User User name Password  
   
Friday 29.8.2025 / 16:28
Search AfterDawn Forums:        In English   Suomeksi   På svenska
afterdawn.com > forums > software, operating systems and more > windows - virus and spyware problems > need help
Show topics
 
Forums
Forums
Need Help
  Jump to:
 
Posted Message
Page:12Next >
Clamp1
Newbie
_
18. October 2006 @ 13:44 _ Link to this message    Send private message to this user   
Hi
Can anyone help me remove some vius. Thanks. Heres my HijackThis log.


Logfile of HijackThis v1.99.1
Scan saved at 5:41:27 PM, on 10/18/2006
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\MMediaCodec\pmsngr.exe
C:\Program Files\MMediaCodec\isamonitor.exe
C:\WINDOWS\system32\hkcmd.exe
C:\Program Files\Lexmark 2300 Series\ezprint.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\Program Files\QuickTime\qttask.exe
C:\Program Files\Java\jre1.5.0_06\bin\jusched.exe
C:\Program Files\MMediaCodec\pmmon.exe
C:\Program Files\MMediaCodec\isamini.exe
C:\Program Files\Webroot\Spy Sweeper\SpySweeperUI.exe
C:\Program Files\AntiVermins\AntiVermins.exe
C:\Program Files\CA\eTrust EZ Armor\eTrust Anti-Spam\QSP-2.1.215.5\QOELoader.exe
C:\Program Files\CA\eTrust EZ Armor\eTrust EZ Antivirus\CAVTray.exe
C:\Program Files\CA\eTrust EZ Armor\eTrust EZ Antivirus\CAVRID.exe
C:\Program Files\CA\eTrust EZ Armor\eTrust EZ Firewall\ca.exe
C:\Program Files\AntiVermins\AntiVermins.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Messenger\msmsgs.exe
C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe
C:\Program Files\America Online 9.0d\aoltray.exe
C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
C:\Program Files\Updates from HP\309731\Program\Updates from HP.exe
C:\Program Files\Sony\Sony Picture Utility\VolumeWatcher\SPUVolumeWatcher.exe
C:\Program Files\CA\eTrust EZ Armor\eTrust EZ Antivirus\ISafe.exe
c:\Program Files\Common Files\LightScribe\LSSrvc.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\WINDOWS\system32\HPZipm12.exe
C:\WINDOWS\system32\tcpsvcs.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\ZoneLabs\vsmon.exe
C:\Program Files\Webroot\Spy Sweeper\SpySweeper.exe
c:\Program Files\Common Files\Symantec Shared\Security Center\SymWSC.exe
C:\WINDOWS\system32\lxcgcoms.exe
C:\Program Files\CA\eTrust EZ Armor\eTrust EZ Antivirus\VetMsg.exe
C:\Program Files\Google\GoogleToolbarNotifier\1.2.908.5008\GoogleToolbarNotifier.exe
C:\HP\KBD\KBD.EXE
C:\WINDOWS\SOUNDMAN.EXE
C:\WINDOWS\ALCMTR.EXE
C:\WINDOWS\ALCWZRD.EXE
C:\WINDOWS\AGRSMMSG.exe
c:\windows\system\hpsysdrv.exe
C:\WINDOWS\system32\hphmon06.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\PROGRA~1\Yahoo!\COMPAN~1\Installs\cpn1\YTBSDK.exe
C:\Program Files\Webroot\Spy Sweeper\SSU.EXE
C:\Documents and Settings\HP_Owner\Desktop\HijackThis_v1.99.1.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://ie.redirect.hp.com/svs/rdr?TYPE=3...lion&pf=desktop
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://ie.redirect.hp.com/svs/rdr?TYPE=3...lion&pf=desktop
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.rr.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://ie.redirect.hp.com/svs/rdr?TYPE=3...lion&pf=desktop
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://ie.redirect.hp.com/svs/rdr?TYPE=3...lion&pf=desktop
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://ie.redirect.hp.com/svs/rdr?TYPE=3...lion&pf=desktop
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://ie.redirect.hp.com/svs/rdr?TYPE=3...lion&pf=desktop
R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://ie.redirect.hp.com/svs/rdr?TYPE=3...lion&pf=desktop
R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn1\yt.dll
F2 - REG:system.ini: Shell=Explorer.exe,
F2 - REG:system.ini: UserInit=C:\WINDOWS\system32\userinit.exe,cfcqyjv.exe
O2 - BHO: Yahoo! Toolbar Helper - {02478D38-C3F9-4EFB-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn1\yt.dll
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar5.dll
O2 - BHO: (no name) - {d869742a-e5d2-4624-96c7-aae26170665e} - C:\Program Files\MMediaCodec\isaddon.dll
O3 - Toolbar: HP view - {B2847E28-5D7D-4DEB-8B67-05D28BCF79F5} - c:\Program Files\HP\Digital Imaging\bin\HPDTLK02.dll
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn1\yt.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar5.dll
O3 - Toolbar: Protection Bar - {44d22a64-2399-4edf-8b32-f2c729c1e8a7} - C:\Program Files\MMediaCodec\iesplugin.dll
O4 - HKLM\..\Run: [High Definition Audio Property Page Shortcut] HDAudPropShortcut.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\system32\hkcmd.exe
O4 - HKLM\..\Run: [HPBootOp] "C:\Program Files\Hewlett-Packard\HP Boot Optimizer\HPBootOp.exe" /run
O4 - HKLM\..\Run: [_SetRes] c:\hp\bin\cloaker c:\hp\bin\res.bat
O4 - HKLM\..\Run: [IcoSet] "c:\hp\bin\cloaker.exe" c:\hp\bin\IcoSet\adjust.bat seticon
O4 - HKLM\..\Run: [LSBWatcher] c:\hp\drivers\hplsbwatcher\lsburnwatcher.exe
O4 - HKLM\..\Run: [lxcgmon.exe] "C:\Program Files\Lexmark 2300 Series\lxcgmon.exe"
O4 - HKLM\..\Run: [EzPrint] "C:\Program Files\Lexmark 2300 Series\ezprint.exe"
O4 - HKLM\..\Run: [FaxCenterServer] "C:\Program Files\Lexmark Fax Solutions\fm3032.exe" /s
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.5.0_06\bin\jusched.exe"
O4 - HKLM\..\Run: [LXCGCATS] rundll32 C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\LXCGtime.dll,_RunDLLEntry@16
O4 - HKLM\..\Run: [SpySweeper] "C:\Program Files\Webroot\Spy Sweeper\SpySweeperUI.exe" /startintray
O4 - HKLM\..\Run: [AntiVermins] "C:\Program Files\AntiVermins\AntiVermins.exe" /h
O4 - HKLM\..\Run: [QOELOADER] "C:\Program Files\CA\eTrust EZ Armor\eTrust Anti-Spam\QSP-2.1.215.5\QOELoader.exe"
O4 - HKLM\..\Run: [CaAvTray] "C:\Program Files\CA\eTrust EZ Armor\eTrust EZ Antivirus\CAVTray.exe"
O4 - HKLM\..\Run: [CAVRID] "C:\Program Files\CA\eTrust EZ Armor\eTrust EZ Antivirus\CAVRID.exe"
O4 - HKLM\..\Run: [Zone Labs Client] "C:\Program Files\CA\eTrust EZ Armor\eTrust EZ Firewall\ca.exe"
O4 - HKLM\..\Run: [ariboc] C:\WINDOWS\system32\baejoe.exe reg_run
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [swg] "C:\Program Files\Google\GoogleToolbarNotifier\1.0.720.3640\GoogleToolbarNotifier.exe"
O4 - HKCU\..\Run: [wopcp] C:\WINDOWS\system32\baejoe.exe reg_run
O4 - Startup: Cyber-shot Viewer Media Check Tool.lnk = C:\Program Files\Sony\Sony Picture Utility\VolumeWatcher\SPUVolumeWatcher.exe
O4 - Startup: HP Organize.lnk = ?
O4 - Global Startup: America Online 9.0 Tray Icon.lnk = C:\Program Files\America Online 9.0d\aoltray.exe
O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
O4 - Global Startup: SpySubtract.lnk = C:\Program Files\InterMute\SpySubtract\sslaunch.exe
O4 - Global Startup: Updates from HP.lnk = C:\Program Files\Updates from HP\309731\Program\Updates from HP.exe
O8 - Extra context menu item: &Search - http://kl.bar.need2find.com/KL/menusearch.html?p=KL
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MI1933~1\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MI1933~1\OFFICE11\REFIEBAR.DLL
O9 - Extra button: Connection Help - {E2D4D26B-0180-43a4-B05F-462D6D54C789} - C:\WINDOWS\PCHEALTH\HELPCTR\Vendors\CN=Hewlett-Packard,L=Cupertino,S=Ca,C=US\IEButton\support.htm
O9 - Extra 'Tools' menuitem: Connection Help - {E2D4D26B-0180-43a4-B05F-462D6D54C789} - C:\WINDOWS\PCHEALTH\HELPCTR\Vendors\CN=Hewlett-Packard,L=Cupertino,S=Ca,C=US\IEButton\support.htm
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra button: Connection Help - {E2D4D26B-0180-43a4-B05F-462D6D54C789} - C:\WINDOWS\PCHEALTH\HELPCTR\Vendors\CN=Hewlett-Packard,L=Cupertino,S=Ca,C=US\IEButton\support.htm (HKCU)
O9 - Extra 'Tools' menuitem: Connection Help - {E2D4D26B-0180-43a4-B05F-462D6D54C789} - C:\WINDOWS\PCHEALTH\HELPCTR\Vendors\CN=Hewlett-Packard,L=Cupertino,S=Ca,C=US\IEButton\support.htm (HKCU)
O15 - Trusted Zone: ww.rr.com
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?LinkID=39204
O20 - Winlogon Notify: igfxcui - C:\WINDOWS\SYSTEM32\igfxsrvc.dll
O20 - Winlogon Notify: WRNotifier - C:\WINDOWS\SYSTEM32\WRLogonNTF.dll
O20 - Winlogon Notify: yvbb01 - yvbb01.dll (file missing)
O20 - Winlogon Notify: yvpp01 - C:\WINDOWS\SYSTEM32\yvpp01.dll
O21 - SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll
O21 - SSODL: contrabandists - {dfa61db1-388e-4c87-8d56-540fa229bcb4} - C:\WINDOWS\system32\dpfwu.dll (file missing)
O23 - Service: Automatic LiveUpdate Scheduler - Symantec Corporation - C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe
O23 - Service: CAISafe - Computer Associates International, Inc. - C:\Program Files\CA\eTrust EZ Armor\eTrust EZ Antivirus\ISafe.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe
O23 - Service: iPod Service (iPodService) - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - c:\Program Files\Common Files\LightScribe\LSSrvc.exe
O23 - Service: LiveUpdate - Symantec Corporation - C:\PROGRA~1\Symantec\LIVEUP~1\LUCOMS~1.EXE
O23 - Service: lxcg_device - - C:\WINDOWS\system32\lxcgcoms.exe
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe
O23 - Service: SymWMI Service (SymWSC) - Symantec Corporation - c:\Program Files\Common Files\Symantec Shared\Security Center\SymWSC.exe
O23 - Service: VET Message Service (VETMSGNT) - Computer Associates International, Inc. - C:\Program Files\CA\eTrust EZ Armor\eTrust EZ Antivirus\VetMsg.exe
O23 - Service: TrueVector Internet Monitor (vsmon) - Zone Labs Inc. - C:\WINDOWS\system32\ZoneLabs\vsmon.exe
O23 - Service: Webroot Spy Sweeper Engine (WebrootSpySweeperService) - Webroot Software, Inc. - C:\Program Files\Webroot\Spy Sweeper\SpySweeper.exe
Advertisement
_
__
Senior Member
_
19. October 2006 @ 19:49 _ Link to this message    Send private message to this user   
Hello Clamp1, there is alot of infected files. Please follow these instructions as posted. If you run into a problem with one of the fixes please come back and ask before moving to next step.

Step 1:

Download haxfix.exe from here and save it to your desktop.
Download SmitfraudFix.zip from here and unzip it to your desktop. Do not run it yet, will later in safe mode.
Download the trial version of AVG Anti-spyware from here. Do not install it yet, will after running haxfix.

Step 2:

Please diable SpySweeper's Shields becasue it may interfere with our fixes.
Open SpySweeper.
Click Shield Settings on the right
(or Shields on the left, depending what screen you're on).
Click Internet Explorer and uncheck all items.
Click Windows System and uncheck all items.
Click Hosts File and uncheck all items.
Click Startup Programs and uncheck all items.
Close SpySweeper.

Step 3:

* Double click on haxfix.exe to install it.
* Checkmark "Create a desktop icon".
* Click "Next".
* When the installation is completed, make sure that the checkmark "Launch HaxFix" is placed.
* Click "Finish".

A red "dos window" (dos box) will open with options:
1. Make logfile
2. Run auto fix
3. Run manual fix
E. Exit Haxfix

* Select option 2. Run auto fix by typing 2 and then pressing Enter.
If an infection is found, you'll get a message to close all other open windows.
* Close all open windows except the red dos window from haxfix and then press Enter.
* The computer will reboot.
* After reboot a logfile will open > (c:\haxfix.txt) save and close it.

Step 4:

Note: Print or copy these instructions to Notepad and save them. You will be in safe mode and can't acces the internet.

Install and update AVGAS.
Restart your computer in safe mode(press F8 upon boot, select "Safe Mode" from menu and press Enter).

* Open the SmitfraudFix folder.
* Double-click smitfraudfix.cmd
* Select 2 and hit Enter to delete infect files.
* You will be prompted: Do you want to clean the registry ? answer Y (yes) and hit Enter in order to remove the Desktop background and clean registry keys associated with the infection.
* The tool will now check if wininet.dll is infected. You may be prompted to replace the infected file (if found): Replace infected file ? answer Y (yes) and hit Enter to restore a clean file.
* A reboot may be needed to finish the cleaning process. The report can be found at the root of the system drive, usually at C:\rapport.txt.
* Exit SmitfraudFix.

Step 5:

* Open AVG AS and click "Scanner".
* Click "Complete System Scan".
* When it finishes scanning, set all items to "Quarantine".
* Click "Apply All Actions".
* Click "Save Report".
* Click "Save report as" and save it to the desktop.
* Exit AVGAS and restart in normal mode.

Step 6:

Run a new scan with HijackThis and save a new log.
Please post back with the Haxfix log, the SmitfraudFix log, the AVGAS report, and a new HijackThis log.


Clamp1
Newbie
_
21. October 2006 @ 13:56 _ Link to this message    Send private message to this user   
Thank for helping me Niobis. I realy thank you. Here is the HijackThis log.

Logfile of HijackThis v1.99.1
Scan saved at 5:25:46 PM, on 10/21/2006
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\hkcmd.exe
C:\Program Files\Hewlett-Packard\HP Boot Optimizer\HPBootOp.exe
C:\Program Files\Lexmark 2300 Series\ezprint.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\Program Files\QuickTime\qttask.exe
C:\Program Files\Java\jre1.5.0_06\bin\jusched.exe
C:\Program Files\Webroot\Spy Sweeper\SpySweeperUI.exe
C:\Program Files\CA\eTrust EZ Armor\eTrust Anti-Spam\QSP-2.1.215.5\QOELoader.exe
C:\Program Files\CA\eTrust EZ Armor\eTrust EZ Antivirus\CAVTray.exe
C:\Program Files\CA\eTrust EZ Armor\eTrust EZ Antivirus\CAVRID.exe
C:\Program Files\CA\eTrust EZ Armor\eTrust EZ Firewall\ca.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Messenger\msmsgs.exe
C:\Program Files\America Online 9.0d\aoltray.exe
C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe
C:\Program Files\Updates from HP\309731\Program\Updates from HP.exe
C:\Program Files\Sony\Sony Picture Utility\VolumeWatcher\SPUVolumeWatcher.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
C:\Program Files\CA\eTrust EZ Armor\eTrust EZ Antivirus\ISafe.exe
c:\Program Files\Common Files\LightScribe\LSSrvc.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\WINDOWS\system32\HPZipm12.exe
C:\WINDOWS\system32\tcpsvcs.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\CA\eTrust EZ Armor\eTrust EZ Antivirus\VetMsg.exe
C:\WINDOWS\system32\ZoneLabs\vsmon.exe
C:\Program Files\Webroot\Spy Sweeper\SpySweeper.exe
c:\Program Files\Common Files\Symantec Shared\Security Center\SymWSC.exe
C:\WINDOWS\system32\lxcgcoms.exe
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\Program Files\Google\GoogleToolbarNotifier\1.2.908.5008\GoogleToolbarNotifier.exe
C:\PROGRA~1\Yahoo!\COMPAN~1\Installs\cpn1\YTBSDK.exe
C:\HP\KBD\KBD.EXE
C:\WINDOWS\SOUNDMAN.EXE
C:\WINDOWS\ALCMTR.EXE
C:\WINDOWS\system32\NOTEPAD.EXE
C:\WINDOWS\ALCWZRD.EXE
C:\WINDOWS\AGRSMMSG.exe
c:\windows\system\hpsysdrv.exe
C:\WINDOWS\system32\hphmon06.exe
C:\Documents and Settings\HP_Owner\Desktop\HijackThis_v1.99.1.exe

