Jump to content

CAN RAMNIT SURVIVE A SYSTEM RECOVERY?


Recommended Posts

I am in urgent need of some advice. A couple of weeks ago my computer was infested with hundreds of Ramnit.g viruses and after contacting this forum I was advised that the only option open to me was a reformat of the hard drive and os reinstallation. I used the HP destructive recovery process which does this and thought everything was fine (it did the reformat and reinstallation as it warned me before starting). Today I did a virus scan with Avast and it came back with 527 instances of Ramnit.g. Not knowing if I had reinfected my PC over the last 2 weeks, I today did another destructive system recovery and have only been online to download the free avast virus software. I have just run the scan and again it has found hundreds of this ramnit virus. It seems that ramnit survived 2 destructive system recoverys and I am at a loss on what to do next. I was under the impression and was advised by this forum that a complete system recovery was the only way to be sure that ramnit had gone but here it still is. PLEASE HELP!!.

Link to post
Share on other sites

Scanned with Malwarebytes which strangely shows no infections but here is the log anyway:

Malwarebytes' Anti-Malware 1.50.1.1100

www.malwarebytes.org

Database version: 6455

Windows 5.1.2600 Service Pack 2

Internet Explorer 6.0.2900.2180

27/04/2011 11:23:22

mbam-log-2011-04-27 (11-23-22).txt

Scan type: Quick scan

Objects scanned: 148598

Time elapsed: 5 minute(s), 20 second(s)

Memory Processes Infected: 0

Memory Modules Infected: 0

Registry Keys Infected: 0

Registry Values Infected: 0

Registry Data Items Infected: 0

Folders Infected: 0

Files Infected: 0

Memory Processes Infected:

(No malicious items detected)

Memory Modules Infected:

(No malicious items detected)

Registry Keys Infected:

(No malicious items detected)

Registry Values Infected:

(No malicious items detected)

Registry Data Items Infected:

(No malicious items detected)

Folders Infected:

(No malicious items detected)

Files Infected:

(No malicious items detected)

Link to post
Share on other sites

.

DDS (Ver_11-03-05.01) - NTFSx86

Run by Compaq_Administrator at 11:28:58.18 on 27/04/2011

Internet Explorer: 6.0.2900.2180

Microsoft Windows XP Professional 5.1.2600.2.1252.44.1033.18.958.573 [GMT 1:00]

.

AV: avast! Antivirus *Enabled/Updated* {7591DB91-41F0-48A3-B128-1A293FD8233D}

.

============== Running Processes ===============

.

C:\WINDOWS\system32\svchost -k DcomLaunch

svchost.exe

C:\WINDOWS\System32\svchost.exe -k netsvcs

svchost.exe

svchost.exe

C:\WINDOWS\Explorer.EXE

C:\Program Files\AVAST Software\Avast\AvastSvc.exe

C:\WINDOWS\ehome\ehtray.exe

C:\WINDOWS\RTHDCPL.EXE

C:\Program Files\HP\HP Software Update\HPwuSchd2.exe

C:\Program Files\AVAST Software\Avast\avastUI.exe

C:\Program Files\Messenger\msmsgs.exe

C:\WINDOWS\system32\spoolsv.exe

C:\WINDOWS\arservice.exe

C:\WINDOWS\eHome\ehRecvr.exe

C:\WINDOWS\eHome\ehSched.exe

C:\WINDOWS\system32\nvsvc32.exe

svchost.exe

C:\WINDOWS\system32\wuauclt.exe

C:\WINDOWS\system32\dllhost.exe

C:\WINDOWS\eHome\ehmsas.exe

C:\HP\KBD\KBD.EXE

c:\windows\system\hpsysdrv.exe

C:\WINDOWS\system32\NOTEPAD.EXE

C:\WINDOWS\System32\svchost.exe -k HTTPFilter

C:\WINDOWS\system32\wuauclt.exe

C:\Program Files\Internet Explorer\iexplore.exe

C:\Documents and Settings\Compaq_Administrator\Local Settings\Temporary Internet Files\Content.IE5\C1UZ85IR\dds[1].scr

.

============== Pseudo HJT Report ===============

.

uStart Page = hxxp://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iehome&locale=EN_GB&c=64&bd=PRESARIO&pf=desktop

uSearch Page = hxxp://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iesearch&locale=EN_GB&c=64&bd=PRESARIO&pf=desktop

uDefault_Page_URL = hxxp://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iehome&locale=EN_GB&c=64&bd=PRESARIO&pf=desktop

uDefault_Search_URL = hxxp://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iesearch&locale=EN_GB&c=64&bd=PRESARIO&pf=desktop

uSearch Bar = hxxp://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iesearch&locale=EN_GB&c=64&bd=PRESARIO&pf=desktop

mDefault_Page_URL = hxxp://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iehome&locale=EN_GB&c=64&bd=PRESARIO&pf=desktop

mDefault_Search_URL = hxxp://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iesearch&locale=EN_GB&c=64&bd=PRESARIO&pf=desktop

mSearch Page = hxxp://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iesearch&locale=EN_GB&c=64&bd=PRESARIO&pf=desktop

mStart Page = hxxp://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iehome&locale=EN_GB&c=64&bd=PRESARIO&pf=desktop

mSearch Bar = hxxp://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iesearch&locale=EN_GB&c=64&bd=PRESARIO&pf=desktop

mSearchAssistant = hxxp://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iesearch&locale=EN_GB&c=64&bd=PRESARIO&pf=desktop

BHO: AcroIEHlprObj Class: {06849e9f-c8d7-4d59-b87d-784b7d6be0b3} - c:\program files\adobe\acrobat 7.0\activex\AcroIEHelper.dll

BHO: SSVHelper Class: {761497bb-d6f0-462c-b6eb-d4daf1d92d43} - c:\program files\java\jre1.5.0_06\bin\ssv.dll

BHO: Google Toolbar Helper: {aa58ed58-01dd-4d91-8333-cf10577473f7} - c:\program files\google\googletoolbar1.dll

TB: &Google: {2318c2b1-4965-11d4-9b18-009027a5cd4f} - c:\program files\google\googletoolbar1.dll

TB: {C4069E3A-68F1-403E-B40E-20066696354B} - No File

uRun: [MSMSGS] "c:\program files\messenger\msmsgs.exe" /background

mRun: [ehTray] c:\windows\ehome\ehtray.exe

mRun: [ftutil2] rundll32.exe ftutil2.dll,SetWriteCacheMode

mRun: [RTHDCPL] RTHDCPL.EXE

mRun: [AlwaysReady Power Message APP] ARPWRMSG.EXE

mRun: [NvCplDaemon] RUNDLL32.EXE c:\windows\system32\NvCpl.dll,NvStartup

mRun: [nwiz] nwiz.exe /install

mRun: [Recguard] c:\windows\sminst\RECGUARD.EXE

mRun: [PCDrProfiler]

mRun: [HPBootOp] "c:\program files\hewlett-packard\hp boot optimizer\HPBootOp.exe" /run

mRun: [Reminder] "c:\windows\creator\Remind_XP.exe"

mRun: [HP Software Update] c:\program files\hp\hp software update\HPwuSchd2.exe

mRun: [avast] "c:\program files\avast software\avast\avastUI.exe" /nogui

mRunOnce: [Malwarebytes' Anti-Malware] c:\program files\malwarebytes' anti-malware\mbamgui.exe /install /silent

IE: &Google Search - c:\program files\google\GoogleToolbar1.dll/cmsearch.html

IE: &Translate English Word - c:\program files\google\GoogleToolbar1.dll/cmwordtrans.html

IE: Backward Links - c:\program files\google\GoogleToolbar1.dll/cmbacklinks.html

IE: Cached Snapshot of Page - c:\program files\google\GoogleToolbar1.dll/cmcache.html

IE: Similar Pages - c:\program files\google\GoogleToolbar1.dll/cmsimilar.html

IE: Translate Page into English - c:\program files\google\GoogleToolbar1.dll/cmtrans.html

IE: {E2D4D26B-0180-43a4-B05F-462D6D54C789} - c:\windows\pchealth\helpctr\vendors\cn=hewlett-packard,l=cupertino,s=ca,c=us\iebutton\support.htm

IE: {FB5F1910-F110-11d2-BB9E-00C04F795683} - c:\program files\messenger\msmsgs.exe

IE: {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - {CAFEEFAC-0015-0000-0006-ABCDEFFEDCBC} - c:\program files\java\jre1.5.0_06\bin\ssv.dll

DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.5.0/jinstall-1_5_0_06-windows-i586.cab

DPF: {CAFEEFAC-0015-0000-0006-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.5.0/jinstall-1_5_0_06-windows-i586.cab

DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.5.0/jinstall-1_5_0_06-windows-i586.cab

.

============= SERVICES / DRIVERS ===============

.

R1 aswSnx;aswSnx;c:\windows\system32\drivers\aswSnx.sys [2011-4-24 441176]

R1 aswSP;aswSP;c:\windows\system32\drivers\aswSP.sys [2011-4-24 307288]

R2 aswFsBlk;aswFsBlk;c:\windows\system32\drivers\aswFsBlk.sys [2011-4-24 19544]

R2 avast! Antivirus;avast! Antivirus;c:\program files\avast software\avast\AvastSvc.exe [2011-4-24 42184]

R2 McrdSvc;Media Center Extender Service;c:\windows\ehome\mcrdsvc.exe [2005-8-5 99328]

.

=============== Created Last 30 ================

.

2011-04-27 10:16:15 -------- d-----w- c:\docume~1\compaq~1\applic~1\Malwarebytes

2011-04-27 10:16:05 38224 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys

2011-04-27 10:16:04 -------- d-----w- c:\docume~1\alluse~1\applic~1\Malwarebytes

2011-04-27 10:16:00 20952 ----a-w- c:\windows\system32\drivers\mbam.sys

2011-04-27 10:15:59 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware

2011-04-27 08:12:08 -------- d-----w- c:\windows\system32\PreInstall

2011-04-25 01:42:12 -------- d-----r- C:\Program Files

2011-04-25 01:40:59 -------- d-----r- c:\documents and settings\all users\Documents

2011-04-25 01:39:07 -------- d-----r- c:\windows\Offline Web Pages

2011-04-25 01:36:15 -------- d-sh--r- c:\windows\system32\dllcache

2011-04-24 19:14:28 441176 ----a-w- c:\windows\system32\drivers\aswSnx.sys

2011-04-24 19:14:16 40112 ----a-w- c:\windows\avastSS.scr

2011-04-24 19:14:07 -------- d-----w- c:\program files\AVAST Software

2011-04-24 19:14:07 -------- d-----w- c:\docume~1\alluse~1\applic~1\AVAST Software

2011-04-24 19:00:50 -------- d-sh--r- C:\cmdcons

2011-04-24 19:00:48 -------- d-----w- c:\windows\setup.pss

2011-04-24 19:00:29 -------- d-----w- c:\windows\setupupd

2011-04-24 18:55:03 -------- d-----w- c:\windows\system32\SoftwareDistribution

.

==================== Find3M ====================

.

.

============= FINISH: 11:31:30.71 ===============

Link to post
Share on other sites

ComboFix 11-04-27.02 - Compaq_Administrator 28/04/2011 10:06:49.1.1 - x86

Microsoft Windows XP Professional 5.1.2600.2.1252.44.1033.18.958.621 [GMT 1:00]

Running from: c:\documents and settings\Compaq_Administrator\Desktop\ComboFix.exe

AV: avast! Antivirus *Disabled/Updated* {7591DB91-41F0-48A3-B128-1A293FD8233D}

.

.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))

.

.

c:\documents and settings\Administrator\WINDOWS

c:\documents and settings\Compaq_Administrator\WINDOWS

c:\documents and settings\Default User\WINDOWS

c:\windows\system32\_000003_.tmp.dll

c:\windows\system32\_000005_.tmp.dll

c:\windows\system32\_000006_.tmp.dll

c:\windows\system32\_000007_.tmp.dll

c:\windows\system32\_000013_.tmp.dll

c:\windows\system32\config\systemprofile\WINDOWS

.

.

((((((((((((((((((((((((( Files Created from 2011-03-28 to 2011-04-28 )))))))))))))))))))))))))))))))

.

.

2011-04-28 09:01 . 2006-08-21 12:21 16896 ----a-w- c:\windows\system32\SET252.tmp

2011-04-28 09:01 . 2006-08-21 09:14 23040 ----a-w- c:\windows\system32\SET251.tmp

2011-04-28 08:58 . 2011-04-28 08:58 -------- d-----w- c:\windows\ServicePackFiles

2011-04-28 08:54 . 2011-04-28 09:01 -------- d-----w- c:\windows\LastGood

2011-04-27 10:16 . 2010-12-20 17:09 38224 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys

2011-04-27 10:16 . 2010-12-20 17:08 20952 ----a-w- c:\windows\system32\drivers\mbam.sys

2011-04-27 09:01 . 2009-08-21 09:46 450560 ------w- c:\windows\system32\SET1CA.tmp

2011-04-27 09:00 . 2008-10-15 16:57 332800 ----a-w- c:\windows\system32\SETFF.tmp

2011-04-27 08:52 . 2010-02-12 10:03 293376 ------w- c:\windows\system32\browserchoice.exe

2011-04-25 01:42 . 2011-04-28 08:56 -------- d-----r- C:\Program Files

2011-04-25 01:40 . 2011-04-25 01:45 -------- d-----r- c:\documents and settings\All Users\Documents

2011-04-25 01:36 . 2011-04-28 09:03 -------- d-sh--r- c:\windows\system32\dllcache

2011-04-24 19:26 . 2008-09-04 16:42 1106944 ----a-w- c:\windows\system32\SETE6.tmp

2011-04-24 19:14 . 2011-04-18 17:12 19544 ----a-w- c:\windows\system32\drivers\aswFsBlk.sys

2011-04-24 19:14 . 2011-04-18 17:17 307288 ----a-w- c:\windows\system32\drivers\aswSP.sys

2011-04-24 19:14 . 2011-04-18 17:16 49240 ----a-w- c:\windows\system32\drivers\aswTdi.sys

2011-04-24 19:14 . 2011-04-18 17:13 25432 ----a-w- c:\windows\system32\drivers\aswRdr.sys

2011-04-24 19:14 . 2011-04-18 17:17 441176 ----a-w- c:\windows\system32\drivers\aswSnx.sys

2011-04-24 19:14 . 2011-04-18 17:16 102488 ----a-w- c:\windows\system32\drivers\aswmon2.sys

2011-04-24 19:14 . 2011-04-18 17:16 96344 ----a-w- c:\windows\system32\drivers\aswmon.sys

2011-04-24 19:14 . 2011-04-18 17:13 30680 ----a-w- c:\windows\system32\drivers\aavmker4.sys

2011-04-24 19:14 . 2011-04-18 17:25 40112 ----a-w- c:\windows\avastSS.scr

2011-04-24 19:14 . 2011-04-18 17:25 199304 ----a-w- c:\windows\system32\aswBoot.exe

2011-04-24 18:57 . 2011-04-28 09:11 -------- d-----w- c:\documents and settings\Compaq_Administrator

.

.

.

(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))

.

2011-02-04 16:48 . 2004-08-10 04:00 456192 ----a-w- c:\windows\system32\encdec.dll

2011-02-04 16:48 . 2004-08-10 04:00 291840 ----a-w- c:\windows\system32\sbe.dll

.

.

((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))

.

.

*Note* empty entries & legit default entries are not shown

REGEDIT4

.

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\00avast]

@="{472083B0-C522-11CF-8763-00608CC02F24}"

[HKEY_CLASSES_ROOT\CLSID\{472083B0-C522-11CF-8763-00608CC02F24}]

2011-04-18 17:25 122512 ----a-w- c:\program files\AVAST Software\Avast\ashShell.dll

.

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]

"BrowserChoice"="c:\windows\system32\browserchoice.exe" [2010-02-12 293376]

.

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]

"ehTray"="c:\windows\ehome\ehtray.exe" [2005-08-05 64512]

"ftutil2"="ftutil2.dll" [2004-06-07 106496]

"RTHDCPL"="RTHDCPL.EXE" [2006-07-21 16261632]

"AlwaysReady Power Message APP"="ARPWRMSG.EXE" [2005-08-02 77312]

"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2006-05-09 7311360]

"nwiz"="nwiz.exe" [2006-05-09 1519616]

"Recguard"="c:\windows\SMINST\RECGUARD.EXE" [2005-07-22 237568]

"HPBootOp"="c:\program files\Hewlett-Packard\HP Boot Optimizer\HPBootOp.exe" [2006-02-15 249856]

"Reminder"="c:\windows\Creator\Remind_XP.exe" [2004-12-14 663552]

"HP Software Update"="c:\program files\HP\HP Software Update\HPwuSchd2.exe" [2005-02-17 49152]

"avast"="c:\program files\AVAST Software\Avast\avastUI.exe" [2011-04-18 3460784]

.

c:\documents and settings\Default User\Start Menu\Programs\Startup\

Pin.lnk - c:\hp\bin\CLOAKER.EXE [2006-9-1 27136]

PinMcLnk.lnk - c:\hp\bin\cloaker.exe [2006-9-1 27136]

.

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]

"%windir%\\system32\\sessmgr.exe"=

.

R1 aswSnx;aswSnx;c:\windows\system32\drivers\aswSnx.sys [24/04/2011 20:14 441176]

R1 aswSP;aswSP;c:\windows\system32\drivers\aswSP.sys [24/04/2011 20:14 307288]

R2 aswFsBlk;aswFsBlk;c:\windows\system32\drivers\aswFsBlk.sys [24/04/2011 20:14 19544]

.

.

------- Supplementary Scan -------

.

uStart Page = hxxp://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iehome&locale=EN_GB&c=64&bd=PRESARIO&pf=desktop

uDefault_Search_URL = hxxp://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iesearch&locale=EN_GB&c=64&bd=PRESARIO&pf=desktop

mStart Page = hxxp://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iehome&locale=EN_GB&c=64&bd=PRESARIO&pf=desktop

mSearch Bar = hxxp://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iesearch&locale=EN_GB&c=64&bd=PRESARIO&pf=desktop

IE: &Google Search - c:\program files\Google\GoogleToolbar1.dll/cmsearch.html

IE: &Translate English Word - c:\program files\Google\GoogleToolbar1.dll/cmwordtrans.html

IE: Backward Links - c:\program files\Google\GoogleToolbar1.dll/cmbacklinks.html

IE: Cached Snapshot of Page - c:\program files\Google\GoogleToolbar1.dll/cmcache.html

IE: Similar Pages - c:\program files\Google\GoogleToolbar1.dll/cmsimilar.html

IE: Translate Page into English - c:\program files\Google\GoogleToolbar1.dll/cmtrans.html

.

- - - - ORPHANS REMOVED - - - -

.

HKLM-Run-PCDrProfiler - (no file)

.

.

.

**************************************************************************

.

catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net

Rootkit scan 2011-04-28 10:11

Windows 5.1.2600 Service Pack 2 NTFS

.

scanning hidden processes ...

.

scanning hidden autostart entries ...

.

scanning hidden files ...

.

scan completed successfully

hidden files: 0

.

**************************************************************************

.

Completion time: 2011-04-28 10:14:01

ComboFix-quarantined-files.txt 2011-04-28 09:13

.

Pre-Run: 142,800,068,608 bytes free

Post-Run: 142,789,033,984 bytes free

.

WindowsXP-KB310994-SP2-Pro-BootDisk-ENU.exe

[boot loader]

timeout=2

default=multi(0)disk(0)rdisk(0)partition(1)\WINDOWS

[operating systems]

c:\cmdcons\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons

UnsupportedDebug="do not select this" /debug

multi(0)disk(0)rdisk(0)partition(1)\WINDOWS="Windows XP Media Center Edition" /noexecute=optin /fastdetect

.

- - End Of File - - 63D3C41C99AD7DB99597C773A37983A5

Link to post
Share on other sites

.

DDS (Ver_11-03-05.01) - NTFSx86

Run by Compaq_Administrator at 10:21:51.46 on 28/04/2011

Internet Explorer: 6.0.2900.2180

Microsoft Windows XP Professional 5.1.2600.2.1252.44.1033.18.958.558 [GMT 1:00]

.

AV: avast! Antivirus *Disabled/Updated* {7591DB91-41F0-48A3-B128-1A293FD8233D}

.

============== Running Processes ===============

.

C:\WINDOWS\system32\svchost -k DcomLaunch

svchost.exe

C:\WINDOWS\System32\svchost.exe -k netsvcs

svchost.exe

svchost.exe

C:\Program Files\AVAST Software\Avast\AvastSvc.exe

C:\WINDOWS\system32\spoolsv.exe

C:\WINDOWS\RTHDCPL.EXE

C:\Program Files\HP\HP Software Update\HPwuSchd2.exe

C:\Program Files\AVAST Software\Avast\avastUI.exe

C:\WINDOWS\arservice.exe

C:\WINDOWS\system32\nvsvc32.exe

svchost.exe

C:\WINDOWS\system32\dllhost.exe

C:\WINDOWS\System32\svchost.exe -k HTTPFilter

C:\HP\KBD\KBD.EXE

c:\windows\system\hpsysdrv.exe

C:\WINDOWS\system32\wscntfy.exe

C:\WINDOWS\explorer.exe

C:\WINDOWS\system32\wuauclt.exe

C:\Program Files\internet explorer\iexplore.exe

C:\Documents and Settings\Compaq_Administrator\Desktop\dds.scr

.

============== Pseudo HJT Report ===============

.

uStart Page = hxxp://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iehome&locale=EN_GB&c=64&bd=PRESARIO&pf=desktop

uDefault_Search_URL = hxxp://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iesearch&locale=EN_GB&c=64&bd=PRESARIO&pf=desktop

mStart Page = hxxp://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iehome&locale=EN_GB&c=64&bd=PRESARIO&pf=desktop

mSearch Bar = hxxp://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iesearch&locale=EN_GB&c=64&bd=PRESARIO&pf=desktop

BHO: AcroIEHlprObj Class: {06849e9f-c8d7-4d59-b87d-784b7d6be0b3} - c:\program files\adobe\acrobat 7.0\activex\AcroIEHelper.dll

BHO: SSVHelper Class: {761497bb-d6f0-462c-b6eb-d4daf1d92d43} - c:\program files\java\jre1.5.0_06\bin\ssv.dll

BHO: Google Toolbar Helper: {aa58ed58-01dd-4d91-8333-cf10577473f7} - c:\program files\google\googletoolbar1.dll

TB: &Google: {2318c2b1-4965-11d4-9b18-009027a5cd4f} - c:\program files\google\googletoolbar1.dll

TB: {C4069E3A-68F1-403E-B40E-20066696354B} - No File

uRun: [browserChoice] "c:\windows\system32\browserchoice.exe" /run

mRun: [ehTray] c:\windows\ehome\ehtray.exe

mRun: [ftutil2] rundll32.exe ftutil2.dll,SetWriteCacheMode

mRun: [RTHDCPL] RTHDCPL.EXE

mRun: [AlwaysReady Power Message APP] ARPWRMSG.EXE

mRun: [NvCplDaemon] RUNDLL32.EXE c:\windows\system32\NvCpl.dll,NvStartup

mRun: [nwiz] nwiz.exe /install

mRun: [Recguard] c:\windows\sminst\RECGUARD.EXE

mRun: [HPBootOp] "c:\program files\hewlett-packard\hp boot optimizer\HPBootOp.exe" /run

mRun: [Reminder] "c:\windows\creator\Remind_XP.exe"

mRun: [HP Software Update] c:\program files\hp\hp software update\HPwuSchd2.exe

mRun: [avast] "c:\program files\avast software\avast\avastUI.exe" /nogui

IE: &Google Search - c:\program files\google\GoogleToolbar1.dll/cmsearch.html

IE: &Translate English Word - c:\program files\google\GoogleToolbar1.dll/cmwordtrans.html

IE: Backward Links - c:\program files\google\GoogleToolbar1.dll/cmbacklinks.html

IE: Cached Snapshot of Page - c:\program files\google\GoogleToolbar1.dll/cmcache.html

IE: Similar Pages - c:\program files\google\GoogleToolbar1.dll/cmsimilar.html

IE: Translate Page into English - c:\program files\google\GoogleToolbar1.dll/cmtrans.html

IE: {E2D4D26B-0180-43a4-B05F-462D6D54C789} - c:\windows\pchealth\helpctr\vendors\cn=hewlett-packard,l=cupertino,s=ca,c=us\iebutton\support.htm

IE: {FB5F1910-F110-11d2-BB9E-00C04F795683} - c:\program files\messenger\msmsgs.exe

IE: {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - {CAFEEFAC-0015-0000-0006-ABCDEFFEDCBC} - c:\program files\java\jre1.5.0_06\bin\ssv.dll

DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.5.0/jinstall-1_5_0_06-windows-i586.cab

DPF: {CAFEEFAC-0015-0000-0006-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.5.0/jinstall-1_5_0_06-windows-i586.cab

DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.5.0/jinstall-1_5_0_06-windows-i586.cab

.

============= SERVICES / DRIVERS ===============

.

R1 aswSnx;aswSnx;c:\windows\system32\drivers\aswSnx.sys [2011-4-24 441176]

R1 aswSP;aswSP;c:\windows\system32\drivers\aswSP.sys [2011-4-24 307288]

R2 aswFsBlk;aswFsBlk;c:\windows\system32\drivers\aswFsBlk.sys [2011-4-24 19544]

R2 avast! Antivirus;avast! Antivirus;c:\program files\avast software\avast\AvastSvc.exe [2011-4-24 42184]

R2 McrdSvc;Media Center Extender Service;c:\windows\ehome\mcrdsvc.exe [2005-8-5 99328]

.

=============== Created Last 30 ================

.

