Jump to content


 


Register a free account to unlock additional features at BleepingComputer.com
Welcome to BleepingComputer, a free community where people like yourself come together to discuss and learn how to use their computers. Using the site is easy and fun. As a guest, you can browse and view the various discussions in the forums, but can not create a new topic or reply to an existing one unless you are logged in. Other benefits of registering an account are subscribing to topics and forums, creating a blog, and having no ads shown anywhere on the site.


Click here to Register a free account now! or read our Welcome Guide to learn how to use this site.

Photo

Finding a bunch of "(pcname).eml" files everywhere. Programs fail to launch, etc


  • Please log in to reply
15 replies to this topic

#1 eggylisk

eggylisk

  • Members
  • 8 posts
  • OFFLINE
  •  
  • Local time:02:59 AM

Posted 24 July 2015 - 01:48 AM

Malwarebytes also found worm.runounce. Tried deleting the worm but it still keeps coming back. A good majority of my programs are also failing to launch. I either get a "0xc000007b" error, "nota valid win32 application" or nothing at all and would just not launch. Please help



BC AdBot (Login to Remove)

 


m

#2 Sintharius

Sintharius

    Bleepin' Sniper


  • Members
  • 5,639 posts
  • OFFLINE
  •  
  • Gender:Female
  • Location:The Netherlands
  • Local time:10:59 AM

Posted 24 July 2015 - 03:23 AM

Hi there,

Malwarebytes do not target worms - you will need to use an antivirus.

Try this.

Emsisoft Emergency Kit

Please download Emsisoft Emergency Kit and save it to your desktop. Double click on the EmsisoftEmergencyKit file you downloaded to extract its contents and create a shortcut on the desktop. Leave all settings as they are and click the Extract button at the bottom. A folder named EEK will be created in the root of the drive (usually c:\).
  • After extraction please double-click on the new Start Emsisoft Emergency Kit icon on your desktop.
  • The first time you launch it, Emsisoft Emergency Kit will recommend that you allow it to download updates. Please click Yes so that it downloads the latest database updates.
  • When update is complete, click Malware Scan. When asked if you want the scanner to scan for Potentially Unwanted Programs, click Yes. Emsisoft Emergency Kit will start scanning.
  • When the scan is completed click Quarantine selected objects. Note, this option is only available if malicious objects were detected during the scan.
  • When the threats have been quarantined, click the View report button in the lower-right corner, and the scan log will be opened in Notepad.
  • Please save the log in Notepad on your desktop and post the contents in your next reply.
  • When you close Emsisoft Emergency Kit, it will give you an option to sign up for a newsletter. This is optional, and is not necessary for the malware removal process.
===

Security Check by screen317
  • Download Security Check by screen317 from here or here.
  • Save it to your Desktop.
  • Double click SecurityCheck.exe and follow the onscreen instructions inside of the black box.
A Notepad document should open automatically called checkup.txt. Please copy and paste the contents of the log in your next reply.

Regards,
Alex

#3 eggylisk

eggylisk
  • Topic Starter

  • Members
  • 8 posts
  • OFFLINE
  •  
  • Local time:02:59 AM

Posted 24 July 2015 - 04:14 AM

It kept giving me an error saying I've used too many smileys. I hope this is okay in this format. Security Check is coming right up, still waiting for it to finish. Also, thanks for spending your time helping me solve this headache! 

Emsisoft Emergency Kit - Version 10.0
Last update: 7/24/2015 1:44:04 AM
User account: Kevin-PC\Kevin

Scan settings:

Scan type: Malware Scan
Objects: Rootkits, Memory, Traces, Files

Detect PUPs: On
Scan archives: Off
ADS Scan: On
File extension filter: Off
Advanced caching: On
Direct disk access: Off

