DFW,
Please find the latest logs below:
HJT Log:
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 10:58, on 2008-04-01
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Boot mode: Normal
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Intel\Wireless\Bin\EvtEng.exe
C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe
C:\Program Files\Intel\Wireless\Bin\WLKeeper.exe
C:\WINDOWS\system32\spoolsv.exe
C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe
C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe
C:\Program Files\Cisco Systems\VPN Client\cvpnd.exe
C:\Program Files\Trend Micro\OfficeScan Client\ntrtscan.exe
C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Trend Micro\OfficeScan Client\tmlisten.exe
C:\Program Files\Trend Micro\OfficeScan Client\OfcPfwSvc.exe
C:\WINDOWS\TEMP\FY3F34.EXE
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\stsystra.exe
C:\Program Files\Intel\Wireless\bin\ZCfgSvc.exe
C:\Program Files\Intel\Wireless\Bin\ifrmewrk.exe
C:\WINDOWS\system32\hkcmd.exe
C:\WINDOWS\system32\igfxpers.exe
C:\WINDOWS\system32\igfxsrvc.exe
C:\Program Files\Trend Micro\OfficeScan Client\pccntmon.exe
D:\HP\HP Software Update\HPWuSchd2.exe
C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe
C:\Program Files\Trend Micro\OfficeScan Client\pccntupd.exe
C:\PROGRA~1\Grisoft\AVG7\avgcc.exe
C:\Program Files\Skype\Phone\Skype.exe
C:\Program Files\Messenger\msmsgs.exe
C:\PROGRA~1\Intel\Wireless\Bin\Dot1XCfg.exe
C:\WINDOWS\system32\userinit.exe
D:\HP\Digital Imaging\bin\hpqtra08.exe
D:\HP\Digital Imaging\bin\hpqSTE08.exe
C:\Program Files\Skype\Plugin Manager\skypePM.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: Skype add-on (mastermind) - {22BF413B-C6D2-4d91-82A9-A0F997BA588C} - C:\Program Files\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll
O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - D:\SPYBOT~1\SDHelper.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar1.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll
O4 - HKLM\..\Run: [SigmatelSysTrayApp] stsystra.exe
O4 - HKLM\..\Run: [IntelZeroConfig] "C:\Program Files\Intel\Wireless\bin\ZCfgSvc.exe"
O4 - HKLM\..\Run: [IntelWireless] "C:\Program Files\Intel\Wireless\Bin\ifrmewrk.exe" /tf Intel PROSet/Wireless
O4 - HKLM\..\Run: [igfxtray] C:\WINDOWS\system32\igfxtray.exe
O4 - HKLM\..\Run: [igfxhkcmd] C:\WINDOWS\system32\hkcmd.exe
O4 - HKLM\..\Run: [igfxpers] C:\WINDOWS\system32\igfxpers.exe
O4 - HKLM\..\Run: [OfficeScanNT Monitor] "C:\Program Files\Trend Micro\OfficeScan Client\pccntmon.exe" -HideWindow
O4 - HKLM\..\Run: [HP Software Update] D:\HP\HP Software Update\HPWuSchd2.exe
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\Grisoft\AVG7\avgcc.exe /STARTUP
O4 - HKCU\..\Run: [Skype] "C:\Program Files\Skype\Phone\Skype.exe" /nosplash /minimized
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKUS\S-1-5-19\..\Run: [AVG7_Run] C:\PROGRA~1\Grisoft\AVG7\avgw.exe /RUNONCE (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [AVG7_Run] C:\PROGRA~1\Grisoft\AVG7\avgw.exe /RUNONCE (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-18\..\Run: [AVG7_Run] C:\PROGRA~1\Grisoft\AVG7\avgw.exe /RUNONCE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [AVG7_Run] C:\PROGRA~1\Grisoft\AVG7\avgw.exe /RUNONCE (User 'Default user')
O4 - Global Startup: Cisco Systems VPN Client.lnk = C:\Program Files\Cisco Systems\VPN Client\vpngui.exe
O4 - Global Startup: HP Digital Imaging Monitor.lnk = D:\HP\Digital Imaging\bin\hpqtra08.exe
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: Skype - {77BF5300-1474-4EC7-9980-D32B190E9B07} - C:\Program Files\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - D:\SPYBOT~1\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - D:\SPYBOT~1\SDHelper.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {0EB0E74A-2A76-4AB3-A7FB-9BD8C29F7F75} (CKAVWebScan Object) - http://www.kaspersky.com/kos/eng/partner/d…can_unicode.cab
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: Domain = techview.com.tw
O17 - HKLM\Software\..\Telephony: DomainName = techview.com.tw
O17 - HKLM\System\CS1\Services\Tcpip\Parameters: Domain = techview.com.tw
O17 - HKLM\System\CS2\Services\Tcpip\Parameters: Domain = techview.com.tw
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL
O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe
O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe
O23 - Service: Cisco Systems, Inc. VPN Service (CVPND) - Cisco Systems, Inc. - C:\Program Files\Cisco Systems\VPN Client\cvpnd.exe
O23 - Service: Intel® PROSet/Wireless Event Log (EvtEng) - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\EvtEng.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: OfficeScanNT RealTime Scan (ntrtscan) - Trend Micro Inc. - C:\Program Files\Trend Micro\OfficeScan Client\ntrtscan.exe
O23 - Service: OfficeScanNT Personal Firewall (OfcPfwSvc) - Trend Micro Inc. - C:\Program Files\Trend Micro\OfficeScan Client\OfcPfwSvc.exe
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe
O23 - Service: Intel® PROSet/Wireless Registry Service (RegSrvc) - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe
O23 - Service: Intel® PROSet/Wireless Service (S24EventMonitor) - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe
O23 - Service: OfficeScanNT Listener (tmlisten) - Trend Micro Inc. - C:\Program Files\Trend Micro\OfficeScan Client\tmlisten.exe
O23 - Service: Intel® PROSet/Wireless SSO Service (WLANKEEPER) - Intel® Corporation - C:\Program Files\Intel\Wireless\Bin\WLKeeper.exe
–
End of file - 7360 bytes
Combofix Log:
ComboFix 08-03-30.3 - 96111201 2008-04-01 9:06:02.4 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.2.1252.1.1033.18.487 [GMT -4:00]
Running from: C:\Documents and Settings\[removed]\Desktop\ComboFix.exe
Command switches used :: C:\Documents and Settings\96111201\Desktop\CFScript.txt
* Created a new restore point
FILE ::
F:\ekf6dbg0.com
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
C:\WINDOWS\SxsCaPendDel
.
