清理或破坏病毒流氓若干

http://about.blank.la
http://Qyule.com
http://591ani.cn

//--1------------

591ani.cn清理:网上未发现有用资料,以下均为自己胡整。

system32目录下有个arpcb.exe的自解压压缩包,里面的内容有jopen.vbs,npf.sys,Packet.dll,run.bat,wanpacket.dll和wpcap.dll。故把arpcb.exe删除,system32下的这些解压出来的文件也以并删除。

另外还发现有各downloadpath0.txt文件,内容

[path]
http://wm.591ani.cn/fz/systemabc.vbs   v1
http://wm.591ani.cn/Game.exe  v1
http://wm.591ani.cn/fz/iis.exe v1
http://wm.591ani.cn/fz/nsettop.exe v1
[killprocess]
RavMonD.exe
RavMon.exe
RavTask.exe
RavStub.exe
UIHost.exe
KRegEx.exe
Navapw32.exe
Navapsvc.exe
NMain.exe
navw32.EXE
KVFW.EXE
KAVSvcUI.exe
KAVPFW.EXE
KAV32.exe
TrojDie.kxp
KVSrvXP.exe
KvXP.kxp
KVMonXP.kxp
KVwsc.exe
KAVsvc.exe
KWatchUI.EXE
Iparmor.exe
TrojanHunter.exe
THGUARD.EXE
EGHOST.EXE
MAILMON.EXE
yassistse.exe
gfosdg.exe
mpnxyl.exe
KVSrvXp_1.exe
RRfwMain.exe
kavstart.exe
KVCenter.kxp
kvolself.exe
MSKAGENT.exe
MCVSESCN.exe
RfwMain.exe
KpopMon.exe
CCenter.exe
KVMonXP.exe
Nvsvc32.exe
Rtvscan.exe
KAVPLUS.exe
MCAGENT.exe
SHSTAT.exe
VPTray.exe
CCAPP.exe
TBMon.exe
qqav.exe
adam.exe
KVOL.exe
Kav.exe
mmsk.exe
SREng.exe
MagicSet.exe
360Safe.exe
runiep.exe
kabaload.exe
WoptiClean.exe
SREng.exe
360tray.exe
AntiArp.exe
RsAgent.exe
KWatch.EXE
KPFW32.EXE
AgentSrv.exe
Frogagent.exe
KvDetect.exe
GameSetup.exe
[protectprocess]
pk1.exe
pk2.exe
pk3.exe
pk4.exe
pk5.exe
pk6.exe
[proveddelete]
pd1.exe
pd2.exe
pd3.exe
pd4.exe
pd5.exe
pd6.exe
[end]

不用说,删。连[path],[protectprocess],[proveddelete]项下的那些文件,一经发现,删无赦。[killprocess]下的文件就不要动了,这些都是病毒的对头。

 

//--2--------------

另外还发现system32下有文件wwwzw.ini和zzwzz.ini。打开,把里面列的那些文件删除,此两个文件也删了。

wwwzw.ini的内容

[settings]
ID=71
hasdown=dodolook391.exe;dodolook391.exe;bind_50467.exe;ad_2225.exe;5d009.exe;UUSEE_digital_Setup_8.exe;maa.exe;my_70074.exe;12d009.exe;yuhan.exe;f.exe;

zzwzz.ini的内容

[settings]
hasdown=setup237.exe;dodolook406.exe;my_70200.exe;ad_2238.exe;mgoogle.exe;
currentday=2007-08-05
currentIP=
haspop=

//--3------------------
IE页面顶部都有qyule的连接图片等,暂时的解决方法

打开internet选项,程序页,点击下面的管理加载项按钮。也不清楚是哪个,就把可以的都禁用了。问题(暂时)解决。

清理或破坏病毒流氓若干_第1张图片

//--4--------------

删除的可疑文件(前几日已删除无数,没有记录,下面的只是今天的,这些文件avast都没有检测出来是病毒):

C:/Windows目录下:

003.exe
d16.exe
d070.exe
uda.exe
yuhan.exe
iun6002.exe
12d001.exe
setup237.exe
mgoogle.exe
SET8.tmp
SET3.tmp
SET4.tmp
QTFont.for
erttersbar.dll
sss.dll
video.dll

 

C:/WINDOWS/System32目录下

5.exe
4.exe
d03.exe
d3d8.dll
downloadpath0.txt
QQDownload.exe
fuck.exe
viking.exe
wwwzw.ini
sysfuck.exe
zzwzz.ini
iis.exe
arpcb.exe
jopen.vbs
run.bat
npf.sys
Packet.dll
WanPacket.dll
wpcap.dll
nsettop.exe
wdbini.dll
ztkini.dll
mohgcyiai.dll

 

//--5--------------

可能是我前几天删除的文件

c:/windows/system32/djkk.exe
C:/WINDOWS/system32/drivers/acpidisk.sys
C:/WINDOWS/system32/drivers/daidgccd.sys
C:/WINDOWS/system32/drivers/dbdjgdij.sys
C:/WINDOWS/system32/drivers/EntDrv51.sys

