BitDefender Log File !!!!!
Product : BitDefender Total Security 2008
Version : BitDefender UIScanner v.11
Log date : 17:51:04 24/01/2008
Log path : C:\Documents and Settings\user\Application
Data\BitDefender\Desktop\Profiles\Logs\contextual\ 120121
5064_1_02.xml
Scan Paths:Path0000: C:\
Path0001: D:\
Scan Options:Scan for viruses : Yes
Scan for adware : Yes
Scan for spyware : Yes
Scan for applications : Yes
Scan for dialers : Yes
Scan for rootkits : No
Target selection options:Scan registry keys : No
Scan cookies : No
Scan boot sectors : No
Scan memory processes : No
Scan archives : Yes
Scan runtime packers : Yes
Scan emails : Yes
Scan all files : Yes
Heuristic Scan : Yes
Scanned extensions :
Excluded extensions :
Target ProcessingDefault action for infected objects :
Disinfect
Default action for suspicious objects : None
Default action for hidden objects : None
Scan engines summaryNumber of virus signatures : 976923
Archive plugins : 41
Email plugins : 6
Scan plugins : 12
Archive plugins : 41
System plugins : 4
Unpack plugins : 7
Overall scan summaryScanned items : 300042
Infected items : 159
Suspicious items : 1
Resolved items : 128
Individual viruses found : 33
Scanned directories : 1983
Scanned boot sectors : 0
Scanned archives : 10043
Input-output errors : 28
Scan time : 00:03:55:02
Files per second : 21
Scanned processes summaryScanned : 0
Infected : 0
Scanned registry keys summaryScanned : 0
Infected : 0
Scanned cookies summaryScanned : 0
Infected : 0
D:\qwe\New Folder\getright.exe=]wise0088 Adware.Gator.AD
Delete Failed (file was in an archive)
D:\System Volume Information\_restore{7BC99C4C-760E-
4A10-ABDA-0C86E98FEB48}\RP12\A0001547.exe=](VISE
Installer o)=]Gain_Trickler.exe Adware.Gator.C Delete
Failed (file was in an archive)
D:\System Volume Information\_restore{7BC99C4C-760E-
4A10-ABDA-0C86E98FEB48}\RP12\A0001593.exe=](VISE
Installer o)=]Gain_Trickler.exe Adware.Gator.C Delete
Failed (file was in an archive)
D:\qwe\New Folder\serv-u.zip=]Serv-U3.0.19.exe=](ZIP Sfx
o)=]SERVUDAEMON.EXE Backdoor.Servudoor.B Delete Failed
(file was in an archive)
D:\qwe\New Folder\AD Kill.zip=]akiller.exe=](Instyler
o)=](Instyler Module 1) BehavesLike:Win32.Keylogger
Delete Failed (file was in an archive)
D:\game\gb_digimon_cn.zip=]gb_digimon_cn.gbc Password-
Protected Items No action was possible
D:\Program Files\Lavasoft\Ad-Aware SE Personal\Skins\Ad
-Aware SE default.ask=]Ad-Aware SE Default.skn Password
-Protected Items No action was possible
D:\Program Files\Lavasoft\Ad-Aware SE Personal\Skins\Ad
-Aware SE default.ask=]arrow1.bmp Password-Protected
Items No action was possible
D:\Program Files\Lavasoft\Ad-Aware SE Personal\Skins\Ad
-Aware SE default.ask=]arrow2.bmp Password-Protected
Items No action was possible
D:\Program Files\Lavasoft\Ad-Aware SE Personal\Skins\Ad
-Aware SE default.ask=]bck1.bmp Password-Protected Items
No action was possible
D:\Program Files\Lavasoft\Ad-Aware SE Personal\Skins\Ad
-Aware SE default.ask=]bt11.bmp Password-Protected Items
No action was possible