Scan start:	7/24/2015 1:45:00 AM
Key: HKEY_USERS\.DEFAULT\SOFTWARE\APPDATALOW\{12DA0E6F-5543-440C-BAA2-28BF01070AFA} 	detected: Application.Bundle (A)
Key: HKEY_USERS\S-1-5-21-2594220630-3603304000-901252706-1001\SOFTWARE\APPDATALOW\{12DA0E6F-5543-440C-BAA2-28BF01070AFA} 	detected: Application.Bundle (A)
Key: HKEY_USERS\S-1-5-18\SOFTWARE\APPDATALOW\{12DA0E6F-5543-440C-BAA2-28BF01070AFA} 	detected: Application.Bundle (A)
Key: HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432NODE\{12DA0E6F-5543-440C-BAA2-28BF01070AFA} 	detected: Application.AdFix (A)
C:\$Recycle.Bin\S-1-5-21-2594220630-3603304000-901252706-1001\$RZZS1Q2.eml 	detected: Win32.Worm.Nimda.R (B)
C:\Program Files (x86)\Origin\3RDPARTYLICENSES.HTML 	detected: Win32.Worm.Nimda.O (B)
C:\Program Files (x86)\Origin\3RDPARTYLICENSES_FR.HTML 	detected: Win32.Worm.Nimda.O (B)
C:\Program Files (x86)\Origin\logreader.html 	detected: Win32.Worm.Nimda.O (B)
C:\Program Files (x86)\Origin\readme.eml 	detected: Win32.Worm.Nimda.R (B)
C:\Program Files (x86)\QPST\readme.eml 	detected: Win32.Worm.Nimda.R (B)
C:\Program Files (x86)\Steam\readme.eml 	detected: Win32.Worm.Nimda.R (B)
C:\Program Files (x86)\Steam\ThirdPartyLegalNotices.html 	detected: Win32.Worm.Nimda.O (B)
C:\Program Files\WinRAR\readme.eml 	detected: Win32.Worm.Nimda.R (B)
C:\ProgramData\Adobe\AAMUpdater\KEVIN-PC.eml 	detected: Win32.Worm.Nimda.R (B)
C:\ProgramData\Adobe\ARM\KEVIN-PC.eml 	detected: Win32.Worm.Nimda.R (B)
C:\ProgramData\Adobe\CameraRaw\KEVIN-PC.eml 	detected: Win32.Worm.Nimda.R (B)
C:\ProgramData\Adobe\Acrobat\KEVIN-PC.eml 	detected: Win32.Worm.Nimda.R (B)
C:\ProgramData\Adobe\Setup\KEVIN-PC.eml 	detected: Win32.Worm.Nimda.R (B)
C:\ProgramData\Adobe\Extension Manager CC\KEVIN-PC.eml 	detected: Win32.Worm.Nimda.R (B)
C:\ProgramData\Adobe\SLStore\KEVIN-PC.eml 	detected: Win32.Worm.Nimda.R (B)
C:\ProgramData\Adobe\Updater\KEVIN-PC.eml 	detected: Win32.Worm.Nimda.R (B)
C:\ProgramData\Aeria Games\KEVIN-PC.eml 	detected: Win32.Worm.Nimda.R (B)
C:\ProgramData\Aeria Games\Ignite\KEVIN-PC.eml 	detected: Win32.Worm.Nimda.R (B)
C:\ProgramData\Adobe\KEVIN-PC.eml 	detected: Win32.Worm.Nimda.R (B)
C:\ProgramData\Andy_44_Online\keymapper\KEVIN-PC.eml 	detected: Win32.Worm.Nimda.R (B)
C:\ProgramData\Andy_44_Online\KEVIN-PC.eml 	detected: Win32.Worm.Nimda.R (B)
C:\ProgramData\Andy\KEVIN-PC.eml 	detected: Win32.Worm.Nimda.R (B)
C:\ProgramData\Andy_44_Online\SetupFiles\KEVIN-PC.eml 	detected: Win32.Worm.Nimda.R (B)
C:\ProgramData\Apple Computer\Installer Cache\KEVIN-PC.eml 	detected: Win32.Worm.Nimda.R (B)
C:\ProgramData\Apple\KEVIN-PC.eml 	detected: Win32.Worm.Nimda.R (B)
C:\ProgramData\Apple\Installer Cache\KEVIN-PC.eml 	detected: Win32.Worm.Nimda.R (B)
C:\ProgramData\Apple Computer\KEVIN-PC.eml 	detected: Win32.Worm.Nimda.R (B)
C:\ProgramData\Apple\Apple Application Support\KEVIN-PC.eml 	detected: Win32.Worm.Nimda.R (B)
C:\ProgramData\Apple Computer\iTunes\KEVIN-PC.eml 	detected: Win32.Worm.Nimda.R (B)
C:\ProgramData\ATI\ACE\KEVIN-PC.eml 	detected: Win32.Worm.Nimda.R (B)
C:\ProgramData\ATI\KEVIN-PC.eml 	detected: Win32.Worm.Nimda.R (B)
C:\ProgramData\Battle.net\Agent\KEVIN-PC.eml 	detected: Win32.Worm.Nimda.R (B)
C:\ProgramData\Battle.net\Client\KEVIN-PC.eml 	detected: Win32.Worm.Nimda.R (B)
C:\ProgramData\Battle.net\KEVIN-PC.eml 	detected: Win32.Worm.Nimda.R (B)
C:\ProgramData\Battle.net\Setup\KEVIN-PC.eml 	detected: Win32.Worm.Nimda.R (B)
C:\ProgramData\Blizzard Entertainment\KEVIN-PC.eml 	detected: Win32.Worm.Nimda.R (B)
C:\ProgramData\Blizzard Entertainment\Battle.net\KEVIN-PC.eml 	detected: Win32.Worm.Nimda.R (B)
C:\ProgramData\Blizzard Entertainment\StarCraft II\KEVIN-PC.eml 	detected: Win32.Worm.Nimda.R (B)
C:\ProgramData\CanonBJ\IJPrinter\KEVIN-PC.eml 	detected: Win32.Worm.Nimda.R (B)
C:\ProgramData\COSMOS Applications\KEVIN-PC.eml 	detected: Win32.Worm.Nimda.R (B)
C:\ProgramData\COSMOS Applications\Flow Simulation 2015\KEVIN-PC.eml 	detected: Win32.Worm.Nimda.R (B)
C:\ProgramData\Creative\KEVIN-PC.eml 	detected: Win32.Worm.Nimda.R (B)
C:\ProgramData\Common Files\KEVIN-PC.eml 	detected: Win32.Worm.Nimda.R (B)
C:\ProgramData\CanonBJ\KEVIN-PC.eml 	detected: Win32.Worm.Nimda.R (B)
C:\ProgramData\Creative\Photo Manager\KEVIN-PC.eml 	detected: Win32.Worm.Nimda.R (B)
C:\ProgramData\DassaultSystemes\KEVIN-PC.eml 	detected: Win32.Worm.Nimda.R (B)
C:\ProgramData\DAEMON Tools Lite\KEVIN-PC.eml 	detected: Win32.Worm.Nimda.R (B)
C:\ProgramData\DassaultSystemes\Kevin\KEVIN-PC.eml 	detected: Win32.Worm.Nimda.R (B)
C:\ProgramData\Dell\KEVIN-PC.eml 	detected: Win32.Worm.Nimda.R (B)
C:\ProgramData\Dell\QuickSet\KEVIN-PC.eml 	detected: Win32.Worm.Nimda.R (B)
C:\ProgramData\E1864A66-75E3-486a-BD95-D1B7D99A84A7\KEVIN-PC.eml 	detected: Win32.Worm.Nimda.R (B)
C:\ProgramData\EA Core\cache\KEVIN-PC.eml 	detected: Win32.Worm.Nimda.R (B)
C:\ProgramData\E1864A66-75E3-486a-BD95-D1B7D99A84A7\x64\KEVIN-PC.eml 	detected: Win32.Worm.Nimda.R (B)
C:\ProgramData\EA Core\KEVIN-PC.eml 	detected: Win32.Worm.Nimda.R (B)
C:\ProgramData\Electronic Arts\EA Services\KEVIN-PC.eml 	detected: Win32.Worm.Nimda.R (B)
C:\ProgramData\FLEXnet\KEVIN-PC.eml 	detected: Win32.Worm.Nimda.R (B)
C:\ProgramData\EA Logs\KEVIN-PC.eml 	detected: Win32.Worm.Nimda.R (B)
C:\ProgramData\Electronic Arts\EA Core\KEVIN-PC.eml 	detected: Win32.Worm.Nimda.R (B)
C:\ProgramData\Installations\KEVIN-PC.eml 	detected: Win32.Worm.Nimda.R (B)
C:\ProgramData\Electronic Arts\KEVIN-PC.eml 	detected: Win32.Worm.Nimda.R (B)
C:\ProgramData\Installations\{AB6F6C80-1C35-4672-BDEF-F26FF214C409}\KEVIN-PC.eml 	detected: Win32.Worm.Nimda.R (B)
C:\ProgramData\Malwarebytes\KEVIN-PC.eml 	detected: Win32.Worm.Nimda.R (B)
C:\ProgramData\KEVIN-PC.eml 	detected: Win32.Worm.Nimda.R (B)
C:\ProgramData\Malwarebytes\Malwarebytes Anti-Malware\KEVIN-PC.eml 	detected: Win32.Worm.Nimda.R (B)
C:\ProgramData\Malwarebytes\Malwarebytes' Anti-Malware\KEVIN-PC.eml 	detected: Win32.Worm.Nimda.R (B)
C:\ProgramData\McAfee\MCLOGS\KEVIN-PC.eml 	detected: Win32.Worm.Nimda.R (B)
C:\ProgramData\McAfee\KEVIN-PC.eml 	detected: Win32.Worm.Nimda.R (B)
C:\ProgramData\Microsoft Help\KEVIN-PC.eml 	detected: Win32.Worm.Nimda.R (B)
C:\ProgramData\Microsoft\Assistance\KEVIN-PC.eml 	detected: Win32.Worm.Nimda.R (B)
C:\ProgramData\Microsoft\Crypto\KEVIN-PC.eml 	detected: Win32.Worm.Nimda.R (B)
C:\ProgramData\Microsoft\DeviceSync\KEVIN-PC.eml 	detected: Win32.Worm.Nimda.R (B)
C:\ProgramData\Microsoft\Device Stage\KEVIN-PC.eml 	detected: Win32.Worm.Nimda.R (B)
C:\ProgramData\Microsoft\Diagnosis\KEVIN-PC.eml 	detected: Win32.Worm.Nimda.R (B)
C:\ProgramData\Microsoft\Event Viewer\KEVIN-PC.eml 	detected: Win32.Worm.Nimda.R (B)
C:\ProgramData\Microsoft\eHome\KEVIN-PC.eml 	detected: Win32.Worm.Nimda.R (B)
C:\ProgramData\Microsoft\DRM\KEVIN-PC.eml 	detected: Win32.Worm.Nimda.R (B)
C:\ProgramData\Microsoft\IdentityCRL\KEVIN-PC.eml 	detected: Win32.Worm.Nimda.R (B)
C:\ProgramData\Microsoft\HTML Help\KEVIN-PC.eml 	detected: Win32.Worm.Nimda.R (B)
C:\ProgramData\Microsoft\IlsCache\KEVIN-PC.eml 	detected: Win32.Worm.Nimda.R (B)
C:\ProgramData\Microsoft\MF\KEVIN-PC.eml 	detected: Win32.Worm.Nimda.R (B)
C:\ProgramData\Microsoft\Media Player\KEVIN-PC.eml 	detected: Win32.Worm.Nimda.R (B)
C:\ProgramData\Microsoft\Network\KEVIN-PC.eml 	detected: Win32.Worm.Nimda.R (B)
C:\ProgramData\Microsoft\KEVIN-PC.eml 	detected: Win32.Worm.Nimda.R (B)
C:\ProgramData\Microsoft\NetFramework\KEVIN-PC.eml 	detected: Win32.Worm.Nimda.R (B)
C:\ProgramData\Microsoft\MSDN\KEVIN-PC.eml 	detected: Win32.Worm.Nimda.R (B)
C:\ProgramData\Microsoft\OFFICE\KEVIN-PC.eml 	detected: Win32.Worm.Nimda.R (B)
C:\ProgramData\Microsoft\OfficeSoftwareProtectionPlatform\KEVIN-PC.eml 	detected: Win32.Worm.Nimda.R (B)
C:\ProgramData\Microsoft\PlayReady\KEVIN-PC.eml 	detected: Win32.Worm.Nimda.R (B)
C:\ProgramData\Microsoft\PlayReadySilverlight\KEVIN-PC.eml 	detected: Win32.Worm.Nimda.R (B)
C:\ProgramData\Microsoft\Vault\KEVIN-PC.eml 	detected: Win32.Worm.Nimda.R (B)
C:\ProgramData\Microsoft\Search\KEVIN-PC.eml 	detected: Win32.Worm.Nimda.R (B)
C:\ProgramData\Microsoft\User Account Pictures\KEVIN-PC.eml 	detected: Win32.Worm.Nimda.R (B)
C:\ProgramData\Microsoft\WPD\KEVIN-PC.eml 	detected: Win32.Worm.Nimda.R (B)
C:\ProgramData\Microsoft\WwanSvc\KEVIN-PC.eml 	detected: Win32.Worm.Nimda.R (B)
C:\ProgramData\Microsoft\RAC\KEVIN-PC.eml 	detected: Win32.Worm.Nimda.R (B)
C:\ProgramData\Microsoft\Wlansvc\KEVIN-PC.eml 	detected: Win32.Worm.Nimda.R (B)
C:\ProgramData\Mozilla\KEVIN-PC.eml 	detected: Win32.Worm.Nimda.R (B)
C:\ProgramData\Mozilla\logs\KEVIN-PC.eml 	detected: Win32.Worm.Nimda.R (B)
C:\ProgramData\Nexon\KEVIN-PC.eml 	detected: Win32.Worm.Nimda.R (B)
C:\ProgramData\NexonUS\KEVIN-PC.eml 	detected: Win32.Worm.Nimda.R (B)
C:\ProgramData\Nexon\Common\KEVIN-PC.eml 	detected: Win32.Worm.Nimda.R (B)
C:\ProgramData\NexonUS\NGM\KEVIN-PC.eml 	detected: Win32.Worm.Nimda.R (B)
C:\ProgramData\Origin\AchievementCache\KEVIN-PC.eml 	detected: Win32.Worm.Nimda.R (B)
C:\ProgramData\Origin\CustomBoxartCache\KEVIN-PC.eml 	detected: Win32.Worm.Nimda.R (B)
C:\ProgramData\Origin\DownloadCache\KEVIN-PC.eml 	detected: Win32.Worm.Nimda.R (B)
C:\ProgramData\Origin\EntitlementCache\KEVIN-PC.eml 	detected: Win32.Worm.Nimda.R (B)
C:\ProgramData\Origin\KEVIN-PC.eml 	detected: Win32.Worm.Nimda.R (B)
C:\ProgramData\Origin\LocalContent\KEVIN-PC.eml 	detected: Win32.Worm.Nimda.R (B)
C:\ProgramData\Oracle\KEVIN-PC.eml 	detected: Win32.Worm.Nimda.R (B)
C:\ProgramData\Origin\Logs\KEVIN-PC.eml 	detected: Win32.Worm.Nimda.R (B)
C:\ProgramData\Origin\NonOriginContentCache\KEVIN-PC.eml 	detected: Win32.Worm.Nimda.R (B)
C:\ProgramData\Origin\Telemetry\KEVIN-PC.eml 	detected: Win32.Worm.Nimda.R (B)
C:\ProgramData\Package Cache\KEVIN-PC.eml 	detected: Win32.Worm.Nimda.R (B)
C:\ProgramData\Package Cache\{13A4EE12-23EA-3371-91EE-EFB36DDFFF3E}v12.0.21005\KEVIN-PC.eml 	detected: Win32.Worm.Nimda.R (B)
C:\ProgramData\Package Cache\{33d1fd90-4274-48a1-9bc1-97e33d9c2d6f}\KEVIN-PC.eml 	detected: Win32.Worm.Nimda.R (B)
C:\ProgramData\Package Cache\{7f51bdb9-ee21-49ee-94d6-90afc321780e}\KEVIN-PC.eml 	detected: Win32.Worm.Nimda.R (B)
C:\ProgramData\Package Cache\{37B8F9C7-03FB-3253-8781-2517C99D7C00}v11.0.61030\KEVIN-PC.eml 	detected: Win32.Worm.Nimda.R (B)
C:\ProgramData\Package Cache\{A749D8E6-B613-3BE3-8F5F-045C84EBA29B}v12.0.21005\KEVIN-PC.eml 	detected: Win32.Worm.Nimda.R (B)
C:\ProgramData\Package Cache\{929FBD26-9020-399B-9A7A-751D61F0B942}v12.0.21005\KEVIN-PC.eml 	detected: Win32.Worm.Nimda.R (B)
C:\ProgramData\Package Cache\{B175520C-86A2-35A7-8619-86DC379688B9}v11.0.61030\KEVIN-PC.eml 	detected: Win32.Worm.Nimda.R (B)
C:\ProgramData\Package Cache\{BD95A8CD-1D9F-35AD-981A-3E7925026EBB}v11.0.61030\KEVIN-PC.eml 	detected: Win32.Worm.Nimda.R (B)
C:\ProgramData\Ralink Driver\RT2870 Wireless LAN Card\KEVIN-PC.eml 	detected: Win32.Worm.Nimda.R (B)
C:\ProgramData\Package Cache\{ca67548a-5ebe-413a-b50c-4b9ceb6d66c6}\KEVIN-PC.eml 	detected: Win32.Worm.Nimda.R (B)
C:\ProgramData\Package Cache\{CF2BEA3C-26EA-32F8-AA9B-331F7E34BA97}v11.0.61030\KEVIN-PC.eml 	detected: Win32.Worm.Nimda.R (B)
C:\ProgramData\Package Cache\{ce085a78-074e-4823-8dc1-8a721b94b76d}\KEVIN-PC.eml 	detected: Win32.Worm.Nimda.R (B)
C:\ProgramData\Package Cache\{F8CFEB22-A2E7-3971-9EDA-4B11EDEFC185}v12.0.21005\KEVIN-PC.eml 	detected: Win32.Worm.Nimda.R (B)
C:\ProgramData\Ralink Driver\KEVIN-PC.eml 	detected: Win32.Worm.Nimda.R (B)
C:\ProgramData\regid.1986-12.com.adobe\KEVIN-PC.eml 	detected: Win32.Worm.Nimda.R (B)
C:\ProgramData\Reprise\KEVIN-PC.eml 	detected: Win32.Worm.Nimda.R (B)
C:\ProgramData\Riot Games\KEVIN-PC.eml 	detected: Win32.Worm.Nimda.R (B)
C:\ProgramData\RogueKiller\KEVIN-PC.eml 	detected: Win32.Worm.Nimda.R (B)
C:\ProgramData\RogueKiller\Debug\KEVIN-PC.eml 	detected: Win32.Worm.Nimda.R (B)
C:\ProgramData\RogueKiller\Logs\KEVIN-PC.eml 	detected: Win32.Worm.Nimda.R (B)
C:\ProgramData\RogueKiller\Quarantine\KEVIN-PC.eml 	detected: Win32.Worm.Nimda.R (B)
C:\ProgramData\Samsung\KEVIN-PC.eml 	detected: Win32.Worm.Nimda.R (B)
C:\ProgramData\Samsung\DeviceProfile\KEVIN-PC.eml 	detected: Win32.Worm.Nimda.R (B)
C:\ProgramData\Samsung\Device Error Recovery\KEVIN-PC.eml 	detected: Win32.Worm.Nimda.R (B)
C:\ProgramData\Samsung\Kies\KEVIN-PC.eml 	detected: Win32.Worm.Nimda.R (B)
C:\ProgramData\SketchUp\SketchUp 2014\KEVIN-PC.eml 	detected: Win32.Worm.Nimda.R (B)
C:\ProgramData\Simpoe\KEVIN-PC.eml 	detected: Win32.Worm.Nimda.R (B)
C:\ProgramData\SketchUp\KEVIN-PC.eml 	detected: Win32.Worm.Nimda.R (B)
C:\ProgramData\SketchUp\SketchUp 2015\KEVIN-PC.eml 	detected: Win32.Worm.Nimda.R (B)
C:\ProgramData\Skype\{24991BA0-F0EE-44AD-9CC8-5EC50AECF6B7}\KEVIN-PC.eml 	detected: Win32.Worm.Nimda.R (B)
C:\ProgramData\Skype\KEVIN-PC.eml 	detected: Win32.Worm.Nimda.R (B)
C:\ProgramData\Skype\{4E76FF7E-AEBA-4C87-B788-CD47E5425B9D}\KEVIN-PC.eml 	detected: Win32.Worm.Nimda.R (B)
C:\ProgramData\Skype\Apps\KEVIN-PC.eml 	detected: Win32.Worm.Nimda.R (B)
C:\ProgramData\Skype\{7A3C7E05-EE37-47D6-99E1-2EB05A3DA3F7}\KEVIN-PC.eml 	detected: Win32.Worm.Nimda.R (B)
C:\ProgramData\SOLIDWORKS Electrical\catalog\KEVIN-PC.eml 	detected: Win32.Worm.Nimda.R (B)
C:\ProgramData\SOLIDWORKS Electrical\MSSQL11.TEW_SQLEXPRESS\KEVIN-PC.eml 	detected: Win32.Worm.Nimda.R (B)
C:\ProgramData\SOLIDWORKS Electrical\KEVIN-PC.eml 	detected: Win32.Worm.Nimda.R (B)
C:\ProgramData\SOLIDWORKS Electrical\epdm_bom\KEVIN-PC.eml 	detected: Win32.Worm.Nimda.R (B)
C:\ProgramData\SOLIDWORKS\CircuitWorks\KEVIN-PC.eml 	detected: Win32.Worm.Nimda.R (B)
C:\ProgramData\SOLIDWORKS Flow Simulation\Flow Simulation 2014\KEVIN-PC.eml 	detected: Win32.Worm.Nimda.R (B)
C:\ProgramData\SOLIDWORKS Electrical\Update\KEVIN-PC.eml 	detected: Win32.Worm.Nimda.R (B)
C:\ProgramData\SOLIDWORKS Flow Simulation\KEVIN-PC.eml 	detected: Win32.Worm.Nimda.R (B)
C:\ProgramData\SOLIDWORKS\KEVIN-PC.eml 	detected: Win32.Worm.Nimda.R (B)
C:\ProgramData\SOLIDWORKS\SOLIDWORKS 2015\KEVIN-PC.eml 	detected: Win32.Worm.Nimda.R (B)
C:\ProgramData\SOLIDWORKS\SOLIDWORKS Inspection 2015 Addin\KEVIN-PC.eml 	detected: Win32.Worm.Nimda.R (B)
C:\Users\Default\AppData\Local\Temp\KEVIN-PC.eml 	detected: Win32.Worm.Nimda.R (B)
C:\ProgramData\Sun\KEVIN-PC.eml 	detected: Win32.Worm.Nimda.R (B)
C:\ProgramData\Sun\Java\KEVIN-PC.eml 	detected: Win32.Worm.Nimda.R (B)
C:\ProgramData\TEMP\KEVIN-PC.eml 	detected: Win32.Worm.Nimda.R (B)
C:\ProgramData\SOLIDWORKS\SOLIDWORKS Inspection 2015 Standalone\KEVIN-PC.eml 	detected: Win32.Worm.Nimda.R (B)
C:\Users\Default\Documents\KEVIN-PC.eml 	detected: Win32.Worm.Nimda.R (B)
C:\Users\Default\Desktop\KEVIN-PC.eml 	detected: Win32.Worm.Nimda.R (B)
C:\Users\Default\Favorites\KEVIN-PC.eml 	detected: Win32.Worm.Nimda.R (B)
C:\Users\Default\AppData\KEVIN-PC.eml 	detected: Win32.Worm.Nimda.R (B)
C:\Users\Default\Downloads\KEVIN-PC.eml 	detected: Win32.Worm.Nimda.R (B)
C:\Users\Default\KEVIN-PC.eml 	detected: Win32.Worm.Nimda.R (B)
C:\Users\Default\Links\KEVIN-PC.eml 	detected: Win32.Worm.Nimda.R (B)
C:\Users\Default\Music\KEVIN-PC.eml 	detected: Win32.Worm.Nimda.R (B)
C:\Users\Default\Pictures\KEVIN-PC.eml 	detected: Win32.Worm.Nimda.R (B)
C:\Users\Default\Saved Games\KEVIN-PC.eml 	detected: Win32.Worm.Nimda.R (B)
C:\Users\Default\Videos\KEVIN-PC.eml 	detected: Win32.Worm.Nimda.R (B)
C:\Users\Kevin\Andy\KEVIN-PC.eml 	detected: Win32.Worm.Nimda.R (B)
C:\Users\Kevin\AppData\Local\Aeria Games\KEVIN-PC.eml 	detected: Win32.Worm.Nimda.R (B)
C:\Users\Kevin\AppData\Local\Adobe\KEVIN-PC.eml 	detected: Win32.Worm.Nimda.R (B)
C:\Users\Kevin\AppData\KEVIN-PC.eml 	detected: Win32.Worm.Nimda.R (B)
C:\Users\Kevin\AppData\Local\Akamai\KEVIN-PC.eml 	detected: Win32.Worm.Nimda.R (B)
C:\Users\Kevin\AppData\Local\Anvisoft\KEVIN-PC.eml 	detected: Win32.Worm.Nimda.R (B)
C:\Users\Kevin\AppData\Local\AOL\KEVIN-PC.eml 	detected: Win32.Worm.Nimda.R (B)
