piratenews
New member
I didn't do a complete scan with Avira, so I did a full scan. Then I realized most of the 901 viruses were already in quarantine by Spybot and Combofix (and 20 from Avira), so I deleted those and ran another scan. Seems some of the freeware downloads were infected.
----------------------------------------------------------------
FIRST FULL SCAN WITH AVIRA BEFORE DELETING OLD QUARANTINE
----------------------------------------------------------------
End of the scan: Saturday, June 21, 2008 16:34
Used time: 9:58:39 min
The scan has been done completely.
15699 Scanning directories
539792 Files were scanned
901 viruses and/or unwanted programs were found
8 Files were classified as suspicious:
0 files were deleted
0 files were repaired
21 files were moved to quarantine
0 files were renamed
5 Files cannot be scanned
538891 Files not concerned
10486 Archives were scanned
800 Warnings
21 Notes
----------------------------------------------------------------
2ND FULL SCAN WITH AVIRA AFTER DELETING OLD QUARANTINE
----------------------------------------------------------------
Avira AntiVir Personal
Report file date: Saturday, June 21, 2008 18:50
Scanning for 1349608 virus strains and unwanted programs.
Licensed to: Avira AntiVir PersonalEdition Classic
Serial number: 0000149996-ADJIE-0001
Platform: Windows XP
Windows version: (Service Pack 2) [5.1.2600]
Boot mode: Normally booted
Username: SYSTEM
Computer name: CTV
Version information:
BUILD.DAT : 8.1.00.295 16479 Bytes 4/9/2008 16:24:00
AVSCAN.EXE : 8.1.2.12 311553 Bytes 3/18/2008 15:02:56
AVSCAN.DLL : 8.1.1.0 53505 Bytes 2/7/2008 14:43:37
LUKE.DLL : 8.1.2.9 151809 Bytes 2/28/2008 14:41:23
LUKERES.DLL : 8.1.2.1 12033 Bytes 2/21/2008 14:28:40
ANTIVIR0.VDF : 6.40.0.0 11030528 Bytes 7/18/2007 16:33:34
ANTIVIR1.VDF : 7.0.3.2 5447168 Bytes 3/7/2008 19:08:58
ANTIVIR2.VDF : 7.0.4.195 2546176 Bytes 6/14/2008 04:07:10
ANTIVIR3.VDF : 7.0.4.232 250880 Bytes 6/20/2008 04:07:12
Engineversion : 8.1.0.59
AEVDF.DLL : 8.1.0.5 102772 Bytes 2/25/2008 15:58:21
AESCRIPT.DLL : 8.1.0.44 278907 Bytes 6/21/2008 04:07:25
AESCN.DLL : 8.1.0.22 119157 Bytes 6/21/2008 04:07:24
AERDL.DLL : 8.1.0.20 418165 Bytes 6/21/2008 04:07:23
AEPACK.DLL : 8.1.1.6 364918 Bytes 6/21/2008 04:07:22
AEOFFICE.DLL : 8.1.0.20 192891 Bytes 6/21/2008 04:07:21
AEHEUR.DLL : 8.1.0.32 1274231 Bytes 6/21/2008 04:07:21
AEHELP.DLL : 8.1.0.15 115063 Bytes 6/21/2008 04:07:18
AEGEN.DLL : 8.1.0.29 307573 Bytes 6/21/2008 04:07:17
AEEMU.DLL : 8.1.0.6 430451 Bytes 6/21/2008 04:07:15
AECORE.DLL : 8.1.0.31 168310 Bytes 6/21/2008 04:07:13
AVWINLL.DLL : 1.0.0.7 14593 Bytes 1/23/2008 23:07:53
AVPREF.DLL : 8.0.0.1 25857 Bytes 2/18/2008 16:37:50
AVREP.DLL : 7.0.0.1 155688 Bytes 4/16/2007 19:26:47
AVREG.DLL : 8.0.0.0 30977 Bytes 1/23/2008 23:07:49
AVARKT.DLL : 1.0.0.23 307457 Bytes 2/12/2008 14:29:23
AVEVTLOG.DLL : 8.0.0.11 114945 Bytes 2/28/2008 14:31:31
SQLITE3.DLL : 3.3.17.1 339968 Bytes 1/22/2008 23:28:02
SMTPLIB.DLL : 1.2.0.19 28929 Bytes 1/23/2008 23:08:39
NETNT.DLL : 8.0.0.1 7937 Bytes 1/25/2008 18:05:10
RCIMAGE.DLL : 8.0.0.35 2371841 Bytes 3/10/2008 20:37:25
RCTEXT.DLL : 8.0.32.0 86273 Bytes 3/6/2008 18:02:11
Configuration settings for the scan:
Jobname..........................: Complete system scan
Configuration file...............: c:\program files\avira\antivir personaledition classic\sysscan.avp
Logging..........................: low
Primary action...................: interactive
Secondary action.................: ignore
Scan master boot sector..........: on
Scan boot sector.................: on
Boot sectors.....................: C:, E:, H:,
Scan memory......................: on
Process scan.....................: on
Scan registry....................: on
Search for rootkits..............: off
Scan all files...................: Intelligent file selection
Scan archives....................: on
Recursion depth..................: 20
Smart extensions.................: on
Macro heuristic..................: on
File heuristic...................: medium
Start of the scan: Saturday, June 21, 2008 18:50
The scan of running processes will be started
Scan process 'avwsc.exe' - '1' Module(s) have been scanned
Scan process 'avscan.exe' - '1' Module(s) have been scanned
Scan process 'AcroRd32.exe' - '1' Module(s) have been scanned
Scan process 'notepad.exe' - '1' Module(s) have been scanned
Scan process 'explorer.exe' - '1' Module(s) have been scanned
Scan process 'taskmgr.exe' - '1' Module(s) have been scanned
Scan process 'avgnt.exe' - '1' Module(s) have been scanned
Scan process 'oaui.exe' - '0' Module(s) have been scanned
Scan process 'CTSysVol.exe' - '1' Module(s) have been scanned
Scan process 'igfxtray.exe' - '1' Module(s) have been scanned
Scan process 'explorer.exe' - '1' Module(s) have been scanned
Scan process 'sched.exe' - '1' Module(s) have been scanned
Scan process 'oasrv.exe' - '0' Module(s) have been scanned
Scan process 'svchost.exe' - '1' Module(s) have been scanned
Scan process 'svchost.exe' - '1' Module(s) have been scanned
Scan process 'svchost.exe' - '1' Module(s) have been scanned
Scan process 'svchost.exe' - '1' Module(s) have been scanned
Scan process 'svchost.exe' - '1' Module(s) have been scanned
Scan process 'lsass.exe' - '1' Module(s) have been scanned
Scan process 'services.exe' - '1' Module(s) have been scanned
Scan process 'winlogon.exe' - '1' Module(s) have been scanned
Scan process 'csrss.exe' - '1' Module(s) have been scanned
Scan process 'smss.exe' - '1' Module(s) have been scanned
21 processes with 21 modules were scanned
Starting master boot sector scan:
Master boot sector HD0
[INFO] No virus was found!
Master boot sector HD1
[INFO] No virus was found!
Master boot sector HD2
[INFO] No virus was found!
Start scanning boot sectors:
Boot sector 'C:\'
[INFO] No virus was found!
Boot sector 'E:\'
[INFO] No virus was found!
Boot sector 'H:\'
[INFO] No virus was found!
Starting to scan the registry.
The registry was scanned ( '18' files ).
Starting the file scan:
Begin scan in 'C:\'
C:\pagefile.sys
[WARNING] The file could not be opened!
C:\WINDOWS\Installer\{1ad4b29b-ff03-42c5-9803-969fdcb47c9d}\zip.dll
[DETECTION] Is the Trojan horse TR/Shell.Eviell
[NOTE] The file was moved to '48cd9f4b.qua'!
C:\WINDOWS\Installer\{2931ea2a-6692-45ed-8180-2ffc3378c658}\zip.dll
[DETECTION] Is the Trojan horse TR/Shell.Eviell
[NOTE] The file was moved to '48cd9f54.qua'!
C:\WINDOWS\Installer\{29e9372a-d7d2-4003-91ea-da7e38635700}\zip.dll
[DETECTION] Is the Trojan horse TR/Shell.Eviell
[NOTE] The file was moved to '48cd9f55.qua'!
C:\WINDOWS\Installer\{47a73001-2c42-45e0-95ee-64c647a0c7b9}\zip.dll
[DETECTION] Is the Trojan horse TR/Shell.Eviell
[NOTE] The file was moved to '4944b606.qua'!
C:\WINDOWS\Installer\{53b4046e-0116-4d23-b5ce-a76c1a758511}\zip.dll
[DETECTION] Is the Trojan horse TR/Shell.Eviell
[NOTE] The file was moved to '48cd9f56.qua'!
C:\WINDOWS\Installer\{6ea97d2b-af03-4653-9ca0-ff61d00d5cbf}\zip.dll
[DETECTION] Is the Trojan horse TR/Shell.Eviell
[NOTE] The file was moved to '4944b607.qua'!
C:\WINDOWS\Installer\{74fdc03e-393c-4c0d-806a-19b427bfd6c8}\zip.dll
[DETECTION] Is the Trojan horse TR/Shell.Eviell
[NOTE] The file was moved to '48cd9f57.qua'!
C:\WINDOWS\Installer\{ac633de7-14d4-4297-8e5f-613b933fb5ab}\KbdSetup.dll
[DETECTION] Is the Trojan horse TR/Shell.Eviell
[NOTE] The file was moved to '48c19f53.qua'!
C:\WINDOWS\Installer\{d5922084-f076-4b91-abc8-9390f0f76e02}\zip.dll
[DETECTION] Is the Trojan horse TR/Shell.Eviell
[NOTE] The file was moved to '48cd9f5b.qua'!
C:\WINDOWS\Installer\{e82124db-dadc-4f41-977a-12c725dd7cc0}\DrvAvp.dll
[DETECTION] Is the Trojan horse TR/Shell.Eviell
[NOTE] The file was moved to '48d39f64.qua'!
C:\WINDOWS\Installer\{ffec9829-e3c4-4c07-ae34-3eadf8b7a6bf}\zip.dll
[DETECTION] Is the Trojan horse TR/Shell.Eviell
[NOTE] The file was moved to '4944b60c.qua'!
C:\WINDOWS\system32\drivers\OADriver.sys
[WARNING] The file could not be opened!
C:\WINDOWS\system32\drivers\OAmon.sys
[WARNING] The file could not be opened!
C:\WINDOWS\system32\drivers\oanet.sys
[WARNING] The file could not be opened!
C:\_OTMoveIt\MovedFiles\06202008_062618\WINDOWS\Installer\{0bfb355f-1157-4832-81f7-b2da5b3957c7}\zip.dll
[DETECTION] Is the Trojan horse TR/Shell.Eviell
[NOTE] The file was moved to '48cda0e4.qua'!
C:\_OTMoveIt\MovedFiles\06202008_062618\WINDOWS\Installer\{334ff6d0-523d-4f68-828b-09d34d3a6b9a}\zip.dll
[DETECTION] Is the Trojan horse TR/Shell.Eviell
[NOTE] The file was moved to '4941e0d5.qua'!
C:\_OTMoveIt\MovedFiles\06202008_062618\WINDOWS\Installer\{8dceb2ba-45a6-4b83-8580-51cb2b532546}\zip.dll
[DETECTION] Is the Trojan horse TR/Shell.Eviell
[NOTE] The file was moved to '48cda0e6.qua'!
C:\_OTMoveIt\MovedFiles\06202008_062618\WINDOWS\Installer\{9d00dc2b-b071-4706-876d-4bac586f2ab7}\zip.dll
[DETECTION] Is the Trojan horse TR/Shell.Eviell
[NOTE] The file was moved to '48cda0e5.qua'!
C:\_OTMoveIt\MovedFiles\06202008_062618\WINDOWS\Installer\{ac234da1-fa9d-4cff-850c-b9d5e6659f1b}\zip.dll
[DETECTION] Is the Trojan horse TR/Shell.Eviell
[NOTE] The file was moved to '4941e0d6.qua'!
Begin scan in 'E:\' <DSK2_VOL1>
E:\pagefile.sys
[WARNING] The file could not be opened!
E:\System Volume Information\_restore{879E598B-020E-408B-AC9B-13ABBD7D02C3}\RP91\A0026306.exe
[DETECTION] Is the Trojan horse TR/Drop.Halloween.A
[NOTE] The file was moved to '488da33f.qua'!