R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://ie.redirect.hp.com/svs/rdr?TYPE=3...lion&pf=desktop
R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn1\yt.dll
F2 - REG:system.ini: UserInit=C:\WINDOWS\system32\userinit.exe,cfcqyjv.exe
O2 - BHO: Yahoo! Toolbar Helper - {02478D38-C3F9-4EFB-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn1\yt.dll
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar5.dll
O3 - Toolbar: HP view - {B2847E28-5D7D-4DEB-8B67-05D28BCF79F5} - c:\Program Files\HP\Digital Imaging\bin\HPDTLK02.dll
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn1\yt.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar5.dll
O4 - HKLM\..\Run: [High Definition Audio Property Page Shortcut] HDAudPropShortcut.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\system32\hkcmd.exe
O4 - HKLM\..\Run: [HPBootOp] "C:\Program Files\Hewlett-Packard\HP Boot Optimizer\HPBootOp.exe" /run
O4 - HKLM\..\Run: [_SetRes] c:\hp\bin\cloaker c:\hp\bin\res.bat
O4 - HKLM\..\Run: [IcoSet] "c:\hp\bin\cloaker.exe" c:\hp\bin\IcoSet\adjust.bat seticon
O4 - HKLM\..\Run: [LSBWatcher] c:\hp\drivers\hplsbwatcher\lsburnwatcher.exe
O4 - HKLM\..\Run: [lxcgmon.exe] "C:\Program Files\Lexmark 2300 Series\lxcgmon.exe"
O4 - HKLM\..\Run: [EzPrint] "C:\Program Files\Lexmark 2300 Series\ezprint.exe"
O4 - HKLM\..\Run: [FaxCenterServer] "C:\Program Files\Lexmark Fax Solutions\fm3032.exe" /s
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.5.0_06\bin\jusched.exe"
O4 - HKLM\..\Run: [LXCGCATS] rundll32 C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\LXCGtime.dll,_RunDLLEntry@16
O4 - HKLM\..\Run: [SpySweeper] "C:\Program Files\Webroot\Spy Sweeper\SpySweeperUI.exe" /startintray
O4 - HKLM\..\Run: [QOELOADER] "C:\Program Files\CA\eTrust EZ Armor\eTrust Anti-Spam\QSP-2.1.215.5\QOELoader.exe"
O4 - HKLM\..\Run: [CaAvTray] "C:\Program Files\CA\eTrust EZ Armor\eTrust EZ Antivirus\CAVTray.exe"
O4 - HKLM\..\Run: [CAVRID] "C:\Program Files\CA\eTrust EZ Armor\eTrust EZ Antivirus\CAVRID.exe"
O4 - HKLM\..\Run: [Zone Labs Client] "C:\Program Files\CA\eTrust EZ Armor\eTrust EZ Firewall\ca.exe"
O4 - HKLM\..\Run: [ariboc] C:\WINDOWS\system32\baejoe.exe reg_run
O4 - HKLM\..\Run: [!AVG Anti-Spyware] "C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" /minimized
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [swg] "C:\Program Files\Google\GoogleToolbarNotifier\1.0.720.3640\GoogleToolbarNotifier.exe"
O4 - HKCU\..\Run: [wopcp] C:\WINDOWS\system32\baejoe.exe reg_run
O4 - Startup: Cyber-shot Viewer Media Check Tool.lnk = C:\Program Files\Sony\Sony Picture Utility\VolumeWatcher\SPUVolumeWatcher.exe
O4 - Startup: HP Organize.lnk = ?
O4 - Global Startup: America Online 9.0 Tray Icon.lnk = C:\Program Files\America Online 9.0d\aoltray.exe
O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
O4 - Global Startup: SpySubtract.lnk = C:\Program Files\InterMute\SpySubtract\sslaunch.exe
O4 - Global Startup: Updates from HP.lnk = C:\Program Files\Updates from HP\309731\Program\Updates from HP.exe
O8 - Extra context menu item: &Search - http://kl.bar.need2find.com/KL/menusearch.html?p=KL
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MI1933~1\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MI1933~1\OFFICE11\REFIEBAR.DLL
O9 - Extra button: Connection Help - {E2D4D26B-0180-43a4-B05F-462D6D54C789} - C:\WINDOWS\PCHEALTH\HELPCTR\Vendors\CN=Hewlett-Packard,L=Cupertino,S=Ca,C=US\IEButton\support.htm
O9 - Extra 'Tools' menuitem: Connection Help - {E2D4D26B-0180-43a4-B05F-462D6D54C789} - C:\WINDOWS\PCHEALTH\HELPCTR\Vendors\CN=Hewlett-Packard,L=Cupertino,S=Ca,C=US\IEButton\support.htm
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra button: Connection Help - {E2D4D26B-0180-43a4-B05F-462D6D54C789} - C:\WINDOWS\PCHEALTH\HELPCTR\Vendors\CN=Hewlett-Packard,L=Cupertino,S=Ca,C=US\IEButton\support.htm (HKCU)
O9 - Extra 'Tools' menuitem: Connection Help - {E2D4D26B-0180-43a4-B05F-462D6D54C789} - C:\WINDOWS\PCHEALTH\HELPCTR\Vendors\CN=Hewlett-Packard,L=Cupertino,S=Ca,C=US\IEButton\support.htm (HKCU)
O15 - Trusted Zone: ww.rr.com
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?LinkID=39204
O20 - Winlogon Notify: igfxcui - C:\WINDOWS\SYSTEM32\igfxsrvc.dll
O20 - Winlogon Notify: WRNotifier - C:\WINDOWS\SYSTEM32\WRLogonNTF.dll
O20 - Winlogon Notify: yvbb01 - yvbb01.dll (file missing)
O21 - SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll
O23 - Service: Automatic LiveUpdate Scheduler - Symantec Corporation - C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe
O23 - Service: AVG Anti-Spyware Guard - Anti-Malware Development a.s. - C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
O23 - Service: CAISafe - Computer Associates International, Inc. - C:\Program Files\CA\eTrust EZ Armor\eTrust EZ Antivirus\ISafe.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe
O23 - Service: iPod Service (iPodService) - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - c:\Program Files\Common Files\LightScribe\LSSrvc.exe
O23 - Service: LiveUpdate - Symantec Corporation - C:\PROGRA~1\Symantec\LIVEUP~1\LUCOMS~1.EXE
O23 - Service: lxcg_device - - C:\WINDOWS\system32\lxcgcoms.exe
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe
O23 - Service: SymWMI Service (SymWSC) - Symantec Corporation - c:\Program Files\Common Files\Symantec Shared\Security Center\SymWSC.exe
O23 - Service: VET Message Service (VETMSGNT) - Computer Associates International, Inc. - C:\Program Files\CA\eTrust EZ Armor\eTrust EZ Antivirus\VetMsg.exe
O23 - Service: TrueVector Internet Monitor (vsmon) - Zone Labs Inc. - C:\WINDOWS\system32\ZoneLabs\vsmon.exe
O23 - Service: Webroot Spy Sweeper Engine (WebrootSpySweeperService) - Webroot Software, Inc. - C:\Program Files\Webroot\Spy Sweeper\SpySweeper.exe
Clamp1
Newbie
_
21. October 2006 @ 14:00 _ Link to this message    Send private message to this user   
Here is the Smitfraudfix log

SmitFraudFix v2.112

Scan done at 15:53:00.42, Sat 10/21/2006
Run from C:\Documents and Settings\HP_Owner\Desktop\SmitfraudFix
OS: Microsoft Windows XP [Version 5.1.2600] - Windows_NT
Fix run in safe mode

»»»»»»»»»»»»»»»»»»»»»»»» Before SmitFraudFix
!!!Attention, following keys are not inevitably infected!!!

SrchSTS.exe by S!Ri
Search SharedTaskScheduler's .dll

»»»»»»»»»»»»»»»»»»»»»»»» Killing process


»»»»»»»»»»»»»»»»»»»»»»»» Generic Renos Fix

GenericRenosFix by S!Ri


»»»»»»»»»»»»»»»»»»»»»»»» Deleting infected files


»»»»»»»»»»»»»»»»»»»»»»»» Deleting Temp Files


»»»»»»»»»»»»»»»»»»»»»»»» Registry Cleaning

Registry Cleaning done.

»»»»»»»»»»»»»»»»»»»»»»»» After SmitFraudFix
!!!Attention, following keys are not inevitably infected!!!

SrchSTS.exe by S!Ri
Search SharedTaskScheduler's .dll


»»»»»»»»»»»»»»»»»»»»»»»» End
Clamp1
Newbie
_
21. October 2006 @ 14:03 _ Link to this message    Send private message to this user   
Here is the Haxfix log

HAXFIX logfile - by Marckie
--------------
version 4.25
Sat 10/21/2006 15:21:14.15

--- Auto Haxdoorfix ---


searching for files:
yvpp01.dll

no infections found


--- Goldunfix ---


searching for files:

searching for SSODLkeys:
no SSODLkeys found

searching for notifykeys:
no notifykeys found

searching for services:
no services found


.....rebooting the computer.....


searching for ssodlkeys

not needed


searching for notifykeys

notifykey yvpp01 not found


searching for services

not needed


searching for safeboot services

not needed


searching for files

yvpp01.dll exists
deleting yvpp01.dll
yvpp01.dll has been deleted


checking for other files

No other files found


checking for a3d files

no a3d files found


Finished
Clamp1
Newbie
_
21. October 2006 @ 14:11 _ Link to this message    Send private message to this user   

This message has been edited since posting. Last time this message was edited on 22. October 2006 @ 09:04

Senior Member
_
21. October 2006 @ 14:23 _ Link to this message    Send private message to this user   
Good! Now, let's get rid of Qoologic.

First, turn off SpySweeper's Shields becasue it may interfere with the fixes. Please leave them off until we know you're clean.

Open SpySweeper.
Click Shield Settings on the right
(or Shields on the left, depending what screen you're on).
Click Internet Explorer and uncheck all items.
Click Windows System and uncheck all items.
Click Hosts File and uncheck all items.
Click Startup Programs and uncheck all items.
Close SpySweeper.

Download Brute Force Uninstaller to your desktop.

* Right click the BFU folder on your desktop, and choose Extract All
* Click "Next"
* In the box to choose where to extract the files to,
* Click "Browse"
* Click on the + sign next to "My Computer"
* Click on "Local Disk (C:)
* Click "Make New Folder"
* Type in BFU
* Click "Next", and Uncheck the "Show Extracted Files" box and then click "Finish".
* Download qoofix.bat
* Place qoofix.bat in your C:\BFU - folder. (Important!)
* Double click qooFix.bat, close all windows.
* Choose option 1 (Qoolfix autofix) and follow the prompts.
* Please be patient, it will take about five minutes.
* After the PC has restarted run a new scan with HijackThis and post the new log.

Edit: forgot to post the SpySweeper instructions.

This message has been edited since posting. Last time this message was edited on 21. October 2006 @ 14:36

Clamp1
Newbie
_
21. October 2006 @ 14:27 _ Link to this message    Send private message to this user   
Hey Niobis

By mistake I Posted HijackThis and Haxfix Two times sorry about that and the AVGAS report is in the end
Senior Member
_
21. October 2006 @ 14:36 _ Link to this message    Send private message to this user   
It's ok. You can edit them if you like. Just click the paper icon at the top right of the post.

Clamp1
Newbie
_
21. October 2006 @ 14:42 _ Link to this message    Send private message to this user   
Here is the AVGAS report


---------------------------------------------------------
AVG Anti-Spyware - Scan Report
---------------------------------------------------------

+ Created at: 5:16:00 PM 10/21/2006

+ Scan result:



C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP14\A0010174.dll -> Adware.Altnet : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP14\A0010175.dll -> Adware.Altnet : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP14\A0010176.exe -> Adware.Altnet : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP14\A0010178.dll -> Adware.Altnet : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP14\A0010179.dll -> Adware.Altnet : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP14\A0010180.dll -> Adware.Altnet : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP14\A0010184.exe -> Adware.Altnet : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP14\A0010191.exe -> Adware.Altnet : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP14\A0010330.exe -> Adware.Altnet : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP19\A0023181.exe -> Adware.AntiVermins : Cleaned with backup (quarantined).
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\\AntiVermins -> Adware.AntiVermins : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP14\A0010145.exe -> Adware.Bestofer : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP14\A0010164.exe -> Adware.Bestofer : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP14\A0010365.exe -> Adware.DriveCleaner : Cleaned with backup (quarantined).
C:\Documents and Settings\HP_Owner\Start Menu\Play Poker Online!.lnk -> Adware.Generic : Cleaned with backup (quarantined).
HKU\S-1-5-21-1247291417-125273098-3146600013-1009\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{44D22A64-2399-4EDF-8B32-F2C729C1E8A7} -> Adware.HQVideoCodec : Cleaned with backup (quarantined).
HKU\S-1-5-21-1247291417-125273098-3146600013-1009\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{D869742A-E5D2-4624-96C7-AAE26170665E} -> Adware.HQVideoCodec : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP13\A0010135.DLL -> Adware.IESearch : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP14\A0010207.DLL -> Adware.IESearch : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP14\A0010234.dll -> Adware.IESearch : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP19\A0023061.exe -> Adware.Malwarewipe : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP19\A0023071.exe -> Adware.Malwarewipe : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP14\A0010153.exe -> Adware.P2PNet : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP0\A0000059.exe -> Backdoor.EggDrop.v : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP1\A0000504.exe -> Backdoor.EggDrop.v : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP1\A0000525.exe -> Backdoor.EggDrop.v : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP1\A0000637.exe -> Backdoor.EggDrop.v : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP1\A0000679.exe -> Backdoor.EggDrop.v : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP1\A0000707.exe -> Backdoor.EggDrop.v : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP1\A0000742.exe -> Backdoor.EggDrop.v : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP1\A0000873.exe -> Backdoor.EggDrop.v : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP1\A0000907.exe -> Backdoor.EggDrop.v : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP5\A0001023.exe -> Backdoor.EggDrop.v : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP5\A0001175.exe -> Backdoor.EggDrop.v : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP8\A0001885.exe -> Backdoor.EggDrop.v : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP8\A0001903.exe -> Backdoor.EggDrop.v : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0002372.exe -> Backdoor.EggDrop.v : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0002503.exe -> Backdoor.EggDrop.v : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0002545.exe -> Backdoor.EggDrop.v : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0004245.exe -> Backdoor.EggDrop.v : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP18\A0015940.sys -> Backdoor.Haxdoor.kl : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP18\A0015964.sys -> Backdoor.Haxdoor.kl : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP18\A0016036.sys -> Backdoor.Haxdoor.kl : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP18\A0016062.sys -> Backdoor.Haxdoor.kl : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP19\A0018963.sys -> Backdoor.Haxdoor.kl : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP19\A0019003.sys -> Backdoor.Haxdoor.kl : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP19\A0019012.sys -> Backdoor.Haxdoor.kl : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP19\A0023060.sys -> Backdoor.Haxdoor.kl : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0004207.exe -> Downloader.Adload.ds : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0004208.exe -> Downloader.Adload.ds : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0004209.exe -> Downloader.Adload.ds : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0004211.exe -> Downloader.Adload.ds : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0004212.exe -> Downloader.Agent.aaf : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0004214.exe -> Downloader.Agent.aaf : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0002781.exe -> Downloader.Agent.ala : Cleaned with backup (quarantined).
C:\data -> Downloader.IstBar.nh : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0004204.exe -> Downloader.Qoologic.at : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP18\A0015923.dll -> Downloader.Qoologic.bj : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP18\A0016021.dll -> Downloader.Qoologic.bj : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP19\A0016212.dll -> Downloader.Qoologic.bj : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP19\A0017323.dll -> Downloader.Qoologic.bj : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP19\A0017324.exe -> Downloader.Qoologic.bj : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP19\A0019005.exe -> Downloader.Qoologic.bj : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP19\A0019010.exe -> Downloader.Qoologic.bj : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP19\A0019011.exe -> Downloader.Qoologic.bj : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP18\A0015925.exe -> Downloader.Small : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP18\A0015963.exe -> Downloader.Small : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0004188.exe -> Downloader.Small : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0004189.exe -> Downloader.Small : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0004201.dll -> Downloader.Small.ctp : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0002775.exe -> Downloader.Small.cyh : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0004192.exe -> Downloader.TSUpdate.f : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0004196.exe -> Downloader.TSUpdate.l : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0004193.exe -> Downloader.TSUpdate.n : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0004194.exe -> Downloader.TSUpdate.r : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP10\A0005714.exe -> Downloader.VB.aga : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0004210.exe -> Downloader.VB.agk : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0004198.exe -> Downloader.VB.aiy : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP19\A0017151.dll -> Downloader.Zlob.apu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP19\A0017152.exe -> Downloader.Zlob.apu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP19\A0017153.exe -> Downloader.Zlob.apu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP19\A0017165.dll -> Downloader.Zlob.apu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP19\A0017166.exe -> Downloader.Zlob.apu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP19\A0017167.exe -> Downloader.Zlob.apu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP19\A0017180.dll -> Downloader.Zlob.apu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP19\A0017181.exe -> Downloader.Zlob.apu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP19\A0017182.exe -> Downloader.Zlob.apu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP19\A0018997.dll -> Downloader.Zlob.apu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP19\A0018998.exe -> Downloader.Zlob.apu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP19\A0018999.exe -> Downloader.Zlob.apu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP19\A0019022.dll -> Downloader.Zlob.apu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP19\A0019023.exe -> Downloader.Zlob.apu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP19\A0019024.exe -> Downloader.Zlob.apu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP19\A0020023.dll -> Downloader.Zlob.apu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP19\A0020024.exe -> Downloader.Zlob.apu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP19\A0020025.exe -> Downloader.Zlob.apu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP19\A0021022.dll -> Downloader.Zlob.apu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP19\A0021023.exe -> Downloader.Zlob.apu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP19\A0021024.exe -> Downloader.Zlob.apu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP19\A0022022.dll -> Downloader.Zlob.apu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP19\A0022023.exe -> Downloader.Zlob.apu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP19\A0022024.exe -> Downloader.Zlob.apu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP19\A0022041.dll -> Downloader.Zlob.apu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP19\A0022042.exe -> Downloader.Zlob.apu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP19\A0022043.exe -> Downloader.Zlob.apu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP19\A0023041.dll -> Downloader.Zlob.apu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP19\A0023042.exe -> Downloader.Zlob.apu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP19\A0023043.exe -> Downloader.Zlob.apu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP19\A0023087.dll -> Downloader.Zlob.apu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP19\A0023088.exe -> Downloader.Zlob.apu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP19\A0023089.exe -> Downloader.Zlob.apu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP19\A0023111.dll -> Downloader.Zlob.apu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP19\A0023112.exe -> Downloader.Zlob.apu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP19\A0023113.exe -> Downloader.Zlob.apu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP19\A0023136.dll -> Downloader.Zlob.apu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP19\A0023137.exe -> Downloader.Zlob.apu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP19\A0023138.exe -> Downloader.Zlob.apu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP19\A0023159.exe -> Downloader.Zlob.apu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP19\A0023160.dll -> Downloader.Zlob.apu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP19\A0023161.exe -> Downloader.Zlob.apu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP19\A0023189.dll -> Downloader.Zlob.apu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP19\A0023190.exe -> Downloader.Zlob.apu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP19\A0023193.exe -> Downloader.Zlob.apu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP19\A0023194.exe -> Downloader.Zlob.apu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0004250.exe -> Dropper.Agent.aie : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0002782.exe -> Dropper.Agent.hl : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0004244.exe -> Dropper.Agent.hl : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0002774.exe -> Dropper.Agent.mu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP1\A0000929.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0002766.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0002785.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0002786.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0002787.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0002788.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0002789.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0002790.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0002791.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0002792.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0002793.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0002794.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0002795.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0002796.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0002797.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0002798.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0002799.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0002800.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0002801.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0002802.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0002803.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0002804.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0002805.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0002806.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0002807.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0002808.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0002809.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0002810.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0002811.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0002812.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0002813.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0002814.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0002815.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0002816.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0002817.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0002818.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0002819.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0002820.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0002821.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0002822.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0002823.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0002824.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0002825.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0002826.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0002827.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0002828.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0002829.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0002830.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0002831.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0002832.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0002833.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0002834.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0002835.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0002836.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0002837.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0002838.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0002839.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0002840.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0002841.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0002842.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0002843.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0002844.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0002845.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0002846.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0002847.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0002848.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0002849.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0002850.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0002851.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0002852.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0002853.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0002854.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0002855.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0002856.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0002857.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0002858.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0002859.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0002860.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0002861.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0002862.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0002863.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0002864.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0002865.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0002866.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0002867.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0002868.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0002869.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0002870.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0002871.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0002872.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0002873.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0002874.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0002875.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0002876.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0002877.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0002878.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0002879.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0002880.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0002881.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0002882.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0002883.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0002884.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0002885.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0002886.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0002887.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0002888.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0002889.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0002890.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0002891.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0002892.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0002893.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0002894.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0002895.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0002896.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0002897.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0002898.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0002899.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0002900.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0002901.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0002902.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0002903.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0002904.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0002905.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0002906.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0002907.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0002908.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0002909.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0002910.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0002911.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0002912.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0002913.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0002914.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0002915.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0002916.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0002917.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0002918.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0002919.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0002920.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0002921.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0002922.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0002923.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0002924.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0002925.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0002926.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0002927.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0002928.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0002929.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0002930.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0002931.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0002932.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0002933.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0002934.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0002935.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0002936.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0002937.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0002938.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0002939.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0002940.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0002941.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0002942.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0002943.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0002944.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0002945.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0002946.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0002947.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0002948.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0002949.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0002950.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0002951.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0002952.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0002953.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0002954.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0002955.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0002956.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0002957.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0002958.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0002959.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0002960.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0002961.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0002962.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0002963.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0002964.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0002965.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0002966.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0002967.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0002968.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0002969.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0002970.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0002971.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0002972.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0002973.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0002974.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0002975.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0002976.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0002977.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0002978.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0002979.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0002980.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0002981.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0002982.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0002983.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0002984.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0002985.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0002986.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0002987.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0002988.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0002989.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0002990.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0002991.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0002992.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0002993.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0002994.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0002995.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0002996.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0002997.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0002998.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0002999.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003000.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003001.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003002.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003003.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003004.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003005.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003006.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003007.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003008.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003009.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003010.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003011.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003012.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003013.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003014.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003015.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003016.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003017.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003018.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003019.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003020.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003021.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003022.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003023.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003024.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003025.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003026.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003027.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003028.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003029.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003030.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003031.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003032.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003033.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003034.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003035.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003036.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003037.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003038.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003039.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003040.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003041.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003042.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003043.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003044.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003045.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003046.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003047.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003048.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003049.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003050.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003051.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003052.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003053.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003054.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003055.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003056.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003057.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003058.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003059.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003060.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003061.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003062.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003063.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003064.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003065.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003066.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003067.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003068.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003069.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003070.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003071.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003072.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003073.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003074.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003075.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003076.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003077.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003078.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003079.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003080.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003081.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003082.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003083.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003084.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003085.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003086.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003087.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003088.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003089.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003090.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003091.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003092.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003093.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003094.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003095.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003096.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003097.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003098.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003099.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003100.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003101.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003102.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003103.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003104.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003105.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003106.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003107.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003108.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003109.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003110.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003111.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003112.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003113.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003114.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003115.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003116.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003117.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003118.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003119.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003120.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003121.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003122.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003123.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003124.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003125.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003126.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003127.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003128.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003129.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003130.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003131.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003132.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003133.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003134.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003135.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003136.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003137.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003138.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003139.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003140.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003141.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003142.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003143.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003144.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003145.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003146.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003147.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003148.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003149.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003150.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003151.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003152.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003153.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003154.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003155.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003156.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003157.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003158.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003159.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003160.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003161.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003162.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003163.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003164.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003165.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003166.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003167.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003168.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003169.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003170.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003171.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003172.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003173.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003174.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003175.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003176.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003177.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003178.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003179.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003180.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003181.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003182.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003183.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003184.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003185.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003186.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003187.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003188.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003189.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003190.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003191.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003192.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003193.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003194.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003195.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003196.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003197.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003198.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003199.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003200.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003201.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003202.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003203.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003204.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003205.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003206.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003207.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003208.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003209.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003210.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003211.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003212.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003213.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003214.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003215.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003216.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003217.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003218.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003219.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003220.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003221.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003222.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003223.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003224.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003225.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003226.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003227.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003228.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003229.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003230.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003231.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003232.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003233.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003234.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003235.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003236.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003237.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003238.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003239.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003240.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003241.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003242.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003243.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003244.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003245.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003246.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003247.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003248.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003249.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003250.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003251.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003252.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003253.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003254.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003255.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003256.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003257.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003258.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003259.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003260.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003261.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003262.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003263.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003264.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003265.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003266.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003267.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003268.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003269.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003270.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003271.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003272.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003273.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003274.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003275.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003276.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003277.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003278.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003279.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003280.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003281.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003282.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003283.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003284.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003285.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003286.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003287.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003288.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003289.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003290.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003291.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003292.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003293.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003294.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003295.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003296.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003297.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003298.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003299.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003300.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003301.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003302.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003303.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003304.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003305.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003306.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003307.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003308.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003309.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003310.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003311.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003312.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003313.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003314.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003315.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003316.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003317.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003318.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003319.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003320.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003321.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003322.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003323.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003324.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003325.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003326.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003327.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003328.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003329.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003330.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003331.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003332.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003333.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003334.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003335.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003336.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003337.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003338.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003339.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003340.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003341.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003342.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003343.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003344.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003345.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003346.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003347.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003348.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003349.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003350.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003351.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003352.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003353.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003354.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003355.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003356.