ok i've done all you said! we seem to have a lot of viruses
firstly the windpfind scan...
WARNING: not all files found by this scanner are bad. Consult with a knowledgable person before proceeding.
If you see a message in the titlebar saying "Not responding..." you can ignore it. Windows somethimes displays this message due to the high volume of disk I/O. As long as the hard disk light is flashing, the program is still working properly.
»»»»»»»»»»»»»»»»» Checking Selected Standard Folders »»»»»»»»»»»»»»»»»»»»
Checking %SystemDrive% folder...
Checking %ProgramFilesDir% folder...
Checking %WinDir% folder...
Checking %System% folder...
SAHAgent 3/7/2005 12:22:12 PM 35 C:\WINDOWS\SYSTEM32\70tovmto.ini
PEC2 8/4/2004 8:00:00 AM 41397 C:\WINDOWS\SYSTEM32\dfrg.msc
PECompact2 7/6/2005 10:21:30 PM 1366872 C:\WINDOWS\SYSTEM32\MRT.exe
aspack 7/6/2005 10:21:30 PM 1366872 C:\WINDOWS\SYSTEM32\MRT.exe
aspack 8/4/2004 8:00:00 AM 708096 C:\WINDOWS\SYSTEM32\ntdll.dll
Umonitor 8/4/2004 8:00:00 AM 657920 C:\WINDOWS\SYSTEM32\rasdlg.dll
winsync 8/4/2004 8:00:00 AM 1309184 C:\WINDOWS\SYSTEM32\wbdbase.deu
Checking %System%\Drivers folder and sub-folders...
Checking the Windows folder for system and hidden files within the last 60 days...
7/11/2005 10:32:28 AM 512020 C:\WINDOWS\addins\asxml.dll
7/11/2005 10:39:52 PM 501708 C:\WINDOWS\addins\lmxsa.bak1
7/25/2005 11:31:16 AM 334415 C:\WINDOWS\addins\lmxsa.bak2
7/26/2005 11:31:18 AM 336452 C:\WINDOWS\addins\lmxsa.ini
7/26/2005 1:43:02 AM 334340 C:\WINDOWS\addins\lmxsa.ini2
7/11/2005 10:32:32 AM 500127 C:\WINDOWS\Help\tunrba.tmp2
7/5/2005 4:33:24 PM 10820 C:\WINDOWS\Help\update.GID
6/25/2005 9:21:56 AM 0 C:\WINDOWS\inf\oem42.inf
7/1/2005 10:29:46 AM 516116 C:\WINDOWS\repair\infowms.dll
7/1/2005 10:46:08 AM 471883 C:\WINDOWS\repair\smwofni.bak1
7/1/2005 10:31:02 AM 472096 C:\WINDOWS\repair\smwofni.bak2
7/26/2005 1:19:28 AM 475414 C:\WINDOWS\repair\smwofni.ini
7/1/2005 10:29:42 AM 473273 C:\WINDOWS\repair\smwofni.ini2
7/26/2005 9:47:46 AM 16384 C:\WINDOWS\system32\config\default.LOG
7/26/2005 9:48:06 AM 1024 C:\WINDOWS\system32\config\SAM.LOG
7/26/2005 9:47:42 AM 16384 C:\WINDOWS\system32\config\SECURITY.LOG
7/26/2005 11:26:46 AM 1024 C:\WINDOWS\system32\config\software.LOG
7/26/2005 11:23:06 AM 1024 C:\WINDOWS\system32\config\system.LOG
7/13/2005 8:32:04 PM 1024 C:\WINDOWS\system32\config\systemprofile\NTUSER.DAT.LOG
7/26/2005 9:46:42 AM 6 C:\WINDOWS\Tasks\SA.DAT
»»»»»»»»»»»»»»»»» Checking Selected Startup Folders »»»»»»»»»»»»»»»»»»»»»
Checking files in %ALLUSERSPROFILE%\Startup folder...
12/22/2004 10:30:44 PM 1918 C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Adobe Gamma Loader.lnk
6/18/2004 8:08:14 PM 1518 C:\Documents and Settings\All Users\Start Menu\Programs\Startup\BigFix.lnk
12/3/2004 3:41:14 PM 551 C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Exif Launcher.lnk
2/21/2005 10:28:42 PM 1730 C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Microsoft Office.lnk
Checking files in %ALLUSERSPROFILE%\Application Data folder...
Checking files in %USERPROFILE%\Startup folder...
Checking files in %USERPROFILE%\Application Data folder...
»»»»»»»»»»»»»»»»» Checking Selected Registry Keys »»»»»»»»»»»»»»»»»»»»»»
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\User Agent\Post Platform
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\User Agent\Post Platform\SV1
SV1 =
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved
HKEY_CLASSES_ROOT\*\shellex\ContextMenuHandlers
HKEY_CLASSES_ROOT\*\shellex\ContextMenuHandlers\Offline Files
{750fdf0e-2a26-11d1-a3ea-080036587f03} = %SystemRoot%\System32\cscui.dll
HKEY_CLASSES_ROOT\*\shellex\ContextMenuHandlers\Open With
{09799AFB-AD67-11d1-ABCD-00C04FC30936} = %SystemRoot%\system32\SHELL32.dll
HKEY_CLASSES_ROOT\*\shellex\ContextMenuHandlers\Open With EncryptionMenu
{A470F8CF-A1E8-4f65-8335-227475AA5C46} = %SystemRoot%\system32\SHELL32.dll
HKEY_CLASSES_ROOT\*\shellex\ContextMenuHandlers\Symantec.Norton.Antivirus.IEContextMenu
{5345A4D5-41EB-4A2F-9616-CE1D4F6C35B2} = C:\Program Files\Norton AntiVirus\NavShExt.dll
HKEY_CLASSES_ROOT\*\shellex\ContextMenuHandlers\Yahoo! Mail
{5464D816-CF16-4784-B9F3-75C0DB52B499} = C:\PROGRA~1\Yahoo!\Common\ymmapi.dll
HKEY_CLASSES_ROOT\*\shellex\ContextMenuHandlers\{a2a9545d-a0c2-42b4-9708-a0b2badd77c8}
Start Menu Pin = %SystemRoot%\system32\SHELL32.dll
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Folder\shellex\ContextMenuHandlers
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Folder\shellex\ContextMenuHandlers\Symantec.Norton.Antivirus.IEContextMenu
{5345A4D5-41EB-4A2F-9616-CE1D4F6C35B2} = C:\Program Files\Norton AntiVirus\NavShExt.dll
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Folder\shellex\ColumnHandlers
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Folder\shellex\ColumnHandlers\{0D2E74C4-3C34-11d2-A27E-00C04FC30871}
= %SystemRoot%\system32\SHELL32.dll
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Folder\shellex\ColumnHandlers\{24F14F01-7B1C-11d1-838f-0000F80461CF}
= %SystemRoot%\system32\SHELL32.dll
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Folder\shellex\ColumnHandlers\{24F14F02-7B1C-11d1-838f-0000F80461CF}
= %SystemRoot%\system32\SHELL32.dll
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Folder\shellex\ColumnHandlers\{66742402-F9B9-11D1-A202-0000F81FEDEE}
= %SystemRoot%\system32\SHELL32.dll
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
SoundMan SOUNDMAN.EXE
MMTray C:\Program Files\MUSICMATCH\MUSICMATCH Jukebox\mm_tray.exe
QuickTime Task "C:\Program Files\QuickTime\qttask.exe" -atboottime
CTHelper cthelper.exe
TkBellExe "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
ccApp "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
Symantec NetDriver Monitor C:\PROGRA~1\SYMNET~1\SNDMon.exe /Consumer
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\OptionalComponents
IMAIL
MAPI
MSFS
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnceEx
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
MSMSGS "C:\Program Files\Messenger\msmsgs.exe" /background
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\NonEnum
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\NonEnum\{BDEADF00-C265-11D0-BCED-00A0C90AB50F}
= C:\PROGRA~1\COMMON~1\MICROS~1\WEBFOL~1\MSONSEXT.DLL
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\NonEnum\{6DFD7C5C-2451-11d3-A299-00C04F8EF6AF}
=
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\NonEnum\{0DF44EAA-FF21-4412-828E-260A8728E7F1}
=
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Ratings
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\system
dontdisplaylastusername 0
legalnoticecaption
legalnoticetext
shutdownwithoutlogon 1
undockwithoutlogon 1
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\policies
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer
NoDriveTypeAutoRun 145
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon
UserInit = C:\WINDOWS\system32\userinit.exe,
Shell = Explorer.exe
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\asxml
= C:\WINDOWS\addins\asxml.dll
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\crypt32chain
= crypt32.dll
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\cryptnet
= cryptnet.dll
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\cscdll
= cscdll.dll
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\igfxcui
= igfxsrvc.dll
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\infowms
= C:\WINDOWS\repair\infowms.dll
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\ScCertProp
= wlnotify.dll
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\Schedule
= wlnotify.dll
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\sclgntfy
= sclgntfy.dll
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\SensLogn
= WlNotify.dll
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\termsrv
= wlnotify.dll
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\unip
= C:\WINDOWS\AppPatch\unip.dll
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\wlballoon
= wlnotify.dll
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad\PostBootReminder
{7849596a-48ea-486e-8937-a2a3009f31a9} = %SystemRoot%\system32\SHELL32.dll
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad\CDBurn
{fbeb8a05-beee-4442-804e-409d6c4515e9} = %SystemRoot%\system32\SHELL32.dll
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad\WebCheck
{E6FB5E20-DE35-11CF-9C87-00AA005127ED} = %SystemRoot%\system32\webcheck.dll
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad\SysTray
{35CEC8A3-2BE6-11D2-8773-92E220524153} = C:\WINDOWS\system32\stobject.dll
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\Your Image File Name Here without a path
Debugger = ntsd -d
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows
AppInit_DLLs
»»»»»»»»»»»»»»»»»»»»»»»» Scan Complete »»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»
WinPFind v1.2.4 - Log file written to "WinPFind.Txt" in the WinPFind folder.
