This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

[Closed] Help! Cannot Open Microsoft Word Files!

37 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

file from blacklight: 09/28/07 20:56:02 [Info]: BlackLight Engine 1.0.64 initialized 09/28/07 20:56:02 [Info]: OS: 5.1 build 2600 (Service Pack 1) 09/28/07 20:56:03 [Note]: 7019 4 09/28/07 20:56:03 [Note]: 7005 0 09/28/07 20:57:16 [Note]: 7006 0 09/28/07 20:57:16 [Note]: 7011 1160 09/28/07 20:57:16 [Note]: 7026 0 09/28/07 20:57:16 [Note]: 7026 0 09/28/07 20:57:21 [Note]: FSRAW library version 1.7.1022 09/28/07 20:59:47 [Note]: 7007 0
i'm not sure wat u meant by the panda scanner thing, were u referring to the panda security i have in my computer? i tried to change my firewall to panda but norton refuses to budge and caused a lot of problems…do you know of any reason why?

and really sorry for the late reply. thanks for helping! my computer's working much better now. =)

HJT file:

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 9:00:46 PM, on 9/28/2007
Platform: Windows XP SP1 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\Explorer.EXE
c:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
c:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\System32\gearsec.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
c:\Program Files\Norton AntiVirus\navapsvc.exe
C:\WINDOWS\System32\svchost.exe
C:\windows\system\hpsysdrv.exe
C:\WINDOWS\System32\hkcmd.exe
C:\HP\KBD\KBD.EXE
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\Common Files\Symantec Shared\ccApp.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\WINDOWS\ALCXMNTR.EXE
C:\Program Files\HP\HP Software Update\HPWuSchd.exe
C:\Program Files\HP\hpcoretech\hpcmpmgr.exe
C:\Program Files\Lavasoft\Ad-Aware 2007\AAWTray.exe
C:\Program Files\Java\jre1.6.0_02\bin\jusched.exe
C:\WINDOWS\System32\ctfmon.exe
C:\Program Files\Compaq Connections\1940576\Program\BackWeb-1940576.exe
C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
C:\Program Files\HP\hpcoretech\comp\hptskmgr.exe
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://ie.redirect.hp.com/svs/rdr?TYPE=3&a…&pf=desktop
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://ie.redirect.hp.com/svs/rdr?TYPE=3&a…&pf=desktop
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://ie.redirect.hp.com/svs/rdr?TYPE=3&a…&pf=desktop
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = localhost
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll
O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_02\bin\ssv.dll
O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
O2 - BHO: NAV Helper - {BDF3E430-B101-42AD-A544-FADC6B084872} - c:\Program Files\Norton AntiVirus\NavShExt.dll
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx
O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - c:\Program Files\Norton AntiVirus\NavShExt.dll
O4 - HKLM\..\Run: [IMJPMIG8.1] "C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE" /Spoil /RemAdvDef /Migration32
O4 - HKLM\..\Run: [MSPY2002] C:\WINDOWS\System32\IME\PINTLGNT\ImScInst.exe /SYNC
O4 - HKLM\..\Run: [PHIME2002ASync] C:\WINDOWS\System32\IME\TINTLGNT\TINTSETP.EXE /SYNC
O4 - HKLM\..\Run: [PHIME2002A] C:\WINDOWS\System32\IME\TINTLGNT\TINTSETP.EXE /IMEName
O4 - HKLM\..\Run: [hpsysdrv] c:\windows\system\hpsysdrv.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\System32\hkcmd.exe
O4 - HKLM\..\Run: [KBD] C:\HP\KBD\KBD.EXE
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [iTunesHelper] C:\Program Files\iTunes\iTunesHelper.exe
O4 - HKLM\..\Run: [Recguard] C:\WINDOWS\SMINST\RECGUARD.EXE
O4 - HKLM\..\Run: [ccApp] "c:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [PS2] C:\WINDOWS\system32\ps2.exe
O4 - HKLM\..\Run: [AlcxMonitor] ALCXMNTR.EXE
O4 - HKLM\..\Run: [HP Software Update] "C:\Program Files\HP\HP Software Update\HPWuSchd.exe"
O4 - HKLM\..\Run: [HP Component Manager] "C:\Program Files\HP\hpcoretech\hpcmpmgr.exe"
O4 - HKLM\..\Run: [AAWTray] C:\Program Files\Lavasoft\Ad-Aware 2007\AAWTray.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_02\bin\jusched.exe"
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\System32\ctfmon.exe
O4 - Global Startup: Compaq Connections.lnk = C:\Program Files\Compaq Connections\1940576\Program\BackWeb-1940576.exe
O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MI1933~1\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_02\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_02\bin\ssv.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MI1933~1\OFFICE11\REFIEBAR.DLL
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O16 - DPF: {0EB0E74A-2A76-4AB3-A7FB-9BD8C29F7F75} (CKAVWebScan Object) - http://www.kaspersky.com/kos/eng/partner/d…can_unicode.cab
O23 - Service: Ad-Aware 2007 Service (aawservice) - Lavasoft AB - C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - c:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
O23 - Service: Symantec Password Validation (ccPwdSvc) - Symantec Corporation - c:\Program Files\Common Files\Symantec Shared\ccPwdSvc.exe
O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - c:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
O23 - Service: Gear Security Service (GEARSecurity) - GEAR Software - C:\WINDOWS\System32\gearsec.exe
O23 - Service: iPod Service (iPodService) - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: Norton AntiVirus Auto Protect Service (navapsvc) - Symantec Corporation - c:\Program Files\Norton AntiVirus\navapsvc.exe
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\System32\HPZipm12.exe
O23 - Service: SAVScan - Symantec Corporation - c:\Program Files\Norton AntiVirus\SAVScan.exe

–
End of file - 6502 bytes
Glad to hear things are running better.
I will feel better about telling you your machine is clean if we can get 1 online scan done.


i tried to change my firewall to panda

No need to change your firewall. We just want an online scan with an anti virus program.

We will try try another one.


______________________________
HJT
Run hijackthis and choose scan only and place a check by the following lines if present.
Close all other windows and browsers except HJT before clicking on Fix Checked


O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)

O4 - HKLM\..\Run: [AlcxMonitor] ALCXMNTR.EXE



________________________________________
Open notepad and copy/paste the text in the quotebox below into it:

File::
C:\WINDOWS\system32\ftmgpd.dll



Save this as CFScript.txt, in the same location as ComboFix.exe


[external image: Posted Image]

Refering to the picture above, drag CFScript into ComboFix.exe

When finished, it shall produce a log for you at C:ComboFix.txt which I will need in your next reply.

__________________________________

Please run the CCleaner program NOW!


If you use either the Firefox or Mozilla browsers, the box to uncheck for Cookies is on the Applications tab, under Firefox/Mozilla.
  • Set Cookie Retention.
    Click on the Options block on the left, then choose Cookies.
    Under the Cookies to delete pane, highlight any cookies you would like to retain permanently (those companies or sites with which you regularly visit or do business), and click the right arrow > to move them to the Cookies to keep pane.
  • Reset Temp File Removal for Regular Use.
    Click on the Options block on the left. Select the Advanced button.
    Check "Only delete files in Windows Temp folders older than 48 hours".


    Now run the program and click on Run Cleaner
    ( Do not use the Issues block to clean anything with this program. It is for experts only and it is risky).

_________________________________
Please do an online scan with Kaspersky Online Scanner
Click on Kaspersky Online Scanner
You will be promted to install an ActiveX component from Kaspersky, Click Yes.
The program will launch and then start to download the latest definition files.
Once the scanner is installed and the definitions downloaded, click Next.
Now click on Scan Settings
In the scan settings make sure that the following are selected:
Scan using the following Anti-Virus database:

Extended (If available otherwise Standard)
Scan Options:
Scan Archives
Scan Mail Bases
Click OK

Now under select a target to scan select My Computer



The scan will take a while so be patient and let it run. Once the scan is complete it will display if your system has been infected.

Now click on the Save as Text button:

Save the file to your desktop.

Copy and paste that information in your next post.

____________________________________________________



_____________________________
In your next reply I would like to see:
  • A new HJT log
  • The report from Combofix
  • The report from Kasperskys.
ComboFix 07-09-17.2 - "Owner" 2007-10-02 19:20:50.5 - NTFSx86
Microsoft Windows XP Home Edition 5.1.2600.1.1252.1.1033.18.61 [GMT 8:00]
* Created a new restore point

FILE::
C:\WINDOWS\system32\ftmgpd.dll
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

C:\WINDOWS\system32\ftmgpd.dll

.
((((((((((((((((((((((((( Files Created from 2007-09-02 to 2007-10-02 )))))))))))))))))))))))))))))))
.

2007-09-30 17:53 208,896 –a—— C:\WINDOWS\system32\wmpns.dll
2007-09-27 23:28 d——– C:\DOCUME~1\Owner\APPLIC~1\Apple Computer
2007-09-23 17:49 d——– C:\DOCUME~1\Owner\Contacts
2007-09-23 17:48 d—-c— C:\WINDOWS\system32\DRVSTORE
2007-09-23 17:48 d——– C:\Program Files\MSN Messenger
2007-09-20 20:12 d——– C:\Program Files\Microsoft ActiveSync
2007-09-20 19:55 d——– C:\DOCUME~1\Owner\APPLIC~1\MSN6
2007-09-20 19:55 d——– C:\DOCUME~1\ALLUSE~1\APPLIC~1\MSN6
2007-09-18 21:44 d——– C:\WINDOWS\system32\Kaspersky Lab
2007-09-18 21:44 d——– C:\DOCUME~1\ALLUSE~1\APPLIC~1\Kaspersky Lab
2007-09-18 21:39 d——– C:\Program Files\CCleaner
2007-09-17 23:31 51,200 –a—— C:\WINDOWS\NirCmd.exe
2007-09-09 22:34 76,560 –a—— C:\WINDOWS\system32\drivers\tmcomm.sys
2007-09-09 20:54 d——– C:\DOCUME~1\ALLUSE~1\APPLIC~1\WinZip
2007-09-09 20:01 d——– C:\Program Files\Common Files\Panda Software
2007-09-09 19:24 d——– C:\DOCUME~1\Owner\.housecall6.6
2007-09-09 18:18 d——– C:\WINDOWS\DED53B0BB67C4244AE6AD6FD3C28D1EF.TMP
2007-09-09 15:33 d——– C:\Program Files\Lavasoft
2007-09-09 15:33 d——– C:\DOCUME~1\ALLUSE~1\APPLIC~1\Lavasoft
2007-09-09 15:31 d——– C:\Program Files\Common Files\Wise Installation Wizard
2007-09-09 14:57 d——– C:\DOCUME~1\ALLUSE~1\APPLIC~1\Spybot - Search & Destroy
2007-09-09 14:51 d——– C:\Program Files\Trend Micro
2007-09-09 13:54 d—s—- C:\DOCUME~1\Owner\UserData
2007-09-08 22:39 182,880 –a–c— C:\WINDOWS\system32\dllcache\iuengine.dll
2007-09-08 22:39 182,880 –a—— C:\WINDOWS\system32\iuengine.dll
2007-09-08 22:19 17,920 –a—— C:\WINDOWS\system32\mdimon.dll
2007-09-08 22:16 d——– C:\Program Files\Common Files\L&H
2007-09-08 22:14 d——– C:\WINDOWS\SHELLNEW
2007-09-08 22:13 d——– C:\Program Files\Microsoft.NET
2007-09-08 22:11 dr-h—– C:\MSOCache
2007-09-08 22:08 51,056 -ra—— C:\WINDOWS\system32\drivers\hpzid412.sys
2007-09-08 22:08 21,760 –a–c— C:\WINDOWS\system32\dllcache\usbstor.sys
2007-09-08 22:08 16,496 -ra—— C:\WINDOWS\system32\drivers\HPZipr12.sys
2007-09-08 22:07 28,160 –a–c— C:\WINDOWS\system32\dllcache\usbccgp.sys
2007-09-08 22:07 28,160 –a—— C:\WINDOWS\system32\drivers\usbccgp.sys
2007-09-08 22:07 24,960 –a–c— C:\WINDOWS\system32\dllcache\usbprint.sys
2007-09-08 22:07 24,960 –a—— C:\WINDOWS\system32\drivers\usbprint.sys
2007-09-08 22:07 21,488 -ra—— C:\WINDOWS\system32\drivers\HPZius12.sys
2007-09-08 22:07 14,208 –a–c— C:\WINDOWS\system32\dllcache\usbscan.sys
2007-09-08 22:07 14,208 –a—— C:\WINDOWS\system32\drivers\usbscan.sys
2007-09-08 22:03 626,960 -ra—— C:\WINDOWS\system32\hpvaut32.dll
2007-09-08 22:03 487,424 -ra—— C:\WINDOWS\system32\hpvcp70.dll
2007-09-08 22:03 44,544 -ra—— C:\WINDOWS\system32\MSXML4a.dll
2007-09-08 22:03 344,064 -ra—— C:\WINDOWS\system32\hpvcr70.dll
2007-09-08 22:02 d——– C:\Program Files\Common Files\Hewlett-Packard
2007-09-08 21:59 43,488 –a—— C:\WINDOWS\system32\drivers\AFS2K.SYS
2007-09-08 21:59 d——– C:\Program Files\Common Files\HP
2007-09-08 21:55 34,383 ——— C:\WINDOWS\hpomdl03.dat
2007-09-08 21:55 28,886 –a—— C:\WINDOWS\hpoins03.dat
2007-09-08 21:55 d——– C:\Program Files\HP
2007-09-03 08:39 249 –a—— C:\WINDOWS\system\hpsysdrv.dat
2007-09-03 08:38 d——– C:\WINDOWS\I386
2007-09-03 08:33 dr——- C:\DOCUME~1\ALLUSE~1\Documents
2007-09-02 17:59 155,648 –a—— C:\WINDOWS\system32\igfxres.dll
2007-09-02 17:57 204,800 –a—— C:\WINDOWS\system32\IVIresizeW7.dll
2007-09-02 17:57 200,704 –a—— C:\WINDOWS\system32\IVIresizeA6.dll
2007-09-02 17:57 20,480 –a—— C:\WINDOWS\system32\IVIresize.dll
2007-09-02 17:57 192,512 –a—— C:\WINDOWS\system32\IVIresizeP6.dll
2007-09-02 17:57 192,512 –a—— C:\WINDOWS\system32\IVIresizeM6.dll
2007-09-02 17:57 188,416 –a—— C:\WINDOWS\system32\IVIresizePX.dll
2007-09-02 17:57 10,368 ——— C:\WINDOWS\system32\drivers\pfc.sys
2007-09-02 17:57 d——– C:\WINDOWS\uninstall
2007-09-02 17:57 d——– C:\WINDOWS\system32\config\SYSTEM~1\WINDOWS
2007-09-02 17:57 d——– C:\WINDOWS\system32\config\SYSTEM~1\APPLIC~1\Symantec
2007-09-02 17:57 d——– C:\WINDOWS\system32\config\SYSTEM~1\APPLIC~1\SampleView
2007-09-02 17:57 d——– C:\WINDOWS\system32\config\SYSTEM~1\APPLIC~1\Real
2007-09-02 17:57 d——– C:\863d765bceb76777372b95ff1d0a40
2007-09-02 17:57 d——– C:\54f4ff25124b3b9e53a7416b03
2007-09-02 17:56 57,856 –a—— C:\WINDOWS\system32\drivers\drmk.sys
2007-09-02 17:56 134,272 –a—— C:\WINDOWS\system32\drivers\portcls.sys
2007-09-02 17:56 d——– C:\Program Files\InterVideo
2007-09-02 17:54 51,072 –a—— C:\WINDOWS\system32\drivers\i8042prt.sys
2007-09-02 17:54 23,424 –a—— C:\WINDOWS\system32\drivers\kbdclass.sys
2007-09-02 17:54 d——– C:\DOCUME~1\DEFAUL~1\WINDOWS

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2007-09-27 23:12 ——— d——– C:\DOCUME~1\Owner\APPLIC~1\Real
2007-09-20 20:11 ——— d——– C:\Program Files\Microsoft Works
2007-09-09 21:34 ——— d——– C:\Program Files\QuickTime
2007-09-09 21:34 ——— d——– C:\Program Files\Presario PC Help
2007-09-09 21:34 ——— d——– C:\Program Files\PC-Doctor for Windows
2007-09-09 21:33 ——— d——– C:\Program Files\Norton AntiVirus
2007-09-09 21:32 ——— d——– C:\Program Files\iTunes
2007-09-09 21:28 ——— d——– C:\Program Files\Easy Internet signup
2007-09-09 20:02 ——— d——– C:\Program Files\Common Files\InstallShield
2007-09-02 17:59 3674 -rahs—- C:\WINDOWS\system32\drivers\HP_P9902CV-AB4 SR1120CF SE610_YC_Pres_QTHT424_E43SEhwRET1_4_IGamila Giovani Neon series_SMICRO-STAR INTERNATIONAL CO., LTD_V030_B3.10_T040415_WXH1_L409_M248_J80_7Intel_8Pentium 4_92.8_111063044_N10EC8139_P_Z_K_A808624C5.MRK
2007-09-02 17:56 ——— d–h—– C:\Program Files\InstallShield Installation Information
2007-08-07 13:58 8320 –a—— C:\WINDOWS\system32\drivers\AWRTRD.sys
2007-08-07 13:56 9344 –a—— C:\WINDOWS\system32\drivers\NSDriver.sys
.

((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.

*Note* empty entries & legit default entries are not shown

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"IMJPMIG8.1"="C:\WINDOWS\IME\imjp8_1\IMJPMIG.exe" [2003-08-17 06:57]
"MSPY2002"="C:\WINDOWS\System32\IME\PINTLGNT\ImScInst.exe" [2003-08-17 00:24]
"PHIME2002ASync"="C:\WINDOWS\System32\IME\TINTLGNT\TINTSETP.exe" [2003-08-17 00:25]
"PHIME2002A"="C:\WINDOWS\System32\IME\TINTLGNT\TINTSETP.exe" [2003-08-17 00:25]
"hpsysdrv"="c:\windows\system\hpsysdrv.exe" [1998-05-07 23:04]
"HotKeysCmds"="C:\WINDOWS\System32\hkcmd.exe" [2004-02-11 00:51]
"KBD"="C:\HP\KBD\KBD.EXE" [2003-02-12 02:02]
"TkBellExe"="C:\Program Files\Common Files\Real\Update_OB\realsched.exe" [2004-04-01 22:04]
"iTunesHelper"="C:\Program Files\iTunes\iTunesHelper.exe" [2004-01-17 02:16]
"Recguard"="C:\WINDOWS\SMINST\RECGUARD.EXE" [2003-11-03 23:50]
"ccApp"="c:\Program Files\Common Files\Symantec Shared\ccApp.exe" [2003-08-15 07:59]
"PS2"="C:\WINDOWS\system32\ps2.exe" [2003-09-13 02:13]
"HP Software Update"="C:\Program Files\HP\HP Software Update\HPWuSchd.exe" [2003-06-25 11:24]
"HP Component Manager"="C:\Program Files\HP\hpcoretech\hpcmpmgr.exe" [2003-06-26 18:50]
"AAWTray"="C:\Program Files\Lavasoft\Ad-Aware 2007\AAWTray.exe" [2007-08-08 15:53]
"SunJavaUpdateSched"="C:\Program Files\Java\jre1.6.0_02\bin\jusched.exe" [2007-07-12 04:00]

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="C:\WINDOWS\System32\ctfmon.exe" [2003-08-16 09:54]

C:\DOCUME~1\ALLUSE~1\STARTM~1\Programs\Startup\
Compaq Connections.lnk - C:\Program Files\Compaq Connections\1940576\Program\BackWeb-1940576.exe [2004-04-01 22:26:37]
HP Digital Imaging Monitor.lnk - C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe [2003-07-07 01:20:40]

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\explorer]
"NoInstrumentation"=1 (0x1)
"NoStartMenuSubFolders"=1 (0x1)
"NoFavoritesMenu"=1 (0x1)


