Hello,
I have to say this problem is kickin my behind. I'm an IT person working on a remote pc, but do get help with safe mode starts, etc. from the user. I use VNC to connect remotely.
I've cleaned with Spybot several times. Tried SDFix, which found nothing. Windows Defender (of course) finds nothing, no surprise there. Popups are less frequent, & some problems SpyBot did fix, as I now have access to TaskManager again. the latest popup is calling out TrojanDownloader.XS.
Scanned w/ Kaspersky web, it found 5? viruses infecting 15 items.

Thank you very much for any assistance you are able to render
blinks

here is my HJTLog:

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 16:18, on 2008-05-01
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16640)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Windows Defender\MsMpEng.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Dell\OpenManage\Client\ActionAgent.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\DMI\WIN32\bin\DellDmi.exe
C:\Program Files\Dell\OpenManage\Client\EventAgt.exe
C:\Program Files\Dell\OpenManage\Client\DLT.exe
C:\Program Files\Dell\OpenManage\Client\Iap.exe
C:\Program Files\Network Associates\Common Framework\FrameworkService.exe
C:\Program Files\Network Associates\VirusScan\Mcshield.exe
C:\Program Files\Network Associates\VirusScan\VsTskMgr.exe
C:\dmi\win32\bin\Win32sl.exe
C:\Program Files\UltraVNC\WinVNC.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Network Associates\Common Framework\UdaterUI.exe
C:\Program Files\Network Associates\VirusScan\SHSTAT.EXE
C:\Program Files\Common Files\Network Associates\TalkBack\TBMon.exe
C:\Program Files\Windows Defender\MSASCui.exe
C:\WINDOWS\system32\ctfmon.exe
C:\WINDOWS\system32\wxudqfep.exe
C:\Program Files\Network Associates\Common Framework\McTray.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe
C:\WINDOWS\system32\wuauclt.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.hotsheet.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = 192.168.141.231:8080
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: RealPlayer Download and Record Plugin for Internet Explorer - {3049C3E9-B461-4BC5-8870-4C09146192CA} - C:\Program Files\Real\RealPlayer\rpbrowserrecordplugin.dll
O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: Israel Radio Toolbar - {5dc2c36d-747c-4fee-8bc3-e86c21981440} - C:\Program Files\Israel_Radio\tbIsr1.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar2.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\3.0.1225.9868\swg.dll
O2 - BHO: Windows Live Toolbar Helper - {BDBD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\Windows Live Toolbar\msntb.dll
O3 - Toolbar: Israel Radio Toolbar - {5dc2c36d-747c-4fee-8bc3-e86c21981440} - C:\Program Files\Israel_Radio\tbIsr1.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar2.dll
O3 - Toolbar: Windows Live Toolbar - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\Windows Live Toolbar\msntb.dll
O3 - Toolbar: (no name) - {C71F6A92-8438-46A4-9237-15A1F1AF179D} - (no file)
O4 - HKLM\..\Run: [WinVNC] "C:\Program Files\UltraVNC\WinVNC.exe" -servicehelper
O4 - HKLM\..\Run: [McAfeeUpdaterUI] "C:\Program Files\Network Associates\Common Framework\UdaterUI.exe" /StartedFromRunKey
O4 - HKLM\..\Run: [ShStatEXE] "C:\Program Files\Network Associates\VirusScan\SHSTAT.EXE" /STANDALONE
O4 - HKLM\..\Run: [Network Associates Error Reporting Service] "C:\Program Files\Common Files\Network Associates\TalkBack\TBMon.exe"
O4 - HKLM\..\Run: [Windows Defender] "C:\Program Files\Windows Defender\MSASCui.exe" -hide
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [gtjcrnvp] C:\WINDOWS\system32\gxolwpyj.exe