the mwav one .....
File C:\WINDOWS\system32\apdd.dll infected by "Trojan-Downloader.Win32.Delf.lh" Virus. Action Taken: File to be deleted on reboot.
File C:\WINDOWS\system32\netut80ex.vxd tagged as not-a-virus:AdWare.BargainBuddy.q. No Action Taken.
File C:\WINDOWS\system32\q17i9a4j.exe tagged as not-a-virus:AdWare.Sahat.o. No Action Taken.
File C:\Documents and Settings\Harriet\Local Settings\Temporary Internet Files\Content.IE5\4H6JGPY3\m1984p16[1].txt infected by "Trojan-Dropper.Win32.Small.zn" Virus. Action Taken: File Deleted.
File C:\Documents and Settings\nick\Local Settings\Temporary Internet Files\Content.IE5\28Q9ZHK8\ad79a8[1].js infected by "Trojan-Downloader.JS.Small.af" Virus. Action Taken: File Deleted.
File C:\Documents and Settings\nick\Local Settings\Temporary Internet Files\Content.IE5\EXXIVALW\interview_of_week_[1].jpg infected by "BkCln.Unknown" Virus. Action Taken: File Renamed.
File C:\Documents and Settings\Owner\Local Settings\Application Data\Wildtangent\Cdacache\00\00\0F.dat tagged as not-a-virus:AdWare.WildTangent.b. No Action Taken.
File C:\Documents and Settings\Owner\Local Settings\Temporary Internet Files\Content.IE5\WZ7FI4P5\ysb_prompt[1].htm infected by "Exploit.HTML.CodeBaseExec" Virus. Action Taken: File Renamed.
File C:\Program Files\Norton AntiVirus\Quarantine\0CF31931.dll tagged as not-a-virus:AdWare.Apropos.f. No Action Taken.
File C:\Program Files\Norton AntiVirus\Quarantine\0CF31931.exe infected by "Trojan-Dropper.Win32.Agent.gk" Virus. Action Taken: File Deleted.
File C:\System Volume Information\_restore{C5941BA0-7954-431B-BB37-2E1ABEED1085}\RP170\A0014629.dll infected by "Trojan.Win32.Agent.cs" Virus. Action Taken: File Deleted.
File C:\System Volume Information\_restore{C5941BA0-7954-431B-BB37-2E1ABEED1085}\RP170\A0014630.exe infected by "Trojan-Dropper.Win32.Agent.jz" Virus. Action Taken: File Deleted.
File C:\System Volume Information\_restore{C5941BA0-7954-431B-BB37-2E1ABEED1085}\RP171\A0014698.dll infected by "Trojan.Win32.Agent.cs" Virus. Action Taken: File Deleted.
File C:\System Volume Information\_restore{C5941BA0-7954-431B-BB37-2E1ABEED1085}\RP171\A0014699.exe tagged as not-a-virus:AdWare.Apropos.f. No Action Taken.
File C:\System Volume Information\_restore{C5941BA0-7954-431B-BB37-2E1ABEED1085}\RP171\A0014700.exe infected by "Trojan-Downloader.Win32.Apropo.t" Virus. Action Taken: File Deleted.
File C:\System Volume Information\_restore{C5941BA0-7954-431B-BB37-2E1ABEED1085}\RP171\A0014701.exe infected by "Trojan-Downloader.Win32.Apropo.t" Virus. Action Taken: File Deleted.
File C:\System Volume Information\_restore{C5941BA0-7954-431B-BB37-2E1ABEED1085}\RP171\A0014702.exe tagged as not-a-virus:AdWare.Apropos.f. No Action Taken.
File C:\System Volume Information\_restore{C5941BA0-7954-431B-BB37-2E1ABEED1085}\RP171\A0014706.dll infected by "Trojan.Win32.Agent.cs" Virus. Action Taken: File Deleted.
File C:\System Volume Information\_restore{C5941BA0-7954-431B-BB37-2E1ABEED1085}\RP171\A0014720.dll infected by "Trojan.Win32.Agent.cs" Virus. Action Taken: File Deleted.
File C:\System Volume Information\_restore{C5941BA0-7954-431B-BB37-2E1ABEED1085}\RP172\A0014731.dll infected by "Trojan.Win32.Agent.cs" Virus. Action Taken: File Deleted.
File C:\System Volume Information\_restore{C5941BA0-7954-431B-BB37-2E1ABEED1085}\RP172\A0014758.dll infected by "Trojan.Win32.Agent.cs" Virus. Action Taken: File Deleted.
File C:\System Volume Information\_restore{C5941BA0-7954-431B-BB37-2E1ABEED1085}\RP173\A0014775.dll infected by "Trojan.Win32.Agent.cs" Virus. Action Taken: File Deleted.
File C:\System Volume Information\_restore{C5941BA0-7954-431B-BB37-2E1ABEED1085}\RP173\A0014818.dll infected by "Trojan.Win32.Agent.cs" Virus. Action Taken: File Deleted.
File C:\System Volume Information\_restore{C5941BA0-7954-431B-BB37-2E1ABEED1085}\RP174\A0014829.dll infected by "Trojan.Win32.Agent.cs" Virus. Action Taken: File Deleted.
File C:\System Volume Information\_restore{C5941BA0-7954-431B-BB37-2E1ABEED1085}\RP174\A0014936.dll infected by "Trojan.Win32.Agent.cs" Virus. Action Taken: File Deleted.
File C:\System Volume Information\_restore{C5941BA0-7954-431B-BB37-2E1ABEED1085}\RP174\A0014950.dll infected by "Trojan.Win32.Agent.cs" Virus. Action Taken: File Deleted.
File C:\System Volume Information\_restore{C5941BA0-7954-431B-BB37-2E1ABEED1085}\RP174\A0014960.dll infected by "Trojan.Win32.Agent.cs" Virus. Action Taken: File Deleted.
File C:\System Volume Information\_restore{C5941BA0-7954-431B-BB37-2E1ABEED1085}\RP174\A0014965.dll infected by "Trojan.Win32.Agent.cs" Virus. Action Taken: File Deleted.