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003357.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003358.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003359.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003360.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003361.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003362.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003363.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003364.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003365.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003366.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003367.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003368.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003369.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003370.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003371.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003372.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003373.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003374.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003375.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003376.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003377.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003378.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003379.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003380.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003381.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003382.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003383.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003384.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003385.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003386.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003387.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003388.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003389.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003390.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003391.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003392.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003393.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003394.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003395.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003396.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003397.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003398.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003399.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003400.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003401.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003402.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003403.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003404.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003405.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003406.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003407.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003408.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003409.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003410.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003411.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003412.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003413.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003414.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003415.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003416.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003417.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003418.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003419.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003420.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003421.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003422.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003423.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003424.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003425.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003426.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003427.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003428.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003429.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003430.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003431.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003432.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003433.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003434.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003435.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003436.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003437.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003438.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003439.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003440.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003441.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003442.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003443.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003444.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003445.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003446.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003447.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003448.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003449.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003450.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003451.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003452.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003453.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003454.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003455.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003456.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003457.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003458.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003459.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003460.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003461.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003462.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003463.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003464.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003465.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003466.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003467.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003468.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003469.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003470.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003471.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003472.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003473.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003474.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003475.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003476.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003477.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003478.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003479.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003480.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003481.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003482.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003483.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003484.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003485.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003486.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003487.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003488.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003489.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003490.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003491.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003492.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003493.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003494.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003495.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003496.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003497.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003498.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003499.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003500.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003501.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003502.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003503.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003504.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003505.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003506.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003507.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003508.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003509.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003510.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003511.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003512.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003513.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003514.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003515.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003516.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003517.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003518.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003519.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003520.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003521.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003522.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003523.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003524.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003525.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003526.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003527.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003528.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003529.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003530.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003531.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003532.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003533.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003534.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003535.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003536.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003537.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003538.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003539.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003540.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003541.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003542.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003543.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003544.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003545.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003546.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003547.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003548.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003549.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003550.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003551.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003552.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003553.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003554.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003555.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003556.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003557.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003558.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003559.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003560.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003561.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003562.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003563.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003564.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003565.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003566.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003567.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003568.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003569.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003570.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003571.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003572.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003573.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003574.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003575.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003576.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003577.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003578.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003579.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003580.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003581.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003582.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003583.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003584.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003585.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003586.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003587.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003588.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003589.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003590.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003591.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003592.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003593.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003594.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003595.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003596.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003597.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003598.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003599.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003600.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003601.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003602.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003603.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003604.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003605.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003606.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003607.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003608.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003609.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003610.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003611.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003612.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003613.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003614.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003615.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003616.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003617.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003618.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003619.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003620.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003621.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003622.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003623.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003624.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003625.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003626.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003627.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003628.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003629.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003630.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003631.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003632.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003633.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003634.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003635.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003636.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003637.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003638.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003639.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003640.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003641.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003642.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003643.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003644.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003645.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003646.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003647.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003648.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003649.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003650.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003651.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003652.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003653.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003654.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003655.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003656.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003657.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003658.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003659.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003660.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003661.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003662.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003663.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003664.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003665.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003666.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003667.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003668.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003669.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003670.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003671.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003672.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003673.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003674.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003675.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003676.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003677.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003678.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003679.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003680.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003681.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003682.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003683.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003684.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003685.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003686.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003687.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003688.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003689.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003690.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003691.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003692.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003693.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003694.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003695.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003696.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003697.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003698.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003699.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003700.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003701.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003702.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003703.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003704.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003705.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003706.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003707.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003708.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003709.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003710.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003711.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003712.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003713.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003714.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003715.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003716.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003717.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003718.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003719.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003720.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003721.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003722.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003723.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003724.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003725.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003726.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003727.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003728.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003729.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003730.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003731.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003732.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003733.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003734.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003735.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003736.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003737.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003738.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003739.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003740.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003741.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003742.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003743.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003744.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003745.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003746.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003747.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003748.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003749.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003750.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003751.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003752.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003753.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003754.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003755.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003756.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003757.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003758.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003759.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003760.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003761.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003762.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003763.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003764.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003765.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003766.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003767.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003768.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003769.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003770.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003771.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003772.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003773.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003774.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003775.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003776.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003777.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003778.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003779.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003780.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003781.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003782.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003783.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003784.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003785.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003786.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003787.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003788.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003789.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003790.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003791.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003792.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003793.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003794.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003795.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003796.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003797.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003798.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003799.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003800.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003801.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003802.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003803.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003804.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003805.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003806.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003807.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003808.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003809.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003810.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003811.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003812.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003813.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003814.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003815.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003816.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003817.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003818.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003819.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003820.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003821.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003822.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003823.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003824.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003825.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003826.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003827.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003828.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003829.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003830.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003831.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003832.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003833.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003834.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003835.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003836.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003837.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003838.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003839.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003840.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003841.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003842.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003843.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003844.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003845.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003846.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003847.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003848.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003849.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003850.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003851.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003852.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003853.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003854.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003855.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003856.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003857.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003858.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003859.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003860.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003861.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003862.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003863.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003864.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003865.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003866.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003867.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003868.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003869.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003870.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003871.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003872.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003873.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003874.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003875.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003876.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003877.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003878.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003879.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003880.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003881.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003882.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003883.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003884.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003885.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003886.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003887.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003888.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003889.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003890.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003891.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003892.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003893.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003894.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003895.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003896.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003897.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003898.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003899.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003900.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003901.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003902.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003903.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003904.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003905.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003906.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003907.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003908.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003909.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003910.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003911.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003912.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003913.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003914.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003915.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003916.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003917.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003918.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003919.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003920.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003921.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003922.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003923.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003924.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003925.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003926.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003927.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003928.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003929.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003930.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003931.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003932.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003933.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003934.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003935.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003936.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003937.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003938.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003939.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003940.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003941.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003942.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003943.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003944.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003945.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003946.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003947.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003948.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003949.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003950.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003951.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003952.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003953.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003954.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003955.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003956.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003957.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003958.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003959.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003960.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003961.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003962.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003963.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003964.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003965.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003966.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003967.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003968.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003969.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003970.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003971.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003972.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003973.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003974.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003975.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003976.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003977.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003978.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003979.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003980.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003981.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003982.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003983.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003984.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003985.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003986.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003987.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003988.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003989.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003990.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003991.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003992.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003993.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003994.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003995.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003996.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003997.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003998.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0003999.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0004000.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0004001.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0004002.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0004003.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0004004.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0004005.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0004006.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0004007.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0004008.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0004009.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0004010.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0004011.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0004012.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0004013.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0004014.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0004015.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0004016.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0004017.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0004018.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0004019.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0004020.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0004021.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0004022.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0004023.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0004024.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0004025.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0004026.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0004027.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0004028.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0004029.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0004030.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0004031.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0004032.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0004033.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0004034.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0004035.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0004036.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0004037.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0004038.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0004039.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0004040.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0004041.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0004042.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0004043.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0004044.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0004045.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0004046.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0004047.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0004048.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0004049.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0004050.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0004051.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0004052.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0004053.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0004054.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0004055.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0004056.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0004057.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0004058.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0004059.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0004060.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0004061.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0004062.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0004063.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0004064.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0004065.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0004066.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0004067.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0004068.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0004069.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0004070.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0004071.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0004072.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0004073.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0004074.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0004075.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0004076.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0004077.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0004078.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0004079.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0004080.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0004081.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0004082.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0004083.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0004084.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0004085.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0004086.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0004087.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0004088.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0004089.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0004090.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0004091.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0004092.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0004093.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0004094.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0004095.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0004096.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0004097.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0004098.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0004099.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0004100.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0004101.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0004102.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0004103.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0004104.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0004105.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0004106.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0004107.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0004108.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0004109.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0004110.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0004111.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0004112.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0004113.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0004114.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0004115.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0004116.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0004117.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0004118.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0004119.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0004120.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0004121.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0004122.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0004123.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0004124.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0004125.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0004126.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0004127.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0004128.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0004129.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0004130.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0004131.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0004132.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0004133.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0004134.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0004135.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0004136.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0004137.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0004138.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0004139.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0004140.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0004141.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0004142.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0004143.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0004144.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0004145.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0004146.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0004147.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0004148.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0004149.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0004150.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0004151.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0004152.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0004153.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0004154.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0004155.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0004156.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0004157.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0004158.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0004159.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0004160.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0004161.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0004162.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0004163.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0004164.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0004165.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0004166.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0004167.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0004168.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0004169.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0004170.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0004171.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0004172.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0004173.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0004174.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0004175.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0004176.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0004177.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0004178.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0004179.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0004180.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0004181.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0004182.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0004183.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0004184.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0004185.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0004186.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0004187.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
