spyware problem

Discussion in 'Windows - Virus and spyware problems' started by mayuen, Aug 22, 2006.

  1. mayuen

    mayuen Member

    Joined:
    Apr 22, 2006
    Messages:
    12
    Likes Received:
    0
    Trophy Points:
    11
    this is the log for my friend's computer which is attacked by spyware. i don't know what happen before. can u help me tofind out the problem?

    thz a lot!



    Logfile of HijackThis v1.99.1
    Scan saved at 22:12:28, on 22/8/2006
    Platform: Windows XP SP2 (WinNT 5.01.2600)
    MSIE: Internet Explorer v6.00 SP1 (6.00.2900.2180)

    Running processes:
    C:\WINDOWS\System32\smss.exe
    C:\WINDOWS\system32\winlogon.exe
    C:\WINDOWS\system32\services.exe
    C:\WINDOWS\system32\lsass.exe
    C:\WINDOWS\system32\svchost.exe
    C:\Program Files\Windows Defender\MsMpEng.exe
    C:\WINDOWS\System32\svchost.exe
    C:\WINDOWS\system32\spoolsv.exe
    C:\WINDOWS\Explorer.EXE
    C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
    C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
    C:\PROGRA~1\Grisoft\AVGFRE~1\avgemc.exe
    C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
    C:\Program Files\ewido anti-spyware 4.0\guard.exe
    C:\WINDOWS\System32\nvsvc32.exe
    C:\WINDOWS\System32\tcpsvcs.exe
    C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe
    C:\Program Files\Common Files\Symantec Shared\Security Center\SymWSC.exe
    C:\WINDOWS\system32\rundll32.exe
    C:\Program Files\IBM\Messages By IBM\ibmmessages.exe
    C:\WINDOWS\system32\dla\tfswctrl.exe
    C:\WINDOWS\system32\SKDAEMON.EXE
    C:\WINDOWS\system32\ICO.EXE
    C:\Program Files\iTunes\iTunesHelper.exe
    C:\Program Files\QuickTime\qttask.exe
    C:\Program Files\Windows Defender\MSASCui.exe
    C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe
    C:\Program Files\ewido anti-spyware 4.0\ewido.exe
    C:\WINDOWS\system32\ctfmon.exe
    C:\Program Files\iPod\bin\iPodService.exe
    C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
    C:\Program Files\WinZip\WZQKPICK.EXE
    C:\WINDOWS\system32\Pelmiced.exe
    C:\WINDOWS\system32\wuauclt.exe
    C:\Documents and Settings\Chilly\My Documents\software file\HijackThis_v1.99.1.exe

    R3 - Default URLSearchHook is missing
    O2 - BHO: (no name) - {17AF3D30-061C-15C3-F3DD-FF77212FA819} - (no file)
    O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - C:\Program Files\Norton AntiVirus\NavShExt.dll (file missing)
    O4 - HKLM\..\Run: [IMJPMIG8.1] "C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE" /Spoil /RemAdvDef /Migration32
    O4 - HKLM\..\Run: [PHIME2002ASync] C:\WINDOWS\System32\IME\TINTLGNT\TINTSETP.EXE /SYNC
    O4 - HKLM\..\Run: [PHIME2002A] C:\WINDOWS\System32\IME\TINTLGNT\TINTSETP.EXE /IMEName
    O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\System32\NvCpl.dll,NvStartup
    O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
    O4 - HKLM\..\Run: [BluetoothAuthenticationAgent] rundll32.exe irprops.cpl,,BluetoothAuthenticationAgent
    O4 - HKLM\..\Run: [ibmmessages] C:\Program Files\IBM\Messages By IBM\ibmmessages.exe
    O4 - HKLM\..\Run: [dla] C:\WINDOWS\system32\dla\tfswctrl.exe
    O4 - HKLM\..\Run: [IMEKRMIG6.1] C:\WINDOWS\ime\imkr6_1\IMEKRMIG.EXE
    O4 - HKLM\..\Run: [MSPY2002] C:\WINDOWS\System32\IME\PINTLGNT\ImScInst.exe /SYNC
    O4 - HKLM\..\Run: [Hot Key Kbd Daemon] SKDAEMON.EXE
    O4 - HKLM\..\Run: [Mouse Suite 98 Daemon] ICO.EXE
    O4 - HKLM\..\Run: [atlja32.exe] C:\WINDOWS\system32\atlja32.exe
    O4 - HKLM\..\Run: [REGSHAVE] C:\Program Files\REGSHAVE\REGSHAVE.EXE /AUTORUN
    O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
    O4 - HKLM\..\Run: [ccRegVfy] "C:\Program Files\Common Files\Symantec Shared\ccRegVfy.exe"
    O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
    O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
    O4 - HKLM\..\Run: [Symantec NetDriver Monitor] C:\PROGRA~1\SYMNET~1\SNDMon.exe /Consumer
    O4 - HKLM\..\Run: [Windows Defender] "C:\Program Files\Windows Defender\MSASCui.exe" -hide
    O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe /STARTUP
    O4 - HKLM\..\Run: [!ewido] "C:\Program Files\ewido anti-spyware 4.0\ewido.exe" /minimized
    O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
    O4 - HKCU\..\Run: [Spyware Begone] C:\freescan\freescan.exe -FastScan
    O4 - HKCU\..\Run: [Spyware Vanisher] C:\spywarevanisher-free\FreeScanner.exe -FastScan
    O4 - HKCU\..\Run: [PcSync] C:\Program Files\Nokia\Nokia PC Suite 6\PcSync2.exe /NoDialog
    O4 - HKCU\..\Run: [ibmmessages] C:\Program Files\IBM\Messages By IBM\ibmmessages.exe
    O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
    O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
    O11 - Options group: [JAVA_IBM] Java (IBM)
    O15 - Trusted Zone: *.05p.com
    O15 - Trusted Zone: http://*.billingnow.com
    O15 - Trusted Zone: http://*.reliablestats.com
    O15 - Trusted Zone: *.scoobidoo.com
    O15 - Trusted Zone: http://*.winantispyware.com
    O15 - Trusted Zone: http://*.winantivirus.com
    O15 - Trusted Zone: http://*.winantiviruspro.com
    O15 - Trusted Zone: http://*.winfixer.com
    O15 - Trusted Zone: http://*.winnanny.com
    O15 - Trusted Zone: http://*.winsoftware.com
    O15 - Trusted Zone: *.05p.com (HKLM)
    O15 - Trusted Zone: *.scoobidoo.com (HKLM)
    O15 - Trusted IP range: 206.161.125.149 (HKLM)
    O18 - Protocol: icoo - {86FE362E-74FA-4F71-8B69-B94D28880628} - C:\Program Files\ICOO Loader\addons\icoou.dll (file missing)
    O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll
    O23 - Service: Workstation NetLogon Service ( 11F蛷#滓齡`I) - Unknown owner - C:\WINDOWS\winyy32.exe (file missing)
    O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
    O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
    O23 - Service: AVG E-mail Scanner (AVGEMS) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgemc.exe
    O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
    O23 - Service: Symantec Password Validation Service (ccPwdSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccPwdSvc.exe
    O23 - Service: ewido anti-spyware 4.0 guard - Anti-Malware Development a.s. - C:\Program Files\ewido anti-spyware 4.0\guard.exe
    O23 - Service: iPod 服務 (iPodService) - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
    O23 - Service: NVIDIA Driver Helper Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\System32\nvsvc32.exe
    O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
    O23 - Service: SoundMAX Agent Service (SoundMAX Agent Service (default)) - Analog Devices, Inc. - C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe
    O23 - Service: SymWMI Service (SymWSC) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\Security Center\SymWSC.exe
    O23 - Service: TrueVector Internet Monitor (vsmon) - Unknown owner - C:\WINDOWS\system32\ZoneLabs\vsmon.exe (file missing)

     
    Last edited: Aug 22, 2006
  2. mayuen

    mayuen Member

    Joined:
    Apr 22, 2006
    Messages:
    12
    Likes Received:
    0
    Trophy Points:
    11
    btw, what should i do with the above log of ewido anti-spyware? i've not done anything to destory or delete the scan result.
     
  3. Woz

    Woz Regular member

    Joined:
    Dec 6, 2002
    Messages:
    239
    Likes Received:
    0
    Trophy Points:
    26
    Download SPYBOT.

    I think its the best, it has cleaned everything out in the past for me. Its free as well!

    Run it and see if it solves your problems.

    Woz
     
  4. tmfloria

    tmfloria Active member

    Joined:
    Sep 30, 2003
    Messages:
    1,127
    Likes Received:
    0
    Trophy Points:
    66
    I use Spybot Ad-Aware & Spyware Doctor on my system and my system stays clean

     
  5. Niobis

    Niobis Active member

    Joined:
    Jan 30, 2005
    Messages:
    2,326
    Likes Received:
    0
    Trophy Points:
    66
    First of all you didn't delete the items with Ewdio. Look in your quarantine and delete them all. Then, run a new Ewido scan in safe mode(press F8 upon boot, select "Safe Mode" from menu). Be sure if Ewido finds anything with new scan delete them.

    Next, run a scan with HijackThis, check and fix these:

    [bold]R3 - Default URLSearchHook is missing

    O2 - BHO: (no name) - {17AF3D30-061C-15C3-F3DD-FF77212FA819} - (no file)

    O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - C:\Program Files\Norton AntiVirus\NavShExt.dll (file missing)

    O18 - Protocol: icoo - {86FE362E-74FA-4F71-8B69-B94D28880628} - C:\Program Files\ICOO Loader\addons\icoou.dll (file missing) [/bold]

    Post new HijkackThis log along with a new Ewdio log.
     
    Last edited: Aug 22, 2006
  6. maca1

    maca1 Regular member

    Joined:
    Mar 15, 2006
    Messages:
    630
    Likes Received:
    0
    Trophy Points:
    26
    Check all these also

    O15 - Trusted Zone: *.05p.com
    O15 - Trusted Zone: http://*.billingnow.com
    O15 - Trusted Zone: http://*.reliablestats.com
    O15 - Trusted Zone: *.scoobidoo.com
    O15 - Trusted Zone: http://*.winantispyware.com
    O15 - Trusted Zone: http://*.winantivirus.com
    O15 - Trusted Zone: http://*.winantiviruspro.com
    O15 - Trusted Zone: http://*.winfixer.com
    O15 - Trusted Zone: http://*.winnanny.com
    O15 - Trusted Zone: http://*.winsoftware.com
    O15 - Trusted Zone: *.05p.com (HKLM)
    O15 - Trusted Zone: *.scoobidoo.com (HKLM)
    O15 - Trusted IP range: 206.161.125.149 (HKLM)

    make sure all other windows are closed and click Fix checked

    There are more but would have to see new hijacjthis log in case they're gone.
     
  7. mayuen

    mayuen Member

    Joined:
    Apr 22, 2006
    Messages:
    12
    Likes Received:
    0
    Trophy Points:
    11
    thank you! Niobis and maca1.

    i've tried twice but this one can not be fixed.
    O2 - BHO: (no name) - {17AF3D30-061C-15C3-F3DD-FF77212FA819} - (no file)

    Here is the latest hijackthis log.

    Logfile of HijackThis v1.99.1
    Scan saved at 18:18:10, on 23/8/2006
    Platform: Windows XP SP2 (WinNT 5.01.2600)
    MSIE: Internet Explorer v6.00 SP1 (6.00.2900.2180)

    Running processes:
    C:\WINDOWS\System32\smss.exe
    C:\WINDOWS\system32\winlogon.exe
    C:\WINDOWS\system32\services.exe
    C:\WINDOWS\system32\lsass.exe
    C:\WINDOWS\system32\svchost.exe
    C:\Program Files\Windows Defender\MsMpEng.exe
    C:\WINDOWS\System32\svchost.exe
    C:\WINDOWS\system32\spoolsv.exe
    C:\WINDOWS\Explorer.EXE
    C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
    C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
    C:\PROGRA~1\Grisoft\AVGFRE~1\avgemc.exe
    C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
    C:\Program Files\ewido anti-spyware 4.0\guard.exe
    C:\WINDOWS\System32\nvsvc32.exe
    C:\WINDOWS\System32\tcpsvcs.exe
    C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe
    C:\Program Files\Common Files\Symantec Shared\Security Center\SymWSC.exe
    C:\Program Files\IBM\Messages By IBM\ibmmessages.exe
    C:\WINDOWS\system32\dla\tfswctrl.exe
    C:\WINDOWS\system32\SKDAEMON.EXE
    C:\WINDOWS\system32\ICO.EXE
    C:\WINDOWS\system32\Pelmiced.exe
    C:\Program Files\iTunes\iTunesHelper.exe
    C:\Program Files\QuickTime\qttask.exe
    C:\Program Files\Windows Defender\MSASCui.exe
    C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe
    C:\Program Files\ewido anti-spyware 4.0\ewido.exe
    C:\WINDOWS\system32\ctfmon.exe
    C:\Program Files\iPod\bin\iPodService.exe
    C:\Program Files\WinZip\WZQKPICK.EXE
    C:\Documents and Settings\Chilly\My Documents\software file\HijackThis_v1.99.1.exe

    O2 - BHO: (no name) - {17AF3D30-061C-15C3-F3DD-FF77212FA819} - (no file)
    O4 - HKLM\..\Run: [IMJPMIG8.1] "C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE" /Spoil /RemAdvDef /Migration32
    O4 - HKLM\..\Run: [PHIME2002ASync] C:\WINDOWS\System32\IME\TINTLGNT\TINTSETP.EXE /SYNC
    O4 - HKLM\..\Run: [PHIME2002A] C:\WINDOWS\System32\IME\TINTLGNT\TINTSETP.EXE /IMEName
    O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\System32\NvCpl.dll,NvStartup
    O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
    O4 - HKLM\..\Run: [BluetoothAuthenticationAgent] rundll32.exe irprops.cpl,,BluetoothAuthenticationAgent
    O4 - HKLM\..\Run: [ibmmessages] C:\Program Files\IBM\Messages By IBM\ibmmessages.exe
    O4 - HKLM\..\Run: [dla] C:\WINDOWS\system32\dla\tfswctrl.exe
    O4 - HKLM\..\Run: [IMEKRMIG6.1] C:\WINDOWS\ime\imkr6_1\IMEKRMIG.EXE
    O4 - HKLM\..\Run: [MSPY2002] C:\WINDOWS\System32\IME\PINTLGNT\ImScInst.exe /SYNC
    O4 - HKLM\..\Run: [Hot Key Kbd Daemon] SKDAEMON.EXE
    O4 - HKLM\..\Run: [Mouse Suite 98 Daemon] ICO.EXE
    O4 - HKLM\..\Run: [atlja32.exe] C:\WINDOWS\system32\atlja32.exe
    O4 - HKLM\..\Run: [REGSHAVE] C:\Program Files\REGSHAVE\REGSHAVE.EXE /AUTORUN
    O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
    O4 - HKLM\..\Run: [ccRegVfy] "C:\Program Files\Common Files\Symantec Shared\ccRegVfy.exe"
    O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
    O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
    O4 - HKLM\..\Run: [Symantec NetDriver Monitor] C:\PROGRA~1\SYMNET~1\SNDMon.exe /Consumer
    O4 - HKLM\..\Run: [Windows Defender] "C:\Program Files\Windows Defender\MSASCui.exe" -hide
    O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe /STARTUP
    O4 - HKLM\..\Run: [!ewido] "C:\Program Files\ewido anti-spyware 4.0\ewido.exe" /minimized
    O4 - HKLM\..\Run: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k
    O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
    O4 - HKCU\..\Run: [Spyware Begone] C:\freescan\freescan.exe -FastScan
    O4 - HKCU\..\Run: [Spyware Vanisher] C:\spywarevanisher-free\FreeScanner.exe -FastScan
    O4 - HKCU\..\Run: [PcSync] C:\Program Files\Nokia\Nokia PC Suite 6\PcSync2.exe /NoDialog
    O4 - HKCU\..\Run: [ibmmessages] C:\Program Files\IBM\Messages By IBM\ibmmessages.exe
    O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
    O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
    O11 - Options group: [JAVA_IBM] Java (IBM)
    O18 - Protocol: about - {3050F406-98B5-11CF-BB82-00AA00BDCE0B} - C:\WINDOWS\System32\mshtml.dll
    O18 - Protocol: cdl - {3DD53D40-7B8B-11D0-B013-00AA0059CE02} - C:\WINDOWS\system32\urlmon.dll
    O18 - Protocol: cdo - {CD00020A-8B95-11D1-82DB-00C04FB1625D} - C:\Program Files\Common Files\Microsoft Shared\Web Folders\PKMCDO.DLL
    O18 - Protocol: dvd - {12D51199-0DB5-46FE-A120-47A3D7D937CC} - C:\WINDOWS\system32\msvidctl.dll
    O18 - Protocol: file - {79EAC9E7-BAF9-11CE-8C82-00AA004BA90B} - C:\WINDOWS\system32\urlmon.dll
    O18 - Protocol: ftp - {79EAC9E3-BAF9-11CE-8C82-00AA004BA90B} - C:\WINDOWS\system32\urlmon.dll
    O18 - Protocol: gopher - {79EAC9E4-BAF9-11CE-8C82-00AA004BA90B} - C:\WINDOWS\system32\urlmon.dll
    O18 - Protocol: http - {79EAC9E2-BAF9-11CE-8C82-00AA004BA90B} - C:\WINDOWS\system32\urlmon.dll
    O18 - Protocol: https - {79EAC9E5-BAF9-11CE-8C82-00AA004BA90B} - C:\WINDOWS\system32\urlmon.dll
    O18 - Protocol: ipp - (no CLSID) - (no file)
    O18 - Protocol: its - {9D148291-B9C8-11D0-A4CC-0000F80149F6} - C:\WINDOWS\System32\itss.dll
    O18 - Protocol: javascript - {3050F3B2-98B5-11CF-BB82-00AA00BDCE0B} - C:\WINDOWS\System32\mshtml.dll
    O18 - Protocol: local - {79EAC9E7-BAF9-11CE-8C82-00AA004BA90B} - C:\WINDOWS\system32\urlmon.dll
    O18 - Protocol: mailto - {3050F3DA-98B5-11CF-BB82-00AA00BDCE0B} - C:\WINDOWS\System32\mshtml.dll
    O18 - Protocol: mhtml - {05300401-BCBC-11D0-85E3-00C04FD85AB4} - C:\WINDOWS\System32\inetcomm.dll
    O18 - Protocol: mk - {79EAC9E6-BAF9-11CE-8C82-00AA004BA90B} - C:\WINDOWS\system32\urlmon.dll
    O18 - Protocol: ms-its - {9D148291-B9C8-11D0-A4CC-0000F80149F6} - C:\WINDOWS\System32\itss.dll
    O18 - Protocol: msdaipp - (no CLSID) - (no file)
    O18 - Protocol: res - {3050F3BC-98B5-11CF-BB82-00AA00BDCE0B} - C:\WINDOWS\System32\mshtml.dll
    O18 - Protocol: sysimage - {76E67A63-06E9-11D2-A840-006008059382} - C:\WINDOWS\System32\mshtml.dll
    O18 - Protocol: tv - {CBD30858-AF45-11D2-B6D6-00C04FBBDE6E} - C:\WINDOWS\system32\msvidctl.dll
    O18 - Protocol: vbscript - {3050F3B2-98B5-11CF-BB82-00AA00BDCE0B} - C:\WINDOWS\System32\mshtml.dll
    O18 - Protocol: wia - {13F3EA8B-91D7-4F0A-AD76-D2853AC8BECE} - C:\WINDOWS\System32\wiascr.dll
    O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll
    O23 - Service: Workstation NetLogon Service ( 11F蛷#滓齡`I) - Unknown owner - C:\WINDOWS\winyy32.exe (file missing)
    O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
    O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
    O23 - Service: AVG E-mail Scanner (AVGEMS) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgemc.exe
    O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
    O23 - Service: Symantec Password Validation Service (ccPwdSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccPwdSvc.exe
    O23 - Service: ewido anti-spyware 4.0 guard - Anti-Malware Development a.s. - C:\Program Files\ewido anti-spyware 4.0\guard.exe
    O23 - Service: iPod 服務 (iPodService) - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
    O23 - Service: NVIDIA Driver Helper Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\System32\nvsvc32.exe
    O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
    O23 - Service: SoundMAX Agent Service (SoundMAX Agent Service (default)) - Analog Devices, Inc. - C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe
    O23 - Service: SymWMI Service (SymWSC) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\Security Center\SymWSC.exe
    O23 - Service: TrueVector Internet Monitor (vsmon) - Unknown owner - C:\WINDOWS\system32\ZoneLabs\vsmon.exe (file missing)

     
  8. mayuen

    mayuen Member

    Joined:
    Apr 22, 2006
    Messages:
    12
    Likes Received:
    0
    Trophy Points:
    11
    and this is the latest ewido report
    i scan one more time afterwards and nothing was found



    ---------------------------------------------------------
    ewido anti-spyware - Scan Report
    ---------------------------------------------------------

    + Created at: 17:00:53 23/8/2006

    + Scan result:



    C:\System Volume Information\_restore{43C61967-F800-4B8C-AEAC-365A334DE418}\RP589\A0207192.dll -> Adware.SearchPage : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{43C61967-F800-4B8C-AEAC-365A334DE418}\RP589\A0207190.dll -> Adware.WinAD : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{43C61967-F800-4B8C-AEAC-365A334DE418}\RP589\A0207191.sys -> Adware.Winfixer : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{43C61967-F800-4B8C-AEAC-365A334DE418}\RP589\A0207129.exe -> Backdoor.Small.dc : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{43C61967-F800-4B8C-AEAC-365A334DE418}\RP589\A0207130.exe -> Backdoor.Small.dc : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{43C61967-F800-4B8C-AEAC-365A334DE418}\RP589\A0207131.exe -> Backdoor.Small.dc : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{43C61967-F800-4B8C-AEAC-365A334DE418}\RP589\A0207132.exe -> Backdoor.Small.dc : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{43C61967-F800-4B8C-AEAC-365A334DE418}\RP589\A0207133.exe -> Backdoor.Small.dc : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{43C61967-F800-4B8C-AEAC-365A334DE418}\RP589\A0207134.exe -> Backdoor.Small.dc : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{43C61967-F800-4B8C-AEAC-365A334DE418}\RP589\A0207135.exe -> Backdoor.Small.dc : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{43C61967-F800-4B8C-AEAC-365A334DE418}\RP589\A0207136.exe -> Backdoor.Small.dc : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{43C61967-F800-4B8C-AEAC-365A334DE418}\RP589\A0207137.exe -> Backdoor.Small.dc : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{43C61967-F800-4B8C-AEAC-365A334DE418}\RP589\A0207138.exe -> Backdoor.Small.dc : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{43C61967-F800-4B8C-AEAC-365A334DE418}\RP589\A0207139.exe -> Backdoor.Small.dc : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{43C61967-F800-4B8C-AEAC-365A334DE418}\RP589\A0207140.exe -> Backdoor.Small.dc : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{43C61967-F800-4B8C-AEAC-365A334DE418}\RP589\A0207141.exe -> Backdoor.Small.dc : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{43C61967-F800-4B8C-AEAC-365A334DE418}\RP589\A0207142.exe -> Backdoor.Small.dc : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{43C61967-F800-4B8C-AEAC-365A334DE418}\RP589\A0207143.exe -> Backdoor.Small.dc : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{43C61967-F800-4B8C-AEAC-365A334DE418}\RP589\A0207144.exe -> Backdoor.Small.dc : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{43C61967-F800-4B8C-AEAC-365A334DE418}\RP589\A0207145.exe -> Backdoor.Small.dc : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{43C61967-F800-4B8C-AEAC-365A334DE418}\RP589\A0207146.exe -> Backdoor.Small.dc : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{43C61967-F800-4B8C-AEAC-365A334DE418}\RP589\A0207147.exe -> Backdoor.Small.dc : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{43C61967-F800-4B8C-AEAC-365A334DE418}\RP589\A0207148.exe -> Backdoor.Small.dc : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{43C61967-F800-4B8C-AEAC-365A334DE418}\RP589\A0207149.exe -> Backdoor.Small.dc : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{43C61967-F800-4B8C-AEAC-365A334DE418}\RP589\A0207150.exe -> Backdoor.Small.dc : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{43C61967-F800-4B8C-AEAC-365A334DE418}\RP589\A0207151.exe -> Backdoor.Small.dc : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{43C61967-F800-4B8C-AEAC-365A334DE418}\RP589\A0207152.exe -> Backdoor.Small.dc : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{43C61967-F800-4B8C-AEAC-365A334DE418}\RP589\A0207153.exe -> Backdoor.Small.dc : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{43C61967-F800-4B8C-AEAC-365A334DE418}\RP589\A0207154.exe -> Backdoor.Small.dc : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{43C61967-F800-4B8C-AEAC-365A334DE418}\RP589\A0207155.exe -> Backdoor.Small.dc : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{43C61967-F800-4B8C-AEAC-365A334DE418}\RP589\A0207156.exe -> Backdoor.Small.dc : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{43C61967-F800-4B8C-AEAC-365A334DE418}\RP589\A0207157.exe -> Backdoor.Small.dc : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{43C61967-F800-4B8C-AEAC-365A334DE418}\RP589\A0207158.exe -> Backdoor.Small.dc : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{43C61967-F800-4B8C-AEAC-365A334DE418}\RP589\A0207159.exe -> Backdoor.Small.dc : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{43C61967-F800-4B8C-AEAC-365A334DE418}\RP589\A0207160.exe -> Backdoor.Small.dc : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{43C61967-F800-4B8C-AEAC-365A334DE418}\RP589\A0207161.exe -> Backdoor.Small.dc : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{43C61967-F800-4B8C-AEAC-365A334DE418}\RP589\A0206030.exe -> Dialer.Holistyc : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{43C61967-F800-4B8C-AEAC-365A334DE418}\RP589\A0207016.EXE:wfskq -> Downloader.Agent.al : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{43C61967-F800-4B8C-AEAC-365A334DE418}\RP589\A0207017.exe -> Downloader.Agent.al : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{43C61967-F800-4B8C-AEAC-365A334DE418}\RP589\A0207018.dll -> Downloader.Agent.al : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{43C61967-F800-4B8C-AEAC-365A334DE418}\RP589\A0207019.dll -> Downloader.Agent.al : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{43C61967-F800-4B8C-AEAC-365A334DE418}\RP589\A0207020.dll -> Downloader.Agent.al : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{43C61967-F800-4B8C-AEAC-365A334DE418}\RP589\A0207021.exe -> Downloader.Agent.al : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{43C61967-F800-4B8C-AEAC-365A334DE418}\RP589\A0207022.dll -> Downloader.Agent.al : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{43C61967-F800-4B8C-AEAC-365A334DE418}\RP589\A0207023.exe -> Downloader.Agent.al : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{43C61967-F800-4B8C-AEAC-365A334DE418}\RP589\A0207024.dll -> Downloader.Agent.al : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{43C61967-F800-4B8C-AEAC-365A334DE418}\RP589\A0207025.dll -> Downloader.Agent.al : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{43C61967-F800-4B8C-AEAC-365A334DE418}\RP589\A0207026.dll -> Downloader.Agent.al : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{43C61967-F800-4B8C-AEAC-365A334DE418}\RP589\A0207027.exe -> Downloader.Agent.al : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{43C61967-F800-4B8C-AEAC-365A334DE418}\RP589\A0207028.dll -> Downloader.Agent.al : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{43C61967-F800-4B8C-AEAC-365A334DE418}\RP589\A0207029.dll -> Downloader.Agent.al : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{43C61967-F800-4B8C-AEAC-365A334DE418}\RP589\A0207030.exe -> Downloader.Agent.al : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{43C61967-F800-4B8C-AEAC-365A334DE418}\RP589\A0207031.dll -> Downloader.Agent.al : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{43C61967-F800-4B8C-AEAC-365A334DE418}\RP589\A0207032.exe -> Downloader.Agent.al : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{43C61967-F800-4B8C-AEAC-365A334DE418}\RP589\A0207033.dll -> Downloader.Agent.al : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{43C61967-F800-4B8C-AEAC-365A334DE418}\RP589\A0207034.dll -> Downloader.Agent.al : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{43C61967-F800-4B8C-AEAC-365A334DE418}\RP589\A0207035.exe -> Downloader.Agent.al : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{43C61967-F800-4B8C-AEAC-365A334DE418}\RP589\A0207036.dll -> Downloader.Agent.al : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{43C61967-F800-4B8C-AEAC-365A334DE418}\RP589\A0207037.dll -> Downloader.Agent.al : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{43C61967-F800-4B8C-AEAC-365A334DE418}\RP589\A0207038.dll -> Downloader.Agent.al : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{43C61967-F800-4B8C-AEAC-365A334DE418}\RP589\A0207039.dll -> Downloader.Agent.al : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{43C61967-F800-4B8C-AEAC-365A334DE418}\RP589\A0207040.dll -> Downloader.Agent.al : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{43C61967-F800-4B8C-AEAC-365A334DE418}\RP589\A0207041.dll -> Downloader.Agent.al : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{43C61967-F800-4B8C-AEAC-365A334DE418}\RP589\A0207042.exe -> Downloader.Agent.al : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{43C61967-F800-4B8C-AEAC-365A334DE418}\RP589\A0207043.dll -> Downloader.Agent.al : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{43C61967-F800-4B8C-AEAC-365A334DE418}\RP589\A0207044.dll -> Downloader.Agent.al : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{43C61967-F800-4B8C-AEAC-365A334DE418}\RP589\A0207045.dll -> Downloader.Agent.al : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{43C61967-F800-4B8C-AEAC-365A334DE418}\RP589\A0207046.exe -> Downloader.Agent.al : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{43C61967-F800-4B8C-AEAC-365A334DE418}\RP589\A0207047.dll -> Downloader.Agent.al : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{43C61967-F800-4B8C-AEAC-365A334DE418}\RP589\A0207048.exe:kyihs -> Downloader.Agent.al : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{43C61967-F800-4B8C-AEAC-365A334DE418}\RP589\A0207049.dll -> Downloader.Agent.al : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{43C61967-F800-4B8C-AEAC-365A334DE418}\RP589\A0207050.exe -> Downloader.Agent.al : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{43C61967-F800-4B8C-AEAC-365A334DE418}\RP589\A0207051.dll -> Downloader.Agent.al : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{43C61967-F800-4B8C-AEAC-365A334DE418}\RP589\A0207052.exe -> Downloader.Agent.al : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{43C61967-F800-4B8C-AEAC-365A334DE418}\RP589\A0207053.dll -> Downloader.Agent.al : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{43C61967-F800-4B8C-AEAC-365A334DE418}\RP589\A0207054.exe -> Downloader.Agent.al : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{43C61967-F800-4B8C-AEAC-365A334DE418}\RP589\A0207055.dll -> Downloader.Agent.al : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{43C61967-F800-4B8C-AEAC-365A334DE418}\RP589\A0207056.exe -> Downloader.Agent.al : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{43C61967-F800-4B8C-AEAC-365A334DE418}\RP589\A0207057.dll -> Downloader.Agent.al : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{43C61967-F800-4B8C-AEAC-365A334DE418}\RP589\A0207058.exe -> Downloader.Agent.al : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{43C61967-F800-4B8C-AEAC-365A334DE418}\RP589\A0207059.exe -> Downloader.Agent.al : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{43C61967-F800-4B8C-AEAC-365A334DE418}\RP589\A0207060.exe -> Downloader.Agent.al : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{43C61967-F800-4B8C-AEAC-365A334DE418}\RP589\A0207061.dll -> Downloader.Agent.al : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{43C61967-F800-4B8C-AEAC-365A334DE418}\RP589\A0207062.exe -> Downloader.Agent.al : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{43C61967-F800-4B8C-AEAC-365A334DE418}\RP589\A0207063.dll -> Downloader.Agent.al : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{43C61967-F800-4B8C-AEAC-365A334DE418}\RP589\A0207064.exe -> Downloader.Agent.al : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{43C61967-F800-4B8C-AEAC-365A334DE418}\RP589\A0207065.dll -> Downloader.Agent.al : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{43C61967-F800-4B8C-AEAC-365A334DE418}\RP589\A0207066.dll -> Downloader.Agent.al : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{43C61967-F800-4B8C-AEAC-365A334DE418}\RP589\A0207067.exe:brkxp -> Downloader.Agent.al : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{43C61967-F800-4B8C-AEAC-365A334DE418}\RP589\A0207067.exe:hldvr -> Downloader.Agent.al : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{43C61967-F800-4B8C-AEAC-365A334DE418}\RP589\A0207068.dll -> Downloader.Agent.al : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{43C61967-F800-4B8C-AEAC-365A334DE418}\RP589\A0207069.exe -> Downloader.Agent.al : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{43C61967-F800-4B8C-AEAC-365A334DE418}\RP589\A0207070.exe:tuyuh -> Downloader.Agent.al : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{43C61967-F800-4B8C-AEAC-365A334DE418}\RP589\A0207070.exe:wupib -> Downloader.Agent.al : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{43C61967-F800-4B8C-AEAC-365A334DE418}\RP589\A0207071.old:swlpu -> Downloader.Agent.al : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{43C61967-F800-4B8C-AEAC-365A334DE418}\RP589\A0207072.dll -> Downloader.Agent.al : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{43C61967-F800-4B8C-AEAC-365A334DE418}\RP589\A0207073.exe -> Downloader.Agent.al : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{43C61967-F800-4B8C-AEAC-365A334DE418}\RP589\A0207074.exe -> Downloader.Agent.al : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{43C61967-F800-4B8C-AEAC-365A334DE418}\RP589\A0207075.dll -> Downloader.Agent.al : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{43C61967-F800-4B8C-AEAC-365A334DE418}\RP589\A0207076.exe -> Downloader.Agent.al : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{43C61967-F800-4B8C-AEAC-365A334DE418}\RP589\A0207077.dll -> Downloader.Agent.al : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{43C61967-F800-4B8C-AEAC-365A334DE418}\RP589\A0207078.exe -> Downloader.Agent.al : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{43C61967-F800-4B8C-AEAC-365A334DE418}\RP589\A0207079.dll -> Downloader.Agent.al : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{43C61967-F800-4B8C-AEAC-365A334DE418}\RP589\A0207080.dll -> Downloader.Agent.al : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{43C61967-F800-4B8C-AEAC-365A334DE418}\RP589\A0207081.dll -> Downloader.Agent.al : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{43C61967-F800-4B8C-AEAC-365A334DE418}\RP589\A0207082.dll -> Downloader.Agent.al : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{43C61967-F800-4B8C-AEAC-365A334DE418}\RP589\A0207083.dll -> Downloader.Agent.al : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{43C61967-F800-4B8C-AEAC-365A334DE418}\RP589\A0207084.dll -> Downloader.Agent.al : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{43C61967-F800-4B8C-AEAC-365A334DE418}\RP589\A0207085.dll -> Downloader.Agent.al : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{43C61967-F800-4B8C-AEAC-365A334DE418}\RP589\A0207086.exe -> Downloader.Agent.al : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{43C61967-F800-4B8C-AEAC-365A334DE418}\RP589\A0207087.dll -> Downloader.Agent.al : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{43C61967-F800-4B8C-AEAC-365A334DE418}\RP589\A0207088.dll -> Downloader.Agent.al : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{43C61967-F800-4B8C-AEAC-365A334DE418}\RP589\A0207089.dll -> Downloader.Agent.al : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{43C61967-F800-4B8C-AEAC-365A334DE418}\RP589\A0207090.dll -> Downloader.Agent.al : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{43C61967-F800-4B8C-AEAC-365A334DE418}\RP589\A0207091.dll -> Downloader.Agent.al : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{43C61967-F800-4B8C-AEAC-365A334DE418}\RP589\A0207092.exe -> Downloader.Agent.al : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{43C61967-F800-4B8C-AEAC-365A334DE418}\RP589\A0207093.dll -> Downloader.Agent.al : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{43C61967-F800-4B8C-AEAC-365A334DE418}\RP589\A0207094.dll -> Downloader.Agent.al : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{43C61967-F800-4B8C-AEAC-365A334DE418}\RP589\A0207095.exe -> Downloader.Agent.al : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{43C61967-F800-4B8C-AEAC-365A334DE418}\RP589\A0207096.dll -> Downloader.Agent.al : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{43C61967-F800-4B8C-AEAC-365A334DE418}\RP589\A0207097.dll -> Downloader.Agent.al : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{43C61967-F800-4B8C-AEAC-365A334DE418}\RP589\A0207098.dll -> Downloader.Agent.al : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{43C61967-F800-4B8C-AEAC-365A334DE418}\RP589\A0207099.exe -> Downloader.Agent.al : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{43C61967-F800-4B8C-AEAC-365A334DE418}\RP589\A0207100.exe -> Downloader.Agent.al : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{43C61967-F800-4B8C-AEAC-365A334DE418}\RP589\A0207101.exe -> Downloader.Agent.al : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{43C61967-F800-4B8C-AEAC-365A334DE418}\RP589\A0207102.exe -> Downloader.Agent.al : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{43C61967-F800-4B8C-AEAC-365A334DE418}\RP589\A0207103.dll -> Downloader.Agent.al : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{43C61967-F800-4B8C-AEAC-365A334DE418}\RP589\A0207104.exe -> Downloader.Agent.al : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{43C61967-F800-4B8C-AEAC-365A334DE418}\RP589\A0207105.dll -> Downloader.Agent.al : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{43C61967-F800-4B8C-AEAC-365A334DE418}\RP589\A0207106.dll -> Downloader.Agent.al : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{43C61967-F800-4B8C-AEAC-365A334DE418}\RP589\A0207107.dll -> Downloader.Agent.al : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{43C61967-F800-4B8C-AEAC-365A334DE418}\RP589\A0207108.dll -> Downloader.Agent.al : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{43C61967-F800-4B8C-AEAC-365A334DE418}\RP589\A0207109.dll -> Downloader.Agent.al : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{43C61967-F800-4B8C-AEAC-365A334DE418}\RP589\A0207110.dll -> Downloader.Agent.al : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{43C61967-F800-4B8C-AEAC-365A334DE418}\RP589\A0207111.dll -> Downloader.Agent.al : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{43C61967-F800-4B8C-AEAC-365A334DE418}\RP589\A0207112.dll -> Downloader.Agent.al : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{43C61967-F800-4B8C-AEAC-365A334DE418}\RP589\A0207113.dll -> Downloader.Agent.al : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{43C61967-F800-4B8C-AEAC-365A334DE418}\RP589\A0207114.dll -> Downloader.Agent.al : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{43C61967-F800-4B8C-AEAC-365A334DE418}\RP589\A0207115.dll -> Downloader.Agent.al : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{43C61967-F800-4B8C-AEAC-365A334DE418}\RP589\A0207116.exe -> Downloader.Agent.al : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{43C61967-F800-4B8C-AEAC-365A334DE418}\RP589\A0207117.dll -> Downloader.Agent.al : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{43C61967-F800-4B8C-AEAC-365A334DE418}\RP589\A0207118.dll -> Downloader.Agent.al : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{43C61967-F800-4B8C-AEAC-365A334DE418}\RP589\A0207119.dll -> Downloader.Agent.al : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{43C61967-F800-4B8C-AEAC-365A334DE418}\RP589\A0207120.dll -> Downloader.Agent.al : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{43C61967-F800-4B8C-AEAC-365A334DE418}\RP589\A0207121.dll -> Downloader.Agent.al : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{43C61967-F800-4B8C-AEAC-365A334DE418}\RP589\A0207122.dll -> Downloader.Agent.al : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{43C61967-F800-4B8C-AEAC-365A334DE418}\RP589\A0207123.dll -> Downloader.Agent.al : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{43C61967-F800-4B8C-AEAC-365A334DE418}\RP589\A0207124.dll -> Downloader.Agent.al : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{43C61967-F800-4B8C-AEAC-365A334DE418}\RP589\A0207125.dll -> Downloader.Agent.al : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{43C61967-F800-4B8C-AEAC-365A334DE418}\RP589\A0207126.exe -> Downloader.Agent.al : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{43C61967-F800-4B8C-AEAC-365A334DE418}\RP589\A0207127.dll -> Downloader.Agent.al : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{43C61967-F800-4B8C-AEAC-365A334DE418}\RP589\A0207128.dll -> Downloader.Agent.al : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{43C61967-F800-4B8C-AEAC-365A334DE418}\RP589\A0206541.EXE:ylahv -> Downloader.Agent.bc : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{43C61967-F800-4B8C-AEAC-365A334DE418}\RP589\A0206542.dll -> Downloader.Agent.bc : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{43C61967-F800-4B8C-AEAC-365A334DE418}\RP589\A0206543.dll -> Downloader.Agent.bc : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{43C61967-F800-4B8C-AEAC-365A334DE418}\RP589\A0206544.dll -> Downloader.Agent.bc : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{43C61967-F800-4B8C-AEAC-365A334DE418}\RP589\A0206545.dll -> Downloader.Agent.bc : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{43C61967-F800-4B8C-AEAC-365A334DE418}\RP589\A0206546.dll -> Downloader.Agent.bc : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{43C61967-F800-4B8C-AEAC-365A334DE418}\RP589\A0206547.dll -> Downloader.Agent.bc : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{43C61967-F800-4B8C-AEAC-365A334DE418}\RP589\A0206548.dll -> Downloader.Agent.bc : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{43C61967-F800-4B8C-AEAC-365A334DE418}\RP589\A0206549.dll -> Downloader.Agent.bc : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{43C61967-F800-4B8C-AEAC-365A334DE418}\RP589\A0206550.dll -> Downloader.Agent.bc : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{43C61967-F800-4B8C-AEAC-365A334DE418}\RP589\A0206551.dll -> Downloader.Agent.bc : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{43C61967-F800-4B8C-AEAC-365A334DE418}\RP589\A0206552.dll -> Downloader.Agent.bc : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{43C61967-F800-4B8C-AEAC-365A334DE418}\RP589\A0206553.dll -> Downloader.Agent.bc : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{43C61967-F800-4B8C-AEAC-365A334DE418}\RP589\A0206554.dll -> Downloader.Agent.bc : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{43C61967-F800-4B8C-AEAC-365A334DE418}\RP589\A0206555.dll -> Downloader.Agent.bc : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{43C61967-F800-4B8C-AEAC-365A334DE418}\RP589\A0206556.dll -> Downloader.Agent.bc : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{43C61967-F800-4B8C-AEAC-365A334DE418}\RP589\A0206557.dll -> Downloader.Agent.bc : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{43C61967-F800-4B8C-AEAC-365A334DE418}\RP589\A0206558.dll -> Downloader.Agent.bc : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{43C61967-F800-4B8C-AEAC-365A334DE418}\RP589\A0206559.dll -> Downloader.Agent.bc : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{43C61967-F800-4B8C-AEAC-365A334DE418}\RP589\A0206560.dll -> Downloader.Agent.bc : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{43C61967-F800-4B8C-AEAC-365A334DE418}\RP589\A0206561.dll -> Downloader.Agent.bc : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{43C61967-F800-4B8C-AEAC-365A334DE418}\RP589\A0206562.dll -> Downloader.Agent.bc : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{43C61967-F800-4B8C-AEAC-365A334DE418}\RP589\A0206563.dll -> Downloader.Agent.bc : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{43C61967-F800-4B8C-AEAC-365A334DE418}\RP589\A0206564.dll -> Downloader.Agent.bc : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{43C61967-F800-4B8C-AEAC-365A334DE418}\RP589\A0206565.dll -> Downloader.Agent.bc : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{43C61967-F800-4B8C-AEAC-365A334DE418}\RP589\A0206566.dll -> Downloader.Agent.bc : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{43C61967-F800-4B8C-AEAC-365A334DE418}\RP589\A0206567.dll -> Downloader.Agent.bc : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{43C61967-F800-4B8C-AEAC-365A334DE418}\RP589\A0206568.dll -> Downloader.Agent.bc : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{43C61967-F800-4B8C-AEAC-365A334DE418}\RP589\A0206569.dll:pnivg -> Downloader.Agent.bc : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{43C61967-F800-4B8C-AEAC-365A334DE418}\RP589\A0206570.dll -> Downloader.Agent.bc : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{43C61967-F800-4B8C-AEAC-365A334DE418}\RP589\A0206571.dll -> Downloader.Agent.bc : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{43C61967-F800-4B8C-AEAC-365A334DE418}\RP589\A0206572.dll -> Downloader.Agent.bc : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{43C61967-F800-4B8C-AEAC-365A334DE418}\RP589\A0206573.dll -> Downloader.Agent.bc : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{43C61967-F800-4B8C-AEAC-365A334DE418}\RP589\A0206574.dll -> Downloader.Agent.bc : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{43C61967-F800-4B8C-AEAC-365A334DE418}\RP589\A0206575.dll -> Downloader.Agent.bc : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{43C61967-F800-4B8C-AEAC-365A334DE418}\RP589\A0206576.dll -> Downloader.Agent.bc : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{43C61967-F800-4B8C-AEAC-365A334DE418}\RP589\A0206577.dll -> Downloader.Agent.bc : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{43C61967-F800-4B8C-AEAC-365A334DE418}\RP589\A0206578.dll -> Downloader.Agent.bc : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{43C61967-F800-4B8C-AEAC-365A334DE418}\RP589\A0206579.dll -> Downloader.Agent.bc : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{43C61967-F800-4B8C-AEAC-365A334DE418}\RP589\A0206580.dll -> Downloader.Agent.bc : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{43C61967-F800-4B8C-AEAC-365A334DE418}\RP589\A0206581.dll -> Downloader.Agent.bc : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{43C61967-F800-4B8C-AEAC-365A334DE418}\RP589\A0206582.dll -> Downloader.Agent.bc : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{43C61967-F800-4B8C-AEAC-365A334DE418}\RP589\A0206583.dll -> Downloader.Agent.bc : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{43C61967-F800-4B8C-AEAC-365A334DE418}\RP589\A0206584.dll -> Downloader.Agent.bc : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{43C61967-F800-4B8C-AEAC-365A334DE418}\RP589\A0206585.dll -> Downloader.Agent.bc : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{43C61967-F800-4B8C-AEAC-365A334DE418}\RP589\A0206586.dll -> Downloader.Agent.bc : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{43C61967-F800-4B8C-AEAC-365A334DE418}\RP589\A0206587.dll -> Downloader.Agent.bc : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{43C61967-F800-4B8C-AEAC-365A334DE418}\RP589\A0206588.dll -> Downloader.Agent.bc : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{43C61967-F800-4B8C-AEAC-365A334DE418}\RP589\A0206589.dll -> Downloader.Agent.bc : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{43C61967-F800-4B8C-AEAC-365A334DE418}\RP589\A0206590.dll -> Downloader.Agent.bc : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{43C61967-F800-4B8C-AEAC-365A334DE418}\RP589\A0206591.dll -> Downloader.Agent.bc : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{43C61967-F800-4B8C-AEAC-365A334DE418}\RP589\A0206592.dll -> Downloader.Agent.bc : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{43C61967-F800-4B8C-AEAC-365A334DE418}\RP589\A0206593.dll -> Downloader.Agent.bc : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{43C61967-F800-4B8C-AEAC-365A334DE418}\RP589\A0206594.dll -> Downloader.Agent.bc : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{43C61967-F800-4B8C-AEAC-365A334DE418}\RP589\A0206595.dll -> Downloader.Agent.bc : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{43C61967-F800-4B8C-AEAC-365A334DE418}\RP589\A0206596.dll -> Downloader.Agent.bc : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{43C61967-F800-4B8C-AEAC-365A334DE418}\RP589\A0206597.dll -> Downloader.Agent.bc : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{43C61967-F800-4B8C-AEAC-365A334DE418}\RP589\A0206598.dll -> Downloader.Agent.bc : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{43C61967-F800-4B8C-AEAC-365A334DE418}\RP589\A0206599.dll -> Downloader.Agent.bc : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{43C61967-F800-4B8C-AEAC-365A334DE418}\RP589\A0206600.dll -> Downloader.Agent.bc : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{43C61967-F800-4B8C-AEAC-365A334DE418}\RP589\A0206601.dll -> Downloader.Agent.bc : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{43C61967-F800-4B8C-AEAC-365A334DE418}\RP589\A0206602.dll -> Downloader.Agent.bc : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{43C61967-F800-4B8C-AEAC-365A334DE418}\RP589\A0206603.dll -> Downloader.Agent.bc : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{43C61967-F800-4B8C-AEAC-365A334DE418}\RP589\A0206604.dll -> Downloader.Agent.bc : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{43C61967-F800-4B8C-AEAC-365A334DE418}\RP589\A0206605.dll -> Downloader.Agent.bc : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{43C61967-F800-4B8C-AEAC-365A334DE418}\RP589\A0206606.dll -> Downloader.Agent.bc : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{43C61967-F800-4B8C-AEAC-365A334DE418}\RP589\A0206607.dll -> Downloader.Agent.bc : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{43C61967-F800-4B8C-AEAC-365A334DE418}\RP589\A0206608.dll -> Downloader.Agent.bc : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{43C61967-F800-4B8C-AEAC-365A334DE418}\RP589\A0206609.dll -> Downloader.Agent.bc : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{43C61967-F800-4B8C-AEAC-365A334DE418}\RP589\A0206610.dll -> Downloader.Agent.bc : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{43C61967-F800-4B8C-AEAC-365A334DE418}\RP589\A0206611.dll -> Downloader.Agent.bc : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{43C61967-F800-4B8C-AEAC-365A334DE418}\RP589\A0206612.dll -> Downloader.Agent.bc : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{43C61967-F800-4B8C-AEAC-365A334DE418}\RP589\A0206613.dll -> Downloader.Agent.bc : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{43C61967-F800-4B8C-AEAC-365A334DE418}\RP589\A0206614.dll -> Downloader.Agent.bc : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{43C61967-F800-4B8C-AEAC-365A334DE418}\RP589\A0206615.dll -> Downloader.Agent.bc : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{43C61967-F800-4B8C-AEAC-365A334DE418}\RP589\A0206616.dll -> Downloader.Agent.bc : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{43C61967-F800-4B8C-AEAC-365A334DE418}\RP589\A0206617.dll -> Downloader.Agent.bc : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{43C61967-F800-4B8C-AEAC-365A334DE418}\RP589\A0206618.dll:qsyho -> Downloader.Agent.bc : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{43C61967-F800-4B8C-AEAC-365A334DE418}\RP589\A0206536.exe -> Downloader.Agent.bq : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{43C61967-F800-4B8C-AEAC-365A334DE418}\RP589\A0206537.exe -> Downloader.Agent.bq : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{43C61967-F800-4B8C-AEAC-365A334DE418}\RP589\A0207048.exe -> Downloader.Agent.bq : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{43C61967-F800-4B8C-AEAC-365A334DE418}\RP589\A0207067.exe -> Downloader.Agent.bq : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{43C61967-F800-4B8C-AEAC-365A334DE418}\RP589\A0207162.exe -> Downloader.Agent.bq : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{43C61967-F800-4B8C-AEAC-365A334DE418}\RP589\A0207163.exe -> Downloader.Agent.bq : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{43C61967-F800-4B8C-AEAC-365A334DE418}\RP589\A0207164.exe -> Downloader.Agent.bq : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{43C61967-F800-4B8C-AEAC-365A334DE418}\RP589\A0207165.exe -> Downloader.Agent.bq : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{43C61967-F800-4B8C-AEAC-365A334DE418}\RP589\A0207166.exe -> Downloader.Agent.bq : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{43C61967-F800-4B8C-AEAC-365A334DE418}\RP589\A0207167.exe -> Downloader.Agent.bq : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{43C61967-F800-4B8C-AEAC-365A334DE418}\RP589\A0207168.exe -> Downloader.Agent.bq : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{43C61967-F800-4B8C-AEAC-365A334DE418}\RP589\A0207169.exe -> Downloader.Agent.bq : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{43C61967-F800-4B8C-AEAC-365A334DE418}\RP589\A0207170.exe -> Downloader.Agent.bq : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{43C61967-F800-4B8C-AEAC-365A334DE418}\RP589\A0207171.exe -> Downloader.Agent.bq : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{43C61967-F800-4B8C-AEAC-365A334DE418}\RP589\A0207172.exe -> Downloader.Agent.bq : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{43C61967-F800-4B8C-AEAC-365A334DE418}\RP589\A0207173.exe -> Downloader.Agent.bq : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{43C61967-F800-4B8C-AEAC-365A334DE418}\RP589\A0207174.exe -> Downloader.Agent.bq : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{43C61967-F800-4B8C-AEAC-365A334DE418}\RP589\A0207175.exe -> Downloader.Agent.bq : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{43C61967-F800-4B8C-AEAC-365A334DE418}\RP589\A0207176.exe -> Downloader.Agent.bq : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{43C61967-F800-4B8C-AEAC-365A334DE418}\RP589\A0207177.exe -> Downloader.Agent.bq : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{43C61967-F800-4B8C-AEAC-365A334DE418}\RP589\A0207178.exe -> Downloader.Agent.bq : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{43C61967-F800-4B8C-AEAC-365A334DE418}\RP589\A0207179.exe -> Downloader.Agent.bq : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{43C61967-F800-4B8C-AEAC-365A334DE418}\RP589\A0207180.exe -> Downloader.Agent.bq : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{43C61967-F800-4B8C-AEAC-365A334DE418}\RP589\A0207181.exe -> Downloader.Agent.bq : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{43C61967-F800-4B8C-AEAC-365A334DE418}\RP589\A0207182.exe -> Downloader.Agent.bq : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{43C61967-F800-4B8C-AEAC-365A334DE418}\RP589\A0207183.exe -> Downloader.Agent.bq : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{43C61967-F800-4B8C-AEAC-365A334DE418}\RP589\A0207184.exe -> Downloader.Agent.bq : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{43C61967-F800-4B8C-AEAC-365A334DE418}\RP589\A0206253.exe:pwjho -> Downloader.Agent.cd : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{43C61967-F800-4B8C-AEAC-365A334DE418}\RP589\A0206533.INI:pywmf -> Downloader.Agent.cd : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{43C61967-F800-4B8C-AEAC-365A334DE418}\RP589\A0206534.ini:dkeal -> Downloader.Agent.cd : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{43C61967-F800-4B8C-AEAC-365A334DE418}\RP589\A0206535.exe:ltepg -> Downloader.Agent.cd : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{43C61967-F800-4B8C-AEAC-365A334DE418}\RP589\A0206536.exe:drsnn -> Downloader.Agent.cd : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{43C61967-F800-4B8C-AEAC-365A334DE418}\RP589\A0206537.exe:eek:rmto -> Downloader.Agent.cd : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{43C61967-F800-4B8C-AEAC-365A334DE418}\RP589\A0206538.isu:dvqzb -> Downloader.Agent.cd : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{43C61967-F800-4B8C-AEAC-365A334DE418}\RP589\A0206538.isu:eek:nine -> Downloader.Agent.cd : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{43C61967-F800-4B8C-AEAC-365A334DE418}\RP589\A0206539.dll:gglps -> Downloader.Agent.cd : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{43C61967-F800-4B8C-AEAC-365A334DE418}\RP589\A0206540.exe:yxwvm -> Downloader.Agent.cd : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{43C61967-F800-4B8C-AEAC-365A334DE418}\RP589\A0206033.exe -> Downloader.Agent.ck : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{43C61967-F800-4B8C-AEAC-365A334DE418}\RP589\A0206034.exe -> Downloader.Agent.ck : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{43C61967-F800-4B8C-AEAC-365A334DE418}\RP589\A0206035.exe -> Downloader.Agent.ck : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{43C61967-F800-4B8C-AEAC-365A334DE418}\RP589\A0206036.exe -> Downloader.Agent.ck : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{43C61967-F800-4B8C-AEAC-365A334DE418}\RP589\A0206031.exe -> Downloader.Petrolin.b : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{43C61967-F800-4B8C-AEAC-365A334DE418}\RP589\A0206032.exe -> Downloader.Petrolin.b : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{43C61967-F800-4B8C-AEAC-365A334DE418}\RP589\A0206037.exe -> Downloader.Small.ug : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{43C61967-F800-4B8C-AEAC-365A334DE418}\RP589\A0206038.exe -> Downloader.Small.ug : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{43C61967-F800-4B8C-AEAC-365A334DE418}\RP589\A0206039.exe -> Downloader.Small.ug : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{43C61967-F800-4B8C-AEAC-365A334DE418}\RP589\A0206040.exe -> Downloader.Small.ug : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{43C61967-F800-4B8C-AEAC-365A334DE418}\RP589\A0207186.exe -> Downloader.Zlob.mj : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{43C61967-F800-4B8C-AEAC-365A334DE418}\RP589\A0207187.tlb -> Downloader.Zlob.mj : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{43C61967-F800-4B8C-AEAC-365A334DE418}\RP589\A0206041.exe -> Dropper.Small.hx : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{43C61967-F800-4B8C-AEAC-365A334DE418}\RP589\A0206619.dll -> Hijacker.Small : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{43C61967-F800-4B8C-AEAC-365A334DE418}\RP589\A0206620.dll -> Hijacker.Small : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{43C61967-F800-4B8C-AEAC-365A334DE418}\RP589\A0206621.dll -> Hijacker.Small : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{43C61967-F800-4B8C-AEAC-365A334DE418}\RP589\A0206622.dll -> Hijacker.Small : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{43C61967-F800-4B8C-AEAC-365A334DE418}\RP589\A0206623.dll -> Hijacker.Small : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{43C61967-F800-4B8C-AEAC-365A334DE418}\RP589\A0206624.dll -> Hijacker.Small : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{43C61967-F800-4B8C-AEAC-365A334DE418}\RP589\A0206625.dll -> Hijacker.Small : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{43C61967-F800-4B8C-AEAC-365A334DE418}\RP589\A0206626.dll -> Hijacker.Small : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{43C61967-F800-4B8C-AEAC-365A334DE418}\RP589\A0206627.dll -> Hijacker.Small : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{43C61967-F800-4B8C-AEAC-365A334DE418}\RP589\A0206628.dll -> Hijacker.Small : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{43C61967-F800-4B8C-AEAC-365A334DE418}\RP589\A0206629.dll -> Hijacker.Small : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{43C61967-F800-4B8C-AEAC-365A334DE418}\RP589\A0206630.dll -> Hijacker.Small : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{43C61967-F800-4B8C-AEAC-365A334DE418}\RP589\A0206631.dll -> Hijacker.Small : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{43C61967-F800-4B8C-AEAC-365A334DE418}\RP589\A0206632.dll -> Hijacker.Small : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{43C61967-F800-4B8C-AEAC-365A334DE418}\RP589\A0206633.dll -> Hijacker.Small : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{43C61967-F800-4B8C-AEAC-365A334DE418}\RP589\A0206634.dll -> Hijacker.Small : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{43C61967-F800-4B8C-AEAC-365A334DE418}\RP589\A0206635.dll -> Hijacker.Small : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{43C61967-F800-4B8C-AEAC-365A334DE418}\RP589\A0206636.dll -> Hijacker.Small : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{43C61967-F800-4B8C-AEAC-365A334DE418}\RP589\A0206637.dll -> Hijacker.Small : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{43C61967-F800-4B8C-AEAC-365A334DE418}\RP589\A0206638.dll -> Hijacker.Small : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{43C61967-F800-4B8C-AEAC-365A334DE418}\RP589\A0206639.dll -> Hijacker.Small : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{43C61967-F800-4B8C-AEAC-365A334DE418}\RP589\A0206640.dll -> Hijacker.Small : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{43C61967-F800-4B8C-AEAC-365A334DE418}\RP589\A0206641.dll -> Hijacker.Small : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{43C61967-F800-4B8C-AEAC-365A334DE418}\RP589\A0206642.dll -> Hijacker.Small : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{43C61967-F800-4B8C-AEAC-365A334DE418}\RP589\A0206643.dll -> Hijacker.Small : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{43C61967-F800-4B8C-AEAC-365A334DE418}\RP589\A0206644.dll -> Hijacker.Small : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{43C61967-F800-4B8C-AEAC-365A334DE418}\RP589\A0206645.dll -> Hijacker.Small : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{43C61967-F800-4B8C-AEAC-365A334DE418}\RP589\A0206646.dll -> Hijacker.Small : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{43C61967-F800-4B8C-AEAC-365A334DE418}\RP589\A0206647.dll -> Hijacker.Small : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{43C61967-F800-4B8C-AEAC-365A334DE418}\RP589\A0206648.dll -> Hijacker.Small : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{43C61967-F800-4B8C-AEAC-365A334DE418}\RP589\A0206649.dll -> Hijacker.Small : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{43C61967-F800-4B8C-AEAC-365A334DE418}\RP589\A0206650.dll -> Hijacker.Small : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{43C61967-F800-4B8C-AEAC-365A334DE418}\RP589\A0206651.dll -> Hijacker.Small : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{43C61967-F800-4B8C-AEAC-365A334DE418}\RP589\A0206652.dll -> Hijacker.Small : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{43C61967-F800-4B8C-AEAC-365A334DE418}\RP589\A0206653.dll -> Hijacker.Small : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{43C61967-F800-4B8C-AEAC-365A334DE418}\RP589\A0206654.dll -> Hijacker.Small : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{43C61967-F800-4B8C-AEAC-365A334DE418}\RP589\A0206655.dll -> Hijacker.Small : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{43C61967-F800-4B8C-AEAC-365A334DE418}\RP589\A0206656.dll -> Hijacker.Small : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{43C61967-F800-4B8C-AEAC-365A334DE418}\RP589\A0206657.dll -> Hijacker.Small : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{43C61967-F800-4B8C-AEAC-365A334DE418}\RP589\A0206658.dll -> Hijacker.Small : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{43C61967-F800-4B8C-AEAC-365A334DE418}\RP589\A0206659.dll -> Hijacker.Small : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{43C61967-F800-4B8C-AEAC-365A334DE418}\RP589\A0206660.dll -> Hijacker.Small : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{43C61967-F800-4B8C-AEAC-365A334DE418}\RP589\A0206661.dll -> Hijacker.Small : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{43C61967-F800-4B8C-AEAC-365A334DE418}\RP589\A0206662.dll -> Hijacker.Small : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{43C61967-F800-4B8C-AEAC-365A334DE418}\RP589\A0206663.dll -> Hijacker.Small : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{43C61967-F800-4B8C-AEAC-365A334DE418}\RP589\A0206664.dll -> Hijacker.Small : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{43C61967-F800-4B8C-AEAC-365A334DE418}\RP589\A0206665.dll -> Hijacker.Small : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{43C61967-F800-4B8C-AEAC-365A334DE418}\RP589\A0206666.dll -> Hijacker.Small : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{43C61967-F800-4B8C-AEAC-365A334DE418}\RP589\A0206667.dll -> Hijacker.Small : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{43C61967-F800-4B8C-AEAC-365A334DE418}\RP589\A0206668.dll -> Hijacker.Small : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{43C61967-F800-4B8C-AEAC-365A334DE418}\RP589\A0206669.dll -> Hijacker.Small : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{43C61967-F800-4B8C-AEAC-365A334DE418}\RP589\A0206670.dll -> Hijacker.Small : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{43C61967-F800-4B8C-AEAC-365A334DE418}\RP589\A0206671.dll -> Hijacker.Small : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{43C61967-F800-4B8C-AEAC-365A334DE418}\RP589\A0206672.dll -> Hijacker.Small : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{43C61967-F800-4B8C-AEAC-365A334DE418}\RP589\A0206673.dll -> Hijacker.Small : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{43C61967-F800-4B8C-AEAC-365A334DE418}\RP589\A0206674.dll -> Hijacker.Small : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{43C61967-F800-4B8C-AEAC-365A334DE418}\RP589\A0206675.dll -> Hijacker.Small : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{43C61967-F800-4B8C-AEAC-365A334DE418}\RP589\A0206676.dll -> Hijacker.Small : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{43C61967-F800-4B8C-AEAC-365A334DE418}\RP589\A0206677.dll -> Hijacker.Small : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{43C61967-F800-4B8C-AEAC-365A334DE418}\RP589\A0206678.dll -> Hijacker.Small : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{43C61967-F800-4B8C-AEAC-365A334DE418}\RP589\A0206679.dll -> Hijacker.Small : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{43C61967-F800-4B8C-AEAC-365A334DE418}\RP589\A0206680.dll -> Hijacker.Small : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{43C61967-F800-4B8C-AEAC-365A334DE418}\RP589\A0206681.dll -> Hijacker.Small : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{43C61967-F800-4B8C-AEAC-365A334DE418}\RP589\A0206682.dll -> Hijacker.Small : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{43C61967-F800-4B8C-AEAC-365A334DE418}\RP589\A0206683.dll -> Hijacker.Small : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{43C61967-F800-4B8C-AEAC-365A334DE418}\RP589\A0206684.dll -> Hijacker.Small : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{43C61967-F800-4B8C-AEAC-365A334DE418}\RP589\A0206685.dll -> Hijacker.Small : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{43C61967-F800-4B8C-AEAC-365A334DE418}\RP589\A0206686.dll -> Hijacker.Small : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{43C61967-F800-4B8C-AEAC-365A334DE418}\RP589\A0206687.dll -> Hijacker.Small : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{43C61967-F800-4B8C-AEAC-365A334DE418}\RP589\A0206688.dll -> Hijacker.Small : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{43C61967-F800-4B8C-AEAC-365A334DE418}\RP589\A0206689.dll -> Hijacker.Small : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{43C61967-F800-4B8C-AEAC-365A334DE418}\RP589\A0206690.dll -> Hijacker.Small : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{43C61967-F800-4B8C-AEAC-365A334DE418}\RP589\A0206691.dll -> Hijacker.Small : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{43C61967-F800-4B8C-AEAC-365A334DE418}\RP589\A0206692.dll -> Hijacker.Small : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{43C61967-F800-4B8C-AEAC-365A334DE418}\RP589\A0206693.dll -> Hijacker.Small : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{43C61967-F800-4B8C-AEAC-365A334DE418}\RP589\A0206694.dll -> Hijacker.Small : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{43C61967-F800-4B8C-AEAC-365A334DE418}\RP589\A0206695.dll -> Hijacker.Small : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{43C61967-F800-4B8C-AEAC-365A334DE418}\RP589\A0206696.dll -> Hijacker.Small : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{43C61967-F800-4B8C-AEAC-365A334DE418}\RP589\A0206697.dll -> Hijacker.Small : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{43C61967-F800-4B8C-AEAC-365A334DE418}\RP589\A0206698.dll -> Hijacker.Small : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{43C61967-F800-4B8C-AEAC-365A334DE418}\RP589\A0206699.dll -> Hijacker.Small : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{43C61967-F800-4B8C-AEAC-365A334DE418}\RP589\A0206700.dll -> Hijacker.Small : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{43C61967-F800-4B8C-AEAC-365A334DE418}\RP589\A0206701.dll -> Hijacker.Small : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{43C61967-F800-4B8C-AEAC-365A334DE418}\RP589\A0206702.dll -> Hijacker.Small : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{43C61967-F800-4B8C-AEAC-365A334DE418}\RP589\A0206703.dll -> Hijacker.Small : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{43C61967-F800-4B8C-AEAC-365A334DE418}\RP589\A0206704.dll -> Hijacker.Small : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{43C61967-F800-4B8C-AEAC-365A334DE418}\RP589\A0206705.dll -> Hijacker.Small : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{43C61967-F800-4B8C-AEAC-365A334DE418}\RP589\A0206706.dll -> Hijacker.Small : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{43C61967-F800-4B8C-AEAC-365A334DE418}\RP589\A0206707.dll -> Hijacker.Small : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{43C61967-F800-4B8C-AEAC-365A334DE418}\RP589\A0206708.dll -> Hijacker.Small : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{43C61967-F800-4B8C-AEAC-365A334DE418}\RP589\A0206709.dll -> Hijacker.Small : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{43C61967-F800-4B8C-AEAC-365A334DE418}\RP589\A0206710.dll -> Hijacker.Small : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{43C61967-F800-4B8C-AEAC-365A334DE418}\RP589\A0206711.dll -> Hijacker.Small : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{43C61967-F800-4B8C-AEAC-365A334DE418}\RP589\A0206712.dll -> Hijacker.Small : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{43C61967-F800-4B8C-AEAC-365A334DE418}\RP589\A0206713.dll -> Hijacker.Small : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{43C61967-F800-4B8C-AEAC-365A334DE418}\RP589\A0206714.dll -> Hijacker.Small : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{43C61967-F800-4B8C-AEAC-365A334DE418}\RP589\A0206715.dll -> Hijacker.Small : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{43C61967-F800-4B8C-AEAC-365A334DE418}\RP589\A0206716.dll -> Hijacker.Small : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{43C61967-F800-4B8C-AEAC-365A334DE418}\RP589\A0206717.dll -> Hijacker.Small : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{43C61967-F800-4B8C-AEAC-365A334DE418}\RP589\A0206718.dll -> Hijacker.Small : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{43C61967-F800-4B8C-AEAC-365A334DE418}\RP589\A0206719.dll -> Hijacker.Small : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{43C61967-F800-4B8C-AEAC-365A334DE418}\RP589\A0206720.dll -> Hijacker.Small : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{43C61967-F800-4B8C-AEAC-365A334DE418}\RP589\A0206721.dll -> Hijacker.Small : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{43C61967-F800-4B8C-AEAC-365A334DE418}\RP589\A0206722.dll -> Hijacker.Small : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{43C61967-F800-4B8C-AEAC-365A334DE418}\RP589\A0206723.dll -> Hijacker.Small : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{43C61967-F800-4B8C-AEAC-365A334DE418}\RP589\A0206724.dll -> Hijacker.Small : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{43C61967-F800-4B8C-AEAC-365A334DE418}\RP589\A0206725.dll -> Hijacker.Small : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{43C61967-F800-4B8C-AEAC-365A334DE418}\RP589\A0206726.dll -> Hijacker.Small : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{43C61967-F800-4B8C-AEAC-365A334DE418}\RP589\A0206727.dll -> Hijacker.Small : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{43C61967-F800-4B8C-AEAC-365A334DE418}\RP589\A0206728.dll -> Hijacker.Small : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{43C61967-F800-4B8C-AEAC-365A334DE418}\RP589\A0206729.dll -> Hijacker.Small : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{43C61967-F800-4B8C-AEAC-365A334DE418}\RP589\A0206730.dll -> Hijacker.Small : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{43C61967-F800-4B8C-AEAC-365A334DE418}\RP589\A0206731.dll -> Hijacker.Small : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{43C61967-F800-4B8C-AEAC-365A334DE418}\RP589\A0206732.dll -> Hijacker.Small : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{43C61967-F800-4B8C-AEAC-365A334DE418}\RP589\A0206733.dll -> Hijacker.Small : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{43C61967-F800-4B8C-AEAC-365A334DE418}\RP589\A0206734.dll -> Hijacker.Small : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{43C61967-F800-4B8C-AEAC-365A334DE418}\RP589\A0206735.dll -> Hijacker.Small : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{43C61967-F800-4B8C-AEAC-365A334DE418}\RP589\A0206736.dll -> Hijacker.Small : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{43C61967-F800-4B8C-AEAC-365A334DE418}\RP589\A0206737.dll -> Hijacker.Small : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{43C61967-F800-4B8C-AEAC-365A334DE418}\RP589\A0206738.dll -> Hijacker.Small : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{43C61967-F800-4B8C-AEAC-365A334DE418}\RP589\A0206739.dll -> Hijacker.Small : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{43C61967-F800-4B8C-AEAC-365A334DE418}\RP589\A0206740.dll -> Hijacker.Small : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{43C61967-F800-4B8C-AEAC-365A334DE418}\RP589\A0206741.dll -> Hijacker.Small : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{43C61967-F800-4B8C-AEAC-365A334DE418}\RP589\A0206742.dll -> Hijacker.Small : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{43C61967-F800-4B8C-AEAC-365A334DE418}\RP589\A0206743.dll -> Hijacker.Small : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{43C61967-F800-4B8C-AEAC-365A334DE418}\RP589\A0206744.dll -> Hijacker.Small : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{43C61967-F800-4B8C-AEAC-365A334DE418}\RP589\A0206745.dll -> Hijacker.Small : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{43C61967-F800-4B8C-AEAC-365A334DE418}\RP589\A0206746.dll -> Hijacker.Small : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{43C61967-F800-4B8C-AEAC-365A334DE418}\RP589\A0206747.dll -> Hijacker.Small : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{43C61967-F800-4B8C-AEAC-365A334DE418}\RP589\A0206748.dll -> Hijacker.Small : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{43C61967-F800-4B8C-AEAC-365A334DE418}\RP589\A0206749.dll -> Hijacker.Small : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{43C61967-F800-4B8C-AEAC-365A334DE418}\RP589\A0206750.dll -> Hijacker.Small : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{43C61967-F800-4B8C-AEAC-365A334DE418}\RP589\A0206751.dll -> Hijacker.Small : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{43C61967-F800-4B8C-AEAC-365A334DE418}\RP589\A0206752.dll -> Hijacker.Small : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{43C61967-F800-4B8C-AEAC-365A334DE418}\RP589\A0206753.dll -> Hijacker.Small : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{43C61967-F800-4B8C-AEAC-365A334DE418}\RP589\A0206754.dll -> Hijacker.Small : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{43C61967-F800-4B8C-AEAC-365A334DE418}\RP589\A0206755.dll -> Hijacker.Small : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{43C61967-F800-4B8C-AEAC-365A334DE418}\RP589\A0206756.dll -> Hijacker.Small : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{43C61967-F800-4B8C-AEAC-365A334DE418}\RP589\A0206757.dll -> Hijacker.Small : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{43C61967-F800-4B8C-AEAC-365A334DE418}\RP589\A0206758.dll -> Hijacker.Small : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{43C61967-F800-4B8C-AEAC-365A334DE418}\RP589\A0206759.dll -> Hijacker.Small : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{43C61967-F800-4B8C-AEAC-365A334DE418}\RP589\A0206760.dll -> Hijacker.Small : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{43C61967-F800-4B8C-AEAC-365A334DE418}\RP589\A0206761.dll -> Hijacker.Small : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{43C61967-F800-4B8C-AEAC-365A334DE418}\RP589\A0206762.dll -> Hijacker.Small : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{43C61967-F800-4B8C-AEAC-365A334DE418}\RP589\A0206763.dll -> Hijacker.Small : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{43C61967-F800-4B8C-AEAC-365A334DE418}\RP589\A0206764.dll -> Hijacker.Small : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{43C61967-F800-4B8C-AEAC-365A334DE418}\RP589\A0206765.dll -> Hijacker.Small : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{43C61967-F800-4B8C-AEAC-365A334DE418}\RP589\A0206766.dll -> Hijacker.Small : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{43C61967-F800-4B8C-AEAC-365A334DE418}\RP589\A0206767.dll -> Hijacker.Small : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{43C61967-F800-4B8C-AEAC-365A334DE418}\RP589\A0206768.dll -> Hijacker.Small : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{43C61967-F800-4B8C-AEAC-365A334DE418}\RP589\A0206769.dll -> Hijacker.Small : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{43C61967-F800-4B8C-AEAC-365A334DE418}\RP589\A0206770.dll -> Hijacker.Small : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{43C61967-F800-4B8C-AEAC-365A334DE418}\RP589\A0206771.dll -> Hijacker.Small : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{43C61967-F800-4B8C-AEAC-365A334DE418}\RP589\A0206772.dll -> Hijacker.Small : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{43C61967-F800-4B8C-AEAC-365A334DE418}\RP589\A0206773.dll -> Hijacker.Small : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{43C61967-F800-4B8C-AEAC-365A334DE418}\RP589\A0206774.dll -> Hijacker.Small : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{43C61967-F800-4B8C-AEAC-365A334DE418}\RP589\A0206775.dll -> Hijacker.Small : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{43C61967-F800-4B8C-AEAC-365A334DE418}\RP589\A0206776.dll -> Hijacker.Small : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{43C61967-F800-4B8C-AEAC-365A334DE418}\RP589\A0206777.dll -> Hijacker.Small : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{43C61967-F800-4B8C-AEAC-365A334DE418}\RP589\A0206778.dll -> Hijacker.Small : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{43C61967-F800-4B8C-AEAC-365A334DE418}\RP589\A0206779.dll -> Hijacker.Small : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{43C61967-F800-4B8C-AEAC-365A334DE418}\RP589\A0206780.dll -> Hijacker.Small : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{43C61967-F800-4B8C-AEAC-365A334DE418}\RP589\A0206781.dll -> Hijacker.Small : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{43C61967-F800-4B8C-AEAC-365A334DE418}\RP589\A0206782.dll -> Hijacker.Small : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{43C61967-F800-4B8C-AEAC-365A334DE418}\RP589\A0206783.dll -> Hijacker.Small : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{43C61967-F800-4B8C-AEAC-365A334DE418}\RP589\A0206784.dll -> Hijacker.Small : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{43C61967-F800-4B8C-AEAC-365A334DE418}\RP589\A0206785.dll -> Hijacker.Small : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{43C61967-F800-4B8C-AEAC-365A334DE418}\RP589\A0206786.dll -> Hijacker.Small : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{43C61967-F800-4B8C-AEAC-365A334DE418}\RP589\A0206787.dll -> Hijacker.Small : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{43C61967-F800-4B8C-AEAC-365A334DE418}\RP589\A0206788.dll -> Hijacker.Small : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{43C61967-F800-4B8C-AEAC-365A334DE418}\RP589\A0206789.dll -> Hijacker.Small : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{43C61967-F800-4B8C-AEAC-365A334DE418}\RP589\A0206790.dll -> Hijacker.Small : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{43C61967-F800-4B8C-AEAC-365A334DE418}\RP589\A0206791.dll -> Hijacker.Small : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{43C61967-F800-4B8C-AEAC-365A334DE418}\RP589\A0206792.dll -> Hijacker.Small : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{43C61967-F800-4B8C-AEAC-365A334DE418}\RP589\A0206793.dll -> Hijacker.Small : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{43C61967-F800-4B8C-AEAC-365A334DE418}\RP589\A0206794.dll -> Hijacker.Small : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{43C61967-F800-4B8C-AEAC-365A334DE418}\RP589\A0206795.dll -> Hijacker.Small : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{43C61967-F800-4B8C-AEAC-365A334DE418}\RP589\A0206796.dll -> Hijacker.Small : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{43C61967-F800-4B8C-AEAC-365A334DE418}\RP589\A0206797.dll -> Hijacker.Small : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{43C61967-F800-4B8C-AEAC-365A334DE418}\RP589\A0206798.dll -> Hijacker.Small : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{43C61967-F800-4B8C-AEAC-365A334DE418}\RP589\A0206799.dll -> Hijacker.Small : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{43C61967-F800-4B8C-AEAC-365A334DE418}\RP589\A0206800.dll -> Hijacker.Small : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{43C61967-F800-4B8C-AEAC-365A334DE418}\RP589\A0206801.dll -> Hijacker.Small : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{43C61967-F800-4B8C-AEAC-365A334DE418}\RP589\A0206802.dll -> Hijacker.Small : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{43C61967-F800-4B8C-AEAC-365A334DE418}\RP589\A0206803.dll -> Hijacker.Small : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{43C61967-F800-4B8C-AEAC-365A334DE418}\RP589\A0206804.dll -> Hijacker.Small : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{43C61967-F800-4B8C-AEAC-365A334DE418}\RP589\A0206805.dll -> Hijacker.Small : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{43C61967-F800-4B8C-AEAC-365A334DE418}\RP589\A0206806.dll -> Hijacker.Small : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{43C61967-F800-4B8C-AEAC-365A334DE418}\RP589\A0206807.dll -> Hijacker.Small : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{43C61967-F800-4B8C-AEAC-365A334DE418}\RP589\A0206808.dll -> Hijacker.Small : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{43C61967-F800-4B8C-AEAC-365A334DE418}\RP589\A0206809.dll -> Hijacker.Small : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{43C61967-F800-4B8C-AEAC-365A334DE418}\RP589\A0206810.dll -> Hijacker.Small : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{43C61967-F800-4B8C-AEAC-365A334DE418}\RP589\A0206811.dll -> Hijacker.Small : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{43C61967-F800-4B8C-AEAC-365A334DE418}\RP589\A0206812.dll -> Hijacker.Small : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{43C61967-F800-4B8C-AEAC-365A334DE418}\RP589\A0206813.dll -> Hijacker.Small : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{43C61967-F800-4B8C-AEAC-365A334DE418}\RP589\A0206814.dll -> Hijacker.Small : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{43C61967-F800-4B8C-AEAC-365A334DE418}\RP589\A0206815.dll -> Hijacker.Small : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{43C61967-F800-4B8C-AEAC-365A334DE418}\RP589\A0206816.dll -> Hijacker.Small : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{43C61967-F800-4B8C-AEAC-365A334DE418}\RP589\A0206817.dll -> Hijacker.Small : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{43C61967-F800-4B8C-AEAC-365A334DE418}\RP589\A0206818.dll -> Hijacker.Small : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{43C61967-F800-4B8C-AEAC-365A334DE418}\RP589\A0206819.dll -> Hijacker.Small : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{43C61967-F800-4B8C-AEAC-365A334DE418}\RP589\A0206820.dll -> Hijacker.Small : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{43C61967-F800-4B8C-AEAC-365A334DE418}\RP589\A0206821.dll -> Hijacker.Small : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{43C61967-F800-4B8C-AEAC-365A334DE418}\RP589\A0206822.dll -> Hijacker.Small : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{43C61967-F800-4B8C-AEAC-365A334DE418}\RP589\A0206823.dll -> Hijacker.Small : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{43C61967-F800-4B8C-AEAC-365A334DE418}\RP589\A0206824.dll -> Hijacker.Small : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{43C61967-F800-4B8C-AEAC-365A334DE418}\RP589\A0206825.dll -> Hijacker.Small : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{43C61967-F800-4B8C-AEAC-365A334DE418}\RP589\A0206826.dll -> Hijacker.Small : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{43C61967-F800-4B8C-AEAC-365A334DE418}\RP589\A0206827.dll -> Hijacker.Small : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{43C61967-F800-4B8C-AEAC-365A334DE418}\RP589\A0206828.dll -> Hijacker.Small : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{43C61967-F800-4B8C-AEAC-365A334DE418}\RP589\A0206829.dll -> Hijacker.Small : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{43C61967-F800-4B8C-AEAC-365A334DE418}\RP589\A0206830.dll -> Hijacker.Small : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{43C61967-F800-4B8C-AEAC-365A334DE418}\RP589\A0206831.dll -> Hijacker.Small : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{43C61967-F800-4B8C-AEAC-365A334DE418}\RP589\A0206832.dll -> Hijacker.Small : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{43C61967-F800-4B8C-AEAC-365A334DE418}\RP589\A0206833.dll -> Hijacker.Small : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{43C61967-F800-4B8C-AEAC-365A334DE418}\RP589\A0206834.dll -> Hijacker.Small : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{43C61967-F800-4B8C-AEAC-365A334DE418}\RP589\A0206835.dll -> Hijacker.Small : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{43C61967-F800-4B8C-AEAC-365A334DE418}\RP589\A0206836.dll -> Hijacker.Small : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{43C61967-F800-4B8C-AEAC-365A334DE418}\RP589\A0206837.dll -> Hijacker.Small : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{43C61967-F800-4B8C-AEAC-365A334DE418}\RP589\A0206838.dll -> Hijacker.Small : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{43C61967-F800-4B8C-AEAC-365A334DE418}\RP589\A0206839.dll -> Hijacker.Small : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{43C61967-F800-4B8C-AEAC-365A334DE418}\RP589\A0206840.dll -> Hijacker.Small : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{43C61967-F800-4B8C-AEAC-365A334DE418}\RP589\A0206841.dll -> Hijacker.Small : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{43C61967-F800-4B8C-AEAC-365A334DE418}\RP589\A0206842.dll -> Hijacker.Small : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{43C61967-F800-4B8C-AEAC-365A334DE418}\RP589\A0206843.dll -> Hijacker.Small : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{43C61967-F800-4B8C-AEAC-365A334DE418}\RP589\A0206844.dll -> Hijacker.Small : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{43C61967-F800-4B8C-AEAC-365A334DE418}\RP589\A0206845.dll -> Hijacker.Small : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{43C61967-F800-4B8C-AEAC-365A334DE418}\RP589\A0206846.dll -> Hijacker.Small : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{43C61967-F800-4B8C-AEAC-365A334DE418}\RP589\A0206847.dll -> Hijacker.Small : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{43C61967-F800-4B8C-AEAC-365A334DE418}\RP589\A0206848.dll -> Hijacker.Small : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{43C61967-F800-4B8C-AEAC-365A334DE418}\RP589\A0206849.dll -> Hijacker.Small : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{43C61967-F800-4B8C-AEAC-365A334DE418}\RP589\A0206850.dll -> Hijacker.Small : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{43C61967-F800-4B8C-AEAC-365A334DE418}\RP589\A0206851.dll -> Hijacker.Small : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{43C61967-F800-4B8C-AEAC-365A334DE418}\RP589\A0206852.dll -> Hijacker.Small : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{43C61967-F800-4B8C-AEAC-365A334DE418}\RP589\A0206853.dll -> Hijacker.Small : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{43C61967-F800-4B8C-AEAC-365A334DE418}\RP589\A0206854.dll -> Hijacker.Small : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{43C61967-F800-4B8C-AEAC-365A334DE418}\RP589\A0206855.dll -> Hijacker.Small : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{43C61967-F800-4B8C-AEAC-365A334DE418}\RP589\A0206856.dll -> Hijacker.Small : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{43C61967-F800-4B8C-AEAC-365A334DE418}\RP589\A0206857.dll -> Hijacker.Small : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{43C61967-F800-4B8C-AEAC-365A334DE418}\RP589\A0206858.dll -> Hijacker.Small : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{43C61967-F800-4B8C-AEAC-365A334DE418}\RP589\A0206859.dll -> Hijacker.Small : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{43C61967-F800-4B8C-AEAC-365A334DE418}\RP589\A0206860.dll -> Hijacker.Small : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{43C61967-F800-4B8C-AEAC-365A334DE418}\RP589\A0206861.dll -> Hijacker.Small : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{43C61967-F800-4B8C-AEAC-365A334DE418}\RP589\A0206862.dll -> Hijacker.Small : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{43C61967-F800-4B8C-AEAC-365A334DE418}\RP589\A0206863.dll -> Hijacker.Small : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{43C61967-F800-4B8C-AEAC-365A334DE418}\RP589\A0206864.dll -> Hijacker.Small : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{43C61967-F800-4B8C-AEAC-365A334DE418}\RP589\A0206865.dll -> Hijacker.Small : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{43C61967-F800-4B8C-AEAC-365A334DE418}\RP589\A0206866.dll -> Hijacker.Small : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{43C61967-F800-4B8C-AEAC-365A334DE418}\RP589\A0206867.dll -> Hijacker.Small : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{43C61967-F800-4B8C-AEAC-365A334DE418}\RP589\A0206868.dll -> Hijacker.Small : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{43C61967-F800-4B8C-AEAC-365A334DE418}\RP589\A0206869.dll -> Hijacker.Small : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{43C61967-F800-4B8C-AEAC-365A334DE418}\RP589\A0206870.dll -> Hijacker.Small : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{43C61967-F800-4B8C-AEAC-365A334DE418}\RP589\A0206871.dll -> Hijacker.Small : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{43C61967-F800-4B8C-AEAC-365A334DE418}\RP589\A0206872.dll -> Hijacker.Small : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{43C61967-F800-4B8C-AEAC-365A334DE418}\RP589\A0206873.dll -> Hijacker.Small : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{43C61967-F800-4B8C-AEAC-365A334DE418}\RP589\A0206874.dll -> Hijacker.Small : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{43C61967-F800-4B8C-AEAC-365A334DE418}\RP589\A0206875.dll -> Hijacker.Small : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{43C61967-F800-4B8C-AEAC-365A334DE418}\RP589\A0206876.dll -> Hijacker.Small : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{43C61967-F800-4B8C-AEAC-365A334DE418}\RP589\A0206877.dll -> Hijacker.Small : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{43C61967-F800-4B8C-AEAC-365A334DE418}\RP589\A0206878.dll -> Hijacker.Small : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{43C61967-F800-4B8C-AEAC-365A334DE418}\RP589\A0206879.dll -> Hijacker.Small : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{43C61967-F800-4B8C-AEAC-365A334DE418}\RP589\A0206880.dll -> Hijacker.Small : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{43C61967-F800-4B8C-AEAC-365A334DE418}\RP589\A0206881.dll -> Hijacker.Small : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{43C61967-F800-4B8C-AEAC-365A334DE418}\RP589\A0206882.dll -> Hijacker.Small : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{43C61967-F800-4B8C-AEAC-365A334DE418}\RP589\A0206883.dll -> Hijacker.Small : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{43C61967-F800-4B8C-AEAC-365A334DE418}\RP589\A0206884.dll -> Hijacker.Small : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{43C61967-F800-4B8C-AEAC-365A334DE418}\RP589\A0206885.dll -> Hijacker.Small : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{43C61967-F800-4B8C-AEAC-365A334DE418}\RP589\A0206886.dll -> Hijacker.Small : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{43C61967-F800-4B8C-AEAC-365A334DE418}\RP589\A0206887.dll -> Hijacker.Small : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{43C61967-F800-4B8C-AEAC-365A334DE418}\RP589\A0206888.dll -> Hijacker.Small : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{43C61967-F800-4B8C-AEAC-365A334DE418}\RP589\A0206889.dll -> Hijacker.Small : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{43C61967-F800-4B8C-AEAC-365A334DE418}\RP589\A0206890.dll -> Hijacker.Small : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{43C61967-F800-4B8C-AEAC-365A334DE418}\RP589\A0206891.dll -> Hijacker.Small : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{43C61967-F800-4B8C-AEAC-365A334DE418}\RP589\A0206892.dll -> Hijacker.Small : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{43C61967-F800-4B8C-AEAC-365A334DE418}\RP589\A0206893.dll -> Hijacker.Small : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{43C61967-F800-4B8C-AEAC-365A334DE418}\RP589\A0206894.dll -> Hijacker.Small : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{43C61967-F800-4B8C-AEAC-365A334DE418}\RP589\A0206895.dll -> Hijacker.Small : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{43C61967-F800-4B8C-AEAC-365A334DE418}\RP589\A0206896.dll -> Hijacker.Small : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{43C61967-F800-4B8C-AEAC-365A334DE418}\RP589\A0206897.dll -> Hijacker.Small : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{43C61967-F800-4B8C-AEAC-365A334DE418}\RP589\A0206898.dll -> Hijacker.Small : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{43C61967-F800-4B8C-AEAC-365A334DE418}\RP589\A0206899.dll -> Hijacker.Small : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{43C61967-F800-4B8C-AEAC-365A334DE418}\RP589\A0206900.dll -> Hijacker.Small : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{43C61967-F800-4B8C-AEAC-365A334DE418}\RP589\A0206901.dll -> Hijacker.Small : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{43C61967-F800-4B8C-AEAC-365A334DE418}\RP589\A0206902.dll -> Hijacker.Small : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{43C61967-F800-4B8C-AEAC-365A334DE418}\RP589\A0206903.dll -> Hijacker.Small : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{43C61967-F800-4B8C-AEAC-365A334DE418}\RP589\A0206904.dll -> Hijacker.Small : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{43C61967-F800-4B8C-AEAC-365A334DE418}\RP589\A0206905.dll -> Hijacker.Small : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{43C61967-F800-4B8C-AEAC-365A334DE418}\RP589\A0206906.dll -> Hijacker.Small : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{43C61967-F800-4B8C-AEAC-365A334DE418}\RP589\A0206907.dll -> Hijacker.Small : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{43C61967-F800-4B8C-AEAC-365A334DE418}\RP589\A0206908.dll -> Hijacker.Small : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{43C61967-F800-4B8C-AEAC-365A334DE418}\RP589\A0206909.dll -> Hijacker.Small : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{43C61967-F800-4B8C-AEAC-365A334DE418}\RP589\A0206910.dll -> Hijacker.Small : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{43C61967-F800-4B8C-AEAC-365A334DE418}\RP589\A0206911.dll -> Hijacker.Small : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{43C61967-F800-4B8C-AEAC-365A334DE418}\RP589\A0206912.dll -> Hijacker.Small : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{43C61967-F800-4B8C-AEAC-365A334DE418}\RP589\A0206913.dll -> Hijacker.Small : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{43C61967-F800-4B8C-AEAC-365A334DE418}\RP589\A0206914.dll -> Hijacker.Small : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{43C61967-F800-4B8C-AEAC-365A334DE418}\RP589\A0206915.dll -> Hijacker.Small : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{43C61967-F800-4B8C-AEAC-365A334DE418}\RP589\A0206916.dll -> Hijacker.Small : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{43C61967-F800-4B8C-AEAC-365A334DE418}\RP589\A0206917.dll -> Hijacker.Small : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{43C61967-F800-4B8C-AEAC-365A334DE418}\RP589\A0206918.dll -> Hijacker.Small : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{43C61967-F800-4B8C-AEAC-365A334DE418}\RP589\A0206919.dll -> Hijacker.Small : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{43C61967-F800-4B8C-AEAC-365A334DE418}\RP589\A0206920.dll -> Hijacker.Small : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{43C61967-F800-4B8C-AEAC-365A334DE418}\RP589\A0206921.dll -> Hijacker.Small : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{43C61967-F800-4B8C-AEAC-365A334DE418}\RP589\A0206922.dll -> Hijacker.Small : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{43C61967-F800-4B8C-AEAC-365A334DE418}\RP589\A0206923.dll -> Hijacker.Small : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{43C61967-F800-4B8C-AEAC-365A334DE418}\RP589\A0206924.dll -> Hijacker.Small : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{43C61967-F800-4B8C-AEAC-365A334DE418}\RP589\A0206925.dll -> Hijacker.Small : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{43C61967-F800-4B8C-AEAC-365A334DE418}\RP589\A0206926.dll -> Hijacker.Small : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{43C61967-F800-4B8C-AEAC-365A334DE418}\RP589\A0206927.dll -> Hijacker.Small : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{43C61967-F800-4B8C-AEAC-365A334DE418}\RP589\A0206928.dll -> Hijacker.Small : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{43C61967-F800-4B8C-AEAC-365A334DE418}\RP589\A0206929.dll -> Hijacker.Small : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{43C61967-F800-4B8C-AEAC-365A334DE418}\RP589\A0206930.dll -> Hijacker.Small : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{43C61967-F800-4B8C-AEAC-365A334DE418}\RP589\A0206931.dll -> Hijacker.Small : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{43C61967-F800-4B8C-AEAC-365A334DE418}\RP589\A0206932.dll -> Hijacker.Small : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{43C61967-F800-4B8C-AEAC-365A334DE418}\RP589\A0206933.dll -> Hijacker.Small : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{43C61967-F800-4B8C-AEAC-365A334DE418}\RP589\A0206934.dll -> Hijacker.Small : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{43C61967-F800-4B8C-AEAC-365A334DE418}\RP589\A0206935.dll -> Hijacker.Small : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{43C61967-F800-4B8C-AEAC-365A334DE418}\RP589\A0206936.dll -> Hijacker.Small : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{43C61967-F800-4B8C-AEAC-365A334DE418}\RP589\A0206937.dll -> Hijacker.Small : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{43C61967-F800-4B8C-AEAC-365A334DE418}\RP589\A0206938.dll -> Hijacker.Small : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{43C61967-F800-4B8C-AEAC-365A334DE418}\RP589\A0206939.dll -> Hijacker.Small : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{43C61967-F800-4B8C-AEAC-365A334DE418}\RP589\A0206940.dll -> Hijacker.Small : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{43C61967-F800-4B8C-AEAC-365A334DE418}\RP589\A0206941.dll -> Hijacker.Small : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{43C61967-F800-4B8C-AEAC-365A334DE418}\RP589\A0206942.dll -> Hijacker.Small : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{43C61967-F800-4B8C-AEAC-365A334DE418}\RP589\A0206943.dll -> Hijacker.Small : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{43C61967-F800-4B8C-AEAC-365A334DE418}\RP589\A0206944.dll -> Hijacker.Small : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{43C61967-F800-4B8C-AEAC-365A334DE418}\RP589\A0206945.dll -> Hijacker.Small : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{43C61967-F800-4B8C-AEAC-365A334DE418}\RP589\A0206946.dll -> Hijacker.Small : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{43C61967-F800-4B8C-AEAC-365A334DE418}\RP589\A0206947.dll -> Hijacker.Small : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{43C61967-F800-4B8C-AEAC-365A334DE418}\RP589\A0206948.dll -> Hijacker.Small : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{43C61967-F800-4B8C-AEAC-365A334DE418}\RP589\A0206949.dll -> Hijacker.Small : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{43C61967-F800-4B8C-AEAC-365A334DE418}\RP589\A0206950.dll -> Hijacker.Small : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{43C61967-F800-4B8C-AEAC-365A334DE418}\RP589\A0206951.dll -> Hijacker.Small : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{43C61967-F800-4B8C-AEAC-365A334DE418}\RP589\A0206952.dll -> Hijacker.Small : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{43C61967-F800-4B8C-AEAC-365A334DE418}\RP589\A0206953.dll -> Hijacker.Small : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{43C61967-F800-4B8C-AEAC-365A334DE418}\RP589\A0206954.dll -> Hijacker.Small : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{43C61967-F800-4B8C-AEAC-365A334DE418}\RP589\A0206955.dll -> Hijacker.Small : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{43C61967-F800-4B8C-AEAC-365A334DE418}\RP589\A0206956.dll -> Hijacker.Small : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{43C61967-F800-4B8C-AEAC-365A334DE418}\RP589\A0206957.dll -> Hijacker.Small : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{43C61967-F800-4B8C-AEAC-365A334DE418}\RP589\A0206958.dll -> Hijacker.Small : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{43C61967-F800-4B8C-AEAC-365A334DE418}\RP589\A0206959.dll -> Hijacker.Small : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{43C61967-F800-4B8C-AEAC-365A334DE418}\RP589\A0206960.dll -> Hijacker.Small : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{43C61967-F800-4B8C-AEAC-365A334DE418}\RP589\A0206961.dll -> Hijacker.Small : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{43C61967-F800-4B8C-AEAC-365A334DE418}\RP589\A0206962.dll -> Hijacker.Small : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{43C61967-F800-4B8C-AEAC-365A334DE418}\RP589\A0206963.dll -> Hijacker.Small : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{43C61967-F800-4B8C-AEAC-365A334DE418}\RP589\A0206964.dll -> Hijacker.Small : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{43C61967-F800-4B8C-AEAC-365A334DE418}\RP589\A0206965.dll -> Hijacker.Small : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{43C61967-F800-4B8C-AEAC-365A334DE418}\RP589\A0206966.dll -> Hijacker.Small : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{43C61967-F800-4B8C-AEAC-365A334DE418}\RP589\A0206967.dll -> Hijacker.Small : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{43C61967-F800-4B8C-AEAC-365A334DE418}\RP589\A0206968.dll -> Hijacker.Small : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{43C61967-F800-4B8C-AEAC-365A334DE418}\RP589\A0206969.dll -> Hijacker.Small : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{43C61967-F800-4B8C-AEAC-365A334DE418}\RP589\A0206970.dll -> Hijacker.Small : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{43C61967-F800-4B8C-AEAC-365A334DE418}\RP589\A0206971.dll -> Hijacker.Small : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{43C61967-F800-4B8C-AEAC-365A334DE418}\RP589\A0206972.dll -> Hijacker.Small : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{43C61967-F800-4B8C-AEAC-365A334DE418}\RP589\A0206973.dll -> Hijacker.Small : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{43C61967-F800-4B8C-AEAC-365A334DE418}\RP589\A0206974.dll -> Hijacker.Small : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{43C61967-F800-4B8C-AEAC-365A334DE418}\RP589\A0206975.dll -> Hijacker.Small : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{43C61967-F800-4B8C-AEAC-365A334DE418}\RP589\A0206976.dll -> Hijacker.Small : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{43C61967-F800-4B8C-AEAC-365A334DE418}\RP589\A0206977.dll -> Hijacker.Small : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{43C61967-F800-4B8C-AEAC-365A334DE418}\RP589\A0206978.dll -> Hijacker.Small : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{43C61967-F800-4B8C-AEAC-365A334DE418}\RP589\A0206979.dll -> Hijacker.Small : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{43C61967-F800-4B8C-AEAC-365A334DE418}\RP589\A0206980.dll -> Hijacker.Small : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{43C61967-F800-4B8C-AEAC-365A334DE418}\RP589\A0206981.dll -> Hijacker.Small : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{43C61967-F800-4B8C-AEAC-365A334DE418}\RP589\A0206982.dll -> Hijacker.Small : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{43C61967-F800-4B8C-AEAC-365A334DE418}\RP589\A0206983.dll -> Hijacker.Small : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{43C61967-F800-4B8C-AEAC-365A334DE418}\RP589\A0206984.dll -> Hijacker.Small : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{43C61967-F800-4B8C-AEAC-365A334DE418}\RP589\A0206985.dll -> Hijacker.Small : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{43C61967-F800-4B8C-AEAC-365A334DE418}\RP589\A0206986.dll -> Hijacker.Small : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{43C61967-F800-4B8C-AEAC-365A334DE418}\RP589\A0206987.dll -> Hijacker.Small : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{43C61967-F800-4B8C-AEAC-365A334DE418}\RP589\A0206988.dll -> Hijacker.Small : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{43C61967-F800-4B8C-AEAC-365A334DE418}\RP589\A0206989.dll -> Hijacker.Small : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{43C61967-F800-4B8C-AEAC-365A334DE418}\RP589\A0206990.dll -> Hijacker.Small : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{43C61967-F800-4B8C-AEAC-365A334DE418}\RP589\A0206991.dll -> Hijacker.Small : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{43C61967-F800-4B8C-AEAC-365A334DE418}\RP589\A0206992.dll -> Hijacker.Small : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{43C61967-F800-4B8C-AEAC-365A334DE418}\RP589\A0206993.dll -> Hijacker.Small : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{43C61967-F800-4B8C-AEAC-365A334DE418}\RP589\A0206994.dll -> Hijacker.Small : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{43C61967-F800-4B8C-AEAC-365A334DE418}\RP589\A0206995.dll -> Hijacker.Small : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{43C61967-F800-4B8C-AEAC-365A334DE418}\RP589\A0206996.dll -> Hijacker.Small : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{43C61967-F800-4B8C-AEAC-365A334DE418}\RP589\A0206997.dll -> Hijacker.Small : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{43C61967-F800-4B8C-AEAC-365A334DE418}\RP589\A0206998.dll -> Hijacker.Small : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{43C61967-F800-4B8C-AEAC-365A334DE418}\RP589\A0206999.dll -> Hijacker.Small : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{43C61967-F800-4B8C-AEAC-365A334DE418}\RP589\A0207000.dll -> Hijacker.Small : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{43C61967-F800-4B8C-AEAC-365A334DE418}\RP589\A0207001.dll -> Hijacker.Small : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{43C61967-F800-4B8C-AEAC-365A334DE418}\RP589\A0207002.dll -> Hijacker.Small : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{43C61967-F800-4B8C-AEAC-365A334DE418}\RP589\A0207003.dll -> Hijacker.Small : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{43C61967-F800-4B8C-AEAC-365A334DE418}\RP589\A0207004.dll -> Hijacker.Small : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{43C61967-F800-4B8C-AEAC-365A334DE418}\RP589\A0207005.dll -> Hijacker.Small : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{43C61967-F800-4B8C-AEAC-365A334DE418}\RP589\A0207006.dll -> Hijacker.Small : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{43C61967-F800-4B8C-AEAC-365A334DE418}\RP589\A0207007.dll -> Hijacker.Small : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{43C61967-F800-4B8C-AEAC-365A334DE418}\RP589\A0207008.dll -> Hijacker.Small : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{43C61967-F800-4B8C-AEAC-365A334DE418}\RP589\A0207009.dll -> Hijacker.Small : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{43C61967-F800-4B8C-AEAC-365A334DE418}\RP589\A0207010.dll -> Hijacker.Small : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{43C61967-F800-4B8C-AEAC-365A334DE418}\RP589\A0207011.dll -> Hijacker.Small : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{43C61967-F800-4B8C-AEAC-365A334DE418}\RP589\A0207012.dll -> Hijacker.Small : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{43C61967-F800-4B8C-AEAC-365A334DE418}\RP589\A0207013.dll -> Hijacker.Small : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{43C61967-F800-4B8C-AEAC-365A334DE418}\RP589\A0207014.dll -> Hijacker.Small : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{43C61967-F800-4B8C-AEAC-365A334DE418}\RP589\A0207015.dll -> Hijacker.Small : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{43C61967-F800-4B8C-AEAC-365A334DE418}\RP589\A0206042.exe -> Trojan.Agent.bi : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{43C61967-F800-4B8C-AEAC-365A334DE418}\RP589\A0206043.exe -> Trojan.Agent.bi : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{43C61967-F800-4B8C-AEAC-365A334DE418}\RP589\A0206044.exe -> Trojan.Agent.bi : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{43C61967-F800-4B8C-AEAC-365A334DE418}\RP589\A0206045.exe -> Trojan.Agent.bi : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{43C61967-F800-4B8C-AEAC-365A334DE418}\RP589\A0206046.exe -> Trojan.Agent.bi : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{43C61967-F800-4B8C-AEAC-365A334DE418}\RP589\A0206047.exe -> Trojan.Agent.bi : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{43C61967-F800-4B8C-AEAC-365A334DE418}\RP589\A0206048.exe -> Trojan.Agent.bi : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{43C61967-F800-4B8C-AEAC-365A334DE418}\RP589\A0206049.exe -> Trojan.Agent.bi : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{43C61967-F800-4B8C-AEAC-365A334DE418}\RP589\A0206050.exe -> Trojan.Agent.bi : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{43C61967-F800-4B8C-AEAC-365A334DE418}\RP589\A0206051.exe -> Trojan.Agent.bi : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{43C61967-F800-4B8C-AEAC-365A334DE418}\RP589\A0206052.exe -> Trojan.Agent.bi : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{43C61967-F800-4B8C-AEAC-365A334DE418}\RP589\A0206053.exe -> Trojan.Agent.bi : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{43C61967-F800-4B8C-AEAC-365A334DE418}\RP589\A0206054.exe -> Trojan.Agent.bi : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{43C61967-F800-4B8C-AEAC-365A334DE418}\RP589\A0206055.exe -> Trojan.Agent.bi : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{43C61967-F800-4B8C-AEAC-365A334DE418}\RP589\A0206056.exe -> Trojan.Agent.bi : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{43C61967-F800-4B8C-AEAC-365A334DE418}\RP589\A0206057.exe -> Trojan.Agent.bi : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{43C61967-F800-4B8C-AEAC-365A334DE418}\RP589\A0206058.exe -> Trojan.Agent.bi : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{43C61967-F800-4B8C-AEAC-365A334DE418}\RP589\A0206059.exe -> Trojan.Agent.bi : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{43C61967-F800-4B8C-AEAC-365A334DE418}\RP589\A0206060.exe -> Trojan.Agent.bi : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{43C61967-F800-4B8C-AEAC-365A334DE418}\RP589\A0206061.exe -> Trojan.Agent.bi : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{43C61967-F800-4B8C-AEAC-365A334DE418}\RP589\A0206062.exe -> Trojan.Agent.bi : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{43C61967-F800-4B8C-AEAC-365A334DE418}\RP589\A0206063.exe -> Trojan.Agent.bi : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{43C61967-F800-4B8C-AEAC-365A334DE418}\RP589\A0206064.exe -> Trojan.Agent.bi : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{43C61967-F800-4B8C-AEAC-365A334DE418}\RP589\A0206065.exe -> Trojan.Agent.bi : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{43C61967-F800-4B8C-AEAC-365A334DE418}\RP589\A0206066.exe -> Trojan.Agent.bi : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{43C61967-F800-4B8C-AEAC-365A334DE418}\RP589\A0206067.exe -> Trojan.Agent.bi : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{43C61967-F800-4B8C-AEAC-365A334DE418}\RP589\A0206068.exe -> Trojan.Agent.bi : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{43C61967-F800-4B8C-AEAC-365A334DE418}\RP589\A0206069.exe -> Trojan.Agent.bi : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{43C61967-F800-4B8C-AEAC-365A334DE418}\RP589\A0206070.exe -> Trojan.Agent.bi : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{43C61967-F800-4B8C-AEAC-365A334DE418}\RP589\A0206071.exe -> Trojan.Agent.bi : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{43C61967-F800-4B8C-AEAC-365A334DE418}\RP589\A0206072.exe -> Trojan.Agent.bi : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{43C61967-F800-4B8C-AEAC-365A334DE418}\RP589\A0206073.exe -> Trojan.Agent.bi : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{43C61967-F800-4B8C-AEAC-365A334DE418}\RP589\A0206074.exe -> Trojan.Agent.bi : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{43C61967-F800-4B8C-AEAC-365A334DE418}\RP589\A0206075.exe -> Trojan.Agent.bi : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{43C61967-F800-4B8C-AEAC-365A334DE418}\RP589\A0206076.exe -> Trojan.Agent.bi : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{43C61967-F800-4B8C-AEAC-365A334DE418}\RP589\A0206077.exe -> Trojan.Agent.bi : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{43C61967-F800-4B8C-AEAC-365A334DE418}\RP589\A0206078.exe -> Trojan.Agent.bi : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{43C61967-F800-4B8C-AEAC-365A334DE418}\RP589\A0206079.dll -> Trojan.Agent.bi : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{43C61967-F800-4B8C-AEAC-365A334DE418}\RP589\A0206080.exe -> Trojan.Agent.bi : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{43C61967-F800-4B8C-AEAC-365A334DE418}\RP589\A0206081.exe -> Trojan.Agent.bi : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{43C61967-F800-4B8C-AEAC-365A334DE418}\RP589\A0206082.exe -> Trojan.Agent.bi : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{43C61967-F800-4B8C-AEAC-365A334DE418}\RP589\A0206083.exe -> Trojan.Agent.bi : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{43C61967-F800-4B8C-AEAC-365A334DE418}\RP589\A0206084.exe -> Trojan.Agent.bi : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{43C61967-F800-4B8C-AEAC-365A334DE418}\RP589\A0206085.exe -> Trojan.Agent.bi : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{43C61967-F800-4B8C-AEAC-365A334DE418}\RP589\A0206086.exe -> Trojan.Agent.bi : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{43C61967-F800-4B8C-AEAC-365A334DE418}\RP589\A0206087.exe -> Trojan.Agent.bi : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{43C61967-F800-4B8C-AEAC-365A334DE418}\RP589\A0206088.exe -> Trojan.Agent.bi : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{43C61967-F800-4B8C-AEAC-365A334DE418}\RP589\A0206089.exe -> Trojan.Agent.bi : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{43C61967-F800-4B8C-AEAC-365A334DE418}\RP589\A0206090.exe -> Trojan.Agent.bi : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{43C61967-F800-4B8C-AEAC-365A334DE418}\RP589\A0206091.exe -> Trojan.Agent.bi : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{43C61967-F800-4B8C-AEAC-365A334DE418}\RP589\A0206092.exe -> Trojan.Agent.bi : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{43C61967-F800-4B8C-AEAC-365A334DE418}\RP589\A0206093.exe -> Trojan.Agent.bi : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{43C61967-F800-4B8C-AEAC-365A334DE418}\RP589\A0206094.exe -> Trojan.Agent.bi : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{43C61967-F800-4B8C-AEAC-365A334DE418}\RP589\A0206095.exe -> Trojan.Agent.bi : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{43C61967-F800-4B8C-AEAC-365A334DE418}\RP589\A0206096.exe -> Trojan.Agent.bi : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{43C61967-F800-4B8C-AEAC-365A334DE418}\RP589\A0206097.exe -> Trojan.Agent.bi : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{43C61967-F800-4B8C-AEAC-365A334DE418}\RP589\A0206098.exe -> Trojan.Agent.bi : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{43C61967-F800-4B8C-AEAC-365A334DE418}\RP589\A0206099.exe -> Trojan.Agent.bi : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{43C61967-F800-4B8C-AEAC-365A334DE418}\RP589\A0206100.exe -> Trojan.Agent.bi : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{43C61967-F800-4B8C-AEAC-365A334DE418}\RP589\A0206101.exe -> Trojan.Agent.bi : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{43C61967-F800-4B8C-AEAC-365A334DE418}\RP589\A0206102.exe -> Trojan.Agent.bi : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{43C61967-F800-4B8C-AEAC-365A334DE418}\RP589\A0206103.exe -> Trojan.Agent.bi : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{43C61967-F800-4B8C-AEAC-365A334DE418}\RP589\A0206104.exe -> Trojan.Agent.bi : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{43C61967-F800-4B8C-AEAC-365A334DE418}\RP589\A0206105.exe -> Trojan.Agent.bi : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{43C61967-F800-4B8C-AEAC-365A334DE418}\RP589\A0206106.exe -> Trojan.Agent.bi : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{43C61967-F800-4B8C-AEAC-365A334DE418}\RP589\A0206107.exe -> Trojan.Agent.bi : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{43C61967-F800-4B8C-AEAC-365A334DE418}\RP589\A0206108.exe -> Trojan.Agent.bi : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{43C61967-F800-4B8C-AEAC-365A334DE418}\RP589\A0206109.exe -> Trojan.Agent.bi : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{43C61967-F800-4B8C-AEAC-365A334DE418}\RP589\A0206110.exe -> Trojan.Agent.bi : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{43C61967-F800-4B8C-AEAC-365A334DE418}\RP589\A0206111.exe -> Trojan.Agent.bi : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{43C61967-F800-4B8C-AEAC-365A334DE418}\RP589\A0206112.exe -> Trojan.Agent.bi : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{43C61967-F800-4B8C-AEAC-365A334DE418}\RP589\A0206113.exe -> Trojan.Agent.bi : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{43C61967-F800-4B8C-AEAC-365A334DE418}\RP589\A0206114.exe -> Trojan.Agent.bi : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{43C61967-F800-4B8C-AEAC-365A334DE418}\RP589\A0206115.exe -> Trojan.Agent.bi : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{43C61967-F800-4B8C-AEAC-365A334DE418}\RP589\A0206116.dll -> Trojan.Agent.bi : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{43C61967-F800-4B8C-AEAC-365A334DE418}\RP589\A0206117.exe -> Trojan.Agent.bi : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{43C61967-F800-4B8C-AEAC-365A334DE418}\RP589\A0206118.exe -> Trojan.Agent.bi : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{43C61967-F800-4B8C-AEAC-365A334DE418}\RP589\A0206119.dll -> Trojan.Agent.bi : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{43C61967-F800-4B8C-AEAC-365A334DE418}\RP589\A0206120.exe -> Trojan.Agent.bi : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{43C61967-F800-4B8C-AEAC-365A334DE418}\RP589\A0206121.exe -> Trojan.Agent.bi : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{43C61967-F800-4B8C-AEAC-365A334DE418}\RP589\A0206122.exe -> Trojan.Agent.bi : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{43C61967-F800-4B8C-AEAC-365A334DE418}\RP589\A0206123.exe -> Trojan.Agent.bi : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{43C61967-F800-4B8C-AEAC-365A334DE418}\RP589\A0206124.exe -> Trojan.Agent.bi : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{43C61967-F800-4B8C-AEAC-365A334DE418}\RP589\A0206125.exe -> Trojan.Agent.bi : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{43C61967-F800-4B8C-AEAC-365A334DE418}\RP589\A0206126.exe -> Trojan.Agent.bi : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{43C61967-F800-4B8C-AEAC-365A334DE418}\RP589\A0206127.exe -> Trojan.Agent.bi : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{43C61967-F800-4B8C-AEAC-365A334DE418}\RP589\A0206128.exe -> Trojan.Agent.bi : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{43C61967-F800-4B8C-AEAC-365A334DE418}\RP589\A0206129.exe -> Trojan.Agent.bi : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{43C61967-F800-4B8C-AEAC-365A334DE418}\RP589\A0206130.exe -> Trojan.Agent.bi : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{43C61967-F800-4B8C-AEAC-365A334DE418}\RP589\A0206131.exe -> Trojan.Agent.bi : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{43C61967-F800-4B8C-AEAC-365A334DE418}\RP589\A0206132.exe -> Trojan.Agent.bi : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{43C61967-F800-4B8C-AEAC-365A334DE418}\RP589\A0206133.exe -> Trojan.Agent.bi : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{43C61967-F800-4B8C-AEAC-365A334DE418}\RP589\A0206134.exe -> Trojan.Agent.bi : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{43C61967-F800-4B8C-AEAC-365A334DE418}\RP589\A0206135.exe -> Trojan.Agent.bi : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{43C61967-F800-4B8C-AEAC-365A334DE418}\RP589\A0206136.exe -> Trojan.Agent.bi : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{43C61967-F800-4B8C-AEAC-365A334DE418}\RP589\A0206137.exe -> Trojan.Agent.bi : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{43C61967-F800-4B8C-AEAC-365A334DE418}\RP589\A0206138.exe -> Trojan.Agent.bi : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{43C61967-F800-4B8C-AEAC-365A334DE418}\RP589\A0206139.exe -> Trojan.Agent.bi : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{43C61967-F800-4B8C-AEAC-365A334DE418}\RP589\A0206140.exe -> Trojan.Agent.bi : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{43C61967-F800-4B8C-AEAC-365A334DE418}\RP589\A0206141.exe -> Trojan.Agent.bi : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{43C61967-F800-4B8C-AEAC-365A334DE418}\RP589\A0206142.exe -> Trojan.Agent.bi : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{43C61967-F800-4B8C-AEAC-365A334DE418}\RP589\A0206143.exe -> Trojan.Agent.bi : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{43C61967-F800-4B8C-AEAC-365A334DE418}\RP589\A0206144.exe -> Trojan.Agent.bi : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{43C61967-F800-4B8C-AEAC-365A334DE418}\RP589\A0206145.exe -> Trojan.Agent.bi : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{43C61967-F800-4B8C-AEAC-365A334DE418}\RP589\A0206146.exe -> Trojan.Agent.bi : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{43C61967-F800-4B8C-AEAC-365A334DE418}\RP589\A0206147.exe -> Trojan.Agent.bi : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{43C61967-F800-4B8C-AEAC-365A334DE418}\RP589\A0206148.exe -> Trojan.Agent.bi : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{43C61967-F800-4B8C-AEAC-365A334DE418}\RP589\A0206149.exe -> Trojan.Agent.bi : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{43C61967-F800-4B8C-AEAC-365A334DE418}\RP589\A0206150.exe -> Trojan.Agent.bi : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{43C61967-F800-4B8C-AEAC-365A334DE418}\RP589\A0206151.exe -> Trojan.Agent.bi : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{43C61967-F800-4B8C-AEAC-365A334DE418}\RP589\A0206152.exe -> Trojan.Agent.bi : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{43C61967-F800-4B8C-AEAC-365A334DE418}\RP589\A0206153.exe -> Trojan.Agent.bi : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{43C61967-F800-4B8C-AEAC-365A334DE418}\RP589\A0206154.exe -> Trojan.Agent.bi : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{43C61967-F800-4B8C-AEAC-365A334DE418}\RP589\A0206155.exe -> Trojan.Agent.bi : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{43C61967-F800-4B8C-AEAC-365A334DE418}\RP589\A0206156.exe -> Trojan.Agent.bi : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{43C61967-F800-4B8C-AEAC-365A334DE418}\RP589\A0206157.exe -> Trojan.Agent.bi : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{43C61967-F800-4B8C-AEAC-365A334DE418}\RP589\A0206158.exe -> Trojan.Agent.bi : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{43C61967-F800-4B8C-AEAC-365A334DE418}\RP589\A0206159.exe -> Trojan.Agent.bi : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{43C61967-F800-4B8C-AEAC-365A334DE418}\RP589\A0206160.exe -> Trojan.Agent.bi : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{43C61967-F800-4B8C-AEAC-365A334DE418}\RP589\A0206161.exe -> Trojan.Agent.bi : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{43C61967-F800-4B8C-AEAC-365A334DE418}\RP589\A0206162.exe -> Trojan.Agent.bi : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{43C61967-F800-4B8C-AEAC-365A334DE418}\RP589\A0206163.exe -> Trojan.Agent.bi : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{43C61967-F800-4B8C-AEAC-365A334DE418}\RP589\A0206164.exe -> Trojan.Agent.bi : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{43C61967-F800-4B8C-AEAC-365A334DE418}\RP589\A0206165.exe -> Trojan.Agent.bi : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{43C61967-F800-4B8C-AEAC-365A334DE418}\RP589\A0206166.exe -> Trojan.Agent.bi : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{43C61967-F800-4B8C-AEAC-365A334DE418}\RP589\A0206167.exe -> Trojan.Agent.bi : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{43C61967-F800-4B8C-AEAC-365A334DE418}\RP589\A0206168.exe -> Trojan.Agent.bi : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{43C61967-F800-4B8C-AEAC-365A334DE418}\RP589\A0206169.exe -> Trojan.Agent.bi : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{43C61967-F800-4B8C-AEAC-365A334DE418}\RP589\A0206170.exe -> Trojan.Agent.bi : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{43C61967-F800-4B8C-AEAC-365A334DE418}\RP589\A0206171.exe -> Trojan.Agent.bi : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{43C61967-F800-4B8C-AEAC-365A334DE418}\RP589\A0206172.exe -> Trojan.Agent.bi : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{43C61967-F800-4B8C-AEAC-365A334DE418}\RP589\A0206173.exe -> Trojan.Agent.bi : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{43C61967-F800-4B8C-AEAC-365A334DE418}\RP589\A0206174.exe -> Trojan.Agent.bi : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{43C61967-F800-4B8C-AEAC-365A334DE418}\RP589\A0206175.exe -> Trojan.Agent.bi : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{43C61967-F800-4B8C-AEAC-365A334DE418}\RP589\A0206176.exe -> Trojan.Agent.bi : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{43C61967-F800-4B8C-AEAC-365A334DE418}\RP589\A0206177.exe -> Trojan.Agent.bi : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{43C61967-F800-4B8C-AEAC-365A334DE418}\RP589\A0206178.exe -> Trojan.Agent.bi : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{43C61967-F800-4B8C-AEAC-365A334DE418}\RP589\A0206179.exe -> Trojan.Agent.bi : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{43C61967-F800-4B8C-AEAC-365A334DE418}\RP589\A0206180.exe -> Trojan.Agent.bi : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{43C61967-F800-4B8C-AEAC-365A334DE418}\RP589\A0206181.exe -> Trojan.Agent.bi : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{43C61967-F800-4B8C-AEAC-365A334DE418}\RP589\A0206182.exe -> Trojan.Agent.bi : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{43C61967-F800-4B8C-AEAC-365A334DE418}\RP589\A0206183.exe -> Trojan.Agent.bi : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{43C61967-F800-4B8C-AEAC-365A334DE418}\RP589\A0206184.exe -> Trojan.Agent.bi : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{43C61967-F800-4B8C-AEAC-365A334DE418}\RP589\A0206185.exe -> Trojan.Agent.bi : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{43C61967-F800-4B8C-AEAC-365A334DE418}\RP589\A0206186.exe -> Trojan.Agent.bi : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{43C61967-F800-4B8C-AEAC-365A334DE418}\RP589\A0206187.exe -> Trojan.Agent.bi : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{43C61967-F800-4B8C-AEAC-365A334DE418}\RP589\A0206188.exe -> Trojan.Agent.bi : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{43C61967-F800-4B8C-AEAC-365A334DE418}\RP589\A0206189.exe -> Trojan.Agent.bi : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{43C61967-F800-4B8C-AEAC-365A334DE418}\RP589\A0206190.exe -> Trojan.Agent.bi : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{43C61967-F800-4B8C-AEAC-365A334DE418}\RP589\A0206191.exe -> Trojan.Agent.bi : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{43C61967-F800-4B8C-AEAC-365A334DE418}\RP589\A0206192.dll -> Trojan.Agent.bi : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{43C61967-F800-4B8C-AEAC-365A334DE418}\RP589\A0206193.exe -> Trojan.Agent.bi : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{43C61967-F800-4B8C-AEAC-365A334DE418}\RP589\A0206194.exe -> Trojan.Agent.bi : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{43C61967-F800-4B8C-AEAC-365A334DE418}\RP589\A0206195.exe -> Trojan.Agent.bi : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{43C61967-F800-4B8C-AEAC-365A334DE418}\RP589\A0206196.exe -> Trojan.Agent.bi : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{43C61967-F800-4B8C-AEAC-365A334DE418}\RP589\A0206197.exe -> Trojan.Agent.bi : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{43C61967-F800-4B8C-AEAC-365A334DE418}\RP589\A0206198.exe -> Trojan.Agent.bi : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{43C61967-F800-4B8C-AEAC-365A334DE418}\RP589\A0206199.exe -> Trojan.Agent.bi : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{43C61967-F800-4B8C-AEAC-365A334DE418}\RP589\A0206200.exe -> Trojan.Agent.bi : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{43C61967-F800-4B8C-AEAC-365A334DE418}\RP589\A0206201.exe -> Trojan.Agent.bi : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{43C61967-F800-4B8C-AEAC-365A334DE418}\RP589\A0206202.exe -> Trojan.Agent.bi : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{43C61967-F800-4B8C-AEAC-365A334DE418}\RP589\A0206203.exe -> Trojan.Agent.bi : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{43C61967-F800-4B8C-AEAC-365A334DE418}\RP589\A0206204.exe -> Trojan.Agent.bi : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{43C61967-F800-4B8C-AEAC-365A334DE418}\RP589\A0206205.exe -> Trojan.Agent.bi : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{43C61967-F800-4B8C-AEAC-365A334DE418}\RP589\A0206206.exe -> Trojan.Agent.bi : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{43C61967-F800-4B8C-AEAC-365A334DE418}\RP589\A0206207.exe -> Trojan.Agent.bi : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{43C61967-F800-4B8C-AEAC-365A334DE418}\RP589\A0206208.exe -> Trojan.Agent.bi : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{43C61967-F800-4B8C-AEAC-365A334DE418}\RP589\A0206209.exe -> Trojan.Agent.bi : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{43C61967-F800-4B8C-AEAC-365A334DE418}\RP589\A0206210.exe -> Trojan.Agent.bi : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{43C61967-F800-4B8C-AEAC-365A334DE418}\RP589\A0206211.exe -> Trojan.Agent.bi : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{43C61967-F800-4B8C-AEAC-365A334DE418}\RP589\A0206212.exe -> Trojan.Agent.bi : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{43C61967-F800-4B8C-AEAC-365A334DE418}\RP589\A0206213.exe -> Trojan.Agent.bi : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{43C61967-F800-4B8C-AEAC-365A334DE418}\RP589\A0206214.exe -> Trojan.Agent.bi : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{43C61967-F800-4B8C-AEAC-365A334DE418}\RP589\A0206215.exe -> Trojan.Agent.bi : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{43C61967-F800-4B8C-AEAC-365A334DE418}\RP589\A0206216.exe -> Trojan.Agent.bi : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{43C61967-F800-4B8C-AEAC-365A334DE418}\RP589\A0206217.exe -> Trojan.Agent.bi : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{43C61967-F800-4B8C-AEAC-365A334DE418}\RP589\A0206218.exe -> Trojan.Agent.bi : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{43C61967-F800-4B8C-AEAC-365A334DE418}\RP589\A0206219.exe -> Trojan.Agent.bi : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{43C61967-F800-4B8C-AEAC-365A334DE418}\RP589\A0206220.exe -> Trojan.Agent.bi : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{43C61967-F800-4B8C-AEAC-365A334DE418}\RP589\A0206221.exe -> Trojan.Agent.bi : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{43C61967-F800-4B8C-AEAC-365A334DE418}\RP589\A0206222.exe -> Trojan.Agent.bi : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{43C61967-F800-4B8C-AEAC-365A334DE418}\RP589\A0206223.exe -> Trojan.Agent.bi : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{43C61967-F800-4B8C-AEAC-365A334DE418}\RP589\A0206224.exe -> Trojan.Agent.bi : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{43C61967-F800-4B8C-AEAC-365A334DE418}\RP589\A0206225.dll -> Trojan.Agent.bi : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{43C61967-F800-4B8C-AEAC-365A334DE418}\RP589\A0206226.exe -> Trojan.Agent.bi : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{43C61967-F800-4B8C-AEAC-365A334DE418}\RP589\A0206227.exe -> Trojan.Agent.bi : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{43C61967-F800-4B8C-AEAC-365A334DE418}\RP589\A0206228.exe -> Trojan.Agent.bi : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{43C61967-F800-4B8C-AEAC-365A334DE418}\RP589\A0206229.exe -> Trojan.Agent.bi : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{43C61967-F800-4B8C-AEAC-365A334DE418}\RP589\A0206230.exe -> Trojan.Agent.bi : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{43C61967-F800-4B8C-AEAC-365A334DE418}\RP589\A0206231.exe -> Trojan.Agent.bi : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{43C61967-F800-4B8C-AEAC-365A334DE418}\RP589\A0206232.exe -> Trojan.Agent.bi : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{43C61967-F800-4B8C-AEAC-365A334DE418}\RP589\A0206233.exe -> Trojan.Agent.bi : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{43C61967-F800-4B8C-AEAC-365A334DE418}\RP589\A0206234.exe -> Trojan.Agent.bi : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{43C61967-F800-4B8C-AEAC-365A334DE418}\RP589\A0206235.dll -> Trojan.Agent.bi : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{43C61967-F800-4B8C-AEAC-365A334DE418}\RP589\A0206236.exe -> Trojan.Agent.bi : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{43C61967-F800-4B8C-AEAC-365A334DE418}\RP589\A0206237.exe -> Trojan.Agent.bi : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{43C61967-F800-4B8C-AEAC-365A334DE418}\RP589\A0206238.exe -> Trojan.Agent.bi : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{43C61967-F800-4B8C-AEAC-365A334DE418}\RP589\A0206239.exe -> Trojan.Agent.bi : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{43C61967-F800-4B8C-AEAC-365A334DE418}\RP589\A0206240.exe -> Trojan.Agent.bi : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{43C61967-F800-4B8C-AEAC-365A334DE418}\RP589\A0206241.exe -> Trojan.Agent.bi : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{43C61967-F800-4B8C-AEAC-365A334DE418}\RP589\A0206242.exe -> Trojan.Agent.bi : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{43C61967-F800-4B8C-AEAC-365A334DE418}\RP589\A0206243.exe -> Trojan.Agent.bi : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{43C61967-F800-4B8C-AEAC-365A334DE418}\RP589\A0206244.exe -> Trojan.Agent.bi : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{43C61967-F800-4B8C-AEAC-365A334DE418}\RP589\A0206245.exe -> Trojan.Agent.bi : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{43C61967-F800-4B8C-AEAC-365A334DE418}\RP589\A0206246.exe -> Trojan.Agent.bi : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{43C61967-F800-4B8C-AEAC-365A334DE418}\RP589\A0206247.exe -> Trojan.Agent.bi : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{43C61967-F800-4B8C-AEAC-365A334DE418}\RP589\A0206248.exe -> Trojan.Agent.bi : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{43C61967-F800-4B8C-AEAC-365A334DE418}\RP589\A0206249.exe -> Trojan.Agent.bi : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{43C61967-F800-4B8C-AEAC-365A334DE418}\RP589\A0206250.exe -> Trojan.Agent.bi : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{43C61967-F800-4B8C-AEAC-365A334DE418}\RP589\A0206251.exe -> Trojan.Agent.bi : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{43C61967-F800-4B8C-AEAC-365A334DE418}\RP589\A0206252.dll -> Trojan.Agent.bi : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{43C61967-F800-4B8C-AEAC-365A334DE418}\RP589\A0206253.exe:dxlwu -> Trojan.Agent.bi : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{43C61967-F800-4B8C-AEAC-365A334DE418}\RP589\A0206254.exe -> Trojan.Agent.bi : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{43C61967-F800-4B8C-AEAC-365A334DE418}\RP589\A0206255.exe -> Trojan.Agent.bi : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{43C61967-F800-4B8C-AEAC-365A334DE418}\RP589\A0206256.exe -> Trojan.Agent.bi : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{43C61967-F800-4B8C-AEAC-365A334DE418}\RP589\A0206257.exe -> Trojan.Agent.bi : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{43C61967-F800-4B8C-AEAC-365A334DE418}\RP589\A0206258.exe -> Trojan.Agent.bi : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{43C61967-F800-4B8C-AEAC-365A334DE418}\RP589\A0206259.exe -> Trojan.Agent.bi : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{43C61967-F800-4B8C-AEAC-365A334DE418}\RP589\A0206260.exe -> Trojan.Agent.bi : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{43C61967-F800-4B8C-AEAC-365A334DE418}\RP589\A0206261.exe -> Trojan.Agent.bi : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{43C61967-F800-4B8C-AEAC-365A334DE418}\RP589\A0206262.exe -> Trojan.Agent.bi : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{43C61967-F800-4B8C-AEAC-365A334DE418}\RP589\A0206263.exe -> Trojan.Agent.bi : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{43C61967-F800-4B8C-AEAC-365A334DE418}\RP589\A0206264.exe -> Trojan.Agent.bi : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{43C61967-F800-4B8C-AEAC-365A334DE418}\RP589\A0206265.exe -> Trojan.Agent.bi : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{43C61967-F800-4B8C-AEAC-365A334DE418}\RP589\A0206266.exe -> Trojan.Agent.bi : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{43C61967-F800-4B8C-AEAC-365A334DE418}\RP589\A0206267.dll -> Trojan.Agent.bi : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{43C61967-F800-4B8C-AEAC-365A334DE418}\RP589\A0206268.exe -> Trojan.Agent.bi : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{43C61967-F800-4B8C-AEAC-365A334DE418}\RP589\A0206269.exe -> Trojan.Agent.bi : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{43C61967-F800-4B8C-AEAC-365A334DE418}\RP589\A0206270.exe -> Trojan.Agent.bi : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{43C61967-F800-4B8C-AEAC-365A334DE418}\RP589\A0206271.exe -> Trojan.Agent.bi : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{43C61967-F800-4B8C-AEAC-365A334DE418}\RP589\A0206272.exe -> Trojan.Agent.bi : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{43C61967-F800-4B8C-AEAC-365A334DE418}\RP589\A0206273.exe -> Trojan.Agent.bi : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{43C61967-F800-4B8C-AEAC-365A334DE418}\RP589\A0206274.exe -> Trojan.Agent.bi : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{43C61967-F800-4B8C-AEAC-365A334DE418}\RP589\A0206275.exe -> Trojan.Agent.bi : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{43C61967-F800-4B8C-AEAC-365A334DE418}\RP589\A0206276.exe -> Trojan.Agent.bi : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{43C61967-F800-4B8C-AEAC-365A334DE418}\RP589\A0206277.exe -> Trojan.Agent.bi : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{43C61967-F800-4B8C-AEAC-365A334DE418}\RP589\A0206278.exe -> Trojan.Agent.bi : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{43C61967-F800-4B8C-AEAC-365A334DE418}\RP589\A0206279.exe -> Trojan.Agent.bi : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{43C61967-F800-4B8C-AEAC-365A334DE418}\RP589\A0206280.exe -> Trojan.Agent.bi : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{43C61967-F800-4B8C-AEAC-365A334DE418}\RP589\A0206281.exe -> Trojan.Agent.bi : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{43C61967-F800-4B8C-AEAC-365A334DE418}\RP589\A0206282.exe -> Trojan.Agent.bi : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{43C61967-F800-4B8C-AEAC-365A334DE418}\RP589\A0206283.exe -> Trojan.Agent.bi : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{43C61967-F800-4B8C-AEAC-365A334DE418}\RP589\A0206284.exe -> Trojan.Agent.bi : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{43C61967-F800-4B8C-AEAC-365A334DE418}\RP589\A0206285.exe -> Trojan.Agent.bi : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{43C61967-F800-4B8C-AEAC-365A334DE418}\RP589\A0206286.exe -> Trojan.Agent.bi : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{43C61967-F800-4B8C-AEAC-365A334DE418}\RP589\A0206287.exe -> Trojan.Agent.bi : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{43C61967-F800-4B8C-AEAC-365A334DE418}\RP589\A0206288.exe -> Trojan.Agent.bi : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{43C61967-F800-4B8C-AEAC-365A334DE418}\RP589\A0206289.exe -> Trojan.Agent.bi : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{43C61967-F800-4B8C-AEAC-365A334DE418}\RP589\A0206290.exe -> Trojan.Agent.bi : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{43C61967-F800-4B8C-AEAC-365A334DE418}\RP589\A0206291.exe -> Trojan.Agent.bi : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{43C61967-F800-4B8C-AEAC-365A334DE418}\RP589\A0206292.exe -> Trojan.Agent.bi : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{43C61967-F800-4B8C-AEAC-365A334DE418}\RP589\A0206293.exe -> Trojan.Agent.bi : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{43C61967-F800-4B8C-AEAC-365A334DE418}\RP589\A0206294.exe -> Trojan.Agent.bi : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{43C61967-F800-4B8C-AEAC-365A334DE418}\RP589\A0206295.exe -> Trojan.Agent.bi : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{43C61967-F800-4B8C-AEAC-365A334DE418}\RP589\A0206296.exe -> Trojan.Agent.bi : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{43C61967-F800-4B8C-AEAC-365A334DE418}\RP589\A0206297.exe -> Trojan.Agent.bi : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{43C61967-F800-4B8C-AEAC-365A334DE418}\RP589\A0206298.exe -> Trojan.Agent.bi : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{43C61967-F800-4B8C-AEAC-365A334DE418}\RP589\A0206299.exe -> Trojan.Agent.bi : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{43C61967-F800-4B8C-AEAC-365A334DE418}\RP589\A0206300.exe -> Trojan.Agent.bi : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{43C61967-F800-4B8C-AEAC-365A334DE418}\RP589\A0206301.exe -> Trojan.Agent.bi : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{43C61967-F800-4B8C-AEAC-365A334DE418}\RP589\A0206302.exe -> Trojan.Agent.bi : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{43C61967-F800-4B8C-AEAC-365A334DE418}\RP589\A0206303.exe -> Trojan.Agent.bi : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{43C61967-F800-4B8C-AEAC-365A334DE418}\RP589\A0206304.exe -> Trojan.Agent.bi : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{43C61967-F800-4B8C-AEAC-365A334DE418}\RP589\A0206305.exe -> Trojan.Agent.bi : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{43C61967-F800-4B8C-AEAC-365A334DE418}\RP589\A0206306.exe -> Trojan.Agent.bi : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{43C61967-F800-4B8C-AEAC-365A334DE418}\RP589\A0206307.exe -> Trojan.Agent.bi : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{43C61967-F800-4B8C-AEAC-365A334DE418}\RP589\A0206308.exe -> Trojan.Agent.bi : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{43C61967-F800-4B8C-AEAC-365A334DE418}\RP589\A0206309.exe -> Trojan.Agent.bi : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{43C61967-F800-4B8C-AEAC-365A334DE418}\RP589\A0206310.exe -> Trojan.Agent.bi : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{43C61967-F800-4B8C-AEAC-365A334DE418}\RP589\A0206311.exe -> Trojan.Agent.bi : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{43C61967-F800-4B8C-AEAC-365A334DE418}\RP589\A0206312.exe -> Trojan.Agent.bi : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{43C61967-F800-4B8C-AEAC-365A334DE418}\RP589\A0206313.exe -> Trojan.Agent.bi : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{43C61967-F800-4B8C-AEAC-365A334DE418}\RP589\A0206314.exe -> Trojan.Agent.bi : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{43C61967-F800-4B8C-AEAC-365A334DE418}\RP589\A0206315.exe -> Trojan.Agent.bi : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{43C61967-F800-4B8C-AEAC-365A334DE418}\RP589\A0206316.exe -> Trojan.Agent.bi : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{43C61967-F800-4B8C-AEAC-365A334DE418}\RP589\A0206317.exe -> Trojan.Agent.bi : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{43C61967-F800-4B8C-AEAC-365A334DE418}\RP589\A0206318.exe -> Trojan.Agent.bi : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{43C61967-F800-4B8C-AEAC-365A334DE418}\RP589\A0206319.exe -> Trojan.Agent.bi : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{43C61967-F800-4B8C-AEAC-365A334DE418}\RP589\A0206320.exe -> Trojan.Agent.bi : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{43C61967-F800-4B8C-AEAC-365A334DE418}\RP589\A0206321.exe -> Trojan.Agent.bi : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{43C61967-F800-4B8C-AEAC-365A334DE418}\RP589\A0206322.exe -> Trojan.Agent.bi : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{43C61967-F800-4B8C-AEAC-365A334DE418}\RP589\A0206323.exe -> Trojan.Agent.bi : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{43C61967-F800-4B8C-AEAC-365A334DE418}\RP589\A0206324.exe -> Trojan.Agent.bi : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{43C61967-F800-4B8C-AEAC-365A334DE418}\RP589\A0206325.exe -> Trojan.Agent.bi : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{43C61967-F800-4B8C-AEAC-365A334DE418}\RP589\A0206326.exe -> Trojan.Agent.bi : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{43C61967-F800-4B8C-AEAC-365A334DE418}\RP589\A0206327.exe -> Trojan.Agent.bi : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{43C61967-F800-4B8C-AEAC-365A334DE418}\RP589\A0206328.exe -> Trojan.Agent.bi : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{43C61967-F800-4B8C-AEAC-365A334DE418}\RP589\A0206329.exe -> Trojan.Agent.bi : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{43C61967-F800-4B8C-AEAC-365A334DE418}\RP589\A0206330.exe -> Trojan.Agent.bi : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{43C61967-F800-4B8C-AEAC-365A334DE418}\RP589\A0206331.exe -> Trojan.Agent.bi : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{43C61967-F800-4B8C-AEAC-365A334DE418}\RP589\A0206332.exe -> Trojan.Agent.bi : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{43C61967-F800-4B8C-AEAC-365A334DE418}\RP589\A0206333.exe -> Trojan.Agent.bi : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{43C61967-F800-4B8C-AEAC-365A334DE418}\RP589\A0206334.exe -> Trojan.Agent.bi : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{43C61967-F800-4B8C-AEAC-365A334DE418}\RP589\A0206335.exe -> Trojan.Agent.bi : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{43C61967-F800-4B8C-AEAC-365A334DE418}\RP589\A0206336.exe -> Trojan.Agent.bi : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{43C61967-F800-4B8C-AEAC-365A334DE418}\RP589\A0206337.exe -> Trojan.Agent.bi : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{43C61967-F800-4B8C-AEAC-365A334DE418}\RP589\A0206338.exe -> Trojan.Agent.bi : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{43C61967-F800-4B8C-AEAC-365A334DE418}\RP589\A0206339.exe -> Trojan.Agent.bi : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{43C61967-F800-4B8C-AEAC-365A334DE418}\RP589\A0206340.exe -> Trojan.Agent.bi : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{43C61967-F800-4B8C-AEAC-365A334DE418}\RP589\A0206341.exe -> Trojan.Agent.bi : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{43C61967-F800-4B8C-AEAC-365A334DE418}\RP589\A0206342.exe -> Trojan.Agent.bi : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{43C61967-F800-4B8C-AEAC-365A334DE418}\RP589\A0206343.exe -> Trojan.Agent.bi : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{43C61967-F800-4B8C-AEAC-365A334DE418}\RP589\A0206344.exe -> Trojan.Agent.bi : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{43C61967-F800-4B8C-AEAC-365A334DE418}\RP589\A0206345.exe -> Trojan.Agent.bi : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{43C61967-F800-4B8C-AEAC-365A334DE418}\RP589\A0206346.exe -> Trojan.Agent.bi : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{43C61967-F800-4B8C-AEAC-365A334DE418}\RP589\A0206347.exe -> Trojan.Agent.bi : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{43C61967-F800-4B8C-AEAC-365A334DE418}\RP589\A0206348.exe -> Trojan.Agent.bi : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{43C61967-F800-4B8C-AEAC-365A334DE418}\RP589\A0206349.exe -> Trojan.Agent.bi : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{43C61967-F800-4B8C-AEAC-365A334DE418}\RP589\A0206350.exe -> Trojan.Agent.bi : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{43C61967-F800-4B8C-AEAC-365A334DE418}\RP589\A0206351.exe -> Trojan.Agent.bi : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{43C61967-F800-4B8C-AEAC-365A334DE418}\RP589\A0206352.exe -> Trojan.Agent.bi : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{43C61967-F800-4B8C-AEAC-365A334DE418}\RP589\A0206353.exe -> Trojan.Agent.bi : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{43C61967-F800-4B8C-AEAC-365A334DE418}\RP589\A0206354.exe -> Trojan.Agent.bi : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{43C61967-F800-4B8C-AEAC-365A334DE418}\RP589\A0206355.exe -> Trojan.Agent.bi : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{43C61967-F800-4B8C-AEAC-365A334DE418}\RP589\A0206356.dll -> Trojan.Agent.bi : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{43C61967-F800-4B8C-AEAC-365A334DE418}\RP589\A0206357.exe -> Trojan.Agent.bi : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{43C61967-F800-4B8C-AEAC-365A334DE418}\RP589\A0206358.exe -> Trojan.Agent.bi : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{43C61967-F800-4B8C-AEAC-365A334DE418}\RP589\A0206359.exe -> Trojan.Agent.bi : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{43C61967-F800-4B8C-AEAC-365A334DE418}\RP589\A0206360.exe -> Trojan.Agent.bi : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{43C61967-F800-4B8C-AEAC-365A334DE418}\RP589\A0206361.exe -> Trojan.Agent.bi : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{43C61967-F800-4B8C-AEAC-365A334DE418}\RP589\A0206362.exe -> Trojan.Agent.bi : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{43C61967-F800-4B8C-AEAC-365A334DE418}\RP589\A0206363.exe -> Trojan.Agent.bi : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{43C61967-F800-4B8C-AEAC-365A334DE418}\RP589\A0206364.exe -> Trojan.Agent.bi : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{43C61967-F800-4B8C-AEAC-365A334DE418}\RP589\A0206365.dll -> Trojan.Agent.bi : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{43C61967-F800-4B8C-AEAC-365A334DE418}\RP589\A0206366.exe -> Trojan.Agent.bi : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{43C61967-F800-4B8C-AEAC-365A334DE418}\RP589\A0206367.exe -> Trojan.Agent.bi : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{43C61967-F800-4B8C-AEAC-365A334DE418}\RP589\A0206368.exe -> Trojan.Agent.bi : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{43C61967-F800-4B8C-AEAC-365A334DE418}\RP589\A0206369.exe -> Trojan.Agent.bi : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{43C61967-F800-4B8C-AEAC-365A334DE418}\RP589\A0206370.exe -> Trojan.Agent.bi : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{43C61967-F800-4B8C-AEAC-365A334DE418}\RP589\A0206371.exe -> Trojan.Agent.bi : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{43C61967-F800-4B8C-AEAC-365A334DE418}\RP589\A0206372.exe -> Trojan.Agent.bi : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{43C61967-F800-4B8C-AEAC-365A334DE418}\RP589\A0206373.exe -> Trojan.Agent.bi : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{43C61967-F800-4B8C-AEAC-365A334DE418}\RP589\A0206374.exe -> Trojan.Agent.bi : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{43C61967-F800-4B8C-AEAC-365A334DE418}\RP589\A0206375.exe -> Trojan.Agent.bi : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{43C61967-F800-4B8C-AEAC-365A334DE418}\RP589\A0206376.exe -> Trojan.Agent.bi : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{43C61967-F800-4B8C-AEAC-365A334DE418}\RP589\A0206377.exe -> Trojan.Agent.bi : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{43C61967-F800-4B8C-AEAC-365A334DE418}\RP589\A0206378.exe -> Trojan.Agent.bi : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{43C61967-F800-4B8C-AEAC-365A334DE418}\RP589\A0206379.exe -> Trojan.Agent.bi : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{43C61967-F800-4B8C-AEAC-365A334DE418}\RP589\A0206380.exe -> Trojan.Agent.bi : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{43C61967-F800-4B8C-AEAC-365A334DE418}\RP589\A0206381.exe -> Trojan.Agent.bi : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{43C61967-F800-4B8C-AEAC-365A334DE418}\RP589\A0206382.exe -> Trojan.Agent.bi : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{43C61967-F800-4B8C-AEAC-365A334DE418}\RP589\A0206383.exe -> Trojan.Agent.bi : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{43C61967-F800-4B8C-AEAC-365A334DE418}\RP589\A0206384.exe -> Trojan.Agent.bi : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{43C61967-F800-4B8C-AEAC-365A334DE418}\RP589\A0206385.exe -> Trojan.Agent.bi : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{43C61967-F800-4B8C-AEAC-365A334DE418}\RP589\A0206386.exe -> Trojan.Agent.bi : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{43C61967-F800-4B8C-AEAC-365A334DE418}\RP589\A0206387.exe -> Trojan.Agent.bi : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{43C61967-F800-4B8C-AEAC-365A334DE418}\RP589\A0206388.exe -> Trojan.Agent.bi : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{43C61967-F800-4B8C-AEAC-365A334DE418}\RP589\A0206389.exe -> Trojan.Agent.bi : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{43C61967-F800-4B8C-AEAC-365A334DE418}\RP589\A0206390.exe -> Trojan.Agent.bi : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{43C61967-F800-4B8C-AEAC-365A334DE418}\RP589\A0206391.exe -> Trojan.Agent.bi : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{43C61967-F800-4B8C-AEAC-365A334DE418}\RP589\A0206392.exe -> Trojan.Agent.bi : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{43C61967-F800-4B8C-AEAC-365A334DE418}\RP589\A0206393.dll -> Trojan.Agent.bi : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{43C61967-F800-4B8C-AEAC-365A334DE418}\RP589\A0206394.exe -> Trojan.Agent.bi : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{43C61967-F800-4B8C-AEAC-365A334DE418}\RP589\A0206395.exe -> Trojan.Agent.bi : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{43C61967-F800-4B8C-AEAC-365A334DE418}\RP589\A0206396.exe -> Trojan.Agent.bi : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{43C61967-F800-4B8C-AEAC-365A334DE418}\RP589\A0206397.exe -> Trojan.Agent.bi : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{43C61967-F800-4B8C-AEAC-365A334DE418}\RP589\A0206398.exe -> Trojan.Agent.bi : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{43C61967-F800-4B8C-AEAC-365A334DE418}\RP589\A0206399.exe -> Trojan.Agent.bi : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{43C61967-F800-4B8C-AEAC-365A334DE418}\RP589\A0206400.exe -> Trojan.Agent.bi : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{43C61967-F800-4B8C-AEAC-365A334DE418}\RP589\A0206401.exe -> Trojan.Agent.bi : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{43C61967-F800-4B8C-AEAC-365A334DE418}\RP589\A0206402.exe -> Trojan.Agent.bi : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{43C61967-F800-4B8C-AEAC-365A334DE418}\RP589\A0206403.exe -> Trojan.Agent.bi : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{43C61967-F800-4B8C-AEAC-365A334DE418}\RP589\A0206404.exe -> Trojan.Agent.bi : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{43C61967-F800-4B8C-AEAC-365A334DE418}\RP589\A0206405.exe -> Trojan.Agent.bi : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{43C61967-F800-4B8C-AEAC-365A334DE418}\RP589\A0206406.dll -> Trojan.Agent.bi : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{43C61967-F800-4B8C-AEAC-365A334DE418}\RP589\A0206407.exe -> Trojan.Agent.bi : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{43C61967-F800-4B8C-AEAC-365A334DE418}\RP589\A0206408.dll -> Trojan.Agent.bi : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{43C61967-F800-4B8C-AEAC-365A334DE418}\RP589\A0206409.dll -> Trojan.Agent.bi : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{43C61967-F800-4B8C-AEAC-365A334DE418}\RP589\A0206410.exe -> Trojan.Agent.bi : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{43C61967-F800-4B8C-AEAC-365A334DE418}\RP589\A0206411.exe -> Trojan.Agent.bi : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{43C61967-F800-4B8C-AEAC-365A334DE418}\RP589\A0206412.exe -> Trojan.Agent.bi : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{43C61967-F800-4B8C-AEAC-365A334DE418}\RP589\A0206413.exe -> Trojan.Agent.bi : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{43C61967-F800-4B8C-AEAC-365A334DE418}\RP589\A0206414.exe -> Trojan.Agent.bi : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{43C61967-F800-4B8C-AEAC-365A334DE418}\RP589\A0206415.exe -> Trojan.Agent.bi : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{43C61967-F800-4B8C-AEAC-365A334DE418}\RP589\A0206416.exe -> Trojan.Agent.bi : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{43C61967-F800-4B8C-AEAC-365A334DE418}\RP589\A0206417.exe -> Trojan.Agent.bi : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{43C61967-F800-4B8C-AEAC-365A334DE418}\RP589\A0206418.exe -> Trojan.Agent.bi : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{43C61967-F800-4B8C-AEAC-365A334DE418}\RP589\A0206419.exe -> Trojan.Agent.bi : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{43C61967-F800-4B8C-AEAC-365A334DE418}\RP589\A0206420.exe -> Trojan.Agent.bi : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{43C61967-F800-4B8C-AEAC-365A334DE418}\RP589\A0206421.exe -> Trojan.Agent.bi : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{43C61967-F800-4B8C-AEAC-365A334DE418}\RP589\A0206422.exe -> Trojan.Agent.bi : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{43C61967-F800-4B8C-AEAC-365A334DE418}\RP589\A0206423.exe -> Trojan.Agent.bi : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{43C61967-F800-4B8C-AEAC-365A334DE418}\RP589\A0206424.dll -> Trojan.Agent.bi : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{43C61967-F800-4B8C-AEAC-365A334DE418}\RP589\A0206425.exe -> Trojan.Agent.bi : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{43C61967-F800-4B8C-AEAC-365A334DE418}\RP589\A0206426.exe -> Trojan.Agent.bi : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{43C61967-F800-4B8C-AEAC-365A334DE418}\RP589\A0206427.exe -> Trojan.Agent.bi : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{43C61967-F800-4B8C-AEAC-365A334DE418}\RP589\A0206428.exe -> Trojan.Agent.bi : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{43C61967-F800-4B8C-AEAC-365A334DE418}\RP589\A0206429.exe -> Trojan.Agent.bi : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{43C61967-F800-4B8C-AEAC-365A334DE418}\RP589\A0206430.exe -> Trojan.Agent.bi : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{43C61967-F800-4B8C-AEAC-365A334DE418}\RP589\A0206431.exe -> Trojan.Agent.bi : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{43C61967-F800-4B8C-AEAC-365A334DE418}\RP589\A0206432.exe -> Trojan.Agent.bi : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{43C61967-F800-4B8C-AEAC-365A334DE418}\RP589\A0206433.exe -> Trojan.Agent.bi : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{43C61967-F800-4B8C-AEAC-365A334DE418}\RP589\A0206434.exe -> Trojan.Agent.bi : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{43C61967-F800-4B8C-AEAC-365A334DE418}\RP589\A0206435.exe -> Trojan.Agent.bi : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{43C61967-F800-4B8C-AEAC-365A334DE418}\RP589\A0206436.exe -> Trojan.Agent.bi : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{43C61967-F800-4B8C-AEAC-365A334DE418}\RP589\A0206437.exe -> Trojan.Agent.bi : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{43C61967-F800-4B8C-AEAC-365A334DE418}\RP589\A0206438.exe -> Trojan.Agent.bi : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{43C61967-F800-4B8C-AEAC-365A334DE418}\RP589\A0206439.exe -> Trojan.Agent.bi : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{43C61967-F800-4B8C-AEAC-365A334DE418}\RP589\A0206440.exe -> Trojan.Agent.bi : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{43C61967-F800-4B8C-AEAC-365A334DE418}\RP589\A0206441.exe -> Trojan.Agent.bi : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{43C61967-F800-4B8C-AEAC-365A334DE418}\RP589\A0206442.exe -> Trojan.Agent.bi : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{43C61967-F800-4B8C-AEAC-365A334DE418}\RP589\A0206443.exe -> Trojan.Agent.bi : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{43C61967-F800-4B8C-AEAC-365A334DE418}\RP589\A0206444.exe -> Trojan.Agent.bi : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{43C61967-F800-4B8C-AEAC-365A334DE418}\RP589\A0206445.exe -> Trojan.Agent.bi : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{43C61967-F800-4B8C-AEAC-365A334DE418}\RP589\A0206446.exe -> Trojan.Agent.bi : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{43C61967-F800-4B8C-AEAC-365A334DE418}\RP589\A0206447.exe -> Trojan.Agent.bi : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{43C61967-F800-4B8C-AEAC-365A334DE418}\RP589\A0206448.exe -> Trojan.Agent.bi : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{43C61967-F800-4B8C-AEAC-365A334DE418}\RP589\A0206449.exe -> Trojan.Agent.bi : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{43C61967-F800-4B8C-AEAC-365A334DE418}\RP589\A0206450.exe -> Trojan.Agent.bi : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{43C61967-F800-4B8C-AEAC-365A334DE418}\RP589\A0206451.exe -> Trojan.Agent.bi : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{43C61967-F800-4B8C-AEAC-365A334DE418}\RP589\A0206452.exe -> Trojan.Agent.bi : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{43C61967-F800-4B8C-AEAC-365A334DE418}\RP589\A0206453.exe -> Trojan.Agent.bi : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{43C61967-F800-4B8C-AEAC-365A334DE418}\RP589\A0206454.exe -> Trojan.Agent.bi : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{43C61967-F800-4B8C-AEAC-365A334DE418}\RP589\A0206455.exe -> Trojan.Agent.bi : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{43C61967-F800-4B8C-AEAC-365A334DE418}\RP589\A0206456.exe -> Trojan.Agent.bi : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{43C61967-F800-4B8C-AEAC-365A334DE418}\RP589\A0206457.exe -> Trojan.Agent.bi : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{43C61967-F800-4B8C-AEAC-365A334DE418}\RP589\A0206458.exe -> Trojan.Agent.bi : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{43C61967-F800-4B8C-AEAC-365A334DE418}\RP589\A0206459.exe -> Trojan.Agent.bi : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{43C61967-F800-4B8C-AEAC-365A334DE418}\RP589\A0206460.exe -> Trojan.Agent.bi : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{43C61967-F800-4B8C-AEAC-365A334DE418}\RP589\A0206461.exe -> Trojan.Agent.bi : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{43C61967-F800-4B8C-AEAC-365A334DE418}\RP589\A0206462.exe -> Trojan.Agent.bi : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{43C61967-F800-4B8C-AEAC-365A334DE418}\RP589\A0206463.exe -> Trojan.Agent.bi : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{43C61967-F800-4B8C-AEAC-365A334DE418}\RP589\A0206464.exe -> Trojan.Agent.bi : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{43C61967-F800-4B8C-AEAC-365A334DE418}\RP589\A0206465.exe -> Trojan.Agent.bi : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{43C61967-F800-4B8C-AEAC-365A334DE418}\RP589\A0206466.exe -> Trojan.Agent.bi : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{43C61967-F800-4B8C-AEAC-365A334DE418}\RP589\A0206467.exe -> Trojan.Agent.bi : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{43C61967-F800-4B8C-AEAC-365A334DE418}\RP589\A0206468.exe -> Trojan.Agent.bi : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{43C61967-F800-4B8C-AEAC-365A334DE418}\RP589\A0206469.exe -> Trojan.Agent.bi : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{43C61967-F800-4B8C-AEAC-365A334DE418}\RP589\A0206470.exe -> Trojan.Agent.bi : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{43C61967-F800-4B8C-AEAC-365A334DE418}\RP589\A0206471.exe -> Trojan.Agent.bi : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{43C61967-F800-4B8C-AEAC-365A334DE418}\RP589\A0206472.exe -> Trojan.Agent.bi : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{43C61967-F800-4B8C-AEAC-365A334DE418}\RP589\A0206473.exe -> Trojan.Agent.bi : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{43C61967-F800-4B8C-AEAC-365A334DE418}\RP589\A0206474.exe -> Trojan.Agent.bi : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{43C61967-F800-4B8C-AEAC-365A334DE418}\RP589\A0206475.exe -> Trojan.Agent.bi : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{43C61967-F800-4B8C-AEAC-365A334DE418}\RP589\A0206476.exe -> Trojan.Agent.bi : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{43C61967-F800-4B8C-AEAC-365A334DE418}\RP589\A0206477.dll -> Trojan.Agent.bi : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{43C61967-F800-4B8C-AEAC-365A334DE418}\RP589\A0206478.exe -> Trojan.Agent.bi : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{43C61967-F800-4B8C-AEAC-365A334DE418}\RP589\A0206479.exe -> Trojan.Agent.bi : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{43C61967-F800-4B8C-AEAC-365A334DE418}\RP589\A0206480.exe -> Trojan.Agent.bi : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{43C61967-F800-4B8C-AEAC-365A334DE418}\RP589\A0206481.exe -> Trojan.Agent.bi : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{43C61967-F800-4B8C-AEAC-365A334DE418}\RP589\A0206482.exe -> Trojan.Agent.bi : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{43C61967-F800-4B8C-AEAC-365A334DE418}\RP589\A0206483.exe -> Trojan.Agent.bi : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{43C61967-F800-4B8C-AEAC-365A334DE418}\RP589\A0206484.exe -> Trojan.Agent.bi : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{43C61967-F800-4B8C-AEAC-365A334DE418}\RP589\A0206485.exe -> Trojan.Agent.bi : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{43C61967-F800-4B8C-AEAC-365A334DE418}\RP589\A0206486.exe -> Trojan.Agent.bi : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{43C61967-F800-4B8C-AEAC-365A334DE418}\RP589\A0206487.dll -> Trojan.Agent.bi : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{43C61967-F800-4B8C-AEAC-365A334DE418}\RP589\A0206488.exe -> Trojan.Agent.bi : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{43C61967-F800-4B8C-AEAC-365A334DE418}\RP589\A0206489.exe -> Trojan.Agent.bi : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{43C61967-F800-4B8C-AEAC-365A334DE418}\RP589\A0206490.exe -> Trojan.Agent.bi : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{43C61967-F800-4B8C-AEAC-365A334DE418}\RP589\A0206491.exe -> Trojan.Agent.bi : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{43C61967-F800-4B8C-AEAC-365A334DE418}\RP589\A0206492.exe -> Trojan.Agent.bi : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{43C61967-F800-4B8C-AEAC-365A334DE418}\RP589\A0206493.exe -> Trojan.Agent.bi : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{43C61967-F800-4B8C-AEAC-365A334DE418}\RP589\A0206494.exe -> Trojan.Agent.bi : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{43C61967-F800-4B8C-AEAC-365A334DE418}\RP589\A0206495.exe -> Trojan.Agent.bi : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{43C61967-F800-4B8C-AEAC-365A334DE418}\RP589\A0206496.exe -> Trojan.Agent.bi : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{43C61967-F800-4B8C-AEAC-365A334DE418}\RP589\A0206497.exe -> Trojan.Agent.bi : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{43C61967-F800-4B8C-AEAC-365A334DE418}\RP589\A0206498.exe -> Trojan.Agent.bi : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{43C61967-F800-4B8C-AEAC-365A334DE418}\RP589\A0206499.exe -> Trojan.Agent.bi : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{43C61967-F800-4B8C-AEAC-365A334DE418}\RP589\A0206500.exe -> Trojan.Agent.bi : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{43C61967-F800-4B8C-AEAC-365A334DE418}\RP589\A0206501.exe -> Trojan.Agent.bi : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{43C61967-F800-4B8C-AEAC-365A334DE418}\RP589\A0206502.exe -> Trojan.Agent.bi : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{43C61967-F800-4B8C-AEAC-365A334DE418}\RP589\A0206503.exe -> Trojan.Agent.bi : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{43C61967-F800-4B8C-AEAC-365A334DE418}\RP589\A0206504.exe -> Trojan.Agent.bi : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{43C61967-F800-4B8C-AEAC-365A334DE418}\RP589\A0206505.exe -> Trojan.Agent.bi : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{43C61967-F800-4B8C-AEAC-365A334DE418}\RP589\A0206506.exe -> Trojan.Agent.bi : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{43C61967-F800-4B8C-AEAC-365A334DE418}\RP589\A0206507.exe -> Trojan.Agent.bi : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{43C61967-F800-4B8C-AEAC-365A334DE418}\RP589\A0206508.exe -> Trojan.Agent.bi : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{43C61967-F800-4B8C-AEAC-365A334DE418}\RP589\A0206509.exe -> Trojan.Agent.bi : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{43C61967-F800-4B8C-AEAC-365A334DE418}\RP589\A0206510.exe -> Trojan.Agent.bi : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{43C61967-F800-4B8C-AEAC-365A334DE418}\RP589\A0206511.exe -> Trojan.Agent.bi : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{43C61967-F800-4B8C-AEAC-365A334DE418}\RP589\A0206512.dll -> Trojan.Agent.bi : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{43C61967-F800-4B8C-AEAC-365A334DE418}\RP589\A0206513.exe -> Trojan.Agent.bi : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{43C61967-F800-4B8C-AEAC-365A334DE418}\RP589\A0206514.exe -> Trojan.Agent.bi : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{43C61967-F800-4B8C-AEAC-365A334DE418}\RP589\A0206515.exe -> Trojan.Agent.bi : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{43C61967-F800-4B8C-AEAC-365A334DE418}\RP589\A0206516.exe -> Trojan.Agent.bi : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{43C61967-F800-4B8C-AEAC-365A334DE418}\RP589\A0206517.exe -> Trojan.Agent.bi : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{43C61967-F800-4B8C-AEAC-365A334DE418}\RP589\A0206518.exe -> Trojan.Agent.bi : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{43C61967-F800-4B8C-AEAC-365A334DE418}\RP589\A0206519.exe -> Trojan.Agent.bi : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{43C61967-F800-4B8C-AEAC-365A334DE418}\RP589\A0206520.exe -> Trojan.Agent.bi : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{43C61967-F800-4B8C-AEAC-365A334DE418}\RP589\A0206521.exe -> Trojan.Agent.bi : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{43C61967-F800-4B8C-AEAC-365A334DE418}\RP589\A0206522.exe -> Trojan.Agent.bi : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{43C61967-F800-4B8C-AEAC-365A334DE418}\RP589\A0206523.exe -> Trojan.Agent.bi : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{43C61967-F800-4B8C-AEAC-365A334DE418}\RP589\A0206524.exe -> Trojan.Agent.bi : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{43C61967-F800-4B8C-AEAC-365A334DE418}\RP589\A0206525.exe -> Trojan.Agent.bi : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{43C61967-F800-4B8C-AEAC-365A334DE418}\RP589\A0206526.exe -> Trojan.Agent.bi : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{43C61967-F800-4B8C-AEAC-365A334DE418}\RP589\A0206527.exe -> Trojan.Agent.bi : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{43C61967-F800-4B8C-AEAC-365A334DE418}\RP589\A0206528.exe -> Trojan.Agent.bi : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{43C61967-F800-4B8C-AEAC-365A334DE418}\RP589\A0206529.exe -> Trojan.Agent.bi : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{43C61967-F800-4B8C-AEAC-365A334DE418}\RP589\A0206530.exe -> Trojan.Agent.bi : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{43C61967-F800-4B8C-AEAC-365A334DE418}\RP589\A0206531.exe -> Trojan.Agent.bi : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{43C61967-F800-4B8C-AEAC-365A334DE418}\RP589\A0206532.exe -> Trojan.Agent.bi : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{43C61967-F800-4B8C-AEAC-365A334DE418}\RP589\A0207185.exe -> Trojan.Agent.if : Cleaned with backup (quarantined).