File C:\System Volume Information\_restore{C5941BA0-7954-431B-BB37-2E1ABEED1085}\RP174\A0014978.dll infected by "Trojan.Win32.Agent.cs" Virus. Action Taken: File Deleted.
File C:\System Volume Information\_restore{C5941BA0-7954-431B-BB37-2E1ABEED1085}\RP174\A0014983.dll infected by "Trojan.Win32.Agent.cs" Virus. Action Taken: File Deleted.
File C:\System Volume Information\_restore{C5941BA0-7954-431B-BB37-2E1ABEED1085}\RP175\A0014996.dll infected by "Trojan.Win32.Agent.cs" Virus. Action Taken: File Deleted.
File C:\System Volume Information\_restore{C5941BA0-7954-431B-BB37-2E1ABEED1085}\RP175\A0015012.dll infected by "Trojan.Win32.Agent.cs" Virus. Action Taken: File Deleted.
File C:\System Volume Information\_restore{C5941BA0-7954-431B-BB37-2E1ABEED1085}\RP175\A0015026.dll infected by "Trojan.Win32.Agent.cs" Virus. Action Taken: File Deleted.
File C:\System Volume Information\_restore{C5941BA0-7954-431B-BB37-2E1ABEED1085}\RP176\A0015033.dll infected by "Trojan.Win32.Agent.cs" Virus. Action Taken: File Deleted.
File C:\System Volume Information\_restore{C5941BA0-7954-431B-BB37-2E1ABEED1085}\RP176\A0015112.dll infected by "Trojan.Win32.Agent.cs" Virus. Action Taken: File Deleted.
File C:\System Volume Information\_restore{C5941BA0-7954-431B-BB37-2E1ABEED1085}\RP177\A0015118.dll infected by "Trojan.Win32.Agent.cs" Virus. Action Taken: File Deleted.
File C:\System Volume Information\_restore{C5941BA0-7954-431B-BB37-2E1ABEED1085}\RP177\A0015128.dll infected by "Trojan.Win32.Agent.cs" Virus. Action Taken: File Deleted.
File C:\System Volume Information\_restore{C5941BA0-7954-431B-BB37-2E1ABEED1085}\RP177\A0015137.dll infected by "Trojan.Win32.Agent.cs" Virus. Action Taken: File Deleted.
File C:\System Volume Information\_restore{C5941BA0-7954-431B-BB37-2E1ABEED1085}\RP178\A0015139.dll infected by "Trojan.Win32.Agent.cs" Virus. Action Taken: File Deleted.
File C:\System Volume Information\_restore{C5941BA0-7954-431B-BB37-2E1ABEED1085}\RP178\A0015149.dll infected by "Trojan.Win32.Agent.cs" Virus. Action Taken: File Deleted.
File C:\System Volume Information\_restore{C5941BA0-7954-431B-BB37-2E1ABEED1085}\RP178\A0015154.dll infected by "Trojan.Win32.Agent.cs" Virus. Action Taken: File Deleted.
File C:\System Volume Information\_restore{C5941BA0-7954-431B-BB37-2E1ABEED1085}\RP179\A0015173.dll infected by "Trojan.Win32.Agent.cs" Virus. Action Taken: File Deleted.
File C:\System Volume Information\_restore{C5941BA0-7954-431B-BB37-2E1ABEED1085}\RP179\A0015212.dll infected by "Trojan.Win32.Agent.cs" Virus. Action Taken: File Deleted.
File C:\System Volume Information\_restore{C5941BA0-7954-431B-BB37-2E1ABEED1085}\RP180\A0015216.dll infected by "Trojan.Win32.Agent.cs" Virus. Action Taken: File Deleted.
File C:\System Volume Information\_restore{C5941BA0-7954-431B-BB37-2E1ABEED1085}\RP180\A0015336.exe infected by "Trojan-Dropper.Win32.Small.zn" Virus. Action Taken: File Deleted.
File C:\System Volume Information\_restore{C5941BA0-7954-431B-BB37-2E1ABEED1085}\RP180\A0015339.dll infected by "Trojan.Win32.Agent.cs" Virus. Action Taken: File Deleted.
File C:\System Volume Information\_restore{C5941BA0-7954-431B-BB37-2E1ABEED1085}\RP181\A0015347.dll infected by "Trojan.Win32.Agent.cs" Virus. Action Taken: File Deleted.
File C:\System Volume Information\_restore{C5941BA0-7954-431B-BB37-2E1ABEED1085}\RP182\A0015352.dll infected by "Trojan.Win32.Agent.cs" Virus. Action Taken: File Deleted.
File C:\System Volume Information\_restore{C5941BA0-7954-431B-BB37-2E1ABEED1085}\RP182\A0015356.dll infected by "Trojan.Win32.Agent.cs" Virus. Action Taken: File Deleted.
File C:\System Volume Information\_restore{C5941BA0-7954-431B-BB37-2E1ABEED1085}\RP182\A0015373.dll infected by "Trojan.Win32.Agent.cs" Virus. Action Taken: File Deleted.
File C:\System Volume Information\_restore{C5941BA0-7954-431B-BB37-2E1ABEED1085}\RP183\A0015377.dll infected by "Trojan.Win32.Agent.cs" Virus. Action Taken: File Deleted.
File C:\System Volume Information\_restore{C5941BA0-7954-431B-BB37-2E1ABEED1085}\RP183\A0015399.dll infected by "Trojan.Win32.Agent.cs" Virus. Action Taken: File Deleted.
File C:\System Volume Information\_restore{C5941BA0-7954-431B-BB37-2E1ABEED1085}\RP184\A0015409.dll infected by "Trojan.Win32.Agent.cs" Virus. Action Taken: File Deleted.
File C:\System Volume Information\_restore{C5941BA0-7954-431B-BB37-2E1ABEED1085}\RP184\A0015437.dll infected by "Trojan.Win32.Agent.cs" Virus. Action Taken: File Deleted.
File C:\System Volume Information\_restore{C5941BA0-7954-431B-BB37-2E1ABEED1085}\RP184\A0015449.dll infected by "Trojan.Win32.Agent.cs" Virus. Action Taken: File Deleted.
File C:\System Volume Information\_restore{C5941BA0-7954-431B-BB37-2E1ABEED1085}\RP185\A0015466.dll infected by "Trojan.Win32.Agent.cs" Virus. Action Taken: File Deleted.
File C:\System Volume Information\_restore{C5941BA0-7954-431B-BB37-2E1ABEED1085}\RP185\A0015506.dll infected by "Trojan.Win32.Agent.cs" Virus. Action Taken: File Deleted.
File C:\System Volume Information\_restore{C5941BA0-7954-431B-BB37-2E1ABEED1085}\RP185\A0015517.dll infected by "Trojan.Win32.Agent.cs" Virus. Action Taken: File Deleted.
File C:\System Volume Information\_restore{C5941BA0-7954-431B-BB37-2E1ABEED1085}\RP185\A0015522.dll infected by "Trojan.Win32.Agent.cs" Virus. Action Taken: File Deleted.
File C:\System Volume Information\_restore{C5941BA0-7954-431B-BB37-2E1ABEED1085}\RP185\A0015527.dll infected by "Trojan.Win32.Agent.cs" Virus. Action Taken: File Deleted.
File C:\System Volume Information\_restore{C5941BA0-7954-431B-BB37-2E1ABEED1085}\RP185\A0015544.dll infected by "Trojan.Win32.Agent.cs" Virus. Action Taken: File Deleted.
File C:\System Volume Information\_restore{C5941BA0-7954-431B-BB37-2E1ABEED1085}\RP186\A0015554.dll infected by "Trojan.Win32.Agent.cs" Virus. Action Taken: File Deleted.
File C:\System Volume Information\_restore{C5941BA0-7954-431B-BB37-2E1ABEED1085}\RP186\A0015585.dll infected by "Trojan.Win32.Agent.cs" Virus. Action Taken: File Deleted.
File C:\System Volume Information\_restore{C5941BA0-7954-431B-BB37-2E1ABEED1085}\RP186\A0015612.dll infected by "Trojan.Win32.Agent.cs" Virus. Action Taken: File Deleted.
