001-08-17 13:48 6,016 --a--c--- C:\WINDOWS\system32\dllcache\msfsio.sys
2008-01-02 22:56 . 2001-08-17 14:56 235,648 --a--c--- C:\WINDOWS\system32\dllcache\mgaud.dll
2008-01-02 22:56 . 2001-08-17 12:12 164,586 --a--c--- C:\WINDOWS\system32\dllcache\mdgndis5.sys
2008-01-02 22:56 . 2001-08-17 22:36 58,880 --a--c--- C:\WINDOWS\system32\dllcache\m3092dc.dll
2008-01-02 22:56 . 2001-08-17 12:19 48,768 --a--c--- C:\WINDOWS\system32\dllcache\maestro.sys
2008-01-02 22:56 . 2001-08-17 22:36 47,616 --a--c--- C:\WINDOWS\system32\dllcache\memgrp.dll
2008-01-02 22:56 . 2004-08-03 23:00 26,112 --a--c--- C:\WINDOWS\system32\dllcache\memstpci.sys
2008-01-02 22:56 . 2001-08-17 13:58 8,320 --a--c--- C:\WINDOWS\system32\dllcache\memcard.sys
2008-01-02 22:56 . 2001-08-17 13:52 7,424 --a--c--- C:\WINDOWS\system32\dllcache\mammoth.sys
2008-01-02 22:54 . 2001-08-17 22:36 242,176 --a--c--- C:\WINDOWS\system32\dllcache\kdsusd.dll
2008-01-02 22:53 . 2004-08-04 00:56 152,576 --a--c--- C:\WINDOWS\system32\dllcache\irftp.exe
2008-01-02 22:52 . 2004-08-04 13:00 811,064 --a--c--- C:\WINDOWS\system32\dllcache\imjp81k.dll
2008-01-02 22:51 . 2004-08-03 22:41 1,041,536 --a--c--- C:\WINDOWS\system32\dllcache\hsfdpsp2.sys
2008-01-02 22:50 . 2001-08-17 13:28 391,199 --a--c--- C:\WINDOWS\system32\dllcache\hsf_k56k.sys
2008-01-02 22:49 . 2001-08-17 14:56 1,733,120 --a--c--- C:\WINDOWS\system32\dllcache\g400d.dll
2008-01-02 22:48 . 2001-08-17 12:15 455,680 --a--c--- C:\WINDOWS\system32\dllcache\fus2base.sys
2008-01-02 22:47 . 2001-08-17 13:28 634,134 --a--c--- C:\WINDOWS\system32\dllcache\el656ct5.sys
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-01-27 01:05 --------- d-----w C:\Program Files\Windows Media Connect 2
2008-01-27 01:04 --------- d-----w C:\Program Files\Support Tools
2008-01-27 01:02 --------- d-----w C:\Program Files\Desktop
2008-01-27 01:02 --------- d-----w C:\Program Files\Common Files\Motive
2008-01-12 08:40 --------- d--h--w C:\Program Files\InstallShield Installation Information
2008-01-03 08:16 --------- d-----w C:\Documents and Settings\CMoney\Application Data\Yahoo!
2007-12-29 09:31 --------- d-----w C:\Program Files\Common Files\Symantec Shared
2007-12-29 09:28 --------- d-----w C:\Program Files\Common Files\Download Manager
2007-12-27 02:53 --------- d-----w C:\Documents and Settings\All Users\Application Data\TEMP
2007-12-20 22:51 --------- d-----w C:\Program Files\Network Chemistry
2007-12-18 00:26 --------- d-----w C:\Documents and Settings\All Users\Application Data\{CFAB4006-0AE0-414D-866A-DCB2C46553CF}
2007-12-04 14:56 93,264 ----a-w C:\WINDOWS\system32\drivers\aswmon.sys
2007-12-04 14:55 94,544 ----a-w C:\WINDOWS\system32\drivers\aswmon2.sys
2007-12-04 14:53 23,152 ----a-w C:\WINDOWS\system32\drivers\aswRdr.sys
2007-12-04 14:51 42,912 ----a-w C:\WINDOWS\system32\drivers\aswTdi.sys
2007-12-04 14:49 26,624 ----a-w C:\WINDOWS\system32\drivers\aavmker4.sys
2007-12-03 01:04 --------- d-----w C:\Program Files\BroadJump
2007-04-08 22:13 15,916 -c--a-w C:\Program Files\Log.txt
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{503FB2AD-1F78-4DE2-97AF-737104478C21}]
C:\WINDOWS\system32\ssttq.dll
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2008-01-14 19:37 15360]
"DLD.EXE"="C:\Program Files\Download Direct\DLD.exe" [ ]
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\securityproviders]
SecurityProviders msapsspc.dll, schannel.dll, digest.dll, msnsspc.dll,
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Multi-function Keyboard]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SynTPEnh]
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SynTPLpr]
C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
R3 ATI_WDMAUD;ATI Integrated Digital Audio;C:\WINDOWS\system32\drivers\atiwdma.sys [2006-03-08 17:06]
R3 tenCapture;tenCapture;C:\WINDOWS\system32\DRIVERS\tenCapture.sys [2007-04-21 08:15]
S3 CBEN5;Xircom CardBus Ethernet 10/100 Adapter family Driver;C:\WINDOWS\system32\DRIVERS\cben5.sys [2001-08-17 11:13]
S3 DCamUSBUVT;ICM532A;C:\WINDOWS\system32\Drivers\usbuvt.sys []
S3 NSNDIS5;NSNDIS5 NDIS Protocol Driver;C:\WINDOWS\system32\NSNDIS5.SYS []
S3 SymIM;Symantec Network Security Intermediate Filter Service;C:\WINDOWS\system32\DRIVERS\SymIM.sys []
S3 SymIMMP;SymIMMP;C:\WINDOWS\system32\DRIVERS\SymIM.sys []
S3 USB_RNDIS_XP;Westell WireSpeed Dual Connect Modem;C:\WINDOWS\system32\DRIVERS\usb8023.sys [2004-08-04 13:00]
.
**************************************************************************
catchme 0.3.1344 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.netRootkit scan 2008-02-02 10:08:30
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
------------------------ Other Running Processes ------------------------
.
C:\WINDOWS\system32\Ati2evxx.exe
C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
C:\Program Files\Alwil Software\Avast4\ashServ.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\Program Files\Common Files\New Boundary\PrismXL\PRISMXL.SYS
C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
C:\WINDOWS\system32\rundll32.exe
.
**************************************************************************
.
Completion time: 2008-02-02 10:13:26 - machine was rebooted
ComboFix-quarantined-files.txt 2008-02-02 16:13:21
ComboFix2.txt 2008-02-02 07:33:13
ComboFix3.txt 2008-02-01 22:41:51
.