//--6-----------------

avast的日志中的病毒

2007-8-10 10:22:31 new 2712 Sign of "Win32:Cinmus-D [Adw]" has been found in "c:/documents and settings/all users/application data/microsoft/pctools/pctools.dll" file. 
2007-8-10 10:23:05 new 2712 Sign of "Win32:Lmir-KB [Trj]" has been found in "c:/windows/system32/mswsock30.dll/[NsPack]" file. 
2007-8-10 10:23:08 new 2712 Sign of "Win32:Agent-HJW [Trj]" has been found in "c:/windows/system32/remotedbg.dll/[PECompact]" file. 
2007-8-10 10:28:16 SYSTEM 1228 Sign of "Win32:Cinmus-D [Adw]" has been found in "C:/WINDOWS/System32/msplrct.dll" file. 
2007-8-10 10:28:16 SYSTEM 1228 Sign of "Win32:Cinmus-D [Adw]" has been found in "C:/WINDOWS/system32/msplrct.dll" file. 
2007-8-10 10:30:35 new 3988 Sign of "Win32:Cinmus-H [Adw]" has been found in "C:/WINDOWS/system32/drivers/acpidisk.sys" file. 
2007-8-10 10:31:55 new 3988 Sign of "Win32:Delf-DQP [Trj]" has been found in "C:/WINDOWS/system32/arpcb.exe/qq.exe" file. 
2007-8-10 10:32:27 new 3988 Sign of "Win32:Agent-HUT [Wrm]" has been found in "C:/WINDOWS/system32/新建文件夹/djkk.exe/[NsPack]" file. 
2007-8-10 10:32:28 new 3988 Sign of "Win32:Agent-JRM [Trj]" has been found in "C:/WINDOWS/system32/pqwq6c4l.dll" file. 
2007-8-10 10:32:29 new 3020 Sign of "Win32:Boran-N [Adw]" has been found in "c:/program files/ezfs/ojpc.dll" file. 
2007-8-10 10:32:29 new 3988 Sign of "Win32:Small-HHY [Trj]" has been found in "C:/WINDOWS/system32/wdbpri.dll_" file. 
2007-8-10 10:32:37 new 3988 Sign of "Win32:Delf-FKI [Trj]" has been found in "C:/WINDOWS/system32/ppinjyldqbywx.dll" file. 
2007-8-10 10:32:37 new 3988 Sign of "Win32:Delf-FKI [Trj]" has been found in "C:/WINDOWS/system32/yzvkmutvfdadx.dll" file. 
2007-8-10 10:32:37 new 3988 Sign of "Win32:Delf-FKI [Trj]" has been found in "C:/WINDOWS/system32/midbxsmundzcl.dll" file. 
2007-8-10 10:32:37 new 3988 Sign of "Win32:Lmir-KB [Trj]" has been found in "C:/WINDOWS/system32/WSP_Fix.dll/[NsPack]" file. 
2007-8-10 10:32:38 new 3988 Sign of "Win32:Ieser-J [Trj]" has been found in "C:/WINDOWS/system32/jrxngnxppjcgr.dll" file. 
2007-8-10 10:33:23 new 3988 Sign of "Win32:Adware-gen. [Adw]" has been found in "C:/WINDOWS/Temp/4FED3553.exe/$COMMONFILES/CPUSH/cpush.dll" file. 
2007-8-10 10:33:24 new 3988 Sign of "Win32:Cinmus-G [Adw]" has been found in "C:/WINDOWS/Temp/3F36168D.exe/$TEMP/$TEMP/dosss11.dll" file. 
2007-8-10 10:33:24 new 3988 Sign of "Win32:Cinmus-H [Adw]" has been found in "C:/WINDOWS/Temp/3F36168D.exe/$TEMP/acpidisk.sys" file. 
2007-8-10 10:33:24 new 3988 Sign of "Win32:Cinmus-G [Adw]" has been found in "C:/WINDOWS/Temp/dosss11.dll" file. 
2007-8-10 10:33:24 new 3988 Sign of "Win32:Adware-gen. [Adw]" has been found in "C:/WINDOWS/Temp/27/cndsv.dll" file. 
2007-8-10 10:33:24 new 3988 Sign of "Win32:Adware-gen. [Adw]" has been found in "C:/WINDOWS/Temp/27/cnprov.sys/[Embedded#0c158]" file. 
2007-8-10 10:33:24 new 3988 Sign of "Win32:Adware-gen. [Adw]" has been found in "C:/WINDOWS/Temp/27/cnprovh.dll" file. 
2007-8-10 10:33:24 new 3988 Sign of "Win32:Adware-gen. [Adw]" has been found in "C:/WINDOWS/Temp/27/config.exe" file. 
2007-8-10 10:33:24 new 3988 Sign of "Win32:Adware-gen. [Adw]" has been found in "C:/WINDOWS/Temp/27/convs.dll" file. 
2007-8-10 10:33:24 new 3988 Sign of "Win32:Adware-gen. [Adw]" has been found in "C:/WINDOWS/Temp/27/idnreg.dll" file. 
2007-8-10 10:33:24 new 3988 Sign of "Win32:Adware-gen. [Adw]" has been found in "C:/WINDOWS/Temp/27/idnsvr.dll" file. 
2007-8-10 10:33:24 new 3988 Sign of "Win32:Adware-gen. [Adw]" has been found in "C:/WINDOWS/Temp/27/idnsvr.exe" file. 
2007-8-10 10:33:24 new 3988 Sign of "Win32:Adware-gen. [Adw]" has been found in "C:/WINDOWS/Temp/27/ieaux.dll" file. 
2007-8-10 10:33:24 new 3988 Sign of "Win32:Adware-gen. [Adw]" has been found in "C:/WINDOWS/Temp/27/loader.exe/[Embedded#08040]" file. 
2007-8-10 10:33:24 new 3988 Sign of "Win32:Adware-gen. [Adw]" has been found in "C:/WINDOWS/Temp/27/loader.exe/[Embedded#0f040]" file. 
2007-8-10 10:33:24 new 3988 Sign of "Win32:Adware-gen. [Adw]" has been found in "C:/WINDOWS/Temp/27/setup.dll" file. 
2007-8-10 10:33:24 new 3988 Sign of "Win32:Adware-gen. [Adw]" has been found in "C:/WINDOWS/Temp/27/setup.exe" file. 
2007-8-10 10:33:24 new 3988 Sign of "Win32:Adware-gen. [Adw]" has been found in "C:/WINDOWS/Temp/27/uninstall.exe/[Embedded#14a54]" file. 
2007-8-10 10:33:24 new 3988 Sign of "Win32:Adware-gen. [Adw]" has been found in "C:/WINDOWS/Temp/29/cndsv.dll" file. 
2007-8-10 10:33:24 new 3988 Sign of "Win32:Adware-gen. [Adw]" has been found in "C:/WINDOWS/Temp/29/cnprov.sys/[Embedded#0c358]" file. 
2007-8-10 10:33:24 new 3988 Sign of "Win32:Adware-gen. [Adw]" has been found in "C:/WINDOWS/Temp/29/cnprovh.dll" file. 
2007-8-10 10:33:24 new 3988 Sign of "JS:Agent-B [Trj]" has been found in "C:/WINDOWS/Temp/29/cnrbtn.html" file. 
2007-8-10 10:33:24 new 3988 Sign of "Win32:Adware-gen. [Adw]" has been found in "C:/WINDOWS/Temp/29/config.exe" file. 
2007-8-10 10:33:24 new 3988 Sign of "Win32:Adware-gen. [Adw]" has been found in "C:/WINDOWS/Temp/29/convf.dll" file. 
2007-8-10 10:33:24 new 3988 Sign of "Win32:Adware-gen. [Adw]" has been found in "C:/WINDOWS/Temp/29/idnaux.sys" file. 
2007-8-10 10:33:24 new 3988 Sign of "Win32:Adware-gen. [Adw]" has been found in "C:/WINDOWS/Temp/29/idnreg.dll" file. 
2007-8-10 10:33:25 new 3988 Sign of "Win32:Adware-gen. [Adw]" has been found in "C:/WINDOWS/Temp/29/idnsvr.exe" file. 
2007-8-10 10:33:25 new 3988 Sign of "Win32:Adware-gen. [Adw]" has been found in "C:/WINDOWS/Temp/29/ieaux.dll" file. 
2007-8-10 10:33:25 new 3988 Sign of "Win32:Adware-gen. [Adw]" has been found in "C:/WINDOWS/Temp/29/setup.exe" file. 
2007-8-10 10:33:25 new 3988 Sign of "Win32:Adware-gen. [Adw]" has been found in "C:/WINDOWS/Temp/29/uninstall.exe/[Embedded#14a3c]" file. 
2007-8-10 10:33:25 new 3988 Sign of "Win32:Adware-gen. [Adw]" has been found in "C:/WINDOWS/Temp/nl23251e39.exe/[ASPack]/[Embedded#007040]" file. 
2007-8-10 10:36:05 new 3988 Sign of "Win32:Qqhelper-DE [Trj]" has been found in "C:/WINDOWS/QQIEHelper.dll/[UPX]" file. 
2007-8-10 10:36:06 new 3988 Sign of "Win32:Delf-FFM [Trj]" has been found in "C:/WINDOWS/kulionrx.dll" file. 
2007-8-10 10:36:06 new 3988 Sign of "Win32:Delf-FFM [Trj]" has been found in "C:/WINDOWS/kulionwl.dll" file. 
2007-8-10 10:36:06 new 3988 Sign of "Win32:Delf-FFM [Trj]" has been found in "C:/WINDOWS/kulionwm.dll" file. 
2007-8-10 10:36:06 new 3988 Sign of "Win32:Delf-FFM [Trj]" has been found in "C:/WINDOWS/kulionzx.dll" file. 
2007-8-10 10:36:06 new 3988 Sign of "Win32:Qqhelper-CY [Trj]" has been found in "C:/WINDOWS/KB/KB998013.log" file. 
2007-8-10 10:36:23 new 3988 Sign of "Win32:Cinmus-G [Adw]" has been found in "C:/WINDOWS/可疑文件/dodolook406.exe/$TEMP/$TEMP/1558.exe/$TEMP/DoSSSetup.dll" file. 
2007-8-10 10:36:23 new 3988 Sign of "Win32:Adware-gen. [Adw]" has been found in "C:/WINDOWS/可疑文件/dodolook406.exe/$TEMP/$TEMP/1558.exe" file. 
2007-8-10 10:36:23 new 3988 Sign of "Win32:Trojano-2575 [Trj]" has been found in "C:/WINDOWS/可疑文件/5d009.exe/$SYSDIR/netdde32.exe" file. 
2007-8-10 10:36:24 new 3988 Sign of "Win32:Cinmus-I [Adw]" has been found in "C:/WINDOWS/可疑文件/5d009.exe/$SYSDIR/d03.exe/$COMMONFILES/CPUSH/cpush.dll" file. 
2007-8-10 10:36:24 new 3988 Sign of "Win32:Adware-gen. [Adw]" has been found in "C:/WINDOWS/可疑文件/5d009.exe/$SYSDIR/d03.exe" file. 
2007-8-10 10:36:24 new 3988 Sign of "Win32:Trojano-2575 [Trj]" has been found in "C:/WINDOWS/可疑文件/12d009.exe/$SYSDIR/netdde32.exe" file. 
2007-8-10 10:36:24 new 3988 Sign of "Win32:Boran-M [Adw]" has been found in "C:/WINDOWS/可疑文件/ad_22.exe/$TEMP/Insshell.exe/[Embedded#2c3d8]" file. 
2007-8-10 10:36:24 new 3988 Sign of "Win32:Boran-N [Adw]" has been found in "C:/WINDOWS/可疑文件/ad_22.exe/$TEMP/Insshell.exe/[Embedded#493d8]" file. 
2007-8-10 10:36:24 new 3988 Sign of "Win32:Boran-N [Adw]" has been found in "C:/WINDOWS/可疑文件/ad_22.exe/$TEMP/Insshell.exe/[Embedded#a53d8]" file. 
2007-8-10 10:36:24 new 3988 Sign of "Win32:Boran-M [Adw]" has been found in "C:/WINDOWS/可疑文件/ad_22.exe/$TEMP/Insshell.exe" file. 
2007-8-10 10:36:24 new 3988 Sign of "Win32:Adware-gen. [Adw]" has been found in "C:/WINDOWS/可疑文件/ad_2225.exe/$TEMP/insshell.exe/[Embedded#093d8]" file. 
2007-8-10 10:36:24 new 3988 Sign of "Win32:Adware-gen. [Adw]" has been found in "C:/WINDOWS/可疑文件/ad_2225.exe/$TEMP/insshell.exe/[Embedded#303d8]" file. 
2007-8-10 10:36:24 new 3988 Sign of "Win32:Adware-gen. [Adw]" has been found in "C:/WINDOWS/可疑文件/ad_2225.exe/$TEMP/insshell.exe/[Embedded#4a3d8]" file. 
2007-8-10 10:36:24 new 3988 Sign of "Win32:Boran-N [Adw]" has been found in "C:/WINDOWS/可疑文件/ad_2225.exe/$TEMP/insshell.exe/[Embedded#683d8]" file. 
2007-8-10 10:36:24 new 3988 Sign of "Win32:Boran-N [Adw]" has been found in "C:/WINDOWS/可疑文件/ad_2225.exe/$TEMP/insshell.exe/[Embedded#903d8]" file. 
2007-8-10 10:36:24 new 3988 Sign of "Win32:Boran-N [Adw]" has been found in "C:/WINDOWS/可疑文件/ad_2225.exe/$TEMP/insshell.exe" file. 
2007-8-10 10:36:24 new 3988 Sign of "Win32:QQHelper-BN [Trj]" has been found in "C:/WINDOWS/可疑文件/bind_50467.exe" file. 
2007-8-10 10:36:24 new 3988 Sign of "Win32:Cinmus-I [Adw]" has been found in "C:/WINDOWS/可疑文件/d063.exe/$COMMONFILES/CPUSH/cpush.dll" file. 
2007-8-10 10:36:24 new 3988 Sign of "Win32:Cinmus-I [Adw]" has been found in "C:/WINDOWS/可疑文件/d064.exe/$COMMONFILES/CPUSH/cpush.dll" file. 
2007-8-10 10:36:24 new 3988 Sign of "Win32:Cinmus-I [Adw]" has been found in "C:/WINDOWS/可疑文件/d065.exe/$COMMONFILES/CPUSH/cpush.dll" file. 
2007-8-10 10:36:24 new 3988 Sign of "Win32:Cinmus-I [Adw]" has been found in "C:/WINDOWS/可疑文件/d066.exe/$COMMONFILES/CPUSH/cpush.dll" file. 
2007-8-10 10:36:24 new 3988 Sign of "Win32:Cinmus-I [Adw]" has been found in "C:/WINDOWS/可疑文件/d067.exe/$COMMONFILES/CPUSH/cpush.dll" file. 
2007-8-10 10:36:25 new 3988 Sign of "Win32:Cinmus-I [Adw]" has been found in "C:/WINDOWS/可疑文件/d068.exe/$COMMONFILES/CPUSH/cpush.dll" file. 
2007-8-10 10:36:25 new 3988 Sign of "Win32:Cinmus-I [Adw]" has been found in "C:/WINDOWS/可疑文件/d069.exe/$COMMONFILES/CPUSH/cpush.dll" file. 
2007-8-10 10:36:25 new 3988 Sign of "Win32:Cinmus-G [Adw]" has been found in "C:/WINDOWS/可疑文件/dodolook391.exe/$TEMP/$TEMP/1208.exe/$TEMP/DoSSSetup.dll" file. 
2007-8-10 10:36:25 new 3988 Sign of "Win32:Cinmus-H [Adw]" has been found in "C:/WINDOWS/可疑文件/dodolook391.exe/$TEMP/$TEMP/1208.exe/$TEMP/acpidisk.sys" file. 
2007-8-10 10:36:25 new 3988 Sign of "Win32:Adware-gen. [Adw]" has been found in "C:/WINDOWS/可疑文件/dodolook391.exe/$TEMP/$TEMP/1208.exe" file. 
