Jump to content


 


Register a free account to unlock additional features at BleepingComputer.com
Welcome to BleepingComputer, a free community where people like yourself come together to discuss and learn how to use their computers. Using the site is easy and fun. As a guest, you can browse and view the various discussions in the forums, but can not create a new topic or reply to an existing one unless you are logged in. Other benefits of registering an account are subscribing to topics and forums, creating a blog, and having no ads shown anywhere on the site.


Click here to Register a free account now! or read our Welcome Guide to learn how to use this site.

Photo

I hope you can help me, BC!


  • This topic is locked This topic is locked
15 replies to this topic

#1 ZlobIsFun

ZlobIsFun

  • Members
  • 92 posts
  • OFFLINE
  •  
  • Local time:09:50 PM

Posted 13 January 2010 - 06:51 AM

Operating system: Windows XP Proffesional SP3 32-bit

What I think I'm infected with: H8SRT.

Symptoms: Redirecting, slow loading, random computer lock ups ( I can move the mouse but I can't move windows or get and reaction onscreen at all besides the mouse moving. ), and I'm unable to save/change the startup files ( Well, I change and save, remove things such as msnmsgr.exe and click apply, exit, restart, and it still starts up. )

Well, I don't know how I got infected.. I never get infected, I mean. I'm a smart user, I never click ads and I can tell when something's fake.

This is how it happened:
A windows security window popped up, it said something about a worm? I don't know, I thought my firewall was off so I clicked 'enable protection' and right away it started downloading malware defense.
I used task manager to end the program and and other .tmp/.exe files/programs running immediately.
I came here after I realized iexplore.exe was always running. I deleted the file and it restored itself right away, I then replaced the iexplorer.exe with a bat file ( read only, as an .exe file. ) At first it opened every few seconds showing " Blah blah blah this is not a valid windows 32 program. "
Anyway, I came here and followed the tutorial on removing melware defense, even though I thought it didn't harm my computer.
I thought, well, everything was okay.
But even after malware bytes scanned mbam.exe wasn't running all the way because the infection wouldn't let it intalize, I renamed it of course and ran it. The infection doesn't delete mbam.exe, it just, well, doesn't let it load up. I tested this by renaming a game exe to mbam and it wouldn't initialize.

It does the same for search and destroy, I have to rename it. :[ ( Yes, I downloaded search and destroy. )

I'm getting redirected to youserch.com and other stupid stuff when I click links on google. Google loads slower, and so do pages.

I keep running malware bytes and it's finding H8SRT in the registry and system32. Before letting it remove it, I look for them to see if I can do it myself. They're not there!
Malware bytes claims it has removed the infection, but when I restart and run another scan it still detects them.
( I also tried jump to location, nothing. )

QUOTE
Memory Processes Infected: 0
Memory Modules Infected: 1
Registry Keys Infected: 1
Registry Values Infected: 0
Registry Data Items Infected: 0
Folders Infected: 0
Files Infected: 1

Memory Processes Infected:
(No malicious items detected)

Memory Modules Infected:
\\?\globalroot\systemroot\system32\H8SRTxwbrsklvdo.dll (Trojan.Vundo) -> Delete on reboot.

Registry Keys Infected:
HKEY_LOCAL_MACHINE\SOFTWARE\H8SRT (Rootkit.TDSS) -> Quarantined and deleted successfully.

Registry Values Infected:
(No malicious items detected)

Registry Data Items Infected:
(No malicious items detected)

Folders Infected:
(No malicious items detected)

Files Infected:
\\?\globalroot\systemroot\system32\H8SRTxwbrsklvdo.dll (Trojan.Vundo) -> Quarantined and deleted successfully.


I'll post/download anything, just please, I need your help BC! :[ This is really starting to annoy me.. I have a short temper and I'm angry because I don't understand why/how I got this stupid virus, and I also don't understand why avast, malwarebytes, and S&D can't help me.

I know you guys can, though.
Now I sit and wait, about to destroy my computer with my bare hands.
I'll be waiting for your replies, thanks in advanced.

BC AdBot (Login to Remove)

 


#2 Elise

Elise

    Bleepin' Blonde


  • Malware Study Hall Admin
  • 61,252 posts
  • OFFLINE
  •  
  • Gender:Female
  • Location:Romania
  • Local time:06:50 AM

Posted 13 January 2010 - 06:54 AM


welcome.gif to the Bleeping Computer Malware Removal Forum
, My name is Elise. I'll be glad to help you with your computer problems.


I will be working on your malware issues, this may or may not solve other issues you may have with your machine.

Please note that whatever repairs we make, are for fixing your computer problems only and by no means should be used on another computer.

You may want to keep the link to this topic in your favorites. Alternatively, you can click the button at the top bar of this topic and Track this Topic, where you can choose email notifications. The topics you are tracking are shown here.
-----------------------------------------------------------
Please be patient and I'd be grateful if you would note the following:
  • The cleaning process is not instant. DDS logs can take some time to research, so please be patient with me. I know that you need your computer working as quickly as possible, and I will work hard to help see that happen.
  • Please reply using the Add/Reply button in the lower right hand corner of your screen. Do not start a new topic.
  • The logs that you post should be pasted directly into the reply. Only attach them if requested or if they do not fit into the post.
  • Unfortunately, if I do not hear back from you within 5 days, I will be forced to close your topic. If you still need help after I have closed your topic, send me or a moderator a personal message with the address of the thread or feel free to create a new one.

In the meantime please, do NOT install any new programs or update anything unless told to do so while we are fixing your problem.


I moved your topic to the HJT malware removal forum, since this is a nasty rootkit infection, which can't be cleaned with the tools we are allowed to use in the Am I Infected forum.

COMBOFIX
---------------
Please download ComboFix from one of these locations:
  • Disable your AntiVirus and AntiSpyware applications, usually via a right click on the System Tray icon. They may otherwise interfere with our tools. (Click on this link to see a list of programs that should be disabled. The list is not all inclusive.)
  • Double click on Combofix.exe and follow the prompts.
  • As part of it's process, ComboFix will check to see if the Microsoft Windows Recovery Console is installed. With malware infections being as they are today, it's strongly recommended to have this pre-installed on your machine before doing any malware removal. It will allow you to boot up into a special recovery/repair mode that will allow us to more easily help you should your computer have a problem after an attempted removal of malware.
  • Follow the prompts to allow ComboFix to download and install the Microsoft Windows Recovery Console, and when prompted, agree to the End-User License Agreement to install the Microsoft Windows Recovery Console.
**Please note: If the Microsoft Windows Recovery Console is already installed, or if you are running Vista, ComboFix will continue it's malware removal procedures.



Once the Microsoft Windows Recovery Console is installed using ComboFix, you should see the following message:



Click on Yes, to continue scanning for malware.

When finished, it shall produce a log for you. Please include the C:\ComboFix.txt in your next reply.


regards, Elise


"Now faith is the substance of things hoped for, the evidence of things not seen."

 

Follow BleepingComputer on: Facebook | Twitter | Google+ | lockerdome

 

Malware analyst @ Emsisoft


#3 ZlobIsFun

ZlobIsFun
  • Topic Starter

  • Members
  • 92 posts
  • OFFLINE
  •  
  • Local time:09:50 PM

Posted 13 January 2010 - 07:33 AM

Hello! Thank you for the fast reply. :]

Combofix won't open unless I rename it, which I have done.

---




The log is too big.
Attachment below.

Attached Files


Edited by ZlobIsFun, 13 January 2010 - 07:35 AM.


#4 Elise

Elise

    Bleepin' Blonde


  • Malware Study Hall Admin
  • 61,252 posts
  • OFFLINE
  •  
  • Gender:Female
  • Location:Romania
  • Local time:06:50 AM

Posted 13 January 2010 - 02:52 PM

Hi, that took care of some nasty stuff. Please consider the following first....

BACKDOOR WARNING
------------------------------
One or more of the identified infections is known to use a backdoor.

This allows hackers to remotely control your computer, steal critical system information and download and execute files.

I would advice you to disconnect this PC from the Internet immediately. If you do any banking or other financial transactions on the PC or if it should contain any other sensitive information, please get to a known clean computer and change all passwords where applicable, and it would be wise to contact those same financial institutions to apprise them of your situation.

Though the infection has been identified and can be killed, because of it's backdoor functionality, your PC is very likely compromised and there is no way to be sure your computer can ever again be trusted. Many experts in the security community believe that once infected with this type of trojan, the best course of action would be a reformat and reinstall of the OS. Please read these for more information:

How Do I Handle Possible Identify Theft, Internet Fraud and CC Fraud?
When Should I Format, How Should I Reinstall

We can still clean this machine but I can't guarantee that it will be 100% secure afterwards. Let me know what you decide to do. If you decide to go through with the cleanup, please proceed with the following steps.


We need to see some information about what is happening in your machine. Please perform the following scan:
  • Download DDS by sUBs from one of the following links. Save it to your desktop.
  • Double click on the DDS icon, allow it to run.
  • A small box will open, with an explanation about the tool. No input is needed, the scan is running.
  • Notepad will open with the results.
  • Follow the instructions that pop up for posting the results. Post both logs (no need to zip attach.txt).
  • Close the program window, and delete the program from your desktop.
Please note: You may have to disable any script protection running if the scan fails to run. After downloading the tool, disconnect from the internet and disable all antivirus protection. Run the scan, enable your A/V and reconnect to the internet.

Information on A/V control HERE

regards, Elise


"Now faith is the substance of things hoped for, the evidence of things not seen."

 

Follow BleepingComputer on: Facebook | Twitter | Google+ | lockerdome

 

Malware analyst @ Emsisoft


#5 ZlobIsFun

ZlobIsFun
  • Topic Starter

  • Members
  • 92 posts
  • OFFLINE
  •  
  • Local time:09:50 PM

Posted 13 January 2010 - 07:22 PM

I have a windows XP home edition CD, I was thinking of reformatting and then installing it. But it's pretty scratched up, so I don't want to take drastic measures just yet.

I don't do any banking, this computer is used for gaming/browsing/Media.

I don't have an anti-virus installed on this computer. I never really get viruses. Well, I probably do but nothing serious like this.

Attached Files


Edited by ZlobIsFun, 13 January 2010 - 07:23 PM.


#6 Elise

Elise

    Bleepin' Blonde


  • Malware Study Hall Admin
  • 61,252 posts
  • OFFLINE
  •  
  • Gender:Female
  • Location:Romania
  • Local time:06:50 AM

Posted 14 January 2010 - 06:05 AM

Hello again,

Please let me know how things are running now.

P2P WARNING
-------------------
Going over your logs I noticed that you have uTorrent installed.
  • Avoid gaming sites, pirated software, cracking tools, keygens, and peer-to-peer (P2P) file sharing programs.
  • They are a security risk which can make your computer susceptible to a smörgåsbord of malware infections, remote attacks, exposure of personal information, and identity theft. Many malicious worms and Trojans spread across P2P file sharing networks, gaming and underground sites.
  • Users visiting such pages may see innocuous-looking banner ads containing code which can trigger pop-up ads and malicious Flash ads that install viruses, Trojans and spyware. Ads are a target for hackers because they offer a stealthy way to distribute malware to a wide range of Internet users.
  • The best way to reduce the risk of infection is to avoid these types of web sites and not use any P2P applications.
It is pretty much certain that if you continue to use P2P programs, you will get infected again.
I would recommend that you uninstall uTorrent, however that choice is up to you. If you choose to remove these programs, you can do so via Start > Control Panel > Add/Remove Programs.

If you wish to keep it, please do not use it until your computer is cleaned.


UPDATE JAVA
------------------
Your Java is out of date. Older versions have vulnerabilities that malicious sites can use to exploit and infect your system. Please follow these steps to remove older version Java components and update:
  • Download the latest version of Java Runtime Environment (JRE) Version 6 and save it to your desktop.
  • Look for "Java Runtime Environment (JRE)" JRE 6 Update 17.
  • Click the Download button to the right.
  • Select your Platform: "Windows".
  • Select your Language: "Multi-language".
  • Read the License Agreement, and then check the box that says: "Accept License Agreement".
  • Click Continue and the page will refresh.
  • Under Required Files, check the box for Windows Offline Installation, click the link below it and save the file to your desktop.
  • Close any programs you may have running - especially your web browser.
Go to Start > Settings > Control Panel, double-click on Add/Remove Programs and remove all older versions of Java.
  • Check (highlight) any item with Java Runtime Environment (JRE or J2SE) in the name.
  • Click the Remove or Change/Remove button and follow the onscreen instructions for the Java uninstaller.
  • Repeat as many times as necessary to remove each Java versions.
  • Reboot your computer once all Java components are removed.
  • Then from your desktop double-click on jre-6u17-windows-i586.exe to install the newest version.
-- If using Windows Vista and the installer refuses to launch due to insufficient user permissions, then Run As Administrator.
-- If you choose to update via the Java applet in Control Panel, uncheck the option to install the Toolbar unless you want it.
-- The uninstaller incorporated in this release removes previous Updates 10 and above, but does not remove older versions, so they still need to be removed manually.


Note: The Java Quick Starter (JQS.exe) adds a service to improve the initial startup time of Java applets and applications. To disable the JQS service if you don't want to use it, go to Start > Control Panel > Java > Advanced > Miscellaneous and uncheck the box for Java Quick Starter. Click Ok and reboot your computer.


MALWAREBYTES ANTIMALWARE
-------------------------------------------
Please launch MBAM and update the program before performing a scan.
  • If an update is found, the program will automatically update itself. Press the OK button to close that box and continue.
  • If you encounter any problems while downloading the definition updates, manually download them from here and just double-click on mbam-rules.exe to install.
On the Scanner tab:
  • Make sure the "Perform Full Scan" option is selected.
  • Then click on the Scan button.
  • If asked to select the drives to scan, leave all the drives selected and click on the Start Scan button.
  • The scan will begin and "Scan in progress" will show at the top. It may take some time to complete so please be patient.
  • When the scan is finished, a message box will say "The scan completed successfully. Click 'Show Results' to display all objects found".
  • Click OK to close the message box and continue with the removal process.
Back at the main Scanner screen:
  • Click on the Show Results button to see a list of any malware that was found.
  • Make sure that everything is checked, and click Remove Selected.
  • When removal is completed, a log report will open in Notepad.
  • The log is automatically saved and can be viewed by clicking the Logs tab in MBAM.
  • Copy and paste the contents of that report in your next reply. Be sure to post the complete log to include the top portion which shows MBAM's database version and your operating system.
  • Exit MBAM when done.
Note: If MBAM encounters a file that is difficult to remove, you will be asked to reboot your computer so MBAM can proceed with the disinfection process. If asked to restart the computer, please do so immediately. Failure to reboot normally (not into safe mode) will prevent MBAM from removing all the malware.


regards, Elise


"Now faith is the substance of things hoped for, the evidence of things not seen."

 

Follow BleepingComputer on: Facebook | Twitter | Google+ | lockerdome

 

Malware analyst @ Emsisoft


#7 ZlobIsFun

ZlobIsFun
  • Topic Starter

  • Members
  • 92 posts
  • OFFLINE
  •  
  • Local time:09:50 PM

Posted 14 January 2010 - 05:06 PM

Thanks for the reply!
I have only ran uTorrent three times, once so my friend could send me a .zip of pictures, another time for a private server game setup which was huge, and the third time-- Something personal?
I'll remove it, I know how to keep safe with the program and all but it is useless.
----
I can't update java. It keeps failing and saying " Reconnecting to server ", then after a few minutes it said " Download failed, maximum retries exceeded.

----

MBAM.exe will open, finally! I don't have to rename it anymore.

----

ALSO: I don't get redirected anymore when I click links on google. thumbup2.gif

----

I guess when combofix removed those H8SRT back doors it fixed a few problems.
Ever since then my games don't get registry errors anymore. ( I didn't mention this problem because I didn't think it was
relevant. )

----

--Will edit post with malwarebytes log later.--

EDIT:
QUOTE
Malwarebytes' Anti-Malware 1.44
Database version: 3565
Windows 5.1.2600 Service Pack 3
Internet Explorer 8.0.6001.18702

1/14/2010 4:58:51 PM
what

Scan type: Full Scan (C:\|)
Objects scanned: 164249
Time elapsed: 56 minute(s), 3 second(s)

Memory Processes Infected: 0
Memory Modules Infected: 0
Registry Keys Infected: 0
Registry Values Infected: 0
Registry Data Items Infected: 0
Folders Infected: 0
Files Infected: 14

Memory Processes Infected:
(No malicious items detected)

Memory Modules Infected:
(No malicious items detected)

Registry Keys Infected:
(No malicious items detected)

Registry Values Infected:
(No malicious items detected)

Registry Data Items Infected:
(No malicious items detected)

Folders Infected:
(No malicious items detected)

Files Infected:
C:\Documents and Settings\Administrator\Local Settings\temp\nsm1A.tmp\brandingurl.dll (Malware.Packer.Morphine) -> No action taken.
C:\Documents and Settings\Administrator\Local Settings\temp\nsq10.tmp\brandingurl.dll (Malware.Packer.Morphine) -> No action taken.
C:\Documents and Settings\Administrator\Local Settings\temp\nsy2F.tmp\brandingurl.dll (Malware.Packer.Morphine) -> No action taken.
C:\Qoobox\Quarantine\C\WINDOWS\system32\H8SRTjqupmenabr.dll.vir (Trojan.Vundo) -> No action taken.
C:\Qoobox\Quarantine\C\WINDOWS\system32\H8SRTtvtpjeuxia.dll.vir (Trojan.Vundo) -> No action taken.
C:\Qoobox\Quarantine\C\WINDOWS\system32\H8SRTuhnxynwayw.dll.vir (Trojan.Vundo) -> No action taken.
C:\Qoobox\Quarantine\C\WINDOWS\system32\H8SRTxwbrsklvdo.dll.vir (Trojan.Vundo) -> No action taken.
C:\Qoobox\Quarantine\C\WINDOWS\system32\drivers\H8SRTntlqvahcsq.sys.vir (Trojan.TDSS) -> No action taken.
C:\System Volume Information\_restore{5D624308-997D-4C89-998C-1122931045B7}\RP57\A0056531.sys (Trojan.TDSS) -> No action taken.
C:\System Volume Information\_restore{5D624308-997D-4C89-998C-1122931045B7}\RP57\A0056532.dll (Trojan.Vundo) -> No action taken.
C:\System Volume Information\_restore{5D624308-997D-4C89-998C-1122931045B7}\RP57\A0056533.dll (Trojan.Vundo) -> No action taken.
C:\System Volume Information\_restore{5D624308-997D-4C89-998C-1122931045B7}\RP57\A0056534.dll (Trojan.Vundo) -> No action taken.
C:\System Volume Information\_restore{5D624308-997D-4C89-998C-1122931045B7}\RP57\A0056535.dll (Trojan.Vundo) -> No action taken.
C:\System Volume Information\_restore{5D624308-997D-4C89-998C-1122931045B7}\RP57\A0056633.sys (Malware.Trace) -> No action taken.


After reboot:
QUOTE
Malwarebytes' Anti-Malware 1.44
Database version: 3565
Windows 5.1.2600 Service Pack 3
Internet Explorer 8.0.6001.18702

1/14/2010 5:00:26 PM
mbam-log-2010-01-14 (17-00-26).txt

Scan type: Full Scan (C:\|)
Objects scanned: 164249
Time elapsed: 56 minute(s), 3 second(s)

Memory Processes Infected: 0
Memory Modules Infected: 0
Registry Keys Infected: 0
Registry Values Infected: 0
Registry Data Items Infected: 0
Folders Infected: 0
Files Infected: 14

Memory Processes Infected:
(No malicious items detected)

Memory Modules Infected:
(No malicious items detected)

Registry Keys Infected:
(No malicious items detected)

Registry Values Infected:
(No malicious items detected)

Registry Data Items Infected:
(No malicious items detected)

Folders Infected:
(No malicious items detected)

Files Infected:
C:\Documents and Settings\Administrator\Local Settings\temp\nsm1A.tmp\brandingurl.dll (Malware.Packer.Morphine) -> Quarantined and deleted successfully.
C:\Documents and Settings\Administrator\Local Settings\temp\nsq10.tmp\brandingurl.dll (Malware.Packer.Morphine) -> Quarantined and deleted successfully.
C:\Documents and Settings\Administrator\Local Settings\temp\nsy2F.tmp\brandingurl.dll (Malware.Packer.Morphine) -> Quarantined and deleted successfully.
C:\Qoobox\Quarantine\C\WINDOWS\system32\H8SRTjqupmenabr.dll.vir (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\Qoobox\Quarantine\C\WINDOWS\system32\H8SRTtvtpjeuxia.dll.vir (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\Qoobox\Quarantine\C\WINDOWS\system32\H8SRTuhnxynwayw.dll.vir (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\Qoobox\Quarantine\C\WINDOWS\system32\H8SRTxwbrsklvdo.dll.vir (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\Qoobox\Quarantine\C\WINDOWS\system32\drivers\H8SRTntlqvahcsq.sys.vir (Trojan.TDSS) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{5D624308-997D-4C89-998C-1122931045B7}\RP57\A0056531.sys (Trojan.TDSS) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{5D624308-997D-4C89-998C-1122931045B7}\RP57\A0056532.dll (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{5D624308-997D-4C89-998C-1122931045B7}\RP57\A0056533.dll (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{5D624308-997D-4C89-998C-1122931045B7}\RP57\A0056534.dll (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{5D624308-997D-4C89-998C-1122931045B7}\RP57\A0056535.dll (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{5D624308-997D-4C89-998C-1122931045B7}\RP57\A0056633.sys (Malware.Trace) -> Quarantined and deleted successfully.