.
Contents of the 'Scheduled Tasks' folder
"2007-09-08 14:13:19 C:\WINDOWS\Tasks\HP DArC Task #Hewlett-Packard#hp psc 1300 series#1189260524.job"
- C:\Program Files\HP\hpcoretech\comp\hpdarc.exe
"2007-09-15 02:31:28 C:\WINDOWS\Tasks\HP DArC Task #Hewlett-Packard#hp psc 1300 series#1189262568.job"
- C:\Program Files\HP\hpcoretech\comp\hpdarc.exe
"2007-09-09 06:03:02 C:\WINDOWS\Tasks\Norton AntiVirus - Scan my computer.job"
- c:\PROGRA~1\NORTON~1\Navw32.exe
"2007-09-09 06:03:02 C:\WINDOWS\Tasks\Symantec NetDetect.job"
- C:\Program Files\Symantec\LiveUpdate\NDETECT.EXE
"2007-09-15 02:27:55 C:\WINDOWS\Tasks\WebReg 20070915102754.job"
.
**************************************************************************

catchme 0.3.1061 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2007-10-02 19:25:07
Windows 5.1.2600 Service Pack 1 NTFS

scanning hidden processes …

scanning hidden autostart entries …

scanning hidden files …

scan completed successfully
hidden files: 0

**************************************************************************
.
Completion time: 2007-10-02 19:27:18 - machine was rebooted
C:\ComboFix-quarantined-files.txt … 2007-10-02 19:27
C:\ComboFix2.txt … 2007-09-28 20:49
C:\ComboFix3.txt … 2007-09-20 19:28
.
— E O F —
just curious, but as i watch videos online, my video tend to take longer and longer to load, and my comp also tends to run slower and slower the more videos i watch. i'm not sure if it's something to do with my cookies…would using CCleaner help in this case?
——————————————————————————- KASPERSKY ONLINE SCANNER REPORT Tuesday, October 02, 2007 9:06:21 PM Operating System: Microsoft Windows XP Home Edition, Service Pack 1 (Build 2600) Kaspersky Online Scanner version: 5.0.93.1 Kaspersky Anti-Virus database last update: 2/10/2007 Kaspersky Anti-Virus database records: 426267 ——————————————————————————- Scan Settings: Scan using the following antivirus database: extended Scan Archives: true Scan Mail Bases: true Scan Target - My Computer: C:\ D:\ E:\ Scan Statistics: Total number of scanned objects: 58204 Number of viruses found: 33 Number of infected objects: 618 Number of suspicious objects: 0 Duration of the scan process: 01:17:02 Infected Object Name / Virus Name / Last Action C:\Documents and Settings\All Users\Application Data\Symantec\Common Client\settings.dat Object is locked skipped C:\Documents and Settings\LocalService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat Object is locked skipped C:\Documents and Settings\LocalService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped C:\Documents and Settings\LocalService\Local Settings\temp\Cookies\index.dat Object is locked skipped C:\Documents and Settings\LocalService\Local Settings\temp\History\History.IE5\index.dat Object is locked skipped C:\Documents and Settings\LocalService\Local Settings\temp\Temporary Internet Files\Content.IE5\index.dat Object is locked skipped C:\Documents and Settings\LocalService\NTUSER.DAT Object is locked skipped C:\Documents and Settings\LocalService\ntuser.dat.LOG Object is locked skipped C:\Documents and Settings\NetworkService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat Object is locked skipped C:\Documents and Settings\NetworkService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped C:\Documents and Settings\NetworkService\NTUSER.DAT Object is locked skipped C:\Documents and Settings\NetworkService\ntuser.dat.LOG Object is locked skipped C:\Documents and Settings\Owner\.housecall6.6\Quarantine\17[1].exe.bac_a02396 Infected: Trojan-PSW.Win32.OnLineGames.bwr skipped C:\Documents and Settings\Owner\.housecall6.6\Quarantine\4[1].exe.bac_a02396 Infected: Trojan-PSW.Win32.OnLineGames.cfq skipped C:\Documents and Settings\Owner\.housecall6.6\Quarantine\7[1].exe.bac_a02396 Infected: Trojan-PSW.Win32.OnLineGames.bgr skipped C:\Documents and Settings\Owner\.housecall6.6\Quarantine\A0000044.exe.bac_a00940 Infected: Virus.Win32.AutoRun.ao skipped C:\Documents and Settings\Owner\.housecall6.6\Quarantine\A0000426.exe.bac_a00940 Infected: Virus.Win32.AutoRun.ao skipped C:\Documents and Settings\Owner\.housecall6.6\Quarantine\A0000442.exe.bac_a00940 Infected: Virus.Win32.AutoRun.ao skipped C:\Documents and Settings\Owner\.housecall6.6\Quarantine\A0000524.exe.bac_a00940 Infected: Virus.Win32.AutoRun.ao skipped C:\Documents and Settings\Owner\.housecall6.6\Quarantine\A0000531.exe.bac_a00940 Infected: Virus.Win32.AutoRun.ao skipped C:\Documents and Settings\Owner\.housecall6.6\Quarantine\A0000544.exe.bac_a00940 Infected: Worm.Win32.Viking.lz skipped C:\Documents and Settings\Owner\.housecall6.6\Quarantine\A0000545.exe.bac_a00940 Infected: Worm.Win32.Viking.lz skipped C:\Documents and Settings\Owner\.housecall6.6\Quarantine\A0001059.pif.bac_a02396 Infected: Worm.Win32.QQPass.m skipped C:\Documents and Settings\Owner\.housecall6.6\Quarantine\App00153.exe.bac_a00940 Infected: Worm.Win32.Viking.lz skipped C:\Documents and Settings\Owner\.housecall6.6\Quarantine\App03902.exe.bac_a00940 Infected: Worm.Win32.Viking.lz skipped C:\Documents and Settings\Owner\.housecall6.6\Quarantine\App04827.exe.bac_a00940 Infected: Worm.Win32.Viking.lz skipped C:\Documents and Settings\Owner\.housecall6.6\Quarantine\App05436.exe.bac_a00940 Infected: Worm.Win32.Viking.lz skipped C:\Documents and Settings\Owner\.housecall6.6\Quarantine\App06334.exe.bac_a00940 Infected: Worm.Win32.Viking.lz skipped C:\Documents and Settings\Owner\.housecall6.6\Quarantine\App09961.exe.bac_a00940 Infected: Worm.Win32.Viking.lz skipped C:\Documents and Settings\Owner\.housecall6.6\Quarantine\App11538.exe.bac_a00940 Infected: Worm.Win32.Viking.lz skipped C:\Documents and Settings\Owner\.housecall6.6\Quarantine\App16827.exe.bac_a00940 Infected: Worm.Win32.Viking.lz skipped C:\Documents and Settings\Owner\.housecall6.6\Quarantine\App18467.exe.bac_a00940 Infected: Worm.Win32.Viking.lz skipped C:\Documents and Settings\Owner\.housecall6.6\Quarantine\App19169.exe.bac_a00940 Infected: Worm.Win32.Viking.lz skipped C:\Documents and Settings\Owner\.housecall6.6\Quarantine\App19912.exe.bac_a00940 Infected: Worm.Win32.Viking.lz skipped C:\Documents and Settings\Owner\.housecall6.6\Quarantine\App21726.exe.bac_a00940 Infected: Worm.Win32.Viking.lz skipped C:\Documents and Settings\Owner\.housecall6.6\Quarantine\App30333.exe.bac_a00940 Infected: Worm.Win32.Viking.lz skipped C:\Documents and Settings\Owner\.housecall6.6\Quarantine\App31322.exe.bac_a00940 Infected: Worm.Win32.Viking.lz skipped C:\Documents and Settings\Owner\.housecall6.6\Quarantine\autochk.exe.bac_a00940 Infected: Worm.Win32.Viking.lz skipped C:\Documents and Settings\Owner\.housecall6.6\Quarantine\autofmt.exe.bac_a00940 Infected: Worm.Win32.Viking.lz skipped C:\Documents and Settings\Owner\.housecall6.6\Quarantine\cmdbcs.exe.bac_a02396 Infected: Trojan-PSW.Win32.OnLineGames.bgr skipped C:\Documents and Settings\Owner\.housecall6.6\Quarantine\DbgHlp32.exe.bac_a02396 Infected: Trojan-PSW.Win32.OnLineGames.bwr skipped C:\Documents and Settings\Owner\.housecall6.6\Quarantine\dbhelp.dll.bac_a02396 Infected: Trojan-PSW.Win32.Delf.aaw skipped C:\Documents and Settings\Owner\.housecall6.6\Quarantine\DWWIN.EXE.bac_a00940 Infected: Worm.Win32.Viking.lz skipped C:\Documents and Settings\Owner\.housecall6.6\Quarantine\EXPAND.EXE.bac_a00940 Infected: Worm.Win32.Viking.lz skipped C:\Documents and Settings\Owner\.housecall6.6\Quarantine\HP_EndBuild_for_BBoot_ALL_WW_0000-02.exe.bac_a00940 Infected: Worm.Win32.Viking.lz skipped C:\Documents and Settings\Owner\.housecall6.6\Quarantine\NETSETUP.EXE.bac_a00940 Infected: Worm.Win32.Viking.lz skipped C:\Documents and Settings\Owner\.housecall6.6\Quarantine\NTSD.EXE.bac_a00940 Infected: Worm.Win32.Viking.lz skipped C:\Documents and Settings\Owner\.housecall6.6\Quarantine\REGEDIT.EXE.bac_a00940 Infected: Worm.Win32.Viking.lz skipped C:\Documents and Settings\Owner\.housecall6.6\Quarantine\SYSPARSE.EXE.bac_a00940 Infected: Worm.Win32.Viking.lz skipped C:\Documents and Settings\Owner\.housecall6.6\Quarantine\TELNET.EXE.bac_a00940 Infected: Worm.Win32.Viking.lz skipped C:\Documents and Settings\Owner\.housecall6.6\Quarantine\upxdnd.exe.bac_a02396 Infected: Trojan-PSW.Win32.OnLineGames.cfq skipped C:\Documents and Settings\Owner\.housecall6.6\Quarantine\USBReader_ALL_WW_XP_0000-01.exe.bac_a00940 Infected: Worm.Win32.Viking.lz skipped C:\Documents and Settings\Owner\.housecall6.6\Quarantine\USETUP.EXE.bac_a00940 Infected: Worm.Win32.Viking.lz skipped C:\Documents and Settings\Owner\.housecall6.6\Quarantine\WindowsXP-KB828741-x86-ARA.EXE.bac_a00940 Infected: Worm.Win32.Viking.lz skipped C:\Documents and Settings\Owner\.housecall6.6\Quarantine\WindowsXP-KB828741-x86-CHS.EXE.bac_a00940 Infected: Worm.Win32.Viking.lz skipped C:\Documents and Settings\Owner\.housecall6.6\Quarantine\WindowsXP-KB828741-x86-CHT.EXE.bac_a00940 Infected: Worm.Win32.Viking.lz skipped C:\Documents and Settings\Owner\.housecall6.6\Quarantine\WindowsXP-KB828741-x86-DAN.EXE.bac_a00940 Infected: Worm.Win32.Viking.lz skipped C:\Documents and Settings\Owner\.housecall6.6\Quarantine\WindowsXP-KB828741-x86-DEU.EXE.bac_a00940 Infected: Worm.Win32.Viking.lz skipped C:\Documents and Settings\Owner\.housecall6.6\Quarantine\WindowsXP-KB828741-x86-ENU.EXE.bac_a00940 Infected: Worm.Win32.Viking.lz skipped C:\Documents and Settings\Owner\.housecall6.6\Quarantine\WindowsXP-KB828741-x86-ESN.EXE.bac_a00940 Infected: Worm.Win32.Viking.lz skipped C:\Documents and Settings\Owner\.housecall6.6\Quarantine\WindowsXP-KB828741-x86-FIN.EXE.bac_a00940 Infected: Worm.Win32.Viking.lz skipped C:\Documents and Settings\Owner\.housecall6.6\Quarantine\WindowsXP-KB828741-x86-FRA.EXE.bac_a00940 Infected: Worm.Win32.Viking.lz skipped C:\Documents and Settings\Owner\.housecall6.6\Quarantine\WindowsXP-KB828741-x86-ITA.EXE.bac_a00940 Infected: Worm.Win32.Viking.lz skipped C:\Documents and Settings\Owner\.housecall6.6\Quarantine\WindowsXP-KB828741-x86-JPN.EXE.bac_a00940 Infected: Worm.Win32.Viking.lz skipped C:\Documents and Settings\Owner\.housecall6.6\Quarantine\WindowsXP-KB828741-x86-KOR.EXE.bac_a00940 Infected: Worm.Win32.Viking.lz skipped C:\Documents and Settings\Owner\.housecall6.6\Quarantine\WindowsXP-KB828741-x86-NLD.EXE.bac_a00940 Infected: Worm.Win32.Viking.lz skipped C:\Documents and Settings\Owner\.housecall6.6\Quarantine\WindowsXP-KB828741-x86-NOR.EXE.bac_a00940 Infected: Worm.Win32.Viking.lz skipped C:\Documents and Settings\Owner\.housecall6.6\Quarantine\WindowsXP-KB828741-x86-PTG.EXE.bac_a00940 Infected: Worm.Win32.Viking.lz skipped C:\Documents and Settings\Owner\.housecall6.6\Quarantine\WindowsXP-KB828741-x86-RUS.EXE.bac_a00940 Infected: Worm.Win32.Viking.lz skipped C:\Documents and Settings\Owner\.housecall6.6\Quarantine\WindowsXP-KB828741-x86-SVE.EXE.bac_a00940 Infected: Worm.Win32.Viking.lz skipped C:\Documents and Settings\Owner\.housecall6.6\Quarantine\WindowsXP-KB828741-x86-TRK.EXE.bac_a00940 Infected: Worm.Win32.Viking.lz skipped C:\Documents and Settings\Owner\.housecall6.6\Quarantine\WindowsXP-KB835732-x86-ARA.EXE.bac_a00940 Infected: Worm.Win32.Viking.lz skipped C:\Documents and Settings\Owner\.housecall6.6\Quarantine\WindowsXP-KB835732-x86-CHS.EXE.bac_a00940 Infected: Worm.Win32.Viking.lz skipped C:\Documents and Settings\Owner\.housecall6.6\Quarantine\WindowsXP-KB835732-x86-CHT.EXE.bac_a00940 Infected: Worm.Win32.Viking.lz skipped C:\Documents and Settings\Owner\.housecall6.6\Quarantine\WindowsXP-KB835732-x86-DAN.EXE.bac_a00940 Infected: Worm.Win32.Viking.lz skipped C:\Documents and Settings\Owner\.housecall6.6\Quarantine\WindowsXP-KB835732-x86-DEU.EXE.bac_a00940 Infected: Worm.Win32.Viking.lz skipped C:\Documents and Settings\Owner\.housecall6.6\Quarantine\WindowsXP-KB835732-x86-ENU.EXE.bac_a00940 Infected: Worm.Win32.Viking.lz skipped C:\Documents and Settings\Owner\.housecall6.6\Quarantine\WindowsXP-KB835732-x86-ESN.EXE.bac_a00940 Infected: Worm.Win32.Viking.lz skipped C:\Documents and Settings\Owner\.housecall6.6\Quarantine\WindowsXP-KB835732-x86-FIN.EXE.bac_a00940 Infected: Worm.Win32.Viking.lz skipped C:\Documents and Settings\Owner\.housecall6.6\Quarantine\WindowsXP-KB835732-x86-FRA.EXE.bac_a00940 Infected: Worm.Win32.Viking.lz skipped C:\Documents and Settings\Owner\.housecall6.6\Quarantine\WindowsXP-KB835732-x86-ITA.EXE.bac_a00940 Infected: Worm.Win32.Viking.lz skipped C:\Documents and Settings\Owner\.housecall6.6\Quarantine\WindowsXP-KB835732-x86-JPN.EXE.bac_a00940 Infected: Worm.Win32.Viking.lz skipped C:\Documents and Settings\Owner\.housecall6.6\Quarantine\WindowsXP-KB835732-x86-KOR.EXE.bac_a00940 Infected: Worm.Win32.Viking.lz skipped C:\Documents and Settings\Owner\.housecall6.6\Quarantine\WindowsXP-KB835732-x86-NLD.EXE.bac_a00940 Infected: Worm.Win32.Viking.lz skipped C:\Documents and Settings\Owner\.housecall6.6\Quarantine\WindowsXP-KB835732-x86-NOR.EXE.bac_a00940 Infected: Worm.Win32.Viking.lz skipped C:\Documents and Settings\Owner\.housecall6.6\Quarantine\WindowsXP-KB835732-x86-PTG.EXE.bac_a00940 Infected: Worm.Win32.Viking.lz skipped C:\Documents and Settings\Owner\.housecall6.6\Quarantine\WindowsXP-KB835732-x86-RUS.EXE.bac_a00940 Infected: Worm.Win32.Viking.lz skipped C:\Documents and Settings\Owner\.housecall6.6\Quarantine\WindowsXP-KB835732-x86-SVE.EXE.bac_a00940 Infected: Worm.Win32.Viking.lz skipped C:\Documents and Settings\Owner\.housecall6.6\Quarantine\WindowsXP-KB835732-x86-TRK.EXE.bac_a00940 Infected: Worm.Win32.Viking.lz skipped C:\Documents and Settings\Owner\.housecall6.6\Quarantine\WINNT.EXE.bac_a00940 Infected: Worm.Win32.Viking.lz skipped C:\Documents and Settings\Owner\.housecall6.6\Quarantine\WINNT32.EXE.bac_a00940 Infected: Worm.Win32.Viking.lz skipped C:\Documents and Settings\Owner\Cookies\index.dat Object is locked skipped C:\Documents and Settings\Owner\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat Object is locked skipped C:\Documents and Settings\Owner\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped C:\Documents and Settings\Owner\Local Settings\History\History.IE5\index.dat Object is locked skipped C:\Documents and Settings\Owner\Local Settings\History\History.IE5\MSHist012007100220071003\index.dat Object is locked skipped C:\Documents and Settings\Owner\Local Settings\Temporary Internet Files\Content.IE5\index.dat Object is locked skipped C:\Documents and Settings\Owner\NTUSER.DAT Object is locked skipped C:\Documents and Settings\Owner\ntuser.dat.LOG Object is locked skipped C:\hp\bin\KillWind.exe Infected: not-a-virus:RiskTool.Win32.PsKill.p skipped C:\hpcmerr.log Object is locked skipped C:\Program Files\Compaq Connections\1940576\Users\Default\Data\chandir.dat Object is locked skipped C:\Program Files\Compaq Connections\1940576\Users\Default\Data\chandir.idx Object is locked skipped C:\Program Files\Compaq Connections\1940576\Users\Default\Data\chn.dat Object is locked skipped C:\Program Files\Compaq Connections\1940576\Users\Default\Data\chn.idx Object is locked skipped C:\Program Files\Compaq Connections\1940576\Users\Default\Data\D0000000.FCS Object is locked skipped C:\Program Files\Compaq Connections\1940576\Users\Default\Data\inuse.txt Object is locked skipped C:\Program Files\Compaq Connections\1940576\Users\Default\Data\L0000001.FCS Object is locked skipped C:\Program Files\Compaq Connections\1940576\Users\Default\Data\main.log Object is locked skipped C:\Program Files\Compaq Connections\1940576\Users\Default\Data\prs.dat Object is locked skipped C:\Program Files\Compaq Connections\1940576\Users\Default\Data\prs.idx Object is locked skipped C:\Program Files\Compaq Connections\1940576\Users\Default\Data\prs_die.dat Object is locked skipped C:\Program Files\Compaq Connections\1940576\Users\Default\Data\prs_die.idx Object is locked skipped C:\Program Files\Compaq Connections\1940576\Users\Default\Data\prs_dnd.dat Object is locked skipped C:\Program Files\Compaq Connections\1940576\Users\Default\Data\prs_dnd.idx Object is locked skipped C:\Program Files\Compaq Connections\1940576\Users\Default\Data\prs_ext.dat Object is locked skipped C:\Program Files\Compaq Connections\1940576\Users\Default\Data\prs_ext.idx Object is locked skipped C:\Program Files\Compaq Connections\1940576\Users\Default\Data\prs_rcv.dat Object is locked skipped C:\Program Files\Compaq Connections\1940576\Users\Default\Data\prs_rcv.idx Object is locked skipped C:\Program Files\Compaq Connections\1940576\Users\Default\Data\storydb.dat Object is locked skipped C:\Program Files\Compaq Connections\1940576\Users\Default\Data\storydb.idx Object is locked skipped C:\Program Files\Norton AntiVirus\AVApp.log Object is locked skipped C:\Program Files\Norton AntiVirus\AVError.log Object is locked skipped C:\Program Files\Norton AntiVirus\AVVirus.log Object is locked skipped C:\qoobox\Quarantine\C\Privilege.dat.vir Infected: Trojan-Dropper.Win32.Agent.bvh skipped C:\qoobox\Quarantine\C\WINDOWS\dbhelp.dll.vir Infected: Trojan-PSW.Win32.Delf.aaw skipped C:\qoobox\Quarantine\C\WINDOWS\RichDll.dll.vir Infected: Worm.Win32.Viking.lz skipped C:\qoobox\Quarantine\C\WINDOWS\system32\cmdbcs.dll.vir Infected: Trojan-PSW.Win32.OnLineGames.cdv skipped C:\qoobox\Quarantine\C\WINDOWS\system32\DbgHlp32.dll.vir Infected: Trojan-PSW.Win32.OnLineGames.bws skipped C:\qoobox\Quarantine\C\WINDOWS\system32\gbekry.dll.vir Infected: Trojan-PSW.Win32.OnLineGames.cdv skipped C:\qoobox\Quarantine\C\WINDOWS\system32\kapjazy.dll.vir Infected: Trojan-PSW.Win32.Agent.pl skipped C:\qoobox\Quarantine\C\WINDOWS\system32\kaqhczy.dll.vir Infected: Trojan-PSW.Win32.OnLineGames.bou skipped C:\qoobox\Quarantine\C\WINDOWS\system32\kawdbzy.dll.vir Infected: Trojan-Spy.Win32.Delf.ago skipped C:\qoobox\Quarantine\C\WINDOWS\system32\kvdxbma.dll.vir Infected: Trojan-Spy.Win32.Delf.aju skipped C:\qoobox\Quarantine\C\WINDOWS\system32\LYLOADER.EXE.vir Infected: Trojan-PSW.Win32.OnLineGames.bmt skipped C:\qoobox\Quarantine\C\WINDOWS\system32\LYLOADMR.EXE.vir Infected: Trojan-Dropper.Win32.Agent.bvh skipped C:\qoobox\Quarantine\C\WINDOWS\system32\LYMANGR.DLL.vir Infected: Trojan-PSW.Win32.OnLineGames.bmu