Just an update on these files, in a few html files you'll find remnants of VBS/Ramnit.B
LTZS_BL20166.Com\phpStudy\WWW\temporary - Be sure to delete this whole folder, and possibly to be safe do not use the files. I'm fairly sure the virus has been removed at this point but to be cautious I'd suggest not using them unless you know what your doing. Sorry for my previous post about the subject since windows defender removed the files before I had a chance to look at them I hadn't noticed the signs.
Also another attempted backdoor in LTZS_BL20166.Com\phpStudy\WWW\gm\gmquery.php
these could be false positives but I'm not up to checking it atm