File C:\System Volume Information\_restore{C5941BA0-7954-431B-BB37-2E1ABEED1085}\RP187\A0015622.dll infected by "Trojan.Win32.Agent.cs" Virus. Action Taken: File Deleted.
File C:\System Volume Information\_restore{C5941BA0-7954-431B-BB37-2E1ABEED1085}\RP187\A0015648.dll infected by "Trojan.Win32.Agent.cs" Virus. Action Taken: File Deleted.
File C:\System Volume Information\_restore{C5941BA0-7954-431B-BB37-2E1ABEED1085}\RP188\A0015652.dll infected by "Trojan.Win32.Agent.cs" Virus. Action Taken: File Deleted.
File C:\System Volume Information\_restore{C5941BA0-7954-431B-BB37-2E1ABEED1085}\RP188\A0015657.dll infected by "Trojan.Win32.Agent.cs" Virus. Action Taken: File Deleted.
File C:\System Volume Information\_restore{C5941BA0-7954-431B-BB37-2E1ABEED1085}\RP188\A0015660.dll infected by "Trojan.Win32.Agent.cs" Virus. Action Taken: File Deleted.
File C:\System Volume Information\_restore{C5941BA0-7954-431B-BB37-2E1ABEED1085}\RP188\A0015687.dll infected by "Trojan.Win32.Agent.cs" Virus. Action Taken: File Deleted.
File C:\System Volume Information\_restore{C5941BA0-7954-431B-BB37-2E1ABEED1085}\RP188\A0015692.dll infected by "Trojan.Win32.Agent.cs" Virus. Action Taken: File Deleted.
File C:\System Volume Information\_restore{C5941BA0-7954-431B-BB37-2E1ABEED1085}\RP188\A0015699.dll infected by "Trojan.Win32.Agent.cs" Virus. Action Taken: File Deleted.
File C:\System Volume Information\_restore{C5941BA0-7954-431B-BB37-2E1ABEED1085}\RP189\A0015703.dll infected by "Trojan.Win32.Agent.cs" Virus. Action Taken: File Deleted.
File C:\System Volume Information\_restore{C5941BA0-7954-431B-BB37-2E1ABEED1085}\RP189\A0016699.dll infected by "Trojan.Win32.Agent.cs" Virus. Action Taken: File Deleted.
File C:\System Volume Information\_restore{C5941BA0-7954-431B-BB37-2E1ABEED1085}\RP189\A0016706.dll infected by "Trojan.Win32.Agent.cs" Virus. Action Taken: File Deleted.
File C:\System Volume Information\_restore{C5941BA0-7954-431B-BB37-2E1ABEED1085}\RP190\A0016709.dll infected by "Trojan.Win32.Agent.cs" Virus. Action Taken: File Deleted.
File C:\System Volume Information\_restore{C5941BA0-7954-431B-BB37-2E1ABEED1085}\RP190\A0016721.dll infected by "Trojan.Win32.Agent.cs" Virus. Action Taken: File Deleted.
File C:\System Volume Information\_restore{C5941BA0-7954-431B-BB37-2E1ABEED1085}\RP191\A0016727.dll infected by "Trojan.Win32.Agent.cs" Virus. Action Taken: File Deleted.
File C:\System Volume Information\_restore{C5941BA0-7954-431B-BB37-2E1ABEED1085}\RP191\A0016741.dll infected by "Trojan.Win32.Agent.cs" Virus. Action Taken: File Deleted.
File C:\System Volume Information\_restore{C5941BA0-7954-431B-BB37-2E1ABEED1085}\RP191\A0016753.dll infected by "Trojan.Win32.Agent.cs" Virus. Action Taken: File Deleted.
File C:\System Volume Information\_restore{C5941BA0-7954-431B-BB37-2E1ABEED1085}\RP191\A0017753.dll infected by "Trojan.Win32.Agent.cs" Virus. Action Taken: File Deleted.
File C:\System Volume Information\_restore{C5941BA0-7954-431B-BB37-2E1ABEED1085}\RP191\A0017810.dll infected by "Trojan.Win32.Agent.cs" Virus. Action Taken: File Deleted.
File C:\System Volume Information\_restore{C5941BA0-7954-431B-BB37-2E1ABEED1085}\RP192\A0017816.dll infected by "Trojan.Win32.Agent.cs" Virus. Action Taken: File Deleted.
File C:\System Volume Information\_restore{C5941BA0-7954-431B-BB37-2E1ABEED1085}\RP192\A0017844.dll infected by "Trojan.Win32.Agent.cs" Virus. Action Taken: File Deleted.
File C:\System Volume Information\_restore{C5941BA0-7954-431B-BB37-2E1ABEED1085}\RP193\A0017852.dll infected by "Trojan.Win32.Agent.cs" Virus. Action Taken: File Deleted.
File C:\System Volume Information\_restore{C5941BA0-7954-431B-BB37-2E1ABEED1085}\RP193\A0017891.dll infected by "Trojan.Win32.Agent.cs" Virus. Action Taken: File Deleted.
File C:\System Volume Information\_restore{C5941BA0-7954-431B-BB37-2E1ABEED1085}\RP194\A0017895.dll infected by "Trojan.Win32.Agent.cs" Virus. Action Taken: File Deleted.
File C:\System Volume Information\_restore{C5941BA0-7954-431B-BB37-2E1ABEED1085}\RP194\A0018891.dll infected by "Trojan.Win32.Agent.cs" Virus. Action Taken: File Deleted.
File C:\System Volume Information\_restore{C5941BA0-7954-431B-BB37-2E1ABEED1085}\RP194\A0018898.dll infected by "Trojan.Win32.Agent.cs" Virus. Action Taken: File Deleted.
File C:\System Volume Information\_restore{C5941BA0-7954-431B-BB37-2E1ABEED1085}\RP194\A0018923.dll infected by "Trojan.Win32.Agent.cs" Virus. Action Taken: File Deleted.
File C:\System Volume Information\_restore{C5941BA0-7954-431B-BB37-2E1ABEED1085}\RP195\A0018942.dll infected by "Trojan.Win32.Agent.cs" Virus. Action Taken: File Deleted.
File C:\System Volume Information\_restore{C5941BA0-7954-431B-BB37-2E1ABEED1085}\RP195\A0019923.dll infected by "Trojan.Win32.Agent.cs" Virus. Action Taken: File Deleted.
File C:\System Volume Information\_restore{C5941BA0-7954-431B-BB37-2E1ABEED1085}\RP195\A0019928.dll infected by "Trojan.Win32.Agent.cs" Virus. Action Taken: File Deleted.
File C:\System Volume Information\_restore{C5941BA0-7954-431B-BB37-2E1ABEED1085}\RP196\A0019943.dll infected by "Trojan.Win32.Agent.cs" Virus. Action Taken: File Deleted.
File C:\System Volume Information\_restore{C5941BA0-7954-431B-BB37-2E1ABEED1085}\RP196\A0020928.dll infected by "Trojan.Win32.Agent.cs" Virus. Action Taken: File Deleted.
File C:\System Volume Information\_restore{C5941BA0-7954-431B-BB37-2E1ABEED1085}\RP196\A0020935.dll infected by "Trojan.Win32.Agent.cs" Virus. Action Taken: File Deleted.
File C:\System Volume Information\_restore{C5941BA0-7954-431B-BB37-2E1ABEED1085}\RP197\A0020947.dll infected by "Trojan.Win32.Agent.cs" Virus. Action Taken: File Deleted.
File C:\System Volume Information\_restore{C5941BA0-7954-431B-BB37-2E1ABEED1085}\RP197\A0020962.dll infected by "Trojan.Win32.Agent.cs" Virus. Action Taken: File Deleted.
File C:\System Volume Information\_restore{C5941BA0-7954-431B-BB37-2E1ABEED1085}\RP198\A0020977.dll infected by "Trojan.Win32.Agent.cs" Virus. Action Taken: File Deleted.
File C:\System Volume Information\_restore{C5941BA0-7954-431B-BB37-2E1ABEED1085}\RP198\A0020992.dll infected by "Trojan.Win32.Agent.cs" Virus. Action Taken: File Deleted.