E:\System Volume Information\_restore{879E598B-020E-408B-AC9B-13ABBD7D02C3}\RP91\A0026307.exe
[DETECTION] Is the Trojan horse TR/Drop.Halloween.A
[NOTE] The file was moved to '488da340.qua'!
Begin scan in 'H:\' <Maxtor 300GB>
H:\C Program Backup Virus Crash 13mar08\CuteComp.exe
[DETECTION] Contains detection pattern of the dropper DR/WhenU.A.112
[NOTE] The file was moved to '48d1a3c0.qua'!
H:\C Program Backup Virus Crash 13mar08\SP-SpookySounds_Install.exe
[0] Archive type: ZIP SFX (self extracting)
--> setup.exe
[DETECTION] Is the Trojan horse TR/Drop.Joiner.DV.2
[NOTE] The file was moved to '488aa3ab.qua'!
H:\C Program Backup Virus Crash 13mar08\Robot Voices\male-voice-american.exe
[DETECTION] Contains detection pattern of the dropper DR/Spy.Delf.FK
[NOTE] The file was moved to '48c9a516.qua'!
H:\System Volume Information\_restore{879E598B-020E-408B-AC9B-13ABBD7D02C3}\RP59\A0016208.dll
[DETECTION] Contains detection pattern of the worm WORM/Locksky.CM.1
[NOTE] The file was moved to '488da85b.qua'!
H:\System Volume Information\_restore{879E598B-020E-408B-AC9B-13ABBD7D02C3}\RP91\A0026154.exe
[DETECTION] Is the Trojan horse TR/Crypt.XPACK.Gen
[NOTE] The file was moved to '488da85d.qua'!
H:\System Volume Information\_restore{879E598B-020E-408B-AC9B-13ABBD7D02C3}\RP91\A0026155.dll
[DETECTION] Is the Trojan horse TR/Vundo.Gen
[NOTE] The file was moved to '4904810e.qua'!
H:\System Volume Information\_restore{879E598B-020E-408B-AC9B-13ABBD7D02C3}\RP91\A0026156.exe
[DETECTION] Is the Trojan horse TR/Crypt.XPACK.Gen
[NOTE] The file was moved to '488da85e.qua'!
H:\System Volume Information\_restore{879E598B-020E-408B-AC9B-13ABBD7D02C3}\RP91\A0026157.sys
[DETECTION] Contains detection pattern of the worm WORM/Locksky.CM.1
[NOTE] The file was moved to '4904810f.qua'!
H:\System Volume Information\_restore{879E598B-020E-408B-AC9B-13ABBD7D02C3}\RP91\A0026158.dll
[DETECTION] Is the Trojan horse TR/Vundo.Gen
[NOTE] The file was moved to '488da840.qua'!
H:\System Volume Information\_restore{879E598B-020E-408B-AC9B-13ABBD7D02C3}\RP91\A0026159.dll
[DETECTION] Contains detection pattern of the worm WORM/Locksky.CM.1
[NOTE] The file was moved to '49048111.qua'!
H:\System Volume Information\_restore{879E598B-020E-408B-AC9B-13ABBD7D02C3}\RP91\A0026160.exe
[DETECTION] Is the Trojan horse TR/Crypt.XPACK.Gen
[NOTE] The file was moved to '488da85f.qua'!
H:\System Volume Information\_restore{879E598B-020E-408B-AC9B-13ABBD7D02C3}\RP91\A0026161.dll
[DETECTION] Is the Trojan horse TR/Vundo.Gen
[NOTE] The file was moved to '49048130.qua'!
H:\System Volume Information\_restore{879E598B-020E-408B-AC9B-13ABBD7D02C3}\RP91\A0026162.exe
[DETECTION] Is the Trojan horse TR/Crypt.XPACK.Gen
[NOTE] The file was moved to '488da861.qua'!
H:\System Volume Information\_restore{879E598B-020E-408B-AC9B-13ABBD7D02C3}\RP91\A0026163.exe
[DETECTION] Is the Trojan horse TR/Crypt.XPACK.Gen
[NOTE] The file was moved to '49048132.qua'!
H:\System Volume Information\_restore{879E598B-020E-408B-AC9B-13ABBD7D02C3}\RP91\A0026164.sys
[DETECTION] Contains detection pattern of the worm WORM/Locksky.CM.1
[NOTE] The file was moved to '488da860.qua'!
H:\System Volume Information\_restore{879E598B-020E-408B-AC9B-13ABBD7D02C3}\RP91\A0026165.dll
[DETECTION] Is the Trojan horse TR/Vundo.Gen
[NOTE] The file was moved to '49048131.qua'!
H:\System Volume Information\_restore{879E598B-020E-408B-AC9B-13ABBD7D02C3}\RP91\A0026166.dll
[DETECTION] Is the Trojan horse TR/Crypt.XPACK.Gen
[NOTE] The file was moved to '488da862.qua'!
H:\System Volume Information\_restore{879E598B-020E-408B-AC9B-13ABBD7D02C3}\RP91\A0026167.exe
[DETECTION] Is the Trojan horse TR/Crypt.XPACK.Gen
[NOTE] The file was moved to '488da863.qua'!
H:\System Volume Information\_restore{879E598B-020E-408B-AC9B-13ABBD7D02C3}\RP91\A0026168.exe
[DETECTION] Is the Trojan horse TR/Crypt.XPACK.Gen
[NOTE] The file was moved to '49048134.qua'!
H:\System Volume Information\_restore{879E598B-020E-408B-AC9B-13ABBD7D02C3}\RP91\A0026169.dll
[DETECTION] Is the Trojan horse TR/Vundo.Gen
[NOTE] The file was moved to '488da865.qua'!
H:\System Volume Information\_restore{879E598B-020E-408B-AC9B-13ABBD7D02C3}\RP91\A0026170.exe
[DETECTION] Is the Trojan horse TR/Crypt.XPACK.Gen
[NOTE] The file was moved to '49048136.qua'!
H:\System Volume Information\_restore{879E598B-020E-408B-AC9B-13ABBD7D02C3}\RP91\A0026171.dll
[DETECTION] Contains detection pattern of the worm WORM/Locksky.CM.1
[NOTE] The file was moved to '49048133.qua'!
H:\System Volume Information\_restore{879E598B-020E-408B-AC9B-13ABBD7D02C3}\RP91\A0026173.sys
[DETECTION] Contains detection pattern of the worm WORM/Locksky.CM.1
[NOTE] The file was moved to '488da864.qua'!
H:\System Volume Information\_restore{879E598B-020E-408B-AC9B-13ABBD7D02C3}\RP91\A0026174.drv
[DETECTION] Contains detection pattern of the worm WORM/Locksky.CM.1
[NOTE] The file was moved to '49048135.qua'!
H:\System Volume Information\_restore{879E598B-020E-408B-AC9B-13ABBD7D02C3}\RP91\A0026175.drv
[DETECTION] Contains detection pattern of the worm WORM/Locksky.CM.1
[NOTE] The file was moved to '488da866.qua'!
H:\System Volume Information\_restore{879E598B-020E-408B-AC9B-13ABBD7D02C3}\RP91\A0026176.dll
[DETECTION] Contains detection pattern of the worm WORM/Locksky.CM.1
[NOTE] The file was moved to '488da867.qua'!
H:\System Volume Information\_restore{879E598B-020E-408B-AC9B-13ABBD7D02C3}\RP91\A0026177.dll
[DETECTION] Contains detection pattern of the worm WORM/Locksky.CM.1
[NOTE] The file was moved to '49048138.qua'!
H:\System Volume Information\_restore{879E598B-020E-408B-AC9B-13ABBD7D02C3}\RP91\A0026178.drv
[DETECTION] Contains detection pattern of the worm WORM/Locksky.CM.1
[NOTE] The file was moved to '488da869.qua'!
H:\System Volume Information\_restore{879E598B-020E-408B-AC9B-13ABBD7D02C3}\RP91\A0026181.exe
[DETECTION] Is the Trojan horse TR/Agent.fwi
[NOTE] The file was moved to '4904813a.qua'!
H:\System Volume Information\_restore{879E598B-020E-408B-AC9B-13ABBD7D02C3}\RP91\A0026182.exe
[DETECTION] Is the Trojan horse TR/Agent.fwi
[NOTE] The file was moved to '49048137.qua'!
H:\System Volume Information\_restore{879E598B-020E-408B-AC9B-13ABBD7D02C3}\RP91\A0026183.exe
[DETECTION] Is the Trojan horse TR/Agent.fwi
[NOTE] The file was moved to '488da868.qua'!
H:\System Volume Information\_restore{879E598B-020E-408B-AC9B-13ABBD7D02C3}\RP91\A0026184.exe
[DETECTION] Is the Trojan horse TR/Spy.Agent.aci
[NOTE] The file was moved to '49048139.qua'!
H:\System Volume Information\_restore{879E598B-020E-408B-AC9B-13ABBD7D02C3}\RP91\A0026185.exe
[DETECTION] Is the Trojan horse TR/Agent.fwi
[NOTE] The file was moved to '488da86b.qua'!
H:\System Volume Information\_restore{879E598B-020E-408B-AC9B-13ABBD7D02C3}\RP91\A0026186.exe
[DETECTION] Is the Trojan horse TR/Agent.fwi
[NOTE] The file was moved to '4904813c.qua'!
H:\System Volume Information\_restore{879E598B-020E-408B-AC9B-13ABBD7D02C3}\RP91\A0026187.exe
[DETECTION] Is the Trojan horse TR/Agent.fwi
[NOTE] The file was moved to '488da86a.qua'!
H:\System Volume Information\_restore{879E598B-020E-408B-AC9B-13ABBD7D02C3}\RP91\A0026188.exe
[DETECTION] Is the Trojan horse TR/Agent.fwi
[NOTE] The file was moved to '4904813b.qua'!
H:\System Volume Information\_restore{879E598B-020E-408B-AC9B-13ABBD7D02C3}\RP91\A0026189.exe
[DETECTION] Is the Trojan horse TR/Spy.Agent.aci
[NOTE] The file was moved to '488da86c.qua'!
H:\System Volume Information\_restore{879E598B-020E-408B-AC9B-13ABBD7D02C3}\RP91\A0026190.exe
[DETECTION] Is the Trojan horse TR/Agent.fwi
[NOTE] The file was moved to '488da86d.qua'!
H:\System Volume Information\_restore{879E598B-020E-408B-AC9B-13ABBD7D02C3}\RP91\A0026191.exe
[DETECTION] Is the Trojan horse TR/Agent.fwi
[NOTE] The file was moved to '4904813e.qua'!
H:\System Volume Information\_restore{879E598B-020E-408B-AC9B-13ABBD7D02C3}\RP91\A0026192.exe
[DETECTION] Is the Trojan horse TR/Agent.fwi
[NOTE] The file was moved to '488da86f.qua'!
H:\System Volume Information\_restore{879E598B-020E-408B-AC9B-13ABBD7D02C3}\RP91\A0026193.exe
[DETECTION] Is the Trojan horse TR/Agent.fwi
[NOTE] The file was moved to '49048120.qua'!
H:\System Volume Information\_restore{879E598B-020E-408B-AC9B-13ABBD7D02C3}\RP91\A0026194.exe
[DETECTION] Is the Trojan horse TR/Agent.fwi
[NOTE] The file was moved to '4904813d.qua'!
H:\System Volume Information\_restore{879E598B-020E-408B-AC9B-13ABBD7D02C3}\RP91\A0026195.exe
[DETECTION] Is the Trojan horse TR/Agent.fwi
[NOTE] The file was moved to '488da86e.qua'!
H:\System Volume Information\_restore{879E598B-020E-408B-AC9B-13ABBD7D02C3}\RP91\A0026196.exe
[DETECTION] Is the Trojan horse TR/Agent.fwi
[NOTE] The file was moved to '4904813f.qua'!
H:\System Volume Information\_restore{879E598B-020E-408B-AC9B-13ABBD7D02C3}\RP91\A0026197.exe
[DETECTION] Is the Trojan horse TR/Agent.fwi
[NOTE] The file was moved to '488da810.qua'!
H:\System Volume Information\_restore{879E598B-020E-408B-AC9B-13ABBD7D02C3}\RP91\A0026198.exe
[DETECTION] Is the Trojan horse TR/Agent.fwi
[NOTE] The file was moved to '488da871.qua'!
H:\System Volume Information\_restore{879E598B-020E-408B-AC9B-13ABBD7D02C3}\RP91\A0026199.exe
[DETECTION] Is the Trojan horse TR/Shell.Eviell
[NOTE] The file was moved to '49048122.qua'!