2007-8-10 10:36:25 new 3988 Sign of "Win32:BHO-FG [Trj]" has been found in "C:/WINDOWS/可疑文件/maa.exe/[PECompact]" file. 
2007-8-10 10:36:25 new 3988 Sign of "Win32:Agent-IWX [Trj]" has been found in "C:/WINDOWS/可疑文件/my_70074.exe" file. 
2007-8-10 10:36:25 new 3988 Sign of "Win32:Adware-gen. [Adw]" has been found in "C:/WINDOWS/可疑文件/UUSEE_digital_Setup_8.exe/$TEMP/UUSEE_digital_Setup_8.exe" file. 
2007-8-10 10:36:25 new 3988 Sign of "Win32:BHO-FG [Trj]" has been found in "C:/WINDOWS/可疑文件/f.exe/[PECompact]" file. 
2007-8-10 10:36:25 new 3988 Sign of "Win32:Agent-JRJ [Trj]" has been found in "C:/WINDOWS/可疑文件/my_70200.exe" file. 
2007-8-10 10:36:25 new 3988 Sign of "Win32:Boran-M [Adw]" has been found in "C:/WINDOWS/可疑文件/ad_2238.exe/$TEMP/Insshell.exe/[Embedded#423d8]" file. 
2007-8-10 10:36:25 new 3988 Sign of "Win32:Boran-N [Adw]" has been found in "C:/WINDOWS/可疑文件/ad_2238.exe/$TEMP/Insshell.exe/[Embedded#5b3d8]" file. 
2007-8-10 10:36:25 new 3988 Sign of "Win32:Boran-N [Adw]" has been found in "C:/WINDOWS/可疑文件/ad_2238.exe/$TEMP/Insshell.exe/[Embedded#c63d8]" file. 
2007-8-10 10:36:25 new 3988 Sign of "Win32:Boran-M [Adw]" has been found in "C:/WINDOWS/可疑文件/ad_2238.exe/$TEMP/Insshell.exe" file. 
2007-8-10 10:36:52 new 3988 Sign of "Win32:Agent-JQE [Trj]" has been found in "C:/Documents and Settings/new/Local Settings/Temp/tempaq/[UPX]" file. 
2007-8-10 10:37:18 new 3988 Sign of "Win32:Cinmus-G [Adw]" has been found in "C:/Documents and Settings/new/Local Settings/Temporary Internet Files/Content.IE5/3ENQIT3A/dodolook406[1].exe/$TEMP/$TEMP/1558.exe/$TEMP/DoSSSetup.dll" file. 
2007-8-10 10:37:18 new 3988 Sign of "Win32:Adware-gen. [Adw]" has been found in "C:/Documents and Settings/new/Local Settings/Temporary Internet Files/Content.IE5/3ENQIT3A/dodolook406[1].exe/$TEMP/$TEMP/1558.exe" file. 
2007-8-10 10:37:25 new 3988 Sign of "Win32:Agent-GZD [Trj]" has been found in "C:/Documents and Settings/new/Local Settings/Temporary Internet Files/Content.IE5/HG1D3XXZ/barsetup[1]" file. 
2007-8-10 10:38:50 new 3988 Sign of "Win32:Trojan-gen. {UPX!}" has been found in "C:/Documents and Settings/new/桌面/资料/IPQQ2007_v5.0.rar/IPQQ2007.exe/$INSTDIR/../QQDoctor/TSECUA.COM" file. 
2007-8-10 10:41:07 new 3988 Sign of "Win32:Trojan-gen. {Other}" has been found in "C:/Program Files/装机人员工具/UPIEA(IE插件屏蔽) 2006.exe" file. 
2007-8-10 10:41:07 new 3988 Sign of "Win32:Trojan-gen. {UPX!}" has been found in "C:/Program Files/装机人员工具/自动填IP地址/填写IP为192.168.0.158.exe" file. 
2007-8-10 10:41:08 new 3988 Sign of "BVCK-05 [Tool]" has been found in "C:/Program Files/装机人员工具/一键还原精灵6.8/setup.exe" file. 
2007-8-10 10:41:19 new 3988 Sign of "Win32:Adware-gen. [Adw]" has been found in "C:/Program Files/Ringz Studio/Storm Codec/StormSet.exe" file. 
2007-8-10 10:42:29 new 3988 Sign of "Win32:Boran-M [Adw]" has been found in "C:/Program Files/ezfs/rmsf.dll" file. 
2007-8-10 10:42:29 new 3988 Sign of "Win32:Boran-N [Adw]" has been found in "C:/Program Files/ezfs/touh.dll" file. 
2007-8-10 10:42:35 new 3988 Sign of "Win32:Trojano-2575 [Trj]" has been found in "C:/System Volume Information/_restore{7619898A-B5C3-490F-A9B0-454B4418678B}/RP245/A0034783.exe" file. 
2007-8-10 10:42:35 new 3988 Sign of "Win32:Trojano-2575 [Trj]" has been found in "C:/System Volume Information/_restore{7619898A-B5C3-490F-A9B0-454B4418678B}/RP245/A0034784.exe" file. 
2007-8-10 10:42:35 new 3988 Sign of "Win32:Boran-J [Trj]" has been found in "C:/System Volume Information/_restore{7619898A-B5C3-490F-A9B0-454B4418678B}/RP245/A0034800.exe" file. 
2007-8-10 10:42:35 new 3988 Sign of "Win32:Qqhelper-DE [Trj]" has been found in "C:/System Volume Information/_restore{7619898A-B5C3-490F-A9B0-454B4418678B}/RP245/A0034801.dll/[ASPack]" file. 
2007-8-10 10:42:35 new 3988 Sign of "Win32:Trojano-2575 [Trj]" has been found in "C:/System Volume Information/_restore{7619898A-B5C3-490F-A9B0-454B4418678B}/RP245/A0035520.exe" file. 
2007-8-10 10:42:35 new 3988 Sign of "Win32:Trojano-2575 [Trj]" has been found in "C:/System Volume Information/_restore{7619898A-B5C3-490F-A9B0-454B4418678B}/RP245/A0035521.exe" file. 
2007-8-10 10:42:36 new 3988 Sign of "Win32:Cinmus-H [Adw]" has been found in "C:/System Volume Information/_restore{7619898A-B5C3-490F-A9B0-454B4418678B}/RP245/A0035578.sys" file. 
2007-8-10 10:42:38 new 3988 Sign of "Win32:Trojano-2575 [Trj]" has been found in "C:/System Volume Information/_restore{7619898A-B5C3-490F-A9B0-454B4418678B}/RP245/A0035825.exe" file. 
2007-8-10 10:42:38 new 3988 Sign of "Win32:Trojano-2575 [Trj]" has been found in "C:/System Volume Information/_restore{7619898A-B5C3-490F-A9B0-454B4418678B}/RP245/A0035826.exe" file. 
2007-8-10 10:42:39 new 3988 Sign of "Win32:Trojano-2575 [Trj]" has been found in "C:/System Volume Information/_restore{7619898A-B5C3-490F-A9B0-454B4418678B}/RP246/A0036550.exe" file. 
2007-8-10 10:42:39 new 3988 Sign of "Win32:Trojano-2575 [Trj]" has been found in "C:/System Volume Information/_restore{7619898A-B5C3-490F-A9B0-454B4418678B}/RP246/A0036551.exe" file. 
2007-8-10 10:42:40 new 3988 Sign of "Win32:Boran-J [Trj]" has been found in "C:/System Volume Information/_restore{7619898A-B5C3-490F-A9B0-454B4418678B}/RP246/A0036571.exe" file. 
2007-8-10 10:42:40 new 3988 Sign of "Win32:Qqhelper-DE [Trj]" has been found in "C:/System Volume Information/_restore{7619898A-B5C3-490F-A9B0-454B4418678B}/RP246/A0036572.dll/[ASPack]" file. 
2007-8-10 10:42:41 new 3988 Sign of "Win32:Trojano-2575 [Trj]" has been found in "C:/System Volume Information/_restore{7619898A-B5C3-490F-A9B0-454B4418678B}/RP246/A0037893.exe" file. 
2007-8-10 10:42:41 new 3988 Sign of "Win32:Trojano-2575 [Trj]" has been found in "C:/System Volume Information/_restore{7619898A-B5C3-490F-A9B0-454B4418678B}/RP246/A0037894.exe" file. 
2007-8-10 10:42:41 new 3988 Sign of "Win32:Trojano-2575 [Trj]" has been found in "C:/System Volume Information/_restore{7619898A-B5C3-490F-A9B0-454B4418678B}/RP246/A0038163.exe" file. 
2007-8-10 10:42:41 new 3988 Sign of "Win32:Trojano-2575 [Trj]" has been found in "C:/System Volume Information/_restore{7619898A-B5C3-490F-A9B0-454B4418678B}/RP246/A0038164.exe" file. 
2007-8-10 10:42:42 new 3988 Sign of "Win32:Trojano-2575 [Trj]" has been found in "C:/System Volume Information/_restore{7619898A-B5C3-490F-A9B0-454B4418678B}/RP246/A0038488.exe" file. 
2007-8-10 10:42:42 new 3988 Sign of "Win32:Trojano-2575 [Trj]" has been found in "C:/System Volume Information/_restore{7619898A-B5C3-490F-A9B0-454B4418678B}/RP246/A0038489.exe" file. 
2007-8-10 10:42:42 new 3988 Sign of "Win32:Boran-J [Trj]" has been found in "C:/System Volume Information/_restore{7619898A-B5C3-490F-A9B0-454B4418678B}/RP246/A0038505.exe" file. 
2007-8-10 10:42:42 new 3988 Sign of "Win32:Qqhelper-DE [Trj]" has been found in "C:/System Volume Information/_restore{7619898A-B5C3-490F-A9B0-454B4418678B}/RP246/A0038506.dll/[ASPack]" file. 
2007-8-10 10:42:43 new 3988 Sign of "Win32:Trojano-2575 [Trj]" has been found in "C:/System Volume Information/_restore{7619898A-B5C3-490F-A9B0-454B4418678B}/RP247/A0038568.exe" file. 
2007-8-10 10:42:43 new 3988 Sign of "Win32:Trojano-2575 [Trj]" has been found in "C:/System Volume Information/_restore{7619898A-B5C3-490F-A9B0-454B4418678B}/RP247/A0038569.exe" file. 
2007-8-10 10:42:43 new 3988 Sign of "Win32:Trojano-2575 [Trj]" has been found in "C:/System Volume Information/_restore{7619898A-B5C3-490F-A9B0-454B4418678B}/RP247/A0038688.exe" file. 
2007-8-10 10:42:43 new 3988 Sign of "Win32:Trojano-2575 [Trj]" has been found in "C:/System Volume Information/_restore{7619898A-B5C3-490F-A9B0-454B4418678B}/RP247/A0038689.exe" file. 
2007-8-10 10:42:43 new 3988 Sign of "Win32:Boran-J [Trj]" has been found in "C:/System Volume Information/_restore{7619898A-B5C3-490F-A9B0-454B4418678B}/RP247/A0038705.exe" file. 
2007-8-10 10:42:43 new 3988 Sign of "Win32:Qqhelper-DE [Trj]" has been found in "C:/System Volume Information/_restore{7619898A-B5C3-490F-A9B0-454B4418678B}/RP247/A0038710.dll/[ASPack]" file. 
2007-8-10 10:42:43 new 3988 Sign of "Win32:Agent-GJB [Trj]" has been found in "C:/System Volume Information/_restore{7619898A-B5C3-490F-A9B0-454B4418678B}/RP247/A0038768.exe" file. 
2007-8-10 10:42:43 new 3988 Sign of "Win32:Agent-GJB [Trj]" has been found in "C:/System Volume Information/_restore{7619898A-B5C3-490F-A9B0-454B4418678B}/RP247/A0038769.exe" file. 
2007-8-10 10:42:44 new 3988 Sign of "Win32:Agent-IXE [Trj]" has been found in "C:/System Volume Information/_restore{7619898A-B5C3-490F-A9B0-454B4418678B}/RP247/A0038785.dll/[NsPack]/[Embedded#12070]/[NsPack]" file. 
2007-8-10 10:42:44 new 3988 Sign of "Win32:Boran-J [Trj]" has been found in "C:/System Volume Information/_restore{7619898A-B5C3-490F-A9B0-454B4418678B}/RP247/A0038787.exe" file. 
2007-8-10 10:42:44 new 3988 Sign of "Win32:Agent-GJB [Trj]" has been found in "C:/System Volume Information/_restore{7619898A-B5C3-490F-A9B0-454B4418678B}/RP247/A0038900.exe" file. 
2007-8-10 10:42:44 new 3988 Sign of "Win32:Agent-GJB [Trj]" has been found in "C:/System Volume Information/_restore{7619898A-B5C3-490F-A9B0-454B4418678B}/RP247/A0038901.exe" file. 
2007-8-10 10:42:44 new 3988 Sign of "Win32:Qqhelper-DE [Trj]" has been found in "C:/System Volume Information/_restore{7619898A-B5C3-490F-A9B0-454B4418678B}/RP247/A0038916.dll/[ASPack]" file. 
2007-8-10 10:42:45 new 3988 Sign of "Win32:Agent-GJB [Trj]" has been found in "C:/System Volume Information/_restore{7619898A-B5C3-490F-A9B0-454B4418678B}/RP247/A0038960.exe" file. 
2007-8-10 10:42:45 new 3988 Sign of "Win32:Agent-GJB [Trj]" has been found in "C:/System Volume Information/_restore{7619898A-B5C3-490F-A9B0-454B4418678B}/RP247/A0038961.exe" file. 
2007-8-10 10:42:45 new 3988 Sign of "Win32:Agent-GJB [Trj]" has been found in "C:/System Volume Information/_restore{7619898A-B5C3-490F-A9B0-454B4418678B}/RP247/A0038966.exe" file. 
2007-8-10 10:42:45 new 3988 Sign of "Win32:Agent-GJB [Trj]" has been found in "C:/System Volume Information/_restore{7619898A-B5C3-490F-A9B0-454B4418678B}/RP247/A0038967.exe" file. 
2007-8-10 10:42:45 new 3988 Sign of "Win32:Agent-GJB [Trj]" has been found in "C:/System Volume Information/_restore{7619898A-B5C3-490F-A9B0-454B4418678B}/RP247/A0039059.exe" file. 
2007-8-10 10:42:45 new 3988 Sign of "Win32:Agent-GJB [Trj]" has been found in "C:/System Volume Information/_restore{7619898A-B5C3-490F-A9B0-454B4418678B}/RP247/A0039060.exe" file. 
2007-8-10 10:42:45 new 3988 Sign of "Win32:Agent-GJB [Trj]" has been found in "C:/System Volume Information/_restore{7619898A-B5C3-490F-A9B0-454B4418678B}/RP247/A0039065.exe" file. 
