Win32:TratBHO prosze o pilną pomoc

Witam mam wirusa Win32:TratBHO zrobilem juz log z ComboFix.exe i wklejam go tutaj co musze zrobić proszę o pomoc. Dziękuję.

ComboFix 08-01-11.3 - Maciej 2008-01-12 15:42:49.1 - NTFSx86

Microsoft Windows XP Professional 5.1.2600.0.1250.1.1045.18.235 [GMT 1:00]

Running from: C:\Documents and Settings\Maciej\Pulpit\ComboFix.exe

* Created a new restore point

.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))

.

C:\Documents and Settings\Maciej\Dane aplikacji\macromedia\Flash Player#SharedObjects\VN49NDUG\www.broadcaster.com

C:\Documents and Settings\Maciej\Dane aplikacji\macromedia\Flash Player\macromedia.com\support\flashplayer\sys#www.broadcaster.com

C:\Documents and Settings\Maciej\Dane aplikacji\macromedia\Flash Player\macromedia.com\support\flashplayer\sys#www.broadcaster.com\settings.sol

C:\WINDOWS\cookies.ini

C:\WINDOWS\system32\cldgbrcf.dll

C:\WINDOWS\system32\ctfmon.exe.tmp

C:\WINDOWS\system32\fcrbgdlc.ini

C:\WINDOWS\system32\gyoeodcd.dll

C:\WINDOWS\system32\Spy_File_kuqjgnib.dll

C:\WINDOWS\system32\ssttt.dll

C:\WINDOWS\system32\tttss.ini2

C:\WINDOWS\system32\tuvtuvw.dll

.

((((((((((((((((((((((((( Files Created from 2007-12-12 to 2008-01-12 )))))))))))))))))))))))))))))))

.

2008-01-23 23:03 . 2008-01-06 15:20 13,312 --a------ C:\WINDOWS\system32\ctfmon .exe

2008-01-12 15:41 . 2000-08-31 08:00 51,200 --a------ C:\WINDOWS\NirCmd.exe

2008-01-12 15:29 . 2008-01-12 15:29

2008-01-12 15:29 . 2008-01-12 15:49

2008-01-09 08:53 . 2008-01-12 15:29

2008-01-09 08:53 . 2007-10-18 00:16 79,688 --a------ C:\WINDOWS\system32\drivers\iksyssec.sys

2008-01-09 08:53 . 2007-10-18 00:15 62,280 --a------ C:\WINDOWS\system32\drivers\iksysflt.sys

2008-01-09 08:53 . 2007-10-18 00:14 41,288 --a------ C:\WINDOWS\system32\drivers\ikfilesec.sys

2008-01-09 08:53 . 2007-10-18 00:16 29,000 --a------ C:\WINDOWS\system32\drivers\kcom.sys

2008-01-09 08:52 . 2005-09-23 08:29 626,688 --a------ C:\WINDOWS\system32\msvcr80.dll

2008-01-08 22:03 . 2008-01-08 22:03

2008-01-08 22:03 . 2008-01-08 22:03

2008-01-08 17:28 . 2007-12-04 14:04 837,496 --a------ C:\WINDOWS\system32\aswBoot.exe

2008-01-08 17:28 . 2004-01-09 10:13 380,928 --a------ C:\WINDOWS\system32\actskin4.ocx

2008-01-08 17:28 . 2007-12-04 13:54 95,608 --a------ C:\WINDOWS\system32\AvastSS.scr

2008-01-08 17:28 . 2007-12-04 15:55 94,544 --a------ C:\WINDOWS\system32\drivers\aswmon2.sys

2008-01-08 17:28 . 2007-12-04 15:56 93,264 --a------ C:\WINDOWS\system32\drivers\aswmon.sys

2008-01-08 17:28 . 2007-12-04 15:51 42,912 --a------ C:\WINDOWS\system32\drivers\aswTdi.sys

2008-01-08 17:28 . 2007-12-04 15:49 26,624 --a------ C:\WINDOWS\system32\drivers\aavmker4.sys

2008-01-08 17:28 . 2007-12-04 15:53 23,152 --a------ C:\WINDOWS\system32\drivers\aswRdr.sys

2008-01-08 17:27 . 2008-01-08 17:27

2008-01-02 23:53 . 2001-05-04 12:05 413,760 --a------ C:\WINDOWS\mpg4c32.dll

2008-01-02 23:53 . 2003-12-22 17:59 405,504 --a------ C:\WINDOWS\GeoCodec.dll

2008-01-02 23:53 . 2003-12-22 17:56 176,128 --a------ C:\WINDOWS\GeoCodecLib.dll

2007-12-15 20:33 . 2007-12-15 20:33 54,156 --ah----- C:\WINDOWS\QTFont.qfn

2007-12-15 20:33 . 2007-12-15 20:33 1,409 --a------ C:\WINDOWS\QTFont.for

2007-12-13 00:51 . 2008-01-27 18:48

2007-12-13 00:51 . 2008-01-26 17:52

2007-12-12 16:31 . 2008-01-12 15:29

.

(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))

.

2008-01-26 16:52 --------- d-----w C:\Program Files\Skype

2008-01-22 20:46 --------- d-----w C:\Program Files\EA SPORTS

2008-01-12 14:49 323,072 ----a-w C:\WINDOWS\system32\ssttt.dll

2008-01-08 16:31 --------- d-----w C:\Program Files\Gadu-Gadu

2008-01-08 15:45 --------- d-----w C:\Program Files\Common Files\Symantec Shared

2008-01-08 15:43 --------- d-----w C:\Documents and Settings\All Users\Dane aplikacji\Symantec

2008-01-08 15:42 --------- d-----w C:\Program Files\Symantec

2008-01-06 22:24 --------- d–h--w C:\Program Files\InstallShield Installation Information

2008-01-06 22:11 --------- d-----w C:\Program Files\SyrenkaRacer

2008-01-06 22:08 --------- d-----w C:\Program Files\City Interactive

2007-12-20 17:22 --------- d-----w C:\Program Files\Java

2007-12-18 14:53 --------- d-----w C:\Documents and Settings\Maciej\Dane aplikacji\Datalayer

2007-12-05 16:57 11,973 ----a-w C:\WINDOWS\system32\drivers\secdrv.sys

2007-11-18 22:30 724,992 ----a-w C:\WINDOWS\iun6002.exe

2007-10-31 22:00 16,760 ----a-w C:\Documents and Settings\Maciej\Dane aplikacji\GDIPFONTCACHEV1.DAT

2004-10-01 14:00 40,960 ----a-w C:\Program Files\Uninstall_CDS.exe

2001-11-23 04:08 712,704 ----a-w C:\WINDOWS\inf\OTHER\audio3d.dll

.

----a-w 50,864 2008-01-28 09:41:29 C:\Program Files\Common Files\Symantec Shared\ccApp .exe

----a-w 34,488 2008-01-26 10:18:40 C:\Program Files\Common Files\Symantec Shared\ccRegVfy .exe

----a-w 1,716,224 2008-01-06 22:31:53 C:\Program Files\Gadu-Gadu\gg .exe

----a-w 1,716,224 2008-01-08 15:41:26 C:\Program Files\Gadu-Gadu\gg .exe

----a-w 2,131,392 2008-01-08 16:31:19 C:\Program Files\Gadu-Gadu\gg .exe

----a-w 2,492,928 2008-01-08 16:19:38 C:\Program Files\Gadu-Gadu\gg .exe

----a-w 229,376 2008-01-30 23:19:55 C:\Program Files\Nokia\Nokia PC Suite 6\LaunchApplication .exe

----a-w 229,376 2008-01-12 14:49:58 C:\Program Files\Nokia\Nokia PC Suite 6\LAUNCH~1 .EXE

----a-w 25,693,224 2008-01-27 17:47:06 C:\Program Files\Skype\Phone\Skype .exe

----a-w 3,712,512 2008-01-08 16:31:23 C:\spywarebegone\SpywareBeGone .exe

----a-w 4,051,456 2008-01-08 16:19:38 C:\spywarebegone\SpywareBeGone .exe

----a-w 4,051,456 2008-01-08 15:42:47 C:\spywarebegone\SpywareBeGone .exe

----a-w 13,312 2008-01-06 14:20:40 C:\WINDOWS\system32\ctfmon .exe

[/code]

((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))

.

.

*Note* empty entries & legit default entries are not shown

REGEDIT4

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]

“CTFMON.EXE”=“C:\WINDOWS\System32\ctfmon.exe” []

“Gadu-Gadu”=“C:\Program Files\Gadu-Gadu\gg .exe” [2008-01-08 17:31 2131392]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]

“PCSuiteTrayApplication”=“C:\PROGRA~1\Nokia\NOKIAP~1\LAUNCH~1.exe” [2008-01-08 16:42 572416]

“avast!”=“C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe” [2007-12-04 14:00 79224]

“SDTray”=“C:\Program Files\Spyware Doctor\SDTrayApp.exe” [2007-11-02 17:24 1065800]

[HKEY_USERS.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]

“CTFMON.EXE”=“C:\WINDOWS\System32\CTFMON.EXE” []

C:\Documents and Settings\All Users\Menu Start\Programy\Autostart\

Microsoft Office.lnk - C:\Program Files\Microsoft Office\Office10\OSA.EXE [2001-02-13 10:01:04]

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\explorer]

“NoInstrumentation”= 1 (0x1)

S3 ZSMC302;VIMICRO USB PC Camera;C:\WINDOWS\System32\Drivers\usbVM31b.sys [2004-09-07 08:11]

.

Contents of the ‘Scheduled Tasks’ folder

“2007-11-08 17:43:08 C:\WINDOWS\Tasks\Symantec NetDetect.job”

  • C:\Program Files\Symantec\LiveUpdate\NDETECT.EXE

.

**************************************************************************

catchme 0.3.1344 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net

Rootkit scan 2008-01-12 15:50:40

Windows 5.1.2600 NTFS

scanning hidden processes …

scanning hidden autostart entries …

scanning hidden files …

scan completed successfully

hidden files: 0

**************************************************************************

.

Completion time: 2008-01-12 15:52:24 - machine was rebooted

ComboFix-quarantined-files.txt 2008-01-12 14:52:18

jakiego masz antyvira ?

Mam Avast

Złapałeś Vundo podmienił dobre plik, programy po usunieciu musisz reinstalować

Wklej do Notatnika:

File::

C:\WINDOWS\system32\ctfmon .exe

C:\WINDOWS\NirCmd.exe 

C:\Program Files\Common Files\Symantec Shared\ccApp .exe

C:\Program Files\Common Files\Symantec Shared\ccRegVfy .exe

C:\Program Files\Gadu-Gadu\gg .exe

C:\Program Files\Gadu-Gadu\gg .exe

C:\Program Files\Gadu-Gadu\gg .exe

C:\Program Files\Gadu-Gadu\gg .exe

C:\Program Files\Nokia\Nokia PC Suite 6\LaunchApplication .exe

C:\Program Files\Nokia\Nokia PC Suite 6\LAUNCH~1 .EXE

C:\Program Files\Skype\Phone\Skype .exe

C:\spywarebegone\SpywareBeGone .exe

C:\spywarebegone\SpywareBeGone .exe

C:\spywarebegone\SpywareBeGone .exe

C:\WINDOWS\system32\ctfmon .exe


Registry::

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]

"CTFMON.EXE"=-

"Gadu-Gadu"=-

>>Plik>>Zapisz jako… >>> CFScript (najwygodniej będzie, jeśli zapiszesz w takiej lokalizacji, by ikonka CFScript.txt znalazła się obok ikonki ComboFix.exe )

Przeciągnij i upuść plik CFScript.txt na plik ComboFix.exe (czyli ikonkę CFScript.txt na ikonkę ComboFix.exe )

– podobnie jak na tym obrazku –>88953CFScript-createdbyMiekiemoes.gif

(jeśli pojawi się pytanie " 1 or 2" - to wpisz 1 i naciśnij ENTER) Ma się rozpocząć usuwanie. (i powstanie log)

Po restarcie usuń ręcznie folder C: ** Qoobox**.

Po tym nowy log z Combo

Zmiana zasad wklejania logów na forum - viewtopic.php?f=16t=213350

Zrobiłem tak jak napisales ale nadal przy uruchomieniu systemu Avast mi wykrywa wirusa;(((.

Moze cos źle zrobilem? Czy ja musze usunąć samemu jakies programy? Proszę o szczegółową instrukcje. Dziękuję i pozdrawiam.

Jest źle - daj log z Combo nowy zawsze po usunięciu syfu

Oto log z combo :

ComboFix 08-01-11.3 - Maciej 2008-01-13 0:34:12.5 - NTFSx86

Microsoft Windows XP Professional 5.1.2600.0.1250.1.1045.18.261 [GMT 1:00]

Running from: C:\Documents and Settings\Maciej\Pulpit\ComboFix.exe

.

((((((((((((((((((((((((( Files Created from 2007-12-12 to 2008-01-12 )))))))))))))))))))))))))))))))

.

2008-01-13 00:33 . 2000-08-31 08:00 51,200 --a------ C:\WINDOWS\NirCmd.exe

2008-01-12 18:52 . 2008-01-12 18:52

2008-01-12 17:45 . 2008-01-12 17:45

2008-01-12 16:31 . 2008-01-12 16:33

2008-01-12 16:27 . 2008-01-13 00:18

2008-01-12 15:29 . 2008-01-12 15:29

2008-01-12 15:29 . 2008-01-13 00:34

2008-01-09 08:53 . 2008-01-12 15:29

2008-01-09 08:53 . 2007-10-18 00:16 79,688 --a------ C:\WINDOWS\system32\drivers\iksyssec.sys

2008-01-09 08:53 . 2007-10-18 00:15 62,280 --a------ C:\WINDOWS\system32\drivers\iksysflt.sys

2008-01-09 08:53 . 2007-10-18 00:14 41,288 --a------ C:\WINDOWS\system32\drivers\ikfilesec.sys

2008-01-09 08:53 . 2007-10-18 00:16 29,000 --a------ C:\WINDOWS\system32\drivers\kcom.sys

2008-01-09 08:52 . 2005-09-23 08:29 626,688 --a------ C:\WINDOWS\system32\msvcr80.dll

2008-01-08 22:03 . 2008-01-08 22:03

2008-01-08 22:03 . 2008-01-08 22:03

2008-01-08 17:28 . 2007-12-04 14:04 837,496 --a------ C:\WINDOWS\system32\aswBoot.exe

2008-01-08 17:28 . 2004-01-09 10:13 380,928 --a------ C:\WINDOWS\system32\actskin4.ocx

2008-01-08 17:28 . 2007-12-04 13:54 95,608 --a------ C:\WINDOWS\system32\AvastSS.scr

2008-01-08 17:28 . 2007-12-04 15:55 94,544 --a------ C:\WINDOWS\system32\drivers\aswmon2.sys

2008-01-08 17:28 . 2007-12-04 15:56 93,264 --a------ C:\WINDOWS\system32\drivers\aswmon.sys

2008-01-08 17:28 . 2007-12-04 15:51 42,912 --a------ C:\WINDOWS\system32\drivers\aswTdi.sys

2008-01-08 17:28 . 2007-12-04 15:49 26,624 --a------ C:\WINDOWS\system32\drivers\aavmker4.sys

2008-01-08 17:28 . 2007-12-04 15:53 23,152 --a------ C:\WINDOWS\system32\drivers\aswRdr.sys

2008-01-08 17:27 . 2008-01-08 17:27

2008-01-02 23:53 . 2001-05-04 12:05 413,760 --a------ C:\WINDOWS\mpg4c32.dll

2008-01-02 23:53 . 2003-12-22 17:59 405,504 --a------ C:\WINDOWS\GeoCodec.dll

2008-01-02 23:53 . 2003-12-22 17:56 176,128 --a------ C:\WINDOWS\GeoCodecLib.dll

2007-12-15 20:33 . 2007-12-15 20:33 54,156 --ah----- C:\WINDOWS\QTFont.qfn

2007-12-15 20:33 . 2007-12-15 20:33 1,409 --a------ C:\WINDOWS\QTFont.for

2007-12-13 00:51 . 2008-01-27 18:48

2007-12-13 00:51 . 2008-01-26 17:52

2007-12-12 16:31 . 2008-01-12 15:29

.

(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))

.

2008-01-26 16:52 --------- d-----w C:\Program Files\Skype

2008-01-22 20:46 --------- d-----w C:\Program Files\EA SPORTS

2008-01-12 23:31 --------- d-----w C:\Program Files\Gadu-Gadu

2008-01-12 17:56 --------- d-----w C:\Program Files\Common Files\Symantec Shared

2008-01-08 15:43 --------- d-----w C:\Documents and Settings\All Users\Dane aplikacji\Symantec

2008-01-08 15:42 --------- d-----w C:\Program Files\Symantec

2008-01-06 22:24 --------- d–h--w C:\Program Files\InstallShield Installation Information

2008-01-06 22:11 --------- d-----w C:\Program Files\SyrenkaRacer

2008-01-06 22:08 --------- d-----w C:\Program Files\City Interactive

2007-12-20 17:22 --------- d-----w C:\Program Files\Java

2007-12-18 14:53 --------- d-----w C:\Documents and Settings\Maciej\Dane aplikacji\Datalayer

2007-12-05 16:57 11,973 ----a-w C:\WINDOWS\system32\drivers\secdrv.sys

2007-11-18 22:30 724,992 ----a-w C:\WINDOWS\iun6002.exe

2007-10-31 22:00 16,760 ----a-w C:\Documents and Settings\Maciej\Dane aplikacji\GDIPFONTCACHEV1.DAT

2004-10-01 14:00 40,960 ----a-w C:\Program Files\Uninstall_CDS.exe

2001-11-23 04:08 712,704 ----a-w C:\WINDOWS\inf\OTHER\audio3d.dll

.

((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))

.

.

*Note* empty entries & legit default entries are not shown

REGEDIT4

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]

“swg”=“C:\Program Files\Google\GoogleToolbarNotifier\1.2.1128.5462\GoogleToolbarNotifier.exe” [2008-01-12 17:45 171448]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]

“PCSuiteTrayApplication”=“C:\PROGRA~1\Nokia\NOKIAP~1\LAUNCH~1.exe” [2008-01-08 16:42 572416]

“avast!”=“C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe” [2007-12-04 14:00 79224]

[HKEY_USERS.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]

“CTFMON.EXE”=“C:\WINDOWS\System32\CTFMON.EXE” []

C:\Documents and Settings\All Users\Menu Start\Programy\Autostart\

Microsoft Office.lnk - C:\Program Files\Microsoft Office\Office10\OSA.EXE [2001-02-13 10:01:04]

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\explorer]

“NoInstrumentation”= 1 (0x1)

S3 ZSMC302;VIMICRO USB PC Camera;C:\WINDOWS\System32\Drivers\usbVM31b.sys [2004-09-07 08:11]

.

