Jump to content


 


Register a free account to unlock additional features at BleepingComputer.com
Welcome to BleepingComputer, a free community where people like yourself come together to discuss and learn how to use their computers. Using the site is easy and fun. As a guest, you can browse and view the various discussions in the forums, but can not create a new topic or reply to an existing one unless you are logged in. Other benefits of registering an account are subscribing to topics and forums, creating a blog, and having no ads shown anywhere on the site.


Click here to Register a free account now! or read our Welcome Guide to learn how to use this site.

Photo

PC restarts when choosing account


  • Please log in to reply
31 replies to this topic

#1 Epacific

Epacific

  • Members
  • 17 posts
  • OFFLINE
  •  
  • Local time:06:08 PM

Posted 23 May 2010 - 04:43 PM

Hello world,

- A freshly minted newbie here so please be gentle :thumbsup:.

I've tried to follow the guidelines to the best of my abilities but I apologize if I missed anything- checking existing topics, I didn't find anything that exactly fit by subject so, here goes.

Yesterday evening, I came down to our basement PC to find that it was locked up - more specifically, screen was black except for numerous chinese-looking pop-ups. The computer was non-responsive so I did a hard-boot.

Upon re-starting, it comes up to the normal XP account screen (where one chooses which account to use). Up to here, all seems normal. But choosing the accounts leads to the following:
1) I'll call this account "Acct RT". This is the normal administrative account. Selecting this one causes the PC to restart. Initially, it made it to the point where I could see my wallpaper (and nothing else) and then the PC would restart. Now, it doesn't even make it that far: from the account screen, I immediately go down.
2) I'll this account "Acct BR". This one is interesting. Initially it came up with only the wallpaper and a "Loading Personal Settings" pop-up. And that was it- it would just hang. Well, I started with this account since at least it gave me chance to try something before the PC went down. Using Ctrl-Alt-Del, and selecting "Logoff" from the Users Tab, I was able to somehow get the files on the desktop to come up. I then ran Malwarebytes' Anti-Malware which removed 355 virus files. I then tried to restart with Acct RT but it still simply rebooted again. From Acct BR, I ran MBAM again and got something on the order of another 122 files.

I would post the logs but the computer does not let me navigate to any folders (MBAM was sitting on the desktop so I was able to access it). MS Explorer is dead - it comes up but selecting any of the drives doesn't do anything.

So, I came across this website in my search and tried the following based on a similar problem that someone else here had:
- I downloaded and ran ATF-Cleaner in Safe Mode (on Acct BR; the other account was still causing re-boots even when selected in safe mode)
- I downloaded SuperAnti-Spyware and tried to install it in normal mode but it kept crashing with a "this problem has experienced and will now close". It appeared to semi-install, meaning it created an icon for the program but attempting to run it didn't work - ran into the same message.

For what it's worth, the computer still has access to the internet. Other than that, when I'm in normal mode in Acct BR, a pop-up with "ERROR! Corrupt Data!" keeps coming up (and the hard drive makes a belaboured chunking noise). Neither of these happen in Safe Mode. If I leave the computer up long enough, I get barraged with numerous Korean & Chinese pop-ups.

I am running XP Home Edition SP2 Build 2600 on a Sony PCV-RZ24G. I run Norton but it expired a bit back and didn't have the latest updates. Other than that, I occasionally run MBAM. I've never had anything like this happen before.

I'm sorry I couldn't provide any of the logs. I'll look into it to see if I can do anything about accessing and posting those files. I do know that, among the hundreds of others, there was also Trojan.Dropper & Trojan.Downloader. Nothing new has been installed on this computer (at least not intentionally).

At this point, I'm happy that I can atleast access the desktop. But I need to back everything up to back up all the important files (pictures, movies, etc) and, if worse comes to worse, I have the Sony "Recovery Disks" but, according to the documentation, this will return me to the factory settings, minus all my precious data (my bad- used to back up on zip disks ages ago and never got a proper back-up drive).

But, my hope is that I can avoid such drastic action. Any and all help would be much appreciated.

Thanks again,
Epacific

Edited by Budapest, 23 May 2010 - 05:36 PM.
Moved from XP ~BP


BC AdBot (Login to Remove)

 


#2 Budapest

Budapest

    Bleepin' Cynic


  • Moderator
  • 23,573 posts
  • OFFLINE
  •  
  • Gender:Male
  • Local time:08:08 AM

Posted 28 May 2010 - 07:10 PM

Before we start fixing anything you should print out these instructions or copy them to a NotePad file so they will be accessible. Some steps will require you to disconnect from the Internet or use Safe Mode and you will not have access to this page.

Please download Dr.Web CureIt and save it to your desktop. DO NOT perform a scan yet.
alternate download link
Note: The file will be randomly named (i.e. 5mkuvc4z.exe).

Reboot your computer in "Safe Mode" using the F8 method. To do this, restart your computer and after hearing your computer beep once during startup (but before the Windows icon appears) press the F8 key repeatedly. A menu will appear with several options. Use the arrow keys to navigate and select the option to run Windows in "Safe Mode".

Scan with Dr.Web CureIt as follows:
  • Double-click on the randomly named file to open the program and click Start. (There is no need to update if you just downloaded the most current version
  • Read the Virus check by DrWeb scanner prompt and click Ok where asked to Start scan now? Allow the setup.exe to load if asked by any of your security programs.
  • The Express scan will automatically begin.
    (This is a short scan of files currently running in memory, boot sectors, and targeted folders).
  • If prompted to dowload the Full version Free Trial, ignore and click the X to close the window.
  • If an infected object is found, you will be prompted to move anything that cannot be cured. Click Yes to All. (This will move any detected files to the C:\Documents and Settings\userprofile\DoctorWeb\Quarantine folder if they can't be cured)
  • After the Express Scan is finished, put a check next to Complete scan to scan all local disks and removable media.
  • In the top menu, click Settings > Change settings, and uncheck "Heuristic analysis" under the "Scanning" tab, then click Apply, Ok.
  • Back at the main window, click the green arrow "Start Scanning" button on the right under the Dr.Web logo.
  • Please be patient as this scan could take a long time to complete.
  • When the scan has finished, a message will be displayed at the bottom indicating if any viruses were found.
  • Click Select All, then choose Cure > Move incurable.
  • In the top menu, click file and choose save report list.
  • Save the DrWeb.csv report to your desktop.
  • Exit Dr.Web Cureit when done.
  • Important! Reboot your computer because it could be possible that files in use will be moved/deleted during reboot.
  • After reboot, post the contents of the log from Dr.Web in your next reply. (You can use Notepad to open the DrWeb.cvs report)

The power of accurate observation is commonly called cynicism by those who haven't got it.

—George Bernard Shaw

#3 Epacific

Epacific
  • Topic Starter

  • Members
  • 17 posts
  • OFFLINE
  •  
  • Local time:06:08 PM

Posted 29 May 2010 - 11:57 AM

Budapest,

Thanks for the detailed response. Here is a description of what happened:

1. I downloaded Dr.Web CureIt
2. I rebooted my computer in Safe Mode. However, my desktop in Safe Mode did not have the downloaded file (ever since the infection, the icons listed in Safe Mode & Normal Mode do not match up one to one).
3. I rebooted my computer in Safe Mode with Networking. While in this mode, I downloaded Dr.Web CureIt using the first link you provided.
4. I double clicked on the randomly named downloaded file. When I click Start (on the Dr.Web CureIt interface), my entire PC reboots.
5. Thinking that this may be caused by the virus while having access to the internet, I restarted my PC in Safe Mode (without access to the internet).
6. I tried re-starting Dr.Web CureIt and got the same response: it re-started my PC.
7. I then deleted this downloaded file and re-downloaded Dr.Web CureIt using the alternative link you provided ("alternate download link"). I tried starting the the program but it kept saying that the registration key is expired. At least this file actually brought up the Dr.Web CureIt GUI (though it won't let do anything as it insists that I buy a version that has an updated registration key).

Is it possible that the virus is aware of this anti-malware program and prevents it from running?

Thanks,
Epacific

#4 Budapest

Budapest

    Bleepin' Cynic


  • Moderator
  • 23,573 posts
  • OFFLINE
  •  
  • Gender:Male
  • Local time:08:08 AM

Posted 29 May 2010 - 05:39 PM

Is it possible that the virus is aware of this anti-malware program and prevents it from running?

Yes this is possible.

If you have access to another computer you could make a DrWebCureIt live CD to run the scan.

http://www.freedrweb.com/livecd/

Instructions here: http://www.freedrweb.com/livecd/how_it_works/

Normally the scan takes a very long time, several hours at least.
The power of accurate observation is commonly called cynicism by those who haven't got it.

—George Bernard Shaw

#5 Epacific

Epacific
  • Topic Starter

  • Members
  • 17 posts
  • OFFLINE
  •  
  • Local time:06:08 PM

Posted 01 June 2010 - 07:40 PM

Budapest,

Just a short update to keep you abreast of my progress. I created the Dr. WebLiveCD and began running the program. Unfortunately, my computer appears to shut down prior to completion of the scan. I'm wondering if it's because the hard drive is set to go to standby mode after five hours.

So, I tried to change the setting (in Windows) such that the hard drive never shuts down. Unfortunately, however, after the virus infection, I no longer have any administrator rights and it says "access denied".

I then went to Safe Mode where I was able to change the setting of the hard drive. I then ran off of the bootable CD and selected option 'Dr.Web LiveCD (Safe Mode)'. I then selected 'Start Scan' which ran. I'm not sure if this was a limited scan but it took a fairly short amount of time.

I then tried running 'Dr.Web LiveCD (Default)' after rebooting again but I ran into the same problem: the computer appears to shut down before the scan is complete.

I'm going to try it again but, this time, only run it on the C: drive (versus also the D: drive which is larger). That way, it will hopefully run to completion and I can post the results of the scan here.

Thanks,
Epacific

#6 Epacific

Epacific
  • Topic Starter

  • Members
  • 17 posts
  • OFFLINE
  •  
  • Local time:06:08 PM

Posted 02 June 2010 - 01:15 AM

Budapest,

I was able to successfully run Dr.Web LiveCD on just my C: drive. It has detected 400+ infected files and I selected the "Cure" button and it has deleted them.

However, unless I'm mistaken, the CD version is different from the normal version of the program in its ability to log a file. After running the scan (and deleting the infected files), I went into the advanced options to try and save the log file. However, it looks like you simply specify where the log file should be kept - something that should have been done before I started the scan (which took 4 hours and 45 minutes to run). I cannot find an existing log file for the current scan - in other words, I don't think a log file has been generated since I didn't specify to do so ahead of time. Also, the interface does not allow me to do a copy/paste (or a print screen) into a file.

Do you know of any way that I can capture the data for me to place in this post? Again, it looks like a "scanner.log" file would have been generated had I specified it prior to my having run the scan. It's a bit frustrating as I can see the list of infected files in the Dr. Web GUI but I have no way to post it here for you to see. I will leave the interface up for now (and hopefully the hard drive won't shut off again while I go hit the sack for tonight). If I hear from you by tomorrow morning and you have another means by which to post the log file, I will and try and do so.

Otherwise, I will specify the log file to be generated for the next scan which will be for the D: drive and then I will run a scan on that. This may take some considerable time as the drive is much larger than the primary drive which, again took nearly five hours- and I kept moving the mouse every fifteen minutes or so in the hope that the drive wouldn't shut down (not sure if that helped or simply the fact that it took less than 5 hours).

For what it's worth, the log shows a majority of the following type of files:
Trojan.PWS.Wsgame.64067
Trojan.PWS.Wsgame.20047
Trojan.PWS.Wsgame.19855

Gotta sleep.
Epacific

#7 Epacific

Epacific
  • Topic Starter

  • Members
  • 17 posts
  • OFFLINE
  •  
  • Local time:06:08 PM

Posted 02 June 2010 - 01:41 AM

Budapest,

Please ignore my confusion regarding the log file in the previous post. It had apparently generated the log file but I simply wasn't able to find it at first in my sleepy-state. Here's what the log file contained after the scan of my C: drive:

