|
Need Help
|
|
Clamp1
Newbie
|
18. October 2006 @ 13:44 |
Link to this message
|
Hi
Can anyone help me remove some vius. Thanks. Heres my HijackThis log.
Logfile of HijackThis v1.99.1
Scan saved at 5:41:27 PM, on 10/18/2006
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\MMediaCodec\pmsngr.exe
C:\Program Files\MMediaCodec\isamonitor.exe
C:\WINDOWS\system32\hkcmd.exe
C:\Program Files\Lexmark 2300 Series\ezprint.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\Program Files\QuickTime\qttask.exe
C:\Program Files\Java\jre1.5.0_06\bin\jusched.exe
C:\Program Files\MMediaCodec\pmmon.exe
C:\Program Files\MMediaCodec\isamini.exe
C:\Program Files\Webroot\Spy Sweeper\SpySweeperUI.exe
C:\Program Files\AntiVermins\AntiVermins.exe
C:\Program Files\CA\eTrust EZ Armor\eTrust Anti-Spam\QSP-2.1.215.5\QOELoader.exe
C:\Program Files\CA\eTrust EZ Armor\eTrust EZ Antivirus\CAVTray.exe
C:\Program Files\CA\eTrust EZ Armor\eTrust EZ Antivirus\CAVRID.exe
C:\Program Files\CA\eTrust EZ Armor\eTrust EZ Firewall\ca.exe
C:\Program Files\AntiVermins\AntiVermins.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Messenger\msmsgs.exe
C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe
C:\Program Files\America Online 9.0d\aoltray.exe
C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
C:\Program Files\Updates from HP\309731\Program\Updates from HP.exe
C:\Program Files\Sony\Sony Picture Utility\VolumeWatcher\SPUVolumeWatcher.exe
C:\Program Files\CA\eTrust EZ Armor\eTrust EZ Antivirus\ISafe.exe
c:\Program Files\Common Files\LightScribe\LSSrvc.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\WINDOWS\system32\HPZipm12.exe
C:\WINDOWS\system32\tcpsvcs.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\ZoneLabs\vsmon.exe
C:\Program Files\Webroot\Spy Sweeper\SpySweeper.exe
c:\Program Files\Common Files\Symantec Shared\Security Center\SymWSC.exe
C:\WINDOWS\system32\lxcgcoms.exe
C:\Program Files\CA\eTrust EZ Armor\eTrust EZ Antivirus\VetMsg.exe
C:\Program Files\Google\GoogleToolbarNotifier\1.2.908.5008\GoogleToolbarNotifier.exe
C:\HP\KBD\KBD.EXE
C:\WINDOWS\SOUNDMAN.EXE
C:\WINDOWS\ALCMTR.EXE
C:\WINDOWS\ALCWZRD.EXE
C:\WINDOWS\AGRSMMSG.exe
c:\windows\system\hpsysdrv.exe
C:\WINDOWS\system32\hphmon06.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\PROGRA~1\Yahoo!\COMPAN~1\Installs\cpn1\YTBSDK.exe
C:\Program Files\Webroot\Spy Sweeper\SSU.EXE
C:\Documents and Settings\HP_Owner\Desktop\HijackThis_v1.99.1.exe
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://ie.redirect.hp.com/svs/rdr?TYPE=3...lion&pf=desktop
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://ie.redirect.hp.com/svs/rdr?TYPE=3...lion&pf=desktop
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.rr.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://ie.redirect.hp.com/svs/rdr?TYPE=3...lion&pf=desktop
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://ie.redirect.hp.com/svs/rdr?TYPE=3...lion&pf=desktop
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://ie.redirect.hp.com/svs/rdr?TYPE=3...lion&pf=desktop
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://ie.redirect.hp.com/svs/rdr?TYPE=3...lion&pf=desktop
R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://ie.redirect.hp.com/svs/rdr?TYPE=3...lion&pf=desktop
R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn1\yt.dll
F2 - REG:system.ini: Shell=Explorer.exe,
F2 - REG:system.ini: UserInit=C:\WINDOWS\system32\userinit.exe,cfcqyjv.exe
O2 - BHO: Yahoo! Toolbar Helper - {02478D38-C3F9-4EFB-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn1\yt.dll
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar5.dll
O2 - BHO: (no name) - {d869742a-e5d2-4624-96c7-aae26170665e} - C:\Program Files\MMediaCodec\isaddon.dll
O3 - Toolbar: HP view - {B2847E28-5D7D-4DEB-8B67-05D28BCF79F5} - c:\Program Files\HP\Digital Imaging\bin\HPDTLK02.dll
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn1\yt.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar5.dll
O3 - Toolbar: Protection Bar - {44d22a64-2399-4edf-8b32-f2c729c1e8a7} - C:\Program Files\MMediaCodec\iesplugin.dll
O4 - HKLM\..\Run: [High Definition Audio Property Page Shortcut] HDAudPropShortcut.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\system32\hkcmd.exe
O4 - HKLM\..\Run: [HPBootOp] "C:\Program Files\Hewlett-Packard\HP Boot Optimizer\HPBootOp.exe" /run
O4 - HKLM\..\Run: [_SetRes] c:\hp\bin\cloaker c:\hp\bin\res.bat
O4 - HKLM\..\Run: [IcoSet] "c:\hp\bin\cloaker.exe" c:\hp\bin\IcoSet\adjust.bat seticon
O4 - HKLM\..\Run: [LSBWatcher] c:\hp\drivers\hplsbwatcher\lsburnwatcher.exe
O4 - HKLM\..\Run: [lxcgmon.exe] "C:\Program Files\Lexmark 2300 Series\lxcgmon.exe"
O4 - HKLM\..\Run: [EzPrint] "C:\Program Files\Lexmark 2300 Series\ezprint.exe"
O4 - HKLM\..\Run: [FaxCenterServer] "C:\Program Files\Lexmark Fax Solutions\fm3032.exe" /s
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.5.0_06\bin\jusched.exe"
O4 - HKLM\..\Run: [LXCGCATS] rundll32 C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\LXCGtime.dll,_RunDLLEntry@16
O4 - HKLM\..\Run: [SpySweeper] "C:\Program Files\Webroot\Spy Sweeper\SpySweeperUI.exe" /startintray
O4 - HKLM\..\Run: [AntiVermins] "C:\Program Files\AntiVermins\AntiVermins.exe" /h
O4 - HKLM\..\Run: [QOELOADER] "C:\Program Files\CA\eTrust EZ Armor\eTrust Anti-Spam\QSP-2.1.215.5\QOELoader.exe"
O4 - HKLM\..\Run: [CaAvTray] "C:\Program Files\CA\eTrust EZ Armor\eTrust EZ Antivirus\CAVTray.exe"
O4 - HKLM\..\Run: [CAVRID] "C:\Program Files\CA\eTrust EZ Armor\eTrust EZ Antivirus\CAVRID.exe"
O4 - HKLM\..\Run: [Zone Labs Client] "C:\Program Files\CA\eTrust EZ Armor\eTrust EZ Firewall\ca.exe"
O4 - HKLM\..\Run: [ariboc] C:\WINDOWS\system32\baejoe.exe reg_run
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [swg] "C:\Program Files\Google\GoogleToolbarNotifier\1.0.720.3640\GoogleToolbarNotifier.exe"
O4 - HKCU\..\Run: [wopcp] C:\WINDOWS\system32\baejoe.exe reg_run
O4 - Startup: Cyber-shot Viewer Media Check Tool.lnk = C:\Program Files\Sony\Sony Picture Utility\VolumeWatcher\SPUVolumeWatcher.exe
O4 - Startup: HP Organize.lnk = ?
O4 - Global Startup: America Online 9.0 Tray Icon.lnk = C:\Program Files\America Online 9.0d\aoltray.exe
O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
O4 - Global Startup: SpySubtract.lnk = C:\Program Files\InterMute\SpySubtract\sslaunch.exe
O4 - Global Startup: Updates from HP.lnk = C:\Program Files\Updates from HP\309731\Program\Updates from HP.exe
O8 - Extra context menu item: &Search - http://kl.bar.need2find.com/KL/menusearch.html?p=KL
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MI1933~1\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MI1933~1\OFFICE11\REFIEBAR.DLL
O9 - Extra button: Connection Help - {E2D4D26B-0180-43a4-B05F-462D6D54C789} - C:\WINDOWS\PCHEALTH\HELPCTR\Vendors\CN=Hewlett-Packard,L=Cupertino,S=Ca,C=US\IEButton\support.htm
O9 - Extra 'Tools' menuitem: Connection Help - {E2D4D26B-0180-43a4-B05F-462D6D54C789} - C:\WINDOWS\PCHEALTH\HELPCTR\Vendors\CN=Hewlett-Packard,L=Cupertino,S=Ca,C=US\IEButton\support.htm
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra button: Connection Help - {E2D4D26B-0180-43a4-B05F-462D6D54C789} - C:\WINDOWS\PCHEALTH\HELPCTR\Vendors\CN=Hewlett-Packard,L=Cupertino,S=Ca,C=US\IEButton\support.htm (HKCU)
O9 - Extra 'Tools' menuitem: Connection Help - {E2D4D26B-0180-43a4-B05F-462D6D54C789} - C:\WINDOWS\PCHEALTH\HELPCTR\Vendors\CN=Hewlett-Packard,L=Cupertino,S=Ca,C=US\IEButton\support.htm (HKCU)
O15 - Trusted Zone: ww.rr.com
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?LinkID=39204
O20 - Winlogon Notify: igfxcui - C:\WINDOWS\SYSTEM32\igfxsrvc.dll
O20 - Winlogon Notify: WRNotifier - C:\WINDOWS\SYSTEM32\WRLogonNTF.dll
O20 - Winlogon Notify: yvbb01 - yvbb01.dll (file missing)
O20 - Winlogon Notify: yvpp01 - C:\WINDOWS\SYSTEM32\yvpp01.dll
O21 - SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll
O21 - SSODL: contrabandists - {dfa61db1-388e-4c87-8d56-540fa229bcb4} - C:\WINDOWS\system32\dpfwu.dll (file missing)
O23 - Service: Automatic LiveUpdate Scheduler - Symantec Corporation - C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe
O23 - Service: CAISafe - Computer Associates International, Inc. - C:\Program Files\CA\eTrust EZ Armor\eTrust EZ Antivirus\ISafe.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe
O23 - Service: iPod Service (iPodService) - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - c:\Program Files\Common Files\LightScribe\LSSrvc.exe
O23 - Service: LiveUpdate - Symantec Corporation - C:\PROGRA~1\Symantec\LIVEUP~1\LUCOMS~1.EXE
O23 - Service: lxcg_device - - C:\WINDOWS\system32\lxcgcoms.exe
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe
O23 - Service: SymWMI Service (SymWSC) - Symantec Corporation - c:\Program Files\Common Files\Symantec Shared\Security Center\SymWSC.exe
O23 - Service: VET Message Service (VETMSGNT) - Computer Associates International, Inc. - C:\Program Files\CA\eTrust EZ Armor\eTrust EZ Antivirus\VetMsg.exe
O23 - Service: TrueVector Internet Monitor (vsmon) - Zone Labs Inc. - C:\WINDOWS\system32\ZoneLabs\vsmon.exe
O23 - Service: Webroot Spy Sweeper Engine (WebrootSpySweeperService) - Webroot Software, Inc. - C:\Program Files\Webroot\Spy Sweeper\SpySweeper.exe
|
Advertisement
|
  |
|
Senior Member
|
19. October 2006 @ 19:49 |
Link to this message
|
Hello Clamp1, there is alot of infected files. Please follow these instructions as posted. If you run into a problem with one of the fixes please come back and ask before moving to next step.
Step 1:
Download haxfix.exe from here and save it to your desktop.
Download SmitfraudFix.zip from here and unzip it to your desktop. Do not run it yet, will later in safe mode.
Download the trial version of AVG Anti-spyware from here. Do not install it yet, will after running haxfix.
Step 2:
Please diable SpySweeper's Shields becasue it may interfere with our fixes.
Open SpySweeper.
Click Shield Settings on the right
(or Shields on the left, depending what screen you're on).
Click Internet Explorer and uncheck all items.
Click Windows System and uncheck all items.
Click Hosts File and uncheck all items.
Click Startup Programs and uncheck all items.
Close SpySweeper.
Step 3:
* Double click on haxfix.exe to install it.
* Checkmark "Create a desktop icon".
* Click "Next".
* When the installation is completed, make sure that the checkmark "Launch HaxFix" is placed.
* Click "Finish".
A red "dos window" (dos box) will open with options:
1. Make logfile
2. Run auto fix
3. Run manual fix
E. Exit Haxfix
* Select option 2. Run auto fix by typing 2 and then pressing Enter.
If an infection is found, you'll get a message to close all other open windows.
* Close all open windows except the red dos window from haxfix and then press Enter.
* The computer will reboot.
* After reboot a logfile will open > (c:\haxfix.txt) save and close it.
Step 4:
Note: Print or copy these instructions to Notepad and save them. You will be in safe mode and can't acces the internet.
Install and update AVGAS.
Restart your computer in safe mode(press F8 upon boot, select "Safe Mode" from menu and press Enter).
* Open the SmitfraudFix folder.
* Double-click smitfraudfix.cmd
* Select 2 and hit Enter to delete infect files.
* You will be prompted: Do you want to clean the registry ? answer Y (yes) and hit Enter in order to remove the Desktop background and clean registry keys associated with the infection.
* The tool will now check if wininet.dll is infected. You may be prompted to replace the infected file (if found): Replace infected file ? answer Y (yes) and hit Enter to restore a clean file.
* A reboot may be needed to finish the cleaning process. The report can be found at the root of the system drive, usually at C:\rapport.txt.
* Exit SmitfraudFix.
Step 5:
* Open AVG AS and click "Scanner".
* Click "Complete System Scan".
* When it finishes scanning, set all items to "Quarantine".
* Click "Apply All Actions".
* Click "Save Report".
* Click "Save report as" and save it to the desktop.
* Exit AVGAS and restart in normal mode.
Step 6:
Run a new scan with HijackThis and save a new log.
Please post back with the Haxfix log, the SmitfraudFix log, the AVGAS report, and a new HijackThis log.
|
Clamp1
Newbie
|
21. October 2006 @ 13:56 |
Link to this message
|
Thank for helping me Niobis. I realy thank you. Here is the HijackThis log.
Logfile of HijackThis v1.99.1
Scan saved at 5:25:46 PM, on 10/21/2006
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\hkcmd.exe
C:\Program Files\Hewlett-Packard\HP Boot Optimizer\HPBootOp.exe
C:\Program Files\Lexmark 2300 Series\ezprint.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\Program Files\QuickTime\qttask.exe
C:\Program Files\Java\jre1.5.0_06\bin\jusched.exe
C:\Program Files\Webroot\Spy Sweeper\SpySweeperUI.exe
C:\Program Files\CA\eTrust EZ Armor\eTrust Anti-Spam\QSP-2.1.215.5\QOELoader.exe
C:\Program Files\CA\eTrust EZ Armor\eTrust EZ Antivirus\CAVTray.exe
C:\Program Files\CA\eTrust EZ Armor\eTrust EZ Antivirus\CAVRID.exe
C:\Program Files\CA\eTrust EZ Armor\eTrust EZ Firewall\ca.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Messenger\msmsgs.exe
C:\Program Files\America Online 9.0d\aoltray.exe
C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe
C:\Program Files\Updates from HP\309731\Program\Updates from HP.exe
C:\Program Files\Sony\Sony Picture Utility\VolumeWatcher\SPUVolumeWatcher.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
C:\Program Files\CA\eTrust EZ Armor\eTrust EZ Antivirus\ISafe.exe
c:\Program Files\Common Files\LightScribe\LSSrvc.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\WINDOWS\system32\HPZipm12.exe
C:\WINDOWS\system32\tcpsvcs.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\CA\eTrust EZ Armor\eTrust EZ Antivirus\VetMsg.exe
C:\WINDOWS\system32\ZoneLabs\vsmon.exe
C:\Program Files\Webroot\Spy Sweeper\SpySweeper.exe
c:\Program Files\Common Files\Symantec Shared\Security Center\SymWSC.exe
C:\WINDOWS\system32\lxcgcoms.exe
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\Program Files\Google\GoogleToolbarNotifier\1.2.908.5008\GoogleToolbarNotifier.exe
C:\PROGRA~1\Yahoo!\COMPAN~1\Installs\cpn1\YTBSDK.exe
C:\HP\KBD\KBD.EXE
C:\WINDOWS\SOUNDMAN.EXE
C:\WINDOWS\ALCMTR.EXE
C:\WINDOWS\system32\NOTEPAD.EXE
C:\WINDOWS\ALCWZRD.EXE
C:\WINDOWS\AGRSMMSG.exe
c:\windows\system\hpsysdrv.exe
C:\WINDOWS\system32\hphmon06.exe
C:\Documents and Settings\HP_Owner\Desktop\HijackThis_v1.99.1.exe
R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://ie.redirect.hp.com/svs/rdr?TYPE=3...lion&pf=desktop
R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn1\yt.dll
F2 - REG:system.ini: UserInit=C:\WINDOWS\system32\userinit.exe,cfcqyjv.exe
O2 - BHO: Yahoo! Toolbar Helper - {02478D38-C3F9-4EFB-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn1\yt.dll
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar5.dll
O3 - Toolbar: HP view - {B2847E28-5D7D-4DEB-8B67-05D28BCF79F5} - c:\Program Files\HP\Digital Imaging\bin\HPDTLK02.dll
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn1\yt.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar5.dll
O4 - HKLM\..\Run: [High Definition Audio Property Page Shortcut] HDAudPropShortcut.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\system32\hkcmd.exe
O4 - HKLM\..\Run: [HPBootOp] "C:\Program Files\Hewlett-Packard\HP Boot Optimizer\HPBootOp.exe" /run
O4 - HKLM\..\Run: [_SetRes] c:\hp\bin\cloaker c:\hp\bin\res.bat
O4 - HKLM\..\Run: [IcoSet] "c:\hp\bin\cloaker.exe" c:\hp\bin\IcoSet\adjust.bat seticon
O4 - HKLM\..\Run: [LSBWatcher] c:\hp\drivers\hplsbwatcher\lsburnwatcher.exe
O4 - HKLM\..\Run: [lxcgmon.exe] "C:\Program Files\Lexmark 2300 Series\lxcgmon.exe"
O4 - HKLM\..\Run: [EzPrint] "C:\Program Files\Lexmark 2300 Series\ezprint.exe"
O4 - HKLM\..\Run: [FaxCenterServer] "C:\Program Files\Lexmark Fax Solutions\fm3032.exe" /s
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.5.0_06\bin\jusched.exe"
O4 - HKLM\..\Run: [LXCGCATS] rundll32 C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\LXCGtime.dll,_RunDLLEntry@16
O4 - HKLM\..\Run: [SpySweeper] "C:\Program Files\Webroot\Spy Sweeper\SpySweeperUI.exe" /startintray
O4 - HKLM\..\Run: [QOELOADER] "C:\Program Files\CA\eTrust EZ Armor\eTrust Anti-Spam\QSP-2.1.215.5\QOELoader.exe"
O4 - HKLM\..\Run: [CaAvTray] "C:\Program Files\CA\eTrust EZ Armor\eTrust EZ Antivirus\CAVTray.exe"
O4 - HKLM\..\Run: [CAVRID] "C:\Program Files\CA\eTrust EZ Armor\eTrust EZ Antivirus\CAVRID.exe"
O4 - HKLM\..\Run: [Zone Labs Client] "C:\Program Files\CA\eTrust EZ Armor\eTrust EZ Firewall\ca.exe"
O4 - HKLM\..\Run: [ariboc] C:\WINDOWS\system32\baejoe.exe reg_run
O4 - HKLM\..\Run: [!AVG Anti-Spyware] "C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" /minimized
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [swg] "C:\Program Files\Google\GoogleToolbarNotifier\1.0.720.3640\GoogleToolbarNotifier.exe"
O4 - HKCU\..\Run: [wopcp] C:\WINDOWS\system32\baejoe.exe reg_run
O4 - Startup: Cyber-shot Viewer Media Check Tool.lnk = C:\Program Files\Sony\Sony Picture Utility\VolumeWatcher\SPUVolumeWatcher.exe
O4 - Startup: HP Organize.lnk = ?
O4 - Global Startup: America Online 9.0 Tray Icon.lnk = C:\Program Files\America Online 9.0d\aoltray.exe
O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
O4 - Global Startup: SpySubtract.lnk = C:\Program Files\InterMute\SpySubtract\sslaunch.exe
O4 - Global Startup: Updates from HP.lnk = C:\Program Files\Updates from HP\309731\Program\Updates from HP.exe
O8 - Extra context menu item: &Search - http://kl.bar.need2find.com/KL/menusearch.html?p=KL
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MI1933~1\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MI1933~1\OFFICE11\REFIEBAR.DLL
O9 - Extra button: Connection Help - {E2D4D26B-0180-43a4-B05F-462D6D54C789} - C:\WINDOWS\PCHEALTH\HELPCTR\Vendors\CN=Hewlett-Packard,L=Cupertino,S=Ca,C=US\IEButton\support.htm
O9 - Extra 'Tools' menuitem: Connection Help - {E2D4D26B-0180-43a4-B05F-462D6D54C789} - C:\WINDOWS\PCHEALTH\HELPCTR\Vendors\CN=Hewlett-Packard,L=Cupertino,S=Ca,C=US\IEButton\support.htm
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra button: Connection Help - {E2D4D26B-0180-43a4-B05F-462D6D54C789} - C:\WINDOWS\PCHEALTH\HELPCTR\Vendors\CN=Hewlett-Packard,L=Cupertino,S=Ca,C=US\IEButton\support.htm (HKCU)
O9 - Extra 'Tools' menuitem: Connection Help - {E2D4D26B-0180-43a4-B05F-462D6D54C789} - C:\WINDOWS\PCHEALTH\HELPCTR\Vendors\CN=Hewlett-Packard,L=Cupertino,S=Ca,C=US\IEButton\support.htm (HKCU)
O15 - Trusted Zone: ww.rr.com
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?LinkID=39204
O20 - Winlogon Notify: igfxcui - C:\WINDOWS\SYSTEM32\igfxsrvc.dll
O20 - Winlogon Notify: WRNotifier - C:\WINDOWS\SYSTEM32\WRLogonNTF.dll
O20 - Winlogon Notify: yvbb01 - yvbb01.dll (file missing)
O21 - SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll
O23 - Service: Automatic LiveUpdate Scheduler - Symantec Corporation - C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe
O23 - Service: AVG Anti-Spyware Guard - Anti-Malware Development a.s. - C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
O23 - Service: CAISafe - Computer Associates International, Inc. - C:\Program Files\CA\eTrust EZ Armor\eTrust EZ Antivirus\ISafe.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe
O23 - Service: iPod Service (iPodService) - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - c:\Program Files\Common Files\LightScribe\LSSrvc.exe
O23 - Service: LiveUpdate - Symantec Corporation - C:\PROGRA~1\Symantec\LIVEUP~1\LUCOMS~1.EXE
O23 - Service: lxcg_device - - C:\WINDOWS\system32\lxcgcoms.exe
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe
O23 - Service: SymWMI Service (SymWSC) - Symantec Corporation - c:\Program Files\Common Files\Symantec Shared\Security Center\SymWSC.exe
O23 - Service: VET Message Service (VETMSGNT) - Computer Associates International, Inc. - C:\Program Files\CA\eTrust EZ Armor\eTrust EZ Antivirus\VetMsg.exe
O23 - Service: TrueVector Internet Monitor (vsmon) - Zone Labs Inc. - C:\WINDOWS\system32\ZoneLabs\vsmon.exe
O23 - Service: Webroot Spy Sweeper Engine (WebrootSpySweeperService) - Webroot Software, Inc. - C:\Program Files\Webroot\Spy Sweeper\SpySweeper.exe
|
Clamp1
Newbie
|
21. October 2006 @ 14:00 |
Link to this message
|
Here is the Smitfraudfix log
SmitFraudFix v2.112
Scan done at 15:53:00.42, Sat 10/21/2006
Run from C:\Documents and Settings\HP_Owner\Desktop\SmitfraudFix
OS: Microsoft Windows XP [Version 5.1.2600] - Windows_NT
Fix run in safe mode
»»»»»»»»»»»»»»»»»»»»»»»» Before SmitFraudFix
!!!Attention, following keys are not inevitably infected!!!
SrchSTS.exe by S!Ri
Search SharedTaskScheduler's .dll
»»»»»»»»»»»»»»»»»»»»»»»» Killing process
»»»»»»»»»»»»»»»»»»»»»»»» Generic Renos Fix
GenericRenosFix by S!Ri
»»»»»»»»»»»»»»»»»»»»»»»» Deleting infected files
»»»»»»»»»»»»»»»»»»»»»»»» Deleting Temp Files
»»»»»»»»»»»»»»»»»»»»»»»» Registry Cleaning
Registry Cleaning done.
»»»»»»»»»»»»»»»»»»»»»»»» After SmitFraudFix
!!!Attention, following keys are not inevitably infected!!!
SrchSTS.exe by S!Ri
Search SharedTaskScheduler's .dll
»»»»»»»»»»»»»»»»»»»»»»»» End
|
Clamp1
Newbie
|
21. October 2006 @ 14:03 |
Link to this message
|
Here is the Haxfix log
HAXFIX logfile - by Marckie
--------------
version 4.25
Sat 10/21/2006 15:21:14.15
--- Auto Haxdoorfix ---
searching for files:
yvpp01.dll
no infections found
--- Goldunfix ---
searching for files:
searching for SSODLkeys:
no SSODLkeys found
searching for notifykeys:
no notifykeys found
searching for services:
no services found
.....rebooting the computer.....
searching for ssodlkeys
not needed
searching for notifykeys
notifykey yvpp01 not found
searching for services
not needed
searching for safeboot services
not needed
searching for files
yvpp01.dll exists
deleting yvpp01.dll
yvpp01.dll has been deleted
checking for other files
No other files found
checking for a3d files
no a3d files found
Finished
|
Clamp1
Newbie
|
21. October 2006 @ 14:11 |
Link to this message
|
This message has been edited since posting. Last time this message was edited on 22. October 2006 @ 09:04
|
Senior Member
|
21. October 2006 @ 14:23 |
Link to this message
|
Good! Now, let's get rid of Qoologic.
First, turn off SpySweeper's Shields becasue it may interfere with the fixes. Please leave them off until we know you're clean.
Open SpySweeper.
Click Shield Settings on the right
(or Shields on the left, depending what screen you're on).
Click Internet Explorer and uncheck all items.
Click Windows System and uncheck all items.
Click Hosts File and uncheck all items.
Click Startup Programs and uncheck all items.
Close SpySweeper.
Download Brute Force Uninstaller to your desktop.
* Right click the BFU folder on your desktop, and choose Extract All
* Click "Next"
* In the box to choose where to extract the files to,
* Click "Browse"
* Click on the + sign next to "My Computer"
* Click on "Local Disk (C:)
* Click "Make New Folder"
* Type in BFU
* Click "Next", and Uncheck the "Show Extracted Files" box and then click "Finish".
* Download qoofix.bat
* Place qoofix.bat in your C:\BFU - folder. (Important!)
* Double click qooFix.bat, close all windows.
* Choose option 1 (Qoolfix autofix) and follow the prompts.
* Please be patient, it will take about five minutes.
* After the PC has restarted run a new scan with HijackThis and post the new log.
Edit: forgot to post the SpySweeper instructions.
This message has been edited since posting. Last time this message was edited on 21. October 2006 @ 14:36
|
Clamp1
Newbie
|
21. October 2006 @ 14:27 |
Link to this message
|
Hey Niobis
By mistake I Posted HijackThis and Haxfix Two times sorry about that and the AVGAS report is in the end
|
Senior Member
|
21. October 2006 @ 14:36 |
Link to this message
|
It's ok. You can edit them if you like. Just click the paper icon at the top right of the post.
|
Clamp1
Newbie
|
21. October 2006 @ 14:42 |
Link to this message
|
Here is the AVGAS report
---------------------------------------------------------
AVG Anti-Spyware - Scan Report
---------------------------------------------------------
+ Created at: 5:16:00 PM 10/21/2006
+ Scan result:
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP14\A0010174.dll -> Adware.Altnet : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP14\A0010175.dll -> Adware.Altnet : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP14\A0010176.exe -> Adware.Altnet : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP14\A0010178.dll -> Adware.Altnet : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP14\A0010179.dll -> Adware.Altnet : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP14\A0010180.dll -> Adware.Altnet : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP14\A0010184.exe -> Adware.Altnet : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP14\A0010191.exe -> Adware.Altnet : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP14\A0010330.exe -> Adware.Altnet : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP19\A0023181.exe -> Adware.AntiVermins : Cleaned with backup (quarantined).
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\\AntiVermins -> Adware.AntiVermins : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP14\A0010145.exe -> Adware.Bestofer : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP14\A0010164.exe -> Adware.Bestofer : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP14\A0010365.exe -> Adware.DriveCleaner : Cleaned with backup (quarantined).
C:\Documents and Settings\HP_Owner\Start Menu\Play Poker Online!.lnk -> Adware.Generic : Cleaned with backup (quarantined).
HKU\S-1-5-21-1247291417-125273098-3146600013-1009\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{44D22A64-2399-4EDF-8B32-F2C729C1E8A7} -> Adware.HQVideoCodec : Cleaned with backup (quarantined).
HKU\S-1-5-21-1247291417-125273098-3146600013-1009\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{D869742A-E5D2-4624-96C7-AAE26170665E} -> Adware.HQVideoCodec : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP13\A0010135.DLL -> Adware.IESearch : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP14\A0010207.DLL -> Adware.IESearch : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP14\A0010234.dll -> Adware.IESearch : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP19\A0023061.exe -> Adware.Malwarewipe : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP19\A0023071.exe -> Adware.Malwarewipe : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP14\A0010153.exe -> Adware.P2PNet : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP0\A0000059.exe -> Backdoor.EggDrop.v : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP1\A0000504.exe -> Backdoor.EggDrop.v : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP1\A0000525.exe -> Backdoor.EggDrop.v : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP1\A0000637.exe -> Backdoor.EggDrop.v : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP1\A0000679.exe -> Backdoor.EggDrop.v : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP1\A0000707.exe -> Backdoor.EggDrop.v : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP1\A0000742.exe -> Backdoor.EggDrop.v : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP1\A0000873.exe -> Backdoor.EggDrop.v : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP1\A0000907.exe -> Backdoor.EggDrop.v : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP5\A0001023.exe -> Backdoor.EggDrop.v : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP5\A0001175.exe -> Backdoor.EggDrop.v : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP8\A0001885.exe -> Backdoor.EggDrop.v : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP8\A0001903.exe -> Backdoor.EggDrop.v : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0002372.exe -> Backdoor.EggDrop.v : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0002503.exe -> Backdoor.EggDrop.v : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0002545.exe -> Backdoor.EggDrop.v : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0004245.exe -> Backdoor.EggDrop.v : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP18\A0015940.sys -> Backdoor.Haxdoor.kl : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP18\A0015964.sys -> Backdoor.Haxdoor.kl : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP18\A0016036.sys -> Backdoor.Haxdoor.kl : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP18\A0016062.sys -> Backdoor.Haxdoor.kl : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP19\A0018963.sys -> Backdoor.Haxdoor.kl : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP19\A0019003.sys -> Backdoor.Haxdoor.kl : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP19\A0019012.sys -> Backdoor.Haxdoor.kl : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP19\A0023060.sys -> Backdoor.Haxdoor.kl : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0004207.exe -> Downloader.Adload.ds : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0004208.exe -> Downloader.Adload.ds : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0004209.exe -> Downloader.Adload.ds : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0004211.exe -> Downloader.Adload.ds : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0004212.exe -> Downloader.Agent.aaf : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0004214.exe -> Downloader.Agent.aaf : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0002781.exe -> Downloader.Agent.ala : Cleaned with backup (quarantined).
C:\data -> Downloader.IstBar.nh : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0004204.exe -> Downloader.Qoologic.at : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP18\A0015923.dll -> Downloader.Qoologic.bj : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP18\A0016021.dll -> Downloader.Qoologic.bj : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP19\A0016212.dll -> Downloader.Qoologic.bj : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP19\A0017323.dll -> Downloader.Qoologic.bj : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP19\A0017324.exe -> Downloader.Qoologic.bj : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP19\A0019005.exe -> Downloader.Qoologic.bj : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP19\A0019010.exe -> Downloader.Qoologic.bj : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP19\A0019011.exe -> Downloader.Qoologic.bj : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP18\A0015925.exe -> Downloader.Small : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP18\A0015963.exe -> Downloader.Small : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0004188.exe -> Downloader.Small : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0004189.exe -> Downloader.Small : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0004201.dll -> Downloader.Small.ctp : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0002775.exe -> Downloader.Small.cyh : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0004192.exe -> Downloader.TSUpdate.f : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0004196.exe -> Downloader.TSUpdate.l : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0004193.exe -> Downloader.TSUpdate.n : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0004194.exe -> Downloader.TSUpdate.r : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP10\A0005714.exe -> Downloader.VB.aga : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0004210.exe -> Downloader.VB.agk : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0004198.exe -> Downloader.VB.aiy : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP19\A0017151.dll -> Downloader.Zlob.apu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP19\A0017152.exe -> Downloader.Zlob.apu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP19\A0017153.exe -> Downloader.Zlob.apu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP19\A0017165.dll -> Downloader.Zlob.apu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP19\A0017166.exe -> Downloader.Zlob.apu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP19\A0017167.exe -> Downloader.Zlob.apu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP19\A0017180.dll -> Downloader.Zlob.apu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP19\A0017181.exe -> Downloader.Zlob.apu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP19\A0017182.exe -> Downloader.Zlob.apu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP19\A0018997.dll -> Downloader.Zlob.apu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP19\A0018998.exe -> Downloader.Zlob.apu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP19\A0018999.exe -> Downloader.Zlob.apu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP19\A0019022.dll -> Downloader.Zlob.apu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP19\A0019023.exe -> Downloader.Zlob.apu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP19\A0019024.exe -> Downloader.Zlob.apu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP19\A0020023.dll -> Downloader.Zlob.apu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP19\A0020024.exe -> Downloader.Zlob.apu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP19\A0020025.exe -> Downloader.Zlob.apu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP19\A0021022.dll -> Downloader.Zlob.apu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP19\A0021023.exe -> Downloader.Zlob.apu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP19\A0021024.exe -> Downloader.Zlob.apu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP19\A0022022.dll -> Downloader.Zlob.apu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP19\A0022023.exe -> Downloader.Zlob.apu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP19\A0022024.exe -> Downloader.Zlob.apu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP19\A0022041.dll -> Downloader.Zlob.apu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP19\A0022042.exe -> Downloader.Zlob.apu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP19\A0022043.exe -> Downloader.Zlob.apu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP19\A0023041.dll -> Downloader.Zlob.apu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP19\A0023042.exe -> Downloader.Zlob.apu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP19\A0023043.exe -> Downloader.Zlob.apu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP19\A0023087.dll -> Downloader.Zlob.apu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP19\A0023088.exe -> Downloader.Zlob.apu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP19\A0023089.exe -> Downloader.Zlob.apu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP19\A0023111.dll -> Downloader.Zlob.apu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP19\A0023112.exe -> Downloader.Zlob.apu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP19\A0023113.exe -> Downloader.Zlob.apu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP19\A0023136.dll -> Downloader.Zlob.apu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP19\A0023137.exe -> Downloader.Zlob.apu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP19\A0023138.exe -> Downloader.Zlob.apu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP19\A0023159.exe -> Downloader.Zlob.apu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP19\A0023160.dll -> Downloader.Zlob.apu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP19\A0023161.exe -> Downloader.Zlob.apu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP19\A0023189.dll -> Downloader.Zlob.apu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP19\A0023190.exe -> Downloader.Zlob.apu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP19\A0023193.exe -> Downloader.Zlob.apu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP19\A0023194.exe -> Downloader.Zlob.apu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0004250.exe -> Dropper.Agent.aie : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0002782.exe -> Dropper.Agent.hl : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0004244.exe -> Dropper.Agent.hl : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0002774.exe -> Dropper.Agent.mu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP1\A0000929.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0002766.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0002785.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0002786.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0002787.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0002788.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0002789.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0002790.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0002791.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0002792.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0002793.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0002794.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0002795.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0002796.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0002797.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0002798.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0002799.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0002800.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0002801.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0002802.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0002803.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0002804.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0002805.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0002806.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0002807.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0002808.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0002809.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0002810.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0002811.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0002812.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0002813.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0002814.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0002815.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0002816.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0002817.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0002818.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0002819.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0002820.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0002821.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0002822.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0002823.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0002824.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0002825.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0002826.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0002827.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0002828.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0002829.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0002830.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0002831.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0002832.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0002833.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0002834.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0002835.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0002836.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0002837.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0002838.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0002839.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0002840.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0002841.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0002842.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0002843.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0002844.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0002845.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0002846.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0002847.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0002848.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0002849.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0002850.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0002851.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0002852.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0002853.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0002854.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0002855.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0002856.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0002857.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0002858.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0002859.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0002860.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0002861.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0002862.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0002863.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0002864.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0002865.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0002866.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0002867.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0002868.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0002869.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0002870.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0002871.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0002872.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0002873.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0002874.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0002875.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0002876.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0002877.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0002878.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0002879.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0002880.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0002881.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0002882.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0002883.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0002884.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0002885.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0002886.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0002887.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0002888.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0002889.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0002890.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0002891.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0002892.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0002893.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0002894.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0002895.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0002896.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0002897.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0002898.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0002899.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0002900.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0002901.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0002902.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0002903.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0002904.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0002905.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0002906.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0002907.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0002908.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0002909.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0002910.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0002911.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0002912.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0002913.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0002914.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0002915.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0002916.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0002917.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0002918.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0002919.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0002920.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0002921.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0002922.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0002923.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0002924.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0002925.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0002926.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0002927.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0002928.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0002929.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0002930.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0002931.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0002932.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0002933.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0002934.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0002935.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0002936.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0002937.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0002938.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0002939.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0002940.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0002941.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0002942.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0002943.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0002944.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0002945.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0002946.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0002947.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0002948.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0002949.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0002950.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0002951.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0002952.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0002953.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0002954.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0002955.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0002956.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0002957.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0002958.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0002959.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0002960.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0002961.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0002962.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0002963.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0002964.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0002965.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0002966.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0002967.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0002968.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0002969.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0002970.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0002971.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0002972.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0002973.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0002974.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0002975.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0002976.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0002977.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0002978.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0002979.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0002980.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0002981.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0002982.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0002983.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0002984.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0002985.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0002986.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0002987.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0002988.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0002989.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0002990.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0002991.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0002992.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0002993.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0002994.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0002995.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0002996.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0002997.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0002998.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0002999.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003000.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003001.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003002.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003003.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003004.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003005.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003006.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003007.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003008.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003009.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003010.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003011.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003012.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003013.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003014.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003015.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003016.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003017.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003018.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003019.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003020.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003021.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003022.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003023.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003024.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003025.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003026.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003027.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003028.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003029.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003030.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003031.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003032.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003033.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003034.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003035.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003036.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003037.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003038.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003039.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003040.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003041.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003042.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003043.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003044.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003045.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003046.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003047.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003048.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003049.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003050.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003051.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003052.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003053.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003054.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003055.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003056.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003057.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003058.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003059.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003060.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003061.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003062.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003063.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003064.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003065.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003066.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003067.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003068.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003069.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003070.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003071.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003072.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003073.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003074.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003075.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003076.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003077.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003078.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003079.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003080.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003081.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003082.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003083.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003084.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003085.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003086.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003087.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003088.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003089.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003090.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003091.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003092.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003093.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003094.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003095.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003096.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003097.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003098.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003099.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003100.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003101.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003102.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003103.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003104.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003105.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003106.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003107.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003108.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003109.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003110.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003111.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003112.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003113.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003114.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003115.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003116.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003117.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003118.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003119.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003120.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003121.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003122.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003123.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003124.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003125.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003126.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003127.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003128.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003129.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003130.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003131.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003132.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003133.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003134.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003135.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003136.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003137.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003138.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003139.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003140.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003141.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003142.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003143.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003144.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003145.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003146.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003147.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003148.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003149.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003150.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003151.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003152.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003153.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003154.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003155.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003156.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003157.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003158.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003159.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003160.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003161.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003162.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003163.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003164.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003165.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003166.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003167.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003168.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003169.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003170.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003171.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003172.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003173.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003174.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003175.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003176.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003177.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003178.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003179.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003180.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003181.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003182.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003183.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003184.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003185.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003186.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003187.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003188.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003189.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003190.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003191.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003192.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003193.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003194.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003195.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003196.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003197.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003198.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003199.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003200.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003201.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003202.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003203.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003204.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003205.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003206.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003207.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003208.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003209.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003210.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003211.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003212.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003213.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003214.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003215.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003216.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003217.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003218.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003219.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003220.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003221.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003222.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003223.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003224.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003225.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003226.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003227.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003228.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003229.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003230.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003231.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003232.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003233.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003234.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003235.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003236.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003237.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003238.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003239.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003240.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003241.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003242.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003243.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003244.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003245.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003246.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003247.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003248.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003249.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003250.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003251.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003252.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003253.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003254.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003255.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003256.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003257.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003258.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003259.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003260.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003261.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003262.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003263.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003264.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003265.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003266.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003267.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003268.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003269.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003270.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003271.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003272.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003273.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003274.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003275.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003276.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003277.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003278.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003279.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003280.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003281.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003282.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003283.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003284.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003285.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003286.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003287.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003288.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003289.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003290.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003291.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003292.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003293.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003294.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003295.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003296.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003297.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003298.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003299.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003300.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003301.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003302.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003303.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003304.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003305.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003306.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003307.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003308.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003309.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003310.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003311.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003312.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003313.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003314.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003315.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003316.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003317.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003318.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003319.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003320.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003321.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003322.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003323.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003324.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003325.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003326.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003327.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003328.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003329.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003330.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003331.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003332.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003333.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003334.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003335.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003336.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003337.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003338.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003339.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003340.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003341.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003342.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003343.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003344.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003345.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003346.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003347.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003348.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003349.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003350.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003351.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003352.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003353.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003354.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003355.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003356.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003357.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003358.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003359.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003360.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003361.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003362.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003363.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003364.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003365.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003366.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003367.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003368.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003369.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003370.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003371.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003372.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003373.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003374.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003375.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003376.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003377.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003378.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003379.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003380.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003381.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003382.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003383.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003384.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003385.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003386.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003387.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003388.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003389.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003390.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003391.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003392.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003393.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003394.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003395.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003396.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003397.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003398.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003399.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003400.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003401.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003402.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003403.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003404.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003405.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003406.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003407.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003408.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003409.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003410.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003411.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003412.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003413.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003414.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003415.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003416.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003417.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003418.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003419.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003420.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003421.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003422.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003423.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003424.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003425.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003426.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003427.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003428.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003429.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003430.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003431.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003432.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003433.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003434.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003435.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003436.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003437.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003438.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003439.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003440.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003441.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003442.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003443.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003444.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003445.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003446.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003447.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003448.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003449.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003450.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003451.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003452.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003453.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003454.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003455.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003456.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003457.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003458.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003459.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003460.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003461.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003462.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003463.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003464.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003465.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003466.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003467.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003468.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003469.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003470.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003471.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003472.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003473.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003474.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003475.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003476.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003477.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003478.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003479.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003480.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003481.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003482.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003483.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003484.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003485.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003486.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003487.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003488.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003489.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003490.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003491.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003492.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003493.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003494.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003495.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003496.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003497.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003498.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003499.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003500.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003501.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003502.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003503.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003504.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003505.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003506.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003507.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003508.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003509.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003510.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003511.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003512.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003513.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003514.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003515.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003516.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003517.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003518.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003519.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003520.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003521.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003522.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003523.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003524.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003525.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003526.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003527.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003528.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003529.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003530.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003531.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003532.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003533.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003534.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003535.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003536.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003537.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003538.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003539.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003540.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003541.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003542.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003543.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003544.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003545.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003546.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003547.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003548.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003549.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003550.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003551.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003552.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003553.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003554.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003555.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003556.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003557.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003558.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003559.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003560.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003561.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003562.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003563.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003564.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003565.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003566.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003567.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003568.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003569.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003570.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003571.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003572.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003573.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003574.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003575.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003576.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003577.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003578.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003579.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003580.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003581.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003582.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003583.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003584.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003585.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003586.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003587.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003588.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003589.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003590.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003591.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003592.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003593.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003594.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003595.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003596.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003597.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003598.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003599.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003600.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003601.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003602.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003603.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003604.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003605.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003606.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003607.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003608.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003609.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003610.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003611.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003612.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003613.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003614.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003615.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003616.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003617.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003618.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003619.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003620.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003621.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003622.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003623.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003624.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003625.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003626.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003627.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003628.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003629.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003630.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003631.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003632.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003633.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003634.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003635.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003636.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003637.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003638.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003639.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003640.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003641.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003642.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003643.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003644.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003645.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003646.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003647.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003648.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003649.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003650.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003651.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003652.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003653.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003654.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003655.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003656.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003657.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003658.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003659.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003660.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003661.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003662.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003663.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003664.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003665.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003666.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003667.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003668.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003669.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003670.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003671.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003672.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003673.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003674.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003675.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003676.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003677.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003678.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003679.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003680.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003681.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003682.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003683.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003684.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003685.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003686.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003687.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003688.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003689.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003690.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003691.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003692.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003693.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003694.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003695.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003696.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003697.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003698.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003699.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003700.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003701.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003702.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003703.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003704.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003705.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003706.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003707.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003708.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003709.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003710.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003711.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003712.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003713.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003714.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003715.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003716.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003717.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003718.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003719.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003720.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003721.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003722.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003723.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003724.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003725.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003726.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003727.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003728.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003729.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003730.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003731.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003732.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003733.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003734.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003735.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003736.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003737.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003738.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003739.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003740.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003741.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003742.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003743.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003744.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003745.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003746.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003747.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003748.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003749.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003750.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003751.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003752.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003753.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003754.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003755.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003756.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003757.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003758.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003759.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003760.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003761.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003762.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003763.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003764.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003765.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003766.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003767.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003768.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003769.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003770.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003771.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003772.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003773.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003774.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003775.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003776.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003777.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003778.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003779.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003780.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003781.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003782.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003783.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003784.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003785.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003786.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003787.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003788.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003789.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003790.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003791.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003792.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003793.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003794.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003795.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003796.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003797.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003798.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003799.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003800.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003801.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003802.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003803.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003804.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003805.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003806.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003807.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003808.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003809.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003810.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003811.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003812.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003813.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003814.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003815.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003816.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003817.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003818.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003819.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003820.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003821.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003822.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003823.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003824.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003825.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003826.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003827.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003828.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003829.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003830.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003831.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003832.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003833.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003834.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003835.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003836.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003837.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003838.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003839.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003840.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003841.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003842.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003843.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003844.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003845.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003846.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003847.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003848.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003849.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003850.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003851.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003852.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003853.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003854.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003855.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003856.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003857.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003858.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003859.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003860.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003861.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003862.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003863.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003864.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003865.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003866.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003867.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003868.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003869.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003870.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003871.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003872.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003873.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003874.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003875.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003876.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003877.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003878.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003879.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003880.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003881.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003882.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003883.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003884.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003885.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003886.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003887.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003888.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003889.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003890.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003891.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003892.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003893.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003894.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003895.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003896.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003897.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003898.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003899.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003900.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003901.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003902.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003903.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003904.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003905.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003906.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003907.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003908.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003909.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003910.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003911.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003912.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003913.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003914.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003915.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003916.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003917.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003918.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003919.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003920.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003921.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003922.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003923.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003924.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003925.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003926.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003927.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003928.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003929.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003930.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003931.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003932.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003933.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003934.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003935.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003936.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003937.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003938.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003939.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003940.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003941.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003942.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003943.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003944.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003945.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003946.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003947.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003948.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003949.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003950.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003951.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003952.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003953.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003954.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003955.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003956.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003957.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003958.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003959.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003960.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003961.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003962.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003963.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003964.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003965.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003966.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003967.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003968.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003969.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003970.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003971.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003972.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003973.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003974.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003975.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003976.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003977.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003978.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003979.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003980.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003981.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003982.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003983.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003984.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003985.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003986.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003987.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003988.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003989.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003990.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003991.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003992.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003993.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003994.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003995.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003996.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003997.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003998.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003999.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0004000.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0004001.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0004002.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0004003.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0004004.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0004005.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0004006.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0004007.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0004008.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0004009.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0004010.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0004011.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0004012.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0004013.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0004014.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0004015.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0004016.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0004017.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0004018.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0004019.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0004020.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0004021.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0004022.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0004023.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0004024.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0004025.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0004026.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0004027.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0004028.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0004029.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0004030.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0004031.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0004032.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0004033.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0004034.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0004035.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0004036.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0004037.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0004038.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0004039.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0004040.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0004041.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0004042.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0004043.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0004044.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0004045.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0004046.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0004047.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0004048.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0004049.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0004050.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0004051.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0004052.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0004053.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0004054.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0004055.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0004056.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0004057.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0004058.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0004059.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0004060.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0004061.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0004062.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0004063.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0004064.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0004065.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0004066.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0004067.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0004068.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0004069.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0004070.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0004071.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0004072.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0004073.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0004074.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0004075.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0004076.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0004077.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0004078.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0004079.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0004080.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0004081.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0004082.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0004083.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0004084.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0004085.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0004086.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0004087.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0004088.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0004089.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0004090.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0004091.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0004092.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0004093.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0004094.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0004095.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0004096.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0004097.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0004098.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0004099.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0004100.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0004101.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0004102.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0004103.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0004104.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0004105.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0004106.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0004107.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0004108.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0004109.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0004110.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0004111.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0004112.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0004113.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0004114.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0004115.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0004116.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0004117.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0004118.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0004119.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0004120.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0004121.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0004122.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0004123.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0004124.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0004125.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0004126.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0004127.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0004128.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0004129.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0004130.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0004131.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0004132.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0004133.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0004134.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0004135.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0004136.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0004137.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0004138.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0004139.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0004140.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0004141.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0004142.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0004143.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0004144.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0004145.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0004146.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0004147.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0004148.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0004149.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0004150.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0004151.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0004152.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0004153.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0004154.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0004155.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0004156.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0004157.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0004158.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0004159.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0004160.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0004161.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0004162.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0004163.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0004164.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0004165.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0004166.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0004167.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0004168.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0004169.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0004170.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0004171.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0004172.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0004173.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0004174.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0004175.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0004176.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0004177.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0004178.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0004179.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0004180.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0004181.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0004182.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0004183.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0004184.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0004185.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0004186.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0004187.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\Documents and Settings\Kaucher.MY-F78BF48CE2\Local Settings\Temporary Internet Files\Content.IE5\C9IJSHYZ\popup[10].htm -> Hijacker.Agent.a : Cleaned with backup (quarantined).
C:\Documents and Settings\Kaucher.MY-F78BF48CE2\Local Settings\Temporary Internet Files\Content.IE5\C9IJSHYZ\popup[11].htm -> Hijacker.Agent.a : Cleaned with backup (quarantined).
C:\Documents and Settings\Kaucher.MY-F78BF48CE2\Local Settings\Temporary Internet Files\Content.IE5\C9IJSHYZ\popup[12].htm -> Hijacker.Agent.a : Cleaned with backup (quarantined).
C:\Documents and Settings\Kaucher.MY-F78BF48CE2\Local Settings\Temporary Internet Files\Content.IE5\C9IJSHYZ\popup[13].htm -> Hijacker.Agent.a : Cleaned with backup (quarantined).
C:\Documents and Settings\Kaucher.MY-F78BF48CE2\Local Settings\Temporary Internet Files\Content.IE5\C9IJSHYZ\popup[14].htm -> Hijacker.Agent.a : Cleaned with backup (quarantined).
C:\Documents and Settings\Kaucher.MY-F78BF48CE2\Local Settings\Temporary Internet Files\Content.IE5\C9IJSHYZ\popup[15].htm -> Hijacker.Agent.a : Cleaned with backup (quarantined).
C:\Documents and Settings\Kaucher.MY-F78BF48CE2\Local Settings\Temporary Internet Files\Content.IE5\C9IJSHYZ\popup[16].htm -> Hijacker.Agent.a : Cleaned with backup (quarantined).
C:\Documents and Settings\Kaucher.MY-F78BF48CE2\Local Settings\Temporary Internet Files\Content.IE5\C9IJSHYZ\popup[17].htm -> Hijacker.Agent.a : Cleaned with backup (quarantined).
C:\Documents and Settings\Kaucher.MY-F78BF48CE2\Local Settings\Temporary Internet Files\Content.IE5\C9IJSHYZ\popup[18].htm -> Hijacker.Agent.a : Cleaned with backup (quarantined).
C:\Documents and Settings\Kaucher.MY-F78BF48CE2\Local Settings\Temporary Internet Files\Content.IE5\C9IJSHYZ\popup[19].htm -> Hijacker.Agent.a : Cleaned with backup (quarantined).
C:\Documents and Settings\Kaucher.MY-F78BF48CE2\Local Settings\Temporary Internet Files\Content.IE5\C9IJSHYZ\popup[1].htm -> Hijacker.Agent.a : Cleaned with backup (quarantined).
C:\Documents and Settings\Kaucher.MY-F78BF48CE2\Local Settings\Temporary Internet Files\Content.IE5\C9IJSHYZ\popup[20].htm -> Hijacker.Agent.a : Cleaned with backup (quarantined).
C:\Documents and Settings\Kaucher.MY-F78BF48CE2\Local Settings\Temporary Internet Files\Content.IE5\C9IJSHYZ\popup[21].htm -> Hijacker.Agent.a : Cleaned with backup (quarantined).
C:\Documents and Settings\Kaucher.MY-F78BF48CE2\Local Settings\Temporary Internet Files\Content.IE5\C9IJSHYZ\popup[22].htm -> Hijacker.Agent.a : Cleaned with backup (quarantined).
C:\Documents and Settings\Kaucher.MY-F78BF48CE2\Local Settings\Temporary Internet Files\Content.IE5\C9IJSHYZ\popup[23].htm -> Hijacker.Agent.a : Cleaned with backup (quarantined).
C:\Documents and Settings\Kaucher.MY-F78BF48CE2\Local Settings\Temporary Internet Files\Content.IE5\C9IJSHYZ\popup[24].htm -> Hijacker.Agent.a : Cleaned with backup (quarantined).
C:\Documents and Settings\Kaucher.MY-F78BF48CE2\Local Settings\Temporary Internet Files\Content.IE5\C9IJSHYZ\popup[25].htm -> Hijacker.Agent.a : Cleaned with backup (quarantined).
C:\Documents and Settings\Kaucher.MY-F78BF48CE2\Local Settings\Temporary Internet Files\Content.IE5\C9IJSHYZ\popup[26].htm -> Hijacker.Agent.a : Cleaned with backup (quarantined).
C:\Documents and Settings\Kaucher.MY-F78BF48CE2\Local Settings\Temporary Internet Files\Content.IE5\C9IJSHYZ\popup[27].htm -> Hijacker.Agent.a : Cleaned with backup (quarantined).
C:\Documents and Settings\Kaucher.MY-F78BF48CE2\Local Settings\Temporary Internet Files\Content.IE5\C9IJSHYZ\popup[28].htm -> Hijacker.Agent.a : Cleaned with backup (quarantined).
C:\Documents and Settings\Kaucher.MY-F78BF48CE2\Local Settings\Temporary Internet Files\Content.IE5\C9IJSHYZ\popup[29].htm -> Hijacker.Agent.a : Cleaned with backup (quarantined).
C:\Documents and Settings\Kaucher.MY-F78BF48CE2\Local Settings\Temporary Internet Files\Content.IE5\C9IJSHYZ\popup[2].htm -> Hijacker.Agent.a : Cleaned with backup (quarantined).
C:\Documents and Settings\Kaucher.MY-F78BF48CE2\Local Settings\Temporary Internet Files\Content.IE5\C9IJSHYZ\popup[30].htm -> Hijacker.Agent.a : Cleaned with backup (quarantined).
C:\Documents and Settings\Kaucher.MY-F78BF48CE2\Local Settings\Temporary Internet Files\Content.IE5\C9IJSHYZ\popup[31].htm -> Hijacker.Agent.a : Cleaned with backup (quarantined).
C:\Documents and Settings\Kaucher.MY-F78BF48CE2\Local Settings\Temporary Internet Files\Content.IE5\C9IJSHYZ\popup[32].htm -> Hijacker.Agent.a : Cleaned with backup (quarantined).
C:\Documents and Settings\Kaucher.MY-F78BF48CE2\Local Settings\Temporary Internet Files\Content.IE5\C9IJSHYZ\popup[33].htm -> Hijacker.Agent.a : Cleaned with backup (quarantined).
C:\Documents and Settings\Kaucher.MY-F78BF48CE2\Local Settings\Temporary Internet Files\Content.IE5\C9IJSHYZ\popup[34].htm -> Hijacker.Agent.a : Cleaned with backup (quarantined).