Edited by ZlobIsFun, 14 January 2010 - 06:27 PM.


#8 Elise

Elise

    Bleepin' Blonde


  • Malware Study Hall Admin
  • 61,252 posts
  • OFFLINE
  •  
  • Gender:Female
  • Location:Romania
  • Local time:06:50 AM

Posted 15 January 2010 - 02:06 AM

Hi, looks good so far!

Can't you access the Java site or do you have troubles after you click the actual download link on the site? Did you try this with another browser. FYI, newest update is 18, not 17 (since two days smile.gif ).

ESET ONLINE SCANNER
----------------------------
I'd like us to scan your machine with ESET OnlineScan
  1. Hold down Control and click on the following link to open ESET OnlineScan in a new window.
    ESET OnlineScan
  2. Click the button.
  3. For alternate browsers only: (Microsoft Internet Explorer users can skip these steps)
    1. Click on to download the ESET Smart Installer. Save it to your desktop.
    2. Double click on the icon on your desktop.
  4. Check
  5. Click the button.
  6. Accept any security warnings from your browser.
  7. Check
  8. Push the Start button.
  9. ESET will then download updates for itself, install itself, and begin scanning your computer. Please be patient as this can take some time.
  10. When the scan completes, push
  11. Push , and save the file to your desktop using a unique name, such as ESETScan. Include the contents of this report in your next reply.
    Note - when ESET doesn't find any threats, no report will be created.
  12. Push the button.
  13. Push

regards, Elise


"Now faith is the substance of things hoped for, the evidence of things not seen."

 

Follow BleepingComputer on: Facebook | Twitter | Google+ | lockerdome

 

Malware analyst @ Emsisoft


#9 ZlobIsFun

ZlobIsFun
  • Topic Starter

  • Members
  • 92 posts
  • OFFLINE
  •  
  • Local time:09:50 PM

Posted 15 January 2010 - 02:58 AM

Thanks for the fast reply.
I accidently removed one of my 'edits' in my last post, I downloaded the Java JRE 18 directly from the website, so all is good.
Yes, everything looks good at the moment, glad you helped me with the nasty infections.

----
SCAN
----
Some of them are false positives! :[
It found a few 'viruses' in my Fruity Loops folder ( FL Studio, basically just to make songs/beats/rhythms/etc.
Also found my modded .theme files as viruses ( Put into .exes. )
Also found my rocket dock files as viruses.
Sality.nac is a nasty virus.. I hope they're not really infected.
Some dlls in i386 are supposedly 'infected'..
Over 1,000 infections?