((((((((((((((((((((((((( Files Created from 2008-03-01 to 2008-04-01 )))))))))))))))))))))))))))))))
.
2008-03-31 18:24 . 2008-03-31 18:24 d——– C:\Program Files\Malwarebytes' Anti-Malware
2008-03-31 18:24 . 2008-03-31 18:24 d——– C:\Documents and Settings\All Users\Application Data\Malwarebytes
2008-03-31 18:24 . 2008-03-31 18:24 d——– C:\Documents and Settings\96111201\Application Data\Malwarebytes
2008-03-28 14:27 . 2008-03-28 14:28 d——– C:\Documents and Settings\Administrator.T96111201\Application Data\AVG7
2008-03-28 13:07 . 2008-03-28 13:07 d——– C:\Program Files\Enigma Software Group
2008-03-28 11:18 . 2008-03-28 13:00 d——– C:\Program Files\Filseclab
2008-03-28 11:18 . 2008-03-28 13:41 d——– C:\Program Files\Common Files\Filseclab
2008-03-28 11:18 . 2008-03-28 11:18 d——– C:\Documents and Settings\96111201\Application Data\InstallShield
2008-03-27 11:00 . 2008-03-27 11:12 d-a—— C:\Documents and Settings\All Users\Application Data\TEMP
2008-03-25 09:55 . 2008-03-25 09:55 d——– C:\Documents and Settings\LocalService\Application Data\AVG7
2008-03-25 09:55 . 2008-03-25 09:55 d——– C:\Documents and Settings\All Users\Application Data\Grisoft
2008-03-25 09:55 . 2008-03-31 09:00 d——– C:\Documents and Settings\All Users\Application Data\avg7
2008-03-25 09:55 . 2008-03-25 11:11 d——– C:\Documents and Settings\96111201\Application Data\AVG7
2008-03-25 09:52 . 2008-03-25 09:54 35,960,792 –a—— C:\avg75free_519a1276.exe
2008-03-13 13:12 . 2008-03-13 13:12 d——– C:\Program Files\MSECache
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-04-01 13:00 ——— d—–w C:\Documents and Settings\96111201\Application Data\Skype
2008-04-01 12:11 ——— d—–w C:\Documents and Settings\96111201\Application Data\skypePM
2008-03-30 13:08 ——— d—–w C:\Program Files\Trend Micro
2008-03-28 15:18 ——— d–h–w C:\Program Files\InstallShield Installation Information
2008-03-25 13:46 ——— d—–w C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy
2007-11-15 16:27 32 —-a-w C:\Documents and Settings\All Users\Application Data\ezsid.dat
.
((((((((((((((((((((((((((((( snapshot@2008-03-31_ 8.38.52.62 )))))))))))))))))))))))))))))))))))))))))
.
- 2008-03-27 12:35:12 16,384 —-a-w C:\WINDOWS\system32\config\systemprofile\Cookies\index.dat
+ 2008-04-01 12:10:05 16,384 —-a-w C:\WINDOWS\system32\config\systemprofile\Cookies\index.dat
- 2008-03-27 12:35:12 32,768 —-a-w C:\WINDOWS\system32\config\systemprofile\Local Settings\History\History.IE5\index.dat
+ 2008-04-01 12:10:05 32,768 —-a-w C:\WINDOWS\system32\config\systemprofile\Local Settings\History\History.IE5\index.dat
- 2008-03-27 12:35:12 32,768 —-a-w C:\WINDOWS\system32\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\index.dat
+ 2008-04-01 12:10:05 32,768 —-a-w C:\WINDOWS\system32\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\index.dat
- 2008-03-31 12:10:01 41,238 —-a-w C:\WINDOWS\system32\perfc009.dat
+ 2008-04-01 12:47:49 41,238 —-a-w C:\WINDOWS\system32\perfc009.dat
- 2008-03-31 12:10:01 315,076 —-a-w C:\WINDOWS\system32\perfh009.dat
+ 2008-04-01 12:47:49 315,076 —-a-w C:\WINDOWS\system32\perfh009.dat
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Skype"="C:\Program Files\Skype\Phone\Skype.exe" [2007-11-12 03:48 21760296]
"MSMSGS"="C:\Program Files\Messenger\msmsgs.exe" [2004-10-13 12:24 1694208]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"SigmatelSysTrayApp"="stsystra.exe" [2006-03-24 05:30 282624 C:\WINDOWS\stsystra.exe]
"IntelZeroConfig"="C:\Program Files\Intel\Wireless\bin\ZCfgSvc.exe" [2005-12-27 23:55 667718]
"IntelWireless"="C:\Program Files\Intel\Wireless\Bin\ifrmewrk.exe" [2005-12-27 23:56 602182]
"igfxtray"="C:\WINDOWS\system32\igfxtray.exe" [2005-12-13 05:44 98304]
"igfxhkcmd"="C:\WINDOWS\system32\hkcmd.exe" [2005-12-13 05:41 77824]
"igfxpers"="C:\WINDOWS\system32\igfxpers.exe" [2005-12-13 05:45 118784]
"OfficeScanNT Monitor"="C:\Program Files\Trend Micro\OfficeScan Client\pccntmon.exe" [2006-05-09 02:36 356352]
"HP Software Update"="D:\HP\HP Software Update\HPWuSchd2.exe" [2006-02-18 14:41 49152]
"Adobe Reader Speed Launcher"="C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2008-01-11 23:16 39792]
"AVG7_CC"="C:\PROGRA~1\Grisoft\AVG7\avgcc.exe" [2008-03-25 09:55 579072]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"AVG7_Run"="C:\PROGRA~1\Grisoft\AVG7\avgw.exe" [2008-03-25 09:55 219136]
C:\Documents and Settings\All Users\Start Menu\Programs\Startup\
Cisco Systems VPN Client.lnk - C:\Program Files\Cisco Systems\VPN Client\vpngui.exe [2007-11-06 03:08:00 1385400]
HP Digital Imaging Monitor.lnk - D:\HP\Digital Imaging\bin\hpqtra08.exe [2006-02-18 16:21:22 288472]
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\TrendFirewall]
"DisableMonitoring"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"C:\\Program Files\\Grisoft\\AVG7\\avginet.exe"=
"C:\\Program Files\\Grisoft\\AVG7\\avgamsvr.exe"=
"C:\\Program Files\\Grisoft\\AVG7\\avgcc.exe"=
"C:\\Program Files\\Skype\\Phone\\Skype.exe"=
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"3389:TCP"= 3389:TCP:@xpsp2res.dll,-22009
S3 PortTalk;PortTalk;C:\WINDOWS\system32\Drivers\PortTalk.sys [2007-11-15 11:39]
S3 Wdm1;USB Bridge Cable Driver;C:\WINDOWS\system32\Drivers\usbbc.sys [2002-10-01 01:12]
.
