doggedouthouse
2007-10-08, 19:49
Im doing this for a friend, they downloaded something, and the pc froze, when i ran s/bot it found virtumonde but then froze and shut down pc and the only way i could get the pc to run in the end was to use the recovery disc as they used h/j to try and fix something on there own.
ive also notice theres something called -Authentium Antivirus SDK-2 . the pc seems very strange and sounds like something is running constent.
Anyway ive followed the steps, s/bot moved virtumonde in safe mode.heres the logs i hope ive done this right.
-------------------------------------------------------------------------------
-------------------------------------------------------------------------------
KASPERSKY ONLINE SCANNER REPORT
Monday, October 08, 2007 6:07:11 AM
Operating System: Microsoft Windows XP Home Edition, Service Pack 2 (Build 2600)
Kaspersky Online Scanner version: 5.0.93.1
Kaspersky Anti-Virus database last update: 7/10/2007
Kaspersky Anti-Virus database records: 428855
-------------------------------------------------------------------------------
Scan Settings:
Scan using the following antivirus database: extended
Scan Archives: true
Scan Mail Bases: true
Scan Target - My Computer:
C:\
D:\
E:\
F:\
G:\
H:\
I:\
J:\
K:\
Scan Statistics:
Total number of scanned objects: 87841
Number of viruses found: 4
Number of infected objects: 9
Number of suspicious objects: 0
Duration of the scan process: 01:50:57
Infected Object Name / Virus Name / Last Action
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\0b115d5bc50b00691ba6fec1c42f4cc6_26551bfd-8945-4dbd-b7ad-27736eb05cc9 Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\100c7e08168c1358a8127cda56b08b67_26551bfd-8945-4dbd-b7ad-27736eb05cc9 Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\182b12b29f7667b66b5e9f8c1881ac4e_26551bfd-8945-4dbd-b7ad-27736eb05cc9 Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\28ad1f840cbc2cb77bf3b0201ae84f64_26551bfd-8945-4dbd-b7ad-27736eb05cc9 Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\6a79f0785b39b81149794f76c8829622_26551bfd-8945-4dbd-b7ad-27736eb05cc9 Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\8f4c0db05f81389e41db45c933715d6e_26551bfd-8945-4dbd-b7ad-27736eb05cc9 Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\9a90b05b2d2ca177adb829119b294df6_26551bfd-8945-4dbd-b7ad-27736eb05cc9 Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\a58c73aa7b82e924c71d06e02068813a_26551bfd-8945-4dbd-b7ad-27736eb05cc9 Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\eceb1677458dfd3210bf37bc2ab49067_26551bfd-8945-4dbd-b7ad-27736eb05cc9 Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\f4de17f26431208e453e0dfc8077260f_26551bfd-8945-4dbd-b7ad-27736eb05cc9 Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Virgin Broadband\PCguard\Logs\Firewall - Blocked Packets - 10-07-2007--19-59-53.log Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Virgin Broadband\PCguard\Logs\FirewallService10-07-2007--19-59-41.log Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Virgin Broadband\PCguard\Logs\Fw_Session.log Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Virgin Broadband\PCguard\Logs\SafetyConsoleLog10-07-2007--19-59-50.log Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Virgin Broadband\PCguard\Logs\ServiceModel10-07-2007--19-59-50.log Object is locked skipped
C:\Documents and Settings\LocalService\Cookies\index.dat Object is locked skipped
C:\Documents and Settings\LocalService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat Object is locked skipped
C:\Documents and Settings\LocalService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped
C:\Documents and Settings\LocalService\Local Settings\History\History.IE5\index.dat Object is locked skipped
C:\Documents and Settings\LocalService\Local Settings\Temp\Cookies\index.dat Object is locked skipped