skipped C:\qoobox\Quarantine\C\WINDOWS\system32\mohekj.dll.vir Infected: Trojan-PSW.Win32.OnLineGames.cdz skipped C:\qoobox\Quarantine\C\WINDOWS\system32\MSDEG32.DLL.vir Infected: Trojan-PSW.Win32.OnLineGames.bmv skipped C:\qoobox\Quarantine\C\WINDOWS\system32\myhpri.dll.vir Infected: Trojan-PSW.Win32.OnLineGames.bjk skipped C:\qoobox\Quarantine\C\WINDOWS\system32\oubttg.dll.vir Infected: Trojan-PSW.Win32.OnLineGames.bws skipped C:\qoobox\Quarantine\C\WINDOWS\system32\raqjapi.dll.vir Infected: Trojan-PSW.Win32.OnLineGames.blx skipped C:\qoobox\Quarantine\C\WINDOWS\system32\rsjzapm.dll.vir Infected: Trojan-PSW.Win32.OnLineGames.bmj skipped C:\qoobox\Quarantine\C\WINDOWS\system32\SHQ.DLL.vir Infected: Trojan.Win32.Agent.bmq skipped C:\qoobox\Quarantine\C\WINDOWS\system32\SHQMANGR.DLL.vir Infected: Trojan-PSW.Win32.OnLineGames.cyk skipped C:\qoobox\Quarantine\C\WINDOWS\system32\upxdnd.dll.vir Infected: Trojan-PSW.Win32.OnLineGames.cdz skipped C:\qoobox\Quarantine\C\WINDOWS\system32\wlhpri.dll.vir Infected: Trojan-Spy.Win32.Delf.aao skipped C:\qoobox\Quarantine\C\WINDOWS\system32\zxipri.dll.vir Infected: Trojan-Spy.Win32.Delf.aao skipped C:\qoobox\Quarantine\D\myplayer.com.vir Infected: Trojan-Spy.Win32.Pophot.mi skipped C:\System Volume Information\_restore{0B6AB4EA-58AD-4BDF-8C7F-C598B3E88003}\RP0\A0000033.dll Infected: Worm.Win32.Viking.lz skipped C:\System Volume Information\_restore{0B6AB4EA-58AD-4BDF-8C7F-C598B3E88003}\RP0\A0000070.exe Infected: not-a-virus:RiskTool.Win32.PsKill.p skipped C:\System Volume Information\_restore{0B6AB4EA-58AD-4BDF-8C7F-C598B3E88003}\RP0\A0000334.exe Infected: Worm.Win32.Viking.lz skipped C:\System Volume Information\_restore{0B6AB4EA-58AD-4BDF-8C7F-C598B3E88003}\RP0\A0000336.exe Infected: Worm.Win32.Viking.lz skipped C:\System Volume Information\_restore{0B6AB4EA-58AD-4BDF-8C7F-C598B3E88003}\RP0\A0000352.exe Infected: Worm.Win32.Viking.lz skipped C:\System Volume Information\_restore{0B6AB4EA-58AD-4BDF-8C7F-C598B3E88003}\RP0\A0000354.EXE Infected: Worm.Win32.Viking.lz skipped C:\System Volume Information\_restore{0B6AB4EA-58AD-4BDF-8C7F-C598B3E88003}\RP0\A0000360.dll Infected: Worm.Win32.Viking.lz skipped C:\System Volume Information\_restore{0B6AB4EA-58AD-4BDF-8C7F-C598B3E88003}\RP0\A0000361.exe Infected: Worm.Win32.Viking.lz skipped C:\System Volume Information\_restore{0B6AB4EA-58AD-4BDF-8C7F-C598B3E88003}\RP0\A0000363.EXE Infected: Worm.Win32.Viking.lz skipped C:\System Volume Information\_restore{0B6AB4EA-58AD-4BDF-8C7F-C598B3E88003}\RP0\A0000364.exe Infected: Worm.Win32.Viking.lz skipped C:\System Volume Information\_restore{0B6AB4EA-58AD-4BDF-8C7F-C598B3E88003}\RP0\A0000424.exe Infected: Worm.Win32.Viking.lz skipped C:\System Volume Information\_restore{0B6AB4EA-58AD-4BDF-8C7F-C598B3E88003}\RP0\A0000434.dll Infected: Worm.Win32.Viking.lz skipped C:\System Volume Information\_restore{0B6AB4EA-58AD-4BDF-8C7F-C598B3E88003}\RP0\A0000460.exe Infected: Worm.Win32.Viking.lz skipped C:\System Volume Information\_restore{0B6AB4EA-58AD-4BDF-8C7F-C598B3E88003}\RP0\A0000461.EXE Infected: Worm.Win32.Viking.lz skipped C:\System Volume Information\_restore{0B6AB4EA-58AD-4BDF-8C7F-C598B3E88003}\RP0\A0000467.EXE Infected: Trojan-PSW.Win32.OnLineGames.bmt skipped C:\System Volume Information\_restore{0B6AB4EA-58AD-4BDF-8C7F-C598B3E88003}\RP0\A0000468.sys Infected: Trojan-Downloader.Win32.Small.czl skipped C:\System Volume Information\_restore{0B6AB4EA-58AD-4BDF-8C7F-C598B3E88003}\RP0\A0000469.DLL Infected: Trojan-PSW.Win32.OnLineGames.bmu skipped C:\System Volume Information\_restore{0B6AB4EA-58AD-4BDF-8C7F-C598B3E88003}\RP0\A0000471.DLL Infected: Trojan-PSW.Win32.OnLineGames.bmv skipped C:\System Volume Information\_restore{0B6AB4EA-58AD-4BDF-8C7F-C598B3E88003}\RP0\A0000472.dll Infected: Trojan-PSW.Win32.Delf.aaw skipped C:\System Volume Information\_restore{0B6AB4EA-58AD-4BDF-8C7F-C598B3E88003}\RP0\A0000473.dll Infected: Trojan-PSW.Win32.OnLineGames.cdz skipped C:\System Volume Information\_restore{0B6AB4EA-58AD-4BDF-8C7F-C598B3E88003}\RP0\A0000474.dll Infected: Trojan-PSW.Win32.OnLineGames.bws skipped C:\System Volume Information\_restore{0B6AB4EA-58AD-4BDF-8C7F-C598B3E88003}\RP0\A0000475.dll Infected: Trojan-PSW.Win32.OnLineGames.cdv skipped C:\System Volume Information\_restore{0B6AB4EA-58AD-4BDF-8C7F-C598B3E88003}\RP0\A0000477.dll Infected: Worm.Win32.Viking.lz skipped C:\System Volume Information\_restore{0B6AB4EA-58AD-4BDF-8C7F-C598B3E88003}\RP0\A0000478.exe Infected: Worm.Win32.Viking.lz skipped C:\System Volume Information\_restore{0B6AB4EA-58AD-4BDF-8C7F-C598B3E88003}\RP0\A0000479.exe Infected: Worm.Win32.Viking.lz skipped C:\System Volume Information\_restore{0B6AB4EA-58AD-4BDF-8C7F-C598B3E88003}\RP0\A0000480.exe Infected: Trojan-PSW.Win32.Delf.aaw skipped C:\System Volume Information\_restore{0B6AB4EA-58AD-4BDF-8C7F-C598B3E88003}\RP0\A0000481.exe Infected: Trojan-PSW.Win32.OnLineGames.box skipped C:\System Volume Information\_restore{0B6AB4EA-58AD-4BDF-8C7F-C598B3E88003}\RP1\snapshot\MFEX-1.DAT Infected: Trojan-PSW.Win32.OnLineGames.bmt skipped C:\System Volume Information\_restore{0B6AB4EA-58AD-4BDF-8C7F-C598B3E88003}\RP1\snapshot\MFEX-2.DAT Infected: Trojan-PSW.Win32.OnLineGames.bmu skipped C:\System Volume Information\_restore{0B6AB4EA-58AD-4BDF-8C7F-C598B3E88003}\RP10\A0002146.dll Infected: Trojan-PSW.Win32.OnLineGames.bws skipped C:\System Volume Information\_restore{0B6AB4EA-58AD-4BDF-8C7F-C598B3E88003}\RP10\A0002147.dll Infected: Trojan-PSW.Win32.OnLineGames.cdv skipped C:\System Volume Information\_restore{0B6AB4EA-58AD-4BDF-8C7F-C598B3E88003}\RP10\A0002148.dll Infected: Trojan-PSW.Win32.OnLineGames.cdz skipped C:\System Volume Information\_restore{0B6AB4EA-58AD-4BDF-8C7F-C598B3E88003}\RP10\A0002150.dll Infected: Trojan-PSW.Win32.OnLineGames.bws skipped C:\System Volume Information\_restore{0B6AB4EA-58AD-4BDF-8C7F-C598B3E88003}\RP10\A0002158.dll Infected: Trojan-PSW.Win32.OnLineGames.bjk skipped C:\System Volume Information\_restore{0B6AB4EA-58AD-4BDF-8C7F-C598B3E88003}\RP10\A0002159.dll Infected: Trojan-Spy.Win32.Delf.aju skipped C:\System Volume Information\_restore{0B6AB4EA-58AD-4BDF-8C7F-C598B3E88003}\RP10\A0002160.dll Infected: Trojan-Spy.Win32.Delf.ago skipped C:\System Volume Information\_restore{0B6AB4EA-58AD-4BDF-8C7F-C598B3E88003}\RP10\A0002161.dll Infected: Trojan-Spy.Win32.Delf.aao skipped C:\System Volume Information\_restore{0B6AB4EA-58AD-4BDF-8C7F-C598B3E88003}\RP10\A0002162.dll Infected: Trojan-PSW.Win32.OnLineGames.blx skipped C:\System Volume Information\_restore{0B6AB4EA-58AD-4BDF-8C7F-C598B3E88003}\RP10\A0002163.dll Infected: Trojan-PSW.Win32.OnLineGames.bmj skipped C:\System Volume Information\_restore{0B6AB4EA-58AD-4BDF-8C7F-C598B3E88003}\RP10\A0002164.dll Infected: Trojan-PSW.Win32.Agent.pl skipped C:\System Volume Information\_restore{0B6AB4EA-58AD-4BDF-8C7F-C598B3E88003}\RP10\A0002165.dll Infected: Trojan-PSW.Win32.OnLineGames.bou skipped C:\System Volume Information\_restore{0B6AB4EA-58AD-4BDF-8C7F-C598B3E88003}\RP10\A0002166.dll Infected: Trojan-Spy.Win32.Delf.aao skipped C:\System Volume Information\_restore{0B6AB4EA-58AD-4BDF-8C7F-C598B3E88003}\RP11\A0002339.DLL Infected: Trojan.Win32.Agent.bmq skipped C:\System Volume Information\_restore{0B6AB4EA-58AD-4BDF-8C7F-C598B3E88003}\RP11\A0002340.EXE Infected: Trojan-Dropper.Win32.Agent.bvh skipped C:\System Volume Information\_restore{0B6AB4EA-58AD-4BDF-8C7F-C598B3E88003}\RP11\A0002341.dll Infected: Trojan-PSW.Win32.Delf.aaw skipped C:\System Volume Information\_restore{0B6AB4EA-58AD-4BDF-8C7F-C598B3E88003}\RP2\snapshot\MFEX-1.DAT Infected: Trojan-PSW.Win32.OnLineGames.bmt skipped C:\System Volume Information\_restore{0B6AB4EA-58AD-4BDF-8C7F-C598B3E88003}\RP2\snapshot\MFEX-2.DAT Infected: Trojan-PSW.Win32.OnLineGames.bmu skipped C:\System Volume Information\_restore{0B6AB4EA-58AD-4BDF-8C7F-C598B3E88003}\RP21\change.log Object is locked skipped C:\System Volume Information\_restore{0B6AB4EA-58AD-4BDF-8C7F-C598B3E88003}\RP3\snapshot\MFEX-1.DAT Infected: Trojan-PSW.Win32.OnLineGames.bmt skipped C:\System Volume Information\_restore{0B6AB4EA-58AD-4BDF-8C7F-C598B3E88003}\RP3\snapshot\MFEX-2.DAT Infected: Trojan-PSW.Win32.OnLineGames.bmu skipped C:\System Volume Information\_restore{0B6AB4EA-58AD-4BDF-8C7F-C598B3E88003}\RP4\snapshot\MFEX-1.DAT Infected: Trojan-PSW.Win32.OnLineGames.bmt skipped C:\System Volume Information\_restore{0B6AB4EA-58AD-4BDF-8C7F-C598B3E88003}\RP4\snapshot\MFEX-2.DAT Infected: Trojan-PSW.Win32.OnLineGames.bmu skipped C:\System Volume Information\_restore{0B6AB4EA-58AD-4BDF-8C7F-C598B3E88003}\RP5\snapshot\MFEX-1.DAT Infected: Trojan-PSW.Win32.OnLineGames.bmt skipped C:\System Volume Information\_restore{0B6AB4EA-58AD-4BDF-8C7F-C598B3E88003}\RP5\snapshot\MFEX-2.DAT Infected: Trojan-PSW.Win32.OnLineGames.bmu skipped C:\System Volume Information\_restore{0B6AB4EA-58AD-4BDF-8C7F-C598B3E88003}\RP6\A0000548.exe Infected: Worm.Win32.Viking.lz skipped C:\System Volume Information\_restore{0B6AB4EA-58AD-4BDF-8C7F-C598B3E88003}\RP6\A0000549.exe Infected: Worm.Win32.Viking.lz skipped C:\System Volume Information\_restore{0B6AB4EA-58AD-4BDF-8C7F-C598B3E88003}\RP6\A0000550.exe Infected: Worm.Win32.Viking.lz skipped C:\System Volume Information\_restore{0B6AB4EA-58AD-4BDF-8C7F-C598B3E88003}\RP6\snapshot\MFEX-1.DAT Infected: Trojan-PSW.Win32.OnLineGames.bmt skipped C:\System Volume Information\_restore{0B6AB4EA-58AD-4BDF-8C7F-C598B3E88003}\RP6\snapshot\MFEX-2.DAT Infected: Trojan-Dropper.Win32.Agent.bvh skipped C:\System Volume Information\_restore{0B6AB4EA-58AD-4BDF-8C7F-C598B3E88003}\RP7\A0000623.exe Infected: Worm.Win32.Viking.lz skipped C:\System Volume Information\_restore{0B6AB4EA-58AD-4BDF-8C7F-C598B3E88003}\RP7\A0000624.EXE Infected: Worm.Win32.Viking.lz skipped C:\System Volume Information\_restore{0B6AB4EA-58AD-4BDF-8C7F-C598B3E88003}\RP7\A0000625.exe Infected: Worm.Win32.Viking.lz skipped C:\System Volume Information\_restore{0B6AB4EA-58AD-4BDF-8C7F-C598B3E88003}\RP7\A0000626.exe Infected: Worm.Win32.Viking.lz skipped C:\System Volume Information\_restore{0B6AB4EA-58AD-4BDF-8C7F-C598B3E88003}\RP7\A0000627.exe Infected: Worm.Win32.Viking.lz skipped C:\System Volume Information\_restore{0B6AB4EA-58AD-4BDF-8C7F-C598B3E88003}\RP7\A0000628.exe Infected: Worm.Win32.Viking.lz skipped C:\System Volume Information\_restore{0B6AB4EA-58AD-4BDF-8C7F-C598B3E88003}\RP7\A0000629.exe Infected: Worm.Win32.Viking.lz skipped C:\System Volume Information\_restore{0B6AB4EA-58AD-4BDF-8C7F-C598B3E88003}\RP7\A0000630.EXE Infected: Worm.Win32.Viking.lz skipped C:\System Volume Information\_restore{0B6AB4EA-58AD-4BDF-8C7F-C598B3E88003}\RP7\A0000631.EXE Infected: Worm.Win32.Viking.lz skipped C:\System Volume Information\_restore{0B6AB4EA-58AD-4BDF-8C7F-C598B3E88003}\RP7\A0000632.EXE Infected: Worm.Win32.Viking.lz skipped C:\System Volume Information\_restore{0B6AB4EA-58AD-4BDF-8C7F-C598B3E88003}\RP7\A0000633.exe Infected: Worm.Win32.Viking.lz skipped C:\System Volume Information\_restore{0B6AB4EA-58AD-4BDF-8C7F-C598B3E88003}\RP7\A0000634.exe Infected: Worm.Win32.Viking.lz skipped C:\System Volume Information\_restore{0B6AB4EA-58AD-4BDF-8C7F-C598B3E88003}\RP7\A0000635.exe Infected: Worm.Win32.Viking.lz skipped C:\System Volume Information\_restore{0B6AB4EA-58AD-4BDF-8C7F-C598B3E88003}\RP7\A0000636.EXE Infected: Worm.Win32.Viking.lz skipped C:\System Volume Information\_restore{0B6AB4EA-58AD-4BDF-8C7F-C598B3E88003}\RP7\A0000637.EXE Infected: Worm.Win32.Viking.lz skipped C:\System Volume Information\_restore{0B6AB4EA-58AD-4BDF-8C7F-C598B3E88003}\RP7\A0000638.EXE Infected: Worm.Win32.Viking.lz skipped C:\System Volume Information\_restore{0B6AB4EA-58AD-4BDF-8C7F-C598B3E88003}\RP7\A0000639.EXE Infected: Worm.Win32.Viking.lz skipped C:\System Volume Information\_restore{0B6AB4EA-58AD-4BDF-8C7F-C598B3E88003}\RP7\A0000640.EXE Infected: Worm.Win32.Viking.lz skipped C:\System Volume Information\_restore{0B6AB4EA-58AD-4BDF-8C7F-C598B3E88003}\RP7\A0000641.EXE Infected: Worm.Win32.Viking.lz skipped C:\System Volume Information\_restore{0B6AB4EA-58AD-4BDF-8C7F-C598B3E88003}\RP7\A0000642.EXE Infected: Worm.Win32.Viking.lz skipped C:\System Volume Information\_restore{0B6AB4EA-58AD-4BDF-8C7F-C598B3E88003}\RP7\A0000643.EXE Infected: Worm.Win32.Viking.lz skipped C:\System Volume Information\_restore{0B6AB4EA-58AD-4BDF-8C7F-C598B3E88003}\RP7\A0000644.EXE Infected: Worm.Win32.Viking.lz skipped C:\System Volume Information\_restore{0B6AB4EA-58AD-4BDF-8C7F-C598B3E88003}\RP7\A0000645.EXE Infected: Worm.Win32.Viking.lz skipped C:\System Volume Information\_restore{0B6AB4EA-58AD-4BDF-8C7F-C598B3E88003}\RP7\A0000646.EXE Infected: Worm.Win32.Viking.lz skipped C:\System Volume Information\_restore{0B6AB4EA-58AD-4BDF-8C7F-C598B3E88003}\RP7\A0000647.EXE Infected: Worm.Win32.Viking.lz skipped C:\System Volume Information\_restore{0B6AB4EA-58AD-4BDF-8C7F-C598B3E88003}\RP7\A0000648.EXE Infected: Worm.Win32.Viking.lz skipped C:\System Volume Information\_restore{0B6AB4EA-58AD-4BDF-8C7F-C598B3E88003}\RP7\A0000649.EXE Infected: Worm.Win32.Viking.lz skipped C:\System Volume Information\_restore{0B6AB4EA-58AD-4BDF-8C7F-C598B3E88003}\RP7\A0000650.EXE Infected: Worm.Win32.Viking.lz skipped C:\System Volume Information\_restore{0B6AB4EA-58AD-4BDF-8C7F-C598B3E88003}\RP7\A0000651.EXE Infected: Worm.Win32.Viking.lz skipped C:\System Volume Information\_restore{0B6AB4EA-58AD-4BDF-8C7F-C598B3E88003}\RP7\A0000652.EXE Infected: Worm.Win32.Viking.lz skipped C:\System Volume Information\_restore{0B6AB4EA-58AD-4BDF-8C7F-C598B3E88003}\RP7\A0000653.EXE Infected: Worm.Win32.Viking.lz skipped C:\System Volume Information\_restore{0B6AB4EA-58AD-4BDF-8C7F-C598B3E88003}\RP7\A0000654.EXE Infected: Worm.Win32.Viking.lz skipped C:\System Volume Information\_restore{0B6AB4EA-58AD-4BDF-8C7F-C598B3E88003}\RP7\A0000655.EXE Infected: Worm.Win32.Viking.lz skipped C:\System Volume Information\_restore{0B6AB4EA-58AD-4BDF-8C7F-C598B3E88003}\RP7\A0000656.EXE Infected: Worm.Win32.Viking.lz skipped C:\System Volume Information\_restore{0B6AB4EA-58AD-4BDF-8C7F-C598B3E88003}\RP7\A0000657.EXE Infected: Worm.Win32.Viking.lz skipped C:\System Volume Information\_restore{0B6AB4EA-58AD-4BDF-8C7F-C598B3E88003}\RP7\A0000658.EXE Infected: Worm.Win32.Viking.lz skipped C:\System Volume Information\_restore{0B6AB4EA-58AD-4BDF-8C7F-C598B3E88003}\RP7\A0000659.EXE Infected: Worm.Win32.Viking.lz skipped C:\System Volume Information\_restore{0B6AB4EA-58AD-4BDF-8C7F-C598B3E88003}\RP7\A0000660.EXE Infected: Worm.Win32.Viking.lz skipped C:\System Volume Information\_restore{0B6AB4EA-58AD-4BDF-8C7F-C598B3E88003}\RP7\A0000661.EXE Infected: Worm.Win32.Viking.lz skipped C:\System Volume Information\_restore{0B6AB4EA-58AD-4BDF-8C7F-C598B3E88003}\RP7\A0000662.EXE Infected: Worm.Win32.Viking.lz skipped C:\System Volume Information\_restore{0B6AB4EA-58AD-4BDF-8C7F-C598B3E88003}\RP7\A0000663.EXE Infected: Worm.Win32.Viking.lz skipped C:\System Volume Information\_restore{0B6AB4EA-58AD-4BDF-8C7F-C598B3E88003}\RP7\A0000664.EXE Infected: Worm.Win32.Viking.lz skipped C:\System Volume Information\_restore{0B6AB4EA-58AD-4BDF-8C7F-C598B3E88003}\RP7\A0000665.EXE Infected: Worm.Win32.Viking.lz skipped C:\System Volume Information\_restore{0B6AB4EA-58AD-4BDF-8C7F-C598B3E88003}\RP7\A0000666.EXE Infected: Worm.Win32.Viking.lz skipped C:\System Volume Information\_restore{0B6AB4EA-58AD-4BDF-8C7F-C598B3E88003}\RP7\A0000667.EXE Infected: Worm.Win32.Viking.lz skipped C:\System Volume Information\_restore{0B6AB4EA-58AD-4BDF-8C7F-C598B3E88003}\RP7\A0000668.EXE Infected: Worm.Win32.Viking.lz skipped C:\System Volume Information\_restore{0B6AB4EA-58AD-4BDF-8C7F-C598B3E88003}\RP7\A0000669.exe Infected: Worm.Win32.Viking.lz skipped C:\System Volume Information\_restore{0B6AB4EA-58AD-4BDF-8C7F-C598B3E88003}\RP7\A0000670.exe Infected: Worm.Win32.Viking.lz skipped C:\System Volume Information\_restore{0B6AB4EA-58AD-4BDF-8C7F-C598B3E88003}\RP7\A0000671.exe Infected: Worm.Win32.Viking.lz skipped C:\System Volume Information\_restore{0B6AB4EA-58AD-4BDF-8C7F-C598B3E88003}\RP7\A0000672.exe Infected: Worm.Win32.Viking.lz skipped C:\System Volume Information\_restore{0B6AB4EA-58AD-4BDF-8C7F-C598B3E88003}\RP7\A0000673.exe Infected: Worm.Win32.Viking.lz skipped C:\System Volume Information\_restore{0B6AB4EA-58AD-4BDF-8C7F-C598B3E88003}\RP7\A0000674.EXE Infected: Worm.Win32.Viking.lz skipped C:\System Volume Information\_restore{0B6AB4EA-58AD-4BDF-8C7F-C598B3E88003}\RP7\A0000675.exe Infected: Worm.Win32.Viking.lz skipped C:\System Volume Information\_restore{0B6AB4EA-58AD-4BDF-8C7F-C598B3E88003}\RP7\A0000676.exe Infected: Worm.Win32.Viking.lz skipped C:\System Volume Information\_restore{0B6AB4EA-58AD-4BDF-8C7F-C598B3E88003}\RP7\A0000677.exe Infected: Worm.Win32.Viking.lz skipped C:\System Volume Information\_restore{0B6AB4EA-58AD-4BDF-8C7F-C598B3E88003}\RP7\A0000678.exe Infected: Worm.Win32.Viking.lz skipped C:\System Volume Information\_restore{0B6AB4EA-58AD-4BDF-8C7F-C598B3E88003}\RP7\A0000679.exe Infected: Worm.Win32.Viking.lz skipped C:\System Volume Information\_restore{0B6AB4EA-58AD-4BDF-8C7F-C598B3E88003}\RP7\A0000680.exe Infected: Worm.Win32.Viking.lz skipped C:\System Volume Information\_restore{0B6AB4EA-58AD-4BDF-8C7F-C598B3E88003}\RP7\A0000681.exe Infected: Worm.Win32.Viking.lz skipped C:\System Volume Information\_restore{0B6AB4EA-58AD-4BDF-8C7F-C598B3E88003}\RP7\A0000682.exe Infected: Worm.Win32.Viking.lz skipped C:\System Volume Information\_restore{0B6AB4EA-58AD-4BDF-8C7F-C598B3E88003}\RP7\A0000683.EXE Infected: Worm.Win32.Viking.lz skipped C:\System Volume Information\_restore{0B6AB4EA-58AD-4BDF-8C7F-C598B3E88003}\RP7\A0000684.exe Infected: Worm.Win32.Viking.lz skipped C:\System Volume Information\_restore{0B6AB4EA-58AD-4BDF-8C7F-C598B3E88003}\RP7\A0000685.exe Infected: Worm.Win32.Viking.lz skipped C:\System Volume Information\_restore{0B6AB4EA-58AD-4BDF-8C7F-C598B3E88003}\RP7\A0000686.exe Infected: Worm.Win32.Viking.lz skipped C:\System Volume Information\_restore{0B6AB4EA-58AD-4BDF-8C7F-C598B3E88003}\RP7\A0000687.exe