2011-04-28 09:05:52 -------- d-sha-r- C:\cmdcons

2011-04-28 09:01:28 23040 ----a-w- c:\windows\system32\SET251.tmp

2011-04-28 09:01:28 23040 ----a-w- c:\windows\system32\dllcache\SET254.tmp

2011-04-28 09:01:28 16896 ----a-w- c:\windows\system32\SET252.tmp

2011-04-28 09:01:28 16896 ----a-w- c:\windows\system32\dllcache\SET255.tmp

2011-04-28 09:01:28 128896 ----a-w- c:\windows\system32\dllcache\SET253.tmp

2011-04-28 08:58:15 -------- d-----w- c:\windows\ServicePackFiles

2011-04-28 08:56:38 -------- d-----w- c:\program files\MSXML 4.0

2011-04-27 10:16:15 -------- d-----w- c:\docume~1\compaq~1\applic~1\Malwarebytes

2011-04-27 10:16:05 38224 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys

2011-04-27 10:16:04 -------- d-----w- c:\docume~1\alluse~1\applic~1\Malwarebytes

2011-04-27 10:16:00 20952 ----a-w- c:\windows\system32\drivers\mbam.sys

2011-04-27 10:15:59 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware

2011-04-27 09:01:02 450560 ------w- c:\windows\system32\SET1CA.tmp

2011-04-27 09:00:02 332800 ----a-w- c:\windows\system32\SETFF.tmp

2011-04-27 08:59:04 215552 ----a-w- c:\program files\windows nt\accessories\SET51.tmp

2011-04-27 08:52:49 293376 ------w- c:\windows\system32\browserchoice.exe

2011-04-27 08:12:08 -------- d-----w- c:\windows\system32\PreInstall

2011-04-25 01:42:12 -------- d-----r- C:\Program Files

2011-04-25 01:40:59 -------- d-----r- c:\documents and settings\all users\Documents

2011-04-25 01:39:07 -------- d-----r- c:\windows\Offline Web Pages

2011-04-25 01:36:15 -------- d-sh--r- c:\windows\system32\dllcache

2011-04-24 19:26:39 1106944 ----a-w- c:\windows\system32\SETE6.tmp

2011-04-24 19:14:28 441176 ----a-w- c:\windows\system32\drivers\aswSnx.sys

2011-04-24 19:14:16 40112 ----a-w- c:\windows\avastSS.scr

2011-04-24 19:14:07 -------- d-----w- c:\program files\AVAST Software

2011-04-24 19:14:07 -------- d-----w- c:\docume~1\alluse~1\applic~1\AVAST Software

2011-04-24 19:00:48 -------- d-----w- c:\windows\setup.pss

2011-04-24 19:00:29 -------- d-----w- c:\windows\setupupd

2011-04-24 18:55:03 -------- d-----w- c:\windows\system32\SoftwareDistribution

.

==================== Find3M ====================

.

2011-02-04 16:48:32 456192 ----a-w- c:\windows\system32\encdec.dll

2011-02-04 16:48:30 291840 ----a-w- c:\windows\system32\sbe.dll

.

============= FINISH: 10:22:16.21 ===============

Link to post
Share on other sites

Hi, just to add, I have just turned my PC back on for the first time since running the ComboFix and DDS programs earlier and the following error message appeared, don't know if it's anything important:

RTHDCPL.EXE - Illegal System DLL Relocation

The system DLL user32.dll was relocated in memory. The application will not run properly. The relocation occurred because the DLL C:\WINDOWS\system32\HHCTRL.OCX occupied an address range reserved for Windows system DLLs. The vendor supplying the DLL should be contacted for a new DLL.

Link to post
Share on other sites

  • Staff

Hi,

Restart your computer and see if that error pops up again. If so, please post a screenshot of it. If not, then we'll write it off as a one-time glitch.

Next, please run a free online scan with the ESET Online Scanner

Note: You will need to use Internet Explorer for this scan.

  1. Tick the box next to YES, I accept the Terms of Use.
  2. Click Start
  3. When asked, allow the ActiveX control to install
  4. Click Start
  5. Make sure that the options Remove found threats and the option Scan unwanted applications is checked
  6. Click Scan
    Wait for the scan to finish
  7. Use Notepad to open the logfile located at C:\Program Files\EsetOnlineScanner\log.txt
  8. Copy and paste that log as a reply to this topic

Next, download my Security Check from here or here.

  • Save it to your Desktop.
  • Double click SecurityCheck.exe and follow the onscreen instructions inside of the black box.
  • A Notepad document should open automatically called checkup.txt; please post the contents of that document.

Let me know how things are running now and what issues remain.

-screen317

Link to post
Share on other sites

The DLL error message appeared again when I started the computer. I have attached a screenshot below. Here is the ESET ONLINE SCANNER LOGFILE (I HAVE HAD TO SPLIT IT INTO 2 REPLIES AS IT WAS TO LONG TO POST IN ONE GO:

ESETSmartInstaller@High as CAB hook log:

OnlineScanner.ocx - registred OK

# version=7

# iexplore.exe=6.00.2900.2180 (xpsp_sp2_rtm.040803-2158)

# OnlineScanner.ocx=1.0.0.6427

# api_version=3.0.2

# EOSSerial=80609158dd70f646adc5715a3424c8c1

# end=finished

# remove_checked=true

# archives_checked=false

# unwanted_checked=true

# unsafe_checked=false

# antistealth_checked=true

# utc_time=2011-04-30 02:02:20

# local_time=2011-04-30 03:02:20 (+0000, GMT Daylight Time)

# country="United Kingdom"

# lang=9

# osver=5.1.2600 NT Service Pack 2

# compatibility_mode=8192 67108863 100 0 129 129 0 0

# scanned=68310

# found=886

# cleaned=886

# scan_time=2171

C:\hp\PATCHES\64WW1NDR\CPC_UPD\OwnerPatch.exe Win32/Ramnit.H virus (cleaned - quarantined) 00000000000000000000000000000000 C

C:\hp\PATCHES\64WW1NDR\CPC_UPD\Sleep.exe Win32/Ramnit.H virus (cleaned - quarantined) 00000000000000000000000000000000 C

C:\System Volume Information\_restore{F7149EC7-4FA5-4148-81FA-2F7A6348FD9A}\RP5\A0002206.exe Win32/Ramnit.H virus (cleaned - quarantined) 00000000000000000000000000000000 C

C:\System Volume Information\_restore{F7149EC7-4FA5-4148-81FA-2F7A6348FD9A}\RP5\A0002207.exe Win32/Ramnit.H virus (cleaned - quarantined) 00000000000000000000000000000000 C

D:\Info.exe Win32/Ramnit.H virus (cleaned - quarantined) 00000000000000000000000000000000 C

D:\MiniNT\system32\Bootini.exe Win32/Ramnit.H virus (cleaned - quarantined) 00000000000000000000000000000000 C

D:\MiniNT\system32\BSUpdate.exe Win32/Ramnit.H virus (cleaned - quarantined) 00000000000000000000000000000000 C

D:\MiniNT\system32\CDBootRC.dll Win32/Ramnit.H virus (cleaned - quarantined) 00000000000000000000000000000000 C

D:\MiniNT\system32\CHSBRKR.DLL Win32/Ramnit.H virus (cleaned - quarantined) 00000000000000000000000000000000 C

D:\MiniNT\system32\CHTBRKR.DLL Win32/Ramnit.H virus (cleaned - quarantined) 00000000000000000000000000000000 C

D:\MiniNT\system32\DblRes.exe Win32/Ramnit.H virus (cleaned - quarantined) 00000000000000000000000000000000 C

D:\MiniNT\system32\DMI.dll Win32/Ramnit.H virus (cleaned - quarantined) 00000000000000000000000000000000 C

D:\MiniNT\system32\DSKPART.EXE Win32/Ramnit.H virus (cleaned - quarantined) 00000000000000000000000000000000 C

D:\MiniNT\system32\DskUtil.dll Win32/Ramnit.H virus (cleaned - quarantined) 00000000000000000000000000000000 C

D:\MiniNT\system32\Eject.exe Win32/Ramnit.H virus (cleaned - quarantined) 00000000000000000000000000000000 C

D:\MiniNT\system32\FATFMT32.EXE Win32/Ramnit.H virus (cleaned - quarantined) 00000000000000000000000000000000 C

D:\MiniNT\system32\flush.dll Win32/Ramnit.H virus (cleaned - quarantined) 00000000000000000000000000000000 C

D:\MiniNT\system32\idecoi.dll Win32/Ramnit.H virus (cleaned - quarantined) 00000000000000000000000000000000 C

D:\MiniNT\system32\KORWBRKR.DLL Win32/Ramnit.H virus (cleaned - quarantined) 00000000000000000000000000000000 C

D:\MiniNT\system32\LogViewer.exe Win32/Ramnit.H virus (cleaned - quarantined) 00000000000000000000000000000000 C

D:\MiniNT\system32\MBR.DLL Win32/Ramnit.H virus (cleaned - quarantined) 00000000000000000000000000000000 C

D:\MiniNT\system32\mount.exe Win32/Ramnit.H virus (cleaned - quarantined) 00000000000000000000000000000000 C

D:\MiniNT\system32\MSIR3JP.DLL Win32/Ramnit.H virus (cleaned - quarantined) 00000000000000000000000000000000 C

D:\MiniNT\system32\NETCFG.EXE Win32/Ramnit.H virus (cleaned - quarantined) 00000000000000000000000000000000 C

D:\MiniNT\system32\nvcoi.dll Win32/Ramnit.H virus (cleaned - quarantined) 00000000000000000000000000000000 C

D:\MiniNT\system32\nvraidco.dll Win32/Ramnit.H virus (cleaned - quarantined) 00000000000000000000000000000000 C

D:\MiniNT\system32\NvRaidMan.exe Win32/Ramnit.H virus (cleaned - quarantined) 00000000000000000000000000000000 C

D:\MiniNT\system32\nvraidservice.exe Win32/Ramnit.H virus (cleaned - quarantined) 00000000000000000000000000000000 C

D:\MiniNT\system32\NvRaidWizard.dll Win32/Ramnit.H virus (cleaned - quarantined) 00000000000000000000000000000000 C

D:\MiniNT\system32\nvuide.exe Win32/Ramnit.H virus (cleaned - quarantined) 00000000000000000000000000000000 C

D:\MiniNT\system32\PAGEFILE.EXE Win32/Ramnit.H virus (cleaned - quarantined) 00000000000000000000000000000000 C

D:\MiniNT\system32\Restore.exe Win32/Ramnit.H virus (cleaned - quarantined) 00000000000000000000000000000000 C

D:\MiniNT\system32\RPONOFF.EXE Win32/Ramnit.H virus (cleaned - quarantined) 00000000000000000000000000000000 C

D:\MiniNT\system32\rsaenh.dll Win32/Ramnit.H virus (cleaned - quarantined) 00000000000000000000000000000000 C

D:\MiniNT\system32\ShutDown.dll Win32/Ramnit.H virus (cleaned - quarantined) 00000000000000000000000000000000 C

D:\MiniNT\system32\ShutDown.exe Win32/Ramnit.H virus (cleaned - quarantined) 00000000000000000000000000000000 C

D:\MiniNT\system32\start.exe Win32/Ramnit.H virus (cleaned - quarantined) 00000000000000000000000000000000 C

D:\MiniNT\system32\SVG.DLL Win32/Ramnit.H virus (cleaned - quarantined) 00000000000000000000000000000000 C

D:\MiniNT\system32\SwapPart.dll Win32/Ramnit.H virus (cleaned - quarantined) 00000000000000000000000000000000 C

D:\MiniNT\system32\UNIIME.DLL Win32/Ramnit.H virus (cleaned - quarantined) 00000000000000000000000000000000 C

D:\MiniNT\system32\Mbrinst.exe Win32/Ramnit.H virus (cleaned - quarantined) 00000000000000000000000000000000 C

D:\MiniNT\system32\bdco1.dll Win32/Ramnit.H virus (cleaned - quarantined) 00000000000000000000000000000000 C

D:\MiniNT\system32\EL2k_CPP.dll Win32/Ramnit.H virus (cleaned - quarantined) 00000000000000000000000000000000 C

D:\MiniNT\system32\EtCoInst.dll Win32/Ramnit.H virus (cleaned - quarantined) 00000000000000000000000000000000 C

D:\MiniNT\system32\fdco1.dll Win32/Ramnit.H virus (cleaned - quarantined) 00000000000000000000000000000000 C

D:\MiniNT\system32\intelnic.dll Win32/Ramnit.H virus (cleaned - quarantined) 00000000000000000000000000000000 C

D:\MiniNT\system32\NicCo.dll Win32/Ramnit.H virus (cleaned - quarantined) 00000000000000000000000000000000 C

D:\MiniNT\system32\NicEtCoE.dll Win32/Ramnit.H virus (cleaned - quarantined) 00000000000000000000000000000000 C

D:\MiniNT\system32\NicInst.dll Win32/Ramnit.H virus (cleaned - quarantined) 00000000000000000000000000000000 C

D:\MiniNT\system32\NicInstE.dll Win32/Ramnit.H virus (cleaned - quarantined) 00000000000000000000000000000000 C

D:\MiniNT\system32\nvconrm.dll Win32/Ramnit.H virus (cleaned - quarantined) 00000000000000000000000000000000 C

D:\MiniNT\system32\NvCpl.dll Win32/Ramnit.H virus (cleaned - quarantined) 00000000000000000000000000000000 C

D:\MiniNT\system32\NvMCTray.dll Win32/Ramnit.H virus (cleaned - quarantined) 00000000000000000000000000000000 C

D:\MiniNT\system32\nvudisp.exe Win32/Ramnit.H virus (cleaned - quarantined) 00000000000000000000000000000000 C

D:\MiniNT\system32\nvuenet.exe Win32/Ramnit.H virus (cleaned - quarantined) 00000000000000000000000000000000 C

D:\MiniNT\system32\nvunrm.exe Win32/Ramnit.H virus (cleaned - quarantined) 00000000000000000000000000000000 C

D:\MiniNT\system32\PROUnstl.exe Win32/Ramnit.H virus (cleaned - quarantined) 00000000000000000000000000000000 C

D:\MiniNT\system32\factory.exe Win32/Ramnit.H virus (cleaned - quarantined) 00000000000000000000000000000000 C

D:\MiniNT\system32\startmgr.exe a variant of Win32/Kryptik.MNM trojan (cleaned by deleting - quarantined) 00000000000000000000000000000000 C

D:\MiniNT\system32\RESTOREmgr.exe a variant of Win32/Kryptik.MNM trojan (cleaned by deleting - quarantined) 00000000000000000000000000000000 C

D:\MiniNT\system32\MBRmgr.exe a variant of Win32/Kryptik.MNM trojan (cleaned by deleting - quarantined) 00000000000000000000000000000000 C

D:\MiniNT\system32\SWAPPARTmgr.exe a variant of Win32/Kryptik.MNM trojan (cleaned by deleting - quarantined) 00000000000000000000000000000000 C

D:\MiniNT\system32\shutdownmgr.exe a variant of Win32/Kryptik.MNM trojan (cleaned by deleting - quarantined) 00000000000000000000000000000000 C

D:\MiniNT\system32\drivers\bdco1.dll Win32/Ramnit.H virus (cleaned - quarantined) 00000000000000000000000000000000 C

D:\MiniNT\system32\drivers\EtCoInst.dll Win32/Ramnit.H virus (cleaned - quarantined) 00000000000000000000000000000000 C

D:\MiniNT\system32\drivers\fdco1.dll Win32/Ramnit.H virus (cleaned - quarantined) 00000000000000000000000000000000 C

D:\MiniNT\system32\drivers\intelnic.dll Win32/Ramnit.H virus (cleaned - quarantined) 00000000000000000000000000000000 C

D:\MiniNT\system32\drivers\nvconrm.dll Win32/Ramnit.H virus (cleaned - quarantined) 00000000000000000000000000000000 C

D:\MiniNT\system32\drivers\nvunrm.exe Win32/Ramnit.H virus (cleaned - quarantined) 00000000000000000000000000000000 C

D:\MiniNT\system32\drivers\PROUnstl.exe Win32/Ramnit.H virus (cleaned - quarantined) 00000000000000000000000000000000 C

D:\I386\APPS\APP00044\commands.exe Win32/Ramnit.H virus (cleaned - quarantined) 00000000000000000000000000000000 C

D:\I386\APPS\APP00044\HPCONTXT.exe Win32/Ramnit.H virus (cleaned - quarantined) 00000000000000000000000000000000 C

D:\I386\APPS\APP00044\hpqca.dll Win32/Ramnit.H virus (cleaned - quarantined) 00000000000000000000000000000000 C

D:\I386\APPS\APP00044\src\HPZidi01.dll Win32/Ramnit.H virus (cleaned - quarantined) 00000000000000000000000000000000 C

D:\I386\APPS\APP00044\src\HPZIDS01.dll Win32/Ramnit.H virus (cleaned - quarantined) 00000000000000000000000000000000 C

D:\I386\APPS\APP00044\src\setup.exe Win32/Ramnit.H virus (cleaned - quarantined) 00000000000000000000000000000000 C

D:\I386\APPS\APP00044\src\readme\CHS\Readme.html Win32/Ramnit.A virus (cleaned - quarantined) 00000000000000000000000000000000 C

D:\I386\APPS\APP00044\src\readme\CHT\Readme.html Win32/Ramnit.A virus (cleaned - quarantined) 00000000000000000000000000000000 C

D:\I386\APPS\APP00044\src\readme\CSY\Readme.html Win32/Ramnit.A virus (cleaned - quarantined) 00000000000000000000000000000000 C

D:\I386\APPS\APP00044\src\readme\DAN\Readme.html Win32/Ramnit.A virus (cleaned - quarantined) 00000000000000000000000000000000 C

D:\I386\APPS\APP00044\src\readme\DEU\Readme.html Win32/Ramnit.A virus (cleaned - quarantined) 00000000000000000000000000000000 C

D:\I386\APPS\APP00044\src\readme\ELL\Readme.html Win32/Ramnit.A virus (cleaned - quarantined) 00000000000000000000000000000000 C

D:\I386\APPS\APP00044\src\readme\ENU\Readme.html Win32/Ramnit.A virus (cleaned - quarantined) 00000000000000000000000000000000 C

D:\I386\APPS\APP00044\src\readme\ESN\Readme.html Win32/Ramnit.A virus (cleaned - quarantined) 00000000000000000000000000000000 C

D:\I386\APPS\APP00044\src\readme\FIN\Readme.html Win32/Ramnit.A virus (cleaned - quarantined) 00000000000000000000000000000000 C

D:\I386\APPS\APP00044\src\readme\FRA\Readme.html Win32/Ramnit.A virus (cleaned - quarantined) 00000000000000000000000000000000 C

D:\I386\APPS\APP00044\src\readme\HUN\Readme.html Win32/Ramnit.A virus (cleaned - quarantined) 00000000000000000000000000000000 C

D:\I386\APPS\APP00044\src\readme\ITA\Readme.html Win32/Ramnit.A virus (cleaned - quarantined) 00000000000000000000000000000000 C

D:\I386\APPS\APP00044\src\readme\JPN\Readme.html Win32/Ramnit.A virus (cleaned - quarantined) 00000000000000000000000000000000 C

D:\I386\APPS\APP00044\src\readme\KOR\Readme.html Win32/Ramnit.A virus (cleaned - quarantined) 00000000000000000000000000000000 C

D:\I386\APPS\APP00044\src\readme\NLD\Readme.html Win32/Ramnit.A virus (cleaned - quarantined) 00000000000000000000000000000000 C

D:\I386\APPS\APP00044\src\readme\NOB\Readme.html Win32/Ramnit.A virus (cleaned - quarantined) 00000000000000000000000000000000 C

D:\I386\APPS\APP00044\src\readme\PLK\Readme.html Win32/Ramnit.A virus (cleaned - quarantined) 00000000000000000000000000000000 C

D:\I386\APPS\APP00044\src\readme\PTB\Readme.html Win32/Ramnit.A virus (cleaned - quarantined) 00000000000000000000000000000000 C

D:\I386\APPS\APP00044\src\readme\RUS\Readme.html Win32/Ramnit.A virus (cleaned - quarantined) 00000000000000000000000000000000 C

D:\I386\APPS\APP00044\src\readme\SVE\Readme.html Win32/Ramnit.A virus (cleaned - quarantined) 00000000000000000000000000000000 C

D:\I386\APPS\APP00044\src\readme\TRK\Readme.html Win32/Ramnit.A virus (cleaned - quarantined) 00000000000000000000000000000000 C

D:\I386\APPS\APP00044\src\setup\HPCommunication.dll Win32/Ramnit.H virus (cleaned - quarantined) 00000000000000000000000000000000 C

D:\I386\APPS\APP00044\src\setup\HPeDiag.dll Win32/Ramnit.H virus (cleaned - quarantined) 00000000000000000000000000000000 C

D:\I386\APPS\APP00044\src\setup\HPScripting.dll Win32/Ramnit.H virus (cleaned - quarantined) 00000000000000000000000000000000 C

D:\I386\APPS\APP00044\src\setup\HPZarp01.exe Win32/Ramnit.H virus (cleaned - quarantined) 00000000000000000000000000000000 C

D:\I386\APPS\APP00044\src\setup\HPZcdl01.exe Win32/Ramnit.H virus (cleaned - quarantined) 00000000000000000000000000000000 C

D:\I386\APPS\APP00044\src\setup\HPZchk01.exe Win32/Ramnit.H virus (cleaned - quarantined) 00000000000000000000000000000000 C

D:\I386\APPS\APP00044\src\setup\HPZddv01.exe Win32/Ramnit.H virus (cleaned - quarantined) 00000000000000000000000000000000 C

D:\I386\APPS\APP00044\src\setup\HPZdui01.exe Win32/Ramnit.H virus (cleaned - quarantined) 00000000000000000000000000000000 C

D:\I386\APPS\APP00044\src\setup\HPZgat01.exe Win32/Ramnit.H virus (cleaned - quarantined) 00000000000000000000000000000000 C

D:\I386\APPS\APP00044\src\setup\HPZmsi01.exe Win32/Ramnit.H virus (cleaned - quarantined) 00000000000000000000000000000000 C

D:\I386\APPS\APP00044\src\setup\HPZnet01.exe Win32/Ramnit.H virus (cleaned - quarantined) 00000000000000000000000000000000 C

D:\I386\APPS\APP00044\src\setup\HPZnfx01.exe Win32/Ramnit.H virus (cleaned - quarantined) 00000000000000000000000000000000 C

D:\I386\APPS\APP00044\src\setup\HPZnop01.exe Win32/Ramnit.H virus (cleaned - quarantined) 00000000000000000000000000000000 C

D:\I386\APPS\APP00044\src\setup\HPZopt01.exe Win32/Ramnit.H virus (cleaned - quarantined) 00000000000000000000000000000000 C

D:\I386\APPS\APP00044\src\setup\HPZpnp01.exe Win32/Ramnit.H virus (cleaned - quarantined) 00000000000000000000000000000000 C

D:\I386\APPS\APP00044\src\setup\HPZprl01.exe Win32/Ramnit.H virus (cleaned - quarantined) 00000000000000000000000000000000 C

D:\I386\APPS\APP00044\src\setup\HPZpsc01.exe Win32/Ramnit.H virus (cleaned - quarantined) 00000000000000000000000000000000 C

D:\I386\APPS\APP00044\src\setup\HPZpsl01.exe Win32/Ramnit.H virus (cleaned - quarantined) 00000000000000000000000000000000 C

D:\I386\APPS\APP00044\src\setup\HPZrcn01.exe Win32/Ramnit.H virus (cleaned - quarantined) 00000000000000000000000000000000 C

D:\I386\APPS\APP00044\src\setup\HPZrcv01.exe Win32/Ramnit.H virus (cleaned - quarantined) 00000000000000000000000000000000 C

D:\I386\APPS\APP00044\src\setup\HPZrein01.exe Win32/Ramnit.H virus (cleaned - quarantined) 00000000000000000000000000000000 C

D:\I386\APPS\APP00044\src\setup\HPZscr01.exe Win32/Ramnit.H virus (cleaned - quarantined) 00000000000000000000000000000000 C

D:\I386\APPS\APP00044\src\setup\HPZshl01.exe Win32/Ramnit.H virus (cleaned - quarantined) 00000000000000000000000000000000 C

D:\I386\APPS\APP00044\src\setup\HPZsui01.exe Win32/Ramnit.H virus (cleaned - quarantined) 00000000000000000000000000000000 C

D:\I386\APPS\APP00044\src\setup\HPZtim01.exe Win32/Ramnit.H virus (cleaned - quarantined) 00000000000000000000000000000000 C

D:\I386\APPS\APP00044\src\setup\HPZwis01.exe Win32/Ramnit.H virus (cleaned - quarantined) 00000000000000000000000000000000 C

D:\I386\APPS\APP00044\src\setup\HPZwup01.exe Win32/Ramnit.H virus (cleaned - quarantined) 00000000000000000000000000000000 C

D:\I386\APPS\APP00044\src\setup\InstallMetrics.dll Win32/Ramnit.H virus (cleaned - quarantined) 00000000000000000000000000000000 C

D:\I386\APPS\APP00044\src\setup\InternetUtil.dll Win32/Ramnit.H virus (cleaned - quarantined) 00000000000000000000000000000000 C

D:\I386\APPS\APP00044\src\setup\msxml3.dll Win32/Ramnit.H virus (cleaned - quarantined) 00000000000000000000000000000000 C

D:\I386\APPS\APP00044\src\setup\RulesEngine.dll Win32/Ramnit.H virus (cleaned - quarantined) 00000000000000000000000000000000 C

D:\I386\APPS\APP00044\src\setup\usbready.exe Win32/Ramnit.H virus (cleaned - quarantined) 00000000000000000000000000000000 C

D:\I386\APPS\APP00044\src\setup\VistaOS_Block1025.htm Win32/Ramnit.A virus (cleaned - quarantined) 00000000000000000000000000000000 C

D:\I386\APPS\APP00044\src\setup\VistaOS_Block1028.htm Win32/Ramnit.A virus (cleaned - quarantined) 00000000000000000000000000000000 C

D:\I386\APPS\APP00044\src\setup\VistaOS_Block1029.htm Win32/Ramnit.A virus (cleaned - quarantined) 00000000000000000000000000000000 C

D:\I386\APPS\APP00044\src\setup\VistaOS_Block1030.htm Win32/Ramnit.A virus (cleaned - quarantined) 00000000000000000000000000000000 C

D:\I386\APPS\APP00044\src\setup\VistaOS_Block1031.htm Win32/Ramnit.A virus (cleaned - quarantined) 00000000000000000000000000000000 C

D:\I386\APPS\APP00044\src\setup\VistaOS_Block1032.htm Win32/Ramnit.A virus (cleaned - quarantined) 00000000000000000000000000000000 C

D:\I386\APPS\APP00044\src\setup\VistaOS_block1033.htm Win32/Ramnit.A virus (cleaned - quarantined) 00000000000000000000000000000000 C

D:\I386\APPS\APP00044\src\setup\VistaOS_Block1034.htm Win32/Ramnit.A virus (cleaned - quarantined) 00000000000000000000000000000000 C