2007-8-10 10:42:46 new 3988 Sign of "Win32:Agent-GJB [Trj]" has been found in "C:/System Volume Information/_restore{7619898A-B5C3-490F-A9B0-454B4418678B}/RP247/A0039066.exe" file. 
2007-8-10 10:42:46 new 3988 Sign of "Win32:Agent-GJB [Trj]" has been found in "C:/System Volume Information/_restore{7619898A-B5C3-490F-A9B0-454B4418678B}/RP247/A0040065.exe" file. 
2007-8-10 10:42:46 new 3988 Sign of "Win32:Agent-GJB [Trj]" has been found in "C:/System Volume Information/_restore{7619898A-B5C3-490F-A9B0-454B4418678B}/RP247/A0040066.exe" file. 
2007-8-10 10:42:46 new 3988 Sign of "Win32:Agent-GJB [Trj]" has been found in "C:/System Volume Information/_restore{7619898A-B5C3-490F-A9B0-454B4418678B}/RP247/A0040140.exe" file. 
2007-8-10 10:42:46 new 3988 Sign of "Win32:Agent-GJB [Trj]" has been found in "C:/System Volume Information/_restore{7619898A-B5C3-490F-A9B0-454B4418678B}/RP247/A0040141.exe" file. 
2007-8-10 10:42:46 new 3988 Sign of "Win32:Agent-GJB [Trj]" has been found in "C:/System Volume Information/_restore{7619898A-B5C3-490F-A9B0-454B4418678B}/RP247/A0040146.exe" file. 
2007-8-10 10:42:46 new 3988 Sign of "Win32:Agent-GJB [Trj]" has been found in "C:/System Volume Information/_restore{7619898A-B5C3-490F-A9B0-454B4418678B}/RP247/A0040147.exe" file. 
2007-8-10 10:42:47 new 3988 Sign of "Win32:Agent-GJB [Trj]" has been found in "C:/System Volume Information/_restore{7619898A-B5C3-490F-A9B0-454B4418678B}/RP248/A0040337.exe" file. 
2007-8-10 10:42:47 new 3988 Sign of "Win32:Agent-GJB [Trj]" has been found in "C:/System Volume Information/_restore{7619898A-B5C3-490F-A9B0-454B4418678B}/RP248/A0040338.exe" file. 
2007-8-10 10:42:48 new 3988 Sign of "Win32:Agent-GJB [Trj]" has been found in "C:/System Volume Information/_restore{7619898A-B5C3-490F-A9B0-454B4418678B}/RP248/A0040407.exe" file. 
2007-8-10 10:42:48 new 3988 Sign of "Win32:Agent-GJB [Trj]" has been found in "C:/System Volume Information/_restore{7619898A-B5C3-490F-A9B0-454B4418678B}/RP248/A0040408.exe" file. 
2007-8-10 10:42:48 new 3988 Sign of "Win32:Boran-J [Trj]" has been found in "C:/System Volume Information/_restore{7619898A-B5C3-490F-A9B0-454B4418678B}/RP248/A0040409.exe" file. 
2007-8-10 10:42:48 new 3988 Sign of "Win32:Boran-M [Adw]" has been found in "C:/System Volume Information/_restore{7619898A-B5C3-490F-A9B0-454B4418678B}/RP248/A0040410.exe/$TEMP/Insshell.exe/[Embedded#2c3d8]" file. 
2007-8-10 10:42:48 new 3988 Sign of "Win32:Boran-N [Adw]" has been found in "C:/System Volume Information/_restore{7619898A-B5C3-490F-A9B0-454B4418678B}/RP248/A0040410.exe/$TEMP/Insshell.exe/[Embedded#493d8]" file. 
2007-8-10 10:42:48 new 3988 Sign of "Win32:Boran-N [Adw]" has been found in "C:/System Volume Information/_restore{7619898A-B5C3-490F-A9B0-454B4418678B}/RP248/A0040410.exe/$TEMP/Insshell.exe/[Embedded#a53d8]" file. 
2007-8-10 10:42:48 new 3988 Sign of "Win32:Boran-M [Adw]" has been found in "C:/System Volume Information/_restore{7619898A-B5C3-490F-A9B0-454B4418678B}/RP248/A0040410.exe/$TEMP/Insshell.exe" file. 
2007-8-10 10:42:48 new 3988 Sign of "Win32:Qqhelper-DE [Trj]" has been found in "C:/System Volume Information/_restore{7619898A-B5C3-490F-A9B0-454B4418678B}/RP248/A0040412.dll/[ASPack]" file. 
2007-8-10 10:42:48 new 3988 Sign of "Win32:Agent-GJB [Trj]" has been found in "C:/System Volume Information/_restore{7619898A-B5C3-490F-A9B0-454B4418678B}/RP248/A0040463.exe" file. 
2007-8-10 10:42:48 new 3988 Sign of "Win32:Agent-GJB [Trj]" has been found in "C:/System Volume Information/_restore{7619898A-B5C3-490F-A9B0-454B4418678B}/RP248/A0040465.exe" file. 
2007-8-10 10:42:52 new 3988 Sign of "Win32:Agent-GJB [Trj]" has been found in "C:/System Volume Information/_restore{7619898A-B5C3-490F-A9B0-454B4418678B}/RP251/A0040724.exe" file. 
2007-8-10 10:42:52 new 3988 Sign of "Win32:Agent-GJB [Trj]" has been found in "C:/System Volume Information/_restore{7619898A-B5C3-490F-A9B0-454B4418678B}/RP251/A0040725.exe" file. 
2007-8-10 10:42:52 new 3988 Sign of "Win32:Delf-DQP [Trj]" has been found in "C:/System Volume Information/_restore{7619898A-B5C3-490F-A9B0-454B4418678B}/RP251/A0049434.exe" file. 
2007-8-10 10:42:53 new 3988 Sign of "Win32:Agent-GJB [Trj]" has been found in "C:/System Volume Information/_restore{7619898A-B5C3-490F-A9B0-454B4418678B}/RP251/A0040744.exe" file. 
2007-8-10 10:42:53 new 3988 Sign of "Win32:Agent-GJB [Trj]" has been found in "C:/System Volume Information/_restore{7619898A-B5C3-490F-A9B0-454B4418678B}/RP251/A0040746.exe" file. 
2007-8-10 10:42:53 new 3988 Sign of "Win32:Delf-DTT [Trj]" has been found in "C:/System Volume Information/_restore{7619898A-B5C3-490F-A9B0-454B4418678B}/RP251/A0049436.exe/[Upack]/[Embedded#DOWN]" file. 
2007-8-10 10:42:53 new 3988 Sign of "Win32:Agent-GJB [Trj]" has been found in "C:/System Volume Information/_restore{7619898A-B5C3-490F-A9B0-454B4418678B}/RP251/A0040752.exe" file. 
2007-8-10 10:42:53 new 3988 Sign of "Win32:Agent-GJB [Trj]" has been found in "C:/System Volume Information/_restore{7619898A-B5C3-490F-A9B0-454B4418678B}/RP251/A0040753.exe" file. 
2007-8-10 10:42:53 new 3988 Sign of "Win32:Delf-FFM [Trj]" has been found in "C:/System Volume Information/_restore{7619898A-B5C3-490F-A9B0-454B4418678B}/RP251/A0049437.exe/[Upack]/[Embedded#DOWN]" file. 
2007-8-10 10:42:53 new 3988 Sign of "Win32:Delf-FFM [Trj]" has been found in "C:/System Volume Information/_restore{7619898A-B5C3-490F-A9B0-454B4418678B}/RP251/A0049438.exe/[Upack]/[Embedded#DOWN]" file. 
2007-8-10 10:42:53 new 3988 Sign of "Win32:Agent-GJB [Trj]" has been found in "C:/System Volume Information/_restore{7619898A-B5C3-490F-A9B0-454B4418678B}/RP251/A0040791.exe" file. 
2007-8-10 10:42:53 new 3988 Sign of "Win32:Agent-GJB [Trj]" has been found in "C:/System Volume Information/_restore{7619898A-B5C3-490F-A9B0-454B4418678B}/RP251/A0040792.exe" file. 
2007-8-10 10:42:53 new 3988 Sign of "Win32:Delf-FFM [Trj]" has been found in "C:/System Volume Information/_restore{7619898A-B5C3-490F-A9B0-454B4418678B}/RP251/A0049439.exe/[Upack]/[Embedded#DOWN]" file. 
2007-8-10 10:42:54 new 3988 Sign of "Win32:Delf-FFM [Trj]" has been found in "C:/System Volume Information/_restore{7619898A-B5C3-490F-A9B0-454B4418678B}/RP251/A0049440.exe/[Upack]/[Embedded#DOWN]" file. 
2007-8-10 10:42:54 new 3988 Sign of "Win32:Agent-GJB [Trj]" has been found in "C:/System Volume Information/_restore{7619898A-B5C3-490F-A9B0-454B4418678B}/RP251/A0040856.exe" file. 
2007-8-10 10:42:54 new 3988 Sign of "Win32:Agent-GJB [Trj]" has been found in "C:/System Volume Information/_restore{7619898A-B5C3-490F-A9B0-454B4418678B}/RP251/A0040857.exe" file. 
2007-8-10 10:42:54 new 3988 Sign of "Win32:Delf-EQW [Trj]" has been found in "C:/System Volume Information/_restore{7619898A-B5C3-490F-A9B0-454B4418678B}/RP251/A0049441.exe/[Upack]" file. 
2007-8-10 10:42:54 new 3988 Sign of "Win32:BHO-FG [Trj]" has been found in "C:/System Volume Information/_restore{7619898A-B5C3-490F-A9B0-454B4418678B}/RP251/A0049442.exe/[PECompact]" file. 
2007-8-10 10:42:54 new 3988 Sign of "Win32:Agent-GJB [Trj]" has been found in "C:/System Volume Information/_restore{7619898A-B5C3-490F-A9B0-454B4418678B}/RP251/A0040879.exe" file. 
2007-8-10 10:42:54 new 3988 Sign of "Win32:Agent-GJB [Trj]" has been found in "C:/System Volume Information/_restore{7619898A-B5C3-490F-A9B0-454B4418678B}/RP251/A0040880.exe" file. 
2007-8-10 10:42:54 new 3988 Sign of "Win32:Agent-GJB [Trj]" has been found in "C:/System Volume Information/_restore{7619898A-B5C3-490F-A9B0-454B4418678B}/RP251/A0040898.exe" file. 
2007-8-10 10:42:54 new 3988 Sign of "Win32:Agent-GJB [Trj]" has been found in "C:/System Volume Information/_restore{7619898A-B5C3-490F-A9B0-454B4418678B}/RP251/A0040899.exe" file. 
2007-8-10 10:42:55 new 3988 Sign of "Win32:Boran-M [Adw]" has been found in "C:/System Volume Information/_restore{7619898A-B5C3-490F-A9B0-454B4418678B}/RP251/A0040952.exe/$TEMP/Insshell.exe/[Embedded#2c3d8]" file. 
2007-8-10 10:42:55 new 3988 Sign of "Win32:Boran-N [Adw]" has been found in "C:/System Volume Information/_restore{7619898A-B5C3-490F-A9B0-454B4418678B}/RP251/A0040952.exe/$TEMP/Insshell.exe/[Embedded#493d8]" file. 
2007-8-10 10:42:55 new 3988 Sign of "Win32:Boran-N [Adw]" has been found in "C:/System Volume Information/_restore{7619898A-B5C3-490F-A9B0-454B4418678B}/RP251/A0040952.exe/$TEMP/Insshell.exe/[Embedded#a53d8]" file. 
2007-8-10 10:42:55 new 3988 Sign of "Win32:Boran-M [Adw]" has been found in "C:/System Volume Information/_restore{7619898A-B5C3-490F-A9B0-454B4418678B}/RP251/A0040952.exe/$TEMP/Insshell.exe" file. 
2007-8-10 10:42:55 new 3988 Sign of "Win32:Qqhelper-DE [Trj]" has been found in "C:/System Volume Information/_restore{7619898A-B5C3-490F-A9B0-454B4418678B}/RP251/A0040954.dll/[ASPack]" file. 
2007-8-10 10:42:55 new 3988 Sign of "Win32:Agent-GJB [Trj]" has been found in "C:/System Volume Information/_restore{7619898A-B5C3-490F-A9B0-454B4418678B}/RP251/A0040980.exe" file. 
2007-8-10 10:42:55 new 3988 Sign of "Win32:Agent-GJB [Trj]" has been found in "C:/System Volume Information/_restore{7619898A-B5C3-490F-A9B0-454B4418678B}/RP251/A0040981.exe" file. 
2007-8-10 10:42:55 new 3988 Sign of "Win32:Boran-J [Trj]" has been found in "C:/System Volume Information/_restore{7619898A-B5C3-490F-A9B0-454B4418678B}/RP251/A0040982.exe" file. 
2007-8-10 10:42:56 new 3988 Sign of "Win32:Qqhelper-DE [Trj]" has been found in "C:/System Volume Information/_restore{7619898A-B5C3-490F-A9B0-454B4418678B}/RP251/A0040983.dll/[ASPack]" file. 
2007-8-10 10:42:56 new 3988 Sign of "Win32:Cinmus-I [Adw]" has been found in "C:/System Volume Information/_restore{7619898A-B5C3-490F-A9B0-454B4418678B}/RP251/A0041288.exe/$COMMONFILES/CPUSH/cpush.dll" file. 
2007-8-10 10:42:56 new 3988 Sign of "Win32:Trojano-2575 [Trj]" has been found in "C:/System Volume Information/_restore{7619898A-B5C3-490F-A9B0-454B4418678B}/RP251/A0041963.exe" file. 
2007-8-10 10:42:56 new 3988 Sign of "Win32:Trojano-2575 [Trj]" has been found in "C:/System Volume Information/_restore{7619898A-B5C3-490F-A9B0-454B4418678B}/RP251/A0042963.exe" file. 
2007-8-10 10:42:56 new 3988 Sign of "Win32:Trojano-2575 [Trj]" has been found in "C:/System Volume Information/_restore{7619898A-B5C3-490F-A9B0-454B4418678B}/RP251/A0042964.exe" file. 
2007-8-10 10:42:57 new 3988 Sign of "Win32:Trojano-2575 [Trj]" has been found in "C:/System Volume Information/_restore{7619898A-B5C3-490F-A9B0-454B4418678B}/RP251/A0043980.exe" file. 