Infected: Worm.Win32.Viking.lz skipped C:\System Volume Information\_restore{0B6AB4EA-58AD-4BDF-8C7F-C598B3E88003}\RP7\A0000688.exe Infected: Worm.Win32.Viking.lz skipped C:\System Volume Information\_restore{0B6AB4EA-58AD-4BDF-8C7F-C598B3E88003}\RP7\A0000689.EXE Infected: Worm.Win32.Viking.lz skipped C:\System Volume Information\_restore{0B6AB4EA-58AD-4BDF-8C7F-C598B3E88003}\RP7\A0000690.exe Infected: Worm.Win32.Viking.lz skipped C:\System Volume Information\_restore{0B6AB4EA-58AD-4BDF-8C7F-C598B3E88003}\RP7\A0000691.exe Infected: Worm.Win32.Viking.lz skipped C:\System Volume Information\_restore{0B6AB4EA-58AD-4BDF-8C7F-C598B3E88003}\RP7\A0000692.EXE Infected: Worm.Win32.Viking.lz skipped C:\System Volume Information\_restore{0B6AB4EA-58AD-4BDF-8C7F-C598B3E88003}\RP7\A0000693.exe Infected: Worm.Win32.Viking.lz skipped C:\System Volume Information\_restore{0B6AB4EA-58AD-4BDF-8C7F-C598B3E88003}\RP7\A0000694.exe Infected: Worm.Win32.Viking.lz skipped C:\System Volume Information\_restore{0B6AB4EA-58AD-4BDF-8C7F-C598B3E88003}\RP7\A0000695.EXE Infected: Worm.Win32.Viking.lz skipped C:\System Volume Information\_restore{0B6AB4EA-58AD-4BDF-8C7F-C598B3E88003}\RP7\A0000696.exe Infected: Worm.Win32.Viking.lz skipped C:\System Volume Information\_restore{0B6AB4EA-58AD-4BDF-8C7F-C598B3E88003}\RP7\A0000697.exe Infected: Worm.Win32.Viking.lz skipped C:\System Volume Information\_restore{0B6AB4EA-58AD-4BDF-8C7F-C598B3E88003}\RP7\A0000698.exe Infected: Worm.Win32.Viking.lz skipped C:\System Volume Information\_restore{0B6AB4EA-58AD-4BDF-8C7F-C598B3E88003}\RP7\A0000699.exe Infected: Worm.Win32.Viking.lz skipped C:\System Volume Information\_restore{0B6AB4EA-58AD-4BDF-8C7F-C598B3E88003}\RP7\A0000700.exe Infected: Worm.Win32.Viking.lz skipped C:\System Volume Information\_restore{0B6AB4EA-58AD-4BDF-8C7F-C598B3E88003}\RP7\A0000701.exe Infected: Worm.Win32.Viking.lz skipped C:\System Volume Information\_restore{0B6AB4EA-58AD-4BDF-8C7F-C598B3E88003}\RP7\A0000702.exe Infected: Worm.Win32.Viking.lz skipped C:\System Volume Information\_restore{0B6AB4EA-58AD-4BDF-8C7F-C598B3E88003}\RP7\A0000703.exe Infected: Worm.Win32.Viking.lz skipped C:\System Volume Information\_restore{0B6AB4EA-58AD-4BDF-8C7F-C598B3E88003}\RP7\A0000704.exe Infected: Worm.Win32.Viking.lz skipped C:\System Volume Information\_restore{0B6AB4EA-58AD-4BDF-8C7F-C598B3E88003}\RP7\A0000705.EXE Infected: Worm.Win32.Viking.lz skipped C:\System Volume Information\_restore{0B6AB4EA-58AD-4BDF-8C7F-C598B3E88003}\RP7\A0000706.exe Infected: Worm.Win32.Viking.lz skipped C:\System Volume Information\_restore{0B6AB4EA-58AD-4BDF-8C7F-C598B3E88003}\RP7\A0000707.exe Infected: Worm.Win32.Viking.lz skipped C:\System Volume Information\_restore{0B6AB4EA-58AD-4BDF-8C7F-C598B3E88003}\RP7\A0000708.exe Infected: Worm.Win32.Viking.lz skipped C:\System Volume Information\_restore{0B6AB4EA-58AD-4BDF-8C7F-C598B3E88003}\RP7\A0000709.exe Infected: Worm.Win32.Viking.lz skipped C:\System Volume Information\_restore{0B6AB4EA-58AD-4BDF-8C7F-C598B3E88003}\RP7\A0000710.exe Infected: Worm.Win32.Viking.lz skipped C:\System Volume Information\_restore{0B6AB4EA-58AD-4BDF-8C7F-C598B3E88003}\RP7\A0000711.exe Infected: Worm.Win32.Viking.lz skipped C:\System Volume Information\_restore{0B6AB4EA-58AD-4BDF-8C7F-C598B3E88003}\RP7\A0000712.exe Infected: Worm.Win32.Viking.lz skipped C:\System Volume Information\_restore{0B6AB4EA-58AD-4BDF-8C7F-C598B3E88003}\RP7\A0000713.exe Infected: Worm.Win32.Viking.lz skipped C:\System Volume Information\_restore{0B6AB4EA-58AD-4BDF-8C7F-C598B3E88003}\RP7\A0000714.exe Infected: Worm.Win32.Viking.lz skipped C:\System Volume Information\_restore{0B6AB4EA-58AD-4BDF-8C7F-C598B3E88003}\RP7\A0000715.exe Infected: Worm.Win32.Viking.lz skipped C:\System Volume Information\_restore{0B6AB4EA-58AD-4BDF-8C7F-C598B3E88003}\RP7\A0000716.exe Infected: Worm.Win32.Viking.lz skipped C:\System Volume Information\_restore{0B6AB4EA-58AD-4BDF-8C7F-C598B3E88003}\RP7\A0000717.exe Infected: Worm.Win32.Viking.lz skipped C:\System Volume Information\_restore{0B6AB4EA-58AD-4BDF-8C7F-C598B3E88003}\RP7\A0000718.exe Infected: Worm.Win32.Viking.lz skipped C:\System Volume Information\_restore{0B6AB4EA-58AD-4BDF-8C7F-C598B3E88003}\RP7\A0000719.exe Infected: Worm.Win32.Viking.lz skipped C:\System Volume Information\_restore{0B6AB4EA-58AD-4BDF-8C7F-C598B3E88003}\RP7\A0000720.EXE Infected: Worm.Win32.Viking.lz skipped C:\System Volume Information\_restore{0B6AB4EA-58AD-4BDF-8C7F-C598B3E88003}\RP7\A0000721.exe Infected: Worm.Win32.Viking.lz skipped C:\System Volume Information\_restore{0B6AB4EA-58AD-4BDF-8C7F-C598B3E88003}\RP7\A0000722.exe Infected: Worm.Win32.Viking.lz skipped C:\System Volume Information\_restore{0B6AB4EA-58AD-4BDF-8C7F-C598B3E88003}\RP7\A0000723.exe Infected: Worm.Win32.Viking.lz skipped C:\System Volume Information\_restore{0B6AB4EA-58AD-4BDF-8C7F-C598B3E88003}\RP7\A0000724.exe Infected: Worm.Win32.Viking.lz skipped C:\System Volume Information\_restore{0B6AB4EA-58AD-4BDF-8C7F-C598B3E88003}\RP7\A0000725.EXE Infected: Worm.Win32.Viking.lz skipped C:\System Volume Information\_restore{0B6AB4EA-58AD-4BDF-8C7F-C598B3E88003}\RP7\A0000726.EXE Infected: Worm.Win32.Viking.lz skipped C:\System Volume Information\_restore{0B6AB4EA-58AD-4BDF-8C7F-C598B3E88003}\RP7\A0000727.EXE Infected: Worm.Win32.Viking.lz skipped C:\System Volume Information\_restore{0B6AB4EA-58AD-4BDF-8C7F-C598B3E88003}\RP7\A0000728.EXE Infected: Worm.Win32.Viking.lz skipped C:\System Volume Information\_restore{0B6AB4EA-58AD-4BDF-8C7F-C598B3E88003}\RP7\A0000729.EXE Infected: Worm.Win32.Viking.lz skipped C:\System Volume Information\_restore{0B6AB4EA-58AD-4BDF-8C7F-C598B3E88003}\RP7\A0000730.EXE Infected: Worm.Win32.Viking.lz skipped C:\System Volume Information\_restore{0B6AB4EA-58AD-4BDF-8C7F-C598B3E88003}\RP7\A0000731.EXE Infected: Worm.Win32.Viking.lz skipped C:\System Volume Information\_restore{0B6AB4EA-58AD-4BDF-8C7F-C598B3E88003}\RP7\A0000732.EXE Infected: Worm.Win32.Viking.lz skipped C:\System Volume Information\_restore{0B6AB4EA-58AD-4BDF-8C7F-C598B3E88003}\RP7\A0000733.EXE Infected: Worm.Win32.Viking.lz skipped C:\System Volume Information\_restore{0B6AB4EA-58AD-4BDF-8C7F-C598B3E88003}\RP7\A0000734.EXE Infected: Worm.Win32.Viking.lz skipped C:\System Volume Information\_restore{0B6AB4EA-58AD-4BDF-8C7F-C598B3E88003}\RP7\A0000735.EXE Infected: Worm.Win32.Viking.lz skipped C:\System Volume Information\_restore{0B6AB4EA-58AD-4BDF-8C7F-C598B3E88003}\RP7\A0000736.EXE Infected: Worm.Win32.Viking.lz skipped C:\System Volume Information\_restore{0B6AB4EA-58AD-4BDF-8C7F-C598B3E88003}\RP7\A0000737.EXE Infected: Worm.Win32.Viking.lz skipped C:\System Volume Information\_restore{0B6AB4EA-58AD-4BDF-8C7F-C598B3E88003}\RP7\A0000738.EXE Infected: Worm.Win32.Viking.lz skipped C:\System Volume Information\_restore{0B6AB4EA-58AD-4BDF-8C7F-C598B3E88003}\RP7\A0000739.EXE Infected: Worm.Win32.Viking.lz skipped C:\System Volume Information\_restore{0B6AB4EA-58AD-4BDF-8C7F-C598B3E88003}\RP7\A0000740.EXE Infected: Worm.Win32.Viking.lz skipped C:\System Volume Information\_restore{0B6AB4EA-58AD-4BDF-8C7F-C598B3E88003}\RP7\A0000741.EXE Infected: Worm.Win32.Viking.lz skipped C:\System Volume Information\_restore{0B6AB4EA-58AD-4BDF-8C7F-C598B3E88003}\RP7\A0000742.EXE Infected: Worm.Win32.Viking.lz skipped C:\System Volume Information\_restore{0B6AB4EA-58AD-4BDF-8C7F-C598B3E88003}\RP7\A0000743.EXE Infected: Worm.Win32.Viking.lz skipped C:\System Volume Information\_restore{0B6AB4EA-58AD-4BDF-8C7F-C598B3E88003}\RP7\A0000744.EXE Infected: Worm.Win32.Viking.lz skipped C:\System Volume Information\_restore{0B6AB4EA-58AD-4BDF-8C7F-C598B3E88003}\RP7\A0000745.EXE Infected: Worm.Win32.Viking.lz skipped C:\System Volume Information\_restore{0B6AB4EA-58AD-4BDF-8C7F-C598B3E88003}\RP7\A0000746.EXE Infected: Worm.Win32.Viking.lz skipped C:\System Volume Information\_restore{0B6AB4EA-58AD-4BDF-8C7F-C598B3E88003}\RP7\A0000747.EXE Infected: Worm.Win32.Viking.lz skipped C:\System Volume Information\_restore{0B6AB4EA-58AD-4BDF-8C7F-C598B3E88003}\RP7\A0000748.EXE Infected: Worm.Win32.Viking.lz skipped C:\System Volume Information\_restore{0B6AB4EA-58AD-4BDF-8C7F-C598B3E88003}\RP7\A0000749.EXE Infected: Worm.Win32.Viking.lz skipped C:\System Volume Information\_restore{0B6AB4EA-58AD-4BDF-8C7F-C598B3E88003}\RP7\A0000750.EXE Infected: Worm.Win32.Viking.lz skipped C:\System Volume Information\_restore{0B6AB4EA-58AD-4BDF-8C7F-C598B3E88003}\RP7\A0000751.EXE Infected: Worm.Win32.Viking.lz skipped C:\System Volume Information\_restore{0B6AB4EA-58AD-4BDF-8C7F-C598B3E88003}\RP7\A0000752.EXE Infected: Worm.Win32.Viking.lz skipped C:\System Volume Information\_restore{0B6AB4EA-58AD-4BDF-8C7F-C598B3E88003}\RP7\A0000753.EXE Infected: Worm.Win32.Viking.lz skipped C:\System Volume Information\_restore{0B6AB4EA-58AD-4BDF-8C7F-C598B3E88003}\RP7\A0000754.EXE Infected: Worm.Win32.Viking.lz skipped C:\System Volume Information\_restore{0B6AB4EA-58AD-4BDF-8C7F-C598B3E88003}\RP7\A0000755.EXE Infected: Worm.Win32.Viking.lz skipped C:\System Volume Information\_restore{0B6AB4EA-58AD-4BDF-8C7F-C598B3E88003}\RP7\A0000756.EXE Infected: Worm.Win32.Viking.lz skipped C:\System Volume Information\_restore{0B6AB4EA-58AD-4BDF-8C7F-C598B3E88003}\RP7\A0000757.EXE Infected: Worm.Win32.Viking.lz skipped C:\System Volume Information\_restore{0B6AB4EA-58AD-4BDF-8C7F-C598B3E88003}\RP7\A0000758.EXE Infected: Worm.Win32.Viking.lz skipped C:\System Volume Information\_restore{0B6AB4EA-58AD-4BDF-8C7F-C598B3E88003}\RP7\A0000759.EXE Infected: Worm.Win32.Viking.lz skipped C:\System Volume Information\_restore{0B6AB4EA-58AD-4BDF-8C7F-C598B3E88003}\RP7\A0000760.EXE Infected: Worm.Win32.Viking.lz skipped C:\System Volume Information\_restore{0B6AB4EA-58AD-4BDF-8C7F-C598B3E88003}\RP7\A0000761.exe Infected: Worm.Win32.Viking.lz skipped C:\System Volume Information\_restore{0B6AB4EA-58AD-4BDF-8C7F-C598B3E88003}\RP7\A0000762.exe Infected: Worm.Win32.Viking.lz skipped C:\System Volume Information\_restore{0B6AB4EA-58AD-4BDF-8C7F-C598B3E88003}\RP7\A0000763.exe Infected: Worm.Win32.Viking.lz skipped C:\System Volume Information\_restore{0B6AB4EA-58AD-4BDF-8C7F-C598B3E88003}\RP7\A0000764.exe Infected: Worm.Win32.Viking.lz skipped C:\System Volume Information\_restore{0B6AB4EA-58AD-4BDF-8C7F-C598B3E88003}\RP7\A0000765.exe Infected: Worm.Win32.Viking.lz skipped C:\System Volume Information\_restore{0B6AB4EA-58AD-4BDF-8C7F-C598B3E88003}\RP7\A0000766.exe Infected: Worm.Win32.Viking.lz skipped C:\System Volume Information\_restore{0B6AB4EA-58AD-4BDF-8C7F-C598B3E88003}\RP7\A0000767.exe Infected: Worm.Win32.Viking.lz skipped C:\System Volume Information\_restore{0B6AB4EA-58AD-4BDF-8C7F-C598B3E88003}\RP7\A0000768.exe Infected: Worm.Win32.Viking.lz skipped C:\System Volume Information\_restore{0B6AB4EA-58AD-4BDF-8C7F-C598B3E88003}\RP7\A0000769.exe Infected: Worm.Win32.Viking.lz skipped C:\System Volume Information\_restore{0B6AB4EA-58AD-4BDF-8C7F-C598B3E88003}\RP7\A0000770.exe Infected: Worm.Win32.Viking.lz skipped C:\System Volume Information\_restore{0B6AB4EA-58AD-4BDF-8C7F-C598B3E88003}\RP7\A0000771.exe Infected: Worm.Win32.Viking.lz skipped C:\System Volume Information\_restore{0B6AB4EA-58AD-4BDF-8C7F-C598B3E88003}\RP7\A0000772.exe Infected: Worm.Win32.Viking.lz skipped C:\System Volume Information\_restore{0B6AB4EA-58AD-4BDF-8C7F-C598B3E88003}\RP7\A0000773.exe Infected: Worm.Win32.Viking.lz skipped C:\System Volume Information\_restore{0B6AB4EA-58AD-4BDF-8C7F-C598B3E88003}\RP7\A0000774.exe Infected: Worm.Win32.Viking.lz skipped C:\System Volume Information\_restore{0B6AB4EA-58AD-4BDF-8C7F-C598B3E88003}\RP7\A0000775.exe Infected: Worm.Win32.Viking.lz skipped C:\System Volume Information\_restore{0B6AB4EA-58AD-4BDF-8C7F-C598B3E88003}\RP7\A0000776.exe Infected: Worm.Win32.Viking.lz skipped C:\System Volume Information\_restore{0B6AB4EA-58AD-4BDF-8C7F-C598B3E88003}\RP7\A0000777.exe Infected: Worm.Win32.Viking.lz skipped C:\System Volume Information\_restore{0B6AB4EA-58AD-4BDF-8C7F-C598B3E88003}\RP7\A0000778.exe Infected: Worm.Win32.Viking.lz skipped C:\System Volume Information\_restore{0B6AB4EA-58AD-4BDF-8C7F-C598B3E88003}\RP7\A0000779.exe Infected: Worm.Win32.Viking.lz skipped C:\System Volume Information\_restore{0B6AB4EA-58AD-4BDF-8C7F-C598B3E88003}\RP7\A0000780.EXE Infected: Worm.Win32.Viking.lz skipped C:\System Volume Information\_restore{0B6AB4EA-58AD-4BDF-8C7F-C598B3E88003}\RP7\A0000781.exe Infected: Worm.Win32.Viking.lz skipped C:\System Volume Information\_restore{0B6AB4EA-58AD-4BDF-8C7F-C598B3E88003}\RP7\A0000782.exe Infected: Worm.Win32.Viking.lz skipped C:\System Volume Information\_restore{0B6AB4EA-58AD-4BDF-8C7F-C598B3E88003}\RP7\A0000783.exe Infected: Worm.Win32.Viking.lz skipped C:\System Volume Information\_restore{0B6AB4EA-58AD-4BDF-8C7F-C598B3E88003}\RP7\A0000784.EXE Infected: Worm.Win32.Viking.lz skipped C:\System Volume Information\_restore{0B6AB4EA-58AD-4BDF-8C7F-C598B3E88003}\RP7\A0000785.EXE Infected: Worm.Win32.Viking.lz skipped C:\System Volume Information\_restore{0B6AB4EA-58AD-4BDF-8C7F-C598B3E88003}\RP7\A0000786.EXE Infected: Worm.Win32.Viking.lz skipped C:\System Volume Information\_restore{0B6AB4EA-58AD-4BDF-8C7F-C598B3E88003}\RP7\A0000787.exe Infected: Worm.Win32.Viking.lz skipped C:\System Volume Information\_restore{0B6AB4EA-58AD-4BDF-8C7F-C598B3E88003}\RP7\A0000788.exe Infected: Worm.Win32.Viking.lz skipped C:\System Volume Information\_restore{0B6AB4EA-58AD-4BDF-8C7F-C598B3E88003}\RP7\A0000789.exe Infected: Worm.Win32.Viking.lz skipped C:\System Volume Information\_restore{0B6AB4EA-58AD-4BDF-8C7F-C598B3E88003}\RP7\A0000790.exe Infected: Worm.Win32.Viking.lz skipped C:\System Volume Information\_restore{0B6AB4EA-58AD-4BDF-8C7F-C598B3E88003}\RP7\A0000791.exe Infected: Worm.Win32.Viking.lz skipped C:\System Volume Information\_restore{0B6AB4EA-58AD-4BDF-8C7F-C598B3E88003}\RP7\A0000792.exe Infected: Worm.Win32.Viking.lz skipped C:\System Volume Information\_restore{0B6AB4EA-58AD-4BDF-8C7F-C598B3E88003}\RP7\A0000793.exe Infected: Worm.Win32.Viking.lz skipped C:\System Volume Information\_restore{0B6AB4EA-58AD-4BDF-8C7F-C598B3E88003}\RP7\A0000794.exe Infected: Worm.Win32.Viking.lz skipped C:\System Volume Information\_restore{0B6AB4EA-58AD-4BDF-8C7F-C598B3E88003}\RP7\A0000795.exe Infected: Worm.Win32.Viking.lz skipped C:\System Volume Information\_restore{0B6AB4EA-58AD-4BDF-8C7F-C598B3E88003}\RP7\A0000796.exe Infected: Worm.Win32.Viking.lz skipped C:\System Volume Information\_restore{0B6AB4EA-58AD-4BDF-8C7F-C598B3E88003}\RP7\A0000797.exe Infected: Worm.Win32.Viking.lz skipped C:\System Volume Information\_restore{0B6AB4EA-58AD-4BDF-8C7F-C598B3E88003}\RP7\A0000798.exe Infected: Worm.Win32.Viking.lz skipped C:\System Volume Information\_restore{0B6AB4EA-58AD-4BDF-8C7F-C598B3E88003}\RP7\A0000799.exe Infected: Worm.Win32.Viking.lz skipped C:\System Volume Information\_restore{0B6AB4EA-58AD-4BDF-8C7F-C598B3E88003}\RP7\A0000800.exe Infected: Worm.Win32.Viking.lz skipped C:\System Volume Information\_restore{0B6AB4EA-58AD-4BDF-8C7F-C598B3E88003}\RP7\A0000801.exe Infected: Worm.Win32.Viking.lz skipped C:\System Volume Information\_restore{0B6AB4EA-58AD-4BDF-8C7F-C598B3E88003}\RP7\A0000802.exe Infected: Worm.Win32.Viking.lz skipped C:\System Volume Information\_restore{0B6AB4EA-58AD-4BDF-8C7F-C598B3E88003}\RP7\A0000803.exe Infected: Worm.Win32.Viking.lz skipped C:\System Volume Information\_restore{0B6AB4EA-58AD-4BDF-8C7F-C598B3E88003}\RP7\A0000804.exe Infected: Worm.Win32.Viking.lz skipped C:\System Volume Information\_restore{0B6AB4EA-58AD-4BDF-8C7F-C598B3E88003}\RP7\A0000805.exe Infected: Worm.Win32.Viking.lz skipped C:\System Volume Information\_restore{0B6AB4EA-58AD-4BDF-8C7F-C598B3E88003}\RP7\A0000806.exe Infected: Worm.Win32.Viking.lz skipped C:\System Volume Information\_restore{0B6AB4EA-58AD-4BDF-8C7F-C598B3E88003}\RP7\A0000807.exe Infected: Worm.Win32.Viking.lz skipped C:\System Volume Information\_restore{0B6AB4EA-58AD-4BDF-8C7F-C598B3E88003}\RP7\A0000808.exe Infected: Worm.Win32.Viking.lz skipped C:\System Volume Information\_restore{0B6AB4EA-58AD-4BDF-8C7F-C598B3E88003}\RP7\A0000809.exe Infected: Worm.Win32.Viking.lz skipped C:\System Volume Information\_restore{0B6AB4EA-58AD-4BDF-8C7F-C598B3E88003}\RP7\A0000810.exe Infected: Worm.Win32.Viking.lz skipped C:\System Volume Information\_restore{0B6AB4EA-58AD-4BDF-8C7F-C598B3E88003}\RP7\A0000811.exe Infected: Worm.Win32.Viking.lz skipped C:\System Volume Information\_restore{0B6AB4EA-58AD-4BDF-8C7F-C598B3E88003}\RP7\A0000812.exe Infected: Worm.Win32.Viking.lz skipped C:\System Volume Information\_restore{0B6AB4EA-58AD-4BDF-8C7F-C598B3E88003}\RP7\A0000813.exe Infected: Worm.Win32.Viking.lz skipped C:\System Volume Information\_restore{0B6AB4EA-58AD-4BDF-8C7F-C598B3E88003}\RP7\A0000814.exe Infected: Worm.Win32.Viking.lz skipped C:\System Volume Information\_restore{0B6AB4EA-58AD-4BDF-8C7F-C598B3E88003}\RP7\A0000815.exe Infected: Worm.Win32.Viking.lz skipped C:\System Volume Information\_restore{0B6AB4EA-58AD-4BDF-8C7F-C598B3E88003}\RP7\A0000816.exe Infected: Worm.Win32.Viking.lz skipped C:\System Volume Information\_restore{0B6AB4EA-58AD-4BDF-8C7F-C598B3E88003}\RP7\A0000817.exe Infected: Worm.Win32.Viking.lz skipped C:\System Volume Information\_restore{0B6AB4EA-58AD-4BDF-8C7F-C598B3E88003}\RP7\A0000818.exe Infected: Worm.Win32.Viking.lz skipped C:\System Volume Information\_restore{0B6AB4EA-58AD-4BDF-8C7F-C598B3E88003}\RP7\A0000819.exe Infected: Worm.Win32.Viking.lz skipped C:\System Volume Information\_restore{0B6AB4EA-58AD-4BDF-8C7F-C598B3E88003}\RP7\A0000820.exe Infected: Worm.Win32.Viking.lz skipped C:\System Volume Information\_restore{0B6AB4EA-58AD-4BDF-8C7F-C598B3E88003}\RP7\A0000821.exe Infected: Worm.Win32.Viking.lz skipped C:\System Volume Information\_restore{0B6AB4EA-58AD-4BDF-8C7F-C598B3E88003}\RP7\A0000822.exe Infected: Worm.Win32.Viking.lz skipped C:\System Volume Information\_restore{0B6AB4EA-58AD-4BDF-8C7F-C598B3E88003}\RP7\A0000823.exe Infected: Worm.Win32.Viking.lz skipped C:\System Volume