C:\Users\Kevin\AppData\Local\Apple Computer\KEVIN-PC.eml 	detected: Win32.Worm.Nimda.R (B)
C:\Users\Kevin\AppData\Local\APManager\KEVIN-PC.eml 	detected: Win32.Worm.Nimda.R (B)
C:\Users\Kevin\AppData\Local\Apps\KEVIN-PC.eml 	detected: Win32.Worm.Nimda.R (B)
C:\Users\Kevin\AppData\Local\Apple\KEVIN-PC.eml 	detected: Win32.Worm.Nimda.R (B)
C:\Users\Kevin\AppData\Local\ATI\KEVIN-PC.eml 	detected: Win32.Worm.Nimda.R (B)
C:\Users\Kevin\AppData\Local\Battle.net\KEVIN-PC.eml 	detected: Win32.Worm.Nimda.R (B)
C:\Users\Kevin\AppData\Local\Blizzard Entertainment\KEVIN-PC.eml 	detected: Win32.Worm.Nimda.R (B)
C:\Users\Kevin\AppData\Local\CrashDumps\GoogleUpdate.exe.5796.dmp 	detected: Win32.Worm.Nimda.R (B)
C:\Users\Kevin\AppData\Local\Diagnostics\KEVIN-PC.eml 	detected: Win32.Worm.Nimda.R (B)
C:\Users\Kevin\AppData\Local\DassaultSystemes\KEVIN-PC.eml 	detected: Win32.Worm.Nimda.R (B)
C:\Users\Kevin\AppData\Local\ElevatedDiagnostics\KEVIN-PC.eml 	detected: Win32.Worm.Nimda.R (B)
C:\Users\Kevin\AppData\Local\Broadcom\KEVIN-PC.eml 	detected: Win32.Worm.Nimda.R (B)
C:\Users\Kevin\AppData\Local\Downloaded Installations\KEVIN-PC.eml 	detected: Win32.Worm.Nimda.R (B)
C:\Users\Kevin\AppData\Local\CrashDumps\KEVIN-PC.eml 	detected: Win32.Worm.Nimda.R (B)
C:\Users\Kevin\AppData\Local\Deployment\KEVIN-PC.eml 	detected: Win32.Worm.Nimda.R (B)
C:\Users\Kevin\AppData\Local\EmieSiteList\KEVIN-PC.eml 	detected: Win32.Worm.Nimda.R (B)
C:\Users\Kevin\AppData\Local\EmieBrowserModeList\KEVIN-PC.eml 	detected: Win32.Worm.Nimda.R (B)
C:\Users\Kevin\AppData\Local\EmieUserList\KEVIN-PC.eml 	detected: Win32.Worm.Nimda.R (B)
C:\Users\Kevin\AppData\Local\ESN\KEVIN-PC.eml 	detected: Win32.Worm.Nimda.R (B)
C:\Users\Kevin\AppData\Local\FluxSoftware\KEVIN-PC.eml 	detected: Win32.Worm.Nimda.R (B)
C:\Users\Kevin\AppData\Local\Facebook\KEVIN-PC.eml 	detected: Win32.Worm.Nimda.R (B)
C:\Users\Kevin\AppData\Local\Google\Chrome\User Data\Default\KEVIN-PC.eml 	detected: Win32.Worm.Nimda.R (B)
C:\Users\Kevin\AppData\Local\Google\KEVIN-PC.eml 	detected: Win32.Worm.Nimda.R (B)
C:\Users\Kevin\AppData\Local\GWX\KEVIN-PC.eml 	detected: Win32.Worm.Nimda.R (B)
C:\Users\Kevin\AppData\Local\MetaGeek,_LLC\KEVIN-PC.eml 	detected: Win32.Worm.Nimda.R (B)
C:\Users\Kevin\AppData\Local\KEVIN-PC.eml 	detected: Win32.Worm.Nimda.R (B)
C:\Users\Kevin\AppData\Local\Microsoft Help\KEVIN-PC.eml 	detected: Win32.Worm.Nimda.R (B)
C:\Users\Kevin\AppData\Local\Microsoft\KEVIN-PC.eml 	detected: Win32.Worm.Nimda.R (B)
C:\Users\Kevin\AppData\Local\Microsoft\Windows\History\KEVIN-PC.eml 	detected: Win32.Worm.Nimda.R (B)
C:\Users\Kevin\AppData\Local\Microsoft\Windows\Temporary Internet Files\KEVIN-PC.eml 	detected: Win32.Worm.Nimda.R (B)
C:\Users\Kevin\AppData\Local\Mozilla\KEVIN-PC.eml 	detected: Win32.Worm.Nimda.R (B)
C:\Users\Kevin\AppData\Local\My Games\KEVIN-PC.eml 	detected: Win32.Worm.Nimda.R (B)
C:\Users\Kevin\AppData\Local\Origin\KEVIN-PC.eml 	detected: Win32.Worm.Nimda.R (B)
C:\Users\Kevin\AppData\Local\openvr\KEVIN-PC.eml 	detected: Win32.Worm.Nimda.R (B)
C:\Users\Kevin\AppData\Local\PunkBuster\KEVIN-PC.eml 	detected: Win32.Worm.Nimda.R (B)
C:\Users\Kevin\AppData\Local\SKIDROW\KEVIN-PC.eml 	detected: Win32.Worm.Nimda.R (B)
C:\Users\Kevin\AppData\Local\ms-drivers\KEVIN-PC.eml 	detected: Win32.Worm.Nimda.R (B)
C:\Users\Kevin\AppData\Local\Programs\KEVIN-PC.eml 	detected: Win32.Worm.Nimda.R (B)
C:\Users\Kevin\AppData\Local\Skype\KEVIN-PC.eml 	detected: Win32.Worm.Nimda.R (B)
C:\Users\Kevin\AppData\Local\Samsung\KEVIN-PC.eml 	detected: Win32.Worm.Nimda.R (B)
C:\Users\Kevin\AppData\Local\SolidWorks\KEVIN-PC.eml 	detected: Win32.Worm.Nimda.R (B)
C:\Users\Kevin\AppData\Local\Steam\KEVIN-PC.eml 	detected: Win32.Worm.Nimda.R (B)
C:\Users\Kevin\AppData\Local\TeamSpeak 3 Client\createfileassoc.exe 	detected: Gen:Malware.Heur.guW@byVpohei (B)
C:\Users\Kevin\AppData\Local\TeamSpeak 3 Client\KEVIN-PC.eml 	detected: Win32.Worm.Nimda.R (B)
C:\Users\Kevin\AppData\Local\TeamSpeak 3 Client\plugin_sdk.html 	detected: Win32.Worm.Nimda.O (B)
C:\Users\Kevin\AppData\Local\TeamSpeak 3 Client\readme.eml 	detected: Win32.Worm.Nimda.R (B)
C:\Users\Kevin\AppData\Local\Temp\KEVIN-PC.eml 	detected: Win32.Worm.Nimda.R (B)
C:\Users\Kevin\AppData\Local\Temp\DirectX_Setup\KEVIN-PC.eml 	detected: Win32.Worm.Nimda.R (B)
C:\Users\Kevin\AppData\Local\Temp\scoped_dir4716_22273\Dictionaries\KEVIN-PC.eml 	detected: Win32.Worm.Nimda.R (B)
C:\Users\Kevin\AppData\Local\Temp\scoped_dir4716_22273\Local Storage\KEVIN-PC.eml 	detected: Win32.Worm.Nimda.R (B)
C:\Users\Kevin\AppData\Local\Temp\scoped_dir4716_22273\KEVIN-PC.eml 	detected: Win32.Worm.Nimda.R (B)
C:\Users\Kevin\AppData\Local\Unity\KEVIN-PC.eml 	detected: Win32.Worm.Nimda.R (B)
C:\Users\Kevin\AppData\Local\TempSWBackupDirectory\KEVIN-PC.eml 	detected: Win32.Worm.Nimda.R (B)
C:\Users\Kevin\AppData\Local\VirtualStore\KEVIN-PC.eml 	detected: Win32.Worm.Nimda.R (B)
C:\Users\Kevin\AppData\Local\ZJMedia\KEVIN-PC.eml 	detected: Win32.Worm.Nimda.R (B)
C:\Users\Kevin\AppData\Roaming\7DaysToDie\KEVIN-PC.eml 	detected: Win32.Worm.Nimda.R (B)
C:\Users\Kevin\AppData\Roaming\7DaysToDie\Saves\KEVIN-PC.eml 	detected: Win32.Worm.Nimda.R (B)
C:\Users\Kevin\AppData\Roaming\Adobe\Acrobat\KEVIN-PC.eml 	detected: Win32.Worm.Nimda.R (B)
C:\Users\Kevin\AppData\Roaming\Adobe\ACSL\KEVIN-PC.eml 	detected: Win32.Worm.Nimda.R (B)
C:\Users\Kevin\AppData\Roaming\Adobe\Adobe PDF\KEVIN-PC.eml 	detected: Win32.Worm.Nimda.R (B)
C:\Users\Kevin\AppData\Roaming\Adobe\CameraRaw\KEVIN-PC.eml 	detected: Win32.Worm.Nimda.R (B)
C:\Users\Kevin\AppData\Roaming\Adobe\Adobe Photoshop CC 2014\KEVIN-PC.eml 	detected: Win32.Worm.Nimda.R (B)
C:\Users\Kevin\AppData\Roaming\Adobe\Color\KEVIN-PC.eml 	detected: Win32.Worm.Nimda.R (B)
C:\Users\Kevin\AppData\Roaming\Adobe\CoreSync\KEVIN-PC.eml 	detected: Win32.Worm.Nimda.R (B)
C:\Users\Kevin\AppData\Roaming\Adobe\Extension Manager CC\KEVIN-PC.eml 	detected: Win32.Worm.Nimda.R (B)
C:\Users\Kevin\AppData\Roaming\Adobe\Flash Player\KEVIN-PC.eml 	detected: Win32.Worm.Nimda.R (B)
C:\Users\Kevin\AppData\Roaming\Adobe\Creative Cloud Libraries\KEVIN-PC.eml 	detected: Win32.Worm.Nimda.R (B)
C:\Users\Kevin\AppData\Roaming\Adobe\KEVIN-PC.eml 	detected: Win32.Worm.Nimda.R (B)
C:\Users\Kevin\AppData\Roaming\Adobe\Linguistics\KEVIN-PC.eml 	detected: Win32.Worm.Nimda.R (B)
C:\Users\Kevin\AppData\Roaming\Adobe\LogTransport2\KEVIN-PC.eml 	detected: Win32.Worm.Nimda.R (B)
C:\Users\Kevin\AppData\Roaming\Adobe\ImageReady\KEVIN-PC.eml 	detected: Win32.Worm.Nimda.R (B)
C:\Users\Kevin\AppData\Roaming\Adobe\Headlights\KEVIN-PC.eml 	detected: Win32.Worm.Nimda.R (B)
C:\Users\Kevin\AppData\Roaming\Adobe\LogTransport2CC\KEVIN-PC.eml 	detected: Win32.Worm.Nimda.R (B)
C:\Users\Kevin\AppData\Roaming\Adobe\Photoshop\KEVIN-PC.eml 	detected: Win32.Worm.Nimda.R (B)
C:\Users\Kevin\AppData\Roaming\Adobe\Workflow\KEVIN-PC.eml 	detected: Win32.Worm.Nimda.R (B)
C:\Users\Kevin\AppData\Roaming\Adobe\Sonar\KEVIN-PC.eml 	detected: Win32.Worm.Nimda.R (B)
C:\Users\Kevin\AppData\Roaming\Adobe\XMP\KEVIN-PC.eml 	detected: Win32.Worm.Nimda.R (B)
C:\Users\Kevin\AppData\Roaming\Andy\KEVIN-PC.eml 	detected: Win32.Worm.Nimda.R (B)
C:\Users\Kevin\AppData\Roaming\Andy\HandyAndy\KEVIN-PC.eml 	detected: Win32.Worm.Nimda.R (B)
C:\Users\Kevin\AppData\Roaming\Andy\keymapper\KEVIN-PC.eml 	detected: Win32.Worm.Nimda.R (B)
C:\Users\Kevin\AppData\Roaming\Apple Computer\iTunes\KEVIN-PC.eml 	detected: Win32.Worm.Nimda.R (B)
C:\Users\Kevin\AppData\Roaming\Andy\machines\KEVIN-PC.eml 	detected: Win32.Worm.Nimda.R (B)
C:\Users\Kevin\AppData\Roaming\Apple Computer\KEVIN-PC.eml 	detected: Win32.Worm.Nimda.R (B)
C:\Users\Kevin\AppData\Roaming\Apple Computer\Logs\KEVIN-PC.eml 	detected: Win32.Worm.Nimda.R (B)
C:\Users\Kevin\AppData\Roaming\Apple Computer\Preferences\KEVIN-PC.eml 	detected: Win32.Worm.Nimda.R (B)
C:\Users\Kevin\AppData\Roaming\Apple Computer\MobileSync\KEVIN-PC.eml 	detected: Win32.Worm.Nimda.R (B)
C:\Users\Kevin\AppData\Roaming\Apple Computer\SyncServices\KEVIN-PC.eml 	detected: Win32.Worm.Nimda.R (B)
C:\Users\Kevin\AppData\Roaming\ATI\ACE\KEVIN-PC.eml 	detected: Win32.Worm.Nimda.R (B)
C:\Users\Kevin\AppData\Roaming\ATI\KEVIN-PC.eml 	detected: Win32.Worm.Nimda.R (B)
C:\Users\Kevin\AppData\Roaming\Bitdreamers\TimeComX Basic\KEVIN-PC.eml 	detected: Win32.Worm.Nimda.R (B)
C:\Users\Kevin\AppData\Roaming\Battle.net\KEVIN-PC.eml 	detected: Win32.Worm.Nimda.R (B)
C:\Users\Kevin\AppData\Roaming\Bitdreamers\KEVIN-PC.eml 	detected: Win32.Worm.Nimda.R (B)
C:\Users\Kevin\AppData\Roaming\Creative\Dell WebCam Central\KEVIN-PC.eml 	detected: Win32.Worm.Nimda.R (B)
C:\Users\Kevin\AppData\Roaming\Creative\KEVIN-PC.eml 	detected: Win32.Worm.Nimda.R (B)
C:\Users\Kevin\AppData\Roaming\Curse Client\Bin\KEVIN-PC.eml 	detected: Win32.Worm.Nimda.R (B)
C:\Users\Kevin\AppData\Roaming\Curse Client\KEVIN-PC.eml 	detected: Win32.Worm.Nimda.R (B)
C:\Users\Kevin\AppData\Roaming\Curse Client\Cache\KEVIN-PC.eml 	detected: Win32.Worm.Nimda.R (B)
C:\Users\Kevin\AppData\Roaming\Curse Client\Logs\KEVIN-PC.eml 	detected: Win32.Worm.Nimda.R (B)
C:\Users\Kevin\AppData\Roaming\Curse Client\Plugins\KEVIN-PC.eml 	detected: Win32.Worm.Nimda.R (B)
C:\Users\Kevin\AppData\Roaming\Curse Client\Overlay\KEVIN-PC.eml 	detected: Win32.Worm.Nimda.R (B)
C:\Users\Kevin\AppData\Roaming\Curse Client\Profiles\KEVIN-PC.eml 	detected: Win32.Worm.Nimda.R (B)
C:\Users\Kevin\AppData\Roaming\Curse\KEVIN-PC.eml 	detected: Win32.Worm.Nimda.R (B)
C:\Users\Kevin\AppData\Roaming\Curse\Curse 6.0.0.0\KEVIN-PC.eml 	detected: Win32.Worm.Nimda.R (B)
C:\Users\Kevin\AppData\Roaming\DAEMON Tools Lite\IconsCache\KEVIN-PC.eml 	detected: Win32.Worm.Nimda.R (B)
C:\Users\Kevin\AppData\Roaming\EDrawings\KEVIN-PC.eml 	detected: Win32.Worm.Nimda.R (B)
C:\Users\Kevin\AppData\Roaming\FreeCAD\KEVIN-PC.eml 	detected: Win32.Worm.Nimda.R (B)
C:\Users\Kevin\AppData\Roaming\DAEMON Tools Lite\KEVIN-PC.eml 	detected: Win32.Worm.Nimda.R (B)
C:\Users\Kevin\AppData\Roaming\Identities\{B3098830-65E0-47C4-8E28-768DD8A23149}\KEVIN-PC.eml 	detected: Win32.Worm.Nimda.R (B)
C:\Users\Kevin\AppData\Roaming\Identities\KEVIN-PC.eml 	detected: Win32.Worm.Nimda.R (B)
C:\Users\Kevin\AppData\Roaming\InstallShield\KEVIN-PC.eml 	detected: Win32.Worm.Nimda.R (B)
C:\Users\Kevin\AppData\Roaming\DassaultSystemes\KEVIN-PC.eml 	detected: Win32.Worm.Nimda.R (B)
C:\Users\Kevin\AppData\Roaming\help_images_otherUI\KEVIN-PC.eml 	detected: Win32.Worm.Nimda.R (B)
C:\Users\Kevin\AppData\Roaming\help_images_otherUI\help_images_otherUI\KEVIN-PC.eml 	detected: Win32.Worm.Nimda.R (B)
C:\Users\Kevin\AppData\Roaming\Kits\KEVIN-PC.eml 	detected: Win32.Worm.Nimda.R (B)
C:\Users\Kevin\AppData\Roaming\InstallShield\ISEngine12.0\KEVIN-PC.eml 	detected: Win32.Worm.Nimda.R (B)
C:\Users\Kevin\AppData\Roaming\KEVIN-PC.eml 	detected: Win32.Worm.Nimda.R (B)
C:\Users\Kevin\AppData\Roaming\LolClient\KEVIN-PC.eml 	detected: Win32.Worm.Nimda.R (B)
C:\Users\Kevin\AppData\Roaming\LolClient\Local Store\KEVIN-PC.eml 	detected: Win32.Worm.Nimda.R (B)
C:\Users\Kevin\AppData\Roaming\Luxology\KEVIN-PC.eml 	detected: Win32.Worm.Nimda.R (B)
C:\Users\Kevin\AppData\Roaming\Luxology\Configs\KEVIN-PC.eml 	detected: Win32.Worm.Nimda.R (B)
C:\Users\Kevin\AppData\Roaming\Luxology\Presets\KEVIN-PC.eml 	detected: Win32.Worm.Nimda.R (B)
C:\Users\Kevin\AppData\Roaming\Luxology\Scripts\KEVIN-PC.eml 	detected: Win32.Worm.Nimda.R (B)
C:\Users\Kevin\AppData\Roaming\Macromedia\KEVIN-PC.eml 	detected: Win32.Worm.Nimda.R (B)
C:\Users\Kevin\AppData\Roaming\Macromedia\Flash Player\KEVIN-PC.eml 	detected: Win32.Worm.Nimda.R (B)
C:\Users\Kevin\AppData\Roaming\Malwarebytes\KEVIN-PC.eml 	detected: Win32.Worm.Nimda.R (B)
C:\Users\Kevin\AppData\Roaming\Media Center Programs\KEVIN-PC.eml 	detected: Win32.Worm.Nimda.R (B)
C:\Users\Kevin\AppData\Roaming\Microsoft\AddIns\KEVIN-PC.eml 	detected: Win32.Worm.Nimda.R (B)
C:\Users\Kevin\AppData\Roaming\Microsoft\CLR Security Config\KEVIN-PC.eml 	detected: Win32.Worm.Nimda.R (B)
C:\Users\Kevin\AppData\Roaming\Microsoft\Credentials\KEVIN-PC.eml 	detected: Win32.Worm.Nimda.R (B)
C:\Users\Kevin\AppData\Roaming\Microsoft\Crypto\KEVIN-PC.eml 	detected: Win32.Worm.Nimda.R (B)
C:\Users\Kevin\AppData\Roaming\Microsoft\Document Building Blocks\KEVIN-PC.eml 	detected: Win32.Worm.Nimda.R (B)
C:\Users\Kevin\AppData\Roaming\Microsoft\CLView\KEVIN-PC.eml 	detected: Win32.Worm.Nimda.R (B)
C:\Users\Kevin\AppData\Roaming\Microsoft\Excel\KEVIN-PC.eml 	detected: Win32.Worm.Nimda.R (B)
C:\Users\Kevin\AppData\Roaming\Microsoft\HTML Help\KEVIN-PC.eml 	detected: Win32.Worm.Nimda.R (B)
C:\Users\Kevin\AppData\Roaming\Microsoft\Installer\KEVIN-PC.eml 	detected: Win32.Worm.Nimda.R (B)
C:\Users\Kevin\AppData\Roaming\Microsoft\Internet Explorer\KEVIN-PC.eml 	detected: Win32.Worm.Nimda.R (B)
C:\Users\Kevin\AppData\Roaming\Microsoft\KEVIN-PC.eml 	detected: Win32.Worm.Nimda.R (B)
C:\Users\Kevin\AppData\Roaming\Microsoft\Network\KEVIN-PC.eml 	detected: Win32.Worm.Nimda.R (B)
C:\Users\Kevin\AppData\Roaming\Microsoft\MSDN\KEVIN-PC.eml 	detected: Win32.Worm.Nimda.R (B)
C:\Users\Kevin\AppData\Roaming\Microsoft\MMC\KEVIN-PC.eml 	detected: Win32.Worm.Nimda.R (B)
C:\Users\Kevin\AppData\Roaming\Microsoft\Office\KEVIN-PC.eml 	detected: Win32.Worm.Nimda.R (B)
C:\Users\Kevin\AppData\Roaming\Microsoft\Outlook\KEVIN-PC.eml 	detected: Win32.Worm.Nimda.R (B)
C:\Users\Kevin\AppData\Roaming\Microsoft\Paint\KEVIN-PC.eml 	detected: Win32.Worm.Nimda.R (B)
C:\Users\Kevin\AppData\Roaming\Microsoft\Protect\KEVIN-PC.eml 	detected: Win32.Worm.Nimda.R (B)
C:\Users\Kevin\AppData\Roaming\Microsoft\Proof\KEVIN-PC.eml 	detected: Win32.Worm.Nimda.R (B)
C:\Users\Kevin\AppData\Roaming\Microsoft\Speech\KEVIN-PC.eml 	detected: Win32.Worm.Nimda.R (B)
C:\Users\Kevin\AppData\Roaming\Microsoft\Spelling\KEVIN-PC.eml 	detected: Win32.Worm.Nimda.R (B)
C:\Users\Kevin\AppData\Roaming\Microsoft\SystemCertificates\KEVIN-PC.eml 	detected: Win32.Worm.Nimda.R (B)
C:\Users\Kevin\AppData\Roaming\Microsoft\Templates\KEVIN-PC.eml 	detected: Win32.Worm.Nimda.R (B)
C:\Users\Kevin\AppData\Roaming\Microsoft\VSTAHost\KEVIN-PC.eml 	detected: Win32.Worm.Nimda.R (B)
C:\Users\Kevin\AppData\Roaming\Microsoft\UProof\KEVIN-PC.eml 	detected: Win32.Worm.Nimda.R (B)
C:\Users\Kevin\AppData\Roaming\Microsoft\Word\KEVIN-PC.eml 	detected: Win32.Worm.Nimda.R (B)
C:\Users\Kevin\AppData\Roaming\Mozilla\Firefox\Profiles\9wljsqgl.default\crashes\events\KEVIN-PC.eml 	detected: Win32.Worm.Nimda.R (B)
C:\Users\Kevin\AppData\Roaming\Mozilla\Firefox\Profiles\9wljsqgl.default\bookmarkbackups\KEVIN-PC.eml 	detected: Win32.Worm.Nimda.R (B)
C:\Users\Kevin\AppData\Roaming\Mozilla\Extensions\KEVIN-PC.eml 	detected: Win32.Worm.Nimda.R (B)
C:\Users\Kevin\AppData\Roaming\Mozilla\Firefox\Profiles\9wljsqgl.default\crashes\KEVIN-PC.eml 	detected: Win32.Worm.Nimda.R (B)
C:\Users\Kevin\AppData\Roaming\Mozilla\Firefox\KEVIN-PC.eml 	detected: Win32.Worm.Nimda.R (B)
C:\Users\Kevin\AppData\Roaming\Mozilla\Firefox\Profiles\9wljsqgl.default\datareporting\KEVIN-PC.eml 	detected: Win32.Worm.Nimda.R (B)
C:\Users\Kevin\AppData\Roaming\Mozilla\Firefox\Profiles\9wljsqgl.default\extensions\KEVIN-PC.eml 	detected: Win32.Worm.Nimda.R (B)
C:\Users\Kevin\AppData\Roaming\Mozilla\Firefox\Profiles\9wljsqgl.default\gmp-eme-adobe\KEVIN-PC.eml 	detected: Win32.Worm.Nimda.R (B)
C:\Users\Kevin\AppData\Roaming\Mozilla\Firefox\Profiles\9wljsqgl.default\gmp-eme-adobe\10\KEVIN-PC.eml 	detected: Win32.Worm.Nimda.R (B)
C:\Users\Kevin\AppData\Roaming\Mozilla\Firefox\Profiles\9wljsqgl.default\gmp-gmpopenh264\KEVIN-PC.eml 	detected: Win32.Worm.Nimda.R (B)
C:\Users\Kevin\AppData\Roaming\Mozilla\Firefox\Profiles\9wljsqgl.default\gmp-gmpopenh264\1.4\KEVIN-PC.eml 	detected: Win32.Worm.Nimda.R (B)
C:\Users\Kevin\AppData\Roaming\Mozilla\Firefox\Profiles\9wljsqgl.default\gmp\KEVIN-PC.eml 	detected: Win32.Worm.Nimda.R (B)
C:\Users\Kevin\AppData\Roaming\Mozilla\Firefox\Profiles\9wljsqgl.default\healthreport\KEVIN-PC.eml 	detected: Win32.Worm.Nimda.R (B)