Contents of the ‘Scheduled Tasks’ folder

“2007-11-08 17:43:08 C:\WINDOWS\Tasks\Symantec NetDetect.job”

  • C:\Program Files\Symantec\LiveUpdate\NDETECT.EXE

.

**************************************************************************

catchme 0.3.1344 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net

Rootkit scan 2008-01-13 00:35:10

Windows 5.1.2600 NTFS

scanning hidden processes …

scanning hidden autostart entries …

scanning hidden files …

scan completed successfully

hidden files: 0

**************************************************************************

.

Completion time: 2008-01-13 0:35:49

ComboFix2.txt 2008-01-12 23:32:56

Otwórz Notatnik i wklej w nim to:

Windows Registry Editor Version 5.00 


[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]

"CTFMON.EXE"=-

Plik >>> Zapisz jako >>> Zmień rozszerzenie z TXT na Wszystkie pliki >>> Zapisz pod nazwą FIX.REG >>> kliknij dwa razy na utworzony plik FIX.REG i potwierdź dodanie do rejestru >>> restart.

Zmiana zasad wklejania logów na forum! !!

Zrobiłem jak pisałes, zresetowałem kompa i nadal wykrywa 2 infekcje ostatnia w pliku ssttt.dll, co robic:(( ???

Przecież je usunięto? Podaj lokalizację tych pików.

Skan AVG Anti-Spyware 7.5 po update + raport :wink:

Zmiana zasad wklejania logów na forum - viewtopic.php?f=16&t=213350

Przeskanowałem tak jak mówiles AVG Anti Spyware 7.5 i wklejam raport z znalezionych infekcji:(( CO robic dalej???

AVG Anti-Spyware - Scan Report


  • Created at: 16:30:37 2008-01-14

  • Scan result:

HKLM\SOFTWARE\Microsoft\Internet Explorer\Extensions{c95fe080-8f5d-11d2-a20b-00aa003c157a} -> Adware.Generic : Ignored.

HKU.DEFAULT\Software\Microsoft\Internet Explorer\Extensions\CmdMapping\{c95fe080-8f5d-11d2-a20b-00aa003c157a} -> Adware.Generic : Ignored.

HKU\S-1-5-18\Software\Microsoft\Internet Explorer\Extensions\CmdMapping\{c95fe080-8f5d-11d2-a20b-00aa003c157a} -> Adware.Generic : Ignored.

HKU\S-1-5-21-1757981266-343818398-839522115-1003\Software\Microsoft\Internet Explorer\Extensions\CmdMapping\{c95fe080-8f5d-11d2-a20b-00aa003c157a} -> Adware.Generic : Ignored.

C:\GTA San Andreas\data\hlm-intro.exe -> Backdoor.Hupigon.kg : Ignored.

C:\GTA San Andreas\hlm-intro.exe -> Backdoor.Hupigon.kg : Ignored.

C:\System Volume Information_restore{A9F343B2-4782-465F-9AC2-EBD5FA767CBC}\RP36\A0033645.exe -> Backdoor.Hupigon.kg : Ignored.

C:\System Volume Information_restore{A9F343B2-4782-465F-9AC2-EBD5FA767CBC}\RP37\A0035882.exe -> Backdoor.Hupigon.kg : Ignored.

C:\Program Files\Nokia\Nokia PC Suite 6\LaunchApplication.exe -> Dropper.Agent.dgo : Ignored.

C:\System Volume Information_restore{A9F343B2-4782-465F-9AC2-EBD5FA767CBC}\RP48\A0056685.exe -> Dropper.Agent.dgo : Ignored.

C:\System Volume Information_restore{A9F343B2-4782-465F-9AC2-EBD5FA767CBC}\RP48\A0056687.exe -> Dropper.Agent.dgo : Ignored.

C:\System Volume Information_restore{A9F343B2-4782-465F-9AC2-EBD5FA767CBC}\RP48\A0056688.exe -> Dropper.Agent.dgo : Ignored.

C:\System Volume Information_restore{A9F343B2-4782-465F-9AC2-EBD5FA767CBC}\RP48\A0056689.exe -> Dropper.Agent.dgo : Ignored.

C:\System Volume Information_restore{A9F343B2-4782-465F-9AC2-EBD5FA767CBC}\RP48\A0056690.exe -> Dropper.Agent.dgo : Ignored.

C:\System Volume Information_restore{A9F343B2-4782-465F-9AC2-EBD5FA767CBC}\RP48\A0057700.exe -> Dropper.Agent.dgo : Ignored.

C:\System Volume Information_restore{A9F343B2-4782-465F-9AC2-EBD5FA767CBC}\RP48\A0057702.exe -> Dropper.Agent.dgo : Ignored.

C:\System Volume Information_restore{A9F343B2-4782-465F-9AC2-EBD5FA767CBC}\RP48\A0057703.exe -> Dropper.Agent.dgo : Ignored.

C:\System Volume Information_restore{A9F343B2-4782-465F-9AC2-EBD5FA767CBC}\RP48\A0057704.exe -> Dropper.Agent.dgo : Ignored.

C:\System Volume Information_restore{A9F343B2-4782-465F-9AC2-EBD5FA767CBC}\RP48\A0057709.exe -> Dropper.Agent.dgo : Ignored.

C:\System Volume Information_restore{A9F343B2-4782-465F-9AC2-EBD5FA767CBC}\RP48\A0058702.exe -> Dropper.Agent.dgo : Ignored.

C:\System Volume Information_restore{A9F343B2-4782-465F-9AC2-EBD5FA767CBC}\RP48\A0058705.exe -> Dropper.Agent.dgo : Ignored.

C:\System Volume Information_restore{A9F343B2-4782-465F-9AC2-EBD5FA767CBC}\RP48\A0058708.exe -> Dropper.Agent.dgo : Ignored.

C:\System Volume Information_restore{A9F343B2-4782-465F-9AC2-EBD5FA767CBC}\RP48\A0058709.exe -> Dropper.Agent.dgo : Ignored.

C:\System Volume Information_restore{A9F343B2-4782-465F-9AC2-EBD5FA767CBC}\RP48\A0058727.exe -> Dropper.Agent.dgo : Ignored.

C:\System Volume Information_restore{A9F343B2-4782-465F-9AC2-EBD5FA767CBC}\RP48\A0058728.exe -> Dropper.Agent.dgo : Ignored.

C:\System Volume Information_restore{A9F343B2-4782-465F-9AC2-EBD5FA767CBC}\RP48\A0058732.exe -> Dropper.Agent.dgo : Ignored.

C:\System Volume Information_restore{A9F343B2-4782-465F-9AC2-EBD5FA767CBC}\RP48\A0058745.exe -> Dropper.Agent.dgo : Ignored.

C:\System Volume Information_restore{A9F343B2-4782-465F-9AC2-EBD5FA767CBC}\RP48\A0058746.exe -> Dropper.Agent.dgo : Ignored.

C:\System Volume Information_restore{A9F343B2-4782-465F-9AC2-EBD5FA767CBC}\RP48\A0058747.exe -> Dropper.Agent.dgo : Ignored.

C:\System Volume Information_restore{A9F343B2-4782-465F-9AC2-EBD5FA767CBC}\RP48\A0058748.exe -> Dropper.Agent.dgo : Ignored.

C:\System Volume Information_restore{A9F343B2-4782-465F-9AC2-EBD5FA767CBC}\RP48\A0058752.exe -> Dropper.Agent.dgo : Ignored.

C:\System Volume Information_restore{A9F343B2-4782-465F-9AC2-EBD5FA767CBC}\RP48\A0058758.exe -> Dropper.Agent.dgo : Ignored.

C:\System Volume Information_restore{A9F343B2-4782-465F-9AC2-EBD5FA767CBC}\RP48\A0058768.exe -> Dropper.Agent.dgo : Ignored.

C:\System Volume Information_restore{A9F343B2-4782-465F-9AC2-EBD5FA767CBC}\RP48\A0058776.exe -> Dropper.Agent.dgo : Ignored.

C:\System Volume Information_restore{A9F343B2-4782-465F-9AC2-EBD5FA767CBC}\RP48\A0059776.exe -> Dropper.Agent.dgo : Ignored.

C:\System Volume Information_restore{A9F343B2-4782-465F-9AC2-EBD5FA767CBC}\RP48\A0059777.exe -> Dropper.Agent.dgo : Ignored.

C:\System Volume Information_restore{A9F343B2-4782-465F-9AC2-EBD5FA767CBC}\RP48\A0059778.exe -> Dropper.Agent.dgo : Ignored.

C:\System Volume Information_restore{A9F343B2-4782-465F-9AC2-EBD5FA767CBC}\RP48\A0059779.exe -> Dropper.Agent.dgo : Ignored.

C:\System Volume Information_restore{A9F343B2-4782-465F-9AC2-EBD5FA767CBC}\RP48\A0059784.exe -> Dropper.Agent.dgo : Ignored.

C:\System Volume Information_restore{A9F343B2-4782-465F-9AC2-EBD5FA767CBC}\RP48\A0059790.exe -> Dropper.Agent.dgo : Ignored.

C:\System Volume Information_restore{A9F343B2-4782-465F-9AC2-EBD5FA767CBC}\RP48\A0059809.exe -> Dropper.Agent.dgo : Ignored.

C:\System Volume Information_restore{A9F343B2-4782-465F-9AC2-EBD5FA767CBC}\RP48\A0059810.exe -> Dropper.Agent.dgo : Ignored.

C:\System Volume Information_restore{A9F343B2-4782-465F-9AC2-EBD5FA767CBC}\RP48\A0059811.exe -> Dropper.Agent.dgo : Ignored.

