This would lead me to believe there is likely another infection somewhere that is attempting to compromise any antivirus vendors it finds on the server. Have you completed a deep scan/root kit scan on this environment?
Beyond that though, those locations look to be in tmp folders so if they are all being generated from there this could be leftover temp files from previous scans perhaps?
Kyle Kerst
IT Coordinator
SmarterTools Inc.
www.smartertools.com