**************************************************************************
catchme 0.3.1344 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.net
Rootkit scan 2008-04-01 09:09:34
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes …
scanning hidden autostart entries …
scanning hidden files …
scan completed successfully
hidden files: 0
**************************************************************************
.
Completion time: 2008-04-01 9:11:13
ComboFix-quarantined-files.txt 2008-04-01 13:11:02
ComboFix2.txt 2008-03-31 22:11:58
ComboFix3.txt 2008-03-31 21:47:35
ComboFix4.txt 2008-03-31 12:39:08
Pre-Run: 14,470,680,576 bytes free
Post-Run: 14,460,932,096 bytes free
.
2008-03-20 02:20:35 — E O F —
Kaspersky Log:
——————————————————————————-
KASPERSKY ONLINE SCANNER REPORT
Tuesday, April 01, 2008 10:52:43 AM
Operating System: Microsoft Windows XP Professional, Service Pack 2 (Build 2600)
Kaspersky Online Scanner version: 5.0.98.0
Kaspersky Anti-Virus database last update: 1/04/2008
Kaspersky Anti-Virus database records: 675855
——————————————————————————-
Scan Settings:
Scan using the following antivirus database: extended
Scan Archives: true
Scan Mail Bases: true
Scan Target - My Computer:
C:\
D:\
E:\
Scan Statistics:
Total number of scanned objects: 38301
Number of viruses found: 18
Number of infected objects: 108
Number of suspicious objects: 0
Duration of the scan process: 00:42:16
Infected Object Name / Virus Name / Last Action
C:\Documents and Settings\96111201\Application Data\Malwarebytes\Malwarebytes' Anti-Malware\Quarantine\QUAR1.82801 Infected: Worm.Win32.AutoRun.ddb skipped
C:\Documents and Settings\Administrator.T96111201\Cookies\index.dat Object is locked skipped
C:\Documents and Settings\Administrator.T96111201\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat Object is locked skipped
C:\Documents and Settings\Administrator.T96111201\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped
C:\Documents and Settings\Administrator.T96111201\Local Settings\History\History.IE5\index.dat Object is locked skipped
C:\Documents and Settings\Administrator.T96111201\Local Settings\History\History.IE5\MSHist012008040120080402\index.dat Object is locked skipped
C:\Documents and Settings\Administrator.T96111201\Local Settings\temp\hpodvd09.log Object is locked skipped
C:\Documents and Settings\Administrator.T96111201\Local Settings\Temporary Internet Files\Content.IE5\index.dat Object is locked skipped
C:\Documents and Settings\Administrator.T96111201\NTUSER.DAT Object is locked skipped
C:\Documents and Settings\Administrator.T96111201\ntuser.dat.LOG Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Grisoft\Avg7Data\avg7log.log Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Grisoft\Avg7Data\avg7log.log.lck Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\8a774fe375e9d8bd89de40c1b1402780_a84585d5-2cc7-4d8b-a09f-66f20f9fcaa4 Object is locked skipped
C:\Documents and Settings\LocalService\Cookies\index.dat Object is locked skipped
C:\Documents and Settings\LocalService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat Object is locked skipped
C:\Documents and Settings\LocalService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped
C:\Documents and Settings\LocalService\Local Settings\History\History.IE5\index.dat Object is locked skipped
C:\Documents and Settings\LocalService\Local Settings\Temporary Internet Files\Content.IE5\index.dat Object is locked skipped
C:\Documents and Settings\LocalService\NTUSER.DAT Object is locked skipped
C:\Documents and Settings\LocalService\ntuser.dat.LOG Object is locked skipped
C:\Documents and Settings\NetworkService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat Object is locked skipped
C:\Documents and Settings\NetworkService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped
C:\Documents and Settings\NetworkService\NTUSER.DAT Object is locked skipped
C:\Documents and Settings\NetworkService\ntuser.dat.LOG Object is locked skipped
C:\Program Files\Trend Micro\OfficeScan Client\ConnLog\Conn_20080401.log Object is locked skipped
C:\QooBox\Quarantine\C\autorun.inf.vir Infected: Trojan-PSW.Win32.OnLineGames.ysc skipped
C:\QooBox\Quarantine\C\ekf6dbg0.com.vir Infected: Trojan-PSW.Win32.OnLineGames.wlc skipped
C:\QooBox\Quarantine\C\f.exe.vir Infected: Trojan-PSW.Win32.OnLineGames.ysc skipped
C:\QooBox\Quarantine\C\WINDOWS\system32\kavo.exe.vir Infected: Trojan-PSW.Win32.OnLineGames.ysc skipped
C:\QooBox\Quarantine\C\WINDOWS\system32\kavo1.dll.vir Infected: Trojan-PSW.Win32.OnLineGames.yrz skipped
C:\QooBox\Quarantine\D\autorun.inf.vir Infected: Trojan-PSW.Win32.OnLineGames.ysc skipped
C:\System Volume Information\MountPointManagerRemoteDatabase Object is locked skipped
C:\System Volume Information\_restore{A3903B9C-587A-40B6-B91B-F7BC00691491}\RP100\A0009871.com Object is locked skipped
C:\System Volume Information\_restore{A3903B9C-587A-40B6-B91B-F7BC00691491}\RP100\A0009872.inf Infected: Trojan-PSW.Win32.OnLineGames.wlc skipped