C:\Users\Kevin\AppData\Roaming\Mozilla\Firefox\Profiles\9wljsqgl.default\KEVIN-PC.eml 	detected: Win32.Worm.Nimda.R (B)
C:\Users\Kevin\AppData\Roaming\Mozilla\Firefox\Profiles\9wljsqgl.default\minidumps\KEVIN-PC.eml 	detected: Win32.Worm.Nimda.R (B)
C:\Users\Kevin\AppData\Roaming\Mozilla\Firefox\Profiles\9wljsqgl.default\webapps\KEVIN-PC.eml 	detected: Win32.Worm.Nimda.R (B)
C:\Users\Kevin\AppData\Roaming\Mozilla\Firefox\Profiles\9wljsqgl.default\storage\permanent\KEVIN-PC.eml 	detected: Win32.Worm.Nimda.R (B)
C:\Users\Kevin\AppData\Roaming\Mozilla\Firefox\Profiles\9wljsqgl.default\sessionstore-backups\KEVIN-PC.eml 	detected: Win32.Worm.Nimda.R (B)
C:\Users\Kevin\AppData\Roaming\Mozilla\Firefox\Profiles\9wljsqgl.default\storage\KEVIN-PC.eml 	detected: Win32.Worm.Nimda.R (B)
C:\Users\Kevin\AppData\Roaming\Oracle\Java\KEVIN-PC.eml 	detected: Win32.Worm.Nimda.R (B)
C:\Users\Kevin\AppData\Roaming\Mozilla\KEVIN-PC.eml 	detected: Win32.Worm.Nimda.R (B)
C:\Users\Kevin\AppData\Roaming\Oracle\KEVIN-PC.eml 	detected: Win32.Worm.Nimda.R (B)
C:\Users\Kevin\AppData\Roaming\Origin\KEVIN-PC.eml 	detected: Win32.Worm.Nimda.R (B)
C:\Users\Kevin\AppData\Roaming\Mozilla\plugins\KEVIN-PC.eml 	detected: Win32.Worm.Nimda.R (B)
C:\Users\Kevin\AppData\Roaming\Origin\Cloud Saves\KEVIN-PC.eml 	detected: Win32.Worm.Nimda.R (B)
C:\Users\Kevin\AppData\Roaming\Origin\CommonTitles\KEVIN-PC.eml 	detected: Win32.Worm.Nimda.R (B)
C:\Users\Kevin\AppData\Roaming\Origin\Widget Updates\KEVIN-PC.eml 	detected: Win32.Worm.Nimda.R (B)
C:\Users\Kevin\AppData\Roaming\Origin\Web Storage\KEVIN-PC.eml 	detected: Win32.Worm.Nimda.R (B)
C:\Users\Kevin\AppData\Roaming\puush\KEVIN-PC.eml 	detected: Win32.Worm.Nimda.R (B)
C:\Users\Kevin\AppData\Roaming\Red Alert 3 Uprising\KEVIN-PC.eml 	detected: Win32.Worm.Nimda.R (B)
C:\Users\Kevin\AppData\Roaming\PDAppFlex\Local Store\KEVIN-PC.eml 	detected: Win32.Worm.Nimda.R (B)
C:\Users\Kevin\AppData\Roaming\Riot Games\KEVIN-PC.eml 	detected: Win32.Worm.Nimda.R (B)
C:\Users\Kevin\AppData\Roaming\PDAppFlex\KEVIN-PC.eml 	detected: Win32.Worm.Nimda.R (B)
C:\Users\Kevin\AppData\Roaming\Red Alert 3 Uprising\Profiles\KEVIN-PC.eml 	detected: Win32.Worm.Nimda.R (B)
C:\Users\Kevin\AppData\Roaming\Riot Games\League of Legends 3.0.1\KEVIN-PC.eml 	detected: Win32.Worm.Nimda.R (B)
C:\Users\Kevin\AppData\Roaming\Red Alert 3 Uprising\Maps\KEVIN-PC.eml 	detected: Win32.Worm.Nimda.R (B)
C:\Users\Kevin\AppData\Roaming\Riot Games\League of Legends\KEVIN-PC.eml 	detected: Win32.Worm.Nimda.R (B)
C:\Users\Kevin\AppData\Roaming\Riot Games\League of Legends 3.0.0\KEVIN-PC.eml 	detected: Win32.Worm.Nimda.R (B)
C:\Users\Kevin\AppData\Roaming\Samsung\KEVIN-PC.eml 	detected: Win32.Worm.Nimda.R (B)
C:\Users\Kevin\AppData\Roaming\Samsung\Kies3.0\KEVIN-PC.eml 	detected: Win32.Worm.Nimda.R (B)
C:\Users\Kevin\AppData\Roaming\Samsung\Kies\KEVIN-PC.eml 	detected: Win32.Worm.Nimda.R (B)
C:\Users\Kevin\AppData\Roaming\Samsung\New PC Studio\KEVIN-PC.eml 	detected: Win32.Worm.Nimda.R (B)
C:\Users\Kevin\AppData\Roaming\SecuROM\KEVIN-PC.eml 	detected: Win32.Worm.Nimda.R (B)
C:\Users\Kevin\AppData\Roaming\SketchUp\SketchUp 2014\KEVIN-PC.eml 	detected: Win32.Worm.Nimda.R (B)
C:\Users\Kevin\AppData\Roaming\SecuROM\UserData\KEVIN-PC.eml 	detected: Win32.Worm.Nimda.R (B)
C:\Users\Kevin\AppData\Roaming\Skype\ayyerochelle\KEVIN-PC.eml 	detected: Win32.Worm.Nimda.R (B)
C:\Users\Kevin\AppData\Roaming\SketchUp\SketchUp 2015\KEVIN-PC.eml 	detected: Win32.Worm.Nimda.R (B)
C:\Users\Kevin\AppData\Roaming\SketchUp\KEVIN-PC.eml 	detected: Win32.Worm.Nimda.R (B)
C:\Users\Kevin\AppData\Roaming\Skype\Content\KEVIN-PC.eml 	detected: Win32.Worm.Nimda.R (B)
C:\Users\Kevin\AppData\Roaming\Skype\daisy.mayo14\KEVIN-PC.eml 	detected: Win32.Worm.Nimda.R (B)
C:\Users\Kevin\AppData\Roaming\Skype\DataRv\KEVIN-PC.eml 	detected: Win32.Worm.Nimda.R (B)
C:\Users\Kevin\AppData\Roaming\Skype\itschelleanne\KEVIN-PC.eml 	detected: Win32.Worm.Nimda.R (B)
C:\Users\Kevin\AppData\Roaming\Skype\j4nem1r4\KEVIN-PC.eml 	detected: Win32.Worm.Nimda.R (B)
C:\Users\Kevin\AppData\Roaming\Skype\KEVIN-PC.eml 	detected: Win32.Worm.Nimda.R (B)
C:\Users\Kevin\AppData\Roaming\Skype\kruzekontrol976\KEVIN-PC.eml 	detected: Win32.Worm.Nimda.R (B)
C:\Users\Kevin\AppData\Roaming\Skype\kirias117\KEVIN-PC.eml 	detected: Win32.Worm.Nimda.R (B)
C:\Users\Kevin\AppData\Roaming\Skype\My Skype Received Files\KEVIN-PC.eml 	detected: Win32.Worm.Nimda.R (B)
C:\Users\Kevin\AppData\Roaming\Skype\shared_dynco\KEVIN-PC.eml 	detected: Win32.Worm.Nimda.R (B)
C:\Users\Kevin\AppData\Roaming\Skype\Pictures\KEVIN-PC.eml 	detected: Win32.Worm.Nimda.R (B)
C:\Users\Kevin\AppData\Roaming\Skype\shared_httpfe\KEVIN-PC.eml 	detected: Win32.Worm.Nimda.R (B)
C:\Users\Kevin\AppData\Roaming\SOLIDWORKS\Installation Manager Data\KEVIN-PC.eml 	detected: Win32.Worm.Nimda.R (B)
C:\Users\Kevin\AppData\Roaming\SOLIDWORKS\KEVIN-PC.eml 	detected: Win32.Worm.Nimda.R (B)
C:\Users\Kevin\AppData\Roaming\SOLIDWORKS\Installation Logs\KEVIN-PC.eml 	detected: Win32.Worm.Nimda.R (B)
C:\Users\Kevin\AppData\Roaming\SOLIDWORKS\SOLIDWORKS 2015\KEVIN-PC.eml 	detected: Win32.Worm.Nimda.R (B)
C:\Users\Kevin\AppData\Roaming\SOLIDWORKS\SolidWorks Inspection 2015 Addin\KEVIN-PC.eml 	detected: Win32.Worm.Nimda.R (B)
C:\Users\Kevin\AppData\Roaming\TS3Client\cache\KEVIN-PC.eml 	detected: Win32.Worm.Nimda.R (B)
C:\Users\Kevin\AppData\Roaming\TS3Client\chats\KEVIN-PC.eml 	detected: Win32.Worm.Nimda.R (B)
C:\Users\Kevin\AppData\Roaming\TS3Client\KEVIN-PC.eml 	detected: Win32.Worm.Nimda.R (B)
C:\Users\Kevin\AppData\Roaming\TS3Client\logs\KEVIN-PC.eml 	detected: Win32.Worm.Nimda.R (B)
C:\Users\Kevin\AppData\Roaming\Unity\WebPlayerPrefs\KEVIN-PC.eml 	detected: Win32.Worm.Nimda.R (B)
C:\Users\Kevin\AppData\Roaming\Unity\KEVIN-PC.eml 	detected: Win32.Worm.Nimda.R (B)
C:\Users\Kevin\AppData\Roaming\uTorrent\apps\KEVIN-PC.eml 	detected: Win32.Worm.Nimda.R (B)
C:\Users\Kevin\AppData\Roaming\uTorrent\dlimagecache\KEVIN-PC.eml 	detected: Win32.Worm.Nimda.R (B)
C:\Users\Kevin\AppData\Roaming\uTorrent\ie\KEVIN-PC.eml 	detected: Win32.Worm.Nimda.R (B)
C:\Users\Kevin\AppData\Roaming\uTorrent\KEVIN-PC.eml 	detected: Win32.Worm.Nimda.R (B)
C:\Users\Kevin\AppData\Roaming\uTorrent\share\KEVIN-PC.eml 	detected: Win32.Worm.Nimda.R (B)
C:\Users\Kevin\AppData\Roaming\uTorrent\trusted\KEVIN-PC.eml 	detected: Win32.Worm.Nimda.R (B)
C:\Users\Kevin\AppData\Roaming\uTorrent\updates\KEVIN-PC.eml 	detected: Win32.Worm.Nimda.R (B)
C:\Users\Kevin\AppData\Roaming\Ventrilo\chatlogs\KEVIN-PC.eml 	detected: Win32.Worm.Nimda.R (B)
C:\Users\Kevin\AppData\Roaming\vlc\KEVIN-PC.eml 	detected: Win32.Worm.Nimda.R (B)
C:\Users\Kevin\AppData\Roaming\Ventrilo\KEVIN-PC.eml 	detected: Win32.Worm.Nimda.R (B)
C:\Users\Kevin\AppData\Roaming\WinRAR\KEVIN-PC.eml 	detected: Win32.Worm.Nimda.R (B)
C:\Users\Kevin\AppData\Roaming\ZJMedia\KEVIN-PC.eml 	detected: Win32.Worm.Nimda.R (B)
C:\Users\Kevin\Contacts\KEVIN-PC.eml 	detected: Win32.Worm.Nimda.R (B)
C:\Users\Kevin\Creative Cloud Files\KEVIN-PC.eml 	detected: Win32.Worm.Nimda.R (B)
C:\Users\Kevin\Desktop\Ervin\DnD\KEVIN-PC.eml 	detected: Win32.Worm.Nimda.R (B)
C:\Users\Kevin\Desktop\Ervin\KEVIN-PC.eml 	detected: Win32.Worm.Nimda.R (B)
C:\Users\Kevin\Desktop\Ervin\New folder (2)\KEVIN-PC.eml 	detected: Win32.Worm.Nimda.R (B)
C:\Users\Kevin\Desktop\Ervin\New folder\KEVIN-PC.eml 	detected: Win32.Worm.Nimda.R (B)
C:\Users\Kevin\Desktop\Ervin\OCS SMASH\KEVIN-PC.eml 	detected: Win32.Worm.Nimda.R (B)
C:\Users\Kevin\Desktop\Ervin\New folder\ \KEVIN-PC.eml 	detected: Win32.Worm.Nimda.R (B)
C:\Users\Kevin\Desktop\Ervin\Region\KEVIN-PC.eml 	detected: Win32.Worm.Nimda.R (B)
C:\Users\Kevin\Desktop\KEVIN-PC.eml 	detected: Win32.Worm.Nimda.R (B)
C:\Users\Kevin\Desktop\Midwest Modified FR-S   Flickr - Photo Sharing!.html 	detected: Win32.Worm.Nimda.O (B)
C:\Users\Kevin\Desktop\Midwest Modified FR-S   Flickr - Photo Sharing!_files\KEVIN-PC.eml 	detected: Win32.Worm.Nimda.R (B)
C:\Users\Kevin\Desktop\N\KEVIN-PC.eml 	detected: Win32.Worm.Nimda.R (B)
C:\Users\Kevin\Desktop\New folder (2)\KEVIN-PC.eml 	detected: Win32.Worm.Nimda.R (B)
C:\Users\Kevin\Desktop\New folder (4)\KEVIN-PC.eml 	detected: Win32.Worm.Nimda.R (B)
C:\Users\Kevin\Desktop\New folder (5)\KEVIN-PC.eml 	detected: Win32.Worm.Nimda.R (B)
C:\Users\Kevin\Desktop\New folder (3)\KEVIN-PC.eml 	detected: Win32.Worm.Nimda.R (B)
C:\Users\Kevin\Desktop\New folder\KEVIN-PC.eml 	detected: Win32.Worm.Nimda.R (B)
C:\Users\Kevin\Desktop\readme.eml 	detected: Win32.Worm.Nimda.R (B)
C:\Users\Kevin\Desktop\rkill\KEVIN-PC.eml 	detected: Win32.Worm.Nimda.R (B)
C:\Users\Kevin\Desktop\S4 unlock\KEVIN-PC.eml 	detected: Win32.Worm.Nimda.R (B)
C:\Users\Kevin\Desktop\S4 unlock\motochopper\KEVIN-PC.eml 	detected: Win32.Worm.Nimda.R (B)
C:\Users\Kevin\Desktop\shafter2\com\KEVIN-PC.eml 	detected: Win32.Worm.Nimda.R (B)
C:\Users\Kevin\Desktop\shafter2\KEVIN-PC.eml 	detected: Win32.Worm.Nimda.R (B)
C:\Users\Kevin\Desktop\shafter2\META-INF\KEVIN-PC.eml 	detected: Win32.Worm.Nimda.R (B)
C:\Users\Kevin\Desktop\shafter2\com\google\KEVIN-PC.eml 	detected: Win32.Worm.Nimda.R (B)
C:\Users\Kevin\Desktop\shafter2\mineshafter\KEVIN-PC.eml 	detected: Win32.Worm.Nimda.R (B)
C:\Users\Kevin\Desktop\shafter2\mineshafter\proxy\KEVIN-PC.eml 	detected: Win32.Worm.Nimda.R (B)
C:\Users\Kevin\Desktop\shafter2\mineshafter\util\KEVIN-PC.eml 	detected: Win32.Worm.Nimda.R (B)
C:\Users\Kevin\Desktop\shafter2\resources\KEVIN-PC.eml 	detected: Win32.Worm.Nimda.R (B)
C:\Users\Kevin\Desktop\shafter2\SevenZip\Compression\KEVIN-PC.eml 	detected: Win32.Worm.Nimda.R (B)
C:\Users\Kevin\Desktop\shafter2\SevenZip\KEVIN-PC.eml 	detected: Win32.Worm.Nimda.R (B)
C:\Users\Kevin\Desktop\shafter\com\google\KEVIN-PC.eml 	detected: Win32.Worm.Nimda.R (B)
C:\Users\Kevin\Desktop\shafter\com\KEVIN-PC.eml 	detected: Win32.Worm.Nimda.R (B)
C:\Users\Kevin\Desktop\shafter\KEVIN-PC.eml 	detected: Win32.Worm.Nimda.R (B)
C:\Users\Kevin\Desktop\shafter\META-INF\KEVIN-PC.eml 	detected: Win32.Worm.Nimda.R (B)
C:\Users\Kevin\Desktop\shafter\mineshafter\KEVIN-PC.eml 	detected: Win32.Worm.Nimda.R (B)
C:\Users\Kevin\Desktop\shafter\mineshafter\proxy\KEVIN-PC.eml 	detected: Win32.Worm.Nimda.R (B)
C:\Users\Kevin\Desktop\shafter\mineshafter\util\KEVIN-PC.eml 	detected: Win32.Worm.Nimda.R (B)
C:\Users\Kevin\Desktop\shafter\resources\KEVIN-PC.eml 	detected: Win32.Worm.Nimda.R (B)
C:\Users\Kevin\Desktop\shafter\SevenZip\Compression\KEVIN-PC.eml 	detected: Win32.Worm.Nimda.R (B)
C:\Users\Kevin\Desktop\shafter\SevenZip\KEVIN-PC.eml 	detected: Win32.Worm.Nimda.R (B)
C:\Users\Kevin\Desktop\TRIBUTES\KEVIN-PC.eml 	detected: Win32.Worm.Nimda.R (B)
C:\Users\Kevin\Downloads\Bloodsports.TV [SteamRip]\KEVIN-PC.eml 	detected: Win32.Worm.Nimda.R (B)
C:\Users\Kevin\Downloads\Game of Thrones - The Complete Season 3 [HDTV]\KEVIN-PC.eml 	detected: Win32.Worm.Nimda.R (B)
C:\Users\Kevin\Downloads\Game Of Thrones Season 1 - Complete\KEVIN-PC.eml 	detected: Win32.Worm.Nimda.R (B)
C:\Users\Kevin\Downloads\Game.of.Thrones.S02\KEVIN-PC.eml 	detected: Win32.Worm.Nimda.R (B)
C:\Users\Kevin\Downloads\Jimmy Eat World - Discography (1994-2013) [FLAC]\Jimmy Eat World - 1994 - Jimmy Eat World [FLAC]\KEVIN-PC.eml 	detected: Win32.Worm.Nimda.R (B)
C:\Users\Kevin\Downloads\Jimmy Eat World - Discography (1994-2013) [FLAC]\Jimmy Eat World - 1996 - Static Prevails (Reissue) (FLAC)\KEVIN-PC.eml 	detected: Win32.Worm.Nimda.R (B)
C:\Users\Kevin\Downloads\Jimmy Eat World - Discography (1994-2013) [FLAC]\Jimmy Eat World - 1998 - Jimmy Eat World (EP) [FLAC]\KEVIN-PC.eml 	detected: Win32.Worm.Nimda.R (B)
C:\Users\Kevin\Downloads\Jimmy Eat World - Discography (1994-2013) [FLAC]\Jimmy Eat World - 1999 - Clarity [Japan TOCP-65240] [FLAC]\KEVIN-PC.eml 	detected: Win32.Worm.Nimda.R (B)
C:\Users\Kevin\Downloads\Jimmy Eat World - Discography (1994-2013) [FLAC]\Jimmy Eat World - 2000 - Singles [Japan TFCK-87212] [FLAC]\KEVIN-PC.eml 	detected: Win32.Worm.Nimda.R (B)
C:\Users\Kevin\Downloads\Jimmy Eat World - Discography (1994-2013) [FLAC]\Jimmy Eat World - 2001 - Bleed American [FLAC]\KEVIN-PC.eml 	detected: Win32.Worm.Nimda.R (B)
C:\Users\Kevin\Downloads\Jimmy Eat World - Discography (1994-2013) [FLAC]\Jimmy Eat World - 2002 - Good To Go EP [Japan UICW-1021] [FLAC]\KEVIN-PC.eml 	detected: Win32.Worm.Nimda.R (B)
C:\Users\Kevin\Downloads\Jimmy Eat World - Discography (1994-2013) [FLAC]\Jimmy Eat World - 2004 - Futures (Japanese 2 CD) [FLAC]\CD1\KEVIN-PC.eml 	detected: Win32.Worm.Nimda.R (B)
C:\Users\Kevin\Downloads\Jimmy Eat World - Discography (1994-2013) [FLAC]\Jimmy Eat World - 2003 - The Middle ~ A Praise Chorus Tour EP [Australia Release] [FLAC]\KEVIN-PC.eml 	detected: Win32.Worm.Nimda.R (B)
C:\Users\Kevin\Downloads\Jimmy Eat World - Discography (1994-2013) [FLAC]\Jimmy Eat World - 2004 - Futures (Japanese 2 CD) [FLAC]\KEVIN-PC.eml 	detected: Win32.Worm.Nimda.R (B)
C:\Users\Kevin\Downloads\Jimmy Eat World - Discography (1994-2013) [FLAC]\Jimmy Eat World - 2004 - Futures (Japanese 2 CD) [FLAC]\CD2\KEVIN-PC.eml 	detected: Win32.Worm.Nimda.R (B)
C:\Users\Kevin\Downloads\Jimmy Eat World - Discography (1994-2013) [FLAC]\Jimmy Eat World - 2005 - Stay On My Side Tonight [EP] [FLAC]\KEVIN-PC.eml 	detected: Win32.Worm.Nimda.R (B)
C:\Users\Kevin\Downloads\Jimmy Eat World - Discography (1994-2013) [FLAC]\Jimmy Eat World - 2007 - Chase This Light (Japanese Tour Edition UICS-9088.9) [FLAC]\KEVIN-PC.eml 	detected: Win32.Worm.Nimda.R (B)
C:\Users\Kevin\Downloads\Jimmy Eat World - Discography (1994-2013) [FLAC]\Jimmy Eat World - 2007 - Chase This Light (Japanese Tour Edition UICS-9088.9) [FLAC]\CD2\KEVIN-PC.eml 	detected: Win32.Worm.Nimda.R (B)
C:\Users\Kevin\Downloads\Jimmy Eat World - Discography (1994-2013) [FLAC]\Jimmy Eat World - 2007 - Chase This Light (Japanese Tour Edition UICS-9088.9) [FLAC]\CD1\KEVIN-PC.eml 	detected: Win32.Worm.Nimda.R (B)
C:\Users\Kevin\Downloads\Jimmy Eat World - Discography (1994-2013) [FLAC]\Jimmy Eat World - 2010 - Invented (Deluxe Edition) [FLAC]\KEVIN-PC.eml 	detected: Win32.Worm.Nimda.R (B)
C:\Users\Kevin\Downloads\Jimmy Eat World - Discography (1994-2013) [FLAC]\Jimmy Eat World - 2013 - Damage [FLAC]\KEVIN-PC.eml 	detected: Win32.Worm.Nimda.R (B)
C:\Users\Kevin\Downloads\Jimmy Eat World - Discography (1994-2013) [FLAC]\KEVIN-PC.eml 	detected: Win32.Worm.Nimda.R (B)
C:\Users\Kevin\Downloads\John.Wick.2014.1080p.BluRay.AC3.x264-tomcat12[ETRG]\KEVIN-PC.eml 	detected: Win32.Worm.Nimda.R (B)
C:\Users\Kevin\Downloads\KEVIN-PC.eml 	detected: Win32.Worm.Nimda.R (B)
C:\Users\Kevin\Downloads\readme (1).eml 	detected: Win32.Worm.Nimda.R (B)
C:\Users\Kevin\Downloads\readme.eml 	detected: Win32.Worm.Nimda.R (B)
C:\Users\Kevin\Downloads\PAssist_Std.exe 	detected: Gen:Variant.Symmi.49209 (B)
C:\Users\Kevin\Downloads\Solidworks 2015 SP2.0 x64\KEVIN-PC.eml 	detected: Win32.Worm.Nimda.R (B)
C:\Users\Kevin\Favorites\KEVIN-PC.eml 	detected: Win32.Worm.Nimda.R (B)
C:\Users\Kevin\Google Drive\KEVIN-PC.eml 	detected: Win32.Worm.Nimda.R (B)
C:\Users\Kevin\KEVIN-PC.eml 	detected: Win32.Worm.Nimda.R (B)
C:\Users\Kevin\jagexcache\KEVIN-PC.eml 	detected: Win32.Worm.Nimda.R (B)
C:\Users\Kevin\Links\KEVIN-PC.eml 	detected: Win32.Worm.Nimda.R (B)
C:\Users\Kevin\Music\KEVIN-PC.eml 	detected: Win32.Worm.Nimda.R (B)
C:\Users\Kevin\New folder\KEVIN-PC.eml 	detected: Win32.Worm.Nimda.R (B)
C:\Users\Kevin\Pictures\KEVIN-PC.eml 	detected: Win32.Worm.Nimda.R (B)
C:\Users\Kevin\Saved Games\KEVIN-PC.eml 	detected: Win32.Worm.Nimda.R (B)
C:\Users\Kevin\Searches\KEVIN-PC.eml 	detected: Win32.Worm.Nimda.R (B)
C:\Users\Kevin\Tracing\KEVIN-PC.eml 	detected: Win32.Worm.Nimda.R (B)
C:\Users\Kevin\Videos\KEVIN-PC.eml 	detected: Win32.Worm.Nimda.R (B)
C:\Users\Public\Desktop\KEVIN-PC.eml 	detected: Win32.Worm.Nimda.R (B)
C:\Users\Public\Downloads\KEVIN-PC.eml 	detected: Win32.Worm.Nimda.R (B)