H:\System Volume Information\_restore{879E598B-020E-408B-AC9B-13ABBD7D02C3}\RP91\A0026200.exe
[DETECTION] Is the Trojan horse TR/Spy.Agent.aci
[NOTE] The file was moved to '488da873.qua'!
H:\System Volume Information\_restore{879E598B-020E-408B-AC9B-13ABBD7D02C3}\RP91\A0026201.exe
[DETECTION] Is the Trojan horse TR/Agent.fwi
[NOTE] The file was moved to '49048141.qua'!
H:\System Volume Information\_restore{879E598B-020E-408B-AC9B-13ABBD7D02C3}\RP91\A0026202.exe
[DETECTION] Is the Trojan horse TR/Agent.fwi
[NOTE] The file was moved to '488da812.qua'!
H:\System Volume Information\_restore{879E598B-020E-408B-AC9B-13ABBD7D02C3}\RP91\A0026203.exe
--> Object
[1] Archive type: RSRC
--> Object
[DETECTION] Is the Trojan horse TR/Click.Agent.WD
[NOTE] The file was moved to '49048143.qua'!
H:\System Volume Information\_restore{879E598B-020E-408B-AC9B-13ABBD7D02C3}\RP91\A0026207.exe
[DETECTION] Is the Trojan horse TR/Crypt.XDR.Gen
[NOTE] The file was moved to '49048124.qua'!
H:\System Volume Information\_restore{879E598B-020E-408B-AC9B-13ABBD7D02C3}\RP91\A0026209.exe
[DETECTION] Is the Trojan horse TR/Crypt.XPACK.Gen
[NOTE] The file was moved to '488da814.qua'!
H:\System Volume Information\_restore{879E598B-020E-408B-AC9B-13ABBD7D02C3}\RP91\A0026210.exe
[DETECTION] Is the Trojan horse TR/Crypt.XPACK.Gen
[NOTE] The file was moved to '49048145.qua'!
H:\System Volume Information\_restore{879E598B-020E-408B-AC9B-13ABBD7D02C3}\RP91\A0026214.exe
[DETECTION] Is the Trojan horse TR/Crypt.XDR.Gen
[NOTE] The file was moved to '488da875.qua'!
H:\System Volume Information\_restore{879E598B-020E-408B-AC9B-13ABBD7D02C3}\RP91\A0026215.exe
[DETECTION] Is the Trojan horse TR/Dldr.Adload.MA.3
[NOTE] The file was moved to '49048126.qua'!
H:\System Volume Information\_restore{879E598B-020E-408B-AC9B-13ABBD7D02C3}\RP91\A0026216.exe
[DETECTION] Is the Trojan horse TR/Crypt.XPACK.Gen
[NOTE] The file was moved to '488da877.qua'!
H:\System Volume Information\_restore{879E598B-020E-408B-AC9B-13ABBD7D02C3}\RP91\A0026217.exe
[DETECTION] Is the Trojan horse TR/Crypt.XPACK.Gen
[NOTE] The file was moved to '49048128.qua'!
H:\System Volume Information\_restore{879E598B-020E-408B-AC9B-13ABBD7D02C3}\RP91\A0026218.dll
[DETECTION] Is the Trojan horse TR/Vundo.Gen
[NOTE] The file was moved to '488da816.qua'!
H:\System Volume Information\_restore{879E598B-020E-408B-AC9B-13ABBD7D02C3}\RP91\A0026219.dll
[DETECTION] Is the Trojan horse TR/Vundo.Gen
[NOTE] The file was moved to '49048147.qua'!
H:\System Volume Information\_restore{879E598B-020E-408B-AC9B-13ABBD7D02C3}\RP91\A0026220.exe
[DETECTION] Is the Trojan horse TR/Crypt.XPACK.Gen
[NOTE] The file was moved to '488da818.qua'!
H:\System Volume Information\_restore{879E598B-020E-408B-AC9B-13ABBD7D02C3}\RP91\A0026221.drv
[DETECTION] Contains detection pattern of the worm WORM/Locksky.CM.1
[NOTE] The file was moved to '49048149.qua'!
H:\System Volume Information\_restore{879E598B-020E-408B-AC9B-13ABBD7D02C3}\RP91\A0026222.drv
[DETECTION] Contains detection pattern of the worm WORM/Locksky.CM.1
[NOTE] The file was moved to '488da879.qua'!
H:\System Volume Information\_restore{879E598B-020E-408B-AC9B-13ABBD7D02C3}\RP91\A0026223.dll
[DETECTION] Contains detection pattern of the worm WORM/Locksky.CM.1
[NOTE] The file was moved to '4904812a.qua'!
H:\System Volume Information\_restore{879E598B-020E-408B-AC9B-13ABBD7D02C3}\RP91\A0026224.dll
[DETECTION] Is the Trojan horse TR/Vundo.Gen
[NOTE] The file was moved to '488da87b.qua'!
H:\System Volume Information\_restore{879E598B-020E-408B-AC9B-13ABBD7D02C3}\RP91\A0026225.exe
[DETECTION] Is the Trojan horse TR/Crypt.XPACK.Gen
[NOTE] The file was moved to '4904812c.qua'!
H:\System Volume Information\_restore{879E598B-020E-408B-AC9B-13ABBD7D02C3}\RP91\A0026226.dll
[DETECTION] Contains detection pattern of the worm WORM/Locksky.CM.1
[NOTE] The file was moved to '488da870.qua'!
H:\System Volume Information\_restore{879E598B-020E-408B-AC9B-13ABBD7D02C3}\RP91\A0026227.dll
[DETECTION] Is the Trojan horse TR/Vundo.Gen
[NOTE] The file was moved to '49048121.qua'!
H:\System Volume Information\_restore{879E598B-020E-408B-AC9B-13ABBD7D02C3}\RP91\A0026228.dll
[DETECTION] Is the Trojan horse TR/Vundo.Gen
[NOTE] The file was moved to '488da872.qua'!
H:\System Volume Information\_restore{879E598B-020E-408B-AC9B-13ABBD7D02C3}\RP91\A0026229.dll
[DETECTION] Is the Trojan horse TR/Vundo.Gen
[NOTE] The file was moved to '49048123.qua'!
H:\System Volume Information\_restore{879E598B-020E-408B-AC9B-13ABBD7D02C3}\RP91\A0026230.exe
[DETECTION] Is the Trojan horse TR/Crypt.XPACK.Gen
[NOTE] The file was moved to '488da87d.qua'!
H:\System Volume Information\_restore{879E598B-020E-408B-AC9B-13ABBD7D02C3}\RP91\A0026231.dll
[DETECTION] Is the Trojan horse TR/Downloader.Gen
[NOTE] The file was moved to '4904812e.qua'!
H:\System Volume Information\_restore{879E598B-020E-408B-AC9B-13ABBD7D02C3}\RP91\A0026232.dll
[DETECTION] Contains detection pattern of the worm WORM/Locksky.CM.1
[NOTE] The file was moved to '488da87f.qua'!
H:\System Volume Information\_restore{879E598B-020E-408B-AC9B-13ABBD7D02C3}\RP91\A0026233.drv
[DETECTION] Contains detection pattern of the worm WORM/Locksky.CM.1
[NOTE] The file was moved to '490481d0.qua'!
H:\System Volume Information\_restore{879E598B-020E-408B-AC9B-13ABBD7D02C3}\RP91\A0026234.exe
[DETECTION] Is the Trojan horse TR/Crypt.XPACK.Gen
[NOTE] The file was moved to '488da874.qua'!
H:\System Volume Information\_restore{879E598B-020E-408B-AC9B-13ABBD7D02C3}\RP91\A0026235.exe
[DETECTION] Is the Trojan horse TR/Crypt.XPACK.Gen
[NOTE] The file was moved to '49048125.qua'!
H:\System Volume Information\_restore{879E598B-020E-408B-AC9B-13ABBD7D02C3}\RP91\A0026236.dll
[DETECTION] Is the Trojan horse TR/Vundo.Gen
[NOTE] The file was moved to '488da876.qua'!
H:\System Volume Information\_restore{879E598B-020E-408B-AC9B-13ABBD7D02C3}\RP91\A0026237.drv
[DETECTION] Contains detection pattern of the worm WORM/Locksky.CM.1
[NOTE] The file was moved to '49048127.qua'!
H:\System Volume Information\_restore{879E598B-020E-408B-AC9B-13ABBD7D02C3}\RP91\A0026238.dll
[DETECTION] Is the Trojan horse TR/Vundo.Gen
[NOTE] The file was moved to '488da881.qua'!
H:\System Volume Information\_restore{879E598B-020E-408B-AC9B-13ABBD7D02C3}\RP91\A0026239.exe
[DETECTION] Is the Trojan horse TR/Crypt.XPACK.Gen
[NOTE] The file was moved to '490481d2.qua'!
H:\System Volume Information\_restore{879E598B-020E-408B-AC9B-13ABBD7D02C3}\RP91\A0026240.sys
[DETECTION] Contains detection pattern of the worm WORM/Locksky.CM.1
[NOTE] The file was moved to '488da883.qua'!
H:\System Volume Information\_restore{879E598B-020E-408B-AC9B-13ABBD7D02C3}\RP91\A0026241.dll
[DETECTION] Is the Trojan horse TR/Vundo.Gen
[NOTE] The file was moved to '490481d4.qua'!
H:\System Volume Information\_restore{879E598B-020E-408B-AC9B-13ABBD7D02C3}\RP91\A0026242.exe
[DETECTION] Is the Trojan horse TR/Crypt.XPACK.Gen
[NOTE] The file was moved to '488da878.qua'!
H:\System Volume Information\_restore{879E598B-020E-408B-AC9B-13ABBD7D02C3}\RP91\A0026243.exe
[DETECTION] Is the Trojan horse TR/Crypt.XPACK.Gen
[NOTE] The file was moved to '49048129.qua'!
H:\System Volume Information\_restore{879E598B-020E-408B-AC9B-13ABBD7D02C3}\RP91\A0026244.exe
[DETECTION] Contains detection pattern of the worm WORM/Socks.C
[NOTE] The file was moved to '488da87a.qua'!
H:\System Volume Information\_restore{879E598B-020E-408B-AC9B-13ABBD7D02C3}\RP91\A0026245.exe
[DETECTION] Is the Trojan horse TR/Hijacker.Gen
[NOTE] The file was moved to '488da885.qua'!
H:\System Volume Information\_restore{879E598B-020E-408B-AC9B-13ABBD7D02C3}\RP91\A0026246.exe
[DETECTION] Is the Trojan horse TR/Dldr.Small.svf
[NOTE] The file was moved to '490481d6.qua'!
H:\System Volume Information\_restore{879E598B-020E-408B-AC9B-13ABBD7D02C3}\RP91\A0026247.exe
[DETECTION] Is the Trojan horse TR/Pakes.cif
[NOTE] The file was moved to '488da887.qua'!
H:\System Volume Information\_restore{879E598B-020E-408B-AC9B-13ABBD7D02C3}\RP91\A0026248.exe
[DETECTION] Is the Trojan horse TR/Peed.A.41
[NOTE] The file was moved to '4904812b.qua'!
H:\System Volume Information\_restore{879E598B-020E-408B-AC9B-13ABBD7D02C3}\RP91\A0026249.exe
[DETECTION] Is the Trojan horse TR/Clicker.Agent.TP
[NOTE] The file was moved to '488da87c.qua'!
H:\System Volume Information\_restore{879E598B-020E-408B-AC9B-13ABBD7D02C3}\RP91\A0026250.exe
[DETECTION] Is the Trojan horse TR/Crypt.XPACK.Gen
[NOTE] The file was moved to '490481d8.qua'!
H:\System Volume Information\_restore{879E598B-020E-408B-AC9B-13ABBD7D02C3}\RP91\A0026251.exe
[DETECTION] Is the Trojan horse TR/Crypt.XPACK.Gen
[NOTE] The file was moved to '488da889.qua'!
H:\System Volume Information\_restore{879E598B-020E-408B-AC9B-13ABBD7D02C3}\RP91\A0026252.dll
[DETECTION] Contains detection pattern of the worm WORM/Locksky.CM.1
[NOTE] The file was moved to '490481da.qua'!
H:\System Volume Information\_restore{879E598B-020E-408B-AC9B-13ABBD7D02C3}\RP91\A0026253.exe
[DETECTION] Is the Trojan horse TR/Crypt.XPACK.Gen
[NOTE] The file was moved to '488da88b.qua'!