2008-02-02 15:56:29 --- E O F ---
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
-------------------------------------------------------------------------------
KASPERSKY ONLINE SCANNER REPORT
Saturday, February 02, 2008 4:45:15 PM
Operating System: Microsoft Windows XP Home Edition, Service Pack 2 (Build 2600)
Kaspersky Online Scanner version: 5.0.98.0
Kaspersky Anti-Virus database last update: 2/02/2008
Kaspersky Anti-Virus database records: 545991
-------------------------------------------------------------------------------
Scan Settings:
Scan using the following antivirus database: extended
Scan Archives: true
Scan Mail Bases: true
Scan Target - My Computer:
C:\
D:\
Scan Statistics:
Total number of scanned objects: 61161
Number of viruses found: 16
Number of infected objects: 258
Number of suspicious objects: 0
Duration of the scan process: 00:59:53
Infected Object Name / Virus Name / Last Action
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\38a0684cc5aeddb28e3ba828369fd43c_6cc9fa0b-102a-425e-bbb4-b538ff860a59 Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\511a0f3f9e960fa97de3d0b74adfc574_6cc9fa0b-102a-425e-bbb4-b538ff860a59 Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Dr Watson\user.dmp Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Network\Downloader\qmgr0.dat Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Network\Downloader\qmgr1.dat Object is locked skipped
C:\Documents and Settings\CMoney\Application Data\Mozilla\Firefox\Profiles\ovxxmgoz.default\cert8.db Object is locked skipped
C:\Documents and Settings\CMoney\Application Data\Mozilla\Firefox\Profiles\ovxxmgoz.default\formhistory.dat Object is locked skipped
C:\Documents and Settings\CMoney\Application Data\Mozilla\Firefox\Profiles\ovxxmgoz.default\history.dat Object is locked skipped
C:\Documents and Settings\CMoney\Application Data\Mozilla\Firefox\Profiles\ovxxmgoz.default\key3.db Object is locked skipped
C:\Documents and Settings\CMoney\Application Data\Mozilla\Firefox\Profiles\ovxxmgoz.default\parent.lock Object is locked skipped
C:\Documents and Settings\CMoney\Application Data\Mozilla\Firefox\Profiles\ovxxmgoz.default\search.sqlite Object is locked skipped
C:\Documents and Settings\CMoney\Application Data\Mozilla\Firefox\Profiles\ovxxmgoz.default\urlclassifier2.sqlite Object is locked skipped
C:\Documents and Settings\CMoney\Application Data\Sun\Java\Deployment\cache\6.0\32\7836d960-49600138/VaannnaaBaa.class Infected: Trojan.Java.ClassLoader.as skipped
C:\Documents and Settings\CMoney\Application Data\Sun\Java\Deployment\cache\6.0\32\7836d960-49600138 ZIP: infected - 1 skipped
C:\Documents and Settings\CMoney\Application Data\Sun\Java\Deployment\cache\6.0\37\3e36ace5-3663d952/Installer.class Infected: Trojan-Downloader.Java.OpenConnection.ao skipped
C:\Documents and Settings\CMoney\Application Data\Sun\Java\Deployment\cache\6.0\37\3e36ace5-3663d952 ZIP: infected - 1 skipped
C:\Documents and Settings\CMoney\Cookies\index.dat Object is locked skipped
C:\Documents and Settings\CMoney\Desktop\SmitfraudFix\Reboot.exe Infected: not-a-virus:RiskTool.Win32.Reboot.f skipped
C:\Documents and Settings\CMoney\Desktop\SmitfraudFix.exe/data.rar/SmitfraudFix/Reboot.exe Infected: not-a-virus:RiskTool.Win32.Reboot.f skipped
C:\Documents and Settings\CMoney\Desktop\SmitfraudFix.exe/data.rar Infected: not-a-virus:RiskTool.Win32.Reboot.f skipped
C:\Documents and Settings\CMoney\Desktop\SmitfraudFix.exe RarSFX: infected - 2 skipped
C:\Documents and Settings\CMoney\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat Object is locked skipped
C:\Documents and Settings\CMoney\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped
C:\Documents and Settings\CMoney\Local Settings\Application Data\Mozilla\Firefox\Profiles\ovxxmgoz.default\Cache\_CACHE_001_ Object is locked skipped
C:\Documents and Settings\CMoney\Local Settings\Application Data\Mozilla\Firefox\Profiles\ovxxmgoz.default\Cache\_CACHE_002_ Object is locked skipped
C:\Documents and Settings\CMoney\Local Settings\Application Data\Mozilla\Firefox\Profiles\ovxxmgoz.default\Cache\_CACHE_003_ Object is locked skipped
C:\Documents and Settings\CMoney\Local Settings\Application Data\Mozilla\Firefox\Profiles\ovxxmgoz.default\Cache\_CACHE_MAP_ Object is locked skipped
C:\Documents and Settings\CMoney\Local Settings\History\History.IE5\index.dat Object is locked skipped
C:\Documents and Settings\CMoney\Local Settings\Temporary Internet Files\AntiPhishing\B3BB5BBA-E7D5-40AB-A041-A5B1C0B26C8F.dat Object is locked skipped
C:\Documents and Settings\CMoney\Local Settings\Temporary Internet Files\Content.IE5\index.dat Object is locked skipped
C:\Documents and Settings\CMoney\My Documents\New Downloads\CS3\Photoshop.exe Infected: Virus.Win32.Sality.p skipped
C:\Documents and Settings\CMoney\My Documents\New Downloads\CS3\Required\Droplet Template.exe Infected: Virus.Win32.Sality.p skipped
C:\Documents and Settings\CMoney\My Documents\New Downloads\nokia m.playa\NokiaMMSViewer.exe Infected: Virus.Win32.Sality.p skipped
C:\Documents and Settings\CMoney\NTUSER.DAT Object is locked skipped
C:\Documents and Settings\CMoney\ntuser.dat.LOG Object is locked skipped
C:\Documents and Settings\LocalService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat Object is locked skipped
C:\Documents and Settings\LocalService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped
C:\Documents and Settings\LocalService\Local Settings\Temp\Cookies\index.dat Object is locked skipped
C:\Documents and Settings\LocalService\Local Settings\Temp\History\History.IE5\index.dat Object is locked skipped
C:\Documents and Settings\LocalService\Local Settings\Temp\Temporary Internet Files\Content.IE5\index.dat Object is locked skipped
C:\Documents and Settings\LocalService\NTUSER.DAT Object is locked skipped
C:\Documents and Settings\LocalService\ntuser.dat.LOG Object is locked skipped
C:\Documents and Settings\NetworkService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat Object is locked skipped
C:\Documents and Settings\NetworkService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped
C:\Documents and Settings\NetworkService\NTUSER.DAT Object is locked skipped
C:\Documents and Settings\NetworkService\ntuser.dat.LOG Object is locked skipped
C:\Program Files\Alwil Software\Avast4\DATA\aswResp.dat Object is locked skipped
C:\Program Files\Alwil Software\Avast4\DATA\Avast4.db Object is locked skipped
C:\Program Files\Alwil Software\Avast4\DATA\integ\avast.int Object is locked skipped
C:\Program Files\Alwil Software\Avast4\DATA\log\AshWebSv.ws Object is locked skipped
C:\Program Files\Alwil Software\Avast4\DATA\log\aswMaiSv.log Object is locked skipped
C:\Program Files\Alwil Software\Avast4\DATA\log\nshield.log Object is locked skipped
C:\Program Files\Alwil Software\Avast4\DATA\report\Resident protection.txt Object is locked skipped
C:\QooBox\Quarantine\C\Program Files\winupdates\a.zip.vir/Setup.exe Infected: Worm.Win32.VB.an skipped
C:\QooBox\Quarantine\C\Program Files\winupdates\a.zip.vir ZIP: infected - 1 skipped
C:\QooBox\Quarantine\C\Program Files\zevivmte\rijelenk.dll.vir Infected: Trojan-Downloader.Win32.Zlob.fvi skipped
C:\QooBox\Quarantine\C\WINDOWS\PerfInfo\a95ykmXnPQuc.exe.vir Infected: not-a-virus:FraudTool.Win32.UltimateDefender.ab skipped
C:\QooBox\Quarantine\C\WINDOWS\PerfInfo\a95ykmXnPQud.exe.vir Infected: not-a-virus:FraudTool.Win32.UltimateDefender.ac skipped
C:\QooBox\Quarantine\C\WINDOWS\system32\vcmgrd32.dll.vir Infected: Virus.Win32.Sality.p skipped
C:\System Volume Information\MountPointManagerRemoteDatabase Object is locked skipped
C:\System Volume Information\_restore{F845E3DB-F751-4BE4-A620-64F2CA1BFB5F}\RP1\A0001472.exe Infected: Virus.Win32.Sality.p skipped
C:\System Volume Information\_restore{F845E3DB-F751-4BE4-A620-64F2CA1BFB5F}\RP1\A0001473.exe Infected: Virus.Win32.Sality.p skipped
C:\System Volume Information\_restore{F845E3DB-F751-4BE4-A620-64F2CA1BFB5F}\RP1\A0001474.exe Infected: Virus.Win32.Sality.p skipped
C:\System Volume Information\_restore{F845E3DB-F751-4BE4-A620-64F2CA1BFB5F}\RP1\A0001475.exe Infected: Virus.Win32.Sality.p skipped
C:\System Volume Information\_restore{F845E3DB-F751-4BE4-A620-64F2CA1BFB5F}\RP1\A0001476.exe Infected: Virus.Win32.Sality.p skipped
C:\System Volume Information\_restore{F845E3DB-F751-4BE4-A620-64F2CA1BFB5F}\RP1\A0001477.exe Infected: Virus.Win32.Sality.p skipped
C:\System Volume Information\_restore{F845E3DB-F751-4BE4-A620-64F2CA1BFB5F}\RP1\A0001478.exe Infected: Virus.Win32.Sality.p skipped
C:\System Volume Information\_restore{F845E3DB-F751-4BE4-A620-64F2CA1BFB5F}\RP1\A0001479.exe Infected: Virus.Win32.Sality.p skipped
C:\System Volume Information\_restore{F845E3DB-F751-4BE4-A620-64F2CA1BFB5F}\RP1\A0001480.exe Infected: Virus.Win32.Sality.p skipped
C:\System Volume Information\_restore{F845E3DB-F751-4BE4-A620-64F2CA1BFB5F}\RP1\A0001481.exe Infected: Virus.Win32.Sality.p skipped
C:\System Volume Information\_restore{F845E3DB-F751-4BE4-A620-64F2CA1BFB5F}\RP1\A0001482.exe Infected: Virus.Win32.Sality.p skipped
C:\System Volume Information\_restore{F845E3DB-F751-4BE4-A620-64F2CA1BFB5F}\RP1\A0001483.exe Infected: Virus.Win32.Sality.p skipped
C:\System Volume Information\_restore{F845E3DB-F751-4BE4-A620-64F2CA1BFB5F}\RP1\A0001484.exe Infected: Virus.Win32.Sality.p skipped
C:\System Volume Information\_restore{F845E3DB-F751-4BE4-A620-64F2CA1BFB5F}\RP1\A0001485.exe Infected: Virus.Win32.Sality.p skipped
C:\System Volume Information\_restore{F845E3DB-F751-4BE4-A620-64F2CA1BFB5F}\RP1\A0001486.exe Infected: Virus.Win32.Sality.p skipped
C:\System Volume Information\_restore{F845E3DB-F751-4BE4-A620-64F2CA1BFB5F}\RP1\A0001487.exe Infected: Virus.Win32.Sality.p skipped
C:\System Volume Information\_restore{F845E3DB-F751-4BE4-A620-64F2CA1BFB5F}\RP1\A0001488.exe Infected: Virus.Win32.Sality.p skipped
C:\System Volume Information\_restore{F845E3DB-F751-4BE4-A620-64F2CA1BFB5F}\RP1\A0001489.exe Infected: Virus.Win32.Sality.p skipped
C:\System Volume Information\_restore{F845E3DB-F751-4BE4-A620-64F2CA1BFB5F}\RP1\A0001490.exe Infected: Virus.Win32.Sality.p skipped
C:\System Volume Information\_restore{F845E3DB-F751-4BE4-A620-64F2CA1BFB5F}\RP1\A0001491.exe Infected: Virus.Win32.Sality.p skipped
C:\System Volume Information\_restore{F845E3DB-F751-4BE4-A620-64F2CA1BFB5F}\RP1\A0001492.exe Infected: Virus.Win32.Sality.p skipped
C:\System Volume Information\_restore{F845E3DB-F751-4BE4-A620-64F2CA1BFB5F}\RP1\A0001493.exe Infected: Virus.Win32.Sality.p skipped
C:\System Volume Information\_restore{F845E3DB-F751-4BE4-A620-64F2CA1BFB5F}\RP1\A0001494.exe Infected: Virus.Win32.Sality.p skipped
C:\System Volume Information\_restore{F845E3DB-F751-4BE4-A620-64F2CA1BFB5F}\RP1\A0001495.exe Infected: Virus.Win32.Sality.p skipped
C:\System Volume Information\_restore{F845E3DB-F751-4BE4-A620-64F2CA1BFB5F}\RP1\A0001496.exe Infected: Virus.Win32.Sality.p skipped