Scanned	80930
Found	506

Scan end:	7/24/2015 1:59:27 AM
Scan time:	0:14:27

C:\Users\Public\Downloads\KEVIN-PC.eml	Quarantined Win32.Worm.Nimda.R (B)
C:\Users\Public\Desktop\KEVIN-PC.eml	Quarantined Win32.Worm.Nimda.R (B)
C:\Users\Kevin\Videos\KEVIN-PC.eml	Quarantined Win32.Worm.Nimda.R (B)
C:\Users\Kevin\Tracing\KEVIN-PC.eml	Quarantined Win32.Worm.Nimda.R (B)
C:\Users\Kevin\Searches\KEVIN-PC.eml	Quarantined Win32.Worm.Nimda.R (B)
C:\Users\Kevin\Saved Games\KEVIN-PC.eml	Quarantined Win32.Worm.Nimda.R (B)
C:\Users\Kevin\Pictures\KEVIN-PC.eml	Quarantined Win32.Worm.Nimda.R (B)
C:\Users\Kevin\New folder\KEVIN-PC.eml	Quarantined Win32.Worm.Nimda.R (B)
C:\Users\Kevin\Music\KEVIN-PC.eml	Quarantined Win32.Worm.Nimda.R (B)
C:\Users\Kevin\Links\KEVIN-PC.eml	Quarantined Win32.Worm.Nimda.R (B)
C:\Users\Kevin\jagexcache\KEVIN-PC.eml	Quarantined Win32.Worm.Nimda.R (B)
C:\Users\Kevin\KEVIN-PC.eml	Quarantined Win32.Worm.Nimda.R (B)
C:\Users\Kevin\Google Drive\KEVIN-PC.eml	Quarantined Win32.Worm.Nimda.R (B)
C:\Users\Kevin\Favorites\KEVIN-PC.eml	Quarantined Win32.Worm.Nimda.R (B)
C:\Users\Kevin\Downloads\Solidworks 2015 SP2.0 x64\KEVIN-PC.eml	Quarantined Win32.Worm.Nimda.R (B)
C:\Users\Kevin\Downloads\PAssist_Std.exe	Quarantined Gen:Variant.Symmi.49209 (B)
C:\Users\Kevin\Downloads\readme.eml	Quarantined Win32.Worm.Nimda.R (B)
C:\Users\Kevin\Downloads\readme (1).eml	Quarantined Win32.Worm.Nimda.R (B)
C:\Users\Kevin\Downloads\KEVIN-PC.eml	Quarantined Win32.Worm.Nimda.R (B)
C:\Users\Kevin\Downloads\John.Wick.2014.1080p.BluRay.AC3.x264-tomcat12[ETRG]\KEVIN-PC.eml	Quarantined Win32.Worm.Nimda.R (B)
C:\Users\Kevin\Downloads\Jimmy Eat World - Discography (1994-2013) [FLAC]\KEVIN-PC.eml	Quarantined Win32.Worm.Nimda.R (B)
C:\Users\Kevin\Downloads\Jimmy Eat World - Discography (1994-2013) [FLAC]\Jimmy Eat World - 2013 - Damage [FLAC]\KEVIN-PC.eml	Quarantined Win32.Worm.Nimda.R (B)
C:\Users\Kevin\Downloads\Jimmy Eat World - Discography (1994-2013) [FLAC]\Jimmy Eat World - 2010 - Invented (Deluxe Edition) [FLAC]\KEVIN-PC.eml	Quarantined Win32.Worm.Nimda.R (B)
C:\Users\Kevin\Downloads\Jimmy Eat World - Discography (1994-2013) [FLAC]\Jimmy Eat World - 2007 - Chase This Light (Japanese Tour Edition UICS-9088.9) [FLAC]\CD1\KEVIN-PC.eml	Quarantined Win32.Worm.Nimda.R (B)
C:\Users\Kevin\Downloads\Jimmy Eat World - Discography (1994-2013) [FLAC]\Jimmy Eat World - 2007 - Chase This Light (Japanese Tour Edition UICS-9088.9) [FLAC]\CD2\KEVIN-PC.eml	Quarantined Win32.Worm.Nimda.R (B)
C:\Users\Kevin\Downloads\Jimmy Eat World - Discography (1994-2013) [FLAC]\Jimmy Eat World - 2007 - Chase This Light (Japanese Tour Edition UICS-9088.9) [FLAC]\KEVIN-PC.eml	Quarantined Win32.Worm.Nimda.R (B)
C:\Users\Kevin\Downloads\Jimmy Eat World - Discography (1994-2013) [FLAC]\Jimmy Eat World - 2005 - Stay On My Side Tonight [EP] [FLAC]\KEVIN-PC.eml	Quarantined Win32.Worm.Nimda.R (B)
C:\Users\Kevin\Downloads\Jimmy Eat World - Discography (1994-2013) [FLAC]\Jimmy Eat World - 2004 - Futures (Japanese 2 CD) [FLAC]\CD2\KEVIN-PC.eml	Quarantined Win32.Worm.Nimda.R (B)
C:\Users\Kevin\Downloads\Jimmy Eat World - Discography (1994-2013) [FLAC]\Jimmy Eat World - 2004 - Futures (Japanese 2 CD) [FLAC]\KEVIN-PC.eml	Quarantined Win32.Worm.Nimda.R (B)
C:\Users\Kevin\Downloads\Jimmy Eat World - Discography (1994-2013) [FLAC]\Jimmy Eat World - 2003 - The Middle ~ A Praise Chorus Tour EP [Australia Release] [FLAC]\KEVIN-PC.eml	Quarantined Win32.Worm.Nimda.R (B)
C:\Users\Kevin\Downloads\Jimmy Eat World - Discography (1994-2013) [FLAC]\Jimmy Eat World - 2004 - Futures (Japanese 2 CD) [FLAC]\CD1\KEVIN-PC.eml	Quarantined Win32.Worm.Nimda.R (B)
C:\Users\Kevin\Downloads\Jimmy Eat World - Discography (1994-2013) [FLAC]\Jimmy Eat World - 2002 - Good To Go EP [Japan UICW-1021] [FLAC]\KEVIN-PC.eml	Quarantined Win32.Worm.Nimda.R (B)
C:\Users\Kevin\Downloads\Jimmy Eat World - Discography (1994-2013) [FLAC]\Jimmy Eat World - 2001 - Bleed American [FLAC]\KEVIN-PC.eml	Quarantined Win32.Worm.Nimda.R (B)
C:\Users\Kevin\Downloads\Jimmy Eat World - Discography (1994-2013) [FLAC]\Jimmy Eat World - 2000 - Singles [Japan TFCK-87212] [FLAC]\KEVIN-PC.eml	Quarantined Win32.Worm.Nimda.R (B)
C:\Users\Kevin\Downloads\Jimmy Eat World - Discography (1994-2013) [FLAC]\Jimmy Eat World - 1999 - Clarity [Japan TOCP-65240] [FLAC]\KEVIN-PC.eml	Quarantined Win32.Worm.Nimda.R (B)
C:\Users\Kevin\Downloads\Jimmy Eat World - Discography (1994-2013) [FLAC]\Jimmy Eat World - 1998 - Jimmy Eat World (EP) [FLAC]\KEVIN-PC.eml	Quarantined Win32.Worm.Nimda.R (B)
C:\Users\Kevin\Downloads\Jimmy Eat World - Discography (1994-2013) [FLAC]\Jimmy Eat World - 1996 - Static Prevails (Reissue) (FLAC)\KEVIN-PC.eml	Quarantined Win32.Worm.Nimda.R (B)
C:\Users\Kevin\Downloads\Jimmy Eat World - Discography (1994-2013) [FLAC]\Jimmy Eat World - 1994 - Jimmy Eat World [FLAC]\KEVIN-PC.eml	Quarantined Win32.Worm.Nimda.R (B)
C:\Users\Kevin\Downloads\Game.of.Thrones.S02\KEVIN-PC.eml	Quarantined Win32.Worm.Nimda.R (B)
C:\Users\Kevin\Downloads\Game Of Thrones Season 1 - Complete\KEVIN-PC.eml	Quarantined Win32.Worm.Nimda.R (B)
C:\Users\Kevin\Downloads\Game of Thrones - The Complete Season 3 [HDTV]\KEVIN-PC.eml	Quarantined Win32.Worm.Nimda.R (B)
C:\Users\Kevin\Downloads\Bloodsports.TV [SteamRip]\KEVIN-PC.eml	Quarantined Win32.Worm.Nimda.R (B)
C:\Users\Kevin\Desktop\TRIBUTES\KEVIN-PC.eml	Quarantined Win32.Worm.Nimda.R (B)
C:\Users\Kevin\Desktop\shafter\SevenZip\KEVIN-PC.eml	Quarantined Win32.Worm.Nimda.R (B)
C:\Users\Kevin\Desktop\shafter\SevenZip\Compression\KEVIN-PC.eml	Quarantined Win32.Worm.Nimda.R (B)
C:\Users\Kevin\Desktop\shafter\resources\KEVIN-PC.eml	Quarantined Win32.Worm.Nimda.R (B)
C:\Users\Kevin\Desktop\shafter\mineshafter\util\KEVIN-PC.eml	Quarantined Win32.Worm.Nimda.R (B)
C:\Users\Kevin\Desktop\shafter\mineshafter\proxy\KEVIN-PC.eml	Quarantined Win32.Worm.Nimda.R (B)
C:\Users\Kevin\Desktop\shafter\mineshafter\KEVIN-PC.eml	Quarantined Win32.Worm.Nimda.R (B)
C:\Users\Kevin\Desktop\shafter\META-INF\KEVIN-PC.eml	Quarantined Win32.Worm.Nimda.R (B)
C:\Users\Kevin\Desktop\shafter\KEVIN-PC.eml	Quarantined Win32.Worm.Nimda.R (B)
C:\Users\Kevin\Desktop\shafter\com\KEVIN-PC.eml	Quarantined Win32.Worm.Nimda.R (B)
C:\Users\Kevin\Desktop\shafter\com\google\KEVIN-PC.eml	Quarantined Win32.Worm.Nimda.R (B)
C:\Users\Kevin\Desktop\shafter2\SevenZip\KEVIN-PC.eml	Quarantined Win32.Worm.Nimda.R (B)
C:\Users\Kevin\Desktop\shafter2\SevenZip\Compression\KEVIN-PC.eml	Quarantined Win32.Worm.Nimda.R (B)
C:\Users\Kevin\Desktop\shafter2\resources\KEVIN-PC.eml	Quarantined Win32.Worm.Nimda.R (B)
C:\Users\Kevin\Desktop\shafter2\mineshafter\util\KEVIN-PC.eml	Quarantined Win32.Worm.Nimda.R (B)
C:\Users\Kevin\Desktop\shafter2\mineshafter\proxy\KEVIN-PC.eml	Quarantined Win32.Worm.Nimda.R (B)
C:\Users\Kevin\Desktop\shafter2\mineshafter\KEVIN-PC.eml	Quarantined Win32.Worm.Nimda.R (B)
C:\Users\Kevin\Desktop\shafter2\com\google\KEVIN-PC.eml	Quarantined Win32.Worm.Nimda.R (B)
C:\Users\Kevin\Desktop\shafter2\META-INF\KEVIN-PC.eml	Quarantined Win32.Worm.Nimda.R (B)
C:\Users\Kevin\Desktop\shafter2\KEVIN-PC.eml	Quarantined Win32.Worm.Nimda.R (B)
C:\Users\Kevin\Desktop\shafter2\com\KEVIN-PC.eml	Quarantined Win32.Worm.Nimda.R (B)
C:\Users\Kevin\Desktop\S4 unlock\motochopper\KEVIN-PC.eml	Quarantined Win32.Worm.Nimda.R (B)
C:\Users\Kevin\Desktop\S4 unlock\KEVIN-PC.eml	Quarantined Win32.Worm.Nimda.R (B)
C:\Users\Kevin\Desktop\rkill\KEVIN-PC.eml	Quarantined Win32.Worm.Nimda.R (B)
C:\Users\Kevin\Desktop\readme.eml	Quarantined Win32.Worm.Nimda.R (B)
C:\Users\Kevin\Desktop\New folder\KEVIN-PC.eml	Quarantined Win32.Worm.Nimda.R (B)
C:\Users\Kevin\Desktop\New folder (3)\KEVIN-PC.eml	Quarantined Win32.Worm.Nimda.R (B)
C:\Users\Kevin\Desktop\New folder (5)\KEVIN-PC.eml	Quarantined Win32.Worm.Nimda.R (B)
C:\Users\Kevin\Desktop\New folder (4)\KEVIN-PC.eml	Quarantined Win32.Worm.Nimda.R (B)
C:\Users\Kevin\Desktop\New folder (2)\KEVIN-PC.eml	Quarantined Win32.Worm.Nimda.R (B)
C:\Users\Kevin\Desktop\N\KEVIN-PC.eml	Quarantined Win32.Worm.Nimda.R (B)
C:\Users\Kevin\Desktop\Midwest Modified FR-S   Flickr - Photo Sharing!_files\KEVIN-PC.eml	Quarantined Win32.Worm.Nimda.R (B)
C:\Users\Kevin\Desktop\Midwest Modified FR-S   Flickr - Photo Sharing!.html	Quarantined Win32.Worm.Nimda.O (B)
C:\Users\Kevin\Desktop\KEVIN-PC.eml	Quarantined Win32.Worm.Nimda.R (B)
C:\Users\Kevin\Desktop\Ervin\Region\KEVIN-PC.eml	Quarantined Win32.Worm.Nimda.R (B)
C:\Users\Kevin\Desktop\Ervin\New folder\ \KEVIN-PC.eml	Quarantined Win32.Worm.Nimda.R (B)
C:\Users\Kevin\Desktop\Ervin\OCS SMASH\KEVIN-PC.eml	Quarantined Win32.Worm.Nimda.R (B)
C:\Users\Kevin\Desktop\Ervin\New folder\KEVIN-PC.eml	Quarantined Win32.Worm.Nimda.R (B)
C:\Users\Kevin\Desktop\Ervin\New folder (2)\KEVIN-PC.eml	Quarantined Win32.Worm.Nimda.R (B)
C:\Users\Kevin\Desktop\Ervin\KEVIN-PC.eml	Quarantined Win32.Worm.Nimda.R (B)
C:\Users\Kevin\Desktop\Ervin\DnD\KEVIN-PC.eml	Quarantined Win32.Worm.Nimda.R (B)
C:\Users\Kevin\Creative Cloud Files\KEVIN-PC.eml	Quarantined Win32.Worm.Nimda.R (B)
C:\Users\Kevin\Contacts\KEVIN-PC.eml	Quarantined Win32.Worm.Nimda.R (B)
C:\Users\Kevin\AppData\Roaming\ZJMedia\KEVIN-PC.eml	Quarantined Win32.Worm.Nimda.R (B)
C:\Users\Kevin\AppData\Roaming\WinRAR\KEVIN-PC.eml	Quarantined Win32.Worm.Nimda.R (B)
C:\Users\Kevin\AppData\Roaming\Ventrilo\KEVIN-PC.eml	Quarantined Win32.Worm.Nimda.R (B)
C:\Users\Kevin\AppData\Roaming\vlc\KEVIN-PC.eml	Quarantined Win32.Worm.Nimda.R (B)
C:\Users\Kevin\AppData\Roaming\Ventrilo\chatlogs\KEVIN-PC.eml	Quarantined Win32.Worm.Nimda.R (B)
C:\Users\Kevin\AppData\Roaming\uTorrent\updates\KEVIN-PC.eml	Quarantined Win32.Worm.Nimda.R (B)
C:\Users\Kevin\AppData\Roaming\uTorrent\trusted\KEVIN-PC.eml	Quarantined Win32.Worm.Nimda.R (B)
C:\Users\Kevin\AppData\Roaming\uTorrent\share\KEVIN-PC.eml	Quarantined Win32.Worm.Nimda.R (B)
C:\Users\Kevin\AppData\Roaming\uTorrent\KEVIN-PC.eml	Quarantined Win32.Worm.Nimda.R (B)
C:\Users\Kevin\AppData\Roaming\uTorrent\ie\KEVIN-PC.eml	Quarantined Win32.Worm.Nimda.R (B)
C:\Users\Kevin\AppData\Roaming\uTorrent\dlimagecache\KEVIN-PC.eml	Quarantined Win32.Worm.Nimda.R (B)
C:\Users\Kevin\AppData\Roaming\uTorrent\apps\KEVIN-PC.eml	Quarantined Win32.Worm.Nimda.R (B)
C:\Users\Kevin\AppData\Roaming\Unity\KEVIN-PC.eml	Quarantined Win32.Worm.Nimda.R (B)
C:\Users\Kevin\AppData\Roaming\Unity\WebPlayerPrefs\KEVIN-PC.eml	Quarantined Win32.Worm.Nimda.R (B)
C:\Users\Kevin\AppData\Roaming\TS3Client\logs\KEVIN-PC.eml	Quarantined Win32.Worm.Nimda.R (B)
C:\Users\Kevin\AppData\Roaming\TS3Client\KEVIN-PC.eml	Quarantined Win32.Worm.Nimda.R (B)
C:\Users\Kevin\AppData\Roaming\TS3Client\chats\KEVIN-PC.eml	Quarantined Win32.Worm.Nimda.R (B)
C:\Users\Kevin\AppData\Roaming\TS3Client\cache\KEVIN-PC.eml	Quarantined Win32.Worm.Nimda.R (B)
C:\Users\Kevin\AppData\Roaming\SOLIDWORKS\SolidWorks Inspection 2015 Addin\KEVIN-PC.eml	Quarantined Win32.Worm.Nimda.R (B)
C:\Users\Kevin\AppData\Roaming\SOLIDWORKS\SOLIDWORKS 2015\KEVIN-PC.eml	Quarantined Win32.Worm.Nimda.R (B)
C:\Users\Kevin\AppData\Roaming\SOLIDWORKS\Installation Logs\KEVIN-PC.eml	Quarantined Win32.Worm.Nimda.R (B)
C:\Users\Kevin\AppData\Roaming\SOLIDWORKS\KEVIN-PC.eml	Quarantined Win32.Worm.Nimda.R (B)
C:\Users\Kevin\AppData\Roaming\SOLIDWORKS\Installation Manager Data\KEVIN-PC.eml	Quarantined Win32.Worm.Nimda.R (B)
C:\Users\Kevin\AppData\Roaming\Skype\shared_httpfe\KEVIN-PC.eml	Quarantined Win32.Worm.Nimda.R (B)
C:\Users\Kevin\AppData\Roaming\Skype\Pictures\KEVIN-PC.eml	Quarantined Win32.Worm.Nimda.R (B)
C:\Users\Kevin\AppData\Roaming\Skype\shared_dynco\KEVIN-PC.eml	Quarantined Win32.Worm.Nimda.R (B)
C:\Users\Kevin\AppData\Roaming\Skype\My Skype Received Files\KEVIN-PC.eml	Quarantined Win32.Worm.Nimda.R (B)
C:\Users\Kevin\AppData\Roaming\Skype\kirias117\KEVIN-PC.eml	Quarantined Win32.Worm.Nimda.R (B)
C:\Users\Kevin\AppData\Roaming\Skype\kruzekontrol976\KEVIN-PC.eml	Quarantined Win32.Worm.Nimda.R (B)
C:\Users\Kevin\AppData\Roaming\Skype\KEVIN-PC.eml	Quarantined Win32.Worm.Nimda.R (B)
C:\Users\Kevin\AppData\Roaming\Skype\j4nem1r4\KEVIN-PC.eml	Quarantined Win32.Worm.Nimda.R (B)
C:\Users\Kevin\AppData\Roaming\Skype\itschelleanne\KEVIN-PC.eml	Quarantined Win32.Worm.Nimda.R (B)
C:\Users\Kevin\AppData\Roaming\Skype\DataRv\KEVIN-PC.eml	Quarantined Win32.Worm.Nimda.R (B)
C:\Users\Kevin\AppData\Roaming\Skype\daisy.mayo14\KEVIN-PC.eml	Quarantined Win32.Worm.Nimda.R (B)
C:\Users\Kevin\AppData\Roaming\Skype\Content\KEVIN-PC.eml	Quarantined Win32.Worm.Nimda.R (B)
C:\Users\Kevin\AppData\Roaming\SketchUp\KEVIN-PC.eml	Quarantined Win32.Worm.Nimda.R (B)
C:\Users\Kevin\AppData\Roaming\SketchUp\SketchUp 2015\KEVIN-PC.eml	Quarantined Win32.Worm.Nimda.R (B)
C:\Users\Kevin\AppData\Roaming\Skype\ayyerochelle\KEVIN-PC.eml	Quarantined Win32.Worm.Nimda.R (B)
C:\Users\Kevin\AppData\Roaming\SecuROM\UserData\KEVIN-PC.eml	Quarantined Win32.Worm.Nimda.R (B)
C:\Users\Kevin\AppData\Roaming\SketchUp\SketchUp 2014\KEVIN-PC.eml	Quarantined Win32.Worm.Nimda.R (B)
C:\Users\Kevin\AppData\Roaming\SecuROM\KEVIN-PC.eml	Quarantined Win32.Worm.Nimda.R (B)
C:\Users\Kevin\AppData\Roaming\Samsung\New PC Studio\KEVIN-PC.eml	Quarantined Win32.Worm.Nimda.R (B)
C:\Users\Kevin\AppData\Roaming\Samsung\Kies\KEVIN-PC.eml	Quarantined Win32.Worm.Nimda.R (B)
C:\Users\Kevin\AppData\Roaming\Samsung\Kies3.0\KEVIN-PC.eml	Quarantined Win32.Worm.Nimda.R (B)
C:\Users\Kevin\AppData\Roaming\Samsung\KEVIN-PC.eml	Quarantined Win32.Worm.Nimda.R (B)
C:\Users\Kevin\AppData\Roaming\Riot Games\League of Legends 3.0.0\KEVIN-PC.eml	Quarantined Win32.Worm.Nimda.R (B)
C:\Users\Kevin\AppData\Roaming\Riot Games\League of Legends\KEVIN-PC.eml	Quarantined Win32.Worm.Nimda.R (B)
C:\Users\Kevin\AppData\Roaming\Red Alert 3 Uprising\Maps\KEVIN-PC.eml	Quarantined Win32.Worm.Nimda.R (B)
C:\Users\Kevin\AppData\Roaming\Riot Games\League of Legends 3.0.1\KEVIN-PC.eml	Quarantined Win32.Worm.Nimda.R (B)
C:\Users\Kevin\AppData\Roaming\Red Alert 3 Uprising\Profiles\KEVIN-PC.eml	Quarantined Win32.Worm.Nimda.R (B)
C:\Users\Kevin\AppData\Roaming\PDAppFlex\KEVIN-PC.eml	Quarantined Win32.Worm.Nimda.R (B)
C:\Users\Kevin\AppData\Roaming\Riot Games\KEVIN-PC.eml	Quarantined Win32.Worm.Nimda.R (B)
C:\Users\Kevin\AppData\Roaming\PDAppFlex\Local Store\KEVIN-PC.eml	Quarantined Win32.Worm.Nimda.R (B)
C:\Users\Kevin\AppData\Roaming\Red Alert 3 Uprising\KEVIN-PC.eml	Quarantined Win32.Worm.Nimda.R (B)
C:\Users\Kevin\AppData\Roaming\puush\KEVIN-PC.eml	Quarantined Win32.Worm.Nimda.R (B)
C:\Users\Kevin\AppData\Roaming\Origin\Web Storage\KEVIN-PC.eml	Quarantined Win32.Worm.Nimda.R (B)
C:\Users\Kevin\AppData\Roaming\Origin\Widget Updates\KEVIN-PC.eml	Quarantined Win32.Worm.Nimda.R (B)
C:\Users\Kevin\AppData\Roaming\Origin\CommonTitles\KEVIN-PC.eml	Quarantined Win32.Worm.Nimda.R (B)
C:\Users\Kevin\AppData\Roaming\Origin\Cloud Saves\KEVIN-PC.eml	Quarantined Win32.Worm.Nimda.R (B)
C:\Users\Kevin\AppData\Roaming\Mozilla\plugins\KEVIN-PC.eml	Quarantined Win32.Worm.Nimda.R (B)
C:\Users\Kevin\AppData\Roaming\Origin\KEVIN-PC.eml	Quarantined Win32.Worm.Nimda.R (B)
C:\Users\Kevin\AppData\Roaming\Oracle\KEVIN-PC.eml	Quarantined Win32.Worm.Nimda.R (B)
C:\Users\Kevin\AppData\Roaming\Mozilla\KEVIN-PC.eml	Quarantined Win32.Worm.Nimda.R (B)
C:\Users\Kevin\AppData\Roaming\Oracle\Java\KEVIN-PC.eml	Quarantined Win32.Worm.Nimda.R (B)
C:\Users\Kevin\AppData\Roaming\Mozilla\Firefox\Profiles\9wljsqgl.default\storage\KEVIN-PC.eml	Quarantined Win32.Worm.Nimda.R (B)
C:\Users\Kevin\AppData\Roaming\Mozilla\Firefox\Profiles\9wljsqgl.default\sessionstore-backups\KEVIN-PC.eml	Quarantined Win32.Worm.Nimda.R (B)
C:\Users\Kevin\AppData\Roaming\Mozilla\Firefox\Profiles\9wljsqgl.default\storage\permanent\KEVIN-PC.eml	Quarantined Win32.Worm.Nimda.R (B)
C:\Users\Kevin\AppData\Roaming\Mozilla\Firefox\Profiles\9wljsqgl.default\webapps\KEVIN-PC.eml	Quarantined Win32.Worm.Nimda.R (B)
C:\Users\Kevin\AppData\Roaming\Mozilla\Firefox\Profiles\9wljsqgl.default\minidumps\KEVIN-PC.eml	Quarantined Win32.Worm.Nimda.R (B)
C:\Users\Kevin\AppData\Roaming\Mozilla\Firefox\Profiles\9wljsqgl.default\KEVIN-PC.eml	Quarantined Win32.Worm.Nimda.R (B)
