Update: Could someone please review the latest Hijack and Ewido logs and tell me what I need to do next. Thanks. This is for my parents' computer and I told them not to use it until this is completely resolved.
Logfile of HijackThis v1.99.1
Scan saved at 6:32:18 PM, on 07/13/2005
Platform: Windows XP SP1 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Common Files\AOL\ACS\AOLAcsd.exe
C:\Program Files\Common Files\AOL\TopSpeed\2.0\aoltsmon.exe
C:\WINDOWS\system32\drivers\dcfssvc.exe
C:\Program Files\ewido\security suite\ewidoctrl.exe
C:\Program Files\ewido\security suite\ewidoguard.exe
C:\WINDOWS\System32\RunDll32.exe
C:\WINDOWS\System32\carpserv.exe
C:\WINDOWS\System32\qttask.exe
C:\WINDOWS\System32\spool\drivers\w32x86\3\hpztsb07.exe
C:\WINDOWS\System32\hphmon04.exe
C:\Program Files\Hewlett-Packard\HP Share-to-Web\hpgs2wnd.exe
C:\Program Files\Common Files\AOL\ACS\AOLDial.exe
C:\PROGRA~1\COMMON~1\AOL\AOLSPY~1\AOLSP Scheduler.exe
C:\Program Files\Real\RealPlayer\RealPlay.exe
C:\Program Files\Messenger\MSMSGS.EXE
C:\Program Files\Hewlett-Packard\HP Share-to-Web\hpgs2wnf.exe
C:\PROGRA~1\COMMON~1\AOL\110911~1\EE\AOLHOS~1.EXE
C:\PROGRA~1\COMMON~1\AOL\110911~1\EE\AOLServiceHost.exe
C:\HJT\HijackThis.exe
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = localhost
R3 - Default URLSearchHook is missing
O1 - Hosts: 64.91.255.87 www.dcsresearch.com
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 5.0\Reader\ActiveX\AcroIEHelper.ocx
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx
O3 - Toolbar: (no name) - {4982D40A-C53B-4615-B15B-B5B5E98D167C} - (no file)
O3 - Toolbar: (no name) - {9A9C9B68-F908-4AAB-8D0C-10EA8997F37E} - (no file)
O3 - Toolbar: (no name) - {0E1230F8-EA50-42A9-983C-D22ABC2EED3B} - (no file)
O4 - HKLM\..\Run: [Cmaudio] RunDll32 cmicnfg.cpl,CMICtrlWnd
O4 - HKLM\..\Run: [CARPService] carpserv.exe
O4 - HKLM\..\Run: [QuickTime Task] C:\WINDOWS\System32\qttask.exe
O4 - HKLM\..\Run: [HPDJ Taskbar Utility] C:\WINDOWS\System32\spool\drivers\w32x86\3\hpztsb07.exe
O4 - HKLM\..\Run: [HPHmon04] C:\WINDOWS\System32\hphmon04.exe
O4 - HKLM\..\Run: [HPHUPD04] "C:\Program Files\HP Photosmart 11\hphinstall\UniPatch\hphupd04.exe"
O4 - HKLM\..\Run: [Share-to-Web Namespace Daemon] C:\Program Files\Hewlett-Packard\HP Share-to-Web\hpgs2wnd.exe
O4 - HKLM\..\Run: [HostManager] C:\Program Files\Common Files\AOL\1109110883\EE\AOLHostManager.exe
O4 - HKLM\..\Run: [AOLDialer] C:\Program Files\Common Files\AOL\ACS\AOLDial.exe
O4 - HKLM\..\Run: [AOL Spyware Protection] "C:\PROGRA~1\COMMON~1\AOL\AOLSPY~1\AOLSP Scheduler.exe"
O4 - HKLM\..\Run: [RealTray] C:\Program Files\Real\RealPlayer\RealPlay.exe SYSTEMBOOTHIDEPLAYER
O4 - HKLM\..\Run: [msxct] msxct.exe
O4 - HKLM\..\Run: [urkh] C:\WINDOWS\urkh.exe
O4 - HKLM\..\Run: [intel32.exe] C:\WINDOWS\System32\intel32.exe
O4 - HKLM\..\Run: [Media Gateway] C:\Program Files\Media Gateway\MediaGateway.exe
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\MSMSGS.EXE" /background
O4 - HKCU\..\Run: [SNInstall] C:\WINDOWS\System32\down3.exe
O8 - Extra context menu item: &AOL Toolbar search - res://C:\Program Files\AOL Toolbar\toolbar.dll/SEARCH.HTML
O9 - Extra button: AOL Toolbar - {4982D40A-C53B-4615-B15B-B5B5E98D167C} - (no file)
O9 - Extra 'Tools' menuitem: AOL Toolbar - {4982D40A-C53B-4615-B15B-B5B5E98D167C} - (no file)
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\System32\Shdocvw.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\MSMSGS.EXE
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\MSMSGS.EXE
O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll
O15 - Trusted Zone:
http://awbeta.net-nucleus.com (HKLM)
O16 - DPF: {15AD6789-CDB4-47E1-A9DA-992EE8E6BAD6} -
http://static.windup...e/bridge-c9.cabO16 - DPF: {189EBB36-9BFB-668E-2E0E-01CE40ABA182} -
http://205.252.161.238/1/gdnUS1880.exeO16 - DPF: {22CF9F12-0D64-60DE-0CF2-58832E54B90F} -
http://205.252.161.238/1/gdnUS1880.exeO16 - DPF: {23CBD580-BAC8-21FB-C0C4-611A4D398141} -
http://205.252.161.238/1/gdnUS1880.exeO16 - DPF: {24311111-1111-1121-1111-111191113457} - file://c:\eied_s7.cab
O16 - DPF: {33331111-1111-1111-1111-611111193457} - file://c:\ex.cab
O16 - DPF: {33331111-1111-1111-1111-611111193458} - file://c:\ex.cab
O16 - DPF: {37D11EAF-C855-127B-6EC1-65B563F3EC5F} -
http://205.252.161.238/1/gdnUS1880.exeO16 - DPF: {4A3CF76B-EC7A-405D-A67D-8DC6B52AB35B} (QDiagAOLCCUpdateObj Class) -
http://aolcc.aol.com...kup/qdiagcc.cabO16 - DPF: {5257D8C6-9E2D-5103-1808-1BA0284CF538} -
http://205.252.161.238/1/gdnUS1880.exeO16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) -
http://update.micros...b?1121107869795O16 - DPF: {713793B6-748E-2049-CE49-0CD2351113B1} -
http://205.252.161.238/1/gdnUS1880.exeO16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) -
http://www.pandasoft.../as5/asinst.cabO21 - SSODL: SystemCheck2 - {54645654-2225-4455-44A1-9F4543D34545} - C:\WINDOWS\System32\vbsys2.dll
O23 - Service: AOL Connectivity Service (AOL ACS) - America Online - C:\Program Files\Common Files\AOL\ACS\AOLAcsd.exe
O23 - Service: AOL TopSpeed Monitor (AOL TopSpeedMonitor) - America Online, Inc - C:\Program Files\Common Files\AOL\TopSpeed\2.0\aoltsmon.exe
O23 - Service: AOL Spyware Protection Service (AOLService) - Unknown owner - C:\PROGRA~1\COMMON~1\AOL\AOLSPY~1\\aolserv.exe
O23 - Service: Dcfssvc - Eastman Kodak Company - C:\WINDOWS\system32\drivers\dcfssvc.exe
O23 - Service: ewido security suite control - ewido networks - C:\Program Files\ewido\security suite\ewidoctrl.exe
O23 - Service: ewido security suite guard - ewido networks - C:\Program Files\ewido\security suite\ewidoguard.exe
O23 - Service: Pml Driver HPH11 - HP - C:\WINDOWS\System32\HPHipm11.exe
---------------------------------------------------------
ewido security suite - Scan report
---------------------------------------------------------
+ Created on: 6:00:24 PM, 07/13/2005
+ Report-Checksum: 302382E1
+ Scan result:
HKLM\SOFTWARE\Classes\CLSID\{031B6D43-CBC4-46A5-8E46-CF8B407C1A33} -> Spyware.CoolWebSearch : Cleaned with backup
HKLM\SOFTWARE\Classes\CLSID\{7F6828CA-9E42-462C-BC60-418C8144012C} -> Dialer.Generic : Cleaned with backup
HKLM\SOFTWARE\Classes\CLSID\{9A9C9B69-F908-4AAB-8D0C-10EA8997F37E} -> Spyware.NetNucleus : Cleaned with backup
HKLM\SOFTWARE\Classes\Interface\{CABBB49A-4D7B-415B-8250-15C3B854E9FF} -> Spyware.CoolWebSearch : Cleaned with backup
HKLM\SOFTWARE\Classes\ToolbarBestToolbarsToolbar.BestToolbarsToolbarObject -> Spyware.FizzleBar : Cleaned with backup
HKLM\SOFTWARE\Classes\ToolbarBestToolbarsToolbar.BestToolbarsToolbarObject\CLSID -> Spyware.FizzleBar : Cleaned with backup
HKLM\SOFTWARE\Classes\ToolbarBestToolbarsToolbar.BestToolbarsToolbarObject\CurVer -> Spyware.FizzleBar : Cleaned with backup
HKLM\SOFTWARE\Microsoft\Code Store Database\Distribution Units\{3446598E-00E4-4B5E-99A6-87ECCA8324A2} -> Dialer.Generic : Cleaned with backup
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\App Management\ARPCache\{8A0DCBDA-6E20-489C-9041-C1E8A0352E75} -> Spyware.NetNucleus : Cleaned with backup
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{031B6D43-CBC4-46A5-8E46-CF8B407C1A33} -> Spyware.CoolWebSearch : Cleaned with backup
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{9A9C9B69-F908-4AAB-8D0C-10EA8997F37E} -> Spyware.NetNucleus : Cleaned with backup
HKU\S-1-5-21-4065856631-3444992295-3662072423-1005\Software\SerG -> Spyware.EZ-Finder : Cleaned with backup
C:\WINDOWS\system32\webdlg32.dll -> Spyware.SBSoft : Cleaned with backup
C:\WINDOWS\system32\__delete_on_reboot__fltmgr.dll -> Backdoor.Agent.lg : Cleaned with backup
C:\WINDOWS\system32\__delete_on_reboot__msxct.exe -> Spyware.BargainBuddy : Cleaned with backup
C:\WINDOWS\system32\__delete_on_reboot__intel32.exe -> Trojan.Agent.ff : Cleaned with backup
C:\WINDOWS\system32\__delete_on_reboot__OLEADM.dll -> Trojan.Agent.ff : Cleaned with backup
C:\WINDOWS\system32\WinNB57.dll -> Spyware.NetNucleus : Cleaned with backup
C:\WINDOWS\system\BHOmod.dll -> TrojanDownloader.Agent.li : Cleaned with backup
C:\WINDOWS\ime\shared\res\Teen [bleep] 16.jpg.pif -> Worm.Netsky.C : Cleaned with backup
C:\WINDOWS\ime\shared\res\Best Matrix Screensaver.scr -> Worm.Netsky.C : Cleaned with backup
C:\WINDOWS\ime\shared\res\[bleep] Screensaver.scr -> Worm.Netsky.C : Cleaned with backup
C:\WINDOWS\ime\shared\res\Dark Angels.pif -> Worm.Netsky.C : Cleaned with backup
C:\WINDOWS\ime\shared\res\Screensaver.scr -> Worm.Netsky.C : Cleaned with backup
C:\WINDOWS\ime\shared\res\Full album.mp3.pif -> Worm.Netsky.C : Cleaned with backup
C:\WINDOWS\ime\shared\res\Virii Sourcecode.scr -> Worm.Netsky.C : Cleaned with backup
C:\WINDOWS\ime\shared\Teen [bleep] 16.jpg.pif -> Worm.Netsky.C : Cleaned with backup
C:\WINDOWS\ime\shared\Best Matrix Screensaver.scr -> Worm.Netsky.C : Cleaned with backup
C:\WINDOWS\ime\shared\[bleep] Screensaver.scr -> Worm.Netsky.C : Cleaned with backup
C:\WINDOWS\ime\shared\Dark Angels.pif -> Worm.Netsky.C : Cleaned with backup
C:\WINDOWS\ime\shared\Screensaver.scr -> Worm.Netsky.C : Cleaned with backup
C:\WINDOWS\ime\shared\Full album.mp3.pif -> Worm.Netsky.C : Cleaned with backup
C:\WINDOWS\ime\shared\Virii Sourcecode.scr -> Worm.Netsky.C : Cleaned with backup
C:\WINDOWS\Downloaded Program Files\CONFLICT.1\istactivex.dll -> TrojanDownloader.IstBar : Cleaned with backup
C:\WINDOWS\Downloaded Program Files\gdnUS1880.exe -> Dialer.Generic : Cleaned with backup
C:\WINDOWS\Downloaded Program Files\CONFLICT.2\istactivex.dll -> TrojanDownloader.IstBar : Cleaned with backup
C:\WINDOWS\Downloaded Program Files\ipreg32.dll -> TrojanDownloader.Domcom.b : Cleaned with backup
C:\WINDOWS\Downloaded Program Files\CONFLICT.3\istactivex.dll -> TrojanDownloader.IstBar : Cleaned with backup
C:\WINDOWS\Downloaded Program Files\CONFLICT.4\istactivex.dll -> TrojanDownloader.IstBar : Cleaned with backup
C:\WINDOWS\Downloaded Program Files\MediaGatewayX.dll -> Spyware.WinAD : Cleaned with backup
C:\WINDOWS\internt.exe -> Dialer.Generic : Cleaned with backup
C:\WINDOWS\winsx.dll -> Spyware.Puper : Cleaned with backup
C:\WINDOWS\webdlg32.dll -> Spyware.SBSoft : Cleaned with backup
C:\Documents and Settings\Gary\Cookies\gary@2o7[2].txt -> Spyware.Cookie.2o7 : Cleaned with backup
C:\Program Files\Common Files\AOL\AOL Spyware Protection\Backup\QFle0711200515283974495.asw -> Spyware.180Solutions : Cleaned with backup
C:\Program Files\Common Files\AOL\AOL Spyware Protection\Backup\QFle06132005160880093888.asw -> TrojanDownloader.Agent.li : Cleaned with backup
C:\Program Files\Common Files\AOL\AOL Spyware Protection\Backup\QMem0702200517355756587.asw -> TrojanDownloader.IstBar : Cleaned with backup
C:\Program Files\Common Files\AOL\AOL Spyware Protection\Backup\QMem0703200517131708046.asw -> TrojanDownloader.IstBar : Cleaned with backup
C:\Program Files\Common Files\AOL\AOL Spyware Protection\Backup\QFle0703200517131709708.asw -> TrojanDownloader.IstBar : Cleaned with backup
C:\Program Files\Common Files\AOL\AOL Spyware Protection\Backup\QMem0705200515441162671.asw -> TrojanDownloader.IstBar : Cleaned with backup
C:\Program Files\Common Files\AOL\AOL Spyware Protection\Backup\QFle0705200515451189941.asw -> TrojanDownloader.IstBar : Cleaned with backup
C:\Program Files\Common Files\AOL\AOL Spyware Protection\Backup\QFle0705200515451199825.asw -> Spyware.180Solutions : Cleaned with backup
C:\Program Files\Common Files\AOL\AOL Spyware Protection\Backup\QFle0705200515451204481.asw -> Spyware.BargainBuddy : Cleaned with backup
C:\Program Files\Media Gateway\__delete_on_reboot__MediaGateway.exe -> Spyware.WinAD : Cleaned with backup
C:\System Volume Information\_restore{93EA7FB1-3634-4E01-BFEE-735EDB571361}\RP118\A0122955.exe -> TrojanDownloader.Mediket.ah : Cleaned with backup
C:\System Volume Information\_restore{93EA7FB1-3634-4E01-BFEE-735EDB571361}\RP118\A0123949.dll -> TrojanDownloader.Agent.li : Cleaned with backup
C:\System Volume Information\_restore{93EA7FB1-3634-4E01-BFEE-735EDB571361}\RP118\A0125969.exe -> Dialer.Generic : Cleaned with backup
C:\System Volume Information\_restore{93EA7FB1-3634-4E01-BFEE-735EDB571361}\RP119\A0125991.dll -> TrojanDownloader.Agent.li : Cleaned with backup
C:\System Volume Information\_restore{93EA7FB1-3634-4E01-BFEE-735EDB571361}\RP119\A0126017.dll -> Spyware.Hijacker.Generic : Cleaned with backup
C:\System Volume Information\_restore{93EA7FB1-3634-4E01-BFEE-735EDB571361}\RP130\A0126280.exe -> TrojanDownloader.Domcom.a : Cleaned with backup
C:\System Volume Information\_restore{93EA7FB1-3634-4E01-BFEE-735EDB571361}\RP131\A0128380.dll -> TrojanDownloader.Domcom.a : Cleaned with backup
C:\System Volume Information\_restore{93EA7FB1-3634-4E01-BFEE-735EDB571361}\RP131\A0128401.dll -> Spyware.SBSoft : Cleaned with backup
C:\System Volume Information\_restore{93EA7FB1-3634-4E01-BFEE-735EDB571361}\RP131\A0128403.dll -> Spyware.Puper : Cleaned with backup