C:\System Volume Information\_restore{A3903B9C-587A-40B6-B91B-F7BC00691491}\RP100\A0009892.com Object is locked skipped
C:\System Volume Information\_restore{A3903B9C-587A-40B6-B91B-F7BC00691491}\RP100\A0009893.inf Infected: Trojan-PSW.Win32.OnLineGames.wlc skipped
C:\System Volume Information\_restore{A3903B9C-587A-40B6-B91B-F7BC00691491}\RP100\A0009896.exe Object is locked skipped
C:\System Volume Information\_restore{A3903B9C-587A-40B6-B91B-F7BC00691491}\RP100\A0009897.dll Infected: Trojan-PSW.Win32.OnLineGames.wld skipped
C:\System Volume Information\_restore{A3903B9C-587A-40B6-B91B-F7BC00691491}\RP100\A0009898.exe Object is locked skipped
C:\System Volume Information\_restore{A3903B9C-587A-40B6-B91B-F7BC00691491}\RP100\A0009899.dll Infected: Trojan-PSW.Win32.OnLineGames.wlc skipped
C:\System Volume Information\_restore{A3903B9C-587A-40B6-B91B-F7BC00691491}\RP100\A0009909.dll Infected: Trojan-PSW.Win32.OnLineGames.wlc skipped
C:\System Volume Information\_restore{A3903B9C-587A-40B6-B91B-F7BC00691491}\RP100\A0009910.dll Infected: Trojan-PSW.Win32.OnLineGames.wld skipped
C:\System Volume Information\_restore{A3903B9C-587A-40B6-B91B-F7BC00691491}\RP100\A0009911.com Object is locked skipped
C:\System Volume Information\_restore{A3903B9C-587A-40B6-B91B-F7BC00691491}\RP100\A0009912.inf Infected: Trojan-PSW.Win32.OnLineGames.wlc skipped
C:\System Volume Information\_restore{A3903B9C-587A-40B6-B91B-F7BC00691491}\RP100\A0009915.exe Object is locked skipped
C:\System Volume Information\_restore{A3903B9C-587A-40B6-B91B-F7BC00691491}\RP100\A0009916.dll Infected: Trojan-PSW.Win32.OnLineGames.wld skipped
C:\System Volume Information\_restore{A3903B9C-587A-40B6-B91B-F7BC00691491}\RP100\A0009924.dll Infected: Trojan-PSW.Win32.OnLineGames.wld skipped
C:\System Volume Information\_restore{A3903B9C-587A-40B6-B91B-F7BC00691491}\RP100\A0009925.dll Infected: Trojan-PSW.Win32.OnLineGames.wlc skipped
C:\System Volume Information\_restore{A3903B9C-587A-40B6-B91B-F7BC00691491}\RP100\A0009926.com Object is locked skipped
C:\System Volume Information\_restore{A3903B9C-587A-40B6-B91B-F7BC00691491}\RP100\A0009927.inf Infected: Trojan-PSW.Win32.OnLineGames.wlc skipped
C:\System Volume Information\_restore{A3903B9C-587A-40B6-B91B-F7BC00691491}\RP100\A0009930.exe Object is locked skipped
C:\System Volume Information\_restore{A3903B9C-587A-40B6-B91B-F7BC00691491}\RP100\A0009931.dll Infected: Trojan-PSW.Win32.OnLineGames.wlc skipped
C:\System Volume Information\_restore{A3903B9C-587A-40B6-B91B-F7BC00691491}\RP100\A0009940.dll Infected: Trojan-PSW.Win32.OnLineGames.wld skipped
C:\System Volume Information\_restore{A3903B9C-587A-40B6-B91B-F7BC00691491}\RP100\A0009941.com Object is locked skipped
C:\System Volume Information\_restore{A3903B9C-587A-40B6-B91B-F7BC00691491}\RP100\A0009942.inf Infected: Trojan-PSW.Win32.OnLineGames.wlc skipped
C:\System Volume Information\_restore{A3903B9C-587A-40B6-B91B-F7BC00691491}\RP100\A0009945.exe Object is locked skipped
C:\System Volume Information\_restore{A3903B9C-587A-40B6-B91B-F7BC00691491}\RP100\A0009946.dll Infected: Trojan-PSW.Win32.OnLineGames.wld skipped
C:\System Volume Information\_restore{A3903B9C-587A-40B6-B91B-F7BC00691491}\RP100\A0009954.dll Infected: Trojan-PSW.Win32.OnLineGames.wld skipped
C:\System Volume Information\_restore{A3903B9C-587A-40B6-B91B-F7BC00691491}\RP100\A0009955.dll Infected: Trojan-PSW.Win32.OnLineGames.wlc skipped
C:\System Volume Information\_restore{A3903B9C-587A-40B6-B91B-F7BC00691491}\RP100\A0009957.com Object is locked skipped
C:\System Volume Information\_restore{A3903B9C-587A-40B6-B91B-F7BC00691491}\RP100\A0009958.inf Infected: Trojan-PSW.Win32.OnLineGames.wlc skipped
C:\System Volume Information\_restore{A3903B9C-587A-40B6-B91B-F7BC00691491}\RP100\A0009961.dll Infected: Trojan-PSW.Win32.OnLineGames.wld skipped
C:\System Volume Information\_restore{A3903B9C-587A-40B6-B91B-F7BC00691491}\RP102\A0010153.exe Object is locked skipped
C:\System Volume Information\_restore{A3903B9C-587A-40B6-B91B-F7BC00691491}\RP102\A0010154.dll Infected: Trojan-PSW.Win32.OnLineGames.wlc skipped
C:\System Volume Information\_restore{A3903B9C-587A-40B6-B91B-F7BC00691491}\RP102\A0010155.com Object is locked skipped
C:\System Volume Information\_restore{A3903B9C-587A-40B6-B91B-F7BC00691491}\RP102\A0010156.inf Infected: Trojan-PSW.Win32.OnLineGames.wlc skipped
C:\System Volume Information\_restore{A3903B9C-587A-40B6-B91B-F7BC00691491}\RP102\A0010159.exe Object is locked skipped
C:\System Volume Information\_restore{A3903B9C-587A-40B6-B91B-F7BC00691491}\RP102\A0010160.dll Infected: Trojan-PSW.Win32.OnLineGames.wld skipped
C:\System Volume Information\_restore{A3903B9C-587A-40B6-B91B-F7BC00691491}\RP102\A0010161.dll Infected: Trojan-PSW.Win32.OnLineGames.wlc skipped
C:\System Volume Information\_restore{A3903B9C-587A-40B6-B91B-F7BC00691491}\RP103\A0010162.bat Object is locked skipped