QUOTE
C:\DELL\UWAKEOFF.EXE Win32/Sality.NAC virus deleted - quarantined
C:\DELL\UWAKEON.EXE Win32/Sality.NAC virus deleted - quarantined
C:\DELL\drivers\R126542\Setup.exe Win32/Sality.NAC virus deleted - quarantined
C:\DELL\drivers\R126542\Win2000\hkcmd.exe Win32/Sality.NAC virus deleted - quarantined
C:\DELL\drivers\R126542\Win2000\ialmudlg.exe Win32/Sality.NAC virus deleted - quarantined
C:\DELL\drivers\R126542\Win2000\igfxcfg.exe Win32/Sality.NAC virus deleted - quarantined
C:\DELL\drivers\R126542\Win2000\igfxext.exe Win32/Sality.NAC virus deleted - quarantined
C:\DELL\drivers\R126542\Win2000\igfxpers.exe Win32/Sality.NAC virus deleted - quarantined
C:\DELL\drivers\R126542\Win2000\igfxsrvc.exe Win32/Sality.NAC virus deleted - quarantined
C:\DELL\drivers\R126542\Win2000\igfxtray.exe Win32/Sality.NAC virus deleted - quarantined
C:\DELL\drivers\R126542\Win2000\igfxzoom.exe Win32/Sality.NAC virus deleted - quarantined
C:\DELL\drivers\R97809\AEEnable.exe Win32/Sality.NAC virus deleted - quarantined
C:\DELL\drivers\R97809\SMAXWDM\W2K_XP\SMax4PNP.exe Win32/Sality.NAC virus deleted - quarantined
C:\DELL\drivers\R97809\Sys\DSndUp.exe Win32/Sality.NAC virus deleted - quarantined
C:\Documents and Settings\Administrator\Application Data\IMVUClient\w9xpopen.exe Win32/Sality.NAC virus deleted - quarantined
C:\Documents and Settings\Administrator\Application Data\IMVUClient\WriteMiniDump.exe Win32/Sality.NAC virus deleted - quarantined
C:\Documents and Settings\Administrator\Application Data\Microsoft\Installer\{9559F7CA-5E34-4237-A2D9-D856464AD727}\ARPPRODUCTICON.exe Win32/Sality.NAC virus deleted - quarantined
C:\Documents and Settings\Administrator\Application Data\Microsoft\Installer\{9559F7CA-5E34-4237-A2D9-D856464AD727}\NewShortcut1_9559F7CA5E344237A2D9D856464AD727.exe Win32/Sality.NAC virus deleted - quarantined
C:\Documents and Settings\Administrator\Desktop\Recorder.exe Win32/Sality.NAC virus deleted - quarantined
C:\Documents and Settings\Administrator\Desktop\Imptortance\Bleeping Computer\dds.scr Win32/Sality.NAC virus deleted - quarantined
C:\Documents and Settings\Administrator\Desktop\Imptortance\Bleeping Computer\Roblox.exe Win32/Sality.NAC virus deleted - quarantined
C:\Documents and Settings\Administrator\Desktop\Imptortance\Craagle\Craagle.exe Win32/Sality.NAC virus deleted - quarantined
C:\Documents and Settings\Administrator\Desktop\Imptortance\Extra\Cracked\SWF stuff\Keygen.exe Win32/Sality.NAC virus deleted - quarantined
C:\Documents and Settings\Administrator\Desktop\Imptortance\Extra\Gaia Hax\Injector.exe Win32/Sality.NAC virus deleted - quarantined
C:\Documents and Settings\Administrator\Desktop\Imptortance\Extra\Gaia Hax\MySQL Injection.Rar.rar Win32/Sality.NAC virus deleted - quarantined
C:\Documents and Settings\Administrator\Desktop\Imptortance\Extra\Hacks\Craagle.exe Win32/Sality.NAC virus deleted - quarantined
C:\Documents and Settings\Administrator\Desktop\Imptortance\Extra\Hacks\rsclient.exe Win32/Sality.NAC virus deleted - quarantined
C:\Documents and Settings\Administrator\Desktop\Imptortance\Extra\Hacks\WPE PRO.exe Win32/Sality.NAC virus deleted - quarantined
C:\Documents and Settings\Administrator\Desktop\Imptortance\Extra\Hacks\WpeSpy.dll Win32/Sniffer.WpePro.B trojan cleaned by deleting - quarantined
C:\Documents and Settings\Administrator\Desktop\Imptortance\Extra\LineTools\gimp_9281.exe Win32/Sality.NAC virus deleted - quarantined
C:\Documents and Settings\Administrator\Desktop\Imptortance\Extra\LineTools\pjtCircleMaker.exe Win32/Sality.NAC virus deleted - quarantined
C:\Documents and Settings\Administrator\Desktop\Imptortance\Extra\LineTools\PowerMenu.exe Win32/Sality.NAC virus deleted - quarantined
C:\Documents and Settings\Administrator\Desktop\Imptortance\Spacja FastAero_1.4\FastAero.exe Win32/Sality.NAC virus deleted - quarantined
C:\Documents and Settings\Administrator\Desktop\Imptortance\xSyR1Ng3x Final Build\CA BGM Editor.exe Win32/Sality.NAC virus deleted - quarantined
C:\Documents and Settings\Administrator\Desktop\Imptortance\xSyR1Ng3x Final Build\Catalyst CA Cracked.exe Win32/Sality.NAC virus deleted - quarantined
C:\Documents and Settings\Administrator\Desktop\Imptortance\xSyR1Ng3x Final Build\FInject.exe Win32/Sality.NAC virus deleted - quarantined
C:\Documents and Settings\Administrator\Desktop\Imptortance\xSyR1Ng3x Final Build\WH.dll probably a variant of Win32/IRCBot trojan cleaned by deleting - quarantined
C:\Documents and Settings\Administrator\Desktop\Imptortance\xSyR1Ng3x Final Build\xSyR1Ng3x.exe Win32/Sality.NAC virus deleted - quarantined
C:\Documents and Settings\Administrator\Desktop\Imptortance\xSyR1Ng3x Final Build\CA-Wallhack\WH.dll probably a variant of Win32/IRCBot trojan cleaned by deleting - quarantined
C:\Documents and Settings\Administrator\Desktop\Imptortance\xSyR1Ng3x Final Build\Hack\CA-Wallhack.zip probably a variant of Win32/IRCBot trojan deleted - quarantined
C:\Documents and Settings\Administrator\Local Settings\Application Data\RobloxVersions\version-29d1896c5e90402b\Roblox.exe Win32/Sality.NAC virus deleted - quarantined
C:\Documents and Settings\Administrator\Local Settings\Application Data\RobloxVersions\version-29d1896c5e90402b\RobloxApp.exe Win32/Sality.NAC virus deleted - quarantined
C:\Documents and Settings\Administrator\My Documents\Downloads\Av Voice Changer Software Diamond 4.0.41 Fullll\Vcs4Core.exe Win32/Sality.NAC virus deleted - quarantined
C:\Documents and Settings\All Users\Application Data\NexonUS\NGM\NGM.exe Win32/Sality.NAC virus deleted - quarantined
C:\Fraps\fraps.exe Win32/Sality.NAC virus deleted - quarantined
C:\Nexon\Combat Arms\CAbyBHl33t.exe Win32/Sality.NAC virus deleted - quarantined
C:\Nexon\Combat Arms\Catalyst CA Cracked.exe Win32/Sality.NAC virus deleted - quarantined
C:\Nexon\Combat Arms\CombatArms.exe Win32/Sality.NAC virus deleted - quarantined
C:\Nexon\Combat Arms\CombatArms_Direct.exe Win32/Sality.NAC virus deleted - quarantined
C:\Nexon\Combat Arms\FInject.exe Win32/Sality.NAC virus deleted - quarantined
C:\Nexon\Combat Arms\NMService.exe Win32/Sality.NAC virus deleted - quarantined
C:\Nexon\Combat Arms\xSyR1Ng3x.exe Win32/Sality.NAC virus deleted - quarantined
C:\Program Files\7-Zip\7z.exe Win32/Sality.NAC virus deleted - quarantined
C:\Program Files\7-Zip\7zFM.exe Win32/Sality.NAC virus deleted - quarantined
C:\Program Files\7-Zip\7zG.exe Win32/Sality.NAC virus deleted - quarantined
C:\Program Files\Adobe\Adobe Help Viewer\1.0\ahv.exe Win32/Sality.NAC virus deleted - quarantined
C:\Program Files\Analog Devices\Core\smax4pnp.exe Win32/Sality.NAC virus deleted - quarantined
C:\Program Files\Analog Devices\SoundMAX\AEEnable.exe Win32/Sality.NAC virus deleted - quarantined
C:\Program Files\AV Vcs 4.0 DIAMOND\UNWISE.EXE Win32/Sality.NAC virus deleted - quarantined
C:\Program Files\AV Vcs 4.0 DIAMOND\Vcs4Cmd.exe Win32/Sality.NAC virus deleted - quarantined
C:\Program Files\AV Vcs 4.0 DIAMOND\Vcs4Core.exe Win32/Sality.NAC virus deleted - quarantined
C:\Program Files\AV Vcs 4.0 DIAMOND\Vcs4Feedback.exe Win32/Sality.NAC virus deleted - quarantined
C:\Program Files\CamStudio\Player.exe Win32/Sality.NAC virus deleted - quarantined
C:\Program Files\CamStudio\Playplus.exe Win32/Sality.NAC virus deleted - quarantined
C:\Program Files\CamStudio\Producer.exe Win32/Sality.NAC virus deleted - quarantined
C:\Program Files\CamStudio\Recorder.exe Win32/Sality.NAC virus deleted - quarantined
C:\Program Files\CamStudio\uninstall.exe Win32/Sality.NAC virus deleted - quarantined
C:\Program Files\Cheat Engine\ceregreset.exe Win32/Sality.NAC virus deleted - quarantined
C:\Program Files\Cheat Engine\Cheat Engine.exe Win32/Sality.NAC virus deleted - quarantined
C:\Program Files\Cheat Engine\EmptyDLL.exe Win32/Sality.NAC virus deleted - quarantined
C:\Program Files\Cheat Engine\EmptyProcess.exe Win32/Sality.NAC virus deleted - quarantined
C:\Program Files\Cheat Engine\Kernelmoduleunloader.exe Win32/Sality.NAC virus deleted - quarantined
C:\Program Files\Cheat Engine\Systemcallretriever.exe Win32/Sality.NAC virus deleted - quarantined
C:\Program Files\Cheat Engine\systemcallsignal.exe Win32/Sality.NAC virus deleted - quarantined
C:\Program Files\Cheat Engine\Tutorial.exe Win32/Sality.NAC virus deleted - quarantined
C:\Program Files\Common Files\Nero\Uninstall\Setupx.exe Win32/Sality.NAC virus deleted - quarantined
C:\Program Files\DAEMON Tools Lite\daemon.exe Win32/Sality.NAC virus deleted - quarantined
C:\Program Files\Dell\Chipset Software Installer\Setup.exe Win32/Sality.NAC virus deleted - quarantined
C:\Program Files\Eltima Software\SWF & FLV Player\swf_player.exe Win32/Sality.NAC virus deleted - quarantined
C:\Program Files\Google\Google Earth\client\earthflashsol.exe Win32/Sality.NAC virus deleted - quarantined
C:\Program Files\Google\Google Earth\client\googleearth.exe Win32/Sality.NAC virus deleted - quarantined
C:\Program Files\Google\Google Earth\client\gpsbabel.exe Win32/Sality.NAC virus deleted - quarantined
C:\Program Files\Google\Google Earth\plugin\geplugin.exe Win32/Sality.NAC virus deleted - quarantined
C:\Program Files\HWiNFO32\HW32inst.EXE Win32/Sality.NAC virus deleted - quarantined
C:\Program Files\Image-Line\Downloader\ILDownloadManager.exe Win32/Sality.NAC virus deleted - quarantined
C:\Program Files\Image-Line\Downloader\Update\Updater.exe Win32/Sality.NAC virus deleted - quarantined
C:\Program Files\Image-Line\FL Studio 9\FL (extended memory).exe Win32/Sality.NAC virus deleted - quarantined
C:\Program Files\Image-Line\FL Studio 9\Plugins\Fruity\Generators\Chrome\GraphicsTester.exe Win32/Sality.NAC virus deleted - quarantined
C:\Program Files\Image-Line\FL Studio 9\Plugins\Fruity\Generators\Chrome\TunnelProfiler.exe Win32/Sality.NAC virus deleted - quarantined
C:\Program Files\Image-Line\Hardcore\Hardcore.exe Win32/Sality.NAC virus deleted - quarantined
C:\Program Files\Image-Line\Sawer\Sawer.exe Win32/Sality.NAC virus deleted - quarantined
C:\Program Files\Internet Explorer\ExtExport.exe Win32/Sality.NAC virus deleted - quarantined
C:\Program Files\K-Lite Codec Pack\Filters\ac3config.exe Win32/Sality.NAC virus deleted - quarantined
C:\Program Files\K-Lite Codec Pack\Filters\Haali\gdsmux.exe Win32/Sality.NAC virus deleted - quarantined
C:\Program Files\K-Lite Codec Pack\Media Player Classic\mplayerc.exe Win32/Sality.NAC virus deleted - quarantined
C:\Program Files\K-Lite Codec Pack\Tools\dsconfig.exe Win32/Sality.NAC virus deleted - quarantined
C:\Program Files\K-Lite Codec Pack\Tools\graphedit.exe Win32/Sality.NAC virus deleted - quarantined
C:\Program Files\K-Lite Codec Pack\Tools\mediainfo.exe Win32/Sality.NAC virus deleted - quarantined
C:\Program Files\K-Lite Codec Pack\Tools\StatsReader.exe Win32/Sality.NAC virus deleted - quarantined
C:\Program Files\K-Lite Codec Pack\Tools\VobSubStrip.exe Win32/Sality.NAC virus deleted - quarantined
C:\Program Files\K-Lite Codec Pack\Tools\gspot\gspot.exe Win32/Sality.NAC virus deleted - quarantined
C:\Program Files\Messenger\msmsgs.backup Win32/Sality.NAC virus deleted - quarantined
C:\Program Files\Messenger\msmsgs.exe Win32/Sality.NAC virus deleted - quarantined
C:\Program Files\Microsoft Windows 7 Upgrade Advisor\WindowsUpgradeAdvisor.exe Win32/Sality.NAC virus deleted - quarantined
C:\Program Files\MSN\MSNCoreFiles\Install\msnsusii.exe Win32/Sality.NAC virus deleted - quarantined
C:\Program Files\NeffyManSp\uninst.exe Win32/Sality.NAC virus deleted - quarantined
C:\Program Files\Project64 1.6\Project64.exe Win32/Sality.NAC virus deleted - quarantined
C:\Program Files\Rockstar Games\GTA San Andreas\gta_sa.exe Win32/Sality.NAC virus deleted - quarantined
C:\Program Files\Rockstar Games\GTA San Andreas\rcon.exe Win32/Sality.NAC virus deleted - quarantined
C:\Program Files\Rockstar Games\GTA San Andreas\samp.exe Win32/Sality.NAC virus deleted - quarantined
C:\Program Files\Rockstar Games\GTA San Andreas\samp_debug.exe Win32/Sality.NAC virus deleted - quarantined
C:\Program Files\Skype\Plugin Manager\skypePM.exe Win32/Sality.NAC virus deleted - quarantined
C:\Program Files\Spybot - Search & Destroy\BOPFJZPEVZYQIIAWJL.scr Win32/Sality.NAC virus deleted - quarantined
C:\Program Files\Spybot - Search & Destroy\LOLR.exe Win32/Sality.NAC virus deleted - quarantined
C:\Program Files\Spybot - Search & Destroy\spyfiles.exe Win32/Sality.NAC virus deleted - quarantined
C:\Program Files\Spybot - Search & Destroy\spyshred.exe Win32/Sality.NAC virus deleted - quarantined
C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe Win32/Sality.NAC virus deleted - quarantined
C:\Program Files\TeamViewer\Version5\install.exe Win32/Sality.NAC virus deleted - quarantined
C:\Program Files\TianCity\PopKart\M01\AdBalloonExt.exe Win32/Sality.NAC virus deleted - quarantined
C:\Program Files\TianCity\PopKart\M01\KartRecovery.exe Win32/Sality.NAC virus deleted - quarantined
C:\Program Files\TianCity\PopKart\M01\Patcher.exe Win32/Sality.NAC virus deleted - quarantined
C:\Program Files\Ventrilo\Ventrilo.exe Win32/Sality.NAC virus deleted - quarantined
C:\Program Files\Windows Desktop Search\WindowsSearch.exe Win32/Sality.NAC virus deleted - quarantined
C:\Program Files\Windows Live\Writer\WindowsLiveWriter.exe Win32/Sality.NAC virus deleted - quarantined
C:\Program Files\Windows Media Connect 2\wmccds.exe Win32/Sality.NAC virus deleted - quarantined
C:\Program Files\Windows Media Connect 2\WMCCFG.exe Win32/Sality.NAC virus deleted - quarantined
C:\Program Files\Windows Media Player\wmdbexport.exe Win32/Sality.NAC virus deleted - quarantined
C:\Program Files\Windows Media Player\wmlaunch.exe Win32/Sality.NAC virus deleted - quarantined
C:\Program Files\Windows Media Player\wmpenc.exe Win32/Sality.NAC virus deleted - quarantined
C:\Program Files\Windows Media Player\wmpnetwk.exe Win32/Sality.NAC virus deleted - quarantined
C:\Program Files\Windows Media Player\wmpnscfg.exe Win32/Sality.NAC virus deleted - quarantined
C:\Program Files\Windows Media Player\wmpshare.exe Win32/Sality.NAC virus deleted - quarantined
C:\Program Files\Windows Media Player\wmsetsdk.exe Win32/Sality.NAC virus deleted - quarantined
C:\Program Files\Windows NT\hypertrm.backup Win32/Sality.NAC virus deleted - quarantined
C:\Program Files\Windows NT\hypertrm.exe Win32/Sality.NAC virus deleted - quarantined
C:\Program Files\Xfire\xfencoder.exe Win32/Sality.NAC virus deleted - quarantined
C:\Program Files\Yahoo!\Messenger\UNWISE.EXE Win32/Sality.NAC virus deleted - quarantined
C:\WINDOWS\grep.exe Win32/Sality.NAC virus deleted - quarantined
C:\WINDOWS\MBR.exe Win32/Sality.NAC virus deleted - quarantined
C:\WINDOWS\NIRCMD.exe Win32/Sality.NAC virus deleted - quarantined
C:\WINDOWS\PEV.exe Win32/Sality.NAC virus deleted - quarantined
C:\WINDOWS\sed.exe Win32/Sality.NAC virus deleted - quarantined
C:\WINDOWS\SWREG.exe Win32/Sality.NAC virus deleted - quarantined
C:\WINDOWS\SWSC.exe Win32/Sality.NAC virus deleted - quarantined
C:\WINDOWS\SWXCACLS.exe Win32/Sality.NAC virus deleted - quarantined
C:\WINDOWS\zip.exe Win32/Sality.NAC virus deleted - quarantined
C:\WINDOWS\$hf_mig$\KB873339\spuninst.exe Win32/Sality.NAC virus deleted - quarantined
C:\WINDOWS\$hf_mig$\KB873339\update\update.exe Win32/Sality.NAC virus deleted - quarantined
C:\WINDOWS\$hf_mig$\KB885835\spuninst.exe Win32/Sality.NAC virus deleted - quarantined
C:\WINDOWS\$hf_mig$\KB885835\update\update.exe Win32/Sality.NAC virus deleted - quarantined
C:\WINDOWS\$hf_mig$\KB885836\spuninst.exe Win32/Sality.NAC virus deleted - quarantined
C:\WINDOWS\$hf_mig$\KB885836\update\update.exe Win32/Sality.NAC virus deleted - quarantined
C:\WINDOWS\$hf_mig$\KB886185\spuninst.exe Win32/Sality.NAC virus deleted - quarantined
C:\WINDOWS\$hf_mig$\KB886185\update\update.exe Win32/Sality.NAC virus deleted - quarantined
C:\WINDOWS\$hf_mig$\KB887472\spuninst.exe Win32/Sality.NAC virus deleted - quarantined
C:\WINDOWS\$hf_mig$\KB887472\SP2QFE\msmsgs.exe Win32/Sality.NAC virus deleted - quarantined
C:\WINDOWS\$hf_mig$\KB887472\update\update.exe Win32/Sality.NAC virus deleted - quarantined
C:\WINDOWS\$hf_mig$\KB888302\spuninst.exe Win32/Sality.NAC virus deleted - quarantined
C:\WINDOWS\$hf_mig$\KB888302\update\update.exe Win32/Sality.NAC virus deleted - quarantined
C:\WINDOWS\$hf_mig$\KB890859\SP2QFE\ntkrnlmp.exe Win32/Sality.NAC virus deleted - quarantined
C:\WINDOWS\$hf_mig$\KB890859\SP2QFE\ntkrnlpa.exe Win32/Sality.NAC virus deleted - quarantined
C:\WINDOWS\$hf_mig$\KB890859\SP2QFE\ntkrpamp.exe Win32/Sality.NAC virus deleted - quarantined
C:\WINDOWS\$hf_mig$\KB890859\SP2QFE\ntoskrnl.exe Win32/Sality.NAC virus deleted - quarantined
C:\WINDOWS\$hf_mig$\KB891781\spuninst.exe Win32/Sality.NAC virus deleted - quarantined
C:\WINDOWS\$hf_mig$\KB891781\update\update.exe Win32/Sality.NAC virus deleted - quarantined
C:\WINDOWS\$hf_mig$\KB893756\update\arpidfix.exe Win32/Sality.NAC virus deleted - quarantined
C:\WINDOWS\$hf_mig$\KB896358\SP2QFE\hh.exe Win32/Sality.NAC virus deleted - quarantined
C:\WINDOWS\$hf_mig$\KB896423\SP2QFE\spoolsv.exe Win32/Sality.NAC virus deleted - quarantined
C:\WINDOWS\$hf_mig$\KB896423\update\arpidfix.exe Win32/Sality.NAC virus deleted - quarantined
C:\WINDOWS\$hf_mig$\KB896424\update\arpidfix.exe Win32/Sality.NAC virus deleted - quarantined
C:\WINDOWS\$hf_mig$\KB896428\SP2QFE\telnet.exe Win32/Sality.NAC virus deleted - quarantined
C:\WINDOWS\$hf_mig$\KB899587\update\arpidfix.exe Win32/Sality.NAC virus deleted - quarantined
C:\WINDOWS\$hf_mig$\KB899591\update\arpidfix.exe Win32/Sality.NAC virus deleted - quarantined
C:\WINDOWS\$hf_mig$\KB900725\update\arpidfix.exe Win32/Sality.NAC virus deleted - quarantined
C:\WINDOWS\$hf_mig$\KB901017\update\arpidfix.exe Win32/Sality.NAC virus deleted - quarantined
C:\WINDOWS\$hf_mig$\KB902400\SP2QFE\migregdb.exe Win32/Sality.NAC virus deleted - quarantined
C:\WINDOWS\$hf_mig$\KB902400\update\arpidfix.exe Win32/Sality.NAC virus deleted - quarantined
C:\WINDOWS\$hf_mig$\KB905414\update\arpidfix.exe Win32/Sality.NAC virus deleted - quarantined
C:\WINDOWS\$hf_mig$\KB905749\update\arpidfix.exe Win32/Sality.NAC virus deleted - quarantined
C:\WINDOWS\$hf_mig$\KB908531\SP2QFE\verclsid.exe Win32/Sality.NAC virus deleted - quarantined
C:\WINDOWS\$hf_mig$\KB920213\SP2QFE\agentsvr.exe Win32/Sality.NAC virus deleted - quarantined
C:\WINDOWS\$hf_mig$\KB922582\SP2QFE\fltmc.exe Win32/Sality.NAC virus deleted - quarantined
C:\WINDOWS\$hf_mig$\KB923561\SP3QFE\wordpad.exe Win32/Sality.NAC virus deleted - quarantined
C:\WINDOWS\$hf_mig$\KB925454\SP2QFE\iedw.exe Win32/Sality.NAC virus deleted - quarantined
C:\WINDOWS\$hf_mig$\KB926141\PSSetupNativeUtils.exe Win32/Sality.NAC virus deleted - quarantined
C:\WINDOWS\$hf_mig$\KB951072-v2\SP3QFE\tzchange.exe Win32/Sality.NAC virus deleted - quarantined
C:\WINDOWS\$hf_mig$\KB951978\SP3QFE\cscript.exe Win32/Sality.NAC virus deleted - quarantined
C:\WINDOWS\$hf_mig$\KB951978\SP3QFE\wscript.exe Win32/Sality.NAC virus deleted - quarantined
C:\WINDOWS\$hf_mig$\KB953838-IE7\SP2QFE\ie4uinit.exe Win32/Sality.NAC virus deleted - quarantined
C:\WINDOWS\$hf_mig$\KB953838-IE7\SP2QFE\ieudinit.exe Win32/Sality.NAC virus deleted - quarantined
C:\WINDOWS\$hf_mig$\KB953838-IE7\SP2QFE\iexplore.exe Win32/Sality.NAC virus deleted - quarantined
C:\WINDOWS\$hf_mig$\KB955839\SP3QFE\tzchange.exe Win32/Sality.NAC virus deleted - quarantined
C:\WINDOWS\$hf_mig$\KB956572\SP3QFE\ntkrnlmp.exe Win32/Sality.NAC virus deleted - quarantined
C:\WINDOWS\$hf_mig$\KB956572\SP3QFE\ntkrnlpa.exe Win32/Sality.NAC virus deleted - quarantined
