PDA

View Full Version : Malware infection, please help



emokid13
2007-08-22, 11:24
Can someone please help me get rid of the Malware spyware?
I followed the steps from the 'Before you post' thread and i included the hjt logfile. I cannot include the online scan logfile because it wil make the post too long. I wil post it after this post.
Thanks in advance!

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 10:10:28 AM, on 08/22/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\csrss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Cisco Systems\VPN Client\cvpnd.exe
C:\Program Files\Common Files\ODT-OCE\Tracing\DOKuStarRemoteTracing.exe
C:\WINDOWS\system32\inetsrv\inetinfo.exe
C:\Program Files\McAfee\VirusScan Enterprise\Mcshield.exe
C:\Program Files\McAfee\VirusScan Enterprise\VsTskMgr.exe
C:\Program Files\Common Files\Microsoft Shared\VS7Debug\mdm.exe
C:\Program Files\ODT-OCE\DOKuStar Professional\MSSQL.1\MSSQL\Binn\sqlservr.exe
C:\PROGRA~1\MI6841~1\MSSQL\binn\sqlservr.exe
C:\Program Files\Spyware Doctor\svcntaux.exe
C:\Program Files\Spyware Doctor\swdsvc.exe
C:\Program Files\Microsoft SQL Server\90\Shared\sqlbrowser.exe
C:\Program Files\Microsoft SQL Server\90\Shared\sqlwriter.exe
C:\Program Files\Webroot\Spy Sweeper\SpySweeper.exe
C:\Program Files\RealVNC\VNC4\WinVNC4.exe
C:\Program Files\ODT-OCE\DOKuStar Professional\DOKuStarLoadManager.exe
C:\Program Files\ODT-OCE\DOKuStar Professional\DOKuStarClusterNode.exe
C:\WINDOWS\System32\alg.exe
C:\WINDOWS\Explorer.exe
C:\WINDOWS\system32\printer.exe
C:\WINDOWS\system32\igfxtray.exe
C:\WINDOWS\system32\hkcmd.exe
C:\WINDOWS\system32\igfxpers.exe
C:\Program Files\hpq\HP Wireless Assistant\HP Wireless Assistant.exe
C:\Program Files\McAfee\Common Framework\UdaterUI.exe
C:\Program Files\McAfee\Common Framework\FrameworkService.exe
C:\Program Files\McAfee\VirusScan Enterprise\SHSTAT.EXE
C:\Program Files\Analog Devices\Core\smax4pnp.exe
C:\WINDOWS\system32\wbem\wmiprvse.exe
C:\Program Files\McAfee\Common Framework\McTray.exe
C:\Program Files\Spyware Doctor\SDTrayApp.exe
C:\Program Files\McAfee\Common Framework\naPrdMgr.exe
C:\Program Files\Webroot\Spy Sweeper\SpySweeperUI.exe
C:\Program Files\AutoHotkey\AutoHotkey.exe
C:\Program Files\Microsoft SQL Server\80\Tools\Binn\sqlmangr.exe
C:\Program Files\WinZip\WZQKPICK.EXE
C:\PROGRA~1\hpq\Shared\HPQTOA~1.EXE
C:\Program Files\Webroot\Spy Sweeper\SSU.EXE
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Microsoft Office\OFFICE11\OUTLOOK.EXE
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe
C:\WINDOWS\system32\wbem\wmiprvse.exe

F2 - REG:system.ini: Shell=Explorer.exe C:\WINDOWS\system32\printer.exe
O2 - BHO: scriptproxy - {7DB2D5A0-7241-4E79-B68D-6309F01C5231} - C:\Program Files\McAfee\VirusScan Enterprise\scriptcl.dll
O2 - BHO: IEHlprObj Class - {ABCDECF0-4B15-11D1-ABED-709549C10000} - C:\WINDOWS\system32\vtr455.dll (file missing)
O4 - HKLM\..\Run: [Cpqset] "C:\Program Files\HPQ\Default Settings\cpqset.exe"
O4 - HKLM\..\Run: [igfxtray] C:\WINDOWS\system32\igfxtray.exe
O4 - HKLM\..\Run: [igfxhkcmd] C:\WINDOWS\system32\hkcmd.exe
O4 - HKLM\..\Run: [igfxpers] C:\WINDOWS\system32\igfxpers.exe
O4 - HKLM\..\Run: [hpWirelessAssistant] "C:\Program Files\hpq\HP Wireless Assistant\HP Wireless Assistant.exe"
O4 - HKLM\..\Run: [McAfeeUpdaterUI] "C:\Program Files\McAfee\Common Framework\UdaterUI.exe" /StartedFromRunKey
O4 - HKLM\..\Run: [ShStatEXE] "C:\Program Files\McAfee\VirusScan Enterprise\SHSTAT.EXE" /STANDALONE
O4 - HKLM\..\Run: [SoundMAXPnP] "C:\Program Files\Analog Devices\Core\smax4pnp.exe"
O4 - HKLM\..\Run: [SoundMAX] "C:\Program Files\Analog Devices\SoundMAX\Smax4.exe" /tray
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [WinAVX] C:\WINDOWS\system32\WinAvXX.exe
O4 - HKLM\..\Run: [NI.UWA7P_0001_N91M0809] "c:\documents and settings\koenh\application data\winantiviruspro2007freeinstall[1].exe" -nag
O4 - HKLM\..\Run: [SDTray] "C:\Program Files\Spyware Doctor\SDTrayApp.exe"
O4 - HKLM\..\Run: [SpySweeper] "C:\Program Files\Webroot\Spy Sweeper\SpySweeperUI.exe" /startintray
O4 - HKCU\..\Run: [WinAVX] C:\WINDOWS\system32\WinAvXX.exe
O4 - HKUS\S-1-5-21-1220945662-630328440-725345543-500\..\Run: [WinAVX] C:\WINDOWS\system32\WinAvXX.exe (User 'Administrator')
O4 - Global Startup: AutoHotkey.lnk = C:\Program Files\AutoHotkey\AutoHotkey.exe
O4 - Global Startup: Service Manager.lnk = C:\Program Files\Microsoft SQL Server\80\Tools\Binn\sqlmangr.exe
O4 - Global Startup: VPN Client.lnk = ?
O4 - Global Startup: WinZip Quick Pick.lnk = C:\Program Files\WinZip\WZQKPICK.EXE
O7 - HKLM\Software\Microsoft\Windows\CurrentVersion\Policies\System, DisableRegedit=1
O9 - Extra button: (no name) - {2D663D1A-8670-49D9-A1A5-4C56B4E14E84} - (no file)
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~3\OFFICE11\REFIEBAR.DLL
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {05CA9FB0-3E3E-4B36-BF41-0E3A5CAA8CD8} (Office Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=58813
O16 - DPF: {0EB0E74A-2A76-4AB3-A7FB-9BD8C29F7F75} (CKAVWebScan Object) - http://www.kaspersky.com/kos/eng/partner/default/kavwebscan_unicode.cab
O16 - DPF: {6E5E167B-1566-4316-B27F-0DDAB3484CF7} (Image Uploader Control) - http://cache.hyvz.com/statics/Aurigma/ImageUploader4.cab
O16 - DPF: {DE625294-70E6-45ED-B895-CFFA13AEB044} (AxisMediaControlEmb Class) - http://robocam.eindhoven.nl/activex/AMC.cab
O16 - DPF: {E6ACF817-0A85-4EBE-9F0A-096C6488CFEA} (NTR ActiveX 1.1.8) - https://www.ntrsupport.com/ssl/inquiero/mod/setup/ntractivex118_24.cab
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: Domain = datacollect.local
O17 - HKLM\Software\..\Telephony: DomainName = datacollect.local
O17 - HKLM\System\CS1\Services\Tcpip\Parameters: Domain = datacollect.local
O17 - HKLM\System\CS2\Services\Tcpip\Parameters: Domain = datacollect.local
O20 - AppInit_DLLs: C:\WINDOWS\system32\hrum455.txt
O23 - Service: Cisco Systems, Inc. VPN Service (CVPND) - Cisco Systems, Inc. - C:\Program Files\Cisco Systems\VPN Client\cvpnd.exe
O23 - Service: DOKuStar Load Manager - Oce Document Technologies GmbH - C:\Program Files\ODT-OCE\DOKuStar Professional\DOKuStarLoadManager.exe
O23 - Service: DOKuStar Tracing - Oce Document Technologies GmbH - C:\Program Files\Common Files\ODT-OCE\Tracing\DOKuStarRemoteTracing.exe
O23 - Service: LicMan - Océ Document Technologies GmbH - C:\Program Files\Common Files\ODT-OCE\LicMan\bin\LicMan.exe
O23 - Service: McAfee Framework Service (McAfeeFramework) - McAfee, Inc. - C:\Program Files\McAfee\Common Framework\FrameworkService.exe
O23 - Service: McAfee McShield (McShield) - McAfee, Inc. - C:\Program Files\McAfee\VirusScan Enterprise\Mcshield.exe
O23 - Service: McAfee Task Manager (McTaskManager) - McAfee, Inc. - C:\Program Files\McAfee\VirusScan Enterprise\VsTskMgr.exe
O23 - Service: PC Tools Auxiliary Service (sdAuxService) - PC Tools - C:\Program Files\Spyware Doctor\svcntaux.exe
O23 - Service: PC Tools Security Service (sdCoreService) - PC Tools - C:\Program Files\Spyware Doctor\swdsvc.exe
O23 - Service: Webroot Spy Sweeper Engine (WebrootSpySweeperService) - Webroot Software, Inc. - C:\Program Files\Webroot\Spy Sweeper\SpySweeper.exe
O23 - Service: Windows Notification Service (Winnotify) - Unknown owner - C:\WINDOWS\System32\winntify.exe (file missing)
O23 - Service: VNC Server Version 4 (WinVNC4) - RealVNC Ltd. - C:\Program Files\RealVNC\VNC4\WinVNC4.exe

--
End of file - 7861 bytes


Thanks in advance.

emokid13
2007-08-22, 11:25
-------------------------------------------------------------------------------
KASPERSKY ONLINE SCANNER REPORT
Wednesday, August 22, 2007 9:06:09 AM
Operating System: Microsoft Windows XP Professional, Service Pack 2 (Build 2600)
Kaspersky Online Scanner version: 5.0.93.0
Kaspersky Anti-Virus database last update: 21/08/2007
Kaspersky Anti-Virus database records: 386752
-------------------------------------------------------------------------------

Scan Settings:
Scan using the following antivirus database: extended
Scan Archives: true
Scan Mail Bases: true

Scan Target - Folders:
C:\

Scan Statistics:
Total number of scanned objects: 103298
Number of viruses found: 10
Number of infected objects: 51
Number of suspicious objects: 0
Duration of the scan process: 04:16:31

Infected Object Name / Virus Name / Last Action
C:\Documents and Settings\Administrator\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat Object is locked skipped
C:\Documents and Settings\Administrator\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped
C:\Documents and Settings\Administrator\NTUSER.DAT Object is locked skipped
C:\Documents and Settings\Administrator\ntuser.dat.LOG Object is locked skipped
C:\Documents and Settings\All Users\Application Data\McAfee\Common Framework\Db\Agent_SDCKHO01.log Object is locked skipped
C:\Documents and Settings\All Users\Application Data\McAfee\Common Framework\Db\PrdMgr_SDCKHO01.log Object is locked skipped
C:\Documents and Settings\All Users\Application Data\McAfee\DesktopProtection\AccessProtectionLog.txt Object is locked skipped
C:\Documents and Settings\All Users\Application Data\McAfee\DesktopProtection\BufferOverflowProtectionLog.txt Object is locked skipped
C:\Documents and Settings\All Users\Application Data\McAfee\DesktopProtection\OnAccessScanLog.txt Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Network\Downloader\qmgr0.dat Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Network\Downloader\qmgr1.dat Object is locked skipped
C:\Documents and Settings\All Users\Application Data\ODT-OCE\Trace\DOKuStar Load Manager\DOKuStar.Cluster.Extraction.SDCKHO01.2007-08-21T14-22-12.265.2624.log Object is locked skipped
C:\Documents and Settings\All Users\Application Data\ODT-OCE\Trace\DOKuStar Load Manager\DOKuStarLoadManager.SDCKHO01.2007-08-21T14-22-10.921.2396.log Object is locked skipped
C:\Documents and Settings\All Users\Application Data\ODT-OCE\Trace\DOKuStar Load Manager\LM.SDCKHO01.2007-08-21T14-22-11.125.2396.log Object is locked skipped
C:\Documents and Settings\All Users\Start Menu\Programs\Startup\autorun.exe Infected: not-virus:Hoax.Win32.Renos.hz skipped
C:\Documents and Settings\koenh\Application Data\Webroot\Spy Sweeper\Logs\070821142308.ses Object is locked skipped
C:\Documents and Settings\koenh\Cookies\index.dat Object is locked skipped
C:\Documents and Settings\koenh\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat Object is locked skipped
C:\Documents and Settings\koenh\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped
C:\Documents and Settings\koenh\Local Settings\History\History.IE5\index.dat Object is locked skipped
C:\Documents and Settings\koenh\Local Settings\Temp\Cookies\index.dat Object is locked skipped
C:\Documents and Settings\koenh\Local Settings\Temp\History\History.IE5\index.dat Object is locked skipped
C:\Documents and Settings\koenh\Local Settings\Temp\NeroDemo12550\Toolbar.exe Infected: not-a-virus:AdTool.Win32.MyWebSearch skipped
C:\Documents and Settings\koenh\Local Settings\Temp\Perflib_Perfdata_7b8.dat Object is locked skipped
C:\Documents and Settings\koenh\Local Settings\Temp\Perflib_Perfdata_7d4.dat Object is locked skipped
C:\Documents and Settings\koenh\Local Settings\Temp\Temporary Internet Files\Content.IE5\index.dat Object is locked skipped
C:\Documents and Settings\koenh\Local Settings\Temp\~freesetup.exe/file01 Infected: not-a-virus:Downloader.Win32.WinFixer.o skipped
C:\Documents and Settings\koenh\Local Settings\Temp\~freesetup.exe/file02/file01 Infected: Trojan-Downloader.Win32.Agent.alr skipped
C:\Documents and Settings\koenh\Local Settings\Temp\~freesetup.exe/file02 Infected: Trojan-Downloader.Win32.Agent.alr skipped
C:\Documents and Settings\koenh\Local Settings\Temp\~freesetup.exe/file18 Infected: not-a-virus:FraudTool.Win32.WinAntiVirus.2006 skipped
C:\Documents and Settings\koenh\Local Settings\Temp\~freesetup.exe/file83 Infected: not-a-virus:Downloader.Win32.WinFixer.x skipped
C:\Documents and Settings\koenh\Local Settings\Temp\~freesetup.exe Inno: infected - 5 skipped
C:\Documents and Settings\koenh\Local Settings\Temporary Internet Files\Content.IE5\index.dat Object is locked skipped
C:\Documents and Settings\koenh\NTUSER.DAT Object is locked skipped
C:\Documents and Settings\koenh\ntuser.dat.LOG Object is locked skipped
C:\Documents and Settings\LocalService\Cookies\index.dat Object is locked skipped
C:\Documents and Settings\LocalService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat Object is locked skipped
C:\Documents and Settings\LocalService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped
C:\Documents and Settings\LocalService\Local Settings\History\History.IE5\index.dat Object is locked skipped
C:\Documents and Settings\LocalService\Local Settings\Temporary Internet Files\Content.IE5\index.dat Object is locked skipped
C:\Documents and Settings\LocalService\NTUSER.DAT Object is locked skipped
C:\Documents and Settings\LocalService\ntuser.dat.LOG Object is locked skipped