C:\Documents and Settings\Kaucher.MY-F78BF48CE2\Local Settings\Temporary Internet Files\Content.IE5\C9IJSHYZ\popup[35].htm -> Hijacker.Agent.a : Cleaned with backup (quarantined).
C:\Documents and Settings\Kaucher.MY-F78BF48CE2\Local Settings\Temporary Internet Files\Content.IE5\C9IJSHYZ\popup[36].htm -> Hijacker.Agent.a : Cleaned with backup (quarantined).
C:\Documents and Settings\Kaucher.MY-F78BF48CE2\Local Settings\Temporary Internet Files\Content.IE5\C9IJSHYZ\popup[37].htm -> Hijacker.Agent.a : Cleaned with backup (quarantined).
C:\Documents and Settings\Kaucher.MY-F78BF48CE2\Local Settings\Temporary Internet Files\Content.IE5\C9IJSHYZ\popup[38].htm -> Hijacker.Agent.a : Cleaned with backup (quarantined).
C:\Documents and Settings\Kaucher.MY-F78BF48CE2\Local Settings\Temporary Internet Files\Content.IE5\C9IJSHYZ\popup[39].htm -> Hijacker.Agent.a : Cleaned with backup (quarantined).
C:\Documents and Settings\Kaucher.MY-F78BF48CE2\Local Settings\Temporary Internet Files\Content.IE5\C9IJSHYZ\popup[3].htm -> Hijacker.Agent.a : Cleaned with backup (quarantined).
C:\Documents and Settings\Kaucher.MY-F78BF48CE2\Local Settings\Temporary Internet Files\Content.IE5\C9IJSHYZ\popup[40].htm -> Hijacker.Agent.a : Cleaned with backup (quarantined).
C:\Documents and Settings\Kaucher.MY-F78BF48CE2\Local Settings\Temporary Internet Files\Content.IE5\C9IJSHYZ\popup[41].htm -> Hijacker.Agent.a : Cleaned with backup (quarantined).
C:\Documents and Settings\Kaucher.MY-F78BF48CE2\Local Settings\Temporary Internet Files\Content.IE5\C9IJSHYZ\popup[42].htm -> Hijacker.Agent.a : Cleaned with backup (quarantined).
C:\Documents and Settings\Kaucher.MY-F78BF48CE2\Local Settings\Temporary Internet Files\Content.IE5\C9IJSHYZ\popup[43].htm -> Hijacker.Agent.a : Cleaned with backup (quarantined).
C:\Documents and Settings\Kaucher.MY-F78BF48CE2\Local Settings\Temporary Internet Files\Content.IE5\C9IJSHYZ\popup[44].htm -> Hijacker.Agent.a : Cleaned with backup (quarantined).
C:\Documents and Settings\Kaucher.MY-F78BF48CE2\Local Settings\Temporary Internet Files\Content.IE5\C9IJSHYZ\popup[4].htm -> Hijacker.Agent.a : Cleaned with backup (quarantined).
C:\Documents and Settings\Kaucher.MY-F78BF48CE2\Local Settings\Temporary Internet Files\Content.IE5\C9IJSHYZ\popup[5].htm -> Hijacker.Agent.a : Cleaned with backup (quarantined).
C:\Documents and Settings\Kaucher.MY-F78BF48CE2\Local Settings\Temporary Internet Files\Content.IE5\C9IJSHYZ\popup[6].htm -> Hijacker.Agent.a : Cleaned with backup (quarantined).
C:\Documents and Settings\Kaucher.MY-F78BF48CE2\Local Settings\Temporary Internet Files\Content.IE5\C9IJSHYZ\popup[7].htm -> Hijacker.Agent.a : Cleaned with backup (quarantined).
C:\Documents and Settings\Kaucher.MY-F78BF48CE2\Local Settings\Temporary Internet Files\Content.IE5\C9IJSHYZ\popup[8].htm -> Hijacker.Agent.a : Cleaned with backup (quarantined).
C:\Documents and Settings\Kaucher.MY-F78BF48CE2\Local Settings\Temporary Internet Files\Content.IE5\C9IJSHYZ\popup[9].htm -> Hijacker.Agent.a : Cleaned with backup (quarantined).
C:\Documents and Settings\Kaucher.MY-F78BF48CE2\Local Settings\Temporary Internet Files\Content.IE5\GP2JKLIB\popup[10].htm -> Hijacker.Agent.a : Cleaned with backup (quarantined).
C:\Documents and Settings\Kaucher.MY-F78BF48CE2\Local Settings\Temporary Internet Files\Content.IE5\GP2JKLIB\popup[11].htm -> Hijacker.Agent.a : Cleaned with backup (quarantined).
C:\Documents and Settings\Kaucher.MY-F78BF48CE2\Local Settings\Temporary Internet Files\Content.IE5\GP2JKLIB\popup[12].htm -> Hijacker.Agent.a : Cleaned with backup (quarantined).
C:\Documents and Settings\Kaucher.MY-F78BF48CE2\Local Settings\Temporary Internet Files\Content.IE5\GP2JKLIB\popup[13].htm -> Hijacker.Agent.a : Cleaned with backup (quarantined).
C:\Documents and Settings\Kaucher.MY-F78BF48CE2\Local Settings\Temporary Internet Files\Content.IE5\GP2JKLIB\popup[14].htm -> Hijacker.Agent.a : Cleaned with backup (quarantined).
C:\Documents and Settings\Kaucher.MY-F78BF48CE2\Local Settings\Temporary Internet Files\Content.IE5\GP2JKLIB\popup[15].htm -> Hijacker.Agent.a : Cleaned with backup (quarantined).
C:\Documents and Settings\Kaucher.MY-F78BF48CE2\Local Settings\Temporary Internet Files\Content.IE5\GP2JKLIB\popup[16].htm -> Hijacker.Agent.a : Cleaned with backup (quarantined).
C:\Documents and Settings\Kaucher.MY-F78BF48CE2\Local Settings\Temporary Internet Files\Content.IE5\GP2JKLIB\popup[17].htm -> Hijacker.Agent.a : Cleaned with backup (quarantined).
C:\Documents and Settings\Kaucher.MY-F78BF48CE2\Local Settings\Temporary Internet Files\Content.IE5\GP2JKLIB\popup[18].htm -> Hijacker.Agent.a : Cleaned with backup (quarantined).
C:\Documents and Settings\Kaucher.MY-F78BF48CE2\Local Settings\Temporary Internet Files\Content.IE5\GP2JKLIB\popup[19].htm -> Hijacker.Agent.a : Cleaned with backup (quarantined).
C:\Documents and Settings\Kaucher.MY-F78BF48CE2\Local Settings\Temporary Internet Files\Content.IE5\GP2JKLIB\popup[1].htm -> Hijacker.Agent.a : Cleaned with backup (quarantined).
C:\Documents and Settings\Kaucher.MY-F78BF48CE2\Local Settings\Temporary Internet Files\Content.IE5\GP2JKLIB\popup[20].htm -> Hijacker.Agent.a : Cleaned with backup (quarantined).
C:\Documents and Settings\Kaucher.MY-F78BF48CE2\Local Settings\Temporary Internet Files\Content.IE5\GP2JKLIB\popup[21].htm -> Hijacker.Agent.a : Cleaned with backup (quarantined).
C:\Documents and Settings\Kaucher.MY-F78BF48CE2\Local Settings\Temporary Internet Files\Content.IE5\GP2JKLIB\popup[22].htm -> Hijacker.Agent.a : Cleaned with backup (quarantined).
C:\Documents and Settings\Kaucher.MY-F78BF48CE2\Local Settings\Temporary Internet Files\Content.IE5\GP2JKLIB\popup[23].htm -> Hijacker.Agent.a : Cleaned with backup (quarantined).
C:\Documents and Settings\Kaucher.MY-F78BF48CE2\Local Settings\Temporary Internet Files\Content.IE5\GP2JKLIB\popup[24].htm -> Hijacker.Agent.a : Cleaned with backup (quarantined).
C:\Documents and Settings\Kaucher.MY-F78BF48CE2\Local Settings\Temporary Internet Files\Content.IE5\GP2JKLIB\popup[25].htm -> Hijacker.Agent.a : Cleaned with backup (quarantined).
C:\Documents and Settings\Kaucher.MY-F78BF48CE2\Local Settings\Temporary Internet Files\Content.IE5\GP2JKLIB\popup[26].htm -> Hijacker.Agent.a : Cleaned with backup (quarantined).
C:\Documents and Settings\Kaucher.MY-F78BF48CE2\Local Settings\Temporary Internet Files\Content.IE5\GP2JKLIB\popup[27].htm -> Hijacker.Agent.a : Cleaned with backup (quarantined).
C:\Documents and Settings\Kaucher.MY-F78BF48CE2\Local Settings\Temporary Internet Files\Content.IE5\GP2JKLIB\popup[28].htm -> Hijacker.Agent.a : Cleaned with backup (quarantined).
C:\Documents and Settings\Kaucher.MY-F78BF48CE2\Local Settings\Temporary Internet Files\Content.IE5\GP2JKLIB\popup[29].htm -> Hijacker.Agent.a : Cleaned with backup (quarantined).
C:\Documents and Settings\Kaucher.MY-F78BF48CE2\Local Settings\Temporary Internet Files\Content.IE5\GP2JKLIB\popup[2].htm -> Hijacker.Agent.a : Cleaned with backup (quarantined).
C:\Documents and Settings\Kaucher.MY-F78BF48CE2\Local Settings\Temporary Internet Files\Content.IE5\GP2JKLIB\popup[30].htm -> Hijacker.Agent.a : Cleaned with backup (quarantined).
C:\Documents and Settings\Kaucher.MY-F78BF48CE2\Local Settings\Temporary Internet Files\Content.IE5\GP2JKLIB\popup[31].htm -> Hijacker.Agent.a : Cleaned with backup (quarantined).
C:\Documents and Settings\Kaucher.MY-F78BF48CE2\Local Settings\Temporary Internet Files\Content.IE5\GP2JKLIB\popup[32].htm -> Hijacker.Agent.a : Cleaned with backup (quarantined).
C:\Documents and Settings\Kaucher.MY-F78BF48CE2\Local Settings\Temporary Internet Files\Content.IE5\GP2JKLIB\popup[33].htm -> Hijacker.Agent.a : Cleaned with backup (quarantined).
C:\Documents and Settings\Kaucher.MY-F78BF48CE2\Local Settings\Temporary Internet Files\Content.IE5\GP2JKLIB\popup[34].htm -> Hijacker.Agent.a : Cleaned with backup (quarantined).
C:\Documents and Settings\Kaucher.MY-F78BF48CE2\Local Settings\Temporary Internet Files\Content.IE5\GP2JKLIB\popup[35].htm -> Hijacker.Agent.a : Cleaned with backup (quarantined).
C:\Documents and Settings\Kaucher.MY-F78BF48CE2\Local Settings\Temporary Internet Files\Content.IE5\GP2JKLIB\popup[36].htm -> Hijacker.Agent.a : Cleaned with backup (quarantined).
C:\Documents and Settings\Kaucher.MY-F78BF48CE2\Local Settings\Temporary Internet Files\Content.IE5\GP2JKLIB\popup[37].htm -> Hijacker.Agent.a : Cleaned with backup (quarantined).
C:\Documents and Settings\Kaucher.MY-F78BF48CE2\Local Settings\Temporary Internet Files\Content.IE5\GP2JKLIB\popup[38].htm -> Hijacker.Agent.a : Cleaned with backup (quarantined).
C:\Documents and Settings\Kaucher.MY-F78BF48CE2\Local Settings\Temporary Internet Files\Content.IE5\GP2JKLIB\popup[39].htm -> Hijacker.Agent.a : Cleaned with backup (quarantined).
C:\Documents and Settings\Kaucher.MY-F78BF48CE2\Local Settings\Temporary Internet Files\Content.IE5\GP2JKLIB\popup[3].htm -> Hijacker.Agent.a : Cleaned with backup (quarantined).
C:\Documents and Settings\Kaucher.MY-F78BF48CE2\Local Settings\Temporary Internet Files\Content.IE5\GP2JKLIB\popup[40].htm -> Hijacker.Agent.a : Cleaned with backup (quarantined).
C:\Documents and Settings\Kaucher.MY-F78BF48CE2\Local Settings\Temporary Internet Files\Content.IE5\GP2JKLIB\popup[41].htm -> Hijacker.Agent.a : Cleaned with backup (quarantined).
C:\Documents and Settings\Kaucher.MY-F78BF48CE2\Local Settings\Temporary Internet Files\Content.IE5\GP2JKLIB\popup[42].htm -> Hijacker.Agent.a : Cleaned with backup (quarantined).
C:\Documents and Settings\Kaucher.MY-F78BF48CE2\Local Settings\Temporary Internet Files\Content.IE5\GP2JKLIB\popup[43].htm -> Hijacker.Agent.a : Cleaned with backup (quarantined).
C:\Documents and Settings\Kaucher.MY-F78BF48CE2\Local Settings\Temporary Internet Files\Content.IE5\GP2JKLIB\popup[44].htm -> Hijacker.Agent.a : Cleaned with backup (quarantined).
C:\Documents and Settings\Kaucher.MY-F78BF48CE2\Local Settings\Temporary Internet Files\Content.IE5\GP2JKLIB\popup[45].htm -> Hijacker.Agent.a : Cleaned with backup (quarantined).
C:\Documents and Settings\Kaucher.MY-F78BF48CE2\Local Settings\Temporary Internet Files\Content.IE5\GP2JKLIB\popup[4].htm -> Hijacker.Agent.a : Cleaned with backup (quarantined).
C:\Documents and Settings\Kaucher.MY-F78BF48CE2\Local Settings\Temporary Internet Files\Content.IE5\GP2JKLIB\popup[5].htm -> Hijacker.Agent.a : Cleaned with backup (quarantined).
C:\Documents and Settings\Kaucher.MY-F78BF48CE2\Local Settings\Temporary Internet Files\Content.IE5\GP2JKLIB\popup[6].htm -> Hijacker.Agent.a : Cleaned with backup (quarantined).
C:\Documents and Settings\Kaucher.MY-F78BF48CE2\Local Settings\Temporary Internet Files\Content.IE5\GP2JKLIB\popup[7].htm -> Hijacker.Agent.a : Cleaned with backup (quarantined).
C:\Documents and Settings\Kaucher.MY-F78BF48CE2\Local Settings\Temporary Internet Files\Content.IE5\GP2JKLIB\popup[8].htm -> Hijacker.Agent.a : Cleaned with backup (quarantined).
C:\Documents and Settings\Kaucher.MY-F78BF48CE2\Local Settings\Temporary Internet Files\Content.IE5\GP2JKLIB\popup[9].htm -> Hijacker.Agent.a : Cleaned with backup (quarantined).
C:\Documents and Settings\Kaucher.MY-F78BF48CE2\Local Settings\Temporary Internet Files\Content.IE5\KDYRCLM7\popup[10].htm -> Hijacker.Agent.a : Cleaned with backup (quarantined).
C:\Documents and Settings\Kaucher.MY-F78BF48CE2\Local Settings\Temporary Internet Files\Content.IE5\KDYRCLM7\popup[11].htm -> Hijacker.Agent.a : Cleaned with backup (quarantined).
C:\Documents and Settings\Kaucher.MY-F78BF48CE2\Local Settings\Temporary Internet Files\Content.IE5\KDYRCLM7\popup[12].htm -> Hijacker.Agent.a : Cleaned with backup (quarantined).
C:\Documents and Settings\Kaucher.MY-F78BF48CE2\Local Settings\Temporary Internet Files\Content.IE5\KDYRCLM7\popup[13].htm -> Hijacker.Agent.a : Cleaned with backup (quarantined).
C:\Documents and Settings\Kaucher.MY-F78BF48CE2\Local Settings\Temporary Internet Files\Content.IE5\KDYRCLM7\popup[14].htm -> Hijacker.Agent.a : Cleaned with backup (quarantined).
C:\Documents and Settings\Kaucher.MY-F78BF48CE2\Local Settings\Temporary Internet Files\Content.IE5\KDYRCLM7\popup[15].htm -> Hijacker.Agent.a : Cleaned with backup (quarantined).
C:\Documents and Settings\Kaucher.MY-F78BF48CE2\Local Settings\Temporary Internet Files\Content.IE5\KDYRCLM7\popup[16].htm -> Hijacker.Agent.a : Cleaned with backup (quarantined).
C:\Documents and Settings\Kaucher.MY-F78BF48CE2\Local Settings\Temporary Internet Files\Content.IE5\KDYRCLM7\popup[17].htm -> Hijacker.Agent.a : Cleaned with backup (quarantined).
C:\Documents and Settings\Kaucher.MY-F78BF48CE2\Local Settings\Temporary Internet Files\Content.IE5\KDYRCLM7\popup[18].htm -> Hijacker.Agent.a : Cleaned with backup (quarantined).
C:\Documents and Settings\Kaucher.MY-F78BF48CE2\Local Settings\Temporary Internet Files\Content.IE5\KDYRCLM7\popup[19].htm -> Hijacker.Agent.a : Cleaned with backup (quarantined).
C:\Documents and Settings\Kaucher.MY-F78BF48CE2\Local Settings\Temporary Internet Files\Content.IE5\KDYRCLM7\popup[1].htm -> Hijacker.Agent.a : Cleaned with backup (quarantined).
C:\Documents and Settings\Kaucher.MY-F78BF48CE2\Local Settings\Temporary Internet Files\Content.IE5\KDYRCLM7\popup[20].htm -> Hijacker.Agent.a : Cleaned with backup (quarantined).
C:\Documents and Settings\Kaucher.MY-F78BF48CE2\Local Settings\Temporary Internet Files\Content.IE5\KDYRCLM7\popup[21].htm -> Hijacker.Agent.a : Cleaned with backup (quarantined).
C:\Documents and Settings\Kaucher.MY-F78BF48CE2\Local Settings\Temporary Internet Files\Content.IE5\KDYRCLM7\popup[22].htm -> Hijacker.Agent.a : Cleaned with backup (quarantined).
C:\Documents and Settings\Kaucher.MY-F78BF48CE2\Local Settings\Temporary Internet Files\Content.IE5\KDYRCLM7\popup[23].htm -> Hijacker.Agent.a : Cleaned with backup (quarantined).
C:\Documents and Settings\Kaucher.MY-F78BF48CE2\Local Settings\Temporary Internet Files\Content.IE5\KDYRCLM7\popup[24].htm -> Hijacker.Agent.a : Cleaned with backup (quarantined).
C:\Documents and Settings\Kaucher.MY-F78BF48CE2\Local Settings\Temporary Internet Files\Content.IE5\KDYRCLM7\popup[25].htm -> Hijacker.Agent.a : Cleaned with backup (quarantined).
C:\Documents and Settings\Kaucher.MY-F78BF48CE2\Local Settings\Temporary Internet Files\Content.IE5\KDYRCLM7\popup[26].htm -> Hijacker.Agent.a : Cleaned with backup (quarantined).
C:\Documents and Settings\Kaucher.MY-F78BF48CE2\Local Settings\Temporary Internet Files\Content.IE5\KDYRCLM7\popup[27].htm -> Hijacker.Agent.a : Cleaned with backup (quarantined).