2007-8-10 10:42:57 new 3988 Sign of "Win32:Trojano-2575 [Trj]" has been found in "C:/System Volume Information/_restore{7619898A-B5C3-490F-A9B0-454B4418678B}/RP251/A0044979.exe" file. 
2007-8-10 10:42:57 new 3988 Sign of "Win32:Trojano-2575 [Trj]" has been found in "C:/System Volume Information/_restore{7619898A-B5C3-490F-A9B0-454B4418678B}/RP251/A0044980.exe" file. 
2007-8-10 10:42:57 new 3988 Sign of "Win32:Delf-FFM [Trj]" has been found in "C:/System Volume Information/_restore{7619898A-B5C3-490F-A9B0-454B4418678B}/RP251/A0044981.exe/[Upack]/[Embedded#DOWN]" file. 
2007-8-10 10:42:57 new 3988 Sign of "Win32:Delf-FFM [Trj]" has been found in "C:/System Volume Information/_restore{7619898A-B5C3-490F-A9B0-454B4418678B}/RP251/A0044982.exe/[Upack]/[Embedded#DOWN]" file. 
2007-8-10 10:42:57 new 3988 Sign of "Win32:Delf-EQW [Trj]" has been found in "C:/System Volume Information/_restore{7619898A-B5C3-490F-A9B0-454B4418678B}/RP251/A0044984.exe/[Upack]" file. 
2007-8-10 10:42:57 new 3988 Sign of "Win32:Delf-FFM [Trj]" has been found in "C:/System Volume Information/_restore{7619898A-B5C3-490F-A9B0-454B4418678B}/RP251/A0044985.exe/[Upack]/[Embedded#DOWN]" file. 
2007-8-10 10:42:57 new 3988 Sign of "Win32:Delf-FFM [Trj]" has been found in "C:/System Volume Information/_restore{7619898A-B5C3-490F-A9B0-454B4418678B}/RP251/A0044986.exe/[Upack]/[Embedded#DOWN]" file. 
2007-8-10 10:42:57 new 3988 Sign of "Win32:Delf-DTT [Trj]" has been found in "C:/System Volume Information/_restore{7619898A-B5C3-490F-A9B0-454B4418678B}/RP251/A0044987.exe/[Upack]/[Embedded#DOWN]" file. 
2007-8-10 10:42:57 new 3988 Sign of "Win32:Trojano-2575 [Trj]" has been found in "C:/System Volume Information/_restore{7619898A-B5C3-490F-A9B0-454B4418678B}/RP251/A0045968.exe" file. 
2007-8-10 10:42:57 new 3988 Sign of "Win32:Trojano-2575 [Trj]" has been found in "C:/System Volume Information/_restore{7619898A-B5C3-490F-A9B0-454B4418678B}/RP251/A0048968.exe" file. 
2007-8-10 10:42:57 new 3988 Sign of "Win32:Delf-DTT [Trj]" has been found in "C:/System Volume Information/_restore{7619898A-B5C3-490F-A9B0-454B4418678B}/RP251/A0048970.dll" file. 
2007-8-10 10:42:58 new 3988 Sign of "Win32:Cinmus-D [Adw]" has been found in "C:/System Volume Information/_restore{7619898A-B5C3-490F-A9B0-454B4418678B}/RP251/A0048987.dll" file. 
2007-8-10 10:42:58 new 3988 Sign of "Win32:Adware-gen. [Adw]" has been found in "C:/System Volume Information/_restore{7619898A-B5C3-490F-A9B0-454B4418678B}/RP251/A0048992.dll" file. 
2007-8-10 10:42:58 new 3988 Sign of "Win32:Adware-gen. [Adw]" has been found in "C:/System Volume Information/_restore{7619898A-B5C3-490F-A9B0-454B4418678B}/RP251/A0048994.sys" file. 
2007-8-10 10:42:58 new 3988 Sign of "Win32:Adware-gen. [Adw]" has been found in "C:/System Volume Information/_restore{7619898A-B5C3-490F-A9B0-454B4418678B}/RP251/A0048995.sys/[Embedded#0c358]" file. 
2007-8-10 10:42:58 new 3988 Sign of "Win32:Adware-gen. [Adw]" has been found in "C:/System Volume Information/_restore{7619898A-B5C3-490F-A9B0-454B4418678B}/RP251/A0048996.dll" file. 
2007-8-10 10:42:58 new 3988 Sign of "Win32:Adware-gen. [Adw]" has been found in "C:/System Volume Information/_restore{7619898A-B5C3-490F-A9B0-454B4418678B}/RP251/A0048998.dll" file. 
2007-8-10 10:42:58 new 3988 Sign of "Win32:Adware-gen. [Adw]" has been found in "C:/System Volume Information/_restore{7619898A-B5C3-490F-A9B0-454B4418678B}/RP251/A0048999.dll" file. 
2007-8-10 10:42:58 new 3988 Sign of "Win32:Adware-gen. [Adw]" has been found in "C:/System Volume Information/_restore{7619898A-B5C3-490F-A9B0-454B4418678B}/RP251/A0049000.dll" file. 
2007-8-10 10:42:58 new 3988 Sign of "Win32:Adware-gen. [Adw]" has been found in "C:/System Volume Information/_restore{7619898A-B5C3-490F-A9B0-454B4418678B}/RP251/A0049001.exe" file. 
2007-8-10 10:42:58 new 3988 Sign of "Win32:Adware-gen. [Adw]" has been found in "C:/System Volume Information/_restore{7619898A-B5C3-490F-A9B0-454B4418678B}/RP251/A0049002.dll" file. 
2007-8-10 10:42:58 new 3988 Sign of "Win32:Adware-gen. [Adw]" has been found in "C:/System Volume Information/_restore{7619898A-B5C3-490F-A9B0-454B4418678B}/RP251/A0049003.dll" file. 
2007-8-10 10:42:58 new 3988 Sign of "Win32:Adware-gen. [Adw]" has been found in "C:/System Volume Information/_restore{7619898A-B5C3-490F-A9B0-454B4418678B}/RP251/A0049004.exe" file. 
2007-8-10 10:42:58 new 3988 Sign of "Win32:Adware-gen. [Adw]" has been found in "C:/System Volume Information/_restore{7619898A-B5C3-490F-A9B0-454B4418678B}/RP251/A0049008.exe/[ASPack]/[Embedded#007040]" file. 
2007-8-10 10:43:04 new 3988 Sign of "Win32:Trojan-gen. {VC}" has been found in "C:/System Volume Information/_restore{7619898A-B5C3-490F-A9B0-454B4418678B}/RP251/A0049426.exe" file. 
2007-8-10 10:43:05 new 3988 Sign of "Win32:Boran-J [Trj]" has been found in "C:/System Volume Information/_restore{7619898A-B5C3-490F-A9B0-454B4418678B}/RP251/A0049481.exe" file. 
2007-8-10 10:43:14 new 3988 Sign of "Win32:Adware-gen. [Adw]" has been found in "C:/System Volume Information/_restore{7619898A-B5C3-490F-A9B0-454B4418678B}/RP252/A0049694.exe/[Embedded#14a3c]" file. 
2007-8-10 10:43:14 new 3988 Sign of "Win32:Small-HHY [Trj]" has been found in "C:/System Volume Information/_restore{7619898A-B5C3-490F-A9B0-454B4418678B}/RP252/A0049701.DLL" file. 
2007-8-10 10:44:14 new 3988 Sign of "Win32:Trojan-gen. {UPX!}" has been found in "C:/System Volume Information/_restore{7619898A-B5C3-490F-A9B0-454B4418678B}/RP254/A0050686.exe/$INSTDIR/../QQDoctor/TSECUA.COM" file. 
2007-8-10 10:44:30 new 3988 Sign of "Win32:Cinmus-D [Adw]" has been found in "C:/System Volume Information/_restore{7619898A-B5C3-490F-A9B0-454B4418678B}/RP256/A0051035.dll" file. 
2007-8-10 10:44:30 new 3988 Sign of "Win32:Lmir-KB [Trj]" has been found in "C:/System Volume Information/_restore{7619898A-B5C3-490F-A9B0-454B4418678B}/RP256/A0051036.dll/[NsPack]" file. 
2007-8-10 10:44:30 new 3988 Sign of "Win32:Agent-HJW [Trj]" has been found in "C:/System Volume Information/_restore{7619898A-B5C3-490F-A9B0-454B4418678B}/RP256/A0051039.dll/[PECompact]" file. 
2007-8-10 10:44:30 new 3988 Sign of "Win32:Cinmus-H [Adw]" has been found in "C:/System Volume Information/_restore{7619898A-B5C3-490F-A9B0-454B4418678B}/RP256/A0051055.sys" file. 
2007-8-10 10:44:31 new 3988 Sign of "Win32:Delf-DQP [Trj]" has been found in "C:/System Volume Information/_restore{7619898A-B5C3-490F-A9B0-454B4418678B}/RP256/A0051056.exe/qq.exe" file. 
2007-8-10 10:44:31 new 3988 Sign of "Win32:Agent-HUT [Wrm]" has been found in "C:/System Volume Information/_restore{7619898A-B5C3-490F-A9B0-454B4418678B}/RP256/A0051057.exe/[NsPack]" file. 
2007-8-10 10:44:31 new 3988 Sign of "Win32:Agent-JRM [Trj]" has been found in "C:/System Volume Information/_restore{7619898A-B5C3-490F-A9B0-454B4418678B}/RP256/A0051058.dll" file. 
2007-8-10 10:44:31 new 3988 Sign of "Win32:Boran-N [Adw]" has been found in "C:/System Volume Information/_restore{7619898A-B5C3-490F-A9B0-454B4418678B}/RP256/A0051059.dll" file. 
2007-8-10 10:44:31 new 3988 Sign of "Win32:Delf-FKI [Trj]" has been found in "C:/System Volume Information/_restore{7619898A-B5C3-490F-A9B0-454B4418678B}/RP256/A0051060.dll" file. 
2007-8-10 10:44:31 new 3988 Sign of "Win32:Delf-FKI [Trj]" has been found in "C:/System Volume Information/_restore{7619898A-B5C3-490F-A9B0-454B4418678B}/RP256/A0051061.dll" file. 
2007-8-10 10:44:31 new 3988 Sign of "Win32:Delf-FKI [Trj]" has been found in "C:/System Volume Information/_restore{7619898A-B5C3-490F-A9B0-454B4418678B}/RP256/A0051062.dll" file. 
2007-8-10 10:44:31 new 3988 Sign of "Win32:Lmir-KB [Trj]" has been found in "C:/System Volume Information/_restore{7619898A-B5C3-490F-A9B0-454B4418678B}/RP256/A0051063.dll/[NsPack]" file. 
2007-8-10 10:44:32 new 3988 Sign of "Win32:Ieser-J [Trj]" has been found in "C:/System Volume Information/_restore{7619898A-B5C3-490F-A9B0-454B4418678B}/RP256/A0051064.dll" file. 
2007-8-10 10:44:32 new 3988 Sign of "Win32:Qqhelper-DE [Trj]" has been found in "C:/System Volume Information/_restore{7619898A-B5C3-490F-A9B0-454B4418678B}/RP256/A0051066.dll/[UPX]" file. 
2007-8-10 10:44:32 new 3988 Sign of "Win32:Delf-FFM [Trj]" has been found in "C:/System Volume Information/_restore{7619898A-B5C3-490F-A9B0-454B4418678B}/RP256/A0051067.dll" file. 
2007-8-10 10:44:32 new 3988 Sign of "Win32:Delf-FFM [Trj]" has been found in "C:/System Volume Information/_restore{7619898A-B5C3-490F-A9B0-454B4418678B}/RP256/A0051068.dll" file. 
2007-8-10 10:44:32 new 3988 Sign of "Win32:Delf-FFM [Trj]" has been found in "C:/System Volume Information/_restore{7619898A-B5C3-490F-A9B0-454B4418678B}/RP256/A0051069.dll" file. 
2007-8-10 10:44:32 new 3988 Sign of "Win32:Delf-FFM [Trj]" has been found in "C:/System Volume Information/_restore{7619898A-B5C3-490F-A9B0-454B4418678B}/RP256/A0051070.dll" file. 
2007-8-10 10:44:32 new 3988 Sign of "Win32:Cinmus-G [Adw]" has been found in "C:/System Volume Information/_restore{7619898A-B5C3-490F-A9B0-454B4418678B}/RP256/A0051071.exe/$TEMP/$TEMP/1558.exe/$TEMP/DoSSSetup.dll" file. 
2007-8-10 10:44:32 new 3988 Sign of "Win32:Adware-gen. [Adw]" has been found in "C:/System Volume Information/_restore{7619898A-B5C3-490F-A9B0-454B4418678B}/RP256/A0051071.exe/$TEMP/$TEMP/1558.exe" file. 
2007-8-10 10:44:32 new 3988 Sign of "Win32:Trojano-2575 [Trj]" has been found in "C:/System Volume Information/_restore{7619898A-B5C3-490F-A9B0-454B4418678B}/RP256/A0051072.exe/$SYSDIR/netdde32.exe" file. 
2007-8-10 10:44:32 new 3988 Sign of "Win32:Cinmus-I [Adw]" has been found in "C:/System Volume Information/_restore{7619898A-B5C3-490F-A9B0-454B4418678B}/RP256/A0051072.exe/$SYSDIR/d03.exe/$COMMONFILES/CPUSH/cpush.dll" file. 
2007-8-10 10:44:32 new 3988 Sign of "Win32:Adware-gen. [Adw]" has been found in "C:/System Volume Information/_restore{7619898A-B5C3-490F-A9B0-454B4418678B}/RP256/A0051072.exe/$SYSDIR/d03.exe" file. 
2007-8-10 10:44:32 new 3988 Sign of "Win32:Trojano-2575 [Trj]" has been found in "C:/System Volume Information/_restore{7619898A-B5C3-490F-A9B0-454B4418678B}/RP256/A0051073.exe/$SYSDIR/netdde32.exe" file. 
2007-8-10 10:44:32 new 3988 Sign of "Win32:Boran-M [Adw]" has been found in "C:/System Volume Information/_restore{7619898A-B5C3-490F-A9B0-454B4418678B}/RP256/A0051074.exe/$TEMP/Insshell.exe/[Embedded#2c3d8]" file. 
2007-8-10 10:44:32 new 3988 Sign of "Win32:Boran-N [Adw]" has been found in "C:/System Volume Information/_restore{7619898A-B5C3-490F-A9B0-454B4418678B}/RP256/A0051074.exe/$TEMP/Insshell.exe/[Embedded#493d8]" file. 
2007-8-10 10:44:32 new 3988 Sign of "Win32:Boran-N [Adw]" has been found in "C:/System Volume Information/_restore{7619898A-B5C3-490F-A9B0-454B4418678B}/RP256/A0051074.exe/$TEMP/Insshell.exe/[Embedded#a53d8]" file. 
2007-8-10 10:44:32 new 3988 Sign of "Win32:Boran-M [Adw]" has been found in "C:/System Volume Information/_restore{7619898A-B5C3-490F-A9B0-454B4418678B}/RP256/A0051074.exe/$TEMP/Insshell.exe" file. 
2007-8-10 10:44:32 new 3988 Sign of "Win32:Adware-gen. [Adw]" has been found in "C:/System Volume Information/_restore{7619898A-B5C3-490F-A9B0-454B4418678B}/RP256/A0051075.exe/$TEMP/insshell.exe/[Embedded#093d8]" file. 
2007-8-10 10:44:32 new 3988 Sign of "Win32:Adware-gen. [Adw]" has been found in "C:/System Volume Information/_restore{7619898A-B5C3-490F-A9B0-454B4418678B}/RP256/A0051075.exe/$TEMP/insshell.exe/[Embedded#303d8]" file. 
2007-8-10 10:44:32 new 3988 Sign of "Win32:Adware-gen. [Adw]" has been found in "C:/System Volume Information/_restore{7619898A-B5C3-490F-A9B0-454B4418678B}/RP256/A0051075.exe/$TEMP/insshell.exe/[Embedded#4a3d8]" file. 
2007-8-10 10:44:32 new 3988 Sign of "Win32:Boran-N [Adw]" has been found in "C:/System Volume Information/_restore{7619898A-B5C3-490F-A9B0-454B4418678B}/RP256/A0051075.exe/$TEMP/insshell.exe/[Embedded#683d8]" file. 
2007-8-10 10:44:32 new 3988 Sign of "Win32:Boran-N [Adw]" has been found in "C:/System Volume Information/_restore{7619898A-B5C3-490F-A9B0-454B4418678B}/RP256/A0051075.exe/$TEMP/insshell.exe/[Embedded#903d8]" file. 
2007-8-10 10:44:32 new 3988 Sign of "Win32:Boran-N [Adw]" has been found in "C:/System Volume Information/_restore{7619898A-B5C3-490F-A9B0-454B4418678B}/RP256/A0051075.exe/$TEMP/insshell.exe" file. 
2007-8-10 10:44:32 new 3988 Sign of "Win32:QQHelper-BN [Trj]" has been found in "C:/System Volume Information/_restore{7619898A-B5C3-490F-A9B0-454B4418678B}/RP256/A0051076.exe" file. 
2007-8-10 10:44:32 new 3988 Sign of "Win32:Cinmus-I [Adw]" has been found in "C:/System Volume Information/_restore{7619898A-B5C3-490F-A9B0-454B4418678B}/RP256/A0051077.exe/$COMMONFILES/CPUSH/cpush.dll" file. 
2007-8-10 10:44:32 new 3988 Sign of "Win32:Cinmus-I [Adw]" has been found in "C:/System Volume Information/_restore{7619898A-B5C3-490F-A9B0-454B4418678B}/RP256/A0051078.exe/$COMMONFILES/CPUSH/cpush.dll" file. 
2007-8-10 10:44:33 new 3988 Sign of "Win32:Cinmus-I [Adw]" has been found in "C:/System Volume Information/_restore{7619898A-B5C3-490F-A9B0-454B4418678B}/RP256/A0051079.exe/$COMMONFILES/CPUSH/cpush.dll" file. 
2007-8-10 10:44:33 new 3988 Sign of "Win32:Cinmus-I [Adw]" has been found in "C:/System Volume Information/_restore{7619898A-B5C3-490F-A9B0-454B4418678B}/RP256/A0051080.exe/$COMMONFILES/CPUSH/cpush.dll" file. 
2007-8-10 10:44:33 new 3988 Sign of "Win32:Cinmus-I [Adw]" has been found in "C:/System Volume Information/_restore{7619898A-B5C3-490F-A9B0-454B4418678B}/RP256/A0051081.exe/$COMMONFILES/CPUSH/cpush.dll" file. 
2007-8-10 10:44:33 new 3988 Sign of "Win32:Cinmus-I [Adw]" has been found in "C:/System Volume Information/_restore{7619898A-B5C3-490F-A9B0-454B4418678B}/RP256/A0051082.exe/$COMMONFILES/CPUSH/cpush.dll" file. 
2007-8-10 10:44:33 new 3988 Sign of "Win32:Cinmus-I [Adw]" has been found in "C:/System Volume Information/_restore{7619898A-B5C3-490F-A9B0-454B4418678B}/RP256/A0051083.exe/$COMMONFILES/CPUSH/cpush.dll" file. 
2007-8-10 10:44:33 new 3988 Sign of "Win32:Cinmus-G [Adw]" has been found in "C:/System Volume Information/_restore{7619898A-B5C3-490F-A9B0-454B4418678B}/RP256/A0051084.exe/$TEMP/$TEMP/1208.exe/$TEMP/DoSSSetup.dll" file. 
2007-8-10 10:44:33 new 3988 Sign of "Win32:Cinmus-H [Adw]" has been found in "C:/System Volume Information/_restore{7619898A-B5C3-490F-A9B0-454B4418678B}/RP256/A0051084.exe/$TEMP/$TEMP/1208.exe/$TEMP/acpidisk.sys" file. 
2007-8-10 10:44:33 new 3988 Sign of "Win32:Adware-gen. [Adw]" has been found in "C:/System Volume Information/_restore{7619898A-B5C3-490F-A9B0-454B4418678B}/RP256/A0051084.exe/$TEMP/$TEMP/1208.exe" file. 
2007-8-10 10:44:33 new 3988 Sign of "Win32:BHO-FG [Trj]" has been found in "C:/System Volume Information/_restore{7619898A-B5C3-490F-A9B0-454B4418678B}/RP256/A0051085.exe/[PECompact]" file. 
2007-8-10 10:44:33 new 3988 Sign of "Win32:Agent-IWX [Trj]" has been found in "C:/System Volume Information/_restore{7619898A-B5C3-490F-A9B0-454B4418678B}/RP256/A0051086.exe" file. 
2007-8-10 10:44:33 new 3988 Sign of "Win32:Adware-gen. [Adw]" has been found in "C:/System Volume Information/_restore{7619898A-B5C3-490F-A9B0-454B4418678B}/RP256/A0051087.exe/$TEMP/UUSEE_digital_Setup_8.exe" file. 
2007-8-10 10:44:33 new 3988 Sign of "Win32:BHO-FG [Trj]" has been found in "C:/System Volume Information/_restore{7619898A-B5C3-490F-A9B0-454B4418678B}/RP256/A0051088.exe/[PECompact]" file. 
2007-8-10 10:44:33 new 3988 Sign of "Win32:Agent-JRJ [Trj]" has been found in "C:/System Volume Information/_restore{7619898A-B5C3-490F-A9B0-454B4418678B}/RP256/A0051089.exe" file. 
2007-8-10 10:44:33 new 3988 Sign of "Win32:Boran-M [Adw]" has been found in "C:/System Volume Information/_restore{7619898A-B5C3-490F-A9B0-454B4418678B}/RP256/A0051090.exe/$TEMP/Insshell.exe/[Embedded#423d8]" file. 
2007-8-10 10:44:33 new 3988 Sign of "Win32:Boran-N [Adw]" has been found in "C:/System Volume Information/_restore{7619898A-B5C3-490F-A9B0-454B4418678B}/RP256/A0051090.exe/$TEMP/Insshell.exe/[Embedded#5b3d8]" file. 
2007-8-10 10:44:33 new 3988 Sign of "Win32:Boran-N [Adw]" has been found in "C:/System Volume Information/_restore{7619898A-B5C3-490F-A9B0-454B4418678B}/RP256/A0051090.exe/$TEMP/Insshell.exe/[Embedded#c63d8]" file. 
2007-8-10 10:44:33 new 3988 Sign of "Win32:Boran-M [Adw]" has been found in "C:/System Volume Information/_restore{7619898A-B5C3-490F-A9B0-454B4418678B}/RP256/A0051090.exe/$TEMP/Insshell.exe" file. 
2007-8-10 10:44:33 new 3988 Sign of "Win32:Trojan-gen. {Other}" has been found in "C:/System Volume Information/_restore{7619898A-B5C3-490F-A9B0-454B4418678B}/RP256/A0051091.exe" file. 
2007-8-10 10:44:33 new 3988 Sign of "Win32:Trojan-gen. {UPX!}" has been found in "C:/System Volume Information/_restore{7619898A-B5C3-490F-A9B0-454B4418678B}/RP256/A0051092.exe" file. 
2007-8-10 10:44:33 new 3988 Sign of "BVCK-05 [Tool]" has been found in "C:/System Volume Information/_restore{7619898A-B5C3-490F-A9B0-454B4418678B}/RP256/A0051093.exe" file. 
2007-8-10 10:44:33 new 3988 Sign of "Win32:Adware-gen. [Adw]" has been found in "C:/System Volume Information/_restore{7619898A-B5C3-490F-A9B0-454B4418678B}/RP256/A0051094.exe" file. 
2007-8-10 10:44:33 new 3988 Sign of "Win32:Boran-M [Adw]" has been found in "C:/System Volume Information/_restore{7619898A-B5C3-490F-A9B0-454B4418678B}/RP256/A0051095.dll" file. 
2007-8-10 10:44:33 new 3988 Sign of "Win32:Boran-N [Adw]" has been found in "C:/System Volume Information/_restore{7619898A-B5C3-490F-A9B0-454B4418678B}/RP256/A0051096.dll" file. 
2007-8-10 10:44:51 new 3988 Sign of "Win32:Trojano-2575 [Trj]" has been found in "C:/System Volume Information/_restore{7619898A-B5C3-490F-A9B0-454B4418678B}/RP242/A0034537.exe" file. 
2007-8-10 10:44:51 new 3988 Sign of "Win32:Trojano-2575 [Trj]" has been found in "C:/System Volume Information/_restore{7619898A-B5C3-490F-A9B0-454B4418678B}/RP242/A0034538.exe" file. 
2007-8-10 10:44:51 new 3988 Sign of "Win32:Trojano-2575 [Trj]" has been found in "C:/System Volume Information/_restore{7619898A-B5C3-490F-A9B0-454B4418678B}/RP242/A0034563.exe" file. 
2007-8-10 10:44:51 new 3988 Sign of "Win32:Trojano-2575 [Trj]" has been found in "C:/System Volume Information/_restore{7619898A-B5C3-490F-A9B0-454B4418678B}/RP242/A0034564.exe" file. 
2007-8-10 10:44:52 new 3988 Sign of "Win32:Adware-gen. [Adw]" has been found in "C:/System Volume Information/_restore{7619898A-B5C3-490F-A9B0-454B4418678B}/RP242/A0034616.dll" file. 
2007-8-10 10:44:52 new 3988 Sign of "Win32:Adware-gen. [Adw]" has been found in "C:/System Volume Information/_restore{7619898A-B5C3-490F-A9B0-454B4418678B}/RP242/A0034618.sys" file. 
2007-8-10 10:44:52 new 3988 Sign of "Win32:Adware-gen. [Adw]" has been found in "C:/System Volume Information/_restore{7619898A-B5C3-490F-A9B0-454B4418678B}/RP242/A0034619.sys/[Embedded#0c158]" file. 
2007-8-10 10:44:52 new 3988 Sign of "Win32:Adware-gen. [Adw]" has been found in "C:/System Volume Information/_restore{7619898A-B5C3-490F-A9B0-454B4418678B}/RP242/A0034620.dll" file. 
2007-8-10 10:44:52 new 3988 Sign of "Win32:Adware-gen. [Adw]" has been found in "C:/System Volume Information/_restore{7619898A-B5C3-490F-A9B0-454B4418678B}/RP242/A0034622.dll" file. 
2007-8-10 10:44:52 new 3988 Sign of "Win32:Adware-gen. [Adw]" has been found in "C:/System Volume Information/_restore{7619898A-B5C3-490F-A9B0-454B4418678B}/RP242/A0034623.dll" file. 
2007-8-10 10:44:52 new 3988 Sign of "Win32:Adware-gen. [Adw]" has been found in "C:/System Volume Information/_restore{7619898A-B5C3-490F-A9B0-454B4418678B}/RP242/A0034624.exe" file. 
2007-8-10 10:44:52 new 3988 Sign of "Win32:Adware-gen. [Adw]" has been found in "C:/System Volume Information/_restore{7619898A-B5C3-490F-A9B0-454B4418678B}/RP242/A0034626.dll" file. 
2007-8-10 10:44:52 new 3988 Sign of "Win32:Adware-gen. [Adw]" has been found in "C:/System Volume Information/_restore{7619898A-B5C3-490F-A9B0-454B4418678B}/RP242/A0034627.exe" file. 
2007-8-10 10:44:52 new 3988 Sign of "Win32:Adware-gen. [Adw]" has been found in "C:/System Volume Information/_restore{7619898A-B5C3-490F-A9B0-454B4418678B}/RP242/A0034628.dll" file. 
2007-8-10 10:44:52 new 3988 Sign of "Win32:Adware-gen. [Adw]" has been found in "C:/System Volume Information/_restore{7619898A-B5C3-490F-A9B0-454B4418678B}/RP242/A0034631.exe/[ASPack]/[Embedded#007040]" file. 
2007-8-10 10:44:53 new 3988 Sign of "Win32:Boran-J [Trj]" has been found in "C:/System Volume Information/_restore{7619898A-B5C3-490F-A9B0-454B4418678B}/RP242/A0034646.exe" file. 
2007-8-10 10:44:53 new 3988 Sign of "Win32:Trojano-2575 [Trj]" has been found in "C:/System Volume Information/_restore{7619898A-B5C3-490F-A9B0-454B4418678B}/RP243/A0034653.exe" file. 
2007-8-10 10:44:53 new 3988 Sign of "Win32:Trojano-2575 [Trj]" has been found in "C:/System Volume Information/_restore{7619898A-B5C3-490F-A9B0-454B4418678B}/RP243/A0034654.exe" file. 
2007-8-10 10:44:53 new 3988 Sign of "Win32:Adware-gen. [Adw]" has been found in "C:/System Volume Information/_restore{7619898A-B5C3-490F-A9B0-454B4418678B}/RP243/A0034655.exe/[Embedded#14a54]" file. 
2007-8-10 10:45:18 new 3988 Sign of "Win32:VB-DJP [Wrm]" has been found in "C:/Recycled/Dc3.exe/[Upack]" file. 
2007-8-10 10:45:19 new 3988 Sign of "Win32:Adware-gen. [Adw]" has been found in "C:/Recycled/Dc9.exe" file. 
2007-8-10 10:45:20 new 3988 Sign of "Win32:Adware-gen. [Adw]" has been found in "C:/Recycled/Dc12.exe" file. 
2007-8-10 10:45:20 new 3988 Sign of "Win32:Adware-gen. [Adw]" has been found in "C:/Recycled/Dc13.exe/[ASPack]/[Embedded#009150]" file. 
2007-8-10 10:45:21 new 3988 Sign of "Win32:Agent-IXE [Trj]" has been found in "C:/Recycled/Dc15.exe/[NsPack]/[Embedded#4070]/[NsPack]/[Embedded#12070]/[NsPack]" file. 
2007-8-10 10:45:21 new 3988 Sign of "Win32:Adware-gen. [Adw]" has been found in "C:/Recycled/Dc16.exe" file. 
2007-8-10 10:45:21 new 3988 Sign of "Win32:Adware-gen. [Adw]" has been found in "C:/Recycled/Dc17.exe/[ASPack]/[Embedded#018f20]" file. 
2007-8-10 10:45:21 new 3988 Sign of "Win32:Adware-gen. [Adw]" has been found in "C:/Recycled/Dc18.exe" file. 
2007-8-10 10:45:21 new 3988 Sign of "Win32:Adware-gen. [Adw]" has been found in "C:/Recycled/Dc19.exe" file. 
2007-8-10 10:45:21 new 3988 Sign of "Win32:Adware-gen. [Adw]" has been found in "C:/Recycled/Dc20.exe" file. 
2007-8-10 10:45:21 new 3988 Sign of "Win32:Adware-gen. [Adw]" has been found in "C:/Recycled/Dc21.exe" file. 
2007-8-10 10:45:21 new 3988 Sign of "Win32:Adware-gen. [Adw]" has been found in "C:/Recycled/Dc22.exe" file. 
2007-8-10 10:45:21 new 3988 Sign of "Win32:Adware-gen. [Adw]" has been found in "C:/Recycled/Dc23.exe" file. 
2007-8-10 10:45:21 new 3988 Sign of "Win32:Adware-gen. [Adw]" has been found in "C:/Recycled/Dc24.exe" file. 
2007-8-10 10:45:21 new 3988 Sign of "Win32:Adware-gen. [Adw]" has been found in "C:/Recycled/Dc25.exe" file. 
2007-8-10 10:45:23 new 3988 Sign of "Win32:Boran-M [Adw]" has been found in "C:/Recycled/Dc29/Content.IE5/ZQC6CEXG/ad_2238[1].exe/$TEMP/Insshell.exe/[Embedded#423d8]" file. 
2007-8-10 10:45:23 new 3988 Sign of "Win32:Boran-N [Adw]" has been found in "C:/Recycled/Dc29/Content.IE5/ZQC6CEXG/ad_2238[1].exe/$TEMP/Insshell.exe/[Embedded#5b3d8]" file. 
2007-8-10 10:45:23 new 3988 Sign of "Win32:Boran-N [Adw]" has been found in "C:/Recycled/Dc29/Content.IE5/ZQC6CEXG/ad_2238[1].exe/$TEMP/Insshell.exe/[Embedded#c63d8]" file. 
2007-8-10 10:45:23 new 3988 Sign of "Win32:Boran-M [Adw]" has been found in "C:/Recycled/Dc29/Content.IE5/ZQC6CEXG/ad_2238[1].exe/$TEMP/Insshell.exe" file. 
2007-8-10 10:45:24 new 3988 Sign of "Win32:Agent-JRJ [Trj]" has been found in "C:/Recycled/Dc29/Content.IE5/TEUMYP6T/my_70200[1].exe" file. 
2007-8-10 10:45:25 new 3988 Sign of "Win32:AdPlus [Adw]" has been found in "C:/Recycled/Dc41.tmp/Setup_QQ.exe/[UPX]" file. 
2007-8-10 10:45:26 new 3988 Sign of "Win32:Trojan-gen. {Other}" has been found in "C:/Ghost/original/boot.exe" file. 
2007-8-10 10:45:39 new 3988 Sign of "Win32:VB-DJP [Wrm]" has been found in "C:/quarantine/odbcasvc.EXE.Vir/[Upack]" file. 
2007-8-10 10:45:40 new 3988 Sign of "Win32:Delf-DTT [Trj]" has been found in "C:/quarantine/sys06.exe.Vir/[Upack]/[Embedded#DOWN]" file. 
2007-8-10 10:45:40 new 3988 Sign of "Win32:Delf-FFM [Trj]" has been found in "C:/quarantine/sys05.exe.Vir/[Upack]/[Embedded#DOWN]" file. 
2007-8-10 10:45:40 new 3988 Sign of "Win32:Delf-FFM [Trj]" has been found in "C:/quarantine/sys04.exe.Vir/[Upack]/[Embedded#DOWN]" file. 
2007-8-10 10:45:40 new 3988 Sign of "Win32:Delf-FFM [Trj]" has been found in "C:/quarantine/sys03.exe.Vir/[Upack]/[Embedded#DOWN]" file. 
2007-8-10 10:45:40 new 3988 Sign of "Win32:Delf-FFM [Trj]" has been found in "C:/quarantine/sys02.exe.Vir/[Upack]/[Embedded#DOWN]" file. 
2007-8-10 10:45:40 new 3988 Sign of "Win32:Delf-EQW [Trj]" has been found in "C:/quarantine/sys01.exe.Vir/[Upack]" file. 
2007-8-10 10:45:40 new 3988 Sign of "Win32:Cinmus-I [Adw]" has been found in "C:/quarantine/cpush.dll.Vir" file. 
2007-8-10 10:45:40 new 3988 Sign of "Win32:Delf-FFM [Trj]" has been found in "C:/quarantine/kulionzx.exe.Vir/[Upack]/[Embedded#DOWN]" file. 
2007-8-10 10:45:40 new 3988 Sign of "Win32:Delf-FFM [Trj]" has been found in "C:/quarantine/kulionrx.exe.Vir/[Upack]/[Embedded#DOWN]" file. 
2007-8-10 10:45:40 new 3988 Sign of "Win32:Delf-EQW [Trj]" has been found in "C:/quarantine/wmsj.exe.Vir/[Upack]" file. 
2007-8-10 10:45:40 new 3988 Sign of "Win32:Delf-FFM [Trj]" has been found in "C:/quarantine/winwm.exe.Vir/[Upack]/[Embedded#DOWN]" file. 
2007-8-10 10:45:40 new 3988 Sign of "Win32:Delf-FFM [Trj]" has been found in "C:/quarantine/winwl.exe.Vir/[Upack]/[Embedded#DOWN]" file. 
2007-8-10 10:45:40 new 3988 Sign of "Win32:Delf-DTT [Trj]" has been found in "C:/quarantine/winow.exe.Vir/[Upack]/[Embedded#DOWN]" file. 
2007-8-10 11:00:15 new 3988 Sign of "Win32:Trojan-gen. {Other}" has been found in "D:/Program Files/Maxthon/Thundermini/xunleibho_v4.dll" file. 
2007-8-10 11:07:11 new 3988 Sign of "Win32:Trojan-gen. {UPX!}" has been found in "D:/Program Files/QQDoctor/TSECUA.COM" file. 
2007-8-10 11:09:55 new 3988 Sign of "Win32:Trojan-gen. {Other}" has been found in "D:/System Volume Information/_restore{31EC3B86-07D6-4822-8C77-AF04A1D9D099}/RP54/A0009131.dll/[Embedded#22250]" file. 
2007-8-10 11:11:28 new 3988 Sign of "Win32:Trojan-gen. {Other}" has been found in "D:/System Volume Information/_restore{7619898A-B5C3-490F-A9B0-454B4418678B}/RP256/A0051120.dll" file. 
2007-8-10 11:11:28 new 3988 Sign of "Win32:Trojan-gen. {UPX!}" has been found in "D:/System Volume Information/_restore{7619898A-B5C3-490F-A9B0-454B4418678B}/RP256/A0051121.COM" file. 
2007-8-10 11:14:46 new 3988 Sign of "Win32:VB-DJP [Wrm]" has been found in "E:/Recycled/INFO.EXE/[Upack]" file. 
2007-8-10 11:15:31 new 3988 Sign of "Win32:Trojan-gen. {Other}" has been found in "E:/System Volume Information/_restore{31EC3B86-07D6-4822-8C77-AF04A1D9D099}/RP53/A0008589.exe/$INSTDIR/Thundermini/xunleibho_v4.dll" file. 
2007-8-10 11:15:33 new 3988 Sign of "Win32:Trojan-gen. {Other}" has been found in "E:/System Volume Information/_restore{31EC3B86-07D6-4822-8C77-AF04A1D9D099}/RP53/A0008590.exe/$INSTDIR/Plugins/xpsp2.dll/[Embedded#22250]" file. 
2007-8-10 11:15:52 new 3988 Sign of "Win32:QQHelper-BF [Trj]" has been found in "E:/System Volume Information/_restore{7619898A-B5C3-490F-A9B0-454B4418678B}/RP246/A0036875.exe/$TEMP/kzdh.exe" file. 
2007-8-10 11:15:52 new 3988 Sign of "Win32:Adware-gen. [Adw]" has been found in "E:/System Volume Information/_restore{7619898A-B5C3-490F-A9B0-454B4418678B}/RP246/A0036875.exe/$TEMP/bimonycb.exe" file. 
2007-8-10 11:16:05 new 3988 Sign of "Win32:Ieser-J [Trj]" has been found in "E:/System Volume Information/_restore{7619898A-B5C3-490F-A9B0-454B4418678B}/RP252/A0049673.exe/[PECompact]/[Embedded#123]" file. 
2007-8-10 11:16:06 new 3988 Sign of "Win32:VB-DJP [Wrm]" has been found in "E:/System Volume Information/_restore{7619898A-B5C3-490F-A9B0-454B4418678B}/RP256/A0051122.EXE/[Upack]" file. 
2007-8-10 11:16:53 new 3988 Sign of "Win32:Adware-gen. [Adw]" has been found in "E:/安装文件备份/BitTorrent Plus! 1.3 Beta2.exe/$TEMP/BaiduBar.exe/$INSTDIR/BaiduBar.dll" file. 
2007-8-10 11:16:53 new 3988 Sign of "Win32:Trojan-gen. {Other}" has been found in "E:/安装文件备份/BitTorrent Plus! 1.3 Beta2.exe/$TEMP/BaiduBar.exe" file. 
2007-8-10 11:16:53 new 3988 Sign of "Win32:Adware-gen. [Adw]" has been found in "E:/安装文件备份/BitTorrent Plus! 1.3 Beta2.exe/$TEMP/CNNIC.exe/[ASPack]/[Embedded#018f20]" file. 
2007-8-10 11:19:55 new 3988 Sign of "Win32:Trojan-gen. {Other}" has been found in "E:/安装文件备份/FlashPlayer.rar/FlashPlayer.EXE/Wise0020.bin/Wise0011.bin" file. 
2007-8-10 11:19:55 new 3988 Sign of "Win32:Small-BTZ [Trj]" has been found in "E:/安装文件备份/FlashPlayer.rar/FlashPlayer.EXE/Wise0020.bin" file. 
2007-8-10 11:19:56 new 3988 Sign of "Win32:VB-BBW [Trj]" has been found in "E:/安装文件备份/FlashPlayer.rar/FlashPlayer.EXE/Wise0151.bin/[ASPack]" file. 
2007-8-10 11:19:56 new 3988 Sign of "Win32:Small-BTZ [Trj]" has been found in "E:/安装文件备份/FlashPlayer.rar/FlashPlayer.EXE" file. 
2007-8-10 14:49:25 SYSTEM 1196 Sign of "Win32:Cinmus-D [Adw]" has been found in "C:/WINDOWS/System32/msplrct.dll" file. 
2007-8-10 14:49:25 SYSTEM 1196 Sign of "Win32:Cinmus-D [Adw]" has been found in "C:/WINDOWS/system32/msplrct.dll" file. 
2007-8-10 14:58:44 new 3260 Sign of "Win32:Trojan-gen. {UPX!}" has been found in "C:/Documents and Settings/new/桌面/资料/IPQQ2007_v5.0.rar/IPQQ2007.exe/$INSTDIR/../QQDoctor/TSECUA.COM" file. 
2007-8-10 15:04:38 new 3260 Sign of "Win32:Trojan-gen. {UPX!}" has been found in "C:/System Volume Information/_restore{7619898A-B5C3-490F-A9B0-454B4418678B}/RP254/A0050686.exe/$INSTDIR/../QQDoctor/TSECUA.COM" file. 
2007-8-10 15:05:00 new 3260 Sign of "Win32:VB-DJP [Wrm]" has been found in "C:/System Volume Information/_restore{7619898A-B5C3-490F-A9B0-454B4418678B}/RP256/A0051099.exe/[Upack]" file. 
2007-8-10 15:05:06 new 3260 Sign of "Win32:Adware-gen. [Adw]" has been found in "C:/System Volume Information/_restore{7619898A-B5C3-490F-A9B0-454B4418678B}/RP256/A0051100.exe" file. 
2007-8-10 15:05:10 new 3260 Sign of "Win32:Adware-gen. [Adw]" has been found in "C:/System Volume Information/_restore{7619898A-B5C3-490F-A9B0-454B4418678B}/RP256/A0051101.exe" file. 
2007-8-10 15:05:13 new 3260 Sign of "Win32:Adware-gen. [Adw]" has been found in "C:/System Volume Information/_restore{7619898A-B5C3-490F-A9B0-454B4418678B}/RP256/A0051102.exe/[ASPack]/[Embedded#009150]" file. 
2007-8-10 15:05:15 new 3260 Sign of "Win32:Agent-IXE [Trj]" has been found in "C:/System Volume Information/_restore{7619898A-B5C3-490F-A9B0-454B4418678B}/RP256/A0051103.exe/[NsPack]/[Embedded#4070]/[NsPack]/[Embedded#12070]/[NsPack]" file. 
2007-8-10 15:05:18 new 3260 Sign of "Win32:Adware-gen. [Adw]" has been found in "C:/System Volume Information/_restore{7619898A-B5C3-490F-A9B0-454B4418678B}/RP256/A0051104.exe" file. 
2007-8-10 15:05:20 new 3260 Sign of "Win32:Adware-gen. [Adw]" has been found in "C:/System Volume Information/_restore{7619898A-B5C3-490F-A9B0-454B4418678B}/RP256/A0051105.exe/[ASPack]/[Embedded#018f20]" file. 
2007-8-10 15:05:22 new 3260 Sign of "Win32:Adware-gen. [Adw]" has been found in "C:/System Volume Information/_restore{7619898A-B5C3-490F-A9B0-454B4418678B}/RP256/A0051106.exe" file. 
2007-8-10 15:05:24 new 3260 Sign of "Win32:Adware-gen. [Adw]" has been found in "C:/System Volume Information/_restore{7619898A-B5C3-490F-A9B0-454B4418678B}/RP256/A0051107.exe" file. 
2007-8-10 15:05:26 new 3260 Sign of "Win32:Adware-gen. [Adw]" has been found in "C:/System Volume Information/_restore{7619898A-B5C3-490F-A9B0-454B4418678B}/RP256/A0051108.exe" file. 