C:\Documents and Settings\NetworkService\Application Data\Webroot\Spy Sweeper\Data\settings.dat Object is locked skipped
C:\Documents and Settings\NetworkService\Application Data\Webroot\Spy Sweeper\Temp\SSCS02C4D529-B612-4C34-8B69-381E0997A188.tmp Object is locked skipped
C:\Documents and Settings\NetworkService\Application Data\Webroot\Spy Sweeper\Temp\SSCS04F469AA-0EB2-4DC4-ABFE-B08BF171E56B.tmp Object is locked skipped
C:\Documents and Settings\NetworkService\Application Data\Webroot\Spy Sweeper\Temp\SSCS097F918D-AB61-456A-861E-EB6C73AF93C7.tmp Object is locked skipped
C:\Documents and Settings\NetworkService\Application Data\Webroot\Spy Sweeper\Temp\SSCS0BE77395-5F31-49FC-A079-8D5B68DAA263.tmp Object is locked skipped
C:\Documents and Settings\NetworkService\Application Data\Webroot\Spy Sweeper\Temp\SSCS0EE447E5-EB3E-4FB3-B9F3-E6A1C76B79F5.tmp Object is locked skipped
C:\Documents and Settings\NetworkService\Application Data\Webroot\Spy Sweeper\Temp\SSCS131EE4CE-E55E-464B-BD0D-6679D1944A86.tmp Object is locked skipped
C:\Documents and Settings\NetworkService\Application Data\Webroot\Spy Sweeper\Temp\SSCS16903D9A-6C39-4B2B-BC6B-B098E6D5F39E.tmp Object is locked skipped
C:\Documents and Settings\NetworkService\Application Data\Webroot\Spy Sweeper\Temp\SSCS1744131B-9F7A-4B2E-9F0E-31B4CED3D79A.tmp Object is locked skipped
C:\Documents and Settings\NetworkService\Application Data\Webroot\Spy Sweeper\Temp\SSCS17BB08D1-BC91-477F-84FD-13C5EAFC584E.tmp Object is locked skipped
C:\Documents and Settings\NetworkService\Application Data\Webroot\Spy Sweeper\Temp\SSCS1A0A1EC5-E49C-426C-926F-8A09DFF7E56B.tmp Object is locked skipped
C:\Documents and Settings\NetworkService\Application Data\Webroot\Spy Sweeper\Temp\SSCS1B31D42C-5256-40CA-B131-CCF8D1B6D37B.tmp Object is locked skipped
C:\Documents and Settings\NetworkService\Application Data\Webroot\Spy Sweeper\Temp\SSCS1DD4E791-4A7D-44CB-A3CD-EE682BD7B1FA.tmp Object is locked skipped
C:\Documents and Settings\NetworkService\Application Data\Webroot\Spy Sweeper\Temp\SSCS1E0948BF-A22B-4008-AEEF-4A288B15B03D.tmp Object is locked skipped
C:\Documents and Settings\NetworkService\Application Data\Webroot\Spy Sweeper\Temp\SSCS20C67DE8-7D9B-424F-B36E-F3FDD160121B.tmp Object is locked skipped
C:\Documents and Settings\NetworkService\Application Data\Webroot\Spy Sweeper\Temp\SSCS23ADED85-0C15-40F5-87B0-444DE79689B3.tmp Object is locked skipped
C:\Documents and Settings\NetworkService\Application Data\Webroot\Spy Sweeper\Temp\SSCS24287F91-1EB5-418F-B36A-3443C4961854.tmp Object is locked skipped
C:\Documents and Settings\NetworkService\Application Data\Webroot\Spy Sweeper\Temp\SSCS263A022E-20AE-4D12-8D1C-2A36584603C2.tmp Object is locked skipped
C:\Documents and Settings\NetworkService\Application Data\Webroot\Spy Sweeper\Temp\SSCS274601A9-B6A4-4719-AB97-68D9B040DD59.tmp Object is locked skipped
C:\Documents and Settings\NetworkService\Application Data\Webroot\Spy Sweeper\Temp\SSCS27E7FAD1-333F-4708-ABC5-A21CB39AA6FD.tmp Object is locked skipped
C:\Documents and Settings\NetworkService\Application Data\Webroot\Spy Sweeper\Temp\SSCS2EF1B63B-FF17-43F7-80CA-B5E37C9FDD1C.tmp Object is locked skipped
C:\Documents and Settings\NetworkService\Application Data\Webroot\Spy Sweeper\Temp\SSCS33F2631C-7340-4803-8A7F-B1657B7F1F8B.tmp Object is locked skipped
C:\Documents and Settings\NetworkService\Application Data\Webroot\Spy Sweeper\Temp\SSCS3B68035C-DCC6-4887-A74E-EEE471AF71F7.tmp Object is locked skipped
C:\Documents and Settings\NetworkService\Application Data\Webroot\Spy Sweeper\Temp\SSCS3E5EDC1E-4790-4A52-AC83-B9D0A96F05A8.tmp Object is locked skipped
C:\Documents and Settings\NetworkService\Application Data\Webroot\Spy Sweeper\Temp\SSCS41A8A47D-5F16-4892-9CF2-AB28461DDBCC.tmp Object is locked skipped
C:\Documents and Settings\NetworkService\Application Data\Webroot\Spy Sweeper\Temp\SSCS495C8F04-4D48-44AE-8F64-28ED70BE26B5.tmp Object is locked skipped
C:\Documents and Settings\NetworkService\Application Data\Webroot\Spy Sweeper\Temp\SSCS49660840-E4A0-44FB-A3CC-8896496950F3.tmp Object is locked skipped
C:\Documents and Settings\NetworkService\Application Data\Webroot\Spy Sweeper\Temp\SSCS4ACC25CB-79B5-4CFA-882B-87462F302B90.tmp Object is locked skipped
C:\Documents and Settings\NetworkService\Application Data\Webroot\Spy Sweeper\Temp\SSCS4DBE4CAC-3CFD-4C74-AEC0-7E5799C4C1E0.tmp Object is locked skipped
C:\Documents and Settings\NetworkService\Application Data\Webroot\Spy Sweeper\Temp\SSCS4FE38C71-3C16-484C-B5E0-F51CE1AA2E8B.tmp Object is locked skipped
C:\Documents and Settings\NetworkService\Application Data\Webroot\Spy Sweeper\Temp\SSCS525224FB-B924-485B-90F2-059EB5EB8410.tmp Object is locked skipped