Report dated 2010-06-02, 01:32:10
Command line: -cu -@+/tmp/drweb_scanner.rl9rSf -ini=/tmp/drweb_conf.MPfXr1
Invalid line in INI-file 59
Invalid line in INI-file 63
Invalid line in INI-file 71
Invalid line in INI-file 72
Invalid line in INI-file 93
Invalid line in INI-file 94
Invalid line in INI-file 99
Invalid line in INI-file 102
Shell version: 5.0.0.10060 <API:2.2>
Engine version: 5.0.2.3300 <API:2.2>
Loading /root/.drweb/local-bases/drwtoday.vdb - Ok, virus records: 5187
Loading /root/.drweb/local-bases/drwdaily.vdb - Ok, virus records: 25840
Loading /root/.drweb/local-bases/drw50026.vdb - Ok, virus records: 18281
Loading /root/.drweb/local-bases/drw50025.vdb - Ok, virus records: 18009
Loading /root/.drweb/local-bases/drw50024.vdb - Ok, virus records: 24685
Loading /root/.drweb/local-bases/drw50023.vdb - Ok, virus records: 13715
Loading /root/.drweb/local-bases/drw50022.vdb - Ok, virus records: 16025
Loading /root/.drweb/local-bases/drw50021.vdb - Ok, virus records: 15644
Loading /root/.drweb/local-bases/drw50020.vdb - Ok, virus records: 23265
Loading /root/.drweb/local-bases/drw50019.vdb - Ok, virus records: 23135
Loading /root/.drweb/local-bases/drw50018.vdb - Ok, virus records: 20510
Loading /root/.drweb/local-bases/drw50017.vdb - Ok, virus records: 25475
Loading /root/.drweb/local-bases/drw50016.vdb - Ok, virus records: 16298
Loading /root/.drweb/local-bases/drw50015.vdb - Ok, virus records: 19357
Loading /root/.drweb/local-bases/drw50014.vdb - Ok, virus records: 18381
Loading /root/.drweb/local-bases/drw50013.vdb - Ok, virus records: 19562
Loading /root/.drweb/local-bases/drw50012.vdb - Ok, virus records: 27102
Loading /root/.drweb/local-bases/drw50011.vdb - Ok, virus records: 21223
Loading /root/.drweb/local-bases/drw50010.vdb - Ok, virus records: 26228
Loading /root/.drweb/local-bases/drw50009.vdb - Ok, virus records: 23251
Loading /root/.drweb/local-bases/drw50008.vdb - Ok, virus records: 14982
Loading /root/.drweb/local-bases/drw50007.vdb - Ok, virus records: 17748
Loading /root/.drweb/local-bases/drw50006.vdb - Ok, virus records: 18725
Loading /root/.drweb/local-bases/drw50005.vdb - Ok, virus records: 18429
Loading /root/.drweb/local-bases/drw50004.vdb - Ok, virus records: 872
Loading /root/.drweb/local-bases/drw50003.vdb - Ok, virus records: 142240
Loading /root/.drweb/local-bases/drw50002.vdb - Ok, virus records: 66726
Loading /root/.drweb/local-bases/drw50001.vdb - Ok, virus records: 24512
Loading /root/.drweb/local-bases/drw50000.vdb - Ok, virus records: 82762
Loading /root/.drweb/local-bases/drwebase.vdb - Ok, virus records: 514157
Loading /root/.drweb/local-bases/dwrtoday.vdb - Ok, virus records: 1313
Loading /root/.drweb/local-bases/dwr50006.vdb - Ok, virus records: 1812
Loading /root/.drweb/local-bases/dwr50005.vdb - Ok, virus records: 1738
Loading /root/.drweb/local-bases/dwr50004.vdb - Ok, virus records: 1885
Loading /root/.drweb/local-bases/dwr50003.vdb - Ok, virus records: 2091
Loading /root/.drweb/local-bases/dwr50002.vdb - Ok, virus records: 1569
Loading /root/.drweb/local-bases/dwr50001.vdb - Ok, virus records: 1834
Loading /root/.drweb/local-bases/dwntoday.vdb - Ok, virus records: 2327
Loading /root/.drweb/local-bases/dwn50014.vdb - Ok, virus records: 2241
Loading /root/.drweb/local-bases/dwn50013.vdb - Ok, virus records: 2596
Loading /root/.drweb/local-bases/dwn50012.vdb - Ok, virus records: 2024
Loading /root/.drweb/local-bases/dwn50011.vdb - Ok, virus records: 1609
Loading /root/.drweb/local-bases/dwn50010.vdb - Ok, virus records: 1471
Loading /root/.drweb/local-bases/dwn50009.vdb - Ok, virus records: 1445
Loading /root/.drweb/local-bases/dwn50008.vdb - Ok, virus records: 1895
Loading /root/.drweb/local-bases/dwn50007.vdb - Ok, virus records: 2312
Loading /root/.drweb/local-bases/dwn50006.vdb - Ok, virus records: 3006
Loading /root/.drweb/local-bases/dwn50005.vdb - Ok, virus records: 2146
Loading /root/.drweb/local-bases/dwn50004.vdb - Ok, virus records: 1714
Loading /root/.drweb/local-bases/dwn50003.vdb - Ok, virus records: 2095
Loading /root/.drweb/local-bases/dwn50002.vdb - Ok, virus records: 2715
Loading /root/.drweb/local-bases/dwn50001.vdb - Ok, virus records: 2545
Loading /root/.drweb/local-bases/dwn50000.vdb - Ok, virus records: 2801
Loading /root/.drweb/local-bases/drwrisky.vdb - Ok, virus records: 6197
Loading /root/.drweb/local-bases/drwnasty.vdb - Ok, virus records: 28348
Total virus records: 1384055
Key file: /opt/drweb/drweb32.key
License key number: 0014100132
License key activates: 2010-03-03
License key expires: 2013-04-07
/mnt/disk/hda1/EasyTime.exe infected with Trojan.DownLoad.64067
/mnt/disk/hda1/EasyTime.exe - deleted!
/mnt/disk/hda1/SafeDrv.exe packed by FSG
>/mnt/disk/hda1/SafeDrv.exe infected with Trojan.MulDrop.origin
>/mnt/disk/hda1/SafeDrv.exe - archive BINARYRES
>>/mnt/disk/hda1/SafeDrv.exe/data001 packed by XOREXE
>>>/mnt/disk/hda1/SafeDrv.exe/data001 infected with Trojan.NtRootKit.2909
/mnt/disk/hda1/Documents and Settings/Administrator/Application Data/Dg32.bak packed by UPACK
>/mnt/disk/hda1/Documents and Settings/Administrator/Application Data/Dg32.bak infected with Trojan.PWS.Qqpass.4551
>/mnt/disk/hda1/Documents and Settings/Administrator/Application Data/Dg32.bak - deleted!
/mnt/disk/hda1/Documents and Settings/Administrator/Application Data/Dg32.Sys packed by UPX
>/mnt/disk/hda1/Documents and Settings/Administrator/Application Data/Dg32.Sys infected with Trojan.PWS.Gamania.25318
>/mnt/disk/hda1/Documents and Settings/Administrator/Application Data/Dg32.Sys - deleted!
/mnt/disk/hda1/Documents and Settings/Administrator/Application Data/Dg32.Tmp packed by UPX
>/mnt/disk/hda1/Documents and Settings/Administrator/Application Data/Dg32.Tmp infected with Trojan.PWS.Gamania.25318
>/mnt/disk/hda1/Documents and Settings/Administrator/Application Data/Dg32.Tmp - deleted!
/mnt/disk/hda1/Documents and Settings/Administrator/Local Settings/Temp/120090015.dll infected with Trojan.PWS.Wsgame.20660
/mnt/disk/hda1/Documents and Settings/Administrator/Local Settings/Temp/120090015.dll - deleted!
/mnt/disk/hda1/Documents and Settings/Administrator/Local Settings/Temp/120105312.dll infected with Trojan.PWS.Wsgame.20660
/mnt/disk/hda1/Documents and Settings/Administrator/Local Settings/Temp/120105312.dll - deleted!
/mnt/disk/hda1/Documents and Settings/Administrator/Local Settings/Temp/120111296.dll infected with Trojan.PWS.Wsgame.20660
/mnt/disk/hda1/Documents and Settings/Administrator/Local Settings/Temp/120111296.dll - deleted!
/mnt/disk/hda1/Documents and Settings/Administrator/Local Settings/Temp/121892421.dll infected with Trojan.PWS.Wsgame.20660
/mnt/disk/hda1/Documents and Settings/Administrator/Local Settings/Temp/121892421.dll - deleted!
/mnt/disk/hda1/Documents and Settings/Administrator/Local Settings/Temp/121894000.dll infected with Trojan.PWS.Wsgame.20660
/mnt/disk/hda1/Documents and Settings/Administrator/Local Settings/Temp/121894000.dll - deleted!
/mnt/disk/hda1/Documents and Settings/Administrator/Local Settings/Temp/123694843.dll infected with Trojan.PWS.Wsgame.20660
/mnt/disk/hda1/Documents and Settings/Administrator/Local Settings/Temp/123694843.dll - deleted!
/mnt/disk/hda1/Documents and Settings/Administrator/Local Settings/Temp/123703421.dll infected with Trojan.PWS.Wsgame.20660
/mnt/disk/hda1/Documents and Settings/Administrator/Local Settings/Temp/123703421.dll - deleted!
/mnt/disk/hda1/Documents and Settings/Administrator/Local Settings/Temp/125499125.dll infected with Trojan.PWS.Wsgame.20660
/mnt/disk/hda1/Documents and Settings/Administrator/Local Settings/Temp/125499125.dll - deleted!
/mnt/disk/hda1/Documents and Settings/Administrator/Local Settings/Temp/125507109.dll infected with Trojan.PWS.Wsgame.20660
/mnt/disk/hda1/Documents and Settings/Administrator/Local Settings/Temp/125507109.dll - deleted!
/mnt/disk/hda1/Documents and Settings/Administrator/Local Settings/Temp/127300203.dll infected with Trojan.PWS.Wsgame.20660
/mnt/disk/hda1/Documents and Settings/Administrator/Local Settings/Temp/127300203.dll - deleted!
/mnt/disk/hda1/Documents and Settings/Administrator/Local Settings/Temp/127304468.dll infected with Trojan.PWS.Wsgame.20660
/mnt/disk/hda1/Documents and Settings/Administrator/Local Settings/Temp/127304468.dll - deleted!
/mnt/disk/hda1/Documents and Settings/Administrator/Local Settings/Temp/129090734.dll infected with Trojan.PWS.Wsgame.20660
/mnt/disk/hda1/Documents and Settings/Administrator/Local Settings/Temp/129090734.dll - deleted!
/mnt/disk/hda1/Documents and Settings/Administrator/Local Settings/Temp/129096312.dll infected with Trojan.PWS.Wsgame.20660
/mnt/disk/hda1/Documents and Settings/Administrator/Local Settings/Temp/129096312.dll - deleted!
/mnt/disk/hda1/Documents and Settings/Administrator/Local Settings/Temp/130886906.dll infected with Trojan.PWS.Wsgame.20660
/mnt/disk/hda1/Documents and Settings/Administrator/Local Settings/Temp/130886906.dll - deleted!
/mnt/disk/hda1/Documents and Settings/Administrator/Local Settings/Temp/130906906.dll infected with Trojan.PWS.Wsgame.20660
/mnt/disk/hda1/Documents and Settings/Administrator/Local Settings/Temp/130906906.dll - deleted!
/mnt/disk/hda1/Documents and Settings/Administrator/Local Settings/Temp/132693640.dll infected with Trojan.PWS.Wsgame.20660
/mnt/disk/hda1/Documents and Settings/Administrator/Local Settings/Temp/132693640.dll - deleted!
/mnt/disk/hda1/Documents and Settings/Administrator/Local Settings/Temp/132702171.dll infected with Trojan.PWS.Wsgame.20660
/mnt/disk/hda1/Documents and Settings/Administrator/Local Settings/Temp/132702171.dll - deleted!
/mnt/disk/hda1/Documents and Settings/Administrator/Local Settings/Temp/134498875.dll infected with Trojan.PWS.Wsgame.20660
/mnt/disk/hda1/Documents and Settings/Administrator/Local Settings/Temp/134498875.dll - deleted!
/mnt/disk/hda1/Documents and Settings/Administrator/Local Settings/Temp/136297703.dll infected with Trojan.PWS.Wsgame.20660
/mnt/disk/hda1/Documents and Settings/Administrator/Local Settings/Temp/136297703.dll - deleted!
/mnt/disk/hda1/Documents and Settings/Administrator/Local Settings/Temp/mh.dll infected with Trojan.PWS.Wsgame.20660
/mnt/disk/hda1/Documents and Settings/Administrator/Local Settings/Temp/mh.dll - deleted!
/mnt/disk/hda1/Documents and Settings/Bhakta Rana/Local Settings/Temp/haodh956705.com infected with Trojan.SpyBot.11
/mnt/disk/hda1/Documents and Settings/Bhakta Rana/Local Settings/Temp/haodh956705.com - deleted!
/mnt/disk/hda1/Documents and Settings/Bhakta Rana/Local Settings/Temp/res77.tmp contains an advertising software Adware.nCase
/mnt/disk/hda1/Documents and Settings/Bhakta Rana/Local Settings/Temporary Internet Files/Content.IE5/GIR47IOI/server[1].exe infected with Trojan.DownLoad.64068
/mnt/disk/hda1/Documents and Settings/Bhakta Rana/Local Settings/Temporary Internet Files/Content.IE5/GIR47IOI/server[1].exe - deleted!
/mnt/disk/hda1/Documents and Settings/Bhakta Rana/Local Settings/Temporary Internet Files/Content.IE5/LXHLX6ZR/9001[1].exe infected with Trojan.SpyBot.11
/mnt/disk/hda1/Documents and Settings/Bhakta Rana/Local Settings/Temporary Internet Files/Content.IE5/LXHLX6ZR/9001[1].exe - deleted!
/mnt/disk/hda1/Documents and Settings/Bhakta Rana/My Documents/Youdao/Dict/EasyTime.exe infected with Trojan.DownLoad.64067
/mnt/disk/hda1/Documents and Settings/Bhakta Rana/My Documents/Youdao/Dict/EasyTime.exe - deleted!
/mnt/disk/hda1/Documents and Settings/Bhakta Rana/My Documents/Youdao/Dict/rundict.exe infected with Trojan.Starter.398
/mnt/disk/hda1/Documents and Settings/Bhakta Rana/My Documents/Youdao/Dict/rundict.exe - cured!
/mnt/disk/hda1/Documents and Settings/Bhakta Rana/My Documents/Youdao/Dict/rundict.exe - Ok
/mnt/disk/hda1/Documents and Settings/Rajeev Thapa/Application Data/Dns32.sys infected with Trojan.PWS.Gamania.25454
/mnt/disk/hda1/Documents and Settings/Rajeev Thapa/Application Data/Dns32.sys - deleted!
/mnt/disk/hda1/Documents and Settings/Rajeev Thapa/Local Settings/Temp/106554265.dll infected with Trojan.PWS.Gamania.25724
/mnt/disk/hda1/Documents and Settings/Rajeev Thapa/Local Settings/Temp/106554265.dll - deleted!
/mnt/disk/hda1/Documents and Settings/Rajeev Thapa/Local Settings/Temp/116518406.dll infected with Trojan.PWS.Wow.1815
/mnt/disk/hda1/Documents and Settings/Rajeev Thapa/Local Settings/Temp/116518406.dll - deleted!
/mnt/disk/hda1/Documents and Settings/Rajeev Thapa/Local Settings/Temp/136520156.dll infected with Trojan.PWS.Gamania.25900
/mnt/disk/hda1/Documents and Settings/Rajeev Thapa/Local Settings/Temp/136520156.dll - deleted!
/mnt/disk/hda1/Documents and Settings/Rajeev Thapa/Local Settings/Temp/146526984.dll infected with Trojan.PWS.Wsgame.20867
/mnt/disk/hda1/Documents and Settings/Rajeev Thapa/Local Settings/Temp/146526984.dll - deleted!
/mnt/disk/hda1/Documents and Settings/Rajeev Thapa/Local Settings/Temp/176538921.dll infected with Trojan.PWS.Gamania.25791
/mnt/disk/hda1/Documents and Settings/Rajeev Thapa/Local Settings/Temp/176538921.dll - deleted!
/mnt/disk/hda1/Documents and Settings/Rajeev Thapa/Local Settings/Temp/186536109.dll infected with Trojan.PWS.Wsgame.20660
/mnt/disk/hda1/Documents and Settings/Rajeev Thapa/Local Settings/Temp/186536109.dll - deleted!
/mnt/disk/hda1/Documents and Settings/Rajeev Thapa/Local Settings/Temp/186556593.dll infected with Trojan.PWS.Wsgame.20660
/mnt/disk/hda1/Documents and Settings/Rajeev Thapa/Local Settings/Temp/186556593.dll - deleted!
/mnt/disk/hda1/Documents and Settings/Rajeev Thapa/Local Settings/Temp/Rem23.exe packed by PORNOPACK
>/mnt/disk/hda1/Documents and Settings/Rajeev Thapa/Local Settings/Temp/Rem23.exe contains an advertising software Adware.Lop.origin
>/mnt/disk/hda1/Documents and Settings/Rajeev Thapa/Local Settings/Temp/Rem23.exe - archive BINARYRES
>>/mnt/disk/hda1/Documents and Settings/Rajeev Thapa/Local Settings/Temp/Rem23.exe/data001 infected with Trojan.Isbar.547
>>/mnt/disk/hda1/Documents and Settings/Rajeev Thapa/Local Settings/Temp/Rem23.exe/data002 - archive HTML
>>>/mnt/disk/hda1/Documents and Settings/Rajeev Thapa/Local Settings/Temp/Rem23.exe/data002/Script.0 - Ok
>>/mnt/disk/hda1/Documents and Settings/Rajeev Thapa/Local Settings/Temp/Rem23.exe/data002 - Ok
>>/mnt/disk/hda1/Documents and Settings/Rajeev Thapa/Local Settings/Temp/Rem23.exe/data003 - archive HTML
>>>/mnt/disk/hda1/Documents and Settings/Rajeev Thapa/Local Settings/Temp/Rem23.exe/data003/Script.0 - Ok
>>/mnt/disk/hda1/Documents and Settings/Rajeev Thapa/Local Settings/Temp/Rem23.exe/data003 - Ok
/mnt/disk/hda1/Documents and Settings/Rajeev Thapa/Local Settings/Temp/Rem24.exe packed by PORNOPACK
>/mnt/disk/hda1/Documents and Settings/Rajeev Thapa/Local Settings/Temp/Rem24.exe contains an advertising software Adware.Lop.origin
>/mnt/disk/hda1/Documents and Settings/Rajeev Thapa/Local Settings/Temp/Rem24.exe - archive BINARYRES
>>/mnt/disk/hda1/Documents and Settings/Rajeev Thapa/Local Settings/Temp/Rem24.exe/data001 infected with Trojan.Isbar.547
>>/mnt/disk/hda1/Documents and Settings/Rajeev Thapa/Local Settings/Temp/Rem24.exe/data002 - archive HTML
>>>/mnt/disk/hda1/Documents and Settings/Rajeev Thapa/Local Settings/Temp/Rem24.exe/data002/Script.0 - Ok
>>/mnt/disk/hda1/Documents and Settings/Rajeev Thapa/Local Settings/Temp/Rem24.exe/data002 - Ok
>>/mnt/disk/hda1/Documents and Settings/Rajeev Thapa/Local Settings/Temp/Rem24.exe/data003 - archive HTML
>>>/mnt/disk/hda1/Documents and Settings/Rajeev Thapa/Local Settings/Temp/Rem24.exe/data003/Script.0 - Ok
>>/mnt/disk/hda1/Documents and Settings/Rajeev Thapa/Local Settings/Temp/Rem24.exe/data003 - Ok
/mnt/disk/hda1/Documents and Settings/Rajeev Thapa/Local Settings/Temp/Rem25.exe packed by PORNOPACK
>/mnt/disk/hda1/Documents and Settings/Rajeev Thapa/Local Settings/Temp/Rem25.exe contains an advertising software Adware.Lop.origin
>/mnt/disk/hda1/Documents and Settings/Rajeev Thapa/Local Settings/Temp/Rem25.exe - archive BINARYRES
>>/mnt/disk/hda1/Documents and Settings/Rajeev Thapa/Local Settings/Temp/Rem25.exe/data001 infected with Trojan.Isbar.547
>>/mnt/disk/hda1/Documents and Settings/Rajeev Thapa/Local Settings/Temp/Rem25.exe/data002 - archive HTML
>>>/mnt/disk/hda1/Documents and Settings/Rajeev Thapa/Local Settings/Temp/Rem25.exe/data002/Script.0 - Ok
>>/mnt/disk/hda1/Documents and Settings/Rajeev Thapa/Local Settings/Temp/Rem25.exe/data002 - Ok
>>/mnt/disk/hda1/Documents and Settings/Rajeev Thapa/Local Settings/Temp/Rem25.exe/data003 - archive HTML
>>>/mnt/disk/hda1/Documents and Settings/Rajeev Thapa/Local Settings/Temp/Rem25.exe/data003/Script.0 - Ok
>>/mnt/disk/hda1/Documents and Settings/Rajeev Thapa/Local Settings/Temp/Rem25.exe/data003 - Ok
/mnt/disk/hda1/Documents and Settings/Rajeev Thapa/Local Settings/Temp/Rem26.exe packed by PORNOPACK
>/mnt/disk/hda1/Documents and Settings/Rajeev Thapa/Local Settings/Temp/Rem26.exe contains an advertising software Adware.Lop.origin
>/mnt/disk/hda1/Documents and Settings/Rajeev Thapa/Local Settings/Temp/Rem26.exe - archive BINARYRES
>>/mnt/disk/hda1/Documents and Settings/Rajeev Thapa/Local Settings/Temp/Rem26.exe/data001 infected with Trojan.Isbar.547
>>/mnt/disk/hda1/Documents and Settings/Rajeev Thapa/Local Settings/Temp/Rem26.exe/data002 - archive HTML
>>>/mnt/disk/hda1/Documents and Settings/Rajeev Thapa/Local Settings/Temp/Rem26.exe/data002/Script.0 - Ok
>>/mnt/disk/hda1/Documents and Settings/Rajeev Thapa/Local Settings/Temp/Rem26.exe/data002 - Ok
>>/mnt/disk/hda1/Documents and Settings/Rajeev Thapa/Local Settings/Temp/Rem26.exe/data003 - archive HTML
>>>/mnt/disk/hda1/Documents and Settings/Rajeev Thapa/Local Settings/Temp/Rem26.exe/data003/Script.0 - Ok
>>/mnt/disk/hda1/Documents and Settings/Rajeev Thapa/Local Settings/Temp/Rem26.exe/data003 - Ok
/mnt/disk/hda1/Documents and Settings/Rajeev Thapa/Local Settings/Temp/Rem27.exe packed by PORNOPACK
>/mnt/disk/hda1/Documents and Settings/Rajeev Thapa/Local Settings/Temp/Rem27.exe contains an advertising software Adware.Lop.origin
>/mnt/disk/hda1/Documents and Settings/Rajeev Thapa/Local Settings/Temp/Rem27.exe - archive BINARYRES
>>/mnt/disk/hda1/Documents and Settings/Rajeev Thapa/Local Settings/Temp/Rem27.exe/data001 infected with Trojan.Isbar.547
>>/mnt/disk/hda1/Documents and Settings/Rajeev Thapa/Local Settings/Temp/Rem27.exe/data002 - archive HTML
>>>/mnt/disk/hda1/Documents and Settings/Rajeev Thapa/Local Settings/Temp/Rem27.exe/data002/Script.0 - Ok
>>/mnt/disk/hda1/Documents and Settings/Rajeev Thapa/Local Settings/Temp/Rem27.exe/data002 - Ok
>>/mnt/disk/hda1/Documents and Settings/Rajeev Thapa/Local Settings/Temp/Rem27.exe/data003 - archive HTML
>>>/mnt/disk/hda1/Documents and Settings/Rajeev Thapa/Local Settings/Temp/Rem27.exe/data003/Script.0 - Ok
>>/mnt/disk/hda1/Documents and Settings/Rajeev Thapa/Local Settings/Temp/Rem27.exe/data003 - Ok
/mnt/disk/hda1/Documents and Settings/Rajeev Thapa/Local Settings/Temp/Rem29.exe packed by PORNOPACK
>/mnt/disk/hda1/Documents and Settings/Rajeev Thapa/Local Settings/Temp/Rem29.exe contains an advertising software Adware.Lop.origin
>/mnt/disk/hda1/Documents and Settings/Rajeev Thapa/Local Settings/Temp/Rem29.exe - archive BINARYRES
>>/mnt/disk/hda1/Documents and Settings/Rajeev Thapa/Local Settings/Temp/Rem29.exe/data001 infected with Trojan.Isbar.547
>>/mnt/disk/hda1/Documents and Settings/Rajeev Thapa/Local Settings/Temp/Rem29.exe/data002 - archive HTML
>>>/mnt/disk/hda1/Documents and Settings/Rajeev Thapa/Local Settings/Temp/Rem29.exe/data002/Script.0 - Ok
>>/mnt/disk/hda1/Documents and Settings/Rajeev Thapa/Local Settings/Temp/Rem29.exe/data002 - Ok
>>/mnt/disk/hda1/Documents and Settings/Rajeev Thapa/Local Settings/Temp/Rem29.exe/data003 - archive HTML
>>>/mnt/disk/hda1/Documents and Settings/Rajeev Thapa/Local Settings/Temp/Rem29.exe/data003/Script.0 - Ok
>>/mnt/disk/hda1/Documents and Settings/Rajeev Thapa/Local Settings/Temp/Rem29.exe/data003 - Ok
/mnt/disk/hda1/Documents and Settings/Rajeev Thapa/Local Settings/Temp/Rem2A.exe packed by PORNOPACK
>/mnt/disk/hda1/Documents and Settings/Rajeev Thapa/Local Settings/Temp/Rem2A.exe contains an advertising software Adware.Lop.origin
>/mnt/disk/hda1/Documents and Settings/Rajeev Thapa/Local Settings/Temp/Rem2A.exe - archive BINARYRES
>>/mnt/disk/hda1/Documents and Settings/Rajeev Thapa/Local Settings/Temp/Rem2A.exe/data001 contains an advertising software Adware.Lop.origin
>>/mnt/disk/hda1/Documents and Settings/Rajeev Thapa/Local Settings/Temp/Rem2A.exe/data002 - archive HTML
>>>/mnt/disk/hda1/Documents and Settings/Rajeev Thapa/Local Settings/Temp/Rem2A.exe/data002/Script.0 - Ok
>>/mnt/disk/hda1/Documents and Settings/Rajeev Thapa/Local Settings/Temp/Rem2A.exe/data002 - Ok
>>/mnt/disk/hda1/Documents and Settings/Rajeev Thapa/Local Settings/Temp/Rem2A.exe/data003 - archive HTML
>>>/mnt/disk/hda1/Documents and Settings/Rajeev Thapa/Local Settings/Temp/Rem2A.exe/data003/Script.0 - Ok
>>/mnt/disk/hda1/Documents and Settings/Rajeev Thapa/Local Settings/Temp/Rem2A.exe/data003 - Ok
/mnt/disk/hda1/Documents and Settings/Rajeev Thapa/Local Settings/Temp/Rem2B.exe packed by PORNOPACK
>/mnt/disk/hda1/Documents and Settings/Rajeev Thapa/Local Settings/Temp/Rem2B.exe contains an advertising software Adware.Lop.origin
>/mnt/disk/hda1/Documents and Settings/Rajeev Thapa/Local Settings/Temp/Rem2B.exe - archive BINARYRES
>>/mnt/disk/hda1/Documents and Settings/Rajeev Thapa/Local Settings/Temp/Rem2B.exe/data001 contains an advertising software Adware.Lop.origin
>>/mnt/disk/hda1/Documents and Settings/Rajeev Thapa/Local Settings/Temp/Rem2B.exe/data002 - archive HTML
>>>/mnt/disk/hda1/Documents and Settings/Rajeev Thapa/Local Settings/Temp/Rem2B.exe/data002/Script.0 - Ok
>>/mnt/disk/hda1/Documents and Settings/Rajeev Thapa/Local Settings/Temp/Rem2B.exe/data002 - Ok
>>/mnt/disk/hda1/Documents and Settings/Rajeev Thapa/Local Settings/Temp/Rem2B.exe/data003 - archive HTML
>>>/mnt/disk/hda1/Documents and Settings/Rajeev Thapa/Local Settings/Temp/Rem2B.exe/data003/Script.0 - Ok
>>/mnt/disk/hda1/Documents and Settings/Rajeev Thapa/Local Settings/Temp/Rem2B.exe/data003 - Ok
/mnt/disk/hda1/Documents and Settings/Rajeev Thapa/Local Settings/Temp/Rem3F.exe packed by PORNOPACK
>/mnt/disk/hda1/Documents and Settings/Rajeev Thapa/Local Settings/Temp/Rem3F.exe infected with Trojan.Swizzor.14555
>/mnt/disk/hda1/Documents and Settings/Rajeev Thapa/Local Settings/Temp/Rem3F.exe - deleted!
/mnt/disk/hda1/Documents and Settings/Rajeev Thapa/Local Settings/Temp/Rem4B.exe packed by PORNOPACK
>/mnt/disk/hda1/Documents and Settings/Rajeev Thapa/Local Settings/Temp/Rem4B.exe infected with Trojan.Swizzor.14555
>/mnt/disk/hda1/Documents and Settings/Rajeev Thapa/Local Settings/Temp/Rem4B.exe - deleted!
/mnt/disk/hda1/Documents and Settings/Rajeev Thapa/Local Settings/Temp/Rem4D.exe packed by PORNOPACK
>/mnt/disk/hda1/Documents and Settings/Rajeev Thapa/Local Settings/Temp/Rem4D.exe contains an advertising software Adware.Lop
/mnt/disk/hda1/Documents and Settings/Rajeev Thapa/Local Settings/Temp/Rem137.exe packed by PORNOPACK
>/mnt/disk/hda1/Documents and Settings/Rajeev Thapa/Local Settings/Temp/Rem137.exe contains an advertising software Adware.Lop
/mnt/disk/hda1/Documents and Settings/Rajeev Thapa/Local Settings/Temp/Rem15.exe packed by PORNOPACK
>/mnt/disk/hda1/Documents and Settings/Rajeev Thapa/Local Settings/Temp/Rem15.exe contains an advertising software Adware.Lop
/mnt/disk/hda1/Documents and Settings/Rajeev Thapa/Local Settings/Temp/Rem16.exe packed by PORNOPACK
>/mnt/disk/hda1/Documents and Settings/Rajeev Thapa/Local Settings/Temp/Rem16.exe contains an advertising software Adware.Lop.origin
>/mnt/disk/hda1/Documents and Settings/Rajeev Thapa/Local Settings/Temp/Rem16.exe - archive BINARYRES
>>/mnt/disk/hda1/Documents and Settings/Rajeev Thapa/Local Settings/Temp/Rem16.exe/data001 infected with Trojan.Isbar.547