D:\Program Files\Lavasoft\Ad-Aware SE Personal\Skins\Ad
-Aware SE default.ask=]bt12.bmp Password-Protected Items
No action was possible
D:\Program Files\Lavasoft\Ad-Aware SE Personal\Skins\Ad
-Aware SE default.ask=]bt13.bmp Password-Protected Items
No action was possible
D:\Program Files\Lavasoft\Ad-Aware SE Personal\Skins\Ad
-Aware SE default.ask=]bt21.bmp Password-Protected Items
No action was possible
D:\Program Files\Lavasoft\Ad-Aware SE Personal\Skins\Ad
-Aware SE default.ask=]bt22.bmp Password-Protected Items
No action was possible
D:\Program Files\Lavasoft\Ad-Aware SE Personal\Skins\Ad
-Aware SE default.ask=]bt23.bmp Password-Protected Items
No action was possible
D:\Program Files\Lavasoft\Ad-Aware SE Personal\Skins\Ad
-Aware SE default.ask=]bt31.bmp Password-Protected Items
No action was possible
D:\Program Files\Lavasoft\Ad-Aware SE Personal\Skins\Ad
-Aware SE default.ask=]bt32.bmp Password-Protected Items
No action was possible
D:\Program Files\Lavasoft\Ad-Aware SE Personal\Skins\Ad
-Aware SE default.ask=]bt33.bmp Password-Protected Items
No action was possible
D:\Program Files\Lavasoft\Ad-Aware SE Personal\Skins\Ad
-Aware SE default.ask=]bt41.bmp Password-Protected Items
No action was possible
D:\Program Files\Lavasoft\Ad-Aware SE Personal\Skins\Ad
-Aware SE default.ask=]bt42.bmp Password-Protected Items
No action was possible
D:\Program Files\Lavasoft\Ad-Aware SE Personal\Skins\Ad
-Aware SE default.ask=]bt43.bmp Password-Protected Items
No action was possible
D:\Program Files\Lavasoft\Ad-Aware SE Personal\Skins\Ad
-Aware SE default.ask=]bt51.bmp Password-Protected Items
No action was possible
D:\Program Files\Lavasoft\Ad-Aware SE Personal\Skins\Ad
-Aware SE default.ask=]bt52.bmp Password-Protected Items
No action was possible
D:\Program Files\Lavasoft\Ad-Aware SE Personal\Skins\Ad
-Aware SE default.ask=]bt53.bmp Password-Protected Items
No action was possible
D:\Program Files\Lavasoft\Ad-Aware SE Personal\Skins\Ad
-Aware SE default.ask=]bt61.bmp Password-Protected Items
No action was possible
D:\Program Files\Lavasoft\Ad-Aware SE Personal\Skins\Ad
-Aware SE default.ask=]bt62.bmp Password-Protected Items
No action was possible
D:\Program Files\Lavasoft\Ad-Aware SE Personal\Skins\Ad
-Aware SE default.ask=]checkbox1.bmp Password-Protected
Items No action was possible
D:\Program Files\Lavasoft\Ad-Aware SE Personal\Skins\Ad
-Aware SE default.ask=]checkbox2.bmp Password-Protected
Items No action was possible
D:\Program Files\Lavasoft\Ad-Aware SE Personal\Skins\Ad
-Aware SE default.ask=]checkbox3.bmp Password-Protected
Items No action was possible
D:\Program Files\Lavasoft\Ad-Aware SE Personal\Skins\Ad
-Aware SE default.ask=]checkbox4.bmp Password-Protected
Items No action was possible
D:\Program Files\Lavasoft\Ad-Aware SE Personal\Skins\Ad
-Aware SE default.ask=]defbtn1.bmp Password-Protected
Items No action was possible
D:\Program Files\Lavasoft\Ad-Aware SE Personal\Skins\Ad
-Aware SE default.ask=]defbtn2.bmp Password-Protected
Items No action was possible