C:\Documents and Settings\NetworkService\Application Data\Webroot\Spy Sweeper\Temp\SSCS53819943-875A-45ED-B4A3-BC3992EFA281.tmp Object is locked skipped
C:\Documents and Settings\NetworkService\Application Data\Webroot\Spy Sweeper\Temp\SSCS56135F95-C142-4831-9D77-4C528CCA83D7.tmp Object is locked skipped
C:\Documents and Settings\NetworkService\Application Data\Webroot\Spy Sweeper\Temp\SSCS58E2F572-BEC9-43A9-9683-9A608F4876B1.tmp Object is locked skipped
C:\Documents and Settings\NetworkService\Application Data\Webroot\Spy Sweeper\Temp\SSCS5CF69363-5D2E-48BE-89F3-A3EE935B09FB.tmp Object is locked skipped
C:\Documents and Settings\NetworkService\Application Data\Webroot\Spy Sweeper\Temp\SSCS5D5A2648-20FB-4307-B9C5-E5A1F9E5FE8C.tmp Object is locked skipped
C:\Documents and Settings\NetworkService\Application Data\Webroot\Spy Sweeper\Temp\SSCS6325BD2F-8304-4CC2-8AF4-70D2EC4AE926.tmp Object is locked skipped
C:\Documents and Settings\NetworkService\Application Data\Webroot\Spy Sweeper\Temp\SSCS681B5540-4F9E-45EA-A239-04CF2B9A7807.tmp Object is locked skipped
C:\Documents and Settings\NetworkService\Application Data\Webroot\Spy Sweeper\Temp\SSCS68B5EA0A-6045-4C25-8366-4D1E172180E8.tmp Object is locked skipped
C:\Documents and Settings\NetworkService\Application Data\Webroot\Spy Sweeper\Temp\SSCS73F1380F-2BF3-4F58-9D45-34B4135E970C.tmp Object is locked skipped
C:\Documents and Settings\NetworkService\Application Data\Webroot\Spy Sweeper\Temp\SSCS7716A275-4547-43FD-98A0-5B6F2AD35EA4.tmp Object is locked skipped
C:\Documents and Settings\NetworkService\Application Data\Webroot\Spy Sweeper\Temp\SSCS7AA01ACA-F330-4EB6-9854-BEA9D72ED5D4.tmp Object is locked skipped
C:\Documents and Settings\NetworkService\Application Data\Webroot\Spy Sweeper\Temp\SSCS7C798F49-A765-49F6-8A78-F5C34CA3DB22.tmp Object is locked skipped
C:\Documents and Settings\NetworkService\Application Data\Webroot\Spy Sweeper\Temp\SSCS7E1DC32A-1A12-4704-8626-E8DDFA5BD034.tmp Object is locked skipped
C:\Documents and Settings\NetworkService\Application Data\Webroot\Spy Sweeper\Temp\SSCS7ED16984-FF05-408C-BB99-414837081034.tmp Object is locked skipped
C:\Documents and Settings\NetworkService\Application Data\Webroot\Spy Sweeper\Temp\SSCS80129DED-F318-4A26-B290-9D9ED0F516C9.tmp Object is locked skipped
C:\Documents and Settings\NetworkService\Application Data\Webroot\Spy Sweeper\Temp\SSCS810DF432-FD9B-46A9-BC86-611C90766D8F.tmp Object is locked skipped
C:\Documents and Settings\NetworkService\Application Data\Webroot\Spy Sweeper\Temp\SSCS82CE5632-B669-47B3-994D-AECCB9A76686.tmp Object is locked skipped
C:\Documents and Settings\NetworkService\Application Data\Webroot\Spy Sweeper\Temp\SSCS88AE39F0-600D-426B-8634-4485A3FA2E33.tmp Object is locked skipped
C:\Documents and Settings\NetworkService\Application Data\Webroot\Spy Sweeper\Temp\SSCS8DAC0CF2-C05B-4FE1-B2FF-17F13928CCA8.tmp Object is locked skipped
C:\Documents and Settings\NetworkService\Application Data\Webroot\Spy Sweeper\Temp\SSCS8FB86A87-DB39-4A35-A28F-117AEE120744.tmp Object is locked skipped
C:\Documents and Settings\NetworkService\Application Data\Webroot\Spy Sweeper\Temp\SSCS91A45839-70E6-4954-83B5-5AF1C2656D01.tmp Object is locked skipped
C:\Documents and Settings\NetworkService\Application Data\Webroot\Spy Sweeper\Temp\SSCS96B86EED-C8AA-457B-A1CF-05FC122567A4.tmp Object is locked skipped
C:\Documents and Settings\NetworkService\Application Data\Webroot\Spy Sweeper\Temp\SSCS96EC7FE8-00F1-48A9-88AC-4540AEC9396B.tmp Object is locked skipped
C:\Documents and Settings\NetworkService\Application Data\Webroot\Spy Sweeper\Temp\SSCSA36A4C54-BABA-4D60-851B-07FCBF895FB7.tmp Object is locked skipped
C:\Documents and Settings\NetworkService\Application Data\Webroot\Spy Sweeper\Temp\SSCSAE8CC46A-887A-4536-AF63-2F2E5D9B0B9F.tmp Object is locked skipped
C:\Documents and Settings\NetworkService\Application Data\Webroot\Spy Sweeper\Temp\SSCSB216B561-4535-438D-BE2B-3FB82B8A5430.tmp Object is locked skipped
C:\Documents and Settings\NetworkService\Application Data\Webroot\Spy Sweeper\Temp\SSCSB3AFCA89-59F6-4C36-BEC3-9057181F78F6.tmp Object is locked skipped
C:\Documents and Settings\NetworkService\Application Data\Webroot\Spy Sweeper\Temp\SSCSB5CA035E-4420-4564-BD2A-675A69E80164.tmp Object is locked skipped
C:\Documents and Settings\NetworkService\Application Data\Webroot\Spy Sweeper\Temp\SSCSB6E92C8F-4C1F-4C62-8C26-4F9240C67166.tmp Object is locked skipped
C:\Documents and Settings\NetworkService\Application Data\Webroot\Spy Sweeper\Temp\SSCSB7B007DA-6F74-4C1F-A5AC-ED65381526BD.tmp Object is locked skipped