>>/mnt/disk/hda1/Documents and Settings/Rajeev Thapa/Local Settings/Temp/Rem16.exe/data002 - archive HTML
>>>/mnt/disk/hda1/Documents and Settings/Rajeev Thapa/Local Settings/Temp/Rem16.exe/data002/Script.0 - Ok
>>/mnt/disk/hda1/Documents and Settings/Rajeev Thapa/Local Settings/Temp/Rem16.exe/data002 - Ok
>>/mnt/disk/hda1/Documents and Settings/Rajeev Thapa/Local Settings/Temp/Rem16.exe/data003 - archive HTML
>>>/mnt/disk/hda1/Documents and Settings/Rajeev Thapa/Local Settings/Temp/Rem16.exe/data003/Script.0 - Ok
>>/mnt/disk/hda1/Documents and Settings/Rajeev Thapa/Local Settings/Temp/Rem16.exe/data003 - Ok
/mnt/disk/hda1/Documents and Settings/Rajeev Thapa/Local Settings/Temp/Rem17.exe packed by PORNOPACK
>/mnt/disk/hda1/Documents and Settings/Rajeev Thapa/Local Settings/Temp/Rem17.exe contains an advertising software Adware.Lop
/mnt/disk/hda1/Documents and Settings/Rajeev Thapa/Local Settings/Temp/Rem19.exe packed by PORNOPACK
>/mnt/disk/hda1/Documents and Settings/Rajeev Thapa/Local Settings/Temp/Rem19.exe contains an advertising software Adware.Lop
/mnt/disk/hda1/Documents and Settings/Rajeev Thapa/Local Settings/Temp/Rem1A.exe packed by PORNOPACK
>/mnt/disk/hda1/Documents and Settings/Rajeev Thapa/Local Settings/Temp/Rem1A.exe contains an advertising software Adware.Lop
/mnt/disk/hda1/Documents and Settings/Rajeev Thapa/Local Settings/Temp/Rem1B.exe packed by PORNOPACK
>/mnt/disk/hda1/Documents and Settings/Rajeev Thapa/Local Settings/Temp/Rem1B.exe contains an advertising software Adware.Lop
/mnt/disk/hda1/Documents and Settings/Rajeev Thapa/Local Settings/Temp/Rem1C.exe packed by PORNOPACK
>/mnt/disk/hda1/Documents and Settings/Rajeev Thapa/Local Settings/Temp/Rem1C.exe contains an advertising software Adware.Lop
/mnt/disk/hda1/Documents and Settings/Rajeev Thapa/Local Settings/Temp/Rem1D.exe packed by PORNOPACK
>/mnt/disk/hda1/Documents and Settings/Rajeev Thapa/Local Settings/Temp/Rem1D.exe infected with Trojan.Swizzor.14555
>/mnt/disk/hda1/Documents and Settings/Rajeev Thapa/Local Settings/Temp/Rem1D.exe - deleted!
/mnt/disk/hda1/Documents and Settings/Rajeev Thapa/Local Settings/Temp/Rem1E.exe packed by PORNOPACK
>/mnt/disk/hda1/Documents and Settings/Rajeev Thapa/Local Settings/Temp/Rem1E.exe contains an advertising software Adware.Lop
/mnt/disk/hda1/Documents and Settings/Rajeev Thapa/Local Settings/Temp/Rem21.exe packed by PORNOPACK
>/mnt/disk/hda1/Documents and Settings/Rajeev Thapa/Local Settings/Temp/Rem21.exe contains an advertising software Adware.Lop.origin
>/mnt/disk/hda1/Documents and Settings/Rajeev Thapa/Local Settings/Temp/Rem21.exe - archive BINARYRES
>>/mnt/disk/hda1/Documents and Settings/Rajeev Thapa/Local Settings/Temp/Rem21.exe/data001 infected with Trojan.Isbar.547
>>/mnt/disk/hda1/Documents and Settings/Rajeev Thapa/Local Settings/Temp/Rem21.exe/data002 - archive HTML
>>>/mnt/disk/hda1/Documents and Settings/Rajeev Thapa/Local Settings/Temp/Rem21.exe/data002/Script.0 - Ok
>>/mnt/disk/hda1/Documents and Settings/Rajeev Thapa/Local Settings/Temp/Rem21.exe/data002 - Ok
>>/mnt/disk/hda1/Documents and Settings/Rajeev Thapa/Local Settings/Temp/Rem21.exe/data003 - archive HTML
>>>/mnt/disk/hda1/Documents and Settings/Rajeev Thapa/Local Settings/Temp/Rem21.exe/data003/Script.0 - Ok
>>/mnt/disk/hda1/Documents and Settings/Rajeev Thapa/Local Settings/Temp/Rem21.exe/data003 - Ok
/mnt/disk/hda1/Documents and Settings/Rajeev Thapa/Local Settings/Temp/RemF.exe packed by PORNOPACK
>/mnt/disk/hda1/Documents and Settings/Rajeev Thapa/Local Settings/Temp/RemF.exe contains an advertising software Adware.Lop.origin
>/mnt/disk/hda1/Documents and Settings/Rajeev Thapa/Local Settings/Temp/RemF.exe - archive BINARYRES
>>/mnt/disk/hda1/Documents and Settings/Rajeev Thapa/Local Settings/Temp/RemF.exe/data001 infected with Trojan.Isbar.547
>>/mnt/disk/hda1/Documents and Settings/Rajeev Thapa/Local Settings/Temp/RemF.exe/data002 - archive HTML
>>>/mnt/disk/hda1/Documents and Settings/Rajeev Thapa/Local Settings/Temp/RemF.exe/data002/Script.0 - Ok
>>/mnt/disk/hda1/Documents and Settings/Rajeev Thapa/Local Settings/Temp/RemF.exe/data002 - Ok
>>/mnt/disk/hda1/Documents and Settings/Rajeev Thapa/Local Settings/Temp/RemF.exe/data003 - archive HTML
>>>/mnt/disk/hda1/Documents and Settings/Rajeev Thapa/Local Settings/Temp/RemF.exe/data003/Script.0 - Ok
>>/mnt/disk/hda1/Documents and Settings/Rajeev Thapa/Local Settings/Temp/RemF.exe/data003 - Ok
/mnt/disk/hda1/Documents and Settings/Rajeev Thapa/Local Settings/Temp/Rem2F.exe packed by PORNOPACK
>/mnt/disk/hda1/Documents and Settings/Rajeev Thapa/Local Settings/Temp/Rem2F.exe contains an advertising software Adware.Lop
/mnt/disk/hda1/Documents and Settings/Rajeev Thapa/Local Settings/Temp/Rem30.exe packed by PORNOPACK
>/mnt/disk/hda1/Documents and Settings/Rajeev Thapa/Local Settings/Temp/Rem30.exe contains an advertising software Adware.Lop
/mnt/disk/hda1/Documents and Settings/Rajeev Thapa/Local Settings/Temp/Rem31.exe packed by PORNOPACK
>/mnt/disk/hda1/Documents and Settings/Rajeev Thapa/Local Settings/Temp/Rem31.exe contains an advertising software Adware.Lop
/mnt/disk/hda1/Documents and Settings/Rajeev Thapa/Local Settings/Temp/Rem32.exe packed by PORNOPACK
>/mnt/disk/hda1/Documents and Settings/Rajeev Thapa/Local Settings/Temp/Rem32.exe contains an advertising software Adware.Lop
/mnt/disk/hda1/Documents and Settings/Rajeev Thapa/Local Settings/Temp/Rem33.exe packed by PORNOPACK
>/mnt/disk/hda1/Documents and Settings/Rajeev Thapa/Local Settings/Temp/Rem33.exe contains an advertising software Adware.Lop
/mnt/disk/hda1/Documents and Settings/Rajeev Thapa/Local Settings/Temp/Rem34.exe packed by PORNOPACK
>/mnt/disk/hda1/Documents and Settings/Rajeev Thapa/Local Settings/Temp/Rem34.exe contains an advertising software Adware.Lop
/mnt/disk/hda1/Documents and Settings/Rajeev Thapa/Local Settings/Temp/Rem35.exe packed by PORNOPACK
>/mnt/disk/hda1/Documents and Settings/Rajeev Thapa/Local Settings/Temp/Rem35.exe contains an advertising software Adware.Lop
/mnt/disk/hda1/Documents and Settings/Rajeev Thapa/Local Settings/Temp/Rem36.exe packed by PORNOPACK
>/mnt/disk/hda1/Documents and Settings/Rajeev Thapa/Local Settings/Temp/Rem36.exe contains an advertising software Adware.Lop
/mnt/disk/hda1/Documents and Settings/Rajeev Thapa/Local Settings/Temp/Rem37.exe packed by PORNOPACK
>/mnt/disk/hda1/Documents and Settings/Rajeev Thapa/Local Settings/Temp/Rem37.exe contains an advertising software Adware.Lop
/mnt/disk/hda1/Documents and Settings/Rajeev Thapa/Local Settings/Temp/Rem38.exe packed by PORNOPACK
>/mnt/disk/hda1/Documents and Settings/Rajeev Thapa/Local Settings/Temp/Rem38.exe infected with Trojan.Swizzor.14555
>/mnt/disk/hda1/Documents and Settings/Rajeev Thapa/Local Settings/Temp/Rem38.exe - deleted!
/mnt/disk/hda1/Documents and Settings/Rajeev Thapa/Local Settings/Temp/Rem3B.exe packed by PORNOPACK
>/mnt/disk/hda1/Documents and Settings/Rajeev Thapa/Local Settings/Temp/Rem3B.exe contains an advertising software Adware.Lop
/mnt/disk/hda1/Documents and Settings/Rajeev Thapa/Local Settings/Temp/Rem4F.exe packed by PORNOPACK
>/mnt/disk/hda1/Documents and Settings/Rajeev Thapa/Local Settings/Temp/Rem4F.exe contains an advertising software Adware.Lop
/mnt/disk/hda1/Documents and Settings/Rajeev Thapa/Local Settings/Temp/Rem50.exe packed by PORNOPACK
>/mnt/disk/hda1/Documents and Settings/Rajeev Thapa/Local Settings/Temp/Rem50.exe contains an advertising software Adware.Lop
/mnt/disk/hda1/Documents and Settings/Rajeev Thapa/Local Settings/Temp/Rem52.exe packed by PORNOPACK
>/mnt/disk/hda1/Documents and Settings/Rajeev Thapa/Local Settings/Temp/Rem52.exe contains an advertising software Adware.Lop
/mnt/disk/hda1/Documents and Settings/Rajeev Thapa/Local Settings/Temp/RemA.exe packed by PORNOPACK
>/mnt/disk/hda1/Documents and Settings/Rajeev Thapa/Local Settings/Temp/RemA.exe contains an advertising software Adware.Lop.origin
>/mnt/disk/hda1/Documents and Settings/Rajeev Thapa/Local Settings/Temp/RemA.exe - archive BINARYRES
>>/mnt/disk/hda1/Documents and Settings/Rajeev Thapa/Local Settings/Temp/RemA.exe/data001 infected with Trojan.Isbar.547
>>/mnt/disk/hda1/Documents and Settings/Rajeev Thapa/Local Settings/Temp/RemA.exe/data002 - archive HTML
>>>/mnt/disk/hda1/Documents and Settings/Rajeev Thapa/Local Settings/Temp/RemA.exe/data002/Script.0 - Ok
>>/mnt/disk/hda1/Documents and Settings/Rajeev Thapa/Local Settings/Temp/RemA.exe/data002 - Ok
>>/mnt/disk/hda1/Documents and Settings/Rajeev Thapa/Local Settings/Temp/RemA.exe/data003 - archive HTML
>>>/mnt/disk/hda1/Documents and Settings/Rajeev Thapa/Local Settings/Temp/RemA.exe/data003/Script.0 - Ok
>>/mnt/disk/hda1/Documents and Settings/Rajeev Thapa/Local Settings/Temp/RemA.exe/data003 - Ok
/mnt/disk/hda1/Documents and Settings/Rajeev Thapa/Local Settings/Temp/RemB.exe packed by PORNOPACK
>/mnt/disk/hda1/Documents and Settings/Rajeev Thapa/Local Settings/Temp/RemB.exe contains an advertising software Adware.Lop.origin
>/mnt/disk/hda1/Documents and Settings/Rajeev Thapa/Local Settings/Temp/RemB.exe - archive BINARYRES
>>/mnt/disk/hda1/Documents and Settings/Rajeev Thapa/Local Settings/Temp/RemB.exe/data001 infected with Trojan.Isbar.547
>>/mnt/disk/hda1/Documents and Settings/Rajeev Thapa/Local Settings/Temp/RemB.exe/data002 - archive HTML
>>>/mnt/disk/hda1/Documents and Settings/Rajeev Thapa/Local Settings/Temp/RemB.exe/data002/Script.0 - Ok
>>/mnt/disk/hda1/Documents and Settings/Rajeev Thapa/Local Settings/Temp/RemB.exe/data002 - Ok
>>/mnt/disk/hda1/Documents and Settings/Rajeev Thapa/Local Settings/Temp/RemB.exe/data003 - archive HTML
>>>/mnt/disk/hda1/Documents and Settings/Rajeev Thapa/Local Settings/Temp/RemB.exe/data003/Script.0 - Ok
>>/mnt/disk/hda1/Documents and Settings/Rajeev Thapa/Local Settings/Temp/RemB.exe/data003 - Ok
/mnt/disk/hda1/Documents and Settings/Rajeev Thapa/Local Settings/Temp/RemC.exe packed by PORNOPACK
>/mnt/disk/hda1/Documents and Settings/Rajeev Thapa/Local Settings/Temp/RemC.exe contains an advertising software Adware.Lop
/mnt/disk/hda1/Documents and Settings/Rajeev Thapa/Local Settings/Temp/RemD.exe packed by PORNOPACK
>/mnt/disk/hda1/Documents and Settings/Rajeev Thapa/Local Settings/Temp/RemD.exe contains an advertising software Adware.Lop.origin
>/mnt/disk/hda1/Documents and Settings/Rajeev Thapa/Local Settings/Temp/RemD.exe - archive BINARYRES
>>/mnt/disk/hda1/Documents and Settings/Rajeev Thapa/Local Settings/Temp/RemD.exe/data001 infected with Trojan.Isbar.547
>>/mnt/disk/hda1/Documents and Settings/Rajeev Thapa/Local Settings/Temp/RemD.exe/data002 - archive HTML
>>>/mnt/disk/hda1/Documents and Settings/Rajeev Thapa/Local Settings/Temp/RemD.exe/data002/Script.0 - Ok
>>/mnt/disk/hda1/Documents and Settings/Rajeev Thapa/Local Settings/Temp/RemD.exe/data002 - Ok
>>/mnt/disk/hda1/Documents and Settings/Rajeev Thapa/Local Settings/Temp/RemD.exe/data003 - archive HTML
>>>/mnt/disk/hda1/Documents and Settings/Rajeev Thapa/Local Settings/Temp/RemD.exe/data003/Script.0 - Ok
>>/mnt/disk/hda1/Documents and Settings/Rajeev Thapa/Local Settings/Temp/RemD.exe/data003 - Ok
/mnt/disk/hda1/Documents and Settings/Rajeev Thapa/Local Settings/Temp/RemE.exe packed by PORNOPACK
>/mnt/disk/hda1/Documents and Settings/Rajeev Thapa/Local Settings/Temp/RemE.exe contains an advertising software Adware.Lop.origin
>/mnt/disk/hda1/Documents and Settings/Rajeev Thapa/Local Settings/Temp/RemE.exe - archive BINARYRES
>>/mnt/disk/hda1/Documents and Settings/Rajeev Thapa/Local Settings/Temp/RemE.exe/data001 infected with Trojan.Isbar.547
>>/mnt/disk/hda1/Documents and Settings/Rajeev Thapa/Local Settings/Temp/RemE.exe/data002 - archive HTML
>>>/mnt/disk/hda1/Documents and Settings/Rajeev Thapa/Local Settings/Temp/RemE.exe/data002/Script.0 - Ok
>>/mnt/disk/hda1/Documents and Settings/Rajeev Thapa/Local Settings/Temp/RemE.exe/data002 - Ok
>>/mnt/disk/hda1/Documents and Settings/Rajeev Thapa/Local Settings/Temp/RemE.exe/data003 - archive HTML
>>>/mnt/disk/hda1/Documents and Settings/Rajeev Thapa/Local Settings/Temp/RemE.exe/data003/Script.0 - Ok
>>/mnt/disk/hda1/Documents and Settings/Rajeev Thapa/Local Settings/Temp/RemE.exe/data003 - Ok
/mnt/disk/hda1/Documents and Settings/Rajeev Thapa/Local Settings/Temp/Rem134.exe packed by PORNOPACK
>/mnt/disk/hda1/Documents and Settings/Rajeev Thapa/Local Settings/Temp/Rem134.exe contains an advertising software Adware.Lop
/mnt/disk/hda1/Documents and Settings/Rajeev Thapa/Local Settings/Temp/Rem22.exe packed by PORNOPACK
>/mnt/disk/hda1/Documents and Settings/Rajeev Thapa/Local Settings/Temp/Rem22.exe contains an advertising software Adware.Lop
/mnt/disk/hda1/Documents and Settings/Rajeev Thapa/Local Settings/Temp/Rem3E.exe packed by PORNOPACK
>/mnt/disk/hda1/Documents and Settings/Rajeev Thapa/Local Settings/Temp/Rem3E.exe infected with Trojan.Swizzor.14555
>/mnt/disk/hda1/Documents and Settings/Rajeev Thapa/Local Settings/Temp/Rem3E.exe - deleted!
/mnt/disk/hda1/Documents and Settings/Rajeev Thapa/Local Settings/Temp/Rem10.exe packed by PORNOPACK
>/mnt/disk/hda1/Documents and Settings/Rajeev Thapa/Local Settings/Temp/Rem10.exe contains an advertising software Adware.Lop.origin
>/mnt/disk/hda1/Documents and Settings/Rajeev Thapa/Local Settings/Temp/Rem10.exe - archive BINARYRES
>>/mnt/disk/hda1/Documents and Settings/Rajeev Thapa/Local Settings/Temp/Rem10.exe/data001 infected with Trojan.Isbar.547
>>/mnt/disk/hda1/Documents and Settings/Rajeev Thapa/Local Settings/Temp/Rem10.exe/data002 - archive HTML
>>>/mnt/disk/hda1/Documents and Settings/Rajeev Thapa/Local Settings/Temp/Rem10.exe/data002/Script.0 - Ok
>>/mnt/disk/hda1/Documents and Settings/Rajeev Thapa/Local Settings/Temp/Rem10.exe/data002 - Ok
>>/mnt/disk/hda1/Documents and Settings/Rajeev Thapa/Local Settings/Temp/Rem10.exe/data003 - archive HTML
>>>/mnt/disk/hda1/Documents and Settings/Rajeev Thapa/Local Settings/Temp/Rem10.exe/data003/Script.0 - Ok
>>/mnt/disk/hda1/Documents and Settings/Rajeev Thapa/Local Settings/Temp/Rem10.exe/data003 - Ok
/mnt/disk/hda1/Documents and Settings/Rajeev Thapa/Local Settings/Temp/Rem132.exe packed by PORNOPACK
>/mnt/disk/hda1/Documents and Settings/Rajeev Thapa/Local Settings/Temp/Rem132.exe contains an advertising software Adware.Lop
/mnt/disk/hda1/Documents and Settings/Rajeev Thapa/Local Settings/Temp/gg.dll infected with Trojan.PWS.Gamania.25724
/mnt/disk/hda1/Documents and Settings/Rajeev Thapa/Local Settings/Temp/gg.dll - deleted!
/mnt/disk/hda1/Documents and Settings/Rajeev Thapa/Local Settings/Temp/206537703.dll infected with Trojan.PWS.Gamania.25550
/mnt/disk/hda1/Documents and Settings/Rajeev Thapa/Local Settings/Temp/206537703.dll - deleted!
/mnt/disk/hda1/Documents and Settings/Rajeev Thapa/Local Settings/Temp/226541703.dll packed by BINARYRES
>/mnt/disk/hda1/Documents and Settings/Rajeev Thapa/Local Settings/Temp/226541703.dll infected with Trojan.Loader.555
>/mnt/disk/hda1/Documents and Settings/Rajeev Thapa/Local Settings/Temp/226541703.dll - deleted!
/mnt/disk/hda1/Documents and Settings/Rajeev Thapa/Local Settings/Temp/236544593.dll infected with Trojan.PWS.Gamania.25598
/mnt/disk/hda1/Documents and Settings/Rajeev Thapa/Local Settings/Temp/236544593.dll - deleted!
/mnt/disk/hda1/Documents and Settings/Rajeev Thapa/Local Settings/Temp/lzhyh/s.exe infected with Trojan.DownLoader1.8568
/mnt/disk/hda1/Documents and Settings/Rajeev Thapa/Local Settings/Temp/lzhyh/s.exe - deleted!
/mnt/disk/hda1/Program Files/A00.exe packed by UPACK
>/mnt/disk/hda1/Program Files/A00.exe infected with Trojan.PWS.Qqpass.4551
>/mnt/disk/hda1/Program Files/A00.exe - deleted!
/mnt/disk/hda1/Program Files/A02.exe packed by MEW
>/mnt/disk/hda1/Program Files/A02.exe infected with Trojan.PWS.Wsgame.20047
>/mnt/disk/hda1/Program Files/A02.exe - deleted!
/mnt/disk/hda1/Program Files/A04.exe packed by MEW
>/mnt/disk/hda1/Program Files/A04.exe infected with Trojan.PWS.Wsgame.20047
>/mnt/disk/hda1/Program Files/A04.exe - deleted!
/mnt/disk/hda1/Program Files/A07.exe packed by MEW
>/mnt/disk/hda1/Program Files/A07.exe infected with Trojan.PWS.Wsgame.20047
>/mnt/disk/hda1/Program Files/A07.exe - deleted!
/mnt/disk/hda1/Program Files/A08.exe packed by MEW
>/mnt/disk/hda1/Program Files/A08.exe infected with Trojan.PWS.Wsgame.20047
>/mnt/disk/hda1/Program Files/A08.exe - deleted!
/mnt/disk/hda1/Program Files/A12.exe packed by MEW
>/mnt/disk/hda1/Program Files/A12.exe infected with Trojan.PWS.Wsgame.20047
>/mnt/disk/hda1/Program Files/A12.exe - deleted!
/mnt/disk/hda1/Program Files/A13.exe packed by MEW
>/mnt/disk/hda1/Program Files/A13.exe infected with Trojan.PWS.Wsgame.20047
>/mnt/disk/hda1/Program Files/A13.exe - deleted!
/mnt/disk/hda1/Program Files/A14.exe packed by MEW
>/mnt/disk/hda1/Program Files/A14.exe infected with Trojan.PWS.Wsgame.20047
>/mnt/disk/hda1/Program Files/A14.exe - deleted!
/mnt/disk/hda1/Program Files/A16.exe packed by MEW
>/mnt/disk/hda1/Program Files/A16.exe infected with Trojan.PWS.Wsgame.20047
>/mnt/disk/hda1/Program Files/A16.exe - deleted!
/mnt/disk/hda1/Program Files/msn.exe infected with Trojan.MulDrop.3631
/mnt/disk/hda1/Program Files/msn.exe - deleted!
/mnt/disk/hda1/Program Files/fh.exe contains an advertising software Adware.IEBar.52
/mnt/disk/hda1/Program Files/Adobe/Reader 9.0/Reader/EasyTime.exe infected with Trojan.DownLoad.64067
/mnt/disk/hda1/Program Files/Adobe/Reader 9.0/Reader/EasyTime.exe - deleted!
/mnt/disk/hda1/Program Files/Adobe/Reader 9.0/Reader/reader_sl.exe infected with Trojan.Starter.398
/mnt/disk/hda1/Program Files/Adobe/Reader 9.0/Reader/reader_sl.exe - cured!
/mnt/disk/hda1/Program Files/Adobe/Reader 9.0/Reader/reader_sl.exe - Ok
/mnt/disk/hda1/Program Files/Common Files/SafeDrv.exe packed by FSG
>/mnt/disk/hda1/Program Files/Common Files/SafeDrv.exe infected with Trojan.MulDrop.origin
>/mnt/disk/hda1/Program Files/Common Files/SafeDrv.exe - archive BINARYRES
>>/mnt/disk/hda1/Program Files/Common Files/SafeDrv.exe/data001 packed by XOREXE
>>>/mnt/disk/hda1/Program Files/Common Files/SafeDrv.exe/data001 infected with Trojan.NtRootKit.2909
/mnt/disk/hda1/Program Files/Common Files/Microsoft Shared/Works Shared/EasyTime.exe infected with Trojan.DownLoad.64067
/mnt/disk/hda1/Program Files/Common Files/Microsoft Shared/Works Shared/EasyTime.exe - deleted!
/mnt/disk/hda1/Program Files/Common Files/Adobe/ARM/1.0/adobearm.exe infected with Trojan.Starter.398
/mnt/disk/hda1/Program Files/Common Files/Adobe/ARM/1.0/adobearm.exe - cured!
/mnt/disk/hda1/Program Files/Common Files/Adobe/ARM/1.0/adobearm.exe - Ok
/mnt/disk/hda1/Program Files/Common Files/Adobe/ARM/1.0/EasyTime.exe infected with Trojan.DownLoad.64067
/mnt/disk/hda1/Program Files/Common Files/Adobe/ARM/1.0/EasyTime.exe - deleted!
/mnt/disk/hda1/Program Files/Common Files/logishrd/LComMgr/communications_helper.exe infected with Trojan.Starter.398
/mnt/disk/hda1/Program Files/Common Files/logishrd/LComMgr/communications_helper.exe - cured!
/mnt/disk/hda1/Program Files/Common Files/logishrd/LComMgr/communications_helper.exe - Ok
/mnt/disk/hda1/Program Files/Common Files/logishrd/LComMgr/EasyTime.exe infected with Trojan.DownLoad.64067
/mnt/disk/hda1/Program Files/Common Files/logishrd/LComMgr/EasyTime.exe - deleted!
/mnt/disk/hda1/Program Files/PrecisionTime/PrecisionTime.exe contains an advertising software Adware.Gator
/mnt/disk/hda1/Program Files/PrecisionTime/PTUninstaller.exe contains an advertising software Adware.Gator.origin
/mnt/disk/hda1/Program Files/ProSiteFinder/0whfethk.DLL infected with BackDoor.Ruller
/mnt/disk/hda1/Program Files/ProSiteFinder/0whfethk.DLL - deleted!
/mnt/disk/hda1/Program Files/ProSiteFinder/EasyTime.exe infected with Trojan.DownLoad.64067
/mnt/disk/hda1/Program Files/ProSiteFinder/EasyTime.exe - deleted!
/mnt/disk/hda1/Program Files/NaviSearch/nls8034.exe - archive NSIS
>/mnt/disk/hda1/Program Files/NaviSearch/nls8034.exe/script.bin - Ok
>/mnt/disk/hda1/Program Files/NaviSearch/nls8034.exe/nvms.dll contains an advertising software Adware.Exact
>/mnt/disk/hda1/Program Files/NaviSearch/nls8034.exe/exdl.exe contains an advertising software Adware.BargainBuddy
>/mnt/disk/hda1/Program Files/NaviSearch/nls8034.exe/exul.exe contains an advertising software Adware.BargainBuddy
>/mnt/disk/hda1/Program Files/NaviSearch/nls8034.exe/bbchk.exe - Ok
>/mnt/disk/hda1/Program Files/NaviSearch/nls8034.exe/trkgif.exe infected with Trojan.Click.240
>/mnt/disk/hda1/Program Files/NaviSearch/nls8034.exe/ahnls.exe - archive NSIS
>>/mnt/disk/hda1/Program Files/NaviSearch/nls8034.exe/ahnls.exe/script.bin - Ok
>>/mnt/disk/hda1/Program Files/NaviSearch/nls8034.exe/ahnls.exe/angelex.exe contains an advertising software Adware.BargainBuddy
>>/mnt/disk/hda1/Program Files/NaviSearch/nls8034.exe/ahnls.exe/instsrv.exe contains an intrusion tool Tool.SrvRunner
>>/mnt/disk/hda1/Program Files/NaviSearch/nls8034.exe/ahnls.exe/msexreg.exe - Ok
>/mnt/disk/hda1/Program Files/NaviSearch/nls8034.exe/nls8034_OUTB.exe - archive NSIS
>>/mnt/disk/hda1/Program Files/NaviSearch/nls8034.exe/nls8034_OUTB.exe/script.bin - Ok
>>/mnt/disk/hda1/Program Files/NaviSearch/nls8034.exe/nls8034_OUTB.exe/___\modern-header.bmp - Ok
>>/mnt/disk/hda1/Program Files/NaviSearch/nls8034.exe/nls8034_OUTB.exe/nvms.dll contains an advertising software Adware.Exact
>>/mnt/disk/hda1/Program Files/NaviSearch/nls8034.exe/nls8034_OUTB.exe/nls.exe contains an advertising software Adware.Exact
>>/mnt/disk/hda1/Program Files/NaviSearch/nls8034.exe/nls8034_OUTB.exe/ad-nls.dat - Ok
>/mnt/disk/hda1/Program Files/NaviSearch/nls8034.exe/exclean.exe - archive NSIS
>>/mnt/disk/hda1/Program Files/NaviSearch/nls8034.exe/exclean.exe/script.bin - Ok
>>/mnt/disk/hda1/Program Files/NaviSearch/nls8034.exe/exclean.exe/1.file - Ok
>/mnt/disk/hda1/Program Files/NaviSearch/nls8034.exe/exclean.exe - Ok
/mnt/disk/hda1/Program Files/NaviSearch/bin/nls.exe contains an advertising software Adware.Exact
/mnt/disk/hda1/Program Files/TopSearch/ls_update.exe - archive NSIS
>/mnt/disk/hda1/Program Files/TopSearch/ls_update.exe/script.bin - Ok
>/mnt/disk/hda1/Program Files/TopSearch/ls_update.exe/___\UserInfo.dll - Ok
>/mnt/disk/hda1/Program Files/TopSearch/ls_update.exe/WebSearch.exe contains an advertising software Adware.TopSearch
>/mnt/disk/hda1/Program Files/TopSearch/ls_update.exe/WebSearch.dll contains an advertising software Adware.TopSearch.8
>/mnt/disk/hda1/Program Files/TopSearch/ls_update.exe/WebSearch - Ok
>/mnt/disk/hda1/Program Files/TopSearch/ls_update.exe/1 - Ok
/mnt/disk/hda1/Program Files/FlashGet Network/FlashGet Mini/EasyTime.exe infected with Trojan.DownLoad.64067
/mnt/disk/hda1/Program Files/FlashGet Network/FlashGet Mini/EasyTime.exe - deleted!
/mnt/disk/hda1/Program Files/FlashGet Network/FlashGet Mini/flashgetmini.exe infected with Trojan.Starter.398
/mnt/disk/hda1/Program Files/FlashGet Network/FlashGet Mini/flashgetmini.exe - cured!
/mnt/disk/hda1/Program Files/FlashGet Network/FlashGet Mini/flashgetmini.exe packed by ZLIB
>/mnt/disk/hda1/Program Files/FlashGet Network/FlashGet Mini/flashgetmini.exe - archive BINARYRES
>>/mnt/disk/hda1/Program Files/FlashGet Network/FlashGet Mini/flashgetmini.exe/data001 - Ok
>>/mnt/disk/hda1/Program Files/FlashGet Network/FlashGet Mini/flashgetmini.exe/data002 - Ok
>>/mnt/disk/hda1/Program Files/FlashGet Network/FlashGet Mini/flashgetmini.exe/data003 - Ok
>>/mnt/disk/hda1/Program Files/FlashGet Network/FlashGet Mini/flashgetmini.exe/data004 - Ok
>>/mnt/disk/hda1/Program Files/FlashGet Network/FlashGet Mini/flashgetmini.exe/data005 - Ok
>>/mnt/disk/hda1/Program Files/FlashGet Network/FlashGet Mini/flashgetmini.exe/data006 - Ok
>>/mnt/disk/hda1/Program Files/FlashGet Network/FlashGet Mini/flashgetmini.exe/data007 - Ok
>>/mnt/disk/hda1/Program Files/FlashGet Network/FlashGet Mini/flashgetmini.exe/data008 - Ok
>>/mnt/disk/hda1/Program Files/FlashGet Network/FlashGet Mini/flashgetmini.exe/data009 - Ok