C:\Documents and Settings\Kaucher.MY-F78BF48CE2\Local Settings\Temporary Internet Files\Content.IE5\KDYRCLM7\popup[28].htm -> Hijacker.Agent.a : Cleaned with backup (quarantined).
C:\Documents and Settings\Kaucher.MY-F78BF48CE2\Local Settings\Temporary Internet Files\Content.IE5\KDYRCLM7\popup[29].htm -> Hijacker.Agent.a : Cleaned with backup (quarantined).
C:\Documents and Settings\Kaucher.MY-F78BF48CE2\Local Settings\Temporary Internet Files\Content.IE5\KDYRCLM7\popup[2].htm -> Hijacker.Agent.a : Cleaned with backup (quarantined).
C:\Documents and Settings\Kaucher.MY-F78BF48CE2\Local Settings\Temporary Internet Files\Content.IE5\KDYRCLM7\popup[30].htm -> Hijacker.Agent.a : Cleaned with backup (quarantined).
C:\Documents and Settings\Kaucher.MY-F78BF48CE2\Local Settings\Temporary Internet Files\Content.IE5\KDYRCLM7\popup[31].htm -> Hijacker.Agent.a : Cleaned with backup (quarantined).
C:\Documents and Settings\Kaucher.MY-F78BF48CE2\Local Settings\Temporary Internet Files\Content.IE5\KDYRCLM7\popup[32].htm -> Hijacker.Agent.a : Cleaned with backup (quarantined).
C:\Documents and Settings\Kaucher.MY-F78BF48CE2\Local Settings\Temporary Internet Files\Content.IE5\KDYRCLM7\popup[33].htm -> Hijacker.Agent.a : Cleaned with backup (quarantined).
C:\Documents and Settings\Kaucher.MY-F78BF48CE2\Local Settings\Temporary Internet Files\Content.IE5\KDYRCLM7\popup[34].htm -> Hijacker.Agent.a : Cleaned with backup (quarantined).
C:\Documents and Settings\Kaucher.MY-F78BF48CE2\Local Settings\Temporary Internet Files\Content.IE5\KDYRCLM7\popup[35].htm -> Hijacker.Agent.a : Cleaned with backup (quarantined).
C:\Documents and Settings\Kaucher.MY-F78BF48CE2\Local Settings\Temporary Internet Files\Content.IE5\KDYRCLM7\popup[36].htm -> Hijacker.Agent.a : Cleaned with backup (quarantined).
C:\Documents and Settings\Kaucher.MY-F78BF48CE2\Local Settings\Temporary Internet Files\Content.IE5\KDYRCLM7\popup[37].htm -> Hijacker.Agent.a : Cleaned with backup (quarantined).
C:\Documents and Settings\Kaucher.MY-F78BF48CE2\Local Settings\Temporary Internet Files\Content.IE5\KDYRCLM7\popup[38].htm -> Hijacker.Agent.a : Cleaned with backup (quarantined).
C:\Documents and Settings\Kaucher.MY-F78BF48CE2\Local Settings\Temporary Internet Files\Content.IE5\KDYRCLM7\popup[39].htm -> Hijacker.Agent.a : Cleaned with backup (quarantined).
C:\Documents and Settings\Kaucher.MY-F78BF48CE2\Local Settings\Temporary Internet Files\Content.IE5\KDYRCLM7\popup[3].htm -> Hijacker.Agent.a : Cleaned with backup (quarantined).
C:\Documents and Settings\Kaucher.MY-F78BF48CE2\Local Settings\Temporary Internet Files\Content.IE5\KDYRCLM7\popup[40].htm -> Hijacker.Agent.a : Cleaned with backup (quarantined).
C:\Documents and Settings\Kaucher.MY-F78BF48CE2\Local Settings\Temporary Internet Files\Content.IE5\KDYRCLM7\popup[41].htm -> Hijacker.Agent.a : Cleaned with backup (quarantined).
C:\Documents and Settings\Kaucher.MY-F78BF48CE2\Local Settings\Temporary Internet Files\Content.IE5\KDYRCLM7\popup[42].htm -> Hijacker.Agent.a : Cleaned with backup (quarantined).
C:\Documents and Settings\Kaucher.MY-F78BF48CE2\Local Settings\Temporary Internet Files\Content.IE5\KDYRCLM7\popup[4].htm -> Hijacker.Agent.a : Cleaned with backup (quarantined).
C:\Documents and Settings\Kaucher.MY-F78BF48CE2\Local Settings\Temporary Internet Files\Content.IE5\KDYRCLM7\popup[5].htm -> Hijacker.Agent.a : Cleaned with backup (quarantined).
C:\Documents and Settings\Kaucher.MY-F78BF48CE2\Local Settings\Temporary Internet Files\Content.IE5\KDYRCLM7\popup[6].htm -> Hijacker.Agent.a : Cleaned with backup (quarantined).
C:\Documents and Settings\Kaucher.MY-F78BF48CE2\Local Settings\Temporary Internet Files\Content.IE5\KDYRCLM7\popup[7].htm -> Hijacker.Agent.a : Cleaned with backup (quarantined).
C:\Documents and Settings\Kaucher.MY-F78BF48CE2\Local Settings\Temporary Internet Files\Content.IE5\KDYRCLM7\popup[8].htm -> Hijacker.Agent.a : Cleaned with backup (quarantined).
C:\Documents and Settings\Kaucher.MY-F78BF48CE2\Local Settings\Temporary Internet Files\Content.IE5\KDYRCLM7\popup[9].htm -> Hijacker.Agent.a : Cleaned with backup (quarantined).
C:\Documents and Settings\Kaucher.MY-F78BF48CE2\Local Settings\Temporary Internet Files\Content.IE5\W9E7KDU3\popup[10].htm -> Hijacker.Agent.a : Cleaned with backup (quarantined).
C:\Documents and Settings\Kaucher.MY-F78BF48CE2\Local Settings\Temporary Internet Files\Content.IE5\W9E7KDU3\popup[11].htm -> Hijacker.Agent.a : Cleaned with backup (quarantined).
C:\Documents and Settings\Kaucher.MY-F78BF48CE2\Local Settings\Temporary Internet Files\Content.IE5\W9E7KDU3\popup[12].htm -> Hijacker.Agent.a : Cleaned with backup (quarantined).
C:\Documents and Settings\Kaucher.MY-F78BF48CE2\Local Settings\Temporary Internet Files\Content.IE5\W9E7KDU3\popup[13].htm -> Hijacker.Agent.a : Cleaned with backup (quarantined).
C:\Documents and Settings\Kaucher.MY-F78BF48CE2\Local Settings\Temporary Internet Files\Content.IE5\W9E7KDU3\popup[14].htm -> Hijacker.Agent.a : Cleaned with backup (quarantined).
C:\Documents and Settings\Kaucher.MY-F78BF48CE2\Local Settings\Temporary Internet Files\Content.IE5\W9E7KDU3\popup[15].htm -> Hijacker.Agent.a : Cleaned with backup (quarantined).
C:\Documents and Settings\Kaucher.MY-F78BF48CE2\Local Settings\Temporary Internet Files\Content.IE5\W9E7KDU3\popup[16].htm -> Hijacker.Agent.a : Cleaned with backup (quarantined).
C:\Documents and Settings\Kaucher.MY-F78BF48CE2\Local Settings\Temporary Internet Files\Content.IE5\W9E7KDU3\popup[17].htm -> Hijacker.Agent.a : Cleaned with backup (quarantined).
C:\Documents and Settings\Kaucher.MY-F78BF48CE2\Local Settings\Temporary Internet Files\Content.IE5\W9E7KDU3\popup[18].htm -> Hijacker.Agent.a : Cleaned with backup (quarantined).
C:\Documents and Settings\Kaucher.MY-F78BF48CE2\Local Settings\Temporary Internet Files\Content.IE5\W9E7KDU3\popup[19].htm -> Hijacker.Agent.a : Cleaned with backup (quarantined).
C:\Documents and Settings\Kaucher.MY-F78BF48CE2\Local Settings\Temporary Internet Files\Content.IE5\W9E7KDU3\popup[1].htm -> Hijacker.Agent.a : Cleaned with backup (quarantined).
C:\Documents and Settings\Kaucher.MY-F78BF48CE2\Local Settings\Temporary Internet Files\Content.IE5\W9E7KDU3\popup[20].htm -> Hijacker.Agent.a : Cleaned with backup (quarantined).
C:\Documents and Settings\Kaucher.MY-F78BF48CE2\Local Settings\Temporary Internet Files\Content.IE5\W9E7KDU3\popup[21].htm -> Hijacker.Agent.a : Cleaned with backup (quarantined).
C:\Documents and Settings\Kaucher.MY-F78BF48CE2\Local Settings\Temporary Internet Files\Content.IE5\W9E7KDU3\popup[22].htm -> Hijacker.Agent.a : Cleaned with backup (quarantined).
C:\Documents and Settings\Kaucher.MY-F78BF48CE2\Local Settings\Temporary Internet Files\Content.IE5\W9E7KDU3\popup[23].htm -> Hijacker.Agent.a : Cleaned with backup (quarantined).
C:\Documents and Settings\Kaucher.MY-F78BF48CE2\Local Settings\Temporary Internet Files\Content.IE5\W9E7KDU3\popup[24].htm -> Hijacker.Agent.a : Cleaned with backup (quarantined).
C:\Documents and Settings\Kaucher.MY-F78BF48CE2\Local Settings\Temporary Internet Files\Content.IE5\W9E7KDU3\popup[25].htm -> Hijacker.Agent.a : Cleaned with backup (quarantined).
C:\Documents and Settings\Kaucher.MY-F78BF48CE2\Local Settings\Temporary Internet Files\Content.IE5\W9E7KDU3\popup[26].htm -> Hijacker.Agent.a : Cleaned with backup (quarantined).
C:\Documents and Settings\Kaucher.MY-F78BF48CE2\Local Settings\Temporary Internet Files\Content.IE5\W9E7KDU3\popup[27].htm -> Hijacker.Agent.a : Cleaned with backup (quarantined).
C:\Documents and Settings\Kaucher.MY-F78BF48CE2\Local Settings\Temporary Internet Files\Content.IE5\W9E7KDU3\popup[28].htm -> Hijacker.Agent.a : Cleaned with backup (quarantined).
C:\Documents and Settings\Kaucher.MY-F78BF48CE2\Local Settings\Temporary Internet Files\Content.IE5\W9E7KDU3\popup[29].htm -> Hijacker.Agent.a : Cleaned with backup (quarantined).
C:\Documents and Settings\Kaucher.MY-F78BF48CE2\Local Settings\Temporary Internet Files\Content.IE5\W9E7KDU3\popup[2].htm -> Hijacker.Agent.a : Cleaned with backup (quarantined).
C:\Documents and Settings\Kaucher.MY-F78BF48CE2\Local Settings\Temporary Internet Files\Content.IE5\W9E7KDU3\popup[30].htm -> Hijacker.Agent.a : Cleaned with backup (quarantined).
C:\Documents and Settings\Kaucher.MY-F78BF48CE2\Local Settings\Temporary Internet Files\Content.IE5\W9E7KDU3\popup[31].htm -> Hijacker.Agent.a : Cleaned with backup (quarantined).
C:\Documents and Settings\Kaucher.MY-F78BF48CE2\Local Settings\Temporary Internet Files\Content.IE5\W9E7KDU3\popup[32].htm -> Hijacker.Agent.a : Cleaned with backup (quarantined).
C:\Documents and Settings\Kaucher.MY-F78BF48CE2\Local Settings\Temporary Internet Files\Content.IE5\W9E7KDU3\popup[33].htm -> Hijacker.Agent.a : Cleaned with backup (quarantined).
C:\Documents and Settings\Kaucher.MY-F78BF48CE2\Local Settings\Temporary Internet Files\Content.IE5\W9E7KDU3\popup[34].htm -> Hijacker.Agent.a : Cleaned with backup (quarantined).
C:\Documents and Settings\Kaucher.MY-F78BF48CE2\Local Settings\Temporary Internet Files\Content.IE5\W9E7KDU3\popup[35].htm -> Hijacker.Agent.a : Cleaned with backup (quarantined).
C:\Documents and Settings\Kaucher.MY-F78BF48CE2\Local Settings\Temporary Internet Files\Content.IE5\W9E7KDU3\popup[36].htm -> Hijacker.Agent.a : Cleaned with backup (quarantined).
C:\Documents and Settings\Kaucher.MY-F78BF48CE2\Local Settings\Temporary Internet Files\Content.IE5\W9E7KDU3\popup[37].htm -> Hijacker.Agent.a : Cleaned with backup (quarantined).
C:\Documents and Settings\Kaucher.MY-F78BF48CE2\Local Settings\Temporary Internet Files\Content.IE5\W9E7KDU3\popup[38].htm -> Hijacker.Agent.a : Cleaned with backup (quarantined).
C:\Documents and Settings\Kaucher.MY-F78BF48CE2\Local Settings\Temporary Internet Files\Content.IE5\W9E7KDU3\popup[39].htm -> Hijacker.Agent.a : Cleaned with backup (quarantined).
C:\Documents and Settings\Kaucher.MY-F78BF48CE2\Local Settings\Temporary Internet Files\Content.IE5\W9E7KDU3\popup[3].htm -> Hijacker.Agent.a : Cleaned with backup (quarantined).
C:\Documents and Settings\Kaucher.MY-F78BF48CE2\Local Settings\Temporary Internet Files\Content.IE5\W9E7KDU3\popup[40].htm -> Hijacker.Agent.a : Cleaned with backup (quarantined).
C:\Documents and Settings\Kaucher.MY-F78BF48CE2\Local Settings\Temporary Internet Files\Content.IE5\W9E7KDU3\popup[4].htm -> Hijacker.Agent.a : Cleaned with backup (quarantined).
C:\Documents and Settings\Kaucher.MY-F78BF48CE2\Local Settings\Temporary Internet Files\Content.IE5\W9E7KDU3\popup[5].htm -> Hijacker.Agent.a : Cleaned with backup (quarantined).
C:\Documents and Settings\Kaucher.MY-F78BF48CE2\Local Settings\Temporary Internet Files\Content.IE5\W9E7KDU3\popup[6].htm -> Hijacker.Agent.a : Cleaned with backup (quarantined).
C:\Documents and Settings\Kaucher.MY-F78BF48CE2\Local Settings\Temporary Internet Files\Content.IE5\W9E7KDU3\popup[7].htm -> Hijacker.Agent.a : Cleaned with backup (quarantined).
C:\Documents and Settings\Kaucher.MY-F78BF48CE2\Local Settings\Temporary Internet Files\Content.IE5\W9E7KDU3\popup[8].htm -> Hijacker.Agent.a : Cleaned with backup (quarantined).
C:\Documents and Settings\Kaucher.MY-F78BF48CE2\Local Settings\Temporary Internet Files\Content.IE5\W9E7KDU3\popup[9].htm -> Hijacker.Agent.a : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0004251.exe -> Hijacker.Small : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0004248.exe -> Hijacker.VB.ij : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0004249.exe -> Hijacker.VB.ij : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0004213.exe -> Hijacker.VB.ly : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP17\A0014520.exe -> Not-A-Virus.Hoax.Win32.Renos.eo : Cleaned with backup (quarantined).
:mozilla.103:C:\Documents and Settings\Kaucher.MY-F78BF48CE2\Application Data\Mozilla\Firefox\Profiles\teoqfp38.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.110:C:\Documents and Settings\Kaucher.MY-F78BF48CE2\Application Data\Mozilla\Firefox\Profiles\teoqfp38.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.123:C:\Documents and Settings\HP_Owner\Application Data\Mozilla\Firefox\Profiles\asb9a5b8.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.199:C:\Documents and Settings\Kaucher.MY-F78BF48CE2\Application Data\Mozilla\Firefox\Profiles\teoqfp38.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.287:C:\Documents and Settings\Kaucher.MY-F78BF48CE2\Application Data\Mozilla\Firefox\Profiles\teoqfp38.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
C:\Documents and Settings\Kaucher.MY-F78BF48CE2\Cookies\kaucher@2o7[2].txt -> TrackingCookie.2o7 : Cleaned.
C:\Documents and Settings\Kaucher.MY-F78BF48CE2\Cookies\kaucher@msnportal.112.2o7[1].txt -> TrackingCookie.2o7 : Cleaned.
C:\Documents and Settings\Kaucher.MY-F78BF48CE2\Cookies\kaucher@partygaming.122.2o7[1].txt -> TrackingCookie.2o7 : Cleaned.
C:\Documents and Settings\Kaucher.MY-F78BF48CE2\Cookies\kaucher@tcompany.122.2o7[1].txt -> TrackingCookie.2o7 : Cleaned.
C:\Documents and Settings\Kaucher.MY-F78BF48CE2\Cookies\kaucher@viamtvcom.112.2o7[2].txt -> TrackingCookie.2o7 : Cleaned.
C:\Documents and Settings\Kaucher\Cookies\kaucher@msnportal.112.2o7[1].txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.29:C:\Documents and Settings\HP_Owner\Application Data\Mozilla\Firefox\Profiles\asb9a5b8.default\cookies.txt -> TrackingCookie.Adbrite : Cleaned.
:mozilla.30:C:\Documents and Settings\HP_Owner\Application Data\Mozilla\Firefox\Profiles\asb9a5b8.default\cookies.txt -> TrackingCookie.Adbrite : Cleaned.
:mozilla.31:C:\Documents and Settings\HP_Owner\Application Data\Mozilla\Firefox\Profiles\asb9a5b8.default\cookies.txt -> TrackingCookie.Adbrite : Cleaned.
:mozilla.112:C:\Documents and Settings\Kaucher.MY-F78BF48CE2\Application Data\Mozilla\Firefox\Profiles\teoqfp38.default\cookies.txt -> TrackingCookie.Adjuggler : Cleaned.
:mozilla.113:C:\Documents and Settings\Kaucher.MY-F78BF48CE2\Application Data\Mozilla\Firefox\Profiles\teoqfp38.default\cookies.txt -> TrackingCookie.Adjuggler : Cleaned.
C:\Documents and Settings\Kaucher.MY-F78BF48CE2\Cookies\kaucher@rotator.adjuggler[1].txt -> TrackingCookie.Adjuggler : Cleaned.
C:\Documents and Settings\Kaucher.MY-F78BF48CE2\Cookies\kaucher@advertising[2].txt -> TrackingCookie.Advertising : Cleaned.
:mozilla.25:C:\Documents and Settings\Kaucher.MY-F78BF48CE2\Application Data\Mozilla\Firefox\Profiles\teoqfp38.default\cookies.txt -> TrackingCookie.Atdmt : Cleaned.
C:\Documents and Settings\HP_Owner\Cookies\hp_owner@atdmt[2].txt -> TrackingCookie.Atdmt : Cleaned.
C:\Documents and Settings\Kaucher.MY-F78BF48CE2\Cookies\kaucher@atdmt[2].txt -> TrackingCookie.Atdmt : Cleaned.
:mozilla.124:C:\Documents and Settings\Kaucher.MY-F78BF48CE2\Application Data\Mozilla\Firefox\Profiles\teoqfp38.default\cookies.txt -> TrackingCookie.Burstbeacon : Cleaned.
C:\Documents and Settings\Kaucher.MY-F78BF48CE2\Cookies\kaucher@www.burstbeacon[1].txt -> TrackingCookie.Burstbeacon : Cleaned.