C:\WINDOWS\$hf_mig$\KB956572\SP3QFE\ntkrpamp.exe Win32/Sality.NAC virus deleted - quarantined
C:\WINDOWS\$hf_mig$\KB956572\SP3QFE\ntoskrnl.exe Win32/Sality.NAC virus deleted - quarantined
C:\WINDOWS\$hf_mig$\KB956572\SP3QFE\sc.exe Win32/Sality.NAC virus deleted - quarantined
C:\WINDOWS\$hf_mig$\KB956572\SP3QFE\services.exe Win32/Sality.NAC virus deleted - quarantined
C:\WINDOWS\$hf_mig$\KB956572\SP3QFE\wmiprvse.exe Win32/Sality.NAC virus deleted - quarantined
C:\WINDOWS\$hf_mig$\KB956841\SP3QFE\ntkrnlmp.exe Win32/Sality.NAC virus deleted - quarantined
C:\WINDOWS\$hf_mig$\KB956841\SP3QFE\ntkrnlpa.exe Win32/Sality.NAC virus deleted - quarantined
C:\WINDOWS\$hf_mig$\KB956841\SP3QFE\ntkrpamp.exe Win32/Sality.NAC virus deleted - quarantined
C:\WINDOWS\$hf_mig$\KB956841\SP3QFE\ntoskrnl.exe Win32/Sality.NAC virus deleted - quarantined
C:\WINDOWS\$hf_mig$\KB960859\SP3QFE\telnet.exe Win32/Sality.NAC virus deleted - quarantined
C:\WINDOWS\$hf_mig$\KB960859\SP3QFE\tlntsess.exe Win32/Sality.NAC virus deleted - quarantined
C:\WINDOWS\$hf_mig$\KB969897-IE7\SP3QFE\ie4uinit.exe Win32/Sality.NAC virus deleted - quarantined
C:\WINDOWS\$hf_mig$\KB969897-IE7\SP3QFE\ieudinit.exe Win32/Sality.NAC virus deleted - quarantined
C:\WINDOWS\$hf_mig$\KB969897-IE8\SP3QFE\ie4uinit.exe Win32/Sality.NAC virus deleted - quarantined
C:\WINDOWS\$hf_mig$\KB971486\SP3QFE\ntkrnlmp.exe Win32/Sality.NAC virus deleted - quarantined
C:\WINDOWS\$hf_mig$\KB971486\SP3QFE\ntkrnlpa.exe Win32/Sality.NAC virus deleted - quarantined
C:\WINDOWS\$hf_mig$\KB971486\SP3QFE\ntkrpamp.exe Win32/Sality.NAC virus deleted - quarantined
C:\WINDOWS\$hf_mig$\KB971486\SP3QFE\ntoskrnl.exe Win32/Sality.NAC virus deleted - quarantined
C:\WINDOWS\$hf_mig$\KB972260-IE8\SP3QFE\ie4uinit.exe Win32/Sality.NAC virus deleted - quarantined
C:\WINDOWS\$hf_mig$\KB974455-IE8\SP3QFE\ie4uinit.exe Win32/Sality.NAC virus deleted - quarantined
C:\WINDOWS\$hf_mig$\KB976325-IE8\SP3QFE\ie4uinit.exe Win32/Sality.NAC virus deleted - quarantined
C:\WINDOWS\$NtServicePackUninstall$\accwiz.exe Win32/Sality.NAC virus deleted - quarantined
C:\WINDOWS\$NtServicePackUninstall$\admin.exe Win32/Sality.NAC virus deleted - quarantined
C:\WINDOWS\$NtServicePackUninstall$\agentsvr.exe Win32/Sality.NAC virus deleted - quarantined
C:\WINDOWS\$NtServicePackUninstall$\ahui.exe Win32/Sality.NAC virus deleted - quarantined
C:\WINDOWS\$NtServicePackUninstall$\alg.exe Win32/Sality.NAC virus deleted - quarantined
C:\WINDOWS\$NtServicePackUninstall$\asr_fmt.exe Win32/Sality.NAC virus deleted - quarantined
C:\WINDOWS\$NtServicePackUninstall$\asr_pfu.exe Win32/Sality.NAC virus deleted - quarantined
C:\WINDOWS\$NtServicePackUninstall$\at.exe Win32/Sality.NAC virus deleted - quarantined
C:\WINDOWS\$NtServicePackUninstall$\atmadm.exe Win32/Sality.NAC virus deleted - quarantined
C:\WINDOWS\$NtServicePackUninstall$\attrib.exe Win32/Sality.NAC virus deleted - quarantined
C:\WINDOWS\$NtServicePackUninstall$\auditusr.exe Win32/Sality.NAC virus deleted - quarantined
C:\WINDOWS\$NtServicePackUninstall$\author.exe Win32/Sality.NAC virus deleted - quarantined
C:\WINDOWS\$NtServicePackUninstall$\autochk.exe Win32/Sality.NAC virus deleted - quarantined
C:\WINDOWS\$NtServicePackUninstall$\autoconv.exe Win32/Sality.NAC virus deleted - quarantined
C:\WINDOWS\$NtServicePackUninstall$\autofmt.exe Win32/Sality.NAC virus deleted - quarantined
C:\WINDOWS\$NtServicePackUninstall$\autolfn.exe Win32/Sality.NAC virus deleted - quarantined
C:\WINDOWS\$NtServicePackUninstall$\blastcln.exe Win32/Sality.NAC virus deleted - quarantined
C:\WINDOWS\$NtServicePackUninstall$\bootcfg.exe Win32/Sality.NAC virus deleted - quarantined
C:\WINDOWS\$NtServicePackUninstall$\cacls.exe Win32/Sality.NAC virus deleted - quarantined
C:\WINDOWS\$NtServicePackUninstall$\cfgwiz.exe Win32/Sality.NAC virus deleted - quarantined
C:\WINDOWS\$NtServicePackUninstall$\cipher.exe Win32/Sality.NAC virus deleted - quarantined
C:\WINDOWS\$NtServicePackUninstall$\cisvc.exe Win32/Sality.NAC virus deleted - quarantined
C:\WINDOWS\$NtServicePackUninstall$\cliconfg.exe Win32/Sality.NAC virus deleted - quarantined
C:\WINDOWS\$NtServicePackUninstall$\clipbrd.exe Win32/Sality.NAC virus deleted - quarantined
C:\WINDOWS\$NtServicePackUninstall$\clipsrv.exe Win32/Sality.NAC virus deleted - quarantined
C:\WINDOWS\$NtServicePackUninstall$\cmd.exe Win32/Sality.NAC virus deleted - quarantined
C:\WINDOWS\$NtServicePackUninstall$\cmdl32.exe Win32/Sality.NAC virus deleted - quarantined
C:\WINDOWS\$NtServicePackUninstall$\cmmon32.exe Win32/Sality.NAC virus deleted - quarantined
C:\WINDOWS\$NtServicePackUninstall$\cmstp.exe Win32/Sality.NAC virus deleted - quarantined
C:\WINDOWS\$NtServicePackUninstall$\comrepl.exe Win32/Sality.NAC virus deleted - quarantined
C:\WINDOWS\$NtServicePackUninstall$\comrereg.exe Win32/Sality.NAC virus deleted - quarantined
C:\WINDOWS\$NtServicePackUninstall$\conf.exe Win32/Sality.NAC virus deleted - quarantined
C:\WINDOWS\$NtServicePackUninstall$\conime.exe Win32/Sality.NAC virus deleted - quarantined
C:\WINDOWS\$NtServicePackUninstall$\cscript.exe Win32/Sality.NAC virus deleted - quarantined
C:\WINDOWS\$NtServicePackUninstall$\csrss.exe Win32/Sality.NAC virus deleted - quarantined
C:\WINDOWS\$NtServicePackUninstall$\ctfmon.exe Win32/Sality.NAC virus deleted - quarantined
C:\WINDOWS\$NtServicePackUninstall$\davcdata.exe Win32/Sality.NAC virus deleted - quarantined
C:\WINDOWS\$NtServicePackUninstall$\dcomcnfg.exe Win32/Sality.NAC virus deleted - quarantined
C:\WINDOWS\$NtServicePackUninstall$\ddeshare.exe Win32/Sality.NAC virus deleted - quarantined
C:\WINDOWS\$NtServicePackUninstall$\defrag.exe Win32/Sality.NAC virus deleted - quarantined
C:\WINDOWS\$NtServicePackUninstall$\dfrgfat.exe Win32/Sality.NAC virus deleted - quarantined
C:\WINDOWS\$NtServicePackUninstall$\dfrgntfs.exe Win32/Sality.NAC virus deleted - quarantined
C:\WINDOWS\$NtServicePackUninstall$\diantz.exe Win32/Sality.NAC virus deleted - quarantined
C:\WINDOWS\$NtServicePackUninstall$\diskpart.exe Win32/Sality.NAC virus deleted - quarantined
C:\WINDOWS\$NtServicePackUninstall$\dllhost.exe Win32/Sality.NAC virus deleted - quarantined
C:\WINDOWS\$NtServicePackUninstall$\dmadmin.exe Win32/Sality.NAC virus deleted - quarantined
C:\WINDOWS\$NtServicePackUninstall$\dmremote.exe Win32/Sality.NAC virus deleted - quarantined
C:\WINDOWS\$NtServicePackUninstall$\dplaysvr.exe Win32/Sality.NAC virus deleted - quarantined
C:\WINDOWS\$NtServicePackUninstall$\dpnsvr.exe Win32/Sality.NAC virus deleted - quarantined
C:\WINDOWS\$NtServicePackUninstall$\dpvsetup.exe Win32/Sality.NAC virus deleted - quarantined
C:\WINDOWS\$NtServicePackUninstall$\driverquery.exe Win32/Sality.NAC virus deleted - quarantined
C:\WINDOWS\$NtServicePackUninstall$\drvqry.exe Win32/Sality.NAC virus deleted - quarantined
C:\WINDOWS\$NtServicePackUninstall$\dumprep.exe Win32/Sality.NAC virus deleted - quarantined
C:\WINDOWS\$NtServicePackUninstall$\dvdupgrd.exe Win32/Sality.NAC virus deleted - quarantined
C:\WINDOWS\$NtServicePackUninstall$\dwwin.exe Win32/Sality.NAC virus deleted - quarantined
C:\WINDOWS\$NtServicePackUninstall$\dxdiag.exe Win32/Sality.NAC virus deleted - quarantined
C:\WINDOWS\$NtServicePackUninstall$\eudcedit.exe Win32/Sality.NAC virus deleted - quarantined
C:\WINDOWS\$NtServicePackUninstall$\evcreate.exe Win32/Sality.NAC virus deleted - quarantined
C:\WINDOWS\$NtServicePackUninstall$\eventcreate.exe Win32/Sality.NAC virus deleted - quarantined
C:\WINDOWS\$NtServicePackUninstall$\eventtriggers.exe Win32/Sality.NAC virus deleted - quarantined
C:\WINDOWS\$NtServicePackUninstall$\evntcmd.exe Win32/Sality.NAC virus deleted - quarantined
C:\WINDOWS\$NtServicePackUninstall$\evntwin.exe Win32/Sality.NAC virus deleted - quarantined
C:\WINDOWS\$NtServicePackUninstall$\evtrig.exe Win32/Sality.NAC virus deleted - quarantined
C:\WINDOWS\$NtServicePackUninstall$\explorer.exe Win32/Sality.NAC virus deleted - quarantined
C:\WINDOWS\$NtServicePackUninstall$\extrac32.exe Win32/Sality.NAC virus deleted - quarantined
C:\WINDOWS\$NtServicePackUninstall$\findstr.exe Win32/Sality.NAC virus deleted - quarantined
C:\WINDOWS\$NtServicePackUninstall$\fltmc.exe Win32/Sality.NAC virus deleted - quarantined
C:\WINDOWS\$NtServicePackUninstall$\fontview.exe Win32/Sality.NAC virus deleted - quarantined
C:\WINDOWS\$NtServicePackUninstall$\forcedos.exe Win32/Sality.NAC virus deleted - quarantined
C:\WINDOWS\$NtServicePackUninstall$\fpadmcgi.exe Win32/Sality.NAC virus deleted - quarantined
C:\WINDOWS\$NtServicePackUninstall$\fpcount.exe Win32/Sality.NAC virus deleted - quarantined
C:\WINDOWS\$NtServicePackUninstall$\fpremadm.exe Win32/Sality.NAC virus deleted - quarantined
C:\WINDOWS\$NtServicePackUninstall$\fsquirt.exe Win32/Sality.NAC virus deleted - quarantined
C:\WINDOWS\$NtServicePackUninstall$\ftp.exe Win32/Sality.NAC virus deleted - quarantined
C:\WINDOWS\$NtServicePackUninstall$\fxsclnt.exe Win32/Sality.NAC virus deleted - quarantined
C:\WINDOWS\$NtServicePackUninstall$\fxscover.exe Win32/Sality.NAC virus deleted - quarantined
C:\WINDOWS\$NtServicePackUninstall$\getmac.exe Win32/Sality.NAC virus deleted - quarantined
C:\WINDOWS\$NtServicePackUninstall$\gpresult.exe Win32/Sality.NAC virus deleted - quarantined
C:\WINDOWS\$NtServicePackUninstall$\gprslt.exe Win32/Sality.NAC virus deleted - quarantined
C:\WINDOWS\$NtServicePackUninstall$\grpconv.exe Win32/Sality.NAC virus deleted - quarantined
C:\WINDOWS\$NtServicePackUninstall$\help.exe Win32/Sality.NAC virus deleted - quarantined
C:\WINDOWS\$NtServicePackUninstall$\helpctr.exe Win32/Sality.NAC virus deleted - quarantined
C:\WINDOWS\$NtServicePackUninstall$\helpsvc.exe Win32/Sality.NAC virus deleted - quarantined
C:\WINDOWS\$NtServicePackUninstall$\hh.exe Win32/Sality.NAC virus deleted - quarantined
C:\WINDOWS\$NtServicePackUninstall$\hscupd.exe Win32/Sality.NAC virus deleted - quarantined
C:\WINDOWS\$NtServicePackUninstall$\icwconn1.exe Win32/Sality.NAC virus deleted - quarantined
C:\WINDOWS\$NtServicePackUninstall$\icwconn2.exe Win32/Sality.NAC virus deleted - quarantined
C:\WINDOWS\$NtServicePackUninstall$\icwrmind.exe Win32/Sality.NAC virus deleted - quarantined
C:\WINDOWS\$NtServicePackUninstall$\iexpress.exe Win32/Sality.NAC virus deleted - quarantined
C:\WINDOWS\$NtServicePackUninstall$\iisrstas.exe Win32/Sality.NAC virus deleted - quarantined
C:\WINDOWS\$NtServicePackUninstall$\imapi.exe Win32/Sality.NAC virus deleted - quarantined
C:\WINDOWS\$NtServicePackUninstall$\inetin51.exe Win32/Sality.NAC virus deleted - quarantined
C:\WINDOWS\$NtServicePackUninstall$\inetwiz.exe Win32/Sality.NAC virus deleted - quarantined
C:\WINDOWS\$NtServicePackUninstall$\ipconfig.exe Win32/Sality.NAC virus deleted - quarantined
C:\WINDOWS\$NtServicePackUninstall$\ipv6.exe Win32/Sality.NAC virus deleted - quarantined
C:\WINDOWS\$NtServicePackUninstall$\ipxroute.exe Win32/Sality.NAC virus deleted - quarantined
C:\WINDOWS\$NtServicePackUninstall$\locator.exe Win32/Sality.NAC virus deleted - quarantined
C:\WINDOWS\$NtServicePackUninstall$\logman.exe Win32/Sality.NAC virus deleted - quarantined
C:\WINDOWS\$NtServicePackUninstall$\logon.scr Win32/Sality.NAC virus deleted - quarantined
C:\WINDOWS\$NtServicePackUninstall$\logonui.exe Win32/Sality.NAC virus deleted - quarantined
C:\WINDOWS\$NtServicePackUninstall$\lsass.exe Win32/Sality.NAC virus deleted - quarantined
C:\WINDOWS\$NtServicePackUninstall$\magnify.exe Win32/Sality.NAC virus deleted - quarantined
C:\WINDOWS\$NtServicePackUninstall$\makecab.exe Win32/Sality.NAC virus deleted - quarantined
C:\WINDOWS\$NtServicePackUninstall$\migload.exe Win32/Sality.NAC virus deleted - quarantined
C:\WINDOWS\$NtServicePackUninstall$\migregdb.exe Win32/Sality.NAC virus deleted - quarantined
C:\WINDOWS\$NtServicePackUninstall$\migwiz.exe Win32/Sality.NAC virus deleted - quarantined
C:\WINDOWS\$NtServicePackUninstall$\mmc.exe Win32/Sality.NAC virus deleted - quarantined
C:\WINDOWS\$NtServicePackUninstall$\mnmsrvc.exe Win32/Sality.NAC virus deleted - quarantined
C:\WINDOWS\$NtServicePackUninstall$\mobsync.exe Win32/Sality.NAC virus deleted - quarantined
C:\WINDOWS\$NtServicePackUninstall$\mofcomp.exe Win32/Sality.NAC virus deleted - quarantined
C:\WINDOWS\$NtServicePackUninstall$\moviemk.exe Win32/Sality.NAC virus deleted - quarantined
C:\WINDOWS\$NtServicePackUninstall$\mplay32.exe Win32/Sality.NAC virus deleted - quarantined
C:\WINDOWS\$NtServicePackUninstall$\mplayer2.exe Win32/Sality.NAC virus deleted - quarantined
C:\WINDOWS\$NtServicePackUninstall$\mqbkup.exe Win32/Sality.NAC virus deleted - quarantined
C:\WINDOWS\$NtServicePackUninstall$\mqsvc.exe Win32/Sality.NAC virus deleted - quarantined
C:\WINDOWS\$NtServicePackUninstall$\mqtgsvc.exe Win32/Sality.NAC virus deleted - quarantined
C:\WINDOWS\$NtServicePackUninstall$\msconfig.exe Win32/Sality.NAC virus deleted - quarantined
C:\WINDOWS\$NtServicePackUninstall$\msdtc.exe Win32/Sality.NAC virus deleted - quarantined
C:\WINDOWS\$NtServicePackUninstall$\msiexec.exe Win32/Sality.NAC virus deleted - quarantined
C:\WINDOWS\$NtServicePackUninstall$\msimn.exe Win32/Sality.NAC virus deleted - quarantined
C:\WINDOWS\$NtServicePackUninstall$\msiregmv.exe Win32/Sality.NAC virus deleted - quarantined
C:\WINDOWS\$NtServicePackUninstall$\msmsgs.exe Win32/Sality.NAC virus deleted - quarantined
C:\WINDOWS\$NtServicePackUninstall$\msoobe.exe Win32/Sality.NAC virus deleted - quarantined
C:\WINDOWS\$NtServicePackUninstall$\mspaint.exe Win32/Sality.NAC virus deleted - quarantined
C:\WINDOWS\$NtServicePackUninstall$\mstinit.exe Win32/Sality.NAC virus deleted - quarantined
C:\WINDOWS\$NtServicePackUninstall$\mstsc.exe Win32/Sality.NAC virus deleted - quarantined
C:\WINDOWS\$NtServicePackUninstall$\mtstocom.exe Win32/Sality.NAC virus deleted - quarantined
C:\WINDOWS\$NtServicePackUninstall$\muisetup.exe Win32/Sality.NAC virus deleted - quarantined
C:\WINDOWS\$NtServicePackUninstall$\narrator.exe Win32/Sality.NAC virus deleted - quarantined
C:\WINDOWS\$NtServicePackUninstall$\net.exe Win32/Sality.NAC virus deleted - quarantined
C:\WINDOWS\$NtServicePackUninstall$\net1.exe Win32/Sality.NAC virus deleted - quarantined
C:\WINDOWS\$NtServicePackUninstall$\netdde.exe Win32/Sality.NAC virus deleted - quarantined
C:\WINDOWS\$NtServicePackUninstall$\netsetup.exe Win32/Sality.NAC virus deleted - quarantined
C:\WINDOWS\$NtServicePackUninstall$\netsh.exe Win32/Sality.NAC virus deleted - quarantined
C:\WINDOWS\$NtServicePackUninstall$\netstat.exe Win32/Sality.NAC virus deleted - quarantined
C:\WINDOWS\$NtServicePackUninstall$\notepad.exe Win32/Sality.NAC virus deleted - quarantined
C:\WINDOWS\$NtServicePackUninstall$\nppagent.exe Win32/Sality.NAC virus deleted - quarantined
C:\WINDOWS\$NtServicePackUninstall$\nslookup.exe Win32/Sality.NAC virus deleted - quarantined
C:\WINDOWS\$NtServicePackUninstall$\ntbackup.exe Win32/Sality.NAC virus deleted - quarantined
C:\WINDOWS\$NtServicePackUninstall$\ntkrnlmp.exe Win32/Sality.NAC virus deleted - quarantined
C:\WINDOWS\$NtServicePackUninstall$\ntkrnlpa.exe Win32/Sality.NAC virus deleted - quarantined
C:\WINDOWS\$NtServicePackUninstall$\ntkrpamp.exe Win32/Sality.NAC virus deleted - quarantined
C:\WINDOWS\$NtServicePackUninstall$\ntoskrnl.exe Win32/Sality.NAC virus deleted - quarantined
C:\WINDOWS\$NtServicePackUninstall$\ntvdm.exe Win32/Sality.NAC virus deleted - quarantined
C:\WINDOWS\$NtServicePackUninstall$\odbcad32.exe Win32/Sality.NAC virus deleted - quarantined
C:\WINDOWS\$NtServicePackUninstall$\odbcconf.exe Win32/Sality.NAC virus deleted - quarantined
C:\WINDOWS\$NtServicePackUninstall$\oemig50.exe Win32/Sality.NAC virus deleted - quarantined
C:\WINDOWS\$NtServicePackUninstall$\oobebaln.exe Win32/Sality.NAC virus deleted - quarantined
C:\WINDOWS\$NtServicePackUninstall$\openfiles.exe Win32/Sality.NAC virus deleted - quarantined
C:\WINDOWS\$NtServicePackUninstall$\opnfiles.exe Win32/Sality.NAC virus deleted - quarantined
C:\WINDOWS\$NtServicePackUninstall$\osk.exe Win32/Sality.NAC virus deleted - quarantined
C:\WINDOWS\$NtServicePackUninstall$\packager.exe Win32/Sality.NAC virus deleted - quarantined
C:\WINDOWS\$NtServicePackUninstall$\perfmon.exe Win32/Sality.NAC virus deleted - quarantined
C:\WINDOWS\$NtServicePackUninstall$\pinball.exe Win32/Sality.NAC virus deleted - quarantined
C:\WINDOWS\$NtServicePackUninstall$\ping.exe Win32/Sality.NAC virus deleted - quarantined
C:\WINDOWS\$NtServicePackUninstall$\pintlphr.exe Win32/Sality.NAC virus deleted - quarantined
C:\WINDOWS\$NtServicePackUninstall$\powercfg.exe Win32/Sality.NAC virus deleted - quarantined
C:\WINDOWS\$NtServicePackUninstall$\progman.exe Win32/Sality.NAC virus deleted - quarantined
C:\WINDOWS\$NtServicePackUninstall$\proquota.exe Win32/Sality.NAC virus deleted - quarantined
C:\WINDOWS\$NtServicePackUninstall$\proxycfg.exe Win32/Sality.NAC virus deleted - quarantined
C:\WINDOWS\$NtServicePackUninstall$\qprocess.exe Win32/Sality.NAC virus deleted - quarantined
C:\WINDOWS\$NtServicePackUninstall$\rasphone.exe Win32/Sality.NAC virus deleted - quarantined
C:\WINDOWS\$NtServicePackUninstall$\rcimlby.exe Win32/Sality.NAC virus deleted - quarantined
C:\WINDOWS\$NtServicePackUninstall$\rcp.exe Win32/Sality.NAC virus deleted - quarantined
C:\WINDOWS\$NtServicePackUninstall$\rdpclip.exe Win32/Sality.NAC virus deleted - quarantined
C:\WINDOWS\$NtServicePackUninstall$\rdsaddin.exe Win32/Sality.NAC virus deleted - quarantined
C:\WINDOWS\$NtServicePackUninstall$\rdshost.exe Win32/Sality.NAC virus deleted - quarantined
C:\WINDOWS\$NtServicePackUninstall$\reg.exe Win32/Sality.NAC virus deleted - quarantined
C:\WINDOWS\$NtServicePackUninstall$\regedit.exe Win32/Sality.NAC virus deleted - quarantined
C:\WINDOWS\$NtServicePackUninstall$\regsvr32.exe Win32/Sality.NAC virus deleted - quarantined
C:\WINDOWS\$NtServicePackUninstall$\rexec.exe Win32/Sality.NAC virus deleted - quarantined
C:\WINDOWS\$NtServicePackUninstall$\rsh.exe Win32/Sality.NAC virus deleted - quarantined
C:\WINDOWS\$NtServicePackUninstall$\rsnotify.exe Win32/Sality.NAC virus deleted - quarantined
C:\WINDOWS\$NtServicePackUninstall$\rstrui.exe Win32/Sality.NAC virus deleted - quarantined
C:\WINDOWS\$NtServicePackUninstall$\rtcshare.exe Win32/Sality.NAC virus deleted - quarantined
C:\WINDOWS\$NtServicePackUninstall$\rundll32.exe Win32/Sality.NAC virus deleted - quarantined
C:\WINDOWS\$NtServicePackUninstall$\runonce.exe Win32/Sality.NAC virus deleted - quarantined
C:\WINDOWS\$NtServicePackUninstall$\savedump.exe Win32/Sality.NAC virus deleted - quarantined
C:\WINDOWS\$NtServicePackUninstall$\scardsvr.exe Win32/Sality.NAC virus deleted - quarantined
C:\WINDOWS\$NtServicePackUninstall$\schtasks.exe Win32/Sality.NAC virus deleted - quarantined
C:\WINDOWS\$NtServicePackUninstall$\scrcons.exe Win32/Sality.NAC virus deleted - quarantined
C:\WINDOWS\$NtServicePackUninstall$\scrnsave.scr Win32/Sality.NAC virus deleted - quarantined
C:\WINDOWS\$NtServicePackUninstall$\sctasks.exe Win32/Sality.NAC virus deleted - quarantined
C:\WINDOWS\$NtServicePackUninstall$\sdbinst.exe Win32/Sality.NAC virus deleted - quarantined
C:\WINDOWS\$NtServicePackUninstall$\secedit.exe Win32/Sality.NAC virus deleted - quarantined
C:\WINDOWS\$NtServicePackUninstall$\services.exe Win32/Sality.NAC virus deleted - quarantined
C:\WINDOWS\$NtServicePackUninstall$\sessmgr.exe Win32/Sality.NAC virus deleted - quarantined