H:\System Volume Information\_restore{879E598B-020E-408B-AC9B-13ABBD7D02C3}\RP91\A0026254.exe
[DETECTION] Is the Trojan horse TR/Crypt.XPACK.Gen
[NOTE] The file was moved to '4904812d.qua'!
H:\System Volume Information\_restore{879E598B-020E-408B-AC9B-13ABBD7D02C3}\RP91\A0026255.exe
[DETECTION] Is the Trojan horse TR/Crypt.XPACK.Gen
[NOTE] The file was moved to '488da87e.qua'!
H:\System Volume Information\_restore{879E598B-020E-408B-AC9B-13ABBD7D02C3}\RP91\A0026256.exe
[DETECTION] Is the Trojan horse TR/Crypt.XPACK.Gen
[NOTE] The file was moved to '4904812f.qua'!
H:\System Volume Information\_restore{879E598B-020E-408B-AC9B-13ABBD7D02C3}\RP91\A0026257.sys
[DETECTION] Contains detection pattern of the worm WORM/Locksky.CM.1
[NOTE] The file was moved to '490481dc.qua'!
H:\System Volume Information\_restore{879E598B-020E-408B-AC9B-13ABBD7D02C3}\RP91\A0026258.exe
[DETECTION] Is the Trojan horse TR/Crypt.XPACK.Gen
[NOTE] The file was moved to '488da88d.qua'!
H:\System Volume Information\_restore{879E598B-020E-408B-AC9B-13ABBD7D02C3}\RP91\A0026259.exe
[DETECTION] Is the Trojan horse TR/Crypt.XPACK.Gen
[NOTE] The file was moved to '490481de.qua'!
H:\System Volume Information\_restore{879E598B-020E-408B-AC9B-13ABBD7D02C3}\RP91\A0026260.exe
[DETECTION] Is the Trojan horse TR/Crypt.XPACK.Gen
[NOTE] The file was moved to '488da88f.qua'!
H:\System Volume Information\_restore{879E598B-020E-408B-AC9B-13ABBD7D02C3}\RP91\A0026261.exe
[DETECTION] Is the Trojan horse TR/Crypt.XPACK.Gen
[NOTE] The file was moved to '488da81a.qua'!
H:\System Volume Information\_restore{879E598B-020E-408B-AC9B-13ABBD7D02C3}\RP91\A0026262.exe
[DETECTION] Is the Trojan horse TR/Crypt.XPACK.Gen
[NOTE] The file was moved to '4904814b.qua'!
H:\System Volume Information\_restore{879E598B-020E-408B-AC9B-13ABBD7D02C3}\RP91\A0026264.dll
[DETECTION] Is the Trojan horse TR/Vundo.Gen
[NOTE] The file was moved to '490481c0.qua'!
H:\System Volume Information\_restore{879E598B-020E-408B-AC9B-13ABBD7D02C3}\RP91\A0026265.exe
[DETECTION] Is the Trojan horse TR/Crypt.XPACK.Gen
[NOTE] The file was moved to '488da891.qua'!
H:\System Volume Information\_restore{879E598B-020E-408B-AC9B-13ABBD7D02C3}\RP91\A0026266.exe
[DETECTION] Is the Trojan horse TR/Crypt.XPACK.Gen
[NOTE] The file was moved to '488da81c.qua'!
H:\System Volume Information\_restore{879E598B-020E-408B-AC9B-13ABBD7D02C3}\RP91\A0026267.dll
[DETECTION] Is the Trojan horse TR/Vundo.Gen
[NOTE] The file was moved to '4904814d.qua'!
H:\System Volume Information\_restore{879E598B-020E-408B-AC9B-13ABBD7D02C3}\RP91\A0026268.exe
[DETECTION] Is the Trojan horse TR/Crypt.XPACK.Gen
[NOTE] The file was moved to '488da81e.qua'!
H:\System Volume Information\_restore{879E598B-020E-408B-AC9B-13ABBD7D02C3}\RP91\A0026269.exe
[DETECTION] Is the Trojan horse TR/Crypt.XPACK.Gen
[NOTE] The file was moved to '490481c2.qua'!
H:\System Volume Information\_restore{879E598B-020E-408B-AC9B-13ABBD7D02C3}\RP91\A0026270.exe
[DETECTION] Is the Trojan horse TR/Crypt.XPACK.Gen
[NOTE] The file was moved to '488da893.qua'!
H:\System Volume Information\_restore{879E598B-020E-408B-AC9B-13ABBD7D02C3}\RP91\A0026271.exe
[DETECTION] Is the Trojan horse TR/Crypt.XPACK.Gen
[NOTE] The file was moved to '490481c4.qua'!
H:\System Volume Information\_restore{879E598B-020E-408B-AC9B-13ABBD7D02C3}\RP91\A0026272.exe
[DETECTION] Is the Trojan horse TR/Crypt.XPACK.Gen
[NOTE] The file was moved to '4904814f.qua'!
H:\System Volume Information\_restore{879E598B-020E-408B-AC9B-13ABBD7D02C3}\RP91\A0026273.dll
[DETECTION] Is the Trojan horse TR/Vundo.Gen
[NOTE] The file was moved to '488da800.qua'!
H:\System Volume Information\_restore{879E598B-020E-408B-AC9B-13ABBD7D02C3}\RP91\A0026274.exe
[DETECTION] Is the Trojan horse TR/Crypt.XPACK.Gen
[NOTE] The file was moved to '49048151.qua'!
H:\System Volume Information\_restore{879E598B-020E-408B-AC9B-13ABBD7D02C3}\RP91\A0026275.exe
[DETECTION] Is the Trojan horse TR/Crypt.XPACK.Gen
[NOTE] The file was moved to '488da895.qua'!
H:\System Volume Information\_restore{879E598B-020E-408B-AC9B-13ABBD7D02C3}\RP91\A0026276.exe
[DETECTION] Is the Trojan horse TR/Crypt.XPACK.Gen
[NOTE] The file was moved to '490481c6.qua'!
H:\System Volume Information\_restore{879E598B-020E-408B-AC9B-13ABBD7D02C3}\RP91\A0026277.exe
[DETECTION] Is the Trojan horse TR/Crypt.XPACK.Gen
[NOTE] The file was moved to '488da897.qua'!
H:\System Volume Information\_restore{879E598B-020E-408B-AC9B-13ABBD7D02C3}\RP91\A0026283.exe
[DETECTION] Is the Trojan horse TR/Crypt.XPACK.Gen
[NOTE] The file was moved to '490481c8.qua'!
H:\System Volume Information\_restore{879E598B-020E-408B-AC9B-13ABBD7D02C3}\RP91\A0026284.dll
[DETECTION] Is the Trojan horse TR/Vundo.Gen
[NOTE] The file was moved to '488da880.qua'!
H:\System Volume Information\_restore{879E598B-020E-408B-AC9B-13ABBD7D02C3}\RP91\A0026285.exe
[DETECTION] Is the Trojan horse TR/Crypt.XPACK.Gen
[NOTE] The file was moved to '490481d1.qua'!
H:\System Volume Information\_restore{879E598B-020E-408B-AC9B-13ABBD7D02C3}\RP91\A0026286.dll
[DETECTION] Is the Trojan horse TR/Vundo.Gen
[NOTE] The file was moved to '488da882.qua'!
H:\System Volume Information\_restore{879E598B-020E-408B-AC9B-13ABBD7D02C3}\RP91\A0026287.exe
[DETECTION] Is the Trojan horse TR/Crypt.XPACK.Gen
[NOTE] The file was moved to '488da899.qua'!
H:\System Volume Information\_restore{879E598B-020E-408B-AC9B-13ABBD7D02C3}\RP91\A0026288.exe
[DETECTION] Is the Trojan horse TR/Crypt.XPACK.Gen
[NOTE] The file was moved to '490481ca.qua'!
H:\System Volume Information\_restore{879E598B-020E-408B-AC9B-13ABBD7D02C3}\RP91\A0026289.exe
[DETECTION] Is the Trojan horse TR/Crypt.XPACK.Gen
[NOTE] The file was moved to '488da89b.qua'!
H:\System Volume Information\_restore{879E598B-020E-408B-AC9B-13ABBD7D02C3}\RP91\A0026290.exe
[DETECTION] Is the Trojan horse TR/Crypt.XPACK.Gen
[NOTE] The file was moved to '490481cc.qua'!
H:\System Volume Information\_restore{879E598B-020E-408B-AC9B-13ABBD7D02C3}\RP91\A0026291.exe
[DETECTION] Is the Trojan horse TR/Crypt.XPACK.Gen
[NOTE] The file was moved to '490481d3.qua'!
H:\System Volume Information\_restore{879E598B-020E-408B-AC9B-13ABBD7D02C3}\RP91\A0026292.exe
[DETECTION] Is the Trojan horse TR/Crypt.XPACK.Gen
[NOTE] The file was moved to '49048f54.qua'!
H:\System Volume Information\_restore{879E598B-020E-408B-AC9B-13ABBD7D02C3}\RP91\A0026293.exe
[DETECTION] Is the Trojan horse TR/Crypt.XPACK.Gen
[NOTE] The file was moved to '49048f56.qua'!
H:\System Volume Information\_restore{879E598B-020E-408B-AC9B-13ABBD7D02C3}\RP91\A0026294.exe
[DETECTION] Is the Trojan horse TR/Crypt.XPACK.Gen
[NOTE] The file was moved to '49048f58.qua'!
H:\System Volume Information\_restore{879E598B-020E-408B-AC9B-13ABBD7D02C3}\RP91\A0026295.exe
[DETECTION] Is the Trojan horse TR/Crypt.XPACK.Gen
[NOTE] The file was moved to '488da884.qua'!
H:\System Volume Information\_restore{879E598B-020E-408B-AC9B-13ABBD7D02C3}\RP91\A0026296.exe
[DETECTION] Is the Trojan horse TR/Crypt.XPACK.Gen
[NOTE] The file was moved to '49048f55.qua'!
H:\System Volume Information\_restore{879E598B-020E-408B-AC9B-13ABBD7D02C3}\RP91\A0026298.exe
[DETECTION] Is the Trojan horse TR/Crypt.XPACK.Gen
[NOTE] The file was moved to '488da886.qua'!
H:\System Volume Information\_restore{879E598B-020E-408B-AC9B-13ABBD7D02C3}\RP91\A0026299.exe
[DETECTION] Is the Trojan horse TR/Crypt.XPACK.Gen
[NOTE] The file was moved to '49048f5a.qua'!
H:\System Volume Information\_restore{879E598B-020E-408B-AC9B-13ABBD7D02C3}\RP91\A0026300.exe
[DETECTION] Is the Trojan horse TR/Crypt.XPACK.Gen
[NOTE] The file was moved to '49048f5c.qua'!
H:\System Volume Information\_restore{879E598B-020E-408B-AC9B-13ABBD7D02C3}\RP91\A0026301.exe
[DETECTION] Is the Trojan horse TR/Crypt.XPACK.Gen
[NOTE] The file was moved to '49048f5e.qua'!
H:\System Volume Information\_restore{879E598B-020E-408B-AC9B-13ABBD7D02C3}\RP91\A0026302.exe
[DETECTION] Is the Trojan horse TR/Crypt.XPACK.Gen
[NOTE] The file was moved to '49048f40.qua'!
H:\System Volume Information\_restore{879E598B-020E-408B-AC9B-13ABBD7D02C3}\RP91\A0026368.exe
[DETECTION] Contains detection pattern of the dropper DR/WhenU.A.112
[NOTE] The file was moved to '49048f57.qua'!
H:\System Volume Information\_restore{879E598B-020E-408B-AC9B-13ABBD7D02C3}\RP91\A0026369.exe
[0] Archive type: ZIP SFX (self extracting)
--> setup.exe
[DETECTION] Is the Trojan horse TR/Drop.Joiner.DV.2
[NOTE] The file was moved to '488da888.qua'!
H:\System Volume Information\_restore{879E598B-020E-408B-AC9B-13ABBD7D02C3}\RP91\A0026370.exe
[DETECTION] Contains detection pattern of the dropper DR/Spy.Delf.FK
[NOTE] The file was moved to '49048f42.qua'!
End of the scan: Saturday, June 21, 2008 21:19
Used time: 2:28:29 min
The scan has been done completely.