:mozilla.37:C:\Documents and Settings\HP_Owner\Application Data\Mozilla\Firefox\Profiles\asb9a5b8.default\cookies.txt -> TrackingCookie.Burstnet : Cleaned.
C:\Documents and Settings\Kaucher.MY-F78BF48CE2\Cookies\kaucher@www.burstnet[2].txt -> TrackingCookie.Burstnet : Cleaned.
:mozilla.40:C:\Documents and Settings\HP_Owner\Application Data\Mozilla\Firefox\Profiles\asb9a5b8.default\cookies.txt -> TrackingCookie.Casalemedia : Cleaned.
:mozilla.41:C:\Documents and Settings\HP_Owner\Application Data\Mozilla\Firefox\Profiles\asb9a5b8.default\cookies.txt -> TrackingCookie.Casalemedia : Cleaned.
:mozilla.42:C:\Documents and Settings\HP_Owner\Application Data\Mozilla\Firefox\Profiles\asb9a5b8.default\cookies.txt -> TrackingCookie.Casalemedia : Cleaned.
:mozilla.32:C:\Documents and Settings\HP_Owner\Application Data\Mozilla\Firefox\Profiles\asb9a5b8.default\cookies.txt -> TrackingCookie.Com : Cleaned.
C:\Documents and Settings\Kaucher.MY-F78BF48CE2\Cookies\kaucher@cpvfeed[1].txt -> TrackingCookie.Cpvfeed : Cleaned.
C:\Documents and Settings\HP_Owner\Cookies\hp_owner@doubleclick[1].txt -> TrackingCookie.Doubleclick : Cleaned.
C:\Documents and Settings\Kaucher.MY-F78BF48CE2\Cookies\kaucher@doubleclick[1].txt -> TrackingCookie.Doubleclick : Cleaned.
:mozilla.153:C:\Documents and Settings\Kaucher.MY-F78BF48CE2\Application Data\Mozilla\Firefox\Profiles\teoqfp38.default\cookies.txt -> TrackingCookie.Hitbox : Cleaned.
:mozilla.154:C:\Documents and Settings\Kaucher.MY-F78BF48CE2\Application Data\Mozilla\Firefox\Profiles\teoqfp38.default\cookies.txt -> TrackingCookie.Hitbox : Cleaned.
:mozilla.155:C:\Documents and Settings\Kaucher.MY-F78BF48CE2\Application Data\Mozilla\Firefox\Profiles\teoqfp38.default\cookies.txt -> TrackingCookie.Hitbox : Cleaned.
:mozilla.156:C:\Documents and Settings\Kaucher.MY-F78BF48CE2\Application Data\Mozilla\Firefox\Profiles\teoqfp38.default\cookies.txt -> TrackingCookie.Hitbox : Cleaned.
:mozilla.157:C:\Documents and Settings\Kaucher.MY-F78BF48CE2\Application Data\Mozilla\Firefox\Profiles\teoqfp38.default\cookies.txt -> TrackingCookie.Hitbox : Cleaned.
:mozilla.158:C:\Documents and Settings\Kaucher.MY-F78BF48CE2\Application Data\Mozilla\Firefox\Profiles\teoqfp38.default\cookies.txt -> TrackingCookie.Hitbox : Cleaned.
:mozilla.159:C:\Documents and Settings\Kaucher.MY-F78BF48CE2\Application Data\Mozilla\Firefox\Profiles\teoqfp38.default\cookies.txt -> TrackingCookie.Hitbox : Cleaned.
:mozilla.160:C:\Documents and Settings\Kaucher.MY-F78BF48CE2\Application Data\Mozilla\Firefox\Profiles\teoqfp38.default\cookies.txt -> TrackingCookie.Hitbox : Cleaned.
C:\Documents and Settings\Kaucher.MY-F78BF48CE2\Cookies\kaucher@ehg-dig.hitbox[2].txt -> TrackingCookie.Hitbox : Cleaned.
:mozilla.111:C:\Documents and Settings\Kaucher.MY-F78BF48CE2\Application Data\Mozilla\Firefox\Profiles\teoqfp38.default\cookies.txt -> TrackingCookie.Liveperson : Cleaned.
:mozilla.161:C:\Documents and Settings\Kaucher.MY-F78BF48CE2\Application Data\Mozilla\Firefox\Profiles\teoqfp38.default\cookies.txt -> TrackingCookie.Liveperson : Cleaned.
:mozilla.209:C:\Documents and Settings\Kaucher.MY-F78BF48CE2\Application Data\Mozilla\Firefox\Profiles\teoqfp38.default\cookies.txt -> TrackingCookie.Liveperson : Cleaned.
:mozilla.210:C:\Documents and Settings\Kaucher.MY-F78BF48CE2\Application Data\Mozilla\Firefox\Profiles\teoqfp38.default\cookies.txt -> TrackingCookie.Liveperson : Cleaned.
C:\Documents and Settings\Kaucher.MY-F78BF48CE2\Cookies\kaucher@server.lon.liveperson[1].txt -> TrackingCookie.Liveperson : Cleaned.
:mozilla.142:C:\Documents and Settings\Kaucher.MY-F78BF48CE2\Application Data\Mozilla\Firefox\Profiles\teoqfp38.default\cookies.txt -> TrackingCookie.Masterstats : Cleaned.
C:\Documents and Settings\Kaucher.MY-F78BF48CE2\Cookies\kaucher@image.masterstats[1].txt -> TrackingCookie.Masterstats : Cleaned.
C:\Documents and Settings\HP_Owner\Cookies\hp_owner@mediaplex[1].txt -> TrackingCookie.Mediaplex : Cleaned.
C:\Documents and Settings\Kaucher.MY-F78BF48CE2\Cookies\kaucher@www.myaffiliateprogram[1].txt -> TrackingCookie.Myaffiliateprogram : Cleaned.
C:\Documents and Settings\HP_Owner\Cookies\hp_owner@perf.overture[1].txt -> TrackingCookie.Overture : Cleaned.
C:\Documents and Settings\Kaucher.MY-F78BF48CE2\Cookies\kaucher@ads.pointroll[2].txt -> TrackingCookie.Pointroll : Cleaned.
:mozilla.124:C:\Documents and Settings\HP_Owner\Application Data\Mozilla\Firefox\Profiles\asb9a5b8.default\cookies.txt -> TrackingCookie.Questionmarket : Cleaned.
:mozilla.125:C:\Documents and Settings\HP_Owner\Application Data\Mozilla\Firefox\Profiles\asb9a5b8.default\cookies.txt -> TrackingCookie.Questionmarket : Cleaned.
C:\Documents and Settings\Kaucher.MY-F78BF48CE2\Cookies\kaucher@stats1.reliablestats[1].txt -> TrackingCookie.Reliablestats : Cleaned.
:mozilla.136:C:\Documents and Settings\HP_Owner\Application Data\Mozilla\Firefox\Profiles\asb9a5b8.default\cookies.txt -> TrackingCookie.Revenue : Cleaned.
:mozilla.137:C:\Documents and Settings\HP_Owner\Application Data\Mozilla\Firefox\Profiles\asb9a5b8.default\cookies.txt -> TrackingCookie.Revenue : Cleaned.
C:\Documents and Settings\Kaucher.MY-F78BF48CE2\Cookies\kaucher@edge.ru4[1].txt -> TrackingCookie.Ru4 : Cleaned.
:mozilla.78:C:\Documents and Settings\HP_Owner\Application Data\Mozilla\Firefox\Profiles\asb9a5b8.default\cookies.txt -> TrackingCookie.Sexcounter : Cleaned.
:mozilla.79:C:\Documents and Settings\HP_Owner\Application Data\Mozilla\Firefox\Profiles\asb9a5b8.default\cookies.txt -> TrackingCookie.Sexcounter : Cleaned.
:mozilla.197:C:\Documents and Settings\Kaucher.MY-F78BF48CE2\Application Data\Mozilla\Firefox\Profiles\teoqfp38.default\cookies.txt -> TrackingCookie.Specificclick : Cleaned.
:mozilla.198:C:\Documents and Settings\Kaucher.MY-F78BF48CE2\Application Data\Mozilla\Firefox\Profiles\teoqfp38.default\cookies.txt -> TrackingCookie.Specificclick : Cleaned.
C:\Documents and Settings\Kaucher.MY-F78BF48CE2\Cookies\kaucher@adopt.specificclick[2].txt -> TrackingCookie.Specificclick : Cleaned.
:mozilla.227:C:\Documents and Settings\Kaucher.MY-F78BF48CE2\Application Data\Mozilla\Firefox\Profiles\teoqfp38.default\cookies.txt -> TrackingCookie.Starware : Cleaned.
:mozilla.228:C:\Documents and Settings\Kaucher.MY-F78BF48CE2\Application Data\Mozilla\Firefox\Profiles\teoqfp38.default\cookies.txt -> TrackingCookie.Starware : Cleaned.
:mozilla.50:C:\Documents and Settings\Kaucher.MY-F78BF48CE2\Application Data\Mozilla\Firefox\Profiles\teoqfp38.default\cookies.txt -> TrackingCookie.Starware : Cleaned.
C:\Documents and Settings\Kaucher.MY-F78BF48CE2\Cookies\kaucher@h.starware[2].txt -> TrackingCookie.Starware : Cleaned.
C:\Documents and Settings\Kaucher.MY-F78BF48CE2\Cookies\kaucher@try.starware[1].txt -> TrackingCookie.Starware : Cleaned.
C:\Documents and Settings\Kaucher\Cookies\kaucher@anad.tacoda[1].txt -> TrackingCookie.Tacoda : Cleaned.
:mozilla.136:C:\Documents and Settings\Kaucher.MY-F78BF48CE2\Application Data\Mozilla\Firefox\Profiles\teoqfp38.default\cookies.txt -> TrackingCookie.Web-stat : Cleaned.
:mozilla.137:C:\Documents and Settings\Kaucher.MY-F78BF48CE2\Application Data\Mozilla\Firefox\Profiles\teoqfp38.default\cookies.txt -> TrackingCookie.Web-stat : Cleaned.
:mozilla.26:C:\Documents and Settings\Kaucher.MY-F78BF48CE2\Application Data\Mozilla\Firefox\Profiles\teoqfp38.default\cookies.txt -> TrackingCookie.Web-stat : Cleaned.
C:\Documents and Settings\Kaucher.MY-F78BF48CE2\Cookies\kaucher@webstat[1].txt -> TrackingCookie.Web-stat : Cleaned.
:mozilla.106:C:\Documents and Settings\HP_Owner\Application Data\Mozilla\Firefox\Profiles\asb9a5b8.default\cookies.txt -> TrackingCookie.Yadro : Cleaned.
:mozilla.107:C:\Documents and Settings\HP_Owner\Application Data\Mozilla\Firefox\Profiles\asb9a5b8.default\cookies.txt -> TrackingCookie.Yadro : Cleaned.
:mozilla.25:C:\Documents and Settings\HP_Owner\Application Data\Mozilla\Firefox\Profiles\asb9a5b8.default\cookies.txt -> TrackingCookie.Yieldmanager : Cleaned.
:mozilla.26:C:\Documents and Settings\HP_Owner\Application Data\Mozilla\Firefox\Profiles\asb9a5b8.default\cookies.txt -> TrackingCookie.Yieldmanager : Cleaned.
:mozilla.27:C:\Documents and Settings\HP_Owner\Application Data\Mozilla\Firefox\Profiles\asb9a5b8.default\cookies.txt -> TrackingCookie.Yieldmanager : Cleaned.
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0004301.exe -> Trojan.Qoologic : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0004259.exe -> Trojan.VB.tg : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0004299.exe -> Trojan.VB.tg : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0004300.exe -> Trojan.VB.tg : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0002784.exe -> Worm.VB.dw : Cleaned with backup (quarantined).
::Report end
|
Clamp1
Newbie
|
21. October 2006 @ 14:48 |
Link to this message
|
This message has been edited since posting. Last time this message was edited on 22. October 2006 @ 09:11
|
Senior Member
|
21. October 2006 @ 17:08 |
Link to this message
|
I seen the AVGAS report. Please edit those two posts, it makes the thread long and hard to navigate for no reason.
I posted the next instructions earlier. Please follow them to get rid of Qoologic.
Here's a quick link to find them.
http://forums.afterdawn.com/thread_jump.cfm/408854/2476210
|
Clamp1
Newbie
|
22. October 2006 @ 08:57 |
Link to this message
|
Niobis I cant get qoofix.bat I dont know why. I try to get it but the website says HTTP 404 Not Found.
This message has been edited since posting. Last time this message was edited on 22. October 2006 @ 09:14
|
Clamp1
Newbie
|
22. October 2006 @ 10:29 |
Link to this message
|
I cant find qoofix.bat anywhere. Can you tell me where it is.
This message has been edited since posting. Last time this message was edited on 22. October 2006 @ 10:51
|
Senior Member
|
22. October 2006 @ 12:36 |
Link to this message
|
Sorry about that, that fix is outdated. You may delete/uninstall BFU.
Here's the new fix for Qoo.
Please download Qoofix by RubbeR DuckY from one of the following locations:
http://www.malwarebytes.org/Qoofix.zip or
http://www.besttechie.net/tools/Qoofix.zip
* Unzip all files to a convenient location such as C:\Qoofix.
* Go to the folder you unzipped all files and run Qoofix.exe.
* Click Begin Removal and wait for the scan to finish.
* If an infection has been found, select Yes to restart your computer.
Post back with the Qoofix log and a new HijackThis log.
This message has been edited since posting. Last time this message was edited on 22. October 2006 @ 12:38
|
Clamp1
Newbie
|
23. October 2006 @ 09:58 |
Link to this message
|
Here is the Qoolfix log.
Qoofix v1.03 by http://www.malwarebytes.org
Scan started on [10/23/2006] at [1:48:52 PM]
-------------------------------------------------------------
No malicious modules found!
-------------------------------------------------------------
No Qoologic infected files found!
-------------------------------------------------------------
Scan COMPLETED SUCCESSFULLY on [10/23/2006] at [1:50:34 PM]
Note: Some registry keys may have been removed.
|
Clamp1
Newbie
|
23. October 2006 @ 10:01 |
Link to this message
|
Here is the HijackThis log.
Logfile of HijackThis v1.99.1
Scan saved at 1:59:05 PM, on 10/23/2006
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\hkcmd.exe
C:\Program Files\Hewlett-Packard\HP Boot Optimizer\HPBootOp.exe
C:\Program Files\Lexmark 2300 Series\ezprint.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\Program Files\QuickTime\qttask.exe
C:\Program Files\Java\jre1.5.0_06\bin\jusched.exe
C:\Program Files\Webroot\Spy Sweeper\SpySweeperUI.exe
C:\Program Files\CA\eTrust EZ Armor\eTrust Anti-Spam\QSP-2.1.215.5\QOELoader.exe
C:\Program Files\CA\eTrust EZ Armor\eTrust EZ Antivirus\CAVTray.exe
C:\Program Files\CA\eTrust EZ Armor\eTrust EZ Antivirus\CAVRID.exe
C:\Program Files\CA\eTrust EZ Armor\eTrust EZ Firewall\ca.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Messenger\msmsgs.exe
C:\Program Files\America Online 9.0d\aoltray.exe
C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
C:\Program Files\Updates from HP\309731\Program\Updates from HP.exe
C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe
C:\Program Files\Sony\Sony Picture Utility\VolumeWatcher\SPUVolumeWatcher.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
C:\Program Files\CA\eTrust EZ Armor\eTrust EZ Antivirus\ISafe.exe
c:\Program Files\Common Files\LightScribe\LSSrvc.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\WINDOWS\system32\HPZipm12.exe
C:\WINDOWS\system32\tcpsvcs.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\CA\eTrust EZ Armor\eTrust EZ Antivirus\VetMsg.exe
C:\WINDOWS\system32\ZoneLabs\vsmon.exe
C:\Program Files\Webroot\Spy Sweeper\SpySweeper.exe
c:\Program Files\Common Files\Symantec Shared\Security Center\SymWSC.exe
C:\WINDOWS\system32\wuauclt.exe
C:\WINDOWS\system32\lxcgcoms.exe
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\PROGRA~1\Yahoo!\COMPAN~1\Installs\cpn1\YTBSDK.exe
C:\Program Files\Google\GoogleToolbarNotifier\1.2.908.5008\GoogleToolbarNotifier.exe
C:\Documents and Settings\HP_Owner\Desktop\HijackThis_v1.99.1.exe
C:\Program Files\Symantec\LiveUpdate\AUpdate.exe
R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://ie.redirect.hp.com/svs/rdr?TYPE=3...lion&pf=desktop
R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn1\yt.dll
O2 - BHO: Yahoo! Toolbar Helper - {02478D38-C3F9-4EFB-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn1\yt.dll
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar5.dll
O3 - Toolbar: HP view - {B2847E28-5D7D-4DEB-8B67-05D28BCF79F5} - c:\Program Files\HP\Digital Imaging\bin\HPDTLK02.dll
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn1\yt.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar5.dll
O4 - HKLM\..\Run: [High Definition Audio Property Page Shortcut] HDAudPropShortcut.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\system32\hkcmd.exe
O4 - HKLM\..\Run: [HPBootOp] "C:\Program Files\Hewlett-Packard\HP Boot Optimizer\HPBootOp.exe" /run
O4 - HKLM\..\Run: [_SetRes] c:\hp\bin\cloaker c:\hp\bin\res.bat
O4 - HKLM\..\Run: [IcoSet] "c:\hp\bin\cloaker.exe" c:\hp\bin\IcoSet\adjust.bat seticon
O4 - HKLM\..\Run: [LSBWatcher] c:\hp\drivers\hplsbwatcher\lsburnwatcher.exe
O4 - HKLM\..\Run: [lxcgmon.exe] "C:\Program Files\Lexmark 2300 Series\lxcgmon.exe"
O4 - HKLM\..\Run: [EzPrint] "C:\Program Files\Lexmark 2300 Series\ezprint.exe"
O4 - HKLM\..\Run: [FaxCenterServer] "C:\Program Files\Lexmark Fax Solutions\fm3032.exe" /s
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.5.0_06\bin\jusched.exe"
O4 - HKLM\..\Run: [LXCGCATS] rundll32 C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\LXCGtime.dll,_RunDLLEntry@16
O4 - HKLM\..\Run: [SpySweeper] "C:\Program Files\Webroot\Spy Sweeper\SpySweeperUI.exe" /startintray
O4 - HKLM\..\Run: [QOELOADER] "C:\Program Files\CA\eTrust EZ Armor\eTrust Anti-Spam\QSP-2.1.215.5\QOELoader.exe"
O4 - HKLM\..\Run: [CaAvTray] "C:\Program Files\CA\eTrust EZ Armor\eTrust EZ Antivirus\CAVTray.exe"
O4 - HKLM\..\Run: [CAVRID] "C:\Program Files\CA\eTrust EZ Armor\eTrust EZ Antivirus\CAVRID.exe"
O4 - HKLM\..\Run: [Zone Labs Client] "C:\Program Files\CA\eTrust EZ Armor\eTrust EZ Firewall\ca.exe"
O4 - HKLM\..\Run: [!AVG Anti-Spyware] "C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" /minimized
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [swg] "C:\Program Files\Google\GoogleToolbarNotifier\1.0.720.3640\GoogleToolbarNotifier.exe"
O4 - Startup: Cyber-shot Viewer Media Check Tool.lnk = C:\Program Files\Sony\Sony Picture Utility\VolumeWatcher\SPUVolumeWatcher.exe
O4 - Startup: HP Organize.lnk = ?