File C:\System Volume Information\_restore{C5941BA0-7954-431B-BB37-2E1ABEED1085}\RP198\A0020997.dll infected by "Trojan.Win32.Agent.cs" Virus. Action Taken: File Deleted.
File C:\System Volume Information\_restore{C5941BA0-7954-431B-BB37-2E1ABEED1085}\RP199\A0021005.dll infected by "Trojan.Win32.Agent.cs" Virus. Action Taken: File Deleted.
File C:\System Volume Information\_restore{C5941BA0-7954-431B-BB37-2E1ABEED1085}\RP199\A0021015.dll infected by "Trojan.Win32.Agent.cs" Virus. Action Taken: File Deleted.
File C:\System Volume Information\_restore{C5941BA0-7954-431B-BB37-2E1ABEED1085}\RP200\A0021029.dll infected by "Trojan.Win32.Agent.cs" Virus. Action Taken: File Deleted.
File C:\System Volume Information\_restore{C5941BA0-7954-431B-BB37-2E1ABEED1085}\RP200\A0021037.dll infected by "Trojan.Win32.Agent.cs" Virus. Action Taken: File Deleted.
File C:\System Volume Information\_restore{C5941BA0-7954-431B-BB37-2E1ABEED1085}\RP200\A0022037.dll infected by "Trojan.Win32.Agent.cs" Virus. Action Taken: File Deleted.
File C:\System Volume Information\_restore{C5941BA0-7954-431B-BB37-2E1ABEED1085}\RP201\A0022052.dll infected by "Trojan.Win32.Agent.cs" Virus. Action Taken: File Deleted.
File C:\System Volume Information\_restore{C5941BA0-7954-431B-BB37-2E1ABEED1085}\RP201\A0022084.dll infected by "Trojan.Win32.Agent.cs" Virus. Action Taken: File Deleted.
File C:\System Volume Information\_restore{C5941BA0-7954-431B-BB37-2E1ABEED1085}\RP202\A0022094.dll infected by "Trojan.Win32.Agent.cs" Virus. Action Taken: File Deleted.
File C:\System Volume Information\_restore{C5941BA0-7954-431B-BB37-2E1ABEED1085}\RP202\A0022149.dll infected by "Trojan.Win32.Agent.cs" Virus. Action Taken: File Deleted.
File C:\System Volume Information\_restore{C5941BA0-7954-431B-BB37-2E1ABEED1085}\RP203\A0022165.dll infected by "Trojan.Win32.Agent.cs" Virus. Action Taken: File Deleted.
File C:\System Volume Information\_restore{C5941BA0-7954-431B-BB37-2E1ABEED1085}\RP205\A0022190.dll infected by "Trojan.Win32.Agent.cs" Virus. Action Taken: File Deleted.
File C:\System Volume Information\_restore{C5941BA0-7954-431B-BB37-2E1ABEED1085}\RP205\A0022204.dll infected by "Trojan.Win32.Agent.cs" Virus. Action Taken: File Deleted.
File C:\System Volume Information\_restore{C5941BA0-7954-431B-BB37-2E1ABEED1085}\RP206\A0022226.dll infected by "Trojan.Win32.Agent.cs" Virus. Action Taken: File Deleted.
File C:\System Volume Information\_restore{C5941BA0-7954-431B-BB37-2E1ABEED1085}\RP206\A0022433.dll infected by "Trojan.Win32.Agent.cs" Virus. Action Taken: File Deleted.
File C:\System Volume Information\_restore{C5941BA0-7954-431B-BB37-2E1ABEED1085}\RP207\A0022437.dll infected by "Trojan.Win32.Agent.cs" Virus. Action Taken: File Deleted.
File C:\System Volume Information\_restore{C5941BA0-7954-431B-BB37-2E1ABEED1085}\RP207\A0022475.dll infected by "Trojan.Win32.Agent.cs" Virus. Action Taken: File Deleted.
File C:\System Volume Information\_restore{C5941BA0-7954-431B-BB37-2E1ABEED1085}\RP207\A0022480.dll infected by "Trojan.Win32.Agent.cs" Virus. Action Taken: File Deleted.
File C:\System Volume Information\_restore{C5941BA0-7954-431B-BB37-2E1ABEED1085}\RP208\A0022492.dll infected by "Trojan.Win32.Agent.cs" Virus. Action Taken: File Deleted.
File C:\System Volume Information\_restore{C5941BA0-7954-431B-BB37-2E1ABEED1085}\RP208\A0022511.dll infected by "Trojan.Win32.Agent.cs" Virus. Action Taken: File Deleted.
File C:\System Volume Information\_restore{C5941BA0-7954-431B-BB37-2E1ABEED1085}\RP209\A0022523.dll infected by "Trojan.Win32.Agent.cs" Virus. Action Taken: File Deleted.
File C:\System Volume Information\_restore{C5941BA0-7954-431B-BB37-2E1ABEED1085}\RP209\A0023511.dll infected by "Trojan.Win32.Agent.cs" Virus. Action Taken: File Deleted.
File C:\System Volume Information\_restore{C5941BA0-7954-431B-BB37-2E1ABEED1085}\RP209\A0024511.dll infected by "Trojan.Win32.Agent.cs" Virus. Action Taken: File Deleted.
File C:\System Volume Information\_restore{C5941BA0-7954-431B-BB37-2E1ABEED1085}\RP209\A0025511.dll infected by "Trojan.Win32.Agent.cs" Virus. Action Taken: File Deleted.
File C:\System Volume Information\_restore{C5941BA0-7954-431B-BB37-2E1ABEED1085}\RP209\A0025528.dll infected by "Trojan.Win32.Agent.cs" Virus. Action Taken: File Deleted.
File C:\System Volume Information\_restore{C5941BA0-7954-431B-BB37-2E1ABEED1085}\RP209\A0025573.dll infected by "Trojan.Win32.Agent.cs" Virus. Action Taken: File Deleted.
File C:\System Volume Information\_restore{C5941BA0-7954-431B-BB37-2E1ABEED1085}\RP209\A0025577.exe infected by "Trojan-Dropper.Win32.Delf.jm" Virus. Action Taken: File Deleted.
File C:\System Volume Information\_restore{C5941BA0-7954-431B-BB37-2E1ABEED1085}\RP209\A0025584.dll infected by "Trojan.Win32.Agent.cs" Virus. Action Taken: File Deleted.
File C:\System Volume Information\_restore{C5941BA0-7954-431B-BB37-2E1ABEED1085}\RP210\A0025594.dll infected by "Trojan.Win32.Agent.cs" Virus. Action Taken: File Deleted.
File C:\System Volume Information\_restore{C5941BA0-7954-431B-BB37-2E1ABEED1085}\RP210\A0026594.dll infected by "Trojan.Win32.Agent.cs" Virus. Action Taken: File Deleted.
File C:\System Volume Information\_restore{C5941BA0-7954-431B-BB37-2E1ABEED1085}\RP210\A0027594.dll infected by "Trojan.Win32.Agent.cs" Virus. Action Taken: File Deleted.
File C:\System Volume Information\_restore{C5941BA0-7954-431B-BB37-2E1ABEED1085}\RP211\A0027622.dll infected by "Trojan.Win32.Agent.cs" Virus. Action Taken: File Deleted.
File C:\System Volume Information\_restore{C5941BA0-7954-431B-BB37-2E1ABEED1085}\RP211\A0027629.dll infected by "Trojan.Win32.Agent.cs" Virus. Action Taken: File Deleted.
File C:\System Volume Information\_restore{C5941BA0-7954-431B-BB37-2E1ABEED1085}\RP212\A0027667.dll infected by "Trojan.Win32.Agent.cs" Virus. Action Taken: File Deleted.
File C:\System Volume Information\_restore{C5941BA0-7954-431B-BB37-2E1ABEED1085}\RP212\A0027671.dll infected by "Trojan.Win32.Agent.cs" Virus. Action Taken: File Deleted.