C:\Documents and Settings\LocalService\Local Settings\Temp\History\History.IE5\index.dat Object is locked skipped
C:\Documents and Settings\LocalService\Local Settings\Temp\Temporary Internet Files\Content.IE5\index.dat Object is locked skipped
C:\Documents and Settings\LocalService\Local Settings\Temporary Internet Files\Content.IE5\index.dat Object is locked skipped
C:\Documents and Settings\LocalService\NTUSER.DAT Object is locked skipped
C:\Documents and Settings\LocalService\NTUSER.DAT.LOG Object is locked skipped
C:\Documents and Settings\NetworkService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat Object is locked skipped
C:\Documents and Settings\NetworkService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped
C:\Documents and Settings\NetworkService\Local Settings\Application Data\Mozilla\Firefox\Profiles\dq0f60gj.default\Cache\23A27049d01 Object is locked skipped
C:\Documents and Settings\NetworkService\NTUSER.DAT Object is locked skipped
C:\Documents and Settings\NetworkService\NTUSER.DAT.LOG Object is locked skipped
C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\2t1c68r7.default\cert8.db Object is locked skipped
C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\2t1c68r7.default\extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}\chrome\adblockplus.jar Object is locked skipped
C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\2t1c68r7.default\history.dat Object is locked skipped
C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\2t1c68r7.default\key3.db Object is locked skipped
C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\2t1c68r7.default\parent.lock Object is locked skipped
C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\2t1c68r7.default\search.sqlite Object is locked skipped
C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\2t1c68r7.default\urlclassifier2.sqlite Object is locked skipped
C:\Documents and Settings\Owner\Application Data\Virgin Broadband\advisor\client_gateway.log Object is locked skipped
C:\Documents and Settings\Owner\Cookies\index.dat Object is locked skipped
C:\Documents and Settings\Owner\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat Object is locked skipped
C:\Documents and Settings\Owner\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped
C:\Documents and Settings\Owner\Local Settings\Application Data\Mozilla\Firefox\Profiles\2t1c68r7.default\Cache\_CACHE_001_ Object is locked skipped
C:\Documents and Settings\Owner\Local Settings\Application Data\Mozilla\Firefox\Profiles\2t1c68r7.default\Cache\_CACHE_002_ Object is locked skipped
C:\Documents and Settings\Owner\Local Settings\Application Data\Mozilla\Firefox\Profiles\2t1c68r7.default\Cache\_CACHE_003_ Object is locked skipped
C:\Documents and Settings\Owner\Local Settings\Application Data\Mozilla\Firefox\Profiles\2t1c68r7.default\Cache\_CACHE_MAP_ Object is locked skipped
C:\Documents and Settings\Owner\Local Settings\History\History.IE5\index.dat Object is locked skipped
C:\Documents and Settings\Owner\Local Settings\Temporary Internet Files\Content.IE5\index.dat Object is locked skipped
C:\Documents and Settings\Owner\My Documents\Downloads\carl_cox_-_3_deck_colors.zip Object is locked skipped
C:\Documents and Settings\Owner\NTUSER.DAT Object is locked skipped
C:\Documents and Settings\Owner\NTUSER.DAT.LOG Object is locked skipped
C:\hp\bin\KillWind.exe Infected: not-a-virus:RiskTool.Win32.PsKill.p skipped
C:\pnpgoj.exe Infected: Trojan-Downloader.Win32.Agent.ddl skipped
C:\Program Files\CA\PPRT\logs\2007-10-07.csv Object is locked skipped
C:\Program Files\HP Pavilion PC Help\Pavilion\XPHWWBP4\plugin\bin\motdeusr.zip Object is locked skipped
C:\Program Files\HP Pavilion PC Help\Pavilion\XPHWWBP4\plugin\bin\pchplugin.zip Object is locked skipped
C:\Program Files\Java\j2re1.4.2_03\javaws\javaws.jar Object is locked skipped
C:\Program Files\Java\j2re1.4.2_03\lib\jsse.jar Object is locked skipped