C:\System Volume Information\_restore{93EA7FB1-3634-4E01-BFEE-735EDB571361}\RP131\A0128427.exe -> Worm.Bagz.j : Cleaned with backup
C:\System Volume Information\_restore{93EA7FB1-3634-4E01-BFEE-735EDB571361}\RP131\A0129377.exe -> TrojanDownloader.Domcom.a : Cleaned with backup
C:\System Volume Information\_restore{93EA7FB1-3634-4E01-BFEE-735EDB571361}\RP132\A0130515.dll -> TrojanDownloader.Domcom.a : Cleaned with backup
C:\System Volume Information\_restore{93EA7FB1-3634-4E01-BFEE-735EDB571361}\RP132\A0130516.exe -> TrojanDownloader.Domcom.a : Cleaned with backup
C:\System Volume Information\_restore{93EA7FB1-3634-4E01-BFEE-735EDB571361}\RP132\A0130527.vxd -> Spyware.BargainBuddy : Cleaned with backup
C:\System Volume Information\_restore{93EA7FB1-3634-4E01-BFEE-735EDB571361}\RP132\A0130529.srg -> Spyware.BargainBuddy : Cleaned with backup
C:\System Volume Information\_restore{93EA7FB1-3634-4E01-BFEE-735EDB571361}\RP132\A0130533.exe -> Spyware.BargainBuddy : Cleaned with backup
C:\System Volume Information\_restore{93EA7FB1-3634-4E01-BFEE-735EDB571361}\RP132\A0130536.exe -> TrojanDownloader.Dyfuca.ei : Cleaned with backup
C:\System Volume Information\_restore{93EA7FB1-3634-4E01-BFEE-735EDB571361}\RP132\A0130580.exe -> Trojan.Agent.ff : Cleaned with backup
C:\System Volume Information\_restore{93EA7FB1-3634-4E01-BFEE-735EDB571361}\RP132\A0130581.exe -> Trojan.Agent.ff : Cleaned with backup
C:\System Volume Information\_restore{93EA7FB1-3634-4E01-BFEE-735EDB571361}\RP132\A0130583.dll -> Spyware.Puper : Cleaned with backup
C:\System Volume Information\_restore{93EA7FB1-3634-4E01-BFEE-735EDB571361}\RP132\A0130585.dll -> Spyware.SBSoft : Cleaned with backup
C:\System Volume Information\_restore{93EA7FB1-3634-4E01-BFEE-735EDB571361}\RP132\A0130593.srg -> Spyware.BargainBuddy : Cleaned with backup
C:\System Volume Information\_restore{93EA7FB1-3634-4E01-BFEE-735EDB571361}\RP133\A0130617.dll -> TrojanDownloader.Domcom.a : Cleaned with backup
C:\System Volume Information\_restore{93EA7FB1-3634-4E01-BFEE-735EDB571361}\RP133\A0130618.exe -> TrojanDownloader.Domcom.a : Cleaned with backup
C:\System Volume Information\_restore{93EA7FB1-3634-4E01-BFEE-735EDB571361}\RP133\A0130629.vxd -> Spyware.BargainBuddy : Cleaned with backup
C:\System Volume Information\_restore{93EA7FB1-3634-4E01-BFEE-735EDB571361}\RP133\A0130634.exe -> Spyware.BargainBuddy : Cleaned with backup
C:\System Volume Information\_restore{93EA7FB1-3634-4E01-BFEE-735EDB571361}\RP133\A0130637.exe -> TrojanDownloader.Dyfuca.ei : Cleaned with backup
C:\System Volume Information\_restore{93EA7FB1-3634-4E01-BFEE-735EDB571361}\RP133\A0130681.exe -> Trojan.Agent.ff : Cleaned with backup
C:\System Volume Information\_restore{93EA7FB1-3634-4E01-BFEE-735EDB571361}\RP133\A0130682.exe -> Trojan.Agent.ff : Cleaned with backup
C:\System Volume Information\_restore{93EA7FB1-3634-4E01-BFEE-735EDB571361}\RP133\A0130684.dll -> Spyware.Puper : Cleaned with backup
C:\System Volume Information\_restore{93EA7FB1-3634-4E01-BFEE-735EDB571361}\RP133\A0130686.dll -> Spyware.SBSoft : Cleaned with backup
C:\System Volume Information\_restore{93EA7FB1-3634-4E01-BFEE-735EDB571361}\RP133\A0130697.dll -> TrojanDownloader.Domcom.a : Cleaned with backup
C:\System Volume Information\_restore{93EA7FB1-3634-4E01-BFEE-735EDB571361}\RP133\A0130763.exe -> TrojanDownloader.Domcom.a : Cleaned with backup
C:\System Volume Information\_restore{93EA7FB1-3634-4E01-BFEE-735EDB571361}\RP133\A0130767.dll -> TrojanDownloader.Domcom.a : Cleaned with backup
C:\System Volume Information\_restore{93EA7FB1-3634-4E01-BFEE-735EDB571361}\RP133\A0130807.dll -> Spyware.SBSoft : Cleaned with backup
C:\System Volume Information\_restore{93EA7FB1-3634-4E01-BFEE-735EDB571361}\RP133\A0130810.dll -> Spyware.Puper : Cleaned with backup
C:\System Volume Information\_restore{93EA7FB1-3634-4E01-BFEE-735EDB571361}\RP133\A0130812.exe -> Worm.Bagz.j : Cleaned with backup
C:\System Volume Information\_restore{93EA7FB1-3634-4E01-BFEE-735EDB571361}\RP133\A0130816.exe -> Trojan.Small.ej : Cleaned with backup
C:\System Volume Information\_restore{93EA7FB1-3634-4E01-BFEE-735EDB571361}\RP133\A0131763.exe -> TrojanDownloader.Domcom.a : Cleaned with backup
C:\System Volume Information\_restore{93EA7FB1-3634-4E01-BFEE-735EDB571361}\RP133\A0131767.dll -> TrojanDownloader.Domcom.a : Cleaned with backup
C:\System Volume Information\_restore{93EA7FB1-3634-4E01-BFEE-735EDB571361}\RP135\A0132766.dll -> TrojanDownloader.Domcom.a : Cleaned with backup
C:\System Volume Information\_restore{93EA7FB1-3634-4E01-BFEE-735EDB571361}\RP135\A0133785.dll -> TrojanDownloader.Domcom.a : Cleaned with backup
C:\System Volume Information\_restore{93EA7FB1-3634-4E01-BFEE-735EDB571361}\RP135\A0135763.exe -> Trojan.Agent.ff : Cleaned with backup
C:\System Volume Information\_restore{93EA7FB1-3634-4E01-BFEE-735EDB571361}\RP135\A0135795.dll -> TrojanDownloader.Domcom.a : Cleaned with backup
C:\System Volume Information\_restore{93EA7FB1-3634-4E01-BFEE-735EDB571361}\RP135\A0136795.dll -> TrojanDownloader.Domcom.a : Cleaned with backup
C:\System Volume Information\_restore{93EA7FB1-3634-4E01-BFEE-735EDB571361}\RP135\A0136833.vxd -> Spyware.BargainBuddy : Cleaned with backup
C:\System Volume Information\_restore{93EA7FB1-3634-4E01-BFEE-735EDB571361}\RP135\A0136834.dll -> TrojanDownloader.Domcom.a : Cleaned with backup
C:\System Volume Information\_restore{93EA7FB1-3634-4E01-BFEE-735EDB571361}\RP135\A0136876.dll -> Spyware.SBSoft : Cleaned with backup
C:\System Volume Information\_restore{93EA7FB1-3634-4E01-BFEE-735EDB571361}\RP135\A0136880.exe -> Worm.Bagz.j : Cleaned with backup
C:\System Volume Information\_restore{93EA7FB1-3634-4E01-BFEE-735EDB571361}\RP135\A0136882.exe -> Trojan.Small.ej : Cleaned with backup
C:\System Volume Information\_restore{93EA7FB1-3634-4E01-BFEE-735EDB571361}\RP135\A0136883.exe -> TrojanDownloader.Dyfuca.ei : Cleaned with backup
C:\System Volume Information\_restore{93EA7FB1-3634-4E01-BFEE-735EDB571361}\RP135\A0137008.dll -> Spyware.SBSoft : Cleaned with backup
C:\System Volume Information\_restore{93EA7FB1-3634-4E01-BFEE-735EDB571361}\RP135\A0137009.dll -> Spyware.Puper : Cleaned with backup
C:\System Volume Information\_restore{93EA7FB1-3634-4E01-BFEE-735EDB571361}\RP135\A0137029.dll -> Dialer.Generic : Cleaned with backup
C:\System Volume Information\_restore{93EA7FB1-3634-4E01-BFEE-735EDB571361}\RP135\A0137033.srg -> Spyware.BargainBuddy : Cleaned with backup