File C:\System Volume Information\_restore{C5941BA0-7954-431B-BB37-2E1ABEED1085}\RP212\A0027676.dll infected by "Trojan.Win32.Agent.cs" Virus. Action Taken: File Deleted.
File C:\System Volume Information\_restore{C5941BA0-7954-431B-BB37-2E1ABEED1085}\RP212\A0027731.dll infected by "Trojan.Win32.Agent.cs" Virus. Action Taken: File Deleted.
File C:\System Volume Information\_restore{C5941BA0-7954-431B-BB37-2E1ABEED1085}\RP212\A0027738.dll infected by "Trojan.Win32.Agent.cs" Virus. Action Taken: File Deleted.
File C:\System Volume Information\_restore{C5941BA0-7954-431B-BB37-2E1ABEED1085}\RP212\A0027745.dll infected by "Trojan.Win32.Agent.cs" Virus. Action Taken: File Deleted.
File C:\System Volume Information\_restore{C5941BA0-7954-431B-BB37-2E1ABEED1085}\RP212\A0027749.dll infected by "Trojan.Win32.Agent.cs" Virus. Action Taken: File Deleted.
File C:\System Volume Information\_restore{C5941BA0-7954-431B-BB37-2E1ABEED1085}\RP213\A0027752.dll infected by "Trojan.Win32.Agent.cs" Virus. Action Taken: File Deleted.
File C:\System Volume Information\_restore{C5941BA0-7954-431B-BB37-2E1ABEED1085}\RP213\A0027756.dll infected by "Trojan.Win32.Agent.cs" Virus. Action Taken: File Deleted.
File C:\System Volume Information\_restore{C5941BA0-7954-431B-BB37-2E1ABEED1085}\RP213\A0027762.dll infected by "Trojan.Win32.Agent.cs" Virus. Action Taken: File Deleted.
File C:\System Volume Information\_restore{C5941BA0-7954-431B-BB37-2E1ABEED1085}\RP214\A0027769.dll infected by "Trojan.Win32.Agent.cs" Virus. Action Taken: File Deleted.
File C:\System Volume Information\_restore{C5941BA0-7954-431B-BB37-2E1ABEED1085}\RP214\A0027772.dll infected by "Trojan.Win32.Agent.cs" Virus. Action Taken: File Deleted.
File C:\System Volume Information\_restore{C5941BA0-7954-431B-BB37-2E1ABEED1085}\RP215\A0027779.dll infected by "Trojan.Win32.Agent.cs" Virus. Action Taken: File Deleted.
File C:\System Volume Information\_restore{C5941BA0-7954-431B-BB37-2E1ABEED1085}\RP215\A0028779.dll infected by "Trojan.Win32.Agent.cs" Virus. Action Taken: File Deleted.
File C:\System Volume Information\_restore{C5941BA0-7954-431B-BB37-2E1ABEED1085}\RP216\A0028788.dll infected by "Trojan.Win32.Agent.cs" Virus. Action Taken: File Deleted.
File C:\System Volume Information\_restore{C5941BA0-7954-431B-BB37-2E1ABEED1085}\RP216\A0028800.dll infected by "Trojan.Win32.Agent.cs" Virus. Action Taken: File Deleted.
File C:\System Volume Information\_restore{C5941BA0-7954-431B-BB37-2E1ABEED1085}\RP217\A0028805.dll infected by "Trojan.Win32.Agent.cs" Virus. Action Taken: File Deleted.
File C:\System Volume Information\_restore{C5941BA0-7954-431B-BB37-2E1ABEED1085}\RP218\A0028807.dll infected by "Trojan.Win32.Agent.cs" Virus. Action Taken: File Deleted.
File C:\System Volume Information\_restore{C5941BA0-7954-431B-BB37-2E1ABEED1085}\RP218\A0028898.dll infected by "Trojan.Win32.Agent.cs" Virus. Action Taken: File Deleted.
File C:\System Volume Information\_restore{C5941BA0-7954-431B-BB37-2E1ABEED1085}\RP219\A0028908.dll infected by "Trojan.Win32.Agent.cs" Virus. Action Taken: File Deleted.
File C:\System Volume Information\_restore{C5941BA0-7954-431B-BB37-2E1ABEED1085}\RP219\A0028914.dll infected by "Trojan.Win32.Agent.cs" Virus. Action Taken: File Deleted.
File C:\System Volume Information\_restore{C5941BA0-7954-431B-BB37-2E1ABEED1085}\RP220\A0028919.dll infected by "Trojan.Win32.Agent.cs" Virus. Action Taken: File Deleted.
File C:\System Volume Information\_restore{C5941BA0-7954-431B-BB37-2E1ABEED1085}\RP220\A0028944.dll infected by "Trojan.Win32.Agent.cs" Virus. Action Taken: File Deleted.
File C:\System Volume Information\_restore{C5941BA0-7954-431B-BB37-2E1ABEED1085}\RP220\A0028972.dll infected by "Trojan-Downloader.Win32.ConHook.c" Virus. Action Taken: File Deleted.
File C:\System Volume Information\_restore{C5941BA0-7954-431B-BB37-2E1ABEED1085}\RP224\A0029166.exe tagged as not-a-virus:AdWare.Sahat.o. No Action Taken.
File C:\System Volume Information\_restore{C5941BA0-7954-431B-BB37-2E1ABEED1085}\RP224\A0029168.exe tagged as not-a-virus:AdWare.180Solutions. No Action Taken.
File C:\System Volume Information\_restore{C5941BA0-7954-431B-BB37-2E1ABEED1085}\RP224\A0029169.exe tagged as not-a-virus:AdWare.Sahat.o. No Action Taken.
File C:\System Volume Information\_restore{C5941BA0-7954-431B-BB37-2E1ABEED1085}\RP224\A0029170.dll tagged as not-a-virus:AdWare.Sahat.l. No Action Taken.
File C:\System Volume Information\_restore{C5941BA0-7954-431B-BB37-2E1ABEED1085}\RP224\A0029174.exe tagged as not-a-virus:AdWare.180Solutions. No Action Taken.
File C:\System Volume Information\_restore{C5941BA0-7954-431B-BB37-2E1ABEED1085}\RP224\A0029175.exe tagged as not-a-virus:AdWare.Sahat.o. No Action Taken.
File C:\System Volume Information\_restore{C5941BA0-7954-431B-BB37-2E1ABEED1085}\RP224\A0029176.dll tagged as not-a-virus:AdWare.Sahat.l. No Action Taken.
File C:\System Volume Information\_restore{C5941BA0-7954-431B-BB37-2E1ABEED1085}\RP224\A0029178.exe infected by "Trojan-Dropper.Win32.Delf.jm" Virus. Action Taken: File Deleted.
File C:\System Volume Information\_restore{C5941BA0-7954-431B-BB37-2E1ABEED1085}\RP224\A0029179.exe infected by "Backdoor.Win32.Rbot.gen" Virus. Action Taken: File Renamed.
File C:\System Volume Information\_restore{C5941BA0-7954-431B-BB37-2E1ABEED1085}\RP224\A0029180.exe infected by "Backdoor.Win32.Rbot.km" Virus. Action Taken: File Renamed.
File C:\System Volume Information\_restore{C5941BA0-7954-431B-BB37-2E1ABEED1085}\RP236\A0031043.dll tagged as not-a-virus:AdWare.Virtumonde.l. No Action Taken.
File C:\System Volume Information\_restore{C5941BA0-7954-431B-BB37-2E1ABEED1085}\RP241\A0032659.exe tagged as not-a-virus:AdWare.BargainBuddy.l. No Action Taken.
File C:\System Volume Information\_restore{C5941BA0-7954-431B-BB37-2E1ABEED1085}\RP241\A0032660.exe tagged as not-a-virus:AdWare.BargainBuddy.y. No Action Taken.
File C:\System Volume Information\_restore{C5941BA0-7954-431B-BB37-2E1ABEED1085}\RP242\A0033055.exe infected by "Trojan-Dropper.Win32.Agent.gk" Virus. Action Taken: File Deleted.