C:\Users\Kevin\AppData\Roaming\Mozilla\Firefox\Profiles\9wljsqgl.default\healthreport\KEVIN-PC.eml	Quarantined Win32.Worm.Nimda.R (B)
C:\Users\Kevin\AppData\Roaming\Mozilla\Firefox\Profiles\9wljsqgl.default\gmp\KEVIN-PC.eml	Quarantined Win32.Worm.Nimda.R (B)
C:\Users\Kevin\AppData\Roaming\Mozilla\Firefox\Profiles\9wljsqgl.default\gmp-gmpopenh264\1.4\KEVIN-PC.eml	Quarantined Win32.Worm.Nimda.R (B)
C:\Users\Kevin\AppData\Roaming\Mozilla\Firefox\Profiles\9wljsqgl.default\gmp-gmpopenh264\KEVIN-PC.eml	Quarantined Win32.Worm.Nimda.R (B)
C:\Users\Kevin\AppData\Roaming\Mozilla\Firefox\Profiles\9wljsqgl.default\gmp-eme-adobe\10\KEVIN-PC.eml	Quarantined Win32.Worm.Nimda.R (B)
C:\Users\Kevin\AppData\Roaming\Mozilla\Firefox\Profiles\9wljsqgl.default\gmp-eme-adobe\KEVIN-PC.eml	Quarantined Win32.Worm.Nimda.R (B)
C:\Users\Kevin\AppData\Roaming\Mozilla\Firefox\Profiles\9wljsqgl.default\extensions\KEVIN-PC.eml	Quarantined Win32.Worm.Nimda.R (B)
C:\Users\Kevin\AppData\Roaming\Mozilla\Firefox\Profiles\9wljsqgl.default\datareporting\KEVIN-PC.eml	Quarantined Win32.Worm.Nimda.R (B)
C:\Users\Kevin\AppData\Roaming\Mozilla\Firefox\KEVIN-PC.eml	Quarantined Win32.Worm.Nimda.R (B)
C:\Users\Kevin\AppData\Roaming\Mozilla\Firefox\Profiles\9wljsqgl.default\crashes\KEVIN-PC.eml	Quarantined Win32.Worm.Nimda.R (B)
C:\Users\Kevin\AppData\Roaming\Mozilla\Extensions\KEVIN-PC.eml	Quarantined Win32.Worm.Nimda.R (B)
C:\Users\Kevin\AppData\Roaming\Mozilla\Firefox\Profiles\9wljsqgl.default\bookmarkbackups\KEVIN-PC.eml	Quarantined Win32.Worm.Nimda.R (B)
C:\Users\Kevin\AppData\Roaming\Mozilla\Firefox\Profiles\9wljsqgl.default\crashes\events\KEVIN-PC.eml	Quarantined Win32.Worm.Nimda.R (B)
C:\Users\Kevin\AppData\Roaming\Microsoft\Word\KEVIN-PC.eml	Quarantined Win32.Worm.Nimda.R (B)
C:\Users\Kevin\AppData\Roaming\Microsoft\UProof\KEVIN-PC.eml	Quarantined Win32.Worm.Nimda.R (B)
C:\Users\Kevin\AppData\Roaming\Microsoft\VSTAHost\KEVIN-PC.eml	Quarantined Win32.Worm.Nimda.R (B)
C:\Users\Kevin\AppData\Roaming\Microsoft\Templates\KEVIN-PC.eml	Quarantined Win32.Worm.Nimda.R (B)
C:\Users\Kevin\AppData\Roaming\Microsoft\SystemCertificates\KEVIN-PC.eml	Quarantined Win32.Worm.Nimda.R (B)
C:\Users\Kevin\AppData\Roaming\Microsoft\Spelling\KEVIN-PC.eml	Quarantined Win32.Worm.Nimda.R (B)
C:\Users\Kevin\AppData\Roaming\Microsoft\Speech\KEVIN-PC.eml	Quarantined Win32.Worm.Nimda.R (B)
C:\Users\Kevin\AppData\Roaming\Microsoft\Proof\KEVIN-PC.eml	Quarantined Win32.Worm.Nimda.R (B)
C:\Users\Kevin\AppData\Roaming\Microsoft\Protect\KEVIN-PC.eml	Quarantined Win32.Worm.Nimda.R (B)
C:\Users\Kevin\AppData\Roaming\Microsoft\Paint\KEVIN-PC.eml	Quarantined Win32.Worm.Nimda.R (B)
C:\Users\Kevin\AppData\Roaming\Microsoft\Outlook\KEVIN-PC.eml	Quarantined Win32.Worm.Nimda.R (B)
C:\Users\Kevin\AppData\Roaming\Microsoft\Office\KEVIN-PC.eml	Quarantined Win32.Worm.Nimda.R (B)
C:\Users\Kevin\AppData\Roaming\Microsoft\MMC\KEVIN-PC.eml	Quarantined Win32.Worm.Nimda.R (B)
C:\Users\Kevin\AppData\Roaming\Microsoft\MSDN\KEVIN-PC.eml	Quarantined Win32.Worm.Nimda.R (B)
C:\Users\Kevin\AppData\Roaming\Microsoft\Network\KEVIN-PC.eml	Quarantined Win32.Worm.Nimda.R (B)
C:\Users\Kevin\AppData\Roaming\Microsoft\KEVIN-PC.eml	Quarantined Win32.Worm.Nimda.R (B)
C:\Users\Kevin\AppData\Roaming\Microsoft\Internet Explorer\KEVIN-PC.eml	Quarantined Win32.Worm.Nimda.R (B)
C:\Users\Kevin\AppData\Roaming\Microsoft\Installer\KEVIN-PC.eml	Quarantined Win32.Worm.Nimda.R (B)
C:\Users\Kevin\AppData\Roaming\Microsoft\HTML Help\KEVIN-PC.eml	Quarantined Win32.Worm.Nimda.R (B)
C:\Users\Kevin\AppData\Roaming\Microsoft\Excel\KEVIN-PC.eml	Quarantined Win32.Worm.Nimda.R (B)
C:\Users\Kevin\AppData\Roaming\Microsoft\CLView\KEVIN-PC.eml	Quarantined Win32.Worm.Nimda.R (B)
C:\Users\Kevin\AppData\Roaming\Microsoft\Document Building Blocks\KEVIN-PC.eml	Quarantined Win32.Worm.Nimda.R (B)
C:\Users\Kevin\AppData\Roaming\Microsoft\Crypto\KEVIN-PC.eml	Quarantined Win32.Worm.Nimda.R (B)
C:\Users\Kevin\AppData\Roaming\Microsoft\Credentials\KEVIN-PC.eml	Quarantined Win32.Worm.Nimda.R (B)
C:\Users\Kevin\AppData\Roaming\Microsoft\CLR Security Config\KEVIN-PC.eml	Quarantined Win32.Worm.Nimda.R (B)
C:\Users\Kevin\AppData\Roaming\Microsoft\AddIns\KEVIN-PC.eml	Quarantined Win32.Worm.Nimda.R (B)
C:\Users\Kevin\AppData\Roaming\Media Center Programs\KEVIN-PC.eml	Quarantined Win32.Worm.Nimda.R (B)
C:\Users\Kevin\AppData\Roaming\Malwarebytes\KEVIN-PC.eml	Quarantined Win32.Worm.Nimda.R (B)
C:\Users\Kevin\AppData\Roaming\Macromedia\Flash Player\KEVIN-PC.eml	Quarantined Win32.Worm.Nimda.R (B)
C:\Users\Kevin\AppData\Roaming\Macromedia\KEVIN-PC.eml	Quarantined Win32.Worm.Nimda.R (B)
C:\Users\Kevin\AppData\Roaming\Luxology\Scripts\KEVIN-PC.eml	Quarantined Win32.Worm.Nimda.R (B)
C:\Users\Kevin\AppData\Roaming\Luxology\Presets\KEVIN-PC.eml	Quarantined Win32.Worm.Nimda.R (B)
C:\Users\Kevin\AppData\Roaming\Luxology\Configs\KEVIN-PC.eml	Quarantined Win32.Worm.Nimda.R (B)
C:\Users\Kevin\AppData\Roaming\Luxology\KEVIN-PC.eml	Quarantined Win32.Worm.Nimda.R (B)
C:\Users\Kevin\AppData\Roaming\LolClient\Local Store\KEVIN-PC.eml	Quarantined Win32.Worm.Nimda.R (B)
C:\Users\Kevin\AppData\Roaming\LolClient\KEVIN-PC.eml	Quarantined Win32.Worm.Nimda.R (B)
C:\Users\Kevin\AppData\Roaming\KEVIN-PC.eml	Quarantined Win32.Worm.Nimda.R (B)
C:\Users\Kevin\AppData\Roaming\InstallShield\ISEngine12.0\KEVIN-PC.eml	Quarantined Win32.Worm.Nimda.R (B)
C:\Users\Kevin\AppData\Roaming\Kits\KEVIN-PC.eml	Quarantined Win32.Worm.Nimda.R (B)
C:\Users\Kevin\AppData\Roaming\help_images_otherUI\help_images_otherUI\KEVIN-PC.eml	Quarantined Win32.Worm.Nimda.R (B)
C:\Users\Kevin\AppData\Roaming\help_images_otherUI\KEVIN-PC.eml	Quarantined Win32.Worm.Nimda.R (B)
C:\Users\Kevin\AppData\Roaming\DassaultSystemes\KEVIN-PC.eml	Quarantined Win32.Worm.Nimda.R (B)
C:\Users\Kevin\AppData\Roaming\InstallShield\KEVIN-PC.eml	Quarantined Win32.Worm.Nimda.R (B)
C:\Users\Kevin\AppData\Roaming\Identities\KEVIN-PC.eml	Quarantined Win32.Worm.Nimda.R (B)
C:\Users\Kevin\AppData\Roaming\Identities\{B3098830-65E0-47C4-8E28-768DD8A23149}\KEVIN-PC.eml	Quarantined Win32.Worm.Nimda.R (B)
C:\Users\Kevin\AppData\Roaming\DAEMON Tools Lite\KEVIN-PC.eml	Quarantined Win32.Worm.Nimda.R (B)
C:\Users\Kevin\AppData\Roaming\FreeCAD\KEVIN-PC.eml	Quarantined Win32.Worm.Nimda.R (B)
C:\Users\Kevin\AppData\Roaming\EDrawings\KEVIN-PC.eml	Quarantined Win32.Worm.Nimda.R (B)
C:\Users\Kevin\AppData\Roaming\DAEMON Tools Lite\IconsCache\KEVIN-PC.eml	Quarantined Win32.Worm.Nimda.R (B)
C:\Users\Kevin\AppData\Roaming\Curse\Curse 6.0.0.0\KEVIN-PC.eml	Quarantined Win32.Worm.Nimda.R (B)
C:\Users\Kevin\AppData\Roaming\Curse\KEVIN-PC.eml	Quarantined Win32.Worm.Nimda.R (B)
C:\Users\Kevin\AppData\Roaming\Curse Client\Profiles\KEVIN-PC.eml	Quarantined Win32.Worm.Nimda.R (B)
C:\Users\Kevin\AppData\Roaming\Curse Client\Overlay\KEVIN-PC.eml	Quarantined Win32.Worm.Nimda.R (B)
C:\Users\Kevin\AppData\Roaming\Curse Client\Plugins\KEVIN-PC.eml	Quarantined Win32.Worm.Nimda.R (B)
C:\Users\Kevin\AppData\Roaming\Curse Client\Logs\KEVIN-PC.eml	Quarantined Win32.Worm.Nimda.R (B)
C:\Users\Kevin\AppData\Roaming\Curse Client\Cache\KEVIN-PC.eml	Quarantined Win32.Worm.Nimda.R (B)
C:\Users\Kevin\AppData\Roaming\Curse Client\KEVIN-PC.eml	Quarantined Win32.Worm.Nimda.R (B)
C:\Users\Kevin\AppData\Roaming\Curse Client\Bin\KEVIN-PC.eml	Quarantined Win32.Worm.Nimda.R (B)
C:\Users\Kevin\AppData\Roaming\Creative\KEVIN-PC.eml	Quarantined Win32.Worm.Nimda.R (B)
C:\Users\Kevin\AppData\Roaming\Creative\Dell WebCam Central\KEVIN-PC.eml	Quarantined Win32.Worm.Nimda.R (B)
C:\Users\Kevin\AppData\Roaming\Bitdreamers\KEVIN-PC.eml	Quarantined Win32.Worm.Nimda.R (B)
C:\Users\Kevin\AppData\Roaming\Battle.net\KEVIN-PC.eml	Quarantined Win32.Worm.Nimda.R (B)
C:\Users\Kevin\AppData\Roaming\Bitdreamers\TimeComX Basic\KEVIN-PC.eml	Quarantined Win32.Worm.Nimda.R (B)
C:\Users\Kevin\AppData\Roaming\ATI\KEVIN-PC.eml	Quarantined Win32.Worm.Nimda.R (B)
C:\Users\Kevin\AppData\Roaming\ATI\ACE\KEVIN-PC.eml	Quarantined Win32.Worm.Nimda.R (B)
C:\Users\Kevin\AppData\Roaming\Apple Computer\SyncServices\KEVIN-PC.eml	Quarantined Win32.Worm.Nimda.R (B)
C:\Users\Kevin\AppData\Roaming\Apple Computer\MobileSync\KEVIN-PC.eml	Quarantined Win32.Worm.Nimda.R (B)
C:\Users\Kevin\AppData\Roaming\Apple Computer\Preferences\KEVIN-PC.eml	Quarantined Win32.Worm.Nimda.R (B)
C:\Users\Kevin\AppData\Roaming\Apple Computer\Logs\KEVIN-PC.eml	Quarantined Win32.Worm.Nimda.R (B)
C:\Users\Kevin\AppData\Roaming\Apple Computer\KEVIN-PC.eml	Quarantined Win32.Worm.Nimda.R (B)
C:\Users\Kevin\AppData\Roaming\Andy\machines\KEVIN-PC.eml	Quarantined Win32.Worm.Nimda.R (B)
C:\Users\Kevin\AppData\Roaming\Apple Computer\iTunes\KEVIN-PC.eml	Quarantined Win32.Worm.Nimda.R (B)
C:\Users\Kevin\AppData\Roaming\Andy\keymapper\KEVIN-PC.eml	Quarantined Win32.Worm.Nimda.R (B)
C:\Users\Kevin\AppData\Roaming\Andy\HandyAndy\KEVIN-PC.eml	Quarantined Win32.Worm.Nimda.R (B)
C:\Users\Kevin\AppData\Roaming\Andy\KEVIN-PC.eml	Quarantined Win32.Worm.Nimda.R (B)
C:\Users\Kevin\AppData\Roaming\Adobe\XMP\KEVIN-PC.eml	Quarantined Win32.Worm.Nimda.R (B)
C:\Users\Kevin\AppData\Roaming\Adobe\Sonar\KEVIN-PC.eml	Quarantined Win32.Worm.Nimda.R (B)
C:\Users\Kevin\AppData\Roaming\Adobe\Workflow\KEVIN-PC.eml	Quarantined Win32.Worm.Nimda.R (B)
C:\Users\Kevin\AppData\Roaming\Adobe\Photoshop\KEVIN-PC.eml	Quarantined Win32.Worm.Nimda.R (B)
C:\Users\Kevin\AppData\Roaming\Adobe\LogTransport2CC\KEVIN-PC.eml	Quarantined Win32.Worm.Nimda.R (B)
C:\Users\Kevin\AppData\Roaming\Adobe\Headlights\KEVIN-PC.eml	Quarantined Win32.Worm.Nimda.R (B)
C:\Users\Kevin\AppData\Roaming\Adobe\ImageReady\KEVIN-PC.eml	Quarantined Win32.Worm.Nimda.R (B)
C:\Users\Kevin\AppData\Roaming\Adobe\LogTransport2\KEVIN-PC.eml	Quarantined Win32.Worm.Nimda.R (B)
C:\Users\Kevin\AppData\Roaming\Adobe\Linguistics\KEVIN-PC.eml	Quarantined Win32.Worm.Nimda.R (B)
C:\Users\Kevin\AppData\Roaming\Adobe\KEVIN-PC.eml	Quarantined Win32.Worm.Nimda.R (B)
C:\Users\Kevin\AppData\Roaming\Adobe\Creative Cloud Libraries\KEVIN-PC.eml	Quarantined Win32.Worm.Nimda.R (B)
C:\Users\Kevin\AppData\Roaming\Adobe\Flash Player\KEVIN-PC.eml	Quarantined Win32.Worm.Nimda.R (B)
C:\Users\Kevin\AppData\Roaming\Adobe\Extension Manager CC\KEVIN-PC.eml	Quarantined Win32.Worm.Nimda.R (B)
C:\Users\Kevin\AppData\Roaming\Adobe\CoreSync\KEVIN-PC.eml	Quarantined Win32.Worm.Nimda.R (B)
C:\Users\Kevin\AppData\Roaming\Adobe\Color\KEVIN-PC.eml	Quarantined Win32.Worm.Nimda.R (B)
C:\Users\Kevin\AppData\Roaming\Adobe\Adobe Photoshop CC 2014\KEVIN-PC.eml	Quarantined Win32.Worm.Nimda.R (B)
C:\Users\Kevin\AppData\Roaming\Adobe\CameraRaw\KEVIN-PC.eml	Quarantined Win32.Worm.Nimda.R (B)
C:\Users\Kevin\AppData\Roaming\Adobe\Adobe PDF\KEVIN-PC.eml	Quarantined Win32.Worm.Nimda.R (B)
C:\Users\Kevin\AppData\Roaming\Adobe\ACSL\KEVIN-PC.eml	Quarantined Win32.Worm.Nimda.R (B)
C:\Users\Kevin\AppData\Roaming\Adobe\Acrobat\KEVIN-PC.eml	Quarantined Win32.Worm.Nimda.R (B)
C:\Users\Kevin\AppData\Roaming\7DaysToDie\Saves\KEVIN-PC.eml	Quarantined Win32.Worm.Nimda.R (B)
C:\Users\Kevin\AppData\Roaming\7DaysToDie\KEVIN-PC.eml	Quarantined Win32.Worm.Nimda.R (B)
C:\Users\Kevin\AppData\Local\ZJMedia\KEVIN-PC.eml	Quarantined Win32.Worm.Nimda.R (B)
C:\Users\Kevin\AppData\Local\VirtualStore\KEVIN-PC.eml	Quarantined Win32.Worm.Nimda.R (B)
C:\Users\Kevin\AppData\Local\TempSWBackupDirectory\KEVIN-PC.eml	Quarantined Win32.Worm.Nimda.R (B)
C:\Users\Kevin\AppData\Local\Unity\KEVIN-PC.eml	Quarantined Win32.Worm.Nimda.R (B)
C:\Users\Kevin\AppData\Local\Temp\scoped_dir4716_22273\KEVIN-PC.eml	Quarantined Win32.Worm.Nimda.R (B)
C:\Users\Kevin\AppData\Local\Temp\scoped_dir4716_22273\Local Storage\KEVIN-PC.eml	Quarantined Win32.Worm.Nimda.R (B)
C:\Users\Kevin\AppData\Local\Temp\scoped_dir4716_22273\Dictionaries\KEVIN-PC.eml	Quarantined Win32.Worm.Nimda.R (B)
C:\Users\Kevin\AppData\Local\Temp\DirectX_Setup\KEVIN-PC.eml	Quarantined Win32.Worm.Nimda.R (B)
C:\Users\Kevin\AppData\Local\Temp\KEVIN-PC.eml	Quarantined Win32.Worm.Nimda.R (B)
C:\Users\Kevin\AppData\Local\TeamSpeak 3 Client\readme.eml	Quarantined Win32.Worm.Nimda.R (B)
C:\Users\Kevin\AppData\Local\TeamSpeak 3 Client\plugin_sdk.html	Quarantined Win32.Worm.Nimda.O (B)
C:\Users\Kevin\AppData\Local\TeamSpeak 3 Client\KEVIN-PC.eml	Quarantined Win32.Worm.Nimda.R (B)
C:\Users\Kevin\AppData\Local\TeamSpeak 3 Client\createfileassoc.exe	Quarantined Gen:Malware.Heur.guW@byVpohei (B)
C:\Users\Kevin\AppData\Local\Steam\KEVIN-PC.eml	Quarantined Win32.Worm.Nimda.R (B)
C:\Users\Kevin\AppData\Local\SolidWorks\KEVIN-PC.eml	Quarantined Win32.Worm.Nimda.R (B)
C:\Users\Kevin\AppData\Local\Samsung\KEVIN-PC.eml	Quarantined Win32.Worm.Nimda.R (B)
C:\Users\Kevin\AppData\Local\Skype\KEVIN-PC.eml	Quarantined Win32.Worm.Nimda.R (B)
C:\Users\Kevin\AppData\Local\Programs\KEVIN-PC.eml	Quarantined Win32.Worm.Nimda.R (B)
C:\Users\Kevin\AppData\Local\ms-drivers\KEVIN-PC.eml	Quarantined Win32.Worm.Nimda.R (B)
C:\Users\Kevin\AppData\Local\SKIDROW\KEVIN-PC.eml	Quarantined Win32.Worm.Nimda.R (B)
C:\Users\Kevin\AppData\Local\PunkBuster\KEVIN-PC.eml	Quarantined Win32.Worm.Nimda.R (B)
C:\Users\Kevin\AppData\Local\openvr\KEVIN-PC.eml	Quarantined Win32.Worm.Nimda.R (B)
C:\Users\Kevin\AppData\Local\Origin\KEVIN-PC.eml	Quarantined Win32.Worm.Nimda.R (B)
C:\Users\Kevin\AppData\Local\My Games\KEVIN-PC.eml	Quarantined Win32.Worm.Nimda.R (B)
C:\Users\Kevin\AppData\Local\Mozilla\KEVIN-PC.eml	Quarantined Win32.Worm.Nimda.R (B)
C:\Users\Kevin\AppData\Local\Microsoft\Windows\Temporary Internet Files\KEVIN-PC.eml	Quarantined Win32.Worm.Nimda.R (B)
C:\Users\Kevin\AppData\Local\Microsoft\Windows\History\KEVIN-PC.eml	Quarantined Win32.Worm.Nimda.R (B)
C:\Users\Kevin\AppData\Local\Microsoft\KEVIN-PC.eml	Quarantined Win32.Worm.Nimda.R (B)
C:\Users\Kevin\AppData\Local\Microsoft Help\KEVIN-PC.eml	Quarantined Win32.Worm.Nimda.R (B)
C:\Users\Kevin\AppData\Local\KEVIN-PC.eml	Quarantined Win32.Worm.Nimda.R (B)
C:\Users\Kevin\AppData\Local\MetaGeek,_LLC\KEVIN-PC.eml	Quarantined Win32.Worm.Nimda.R (B)
C:\Users\Kevin\AppData\Local\GWX\KEVIN-PC.eml	Quarantined Win32.Worm.Nimda.R (B)
C:\Users\Kevin\AppData\Local\Google\KEVIN-PC.eml	Quarantined Win32.Worm.Nimda.R (B)
C:\Users\Kevin\AppData\Local\Google\Chrome\User Data\Default\KEVIN-PC.eml	Quarantined Win32.Worm.Nimda.R (B)
C:\Users\Kevin\AppData\Local\Facebook\KEVIN-PC.eml	Quarantined Win32.Worm.Nimda.R (B)
C:\Users\Kevin\AppData\Local\FluxSoftware\KEVIN-PC.eml	Quarantined Win32.Worm.Nimda.R (B)
C:\Users\Kevin\AppData\Local\ESN\KEVIN-PC.eml	Quarantined Win32.Worm.Nimda.R (B)
C:\Users\Kevin\AppData\Local\EmieUserList\KEVIN-PC.eml	Quarantined Win32.Worm.Nimda.R (B)
C:\Users\Kevin\AppData\Local\EmieBrowserModeList\KEVIN-PC.eml	Quarantined Win32.Worm.Nimda.R (B)
C:\Users\Kevin\AppData\Local\EmieSiteList\KEVIN-PC.eml	Quarantined Win32.Worm.Nimda.R (B)
C:\Users\Kevin\AppData\Local\Deployment\KEVIN-PC.eml	Quarantined Win32.Worm.Nimda.R (B)
C:\Users\Kevin\AppData\Local\CrashDumps\KEVIN-PC.eml	Quarantined Win32.Worm.Nimda.R (B)
C:\Users\Kevin\AppData\Local\Downloaded Installations\KEVIN-PC.eml	Quarantined Win32.Worm.Nimda.R (B)
C:\Users\Kevin\AppData\Local\Broadcom\KEVIN-PC.eml	Quarantined Win32.Worm.Nimda.R (B)
C:\Users\Kevin\AppData\Local\ElevatedDiagnostics\KEVIN-PC.eml	Quarantined Win32.Worm.Nimda.R (B)
C:\Users\Kevin\AppData\Local\DassaultSystemes\KEVIN-PC.eml	Quarantined Win32.Worm.Nimda.R (B)
C:\Users\Kevin\AppData\Local\Diagnostics\KEVIN-PC.eml	Quarantined Win32.Worm.Nimda.R (B)
C:\Users\Kevin\AppData\Local\CrashDumps\GoogleUpdate.exe.5796.dmp	Quarantined Win32.Worm.Nimda.R (B)
C:\Users\Kevin\AppData\Local\Blizzard Entertainment\KEVIN-PC.eml	Quarantined Win32.Worm.Nimda.R (B)
C:\Users\Kevin\AppData\Local\Battle.net\KEVIN-PC.eml	Quarantined Win32.Worm.Nimda.R (B)
C:\Users\Kevin\AppData\Local\ATI\KEVIN-PC.eml	Quarantined Win32.Worm.Nimda.R (B)
C:\Users\Kevin\AppData\Local\Apple\KEVIN-PC.eml	Quarantined Win32.Worm.Nimda.R (B)
C:\Users\Kevin\AppData\Local\Apps\KEVIN-PC.eml	Quarantined Win32.Worm.Nimda.R (B)