C:\System Volume Information\_restore{93EA7FB1-3634-4E01-BFEE-735EDB571361}\RP135\A0137034.exe -> Dialer.Generic : Cleaned with backup
C:\System Volume Information\_restore{93EA7FB1-3634-4E01-BFEE-735EDB571361}\RP135\A0137046.exe -> Worm.Netsky.Q : Cleaned with backup
C:\System Volume Information\_restore{93EA7FB1-3634-4E01-BFEE-735EDB571361}\RP135\A0137047.exe -> Worm.Netsky.Q : Cleaned with backup
C:\System Volume Information\_restore{93EA7FB1-3634-4E01-BFEE-735EDB571361}\RP135\A0137048.exe -> Worm.Netsky.Q : Cleaned with backup
C:\System Volume Information\_restore{93EA7FB1-3634-4E01-BFEE-735EDB571361}\RP135\A0137049.exe -> Worm.Netsky.Q : Cleaned with backup
C:\System Volume Information\_restore{93EA7FB1-3634-4E01-BFEE-735EDB571361}\RP135\A0137050.exe -> Worm.Netsky.Q : Cleaned with backup
C:\System Volume Information\_restore{93EA7FB1-3634-4E01-BFEE-735EDB571361}\RP135\A0137051.exe -> Worm.Netsky.Q : Cleaned with backup
C:\System Volume Information\_restore{93EA7FB1-3634-4E01-BFEE-735EDB571361}\RP135\A0137052.exe -> Worm.Netsky.Q : Cleaned with backup
C:\System Volume Information\_restore{93EA7FB1-3634-4E01-BFEE-735EDB571361}\RP135\A0137053.exe -> Worm.Netsky.Q : Cleaned with backup
C:\System Volume Information\_restore{93EA7FB1-3634-4E01-BFEE-735EDB571361}\RP135\A0137054.exe -> Worm.Netsky.Q : Cleaned with backup
C:\System Volume Information\_restore{93EA7FB1-3634-4E01-BFEE-735EDB571361}\RP135\A0137055.exe -> Worm.Netsky.Q : Cleaned with backup
C:\System Volume Information\_restore{93EA7FB1-3634-4E01-BFEE-735EDB571361}\RP135\A0137056.exe -> Worm.Netsky.Q : Cleaned with backup
C:\System Volume Information\_restore{93EA7FB1-3634-4E01-BFEE-735EDB571361}\RP135\A0137057.exe -> Worm.Netsky.Q : Cleaned with backup
C:\System Volume Information\_restore{93EA7FB1-3634-4E01-BFEE-735EDB571361}\RP135\A0137058.exe -> Worm.Netsky.Q : Cleaned with backup
C:\System Volume Information\_restore{93EA7FB1-3634-4E01-BFEE-735EDB571361}\RP135\A0137059.exe -> Worm.Netsky.Q : Cleaned with backup
C:\System Volume Information\_restore{93EA7FB1-3634-4E01-BFEE-735EDB571361}\RP135\A0137060.exe -> Worm.Netsky.Q : Cleaned with backup
C:\System Volume Information\_restore{93EA7FB1-3634-4E01-BFEE-735EDB571361}\RP135\A0137061.exe -> Worm.Netsky.Q : Cleaned with backup
C:\System Volume Information\_restore{93EA7FB1-3634-4E01-BFEE-735EDB571361}\RP135\A0137062.exe -> Worm.Netsky.Q : Cleaned with backup
C:\System Volume Information\_restore{93EA7FB1-3634-4E01-BFEE-735EDB571361}\RP135\A0137063.exe -> Worm.Netsky.Q : Cleaned with backup
C:\System Volume Information\_restore{93EA7FB1-3634-4E01-BFEE-735EDB571361}\RP135\A0137064.exe -> Worm.Netsky.Q : Cleaned with backup
C:\System Volume Information\_restore{93EA7FB1-3634-4E01-BFEE-735EDB571361}\RP135\A0137065.exe -> Worm.Netsky.Q : Cleaned with backup
C:\System Volume Information\_restore{93EA7FB1-3634-4E01-BFEE-735EDB571361}\RP135\A0137066.exe -> Worm.Netsky.Q : Cleaned with backup
C:\System Volume Information\_restore{93EA7FB1-3634-4E01-BFEE-735EDB571361}\RP135\A0137067.exe -> Worm.Netsky.Q : Cleaned with backup
C:\System Volume Information\_restore{93EA7FB1-3634-4E01-BFEE-735EDB571361}\RP135\A0137068.exe -> Worm.Netsky.Q : Cleaned with backup
C:\System Volume Information\_restore{93EA7FB1-3634-4E01-BFEE-735EDB571361}\RP135\A0137069.exe -> Worm.Netsky.Q : Cleaned with backup
C:\System Volume Information\_restore{93EA7FB1-3634-4E01-BFEE-735EDB571361}\RP135\A0137070.exe -> Worm.Netsky.Q : Cleaned with backup
C:\System Volume Information\_restore{93EA7FB1-3634-4E01-BFEE-735EDB571361}\RP135\A0137071.exe -> Worm.Netsky.Q : Cleaned with backup
C:\System Volume Information\_restore{93EA7FB1-3634-4E01-BFEE-735EDB571361}\RP135\A0137072.exe -> Worm.Netsky.Q : Cleaned with backup
C:\System Volume Information\_restore{93EA7FB1-3634-4E01-BFEE-735EDB571361}\RP135\A0137073.exe -> Worm.Netsky.Q : Cleaned with backup
C:\System Volume Information\_restore{93EA7FB1-3634-4E01-BFEE-735EDB571361}\RP135\A0137074.exe -> Worm.Netsky.Q : Cleaned with backup
C:\System Volume Information\_restore{93EA7FB1-3634-4E01-BFEE-735EDB571361}\RP135\A0137075.exe -> Worm.Netsky.Q : Cleaned with backup
C:\System Volume Information\_restore{93EA7FB1-3634-4E01-BFEE-735EDB571361}\RP135\A0137076.scr -> Worm.Netsky.Q : Cleaned with backup
C:\System Volume Information\_restore{93EA7FB1-3634-4E01-BFEE-735EDB571361}\RP135\A0137077.exe -> Worm.Netsky.Q : Cleaned with backup
C:\System Volume Information\_restore{93EA7FB1-3634-4E01-BFEE-735EDB571361}\RP135\A0137078.pif -> Worm.Netsky.Q : Cleaned with backup
C:\System Volume Information\_restore{93EA7FB1-3634-4E01-BFEE-735EDB571361}\RP135\A0137079.scr -> Worm.Netsky.Q : Cleaned with backup
C:\System Volume Information\_restore{93EA7FB1-3634-4E01-BFEE-735EDB571361}\RP135\A0137080.exe -> Worm.Netsky.Q : Cleaned with backup
C:\System Volume Information\_restore{93EA7FB1-3634-4E01-BFEE-735EDB571361}\RP135\A0137081.exe -> Worm.Netsky.Q : Cleaned with backup
C:\System Volume Information\_restore{93EA7FB1-3634-4E01-BFEE-735EDB571361}\RP135\A0137082.exe -> Worm.Netsky.Q : Cleaned with backup
C:\System Volume Information\_restore{93EA7FB1-3634-4E01-BFEE-735EDB571361}\RP135\A0137083.pif -> Worm.Netsky.Q : Cleaned with backup
C:\System Volume Information\_restore{93EA7FB1-3634-4E01-BFEE-735EDB571361}\RP135\A0137084.scr -> Worm.Netsky.Q : Cleaned with backup
C:\System Volume Information\_restore{93EA7FB1-3634-4E01-BFEE-735EDB571361}\RP135\A0137085.scr -> Worm.Netsky.Q : Cleaned with backup
C:\System Volume Information\_restore{93EA7FB1-3634-4E01-BFEE-735EDB571361}\RP135\A0137086.exe -> Worm.Netsky.Q : Cleaned with backup
C:\System Volume Information\_restore{93EA7FB1-3634-4E01-BFEE-735EDB571361}\RP135\A0137087.exe -> Worm.Netsky.Q : Cleaned with backup
C:\System Volume Information\_restore{93EA7FB1-3634-4E01-BFEE-735EDB571361}\RP135\A0137088.pif -> Worm.Netsky.Q : Cleaned with backup
C:\System Volume Information\_restore{93EA7FB1-3634-4E01-BFEE-735EDB571361}\RP135\A0137089.exe -> Worm.Netsky.Q : Cleaned with backup
C:\System Volume Information\_restore{93EA7FB1-3634-4E01-BFEE-735EDB571361}\RP135\A0137090.exe -> Worm.Netsky.Q : Cleaned with backup
C:\System Volume Information\_restore{93EA7FB1-3634-4E01-BFEE-735EDB571361}\RP135\A0137091.exe -> Worm.Netsky.Q : Cleaned with backup
C:\System Volume Information\_restore{93EA7FB1-3634-4E01-BFEE-735EDB571361}\RP135\A0137092.exe -> Worm.Netsky.Q : Cleaned with backup