O4 - Global Startup: America Online 9.0 Tray Icon.lnk = C:\Program Files\America Online 9.0d\aoltray.exe
O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
O4 - Global Startup: SpySubtract.lnk = C:\Program Files\InterMute\SpySubtract\sslaunch.exe
O4 - Global Startup: Updates from HP.lnk = C:\Program Files\Updates from HP\309731\Program\Updates from HP.exe
O8 - Extra context menu item: &Search - http://kl.bar.need2find.com/KL/menusearch.html?p=KL
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MI1933~1\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MI1933~1\OFFICE11\REFIEBAR.DLL
O9 - Extra button: Connection Help - {E2D4D26B-0180-43a4-B05F-462D6D54C789} - C:\WINDOWS\PCHEALTH\HELPCTR\Vendors\CN=Hewlett-Packard,L=Cupertino,S=Ca,C=US\IEButton\support.htm
O9 - Extra 'Tools' menuitem: Connection Help - {E2D4D26B-0180-43a4-B05F-462D6D54C789} - C:\WINDOWS\PCHEALTH\HELPCTR\Vendors\CN=Hewlett-Packard,L=Cupertino,S=Ca,C=US\IEButton\support.htm
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra button: Connection Help - {E2D4D26B-0180-43a4-B05F-462D6D54C789} - C:\WINDOWS\PCHEALTH\HELPCTR\Vendors\CN=Hewlett-Packard,L=Cupertino,S=Ca,C=US\IEButton\support.htm (HKCU)
O9 - Extra 'Tools' menuitem: Connection Help - {E2D4D26B-0180-43a4-B05F-462D6D54C789} - C:\WINDOWS\PCHEALTH\HELPCTR\Vendors\CN=Hewlett-Packard,L=Cupertino,S=Ca,C=US\IEButton\support.htm (HKCU)
O15 - Trusted Zone: ww.rr.com
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?LinkID=39204
O20 - Winlogon Notify: igfxcui - C:\WINDOWS\SYSTEM32\igfxsrvc.dll
O20 - Winlogon Notify: WRNotifier - C:\WINDOWS\SYSTEM32\WRLogonNTF.dll
O20 - Winlogon Notify: yvbb01 - yvbb01.dll (file missing)
O21 - SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll
O23 - Service: Automatic LiveUpdate Scheduler - Symantec Corporation - C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe
O23 - Service: AVG Anti-Spyware Guard - Anti-Malware Development a.s. - C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
O23 - Service: CAISafe - Computer Associates International, Inc. - C:\Program Files\CA\eTrust EZ Armor\eTrust EZ Antivirus\ISafe.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe
O23 - Service: iPod Service (iPodService) - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - c:\Program Files\Common Files\LightScribe\LSSrvc.exe
O23 - Service: LiveUpdate - Symantec Corporation - C:\PROGRA~1\Symantec\LIVEUP~1\LUCOMS~1.EXE
O23 - Service: lxcg_device - - C:\WINDOWS\system32\lxcgcoms.exe
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe
O23 - Service: SymWMI Service (SymWSC) - Symantec Corporation - c:\Program Files\Common Files\Symantec Shared\Security Center\SymWSC.exe
O23 - Service: VET Message Service (VETMSGNT) - Computer Associates International, Inc. - C:\Program Files\CA\eTrust EZ Armor\eTrust EZ Antivirus\VetMsg.exe
O23 - Service: TrueVector Internet Monitor (vsmon) - Zone Labs Inc. - C:\WINDOWS\system32\ZoneLabs\vsmon.exe
O23 - Service: Webroot Spy Sweeper Engine (WebrootSpySweeperService) - Webroot Software, Inc. - C:\Program Files\Webroot\Spy Sweeper\SpySweeper.exe
|
Senior Member
|
23. October 2006 @ 14:10 |
Link to this message
|
No Qoo files found, but it's not in the log anymore. :)
Turn off the real-time protection of AVGAS since you already had SpySweeper. Or you may uninstall it.
Turn off SpySweepers Shields becasue it may interfere with these fixes.
Open SpySweeper.
Click Shield Settings on the right
(or Shields on the left, depending what screen you're on).
Click Internet Explorer and uncheck all items.
Click Windows System and uncheck all items.
Click Hosts File and uncheck all items.
Click Startup Programs and uncheck all items.
Close SpySweeper.
Run a scan only with HijackThis, check these:
R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://ie.redirect.hp.com/svs/rdr?TYPE=3...lion&pf=desktop
O8 - Extra context menu item: &Search - http://kl.bar.need2find.com/KL/menusearch.html?p=KL
O15 - Trusted Zone: ww.rr.com
O20 - Winlogon Notify: yvbb01 - yvbb01.dll (file missing)
Close all windows except HijackThis, then click "Fix checked".
Close HijackThis.
Turn off System Restore.
Right click My Computer > Properties > System Restore tab > check "Turn off System Restore".
Go here and run Kaspersky Online Scanner.
Accept the terms.
After downloading, click "My Computer".
After scanning, click "Save report as".
Save as a text file and post it here along with a new HijackThis log.
|
Clamp1
Newbie
|
24. October 2006 @ 17:11 |
Link to this message
|
Here is the Kaspersky Report.
-------------------------------------------------------------------------------
KASPERSKY ONLINE SCANNER REPORT
Tuesday, October 24, 2006 9:09:57 PM
Operating System: Microsoft Windows XP Home Edition, Service Pack 2 (Build 2600)
Kaspersky Online Scanner version: 5.0.83.0
Kaspersky Anti-Virus database last update: 25/10/2006
Kaspersky Anti-Virus database records: 221217
-------------------------------------------------------------------------------
Scan Settings:
Scan using the following antivirus database: standard
Scan Archives: true
Scan Mail Bases: true
Scan Target - My Computer:
C:\
D:\
E:\
F:\
G:\
H:\
I:\
Scan Statistics:
Total number of scanned objects: 105388
Number of viruses found: 1
Number of infected objects: 1 / 0
Number of suspicious objects: 0
Duration of the scan process: 01:34:09
Infected Object Name / Virus Name / Last Action
C:\23100247.exe Infected: Trojan-Downloader.Win32.Small.dwn skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\19e26cec064e9195496f0b92ff8bcf4b_a428afe7-50b8-4162-b914-dcf91c784d8a Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\511a0f3f9e960fa97de3d0b74adfc574_a428afe7-50b8-4162-b914-dcf91c784d8a Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\54452f224c92ccdf01d600d04864a4dc_a428afe7-50b8-4162-b914-dcf91c784d8a Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Dr Watson\user.dmp Object is locked skipped
C:\Documents and Settings\All Users\Application Data\muvee Technologies\030625\scratch\ERRSTAT.HTM Object is locked skipped
C:\Documents and Settings\All Users\Application Data\muvee Technologies\030625\scratch\Sample_Picture03.jpg.41b2b144.180.mtn Object is locked skipped
C:\Documents and Settings\All Users\Application Data\muvee Technologies\030625\scratch\Sample_Picture03.jpg.41b2b144.270.mtn Object is locked skipped
C:\Documents and Settings\All Users\Application Data\muvee Technologies\030625\scratch\Sample_Picture03.jpg.41b2b144.90.mtn Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Symantec\LiveUpdate\2006-10-24_Log.ALUSchedulerSvc.LiveUpdate Object is locked skipped
C:\Documents and Settings\HP_Owner\Application Data\Webroot\Spy Sweeper\Logs\061002020006.ses Object is locked skipped
C:\Documents and Settings\HP_Owner\Cookies\index.dat Object is locked skipped
C:\Documents and Settings\HP_Owner\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat Object is locked skipped
C:\Documents and Settings\HP_Owner\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped
C:\Documents and Settings\HP_Owner\Local Settings\History\History.IE5\index.dat Object is locked skipped
C:\Documents and Settings\HP_Owner\Local Settings\History\History.IE5\MSHist012006102420061025\index.dat Object is locked skipped
C:\Documents and Settings\HP_Owner\Local Settings\Temp\hpodvd09.log Object is locked skipped
C:\Documents and Settings\HP_Owner\Local Settings\Temporary Internet Files\Content.IE5\index.dat Object is locked skipped
C:\Documents and Settings\HP_Owner\NTUSER.DAT Object is locked skipped
C:\Documents and Settings\HP_Owner\ntuser.dat.LOG Object is locked skipped
C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Data\settings.dat Object is locked skipped
C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSCS058FD4A4-A4AE-4BC4-AD38-F02AD75E60C3.tmp Object is locked skipped
C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSCS06CCEDB2-1EEA-4A91-9081-87A5F1CB82EC.tmp Object is locked skipped
C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSCS0825A652-5A62-4080-AF5E-EB18E3735B33.tmp Object is locked skipped
C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSCS091BE407-C8B7-4D2D-9450-EFE19A6D0266.tmp Object is locked skipped
C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSCS0A834399-A7A5-4031-9F98-0F6D6092EF9B.tmp Object is locked skipped
C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSCS0BC89914-4586-452B-9BD9-E534FF115DD6.tmp Object is locked skipped
C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSCS0C7B999C-27B9-4048-9C80-7162D8F3C943.tmp Object is locked skipped
C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSCS0D2B9A24-1C0F-467D-897E-354AAF1E3222.tmp Object is locked skipped
C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSCS10A2E07E-D3EE-428D-A8AF-6FCE9FD017FA.tmp Object is locked skipped
C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSCS13DB7599-D733-4C36-B5C5-ABB6D501CC1F.tmp Object is locked skipped
C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSCS1418C20B-3803-4572-9B4D-4C43CB4B9166.tmp Object is locked skipped
C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSCS1439DE42-F404-43B9-84ED-C5B1B039B49C.tmp Object is locked skipped
C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSCS15275E55-575B-4A48-A008-29BA897A1690.tmp Object is locked skipped
C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSCS16FB6637-9464-42B7-AC03-48F42E61F784.tmp Object is locked skipped
C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSCS1D5AEE7D-7CB0-4FD8-90AE-BC5D97032E97.tmp Object is locked skipped
C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSCS1F4BD168-9A6D-4A03-B905-965CFA890E8E.tmp Object is locked skipped
C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSCS20EC39FB-02CE-4C76-8E5C-F8F7C1728DD2.tmp Object is locked skipped
C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSCS2197C2E3-6B4C-47B1-B922-017270F51A41.tmp Object is locked skipped
C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSCS281274CB-424A-4B78-87F5-23A6D8918CD7.tmp Object is locked skipped
C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSCS2B0C0419-8D66-4FF2-A459-09678197C3F0.tmp Object is locked skipped
C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSCS3D069ADD-05BB-4CA7-BB96-7393F932891D.tmp Object is locked skipped
C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSCS3DF9CDC5-D219-424B-8F18-58638E83DC8C.tmp Object is locked skipped
C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSCS3ECBBCF1-AD2B-455B-BF64-8148E7DE3137.tmp Object is locked skipped
C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSCS4156F605-A0D9-48AC-AC6E-FDF8E090E1CD.tmp Object is locked skipped
C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSCS43A5B36A-0561-4769-AFF2-C97887A7E783.tmp Object is locked skipped
C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSCS4D105F8F-B9D9-4A87-AA28-B068F433796B.tmp Object is locked skipped
C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSCS4ECF14FB-AF7B-4491-83C7-B7AAB9264C08.tmp Object is locked skipped
C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSCS559154D7-476A-4265-9A13-48684B8DC33F.tmp Object is locked skipped
C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSCS5B7D366C-05AC-41D6-933E-B7706983BD76.tmp Object is locked skipped
C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSCS5C7C2388-2777-49F4-B599-68DA1BFCF1A8.tmp Object is locked skipped
C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSCS5E67CF64-1F0A-4610-969B-CCE51442063B.tmp Object is locked skipped
C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSCS5E6E13B5-0B87-43A8-85CD-5E2EE80B4852.tmp Object is locked skipped
C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSCS639A69D8-3C07-4326-AA71-79FD0D8995B0.tmp Object is locked skipped
C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSCS64E8ED99-AC27-44B6-8DA9-14C8810451AA.tmp Object is locked skipped
C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSCS654F3972-9EDC-4153-93E4-A3E573047C1C.tmp Object is locked skipped
C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSCS67B0214B-7EE7-4108-8CBF-24F1FAAA62F9.tmp Object is locked skipped
C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSCS67D2050B-1F89-4C80-BE00-CC0FB081B75A.tmp Object is locked skipped
C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSCS6AC3F18A-DC63-4A7F-8433-09CB0B1420B1.tmp Object is locked skipped
C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSCS6B21402C-248D-4757-B548-DFC66C2AFBB0.tmp Object is locked skipped
C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSCS6C64710A-2E66-4B42-93A9-735F8A2DD425.tmp Object is locked skipped
C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSCS6D1A22FC-10FF-430B-BE03-477317E43EDA.tmp Object is locked skipped
C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSCS70210296-00D2-40E2-AA7E-9421A570DEDA.tmp Object is locked skipped
C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSCS703062EF-BCAB-4450-ABD3-6C28F1822CC6.tmp Object is locked skipped
C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSCS7185027F-8626-4D02-98C7-4DD1826735A4.tmp Object is locked skipped
C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSCS73416C4A-7CA6-4F65-B1F3-C28C1CC7F3BD.tmp Object is locked skipped
C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSCS74C512BA-3A57-4D7D-92A0-9982E9C6BFF3.tmp Object is locked skipped
C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSCS75CA5AE3-DE0F-4C86-B25D-2ACBF54E779C.tmp Object is locked skipped
C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSCS76C884C8-0679-4A54-B668-85500C6B5FB0.tmp Object is locked skipped
C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSCS7A623A80-6428-4A89-B3B0-F5F5A2361DAE.tmp Object is locked skipped
C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSCS7AB2CC11-62F5-4B49-8230-8E66DE31308A.tmp Object is locked skipped
C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSCS80B4E2B4-21D8-45EE-8F0F-233CC3666DC7.tmp Object is locked skipped
C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSCS841A5B6C-2FB7-44BD-A352-0E7632051460.tmp Object is locked skipped
C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSCS87635EC1-FD84-4F94-A087-687027005A04.tmp Object is locked skipped
C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSCS87EBD65A-3481-40A3-8D4D-568382CE7118.tmp Object is locked skipped
C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSCS8AA86AFB-4AC4-4779-A314-E6F161168C3A.tmp Object is locked skipped
C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSCS8B885318-AE95-4ECD-ADC0-4584CC641CA3.tmp Object is locked skipped
C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSCS8CE83164-9219-4630-90D6-41815157C3F4.tmp Object is locked skipped
C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSCS8D9F04DF-F2A4-4DC8-8BD0-2335C18C8E0E.tmp Object is locked skipped
C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSCS8DF7E4A4-5DDE-4DD6-B414-4FFFDDEB8A7C.tmp Object is locked skipped
C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSCS90C2BDDF-BC0A-4B45-9933-5BF00A97003B.tmp Object is locked skipped
C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSCS9485832A-9B0A-4952-B7E6-3C1C5A1C5C2B.tmp Object is locked skipped
C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSCS96A93C5A-45A2-4B25-9088-50A55674380C.tmp Object is locked skipped
C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSCS9809BC77-DDA8-45E6-8EFB-D4B4AEA7C3EE.tmp Object is locked skipped
C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSCS99BE14DF-7DB9-4662-A413-F3497472A99C.tmp Object is locked skipped
C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSCS9B52C8B7-7867-464E-9948-E4654B320A63.tmp Object is locked skipped
C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSCSA22D2B05-09F9-4ECF-B3D6-6995358A1A2B.tmp Object is locked skipped
C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSCSA2FF050C-A6A8-4840-94E2-96DBC8498A6A.tmp Object is locked skipped
C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSCSA55A0321-7D61-4861-BEF8-E785F2C4CDA1.tmp Object is locked skipped
C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSCSA59BCCA6-FFDE-4DCA-84CF-1B44165056C1.tmp Object is locked skipped
C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSCSA768C2AA-D89F-48D3-9A3C-7BD25F766485.tmp Object is locked skipped
C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSCSB04CAB54-AC02-4F0D-9693-AED2998FB08D.tmp Object is locked skipped
C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSCSB23E622D-D9D7-42E7-9151-F6AF81EA63E6.tmp Object is locked skipped
C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSCSB2E76963-DA8E-4300-A513-482C1E6CBD4A.tmp Object is locked skipped
C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSCSB76A7172-B22C-4B87-82A4-B898A4513C21.tmp Object is locked skipped
C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSCSB9511548-E4FA-45C8-B20E-FC42C9007070.tmp Object is locked skipped
C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSCSBBD6C2BA-0A4D-4D4F-AA14-0ECE04C8381B.tmp Object is locked skipped
C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSCSC0AA76C7-D1BE-433B-9D4F-3D5518CF5251.tmp Object is locked skipped
C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSCSC15DF805-4F0E-4F8B-9D35-63E8BCB5C152.tmp Object is locked skipped
C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSCSC66B8195-6966-43DE-BCA2-439ED3B4795B.tmp Object is locked skipped
C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSCSC7159D08-8194-44AA-BE6B-B87F430C7CAE.tmp Object is locked skipped
C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSCSC8405296-71D8-483F-B50B-5845B7929818.tmp Object is locked skipped
C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSCSCF53D89E-B375-4EA5-87FA-E9C7B1022A06.tmp Object is locked skipped
C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSCSCFCB128C-0A84-454C-A537-3C1C1EF70EE0.tmp Object is locked skipped
C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSCSD26A9076-26F7-4082-9720-02F5EAE91355.tmp Object is locked skipped
C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSCSD3FFEA26-67CF-4414-B8D9-9D09F43488D8.tmp Object is locked skipped
C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSCSD6BEA5EF-FEAA-48E0-BB46-CF565C48C9E9.tmp Object is locked skipped
C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSCSD973EE32-FD6D-405A-B537-BDC867747A73.tmp Object is locked skipped