D:\Program Files\Lavasoft\Ad-Aware SE Personal\Skins\Ad
-Aware SE default.ask=]defbtn3.bmp Password-Protected
Items No action was possible
D:\Program Files\Lavasoft\Ad-Aware SE Personal\Skins\Ad
-Aware SE default.ask=]glyph1.bmp Password-Protected
Items No action was possible
D:\Program Files\Lavasoft\Ad-Aware SE Personal\Skins\Ad
-Aware SE default.ask=]glyph2.bmp Password-Protected
Items No action was possible
D:\Program Files\Lavasoft\Ad-Aware SE Personal\Skins\Ad
-Aware SE default.ask=]glyph3.bmp Password-Protected
Items No action was possible
D:\Program Files\Lavasoft\Ad-Aware SE Personal\Skins\Ad
-Aware SE default.ask=]glyph4.bmp Password-Protected
Items No action was possible
D:\Program Files\Lavasoft\Ad-Aware SE Personal\Skins\Ad
-Aware SE default.ask=]glyph5.bmp Password-Protected
Items No action was possible
D:\Program Files\Lavasoft\Ad-Aware SE Personal\Skins\Ad
-Aware SE default.ask=]glyph6.bmp Password-Protected
Items No action was possible
D:\Program Files\Lavasoft\Ad-Aware SE Personal\Skins\Ad
-Aware SE default.ask=]glyph7.bmp Password-Protected
Items No action was possible
D:\Program Files\Lavasoft\Ad-Aware SE Personal\Skins\Ad
-Aware SE default.ask=]main.bmp Password-Protected Items
No action was possible
D:\Program Files\Lavasoft\Ad-Aware SE Personal\Skins\Ad
-Aware SE default.ask=]preview.bmp Password-Protected
Items No action was possible
D:\Program Files\Lavasoft\Ad-Aware SE Personal\Skins\Ad
-Aware SE default.ask=]sprite1.bmp Password-Protected
Items No action was possible
D:\qwe\New Folder\Hero-2001XP.rar=]Bkbmp\START.WAV
Password-Protected Items No action was possible
D:\qwe\New Folder\Hero-2001XP.rar=]Bkbmp\setup01.bmp
Password-Protected Items No action was possible
D:\qwe\New Folder\Hero-2001XP.rar=]Bkbmp\setup02.bmp
Password-Protected Items No action was possible
D:\qwe\New Folder\Hero-2001XP.rar=]Bkbmp\setup03.bmp
Password-Protected Items No action was possible
D:\qwe\New Folder\Hero-2001XP.rar=]Bkbmp\setup04.bmp
Password-Protected Items No action was possible
D:\qwe\New Folder\Hero-2001XP.rar=]Bkbmp\setup05.bmp
Password-Protected Items No action was possible
D:\qwe\New Folder\Hero-2001XP.rar=]Bkbmp\setup06.bmp
Password-Protected Items No action was possible
D:\qwe\New Folder\Hero-2001XP.rar=]Bkbmp\setup07.bmp
Password-Protected Items No action was possible
D:\qwe\New Folder\Hero-2001XP.rar=]Bkbmp\setup08.bmp
Password-Protected Items No action was possible
D:\qwe\New Folder\Hero-2001XP.rar=]Bkbmp\setup09.bmp
Password-Protected Items No action was possible
D:\qwe\New Folder\Hero-2001XP.rar=]Bkbmp\setup10.bmp
Password-Protected Items No action was possible
D:\qwe\New Folder\Hero-2001XP.rar=]Mpeg4\INSTMPG4.EXE
Password-Protected Items No action was possible
D:\qwe\New Folder\Hero-2001XP.rar=]AUTORUN.INF Password
-Protected Items No action was possible
D:\qwe\New Folder\Hero-2001XP.rar=]CHINA.INI Password-
Protected Items No action was possible
D:\qwe\New Folder\Hero-2001XP.rar=]DATA.DAT Password-
Protected Items No action was possible
D:\qwe\New Folder\Hero-2001XP.rar=]ENGLISH.INI Password