C:\System Volume Information_restore{A9F343B2-4782-465F-9AC2-EBD5FA767CBC}\RP48\A0059814.exe -> Dropper.Agent.dgo : Ignored.

C:\System Volume Information_restore{A9F343B2-4782-465F-9AC2-EBD5FA767CBC}\RP48\A0059816.exe -> Dropper.Agent.dgo : Ignored.

C:\System Volume Information_restore{A9F343B2-4782-465F-9AC2-EBD5FA767CBC}\RP48\A0059822.exe -> Dropper.Agent.dgo : Ignored.

C:\System Volume Information_restore{A9F343B2-4782-465F-9AC2-EBD5FA767CBC}\RP48\A0059827.exe -> Dropper.Agent.dgo : Ignored.

C:\System Volume Information_restore{A9F343B2-4782-465F-9AC2-EBD5FA767CBC}\RP48\A0059836.exe -> Dropper.Agent.dgo : Ignored.

C:\System Volume Information_restore{A9F343B2-4782-465F-9AC2-EBD5FA767CBC}\RP48\A0059837.exe -> Dropper.Agent.dgo : Ignored.

C:\System Volume Information_restore{A9F343B2-4782-465F-9AC2-EBD5FA767CBC}\RP48\A0059839.exe -> Dropper.Agent.dgo : Ignored.

C:\System Volume Information_restore{A9F343B2-4782-465F-9AC2-EBD5FA767CBC}\RP48\A0059841.exe -> Dropper.Agent.dgo : Ignored.

C:\System Volume Information_restore{A9F343B2-4782-465F-9AC2-EBD5FA767CBC}\RP48\A0059844.exe -> Dropper.Agent.dgo : Ignored.

C:\System Volume Information_restore{A9F343B2-4782-465F-9AC2-EBD5FA767CBC}\RP48\A0059845.exe -> Dropper.Agent.dgo : Ignored.

C:\System Volume Information_restore{A9F343B2-4782-465F-9AC2-EBD5FA767CBC}\RP48\A0060837.exe -> Dropper.Agent.dgo : Ignored.

C:\System Volume Information_restore{A9F343B2-4782-465F-9AC2-EBD5FA767CBC}\RP48\A0060841.exe -> Dropper.Agent.dgo : Ignored.

C:\System Volume Information_restore{A9F343B2-4782-465F-9AC2-EBD5FA767CBC}\RP48\A0060842.exe -> Dropper.Agent.dgo : Ignored.

C:\System Volume Information_restore{A9F343B2-4782-465F-9AC2-EBD5FA767CBC}\RP48\A0060843.exe -> Dropper.Agent.dgo : Ignored.

C:\System Volume Information_restore{A9F343B2-4782-465F-9AC2-EBD5FA767CBC}\RP48\A0060850.exe -> Dropper.Agent.dgo : Ignored.

C:\System Volume Information_restore{A9F343B2-4782-465F-9AC2-EBD5FA767CBC}\RP48\A0060856.exe -> Dropper.Agent.dgo : Ignored.

C:\System Volume Information_restore{A9F343B2-4782-465F-9AC2-EBD5FA767CBC}\RP48\A0060857.exe -> Dropper.Agent.dgo : Ignored.

C:\System Volume Information_restore{A9F343B2-4782-465F-9AC2-EBD5FA767CBC}\RP48\A0060858.exe -> Dropper.Agent.dgo : Ignored.

C:\System Volume Information_restore{A9F343B2-4782-465F-9AC2-EBD5FA767CBC}\RP48\A0060878.exe -> Dropper.Agent.dgo : Ignored.

C:\System Volume Information_restore{A9F343B2-4782-465F-9AC2-EBD5FA767CBC}\RP48\A0060879.exe -> Dropper.Agent.dgo : Ignored.

C:\System Volume Information_restore{A9F343B2-4782-465F-9AC2-EBD5FA767CBC}\RP48\A0060888.exe -> Dropper.Agent.dgo : Ignored.

C:\System Volume Information_restore{A9F343B2-4782-465F-9AC2-EBD5FA767CBC}\RP48\A0060889.exe -> Dropper.Agent.dgo : Ignored.

C:\System Volume Information_restore{A9F343B2-4782-465F-9AC2-EBD5FA767CBC}\RP48\A0060904.exe -> Dropper.Agent.dgo : Ignored.

C:\System Volume Information_restore{A9F343B2-4782-465F-9AC2-EBD5FA767CBC}\RP48\A0060905.exe -> Dropper.Agent.dgo : Ignored.

C:\System Volume Information_restore{A9F343B2-4782-465F-9AC2-EBD5FA767CBC}\RP48\A0060922.exe -> Dropper.Agent.dgo : Ignored.

C:\System Volume Information_restore{A9F343B2-4782-465F-9AC2-EBD5FA767CBC}\RP48\A0060923.exe -> Dropper.Agent.dgo : Ignored.

C:\System Volume Information_restore{A9F343B2-4782-465F-9AC2-EBD5FA767CBC}\RP48\A0060935.exe -> Dropper.Agent.dgo : Ignored.

C:\System Volume Information_restore{A9F343B2-4782-465F-9AC2-EBD5FA767CBC}\RP48\A0060938.exe -> Dropper.Agent.dgo : Ignored.

C:\System Volume Information_restore{A9F343B2-4782-465F-9AC2-EBD5FA767CBC}\RP48\A0060940.exe -> Dropper.Agent.dgo : Ignored.

C:\System Volume Information_restore{A9F343B2-4782-465F-9AC2-EBD5FA767CBC}\RP48\A0060941.exe -> Dropper.Agent.dgo : Ignored.

C:\System Volume Information_restore{A9F343B2-4782-465F-9AC2-EBD5FA767CBC}\RP48\A0060945.exe -> Dropper.Agent.dgo : Ignored.

C:\System Volume Information_restore{A9F343B2-4782-465F-9AC2-EBD5FA767CBC}\RP48\A0060946.exe -> Dropper.Agent.dgo : Ignored.

C:\System Volume Information_restore{A9F343B2-4782-465F-9AC2-EBD5FA767CBC}\RP48\A0060947.exe -> Dropper.Agent.dgo : Ignored.

C:\System Volume Information_restore{A9F343B2-4782-465F-9AC2-EBD5FA767CBC}\RP48\A0060953.exe -> Dropper.Agent.dgo : Ignored.

C:\System Volume Information_restore{A9F343B2-4782-465F-9AC2-EBD5FA767CBC}\RP48\A0060960.exe -> Dropper.Agent.dgo : Ignored.

C:\System Volume Information_restore{A9F343B2-4782-465F-9AC2-EBD5FA767CBC}\RP48\A0060965.exe -> Dropper.Agent.dgo : Ignored.

C:\System Volume Information_restore{A9F343B2-4782-465F-9AC2-EBD5FA767CBC}\RP48\A0060967.exe -> Dropper.Agent.dgo : Ignored.

C:\System Volume Information_restore{A9F343B2-4782-465F-9AC2-EBD5FA767CBC}\RP48\A0060971.exe -> Dropper.Agent.dgo : Ignored.

C:\System Volume Information_restore{A9F343B2-4782-465F-9AC2-EBD5FA767CBC}\RP48\A0060976.exe -> Dropper.Agent.dgo : Ignored.

C:\System Volume Information_restore{A9F343B2-4782-465F-9AC2-EBD5FA767CBC}\RP48\A0060984.exe -> Dropper.Agent.dgo : Ignored.

C:\System Volume Information_restore{A9F343B2-4782-465F-9AC2-EBD5FA767CBC}\RP48\A0060988.exe -> Dropper.Agent.dgo : Ignored.

C:\System Volume Information_restore{A9F343B2-4782-465F-9AC2-EBD5FA767CBC}\RP48\A0061003.exe -> Dropper.Agent.dgo : Ignored.

C:\System Volume Information_restore{A9F343B2-4782-465F-9AC2-EBD5FA767CBC}\RP48\A0061004.exe -> Dropper.Agent.dgo : Ignored.

C:\System Volume Information_restore{A9F343B2-4782-465F-9AC2-EBD5FA767CBC}\RP48\A0061009.exe -> Dropper.Agent.dgo : Ignored.

C:\System Volume Information_restore{A9F343B2-4782-465F-9AC2-EBD5FA767CBC}\RP48\A0061010.exe -> Dropper.Agent.dgo : Ignored.

C:\System Volume Information_restore{A9F343B2-4782-465F-9AC2-EBD5FA767CBC}\RP48\A0061011.exe -> Dropper.Agent.dgo : Ignored.

C:\System Volume Information_restore{A9F343B2-4782-465F-9AC2-EBD5FA767CBC}\RP48\A0061017.exe -> Dropper.Agent.dgo : Ignored.

C:\System Volume Information_restore{A9F343B2-4782-465F-9AC2-EBD5FA767CBC}\RP48\A0061018.exe -> Dropper.Agent.dgo : Ignored.

C:\System Volume Information_restore{A9F343B2-4782-465F-9AC2-EBD5FA767CBC}\RP48\A0061022.exe -> Dropper.Agent.dgo : Ignored.

C:\System Volume Information_restore{A9F343B2-4782-465F-9AC2-EBD5FA767CBC}\RP48\A0061030.exe -> Dropper.Agent.dgo : Ignored.

C:\System Volume Information_restore{A9F343B2-4782-465F-9AC2-EBD5FA767CBC}\RP48\A0062029.exe -> Dropper.Agent.dgo : Ignored.

C:\System Volume Information_restore{A9F343B2-4782-465F-9AC2-EBD5FA767CBC}\RP48\A0062030.exe -> Dropper.Agent.dgo : Ignored.