>>/mnt/disk/hda1/Program Files/FlashGet Network/FlashGet Mini/flashgetmini.exe/data010 - Ok
>>/mnt/disk/hda1/Program Files/FlashGet Network/FlashGet Mini/flashgetmini.exe/data011 - Ok
>>/mnt/disk/hda1/Program Files/FlashGet Network/FlashGet Mini/flashgetmini.exe/data012 - Ok
>>/mnt/disk/hda1/Program Files/FlashGet Network/FlashGet Mini/flashgetmini.exe/data013 - Ok
>>/mnt/disk/hda1/Program Files/FlashGet Network/FlashGet Mini/flashgetmini.exe/data014 - Ok
>>/mnt/disk/hda1/Program Files/FlashGet Network/FlashGet Mini/flashgetmini.exe/data015 - Ok
>>/mnt/disk/hda1/Program Files/FlashGet Network/FlashGet Mini/flashgetmini.exe/data016 - Ok
/mnt/disk/hda1/Program Files/Internet Explorer/IETimbar/IETimbar.dll contains an advertising software Adware.IEBar.52
/mnt/disk/hda1/Program Files/Internet Optimizer/actalert.exe packed by PETITE
>/mnt/disk/hda1/Program Files/Internet Optimizer/actalert.exe infected with Trojan.Dyfuca
>/mnt/disk/hda1/Program Files/Internet Optimizer/actalert.exe - deleted!
/mnt/disk/hda1/Program Files/Internet Optimizer/backup.dat packed by PETITE
>/mnt/disk/hda1/Program Files/Internet Optimizer/backup.dat infected with Trojan.Dyfuca
>/mnt/disk/hda1/Program Files/Internet Optimizer/backup.dat - deleted!
/mnt/disk/hda1/Program Files/Internet Optimizer/EasyTime.exe infected with Trojan.DownLoad.64067
/mnt/disk/hda1/Program Files/Internet Optimizer/EasyTime.exe - deleted!
/mnt/disk/hda1/Program Files/Internet Optimizer/optimize.exe infected with Trojan.Starter.398
/mnt/disk/hda1/Program Files/Internet Optimizer/optimize.exe - cured!
/mnt/disk/hda1/Program Files/Internet Optimizer/optimize.exe packed by PETITE
>/mnt/disk/hda1/Program Files/Internet Optimizer/optimize.exe - decompression error!
/mnt/disk/hda1/Program Files/Logitech/QuickCam/EasyTime.exe infected with Trojan.DownLoad.64067
/mnt/disk/hda1/Program Files/Logitech/QuickCam/EasyTime.exe - deleted!
/mnt/disk/hda1/Program Files/Logitech/QuickCam/quickcam.exe infected with Trojan.Starter.398
/mnt/disk/hda1/Program Files/Logitech/QuickCam/quickcam.exe - cured!
/mnt/disk/hda1/Program Files/Logitech/QuickCam/quickcam.exe packed by ZLIB
>/mnt/disk/hda1/Program Files/Logitech/QuickCam/quickcam.exe - archive BINARYRES
>>/mnt/disk/hda1/Program Files/Logitech/QuickCam/quickcam.exe/data001 - Ok
>>/mnt/disk/hda1/Program Files/Logitech/QuickCam/quickcam.exe/data002 - Ok
>>/mnt/disk/hda1/Program Files/Logitech/QuickCam/quickcam.exe/data003 - Ok
>>/mnt/disk/hda1/Program Files/Logitech/QuickCam/quickcam.exe/data004 - Ok
>>/mnt/disk/hda1/Program Files/Logitech/QuickCam/quickcam.exe/data005 - Ok
>>/mnt/disk/hda1/Program Files/Logitech/QuickCam/quickcam.exe/data006 - Ok
>>/mnt/disk/hda1/Program Files/Logitech/QuickCam/quickcam.exe/data007 - Ok
>>/mnt/disk/hda1/Program Files/Logitech/QuickCam/quickcam.exe/data008 - Ok
>>/mnt/disk/hda1/Program Files/Logitech/QuickCam/quickcam.exe/data009 - Ok
>>/mnt/disk/hda1/Program Files/Logitech/QuickCam/quickcam.exe/data010 - Ok
>>/mnt/disk/hda1/Program Files/Logitech/QuickCam/quickcam.exe/data011 - Ok
>>/mnt/disk/hda1/Program Files/Logitech/QuickCam/quickcam.exe/data012 - Ok
>>/mnt/disk/hda1/Program Files/Logitech/QuickCam/quickcam.exe/data013 - Ok
>>/mnt/disk/hda1/Program Files/Logitech/QuickCam/quickcam.exe/data014 - Ok
/mnt/disk/hda1/Program Files/Messenger/EasyTime.exe infected with Trojan.DownLoad.64067
/mnt/disk/hda1/Program Files/Messenger/EasyTime.exe - deleted!
/mnt/disk/hda1/Program Files/Messenger/msmsgs.exe infected with Trojan.Starter.398
/mnt/disk/hda1/Program Files/Messenger/msmsgs.exe - cured!
/mnt/disk/hda1/Program Files/Messenger/msmsgs.exe - Ok
/mnt/disk/hda1/Program Files/Qzmlvmp/backup.dat packed by PETITE
>/mnt/disk/hda1/Program Files/Qzmlvmp/backup.dat infected with Trojan.DownLoader.1389
>/mnt/disk/hda1/Program Files/Qzmlvmp/backup.dat - deleted!
/mnt/disk/hda1/Program Files/Qzmlvmp/EasyTime.exe infected with Trojan.DownLoad.64067
/mnt/disk/hda1/Program Files/Qzmlvmp/EasyTime.exe - deleted!
/mnt/disk/hda1/Program Files/Qzmlvmp/mwqp.exe infected with Trojan.Starter.398
/mnt/disk/hda1/Program Files/Qzmlvmp/mwqp.exe - cured!
/mnt/disk/hda1/Program Files/Qzmlvmp/mwqp.exe packed by PETITE
>/mnt/disk/hda1/Program Files/Qzmlvmp/mwqp.exe - decompression error!
/mnt/disk/hda1/Program Files/Recommended Hotfix - 421701D/v15/RH.DLL contains an advertising software Adware.Hopper
/mnt/disk/hda1/Program Files/Consumer Input/dca-ua.exe infected with Trojan.Starter.398
/mnt/disk/hda1/Program Files/Consumer Input/dca-ua.exe - cured!
/mnt/disk/hda1/Program Files/Consumer Input/dca-ua.exe - Ok
/mnt/disk/hda1/Program Files/Consumer Input/EasyTime.exe infected with Trojan.DownLoad.64067
/mnt/disk/hda1/Program Files/Consumer Input/EasyTime.exe - deleted!
/mnt/disk/hda1/Program Files/cyberlink/PCM4Everio/EasyTime.exe infected with Trojan.DownLoad.64067
/mnt/disk/hda1/Program Files/cyberlink/PCM4Everio/EasyTime.exe - deleted!
/mnt/disk/hda1/Program Files/cyberlink/PCM4Everio/everioservice.exe infected with Trojan.Starter.398
/mnt/disk/hda1/Program Files/cyberlink/PCM4Everio/everioservice.exe - cured!
/mnt/disk/hda1/Program Files/cyberlink/PCM4Everio/everioservice.exe - Ok
/mnt/disk/hda1/Program Files/Date Manager/DateManager.exe contains an advertising software Adware.Gator
/mnt/disk/hda1/Program Files/Date Manager/DMUninstaller.exe contains an advertising software Adware.Gator
/mnt/disk/hda1/Program Files/DownloadWare/Downloads/201.dat contains an advertising software Adware.Hopper
/mnt/disk/hda1/Program Files/DownloadWare/Temp/rh.exe contains an advertising software Adware.Hopper
/mnt/disk/hda1/System Volume Information/_restore{39B55467-8C7E-46C6-B32A-C58455643C25}/RP1251/A0122394.EXE infected with Trojan.Siggen1.30079
/mnt/disk/hda1/System Volume Information/_restore{39B55467-8C7E-46C6-B32A-C58455643C25}/RP1251/A0122394.EXE - deleted!
/mnt/disk/hda1/System Volume Information/_restore{39B55467-8C7E-46C6-B32A-C58455643C25}/RP1251/A0122395.EXE infected with Trojan.Siggen1.30079
/mnt/disk/hda1/System Volume Information/_restore{39B55467-8C7E-46C6-B32A-C58455643C25}/RP1251/A0122395.EXE - deleted!
/mnt/disk/hda1/System Volume Information/_restore{39B55467-8C7E-46C6-B32A-C58455643C25}/RP1253/A0122595.EXE infected with Trojan.Siggen1.30079
/mnt/disk/hda1/System Volume Information/_restore{39B55467-8C7E-46C6-B32A-C58455643C25}/RP1253/A0122595.EXE - deleted!
/mnt/disk/hda1/System Volume Information/_restore{39B55467-8C7E-46C6-B32A-C58455643C25}/RP1253/A0122656.exe packed by PETITE
>/mnt/disk/hda1/System Volume Information/_restore{39B55467-8C7E-46C6-B32A-C58455643C25}/RP1253/A0122656.exe infected with Trojan.Dyfuca
>/mnt/disk/hda1/System Volume Information/_restore{39B55467-8C7E-46C6-B32A-C58455643C25}/RP1253/A0122656.exe - deleted!
/mnt/disk/hda1/System Volume Information/_restore{39B55467-8C7E-46C6-B32A-C58455643C25}/RP1253/A0122657.exe packed by PETITE
>/mnt/disk/hda1/System Volume Information/_restore{39B55467-8C7E-46C6-B32A-C58455643C25}/RP1253/A0122657.exe infected with Trojan.DownLoader.1389
>/mnt/disk/hda1/System Volume Information/_restore{39B55467-8C7E-46C6-B32A-C58455643C25}/RP1253/A0122657.exe - deleted!
/mnt/disk/hda1/System Volume Information/_restore{39B55467-8C7E-46C6-B32A-C58455643C25}/RP1254/A0123386.exe infected with Trojan.DownLoader1.8017
/mnt/disk/hda1/System Volume Information/_restore{39B55467-8C7E-46C6-B32A-C58455643C25}/RP1254/A0123386.exe - deleted!
/mnt/disk/hda1/System Volume Information/_restore{39B55467-8C7E-46C6-B32A-C58455643C25}/RP1254/A0123387.dll infected with Trojan.DownLoad1.56737
/mnt/disk/hda1/System Volume Information/_restore{39B55467-8C7E-46C6-B32A-C58455643C25}/RP1254/A0123387.dll - deleted!
/mnt/disk/hda1/System Volume Information/_restore{39B55467-8C7E-46C6-B32A-C58455643C25}/RP1254/A0123388.exe infected with Trojan.Siggen1.33584
/mnt/disk/hda1/System Volume Information/_restore{39B55467-8C7E-46C6-B32A-C58455643C25}/RP1254/A0123388.exe - deleted!
/mnt/disk/hda1/System Volume Information/_restore{39B55467-8C7E-46C6-B32A-C58455643C25}/RP1254/A0123389.sys infected with Trojan.PWS.Gamania.25454
/mnt/disk/hda1/System Volume Information/_restore{39B55467-8C7E-46C6-B32A-C58455643C25}/RP1254/A0123389.sys - deleted!
/mnt/disk/hda1/System Volume Information/_restore{39B55467-8C7E-46C6-B32A-C58455643C25}/RP1254/A0123390.Sys packed by UPX
>/mnt/disk/hda1/System Volume Information/_restore{39B55467-8C7E-46C6-B32A-C58455643C25}/RP1254/A0123390.Sys infected with Trojan.PWS.Gamania.25318
>/mnt/disk/hda1/System Volume Information/_restore{39B55467-8C7E-46C6-B32A-C58455643C25}/RP1254/A0123390.Sys - deleted!
/mnt/disk/hda1/System Volume Information/_restore{39B55467-8C7E-46C6-B32A-C58455643C25}/RP1254/A0123391.dll infected with Trojan.DownLoad1.56737
/mnt/disk/hda1/System Volume Information/_restore{39B55467-8C7E-46C6-B32A-C58455643C25}/RP1254/A0123391.dll - deleted!
/mnt/disk/hda1/System Volume Information/_restore{39B55467-8C7E-46C6-B32A-C58455643C25}/RP1254/A0123392.exe infected with Trojan.DownLoad1.56737
/mnt/disk/hda1/System Volume Information/_restore{39B55467-8C7E-46C6-B32A-C58455643C25}/RP1254/A0123392.exe - deleted!
/mnt/disk/hda1/System Volume Information/_restore{39B55467-8C7E-46C6-B32A-C58455643C25}/RP1254/A0127470.dll contains an advertising software Adware.Cinmus.24910
/mnt/disk/hda1/System Volume Information/_restore{39B55467-8C7E-46C6-B32A-C58455643C25}/RP1254/A0127680.dll infected with Trojan.PWS.Wsgame.20660
/mnt/disk/hda1/System Volume Information/_restore{39B55467-8C7E-46C6-B32A-C58455643C25}/RP1254/A0127680.dll - deleted!
/mnt/disk/hda1/System Volume Information/_restore{39B55467-8C7E-46C6-B32A-C58455643C25}/RP1254/A0127738.exe packed by MEW
>/mnt/disk/hda1/System Volume Information/_restore{39B55467-8C7E-46C6-B32A-C58455643C25}/RP1254/A0127738.exe infected with Trojan.PWS.Wsgame.20047
>/mnt/disk/hda1/System Volume Information/_restore{39B55467-8C7E-46C6-B32A-C58455643C25}/RP1254/A0127738.exe - deleted!
/mnt/disk/hda1/System Volume Information/_restore{39B55467-8C7E-46C6-B32A-C58455643C25}/RP1254/A0127756.exe packed by MEW
>/mnt/disk/hda1/System Volume Information/_restore{39B55467-8C7E-46C6-B32A-C58455643C25}/RP1254/A0127756.exe infected with Trojan.PWS.Wsgame.20047
>/mnt/disk/hda1/System Volume Information/_restore{39B55467-8C7E-46C6-B32A-C58455643C25}/RP1254/A0127756.exe - deleted!
/mnt/disk/hda1/System Volume Information/_restore{39B55467-8C7E-46C6-B32A-C58455643C25}/RP1254/A0127468.dll infected with Trojan.Click1.6534
/mnt/disk/hda1/System Volume Information/_restore{39B55467-8C7E-46C6-B32A-C58455643C25}/RP1254/A0127468.dll - deleted!
/mnt/disk/hda1/System Volume Information/_restore{39B55467-8C7E-46C6-B32A-C58455643C25}/RP1254/A0127471.dll infected with Trojan.DownLoad1.56737
/mnt/disk/hda1/System Volume Information/_restore{39B55467-8C7E-46C6-B32A-C58455643C25}/RP1254/A0127471.dll - deleted!
/mnt/disk/hda1/System Volume Information/_restore{39B55467-8C7E-46C6-B32A-C58455643C25}/RP1254/A0127525.exe infected with Trojan.DownLoad.64067
/mnt/disk/hda1/System Volume Information/_restore{39B55467-8C7E-46C6-B32A-C58455643C25}/RP1254/A0127525.exe - deleted!
/mnt/disk/hda1/System Volume Information/_restore{39B55467-8C7E-46C6-B32A-C58455643C25}/RP1254/A0127528.Sys packed by UPX
>/mnt/disk/hda1/System Volume Information/_restore{39B55467-8C7E-46C6-B32A-C58455643C25}/RP1254/A0127528.Sys infected with Trojan.PWS.Gamania.25318
>/mnt/disk/hda1/System Volume Information/_restore{39B55467-8C7E-46C6-B32A-C58455643C25}/RP1254/A0127528.Sys - deleted!
/mnt/disk/hda1/System Volume Information/_restore{39B55467-8C7E-46C6-B32A-C58455643C25}/RP1254/A0127532.sys infected with Trojan.MulDrop1.19812
/mnt/disk/hda1/System Volume Information/_restore{39B55467-8C7E-46C6-B32A-C58455643C25}/RP1254/A0127532.sys - deleted!
/mnt/disk/hda1/System Volume Information/_restore{39B55467-8C7E-46C6-B32A-C58455643C25}/RP1254/A0127542.exe infected with Trojan.Click.64105
/mnt/disk/hda1/System Volume Information/_restore{39B55467-8C7E-46C6-B32A-C58455643C25}/RP1254/A0127542.exe - deleted!
/mnt/disk/hda1/System Volume Information/_restore{39B55467-8C7E-46C6-B32A-C58455643C25}/RP1254/A0127543.exe infected with Trojan.MulDrop.3631
/mnt/disk/hda1/System Volume Information/_restore{39B55467-8C7E-46C6-B32A-C58455643C25}/RP1254/A0127543.exe - deleted!
/mnt/disk/hda1/System Volume Information/_restore{39B55467-8C7E-46C6-B32A-C58455643C25}/RP1254/A0127577.dll infected with Trojan.PWS.Wsgame.19855
/mnt/disk/hda1/System Volume Information/_restore{39B55467-8C7E-46C6-B32A-C58455643C25}/RP1254/A0127577.dll - cured!
/mnt/disk/hda1/System Volume Information/_restore{39B55467-8C7E-46C6-B32A-C58455643C25}/RP1254/A0127577.dll - Ok
/mnt/disk/hda1/System Volume Information/_restore{39B55467-8C7E-46C6-B32A-C58455643C25}/RP1254/A0127587.exe packed by UPX
>/mnt/disk/hda1/System Volume Information/_restore{39B55467-8C7E-46C6-B32A-C58455643C25}/RP1254/A0127587.exe infected with Trojan.MulDrop1.20666
>/mnt/disk/hda1/System Volume Information/_restore{39B55467-8C7E-46C6-B32A-C58455643C25}/RP1254/A0127587.exe - deleted!
/mnt/disk/hda1/System Volume Information/_restore{39B55467-8C7E-46C6-B32A-C58455643C25}/RP1254/A0127589.exe contains an advertising software Adware.IEBar.52
/mnt/disk/hda1/System Volume Information/_restore{39B55467-8C7E-46C6-B32A-C58455643C25}/RP1254/A0127607.exe packed by FSG
>/mnt/disk/hda1/System Volume Information/_restore{39B55467-8C7E-46C6-B32A-C58455643C25}/RP1254/A0127607.exe infected with Trojan.MulDrop.origin
>/mnt/disk/hda1/System Volume Information/_restore{39B55467-8C7E-46C6-B32A-C58455643C25}/RP1254/A0127607.exe - archive BINARYRES
>>/mnt/disk/hda1/System Volume Information/_restore{39B55467-8C7E-46C6-B32A-C58455643C25}/RP1254/A0127607.exe/data001 packed by XOREXE
>>>/mnt/disk/hda1/System Volume Information/_restore{39B55467-8C7E-46C6-B32A-C58455643C25}/RP1254/A0127607.exe/data001 infected with Trojan.NtRootKit.2909
/mnt/disk/hda1/System Volume Information/_restore{39B55467-8C7E-46C6-B32A-C58455643C25}/RP1254/A0127608.dll infected with Trojan.DownLoader.origin
/mnt/disk/hda1/System Volume Information/_restore{39B55467-8C7E-46C6-B32A-C58455643C25}/RP1254/A0127608.dll packed by BINARYRES
>/mnt/disk/hda1/System Volume Information/_restore{39B55467-8C7E-46C6-B32A-C58455643C25}/RP1254/A0127608.dll infected with Trojan.DownLoad1.59715
>/mnt/disk/hda1/System Volume Information/_restore{39B55467-8C7E-46C6-B32A-C58455643C25}/RP1254/A0127608.dll - deleted!
/mnt/disk/hda1/System Volume Information/_restore{39B55467-8C7E-46C6-B32A-C58455643C25}/RP1254/A0127609.Sys packed by UPX
>/mnt/disk/hda1/System Volume Information/_restore{39B55467-8C7E-46C6-B32A-C58455643C25}/RP1254/A0127609.Sys infected with Trojan.PWS.Gamania.25318
>/mnt/disk/hda1/System Volume Information/_restore{39B55467-8C7E-46C6-B32A-C58455643C25}/RP1254/A0127609.Sys - deleted!
/mnt/disk/hda1/System Volume Information/_restore{39B55467-8C7E-46C6-B32A-C58455643C25}/RP1254/A0127610.dll infected with Trojan.DownLoad1.59715
/mnt/disk/hda1/System Volume Information/_restore{39B55467-8C7E-46C6-B32A-C58455643C25}/RP1254/A0127610.dll - deleted!
/mnt/disk/hda1/System Volume Information/_restore{39B55467-8C7E-46C6-B32A-C58455643C25}/RP1254/A0127611.dll infected with Trojan.DownLoad1.59983
/mnt/disk/hda1/System Volume Information/_restore{39B55467-8C7E-46C6-B32A-C58455643C25}/RP1254/A0127611.dll - deleted!
/mnt/disk/hda1/System Volume Information/_restore{39B55467-8C7E-46C6-B32A-C58455643C25}/RP1254/A0127613.exe packed by FSG
>/mnt/disk/hda1/System Volume Information/_restore{39B55467-8C7E-46C6-B32A-C58455643C25}/RP1254/A0127613.exe infected with Trojan.MulDrop.origin
>/mnt/disk/hda1/System Volume Information/_restore{39B55467-8C7E-46C6-B32A-C58455643C25}/RP1254/A0127613.exe - archive BINARYRES
>>/mnt/disk/hda1/System Volume Information/_restore{39B55467-8C7E-46C6-B32A-C58455643C25}/RP1254/A0127613.exe/data001 packed by XOREXE
>>>/mnt/disk/hda1/System Volume Information/_restore{39B55467-8C7E-46C6-B32A-C58455643C25}/RP1254/A0127613.exe/data001 infected with Trojan.NtRootKit.2909
/mnt/disk/hda1/System Volume Information/_restore{39B55467-8C7E-46C6-B32A-C58455643C25}/RP1254/A0127614.dll infected with Trojan.DownLoader.origin
/mnt/disk/hda1/System Volume Information/_restore{39B55467-8C7E-46C6-B32A-C58455643C25}/RP1254/A0127614.dll packed by BINARYRES
>/mnt/disk/hda1/System Volume Information/_restore{39B55467-8C7E-46C6-B32A-C58455643C25}/RP1254/A0127614.dll infected with Trojan.DownLoad1.59715
>/mnt/disk/hda1/System Volume Information/_restore{39B55467-8C7E-46C6-B32A-C58455643C25}/RP1254/A0127614.dll - deleted!
/mnt/disk/hda1/System Volume Information/_restore{39B55467-8C7E-46C6-B32A-C58455643C25}/RP1254/A0127615.tsk infected with Trojan.PWS.Wsgame.19855
/mnt/disk/hda1/System Volume Information/_restore{39B55467-8C7E-46C6-B32A-C58455643C25}/RP1254/A0127615.tsk - deleted!
/mnt/disk/hda1/System Volume Information/_restore{39B55467-8C7E-46C6-B32A-C58455643C25}/RP1254/A0127616.exe infected with Trojan.PWS.Qqpass.4993
/mnt/disk/hda1/System Volume Information/_restore{39B55467-8C7E-46C6-B32A-C58455643C25}/RP1254/A0127616.exe - deleted!
/mnt/disk/hda1/System Volume Information/_restore{39B55467-8C7E-46C6-B32A-C58455643C25}/RP1254/A0127648.exe packed by MEW
>/mnt/disk/hda1/System Volume Information/_restore{39B55467-8C7E-46C6-B32A-C58455643C25}/RP1254/A0127648.exe infected with Trojan.PWS.Wsgame.20047
>/mnt/disk/hda1/System Volume Information/_restore{39B55467-8C7E-46C6-B32A-C58455643C25}/RP1254/A0127648.exe - deleted!
/mnt/disk/hda1/System Volume Information/_restore{39B55467-8C7E-46C6-B32A-C58455643C25}/RP1254/A0127649.exe packed by MEW
>/mnt/disk/hda1/System Volume Information/_restore{39B55467-8C7E-46C6-B32A-C58455643C25}/RP1254/A0127649.exe infected with Trojan.PWS.Wsgame.20047
>/mnt/disk/hda1/System Volume Information/_restore{39B55467-8C7E-46C6-B32A-C58455643C25}/RP1254/A0127649.exe - deleted!
/mnt/disk/hda1/System Volume Information/_restore{39B55467-8C7E-46C6-B32A-C58455643C25}/RP1254/A0127650.exe packed by MEW
>/mnt/disk/hda1/System Volume Information/_restore{39B55467-8C7E-46C6-B32A-C58455643C25}/RP1254/A0127650.exe infected with Trojan.PWS.Wsgame.20047
>/mnt/disk/hda1/System Volume Information/_restore{39B55467-8C7E-46C6-B32A-C58455643C25}/RP1254/A0127650.exe - deleted!
/mnt/disk/hda1/System Volume Information/_restore{39B55467-8C7E-46C6-B32A-C58455643C25}/RP1254/A0127652.exe packed by MEW
>/mnt/disk/hda1/System Volume Information/_restore{39B55467-8C7E-46C6-B32A-C58455643C25}/RP1254/A0127652.exe infected with Trojan.PWS.Wsgame.20047
>/mnt/disk/hda1/System Volume Information/_restore{39B55467-8C7E-46C6-B32A-C58455643C25}/RP1254/A0127652.exe - deleted!
/mnt/disk/hda1/System Volume Information/_restore{39B55467-8C7E-46C6-B32A-C58455643C25}/RP1254/A0127653.exe packed by MEW
>/mnt/disk/hda1/System Volume Information/_restore{39B55467-8C7E-46C6-B32A-C58455643C25}/RP1254/A0127653.exe infected with Trojan.PWS.Wsgame.20047
>/mnt/disk/hda1/System Volume Information/_restore{39B55467-8C7E-46C6-B32A-C58455643C25}/RP1254/A0127653.exe - deleted!
/mnt/disk/hda1/System Volume Information/_restore{39B55467-8C7E-46C6-B32A-C58455643C25}/RP1254/A0127654.exe packed by MEW
>/mnt/disk/hda1/System Volume Information/_restore{39B55467-8C7E-46C6-B32A-C58455643C25}/RP1254/A0127654.exe infected with Trojan.PWS.Wsgame.20047
>/mnt/disk/hda1/System Volume Information/_restore{39B55467-8C7E-46C6-B32A-C58455643C25}/RP1254/A0127654.exe - deleted!
/mnt/disk/hda1/System Volume Information/_restore{39B55467-8C7E-46C6-B32A-C58455643C25}/RP1254/A0127656.exe packed by MEW
>/mnt/disk/hda1/System Volume Information/_restore{39B55467-8C7E-46C6-B32A-C58455643C25}/RP1254/A0127656.exe infected with Trojan.PWS.Wsgame.19855
>/mnt/disk/hda1/System Volume Information/_restore{39B55467-8C7E-46C6-B32A-C58455643C25}/RP1254/A0127656.exe - deleted!
/mnt/disk/hda1/System Volume Information/_restore{39B55467-8C7E-46C6-B32A-C58455643C25}/RP1254/A0127657.exe packed by MEW
>/mnt/disk/hda1/System Volume Information/_restore{39B55467-8C7E-46C6-B32A-C58455643C25}/RP1254/A0127657.exe infected with Trojan.PWS.Wsgame.19855
>/mnt/disk/hda1/System Volume Information/_restore{39B55467-8C7E-46C6-B32A-C58455643C25}/RP1254/A0127657.exe - deleted!
/mnt/disk/hda1/System Volume Information/_restore{39B55467-8C7E-46C6-B32A-C58455643C25}/RP1254/A0127658.exe packed by MEW
>/mnt/disk/hda1/System Volume Information/_restore{39B55467-8C7E-46C6-B32A-C58455643C25}/RP1254/A0127658.exe infected with Trojan.PWS.Wsgame.20047
>/mnt/disk/hda1/System Volume Information/_restore{39B55467-8C7E-46C6-B32A-C58455643C25}/RP1254/A0127658.exe - deleted!
/mnt/disk/hda1/System Volume Information/_restore{39B55467-8C7E-46C6-B32A-C58455643C25}/RP1254/A0127660.dll infected with Trojan.PWS.Wsgame.19855
/mnt/disk/hda1/System Volume Information/_restore{39B55467-8C7E-46C6-B32A-C58455643C25}/RP1254/A0127660.dll - cured!
/mnt/disk/hda1/System Volume Information/_restore{39B55467-8C7E-46C6-B32A-C58455643C25}/RP1254/A0127660.dll - Ok
/mnt/disk/hda1/System Volume Information/_restore{39B55467-8C7E-46C6-B32A-C58455643C25}/RP1254/A0127661.exe packed by MEW
>/mnt/disk/hda1/System Volume Information/_restore{39B55467-8C7E-46C6-B32A-C58455643C25}/RP1254/A0127661.exe infected with Trojan.PWS.Wsgame.20047
>/mnt/disk/hda1/System Volume Information/_restore{39B55467-8C7E-46C6-B32A-C58455643C25}/RP1254/A0127661.exe - deleted!
/mnt/disk/hda1/System Volume Information/_restore{39B55467-8C7E-46C6-B32A-C58455643C25}/RP1254/A0127663.exe packed by MEW
>/mnt/disk/hda1/System Volume Information/_restore{39B55467-8C7E-46C6-B32A-C58455643C25}/RP1254/A0127663.exe infected with Trojan.PWS.Wsgame.20047
>/mnt/disk/hda1/System Volume Information/_restore{39B55467-8C7E-46C6-B32A-C58455643C25}/RP1254/A0127663.exe - deleted!
/mnt/disk/hda1/System Volume Information/_restore{39B55467-8C7E-46C6-B32A-C58455643C25}/RP1254/A0127667.exe packed by MEW
>/mnt/disk/hda1/System Volume Information/_restore{39B55467-8C7E-46C6-B32A-C58455643C25}/RP1254/A0127667.exe infected with Trojan.PWS.Wsgame.20047
>/mnt/disk/hda1/System Volume Information/_restore{39B55467-8C7E-46C6-B32A-C58455643C25}/RP1254/A0127667.exe - deleted!
/mnt/disk/hda1/System Volume Information/_restore{39B55467-8C7E-46C6-B32A-C58455643C25}/RP1254/A0127670.exe packed by MEW
>/mnt/disk/hda1/System Volume Information/_restore{39B55467-8C7E-46C6-B32A-C58455643C25}/RP1254/A0127670.exe infected with Trojan.PWS.Wsgame.20047
>/mnt/disk/hda1/System Volume Information/_restore{39B55467-8C7E-46C6-B32A-C58455643C25}/RP1254/A0127670.exe - deleted!
/mnt/disk/hda1/System Volume Information/_restore{39B55467-8C7E-46C6-B32A-C58455643C25}/RP1254/A0127671.exe packed by MEW
>/mnt/disk/hda1/System Volume Information/_restore{39B55467-8C7E-46C6-B32A-C58455643C25}/RP1254/A0127671.exe infected with Trojan.PWS.Wsgame.20047
>/mnt/disk/hda1/System Volume Information/_restore{39B55467-8C7E-46C6-B32A-C58455643C25}/RP1254/A0127671.exe - deleted!
/mnt/disk/hda1/System Volume Information/_restore{39B55467-8C7E-46C6-B32A-C58455643C25}/RP1254/A0127673.exe packed by MEW
>/mnt/disk/hda1/System Volume Information/_restore{39B55467-8C7E-46C6-B32A-C58455643C25}/RP1254/A0127673.exe infected with Trojan.PWS.Wsgame.20047
>/mnt/disk/hda1/System Volume Information/_restore{39B55467-8C7E-46C6-B32A-C58455643C25}/RP1254/A0127673.exe - deleted!
/mnt/disk/hda1/System Volume Information/_restore{39B55467-8C7E-46C6-B32A-C58455643C25}/RP1254/A0127674.exe packed by MEW
>/mnt/disk/hda1/System Volume Information/_restore{39B55467-8C7E-46C6-B32A-C58455643C25}/RP1254/A0127674.exe infected with Trojan.PWS.Wsgame.20047
>/mnt/disk/hda1/System Volume Information/_restore{39B55467-8C7E-46C6-B32A-C58455643C25}/RP1254/A0127674.exe - deleted!
/mnt/disk/hda1/System Volume Information/_restore{39B55467-8C7E-46C6-B32A-C58455643C25}/RP1254/A0127675.exe packed by MEW
>/mnt/disk/hda1/System Volume Information/_restore{39B55467-8C7E-46C6-B32A-C58455643C25}/RP1254/A0127675.exe infected with Trojan.PWS.Wsgame.20047