D:\I386\APPS\APP00044\src\setup\VistaOS_Block1035.htm Win32/Ramnit.A virus (cleaned - quarantined) 00000000000000000000000000000000 C

D:\I386\APPS\APP00044\src\setup\VistaOS_Block1036.htm Win32/Ramnit.A virus (cleaned - quarantined) 00000000000000000000000000000000 C

D:\I386\APPS\APP00044\src\setup\VistaOS_Block1037.htm Win32/Ramnit.A virus (cleaned - quarantined) 00000000000000000000000000000000 C

D:\I386\APPS\APP00044\src\setup\VistaOS_Block1038.htm Win32/Ramnit.A virus (cleaned - quarantined) 00000000000000000000000000000000 C

D:\I386\APPS\APP00044\src\setup\VistaOS_Block1040.htm Win32/Ramnit.A virus (cleaned - quarantined) 00000000000000000000000000000000 C

D:\I386\APPS\APP00044\src\setup\VistaOS_Block1041.htm Win32/Ramnit.A virus (cleaned - quarantined) 00000000000000000000000000000000 C

D:\I386\APPS\APP00044\src\setup\VistaOS_Block1042.htm Win32/Ramnit.A virus (cleaned - quarantined) 00000000000000000000000000000000 C

D:\I386\APPS\APP00044\src\setup\VistaOS_Block1043.htm Win32/Ramnit.A virus (cleaned - quarantined) 00000000000000000000000000000000 C

D:\I386\APPS\APP00044\src\setup\VistaOS_Block1044.htm Win32/Ramnit.A virus (cleaned - quarantined) 00000000000000000000000000000000 C

D:\I386\APPS\APP00044\src\setup\VistaOS_Block1045.htm Win32/Ramnit.A virus (cleaned - quarantined) 00000000000000000000000000000000 C

D:\I386\APPS\APP00044\src\setup\VistaOS_Block1046.htm Win32/Ramnit.A virus (cleaned - quarantined) 00000000000000000000000000000000 C

D:\I386\APPS\APP00044\src\setup\VistaOS_Block1049.htm Win32/Ramnit.A virus (cleaned - quarantined) 00000000000000000000000000000000 C

D:\I386\APPS\APP00044\src\setup\VistaOS_Block1053.htm Win32/Ramnit.A virus (cleaned - quarantined) 00000000000000000000000000000000 C

D:\I386\APPS\APP00044\src\setup\VistaOS_Block1054.htm Win32/Ramnit.A virus (cleaned - quarantined) 00000000000000000000000000000000 C

D:\I386\APPS\APP00044\src\setup\VistaOS_Block1055.htm Win32/Ramnit.A virus (cleaned - quarantined) 00000000000000000000000000000000 C

D:\I386\APPS\APP00044\src\setup\VistaOS_Block2052.htm Win32/Ramnit.A virus (cleaned - quarantined) 00000000000000000000000000000000 C

D:\I386\APPS\APP00044\src\setup\HPZwrp01.exe Win32/Ramnit.H virus (cleaned - quarantined) 00000000000000000000000000000000 C

D:\I386\APPS\APP00044\src\util\ccc\FixErr1714.exe Win32/Ramnit.H virus (cleaned - quarantined) 00000000000000000000000000000000 C

D:\I386\APPS\APP00044\src\util\ccc\HPZlgc01.exe Win32/Ramnit.H virus (cleaned - quarantined) 00000000000000000000000000000000 C

D:\I386\APPS\APP00044\src\util\ccc\HPZprs01.exe Win32/Ramnit.H virus (cleaned - quarantined) 00000000000000000000000000000000 C

D:\I386\APPS\APP00044\src\util\ccc\MediaSizeSettings.exe Win32/Ramnit.H virus (cleaned - quarantined) 00000000000000000000000000000000 C

D:\I386\APPS\APP00586\commands.exe Win32/Ramnit.H virus (cleaned - quarantined) 00000000000000000000000000000000 C

D:\I386\APPS\APP00586\src\Setup.exe Win32/Ramnit.H virus (cleaned - quarantined) 00000000000000000000000000000000 C

D:\I386\APPS\APP00586\src\bin\left_paneCHS.htm Win32/Ramnit.A virus (cleaned - quarantined) 00000000000000000000000000000000 C

D:\I386\APPS\APP00586\src\bin\left_paneCHT.htm Win32/Ramnit.A virus (cleaned - quarantined) 00000000000000000000000000000000 C

D:\I386\APPS\APP00586\src\bin\left_paneDAN.htm Win32/Ramnit.A virus (cleaned - quarantined) 00000000000000000000000000000000 C

D:\I386\APPS\APP00586\src\bin\left_paneDEU.htm Win32/Ramnit.A virus (cleaned - quarantined) 00000000000000000000000000000000 C

D:\I386\APPS\APP00586\src\bin\left_paneENU.htm Win32/Ramnit.A virus (cleaned - quarantined) 00000000000000000000000000000000 C

D:\I386\APPS\APP00586\src\bin\left_paneESN.htm Win32/Ramnit.A virus (cleaned - quarantined) 00000000000000000000000000000000 C

D:\I386\APPS\APP00586\src\bin\left_paneFIN.htm Win32/Ramnit.A virus (cleaned - quarantined) 00000000000000000000000000000000 C

D:\I386\APPS\APP00586\src\bin\left_paneFRA.htm Win32/Ramnit.A virus (cleaned - quarantined) 00000000000000000000000000000000 C

D:\I386\APPS\APP00586\src\bin\left_paneITA.htm Win32/Ramnit.A virus (cleaned - quarantined) 00000000000000000000000000000000 C

D:\I386\APPS\APP00586\src\bin\left_paneJPN.htm Win32/Ramnit.A virus (cleaned - quarantined) 00000000000000000000000000000000 C

D:\I386\APPS\APP00586\src\bin\left_paneKOR.htm Win32/Ramnit.A virus (cleaned - quarantined) 00000000000000000000000000000000 C

D:\I386\APPS\APP00586\src\bin\left_paneNLD.htm Win32/Ramnit.A virus (cleaned - quarantined) 00000000000000000000000000000000 C

D:\I386\APPS\APP00586\src\bin\left_paneNOR.htm Win32/Ramnit.A virus (cleaned - quarantined) 00000000000000000000000000000000 C

D:\I386\APPS\APP00586\src\bin\left_panePTB.htm Win32/Ramnit.A virus (cleaned - quarantined) 00000000000000000000000000000000 C

D:\I386\APPS\APP00586\src\bin\left_panePTG.htm Win32/Ramnit.A virus (cleaned - quarantined) 00000000000000000000000000000000 C

D:\I386\APPS\APP00586\src\bin\left_paneSVE.htm Win32/Ramnit.A virus (cleaned - quarantined) 00000000000000000000000000000000 C

D:\I386\APPS\APP00586\src\bin\setupui.dll Win32/Ramnit.H virus (cleaned - quarantined) 00000000000000000000000000000000 C

D:\I386\APPS\APP00586\src\SC_AUDIO_206\BIN\MRating.exe Win32/Ramnit.H virus (cleaned - quarantined) 00000000000000000000000000000000 C

D:\I386\APPS\APP00586\src\SC_COPY_206\BIN\MRating.exe Win32/Ramnit.H virus (cleaned - quarantined) 00000000000000000000000000000000 C

D:\I386\APPS\APP00586\src\SC_DATA_206\BIN\MRating.exe Win32/Ramnit.H virus (cleaned - quarantined) 00000000000000000000000000000000 C

D:\I386\APPS\APP01217\commands.exe Win32/Ramnit.H virus (cleaned - quarantined) 00000000000000000000000000000000 C

D:\I386\APPS\APP01217\SUPPORT\TOOLS\FASTWIZ.EXE Win32/Ramnit.H virus (cleaned - quarantined) 00000000000000000000000000000000 C

D:\I386\APPS\APP01217\SUPPORT\TOOLS\GBUNICNV.EXE Win32/Ramnit.H virus (cleaned - quarantined) 00000000000000000000000000000000 C

D:\I386\APPS\APP01217\SUPPORT\TOOLS\MSRDPCLI.EXE Win32/Ramnit.H virus (cleaned - quarantined) 00000000000000000000000000000000 C

D:\I386\APPS\APP01217\SUPPORT\TOOLS\README.HTM Win32/Ramnit.A virus (cleaned - quarantined) 00000000000000000000000000000000 C

D:\I386\APPS\APP01217\SUPPORT\TOOLS\SETUP.EXE Win32/Ramnit.H virus (cleaned - quarantined) 00000000000000000000000000000000 C

D:\I386\APPS\APP02157\commands.exe Win32/Ramnit.H virus (cleaned - quarantined) 00000000000000000000000000000000 C

D:\I386\APPS\APP02157\src\Setup.exe Win32/Ramnit.H virus (cleaned - quarantined) 00000000000000000000000000000000 C

D:\I386\APPS\APP02157\src\BIN\SKULib.dll Win32/Ramnit.H virus (cleaned - quarantined) 00000000000000000000000000000000 C

D:\I386\APPS\APP02834\commands.exe Win32/Ramnit.H virus (cleaned - quarantined) 00000000000000000000000000000000 C

D:\I386\APPS\APP03912\commands.exe Win32/Ramnit.H virus (cleaned - quarantined) 00000000000000000000000000000000 C

D:\I386\APPS\APP03912\VALUEADD\VALUEADD.HTM Win32/Ramnit.A virus (cleaned - quarantined) 00000000000000000000000000000000 C

D:\I386\APPS\APP03912\VALUEADD\3RDPARTY\MGMT\CITRIX\README.HTM Win32/Ramnit.A virus (cleaned - quarantined) 00000000000000000000000000000000 C

D:\I386\APPS\APP03912\VALUEADD\MSFT\MGMT\IAS\README.HTM Win32/Ramnit.A virus (cleaned - quarantined) 00000000000000000000000000000000 C

D:\I386\APPS\APP03912\VALUEADD\MSFT\MGMT\PBA\PBAINST.EXE Win32/Ramnit.H virus (cleaned - quarantined) 00000000000000000000000000000000 C

D:\I386\APPS\APP03912\VALUEADD\MSFT\MGMT\PBA\README.HTM Win32/Ramnit.A virus (cleaned - quarantined) 00000000000000000000000000000000 C

D:\I386\APPS\APP03912\VALUEADD\MSFT\MGMT\WBEMODBC\README.HTM Win32/Ramnit.A virus (cleaned - quarantined) 00000000000000000000000000000000 C

D:\I386\APPS\APP03912\VALUEADD\MSFT\NET\TOOLS\TTCP.EXE Win32/Ramnit.H virus (cleaned - quarantined) 00000000000000000000000000000000 C

D:\I386\APPS\APP03912\VALUEADD\MSFT\USMT\LOADSTATE.EXE Win32/Ramnit.H virus (cleaned - quarantined) 00000000000000000000000000000000 C

D:\I386\APPS\APP03912\VALUEADD\MSFT\USMT\LOG.DLL Win32/Ramnit.H virus (cleaned - quarantined) 00000000000000000000000000000000 C

D:\I386\APPS\APP03912\VALUEADD\MSFT\USMT\MIGISM.DLL Win32/Ramnit.H virus (cleaned - quarantined) 00000000000000000000000000000000 C

D:\I386\APPS\APP03912\VALUEADD\MSFT\USMT\MIGISM_A.DLL Win32/Ramnit.H virus (cleaned - quarantined) 00000000000000000000000000000000 C

D:\I386\APPS\APP03912\VALUEADD\MSFT\USMT\SCANSTATE.EXE Win32/Ramnit.H virus (cleaned - quarantined) 00000000000000000000000000000000 C

D:\I386\APPS\APP03912\VALUEADD\MSFT\USMT\SCANSTATE_A.EXE Win32/Ramnit.H virus (cleaned - quarantined) 00000000000000000000000000000000 C

D:\I386\APPS\APP03912\VALUEADD\MSFT\USMT\SCRIPT.DLL Win32/Ramnit.H virus (cleaned - quarantined) 00000000000000000000000000000000 C

D:\I386\APPS\APP03912\VALUEADD\MSFT\USMT\SCRIPT_A.DLL Win32/Ramnit.H virus (cleaned - quarantined) 00000000000000000000000000000000 C

D:\I386\APPS\APP03912\VALUEADD\MSFT\USMT\SYSMOD.DLL Win32/Ramnit.H virus (cleaned - quarantined) 00000000000000000000000000000000 C

D:\I386\APPS\APP03912\VALUEADD\MSFT\USMT\SYSMOD_A.DLL Win32/Ramnit.H virus (cleaned - quarantined) 00000000000000000000000000000000 C

D:\I386\APPS\APP03912\VALUEADD\MSFT\USMT\UNCTRN.DLL Win32/Ramnit.H virus (cleaned - quarantined) 00000000000000000000000000000000 C

D:\I386\APPS\APP03912\VALUEADD\MSFT\USMT\UNCTRN_A.DLL Win32/Ramnit.H virus (cleaned - quarantined) 00000000000000000000000000000000 C

D:\I386\APPS\APP03912\VALUEADD\MSFT\USMT\ANSI\LOG.DLL Win32/Ramnit.H virus (cleaned - quarantined) 00000000000000000000000000000000 C

D:\I386\APPS\APP03912\VALUEADD\MSFT\USMT\ANSI\MIGISM.DLL Win32/Ramnit.H virus (cleaned - quarantined) 00000000000000000000000000000000 C

D:\I386\APPS\APP03912\VALUEADD\MSFT\USMT\ANSI\SCANSTATE.EXE Win32/Ramnit.H virus (cleaned - quarantined) 00000000000000000000000000000000 C

D:\I386\APPS\APP03912\VALUEADD\MSFT\USMT\ANSI\SCRIPT.DLL Win32/Ramnit.H virus (cleaned - quarantined) 00000000000000000000000000000000 C

D:\I386\APPS\APP03912\VALUEADD\MSFT\USMT\ANSI\SYSMOD.DLL Win32/Ramnit.H virus (cleaned - quarantined) 00000000000000000000000000000000 C

D:\I386\APPS\APP03912\VALUEADD\MSFT\USMT\ANSI\UNCTRN.DLL Win32/Ramnit.H virus (cleaned - quarantined) 00000000000000000000000000000000 C

D:\I386\APPS\APP06210\commands.exe Win32/Ramnit.H virus (cleaned - quarantined) 00000000000000000000000000000000 C

D:\I386\APPS\APP06210\HPBootOp\Setup.Exe Win32/Ramnit.H virus (cleaned - quarantined) 00000000000000000000000000000000 C

D:\I386\APPS\APP09876\commands.exe Win32/Ramnit.H virus (cleaned - quarantined) 00000000000000000000000000000000 C

D:\I386\APPS\APP10679\commands.exe Win32/Ramnit.H virus (cleaned - quarantined) 00000000000000000000000000000000 C

D:\I386\APPS\APP12936\commands.exe Win32/Ramnit.H virus (cleaned - quarantined) 00000000000000000000000000000000 C

D:\I386\APPS\APP13211\commands.exe Win32/Ramnit.H virus (cleaned - quarantined) 00000000000000000000000000000000 C

D:\I386\APPS\APP13904\commands.exe Win32/Ramnit.H virus (cleaned - quarantined) 00000000000000000000000000000000 C

D:\I386\APPS\APP13963\commands.exe Win32/Ramnit.H virus (cleaned - quarantined) 00000000000000000000000000000000 C

D:\I386\APPS\APP15411\commands.exe Win32/Ramnit.H virus (cleaned - quarantined) 00000000000000000000000000000000 C

D:\I386\APPS\APP18237\commands.exe Win32/Ramnit.H virus (cleaned - quarantined) 00000000000000000000000000000000 C

D:\I386\APPS\APP18237\src\msvcp71.dll Win32/Ramnit.H virus (cleaned - quarantined) 00000000000000000000000000000000 C

D:\I386\APPS\APP18237\src\msvcr71.dll Win32/Ramnit.H virus (cleaned - quarantined) 00000000000000000000000000000000 C

D:\I386\APPS\APP18237\src\Setup\asCore\AntiSpam\bteuclid.dll Win32/Ramnit.H virus (cleaned - quarantined) 00000000000000000000000000000000 C

D:\I386\APPS\APP18237\src\Setup\asCore\AntiSpam\btutils.dll Win32/Ramnit.H virus (cleaned - quarantined) 00000000000000000000000000000000 C

D:\I386\APPS\APP18237\src\Support\HelpMSI\External\context.dll Win32/Ramnit.H virus (cleaned - quarantined) 00000000000000000000000000000000 C

D:\I386\APPS\APP18237\src\Support\HelpMSI\External\disable.dll Win32/Ramnit.H virus (cleaned - quarantined) 00000000000000000000000000000000 C

D:\I386\APPS\APP18237\src\Support\HelpMSI\External\emerg.dll Win32/Ramnit.H virus (cleaned - quarantined) 00000000000000000000000000000000 C

D:\I386\APPS\APP18237\src\Support\HelpMSI\External\faq.dll Win32/Ramnit.H virus (cleaned - quarantined) 00000000000000000000000000000000 C

D:\I386\APPS\APP18237\src\Support\HelpMSI\External\feat_sum.dll Win32/Ramnit.H virus (cleaned - quarantined) 00000000000000000000000000000000 C

D:\I386\APPS\APP18237\src\Support\HelpMSI\External\LU_001.dll Win32/Ramnit.H virus (cleaned - quarantined) 00000000000000000000000000000000 C

D:\I386\APPS\APP18237\src\Support\HelpMSI\External\LU_002.dll Win32/Ramnit.H virus (cleaned - quarantined) 00000000000000000000000000000000 C

D:\I386\APPS\APP18237\src\Support\HelpMSI\External\LU_003.dll Win32/Ramnit.H virus (cleaned - quarantined) 00000000000000000000000000000000 C

D:\I386\APPS\APP18237\src\Support\HelpMSI\External\LU_004.dll Win32/Ramnit.H virus (cleaned - quarantined) 00000000000000000000000000000000 C

D:\I386\APPS\APP18237\src\Support\HelpMSI\External\LU_005.dll Win32/Ramnit.H virus (cleaned - quarantined) 00000000000000000000000000000000 C

D:\I386\APPS\APP18237\src\Support\HelpMSI\External\LU_006.dll Win32/Ramnit.H virus (cleaned - quarantined) 00000000000000000000000000000000 C

D:\I386\APPS\APP18237\src\Support\HelpMSI\External\LU_PC.dll Win32/Ramnit.H virus (cleaned - quarantined) 00000000000000000000000000000000 C

D:\I386\APPS\APP18237\src\Support\HelpMSI\External\LU_Sub.dll Win32/Ramnit.H virus (cleaned - quarantined) 00000000000000000000000000000000 C

D:\I386\APPS\APP18237\src\Support\HelpMSI\External\monitor.dll Win32/Ramnit.H virus (cleaned - quarantined) 00000000000000000000000000000000 C

D:\I386\APPS\APP18237\src\Support\HelpMSI\External\NAV_001.dll Win32/Ramnit.H virus (cleaned - quarantined) 00000000000000000000000000000000 C

D:\I386\APPS\APP18237\src\Support\HelpMSI\External\options.dll Win32/Ramnit.H virus (cleaned - quarantined) 00000000000000000000000000000000 C

D:\I386\APPS\APP18237\src\Support\HelpMSI\External\Supt_CPD.dll Win32/Ramnit.H virus (cleaned - quarantined) 00000000000000000000000000000000 C

D:\I386\APPS\APP18237\src\Support\HelpMSI\External\symhelp.dll Win32/Ramnit.H virus (cleaned - quarantined) 00000000000000000000000000000000 C

D:\I386\APPS\APP18237\src\Support\HelpMSI\External\unin.dll Win32/Ramnit.H virus (cleaned - quarantined) 00000000000000000000000000000000 C

D:\I386\APPS\APP18237\src\Support\Redist\MSRedist\atl71.dll Win32/Ramnit.H virus (cleaned - quarantined) 00000000000000000000000000000000 C

D:\I386\APPS\APP18237\src\Support\Redist\MSRedist\mfc71.dll Win32/Ramnit.H virus (cleaned - quarantined) 00000000000000000000000000000000 C

D:\I386\APPS\APP18237\src\Support\Redist\MSRedist\mfc71u.dll Win32/Ramnit.H virus (cleaned - quarantined) 00000000000000000000000000000000 C

D:\I386\APPS\APP18237\src\Support\Redist\MSRedist\msvcp71.dll Win32/Ramnit.H virus (cleaned - quarantined) 00000000000000000000000000000000 C

D:\I386\APPS\APP18237\src\Support\Redist\MSRedist\msvcr71.dll Win32/Ramnit.H virus (cleaned - quarantined) 00000000000000000000000000000000 C

D:\I386\APPS\APP18237\src\Support\Redist\MSRedist\msxml3.dll Win32/Ramnit.H virus (cleaned - quarantined) 00000000000000000000000000000000 C

D:\I386\APPS\APP18237\src\Support\Redist\MSRedist\Ansi\atl71.dll Win32/Ramnit.H virus (cleaned - quarantined) 00000000000000000000000000000000 C

D:\I386\APPS\APP18237\src\Support\SymLnch\SymLnch.exe Win32/Ramnit.H virus (cleaned - quarantined) 00000000000000000000000000000000 C

D:\I386\APPS\APP24903\commands.exe Win32/Ramnit.H virus (cleaned - quarantined) 00000000000000000000000000000000 C

D:\I386\APPS\APP24903\src\MSWORKS\AUTORUN.EXE Win32/Ramnit.H virus (cleaned - quarantined) 00000000000000000000000000000000 C

D:\I386\APPS\APP24903\src\MSWORKS\SETUP.EXE Win32/Ramnit.H virus (cleaned - quarantined) 00000000000000000000000000000000 C

D:\I386\APPS\APP24903\src\MSWORKS\COMMON\MSSHARED\EQUATION\EQNEDT32.EXE Win32/Ramnit.H virus (cleaned - quarantined) 00000000000000000000000000000000 C

D:\I386\APPS\APP24903\src\MSWORKS\COMMON\MSSHARED\INFORET\ITIRCL54.DLL Win32/Ramnit.H virus (cleaned - quarantined) 00000000000000000000000000000000 C

D:\I386\APPS\APP24903\src\MSWORKS\COMMON\MSSHARED\INFORET\MSITSS.DLL Win32/Ramnit.H virus (cleaned - quarantined) 00000000000000000000000000000000 C

D:\I386\APPS\APP24903\src\MSWORKS\COMMON\MSSHARED\SHOEBOX\MSVCR71.DLL Win32/Ramnit.H virus (cleaned - quarantined) 00000000000000000000000000000000 C

D:\I386\APPS\APP24903\src\MSWORKS\COMMON\MSSHARED\SHOEBOX\PIOLCH.EXE Win32/Ramnit.H virus (cleaned - quarantined) 00000000000000000000000000000000 C

D:\I386\APPS\APP24903\src\MSWORKS\COMMON\MSSHARED\SHOEBOX\SBOX7.DLL Win32/Ramnit.H virus (cleaned - quarantined) 00000000000000000000000000000000 C

D:\I386\APPS\APP24903\src\MSWORKS\COMMON\MSSHARED\SHOEBOX\STV7.DLL Win32/Ramnit.H virus (cleaned - quarantined) 00000000000000000000000000000000 C

D:\I386\APPS\APP24903\src\MSWORKS\COMMON\MSSHARED\SHOEBOX\WKWINUNI.DLL Win32/Ramnit.H virus (cleaned - quarantined) 00000000000000000000000000000000 C

D:\I386\APPS\APP24903\src\MSWORKS\COMMON\MSSHARED\TEXTCONV\MSVCR71.DLL Win32/Ramnit.H virus (cleaned - quarantined) 00000000000000000000000000000000 C

D:\I386\APPS\APP24903\src\MSWORKS\COMMON\MSSHARED\TEXTCONV\WKCVQD01.DLL Win32/Ramnit.H virus (cleaned - quarantined) 00000000000000000000000000000000 C

D:\I386\APPS\APP24903\src\MSWORKS\COMMON\MSSHARED\TEXTCONV\WKCVQR01.DLL Win32/Ramnit.H virus (cleaned - quarantined) 00000000000000000000000000000000 C

D:\I386\APPS\APP24903\src\MSWORKS\COMMON\MSSHARED\WKSHARED\CPITOOL7.DLL Win32/Ramnit.H virus (cleaned - quarantined) 00000000000000000000000000000000 C

D:\I386\APPS\APP24903\src\MSWORKS\COMMON\MSSHARED\WKSHARED\CPITV7.DLL Win32/Ramnit.H virus (cleaned - quarantined) 00000000000000000000000000000000 C

D:\I386\APPS\APP24903\src\MSWORKS\COMMON\MSSHARED\WKSHARED\EULAREGN.DLL Win32/Ramnit.H virus (cleaned - quarantined) 00000000000000000000000000000000 C

D:\I386\APPS\APP24903\src\MSWORKS\COMMON\MSSHARED\WKSHARED\GDIPLUS.DLL Win32/Ramnit.H virus (cleaned - quarantined) 00000000000000000000000000000000 C

D:\I386\APPS\APP24903\src\MSWORKS\COMMON\MSSHARED\WKSHARED\GTV7.DLL Win32/Ramnit.H virus (cleaned - quarantined) 00000000000000000000000000000000 C

D:\I386\APPS\APP24903\src\MSWORKS\COMMON\MSSHARED\WKSHARED\HTMLLITE.DLL Win32/Ramnit.H virus (cleaned - quarantined) 00000000000000000000000000000000 C

D:\I386\APPS\APP24903\src\MSWORKS\COMMON\MSSHARED\WKSHARED\MSSPELL3.DLL Win32/Ramnit.H virus (cleaned - quarantined) 00000000000000000000000000000000 C

D:\I386\APPS\APP24903\src\MSWORKS\COMMON\MSSHARED\WKSHARED\MSTHES3.DLL Win32/Ramnit.H virus (cleaned - quarantined) 00000000000000000000000000000000 C

D:\I386\APPS\APP24903\src\MSWORKS\COMMON\MSSHARED\WKSHARED\MSVCP71.DLL Win32/Ramnit.H virus (cleaned - quarantined) 00000000000000000000000000000000 C

D:\I386\APPS\APP24903\src\MSWORKS\COMMON\MSSHARED\WKSHARED\MSVCR71.DLL Win32/Ramnit.H virus (cleaned - quarantined) 00000000000000000000000000000000 C