C:\System Volume Information\_restore{F845E3DB-F751-4BE4-A620-64F2CA1BFB5F}\RP1\A0001497.exe Infected: Virus.Win32.Sality.p skipped
C:\System Volume Information\_restore{F845E3DB-F751-4BE4-A620-64F2CA1BFB5F}\RP1\A0001498.exe Infected: Virus.Win32.Sality.p skipped
C:\System Volume Information\_restore{F845E3DB-F751-4BE4-A620-64F2CA1BFB5F}\RP1\A0001499.exe Infected: Virus.Win32.Sality.p skipped
C:\System Volume Information\_restore{F845E3DB-F751-4BE4-A620-64F2CA1BFB5F}\RP1\A0001500.exe Infected: Virus.Win32.Sality.p skipped
C:\System Volume Information\_restore{F845E3DB-F751-4BE4-A620-64F2CA1BFB5F}\RP1\A0001501.exe Infected: Virus.Win32.Sality.p skipped
C:\System Volume Information\_restore{F845E3DB-F751-4BE4-A620-64F2CA1BFB5F}\RP1\A0001502.exe Infected: Virus.Win32.Sality.p skipped
C:\System Volume Information\_restore{F845E3DB-F751-4BE4-A620-64F2CA1BFB5F}\RP1\A0001503.exe Infected: Virus.Win32.Sality.p skipped
C:\System Volume Information\_restore{F845E3DB-F751-4BE4-A620-64F2CA1BFB5F}\RP1\A0001504.exe Infected: Virus.Win32.Sality.p skipped
C:\System Volume Information\_restore{F845E3DB-F751-4BE4-A620-64F2CA1BFB5F}\RP1\A0001505.exe Infected: Virus.Win32.Sality.p skipped
C:\System Volume Information\_restore{F845E3DB-F751-4BE4-A620-64F2CA1BFB5F}\RP1\A0001506.exe Infected: Virus.Win32.Sality.p skipped
C:\System Volume Information\_restore{F845E3DB-F751-4BE4-A620-64F2CA1BFB5F}\RP1\A0001507.exe Infected: Virus.Win32.Sality.p skipped
C:\System Volume Information\_restore{F845E3DB-F751-4BE4-A620-64F2CA1BFB5F}\RP1\A0001508.exe Infected: Virus.Win32.Sality.p skipped
C:\System Volume Information\_restore{F845E3DB-F751-4BE4-A620-64F2CA1BFB5F}\RP1\A0001509.exe Infected: Virus.Win32.Sality.p skipped
C:\System Volume Information\_restore{F845E3DB-F751-4BE4-A620-64F2CA1BFB5F}\RP1\A0001510.exe Infected: Virus.Win32.Sality.p skipped
C:\System Volume Information\_restore{F845E3DB-F751-4BE4-A620-64F2CA1BFB5F}\RP1\A0001511.exe Infected: Virus.Win32.Sality.p skipped
C:\System Volume Information\_restore{F845E3DB-F751-4BE4-A620-64F2CA1BFB5F}\RP1\A0001512.exe Infected: Virus.Win32.Sality.p skipped
C:\System Volume Information\_restore{F845E3DB-F751-4BE4-A620-64F2CA1BFB5F}\RP1\A0001513.exe Infected: Virus.Win32.Sality.p skipped
C:\System Volume Information\_restore{F845E3DB-F751-4BE4-A620-64F2CA1BFB5F}\RP1\A0001514.exe Infected: Virus.Win32.Sality.p skipped
C:\System Volume Information\_restore{F845E3DB-F751-4BE4-A620-64F2CA1BFB5F}\RP1\A0001515.exe Infected: Virus.Win32.Sality.p skipped
C:\System Volume Information\_restore{F845E3DB-F751-4BE4-A620-64F2CA1BFB5F}\RP1\A0001516.exe Infected: Virus.Win32.Sality.p skipped
C:\System Volume Information\_restore{F845E3DB-F751-4BE4-A620-64F2CA1BFB5F}\RP1\A0001517.exe Infected: Virus.Win32.Sality.p skipped
C:\System Volume Information\_restore{F845E3DB-F751-4BE4-A620-64F2CA1BFB5F}\RP1\A0001518.exe Infected: Virus.Win32.Sality.p skipped
C:\System Volume Information\_restore{F845E3DB-F751-4BE4-A620-64F2CA1BFB5F}\RP1\A0001519.exe Infected: Virus.Win32.Sality.p skipped
C:\System Volume Information\_restore{F845E3DB-F751-4BE4-A620-64F2CA1BFB5F}\RP1\A0001520.exe Infected: Virus.Win32.Sality.p skipped
C:\System Volume Information\_restore{F845E3DB-F751-4BE4-A620-64F2CA1BFB5F}\RP1\A0001521.exe Infected: Virus.Win32.Sality.p skipped
C:\System Volume Information\_restore{F845E3DB-F751-4BE4-A620-64F2CA1BFB5F}\RP1\A0001522.exe Infected: Virus.Win32.Sality.p skipped
C:\System Volume Information\_restore{F845E3DB-F751-4BE4-A620-64F2CA1BFB5F}\RP1\A0001523.exe Infected: Virus.Win32.Sality.p skipped
C:\System Volume Information\_restore{F845E3DB-F751-4BE4-A620-64F2CA1BFB5F}\RP1\A0001524.exe Infected: Virus.Win32.Sality.p skipped
C:\System Volume Information\_restore{F845E3DB-F751-4BE4-A620-64F2CA1BFB5F}\RP1\A0001525.exe Infected: Virus.Win32.Sality.p skipped
C:\System Volume Information\_restore{F845E3DB-F751-4BE4-A620-64F2CA1BFB5F}\RP1\A0001526.exe Infected: Virus.Win32.Sality.p skipped
C:\System Volume Information\_restore{F845E3DB-F751-4BE4-A620-64F2CA1BFB5F}\RP1\A0001527.exe Infected: Virus.Win32.Sality.p skipped
C:\System Volume Information\_restore{F845E3DB-F751-4BE4-A620-64F2CA1BFB5F}\RP1\A0001528.exe Infected: Virus.Win32.Sality.p skipped
C:\System Volume Information\_restore{F845E3DB-F751-4BE4-A620-64F2CA1BFB5F}\RP1\A0001529.exe Infected: Virus.Win32.Sality.p skipped
C:\System Volume Information\_restore{F845E3DB-F751-4BE4-A620-64F2CA1BFB5F}\RP1\A0001530.exe Infected: Virus.Win32.Sality.p skipped
C:\System Volume Information\_restore{F845E3DB-F751-4BE4-A620-64F2CA1BFB5F}\RP1\A0001531.exe Infected: Virus.Win32.Sality.p skipped
C:\System Volume Information\_restore{F845E3DB-F751-4BE4-A620-64F2CA1BFB5F}\RP1\A0001532.exe Infected: Virus.Win32.Sality.p skipped
C:\System Volume Information\_restore{F845E3DB-F751-4BE4-A620-64F2CA1BFB5F}\RP1\A0001533.exe Infected: Virus.Win32.Sality.p skipped
C:\System Volume Information\_restore{F845E3DB-F751-4BE4-A620-64F2CA1BFB5F}\RP1\A0001534.exe Infected: Virus.Win32.Sality.p skipped
C:\System Volume Information\_restore{F845E3DB-F751-4BE4-A620-64F2CA1BFB5F}\RP1\A0001535.exe Infected: Virus.Win32.Sality.p skipped
C:\System Volume Information\_restore{F845E3DB-F751-4BE4-A620-64F2CA1BFB5F}\RP1\A0001536.exe Infected: Virus.Win32.Sality.p skipped
C:\System Volume Information\_restore{F845E3DB-F751-4BE4-A620-64F2CA1BFB5F}\RP1\A0001537.exe Infected: Virus.Win32.Sality.p skipped