C:\Users\Kevin\AppData\Local\APManager\KEVIN-PC.eml	Quarantined Win32.Worm.Nimda.R (B)
C:\Users\Kevin\AppData\Local\Apple Computer\KEVIN-PC.eml	Quarantined Win32.Worm.Nimda.R (B)
C:\Users\Kevin\AppData\Local\AOL\KEVIN-PC.eml	Quarantined Win32.Worm.Nimda.R (B)
C:\Users\Kevin\AppData\Local\Anvisoft\KEVIN-PC.eml	Quarantined Win32.Worm.Nimda.R (B)
C:\Users\Kevin\AppData\Local\Akamai\KEVIN-PC.eml	Quarantined Win32.Worm.Nimda.R (B)
C:\Users\Kevin\AppData\KEVIN-PC.eml	Quarantined Win32.Worm.Nimda.R (B)
C:\Users\Kevin\AppData\Local\Adobe\KEVIN-PC.eml	Quarantined Win32.Worm.Nimda.R (B)
C:\Users\Kevin\AppData\Local\Aeria Games\KEVIN-PC.eml	Quarantined Win32.Worm.Nimda.R (B)
C:\Users\Kevin\Andy\KEVIN-PC.eml	Quarantined Win32.Worm.Nimda.R (B)
C:\Users\Default\Videos\KEVIN-PC.eml	Quarantined Win32.Worm.Nimda.R (B)
C:\Users\Default\Saved Games\KEVIN-PC.eml	Quarantined Win32.Worm.Nimda.R (B)
C:\Users\Default\Pictures\KEVIN-PC.eml	Quarantined Win32.Worm.Nimda.R (B)
C:\Users\Default\Music\KEVIN-PC.eml	Quarantined Win32.Worm.Nimda.R (B)
C:\Users\Default\Links\KEVIN-PC.eml	Quarantined Win32.Worm.Nimda.R (B)
C:\Users\Default\KEVIN-PC.eml	Quarantined Win32.Worm.Nimda.R (B)
C:\Users\Default\Downloads\KEVIN-PC.eml	Quarantined Win32.Worm.Nimda.R (B)
C:\Users\Default\AppData\KEVIN-PC.eml	Quarantined Win32.Worm.Nimda.R (B)
C:\Users\Default\Favorites\KEVIN-PC.eml	Quarantined Win32.Worm.Nimda.R (B)
C:\Users\Default\Desktop\KEVIN-PC.eml	Quarantined Win32.Worm.Nimda.R (B)
C:\Users\Default\Documents\KEVIN-PC.eml	Quarantined Win32.Worm.Nimda.R (B)
C:\ProgramData\SOLIDWORKS\SOLIDWORKS Inspection 2015 Standalone\KEVIN-PC.eml	Quarantined Win32.Worm.Nimda.R (B)
C:\ProgramData\TEMP\KEVIN-PC.eml	Quarantined Win32.Worm.Nimda.R (B)
C:\ProgramData\Sun\Java\KEVIN-PC.eml	Quarantined Win32.Worm.Nimda.R (B)
C:\ProgramData\Sun\KEVIN-PC.eml	Quarantined Win32.Worm.Nimda.R (B)
C:\Users\Default\AppData\Local\Temp\KEVIN-PC.eml	Quarantined Win32.Worm.Nimda.R (B)
C:\ProgramData\SOLIDWORKS\SOLIDWORKS Inspection 2015 Addin\KEVIN-PC.eml	Quarantined Win32.Worm.Nimda.R (B)
C:\ProgramData\SOLIDWORKS\SOLIDWORKS 2015\KEVIN-PC.eml	Quarantined Win32.Worm.Nimda.R (B)
C:\ProgramData\SOLIDWORKS\KEVIN-PC.eml	Quarantined Win32.Worm.Nimda.R (B)
C:\ProgramData\SOLIDWORKS Flow Simulation\KEVIN-PC.eml	Quarantined Win32.Worm.Nimda.R (B)
C:\ProgramData\SOLIDWORKS Electrical\Update\KEVIN-PC.eml	Quarantined Win32.Worm.Nimda.R (B)
C:\ProgramData\SOLIDWORKS Flow Simulation\Flow Simulation 2014\KEVIN-PC.eml	Quarantined Win32.Worm.Nimda.R (B)
C:\ProgramData\SOLIDWORKS\CircuitWorks\KEVIN-PC.eml	Quarantined Win32.Worm.Nimda.R (B)
C:\ProgramData\SOLIDWORKS Electrical\epdm_bom\KEVIN-PC.eml	Quarantined Win32.Worm.Nimda.R (B)
C:\ProgramData\SOLIDWORKS Electrical\KEVIN-PC.eml	Quarantined Win32.Worm.Nimda.R (B)
C:\ProgramData\SOLIDWORKS Electrical\MSSQL11.TEW_SQLEXPRESS\KEVIN-PC.eml	Quarantined Win32.Worm.Nimda.R (B)
C:\ProgramData\SOLIDWORKS Electrical\catalog\KEVIN-PC.eml	Quarantined Win32.Worm.Nimda.R (B)
C:\ProgramData\Skype\{7A3C7E05-EE37-47D6-99E1-2EB05A3DA3F7}\KEVIN-PC.eml	Quarantined Win32.Worm.Nimda.R (B)
C:\ProgramData\Skype\Apps\KEVIN-PC.eml	Quarantined Win32.Worm.Nimda.R (B)
C:\ProgramData\Skype\{4E76FF7E-AEBA-4C87-B788-CD47E5425B9D}\KEVIN-PC.eml	Quarantined Win32.Worm.Nimda.R (B)
C:\ProgramData\Skype\KEVIN-PC.eml	Quarantined Win32.Worm.Nimda.R (B)
C:\ProgramData\Skype\{24991BA0-F0EE-44AD-9CC8-5EC50AECF6B7}\KEVIN-PC.eml	Quarantined Win32.Worm.Nimda.R (B)
C:\ProgramData\SketchUp\SketchUp 2015\KEVIN-PC.eml	Quarantined Win32.Worm.Nimda.R (B)
C:\ProgramData\SketchUp\KEVIN-PC.eml	Quarantined Win32.Worm.Nimda.R (B)
C:\ProgramData\Simpoe\KEVIN-PC.eml	Quarantined Win32.Worm.Nimda.R (B)
C:\ProgramData\SketchUp\SketchUp 2014\KEVIN-PC.eml	Quarantined Win32.Worm.Nimda.R (B)
C:\ProgramData\Samsung\Kies\KEVIN-PC.eml	Quarantined Win32.Worm.Nimda.R (B)
C:\ProgramData\Samsung\Device Error Recovery\KEVIN-PC.eml	Quarantined Win32.Worm.Nimda.R (B)
C:\ProgramData\Samsung\DeviceProfile\KEVIN-PC.eml	Quarantined Win32.Worm.Nimda.R (B)
C:\ProgramData\Samsung\KEVIN-PC.eml	Quarantined Win32.Worm.Nimda.R (B)
C:\ProgramData\RogueKiller\Quarantine\KEVIN-PC.eml	Quarantined Win32.Worm.Nimda.R (B)
C:\ProgramData\RogueKiller\Logs\KEVIN-PC.eml	Quarantined Win32.Worm.Nimda.R (B)
C:\ProgramData\RogueKiller\Debug\KEVIN-PC.eml	Quarantined Win32.Worm.Nimda.R (B)
C:\ProgramData\RogueKiller\KEVIN-PC.eml	Quarantined Win32.Worm.Nimda.R (B)
C:\ProgramData\Riot Games\KEVIN-PC.eml	Quarantined Win32.Worm.Nimda.R (B)
C:\ProgramData\Reprise\KEVIN-PC.eml	Quarantined Win32.Worm.Nimda.R (B)
C:\ProgramData\regid.1986-12.com.adobe\KEVIN-PC.eml	Quarantined Win32.Worm.Nimda.R (B)
C:\ProgramData\Ralink Driver\KEVIN-PC.eml	Quarantined Win32.Worm.Nimda.R (B)
C:\ProgramData\Package Cache\{F8CFEB22-A2E7-3971-9EDA-4B11EDEFC185}v12.0.21005\KEVIN-PC.eml	Quarantined Win32.Worm.Nimda.R (B)
C:\ProgramData\Package Cache\{ce085a78-074e-4823-8dc1-8a721b94b76d}\KEVIN-PC.eml	Quarantined Win32.Worm.Nimda.R (B)
C:\ProgramData\Package Cache\{CF2BEA3C-26EA-32F8-AA9B-331F7E34BA97}v11.0.61030\KEVIN-PC.eml	Quarantined Win32.Worm.Nimda.R (B)
C:\ProgramData\Package Cache\{ca67548a-5ebe-413a-b50c-4b9ceb6d66c6}\KEVIN-PC.eml	Quarantined Win32.Worm.Nimda.R (B)
C:\ProgramData\Ralink Driver\RT2870 Wireless LAN Card\KEVIN-PC.eml	Quarantined Win32.Worm.Nimda.R (B)
C:\ProgramData\Package Cache\{BD95A8CD-1D9F-35AD-981A-3E7925026EBB}v11.0.61030\KEVIN-PC.eml	Quarantined Win32.Worm.Nimda.R (B)
C:\ProgramData\Package Cache\{B175520C-86A2-35A7-8619-86DC379688B9}v11.0.61030\KEVIN-PC.eml	Quarantined Win32.Worm.Nimda.R (B)
C:\ProgramData\Package Cache\{929FBD26-9020-399B-9A7A-751D61F0B942}v12.0.21005\KEVIN-PC.eml	Quarantined Win32.Worm.Nimda.R (B)
C:\ProgramData\Package Cache\{A749D8E6-B613-3BE3-8F5F-045C84EBA29B}v12.0.21005\KEVIN-PC.eml	Quarantined Win32.Worm.Nimda.R (B)
C:\ProgramData\Package Cache\{37B8F9C7-03FB-3253-8781-2517C99D7C00}v11.0.61030\KEVIN-PC.eml	Quarantined Win32.Worm.Nimda.R (B)
C:\ProgramData\Package Cache\{7f51bdb9-ee21-49ee-94d6-90afc321780e}\KEVIN-PC.eml	Quarantined Win32.Worm.Nimda.R (B)
C:\ProgramData\Package Cache\{33d1fd90-4274-48a1-9bc1-97e33d9c2d6f}\KEVIN-PC.eml	Quarantined Win32.Worm.Nimda.R (B)
C:\ProgramData\Package Cache\{13A4EE12-23EA-3371-91EE-EFB36DDFFF3E}v12.0.21005\KEVIN-PC.eml	Quarantined Win32.Worm.Nimda.R (B)
C:\ProgramData\Package Cache\KEVIN-PC.eml	Quarantined Win32.Worm.Nimda.R (B)
C:\ProgramData\Origin\Telemetry\KEVIN-PC.eml	Quarantined Win32.Worm.Nimda.R (B)
C:\ProgramData\Origin\NonOriginContentCache\KEVIN-PC.eml	Quarantined Win32.Worm.Nimda.R (B)
C:\ProgramData\Origin\Logs\KEVIN-PC.eml	Quarantined Win32.Worm.Nimda.R (B)
C:\ProgramData\Oracle\KEVIN-PC.eml	Quarantined Win32.Worm.Nimda.R (B)
C:\ProgramData\Origin\LocalContent\KEVIN-PC.eml	Quarantined Win32.Worm.Nimda.R (B)
C:\ProgramData\Origin\KEVIN-PC.eml	Quarantined Win32.Worm.Nimda.R (B)
C:\ProgramData\Origin\EntitlementCache\KEVIN-PC.eml	Quarantined Win32.Worm.Nimda.R (B)
C:\ProgramData\Origin\DownloadCache\KEVIN-PC.eml	Quarantined Win32.Worm.Nimda.R (B)
C:\ProgramData\Origin\CustomBoxartCache\KEVIN-PC.eml	Quarantined Win32.Worm.Nimda.R (B)
C:\ProgramData\Origin\AchievementCache\KEVIN-PC.eml	Quarantined Win32.Worm.Nimda.R (B)
C:\ProgramData\NexonUS\NGM\KEVIN-PC.eml	Quarantined Win32.Worm.Nimda.R (B)
C:\ProgramData\Nexon\Common\KEVIN-PC.eml	Quarantined Win32.Worm.Nimda.R (B)
C:\ProgramData\NexonUS\KEVIN-PC.eml	Quarantined Win32.Worm.Nimda.R (B)
C:\ProgramData\Nexon\KEVIN-PC.eml	Quarantined Win32.Worm.Nimda.R (B)
C:\ProgramData\Mozilla\logs\KEVIN-PC.eml	Quarantined Win32.Worm.Nimda.R (B)
C:\ProgramData\Mozilla\KEVIN-PC.eml	Quarantined Win32.Worm.Nimda.R (B)
C:\ProgramData\Microsoft\Wlansvc\KEVIN-PC.eml	Quarantined Win32.Worm.Nimda.R (B)
C:\ProgramData\Microsoft\RAC\KEVIN-PC.eml	Quarantined Win32.Worm.Nimda.R (B)
C:\ProgramData\Microsoft\WwanSvc\KEVIN-PC.eml	Quarantined Win32.Worm.Nimda.R (B)
C:\ProgramData\Microsoft\WPD\KEVIN-PC.eml	Quarantined Win32.Worm.Nimda.R (B)
C:\ProgramData\Microsoft\User Account Pictures\KEVIN-PC.eml	Quarantined Win32.Worm.Nimda.R (B)
C:\ProgramData\Microsoft\Search\KEVIN-PC.eml	Quarantined Win32.Worm.Nimda.R (B)
C:\ProgramData\Microsoft\Vault\KEVIN-PC.eml	Quarantined Win32.Worm.Nimda.R (B)
C:\ProgramData\Microsoft\PlayReadySilverlight\KEVIN-PC.eml	Quarantined Win32.Worm.Nimda.R (B)
C:\ProgramData\Microsoft\PlayReady\KEVIN-PC.eml	Quarantined Win32.Worm.Nimda.R (B)
C:\ProgramData\Microsoft\OfficeSoftwareProtectionPlatform\KEVIN-PC.eml	Quarantined Win32.Worm.Nimda.R (B)
C:\ProgramData\Microsoft\OFFICE\KEVIN-PC.eml	Quarantined Win32.Worm.Nimda.R (B)
C:\ProgramData\Microsoft\MSDN\KEVIN-PC.eml	Quarantined Win32.Worm.Nimda.R (B)
C:\ProgramData\Microsoft\NetFramework\KEVIN-PC.eml	Quarantined Win32.Worm.Nimda.R (B)
C:\ProgramData\Microsoft\KEVIN-PC.eml	Quarantined Win32.Worm.Nimda.R (B)
C:\ProgramData\Microsoft\Network\KEVIN-PC.eml	Quarantined Win32.Worm.Nimda.R (B)
C:\ProgramData\Microsoft\Media Player\KEVIN-PC.eml	Quarantined Win32.Worm.Nimda.R (B)
C:\ProgramData\Microsoft\MF\KEVIN-PC.eml	Quarantined Win32.Worm.Nimda.R (B)
C:\ProgramData\Microsoft\IlsCache\KEVIN-PC.eml	Quarantined Win32.Worm.Nimda.R (B)
C:\ProgramData\Microsoft\HTML Help\KEVIN-PC.eml	Quarantined Win32.Worm.Nimda.R (B)
C:\ProgramData\Microsoft\IdentityCRL\KEVIN-PC.eml	Quarantined Win32.Worm.Nimda.R (B)
C:\ProgramData\Microsoft\DRM\KEVIN-PC.eml	Quarantined Win32.Worm.Nimda.R (B)
C:\ProgramData\Microsoft\eHome\KEVIN-PC.eml	Quarantined Win32.Worm.Nimda.R (B)
C:\ProgramData\Microsoft\Event Viewer\KEVIN-PC.eml	Quarantined Win32.Worm.Nimda.R (B)
C:\ProgramData\Microsoft\Diagnosis\KEVIN-PC.eml	Quarantined Win32.Worm.Nimda.R (B)
C:\ProgramData\Microsoft\Device Stage\KEVIN-PC.eml	Quarantined Win32.Worm.Nimda.R (B)
C:\ProgramData\Microsoft\DeviceSync\KEVIN-PC.eml	Quarantined Win32.Worm.Nimda.R (B)
C:\ProgramData\Microsoft\Crypto\KEVIN-PC.eml	Quarantined Win32.Worm.Nimda.R (B)
C:\ProgramData\Microsoft\Assistance\KEVIN-PC.eml	Quarantined Win32.Worm.Nimda.R (B)
C:\ProgramData\Microsoft Help\KEVIN-PC.eml	Quarantined Win32.Worm.Nimda.R (B)
C:\ProgramData\McAfee\KEVIN-PC.eml	Quarantined Win32.Worm.Nimda.R (B)
C:\ProgramData\McAfee\MCLOGS\KEVIN-PC.eml	Quarantined Win32.Worm.Nimda.R (B)
C:\ProgramData\Malwarebytes\Malwarebytes' Anti-Malware\KEVIN-PC.eml	Quarantined Win32.Worm.Nimda.R (B)
C:\ProgramData\Malwarebytes\Malwarebytes Anti-Malware\KEVIN-PC.eml	Quarantined Win32.Worm.Nimda.R (B)
C:\ProgramData\KEVIN-PC.eml	Quarantined Win32.Worm.Nimda.R (B)
C:\ProgramData\Malwarebytes\KEVIN-PC.eml	Quarantined Win32.Worm.Nimda.R (B)
C:\ProgramData\Installations\{AB6F6C80-1C35-4672-BDEF-F26FF214C409}\KEVIN-PC.eml	Quarantined Win32.Worm.Nimda.R (B)
C:\ProgramData\Electronic Arts\KEVIN-PC.eml	Quarantined Win32.Worm.Nimda.R (B)
C:\ProgramData\Installations\KEVIN-PC.eml	Quarantined Win32.Worm.Nimda.R (B)
C:\ProgramData\Electronic Arts\EA Core\KEVIN-PC.eml	Quarantined Win32.Worm.Nimda.R (B)
C:\ProgramData\EA Logs\KEVIN-PC.eml	Quarantined Win32.Worm.Nimda.R (B)
C:\ProgramData\FLEXnet\KEVIN-PC.eml	Quarantined Win32.Worm.Nimda.R (B)
C:\ProgramData\Electronic Arts\EA Services\KEVIN-PC.eml	Quarantined Win32.Worm.Nimda.R (B)
C:\ProgramData\EA Core\KEVIN-PC.eml	Quarantined Win32.Worm.Nimda.R (B)
C:\ProgramData\E1864A66-75E3-486a-BD95-D1B7D99A84A7\x64\KEVIN-PC.eml	Quarantined Win32.Worm.Nimda.R (B)
C:\ProgramData\EA Core\cache\KEVIN-PC.eml	Quarantined Win32.Worm.Nimda.R (B)
C:\ProgramData\E1864A66-75E3-486a-BD95-D1B7D99A84A7\KEVIN-PC.eml	Quarantined Win32.Worm.Nimda.R (B)
C:\ProgramData\Dell\QuickSet\KEVIN-PC.eml	Quarantined Win32.Worm.Nimda.R (B)
C:\ProgramData\Dell\KEVIN-PC.eml	Quarantined Win32.Worm.Nimda.R (B)
C:\ProgramData\DassaultSystemes\Kevin\KEVIN-PC.eml	Quarantined Win32.Worm.Nimda.R (B)
C:\ProgramData\DAEMON Tools Lite\KEVIN-PC.eml	Quarantined Win32.Worm.Nimda.R (B)
C:\ProgramData\DassaultSystemes\KEVIN-PC.eml	Quarantined Win32.Worm.Nimda.R (B)
C:\ProgramData\Creative\Photo Manager\KEVIN-PC.eml	Quarantined Win32.Worm.Nimda.R (B)
C:\ProgramData\CanonBJ\KEVIN-PC.eml	Quarantined Win32.Worm.Nimda.R (B)
C:\ProgramData\Common Files\KEVIN-PC.eml	Quarantined Win32.Worm.Nimda.R (B)
C:\ProgramData\Creative\KEVIN-PC.eml	Quarantined Win32.Worm.Nimda.R (B)
C:\ProgramData\COSMOS Applications\Flow Simulation 2015\KEVIN-PC.eml	Quarantined Win32.Worm.Nimda.R (B)
C:\ProgramData\COSMOS Applications\KEVIN-PC.eml	Quarantined Win32.Worm.Nimda.R (B)
C:\ProgramData\CanonBJ\IJPrinter\KEVIN-PC.eml	Quarantined Win32.Worm.Nimda.R (B)
C:\ProgramData\Blizzard Entertainment\StarCraft II\KEVIN-PC.eml	Quarantined Win32.Worm.Nimda.R (B)
C:\ProgramData\Blizzard Entertainment\Battle.net\KEVIN-PC.eml	Quarantined Win32.Worm.Nimda.R (B)
C:\ProgramData\Blizzard Entertainment\KEVIN-PC.eml	Quarantined Win32.Worm.Nimda.R (B)
C:\ProgramData\Battle.net\Setup\KEVIN-PC.eml	Quarantined Win32.Worm.Nimda.R (B)
C:\ProgramData\Battle.net\KEVIN-PC.eml	Quarantined Win32.Worm.Nimda.R (B)
C:\ProgramData\Battle.net\Client\KEVIN-PC.eml	Quarantined Win32.Worm.Nimda.R (B)
C:\ProgramData\Battle.net\Agent\KEVIN-PC.eml	Quarantined Win32.Worm.Nimda.R (B)
C:\ProgramData\ATI\KEVIN-PC.eml	Quarantined Win32.Worm.Nimda.R (B)
C:\ProgramData\ATI\ACE\KEVIN-PC.eml	Quarantined Win32.Worm.Nimda.R (B)
C:\ProgramData\Apple Computer\iTunes\KEVIN-PC.eml	Quarantined Win32.Worm.Nimda.R (B)
C:\ProgramData\Apple\Apple Application Support\KEVIN-PC.eml	Quarantined Win32.Worm.Nimda.R (B)
C:\ProgramData\Apple Computer\KEVIN-PC.eml	Quarantined Win32.Worm.Nimda.R (B)
C:\ProgramData\Apple\Installer Cache\KEVIN-PC.eml	Quarantined Win32.Worm.Nimda.R (B)
C:\ProgramData\Apple\KEVIN-PC.eml	Quarantined Win32.Worm.Nimda.R (B)
C:\ProgramData\Apple Computer\Installer Cache\KEVIN-PC.eml	Quarantined Win32.Worm.Nimda.R (B)
C:\ProgramData\Andy_44_Online\SetupFiles\KEVIN-PC.eml	Quarantined Win32.Worm.Nimda.R (B)
C:\ProgramData\Andy\KEVIN-PC.eml	Quarantined Win32.Worm.Nimda.R (B)
C:\ProgramData\Andy_44_Online\KEVIN-PC.eml	Quarantined Win32.Worm.Nimda.R (B)
C:\ProgramData\Andy_44_Online\keymapper\KEVIN-PC.eml	Quarantined Win32.Worm.Nimda.R (B)
C:\ProgramData\Adobe\KEVIN-PC.eml	Quarantined Win32.Worm.Nimda.R (B)
C:\ProgramData\Aeria Games\Ignite\KEVIN-PC.eml	Quarantined Win32.Worm.Nimda.R (B)
C:\ProgramData\Aeria Games\KEVIN-PC.eml	Quarantined Win32.Worm.Nimda.R (B)
C:\ProgramData\Adobe\Updater\KEVIN-PC.eml	Quarantined Win32.Worm.Nimda.R (B)
C:\ProgramData\Adobe\SLStore\KEVIN-PC.eml	Quarantined Win32.Worm.Nimda.R (B)
C:\ProgramData\Adobe\Extension Manager CC\KEVIN-PC.eml	Quarantined Win32.Worm.Nimda.R (B)
C:\ProgramData\Adobe\Setup\KEVIN-PC.eml	Quarantined Win32.Worm.Nimda.R (B)
C:\ProgramData\Adobe\Acrobat\KEVIN-PC.eml	Quarantined Win32.Worm.Nimda.R (B)
C:\ProgramData\Adobe\CameraRaw\KEVIN-PC.eml	Quarantined Win32.Worm.Nimda.R (B)
C:\ProgramData\Adobe\ARM\KEVIN-PC.eml	Quarantined Win32.Worm.Nimda.R (B)
C:\ProgramData\Adobe\AAMUpdater\KEVIN-PC.eml	Quarantined Win32.Worm.Nimda.R (B)
C:\Program Files\WinRAR\readme.eml	Quarantined Win32.Worm.Nimda.R (B)
C:\Program Files (x86)\Steam\ThirdPartyLegalNotices.html	Quarantined Win32.Worm.Nimda.O (B)
C:\Program Files (x86)\Steam\readme.eml	Quarantined Win32.Worm.Nimda.R (B)
C:\Program Files (x86)\QPST\readme.eml	Quarantined Win32.Worm.Nimda.R (B)
C:\Program Files (x86)\Origin\readme.eml	Quarantined Win32.Worm.Nimda.R (B)
C:\Program Files (x86)\Origin\logreader.html	Quarantined Win32.Worm.Nimda.O (B)
C:\Program Files (x86)\Origin\3RDPARTYLICENSES_FR.HTML	Quarantined Win32.Worm.Nimda.O (B)
C:\Program Files (x86)\Origin\3RDPARTYLICENSES.HTML	Quarantined Win32.Worm.Nimda.O (B)
C:\$Recycle.Bin\S-1-5-21-2594220630-3603304000-901252706-1001\$RZZS1Q2.eml	Quarantined Win32.Worm.Nimda.R (B)
Key: HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432NODE\{12DA0E6F-5543-440C-BAA2-28BF01070AFA}	Quarantined Application.AdFix (A)
Key: HKEY_USERS\S-1-5-18\SOFTWARE\APPDATALOW\{12DA0E6F-5543-440C-BAA2-28BF01070AFA}	Quarantined Application.Bundle (A)
Key: HKEY_USERS\S-1-5-21-2594220630-3603304000-901252706-1001\SOFTWARE\APPDATALOW\{12DA0E6F-5543-440C-BAA2-28BF01070AFA}	Quarantined Application.Bundle (A)