C:\WINDOWS\$NtServicePackUninstall$\sethc.exe Win32/Sality.NAC virus deleted - quarantined
C:\WINDOWS\$NtServicePackUninstall$\setup.exe Win32/Sality.NAC virus deleted - quarantined
C:\WINDOWS\$NtServicePackUninstall$\setup50.exe Win32/Sality.NAC virus deleted - quarantined
C:\WINDOWS\$NtServicePackUninstall$\shmgrate.exe Win32/Sality.NAC virus deleted - quarantined
C:\WINDOWS\$NtServicePackUninstall$\shrpubw.exe Win32/Sality.NAC virus deleted - quarantined
C:\WINDOWS\$NtServicePackUninstall$\shtml.exe Win32/Sality.NAC virus deleted - quarantined
C:\WINDOWS\$NtServicePackUninstall$\shutdown.exe Win32/Sality.NAC virus deleted - quarantined
C:\WINDOWS\$NtServicePackUninstall$\sigverif.exe Win32/Sality.NAC virus deleted - quarantined
C:\WINDOWS\$NtServicePackUninstall$\skeys.exe Win32/Sality.NAC virus deleted - quarantined
C:\WINDOWS\$NtServicePackUninstall$\smbinst.exe Win32/Sality.NAC virus deleted - quarantined
C:\WINDOWS\$NtServicePackUninstall$\smi2smir.exe Win32/Sality.NAC virus deleted - quarantined
C:\WINDOWS\$NtServicePackUninstall$\smlogsvc.exe Win32/Sality.NAC virus deleted - quarantined
C:\WINDOWS\$NtServicePackUninstall$\smss.exe Win32/Sality.NAC virus deleted - quarantined
C:\WINDOWS\$NtServicePackUninstall$\sndrec32.exe Win32/Sality.NAC virus deleted - quarantined
C:\WINDOWS\$NtServicePackUninstall$\snmp.exe Win32/Sality.NAC virus deleted - quarantined
C:\WINDOWS\$NtServicePackUninstall$\snmptrap.exe Win32/Sality.NAC virus deleted - quarantined
C:\WINDOWS\$NtServicePackUninstall$\sort.exe Win32/Sality.NAC virus deleted - quarantined
C:\WINDOWS\$NtServicePackUninstall$\spider.exe Win32/Sality.NAC virus deleted - quarantined
C:\WINDOWS\$NtServicePackUninstall$\spiisupd.exe Win32/Sality.NAC virus deleted - quarantined
C:\WINDOWS\$NtServicePackUninstall$\spnpinst.exe Win32/Sality.NAC virus deleted - quarantined
C:\WINDOWS\$NtServicePackUninstall$\spoolsv.exe Win32/Sality.NAC virus deleted - quarantined
C:\WINDOWS\$NtServicePackUninstall$\ss3dfo.scr Win32/Sality.NAC virus deleted - quarantined
C:\WINDOWS\$NtServicePackUninstall$\ssbezier.scr Win32/Sality.NAC virus deleted - quarantined
C:\WINDOWS\$NtServicePackUninstall$\ssflwbox.scr Win32/Sality.NAC virus deleted - quarantined
C:\WINDOWS\$NtServicePackUninstall$\ssmarque.scr Win32/Sality.NAC virus deleted - quarantined
C:\WINDOWS\$NtServicePackUninstall$\ssmypics.scr Win32/Sality.NAC virus deleted - quarantined
C:\WINDOWS\$NtServicePackUninstall$\ssmyst.scr Win32/Sality.NAC virus deleted - quarantined
C:\WINDOWS\$NtServicePackUninstall$\sspipes.scr Win32/Sality.NAC virus deleted - quarantined
C:\WINDOWS\$NtServicePackUninstall$\ssstars.scr Win32/Sality.NAC virus deleted - quarantined
C:\WINDOWS\$NtServicePackUninstall$\sstext3d.scr Win32/Sality.NAC virus deleted - quarantined
C:\WINDOWS\$NtServicePackUninstall$\stimon.exe Win32/Sality.NAC virus deleted - quarantined
C:\WINDOWS\$NtServicePackUninstall$\svchost.exe Win32/Sality.NAC virus deleted - quarantined
C:\WINDOWS\$NtServicePackUninstall$\sysinfo.exe Win32/Sality.NAC virus deleted - quarantined
C:\WINDOWS\$NtServicePackUninstall$\sysocmgr.exe Win32/Sality.NAC virus deleted - quarantined
C:\WINDOWS\$NtServicePackUninstall$\systeminfo.exe Win32/Sality.NAC virus deleted - quarantined
C:\WINDOWS\$NtServicePackUninstall$\taskkill.exe Win32/Sality.NAC virus deleted - quarantined
C:\WINDOWS\$NtServicePackUninstall$\tasklist.exe Win32/Sality.NAC virus deleted - quarantined
C:\WINDOWS\$NtServicePackUninstall$\taskmgr.exe Win32/Sality.NAC virus deleted - quarantined
C:\WINDOWS\$NtServicePackUninstall$\tcptest.exe Win32/Sality.NAC virus deleted - quarantined
C:\WINDOWS\$NtServicePackUninstall$\telnet.exe Win32/Sality.NAC virus deleted - quarantined
C:\WINDOWS\$NtServicePackUninstall$\tlntadmn.exe Win32/Sality.NAC virus deleted - quarantined
C:\WINDOWS\$NtServicePackUninstall$\tlntsess.exe Win32/Sality.NAC virus deleted - quarantined
C:\WINDOWS\$NtServicePackUninstall$\tlntsvr.exe Win32/Sality.NAC virus deleted - quarantined
C:\WINDOWS\$NtServicePackUninstall$\tourstart.exe Win32/Sality.NAC virus deleted - quarantined
C:\WINDOWS\$NtServicePackUninstall$\tourstrt.exe Win32/Sality.NAC virus deleted - quarantined
C:\WINDOWS\$NtServicePackUninstall$\tracerpt.exe Win32/Sality.NAC virus deleted - quarantined
C:\WINDOWS\$NtServicePackUninstall$\tracert.exe Win32/Sality.NAC virus deleted - quarantined
C:\WINDOWS\$NtServicePackUninstall$\uploadm.exe Win32/Sality.NAC virus deleted - quarantined
C:\WINDOWS\$NtServicePackUninstall$\upnpcont.exe Win32/Sality.NAC virus deleted - quarantined
C:\WINDOWS\$NtServicePackUninstall$\ups.exe Win32/Sality.NAC virus deleted - quarantined
C:\WINDOWS\$NtServicePackUninstall$\userinit.exe Win32/Sality.NAC virus deleted - quarantined
C:\WINDOWS\$NtServicePackUninstall$\utilman.exe Win32/Sality.NAC virus deleted - quarantined
C:\WINDOWS\$NtServicePackUninstall$\verclsid.exe Win32/Sality.NAC virus deleted - quarantined
C:\WINDOWS\$NtServicePackUninstall$\vssvc.exe Win32/Sality.NAC virus deleted - quarantined
C:\WINDOWS\$NtServicePackUninstall$\wab.exe Win32/Sality.NAC virus deleted - quarantined
C:\WINDOWS\$NtServicePackUninstall$\wabmig.exe Win32/Sality.NAC virus deleted - quarantined
C:\WINDOWS\$NtServicePackUninstall$\wbemtest.exe Win32/Sality.NAC virus deleted - quarantined
C:\WINDOWS\$NtServicePackUninstall$\wextract.exe Win32/Sality.NAC virus deleted - quarantined
C:\WINDOWS\$NtServicePackUninstall$\wiaacmgr.exe Win32/Sality.NAC virus deleted - quarantined
C:\WINDOWS\$NtServicePackUninstall$\winhlp32.exe Win32/Sality.NAC virus deleted - quarantined
C:\WINDOWS\$NtServicePackUninstall$\winver.exe Win32/Sality.NAC virus deleted - quarantined
C:\WINDOWS\$NtServicePackUninstall$\wmiadap.exe Win32/Sality.NAC virus deleted - quarantined
C:\WINDOWS\$NtServicePackUninstall$\wmiapsrv.exe Win32/Sality.NAC virus deleted - quarantined
C:\WINDOWS\$NtServicePackUninstall$\wmic.exe Win32/Sality.NAC virus deleted - quarantined
C:\WINDOWS\$NtServicePackUninstall$\wmiprvse.exe Win32/Sality.NAC virus deleted - quarantined
C:\WINDOWS\$NtServicePackUninstall$\wordpad.exe Win32/Sality.NAC virus deleted - quarantined
C:\WINDOWS\$NtServicePackUninstall$\wpabaln.exe Win32/Sality.NAC virus deleted - quarantined
C:\WINDOWS\$NtServicePackUninstall$\wpnpinst.exe Win32/Sality.NAC virus deleted - quarantined
C:\WINDOWS\$NtServicePackUninstall$\wscntfy.exe Win32/Sality.NAC virus deleted - quarantined
C:\WINDOWS\$NtServicePackUninstall$\wscript.exe Win32/Sality.NAC virus deleted - quarantined
C:\WINDOWS\$NtServicePackUninstall$\xcopy.exe Win32/Sality.NAC virus deleted - quarantined
C:\WINDOWS\$NtServicePackUninstall$\xpnetdiag.exe Win32/Sality.NAC virus deleted - quarantined
C:\WINDOWS\$NtUninstallWMFDist11$\logagent.exe Win32/Sality.NAC virus deleted - quarantined
C:\WINDOWS\$NtUninstallwmp11$\setup_wm.exe Win32/Sality.NAC virus deleted - quarantined
C:\WINDOWS\$NtUninstallwmp11$\unregmp2.exe Win32/Sality.NAC virus deleted - quarantined
C:\WINDOWS\$NtUninstallwmp11$\wmplayer.exe Win32/Sality.NAC virus deleted - quarantined
C:\WINDOWS\7SP_Files\About.exe Win32/Sality.NAC virus deleted - quarantined
C:\WINDOWS\7SP_Files\accwiz.exe Win32/Sality.NAC virus deleted - quarantined
C:\WINDOWS\7SP_Files\ahui.exe Win32/Sality.NAC virus deleted - quarantined
C:\WINDOWS\7SP_Files\calc.exe Win32/Sality.NAC virus deleted - quarantined
C:\WINDOWS\7SP_Files\charmap.exe Win32/Sality.NAC virus deleted - quarantined
C:\WINDOWS\7SP_Files\cmd.exe Win32/Sality.NAC virus deleted - quarantined
C:\WINDOWS\7SP_Files\explorer.exe Win32/Sality.NAC virus deleted - quarantined
C:\WINDOWS\7SP_Files\freecell.exe Win32/Sality.NAC virus deleted - quarantined
C:\WINDOWS\7SP_Files\fsquirt.exe Win32/Sality.NAC virus deleted - quarantined
C:\WINDOWS\7SP_Files\helpctr.exe Win32/Sality.NAC virus deleted - quarantined
C:\WINDOWS\7SP_Files\hypertrm.exe Win32/Sality.NAC virus deleted - quarantined
C:\WINDOWS\7SP_Files\icwconn1.exe Win32/Sality.NAC virus deleted - quarantined
C:\WINDOWS\7SP_Files\icwconn2.exe Win32/Sality.NAC virus deleted - quarantined
C:\WINDOWS\7SP_Files\iexpress.exe Win32/Sality.NAC virus deleted - quarantined
C:\WINDOWS\7SP_Files\logon.scr Win32/Sality.NAC virus deleted - quarantined
C:\WINDOWS\7SP_Files\logonui.exe Win32/Sality.NAC virus deleted - quarantined
C:\WINDOWS\7SP_Files\magnify.exe Win32/Sality.NAC virus deleted - quarantined
C:\WINDOWS\7SP_Files\migload.exe Win32/Sality.NAC virus deleted - quarantined
C:\WINDOWS\7SP_Files\migpwd.exe Win32/Sality.NAC virus deleted - quarantined
C:\WINDOWS\7SP_Files\migwiz.exe Win32/Sality.NAC virus deleted - quarantined
C:\WINDOWS\7SP_Files\mobsync.exe Win32/Sality.NAC virus deleted - quarantined
C:\WINDOWS\7SP_Files\mshearts.exe Win32/Sality.NAC virus deleted - quarantined
C:\WINDOWS\7SP_Files\msiexec.exe Win32/Sality.NAC virus deleted - quarantined
C:\WINDOWS\7SP_Files\msimn.exe Win32/Sality.NAC virus deleted - quarantined
C:\WINDOWS\7SP_Files\msinfo32.exe Win32/Sality.NAC virus deleted - quarantined
C:\WINDOWS\7SP_Files\msmsgs.exe Win32/Sality.NAC virus deleted - quarantined
C:\WINDOWS\7SP_Files\msoobe.exe Win32/Sality.NAC virus deleted - quarantined
C:\WINDOWS\7SP_Files\mspaint.exe Win32/Sality.NAC virus deleted - quarantined
C:\WINDOWS\7SP_Files\mstsc.exe Win32/Sality.NAC virus deleted - quarantined
C:\WINDOWS\7SP_Files\narrator.exe Win32/Sality.NAC virus deleted - quarantined
C:\WINDOWS\7SP_Files\notepad.exe Win32/Sality.NAC virus deleted - quarantined
C:\WINDOWS\7SP_Files\ntbackup.exe Win32/Sality.NAC virus deleted - quarantined
C:\WINDOWS\7SP_Files\ntoskrnl.exe Win32/Sality.NAC virus deleted - quarantined
C:\WINDOWS\7SP_Files\odbcad32.exe Win32/Sality.NAC virus deleted - quarantined
C:\WINDOWS\7SP_Files\oobebaln.exe Win32/Sality.NAC virus deleted - quarantined
C:\WINDOWS\7SP_Files\osk.exe Win32/Sality.NAC virus deleted - quarantined
C:\WINDOWS\7SP_Files\pinball.exe Win32/Sality.NAC virus deleted - quarantined
C:\WINDOWS\7SP_Files\rcimlby.exe Win32/Sality.NAC virus deleted - quarantined
C:\WINDOWS\7SP_Files\regedit.exe Win32/Sality.NAC virus deleted - quarantined
C:\WINDOWS\7SP_Files\ResHacker.exe Win32/Sality.NAC virus deleted - quarantined
C:\WINDOWS\7SP_Files\rstrui.exe Win32/Sality.NAC virus deleted - quarantined
C:\WINDOWS\7SP_Files\rtcshare.exe Win32/Sality.NAC virus deleted - quarantined
C:\WINDOWS\7SP_Files\shrpubw.exe Win32/Sality.NAC virus deleted - quarantined
C:\WINDOWS\7SP_Files\sigverif.exe Win32/Sality.NAC virus deleted - quarantined
C:\WINDOWS\7SP_Files\sndrec32.exe Win32/Sality.NAC virus deleted - quarantined
C:\WINDOWS\7SP_Files\sndvol32.exe Win32/Sality.NAC virus deleted - quarantined
C:\WINDOWS\7SP_Files\sol.exe Win32/Sality.NAC virus deleted - quarantined
C:\WINDOWS\7SP_Files\spider.exe Win32/Sality.NAC virus deleted - quarantined
C:\WINDOWS\7SP_Files\syncapp.exe Win32/Sality.NAC virus deleted - quarantined
C:\WINDOWS\7SP_Files\sysocmgr.exe Win32/Sality.NAC virus deleted - quarantined
C:\WINDOWS\7SP_Files\taskmgr.exe Win32/Sality.NAC virus deleted - quarantined
C:\WINDOWS\7SP_Files\tourstart.exe Win32/Sality.NAC virus deleted - quarantined
C:\WINDOWS\7SP_Files\utilman.exe Win32/Sality.NAC virus deleted - quarantined
C:\WINDOWS\7SP_Files\wab.exe Win32/Sality.NAC virus deleted - quarantined
C:\WINDOWS\7SP_Files\wiaacmgr.exe Win32/Sality.NAC virus deleted - quarantined
C:\WINDOWS\7SP_Files\winchat.exe Win32/Sality.NAC virus deleted - quarantined
C:\WINDOWS\7SP_Files\winmine.exe Win32/Sality.NAC virus deleted - quarantined
C:\WINDOWS\7SP_Files\wmplayer.exe Win32/Sality.NAC virus deleted - quarantined
C:\WINDOWS\7SP_Files\wordpad.exe Win32/Sality.NAC virus deleted - quarantined
C:\WINDOWS\7SP_Files\wscript.exe Win32/Sality.NAC virus deleted - quarantined
C:\WINDOWS\7SP_Files\wupdmgr.exe Win32/Sality.NAC virus deleted - quarantined
C:\WINDOWS\7SP_Files\7 Taskbar Iconizer\7 Taskbar Iconizer.exe Win32/Sality.NAC virus deleted - quarantined
C:\WINDOWS\7SP_Files\Aero Shake\AeroShake.exe Win32/Sality.NAC virus deleted - quarantined
C:\WINDOWS\7SP_Files\backup\accwiz.exe Win32/Sality.NAC virus deleted - quarantined
C:\WINDOWS\7SP_Files\backup\ahui.exe Win32/Sality.NAC virus deleted - quarantined
C:\WINDOWS\7SP_Files\backup\calc.exe Win32/Sality.NAC virus deleted - quarantined
C:\WINDOWS\7SP_Files\backup\charmap.exe Win32/Sality.NAC virus deleted - quarantined
C:\WINDOWS\7SP_Files\backup\cmd.exe Win32/Sality.NAC virus deleted - quarantined
C:\WINDOWS\7SP_Files\backup\explorer.exe Win32/Sality.NAC virus deleted - quarantined
C:\WINDOWS\7SP_Files\backup\freecell.exe Win32/Sality.NAC virus deleted - quarantined
C:\WINDOWS\7SP_Files\backup\fsquirt.exe Win32/Sality.NAC virus deleted - quarantined
C:\WINDOWS\7SP_Files\backup\helpctr.exe Win32/Sality.NAC virus deleted - quarantined
C:\WINDOWS\7SP_Files\backup\hypertrm.exe Win32/Sality.NAC virus deleted - quarantined
C:\WINDOWS\7SP_Files\backup\icwconn1.exe Win32/Sality.NAC virus deleted - quarantined
C:\WINDOWS\7SP_Files\backup\icwconn2.exe Win32/Sality.NAC virus deleted - quarantined
C:\WINDOWS\7SP_Files\backup\iexpress.exe Win32/Sality.NAC virus deleted - quarantined
C:\WINDOWS\7SP_Files\backup\logon.scr Win32/Sality.NAC virus deleted - quarantined
C:\WINDOWS\7SP_Files\backup\logonui.exe Win32/Sality.NAC virus deleted - quarantined
C:\WINDOWS\7SP_Files\backup\magnify.exe Win32/Sality.NAC virus deleted - quarantined
C:\WINDOWS\7SP_Files\backup\migload.exe Win32/Sality.NAC virus deleted - quarantined
C:\WINDOWS\7SP_Files\backup\migpwd.exe Win32/Sality.NAC virus deleted - quarantined
C:\WINDOWS\7SP_Files\backup\migwiz.exe Win32/Sality.NAC virus deleted - quarantined
C:\WINDOWS\7SP_Files\backup\mobsync.exe Win32/Sality.NAC virus deleted - quarantined
C:\WINDOWS\7SP_Files\backup\mshearts.exe Win32/Sality.NAC virus deleted - quarantined
C:\WINDOWS\7SP_Files\backup\msiexec.exe Win32/Sality.NAC virus deleted - quarantined
C:\WINDOWS\7SP_Files\backup\msimn.exe Win32/Sality.NAC virus deleted - quarantined
C:\WINDOWS\7SP_Files\backup\msinfo32.exe Win32/Sality.NAC virus deleted - quarantined
C:\WINDOWS\7SP_Files\backup\msmsgs.exe Win32/Sality.NAC virus deleted - quarantined
C:\WINDOWS\7SP_Files\backup\msoobe.exe Win32/Sality.NAC virus deleted - quarantined
C:\WINDOWS\7SP_Files\backup\mspaint.exe Win32/Sality.NAC virus deleted - quarantined
C:\WINDOWS\7SP_Files\backup\mstsc.exe Win32/Sality.NAC virus deleted - quarantined
C:\WINDOWS\7SP_Files\backup\narrator.exe Win32/Sality.NAC virus deleted - quarantined
C:\WINDOWS\7SP_Files\backup\notepad.exe Win32/Sality.NAC virus deleted - quarantined
C:\WINDOWS\7SP_Files\backup\ntbackup.exe Win32/Sality.NAC virus deleted - quarantined
C:\WINDOWS\7SP_Files\backup\ntoskrnl.exe Win32/Sality.NAC virus deleted - quarantined
C:\WINDOWS\7SP_Files\backup\odbcad32.exe Win32/Sality.NAC virus deleted - quarantined
C:\WINDOWS\7SP_Files\backup\oobebaln.exe Win32/Sality.NAC virus deleted - quarantined
C:\WINDOWS\7SP_Files\backup\osk.exe Win32/Sality.NAC virus deleted - quarantined
C:\WINDOWS\7SP_Files\backup\pinball.exe Win32/Sality.NAC virus deleted - quarantined
C:\WINDOWS\7SP_Files\backup\rcimlby.exe Win32/Sality.NAC virus deleted - quarantined
C:\WINDOWS\7SP_Files\backup\regedit.exe Win32/Sality.NAC virus deleted - quarantined
C:\WINDOWS\7SP_Files\backup\rstrui.exe Win32/Sality.NAC virus deleted - quarantined
C:\WINDOWS\7SP_Files\backup\rtcshare.exe Win32/Sality.NAC virus deleted - quarantined
C:\WINDOWS\7SP_Files\backup\shrpubw.exe Win32/Sality.NAC virus deleted - quarantined
C:\WINDOWS\7SP_Files\backup\sigverif.exe Win32/Sality.NAC virus deleted - quarantined
C:\WINDOWS\7SP_Files\backup\sndrec32.exe Win32/Sality.NAC virus deleted - quarantined
C:\WINDOWS\7SP_Files\backup\sndvol32.exe Win32/Sality.NAC virus deleted - quarantined
C:\WINDOWS\7SP_Files\backup\sol.exe Win32/Sality.NAC virus deleted - quarantined
C:\WINDOWS\7SP_Files\backup\spider.exe Win32/Sality.NAC virus deleted - quarantined
C:\WINDOWS\7SP_Files\backup\syncapp.exe Win32/Sality.NAC virus deleted - quarantined
C:\WINDOWS\7SP_Files\backup\sysocmgr.exe Win32/Sality.NAC virus deleted - quarantined
C:\WINDOWS\7SP_Files\backup\taskmgr.exe Win32/Sality.NAC virus deleted - quarantined
C:\WINDOWS\7SP_Files\backup\tourstart.exe Win32/Sality.NAC virus deleted - quarantined
C:\WINDOWS\7SP_Files\backup\utilman.exe Win32/Sality.NAC virus deleted - quarantined
C:\WINDOWS\7SP_Files\backup\wab.exe Win32/Sality.NAC virus deleted - quarantined
C:\WINDOWS\7SP_Files\backup\wiaacmgr.exe Win32/Sality.NAC virus deleted - quarantined
C:\WINDOWS\7SP_Files\backup\winchat.exe Win32/Sality.NAC virus deleted - quarantined
C:\WINDOWS\7SP_Files\backup\winmine.exe Win32/Sality.NAC virus deleted - quarantined
C:\WINDOWS\7SP_Files\backup\wmplayer.exe Win32/Sality.NAC virus deleted - quarantined
C:\WINDOWS\7SP_Files\backup\wordpad.exe Win32/Sality.NAC virus deleted - quarantined
C:\WINDOWS\7SP_Files\backup\wscript.exe Win32/Sality.NAC virus deleted - quarantined
C:\WINDOWS\7SP_Files\backup\wupdmgr.exe Win32/Sality.NAC virus deleted - quarantined
C:\WINDOWS\7SP_Files\Drive Icon\DrvIcon.exe Win32/Sality.NAC virus deleted - quarantined
C:\WINDOWS\7SP_Files\Rainmeter\Rainmeter.exe Win32/Sality.NAC virus deleted - quarantined
C:\WINDOWS\7SP_Files\Rainmeter\StartWinD.exe Win32/Sality.NAC virus deleted - quarantined
C:\WINDOWS\7SP_Files\Rainmeter\StartWinE.exe Win32/Sality.NAC virus deleted - quarantined
C:\WINDOWS\7SP_Files\Refresh Icon Cache\Refresh Icon Cache.exe Win32/Sality.NAC virus deleted - quarantined
C:\WINDOWS\7SP_Files\Styler\Styler.exe Win32/Sality.NAC virus deleted - quarantined
C:\WINDOWS\7SP_Files\TransBar\TransBar.exe Win32/Sality.NAC virus deleted - quarantined
C:\WINDOWS\7SP_Files\TrueTransparency\TrueTransparency.exe Win32/Sality.NAC virus deleted - quarantined
C:\WINDOWS\7SP_Files\ViStart\ViStart.exe Win32/Sality.NAC virus deleted - quarantined
C:\WINDOWS\7SP_Files\VisualTaskTips\VisualTaskTips.exe Win32/Sality.NAC virus deleted - quarantined
C:\WINDOWS\7SP_Files\WinFlip\WinFlip.exe Win32/Sality.NAC virus deleted - quarantined
C:\WINDOWS\7SP_Files\YzShadow\YzShadow.exe Win32/Sality.NAC virus deleted - quarantined
C:\WINDOWS\BricoPacks\SysFiles\14_explorer.exe Win32/Sality.NAC virus deleted - quarantined
C:\WINDOWS\BricoPacks\SysFiles\17_helpctr.exe Win32/Sality.NAC virus deleted - quarantined
C:\WINDOWS\BricoPacks\SysFiles\24_logon.scr Win32/Sality.NAC virus deleted - quarantined
C:\WINDOWS\BricoPacks\SysFiles\26_migwiz.exe Win32/Sality.NAC virus deleted - quarantined
C:\WINDOWS\BricoPacks\SysFiles\2_ahui.exe Win32/Sality.NAC virus deleted - quarantined
C:\WINDOWS\BricoPacks\SysFiles\31_mspaint.exe Win32/Sality.NAC virus deleted - quarantined
C:\WINDOWS\BricoPacks\SysFiles\35_narrator.exe Win32/Sality.NAC virus deleted - quarantined
C:\WINDOWS\BricoPacks\SysFiles\40_notepad.exe Win32/Sality.NAC virus deleted - quarantined
C:\WINDOWS\BricoPacks\SysFiles\41_notepad.exe Win32/Sality.NAC virus deleted - quarantined
C:\WINDOWS\BricoPacks\SysFiles\48_regedit.exe Win32/Sality.NAC virus deleted - quarantined
C:\WINDOWS\BricoPacks\SysFiles\54_sndrec32.exe Win32/Sality.NAC virus deleted - quarantined
C:\WINDOWS\BricoPacks\SysFiles\55_sndvol32.exe Win32/Sality.NAC virus deleted - quarantined
C:\WINDOWS\BricoPacks\SysFiles\58_sysocmgr.exe Win32/Sality.NAC virus deleted - quarantined
C:\WINDOWS\BricoPacks\SysFiles\60_taskmgr.exe Win32/Sality.NAC virus deleted - quarantined
C:\WINDOWS\BricoPacks\SysFiles\67_wiaacmgr.exe Win32/Sality.NAC virus deleted - quarantined