C:\Program Files\Java\j2re1.4.2_04\javaws\javaws.jar Object is locked skipped
C:\Program Files\Java\jre1.5(2).0_06\lib(2)\deploy.jar Object is locked skipped
C:\Program Files\Java\jre1.5.0_02\lib\deploy.jar Object is locked skipped
C:\Program Files\Java\jre1.5.0_04\lib\deploy.jar Object is locked skipped
C:\Program Files\Java\jre1.6.0_01\lib\ext\sunjce_provider.jar Object is locked skipped
C:\Program Files\Java\jre1.6.0_01\lib\ext\sunpkcs11.jar Object is locked skipped
C:\Program Files\Java\jre1.6.0_01\lib\javaws.jar Object is locked skipped
C:\Program Files\Online Services\BTopenworldAnytime\Narrowband\Signup\Anytime\SignupLt.exe/btwebcontrol.dll Infected: not-a-virus:Dialer.Win32.BT.b skipped
C:\Program Files\Online Services\BTopenworldAnytime\Narrowband\Signup\Anytime\SignupLt.exe CAB: infected - 1 skipped
C:\Program Files\Online Services\BTopenworldAnytime\Narrowband\Signup\Reinstall\SignupLt.exe/btwebcontrol.dll Infected: not-a-virus:Dialer.Win32.BT.b skipped
C:\Program Files\Online Services\BTopenworldAnytime\Narrowband\Signup\Reinstall\SignupLt.exe CAB: infected - 1 skipped
C:\Program Files\Online Services\BTopenworldAnytime\Narrowband\Signup\Standard\SignupLt.exe/btwebcontrol.dll Infected: not-a-virus:Dialer.Win32.BT.b skipped
C:\Program Files\Online Services\BTopenworldAnytime\Narrowband\Signup\Standard\SignupLt.exe CAB: infected - 1 skipped
C:\Program Files\PC-Doctor for Windows\Java\classes\consumerui.jar Object is locked skipped
C:\Program Files\PC-Doctor for Windows\Java\classes\log4j.jar Object is locked skipped
C:\Program Files\PC-Doctor for Windows\Java\jre\lib\ext\localedata.jar Object is locked skipped
C:\Program Files\PC-Doctor for Windows\Java\jre\lib\im\indicim.jar Object is locked skipped
C:\Program Files\PC-Doctor for Windows\Java\jre\lib\jaws.jar Object is locked skipped
C:\Program Files\PC-Doctor for Windows\Java\Native Help\de\webhelp.jar Object is locked skipped
C:\Program Files\PC-Doctor for Windows\Java\Native Help\en\webhelp.jar Object is locked skipped
C:\Program Files\PC-Doctor for Windows\Java\Native Help\en\webhelp0.zip Object is locked skipped
C:\Program Files\PC-Doctor for Windows\Java\Native Help\fr\webhelp.jar Object is locked skipped
C:\Program Files\PC-Doctor for Windows\Java\Native Help\ja\webhelp.jar Object is locked skipped
C:\Program Files\PC-Doctor for Windows\Java\Native Help\nl\webhelp.jar Object is locked skipped
C:\Program Files\Trend Micro\HijackThis\SmitfraudFix\Reboot.exe Infected: not-a-virus:RiskTool.Win32.Reboot.f skipped
C:\Program Files\Windows Media Player\Skins\Atomic.wmz Object is locked skipped
C:\Program Files\Windows Media Player\Skins\compact.wmz Object is locked skipped
C:\Program Files\Windows Media Player\Skins\QuickSilver.wmz Object is locked skipped
C:\Program Files\Windows Media Player\Skins\splat.wmz Object is locked skipped
C:\Program Files\Windows Media Player\Skins\Windows Classic.wmz Object is locked skipped
C:\System Volume Information\MountPointManagerRemoteDatabase Object is locked skipped
C:\System Volume Information\_restore{64D353BC-F70D-499F-9163-3CEC028719CD}\RP27\change.log Object is locked skipped
C:\WINDOWS\$NtUninstallQ828026$\msdxm.ocx Object is locked skipped
C:\WINDOWS\Debug\PASSWD.LOG Object is locked skipped
C:\WINDOWS\SchedLgU.Txt Object is locked skipped
C:\WINDOWS\SoftwareDistribution\ReportingEvents.log Object is locked skipped
C:\WINDOWS\Sti_Trace.log Object is locked skipped
C:\WINDOWS\system32\CatRoot2\edb.log Object is locked skipped
C:\WINDOWS\system32\CatRoot2\tmp.edb Object is locked skipped
C:\WINDOWS\system32\config\AppEvent.Evt Object is locked skipped
C:\WINDOWS\system32\config\default Object is locked skipped
C:\WINDOWS\system32\config\default.LOG Object is locked skipped
C:\WINDOWS\system32\config\SAM Object is locked skipped
C:\WINDOWS\system32\config\SAM.LOG Object is locked skipped
C:\WINDOWS\system32\config\SecEvent.Evt Object is locked skipped