>/mnt/disk/hda1/System Volume Information/_restore{39B55467-8C7E-46C6-B32A-C58455643C25}/RP1254/A0127675.exe - deleted!
/mnt/disk/hda1/System Volume Information/_restore{39B55467-8C7E-46C6-B32A-C58455643C25}/RP1254/A0127676.exe packed by MEW
>/mnt/disk/hda1/System Volume Information/_restore{39B55467-8C7E-46C6-B32A-C58455643C25}/RP1254/A0127676.exe infected with Trojan.PWS.Wsgame.20047
>/mnt/disk/hda1/System Volume Information/_restore{39B55467-8C7E-46C6-B32A-C58455643C25}/RP1254/A0127676.exe - deleted!
/mnt/disk/hda1/System Volume Information/_restore{39B55467-8C7E-46C6-B32A-C58455643C25}/RP1254/A0127677.exe packed by MEW
>/mnt/disk/hda1/System Volume Information/_restore{39B55467-8C7E-46C6-B32A-C58455643C25}/RP1254/A0127677.exe infected with Trojan.PWS.Wsgame.20047
>/mnt/disk/hda1/System Volume Information/_restore{39B55467-8C7E-46C6-B32A-C58455643C25}/RP1254/A0127677.exe - deleted!
/mnt/disk/hda1/System Volume Information/_restore{39B55467-8C7E-46C6-B32A-C58455643C25}/RP1254/A0127678.exe packed by UPX
>/mnt/disk/hda1/System Volume Information/_restore{39B55467-8C7E-46C6-B32A-C58455643C25}/RP1254/A0127678.exe infected with Trojan.MulDrop1.20666
>/mnt/disk/hda1/System Volume Information/_restore{39B55467-8C7E-46C6-B32A-C58455643C25}/RP1254/A0127678.exe - deleted!
/mnt/disk/hda1/System Volume Information/_restore{39B55467-8C7E-46C6-B32A-C58455643C25}/RP1254/A0127681.exe packed by UPACK
>/mnt/disk/hda1/System Volume Information/_restore{39B55467-8C7E-46C6-B32A-C58455643C25}/RP1254/A0127681.exe infected with Trojan.PWS.Qqpass.4551
>/mnt/disk/hda1/System Volume Information/_restore{39B55467-8C7E-46C6-B32A-C58455643C25}/RP1254/A0127681.exe - deleted!
/mnt/disk/hda1/System Volume Information/_restore{39B55467-8C7E-46C6-B32A-C58455643C25}/RP1254/A0127682.exe contains an advertising software Adware.IEBar.52
/mnt/disk/hda1/System Volume Information/_restore{39B55467-8C7E-46C6-B32A-C58455643C25}/RP1254/A0127690.Sys packed by UPX
>/mnt/disk/hda1/System Volume Information/_restore{39B55467-8C7E-46C6-B32A-C58455643C25}/RP1254/A0127690.Sys infected with Trojan.PWS.Gamania.25318
>/mnt/disk/hda1/System Volume Information/_restore{39B55467-8C7E-46C6-B32A-C58455643C25}/RP1254/A0127690.Sys - deleted!
/mnt/disk/hda1/System Volume Information/_restore{39B55467-8C7E-46C6-B32A-C58455643C25}/RP1254/A0127712.exe packed by FSG
>/mnt/disk/hda1/System Volume Information/_restore{39B55467-8C7E-46C6-B32A-C58455643C25}/RP1254/A0127712.exe infected with Trojan.MulDrop.origin
>/mnt/disk/hda1/System Volume Information/_restore{39B55467-8C7E-46C6-B32A-C58455643C25}/RP1254/A0127712.exe - archive BINARYRES
>>/mnt/disk/hda1/System Volume Information/_restore{39B55467-8C7E-46C6-B32A-C58455643C25}/RP1254/A0127712.exe/data001 packed by XOREXE
>>>/mnt/disk/hda1/System Volume Information/_restore{39B55467-8C7E-46C6-B32A-C58455643C25}/RP1254/A0127712.exe/data001 infected with Trojan.NtRootKit.2909
/mnt/disk/hda1/System Volume Information/_restore{39B55467-8C7E-46C6-B32A-C58455643C25}/RP1254/A0127713.exe packed by FSG
>/mnt/disk/hda1/System Volume Information/_restore{39B55467-8C7E-46C6-B32A-C58455643C25}/RP1254/A0127713.exe infected with Trojan.MulDrop.origin
>/mnt/disk/hda1/System Volume Information/_restore{39B55467-8C7E-46C6-B32A-C58455643C25}/RP1254/A0127713.exe - archive BINARYRES
>>/mnt/disk/hda1/System Volume Information/_restore{39B55467-8C7E-46C6-B32A-C58455643C25}/RP1254/A0127713.exe/data001 packed by XOREXE
>>>/mnt/disk/hda1/System Volume Information/_restore{39B55467-8C7E-46C6-B32A-C58455643C25}/RP1254/A0127713.exe/data001 infected with Trojan.NtRootKit.2909
/mnt/disk/hda1/System Volume Information/_restore{39B55467-8C7E-46C6-B32A-C58455643C25}/RP1254/A0127724.exe packed by MEW
>/mnt/disk/hda1/System Volume Information/_restore{39B55467-8C7E-46C6-B32A-C58455643C25}/RP1254/A0127724.exe infected with Trojan.PWS.Wsgame.20047
>/mnt/disk/hda1/System Volume Information/_restore{39B55467-8C7E-46C6-B32A-C58455643C25}/RP1254/A0127724.exe - deleted!
/mnt/disk/hda1/System Volume Information/_restore{39B55467-8C7E-46C6-B32A-C58455643C25}/RP1254/A0127725.exe packed by MEW
>/mnt/disk/hda1/System Volume Information/_restore{39B55467-8C7E-46C6-B32A-C58455643C25}/RP1254/A0127725.exe infected with Trojan.PWS.Wsgame.20047
>/mnt/disk/hda1/System Volume Information/_restore{39B55467-8C7E-46C6-B32A-C58455643C25}/RP1254/A0127725.exe - deleted!
/mnt/disk/hda1/System Volume Information/_restore{39B55467-8C7E-46C6-B32A-C58455643C25}/RP1254/A0127726.exe packed by MEW
>/mnt/disk/hda1/System Volume Information/_restore{39B55467-8C7E-46C6-B32A-C58455643C25}/RP1254/A0127726.exe infected with Trojan.PWS.Wsgame.20047
>/mnt/disk/hda1/System Volume Information/_restore{39B55467-8C7E-46C6-B32A-C58455643C25}/RP1254/A0127726.exe - deleted!
/mnt/disk/hda1/System Volume Information/_restore{39B55467-8C7E-46C6-B32A-C58455643C25}/RP1254/A0127728.exe packed by MEW
>/mnt/disk/hda1/System Volume Information/_restore{39B55467-8C7E-46C6-B32A-C58455643C25}/RP1254/A0127728.exe infected with Trojan.PWS.Wsgame.20047
>/mnt/disk/hda1/System Volume Information/_restore{39B55467-8C7E-46C6-B32A-C58455643C25}/RP1254/A0127728.exe - deleted!
/mnt/disk/hda1/System Volume Information/_restore{39B55467-8C7E-46C6-B32A-C58455643C25}/RP1254/A0127729.exe packed by MEW
>/mnt/disk/hda1/System Volume Information/_restore{39B55467-8C7E-46C6-B32A-C58455643C25}/RP1254/A0127729.exe infected with Trojan.PWS.Wsgame.20047
>/mnt/disk/hda1/System Volume Information/_restore{39B55467-8C7E-46C6-B32A-C58455643C25}/RP1254/A0127729.exe - deleted!
/mnt/disk/hda1/System Volume Information/_restore{39B55467-8C7E-46C6-B32A-C58455643C25}/RP1254/A0127730.exe packed by UPX
>/mnt/disk/hda1/System Volume Information/_restore{39B55467-8C7E-46C6-B32A-C58455643C25}/RP1254/A0127730.exe infected with Trojan.MulDrop1.20666
>/mnt/disk/hda1/System Volume Information/_restore{39B55467-8C7E-46C6-B32A-C58455643C25}/RP1254/A0127730.exe - deleted!
/mnt/disk/hda1/System Volume Information/_restore{39B55467-8C7E-46C6-B32A-C58455643C25}/RP1254/A0127731.exe packed by MEW
>/mnt/disk/hda1/System Volume Information/_restore{39B55467-8C7E-46C6-B32A-C58455643C25}/RP1254/A0127731.exe infected with Trojan.PWS.Wsgame.20047
>/mnt/disk/hda1/System Volume Information/_restore{39B55467-8C7E-46C6-B32A-C58455643C25}/RP1254/A0127731.exe - deleted!
/mnt/disk/hda1/System Volume Information/_restore{39B55467-8C7E-46C6-B32A-C58455643C25}/RP1254/A0127732.exe packed by MEW
>/mnt/disk/hda1/System Volume Information/_restore{39B55467-8C7E-46C6-B32A-C58455643C25}/RP1254/A0127732.exe infected with Trojan.PWS.Wsgame.20047
>/mnt/disk/hda1/System Volume Information/_restore{39B55467-8C7E-46C6-B32A-C58455643C25}/RP1254/A0127732.exe - deleted!
/mnt/disk/hda1/System Volume Information/_restore{39B55467-8C7E-46C6-B32A-C58455643C25}/RP1254/A0127733.exe packed by MEW
>/mnt/disk/hda1/System Volume Information/_restore{39B55467-8C7E-46C6-B32A-C58455643C25}/RP1254/A0127733.exe infected with Trojan.PWS.Wsgame.20047
>/mnt/disk/hda1/System Volume Information/_restore{39B55467-8C7E-46C6-B32A-C58455643C25}/RP1254/A0127733.exe - deleted!
/mnt/disk/hda1/System Volume Information/_restore{39B55467-8C7E-46C6-B32A-C58455643C25}/RP1254/A0127735.exe packed by MEW
>/mnt/disk/hda1/System Volume Information/_restore{39B55467-8C7E-46C6-B32A-C58455643C25}/RP1254/A0127735.exe infected with Trojan.PWS.Wsgame.19855
>/mnt/disk/hda1/System Volume Information/_restore{39B55467-8C7E-46C6-B32A-C58455643C25}/RP1254/A0127735.exe - deleted!
/mnt/disk/hda1/System Volume Information/_restore{39B55467-8C7E-46C6-B32A-C58455643C25}/RP1254/A0127736.exe packed by MEW
>/mnt/disk/hda1/System Volume Information/_restore{39B55467-8C7E-46C6-B32A-C58455643C25}/RP1254/A0127736.exe infected with Trojan.PWS.Wsgame.20047
>/mnt/disk/hda1/System Volume Information/_restore{39B55467-8C7E-46C6-B32A-C58455643C25}/RP1254/A0127736.exe - deleted!
/mnt/disk/hda1/System Volume Information/_restore{39B55467-8C7E-46C6-B32A-C58455643C25}/RP1254/A0127737.tsk infected with Trojan.PWS.Wsgame.19855
/mnt/disk/hda1/System Volume Information/_restore{39B55467-8C7E-46C6-B32A-C58455643C25}/RP1254/A0127737.tsk - deleted!
/mnt/disk/hda1/System Volume Information/_restore{39B55467-8C7E-46C6-B32A-C58455643C25}/RP1254/A0127739.exe packed by MEW
>/mnt/disk/hda1/System Volume Information/_restore{39B55467-8C7E-46C6-B32A-C58455643C25}/RP1254/A0127739.exe infected with Trojan.PWS.Wsgame.20047
>/mnt/disk/hda1/System Volume Information/_restore{39B55467-8C7E-46C6-B32A-C58455643C25}/RP1254/A0127739.exe - deleted!
/mnt/disk/hda1/System Volume Information/_restore{39B55467-8C7E-46C6-B32A-C58455643C25}/RP1254/A0127741.exe packed by MEW
>/mnt/disk/hda1/System Volume Information/_restore{39B55467-8C7E-46C6-B32A-C58455643C25}/RP1254/A0127741.exe infected with Trojan.PWS.Wsgame.20047
>/mnt/disk/hda1/System Volume Information/_restore{39B55467-8C7E-46C6-B32A-C58455643C25}/RP1254/A0127741.exe - deleted!
/mnt/disk/hda1/System Volume Information/_restore{39B55467-8C7E-46C6-B32A-C58455643C25}/RP1254/A0127742.dll infected with Trojan.PWS.Wsgame.19855
/mnt/disk/hda1/System Volume Information/_restore{39B55467-8C7E-46C6-B32A-C58455643C25}/RP1254/A0127742.dll - cured!
/mnt/disk/hda1/System Volume Information/_restore{39B55467-8C7E-46C6-B32A-C58455643C25}/RP1254/A0127742.dll - Ok
/mnt/disk/hda1/System Volume Information/_restore{39B55467-8C7E-46C6-B32A-C58455643C25}/RP1254/A0127743.exe packed by MEW
>/mnt/disk/hda1/System Volume Information/_restore{39B55467-8C7E-46C6-B32A-C58455643C25}/RP1254/A0127743.exe infected with Trojan.PWS.Wsgame.20047
>/mnt/disk/hda1/System Volume Information/_restore{39B55467-8C7E-46C6-B32A-C58455643C25}/RP1254/A0127743.exe - deleted!
/mnt/disk/hda1/System Volume Information/_restore{39B55467-8C7E-46C6-B32A-C58455643C25}/RP1254/A0127745.exe packed by MEW
>/mnt/disk/hda1/System Volume Information/_restore{39B55467-8C7E-46C6-B32A-C58455643C25}/RP1254/A0127745.exe infected with Trojan.PWS.Wsgame.20047
>/mnt/disk/hda1/System Volume Information/_restore{39B55467-8C7E-46C6-B32A-C58455643C25}/RP1254/A0127745.exe - deleted!
/mnt/disk/hda1/System Volume Information/_restore{39B55467-8C7E-46C6-B32A-C58455643C25}/RP1254/A0127749.exe packed by MEW
>/mnt/disk/hda1/System Volume Information/_restore{39B55467-8C7E-46C6-B32A-C58455643C25}/RP1254/A0127749.exe infected with Trojan.PWS.Wsgame.20047
>/mnt/disk/hda1/System Volume Information/_restore{39B55467-8C7E-46C6-B32A-C58455643C25}/RP1254/A0127749.exe - deleted!
/mnt/disk/hda1/System Volume Information/_restore{39B55467-8C7E-46C6-B32A-C58455643C25}/RP1254/A0127751.exe packed by MEW
>/mnt/disk/hda1/System Volume Information/_restore{39B55467-8C7E-46C6-B32A-C58455643C25}/RP1254/A0127751.exe infected with Trojan.PWS.Wsgame.20047
>/mnt/disk/hda1/System Volume Information/_restore{39B55467-8C7E-46C6-B32A-C58455643C25}/RP1254/A0127751.exe - deleted!
/mnt/disk/hda1/System Volume Information/_restore{39B55467-8C7E-46C6-B32A-C58455643C25}/RP1254/A0127752.exe packed by UPACK
>/mnt/disk/hda1/System Volume Information/_restore{39B55467-8C7E-46C6-B32A-C58455643C25}/RP1254/A0127752.exe infected with Trojan.PWS.Qqpass.4551
>/mnt/disk/hda1/System Volume Information/_restore{39B55467-8C7E-46C6-B32A-C58455643C25}/RP1254/A0127752.exe - deleted!
/mnt/disk/hda1/System Volume Information/_restore{39B55467-8C7E-46C6-B32A-C58455643C25}/RP1254/A0127753.exe packed by MEW
>/mnt/disk/hda1/System Volume Information/_restore{39B55467-8C7E-46C6-B32A-C58455643C25}/RP1254/A0127753.exe infected with Trojan.PWS.Wsgame.20047
>/mnt/disk/hda1/System Volume Information/_restore{39B55467-8C7E-46C6-B32A-C58455643C25}/RP1254/A0127753.exe - deleted!
/mnt/disk/hda1/System Volume Information/_restore{39B55467-8C7E-46C6-B32A-C58455643C25}/RP1254/A0127755.exe packed by MEW
>/mnt/disk/hda1/System Volume Information/_restore{39B55467-8C7E-46C6-B32A-C58455643C25}/RP1254/A0127755.exe infected with Trojan.PWS.Wsgame.20047
>/mnt/disk/hda1/System Volume Information/_restore{39B55467-8C7E-46C6-B32A-C58455643C25}/RP1254/A0127755.exe - deleted!
/mnt/disk/hda1/System Volume Information/_restore{39B55467-8C7E-46C6-B32A-C58455643C25}/RP1254/A0127760.exe packed by MEW
>/mnt/disk/hda1/System Volume Information/_restore{39B55467-8C7E-46C6-B32A-C58455643C25}/RP1254/A0127760.exe infected with Trojan.PWS.Wsgame.20047
>/mnt/disk/hda1/System Volume Information/_restore{39B55467-8C7E-46C6-B32A-C58455643C25}/RP1254/A0127760.exe - deleted!
/mnt/disk/hda1/System Volume Information/_restore{39B55467-8C7E-46C6-B32A-C58455643C25}/RP1254/A0127761.exe packed by MEW
>/mnt/disk/hda1/System Volume Information/_restore{39B55467-8C7E-46C6-B32A-C58455643C25}/RP1254/A0127761.exe infected with Trojan.PWS.Wsgame.20047
>/mnt/disk/hda1/System Volume Information/_restore{39B55467-8C7E-46C6-B32A-C58455643C25}/RP1254/A0127761.exe - deleted!
/mnt/disk/hda1/System Volume Information/_restore{39B55467-8C7E-46C6-B32A-C58455643C25}/RP1254/A0127773.dll infected with Trojan.PWS.Wsgame.20660
/mnt/disk/hda1/System Volume Information/_restore{39B55467-8C7E-46C6-B32A-C58455643C25}/RP1254/A0127773.dll - deleted!
/mnt/disk/hda1/System Volume Information/_restore{39B55467-8C7E-46C6-B32A-C58455643C25}/RP1254/A0127787.exe packed by UPACK
>/mnt/disk/hda1/System Volume Information/_restore{39B55467-8C7E-46C6-B32A-C58455643C25}/RP1254/A0127787.exe infected with Trojan.PWS.Qqpass.4551
>/mnt/disk/hda1/System Volume Information/_restore{39B55467-8C7E-46C6-B32A-C58455643C25}/RP1254/A0127787.exe - deleted!
/mnt/disk/hda1/System Volume Information/_restore{39B55467-8C7E-46C6-B32A-C58455643C25}/RP1254/A0127798.exe infected with Trojan.MulDrop.3631
/mnt/disk/hda1/System Volume Information/_restore{39B55467-8C7E-46C6-B32A-C58455643C25}/RP1254/A0127798.exe - deleted!
/mnt/disk/hda1/System Volume Information/_restore{39B55467-8C7E-46C6-B32A-C58455643C25}/RP1254/A0127799.exe contains an advertising software Adware.IEBar.52
/mnt/disk/hda1/System Volume Information/_restore{39B55467-8C7E-46C6-B32A-C58455643C25}/RP1254/A0127800.dll contains an advertising software Adware.IEBar.52
/mnt/disk/hda1/System Volume Information/_restore{39B55467-8C7E-46C6-B32A-C58455643C25}/RP1254/A0127804.Sys packed by UPX
>/mnt/disk/hda1/System Volume Information/_restore{39B55467-8C7E-46C6-B32A-C58455643C25}/RP1254/A0127804.Sys infected with Trojan.PWS.Gamania.25318
>/mnt/disk/hda1/System Volume Information/_restore{39B55467-8C7E-46C6-B32A-C58455643C25}/RP1254/A0127804.Sys - deleted!
/mnt/disk/hda1/System Volume Information/_restore{39B55467-8C7E-46C6-B32A-C58455643C25}/RP1255/A0127854.exe contains an advertising software Adware.IEBar.52
/mnt/disk/hda1/System Volume Information/_restore{39B55467-8C7E-46C6-B32A-C58455643C25}/RP1255/A0127857.exe packed by UPX
>/mnt/disk/hda1/System Volume Information/_restore{39B55467-8C7E-46C6-B32A-C58455643C25}/RP1255/A0127857.exe - archive BINARYRES
>>/mnt/disk/hda1/System Volume Information/_restore{39B55467-8C7E-46C6-B32A-C58455643C25}/RP1255/A0127857.exe/data001 infected with Trojan.DownLoader1.8535
>>/mnt/disk/hda1/System Volume Information/_restore{39B55467-8C7E-46C6-B32A-C58455643C25}/RP1255/A0127857.exe/data002 infected with Trojan.DownLoader.origin
>>/mnt/disk/hda1/System Volume Information/_restore{39B55467-8C7E-46C6-B32A-C58455643C25}/RP1255/A0127857.exe/data002 packed by BINARYRES
>>>/mnt/disk/hda1/System Volume Information/_restore{39B55467-8C7E-46C6-B32A-C58455643C25}/RP1255/A0127857.exe/data002 infected with Trojan.DownLoad1.59715
>>/mnt/disk/hda1/System Volume Information/_restore{39B55467-8C7E-46C6-B32A-C58455643C25}/RP1255/A0127857.exe/data003 infected with Trojan.Click1.6534
/mnt/disk/hda1/System Volume Information/_restore{39B55467-8C7E-46C6-B32A-C58455643C25}/RP1255/A0127860.exe infected with Trojan.DownLoad.64067
/mnt/disk/hda1/System Volume Information/_restore{39B55467-8C7E-46C6-B32A-C58455643C25}/RP1255/A0127860.exe - deleted!
/mnt/disk/hda1/System Volume Information/_restore{39B55467-8C7E-46C6-B32A-C58455643C25}/RP1255/A0127861.exe infected with Trojan.DownLoad.64067
/mnt/disk/hda1/System Volume Information/_restore{39B55467-8C7E-46C6-B32A-C58455643C25}/RP1255/A0127861.exe - deleted!
/mnt/disk/hda1/System Volume Information/_restore{39B55467-8C7E-46C6-B32A-C58455643C25}/RP1255/A0127862.exe infected with Trojan.DownLoad.64067
/mnt/disk/hda1/System Volume Information/_restore{39B55467-8C7E-46C6-B32A-C58455643C25}/RP1255/A0127862.exe - deleted!
/mnt/disk/hda1/System Volume Information/_restore{39B55467-8C7E-46C6-B32A-C58455643C25}/RP1255/A0127863.exe infected with Trojan.DownLoad.64067
/mnt/disk/hda1/System Volume Information/_restore{39B55467-8C7E-46C6-B32A-C58455643C25}/RP1255/A0127863.exe - deleted!
/mnt/disk/hda1/System Volume Information/_restore{39B55467-8C7E-46C6-B32A-C58455643C25}/RP1255/A0127864.exe infected with Trojan.DownLoad.64067
/mnt/disk/hda1/System Volume Information/_restore{39B55467-8C7E-46C6-B32A-C58455643C25}/RP1255/A0127864.exe - deleted!
/mnt/disk/hda1/System Volume Information/_restore{39B55467-8C7E-46C6-B32A-C58455643C25}/RP1255/A0127865.exe infected with Trojan.DownLoad.64067
/mnt/disk/hda1/System Volume Information/_restore{39B55467-8C7E-46C6-B32A-C58455643C25}/RP1255/A0127865.exe - deleted!
/mnt/disk/hda1/System Volume Information/_restore{39B55467-8C7E-46C6-B32A-C58455643C25}/RP1255/A0127866.exe infected with Trojan.DownLoad.64067
/mnt/disk/hda1/System Volume Information/_restore{39B55467-8C7E-46C6-B32A-C58455643C25}/RP1255/A0127866.exe - deleted!
/mnt/disk/hda1/System Volume Information/_restore{39B55467-8C7E-46C6-B32A-C58455643C25}/RP1255/A0127867.exe infected with Trojan.DownLoad.64067
/mnt/disk/hda1/System Volume Information/_restore{39B55467-8C7E-46C6-B32A-C58455643C25}/RP1255/A0127867.exe - deleted!
/mnt/disk/hda1/System Volume Information/_restore{39B55467-8C7E-46C6-B32A-C58455643C25}/RP1255/A0127868.exe infected with Trojan.DownLoad.64067
/mnt/disk/hda1/System Volume Information/_restore{39B55467-8C7E-46C6-B32A-C58455643C25}/RP1255/A0127868.exe - deleted!
/mnt/disk/hda1/System Volume Information/_restore{39B55467-8C7E-46C6-B32A-C58455643C25}/RP1255/A0127869.exe infected with Trojan.DownLoad.64067
/mnt/disk/hda1/System Volume Information/_restore{39B55467-8C7E-46C6-B32A-C58455643C25}/RP1255/A0127869.exe - deleted!
/mnt/disk/hda1/System Volume Information/_restore{39B55467-8C7E-46C6-B32A-C58455643C25}/RP1255/A0128893.exe infected with Trojan.DownLoad.64067
/mnt/disk/hda1/System Volume Information/_restore{39B55467-8C7E-46C6-B32A-C58455643C25}/RP1255/A0128893.exe - deleted!
/mnt/disk/hda1/System Volume Information/_restore{39B55467-8C7E-46C6-B32A-C58455643C25}/RP1255/A0128894.exe infected with Trojan.DownLoad.64067
/mnt/disk/hda1/System Volume Information/_restore{39B55467-8C7E-46C6-B32A-C58455643C25}/RP1255/A0128894.exe - deleted!
/mnt/disk/hda1/System Volume Information/_restore{39B55467-8C7E-46C6-B32A-C58455643C25}/RP1255/A0128895.exe infected with Trojan.DownLoad.64067
/mnt/disk/hda1/System Volume Information/_restore{39B55467-8C7E-46C6-B32A-C58455643C25}/RP1255/A0128895.exe - deleted!
/mnt/disk/hda1/System Volume Information/_restore{39B55467-8C7E-46C6-B32A-C58455643C25}/RP1255/A0128896.exe infected with Trojan.DownLoad.64067
/mnt/disk/hda1/System Volume Information/_restore{39B55467-8C7E-46C6-B32A-C58455643C25}/RP1255/A0128896.exe - deleted!
/mnt/disk/hda1/System Volume Information/_restore{39B55467-8C7E-46C6-B32A-C58455643C25}/RP1255/A0128897.exe infected with Trojan.DownLoad.64067
/mnt/disk/hda1/System Volume Information/_restore{39B55467-8C7E-46C6-B32A-C58455643C25}/RP1255/A0128897.exe - deleted!
/mnt/disk/hda1/System Volume Information/_restore{39B55467-8C7E-46C6-B32A-C58455643C25}/RP1255/A0128898.exe infected with Trojan.DownLoad.64067
/mnt/disk/hda1/System Volume Information/_restore{39B55467-8C7E-46C6-B32A-C58455643C25}/RP1255/A0128898.exe - deleted!
/mnt/disk/hda1/System Volume Information/_restore{39B55467-8C7E-46C6-B32A-C58455643C25}/RP1255/A0128899.exe infected with Trojan.DownLoad.64067
/mnt/disk/hda1/System Volume Information/_restore{39B55467-8C7E-46C6-B32A-C58455643C25}/RP1255/A0128899.exe - deleted!
/mnt/disk/hda1/System Volume Information/_restore{39B55467-8C7E-46C6-B32A-C58455643C25}/RP1255/A0128900.exe infected with Trojan.DownLoad.64067
/mnt/disk/hda1/System Volume Information/_restore{39B55467-8C7E-46C6-B32A-C58455643C25}/RP1255/A0128900.exe - deleted!
/mnt/disk/hda1/System Volume Information/_restore{39B55467-8C7E-46C6-B32A-C58455643C25}/RP1255/A0128901.exe infected with Trojan.DownLoad.64067
/mnt/disk/hda1/System Volume Information/_restore{39B55467-8C7E-46C6-B32A-C58455643C25}/RP1255/A0128901.exe - deleted!
/mnt/disk/hda1/System Volume Information/_restore{39B55467-8C7E-46C6-B32A-C58455643C25}/RP1255/A0128902.exe infected with Trojan.DownLoad.64067
/mnt/disk/hda1/System Volume Information/_restore{39B55467-8C7E-46C6-B32A-C58455643C25}/RP1255/A0128902.exe - deleted!
/mnt/disk/hda1/System Volume Information/_restore{39B55467-8C7E-46C6-B32A-C58455643C25}/RP1255/A0128903.exe infected with Trojan.DownLoad.64067
/mnt/disk/hda1/System Volume Information/_restore{39B55467-8C7E-46C6-B32A-C58455643C25}/RP1255/A0128903.exe - deleted!
/mnt/disk/hda1/System Volume Information/_restore{39B55467-8C7E-46C6-B32A-C58455643C25}/RP1255/A0128873.exe infected with Trojan.DownLoad.64067
/mnt/disk/hda1/System Volume Information/_restore{39B55467-8C7E-46C6-B32A-C58455643C25}/RP1255/A0128873.exe - deleted!
/mnt/disk/hda1/System Volume Information/_restore{39B55467-8C7E-46C6-B32A-C58455643C25}/RP1255/A0128887.dll infected with Trojan.DownLoad1.59983
/mnt/disk/hda1/System Volume Information/_restore{39B55467-8C7E-46C6-B32A-C58455643C25}/RP1255/A0128887.dll - deleted!
/mnt/disk/hda1/System Volume Information/_restore{39B55467-8C7E-46C6-B32A-C58455643C25}/RP1255/A0127852.exe infected with Trojan.MulDrop.3631
/mnt/disk/hda1/System Volume Information/_restore{39B55467-8C7E-46C6-B32A-C58455643C25}/RP1255/A0127852.exe - deleted!
/mnt/disk/hda1/System Volume Information/_restore{39B55467-8C7E-46C6-B32A-C58455643C25}/RP1255/A0128911.exe infected with Trojan.DownLoad.64067
/mnt/disk/hda1/System Volume Information/_restore{39B55467-8C7E-46C6-B32A-C58455643C25}/RP1255/A0128911.exe - deleted!
/mnt/disk/hda1/System Volume Information/_restore{39B55467-8C7E-46C6-B32A-C58455643C25}/RP1255/A0128912.exe infected with Trojan.DownLoad.64067
/mnt/disk/hda1/System Volume Information/_restore{39B55467-8C7E-46C6-B32A-C58455643C25}/RP1255/A0128912.exe - deleted!
/mnt/disk/hda1/System Volume Information/_restore{39B55467-8C7E-46C6-B32A-C58455643C25}/RP1255/A0128913.exe infected with Trojan.DownLoad.64067
/mnt/disk/hda1/System Volume Information/_restore{39B55467-8C7E-46C6-B32A-C58455643C25}/RP1255/A0128913.exe - deleted!
/mnt/disk/hda1/System Volume Information/_restore{39B55467-8C7E-46C6-B32A-C58455643C25}/RP1255/A0128914.exe infected with Trojan.DownLoad.64067
/mnt/disk/hda1/System Volume Information/_restore{39B55467-8C7E-46C6-B32A-C58455643C25}/RP1255/A0128914.exe - deleted!
/mnt/disk/hda1/System Volume Information/_restore{39B55467-8C7E-46C6-B32A-C58455643C25}/RP1255/A0128915.exe infected with Trojan.DownLoad.64067
/mnt/disk/hda1/System Volume Information/_restore{39B55467-8C7E-46C6-B32A-C58455643C25}/RP1255/A0128915.exe - deleted!
/mnt/disk/hda1/System Volume Information/_restore{39B55467-8C7E-46C6-B32A-C58455643C25}/RP1255/A0128916.exe infected with Trojan.DownLoad.64067
/mnt/disk/hda1/System Volume Information/_restore{39B55467-8C7E-46C6-B32A-C58455643C25}/RP1255/A0128916.exe - deleted!
/mnt/disk/hda1/System Volume Information/_restore{39B55467-8C7E-46C6-B32A-C58455643C25}/RP1255/A0128917.exe infected with Trojan.DownLoad.64067
/mnt/disk/hda1/System Volume Information/_restore{39B55467-8C7E-46C6-B32A-C58455643C25}/RP1255/A0128917.exe - deleted!
/mnt/disk/hda1/System Volume Information/_restore{39B55467-8C7E-46C6-B32A-C58455643C25}/RP1255/A0128918.exe infected with Trojan.DownLoad.64067