C:\WINDOWS\BricoPacks\SysFiles\78_logonui.exe Win32/Sality.NAC virus deleted - quarantined
C:\WINDOWS\BricoPacks\SysFiles\7_calc.exe Win32/Sality.NAC virus deleted - quarantined
C:\WINDOWS\BricoPacks\SysFiles\80_msimn.exe Win32/Sality.NAC virus deleted - quarantined
C:\WINDOWS\BricoPacks\SysFiles\82_moviemk.exe Win32/Sality.NAC virus deleted - quarantined
C:\WINDOWS\BricoPacks\SysFiles\9_cmd.exe Win32/Sality.NAC virus deleted - quarantined
C:\WINDOWS\BricoPacks\Vista Inspirat 2\pack-it.exe Win32/Sality.NAC virus deleted - quarantined
C:\WINDOWS\BricoPacks\Vista Inspirat 2\Panel.exe Win32/Sality.NAC virus deleted - quarantined
C:\WINDOWS\BricoPacks\Vista Inspirat 2\iColorFolder\iColorFolder.exe Win32/Sality.NAC virus deleted - quarantined
C:\WINDOWS\BricoPacks\Vista Inspirat 2\iColorFolder\uninstall.exe Win32/Sality.NAC virus deleted - quarantined
C:\WINDOWS\BricoPacks\Vista Inspirat 2\PackFiles\14_explorer.exe Win32/Sality.NAC virus deleted - quarantined
C:\WINDOWS\BricoPacks\Vista Inspirat 2\PackFiles\17_helpctr.exe Win32/Sality.NAC virus deleted - quarantined
C:\WINDOWS\BricoPacks\Vista Inspirat 2\PackFiles\24_logon.scr Win32/Sality.NAC virus deleted - quarantined
C:\WINDOWS\BricoPacks\Vista Inspirat 2\PackFiles\26_migwiz.exe Win32/Sality.NAC virus deleted - quarantined
C:\WINDOWS\BricoPacks\Vista Inspirat 2\PackFiles\2_ahui.exe Win32/Sality.NAC virus deleted - quarantined
C:\WINDOWS\BricoPacks\Vista Inspirat 2\PackFiles\31_mspaint.exe Win32/Sality.NAC virus deleted - quarantined
C:\WINDOWS\BricoPacks\Vista Inspirat 2\PackFiles\35_narrator.exe Win32/Sality.NAC virus deleted - quarantined
C:\WINDOWS\BricoPacks\Vista Inspirat 2\PackFiles\40_notepad.exe Win32/Sality.NAC virus deleted - quarantined
C:\WINDOWS\BricoPacks\Vista Inspirat 2\PackFiles\41_notepad.exe Win32/Sality.NAC virus deleted - quarantined
C:\WINDOWS\BricoPacks\Vista Inspirat 2\PackFiles\48_regedit.exe Win32/Sality.NAC virus deleted - quarantined
C:\WINDOWS\BricoPacks\Vista Inspirat 2\PackFiles\54_sndrec32.exe Win32/Sality.NAC virus deleted - quarantined
C:\WINDOWS\BricoPacks\Vista Inspirat 2\PackFiles\55_sndvol32.exe Win32/Sality.NAC virus deleted - quarantined
C:\WINDOWS\BricoPacks\Vista Inspirat 2\PackFiles\58_sysocmgr.exe Win32/Sality.NAC virus deleted - quarantined
C:\WINDOWS\BricoPacks\Vista Inspirat 2\PackFiles\60_taskmgr.exe Win32/Sality.NAC virus deleted - quarantined
C:\WINDOWS\BricoPacks\Vista Inspirat 2\PackFiles\67_wiaacmgr.exe Win32/Sality.NAC virus deleted - quarantined
C:\WINDOWS\BricoPacks\Vista Inspirat 2\PackFiles\78_logonui.exe Win32/Sality.NAC virus deleted - quarantined
C:\WINDOWS\BricoPacks\Vista Inspirat 2\PackFiles\7_calc.exe Win32/Sality.NAC virus deleted - quarantined
C:\WINDOWS\BricoPacks\Vista Inspirat 2\PackFiles\80_msimn.exe Win32/Sality.NAC virus deleted - quarantined
C:\WINDOWS\BricoPacks\Vista Inspirat 2\PackFiles\82_moviemk.exe Win32/Sality.NAC virus deleted - quarantined
C:\WINDOWS\BricoPacks\Vista Inspirat 2\PackFiles\9_cmd.exe Win32/Sality.NAC virus deleted - quarantined
C:\WINDOWS\BricoPacks\Vista Inspirat 2\ResHacker\ResHacker.exe Win32/Sality.NAC virus deleted - quarantined
C:\WINDOWS\BricoPacks\Vista Inspirat 2\RocketDock\RocketDock.exe Win32/Sality.NAC virus deleted - quarantined
C:\WINDOWS\BricoPacks\Vista Inspirat 2\RocketDock\Tools\Debug.exe Win32/Sality.NAC virus deleted - quarantined
C:\WINDOWS\BricoPacks\Vista Inspirat 2\RocketDock\Tools\LanguageID Finder.exe Win32/Sality.NAC virus deleted - quarantined
C:\WINDOWS\BricoPacks\Vista Inspirat 2\Tools\dialog.exe Win32/Sality.NAC virus deleted - quarantined
C:\WINDOWS\BricoPacks\Vista Inspirat 2\Tools\refresh.exe Win32/Sality.NAC virus deleted - quarantined
C:\WINDOWS\BricoPacks\Vista Inspirat 2\TransBar\TransBar.exe Win32/Sality.NAC virus deleted - quarantined
C:\WINDOWS\BricoPacks\Vista Inspirat 2\UberIcon\UberIcon Manager.exe Win32/Sality.NAC virus deleted - quarantined
C:\WINDOWS\BricoPacks\Vista Inspirat 2\UberIcon\Uninst.exe Win32/Sality.NAC virus deleted - quarantined
C:\WINDOWS\BricoPacks\Vista Inspirat 2\UberIcon\Languages\LanguageID Finder.exe Win32/Sality.NAC virus deleted - quarantined
C:\WINDOWS\BricoPacks\Vista Inspirat 2\YzShadow\YzShadow.exe Win32/Sality.NAC virus deleted - quarantined
C:\WINDOWS\Driver Cache\i386\ntkrnlmp.exe Win32/Sality.NAC virus deleted - quarantined
C:\WINDOWS\Driver Cache\i386\ntkrnlpa.exe Win32/Sality.NAC virus deleted - quarantined
C:\WINDOWS\Driver Cache\i386\ntkrpamp.exe Win32/Sality.NAC virus deleted - quarantined
C:\WINDOWS\Driver Cache\i386\ntoskrnl.exe Win32/Sality.NAC virus deleted - quarantined
C:\WINDOWS\ERDNT\cache\ctfmon.exe Win32/Sality.NAC virus deleted - quarantined
C:\WINDOWS\ERDNT\cache\explorer.exe Win32/Sality.NAC virus deleted - quarantined
C:\WINDOWS\ERDNT\cache\lsass.exe Win32/Sality.NAC virus deleted - quarantined
C:\WINDOWS\ERDNT\cache\ntkrnlpa.exe Win32/Sality.NAC virus deleted - quarantined
C:\WINDOWS\ERDNT\cache\ntoskrnl.exe Win32/Sality.NAC virus deleted - quarantined
C:\WINDOWS\ERDNT\cache\services.exe Win32/Sality.NAC virus deleted - quarantined
C:\WINDOWS\ERDNT\cache\spoolsv.exe Win32/Sality.NAC virus deleted - quarantined
C:\WINDOWS\ERDNT\cache\svchost.exe Win32/Sality.NAC virus deleted - quarantined
C:\WINDOWS\ERDNT\cache\userinit.exe Win32/Sality.NAC virus deleted - quarantined
C:\WINDOWS\ERDNT\cache\wscntfy.exe Win32/Sality.NAC virus deleted - quarantined
C:\WINDOWS\ERDNT\Hiv-backup\ERDNT.EXE Win32/Sality.NAC virus deleted - quarantined
C:\WINDOWS\ERDNT\subs\ERDNT.EXE Win32/Sality.NAC virus deleted - quarantined
C:\WINDOWS\ie7\ie4uinit.exe Win32/Sality.NAC virus deleted - quarantined
C:\WINDOWS\ie7\iedw.exe Win32/Sality.NAC virus deleted - quarantined
C:\WINDOWS\ie7\iexplore.exe Win32/Sality.NAC virus deleted - quarantined
C:\WINDOWS\ie7\mshta.exe Win32/Sality.NAC virus deleted - quarantined
C:\WINDOWS\ie7\spuninst\ieResetIcons.exe Win32/Sality.NAC virus deleted - quarantined
C:\WINDOWS\ie7updates\KB953838-IE7\ie4uinit.exe Win32/Sality.NAC virus deleted - quarantined
C:\WINDOWS\ie7updates\KB953838-IE7\ieudinit.exe Win32/Sality.NAC virus deleted - quarantined
C:\WINDOWS\ie7updates\KB953838-IE7\iexplore.exe Win32/Sality.NAC virus deleted - quarantined
C:\WINDOWS\ie7updates\KB969897-IE7\ieudinit.exe Win32/Sality.NAC virus deleted - quarantined
C:\WINDOWS\ie8\ie4uinit.exe Win32/Sality.NAC virus deleted - quarantined
C:\WINDOWS\ie8\iexplore.exe Win32/Sality.NAC virus deleted - quarantined
C:\WINDOWS\ie8\msfeedssync.exe Win32/Sality.NAC virus deleted - quarantined
C:\WINDOWS\ie8\mshta.exe Win32/Sality.NAC virus deleted - quarantined
C:\WINDOWS\ie8\winfxdocobj.exe Win32/Sality.NAC virus deleted - quarantined
C:\WINDOWS\ie8updates\KB969897-IE8\ie4uinit.exe Win32/Sality.NAC virus deleted - quarantined
C:\WINDOWS\ie8updates\KB972260-IE8\ie4uinit.exe Win32/Sality.NAC virus deleted - quarantined
C:\WINDOWS\ie8updates\KB974455-IE8\ie4uinit.exe Win32/Sality.NAC virus deleted - quarantined
C:\WINDOWS\ie8updates\KB976325-IE8\ie4uinit.exe Win32/Sality.NAC virus deleted - quarantined
C:\WINDOWS\ime\imjp8_1\cplexe.exe Win32/Sality.NAC virus unable to clean
C:\WINDOWS\ime\imjp8_1\imjpdct.exe Win32/Sality.NAC virus unable to clean
C:\WINDOWS\ime\imjp8_1\imjpdsvr.exe Win32/Sality.NAC virus unable to clean
C:\WINDOWS\ime\imjp8_1\imjpinst.exe Win32/Sality.NAC virus unable to clean
C:\WINDOWS\ime\imjp8_1\imjpmig.exe Win32/Sality.NAC virus unable to clean
C:\WINDOWS\ime\imjp8_1\imjprw.exe Win32/Sality.NAC virus unable to clean
C:\WINDOWS\ime\imjp8_1\imjputy.exe Win32/Sality.NAC virus unable to clean
C:\WINDOWS\Installer\{048298C9-A4D3-490B-9FF9-AB023A9238F3}\Icon048298C91.exe Win32/Sality.NAC virus deleted - quarantined
C:\WINDOWS\Installer\{350C97B0-3D7C-4EE8-BAA9-00BCB3D54227}\places.exe Win32/Sality.NAC virus deleted - quarantined
C:\WINDOWS\Installer\{716E0306-8318-4364-8B8F-0CC4E9376BAC}\icon.exe Win32/Sality.NAC virus deleted - quarantined
C:\WINDOWS\Installer\{86493ADD-824D-4B8E-BD72-8C5DCDC52A71}\icon.exe Win32/Sality.NAC virus deleted - quarantined
C:\WINDOWS\Installer\{F662A8E6-F4DC-41A2-901E-8C11F044BDEC}\icon.exe Win32/Sality.NAC virus deleted - quarantined
C:\WINDOWS\Microsoft.NET\Framework\v1.1.4322\aspnet_regiis.exe Win32/Sality.NAC virus deleted - quarantined
C:\WINDOWS\Microsoft.NET\Framework\v1.1.4322\aspnet_state.exe Win32/Sality.NAC virus deleted - quarantined
C:\WINDOWS\Microsoft.NET\Framework\v1.1.4322\aspnet_wp.exe Win32/Sality.NAC virus deleted - quarantined
C:\WINDOWS\Microsoft.NET\Framework\v1.1.4322\CasPol.exe Win32/Sality.NAC virus deleted - quarantined
C:\WINDOWS\Microsoft.NET\Framework\v1.1.4322\ConfigWizards.exe Win32/Sality.NAC virus deleted - quarantined
C:\WINDOWS\Microsoft.NET\Framework\v1.1.4322\csc.exe Win32/Sality.NAC virus deleted - quarantined
C:\WINDOWS\Microsoft.NET\Framework\v1.1.4322\cvtres.exe Win32/Sality.NAC virus deleted - quarantined
C:\WINDOWS\Microsoft.NET\Framework\v1.1.4322\gacutil.exe Win32/Sality.NAC virus deleted - quarantined
C:\WINDOWS\Microsoft.NET\Framework\v1.1.4322\ilasm.exe Win32/Sality.NAC virus deleted - quarantined
C:\WINDOWS\Microsoft.NET\Framework\v1.1.4322\jsc.exe Win32/Sality.NAC virus deleted - quarantined
C:\WINDOWS\Microsoft.NET\Framework\v1.1.4322\MigPol.exe Win32/Sality.NAC virus deleted - quarantined
C:\WINDOWS\Microsoft.NET\Framework\v1.1.4322\MigPolWin.exe Win32/Sality.NAC virus deleted - quarantined
C:\WINDOWS\Microsoft.NET\Framework\v1.1.4322\netfxupdate.exe Win32/Sality.NAC virus deleted - quarantined
C:\WINDOWS\Microsoft.NET\Framework\v1.1.4322\ngen.exe Win32/Sality.NAC virus deleted - quarantined
C:\WINDOWS\Microsoft.NET\Framework\v1.1.4322\RegAsm.exe Win32/Sality.NAC virus deleted - quarantined
C:\WINDOWS\Microsoft.NET\Framework\v1.1.4322\vbc.exe Win32/Sality.NAC virus deleted - quarantined
C:\WINDOWS\Microsoft.NET\Framework\v1.1.4322\Updates\hotfix.exe Win32/Sality.NAC virus deleted - quarantined
C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\aspnet_compiler.exe Win32/Sality.NAC virus deleted - quarantined
C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\aspnet_regbrowsers.exe Win32/Sality.NAC virus deleted - quarantined
C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\aspnet_regsql.exe Win32/Sality.NAC virus deleted - quarantined
C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\CasPol.exe Win32/Sality.NAC virus deleted - quarantined
C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\InstallUtil.exe Win32/Sality.NAC virus deleted - quarantined
C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\jsc.exe Win32/Sality.NAC virus deleted - quarantined
C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\MSBuild.exe Win32/Sality.NAC virus deleted - quarantined
C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\RegAsm.exe Win32/Sality.NAC virus deleted - quarantined
C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\RegSvcs.exe Win32/Sality.NAC virus deleted - quarantined
C:\WINDOWS\network diagnostic\xpnetdiag.exe Win32/Sality.NAC virus deleted - quarantined
C:\WINDOWS\San Andreas Mod Installer\uninstall.exe Win32/Sality.NAC virus deleted - quarantined
C:\WINDOWS\ServicePackFiles\i386\accwiz.exe Win32/Sality.NAC virus deleted - quarantined
C:\WINDOWS\ServicePackFiles\i386\admin.exe Win32/Sality.NAC virus deleted - quarantined
C:\WINDOWS\ServicePackFiles\i386\agentsvr.exe Win32/Sality.NAC virus deleted - quarantined
C:\WINDOWS\ServicePackFiles\i386\ahui.exe Win32/Sality.NAC virus deleted - quarantined
C:\WINDOWS\ServicePackFiles\i386\alg.exe Win32/Sality.NAC virus deleted - quarantined
C:\WINDOWS\ServicePackFiles\i386\aspnet_regiis.exe Win32/Sality.NAC virus deleted - quarantined
C:\WINDOWS\ServicePackFiles\i386\aspnet_state.exe Win32/Sality.NAC virus deleted - quarantined
C:\WINDOWS\ServicePackFiles\i386\aspnet_wp.exe Win32/Sality.NAC virus deleted - quarantined
C:\WINDOWS\ServicePackFiles\i386\asr_fmt.exe Win32/Sality.NAC virus deleted - quarantined
C:\WINDOWS\ServicePackFiles\i386\asr_pfu.exe Win32/Sality.NAC virus deleted - quarantined
C:\WINDOWS\ServicePackFiles\i386\at.exe Win32/Sality.NAC virus deleted - quarantined
C:\WINDOWS\ServicePackFiles\i386\atmadm.exe Win32/Sality.NAC virus deleted - quarantined
C:\WINDOWS\ServicePackFiles\i386\attrib.exe Win32/Sality.NAC virus deleted - quarantined
C:\WINDOWS\ServicePackFiles\i386\auditusr.exe Win32/Sality.NAC virus deleted - quarantined
C:\WINDOWS\ServicePackFiles\i386\author.exe Win32/Sality.NAC virus deleted - quarantined
C:\WINDOWS\ServicePackFiles\i386\autochk.exe Win32/Sality.NAC virus deleted - quarantined
C:\WINDOWS\ServicePackFiles\i386\autoconv.exe Win32/Sality.NAC virus deleted - quarantined
C:\WINDOWS\ServicePackFiles\i386\autofmt.exe Win32/Sality.NAC virus deleted - quarantined
C:\WINDOWS\ServicePackFiles\i386\autolfn.exe Win32/Sality.NAC virus deleted - quarantined
C:\WINDOWS\ServicePackFiles\i386\blastcln.exe Win32/Sality.NAC virus deleted - quarantined
C:\WINDOWS\ServicePackFiles\i386\bootcfg.exe Win32/Sality.NAC virus deleted - quarantined
C:\WINDOWS\ServicePackFiles\i386\cacls.exe Win32/Sality.NAC virus deleted - quarantined
C:\WINDOWS\ServicePackFiles\i386\caspol.exe Win32/Sality.NAC virus deleted - quarantined
C:\WINDOWS\ServicePackFiles\i386\cfgwiz.exe Win32/Sality.NAC virus deleted - quarantined
C:\WINDOWS\ServicePackFiles\i386\cipher.exe Win32/Sality.NAC virus deleted - quarantined
C:\WINDOWS\ServicePackFiles\i386\cisvc.exe Win32/Sality.NAC virus deleted - quarantined
C:\WINDOWS\ServicePackFiles\i386\cliconfg.exe Win32/Sality.NAC virus deleted - quarantined
C:\WINDOWS\ServicePackFiles\i386\clipbrd.exe Win32/Sality.NAC virus deleted - quarantined
C:\WINDOWS\ServicePackFiles\i386\clipsrv.exe Win32/Sality.NAC virus deleted - quarantined
C:\WINDOWS\ServicePackFiles\i386\cmd.exe Win32/Sality.NAC virus deleted - quarantined
C:\WINDOWS\ServicePackFiles\i386\cmdl32.exe Win32/Sality.NAC virus deleted - quarantined
C:\WINDOWS\ServicePackFiles\i386\cmmon32.exe Win32/Sality.NAC virus deleted - quarantined
C:\WINDOWS\ServicePackFiles\i386\cmstp.exe Win32/Sality.NAC virus deleted - quarantined
C:\WINDOWS\ServicePackFiles\i386\comrepl.exe Win32/Sality.NAC virus deleted - quarantined
C:\WINDOWS\ServicePackFiles\i386\comrereg.exe Win32/Sality.NAC virus deleted - quarantined
C:\WINDOWS\ServicePackFiles\i386\comsdupd.exe Win32/Sality.NAC virus deleted - quarantined
C:\WINDOWS\ServicePackFiles\i386\conf.exe Win32/Sality.NAC virus deleted - quarantined
C:\WINDOWS\ServicePackFiles\i386\conime.exe Win32/Sality.NAC virus deleted - quarantined
C:\WINDOWS\ServicePackFiles\i386\csc.exe Win32/Sality.NAC virus deleted - quarantined
C:\WINDOWS\ServicePackFiles\i386\cscript.exe Win32/Sality.NAC virus deleted - quarantined
C:\WINDOWS\ServicePackFiles\i386\csrss.exe Win32/Sality.NAC virus deleted - quarantined
C:\WINDOWS\ServicePackFiles\i386\ctfmon.exe Win32/Sality.NAC virus deleted - quarantined
C:\WINDOWS\ServicePackFiles\i386\davcdata.exe Win32/Sality.NAC virus deleted - quarantined
C:\WINDOWS\ServicePackFiles\i386\dcomcnfg.exe Win32/Sality.NAC virus deleted - quarantined
C:\WINDOWS\ServicePackFiles\i386\ddeshare.exe Win32/Sality.NAC virus deleted - quarantined
C:\WINDOWS\ServicePackFiles\i386\defrag.exe Win32/Sality.NAC virus deleted - quarantined
C:\WINDOWS\ServicePackFiles\i386\dfrgfat.exe Win32/Sality.NAC virus deleted - quarantined
C:\WINDOWS\ServicePackFiles\i386\dfrgntfs.exe Win32/Sality.NAC virus deleted - quarantined
C:\WINDOWS\ServicePackFiles\i386\diantz.exe Win32/Sality.NAC virus deleted - quarantined
C:\WINDOWS\ServicePackFiles\i386\diskpart.exe Win32/Sality.NAC virus deleted - quarantined
C:\WINDOWS\ServicePackFiles\i386\dllhost.exe Win32/Sality.NAC virus deleted - quarantined
C:\WINDOWS\ServicePackFiles\i386\dmadmin.exe Win32/Sality.NAC virus deleted - quarantined
C:\WINDOWS\ServicePackFiles\i386\dmremote.exe Win32/Sality.NAC virus deleted - quarantined
C:\WINDOWS\ServicePackFiles\i386\dplaysvr.exe Win32/Sality.NAC virus deleted - quarantined
C:\WINDOWS\ServicePackFiles\i386\dpnsvr.exe Win32/Sality.NAC virus deleted - quarantined
C:\WINDOWS\ServicePackFiles\i386\dpvsetup.exe Win32/Sality.NAC virus deleted - quarantined
C:\WINDOWS\ServicePackFiles\i386\drvqry.exe Win32/Sality.NAC virus deleted - quarantined
C:\WINDOWS\ServicePackFiles\i386\dumprep.exe Win32/Sality.NAC virus deleted - quarantined
C:\WINDOWS\ServicePackFiles\i386\dvdupgrd.exe Win32/Sality.NAC virus deleted - quarantined
C:\WINDOWS\ServicePackFiles\i386\dwwin.exe Win32/Sality.NAC virus deleted - quarantined
C:\WINDOWS\ServicePackFiles\i386\dxdiag.exe Win32/Sality.NAC virus deleted - quarantined
C:\WINDOWS\ServicePackFiles\i386\eudcedit.exe Win32/Sality.NAC virus deleted - quarantined
C:\WINDOWS\ServicePackFiles\i386\evcreate.exe Win32/Sality.NAC virus deleted - quarantined
C:\WINDOWS\ServicePackFiles\i386\evntcmd.exe Win32/Sality.NAC virus deleted - quarantined
C:\WINDOWS\ServicePackFiles\i386\evntwin.exe Win32/Sality.NAC virus deleted - quarantined
C:\WINDOWS\ServicePackFiles\i386\evtrig.exe Win32/Sality.NAC virus deleted - quarantined
C:\WINDOWS\ServicePackFiles\i386\explorer.exe Win32/Sality.NAC virus deleted - quarantined
C:\WINDOWS\ServicePackFiles\i386\extrac32.exe Win32/Sality.NAC virus deleted - quarantined
C:\WINDOWS\ServicePackFiles\i386\faxpatch.exe Win32/Sality.NAC virus deleted - quarantined
C:\WINDOWS\ServicePackFiles\i386\findstr.exe Win32/Sality.NAC virus deleted - quarantined
C:\WINDOWS\ServicePackFiles\i386\fltmc.exe Win32/Sality.NAC virus deleted - quarantined
C:\WINDOWS\ServicePackFiles\i386\fontview.exe Win32/Sality.NAC virus deleted - quarantined
C:\WINDOWS\ServicePackFiles\i386\forcedos.exe Win32/Sality.NAC virus deleted - quarantined
C:\WINDOWS\ServicePackFiles\i386\fp98sadm.exe Win32/Sality.NAC virus deleted - quarantined
C:\WINDOWS\ServicePackFiles\i386\fp98swin.exe Win32/Sality.NAC virus deleted - quarantined
C:\WINDOWS\ServicePackFiles\i386\fpadmcgi.exe Win32/Sality.NAC virus deleted - quarantined
C:\WINDOWS\ServicePackFiles\i386\fpcount.exe Win32/Sality.NAC virus deleted - quarantined
C:\WINDOWS\ServicePackFiles\i386\fpremadm.exe Win32/Sality.NAC virus deleted - quarantined
C:\WINDOWS\ServicePackFiles\i386\fpsrvadm.exe Win32/Sality.NAC virus deleted - quarantined
C:\WINDOWS\ServicePackFiles\i386\fsquirt.exe Win32/Sality.NAC virus deleted - quarantined
C:\WINDOWS\ServicePackFiles\i386\ftp.exe Win32/Sality.NAC virus deleted - quarantined
C:\WINDOWS\ServicePackFiles\i386\fxsclnt.exe Win32/Sality.NAC virus deleted - quarantined
C:\WINDOWS\ServicePackFiles\i386\fxscover.exe Win32/Sality.NAC virus deleted - quarantined
C:\WINDOWS\ServicePackFiles\i386\getmac.exe Win32/Sality.NAC virus deleted - quarantined
C:\WINDOWS\ServicePackFiles\i386\gprslt.exe Win32/Sality.NAC virus deleted - quarantined
C:\WINDOWS\ServicePackFiles\i386\grpconv.exe Win32/Sality.NAC virus deleted - quarantined
C:\WINDOWS\ServicePackFiles\i386\help.exe Win32/Sality.NAC virus deleted - quarantined
C:\WINDOWS\ServicePackFiles\i386\helpctr.exe Win32/Sality.NAC virus deleted - quarantined
C:\WINDOWS\ServicePackFiles\i386\helpsvc.exe Win32/Sality.NAC virus deleted - quarantined
C:\WINDOWS\ServicePackFiles\i386\hh.exe Win32/Sality.NAC virus deleted - quarantined
C:\WINDOWS\ServicePackFiles\i386\hscupd.exe Win32/Sality.NAC virus deleted - quarantined
C:\WINDOWS\ServicePackFiles\i386\icwconn1.exe Win32/Sality.NAC virus deleted - quarantined
C:\WINDOWS\ServicePackFiles\i386\icwconn2.exe Win32/Sality.NAC virus deleted - quarantined