C:\System Volume Information_restore{A9F343B2-4782-465F-9AC2-EBD5FA767CBC}\RP48\A0062031.exe -> Dropper.Agent.dgo : Ignored.

C:\System Volume Information_restore{A9F343B2-4782-465F-9AC2-EBD5FA767CBC}\RP48\A0062036.exe -> Dropper.Agent.dgo : Ignored.

C:\System Volume Information_restore{A9F343B2-4782-465F-9AC2-EBD5FA767CBC}\RP48\A0062040.exe -> Dropper.Agent.dgo : Ignored.

C:\System Volume Information_restore{A9F343B2-4782-465F-9AC2-EBD5FA767CBC}\RP48\A0062118.exe -> Dropper.Agent.dgo : Ignored.

C:\System Volume Information_restore{A9F343B2-4782-465F-9AC2-EBD5FA767CBC}\RP48\A0062129.exe -> Dropper.Agent.dgo : Ignored.

C:\System Volume Information_restore{A9F343B2-4782-465F-9AC2-EBD5FA767CBC}\RP48\A0062130.exe -> Dropper.Agent.dgo : Ignored.

C:\System Volume Information_restore{A9F343B2-4782-465F-9AC2-EBD5FA767CBC}\RP48\A0062133.exe -> Dropper.Agent.dgo : Ignored.

C:\System Volume Information_restore{A9F343B2-4782-465F-9AC2-EBD5FA767CBC}\RP48\A0062135.exe -> Dropper.Agent.dgo : Ignored.

C:\System Volume Information_restore{A9F343B2-4782-465F-9AC2-EBD5FA767CBC}\RP48\A0062136.exe -> Dropper.Agent.dgo : Ignored.

C:\System Volume Information_restore{A9F343B2-4782-465F-9AC2-EBD5FA767CBC}\RP48\A0062142.exe -> Dropper.Agent.dgo : Ignored.

C:\System Volume Information_restore{A9F343B2-4782-465F-9AC2-EBD5FA767CBC}\RP48\A0062159.exe -> Dropper.Agent.dgo : Ignored.

C:\System Volume Information_restore{A9F343B2-4782-465F-9AC2-EBD5FA767CBC}\RP48\A0062160.exe -> Dropper.Agent.dgo : Ignored.

C:\System Volume Information_restore{A9F343B2-4782-465F-9AC2-EBD5FA767CBC}\RP48\A0063130.exe -> Dropper.Agent.dgo : Ignored.

C:\System Volume Information_restore{A9F343B2-4782-465F-9AC2-EBD5FA767CBC}\RP48\A0063132.exe -> Dropper.Agent.dgo : Ignored.

C:\System Volume Information_restore{A9F343B2-4782-465F-9AC2-EBD5FA767CBC}\RP48\A0063135.exe -> Dropper.Agent.dgo : Ignored.

C:\System Volume Information_restore{A9F343B2-4782-465F-9AC2-EBD5FA767CBC}\RP48\A0063136.exe -> Dropper.Agent.dgo : Ignored.

C:\System Volume Information_restore{A9F343B2-4782-465F-9AC2-EBD5FA767CBC}\RP48\A0063142.exe -> Dropper.Agent.dgo : Ignored.

C:\System Volume Information_restore{A9F343B2-4782-465F-9AC2-EBD5FA767CBC}\RP48\A0063143.exe -> Dropper.Agent.dgo : Ignored.

C:\System Volume Information_restore{A9F343B2-4782-465F-9AC2-EBD5FA767CBC}\RP48\A0063152.exe -> Dropper.Agent.dgo : Ignored.

C:\System Volume Information_restore{A9F343B2-4782-465F-9AC2-EBD5FA767CBC}\RP48\A0064151.exe -> Dropper.Agent.dgo : Ignored.

C:\System Volume Information_restore{A9F343B2-4782-465F-9AC2-EBD5FA767CBC}\RP48\A0064157.exe -> Dropper.Agent.dgo : Ignored.

C:\System Volume Information_restore{A9F343B2-4782-465F-9AC2-EBD5FA767CBC}\RP48\A0064159.exe -> Dropper.Agent.dgo : Ignored.

C:\System Volume Information_restore{A9F343B2-4782-465F-9AC2-EBD5FA767CBC}\RP48\A0064164.exe -> Dropper.Agent.dgo : Ignored.

C:\System Volume Information_restore{A9F343B2-4782-465F-9AC2-EBD5FA767CBC}\RP48\A0064165.exe -> Dropper.Agent.dgo : Ignored.

C:\System Volume Information_restore{A9F343B2-4782-465F-9AC2-EBD5FA767CBC}\RP48\A0064174.exe -> Dropper.Agent.dgo : Ignored.

C:\System Volume Information_restore{A9F343B2-4782-465F-9AC2-EBD5FA767CBC}\RP48\A0064175.exe -> Dropper.Agent.dgo : Ignored.

C:\System Volume Information_restore{A9F343B2-4782-465F-9AC2-EBD5FA767CBC}\RP48\A0064180.exe -> Dropper.Agent.dgo : Ignored.

C:\System Volume Information_restore{A9F343B2-4782-465F-9AC2-EBD5FA767CBC}\RP48\A0064184.exe -> Dropper.Agent.dgo : Ignored.

C:\System Volume Information_restore{A9F343B2-4782-465F-9AC2-EBD5FA767CBC}\RP48\A0064188.exe -> Dropper.Agent.dgo : Ignored.

C:\System Volume Information_restore{A9F343B2-4782-465F-9AC2-EBD5FA767CBC}\RP48\A0064193.exe -> Dropper.Agent.dgo : Ignored.

C:\System Volume Information_restore{A9F343B2-4782-465F-9AC2-EBD5FA767CBC}\RP48\A0064202.exe -> Dropper.Agent.dgo : Ignored.

C:\System Volume Information_restore{A9F343B2-4782-465F-9AC2-EBD5FA767CBC}\RP48\A0064204.exe -> Dropper.Agent.dgo : Ignored.

C:\System Volume Information_restore{A9F343B2-4782-465F-9AC2-EBD5FA767CBC}\RP48\A0064205.exe -> Dropper.Agent.dgo : Ignored.

C:\System Volume Information_restore{A9F343B2-4782-465F-9AC2-EBD5FA767CBC}\RP48\A0064207.exe -> Dropper.Agent.dgo : Ignored.

C:\System Volume Information_restore{A9F343B2-4782-465F-9AC2-EBD5FA767CBC}\RP48\A0064219.exe -> Dropper.Agent.dgo : Ignored.

C:\System Volume Information_restore{A9F343B2-4782-465F-9AC2-EBD5FA767CBC}\RP48\A0064223.exe -> Dropper.Agent.dgo : Ignored.

C:\System Volume Information_restore{A9F343B2-4782-465F-9AC2-EBD5FA767CBC}\RP48\A0064224.exe -> Dropper.Agent.dgo : Ignored.

C:\System Volume Information_restore{A9F343B2-4782-465F-9AC2-EBD5FA767CBC}\RP48\A0065236.exe -> Dropper.Agent.dgo : Ignored.

C:\System Volume Information_restore{A9F343B2-4782-465F-9AC2-EBD5FA767CBC}\RP48\A0065237.exe -> Dropper.Agent.dgo : Ignored.

C:\System Volume Information_restore{A9F343B2-4782-465F-9AC2-EBD5FA767CBC}\RP48\A0065240.exe -> Dropper.Agent.dgo : Ignored.

C:\System Volume Information_restore{A9F343B2-4782-465F-9AC2-EBD5FA767CBC}\RP48\A0065247.exe -> Dropper.Agent.dgo : Ignored.

C:\System Volume Information_restore{A9F343B2-4782-465F-9AC2-EBD5FA767CBC}\RP48\A0065255.exe -> Dropper.Agent.dgo : Ignored.

C:\System Volume Information_restore{A9F343B2-4782-465F-9AC2-EBD5FA767CBC}\RP48\A0065266.exe -> Dropper.Agent.dgo : Ignored.

C:\System Volume Information_restore{A9F343B2-4782-465F-9AC2-EBD5FA767CBC}\RP48\A0065267.exe -> Dropper.Agent.dgo : Ignored.

C:\System Volume Information_restore{A9F343B2-4782-465F-9AC2-EBD5FA767CBC}\RP48\A0065270.exe -> Dropper.Agent.dgo : Ignored.

C:\System Volume Information_restore{A9F343B2-4782-465F-9AC2-EBD5FA767CBC}\RP48\A0065286.exe -> Dropper.Agent.dgo : Ignored.

C:\System Volume Information_restore{A9F343B2-4782-465F-9AC2-EBD5FA767CBC}\RP48\A0065287.exe -> Dropper.Agent.dgo : Ignored.

C:\System Volume Information_restore{A9F343B2-4782-465F-9AC2-EBD5FA767CBC}\RP48\A0066285.exe -> Dropper.Agent.dgo : Ignored.

C:\System Volume Information_restore{A9F343B2-4782-465F-9AC2-EBD5FA767CBC}\RP48\A0066286.exe -> Dropper.Agent.dgo : Ignored.

C:\System Volume Information_restore{A9F343B2-4782-465F-9AC2-EBD5FA767CBC}\RP48\A0066289.exe -> Dropper.Agent.dgo : Ignored.

C:\System Volume Information_restore{A9F343B2-4782-465F-9AC2-EBD5FA767CBC}\RP48\A0066290.exe -> Dropper.Agent.dgo : Ignored.

C:\System Volume Information_restore{A9F343B2-4782-465F-9AC2-EBD5FA767CBC}\RP48\A0066295.exe -> Dropper.Agent.dgo : Ignored.