C:\System Volume Information\_restore{F845E3DB-F751-4BE4-A620-64F2CA1BFB5F}\RP1\A0001538.exe Infected: Virus.Win32.Sality.p skipped
C:\System Volume Information\_restore{F845E3DB-F751-4BE4-A620-64F2CA1BFB5F}\RP1\A0001539.exe Infected: Virus.Win32.Sality.p skipped
C:\System Volume Information\_restore{F845E3DB-F751-4BE4-A620-64F2CA1BFB5F}\RP1\A0001540.exe Infected: Virus.Win32.Sality.p skipped
C:\System Volume Information\_restore{F845E3DB-F751-4BE4-A620-64F2CA1BFB5F}\RP1\A0001541.exe Infected: Virus.Win32.Sality.p skipped
C:\System Volume Information\_restore{F845E3DB-F751-4BE4-A620-64F2CA1BFB5F}\RP1\A0001542.exe Infected: Virus.Win32.Sality.p skipped
C:\System Volume Information\_restore{F845E3DB-F751-4BE4-A620-64F2CA1BFB5F}\RP1\A0001543.exe Infected: Virus.Win32.Sality.p skipped
C:\System Volume Information\_restore{F845E3DB-F751-4BE4-A620-64F2CA1BFB5F}\RP1\A0001544.exe Infected: Virus.Win32.Sality.p skipped
C:\System Volume Information\_restore{F845E3DB-F751-4BE4-A620-64F2CA1BFB5F}\RP1\A0001545.exe Infected: Virus.Win32.Sality.p skipped
C:\System Volume Information\_restore{F845E3DB-F751-4BE4-A620-64F2CA1BFB5F}\RP1\A0001546.exe Infected: Virus.Win32.Sality.p skipped
C:\System Volume Information\_restore{F845E3DB-F751-4BE4-A620-64F2CA1BFB5F}\RP1\A0001547.exe Infected: Virus.Win32.Sality.p skipped
C:\System Volume Information\_restore{F845E3DB-F751-4BE4-A620-64F2CA1BFB5F}\RP1\A0001548.exe Infected: Virus.Win32.Sality.p skipped
C:\System Volume Information\_restore{F845E3DB-F751-4BE4-A620-64F2CA1BFB5F}\RP1\A0001549.exe Infected: Virus.Win32.Sality.p skipped
C:\System Volume Information\_restore{F845E3DB-F751-4BE4-A620-64F2CA1BFB5F}\RP1\A0001550.exe Infected: Virus.Win32.Sality.p skipped
C:\System Volume Information\_restore{F845E3DB-F751-4BE4-A620-64F2CA1BFB5F}\RP1\A0001551.exe Infected: Virus.Win32.Sality.p skipped
C:\System Volume Information\_restore{F845E3DB-F751-4BE4-A620-64F2CA1BFB5F}\RP1\A0001552.exe Infected: Virus.Win32.Sality.p skipped
C:\System Volume Information\_restore{F845E3DB-F751-4BE4-A620-64F2CA1BFB5F}\RP1\A0001553.exe Infected: Virus.Win32.Sality.p skipped
C:\System Volume Information\_restore{F845E3DB-F751-4BE4-A620-64F2CA1BFB5F}\RP1\A0001554.exe Infected: Virus.Win32.Sality.p skipped
C:\System Volume Information\_restore{F845E3DB-F751-4BE4-A620-64F2CA1BFB5F}\RP1\A0001555.exe Infected: Virus.Win32.Sality.p skipped
C:\System Volume Information\_restore{F845E3DB-F751-4BE4-A620-64F2CA1BFB5F}\RP1\A0001556.exe Infected: Virus.Win32.Sality.p skipped
C:\System Volume Information\_restore{F845E3DB-F751-4BE4-A620-64F2CA1BFB5F}\RP1\A0001557.exe Infected: Virus.Win32.Sality.p skipped
C:\System Volume Information\_restore{F845E3DB-F751-4BE4-A620-64F2CA1BFB5F}\RP1\A0001558.exe Infected: Virus.Win32.Sality.p skipped
C:\System Volume Information\_restore{F845E3DB-F751-4BE4-A620-64F2CA1BFB5F}\RP1\A0001559.exe Infected: Virus.Win32.Sality.p skipped
C:\System Volume Information\_restore{F845E3DB-F751-4BE4-A620-64F2CA1BFB5F}\RP1\A0001560.exe Infected: Virus.Win32.Sality.p skipped
C:\System Volume Information\_restore{F845E3DB-F751-4BE4-A620-64F2CA1BFB5F}\RP1\A0001561.exe Infected: Virus.Win32.Sality.p skipped
C:\System Volume Information\_restore{F845E3DB-F751-4BE4-A620-64F2CA1BFB5F}\RP1\A0001562.exe Infected: Virus.Win32.Sality.p skipped
C:\System Volume Information\_restore{F845E3DB-F751-4BE4-A620-64F2CA1BFB5F}\RP1\A0001563.exe Infected: Virus.Win32.Sality.p skipped
C:\System Volume Information\_restore{F845E3DB-F751-4BE4-A620-64F2CA1BFB5F}\RP1\A0001564.exe Infected: Virus.Win32.Sality.p skipped
C:\System Volume Information\_restore{F845E3DB-F751-4BE4-A620-64F2CA1BFB5F}\RP1\A0001565.exe Infected: Virus.Win32.Sality.p skipped
C:\System Volume Information\_restore{F845E3DB-F751-4BE4-A620-64F2CA1BFB5F}\RP1\A0001566.exe Infected: Virus.Win32.Sality.p skipped
C:\System Volume Information\_restore{F845E3DB-F751-4BE4-A620-64F2CA1BFB5F}\RP1\A0001567.exe Infected: Virus.Win32.Sality.p skipped
C:\System Volume Information\_restore{F845E3DB-F751-4BE4-A620-64F2CA1BFB5F}\RP1\A0001568.exe Infected: Virus.Win32.Sality.p skipped
C:\System Volume Information\_restore{F845E3DB-F751-4BE4-A620-64F2CA1BFB5F}\RP1\A0001569.exe Infected: Virus.Win32.Sality.p skipped
C:\System Volume Information\_restore{F845E3DB-F751-4BE4-A620-64F2CA1BFB5F}\RP1\A0001570.exe Infected: Virus.Win32.Sality.p skipped
C:\System Volume Information\_restore{F845E3DB-F751-4BE4-A620-64F2CA1BFB5F}\RP1\A0001571.exe Infected: Virus.Win32.Sality.p skipped
C:\System Volume Information\_restore{F845E3DB-F751-4BE4-A620-64F2CA1BFB5F}\RP1\A0001572.exe Infected: Virus.Win32.Sality.p skipped
C:\System Volume Information\_restore{F845E3DB-F751-4BE4-A620-64F2CA1BFB5F}\RP1\A0001573.exe Infected: Virus.Win32.Sality.p skipped
C:\System Volume Information\_restore{F845E3DB-F751-4BE4-A620-64F2CA1BFB5F}\RP1\A0001574.exe Infected: Virus.Win32.Sality.p skipped
C:\System Volume Information\_restore{F845E3DB-F751-4BE4-A620-64F2CA1BFB5F}\RP1\A0001575.exe Infected: Virus.Win32.Sality.p skipped
C:\System Volume Information\_restore{F845E3DB-F751-4BE4-A620-64F2CA1BFB5F}\RP1\A0001576.exe Infected: Virus.Win32.Sality.p skipped
C:\System Volume Information\_restore{F845E3DB-F751-4BE4-A620-64F2CA1BFB5F}\RP1\A0001577.exe Infected: Virus.Win32.Sality.p skipped
C:\System Volume Information\_restore{F845E3DB-F751-4BE4-A620-64F2CA1BFB5F}\RP1\A0001578.exe Infected: Virus.Win32.Sality.p skipped
C:\System Volume Information\_restore{F845E3DB-F751-4BE4-A620-64F2CA1BFB5F}\RP1\A0001579.exe Infected: Virus.Win32.Sality.p skipped
