ja prøvede at trykke 2 istedet.. virker vist bedre
den er ikke færdig endnu men fandt denne bagle og slettede
C:\document an settings\Ejer \applikation Data\hidires\hidr.exe(infected with W32/bagle.Rx)
|
|
|
|
ja prøvede at trykke 2 istedet.. virker vist bedre den er ikke færdig endnu men fandt denne bagle og slettede C:\document an settings\Ejer \applikation Data\hidires\hidr.exe(infected with W32/bagle.Rx)
|
|
|
|
|
|
lige et par spm er det overhovedet muligt at fjerne denne orm helt. og kan det som den har ændret, gendannes HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot og installeret, fjernes uden at jeg skal geninstallere xp igen. så vidt jeg ku læse blev der benyttet en bagdør via en proxyserver og ..... I al stilhed droppes i baggrunden en kopi af ormen til det inficerede system i roden af C drevet som temp.zip, mens Bagle både dræber en lang liste af sikkerhedssoftware og forbinder sig til en stribe webservere (99 i alt) for at opdatere sig selv. Den henter fjernkoden ned som ”re_file.exe”, og eksekverer den på det inficerede system. På den måde er forfatteren i stand til at fjernkontrollere inficerede systemer. De fleste af disse websider/domæner befinder sig i Rusland og Tjekkiet. Fra ”temp.zip” kopieres en udpakket version af Bagle-FY over i mappen for dokumenter og indstillinger – mere præcist under \Application Data\hidn\hidn.exe. I samme mappe droppes et rootkit med filnavnet ” m_hook.sys”. For at rootkittet opnår den ønskede funktionalitet foretages følgende ændringer i registreringsdatabasen: hvis systemgendannelse, fejlsikker tilstand, firewall først engang er blevet smadret via registreringsdatabasen. skal jeg så partout geninstallere. eller vil nogle af funktionerne vende tilbage når ormen er fjernet??.
|
|
|
|
|
|
hej igen smider lige denne log Logfile of HijackThis v1.99.1 Running processes: R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,AutoConfigURL = http://wpad.iha.dk/wpad.dat der er stadig ingen af førnævnte funktioner der virker |
|
|
|
|
|
Lad os lige tjekke om det er et rootkit der laver de numre - Hent derefter dette værktøj, og gem det på dit skrivebord: Kør programmet. Efter kort tid vil der dukke en logfil op, som kan findes her C:\rootlog txt. Kopier indholdet af denne log herind i tråden
|
|
|
|
|
|
hej det vil jeg forsøge… her er lige loggen fra SDFIX, som jeg glemte Norman Generic Fix Norman Scanner Engine Version: 5.90.28 Running pre-scan cleanup routine: Removed registry value: HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System -> DisableRegistryTools = 0x00BF4550
Number of processes/threads found: 2353
C:\*.*
C:\Documents and Settings\Ejer\Application Data\hidires\hidr.exe (Infected with W32/Bagle.RX) C:\Documents and Settings\Ejer\Lokale indstillinger\Temp\a2archive\xmldso4.cab/unknown20 (Error whilst scanning file) C:\Documents and Settings\Ejer\Lokale indstillinger\Temp\a2archive\xmldso4.cab/unknown21 (Error whilst scanning file) C:\Documents and Settings\Ejer\Lokale indstillinger\Temp\a2archive\xmldso4.cab/unknown22 (Error whilst scanning file) C:\Documents and Settings\Ejer\Lokale indstillinger\Temp\a2archive\xmldso4.cab/unknown23 (Error whilst scanning file) C:\Documents and Settings\Ejer\Lokale indstillinger\Temp\a2archive\xmldso4.cab/unknown24 (Error whilst scanning file) C:\Documents and Settings\Ejer\Lokale indstillinger\Temp\a2archive\xmldso4.cab/unknown25 (Error whilst scanning file) C:\Documents and Settings\Ejer\Lokale indstillinger\Temp\a2archive\xmldso4.cab/unknown26 (Error whilst scanning file) C:\Documents and Settings\Ejer\Lokale indstillinger\Temp\a2archive\xmldso4.cab/unknown27 (Error whilst scanning file) C:\Documents and Settings\Ejer\Lokale indstillinger\Temp\a2archive\xmldso4.cab/unknown28 (Error whilst scanning file) C:\Documents and Settings\Ejer\Lokale indstillinger\Temp\a2archive\xmldso4.cab/unknown29 (Error whilst scanning file) C:\Documents and Settings\Ejer\Lokale indstillinger\Temp\a2archive\xmldso4.cab/unknown30 (Error whilst scanning file) C:\Documents and Settings\Ejer\Lokale indstillinger\Temp\a2archive\xmldso4.cab/unknown31 (Error whilst scanning file) C:\Documents and Settings\Ejer\Lokale indstillinger\Temp\a2archive\xmldso4.cab/unknown32 (Error whilst scanning file) C:\Documents and Settings\Ejer\Lokale indstillinger\Temp\a2archive\xmldso4.cab/unknown33 (Error whilst scanning file) C:\Documents and Settings\Ejer\Lokale indstillinger\Temp\a2archive\xmldso4.cab/unknown34 (Error whilst scanning file) C:\Documents and Settings\Ejer\Lokale indstillinger\Temp\a2archive\xmldso4.cab/unknown35 (Error whilst scanning file) C:\Documents and Settings\Ejer\Lokale indstillinger\Temp\a2archive\xmldso4.cab/unknown36 (Error whilst scanning file) C:\Documents and Settings\Ejer\Lokale indstillinger\Temp\a2archive\xmldso4.cab/unknown37 (Error whilst scanning file) C:\Documents and Settings\Ejer\Lokale indstillinger\Temp\a2archive\xmldso4.cab/unknown38 (Error whilst scanning file) C:\Documents and Settings\Ejer\Lokale indstillinger\Temp\a2archive\xmldso4.cab/unknown39 (Error whilst scanning file) C:\Documents and Settings\Ejer\Lokale indstillinger\Temp\a2archive\xmldso4.cab/unknown40 (Error whilst scanning file) C:\Documents and Settings\Ejer\Lokale indstillinger\Temp\a2archive\xmldso4.cab/unknown41 (Error whilst scanning file) C:\Documents and Settings\Ejer\Lokale indstillinger\Temp\a2archive\xmldso4.cab/unknown42 (Error whilst scanning file) C:\Documents and Settings\Ejer\Lokale indstillinger\Temp\a2archive\xmldso4.cab/unknown43 (Error whilst scanning file) C:\Documents and Settings\Ejer\Lokale indstillinger\Temp\a2archive\xmldso4.cab/unknown44 (Error whilst scanning file) C:\Documents and Settings\Ejer\Lokale indstillinger\Temp\a2archive\xmldso4.cab/unknown45 (Error whilst scanning file) C:\Documents and Settings\Ejer\Lokale indstillinger\Temp\a2archive\xmldso4.cab/unknown46 (Error whilst scanning file) C:\Documents and Settings\Ejer\Lokale indstillinger\Temp\a2archive\xmldso4.cab/unknown47 (Error whilst scanning file) C:\Documents and Settings\Ejer\Lokale indstillinger\Temp\a2archive\xmldso4.cab/unknown48 (Error whilst scanning file) C:\Documents and Settings\Ejer\Lokale indstillinger\Temp\a2archive\xmldso4.cab/unknown49 (Error whilst scanning file) C:\System Volume Information\_restore{A760429D-B2C8-4A37-9C31-A7BFB448DA32}\RP100\A0016122.exe (Infected with W32/Bagle.RX) C:\System Volume Information\_restore{A760429D-B2C8-4A37-9C31-A7BFB448DA32}\RP100\A0016139.exe (Infected with W32/Bagle.RX) C:\System Volume Information\_restore{A760429D-B2C8-4A37-9C31-A7BFB448DA32}\RP100\A0016154.exe (Infected with W32/Bagle.RX) C:\System Volume Information\_restore{A760429D-B2C8-4A37-9C31-A7BFB448DA32}\RP101\A0016156.exe (Infected with W32/Bagle.RX) C:\System Volume Information\_restore{A760429D-B2C8-4A37-9C31-A7BFB448DA32}\RP102\A0016169.exe (Infected with W32/Bagle.RX) C:\System Volume Information\_restore{A760429D-B2C8-4A37-9C31-A7BFB448DA32}\RP102\A0016210.exe (Infected with W32/Bagle.RX) C:\System Volume Information\_restore{A760429D-B2C8-4A37-9C31-A7BFB448DA32}\RP103\A0017212.exe (Infected with W32/Bagle.RX) C:\System Volume Information\_restore{A760429D-B2C8-4A37-9C31-A7BFB448DA32}\RP106\A0020342.exe (Infected with W32/Bagle.RS) C:\System Volume Information\_restore{A760429D-B2C8-4A37-9C31-A7BFB448DA32}\RP108\A0020583.exe (Infected with W32/Bagle.RS) C:\System Volume Information\_restore{A760429D-B2C8-4A37-9C31-A7BFB448DA32}\RP108\A0020584.exe (Infected