C:\Documents and Settings\Kaucher.MY-F78BF48CE2\Local Settings\Temporary Internet Files\Content.IE5\C9IJSHYZ\popup[10].htm -> Hijacker.Agent.a : Cleaned with backup (quarantined).
C:\Documents and Settings\Kaucher.MY-F78BF48CE2\Local Settings\Temporary Internet Files\Content.IE5\C9IJSHYZ\popup[11].htm -> Hijacker.Agent.a : Cleaned with backup (quarantined).
C:\Documents and Settings\Kaucher.MY-F78BF48CE2\Local Settings\Temporary Internet Files\Content.IE5\C9IJSHYZ\popup[12].htm -> Hijacker.Agent.a : Cleaned with backup (quarantined).
C:\Documents and Settings\Kaucher.MY-F78BF48CE2\Local Settings\Temporary Internet Files\Content.IE5\C9IJSHYZ\popup[13].htm -> Hijacker.Agent.a : Cleaned with backup (quarantined).
C:\Documents and Settings\Kaucher.MY-F78BF48CE2\Local Settings\Temporary Internet Files\Content.IE5\C9IJSHYZ\popup[14].htm -> Hijacker.Agent.a : Cleaned with backup (quarantined).
C:\Documents and Settings\Kaucher.MY-F78BF48CE2\Local Settings\Temporary Internet Files\Content.IE5\C9IJSHYZ\popup[15].htm -> Hijacker.Agent.a : Cleaned with backup (quarantined).
C:\Documents and Settings\Kaucher.MY-F78BF48CE2\Local Settings\Temporary Internet Files\Content.IE5\C9IJSHYZ\popup[16].htm -> Hijacker.Agent.a : Cleaned with backup (quarantined).
C:\Documents and Settings\Kaucher.MY-F78BF48CE2\Local Settings\Temporary Internet Files\Content.IE5\C9IJSHYZ\popup[17].htm -> Hijacker.Agent.a : Cleaned with backup (quarantined).
C:\Documents and Settings\Kaucher.MY-F78BF48CE2\Local Settings\Temporary Internet Files\Content.IE5\C9IJSHYZ\popup[18].htm -> Hijacker.Agent.a : Cleaned with backup (quarantined).
C:\Documents and Settings\Kaucher.MY-F78BF48CE2\Local Settings\Temporary Internet Files\Content.IE5\C9IJSHYZ\popup[19].htm -> Hijacker.Agent.a : Cleaned with backup (quarantined).
C:\Documents and Settings\Kaucher.MY-F78BF48CE2\Local Settings\Temporary Internet Files\Content.IE5\C9IJSHYZ\popup[1].htm -> Hijacker.Agent.a : Cleaned with backup (quarantined).
C:\Documents and Settings\Kaucher.MY-F78BF48CE2\Local Settings\Temporary Internet Files\Content.IE5\C9IJSHYZ\popup[20].htm -> Hijacker.Agent.a : Cleaned with backup (quarantined).
C:\Documents and Settings\Kaucher.MY-F78BF48CE2\Local Settings\Temporary Internet Files\Content.IE5\C9IJSHYZ\popup[21].htm -> Hijacker.Agent.a : Cleaned with backup (quarantined).
C:\Documents and Settings\Kaucher.MY-F78BF48CE2\Local Settings\Temporary Internet Files\Content.IE5\C9IJSHYZ\popup[22].htm -> Hijacker.Agent.a : Cleaned with backup (quarantined).
C:\Documents and Settings\Kaucher.MY-F78BF48CE2\Local Settings\Temporary Internet Files\Content.IE5\C9IJSHYZ\popup[23].htm -> Hijacker.Agent.a : Cleaned with backup (quarantined).
C:\Documents and Settings\Kaucher.MY-F78BF48CE2\Local Settings\Temporary Internet Files\Content.IE5\C9IJSHYZ\popup[24].htm -> Hijacker.Agent.a : Cleaned with backup (quarantined).
C:\Documents and Settings\Kaucher.MY-F78BF48CE2\Local Settings\Temporary Internet Files\Content.IE5\C9IJSHYZ\popup[25].htm -> Hijacker.Agent.a : Cleaned with backup (quarantined).
C:\Documents and Settings\Kaucher.MY-F78BF48CE2\Local Settings\Temporary Internet Files\Content.IE5\C9IJSHYZ\popup[26].htm -> Hijacker.Agent.a : Cleaned with backup (quarantined).
C:\Documents and Settings\Kaucher.MY-F78BF48CE2\Local Settings\Temporary Internet Files\Content.IE5\C9IJSHYZ\popup[27].htm -> Hijacker.Agent.a : Cleaned with backup (quarantined).
C:\Documents and Settings\Kaucher.MY-F78BF48CE2\Local Settings\Temporary Internet Files\Content.IE5\C9IJSHYZ\popup[28].htm -> Hijacker.Agent.a : Cleaned with backup (quarantined).
C:\Documents and Settings\Kaucher.MY-F78BF48CE2\Local Settings\Temporary Internet Files\Content.IE5\C9IJSHYZ\popup[29].htm -> Hijacker.Agent.a : Cleaned with backup (quarantined).
C:\Documents and Settings\Kaucher.MY-F78BF48CE2\Local Settings\Temporary Internet Files\Content.IE5\C9IJSHYZ\popup[2].htm -> Hijacker.Agent.a : Cleaned with backup (quarantined).
C:\Documents and Settings\Kaucher.MY-F78BF48CE2\Local Settings\Temporary Internet Files\Content.IE5\C9IJSHYZ\popup[30].htm -> Hijacker.Agent.a : Cleaned with backup (quarantined).
C:\Documents and Settings\Kaucher.MY-F78BF48CE2\Local Settings\Temporary Internet Files\Content.IE5\C9IJSHYZ\popup[31].htm -> Hijacker.Agent.a : Cleaned with backup (quarantined).
C:\Documents and Settings\Kaucher.MY-F78BF48CE2\Local Settings\Temporary Internet Files\Content.IE5\C9IJSHYZ\popup[32].htm -> Hijacker.Agent.a : Cleaned with backup (quarantined).
C:\Documents and Settings\Kaucher.MY-F78BF48CE2\Local Settings\Temporary Internet Files\Content.IE5\C9IJSHYZ\popup[33].htm -> Hijacker.Agent.a : Cleaned with backup (quarantined).
C:\Documents and Settings\Kaucher.MY-F78BF48CE2\Local Settings\Temporary Internet Files\Content.IE5\C9IJSHYZ\popup[34].htm -> Hijacker.Agent.a : Cleaned with backup (quarantined).
C:\Documents and Settings\Kaucher.MY-F78BF48CE2\Local Settings\Temporary Internet Files\Content.IE5\C9IJSHYZ\popup[35].htm -> Hijacker.Agent.a : Cleaned with backup (quarantined).
C:\Documents and Settings\Kaucher.MY-F78BF48CE2\Local Settings\Temporary Internet Files\Content.IE5\C9IJSHYZ\popup[36].htm -> Hijacker.Agent.a : Cleaned with backup (quarantined).
C:\Documents and Settings\Kaucher.MY-F78BF48CE2\Local Settings\Temporary Internet Files\Content.IE5\C9IJSHYZ\popup[37].htm -> Hijacker.Agent.a : Cleaned with backup (quarantined).
C:\Documents and Settings\Kaucher.MY-F78BF48CE2\Local Settings\Temporary Internet Files\Content.IE5\C9IJSHYZ\popup[38].htm -> Hijacker.Agent.a : Cleaned with backup (quarantined).
C:\Documents and Settings\Kaucher.MY-F78BF48CE2\Local Settings\Temporary Internet Files\Content.IE5\C9IJSHYZ\popup[39].htm -> Hijacker.Agent.a : Cleaned with backup (quarantined).
C:\Documents and Settings\Kaucher.MY-F78BF48CE2\Local Settings\Temporary Internet Files\Content.IE5\C9IJSHYZ\popup[3].htm -> Hijacker.Agent.a : Cleaned with backup (quarantined).
C:\Documents and Settings\Kaucher.MY-F78BF48CE2\Local Settings\Temporary Internet Files\Content.IE5\C9IJSHYZ\popup[40].htm -> Hijacker.Agent.a : Cleaned with backup (quarantined).
C:\Documents and Settings\Kaucher.MY-F78BF48CE2\Local Settings\Temporary Internet Files\Content.IE5\C9IJSHYZ\popup[41].htm -> Hijacker.Agent.a : Cleaned with backup (quarantined).
C:\Documents and Settings\Kaucher.MY-F78BF48CE2\Local Settings\Temporary Internet Files\Content.IE5\C9IJSHYZ\popup[42].htm -> Hijacker.Agent.a : Cleaned with backup (quarantined).
C:\Documents and Settings\Kaucher.MY-F78BF48CE2\Local Settings\Temporary Internet Files\Content.IE5\C9IJSHYZ\popup[43].htm -> Hijacker.Agent.a : Cleaned with backup (quarantined).
C:\Documents and Settings\Kaucher.MY-F78BF48CE2\Local Settings\Temporary Internet Files\Content.IE5\C9IJSHYZ\popup[44].htm -> Hijacker.Agent.a : Cleaned with backup (quarantined).
C:\Documents and Settings\Kaucher.MY-F78BF48CE2\Local Settings\Temporary Internet Files\Content.IE5\C9IJSHYZ\popup[4].htm -> Hijacker.Agent.a : Cleaned with backup (quarantined).
C:\Documents and Settings\Kaucher.MY-F78BF48CE2\Local Settings\Temporary Internet Files\Content.IE5\C9IJSHYZ\popup[5].htm -> Hijacker.Agent.a : Cleaned with backup (quarantined).
C:\Documents and Settings\Kaucher.MY-F78BF48CE2\Local Settings\Temporary Internet Files\Content.IE5\C9IJSHYZ\popup[6].htm -> Hijacker.Agent.a : Cleaned with backup (quarantined).
C:\Documents and Settings\Kaucher.MY-F78BF48CE2\Local Settings\Temporary Internet Files\Content.IE5\C9IJSHYZ\popup[7].htm -> Hijacker.Agent.a : Cleaned with backup (quarantined).
C:\Documents and Settings\Kaucher.MY-F78BF48CE2\Local Settings\Temporary Internet Files\Content.IE5\C9IJSHYZ\popup[8].htm -> Hijacker.Agent.a : Cleaned with backup (quarantined).
C:\Documents and Settings\Kaucher.MY-F78BF48CE2\Local Settings\Temporary Internet Files\Content.IE5\C9IJSHYZ\popup[9].htm -> Hijacker.Agent.a : Cleaned with backup (quarantined).
C:\Documents and Settings\Kaucher.MY-F78BF48CE2\Local Settings\Temporary Internet Files\Content.IE5\GP2JKLIB\popup[10].htm -> Hijacker.Agent.a : Cleaned with backup (quarantined).
C:\Documents and Settings\Kaucher.MY-F78BF48CE2\Local Settings\Temporary Internet Files\Content.IE5\GP2JKLIB\popup[11].htm -> Hijacker.Agent.a : Cleaned with backup (quarantined).
C:\Documents and Settings\Kaucher.MY-F78BF48CE2\Local Settings\Temporary Internet Files\Content.IE5\GP2JKLIB\popup[12].htm -> Hijacker.Agent.a : Cleaned with backup (quarantined).
C:\Documents and Settings\Kaucher.MY-F78BF48CE2\Local Settings\Temporary Internet Files\Content.IE5\GP2JKLIB\popup[13].htm -> Hijacker.Agent.a : Cleaned with backup (quarantined).
C:\Documents and Settings\Kaucher.MY-F78BF48CE2\Local Settings\Temporary Internet Files\Content.IE5\GP2JKLIB\popup[14].htm -> Hijacker.Agent.a : Cleaned with backup (quarantined).
C:\Documents and Settings\Kaucher.MY-F78BF48CE2\Local Settings\Temporary Internet Files\Content.IE5\GP2JKLIB\popup[15].htm -> Hijacker.Agent.a : Cleaned with backup (quarantined).
C:\Documents and Settings\Kaucher.MY-F78BF48CE2\Local Settings\Temporary Internet Files\Content.IE5\GP2JKLIB\popup[16].htm -> Hijacker.Agent.a : Cleaned with backup (quarantined).
C:\Documents and Settings\Kaucher.MY-F78BF48CE2\Local Settings\Temporary Internet Files\Content.IE5\GP2JKLIB\popup[17].htm -> Hijacker.Agent.a : Cleaned with backup (quarantined).
C:\Documents and Settings\Kaucher.MY-F78BF48CE2\Local Settings\Temporary Internet Files\Content.IE5\GP2JKLIB\popup[18].htm -> Hijacker.Agent.a : Cleaned with backup (quarantined).
C:\Documents and Settings\Kaucher.MY-F78BF48CE2\Local Settings\Temporary Internet Files\Content.IE5\GP2JKLIB\popup[19].htm -> Hijacker.Agent.a : Cleaned with backup (quarantined).
C:\Documents and Settings\Kaucher.MY-F78BF48CE2\Local Settings\Temporary Internet Files\Content.IE5\GP2JKLIB\popup[1].htm -> Hijacker.Agent.a : Cleaned with backup (quarantined).
C:\Documents and Settings\Kaucher.MY-F78BF48CE2\Local Settings\Temporary Internet Files\Content.IE5\GP2JKLIB\popup[20].htm -> Hijacker.Agent.a : Cleaned with backup (quarantined).
C:\Documents and Settings\Kaucher.MY-F78BF48CE2\Local Settings\Temporary Internet Files\Content.IE5\GP2JKLIB\popup[21].htm -> Hijacker.Agent.a : Cleaned with backup (quarantined).
C:\Documents and Settings\Kaucher.MY-F78BF48CE2\Local Settings\Temporary Internet Files\Content.IE5\GP2JKLIB\popup[22].htm -> Hijacker.Agent.a : Cleaned with backup (quarantined).
C:\Documents and Settings\Kaucher.MY-F78BF48CE2\Local Settings\Temporary Internet Files\Content.IE5\GP2JKLIB\popup[23].htm -> Hijacker.Agent.a : Cleaned with backup (quarantined).
C:\Documents and Settings\Kaucher.MY-F78BF48CE2\Local Settings\Temporary Internet Files\Content.IE5\GP2JKLIB\popup[24].htm -> Hijacker.Agent.a : Cleaned with backup (quarantined).
C:\Documents and Settings\Kaucher.MY-F78BF48CE2\Local Settings\Temporary Internet Files\Content.IE5\GP2JKLIB\popup[25].htm -> Hijacker.Agent.a : Cleaned with backup (quarantined).
C:\Documents and Settings\Kaucher.MY-F78BF48CE2\Local Settings\Temporary Internet Files\Content.IE5\GP2JKLIB\popup[26].htm -> Hijacker.Agent.a : Cleaned with backup (quarantined).
C:\Documents and Settings\Kaucher.MY-F78BF48CE2\Local Settings\Temporary Internet Files\Content.IE5\GP2JKLIB\popup[27].htm -> Hijacker.Agent.a : Cleaned with backup (quarantined).
C:\Documents and Settings\Kaucher.MY-F78BF48CE2\Local Settings\Temporary Internet Files\Content.IE5\GP2JKLIB\popup[28].htm -> Hijacker.Agent.a : Cleaned with backup (quarantined).
C:\Documents and Settings\Kaucher.MY-F78BF48CE2\Local Settings\Temporary Internet Files\Content.IE5\GP2JKLIB\popup[29].htm -> Hijacker.Agent.a : Cleaned with backup (quarantined).
C:\Documents and Settings\Kaucher.MY-F78BF48CE2\Local Settings\Temporary Internet Files\Content.IE5\GP2JKLIB\popup[2].htm -> Hijacker.Agent.a : Cleaned with backup (quarantined).
C:\Documents and Settings\Kaucher.MY-F78BF48CE2\Local Settings\Temporary Internet Files\Content.IE5\GP2JKLIB\popup[30].htm -> Hijacker.Agent.a : Cleaned with backup (quarantined).
C:\Documents and Settings\Kaucher.MY-F78BF48CE2\Local Settings\Temporary Internet Files\Content.IE5\GP2JKLIB\popup[31].htm -> Hijacker.Agent.a : Cleaned with backup (quarantined).
C:\Documents and Settings\Kaucher.MY-F78BF48CE2\Local Settings\Temporary Internet Files\Content.IE5\GP2JKLIB\popup[32].htm -> Hijacker.Agent.a : Cleaned with backup (quarantined).
C:\Documents and Settings\Kaucher.MY-F78BF48CE2\Local Settings\Temporary Internet Files\Content.IE5\GP2JKLIB\popup[33].htm -> Hijacker.Agent.a : Cleaned with backup (quarantined).
C:\Documents and Settings\Kaucher.MY-F78BF48CE2\Local Settings\Temporary Internet Files\Content.IE5\GP2JKLIB\popup[34].htm -> Hijacker.Agent.a : Cleaned with backup (quarantined).
C:\Documents and Settings\Kaucher.MY-F78BF48CE2\Local Settings\Temporary Internet Files\Content.IE5\GP2JKLIB\popup[35].htm -> Hijacker.Agent.a : Cleaned with backup (quarantined).
C:\Documents and Settings\Kaucher.MY-F78BF48CE2\Local Settings\Temporary Internet Files\Content.IE5\GP2JKLIB\popup[36].htm -> Hijacker.Agent.a : Cleaned with backup (quarantined).
C:\Documents and Settings\Kaucher.MY-F78BF48CE2\Local Settings\Temporary Internet Files\Content.IE5\GP2JKLIB\popup[37].htm -> Hijacker.Agent.a : Cleaned with backup (quarantined).
C:\Documents and Settings\Kaucher.MY-F78BF48CE2\Local Settings\Temporary Internet Files\Content.IE5\GP2JKLIB\popup[38].htm -> Hijacker.Agent.a : Cleaned with backup (quarantined).
C:\Documents and Settings\Kaucher.MY-F78BF48CE2\Local Settings\Temporary Internet Files\Content.IE5\GP2JKLIB\popup[39].htm -> Hijacker.Agent.a : Cleaned with backup (quarantined).
C:\Documents and Settings\Kaucher.MY-F78BF48CE2\Local Settings\Temporary Internet Files\Content.IE5\GP2JKLIB\popup[3].htm -> Hijacker.Agent.a : Cleaned with backup (quarantined).
C:\Documents and Settings\Kaucher.MY-F78BF48CE2\Local Settings\Temporary Internet Files\Content.IE5\GP2JKLIB\popup[40].htm -> Hijacker.Agent.a : Cleaned with backup (quarantined).
C:\Documents and Settings\Kaucher.MY-F78BF48CE2\Local Settings\Temporary Internet Files\Content.IE5\GP2JKLIB\popup[41].htm -> Hijacker.Agent.a : Cleaned with backup (quarantined).
C:\Documents and Settings\Kaucher.MY-F78BF48CE2\Local Settings\Temporary Internet Files\Content.IE5\GP2JKLIB\popup[42].htm -> Hijacker.Agent.a : Cleaned with backup (quarantined).
C:\Documents and Settings\Kaucher.MY-F78BF48CE2\Local Settings\Temporary Internet Files\Content.IE5\GP2JKLIB\popup[43].htm -> Hijacker.Agent.a : Cleaned with backup (quarantined).
C:\Documents and Settings\Kaucher.MY-F78BF48CE2\Local Settings\Temporary Internet Files\Content.IE5\GP2JKLIB\popup[44].htm -> Hijacker.Agent.a : Cleaned with backup (quarantined).
C:\Documents and Settings\Kaucher.MY-F78BF48CE2\Local Settings\Temporary Internet Files\Content.IE5\GP2JKLIB\popup[45].htm -> Hijacker.Agent.a : Cleaned with backup (quarantined).
C:\Documents and Settings\Kaucher.MY-F78BF48CE2\Local Settings\Temporary Internet Files\Content.IE5\GP2JKLIB\popup[4].htm -> Hijacker.Agent.a : Cleaned with backup (quarantined).
C:\Documents and Settings\Kaucher.MY-F78BF48CE2\Local Settings\Temporary Internet Files\Content.IE5\GP2JKLIB\popup[5].htm -> Hijacker.Agent.a : Cleaned with backup (quarantined).
C:\Documents and Settings\Kaucher.MY-F78BF48CE2\Local Settings\Temporary Internet Files\Content.IE5\GP2JKLIB\popup[6].htm -> Hijacker.Agent.a : Cleaned with backup (quarantined).
C:\Documents and Settings\Kaucher.MY-F78BF48CE2\Local Settings\Temporary Internet Files\Content.IE5\GP2JKLIB\popup[7].htm -> Hijacker.Agent.a : Cleaned with backup (quarantined).
C:\Documents and Settings\Kaucher.MY-F78BF48CE2\Local Settings\Temporary Internet Files\Content.IE5\GP2JKLIB\popup[8].htm -> Hijacker.Agent.a : Cleaned with backup (quarantined).
C:\Documents and Settings\Kaucher.MY-F78BF48CE2\Local Settings\Temporary Internet Files\Content.IE5\GP2JKLIB\popup[9].htm -> Hijacker.Agent.a : Cleaned with backup (quarantined).
C:\Documents and Settings\Kaucher.MY-F78BF48CE2\Local Settings\Temporary Internet Files\Content.IE5\KDYRCLM7\popup[10].htm -> Hijacker.Agent.a : Cleaned with backup (quarantined).
C:\Documents and Settings\Kaucher.MY-F78BF48CE2\Local Settings\Temporary Internet Files\Content.IE5\KDYRCLM7\popup[11].htm -> Hijacker.Agent.a : Cleaned with backup (quarantined).
C:\Documents and Settings\Kaucher.MY-F78BF48CE2\Local Settings\Temporary Internet Files\Content.IE5\KDYRCLM7\popup[12].htm -> Hijacker.Agent.a : Cleaned with backup (quarantined).
C:\Documents and Settings\Kaucher.MY-F78BF48CE2\Local Settings\Temporary Internet Files\Content.IE5\KDYRCLM7\popup[13].htm -> Hijacker.Agent.a : Cleaned with backup (quarantined).
C:\Documents and Settings\Kaucher.MY-F78BF48CE2\Local Settings\Temporary Internet Files\Content.IE5\KDYRCLM7\popup[14].htm -> Hijacker.Agent.a : Cleaned with backup (quarantined).
C:\Documents and Settings\Kaucher.MY-F78BF48CE2\Local Settings\Temporary Internet Files\Content.IE5\KDYRCLM7\popup[15].htm -> Hijacker.Agent.a : Cleaned with backup (quarantined).
C:\Documents and Settings\Kaucher.MY-F78BF48CE2\Local Settings\Temporary Internet Files\Content.IE5\KDYRCLM7\popup[16].htm -> Hijacker.Agent.a : Cleaned with backup (quarantined).
C:\Documents and Settings\Kaucher.MY-F78BF48CE2\Local Settings\Temporary Internet Files\Content.IE5\KDYRCLM7\popup[17].htm -> Hijacker.Agent.a : Cleaned with backup (quarantined).
C:\Documents and Settings\Kaucher.MY-F78BF48CE2\Local Settings\Temporary Internet Files\Content.IE5\KDYRCLM7\popup[18].htm -> Hijacker.Agent.a : Cleaned with backup (quarantined).
C:\Documents and Settings\Kaucher.MY-F78BF48CE2\Local Settings\Temporary Internet Files\Content.IE5\KDYRCLM7\popup[19].htm -> Hijacker.Agent.a : Cleaned with backup (quarantined).
C:\Documents and Settings\Kaucher.MY-F78BF48CE2\Local Settings\Temporary Internet Files\Content.IE5\KDYRCLM7\popup[1].htm -> Hijacker.Agent.a : Cleaned with backup (quarantined).
C:\Documents and Settings\Kaucher.MY-F78BF48CE2\Local Settings\Temporary Internet Files\Content.IE5\KDYRCLM7\popup[20].htm -> Hijacker.Agent.a : Cleaned with backup (quarantined).
C:\Documents and Settings\Kaucher.MY-F78BF48CE2\Local Settings\Temporary Internet Files\Content.IE5\KDYRCLM7\popup[21].htm -> Hijacker.Agent.a : Cleaned with backup (quarantined).
C:\Documents and Settings\Kaucher.MY-F78BF48CE2\Local Settings\Temporary Internet Files\Content.IE5\KDYRCLM7\popup[22].htm -> Hijacker.Agent.a : Cleaned with backup (quarantined).
C:\Documents and Settings\Kaucher.MY-F78BF48CE2\Local Settings\Temporary Internet Files\Content.IE5\KDYRCLM7\popup[23].htm -> Hijacker.Agent.a : Cleaned with backup (quarantined).
C:\Documents and Settings\Kaucher.MY-F78BF48CE2\Local Settings\Temporary Internet Files\Content.IE5\KDYRCLM7\popup[24].htm -> Hijacker.Agent.a : Cleaned with backup (quarantined).
C:\Documents and Settings\Kaucher.MY-F78BF48CE2\Local Settings\Temporary Internet Files\Content.IE5\KDYRCLM7\popup[25].htm -> Hijacker.Agent.a : Cleaned with backup (quarantined).
C:\Documents and Settings\Kaucher.MY-F78BF48CE2\Local Settings\Temporary Internet Files\Content.IE5\KDYRCLM7\popup[26].htm -> Hijacker.Agent.a : Cleaned with backup (quarantined).
C:\Documents and Settings\Kaucher.MY-F78BF48CE2\Local Settings\Temporary Internet Files\Content.IE5\KDYRCLM7\popup[27].htm -> Hijacker.Agent.a : Cleaned with backup (quarantined).
C:\Documents and Settings\Kaucher.MY-F78BF48CE2\Local Settings\Temporary Internet Files\Content.IE5\KDYRCLM7\popup[28].htm -> Hijacker.Agent.a : Cleaned with backup (quarantined).
C:\Documents and Settings\Kaucher.MY-F78BF48CE2\Local Settings\Temporary Internet Files\Content.IE5\KDYRCLM7\popup[29].htm -> Hijacker.Agent.a : Cleaned with backup (quarantined).
C:\Documents and Settings\Kaucher.MY-F78BF48CE2\Local Settings\Temporary Internet Files\Content.IE5\KDYRCLM7\popup[2].htm -> Hijacker.Agent.a : Cleaned with backup (quarantined).
C:\Documents and Settings\Kaucher.MY-F78BF48CE2\Local Settings\Temporary Internet Files\Content.IE5\KDYRCLM7\popup[30].htm -> Hijacker.Agent.a : Cleaned with backup (quarantined).
C:\Documents and Settings\Kaucher.MY-F78BF48CE2\Local Settings\Temporary Internet Files\Content.IE5\KDYRCLM7\popup[31].htm -> Hijacker.Agent.a : Cleaned with backup (quarantined).
C:\Documents and Settings\Kaucher.MY-F78BF48CE2\Local Settings\Temporary Internet Files\Content.IE5\KDYRCLM7\popup[32].htm -> Hijacker.Agent.a : Cleaned with backup (quarantined).
C:\Documents and Settings\Kaucher.MY-F78BF48CE2\Local Settings\Temporary Internet Files\Content.IE5\KDYRCLM7\popup[33].htm -> Hijacker.Agent.a : Cleaned with backup (quarantined).
C:\Documents and Settings\Kaucher.MY-F78BF48CE2\Local Settings\Temporary Internet Files\Content.IE5\KDYRCLM7\popup[34].htm -> Hijacker.Agent.a : Cleaned with backup (quarantined).
C:\Documents and Settings\Kaucher.MY-F78BF48CE2\Local Settings\Temporary Internet Files\Content.IE5\KDYRCLM7\popup[35].htm -> Hijacker.Agent.a : Cleaned with backup (quarantined).
C:\Documents and Settings\Kaucher.MY-F78BF48CE2\Local Settings\Temporary Internet Files\Content.IE5\KDYRCLM7\popup[36].htm -> Hijacker.Agent.a : Cleaned with backup (quarantined).
C:\Documents and Settings\Kaucher.MY-F78BF48CE2\Local Settings\Temporary Internet Files\Content.IE5\KDYRCLM7\popup[37].htm -> Hijacker.Agent.a : Cleaned with backup (quarantined).
C:\Documents and Settings\Kaucher.MY-F78BF48CE2\Local Settings\Temporary Internet Files\Content.IE5\KDYRCLM7\popup[38].htm -> Hijacker.Agent.a : Cleaned with backup (quarantined).
C:\Documents and Settings\Kaucher.MY-F78BF48CE2\Local Settings\Temporary Internet Files\Content.IE5\KDYRCLM7\popup[39].htm -> Hijacker.Agent.a : Cleaned with backup (quarantined).
C:\Documents and Settings\Kaucher.MY-F78BF48CE2\Local Settings\Temporary Internet Files\Content.IE5\KDYRCLM7\popup[3].htm -> Hijacker.Agent.a : Cleaned with backup (quarantined).
C:\Documents and Settings\Kaucher.MY-F78BF48CE2\Local Settings\Temporary Internet Files\Content.IE5\KDYRCLM7\popup[40].htm -> Hijacker.Agent.a : Cleaned with backup (quarantined).
C:\Documents and Settings\Kaucher.MY-F78BF48CE2\Local Settings\Temporary Internet Files\Content.IE5\KDYRCLM7\popup[41].htm -> Hijacker.Agent.a : Cleaned with backup (quarantined).
C:\Documents and Settings\Kaucher.MY-F78BF48CE2\Local Settings\Temporary Internet Files\Content.IE5\KDYRCLM7\popup[42].htm -> Hijacker.Agent.a : Cleaned with backup (quarantined).
C:\Documents and Settings\Kaucher.MY-F78BF48CE2\Local Settings\Temporary Internet Files\Content.IE5\KDYRCLM7\popup[4].htm -> Hijacker.Agent.a : Cleaned with backup (quarantined).
C:\Documents and Settings\Kaucher.MY-F78BF48CE2\Local Settings\Temporary Internet Files\Content.IE5\KDYRCLM7\popup[5].htm -> Hijacker.Agent.a : Cleaned with backup (quarantined).
C:\Documents and Settings\Kaucher.MY-F78BF48CE2\Local Settings\Temporary Internet Files\Content.IE5\KDYRCLM7\popup[6].htm -> Hijacker.Agent.a : Cleaned with backup (quarantined).
C:\Documents and Settings\Kaucher.MY-F78BF48CE2\Local Settings\Temporary Internet Files\Content.IE5\KDYRCLM7\popup[7].htm -> Hijacker.Agent.a : Cleaned with backup (quarantined).
C:\Documents and Settings\Kaucher.MY-F78BF48CE2\Local Settings\Temporary Internet Files\Content.IE5\KDYRCLM7\popup[8].htm -> Hijacker.Agent.a : Cleaned with backup (quarantined).
C:\Documents and Settings\Kaucher.MY-F78BF48CE2\Local Settings\Temporary Internet Files\Content.IE5\KDYRCLM7\popup[9].htm -> Hijacker.Agent.a : Cleaned with backup (quarantined).
C:\Documents and Settings\Kaucher.MY-F78BF48CE2\Local Settings\Temporary Internet Files\Content.IE5\W9E7KDU3\popup[10].htm -> Hijacker.Agent.a : Cleaned with backup (quarantined).
C:\Documents and Settings\Kaucher.MY-F78BF48CE2\Local Settings\Temporary Internet Files\Content.IE5\W9E7KDU3\popup[11].htm -> Hijacker.Agent.a : Cleaned with backup (quarantined).
C:\Documents and Settings\Kaucher.MY-F78BF48CE2\Local Settings\Temporary Internet Files\Content.IE5\W9E7KDU3\popup[12].htm -> Hijacker.Agent.a : Cleaned with backup (quarantined).
C:\Documents and Settings\Kaucher.MY-F78BF48CE2\Local Settings\Temporary Internet Files\Content.IE5\W9E7KDU3\popup[13].htm -> Hijacker.Agent.a : Cleaned with backup (quarantined).
C:\Documents and Settings\Kaucher.MY-F78BF48CE2\Local Settings\Temporary Internet Files\Content.IE5\W9E7KDU3\popup[14].htm -> Hijacker.Agent.a : Cleaned with backup (quarantined).
C:\Documents and Settings\Kaucher.MY-F78BF48CE2\Local Settings\Temporary Internet Files\Content.IE5\W9E7KDU3\popup[15].htm -> Hijacker.Agent.a : Cleaned with backup (quarantined).
C:\Documents and Settings\Kaucher.MY-F78BF48CE2\Local Settings\Temporary Internet Files\Content.IE5\W9E7KDU3\popup[16].htm -> Hijacker.Agent.a : Cleaned with backup (quarantined).
C:\Documents and Settings\Kaucher.MY-F78BF48CE2\Local Settings\Temporary Internet Files\Content.IE5\W9E7KDU3\popup[17].htm -> Hijacker.Agent.a : Cleaned with backup (quarantined).
C:\Documents and Settings\Kaucher.MY-F78BF48CE2\Local Settings\Temporary Internet Files\Content.IE5\W9E7KDU3\popup[18].htm -> Hijacker.Agent.a : Cleaned with backup (quarantined).
C:\Documents and Settings\Kaucher.MY-F78BF48CE2\Local Settings\Temporary Internet Files\Content.IE5\W9E7KDU3\popup[19].htm -> Hijacker.Agent.a : Cleaned with backup (quarantined).
C:\Documents and Settings\Kaucher.MY-F78BF48CE2\Local Settings\Temporary Internet Files\Content.IE5\W9E7KDU3\popup[1].htm -> Hijacker.Agent.a : Cleaned with backup (quarantined).
C:\Documents and Settings\Kaucher.MY-F78BF48CE2\Local Settings\Temporary Internet Files\Content.IE5\W9E7KDU3\popup[20].htm -> Hijacker.Agent.a : Cleaned with backup (quarantined).
C:\Documents and Settings\Kaucher.MY-F78BF48CE2\Local Settings\Temporary Internet Files\Content.IE5\W9E7KDU3\popup[21].htm -> Hijacker.Agent.a : Cleaned with backup (quarantined).
C:\Documents and Settings\Kaucher.MY-F78BF48CE2\Local Settings\Temporary Internet Files\Content.IE5\W9E7KDU3\popup[22].htm -> Hijacker.Agent.a : Cleaned with backup (quarantined).
C:\Documents and Settings\Kaucher.MY-F78BF48CE2\Local Settings\Temporary Internet Files\Content.IE5\W9E7KDU3\popup[23].htm -> Hijacker.Agent.a : Cleaned with backup (quarantined).
C:\Documents and Settings\Kaucher.MY-F78BF48CE2\Local Settings\Temporary Internet Files\Content.IE5\W9E7KDU3\popup[24].htm -> Hijacker.Agent.a : Cleaned with backup (quarantined).
C:\Documents and Settings\Kaucher.MY-F78BF48CE2\Local Settings\Temporary Internet Files\Content.IE5\W9E7KDU3\popup[25].htm -> Hijacker.Agent.a : Cleaned with backup (quarantined).
C:\Documents and Settings\Kaucher.MY-F78BF48CE2\Local Settings\Temporary Internet Files\Content.IE5\W9E7KDU3\popup[26].htm -> Hijacker.Agent.a : Cleaned with backup (quarantined).
C:\Documents and Settings\Kaucher.MY-F78BF48CE2\Local Settings\Temporary Internet Files\Content.IE5\W9E7KDU3\popup[27].htm -> Hijacker.Agent.a : Cleaned with backup (quarantined).
C:\Documents and Settings\Kaucher.MY-F78BF48CE2\Local Settings\Temporary Internet Files\Content.IE5\W9E7KDU3\popup[28].htm -> Hijacker.Agent.a : Cleaned with backup (quarantined).
C:\Documents and Settings\Kaucher.MY-F78BF48CE2\Local Settings\Temporary Internet Files\Content.IE5\W9E7KDU3\popup[29].htm -> Hijacker.Agent.a : Cleaned with backup (quarantined).
C:\Documents and Settings\Kaucher.MY-F78BF48CE2\Local Settings\Temporary Internet Files\Content.IE5\W9E7KDU3\popup[2].htm -> Hijacker.Agent.a : Cleaned with backup (quarantined).
C:\Documents and Settings\Kaucher.MY-F78BF48CE2\Local Settings\Temporary Internet Files\Content.IE5\W9E7KDU3\popup[30].htm -> Hijacker.Agent.a : Cleaned with backup (quarantined).
C:\Documents and Settings\Kaucher.MY-F78BF48CE2\Local Settings\Temporary Internet Files\Content.IE5\W9E7KDU3\popup[31].htm -> Hijacker.Agent.a : Cleaned with backup (quarantined).
C:\Documents and Settings\Kaucher.MY-F78BF48CE2\Local Settings\Temporary Internet Files\Content.IE5\W9E7KDU3\popup[32].htm -> Hijacker.Agent.a : Cleaned with backup (quarantined).
C:\Documents and Settings\Kaucher.MY-F78BF48CE2\Local Settings\Temporary Internet Files\Content.IE5\W9E7KDU3\popup[33].htm -> Hijacker.Agent.a : Cleaned with backup (quarantined).
C:\Documents and Settings\Kaucher.MY-F78BF48CE2\Local Settings\Temporary Internet Files\Content.IE5\W9E7KDU3\popup[34].htm -> Hijacker.Agent.a : Cleaned with backup (quarantined).
C:\Documents and Settings\Kaucher.MY-F78BF48CE2\Local Settings\Temporary Internet Files\Content.IE5\W9E7KDU3\popup[35].htm -> Hijacker.Agent.a : Cleaned with backup (quarantined).
C:\Documents and Settings\Kaucher.MY-F78BF48CE2\Local Settings\Temporary Internet Files\Content.IE5\W9E7KDU3\popup[36].htm -> Hijacker.Agent.a : Cleaned with backup (quarantined).
C:\Documents and Settings\Kaucher.MY-F78BF48CE2\Local Settings\Temporary Internet Files\Content.IE5\W9E7KDU3\popup[37].htm -> Hijacker.Agent.a : Cleaned with backup (quarantined).
C:\Documents and Settings\Kaucher.MY-F78BF48CE2\Local Settings\Temporary Internet Files\Content.IE5\W9E7KDU3\popup[38].htm -> Hijacker.Agent.a : Cleaned with backup (quarantined).
C:\Documents and Settings\Kaucher.MY-F78BF48CE2\Local Settings\Temporary Internet Files\Content.IE5\W9E7KDU3\popup[39].htm -> Hijacker.Agent.a : Cleaned with backup (quarantined).
C:\Documents and Settings\Kaucher.MY-F78BF48CE2\Local Settings\Temporary Internet Files\Content.IE5\W9E7KDU3\popup[3].htm -> Hijacker.Agent.a : Cleaned with backup (quarantined).
C:\Documents and Settings\Kaucher.MY-F78BF48CE2\Local Settings\Temporary Internet Files\Content.IE5\W9E7KDU3\popup[40].htm -> Hijacker.Agent.a : Cleaned with backup (quarantined).
C:\Documents and Settings\Kaucher.MY-F78BF48CE2\Local Settings\Temporary Internet Files\Content.IE5\W9E7KDU3\popup[4].htm -> Hijacker.Agent.a : Cleaned with backup (quarantined).
C:\Documents and Settings\Kaucher.MY-F78BF48CE2\Local Settings\Temporary Internet Files\Content.IE5\W9E7KDU3\popup[5].htm -> Hijacker.Agent.a : Cleaned with backup (quarantined).
C:\Documents and Settings\Kaucher.MY-F78BF48CE2\Local Settings\Temporary Internet Files\Content.IE5\W9E7KDU3\popup[6].htm -> Hijacker.Agent.a : Cleaned with backup (quarantined).
C:\Documents and Settings\Kaucher.MY-F78BF48CE2\Local Settings\Temporary Internet Files\Content.IE5\W9E7KDU3\popup[7].htm -> Hijacker.Agent.a : Cleaned with backup (quarantined).
C:\Documents and Settings\Kaucher.MY-F78BF48CE2\Local Settings\Temporary Internet Files\Content.IE5\W9E7KDU3\popup[8].htm -> Hijacker.Agent.a : Cleaned with backup (quarantined).
C:\Documents and Settings\Kaucher.MY-F78BF48CE2\Local Settings\Temporary Internet Files\Content.IE5\W9E7KDU3\popup[9].htm -> Hijacker.Agent.a : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0004251.exe -> Hijacker.Small : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0004248.exe -> Hijacker.VB.ij : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0004249.exe -> Hijacker.VB.ij : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0004213.exe -> Hijacker.VB.ly : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP17\A0014520.exe -> Not-A-Virus.Hoax.Win32.Renos.eo : Cleaned with backup (quarantined).
:mozilla.103:C:\Documents and Settings\Kaucher.MY-F78BF48CE2\Application Data\Mozilla\Firefox\Profiles\teoqfp38.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.110:C:\Documents and Settings\Kaucher.MY-F78BF48CE2\Application Data\Mozilla\Firefox\Profiles\teoqfp38.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.123:C:\Documents and Settings\HP_Owner\Application Data\Mozilla\Firefox\Profiles\asb9a5b8.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.199:C:\Documents and Settings\Kaucher.MY-F78BF48CE2\Application Data\Mozilla\Firefox\Profiles\teoqfp38.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.287:C:\Documents and Settings\Kaucher.MY-F78BF48CE2\Application Data\Mozilla\Firefox\Profiles\teoqfp38.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
C:\Documents and Settings\Kaucher.MY-F78BF48CE2\Cookies\kaucher@2o7[2].txt -> TrackingCookie.2o7 : Cleaned.
C:\Documents and Settings\Kaucher.MY-F78BF48CE2\Cookies\kaucher@msnportal.112.2o7[1].txt -> TrackingCookie.2o7 : Cleaned.
C:\Documents and Settings\Kaucher.MY-F78BF48CE2\Cookies\kaucher@partygaming.122.2o7[1].txt -> TrackingCookie.2o7 : Cleaned.
C:\Documents and Settings\Kaucher.MY-F78BF48CE2\Cookies\kaucher@tcompany.122.2o7[1].txt -> TrackingCookie.2o7 : Cleaned.
C:\Documents and Settings\Kaucher.MY-F78BF48CE2\Cookies\kaucher@viamtvcom.112.2o7[2].txt -> TrackingCookie.2o7 : Cleaned.
C:\Documents and Settings\Kaucher\Cookies\kaucher@msnportal.112.2o7[1].txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.29:C:\Documents and Settings\HP_Owner\Application Data\Mozilla\Firefox\Profiles\asb9a5b8.default\cookies.txt -> TrackingCookie.Adbrite : Cleaned.
:mozilla.30:C:\Documents and Settings\HP_Owner\Application Data\Mozilla\Firefox\Profiles\asb9a5b8.default\cookies.txt -> TrackingCookie.Adbrite : Cleaned.
:mozilla.31:C:\Documents and Settings\HP_Owner\Application Data\Mozilla\Firefox\Profiles\asb9a5b8.default\cookies.txt -> TrackingCookie.Adbrite : Cleaned.
:mozilla.112:C:\Documents and Settings\Kaucher.MY-F78BF48CE2\Application Data\Mozilla\Firefox\Profiles\teoqfp38.default\cookies.txt -> TrackingCookie.Adjuggler : Cleaned.
:mozilla.113:C:\Documents and Settings\Kaucher.MY-F78BF48CE2\Application Data\Mozilla\Firefox\Profiles\teoqfp38.default\cookies.txt -> TrackingCookie.Adjuggler : Cleaned.
C:\Documents and Settings\Kaucher.MY-F78BF48CE2\Cookies\kaucher@rotator.adjuggler[1].txt -> TrackingCookie.Adjuggler : Cleaned.
C:\Documents and Settings\Kaucher.MY-F78BF48CE2\Cookies\kaucher@advertising[2].txt -> TrackingCookie.Advertising : Cleaned.
:mozilla.25:C:\Documents and Settings\Kaucher.MY-F78BF48CE2\Application Data\Mozilla\Firefox\Profiles\teoqfp38.default\cookies.txt -> TrackingCookie.Atdmt : Cleaned.
C:\Documents and Settings\HP_Owner\Cookies\hp_owner@atdmt[2].txt -> TrackingCookie.Atdmt : Cleaned.
C:\Documents and Settings\Kaucher.MY-F78BF48CE2\Cookies\kaucher@atdmt[2].txt -> TrackingCookie.Atdmt : Cleaned.
:mozilla.124:C:\Documents and Settings\Kaucher.MY-F78BF48CE2\Application Data\Mozilla\Firefox\Profiles\teoqfp38.default\cookies.txt -> TrackingCookie.Burstbeacon : Cleaned.
C:\Documents and Settings\Kaucher.MY-F78BF48CE2\Cookies\kaucher@www.burstbeacon[1].txt -> TrackingCookie.Burstbeacon : Cleaned.
:mozilla.37:C:\Documents and Settings\HP_Owner\Application Data\Mozilla\Firefox\Profiles\asb9a5b8.default\cookies.txt -> TrackingCookie.Burstnet : Cleaned.
C:\Documents and Settings\Kaucher.MY-F78BF48CE2\Cookies\kaucher@www.burstnet[2].txt -> TrackingCookie.Burstnet : Cleaned.
:mozilla.40:C:\Documents and Settings\HP_Owner\Application Data\Mozilla\Firefox\Profiles\asb9a5b8.default\cookies.txt -> TrackingCookie.Casalemedia : Cleaned.
:mozilla.41:C:\Documents and Settings\HP_Owner\Application Data\Mozilla\Firefox\Profiles\asb9a5b8.default\cookies.txt -> TrackingCookie.Casalemedia : Cleaned.
:mozilla.42:C:\Documents and Settings\HP_Owner\Application Data\Mozilla\Firefox\Profiles\asb9a5b8.default\cookies.txt -> TrackingCookie.Casalemedia : Cleaned.
:mozilla.32:C:\Documents and Settings\HP_Owner\Application Data\Mozilla\Firefox\Profiles\asb9a5b8.default\cookies.txt -> TrackingCookie.Com : Cleaned.
C:\Documents and Settings\Kaucher.MY-F78BF48CE2\Cookies\kaucher@cpvfeed[1].txt -> TrackingCookie.Cpvfeed : Cleaned.
C:\Documents and Settings\HP_Owner\Cookies\hp_owner@doubleclick[1].txt -> TrackingCookie.Doubleclick : Cleaned.
C:\Documents and Settings\Kaucher.MY-F78BF48CE2\Cookies\kaucher@doubleclick[1].txt -> TrackingCookie.Doubleclick : Cleaned.
:mozilla.153:C:\Documents and Settings\Kaucher.MY-F78BF48CE2\Application Data\Mozilla\Firefox\Profiles\teoqfp38.default\cookies.txt -> TrackingCookie.Hitbox : Cleaned.
:mozilla.154:C:\Documents and Settings\Kaucher.MY-F78BF48CE2\Application Data\Mozilla\Firefox\Profiles\teoqfp38.default\cookies.txt -> TrackingCookie.Hitbox : Cleaned.
:mozilla.155:C:\Documents and Settings\Kaucher.MY-F78BF48CE2\Application Data\Mozilla\Firefox\Profiles\teoqfp38.default\cookies.txt -> TrackingCookie.Hitbox : Cleaned.
:mozilla.156:C:\Documents and Settings\Kaucher.MY-F78BF48CE2\Application Data\Mozilla\Firefox\Profiles\teoqfp38.default\cookies.txt -> TrackingCookie.Hitbox : Cleaned.
:mozilla.157:C:\Documents and Settings\Kaucher.MY-F78BF48CE2\Application Data\Mozilla\Firefox\Profiles\teoqfp38.default\cookies.txt -> TrackingCookie.Hitbox : Cleaned.
:mozilla.158:C:\Documents and Settings\Kaucher.MY-F78BF48CE2\Application Data\Mozilla\Firefox\Profiles\teoqfp38.default\cookies.txt -> TrackingCookie.Hitbox : Cleaned.
:mozilla.159:C:\Documents and Settings\Kaucher.MY-F78BF48CE2\Application Data\Mozilla\Firefox\Profiles\teoqfp38.default\cookies.txt -> TrackingCookie.Hitbox : Cleaned.
:mozilla.160:C:\Documents and Settings\Kaucher.MY-F78BF48CE2\Application Data\Mozilla\Firefox\Profiles\teoqfp38.default\cookies.txt -> TrackingCookie.Hitbox : Cleaned.
C:\Documents and Settings\Kaucher.MY-F78BF48CE2\Cookies\kaucher@ehg-dig.hitbox[2].txt -> TrackingCookie.Hitbox : Cleaned.
:mozilla.111:C:\Documents and Settings\Kaucher.MY-F78BF48CE2\Application Data\Mozilla\Firefox\Profiles\teoqfp38.default\cookies.txt -> TrackingCookie.Liveperson : Cleaned.
:mozilla.161:C:\Documents and Settings\Kaucher.MY-F78BF48CE2\Application Data\Mozilla\Firefox\Profiles\teoqfp38.default\cookies.txt -> TrackingCookie.Liveperson : Cleaned.
:mozilla.209:C:\Documents and Settings\Kaucher.MY-F78BF48CE2\Application Data\Mozilla\Firefox\Profiles\teoqfp38.default\cookies.txt -> TrackingCookie.Liveperson : Cleaned.
:mozilla.210:C:\Documents and Settings\Kaucher.MY-F78BF48CE2\Application Data\Mozilla\Firefox\Profiles\teoqfp38.default\cookies.txt -> TrackingCookie.Liveperson : Cleaned.
C:\Documents and Settings\Kaucher.MY-F78BF48CE2\Cookies\kaucher@server.lon.liveperson[1].txt -> TrackingCookie.Liveperson : Cleaned.
:mozilla.142:C:\Documents and Settings\Kaucher.MY-F78BF48CE2\Application Data\Mozilla\Firefox\Profiles\teoqfp38.default\cookies.txt -> TrackingCookie.Masterstats : Cleaned.
C:\Documents and Settings\Kaucher.MY-F78BF48CE2\Cookies\kaucher@image.masterstats[1].txt -> TrackingCookie.Masterstats : Cleaned.
C:\Documents and Settings\HP_Owner\Cookies\hp_owner@mediaplex[1].txt -> TrackingCookie.Mediaplex : Cleaned.
C:\Documents and Settings\Kaucher.MY-F78BF48CE2\Cookies\kaucher@www.myaffiliateprogram[1].txt -> TrackingCookie.Myaffiliateprogram : Cleaned.
C:\Documents and Settings\HP_Owner\Cookies\hp_owner@perf.overture[1].txt -> TrackingCookie.Overture : Cleaned.
C:\Documents and Settings\Kaucher.MY-F78BF48CE2\Cookies\kaucher@ads.pointroll[2].txt -> TrackingCookie.Pointroll : Cleaned.
:mozilla.124:C:\Documents and Settings\HP_Owner\Application Data\Mozilla\Firefox\Profiles\asb9a5b8.default\cookies.txt -> TrackingCookie.Questionmarket : Cleaned.
:mozilla.125:C:\Documents and Settings\HP_Owner\Application Data\Mozilla\Firefox\Profiles\asb9a5b8.default\cookies.txt -> TrackingCookie.Questionmarket : Cleaned.
C:\Documents and Settings\Kaucher.MY-F78BF48CE2\Cookies\kaucher@stats1.reliablestats[1].txt -> TrackingCookie.Reliablestats : Cleaned.
:mozilla.136:C:\Documents and Settings\HP_Owner\Application Data\Mozilla\Firefox\Profiles\asb9a5b8.default\cookies.txt -> TrackingCookie.Revenue : Cleaned.
:mozilla.137:C:\Documents and Settings\HP_Owner\Application Data\Mozilla\Firefox\Profiles\asb9a5b8.default\cookies.txt -> TrackingCookie.Revenue : Cleaned.
C:\Documents and Settings\Kaucher.MY-F78BF48CE2\Cookies\kaucher@edge.ru4[1].txt -> TrackingCookie.Ru4 : Cleaned.
:mozilla.78:C:\Documents and Settings\HP_Owner\Application Data\Mozilla\Firefox\Profiles\asb9a5b8.default\cookies.txt -> TrackingCookie.Sexcounter : Cleaned.
:mozilla.79:C:\Documents and Settings\HP_Owner\Application Data\Mozilla\Firefox\Profiles\asb9a5b8.default\cookies.txt -> TrackingCookie.Sexcounter : Cleaned.
:mozilla.197:C:\Documents and Settings\Kaucher.MY-F78BF48CE2\Application Data\Mozilla\Firefox\Profiles\teoqfp38.default\cookies.txt -> TrackingCookie.Specificclick : Cleaned.
:mozilla.198:C:\Documents and Settings\Kaucher.MY-F78BF48CE2\Application Data\Mozilla\Firefox\Profiles\teoqfp38.default\cookies.txt -> TrackingCookie.Specificclick : Cleaned.
C:\Documents and Settings\Kaucher.MY-F78BF48CE2\Cookies\kaucher@adopt.specificclick[2].txt -> TrackingCookie.Specificclick : Cleaned.
:mozilla.227:C:\Documents and Settings\Kaucher.MY-F78BF48CE2\Application Data\Mozilla\Firefox\Profiles\teoqfp38.default\cookies.txt -> TrackingCookie.Starware : Cleaned.
:mozilla.228:C:\Documents and Settings\Kaucher.MY-F78BF48CE2\Application Data\Mozilla\Firefox\Profiles\teoqfp38.default\cookies.txt -> TrackingCookie.Starware : Cleaned.
:mozilla.50:C:\Documents and Settings\Kaucher.MY-F78BF48CE2\Application Data\Mozilla\Firefox\Profiles\teoqfp38.default\cookies.txt -> TrackingCookie.Starware : Cleaned.
C:\Documents and Settings\Kaucher.MY-F78BF48CE2\Cookies\kaucher@h.starware[2].txt -> TrackingCookie.Starware : Cleaned.
C:\Documents and Settings\Kaucher.MY-F78BF48CE2\Cookies\kaucher@try.starware[1].txt -> TrackingCookie.Starware : Cleaned.
C:\Documents and Settings\Kaucher\Cookies\kaucher@anad.tacoda[1].txt -> TrackingCookie.Tacoda : Cleaned.
:mozilla.136:C:\Documents and Settings\Kaucher.MY-F78BF48CE2\Application Data\Mozilla\Firefox\Profiles\teoqfp38.default\cookies.txt -> TrackingCookie.Web-stat : Cleaned.
:mozilla.137:C:\Documents and Settings\Kaucher.MY-F78BF48CE2\Application Data\Mozilla\Firefox\Profiles\teoqfp38.default\cookies.txt -> TrackingCookie.Web-stat : Cleaned.
:mozilla.26:C:\Documents and Settings\Kaucher.MY-F78BF48CE2\Application Data\Mozilla\Firefox\Profiles\teoqfp38.default\cookies.txt -> TrackingCookie.Web-stat : Cleaned.
C:\Documents and Settings\Kaucher.MY-F78BF48CE2\Cookies\kaucher@webstat[1].txt -> TrackingCookie.Web-stat : Cleaned.
:mozilla.106:C:\Documents and Settings\HP_Owner\Application Data\Mozilla\Firefox\Profiles\asb9a5b8.default\cookies.txt -> TrackingCookie.Yadro : Cleaned.
:mozilla.107:C:\Documents and Settings\HP_Owner\Application Data\Mozilla\Firefox\Profiles\asb9a5b8.default\cookies.txt -> TrackingCookie.Yadro : Cleaned.
:mozilla.25:C:\Documents and Settings\HP_Owner\Application Data\Mozilla\Firefox\Profiles\asb9a5b8.default\cookies.txt -> TrackingCookie.Yieldmanager : Cleaned.
:mozilla.26:C:\Documents and Settings\HP_Owner\Application Data\Mozilla\Firefox\Profiles\asb9a5b8.default\cookies.txt -> TrackingCookie.Yieldmanager : Cleaned.
:mozilla.27:C:\Documents and Settings\HP_Owner\Application Data\Mozilla\Firefox\Profiles\asb9a5b8.default\cookies.txt -> TrackingCookie.Yieldmanager : Cleaned.
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0004301.exe -> Trojan.Qoologic : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0004259.exe -> Trojan.VB.tg : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0004299.exe -> Trojan.VB.tg : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0004300.exe -> Trojan.VB.tg : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP9\A0002784.exe -> Worm.VB.dw : Cleaned with backup (quarantined).