C:\Documents and Settings\NetworkService\Application Data\Webroot\Spy Sweeper\Temp\SSCSB89C4867-45B1-4CA5-8169-EA43FC59F503.tmp Object is locked skipped
C:\Documents and Settings\NetworkService\Application Data\Webroot\Spy Sweeper\Temp\SSCSB93C4518-ED4B-44AE-A0B9-423DF8852729.tmp Object is locked skipped
C:\Documents and Settings\NetworkService\Application Data\Webroot\Spy Sweeper\Temp\SSCSB93E9D08-B160-4581-B4B1-5CE45CF6E3F5.tmp Object is locked skipped
C:\Documents and Settings\NetworkService\Application Data\Webroot\Spy Sweeper\Temp\SSCSBC1F6930-0E82-40EF-B6A3-BA6498BAB428.tmp Object is locked skipped
C:\Documents and Settings\NetworkService\Application Data\Webroot\Spy Sweeper\Temp\SSCSC0AEEC57-17A3-4D4B-BD83-0D2072730260.tmp Object is locked skipped
C:\Documents and Settings\NetworkService\Application Data\Webroot\Spy Sweeper\Temp\SSCSC3467FA5-77ED-4C12-B6C6-7F0014FFD365.tmp Object is locked skipped
C:\Documents and Settings\NetworkService\Application Data\Webroot\Spy Sweeper\Temp\SSCSC5A74E4D-FC6B-40DB-9797-2A73B554AA33.tmp Object is locked skipped
C:\Documents and Settings\NetworkService\Application Data\Webroot\Spy Sweeper\Temp\SSCSC85A9169-DCA2-44BF-9295-806ED7148035.tmp Object is locked skipped
C:\Documents and Settings\NetworkService\Application Data\Webroot\Spy Sweeper\Temp\SSCSC8E6CAD2-A01F-47F0-B1C6-EC546DAF6F25.tmp Object is locked skipped
C:\Documents and Settings\NetworkService\Application Data\Webroot\Spy Sweeper\Temp\SSCSCA195AF5-4747-4568-BB4D-824DBE8724D1.tmp Object is locked skipped
C:\Documents and Settings\NetworkService\Application Data\Webroot\Spy Sweeper\Temp\SSCSCD9BFCF2-0A61-47EB-A2BD-790C7C9D077D.tmp Object is locked skipped
C:\Documents and Settings\NetworkService\Application Data\Webroot\Spy Sweeper\Temp\SSCSCEBA9828-92D9-4EF3-A783-5DA37F94E7A6.tmp Object is locked skipped
C:\Documents and Settings\NetworkService\Application Data\Webroot\Spy Sweeper\Temp\SSCSD63B3F81-3372-42B0-9B51-CE4161C2295C.tmp Object is locked skipped
C:\Documents and Settings\NetworkService\Application Data\Webroot\Spy Sweeper\Temp\SSCSD64F08FC-B017-449D-BCF6-7E21FD3C9FBB.tmp Object is locked skipped
C:\Documents and Settings\NetworkService\Application Data\Webroot\Spy Sweeper\Temp\SSCSDA625F70-5213-415D-BF3F-71469723BBA1.tmp Object is locked skipped
C:\Documents and Settings\NetworkService\Application Data\Webroot\Spy Sweeper\Temp\SSCSDE460D04-CDF2-4964-8827-5020D3B94AD5.tmp Object is locked skipped
C:\Documents and Settings\NetworkService\Application Data\Webroot\Spy Sweeper\Temp\SSCSE84F71A2-EDF2-4E9C-9E97-EFB75BA24057.tmp Object is locked skipped
C:\Documents and Settings\NetworkService\Application Data\Webroot\Spy Sweeper\Temp\SSCSE8B0A243-3EB8-43AF-8A66-FA64CDA3033D.tmp Object is locked skipped
C:\Documents and Settings\NetworkService\Application Data\Webroot\Spy Sweeper\Temp\SSCSE8ECA80D-C3FA-4EB2-8624-3223D4E14CD3.tmp Object is locked skipped
C:\Documents and Settings\NetworkService\Application Data\Webroot\Spy Sweeper\Temp\SSCSE9EEFA01-20DB-418B-BD27-72B8D5021688.tmp Object is locked skipped
C:\Documents and Settings\NetworkService\Application Data\Webroot\Spy Sweeper\Temp\SSCSEA34056F-0F5E-4429-AD1E-2B026FD78DF0.tmp Object is locked skipped
C:\Documents and Settings\NetworkService\Application Data\Webroot\Spy Sweeper\Temp\SSCSEA4BC11F-BCCE-411E-97AC-AAB22987ABA7.tmp Object is locked skipped
C:\Documents and Settings\NetworkService\Application Data\Webroot\Spy Sweeper\Temp\SSCSEBDE65D5-DD93-426F-BCB7-92AC2FACC913.tmp Object is locked skipped
C:\Documents and Settings\NetworkService\Application Data\Webroot\Spy Sweeper\Temp\SSCSED90A325-696F-4A8A-8503-8085D970BDD2.tmp Object is locked skipped
C:\Documents and Settings\NetworkService\Application Data\Webroot\Spy Sweeper\Temp\SSCSEE44F442-83DE-4F48-90A6-89430B270D24.tmp Object is locked skipped
C:\Documents and Settings\NetworkService\Application Data\Webroot\Spy Sweeper\Temp\SSCSEE6F7591-E6E7-448C-B57E-AF5FF208A901.tmp Object is locked skipped
C:\Documents and Settings\NetworkService\Application Data\Webroot\Spy Sweeper\Temp\SSCSEFF125EE-CA72-4394-A284-E7EFFF97DC25.tmp Object is locked skipped
C:\Documents and Settings\NetworkService\Application Data\Webroot\Spy Sweeper\Temp\SSCSF225642E-7C3B-4147-AF02-D915F7E9E95C.tmp Object is locked skipped
C:\Documents and Settings\NetworkService\Application Data\Webroot\Spy Sweeper\Temp\SSCSF8A7A3A4-53E6-4B88-9BE4-47E5F605FBF3.tmp Object is locked skipped
C:\Documents and Settings\NetworkService\Application Data\Webroot\Spy Sweeper\Temp\SSCSFE4D44C2-7CC6-4609-80F9-11268310A459.tmp Object is locked skipped
C:\Documents and Settings\NetworkService\Application Data\Webroot\Spy Sweeper\Temp\SSCSFF74C10D-31A7-44B7-AB08-D0C13D1CA07F.tmp Object is locked skipped