with W32/Bagle.RZ) C:\System Volume Information\_restore{A760429D-B2C8-4A37-9C31-A7BFB448DA32}\RP108\A0020585.exe (Infected with W32/Bagle.RX) C:\System Volume Information\_restore{A760429D-B2C8-4A37-9C31-A7BFB448DA32}\RP108\A0020586.exe (Infected with W32/Bagle.RZ) C:\System Volume Information\_restore{A760429D-B2C8-4A37-9C31-A7BFB448DA32}\RP108\A0020587.exe (Infected with W32/Bagle.RX) C:\System Volume Information\_restore{A760429D-B2C8-4A37-9C31-A7BFB448DA32}\RP108\A0020588.exe (Infected with W32/Bagle.RP) C:\System Volume Information\_restore{A760429D-B2C8-4A37-9C31-A7BFB448DA32}\RP108\A0020589.exe (Infected with W32/Bagle.RZ) C:\System Volume Information\_restore{A760429D-B2C8-4A37-9C31-A7BFB448DA32}\RP108\A0020590.exe (Infected with W32/Bagle.RX) C:\System Volume Information\_restore{A760429D-B2C8-4A37-9C31-A7BFB448DA32}\RP108\A0020591.exe (Infected with W32/Bagle.RZ) C:\System Volume Information\_restore{A760429D-B2C8-4A37-9C31-A7BFB448DA32}\RP108\A0020592.exe (Infected with W32/Bagle.RX) C:\System Volume Information\_restore{A760429D-B2C8-4A37-9C31-A7BFB448DA32}\RP108\A0020593.exe (Infected with W32/Bagle.RZ) C:\System Volume Information\_restore{A760429D-B2C8-4A37-9C31-A7BFB448DA32}\RP108\A0020594.exe (Infected with W32/Bagle.RX) C:\System Volume Information\_restore{A760429D-B2C8-4A37-9C31-A7BFB448DA32}\RP108\A0020595.exe (Infected with W32/Bagle.RZ) C:\System Volume Information\_restore{A760429D-B2C8-4A37-9C31-A7BFB448DA32}\RP108\A0020596.exe (Infected with W32/Bagle.RX) C:\System Volume Information\_restore{A760429D-B2C8-4A37-9C31-A7BFB448DA32}\RP108\A0020597.exe (Infected with W32/Bagle.RZ) C:\System Volume Information\_restore{A760429D-B2C8-4A37-9C31-A7BFB448DA32}\RP108\A0020598.exe (Infected with W32/Bagle.RX) C:\System Volume Information\_restore{A760429D-B2C8-4A37-9C31-A7BFB448DA32}\RP108\A0020599.exe (Infected with W32/Bagle.RZ) C:\System Volume Information\_restore{A760429D-B2C8-4A37-9C31-A7BFB448DA32}\RP108\A0020600.exe (Infected with W32/Bagle.RS) C:\System Volume Information\_restore{A760429D-B2C8-4A37-9C31-A7BFB448DA32}\RP108\A0020601.exe (Infected with W32/Bagle.RZ) C:\System Volume Information\_restore{A760429D-B2C8-4A37-9C31-A7BFB448DA32}\RP108\A0020602.exe (Infected with W32/Bagle.RX) C:\System Volume Information\_restore{A760429D-B2C8-4A37-9C31-A7BFB448DA32}\RP108\A0020603.exe (Infected with W32/Bagle.RZ) C:\System Volume Information\_restore{A760429D-B2C8-4A37-9C31-A7BFB448DA32}\RP108\A0020604.exe (Infected with W32/Bagle.RX) C:\System Volume Information\_restore{A760429D-B2C8-4A37-9C31-A7BFB448DA32}\RP108\A0020605.exe (Infected with W32/Bagle.RZ) C:\System Volume Information\_restore{A760429D-B2C8-4A37-9C31-A7BFB448DA32}\RP108\A0020606.exe (Infected with W32/Bagle.RX) C:\System Volume Information\_restore{A760429D-B2C8-4A37-9C31-A7BFB448DA32}\RP108\A0020607.exe (Infected with W32/Bagle.RZ) C:\System Volume Information\_restore{A760429D-B2C8-4A37-9C31-A7BFB448DA32}\RP108\A0020608.exe (Infected with W32/Bagle.RX) C:\System Volume Information\_restore{A760429D-B2C8-4A37-9C31-A7BFB448DA32}\RP108\A0020609.exe (Infected with W32/Bagle.RZ) C:\System Volume Information\_restore{A760429D-B2C8-4A37-9C31-A7BFB448DA32}\RP108\A0020610.exe (Infected with W32/Bagle.RX) C:\System Volume Information\_restore{A760429D-B2C8-4A37-9C31-A7BFB448DA32}\RP108\A0020611.exe (Infected with W32/Bagle.RZ) C:\System Volume Information\_restore{A760429D-B2C8-4A37-9C31-A7BFB448DA32}\RP108\A0020612.exe (Infected with W32/Bagle.RX) C:\System Volume Information\_restore{A760429D-B2C8-4A37-9C31-A7BFB448DA32}\RP108\A0020613.exe (Infected with W32/Bagle.RX) C:\System Volume Information\_restore{A760429D-B2C8-4A37-9C31-A7BFB448DA32}\RP108\A0020614.exe (Infected with W32/Bagle.RZ) C:\System Volume Information\_restore{A760429D-B2C8-4A37-9C31-A7BFB448DA32}\RP108\A0020615.exe (Infected with W32/Bagle.RX) C:\System Volume Information\_restore{A760429D-B2C8-4A37-9C31-A7BFB448DA32}\RP108\A0020616.exe (Infected with W32/Bagle.RZ) C:\System Volume Information\_restore{A760429D-B2C8-4A37-9C31-A7BFB448DA32}\RP108\A0020617.exe (Infected with W32/Bagle.RP) C:\System Volume Information\_restore{A760429D-B2C8-4A37-9C31-A7BFB448DA32}\RP108\A0020618.exe (Infected with W32/Bagle.RX) C:\System Volume Information\_restore{A760429D-B2C8-4A37-9C31-A7BFB448DA32}\RP108\A0020619.exe (Infected with W32/Bagle.RZ) C:\System Volume Information\_restore{A760429D-B2C8-4A37-9C31-A7BFB448DA32}\RP108\A0020620.exe (Infected with W32/Bagle.RZ) C:\System Volume Information\_restore{A760429D-B2C8-4A37-9C31-A7BFB448DA32}\RP108\A0020621.exe (Infected with W32/Bagle.RX) C:\System Volume Information\_restore{A760429D-B2C8-4A37-9C31-A7BFB448DA32}\RP108\A0020622.exe (Infected with W32/Bagle.RX) C:\System Volume Information\_restore{A760429D-B2C8-4A37-9C31-A7BFB448DA32}\RP108\A0020623.exe (Infected with W32/Bagle.RZ) C:\System Volume Information\_restore{A760429D-B2C8-4A37-9C31-A7BFB448DA32}\RP108\A0020624.exe (Infected with W32/Bagle.RX) C:\System Volume Information\_restore{A760429D-B2C8-4A37-9C31-A7BFB448DA32}\RP108\A0020625.exe (Infected with W32/Bagle.RZ) C:\System Volume Information\_restore{A760429D-B2C8-4A37-9C31-A7BFB448DA32}\RP108\A0020626.exe (Infected with W32/Bagle.RX) C:\System Volume Information\_restore{A760429D-B2C8-4A37-9C31-A7BFB448DA32}\RP108\A0020627.exe (Infected with W32/Bagle.RZ) C:\System Volume Information\_restore{A760429D-B2C8-4A37-9C31-A7BFB448DA32}\RP108\A0020628.exe (Infected with W32/Bagle.RZ) C:\System Volume Information\_restore{A760429D-B2C8-4A37-9C31-A7BFB448DA32}\RP108\A0020629.exe (Infected with W32/Bagle.RX) C:\System Volume Information\_restore{A760429D-B2C8-4A37-9C31-A7BFB448DA32}\RP108\A0020630.exe (Infected with W32/Bagle.RX) C:\System Volume Information\_restore{A760429D-B2C8-4A37-9C31-A7BFB448DA32}\RP108\A0020631.exe (Infected with W32/Bagle.RZ) C:\System Volume Information\_restore{A760429D-B2C8-4A37-9C31-A7BFB448DA32}\RP108\A0020632.exe (Infected with W32/Bagle.RX) C:\System Volume Information\_restore{A760429D-B2C8-4A37-9C31-A7BFB448DA32}\RP108\A0020633.exe (Infected with W32/Bagle.RZ) C:\System Volume Information\_restore{A760429D-B2C8-4A37-9C31-A7BFB448DA32}\RP108\A0020634.exe (Infected with W32/Bagle.RS) C:\System Volume Information\_restore{A760429D-B2C8-4A37-9C31-A7BFB448DA32}\RP108\A0020635.exe (Infected with W32/Bagle.RZ) C:\System Volume Information\_restore{A760429D-B2C8-4A37-9C31-A7BFB448DA32}\RP108\A0020636.exe (Infected with W32/Bagle.RX) C:\System Volume Information\_restore{A760429D-B2C8-4A37-9C31-A7BFB448DA32}\RP108\A0020637.exe (Infected with W32/Bagle.RZ) C:\System Volume Information\_restore{A760429D-B2C8-4A37-9C31-A7BFB448DA32}\RP108\A0020638.exe (Infected with W32/Bagle.RX) C:\System Volume Information\_restore{A760429D-B2C8-4A37-9C31-A7BFB448DA32}\RP108\A0020639.exe (Infected with W32/Bagle.RX) C:\System Volume Information\_restore{A760429D-B2C8-4A37-9C31-A7BFB448DA32}\RP108\A0020640.exe (Infected with W32/Bagle.RZ) C:\System Volume Information\_restore{A760429D-B2C8-4A37-9C31-A7BFB448DA32}\RP108\A0020641.exe (Infected with W32/Bagle.RX) C:\System Volume Information\_restore{A760429D-B2C8-4A37-9C31-A7BFB448DA32}\RP108\A0020642.exe (Infected with W32/Bagle.RZ) C:\System Volume Information\_restore{A760429D-B2C8-4A37-9C31-A7BFB448DA32}\RP108\A0020643.exe (Infected with W32/Bagle.RX) C:\System Volume Information\_restore{A760429D-B2C8-4A37-9C31-A7BFB448DA32}\RP108\A0020644.exe (Infected with W32/Bagle.RZ) C:\System