2007-8-10 15:05:28 new 3260 Sign of "Win32:Adware-gen. [Adw]" has been found in "C:/System Volume Information/_restore{7619898A-B5C3-490F-A9B0-454B4418678B}/RP256/A0051109.exe" file. 
2007-8-10 15:05:30 new 3260 Sign of "Win32:Adware-gen. [Adw]" has been found in "C:/System Volume Information/_restore{7619898A-B5C3-490F-A9B0-454B4418678B}/RP256/A0051110.exe" file. 
2007-8-10 15:05:32 new 3260 Sign of "Win32:Adware-gen. [Adw]" has been found in "C:/System Volume Information/_restore{7619898A-B5C3-490F-A9B0-454B4418678B}/RP256/A0051111.exe" file. 
2007-8-10 15:05:35 new 3260 Sign of "Win32:Adware-gen. [Adw]" has been found in "C:/System Volume Information/_restore{7619898A-B5C3-490F-A9B0-454B4418678B}/RP256/A0051112.exe" file. 
2007-8-10 15:05:38 new 3260 Sign of "Win32:Adware-gen. [Adw]" has been found in "C:/System Volume Information/_restore{7619898A-B5C3-490F-A9B0-454B4418678B}/RP256/A0051113.exe" file. 
2007-8-10 15:05:41 new 3260 Sign of "Win32:Boran-M [Adw]" has been found in "C:/System Volume Information/_restore{7619898A-B5C3-490F-A9B0-454B4418678B}/RP256/A0051114.exe/$TEMP/Insshell.exe/[Embedded#423d8]" file. 
2007-8-10 15:05:43 new 3260 Sign of "Win32:Boran-N [Adw]" has been found in "C:/System Volume Information/_restore{7619898A-B5C3-490F-A9B0-454B4418678B}/RP256/A0051114.exe/$TEMP/Insshell.exe/[Embedded#5b3d8]" file. 
2007-8-10 15:05:46 new 3260 Sign of "Win32:Boran-N [Adw]" has been found in "C:/System Volume Information/_restore{7619898A-B5C3-490F-A9B0-454B4418678B}/RP256/A0051114.exe/$TEMP/Insshell.exe/[Embedded#c63d8]" file. 
2007-8-10 15:05:48 new 3260 Sign of "Win32:Boran-M [Adw]" has been found in "C:/System Volume Information/_restore{7619898A-B5C3-490F-A9B0-454B4418678B}/RP256/A0051114.exe/$TEMP/Insshell.exe" file. 
2007-8-10 15:05:51 new 3260 Sign of "Win32:Agent-JRJ [Trj]" has been found in "C:/System Volume Information/_restore{7619898A-B5C3-490F-A9B0-454B4418678B}/RP256/A0051115.exe" file. 
2007-8-10 15:05:53 new 3260 Sign of "Win32:AdPlus [Adw]" has been found in "C:/System Volume Information/_restore{7619898A-B5C3-490F-A9B0-454B4418678B}/RP256/A0051116.exe/[UPX]" file. 
2007-8-10 15:05:55 new 3260 Sign of "Win32:Trojan-gen. {Other}" has been found in "C:/System Volume Information/_restore{7619898A-B5C3-490F-A9B0-454B4418678B}/RP256/A0051117.exe" file. 
2007-8-10 15:44:54 new 3260 Sign of "Win32:Adware-gen. [Adw]" has been found in "E:/System Volume Information/_restore{7619898A-B5C3-490F-A9B0-454B4418678B}/RP256/A0051123.exe/$TEMP/BaiduBar.exe/$INSTDIR/BaiduBar.dll" file. 
2007-8-10 15:45:42 new 3260 Sign of "Win32:Trojan-gen. {Other}" has been found in "E:/System Volume Information/_restore{7619898A-B5C3-490F-A9B0-454B4418678B}/RP256/A0051123.exe/$TEMP/BaiduBar.exe" file. 
2007-8-10 15:45:45 new 3260 Sign of "Win32:Adware-gen. [Adw]" has been found in "E:/System Volume Information/_restore{7619898A-B5C3-490F-A9B0-454B4418678B}/RP256/A0051123.exe/$TEMP/CNNIC.exe/[ASPack]/[Embedded#018f20]" file. 
2007-8-10 16:15:11 new 3260 Sign of "Win32:Trojan-gen. {VC}" has been found in "E:/安装文件备份/qq2006standard.exe/$[65]/config/Original/QQGame.exe" file. 
2007-8-10 16:15:33 new 3260 Sign of "Win32:Adware-gen. [Adw]" has been found in "E:/安装文件备份/StormCodec6.04.08.exe/$TEMP/mms.exe/$INSTDIR/$INSTDIR/Mmsass~1.dll" file. 
2007-8-10 16:15:39 new 3260 Sign of "Win32:Adware-gen. [Adw]" has been found in "E:/安装文件备份/StormCodec6.04.08.exe/$TEMP/mms.exe" file. 
2007-8-10 16:15:53 new 3260 Sign of "Win32:Adware-gen. [Adw]" has been found in "E:/安装文件备份/ttpsetup.exe/files/BaiduBar.dll" file. 
2007-8-10 16:16:19 new 3260 Sign of "Win32:Small-EFC [Trj]" has been found in "E:/安装文件备份/upload2006112035412setup.exe/bind_50024.exe" file. 
2007-8-10 16:16:23 new 3260 Sign of "Win32:Small-EXB [Trj]" has been found in "E:/安装文件备份/upload2006112035412setup.exe/5715.exe/[NsPack]/[Embedded#4010]/[NsPack]" file. 
2007-8-10 16:16:25 new 3260 Sign of "Win32:Qqhelper-CY [Trj]" has been found in "E:/安装文件备份/upload2006112035412setup.exe/ssof17.exe/$SYSDIR/drwtsm32.exe/[Embedded#EGG1]" file. 
2007-8-10 16:16:28 new 3260 Sign of "Win32:Qqhelper-BW [Trj]" has been found in "E:/安装文件备份/upload2006112035412setup.exe/ssof17.exe/$SYSDIR/drwtsm32.exe" file. 
2007-8-10 16:16:30 new 3260 Sign of "Win32:Adware-gen. [Adw]" has been found in "E:/安装文件备份/upload2006112035412setup.exe/ssof17.exe/$SYSDIR/202.exe/$COMMONFILES/CPUSH/cpush.dll" file. 
2007-8-10 16:16:32 new 3260 Sign of "Win32:Adware-gen. [Adw]" has been found in "E:/安装文件备份/upload2006112035412setup.exe/ssof17.exe/$SYSDIR/202.exe" file. 
2007-8-10 16:16:34 new 3260 Sign of "Win32:Trojan-gen. {Other}" has been found in "E:/安装文件备份/upload2006112035412setup.exe/ssof17.exe" file. 
2007-8-10 16:30:30 new 3260 Sign of "Win32:VB-QK [Trj]" has been found in "E:/安装文件备份/webhy.zip/webhy.exe/webhy/setup.exe/[ASPack]" file. 
2007-8-10 16:30:37 new 3260 Sign of "Win32:QQHelper-BK [Trj]" has been found in "E:/安装文件备份/webhy.zip/webhy.exe/webhy/yqu.exe/bind_50100.exe" file. 
2007-8-10 16:30:39 new 3260 Sign of "Win32:Baidu-B [Adw]" has been found in "E:/安装文件备份/webhy.zip/webhy.exe/webhy/yqu.exe/yqud.exe/BaiduBar.dll" file. 
2007-8-10 16:30:41 new 3260 Sign of "Win32:Adware-gen. [Adw]" has been found in "E:/安装文件备份/webhy.zip/webhy.exe/webhy/yqu.exe/yqud.exe" file. 
2007-8-10 16:30:43 new 3260 Sign of "Win32:Delf-FCJ [Trj]" has been found in "E:/安装文件备份/webhy.zip/webhy.exe/webhy/yqu.exe/yqu.exe" file. 
2007-8-10 16:30:45 new 3260 Sign of "Win32:Adware-gen. [Adw]" has been found in "E:/安装文件备份/webhy.zip/webhy.exe/webhy/yqu.exe/cngr.exe/[ASPack]/[Embedded#009150]" file. 
2007-8-10 16:30:53 new 3260 Sign of "Win32:Adware-gen. [Adw]" has been found in "E:/安装文件备份/WindowsXP-KB835935-SP2-CHS.exe/i386/6to4svc.dl_/6to4svc.dll" file. 
2007-8-10 16:31:51 new 3260 Sign of "Win32:Adware-gen. [Adw]" has been found in "E:/安装文件备份/WindowsXP-KB835935-SP2-CHS.exe/i386/fltmc.ex_/fltmc.exe" file. 
2007-8-10 16:33:57 new 3260 Sign of "Win32:Trojan-gen. {Other}" has been found in "E:/安装文件备份/优化大师附注册机/优化大师6.56.exe/assist4.exe/Wise0019.bin" file. 
2007-8-10 16:36:38 new 3260 Sign of "Win32:VB-DJP [Wrm]" has been found in "F:/Recycled/INFO.EXE/[Upack]" file. 
2007-8-10 16:37:13 new 3260 Sign of "Win32:Ieser-J [Trj]" has been found in "F:/System Volume Information/_restore{7619898A-B5C3-490F-A9B0-454B4418678B}/RP252/A0049677.exe/[PECompact]/[Embedded#123]" file. 
2007-8-10 16:37:17 new 3260 Sign of "Win32:VB-DJP [Wrm]" has been found in "F:/System Volume Information/_restore{7619898A-B5C3-490F-A9B0-454B4418678B}/RP256/A0051164.EXE/[Upack]" file. 
2007-8-10 16:44:44 new 3260 Sign of "Win32:Trojan-gen. {UPX!}" has been found in "F:/资料/工具/WinRAR 3.50 Beta 3 汉化美化版.exe/Default.sfx" file. 
2007-8-10 16:44:54 new 3260 Sign of "Win32:Baidu-C [Trj]" has been found in "F:/资料/工具/优化大师/Wom.exe/setup_lamblujincb.exe/BaiduBar.dll" file. 
2007-8-10 16:44:58 new 3260 Sign of "Win32:Trojan-gen. {Other}" has been found in "F:/资料/工具/优化大师/Wom.exe/assist4.exe/Wise0019.bin" file. 
2007-8-10 16:45:00 new 3260 Sign of "Win32:Adware-gen. [Adw]" has been found in "F:/资料/工具/天网/SkynetPFW_Beta_v2.8_Build0909.EXE/UNREGSKYPFW.EXE" file. 
2007-8-10 16:55:59 new 3260 Sign of "Win32:VB-DJP [Wrm]" has been found in "G:/Recycled/INFO.EXE/[Upack]" file. 
2007-8-10 16:56:11 new 3260 Sign of "Win32:Ieser-J [Trj]" has been found in "G:/System Volume Information/_restore{7619898A-B5C3-490F-A9B0-454B4418678B}/RP252/A0049680.exe/[PECompact]/[Embedded#123]" file. 
2007-8-10 16:57:12 new 3260 Sign of "Win32:VB-DJP [Wrm]" has been found in "G:/System Volume Information/_restore{7619898A-B5C3-490F-A9B0-454B4418678B}/RP256/A0051168.EXE/[Upack]" file. 
2007-8-10 18:16:58 SYSTEM 1208 Sign of "Win32:Cinmus-D [Adw]" has been found in "C:/WINDOWS/System32/msplrct.dll" file. 
2007-8-10 18:16:59 SYSTEM 1208 Sign of "Win32:Cinmus-D [Adw]" has been found in "C:/WINDOWS/system32/msplrct.dll" file. 
2007-8-10 19:12:12 SYSTEM 1188 Sign of "Win32:Cinmus-D [Adw]" has been found in "C:/WINDOWS/System32/msplrct.dll" file. 
2007-8-10 19:12:12 SYSTEM 1188 Sign of "Win32:Cinmus-D [Adw]" has been found in "C:/WINDOWS/system32/msplrct.dll" file. 
2007-8-11 8:30:27 SYSTEM 1188 Sign of "Win32:Cinmus-D [Adw]" has been found in "C:/WINDOWS/System32/msplrct.dll" file. 
2007-8-11 8:30:27 SYSTEM 1188 Sign of "Win32:Cinmus-D [Adw]" has been found in "C:/WINDOWS/system32/msplrct.dll" file. 
2007-8-11 13:27:41 SYSTEM 1208 Sign of "Win32:Cinmus-D [Adw]" has been found in "C:/WINDOWS/System32/msplrct.dll" file. 
2007-8-11 13:27:41 SYSTEM 1208 Sign of "Win32:Cinmus-D [Adw]" has been found in "C:/WINDOWS/system32/msplrct.dll" file. 
2007-8-11 13:44:21 SYSTEM 1176 Sign of "Win32:Cinmus-D [Adw]" has been found in "C:/WINDOWS/System32/msplrct.dll" file. 
2007-8-11 13:44:21 SYSTEM 1176 Sign of "Win32:Cinmus-D [Adw]" has been found in "C:/WINDOWS/system32/msplrct.dll" file. 
2007-8-11 21:43:59 SYSTEM 1180 Sign of "Win32:Cinmus-D [Adw]" has been found in "C:/WINDOWS/System32/msplrct.dll" file. 
2007-8-11 21:43:59 SYSTEM 1180 Sign of "Win32:Cinmus-D [Adw]" has been found in "C:/WINDOWS/system32/msplrct.dll" file. 
2007-8-12 10:16:46 SYSTEM 1180 Sign of "Win32:Cinmus-D [Adw]" has been found in "C:/WINDOWS/System32/msplrct.dll" file. 
2007-8-12 10:16:46 SYSTEM 1180 Sign of "Win32:Cinmus-D [Adw]" has been found in "C:/WINDOWS/system32/msplrct.dll" file. 
2007-8-12 10:31:45 SYSTEM 1180 Sign of "Win32:Cinmus-D [Adw]" has been found in "C:/WINDOWS/System32/msplrct.dll" file. 
2007-8-12 10:31:45 SYSTEM 1180 Sign of "Win32:Cinmus-D [Adw]" has been found in "C:/WINDOWS/system32/msplrct.dll" file. 
2007-8-12 10:41:18 SYSTEM 1180 Sign of "Win32:Cinmus-D [Adw]" has been found in "C:/WINDOWS/System32/msplrct.dll" file. 
2007-8-12 10:41:18 SYSTEM 1180 Sign of "Win32:Cinmus-D [Adw]" has been found in "C:/WINDOWS/system32/msplrct.dll" file. 
2007-8-12 11:42:04 SYSTEM 1212 Sign of "Win32:Cinmus-D [Adw]" has been found in "C:/WINDOWS/System32/msplrct.dll" file. 
2007-8-12 11:42:04 SYSTEM 1212 Sign of "Win32:Cinmus-D [Adw]" has been found in "C:/WINDOWS/system32/msplrct.dll" file. 
2007-8-12 13:03:45 SYSTEM 1216 Sign of "Win32:Cinmus-D [Adw]" has been found in "C:/WINDOWS/System32/msplrct.dll" file. 
2007-8-12 13:03:45 SYSTEM 1216 Sign of "Win32:Cinmus-D [Adw]" has been found in "C:/WINDOWS/system32/msplrct.dll" file. 

//--7---

mvplayer.syb注册成了服务“Network Connections”,描述为“管理‘网络与拨号连接’文件夹中的对象。。。”

djkk.exe也注册成了服务“WindowsDsss”,描述为“为即插即用设备提供支持”。

// --END--------

如有哪位大虾发现我有删错的和漏删的,谢谢告知。不甚感及。

又挽救了一台电脑。

最看不起老重装系统了。对系统重装呗儿熟(辈儿熟?哪个?抑或其它)不是高手,高手从不重装系统。

你可能感兴趣的:(清理或破坏病毒流氓若干)