C:\System Volume Information\_restore{93EA7FB1-3634-4E01-BFEE-735EDB571361}\RP135\A0137093.exe -> Worm.Netsky.Q : Cleaned with backup
C:\System Volume Information\_restore{93EA7FB1-3634-4E01-BFEE-735EDB571361}\RP135\A0137094.exe -> Worm.Netsky.Q : Cleaned with backup
C:\System Volume Information\_restore{93EA7FB1-3634-4E01-BFEE-735EDB571361}\RP135\A0137095.exe -> Worm.Netsky.Q : Cleaned with backup
C:\System Volume Information\_restore{93EA7FB1-3634-4E01-BFEE-735EDB571361}\RP135\A0137096.exe -> Worm.Netsky.Q : Cleaned with backup
C:\System Volume Information\_restore{93EA7FB1-3634-4E01-BFEE-735EDB571361}\RP135\A0137097.exe -> Worm.Netsky.Q : Cleaned with backup
C:\System Volume Information\_restore{93EA7FB1-3634-4E01-BFEE-735EDB571361}\RP135\A0137098.exe -> Worm.Netsky.Q : Cleaned with backup
C:\System Volume Information\_restore{93EA7FB1-3634-4E01-BFEE-735EDB571361}\RP135\A0137099.exe -> Worm.Netsky.Q : Cleaned with backup
C:\System Volume Information\_restore{93EA7FB1-3634-4E01-BFEE-735EDB571361}\RP135\A0137100.exe -> Worm.Netsky.Q : Cleaned with backup
C:\System Volume Information\_restore{93EA7FB1-3634-4E01-BFEE-735EDB571361}\RP135\A0137101.exe -> Worm.Netsky.Q : Cleaned with backup
C:\System Volume Information\_restore{93EA7FB1-3634-4E01-BFEE-735EDB571361}\RP135\A0137102.exe -> Worm.Netsky.Q : Cleaned with backup
C:\System Volume Information\_restore{93EA7FB1-3634-4E01-BFEE-735EDB571361}\RP135\A0137103.exe -> Worm.Netsky.Q : Cleaned with backup
C:\System Volume Information\_restore{93EA7FB1-3634-4E01-BFEE-735EDB571361}\RP135\A0137104.exe -> Worm.Netsky.Q : Cleaned with backup
C:\System Volume Information\_restore{93EA7FB1-3634-4E01-BFEE-735EDB571361}\RP135\A0137105.exe -> Worm.Netsky.Q : Cleaned with backup
C:\System Volume Information\_restore{93EA7FB1-3634-4E01-BFEE-735EDB571361}\RP135\A0137106.exe -> Worm.Netsky.Q : Cleaned with backup
C:\System Volume Information\_restore{93EA7FB1-3634-4E01-BFEE-735EDB571361}\RP135\A0137107.exe -> Worm.Netsky.Q : Cleaned with backup
C:\System Volume Information\_restore{93EA7FB1-3634-4E01-BFEE-735EDB571361}\RP135\A0137108.exe -> Worm.Netsky.Q : Cleaned with backup
C:\System Volume Information\_restore{93EA7FB1-3634-4E01-BFEE-735EDB571361}\RP135\A0137109.exe -> Worm.Netsky.Q : Cleaned with backup
C:\System Volume Information\_restore{93EA7FB1-3634-4E01-BFEE-735EDB571361}\RP135\A0137110.exe -> Worm.Netsky.Q : Cleaned with backup
C:\System Volume Information\_restore{93EA7FB1-3634-4E01-BFEE-735EDB571361}\RP135\A0137111.exe -> Worm.Netsky.Q : Cleaned with backup
C:\System Volume Information\_restore{93EA7FB1-3634-4E01-BFEE-735EDB571361}\RP135\A0137112.exe -> Worm.Netsky.Q : Cleaned with backup
C:\System Volume Information\_restore{93EA7FB1-3634-4E01-BFEE-735EDB571361}\RP135\A0137113.exe -> Worm.Netsky.Q : Cleaned with backup
C:\System Volume Information\_restore{93EA7FB1-3634-4E01-BFEE-735EDB571361}\RP135\A0137114.exe -> Worm.Netsky.Q : Cleaned with backup
C:\System Volume Information\_restore{93EA7FB1-3634-4E01-BFEE-735EDB571361}\RP135\A0137115.exe -> Worm.Netsky.Q : Cleaned with backup
C:\System Volume Information\_restore{93EA7FB1-3634-4E01-BFEE-735EDB571361}\RP135\A0137116.exe -> Worm.Netsky.Q : Cleaned with backup
C:\System Volume Information\_restore{93EA7FB1-3634-4E01-BFEE-735EDB571361}\RP135\A0137117.exe -> Worm.Netsky.Q : Cleaned with backup
C:\System Volume Information\_restore{93EA7FB1-3634-4E01-BFEE-735EDB571361}\RP135\A0137118.exe -> Worm.Netsky.Q : Cleaned with backup
C:\System Volume Information\_restore{93EA7FB1-3634-4E01-BFEE-735EDB571361}\RP135\A0137119.exe -> Worm.Netsky.Q : Cleaned with backup
C:\System Volume Information\_restore{93EA7FB1-3634-4E01-BFEE-735EDB571361}\RP135\A0137120.exe -> Worm.Netsky.Q : Cleaned with backup
C:\System Volume Information\_restore{93EA7FB1-3634-4E01-BFEE-735EDB571361}\RP135\A0137121.exe -> Worm.Netsky.Q : Cleaned with backup
C:\System Volume Information\_restore{93EA7FB1-3634-4E01-BFEE-735EDB571361}\RP135\A0137122.exe -> Worm.Netsky.Q : Cleaned with backup
C:\System Volume Information\_restore{93EA7FB1-3634-4E01-BFEE-735EDB571361}\RP135\A0137123.exe -> Worm.Netsky.Q : Cleaned with backup
C:\System Volume Information\_restore{93EA7FB1-3634-4E01-BFEE-735EDB571361}\RP135\A0137124.exe -> Worm.Netsky.Q : Cleaned with backup
C:\System Volume Information\_restore{93EA7FB1-3634-4E01-BFEE-735EDB571361}\RP135\A0137125.exe -> Worm.Netsky.Q : Cleaned with backup
C:\System Volume Information\_restore{93EA7FB1-3634-4E01-BFEE-735EDB571361}\RP135\A0137126.exe -> Worm.Netsky.Q : Cleaned with backup
C:\System Volume Information\_restore{93EA7FB1-3634-4E01-BFEE-735EDB571361}\RP135\A0137127.exe -> Worm.Netsky.Q : Cleaned with backup
C:\System Volume Information\_restore{93EA7FB1-3634-4E01-BFEE-735EDB571361}\RP135\A0137163.dll -> Backdoor.Agent.lg : Cleaned with backup
C:\System Volume Information\_restore{93EA7FB1-3634-4E01-BFEE-735EDB571361}\RP135\A0137186.dll -> Spyware.SBSoft : Cleaned with backup
C:\System Volume Information\_restore{93EA7FB1-3634-4E01-BFEE-735EDB571361}\RP135\A0137189.dll -> Spyware.Puper : Cleaned with backup
C:\System Volume Information\_restore{93EA7FB1-3634-4E01-BFEE-735EDB571361}\RP135\A0137234.exe -> TrojanDownloader.Domcom.a : Cleaned with backup
C:\System Volume Information\_restore{93EA7FB1-3634-4E01-BFEE-735EDB571361}\RP137\A0137279.exe -> Trojan.Agent.ff : Cleaned with backup
C:\System Volume Information\_restore{93EA7FB1-3634-4E01-BFEE-735EDB571361}\RP137\A0137280.exe -> Trojan.Agent.ff : Cleaned with backup
C:\System Volume Information\_restore{93EA7FB1-3634-4E01-BFEE-735EDB571361}\RP137\A0137303.dll -> Dialer.Generic : Cleaned with backup
C:\System Volume Information\_restore{93EA7FB1-3634-4E01-BFEE-735EDB571361}\RP137\A0137304.dll -> TrojanDownloader.Wintrim.h : Cleaned with backup
C:\System Volume Information\_restore{93EA7FB1-3634-4E01-BFEE-735EDB571361}\RP137\A0137305.dll -> Dialer.Generic : Cleaned with backup
C:\System Volume Information\_restore{93EA7FB1-3634-4E01-BFEE-735EDB571361}\RP138\A0140304.exe -> Worm.Netsky.Q : Cleaned with backup
C:\System Volume Information\_restore{93EA7FB1-3634-4E01-BFEE-735EDB571361}\RP138\A0140305.scr -> Worm.Netsky.C : Cleaned with backup
C:\System Volume Information\_restore{93EA7FB1-3634-4E01-BFEE-735EDB571361}\RP138\A0140306.scr -> Worm.Netsky.Q : Cleaned with backup
C:\System Volume Information\_restore{93EA7FB1-3634-4E01-BFEE-735EDB571361}\RP138\A0140307.exe -> Worm.Netsky.Q : Cleaned with backup