Volume Information\_restore{A760429D-B2C8-4A37-9C31-A7BFB448DA32}\RP108\A0020645.exe (Infected with W32/Bagle.RX) C:\System Volume Information\_restore{A760429D-B2C8-4A37-9C31-A7BFB448DA32}\RP108\A0020646.exe (Infected with W32/Bagle.RZ) C:\System Volume Information\_restore{A760429D-B2C8-4A37-9C31-A7BFB448DA32}\RP108\A0020647.exe (Infected with W32/Bagle.RX) C:\System Volume Information\_restore{A760429D-B2C8-4A37-9C31-A7BFB448DA32}\RP108\A0020648.exe (Infected with W32/Bagle.RZ) C:\System Volume Information\_restore{A760429D-B2C8-4A37-9C31-A7BFB448DA32}\RP108\A0020649.exe (Infected with W32/Bagle.RX) C:\System Volume Information\_restore{A760429D-B2C8-4A37-9C31-A7BFB448DA32}\RP108\A0020650.exe (Infected with W32/Bagle.RZ) C:\System Volume Information\_restore{A760429D-B2C8-4A37-9C31-A7BFB448DA32}\RP108\A0020651.exe (Infected with W32/Bagle.RP) C:\System Volume Information\_restore{A760429D-B2C8-4A37-9C31-A7BFB448DA32}\RP108\A0020652.exe (Infected with W32/Bagle.RX) C:\System Volume Information\_restore{A760429D-B2C8-4A37-9C31-A7BFB448DA32}\RP108\A0020653.exe (Infected with W32/Bagle.RZ) C:\System Volume Information\_restore{A760429D-B2C8-4A37-9C31-A7BFB448DA32}\RP108\A0020654.exe (Infected with W32/Bagle.RX) C:\System Volume Information\_restore{A760429D-B2C8-4A37-9C31-A7BFB448DA32}\RP108\A0020655.exe (Infected with W32/Bagle.RZ) C:\System Volume Information\_restore{A760429D-B2C8-4A37-9C31-A7BFB448DA32}\RP108\A0020656.exe (Infected with W32/Bagle.RX) C:\System Volume Information\_restore{A760429D-B2C8-4A37-9C31-A7BFB448DA32}\RP108\A0020657.exe (Infected with W32/Bagle.RZ) C:\System Volume Information\_restore{A760429D-B2C8-4A37-9C31-A7BFB448DA32}\RP108\A0020658.exe (Infected with W32/Bagle.RX) C:\System Volume Information\_restore{A760429D-B2C8-4A37-9C31-A7BFB448DA32}\RP108\A0020659.exe (Infected with W32/Bagle.RZ) C:\System Volume Information\_restore{A760429D-B2C8-4A37-9C31-A7BFB448DA32}\RP108\A0020660.exe (Infected with W32/Bagle.RZ) C:\System Volume Information\_restore{A760429D-B2C8-4A37-9C31-A7BFB448DA32}\RP108\A0020661.exe (Infected with W32/Bagle.RX) C:\System Volume Information\_restore{A760429D-B2C8-4A37-9C31-A7BFB448DA32}\RP108\A0020662.exe (Infected with W32/Bagle.RZ) C:\System Volume Information\_restore{A760429D-B2C8-4A37-9C31-A7BFB448DA32}\RP108\A0020663.exe (Infected with W32/Bagle.RX) C:\System Volume Information\_restore{A760429D-B2C8-4A37-9C31-A7BFB448DA32}\RP108\A0020664.exe (Infected with W32/Bagle.RX) C:\System Volume Information\_restore{A760429D-B2C8-4A37-9C31-A7BFB448DA32}\RP108\A0020665.exe (Infected with W32/Bagle.RZ) C:\System Volume Information\_restore{A760429D-B2C8-4A37-9C31-A7BFB448DA32}\RP108\A0020666.exe (Infected with W32/Bagle.RZ) C:\System Volume Information\_restore{A760429D-B2C8-4A37-9C31-A7BFB448DA32}\RP108\A0020667.exe (Infected with W32/Bagle.RX) C:\System Volume Information\_restore{A760429D-B2C8-4A37-9C31-A7BFB448DA32}\RP108\A0020668.exe (Infected with W32/Bagle.RS) C:\System Volume Information\_restore{A760429D-B2C8-4A37-9C31-A7BFB448DA32}\RP108\A0020669.exe (Infected with W32/Bagle.RZ) C:\System Volume Information\_restore{A760429D-B2C8-4A37-9C31-A7BFB448DA32}\RP108\A0020670.exe (Infected with W32/Bagle.RX) C:\System Volume Information\_restore{A760429D-B2C8-4A37-9C31-A7BFB448DA32}\RP108\A0020671.exe (Infected with W32/Bagle.RX) C:\System Volume Information\_restore{A760429D-B2C8-4A37-9C31-A7BFB448DA32}\RP108\A0020672.exe (Infected with W32/Bagle.RZ) C:\System Volume Information\_restore{A760429D-B2C8-4A37-9C31-A7BFB448DA32}\RP108\A0020677.exe (Infected with W32/Bagle.RX) C:\System Volume Information\_restore{A760429D-B2C8-4A37-9C31-A7BFB448DA32}\RP108\A0020682.exe (Infected with W32/Bagle.RZ) C:\System Volume Information\_restore{A760429D-B2C8-4A37-9C31-A7BFB448DA32}\RP108\A0020683.exe (Infected with W32/Bagle.RS) C:\System Volume Information\_restore{A760429D-B2C8-4A37-9C31-A7BFB448DA32}\RP108\A0020684.exe (Infected with W32/Bagle.RP) C:\System Volume Information\_restore{A760429D-B2C8-4A37-9C31-A7BFB448DA32}\RP108\A0020685.exe (Infected with W32/Bagle.RS) C:\System Volume Information\_restore{A760429D-B2C8-4A37-9C31-A7BFB448DA32}\RP108\A0020686.exe (Infected with W32/Bagle.RS) C:\System Volume Information\_restore{A760429D-B2C8-4A37-9C31-A7BFB448DA32}\RP108\A0020687.exe (Infected with W32/Bagle.RP) C:\System Volume Information\_restore{A760429D-B2C8-4A37-9C31-A7BFB448DA32}\RP108\A0020688.exe (Infected with W32/Bagle.RX) C:\System Volume Information\_restore{A760429D-B2C8-4A37-9C31-A7BFB448DA32}\RP108\A0020689.exe (Infected with W32/Bagle.RZ) C:\System Volume Information\_restore{A760429D-B2C8-4A37-9C31-A7BFB448DA32}\RP108\A0020690.exe (Infected with W32/Bagle.RX) C:\System Volume Information\_restore{A760429D-B2C8-4A37-9C31-A7BFB448DA32}\RP108\A0020691.exe (Infected with W32/Bagle.RZ) C:\System Volume Information\_restore{A760429D-B2C8-4A37-9C31-A7BFB448DA32}\RP108\A0020692.exe (Infected with W32/Bagle.RX) C:\System Volume Information\_restore{A760429D-B2C8-4A37-9C31-A7BFB448DA32}\RP108\A0020693.exe (Infected with W32/Bagle.RZ) C:\System Volume Information\_restore{A760429D-B2C8-4A37-9C31-A7BFB448DA32}\RP108\A0020694.exe (Infected with W32/Bagle.RX) C:\System Volume Information\_restore{A760429D-B2C8-4A37-9C31-A7BFB448DA32}\RP108\A0020695.exe (Infected with W32/Bagle.RZ) C:\System Volume Information\_restore{A760429D-B2C8-4A37-9C31-A7BFB448DA32}\RP108\A0020696.exe (Infected with W32/Bagle.RX) C:\System Volume Information\_restore{A760429D-B2C8-4A37-9C31-A7BFB448DA32}\RP108\A0020697.exe (Infected with W32/Bagle.RZ) C:\System Volume Information\_restore{A760429D-B2C8-4A37-9C31-A7BFB448DA32}\RP108\A0020698.exe (Infected with W32/Bagle.RX) C:\System Volume Information\_restore{A760429D-B2C8-4A37-9C31-A7BFB448DA32}\RP108\A0020699.exe (Infected with W32/Bagle.RZ) C:\System Volume Information\_restore{A760429D-B2C8-4A37-9C31-A7BFB448DA32}\RP108\A0020700.exe (Infected with W32/Bagle.RZ) C:\System Volume Information\_restore{A760429D-B2C8-4A37-9C31-A7BFB448DA32}\RP108\A0020701.exe (Infected with W32/Bagle.RX) C:\System Volume Information\_restore{A760429D-B2C8-4A37-9C31-A7BFB448DA32}\RP108\A0020702.exe (Infected with W32/Bagle.RP) C:\System Volume Information\_restore{A760429D-B2C8-4A37-9C31-A7BFB448DA32}\RP108\A0020703.exe (Infected with W32/Bagle.RZ) C:\System Volume Information\_restore{A760429D-B2C8-4A37-9C31-A7BFB448DA32}\RP108\A0020704.exe (Infected with W32/Bagle.RX) C:\System Volume Information\_restore{A760429D-B2C8-4A37-9C31-A7BFB448DA32}\RP108\A0020705.exe (Infected with W32/Bagle.RX) C:\System Volume Information\_restore{A760429D-B2C8-4A37-9C31-A7BFB448DA32}\RP108\A0020706.exe (Infected with W32/Bagle.RZ) C:\System Volume Information\_restore{A760429D-B2C8-4A37-9C31-A7BFB448DA32}\RP108\A0020707.exe (Infected with W32/Bagle.RX) C:\System Volume Information\_restore{A760429D-B2C8-4A37-9C31-A7BFB448DA32}\RP108\A0020708.exe (Infected with W32/Bagle.RZ) C:\System Volume Information\_restore{A760429D-B2C8-4A37-9C31-A7BFB448DA32}\RP108\A0020709.exe (Infected with W32/Bagle.RX) C:\System Volume Information\_restore{A760429D-B2C8-4A37-9C31-A7BFB448DA32}\RP108\A0020710.exe (Infected with W32/Bagle.RZ) C:\System Volume Information\_restore{A760429D-B2C8-4A37-9C31-A7BFB448DA32}\RP108\A0020711.exe (Infected with W32/Bagle.RX) C:\System Volume Information\_restore{A760429D-B2C8-4A37-9C31-A7BFB448DA32}\RP108\A0020712.exe (Infected with W32/Bagle.RZ) C:\System Volume Information\_restore{A760429D-B2C8-4A37-9C31-A7BFB448DA32}\RP108\A0020713.exe (Infected with W32/Bagle.RX) C:\System Volume Information\_restore{A760429D-B2C8-4A37-9C31-A7BFB448DA32}\RP108\A0020714.exe (Infected with W32/Bagle.RZ) C:\System Volume Information\_restore{A760429D-B2C8-4A37-9C31-A7BFB448DA32}\RP108\A0020715.exe (Infected with W32/Bagle.RX) C:\System Volume Information\_restore{A760429D-B2C8-4A37-9C31-A7BFB448DA32}\RP108\A0020716.exe (Infected with W32/Bagle.RZ) C:\System Volume Information\_restore{A760429D-B2C8-4A37-9C31-A7BFB448DA32}\RP108\A0020717.exe (Infected with W32/Bagle.RX) C:\System Volume Information\_restore{A760429D-B2C8-4A37-9C31-A7BFB448DA32}\RP108\A0020718.exe (Infected with W32/Bagle.RS) C:\System Volume Information\_restore{A760429D-B2C8-4A37-9C31-A7BFB448DA32}\RP108\A0020719.exe (Infected with W32/Bagle.RS) C:\System Volume Information\_restore{A760429D-B2C8-4A37-9C31-A7BFB448DA32}\RP108\A0020720.exe (Infected with W32/Bagle.RP) C:\System Volume Information\_restore{A760429D-B2C8-4A37-9C31-A7BFB448DA32}\RP108\A0020721.exe (Infected with W32/Bagle.RZ) C:\System Volume Information\_restore{A760429D-B2C8-4A37-9C31-A7BFB448DA32}\RP108\A0020722.exe (Infected with W32/Bagle.RS) C:\System Volume Information\_restore{A760429D-B2C8-4A37-9C31-A7BFB448DA32}\RP108\A0020723.exe (Infected with W32/Bagle.RP) C:\System Volume Information\_restore{A760429D-B2C8-4A37-9C31-A7BFB448DA32}\RP108\A0020724.exe (Infected with W32/Bagle.RX) C:\System Volume Information\_restore{A760429D-B2C8-4A37-9C31-A7BFB448DA32}\RP108\A0020725.exe (Infected with W32/Bagle.RZ) C:\System Volume Information\_restore{A760429D-B2C8-4A37-9C31-A7BFB448DA32}\RP108\A0020726.exe (Infected with W32/Bagle.RX) C:\System Volume Information\_restore{A760429D-B2C8-4A37-9C31-A7BFB448DA32}\RP108\A0020727.exe (Infected with W32/Bagle.RZ) C:\System Volume Information\_restore{A760429D-B2C8-4A37-9C31-A7BFB448DA32}\RP108\A0020728.exe (Infected with W32/Bagle.RX) C:\System Volume Information\_restore{A760429D-B2C8-4A37-9C31-A7BFB448DA32}\RP108\A0020729.exe (Infected with W32/Bagle.RZ) C:\System Volume Information\_restore{A760429D-B2C8-4A37-9C31-A7BFB448DA32}\RP108\A0020730.exe (Infected with W32/Bagle.RZ) C:\System Volume Information\_restore{A760429D-B2C8-4A37-9C31-A7BFB448DA32}\RP108\A0020731.exe (Infected with W32/Bagle.RX) C:\System Volume Information\_restore{A760429D-B2C8-4A37-9C31-A7BFB448DA32}\RP108\A0020732.exe (Infected with W32/Bagle.RZ) C:\System Volume Information\_restore{A760429D-B2C8-4A37-9C31-A7BFB448DA32}\RP108\A0020733.exe (Infected with W32/Bagle.RX) C:\System Volume Information\_restore{A760429D-B2C8-4A37-9C31-A7BFB448DA32}\RP108\A0020734.exe (Infected with W32/Bagle.RX) C:\System Volume Information\_restore{A760429D-B2C8-4A37-9C31-A7BFB448DA32}\RP108\A0020735.exe (Infected with W32/Bagle.RZ) C:\System Volume Information\_restore{A760429D-B2C8-4A37-9C31-A7BFB448DA32}\RP108\A0020736.exe (Infected with W32/Bagle.RX) C:\System Volume Information\_restore{A760429D-B2C8-4A37-9C31-A7BFB448DA32}\RP108\A0020737.exe (Infected with W32/Bagle.RZ) C:\System Volume Information\_restore{A760429D-B2C8-4A37-9C31-A7BFB448DA32}\RP108\A0020738.exe (Infected with W32/Bagle.RX) C:\System Volume Information\_restore{A760429D-B2C8-4A37-9C31-A7BFB448DA32}\RP108\A0020739.exe (Infected with W32/Bagle.RZ) C:\System Volume Information\_restore{A760429D-B2C8-4A37-9C31-A7BFB448DA32}\RP108\A0020740.exe (Infected with W32/Bagle.RP) C:\System Volume Information\_restore{A760429D-B2C8-4A37-9C31-A7BFB448DA32}\RP108\A0020741.exe (Infected with W32/Bagle.RX) C:\System Volume Information\_restore{A760429D-B2C8-4A37-9C31-A7BFB448DA32}\RP108\A0020742.exe (Infected with W32/Bagle.RZ) C:\System Volume Information\_restore{A760429D-B2C8-4A37-9C31-A7BFB448DA32}\RP108\A0020743.exe (Infected with W32/Bagle.RX) C:\System Volume Information\_restore{A760429D-B2C8-4A37-9C31-A7BFB448DA32}\RP108\A0020744.exe (Infected with W32/Bagle.RZ) C:\System Volume Information\_restore{A760429D-B2C8-4A37-9C31-A7BFB448DA32}\RP108\A0020745.exe (Infected with W32/Bagle.RX) C:\System Volume Information\_restore{A760429D-B2C8-4A37-9C31-A7BFB448DA32}\RP108\A0020746.exe (Infected with W32/Bagle.RZ) C:\System Volume Information\_restore{A760429D-B2C8-4A37-9C31-A7BFB448DA32}\RP108\A0020747.exe (Infected with W32/Bagle.RX) C:\System Volume Information\_restore{A760429D-B2C8-4A37-9C31-A7BFB448DA32}\RP108\A0020748.exe (Infected with W32/Bagle.RZ) C:\System Volume Information\_restore{A760429D-B2C8-4A37-9C31-A7BFB448DA32}\RP108\A0020749.exe (Infected with W32/Bagle.RX) C:\System Volume Information\_restore{A760429D-B2C8-4A37-9C31-A7BFB448DA32}\RP108\A0020750.exe (Infected with W32/Bagle.RZ) C:\System Volume Information\_restore{A760429D-B2C8-4A37-9C31-A7BFB448DA32}\RP108\A0020751.exe (Infected with W32/Bagle.RZ) C:\System Volume Information\_restore{A760429D-B2C8-4A37-9C31-A7BFB448DA32}\RP108\A0020752.exe (Infected with W32/Bagle.RX) C:\System Volume Information\_restore{A760429D-B2C8-4A37-9C31-A7BFB448DA32}\RP108\A0020753.exe (Infected with W32/Bagle.RZ) C:\System Volume Information\_restore{A760429D-B2C8-4A37-9C31-A7BFB448DA32}\RP108\A0020754.exe (Infected with W32/Bagle.RS) C:\System Volume Information\_restore{A760429D-B2C8-4A37-9C31-A7BFB448DA32}\RP108\A0020755.exe (Infected with W32/Bagle.RP) C:\System Volume Information\_restore{A760429D-B2C8-4A37-9C31-A7BFB448DA32}\RP108\A0020756.exe (Infected with W32/Bagle.RS) C:\System Volume Information\_restore{A760429D-B2C8-4A37-9C31-A7BFB448DA32}\RP108\A0020757.exe (Infected with W32/Bagle.RP) C:\System Volume Information\_restore{A760429D-B2C8-4A37-9C31-A7BFB448DA32}\RP108\A0020758.exe (Infected with W32/Bagle.RP) C:\System Volume Information\_restore{A760429D-B2C8-4A37-9C31-A7BFB448DA32}\RP108\A0020759.exe (Infected with W32/Bagle.RX) C:\System Volume Information\_restore{A760429D-B2C8-4A37-9C31-A7BFB448DA32}\RP108\A0020760.exe (Infected with W32/Bagle.RS) C:\System Volume Information\_restore{A760429D-B2C8-4A37-9C31-A7BFB448DA32}\RP108\A0020761.exe (Infected with W32/Bagle.RP) C:\System Volume Information\_restore{A760429D-B2C8-4A37-9C31-A7BFB448DA32}\RP108\A0020762.exe (Infected with W32/Bagle.RS) C:\System Volume Information\_restore{A760429D-B2C8-4A37-9C31-A7BFB448DA32}\RP108\A0020763.exe (Infected with W32/Bagle.RP) C:\System Volume Information\_restore{A760429D-B2C8-4A37-9C31-A7BFB448DA32}\RP108\A0020764.exe (Infected with W32/Bagle.RX) C:\System Volume Information\_restore{A760429D-B2C8-4A37-9C31-A7BFB448DA32}\RP108\A0020765.exe (Infected with W32/Bagle.RZ) C:\System Volume Information\_restore{A760429D-B2C8-4A37-9C31-A7BFB448DA32}\RP108\A0020766.exe (Infected with W32/Bagle.RX) C:\System Volume Information\_restore{A760429D-B2C8-4A37-9C31-A7BFB448DA32}\RP108\A0020767.exe (Infected with W32/Bagle.RZ) C:\System Volume Information\_restore{A760429D-B2C8-4A37-9C31-A7BFB448DA32}\RP108\A0020768.exe (Infected with W32/Bagle.RX) C:\System Volume Information\_restore{A760429D-B2C8-4A37-9C31-A7BFB448DA32}\RP108\A0020769.exe (Infected with W32/Bagle.RZ) C:\System Volume Information\_restore{A760429D-B2C8-4A37-9C31-A7BFB448DA32}\RP108\A0020770.exe (Infected with W32/Bagle.RX) C:\System Volume Information\_restore{A760429D-B2C8-4A37-9C31-A7BFB448DA32}\RP108\A0020771.exe (Infected with W32/Bagle.RS) C:\System Volume Information\_restore{A760429D-B2C8-4A37-9C31-A7BFB448DA32}\RP108\A0020772.exe (Infected with W32/Bagle.RP) C:\System Volume Information\_restore{A760429D-B2C8-4A37-9C31-A7BFB448DA32}\RP108\A0020773.exe (Infected with W32/Bagle.RS) C:\System Volume Information\_restore{A760429D-B2C8-4A37-9C31-A7BFB448DA32}\RP108\A0020774.exe (Infected with W32/Bagle.RP) C:\System Volume Information\_restore{A760429D-B2C8-4A37-9C31-A7BFB448DA32}\RP108\A0020775.exe (Infected with W32/Bagle.RP) C:\System Volume Information\_restore{A760429D-B2C8-4A37-9C31-A7BFB448DA32}\RP108\A0020776.exe (Infected with W32/Bagle.RS) C:\System Volume Information\_restore{A760429D-B2C8-4A37-9C31-A7BFB448DA32}\RP108\A0020777.exe (Infected with W32/Bagle.RP) C:\System Volume Information\_restore{A760429D-B2C8-4A37-9C31-A7BFB448DA32}\RP108\A0020778.exe (Infected with W32/Bagle.RS) C:\System Volume Information\_restore{A760429D-B2C8-4A37-9C31-A7BFB448DA32}\RP108\A0020779.exe (Infected with W32/Bagle.RP) C:\System Volume Information\_restore{A760429D-B2C8-4A37-9C31-A7BFB448DA32}\RP108\A0020780.exe (Infected with W32/Bagle.RS) C:\System Volume Information\_restore{A760429D-B2C8-4A37-9C31-A7BFB448DA32}\RP108\A0020781.exe (Infected with W32/Bagle.RP) C:\System Volume Information\_restore{A760429D-B2C8-4A37-9C31-A7BFB448DA32}\RP108\A0020782.exe (Infected with W32/Bagle.RS) C:\System Volume Information\_restore{A760429D-B2C8-4A37-9C31-A7BFB448DA32}\RP108\A0020783.exe (Infected with W32/Bagle.RS) C:\System Volume Information\_restore{A760429D-B2C8-4A37-9C31-A7BFB448DA32}\RP108\A0020784.exe (Infected with W32/Bagle.RP) C:\System Volume Information\_restore{A760429D-B2C8-4A37-9C31-A7BFB448DA32}\RP108\A0020785.exe (Infected with W32/Bagle.RZ) C:\System Volume Information\_restore{A760429D-B2C8-4A37-9C31-A7BFB448DA32}\RP108\A0020786.exe (Infected with W32/Bagle.RX) C:\System Volume Information\_restore{A760429D-B2C8-4A37-9C31-A7BFB448DA32}\RP108\A0020787.exe (Infected with W32/Bagle.RZ) C:\System Volume Information\_restore{A760429D-B2C8-4A37-9C31-A7BFB448DA32}\RP108\A0020788.exe (Infected with W32/Bagle.RX) C:\System Volume Information\_restore{A760429D-B2C8-4A37-9C31-A7BFB448DA32}\RP108\A0020789.exe (Infected with W32/Bagle.RS) C:\System Volume Information\_restore{A760429D-B2C8-4A37-9C31-A7BFB448DA32}\RP108\A0020790.exe (Infected with W32/Bagle.RP) C:\System Volume Information\_restore{A760429D-B2C8-4A37-9C31-A7BFB448DA32}\RP108\A0020791.exe (Infected with W32/Bagle.RS) C:\System Volume Information\_restore{A760429D-B2C8-4A37-9C31-A7BFB448DA32}\RP108\A0020792.exe (Infected with W32/Bagle.RP) C:\System Volume Information\_restore{A760429D-B2C8-4A37-9C31-A7BFB448DA32}\RP108\A0020793.exe (Infected with W32/Bagle.RZ) C:\System Volume Information\_restore{A760429D-B2C8-4A37-9C31-A7BFB448DA32}\RP108\A0020794.exe (Infected with W32/Bagle.RX) C:\System Volume Information\_restore{A760429D-B2C8-4A37-9C31-A7BFB448DA32}\RP108\A0020795.exe (Infected with W32/Bagle.RS) C:\System Volume Information\_restore{A760429D-B2C8-4A37-9C31-A7BFB448DA32}\RP108\A0020796.exe (Infected with W32/Bagle.RZ) C:\System Volume Information\_restore{A760429D-B2C8-4A37-9C31-A7BFB448DA32}\RP108\A0020797.exe (Infected with W32/Bagle.RX) C:\System Volume Information\_restore{A760429D-B2C8-4A37-9C31-A7BFB448DA32}\RP108\A0020798.exe (Infected with W32/Bagle.RZ) C:\System Volume Information\_restore{A760429D-B2C8-4A37-9C31-A7BFB448DA32}\RP108\A0020799.exe (Infected with W32/Bagle.RX) C:\System Volume Information\_restore{A760429D-B2C8-4A37-9C31-A7BFB448DA32}\RP108\A0020800.exe (Infected with W32/Bagle.RZ) C:\System Volume Information\_restore{A760429D-B2C8-4A37-9C31-A7BFB448DA32}\RP108\A0020801.exe (Infected with W32/Bagle.RX) C:\System Volume Information\_restore{A760429D-B2C8-4A37-9C31-A7BFB448DA32}\RP108\A0020802.exe (Infected with W32/Bagle.RP) C:\System Volume Information\_restore{A760429D-B2C8-4A37-9C31-A7BFB448DA32}\RP108\A0020803.exe (Infected with W32/Bagle.RZ) C:\System Volume Information\_restore{A760429D-B2C8-4A37-9C31-A7BFB448DA32}\RP108\A0020804.exe (Infected with W32/Bagle.RX) C:\System Volume Information\_restore{A760429D-B2C8-4A37-9C31-A7BFB448DA32}\RP108\A0020805.exe (Infected with W32/Bagle.RZ) C:\System Volume Information\_restore{A760429D-B2C8-4A37-9C31-A7BFB448DA32}\RP108\A0020806.exe (Infected with W32/Bagle.RX) C:\System Volume Information\_restore{A760429D-B2C8-4A37-9C31-A7BFB448DA32}\RP108\A0020807.exe (Infected with W32/Bagle.RS) C:\System Volume Information\_restore{A760429D-B2C8-4A37-9C31-A7BFB448DA32}\RP108\A0020808.exe (Infected with W32/Bagle.RZ) C:\System Volume Information\_restore{A760429D-B2C8-4A37-9C31-A7BFB448DA32}\RP108\A0020809.exe (Infected with W32/Bagle.RX) C:\System Volume Information\_restore{A760429D-B2C8-4A37-9C31-A7BFB448DA32}\RP108\A0020810.exe (Infected with W32/Bagle.RZ) C:\System Volume Information\_restore{A760429D-B2C8-4A37-9C31-A7BFB448DA32}\RP108\A0020811.exe (Infected with W32/Bagle.RX) C:\System Volume Information\_restore{A760429D-B2C8-4A37-9C31-A7BFB448DA32}\RP108\A0020812.exe (Infected with W32/Bagle.RP) C:\System Volume Information\_restore{A760429D-B2C8-4A37-9C31-A7BFB448DA32}\RP108\A0020813.exe (Infected with W32/Bagle.RZ) C:\System Volume Information\_restore{A760429D-B2C8-4A37-9C31-A7BFB448DA32}\RP108\A0020814.exe (Infected with W32/Bagle.RX) C:\System Volume Information\_restore{A760429D-B2C8-4A37-9C31-A7BFB448DA32}\RP108\A0020815.exe (Infected with W32/Bagle.RZ) C:\System Volume Information\_restore{A760429D-B2C8-4A37-9C31-A7BFB448DA32}\RP108\A0020816.exe (Infected with W32/Bagle.RX) C:\System Volume Information\_restore{A760429D-B2C8-4A37-9C31-A7BFB448DA32}\RP108\A0020817.exe (Infected with W32/Bagle.RZ) C:\System Volume Information\_restore{A760429D-B2C8-4A37-9C31-A7BFB448DA32}\RP108\A0020818.exe (Infected with W32/Bagle.RX) C:\System Volume Information\_restore{A760429D-B2C8-4A37-9C31-A7BFB448DA32}\RP108\A0020819.exe (Infected with W32/Bagle.RS) C:\System Volume Information\_restore{A760429D-B2C8-4A37-9C31-A7BFB448DA32}\RP108\A0020820.exe (Infected with W32/Bagle.RZ) C:\System Volume Information\_restore{A760429D-B2C8-4A37-9C31-A7BFB448DA32}\RP108\A0020821.exe (Infected with W32/Bagle.RX) C:\System Volume Information\_restore{A760429D-B2C8-4A37-9C31-A7BFB448DA32}\RP108\A0020822.exe (Infected with W32/Bagle.RP) C:\System Volume Information\_restore{A760429D-B2C8-4A37-9C31-A7BFB448DA32}\RP108\A0020823.exe (Infected with W32/Bagle.RS) C:\System Volume Information\_restore{A760429D-B2C8-4A37-9C31-A7BFB448DA32}\RP108\A0020824.exe (Infected with W32/Bagle.RS) C:\System Volume Information\_restore{A760429D-B2C8-4A37-9C31-A7BFB448DA32}\RP108\A0020825.exe (Infected with W32/Bagle.RP) C:\System Volume Information\_restore{A760429D-B2C8-4A37-9C31-A7BFB448DA32}\RP108\A0020826.exe (Infected with W32/Bagle.RZ) C:\System Volume Information\_restore{A760429D-B2C8-4A37-9C31-A7BFB448DA32}\RP108\A0020827.exe (Infected with W32/Bagle.RX) C:\System Volume Information\_restore{A760429D-B2C8-4A37-9C31-A7BFB448DA32}\RP108\A0020828.exe (Infected with W32/Bagle.RZ) C:\System Volume Information\_restore{A760429D-B2C8-4A37-9C31-A7BFB448DA32}\RP108\A0020829.exe (Infected with W32/Bagle.RX) C:\System Volume Information\_restore{A760429D-B2C8-4A37-9C31-A7BFB448DA32}\RP108\A0020830.exe (Infected with W32/Bagle.RS) C:\System Volume Information\_restore{A760429D-B2C8-4A37-9C31-A7BFB448DA32}\RP108\A0020831.exe (Infected with W32/Bagle.RP) C:\System Volume Information\_restore{A760429D-B2C8-4A37-9C31-A7BFB448DA32}\RP108\A0020832.exe (Infected with W32/Bagle.RP) C:\System Volume Information\_restore{A760429D-B2C8-4A37-9C31-A7BFB448DA32}\RP108\A0020833.exe (Infected with W32/Bagle.RS) C:\System Volume Information\_restore{A760429D-B2C8-4A37-9C31-A7BFB448DA32}\RP108\A0020834.exe (Infected with W32/Bagle.RP) C:\System Volume Information\_restore{A760429D-B2C8-4A37-9C31-A7BFB448DA32}\RP108\A0020835.exe (Infected with W32/Bagle.RS) C:\System Volume Information\_restore{A760429D-B2C8-4A37-9C31-A7BFB448DA32}\RP108\A0020836.exe (Infected with W32/Bagle.RP) C:\System Volume Information\_restore{A760429D-B2C8-4A37-9C31-A7BFB448DA32}\RP108\A0020837.exe (Infected with W32/Bagle.RS) C:\System Volume Information\_restore{A760429D-B2C8-4A37-9C31-A7BFB448DA32}\RP108\A0020838.exe (Infected with W32/Bagle.RZ) C:\System Volume Information\_restore{A760429D-B2C8-4A37-9C31-A7BFB448DA32}\RP108\A0020839.exe (Infected with W32/Bagle.RX) C:\System Volume Information\_restore{A760429D-B2C8-4A37-9C31-A7BFB448DA32}\RP108\A0020840.exe (Infected with W32/Bagle.RZ) C:\System Volume Information\_restore{A760429D-B2C8-4A37-9C31-A7BFB448DA32}\RP108\A0020841.exe (Infected with W32/Bagle.RX) C:\System Volume Information\_restore{A760429D-B2C8-4A37-9C31-A7BFB448DA32}\RP108\A0020842.exe (Infected with W32/Bagle.RP) C:\System Volume Information\_restore{A760429D-B2C8-4A37-9C31-A7BFB448DA32}\RP108\A0021114.exe (Infected with W32/Bagle.RY) C:\System Volume Information\_restore{A760429D-B2C8-4A37-9C31-A7BFB448DA32}\RP108\A0021115.exe (Infected with W32/Bagle.RX) C:\System Volume Information\_restore{A760429D-B2C8-4A37-9C31-A7BFB448DA32}\RP108\A0021116.exe (Infected with W32/Bagle.RY) C:\System Volume Information\_restore{A760429D-B2C8-4A37-9C31-A7BFB448DA32}\RP108\A0021177.exe (Infected with W32/Bagle.RY) C:\System Volume Information\_restore{A760429D-B2C8-4A37-9C31-A7BFB448DA32}\RP108\A0021178.exe (Infected with W32/Bagle.RY) C:\System Volume Information\_restore{A760429D-B2C8-4A37-9C31-A7BFB448DA32}\RP108\A0021225.exe (Infected with W32/Bagle.RY) C:\System Volume Information\_restore{A760429D-B2C8-4A37-9C31-A7BFB448DA32}\RP108\A0021226.exe (Infected with W32/Bagle.RY) C:\System Volume Information\_restore{A760429D-B2C8-4A37-9C31-A7BFB448DA32}\RP108\A0021228.exe (Infected with W32/Bagle.RY) C:\System Volume Information\_restore{A760429D-B2C8-4A37-9C31-A7BFB448DA32}\RP108\A0021229.exe (Infected with W32/Bagle.RY) C:\System Volume Information\_restore{A760429D-B2C8-4A37-9C31-A7BFB448DA32}\RP108\A0021239.exe (Infected with W32/Bagle.RY) C:\System Volume Information\_restore{A760429D-B2C8-4A37-9C31-A7BFB448DA32}\RP108\A0021240.exe (Infected with W32/Bagle.RY) C:\System Volume Information\_restore{A760429D-B2C8-4A37-9C31-A7BFB448DA32}\RP108\A0021241.exe (Infected with W32/Bagle.RY) C:\System Volume Information\_restore{A760429D-B2C8-4A37-9C31-A7BFB448DA32}\RP108\A0021242.exe (Infected with W32/Bagle.RY) C:\System Volume Information\_restore{A760429D-B2C8-4A37-9C31-A7BFB448DA32}\RP108\A0021243.exe (Infected with W32/Bagle.RY) C:\System Volume Information\_restore{A760429D-B2C8-4A37-9C31-A7BFB448DA32}\RP108\A0021244.exe (Infected with W32/Bagle.RY) C:\System Volume Information\_restore{A760429D-B2C8-4A37-9C31-A7BFB448DA32}\RP108\A0021245.exe (Infected with W32/Bagle.RY) C:\System Volume Information\_restore{A760429D-B2C8-4A37-9C31-A7BFB448DA32}\RP108\A0021246.exe (Infected with W32/Bagle.RY) C:\System Volume Information\_restore{A760429D-B2C8-4A37-9C31-A7BFB448DA32}\RP108\A0021247.exe (Infected with W32/Bagle.RY) C:\System Volume Information\_restore{A760429D-B2C8-4A37-9C31-A7BFB448DA32}\RP108\A0021248.exe (Infected with W32/Bagle.RY) C:\System Volume Information\_restore{A760429D-B2C8-4A37-9C31-A7BFB448DA32}\RP108\A0021251.exe (Infected with W32/Bagle.RY) C:\System Volume Information\_restore{A760429D-B2C8-4A37-9C31-A7BFB448DA32}\RP108\A0021252.exe (Infected with W32/Bagle.RY) C:\System Volume Information\_restore{A760429D-B2C8-4A37-9C31-A7BFB448DA32}\RP108\A0021253.exe (Infected with W32/Bagle.RY) C:\System Volume Information\_restore{A760429D-B2C8-4A37-9C31-A7BFB448DA32}\RP108\A0021254.exe (Infected with W32/Bagle.RY) C:\System Volume Information\_restore{A760429D-B2C8-4A37-9C31-A7BFB448DA32}\RP108\A0021255.exe (Infected with W32/Bagle.RY) C:\System Volume Information\_restore{A760429D-B2C8-4A37-9C31-A7BFB448DA32}\RP108\A0021256.exe (Infected with W32/Bagle.RY) C:\System Volume Information\_restore{A760429D-B2C8-4A37-9C31-A7BFB448DA32}\RP108\A0021257.exe (Infected with W32/Bagle.RY) C:\System Volume Information\_restore{A760429D-B2C8-4A37-9C31-A7BFB448DA32}\RP108\A0021258.exe (Infected with W32/Bagle.RY) C:\System Volume Information\_restore{A760429D-B2C8-4A37-9C31-A7BFB448DA32}\RP108\A0021259.exe (Infected with W32/Bagle.RY) C:\System Volume Information\_restore{A760429D-B2C8-4A37-9C31-A7BFB448DA32}\RP108\A0021260.exe (Infected with W32/Bagle.RY) C:\System Volume Information\_restore{A760429D-B2C8-4A37-9C31-A7BFB448DA32}\RP108\A0021265.exe (Infected with W32/Bagle.RY) C:\System Volume Information\_restore{A760429D-B2C8-4A37-9C31-A7BFB448DA32}\RP108\A0021266.exe (Infected with W32/Bagle.RY) C:\System Volume Information\_restore{A760429D-B2C8-4A37-9C31-A7BFB448DA32}\RP108\A0021270.exe (Infected with W32/Bagle.RY) C:\System Volume Information\_restore{A760429D-B2C8-4A37-9C31-A7BFB448DA32}\RP108\A0021271.exe (Infected with W32/Bagle.RY) C:\System Volume Information\_restore{A760429D-B2C8-4A37-9C31-A7BFB448DA32}\RP108\A0021272.exe (Infected with W32/Bagle.RY) C:\System Volume Information\_restore{A760429D-B2C8-4A37-9C31-A7BFB448DA32}\RP108\A0021273.exe (Infected with W32/Bagle.RY) C:\System Volume Information\_restore{A760429D-B2C8-4A37-9C31-A7BFB448DA32}\RP108\A0021276.exe (Infected with W32/Bagle.RY) C:\System Volume Information\_restore{A760429D-B2C8-4A37-9C31-A7BFB448DA32}\RP108\A0021277.exe (Infected with W32/Bagle.RY) C:\System Volume Information\_restore{A760429D-B2C8-4A37-9C31-A7BFB448DA32}\RP108\A0021278.exe (Infected with W32/Bagle.RY) C:\System Volume Information\_restore{A760429D-B2C8-4A37-9C31-A7BFB448DA32}\RP108\A0021279.exe (Infected with W32/Bagle.RY) C:\System Volume Information\_restore{A760429D-B2C8-4A37-9C31-A7BFB448DA32}\RP108\A0021280.exe (Infected with W32/Bagle.RY) C:\System Volume Information\_restore{A760429D-B2C8-4A37-9C31-A7BFB448DA32}\RP108\A0021281.exe (Infected with W32/Bagle.RY) C:\System Volume Information\_restore{A760429D-B2C8-4A37-9C31-A7BFB448DA32}\RP111\A0022893.exe (Infected with W32/Bagle.RP) C:\System Volume Information\_restore{A760429D-B2C8-4A37-9C31-A7BFB448DA32}\RP111\A0022894.exe (Infected with W32/Bagle.RX) C:\System Volume Information\_restore{A760429D-B2C8-4A37-9C31-A7BFB448DA32}\RP111\A0022895.exe (Infected with W32/Bagle.RZ) C:\System Volume Information\_restore{A760429D-B2C8-4A37-9C31-A7BFB448DA32}\RP111\A0022896.exe (Infected with W32/Bagle.RX) C:\System Volume Information\_restore{A760429D-B2C8-4A37-9C31-A7BFB448DA32}\RP111\A0022897.exe (Infected with W32/Bagle.RZ) C:\System Volume Information\_restore{A760429D-B2C8-4A37-9C31-A7BFB448DA32}\RP111\A0022898.exe (Infected with W32/Bagle.RS) C:\System Volume Information\_restore{A760429D-B2C8-4A37-9C31-A7BFB448DA32}\RP111\A0022899.exe (Infected with W32/Bagle.RP) C:\System Volume Information\_restore{A760429D-B2C8-4A37-9C31-A7BFB448DA32}\RP111\A0022900.exe (Infected with W32/Bagle.RS) C:\System Volume Information\_restore{A760429D-B2C8-4A37-9C31-A7BFB448DA32}\RP111\A0022901.exe (Infected with W32/Bagle.RP) C:\System Volume Information\_restore{A760429D-B2C8-4A37-9C31-A7BFB448DA32}\RP111\A0022902.exe (Infected with W32/Bagle.RS) C:\System Volume