/mnt/disk/hda1/System Volume Information/_restore{39B55467-8C7E-46C6-B32A-C58455643C25}/RP1255/A0128918.exe - deleted!
/mnt/disk/hda1/System Volume Information/_restore{39B55467-8C7E-46C6-B32A-C58455643C25}/RP1255/A0128919.exe infected with Trojan.DownLoad.64067
/mnt/disk/hda1/System Volume Information/_restore{39B55467-8C7E-46C6-B32A-C58455643C25}/RP1255/A0128919.exe - deleted!
/mnt/disk/hda1/System Volume Information/_restore{39B55467-8C7E-46C6-B32A-C58455643C25}/RP1255/A0128920.exe infected with Trojan.DownLoad.64067
/mnt/disk/hda1/System Volume Information/_restore{39B55467-8C7E-46C6-B32A-C58455643C25}/RP1255/A0128920.exe - deleted!
/mnt/disk/hda1/System Volume Information/_restore{39B55467-8C7E-46C6-B32A-C58455643C25}/RP1255/A0128921.exe infected with Trojan.DownLoad.64067
/mnt/disk/hda1/System Volume Information/_restore{39B55467-8C7E-46C6-B32A-C58455643C25}/RP1255/A0128921.exe - deleted!
/mnt/disk/hda1/System Volume Information/_restore{39B55467-8C7E-46C6-B32A-C58455643C25}/RP1257/A0129957.exe infected with Trojan.DownLoad.64067
/mnt/disk/hda1/System Volume Information/_restore{39B55467-8C7E-46C6-B32A-C58455643C25}/RP1257/A0129957.exe - deleted!
/mnt/disk/hda1/System Volume Information/_restore{39B55467-8C7E-46C6-B32A-C58455643C25}/RP1257/A0129958.exe infected with Trojan.DownLoad.64067
/mnt/disk/hda1/System Volume Information/_restore{39B55467-8C7E-46C6-B32A-C58455643C25}/RP1257/A0129958.exe - deleted!
/mnt/disk/hda1/System Volume Information/_restore{39B55467-8C7E-46C6-B32A-C58455643C25}/RP1257/A0129959.exe infected with Trojan.DownLoad.64067
/mnt/disk/hda1/System Volume Information/_restore{39B55467-8C7E-46C6-B32A-C58455643C25}/RP1257/A0129959.exe - deleted!
/mnt/disk/hda1/System Volume Information/_restore{39B55467-8C7E-46C6-B32A-C58455643C25}/RP1257/A0129960.exe infected with Trojan.DownLoad.64067
/mnt/disk/hda1/System Volume Information/_restore{39B55467-8C7E-46C6-B32A-C58455643C25}/RP1257/A0129960.exe - deleted!
/mnt/disk/hda1/System Volume Information/_restore{39B55467-8C7E-46C6-B32A-C58455643C25}/RP1257/A0129961.exe infected with Trojan.DownLoad.64067
/mnt/disk/hda1/System Volume Information/_restore{39B55467-8C7E-46C6-B32A-C58455643C25}/RP1257/A0129961.exe - deleted!
/mnt/disk/hda1/System Volume Information/_restore{39B55467-8C7E-46C6-B32A-C58455643C25}/RP1257/A0129962.exe infected with Trojan.DownLoad.64067
/mnt/disk/hda1/System Volume Information/_restore{39B55467-8C7E-46C6-B32A-C58455643C25}/RP1257/A0129962.exe - deleted!
/mnt/disk/hda1/System Volume Information/_restore{39B55467-8C7E-46C6-B32A-C58455643C25}/RP1257/A0129963.exe infected with Trojan.DownLoad.64067
/mnt/disk/hda1/System Volume Information/_restore{39B55467-8C7E-46C6-B32A-C58455643C25}/RP1257/A0129963.exe - deleted!
/mnt/disk/hda1/System Volume Information/_restore{39B55467-8C7E-46C6-B32A-C58455643C25}/RP1257/A0129964.exe infected with Trojan.DownLoad.64067
/mnt/disk/hda1/System Volume Information/_restore{39B55467-8C7E-46C6-B32A-C58455643C25}/RP1257/A0129964.exe - deleted!
/mnt/disk/hda1/System Volume Information/_restore{39B55467-8C7E-46C6-B32A-C58455643C25}/RP1257/A0129965.exe infected with Trojan.DownLoad.64067
/mnt/disk/hda1/System Volume Information/_restore{39B55467-8C7E-46C6-B32A-C58455643C25}/RP1257/A0129965.exe - deleted!
/mnt/disk/hda1/System Volume Information/_restore{39B55467-8C7E-46C6-B32A-C58455643C25}/RP1257/A0129966.exe infected with Trojan.DownLoad.64067
/mnt/disk/hda1/System Volume Information/_restore{39B55467-8C7E-46C6-B32A-C58455643C25}/RP1257/A0129966.exe - deleted!
/mnt/disk/hda1/System Volume Information/_restore{39B55467-8C7E-46C6-B32A-C58455643C25}/RP1257/A0129977.exe infected with Trojan.DownLoad.64067
/mnt/disk/hda1/System Volume Information/_restore{39B55467-8C7E-46C6-B32A-C58455643C25}/RP1257/A0129977.exe - deleted!
/mnt/disk/hda1/System Volume Information/_restore{39B55467-8C7E-46C6-B32A-C58455643C25}/RP1257/A0129978.exe infected with Trojan.DownLoad.64067
/mnt/disk/hda1/System Volume Information/_restore{39B55467-8C7E-46C6-B32A-C58455643C25}/RP1257/A0129978.exe - deleted!
/mnt/disk/hda1/System Volume Information/_restore{39B55467-8C7E-46C6-B32A-C58455643C25}/RP1257/A0129979.exe infected with Trojan.DownLoad.64067
/mnt/disk/hda1/System Volume Information/_restore{39B55467-8C7E-46C6-B32A-C58455643C25}/RP1257/A0129979.exe - deleted!
/mnt/disk/hda1/System Volume Information/_restore{39B55467-8C7E-46C6-B32A-C58455643C25}/RP1257/A0129980.exe infected with Trojan.DownLoad.64067
/mnt/disk/hda1/System Volume Information/_restore{39B55467-8C7E-46C6-B32A-C58455643C25}/RP1257/A0129980.exe - deleted!
/mnt/disk/hda1/System Volume Information/_restore{39B55467-8C7E-46C6-B32A-C58455643C25}/RP1257/A0129981.exe infected with Trojan.DownLoad.64067
/mnt/disk/hda1/System Volume Information/_restore{39B55467-8C7E-46C6-B32A-C58455643C25}/RP1257/A0129981.exe - deleted!
/mnt/disk/hda1/System Volume Information/_restore{39B55467-8C7E-46C6-B32A-C58455643C25}/RP1257/A0129982.exe infected with Trojan.DownLoad.64067
/mnt/disk/hda1/System Volume Information/_restore{39B55467-8C7E-46C6-B32A-C58455643C25}/RP1257/A0129982.exe - deleted!
/mnt/disk/hda1/System Volume Information/_restore{39B55467-8C7E-46C6-B32A-C58455643C25}/RP1257/A0129983.exe infected with Trojan.DownLoad.64067
/mnt/disk/hda1/System Volume Information/_restore{39B55467-8C7E-46C6-B32A-C58455643C25}/RP1257/A0129983.exe - deleted!
/mnt/disk/hda1/System Volume Information/_restore{39B55467-8C7E-46C6-B32A-C58455643C25}/RP1257/A0129984.exe infected with Trojan.DownLoad.64067
/mnt/disk/hda1/System Volume Information/_restore{39B55467-8C7E-46C6-B32A-C58455643C25}/RP1257/A0129984.exe - deleted!
/mnt/disk/hda1/System Volume Information/_restore{39B55467-8C7E-46C6-B32A-C58455643C25}/RP1257/A0129985.exe infected with Trojan.DownLoad.64067
/mnt/disk/hda1/System Volume Information/_restore{39B55467-8C7E-46C6-B32A-C58455643C25}/RP1257/A0129985.exe - deleted!
/mnt/disk/hda1/System Volume Information/_restore{39B55467-8C7E-46C6-B32A-C58455643C25}/RP1257/A0129986.exe infected with Trojan.DownLoad.64067
/mnt/disk/hda1/System Volume Information/_restore{39B55467-8C7E-46C6-B32A-C58455643C25}/RP1257/A0129986.exe - deleted!
/mnt/disk/hda1/System Volume Information/_restore{39B55467-8C7E-46C6-B32A-C58455643C25}/RP1257/A0131980.exe infected with Trojan.DownLoad.64067
/mnt/disk/hda1/System Volume Information/_restore{39B55467-8C7E-46C6-B32A-C58455643C25}/RP1257/A0131980.exe - deleted!
/mnt/disk/hda1/System Volume Information/_restore{39B55467-8C7E-46C6-B32A-C58455643C25}/RP1257/A0131981.exe infected with Trojan.DownLoad.64067
/mnt/disk/hda1/System Volume Information/_restore{39B55467-8C7E-46C6-B32A-C58455643C25}/RP1257/A0131981.exe - deleted!
/mnt/disk/hda1/System Volume Information/_restore{39B55467-8C7E-46C6-B32A-C58455643C25}/RP1257/A0131982.exe infected with Trojan.DownLoad.64067
/mnt/disk/hda1/System Volume Information/_restore{39B55467-8C7E-46C6-B32A-C58455643C25}/RP1257/A0131982.exe - deleted!
/mnt/disk/hda1/System Volume Information/_restore{39B55467-8C7E-46C6-B32A-C58455643C25}/RP1257/A0131983.exe infected with Trojan.DownLoad.64067
/mnt/disk/hda1/System Volume Information/_restore{39B55467-8C7E-46C6-B32A-C58455643C25}/RP1257/A0131983.exe - deleted!
/mnt/disk/hda1/System Volume Information/_restore{39B55467-8C7E-46C6-B32A-C58455643C25}/RP1257/A0131984.exe infected with Trojan.DownLoad.64067
/mnt/disk/hda1/System Volume Information/_restore{39B55467-8C7E-46C6-B32A-C58455643C25}/RP1257/A0131984.exe - deleted!
/mnt/disk/hda1/System Volume Information/_restore{39B55467-8C7E-46C6-B32A-C58455643C25}/RP1257/A0131985.exe infected with Trojan.DownLoad.64067
/mnt/disk/hda1/System Volume Information/_restore{39B55467-8C7E-46C6-B32A-C58455643C25}/RP1257/A0131985.exe - deleted!
/mnt/disk/hda1/System Volume Information/_restore{39B55467-8C7E-46C6-B32A-C58455643C25}/RP1257/A0131986.exe infected with Trojan.DownLoad.64067
/mnt/disk/hda1/System Volume Information/_restore{39B55467-8C7E-46C6-B32A-C58455643C25}/RP1257/A0131986.exe - deleted!
/mnt/disk/hda1/System Volume Information/_restore{39B55467-8C7E-46C6-B32A-C58455643C25}/RP1257/A0131987.exe infected with Trojan.DownLoad.64067
/mnt/disk/hda1/System Volume Information/_restore{39B55467-8C7E-46C6-B32A-C58455643C25}/RP1257/A0131987.exe - deleted!
/mnt/disk/hda1/System Volume Information/_restore{39B55467-8C7E-46C6-B32A-C58455643C25}/RP1257/A0131988.exe infected with Trojan.DownLoad.64067
/mnt/disk/hda1/System Volume Information/_restore{39B55467-8C7E-46C6-B32A-C58455643C25}/RP1257/A0131988.exe - deleted!
/mnt/disk/hda1/System Volume Information/_restore{39B55467-8C7E-46C6-B32A-C58455643C25}/RP1257/A0131989.exe infected with Trojan.DownLoad.64067
/mnt/disk/hda1/System Volume Information/_restore{39B55467-8C7E-46C6-B32A-C58455643C25}/RP1257/A0131989.exe - deleted!
/mnt/disk/hda1/WINDOWS/zeta.exe contains an advertising software Adware.BargainBuddy
/mnt/disk/hda1/WINDOWS/lycos.exe - archive NSIS
>/mnt/disk/hda1/WINDOWS/lycos.exe/script.bin - Ok
>/mnt/disk/hda1/WINDOWS/lycos.exe/rrentVersion\Uninstall\Lycos Sidesearch - Ok
>/mnt/disk/hda1/WINDOWS/lycos.exe/0x0000FFFF - Ok
>/mnt/disk/hda1/WINDOWS/lycos.exe/offline.htm - archive HTML
>>/mnt/disk/hda1/WINDOWS/lycos.exe/offline.htm/Script.0 - Ok
>/mnt/disk/hda1/WINDOWS/lycos.exe/offline.htm - Ok
>/mnt/disk/hda1/WINDOWS/lycos.exe/_ contains an advertising software Adware.SideSearch
/mnt/disk/hda1/WINDOWS/autoheal.exe contains an advertising software Adware.BargainBuddy
/mnt/disk/hda1/WINDOWS/UoDo/game.dll contains an advertising software Adware.Cinmus.26415
/mnt/disk/hda1/WINDOWS/host/smss.exe infected with Trojan.Click.64105
/mnt/disk/hda1/WINDOWS/host/smss.exe - deleted!
/mnt/disk/hda1/WINDOWS/system/olepro32.dll infected with Trojan.PWS.Wsgame.19855
/mnt/disk/hda1/WINDOWS/system/olepro32.dll - cured!
/mnt/disk/hda1/WINDOWS/system/olepro32.dll - Ok
/mnt/disk/hda1/WINDOWS/system/olepro32.dll.bank infected with Trojan.PWS.Wsgame.19855
/mnt/disk/hda1/WINDOWS/system/olepro32.dll.bank - cured!
/mnt/disk/hda1/WINDOWS/system/olepro32.dll.bank - Ok
/mnt/disk/hda1/WINDOWS/system/TIM1A7.tsk infected with Trojan.PWS.Wsgame.19855
/mnt/disk/hda1/WINDOWS/system/TIM1A7.tsk - deleted!
/mnt/disk/hda1/WINDOWS/system/TIM1B7.tsk infected with Trojan.PWS.Wsgame.19855
/mnt/disk/hda1/WINDOWS/system/TIM1B7.tsk - deleted!
/mnt/disk/hda1/WINDOWS/system/TIM1C7.tsk infected with Trojan.PWS.Wsgame.19855
/mnt/disk/hda1/WINDOWS/system/TIM1C7.tsk - deleted!
/mnt/disk/hda1/WINDOWS/system/TIM1D.tsk infected with Trojan.PWS.Wsgame.19855
/mnt/disk/hda1/WINDOWS/system/TIM1D.tsk - deleted!
/mnt/disk/hda1/WINDOWS/system/TIM1D7.tsk infected with Trojan.PWS.Wsgame.19855
/mnt/disk/hda1/WINDOWS/system/TIM1D7.tsk - deleted!
/mnt/disk/hda1/WINDOWS/system/TIM34.tsk infected with Trojan.PWS.Wsgame.19855
/mnt/disk/hda1/WINDOWS/system/TIM34.tsk - deleted!
/mnt/disk/hda1/WINDOWS/system/TIM45.tsk infected with Trojan.PWS.Wsgame.19855
/mnt/disk/hda1/WINDOWS/system/TIM45.tsk - deleted!
/mnt/disk/hda1/WINDOWS/system/TIM57.tsk infected with Trojan.PWS.Wsgame.19855
/mnt/disk/hda1/WINDOWS/system/TIM57.tsk - deleted!
/mnt/disk/hda1/WINDOWS/system/TIM63.tsk infected with Trojan.PWS.Wsgame.19855
/mnt/disk/hda1/WINDOWS/system/TIM63.tsk - deleted!
/mnt/disk/hda1/WINDOWS/system/TIM67.tsk infected with Trojan.PWS.Wsgame.19855
/mnt/disk/hda1/WINDOWS/system/TIM67.tsk - deleted!
/mnt/disk/hda1/WINDOWS/system/TIM7.tsk infected with Trojan.PWS.Wsgame.19855
/mnt/disk/hda1/WINDOWS/system/TIM7.tsk - deleted!
/mnt/disk/hda1/WINDOWS/system/TIM79.tsk infected with Trojan.PWS.Wsgame.19855
/mnt/disk/hda1/WINDOWS/system/TIM79.tsk - deleted!
/mnt/disk/hda1/WINDOWS/system/TIM89.tsk infected with Trojan.PWS.Wsgame.19855
/mnt/disk/hda1/WINDOWS/system/TIM89.tsk - deleted!
/mnt/disk/hda1/WINDOWS/system32/24464.exe - archive NSIS
>/mnt/disk/hda1/WINDOWS/system32/24464.exe/script.bin - Ok
>/mnt/disk/hda1/WINDOWS/system32/24464.exe/___\System.dll - Ok
>/mnt/disk/hda1/WINDOWS/system32/24464.exe/EasyTime.exe infected with Trojan.DownLoad.64067
>/mnt/disk/hda1/WINDOWS/system32/24464.exe/user.dat - Ok
>/mnt/disk/hda1/WINDOWS/system32/24464.exe/load.dat - Ok
/mnt/disk/hda1/WINDOWS/system32/28145.exe probably infected with DLOADER.Trojan
/mnt/disk/hda1/WINDOWS/system32/28145.exe packed by BINARYRES
/mnt/disk/hda1/WINDOWS/system32/mty2176.dll packed by UPX
>/mnt/disk/hda1/WINDOWS/system32/mty2176.dll - archive BINARYRES
>>/mnt/disk/hda1/WINDOWS/system32/mty2176.dll/data001 infected with Trojan.DownLoad1.59715
>>/mnt/disk/hda1/WINDOWS/system32/mty2176.dll/data002 infected with Trojan.MulDrop1.20885
/mnt/disk/hda1/WINDOWS/system32/mty9903.dll packed by UPX
>/mnt/disk/hda1/WINDOWS/system32/mty9903.dll - archive BINARYRES
>>/mnt/disk/hda1/WINDOWS/system32/mty9903.dll/data001 infected with Trojan.DownLoader1.8936
>>/mnt/disk/hda1/WINDOWS/system32/mty9903.dll/data002 infected with Trojan.Click.58055
/mnt/disk/hda1/WINDOWS/system32/angelex.exe contains an advertising software Adware.BargainBuddy
/mnt/disk/hda1/WINDOWS/system32/exdl.exe contains an advertising software Adware.BargainBuddy
/mnt/disk/hda1/WINDOWS/system32/exdl0.exe contains an advertising software Adware.BargainBuddy
/mnt/disk/hda1/WINDOWS/system32/FloodCore.dll infected with Trojan.DownLoad1.59715
/mnt/disk/hda1/WINDOWS/system32/FloodCore.dll - deleted!
/mnt/disk/hda1/WINDOWS/system32/mqexdlm.srg contains an advertising software Adware.BargainBuddy
/mnt/disk/hda1/WINDOWS/system32/NoViewRun2.dll infected with Trojan.DownLoad1.59983
/mnt/disk/hda1/WINDOWS/system32/NoViewRun2.dll - deleted!
/mnt/disk/hda1/WINDOWS/system32/olepro32.dll.dat infected with Trojan.PWS.Wsgame.19855
/mnt/disk/hda1/WINDOWS/system32/olepro32.dll.dat - cured!
/mnt/disk/hda1/WINDOWS/system32/olepro32.dll.dat - Ok
/mnt/disk/hda1/WINDOWS/system32/runie.dll infected with Trojan.DownLoad1.59983
/mnt/disk/hda1/WINDOWS/system32/runie.dll - deleted!
/mnt/disk/hda1/WINDOWS/system32/talq6.dll infected with Trojan.DownLoader.origin
/mnt/disk/hda1/WINDOWS/system32/talq6.dll packed by BINARYRES
>/mnt/disk/hda1/WINDOWS/system32/talq6.dll infected with Trojan.DownLoad1.59715
>/mnt/disk/hda1/WINDOWS/system32/talq6.dll - deleted!
/mnt/disk/hda1/WINDOWS/system32/talqq.dll infected with Trojan.DownLoader1.8535
/mnt/disk/hda1/WINDOWS/system32/talqq.dll - deleted!
/mnt/disk/hda1/WINDOWS/system32/HtmlUI.dll packed by UPX
>/mnt/disk/hda1/WINDOWS/system32/HtmlUI.dll infected with Trojan.MulDrop1.20885
>/mnt/disk/hda1/WINDOWS/system32/HtmlUI.dll - deleted!
/mnt/disk/hda1/WINDOWS/system32/icmk6.dll infected with Trojan.DownLoader.origin
/mnt/disk/hda1/WINDOWS/system32/icmk6.dll packed by BINARYRES
>/mnt/disk/hda1/WINDOWS/system32/icmk6.dll infected with Trojan.DownLoad1.59715
>/mnt/disk/hda1/WINDOWS/system32/icmk6.dll - deleted!
/mnt/disk/hda1/WINDOWS/system32/icmkq.dll infected with Trojan.DownLoader1.8535
/mnt/disk/hda1/WINDOWS/system32/icmkq.dll - deleted!
/mnt/disk/hda1/WINDOWS/system32/SDCCInfo.dll infected with Trojan.Click.27213
/mnt/disk/hda1/WINDOWS/system32/SDCCInfo.dll - deleted!
/mnt/disk/hda1/WINDOWS/system32/nvms.dll contains an advertising software Adware.Exact
/mnt/disk/hda1/WINDOWS/system32/mabu6.dll infected with Trojan.DownLoader.origin
/mnt/disk/hda1/WINDOWS/system32/mabu6.dll packed by BINARYRES
>/mnt/disk/hda1/WINDOWS/system32/mabu6.dll infected with Trojan.DownLoad1.59715
>/mnt/disk/hda1/WINDOWS/system32/mabu6.dll - deleted!
/mnt/disk/hda1/WINDOWS/system32/mabua.dll infected with Trojan.DownLoader1.8535
/mnt/disk/hda1/WINDOWS/system32/mabua.dll - deleted!
/mnt/disk/hda1/WINDOWS/system32/javex80.vxd - archive ZIP
>/mnt/disk/hda1/WINDOWS/system32/javex80.vxd/C:/WINDOWS/system32/vx2.nls - Ok
>/mnt/disk/hda1/WINDOWS/system32/javex80.vxd/C:/WINDOWS/system32/vx2x.nls - Ok
>/mnt/disk/hda1/WINDOWS/system32/javex80.vxd/C:/WINDOWS/system32/nvms.dll contains an advertising software Adware.Exact
>/mnt/disk/hda1/WINDOWS/system32/javex80.vxd/C:/Program Files/NaviSearch/ad.dat - Ok
>/mnt/disk/hda1/WINDOWS/system32/javex80.vxd/C:/Program Files/NaviSearch/Uninstall.exe - archive NSIS
>>/mnt/disk/hda1/WINDOWS/system32/javex80.vxd/C:/Program Files/NaviSearch/Uninstall.exe/script.bin - Ok
>>/mnt/disk/hda1/WINDOWS/system32/javex80.vxd/C:/Program Files/NaviSearch/Uninstall.exe/Settings - Ok
>>/mnt/disk/hda1/WINDOWS/system32/javex80.vxd/C:/Program Files/NaviSearch/Uninstall.exe/___\ioSpecial.ini - Ok
>>/mnt/disk/hda1/WINDOWS/system32/javex80.vxd/C:/Program Files/NaviSearch/Uninstall.exe/___\modern-wizard.bmp - Ok
>>/mnt/disk/hda1/WINDOWS/system32/javex80.vxd/C:/Program Files/NaviSearch/Uninstall.exe/___\modern-header.bmp - Ok
>>/mnt/disk/hda1/WINDOWS/system32/javex80.vxd/C:/Program Files/NaviSearch/Uninstall.exe/___\nlsA.ini - Ok
>>/mnt/disk/hda1/WINDOWS/system32/javex80.vxd/C:/Program Files/NaviSearch/Uninstall.exe/___\nlsB.ini - Ok
>>/mnt/disk/hda1/WINDOWS/system32/javex80.vxd/C:/Program Files/NaviSearch/Uninstall.exe/___\nlsC.ini - Ok
>/mnt/disk/hda1/WINDOWS/system32/javex80.vxd/C:/Program Files/NaviSearch/Uninstall.exe - Ok
>/mnt/disk/hda1/WINDOWS/system32/javex80.vxd/C:/Program Files/NaviSearch/bin/nls.exe contains an advertising software Adware.Exact
/mnt/disk/hda1/WINDOWS/system32/javexulm.vxd contains an advertising software Adware.BargainBuddy
/mnt/disk/hda1/WINDOWS/system32/exul.exe contains an advertising software Adware.BargainBuddy
/mnt/disk/hda1/WINDOWS/system32/netut80ex.vxd - archive ZIP
>/mnt/disk/hda1/WINDOWS/system32/netut80ex.vxd/C:/WINDOWS/system32/vx0.nls - Ok
>/mnt/disk/hda1/WINDOWS/system32/netut80ex.vxd/C:/WINDOWS/system32/exdl.exe contains an advertising software Adware.BargainBuddy
>/mnt/disk/hda1/WINDOWS/system32/netut80ex.vxd/C:/WINDOWS/system32/mqexdlm.srg contains an advertising software Adware.BargainBuddy
>/mnt/disk/hda1/WINDOWS/system32/netut80ex.vxd/C:/WINDOWS/system32/exul.exe contains an advertising software Adware.BargainBuddy
>/mnt/disk/hda1/WINDOWS/system32/netut80ex.vxd/C:/WINDOWS/system32/javexulm.vxd contains an advertising software Adware.BargainBuddy
>/mnt/disk/hda1/WINDOWS/system32/netut80ex.vxd/C:/WINDOWS/system32/bbchk.exe - Ok
>/mnt/disk/hda1/WINDOWS/system32/netut80ex.vxd/C:/WINDOWS/system32/msexreg.exe - Ok
>/mnt/disk/hda1/WINDOWS/system32/netut80ex.vxd/C:/WINDOWS/system32/instsrv.exe contains an intrusion tool Tool.SrvRunner
>/mnt/disk/hda1/WINDOWS/system32/netut80ex.vxd/C:/WINDOWS/system32/exclean.exe - archive NSIS
>>/mnt/disk/hda1/WINDOWS/system32/netut80ex.vxd/C:/WINDOWS/system32/exclean.exe/script.bin - Ok
>>/mnt/disk/hda1/WINDOWS/system32/netut80ex.vxd/C:/WINDOWS/system32/exclean.exe/1.file - Ok
>/mnt/disk/hda1/WINDOWS/system32/netut80ex.vxd/C:/WINDOWS/system32/exclean.exe - Ok
>/mnt/disk/hda1/WINDOWS/system32/netut80ex.vxd/C:/WINDOWS/system32/basexinfo.txt - Ok
>/mnt/disk/hda1/WINDOWS/system32/netut80ex.vxd/C:/WINDOWS/system32/basexuk.txt - Ok
/mnt/disk/hda1/WINDOWS/system32/ofzm.dll infected with Trojan.Koutad.1
/mnt/disk/hda1/WINDOWS/system32/ofzm.dll - deleted!
/mnt/disk/hda1/WINDOWS/system32/Windows.dat infected with Trojan.Siggen1.31814
/mnt/disk/hda1/WINDOWS/system32/Windows.dat - deleted!
/mnt/disk/hda1/WINDOWS/system32/ostmnzw.exe infected with Trojan.DownLoader1.8667
/mnt/disk/hda1/WINDOWS/system32/ostmnzw.exe - deleted!
/mnt/disk/hda1/WINDOWS/system32/ggsfs7.dll infected with Trojan.Click1.6915
/mnt/disk/hda1/WINDOWS/system32/ggsfs7.dll - deleted!
/mnt/disk/hda1/WINDOWS/system32/ggsss7.dll infected with Trojan.Click1.6534
/mnt/disk/hda1/WINDOWS/system32/ggsss7.dll - deleted!
/mnt/disk/hda1/WINDOWS/system32/6334.exe packed by UPX
>/mnt/disk/hda1/WINDOWS/system32/6334.exe infected with Trojan.Click.64105
>/mnt/disk/hda1/WINDOWS/system32/6334.exe - deleted!
/mnt/disk/hda1/WINDOWS/system32/1.2.8/WndHook.dll infected with Trojan.DownLoader1.6838
/mnt/disk/hda1/WINDOWS/system32/1.2.8/WndHook.dll - deleted!
/mnt/disk/hda1/WINDOWS/system32/dllcache/icmk6.dll infected with Trojan.DownLoader.origin
/mnt/disk/hda1/WINDOWS/system32/dllcache/icmk6.dll packed by BINARYRES
>/mnt/disk/hda1/WINDOWS/system32/dllcache/icmk6.dll infected with Trojan.DownLoad1.59715
>/mnt/disk/hda1/WINDOWS/system32/dllcache/icmk6.dll - deleted!
/mnt/disk/hda1/WINDOWS/system32/dllcache/mabu6.dll infected with Trojan.DownLoader.origin
/mnt/disk/hda1/WINDOWS/system32/dllcache/mabu6.dll packed by BINARYRES
>/mnt/disk/hda1/WINDOWS/system32/dllcache/mabu6.dll infected with Trojan.DownLoad1.59715
>/mnt/disk/hda1/WINDOWS/system32/dllcache/mabu6.dll - deleted!
/mnt/disk/hda1/WINDOWS/system32/dllcache/talq6.dll infected with Trojan.DownLoader.origin
/mnt/disk/hda1/WINDOWS/system32/dllcache/talq6.dll packed by BINARYRES
>/mnt/disk/hda1/WINDOWS/system32/dllcache/talq6.dll infected with Trojan.DownLoad1.59715
>/mnt/disk/hda1/WINDOWS/system32/dllcache/talq6.dll - deleted!
/mnt/disk/hda1/WINDOWS/system32/drivers/aswsy.sys infected with Trojan.Koutad.1
/mnt/disk/hda1/WINDOWS/system32/drivers/aswsy.sys - deleted!
/mnt/disk/hda1/WINDOWS/system32/Catius/wihcqmyfcait.dll probably infected with DLOADER.Trojan
/mnt/disk/hda1/WINDOWS/system32/Catius/wihcqmyfcait.dll packed by BINARYRES
>/mnt/disk/hda1/WINDOWS/system32/Catius/wihcqmyfcait.dll infected with Trojan.Siggen.64438
>/mnt/disk/hda1/WINDOWS/system32/Catius/wihcqmyfcait.dll - deleted!
/mnt/disk/hda1/WINDOWS/system32/lzghzwp/lsass.exe infected with Trojan.DownLoader1.8017
/mnt/disk/hda1/WINDOWS/system32/lzghzwp/lsass.exe - deleted!
/mnt/disk/hda1/WINDOWS/system32/6739F5/6391BA.EXE packed by PESTUB
>/mnt/disk/hda1/WINDOWS/system32/6739F5/6391BA.EXE packed by PESTUB
>>/mnt/disk/hda1/WINDOWS/system32/6739F5/6391BA.EXE packed by FLY-CODE
>>>/mnt/disk/hda1/WINDOWS/system32/6739F5/6391BA.EXE packed by CFCRYPT
>>>>/mnt/disk/hda1/WINDOWS/system32/6739F5/6391BA.EXE infected with Win32.HLLW.Autoruner.4360
>>>>/mnt/disk/hda1/WINDOWS/system32/6739F5/6391BA.EXE - deleted!
/mnt/disk/hda1/WINDOWS/system32/73A8A0/WV4182AF.EXE infected with Trojan.DownLoad1.53443
/mnt/disk/hda1/WINDOWS/system32/73A8A0/WV4182AF.EXE - deleted!
/mnt/disk/hda1/WINDOWS/system32/73A8A0/B-7U7.EXE infected with Trojan.DownLoad1.53443
/mnt/disk/hda1/WINDOWS/system32/73A8A0/B-7U7.EXE - deleted!
/mnt/disk/hda1/WINDOWS/system32/73A8A0/GC-9876.EXE infected with Trojan.PWS.Qqpass.4357
/mnt/disk/hda1/WINDOWS/system32/73A8A0/GC-9876.EXE - deleted!
/mnt/disk/hda1/WINDOWS/system32/73A8A0/X6-BD274.EXE infected with Trojan.Siggen.47608
/mnt/disk/hda1/WINDOWS/system32/73A8A0/X6-BD274.EXE - deleted!
/mnt/disk/hda1/WINDOWS/system32/73A8A0/XV409C2A.EXE infected with Trojan.PWS.Qqpass.4357
/mnt/disk/hda1/WINDOWS/system32/73A8A0/XV409C2A.EXE - deleted!
/mnt/disk/hda1/WINDOWS/system32/73A8A0/Y-81U7.EXE infected with Trojan.Siggen.47608
/mnt/disk/hda1/WINDOWS/system32/73A8A0/Y-81U7.EXE - deleted!
/mnt/disk/hda1/WINDOWS/system32/73A8A0/Q88C22D0.EXE infected with Trojan.Siggen1.29203
/mnt/disk/hda1/WINDOWS/system32/73A8A0/Q88C22D0.EXE - deleted!
/mnt/disk/hda1/WINDOWS/system32/73A8A0/QV82D72F.EXE infected with Trojan.Siggen1.30079
/mnt/disk/hda1/WINDOWS/system32/73A8A0/QV82D72F.EXE - deleted!
/mnt/disk/hda1/WINDOWS/system32/73A8A0/TC-8U7.EXE infected with Trojan.Siggen1.9589
/mnt/disk/hda1/WINDOWS/system32/73A8A0/TC-8U7.EXE - deleted!
/mnt/disk/hda1/WINDOWS/system32/73A8A0/TC-VN5.EXE infected with Trojan.Siggen1.29203
/mnt/disk/hda1/WINDOWS/system32/73A8A0/TC-VN5.EXE - deleted!
/mnt/disk/hda1/WINDOWS/system32/73A8A0/TC-VN7.EXE infected with Trojan.Siggen1.30079
/mnt/disk/hda1/WINDOWS/system32/73A8A0/TC-VN7.EXE - deleted!
/mnt/disk/hda1/WINDOWS/system32/73A8A0/TX8BF4D4.EXE infected with Trojan.Siggen1.9589
/mnt/disk/hda1/WINDOWS/system32/73A8A0/TX8BF4D4.EXE - deleted!
Scanned: 573/187 Cured: 17
Infected: 321/29 Deleted: 267
Modifications: 0/0 Renamed: 0
Suspicious: 1/0 Moved: 0
Adware: 70/17 Ignored: 0
Dialer: 0/0
Joke: 0/0 Scan time: 0:01:24
Riskware: 0/0 Scan speed: 1057 Kb/s
Hacktool: 2/2 Scan speed: 1057 Kb/s