C:\System Volume Information_restore{A9F343B2-4782-465F-9AC2-EBD5FA767CBC}\RP48\A0066296.exe -> Dropper.Agent.dgo : Ignored.

C:\System Volume Information_restore{A9F343B2-4782-465F-9AC2-EBD5FA767CBC}\RP48\A0066300.exe -> Dropper.Agent.dgo : Ignored.

C:\System Volume Information_restore{A9F343B2-4782-465F-9AC2-EBD5FA767CBC}\RP48\A0066306.exe -> Dropper.Agent.dgo : Ignored.

C:\System Volume Information_restore{A9F343B2-4782-465F-9AC2-EBD5FA767CBC}\RP48\A0066308.exe -> Dropper.Agent.dgo : Ignored.

C:\System Volume Information_restore{A9F343B2-4782-465F-9AC2-EBD5FA767CBC}\RP48\A0066310.exe -> Dropper.Agent.dgo : Ignored.

C:\System Volume Information_restore{A9F343B2-4782-465F-9AC2-EBD5FA767CBC}\RP48\A0066320.exe -> Dropper.Agent.dgo : Ignored.

C:\System Volume Information_restore{A9F343B2-4782-465F-9AC2-EBD5FA767CBC}\RP48\A0066322.exe -> Dropper.Agent.dgo : Ignored.

C:\System Volume Information_restore{A9F343B2-4782-465F-9AC2-EBD5FA767CBC}\RP48\A0067308.exe -> Dropper.Agent.dgo : Ignored.

C:\System Volume Information_restore{A9F343B2-4782-465F-9AC2-EBD5FA767CBC}\RP48\A0067309.exe -> Dropper.Agent.dgo : Ignored.

C:\System Volume Information_restore{A9F343B2-4782-465F-9AC2-EBD5FA767CBC}\RP48\A0067310.exe -> Dropper.Agent.dgo : Ignored.

C:\System Volume Information_restore{A9F343B2-4782-465F-9AC2-EBD5FA767CBC}\RP48\A0067313.exe -> Dropper.Agent.dgo : Ignored.

C:\System Volume Information_restore{A9F343B2-4782-465F-9AC2-EBD5FA767CBC}\RP48\A0067320.exe -> Dropper.Agent.dgo : Ignored.

C:\System Volume Information_restore{A9F343B2-4782-465F-9AC2-EBD5FA767CBC}\RP48\A0067329.exe -> Dropper.Agent.dgo : Ignored.

C:\System Volume Information_restore{A9F343B2-4782-465F-9AC2-EBD5FA767CBC}\RP48\A0067331.exe -> Dropper.Agent.dgo : Ignored.

C:\System Volume Information_restore{A9F343B2-4782-465F-9AC2-EBD5FA767CBC}\RP48\A0067333.exe -> Dropper.Agent.dgo : Ignored.

C:\System Volume Information_restore{A9F343B2-4782-465F-9AC2-EBD5FA767CBC}\RP48\A0067355.exe -> Dropper.Agent.dgo : Ignored.

C:\System Volume Information_restore{A9F343B2-4782-465F-9AC2-EBD5FA767CBC}\RP48\A0067356.exe -> Dropper.Agent.dgo : Ignored.

C:\System Volume Information_restore{A9F343B2-4782-465F-9AC2-EBD5FA767CBC}\RP48\A0067363.exe -> Dropper.Agent.dgo : Ignored.

C:\System Volume Information_restore{A9F343B2-4782-465F-9AC2-EBD5FA767CBC}\RP48\A0067364.exe -> Dropper.Agent.dgo : Ignored.

C:\System Volume Information_restore{A9F343B2-4782-465F-9AC2-EBD5FA767CBC}\RP48\A0067368.exe -> Dropper.Agent.dgo : Ignored.

C:\System Volume Information_restore{A9F343B2-4782-465F-9AC2-EBD5FA767CBC}\RP48\A0067373.exe -> Dropper.Agent.dgo : Ignored.

C:\System Volume Information_restore{A9F343B2-4782-465F-9AC2-EBD5FA767CBC}\RP48\A0067381.exe -> Dropper.Agent.dgo : Ignored.

C:\System Volume Information_restore{A9F343B2-4782-465F-9AC2-EBD5FA767CBC}\RP48\A0067391.exe -> Dropper.Agent.dgo : Ignored.

C:\System Volume Information_restore{A9F343B2-4782-465F-9AC2-EBD5FA767CBC}\RP48\A0067393.exe -> Dropper.Agent.dgo : Ignored.

C:\System Volume Information_restore{A9F343B2-4782-465F-9AC2-EBD5FA767CBC}\RP48\A0067396.exe -> Dropper.Agent.dgo : Ignored.

C:\System Volume Information_restore{A9F343B2-4782-465F-9AC2-EBD5FA767CBC}\RP48\A0067402.exe -> Dropper.Agent.dgo : Ignored.

C:\System Volume Information_restore{A9F343B2-4782-465F-9AC2-EBD5FA767CBC}\RP48\A0067422.exe -> Dropper.Agent.dgo : Ignored.

C:\System Volume Information_restore{A9F343B2-4782-465F-9AC2-EBD5FA767CBC}\RP48\A0067429.exe -> Dropper.Agent.dgo : Ignored.

C:\System Volume Information_restore{A9F343B2-4782-465F-9AC2-EBD5FA767CBC}\RP48\A0067430.exe -> Dropper.Agent.dgo : Ignored.

C:\System Volume Information_restore{A9F343B2-4782-465F-9AC2-EBD5FA767CBC}\RP48\A0067431.exe -> Dropper.Agent.dgo : Ignored.

C:\System Volume Information_restore{A9F343B2-4782-465F-9AC2-EBD5FA767CBC}\RP48\A0067435.exe -> Dropper.Agent.dgo : Ignored.

C:\System Volume Information_restore{A9F343B2-4782-465F-9AC2-EBD5FA767CBC}\RP48\A0067451.exe -> Dropper.Agent.dgo : Ignored.

C:\System Volume Information_restore{A9F343B2-4782-465F-9AC2-EBD5FA767CBC}\RP48\A0067460.exe -> Dropper.Agent.dgo : Ignored.

C:\System Volume Information_restore{A9F343B2-4782-465F-9AC2-EBD5FA767CBC}\RP48\A0067463.exe -> Dropper.Agent.dgo : Ignored.

C:\System Volume Information_restore{A9F343B2-4782-465F-9AC2-EBD5FA767CBC}\RP48\A0067469.exe -> Dropper.Agent.dgo : Ignored.

C:\System Volume Information_restore{A9F343B2-4782-465F-9AC2-EBD5FA767CBC}\RP48\A0067479.exe -> Dropper.Agent.dgo : Ignored.

C:\System Volume Information_restore{A9F343B2-4782-465F-9AC2-EBD5FA767CBC}\RP48\A0067480.exe -> Dropper.Agent.dgo : Ignored.

C:\System Volume Information_restore{A9F343B2-4782-465F-9AC2-EBD5FA767CBC}\RP48\A0068463.exe -> Dropper.Agent.dgo : Ignored.

C:\System Volume Information_restore{A9F343B2-4782-465F-9AC2-EBD5FA767CBC}\RP48\A0068464.exe -> Dropper.Agent.dgo : Ignored.

C:\System Volume Information_restore{A9F343B2-4782-465F-9AC2-EBD5FA767CBC}\RP48\A0068465.exe -> Dropper.Agent.dgo : Ignored.

C:\System Volume Information_restore{A9F343B2-4782-465F-9AC2-EBD5FA767CBC}\RP48\A0068471.exe -> Dropper.Agent.dgo : Ignored.

C:\System Volume Information_restore{A9F343B2-4782-465F-9AC2-EBD5FA767CBC}\RP48\A0068476.exe -> Dropper.Agent.dgo : Ignored.

C:\System Volume Information_restore{A9F343B2-4782-465F-9AC2-EBD5FA767CBC}\RP48\A0068481.exe -> Dropper.Agent.dgo : Ignored.

C:\System Volume Information_restore{A9F343B2-4782-465F-9AC2-EBD5FA767CBC}\RP48\A0069462.exe -> Dropper.Agent.dgo : Ignored.

C:\System Volume Information_restore{A9F343B2-4782-465F-9AC2-EBD5FA767CBC}\RP48\A0069465.exe -> Dropper.Agent.dgo : Ignored.

C:\System Volume Information_restore{A9F343B2-4782-465F-9AC2-EBD5FA767CBC}\RP48\A0069466.exe -> Dropper.Agent.dgo : Ignored.

C:\System Volume Information_restore{A9F343B2-4782-465F-9AC2-EBD5FA767CBC}\RP48\A0069467.exe -> Dropper.Agent.dgo : Ignored.

C:\System Volume Information_restore{A9F343B2-4782-465F-9AC2-EBD5FA767CBC}\RP48\A0069468.exe -> Dropper.Agent.dgo : Ignored.

C:\System Volume Information_restore{A9F343B2-4782-465F-9AC2-EBD5FA767CBC}\RP48\A0069475.exe -> Dropper.Agent.dgo : Ignored.

C:\System Volume Information_restore{A9F343B2-4782-465F-9AC2-EBD5FA767CBC}\RP48\A0069479.exe -> Dropper.Agent.dgo : Ignored.

C:\System Volume Information_restore{A9F343B2-4782-465F-9AC2-EBD5FA767CBC}\RP48\A0069488.exe -> Dropper.Agent.dgo : Ignored.