15569 Scanning directories
532542 Files were scanned
157 viruses and/or unwanted programs were found
0 Files were classified as suspicious:
0 files were deleted
0 files were repaired
157 files were moved to quarantine
0 files were renamed
5 Files cannot be scanned
532385 Files not concerned
8990 Archives were scanned
5 Warnings
157 Notes
----------------------------------------------------------------
FIRST FULL SCAN WITH AVIRA BEFORE DELETING OLD QUARANTINE
----------------------------------------------------------------
End of the scan: Saturday, June 21, 2008 16:34
Used time: 9:58:39 min
The scan has been done completely.
15699 Scanning directories
539792 Files were scanned
901 viruses and/or unwanted programs were found
8 Files were classified as suspicious:
0 files were deleted
0 files were repaired
21 files were moved to quarantine
0 files were renamed
5 Files cannot be scanned
538891 Files not concerned
10486 Archives were scanned
800 Warnings
21 Notes
----------------------------------------------------------------
2ND FULL SCAN WITH AVIRA AFTER DELETING OLD QUARANTINE
----------------------------------------------------------------
Avira AntiVir Personal
Report file date: Saturday, June 21, 2008 18:50
Scanning for 1349608 virus strains and unwanted programs.
Licensed to: Avira AntiVir PersonalEdition Classic
Serial number: 0000149996-ADJIE-0001
Platform: Windows XP
Windows version: (Service Pack 2) [5.1.2600]
Boot mode: Normally booted
Username: SYSTEM
Computer name: CTV
Version information:
BUILD.DAT : 8.1.00.295 16479 Bytes 4/9/2008 16:24:00
AVSCAN.EXE : 8.1.2.12 311553 Bytes 3/18/2008 15:02:56
AVSCAN.DLL : 8.1.1.0 53505 Bytes 2/7/2008 14:43:37
LUKE.DLL : 8.1.2.9 151809 Bytes 2/28/2008 14:41:23
LUKERES.DLL : 8.1.2.1 12033 Bytes 2/21/2008 14:28:40
ANTIVIR0.VDF : 6.40.0.0 11030528 Bytes 7/18/2007 16:33:34
ANTIVIR1.VDF : 7.0.3.2 5447168 Bytes 3/7/2008 19:08:58
ANTIVIR2.VDF : 7.0.4.195 2546176 Bytes 6/14/2008 04:07:10
ANTIVIR3.VDF : 7.0.4.232 250880 Bytes 6/20/2008 04:07:12
Engineversion : 8.1.0.59
AEVDF.DLL : 8.1.0.5 102772 Bytes 2/25/2008 15:58:21
AESCRIPT.DLL : 8.1.0.44 278907 Bytes 6/21/2008 04:07:25
AESCN.DLL : 8.1.0.22 119157 Bytes 6/21/2008 04:07:24
AERDL.DLL : 8.1.0.20 418165 Bytes 6/21/2008 04:07:23
AEPACK.DLL : 8.1.1.6 364918 Bytes 6/21/2008 04:07:22
AEOFFICE.DLL : 8.1.0.20 192891 Bytes 6/21/2008 04:07:21
AEHEUR.DLL : 8.1.0.32 1274231 Bytes 6/21/2008 04:07:21
AEHELP.DLL : 8.1.0.15 115063 Bytes 6/21/2008 04:07:18
AEGEN.DLL : 8.1.0.29 307573 Bytes 6/21/2008 04:07:17
AEEMU.DLL : 8.1.0.6 430451 Bytes 6/21/2008 04:07:15
AECORE.DLL : 8.1.0.31 168310 Bytes 6/21/2008 04:07:13
AVWINLL.DLL : 1.0.0.7 14593 Bytes 1/23/2008 23:07:53
AVPREF.DLL : 8.0.0.1 25857 Bytes 2/18/2008 16:37:50
AVREP.DLL : 7.0.0.1 155688 Bytes 4/16/2007 19:26:47
AVREG.DLL : 8.0.0.0 30977 Bytes 1/23/2008 23:07:49
AVARKT.DLL : 1.0.0.23 307457 Bytes 2/12/2008 14:29:23
AVEVTLOG.DLL : 8.0.0.11 114945 Bytes 2/28/2008 14:31:31
SQLITE3.DLL : 3.3.17.1 339968 Bytes 1/22/2008 23:28:02
SMTPLIB.DLL : 1.2.0.19 28929 Bytes 1/23/2008 23:08:39
NETNT.DLL : 8.0.0.1 7937 Bytes 1/25/2008 18:05:10
RCIMAGE.DLL : 8.0.0.35 2371841 Bytes 3/10/2008 20:37:25
RCTEXT.DLL : 8.0.32.0 86273 Bytes 3/6/2008 18:02:11
Configuration settings for the scan:
Jobname..........................: Complete system scan
Configuration file...............: c:\program files\avira\antivir personaledition classic\sysscan.avp
Logging..........................: low
Primary action...................: interactive
Secondary action.................: ignore
Scan master boot sector..........: on
Scan boot sector.................: on
Boot sectors.....................: C:, E:, H:,
Scan memory......................: on
Process scan.....................: on
Scan registry....................: on
Search for rootkits..............: off
Scan all files...................: Intelligent file selection
Scan archives....................: on
Recursion depth..................: 20
Smart extensions.................: on
Macro heuristic..................: on
File heuristic...................: medium
Start of the scan: Saturday, June 21, 2008 18:50
The scan of running processes will be started
Scan process 'avwsc.exe' - '1' Module(s) have been scanned
Scan process 'avscan.exe' - '1' Module(s) have been scanned
Scan process 'AcroRd32.exe' - '1' Module(s) have been scanned
Scan process 'notepad.exe' - '1' Module(s) have been scanned
Scan process 'explorer.exe' - '1' Module(s) have been scanned
Scan process 'taskmgr.exe' - '1' Module(s) have been scanned
Scan process 'avgnt.exe' - '1' Module(s) have been scanned
Scan process 'oaui.exe' - '0' Module(s) have been scanned
Scan process 'CTSysVol.exe' - '1' Module(s) have been scanned
Scan process 'igfxtray.exe' - '1' Module(s) have been scanned
Scan process 'explorer.exe' - '1' Module(s) have been scanned
Scan process 'sched.exe' - '1' Module(s) have been scanned
Scan process 'oasrv.exe' - '0' Module(s) have been scanned
Scan process 'svchost.exe' - '1' Module(s) have been scanned
Scan process 'svchost.exe' - '1' Module(s) have been scanned
Scan process 'svchost.exe' - '1' Module(s) have been scanned
Scan process 'svchost.exe' - '1' Module(s) have been scanned
Scan process 'svchost.exe' - '1' Module(s) have been scanned
Scan process 'lsass.exe' - '1' Module(s) have been scanned
Scan process 'services.exe' - '1' Module(s) have been scanned
Scan process 'winlogon.exe' - '1' Module(s) have been scanned
Scan process 'csrss.exe' - '1' Module(s) have been scanned
Scan process 'smss.exe' - '1' Module(s) have been scanned
21 processes with 21 modules were scanned
Starting master boot sector scan:
Master boot sector HD0
[INFO] No virus was found!
Master boot sector HD1
[INFO] No virus was found!
Master boot sector HD2
[INFO] No virus was found!
Start scanning boot sectors:
Boot sector 'C:\'
[INFO] No virus was found!
Boot sector 'E:\'
[INFO] No virus was found!
Boot sector 'H:\'
[INFO] No virus was found!
Starting to scan the registry.
The registry was scanned ( '18' files ).
Starting the file scan:
Begin scan in 'C:\'
C:\pagefile.sys
[WARNING] The file could not be opened!
C:\WINDOWS\Installer\{1ad4b29b-ff03-42c5-9803-969fdcb47c9d}\zip.dll
[DETECTION] Is the Trojan horse TR/Shell.Eviell
[NOTE] The file was moved to '48cd9f4b.qua'!
C:\WINDOWS\Installer\{2931ea2a-6692-45ed-8180-2ffc3378c658}\zip.dll
[DETECTION] Is the Trojan horse TR/Shell.Eviell
[NOTE] The file was moved to '48cd9f54.qua'!
C:\WINDOWS\Installer\{29e9372a-d7d2-4003-91ea-da7e38635700}\zip.dll
[DETECTION] Is the Trojan horse TR/Shell.Eviell
[NOTE] The file was moved to '48cd9f55.qua'!
C:\WINDOWS\Installer\{47a73001-2c42-45e0-95ee-64c647a0c7b9}\zip.dll
[DETECTION] Is the Trojan horse TR/Shell.Eviell
[NOTE] The file was moved to '4944b606.qua'!
C:\WINDOWS\Installer\{53b4046e-0116-4d23-b5ce-a76c1a758511}\zip.dll
[DETECTION] Is the Trojan horse TR/Shell.Eviell
[NOTE] The file was moved to '48cd9f56.qua'!
C:\WINDOWS\Installer\{6ea97d2b-af03-4653-9ca0-ff61d00d5cbf}\zip.dll
[DETECTION] Is the Trojan horse TR/Shell.Eviell
[NOTE] The file was moved to '4944b607.qua'!
C:\WINDOWS\Installer\{74fdc03e-393c-4c0d-806a-19b427bfd6c8}\zip.dll
[DETECTION] Is the Trojan horse TR/Shell.Eviell
[NOTE] The file was moved to '48cd9f57.qua'!
C:\WINDOWS\Installer\{ac633de7-14d4-4297-8e5f-613b933fb5ab}\KbdSetup.dll
[DETECTION] Is the Trojan horse TR/Shell.Eviell
[NOTE] The file was moved to '48c19f53.qua'!
C:\WINDOWS\Installer\{d5922084-f076-4b91-abc8-9390f0f76e02}\zip.dll
[DETECTION] Is the Trojan horse TR/Shell.Eviell
[NOTE] The file was moved to '48cd9f5b.qua'!
C:\WINDOWS\Installer\{e82124db-dadc-4f41-977a-12c725dd7cc0}\DrvAvp.dll
[DETECTION] Is the Trojan horse TR/Shell.Eviell
[NOTE] The file was moved to '48d39f64.qua'!
C:\WINDOWS\Installer\{ffec9829-e3c4-4c07-ae34-3eadf8b7a6bf}\zip.dll
[DETECTION] Is the Trojan horse TR/Shell.Eviell
[NOTE] The file was moved to '4944b60c.qua'!
C:\WINDOWS\system32\drivers\OADriver.sys
[WARNING] The file could not be opened!
C:\WINDOWS\system32\drivers\OAmon.sys
[WARNING] The file could not be opened!
C:\WINDOWS\system32\drivers\oanet.sys
[WARNING] The file could not be opened!
C:\_OTMoveIt\MovedFiles\06202008_062618\WINDOWS\Installer\{0bfb355f-1157-4832-81f7-b2da5b3957c7}\zip.dll
[DETECTION] Is the Trojan horse TR/Shell.Eviell
[NOTE] The file was moved to '48cda0e4.qua'!
C:\_OTMoveIt\MovedFiles\06202008_062618\WINDOWS\Installer\{334ff6d0-523d-4f68-828b-09d34d3a6b9a}\zip.dll
[DETECTION] Is the Trojan horse TR/Shell.Eviell
[NOTE] The file was moved to '4941e0d5.qua'!
C:\_OTMoveIt\MovedFiles\06202008_062618\WINDOWS\Installer\{8dceb2ba-45a6-4b83-8580-51cb2b532546}\zip.dll
[DETECTION] Is the Trojan horse TR/Shell.Eviell
[NOTE] The file was moved to '48cda0e6.qua'!
C:\_OTMoveIt\MovedFiles\06202008_062618\WINDOWS\Installer\{9d00dc2b-b071-4706-876d-4bac586f2ab7}\zip.dll
[DETECTION] Is the Trojan horse TR/Shell.Eviell
[NOTE] The file was moved to '48cda0e5.qua'!
C:\_OTMoveIt\MovedFiles\06202008_062618\WINDOWS\Installer\{ac234da1-fa9d-4cff-850c-b9d5e6659f1b}\zip.dll
[DETECTION] Is the Trojan horse TR/Shell.Eviell
[NOTE] The file was moved to '4941e0d6.qua'!
Begin scan in 'E:\' <DSK2_VOL1>
E:\pagefile.sys
[WARNING] The file could not be opened!
E:\System Volume Information\_restore{879E598B-020E-408B-AC9B-13ABBD7D02C3}\RP91\A0026306.exe
[DETECTION] Is the Trojan horse TR/Drop.Halloween.A
[NOTE] The file was moved to '488da33f.qua'!