-Protected Items No action was possible
D:\qwe\New Folder\Hero-2001XP.rar=]FILELIST.INI
Password-Protected Items No action was possible
D:\qwe\New Folder\Hero-2001XP.rar=]herosoft.url
Password-Protected Items No action was possible
D:\qwe\New Folder\Hero-2001XP.rar=]SETUP.EXE Password-
Protected Items No action was possible
D:\qwe\New Folder\Hero-2001XP.rar=]SETUP.INI Password-
Protected Items No action was possible
D:\qwe\New Folder\Hero-2001XP.rar=]SETUP936.DLL
Password-Protected Items No action was possible
D:\qwe\New Folder\Hero-2001XP.rar=]SETUPLUG.DLL
Password-Protected Items No action was possible
D:\qwe\New Folder\Hero-2001XP.rar=]????????.txt
Password-Protected Items No action was possible
D:\qwe\New Folder\Hero-2001XP.rar=]????????.txt
Password-Protected Items No action was possible
D:\qwe\New Folder\Hero-2001XP.rar=]????????????.url
Password-Protected Items No action was possible
D:\qwe\New Folder\hotmailhack.zip=]Hotmail hack.exe
Password-Protected Items No action was possible
D:\qwe\New Folder\hotmailhack.zip=]001.txt Password-
Protected Items No action was possible
D:\qwe\New Folder\hotmailhack.zip=]002.txt Password-
Protected Items No action was possible
D:\qwe\New Folder\hotmailhack.zip=]003.txt Password-
Protected Items No action was possible
D:\qwe\New Folder\hotmailhack.zip=]004.txt Password-
Protected Items No action was possible
D:\qwe\New Folder\hotmailhack.zip=]005.txt Password-
Protected Items No action was possible
D:\qwe\New Folder\hotmailhack.zip=]006.txt Password-
Protected Items No action was possible
Resolved issues:Object Name Threat Name Final Status
D:\ntldr.exe Generic.Malware.SP!BdldPk!g.C2058CB7 Moved
to Quarantine
D:\System Volume Information\_restore{3C251E10-6E50-
4A43-8132-B5F122A37B6C}\RP7\A0002385.exe
Generic.Malware.SP!BdldPk!g.C2058CB7 Moved to Quarantine
D:\System Volume Information\_restore{3C251E10-6E50-
4A43-8132-B5F122A37B6C}\RP7\A0003392.exe
Generic.Malware.SP!BdldPk!g.C2058CB7 Moved to Quarantine
D:\System Volume Information\_restore{3C251E10-6E50-
4A43-8132-B5F122A37B6C}\RP7\A0003395.exe
Generic.Malware.SP!BdldPk!g.C2058CB7 Moved to Quarantine
D:\System Volume Information\_restore{3C251E10-6E50-
4A43-8132-B5F122A37B6C}\RP7\A0004394.exe
Generic.Malware.SP!BdldPk!g.C2058CB7 Moved to Quarantine
D:\System Volume Information\_restore{3C251E10-6E50-
4A43-8132-B5F122A37B6C}\RP8\A0003405.exe
Generic.Malware.SP!BdldPk!g.C2058CB7 Moved to Quarantine
D:\System Volume Information\_restore{3C251E10-6E50-
4A43-8132-B5F122A37B6C}\RP9\A0003427.exe
Generic.Malware.SP!BdldPk!g.C2058CB7 Moved to Quarantine
D:\qwe\New Folder\Boom21.zip=]Boom21/Boom.exe
Trojan.DoS.Lanxue.21 Deleted
D:\Program Files\Tencent\QQ\QQexternal.exe
Trojan.Dropper.Agent.AJW Deleted
D:\System Volume Information\_restore{3C251E10-6E50-
4A43-8132-B5F122A37B6C}\RP10\A0004520.exe
Trojan.Dropper.Agent.AJW Deleted
D:\Program Files\Tencent\QQ\QQPet\QQPetDazzle.exe
Trojan.Dropper.Agent.BCT Deleted
D:\System Volume Information\_restore{3C251E10-6E50-