::Report end
Clamp1
Newbie
_
21. October 2006 @ 14:48 _ Link to this message    Send private message to this user   

This message has been edited since posting. Last time this message was edited on 22. October 2006 @ 09:11

Senior Member
_
21. October 2006 @ 17:08 _ Link to this message    Send private message to this user   
I seen the AVGAS report. Please edit those two posts, it makes the thread long and hard to navigate for no reason.

I posted the next instructions earlier. Please follow them to get rid of Qoologic.

Here's a quick link to find them.
http://forums.afterdawn.com/thread_jump.cfm/408854/2476210

Clamp1
Newbie
_
22. October 2006 @ 08:57 _ Link to this message    Send private message to this user   
Niobis I cant get qoofix.bat I dont know why. I try to get it but the website says HTTP 404 Not Found.

This message has been edited since posting. Last time this message was edited on 22. October 2006 @ 09:14

Clamp1
Newbie
_
22. October 2006 @ 10:29 _ Link to this message    Send private message to this user   
I cant find qoofix.bat anywhere. Can you tell me where it is.

This message has been edited since posting. Last time this message was edited on 22. October 2006 @ 10:51

Senior Member
_
22. October 2006 @ 12:36 _ Link to this message    Send private message to this user   
Sorry about that, that fix is outdated. You may delete/uninstall BFU.

Here's the new fix for Qoo.

Please download Qoofix by RubbeR DuckY from one of the following locations:

http://www.malwarebytes.org/Qoofix.zip or
http://www.besttechie.net/tools/Qoofix.zip

* Unzip all files to a convenient location such as C:\Qoofix.
* Go to the folder you unzipped all files and run Qoofix.exe.
* Click Begin Removal and wait for the scan to finish.
* If an infection has been found, select Yes to restart your computer.

Post back with the Qoofix log and a new HijackThis log.

This message has been edited since posting. Last time this message was edited on 22. October 2006 @ 12:38

Clamp1
Newbie
_
23. October 2006 @ 09:58 _ Link to this message    Send private message to this user   
Here is the Qoolfix log.

Qoofix v1.03 by http://www.malwarebytes.org
Scan started on [10/23/2006] at [1:48:52 PM]
-------------------------------------------------------------
No malicious modules found!
-------------------------------------------------------------
No Qoologic infected files found!
-------------------------------------------------------------
Scan COMPLETED SUCCESSFULLY on [10/23/2006] at [1:50:34 PM]

Note: Some registry keys may have been removed.
Clamp1
Newbie
_
23. October 2006 @ 10:01 _ Link to this message    Send private message to this user   
Here is the HijackThis log.

Logfile of HijackThis v1.99.1
Scan saved at 1:59:05 PM, on 10/23/2006
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\hkcmd.exe
C:\Program Files\Hewlett-Packard\HP Boot Optimizer\HPBootOp.exe
C:\Program Files\Lexmark 2300 Series\ezprint.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\Program Files\QuickTime\qttask.exe
C:\Program Files\Java\jre1.5.0_06\bin\jusched.exe
C:\Program Files\Webroot\Spy Sweeper\SpySweeperUI.exe
C:\Program Files\CA\eTrust EZ Armor\eTrust Anti-Spam\QSP-2.1.215.5\QOELoader.exe
C:\Program Files\CA\eTrust EZ Armor\eTrust EZ Antivirus\CAVTray.exe
C:\Program Files\CA\eTrust EZ Armor\eTrust EZ Antivirus\CAVRID.exe
C:\Program Files\CA\eTrust EZ Armor\eTrust EZ Firewall\ca.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Messenger\msmsgs.exe
C:\Program Files\America Online 9.0d\aoltray.exe
C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
C:\Program Files\Updates from HP\309731\Program\Updates from HP.exe
C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe
C:\Program Files\Sony\Sony Picture Utility\VolumeWatcher\SPUVolumeWatcher.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
C:\Program Files\CA\eTrust EZ Armor\eTrust EZ Antivirus\ISafe.exe
c:\Program Files\Common Files\LightScribe\LSSrvc.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\WINDOWS\system32\HPZipm12.exe
C:\WINDOWS\system32\tcpsvcs.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\CA\eTrust EZ Armor\eTrust EZ Antivirus\VetMsg.exe
C:\WINDOWS\system32\ZoneLabs\vsmon.exe
C:\Program Files\Webroot\Spy Sweeper\SpySweeper.exe
c:\Program Files\Common Files\Symantec Shared\Security Center\SymWSC.exe
C:\WINDOWS\system32\wuauclt.exe
C:\WINDOWS\system32\lxcgcoms.exe
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\PROGRA~1\Yahoo!\COMPAN~1\Installs\cpn1\YTBSDK.exe
C:\Program Files\Google\GoogleToolbarNotifier\1.2.908.5008\GoogleToolbarNotifier.exe
C:\Documents and Settings\HP_Owner\Desktop\HijackThis_v1.99.1.exe
C:\Program Files\Symantec\LiveUpdate\AUpdate.exe