C:\System Volume Information_restore{A9F343B2-4782-465F-9AC2-EBD5FA767CBC}\RP48\A0069490.exe -> Dropper.Agent.dgo : Ignored.

C:\System Volume Information_restore{A9F343B2-4782-465F-9AC2-EBD5FA767CBC}\RP48\A0069493.exe -> Dropper.Agent.dgo : Ignored.

C:\System Volume Information_restore{A9F343B2-4782-465F-9AC2-EBD5FA767CBC}\RP48\A0069497.exe -> Dropper.Agent.dgo : Ignored.

C:\System Volume Information_restore{A9F343B2-4782-465F-9AC2-EBD5FA767CBC}\RP48\A0069499.exe -> Dropper.Agent.dgo : Ignored.

C:\System Volume Information_restore{A9F343B2-4782-465F-9AC2-EBD5FA767CBC}\RP48\A0069500.exe -> Dropper.Agent.dgo : Ignored.

C:\System Volume Information_restore{A9F343B2-4782-465F-9AC2-EBD5FA767CBC}\RP48\A0069510.exe -> Dropper.Agent.dgo : Ignored.

C:\System Volume Information_restore{A9F343B2-4782-465F-9AC2-EBD5FA767CBC}\RP48\A0069512.exe -> Dropper.Agent.dgo : Ignored.

C:\System Volume Information_restore{A9F343B2-4782-465F-9AC2-EBD5FA767CBC}\RP48\A0069513.exe -> Dropper.Agent.dgo : Ignored.

C:\System Volume Information_restore{A9F343B2-4782-465F-9AC2-EBD5FA767CBC}\RP48\A0069514.exe -> Dropper.Agent.dgo : Ignored.

C:\System Volume Information_restore{A9F343B2-4782-465F-9AC2-EBD5FA767CBC}\RP48\A0069515.exe -> Dropper.Agent.dgo : Ignored.

C:\System Volume Information_restore{A9F343B2-4782-465F-9AC2-EBD5FA767CBC}\RP48\A0069520.exe -> Dropper.Agent.dgo : Ignored.

C:\System Volume Information_restore{A9F343B2-4782-465F-9AC2-EBD5FA767CBC}\RP48\A0069528.exe -> Dropper.Agent.dgo : Ignored.

C:\System Volume Information_restore{A9F343B2-4782-465F-9AC2-EBD5FA767CBC}\RP48\A0069529.exe -> Dropper.Agent.dgo : Ignored.

C:\System Volume Information_restore{A9F343B2-4782-465F-9AC2-EBD5FA767CBC}\RP48\A0069533.exe -> Dropper.Agent.dgo : Ignored.

C:\System Volume Information_restore{A9F343B2-4782-465F-9AC2-EBD5FA767CBC}\RP48\A0069534.exe -> Dropper.Agent.dgo : Ignored.

C:\System Volume Information_restore{A9F343B2-4782-465F-9AC2-EBD5FA767CBC}\RP48\A0069547.exe -> Dropper.Agent.dgo : Ignored.

C:\System Volume Information_restore{A9F343B2-4782-465F-9AC2-EBD5FA767CBC}\RP48\A0069548.exe -> Dropper.Agent.dgo : Ignored.

C:\System Volume Information_restore{A9F343B2-4782-465F-9AC2-EBD5FA767CBC}\RP48\A0069552.exe -> Dropper.Agent.dgo : Ignored.

C:\System Volume Information_restore{A9F343B2-4782-465F-9AC2-EBD5FA767CBC}\RP48\A0069575.exe -> Dropper.Agent.dgo : Ignored.

C:\System Volume Information_restore{A9F343B2-4782-465F-9AC2-EBD5FA767CBC}\RP48\A0069576.exe -> Dropper.Agent.dgo : Ignored.

C:\System Volume Information_restore{A9F343B2-4782-465F-9AC2-EBD5FA767CBC}\RP48\A0069581.exe -> Dropper.Agent.dgo : Ignored.

C:\System Volume Information_restore{A9F343B2-4782-465F-9AC2-EBD5FA767CBC}\RP48\A0069586.exe -> Dropper.Agent.dgo : Ignored.

C:\System Volume Information_restore{A9F343B2-4782-465F-9AC2-EBD5FA767CBC}\RP48\A0069587.exe -> Dropper.Agent.dgo : Ignored.

C:\System Volume Information_restore{A9F343B2-4782-465F-9AC2-EBD5FA767CBC}\RP48\A0069591.exe -> Dropper.Agent.dgo : Ignored.

C:\System Volume Information_restore{A9F343B2-4782-465F-9AC2-EBD5FA767CBC}\RP48\A0069599.exe -> Dropper.Agent.dgo : Ignored.

C:\System Volume Information_restore{A9F343B2-4782-465F-9AC2-EBD5FA767CBC}\RP48\A0069600.exe -> Dropper.Agent.dgo : Ignored.

C:\System Volume Information_restore{A9F343B2-4782-465F-9AC2-EBD5FA767CBC}\RP48\A0069603.exe -> Dropper.Agent.dgo : Ignored.

C:\System Volume Information_restore{A9F343B2-4782-465F-9AC2-EBD5FA767CBC}\RP48\A0069604.exe -> Dropper.Agent.dgo : Ignored.

C:\System Volume Information_restore{A9F343B2-4782-465F-9AC2-EBD5FA767CBC}\RP48\A0069613.exe -> Dropper.Agent.dgo : Ignored.

C:\System Volume Information_restore{A9F343B2-4782-465F-9AC2-EBD5FA767CBC}\RP48\A0069614.exe -> Dropper.Agent.dgo : Ignored.

C:\System Volume Information_restore{A9F343B2-4782-465F-9AC2-EBD5FA767CBC}\RP48\A0069625.exe -> Dropper.Agent.dgo : Ignored.

C:\System Volume Information_restore{A9F343B2-4782-465F-9AC2-EBD5FA767CBC}\RP48\A0069628.exe -> Dropper.Agent.dgo : Ignored.

C:\System Volume Information_restore{A9F343B2-4782-465F-9AC2-EBD5FA767CBC}\RP48\A0069629.exe -> Dropper.Agent.dgo : Ignored.

C:\System Volume Information_restore{A9F343B2-4782-465F-9AC2-EBD5FA767CBC}\RP48\A0069630.exe -> Dropper.Agent.dgo : Ignored.

C:\System Volume Information_restore{A9F343B2-4782-465F-9AC2-EBD5FA767CBC}\RP48\A0069634.exe -> Dropper.Agent.dgo : Ignored.

C:\System Volume Information_restore{A9F343B2-4782-465F-9AC2-EBD5FA767CBC}\RP48\A0069637.exe -> Dropper.Agent.dgo : Ignored.

C:\System Volume Information_restore{A9F343B2-4782-465F-9AC2-EBD5FA767CBC}\RP48\A0069643.exe -> Dropper.Agent.dgo : Ignored.

C:\System Volume Information_restore{A9F343B2-4782-465F-9AC2-EBD5FA767CBC}\RP48\A0069655.exe -> Dropper.Agent.dgo : Ignored.

C:\System Volume Information_restore{A9F343B2-4782-465F-9AC2-EBD5FA767CBC}\RP48\A0069657.exe -> Dropper.Agent.dgo : Ignored.

C:\System Volume Information_restore{A9F343B2-4782-465F-9AC2-EBD5FA767CBC}\RP48\A0069659.exe -> Dropper.Agent.dgo : Ignored.

C:\System Volume Information_restore{A9F343B2-4782-465F-9AC2-EBD5FA767CBC}\RP48\A0069660.exe -> Dropper.Agent.dgo : Ignored.

C:\System Volume Information_restore{A9F343B2-4782-465F-9AC2-EBD5FA767CBC}\RP48\A0069671.exe -> Dropper.Agent.dgo : Ignored.

C:\System Volume Information_restore{A9F343B2-4782-465F-9AC2-EBD5FA767CBC}\RP48\A0069673.exe -> Dropper.Agent.dgo : Ignored.

C:\System Volume Information_restore{A9F343B2-4782-465F-9AC2-EBD5FA767CBC}\RP48\A0069675.exe -> Dropper.Agent.dgo : Ignored.

C:\System Volume Information_restore{A9F343B2-4782-465F-9AC2-EBD5FA767CBC}\RP48\A0070674.exe -> Dropper.Agent.dgo : Ignored.

C:\System Volume Information_restore{A9F343B2-4782-465F-9AC2-EBD5FA767CBC}\RP48\A0070675.exe -> Dropper.Agent.dgo : Ignored.

C:\System Volume Information_restore{A9F343B2-4782-465F-9AC2-EBD5FA767CBC}\RP48\A0071670.exe -> Dropper.Agent.dgo : Ignored.

C:\System Volume Information_restore{A9F343B2-4782-465F-9AC2-EBD5FA767CBC}\RP48\A0071671.exe -> Dropper.Agent.dgo : Ignored.

C:\System Volume Information_restore{A9F343B2-4782-465F-9AC2-EBD5FA767CBC}\RP48\A0071672.exe -> Dropper.Agent.dgo : Ignored.

C:\System Volume Information_restore{A9F343B2-4782-465F-9AC2-EBD5FA767CBC}\RP48\A0071686.exe -> Dropper.Agent.dgo : Ignored.

C:\System Volume Information_restore{A9F343B2-4782-465F-9AC2-EBD5FA767CBC}\RP48\A0071693.exe -> Dropper.Agent.dgo : Ignored.

C:\System Volume Information_restore{A9F343B2-4782-465F-9AC2-EBD5FA767CBC}\RP48\A0071702.exe -> Dropper.Agent.dgo : Ignored.