    ::Report end

     
  9. maca1

    maca1 Regular member

    Joined:
    Mar 15, 2006
    Messages:
    630
    Likes Received:
    0
    Trophy Points:
    26
    go to add/remove programs and remove Spyware Vanisher

    rescan with hijackthis and place a check beside

    O2 - BHO: (no name) - {17AF3D30-061C-15C3-F3DD-FF77212FA819} - (no file)
    O4 - HKLM\..\Run: [atlja32.exe] C:\WINDOWS\system32\atlja32.ex
    O4 - HKCU\..\Run: [Spyware Vanisher] C:\spywarevanisher-free\FreeScanner.exe -FastScan


    make sure all other windows are closed and click fix checked

    Click here to download ATF Cleaner by Atribune and save it to your desktop.

    http://majorgeeks.com/ATF_Cleaner_d4949.html


    * Double-click ATF-Cleaner.exe to run the program.
    * Under Main choose: Select All
    * Click the Empty Selected button.
    o If you use Firefox:
    + Click Firefox at the top and choose: Select All
    + Click the Empty Selected button.
    + NOTE: If you would like to keep your saved passwords, please click No at the prompt.
    o If you use Opera:
    + Click Opera at the top and choose: Select All
    + Click the Empty Selected button.
    + NOTE: If you would like to keep your saved passwords, please click No at the prompt.
    * Click Exit on the Main menu to close the program.


    Run ActiveScan online virus scan:
    http://www.pandasoftware.com/products/activescan.htm
    When the scan is finished, save the results from the scan!

    Come back here and post a new Hijack This log along with the log from the Panda scan.
     
  10. mayuen

    mayuen Member

    Joined:
    Apr 22, 2006
    Messages:
    12
    Likes Received:
    0
    Trophy Points:
    11
    I went to add/remove programs but there was no item called Spyware Vanisher

    this one still can not be fixed by HijackThis

    O2 - BHO: (no name) - {17AF3D30-061C-15C3-F3DD-FF77212FA819} - (no file)


    After using the ATF Cleaner, I tried to download ActiveScan online virus scan for several times. It showed "Error on downloading ActiveScan". I can't see any problems with the ActiveX

    this is the new Hijack This log.

    Logfile of HijackThis v1.99.1
    Scan saved at 15:48:27, on 24/8/2006
    Platform: Windows XP SP2 (WinNT 5.01.2600)
    MSIE: Internet Explorer v6.00 SP1 (6.00.2900.2180)

    Running processes:
    C:\WINDOWS\System32\smss.exe
    C:\WINDOWS\system32\winlogon.exe
    C:\WINDOWS\system32\services.exe
    C:\WINDOWS\system32\lsass.exe
    C:\WINDOWS\system32\svchost.exe
    C:\Program Files\Windows Defender\MsMpEng.exe
    C:\WINDOWS\System32\svchost.exe
    C:\WINDOWS\system32\spoolsv.exe
    C:\WINDOWS\Explorer.EXE
    C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
    C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
    C:\PROGRA~1\Grisoft\AVGFRE~1\avgemc.exe
    C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
    C:\Program Files\ewido anti-spyware 4.0\guard.exe
    C:\WINDOWS\System32\nvsvc32.exe
    C:\WINDOWS\System32\tcpsvcs.exe
    C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe
    C:\Program Files\Common Files\Symantec Shared\Security Center\SymWSC.exe
    C:\Program Files\IBM\Messages By IBM\ibmmessages.exe
    C:\WINDOWS\system32\dla\tfswctrl.exe
    C:\WINDOWS\system32\SKDAEMON.EXE
    C:\WINDOWS\system32\ICO.EXE
    C:\WINDOWS\system32\Pelmiced.exe
    C:\Program Files\iTunes\iTunesHelper.exe
    C:\Program Files\QuickTime\qttask.exe
    C:\Program Files\iPod\bin\iPodService.exe
    C:\Program Files\Windows Defender\MSASCui.exe
    C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe
    C:\Program Files\ewido anti-spyware 4.0\ewido.exe
    C:\WINDOWS\system32\ctfmon.exe
    C:\Program Files\WinZip\WZQKPICK.EXE
    C:\Documents and Settings\Chilly\My Documents\software file\HijackThis_v1.99.1.exe

    O2 - BHO: (no name) - {17AF3D30-061C-15C3-F3DD-FF77212FA819} - (no file)
    O4 - HKLM\..\Run: [IMJPMIG8.1] "C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE" /Spoil /RemAdvDef /Migration32
    O4 - HKLM\..\Run: [PHIME2002ASync] C:\WINDOWS\System32\IME\TINTLGNT\TINTSETP.EXE /SYNC
    O4 - HKLM\..\Run: [PHIME2002A] C:\WINDOWS\System32\IME\TINTLGNT\TINTSETP.EXE /IMEName
    O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\System32\NvCpl.dll,NvStartup
    O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
    O4 - HKLM\..\Run: [BluetoothAuthenticationAgent] rundll32.exe irprops.cpl,,BluetoothAuthenticationAgent
    O4 - HKLM\..\Run: [ibmmessages] C:\Program Files\IBM\Messages By IBM\ibmmessages.exe
    O4 - HKLM\..\Run: [dla] C:\WINDOWS\system32\dla\tfswctrl.exe
    O4 - HKLM\..\Run: [IMEKRMIG6.1] C:\WINDOWS\ime\imkr6_1\IMEKRMIG.EXE
    O4 - HKLM\..\Run: [MSPY2002] C:\WINDOWS\System32\IME\PINTLGNT\ImScInst.exe /SYNC
    O4 - HKLM\..\Run: [Hot Key Kbd Daemon] SKDAEMON.EXE
    O4 - HKLM\..\Run: [Mouse Suite 98 Daemon] ICO.EXE
    O4 - HKLM\..\Run: [REGSHAVE] C:\Program Files\REGSHAVE\REGSHAVE.EXE /AUTORUN
    O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
    O4 - HKLM\..\Run: [ccRegVfy] "C:\Program Files\Common Files\Symantec Shared\ccRegVfy.exe"
    O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
    O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
    O4 - HKLM\..\Run: [Symantec NetDriver Monitor] C:\PROGRA~1\SYMNET~1\SNDMon.exe /Consumer
    O4 - HKLM\..\Run: [Windows Defender] "C:\Program Files\Windows Defender\MSASCui.exe" -hide
    O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe /STARTUP
    O4 - HKLM\..\Run: [!ewido] "C:\Program Files\ewido anti-spyware 4.0\ewido.exe" /minimized
    O4 - HKLM\..\Run: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k
    O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
    O4 - HKCU\..\Run: [Spyware Begone] C:\freescan\freescan.exe -FastScan
    O4 - HKCU\..\Run: [PcSync] C:\Program Files\Nokia\Nokia PC Suite 6\PcSync2.exe /NoDialog
    O4 - HKCU\..\Run: [ibmmessages] C:\Program Files\IBM\Messages By IBM\ibmmessages.exe
    O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
    O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
    O11 - Options group: [JAVA_IBM] Java (IBM)
    O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll
    O23 - Service: Workstation NetLogon Service ( 11F蛷#滓齡`I) - Unknown owner - C:\WINDOWS\winyy32.exe (file missing)
    O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
    O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
    O23 - Service: AVG E-mail Scanner (AVGEMS) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgemc.exe
    O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
    O23 - Service: Symantec Password Validation Service (ccPwdSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccPwdSvc.exe
    O23 - Service: ewido anti-spyware 4.0 guard - Anti-Malware Development a.s. - C:\Program Files\ewido anti-spyware 4.0\guard.exe
    O23 - Service: iPod 服務 (iPodService) - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
    O23 - Service: NVIDIA Driver Helper Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\System32\nvsvc32.exe
    O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
    O23 - Service: SoundMAX Agent Service (SoundMAX Agent Service (default)) - Analog Devices, Inc. - C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe
    O23 - Service: SymWMI Service (SymWSC) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\Security Center\SymWSC.exe
    O23 - Service: TrueVector Internet Monitor (vsmon) - Unknown owner - C:\WINDOWS\system32\ZoneLabs\vsmon.exe (file missing)
     
  11. maca1

    maca1 Regular member

    Joined:
    Mar 15, 2006
    Messages:
    630
    Likes Received:
    0
    Trophy Points:
    26
    Click Start > Run > and type in:

    services.msc

    Click OK.

    In the services window find this exact name

    Workstation NetLogon Service

    Rightclick and choose "Properties". On the "General" tab under "Service Status" click the "Stop" button to stop the service. Beside "Startup Type" in the dropdown menu select "Disabled". Click Apply then OK. File-Exit the Services utility.


    Download WinPFind http://www.bleepingcomputer.com/files/winpfind.php
    Right Click the Zip Folder and Select "Extract All"
    Extract it somewhere you will remember like the Desktop
    Don’t do anything with it yet!

    Reboot into Safe Mode.
    restart your computer and as soon as it starts booting up again continuously tap F8. A menu should come up where you will be given the option to enter Safe Mode.

    Double click WinPFind.exe
    Click "Start Scan"
    It will scan the entire System, so please be patient and let it complete.


    Reboot back to Normal Mode!

    Go to the WinPFind folder
    Locate WinPFind.txt
    Copy and paste WinPFind.txt in your next post here.
     

Share This Page