R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://ie.redirect.hp.com/svs/rdr?TYPE=3...lion&pf=desktop
R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn1\yt.dll
O2 - BHO: Yahoo! Toolbar Helper - {02478D38-C3F9-4EFB-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn1\yt.dll
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar5.dll
O3 - Toolbar: HP view - {B2847E28-5D7D-4DEB-8B67-05D28BCF79F5} - c:\Program Files\HP\Digital Imaging\bin\HPDTLK02.dll
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn1\yt.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar5.dll
O4 - HKLM\..\Run: [High Definition Audio Property Page Shortcut] HDAudPropShortcut.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\system32\hkcmd.exe
O4 - HKLM\..\Run: [HPBootOp] "C:\Program Files\Hewlett-Packard\HP Boot Optimizer\HPBootOp.exe" /run
O4 - HKLM\..\Run: [_SetRes] c:\hp\bin\cloaker c:\hp\bin\res.bat
O4 - HKLM\..\Run: [IcoSet] "c:\hp\bin\cloaker.exe" c:\hp\bin\IcoSet\adjust.bat seticon
O4 - HKLM\..\Run: [LSBWatcher] c:\hp\drivers\hplsbwatcher\lsburnwatcher.exe
O4 - HKLM\..\Run: [lxcgmon.exe] "C:\Program Files\Lexmark 2300 Series\lxcgmon.exe"
O4 - HKLM\..\Run: [EzPrint] "C:\Program Files\Lexmark 2300 Series\ezprint.exe"
O4 - HKLM\..\Run: [FaxCenterServer] "C:\Program Files\Lexmark Fax Solutions\fm3032.exe" /s
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.5.0_06\bin\jusched.exe"
O4 - HKLM\..\Run: [LXCGCATS] rundll32 C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\LXCGtime.dll,_RunDLLEntry@16
O4 - HKLM\..\Run: [SpySweeper] "C:\Program Files\Webroot\Spy Sweeper\SpySweeperUI.exe" /startintray
O4 - HKLM\..\Run: [QOELOADER] "C:\Program Files\CA\eTrust EZ Armor\eTrust Anti-Spam\QSP-2.1.215.5\QOELoader.exe"
O4 - HKLM\..\Run: [CaAvTray] "C:\Program Files\CA\eTrust EZ Armor\eTrust EZ Antivirus\CAVTray.exe"
O4 - HKLM\..\Run: [CAVRID] "C:\Program Files\CA\eTrust EZ Armor\eTrust EZ Antivirus\CAVRID.exe"
O4 - HKLM\..\Run: [Zone Labs Client] "C:\Program Files\CA\eTrust EZ Armor\eTrust EZ Firewall\ca.exe"
O4 - HKLM\..\Run: [!AVG Anti-Spyware] "C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" /minimized
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [swg] "C:\Program Files\Google\GoogleToolbarNotifier\1.0.720.3640\GoogleToolbarNotifier.exe"
O4 - Startup: Cyber-shot Viewer Media Check Tool.lnk = C:\Program Files\Sony\Sony Picture Utility\VolumeWatcher\SPUVolumeWatcher.exe
O4 - Startup: HP Organize.lnk = ?
O4 - Global Startup: America Online 9.0 Tray Icon.lnk = C:\Program Files\America Online 9.0d\aoltray.exe
O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
O4 - Global Startup: SpySubtract.lnk = C:\Program Files\InterMute\SpySubtract\sslaunch.exe
O4 - Global Startup: Updates from HP.lnk = C:\Program Files\Updates from HP\309731\Program\Updates from HP.exe
O8 - Extra context menu item: &Search - http://kl.bar.need2find.com/KL/menusearch.html?p=KL
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MI1933~1\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MI1933~1\OFFICE11\REFIEBAR.DLL
O9 - Extra button: Connection Help - {E2D4D26B-0180-43a4-B05F-462D6D54C789} - C:\WINDOWS\PCHEALTH\HELPCTR\Vendors\CN=Hewlett-Packard,L=Cupertino,S=Ca,C=US\IEButton\support.htm
O9 - Extra 'Tools' menuitem: Connection Help - {E2D4D26B-0180-43a4-B05F-462D6D54C789} - C:\WINDOWS\PCHEALTH\HELPCTR\Vendors\CN=Hewlett-Packard,L=Cupertino,S=Ca,C=US\IEButton\support.htm
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra button: Connection Help - {E2D4D26B-0180-43a4-B05F-462D6D54C789} - C:\WINDOWS\PCHEALTH\HELPCTR\Vendors\CN=Hewlett-Packard,L=Cupertino,S=Ca,C=US\IEButton\support.htm (HKCU)
O9 - Extra 'Tools' menuitem: Connection Help - {E2D4D26B-0180-43a4-B05F-462D6D54C789} - C:\WINDOWS\PCHEALTH\HELPCTR\Vendors\CN=Hewlett-Packard,L=Cupertino,S=Ca,C=US\IEButton\support.htm (HKCU)
O15 - Trusted Zone: ww.rr.com
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?LinkID=39204
O20 - Winlogon Notify: igfxcui - C:\WINDOWS\SYSTEM32\igfxsrvc.dll
O20 - Winlogon Notify: WRNotifier - C:\WINDOWS\SYSTEM32\WRLogonNTF.dll
O20 - Winlogon Notify: yvbb01 - yvbb01.dll (file missing)
O21 - SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll
O23 - Service: Automatic LiveUpdate Scheduler - Symantec Corporation - C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe
O23 - Service: AVG Anti-Spyware Guard - Anti-Malware Development a.s. - C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
O23 - Service: CAISafe - Computer Associates International, Inc. - C:\Program Files\CA\eTrust EZ Armor\eTrust EZ Antivirus\ISafe.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe
O23 - Service: iPod Service (iPodService) - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - c:\Program Files\Common Files\LightScribe\LSSrvc.exe
O23 - Service: LiveUpdate - Symantec Corporation - C:\PROGRA~1\Symantec\LIVEUP~1\LUCOMS~1.EXE
O23 - Service: lxcg_device - - C:\WINDOWS\system32\lxcgcoms.exe
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe
O23 - Service: SymWMI Service (SymWSC) - Symantec Corporation - c:\Program Files\Common Files\Symantec Shared\Security Center\SymWSC.exe
O23 - Service: VET Message Service (VETMSGNT) - Computer Associates International, Inc. - C:\Program Files\CA\eTrust EZ Armor\eTrust EZ Antivirus\VetMsg.exe
O23 - Service: TrueVector Internet Monitor (vsmon) - Zone Labs Inc. - C:\WINDOWS\system32\ZoneLabs\vsmon.exe
O23 - Service: Webroot Spy Sweeper Engine (WebrootSpySweeperService) - Webroot Software, Inc. - C:\Program Files\Webroot\Spy Sweeper\SpySweeper.exe
Senior Member
_
23. October 2006 @ 14:10 _ Link to this message    Send private message to this user   
No Qoo files found, but it's not in the log anymore. :)

Turn off the real-time protection of AVGAS since you already had SpySweeper. Or you may uninstall it.

Turn off SpySweepers Shields becasue it may interfere with these fixes.
Open SpySweeper.
Click Shield Settings on the right
(or Shields on the left, depending what screen you're on).
Click Internet Explorer and uncheck all items.
Click Windows System and uncheck all items.
Click Hosts File and uncheck all items.
Click Startup Programs and uncheck all items.
Close SpySweeper.

Run a scan only with HijackThis, check these:

R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://ie.redirect.hp.com/svs/rdr?TYPE=3...lion&pf=desktop
O8 - Extra context menu item: &Search - http://kl.bar.need2find.com/KL/menusearch.html?p=KL
O15 - Trusted Zone: ww.rr.com
O20 - Winlogon Notify: yvbb01 - yvbb01.dll (file missing)


Close all windows except HijackThis, then click "Fix checked".
Close HijackThis.

Turn off System Restore.
Right click My Computer > Properties > System Restore tab > check "Turn off System Restore".

Go here and run Kaspersky Online Scanner.
Accept the terms.
After downloading, click "My Computer".
After scanning, click "Save report as".
Save as a text file and post it here along with a new HijackThis log.


Clamp1
Newbie
_
24. October 2006 @ 17:11 _ Link to this message    Send private message to this user   
Here is the Kaspersky Report.


-------------------------------------------------------------------------------
KASPERSKY ONLINE SCANNER REPORT
Tuesday, October 24, 2006 9:09:57 PM
Operating System: Microsoft Windows XP Home Edition, Service Pack 2 (Build 2600)
Kaspersky Online Scanner version: 5.0.83.0
Kaspersky Anti-Virus database last update: 25/10/2006
Kaspersky Anti-Virus database records: 221217
-------------------------------------------------------------------------------

Scan Settings:
Scan using the following antivirus database: standard
Scan Archives: true
Scan Mail Bases: true

Scan Target - My Computer:
C:\
D:\
E:\
F:\
G:\
H:\
I:\

Scan Statistics:
Total number of scanned objects: 105388
Number of viruses found: 1
Number of infected objects: 1 / 0
Number of suspicious objects: 0
Duration of the scan process: 01:34:09

Infected Object Name / Virus Name / Last Action
C:\23100247.exe Infected: Trojan-Downloader.Win32.Small.dwn skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\19e26cec064e9195496f0b92ff8bcf4b_a428afe7-50b8-4162-b914-dcf91c784d8a Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\511a0f3f9e960fa97de3d0b74adfc574_a428afe7-50b8-4162-b914-dcf91c784d8a Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\54452f224c92ccdf01d600d04864a4dc_a428afe7-50b8-4162-b914-dcf91c784d8a Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Dr Watson\user.dmp Object is locked skipped
C:\Documents and Settings\All Users\Application Data\muvee Technologies\030625\scratch\ERRSTAT.HTM Object is locked skipped
C:\Documents and Settings\All Users\Application Data\muvee Technologies\030625\scratch\Sample_Picture03.jpg.41b2b144.180.mtn Object is locked skipped
C:\Documents and Settings\All Users\Application Data\muvee Technologies\030625\scratch\Sample_Picture03.jpg.41b2b144.270.mtn Object is locked skipped
C:\Documents and Settings\All Users\Application Data\muvee Technologies\030625\scratch\Sample_Picture03.jpg.41b2b144.90.mtn Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Symantec\LiveUpdate\2006-10-24_Log.ALUSchedulerSvc.LiveUpdate Object is locked skipped
C:\Documents and Settings\HP_Owner\Application Data\Webroot\Spy Sweeper\Logs\061002020006.ses Object is locked skipped
C:\Documents and Settings\HP_Owner\Cookies\index.dat Object is locked skipped
C:\Documents and Settings\HP_Owner\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat Object is locked skipped
C:\Documents and Settings\HP_Owner\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped
C:\Documents and Settings\HP_Owner\Local Settings\History\History.IE5\index.dat Object is locked skipped
C:\Documents and Settings\HP_Owner\Local Settings\History\History.IE5\MSHist012006102420061025\index.dat Object is locked skipped
C:\Documents and Settings\HP_Owner\Local Settings\Temp\hpodvd09.log Object is locked skipped
C:\Documents and Settings\HP_Owner\Local Settings\Temporary Internet Files\Content.IE5\index.dat Object is locked skipped
C:\Documents and Settings\HP_Owner\NTUSER.DAT Object is locked skipped
C:\Documents and Settings\HP_Owner\ntuser.dat.LOG Object is locked skipped
C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Data\settings.dat Object is locked skipped
C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSCS058FD4A4-A4AE-4BC4-AD38-F02AD75E60C3.tmp Object is locked skipped
C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSCS06CCEDB2-1EEA-4A91-9081-87A5F1CB82EC.tmp Object is locked skipped
C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSCS0825A652-5A62-4080-AF5E-EB18E3735B33.tmp Object is locked skipped
C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSCS091BE407-C8B7-4D2D-9450-EFE19A6D0266.tmp Object is locked skipped
C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSCS0A834399-A7A5-4031-9F98-0F6D6092EF9B.tmp Object is locked skipped
C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSCS0BC89914-4586-452B-9BD9-E534FF115DD6.tmp Object is locked skipped
C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSCS0C7B999C-27B9-4048-9C80-7162D8F3C943.tmp Object is locked skipped
C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSCS0D2B9A24-1C0F-467D-897E-354AAF1E3222.tmp Object is locked skipped
C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSCS10A2E07E-D3EE-428D-A8AF-6FCE9FD017FA.tmp Object is locked skipped
C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSCS13DB7599-D733-4C36-B5C5-ABB6D501CC1F.tmp Object is locked skipped
C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSCS1418C20B-3803-4572-9B4D-4C43CB4B9166.tmp Object is locked skipped
C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSCS1439DE42-F404-43B9-84ED-C5B1B039B49C.tmp Object is locked skipped
C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSCS15275E55-575B-4A48-A008-29BA897A1690.tmp Object is locked skipped
C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSCS16FB6637-9464-42B7-AC03-48F42E61F784.tmp Object is locked skipped
C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSCS1D5AEE7D-7CB0-4FD8-90AE-BC5D97032E97.tmp Object is locked skipped
C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSCS1F4BD168-9A6D-4A03-B905-965CFA890E8E.tmp Object is locked skipped
C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSCS20EC39FB-02CE-4C76-8E5C-F8F7C1728DD2.tmp Object is locked skipped
C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSCS2197C2E3-6B4C-47B1-B922-017270F51A41.tmp Object is locked skipped
C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSCS281274CB-424A-4B78-87F5-23A6D8918CD7.tmp Object is locked skipped
C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSCS2B0C0419-8D66-4FF2-A459-09678197C3F0.tmp Object is locked skipped
C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSCS3D069ADD-05BB-4CA7-BB96-7393F932891D.tmp Object is locked skipped
C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSCS3DF9CDC5-D219-424B-8F18-58638E83DC8C.tmp Object is locked skipped
C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSCS3ECBBCF1-AD2B-455B-BF64-8148E7DE3137.tmp Object is locked skipped
C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSCS4156F605-A0D9-48AC-AC6E-FDF8E090E1CD.tmp Object is locked skipped
C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSCS43A5B36A-0561-4769-AFF2-C97887A7E783.tmp Object is locked skipped
C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSCS4D105F8F-B9D9-4A87-AA28-B068F433796B.tmp Object is locked skipped
C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSCS4ECF14FB-AF7B-4491-83C7-B7AAB9264C08.tmp Object is locked skipped
C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSCS559154D7-476A-4265-9A13-48684B8DC33F.tmp Object is locked skipped
C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSCS5B7D366C-05AC-41D6-933E-B7706983BD76.tmp Object is locked skipped
C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSCS5C7C2388-2777-49F4-B599-68DA1BFCF1A8.tmp Object is locked skipped
C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSCS5E67CF64-1F0A-4610-969B-CCE51442063B.tmp Object is locked skipped
C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSCS5E6E13B5-0B87-43A8-85CD-5E2EE80B4852.tmp Object is locked skipped
C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSCS639A69D8-3C07-4326-AA71-79FD0D8995B0.tmp Object is locked skipped
C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSCS64E8ED99-AC27-44B6-8DA9-14C8810451AA.tmp Object is locked skipped
C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSCS654F3972-9EDC-4153-93E4-A3E573047C1C.tmp Object is locked skipped
C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSCS67B0214B-7EE7-4108-8CBF-24F1FAAA62F9.tmp Object is locked skipped
C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSCS67D2050B-1F89-4C80-BE00-CC0FB081B75A.tmp Object is locked skipped
C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSCS6AC3F18A-DC63-4A7F-8433-09CB0B1420B1.tmp Object is locked skipped
C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSCS6B21402C-248D-4757-B548-DFC66C2AFBB0.tmp Object is locked skipped
C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSCS6C64710A-2E66-4B42-93A9-735F8A2DD425.tmp Object is locked skipped
C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSCS6D1A22FC-10FF-430B-BE03-477317E43EDA.tmp Object is locked skipped
C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSCS70210296-00D2-40E2-AA7E-9421A570DEDA.tmp Object is locked skipped
C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSCS703062EF-BCAB-4450-ABD3-6C28F1822CC6.tmp Object is locked skipped
C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSCS7185027F-8626-4D02-98C7-4DD1826735A4.tmp Object is locked skipped
C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSCS73416C4A-7CA6-4F65-B1F3-C28C1CC7F3BD.tmp Object is locked skipped
C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSCS74C512BA-3A57-4D7D-92A0-9982E9C6BFF3.tmp Object is locked skipped
C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSCS75CA5AE3-DE0F-4C86-B25D-2ACBF54E779C.tmp Object is locked skipped
C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSCS76C884C8-0679-4A54-B668-85500C6B5FB0.tmp Object is locked skipped
C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSCS7A623A80-6428-4A89-B3B0-F5F5A2361DAE.tmp Object is locked skipped
C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSCS7AB2CC11-62F5-4B49-8230-8E66DE31308A.tmp Object is locked skipped
C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSCS80B4E2B4-21D8-45EE-8F0F-233CC3666DC7.tmp Object is locked skipped
C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSCS841A5B6C-2FB7-44BD-A352-0E7632051460.tmp Object is locked skipped
C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSCS87635EC1-FD84-4F94-A087-687027005A04.tmp Object is locked skipped
C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSCS87EBD65A-3481-40A3-8D4D-568382CE7118.tmp Object is locked skipped
C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSCS8AA86AFB-4AC4-4779-A314-E6F161168C3A.tmp Object is locked skipped
C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSCS8B885318-AE95-4ECD-ADC0-4584CC641CA3.tmp Object is locked skipped
C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSCS8CE83164-9219-4630-90D6-41815157C3F4.tmp Object is locked skipped
C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSCS8D9F04DF-F2A4-4DC8-8BD0-2335C18C8E0E.tmp Object is locked skipped
C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSCS8DF7E4A4-5DDE-4DD6-B414-4FFFDDEB8A7C.tmp Object is locked skipped
C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSCS90C2BDDF-BC0A-4B45-9933-5BF00A97003B.tmp Object is locked skipped
C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSCS9485832A-9B0A-4952-B7E6-3C1C5A1C5C2B.tmp Object is locked skipped
C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSCS96A93C5A-45A2-4B25-9088-50A55674380C.tmp Object is locked skipped
C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSCS9809BC77-DDA8-45E6-8EFB-D4B4AEA7C3EE.tmp Object is locked skipped
C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSCS99BE14DF-7DB9-4662-A413-F3497472A99C.tmp Object is locked skipped
C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSCS9B52C8B7-7867-464E-9948-E4654B320A63.tmp Object is locked skipped
C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSCSA22D2B05-09F9-4ECF-B3D6-6995358A1A2B.tmp Object is locked skipped
C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSCSA2FF050C-A6A8-4840-94E2-96DBC8498A6A.tmp Object is locked skipped
C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSCSA55A0321-7D61-4861-BEF8-E785F2C4CDA1.tmp Object is locked skipped
C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSCSA59BCCA6-FFDE-4DCA-84CF-1B44165056C1.tmp Object is locked skipped
C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSCSA768C2AA-D89F-48D3-9A3C-7BD25F766485.tmp Object is locked skipped
C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSCSB04CAB54-AC02-4F0D-9693-AED2998FB08D.tmp Object is locked skipped
C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSCSB23E622D-D9D7-42E7-9151-F6AF81EA63E6.tmp Object is locked skipped
C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSCSB2E76963-DA8E-4300-A513-482C1E6CBD4A.tmp Object is locked skipped
C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSCSB76A7172-B22C-4B87-82A4-B898A4513C21.tmp Object is locked skipped
C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSCSB9511548-E4FA-45C8-B20E-FC42C9007070.tmp Object is locked skipped
C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSCSBBD6C2BA-0A4D-4D4F-AA14-0ECE04C8381B.tmp Object is locked skipped
C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSCSC0AA76C7-D1BE-433B-9D4F-3D5518CF5251.tmp Object is locked skipped
C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSCSC15DF805-4F0E-4F8B-9D35-63E8BCB5C152.tmp Object is locked skipped
C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSCSC66B8195-6966-43DE-BCA2-439ED3B4795B.tmp Object is locked skipped
C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSCSC7159D08-8194-44AA-BE6B-B87F430C7CAE.tmp Object is locked skipped
C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSCSC8405296-71D8-483F-B50B-5845B7929818.tmp Object is locked skipped
C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSCSCF53D89E-B375-4EA5-87FA-E9C7B1022A06.tmp Object is locked skipped
C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSCSCFCB128C-0A84-454C-A537-3C1C1EF70EE0.tmp Object is locked skipped
C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSCSD26A9076-26F7-4082-9720-02F5EAE91355.tmp Object is locked skipped
C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSCSD3FFEA26-67CF-4414-B8D9-9D09F43488D8.tmp Object is locked skipped
C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSCSD6BEA5EF-FEAA-48E0-BB46-CF565C48C9E9.tmp Object is locked skipped
C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSCSD973EE32-FD6D-405A-B537-BDC867747A73.tmp Object is locked skipped
C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSCSDAADEDF7-19D7-4036-8306-03EC24B1D3DA.tmp Object is locked skipped
C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSCSDED6FECA-0DED-4005-B858-A73A11A0D4B4.tmp Object is locked skipped
C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSCSDEE05992-052C-400C-B5E1-459FAF303BA4.tmp Object is locked skipped
C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSCSDF3EA2EE-6702-4694-99FB-2078F2764566.tmp Object is locked skipped
C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSCSDF97FE2B-0086-4E74-BFCC-7AEFA5DA10BE.tmp Object is locked skipped
C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSCSE0576EC6-2053-42FB-8DDB-B6B4442BD7BF.tmp Object is locked skipped
C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSCSE090AE67-A51E-48FA-B7A7-3254DBF0E891.tmp Object is locked skipped
C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSCSE387899D-06F2-42C0-85EA-D4D74F8631B0.tmp Object is locked skipped
C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSCSE3AD584F-CAC4-4F63-B125-75415F3B67A1.tmp Object is locked skipped
C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSCSE48F34E9-9663-40A9-8527-D0DE2CF5C1ED.tmp Object is locked skipped
C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSCSEABEB553-85B0-4AA2-BF2F-079288F7D64B.tmp Object is locked skipped
C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSCSEC5DBDC3-B804-4241-A32A-426DC7D0DB35.tmp Object is locked skipped
C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSCSEDBAFAD2-BA48-4AE9-8928-3D084F9A24C0.tmp Object is locked skipped
C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSCSEE504813-F47F-4800-AFC1-9BDAFA6FD30E.tmp Object is locked skipped
C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSCSF1598063-E782-4180-99FE-5CAC08CD7DAA.tmp Object is locked skipped
C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSCSF4695070-CA82-4D93-96D4-29BE05FCA1E7.tmp Object is locked skipped
C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSCSF8797811-CD56-424C-B534-3E64E495B7BF.tmp Object is locked skipped
C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSCSF986DF4B-1CA1-417B-8C2E-670BCE22C2D4.tmp Object is locked skipped
C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSCSF9E58E74-4BE7-45AC-A0AE-FE044B08DF6B.tmp Object is locked skipped
C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSCSFB250F1A-C4CA-4C53-B288-FC11F9606C64.tmp Object is locked skipped
C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSCSFE2F9036-1DB0-4599-9BFE-B2E416BE894F.tmp Object is locked skipped
C:\Documents and Settings\LocalService\Application Data\Webroot\Spy Sweeper\Temp\SSCSFF79A2FB-836E-48BF-97F8-247D20C465D1.tmp Object is locked skipped
C:\Documents and Settings\LocalService\Cookies\index.dat Object is locked skipped
C:\Documents and Settings\LocalService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat Object is locked skipped
C:\Documents and Settings\LocalService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped
C:\Documents and Settings\LocalService\Local Settings\History\History.IE5\index.dat Object is locked skipped
C:\Documents and Settings\LocalService\Local Settings\Temporary Internet Files\Content.IE5\index.dat Object is locked skipped
C:\Documents and Settings\LocalService\NTUSER.DAT Object is locked skipped
C:\Documents and Settings\LocalService\ntuser.dat.LOG Object is locked skipped
C:\Documents and Settings\NetworkService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat Object is locked skipped
C:\Documents and Settings\NetworkService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped
C:\Documents and Settings\NetworkService\NTUSER.DAT Object is locked skipped
C:\Documents and Settings\NetworkService\ntuser.dat.LOG Object is locked skipped
C:\Program Files\Updates from HP\309731\Users\Default\Data\cache.dat Object is locked skipped
C:\Program Files\Updates from HP\309731\Users\Default\Data\chandir.dat Object is locked skipped
C:\Program Files\Updates from HP\309731\Users\Default\Data\chandir.idx Object is locked skipped
C:\Program Files\Updates from HP\309731\Users\Default\Data\chn.dat Object is locked skipped
C:\Program Files\Updates from HP\309731\Users\Default\Data\chn.idx Object is locked skipped
C:\Program Files\Updates from HP\309731\Users\Default\Data\D0000000.FCS Object is locked skipped
C:\Program Files\Updates from HP\309731\Users\Default\Data\FileRep.log Object is locked skipped
C:\Program Files\Updates from HP\309731\Users\Default\Data\inuse.txt Object is locked skipped
C:\Program Files\Updates from HP\309731\Users\Default\Data\L0000002.FCS Object is locked skipped
C:\Program Files\Updates from HP\309731\Users\Default\Data\main.log Object is locked skipped
C:\Program Files\Updates from HP\309731\Users\Default\Data\prs.dat Object is locked skipped
C:\Program Files\Updates from HP\309731\Users\Default\Data\prs.idx Object is locked skipped
C:\Program Files\Updates from HP\309731\Users\Default\Data\prs_die.dat Object is locked skipped
C:\Program Files\Updates from HP\309731\Users\Default\Data\prs_die.idx Object is locked skipped
C:\Program Files\Updates from HP\309731\Users\Default\Data\prs_dnd.dat Object is locked skipped
C:\Program Files\Updates from HP\309731\Users\Default\Data\prs_dnd.idx Object is locked skipped
C:\Program Files\Updates from HP\309731\Users\Default\Data\prs_ext.dat Object is locked skipped
C:\Program Files\Updates from HP\309731\Users\Default\Data\prs_ext.idx Object is locked skipped
C:\Program Files\Updates from HP\309731\Users\Default\Data\prs_rcv.dat Object is locked skipped
C:\Program Files\Updates from HP\309731\Users\Default\Data\prs_rcv.idx Object is locked skipped
C:\Program Files\Updates from HP\309731\Users\Default\Data\storydb.dat Object is locked skipped
C:\Program Files\Updates from HP\309731\Users\Default\Data\storydb.idx Object is locked skipped
C:\Program Files\Webroot\Spy Sweeper\Masters\masters.bak Object is locked skipped
C:\Program Files\Webroot\Spy Sweeper\Masters\Masters.const Object is locked skipped
C:\Program Files\Webroot\Spy Sweeper\Masters\masters.mst Object is locked skipped
C:\Program Files\Webroot\Spy Sweeper\Masters.base Object is locked skipped
C:\System Volume Information\MountPointManagerRemoteDatabase Object is locked skipped
C:\WINDOWS\Debug\PASSWD.LOG Object is locked skipped
C:\WINDOWS\Internet Logs\fwdbglog.txt Object is locked skipped
C:\WINDOWS\Internet Logs\fwpktlog.txt Object is locked skipped
C:\WINDOWS\Internet Logs\IAMDB.RDB Object is locked skipped
C:\WINDOWS\Internet Logs\MY-F78BF48CE2.ldb Object is locked skipped
C:\WINDOWS\Internet Logs\tvDebug.log Object is locked skipped
C:\WINDOWS\SchedLgU.Txt Object is locked skipped
C:\WINDOWS\SoftwareDistribution\EventCache\{33359FE3-616B-4AB0-8A14-AC8A3AF62696}.bin Object is locked skipped
C:\WINDOWS\SoftwareDistribution\EventCache\{61D33514-88C6-45AF-870A-144C8A2EC725}.bin Object is locked skipped
C:\WINDOWS\SoftwareDistribution\ReportingEvents.log Object is locked skipped
C:\WINDOWS\Sti_Trace.log Object is locked skipped
C:\WINDOWS\system32\CatRoot2\edb.log Object is locked skipped
C:\WINDOWS\system32\CatRoot2\tmp.edb Object is locked skipped
C:\WINDOWS\system32\config\AppEvent.Evt Object is locked skipped
C:\WINDOWS\system32\config\default Object is locked skipped
C:\WINDOWS\system32\config\default.LOG Object is locked skipped
C:\WINDOWS\system32\config\SAM Object is locked skipped
C:\WINDOWS\system32\config\SAM.LOG Object is locked skipped
C:\WINDOWS\system32\config\SecEvent.Evt Object is locked skipped
C:\WINDOWS\system32\config\SECURITY Object is locked skipped
C:\WINDOWS\system32\config\SECURITY.LOG Object is locked skipped
C:\WINDOWS\system32\config\software Object is locked skipped
C:\WINDOWS\system32\config\software.LOG Object is locked skipped
C:\WINDOWS\system32\config\SysEvent.Evt Object is locked skipped
C:\WINDOWS\system32\config\system Object is locked skipped
C:\WINDOWS\system32\config\system.LOG Object is locked skipped
C:\WINDOWS\system32\h323log.txt Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\INDEX.BTR Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\INDEX.MAP Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\MAPPING.VER Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\MAPPING1.MAP Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\MAPPING2.MAP Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\OBJECTS.DATA Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\OBJECTS.MAP Object is locked skipped
C:\WINDOWS\Temp\ZLT024e9.TMP Object is locked skipped
C:\WINDOWS\wiadebug.log Object is locked skipped
C:\WINDOWS\wiaservc.log Object is locked skipped
C:\WINDOWS\WindowsUpdate.log Object is locked skipped