D:\I386\APPS\APP24903\src\MSWORKS\COMMON\MSSHARED\WKSHARED\NUMFMT80.DLL Win32/Ramnit.H virus (cleaned - quarantined) 00000000000000000000000000000000 C

D:\I386\APPS\APP24903\src\MSWORKS\COMMON\MSSHARED\WKSHARED\WKAPCOMP.DLL Win32/Ramnit.H virus (cleaned - quarantined) 00000000000000000000000000000000 C

D:\I386\APPS\APP24903\src\MSWORKS\COMMON\MSSHARED\WKSHARED\WKCALAC.DLL Win32/Ramnit.H virus (cleaned - quarantined) 00000000000000000000000000000000 C

D:\I386\APPS\APP24903\src\MSWORKS\COMMON\MSSHARED\WKSHARED\WKCALIMP.DLL Win32/Ramnit.H virus (cleaned - quarantined) 00000000000000000000000000000000 C

D:\I386\APPS\APP24903\src\MSWORKS\COMMON\MSSHARED\WKSHARED\WKCALOLE.DLL Win32/Ramnit.H virus (cleaned - quarantined) 00000000000000000000000000000000 C

D:\I386\APPS\APP24903\src\MSWORKS\COMMON\MSSHARED\WKSHARED\WKCALPS.DLL Win32/Ramnit.H virus (cleaned - quarantined) 00000000000000000000000000000000 C

D:\I386\APPS\APP24903\src\MSWORKS\COMMON\MSSHARED\WKSHARED\WKCALPSE.DLL Win32/Ramnit.H virus (cleaned - quarantined) 00000000000000000000000000000000 C

D:\I386\APPS\APP24903\src\MSWORKS\COMMON\MSSHARED\WKSHARED\WKCALREM.EXE Win32/Ramnit.H virus (cleaned - quarantined) 00000000000000000000000000000000 C

D:\I386\APPS\APP24903\src\MSWORKS\COMMON\MSSHARED\WKSHARED\WKCALSVC.DLL Win32/Ramnit.H virus (cleaned - quarantined) 00000000000000000000000000000000 C

D:\I386\APPS\APP24903\src\MSWORKS\COMMON\MSSHARED\WKSHARED\WKCALVP.DLL Win32/Ramnit.H virus (cleaned - quarantined) 00000000000000000000000000000000 C

D:\I386\APPS\APP24903\src\MSWORKS\COMMON\MSSHARED\WKSHARED\WKHLP80.DLL Win32/Ramnit.H virus (cleaned - quarantined) 00000000000000000000000000000000 C

D:\I386\APPS\APP24903\src\MSWORKS\COMMON\MSSHARED\WKSHARED\WKPR80.DLL Win32/Ramnit.H virus (cleaned - quarantined) 00000000000000000000000000000000 C

D:\I386\APPS\APP24903\src\MSWORKS\COMMON\MSSHARED\WKSHARED\WKPROOF.DLL Win32/Ramnit.H virus (cleaned - quarantined) 00000000000000000000000000000000 C

D:\I386\APPS\APP24903\src\MSWORKS\COMMON\MSSHARED\WKSHARED\WKSCAL.EXE Win32/Ramnit.H virus (cleaned - quarantined) 00000000000000000000000000000000 C

D:\I386\APPS\APP24903\src\MSWORKS\COMMON\MSSHARED\WKSHARED\WKSCAL.HTM Win32/Ramnit.A virus (cleaned - quarantined) 00000000000000000000000000000000 C

D:\I386\APPS\APP24903\src\MSWORKS\COMMON\MSSHARED\WKSHARED\WKSWAB.DLL Win32/Ramnit.H virus (cleaned - quarantined) 00000000000000000000000000000000 C

D:\I386\APPS\APP24903\src\MSWORKS\COMMON\MSSHARED\WKSHARED\WKWAT.DLL Win32/Ramnit.H virus (cleaned - quarantined) 00000000000000000000000000000000 C

D:\I386\APPS\APP24903\src\MSWORKS\COMMON\MSSHARED\WKSHARED\WKWBL.DLL Win32/Ramnit.H virus (cleaned - quarantined) 00000000000000000000000000000000 C

D:\I386\APPS\APP24903\src\MSWORKS\COMMON\MSSHARED\WKSHARED\WKWFX.DLL Win32/Ramnit.H virus (cleaned - quarantined) 00000000000000000000000000000000 C

D:\I386\APPS\APP24903\src\MSWORKS\COMMON\MSSHARED\WKSHARED\WKWINUNI.DLL Win32/Ramnit.H virus (cleaned - quarantined) 00000000000000000000000000000000 C

D:\I386\APPS\APP24903\src\MSWORKS\COMMON\MSSHARED\WKSHARED\1033\MSGR3EN.DLL Win32/Ramnit.H virus (cleaned - quarantined) 00000000000000000000000000000000 C

D:\I386\APPS\APP24903\src\MSWORKS\COMMON\MSSHARED\WKSHARED\OEM\WKS8WARR.HTM Win32/Ramnit.A virus (cleaned - quarantined) 00000000000000000000000000000000 C

D:\I386\APPS\APP24903\src\MSWORKS\COMMON\MSSHARED\WKSHARED\OEM\WS05WARR.HTM Win32/Ramnit.A virus (cleaned - quarantined) 00000000000000000000000000000000 C

D:\I386\APPS\APP24903\src\MSWORKS\PFILES\MSWORKS\ATL71.DLL Win32/Ramnit.H virus (cleaned - quarantined) 00000000000000000000000000000000 C

D:\I386\APPS\APP24903\src\MSWORKS\PFILES\MSWORKS\EDICTITS.DLL Win32/Ramnit.H virus (cleaned - quarantined) 00000000000000000000000000000000 C

D:\I386\APPS\APP24903\src\MSWORKS\PFILES\MSWORKS\GDIPLUS.DLL Win32/Ramnit.H virus (cleaned - quarantined) 00000000000000000000000000000000 C

D:\I386\APPS\APP24903\src\MSWORKS\PFILES\MSWORKS\HSAPI.DLL Win32/Ramnit.H virus (cleaned - quarantined) 00000000000000000000000000000000 C

D:\I386\APPS\APP24903\src\MSWORKS\PFILES\MSWORKS\HTMLLITE.DLL Win32/Ramnit.H virus (cleaned - quarantined) 00000000000000000000000000000000 C

D:\I386\APPS\APP24903\src\MSWORKS\PFILES\MSWORKS\LFBMP13N.DLL Win32/Ramnit.H virus (cleaned - quarantined) 00000000000000000000000000000000 C

D:\I386\APPS\APP24903\src\MSWORKS\PFILES\MSWORKS\LFCMP13N.DLL Win32/Ramnit.H virus (cleaned - quarantined) 00000000000000000000000000000000 C

D:\I386\APPS\APP24903\src\MSWORKS\PFILES\MSWORKS\LFEPS13N.DLL Win32/Ramnit.H virus (cleaned - quarantined) 00000000000000000000000000000000 C

D:\I386\APPS\APP24903\src\MSWORKS\PFILES\MSWORKS\LFFAX13N.DLL Win32/Ramnit.H virus (cleaned - quarantined) 00000000000000000000000000000000 C

D:\I386\APPS\APP24903\src\MSWORKS\PFILES\MSWORKS\LFGIF13N.DLL Win32/Ramnit.H virus (cleaned - quarantined) 00000000000000000000000000000000 C

D:\I386\APPS\APP24903\src\MSWORKS\PFILES\MSWORKS\LFPCX13N.DLL Win32/Ramnit.H virus (cleaned - quarantined) 00000000000000000000000000000000 C

D:\I386\APPS\APP24903\src\MSWORKS\PFILES\MSWORKS\LFPNG13N.DLL Win32/Ramnit.H virus (cleaned - quarantined) 00000000000000000000000000000000 C

D:\I386\APPS\APP24903\src\MSWORKS\PFILES\MSWORKS\LFPSD13N.DLL Win32/Ramnit.H virus (cleaned - quarantined) 00000000000000000000000000000000 C

D:\I386\APPS\APP24903\src\MSWORKS\PFILES\MSWORKS\LFTGA13N.DLL Win32/Ramnit.H virus (cleaned - quarantined) 00000000000000000000000000000000 C

D:\I386\APPS\APP24903\src\MSWORKS\PFILES\MSWORKS\LFTIF13N.DLL Win32/Ramnit.H virus (cleaned - quarantined) 00000000000000000000000000000000 C

D:\I386\APPS\APP24903\src\MSWORKS\PFILES\MSWORKS\LFWMF13N.DLL Win32/Ramnit.H virus (cleaned - quarantined) 00000000000000000000000000000000 C

D:\I386\APPS\APP24903\src\MSWORKS\PFILES\MSWORKS\LTDIS13N.DLL Win32/Ramnit.H virus (cleaned - quarantined) 00000000000000000000000000000000 C

D:\I386\APPS\APP24903\src\MSWORKS\PFILES\MSWORKS\LTFIL13N.DLL Win32/Ramnit.H virus (cleaned - quarantined) 00000000000000000000000000000000 C

D:\I386\APPS\APP24903\src\MSWORKS\PFILES\MSWORKS\LTIMG13N.DLL Win32/Ramnit.H virus (cleaned - quarantined) 00000000000000000000000000000000 C

D:\I386\APPS\APP24903\src\MSWORKS\PFILES\MSWORKS\LTKRN13N.DLL Win32/Ramnit.H virus (cleaned - quarantined) 00000000000000000000000000000000 C

D:\I386\APPS\APP24903\src\MSWORKS\PFILES\MSWORKS\LTWVC13N.DLL Win32/Ramnit.H virus (cleaned - quarantined) 00000000000000000000000000000000 C

D:\I386\APPS\APP24903\src\MSWORKS\PFILES\MSWORKS\MFC71.DLL Win32/Ramnit.H virus (cleaned - quarantined) 00000000000000000000000000000000 C

D:\I386\APPS\APP24903\src\MSWORKS\PFILES\MSWORKS\MSVCP71.DLL Win32/Ramnit.H virus (cleaned - quarantined) 00000000000000000000000000000000 C

D:\I386\APPS\APP24903\src\MSWORKS\PFILES\MSWORKS\MSVCR71.DLL Win32/Ramnit.H virus (cleaned - quarantined) 00000000000000000000000000000000 C

D:\I386\APPS\APP24903\src\MSWORKS\PFILES\MSWORKS\MSWORKS.EXE Win32/Ramnit.H virus (cleaned - quarantined) 00000000000000000000000000000000 C

D:\I386\APPS\APP24903\src\MSWORKS\PFILES\MSWORKS\WKABSTUB.DLL Win32/Ramnit.H virus (cleaned - quarantined) 00000000000000000000000000000000 C

D:\I386\APPS\APP24903\src\MSWORKS\PFILES\MSWORKS\WKDBEXT.DLL Win32/Ramnit.H virus (cleaned - quarantined) 00000000000000000000000000000000 C

D:\I386\APPS\APP24903\src\MSWORKS\PFILES\MSWORKS\WKDBOLE.DLL Win32/Ramnit.H virus (cleaned - quarantined) 00000000000000000000000000000000 C

D:\I386\APPS\APP24903\src\MSWORKS\PFILES\MSWORKS\WKDSTORE.EXE Win32/Ramnit.H virus (cleaned - quarantined) 00000000000000000000000000000000 C

D:\I386\APPS\APP24903\src\MSWORKS\PFILES\MSWORKS\WKGDCACH.EXE Win32/Ramnit.H virus (cleaned - quarantined) 00000000000000000000000000000000 C

D:\I386\APPS\APP24903\src\MSWORKS\PFILES\MSWORKS\WKGDIPS.DLL Win32/Ramnit.H virus (cleaned - quarantined) 00000000000000000000000000000000 C

D:\I386\APPS\APP24903\src\MSWORKS\PFILES\MSWORKS\WKIMGING.DLL Win32/Ramnit.H virus (cleaned - quarantined) 00000000000000000000000000000000 C

D:\I386\APPS\APP24903\src\MSWORKS\PFILES\MSWORKS\WKIMGSRV.DLL Win32/Ramnit.H virus (cleaned - quarantined) 00000000000000000000000000000000 C

D:\I386\APPS\APP24903\src\MSWORKS\PFILES\MSWORKS\WKLNCKML.EXE Win32/Ramnit.H virus (cleaned - quarantined) 00000000000000000000000000000000 C

D:\I386\APPS\APP24903\src\MSWORKS\PFILES\MSWORKS\WKMERGE.DLL Win32/Ramnit.H virus (cleaned - quarantined) 00000000000000000000000000000000 C

D:\I386\APPS\APP24903\src\MSWORKS\PFILES\MSWORKS\WKMMWDB.DLL Win32/Ramnit.H virus (cleaned - quarantined) 00000000000000000000000000000000 C

D:\I386\APPS\APP24903\src\MSWORKS\PFILES\MSWORKS\WKPJLINK.DLL Win32/Ramnit.H virus (cleaned - quarantined) 00000000000000000000000000000000 C

D:\I386\APPS\APP24903\src\MSWORKS\PFILES\MSWORKS\WKPLMCAL.DLL Win32/Ramnit.H virus (cleaned - quarantined) 00000000000000000000000000000000 C

D:\I386\APPS\APP24903\src\MSWORKS\PFILES\MSWORKS\WKPLMSTP.EXE Win32/Ramnit.H virus (cleaned - quarantined) 00000000000000000000000000000000 C

D:\I386\APPS\APP24903\src\MSWORKS\PFILES\MSWORKS\WKPLMWAB.DLL Win32/Ramnit.H virus (cleaned - quarantined) 00000000000000000000000000000000 C

D:\I386\APPS\APP24903\src\MSWORKS\PFILES\MSWORKS\WKPRJAPI.DLL Win32/Ramnit.H virus (cleaned - quarantined) 00000000000000000000000000000000 C

D:\I386\APPS\APP24903\src\MSWORKS\PFILES\MSWORKS\WKSAB.EXE Win32/Ramnit.H virus (cleaned - quarantined) 00000000000000000000000000000000 C

D:\I386\APPS\APP24903\src\MSWORKS\PFILES\MSWORKS\WKSABIMP.DLL Win32/Ramnit.H virus (cleaned - quarantined) 00000000000000000000000000000000 C

D:\I386\APPS\APP24903\src\MSWORKS\PFILES\MSWORKS\WKSBDP.DLL Win32/Ramnit.H virus (cleaned - quarantined) 00000000000000000000000000000000 C

D:\I386\APPS\APP24903\src\MSWORKS\PFILES\MSWORKS\WKSDB.EXE Win32/Ramnit.H virus (cleaned - quarantined) 00000000000000000000000000000000 C

D:\I386\APPS\APP24903\src\MSWORKS\PFILES\MSWORKS\WKSDB.HTM Win32/Ramnit.A virus (cleaned - quarantined) 00000000000000000000000000000000 C

D:\I386\APPS\APP24903\src\MSWORKS\PFILES\MSWORKS\WKSDICT.EXE Win32/Ramnit.H virus (cleaned - quarantined) 00000000000000000000000000000000 C

D:\I386\APPS\APP24903\src\MSWORKS\PFILES\MSWORKS\WKSHBSVC.DLL Win32/Ramnit.H virus (cleaned - quarantined) 00000000000000000000000000000000 C

D:\I386\APPS\APP24903\src\MSWORKS\PFILES\MSWORKS\WKSSB.EXE Win32/Ramnit.H virus (cleaned - quarantined) 00000000000000000000000000000000 C

D:\I386\APPS\APP24903\src\MSWORKS\PFILES\MSWORKS\WKSSFRM.DLL Win32/Ramnit.H virus (cleaned - quarantined) 00000000000000000000000000000000 C

D:\I386\APPS\APP24903\src\MSWORKS\PFILES\MSWORKS\WKSSHELP.DLL Win32/Ramnit.H virus (cleaned - quarantined) 00000000000000000000000000000000 C

D:\I386\APPS\APP24903\src\MSWORKS\PFILES\MSWORKS\WKSSOLE.DLL Win32/Ramnit.H virus (cleaned - quarantined) 00000000000000000000000000000000 C

D:\I386\APPS\APP24903\src\MSWORKS\PFILES\MSWORKS\WKSSS.EXE Win32/Ramnit.H virus (cleaned - quarantined) 00000000000000000000000000000000 C

D:\I386\APPS\APP24903\src\MSWORKS\PFILES\MSWORKS\WKSSS.HTM Win32/Ramnit.A virus (cleaned - quarantined) 00000000000000000000000000000000 C

D:\I386\APPS\APP24903\src\MSWORKS\PFILES\MSWORKS\WKSWP.EXE Win32/Ramnit.H virus (cleaned - quarantined) 00000000000000000000000000000000 C

D:\I386\APPS\APP24903\src\MSWORKS\PFILES\MSWORKS\WKSWP.HTM Win32/Ramnit.A virus (cleaned - quarantined) 00000000000000000000000000000000 C

D:\I386\APPS\APP24903\src\MSWORKS\PFILES\MSWORKS\WKTHEMES.DLL Win32/Ramnit.H virus (cleaned - quarantined) 00000000000000000000000000000000 C

D:\I386\APPS\APP24903\src\MSWORKS\PFILES\MSWORKS\WKWAT.DLL Win32/Ramnit.H virus (cleaned - quarantined) 00000000000000000000000000000000 C

D:\I386\APPS\APP24903\src\MSWORKS\PFILES\MSWORKS\WKWBL.DLL Win32/Ramnit.H virus (cleaned - quarantined) 00000000000000000000000000000000 C

D:\I386\APPS\APP24903\src\MSWORKS\PFILES\MSWORKS\WKWCECAL.DLL Win32/Ramnit.H virus (cleaned - quarantined) 00000000000000000000000000000000 C

D:\I386\APPS\APP24903\src\MSWORKS\PFILES\MSWORKS\WKWCESTP.EXE Win32/Ramnit.H virus (cleaned - quarantined) 00000000000000000000000000000000 C

D:\I386\APPS\APP24903\src\MSWORKS\PFILES\MSWORKS\WKWCEWAB.DLL Win32/Ramnit.H virus (cleaned - quarantined) 00000000000000000000000000000000 C

D:\I386\APPS\APP24903\src\MSWORKS\PFILES\MSWORKS\WKWFX.DLL Win32/Ramnit.H virus (cleaned - quarantined) 00000000000000000000000000000000 C

D:\I386\APPS\APP24903\src\MSWORKS\PFILES\MSWORKS\WKWINUNI.DLL Win32/Ramnit.H virus (cleaned - quarantined) 00000000000000000000000000000000 C

D:\I386\APPS\APP24903\src\MSWORKS\PFILES\MSWORKS\WKWPAC.DLL Win32/Ramnit.H virus (cleaned - quarantined) 00000000000000000000000000000000 C

D:\I386\APPS\APP24903\src\MSWORKS\PFILES\MSWORKS\WKWPQD.DLL Win32/Ramnit.H virus (cleaned - quarantined) 00000000000000000000000000000000 C

D:\I386\APPS\APP24903\src\MSWORKS\PFILES\MSWORKS\WKWPQRTF.DLL Win32/Ramnit.H virus (cleaned - quarantined) 00000000000000000000000000000000 C

D:\I386\APPS\APP24903\src\MSWORKS\PFILES\MSWORKS\WKWPQUIL.DLL Win32/Ramnit.H virus (cleaned - quarantined) 00000000000000000000000000000000 C

D:\I386\APPS\APP24903\src\MSWORKS\PFILES\MSWORKS\WKWZADDR.DLL Win32/Ramnit.H virus (cleaned - quarantined) 00000000000000000000000000000000 C

D:\I386\APPS\APP24903\src\MSWORKS\PFILES\MSWORKS\WKWZLAY.DLL Win32/Ramnit.H virus (cleaned - quarantined) 00000000000000000000000000000000 C

D:\I386\APPS\APP24903\src\MSWORKS\PFILES\MSWORKS\WKWZLH.DLL Win32/Ramnit.H virus (cleaned - quarantined) 00000000000000000000000000000000 C

D:\I386\APPS\APP24903\src\MSWORKS\PFILES\MSWORKS\WKWZMRG.DLL Win32/Ramnit.H virus (cleaned - quarantined) 00000000000000000000000000000000 C

D:\I386\APPS\APP24903\src\MSWORKS\PFILES\MSWORKS\WKWZSMPL.DLL Win32/Ramnit.H virus (cleaned - quarantined) 00000000000000000000000000000000 C

D:\I386\APPS\APP24903\src\MSWORKS\PFILES\MSWORKS\WKWZTHM.DLL Win32/Ramnit.H virus (cleaned - quarantined) 00000000000000000000000000000000 C

D:\I386\APPS\APP24903\src\MSWORKS\PFILES\MSWORKS\WKWZTMPL.DLL Win32/Ramnit.H virus (cleaned - quarantined) 00000000000000000000000000000000 C

D:\I386\APPS\APP24903\src\MSWORKS\PFILES\MSWORKS\WKWZWIZ.DLL Win32/Ramnit.H virus (cleaned - quarantined) 00000000000000000000000000000000 C

D:\I386\APPS\APP24903\src\MSWORKS\PFILES\MSWORKS\WORKSSVC.DLL Win32/Ramnit.H virus (cleaned - quarantined) 00000000000000000000000000000000 C

D:\I386\APPS\APP24903\src\MSWORKS\PFILES\MSWORKS\WORKSUP.DLL Win32/Ramnit.H virus (cleaned - quarantined) 00000000000000000000000000000000 C

D:\I386\APPS\APP24903\src\MSWORKS\PFILES\MSWORKS\ANSI\ATL71.DLL Win32/Ramnit.H virus (cleaned - quarantined) 00000000000000000000000000000000 C

D:\I386\APPS\APP24903\src\MSWORKS\PFILES\MSWORKS\STANDARD\HELP.HTM Win32/Ramnit.A virus (cleaned - quarantined) 00000000000000000000000000000000 C

D:\I386\APPS\APP24903\src\MSWORKS\PFILES\MSWORKS\STANDARD\PAGES.HTM Win32/Ramnit.A virus (cleaned - quarantined) 00000000000000000000000000000000 C

D:\I386\APPS\APP24903\src\MSWORKS\PFILES\MSWORKS\STANDARD\START.HTM Win32/Ramnit.A virus (cleaned - quarantined) 00000000000000000000000000000000 C

D:\I386\APPS\APP24903\src\MSWORKS\PFILES\MSWORKS\STANDARD\TASKS.HTM Win32/Ramnit.A virus (cleaned - quarantined) 00000000000000000000000000000000 C

D:\I386\APPS\APP24903\src\MSWORKS\PFILES\MSWORKS\STANDARD\WKSGSG.HTM Win32/Ramnit.A virus (cleaned - quarantined) 00000000000000000000000000000000 C

D:\I386\APPS\APP24903\src\MSWORKS\PFILES\MSWORKS\SUITE\HELP.HTM Win32/Ramnit.A virus (cleaned - quarantined) 00000000000000000000000000000000 C

D:\I386\APPS\APP24903\src\MSWORKS\PFILES\MSWORKS\SUITE\PAGES.HTM Win32/Ramnit.A virus (cleaned - quarantined) 00000000000000000000000000000000 C

D:\I386\APPS\APP24903\src\MSWORKS\PFILES\MSWORKS\SUITE\START.HTM Win32/Ramnit.A virus (cleaned - quarantined) 00000000000000000000000000000000 C

D:\I386\APPS\APP24903\src\MSWORKS\PFILES\MSWORKS\SUITE\TASKS.HTM Win32/Ramnit.A virus (cleaned - quarantined) 00000000000000000000000000000000 C

D:\I386\APPS\APP24903\src\MSWORKS\PFILES\MSWORKS\SUITE\WKSGSG.HTM Win32/Ramnit.A virus (cleaned - quarantined) 00000000000000000000000000000000 C

D:\I386\APPS\APP24903\src\MSWORKS\PFILES\OFFICE\PPV\GDIPLUS.DLL Win32/Ramnit.H virus (cleaned - quarantined) 00000000000000000000000000000000 C

D:\I386\APPS\APP24903\src\MSWORKS\PFILES\OFFICE\PPV\PVREADME.HTM Win32/Ramnit.A virus (cleaned - quarantined) 00000000000000000000000000000000 C

D:\I386\APPS\APP24903\src\MSWORKS\SXS\MSXML4.DLL Win32/Ramnit.H virus (cleaned - quarantined) 00000000000000000000000000000000 C

D:\I386\APPS\APP24903\src\MSWORKS\SYSTEM\MSXML4.DLL Win32/Ramnit.H virus (cleaned - quarantined) 00000000000000000000000000000000 C

D:\I386\APPS\APP24903\src\MSWORKS\SYSTEM32\HLP95EN.DLL Win32/Ramnit.H virus (cleaned - quarantined) 00000000000000000000000000000000 C

D:\I386\APPS\APP24903\src\MSWORKS\SYSTEM32\LFBMP11N.DLL Win32/Ramnit.H virus (cleaned - quarantined) 00000000000000000000000000000000 C

D:\I386\APPS\APP24903\src\MSWORKS\SYSTEM32\LFCMP11N.DLL Win32/Ramnit.H virus (cleaned - quarantined) 00000000000000000000000000000000 C

D:\I386\APPS\APP24903\src\MSWORKS\SYSTEM32\LFEPS11N.DLL Win32/Ramnit.H virus (cleaned - quarantined) 00000000000000000000000000000000 C

D:\I386\APPS\APP24903\src\MSWORKS\SYSTEM32\LFFAX11N.DLL Win32/Ramnit.H virus (cleaned - quarantined) 00000000000000000000000000000000 C

D:\I386\APPS\APP24903\src\MSWORKS\SYSTEM32\LFGIF11N.DLL Win32/Ramnit.H virus (cleaned - quarantined) 00000000000000000000000000000000 C

D:\I386\APPS\APP24903\src\MSWORKS\SYSTEM32\LFPCD11N.DLL Win32/Ramnit.H virus (cleaned - quarantined) 00000000000000000000000000000000 C

D:\I386\APPS\APP24903\src\MSWORKS\SYSTEM32\LFPCX11N.DLL Win32/Ramnit.H virus (cleaned - quarantined) 00000000000000000000000000000000 C

D:\I386\APPS\APP24903\src\MSWORKS\SYSTEM32\LFPNG11N.DLL Win32/Ramnit.H virus (cleaned - quarantined) 00000000000000000000000000000000 C

D:\I386\APPS\APP24903\src\MSWORKS\SYSTEM32\LFPSD11N.DLL Win32/Ramnit.H virus (cleaned - quarantined) 00000000000000000000000000000000 C

D:\I386\APPS\APP24903\src\MSWORKS\SYSTEM32\LFTGA11N.DLL Win32/Ramnit.H virus (cleaned - quarantined) 00000000000000000000000000000000 C

D:\I386\APPS\APP24903\src\MSWORKS\SYSTEM32\LFTIF11N.DLL Win32/Ramnit.H virus (cleaned - quarantined) 00000000000000000000000000000000 C

D:\I386\APPS\APP24903\src\MSWORKS\SYSTEM32\LFWMF11N.DLL Win32/Ramnit.H virus (cleaned - quarantined) 00000000000000000000000000000000 C

D:\I386\APPS\APP24903\src\MSWORKS\SYSTEM32\LTDIS11N.DLL Win32/Ramnit.H virus (cleaned - quarantined) 00000000000000000000000000000000 C

D:\I386\APPS\APP24903\src\MSWORKS\SYSTEM32\LTFIL11N.DLL Win32/Ramnit.H virus (cleaned - quarantined) 00000000000000000000000000000000 C

D:\I386\APPS\APP24903\src\MSWORKS\SYSTEM32\LTIMG11N.DLL Win32/Ramnit.H virus (cleaned - quarantined) 00000000000000000000000000000000 C

D:\I386\APPS\APP24903\src\MSWORKS\SYSTEM32\LTKRN11N.DLL Win32/Ramnit.H virus (cleaned - quarantined) 00000000000000000000000000000000 C

D:\I386\APPS\APP24903\src\MSWORKS\SYSTEM32\LTWVC11N.DLL Win32/Ramnit.H virus (cleaned - quarantined) 00000000000000000000000000000000 C

D:\I386\APPS\APP24903\src\MSWORKS\SYSTEM32\MFCUIA32.DLL Win32/Ramnit.H virus (cleaned - quarantined) 00000000000000000000000000000000 C

D:\I386\APPS\APP24903\src\MSWORKS\SYSTEM32\MSVCI70.DLL Win32/Ramnit.H virus (cleaned - quarantined) 00000000000000000000000000000000 C

D:\I386\APPS\APP24903\src\MSWORKS\SYSTEM32\MSVCP50.DLL Win32/Ramnit.H virus (cleaned - quarantined) 00000000000000000000000000000000 C

D:\I386\APPS\APP24903\src\MSWORKS\SYSTEM32\MSVCP70.DLL Win32/Ramnit.H virus (cleaned - quarantined) 00000000000000000000000000000000 C

D:\I386\APPS\APP24903\src\MSWORKS\SYSTEM32\MSVCR70.DLL Win32/Ramnit.H virus (cleaned - quarantined) 00000000000000000000000000000000 C

D:\I386\APPS\APP24903\src\MSWORKS\SYSTEM32\OCHLP30E.DLL Win32/Ramnit.H virus (cleaned - quarantined) 00000000000000000000000000000000 C

D:\I386\APPS\APP24903\src\MSWORKS\SYSTEM32\RSRC32.DLL Win32/Ramnit.H virus (cleaned - quarantined) 00000000000000000000000000000000 C

D:\I386\APPS\APP24903\src\MSWORKS\SYSTEM32\REDIST\MS\SYSTEM\ATL.DLL Win32/Ramnit.H virus (cleaned - quarantined) 00000000000000000000000000000000 C

D:\I386\APPS\APP30697\commands.exe Win32/Ramnit.H virus (cleaned - quarantined) 00000000000000000000000000000000 C

D:\I386\APPS\APP30697\src\HPDUtil.dll Win32/Ramnit.H virus (cleaned - quarantined) 00000000000000000000000000000000 C

D:\I386\APPS\APP30697\src\Setup.exe Win32/Ramnit.H virus (cleaned - quarantined) 00000000000000000000000000000000 C

D:\I386\DRV\APP00107\commands.exe Win32/Ramnit.H virus (cleaned - quarantined) 00000000000000000000000000000000 C

D:\I386\DRV\APP00107\KBUPDATE.EXE Win32/Ramnit.H virus (cleaned - quarantined) 00000000000000000000000000000000 C

D:\I386\DRV\APP00107\KBD_DLL\aol.dll Win32/Ramnit.H virus (cleaned - quarantined) 00000000000000000000000000000000 C

D:\I386\DRV\APP00107\KBD_DLL\cfg.dll Win32/Ramnit.H virus (cleaned - quarantined) 00000000000000000000000000000000 C

D:\I386\DRV\APP00107\KBD_DLL\Kbdcpl.dll Win32/Ramnit.H virus (cleaned - quarantined) 00000000000000000000000000000000 C

D:\I386\DRV\APP00107\KBD_DLL\led.dll Win32/Ramnit.H virus (cleaned - quarantined) 00000000000000000000000000000000 C

D:\I386\DRV\APP00107\KBD_DLL\msg.dll Win32/Ramnit.H virus (cleaned - quarantined) 00000000000000000000000000000000 C

D:\I386\DRV\APP00107\KBD_DLL\msikbdif.dll Win32/Ramnit.H virus (cleaned - quarantined) 00000000000000000000000000000000 C

D:\I386\DRV\APP00107\KBD_DLL\Onl.dll Win32/Ramnit.H virus (cleaned - quarantined) 00000000000000000000000000000000 C

D:\I386\DRV\APP00107\KBD_DLL\OSD.DLL Win32/Ramnit.H virus (cleaned - quarantined) 00000000000000000000000000000000 C

D:\I386\DRV\APP00107\KBD_DLL\PS2.dll Win32/Ramnit.H virus (cleaned - quarantined) 00000000000000000000000000000000 C

D:\I386\DRV\APP00107\KBD_DLL\sct.dll Win32/Ramnit.H virus (cleaned - quarantined) 00000000000000000000000000000000 C

D:\I386\DRV\APP00107\KBD_DLL\url.dll Win32/Ramnit.H virus (cleaned - quarantined) 00000000000000000000000000000000 C

D:\I386\DRV\APP00107\KBD_DLL\usb.dll Win32/Ramnit.H virus (cleaned - quarantined) 00000000000000000000000000000000 C

D:\I386\DRV\APP00107\src\CreateVF.exe Win32/Ramnit.H virus (cleaned - quarantined) 00000000000000000000000000000000 C

D:\I386\DRV\APP00107\src\Help.exe Win32/Ramnit.H virus (cleaned - quarantined) 00000000000000000000000000000000 C

D:\I386\DRV\APP00107\src\kbd.exe Win32/Ramnit.H virus (cleaned - quarantined) 00000000000000000000000000000000 C

D:\I386\DRV\APP00107\static\buttonconfig.htm Win32/Ramnit.A virus (cleaned - quarantined) 00000000000000000000000000000000 C

D:\I386\DRV\APP00107\static\AR\buttonconfig.htm Win32/Ramnit.A virus (cleaned - quarantined) 00000000000000000000000000000000 C

D:\I386\DRV\APP00107\static\AR\Chat.htm Win32/Ramnit.A virus (cleaned - quarantined) 00000000000000000000000000000000 C

D:\I386\DRV\APP00107\static\AR\Connect.htm Win32/Ramnit.A virus (cleaned - quarantined) 00000000000000000000000000000000 C

D:\I386\DRV\APP00107\static\AR\Copy of HP.htm Win32/Ramnit.A virus (cleaned - quarantined) 00000000000000000000000000000000 C

D:\I386\DRV\APP00107\static\AR\email.htm Win32/Ramnit.A virus (cleaned - quarantined) 00000000000000000000000000000000 C

D:\I386\DRV\APP00107\static\AR\Entertainment.htm Win32/Ramnit.A virus (cleaned - quarantined) 00000000000000000000000000000000 C

D:\I386\DRV\APP00107\static\AR\Finance.htm Win32/Ramnit.A virus (cleaned - quarantined) 00000000000000000000000000000000 C

D:\I386\DRV\APP00107\static\AR\help.htm Win32/Ramnit.A virus (cleaned - quarantined) 00000000000000000000000000000000 C

D:\I386\DRV\APP00107\static\AR\HP.htm Win32/Ramnit.A virus (cleaned - quarantined) 00000000000000000000000000000000 C

D:\I386\DRV\APP00107\static\AR\People.htm Win32/Ramnit.A virus (cleaned - quarantined) 00000000000000000000000000000000 C

D:\I386\DRV\APP00107\static\AR\Search.htm Win32/Ramnit.A virus (cleaned - quarantined) 00000000000000000000000000000000 C

D:\I386\DRV\APP00107\static\AR\Shopping.htm Win32/Ramnit.A virus (cleaned - quarantined) 00000000000000000000000000000000 C

D:\I386\DRV\APP00107\static\AR\Sports.htm Win32/Ramnit.A virus (cleaned - quarantined) 00000000000000000000000000000000 C

D:\I386\DRV\APP00107\static\AR\video.htm Win32/Ramnit.A virus (cleaned - quarantined) 00000000000000000000000000000000 C

D:\I386\DRV\APP00107\static\AR\weather.htm Win32/Ramnit.A virus (cleaned - quarantined) 00000000000000000000000000000000 C

D:\I386\DRV\APP00107\static\Common\hpkey.exe Win32/Ramnit.H virus (cleaned - quarantined) 00000000000000000000000000000000 C

D:\I386\DRV\APP00107\static\DA\buttonconfig.htm Win32/Ramnit.A virus (cleaned - quarantined) 00000000000000000000000000000000 C

D:\I386\DRV\APP00107\static\DA\Chat.htm Win32/Ramnit.A virus (cleaned - quarantined) 00000000000000000000000000000000 C

D:\I386\DRV\APP00107\static\DA\Connect.htm Win32/Ramnit.A virus (cleaned - quarantined) 00000000000000000000000000000000 C

D:\I386\DRV\APP00107\static\DA\email.htm Win32/Ramnit.A virus (cleaned - quarantined) 00000000000000000000000000000000 C

D:\I386\DRV\APP00107\static\DA\Entertainment.htm Win32/Ramnit.A virus (cleaned - quarantined) 00000000000000000000000000000000 C

D:\I386\DRV\APP00107\static\DA\Finance.htm Win32/Ramnit.A virus (cleaned - quarantined) 00000000000000000000000000000000 C

D:\I386\DRV\APP00107\static\DA\help.htm Win32/Ramnit.A virus (cleaned - quarantined) 00000000000000000000000000000000 C

D:\I386\DRV\APP00107\static\DA\HP.htm Win32/Ramnit.A virus (cleaned - quarantined) 00000000000000000000000000000000 C

D:\I386\DRV\APP00107\static\DA\People.htm Win32/Ramnit.A virus (cleaned - quarantined) 00000000000000000000000000000000 C

D:\I386\DRV\APP00107\static\DA\Search.htm Win32/Ramnit.A virus (cleaned - quarantined) 00000000000000000000000000000000 C

D:\I386\DRV\APP00107\static\DA\Shopping.htm Win32/Ramnit.A virus (cleaned - quarantined) 00000000000000000000000000000000 C

D:\I386\DRV\APP00107\static\DA\Sports.htm Win32/Ramnit.A virus (cleaned - quarantined) 00000000000000000000000000000000 C

D:\I386\DRV\APP00107\static\DA\weather.htm Win32/Ramnit.A virus (cleaned - quarantined) 00000000000000000000000000000000 C

D:\I386\DRV\APP00107\static\DE\buttonconfig.htm Win32/Ramnit.A virus (cleaned - quarantined) 00000000000000000000000000000000 C

D:\I386\DRV\APP00107\static\DE\chat.htm Win32/Ramnit.A virus (cleaned - quarantined) 00000000000000000000000000000000 C

D:\I386\DRV\APP00107\static\DE\Connect.htm Win32/Ramnit.A virus (cleaned - quarantined) 00000000000000000000000000000000 C

D:\I386\DRV\APP00107\static\DE\email.htm Win32/Ramnit.A virus (cleaned - quarantined) 00000000000000000000000000000000 C

D:\I386\DRV\APP00107\static\DE\Entertainment.htm Win32/Ramnit.A virus (cleaned - quarantined) 00000000000000000000000000000000 C

D:\I386\DRV\APP00107\static\DE\Finance.htm Win32/Ramnit.A virus (cleaned - quarantined) 00000000000000000000000000000000 C

D:\I386\DRV\APP00107\static\DE\help.htm Win32/Ramnit.A virus (cleaned - quarantined) 00000000000000000000000000000000 C

D:\I386\DRV\APP00107\static\DE\HP.htm Win32/Ramnit.A virus (cleaned - quarantined) 00000000000000000000000000000000 C

D:\I386\DRV\APP00107\static\DE\People.htm Win32/Ramnit.A virus (cleaned - quarantined) 00000000000000000000000000000000 C

D:\I386\DRV\APP00107\static\DE\Search.htm Win32/Ramnit.A virus (cleaned - quarantined) 00000000000000000000000000000000 C

D:\I386\DRV\APP00107\static\DE\Shopping.htm Win32/Ramnit.A virus (cleaned - quarantined) 00000000000000000000000000000000 C

D:\I386\DRV\APP00107\static\DE\Sports.htm Win32/Ramnit.A virus (cleaned - quarantined) 00000000000000000000000000000000 C

D:\I386\DRV\APP00107\static\EN\buttonconfig.htm Win32/Ramnit.A virus (cleaned - quarantined) 00000000000000000000000000000000 C

D:\I386\DRV\APP00107\static\EN\Chat.htm Win32/Ramnit.A virus (cleaned - quarantined) 00000000000000000000000000000000 C

D:\I386\DRV\APP00107\static\EN\Connect.htm Win32/Ramnit.A virus (cleaned - quarantined) 00000000000000000000000000000000 C

D:\I386\DRV\APP00107\static\EN\email.htm Win32/Ramnit.A virus (cleaned - quarantined) 00000000000000000000000000000000 C

D:\I386\DRV\APP00107\static\EN\Entertainment.htm Win32/Ramnit.A virus (cleaned - quarantined) 00000000000000000000000000000000 C

D:\I386\DRV\APP00107\static\EN\Finance.htm Win32/Ramnit.A virus (cleaned - quarantined) 00000000000000000000000000000000 C

D:\I386\DRV\APP00107\static\EN\help.htm Win32/Ramnit.A virus (cleaned - quarantined) 00000000000000000000000000000000 C

D:\I386\DRV\APP00107\static\EN\HP.htm Win32/Ramnit.A virus (cleaned - quarantined) 00000000000000000000000000000000 C

D:\I386\DRV\APP00107\static\EN\People.htm Win32/Ramnit.A virus (cleaned - quarantined) 00000000000000000000000000000000 C

D:\I386\DRV\APP00107\static\EN\Search.htm Win32/Ramnit.A virus (cleaned - quarantined) 00000000000000000000000000000000 C

D:\I386\DRV\APP00107\static\EN\Shopping.htm Win32/Ramnit.A virus (cleaned - quarantined) 00000000000000000000000000000000 C

D:\I386\DRV\APP00107\static\EN\Sports.htm Win32/Ramnit.A virus (cleaned - quarantined) 00000000000000000000000000000000 C

D:\I386\DRV\APP00107\static\EN\video.htm Win32/Ramnit.A virus (cleaned - quarantined) 00000000000000000000000000000000 C

D:\I386\DRV\APP00107\static\EN\weather.htm Win32/Ramnit.A virus (cleaned - quarantined) 00000000000000000000000000000000 C

D:\I386\DRV\APP00107\static\ES\buttonconfig.htm Win32/Ramnit.A virus (cleaned - quarantined) 00000000000000000000000000000000 C

D:\I386\DRV\APP00107\static\ES\Chat.htm Win32/Ramnit.A virus (cleaned - quarantined) 00000000000000000000000000000000 C

D:\I386\DRV\APP00107\static\ES\Connect.htm Win32/Ramnit.A virus (cleaned - quarantined) 00000000000000000000000000000000 C

D:\I386\DRV\APP00107\static\ES\email.htm Win32/Ramnit.A virus (cleaned - quarantined) 00000000000000000000000000000000 C

D:\I386\DRV\APP00107\static\ES\Entertainment.htm Win32/Ramnit.A virus (cleaned - quarantined) 00000000000000000000000000000000 C

D:\I386\DRV\APP00107\static\ES\Finance.htm Win32/Ramnit.A virus (cleaned - quarantined) 00000000000000000000000000000000 C

D:\I386\DRV\APP00107\static\ES\help.htm Win32/Ramnit.A virus (cleaned - quarantined) 00000000000000000000000000000000 C

D:\I386\DRV\APP00107\static\ES\HP.htm Win32/Ramnit.A virus (cleaned - quarantined) 00000000000000000000000000000000 C

D:\I386\DRV\APP00107\static\ES\People.htm Win32/Ramnit.A virus (cleaned - quarantined) 00000000000000000000000000000000 C

D:\I386\DRV\APP00107\static\ES\Search.htm Win32/Ramnit.A virus (cleaned - quarantined) 00000000000000000000000000000000 C

D:\I386\DRV\APP00107\static\ES\Shopping.htm Win32/Ramnit.A virus (cleaned - quarantined) 00000000000000000000000000000000 C

D:\I386\DRV\APP00107\static\ES\sports.htm Win32/Ramnit.A virus (cleaned - quarantined) 00000000000000000000000000000000 C

D:\I386\DRV\APP00107\static\FI\buttonconfig.htm Win32/Ramnit.A virus (cleaned - quarantined) 00000000000000000000000000000000 C

D:\I386\DRV\APP00107\static\FI\Chat.htm Win32/Ramnit.A virus (cleaned - quarantined) 00000000000000000000000000000000 C

D:\I386\DRV\APP00107\static\FI\Connect.htm Win32/Ramnit.A virus (cleaned - quarantined) 00000000000000000000000000000000 C

D:\I386\DRV\APP00107\static\FI\email.htm Win32/Ramnit.A virus (cleaned - quarantined) 00000000000000000000000000000000 C

D:\I386\DRV\APP00107\static\FI\Entertainment.htm Win32/Ramnit.A virus (cleaned - quarantined) 00000000000000000000000000000000 C

D:\I386\DRV\APP00107\static\FI\Finance.htm Win32/Ramnit.A virus (cleaned - quarantined) 00000000000000000000000000000000 C

D:\I386\DRV\APP00107\static\FI\help.htm Win32/Ramnit.A virus (cleaned - quarantined) 00000000000000000000000000000000 C

D:\I386\DRV\APP00107\static\FI\HP.htm Win32/Ramnit.A virus (cleaned - quarantined) 00000000000000000000000000000000 C

D:\I386\DRV\APP00107\static\FI\People.htm Win32/Ramnit.A virus (cleaned - quarantined) 00000000000000000000000000000000 C

D:\I386\DRV\APP00107\static\FI\Search.htm Win32/Ramnit.A virus (cleaned - quarantined) 00000000000000000000000000000000 C

D:\I386\DRV\APP00107\static\FI\Shopping.htm Win32/Ramnit.A virus (cleaned - quarantined) 00000000000000000000000000000000 C

D:\I386\DRV\APP00107\static\FI\Sports.htm Win32/Ramnit.A virus (cleaned - quarantined) 00000000000000000000000000000000 C

D:\I386\DRV\APP00107\static\FI\weather.htm Win32/Ramnit.A virus (cleaned - quarantined) 00000000000000000000000000000000 C

D:\I386\DRV\APP00107\static\FR\buttonconfig.htm Win32/Ramnit.A virus (cleaned - quarantined) 00000000000000000000000000000000 C

D:\I386\DRV\APP00107\static\FR\chat.htm Win32/Ramnit.A virus (cleaned - quarantined) 00000000000000000000000000000000 C

D:\I386\DRV\APP00107\static\FR\Connect.htm Win32/Ramnit.A virus (cleaned - quarantined) 00000000000000000000000000000000 C

D:\I386\DRV\APP00107\static\FR\email.htm Win32/Ramnit.A virus (cleaned - quarantined) 00000000000000000000000000000000 C

D:\I386\DRV\APP00107\static\FR\Entertainment.htm Win32/Ramnit.A virus (cleaned - quarantined) 00000000000000000000000000000000 C

D:\I386\DRV\APP00107\static\FR\Finance.htm Win32/Ramnit.A virus (cleaned - quarantined) 00000000000000000000000000000000 C

errorDLL.bmp

Link to post
Share on other sites

D:\System Volume Information\_restore{F7149EC7-4FA5-4148-81FA-2F7A6348FD9A}\RP5\A0002327.EXE Win32/Ramnit.H virus (cleaned - quarantined) 00000000000000000000000000000000 C

D:\System Volume Information\_restore{F7149EC7-4FA5-4148-81FA-2F7A6348FD9A}\RP5\A0002208.exe Win32/Ramnit.H virus (cleaned - quarantined) 00000000000000000000000000000000 C

D:\System Volume Information\_restore{F7149EC7-4FA5-4148-81FA-2F7A6348FD9A}\RP5\A0002209.exe Win32/Ramnit.H virus (cleaned - quarantined) 00000000000000000000000000000000 C

D:\System Volume Information\_restore{F7149EC7-4FA5-4148-81FA-2F7A6348FD9A}\RP5\A0002210.exe Win32/Ramnit.H virus (cleaned - quarantined) 00000000000000000000000000000000 C

D:\System Volume Information\_restore{F7149EC7-4FA5-4148-81FA-2F7A6348FD9A}\RP5\A0002211.dll Win32/Ramnit.H virus (cleaned - quarantined) 00000000000000000000000000000000 C

D:\System Volume Information\_restore{F7149EC7-4FA5-4148-81FA-2F7A6348FD9A}\RP5\A0002212.DLL Win32/Ramnit.H virus (cleaned - quarantined) 00000000000000000000000000000000 C

D:\System Volume Information\_restore{F7149EC7-4FA5-4148-81FA-2F7A6348FD9A}\RP5\A0002213.DLL Win32/Ramnit.H virus (cleaned - quarantined) 00000000000000000000000000000000 C

D:\System Volume Information\_restore{F7149EC7-4FA5-4148-81FA-2F7A6348FD9A}\RP5\A0002214.exe Win32/Ramnit.H virus (cleaned - quarantined) 00000000000000000000000000000000 C

D:\System Volume Information\_restore{F7149EC7-4FA5-4148-81FA-2F7A6348FD9A}\RP5\A0002215.dll Win32/Ramnit.H virus (cleaned - quarantined) 00000000000000000000000000000000 C

D:\System Volume Information\_restore{F7149EC7-4FA5-4148-81FA-2F7A6348FD9A}\RP5\A0002216.EXE Win32/Ramnit.H virus (cleaned - quarantined) 00000000000000000000000000000000 C

D:\System Volume Information\_restore{F7149EC7-4FA5-4148-81FA-2F7A6348FD9A}\RP5\A0002217.dll Win32/Ramnit.H virus (cleaned - quarantined) 00000000000000000000000000000000 C

D:\System Volume Information\_restore{F7149EC7-4FA5-4148-81FA-2F7A6348FD9A}\RP5\A0002218.exe Win32/Ramnit.H virus (cleaned - quarantined) 00000000000000000000000000000000 C

D:\System Volume Information\_restore{F7149EC7-4FA5-4148-81FA-2F7A6348FD9A}\RP5\A0002219.EXE Win32/Ramnit.H virus (cleaned - quarantined) 00000000000000000000000000000000 C

D:\System Volume Information\_restore{F7149EC7-4FA5-4148-81FA-2F7A6348FD9A}\RP5\A0002220.dll Win32/Ramnit.H virus (cleaned - quarantined) 00000000000000000000000000000000 C

D:\System Volume Information\_restore{F7149EC7-4FA5-4148-81FA-2F7A6348FD9A}\RP5\A0002221.dll Win32/Ramnit.H virus (cleaned - quarantined) 00000000000000000000000000000000 C

D:\System Volume Information\_restore{F7149EC7-4FA5-4148-81FA-2F7A6348FD9A}\RP5\A0002222.DLL Win32/Ramnit.H virus (cleaned - quarantined) 00000000000000000000000000000000 C

D:\System Volume Information\_restore{F7149EC7-4FA5-4148-81FA-2F7A6348FD9A}\RP5\A0002223.exe Win32/Ramnit.H virus (cleaned - quarantined) 00000000000000000000000000000000 C

D:\System Volume Information\_restore{F7149EC7-4FA5-4148-81FA-2F7A6348FD9A}\RP5\A0002224.DLL Win32/Ramnit.H virus (cleaned - quarantined) 00000000000000000000000000000000 C

D:\System Volume Information\_restore{F7149EC7-4FA5-4148-81FA-2F7A6348FD9A}\RP5\A0002225.exe Win32/Ramnit.H virus (cleaned - quarantined) 00000000000000000000000000000000 C

D:\System Volume Information\_restore{F7149EC7-4FA5-4148-81FA-2F7A6348FD9A}\RP5\A0002226.DLL Win32/Ramnit.H virus (cleaned - quarantined) 00000000000000000000000000000000 C

D:\System Volume Information\_restore{F7149EC7-4FA5-4148-81FA-2F7A6348FD9A}\RP5\A0002227.EXE Win32/Ramnit.H virus (cleaned - quarantined) 00000000000000000000000000000000 C

D:\System Volume Information\_restore{F7149EC7-4FA5-4148-81FA-2F7A6348FD9A}\RP5\A0002228.dll Win32/Ramnit.H virus (cleaned - quarantined) 00000000000000000000000000000000 C

D:\System Volume Information\_restore{F7149EC7-4FA5-4148-81FA-2F7A6348FD9A}\RP5\A0002229.dll Win32/Ramnit.H virus (cleaned - quarantined) 00000000000000000000000000000000 C

D:\System Volume Information\_restore{F7149EC7-4FA5-4148-81FA-2F7A6348FD9A}\RP5\A0002230.exe Win32/Ramnit.H virus (cleaned - quarantined) 00000000000000000000000000000000 C

D:\System Volume Information\_restore{F7149EC7-4FA5-4148-81FA-2F7A6348FD9A}\RP5\A0002231.exe Win32/Ramnit.H virus (cleaned - quarantined) 00000000000000000000000000000000 C

D:\System Volume Information\_restore{F7149EC7-4FA5-4148-81FA-2F7A6348FD9A}\RP5\A0002232.dll Win32/Ramnit.H virus (cleaned - quarantined) 00000000000000000000000000000000 C

D:\System Volume Information\_restore{F7149EC7-4FA5-4148-81FA-2F7A6348FD9A}\RP5\A0002233.exe Win32/Ramnit.H virus (cleaned - quarantined) 00000000000000000000000000000000 C

D:\System Volume Information\_restore{F7149EC7-4FA5-4148-81FA-2F7A6348FD9A}\RP5\A0002234.EXE Win32/Ramnit.H virus (cleaned - quarantined) 00000000000000000000000000000000 C

D:\System Volume Information\_restore{F7149EC7-4FA5-4148-81FA-2F7A6348FD9A}\RP5\A0002235.exe Win32/Ramnit.H virus (cleaned - quarantined) 00000000000000000000000000000000 C

D:\System Volume Information\_restore{F7149EC7-4FA5-4148-81FA-2F7A6348FD9A}\RP5\A0002236.EXE Win32/Ramnit.H virus (cleaned - quarantined) 00000000000000000000000000000000 C

D:\System Volume Information\_restore{F7149EC7-4FA5-4148-81FA-2F7A6348FD9A}\RP5\A0002237.dll Win32/Ramnit.H virus (cleaned - quarantined) 00000000000000000000000000000000 C

D:\System Volume Information\_restore{F7149EC7-4FA5-4148-81FA-2F7A6348FD9A}\RP5\A0002238.dll Win32/Ramnit.H virus (cleaned - quarantined) 00000000000000000000000000000000 C

D:\System Volume Information\_restore{F7149EC7-4FA5-4148-81FA-2F7A6348FD9A}\RP5\A0002239.exe Win32/Ramnit.H virus (cleaned - quarantined) 00000000000000000000000000000000 C

D:\System Volume Information\_restore{F7149EC7-4FA5-4148-81FA-2F7A6348FD9A}\RP5\A0002240.exe Win32/Ramnit.H virus (cleaned - quarantined) 00000000000000000000000000000000 C

D:\System Volume Information\_restore{F7149EC7-4FA5-4148-81FA-2F7A6348FD9A}\RP5\A0002241.DLL Win32/Ramnit.H virus (cleaned - quarantined) 00000000000000000000000000000000 C

D:\System Volume Information\_restore{F7149EC7-4FA5-4148-81FA-2F7A6348FD9A}\RP5\A0002242.dll Win32/Ramnit.H virus (cleaned - quarantined) 00000000000000000000000000000000 C

D:\System Volume Information\_restore{F7149EC7-4FA5-4148-81FA-2F7A6348FD9A}\RP5\A0002243.DLL Win32/Ramnit.H virus (cleaned - quarantined) 00000000000000000000000000000000 C

D:\System Volume Information\_restore{F7149EC7-4FA5-4148-81FA-2F7A6348FD9A}\RP5\A0002244.exe Win32/Ramnit.H virus (cleaned - quarantined) 00000000000000000000000000000000 C

D:\System Volume Information\_restore{F7149EC7-4FA5-4148-81FA-2F7A6348FD9A}\RP5\A0002245.dll Win32/Ramnit.H virus (cleaned - quarantined) 00000000000000000000000000000000 C

D:\System Volume Information\_restore{F7149EC7-4FA5-4148-81FA-2F7A6348FD9A}\RP5\A0002246.dll Win32/Ramnit.H virus (cleaned - quarantined) 00000000000000000000000000000000 C

D:\System Volume Information\_restore{F7149EC7-4FA5-4148-81FA-2F7A6348FD9A}\RP5\A0002247.dll Win32/Ramnit.H virus (cleaned - quarantined) 00000000000000000000000000000000 C

D:\System Volume Information\_restore{F7149EC7-4FA5-4148-81FA-2F7A6348FD9A}\RP5\A0002248.dll Win32/Ramnit.H virus (cleaned - quarantined) 00000000000000000000000000000000 C

D:\System Volume Information\_restore{F7149EC7-4FA5-4148-81FA-2F7A6348FD9A}\RP5\A0002249.dll Win32/Ramnit.H virus (cleaned - quarantined) 00000000000000000000000000000000 C

D:\System Volume Information\_restore{F7149EC7-4FA5-4148-81FA-2F7A6348FD9A}\RP5\A0002250.dll Win32/Ramnit.H virus (cleaned - quarantined) 00000000000000000000000000000000 C

D:\System Volume Information\_restore{F7149EC7-4FA5-4148-81FA-2F7A6348FD9A}\RP5\A0002251.dll Win32/Ramnit.H virus (cleaned - quarantined) 00000000000000000000000000000000 C

D:\System Volume Information\_restore{F7149EC7-4FA5-4148-81FA-2F7A6348FD9A}\RP5\A0002252.dll Win32/Ramnit.H virus (cleaned - quarantined) 00000000000000000000000000000000 C

D:\System Volume Information\_restore{F7149EC7-4FA5-4148-81FA-2F7A6348FD9A}\RP5\A0002253.dll Win32/Ramnit.H virus (cleaned - quarantined) 00000000000000000000000000000000 C

D:\System Volume Information\_restore{F7149EC7-4FA5-4148-81FA-2F7A6348FD9A}\RP5\A0002254.dll Win32/Ramnit.H virus (cleaned - quarantined) 00000000000000000000000000000000 C

D:\System Volume Information\_restore{F7149EC7-4FA5-4148-81FA-2F7A6348FD9A}\RP5\A0002255.dll Win32/Ramnit.H virus (cleaned - quarantined) 00000000000000000000000000000000 C

D:\System Volume Information\_restore{F7149EC7-4FA5-4148-81FA-2F7A6348FD9A}\RP5\A0002256.dll Win32/Ramnit.H virus (cleaned - quarantined) 00000000000000000000000000000000 C

D:\System Volume Information\_restore{F7149EC7-4FA5-4148-81FA-2F7A6348FD9A}\RP5\A0002257.exe Win32/Ramnit.H virus (cleaned - quarantined) 00000000000000000000000000000000 C

D:\System Volume Information\_restore{F7149EC7-4FA5-4148-81FA-2F7A6348FD9A}\RP5\A0002258.exe Win32/Ramnit.H virus (cleaned - quarantined) 00000000000000000000000000000000 C

D:\System Volume Information\_restore{F7149EC7-4FA5-4148-81FA-2F7A6348FD9A}\RP5\A0002259.exe Win32/Ramnit.H virus (cleaned - quarantined) 00000000000000000000000000000000 C

D:\System Volume Information\_restore{F7149EC7-4FA5-4148-81FA-2F7A6348FD9A}\RP5\A0002260.exe Win32/Ramnit.H virus (cleaned - quarantined) 00000000000000000000000000000000 C

D:\System Volume Information\_restore{F7149EC7-4FA5-4148-81FA-2F7A6348FD9A}\RP5\A0002261.exe Win32/Ramnit.H virus (cleaned - quarantined) 00000000000000000000000000000000 C

D:\System Volume Information\_restore{F7149EC7-4FA5-4148-81FA-2F7A6348FD9A}\RP5\A0002262.exe a variant of Win32/Kryptik.MNM trojan (cleaned by deleting - quarantined) 00000000000000000000000000000000 C

D:\System Volume Information\_restore{F7149EC7-4FA5-4148-81FA-2F7A6348FD9A}\RP5\A0002263.exe a variant of Win32/Kryptik.MNM trojan (cleaned by deleting - quarantined) 00000000000000000000000000000000 C

D:\System Volume Information\_restore{F7149EC7-4FA5-4148-81FA-2F7A6348FD9A}\RP5\A0002264.exe a variant of Win32/Kryptik.MNM trojan (cleaned by deleting - quarantined) 00000000000000000000000000000000 C

D:\System Volume Information\_restore{F7149EC7-4FA5-4148-81FA-2F7A6348FD9A}\RP5\A0002265.exe a variant of Win32/Kryptik.MNM trojan (cleaned by deleting - quarantined) 00000000000000000000000000000000 C

D:\System Volume Information\_restore{F7149EC7-4FA5-4148-81FA-2F7A6348FD9A}\RP5\A0002266.exe a variant of Win32/Kryptik.MNM trojan (cleaned by deleting - quarantined) 00000000000000000000000000000000 C

D:\System Volume Information\_restore{F7149EC7-4FA5-4148-81FA-2F7A6348FD9A}\RP5\A0002267.dll Win32/Ramnit.H virus (cleaned - quarantined) 00000000000000000000000000000000 C

D:\System Volume Information\_restore{F7149EC7-4FA5-4148-81FA-2F7A6348FD9A}\RP5\A0002268.dll Win32/Ramnit.H virus (cleaned - quarantined) 00000000000000000000000000000000 C

D:\System Volume Information\_restore{F7149EC7-4FA5-4148-81FA-2F7A6348FD9A}\RP5\A0002269.dll Win32/Ramnit.H virus (cleaned - quarantined) 00000000000000000000000000000000 C

D:\System Volume Information\_restore{F7149EC7-4FA5-4148-81FA-2F7A6348FD9A}\RP5\A0002270.dll Win32/Ramnit.H virus (cleaned - quarantined) 00000000000000000000000000000000 C

D:\System Volume Information\_restore{F7149EC7-4FA5-4148-81FA-2F7A6348FD9A}\RP5\A0002271.dll Win32/Ramnit.H virus (cleaned - quarantined) 00000000000000000000000000000000 C

D:\System Volume Information\_restore{F7149EC7-4FA5-4148-81FA-2F7A6348FD9A}\RP5\A0002272.exe Win32/Ramnit.H virus (cleaned - quarantined) 00000000000000000000000000000000 C

D:\System Volume Information\_restore{F7149EC7-4FA5-4148-81FA-2F7A6348FD9A}\RP5\A0002273.exe Win32/Ramnit.H virus (cleaned - quarantined) 00000000000000000000000000000000 C

D:\System Volume Information\_restore{F7149EC7-4FA5-4148-81FA-2F7A6348FD9A}\RP5\A0002274.exe Win32/Ramnit.H virus (cleaned - quarantined) 00000000000000000000000000000000 C

D:\System Volume Information\_restore{F7149EC7-4FA5-4148-81FA-2F7A6348FD9A}\RP5\A0002275.exe Win32/Ramnit.H virus (cleaned - quarantined) 00000000000000000000000000000000 C

D:\System Volume Information\_restore{F7149EC7-4FA5-4148-81FA-2F7A6348FD9A}\RP5\A0002276.dll Win32/Ramnit.H virus (cleaned - quarantined) 00000000000000000000000000000000 C

D:\System Volume Information\_restore{F7149EC7-4FA5-4148-81FA-2F7A6348FD9A}\RP5\A0002277.dll Win32/Ramnit.H virus (cleaned - quarantined) 00000000000000000000000000000000 C

D:\System Volume Information\_restore{F7149EC7-4FA5-4148-81FA-2F7A6348FD9A}\RP5\A0002278.dll Win32/Ramnit.H virus (cleaned - quarantined) 00000000000000000000000000000000 C

D:\System Volume Information\_restore{F7149EC7-4FA5-4148-81FA-2F7A6348FD9A}\RP5\A0002279.exe Win32/Ramnit.H virus (cleaned - quarantined) 00000000000000000000000000000000 C

D:\System Volume Information\_restore{F7149EC7-4FA5-4148-81FA-2F7A6348FD9A}\RP5\A0002280.dll Win32/Ramnit.H virus (cleaned - quarantined) 00000000000000000000000000000000 C

D:\System Volume Information\_restore{F7149EC7-4FA5-4148-81FA-2F7A6348FD9A}\RP5\A0002281.dll Win32/Ramnit.H virus (cleaned - quarantined) 00000000000000000000000000000000 C

D:\System Volume Information\_restore{F7149EC7-4FA5-4148-81FA-2F7A6348FD9A}\RP5\A0002282.dll Win32/Ramnit.H virus (cleaned - quarantined) 00000000000000000000000000000000 C

D:\System Volume Information\_restore{F7149EC7-4FA5-4148-81FA-2F7A6348FD9A}\RP5\A0002283.exe Win32/Ramnit.H virus (cleaned - quarantined) 00000000000000000000000000000000 C

D:\System Volume Information\_restore{F7149EC7-4FA5-4148-81FA-2F7A6348FD9A}\RP5\A0002284.exe Win32/Ramnit.H virus (cleaned - quarantined) 00000000000000000000000000000000 C

D:\System Volume Information\_restore{F7149EC7-4FA5-4148-81FA-2F7A6348FD9A}\RP5\A0002285.exe Win32/Ramnit.H virus (cleaned - quarantined) 00000000000000000000000000000000 C

D:\System Volume Information\_restore{F7149EC7-4FA5-4148-81FA-2F7A6348FD9A}\RP5\A0002286.exe Win32/Ramnit.H virus (cleaned - quarantined) 00000000000000000000000000000000 C

D:\System Volume Information\_restore{F7149EC7-4FA5-4148-81FA-2F7A6348FD9A}\RP5\A0002287.exe Win32/Ramnit.H virus (cleaned - quarantined) 00000000000000000000000000000000 C

D:\System Volume Information\_restore{F7149EC7-4FA5-4148-81FA-2F7A6348FD9A}\RP5\A0002288.exe Win32/Ramnit.H virus (cleaned - quarantined) 00000000000000000000000000000000 C

D:\System Volume Information\_restore{F7149EC7-4FA5-4148-81FA-2F7A6348FD9A}\RP5\A0002289.exe Win32/Ramnit.H virus (cleaned - quarantined) 00000000000000000000000000000000 C

D:\System Volume Information\_restore{F7149EC7-4FA5-4148-81FA-2F7A6348FD9A}\RP5\A0002290.exe Win32/Ramnit.H virus (cleaned - quarantined) 00000000000000000000000000000000 C

D:\System Volume Information\_restore{F7149EC7-4FA5-4148-81FA-2F7A6348FD9A}\RP5\A0002291.exe Win32/Ramnit.H virus (cleaned - quarantined) 00000000000000000000000000000000 C

D:\System Volume Information\_restore{F7149EC7-4FA5-4148-81FA-2F7A6348FD9A}\RP5\A0002292.exe Win32/Ramnit.H virus (cleaned - quarantined) 00000000000000000000000000000000 C

D:\System Volume Information\_restore{F7149EC7-4FA5-4148-81FA-2F7A6348FD9A}\RP5\A0002293.exe Win32/Ramnit.H virus (cleaned - quarantined) 00000000000000000000000000000000 C

D:\System Volume Information\_restore{F7149EC7-4FA5-4148-81FA-2F7A6348FD9A}\RP5\A0002294.exe Win32/Ramnit.H virus (cleaned - quarantined) 00000000000000000000000000000000 C

D:\System Volume Information\_restore{F7149EC7-4FA5-4148-81FA-2F7A6348FD9A}\RP5\A0002295.exe Win32/Ramnit.H virus (cleaned - quarantined) 00000000000000000000000000000000 C

D:\System Volume Information\_restore{F7149EC7-4FA5-4148-81FA-2F7A6348FD9A}\RP5\A0002296.exe Win32/Ramnit.H virus (cleaned - quarantined) 00000000000000000000000000000000 C

D:\System Volume Information\_restore{F7149EC7-4FA5-4148-81FA-2F7A6348FD9A}\RP5\A0002297.exe Win32/Ramnit.H virus (cleaned - quarantined) 00000000000000000000000000000000 C

D:\System Volume Information\_restore{F7149EC7-4FA5-4148-81FA-2F7A6348FD9A}\RP5\A0002298.exe Win32/Ramnit.H virus (cleaned - quarantined) 00000000000000000000000000000000 C

D:\System Volume Information\_restore{F7149EC7-4FA5-4148-81FA-2F7A6348FD9A}\RP5\A0002299.exe Win32/Ramnit.H virus (cleaned - quarantined) 00000000000000000000000000000000 C

D:\System Volume Information\_restore{F7149EC7-4FA5-4148-81FA-2F7A6348FD9A}\RP5\A0002300.exe Win32/Ramnit.H virus (cleaned - quarantined) 00000000000000000000000000000000 C

D:\System Volume Information\_restore{F7149EC7-4FA5-4148-81FA-2F7A6348FD9A}\RP5\A0002301.exe Win32/Ramnit.H virus (cleaned - quarantined) 00000000000000000000000000000000 C

D:\System Volume Information\_restore{F7149EC7-4FA5-4148-81FA-2F7A6348FD9A}\RP5\A0002302.exe Win32/Ramnit.H virus (cleaned - quarantined) 00000000000000000000000000000000 C

D:\System Volume Information\_restore{F7149EC7-4FA5-4148-81FA-2F7A6348FD9A}\RP5\A0002303.exe Win32/Ramnit.H virus (cleaned - quarantined) 00000000000000000000000000000000 C

D:\System Volume Information\_restore{F7149EC7-4FA5-4148-81FA-2F7A6348FD9A}\RP5\A0002304.exe Win32/Ramnit.H virus (cleaned - quarantined) 00000000000000000000000000000000 C

D:\System Volume Information\_restore{F7149EC7-4FA5-4148-81FA-2F7A6348FD9A}\RP5\A0002305.exe Win32/Ramnit.H virus (cleaned - quarantined) 00000000000000000000000000000000 C

D:\System Volume Information\_restore{F7149EC7-4FA5-4148-81FA-2F7A6348FD9A}\RP5\A0002306.exe Win32/Ramnit.H virus (cleaned - quarantined) 00000000000000000000000000000000 C

D:\System Volume Information\_restore{F7149EC7-4FA5-4148-81FA-2F7A6348FD9A}\RP5\A0002307.dll Win32/Ramnit.H virus (cleaned - quarantined) 00000000000000000000000000000000 C

D:\System Volume Information\_restore{F7149EC7-4FA5-4148-81FA-2F7A6348FD9A}\RP5\A0002308.dll Win32/Ramnit.H virus (cleaned - quarantined) 00000000000000000000000000000000 C

D:\System Volume Information\_restore{F7149EC7-4FA5-4148-81FA-2F7A6348FD9A}\RP5\A0002309.dll Win32/Ramnit.H virus (cleaned - quarantined) 00000000000000000000000000000000 C

D:\System Volume Information\_restore{F7149EC7-4FA5-4148-81FA-2F7A6348FD9A}\RP5\A0002310.dll Win32/Ramnit.H virus (cleaned - quarantined) 00000000000000000000000000000000 C

D:\System Volume Information\_restore{F7149EC7-4FA5-4148-81FA-2F7A6348FD9A}\RP5\A0002311.exe Win32/Ramnit.H virus (cleaned - quarantined) 00000000000000000000000000000000 C

D:\System Volume Information\_restore{F7149EC7-4FA5-4148-81FA-2F7A6348FD9A}\RP5\A0002312.exe Win32/Ramnit.H virus (cleaned - quarantined) 00000000000000000000000000000000 C

D:\System Volume Information\_restore{F7149EC7-4FA5-4148-81FA-2F7A6348FD9A}\RP5\A0002313.exe Win32/Ramnit.H virus (cleaned - quarantined) 00000000000000000000000000000000 C

D:\System Volume Information\_restore{F7149EC7-4FA5-4148-81FA-2F7A6348FD9A}\RP5\A0002314.exe Win32/Ramnit.H virus (cleaned - quarantined) 00000000000000000000000000000000 C

D:\System Volume Information\_restore{F7149EC7-4FA5-4148-81FA-2F7A6348FD9A}\RP5\A0002315.exe Win32/Ramnit.H virus (cleaned - quarantined) 00000000000000000000000000000000 C

D:\System Volume Information\_restore{F7149EC7-4FA5-4148-81FA-2F7A6348FD9A}\RP5\A0002316.exe Win32/Ramnit.H virus (cleaned - quarantined) 00000000000000000000000000000000 C

D:\System Volume Information\_restore{F7149EC7-4FA5-4148-81FA-2F7A6348FD9A}\RP5\A0002317.exe Win32/Ramnit.H virus (cleaned - quarantined) 00000000000000000000000000000000 C

D:\System Volume Information\_restore{F7149EC7-4FA5-4148-81FA-2F7A6348FD9A}\RP5\A0002318.exe Win32/Ramnit.H virus (cleaned - quarantined) 00000000000000000000000000000000 C

D:\System Volume Information\_restore{F7149EC7-4FA5-4148-81FA-2F7A6348FD9A}\RP5\A0002319.dll Win32/Ramnit.H virus (cleaned - quarantined) 00000000000000000000000000000000 C

D:\System Volume Information\_restore{F7149EC7-4FA5-4148-81FA-2F7A6348FD9A}\RP5\A0002320.exe Win32/Ramnit.H virus (cleaned - quarantined) 00000000000000000000000000000000 C

D:\System Volume Information\_restore{F7149EC7-4FA5-4148-81FA-2F7A6348FD9A}\RP5\A0002321.exe Win32/Ramnit.H virus (cleaned - quarantined) 00000000000000000000000000000000 C

D:\System Volume Information\_restore{F7149EC7-4FA5-4148-81FA-2F7A6348FD9A}\RP5\A0002322.exe Win32/Ramnit.H virus (cleaned - quarantined) 00000000000000000000000000000000 C

D:\System Volume Information\_restore{F7149EC7-4FA5-4148-81FA-2F7A6348FD9A}\RP5\A0002323.exe Win32/Ramnit.H virus (cleaned - quarantined) 00000000000000000000000000000000 C

D:\System Volume Information\_restore{F7149EC7-4FA5-4148-81FA-2F7A6348FD9A}\RP5\A0002324.EXE Win32/Ramnit.H virus (cleaned - quarantined) 00000000000000000000000000000000 C

D:\System Volume Information\_restore{F7149EC7-4FA5-4148-81FA-2F7A6348FD9A}\RP5\A0002325.EXE Win32/Ramnit.H virus (cleaned - quarantined) 00000000000000000000000000000000 C

D:\System Volume Information\_restore{F7149EC7-4FA5-4148-81FA-2F7A6348FD9A}\RP5\A0002326.EXE Win32/Ramnit.H virus (cleaned - quarantined) 00000000000000000000000000000000 C

D:\System Volume Information\_restore{F7149EC7-4FA5-4148-81FA-2F7A6348FD9A}\RP5\A0002328.exe Win32/Ramnit.H virus (cleaned - quarantined) 00000000000000000000000000000000 C

D:\System Volume Information\_restore{F7149EC7-4FA5-4148-81FA-2F7A6348FD9A}\RP5\A0002329.exe Win32/Ramnit.H virus (cleaned - quarantined) 00000000000000000000000000000000 C

D:\System Volume Information\_restore{F7149EC7-4FA5-4148-81FA-2F7A6348FD9A}\RP5\A0002330.dll Win32/Ramnit.H virus (cleaned - quarantined) 00000000000000000000000000000000 C

D:\System Volume Information\_restore{F7149EC7-4FA5-4148-81FA-2F7A6348FD9A}\RP5\A0002331.exe Win32/Ramnit.H virus (cleaned - quarantined) 00000000000000000000000000000000 C

D:\System Volume Information\_restore{F7149EC7-4FA5-4148-81FA-2F7A6348FD9A}\RP5\A0002332.exe Win32/Ramnit.H virus (cleaned - quarantined) 00000000000000000000000000000000 C

D:\System Volume Information\_restore{F7149EC7-4FA5-4148-81FA-2F7A6348FD9A}\RP5\A0002333.EXE Win32/Ramnit.H virus (cleaned - quarantined) 00000000000000000000000000000000 C

D:\System Volume Information\_restore{F7149EC7-4FA5-4148-81FA-2F7A6348FD9A}\RP5\A0002334.EXE Win32/Ramnit.H virus (cleaned - quarantined) 00000000000000000000000000000000 C

D:\System Volume Information\_restore{F7149EC7-4FA5-4148-81FA-2F7A6348FD9A}\RP5\A0002335.EXE Win32/Ramnit.H virus (cleaned - quarantined) 00000000000000000000000000000000 C

D:\System Volume Information\_restore{F7149EC7-4FA5-4148-81FA-2F7A6348FD9A}\RP5\A0002336.DLL Win32/Ramnit.H virus (cleaned - quarantined) 00000000000000000000000000000000 C

D:\System Volume Information\_restore{F7149EC7-4FA5-4148-81FA-2F7A6348FD9A}\RP5\A0002337.DLL Win32/Ramnit.H virus (cleaned - quarantined) 00000000000000000000000000000000 C

D:\System Volume Information\_restore{F7149EC7-4FA5-4148-81FA-2F7A6348FD9A}\RP5\A0002338.DLL Win32/Ramnit.H virus (cleaned - quarantined) 00000000000000000000000000000000 C

D:\System Volume Information\_restore{F7149EC7-4FA5-4148-81FA-2F7A6348FD9A}\RP5\A0002339.EXE Win32/Ramnit.H virus (cleaned - quarantined) 00000000000000000000000000000000 C

D:\System Volume Information\_restore{F7149EC7-4FA5-4148-81FA-2F7A6348FD9A}\RP5\A0002340.EXE Win32/Ramnit.H virus (cleaned - quarantined) 00000000000000000000000000000000 C

D:\System Volume Information\_restore{F7149EC7-4FA5-4148-81FA-2F7A6348FD9A}\RP5\A0002341.DLL Win32/Ramnit.H virus (cleaned - quarantined) 00000000000000000000000000000000 C

D:\System Volume Information\_restore{F7149EC7-4FA5-4148-81FA-2F7A6348FD9A}\RP5\A0002342.DLL Win32/Ramnit.H virus (cleaned - quarantined) 00000000000000000000000000000000 C

D:\System Volume Information\_restore{F7149EC7-4FA5-4148-81FA-2F7A6348FD9A}\RP5\A0002343.DLL Win32/Ramnit.H virus (cleaned - quarantined) 00000000000000000000000000000000 C

D:\System Volume Information\_restore{F7149EC7-4FA5-4148-81FA-2F7A6348FD9A}\RP5\A0002344.DLL Win32/Ramnit.H virus (cleaned - quarantined) 00000000000000000000000000000000 C

D:\System Volume Information\_restore{F7149EC7-4FA5-4148-81FA-2F7A6348FD9A}\RP5\A0002345.DLL Win32/Ramnit.H virus (cleaned - quarantined) 00000000000000000000000000000000 C

D:\System Volume Information\_restore{F7149EC7-4FA5-4148-81FA-2F7A6348FD9A}\RP5\A0002346.DLL Win32/Ramnit.H virus (cleaned - quarantined) 00000000000000000000000000000000 C

D:\System Volume Information\_restore{F7149EC7-4FA5-4148-81FA-2F7A6348FD9A}\RP5\A0002347.DLL Win32/Ramnit.H virus (cleaned - quarantined) 00000000000000000000000000000000 C

