Can you find out what do these Win32:Agent-SG [Trj] detections correspond to? I mean, if you run Process Explorer and check the process with ID 876 (or what the virus dialog shows at the particular case)… what is it?
Additionally, if you select this process (in Process Explorer) and press Ctrl+D to display the DLLs in the lower pane - is there any DLL where the reported addresses (e.g. 02B10000) would fall into?