C:\WINDOWS\ServicePackFiles\i386\icwrmind.exe Win32/Sality.NAC virus deleted - quarantined
C:\WINDOWS\ServicePackFiles\i386\ie4uinit.exe Win32/Sality.NAC virus deleted - quarantined
C:\WINDOWS\ServicePackFiles\i386\iedw.exe Win32/Sality.NAC virus deleted - quarantined
C:\WINDOWS\ServicePackFiles\i386\iexpress.exe Win32/Sality.NAC virus deleted - quarantined
C:\WINDOWS\ServicePackFiles\i386\iisrstas.exe Win32/Sality.NAC virus deleted - quarantined
C:\WINDOWS\ServicePackFiles\i386\ilasm.exe Win32/Sality.NAC virus deleted - quarantined
C:\WINDOWS\ServicePackFiles\i386\imapi.exe Win32/Sality.NAC virus deleted - quarantined
C:\WINDOWS\ServicePackFiles\i386\inetin51.exe Win32/Sality.NAC virus deleted - quarantined
C:\WINDOWS\ServicePackFiles\i386\inetwiz.exe Win32/Sality.NAC virus deleted - quarantined
C:\WINDOWS\ServicePackFiles\i386\ipconfig.exe Win32/Sality.NAC virus deleted - quarantined
C:\WINDOWS\ServicePackFiles\i386\ipv6.exe Win32/Sality.NAC virus deleted - quarantined
C:\WINDOWS\ServicePackFiles\i386\ipxroute.exe Win32/Sality.NAC virus deleted - quarantined
C:\WINDOWS\ServicePackFiles\i386\irftp.exe Win32/Sality.NAC virus deleted - quarantined
C:\WINDOWS\ServicePackFiles\i386\jsc.exe Win32/Sality.NAC virus deleted - quarantined
C:\WINDOWS\ServicePackFiles\i386\lhmstsc.exe Win32/Sality.NAC virus deleted - quarantined
C:\WINDOWS\ServicePackFiles\i386\locator.exe Win32/Sality.NAC virus deleted - quarantined
C:\WINDOWS\ServicePackFiles\i386\logman.exe Win32/Sality.NAC virus deleted - quarantined
C:\WINDOWS\ServicePackFiles\i386\logon.scr Win32/Sality.NAC virus deleted - quarantined
C:\WINDOWS\ServicePackFiles\i386\logonui.exe Win32/Sality.NAC virus deleted - quarantined
C:\WINDOWS\ServicePackFiles\i386\lsass.exe Win32/Sality.NAC virus deleted - quarantined
C:\WINDOWS\ServicePackFiles\i386\magnify.exe Win32/Sality.NAC virus deleted - quarantined
C:\WINDOWS\ServicePackFiles\i386\makecab.exe Win32/Sality.NAC virus deleted - quarantined
C:\WINDOWS\ServicePackFiles\i386\migload.exe Win32/Sality.NAC virus deleted - quarantined
C:\WINDOWS\ServicePackFiles\i386\migregdb.exe Win32/Sality.NAC virus deleted - quarantined
C:\WINDOWS\ServicePackFiles\i386\migwiz.exe Win32/Sality.NAC virus deleted - quarantined
C:\WINDOWS\ServicePackFiles\i386\migwiza.exe Win32/Sality.NAC virus deleted - quarantined
C:\WINDOWS\ServicePackFiles\i386\mmcperf.exe Win32/Sality.NAC virus deleted - quarantined
C:\WINDOWS\ServicePackFiles\i386\mnmsrvc.exe Win32/Sality.NAC virus deleted - quarantined
C:\WINDOWS\ServicePackFiles\i386\mobsync.exe Win32/Sality.NAC virus deleted - quarantined
C:\WINDOWS\ServicePackFiles\i386\mofcomp.exe Win32/Sality.NAC virus deleted - quarantined
C:\WINDOWS\ServicePackFiles\i386\moviemk.exe Win32/Sality.NAC virus deleted - quarantined
C:\WINDOWS\ServicePackFiles\i386\mplay32.exe Win32/Sality.NAC virus deleted - quarantined
C:\WINDOWS\ServicePackFiles\i386\mqbkup.exe Win32/Sality.NAC virus deleted - quarantined
C:\WINDOWS\ServicePackFiles\i386\mqsvc.exe Win32/Sality.NAC virus deleted - quarantined
C:\WINDOWS\ServicePackFiles\i386\mqtgsvc.exe Win32/Sality.NAC virus deleted - quarantined
C:\WINDOWS\ServicePackFiles\i386\msconfig.exe Win32/Sality.NAC virus deleted - quarantined
C:\WINDOWS\ServicePackFiles\i386\msdtc.exe Win32/Sality.NAC virus deleted - quarantined
C:\WINDOWS\ServicePackFiles\i386\mshta.exe Win32/Sality.NAC virus deleted - quarantined
C:\WINDOWS\ServicePackFiles\i386\msiexec.exe Win32/Sality.NAC virus deleted - quarantined
C:\WINDOWS\ServicePackFiles\i386\msimn.exe Win32/Sality.NAC virus deleted - quarantined
C:\WINDOWS\ServicePackFiles\i386\msiregmv.exe Win32/Sality.NAC virus deleted - quarantined
C:\WINDOWS\ServicePackFiles\i386\msmsgs.exe Win32/Sality.NAC virus deleted - quarantined
C:\WINDOWS\ServicePackFiles\i386\msnsusii.exe Win32/Sality.NAC virus deleted - quarantined
C:\WINDOWS\ServicePackFiles\i386\msoobe.exe Win32/Sality.NAC virus deleted - quarantined
C:\WINDOWS\ServicePackFiles\i386\mspaint.exe Win32/Sality.NAC virus deleted - quarantined
C:\WINDOWS\ServicePackFiles\i386\mstinit.exe Win32/Sality.NAC virus deleted - quarantined
C:\WINDOWS\ServicePackFiles\i386\mtstocom.exe Win32/Sality.NAC virus deleted - quarantined
C:\WINDOWS\ServicePackFiles\i386\muisetup.exe Win32/Sality.NAC virus deleted - quarantined
C:\WINDOWS\ServicePackFiles\i386\napstat.exe Win32/Sality.NAC virus deleted - quarantined
C:\WINDOWS\ServicePackFiles\i386\narrator.exe Win32/Sality.NAC virus deleted - quarantined
C:\WINDOWS\ServicePackFiles\i386\net.exe Win32/Sality.NAC virus deleted - quarantined
C:\WINDOWS\ServicePackFiles\i386\net1.exe Win32/Sality.NAC virus deleted - quarantined
C:\WINDOWS\ServicePackFiles\i386\netdde.exe Win32/Sality.NAC virus deleted - quarantined
C:\WINDOWS\ServicePackFiles\i386\netsetup.exe Win32/Sality.NAC virus deleted - quarantined
C:\WINDOWS\ServicePackFiles\i386\netsh.exe Win32/Sality.NAC virus deleted - quarantined
C:\WINDOWS\ServicePackFiles\i386\netstat.exe Win32/Sality.NAC virus deleted - quarantined
C:\WINDOWS\ServicePackFiles\i386\ngen.exe Win32/Sality.NAC virus deleted - quarantined
C:\WINDOWS\ServicePackFiles\i386\notepad.exe Win32/Sality.NAC virus deleted - quarantined
C:\WINDOWS\ServicePackFiles\i386\nppagent.exe Win32/Sality.NAC virus deleted - quarantined
C:\WINDOWS\ServicePackFiles\i386\nslookup.exe Win32/Sality.NAC virus deleted - quarantined
C:\WINDOWS\ServicePackFiles\i386\ntbackup.exe Win32/Sality.NAC virus deleted - quarantined
C:\WINDOWS\ServicePackFiles\i386\ntkrnlmp.exe Win32/Sality.NAC virus deleted - quarantined
C:\WINDOWS\ServicePackFiles\i386\ntkrnlpa.exe Win32/Sality.NAC virus deleted - quarantined
C:\WINDOWS\ServicePackFiles\i386\ntkrpamp.exe Win32/Sality.NAC virus deleted - quarantined
C:\WINDOWS\ServicePackFiles\i386\ntoskrnl.exe Win32/Sality.NAC virus deleted - quarantined
C:\WINDOWS\ServicePackFiles\i386\ntvdm.exe Win32/Sality.NAC virus deleted - quarantined
C:\WINDOWS\ServicePackFiles\i386\odbcad32.exe Win32/Sality.NAC virus deleted - quarantined
C:\WINDOWS\ServicePackFiles\i386\odbcconf.exe Win32/Sality.NAC virus deleted - quarantined
C:\WINDOWS\ServicePackFiles\i386\oemig50.exe Win32/Sality.NAC virus deleted - quarantined
C:\WINDOWS\ServicePackFiles\i386\oobebaln.exe Win32/Sality.NAC virus deleted - quarantined
C:\WINDOWS\ServicePackFiles\i386\opnfiles.exe Win32/Sality.NAC virus deleted - quarantined
C:\WINDOWS\ServicePackFiles\i386\oschoice.exe Win32/Sality.NAC virus deleted - quarantined
C:\WINDOWS\ServicePackFiles\i386\osk.exe Win32/Sality.NAC virus deleted - quarantined
C:\WINDOWS\ServicePackFiles\i386\osloader.exe Win32/Sality.NAC virus deleted - quarantined
C:\WINDOWS\ServicePackFiles\i386\packager.exe Win32/Sality.NAC virus deleted - quarantined
C:\WINDOWS\ServicePackFiles\i386\perfmon.exe Win32/Sality.NAC virus deleted - quarantined
C:\WINDOWS\ServicePackFiles\i386\pinball.exe Win32/Sality.NAC virus deleted - quarantined
C:\WINDOWS\ServicePackFiles\i386\ping.exe Win32/Sality.NAC virus deleted - quarantined
C:\WINDOWS\ServicePackFiles\i386\powercfg.exe Win32/Sality.NAC virus deleted - quarantined
C:\WINDOWS\ServicePackFiles\i386\progman.exe Win32/Sality.NAC virus deleted - quarantined
C:\WINDOWS\ServicePackFiles\i386\proquota.exe Win32/Sality.NAC virus deleted - quarantined
C:\WINDOWS\ServicePackFiles\i386\proxycfg.exe Win32/Sality.NAC virus deleted - quarantined
C:\WINDOWS\ServicePackFiles\i386\qprocess.exe Win32/Sality.NAC virus deleted - quarantined
C:\WINDOWS\ServicePackFiles\i386\rasphone.exe Win32/Sality.NAC virus deleted - quarantined
C:\WINDOWS\ServicePackFiles\i386\rcimlby.exe Win32/Sality.NAC virus deleted - quarantined
C:\WINDOWS\ServicePackFiles\i386\rcp.exe Win32/Sality.NAC virus deleted - quarantined
C:\WINDOWS\ServicePackFiles\i386\rdpclip.exe Win32/Sality.NAC virus deleted - quarantined
C:\WINDOWS\ServicePackFiles\i386\rdsaddin.exe Win32/Sality.NAC virus deleted - quarantined
C:\WINDOWS\ServicePackFiles\i386\rdshost.exe Win32/Sality.NAC virus deleted - quarantined
C:\WINDOWS\ServicePackFiles\i386\reg.exe Win32/Sality.NAC virus deleted - quarantined
C:\WINDOWS\ServicePackFiles\i386\regasm.exe Win32/Sality.NAC virus deleted - quarantined
C:\WINDOWS\ServicePackFiles\i386\regedit.exe Win32/Sality.NAC virus deleted - quarantined
C:\WINDOWS\ServicePackFiles\i386\regsvr32.exe Win32/Sality.NAC virus deleted - quarantined
C:\WINDOWS\ServicePackFiles\i386\rexec.exe Win32/Sality.NAC virus deleted - quarantined
C:\WINDOWS\ServicePackFiles\i386\rsh.exe Win32/Sality.NAC virus deleted - quarantined
C:\WINDOWS\ServicePackFiles\i386\rsnotify.exe Win32/Sality.NAC virus deleted - quarantined
C:\WINDOWS\ServicePackFiles\i386\rstrui.exe Win32/Sality.NAC virus deleted - quarantined
C:\WINDOWS\ServicePackFiles\i386\rtcshare.exe Win32/Sality.NAC virus deleted - quarantined
C:\WINDOWS\ServicePackFiles\i386\rundll32.exe Win32/Sality.NAC virus deleted - quarantined
C:\WINDOWS\ServicePackFiles\i386\runonce.exe Win32/Sality.NAC virus deleted - quarantined
C:\WINDOWS\ServicePackFiles\i386\savedump.exe Win32/Sality.NAC virus deleted - quarantined
C:\WINDOWS\ServicePackFiles\i386\scardsvr.exe Win32/Sality.NAC virus deleted - quarantined
C:\WINDOWS\ServicePackFiles\i386\scrcons.exe Win32/Sality.NAC virus deleted - quarantined
C:\WINDOWS\ServicePackFiles\i386\scrnsave.scr Win32/Sality.NAC virus deleted - quarantined
C:\WINDOWS\ServicePackFiles\i386\sctasks.exe Win32/Sality.NAC virus deleted - quarantined
C:\WINDOWS\ServicePackFiles\i386\sdbinst.exe Win32/Sality.NAC virus deleted - quarantined
C:\WINDOWS\ServicePackFiles\i386\secedit.exe Win32/Sality.NAC virus deleted - quarantined
C:\WINDOWS\ServicePackFiles\i386\services.exe Win32/Sality.NAC virus deleted - quarantined
C:\WINDOWS\ServicePackFiles\i386\sessmgr.exe Win32/Sality.NAC virus deleted - quarantined
C:\WINDOWS\ServicePackFiles\i386\sethc.exe Win32/Sality.NAC virus deleted - quarantined
C:\WINDOWS\ServicePackFiles\i386\setup.exe Win32/Sality.NAC virus deleted - quarantined
C:\WINDOWS\ServicePackFiles\i386\setup50.exe Win32/Sality.NAC virus deleted - quarantined
C:\WINDOWS\ServicePackFiles\i386\setupn.exe Win32/Sality.NAC virus deleted - quarantined
C:\WINDOWS\ServicePackFiles\i386\shmgrate.exe Win32/Sality.NAC virus deleted - quarantined
C:\WINDOWS\ServicePackFiles\i386\shrpubw.exe Win32/Sality.NAC virus deleted - quarantined
C:\WINDOWS\ServicePackFiles\i386\shtml.exe Win32/Sality.NAC virus deleted - quarantined
C:\WINDOWS\ServicePackFiles\i386\shutdown.exe Win32/Sality.NAC virus deleted - quarantined
C:\WINDOWS\ServicePackFiles\i386\sigverif.exe Win32/Sality.NAC virus deleted - quarantined
C:\WINDOWS\ServicePackFiles\i386\skeys.exe Win32/Sality.NAC virus deleted - quarantined
C:\WINDOWS\ServicePackFiles\i386\slrundll.exe Win32/Sality.NAC virus deleted - quarantined
C:\WINDOWS\ServicePackFiles\i386\slserv.exe Win32/Sality.NAC virus deleted - quarantined
C:\WINDOWS\ServicePackFiles\i386\smbinst.exe Win32/Sality.NAC virus deleted - quarantined
C:\WINDOWS\ServicePackFiles\i386\smi2smir.exe Win32/Sality.NAC virus deleted - quarantined
C:\WINDOWS\ServicePackFiles\i386\smlogsvc.exe Win32/Sality.NAC virus deleted - quarantined
C:\WINDOWS\ServicePackFiles\i386\smss.exe Win32/Sality.NAC virus deleted - quarantined
C:\WINDOWS\ServicePackFiles\i386\sndrec32.exe Win32/Sality.NAC virus deleted - quarantined
C:\WINDOWS\ServicePackFiles\i386\snmp.exe Win32/Sality.NAC virus deleted - quarantined
C:\WINDOWS\ServicePackFiles\i386\snmptrap.exe Win32/Sality.NAC virus deleted - quarantined
C:\WINDOWS\ServicePackFiles\i386\sort.exe Win32/Sality.NAC virus deleted - quarantined
C:\WINDOWS\ServicePackFiles\i386\spdwnwxp.exe Win32/Sality.NAC virus deleted - quarantined
C:\WINDOWS\ServicePackFiles\i386\spider.exe Win32/Sality.NAC virus deleted - quarantined
C:\WINDOWS\ServicePackFiles\i386\spiisupd.exe Win32/Sality.NAC virus deleted - quarantined
C:\WINDOWS\ServicePackFiles\i386\spnpinst.exe Win32/Sality.NAC virus deleted - quarantined
C:\WINDOWS\ServicePackFiles\i386\spoolsv.exe Win32/Sality.NAC virus deleted - quarantined
C:\WINDOWS\ServicePackFiles\i386\spupdwxp.exe Win32/Sality.NAC virus deleted - quarantined
C:\WINDOWS\ServicePackFiles\i386\ss3dfo.scr Win32/Sality.NAC virus deleted - quarantined
C:\WINDOWS\ServicePackFiles\i386\ssbezier.scr Win32/Sality.NAC virus deleted - quarantined
C:\WINDOWS\ServicePackFiles\i386\ssflwbox.scr Win32/Sality.NAC virus deleted - quarantined
C:\WINDOWS\ServicePackFiles\i386\ssmarque.scr Win32/Sality.NAC virus deleted - quarantined
C:\WINDOWS\ServicePackFiles\i386\ssmypics.scr Win32/Sality.NAC virus deleted - quarantined
C:\WINDOWS\ServicePackFiles\i386\ssmyst.scr Win32/Sality.NAC virus deleted - quarantined
C:\WINDOWS\ServicePackFiles\i386\sspipes.scr Win32/Sality.NAC virus deleted - quarantined
C:\WINDOWS\ServicePackFiles\i386\ssstars.scr Win32/Sality.NAC virus deleted - quarantined
C:\WINDOWS\ServicePackFiles\i386\sstext3d.scr Win32/Sality.NAC virus deleted - quarantined
C:\WINDOWS\ServicePackFiles\i386\stimon.exe Win32/Sality.NAC virus deleted - quarantined
C:\WINDOWS\ServicePackFiles\i386\stub_fpsrvadm.exe Win32/Sality.NAC virus deleted - quarantined
C:\WINDOWS\ServicePackFiles\i386\stub_fpsrvwin.exe Win32/Sality.NAC virus deleted - quarantined
C:\WINDOWS\ServicePackFiles\i386\svchost.exe Win32/Sality.NAC virus deleted - quarantined
C:\WINDOWS\ServicePackFiles\i386\sysinfo.exe Win32/Sality.NAC virus deleted - quarantined
C:\WINDOWS\ServicePackFiles\i386\sysocmgr.exe Win32/Sality.NAC virus deleted - quarantined
C:\WINDOWS\ServicePackFiles\i386\taskkill.exe Win32/Sality.NAC virus deleted - quarantined
C:\WINDOWS\ServicePackFiles\i386\tasklist.exe Win32/Sality.NAC virus deleted - quarantined
C:\WINDOWS\ServicePackFiles\i386\taskmgr.exe Win32/Sality.NAC virus deleted - quarantined
C:\WINDOWS\ServicePackFiles\i386\tcptest.exe Win32/Sality.NAC virus deleted - quarantined
C:\WINDOWS\ServicePackFiles\i386\telnet.exe Win32/Sality.NAC virus deleted - quarantined
C:\WINDOWS\ServicePackFiles\i386\tlntadmn.exe Win32/Sality.NAC virus deleted - quarantined
C:\WINDOWS\ServicePackFiles\i386\tlntsess.exe Win32/Sality.NAC virus deleted - quarantined
C:\WINDOWS\ServicePackFiles\i386\tlntsvr.exe Win32/Sality.NAC virus deleted - quarantined
C:\WINDOWS\ServicePackFiles\i386\tourstrt.exe Win32/Sality.NAC virus deleted - quarantined
C:\WINDOWS\ServicePackFiles\i386\tp4mon.exe Win32/Sality.NAC virus deleted - quarantined
C:\WINDOWS\ServicePackFiles\i386\tracerpt.exe Win32/Sality.NAC virus deleted - quarantined
C:\WINDOWS\ServicePackFiles\i386\tracert.exe Win32/Sality.NAC virus deleted - quarantined
C:\WINDOWS\ServicePackFiles\i386\tzchange.exe Win32/Sality.NAC virus deleted - quarantined
C:\WINDOWS\ServicePackFiles\i386\uploadm.exe Win32/Sality.NAC virus deleted - quarantined
C:\WINDOWS\ServicePackFiles\i386\upnpcont.exe Win32/Sality.NAC virus deleted - quarantined
C:\WINDOWS\ServicePackFiles\i386\ups.exe Win32/Sality.NAC virus deleted - quarantined
C:\WINDOWS\ServicePackFiles\i386\userinit.exe Win32/Sality.NAC virus deleted - quarantined
C:\WINDOWS\ServicePackFiles\i386\utilman.exe Win32/Sality.NAC virus deleted - quarantined
C:\WINDOWS\ServicePackFiles\i386\vbc.exe Win32/Sality.NAC virus deleted - quarantined
C:\WINDOWS\ServicePackFiles\i386\verclsid.exe Win32/Sality.NAC virus deleted - quarantined
C:\WINDOWS\ServicePackFiles\i386\vssvc.exe Win32/Sality.NAC virus deleted - quarantined
C:\WINDOWS\ServicePackFiles\i386\wab.exe Win32/Sality.NAC virus deleted - quarantined
C:\WINDOWS\ServicePackFiles\i386\wabmig.exe Win32/Sality.NAC virus deleted - quarantined
C:\WINDOWS\ServicePackFiles\i386\wbemtest.exe Win32/Sality.NAC virus deleted - quarantined
C:\WINDOWS\ServicePackFiles\i386\wextract.exe Win32/Sality.NAC virus deleted - quarantined
C:\WINDOWS\ServicePackFiles\i386\wiaacmgr.exe Win32/Sality.NAC virus deleted - quarantined
C:\WINDOWS\ServicePackFiles\i386\winhlp32.exe Win32/Sality.NAC virus deleted - quarantined
C:\WINDOWS\ServicePackFiles\i386\winver.exe Win32/Sality.NAC virus deleted - quarantined
C:\WINDOWS\ServicePackFiles\i386\wmiadap.exe Win32/Sality.NAC virus deleted - quarantined
C:\WINDOWS\ServicePackFiles\i386\wmiapsrv.exe Win32/Sality.NAC virus deleted - quarantined
C:\WINDOWS\ServicePackFiles\i386\wmic.exe Win32/Sality.NAC virus deleted - quarantined
C:\WINDOWS\ServicePackFiles\i386\wmiprvse.exe Win32/Sality.NAC virus deleted - quarantined
C:\WINDOWS\ServicePackFiles\i386\wordpad.exe Win32/Sality.NAC virus deleted - quarantined
C:\WINDOWS\ServicePackFiles\i386\wpabaln.exe Win32/Sality.NAC virus deleted - quarantined
C:\WINDOWS\ServicePackFiles\i386\wpnpinst.exe Win32/Sality.NAC virus deleted - quarantined
C:\WINDOWS\ServicePackFiles\i386\wscntfy.exe Win32/Sality.NAC virus deleted - quarantined
C:\WINDOWS\ServicePackFiles\i386\wscript.exe Win32/Sality.NAC virus deleted - quarantined
C:\WINDOWS\ServicePackFiles\i386\xcopy.exe Win32/Sality.NAC virus deleted - quarantined
C:\WINDOWS\ServicePackFiles\i386\xpnetdg.exe Win32/Sality.NAC virus deleted - quarantined
C:\WINDOWS\ServicePackFiles\i386\lang\cintsetp.exe Win32/Sality.NAC virus deleted - quarantined
C:\WINDOWS\ServicePackFiles\i386\lang\cplexe.exe Win32/Sality.NAC virus deleted - quarantined
C:\WINDOWS\ServicePackFiles\i386\lang\imjpdct.exe Win32/Sality.NAC virus deleted - quarantined
C:\WINDOWS\ServicePackFiles\i386\lang\imjpdsvr.exe Win32/Sality.NAC virus deleted - quarantined
C:\WINDOWS\ServicePackFiles\i386\lang\imjpinst.exe Win32/Sality.NAC virus deleted - quarantined
C:\WINDOWS\ServicePackFiles\i386\lang\imjpmig.exe Win32/Sality.NAC virus deleted - quarantined
C:\WINDOWS\ServicePackFiles\i386\lang\imjprw.exe Win32/Sality.NAC virus deleted - quarantined
C:\WINDOWS\ServicePackFiles\i386\lang\imjputy.exe Win32/Sality.NAC virus deleted - quarantined
C:\WINDOWS\ServicePackFiles\i386\lang\imscinst.exe Win32/Sality.NAC virus deleted - quarantined
C:\WINDOWS\ServicePackFiles\i386\lang\pintlphr.exe Win32/Sality.NAC virus deleted - quarantined
C:\WINDOWS\ServicePackFiles\i386\lang\tintlphr.exe Win32/Sality.NAC virus deleted - quarantined
C:\WINDOWS\ServicePackFiles\i386\lang\tintsetp.exe Win32/Sality.NAC virus deleted - quarantined
C:\WINDOWS\ServicePackFiles\ServicePackCache\i386\msmsgs.exe Win32/Sality.NAC virus deleted - quarantined
C:\WINDOWS\SoftwareDistribution\Download\0facce6115ab861022eae3087e064a2a\SP2QFE\xpnetdg.exe Win32/Sality.NAC virus deleted - quarantined
C:\WINDOWS\SoftwareDistribution\Download\97fe76a20161cb86e78057600e7c82a0\SP3GDR\ie4uinit.exe Win32/Sality.NAC virus deleted - quarantined
C:\WINDOWS\SoftwareDistribution\Download\97fe76a20161cb86e78057600e7c82a0\SP3QFE\ie4uinit.exe Win32/Sality.NAC virus deleted - quarantined
C:\WINDOWS\system32\hkcmd.exe Win32/Sality.NAC virus deleted - quarantined
C:\WINDOWS\system32\igfxpers.exe Win32/Sality.NAC virus deleted - quarantined
C:\WINDOWS\system32\igfxtray.exe Win32/Sality.NAC virus deleted - quarantined
C:\WINDOWS\system32\olemdb32.dll Win32/Sality.NAD virus deleted (after the next restart) - quarantined
C:\WINDOWS\system32\IME\CINTLGNT\CINTSETP.EXE Win32/Sality.NAC virus unable to clean
C:\WINDOWS\system32\IME\PINTLGNT\IMSCINST.EXE Win32/Sality.NAC virus unable to clean
C:\WINDOWS\system32\IME\PINTLGNT\pintlphr.exe Win32/Sality.NAC virus unable to clean
C:\WINDOWS\system32\IME\TINTLGNT\tintlphr.exe Win32/Sality.NAC virus unable to clean
C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE Win32/Sality.NAC virus unable to clean