4A43-8132-B5F122A37B6C}\RP10\A0004521.exe
Trojan.Dropper.Agent.BCT Deleted
D:\qwe\New Folder\ipcscan.zip=]ipcscan/IpcScan.exe
Trojan.IpcScan.1.50 Deleted
C:\System Volume Information\_restore{3C251E10-6E50-
4A43-8132-B5F122A37B6C}\RP2\A0000027.inf
Win32.Worm.Autorun.GN Moved to Quarantine
D:\autorun.inf Win32.Worm.Autorun.GN Moved to Quarantine
D:\Documents and Setting\Ash\zzz.txt
Win32.Worm.Autorun.GN Moved to Quarantine
D:\RECYCLER\S-1-5-21-1757981266-1682526488-1060284298-
1003\Dd1.inf Win32.Worm.Autorun.GN Moved to Quarantine
D:\RECYCLER\S-1-5-21-1757981266-1682526488-1060284298-
1003\Dd7.inf Win32.Worm.Autorun.GN Moved to Quarantine
D:\RECYCLER\S-1-5-21-2025429265-854245398-1957994488-
1003\Dd3.inf Win32.Worm.Autorun.GN Moved to Quarantine
D:\System Volume Information\_restore{3C251E10-6E50-
4A43-8132-B5F122A37B6C}\RP4\A0000055.inf
Win32.Worm.Autorun.GN Moved to Quarantine
D:\System Volume Information\_restore{3C251E10-6E50-
4A43-8132-B5F122A37B6C}\RP4\A0000056.inf
Win32.Worm.Autorun.GN Moved to Quarantine
D:\System Volume Information\_restore{3C251E10-6E50-
4A43-8132-B5F122A37B6C}\RP5\A0000091.inf
Win32.Worm.Autorun.GN Moved to Quarantine
D:\System Volume Information\_restore{3C251E10-6E50-
4A43-8132-B5F122A37B6C}\RP7\A0001384.inf
Win32.Worm.Autorun.GN Moved to Quarantine
D:\System Volume Information\_restore{3C251E10-6E50-
4A43-8132-B5F122A37B6C}\RP7\A0001387.inf
Win32.Worm.Autorun.GN Moved to Quarantine
D:\System Volume Information\_restore{3C251E10-6E50-
4A43-8132-B5F122A37B6C}\RP7\A0002384.inf
Win32.Worm.Autorun.GN Moved to Quarantine
D:\System Volume Information\_restore{3C251E10-6E50-
4A43-8132-B5F122A37B6C}\RP7\A0003391.inf
Win32.Worm.Autorun.GN Moved to Quarantine
D:\System Volume Information\_restore{3C251E10-6E50-
4A43-8132-B5F122A37B6C}\RP7\A0003394.inf
Win32.Worm.Autorun.GN Moved to Quarantine
D:\System Volume Information\_restore{3C251E10-6E50-
4A43-8132-B5F122A37B6C}\RP7\A0004393.inf
Win32.Worm.Autorun.GN Moved to Quarantine
D:\System Volume Information\_restore{3C251E10-6E50-
4A43-8132-B5F122A37B6C}\RP8\A0003404.inf
Win32.Worm.Autorun.GN Moved to Quarantine
D:\System Volume Information\_restore{3C251E10-6E50-
4A43-8132-B5F122A37B6C}\RP9\A0003426.inf
Win32.Worm.Autorun.GN Moved to Quarantine
D:\Documents and Setting\Ash\game\New Folder\New
Folder\BasicBoy202\BasicBoy202.exe Win32.Worm.Cekar.A
Moved to Quarantine
D:\Documents and Setting\Ash\game\New Folder\New Folder
(2)\kigb.exe Win32.Worm.Cekar.A Moved to Quarantine
D:\Documents and Setting\Ash\game\New Folder\New Folder
(3)\PlayGuy+.exe Win32.Worm.Cekar.A Moved to Quarantine
D:\Documents and Setting\Ash\game\New Folder\New Folder
(4)\kigb.exe Win32.Worm.Cekar.A Moved to Quarantine
D:\Documents and Setting\Ash\game\New Folder (5)
\VisualBoyAdvance.exe Win32.Worm.Cekar.A Moved to
Quarantine
D:\Documents and Setting\Ash\qwe.exe Win32.Worm.Cekar.A
Moved to Quarantine
D:\Documents and Setting\Ash\sea.exe Win32.Worm.Cekar.A
Moved to Quarantine
D:\Documents and Setting\Ash\soft\ATF-Cleaner.exe
Win32.Worm.Cekar.A Moved to Quarantine