C:\System Volume Information\_restore{93EA7FB1-3634-4E01-BFEE-735EDB571361}\RP138\A0140308.exe -> Worm.Netsky.Q : Cleaned with backup
C:\System Volume Information\_restore{93EA7FB1-3634-4E01-BFEE-735EDB571361}\RP138\A0139581.exe -> Worm.Bagz.j : Cleaned with backup
C:\System Volume Information\_restore{93EA7FB1-3634-4E01-BFEE-735EDB571361}\RP138\A0139582.exe -> Worm.Bagz.j : Cleaned with backup
C:\System Volume Information\_restore{93EA7FB1-3634-4E01-BFEE-735EDB571361}\RP138\A0139583.exe -> Trojan.Small.ej : Cleaned with backup
C:\System Volume Information\_restore{93EA7FB1-3634-4E01-BFEE-735EDB571361}\RP138\A0139584.exe -> Trojan.Small.ej : Cleaned with backup
C:\System Volume Information\_restore{93EA7FB1-3634-4E01-BFEE-735EDB571361}\RP138\A0139585.exe -> Trojan.LowZones : Cleaned with backup
C:\System Volume Information\_restore{93EA7FB1-3634-4E01-BFEE-735EDB571361}\RP138\A0139586.pif -> Worm.Netsky.C : Cleaned with backup
C:\System Volume Information\_restore{93EA7FB1-3634-4E01-BFEE-735EDB571361}\RP138\A0139587.scr -> Worm.Netsky.C : Cleaned with backup
C:\System Volume Information\_restore{93EA7FB1-3634-4E01-BFEE-735EDB571361}\RP138\A0139588.scr -> Worm.Netsky.C : Cleaned with backup
C:\System Volume Information\_restore{93EA7FB1-3634-4E01-BFEE-735EDB571361}\RP138\A0139589.pif -> Worm.Netsky.C : Cleaned with backup
C:\System Volume Information\_restore{93EA7FB1-3634-4E01-BFEE-735EDB571361}\RP138\A0139590.scr -> Worm.Netsky.C : Cleaned with backup
C:\System Volume Information\_restore{93EA7FB1-3634-4E01-BFEE-735EDB571361}\RP138\A0139591.pif -> Worm.Netsky.C : Cleaned with backup
C:\System Volume Information\_restore{93EA7FB1-3634-4E01-BFEE-735EDB571361}\RP138\A0139592.scr -> Worm.Netsky.C : Cleaned with backup
C:\System Volume Information\_restore{93EA7FB1-3634-4E01-BFEE-735EDB571361}\RP138\A0139593.pif -> Worm.Netsky.C : Cleaned with backup
C:\System Volume Information\_restore{93EA7FB1-3634-4E01-BFEE-735EDB571361}\RP138\A0139594.scr -> Worm.Netsky.C : Cleaned with backup
C:\System Volume Information\_restore{93EA7FB1-3634-4E01-BFEE-735EDB571361}\RP138\A0139595.scr -> Worm.Netsky.C : Cleaned with backup
C:\System Volume Information\_restore{93EA7FB1-3634-4E01-BFEE-735EDB571361}\RP138\A0139596.pif -> Worm.Netsky.C : Cleaned with backup
C:\System Volume Information\_restore{93EA7FB1-3634-4E01-BFEE-735EDB571361}\RP138\A0139597.scr -> Worm.Netsky.C : Cleaned with backup
C:\System Volume Information\_restore{93EA7FB1-3634-4E01-BFEE-735EDB571361}\RP138\A0139598.pif -> Worm.Netsky.C : Cleaned with backup
C:\System Volume Information\_restore{93EA7FB1-3634-4E01-BFEE-735EDB571361}\RP138\A0139599.scr -> Worm.Netsky.C : Cleaned with backup
C:\System Volume Information\_restore{93EA7FB1-3634-4E01-BFEE-735EDB571361}\RP138\A0139612.exe -> Worm.Netsky.Q : Cleaned with backup
C:\System Volume Information\_restore{93EA7FB1-3634-4E01-BFEE-735EDB571361}\RP138\A0139613.exe -> Worm.Netsky.Q : Cleaned with backup
C:\System Volume Information\_restore{93EA7FB1-3634-4E01-BFEE-735EDB571361}\RP138\A0139614.exe -> Worm.Netsky.Q : Cleaned with backup
C:\System Volume Information\_restore{93EA7FB1-3634-4E01-BFEE-735EDB571361}\RP138\A0139615.exe -> Worm.Netsky.Q : Cleaned with backup
C:\System Volume Information\_restore{93EA7FB1-3634-4E01-BFEE-735EDB571361}\RP138\A0139616.exe -> Worm.Netsky.Q : Cleaned with backup
C:\System Volume Information\_restore{93EA7FB1-3634-4E01-BFEE-735EDB571361}\RP138\A0139617.exe -> Worm.Netsky.Q : Cleaned with backup
C:\System Volume Information\_restore{93EA7FB1-3634-4E01-BFEE-735EDB571361}\RP138\A0139618.exe -> Worm.Netsky.Q : Cleaned with backup
C:\System Volume Information\_restore{93EA7FB1-3634-4E01-BFEE-735EDB571361}\RP138\A0139619.exe -> Worm.Netsky.Q : Cleaned with backup
C:\System Volume Information\_restore{93EA7FB1-3634-4E01-BFEE-735EDB571361}\RP138\A0139620.exe -> Worm.Netsky.Q : Cleaned with backup
C:\System Volume Information\_restore{93EA7FB1-3634-4E01-BFEE-735EDB571361}\RP138\A0139621.exe -> Worm.Netsky.Q : Cleaned with backup
C:\System Volume Information\_restore{93EA7FB1-3634-4E01-BFEE-735EDB571361}\RP138\A0139622.exe -> Worm.Netsky.Q : Cleaned with backup
C:\System Volume Information\_restore{93EA7FB1-3634-4E01-BFEE-735EDB571361}\RP138\A0139623.exe -> Worm.Netsky.Q : Cleaned with backup
C:\System Volume Information\_restore{93EA7FB1-3634-4E01-BFEE-735EDB571361}\RP138\A0139624.exe -> Worm.Netsky.Q : Cleaned with backup
C:\System Volume Information\_restore{93EA7FB1-3634-4E01-BFEE-735EDB571361}\RP138\A0139625.exe -> Worm.Netsky.Q : Cleaned with backup
C:\System Volume Information\_restore{93EA7FB1-3634-4E01-BFEE-735EDB571361}\RP138\A0139626.exe -> Worm.Netsky.Q : Cleaned with backup
C:\System Volume Information\_restore{93EA7FB1-3634-4E01-BFEE-735EDB571361}\RP138\A0139627.exe -> Worm.Netsky.Q : Cleaned with backup
C:\System Volume Information\_restore{93EA7FB1-3634-4E01-BFEE-735EDB571361}\RP138\A0139628.exe -> Worm.Netsky.Q : Cleaned with backup
C:\System Volume Information\_restore{93EA7FB1-3634-4E01-BFEE-735EDB571361}\RP138\A0139629.exe -> Worm.Netsky.Q : Cleaned with backup
C:\System Volume Information\_restore{93EA7FB1-3634-4E01-BFEE-735EDB571361}\RP138\A0139630.exe -> Worm.Netsky.Q : Cleaned with backup
C:\System Volume Information\_restore{93EA7FB1-3634-4E01-BFEE-735EDB571361}\RP138\A0139631.exe -> Worm.Netsky.Q : Cleaned with backup
C:\System Volume Information\_restore{93EA7FB1-3634-4E01-BFEE-735EDB571361}\RP138\A0139632.exe -> Worm.Netsky.Q : Cleaned with backup
C:\System Volume Information\_restore{93EA7FB1-3634-4E01-BFEE-735EDB571361}\RP138\A0139633.exe -> Worm.Netsky.Q : Cleaned with backup
C:\System Volume Information\_restore{93EA7FB1-3634-4E01-BFEE-735EDB571361}\RP138\A0139634.exe -> Worm.Netsky.Q : Cleaned with backup
C:\System Volume Information\_restore{93EA7FB1-3634-4E01-BFEE-735EDB571361}\RP138\A0139635.exe -> Worm.Netsky.Q : Cleaned with backup
C:\System Volume Information\_restore{93EA7FB1-3634-4E01-BFEE-735EDB571361}\RP138\A0139636.exe -> Worm.Netsky.Q : Cleaned with backup
C:\System Volume Information\_restore{93EA7FB1-3634-4E01-BFEE-735EDB571361}\RP138\A0139637.exe -> Worm.Netsky.Q : Cleaned with backup
C:\System Volume Information\_restore{93EA7FB1-3634-4E01-BFEE-735EDB571361}\RP138\A0139638.exe -> Worm.Netsky.Q : Cleaned with backup
C:\System Volume Information\_restore{93EA7FB1-3634-4E01-BFEE-735EDB571361}\RP138\A0139639.exe -> Worm.Netsky.Q : Cleaned with backup