Information\_restore{0B6AB4EA-58AD-4BDF-8C7F-C598B3E88003}\RP7\A0000824.exe Infected: Worm.Win32.Viking.lz skipped C:\System Volume Information\_restore{0B6AB4EA-58AD-4BDF-8C7F-C598B3E88003}\RP7\A0000825.exe Infected: Worm.Win32.Viking.lz skipped C:\System Volume Information\_restore{0B6AB4EA-58AD-4BDF-8C7F-C598B3E88003}\RP7\A0000826.exe Infected: Worm.Win32.Viking.lz skipped C:\System Volume Information\_restore{0B6AB4EA-58AD-4BDF-8C7F-C598B3E88003}\RP7\A0000827.exe Infected: Worm.Win32.Viking.lz skipped C:\System Volume Information\_restore{0B6AB4EA-58AD-4BDF-8C7F-C598B3E88003}\RP7\A0000828.exe Infected: Worm.Win32.Viking.lz skipped C:\System Volume Information\_restore{0B6AB4EA-58AD-4BDF-8C7F-C598B3E88003}\RP7\A0000829.exe Infected: Worm.Win32.Viking.lz skipped C:\System Volume Information\_restore{0B6AB4EA-58AD-4BDF-8C7F-C598B3E88003}\RP7\A0000830.exe Infected: Worm.Win32.Viking.lz skipped C:\System Volume Information\_restore{0B6AB4EA-58AD-4BDF-8C7F-C598B3E88003}\RP7\A0000831.exe Infected: Worm.Win32.Viking.lz skipped C:\System Volume Information\_restore{0B6AB4EA-58AD-4BDF-8C7F-C598B3E88003}\RP7\A0000832.exe Infected: Worm.Win32.Viking.lz skipped C:\System Volume Information\_restore{0B6AB4EA-58AD-4BDF-8C7F-C598B3E88003}\RP7\A0000833.exe Infected: Worm.Win32.Viking.lz skipped C:\System Volume Information\_restore{0B6AB4EA-58AD-4BDF-8C7F-C598B3E88003}\RP7\A0000834.exe Infected: Worm.Win32.Viking.lz skipped C:\System Volume Information\_restore{0B6AB4EA-58AD-4BDF-8C7F-C598B3E88003}\RP7\A0000835.exe Infected: Worm.Win32.Viking.lz skipped C:\System Volume Information\_restore{0B6AB4EA-58AD-4BDF-8C7F-C598B3E88003}\RP7\A0000836.exe Infected: Worm.Win32.Viking.lz skipped C:\System Volume Information\_restore{0B6AB4EA-58AD-4BDF-8C7F-C598B3E88003}\RP7\A0000837.exe Infected: Worm.Win32.Viking.lz skipped C:\System Volume Information\_restore{0B6AB4EA-58AD-4BDF-8C7F-C598B3E88003}\RP7\A0000838.exe Infected: Worm.Win32.Viking.lz skipped C:\System Volume Information\_restore{0B6AB4EA-58AD-4BDF-8C7F-C598B3E88003}\RP7\A0000839.exe Infected: Worm.Win32.Viking.lz skipped C:\System Volume Information\_restore{0B6AB4EA-58AD-4BDF-8C7F-C598B3E88003}\RP7\A0000840.exe Infected: Worm.Win32.Viking.lz skipped C:\System Volume Information\_restore{0B6AB4EA-58AD-4BDF-8C7F-C598B3E88003}\RP7\A0000841.exe Infected: Worm.Win32.Viking.lz skipped C:\System Volume Information\_restore{0B6AB4EA-58AD-4BDF-8C7F-C598B3E88003}\RP7\A0000842.exe Infected: Worm.Win32.Viking.lz skipped C:\System Volume Information\_restore{0B6AB4EA-58AD-4BDF-8C7F-C598B3E88003}\RP7\A0000843.exe Infected: Worm.Win32.Viking.lz skipped C:\System Volume Information\_restore{0B6AB4EA-58AD-4BDF-8C7F-C598B3E88003}\RP7\A0000844.exe Infected: Worm.Win32.Viking.lz skipped C:\System Volume Information\_restore{0B6AB4EA-58AD-4BDF-8C7F-C598B3E88003}\RP7\A0000845.exe Infected: Worm.Win32.Viking.lz skipped C:\System Volume Information\_restore{0B6AB4EA-58AD-4BDF-8C7F-C598B3E88003}\RP7\A0000846.exe Infected: Worm.Win32.Viking.lz skipped C:\System Volume Information\_restore{0B6AB4EA-58AD-4BDF-8C7F-C598B3E88003}\RP7\A0000847.exe Infected: Worm.Win32.Viking.lz skipped C:\System Volume Information\_restore{0B6AB4EA-58AD-4BDF-8C7F-C598B3E88003}\RP7\A0000848.exe Infected: Worm.Win32.Viking.lz skipped C:\System Volume Information\_restore{0B6AB4EA-58AD-4BDF-8C7F-C598B3E88003}\RP7\A0000849.exe Infected: Worm.Win32.Viking.lz skipped C:\System Volume Information\_restore{0B6AB4EA-58AD-4BDF-8C7F-C598B3E88003}\RP7\A0000850.exe Infected: Worm.Win32.Viking.lz skipped C:\System Volume Information\_restore{0B6AB4EA-58AD-4BDF-8C7F-C598B3E88003}\RP7\A0000851.exe Infected: Worm.Win32.Viking.lz skipped C:\System Volume Information\_restore{0B6AB4EA-58AD-4BDF-8C7F-C598B3E88003}\RP7\A0000852.exe Infected: Worm.Win32.Viking.lz skipped C:\System Volume Information\_restore{0B6AB4EA-58AD-4BDF-8C7F-C598B3E88003}\RP7\A0000853.exe Infected: Worm.Win32.Viking.lz skipped C:\System Volume Information\_restore{0B6AB4EA-58AD-4BDF-8C7F-C598B3E88003}\RP7\A0000854.exe Infected: Worm.Win32.Viking.lz skipped C:\System Volume Information\_restore{0B6AB4EA-58AD-4BDF-8C7F-C598B3E88003}\RP7\A0000855.exe Infected: Worm.Win32.Viking.lz skipped C:\System Volume Information\_restore{0B6AB4EA-58AD-4BDF-8C7F-C598B3E88003}\RP7\A0000856.exe Infected: Worm.Win32.Viking.lz skipped C:\System Volume Information\_restore{0B6AB4EA-58AD-4BDF-8C7F-C598B3E88003}\RP7\A0000857.exe Infected: Worm.Win32.Viking.lz skipped C:\System Volume Information\_restore{0B6AB4EA-58AD-4BDF-8C7F-C598B3E88003}\RP7\A0000858.exe Infected: Worm.Win32.Viking.lz skipped C:\System Volume Information\_restore{0B6AB4EA-58AD-4BDF-8C7F-C598B3E88003}\RP7\A0000859.exe Infected: Worm.Win32.Viking.lz skipped C:\System Volume Information\_restore{0B6AB4EA-58AD-4BDF-8C7F-C598B3E88003}\RP7\A0000860.exe Infected: Worm.Win32.Viking.lz skipped C:\System Volume Information\_restore{0B6AB4EA-58AD-4BDF-8C7F-C598B3E88003}\RP7\A0000861.exe Infected: Worm.Win32.Viking.lz skipped C:\System Volume Information\_restore{0B6AB4EA-58AD-4BDF-8C7F-C598B3E88003}\RP7\A0000862.exe Infected: Worm.Win32.Viking.lz skipped C:\System Volume Information\_restore{0B6AB4EA-58AD-4BDF-8C7F-C598B3E88003}\RP7\A0000863.exe Infected: Worm.Win32.Viking.lz skipped C:\System Volume Information\_restore{0B6AB4EA-58AD-4BDF-8C7F-C598B3E88003}\RP7\A0000864.exe Infected: Worm.Win32.Viking.lz skipped C:\System Volume Information\_restore{0B6AB4EA-58AD-4BDF-8C7F-C598B3E88003}\RP7\A0000865.exe Infected: Worm.Win32.Viking.lz skipped C:\System Volume Information\_restore{0B6AB4EA-58AD-4BDF-8C7F-C598B3E88003}\RP7\A0000866.exe Infected: Worm.Win32.Viking.lz skipped C:\System Volume Information\_restore{0B6AB4EA-58AD-4BDF-8C7F-C598B3E88003}\RP7\A0000867.exe Infected: Worm.Win32.Viking.lz skipped C:\System Volume Information\_restore{0B6AB4EA-58AD-4BDF-8C7F-C598B3E88003}\RP7\A0000868.exe Infected: Worm.Win32.Viking.lz skipped C:\System Volume Information\_restore{0B6AB4EA-58AD-4BDF-8C7F-C598B3E88003}\RP7\A0000869.exe Infected: Worm.Win32.Viking.lz skipped C:\System Volume Information\_restore{0B6AB4EA-58AD-4BDF-8C7F-C598B3E88003}\RP7\A0000870.exe Infected: Worm.Win32.Viking.lz skipped C:\System Volume Information\_restore{0B6AB4EA-58AD-4BDF-8C7F-C598B3E88003}\RP7\A0000871.exe Infected: Worm.Win32.Viking.lz skipped C:\System Volume Information\_restore{0B6AB4EA-58AD-4BDF-8C7F-C598B3E88003}\RP7\A0000872.exe Infected: Worm.Win32.Viking.lz skipped C:\System Volume Information\_restore{0B6AB4EA-58AD-4BDF-8C7F-C598B3E88003}\RP7\A0000873.EXE Infected: Worm.Win32.Viking.lz skipped C:\System Volume Information\_restore{0B6AB4EA-58AD-4BDF-8C7F-C598B3E88003}\RP7\A0000874.EXE Infected: Worm.Win32.Viking.lz skipped C:\System Volume Information\_restore{0B6AB4EA-58AD-4BDF-8C7F-C598B3E88003}\RP7\A0000875.exe Infected: Worm.Win32.Viking.lz skipped C:\System Volume Information\_restore{0B6AB4EA-58AD-4BDF-8C7F-C598B3E88003}\RP7\A0000876.exe Infected: Worm.Win32.Viking.lz skipped C:\System Volume Information\_restore{0B6AB4EA-58AD-4BDF-8C7F-C598B3E88003}\RP7\A0000877.exe Infected: Worm.Win32.Viking.lz skipped C:\System Volume Information\_restore{0B6AB4EA-58AD-4BDF-8C7F-C598B3E88003}\RP7\A0000878.exe Infected: Worm.Win32.Viking.lz skipped C:\System Volume Information\_restore{0B6AB4EA-58AD-4BDF-8C7F-C598B3E88003}\RP7\A0000879.exe Infected: Worm.Win32.Viking.lz skipped C:\System Volume Information\_restore{0B6AB4EA-58AD-4BDF-8C7F-C598B3E88003}\RP7\A0000880.exe Infected: Worm.Win32.Viking.lz skipped C:\System Volume Information\_restore{0B6AB4EA-58AD-4BDF-8C7F-C598B3E88003}\RP7\A0000881.exe Infected: Worm.Win32.Viking.lz skipped C:\System Volume Information\_restore{0B6AB4EA-58AD-4BDF-8C7F-C598B3E88003}\RP7\A0000882.exe Infected: Worm.Win32.Viking.lz skipped C:\System Volume Information\_restore{0B6AB4EA-58AD-4BDF-8C7F-C598B3E88003}\RP7\A0000883.exe Infected: Worm.Win32.Viking.lz skipped C:\System Volume Information\_restore{0B6AB4EA-58AD-4BDF-8C7F-C598B3E88003}\RP7\A0000884.exe Infected: Worm.Win32.Viking.lz skipped C:\System Volume Information\_restore{0B6AB4EA-58AD-4BDF-8C7F-C598B3E88003}\RP7\A0000885.exe Infected: Worm.Win32.Viking.lz skipped C:\System Volume Information\_restore{0B6AB4EA-58AD-4BDF-8C7F-C598B3E88003}\RP7\A0000886.exe Infected: Worm.Win32.Viking.lz skipped C:\System Volume Information\_restore{0B6AB4EA-58AD-4BDF-8C7F-C598B3E88003}\RP7\A0000887.exe Infected: Worm.Win32.Viking.lz skipped C:\System Volume Information\_restore{0B6AB4EA-58AD-4BDF-8C7F-C598B3E88003}\RP7\A0000888.exe Infected: Worm.Win32.Viking.lz skipped C:\System Volume Information\_restore{0B6AB4EA-58AD-4BDF-8C7F-C598B3E88003}\RP7\A0000889.exe Infected: Worm.Win32.Viking.lz skipped C:\System Volume Information\_restore{0B6AB4EA-58AD-4BDF-8C7F-C598B3E88003}\RP7\A0000890.exe Infected: Worm.Win32.Viking.lz skipped C:\System Volume Information\_restore{0B6AB4EA-58AD-4BDF-8C7F-C598B3E88003}\RP7\A0000891.exe Infected: Worm.Win32.Viking.lz skipped C:\System Volume Information\_restore{0B6AB4EA-58AD-4BDF-8C7F-C598B3E88003}\RP7\A0000892.exe Infected: Worm.Win32.Viking.lz skipped C:\System Volume Information\_restore{0B6AB4EA-58AD-4BDF-8C7F-C598B3E88003}\RP7\A0000893.exe Infected: Worm.Win32.Viking.lz skipped C:\System Volume Information\_restore{0B6AB4EA-58AD-4BDF-8C7F-C598B3E88003}\RP7\A0000894.exe Infected: Worm.Win32.Viking.lz skipped C:\System Volume Information\_restore{0B6AB4EA-58AD-4BDF-8C7F-C598B3E88003}\RP7\A0000895.exe Infected: Worm.Win32.Viking.lz skipped C:\System Volume Information\_restore{0B6AB4EA-58AD-4BDF-8C7F-C598B3E88003}\RP7\A0000896.EXE Infected: Worm.Win32.Viking.lz skipped C:\System Volume Information\_restore{0B6AB4EA-58AD-4BDF-8C7F-C598B3E88003}\RP7\A0000897.exe Infected: Worm.Win32.Viking.lz skipped C:\System Volume Information\_restore{0B6AB4EA-58AD-4BDF-8C7F-C598B3E88003}\RP7\A0000898.EXE Infected: Worm.Win32.Viking.lz skipped C:\System Volume Information\_restore{0B6AB4EA-58AD-4BDF-8C7F-C598B3E88003}\RP7\A0000899.exe Infected: Worm.Win32.Viking.lz skipped C:\System Volume Information\_restore{0B6AB4EA-58AD-4BDF-8C7F-C598B3E88003}\RP7\A0000900.exe Infected: Worm.Win32.Viking.lz skipped C:\System Volume Information\_restore{0B6AB4EA-58AD-4BDF-8C7F-C598B3E88003}\RP7\A0000901.exe Infected: Worm.Win32.Viking.lz skipped C:\System Volume Information\_restore{0B6AB4EA-58AD-4BDF-8C7F-C598B3E88003}\RP7\A0000902.exe Infected: Worm.Win32.Viking.lz skipped C:\System Volume Information\_restore{0B6AB4EA-58AD-4BDF-8C7F-C598B3E88003}\RP7\A0000903.exe Infected: Worm.Win32.Viking.lz skipped C:\System Volume Information\_restore{0B6AB4EA-58AD-4BDF-8C7F-C598B3E88003}\RP7\A0000904.exe Infected: Worm.Win32.Viking.lz skipped C:\System Volume Information\_restore{0B6AB4EA-58AD-4BDF-8C7F-C598B3E88003}\RP7\A0000905.exe Infected: Worm.Win32.Viking.lz skipped C:\System Volume Information\_restore{0B6AB4EA-58AD-4BDF-8C7F-C598B3E88003}\RP7\A0000906.exe Infected: Worm.Win32.Viking.lz skipped C:\System Volume Information\_restore{0B6AB4EA-58AD-4BDF-8C7F-C598B3E88003}\RP7\A0000907.exe Infected: Worm.Win32.Viking.lz skipped C:\System Volume Information\_restore{0B6AB4EA-58AD-4BDF-8C7F-C598B3E88003}\RP7\A0000908.exe Infected: Worm.Win32.Viking.lz skipped C:\System Volume Information\_restore{0B6AB4EA-58AD-4BDF-8C7F-C598B3E88003}\RP7\A0000909.exe Infected: Worm.Win32.Viking.lz skipped C:\System Volume Information\_restore{0B6AB4EA-58AD-4BDF-8C7F-C598B3E88003}\RP7\A0000910.exe Infected: Worm.Win32.Viking.lz skipped C:\System Volume Information\_restore{0B6AB4EA-58AD-4BDF-8C7F-C598B3E88003}\RP7\A0000911.exe Infected: Worm.Win32.Viking.lz skipped C:\System Volume Information\_restore{0B6AB4EA-58AD-4BDF-8C7F-C598B3E88003}\RP7\A0000912.exe Infected: Worm.Win32.Viking.lz skipped C:\System Volume Information\_restore{0B6AB4EA-58AD-4BDF-8C7F-C598B3E88003}\RP7\A0000913.exe Infected: Worm.Win32.Viking.lz skipped C:\System Volume Information\_restore{0B6AB4EA-58AD-4BDF-8C7F-C598B3E88003}\RP7\A0000914.exe Infected: Worm.Win32.Viking.lz skipped C:\System Volume Information\_restore{0B6AB4EA-58AD-4BDF-8C7F-C598B3E88003}\RP7\A0000915.exe Infected: Worm.Win32.Viking.lz skipped C:\System Volume Information\_restore{0B6AB4EA-58AD-4BDF-8C7F-C598B3E88003}\RP7\A0000916.exe Infected: Worm.Win32.Viking.lz skipped C:\System Volume Information\_restore{0B6AB4EA-58AD-4BDF-8C7F-C598B3E88003}\RP7\A0000917.exe Infected: Worm.Win32.Viking.lz skipped C:\System Volume Information\_restore{0B6AB4EA-58AD-4BDF-8C7F-C598B3E88003}\RP7\A0000918.exe Infected: Worm.Win32.Viking.lz skipped C:\System Volume Information\_restore{0B6AB4EA-58AD-4BDF-8C7F-C598B3E88003}\RP7\A0000919.exe Infected: Worm.Win32.Viking.lz skipped C:\System Volume Information\_restore{0B6AB4EA-58AD-4BDF-8C7F-C598B3E88003}\RP7\A0000920.exe Infected: Worm.Win32.Viking.lz skipped C:\System Volume Information\_restore{0B6AB4EA-58AD-4BDF-8C7F-C598B3E88003}\RP7\A0000921.exe Infected: Worm.Win32.Viking.lz skipped C:\System Volume Information\_restore{0B6AB4EA-58AD-4BDF-8C7F-C598B3E88003}\RP7\A0000922.exe Infected: Worm.Win32.Viking.lz skipped C:\System Volume Information\_restore{0B6AB4EA-58AD-4BDF-8C7F-C598B3E88003}\RP7\A0000923.exe Infected: Worm.Win32.Viking.lz skipped C:\System Volume Information\_restore{0B6AB4EA-58AD-4BDF-8C7F-C598B3E88003}\RP7\A0000924.exe Infected: Worm.Win32.Viking.lz skipped C:\System Volume Information\_restore{0B6AB4EA-58AD-4BDF-8C7F-C598B3E88003}\RP7\A0000925.exe Infected: Worm.Win32.Viking.lz skipped C:\System Volume Information\_restore{0B6AB4EA-58AD-4BDF-8C7F-C598B3E88003}\RP7\A0000926.EXE Infected: Worm.Win32.Viking.lz skipped C:\System Volume Information\_restore{0B6AB4EA-58AD-4BDF-8C7F-C598B3E88003}\RP7\A0000927.exe Infected: Worm.Win32.Viking.lz skipped C:\System Volume Information\_restore{0B6AB4EA-58AD-4BDF-8C7F-C598B3E88003}\RP7\A0000928.exe Infected: Worm.Win32.Viking.lz skipped C:\System Volume Information\_restore{0B6AB4EA-58AD-4BDF-8C7F-C598B3E88003}\RP7\A0000929.exe Infected: Worm.Win32.Viking.lz skipped C:\System Volume Information\_restore{0B6AB4EA-58AD-4BDF-8C7F-C598B3E88003}\RP7\A0000930.exe Infected: Worm.Win32.Viking.lz skipped C:\System Volume Information\_restore{0B6AB4EA-58AD-4BDF-8C7F-C598B3E88003}\RP7\A0000931.exe Infected: Worm.Win32.Viking.lz skipped C:\System Volume Information\_restore{0B6AB4EA-58AD-4BDF-8C7F-C598B3E88003}\RP7\A0000932.exe Infected: Worm.Win32.Viking.lz skipped C:\System Volume Information\_restore{0B6AB4EA-58AD-4BDF-8C7F-C598B3E88003}\RP7\A0000933.exe Infected: Worm.Win32.Viking.lz skipped C:\System Volume Information\_restore{0B6AB4EA-58AD-4BDF-8C7F-C598B3E88003}\RP7\A0000934.exe Infected: Worm.Win32.Viking.lz skipped C:\System Volume Information\_restore{0B6AB4EA-58AD-4BDF-8C7F-C598B3E88003}\RP7\A0000935.exe Infected: Worm.Win32.Viking.lz skipped C:\System Volume Information\_restore{0B6AB4EA-58AD-4BDF-8C7F-C598B3E88003}\RP7\A0000936.exe Infected: Worm.Win32.Viking.lz skipped C:\System Volume Information\_restore{0B6AB4EA-58AD-4BDF-8C7F-C598B3E88003}\RP7\A0000937.exe Infected: Worm.Win32.Viking.lz skipped C:\System Volume Information\_restore{0B6AB4EA-58AD-4BDF-8C7F-C598B3E88003}\RP7\A0000938.exe Infected: Worm.Win32.Viking.lz skipped C:\System Volume Information\_restore{0B6AB4EA-58AD-4BDF-8C7F-C598B3E88003}\RP7\A0000939.exe Infected: Worm.Win32.Viking.lz skipped C:\System Volume Information\_restore{0B6AB4EA-58AD-4BDF-8C7F-C598B3E88003}\RP7\A0000940.exe Infected: Worm.Win32.Viking.lz skipped C:\System Volume Information\_restore{0B6AB4EA-58AD-4BDF-8C7F-C598B3E88003}\RP7\A0000941.exe Infected: Worm.Win32.Viking.lz skipped C:\System Volume Information\_restore{0B6AB4EA-58AD-4BDF-8C7F-C598B3E88003}\RP7\A0000942.exe Infected: Worm.Win32.Viking.lz skipped C:\System Volume Information\_restore{0B6AB4EA-58AD-4BDF-8C7F-C598B3E88003}\RP7\A0000943.exe Infected: Worm.Win32.Viking.lz skipped C:\System Volume Information\_restore{0B6AB4EA-58AD-4BDF-8C7F-C598B3E88003}\RP7\A0000944.exe Infected: Worm.Win32.Viking.lz skipped C:\System Volume Information\_restore{0B6AB4EA-58AD-4BDF-8C7F-C598B3E88003}\RP7\A0000945.exe Infected: Worm.Win32.Viking.lz skipped C:\System Volume Information\_restore{0B6AB4EA-58AD-4BDF-8C7F-C598B3E88003}\RP7\A0000946.exe Infected: Worm.Win32.Viking.lz skipped C:\System Volume Information\_restore{0B6AB4EA-58AD-4BDF-8C7F-C598B3E88003}\RP7\A0000947.exe Infected: Worm.Win32.Viking.lz skipped C:\System Volume Information\_restore{0B6AB4EA-58AD-4BDF-8C7F-C598B3E88003}\RP7\A0000948.exe Infected: Worm.Win32.Viking.lz skipped C:\System Volume Information\_restore{0B6AB4EA-58AD-4BDF-8C7F-C598B3E88003}\RP7\A0000949.exe Infected: Worm.Win32.Viking.lz skipped C:\System Volume Information\_restore{0B6AB4EA-58AD-4BDF-8C7F-C598B3E88003}\RP7\A0000950.exe Infected: Worm.Win32.Viking.lz skipped C:\System Volume Information\_restore{0B6AB4EA-58AD-4BDF-8C7F-C598B3E88003}\RP7\A0000951.exe Infected: Worm.Win32.Viking.lz skipped C:\System Volume Information\_restore{0B6AB4EA-58AD-4BDF-8C7F-C598B3E88003}\RP7\A0000952.exe Infected: Worm.Win32.Viking.lz skipped C:\System Volume Information\_restore{0B6AB4EA-58AD-4BDF-8C7F-C598B3E88003}\RP7\A0000953.exe Infected: Worm.Win32.Viking.lz skipped C:\System Volume Information\_restore{0B6AB4EA-58AD-4BDF-8C7F-C598B3E88003}\RP7\A0000954.exe Infected: Worm.Win32.Viking.lz skipped C:\System Volume Information\_restore{0B6AB4EA-58AD-4BDF-8C7F-C598B3E88003}\RP7\A0000955.exe Infected: Worm.Win32.Viking.lz skipped C:\System Volume Information\_restore{0B6AB4EA-58AD-4BDF-8C7F-C598B3E88003}\RP7\A0000956.exe Infected: Worm.Win32.Viking.lz skipped C:\System Volume Information\_restore{0B6AB4EA-58AD-4BDF-8C7F-C598B3E88003}\RP7\A0000957.exe Infected: Worm.Win32.Viking.lz skipped C:\System Volume Information\_restore{0B6AB4EA-58AD-4BDF-8C7F-C598B3E88003}\RP7\A0000958.exe Infected: Worm.Win32.Viking.lz skipped C:\System Volume Information\_restore{0B6AB4EA-58AD-4BDF-8C7F-C598B3E88003}\RP7\A0000959.exe Infected: Worm.Win32.Viking.lz skipped C:\System Volume Information\_restore{0B6AB4EA-58AD-4BDF-8C7F-C598B3E88003}\RP7\A0000960.exe Infected: Worm.Win32.Viking.lz skipped C:\System Volume