C:\System Volume Information_restore{A9F343B2-4782-465F-9AC2-EBD5FA767CBC}\RP48\A0071703.exe -> Dropper.Agent.dgo : Ignored.

C:\System Volume Information_restore{A9F343B2-4782-465F-9AC2-EBD5FA767CBC}\RP48\A0071706.exe -> Dropper.Agent.dgo : Ignored.

C:\System Volume Information_restore{A9F343B2-4782-465F-9AC2-EBD5FA767CBC}\RP48\A0071707.exe -> Dropper.Agent.dgo : Ignored.

C:\System Volume Information_restore{A9F343B2-4782-465F-9AC2-EBD5FA767CBC}\RP48\A0071712.exe -> Dropper.Agent.dgo : Ignored.

C:\System Volume Information_restore{A9F343B2-4782-465F-9AC2-EBD5FA767CBC}\RP48\A0071713.exe -> Dropper.Agent.dgo : Ignored.

C:\System Volume Information_restore{A9F343B2-4782-465F-9AC2-EBD5FA767CBC}\RP48\A0072702.exe -> Dropper.Agent.dgo : Ignored.

C:\System Volume Information_restore{A9F343B2-4782-465F-9AC2-EBD5FA767CBC}\RP48\A0072703.exe -> Dropper.Agent.dgo : Ignored.

C:\System Volume Information_restore{A9F343B2-4782-465F-9AC2-EBD5FA767CBC}\RP48\A0072704.exe -> Dropper.Agent.dgo : Ignored.

C:\System Volume Information_restore{A9F343B2-4782-465F-9AC2-EBD5FA767CBC}\RP48\A0072707.exe -> Dropper.Agent.dgo : Ignored.

C:\System Volume Information_restore{A9F343B2-4782-465F-9AC2-EBD5FA767CBC}\RP48\A0072708.exe -> Dropper.Agent.dgo : Ignored.

C:\System Volume Information_restore{A9F343B2-4782-465F-9AC2-EBD5FA767CBC}\RP48\A0072715.exe -> Dropper.Agent.dgo : Ignored.

C:\System Volume Information_restore{A9F343B2-4782-465F-9AC2-EBD5FA767CBC}\RP48\A0072734.exe -> Dropper.Agent.dgo : Ignored.

C:\System Volume Information_restore{A9F343B2-4782-465F-9AC2-EBD5FA767CBC}\RP48\A0072737.exe -> Dropper.Agent.dgo : Ignored.

C:\System Volume Information_restore{A9F343B2-4782-465F-9AC2-EBD5FA767CBC}\RP48\A0072738.exe -> Dropper.Agent.dgo : Ignored.

C:\System Volume Information_restore{A9F343B2-4782-465F-9AC2-EBD5FA767CBC}\RP48\A0072743.exe -> Dropper.Agent.dgo : Ignored.

C:\System Volume Information_restore{A9F343B2-4782-465F-9AC2-EBD5FA767CBC}\RP48\A0073703.exe -> Dropper.Agent.dgo : Ignored.

C:\System Volume Information_restore{A9F343B2-4782-465F-9AC2-EBD5FA767CBC}\RP48\A0073705.exe -> Dropper.Agent.dgo : Ignored.

C:\System Volume Information_restore{A9F343B2-4782-465F-9AC2-EBD5FA767CBC}\RP48\A0074702.exe -> Dropper.Agent.dgo : Ignored.

C:\System Volume Information_restore{A9F343B2-4782-465F-9AC2-EBD5FA767CBC}\RP48\A0074704.exe -> Dropper.Agent.dgo : Ignored.

C:\System Volume Information_restore{A9F343B2-4782-465F-9AC2-EBD5FA767CBC}\RP48\A0074707.exe -> Dropper.Agent.dgo : Ignored.

C:\System Volume Information_restore{A9F343B2-4782-465F-9AC2-EBD5FA767CBC}\RP48\A0074717.exe -> Dropper.Agent.dgo : Ignored.

C:\System Volume Information_restore{A9F343B2-4782-465F-9AC2-EBD5FA767CBC}\RP48\A0074718.exe -> Dropper.Agent.dgo : Ignored.

C:\System Volume Information_restore{A9F343B2-4782-465F-9AC2-EBD5FA767CBC}\RP48\A0074729.exe -> Dropper.Agent.dgo : Ignored.

C:\System Volume Information_restore{A9F343B2-4782-465F-9AC2-EBD5FA767CBC}\RP50\A0078236.exe -> Dropper.Agent.dgo : Ignored.

C:\System Volume Information_restore{A9F343B2-4782-465F-9AC2-EBD5FA767CBC}\RP50\A0078245.exe -> Dropper.Agent.dgo : Ignored.

C:\System Volume Information_restore{A9F343B2-4782-465F-9AC2-EBD5FA767CBC}\RP50\A0078250.exe -> Dropper.Agent.dgo : Ignored.

C:\System Volume Information_restore{A9F343B2-4782-465F-9AC2-EBD5FA767CBC}\RP50\A0078251.exe -> Dropper.Agent.dgo : Ignored.

C:\System Volume Information_restore{A9F343B2-4782-465F-9AC2-EBD5FA767CBC}\RP50\A0078475.exe -> Dropper.Agent.dgo : Ignored.

C:\System Volume Information_restore{A9F343B2-4782-465F-9AC2-EBD5FA767CBC}\RP51\A0078649.exe -> Dropper.Agent.dgo : Ignored.

C:\System Volume Information_restore{A9F343B2-4782-465F-9AC2-EBD5FA767CBC}\RP51\A0078650.exe -> Dropper.Agent.dgo : Ignored.

C:\System Volume Information_restore{A9F343B2-4782-465F-9AC2-EBD5FA767CBC}\RP51\A0078651.exe -> Dropper.Agent.dgo : Ignored.

C:\System Volume Information_restore{A9F343B2-4782-465F-9AC2-EBD5FA767CBC}\RP51\A0078652.exe -> Dropper.Agent.dgo : Ignored.

C:\System Volume Information_restore{A9F343B2-4782-465F-9AC2-EBD5FA767CBC}\RP51\A0078654.exe -> Dropper.Agent.dgo : Ignored.

C:\System Volume Information_restore{A9F343B2-4782-465F-9AC2-EBD5FA767CBC}\RP51\A0078657.exe -> Dropper.Agent.dgo : Ignored.

C:\System Volume Information_restore{A9F343B2-4782-465F-9AC2-EBD5FA767CBC}\RP52\A0078796.exe -> Dropper.Agent.dgo : Ignored.

C:\System Volume Information_restore{A9F343B2-4782-465F-9AC2-EBD5FA767CBC}\RP57\A0079145.exe -> Dropper.Agent.dgo : Ignored.

C:\System Volume Information_restore{A9F343B2-4782-465F-9AC2-EBD5FA767CBC}\RP57\A0079150.exe -> Dropper.Agent.dgo : Ignored.

C:\System Volume Information_restore{A9F343B2-4782-465F-9AC2-EBD5FA767CBC}\RP57\A0079151.exe -> Dropper.Agent.dgo : Ignored.

C:\System Volume Information_restore{A9F343B2-4782-465F-9AC2-EBD5FA767CBC}\RP59\A0080336.exe -> Dropper.Agent.dgo : Ignored.

C:\Documents and Settings\Maciej\Cookies\maciej@3.adbrite[1].txt -> TrackingCookie.Adbrite : Ignored.

C:\Documents and Settings\Maciej\Cookies\maciej@4.adbrite[2].txt -> TrackingCookie.Adbrite : Ignored.

C:\Documents and Settings\Maciej\Cookies\maciej@adbrite[1].txt -> TrackingCookie.Adbrite : Ignored.

C:\Documents and Settings\Maciej\Cookies\maciej@ads.adbrite[2].txt -> TrackingCookie.Adbrite : Ignored.

C:\Documents and Settings\Maciej\Cookies\maciej@doubleclick[1].txt -> TrackingCookie.Doubleclick : Ignored.

C:\Documents and Settings\Maciej\Cookies\maciej@hit.gemius[13].txt -> TrackingCookie.Gemius : Ignored.

C:\Documents and Settings\Maciej\Cookies\maciej@ivwbox[2].txt -> TrackingCookie.Ivwbox : Ignored.

C:\Documents and Settings\Maciej\Cookies\maciej@image.masterstats[1].txt -> TrackingCookie.Masterstats : Ignored.

:mozilla.44:C:\Documents and Settings\Maciej\Dane aplikacji\Mozilla\Firefox\Profiles\w8kvmd21.default\cookies.txt -> TrackingCookie.Msn : Ignored.

:mozilla.45:C:\Documents and Settings\Maciej\Dane aplikacji\Mozilla\Firefox\Profiles\w8kvmd21.default\cookies.txt -> TrackingCookie.Msn : Ignored.

:mozilla.46:C:\Documents and Settings\Maciej\Dane aplikacji\Mozilla\Firefox\Profiles\w8kvmd21.default\cookies.txt -> TrackingCookie.Msn : Ignored.

C:\Documents and Settings\Maciej\Cookies\maciej@auto.search.msn[2].txt -> TrackingCookie.Msn : Ignored.

C:\Documents and Settings\Maciej\Cookies\maciej@ssl-hints.netflame[1].txt -> TrackingCookie.Netflame : Ignored.

C:\Documents and Settings\Maciej\Cookies\maciej@tradedoubler[1].txt -> TrackingCookie.Tradedoubler : Ignored.

::Report end

Prawoklik na Mój Komputer>>>>Właściwości>>Przywracanie systemu>> wyłącz przywracanie systemu na wszystkich dyskach.