C:\System Volume Information\_restore{A3903B9C-587A-40B6-B91B-F7BC00691491}\RP103\A0010190.dll Infected: Trojan-PSW.Win32.OnLineGames.xjk skipped
C:\System Volume Information\_restore{A3903B9C-587A-40B6-B91B-F7BC00691491}\RP103\A0010191.dll Infected: Trojan-PSW.Win32.OnLineGames.wlc skipped
C:\System Volume Information\_restore{A3903B9C-587A-40B6-B91B-F7BC00691491}\RP103\A0010192.bat Object is locked skipped
C:\System Volume Information\_restore{A3903B9C-587A-40B6-B91B-F7BC00691491}\RP103\A0010198.exe Object is locked skipped
C:\System Volume Information\_restore{A3903B9C-587A-40B6-B91B-F7BC00691491}\RP103\A0010199.dll Infected: Trojan-PSW.Win32.OnLineGames.wld skipped
C:\System Volume Information\_restore{A3903B9C-587A-40B6-B91B-F7BC00691491}\RP103\A0010200.exe Object is locked skipped
C:\System Volume Information\_restore{A3903B9C-587A-40B6-B91B-F7BC00691491}\RP103\A0010201.dll Infected: Worm.Win32.AutoRun.dda skipped
C:\System Volume Information\_restore{A3903B9C-587A-40B6-B91B-F7BC00691491}\RP103\A0010209.dll Infected: Trojan-PSW.Win32.OnLineGames.xjk skipped
C:\System Volume Information\_restore{A3903B9C-587A-40B6-B91B-F7BC00691491}\RP103\A0010210.dll Infected: Worm.Win32.AutoRun.dda skipped
C:\System Volume Information\_restore{A3903B9C-587A-40B6-B91B-F7BC00691491}\RP104\A0011217.exe Object is locked skipped
C:\System Volume Information\_restore{A3903B9C-587A-40B6-B91B-F7BC00691491}\RP104\A0011232.exe Object is locked skipped
C:\System Volume Information\_restore{A3903B9C-587A-40B6-B91B-F7BC00691491}\RP106\A0011298.exe Object is locked skipped
C:\System Volume Information\_restore{A3903B9C-587A-40B6-B91B-F7BC00691491}\RP107\A0011449.exe Object is locked skipped
C:\System Volume Information\_restore{A3903B9C-587A-40B6-B91B-F7BC00691491}\RP107\A0011494.exe Object is locked skipped
C:\System Volume Information\_restore{A3903B9C-587A-40B6-B91B-F7BC00691491}\RP107\A0011523.exe Object is locked skipped
C:\System Volume Information\_restore{A3903B9C-587A-40B6-B91B-F7BC00691491}\RP107\A0011537.exe Object is locked skipped
C:\System Volume Information\_restore{A3903B9C-587A-40B6-B91B-F7BC00691491}\RP107\A0011558.exe Object is locked skipped
C:\System Volume Information\_restore{A3903B9C-587A-40B6-B91B-F7BC00691491}\RP108\A0011673.dll Infected: Trojan-PSW.Win32.OnLineGames.yop skipped
C:\System Volume Information\_restore{A3903B9C-587A-40B6-B91B-F7BC00691491}\RP108\A0011674.exe Object is locked skipped
C:\System Volume Information\_restore{A3903B9C-587A-40B6-B91B-F7BC00691491}\RP108\A0011676.inf Infected: Trojan-PSW.Win32.OnLineGames.yop skipped
C:\System Volume Information\_restore{A3903B9C-587A-40B6-B91B-F7BC00691491}\RP108\A0011721.bat Object is locked skipped
C:\System Volume Information\_restore{A3903B9C-587A-40B6-B91B-F7BC00691491}\RP108\A0011732.com Object is locked skipped
C:\System Volume Information\_restore{A3903B9C-587A-40B6-B91B-F7BC00691491}\RP108\A0011768.exe Object is locked skipped
C:\System Volume Information\_restore{A3903B9C-587A-40B6-B91B-F7BC00691491}\RP108\A0011769.dll Infected: Trojan-PSW.Win32.OnLineGames.yrz skipped
C:\System Volume Information\_restore{A3903B9C-587A-40B6-B91B-F7BC00691491}\RP108\A0011770.exe Object is locked skipped
C:\System Volume Information\_restore{A3903B9C-587A-40B6-B91B-F7BC00691491}\RP108\A0011771.inf Infected: Trojan-PSW.Win32.OnLineGames.ysc skipped
C:\System Volume Information\_restore{A3903B9C-587A-40B6-B91B-F7BC00691491}\RP108\A0011773.exe Object is locked skipped
C:\System Volume Information\_restore{A3903B9C-587A-40B6-B91B-F7BC00691491}\RP109\A0011820.exe Object is locked skipped
C:\System Volume Information\_restore{A3903B9C-587A-40B6-B91B-F7BC00691491}\RP109\A0011821.com Object is locked skipped
C:\System Volume Information\_restore{A3903B9C-587A-40B6-B91B-F7BC00691491}\RP110\change.log Object is locked skipped
C:\System Volume Information\_restore{A3903B9C-587A-40B6-B91B-F7BC00691491}\RP92\A0008087.dll Infected: Packed.Win32.PolyCrypt.h skipped
C:\System Volume Information\_restore{A3903B9C-587A-40B6-B91B-F7BC00691491}\RP92\A0008107.dll Infected: Packed.Win32.PolyCrypt.h skipped
C:\System Volume Information\_restore{A3903B9C-587A-40B6-B91B-F7BC00691491}\RP95\A0008260.dll Infected: Packed.Win32.PolyCrypt.h skipped
C:\System Volume Information\_restore{A3903B9C-587A-40B6-B91B-F7BC00691491}\RP95\A0009259.dll Infected: Packed.Win32.PolyCrypt.h skipped
C:\System Volume Information\_restore{A3903B9C-587A-40B6-B91B-F7BC00691491}\RP95\A0009285.dll Infected: Packed.Win32.PolyCrypt.h skipped
C:\System Volume Information\_restore{A3903B9C-587A-40B6-B91B-F7BC00691491}\RP95\A0009290.exe Object is locked skipped
C:\System Volume Information\_restore{A3903B9C-587A-40B6-B91B-F7BC00691491}\RP95\A0009298.dll Infected: Trojan-PSW.Win32.OnLineGames.uqu skipped
C:\System Volume Information\_restore{A3903B9C-587A-40B6-B91B-F7BC00691491}\RP95\A0009305.dll Infected: Trojan-PSW.Win32.OnLineGames.uqu skipped
C:\System Volume Information\_restore{A3903B9C-587A-40B6-B91B-F7BC00691491}\RP95\A0009313.dll Infected: Trojan-PSW.Win32.OnLineGames.uqu skipped