D:\System Volume Information\_restore{F7149EC7-4FA5-4148-81FA-2F7A6348FD9A}\RP5\A0002348.DLL Win32/Ramnit.H virus (cleaned - quarantined) 00000000000000000000000000000000 C

D:\System Volume Information\_restore{F7149EC7-4FA5-4148-81FA-2F7A6348FD9A}\RP5\A0002349.EXE Win32/Ramnit.H virus (cleaned - quarantined) 00000000000000000000000000000000 C

D:\System Volume Information\_restore{F7149EC7-4FA5-4148-81FA-2F7A6348FD9A}\RP5\A0002350.DLL Win32/Ramnit.H virus (cleaned - quarantined) 00000000000000000000000000000000 C

D:\System Volume Information\_restore{F7149EC7-4FA5-4148-81FA-2F7A6348FD9A}\RP5\A0002351.DLL Win32/Ramnit.H virus (cleaned - quarantined) 00000000000000000000000000000000 C

D:\System Volume Information\_restore{F7149EC7-4FA5-4148-81FA-2F7A6348FD9A}\RP5\A0002352.DLL Win32/Ramnit.H virus (cleaned - quarantined) 00000000000000000000000000000000 C

D:\System Volume Information\_restore{F7149EC7-4FA5-4148-81FA-2F7A6348FD9A}\RP5\A0002353.exe Win32/Ramnit.H virus (cleaned - quarantined) 00000000000000000000000000000000 C

D:\System Volume Information\_restore{F7149EC7-4FA5-4148-81FA-2F7A6348FD9A}\RP5\A0002354.Exe Win32/Ramnit.H virus (cleaned - quarantined) 00000000000000000000000000000000 C

D:\System Volume Information\_restore{F7149EC7-4FA5-4148-81FA-2F7A6348FD9A}\RP5\A0002355.exe Win32/Ramnit.H virus (cleaned - quarantined) 00000000000000000000000000000000 C

D:\System Volume Information\_restore{F7149EC7-4FA5-4148-81FA-2F7A6348FD9A}\RP5\A0002356.exe Win32/Ramnit.H virus (cleaned - quarantined) 00000000000000000000000000000000 C

D:\System Volume Information\_restore{F7149EC7-4FA5-4148-81FA-2F7A6348FD9A}\RP5\A0002357.exe Win32/Ramnit.H virus (cleaned - quarantined) 00000000000000000000000000000000 C

D:\System Volume Information\_restore{F7149EC7-4FA5-4148-81FA-2F7A6348FD9A}\RP5\A0002358.exe Win32/Ramnit.H virus (cleaned - quarantined) 00000000000000000000000000000000 C

D:\System Volume Information\_restore{F7149EC7-4FA5-4148-81FA-2F7A6348FD9A}\RP5\A0002359.exe Win32/Ramnit.H virus (cleaned - quarantined) 00000000000000000000000000000000 C

D:\System Volume Information\_restore{F7149EC7-4FA5-4148-81FA-2F7A6348FD9A}\RP5\A0002360.exe Win32/Ramnit.H virus (cleaned - quarantined) 00000000000000000000000000000000 C

D:\System Volume Information\_restore{F7149EC7-4FA5-4148-81FA-2F7A6348FD9A}\RP5\A0002361.exe Win32/Ramnit.H virus (cleaned - quarantined) 00000000000000000000000000000000 C

D:\System Volume Information\_restore{F7149EC7-4FA5-4148-81FA-2F7A6348FD9A}\RP5\A0002362.exe Win32/Ramnit.H virus (cleaned - quarantined) 00000000000000000000000000000000 C

D:\System Volume Information\_restore{F7149EC7-4FA5-4148-81FA-2F7A6348FD9A}\RP5\A0002363.dll Win32/Ramnit.H virus (cleaned - quarantined) 00000000000000000000000000000000 C

D:\System Volume Information\_restore{F7149EC7-4FA5-4148-81FA-2F7A6348FD9A}\RP5\A0002364.dll Win32/Ramnit.H virus (cleaned - quarantined) 00000000000000000000000000000000 C

D:\System Volume Information\_restore{F7149EC7-4FA5-4148-81FA-2F7A6348FD9A}\RP5\A0002365.dll Win32/Ramnit.H virus (cleaned - quarantined) 00000000000000000000000000000000 C

D:\System Volume Information\_restore{F7149EC7-4FA5-4148-81FA-2F7A6348FD9A}\RP5\A0002366.dll Win32/Ramnit.H virus (cleaned - quarantined) 00000000000000000000000000000000 C

D:\System Volume Information\_restore{F7149EC7-4FA5-4148-81FA-2F7A6348FD9A}\RP5\A0002367.dll Win32/Ramnit.H virus (cleaned - quarantined) 00000000000000000000000000000000 C

D:\System Volume Information\_restore{F7149EC7-4FA5-4148-81FA-2F7A6348FD9A}\RP5\A0002368.dll Win32/Ramnit.H virus (cleaned - quarantined) 00000000000000000000000000000000 C

D:\System Volume Information\_restore{F7149EC7-4FA5-4148-81FA-2F7A6348FD9A}\RP5\A0002369.dll Win32/Ramnit.H virus (cleaned - quarantined) 00000000000000000000000000000000 C

D:\System Volume Information\_restore{F7149EC7-4FA5-4148-81FA-2F7A6348FD9A}\RP5\A0002370.dll Win32/Ramnit.H virus (cleaned - quarantined) 00000000000000000000000000000000 C

D:\System Volume Information\_restore{F7149EC7-4FA5-4148-81FA-2F7A6348FD9A}\RP5\A0002371.dll Win32/Ramnit.H virus (cleaned - quarantined) 00000000000000000000000000000000 C

D:\System Volume Information\_restore{F7149EC7-4FA5-4148-81FA-2F7A6348FD9A}\RP5\A0002372.dll Win32/Ramnit.H virus (cleaned - quarantined) 00000000000000000000000000000000 C

D:\System Volume Information\_restore{F7149EC7-4FA5-4148-81FA-2F7A6348FD9A}\RP5\A0002373.dll Win32/Ramnit.H virus (cleaned - quarantined) 00000000000000000000000000000000 C

D:\System Volume Information\_restore{F7149EC7-4FA5-4148-81FA-2F7A6348FD9A}\RP5\A0002374.dll Win32/Ramnit.H virus (cleaned - quarantined) 00000000000000000000000000000000 C

D:\System Volume Information\_restore{F7149EC7-4FA5-4148-81FA-2F7A6348FD9A}\RP5\A0002375.dll Win32/Ramnit.H virus (cleaned - quarantined) 00000000000000000000000000000000 C

D:\System Volume Information\_restore{F7149EC7-4FA5-4148-81FA-2F7A6348FD9A}\RP5\A0002376.dll Win32/Ramnit.H virus (cleaned - quarantined) 00000000000000000000000000000000 C

D:\System Volume Information\_restore{F7149EC7-4FA5-4148-81FA-2F7A6348FD9A}\RP5\A0002377.dll Win32/Ramnit.H virus (cleaned - quarantined) 00000000000000000000000000000000 C

D:\System Volume Information\_restore{F7149EC7-4FA5-4148-81FA-2F7A6348FD9A}\RP5\A0002378.dll Win32/Ramnit.H virus (cleaned - quarantined) 00000000000000000000000000000000 C

D:\System Volume Information\_restore{F7149EC7-4FA5-4148-81FA-2F7A6348FD9A}\RP5\A0002379.dll Win32/Ramnit.H virus (cleaned - quarantined) 00000000000000000000000000000000 C

D:\System Volume Information\_restore{F7149EC7-4FA5-4148-81FA-2F7A6348FD9A}\RP5\A0002380.dll Win32/Ramnit.H virus (cleaned - quarantined) 00000000000000000000000000000000 C

D:\System Volume Information\_restore{F7149EC7-4FA5-4148-81FA-2F7A6348FD9A}\RP5\A0002381.dll Win32/Ramnit.H virus (cleaned - quarantined) 00000000000000000000000000000000 C

D:\System Volume Information\_restore{F7149EC7-4FA5-4148-81FA-2F7A6348FD9A}\RP5\A0002382.dll Win32/Ramnit.H virus (cleaned - quarantined) 00000000000000000000000000000000 C

D:\System Volume Information\_restore{F7149EC7-4FA5-4148-81FA-2F7A6348FD9A}\RP5\A0002383.dll Win32/Ramnit.H virus (cleaned - quarantined) 00000000000000000000000000000000 C

D:\System Volume Information\_restore{F7149EC7-4FA5-4148-81FA-2F7A6348FD9A}\RP5\A0002384.dll Win32/Ramnit.H virus (cleaned - quarantined) 00000000000000000000000000000000 C

D:\System Volume Information\_restore{F7149EC7-4FA5-4148-81FA-2F7A6348FD9A}\RP5\A0002385.dll Win32/Ramnit.H virus (cleaned - quarantined) 00000000000000000000000000000000 C

D:\System Volume Information\_restore{F7149EC7-4FA5-4148-81FA-2F7A6348FD9A}\RP5\A0002386.dll Win32/Ramnit.H virus (cleaned - quarantined) 00000000000000000000000000000000 C

D:\System Volume Information\_restore{F7149EC7-4FA5-4148-81FA-2F7A6348FD9A}\RP5\A0002387.dll Win32/Ramnit.H virus (cleaned - quarantined) 00000000000000000000000000000000 C

D:\System Volume Information\_restore{F7149EC7-4FA5-4148-81FA-2F7A6348FD9A}\RP5\A0002388.dll Win32/Ramnit.H virus (cleaned - quarantined) 00000000000000000000000000000000 C

D:\System Volume Information\_restore{F7149EC7-4FA5-4148-81FA-2F7A6348FD9A}\RP5\A0002389.dll Win32/Ramnit.H virus (cleaned - quarantined) 00000000000000000000000000000000 C

D:\System Volume Information\_restore{F7149EC7-4FA5-4148-81FA-2F7A6348FD9A}\RP5\A0002390.dll Win32/Ramnit.H virus (cleaned - quarantined) 00000000000000000000000000000000 C

D:\System Volume Information\_restore{F7149EC7-4FA5-4148-81FA-2F7A6348FD9A}\RP5\A0002391.dll Win32/Ramnit.H virus (cleaned - quarantined) 00000000000000000000000000000000 C

D:\System Volume Information\_restore{F7149EC7-4FA5-4148-81FA-2F7A6348FD9A}\RP5\A0002392.dll Win32/Ramnit.H virus (cleaned - quarantined) 00000000000000000000000000000000 C

D:\System Volume Information\_restore{F7149EC7-4FA5-4148-81FA-2F7A6348FD9A}\RP5\A0002393.exe Win32/Ramnit.H virus (cleaned - quarantined) 00000000000000000000000000000000 C

D:\System Volume Information\_restore{F7149EC7-4FA5-4148-81FA-2F7A6348FD9A}\RP5\A0002394.exe Win32/Ramnit.H virus (cleaned - quarantined) 00000000000000000000000000000000 C

D:\System Volume Information\_restore{F7149EC7-4FA5-4148-81FA-2F7A6348FD9A}\RP5\A0002395.EXE Win32/Ramnit.H virus (cleaned - quarantined) 00000000000000000000000000000000 C

D:\System Volume Information\_restore{F7149EC7-4FA5-4148-81FA-2F7A6348FD9A}\RP5\A0002396.EXE Win32/Ramnit.H virus (cleaned - quarantined) 00000000000000000000000000000000 C

D:\System Volume Information\_restore{F7149EC7-4FA5-4148-81FA-2F7A6348FD9A}\RP5\A0002397.EXE Win32/Ramnit.H virus (cleaned - quarantined) 00000000000000000000000000000000 C

D:\System Volume Information\_restore{F7149EC7-4FA5-4148-81FA-2F7A6348FD9A}\RP5\A0002398.DLL Win32/Ramnit.H virus (cleaned - quarantined) 00000000000000000000000000000000 C

D:\System Volume Information\_restore{F7149EC7-4FA5-4148-81FA-2F7A6348FD9A}\RP5\A0002399.DLL Win32/Ramnit.H virus (cleaned - quarantined) 00000000000000000000000000000000 C

D:\System Volume Information\_restore{F7149EC7-4FA5-4148-81FA-2F7A6348FD9A}\RP5\A0002400.DLL Win32/Ramnit.H virus (cleaned - quarantined) 00000000000000000000000000000000 C

D:\System Volume Information\_restore{F7149EC7-4FA5-4148-81FA-2F7A6348FD9A}\RP5\A0002401.EXE Win32/Ramnit.H virus (cleaned - quarantined) 00000000000000000000000000000000 C

D:\System Volume Information\_restore{F7149EC7-4FA5-4148-81FA-2F7A6348FD9A}\RP5\A0002402.DLL Win32/Ramnit.H virus (cleaned - quarantined) 00000000000000000000000000000000 C

D:\System Volume Information\_restore{F7149EC7-4FA5-4148-81FA-2F7A6348FD9A}\RP5\A0002403.DLL Win32/Ramnit.H virus (cleaned - quarantined) 00000000000000000000000000000000 C

D:\System Volume Information\_restore{F7149EC7-4FA5-4148-81FA-2F7A6348FD9A}\RP5\A0002404.DLL Win32/Ramnit.H virus (cleaned - quarantined) 00000000000000000000000000000000 C

D:\System Volume Information\_restore{F7149EC7-4FA5-4148-81FA-2F7A6348FD9A}\RP5\A0002405.DLL Win32/Ramnit.H virus (cleaned - quarantined) 00000000000000000000000000000000 C

D:\System Volume Information\_restore{F7149EC7-4FA5-4148-81FA-2F7A6348FD9A}\RP5\A0002406.DLL Win32/Ramnit.H virus (cleaned - quarantined) 00000000000000000000000000000000 C

D:\System Volume Information\_restore{F7149EC7-4FA5-4148-81FA-2F7A6348FD9A}\RP5\A0002407.DLL Win32/Ramnit.H virus (cleaned - quarantined) 00000000000000000000000000000000 C

D:\System Volume Information\_restore{F7149EC7-4FA5-4148-81FA-2F7A6348FD9A}\RP5\A0002408.DLL Win32/Ramnit.H virus (cleaned - quarantined) 00000000000000000000000000000000 C

D:\System Volume Information\_restore{F7149EC7-4FA5-4148-81FA-2F7A6348FD9A}\RP5\A0002409.DLL Win32/Ramnit.H virus (cleaned - quarantined) 00000000000000000000000000000000 C

D:\System Volume Information\_restore{F7149EC7-4FA5-4148-81FA-2F7A6348FD9A}\RP5\A0002410.DLL Win32/Ramnit.H virus (cleaned - quarantined) 00000000000000000000000000000000 C

D:\System Volume Information\_restore{F7149EC7-4FA5-4148-81FA-2F7A6348FD9A}\RP5\A0002411.DLL Win32/Ramnit.H virus (cleaned - quarantined) 00000000000000000000000000000000 C

D:\System Volume Information\_restore{F7149EC7-4FA5-4148-81FA-2F7A6348FD9A}\RP5\A0002412.DLL Win32/Ramnit.H virus (cleaned - quarantined) 00000000000000000000000000000000 C

D:\System Volume Information\_restore{F7149EC7-4FA5-4148-81FA-2F7A6348FD9A}\RP5\A0002413.DLL Win32/Ramnit.H virus (cleaned - quarantined) 00000000000000000000000000000000 C

D:\System Volume Information\_restore{F7149EC7-4FA5-4148-81FA-2F7A6348FD9A}\RP5\A0002414.DLL Win32/Ramnit.H virus (cleaned - quarantined) 00000000000000000000000000000000 C

D:\System Volume Information\_restore{F7149EC7-4FA5-4148-81FA-2F7A6348FD9A}\RP5\A0002415.DLL Win32/Ramnit.H virus (cleaned - quarantined) 00000000000000000000000000000000 C

D:\System Volume Information\_restore{F7149EC7-4FA5-4148-81FA-2F7A6348FD9A}\RP5\A0002416.DLL Win32/Ramnit.H virus (cleaned - quarantined) 00000000000000000000000000000000 C

D:\System Volume Information\_restore{F7149EC7-4FA5-4148-81FA-2F7A6348FD9A}\RP5\A0002417.DLL Win32/Ramnit.H virus (cleaned - quarantined) 00000000000000000000000000000000 C

D:\System Volume Information\_restore{F7149EC7-4FA5-4148-81FA-2F7A6348FD9A}\RP5\A0002418.DLL Win32/Ramnit.H virus (cleaned - quarantined) 00000000000000000000000000000000 C

D:\System Volume Information\_restore{F7149EC7-4FA5-4148-81FA-2F7A6348FD9A}\RP5\A0002419.DLL Win32/Ramnit.H virus (cleaned - quarantined) 00000000000000000000000000000000 C

D:\System Volume Information\_restore{F7149EC7-4FA5-4148-81FA-2F7A6348FD9A}\RP5\A0002420.DLL Win32/Ramnit.H virus (cleaned - quarantined) 00000000000000000000000000000000 C

D:\System Volume Information\_restore{F7149EC7-4FA5-4148-81FA-2F7A6348FD9A}\RP5\A0002421.DLL Win32/Ramnit.H virus (cleaned - quarantined) 00000000000000000000000000000000 C

D:\System Volume Information\_restore{F7149EC7-4FA5-4148-81FA-2F7A6348FD9A}\RP5\A0002422.DLL Win32/Ramnit.H virus (cleaned - quarantined) 00000000000000000000000000000000 C

D:\System Volume Information\_restore{F7149EC7-4FA5-4148-81FA-2F7A6348FD9A}\RP5\A0002423.DLL Win32/Ramnit.H virus (cleaned - quarantined) 00000000000000000000000000000000 C

D:\System Volume Information\_restore{F7149EC7-4FA5-4148-81FA-2F7A6348FD9A}\RP5\A0002424.DLL Win32/Ramnit.H virus (cleaned - quarantined) 00000000000000000000000000000000 C

D:\System Volume Information\_restore{F7149EC7-4FA5-4148-81FA-2F7A6348FD9A}\RP5\A0002425.EXE Win32/Ramnit.H virus (cleaned - quarantined) 00000000000000000000000000000000 C

D:\System Volume Information\_restore{F7149EC7-4FA5-4148-81FA-2F7A6348FD9A}\RP5\A0002426.DLL Win32/Ramnit.H virus (cleaned - quarantined) 00000000000000000000000000000000 C

D:\System Volume Information\_restore{F7149EC7-4FA5-4148-81FA-2F7A6348FD9A}\RP5\A0002427.DLL Win32/Ramnit.H virus (cleaned - quarantined) 00000000000000000000000000000000 C

D:\System Volume Information\_restore{F7149EC7-4FA5-4148-81FA-2F7A6348FD9A}\RP5\A0002428.DLL Win32/Ramnit.H virus (cleaned - quarantined) 00000000000000000000000000000000 C

D:\System Volume Information\_restore{F7149EC7-4FA5-4148-81FA-2F7A6348FD9A}\RP5\A0002429.DLL Win32/Ramnit.H virus (cleaned - quarantined) 00000000000000000000000000000000 C

D:\System Volume Information\_restore{F7149EC7-4FA5-4148-81FA-2F7A6348FD9A}\RP5\A0002430.DLL Win32/Ramnit.H virus (cleaned - quarantined) 00000000000000000000000000000000 C

D:\System Volume Information\_restore{F7149EC7-4FA5-4148-81FA-2F7A6348FD9A}\RP5\A0002431.EXE Win32/Ramnit.H virus (cleaned - quarantined) 00000000000000000000000000000000 C

D:\System Volume Information\_restore{F7149EC7-4FA5-4148-81FA-2F7A6348FD9A}\RP5\A0002432.DLL Win32/Ramnit.H virus (cleaned - quarantined) 00000000000000000000000000000000 C

D:\System Volume Information\_restore{F7149EC7-4FA5-4148-81FA-2F7A6348FD9A}\RP5\A0002433.DLL Win32/Ramnit.H virus (cleaned - quarantined) 00000000000000000000000000000000 C

D:\System Volume Information\_restore{F7149EC7-4FA5-4148-81FA-2F7A6348FD9A}\RP5\A0002434.DLL Win32/Ramnit.H virus (cleaned - quarantined) 00000000000000000000000000000000 C

D:\System Volume Information\_restore{F7149EC7-4FA5-4148-81FA-2F7A6348FD9A}\RP5\A0002435.DLL Win32/Ramnit.H virus (cleaned - quarantined) 00000000000000000000000000000000 C

D:\System Volume Information\_restore{F7149EC7-4FA5-4148-81FA-2F7A6348FD9A}\RP5\A0002436.DLL Win32/Ramnit.H virus (cleaned - quarantined) 00000000000000000000000000000000 C

D:\System Volume Information\_restore{F7149EC7-4FA5-4148-81FA-2F7A6348FD9A}\RP5\A0002437.DLL Win32/Ramnit.H virus (cleaned - quarantined) 00000000000000000000000000000000 C

D:\System Volume Information\_restore{F7149EC7-4FA5-4148-81FA-2F7A6348FD9A}\RP5\A0002438.DLL Win32/Ramnit.H virus (cleaned - quarantined) 00000000000000000000000000000000 C

D:\System Volume Information\_restore{F7149EC7-4FA5-4148-81FA-2F7A6348FD9A}\RP5\A0002439.DLL Win32/Ramnit.H virus (cleaned - quarantined) 00000000000000000000000000000000 C

D:\System Volume Information\_restore{F7149EC7-4FA5-4148-81FA-2F7A6348FD9A}\RP5\A0002440.DLL Win32/Ramnit.H virus (cleaned - quarantined) 00000000000000000000000000000000 C

D:\System Volume Information\_restore{F7149EC7-4FA5-4148-81FA-2F7A6348FD9A}\RP5\A0002441.DLL Win32/Ramnit.H virus (cleaned - quarantined) 00000000000000000000000000000000 C

D:\System Volume Information\_restore{F7149EC7-4FA5-4148-81FA-2F7A6348FD9A}\RP5\A0002442.DLL Win32/Ramnit.H virus (cleaned - quarantined) 00000000000000000000000000000000 C

D:\System Volume Information\_restore{F7149EC7-4FA5-4148-81FA-2F7A6348FD9A}\RP5\A0002443.DLL Win32/Ramnit.H virus (cleaned - quarantined) 00000000000000000000000000000000 C

D:\System Volume Information\_restore{F7149EC7-4FA5-4148-81FA-2F7A6348FD9A}\RP5\A0002444.DLL Win32/Ramnit.H virus (cleaned - quarantined) 00000000000000000000000000000000 C

D:\System Volume Information\_restore{F7149EC7-4FA5-4148-81FA-2F7A6348FD9A}\RP5\A0002445.DLL Win32/Ramnit.H virus (cleaned - quarantined) 00000000000000000000000000000000 C

D:\System Volume Information\_restore{F7149EC7-4FA5-4148-81FA-2F7A6348FD9A}\RP5\A0002446.DLL Win32/Ramnit.H virus (cleaned - quarantined) 00000000000000000000000000000000 C

D:\System Volume Information\_restore{F7149EC7-4FA5-4148-81FA-2F7A6348FD9A}\RP5\A0002447.DLL Win32/Ramnit.H virus (cleaned - quarantined) 00000000000000000000000000000000 C

D:\System Volume Information\_restore{F7149EC7-4FA5-4148-81FA-2F7A6348FD9A}\RP5\A0002448.DLL Win32/Ramnit.H virus (cleaned - quarantined) 00000000000000000000000000000000 C

D:\System Volume Information\_restore{F7149EC7-4FA5-4148-81FA-2F7A6348FD9A}\RP5\A0002449.DLL Win32/Ramnit.H virus (cleaned - quarantined) 00000000000000000000000000000000 C

D:\System Volume Information\_restore{F7149EC7-4FA5-4148-81FA-2F7A6348FD9A}\RP5\A0002450.DLL Win32/Ramnit.H virus (cleaned - quarantined) 00000000000000000000000000000000 C

D:\System Volume Information\_restore{F7149EC7-4FA5-4148-81FA-2F7A6348FD9A}\RP5\A0002451.DLL Win32/Ramnit.H virus (cleaned - quarantined) 00000000000000000000000000000000 C

D:\System Volume Information\_restore{F7149EC7-4FA5-4148-81FA-2F7A6348FD9A}\RP5\A0002452.DLL Win32/Ramnit.H virus (cleaned - quarantined) 00000000000000000000000000000000 C

D:\System Volume Information\_restore{F7149EC7-4FA5-4148-81FA-2F7A6348FD9A}\RP5\A0002453.DLL Win32/Ramnit.H virus (cleaned - quarantined) 00000000000000000000000000000000 C

D:\System Volume Information\_restore{F7149EC7-4FA5-4148-81FA-2F7A6348FD9A}\RP5\A0002454.DLL Win32/Ramnit.H virus (cleaned - quarantined) 00000000000000000000000000000000 C

D:\System Volume Information\_restore{F7149EC7-4FA5-4148-81FA-2F7A6348FD9A}\RP5\A0002455.DLL Win32/Ramnit.H virus (cleaned - quarantined) 00000000000000000000000000000000 C

D:\System Volume Information\_restore{F7149EC7-4FA5-4148-81FA-2F7A6348FD9A}\RP5\A0002456.DLL Win32/Ramnit.H virus (cleaned - quarantined) 00000000000000000000000000000000 C

D:\System Volume Information\_restore{F7149EC7-4FA5-4148-81FA-2F7A6348FD9A}\RP5\A0002457.DLL Win32/Ramnit.H virus (cleaned - quarantined) 00000000000000000000000000000000 C

D:\System Volume Information\_restore{F7149EC7-4FA5-4148-81FA-2F7A6348FD9A}\RP5\A0002458.DLL Win32/Ramnit.H virus (cleaned - quarantined) 00000000000000000000000000000000 C

D:\System Volume Information\_restore{F7149EC7-4FA5-4148-81FA-2F7A6348FD9A}\RP5\A0002459.DLL Win32/Ramnit.H virus (cleaned - quarantined) 00000000000000000000000000000000 C

D:\System Volume Information\_restore{F7149EC7-4FA5-4148-81FA-2F7A6348FD9A}\RP5\A0002460.DLL Win32/Ramnit.H virus (cleaned - quarantined) 00000000000000000000000000000000 C

D:\System Volume Information\_restore{F7149EC7-4FA5-4148-81FA-2F7A6348FD9A}\RP5\A0002461.DLL Win32/Ramnit.H virus (cleaned - quarantined) 00000000000000000000000000000000 C

D:\System Volume Information\_restore{F7149EC7-4FA5-4148-81FA-2F7A6348FD9A}\RP5\A0002462.EXE Win32/Ramnit.H virus (cleaned - quarantined) 00000000000000000000000000000000 C

D:\System Volume Information\_restore{F7149EC7-4FA5-4148-81FA-2F7A6348FD9A}\RP5\A0002463.DLL Win32/Ramnit.H virus (cleaned - quarantined) 00000000000000000000000000000000 C

D:\System Volume Information\_restore{F7149EC7-4FA5-4148-81FA-2F7A6348FD9A}\RP5\A0002464.DLL Win32/Ramnit.H virus (cleaned - quarantined) 00000000000000000000000000000000 C

D:\System Volume Information\_restore{F7149EC7-4FA5-4148-81FA-2F7A6348FD9A}\RP5\A0002465.DLL Win32/Ramnit.H virus (cleaned - quarantined) 00000000000000000000000000000000 C

D:\System Volume Information\_restore{F7149EC7-4FA5-4148-81FA-2F7A6348FD9A}\RP5\A0002466.EXE Win32/Ramnit.H virus (cleaned - quarantined) 00000000000000000000000000000000 C

D:\System Volume Information\_restore{F7149EC7-4FA5-4148-81FA-2F7A6348FD9A}\RP5\A0002467.EXE Win32/Ramnit.H virus (cleaned - quarantined) 00000000000000000000000000000000 C

D:\System Volume Information\_restore{F7149EC7-4FA5-4148-81FA-2F7A6348FD9A}\RP5\A0002468.DLL Win32/Ramnit.H virus (cleaned - quarantined) 00000000000000000000000000000000 C

D:\System Volume Information\_restore{F7149EC7-4FA5-4148-81FA-2F7A6348FD9A}\RP5\A0002469.DLL Win32/Ramnit.H virus (cleaned - quarantined) 00000000000000000000000000000000 C

D:\System Volume Information\_restore{F7149EC7-4FA5-4148-81FA-2F7A6348FD9A}\RP5\A0002470.DLL Win32/Ramnit.H virus (cleaned - quarantined) 00000000000000000000000000000000 C

D:\System Volume Information\_restore{F7149EC7-4FA5-4148-81FA-2F7A6348FD9A}\RP5\A0002471.EXE Win32/Ramnit.H virus (cleaned - quarantined) 00000000000000000000000000000000 C

D:\System Volume Information\_restore{F7149EC7-4FA5-4148-81FA-2F7A6348FD9A}\RP5\A0002472.DLL Win32/Ramnit.H virus (cleaned - quarantined) 00000000000000000000000000000000 C

D:\System Volume Information\_restore{F7149EC7-4FA5-4148-81FA-2F7A6348FD9A}\RP5\A0002473.DLL Win32/Ramnit.H virus (cleaned - quarantined) 00000000000000000000000000000000 C

D:\System Volume Information\_restore{F7149EC7-4FA5-4148-81FA-2F7A6348FD9A}\RP5\A0002474.DLL Win32/Ramnit.H virus (cleaned - quarantined) 00000000000000000000000000000000 C

D:\System Volume Information\_restore{F7149EC7-4FA5-4148-81FA-2F7A6348FD9A}\RP5\A0002475.DLL Win32/Ramnit.H virus (cleaned - quarantined) 00000000000000000000000000000000 C

D:\System Volume Information\_restore{F7149EC7-4FA5-4148-81FA-2F7A6348FD9A}\RP5\A0002476.EXE Win32/Ramnit.H virus (cleaned - quarantined) 00000000000000000000000000000000 C

D:\System Volume Information\_restore{F7149EC7-4FA5-4148-81FA-2F7A6348FD9A}\RP5\A0002477.DLL Win32/Ramnit.H virus (cleaned - quarantined) 00000000000000000000000000000000 C

D:\System Volume Information\_restore{F7149EC7-4FA5-4148-81FA-2F7A6348FD9A}\RP5\A0002478.DLL Win32/Ramnit.H virus (cleaned - quarantined) 00000000000000000000000000000000 C

D:\System Volume Information\_restore{F7149EC7-4FA5-4148-81FA-2F7A6348FD9A}\RP5\A0002479.EXE Win32/Ramnit.H virus (cleaned - quarantined) 00000000000000000000000000000000 C

D:\System Volume Information\_restore{F7149EC7-4FA5-4148-81FA-2F7A6348FD9A}\RP5\A0002480.DLL Win32/Ramnit.H virus (cleaned - quarantined) 00000000000000000000000000000000 C

D:\System Volume Information\_restore{F7149EC7-4FA5-4148-81FA-2F7A6348FD9A}\RP5\A0002481.DLL Win32/Ramnit.H virus (cleaned - quarantined) 00000000000000000000000000000000 C

D:\System Volume Information\_restore{F7149EC7-4FA5-4148-81FA-2F7A6348FD9A}\RP5\A0002482.EXE Win32/Ramnit.H virus (cleaned - quarantined) 00000000000000000000000000000000 C

D:\System Volume Information\_restore{F7149EC7-4FA5-4148-81FA-2F7A6348FD9A}\RP5\A0002483.EXE Win32/Ramnit.H virus (cleaned - quarantined) 00000000000000000000000000000000 C

D:\System Volume Information\_restore{F7149EC7-4FA5-4148-81FA-2F7A6348FD9A}\RP5\A0002484.DLL Win32/Ramnit.H virus (cleaned - quarantined) 00000000000000000000000000000000 C

D:\System Volume Information\_restore{F7149EC7-4FA5-4148-81FA-2F7A6348FD9A}\RP5\A0002485.EXE Win32/Ramnit.H virus (cleaned - quarantined) 00000000000000000000000000000000 C

D:\System Volume Information\_restore{F7149EC7-4FA5-4148-81FA-2F7A6348FD9A}\RP5\A0002486.DLL Win32/Ramnit.H virus (cleaned - quarantined) 00000000000000000000000000000000 C

D:\System Volume Information\_restore{F7149EC7-4FA5-4148-81FA-2F7A6348FD9A}\RP5\A0002487.DLL Win32/Ramnit.H virus (cleaned - quarantined) 00000000000000000000000000000000 C

D:\System Volume Information\_restore{F7149EC7-4FA5-4148-81FA-2F7A6348FD9A}\RP5\A0002488.DLL Win32/Ramnit.H virus (cleaned - quarantined) 00000000000000000000000000000000 C

D:\System Volume Information\_restore{F7149EC7-4FA5-4148-81FA-2F7A6348FD9A}\RP5\A0002489.EXE Win32/Ramnit.H virus (cleaned - quarantined) 00000000000000000000000000000000 C

D:\System Volume Information\_restore{F7149EC7-4FA5-4148-81FA-2F7A6348FD9A}\RP5\A0002490.EXE Win32/Ramnit.H virus (cleaned - quarantined) 00000000000000000000000000000000 C

D:\System Volume Information\_restore{F7149EC7-4FA5-4148-81FA-2F7A6348FD9A}\RP5\A0002491.DLL Win32/Ramnit.H virus (cleaned - quarantined) 00000000000000000000000000000000 C

D:\System Volume Information\_restore{F7149EC7-4FA5-4148-81FA-2F7A6348FD9A}\RP5\A0002492.DLL Win32/Ramnit.H virus (cleaned - quarantined) 00000000000000000000000000000000 C

D:\System Volume Information\_restore{F7149EC7-4FA5-4148-81FA-2F7A6348FD9A}\RP5\A0002493.DLL Win32/Ramnit.H virus (cleaned - quarantined) 00000000000000000000000000000000 C

D:\System Volume Information\_restore{F7149EC7-4FA5-4148-81FA-2F7A6348FD9A}\RP5\A0002494.DLL Win32/Ramnit.H virus (cleaned - quarantined) 00000000000000000000000000000000 C

D:\System Volume Information\_restore{F7149EC7-4FA5-4148-81FA-2F7A6348FD9A}\RP5\A0002495.EXE Win32/Ramnit.H virus (cleaned - quarantined) 00000000000000000000000000000000 C

D:\System Volume Information\_restore{F7149EC7-4FA5-4148-81FA-2F7A6348FD9A}\RP5\A0002496.DLL Win32/Ramnit.H virus (cleaned - quarantined) 00000000000000000000000000000000 C

D:\System Volume Information\_restore{F7149EC7-4FA5-4148-81FA-2F7A6348FD9A}\RP5\A0002497.DLL Win32/Ramnit.H virus (cleaned - quarantined) 00000000000000000000000000000000 C

D:\System Volume Information\_restore{F7149EC7-4FA5-4148-81FA-2F7A6348FD9A}\RP5\A0002498.DLL Win32/Ramnit.H virus (cleaned - quarantined) 00000000000000000000000000000000 C

D:\System Volume Information\_restore{F7149EC7-4FA5-4148-81FA-2F7A6348FD9A}\RP5\A0002499.DLL Win32/Ramnit.H virus (cleaned - quarantined) 00000000000000000000000000000000 C

D:\System Volume Information\_restore{F7149EC7-4FA5-4148-81FA-2F7A6348FD9A}\RP5\A0002500.DLL Win32/Ramnit.H virus (cleaned - quarantined) 00000000000000000000000000000000 C

D:\System Volume Information\_restore{F7149EC7-4FA5-4148-81FA-2F7A6348FD9A}\RP5\A0002501.DLL Win32/Ramnit.H virus (cleaned - quarantined) 00000000000000000000000000000000 C

D:\System Volume Information\_restore{F7149EC7-4FA5-4148-81FA-2F7A6348FD9A}\RP5\A0002502.DLL Win32/Ramnit.H virus (cleaned - quarantined) 00000000000000000000000000000000 C

D:\System Volume Information\_restore{F7149EC7-4FA5-4148-81FA-2F7A6348FD9A}\RP5\A0002503.DLL Win32/Ramnit.H virus (cleaned - quarantined) 00000000000000000000000000000000 C

D:\System Volume Information\_restore{F7149EC7-4FA5-4148-81FA-2F7A6348FD9A}\RP5\A0002504.DLL Win32/Ramnit.H virus (cleaned - quarantined) 00000000000000000000000000000000 C

D:\System Volume Information\_restore{F7149EC7-4FA5-4148-81FA-2F7A6348FD9A}\RP5\A0002505.DLL Win32/Ramnit.H virus (cleaned - quarantined) 00000000000000000000000000000000 C

D:\System Volume Information\_restore{F7149EC7-4FA5-4148-81FA-2F7A6348FD9A}\RP5\A0002506.DLL Win32/Ramnit.H virus (cleaned - quarantined) 00000000000000000000000000000000 C

D:\System Volume Information\_restore{F7149EC7-4FA5-4148-81FA-2F7A6348FD9A}\RP5\A0002507.DLL Win32/Ramnit.H virus (cleaned - quarantined) 00000000000000000000000000000000 C

D:\System Volume Information\_restore{F7149EC7-4FA5-4148-81FA-2F7A6348FD9A}\RP5\A0002508.DLL Win32/Ramnit.H virus (cleaned - quarantined) 00000000000000000000000000000000 C

D:\System Volume Information\_restore{F7149EC7-4FA5-4148-81FA-2F7A6348FD9A}\RP5\A0002509.DLL Win32/Ramnit.H virus (cleaned - quarantined) 00000000000000000000000000000000 C

D:\System Volume Information\_restore{F7149EC7-4FA5-4148-81FA-2F7A6348FD9A}\RP5\A0002510.DLL Win32/Ramnit.H virus (cleaned - quarantined) 00000000000000000000000000000000 C

D:\System Volume Information\_restore{F7149EC7-4FA5-4148-81FA-2F7A6348FD9A}\RP5\A0002511.DLL Win32/Ramnit.H virus (cleaned - quarantined) 00000000000000000000000000000000 C

D:\System Volume Information\_restore{F7149EC7-4FA5-4148-81FA-2F7A6348FD9A}\RP5\A0002512.DLL Win32/Ramnit.H virus (cleaned - quarantined) 00000000000000000000000000000000 C

D:\System Volume Information\_restore{F7149EC7-4FA5-4148-81FA-2F7A6348FD9A}\RP5\A0002513.DLL Win32/Ramnit.H virus (cleaned - quarantined) 00000000000000000000000000000000 C

D:\System Volume Information\_restore{F7149EC7-4FA5-4148-81FA-2F7A6348FD9A}\RP5\A0002514.DLL Win32/Ramnit.H virus (cleaned - quarantined) 00000000000000000000000000000000 C

D:\System Volume Information\_restore{F7149EC7-4FA5-4148-81FA-2F7A6348FD9A}\RP5\A0002515.DLL Win32/Ramnit.H virus (cleaned - quarantined) 00000000000000000000000000000000 C

D:\System Volume Information\_restore{F7149EC7-4FA5-4148-81FA-2F7A6348FD9A}\RP5\A0002516.DLL Win32/Ramnit.H virus (cleaned - quarantined) 00000000000000000000000000000000 C

D:\System Volume Information\_restore{F7149EC7-4FA5-4148-81FA-2F7A6348FD9A}\RP5\A0002517.DLL Win32/Ramnit.H virus (cleaned - quarantined) 00000000000000000000000000000000 C

D:\System Volume Information\_restore{F7149EC7-4FA5-4148-81FA-2F7A6348FD9A}\RP5\A0002518.DLL Win32/Ramnit.H virus (cleaned - quarantined) 00000000000000000000000000000000 C

D:\System Volume Information\_restore{F7149EC7-4FA5-4148-81FA-2F7A6348FD9A}\RP5\A0002519.DLL Win32/Ramnit.H virus (cleaned - quarantined) 00000000000000000000000000000000 C

D:\System Volume Information\_restore{F7149EC7-4FA5-4148-81FA-2F7A6348FD9A}\RP5\A0002520.DLL Win32/Ramnit.H virus (cleaned - quarantined) 00000000000000000000000000000000 C

D:\System Volume Information\_restore{F7149EC7-4FA5-4148-81FA-2F7A6348FD9A}\RP5\A0002521.DLL Win32/Ramnit.H virus (cleaned - quarantined) 00000000000000000000000000000000 C

D:\System Volume Information\_restore{F7149EC7-4FA5-4148-81FA-2F7A6348FD9A}\RP5\A0002522.DLL Win32/Ramnit.H virus (cleaned - quarantined) 00000000000000000000000000000000 C

D:\System Volume Information\_restore{F7149EC7-4FA5-4148-81FA-2F7A6348FD9A}\RP5\A0002523.DLL Win32/Ramnit.H virus (cleaned - quarantined) 00000000000000000000000000000000 C

D:\System Volume Information\_restore{F7149EC7-4FA5-4148-81FA-2F7A6348FD9A}\RP5\A0002524.DLL Win32/Ramnit.H virus (cleaned - quarantined) 00000000000000000000000000000000 C

D:\System Volume Information\_restore{F7149EC7-4FA5-4148-81FA-2F7A6348FD9A}\RP5\A0002525.DLL Win32/Ramnit.H virus (cleaned - quarantined) 00000000000000000000000000000000 C

D:\System Volume Information\_restore{F7149EC7-4FA5-4148-81FA-2F7A6348FD9A}\RP5\A0002526.DLL Win32/Ramnit.H virus (cleaned - quarantined) 00000000000000000000000000000000 C

D:\System Volume Information\_restore{F7149EC7-4FA5-4148-81FA-2F7A6348FD9A}\RP5\A0002527.DLL Win32/Ramnit.H virus (cleaned - quarantined) 00000000000000000000000000000000 C

D:\System Volume Information\_restore{F7149EC7-4FA5-4148-81FA-2F7A6348FD9A}\RP5\A0002528.DLL Win32/Ramnit.H virus (cleaned - quarantined) 00000000000000000000000000000000 C

D:\System Volume Information\_restore{F7149EC7-4FA5-4148-81FA-2F7A6348FD9A}\RP5\A0002529.DLL Win32/Ramnit.H virus (cleaned - quarantined) 00000000000000000000000000000000 C

D:\System Volume Information\_restore{F7149EC7-4FA5-4148-81FA-2F7A6348FD9A}\RP5\A0002530.DLL Win32/Ramnit.H virus (cleaned - quarantined) 00000000000000000000000000000000 C

D:\System Volume Information\_restore{F7149EC7-4FA5-4148-81FA-2F7A6348FD9A}\RP5\A0002531.DLL Win32/Ramnit.H virus (cleaned - quarantined) 00000000000000000000000000000000 C

D:\System Volume Information\_restore{F7149EC7-4FA5-4148-81FA-2F7A6348FD9A}\RP5\A0002532.DLL Win32/Ramnit.H virus (cleaned - quarantined) 00000000000000000000000000000000 C

D:\System Volume Information\_restore{F7149EC7-4FA5-4148-81FA-2F7A6348FD9A}\RP5\A0002533.DLL Win32/Ramnit.H virus (cleaned - quarantined) 00000000000000000000000000000000 C

D:\System Volume Information\_restore{F7149EC7-4FA5-4148-81FA-2F7A6348FD9A}\RP5\A0002534.DLL Win32/Ramnit.H virus (cleaned - quarantined) 00000000000000000000000000000000 C

D:\System Volume Information\_restore{F7149EC7-4FA5-4148-81FA-2F7A6348FD9A}\RP5\A0002535.DLL Win32/Ramnit.H virus (cleaned - quarantined) 00000000000000000000000000000000 C

D:\System Volume Information\_restore{F7149EC7-4FA5-4148-81FA-2F7A6348FD9A}\RP5\A0002536.DLL Win32/Ramnit.H virus (cleaned - quarantined) 00000000000000000000000000000000 C

D:\System Volume Information\_restore{F7149EC7-4FA5-4148-81FA-2F7A6348FD9A}\RP5\A0002537.DLL Win32/Ramnit.H virus (cleaned - quarantined) 00000000000000000000000000000000 C

D:\System Volume Information\_restore{F7149EC7-4FA5-4148-81FA-2F7A6348FD9A}\RP5\A0002538.DLL Win32/Ramnit.H virus (cleaned - quarantined) 00000000000000000000000000000000 C

D:\System Volume Information\_restore{F7149EC7-4FA5-4148-81FA-2F7A6348FD9A}\RP5\A0002539.DLL Win32/Ramnit.H virus (cleaned - quarantined) 00000000000000000000000000000000 C

D:\System Volume Information\_restore{F7149EC7-4FA5-4148-81FA-2F7A6348FD9A}\RP5\A0002540.DLL Win32/Ramnit.H virus (cleaned - quarantined) 00000000000000000000000000000000 C

D:\System Volume Information\_restore{F7149EC7-4FA5-4148-81FA-2F7A6348FD9A}\RP5\A0002541.DLL Win32/Ramnit.H virus (cleaned - quarantined) 00000000000000000000000000000000 C

D:\System Volume Information\_restore{F7149EC7-4FA5-4148-81FA-2F7A6348FD9A}\RP5\A0002542.DLL Win32/Ramnit.H virus (cleaned - quarantined) 00000000000000000000000000000000 C

D:\System Volume Information\_restore{F7149EC7-4FA5-4148-81FA-2F7A6348FD9A}\RP5\A0002543.exe Win32/Ramnit.H virus (cleaned - quarantined) 00000000000000000000000000000000 C

D:\System Volume Information\_restore{F7149EC7-4FA5-4148-81FA-2F7A6348FD9A}\RP5\A0002544.dll Win32/Ramnit.H virus (cleaned - quarantined) 00000000000000000000000000000000 C

D:\System Volume Information\_restore{F7149EC7-4FA5-4148-81FA-2F7A6348FD9A}\RP5\A0002545.exe Win32/Ramnit.H virus (cleaned - quarantined) 00000000000000000000000000000000 C

D:\System Volume Information\_restore{F7149EC7-4FA5-4148-81FA-2F7A6348FD9A}\RP5\A0002546.exe Win32/Ramnit.H virus (cleaned - quarantined) 00000000000000000000000000000000 C

D:\System Volume Information\_restore{F7149EC7-4FA5-4148-81FA-2F7A6348FD9A}\RP5\A0002547.EXE Win32/Ramnit.H virus (cleaned - quarantined) 00000000000000000000000000000000 C

D:\System Volume Information\_restore{F7149EC7-4FA5-4148-81FA-2F7A6348FD9A}\RP5\A0002548.dll Win32/Ramnit.H virus (cleaned - quarantined) 00000000000000000000000000000000 C

D:\System Volume Information\_restore{F7149EC7-4FA5-4148-81FA-2F7A6348FD9A}\RP5\A0002549.dll Win32/Ramnit.H virus (cleaned - quarantined) 00000000000000000000000000000000 C

D:\System Volume Information\_restore{F7149EC7-4FA5-4148-81FA-2F7A6348FD9A}\RP5\A0002550.dll Win32/Ramnit.H virus (cleaned - quarantined) 00000000000000000000000000000000 C

D:\System Volume Information\_restore{F7149EC7-4FA5-4148-81FA-2F7A6348FD9A}\RP5\A0002551.dll Win32/Ramnit.H virus (cleaned - quarantined) 00000000000000000000000000000000 C

D:\System Volume Information\_restore{F7149EC7-4FA5-4148-81FA-2F7A6348FD9A}\RP5\A0002552.dll Win32/Ramnit.H virus (cleaned - quarantined) 00000000000000000000000000000000 C

D:\System Volume Information\_restore{F7149EC7-4FA5-4148-81FA-2F7A6348FD9A}\RP5\A0002553.dll Win32/Ramnit.H virus (cleaned - quarantined) 00000000000000000000000000000000 C

D:\System Volume Information\_restore{F7149EC7-4FA5-4148-81FA-2F7A6348FD9A}\RP5\A0002554.dll Win32/Ramnit.H virus (cleaned - quarantined) 00000000000000000000000000000000 C

D:\System Volume Information\_restore{F7149EC7-4FA5-4148-81FA-2F7A6348FD9A}\RP5\A0002555.DLL Win32/Ramnit.H virus (cleaned - quarantined) 00000000000000000000000000000000 C

D:\System Volume Information\_restore{F7149EC7-4FA5-4148-81FA-2F7A6348FD9A}\RP5\A0002556.dll Win32/Ramnit.H virus (cleaned - quarantined) 00000000000000000000000000000000 C

D:\System Volume Information\_restore{F7149EC7-4FA5-4148-81FA-2F7A6348FD9A}\RP5\A0002557.dll Win32/Ramnit.H virus (cleaned - quarantined) 00000000000000000000000000000000 C

D:\System Volume Information\_restore{F7149EC7-4FA5-4148-81FA-2F7A6348FD9A}\RP5\A0002558.dll Win32/Ramnit.H virus (cleaned - quarantined) 00000000000000000000000000000000 C

D:\System Volume Information\_restore{F7149EC7-4FA5-4148-81FA-2F7A6348FD9A}\RP5\A0002559.dll Win32/Ramnit.H virus (cleaned - quarantined) 00000000000000000000000000000000 C

D:\System Volume Information\_restore{F7149EC7-4FA5-4148-81FA-2F7A6348FD9A}\RP5\A0002560.exe Win32/Ramnit.H virus (cleaned - quarantined) 00000000000000000000000000000000 C

D:\System Volume Information\_restore{F7149EC7-4FA5-4148-81FA-2F7A6348FD9A}\RP5\A0002561.exe Win32/Ramnit.H virus (cleaned - quarantined) 00000000000000000000000000000000 C

D:\System Volume Information\_restore{F7149EC7-4FA5-4148-81FA-2F7A6348FD9A}\RP5\A0002562.exe Win32/Ramnit.H virus (cleaned - quarantined) 00000000000000000000000000000000 C

D:\System Volume Information\_restore{F7149EC7-4FA5-4148-81FA-2F7A6348FD9A}\RP5\A0002563.exe Win32/Ramnit.H virus (cleaned - quarantined) 00000000000000000000000000000000 C

Link to post
Share on other sites

Results of screen317's Security Check version 0.99.10

Windows XP Service Pack 2

Out of date service pack!!

Internet Explorer 6 Out of date!

``````````````````````````````

Antivirus/Firewall Check:

Windows Firewall Enabled!

avast! Free Antivirus

ESET Online Scanner v3

Antivirus up to date!

```````````````````````````````

Anti-malware/Other Utilities Check:

Malwarebytes' Anti-Malware

Adobe Reader 7.0.5

Out of date Adobe Reader installed!

````````````````````````````````

Process Check:

objlist.exe by Laurent

AVAST Software Avast AvastSvc.exe

AVAST Software Avast avastUI.exe

``````````End of Log````````````

Link to post
Share on other sites

Hi, I see that your scan shows Adobe, Internet Explorer, security patches, etc out of date. Can I just point out that this is because I have recently done a destructive system recovery and the only time I have dared to use the infected PC is to carry out these scans. I have not updated anything yet because I have been to worried to use my PC.

Link to post
Share on other sites

Hi screen317, I hate having to keep bothering someone, especially when they are helping me out but I havent heard from you since April 30th and I would really like to finish getting my PC sorted out. Can you take a look at the last logs I posted for you and let me know what I need to do next.

Thanks,

Stuart.

Link to post
Share on other sites

  • Staff

Hi Stuart,

Some information about file infectors:

These infections are particularly malicious, in that they infect all of your legitimate programs.

The problem is... the virus is very buggy, so it does not do a good job of infecting your files, so any attempt to disinfect and possibly save your files would be futile, in that, due to the buggy virus, we cannot properly disinfect your files.

The recovery partition may also have been infected, so you'll need to format your hard drive and reinstall Windows via some external media (CD) and reinstall.

Link to post
Share on other sites

Hi Chris,

I really appreciate all of your help in what now seems a losing battle. Unfortunaley, I don't have any backup discs as the system came pre-installed without backups and I never created the recovery discs (how I'm regretting not finding the time now). I've looked on the Compaq website and they sell the recovery discs for

Link to post
Share on other sites

  • Staff

Hi,

No the picture files should be safe; usually only executable files like .exe and .scr are infected, sometimes .pdf too. Pictures should be fine though.

Unfortunately this looks like the best course of action for you to ensure the future safety of this computer.

Link to post
Share on other sites

  • Recently Browsing   0 members

    • No registered users viewing this page.
Back to top
×
×
  • Create New...

Important Information

This site uses cookies - We have placed cookies on your device to help make this website better. You can adjust your cookie settings, otherwise we'll assume you're okay to continue.