File C:\System Volume Information\_restore{C5941BA0-7954-431B-BB37-2E1ABEED1085}\RP242\A0033056.dll tagged as not-a-virus:AdWare.Apropos.f. No Action Taken.
File C:\System Volume Information\_restore{C5941BA0-7954-431B-BB37-2E1ABEED1085}\RP250\A0035565.exe infected by "Trojan-Dropper.Win32.Agent.gk" Virus. Action Taken: File Deleted.
File C:\WINDOWS\system32\drivers\etc\hosts infected by "Trojan.Win32.Qhost.r" Virus. Action Taken: File Deleted.
File C:\WINDOWS\system32\netut80ex.vxd tagged as not-a-virus:AdWare.BargainBuddy.q. No Action Taken.
File C:\WINDOWS\system32\q17i9a4j.exe tagged as not-a-virus:AdWare.Sahat.o. No Action Taken.
File C:\WINDOWS\wt\wtupdates\webd\4.1.1\files\wtvh.dll tagged as not-a-virus:AdWare.WildTangent.b. No Action Taken.
File C:\WINDOWS\wt\wtvh.dll tagged as not-a-virus:AdWare.WildTangent.b. No Action Taken.
ewido...
---------------------------------------------------------
ewido security suite - Scan report
---------------------------------------------------------
+ Created on: 11:26:03 AM, 7/26/2005
+ Report-Checksum: 84B3E9F5
+ Scan result:
HKLM\SOFTWARE\Apropos -> Spyware.AproposMedia : Cleaned with backup
HKLM\SOFTWARE\Apropos\Client -> Spyware.AproposMedia : Cleaned with backup
HKLM\SOFTWARE\AutoLoader -> Spyware.AproposMedia : Cleaned with backup
HKLM\SOFTWARE\AutoLoader\AproposClient -> Spyware.AproposMedia : Cleaned with backup
HKLM\SOFTWARE\AutoLoader\swoa1NTLNMLM -> Spyware.AproposMedia : Cleaned with backup
HKLM\SOFTWARE\AutoLoader\swos1NTLNMLM -> Spyware.AproposMedia : Cleaned with backup
HKLM\SOFTWARE\Avenue Media -> Spyware.InternetOptimizer : Cleaned with backup
HKLM\SOFTWARE\Avenue Media\Internet Optimizer -> Spyware.InternetOptimizer : Cleaned with backup
HKLM\SOFTWARE\Avenue Media\Internet Optimizer\Browser Helper -> Spyware.InternetOptimizer : Cleaned with backup
HKLM\SOFTWARE\Classes\ADP.UrlCatcher -> Spyware.BargainBuddy : Cleaned with backup
HKLM\SOFTWARE\Classes\ADP.UrlCatcher\CLSID -> Spyware.BargainBuddy : Cleaned with backup
HKLM\SOFTWARE\Classes\CLSID\{00000010-6F7D-442C-93E3-4A4827C2E4C8} -> Spyware.InternetOptimizer : Cleaned with backup
HKLM\SOFTWARE\Classes\CLSID\{016235BE-59D4-4CEB-ADD5-E2378282A1D9} -> Spyware.AproposMedia : Cleaned with backup
HKLM\SOFTWARE\Classes\CLSID\{205FF73B-CA67-11D5-99DD-444553540006} -> Spyware.CnsMin : Cleaned with backup
HKLM\SOFTWARE\Classes\CLSID\{B5AB638F-D76C-415B-A8F2-F3CEAC502212} -> Spyware.AproposMedia : Cleaned with backup
HKLM\SOFTWARE\Classes\CLSID\{BC333116-6EA1-40A1-9D07-ECB192DB8CEA} -> Spyware.AproposMedia : Cleaned with backup
HKLM\SOFTWARE\Classes\CLSID\{F4E04583-354E-4076-BE7D-ED6A80FD66DA} -> Spyware.BargainBuddy : Cleaned with backup
HKLM\SOFTWARE\Classes\DyFuCA_BH.BHObj -> Spyware.MoneyTree : Cleaned with backup
HKLM\SOFTWARE\Classes\DyFuCA_BH.BHObj\CLSID -> Spyware.MoneyTree : Cleaned with backup
HKLM\SOFTWARE\Classes\DyFuCA_BH.BHObj\CurVer -> Spyware.MoneyTree : Cleaned with backup
HKLM\SOFTWARE\Classes\Interface\{1C01D150-91A4-4DE0-9BF8-A35D1BDF1001} -> Spyware.SafeSurfing : Cleaned with backup
HKLM\SOFTWARE\Classes\Interface\{205FF73A-CA67-11D5-99DD-444553540006} -> Spyware.CnsMin : Cleaned with backup
HKLM\SOFTWARE\Classes\Interface\{8EEE58D5-130E-4CBD-9C83-35A0564E5678} -> Spyware.BargainBuddy : Cleaned with backup
HKLM\SOFTWARE\Classes\Interface\{B548B7D8-3D03-4AED-A6A1-4251FAD00C10} -> Spyware.AproposMedia : Cleaned with backup
HKLM\SOFTWARE\Classes\Interface\{B99A727F-0782-4A71-BCC2-6E1E66414904} -> Spyware.AproposMedia : Cleaned with backup
HKLM\SOFTWARE\Classes\Interface\{BC333116-6EA1-40A1-9D07-ECB192DB8CEA} -> Spyware.AproposMedia : Cleaned with backup
HKLM\SOFTWARE\Classes\Interface\{C6906A23-4717-4E1F-B6FD-F06EBED15678} -> Spyware.BargainBuddy : Cleaned with backup
HKLM\SOFTWARE\Classes\Interface\{CABBB49A-4D7B-415B-8250-15C3B854E9FF} -> Spyware.CoolWebSearch : Cleaned with backup
HKLM\SOFTWARE\Classes\Softomate.IEToolbar -> Spyware.CoolWebSearch : Cleaned with backup
HKLM\SOFTWARE\Classes\Softomate.IEToolbar\CLSID -> Spyware.CoolWebSearch : Cleaned with backup
HKLM\SOFTWARE\Classes\Softomate.IEToolbar\CurVer -> Spyware.CoolWebSearch : Cleaned with backup
HKLM\SOFTWARE\Classes\TypeLib\{205FF72E-CA67-11D5-99DD-444553540006} -> Spyware.CnsMin : Cleaned with backup
HKLM\SOFTWARE\Classes\TypeLib\{40B1D454-9CA4-43CC-86AA-CB175EAC52FB} -> Spyware.MoneyTree : Cleaned with backup
HKLM\SOFTWARE\Classes\TypeLib\{4EB7BBE8-2E15-424B-9DDB-2CDB9516B2C3} -> Spyware.NaviSearch : Cleaned with backup
HKLM\SOFTWARE\Envolo -> Spyware.AproposMedia : Cleaned with backup
HKLM\SOFTWARE\Envolo\AutoUpdate -> Spyware.AproposMedia : Cleaned with backup
HKLM\SOFTWARE\Envolo\AutoUpdate\State -> Spyware.AproposMedia : Cleaned with backup
HKLM\SOFTWARE\Envolo\AutoUpdate\Tasks -> Spyware.AproposMedia : Cleaned with backup
HKLM\SOFTWARE\eXactUtil -> Spyware.BargainBuddy : Cleaned with backup
HKLM\SOFTWARE\Microsoft\Code Store Database\Distribution Units\{205FF73B-CA67-11D5-99DD-444553540006} -> Spyware.CnsMin : Cleaned with backup
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\AMeOpt -> Spyware.InternetOptimizer : Cleaned with backup
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\70tovmto -> Spyware.SAHA : Cleaned with backup
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\AproposClient -> Spyware.AproposMedia : Cleaned with backup
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\AutoUpdate -> Spyware.AproposMedia : Cleaned with backup
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\DyFuCA -> Spyware.MoneyTree : Cleaned with backup
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Internet Optimizer -> Spyware.InternetOptimizer : Cleaned with backup
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Kapabout -> Spyware.InternetOptimizer : Cleaned with backup
HKLM\SOFTWARE\Policies\Avenue Media -> Spyware.InternetOptimizer : Cleaned with backup
HKLM\SYSTEM\CurrentControlSet\Services\ZESOFT -> Spyware.NaviSearch : Cleaned with backup
HKLM\SYSTEM\CurrentControlSet\Services\ZESOFT\Security -> Spyware.NaviSearch : Cleaned with backup
HKLM\SYSTEM\CurrentControlSet\Services\ZESOFT\Enum -> Spyware.NaviSearch : Cleaned with backup