emokid13
2007-08-22, 11:26
C:\Documents and Settings\NetworkService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat Object is locked skipped
C:\Documents and Settings\NetworkService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped
C:\Documents and Settings\NetworkService\NTUSER.DAT Object is locked skipped
C:\Documents and Settings\NetworkService\ntuser.dat.LOG Object is locked skipped
C:\Program Files\Microsoft SQL Server\MSSQL\Data\master.mdf Object is locked skipped
C:\Program Files\Microsoft SQL Server\MSSQL\Data\mastlog.ldf Object is locked skipped
C:\Program Files\Microsoft SQL Server\MSSQL\Data\model.mdf Object is locked skipped
C:\Program Files\Microsoft SQL Server\MSSQL\Data\modellog.ldf Object is locked skipped
C:\Program Files\Microsoft SQL Server\MSSQL\Data\msdbdata.mdf Object is locked skipped
C:\Program Files\Microsoft SQL Server\MSSQL\Data\msdblog.ldf Object is locked skipped
C:\Program Files\Microsoft SQL Server\MSSQL\Data\northwnd.ldf Object is locked skipped
C:\Program Files\Microsoft SQL Server\MSSQL\Data\northwnd.mdf Object is locked skipped
C:\Program Files\Microsoft SQL Server\MSSQL\Data\pubs.mdf Object is locked skipped
C:\Program Files\Microsoft SQL Server\MSSQL\Data\pubs_log.ldf Object is locked skipped
C:\Program Files\Microsoft SQL Server\MSSQL\Data\Teleform.mdf Object is locked skipped
C:\Program Files\Microsoft SQL Server\MSSQL\Data\Teleform_log.LDF Object is locked skipped
C:\Program Files\Microsoft SQL Server\MSSQL\Data\tempdb.mdf Object is locked skipped
C:\Program Files\Microsoft SQL Server\MSSQL\Data\templog.ldf Object is locked skipped
C:\Program Files\Microsoft SQL Server\MSSQL\Data\test_Data.MDF Object is locked skipped
C:\Program Files\Microsoft SQL Server\MSSQL\Data\test_Log.LDF Object is locked skipped
C:\Program Files\Microsoft SQL Server\MSSQL\Data\tlfToets1_Data.MDF Object is locked skipped
C:\Program Files\Microsoft SQL Server\MSSQL\Data\tlfToets1_Log.LDF Object is locked skipped
C:\Program Files\Microsoft SQL Server\MSSQL\Data\tlftoets_Data.MDF Object is locked skipped
C:\Program Files\Microsoft SQL Server\MSSQL\Data\tlftoets_Log.LDF Object is locked skipped
C:\Program Files\Microsoft SQL Server\MSSQL\LOG\ERRORLOG Object is locked skipped
C:\Program Files\ODT-OCE\DOKuStar Professional\MSSQL.1\MSSQL\Data\master.mdf Object is locked skipped
C:\Program Files\ODT-OCE\DOKuStar Professional\MSSQL.1\MSSQL\Data\mastlog.ldf Object is locked skipped
C:\Program Files\ODT-OCE\DOKuStar Professional\MSSQL.1\MSSQL\Data\model.mdf Object is locked skipped
C:\Program Files\ODT-OCE\DOKuStar Professional\MSSQL.1\MSSQL\Data\modellog.ldf Object is locked skipped
C:\Program Files\ODT-OCE\DOKuStar Professional\MSSQL.1\MSSQL\Data\msdbdata.mdf Object is locked skipped
C:\Program Files\ODT-OCE\DOKuStar Professional\MSSQL.1\MSSQL\Data\msdblog.ldf Object is locked skipped
C:\Program Files\ODT-OCE\DOKuStar Professional\MSSQL.1\MSSQL\Data\tempdb.mdf Object is locked skipped
C:\Program Files\ODT-OCE\DOKuStar Professional\MSSQL.1\MSSQL\Data\templog.ldf Object is locked skipped
C:\Program Files\ODT-OCE\DOKuStar Professional\MSSQL.1\MSSQL\LOG\ERRORLOG Object is locked skipped
C:\Program Files\ODT-OCE\DOKuStar Professional\MSSQL.1\MSSQL\LOG\log_67.trc Object is locked skipped
C:\Program Files\RealVNC\VNC4\vncconfig.exe Infected: not-a-virus:RemoteAdmin.Win32.WinVNC.4 skipped
C:\Program Files\RealVNC\VNC4\vncviewer.exe Infected: not-a-virus:RemoteAdmin.Win32.WinVNC.4 skipped
C:\Program Files\RealVNC\VNC4\winvnc4.exe Infected: not-a-virus:RemoteAdmin.Win32.WinVNC.4 skipped
C:\Program Files\RealVNC\VNC4\wm_hooks.dll Infected: not-a-virus:RemoteAdmin.Win32.WinVNC.4 skipped
C:\Program Files\Webroot\Spy Sweeper\Masters\masters.bak Object is locked skipped
C:\Program Files\Webroot\Spy Sweeper\Masters\Masters.const Object is locked skipped
C:\Program Files\Webroot\Spy Sweeper\Masters\masters.mst Object is locked skipped
C:\Program Files\Webroot\Spy Sweeper\Masters.base Object is locked skipped
C:\sdcSoftware\Tools\CrossLoop\bin\VNCHooks.dll Infected: not-a-virus:RemoteAdmin.Win32.WinVNC-based.b skipped
C:\sdcSoftware\Tools\CrossLoop\bin\winvnc.exe Infected: not-a-virus:RemoteAdmin.Win32.WinVNC-based.h skipped
C:\sdcSoftware\VNC\vnc-4_1_2-x86_win32.exe/file1 Infected: not-a-virus:RemoteAdmin.Win32.WinVNC.4 skipped
C:\sdcSoftware\VNC\vnc-4_1_2-x86_win32.exe/file2 Infected: not-a-virus:RemoteAdmin.Win32.WinVNC.4 skipped
C:\sdcSoftware\VNC\vnc-4_1_2-x86_win32.exe/file3 Infected: not-a-virus:RemoteAdmin.Win32.WinVNC.4 skipped
C:\sdcSoftware\VNC\vnc-4_1_2-x86_win32.exe/file5 Infected: not-a-virus:RemoteAdmin.Win32.WinVNC.4 skipped
C:\sdcSoftware\VNC\vnc-4_1_2-x86_win32.exe Inno: infected - 4 skipped
C:\sdcSoftware\VNC\vnc-4_1_2-x86_win32.zip/vnc-4_1_2-x86_win32.exe/file1 Infected: not-a-virus:RemoteAdmin.Win32.WinVNC.4 skipped
C:\sdcSoftware\VNC\vnc-4_1_2-x86_win32.zip/vnc-4_1_2-x86_win32.exe/file2 Infected: not-a-virus:RemoteAdmin.Win32.WinVNC.4 skipped
C:\sdcSoftware\VNC\vnc-4_1_2-x86_win32.zip/vnc-4_1_2-x86_win32.exe/file3 Infected: not-a-virus:RemoteAdmin.Win32.WinVNC.4 skipped
C:\sdcSoftware\VNC\vnc-4_1_2-x86_win32.zip/vnc-4_1_2-x86_win32.exe/file5 Infected: not-a-virus:RemoteAdmin.Win32.WinVNC.4 skipped
C:\sdcSoftware\VNC\vnc-4_1_2-x86_win32.zip/vnc-4_1_2-x86_win32.exe Infected: not-a-virus:RemoteAdmin.Win32.WinVNC.4 skipped
C:\sdcSoftware\VNC\vnc-4_1_2-x86_win32.zip ZIP: infected - 5 skipped
C:\System Volume Information\MountPointManagerRemoteDatabase Object is locked skipped
C:\System Volume Information\_restore{904301B5-8E3A-478C-A384-062EF71E179D}\RP70\A0007142.exe Infected: not-virus:Hoax.Win32.Renos.hz skipped
C:\System Volume Information\_restore{904301B5-8E3A-478C-A384-062EF71E179D}\RP70\A0007143.exe Infected: not-virus:Hoax.Win32.Renos.hz skipped