C:\System Volume Information\_restore{F845E3DB-F751-4BE4-A620-64F2CA1BFB5F}\RP1\A0001580.exe Infected: Virus.Win32.Sality.p skipped
C:\System Volume Information\_restore{F845E3DB-F751-4BE4-A620-64F2CA1BFB5F}\RP1\A0001581.exe Infected: Virus.Win32.Sality.p skipped
C:\System Volume Information\_restore{F845E3DB-F751-4BE4-A620-64F2CA1BFB5F}\RP1\A0001582.exe Infected: Virus.Win32.Sality.p skipped
C:\System Volume Information\_restore{F845E3DB-F751-4BE4-A620-64F2CA1BFB5F}\RP1\A0001583.exe Infected: Virus.Win32.Sality.p skipped
C:\System Volume Information\_restore{F845E3DB-F751-4BE4-A620-64F2CA1BFB5F}\RP1\A0001584.exe Infected: Virus.Win32.Sality.p skipped
C:\System Volume Information\_restore{F845E3DB-F751-4BE4-A620-64F2CA1BFB5F}\RP1\A0001585.exe Infected: Virus.Win32.Sality.p skipped
C:\System Volume Information\_restore{F845E3DB-F751-4BE4-A620-64F2CA1BFB5F}\RP1\A0001586.EXE Infected: Virus.Win32.Sality.p skipped
C:\System Volume Information\_restore{F845E3DB-F751-4BE4-A620-64F2CA1BFB5F}\RP1\A0001587.exe Infected: Virus.Win32.Sality.p skipped
C:\System Volume Information\_restore{F845E3DB-F751-4BE4-A620-64F2CA1BFB5F}\RP1\A0001588.exe Infected: Virus.Win32.Sality.p skipped
C:\System Volume Information\_restore{F845E3DB-F751-4BE4-A620-64F2CA1BFB5F}\RP1\A0001589.exe Infected: Virus.Win32.Sality.p skipped
C:\System Volume Information\_restore{F845E3DB-F751-4BE4-A620-64F2CA1BFB5F}\RP1\A0001590.EXE Infected: Virus.Win32.Sality.p skipped
C:\System Volume Information\_restore{F845E3DB-F751-4BE4-A620-64F2CA1BFB5F}\RP1\A0001591.EXE Infected: Virus.Win32.Sality.p skipped
C:\System Volume Information\_restore{F845E3DB-F751-4BE4-A620-64F2CA1BFB5F}\RP1\A0001592.exe Infected: Virus.Win32.Sality.p skipped
C:\System Volume Information\_restore{F845E3DB-F751-4BE4-A620-64F2CA1BFB5F}\RP1\A0001593.exe Infected: Virus.Win32.Sality.p skipped
C:\System Volume Information\_restore{F845E3DB-F751-4BE4-A620-64F2CA1BFB5F}\RP1\A0001594.exe Infected: Virus.Win32.Sality.p skipped
C:\System Volume Information\_restore{F845E3DB-F751-4BE4-A620-64F2CA1BFB5F}\RP1\A0001595.EXE Infected: Virus.Win32.Sality.p skipped
C:\System Volume Information\_restore{F845E3DB-F751-4BE4-A620-64F2CA1BFB5F}\RP1\A0001596.exe Infected: Virus.Win32.Sality.p skipped
C:\System Volume Information\_restore{F845E3DB-F751-4BE4-A620-64F2CA1BFB5F}\RP1\A0001597.exe Infected: Virus.Win32.Sality.p skipped
C:\System Volume Information\_restore{F845E3DB-F751-4BE4-A620-64F2CA1BFB5F}\RP1\A0001598.exe Infected: Virus.Win32.Sality.p skipped
C:\System Volume Information\_restore{F845E3DB-F751-4BE4-A620-64F2CA1BFB5F}\RP1\A0001599.exe Infected: Virus.Win32.Sality.p skipped
C:\System Volume Information\_restore{F845E3DB-F751-4BE4-A620-64F2CA1BFB5F}\RP1\A0001600.exe Infected: Virus.Win32.Sality.p skipped
C:\System Volume Information\_restore{F845E3DB-F751-4BE4-A620-64F2CA1BFB5F}\RP1\A0001601.exe Infected: Virus.Win32.Sality.p skipped
C:\System Volume Information\_restore{F845E3DB-F751-4BE4-A620-64F2CA1BFB5F}\RP1\A0001602.exe Infected: Virus.Win32.Sality.p skipped
C:\System Volume Information\_restore{F845E3DB-F751-4BE4-A620-64F2CA1BFB5F}\RP1\A0001603.EXE Infected: Virus.Win32.Sality.p skipped
C:\System Volume Information\_restore{F845E3DB-F751-4BE4-A620-64F2CA1BFB5F}\RP1\A0001604.EXE Infected: Virus.Win32.Sality.p skipped
C:\System Volume Information\_restore{F845E3DB-F751-4BE4-A620-64F2CA1BFB5F}\RP1\A0001605.EXE Infected: Virus.Win32.Sality.p skipped
C:\System Volume Information\_restore{F845E3DB-F751-4BE4-A620-64F2CA1BFB5F}\RP1\A0001606.EXE Infected: Virus.Win32.Sality.p skipped
C:\System Volume Information\_restore{F845E3DB-F751-4BE4-A620-64F2CA1BFB5F}\RP1\A0001607.EXE Infected: Virus.Win32.Sality.p skipped
C:\System Volume Information\_restore{F845E3DB-F751-4BE4-A620-64F2CA1BFB5F}\RP1\A0001608.EXE Infected: Virus.Win32.Sality.p skipped
C:\System Volume Information\_restore{F845E3DB-F751-4BE4-A620-64F2CA1BFB5F}\RP1\A0001609.EXE Infected: Virus.Win32.Sality.p skipped
C:\System Volume Information\_restore{F845E3DB-F751-4BE4-A620-64F2CA1BFB5F}\RP1\A0001610.EXE Infected: Virus.Win32.Sality.p skipped
C:\System Volume Information\_restore{F845E3DB-F751-4BE4-A620-64F2CA1BFB5F}\RP1\A0001611.EXE Infected: Virus.Win32.Sality.p skipped
C:\System Volume Information\_restore{F845E3DB-F751-4BE4-A620-64F2CA1BFB5F}\RP1\A0001612.EXE Infected: Virus.Win32.Sality.p skipped
C:\System Volume Information\_restore{F845E3DB-F751-4BE4-A620-64F2CA1BFB5F}\RP1\A0001613.EXE Infected: Virus.Win32.Sality.p skipped
C:\System Volume Information\_restore{F845E3DB-F751-4BE4-A620-64F2CA1BFB5F}\RP1\A0001614.EXE Infected: Virus.Win32.Sality.p skipped
C:\System Volume Information\_restore{F845E3DB-F751-4BE4-A620-64F2CA1BFB5F}\RP1\A0001615.exe Infected: Virus.Win32.Sality.p skipped
C:\System Volume Information\_restore{F845E3DB-F751-4BE4-A620-64F2CA1BFB5F}\RP1\A0001616.exe Infected: Virus.Win32.Sality.p skipped
C:\System Volume Information\_restore{F845E3DB-F751-4BE4-A620-64F2CA1BFB5F}\RP1\A0001617.exe Infected: Virus.Win32.Sality.p skipped
C:\System Volume Information\_restore{F845E3DB-F751-4BE4-A620-64F2CA1BFB5F}\RP1\A0001618.exe Infected: Virus.Win32.Sality.p skipped
C:\System Volume Information\_restore{F845E3DB-F751-4BE4-A620-64F2CA1BFB5F}\RP1\A0001619.exe Infected: Virus.Win32.Sality.p skipped
C:\System Volume Information\_restore{F845E3DB-F751-4BE4-A620-64F2CA1BFB5F}\RP1\A0001620.exe Infected: Virus.Win32.Sality.p skipped