E:\System Volume Information\_restore{879E598B-020E-408B-AC9B-13ABBD7D02C3}\RP91\A0026307.exe
[DETECTION] Is the Trojan horse TR/Drop.Halloween.A
[NOTE] The file was moved to '488da340.qua'!
Begin scan in 'H:\' <Maxtor 300GB>
H:\C Program Backup Virus Crash 13mar08\CuteComp.exe
[DETECTION] Contains detection pattern of the dropper DR/WhenU.A.112
[NOTE] The file was moved to '48d1a3c0.qua'!
H:\C Program Backup Virus Crash 13mar08\SP-SpookySounds_Install.exe
[0] Archive type: ZIP SFX (self extracting)
--> setup.exe
[DETECTION] Is the Trojan horse TR/Drop.Joiner.DV.2
[NOTE] The file was moved to '488aa3ab.qua'!
H:\C Program Backup Virus Crash 13mar08\Robot Voices\male-voice-american.exe
[DETECTION] Contains detection pattern of the dropper DR/Spy.Delf.FK
[NOTE] The file was moved to '48c9a516.qua'!
H:\System Volume Information\_restore{879E598B-020E-408B-AC9B-13ABBD7D02C3}\RP59\A0016208.dll
[DETECTION] Contains detection pattern of the worm WORM/Locksky.CM.1
[NOTE] The file was moved to '488da85b.qua'!
H:\System Volume Information\_restore{879E598B-020E-408B-AC9B-13ABBD7D02C3}\RP91\A0026154.exe
[DETECTION] Is the Trojan horse TR/Crypt.XPACK.Gen
[NOTE] The file was moved to '488da85d.qua'!
H:\System Volume Information\_restore{879E598B-020E-408B-AC9B-13ABBD7D02C3}\RP91\A0026155.dll
[DETECTION] Is the Trojan horse TR/Vundo.Gen
[NOTE] The file was moved to '4904810e.qua'!
H:\System Volume Information\_restore{879E598B-020E-408B-AC9B-13ABBD7D02C3}\RP91\A0026156.exe
[DETECTION] Is the Trojan horse TR/Crypt.XPACK.Gen
[NOTE] The file was moved to '488da85e.qua'!
H:\System Volume Information\_restore{879E598B-020E-408B-AC9B-13ABBD7D02C3}\RP91\A0026157.sys
[DETECTION] Contains detection pattern of the worm WORM/Locksky.CM.1
[NOTE] The file was moved to '4904810f.qua'!
H:\System Volume Information\_restore{879E598B-020E-408B-AC9B-13ABBD7D02C3}\RP91\A0026158.dll
[DETECTION] Is the Trojan horse TR/Vundo.Gen
[NOTE] The file was moved to '488da840.qua'!
H:\System Volume Information\_restore{879E598B-020E-408B-AC9B-13ABBD7D02C3}\RP91\A0026159.dll
[DETECTION] Contains detection pattern of the worm WORM/Locksky.CM.1
[NOTE] The file was moved to '49048111.qua'!
H:\System Volume Information\_restore{879E598B-020E-408B-AC9B-13ABBD7D02C3}\RP91\A0026160.exe
[DETECTION] Is the Trojan horse TR/Crypt.XPACK.Gen
[NOTE] The file was moved to '488da85f.qua'!
H:\System Volume Information\_restore{879E598B-020E-408B-AC9B-13ABBD7D02C3}\RP91\A0026161.dll
[DETECTION] Is the Trojan horse TR/Vundo.Gen
[NOTE] The file was moved to '49048130.qua'!
H:\System Volume Information\_restore{879E598B-020E-408B-AC9B-13ABBD7D02C3}\RP91\A0026162.exe
[DETECTION] Is the Trojan horse TR/Crypt.XPACK.Gen
[NOTE] The file was moved to '488da861.qua'!
H:\System Volume Information\_restore{879E598B-020E-408B-AC9B-13ABBD7D02C3}\RP91\A0026163.exe
[DETECTION] Is the Trojan horse TR/Crypt.XPACK.Gen
[NOTE] The file was moved to '49048132.qua'!
H:\System Volume Information\_restore{879E598B-020E-408B-AC9B-13ABBD7D02C3}\RP91\A0026164.sys
[DETECTION] Contains detection pattern of the worm WORM/Locksky.CM.1
[NOTE] The file was moved to '488da860.qua'!
H:\System Volume Information\_restore{879E598B-020E-408B-AC9B-13ABBD7D02C3}\RP91\A0026165.dll
[DETECTION] Is the Trojan horse TR/Vundo.Gen
[NOTE] The file was moved to '49048131.qua'!
H:\System Volume Information\_restore{879E598B-020E-408B-AC9B-13ABBD7D02C3}\RP91\A0026166.dll
[DETECTION] Is the Trojan horse TR/Crypt.XPACK.Gen
[NOTE] The file was moved to '488da862.qua'!
H:\System Volume Information\_restore{879E598B-020E-408B-AC9B-13ABBD7D02C3}\RP91\A0026167.exe
[DETECTION] Is the Trojan horse TR/Crypt.XPACK.Gen
[NOTE] The file was moved to '488da863.qua'!
H:\System Volume Information\_restore{879E598B-020E-408B-AC9B-13ABBD7D02C3}\RP91\A0026168.exe
[DETECTION] Is the Trojan horse TR/Crypt.XPACK.Gen
[NOTE] The file was moved to '49048134.qua'!
H:\System Volume Information\_restore{879E598B-020E-408B-AC9B-13ABBD7D02C3}\RP91\A0026169.dll
[DETECTION] Is the Trojan horse TR/Vundo.Gen
[NOTE] The file was moved to '488da865.qua'!
H:\System Volume Information\_restore{879E598B-020E-408B-AC9B-13ABBD7D02C3}\RP91\A0026170.exe
[DETECTION] Is the Trojan horse TR/Crypt.XPACK.Gen
[NOTE] The file was moved to '49048136.qua'!
H:\System Volume Information\_restore{879E598B-020E-408B-AC9B-13ABBD7D02C3}\RP91\A0026171.dll
[DETECTION] Contains detection pattern of the worm WORM/Locksky.CM.1
[NOTE] The file was moved to '49048133.qua'!
H:\System Volume Information\_restore{879E598B-020E-408B-AC9B-13ABBD7D02C3}\RP91\A0026173.sys
[DETECTION] Contains detection pattern of the worm WORM/Locksky.CM.1
[NOTE] The file was moved to '488da864.qua'!
H:\System Volume Information\_restore{879E598B-020E-408B-AC9B-13ABBD7D02C3}\RP91\A0026174.drv
[DETECTION] Contains detection pattern of the worm WORM/Locksky.CM.1
[NOTE] The file was moved to '49048135.qua'!
H:\System Volume Information\_restore{879E598B-020E-408B-AC9B-13ABBD7D02C3}\RP91\A0026175.drv
[DETECTION] Contains detection pattern of the worm WORM/Locksky.CM.1
[NOTE] The file was moved to '488da866.qua'!
H:\System Volume Information\_restore{879E598B-020E-408B-AC9B-13ABBD7D02C3}\RP91\A0026176.dll
[DETECTION] Contains detection pattern of the worm WORM/Locksky.CM.1
[NOTE] The file was moved to '488da867.qua'!
H:\System Volume Information\_restore{879E598B-020E-408B-AC9B-13ABBD7D02C3}\RP91\A0026177.dll
[DETECTION] Contains detection pattern of the worm WORM/Locksky.CM.1
[NOTE] The file was moved to '49048138.qua'!
H:\System Volume Information\_restore{879E598B-020E-408B-AC9B-13ABBD7D02C3}\RP91\A0026178.drv
[DETECTION] Contains detection pattern of the worm WORM/Locksky.CM.1
[NOTE] The file was moved to '488da869.qua'!
H:\System Volume Information\_restore{879E598B-020E-408B-AC9B-13ABBD7D02C3}\RP91\A0026181.exe
[DETECTION] Is the Trojan horse TR/Agent.fwi
[NOTE] The file was moved to '4904813a.qua'!
H:\System Volume Information\_restore{879E598B-020E-408B-AC9B-13ABBD7D02C3}\RP91\A0026182.exe
[DETECTION] Is the Trojan horse TR/Agent.fwi
[NOTE] The file was moved to '49048137.qua'!
H:\System Volume Information\_restore{879E598B-020E-408B-AC9B-13ABBD7D02C3}\RP91\A0026183.exe
[DETECTION] Is the Trojan horse TR/Agent.fwi
[NOTE] The file was moved to '488da868.qua'!
H:\System Volume Information\_restore{879E598B-020E-408B-AC9B-13ABBD7D02C3}\RP91\A0026184.exe
[DETECTION] Is the Trojan horse TR/Spy.Agent.aci
[NOTE] The file was moved to '49048139.qua'!
H:\System Volume Information\_restore{879E598B-020E-408B-AC9B-13ABBD7D02C3}\RP91\A0026185.exe
[DETECTION] Is the Trojan horse TR/Agent.fwi
[NOTE] The file was moved to '488da86b.qua'!
H:\System Volume Information\_restore{879E598B-020E-408B-AC9B-13ABBD7D02C3}\RP91\A0026186.exe
[DETECTION] Is the Trojan horse TR/Agent.fwi
[NOTE] The file was moved to '4904813c.qua'!
H:\System Volume Information\_restore{879E598B-020E-408B-AC9B-13ABBD7D02C3}\RP91\A0026187.exe
[DETECTION] Is the Trojan horse TR/Agent.fwi
[NOTE] The file was moved to '488da86a.qua'!
H:\System Volume Information\_restore{879E598B-020E-408B-AC9B-13ABBD7D02C3}\RP91\A0026188.exe
[DETECTION] Is the Trojan horse TR/Agent.fwi
[NOTE] The file was moved to '4904813b.qua'!
H:\System Volume Information\_restore{879E598B-020E-408B-AC9B-13ABBD7D02C3}\RP91\A0026189.exe
[DETECTION] Is the Trojan horse TR/Spy.Agent.aci
[NOTE] The file was moved to '488da86c.qua'!
H:\System Volume Information\_restore{879E598B-020E-408B-AC9B-13ABBD7D02C3}\RP91\A0026190.exe
[DETECTION] Is the Trojan horse TR/Agent.fwi
[NOTE] The file was moved to '488da86d.qua'!
H:\System Volume Information\_restore{879E598B-020E-408B-AC9B-13ABBD7D02C3}\RP91\A0026191.exe
[DETECTION] Is the Trojan horse TR/Agent.fwi
[NOTE] The file was moved to '4904813e.qua'!
H:\System Volume Information\_restore{879E598B-020E-408B-AC9B-13ABBD7D02C3}\RP91\A0026192.exe
[DETECTION] Is the Trojan horse TR/Agent.fwi
[NOTE] The file was moved to '488da86f.qua'!
H:\System Volume Information\_restore{879E598B-020E-408B-AC9B-13ABBD7D02C3}\RP91\A0026193.exe
[DETECTION] Is the Trojan horse TR/Agent.fwi
[NOTE] The file was moved to '49048120.qua'!
H:\System Volume Information\_restore{879E598B-020E-408B-AC9B-13ABBD7D02C3}\RP91\A0026194.exe
[DETECTION] Is the Trojan horse TR/Agent.fwi
[NOTE] The file was moved to '4904813d.qua'!
H:\System Volume Information\_restore{879E598B-020E-408B-AC9B-13ABBD7D02C3}\RP91\A0026195.exe
[DETECTION] Is the Trojan horse TR/Agent.fwi
[NOTE] The file was moved to '488da86e.qua'!
H:\System Volume Information\_restore{879E598B-020E-408B-AC9B-13ABBD7D02C3}\RP91\A0026196.exe
[DETECTION] Is the Trojan horse TR/Agent.fwi
[NOTE] The file was moved to '4904813f.qua'!
H:\System Volume Information\_restore{879E598B-020E-408B-AC9B-13ABBD7D02C3}\RP91\A0026197.exe
[DETECTION] Is the Trojan horse TR/Agent.fwi
[NOTE] The file was moved to '488da810.qua'!
H:\System Volume Information\_restore{879E598B-020E-408B-AC9B-13ABBD7D02C3}\RP91\A0026198.exe
[DETECTION] Is the Trojan horse TR/Agent.fwi
[NOTE] The file was moved to '488da871.qua'!
H:\System Volume Information\_restore{879E598B-020E-408B-AC9B-13ABBD7D02C3}\RP91\A0026199.exe
[DETECTION] Is the Trojan horse TR/Shell.Eviell
[NOTE] The file was moved to '49048122.qua'!
H:\System Volume Information\_restore{879E598B-020E-408B-AC9B-13ABBD7D02C3}\RP91\A0026200.exe
[DETECTION] Is the Trojan horse TR/Spy.Agent.aci
[NOTE] The file was moved to '488da873.qua'!
H:\System Volume Information\_restore{879E598B-020E-408B-AC9B-13ABBD7D02C3}\RP91\A0026201.exe
[DETECTION] Is the Trojan horse TR/Agent.fwi
[NOTE] The file was moved to '49048141.qua'!
H:\System Volume Information\_restore{879E598B-020E-408B-AC9B-13ABBD7D02C3}\RP91\A0026202.exe
[DETECTION] Is the Trojan horse TR/Agent.fwi
[NOTE] The file was moved to '488da812.qua'!
H:\System Volume Information\_restore{879E598B-020E-408B-AC9B-13ABBD7D02C3}\RP91\A0026203.exe
--> Object
[1] Archive type: RSRC
--> Object
[DETECTION] Is the Trojan horse TR/Click.Agent.WD
[NOTE] The file was moved to '49048143.qua'!
H:\System Volume Information\_restore{879E598B-020E-408B-AC9B-13ABBD7D02C3}\RP91\A0026207.exe
[DETECTION] Is the Trojan horse TR/Crypt.XDR.Gen
[NOTE] The file was moved to '49048124.qua'!
H:\System Volume Information\_restore{879E598B-020E-408B-AC9B-13ABBD7D02C3}\RP91\A0026209.exe
[DETECTION] Is the Trojan horse TR/Crypt.XPACK.Gen
[NOTE] The file was moved to '488da814.qua'!
H:\System Volume Information\_restore{879E598B-020E-408B-AC9B-13ABBD7D02C3}\RP91\A0026210.exe
[DETECTION] Is the Trojan horse TR/Crypt.XPACK.Gen
[NOTE] The file was moved to '49048145.qua'!
H:\System Volume Information\_restore{879E598B-020E-408B-AC9B-13ABBD7D02C3}\RP91\A0026214.exe
[DETECTION] Is the Trojan horse TR/Crypt.XDR.Gen
[NOTE] The file was moved to '488da875.qua'!
H:\System Volume Information\_restore{879E598B-020E-408B-AC9B-13ABBD7D02C3}\RP91\A0026215.exe
[DETECTION] Is the Trojan horse TR/Dldr.Adload.MA.3
[NOTE] The file was moved to '49048126.qua'!
H:\System Volume Information\_restore{879E598B-020E-408B-AC9B-13ABBD7D02C3}\RP91\A0026216.exe
[DETECTION] Is the Trojan horse TR/Crypt.XPACK.Gen
[NOTE] The file was moved to '488da877.qua'!
H:\System Volume Information\_restore{879E598B-020E-408B-AC9B-13ABBD7D02C3}\RP91\A0026217.exe
[DETECTION] Is the Trojan horse TR/Crypt.XPACK.Gen
[NOTE] The file was moved to '49048128.qua'!
H:\System Volume Information\_restore{879E598B-020E-408B-AC9B-13ABBD7D02C3}\RP91\A0026218.dll
[DETECTION] Is the Trojan horse TR/Vundo.Gen
[NOTE] The file was moved to '488da816.qua'!
H:\System Volume Information\_restore{879E598B-020E-408B-AC9B-13ABBD7D02C3}\RP91\A0026219.dll
[DETECTION] Is the Trojan horse TR/Vundo.Gen
[NOTE] The file was moved to '49048147.qua'!
H:\System Volume Information\_restore{879E598B-020E-408B-AC9B-13ABBD7D02C3}\RP91\A0026220.exe
[DETECTION] Is the Trojan horse TR/Crypt.XPACK.Gen
[NOTE] The file was moved to '488da818.qua'!
H:\System Volume Information\_restore{879E598B-020E-408B-AC9B-13ABBD7D02C3}\RP91\A0026221.drv
[DETECTION] Contains detection pattern of the worm WORM/Locksky.CM.1
[NOTE] The file was moved to '49048149.qua'!
H:\System Volume Information\_restore{879E598B-020E-408B-AC9B-13ABBD7D02C3}\RP91\A0026222.drv
[DETECTION] Contains detection pattern of the worm WORM/Locksky.CM.1
[NOTE] The file was moved to '488da879.qua'!
H:\System Volume Information\_restore{879E598B-020E-408B-AC9B-13ABBD7D02C3}\RP91\A0026223.dll
[DETECTION] Contains detection pattern of the worm WORM/Locksky.CM.1
[NOTE] The file was moved to '4904812a.qua'!
H:\System Volume Information\_restore{879E598B-020E-408B-AC9B-13ABBD7D02C3}\RP91\A0026224.dll
[DETECTION] Is the Trojan horse TR/Vundo.Gen
[NOTE] The file was moved to '488da87b.qua'!
H:\System Volume Information\_restore{879E598B-020E-408B-AC9B-13ABBD7D02C3}\RP91\A0026225.exe
[DETECTION] Is the Trojan horse TR/Crypt.XPACK.Gen
[NOTE] The file was moved to '4904812c.qua'!
H:\System Volume Information\_restore{879E598B-020E-408B-AC9B-13ABBD7D02C3}\RP91\A0026226.dll
[DETECTION] Contains detection pattern of the worm WORM/Locksky.CM.1
[NOTE] The file was moved to '488da870.qua'!
H:\System Volume Information\_restore{879E598B-020E-408B-AC9B-13ABBD7D02C3}\RP91\A0026227.dll
[DETECTION] Is the Trojan horse TR/Vundo.Gen
[NOTE] The file was moved to '49048121.qua'!
H:\System Volume Information\_restore{879E598B-020E-408B-AC9B-13ABBD7D02C3}\RP91\A0026228.dll
[DETECTION] Is the Trojan horse TR/Vundo.Gen
[NOTE] The file was moved to '488da872.qua'!
H:\System Volume Information\_restore{879E598B-020E-408B-AC9B-13ABBD7D02C3}\RP91\A0026229.dll
[DETECTION] Is the Trojan horse TR/Vundo.Gen
[NOTE] The file was moved to '49048123.qua'!
H:\System Volume Information\_restore{879E598B-020E-408B-AC9B-13ABBD7D02C3}\RP91\A0026230.exe
[DETECTION] Is the Trojan horse TR/Crypt.XPACK.Gen
[NOTE] The file was moved to '488da87d.qua'!
H:\System Volume Information\_restore{879E598B-020E-408B-AC9B-13ABBD7D02C3}\RP91\A0026231.dll
[DETECTION] Is the Trojan horse TR/Downloader.Gen
[NOTE] The file was moved to '4904812e.qua'!
H:\System Volume Information\_restore{879E598B-020E-408B-AC9B-13ABBD7D02C3}\RP91\A0026232.dll
[DETECTION] Contains detection pattern of the worm WORM/Locksky.CM.1
[NOTE] The file was moved to '488da87f.qua'!
H:\System Volume Information\_restore{879E598B-020E-408B-AC9B-13ABBD7D02C3}\RP91\A0026233.drv
[DETECTION] Contains detection pattern of the worm WORM/Locksky.CM.1
[NOTE] The file was moved to '490481d0.qua'!
H:\System Volume Information\_restore{879E598B-020E-408B-AC9B-13ABBD7D02C3}\RP91\A0026234.exe
[DETECTION] Is the Trojan horse TR/Crypt.XPACK.Gen
[NOTE] The file was moved to '488da874.qua'!
H:\System Volume Information\_restore{879E598B-020E-408B-AC9B-13ABBD7D02C3}\RP91\A0026235.exe
[DETECTION] Is the Trojan horse TR/Crypt.XPACK.Gen
[NOTE] The file was moved to '49048125.qua'!
H:\System Volume Information\_restore{879E598B-020E-408B-AC9B-13ABBD7D02C3}\RP91\A0026236.dll
[DETECTION] Is the Trojan horse TR/Vundo.Gen
[NOTE] The file was moved to '488da876.qua'!
H:\System Volume Information\_restore{879E598B-020E-408B-AC9B-13ABBD7D02C3}\RP91\A0026237.drv
[DETECTION] Contains detection pattern of the worm WORM/Locksky.CM.1
[NOTE] The file was moved to '49048127.qua'!
H:\System Volume Information\_restore{879E598B-020E-408B-AC9B-13ABBD7D02C3}\RP91\A0026238.dll
[DETECTION] Is the Trojan horse TR/Vundo.Gen
[NOTE] The file was moved to '488da881.qua'!
H:\System Volume Information\_restore{879E598B-020E-408B-AC9B-13ABBD7D02C3}\RP91\A0026239.exe
[DETECTION] Is the Trojan horse TR/Crypt.XPACK.Gen
[NOTE] The file was moved to '490481d2.qua'!
H:\System Volume Information\_restore{879E598B-020E-408B-AC9B-13ABBD7D02C3}\RP91\A0026240.sys
[DETECTION] Contains detection pattern of the worm WORM/Locksky.CM.1
[NOTE] The file was moved to '488da883.qua'!
H:\System Volume Information\_restore{879E598B-020E-408B-AC9B-13ABBD7D02C3}\RP91\A0026241.dll
[DETECTION] Is the Trojan horse TR/Vundo.Gen
[NOTE] The file was moved to '490481d4.qua'!
H:\System Volume Information\_restore{879E598B-020E-408B-AC9B-13ABBD7D02C3}\RP91\A0026242.exe
[DETECTION] Is the Trojan horse TR/Crypt.XPACK.Gen
[NOTE] The file was moved to '488da878.qua'!
H:\System Volume Information\_restore{879E598B-020E-408B-AC9B-13ABBD7D02C3}\RP91\A0026243.exe
[DETECTION] Is the Trojan horse TR/Crypt.XPACK.Gen
[NOTE] The file was moved to '49048129.qua'!
H:\System Volume Information\_restore{879E598B-020E-408B-AC9B-13ABBD7D02C3}\RP91\A0026244.exe
[DETECTION] Contains detection pattern of the worm WORM/Socks.C
[NOTE] The file was moved to '488da87a.qua'!
H:\System Volume Information\_restore{879E598B-020E-408B-AC9B-13ABBD7D02C3}\RP91\A0026245.exe
[DETECTION] Is the Trojan horse TR/Hijacker.Gen
[NOTE] The file was moved to '488da885.qua'!
H:\System Volume Information\_restore{879E598B-020E-408B-AC9B-13ABBD7D02C3}\RP91\A0026246.exe
[DETECTION] Is the Trojan horse TR/Dldr.Small.svf
[NOTE] The file was moved to '490481d6.qua'!
H:\System Volume Information\_restore{879E598B-020E-408B-AC9B-13ABBD7D02C3}\RP91\A0026247.exe
[DETECTION] Is the Trojan horse TR/Pakes.cif
[NOTE] The file was moved to '488da887.qua'!
H:\System Volume Information\_restore{879E598B-020E-408B-AC9B-13ABBD7D02C3}\RP91\A0026248.exe
[DETECTION] Is the Trojan horse TR/Peed.A.41
[NOTE] The file was moved to '4904812b.qua'!
H:\System Volume Information\_restore{879E598B-020E-408B-AC9B-13ABBD7D02C3}\RP91\A0026249.exe
[DETECTION] Is the Trojan horse TR/Clicker.Agent.TP
[NOTE] The file was moved to '488da87c.qua'!
H:\System Volume Information\_restore{879E598B-020E-408B-AC9B-13ABBD7D02C3}\RP91\A0026250.exe
[DETECTION] Is the Trojan horse TR/Crypt.XPACK.Gen
[NOTE] The file was moved to '490481d8.qua'!
H:\System Volume Information\_restore{879E598B-020E-408B-AC9B-13ABBD7D02C3}\RP91\A0026251.exe
[DETECTION] Is the Trojan horse TR/Crypt.XPACK.Gen
[NOTE] The file was moved to '488da889.qua'!
H:\System Volume Information\_restore{879E598B-020E-408B-AC9B-13ABBD7D02C3}\RP91\A0026252.dll
[DETECTION] Contains detection pattern of the worm WORM/Locksky.CM.1
[NOTE] The file was moved to '490481da.qua'!
H:\System Volume Information\_restore{879E598B-020E-408B-AC9B-13ABBD7D02C3}\RP91\A0026253.exe
[DETECTION] Is the Trojan horse TR/Crypt.XPACK.Gen
[NOTE] The file was moved to '488da88b.qua'!
H:\System Volume Information\_restore{879E598B-020E-408B-AC9B-13ABBD7D02C3}\RP91\A0026254.exe
[DETECTION] Is the Trojan horse TR/Crypt.XPACK.Gen
[NOTE] The file was moved to '4904812d.qua'!
H:\System Volume Information\_restore{879E598B-020E-408B-AC9B-13ABBD7D02C3}\RP91\A0026255.exe
[DETECTION] Is the Trojan horse TR/Crypt.XPACK.Gen
[NOTE] The file was moved to '488da87e.qua'!
H:\System Volume Information\_restore{879E598B-020E-408B-AC9B-13ABBD7D02C3}\RP91\A0026256.exe
[DETECTION] Is the Trojan horse TR/Crypt.XPACK.Gen
[NOTE] The file was moved to '4904812f.qua'!
H:\System Volume Information\_restore{879E598B-020E-408B-AC9B-13ABBD7D02C3}\RP91\A0026257.sys
[DETECTION] Contains detection pattern of the worm WORM/Locksky.CM.1
[NOTE] The file was moved to '490481dc.qua'!
H:\System Volume Information\_restore{879E598B-020E-408B-AC9B-13ABBD7D02C3}\RP91\A0026258.exe
[DETECTION] Is the Trojan horse TR/Crypt.XPACK.Gen
[NOTE] The file was moved to '488da88d.qua'!
H:\System Volume Information\_restore{879E598B-020E-408B-AC9B-13ABBD7D02C3}\RP91\A0026259.exe
[DETECTION] Is the Trojan horse TR/Crypt.XPACK.Gen
[NOTE] The file was moved to '490481de.qua'!
H:\System Volume Information\_restore{879E598B-020E-408B-AC9B-13ABBD7D02C3}\RP91\A0026260.exe
[DETECTION] Is the Trojan horse TR/Crypt.XPACK.Gen
[NOTE] The file was moved to '488da88f.qua'!
H:\System Volume Information\_restore{879E598B-020E-408B-AC9B-13ABBD7D02C3}\RP91\A0026261.exe
[DETECTION] Is the Trojan horse TR/Crypt.XPACK.Gen
[NOTE] The file was moved to '488da81a.qua'!
H:\System Volume Information\_restore{879E598B-020E-408B-AC9B-13ABBD7D02C3}\RP91\A0026262.exe
[DETECTION] Is the Trojan horse TR/Crypt.XPACK.Gen
[NOTE] The file was moved to '4904814b.qua'!
H:\System Volume Information\_restore{879E598B-020E-408B-AC9B-13ABBD7D02C3}\RP91\A0026264.dll
[DETECTION] Is the Trojan horse TR/Vundo.Gen
[NOTE] The file was moved to '490481c0.qua'!
H:\System Volume Information\_restore{879E598B-020E-408B-AC9B-13ABBD7D02C3}\RP91\A0026265.exe
[DETECTION] Is the Trojan horse TR/Crypt.XPACK.Gen
[NOTE] The file was moved to '488da891.qua'!
H:\System Volume Information\_restore{879E598B-020E-408B-AC9B-13ABBD7D02C3}\RP91\A0026266.exe
[DETECTION] Is the Trojan horse TR/Crypt.XPACK.Gen
[NOTE] The file was moved to '488da81c.qua'!
H:\System Volume Information\_restore{879E598B-020E-408B-AC9B-13ABBD7D02C3}\RP91\A0026267.dll
[DETECTION] Is the Trojan horse TR/Vundo.Gen
[NOTE] The file was moved to '4904814d.qua'!
H:\System Volume Information\_restore{879E598B-020E-408B-AC9B-13ABBD7D02C3}\RP91\A0026268.exe
[DETECTION] Is the Trojan horse TR/Crypt.XPACK.Gen
[NOTE] The file was moved to '488da81e.qua'!
H:\System Volume Information\_restore{879E598B-020E-408B-AC9B-13ABBD7D02C3}\RP91\A0026269.exe
[DETECTION] Is the Trojan horse TR/Crypt.XPACK.Gen
[NOTE] The file was moved to '490481c2.qua'!
H:\System Volume Information\_restore{879E598B-020E-408B-AC9B-13ABBD7D02C3}\RP91\A0026270.exe
[DETECTION] Is the Trojan horse TR/Crypt.XPACK.Gen
[NOTE] The file was moved to '488da893.qua'!
H:\System Volume Information\_restore{879E598B-020E-408B-AC9B-13ABBD7D02C3}\RP91\A0026271.exe
[DETECTION] Is the Trojan horse TR/Crypt.XPACK.Gen
[NOTE] The file was moved to '490481c4.qua'!
H:\System Volume Information\_restore{879E598B-020E-408B-AC9B-13ABBD7D02C3}\RP91\A0026272.exe
[DETECTION] Is the Trojan horse TR/Crypt.XPACK.Gen
[NOTE] The file was moved to '4904814f.qua'!
H:\System Volume Information\_restore{879E598B-020E-408B-AC9B-13ABBD7D02C3}\RP91\A0026273.dll
[DETECTION] Is the Trojan horse TR/Vundo.Gen
[NOTE] The file was moved to '488da800.qua'!
H:\System Volume Information\_restore{879E598B-020E-408B-AC9B-13ABBD7D02C3}\RP91\A0026274.exe
[DETECTION] Is the Trojan horse TR/Crypt.XPACK.Gen
[NOTE] The file was moved to '49048151.qua'!
H:\System Volume Information\_restore{879E598B-020E-408B-AC9B-13ABBD7D02C3}\RP91\A0026275.exe
[DETECTION] Is the Trojan horse TR/Crypt.XPACK.Gen
[NOTE] The file was moved to '488da895.qua'!
H:\System Volume Information\_restore{879E598B-020E-408B-AC9B-13ABBD7D02C3}\RP91\A0026276.exe
[DETECTION] Is the Trojan horse TR/Crypt.XPACK.Gen
[NOTE] The file was moved to '490481c6.qua'!
H:\System Volume Information\_restore{879E598B-020E-408B-AC9B-13ABBD7D02C3}\RP91\A0026277.exe
[DETECTION] Is the Trojan horse TR/Crypt.XPACK.Gen
[NOTE] The file was moved to '488da897.qua'!
H:\System Volume Information\_restore{879E598B-020E-408B-AC9B-13ABBD7D02C3}\RP91\A0026283.exe
[DETECTION] Is the Trojan horse TR/Crypt.XPACK.Gen
[NOTE] The file was moved to '490481c8.qua'!
H:\System Volume Information\_restore{879E598B-020E-408B-AC9B-13ABBD7D02C3}\RP91\A0026284.dll
[DETECTION] Is the Trojan horse TR/Vundo.Gen
[NOTE] The file was moved to '488da880.qua'!
H:\System Volume Information\_restore{879E598B-020E-408B-AC9B-13ABBD7D02C3}\RP91\A0026285.exe
[DETECTION] Is the Trojan horse TR/Crypt.XPACK.Gen
[NOTE] The file was moved to '490481d1.qua'!
H:\System Volume Information\_restore{879E598B-020E-408B-AC9B-13ABBD7D02C3}\RP91\A0026286.dll
[DETECTION] Is the Trojan horse TR/Vundo.Gen
[NOTE] The file was moved to '488da882.qua'!
H:\System Volume Information\_restore{879E598B-020E-408B-AC9B-13ABBD7D02C3}\RP91\A0026287.exe
[DETECTION] Is the Trojan horse TR/Crypt.XPACK.Gen
[NOTE] The file was moved to '488da899.qua'!
H:\System Volume Information\_restore{879E598B-020E-408B-AC9B-13ABBD7D02C3}\RP91\A0026288.exe
[DETECTION] Is the Trojan horse TR/Crypt.XPACK.Gen
[NOTE] The file was moved to '490481ca.qua'!
H:\System Volume Information\_restore{879E598B-020E-408B-AC9B-13ABBD7D02C3}\RP91\A0026289.exe
[DETECTION] Is the Trojan horse TR/Crypt.XPACK.Gen
[NOTE] The file was moved to '488da89b.qua'!
H:\System Volume Information\_restore{879E598B-020E-408B-AC9B-13ABBD7D02C3}\RP91\A0026290.exe
[DETECTION] Is the Trojan horse TR/Crypt.XPACK.Gen
[NOTE] The file was moved to '490481cc.qua'!
H:\System Volume Information\_restore{879E598B-020E-408B-AC9B-13ABBD7D02C3}\RP91\A0026291.exe
[DETECTION] Is the Trojan horse TR/Crypt.XPACK.Gen
[NOTE] The file was moved to '490481d3.qua'!
H:\System Volume Information\_restore{879E598B-020E-408B-AC9B-13ABBD7D02C3}\RP91\A0026292.exe
[DETECTION] Is the Trojan horse TR/Crypt.XPACK.Gen
[NOTE] The file was moved to '49048f54.qua'!
H:\System Volume Information\_restore{879E598B-020E-408B-AC9B-13ABBD7D02C3}\RP91\A0026293.exe
[DETECTION] Is the Trojan horse TR/Crypt.XPACK.Gen
[NOTE] The file was moved to '49048f56.qua'!
H:\System Volume Information\_restore{879E598B-020E-408B-AC9B-13ABBD7D02C3}\RP91\A0026294.exe
[DETECTION] Is the Trojan horse TR/Crypt.XPACK.Gen
[NOTE] The file was moved to '49048f58.qua'!
H:\System Volume Information\_restore{879E598B-020E-408B-AC9B-13ABBD7D02C3}\RP91\A0026295.exe
[DETECTION] Is the Trojan horse TR/Crypt.XPACK.Gen
[NOTE] The file was moved to '488da884.qua'!
H:\System Volume Information\_restore{879E598B-020E-408B-AC9B-13ABBD7D02C3}\RP91\A0026296.exe
[DETECTION] Is the Trojan horse TR/Crypt.XPACK.Gen
[NOTE] The file was moved to '49048f55.qua'!
H:\System Volume Information\_restore{879E598B-020E-408B-AC9B-13ABBD7D02C3}\RP91\A0026298.exe
[DETECTION] Is the Trojan horse TR/Crypt.XPACK.Gen
[NOTE] The file was moved to '488da886.qua'!
H:\System Volume Information\_restore{879E598B-020E-408B-AC9B-13ABBD7D02C3}\RP91\A0026299.exe
[DETECTION] Is the Trojan horse TR/Crypt.XPACK.Gen
[NOTE] The file was moved to '49048f5a.qua'!
H:\System Volume Information\_restore{879E598B-020E-408B-AC9B-13ABBD7D02C3}\RP91\A0026300.exe
[DETECTION] Is the Trojan horse TR/Crypt.XPACK.Gen
[NOTE] The file was moved to '49048f5c.qua'!
H:\System Volume Information\_restore{879E598B-020E-408B-AC9B-13ABBD7D02C3}\RP91\A0026301.exe
[DETECTION] Is the Trojan horse TR/Crypt.XPACK.Gen
[NOTE] The file was moved to '49048f5e.qua'!
H:\System Volume Information\_restore{879E598B-020E-408B-AC9B-13ABBD7D02C3}\RP91\A0026302.exe
[DETECTION] Is the Trojan horse TR/Crypt.XPACK.Gen
[NOTE] The file was moved to '49048f40.qua'!
H:\System Volume Information\_restore{879E598B-020E-408B-AC9B-13ABBD7D02C3}\RP91\A0026368.exe
[DETECTION] Contains detection pattern of the dropper DR/WhenU.A.112
[NOTE] The file was moved to '49048f57.qua'!
H:\System Volume Information\_restore{879E598B-020E-408B-AC9B-13ABBD7D02C3}\RP91\A0026369.exe
[0] Archive type: ZIP SFX (self extracting)
--> setup.exe
[DETECTION] Is the Trojan horse TR/Drop.Joiner.DV.2
[NOTE] The file was moved to '488da888.qua'!
H:\System Volume Information\_restore{879E598B-020E-408B-AC9B-13ABBD7D02C3}\RP91\A0026370.exe
[DETECTION] Contains detection pattern of the dropper DR/Spy.Delf.FK
[NOTE] The file was moved to '49048f42.qua'!
End of the scan: Saturday, June 21, 2008 21:19
Used time: 2:28:29 min
The scan has been done completely.
15569 Scanning directories
532542 Files were scanned
157 viruses and/or unwanted programs were found
0 Files were classified as suspicious:
0 files were deleted
0 files were repaired
157 files were moved to quarantine
0 files were renamed
5 Files cannot be scanned
532385 Files not concerned
8990 Archives were scanned
5 Warnings
157 Notes