C:\Documents and Settings\Harriet\Cookies\
[email protected][1].txt -> Spyware.Cookie.2o7 : Cleaned with backup
C:\Documents and Settings\Harriet\Cookies\
[email protected][2].txt -> Spyware.Cookie.2o7 : Cleaned with backup
C:\Documents and Settings\Harriet\Cookies\harriet@2o7[2].txt -> Spyware.Cookie.2o7 : Cleaned with backup
C:\Documents and Settings\Harriet\Cookies\harriet@ad-logics[1].txt -> Spyware.Cookie.Ad-logics : Cleaned with backup
C:\Documents and Settings\Harriet\Cookies\
[email protected][1].txt -> Spyware.Cookie.Yieldmanager : Cleaned with backup
C:\Documents and Settings\Harriet\Cookies\
[email protected][1].txt -> Spyware.Cookie.Clickhype : Cleaned with backup
C:\Documents and Settings\Harriet\Cookies\
[email protected][2].txt -> Spyware.Cookie.Specificclick : Cleaned with backup
C:\Documents and Settings\Harriet\Cookies\
[email protected][2].txt -> Spyware.Cookie.Pointroll : Cleaned with backup
C:\Documents and Settings\Harriet\Cookies\harriet@adtech[1].txt -> Spyware.Cookie.Adtech : Cleaned with backup
C:\Documents and Settings\Harriet\Cookies\harriet@advertising[2].txt -> Spyware.Cookie.Advertising : Cleaned with backup
C:\Documents and Settings\Harriet\Cookies\harriet@adviva[1].txt -> Spyware.Cookie.Adviva : Cleaned with backup
C:\Documents and Settings\Harriet\Cookies\
[email protected][2].txt -> Spyware.Cookie.Falkag : Cleaned with backup
C:\Documents and Settings\Harriet\Cookies\
[email protected][2].txt -> Spyware.Cookie.Falkag : Cleaned with backup
C:\Documents and Settings\Harriet\Cookies\
[email protected][2].txt -> Spyware.Cookie.Falkag : Cleaned with backup
C:\Documents and Settings\Harriet\Cookies\harriet@atdmt[2].txt -> Spyware.Cookie.Atdmt : Cleaned with backup
C:\Documents and Settings\Harriet\Cookies\harriet@bfast[2].txt -> Spyware.Cookie.Bfast : Cleaned with backup
C:\Documents and Settings\Harriet\Cookies\harriet@bluestreak[1].txt -> Spyware.Cookie.Bluestreak : Cleaned with backup
C:\Documents and Settings\Harriet\Cookies\
[email protected][1].txt -> Spyware.Cookie.Serving-sys : Cleaned with backup
C:\Documents and Settings\Harriet\Cookies\harriet@burstnet[2].txt -> Spyware.Cookie.Burstnet : Cleaned with backup
C:\Documents and Settings\Harriet\Cookies\harriet@casalemedia[2].txt -> Spyware.Cookie.Casalemedia : Cleaned with backup
C:\Documents and Settings\Harriet\Cookies\harriet@centrport[1].txt -> Spyware.Cookie.Centrport : Cleaned with backup
C:\Documents and Settings\Harriet\Cookies\
[email protected][2].txt -> Spyware.Cookie.Bridgetrack : Cleaned with backup
C:\Documents and Settings\Harriet\Cookies\harriet@clickagents[2].txt -> Spyware.Cookie.Clickagents : Cleaned with backup
C:\Documents and Settings\Harriet\Cookies\
[email protected][1].txt -> Spyware.Cookie.Hitslink : Cleaned with backup
C:\Documents and Settings\Harriet\Cookies\
[email protected][1].txt -> Spyware.Cookie.Coremetrics : Cleaned with backup
C:\Documents and Settings\Harriet\Cookies\harriet@doubleclick[2].txt -> Spyware.Cookie.Doubleclick : Cleaned with backup
C:\Documents and Settings\Harriet\Cookies\
[email protected][2].txt -> Spyware.Cookie.Esomniture : Cleaned with backup
C:\Documents and Settings\Harriet\Cookies\
[email protected][2].txt -> Spyware.Cookie.Esomniture : Cleaned with backup
C:\Documents and Settings\Harriet\Cookies\
[email protected][2].txt -> Spyware.Cookie.Ru4 : Cleaned with backup
C:\Documents and Settings\Harriet\Cookies\
[email protected][2].txt -> Spyware.Cookie.Hitbox : Cleaned with backup
C:\Documents and Settings\Harriet\Cookies\
[email protected][2].txt -> Spyware.Cookie.Hitbox : Cleaned with backup
C:\Documents and Settings\Harriet\Cookies\
[email protected][2].txt -> Spyware.Cookie.Hitbox : Cleaned with backup
C:\Documents and Settings\Harriet\Cookies\
[email protected][2].txt -> Spyware.Cookie.Hitbox : Cleaned with backup
C:\Documents and Settings\Harriet\Cookies\
[email protected][1].txt -> Spyware.Cookie.Hitbox : Cleaned with backup
C:\Documents and Settings\Harriet\Cookies\
[email protected][1].txt -> Spyware.Cookie.Hitbox : Cleaned with backup
C:\Documents and Settings\Harriet\Cookies\
[email protected][2].txt -> Spyware.Cookie.Hitbox : Cleaned with backup
C:\Documents and Settings\Harriet\Cookies\
[email protected][1].txt -> Spyware.Cookie.Hitbox : Cleaned with backup
C:\Documents and Settings\Harriet\Cookies\
[email protected][2].txt -> Spyware.Cookie.Hitbox : Cleaned with backup
C:\Documents and Settings\Harriet\Cookies\
[email protected][2].txt -> Spyware.Cookie.Hitbox : Cleaned with backup
C:\Documents and Settings\Harriet\Cookies\harriet@euniverseads[2].txt -> Spyware.Cookie.Euniverseads : Cleaned with backup
C:\Documents and Settings\Harriet\Cookies\harriet@fastclick[2].txt -> Spyware.Cookie.Fastclick : Cleaned with backup
C:\Documents and Settings\Harriet\Cookies\
[email protected][1].txt -> Spyware.Cookie.Hitbox : Cleaned with backup
C:\Documents and Settings\Harriet\Cookies\harriet@hitbox[1].txt -> Spyware.Cookie.Hitbox : Cleaned with backup
C:\Documents and Settings\Harriet\Cookies\harriet@hypertracker[1].txt -> Spyware.Cookie.Hypertracker : Cleaned with backup
C:\Documents and Settings\Harriet\Cookies\harriet@linksynergy[1].txt -> Spyware.Cookie.Linksynergy : Cleaned with backup
C:\Documents and Settings\Harriet\Cookies\harriet@mediaplex[1].txt -> Spyware.Cookie.Mediaplex : Cleaned with backup
C:\Documents and Settings\Harriet\Cookies\
[email protected][1].txt -> Spyware.Cookie.Valueclick : Cleaned with backup
C:\Documents and Settings\Harriet\Cookies\harriet@overture[2].txt -> Spyware.Cookie.Overture : Cleaned with backup
C:\Documents and Settings\Harriet\Cookies\
[email protected][1].txt -> Spyware.Cookie.Overture : Cleaned with backup
C:\Documents and Settings\Harriet\Cookies\harriet@pro-market[2].txt -> Spyware.Cookie.Pro-market : Cleaned with backup
C:\Documents and Settings\Harriet\Cookies\harriet@qksrv[2].txt -> Spyware.Cookie.Qksrv : Cleaned with backup
C:\Documents and Settings\Harriet\Cookies\harriet@questionmarket[2].txt -> Spyware.Cookie.Questionmarket : Cleaned with backup
C:\Documents and Se