O4 - HKCU\..\Run: [vvygnutp] C:\WINDOWS\system32\wxudqfep.exe
O4 - HKUS\S-1-5-18\..\RunOnce: [TSClientMSIUninstaller] cmd.exe /C "cscript %systemroot%\Installer\TSClientMsiTrans\tscuinst.vbs" (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\RunOnce: [TSClientMSIUninstaller] cmd.exe /C "cscript %systemroot%\Installer\TSClientMsiTrans\tscuinst.vbs" (User 'Default user')
O8 - Extra context menu item: &Windows Live Search - res://C:\Program Files\Windows Live Toolbar\msntb.dll/search.htm
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
O9 - Extra button: (no name) - {85d1f590-48f4-11d9-9669-0800200c9a66} - C:\WINDOWS\bdoscandel.exe
O9 - Extra 'Tools' menuitem: Uninstall BitDefender Online Scanner v8 - {85d1f590-48f4-11d9-9669-0800200c9a66} - C:\WINDOWS\bdoscandel.exe
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\system32\Shdocvw.dll
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {0EB0E74A-2A76-4AB3-A7FB-9BD8C29F7F75} (CKAVWebScan Object) - http://www.kaspersky.com/kos/english...an_unicode.cab
O16 - DPF: {1239CC52-59EF-4DFA-8C61-90FFA846DF7E} (Musicnotes Viewer) - http://www.musicnotes.com/download/mnviewer.cab
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204
O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (YInstStarter Class) - C:\Program Files\Yahoo!\Common\yinsthelper.dll
O16 - DPF: {5D86DDB5-BDF9-441B-9E9E-D4730F4EE499} (BDSCANONLINE Control) - http://download.bitdefender.com/reso...an8/oscan8.cab
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://www.update.microsoft.com/wind...?1209677410996
O16 - DPF: {A8F2B9BD-A6A0-486A-9744-18920D898429} (ScorchPlugin Class) - http://www.sibelius.com/download/sof...iveXPlugin.cab
O16 - DPF: {B8BE5E93-A60C-4D26-A2DC-220313175592} (MSN Games - Installer) - http://cdn2.zone.msn.com/binFramewor...o.cab56649.cab
O16 - DPF: {DF780F87-FF2B-4DF8-92D0-73DB16A1543A} (PopCapLoader Object) - http://zone.msn.com/bingame/popcaploader_v10.cab
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: Domain = BEALLCORP.NET
O17 - HKLM\Software\..\Telephony: DomainName = BEALLCORP.NET
O17 - HKLM\System\CS1\Services\Tcpip\Parameters: Domain = BEALLCORP.NET
O17 - HKLM\System\CS2\Services\Tcpip\Parameters: Domain = BEALLCORP.NET
O23 - Service: Ad-Aware 2007 Service (aawservice) - Lavasoft - C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
O23 - Service: ActionAgent - Dell Computer Corporation - C:\Program Files\Dell\OpenManage\Client\ActionAgent.exe
O23 - Service: Apple Mobile Device - Apple, Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: iSeries Access for Windows Remote Command (Cwbrxd) - IBM Corporation - C:\WINDOWS\CWBRXD.EXE
O23 - Service: DellDmi - Dell Computer Corporation - C:\DMI\WIN32\bin\DellDmi.exe
O23 - Service: DEventAgent - Dell Computer Corporation - C:\Program Files\Dell\OpenManage\Client\EventAgt.exe
O23 - Service: DLT - Dell Computer Corporation - C:\Program Files\Dell\OpenManage\Client\DLT.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: Iap - Dell Computer Corporation - C:\Program Files\Dell\OpenManage\Client\Iap.exe
O23 - Service: McAfee Framework Service (McAfeeFramework) - McAfee, Inc. - C:\Program Files\Network Associates\Common Framework\FrameworkService.exe
O23 - Service: Network Associates McShield (McShield) - Network Associates, Inc. - C:\Program Files\Network Associates\VirusScan\Mcshield.exe
O23 - Service: Network Associates Task Manager (McTaskManager) - Network Associates, Inc. - C:\Program Files\Network Associates\VirusScan\VsTskMgr.exe
O23 - Service: Win32Sl - Intel - C:\dmi\win32\bin\Win32sl.exe
O23 - Service: VNC Server (winvnc) - UltraVNC - C:\Program Files\UltraVNC\WinVNC.exe