D:\Documents and Setting\Ash\soft\Chessmaster
Challenge\engine\TheKing.exe Win32.Worm.Cekar.A Moved to
Quarantine
D:\Documents and Setting\Ash\soft\ha\ipscan.exe
Win32.Worm.Cekar.A Moved to Quarantine
D:\Documents and Setting\Ash\soft\HijackThis.exe
Win32.Worm.Cekar.A Moved to Quarantine
D:\Documents and Setting\Ash\soft\hijackthis_sfx.exe
Win32.Worm.Cekar.A Moved to Quarantine
D:\Documents and Setting\Ash\soft\index\IDSuite.exe
Win32.Worm.Cekar.A Moved to Quarantine
D:\Documents and Setting\Ash\soft\Magnifying Glass.exe
Win32.Worm.Cekar.A Moved to Quarantine
D:\Documents and Setting\Ash\soft\need\jinstall.exe
Win32.Worm.Cekar.A Moved to Quarantine
D:\Documents and Setting\Ash\soft\netsupport\nsmdos.exe
Win32.Worm.Cekar.A Moved to Quarantine
D:\Documents and Setting\Ash\untitled folder 1
\NJWIN\NJWIN32.EXE Win32.Worm.Cekar.A Moved to
Quarantine
D:\Documents and Setting\Ash\untitled folder 1\Program
Files\AIM95\aimauto.exe Win32.Worm.Cekar.A Moved to
Quarantine
D:\Documents and Setting\Ash\untitled folder 1\Program
Files\AIM95\unwise32.exe Win32.Worm.Cekar.A Moved to
Quarantine
D:\Documents and Setting\Ash\untitled folder 1\Program
Files\ICW-Internet Connection Wizard\ICWCONN1.EXE
Win32.Worm.Cekar.A Moved to Quarantine
D:\Documents and Setting\Ash\untitled folder 1\Program
Files\ICW-Internet Connection Wizard\ICWCONN2.EXE
Win32.Worm.Cekar.A Moved to Quarantine
D:\Documents and Setting\Ash\untitled folder 1\Program
Files\Microsoft Office\Office\BINDER.EXE
Win32.Worm.Cekar.A Moved to Quarantine
D:\Documents and Setting\Ash\untitled folder 1\Program
Files\Microsoft Office\Office\GRAFLINK.EXE
Win32.Worm.Cekar.A Moved to Quarantine
D:\Documents and Setting\Ash\untitled folder 1\Program
Files\Microsoft Office\Office\MSOFFICE.EXE
Win32.Worm.Cekar.A Moved to Quarantine
D:\Documents and Setting\Ash\untitled folder 1\Program
Files\Virtual Cop2\PPJ2DD.EXE Win32.Worm.Cekar.A Moved
to Quarantine
D:\Documents and Setting\Ash\untitled folder 1\Program
Files\Websters World Encyclopedia 98\IUPDATE.EXE
Win32.Worm.Cekar.A Moved to Quarantine
D:\Documents and Setting\Ash\untitled folder 1\Program
Files\Websters World Encyclopedia 98\REGO32.EXE
Win32.Worm.Cekar.A Moved to Quarantine
D:\Documents and Setting\Ash\untitled folder 1\Program
Files\Websters World Encyclopedia 98\WebWorld.exe
Win32.Worm.Cekar.A Moved to Quarantine
D:\Documents and Setting\Ash\untitled folder 1\Program
Files\xmplayer\XMPLAYER.EXE Win32.Worm.Cekar.A Moved to
Quarantine
D:\Documents and Setting\Ash\workig\haqq\New Folder (2)
\to\TCPOptimizer.exe Win32.Worm.Cekar.A Moved to
Quarantine
D:\Documents and Setting\Ash\workig\haqq\New Folder (2)
\to\用到的工具\ASPack加壳\ASPACK.EXE Win32.Worm.Cekar.A
Moved to Quarantine
D:\Documents and Setting\Ash\workig\ms\New
Folder\MapleAidV1.01.exe Win32.Worm.Cekar.A Moved to
Quarantine
D:\Documents and Setting\Ash\workig\ms\New Folder (2)
\Vicious Engine(fixed)\Kernelmoduleunloader.exe
Win32.Worm.Cekar.A Moved to Quarantine
D:\Documents and Setting\Ash\workig\ms\New Folder (2)
\Vicious Engine(fixed)\Systemcallretriever.exe
Win32.Worm.Cekar.A Moved to Quarantine
D:\Documents and Setting\Ash\workig\ms\New Folder (2)
\Vicious Engine(fixed)\Vicious Engine 5.0.exe
Win32.Worm.Cekar.A Moved to Quarantine
D:\Documents and Setting\Ash\workig\qq\New
Folder\TCPlus.exe Win32.Worm.Cekar.A Moved to Quarantine
D:\Documents and Setting\Ash\workig\qq\QQ2004
\ChatRoom.exe Win32.Worm.Cekar.A Moved to Quarantine
D:\Documents and Setting\Ash\workig\qq\QQ2004
\MagicBook.exe Win32.Worm.Cekar.A Moved to Quarantine
D:\Documents and Setting\Ash\workig\qq\QQ2004
\MagicFlash.exe Win32.Worm.Cekar.A Moved to Quarantine
D:\Documents and Setting\Ash\workig\qq\QQ2004
\QQLiveUpdate.exe Win32.Worm.Cekar.A Moved to Quarantine
D:\Documents and Setting\Ash\workig\qq\QQ2004\QQMail.exe
Win32.Worm.Cekar.A Moved to Quarantine
D:\Documents and Setting\Ash\workig\qq\QQ2004\showip.exe
Win32.Worm.Cekar.A Moved to Quarantine
D:\Documents and Setting\Ash\workig\qq\QQ2004
\TIMPlatform.exe Win32.Worm.Cekar.A Moved to Quarantine
D:\Documents and Setting\Ash\workig\qq\QQ2004\Timwp.exe
Win32.Worm.Cekar.A Moved to Quarantine
D:\Documents and Setting\Ash\workig\qq\QQ2004
\TMDLLs\QQMail.exe Win32.Worm.Cekar.A Moved to
Quarantine
D:\Documents and Setting\Ash\workig\qq\QQ2004
\TMDLLs\TIMPlatform.exe Win32.Worm.Cekar.A Moved to
Quarantine
D:\Documents and Setting\Ash\workig\qq\QQ2004
\TMDLLs\Timwp.exe Win32.Worm.Cekar.A Moved to Quarantine
D:\Documents and Setting\Ash\workig\qq\QQ2004
\TMShell.exe Win32.Worm.Cekar.A Moved to Quarantine
D:\Documents and Setting\Ash\workig\qq\qqmail\QQMail.exe
Win32.Worm.Cekar.A Moved to Quarantine
D:\Documents and Setting\Ash\workig\vcd\VCD_PLAY.EXE
Win32.Worm.Cekar.A Moved to Quarantine
D:\Nexon\MapleStory\Patcher.exe Win32.Worm.Cekar.A Moved
to Quarantine
D:\Program Files\eMule\CrashReporter.exe
Win32.Worm.Cekar.A Moved to Quarantine
D:\Program Files\foobar2000\foobar2000.exe
Win32.Worm.Cekar.A Moved to Quarantine
D:\Program Files\iTudou\iTudou.exe Win32.Worm.Cekar.A
Moved to Quarantine
D:\Program Files\iTudou\RepairReg.exe Win32.Worm.Cekar.A
Moved to Quarantine
D:\Program Files\Kingsoft\PowerWord 2006\KSSetting.exe
Win32.Worm.Cekar.A Moved to Quarantine
D:\Program Files\Kingsoft\PowerWord 2006\NewWord.exe
Win32.Worm.Cekar.A Moved to Quarantine
D:\Program Files\Kingsoft\PowerWord 2006\RegDict.exe
Win32.Worm.Cekar.A Moved to Quarantine
D:\Program Files\Kingsoft\PowerWord 2006\ScrollWord.exe
Win32.Worm.Cekar.A Moved to Quarantine
D:\Program Files\Kingsoft\PowerWord 2006\update1.exe
Win32.Worm.Cekar.A Moved to Quarantine
D:\Program Files\Kingsoft\PowerWord 2006\XDICT.EXE
Win32.Worm.Cekar.A Moved to Quarantine
D:\Program Files\Lavasoft\Ad-Aware SE
Personal\unregaaw.exe Win32.Worm.Cekar.A Moved to
Quarantine
D:\Program Files\Tencent\QQ\MagicFlash.exe
Win32.Worm.Cekar.A Moved to Quarantine
D:\Program Files\Tencent\QQ\NetRepair.exe
Win32.Worm.Cekar.A Moved to Quarantine
D:\Program Files\Tencent\QQ\QQ3DAVPlayer.exe
Win32.Worm.Cekar.A Moved to Quarantine
D:\Program Files\Tencent\QQ\QQClubClient.exe
Win32.Worm.Cekar.A Moved to Quarantine
D:\Program Files\Tencent\QQ\QQLiveUpdate.exe
Win32.Worm.Cekar.A Moved to Quarantine
D:\Program Files\Tencent\QQ\QQMail.exe
Win32.Worm.Cekar.A Moved to Quarantine
D:\Program Files\Tencent\QQ\TIMPlatform.exe
Win32.Worm.Cekar.A Moved to Quarantine
D:\Program Files\Tencent\QQ\TIMPlatfrom.exe
Win32.Worm.Cekar.A Moved to Quarantine
D:\Program Files\Tencent\QQ\Timwp.exe Win32.Worm.Cekar.A
Moved to Quarantine
D:\Program Files\Tencent\QQ\TMDLLs\QQMail.exe
Win32.Worm.Cekar.A Moved to Quarantine
D:\Program Files\Tencent\QQ\TMDLLs\TIMPlatform.exe
Win32.Worm.Cekar.A Moved to Quarantine
D:\Program Files\Tencent\QQ\TMShell.exe
Win32.Worm.Cekar.A Moved to Quarantine
D:\Program Files\Tencent\QQ2007b\TMDLLS\QQLiveUpdate.exe
Win32.Worm.Cekar.A Moved to Quarantine
D:\Program Files\Tencent\QQ2007b\TMDLLS\TIMPlatform.exe
Win32.Worm.Cekar.A Moved to Quarantine
D:\Program Files\Tencent\QQ2007b\TMDLLS\Timwp.exe
Win32.Worm.Cekar.A Moved to Quarantine
D:\Program Files\Tencent\QQ2007b\TMShell.exe
Win32.Worm.Cekar.A Moved to Quarantine
D:\Program Files\Tencent\QQDoctor\QQDoctor.exe
Win32.Worm.Cekar.A Moved to Quarantine
D:\Program Files\Tencent\QQDownload\QDAutoUpdate.exe
Win32.Worm.Cekar.A Moved to Quarantine
D:\Program Files\Tencent\QQGame\CChess\CChess.exe
Win32.Worm.Cekar.A Moved to Quarantine
D:\Program Files\Tencent\QQGame\CChess\UNWISE.EXE
Win32.Worm.Cekar.A Moved to Quarantine
D:\Program Files\Tencent\QQGame\Download\qqt2_dl.exe
Win32.Worm.Cekar.A Moved to Quarantine
D:\Program Files\Tencent\QQGame\Go\UNWISE.EXE
Win32.Worm.Cekar.A Moved to Quarantine
D:\Program Files\Tencent\QQGame\Go\Weiqi.exe
Win32.Worm.Cekar.A Moved to Quarantine
D:\Program Files\WinRAR\Rar.exe Win32.Worm.Cekar.A Moved
to Quarantine
D:\Program Files\WinRAR\RarExtLoader.exe
Win32.Worm.Cekar.A Moved to Quarantine
D:\Program Files\WinRAR\Uninstall.exe Win32.Worm.Cekar.A
Moved to Quarantine
D:\Program Files\WinRAR\UnRAR.exe Win32.Worm.Cekar.A
Moved to Quarantine
D:\Program Files\WinRAR\WinRAR.exe Win32.Worm.Cekar.A
Moved to Quarantine
D:\System Volume Information\_restore{3C251E10-6E50-
4A43-8132-B5F122A37B6C}\RP7\A0003398.exe
Win32.Worm.Cekar.A Moved to Quarantine
D:\System Volume Information\_restore{3C251E10-6E50-
4A43-8132-B5F122A37B6C}\RP7\A0003405.exe
Win32.Worm.Cekar.A Moved to Quarantine
D:\System Volume Information\_restore{3C251E10-6E50-
4A43-8132-B5F122A37B6C}\RP7\A0003406.exe
Win32.Worm.Cekar.A Moved to Quarantine
D:\System Volume Information\_restore{3C251E10-6E50-
4A43-8132-B5F122A37B6C}\RP7\A0003408.exe
Win32.Worm.Cekar.A Moved to Quarantine
D:\System Volume Information\_restore{3C251E10-6E50-
4A43-8132-B5F122A37B6C}\RP7\A0003417.exe
Win32.Worm.Cekar.A Moved to Quarantine
D:\System Volume Information\_restore{3C251E10-6E50-
4A43-8132-B5F122A37B6C}\RP7\A0003421.exe
Win32.Worm.Cekar.A Moved to Quarantine
D:\Program Files\Tencent\QQ\QzoneSupport.exe
Win32.Worm.Ice.A Deleted
D:\System Volume Information\_restore{3C251E10-6E50-
4A43-8132-B5F122A37B6C}\RP10\A0004522.exe
Win32.Worm.Ice.A Deleted