Quarantined	505


Edited by eggylisk, 24 July 2015 - 04:17 AM.


#4 Sintharius

Sintharius

    Bleepin' Sniper


  • Members
  • 5,639 posts
  • OFFLINE
  •  
  • Gender:Female
  • Location:The Netherlands
  • Local time:10:59 AM

Posted 24 July 2015 - 04:27 AM

Hello,

I must give you bad news.

Nimda (as you have seen in the EEK log) is a worm with file infector characteristics.

We don't try to clean machines infected with file infectors, as doing that is useless due to how the file infector works.

As this worm compromises all machines that it infect, there is no telling whether the machine will be trustworthy again. The best solution is to reformat the drive completely and reinstall.

Let me know how you want to proceed.

Regards,
Alex

#5 eggylisk

eggylisk
  • Topic Starter

  • Members
  • 8 posts
  • OFFLINE
  •  
  • Local time:02:59 AM

Posted 24 July 2015 - 04:36 AM

bleep...I have a bunch of really important files that I have saved in my laptop. How should I go about backing it up without the risk of transferring over the files, if at all possible?

 

Also, what programs do you suggest I start using to prevent something like this from happening in the future?


Edited by eggylisk, 24 July 2015 - 04:37 AM.


#6 Sintharius

Sintharius

    Bleepin' Sniper


  • Members
  • 5,639 posts
  • OFFLINE
  •  
  • Gender:Female
  • Location:The Netherlands
  • Local time:10:59 AM

Posted 24 July 2015 - 04:44 AM

You can use a live Linux CD to boot up the machine and then copy the files over to another media. Popular distros for this purpose are Linux Puppy and Mint - you can visit the Linux & Unix section of BC to get more information.

As a precaution, do not back up any executables (.exe, .com, .bat, .scr, .pif and so on) and html files, and careful to not grab any of those .eml files by accident - they contain the worm and will reinfect your machine.

If it is possible, keep the infected machine OFF until you can retrieve the data.

If you use an email client (i.e. Mozilla Thunderbird), inform your email contacts about the infection - Nimda can harvest your emails and send mails containing the dropper to people in your mailing list.

Do you know how you are infected in the first place? Nimda is a very old infection dating back to 2001.

Alex

#7 eggylisk

eggylisk
  • Topic Starter

  • Members
  • 8 posts
  • OFFLINE
  •  
  • Local time:02:59 AM

Posted 24 July 2015 - 04:53 AM

I'll give linux puppy a shot, thanks!

The majority of the files I need are pictures, videos and solidworks files, ms office docs

 

I just use yahoo as my main email, should I be worried? I'll be changing passwords for sure though

 

I've got no clue as to how I got infected, the fact that it's such an ancient worm is a bit depressing too

 

I have a recovery partition in my HDD, is that safe to use?

What programs should I start using from now on to prevent things like this from happening in the future?



#8 Sintharius

Sintharius

    Bleepin' Sniper


  • Members
  • 5,639 posts
  • OFFLINE
  •  
  • Gender:Female
  • Location:The Netherlands
  • Local time:10:59 AM

Posted 24 July 2015 - 04:59 AM

If you use Yahoo for your mailbox then you should be fine. Just change passwords as a precaution.

Nimda has 5 main methods of spreading, four of which are still viable today: Via infected email attachments (usually named README.exe), via compromised websites, launching an .exe file infected with the worm, and from network shares infected with the worm. The last one is an exploit of a really old vulnerability in an obsolete web component.

If you are interested, you can read up on F-Secure's writeup here.

The recovery partition should be ok to use. Just remember to get your important data off before doing a factory reset.

All modern antivirus software should be able to stop an infection like this. Did you have one prior to this?

#9 eggylisk

eggylisk
  • Topic Starter

  • Members
  • 8 posts
  • OFFLINE
  •  
  • Local time:02:59 AM

Posted 24 July 2015 - 05:04 AM

It might have been from a .rar file i tried to extract. The first thing that was off was I got the win32 error when I tried extracting it

The only one I had was malwarebytes



#10 Sintharius

Sintharius

    Bleepin' Sniper


  • Members
  • 5,639 posts
  • OFFLINE
  •  
  • Gender:Female
  • Location:The Netherlands
  • Local time:10:59 AM

Posted 24 July 2015 - 05:09 AM

Hi there,

That explains the infection - Malwarebytes does not target threats that traditional AVs detect (worms, file infectors), and thus leaving your computer wide open to the worm.

You will need to get an antivirus to run along with Malwarebytes.

I recommend Avast!, BitDefender Free Edition or Microsoft Security Essentials for free non-commercial everyday use.

If you wish to use a paid-for solution, I recommend Emsisoft Anti-Malware, ESET NOD32 or Kaspersky Anti-Virus.

Let me know what do you intend to do.

Alex

#11 eggylisk

eggylisk
  • Topic Starter

  • Members
  • 8 posts
  • OFFLINE
  •  
  • Local time:02:59 AM

Posted 24 July 2015 - 05:18 AM

Ill give the free ones a shot for now, and if anything i might purchase emsisoft. $40 a year isn't a bad price to pay if I can avoid stuff like this from happening. Is the firewall from the internet security package one worth it? From my previous experience, firewalls have given me more headache than none.

I'm currently trying to figure out how to setup linux puppy and then I'll start the back up.

Thanks once again for all your time and help!


If I have any more questions or issues, would it be okay to post in this thread or should I pm you about it? If neither is okay, that's fine too


Edited by eggylisk, 24 July 2015 - 05:21 AM.


#12 Sintharius

Sintharius

    Bleepin' Sniper


  • Members
  • 5,639 posts
  • OFFLINE
  •  
  • Gender:Female
  • Location:The Netherlands
  • Local time:10:59 AM

Posted 24 July 2015 - 05:39 AM

Hi there,

Just to let you know, Emsisoft has a loyal customer reward program. You get a 25% off of renewal price after the first year, and an additional 5% for each year after that to a maximum of 60%.

Emsisoft Anti-Malware and the Windows Firewall should be fine for home users.

If you have any other questions, feel free to post in here - assistance via pms is not allowed.

Alex

#13 eggylisk

eggylisk
  • Topic Starter

  • Members
  • 8 posts
  • OFFLINE
  •  
  • Local time:02:59 AM

Posted 24 July 2015 - 05:55 AM

Sounds good. Thanks you very much for all your help!

#14 Sintharius

Sintharius

    Bleepin' Sniper


  • Members
  • 5,639 posts
  • OFFLINE
  •  
  • Gender:Female
  • Location:The Netherlands
  • Local time:10:59 AM

Posted 24 July 2015 - 06:02 AM

You are welcome.

If you need help on creating a live Linux disk, then here is a tutorial of how to install Lucid Puppy on a flash drive using Universal USB Installer for Windows. Lucid Puppy is incredibly light (128MB) so you can use it to speed up your recovery process.

#15 eggylisk

eggylisk
  • Topic Starter

  • Members
  • 8 posts
  • OFFLINE
  •  
  • Local time:02:59 AM

Posted 24 July 2015 - 06:29 AM

Thanks. Is it possible to do a scan of just the back up folder I'm putting together just incase I let something slip?




0 user(s) are reading this topic

0 members, 0 guests, 0 anonymous users