--
End of file - 9135 bytes


and KASPERSKY Virus SCAN:

-------------------------------------------------------------------------------
KASPERSKY ONLINE SCANNER REPORT
2008-05-01 08:28
Operating System: Microsoft Windows XP Professional, Service Pack 2 (Build 2600)
Kaspersky Online Scanner version: 5.0.98.0
Kaspersky Anti-Virus database last update: 30/04/2008
Kaspersky Anti-Virus database records: 733438
-------------------------------------------------------------------------------

Scan Settings:
Scan using the following antivirus database: extended
Scan Archives: true
Scan Mail Bases: true

Scan Target - My Computer:
A:\
C:\
D:\
G:\
S:\
U:\

Scan Statistics:
Total number of scanned objects: 37264
Number of viruses found: 5
Number of infected objects: 15
Number of suspicious objects: 0
Duration of the scan process: 02:35:12

Infected Object Name / Virus Name / Last Action
C:\DMI\WIN32\MifDB\errors.log Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\DSS\MachineKeys\d4ab084915cda0549b1a54085095fa40_05360b70-c85e-4979-a995-4d918337c65c Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Windows Defender\Support\MPLog-01092007-160109.log Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Network Associates\BOPDATA\_Date-20080430_Time-101615208_EnterceptExceptions.dat Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Network Associates\BOPDATA\_Date-20080430_Time-101615208_EnterceptRules.dat Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Network Associates\Common Framework\Db\Agent_DEN1D02.log Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Network Associates\Common Framework\Db\PrdMgr_DEN1D02.log Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Network Associates\VirusScan\AccessProtectionLog.txt Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Network Associates\VirusScan\BufferOverflowProtectionLog.txt Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Network Associates\VirusScan\OnAccessScanLog.txt Object is locked skipped
C:\Documents and Settings\All Users\Application Data\uvglszqz\wdsnarwx.exe Infected: Trojan.Win32.Obfuscated.gx skipped
C:\Documents and Settings\LocalService\Cookies\index.dat Object is locked skipped
C:\Documents and Settings\LocalService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat Object is locked skipped
C:\Documents and Settings\LocalService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped
C:\Documents and Settings\LocalService\Local Settings\History\History.IE5\index.dat Object is locked skipped
C:\Documents and Settings\LocalService\Local Settings\Temporary Internet Files\Content.IE5\index.dat Object is locked skipped
C:\Documents and Settings\LocalService\NTUSER.DAT Object is locked skipped
C:\Documents and Settings\LocalService\ntuser.dat.LOG Object is locked skipped
C:\Documents and Settings\NetworkService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat Object is locked skipped
C:\Documents and Settings\NetworkService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped
C:\Documents and Settings\NetworkService\NTUSER.DAT Object is locked skipped
C:\Documents and Settings\NetworkService\ntuser.dat.LOG Object is locked skipped
C:\Documents and Settings\ryusem\Cookies\index.dat Object is locked skipped
C:\Documents and Settings\ryusem\Local Settings\Application Data\Microsoft\Feeds Cache\index.dat Object is locked skipped
C:\Documents and Settings\ryusem\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat Object is locked skipped
C:\Documents and Settings\ryusem\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped
C:\Documents and Settings\ryusem\Local Settings\History\History.IE5\index.dat Object is locked skipped
C:\Documents and Settings\ryusem\Local Settings\History\History.IE5\MSHist012008043020080501\index.dat Object is locked skipped
C:\Documents and Settings\ryusem\Local Settings\Temporary Internet Files\AntiPhishing\B3BB5BBA-E7D5-40AB-A041-A5B1C0B26C8F.dat Object is locked skipped
C:\Documents and Settings\ryusem\Local Settings\Temporary Internet Files\Content.IE5\index.dat Object is locked skipped
C:\Documents and Settings\ryusem\My Documents\House\Flooring.doc Object is locked skipped
C:\Documents and Settings\ryusem\My Documents\House\Upstairs Floor.doc Object is locked skipped
C:\Documents and Settings\ryusem\My Documents\Misc\11 Names of messiah.doc Object is locked skipped