C:\System Volume Information\_restore{A3903B9C-587A-40B6-B91B-F7BC00691491}\RP95\A0009328.dll Infected: Trojan-PSW.Win32.OnLineGames.uqu skipped
C:\System Volume Information\_restore{A3903B9C-587A-40B6-B91B-F7BC00691491}\RP95\A0009333.exe Object is locked skipped
C:\System Volume Information\_restore{A3903B9C-587A-40B6-B91B-F7BC00691491}\RP95\A0009346.dll Infected: Trojan-PSW.Win32.OnLineGames.uqu skipped
C:\System Volume Information\_restore{A3903B9C-587A-40B6-B91B-F7BC00691491}\RP95\A0009352.exe Object is locked skipped
C:\System Volume Information\_restore{A3903B9C-587A-40B6-B91B-F7BC00691491}\RP95\A0009353.dll Infected: Trojan-PSW.Win32.OnLineGames.urf skipped
C:\System Volume Information\_restore{A3903B9C-587A-40B6-B91B-F7BC00691491}\RP96\A0009403.dll Infected: Trojan-PSW.Win32.OnLineGames.uqu skipped
C:\System Volume Information\_restore{A3903B9C-587A-40B6-B91B-F7BC00691491}\RP96\A0009415.dll Infected: Trojan-PSW.Win32.OnLineGames.urf skipped
C:\System Volume Information\_restore{A3903B9C-587A-40B6-B91B-F7BC00691491}\RP96\A0009416.dll Infected: Trojan-PSW.Win32.OnLineGames.uqu skipped
C:\System Volume Information\_restore{A3903B9C-587A-40B6-B91B-F7BC00691491}\RP96\A0009421.exe Object is locked skipped
C:\System Volume Information\_restore{A3903B9C-587A-40B6-B91B-F7BC00691491}\RP96\A0009422.dll Infected: Trojan-PSW.Win32.OnLineGames.urf skipped
C:\System Volume Information\_restore{A3903B9C-587A-40B6-B91B-F7BC00691491}\RP96\A0009434.dll Infected: Trojan-PSW.Win32.OnLineGames.urf skipped
C:\System Volume Information\_restore{A3903B9C-587A-40B6-B91B-F7BC00691491}\RP96\A0009435.dll Infected: Trojan-PSW.Win32.OnLineGames.uqu skipped
C:\System Volume Information\_restore{A3903B9C-587A-40B6-B91B-F7BC00691491}\RP96\A0009442.dll Infected: Trojan-PSW.Win32.OnLineGames.uqu skipped
C:\System Volume Information\_restore{A3903B9C-587A-40B6-B91B-F7BC00691491}\RP97\A0009486.dll Infected: Trojan-PSW.Win32.OnLineGames.urf skipped
C:\System Volume Information\_restore{A3903B9C-587A-40B6-B91B-F7BC00691491}\RP97\A0009487.dll Infected: Trojan-PSW.Win32.OnLineGames.uqu skipped
C:\System Volume Information\_restore{A3903B9C-587A-40B6-B91B-F7BC00691491}\RP97\A0009493.dll Infected: Packed.Win32.PolyCrypt.h skipped
C:\System Volume Information\_restore{A3903B9C-587A-40B6-B91B-F7BC00691491}\RP97\A0009494.exe Object is locked skipped
C:\System Volume Information\_restore{A3903B9C-587A-40B6-B91B-F7BC00691491}\RP97\A0009495.dll Infected: Trojan-PSW.Win32.OnLineGames.urf skipped
C:\System Volume Information\_restore{A3903B9C-587A-40B6-B91B-F7BC00691491}\RP97\A0009511.exe Object is locked skipped
C:\System Volume Information\_restore{A3903B9C-587A-40B6-B91B-F7BC00691491}\RP97\A0009512.dll Infected: Trojan-PSW.Win32.OnLineGames.wfq skipped
C:\System Volume Information\_restore{A3903B9C-587A-40B6-B91B-F7BC00691491}\RP97\A0009514.dll Infected: Trojan-PSW.Win32.OnLineGames.wfo skipped
C:\System Volume Information\_restore{A3903B9C-587A-40B6-B91B-F7BC00691491}\RP97\A0009524.dll Infected: Trojan-PSW.Win32.OnLineGames.wfo skipped
C:\System Volume Information\_restore{A3903B9C-587A-40B6-B91B-F7BC00691491}\RP97\A0009547.dll Infected: Trojan-PSW.Win32.OnLineGames.wfq skipped
C:\System Volume Information\_restore{A3903B9C-587A-40B6-B91B-F7BC00691491}\RP97\A0009548.dll Infected: Trojan-PSW.Win32.OnLineGames.wfo skipped
C:\System Volume Information\_restore{A3903B9C-587A-40B6-B91B-F7BC00691491}\RP98\A0009585.dll Infected: Trojan-PSW.Win32.OnLineGames.wfq skipped
C:\System Volume Information\_restore{A3903B9C-587A-40B6-B91B-F7BC00691491}\RP98\A0009586.dll Infected: Trojan-PSW.Win32.OnLineGames.wfo skipped
C:\System Volume Information\_restore{A3903B9C-587A-40B6-B91B-F7BC00691491}\RP98\A0009592.dll Infected: Trojan-PSW.Win32.OnLineGames.wfo skipped
C:\System Volume Information\_restore{A3903B9C-587A-40B6-B91B-F7BC00691491}\RP98\A0009610.dll Infected: Trojan-PSW.Win32.OnLineGames.wfo skipped
C:\System Volume Information\_restore{A3903B9C-587A-40B6-B91B-F7BC00691491}\RP98\A0009611.dll Infected: Trojan-PSW.Win32.OnLineGames.wfq skipped
C:\System Volume Information\_restore{A3903B9C-587A-40B6-B91B-F7BC00691491}\RP98\A0009618.dll Infected: Trojan-PSW.Win32.OnLineGames.vkf skipped
C:\System Volume Information\_restore{A3903B9C-587A-40B6-B91B-F7BC00691491}\RP98\A0009619.exe Object is locked skipped
C:\System Volume Information\_restore{A3903B9C-587A-40B6-B91B-F7BC00691491}\RP98\A0009620.dll Infected: Trojan-PSW.Win32.OnLineGames.wfq skipped
C:\System Volume Information\_restore{A3903B9C-587A-40B6-B91B-F7BC00691491}\RP99\A0009653.dll Infected: Trojan-PSW.Win32.OnLineGames.wfq skipped
C:\System Volume Information\_restore{A3903B9C-587A-40B6-B91B-F7BC00691491}\RP99\A0009654.dll Infected: Trojan-PSW.Win32.OnLineGames.vkf skipped
C:\System Volume Information\_restore{A3903B9C-587A-40B6-B91B-F7BC00691491}\RP99\A0009659.exe Object is locked skipped