Information\_restore{0B6AB4EA-58AD-4BDF-8C7F-C598B3E88003}\RP7\A0000961.exe Infected: Worm.Win32.Viking.lz skipped C:\System Volume Information\_restore{0B6AB4EA-58AD-4BDF-8C7F-C598B3E88003}\RP7\A0000962.exe Infected: Worm.Win32.Viking.lz skipped C:\System Volume Information\_restore{0B6AB4EA-58AD-4BDF-8C7F-C598B3E88003}\RP7\A0000963.exe Infected: Worm.Win32.Viking.lz skipped C:\System Volume Information\_restore{0B6AB4EA-58AD-4BDF-8C7F-C598B3E88003}\RP7\A0000964.exe Infected: Worm.Win32.Viking.lz skipped C:\System Volume Information\_restore{0B6AB4EA-58AD-4BDF-8C7F-C598B3E88003}\RP7\A0000965.exe Infected: Worm.Win32.Viking.lz skipped C:\System Volume Information\_restore{0B6AB4EA-58AD-4BDF-8C7F-C598B3E88003}\RP7\A0000966.exe Infected: Worm.Win32.Viking.lz skipped C:\System Volume Information\_restore{0B6AB4EA-58AD-4BDF-8C7F-C598B3E88003}\RP7\A0000967.exe Infected: Worm.Win32.Viking.lz skipped C:\System Volume Information\_restore{0B6AB4EA-58AD-4BDF-8C7F-C598B3E88003}\RP7\A0000968.exe Infected: Worm.Win32.Viking.lz skipped C:\System Volume Information\_restore{0B6AB4EA-58AD-4BDF-8C7F-C598B3E88003}\RP7\A0000969.exe Infected: Worm.Win32.Viking.lz skipped C:\System Volume Information\_restore{0B6AB4EA-58AD-4BDF-8C7F-C598B3E88003}\RP7\A0000970.exe Infected: Worm.Win32.Viking.lz skipped C:\System Volume Information\_restore{0B6AB4EA-58AD-4BDF-8C7F-C598B3E88003}\RP7\A0000971.exe Infected: Worm.Win32.Viking.lz skipped C:\System Volume Information\_restore{0B6AB4EA-58AD-4BDF-8C7F-C598B3E88003}\RP7\A0000972.exe Infected: Worm.Win32.Viking.lz skipped C:\System Volume Information\_restore{0B6AB4EA-58AD-4BDF-8C7F-C598B3E88003}\RP7\A0000973.exe Infected: Worm.Win32.Viking.lz skipped C:\System Volume Information\_restore{0B6AB4EA-58AD-4BDF-8C7F-C598B3E88003}\RP7\A0000974.exe Infected: Worm.Win32.Viking.lz skipped C:\System Volume Information\_restore{0B6AB4EA-58AD-4BDF-8C7F-C598B3E88003}\RP7\A0000975.exe Infected: Worm.Win32.Viking.lz skipped C:\System Volume Information\_restore{0B6AB4EA-58AD-4BDF-8C7F-C598B3E88003}\RP7\A0000976.exe Infected: Worm.Win32.Viking.lz skipped C:\System Volume Information\_restore{0B6AB4EA-58AD-4BDF-8C7F-C598B3E88003}\RP7\A0000977.exe Infected: Worm.Win32.Viking.lz skipped C:\System Volume Information\_restore{0B6AB4EA-58AD-4BDF-8C7F-C598B3E88003}\RP7\A0000978.EXE Infected: Worm.Win32.Viking.lz skipped C:\System Volume Information\_restore{0B6AB4EA-58AD-4BDF-8C7F-C598B3E88003}\RP7\A0000979.exe Infected: Worm.Win32.Viking.lz skipped C:\System Volume Information\_restore{0B6AB4EA-58AD-4BDF-8C7F-C598B3E88003}\RP7\A0000980.exe Infected: Worm.Win32.Viking.lz skipped C:\System Volume Information\_restore{0B6AB4EA-58AD-4BDF-8C7F-C598B3E88003}\RP7\A0000981.exe Infected: Worm.Win32.Viking.lz skipped C:\System Volume Information\_restore{0B6AB4EA-58AD-4BDF-8C7F-C598B3E88003}\RP7\A0000982.exe Infected: Worm.Win32.Viking.lz skipped C:\System Volume Information\_restore{0B6AB4EA-58AD-4BDF-8C7F-C598B3E88003}\RP7\A0000983.exe Infected: Worm.Win32.Viking.lz skipped C:\System Volume Information\_restore{0B6AB4EA-58AD-4BDF-8C7F-C598B3E88003}\RP7\A0000984.exe Infected: Worm.Win32.Viking.lz skipped C:\System Volume Information\_restore{0B6AB4EA-58AD-4BDF-8C7F-C598B3E88003}\RP7\A0000985.EXE Infected: Worm.Win32.Viking.lz skipped C:\System Volume Information\_restore{0B6AB4EA-58AD-4BDF-8C7F-C598B3E88003}\RP7\A0000986.EXE Infected: Worm.Win32.Viking.lz skipped C:\System Volume Information\_restore{0B6AB4EA-58AD-4BDF-8C7F-C598B3E88003}\RP7\A0000987.EXE Infected: Worm.Win32.Viking.lz skipped C:\System Volume Information\_restore{0B6AB4EA-58AD-4BDF-8C7F-C598B3E88003}\RP7\A0000988.exe Infected: Worm.Win32.Viking.lz skipped C:\System Volume Information\_restore{0B6AB4EA-58AD-4BDF-8C7F-C598B3E88003}\RP7\A0000989.EXE Infected: Worm.Win32.Viking.lz skipped C:\System Volume Information\_restore{0B6AB4EA-58AD-4BDF-8C7F-C598B3E88003}\RP7\A0000990.exe Infected: Worm.Win32.Viking.lz skipped C:\System Volume Information\_restore{0B6AB4EA-58AD-4BDF-8C7F-C598B3E88003}\RP7\A0000991.exe Infected: Worm.Win32.Viking.lz skipped C:\System Volume Information\_restore{0B6AB4EA-58AD-4BDF-8C7F-C598B3E88003}\RP7\A0000992.exe Infected: Worm.Win32.Viking.lz skipped C:\System Volume Information\_restore{0B6AB4EA-58AD-4BDF-8C7F-C598B3E88003}\RP7\A0000993.exe Infected: Worm.Win32.Viking.lz skipped C:\System Volume Information\_restore{0B6AB4EA-58AD-4BDF-8C7F-C598B3E88003}\RP7\A0000994.exe Infected: Worm.Win32.Viking.lz skipped C:\System Volume Information\_restore{0B6AB4EA-58AD-4BDF-8C7F-C598B3E88003}\RP7\A0000995.exe Infected: Worm.Win32.Viking.lz skipped C:\System Volume Information\_restore{0B6AB4EA-58AD-4BDF-8C7F-C598B3E88003}\RP7\A0000996.exe Infected: Worm.Win32.Viking.lz skipped C:\System Volume Information\_restore{0B6AB4EA-58AD-4BDF-8C7F-C598B3E88003}\RP7\A0000997.exe Infected: Worm.Win32.Viking.lz skipped C:\System Volume Information\_restore{0B6AB4EA-58AD-4BDF-8C7F-C598B3E88003}\RP7\A0000998.exe Infected: Worm.Win32.Viking.lz skipped C:\System Volume Information\_restore{0B6AB4EA-58AD-4BDF-8C7F-C598B3E88003}\RP7\A0000999.exe Infected: Worm.Win32.Viking.lz skipped C:\System Volume Information\_restore{0B6AB4EA-58AD-4BDF-8C7F-C598B3E88003}\RP7\A0001000.exe Infected: Worm.Win32.Viking.lz skipped C:\System Volume Information\_restore{0B6AB4EA-58AD-4BDF-8C7F-C598B3E88003}\RP7\A0001001.exe Infected: Worm.Win32.Viking.lz skipped C:\System Volume Information\_restore{0B6AB4EA-58AD-4BDF-8C7F-C598B3E88003}\RP7\A0001002.exe Infected: Worm.Win32.Viking.lz skipped C:\System Volume Information\_restore{0B6AB4EA-58AD-4BDF-8C7F-C598B3E88003}\RP7\A0001003.exe Infected: Worm.Win32.Viking.lz skipped C:\System Volume Information\_restore{0B6AB4EA-58AD-4BDF-8C7F-C598B3E88003}\RP7\A0001004.exe Infected: Worm.Win32.Viking.lz skipped C:\System Volume Information\_restore{0B6AB4EA-58AD-4BDF-8C7F-C598B3E88003}\RP7\A0001005.exe Infected: Worm.Win32.Viking.lz skipped C:\System Volume Information\_restore{0B6AB4EA-58AD-4BDF-8C7F-C598B3E88003}\RP7\A0001006.exe Infected: Worm.Win32.Viking.lz skipped C:\System Volume Information\_restore{0B6AB4EA-58AD-4BDF-8C7F-C598B3E88003}\RP7\A0001007.exe Infected: Worm.Win32.Viking.lz skipped C:\System Volume Information\_restore{0B6AB4EA-58AD-4BDF-8C7F-C598B3E88003}\RP7\A0001008.exe Infected: Worm.Win32.Viking.lz skipped C:\System Volume Information\_restore{0B6AB4EA-58AD-4BDF-8C7F-C598B3E88003}\RP7\A0001009.exe Infected: Worm.Win32.Viking.lz skipped C:\System Volume Information\_restore{0B6AB4EA-58AD-4BDF-8C7F-C598B3E88003}\RP7\A0001010.exe Infected: Worm.Win32.Viking.lz skipped C:\System Volume Information\_restore{0B6AB4EA-58AD-4BDF-8C7F-C598B3E88003}\RP7\A0001011.exe Infected: Worm.Win32.Viking.lz skipped C:\System Volume Information\_restore{0B6AB4EA-58AD-4BDF-8C7F-C598B3E88003}\RP7\A0001012.exe Infected: Worm.Win32.Viking.lz skipped C:\System Volume Information\_restore{0B6AB4EA-58AD-4BDF-8C7F-C598B3E88003}\RP7\A0001013.exe Infected: Worm.Win32.Viking.lz skipped C:\System Volume Information\_restore{0B6AB4EA-58AD-4BDF-8C7F-C598B3E88003}\RP7\A0001014.exe Infected: Worm.Win32.Viking.lz skipped C:\System Volume Information\_restore{0B6AB4EA-58AD-4BDF-8C7F-C598B3E88003}\RP7\A0001015.exe Infected: Worm.Win32.Viking.lz skipped C:\System Volume Information\_restore{0B6AB4EA-58AD-4BDF-8C7F-C598B3E88003}\RP7\A0001016.exe Infected: Worm.Win32.Viking.lz skipped C:\System Volume Information\_restore{0B6AB4EA-58AD-4BDF-8C7F-C598B3E88003}\RP7\A0001017.exe Infected: Worm.Win32.Viking.lz skipped C:\System Volume Information\_restore{0B6AB4EA-58AD-4BDF-8C7F-C598B3E88003}\RP7\A0001018.exe Infected: Worm.Win32.Viking.lz skipped C:\System Volume Information\_restore{0B6AB4EA-58AD-4BDF-8C7F-C598B3E88003}\RP7\A0001019.exe Infected: Worm.Win32.Viking.lz skipped C:\System Volume Information\_restore{0B6AB4EA-58AD-4BDF-8C7F-C598B3E88003}\RP7\A0001020.exe Infected: Worm.Win32.Viking.lz skipped C:\System Volume Information\_restore{0B6AB4EA-58AD-4BDF-8C7F-C598B3E88003}\RP7\A0001021.exe Infected: Worm.Win32.Viking.lz skipped C:\System Volume Information\_restore{0B6AB4EA-58AD-4BDF-8C7F-C598B3E88003}\RP7\A0001022.exe Infected: Worm.Win32.Viking.lz skipped C:\System Volume Information\_restore{0B6AB4EA-58AD-4BDF-8C7F-C598B3E88003}\RP7\A0001023.exe Infected: Worm.Win32.Viking.lz skipped C:\System Volume Information\_restore{0B6AB4EA-58AD-4BDF-8C7F-C598B3E88003}\RP7\A0001024.exe Infected: Worm.Win32.Viking.lz skipped C:\System Volume Information\_restore{0B6AB4EA-58AD-4BDF-8C7F-C598B3E88003}\RP7\A0001025.exe Infected: Worm.Win32.Viking.lz skipped C:\System Volume Information\_restore{0B6AB4EA-58AD-4BDF-8C7F-C598B3E88003}\RP7\A0001026.EXE Infected: Worm.Win32.Viking.lz skipped C:\System Volume Information\_restore{0B6AB4EA-58AD-4BDF-8C7F-C598B3E88003}\RP7\A0001027.exe Infected: Worm.Win32.Viking.lz skipped C:\System Volume Information\_restore{0B6AB4EA-58AD-4BDF-8C7F-C598B3E88003}\RP7\A0001028.exe Infected: Trojan-PSW.Win32.OnLineGames.box skipped C:\System Volume Information\_restore{0B6AB4EA-58AD-4BDF-8C7F-C598B3E88003}\RP7\A0001029.exe Infected: Trojan-PSW.Win32.Delf.aaw skipped C:\System Volume Information\_restore{0B6AB4EA-58AD-4BDF-8C7F-C598B3E88003}\RP7\A0001030.EXE Infected: Worm.Win32.Viking.lz skipped C:\System Volume Information\_restore{0B6AB4EA-58AD-4BDF-8C7F-C598B3E88003}\RP7\A0001031.EXE Infected: Worm.Win32.Viking.lz skipped C:\System Volume Information\_restore{0B6AB4EA-58AD-4BDF-8C7F-C598B3E88003}\RP7\A0001032.EXE Infected: Worm.Win32.Viking.lz skipped C:\System Volume Information\_restore{0B6AB4EA-58AD-4BDF-8C7F-C598B3E88003}\RP7\A0001033.EXE Infected: Worm.Win32.Viking.lz skipped C:\System Volume Information\_restore{0B6AB4EA-58AD-4BDF-8C7F-C598B3E88003}\RP7\A0001034.EXE Infected: Worm.Win32.Viking.lz skipped C:\System Volume Information\_restore{0B6AB4EA-58AD-4BDF-8C7F-C598B3E88003}\RP7\A0001035.EXE Infected: Worm.Win32.Viking.lz skipped C:\System Volume Information\_restore{0B6AB4EA-58AD-4BDF-8C7F-C598B3E88003}\RP7\A0001036.EXE Infected: Worm.Win32.Viking.lz skipped C:\System Volume Information\_restore{0B6AB4EA-58AD-4BDF-8C7F-C598B3E88003}\RP7\A0001037.EXE Infected: Worm.Win32.Viking.lz skipped C:\System Volume Information\_restore{0B6AB4EA-58AD-4BDF-8C7F-C598B3E88003}\RP7\A0001038.EXE Infected: Worm.Win32.Viking.lz skipped C:\System Volume Information\_restore{0B6AB4EA-58AD-4BDF-8C7F-C598B3E88003}\RP7\A0001039.EXE Infected: Worm.Win32.Viking.lz skipped C:\System Volume Information\_restore{0B6AB4EA-58AD-4BDF-8C7F-C598B3E88003}\RP7\A0001040.EXE Infected: Worm.Win32.Viking.lz skipped C:\System Volume Information\_restore{0B6AB4EA-58AD-4BDF-8C7F-C598B3E88003}\RP7\A0001041.exe Infected: Worm.Win32.Viking.lz skipped C:\System Volume Information\_restore{0B6AB4EA-58AD-4BDF-8C7F-C598B3E88003}\RP7\A0001042.sys Infected: Trojan-Downloader.Win32.Small.czl skipped C:\System Volume Information\_restore{0B6AB4EA-58AD-4BDF-8C7F-C598B3E88003}\RP7\A0001043.exe Infected: Trojan-PSW.Win32.Agent.pl skipped C:\System Volume Information\_restore{0B6AB4EA-58AD-4BDF-8C7F-C598B3E88003}\RP7\A0001044.exe Infected: Trojan-PSW.Win32.OnLineGames.bou skipped C:\System Volume Information\_restore{0B6AB4EA-58AD-4BDF-8C7F-C598B3E88003}\RP7\A0001045.exe Infected: Trojan-Spy.Win32.Delf.ago skipped C:\System Volume Information\_restore{0B6AB4EA-58AD-4BDF-8C7F-C598B3E88003}\RP7\A0001046.exe Infected: Trojan-Spy.Win32.Delf.agk skipped C:\System Volume Information\_restore{0B6AB4EA-58AD-4BDF-8C7F-C598B3E88003}\RP7\A0001047.exe Infected: Trojan-PSW.Win32.OnLineGames.blb skipped C:\System Volume Information\_restore{0B6AB4EA-58AD-4BDF-8C7F-C598B3E88003}\RP7\A0001048.exe Infected: Backdoor.Win32.Agent.alh skipped C:\System Volume Information\_restore{0B6AB4EA-58AD-4BDF-8C7F-C598B3E88003}\RP7\A0001049.exe Infected: Trojan-PSW.Win32.OnLineGames.blx skipped C:\System Volume Information\_restore{0B6AB4EA-58AD-4BDF-8C7F-C598B3E88003}\RP7\A0001050.exe Infected: Trojan-PSW.Win32.OnLineGames.bmj skipped C:\System Volume Information\_restore{0B6AB4EA-58AD-4BDF-8C7F-C598B3E88003}\RP7\A0001051.exe Infected: Trojan-Downloader.Win32.Small.czl skipped C:\System Volume Information\_restore{0B6AB4EA-58AD-4BDF-8C7F-C598B3E88003}\RP7\A0001052.exe Infected: Trojan-Spy.Win32.Delf.abi skipped C:\System Volume Information\_restore{0B6AB4EA-58AD-4BDF-8C7F-C598B3E88003}\RP7\A0001053.exe Infected: Trojan-Spy.Win32.Delf.ach skipped C:\System Volume Information\_restore{0B6AB4EA-58AD-4BDF-8C7F-C598B3E88003}\RP7\A0001054.exe Infected: Worm.Win32.Viking.lz skipped C:\System Volume Information\_restore{0B6AB4EA-58AD-4BDF-8C7F-C598B3E88003}\RP7\A0001055.dll Infected: Trojan-PSW.Win32.OnLineGames.box skipped C:\System Volume Information\_restore{0B6AB4EA-58AD-4BDF-8C7F-C598B3E88003}\RP7\A0001056.exe Infected: Trojan-PSW.Win32.Delf.aaw skipped C:\System Volume Information\_restore{0B6AB4EA-58AD-4BDF-8C7F-C598B3E88003}\RP7\A0001057.exe Infected: Trojan-PSW.Win32.OnLineGames.box skipped C:\System Volume Information\_restore{0B6AB4EA-58AD-4BDF-8C7F-C598B3E88003}\RP7\A0001060.exe Infected: Trojan-PSW.Win32.OnLineGames.bgr skipped C:\System Volume Information\_restore{0B6AB4EA-58AD-4BDF-8C7F-C598B3E88003}\RP7\A0001061.exe Infected: Trojan-PSW.Win32.OnLineGames.bwr skipped C:\System Volume Information\_restore{0B6AB4EA-58AD-4BDF-8C7F-C598B3E88003}\RP7\A0001062.exe Infected: Trojan-PSW.Win32.OnLineGames.cfq skipped C:\System Volume Information\_restore{0B6AB4EA-58AD-4BDF-8C7F-C598B3E88003}\RP7\snapshot\MFEX-1.DAT Infected: Trojan-PSW.Win32.OnLineGames.bmt skipped C:\System Volume Information\_restore{0B6AB4EA-58AD-4BDF-8C7F-C598B3E88003}\RP7\snapshot\MFEX-2.DAT Infected: Trojan-Dropper.Win32.Agent.bvh skipped C:\System Volume Information\_restore{0B6AB4EA-58AD-4BDF-8C7F-C598B3E88003}\RP8\snapshot\MFEX-1.DAT Infected: Trojan-PSW.Win32.OnLineGames.bmt skipped C:\System Volume Information\_restore{0B6AB4EA-58AD-4BDF-8C7F-C598B3E88003}\RP8\snapshot\MFEX-2.DAT Infected: Trojan-Dropper.Win32.Agent.bvh skipped C:\System Volume Information\_restore{0B6AB4EA-58AD-4BDF-8C7F-C598B3E88003}\RP9\A0002083.DLL Infected: Trojan-PSW.Win32.OnLineGames.cyk skipped C:\System Volume Information\_restore{0B6AB4EA-58AD-4BDF-8C7F-C598B3E88003}\RP9\A0002088.dll Infected: Trojan-PSW.Win32.OnLineGames.cdv skipped C:\System Volume Information\_restore{0B6AB4EA-58AD-4BDF-8C7F-C598B3E88003}\RP9\A0002089.dll Infected: Worm.Win32.Viking.lz skipped C:\System Volume Information\_restore{0B6AB4EA-58AD-4BDF-8C7F-C598B3E88003}\RP9\A0002090.EXE Infected: Trojan-PSW.Win32.OnLineGames.bmt skipped C:\System Volume Information\_restore{0B6AB4EA-58AD-4BDF-8C7F-C598B3E88003}\RP9\A0002091.DLL Infected: Trojan-PSW.Win32.OnLineGames.bmu skipped C:\System Volume Information\_restore{0B6AB4EA-58AD-4BDF-8C7F-C598B3E88003}\RP9\A0002092.DLL Infected: Trojan-PSW.Win32.OnLineGames.bmv skipped C:\System Volume Information\_restore{0B6AB4EA-58AD-4BDF-8C7F-C598B3E88003}\RP9\A0002093.dll Infected: Trojan-PSW.Win32.OnLineGames.cdz skipped C:\System Volume Information\_restore{0B6AB4EA-58AD-4BDF-8C7F-C598B3E88003}\RP9\snapshot\MFEX-1.DAT Infected: Trojan-PSW.Win32.OnLineGames.bmt skipped C:\System Volume Information\_restore{0B6AB4EA-58AD-4BDF-8C7F-C598B3E88003}\RP9\snapshot\MFEX-2.DAT Infected: Trojan-Dropper.Win32.Agent.bvh skipped C:\WINDOWS\Debug\oakley.log Object is locked skipped C:\WINDOWS\Debug\PASSWD.LOG Object is locked skipped C:\WINDOWS\SchedLgU.Txt Object is locked skipped C:\WINDOWS\Sti_Trace.log Object is locked skipped C:\WINDOWS\system32\config\AppEvent.Evt Object is locked skipped C:\WINDOWS\system32\config\default Object is locked skipped C:\WINDOWS\system32\config\default.LOG Object is locked skipped C:\WINDOWS\system32\config\SAM Object is locked skipped C:\WINDOWS\system32\config\SAM.LOG Object is locked skipped C:\WINDOWS\system32\config\SecEvent.Evt Object is locked skipped C:\WINDOWS\system32\config\SECURITY Object is locked skipped C:\WINDOWS\system32\config\SECURITY.LOG Object is locked skipped C:\WINDOWS\system32\config\software Object is locked skipped C:\WINDOWS\system32\config\software.LOG Object is locked skipped C:\WINDOWS\system32\config\SysEvent.Evt Object is locked skipped C:\WINDOWS\system32\config\system Object is locked skipped C:\WINDOWS\system32\config\system.LOG Object is locked skipped C:\WINDOWS\system32\h323log.txt Object is locked skipped C:\WINDOWS\system32\wbem\Repository\FS\INDEX.BTR Object is locked skipped C:\WINDOWS\system32\wbem\Repository\FS\OBJECTS.DATA Object is locked skipped C:\WINDOWS\wiadebug.log Object is locked skipped C:\WINDOWS\wiaservc.log Object is locked skipped D:\Avenger\vqrycmb.exe Object is locked skipped D:\System Volume Information\_restore{0B6AB4EA-58AD-4BDF-8C7F-C598B3E88003}\RP10\A0002280.exe Infected: Virus.Win32.AutoRun.ao skipped D:\System Volume Information\_restore{0B6AB4EA-58AD-4BDF-8C7F-C598B3E88003}\RP11\A0002337.exe Infected: Virus.Win32.AutoRun.ao skipped D:\System Volume Information\_restore{0B6AB4EA-58AD-4BDF-8C7F-C598B3E88003}\RP11\A0002338.com Infected: Trojan-Spy.Win32.Pophot.mi skipped D:\System Volume Information\_restore{0B6AB4EA-58AD-4BDF-8C7F-C598B3E88003}\RP21\change.log Object is locked skipped D:\System Volume Information\_restore{0B6AB4EA-58AD-4BDF-8C7F-C598B3E88003}\RP21\A0004321.exe Infected: Virus.Win32.AutoRun.ao skipped Scan process completed.
de reason why i wanted to replace norton was because it has been irritating me with updates as mine was a version that came along with my computer. on top of that, lately it has been giving me reports of the same virus ever since i started seeking for help. while scanning using kaspersky, de same error message popped up. it indicated dat there was a virus called bloodhound.w32.ep at de destination (D:/Avenger/vqrycmb.exe). de same error message popped up a few times. also, my problems started after i was prompted by my computer to download norton. i'm not sure if there's a link but i'm just telling u to let u know more.
________________________________________
Open notepad and copy/paste the text in the quotebox below into it:

Folder::
D:/Avenger






Save this as CFScript.txt, in the same location as ComboFix.exe


[external image: Posted Image]

Refering to the picture above, drag CFScript into ComboFix.exe

When finished, it shall produce a log for you at C:ComboFix.txt which I will need in your next reply.

That should be the end of Nortons annoying you about that virus..

____________________________________

Navigate to and delete the contents of this folder.



C:\Documents and Settings\Owner\.housecall6.6\Quarantine

By clicking on edit /select all/delete.
Don't delete the folder itself.




____________________________

If you would like to uninstall Nortons and try another free anti virus program I can recommend 2 very nice ones for you..
But Nortons has to be uninstalled first.
Let me know what you want to do.

__________________________________________

Post the comboFix log and a new HJT log.

_________________________________

Feel free to run CCleaner weekly or more if you think you need to. It won't hurt anything.
ComboFix 07-09-17.2 - "Owner" 2007-10-03 21:30:35.6 - NTFSx86
Microsoft Windows XP Home Edition 5.1.2600.1.1252.1.1033.18.43 [GMT 8:00]
* Created a new restore point
.

((((((((((((((((((((((((( Files Created from 2007-09-03 to 2007-10-03 )))))))))))))))))))))))))))))))
.

2007-09-30 17:53 208,896 –a—— C:\WINDOWS\system32\wmpns.dll
2007-09-27 23:28 d——– C:\DOCUME~1\Owner\APPLIC~1\Apple Computer
2007-09-23 17:49 d——– C:\DOCUME~1\Owner\Contacts
2007-09-23 17:48 d—-c— C:\WINDOWS\system32\DRVSTORE
2007-09-23 17:48 d——– C:\Program Files\MSN Messenger
2007-09-20 20:12 d——– C:\Program Files\Microsoft ActiveSync
2007-09-20 19:55 d——– C:\DOCUME~1\Owner\APPLIC~1\MSN6
2007-09-20 19:55 d——– C:\DOCUME~1\ALLUSE~1\APPLIC~1\MSN6
2007-09-18 21:44 d——– C:\WINDOWS\system32\Kaspersky Lab
2007-09-18 21:44 d——– C:\DOCUME~1\ALLUSE~1\APPLIC~1\Kaspersky Lab
2007-09-18 21:39 d——– C:\Program Files\CCleaner
2007-09-17 23:31 51,200 –a—— C:\WINDOWS\NirCmd.exe
2007-09-09 22:34 76,560 –a—— C:\WINDOWS\system32\drivers\tmcomm.sys
2007-09-09 20:54 d——– C:\DOCUME~1\ALLUSE~1\APPLIC~1\WinZip
2007-09-09 20:01 d——– C:\Program Files\Common Files\Panda Software
2007-09-09 19:24 d——– C:\DOCUME~1\Owner\.housecall6.6
2007-09-09 18:18 d——– C:\WINDOWS\DED53B0BB67C4244AE6AD6FD3C28D1EF.TMP
2007-09-09 15:33 d——– C:\Program Files\Lavasoft
2007-09-09 15:33 d——– C:\DOCUME~1\ALLUSE~1\APPLIC~1\Lavasoft
2007-09-09 15:31 d——– C:\Program Files\Common Files\Wise Installation Wizard
2007-09-09 14:57 d——– C:\DOCUME~1\ALLUSE~1\APPLIC~1\Spybot - Search & Destroy
2007-09-09 14:51 d——– C:\Program Files\Trend Micro
2007-09-09 13:54 d—s—- C:\DOCUME~1\Owner\UserData
2007-09-08 22:39 182,880 –a–c— C:\WINDOWS\system32\dllcache\iuengine.dll
2007-09-08 22:39 182,880 –a—— C:\WINDOWS\system32\iuengine.dll
2007-09-08 22:19 17,920 –a—— C:\WINDOWS\system32\mdimon.dll
2007-09-08 22:16 d——– C:\Program Files\Common Files\L&H
2007-09-08 22:14 d——– C:\WINDOWS\SHELLNEW
2007-09-08 22:13 d——– C:\Program Files\Microsoft.NET
2007-09-08 22:11 dr-h—– C:\MSOCache
2007-09-08 22:08 51,056 -ra—— C:\WINDOWS\system32\drivers\hpzid412.sys
2007-09-08 22:08 21,760 –a–c— C:\WINDOWS\system32\dllcache\usbstor.sys
2007-09-08 22:08 16,496 -ra—— C:\WINDOWS\system32\drivers\HPZipr12.sys
2007-09-08 22:07 28,160 –a–c— C:\WINDOWS\system32\dllcache\usbccgp.sys
2007-09-08 22:07 28,160 –a—— C:\WINDOWS\system32\drivers\usbccgp.sys
2007-09-08 22:07 24,960 –a–c— C:\WINDOWS\system32\dllcache\usbprint.sys
2007-09-08 22:07 24,960 –a—— C:\WINDOWS\system32\drivers\usbprint.sys
2007-09-08 22:07 21,488 -ra—— C:\WINDOWS\system32\drivers\HPZius12.sys
2007-09-08 22:07 14,208 –a–c— C:\WINDOWS\system32\dllcache\usbscan.sys
2007-09-08 22:07 14,208 –a—— C:\WINDOWS\system32\drivers\usbscan.sys
2007-09-08 22:03 626,960 -ra—— C:\WINDOWS\system32\hpvaut32.dll
2007-09-08 22:03 487,424 -ra—— C:\WINDOWS\system32\hpvcp70.dll
2007-09-08 22:03 44,544 -ra—— C:\WINDOWS\system32\MSXML4a.dll
2007-09-08 22:03 344,064 -ra—— C:\WINDOWS\system32\hpvcr70.dll
2007-09-08 22:02 d——– C:\Program Files\Common Files\Hewlett-Packard
2007-09-08 21:59 43,488 –a—— C:\WINDOWS\system32\drivers\AFS2K.SYS
2007-09-08 21:59 d——– C:\Program Files\Common Files\HP
2007-09-08 21:55 34,383 ——— C:\WINDOWS\hpomdl03.dat
2007-09-08 21:55 28,886 –a—— C:\WINDOWS\hpoins03.dat
2007-09-08 21:55 d——– C:\Program Files\HP
2007-09-03 08:39 249 –a—— C:\WINDOWS\system\hpsysdrv.dat
2007-09-03 08:38 d——– C:\WINDOWS\I386
2007-09-03 08:33 dr——- C:\DOCUME~1\ALLUSE~1\Documents

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2007-09-27 23:12 ——— d——– C:\DOCUME~1\Owner\APPLIC~1\Real
2007-09-20 20:11 ——— d——– C:\Program Files\Microsoft Works
2007-09-09 21:34 ——— d——– C:\Program Files\QuickTime
2007-09-09 21:34 ——— d——– C:\Program Files\Presario PC Help
2007-09-09 21:34 ——— d——– C:\Program Files\PC-Doctor for Windows
2007-09-09 21:33 ——— d——– C:\Program Files\Norton AntiVirus
2007-09-09 21:32 ——— d——– C:\Program Files\iTunes
2007-09-09 21:28 ——— d——– C:\Program Files\Easy Internet signup
2007-09-09 20:02 ——— d——– C:\Program Files\Common Files\InstallShield
2007-09-02 17:59 3674 -rahs—- C:\WINDOWS\system32\drivers\HP_P9902CV-AB4 SR1120CF SE610_YC_Pres_QTHT424_E43SEhwRET1_4_IGamila Giovani Neon series_SMICRO-STAR INTERNATIONAL CO., LTD_V030_B3.10_T040415_WXH1_L409_M248_J80_7Intel_8Pentium 4_92.8_111063044_N10EC8139_P_Z_K_A808624C5.MRK
2007-09-02 17:56 ——— d–h—– C:\Program Files\InstallShield Installation Information
2007-09-02 17:56 ——— d——– C:\Program Files\InterVideo
2007-08-07 13:58 8320 –a—— C:\WINDOWS\system32\drivers\AWRTRD.sys
2007-08-07 13:56 9344 –a—— C:\WINDOWS\system32\drivers\NSDriver.sys
.