C:\System Volume Information\_restore{904301B5-8E3A-478C-A384-062EF71E179D}\RP71\A0007194.exe Infected: not-virus:Hoax.Win32.Renos.hz skipped
C:\System Volume Information\_restore{904301B5-8E3A-478C-A384-062EF71E179D}\RP71\A0007195.exe Infected: not-virus:Hoax.Win32.Renos.hz skipped
C:\System Volume Information\_restore{904301B5-8E3A-478C-A384-062EF71E179D}\RP73\A0007357.dll Infected: Trojan-Downloader.Win32.Agent.bxx skipped
C:\System Volume Information\_restore{904301B5-8E3A-478C-A384-062EF71E179D}\RP73\A0007386.exe Infected: not-virus:Hoax.Win32.Renos.hz skipped
C:\System Volume Information\_restore{904301B5-8E3A-478C-A384-062EF71E179D}\RP73\A0007387.exe Infected: not-virus:Hoax.Win32.Renos.hz skipped
C:\System Volume Information\_restore{904301B5-8E3A-478C-A384-062EF71E179D}\RP73\A0007431.exe Infected: not-virus:Hoax.Win32.Renos.hz skipped
C:\System Volume Information\_restore{904301B5-8E3A-478C-A384-062EF71E179D}\RP73\A0007442.exe Infected: not-virus:Hoax.Win32.Renos.hz skipped
C:\System Volume Information\_restore{904301B5-8E3A-478C-A384-062EF71E179D}\RP73\A0007459.exe Infected: not-virus:Hoax.Win32.Renos.hz skipped
C:\System Volume Information\_restore{904301B5-8E3A-478C-A384-062EF71E179D}\RP73\A0007481.exe Infected: not-virus:Hoax.Win32.Renos.hz skipped
C:\System Volume Information\_restore{904301B5-8E3A-478C-A384-062EF71E179D}\RP73\A0007482.exe Infected: not-virus:Hoax.Win32.Renos.hz skipped
C:\System Volume Information\_restore{904301B5-8E3A-478C-A384-062EF71E179D}\RP73\A0007491.exe Infected: not-virus:Hoax.Win32.Renos.hz skipped
C:\System Volume Information\_restore{904301B5-8E3A-478C-A384-062EF71E179D}\RP73\A0007502.exe Infected: not-virus:Hoax.Win32.Renos.hz skipped
C:\System Volume Information\_restore{904301B5-8E3A-478C-A384-062EF71E179D}\RP74\A0007536.exe Infected: not-virus:Hoax.Win32.Renos.hz skipped
C:\System Volume Information\_restore{904301B5-8E3A-478C-A384-062EF71E179D}\RP74\A0007538.exe Infected: not-virus:Hoax.Win32.Renos.hz skipped
C:\System Volume Information\_restore{904301B5-8E3A-478C-A384-062EF71E179D}\RP74\A0007550.exe Infected: not-virus:Hoax.Win32.Renos.hz skipped
C:\System Volume Information\_restore{904301B5-8E3A-478C-A384-062EF71E179D}\RP75\A0007820.exe Infected: not-virus:Hoax.Win32.Renos.hz skipped
C:\System Volume Information\_restore{904301B5-8E3A-478C-A384-062EF71E179D}\RP75\A0007822.exe Infected: not-virus:Hoax.Win32.Renos.hz skipped
C:\System Volume Information\_restore{904301B5-8E3A-478C-A384-062EF71E179D}\RP75\A0007828.exe Infected: not-virus:Hoax.Win32.Renos.hz skipped
C:\System Volume Information\_restore{904301B5-8E3A-478C-A384-062EF71E179D}\RP75\A0008070.exe Infected: not-virus:Hoax.Win32.Renos.hz skipped
C:\System Volume Information\_restore{904301B5-8E3A-478C-A384-062EF71E179D}\RP75\A0008071.exe Infected: not-virus:Hoax.Win32.Renos.hz skipped
C:\System Volume Information\_restore{904301B5-8E3A-478C-A384-062EF71E179D}\RP75\A0008127.exe Infected: not-virus:Hoax.Win32.Renos.hz skipped
C:\System Volume Information\_restore{904301B5-8E3A-478C-A384-062EF71E179D}\RP75\A0008128.exe Infected: not-virus:Hoax.Win32.Renos.hz skipped
C:\System Volume Information\_restore{904301B5-8E3A-478C-A384-062EF71E179D}\RP75\change.log Object is locked skipped
C:\WINDOWS\CSC\00000001 Object is locked skipped
C:\WINDOWS\Debug\Netlogon.log Object is locked skipped
C:\WINDOWS\Debug\PASSWD.LOG Object is locked skipped
C:\WINDOWS\Internet Logs\tvDebug.log Object is locked skipped
C:\WINDOWS\SchedLgU.Txt Object is locked skipped
C:\WINDOWS\SoftwareDistribution\ReportingEvents.log Object is locked skipped
C:\WINDOWS\system32\CatRoot2\edb.log Object is locked skipped
C:\WINDOWS\system32\CatRoot2\tmp.edb Object is locked skipped
C:\WINDOWS\system32\config\AppEvent.Evt Object is locked skipped
C:\WINDOWS\system32\config\default Object is locked skipped
C:\WINDOWS\system32\config\default.LOG Object is locked skipped
C:\WINDOWS\system32\config\SAM Object is locked skipped
C:\WINDOWS\system32\config\SAM.LOG Object is locked skipped
C:\WINDOWS\system32\config\SecEvent.Evt Object is locked skipped
C:\WINDOWS\system32\config\SECURITY Object is locked skipped
C:\WINDOWS\system32\config\SECURITY.LOG Object is locked skipped
C:\WINDOWS\system32\config\software Object is locked skipped
C:\WINDOWS\system32\config\software.LOG Object is locked skipped
C:\WINDOWS\system32\config\SysEvent.Evt Object is locked skipped
C:\WINDOWS\system32\config\system Object is locked skipped
C:\WINDOWS\system32\config\system.LOG Object is locked skipped
C:\WINDOWS\system32\h323log.txt Object is locked skipped
C:\WINDOWS\system32\printer.exe Infected: not-virus:Hoax.Win32.Renos.hz skipped
C:\WINDOWS\system32\wbem\Repository\FS\INDEX.BTR Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\INDEX.MAP Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\MAPPING.VER Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\MAPPING1.MAP Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\MAPPING2.MAP Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\OBJECTS.DATA Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\OBJECTS.MAP Object is locked skipped
C:\WINDOWS\system32\winavxx.exe Infected: not-virus:Hoax.Win32.Renos.hz skipped
C:\WINDOWS\WindowsUpdate.log Object is locked skipped

Scan process completed.

tashi
2007-09-03, 20:23
Hello and sorry for the delay. For people waiting who have not resolved their problem, we have a sticky topic:
The Waiting Room: Post here if waiting for help longer than four days (http://forums.spybot.info/forumdisplay.php?f=37)


However if members waiting for assistance do not post there, their topic is archived after seven days.

If you need the thread re-opened, please send me a private message (pm) and provide a link.

Applies only to the original poster, anyone else with similar problems please start your own topic.