Scan process completed.
Clamp1
Newbie
_
24. October 2006 @ 17:15 _ Link to this message    Send private message to this user   
Here is the Hijack this log.

Logfile of HijackThis v1.99.1
Scan saved at 9:13:20 PM, on 10/24/2006
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\hkcmd.exe
C:\Program Files\Lexmark 2300 Series\ezprint.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\Program Files\QuickTime\qttask.exe
C:\Program Files\Java\jre1.5.0_06\bin\jusched.exe
C:\Program Files\Webroot\Spy Sweeper\SpySweeperUI.exe
C:\Program Files\CA\eTrust EZ Armor\eTrust Anti-Spam\QSP-2.1.215.5\QOELoader.exe
C:\Program Files\CA\eTrust EZ Armor\eTrust EZ Antivirus\CAVTray.exe
C:\Program Files\CA\eTrust EZ Armor\eTrust EZ Antivirus\CAVRID.exe
C:\Program Files\CA\eTrust EZ Armor\eTrust EZ Firewall\ca.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Messenger\msmsgs.exe
C:\Program Files\America Online 9.0d\aoltray.exe
C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
C:\Program Files\Updates from HP\309731\Program\Updates from HP.exe
C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe
C:\Program Files\Sony\Sony Picture Utility\VolumeWatcher\SPUVolumeWatcher.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
C:\Program Files\CA\eTrust EZ Armor\eTrust EZ Antivirus\ISafe.exe
c:\Program Files\Common Files\LightScribe\LSSrvc.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\WINDOWS\system32\HPZipm12.exe
C:\WINDOWS\system32\tcpsvcs.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\ZoneLabs\vsmon.exe
C:\Program Files\Webroot\Spy Sweeper\SpySweeper.exe
c:\Program Files\Common Files\Symantec Shared\Security Center\SymWSC.exe
C:\WINDOWS\system32\lxcgcoms.exe
C:\Program Files\Google\GoogleToolbarNotifier\1.2.908.5008\GoogleToolbarNotifier.exe
C:\Program Files\CA\eTrust EZ Armor\eTrust EZ Antivirus\VetMsg.exe
C:\HP\KBD\KBD.EXE
C:\WINDOWS\SOUNDMAN.EXE
C:\WINDOWS\ALCMTR.EXE
C:\WINDOWS\ALCWZRD.EXE
C:\WINDOWS\AGRSMMSG.exe
c:\windows\system\hpsysdrv.exe
C:\WINDOWS\system32\hphmon06.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\PROGRA~1\Yahoo!\COMPAN~1\Installs\cpn1\YTBSDK.exe
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\Documents and Settings\HP_Owner\Desktop\HijackThis_v1.99.1.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.rr.com/
R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn1\yt.dll
O2 - BHO: Yahoo! Toolbar Helper - {02478D38-C3F9-4EFB-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn1\yt.dll
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar5.dll
O3 - Toolbar: HP view - {B2847E28-5D7D-4DEB-8B67-05D28BCF79F5} - c:\Program Files\HP\Digital Imaging\bin\HPDTLK02.dll
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn1\yt.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar5.dll
O4 - HKLM\..\Run: [High Definition Audio Property Page Shortcut] HDAudPropShortcut.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\system32\hkcmd.exe
O4 - HKLM\..\Run: [HPBootOp] "C:\Program Files\Hewlett-Packard\HP Boot Optimizer\HPBootOp.exe" /run
O4 - HKLM\..\Run: [_SetRes] c:\hp\bin\cloaker c:\hp\bin\res.bat
O4 - HKLM\..\Run: [IcoSet] "c:\hp\bin\cloaker.exe" c:\hp\bin\IcoSet\adjust.bat seticon
O4 - HKLM\..\Run: [LSBWatcher] c:\hp\drivers\hplsbwatcher\lsburnwatcher.exe
O4 - HKLM\..\Run: [lxcgmon.exe] "C:\Program Files\Lexmark 2300 Series\lxcgmon.exe"
O4 - HKLM\..\Run: [EzPrint] "C:\Program Files\Lexmark 2300 Series\ezprint.exe"
O4 - HKLM\..\Run: [FaxCenterServer] "C:\Program Files\Lexmark Fax Solutions\fm3032.exe" /s
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.5.0_06\bin\jusched.exe"
O4 - HKLM\..\Run: [LXCGCATS] rundll32 C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\LXCGtime.dll,_RunDLLEntry@16
O4 - HKLM\..\Run: [SpySweeper] "C:\Program Files\Webroot\Spy Sweeper\SpySweeperUI.exe" /startintray
O4 - HKLM\..\Run: [QOELOADER] "C:\Program Files\CA\eTrust EZ Armor\eTrust Anti-Spam\QSP-2.1.215.5\QOELoader.exe"
O4 - HKLM\..\Run: [CaAvTray] "C:\Program Files\CA\eTrust EZ Armor\eTrust EZ Antivirus\CAVTray.exe"
O4 - HKLM\..\Run: [CAVRID] "C:\Program Files\CA\eTrust EZ Armor\eTrust EZ Antivirus\CAVRID.exe"
O4 - HKLM\..\Run: [Zone Labs Client] "C:\Program Files\CA\eTrust EZ Armor\eTrust EZ Firewall\ca.exe"
O4 - HKLM\..\Run: [!AVG Anti-Spyware] "C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" /minimized
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [swg] "C:\Program Files\Google\GoogleToolbarNotifier\1.0.720.3640\GoogleToolbarNotifier.exe"
O4 - Startup: Cyber-shot Viewer Media Check Tool.lnk = C:\Program Files\Sony\Sony Picture Utility\VolumeWatcher\SPUVolumeWatcher.exe
O4 - Startup: HP Organize.lnk = ?
O4 - Global Startup: America Online 9.0 Tray Icon.lnk = C:\Program Files\America Online 9.0d\aoltray.exe
O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
O4 - Global Startup: SpySubtract.lnk = C:\Program Files\InterMute\SpySubtract\sslaunch.exe
O4 - Global Startup: Updates from HP.lnk = C:\Program Files\Updates from HP\309731\Program\Updates from HP.exe
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MI1933~1\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MI1933~1\OFFICE11\REFIEBAR.DLL
O9 - Extra button: Connection Help - {E2D4D26B-0180-43a4-B05F-462D6D54C789} - C:\WINDOWS\PCHEALTH\HELPCTR\Vendors\CN=Hewlett-Packard,L=Cupertino,S=Ca,C=US\IEButton\support.htm
O9 - Extra 'Tools' menuitem: Connection Help - {E2D4D26B-0180-43a4-B05F-462D6D54C789} - C:\WINDOWS\PCHEALTH\HELPCTR\Vendors\CN=Hewlett-Packard,L=Cupertino,S=Ca,C=US\IEButton\support.htm
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra button: Connection Help - {E2D4D26B-0180-43a4-B05F-462D6D54C789} - C:\WINDOWS\PCHEALTH\HELPCTR\Vendors\CN=Hewlett-Packard,L=Cupertino,S=Ca,C=US\IEButton\support.htm (HKCU)
O9 - Extra 'Tools' menuitem: Connection Help - {E2D4D26B-0180-43a4-B05F-462D6D54C789} - C:\WINDOWS\PCHEALTH\HELPCTR\Vendors\CN=Hewlett-Packard,L=Cupertino,S=Ca,C=US\IEButton\support.htm (HKCU)
O16 - DPF: {0EB0E74A-2A76-4AB3-A7FB-9BD8C29F7F75} (CKAVWebScan Object) - http://www.kaspersky.com/kos/english/kavwebscan_unicode.cab
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?LinkID=39204
O20 - Winlogon Notify: igfxcui - C:\WINDOWS\SYSTEM32\igfxsrvc.dll
O20 - Winlogon Notify: WRNotifier - C:\WINDOWS\SYSTEM32\WRLogonNTF.dll
O21 - SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll
O23 - Service: Automatic LiveUpdate Scheduler - Symantec Corporation - C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe
O23 - Service: AVG Anti-Spyware Guard - Anti-Malware Development a.s. - C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
O23 - Service: CAISafe - Computer Associates International, Inc. - C:\Program Files\CA\eTrust EZ Armor\eTrust EZ Antivirus\ISafe.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe
O23 - Service: iPod Service (iPodService) - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - c:\Program Files\Common Files\LightScribe\LSSrvc.exe
O23 - Service: LiveUpdate - Symantec Corporation - C:\PROGRA~1\Symantec\LIVEUP~1\LUCOMS~1.EXE
O23 - Service: lxcg_device - - C:\WINDOWS\system32\lxcgcoms.exe
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe
O23 - Service: SymWMI Service (SymWSC) - Symantec Corporation - c:\Program Files\Common Files\Symantec Shared\Security Center\SymWSC.exe
O23 - Service: VET Message Service (VETMSGNT) - Computer Associates International, Inc. - C:\Program Files\CA\eTrust EZ Armor\eTrust EZ Antivirus\VetMsg.exe
O23 - Service: TrueVector Internet Monitor (vsmon) - Zone Labs Inc. - C:\WINDOWS\system32\ZoneLabs\vsmon.exe
O23 - Service: Webroot Spy Sweeper Engine (WebrootSpySweeperService) - Webroot Software, Inc. - C:\Program Files\Webroot\Spy Sweeper\SpySweeper.exe
Senior Member
_
24. October 2006 @ 19:16 _ Link to this message    Send private message to this user   
Wonderful! One more bad file and one more check(for a rootkit) and you should be clear.

Delete this file:
C:\23100247.exe

This isn't malware, but not needed on startup. Read here for more information about this file.
Go to Start > Run > type msconfig > click OK > click the Startup tab > find ALCMTR.EXE and uncheck it.


Dowload F-Secure Blacklight (blbeta.exe) to the desktop from here.
Open it and click Accept Agreement.
Click "Scan".
After the scan is complete, click "Next", then "Exit".
It will create a log on the desktop named "fsbl-xxxxxxx.log" (the xxxxxxx will be the date and time of the scan)
Post that log in your next reply.

How are things? Any problems?


Clamp1
Newbie
_
25. October 2006 @ 12:25 _ Link to this message    Send private message to this user   
When I try to delet the file C:\23100247.exe it says access denied.
And I cant find ALCMTR.EXE in the start up Tab

This message has been edited since posting. Last time this message was edited on 25. October 2006 @ 12:27

Senior Member
_
25. October 2006 @ 12:43 _ Link to this message    Send private message to this user   
Delete the file in safe mode. And no worries about ALCMTR.EXE not being there.

Clamp1
Newbie
_
25. October 2006 @ 13:34 _ Link to this message    Send private message to this user   
Here is the F-Secure Backlight Log

10/25/06 17:24:11 [Info]: BlackLight Engine 1.0.47 initialized
10/25/06 17:24:11 [Info]: OS: 5.1 build 2600 (Service Pack 2)
10/25/06 17:24:11 [Note]: 7019 4
10/25/06 17:24:11 [Note]: 7005 0
10/25/06 17:24:18 [Note]: 7006 0
10/25/06 17:24:18 [Note]: 7011 1392
10/25/06 17:24:19 [Note]: 7026 0
10/25/06 17:24:19 [Note]: 7026 0
10/25/06 17:24:32 [Note]: FSRAW library version 1.7.1020
10/25/06 17:28:33 [Note]: 2000 1012
10/25/06 17:33:15 [Note]: 7007 0
Advertisement
_
__
 
_
Clamp1
Newbie
_
25. October 2006 @ 13:39 _ Link to this message    Send private message to this user   
Before I came to this website my computer said that I was infected by the BackDoor Haxdoor virus. SO I wanted to ask if that is on my computer. And Afterall of this is my computer virus free.
 
Page:12Next >
afterdawn.com > forums > software, operating systems and more > windows - virus and spyware problems > need help
 

Digital video: AfterDawn.com | AfterDawn Forums
Music: MP3Lizard.com
Gaming: Blasteroids.com | Blasteroids Forums | Compare game prices
Software: Software downloads
Blogs: User profile pages
RSS feeds: AfterDawn.com News | Software updates | AfterDawn Forums
International: AfterDawn in Finnish | AfterDawn in Swedish | AfterDawn in Norwegian | download.fi
Navigate: Search | Site map
About us: About AfterDawn Ltd | Advertise on our sites | Rules, Restrictions, Legal disclaimer & Privacy policy
Contact us: Send feedback | Contact our media sales team
 
  © 1999-2025 by AfterDawn Ltd.

  IDG TechNetwork