((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.

*Note* empty entries & legit default entries are not shown

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"IMJPMIG8.1"="C:\WINDOWS\IME\imjp8_1\IMJPMIG.exe" [2003-08-17 06:57]
"MSPY2002"="C:\WINDOWS\System32\IME\PINTLGNT\ImScInst.exe" [2003-08-17 00:24]
"PHIME2002ASync"="C:\WINDOWS\System32\IME\TINTLGNT\TINTSETP.exe" [2003-08-17 00:25]
"PHIME2002A"="C:\WINDOWS\System32\IME\TINTLGNT\TINTSETP.exe" [2003-08-17 00:25]
"hpsysdrv"="c:\windows\system\hpsysdrv.exe" [1998-05-07 23:04]
"HotKeysCmds"="C:\WINDOWS\System32\hkcmd.exe" [2004-02-11 00:51]
"KBD"="C:\HP\KBD\KBD.EXE" [2003-02-12 02:02]
"TkBellExe"="C:\Program Files\Common Files\Real\Update_OB\realsched.exe" [2004-04-01 22:04]
"iTunesHelper"="C:\Program Files\iTunes\iTunesHelper.exe" [2004-01-17 02:16]
"Recguard"="C:\WINDOWS\SMINST\RECGUARD.EXE" [2003-11-03 23:50]
"ccApp"="c:\Program Files\Common Files\Symantec Shared\ccApp.exe" [2003-08-15 07:59]
"PS2"="C:\WINDOWS\system32\ps2.exe" [2003-09-13 02:13]
"HP Software Update"="C:\Program Files\HP\HP Software Update\HPWuSchd.exe" [2003-06-25 11:24]
"HP Component Manager"="C:\Program Files\HP\hpcoretech\hpcmpmgr.exe" [2003-06-26 18:50]
"AAWTray"="C:\Program Files\Lavasoft\Ad-Aware 2007\AAWTray.exe" [2007-08-08 15:53]
"SunJavaUpdateSched"="C:\Program Files\Java\jre1.6.0_02\bin\jusched.exe" [2007-07-12 04:00]

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="C:\WINDOWS\System32\ctfmon.exe" [2003-08-16 09:54]

C:\DOCUME~1\ALLUSE~1\STARTM~1\Programs\Startup\
Compaq Connections.lnk - C:\Program Files\Compaq Connections\1940576\Program\BackWeb-1940576.exe [2004-04-01 22:26:37]
HP Digital Imaging Monitor.lnk - C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe [2003-07-07 01:20:40]

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\explorer]
"NoInstrumentation"=1 (0x1)
"NoStartMenuSubFolders"=1 (0x1)
"NoFavoritesMenu"=1 (0x1)


.
Contents of the 'Scheduled Tasks' folder
"2007-09-08 14:13:19 C:\WINDOWS\Tasks\HP DArC Task #Hewlett-Packard#hp psc 1300 series#1189260524.job"
- C:\Program Files\HP\hpcoretech\comp\hpdarc.exe
"2007-09-15 02:31:28 C:\WINDOWS\Tasks\HP DArC Task #Hewlett-Packard#hp psc 1300 series#1189262568.job"
- C:\Program Files\HP\hpcoretech\comp\hpdarc.exe
"2007-09-09 06:03:02 C:\WINDOWS\Tasks\Norton AntiVirus - Scan my computer.job"
- c:\PROGRA~1\NORTON~1\Navw32.exe
"2007-09-09 06:03:02 C:\WINDOWS\Tasks\Symantec NetDetect.job"
- C:\Program Files\Symantec\LiveUpdate\NDETECT.EXE
"2007-09-15 02:27:55 C:\WINDOWS\Tasks\WebReg 20070915102754.job"
.
**************************************************************************

catchme 0.3.1061 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2007-10-03 21:32:06
Windows 5.1.2600 Service Pack 1 NTFS

scanning hidden processes …

scanning hidden autostart entries …

scanning hidden files …

scan completed successfully
hidden files: 0

**************************************************************************
.
Completion time: 2007-10-03 21:32:56
C:\ComboFix-quarantined-files.txt … 2007-10-03 21:32
C:\ComboFix2.txt … 2007-10-02 19:27
C:\ComboFix3.txt … 2007-09-28 20:49
.
— E O F —
a black screen still pops up when i use microsoft word, i'm not sure why.. i tried to print screen to catch wat it says but it's usually too fast. i think it says sth like my document is too big. sometimes i'll catch de word norton in de title…do u know why?

i wld like to change to other softwares and replace norton. please recommend me some useful softwares and firewalls. =)

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 9:53:31 PM, on 10/3/2007
Platform: Windows XP SP1 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
c:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
c:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
C:\windows\system\hpsysdrv.exe
C:\WINDOWS\System32\hkcmd.exe
C:\HP\KBD\KBD.EXE
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\Common Files\Symantec Shared\ccApp.exe
C:\Program Files\HP\HP Software Update\HPWuSchd.exe
C:\Program Files\HP\hpcoretech\hpcmpmgr.exe
C:\Program Files\Lavasoft\Ad-Aware 2007\AAWTray.exe
C:\Program Files\Java\jre1.6.0_02\bin\jusched.exe
C:\WINDOWS\System32\ctfmon.exe
C:\Program Files\Compaq Connections\1940576\Program\BackWeb-1940576.exe
C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
C:\Program Files\HP\hpcoretech\comp\hptskmgr.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\System32\gearsec.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
c:\Program Files\Norton AntiVirus\navapsvc.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Program Files\MSN Messenger\msnmsgr.exe
C:\Program Files\MSN Messenger\usnsvc.exe
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE
C:\WINDOWS\explorer.exe
C:\WINDOWS\system32\mspaint.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://ie.redirect.hp.com/svs/rdr?TYPE=3&a…&pf=desktop
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://ie.redirect.hp.com/svs/rdr?TYPE=3&a…&pf=desktop
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://ie.redirect.hp.com/svs/rdr?TYPE=3&a…&pf=desktop
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = localhost
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll
O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_02\bin\ssv.dll
O2 - BHO: NAV Helper - {BDF3E430-B101-42AD-A544-FADC6B084872} - c:\Program Files\Norton AntiVirus\NavShExt.dll
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx
O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - c:\Program Files\Norton AntiVirus\NavShExt.dll
O4 - HKLM\..\Run: [IMJPMIG8.1] "C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE" /Spoil /RemAdvDef /Migration32
O4 - HKLM\..\Run: [MSPY2002] C:\WINDOWS\System32\IME\PINTLGNT\ImScInst.exe /SYNC
O4 - HKLM\..\Run: [PHIME2002ASync] C:\WINDOWS\System32\IME\TINTLGNT\TINTSETP.EXE /SYNC
O4 - HKLM\..\Run: [PHIME2002A] C:\WINDOWS\System32\IME\TINTLGNT\TINTSETP.EXE /IMEName
O4 - HKLM\..\Run: [hpsysdrv] c:\windows\system\hpsysdrv.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\System32\hkcmd.exe
O4 - HKLM\..\Run: [KBD] C:\HP\KBD\KBD.EXE
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [iTunesHelper] C:\Program Files\iTunes\iTunesHelper.exe
O4 - HKLM\..\Run: [Recguard] C:\WINDOWS\SMINST\RECGUARD.EXE
O4 - HKLM\..\Run: [ccApp] "c:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [PS2] C:\WINDOWS\system32\ps2.exe
O4 - HKLM\..\Run: [HP Software Update] "C:\Program Files\HP\HP Software Update\HPWuSchd.exe"
O4 - HKLM\..\Run: [HP Component Manager] "C:\Program Files\HP\hpcoretech\hpcmpmgr.exe"
O4 - HKLM\..\Run: [AAWTray] C:\Program Files\Lavasoft\Ad-Aware 2007\AAWTray.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_02\bin\jusched.exe"
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\System32\ctfmon.exe
O4 - Global Startup: Compaq Connections.lnk = C:\Program Files\Compaq Connections\1940576\Program\BackWeb-1940576.exe
O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MI1933~1\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_02\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_02\bin\ssv.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MI1933~1\OFFICE11\REFIEBAR.DLL
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O16 - DPF: {0EB0E74A-2A76-4AB3-A7FB-9BD8C29F7F75} (CKAVWebScan Object) - http://www.kaspersky.com/kos/eng/partner/d…can_unicode.cab
O23 - Service: Ad-Aware 2007 Service (aawservice) - Lavasoft AB - C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - c:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
O23 - Service: Symantec Password Validation (ccPwdSvc) - Symantec Corporation - c:\Program Files\Common Files\Symantec Shared\ccPwdSvc.exe
O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - c:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
O23 - Service: Gear Security Service (GEARSecurity) - GEAR Software - C:\WINDOWS\System32\gearsec.exe
O23 - Service: iPod Service (iPodService) - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: Norton AntiVirus Auto Protect Service (navapsvc) - Symantec Corporation - c:\Program Files\Norton AntiVirus\navapsvc.exe
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\System32\HPZipm12.exe
O23 - Service: SAVScan - Symantec Corporation - c:\Program Files\Norton AntiVirus\SAVScan.exe

–
End of file - 6533 bytes
Something didn't go right with the last combo log.
Nothing major it just didn't delete the folder I wanted it to.



___________________________________
Reconfigure Windows XP to show hidden files::

Click Start. My Computer.
Select the Tools menu Folder Options. Select the View Tab.
Under the Hidden files and folders heading select "Show hidden files and folders".
Uncheck the "Hide protected operating system files (recommended)" option.
Uncheck the "Hide file extensions for known file types" option.
Click Yes to confirm. Click OK.
___________________________________
Search for and remove
Now I want you to search for and delete the following folder and all it's contents if present. If you need help finding them.
Click start /search/ all files and folders/ look for More advanced options. once in there select the first 3 boxes.
Please just remove the files/folders I listed in BOLD


D:/Avenger. Delete that folder and all it's contents.

____________________________

Before we move on with uninstalling nortons I have to clear a few things up.

Let me ask you something.
Did you used to run Trend Micro Anti Virus?
If yes :
Did you uninstall it ?

_____________________________

open CCleaner
click on tools
highlight uninstall

down on the bottom click save to text file.
Save it to your desktop and post
the contents
of that log for me.



_____________________________
In your next reply I would like to see:
  • A new HJT log
  • The report from CCleaner uninstall list.
  • Let me know you were able to delete that folder d:/avenger
i deleted D:/avenger but do i need to delete it from the recycle bin too?
i opened my microsoft word files a few times and i finally got the full title and content of the black box.
it's title is:
c:\PROGRAM~1\NORTON~1\navw32.exe
content:
program too big to fit in memory

it appears everytime i open a saved microsoft file (even microsoft ppt) but doesnt happen when i open microsoft itself to start a new file.

CCleaner list:
1300Tour
1300Trb
1300_Help
1300
Ad-Aware 2007
Adobe Reader 6.0.1
AIOMinimal
AiOSoftware
AiO_Scan
Blackhawk Striker from Compaq (remove only)
Blasterball 2 from Compaq (remove only)
Bounce Symphony from Compaq (remove only)
ccCommon
CCleaner (remove only)
CC_ccStart
Compaq Connections
Copy
CreativeProjects
Crystal Maze from Compaq (remove only)
Director
DirectX Hotfix - KB825116
DocProc
Fax
Five Card Frenzy from Compaq (remove only)
HijackThis 2.0.2
HP Photo & Imaging 3.1
HP PSC & OfficeJet 3.0
hp psc 1300 series
HP Software Update
hpmdtab
HpSdpAppCoreApp
HPSystemDiagnostics
InstantShare
Intel® Extreme Graphics Driver
Internet Explorer Q828750
InterVideo WinDVD Creator 2
iTunes
Java™ 6 Update 2
Kaspersky Online Scanner
KBD
LiveReg (Symantec Corporation)
LiveUpdate 1.90 (Symantec Corporation)
Memories Disc Creator 2.0
Microsoft .NET Framework 1.1
Microsoft Encarta Encyclopedia Standard - WE 2004
Microsoft Money System Pack
Microsoft Money
Microsoft Office Professional Edition 2003
Microsoft Visual J# .NET Redistributable Package 1.1
Microsoft Works 7.0
MSRedist
Norton AntiVirus 2004 (Symantec Corporation)
Norton AntiVirus 2004
Norton AntiVirus Parent MSI
Orbital from Compaq (remove only)
Otto from Compaq (remove only)
Outlook Express Update Q330994
Overball from Compaq (remove only)
Overland
PC-Doctor for Windows
PhotoGallery
Polar Bowler from Compaq (remove only)
Presario PC Help
PrintScreen
PS2
Python 2.2 combined Win32 extensions
Python 2.2.1
QFolder
QuickProjects
QuickTime
Readme
RealOne Player
Scan
Shockwave
SkinsHP1
SkinsHP2
Slyder from Compaq (remove only)
Spybot - Search & Destroy
SymNet
Tradewinds from Compaq (remove only)
TrayApp
Unload
WebFldrs XP
WebReg
Windows Live Messenger
Windows XP Hotfix (SP2) Q327979
Windows XP Hotfix (SP2) Q329112
Windows XP Hotfix (SP2) Q331958
Windows XP Hotfix (SP2) Q811789
Windows XP Hotfix (SP2) Q814995
Windows XP Hotfix (SP2) Q815485
Windows XP Hotfix (SP2) Q817357
Windows XP Hotfix (SP2) [See KB810243 for more information]
Windows XP Hotfix (SP2) [See q329256 for more information]
Windows XP Hotfix - KB810217
Windows XP Hotfix - KB821431
Windows XP Hotfix - KB823182
Windows XP Hotfix - KB824105
Windows XP Hotfix - KB824141
Windows XP Hotfix - KB825119
Windows XP Hotfix - KB826939
Windows XP Hotfix - KB826942
Windows XP Hotfix - KB828028
Windows XP Hotfix - KB828035
Windows XP Hotfix - KB833407
WinZip 11.1
Word Symphony from Compaq (remove only)

i used to run trend micro on the internet. i think i tried to install it but either failed or deleted it later on.

HJT:
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 7:41:18 PM, on 10/4/2007
Platform: Windows XP SP1 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\Explorer.EXE
c:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
c:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
C:\windows\system\hpsysdrv.exe
C:\WINDOWS\System32\hkcmd.exe
C:\HP\KBD\KBD.EXE
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\Common Files\Symantec Shared\ccApp.exe
C:\Program Files\HP\HP Software Update\HPWuSchd.exe
C:\Program Files\HP\hpcoretech\hpcmpmgr.exe
C:\Program Files\Lavasoft\Ad-Aware 2007\AAWTray.exe
C:\Program Files\Java\jre1.6.0_02\bin\jusched.exe
C:\WINDOWS\System32\ctfmon.exe
C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
C:\Program Files\Compaq Connections\1940576\Program\BackWeb-1940576.exe
C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\HP\hpcoretech\comp\hptskmgr.exe
C:\WINDOWS\System32\gearsec.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
c:\Program Files\Norton AntiVirus\navapsvc.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\internet explorer\iexplore.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Program Files\MSN Messenger\msnmsgr.exe
C:\Program Files\MSN Messenger\usnsvc.exe
C:\Program Files\CCleaner\ccleaner.exe
C:\WINDOWS\system32\NOTEPAD.EXE
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://ie.redirect.hp.com/svs/rdr?TYPE=3&a…&pf=desktop
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://ie.redirect.hp.com/svs/rdr?TYPE=3&a…&pf=desktop
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://ie.redirect.hp.com/svs/rdr?TYPE=3&a…&pf=desktop
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = localhost
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll
O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_02\bin\ssv.dll
O2 - BHO: NAV Helper - {BDF3E430-B101-42AD-A544-FADC6B084872} - c:\Program Files\Norton AntiVirus\NavShExt.dll
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx
O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - c:\Program Files\Norton AntiVirus\NavShExt.dll
O4 - HKLM\..\Run: [IMJPMIG8.1] "C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE" /Spoil /RemAdvDef /Migration32
O4 - HKLM\..\Run: [MSPY2002] C:\WINDOWS\System32\IME\PINTLGNT\ImScInst.exe /SYNC
O4 - HKLM\..\Run: [PHIME2002ASync] C:\WINDOWS\System32\IME\TINTLGNT\TINTSETP.EXE /SYNC
O4 - HKLM\..\Run: [PHIME2002A] C:\WINDOWS\System32\IME\TINTLGNT\TINTSETP.EXE /IMEName
O4 - HKLM\..\Run: [hpsysdrv] c:\windows\system\hpsysdrv.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\System32\hkcmd.exe
O4 - HKLM\..\Run: [KBD] C:\HP\KBD\KBD.EXE
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [iTunesHelper] C:\Program Files\iTunes\iTunesHelper.exe
O4 - HKLM\..\Run: [Recguard] C:\WINDOWS\SMINST\RECGUARD.EXE
O4 - HKLM\..\Run: [ccApp] "c:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [PS2] C:\WINDOWS\system32\ps2.exe
O4 - HKLM\..\Run: [HP Software Update] "C:\Program Files\HP\HP Software Update\HPWuSchd.exe"
O4 - HKLM\..\Run: [HP Component Manager] "C:\Program Files\HP\hpcoretech\hpcmpmgr.exe"
O4 - HKLM\..\Run: [AAWTray] C:\Program Files\Lavasoft\Ad-Aware 2007\AAWTray.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_02\bin\jusched.exe"
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\System32\ctfmon.exe
O4 - Global Startup: Compaq Connections.lnk = C:\Program Files\Compaq Connections\1940576\Program\BackWeb-1940576.exe
O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MI1933~1\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_02\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_02\bin\ssv.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MI1933~1\OFFICE11\REFIEBAR.DLL
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O16 - DPF: {0EB0E74A-2A76-4AB3-A7FB-9BD8C29F7F75} (CKAVWebScan Object) - http://www.kaspersky.com/kos/eng/partner/d…can_unicode.cab
O23 - Service: Ad-Aware 2007 Service (aawservice) - Lavasoft AB - C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - c:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
O23 - Service: Symantec Password Validation (ccPwdSvc) - Symantec Corporation - c:\Program Files\Common Files\Symantec Shared\ccPwdSvc.exe
O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - c:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
O23 - Service: Gear Security Service (GEARSecurity) - GEAR Software - C:\WINDOWS\System32\gearsec.exe
O23 - Service: iPod Service (iPodService) - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: Norton AntiVirus Auto Protect Service (navapsvc) - Symantec Corporation - c:\Program Files\Norton AntiVirus\navapsvc.exe
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\System32\HPZipm12.exe
O23 - Service: SAVScan - Symantec Corporation - c:\Program Files\Norton AntiVirus\SAVScan.exe

–
End of file - 6517 bytes

c:\PROGRAM~1\NORTON~1\navw32.exe
content:
program too big to fit in memory



Ok that's Nortons giving you a fit. It really is a resource hog.

We will clear the recycle bin in just a while. CCleaner does this for you.


_____________________________________
Navigate to and
Delete this folder.
C:\Program Files\Trend Micro

__________________________________
Anti Virus:
First download one of these.
But don't run them yet.
You have to to register them to recieve updates.
Please use the correct email address when doing so.

AVG FREE

Avast

____________________________________

Now lets uninstall Nortons through add/remove programs.
If the uninstaller doesn't work or it's actually not there.. ( happens alot.)
go to here
Download and run the appropiate tool for you norton product. As decribed by year.
  • When that's done install one of the anti virus programs . Never run 2 together.
__________________________________
Firewall
A few words on Microsofts firewall. It only works in one direction. Incoming.
That means if something gets by it you would never know it was trying
to contact the internet.
Example: A bad program installs itself. You would never know it was contacting the internet.
Downloading other nasties and so forth.

IBefore you run one of these you should be certain Microsofts firewall is disabled.
To disable it.

I will list a few free firewalls for you. These are good (free) firewalls:

Never run 2 firwalls together. They will interfere with each other.
So just download and install one!

Comodo another that's easy to use.

Zone Alarm

________________________________________
Post a new HJT log and let me know all that went OK.

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI