Sorry, but the other post cut off the scandump.txt
Scan Control Dumped @ 20:14:23 24-04-05
(DELETED) Positive identification: TrojanDownloader.Win32.CWS.k
File: c:\6ecb2699.exe
Suspicious Filename: HTA file in suspicious location
File: c:\d25c119d.hta
Suspicious Filename: Dual extensions
File: c:\cygwin\bin\dumpgdbm-1.5.2.exe
Suspicious Filename: Dual extensions
File: c:\cygwin\bin\gawk-3.1.4.exe
Suspicious Filename: Dual extensions
File: c:\cygwin\bin\loadgdbm-1.5.2.exe
Suspicious Filename: Dual extensions
File: c:\cygwin\bin\perl5.8.6.exe
Suspicious Filename: Dual extensions
File: c:\cygwin\bin\pgawk-3.1.4.exe
(DELETED) Positive identification: Adware.Wintol.g
File: c:\documents and settings\mariola\local settings\temp\~321395.tmp
(DELETED) Positive identification: Adware.Wintol.g
File: c:\documents and settings\mariola\local settings\temp\~333702.tmp
(DELETED) Positive identification: Adware.Wintol.g
File: c:\documents and settings\mariola\local settings\temp\~412637.tmp
(DELETED) Positive identification: Adware.Wintol.g
File: c:\documents and settings\mariola\local settings\temp\~58147.tmp
(DELETED) Positive identification: Adware.Wintol.g
File: c:\documents and settings\mariola\local settings\temp\~714730.tmp
(DELETED) Positive identification: Adware.Wintol.g
File: c:\documents and settings\mariola\local settings\temp\~790027.tmp
(DELETED) Positive identification: TrojanDownloader.Win32.WinTool
File: c:\documents and settings\mariola\local settings\temp\~795270.tmp
(DELETED) Positive identification: TrojanDownloader.Win32.WinTool
File: c:\documents and settings\mariola\local settings\temp\~796211.tmp
(DELETED) Positive identification: Adware.Wintol.g
File: c:\documents and settings\mariola\local settings\temp\~826084.tmp
(DELETED) Positive identification: TrojanDownloader.Win32.WinTool
File: c:\documents and settings\mariola\local settings\temp\~830398.tmp
(DELETED) Positive identification: Adware.Wintol.g
File: c:\documents and settings\mariola\local settings\temp\~854651.tmp
(DELETED) Positive identification: TrojanDownloader.Win32.WinTool
File: c:\documents and settings\mariola\local settings\temp\~911469.tmp
(DELETED) Positive identification: Adware.Wintol.g
File: c:\documents and settings\mariola\local settings\temp\~950458.tmp
(DELETED) Positive identification: Adware.Wintol.g
File: c:\documents and settings\mariola\local settings\temp\~950561.tmp
(DELETED) Positive identification: Adware.Wintol.g
File: c:\documents and settings\mariola\local settings\temp\~964628.tmp
(DELETED) Positive identification: TrojanDropper.Win32.Small.vn
File: c:\documents and settings\mariola\local settings\temporary internet files\content.ie5\k5mbcdmz\$file[1]
(DELETED) Positive identification: TrojanDropper.Win32.Small.vn
File: c:\documents and settings\mariola\local settings\temporary internet files\content.ie5\xjj5vtzc\$file[1]
(DELETED) Positive identification: TrojanDownloader.Win32.VB.df
File: c:\documents and settings\tobiasz\application data\phoenix\profiles\default\7aif9o9v.slt\cache\484dddcad01
(DELETED) Positive identification: Joke.Win32.Life
File: c:\documents and settings\tobiasz\desktop\life.exe
Suspicious Filename: Dual extensions
File: c:\documents and settings\tobiasz\desktop\mingw-3.1.0-1.exe
Suspicious Filename: Dual extensions
File: c:\documents and settings\tobiasz\desktop\the transcendentalists.doc.doc
Suspicious Filename: Dual extensions
File: c:\documents and settings\tobiasz\desktop\comp sci\python-2.3.4c1.exe
Suspicious Filename: Excessive space characters
File: c:\documents and settings\tobiasz\favorites\

? .url
Suspicious Filename: Dual extensions
File: c:\documents and settings\tobiasz\local settings\temp\key-generator 5.5.8.0.exe
(DELETED) Positive identification (DLL): TrojanDownloader.Win32.Agent.kf1 (dll)
File: c:\documents and settings\tobiasz\local settings\temp\wldr.dll
(DELETED) Positive identification: TrojanDownloader.Win32.WinTool
File: c:\documents and settings\tobiasz\local settings\temp\~1184.tmp
(DELETED) Positive identification: Adware.Wintol.p
File: c:\documents and settings\tobiasz\local settings\temp\~16807.tmp
(DELETED) Positive identification: Adware.Wintol.p
File: c:\documents and settings\tobiasz\local settings\temp\~298658.tmp
(DELETED) Positive identification: TrojanDownloader.Win32.WinTool
File: c:\documents and settings\tobiasz\local settings\temp\~3302.tmp
(DELETED) Positive identification: Adware.Wintol.p
File: c:\documents and settings\tobiasz\local settings\temp\~36350.tmp
(DELETED) Positive identification: Adware.Wintol.c
File: c:\documents and settings\tobiasz\local settings\temp\~397943.tmp
(DELETED) Positive identification: TrojanDownloader.Win32.WinTool
File: c:\documents and settings\tobiasz\local settings\temp\~589354.tmp
(DELETED) Positive identification: TrojanDownloader.Win32.WinTool
File: c:\documents and settings\tobiasz\local settings\temp\~677700.tmp
(DELETED) Positive identification: Adware.Wintol.p
File: c:\documents and settings\tobiasz\local settings\temp\~835041.tmp
(DELETED) Positive identification: Adware.Wintol.p
File: c:\documents and settings\tobiasz\local settings\temp\~842966.tmp
(DELETED) Positive identification: Adware.Wintol.p
File: c:\documents and settings\tobiasz\local settings\temp\~870121.tmp
(DELETED) Positive identification: Adware.Wintol.p
File: c:\documents and settings\tobiasz\local settings\temp\~876315.tmp
(DELETED) Positive identification: Adware.Wintol.p
File: c:\documents and settings\tobiasz\local settings\temp\~936581.tmp
(DELETED) Positive identification: Adware.Wintol.c
File: c:\documents and settings\tobiasz\local settings\temp\~952156.tmp
Suspicious Filename: Dual extensions
File: c:\program files\hewlett-packard\digital imaging\hpisinst\install.wse.exe
Suspicious Filename: Dual extensions
File: c:\program files\hewlett-packard\hp instant support di\temp\install.wse.exe
(DELETED) Positive identification: Riskware.Proxy.Hltv
File: c:\sierra\counter-strike\hltv.exe
(DELETED) Positive identification: TrojanDropper.Win32.Small.ty1
File: c:\system volume information\_restore{31414675-6cbe-4639-8f67-8c2e395d7683}\rp807\a0094994.exe
(DELETED) Positive identification: TrojanDropper.Win32.Small.vn
File: c:\system volume information\_restore{31414675-6cbe-4639-8f67-8c2e395d7683}\rp809\a0095074.exe
(DELETED) Positive identification: TrojanDropper.Win32.Small.vn
File: c:\system volume information\_restore{31414675-6cbe-4639-8f67-8c2e395d7683}\rp809\a0096075.exe
(DELETED) Positive identification: TrojanDropper.Win32.Small.vn
File: c:\system volume information\_restore{31414675-6cbe-4639-8f67-8c2e395d7683}\rp809\a0096110.exe
(DELETED) Positive identification: TrojanDropper.Win32.Small.vn
File: c:\system volume information\_restore{31414675-6cbe-4639-8f67-8c2e395d7683}\rp810\a0096116.exe
(DELETED) Positive identification: TrojanDropper.Win32.Small.vn
File: c:\system volume information\_restore{31414675-6cbe-4639-8f67-8c2e395d7683}\rp810\a0096132.exe
(DELETED) Positive identification: TrojanDropper.Win32.Small.vn
File: c:\system volume information\_restore{31414675-6cbe-4639-8f67-8c2e395d7683}\rp810\a0096149.exe
(DELETED) Positive identification (DLL): Trojan.Win32.WebSearch.i (dll)
File: c:\system volume information\_restore{31414675-6cbe-4639-8f67-8c2e395d7683}\rp811\a0097158.dll
(DELETED) Positive identification: Trojan.Win32.WebSearch.i
File: c:\system volume information\_restore{31414675-6cbe-4639-8f67-8c2e395d7683}\rp811\a0097159.exe
(DELETED) Positive identification (DLL): Trojan.Win32.WebSearch.i1 (dll)
File: c:\system volume information\_restore{31414675-6cbe-4639-8f67-8c2e395d7683}\rp811\a0097160.dll
(DELETED) Positive identification (DLL): Trojan.Win32.WebSearch.i (dll)
File: c:\system volume information\_restore{31414675-6cbe-4639-8f67-8c2e395d7683}\rp811\a0097161.dll
(DELETED) Positive identification: Trojan.Win32.WebSearch.i
File: c:\system volume information\_restore{31414675-6cbe-4639-8f67-8c2e395d7683}\rp811\a0097162.exe
(DELETED) Positive identification (DLL): Trojan.Win32.WebSearch.i1 (dll)
File: c:\system volume information\_restore{31414675-6cbe-4639-8f67-8c2e395d7683}\rp811\a0097163.dll
(DELETED) Positive identification (DLL): Trojan.Win32.WebSearch.i (dll)
File: c:\system volume information\_restore{31414675-6cbe-4639-8f67-8c2e395d7683}\rp811\a0097164.dll
(DELETED) Positive identification: Trojan.Win32.WebSearch.i
File: c:\system volume information\_restore{31414675-6cbe-4639-8f67-8c2e395d7683}\rp811\a0097165.exe
(DELETED) Positive identification (DLL): Trojan.Win32.WebSearch.i1 (dll)
File: c:\system volume information\_restore{31414675-6cbe-4639-8f67-8c2e395d7683}\rp811\a0097166.dll
(DELETED) Positive identification (DLL): Trojan.Win32.WebSearch.i (dll)
File: c:\system volume information\_restore{31414675-6cbe-4639-8f67-8c2e395d7683}\rp811\a0097167.dll
(DELETED) Positive identification: Trojan.Win32.WebSearch.i
File: c:\system volume information\_restore{31414675-6cbe-4639-8f67-8c2e395d7683}\rp811\a0097168.exe
(DELETED) Positive identification (DLL): Trojan.Win32.WebSearch.i1 (dll)
File: c:\system volume information\_restore{31414675-6cbe-4639-8f67-8c2e395d7683}\rp811\a0097169.dll
(DELETED) Positive identification (DLL): Trojan.Win32.WebSearch.i (dll)
File: c:\system volume information\_restore{31414675-6cbe-4639-8f67-8c2e395d7683}\rp811\a0097170.dll
(DELETED) Positive identification: Trojan.Win32.WebSearch.i
File: c:\system volume information\_restore{31414675-6cbe-4639-8f67-8c2e395d7683}\rp811\a0097171.exe
(DELETED) Positive identification (DLL): Trojan.Win32.WebSearch.i1 (dll)
File: c:\system volume information\_restore{31414675-6cbe-4639-8f67-8c2e395d7683}\rp811\a0097172.dll
(DELETED) Positive identification (DLL): Trojan.Win32.WebSearch.i (dll)
File: c:\system volume information\_restore{31414675-6cbe-4639-8f67-8c2e395d7683}\rp811\a0097173.dll
(DELETED) Positive identification: Trojan.Win32.WebSearch.i
File: c:\system volume information\_restore{31414675-6cbe-4639-8f67-8c2e395d7683}\rp811\a0097174.exe
(DELETED) Positive identification (DLL): Trojan.Win32.WebSearch.i1 (dll)
File: c:\system volume information\_restore{31414675-6cbe-4639-8f67-8c2e395d7683}\rp811\a0097175.dll
(DELETED) Positive identification (DLL): Trojan.Win32.WebSearch.i (dll)
File: c:\system volume information\_restore{31414675-6cbe-4639-8f67-8c2e395d7683}\rp811\a0097176.dll
(DELETED) Positive identification: Trojan.Win32.WebSearch.i
File: c:\system volume information\_restore{31414675-6cbe-4639-8f67-8c2e395d7683}\rp811\a0097177.exe
(DELETED) Positive identification (DLL): Trojan.Win32.WebSearch.i1 (dll)
File: c:\system volume information\_restore{31414675-6cbe-4639-8f67-8c2e395d7683}\rp811\a0097178.dll
(DELETED) Positive identification (DLL): Trojan.Win32.WebSearch.i (dll)
File: c:\system volume information\_restore{31414675-6cbe-4639-8f67-8c2e395d7683}\rp811\a0097179.dll
(DELETED) Positive identification: Trojan.Win32.WebSearch.i
File: c:\system volume information\_restore{31414675-6cbe-4639-8f67-8c2e395d7683}\rp811\a0097180.exe
(DELETED) Positive identification (DLL): Trojan.Win32.WebSearch.i1 (dll)
File: c:\system volume information\_restore{31414675-6cbe-4639-8f67-8c2e395d7683}\rp811\a0097181.dll
(DELETED) Positive identification (DLL): Trojan.Win32.WebSearch.i (dll)
File: c:\system volume information\_restore{31414675-6cbe-4639-8f67-8c2e395d7683}\rp811\a0097182.dll
(DELETED) Positive identification: Trojan.Win32.WebSearch.i
File: c:\system volume information\_restore{31414675-6cbe-4639-8f67-8c2e395d7683}\rp811\a0097183.exe
(DELETED) Positive identification (DLL): Trojan.Win32.WebSearch.i1 (dll)
File: c:\system volume information\_restore{31414675-6cbe-4639-8f67-8c2e395d7683}\rp811\a0097184.dll
(DELETED) Positive identification (DLL): Trojan.Win32.WebSearch.i (dll)
File: c:\system volume information\_restore{31414675-6cbe-4639-8f67-8c2e395d7683}\rp811\a0097185.dll
(DELETED) Positive identification: Trojan.Win32.WebSearch.i
File: c:\system volume information\_restore{31414675-6cbe-4639-8f67-8c2e395d7683}\rp811\a0097186.exe
(DELETED) Positive identification (DLL): Trojan.Win32.WebSearch.i1 (dll)
File: c:\system volume information\_restore{31414675-6cbe-4639-8f67-8c2e395d7683}\rp811\a0097187.dll
(DELETED) Positive identification (DLL): Trojan.Win32.WebSearch.i (dll)
File: c:\system volume information\_restore{31414675-6cbe-4639-8f67-8c2e395d7683}\rp811\a0097188.dll
(DELETED) Positive identification: Trojan.Win32.WebSearch.i
File: c:\system volume information\_restore{31414675-6cbe-4639-8f67-8c2e395d7683}\rp811\a0097189.exe
(DELETED) Positive identification (DLL): Trojan.Win32.WebSearch.i1 (dll)
File: c:\system volume information\_restore{31414675-6cbe-4639-8f67-8c2e395d7683}\rp811\a0097190.dll
(DELETED) Positive identification (DLL): Trojan.Win32.WebSearch.i (dll)
File: c:\system volume information\_restore{31414675-6cbe-4639-8f67-8c2e395d7683}\rp811\a0097191.dll
(DELETED) Positive identification: Trojan.Win32.WebSearch.i
File: c:\system volume information\_restore{31414675-6cbe-4639-8f67-8c2e395d7683}\rp811\a0097192.exe
(DELETED) Positive identification (DLL): Trojan.Win32.WebSearch.i1 (dll)
File: c:\system volume information\_restore{31414675-6cbe-4639-8f67-8c2e395d7683}\rp811\a0097193.dll
(DELETED) Positive identification (DLL): Trojan.Win32.WebSearch.i (dll)
File: c:\system volume information\_restore{31414675-6cbe-4639-8f67-8c2e395d7683}\rp811\a0097194.dll
(DELETED) Positive identification: Trojan.Win32.WebSearch.i
File: c:\system volume information\_restore{31414675-6cbe-4639-8f67-8c2e395d7683}\rp811\a0097195.exe
(DELETED) Positive identification (DLL): Trojan.Win32.WebSearch.i1 (dll)
File: c:\system volume information\_restore{31414675-6cbe-4639-8f67-8c2e395d7683}\rp811\a0097196.dll
(DELETED) Positive identification (DLL): Trojan.Win32.WebSearch.i (dll)
File: c:\system volume information\_restore{31414675-6cbe-4639-8f67-8c2e395d7683}\rp811\a0097197.dll
(DELETED) Positive identification: Trojan.Win32.WebSearch.i
File: c:\system volume information\_restore{31414675-6cbe-4639-8f67-8c2e395d7683}\rp811\a0097198.exe
(DELETED) Positive identification (DLL): Trojan.Win32.WebSearch.i1 (dll)
File: c:\system volume information\_restore{31414675-6cbe-4639-8f67-8c2e395d7683}\rp811\a0097199.dll
(DELETED) Positive identification (DLL): Trojan.Win32.WebSearch.i (dll)
File: c:\system volume information\_restore{31414675-6cbe-4639-8f67-8c2e395d7683}\rp811\a0097200.dll
(DELETED) Positive identification: Trojan.Win32.WebSearch.i
File: c:\system volume information\_restore{31414675-6cbe-4639-8f67-8c2e395d7683}\rp811\a0097201.exe
(DELETED) Positive identification (DLL): Trojan.Win32.WebSearch.i1 (dll)
File: c:\system volume information\_restore{31414675-6cbe-4639-8f67-8c2e395d7683}\rp811\a0097202.dll
(DELETED) Positive identification (DLL): Trojan.Win32.WebSearch.i (dll)
File: c:\system volume information\_restore{31414675-6cbe-4639-8f67-8c2e395d7683}\rp811\a0097203.dll
(DELETED) Positive identification: Trojan.Win32.WebSearch.i
File: c:\system volume information\_restore{31414675-6cbe-4639-8f67-8c2e395d7683}\rp811\a0097204.exe
(DELETED) Positive identification (DLL): Trojan.Win32.WebSearch.i1 (dll)
File: c:\system volume information\_restore{31414675-6cbe-4639-8f67-8c2e395d7683}\rp811\a0097205.dll
(DELETED) Positive identification (DLL): Trojan.Win32.WebSearch.i (dll)
File: c:\system volume information\_restore{31414675-6cbe-4639-8f67-8c2e395d7683}\rp811\a0097206.dll
(DELETED) Positive identification: Trojan.Win32.WebSearch.i
File: c:\system volume information\_restore{31414675-6cbe-4639-8f67-8c2e395d7683}\rp811\a0097207.exe
(DELETED) Positive identification (DLL): Trojan.Win32.WebSearch.i1 (dll)
File: c:\system volume information\_restore{31414675-6cbe-4639-8f67-8c2e395d7683}\rp811\a0097208.dll
(DELETED) Positive identification (DLL): Trojan.Win32.WebSearch.i (dll)
File: c:\system volume information\_restore{31414675-6cbe-4639-8f67-8c2e395d7683}\rp811\a0097209.dll
(DELETED) Positive identification: Trojan.Win32.WebSearch.i
File: c:\system volume information\_restore{31414675-6cbe-4639-8f67-8c2e395d7683}\rp811\a0097210.exe
(DELETED) Positive identification (DLL): Trojan.Win32.WebSearch.i1 (dll)
File: c:\system volume information\_restore{31414675-6cbe-4639-8f67-8c2e395d7683}\rp811\a0097211.dll
(DELETED) Positive identification (DLL): Trojan.Win32.WebSearch.i (dll)
File: c:\system volume information\_restore{31414675-6cbe-4639-8f67-8c2e395d7683}\rp811\a0097212.dll
(DELETED) Positive identification: Trojan.Win32.WebSearch.i
File: c:\system volume information\_restore{31414675-6cbe-4639-8f67-8c2e395d7683}\rp811\a0097213.exe
(DELETED) Positive identification (DLL): Trojan.Win32.WebSearch.i1 (dll)
File: c:\system volume information\_restore{31414675-6cbe-4639-8f67-8c2e395d7683}\rp811\a0097214.dll
(DELETED) Positive identification (DLL): Trojan.Win32.WebSearch.i (dll)
File: c:\system volume information\_restore{31414675-6cbe-4639-8f67-8c2e395d7683}\rp811\a0097215.dll
(DELETED) Positive identification: Trojan.Win32.WebSearch.i
File: c:\system volume information\_restore{31414675-6cbe-4639-8f67-8c2e395d7683}\rp811\a0097216.exe
(DELETED) Positive identification (DLL): Trojan.Win32.WebSearch.i1 (dll)
File: c:\system volume information\_restore{31414675-6cbe-4639-8f67-8c2e395d7683}\rp811\a0097217.dll
(DELETED) Positive identification (DLL): Trojan.Win32.WebSearch.i (dll)
File: c:\system volume information\_restore{31414675-6cbe-4639-8f67-8c2e395d7683}\rp811\a0097218.dll
(DELETED) Positive identification: Trojan.Win32.WebSearch.i
File: c:\system volume information\_restore{31414675-6cbe-4639-8f67-8c2e395d7683}\rp811\a0097219.exe
(DELETED) Positive identification (DLL): Trojan.Win32.WebSearch.i1 (dll)
File: c:\system volume information\_restore{31414675-6cbe-4639-8f67-8c2e395d7683}\rp811\a0097220.dll
(DELETED) Positive identification (DLL): Trojan.Win32.WebSearch.i (dll)
File: c:\system volume information\_restore{31414675-6cbe-4639-8f67-8c2e395d7683}\rp811\a0097221.dll
(DELETED) Positive identification: Trojan.Win32.WebSearch.i
File: c:\system volume information\_restore{31414675-6cbe-4639-8f67-8c2e395d7683}\rp811\a0097222.exe
(DELETED) Positive identification (DLL): Trojan.Win32.WebSearch.i1 (dll)
File: c:\system volume information\_restore{31414675-6cbe-4639-8f67-8c2e395d7683}\rp811\a0097223.dll
(DELETED) Positive identification (DLL): Trojan.Win32.WebSearch.i (dll)
File: c:\system volume information\_restore{31414675-6cbe-4639-8f67-8c2e395d7683}\rp811\a0097224.dll
(DELETED) Positive identification: Trojan.Win32.WebSearch.i
File: c:\system volume information\_restore{31414675-6cbe-4639-8f67-8c2e395d7683}\rp811\a0097225.exe
(DELETED) Positive identification (DLL): Trojan.Win32.WebSearch.i1 (dll)
File: c:\system volume information\_restore{31414675-6cbe-4639-8f67-8c2e395d7683}\rp811\a0097226.dll
(DELETED) Positive identification (DLL): Trojan.Win32.WebSearch.i (dll)
File: c:\system volume information\_restore{31414675-6cbe-4639-8f67-8c2e395d7683}\rp811\a0097227.dll
(DELETED) Positive identification: Trojan.Win32.WebSearch.i
File: c:\system volume information\_restore{31414675-6cbe-4639-8f67-8c2e395d7683}\rp811\a0097228.exe
(DELETED) Positive identification (DLL): Trojan.Win32.WebSearch.i1 (dll)
File: c:\system volume information\_restore{31414675-6cbe-4639-8f67-8c2e395d7683}\rp811\a0097229.dll
(DELETED) Positive identification (DLL): Trojan.Win32.WebSearch.i (dll)
File: c:\system volume information\_restore{31414675-6cbe-4639-8f67-8c2e395d7683}\rp811\a0097230.dll
(DELETED) Positive identification: Trojan.Win32.WebSearch.i
File: c:\system volume information\_restore{31414675-6cbe-4639-8f67-8c2e395d7683}\rp811\a0097231.exe
(DELETED) Positive identification (DLL): Trojan.Win32.WebSearch.i1 (dll)
File: c:\system volume information\_restore{31414675-6cbe-4639-8f67-8c2e395d7683}\rp811\a0097232.dll
(DELETED) Positive identification (DLL): Trojan.Win32.WebSearch.i (dll)
File: c:\system volume information\_restore{31414675-6cbe-4639-8f67-8c2e395d7683}\rp811\a0097233.dll
(DELETED) Positive identification: Trojan.Win32.WebSearch.i
File: c:\system volume information\_restore{31414675-6cbe-4639-8f67-8c2e395d7683}\rp811\a0097234.exe
(DELETED) Positive identification (DLL): Trojan.Win32.WebSearch.i1 (dll)
File: c:\system volume information\_restore{31414675-6cbe-4639-8f67-8c2e395d7683}\rp811\a0097235.dll
(DELETED) Positive identification (DLL): Trojan.Win32.WebSearch.i (dll)
File: c:\system volume information\_restore{31414675-6cbe-4639-8f67-8c2e395d7683}\rp811\a0097236.dll
(DELETED) Positive identification: Trojan.Win32.WebSearch.i
File: c:\system volume information\_restore{31414675-6cbe-4639-8f67-8c2e395d7683}\rp811\a0097237.exe
(DELETED) Positive identification (DLL): Trojan.Win32.WebSearch.i1 (dll)
File: c:\system volume information\_restore{31414675-6cbe-4639-8f67-8c2e395d7683}\rp811\a0097238.dll
(DELETED) Positive identification (DLL): Trojan.Win32.WebSearch.i (dll)
File: c:\system volume information\_restore{31414675-6cbe-4639-8f67-8c2e395d7683}\rp811\a0097239.dll
(DELETED) Positive identification: Trojan.Win32.WebSearch.i
File: c:\system volume information\_restore{31414675-6cbe-4639-8f67-8c2e395d7683}\rp811\a0097240.exe
(DELETED) Positive identification (DLL): Trojan.Win32.WebSearch.i1 (dll)
File: c:\system volume information\_restore{31414675-6cbe-4639-8f67-8c2e395d7683}\rp811\a0097241.dll
(DELETED) Positive identification (DLL): Trojan.Win32.WebSearch.i (dll)
File: c:\system volume information\_restore{31414675-6cbe-4639-8f67-8c2e395d7683}\rp811\a0097242.dll
(DELETED) Positive identification: Trojan.Win32.WebSearch.i
File: c:\system volume information\_restore{31414675-6cbe-4639-8f67-8c2e395d7683}\rp811\a0097243.exe
(DELETED) Positive identification (DLL): Trojan.Win32.WebSearch.i1 (dll)
File: c:\system volume information\_restore{31414675-6cbe-4639-8f67-8c2e395d7683}\rp811\a0097244.dll
(DELETED) Positive identification (DLL): Trojan.Win32.WebSearch.i (dll)
File: c:\system volume information\_restore{31414675-6cbe-4639-8f67-8c2e395d7683}\rp811\a0097245.dll
(DELETED) Positive identification: Trojan.Win32.WebSearch.i
File: c:\system volume information\_restore{31414675-6cbe-4639-8f67-8c2e395d7683}\rp811\a0097246.exe
(DELETED) Positive identification (DLL): Trojan.Win32.WebSearch.i1 (dll)
File: c:\system volume information\_restore{31414675-6cbe-4639-8f67-8c2e395d7683}\rp811\a0097247.dll
(DELETED) Positive identification (DLL): Trojan.Win32.WebSearch.i (dll)
File: c:\system volume information\_restore{31414675-6cbe-4639-8f67-8c2e395d7683}\rp811\a0097248.dll
(DELETED) Positive identification: Trojan.Win32.WebSearch.i
File: c:\system volume information\_restore{31414675-6cbe-4639-8f67-8c2e395d7683}\rp811\a0097249.exe
(DELETED) Positive identification (DLL): Trojan.Win32.WebSearch.i1 (dll)
File: c:\system volume information\_restore{31414675-6cbe-4639-8f67-8c2e395d7683}\rp811\a0097250.dll
(DELETED) Positive identification: TrojanDropper.Win32.Small.vn
File: c:\system volume information\_restore{31414675-6cbe-4639-8f67-8c2e395d7683}\rp811\a0097266.exe
(DELETED) Positive identification (DLL): TrojanDownloader.Win32.Small.aoa (dll)
File: c:\system volume information\_restore{31414675-6cbe-4639-8f67-8c2e395d7683}\rp811\a0098295.dll
(DELETED) Positive identification: TrojanDownloader.Win32.Small.aoa
File: c:\system volume information\_restore{31414675-6cbe-4639-8f67-8c2e395d7683}\rp811\a0098296.exe
(DELETED) Positive identification (DLL): Trojan.Win32.TopAntiSpyware.i (dll)
File: c:\system volume information\_restore{31414675-6cbe-4639-8f67-8c2e395d7683}\rp812\a0098426.dll
(DELETED) Positive identification: Trojan.Win32.TopAntiSpyware.i
File: c:\system volume information\_restore{31414675-6cbe-4639-8f67-8c2e395d7683}\rp812\a0098427.exe
(DELETED) Positive identification: TrojanDropper.Win32.Small.vn
File: c:\system volume information\_restore{31414675-6cbe-4639-8f67-8c2e395d7683}\rp812\a0098428.exe
(DELETED) Suspicious Filename: HTA file in suspicious location
File: c:\system volume information\_restore{31414675-6cbe-4639-8f67-8c2e395d7683}\rp812\a0098431.hta
(DELETED) Positive identification (DLL): TrojanDownloader.Win32.Agent.ga (dll)
File: c:\system volume information\_restore{31414675-6cbe-4639-8f67-8c2e395d7683}\rp812\a0098432.dll
(DELETED) Positive identification: TrojanDownloader.Win32.Small.aoa
File: c:\system volume information\_restore{31414675-6cbe-4639-8f67-8c2e395d7683}\rp812\a0098435.exe
(DELETED) Positive identification (DLL): Trojan.Win32.WebSearch.i (dll)
File: c:\system volume information\_restore{31414675-6cbe-4639-8f67-8c2e395d7683}\rp812\a0098439.dll
(DELETED) Positive identification: Trojan.Win32.WebSearch.i
File: c:\system volume information\_restore{31414675-6cbe-4639-8f67-8c2e395d7683}\rp812\a0098440.exe
(DELETED) Positive identification (DLL): Trojan.Win32.WebSearch.i1 (dll)
File: c:\system volume information\_restore{31414675-6cbe-4639-8f67-8c2e395d7683}\rp812\a0098441.dll
(DELETED) Positive identification (DLL): Trojan.Win32.WebSearch.i (dll)
File: c:\system volume information\_restore{31414675-6cbe-4639-8f67-8c2e395d7683}\rp813\a0098485.dll
(DELETED) Positive identification: Trojan.Win32.WebSearch.i
File: c:\system volume information\_restore{31414675-6cbe-4639-8f67-8c2e395d7683}\rp813\a0098486.exe
(DELETED) Positive identification (DLL): Trojan.Win32.WebSearch.i1 (dll)
File: c:\system volume information\_restore{31414675-6cbe-4639-8f67-8c2e395d7683}\rp813\a0098487.dll
(DELETED) Positive identification (DLL): Trojan.Win32.WebSearch.i (dll)
File: c:\system volume information\_restore{31414675-6cbe-4639-8f67-8c2e395d7683}\rp813\a0098488.dll
(DELETED) Positive identification: Trojan.Win32.WebSearch.i
File: c:\system volume information\_restore{31414675-6cbe-4639-8f67-8c2e395d7683}\rp813\a0098489.exe
(DELETED) Positive identification (DLL): Trojan.Win32.WebSearch.i1 (dll)
File: c:\system volume information\_restore{31414675-6cbe-4639-8f67-8c2e395d7683}\rp813\a0098490.dll
(DELETED) Positive identification (DLL): Trojan.Win32.WebSearch.i (dll)
File: c:\system volume information\_restore{31414675-6cbe-4639-8f67-8c2e395d7683}\rp813\a0098491.dll
(DELETED) Positive identification: Trojan.Win32.WebSearch.i
File: c:\system volume information\_restore{31414675-6cbe-4639-8f67-8c2e395d7683}\rp813\a0098492.exe
(DELETED) Positive identification (DLL): Trojan.Win32.WebSearch.i1 (dll)
File: c:\system volume information\_restore{31414675-6cbe-4639-8f67-8c2e395d7683}\rp813\a0098493.dll
(DELETED) Positive identification (DLL): Trojan.Win32.WebSearch.i (dll)
File: c:\system volume information\_restore{31414675-6cbe-4639-8f67-8c2e395d7683}\rp813\a0098494.dll
(DELETED) Positive identification: Trojan.Win32.WebSearch.i
File: c:\system volume information\_restore{31414675-6cbe-4639-8f67-8c2e395d7683}\rp813\a0098495.exe
(DELETED) Positive identification (DLL): Trojan.Win32.WebSearch.i1 (dll)
File: c:\system volume information\_restore{31414675-6cbe-4639-8f67-8c2e395d7683}\rp813\a0098496.dll
(DELETED) Positive identification (DLL): Trojan.Win32.WebSearch.i (dll)
File: c:\system volume information\_restore{31414675-6cbe-4639-8f67-8c2e395d7683}\rp813\a0098497.dll
(DELETED) Positive identification: Trojan.Win32.WebSearch.i
File: c:\system volume information\_restore{31414675-6cbe-4639-8f67-8c2e395d7683}\rp813\a0098498.exe
(DELETED) Positive identification (DLL): Trojan.Win32.WebSearch.i1 (dll)
File: c:\system volume information\_restore{31414675-6cbe-4639-8f67-8c2e395d7683}\rp813\a0098499.dll
(DELETED) Positive identification (DLL): Trojan.Win32.WebSearch.i (dll)
File: c:\system volume information\_restore{31414675-6cbe-4639-8f67-8c2e395d7683}\rp813\a0098500.dll
(DELETED) Positive identification: Trojan.Win32.WebSearch.i
File: c:\system volume information\_restore{31414675-6cbe-4639-8f67-8c2e395d7683}\rp813\a0098501.exe
(DELETED) Positive identification (DLL): Trojan.Win32.WebSearch.i1 (dll)
File: c:\system volume information\_restore{31414675-6cbe-4639-8f67-8c2e395d7683}\rp813\a0098502.dll
(DELETED) Positive identification (DLL): Trojan.Win32.WebSearch.i (dll)
File: c:\system volume information\_restore{31414675-6cbe-4639-8f67-8c2e395d7683}\rp813\a0098503.dll
(DELETED) Positive identification: Trojan.Win32.WebSearch.i
File: c:\system volume information\_restore{31414675-6cbe-4639-8f67-8c2e395d7683}\rp813\a0098504.exe
(DELETED) Positive identification (DLL): Trojan.Win32.WebSearch.i1 (dll)
File: c:\system volume information\_restore{31414675-6cbe-4639-8f67-8c2e395d7683}\rp813\a0098505.dll
(DELETED) Positive identification (DLL): Trojan.Win32.WebSearch.i (dll)
File: c:\system volume information\_restore{31414675-6cbe-4639-8f67-8c2e395d7683}\rp813\a0098506.dll
(DELETED) Positive identification: Trojan.Win32.WebSearch.i
File: c:\system volume information\_restore{31414675-6cbe-4639-8f67-8c2e395d7683}\rp813\a0098507.exe
(DELETED) Positive identification (DLL): Trojan.Win32.WebSearch.i1 (dll)
File: c:\system volume information\_restore{31414675-6cbe-4639-8f67-8c2e395d7683}\rp813\a0098508.dll
(DELETED) Positive identification (DLL): Trojan.Win32.WebSearch.i (dll)
File: c:\system volume information\_restore{31414675-6cbe-4639-8f67-8c2e395d7683}\rp813\a0098509.dll
(DELETED) Positive identification: Trojan.Win32.WebSearch.i
File: c:\system volume information\_restore{31414675-6cbe-4639-8f67-8c2e395d7683}\rp813\a0098510.exe
(DELETED) Positive identification (DLL): Trojan.Win32.WebSearch.i1 (dll)
File: c:\system volume information\_restore{31414675-6cbe-4639-8f67-8c2e395d7683}\rp813\a0098511.dll
(DELETED) Positive identification (DLL): Trojan.Win32.WebSearch.i (dll)
File: c:\system volume information\_restore{31414675-6cbe-4639-8f67-8c2e395d7683}\rp813\a0098512.dll
(DELETED) Positive identification: Trojan.Win32.WebSearch.i
File: c:\system volume information\_restore{31414675-6cbe-4639-8f67-8c2e395d7683}\rp813\a0098513.exe
(DELETED) Positive identification (DLL): Trojan.Win32.WebSearch.i1 (dll)
File: c:\system volume information\_restore{31414675-6cbe-4639-8f67-8c2e395d7683}\rp813\a0098514.dll
(DELETED) Positive identification (DLL): Trojan.Win32.WebSearch.i (dll)
File: c:\system volume information\_restore{31414675-6cbe-4639-8f67-8c2e395d7683}\rp813\a0098515.dll
(DELETED) Positive identification: Trojan.Win32.WebSearch.i
File: c:\system volume information\_restore{31414675-6cbe-4639-8f67-8c2e395d7683}\rp813\a0098516.exe
(DELETED) Positive identification (DLL): Trojan.Win32.WebSearch.i1 (dll)
File: c:\system volume information\_restore{31414675-6cbe-4639-8f67-8c2e395d7683}\rp813\a0098517.dll
(DELETED) Positive identification (DLL): Trojan.Win32.WebSearch.i (dll)
File: c:\system volume information\_restore{31414675-6cbe-4639-8f67-8c2e395d7683}\rp813\a0098518.dll
(DELETED) Positive identification: Trojan.Win32.WebSearch.i
File: c:\system volume information\_restore{31414675-6cbe-4639-8f67-8c2e395d7683}\rp813\a0098519.exe
(DELETED) Positive identification (DLL): Trojan.Win32.WebSearch.i1 (dll)
File: c:\system volume information\_restore{31414675-6cbe-4639-8f67-8c2e395d7683}\rp813\a0098520.dll
(DELETED) Positive identification (DLL): Trojan.Win32.WebSearch.i (dll)
File: c:\system volume information\_restore{31414675-6cbe-4639-8f67-8c2e395d7683}\rp813\a0098521.dll
(DELETED) Positive identification: Trojan.Win32.WebSearch.i
File: c:\system volume information\_restore{31414675-6cbe-4639-8f67-8c2e395d7683}\rp813\a0098522.exe
(DELETED) Positive identification (DLL): Trojan.Win32.WebSearch.i1 (dll)
File: c:\system volume information\_restore{31414675-6cbe-4639-8f67-8c2e395d7683}\rp813\a0098523.dll
(DELETED) Positive identification (DLL): Trojan.Win32.WebSearch.i (dll)
File: c:\system volume information\_restore{31414675-6cbe-4639-8f67-8c2e395d7683}\rp813\a0098524.dll
(DELETED) Positive identification: Trojan.Win32.WebSearch.i
File: c:\system volume information\_restore{31414675-6cbe-4639-8f67-8c2e395d7683}\rp813\a0098525.exe
(DELETED) Positive identification (DLL): Trojan.Win32.WebSearch.i1 (dll)
File: c:\system volume information\_restore{31414675-6cbe-4639-8f67-8c2e395d7683}\rp813\a0098526.dll
(DELETED) Positive identification (DLL): Trojan.Win32.WebSearch.i (dll)
File: c:\system volume information\_restore{31414675-6cbe-4639-8f67-8c2e395d7683}\rp813\a0098527.dll
(DELETED) Positive identification: Trojan.Win32.WebSearch.i
File: c:\system volume information\_restore{31414675-6cbe-4639-8f67-8c2e395d7683}\rp813\a0098528.exe
(DELETED) Positive identification (DLL): Trojan.Win32.WebSearch.i1 (dll)
File: c:\system volume information\_restore{31414675-6cbe-4639-8f67-8c2e395d7683}\rp813\a0098529.dll
(DELETED) Positive identification (DLL): Trojan.Win32.WebSearch.i (dll)
File: c:\system volume information\_restore{31414675-6cbe-4639-8f67-8c2e395d7683}\rp813\a0098530.dll
(DELETED) Positive identification: Trojan.Win32.WebSearch.i
File: c:\system volume information\_restore{31414675-6cbe-4639-8f67-8c2e395d7683}\rp813\a0098531.exe
(DELETED) Positive identification (DLL): Trojan.Win32.WebSearch.i1 (dll)
File: c:\system volume information\_restore{31414675-6cbe-4639-8f67-8c2e395d7683}\rp813\a0098532.dll
(DELETED) Positive identification (DLL): Trojan.Win32.WebSearch.i2 (dll)
File: c:\system volume information\_restore{31414675-6cbe-4639-8f67-8c2e395d7683}\rp825\a0101123.dll
(DELETED) Positive identification (DLL): Trojan.Win32.WebSearch.i2 (dll)
File: c:\system volume information\_restore{31414675-6cbe-4639-8f67-8c2e395d7683}\rp825\a0101243.dll
(DELETED) Positive identification (DLL): Trojan.Win32.WebSearch.i2 (dll)
File: c:\system volume information\_restore{31414675-6cbe-4639-8f67-8c2e395d7683}\rp825\a0103244.dll
(DELETED) Positive identification (DLL): Trojan.Win32.WebSearch.i2 (dll)
File: c:\system volume information\_restore{31414675-6cbe-4639-8f67-8c2e395d7683}\rp825\a0103276.dll
(DELETED) Positive identification (DLL): Trojan.Win32.WebSearch.i2 (dll)
File: c:\system volume information\_restore{31414675-6cbe-4639-8f67-8c2e395d7683}\rp826\a0104325.dll
(DELETED) Positive identification (DLL): Trojan.Win32.WebSearch.i2 (dll)
File: c:\system volume information\_restore{31414675-6cbe-4639-8f67-8c2e395d7683}\rp827\a0105387.dll
(DELETED) Positive identification (DLL): Trojan.Win32.WebSearch.i2 (dll)
File: c:\system volume information\_restore{31414675-6cbe-4639-8f67-8c2e395d7683}\rp827\a0105405.dll
(DELETED) Positive identification (DLL): Trojan.Win32.WebSearch.i2 (dll)
File: c:\system volume information\_restore{31414675-6cbe-4639-8f67-8c2e395d7683}\rp827\a0106445.dll
(DELETED) Positive identification (embedded in file): Trojan.Win32.WebSearch.i2 (dll)
File: c:\system volume information\_restore{31414675-6cbe-4639-8f67-8c2e395d7683}\rp827\a0106446.exe
(DELETED) Positive identification: Trojan.Win32.WebSearch.i2
File: c:\system volume information\_restore{31414675-6cbe-4639-8f67-8c2e395d7683}\rp827\a0106446.exe
(DELETED) Positive identification: Trojan.Win32.WebSearch.i3
File: c:\system volume information\_restore{31414675-6cbe-4639-8f67-8c2e395d7683}\rp827\a0106448.exe
(DELETED) Positive identification (DLL): Trojan.Win32.WebSearch.i2 (dll)
File: c:\system volume information\_restore{31414675-6cbe-4639-8f67-8c2e395d7683}\rp827\a0106450.dll
(DELETED) Positive identification (embedded in file): Trojan.Win32.WebSearch.i2 (dll)
File: c:\system volume information\_restore{31414675-6cbe-4639-8f67-8c2e395d7683}\rp827\a0106451.exe
(DELETED) Positive identification: Trojan.Win32.WebSearch.i2
File: c:\system volume information\_restore{31414675-6cbe-4639-8f67-8c2e395d7683}\rp827\a0106451.exe
(DELETED) Positive identification: Trojan.Win32.WebSearch.i3
File: c:\system volume information\_restore{31414675-6cbe-4639-8f67-8c2e395d7683}\rp827\a0106453.exe
(DELETED) Positive identification (DLL): Trojan.Win32.WebSearch.i2 (dll)
File: c:\system volume information\_restore{31414675-6cbe-4639-8f67-8c2e395d7683}\rp827\a0106455.dll
(DELETED) Positive identification (embedded in file): Trojan.Win32.WebSearch.i2 (dll)
File: c:\system volume information\_restore{31414675-6cbe-4639-8f67-8c2e395d7683}\rp827\a0106456.exe
(DELETED) Positive identification: Trojan.Win32.WebSearch.i2
File: c:\system volume information\_restore{31414675-6cbe-4639-8f67-8c2e395d7683}\rp827\a0106456.exe
(DELETED) Positive identification: Trojan.Win32.WebSearch.i3
File: c:\system volume information\_restore{31414675-6cbe-4639-8f67-8c2e395d7683}\rp827\a0106458.exe
(DELETED) Positive identification (DLL): Trojan.Win32.WebSearch.i2 (dll)
File: c:\system volume information\_restore{31414675-6cbe-4639-8f67-8c2e395d7683}\rp827\a0106460.dll
(DELETED) Positive identification (embedded in file): Trojan.Win32.WebSearch.i2 (dll)
File: c:\system volume information\_restore{31414675-6cbe-4639-8f67-8c2e395d7683}\rp827\a0106461.exe
(DELETED) Positive identification: Trojan.Win32.WebSearch.i2
File: c:\system volume information\_restore{31414675-6cbe-4639-8f67-8c2e395d7683}\rp827\a0106461.exe
(DELETED) Positive identification: Trojan.Win32.WebSearch.i3
File: c:\system volume information\_restore{31414675-6cbe-4639-8f67-8c2e395d7683}\rp827\a0106463.exe
(DELETED) Positive identification (DLL): Trojan.Win32.WebSearch.i2 (dll)
File: c:\system volume information\_restore{31414675-6cbe-4639-8f67-8c2e395d7683}\rp827\a0106465.dll
(DELETED) Positive identification (embedded in file): Trojan.Win32.WebSearch.i2 (dll)
File: c:\system volume information\_restore{31414675-6cbe-4639-8f67-8c2e395d7683}\rp827\a0106466.exe
(DELETED) Positive identification: Trojan.Win32.WebSearch.i2
File: c:\system volume information\_restore{31414675-6cbe-4639-8f67-8c2e395d7683}\rp827\a0106466.exe
(DELETED) Positive identification: Trojan.Win32.WebSearch.i3
File: c:\system volume information\_restore{31414675-6cbe-4639-8f67-8c2e395d7683}\rp827\a0106468.exe
(DELETED) Positive identification (DLL): Trojan.Win32.WebSearch.i2 (dll)
File: c:\system volume information\_restore{31414675-6cbe-4639-8f67-8c2e395d7683}\rp827\a0106470.dll
(DELETED) Positive identification (embedded in file): Trojan.Win32.WebSearch.i2 (dll)
File: c:\system volume information\_restore{31414675-6cbe-4639-8f67-8c2e395d7683}\rp827\a0106471.exe
(DELETED) Positive identification: Trojan.Win32.WebSearch.i2
File: c:\system volume information\_restore{31414675-6cbe-4639-8f67-8c2e395d7683}\rp827\a0106471.exe
(DELETED) Positive identification: Trojan.Win32.WebSearch.i3
File: c:\system volume information\_restore{31414675-6cbe-4639-8f67-8c2e395d7683}\rp827\a0106473.exe
(DELETED) Positive identification (embedded in file): Trojan.Win32.WebSearch.i2 (dll)
File: c:\system volume information\_restore{31414675-6cbe-4639-8f67-8c2e395d7683}\rp827\a0106475.exe
(DELETED) Positive identification: Trojan.Win32.WebSearch.i2
File: c:\system volume information\_restore{31414675-6cbe-4639-8f67-8c2e395d7683}\rp827\a0106475.exe
(DELETED) Positive identification: Trojan.Win32.WebSearch.i3
File: c:\system volume information\_restore{31414675-6cbe-4639-8f67-8c2e395d7683}\rp827\a0106477.exe
(DELETED) Positive identification (DLL): Trojan.Win32.WebSearch.i2 (dll)
File: c:\system volume information\_restore{31414675-6cbe-4639-8f67-8c2e395d7683}\rp827\a0106479.dll
(DELETED) Positive identification (embedded in file): Trojan.Win32.WebSearch.i2 (dll)
File: c:\system volume information\_restore{31414675-6cbe-4639-8f67-8c2e395d7683}\rp827\a0106480.exe
(DELETED) Positive identification: Trojan.Win32.WebSearch.i2
File: c:\system volume information\_restore{31414675-6cbe-4639-8f67-8c2e395d7683}\rp827\a0106480.exe
(DELETED) Positive identification: Trojan.Win32.WebSearch.i3
File: c:\system volume information\_restore{31414675-6cbe-4639-8f67-8c2e395d7683}\rp827\a0106482.exe
(DELETED) Positive identification (DLL): Trojan.Win32.WebSearch.i2 (dll)
File: c:\system volume information\_restore{31414675-6cbe-4639-8f67-8c2e395d7683}\rp827\a0106484.dll
(DELETED) Positive identification (embedded in file): Trojan.Win32.WebSearch.i2 (dll)
File: c:\system volume information\_restore{31414675-6cbe-4639-8f67-8c2e395d7683}\rp827\a0106485.exe
(DELETED) Positive identification: Trojan.Win32.WebSearch.i2
File: c:\system volume information\_restore{31414675-6cbe-4639-8f67-8c2e395d7683}\rp827\a0106485.exe
(DELETED) Positive identification: Trojan.Win32.WebSearch.i3
File: c:\system volume information\_restore{31414675-6cbe-4639-8f67-8c2e395d7683}\rp827\a0106487.exe
(DELETED) Positive identification (embedded in file): Trojan.Win32.WebSearch.i2 (dll)
File: c:\system volume information\_restore{31414675-6cbe-4639-8f67-8c2e395d7683}\rp827\a0106489.exe
(DELETED) Positive identification: Trojan.Win32.WebSearch.i2
File: c:\system volume information\_restore{31414675-6cbe-4639-8f67-8c2e395d7683}\rp827\a0106489.exe
(DELETED) Positive identification: Trojan.Win32.WebSearch.i3
File: c:\system volume information\_restore{31414675-6cbe-4639-8f67-8c2e395d7683}\rp827\a0106491.exe
(DELETED) Positive identification (DLL): Trojan.Win32.WebSearch.i2 (dll)
File: c:\system volume information\_restore{31414675-6cbe-4639-8f67-8c2e395d7683}\rp827\a0106493.dll
(DELETED) Positive identification (embedded in file): Trojan.Win32.WebSearch.i2 (dll)
File: c:\system volume information\_restore{31414675-6cbe-4639-8f67-8c2e395d7683}\rp827\a0106494.exe
(DELETED) Positive identification: Trojan.Win32.WebSearch.i2
File: c:\system volume information\_restore{31414675-6cbe-4639-8f67-8c2e395d7683}\rp827\a0106494.exe
(DELETED) Positive identification: Trojan.Win32.WebSearch.i3
File: c:\system volume information\_restore{31414675-6cbe-4639-8f67-8c2e395d7683}\rp827\a0106496.exe
(DELETED) Positive identification (embedded in file): Trojan.Win32.WebSearch.i2 (dll)
File: c:\system volume information\_restore{31414675-6cbe-4639-8f67-8c2e395d7683}\rp827\a0106498.exe
(DELETED) Positive identification: Trojan.Win32.WebSearch.i2
File: c:\system volume information\_restore{31414675-6cbe-4639-8f67-8c2e395d7683}\rp827\a0106498.exe
(DELETED) Positive identification: Trojan.Win32.WebSearch.i3
File: c:\system volume information\_restore{31414675-6cbe-4639-8f67-8c2e395d7683}\rp827\a0106500.exe
(DELETED) Positive identification (DLL): Trojan.Win32.WebSearch.i2 (dll)
File: c:\system volume information\_restore{31414675-6cbe-4639-8f67-8c2e395d7683}\rp827\a0106503.dll
(DELETED) Positive identification (embedded in file): Trojan.Win32.WebSearch.i2 (dll)
File: c:\system volume information\_restore{31414675-6cbe-4639-8f67-8c2e395d7683}\rp827\a0106504.exe
(DELETED) Positive identification: Trojan.Win32.WebSearch.i2
File: c:\system volume information\_restore{31414675-6cbe-4639-8f67-8c2e395d7683}\rp827\a0106504.exe
(DELETED) Positive identification: Trojan.Win32.WebSearch.i3
File: c:\system volume information\_restore{31414675-6cbe-4639-8f67-8c2e395d7683}\rp827\a0106506.exe
(DELETED) Positive identification (DLL): Trojan.Win32.WebSearch.i2 (dll)
File: c:\system volume information\_restore{31414675-6cbe-4639-8f67-8c2e395d7683}\rp827\a0106508.dll
(DELETED) Positive identification (embedded in file): Trojan.Win32.WebSearch.i2 (dll)
File: c:\system volume information\_restore{31414675-6cbe-4639-8f67-8c2e395d7683}\rp827\a0106509.exe
(DELETED) Positive identification: Trojan.Win32.WebSearch.i2
File: c:\system volume information\_restore{31414675-6cbe-4639-8f67-8c2e395d7683}\rp827\a0106509.exe
(DELETED) Positive identification: Trojan.Win32.WebSearch.i3
File: c:\system volume information\_restore{31414675-6cbe-4639-8f67-8c2e395d7683}\rp827\a0106511.exe
(DELETED) Positive identification (DLL): Trojan.Win32.WebSearch.i2 (dll)
File: c:\system volume information\_restore{31414675-6cbe-4639-8f67-8c2e395d7683}\rp827\a0106513.dll
(DELETED) Positive identification (embedded in file): Trojan.Win32.WebSearch.i2 (dll)
File: c:\system volume information\_restore{31414675-6cbe-4639-8f67-8c2e395d7683}\rp827\a0106514.exe
(DELETED) Positive identification: Trojan.Win32.WebSearch.i2
File: c:\system volume information\_restore{31414675-6cbe-4639-8f67-8c2e395d7683}\rp827\a0106514.exe
(DELETED) Positive identification: Trojan.Win32.WebSearch.i3
File: c:\system volume information\_restore{31414675-6cbe-4639-8f67-8c2e395d7683}\rp827\a0106516.exe
(DELETED) Positive identification: Trojan.Win32.TopAntiSpyware.i
File: c:\system volume information\_restore{31414675-6cbe-4639-8f67-8c2e395d7683}\rp827\a0106518.exe
(DELETED) Positive identification (DLL): TrojanDownloader.Win32.Agent.kf1 (dll)
File: c:\windows\wldr.dll
(DELETED) Positive identification (DLL): TrojanDownloader.Win32.Small.aoa (dll)
File: c:\windows\system32\srdrv32.dll
(DELETED) Positive identification (DLL): Trojan.Win32.TopAntiSpyware.i (dll)
File: c:\windows\system32\srpcsrv32.dll
(DELETED) Positive identification (DLL): TrojanDownloader.Win32.Small.aoa (dll)
File: c:\windows\system32\srvc32.dll
(DELETED) Positive identification (DLL): Trojan.Win32.TopAntiSpyware.i (dll)
File: c:\windows\system32\txfdb32.dll
(DELETED) Positive identification (DLL): TrojanDownloader.Win32.Agent.kf1 (dll)
File: c:\windows\system32\wldr.dll
(DELETED) Positive identification: TrojanDropper.Win32.Small.uy
File: c:\windows\system32\x.exe
(DELETED) Positive identification (DLL): Adware.WildTangent.b (dll)
File: c:\windows\wt\wtvh.dll