C:\System Volume Information\_restore{A3903B9C-587A-40B6-B91B-F7BC00691491}\RP99\A0009660.dll Infected: Trojan-PSW.Win32.OnLineGames.vki skipped
C:\System Volume Information\_restore{A3903B9C-587A-40B6-B91B-F7BC00691491}\RP99\A0009662.dll Infected: Trojan-PSW.Win32.OnLineGames.vkf skipped
C:\System Volume Information\_restore{A3903B9C-587A-40B6-B91B-F7BC00691491}\RP99\A0009674.dll Infected: Trojan-PSW.Win32.OnLineGames.vkf skipped
C:\System Volume Information\_restore{A3903B9C-587A-40B6-B91B-F7BC00691491}\RP99\A0009675.dll Infected: Trojan-PSW.Win32.OnLineGames.vki skipped
C:\System Volume Information\_restore{A3903B9C-587A-40B6-B91B-F7BC00691491}\RP99\A0009677.inf Infected: Trojan-PSW.Win32.OnLineGames.vos skipped
C:\System Volume Information\_restore{A3903B9C-587A-40B6-B91B-F7BC00691491}\RP99\A0009693.dll Infected: Trojan-PSW.Win32.OnLineGames.vun skipped
C:\System Volume Information\_restore{A3903B9C-587A-40B6-B91B-F7BC00691491}\RP99\A0009694.dll Infected: Trojan-PSW.Win32.OnLineGames.vos skipped
C:\System Volume Information\_restore{A3903B9C-587A-40B6-B91B-F7BC00691491}\RP99\A0009697.inf Infected: Trojan-PSW.Win32.OnLineGames.vos skipped
C:\System Volume Information\_restore{A3903B9C-587A-40B6-B91B-F7BC00691491}\RP99\A0009700.exe Object is locked skipped
C:\System Volume Information\_restore{A3903B9C-587A-40B6-B91B-F7BC00691491}\RP99\A0009701.dll Infected: Trojan-PSW.Win32.OnLineGames.vun skipped
C:\System Volume Information\_restore{A3903B9C-587A-40B6-B91B-F7BC00691491}\RP99\A0009717.dll Infected: Trojan-PSW.Win32.OnLineGames.vun skipped
C:\System Volume Information\_restore{A3903B9C-587A-40B6-B91B-F7BC00691491}\RP99\A0009718.dll Infected: Trojan-PSW.Win32.OnLineGames.vos skipped
C:\System Volume Information\_restore{A3903B9C-587A-40B6-B91B-F7BC00691491}\RP99\A0009720.inf Infected: Trojan-PSW.Win32.OnLineGames.vos skipped
C:\System Volume Information\_restore{A3903B9C-587A-40B6-B91B-F7BC00691491}\RP99\A0009723.exe Object is locked skipped
C:\System Volume Information\_restore{A3903B9C-587A-40B6-B91B-F7BC00691491}\RP99\A0009725.dll Infected: Trojan-PSW.Win32.OnLineGames.vos skipped
C:\System Volume Information\_restore{A3903B9C-587A-40B6-B91B-F7BC00691491}\RP99\A0009752.exe Object is locked skipped
C:\System Volume Information\_restore{A3903B9C-587A-40B6-B91B-F7BC00691491}\RP99\A0009756.exe Object is locked skipped
C:\System Volume Information\_restore{A3903B9C-587A-40B6-B91B-F7BC00691491}\RP99\A0009757.dll Infected: Trojan-PSW.Win32.OnLineGames.vun skipped
C:\System Volume Information\_restore{A3903B9C-587A-40B6-B91B-F7BC00691491}\RP99\A0009771.exe Object is locked skipped
C:\System Volume Information\_restore{A3903B9C-587A-40B6-B91B-F7BC00691491}\RP99\A0009775.exe Object is locked skipped
C:\System Volume Information\_restore{A3903B9C-587A-40B6-B91B-F7BC00691491}\RP99\A0009777.exe Object is locked skipped
C:\System Volume Information\_restore{A3903B9C-587A-40B6-B91B-F7BC00691491}\RP99\A0009792.inf Infected: Trojan-PSW.Win32.OnLineGames.wla skipped
C:\System Volume Information\_restore{A3903B9C-587A-40B6-B91B-F7BC00691491}\RP99\A0009795.exe Object is locked skipped
C:\System Volume Information\_restore{A3903B9C-587A-40B6-B91B-F7BC00691491}\RP99\A0009806.inf Infected: Trojan-PSW.Win32.OnLineGames.wla skipped
C:\System Volume Information\_restore{A3903B9C-587A-40B6-B91B-F7BC00691491}\RP99\A0009809.exe Object is locked skipped
C:\System Volume Information\_restore{A3903B9C-587A-40B6-B91B-F7BC00691491}\RP99\A0009818.inf Infected: Trojan-PSW.Win32.OnLineGames.wla skipped
C:\System Volume Information\_restore{A3903B9C-587A-40B6-B91B-F7BC00691491}\RP99\A0009821.exe Object is locked skipped
C:\WINDOWS\CSC\00000001 Object is locked skipped
C:\WINDOWS\Debug\Netlogon.log Object is locked skipped
C:\WINDOWS\Debug\PASSWD.LOG Object is locked skipped
C:\WINDOWS\Internet Logs\fwdbglog.txt Object is locked skipped
C:\WINDOWS\Internet Logs\fwpktlog.txt Object is locked skipped
C:\WINDOWS\Internet Logs\tvDebug.log Object is locked skipped
C:\WINDOWS\SchedLgU.Txt Object is locked skipped
C:\WINDOWS\SoftwareDistribution\ReportingEvents.log Object is locked skipped
C:\WINDOWS\Sti_Trace.log Object is locked skipped
C:\WINDOWS\system32\CatRoot2\edb.log Object is locked skipped
C:\WINDOWS\system32\CatRoot2\tmp.edb Object is locked skipped
C:\WINDOWS\system32\config\AppEvent.Evt Object is locked skipped
C:\WINDOWS\system32\config\default Object is locked skipped
C:\WINDOWS\system32\config\default.LOG Object is locked skipped
C:\WINDOWS\system32\config\SAM Object is locked skipped
C:\WINDOWS\system32\config\SAM.LOG Object is locked skipped
C:\WINDOWS\system32\config\SecEvent.Evt Object is locked skipped
C:\WINDOWS\system32\config\SECURITY Object is locked skipped
C:\WINDOWS\system32\config\SECURITY.LOG Object is locked skipped
C:\WINDOWS\system32\config\software Object is locked skipped
C:\WINDOWS\system32\config\software.LOG Object is locked skipped
C:\WINDOWS\system32\config\SysEvent.Evt Object is locked skipped
C:\WINDOWS\system32\config\system Object is locked skipped