I will also try and scan the D: drive later this week.
Thanks!
Epacific

#8 Budapest

Budapest

    Bleepin' Cynic


  • Moderator
  • 23,573 posts
  • OFFLINE
  •  
  • Gender:Male
  • Local time:08:08 AM

Posted 04 June 2010 - 12:16 AM

Okay, let us know how it goes and if your computer is running better.
The power of accurate observation is commonly called cynicism by those who haven't got it.

—George Bernard Shaw

#9 Epacific

Epacific
  • Topic Starter

  • Members
  • 17 posts
  • OFFLINE
  •  
  • Local time:06:08 PM

Posted 13 June 2010 - 05:38 PM

Budapest,

My computer is "slightly more fixed" meaning that it now actually allows me to access the primary account (versus restarting every time I select it). However, it still won't let me access directories on the hard drives (via Windows though I can via the DOS cmd line). Also, I still have some odd-looking programs/ads popping up on my computer (with chinese characters) so I'm not in the clear yet.

I have tried to run Dr Web Livd CD on my D: drive several times (7 times to be exact) but it freezes any time it hits an executable file (like putty.exe for example). Each time this happened, I deleted the executable in question, but on the subsequent run, the program would simply hang on the next executable it encountered.

I tried researching this and it sounds like it's a reported bug with the program but I don't see a fix for it. Do you have any ideas? Alternatively, I tried running Dr. Web directly off of the computer (versus the CD) but the virus(es) always seem to interfere, either not allowing the program to start or simply freezing it prior to completion.

Do you think I should try some additional anti-malware programs? I hear that AVG rescue disk is a pretty good one.

Thanks in advance,
Epacific

#10 Budapest

Budapest

    Bleepin' Cynic


  • Moderator
  • 23,573 posts
  • OFFLINE
  •  
  • Gender:Male
  • Local time:08:08 AM

Posted 13 June 2010 - 05:51 PM

Download rkill, save it to your desktop and then double-click the file to run it.

http://download.bleepingcomputer.com/grinler/rkill.com

Then, without rebooting, run Malwarebytes using the instructions given below:

Please download Malwarebytes Anti-Malware and save it to your desktop.Download Link 1
Download Link 2
MBAM may "make changes to your registry" as part of its disinfection routine. If using other security programs that detect registry changes (ie Spybot's Teatimer), they may interfere or alert you. Temporarily disable such programs or permit them to allow the changes.
  • Make sure you are connected to the Internet.
  • Double-click on mbam-setup.exe to install the application.
    For instructions with screenshots, please refer to the How to use Malwarebytes' Anti-Malware Guide.
  • When the installation begins, follow the prompts and do not make any changes to default settings.
  • When installation has finished, make sure you leave both of these checked:
    • Update Malwarebytes' Anti-Malware
    • Launch Malwarebytes' Anti-Malware
  • Then click Finish.
MBAM will automatically start and you will be asked to update the program before performing a scan.
  • If an update is found, the program will automatically update itself. Press the OK button to close that box and continue.
  • If you encounter any problems while downloading the definition updates, manually download them from here and just double-click on mbam-rules.exe to install.
On the Scanner tab:
  • Make sure the "Perform Quick Scan" option is selected.
  • Then click on the Scan button.
  • If asked to select the drives to scan, leave all the drives selected and click on the Start Scan button.
  • The scan will begin and "Scan in progress" will show at the top. It may take some time to complete so please be patient.
  • When the scan is finished, a message box will say "The scan completed successfully. Click 'Show Results' to display all objects found".
  • Click OK to close the message box and continue with the removal process.
Back at the main Scanner screen:
  • Click on the Show Results button to see a list of any malware that was found.
  • Make sure that everything is checked, and click Remove Selected.
  • When removal is completed, a log report will open in Notepad.
  • The log is automatically saved and can be viewed by clicking the Logs tab in MBAM.
  • Copy and paste the contents of that report in your next reply. Be sure to post the complete log to include the top portion which shows MBAM's database version and your operating system.
  • Exit MBAM when done.
Note: If MBAM encounters a file that is difficult to remove, you will be asked to reboot your computer so MBAM can proceed with the disinfection process. If asked to restart the computer, please do so immediately. Failure to reboot normally (not into safe mode) will prevent MBAM from removing all the malware.
The power of accurate observation is commonly called cynicism by those who haven't got it.

—George Bernard Shaw

#11 Epacific

Epacific
  • Topic Starter

  • Members
  • 17 posts
  • OFFLINE
  •  
  • Local time:06:08 PM

Posted 14 June 2010 - 11:15 PM

Budapest,

I tried running MBAM which I already had on my computer but ever since the infection, any time I try to run it, I get the following error message:
"An error has occurred. Please report this error code to our support team.
MBAM_ERROR_LOAD_RESOURCE (0,53)"

I thought that running the rkill first might allow it to run but it did the same thing.

So, I downloaded Malwarebytes Anti-Malware again via the link you provided and attempted to re-install it. However, during the installation process, I keep getting the following error:
"IPersistFile::Save failed; code 0x80070005.
Access is denied."

Even if I ignore the error and continue with the installation process, at the end I still get the following error that pops up again:
"An error has occurred. Please report this error code to our support team.
MBAM_ERROR_LOAD_RESOURCE (0,53)"

I got the same result regardless of whether I was running in either normal of safe mode.

Do you know what might be causing this? The "IPersist" error is intermittent but any time I try to install or run my existing MBAX excutable file, I get the "MBAM_ERROR_LOAD_RESOURCE(0,53)" error.

Thanks,
Epacific

#12 Budapest

Budapest

    Bleepin' Cynic


  • Moderator
  • 23,573 posts
  • OFFLINE
  •  
  • Gender:Male
  • Local time:08:08 AM

Posted 14 June 2010 - 11:22 PM

It might be the malware that is causing the problem:

Try downloading and using the SUPERAntiSpyware Portable Scanner.
The power of accurate observation is commonly called cynicism by those who haven't got it.