Some important files were deleted/quarantined.
I'm afraid to restart.

What do I restore!? :[

Edited by ZlobIsFun, 15 January 2010 - 03:00 AM.


#10 Elise

Elise

    Bleepin' Blonde


  • Malware Study Hall Admin
  • 61,252 posts
  • OFFLINE
  •  
  • Gender:Female
  • Location:Romania
  • Local time:06:50 AM

Posted 15 January 2010 - 03:06 AM

Ouch, thats not good ohmy.gif

I think you should be able to reboot, no critical files were deleted, but you might get a few errors on start up.

The problem with Sality is that it can't really be cured....

Please see ThreatExpert's awareness of Win32.Sality.

Sality Family is a family of a polymorphic file infectors which infects .exe, .scr files, downloads more malicious files to your computer, steals sensitive system information/passwords and sends it back to the attacker.

With this particular infection, the safest solution and only sure way to remove it effectively is to reformat and reinstall the OS.

QUOTE
As with many other malware, Sality disables antivirus software and prevents access to certain antivirus and security websites. Sality can also prevent booting into Safe Mode and may delete security-related files found on infected systems. To spread via the autorun component, Sality generally drops a .cmd, .pif, and .exe to the root of discoverable drives, along with an autorun.inf file which contains instructions to load the dropped file(s) when the drive is accessed.
About Sality Virus

If the computer was used for online banking, has credit card information or other sensitive data on it, you should disconnect from the Internet until your system is cleaned. All passwords should be changed immediately to include those used for banking, email, eBay, paypal and online forums. You should consider them to be compromised. You should change each password using a clean computer and not the infected one. If not, an attacker may get the new passwords and transaction information. If using a router, you need to reset it with a strong logon/password so the malware cannot gain control before connect again. Banking and credit card institutions should be notified of the possible security breach.

Sality/Win32.Sector is not effectively disinfectable. Your best option is to perform a full reformat as there is no guarantee this infection can be completely removed. In most instances it may have caused so much damage to your system files that it cannot be completely cleaned or repaired. In many cases the infected files cannot be deleted and anti-malware scanners cannot disinfect them properly. Many experts in the security community believe that once infected with this type of malware, the best course of action is to wipe the drive clean, reformat and reinstall the OS. Reinstalling Windows without first wiping the entire hard drive with a repartition and/or format will not remove the infection. The reinstall will only overwrite the Windows files. Any malware on the system will still be there afterwards. Please read:

regards, Elise


"Now faith is the substance of things hoped for, the evidence of things not seen."

 

Follow BleepingComputer on: Facebook | Twitter | Google+ | lockerdome

 

Malware analyst @ Emsisoft


#11 ZlobIsFun

ZlobIsFun
  • Topic Starter

  • Members
  • 92 posts
  • OFFLINE
  •  
  • Local time:09:50 PM

Posted 15 January 2010 - 05:18 AM

Well if I keep the infected files quarantined/deleted, will my system be okay? Or are there still other files that are infected by sality?

Edited by ZlobIsFun, 15 January 2010 - 05:43 AM.


#12 Elise

Elise

    Bleepin' Blonde


  • Malware Study Hall Admin
  • 61,252 posts
  • OFFLINE
  •  
  • Gender:Female
  • Location:Romania
  • Local time:06:50 AM

Posted 15 January 2010 - 05:56 AM

Problem is that your system needs all those files. These are not bad files, they are bad because they have Sality code injected. Even if you use an Antivirus program that can clean all those files, once the malicious code is removed, those file remain corrupt because parts of their original code is overwritten.

It really is a pity because last time you ran Combofix, this was not yet active on your system.

regards, Elise


"Now faith is the substance of things hoped for, the evidence of things not seen."

 

Follow BleepingComputer on: Facebook | Twitter | Google+ | lockerdome

 

Malware analyst @ Emsisoft


#13 ZlobIsFun

ZlobIsFun
  • Topic Starter

  • Members
  • 92 posts
  • OFFLINE
  •  
  • Local time:09:50 PM

Posted 15 January 2010 - 05:00 PM

It happened AFTER combofix? Whaaaat? This was preventable? Were we too slow?
I need the files? You said I could restart? I haven't restarted my computer since aa. I'm afraid to; I tried to use my windows XP Home disk and a few files are corrupt from the scratches.

#14 Elise

Elise

    Bleepin' Blonde


  • Malware Study Hall Admin
  • 61,252 posts
  • OFFLINE
  •  
  • Gender:Female
  • Location:Romania
  • Local time:06:50 AM

Posted 16 January 2010 - 02:51 AM

QUOTE
It happened AFTER combofix? Whaaaat? This was preventable? Were we too slow?
Sorry if I didn't explain it right, the infection hadn't spread so far when we ran Combofix. Its impossible to say when you got infected. It could have been a flashdrive, it could have been something you downloaded, it could have been something the malware already on your system downloaded.

The only option really is a reformat. And even then, be extremely careful with backups, because even one infected file is enough to spread it again through your whole system.

I am really sorry for this, but as explained in an earlier post, there really isn't anything to do about.

regards, Elise


"Now faith is the substance of things hoped for, the evidence of things not seen."

 

Follow BleepingComputer on: Facebook | Twitter | Google+ | lockerdome

 

Malware analyst @ Emsisoft


#15 ZlobIsFun

ZlobIsFun
  • Topic Starter

  • Members
  • 92 posts
  • OFFLINE
  •  
  • Local time:09:50 PM

Posted 16 January 2010 - 04:56 AM

QUOTE(elise025 @ Jan 16 2010, 02:51 AM) View Post
QUOTE
It happened AFTER combofix? Whaaaat? This was preventable? Were we too slow?
Sorry if I didn't explain it right, the infection hadn't spread so far when we ran Combofix. Its impossible to say when you got infected. It could have been a flashdrive, it could have been something you downloaded, it could have been something the malware already on your system downloaded.

The only option really is a reformat. And even then, be extremely careful with backups, because even one infected file is enough to spread it again through your whole system.

I am really sorry for this, but as explained in an earlier post, there really isn't anything to do about.

My flash drive was infected! I just remembered I had files from my old infected computer in it.. The whole importance folder that appeared on the sality infection was from the flash drive.
Can I just remove everything/reformat the flash drive and all will be good?
I'll be reinstalling my system very soon, I just restarted my computer. :] Everything seems fine, this is a gaming computer! I do banking on my netbook - THANKFULLY I realized it was the flash drive, thanks for mentioning it!

You can close the thread, your help is very appreciated, thank you for your time and happy days. :]




0 user(s) are reading this topic

0 members, 0 guests, 0 anonymous users