C:\System Volume Information\_restore{F845E3DB-F751-4BE4-A620-64F2CA1BFB5F}\RP1\A0001621.exe Infected: Virus.Win32.Sality.p skipped
C:\System Volume Information\_restore{F845E3DB-F751-4BE4-A620-64F2CA1BFB5F}\RP1\A0001622.exe Infected: Virus.Win32.Sality.p skipped
C:\System Volume Information\_restore{F845E3DB-F751-4BE4-A620-64F2CA1BFB5F}\RP1\A0001623.exe Infected: Virus.Win32.Sality.p skipped
C:\System Volume Information\_restore{F845E3DB-F751-4BE4-A620-64F2CA1BFB5F}\RP1\A0001624.exe Infected: Virus.Win32.Sality.p skipped
C:\System Volume Information\_restore{F845E3DB-F751-4BE4-A620-64F2CA1BFB5F}\RP1\A0001625.exe Infected: Virus.Win32.Sality.p skipped
C:\System Volume Information\_restore{F845E3DB-F751-4BE4-A620-64F2CA1BFB5F}\RP1\A0001626.exe Infected: Virus.Win32.Sality.p skipped
C:\System Volume Information\_restore{F845E3DB-F751-4BE4-A620-64F2CA1BFB5F}\RP1\A0001627.exe Infected: Virus.Win32.Sality.p skipped
C:\System Volume Information\_restore{F845E3DB-F751-4BE4-A620-64F2CA1BFB5F}\RP1\A0001628.exe Infected: Virus.Win32.Sality.p skipped
C:\System Volume Information\_restore{F845E3DB-F751-4BE4-A620-64F2CA1BFB5F}\RP1\A0001629.exe Infected: Virus.Win32.Sality.p skipped
C:\System Volume Information\_restore{F845E3DB-F751-4BE4-A620-64F2CA1BFB5F}\RP1\A0001630.exe Infected: Virus.Win32.Sality.p skipped
C:\System Volume Information\_restore{F845E3DB-F751-4BE4-A620-64F2CA1BFB5F}\RP1\A0001631.exe Infected: Virus.Win32.Sality.p skipped
C:\System Volume Information\_restore{F845E3DB-F751-4BE4-A620-64F2CA1BFB5F}\RP1\A0001632.exe Infected: Virus.Win32.Sality.p skipped
C:\System Volume Information\_restore{F845E3DB-F751-4BE4-A620-64F2CA1BFB5F}\RP1\A0001633.exe Infected: Virus.Win32.Sality.p skipped
C:\System Volume Information\_restore{F845E3DB-F751-4BE4-A620-64F2CA1BFB5F}\RP1\A0001634.exe Infected: Virus.Win32.Sality.p skipped
C:\System Volume Information\_restore{F845E3DB-F751-4BE4-A620-64F2CA1BFB5F}\RP1\A0001635.exe Infected: Virus.Win32.Sality.p skipped
C:\System Volume Information\_restore{F845E3DB-F751-4BE4-A620-64F2CA1BFB5F}\RP1\A0001636.exe Infected: Virus.Win32.Sality.p skipped
C:\System Volume Information\_restore{F845E3DB-F751-4BE4-A620-64F2CA1BFB5F}\RP1\A0001637.exe Infected: Virus.Win32.Sality.p skipped
C:\System Volume Information\_restore{F845E3DB-F751-4BE4-A620-64F2CA1BFB5F}\RP1\A0001638.exe Infected: Virus.Win32.Sality.p skipped
C:\System Volume Information\_restore{F845E3DB-F751-4BE4-A620-64F2CA1BFB5F}\RP1\A0001639.exe Infected: Virus.Win32.Sality.p skipped
C:\System Volume Information\_restore{F845E3DB-F751-4BE4-A620-64F2CA1BFB5F}\RP1\A0001640.exe Infected: Virus.Win32.Sality.p skipped
C:\System Volume Information\_restore{F845E3DB-F751-4BE4-A620-64F2CA1BFB5F}\RP1\A0001641.exe Infected: Virus.Win32.Sality.p skipped
C:\System Volume Information\_restore{F845E3DB-F751-4BE4-A620-64F2CA1BFB5F}\RP1\A0001642.exe Infected: Virus.Win32.Sality.p skipped
C:\System Volume Information\_restore{F845E3DB-F751-4BE4-A620-64F2CA1BFB5F}\RP1\A0001643.exe Infected: Virus.Win32.Sality.p skipped
C:\System Volume Information\_restore{F845E3DB-F751-4BE4-A620-64F2CA1BFB5F}\RP1\A0001644.exe Infected: Virus.Win32.Sality.p skipped
C:\System Volume Information\_restore{F845E3DB-F751-4BE4-A620-64F2CA1BFB5F}\RP1\A0001645.exe Infected: Virus.Win32.Sality.p skipped
C:\System Volume Information\_restore{F845E3DB-F751-4BE4-A620-64F2CA1BFB5F}\RP1\A0001646.exe Infected: Virus.Win32.Sality.p skipped
C:\System Volume Information\_restore{F845E3DB-F751-4BE4-A620-64F2CA1BFB5F}\RP1\A0001647.exe Infected: Virus.Win32.Sality.p skipped
C:\System Volume Information\_restore{F845E3DB-F751-4BE4-A620-64F2CA1BFB5F}\RP1\A0001648.exe Infected: Virus.Win32.Sality.p skipped
C:\System Volume Information\_restore{F845E3DB-F751-4BE4-A620-64F2CA1BFB5F}\RP1\A0001649.exe Infected: Virus.Win32.Sality.p skipped
C:\System Volume Information\_restore{F845E3DB-F751-4BE4-A620-64F2CA1BFB5F}\RP1\A0001650.exe Infected: Virus.Win32.Sality.p skipped
C:\System Volume Information\_restore{F845E3DB-F751-4BE4-A620-64F2CA1BFB5F}\RP1\A0001651.exe Infected: Virus.Win32.Sality.p skipped
C:\System Volume Information\_restore{F845E3DB-F751-4BE4-A620-64F2CA1BFB5F}\RP1\A0001652.exe Infected: Virus.Win32.Sality.p skipped
C:\System Volume Information\_restore{F845E3DB-F751-4BE4-A620-64F2CA1BFB5F}\RP1\A0001653.exe Infected: Virus.Win32.Sality.p skipped
C:\System Volume Information\_restore{F845E3DB-F751-4BE4-A620-64F2CA1BFB5F}\RP1\A0001654.exe Infected: Virus.Win32.Sality.p skipped
C:\System Volume Information\_restore{F845E3DB-F751-4BE4-A620-64F2CA1BFB5F}\RP1\A0001655.exe Infected: Virus.Win32.Sality.p skipped
C:\System Volume Information\_restore{F845E3DB-F751-4BE4-A620-64F2CA1BFB5F}\RP1\A0001656.exe Infected: Virus.Win32.Sality.p skipped
C:\System Volume Information\_restore{F845E3DB-F751-4BE4-A620-64F2CA1BFB5F}\RP1\A0001657.exe Infected: Virus.Win32.Sality.p skipped
C:\System Volume Information\_restore{F845E3DB-F751-4BE4-A620-64F2CA1BFB5F}\RP1\A0001658.exe Infected: Virus.Win32.Sality.p skipped
C:\System Volume Information\_restore{F845E3DB-F751-4BE4-A620-64F2CA1BFB5F}\RP1\A0001659.exe Infected: Virus.Win32.Sality.p skipped
C:\System Volume Information\_restore{F845E3DB-F751-4BE4-A620-64F2CA1BFB5F}\RP1\A0001660.exe Infected: Virus.Win32.Sality.p skipped
C:\System Volume Information\_restore{F845E3DB-F751-4BE4-A620-64F2CA1BFB5F}\RP1\A0001661.exe Infected: Virus.Win32.Sality.p skipped
C:\System Volume Information\_restore{F845E3DB-F751-4BE4-A620-64F2CA1BFB5F}\RP1\A0001662.exe Infected: Virus.Win32.Sality.p skipped