C:\WINDOWS\system32\config\system.LOG Object is locked skipped
C:\WINDOWS\system32\h323log.txt Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\INDEX.BTR Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\INDEX.MAP Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\MAPPING.VER Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\MAPPING1.MAP Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\MAPPING2.MAP Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\OBJECTS.DATA Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\OBJECTS.MAP Object is locked skipped
C:\WINDOWS\wiadebug.log Object is locked skipped
C:\WINDOWS\wiaservc.log Object is locked skipped
C:\WINDOWS\WindowsUpdate.log Object is locked skipped
D:\dyr2j6mv.exe Object is locked skipped
D:\ekf6dbg0.com Object is locked skipped
D:\f.exe Object is locked skipped
D:\h1ahxi.bat Object is locked skipped
D:\System Volume Information\MountPointManagerRemoteDatabase Object is locked skipped
D:\System Volume Information\_restore{A3903B9C-587A-40B6-B91B-F7BC00691491}\RP100\A0009873.com Object is locked skipped
D:\System Volume Information\_restore{A3903B9C-587A-40B6-B91B-F7BC00691491}\RP100\A0009874.inf Infected: Trojan-PSW.Win32.OnLineGames.wlc skipped
D:\System Volume Information\_restore{A3903B9C-587A-40B6-B91B-F7BC00691491}\RP100\A0009894.com Object is locked skipped
D:\System Volume Information\_restore{A3903B9C-587A-40B6-B91B-F7BC00691491}\RP100\A0009895.inf Infected: Trojan-PSW.Win32.OnLineGames.wlc skipped
D:\System Volume Information\_restore{A3903B9C-587A-40B6-B91B-F7BC00691491}\RP100\A0009913.com Object is locked skipped
D:\System Volume Information\_restore{A3903B9C-587A-40B6-B91B-F7BC00691491}\RP100\A0009914.inf Infected: Trojan-PSW.Win32.OnLineGames.wlc skipped
D:\System Volume Information\_restore{A3903B9C-587A-40B6-B91B-F7BC00691491}\RP100\A0009928.com Object is locked skipped
D:\System Volume Information\_restore{A3903B9C-587A-40B6-B91B-F7BC00691491}\RP100\A0009929.inf Infected: Trojan-PSW.Win32.OnLineGames.wlc skipped
D:\System Volume Information\_restore{A3903B9C-587A-40B6-B91B-F7BC00691491}\RP100\A0009943.com Object is locked skipped
D:\System Volume Information\_restore{A3903B9C-587A-40B6-B91B-F7BC00691491}\RP100\A0009944.inf Infected: Trojan-PSW.Win32.OnLineGames.wlc skipped
D:\System Volume Information\_restore{A3903B9C-587A-40B6-B91B-F7BC00691491}\RP100\A0009959.com Object is locked skipped
D:\System Volume Information\_restore{A3903B9C-587A-40B6-B91B-F7BC00691491}\RP100\A0009960.inf Infected: Trojan-PSW.Win32.OnLineGames.wlc skipped
D:\System Volume Information\_restore{A3903B9C-587A-40B6-B91B-F7BC00691491}\RP102\A0010157.com Object is locked skipped
D:\System Volume Information\_restore{A3903B9C-587A-40B6-B91B-F7BC00691491}\RP102\A0010158.inf Infected: Trojan-PSW.Win32.OnLineGames.wlc skipped
D:\System Volume Information\_restore{A3903B9C-587A-40B6-B91B-F7BC00691491}\RP103\A0010164.bat Object is locked skipped
D:\System Volume Information\_restore{A3903B9C-587A-40B6-B91B-F7BC00691491}\RP103\A0010194.bat Object is locked skipped
D:\System Volume Information\_restore{A3903B9C-587A-40B6-B91B-F7BC00691491}\RP108\A0011677.inf Infected: Trojan-PSW.Win32.OnLineGames.yop skipped
D:\System Volume Information\_restore{A3903B9C-587A-40B6-B91B-F7BC00691491}\RP108\A0011722.bat Object is locked skipped
D:\System Volume Information\_restore{A3903B9C-587A-40B6-B91B-F7BC00691491}\RP108\A0011733.com Object is locked skipped
D:\System Volume Information\_restore{A3903B9C-587A-40B6-B91B-F7BC00691491}\RP108\A0011772.inf Infected: Trojan-PSW.Win32.OnLineGames.ysc skipped
D:\System Volume Information\_restore{A3903B9C-587A-40B6-B91B-F7BC00691491}\RP109\A0011864.bat Object is locked skipped
D:\System Volume Information\_restore{A3903B9C-587A-40B6-B91B-F7BC00691491}\RP110\change.log Object is locked skipped
D:\System Volume Information\_restore{A3903B9C-587A-40B6-B91B-F7BC00691491}\RP99\A0009679.inf Infected: Trojan-PSW.Win32.OnLineGames.vos skipped
D:\System Volume Information\_restore{A3903B9C-587A-40B6-B91B-F7BC00691491}\RP99\A0009699.inf Infected: Trojan-PSW.Win32.OnLineGames.vos skipped
D:\System Volume Information\_restore{A3903B9C-587A-40B6-B91B-F7BC00691491}\RP99\A0009722.inf Infected: Trojan-PSW.Win32.OnLineGames.vos skipped
D:\System Volume Information\_restore{A3903B9C-587A-40B6-B91B-F7BC00691491}\RP99\A0009754.exe Object is locked skipped
D:\System Volume Information\_restore{A3903B9C-587A-40B6-B91B-F7BC00691491}\RP99\A0009773.exe Object is locked skipped
D:\System Volume Information\_restore{A3903B9C-587A-40B6-B91B-F7BC00691491}\RP99\A0009794.inf Infected: Trojan-PSW.Win32.OnLineGames.wla skipped
D:\System Volume Information\_restore{A3903B9C-587A-40B6-B91B-F7BC00691491}\RP99\A0009808.inf Infected: Trojan-PSW.Win32.OnLineGames.wla skipped
D:\System Volume Information\_restore{A3903B9C-587A-40B6-B91B-F7BC00691491}\RP99\A0009820.inf Infected: Trojan-PSW.Win32.OnLineGames.wla skipped
Scan process completed.