Information\_restore{A760429D-B2C8-4A37-9C31-A7BFB448DA32}\RP111\A0022903.exe (Infected with W32/Bagle.RP) C:\System Volume Information\_restore{A760429D-B2C8-4A37-9C31-A7BFB448DA32}\RP111\A0022904.exe (Infected with W32/Bagle.RP) C:\System Volume Information\_restore{A760429D-B2C8-4A37-9C31-A7BFB448DA32}\RP111\A0022905.exe (Infected with W32/Bagle.RS) C:\System Volume Information\_restore{A760429D-B2C8-4A37-9C31-A7BFB448DA32}\RP111\A0022906.exe (Infected with W32/Bagle.RX) C:\System Volume Information\_restore{A760429D-B2C8-4A37-9C31-A7BFB448DA32}\RP111\A0022907.exe (Infected with W32/Bagle.RZ) C:\System Volume Information\_restore{A760429D-B2C8-4A37-9C31-A7BFB448DA32}\RP111\A0022908.exe (Infected with W32/Bagle.RX) C:\System Volume Information\_restore{A760429D-B2C8-4A37-9C31-A7BFB448DA32}\RP111\A0022909.exe (Infected with W32/Bagle.RZ) C:\System Volume Information\_restore{A760429D-B2C8-4A37-9C31-A7BFB448DA32}\RP111\A0022910.exe (Infected with W32/Bagle.RP) C:\System Volume Information\_restore{A760429D-B2C8-4A37-9C31-A7BFB448DA32}\RP111\A0022911.exe (Infected with W32/Bagle.RS) C:\System Volume Information\_restore{A760429D-B2C8-4A37-9C31-A7BFB448DA32}\RP111\A0022912.exe (Infected with W32/Bagle.RS) C:\System Volume Information\_restore{A760429D-B2C8-4A37-9C31-A7BFB448DA32}\RP111\A0022913.exe (Infected with W32/Bagle.RP) C:\System Volume Information\_restore{A760429D-B2C8-4A37-9C31-A7BFB448DA32}\RP111\A0022914.exe (Infected with W32/Bagle.RX) C:\System Volume Information\_restore{A760429D-B2C8-4A37-9C31-A7BFB448DA32}\RP111\A0022915.exe (Infected with W32/Bagle.RZ) C:\System Volume Information\_restore{A760429D-B2C8-4A37-9C31-A7BFB448DA32}\RP111\A0022916.exe (Infected with W32/Bagle.RS) C:\System Volume Information\_restore{A760429D-B2C8-4A37-9C31-A7BFB448DA32}\RP111\A0022917.exe (Infected with W32/Bagle.RX) C:\System Volume Information\_restore{A760429D-B2C8-4A37-9C31-A7BFB448DA32}\RP111\A0022918.exe (Infected with W32/Bagle.RZ) C:\System Volume Information\_restore{A760429D-B2C8-4A37-9C31-A7BFB448DA32}\RP111\A0022919.exe (Infected with W32/Bagle.RX) C:\System Volume Information\_restore{A760429D-B2C8-4A37-9C31-A7BFB448DA32}\RP111\A0022920.exe (Infected with W32/Bagle.RZ) C:\System Volume Information\_restore{A760429D-B2C8-4A37-9C31-A7BFB448DA32}\RP111\A0022921.exe (Infected with W32/Bagle.RX) C:\System Volume Information\_restore{A760429D-B2C8-4A37-9C31-A7BFB448DA32}\RP111\A0022922.exe (Infected with W32/Bagle.RZ) C:\System Volume Information\_restore{A760429D-B2C8-4A37-9C31-A7BFB448DA32}\RP111\A0022923.exe (Infected with W32/Bagle.RP) C:\System Volume Information\_restore{A760429D-B2C8-4A37-9C31-A7BFB448DA32}\RP111\A0022924.exe (Infected with W32/Bagle.RX) C:\System Volume Information\_restore{A760429D-B2C8-4A37-9C31-A7BFB448DA32}\RP111\A0022925.exe (Infected with W32/Bagle.RZ) C:\System Volume Information\_restore{A760429D-B2C8-4A37-9C31-A7BFB448DA32}\RP111\A0022926.exe (Infected with W32/Bagle.RX) C:\System Volume Information\_restore{A760429D-B2C8-4A37-9C31-A7BFB448DA32}\RP111\A0022927.exe (Infected with W32/Bagle.RZ) C:\System Volume Information\_restore{A760429D-B2C8-4A37-9C31-A7BFB448DA32}\RP111\A0022928.exe (Infected with W32/Bagle.RS) C:\System Volume Information\_restore{A760429D-B2C8-4A37-9C31-A7BFB448DA32}\RP111\A0022929.exe (Infected with W32/Bagle.RX) C:\System Volume Information\_restore{A760429D-B2C8-4A37-9C31-A7BFB448DA32}\RP111\A0022930.exe (Infected with W32/Bagle.RZ) C:\System Volume Information\_restore{A760429D-B2C8-4A37-9C31-A7BFB448DA32}\RP111\A0022931.exe (Infected with W32/Bagle.RX) C:\System Volume Information\_restore{A760429D-B2C8-4A37-9C31-A7BFB448DA32}\RP111\A0022932.exe (Infected with W32/Bagle.RZ) C:\System Volume Information\_restore{A760429D-B2C8-4A37-9C31-A7BFB448DA32}\RP111\A0022933.exe (Infected with W32/Bagle.RP) C:\System Volume Information\_restore{A760429D-B2C8-4A37-9C31-A7BFB448DA32}\RP111\A0022934.exe (Infected with W32/Bagle.RX) C:\System Volume Information\_restore{A760429D-B2C8-4A37-9C31-A7BFB448DA32}\RP111\A0022935.exe (Infected with W32/Bagle.RZ) C:\System Volume Information\_restore{A760429D-B2C8-4A37-9C31-A7BFB448DA32}\RP111\A0022936.exe (Infected with W32/Bagle.RX) C:\System Volume Information\_restore{A760429D-B2C8-4A37-9C31-A7BFB448DA32}\RP111\A0022937.exe (Infected with W32/Bagle.RZ) C:\System Volume Information\_restore{A760429D-B2C8-4A37-9C31-A7BFB448DA32}\RP111\A0022938.exe (Infected with W32/Bagle.RX) C:\System Volume Information\_restore{A760429D-B2C8-4A37-9C31-A7BFB448DA32}\RP111\A0022939.exe (Infected with W32/Bagle.RZ) C:\System Volume Information\_restore{A760429D-B2C8-4A37-9C31-A7BFB448DA32}\RP111\A0022940.exe (Infected with W32/Bagle.RS) C:\System Volume Information\_restore{A760429D-B2C8-4A37-9C31-A7BFB448DA32}\RP111\A0022941.exe (Infected with W32/Bagle.RX) C:\System Volume Information\_restore{A760429D-B2C8-4A37-9C31-A7BFB448DA32}\RP111\A0022942.exe (Infected with W32/Bagle.RZ) C:\System Volume Information\_restore{A760429D-B2C8-4A37-9C31-A7BFB448DA32}\RP111\A0022943.exe (Infected with W32/Bagle.RP) C:\System Volume Information\_restore{A760429D-B2C8-4A37-9C31-A7BFB448DA32}\RP111\A0022944.exe (Infected with W32/Bagle.RS) C:\System Volume Information\_restore{A760429D-B2C8-4A37-9C31-A7BFB448DA32}\RP111\A0022945.exe (Infected with W32/Bagle.RP) C:\System Volume Information\_restore{A760429D-B2C8-4A37-9C31-A7BFB448DA32}\RP111\A0022946.exe (Infected with W32/Bagle.RS) C:\System Volume Information\_restore{A760429D-B2C8-4A37-9C31-A7BFB448DA32}\RP111\A0022947.exe (Infected with W32/Bagle.RX) C:\System Volume Information\_restore{A760429D-B2C8-4A37-9C31-A7BFB448DA32}\RP111\A0022948.exe (Infected with W32/Bagle.RZ) C:\System Volume Information\_restore{A760429D-B2C8-4A37-9C31-A7BFB448DA32}\RP111\A0022949.exe (Infected with W32/Bagle.RX) C:\System Volume Information\_restore{A760429D-B2C8-4A37-9C31-A7BFB448DA32}\RP111\A0022950.exe (Infected with W32/Bagle.RZ) C:\System Volume Information\_restore{A760429D-B2C8-4A37-9C31-A7BFB448DA32}\RP111\A0022951.exe (Infected with W32/Bagle.RP) C:\System Volume Information\_restore{A760429D-B2C8-4A37-9C31-A7BFB448DA32}\RP111\A0022952.exe (Infected with W32/Bagle.RS) C:\System Volume Information\_restore{A760429D-B2C8-4A37-9C31-A7BFB448DA32}\RP111\A0022953.exe (Infected with W32/Bagle.RS) C:\System Volume Information\_restore{A760429D-B2C8-4A37-9C31-A7BFB448DA32}\RP111\A0022954.exe (Infected with W32/Bagle.RP) C:\System Volume Information\_restore{A760429D-B2C8-4A37-9C31-A7BFB448DA32}\RP111\A0022955.exe (Infected with W32/Bagle.RS) C:\System Volume Information\_restore{A760429D-B2C8-4A37-9C31-A7BFB448DA32}\RP111\A0022956.exe (Infected with W32/Bagle.RP) C:\System Volume Information\_restore{A760429D-B2C8-4A37-9C31-A7BFB448DA32}\RP111\A0022957.exe (Infected with W32/Bagle.RS) C:\System Volume Information\_restore{A760429D-B2C8-4A37-9C31-A7BFB448DA32}\RP111\A0022958.exe (Infected with W32/Bagle.RP) C:\System Volume Information\_restore{A760429D-B2C8-4A37-9C31-A7BFB448DA32}\RP111\A0022959.exe (Infected with W32/Bagle.RS) C:\System Volume Information\_restore{A760429D-B2C8-4A37-9C31-A7BFB448DA32}\RP111\A0022960.exe (Infected with W32/Bagle.RP) C:\System Volume Information\_restore{A760429D-B2C8-4A37-9C31-A7BFB448DA32}\RP111\A0022961.exe (Infected with W32/Bagle.RP) C:\System Volume Information\_restore{A760429D-B2C8-4A37-9C31-A7BFB448DA32}\RP111\A0022962.exe (Infected with W32/Bagle.RS) C:\System Volume Information\_restore{A760429D-B2C8-4A37-9C31-A7BFB448DA32}\RP111\A0022963.exe (Infected with W32/Bagle.RP) C:\System Volume Information\_restore{A760429D-B2C8-4A37-9C31-A7BFB448DA32}\RP111\A0022964.exe (Infected with W32/Bagle.RS) C:\System Volume Information\_restore{A760429D-B2C8-4A37-9C31-A7BFB448DA32}\RP111\A0022965.exe (Infected with W32/Bagle.RX) C:\System Volume Information\_restore{A760429D-B2C8-4A37-9C31-A7BFB448DA32}\RP111\A0022966.exe (Infected with W32/Bagle.RZ) C:\System Volume Information\_restore{A760429D-B2C8-4A37-9C31-A7BFB448DA32}\RP111\A0022967.exe (Infected with W32/Bagle.RX) C:\System Volume Information\_restore{A760429D-B2C8-4A37-9C31-A7BFB448DA32}\RP111\A0022968.exe (Infected with W32/Bagle.RZ) C:\System Volume Information\_restore{A760429D-B2C8-4A37-9C31-A7BFB448DA32}\RP111\A0022969.exe (Infected with W32/Bagle.RX) C:\System Volume Information\_restore{A760429D-B2C8-4A37-9C31-A7BFB448DA32}\RP111\A0022970.exe (Infected with W32/Bagle.RZ) C:\System Volume Information\_restore{A760429D-B2C8-4A37-9C31-A7BFB448DA32}\RP111\A0022971.exe (Infected with W32/Bagle.RX) C:\System Volume Information\_restore{A760429D-B2C8-4A37-9C31-A7BFB448DA32}\RP111\A0022972.exe (Infected with W32/Bagle.RP) C:\System Volume Information\_restore{A760429D-B2C8-4A37-9C31-A7BFB448DA32}\RP111\A0022973.exe (Infected with W32/Bagle.RS) C:\System Volume Information\_restore{A760429D-B2C8-4A37-9C31-A7BFB448DA32}\RP111\A0022974.exe (Infected with W32/Bagle.RP) C:\System Volume Information\_restore{A760429D-B2C8-4A37-9C31-A7BFB448DA32}\RP111\A0022975.exe (Infected with W32/Bagle.RS) C:\System Volume Information\_restore{A760429D-B2C8-4A37-9C31-A7BFB448DA32}\RP111\A0022976.exe (Infected with W32/Bagle.RX) C:\System Volume Information\_restore{A760429D-B2C8-4A37-9C31-A7BFB448DA32}\RP111\A0022977.exe (Infected with W32/Bagle.RP) C:\System Volume Information\_restore{A760429D-B2C8-4A37-9C31-A7BFB448DA32}\RP111\A0022978.exe (Infected with W32/Bagle.RP) C:\System Volume Information\_restore{A760429D-B2C8-4A37-9C31-A7BFB448DA32}\RP111\A0022979.exe (Infected with W32/Bagle.RS) C:\System Volume Information\_restore{A760429D-B2C8-4A37-9C31-A7BFB448DA32}\RP111\A0022980.exe (Infected with W32/Bagle.RP) C:\System Volume Information\_restore{A760429D-B2C8-4A37-9C31-A7BFB448DA32}\RP111\A0022981.exe (Infected with W32/Bagle.RS) C:\System Volume Information\_restore{A760429D-B2C8-4A37-9C31-A7BFB448DA32}\RP111\A0022982.exe (Infected with W32/Bagle.RZ) C:\System Volume Information\_restore{A760429D-B2C8-4A37-9C31-A7BFB448DA32}\RP111\A0022983.exe (Infected with W32/Bagle.RX) C:\System Volume Information\_restore{A760429D-B2C8-4A37-9C31-A7BFB448DA32}\RP111\A0022984.exe (Infected with W32/Bagle.RZ) C:\System Volume Information\_restore{A760429D-B2C8-4A37-9C31-A7BFB448DA32}\RP111\A0022985.exe (Infected with W32/Bagle.RZ) C:\System Volume Information\_restore{A760429D-B2C8-4A37-9C31-A7BFB448DA32}\RP111\A0022986.exe (Infected with W32/Bagle.RX) C:\System Volume Information\_restore{A760429D-B2C8-4A37-9C31-A7BFB448DA32}\RP111\A0022987.exe (Infected with W32/Bagle.RZ) C:\System Volume Information\_restore{A760429D-B2C8-4A37-9C31-A7BFB448DA32}\RP111\A0022988.exe (Infected with W32/Bagle.RX) C:\System Volume Information\_restore{A760429D-B2C8-4A37-9C31-A7BFB448DA32}\RP111\A0022989.exe (Infected with W32/Bagle.RZ) C:\System Volume Information\_restore{A760429D-B2C8-4A37-9C31-A7BFB448DA32}\RP111\A0022990.exe (Infected with W32/Bagle.RX) C:\System Volume Information\_restore{A760429D-B2C8-4A37-9C31-A7BFB448DA32}\RP111\A0022991.exe (Infected with W32/Bagle.RZ) C:\System Volume Information\_restore{A760429D-B2C8-4A37-9C31-A7BFB448DA32}\RP111\A0022992.exe (Infected with W32/Bagle.RX) C:\System Volume Information\_restore{A760429D-B2C8-4A37-9C31-A7BFB448DA32}\RP111\A0022993.exe (Infected with W32/Bagle.RZ) C:\System Volume Information\_restore{A760429D-B2C8-4A37-9C31-A7BFB448DA32}\RP111\A0022994.exe (Infected with W32/Bagle.RX) |
|
|
|
|
|
her fra rootlog ********************************* ROOTCHK-LOG
|
|
|
|
|
|
Det er et godt link, du har lagt der, og det viser tydeligt, at du har et rootkit, som vi skal have gjort kål på. Jeg overfører derfor tråden til Rootkit-kategorien. Der gælder nogle særlige forhold for supporten i denne kategori, som du kan læse om her: http://www.spywarefri.dk/forum/topic.asp?TOPIC_ID=29320 Start med følgende: Installér programmet. Kør så RKU. Klik på fanebladet “Report”, klik på knappen “Scan”. Lad programmet skanne færdig, klik på “File-Save Report”, og gem rapporten et sted, hvor du kan finde den igen. Læg indholdet af denne rapport herind. |
|
|
|
|
|
Hent også dette værktøj, og gem det på dit skrivebord: Kør programmet. Efter kort tid vil der dukke en logfil op, som kan findes her C:\rootlog txt. Kopier indholdet af denne log herind i tråden. |
|
|
|
|
|
er gjort >SSDT State NtCreateFile NtCreateKey NtCreateProcess NtCreateProcessEx NtCreateThread NtDeleteFile NtDeleteKey NtDeleteValueKey NtLoadKey NtOpenFile NtQueueApcThread NtReadVirtualMemory NtRenameKey NtReplaceKey NtRestoreKey NtSetContextThread NtSetInformationFile NtSetInformationKey NtSetInformationProcess NtSetInformationThread NtSetValueKey NtSuspendProcess NtSuspendThread NtTerminateProcess NtTerminateThread NtWriteVirtualMemory >Processes |
|
|
|
|
|
Så mangler du bare loggen fra driverchk… |
|
|
|
|
|
com vil ikke køre driverchk…. vender tilbage senere |
|
|
|
|
|
So sorry [:o)] , der var en bug i den fil, som jeg havde uploadet. Prøv lige at hente en ny version. Så skulle den virke [:I] |
|
|
|
|
|
her hvad jeg fik ud af driverchk
|
|
|
|
|
|
mange tak for hjælpen alle sammen… det har været meget lærerigt.. Grundet tidmangel valgte jeg at bruge genoprettelses cdérne som jeg skabte tidligere. Her kunne jeg vælge mellem to modes… den ene hvor jeg gendannede men beholdte data og den anden hvor jeg formaterede harddisken.. Jeg valgte den første, hvilket har resulteret i at der er flere ting der skal geninstalleres igen men også en stor del er stadig bevaret. det virkede fint og fejlsikker tilstand og zonealarm virker også ... har ikke prøvet systemgendannelse endnu, det venter jeg lidt med. er der nogle der kender til zonealarm må de gerne fortælle mig hvilken besked jeg skal passe på..da jeg lige nu ser rimelig sort bare på en sådan her Generic Host Process for Win32 services wants to accept connections from the trusted zone. Er dette min internetopkobling der spørger zonealarm om adgang eller hvad ??? svar udbedes helst
Logfile of HijackThis v1.99.1 Running processes: R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.spywarefri.dk/ ser dette fornuftigt ud eller ligger ormen og arbejder stadig ?????????????????????? |
|
|
|
|
|
Jeg må ærligt indrømme, at jeg nu ikke længere har helt overblik over situationen på din computer, fordi jeg ikke ved hvad din gendannelses-cd har foretaget sig. Der er ikke noget at se i HJT-loggen, men det har der ikke været længe. Kan du ikke prøve at gå ind i registreringsdatabasen, og se om du stadig kan finde m_hook entryen? Hvis du vil være HELT sikker på at være fri for skidtet skulle du nok have valgt formaterings-løsningen. Grunden til dette er, at de fleste gendannelses-værktøjer ikke hverken sletter filer, eller ændrer på registreringsdatabasen. Og så kan skidt godt overleve. Angående ZA’s forespørgsel, så må denne proces gerne få adgang. Bemærk at det kan være en god ide at få opdateret dit windows. Du er nu kun sikret med ServicePack1, og bør som det mindste også få lagt ServicePack2 ind. |
|