C:\System Volume Information\_restore{F845E3DB-F751-4BE4-A620-64F2CA1BFB5F}\RP1\A0001663.exe Infected: Virus.Win32.Sality.p skipped
C:\System Volume Information\_restore{F845E3DB-F751-4BE4-A620-64F2CA1BFB5F}\RP1\A0001664.exe Infected: Virus.Win32.Sality.p skipped
C:\System Volume Information\_restore{F845E3DB-F751-4BE4-A620-64F2CA1BFB5F}\RP1\A0001665.exe Infected: Virus.Win32.Sality.p skipped
C:\System Volume Information\_restore{F845E3DB-F751-4BE4-A620-64F2CA1BFB5F}\RP1\A0001666.exe Infected: Virus.Win32.Sality.p skipped
C:\System Volume Information\_restore{F845E3DB-F751-4BE4-A620-64F2CA1BFB5F}\RP1\A0001667.exe Infected: Virus.Win32.Sality.p skipped
C:\System Volume Information\_restore{F845E3DB-F751-4BE4-A620-64F2CA1BFB5F}\RP1\A0001668.exe Infected: Virus.Win32.Sality.p skipped
C:\System Volume Information\_restore{F845E3DB-F751-4BE4-A620-64F2CA1BFB5F}\RP1\A0001669.exe Infected: Virus.Win32.Sality.p skipped
C:\System Volume Information\_restore{F845E3DB-F751-4BE4-A620-64F2CA1BFB5F}\RP1\A0001670.exe Infected: Virus.Win32.Sality.p skipped
C:\System Volume Information\_restore{F845E3DB-F751-4BE4-A620-64F2CA1BFB5F}\RP1\A0001671.scr Infected: Virus.Win32.Sality.p skipped
C:\System Volume Information\_restore{F845E3DB-F751-4BE4-A620-64F2CA1BFB5F}\RP1\A0001672.exe Infected: Virus.Win32.Sality.p skipped
C:\System Volume Information\_restore{F845E3DB-F751-4BE4-A620-64F2CA1BFB5F}\RP1\A0001673.exe Infected: Virus.Win32.Sality.p skipped
C:\System Volume Information\_restore{F845E3DB-F751-4BE4-A620-64F2CA1BFB5F}\RP1\A0001674.exe Infected: Virus.Win32.Sality.p skipped
C:\System Volume Information\_restore{F845E3DB-F751-4BE4-A620-64F2CA1BFB5F}\RP1\A0001675.exe Infected: not-a-virus:Downloader.Win32.WinFixer.au skipped
C:\System Volume Information\_restore{F845E3DB-F751-4BE4-A620-64F2CA1BFB5F}\RP1\A0001676.exe Infected: Backdoor.Win32.Prorat.dz skipped
C:\System Volume Information\_restore{F845E3DB-F751-4BE4-A620-64F2CA1BFB5F}\RP1\A0001677.exe Infected: Virus.Win32.Sality.p skipped
C:\System Volume Information\_restore{F845E3DB-F751-4BE4-A620-64F2CA1BFB5F}\RP1\A0001678.exe Infected: Virus.Win32.Sality.p skipped
C:\System Volume Information\_restore{F845E3DB-F751-4BE4-A620-64F2CA1BFB5F}\RP1\A0001679.EXE Infected: Virus.Win32.Sality.p skipped
C:\System Volume Information\_restore{F845E3DB-F751-4BE4-A620-64F2CA1BFB5F}\RP1\A0001680.EXE Infected: Virus.Win32.Sality.p skipped
C:\System Volume Information\_restore{F845E3DB-F751-4BE4-A620-64F2CA1BFB5F}\RP1\A0001681.exe Infected: Trojan-Downloader.Win32.Agent.gwe skipped
C:\System Volume Information\_restore{F845E3DB-F751-4BE4-A620-64F2CA1BFB5F}\RP1\A0001682.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.din skipped
C:\System Volume Information\_restore{F845E3DB-F751-4BE4-A620-64F2CA1BFB5F}\RP1\A0001684.dll Infected: Trojan-Downloader.Win32.Small.hkd skipped
C:\System Volume Information\_restore{F845E3DB-F751-4BE4-A620-64F2CA1BFB5F}\RP1\A0001685.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.din skipped
C:\System Volume Information\_restore{F845E3DB-F751-4BE4-A620-64F2CA1BFB5F}\RP1\A0001688.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.din skipped
C:\System Volume Information\_restore{F845E3DB-F751-4BE4-A620-64F2CA1BFB5F}\RP1\A0001689.exe Infected: Trojan-Downloader.Win32.Agent.gwe skipped
C:\System Volume Information\_restore{F845E3DB-F751-4BE4-A620-64F2CA1BFB5F}\RP1\A0001690.exe Infected: Trojan-Downloader.Win32.Agent.gwe skipped
C:\System Volume Information\_restore{F845E3DB-F751-4BE4-A620-64F2CA1BFB5F}\RP1\A0001691.exe Infected: Trojan-Downloader.Win32.Agent.gwe skipped
C:\System Volume Information\_restore{F845E3DB-F751-4BE4-A620-64F2CA1BFB5F}\RP1\A0001693.exe Infected: Trojan-Downloader.Win32.Agent.gwe skipped
C:\System Volume Information\_restore{F845E3DB-F751-4BE4-A620-64F2CA1BFB5F}\RP1\A0001694.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.din skipped
C:\System Volume Information\_restore{F845E3DB-F751-4BE4-A620-64F2CA1BFB5F}\RP1\A0001697.exe Infected: Trojan-Downloader.Win32.Agent.gwe skipped
C:\System Volume Information\_restore{F845E3DB-F751-4BE4-A620-64F2CA1BFB5F}\RP1\A0001698.exe Infected: Trojan-Downloader.Win32.Agent.gwe skipped
C:\System Volume Information\_restore{F845E3DB-F751-4BE4-A620-64F2CA1BFB5F}\RP1\A0001699.exe Infected: Trojan-Downloader.Win32.Agent.gwe skipped
C:\System Volume Information\_restore{F845E3DB-F751-4BE4-A620-64F2CA1BFB5F}\RP1\A0001700.exe Infected: Trojan-Downloader.Win32.Agent.gwe skipped
C:\System Volume Information\_restore{F845E3DB-F751-4BE4-A620-64F2CA1BFB5F}\RP1\A0001702.exe Infected: Trojan-Downloader.Win32.Agent.gwe skipped
C:\System Volume Information\_restore{F845E3DB-F751-4BE4-A620-64F2CA1BFB5F}\RP1\A0001705.exe Infected: Trojan-Downloader.Win32.Agent.gwe skipped
C:\System Volume Information\_restore{F845E3DB-F751-4BE4-A620-64F2CA1BFB5F}\RP1\A0001706.exe Infected: Trojan-Downloader.Win32.Agent.gwe skipped
C:\System Volume Information\_restore{F845E3DB-F751-4BE4-A620-64F2CA1BFB5F}\RP1\A0001709.dll Infected: not-a-virus:AdWare.Win32.SuperJuan.is skipped
C:\System Volume Information\_restore{F845E3DB-F751-4BE4-A620-64F2CA1BFB5F}\RP1\A0001710.dll Infected: Virus.Win32.Sality.p skipped
C:\System Volume Information\_restore{F845E3DB-F751-4BE4-A620-64F2CA1BFB5F}\RP1\A0001713.exe Infected: Virus.Win32.Sality.p skipped
C:\System Volume Information\_restore{F845E3DB-F751-4BE4-A620-64F2CA1BFB5F}\RP