C:\Documents and Settings\ryusem\My Documents\Misc\a-free-magic-ebook.zip Object is locked skipped
C:\Documents and Settings\ryusem\My Documents\Misc\a.doc Object is locked skipped
C:\Documents and Settings\ryusem\My Documents\Misc\Angelic name and orders.doc Object is locked skipped
C:\Documents and Settings\ryusem\My Documents\Misc\AstoundingDemo.exe Object is locked skipped
C:\Documents and Settings\ryusem\My Documents\Misc\Asturias.doc Object is locked skipped
C:\Documents and Settings\ryusem\My Documents\Misc\Background.doc Object is locked skipped
C:\Documents and Settings\ryusem\My Documents\Misc\Basic Leg on Shoulder Guard Pass.doc Object is locked skipped
C:\Documents and Settings\ryusem\My Documents\Misc\Book2.xls Object is locked skipped
C:\Documents and Settings\ryusem\My Documents\Misc\cardtricks.exe Object is locked skipped
C:\Documents and Settings\ryusem\My Documents\Misc\cell%20plan.pdf Object is locked skipped
C:\Documents and Settings\ryusem\My Documents\Misc\ConocoPhillips.doc Object is locked skipped
C:\Documents and Settings\ryusem\My Documents\Misc\D14.pdf Object is locked skipped
C:\Documents and Settings\ryusem\My Documents\Misc\Danny Magen.doc Object is locked skipped
C:\Documents and Settings\ryusem\My Documents\Misc\Desktop.ini Object is locked skipped
C:\Documents and Settings\ryusem\My Documents\Misc\Enochian script.doc Object is locked skipped
C:\Documents and Settings\ryusem\My Documents\Misc\GMS_memory.pdf Object is locked skipped
C:\Documents and Settings\ryusem\My Documents\Misc\High Altitude Martial Arts.doc Object is locked skipped
C:\Documents and Settings\ryusem\My Documents\Misc\Irin.doc Object is locked skipped
C:\Documents and Settings\ryusem\My Documents\Misc\Just a Touch of magic.doc Object is locked skipped
C:\Documents and Settings\ryusem\My Documents\Misc\kl.doc Object is locked skipped
C:\Documents and Settings\ryusem\My Documents\Misc\LKJ.doc Object is locked skipped
C:\Documents and Settings\ryusem\My Documents\Misc\MEMORY.doc Object is locked skipped
C:\Documents and Settings\ryusem\My Documents\Misc\Mossad.doc Object is locked skipped
C:\Documents and Settings\ryusem\My Documents\Misc\My words.xls Object is locked skipped
C:\Documents and Settings\ryusem\My Documents\Misc\Mystery of Shambhala.doc Object is locked skipped
C:\Documents and Settings\ryusem\My Documents\Misc\OIL STOCK TO BUY.doc Object is locked skipped
C:\Documents and Settings\ryusem\My Documents\Misc\PHYS THER.doc Object is locked skipped
C:\Documents and Settings\ryusem\My Documents\Misc\PRELIMINARY PLANS.doc Object is locked skipped
C:\Documents and Settings\ryusem\My Documents\Misc\PRRFENTRY_form_200801.doc Object is locked skipped
C:\Documents and Settings\ryusem\My Documents\Misc\PRRF_Catalog_200801.doc Object is locked skipped
C:\Documents and Settings\ryusem\My Documents\Misc\RMHS_Membership_Application.doc Object is locked skipped
C:\Documents and Settings\ryusem\My Documents\Misc\Rosh Hashanna.doc Object is locked skipped
C:\Documents and Settings\ryusem\My Documents\Misc\ryusem83Ways[1].pdf Object is locked skipped
C:\Documents and Settings\ryusem\My Documents\Misc\Shirt\Cheap screen printing tutorial.doc Object is locked skipped
C:\Documents and Settings\ryusem\My Documents\Misc\Shirt\Desktop.ini Object is locked skipped
C:\Documents and Settings\ryusem\My Documents\Misc\Shirt\Gaelic Judo.doc Object is locked skipped
C:\Documents and Settings\ryusem\My Documents\Misc\Shirt\LKJ.pdf Object is locked skipped
C:\Documents and Settings\ryusem\My Documents\Misc\Shirt\LKJ2.pdf Object is locked skipped
C:\Documents and Settings\ryusem\My Documents\Misc\Shirt\sHIRT.doc Object is locked skipped
C:\Documents and Settings\ryusem\My Documents\Misc\Shirt\TER.pdf Object is locked skipped
C:\Documents and Settings\ryusem\My Documents\Misc\Shirt\TER2.pdf Object is locked skipped
C:\Documents and Settings\ryusem\My Documents\Misc\Slowly digesting his stomach he reached over.doc Object is locked skipped
C:\Documents and Settings\ryusem\My Documents\Misc\Story Climax.doc Object is locked skipped
C:\Documents and Settings\ryusem\My Documents\Misc\Street tongue.doc Object is locked skipped
C:\Documents and Settings\ryusem\My Documents\Misc\Sunday.doc Object is locked skipped
C:\Documents and Settings\ryusem\My Documents\Misc\tabs.doc Object is locked skipped
C:\Documents and Settings\ryusem\My Documents\Misc\Taken from a friend.doc Object is locked skipped
C:\Documents and Settings\ryusem\My Documents\Misc\Together they would tackle everything.doc Object is locked skipped
C:\Documents and Settings\ryusem\My Documents\Misc\Vocab list.pdf Object is locked skipped
C:\Documents and Settings\ryusem\My Documents\Misc\~$gelic name and orders.doc Object is locked skipped
C:\Documents and Settings\ryusem\NTUSER.DAT Object is locked skipped
C:\Documents and Settings\ryusem\NTUSER.DAT.LOG Object is locked skipped
C:\Program Files\UltraVNC\vnchooks.dll Infected: not-a-virus:RemoteAdmin.Win32.WinVNC.e skipped
C:\Program Files\UltraVNC\winvnc.exe Infected: not-a-virus:RemoteAdmin.Win32.WinVNC.e skipped
C:\QooBox\Quarantine\C\WINDOWS\Web\def.htm.vir Infected: not-virus:Hoax.HTML.Secureinvites.c skipped
C:\quarantine\Av-test.txt.Vir Object is locked skipped
C:\System Volume Information\MountPointManagerRemoteDatabase Object is locked skipped
C:\System Volume Information\_restore{525A8A03-7DB2-47CF-BDFF-07AEA779E4EC}\RP1\A0005645.exe Infected: Trojan.Win32.Vapsup.elk skipped
C:\System Volume Information\_restore{525A8A03-7DB2-47CF-BDFF-07AEA779E4EC}\RP1\A0005646.dll Infected: Trojan.Win32.Vapsup.elk skipped
C:\System Volume Information\_restore{525A8A03-7DB2-47CF-BDFF-07AEA779E4EC}\RP1\A0005648.dll Infected: Trojan.Win32.Vapsup.elk skipped
C:\System Volume Information\_restore{525A8A03-7DB2-47CF-BDFF-07AEA779E4EC}\RP1\A0005649.dll Infected: Trojan.Win32.Vapsup.elk skipped
C:\System Volume Information\_restore{525A8A03-7DB2-47CF-BDFF-07AEA779E4EC}\RP1\A0005668.exe Infected: Trojan.Win32.Obfuscated.gx skipped
C:\System Volume Information\_restore{525A8A03-7DB2-47CF-BDFF-07AEA779E4EC}\RP1\A0005687.exe Infected: Trojan.Win32.Obfuscated.gx skipped
C:\System Volume Information\_restore{525A8A03-7DB2-47CF-BDFF-07AEA779E4EC}\RP2\A0006754.exe Infected: Trojan.Win32.Obfuscated.gx skipped
C:\System Volume Information\_restore{525A8A03-7DB2-47CF-BDFF-07AEA779E4EC}\RP2\A0006755.exe Infected: Trojan.Win32.Obfuscated.gx skipped
C:\System Volume Information\_restore{525A8A03-7DB2-47CF-BDFF-07AEA779E4EC}\RP4\A0007837.exe Infected: Trojan.Win32.Obfuscated.gx skipped
C:\System Volume Information\_restore{525A8A03-7DB2-47CF-BDFF-07AEA779E4EC}\RP4\A0007838.exe Infected: Trojan.Win32.Obfuscated.gx skipped
C:\System Volume Information\_restore{525A8A03-7DB2-47CF-BDFF-07AEA779E4EC}\RP4\change.log Object is locked skipped
C:\WINDOWS\CSC\00000001 Object is locked skipped
C:\WINDOWS\Debug\Netlogon.log Object is locked skipped
C:\WINDOWS\Debug\PASSWD.LOG Object is locked skipped
C:\WINDOWS\Downloaded Program Files\popcaploader.dll Infected: not-a-virus:Downloader.Win32.PopCap.b skipped
C:\WINDOWS\SchedLgU.Txt Object is locked skipped
C:\WINDOWS\SoftwareDistribution\ReportingEvents.log Object is locked skipped
C:\WINDOWS\system32\CatRoot2\edb.log Object is locked skipped
C:\WINDOWS\system32\CatRoot2\tmp.edb Object is locked skipped
C:\WINDOWS\system32\config\AppEvent.Evt Object is locked skipped
C:\WINDOWS\system32\config\default Object is locked skipped
C:\WINDOWS\system32\config\default.LOG Object is locked skipped
C:\WINDOWS\system32\config\Internet.evt Object is locked skipped
C:\WINDOWS\system32\config\SAM Object is locked skipped
C:\WINDOWS\system32\config\SAM.LOG Object is locked skipped
C:\WINDOWS\system32\config\SecEvent.Evt Object is locked skipped
C:\WINDOWS\system32\config\SECURITY Object is locked skipped
C:\WINDOWS\system32\config\SECURITY.LOG Object is locked skipped
C:\WINDOWS\system32\config\software Object is locked skipped
C:\WINDOWS\system32\config\software.LOG Object is locked skipped
C:\WINDOWS\system32\config\SysEvent.Evt Object is locked skipped
C:\WINDOWS\system32\config\system Object is locked skipped
C:\WINDOWS\system32\config\system.LOG Object is locked skipped
C:\WINDOWS\system32\h323log.txt Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\INDEX.BTR Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\INDEX.MAP Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\MAPPING.VER Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\MAPPING1.MAP Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\MAPPING2.MAP Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\OBJECTS.DATA Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\OBJECTS.MAP Object is locked skipped
C:\WINDOWS\WindowsUpdate.log Object is locked skipped

Scan process completed.