C:\System Volume Information\_restore{93EA7FB1-3634-4E01-BFEE-735EDB571361}\RP138\A0139640.exe -> Worm.Netsky.Q : Cleaned with backup
C:\System Volume Information\_restore{93EA7FB1-3634-4E01-BFEE-735EDB571361}\RP138\A0139641.exe -> Worm.Netsky.Q : Cleaned with backup
C:\System Volume Information\_restore{93EA7FB1-3634-4E01-BFEE-735EDB571361}\RP138\A0139642.exe -> Worm.Netsky.Q : Cleaned with backup
C:\System Volume Information\_restore{93EA7FB1-3634-4E01-BFEE-735EDB571361}\RP138\A0139643.exe -> Worm.Netsky.Q : Cleaned with backup
C:\System Volume Information\_restore{93EA7FB1-3634-4E01-BFEE-735EDB571361}\RP138\A0139644.exe -> Worm.Netsky.Q : Cleaned with backup
C:\System Volume Information\_restore{93EA7FB1-3634-4E01-BFEE-735EDB571361}\RP138\A0139645.exe -> Worm.Netsky.Q : Cleaned with backup
C:\System Volume Information\_restore{93EA7FB1-3634-4E01-BFEE-735EDB571361}\RP138\A0139646.exe -> Worm.Netsky.Q : Cleaned with backup
C:\System Volume Information\_restore{93EA7FB1-3634-4E01-BFEE-735EDB571361}\RP138\A0139647.exe -> Worm.Netsky.Q : Cleaned with backup
C:\System Volume Information\_restore{93EA7FB1-3634-4E01-BFEE-735EDB571361}\RP138\A0139648.exe -> Worm.Netsky.Q : Cleaned with backup
C:\System Volume Information\_restore{93EA7FB1-3634-4E01-BFEE-735EDB571361}\RP138\A0139649.exe -> Worm.Netsky.Q : Cleaned with backup
C:\System Volume Information\_restore{93EA7FB1-3634-4E01-BFEE-735EDB571361}\RP138\A0139650.exe -> Worm.Netsky.Q : Cleaned with backup
C:\System Volume Information\_restore{93EA7FB1-3634-4E01-BFEE-735EDB571361}\RP138\A0139651.exe -> Worm.Netsky.Q : Cleaned with backup
C:\System Volume Information\_restore{93EA7FB1-3634-4E01-BFEE-735EDB571361}\RP138\A0139652.exe -> Worm.Netsky.Q : Cleaned with backup
C:\System Volume Information\_restore{93EA7FB1-3634-4E01-BFEE-735EDB571361}\RP138\A0139653.exe -> Worm.Netsky.Q : Cleaned with backup
C:\System Volume Information\_restore{93EA7FB1-3634-4E01-BFEE-735EDB571361}\RP138\A0139654.exe -> Worm.Netsky.Q : Cleaned with backup
C:\System Volume Information\_restore{93EA7FB1-3634-4E01-BFEE-735EDB571361}\RP138\A0139655.exe -> Worm.Netsky.Q : Cleaned with backup
C:\System Volume Information\_restore{93EA7FB1-3634-4E01-BFEE-735EDB571361}\RP138\A0139656.exe -> Worm.Netsky.Q : Cleaned with backup
C:\System Volume Information\_restore{93EA7FB1-3634-4E01-BFEE-735EDB571361}\RP138\A0139657.exe -> Worm.Netsky.Q : Cleaned with backup
C:\System Volume Information\_restore{93EA7FB1-3634-4E01-BFEE-735EDB571361}\RP138\A0139658.exe -> Worm.Netsky.Q : Cleaned with backup
C:\System Volume Information\_restore{93EA7FB1-3634-4E01-BFEE-735EDB571361}\RP138\A0139659.exe -> Worm.Netsky.Q : Cleaned with backup
C:\System Volume Information\_restore{93EA7FB1-3634-4E01-BFEE-735EDB571361}\RP138\A0139660.exe -> Worm.Netsky.Q : Cleaned with backup
C:\System Volume Information\_restore{93EA7FB1-3634-4E01-BFEE-735EDB571361}\RP138\A0139661.exe -> Worm.Netsky.Q : Cleaned with backup
C:\System Volume Information\_restore{93EA7FB1-3634-4E01-BFEE-735EDB571361}\RP138\A0139662.exe -> Worm.Netsky.Q : Cleaned with backup
C:\System Volume Information\_restore{93EA7FB1-3634-4E01-BFEE-735EDB571361}\RP138\A0139663.exe -> Worm.Netsky.Q : Cleaned with backup
C:\System Volume Information\_restore{93EA7FB1-3634-4E01-BFEE-735EDB571361}\RP138\A0139664.exe -> Worm.Netsky.Q : Cleaned with backup
C:\System Volume Information\_restore{93EA7FB1-3634-4E01-BFEE-735EDB571361}\RP138\A0139665.exe -> Worm.Netsky.Q : Cleaned with backup
C:\System Volume Information\_restore{93EA7FB1-3634-4E01-BFEE-735EDB571361}\RP138\A0139666.exe -> Worm.Netsky.Q : Cleaned with backup
C:\System Volume Information\_restore{93EA7FB1-3634-4E01-BFEE-735EDB571361}\RP138\A0139667.exe -> Worm.Netsky.Q : Cleaned with backup
C:\System Volume Information\_restore{93EA7FB1-3634-4E01-BFEE-735EDB571361}\RP138\A0139668.exe -> Worm.Netsky.Q : Cleaned with backup
C:\System Volume Information\_restore{93EA7FB1-3634-4E01-BFEE-735EDB571361}\RP138\A0139669.exe -> Worm.Netsky.Q : Cleaned with backup
C:\System Volume Information\_restore{93EA7FB1-3634-4E01-BFEE-735EDB571361}\RP138\A0139670.exe -> Worm.Netsky.Q : Cleaned with backup
C:\System Volume Information\_restore{93EA7FB1-3634-4E01-BFEE-735EDB571361}\RP138\A0139671.scr -> Worm.Netsky.Q : Cleaned with backup
C:\System Volume Information\_restore{93EA7FB1-3634-4E01-BFEE-735EDB571361}\RP138\A0139672.exe -> Worm.Netsky.Q : Cleaned with backup
C:\System Volume Information\_restore{93EA7FB1-3634-4E01-BFEE-735EDB571361}\RP138\A0139673.exe -> Worm.Netsky.Q : Cleaned with backup
C:\System Volume Information\_restore{93EA7FB1-3634-4E01-BFEE-735EDB571361}\RP138\A0139674.exe -> Worm.Netsky.Q : Cleaned with backup
C:\System Volume Information\_restore{93EA7FB1-3634-4E01-BFEE-735EDB571361}\RP138\A0139675.scr -> Worm.Netsky.Q : Cleaned with backup
C:\System Volume Information\_restore{93EA7FB1-3634-4E01-BFEE-735EDB571361}\RP138\A0139676.exe -> Worm.Netsky.Q : Cleaned with backup
C:\System Volume Information\_restore{93EA7FB1-3634-4E01-BFEE-735EDB571361}\RP138\A0139677.exe -> Worm.Netsky.Q : Cleaned with backup
C:\System Volume Information\_restore{93EA7FB1-3634-4E01-BFEE-735EDB571361}\RP138\A0139678.exe -> Worm.Netsky.Q : Cleaned with backup
C:\System Volume Information\_restore{93EA7FB1-3634-4E01-BFEE-735EDB571361}\RP138\A0139679.exe -> Worm.Netsky.Q : Cleaned with backup
C:\System Volume Information\_restore{93EA7FB1-3634-4E01-BFEE-735EDB571361}\RP138\A0139680.scr -> Worm.Netsky.Q : Cleaned with backup
C:\System Volume Information\_restore{93EA7FB1-3634-4E01-BFEE-735EDB571361}\RP138\A0139681.exe -> Worm.Netsky.Q : Cleaned with backup
C:\System Volume Information\_restore{93EA7FB1-3634-4E01-BFEE-735EDB571361}\RP138\A0139683.exe -> Worm.Netsky.Q : Cleaned with backup
C:\System Volume Information\_restore{93EA7FB1-3634-4E01-BFEE-735EDB571361}\RP138\A0139684.exe -> Worm.Netsky.Q : Cleaned with backup
C:\System Volume Information\_restore{93EA7FB1-3634-4E01-BFEE-735EDB571361}\RP138\A0139685.pif -> Worm.Netsky.Q : Cleaned with backup
C:\System Volume Information\_restore{93EA7FB1-3634-4E01-BFEE-735EDB571361}\RP138\A0139686.exe -> Worm.Netsky.Q : Cleaned with backup
C:\System Volume Information\_restore{93EA7FB1-3634-4E01-BFEE-735EDB571361}\RP138\A0139687.exe -> Worm.Netsky.Q : Cleaned with backup
C:\System Volume Information\_restore{93EA7FB1-3634-4E01-BFEE-735EDB571361}\RP138\A0139688.exe -> Worm.Netsky.Q : Cleaned with backup
C:\System Volume Information\_restore{93EA7FB1-3634-4E01-BFEE-735EDB571361}\RP138\A0139689.exe -> Worm.Netsky.Q : Cleaned with backup
C:\System Volume Information\_restore{93EA7FB1-3634-4E01-BFEE-735EDB571361}\RP138\A0139690.exe -> Worm.Netsky.Q : Cleaned with backup
C:\System Volume Information\_restore{93EA7FB1-3634-4E01-BFEE-735EDB571361}\RP138\A0139691.exe -> Worm.Netsky.Q : Cleaned with backup
C:\System Volume Information\_restore{93EA7FB1-3634-4E01-BFEE-735EDB571361}\RP138\A0139692.exe -> Worm.Netsky.Q : Cleaned with backup
C:\System Volume Information\_restore{93EA7FB1-3634-4E01-BFEE-735EDB571361}\RP138\A0139693.exe -> Worm.Netsky.Q : Cleaned with backup
C:\System Volume Information\_restore{93EA7FB1-3634-4E01-BFEE-735EDB571361}\RP138\A0139694.exe -> Worm.Netsky.Q : Cleaned with backup
C:\System Volume Information\_restore{93EA7FB1-3634-4E01-BFEE-735EDB571361}\RP138\A0139695.exe -> Worm.Netsky.Q : Cleaned with backup
C:\System Volume Information\_restore{93EA7FB1-3634-4E01-BFEE-735EDB571361}\RP138\A0139696.exe -> Worm.Netsky.Q : Cleaned with backup
C:\System Volume Information\_restore{93EA7FB1-3634-4E01-BFEE-735EDB571361}\RP138\A0139697.exe -> Worm.Netsky.Q : Cleaned with backup
C:\System Volume Information\_restore{93EA7FB1-3634-4E01-BFEE-735EDB571361}\RP138\A0139698.exe -> Worm.Netsky.Q : Cleaned with backup
C:\System Volume Information\_restore{93EA7FB1-3634-4E01-BFEE-735EDB571361}\RP138\A0139699.exe -> Worm.Netsky.Q : Cleaned with backup
C:\System Volume Information\_restore{93EA7FB1-3634-4E01-BFEE-735EDB571361}\RP138\A0139700.exe -> Worm.Netsky.Q : Cleaned with backup
C:\System Volume Information\_restore{93EA7FB1-3634-4E01-BFEE-735EDB571361}\RP138\A0139701.exe -> Worm.Netsky.Q : Cleaned with backup
C:\System Volume Information\_restore{93EA7FB1-3634-4E01-BFEE-735EDB571361}\RP138\A0139702.exe -> Worm.Netsky.Q : Cleaned with backup
C:\System Volume Information\_restore{93EA7FB1-3634-4E01-BFEE-735EDB571361}\RP138\A0139703.exe -> Worm.Netsky.Q : Cleaned with backup
C:\System Volume Information\_restore{93EA7FB1-3634-4E01-BFEE-735EDB571361}\RP138\A0139704.exe -> Worm.Netsky.Q : Cleaned with backup
C:\System Volume Information\_restore{93EA7FB1-3634-4E01-BFEE-735EDB571361}\RP138\A0139705.exe -> Worm.Netsky.Q : Cleaned with backup
C:\System Volume Information\_restore{93EA7FB1-3634-4E01-BFEE-735EDB571361}\RP138\A0139706.scr -> Worm.Netsky.Q : Cleaned with backup
C:\System Volume Information\_restore{93EA7FB1-3634-4E01-BFEE-735EDB571361}\RP138\A0139707.exe -> Worm.Netsky.Q : Cleaned with backup
C:\System Volume Information\_restore{93EA7FB1-3634-4E01-BFEE-735EDB571361}\RP138\A0139708.exe -> Worm.Netsky.Q : Cleaned with backup
C:\System Volume Information\_restore{93EA7FB1-3634-4E01-BFEE-735EDB571361}\RP138\A0139709.exe -> Worm.Netsky.Q : Cleaned with backup
C:\System Volume Information\_restore{93EA7FB1-3634-4E01-BFEE-735EDB571361}\RP138\A0139710.pif -> Worm.Netsky.Q : Cleaned with backup
C:\System Volume Information\_restore{93EA7FB1-3634-4E01-BFEE-735EDB571361}\RP138\A0139711.exe -> Worm.Netsky.Q : Cleaned with backup
C:\System Volume Information\_restore{93EA7FB1-3634-4E01-BFEE-735EDB571361}\RP138\A0139712.exe -> Worm.Netsky.Q : Cleaned with backup
C:\System Volume Information\_restore{93EA7FB1-3634-4E01-BFEE-735EDB571361}\RP138\A0139713.exe -> Worm.Netsky.Q : Cleaned with backup
C:\System Volume Information\_restore{93EA7FB1-3634-4E01-BFEE-735EDB571361}\RP138\A0139714.exe -> Worm.Netsky.Q : Cleaned with backup
C:\System Volume Information\_restore{93EA7FB1-3634-4E01-BFEE-735EDB571361}\RP138\A0139715.exe -> Worm.Netsky.Q : Cleaned with backup
C:\System Volume Information\_restore{93EA7FB1-3634-4E01-BFEE-735EDB571361}\RP138\A0139716.exe -> Worm.Netsky.Q : Cleaned with backup
C:\System Volume Information\_restore{93EA7FB1-3634-4E01-BFEE-735EDB571361}\RP138\A0139717.exe -> Worm.Netsky.Q : Cleaned with backup
C:\System Volume Information\_restore{93EA7FB1-3634-4E01-BFEE-735EDB571361}\RP138\A0139718.exe -> Worm.Netsky.Q : Cleaned with backup
C:\System Volume Information\_restore{93EA7FB1-3634-4E01-BFEE-735EDB571361}\RP138\A0139719.exe -> Worm.Netsky.Q : Cleaned with backup
C:\System Volume Information\_restore{93EA7FB1-3634-4E01-BFEE-735EDB571361}\RP138\A0139720.exe -> Worm.Netsky.Q : Cleaned with backup
C:\System Volume Information\_restore{93EA7FB1-3634-4E01-BFEE-735EDB571361}\RP138\A0139721.exe -> Worm.Netsky.Q : Cleaned with backup
C:\System Volume Information\_restore{93EA7FB1-3634-4E01-BFEE-735EDB571361}\RP138\A0139722.exe -> Worm.Netsky.Q : Cleaned with backup
C:\System Volume Information\_restore{93EA7FB1-3634-4E01-BFEE-735EDB571361}\RP138\A0139723.pif -> Worm.Netsky.Q : Cleaned with backup
C:\System Volume Information\_restore{93EA7FB1-3634-4E01-BFEE-735EDB571361}\RP138\A0139724.exe -> Worm.Netsky.Q : Cleaned with backup
C:\System Volume Information\_restore{93EA7FB1-3634-4E01-BFEE-735EDB571361}\RP138\A0139725.exe -> Worm.Netsky.Q : Cleaned with backup
C:\System Volume Information\_restore{93EA7FB1-3634-4E01-BFEE-735EDB571361}\RP138\A0139726.exe -> Worm.Netsky.Q : Cleaned with backup
C:\System Volume Information\_restore{93EA7FB1-3634-4E01-BFEE-735EDB571361}\RP138\A0139727.exe -> Worm.Netsky.Q : Cleaned with backup
C:\System Volume Information\_restore{93EA7FB1-3634-4E01-BFEE-735EDB571361}\RP138\A0139728.exe -> Worm.Netsky.Q : Cleaned with backup
C:\System Volume Information\_restore{93EA7FB1-3634-4E01-BFEE-735EDB571361}\RP138\A0139729.exe -> Worm.Netsky.Q : Cleaned with backup
C:\System Volume Information\_restore{93EA7FB1-3634-4E01-BFEE-735EDB571361}\RP138\A0139730.exe -> Worm.Netsky.Q : Cleaned with backup
C:\System Volume Information\_restore{93EA7FB1-3634-4E01-BFEE-735EDB571361}\RP138\A0139731.exe -> Worm.Netsky.Q : Cleaned with backup
C:\System Volume Information\_restore{93EA7FB1-3634-4E01-BFEE-735EDB571361}\RP138\A0139732.exe -> Worm.Netsky.Q : Cleaned with backup
C:\System Volume Information\_restore{93EA7FB1-3634-4E01-BFEE-735EDB571361}\RP138\A0139733.exe -> Worm.Netsky.Q : Cleaned with backup
C:\System Volume Information\_restore{93EA7FB1-3634-4E01-BFEE-735EDB571361}\RP138\A0139734.exe -> Worm.Netsky.Q : Cleaned with backup
C:\System Volume Information\_restore{93EA7FB1-3634-4E01-BFEE-735EDB571361}\RP138\A0139735.exe -> Worm.Netsky.Q : Cleaned with backup
C:\System Volume Information\_restore{93EA7FB1-3634-4E01-BFEE-735EDB571361}\RP138\A0139736.exe -> Worm.Netsky.Q : Cleaned with backup
C:\System Volume Information\_restore{93EA7FB1-3634-