—George Bernard Shaw

#13 Epacific

Epacific
  • Topic Starter

  • Members
  • 17 posts
  • OFFLINE
  •  
  • Local time:06:08 PM

Posted 30 June 2010 - 11:47 PM

Thanks Budapest, I have done the following:

1. I ran Super Anti Spyware Portable Scanner.
2. Doing so actually allowed me to run Dr. Web on the computer itself (versus off of the live CD). The quick scan and especially the complete scan took ages. The data for the latter (.csv file) is provided below:

instsrv.exe;C:\WINDOWS\system32;Tool.SrvRunner;;
opsq.exe;C:\WINDOWS\system32;Program.ProxyOSS;;
SSLCore.dll;C:\WINDOWS\system32;Trojan.DownLoader.origin;Incurable.Moved.;
rx.dll;C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp;Trojan.PWS.Gamania.25795;Incurable.Moved.;
~grfkou.txt;C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp;Trojan.NtRootKit.2909;Deleted.;
~rxbkxr.txt;C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp;Trojan.NtRootKit.2909;Deleted.;
EasyTime.exe;C:\;Trojan.DownLoad.64067;Deleted.;
SafeDrv.exe\data001;C:\SafeDrv.exe;Trojan.NtRootKit.2909;;
SafeDrv.exe;C:\;Container contains infected objects;Moved.;
SafeDrv.exe;C:\;Trojan.MulDrop.origin;Invalid path to file ;
safedrv.exe\data001;c:\program files\common files\safedrv.exe;Trojan.NtRootKit.2909;;
safedrv.exe;c:\program files\common files;Container contains infected objects;Moved.;
safedrv.exe;c:\program files\common files;Trojan.MulDrop.origin;Invalid path to file ;
superantispyware.exe;d:\program files\superantispyware;Trojan.Starter.398;Cured.;
safedrv.exe\data001;d:\safedrv.exe;Trojan.NtRootKit.2909;;
safedrv.exe;d:\;Container contains infected objects;Moved.;
safedrv.exe;d:\;Trojan.MulDrop.origin;Invalid path to file ;
yz[1].exe\data001;C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\9980L3B0\yz[1].exe;Trojan.DownLoader.origin;;
yz[1].exe\data002;C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\9980L3B0\yz[1].exe;Trojan.DownLoader.origin;;
yz[1].exe\data003;C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\9980L3B0\yz[1].exe;Trojan.Click.origin;;
yz[1].exe;C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\9980L3B0;Container contains infected objects;Moved.;
msn[1].exe;C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\J2C4EOWZ;Trojan.MulDrop.3631;Deleted.;
fh[1].exe;C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\TRU1B18H;Adware.IEBar.52;;
EasyTime.exe;C:\Documents and Settings\Bhakta Rana\My Documents\Youdao\Dict;Trojan.DownLoad.64067;Deleted.;
80.tmp;C:\Documents and Settings\Rajeev Thapa\Local Settings\Temp;Trojan.Click.23516;Deleted.;
Rem135.exe;C:\Documents and Settings\Rajeev Thapa\Local Settings\Temp;Adware.Lop;;
msn[1].exe;C:\Documents and Settings\Rajeev Thapa\Local Settings\Temporary Internet Files\Content.IE5\JCUTHDDA;Trojan.MulDrop.3631;Deleted.;
fh[1].exe;C:\Documents and Settings\Rajeev Thapa\Local Settings\Temporary Internet Files\Content.IE5\OCWR1AEV;Adware.IEBar.52;;
yz[1].exe\data001;C:\Documents and Settings\Rajeev Thapa\Local Settings\Temporary Internet Files\Content.IE5\Q44IXXJ0\yz[1].exe;Trojan.DownLoader.origin;;
yz[1].exe\data002;C:\Documents and Settings\Rajeev Thapa\Local Settings\Temporary Internet Files\Content.IE5\Q44IXXJ0\yz[1].exe;Trojan.DownLoader.origin;;
yz[1].exe\data003;C:\Documents and Settings\Rajeev Thapa\Local Settings\Temporary Internet Files\Content.IE5\Q44IXXJ0\yz[1].exe;Trojan.Click.origin;;
yz[1].exe;C:\Documents and Settings\Rajeev Thapa\Local Settings\Temporary Internet Files\Content.IE5\Q44IXXJ0;Container contains infected objects;Moved.;
fh.exe;C:\Program Files;Adware.IEBar.52;;
msn.exe;C:\Program Files;Trojan.MulDrop.3631;Deleted.;
EasyTime.exe;C:\Program Files\Adobe\Reader 9.0\Reader;Trojan.DownLoad.64067;Deleted.;
EasyTime.exe;C:\Program Files\Common Files\Adobe\ARM\1.0;Trojan.DownLoad.64067;Deleted.;
EasyTime.exe;C:\Program Files\Common Files\logishrd\LComMgr;Trojan.DownLoad.64067;Deleted.;
EasyTime.exe;C:\Program Files\Common Files\Microsoft Shared\Works Shared;Trojan.DownLoad.64067;Deleted.;
MSVB50CHS.dll;C:\Program Files\ComPlus Applications;Trojan.Click.23516;Deleted.;
pncrt.dll;C:\Program Files\ComPlus Applications;Trojan.Click.23516;Deleted.;
EasyTime.exe;C:\Program Files\Consumer Input;Trojan.DownLoad.64067;Deleted.;
EasyTime.exe;C:\Program Files\cyberlink\PCM4Everio;Trojan.DownLoad.64067;Deleted.;
EasyTime.exe;C:\Program Files\FlashGet Network\FlashGet Mini;Trojan.DownLoad.64067;Deleted.;
EasyTime.exe;C:\Program Files\Logitech\QuickCam;Trojan.DownLoad.64067;Deleted.;
EasyTime.exe;C:\Program Files\Messenger;Trojan.DownLoad.64067;Deleted.;
EasyTime.exe;C:\Program Files\ProSiteFinder;Trojan.DownLoad.64067;Deleted.;
EasyTime.exe;C:\Program Files\Qzmlvmp;Trojan.DownLoad.64067;Deleted.;
A0142367.dll;C:\System Volume Information\_restore{39B55467-8C7E-46C6-B32A-C58455643C25}\RP1260;Trojan.DownLoader.origin;Incurable.Moved.;
A0142368.exe;C:\System Volume Information\_restore{39B55467-8C7E-46C6-B32A-C58455643C25}\RP1260;Trojan.DownLoad.64067;Deleted.;
A0142370.exe\data001;C:\System Volume Information\_restore{39B55467-8C7E-46C6-B32A-C58455643C25}\RP1260\A0142370.exe;Trojan.NtRootKit.2909;;
A0142370.exe;C:\System Volume Information\_restore{39B55467-8C7E-46C6-B32A-C58455643C25}\RP1260;Container contains infected objects;Moved.;
A0142370.exe;C:\System Volume Information\_restore{39B55467-8C7E-46C6-B32A-C58455643C25}\RP1260;Trojan.MulDrop.origin;;
A0142371.exe\data001;C:\System Volume Information\_restore{39B55467-8C7E-46C6-B32A-C58455643C25}\RP1260\A0142371.exe;Trojan.NtRootKit.2909;;
A0142371.exe;C:\System Volume Information\_restore{39B55467-8C7E-46C6-B32A-C58455643C25}\RP1260;Container contains infected objects;Moved.;
A0142371.exe;C:\System Volume Information\_restore{39B55467-8C7E-46C6-B32A-C58455643C25}\RP1260;Trojan.MulDrop.origin;;
A0142375.exe;C:\System Volume Information\_restore{39B55467-8C7E-46C6-B32A-C58455643C25}\RP1260;Trojan.MulDrop.3631;Deleted.;
A0142376.exe;C:\System Volume Information\_restore{39B55467-8C7E-46C6-B32A-C58455643C25}\RP1260;Trojan.DownLoad.64067;Deleted.;
A0142377.exe;C:\System Volume Information\_restore{39B55467-8C7E-46C6-B32A-C58455643C25}\RP1260;Trojan.DownLoad.64067;Deleted.;
A0142378.exe;C:\System Volume Information\_restore{39B55467-8C7E-46C6-B32A-C58455643C25}\RP1260;Trojan.DownLoad.64067;Deleted.;
A0142379.exe;C:\System Volume Information\_restore{39B55467-8C7E-46C6-B32A-C58455643C25}\RP1260;Trojan.DownLoad.64067;Deleted.;
A0142380.dll;C:\System Volume Information\_restore{39B55467-8C7E-46C6-B32A-C58455643C25}\RP1260;Trojan.Click.23516;Deleted.;
A0142381.dll;C:\System Volume Information\_restore{39B55467-8C7E-46C6-B32A-C58455643C25}\RP1260;Trojan.Click.23516;Deleted.;
A0142382.exe;C:\System Volume Information\_restore{39B55467-8C7E-46C6-B32A-C58455643C25}\RP1260;Trojan.DownLoad.64067;Deleted.;
A0142383.exe;C:\System Volume Information\_restore{39B55467-8C7E-46C6-B32A-C58455643C25}\RP1260;Trojan.DownLoad.64067;Deleted.;
A0142384.exe;C:\System Volume Information\_restore{39B55467-8C7E-46C6-B32A-C58455643C25}\RP1260;Trojan.DownLoad.64067;Deleted.;
A0142385.exe;C:\System Volume Information\_restore{39B55467-8C7E-46C6-B32A-C58455643C25}\RP1260;Trojan.DownLoad.64067;Deleted.;
A0142386.exe;C:\System Volume Information\_restore{39B55467-8C7E-46C6-B32A-C58455643C25}\RP1260;Trojan.DownLoad.64067;Deleted.;
A0142387.exe;C:\System Volume Information\_restore{39B55467-8C7E-46C6-B32A-C58455643C25}\RP1260;Trojan.DownLoad.64067;Deleted.;
A0142388.exe;C:\System Volume Information\_restore{39B55467-8C7E-46C6-B32A-C58455643C25}\RP1260;Trojan.DownLoad.64067;Deleted.;
instsrv.exe;C:\WINDOWS\system32;Tool.SrvRunner;;
opsq.exe;C:\WINDOWS\system32;Program.ProxyOSS;;
vnc-4.0-x86_win32_viewer.exe;D:\Documents and Settings\Rajeev Thapa\My Documents\Graduate Classes\GVSU\classes\CS 654;Program.RemoteAdmin;;
login;D:\Documents and Settings\Rajeev Thapa\My Documents\Graduate Classes\GVSU\classes\CS 654\General;Linux.Trojan.Rootkit.40;Incurable.Moved.;
vnc-4.0-x86_win32_viewer.exe;D:\Documents and Settings\Rajeev Thapa\My Documents\Graduate Classes\GVSU\classes\CS 654\General;Program.RemoteAdmin;;
Blatdocs\data027;D:\Documents and Settings\Rajeev Thapa\My Documents\Graduate Classes\GVSU\classes\EGR 680A_600\homework\scilab\scilab-4.0.exe/d;Modification of HLLP.Merlin.3693;;
{app}\bin\Blatdocs;D:\Documents and Settings\Rajeev Thapa\My Documents\Graduate Classes\GVSU\classes\EGR 680A_600\homework\scilab\scilab-4.0.exe/d;Container contains infected objects;;
data002;D:\Documents and Settings\Rajeev Thapa\My Documents\Graduate Classes\GVSU\classes\EGR 680A_600\homework\scilab;Container contains infected objects;;
scilab-4.0.exe;D:\Documents and Settings\Rajeev Thapa\My Documents\Graduate Classes\GVSU\classes\EGR 680A_600\homework\scilab;Container contains infected objects;Moved.;
Blatdocs\data027;D:\Documents and Settings\Rajeev Thapa\My Documents\Graduate Classes\GVSU\classes\EGR 680A_600\scilab\scilab-4.0.exe/data002/{a;Modification of HLLP.Merlin.3693;;
{app}\bin\Blatdocs;D:\Documents and Settings\Rajeev Thapa\My Documents\Graduate Classes\GVSU\classes\EGR 680A_600\scilab\scilab-4.0.exe/data002/{a;Container contains infected objects;;
data002;D:\Documents and Settings\Rajeev Thapa\My Documents\Graduate Classes\GVSU\classes\EGR 680A_600\scilab;Container contains infected objects;;
scilab-4.0.exe;D:\Documents and Settings\Rajeev Thapa\My Documents\Graduate Classes\GVSU\classes\EGR 680A_600\scilab;Container contains infected objects;Moved.;
vnc-4.0-x86_win32_viewer.exe;D:\Documents and Settings\Rajeev Thapa\My Documents\Graduate Classes\GVSU\classes\EGR 693\report\CS 654\General;Program.RemoteAdmin;;
618496_5c58e67a0_\_tv91D3.tmp;D:\Downloads\fullagent.exe/{tmp}\comcast\vault\sd\sdcmon.dll\618496_5c58e67a0_;Probably DLOADER.Trojan;;
{tmp}\comcast\vault\sd\sdcmon.dll\618496_5c58e67a0_;D:\Downloads\fullagent.exe/{tmp}\comcast\vault\sd\sdcmon.dll;Archive contains infected objects;;
819200_50a0c3a96_\_tv8B13.tmp;D:\Downloads\fullagent.exe/{tmp}\comcast\vault\tg\tgupdate.exe\819200_50a0c3a96_;Probably DLOADER.Trojan;;
{tmp}\comcast\vault\tg\tgupdate.exe\819200_50a0c3a96_;D:\Downloads\fullagent.exe/{tmp}\comcast\vault\tg\tgupdate.exe;Archive contains infected objects;;
fullagent.exe;D:\Downloads;Container contains infected objects;Moved.;
mce.exe\data016;D:\Downloads\mce.exe;Adware.nCase;;
mce.exe;D:\Downloads;Container contains infected objects;Moved.;
Blatdocs\data027;D:\Downloads\scilab\scilab-4.0.exe/data002/{app}\bin\Blatdocs;Modification of HLLP.Merlin.3693;;
{app}\bin\Blatdocs;D:\Downloads\scilab\scilab-4.0.exe/data002/{app}\bin;Container contains infected objects;;
data002;D:\Downloads\scilab;Container contains infected objects;;
scilab-4.0.exe;D:\Downloads\scilab;Container contains infected objects;Moved.;
vnc-4.0-x86_win32_viewer.exe;D:\Downloads\VNC;Program.RemoteAdmin;;
notify.exe;D:\Program Files\ClipGenie\notify;Dialer.Charger.25;Incurable.Moved.;
EasyTime.exe;D:\Program Files\Malwarebytes' Anti-Malware;Trojan.DownLoad.64067;Deleted.;
EasyTime.exe;D:\Program Files\SUPERAntiSpyware;Trojan.DownLoad.64067;Deleted.;
bundle_cdt1006.exe;D:\Temp;Adware.SAHAgent;;
Remover.exe;D:\Temp;Adware.Winad.153;;
kb37151.exe;D:\Winup;Trojan.PWS.Wow.1815;Deleted.;
kb37157.exe;D:\Winup;Trojan.MulDrop1.20032;Deleted.;
kb38013.exe;D:\Winup;Trojan.SpyBot.11;Deleted.;



3. Unfortunately, even after this, I was unable to run MBAM or to restore MBAM through re-installation, resulting in the same exact errors documented in my previous post. I ran rkill first.
4. I then ran McAfee Stinger on both my drives. This resulted in the following output file:



McAfee® Stinger Version 10.0.1.926 built on Jun 25 2010
Copyright © 2010 McAfee, Inc. All Rights Reserved.
Virus data file v1000 created on Jun 25 2010.
Ready to scan for 3451 viruses, trojans and variants.

Scan initiated on Mon Jun 28 23:16:51 2010
C:\Documents and Settings\Administrator\Application Data\Dns.bak
Found the Artemis!388968298CCA trojan !!!
C:\Documents and Settings\Administrator\Application Data\Dns.bak has been deleted.
C:\Documents and Settings\Administrator\Desktop\rkill.com
Found the Artemis!002021C84943 trojan !!!
C:\Documents and Settings\Administrator\Desktop\rkill.com has been deleted.
C:\Documents and Settings\Administrator\DoctorWeb\Quarantine\A0142370.exe
Found the Artemis!8F6FEC34B570 virus !!!
C:\Documents and Settings\Administrator\DoctorWeb\Quarantine\A0142370.exe has been deleted.
C:\Documents and Settings\Administrator\DoctorWeb\Quarantine\A0142371.exe
Found the Artemis!8F6FEC34B570 virus !!!
C:\Documents and Settings\Administrator\DoctorWeb\Quarantine\A0142371.exe has been deleted.
C:\Documents and Settings\Administrator\DoctorWeb\Quarantine\SafeDrv.exe
Found the Artemis!8F6FEC34B570 virus !!!
C:\Documents and Settings\Administrator\DoctorWeb\Quarantine\SafeDrv.exe has been deleted.
C:\Documents and Settings\Administrator\DoctorWeb\Quarantine\safedrv0.exe
Found the Artemis!8F6FEC34B570 virus !!!
C:\Documents and Settings\Administrator\DoctorWeb\Quarantine\safedrv0.exe has been deleted.
C:\Documents and Settings\Administrator\DoctorWeb\Quarantine\safedrv1.exe
Found the Artemis!8F6FEC34B570 virus !!!
C:\Documents and Settings\Administrator\DoctorWeb\Quarantine\safedrv1.exe has been deleted.
C:\Documents and Settings\Administrator\DoctorWeb\Quarantine\yz[1].exe
Found the Artemis!4509F091F14B trojan !!!
C:\Documents and Settings\Administrator\DoctorWeb\Quarantine\yz[1].exe has been deleted.
C:\Documents and Settings\Administrator\DoctorWeb\Quarantine\yz[1]__0.exe
Found the Artemis!4509F091F14B trojan !!!
C:\Documents and Settings\Administrator\DoctorWeb\Quarantine\yz[1]__0.exe has been deleted.
C:\Documents and Settings\Administrator\Local Settings\Temp\cb.dll
Found the Artemis!7498102EB0C8 trojan !!!
C:\Documents and Settings\Administrator\Local Settings\Temp\cb.dll has been deleted.
C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\9980L3B0\k[1].exe
Found the Artemis!C1C51A3097DC trojan !!!
C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\9980L3B0\k[1].exe has been deleted.
C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\J2C4EOWZ\k[1].exe
Found the Artemis!C1C51A3097DC trojan !!!
C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\J2C4EOWZ\k[1].exe has been deleted.
C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\TRU1B18H\A00[1].exe
Found the Artemis!388968298CCA trojan !!!
C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\TRU1B18H\A00[1].exe has been deleted.
C:\Documents and Settings\Bhakta Rana\Desktop\rkill.com
Found the Artemis!002021C84943 trojan !!!
C:\Documents and Settings\Bhakta Rana\Desktop\rkill.com has been deleted.
C:\Documents and Settings\Bhakta Rana\Local Settings\Temp\E_N4\cnvpe.fne
Found the Artemis!2286B7FBDDF5 trojan !!!
C:\Documents and Settings\Bhakta Rana\Local Settings\Temp\E_N4\cnvpe.fne has been deleted.
C:\Documents and Settings\Bhakta Rana\Local Settings\Temp\E_N4\dp1.fne
Found the Artemis!EF09232E7250 trojan !!!
C:\Documents and Settings\Bhakta Rana\Local Settings\Temp\E_N4\dp1.fne has been deleted.
C:\Documents and Settings\Bhakta Rana\Local Settings\Temp\E_N4\eAPI.fne
Found the Artemis!2A122CBFE6E4 trojan !!!
C:\Documents and Settings\Bhakta Rana\Local Settings\Temp\E_N4\eAPI.fne has been deleted.
C:\Documents and Settings\Bhakta Rana\Local Settings\Temp\E_N4\krnln.fnr
Found the Artemis!7A88CE51C7A1 trojan !!!
C:\Documents and Settings\Bhakta Rana\Local Settings\Temp\E_N4\krnln.fnr has been deleted.
C:\Documents and Settings\Bhakta Rana\Local Settings\Temp\E_N4\spec.fne
Found the Vundo.gen.cg trojan !!!
C:\Documents and Settings\Bhakta Rana\Local Settings\Temp\E_N4\spec.fne has been deleted.
C:\Documents and Settings\Bhakta Rana\Local Settings\Temp\ZcomMagSubscribe-200-2541.exe\204.nsis
Found the Artemis!D6DC7832F5DD trojan !!!
C:\Documents and Settings\Bhakta Rana\Local Settings\Temp\ZcomMagSubscribe-200-2541.exe\204.nsis has been deleted.
C:\Documents and Settings\Rajeev Thapa\Application Data\Dna.bak
Found the Artemis!C0D37A7780C3 trojan !!!
C:\Documents and Settings\Rajeev Thapa\Application Data\Dna.bak has been deleted.
C:\Documents and Settings\Rajeev Thapa\Application Data\Dns.bak
Found the Artemis!388968298CCA trojan !!!
C:\Documents and Settings\Rajeev Thapa\Application Data\Dns.bak has been deleted.
C:\Documents and Settings\Rajeev Thapa\Local Settings\Temp\cb.dll
Found the Artemis!7498102EB0C8 trojan !!!
C:\Documents and Settings\Rajeev Thapa\Local Settings\Temp\cb.dll has been deleted.
C:\Documents and Settings\Rajeev Thapa\Local Settings\Temporary Internet Files\Content.IE5\OCWR1AEV\A00[1].exe
Found the Artemis!388968298CCA trojan !!!
C:\Documents and Settings\Rajeev Thapa\Local Settings\Temporary Internet Files\Content.IE5\OCWR1AEV\A00[1].exe has been deleted.
C:\Program Files\A00.exe
Found the Artemis!388968298CCA trojan !!!
C:\Program Files\A00.exe has been deleted.
C:\WINDOWS\system32\22068.exe\204.nsis
Found the Artemis!D6DC7832F5DD trojan !!!
C:\WINDOWS\system32\22068.exe\204.nsis has been deleted.
C:\WINDOWS\system32\73A8A0\shell.fne
Found the Artemis!094DAEE505E0 trojan !!!
C:\WINDOWS\system32\73A8A0\shell.fne has been deleted.
C:\WINDOWS\system32\73A8A0\spec.fne
Found the Vundo.gen.cg trojan !!!
C:\WINDOWS\system32\73A8A0\spec.fne has been deleted.
C:\Zcom\E-Space.exe
Found the Artemis!D6DC7832F5DD trojan !!!
C:\Zcom\E-Space.exe has been deleted.
Number of clean files: 178617
Number of infected files: 5
Number of Trojans: 24
Number of files deleted: 29

McAfee® Stinger Version 10.0.1.926 built on Jun 25 2010
Copyright © 2010 McAfee, Inc. All Rights Reserved.
Virus data file v1000 created on Jun 25 2010.
Ready to scan for 3451 viruses, trojans and variants.

Scan initiated on Tue Jun 29 08:17:48 2010
Number of clean files: 1790065


5. After this, I ran rkill again and tried MBAM again which still didn't work


For what it's worth, I can now also access files via windows now. However, the fact that there is still something blocking MBAM bothers me and there are still odd Chinese "drop down menus" on my desktop so there is still some infection.

Finally, I have actually run Dr. Web several times on the computer and every time, it appears to capture viruses- it never seems to be completely clean.

Thanks for your help. Any additional guidance would be greatly appreciated.
Epacific

#14 Budapest

Budapest

    Bleepin' Cynic


  • Moderator
  • 23,573 posts
  • OFFLINE
  •  
  • Gender:Male
  • Local time:08:08 AM

Posted 30 June 2010 - 11:54 PM

Try this:

http://www.bleepingcomputer.com/virus-remo...sing-tdsskiller
The power of accurate observation is commonly called cynicism by those who haven't got it.

—George Bernard Shaw

#15 Epacific

Epacific
  • Topic Starter

  • Members
  • 17 posts
  • OFFLINE
  •  
  • Local time:06:08 PM

Posted 15 July 2010 - 08:19 PM

Budapest,

I tried it and it didn't appear to find any new viruses. Again, the good news, is that my PC is "almost good", i.e. I can now access all files on it. The only thing is that this "CH Chinese (PRC)" drop-down menu still exists on my desktop and MBAM does not work. I even tried uninstalling it and re-installing it and I still get the "MBAM_ERROR_LOAD_RESOURCE(0,53)" error message. I get that when I uninstall, install, or attempt to run it.

Also, when first starting up the computer, I get the following pop-up messages:
1. Dialog box titled, "RUNDLL32.EXE - Bad Image" states the following:
"The application or DLL C:\Windows\system\mfcB.lOG is not a valid Windows image. Please check this against your installation diskette." It has an "Okay" button and I normally just x the box out.
2. Dialog box titled, "RUNDLL32.EXE - Bad Image" states the following:
"The application or DLL C:\Windows\system\mfc3.loG is not a valid Windows image. Please check this against your installation diskette." It has an "Okay" button and I normally just x the box out.
3. Dialog box titled, "RUNDLL32.EXE - Bad Image" states the following:
"The application or DLL C:\Windows\system\mfc5.lOG is not a valid Windows image. Please check this against your installation diskette." It has an "Okay" button and I normally just x the box out.

Thanks,
Epacific

PS- Update: I have managed to get rid of the "CH Chinese (PRC)" drop down menu. It was apparently an MS Language option available under XP that one of the many intruding malwares apparently turned on. I turned it off by doing the following:
1. Going to Control Panel and selecting "Date, Time, Language, and Regional Options"
2. Choosing "Regional and Language Options"
3. Selecting "Languages" tab in resulting dialog box
4. Deselecting the "Install files for East Asian languages" option

So, now all that is left is to:
1. Get rid of the dll error messages
2. Get MBAM to work again

The fact that MBAM doesn't work is what still bothers me the most since this would indicate that there is still something luking to prevent it from running properly.

What should we try now? Thanks for the input and my apologies for the infrequent responses- have been busy and am only able to work this problem intermittently.

Thanks again,
Epacific

PPS- Update: I have found the following directory and program on my computer: Zcom
The associated date for it made me question its installation as it was the same time that I first started having malware problems. Looking into it, it sounds like this is malware and needs to be removed. Can you confirm? It's right on my C: drive:
C:\Zcom

It is not available for removal from the Add/Remove Programs on the Control Panel. Do you know how to get rid of it?
thanks! That's it for today.

Epacific

Edited by Epacific, 15 July 2010 - 09:22 PM.





0 user(s) are reading this topic

0 members, 0 guests, 0 anonymous users