C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSCSDAADEDF7-19D7-4036-8306-03EC24B1D3DA.tmp Object is locked skipped
C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSCSDED6FECA-0DED-4005-B858-A73A11A0D4B4.tmp Object is locked skipped
C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSCSDEE05992-052C-400C-B5E1-459FAF303BA4.tmp Object is locked skipped
C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSCSDF3EA2EE-6702-4694-99FB-2078F2764566.tmp Object is locked skipped
C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSCSDF97FE2B-0086-4E74-BFCC-7AEFA5DA10BE.tmp Object is locked skipped
C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSCSE0576EC6-2053-42FB-8DDB-B6B4442BD7BF.tmp Object is locked skipped
C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSCSE090AE67-A51E-48FA-B7A7-3254DBF0E891.tmp Object is locked skipped
C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSCSE387899D-06F2-42C0-85EA-D4D74F8631B0.tmp Object is locked skipped
C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSCSE3AD584F-CAC4-4F63-B125-75415F3B67A1.tmp Object is locked skipped
C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSCSE48F34E9-9663-40A9-8527-D0DE2CF5C1ED.tmp Object is locked skipped
C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSCSEABEB553-85B0-4AA2-BF2F-079288F7D64B.tmp Object is locked skipped
C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSCSEC5DBDC3-B804-4241-A32A-426DC7D0DB35.tmp Object is locked skipped
C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSCSEDBAFAD2-BA48-4AE9-8928-3D084F9A24C0.tmp Object is locked skipped
C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSCSEE504813-F47F-4800-AFC1-9BDAFA6FD30E.tmp Object is locked skipped
C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSCSF1598063-E782-4180-99FE-5CAC08CD7DAA.tmp Object is locked skipped
C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSCSF4695070-CA82-4D93-96D4-29BE05FCA1E7.tmp Object is locked skipped
C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSCSF8797811-CD56-424C-B534-3E64E495B7BF.tmp Object is locked skipped
C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSCSF986DF4B-1CA1-417B-8C2E-670BCE22C2D4.tmp Object is locked skipped
C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSCSF9E58E74-4BE7-45AC-A0AE-FE044B08DF6B.tmp Object is locked skipped
C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSCSFB250F1A-C4CA-4C53-B288-FC11F9606C64.tmp Object is locked skipped
C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSCSFE2F9036-1DB0-4599-9BFE-B2E416BE894F.tmp Object is locked skipped
C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSCSFF79A2FB-836E-48BF-97F8-247D20C465D1.tmp Object is locked skipped
C:\Documents and Settings\LocalService\Cookies\index.dat Object is locked skipped
C:\Documents and Settings\LocalService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat Object is locked skipped
C:\Documents and Settings\LocalService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped
C:\Documents and Settings\LocalService\Local Settings\History\History.IE5\index.dat Object is locked skipped
C:\Documents and Settings\LocalService\Local Settings\Temporary Internet Files\Content.IE5\index.dat Object is locked skipped
C:\Documents and Settings\LocalService\NTUSER.DAT Object is locked skipped
C:\Documents and Settings\LocalService\ntuser.dat.LOG Object is locked skipped
C:\Documents and Settings\NetworkService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat Object is locked skipped
C:\Documents and Settings\NetworkService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped
C:\Documents and Settings\NetworkService\NTUSER.DAT Object is locked skipped
C:\Documents and Settings\NetworkService\ntuser.dat.LOG Object is locked skipped
C:\Program Files\Updates from HP\309731\Users\Default\Data\cache.dat Object is locked skipped
C:\Program Files\Updates from HP\309731\Users\Default\Data\chandir.dat Object is locked skipped
C:\Program Files\Updates from HP\309731\Users\Default\Data\chandir.idx Object is locked skipped
C:\Program Files\Updates from HP\309731\Users\Default\Data\chn.dat Object is locked skipped
C:\Program Files\Updates from HP\309731\Users\Default\Data\chn.idx Object is locked skipped
C:\Program Files\Updates from HP\309731\Users\Default\Data\D0000000.FCS Object is locked skipped
C:\Program Files\Updates from HP\309731\Users\Default\Data\FileRep.log Object is locked skipped
C:\Program Files\Updates from HP\309731\Users\Default\Data\inuse.txt Object is locked skipped
C:\Program Files\Updates from HP\309731\Users\Default\Data\L0000002.FCS Object is locked skipped
C:\Program Files\Updates from HP\309731\Users\Default\Data\main.log Object is locked skipped
C:\Program Files\Updates from HP\309731\Users\Default\Data\prs.dat Object is locked skipped
C:\Program Files\Updates from HP\309731\Users\Default\Data\prs.idx Object is locked skipped
C:\Program Files\Updates from HP\309731\Users\Default\Data\prs_die.dat Object is locked skipped
C:\Program Files\Updates from HP\309731\Users\Default\Data\prs_die.idx Object is locked skipped
C:\Program Files\Updates from HP\309731\Users\Default\Data\prs_dnd.dat Object is locked skipped
C:\Program Files\Updates from HP\309731\Users\Default\Data\prs_dnd.idx Object is locked skipped
C:\Program Files\Updates from HP\309731\Users\Default\Data\prs_ext.dat Object is locked skipped
C:\Program Files\Updates from HP\309731\Users\Default\Data\prs_ext.idx Object is locked skipped
C:\Program Files\Updates from HP\309731\Users\Default\Data\prs_rcv.dat Object is locked skipped
C:\Program Files\Updates from HP\309731\Users\Default\Data\prs_rcv.idx Object is locked skipped
C:\Program Files\Updates from HP\309731\Users\Default\Data\storydb.dat Object is locked skipped
C:\Program Files\Updates from HP\309731\Users\Default\Data\storydb.idx Object is locked skipped
C:\Program Files\Webroot\Spy Sweeper\Masters\masters.bak Object is locked skipped
C:\Program Files\Webroot\Spy Sweeper\Masters\Masters.const Object is locked skipped
C:\Program Files\Webroot\Spy Sweeper\Masters\masters.mst Object is locked skipped
C:\Program Files\Webroot\Spy Sweeper\Masters.base Object is locked skipped
C:\System Volume Information\MountPointManagerRemoteDatabase Object is locked skipped
C:\WINDOWS\Debug\PASSWD.LOG Object is locked skipped
C:\WINDOWS\Internet Logs\fwdbglog.txt Object is locked skipped
C:\WINDOWS\Internet Logs\fwpktlog.txt Object is locked skipped
C:\WINDOWS\Internet Logs\IAMDB.RDB Object is locked skipped
C:\WINDOWS\Internet Logs\MY-F78BF48CE2.ldb Object is locked skipped
C:\WINDOWS\Internet Logs\tvDebug.log Object is locked skipped
C:\WINDOWS\SchedLgU.Txt Object is locked skipped
C:\WINDOWS\SoftwareDistribution\EventCache\{33359FE3-616B-4AB0-8A14-AC8A3AF62696}.bin Object is locked skipped
C:\WINDOWS\SoftwareDistribution\EventCache\{61D33514-88C6-45AF-870A-144C8A2EC725}.bin Object is locked skipped
C:\WINDOWS\SoftwareDistribution\ReportingEvents.log Object is locked skipped
C:\WINDOWS\Sti_Trace.log Object is locked skipped
C:\WINDOWS\system32\CatRoot2\edb.log Object is locked skipped
C:\WINDOWS\system32\CatRoot2\tmp.edb Object is locked skipped
C:\WINDOWS\system32\config\AppEvent.Evt Object is locked skipped
C:\WINDOWS\system32\config\default Object is locked skipped
C:\WINDOWS\system32\config\default.LOG Object is locked skipped
C:\WINDOWS\system32\config\SAM Object is locked skipped
C:\WINDOWS\system32\config\SAM.LOG Object is locked skipped
C:\WINDOWS\system32\config\SecEvent.Evt Object is locked skipped
C:\WINDOWS\system32\config\SECURITY Object is locked skipped
C:\WINDOWS\system32\config\SECURITY.LOG Object is locked skipped
C:\WINDOWS\system32\config\software Object is locked skipped
C:\WINDOWS\system32\config\software.LOG Object is locked skipped
C:\WINDOWS\system32\config\SysEvent.Evt Object is locked skipped
C:\WINDOWS\system32\config\system Object is locked skipped
C:\WINDOWS\system32\config\system.LOG Object is locked skipped
C:\WINDOWS\system32\h323log.txt Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\INDEX.BTR Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\INDEX.MAP Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\MAPPING.VER Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\MAPPING1.MAP Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\MAPPING2.MAP Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\OBJECTS.DATA Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\OBJECTS.MAP Object is locked skipped
C:\WINDOWS\Temp\ZLT024e9.TMP Object is locked skipped
C:\WINDOWS\wiadebug.log Object is locked skipped
C:\WINDOWS\wiaservc.log Object is locked skipped
C:\WINDOWS\WindowsUpdate.log Object is locked skipped
Scan process completed.
|
Clamp1
Newbie
|
24. October 2006 @ 17:15 |
Link to this message
|
Here is the Hijack this log.
Logfile of HijackThis v1.99.1
Scan saved at 9:13:20 PM, on 10/24/2006
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\hkcmd.exe
C:\Program Files\Lexmark 2300 Series\ezprint.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\Program Files\QuickTime\qttask.exe
C:\Program Files\Java\jre1.5.0_06\bin\jusched.exe
C:\Program Files\Webroot\Spy Sweeper\SpySweeperUI.exe
C:\Program Files\CA\eTrust EZ Armor\eTrust Anti-Spam\QSP-2.1.215.5\QOELoader.exe
C:\Program Files\CA\eTrust EZ Armor\eTrust EZ Antivirus\CAVTray.exe
C:\Program Files\CA\eTrust EZ Armor\eTrust EZ Antivirus\CAVRID.exe
C:\Program Files\CA\eTrust EZ Armor\eTrust EZ Firewall\ca.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Messenger\msmsgs.exe
C:\Program Files\America Online 9.0d\aoltray.exe
C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
C:\Program Files\Updates from HP\309731\Program\Updates from HP.exe
C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe
C:\Program Files\Sony\Sony Picture Utility\VolumeWatcher\SPUVolumeWatcher.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
C:\Program Files\CA\eTrust EZ Armor\eTrust EZ Antivirus\ISafe.exe
c:\Program Files\Common Files\LightScribe\LSSrvc.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\WINDOWS\system32\HPZipm12.exe
C:\WINDOWS\system32\tcpsvcs.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\ZoneLabs\vsmon.exe
C:\Program Files\Webroot\Spy Sweeper\SpySweeper.exe
c:\Program Files\Common Files\Symantec Shared\Security Center\SymWSC.exe
C:\WINDOWS\system32\lxcgcoms.exe
C:\Program Files\Google\GoogleToolbarNotifier\1.2.908.5008\GoogleToolbarNotifier.exe
C:\Program Files\CA\eTrust EZ Armor\eTrust EZ Antivirus\VetMsg.exe
C:\HP\KBD\KBD.EXE
C:\WINDOWS\SOUNDMAN.EXE
C:\WINDOWS\ALCMTR.EXE
C:\WINDOWS\ALCWZRD.EXE
C:\WINDOWS\AGRSMMSG.exe
c:\windows\system\hpsysdrv.exe
C:\WINDOWS\system32\hphmon06.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\PROGRA~1\Yahoo!\COMPAN~1\Installs\cpn1\YTBSDK.exe
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\Documents and Settings\HP_Owner\Desktop\HijackThis_v1.99.1.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.rr.com/
R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn1\yt.dll
O2 - BHO: Yahoo! Toolbar Helper - {02478D38-C3F9-4EFB-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn1\yt.dll
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar5.dll
O3 - Toolbar: HP view - {B2847E28-5D7D-4DEB-8B67-05D28BCF79F5} - c:\Program Files\HP\Digital Imaging\bin\HPDTLK02.dll
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn1\yt.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar5.dll
O4 - HKLM\..\Run: [High Definition Audio Property Page Shortcut] HDAudPropShortcut.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\system32\hkcmd.exe
O4 - HKLM\..\Run: [HPBootOp] "C:\Program Files\Hewlett-Packard\HP Boot Optimizer\HPBootOp.exe" /run
O4 - HKLM\..\Run: [_SetRes] c:\hp\bin\cloaker c:\hp\bin\res.bat
O4 - HKLM\..\Run: [IcoSet] "c:\hp\bin\cloaker.exe" c:\hp\bin\IcoSet\adjust.bat seticon
O4 - HKLM\..\Run: [LSBWatcher] c:\hp\drivers\hplsbwatcher\lsburnwatcher.exe
O4 - HKLM\..\Run: [lxcgmon.exe] "C:\Program Files\Lexmark 2300 Series\lxcgmon.exe"
O4 - HKLM\..\Run: [EzPrint] "C:\Program Files\Lexmark 2300 Series\ezprint.exe"
O4 - HKLM\..\Run: [FaxCenterServer] "C:\Program Files\Lexmark Fax Solutions\fm3032.exe" /s
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.5.0_06\bin\jusched.exe"
O4 - HKLM\..\Run: [LXCGCATS] rundll32 C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\LXCGtime.dll,_RunDLLEntry@16
O4 - HKLM\..\Run: [SpySweeper] "C:\Program Files\Webroot\Spy Sweeper\SpySweeperUI.exe" /startintray
O4 - HKLM\..\Run: [QOELOADER] "C:\Program Files\CA\eTrust EZ Armor\eTrust Anti-Spam\QSP-2.1.215.5\QOELoader.exe"
O4 - HKLM\..\Run: [CaAvTray] "C:\Program Files\CA\eTrust EZ Armor\eTrust EZ Antivirus\CAVTray.exe"
O4 - HKLM\..\Run: [CAVRID] "C:\Program Files\CA\eTrust EZ Armor\eTrust EZ Antivirus\CAVRID.exe"
O4 - HKLM\..\Run: [Zone Labs Client] "C:\Program Files\CA\eTrust EZ Armor\eTrust EZ Firewall\ca.exe"
O4 - HKLM\..\Run: [!AVG Anti-Spyware] "C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" /minimized
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [swg] "C:\Program Files\Google\GoogleToolbarNotifier\1.0.720.3640\GoogleToolbarNotifier.exe"
O4 - Startup: Cyber-shot Viewer Media Check Tool.lnk = C:\Program Files\Sony\Sony Picture Utility\VolumeWatcher\SPUVolumeWatcher.exe
O4 - Startup: HP Organize.lnk = ?
O4 - Global Startup: America Online 9.0 Tray Icon.lnk = C:\Program Files\America Online 9.0d\aoltray.exe
O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
O4 - Global Startup: SpySubtract.lnk = C:\Program Files\InterMute\SpySubtract\sslaunch.exe
O4 - Global Startup: Updates from HP.lnk = C:\Program Files\Updates from HP\309731\Program\Updates from HP.exe
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MI1933~1\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MI1933~1\OFFICE11\REFIEBAR.DLL
O9 - Extra button: Connection Help - {E2D4D26B-0180-43a4-B05F-462D6D54C789} - C:\WINDOWS\PCHEALTH\HELPCTR\Vendors\CN=Hewlett-Packard,L=Cupertino,S=Ca,C=US\IEButton\support.htm
O9 - Extra 'Tools' menuitem: Connection Help - {E2D4D26B-0180-43a4-B05F-462D6D54C789} - C:\WINDOWS\PCHEALTH\HELPCTR\Vendors\CN=Hewlett-Packard,L=Cupertino,S=Ca,C=US\IEButton\support.htm
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra button: Connection Help - {E2D4D26B-0180-43a4-B05F-462D6D54C789} - C:\WINDOWS\PCHEALTH\HELPCTR\Vendors\CN=Hewlett-Packard,L=Cupertino,S=Ca,C=US\IEButton\support.htm (HKCU)
O9 - Extra 'Tools' menuitem: Connection Help - {E2D4D26B-0180-43a4-B05F-462D6D54C789} - C:\WINDOWS\PCHEALTH\HELPCTR\Vendors\CN=Hewlett-Packard,L=Cupertino,S=Ca,C=US\IEButton\support.htm (HKCU)
O16 - DPF: {0EB0E74A-2A76-4AB3-A7FB-9BD8C29F7F75} (CKAVWebScan Object) - http://www.kaspersky.com/kos/english/kavwebscan_unicode.cab
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?LinkID=39204
O20 - Winlogon Notify: igfxcui - C:\WINDOWS\SYSTEM32\igfxsrvc.dll
O20 - Winlogon Notify: WRNotifier - C:\WINDOWS\SYSTEM32\WRLogonNTF.dll
O21 - SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll
O23 - Service: Automatic LiveUpdate Scheduler - Symantec Corporation - C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe
O23 - Service: AVG Anti-Spyware Guard - Anti-Malware Development a.s. - C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
O23 - Service: CAISafe - Computer Associates International, Inc. - C:\Program Files\CA\eTrust EZ Armor\eTrust EZ Antivirus\ISafe.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe
O23 - Service: iPod Service (iPodService) - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - c:\Program Files\Common Files\LightScribe\LSSrvc.exe
O23 - Service: LiveUpdate - Symantec Corporation - C:\PROGRA~1\Symantec\LIVEUP~1\LUCOMS~1.EXE
O23 - Service: lxcg_device - - C:\WINDOWS\system32\lxcgcoms.exe
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe
O23 - Service: SymWMI Service (SymWSC) - Symantec Corporation - c:\Program Files\Common Files\Symantec Shared\Security Center\SymWSC.exe
O23 - Service: VET Message Service (VETMSGNT) - Computer Associates International, Inc. - C:\Program Files\CA\eTrust EZ Armor\eTrust EZ Antivirus\VetMsg.exe
O23 - Service: TrueVector Internet Monitor (vsmon) - Zone Labs Inc. - C:\WINDOWS\system32\ZoneLabs\vsmon.exe
O23 - Service: Webroot Spy Sweeper Engine (WebrootSpySweeperService) - Webroot Software, Inc. - C:\Program Files\Webroot\Spy Sweeper\SpySweeper.exe
|
Senior Member
|
24. October 2006 @ 19:16 |
Link to this message
|
Wonderful! One more bad file and one more check(for a rootkit) and you should be clear.
Delete this file:
C:\23100247.exe
This isn't malware, but not needed on startup. Read here for more information about this file.
Go to Start > Run > type msconfig > click OK > click the Startup tab > find ALCMTR.EXE and uncheck it.
Dowload F-Secure Blacklight (blbeta.exe) to the desktop from here.
Open it and click Accept Agreement.
Click "Scan".
After the scan is complete, click "Next", then "Exit".
It will create a log on the desktop named "fsbl-xxxxxxx.log" (the xxxxxxx will be the date and time of the scan)
Post that log in your next reply.
How are things? Any problems?
|
Clamp1
Newbie
|
25. October 2006 @ 12:25 |
Link to this message
|
When I try to delet the file C:\23100247.exe it says access denied.
And I cant find ALCMTR.EXE in the start up Tab
This message has been edited since posting. Last time this message was edited on 25. October 2006 @ 12:27
|
Senior Member
|
25. October 2006 @ 12:43 |
Link to this message
|
Delete the file in safe mode. And no worries about ALCMTR.EXE not being there.
|
Clamp1
Newbie
|
25. October 2006 @ 13:34 |
Link to this message
|
Here is the F-Secure Backlight Log
10/25/06 17:24:11 [Info]: BlackLight Engine 1.0.47 initialized
10/25/06 17:24:11 [Info]: OS: 5.1 build 2600 (Service Pack 2)
10/25/06 17:24:11 [Note]: 7019 4
10/25/06 17:24:11 [Note]: 7005 0
10/25/06 17:24:18 [Note]: 7006 0
10/25/06 17:24:18 [Note]: 7011 1392
10/25/06 17:24:19 [Note]: 7026 0
10/25/06 17:24:19 [Note]: 7026 0
10/25/06 17:24:32 [Note]: FSRAW library version 1.7.1020
10/25/06 17:28:33 [Note]: 2000 1012
10/25/06 17:33:15 [Note]: 7007 0
|
Advertisement
|
  |
|
Clamp1
Newbie
|
25. October 2006 @ 13:39 |
Link to this message
|
Before I came to this website my computer said that I was infected by the BackDoor Haxdoor virus. SO I wanted to ask if that is on my computer. And Afterall of this is my computer virus free.
|
|