C:\WINDOWS\system32\config\SECURITY Object is locked skipped
C:\WINDOWS\system32\config\SECURITY.LOG Object is locked skipped
C:\WINDOWS\system32\config\software Object is locked skipped
C:\WINDOWS\system32\config\software.LOG Object is locked skipped
C:\WINDOWS\system32\config\SysEvent.Evt Object is locked skipped
C:\WINDOWS\system32\config\system Object is locked skipped
C:\WINDOWS\system32\config\system.LOG Object is locked skipped
C:\WINDOWS\system32\h323log.txt Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\INDEX.BTR Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\INDEX.MAP Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\MAPPING.VER Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\MAPPING1.MAP Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\MAPPING2.MAP Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\OBJECTS.DATA Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\OBJECTS.MAP Object is locked skipped
C:\WINDOWS\wiadebug.log Object is locked skipped
C:\WINDOWS\wiaservc.log Object is locked skipped
C:\WINDOWS\WindowsUpdate.log Object is locked skipped
Scan process completed.
ive also notice theres something called -Authentium Antivirus SDK-2 . the pc seems very strange and sounds like something is running constent.
Anyway ive followed the steps, s/bot moved virtumonde in safe mode.heres the logs i hope ive done this right.
-------------------------------------------------------------------------------
-------------------------------------------------------------------------------
KASPERSKY ONLINE SCANNER REPORT
Monday, October 08, 2007 6:07:11 AM
Operating System: Microsoft Windows XP Home Edition, Service Pack 2 (Build 2600)
Kaspersky Online Scanner version: 5.0.93.1
Kaspersky Anti-Virus database last update: 7/10/2007
Kaspersky Anti-Virus database records: 428855
-------------------------------------------------------------------------------
Scan Settings:
Scan using the following antivirus database: extended
Scan Archives: true
Scan Mail Bases: true
Scan Target - My Computer:
C:\
D:\
E:\
F:\
G:\
H:\
I:\
J:\
K:\
Scan Statistics:
Total number of scanned objects: 87841
Number of viruses found: 4
Number of infected objects: 9
Number of suspicious objects: 0
Duration of the scan process: 01:50:57
Infected Object Name / Virus Name / Last Action
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\0b115d5bc50b00691ba6fec1c42f4cc6_26551bfd-8945-4dbd-b7ad-27736eb05cc9 Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\100c7e08168c1358a8127cda56b08b67_26551bfd-8945-4dbd-b7ad-27736eb05cc9 Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\182b12b29f7667b66b5e9f8c1881ac4e_26551bfd-8945-4dbd-b7ad-27736eb05cc9 Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\28ad1f840cbc2cb77bf3b0201ae84f64_26551bfd-8945-4dbd-b7ad-27736eb05cc9 Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\6a79f0785b39b81149794f76c8829622_26551bfd-8945-4dbd-b7ad-27736eb05cc9 Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\8f4c0db05f81389e41db45c933715d6e_26551bfd-8945-4dbd-b7ad-27736eb05cc9 Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\9a90b05b2d2ca177adb829119b294df6_26551bfd-8945-4dbd-b7ad-27736eb05cc9 Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\a58c73aa7b82e924c71d06e02068813a_26551bfd-8945-4dbd-b7ad-27736eb05cc9 Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\eceb1677458dfd3210bf37bc2ab49067_26551bfd-8945-4dbd-b7ad-27736eb05cc9 Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\f4de17f26431208e453e0dfc8077260f_26551bfd-8945-4dbd-b7ad-27736eb05cc9 Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Virgin Broadband\PCguard\Logs\Firewall - Blocked Packets - 10-07-2007--19-59-53.log Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Virgin Broadband\PCguard\Logs\FirewallService10-07-2007--19-59-41.log Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Virgin Broadband\PCguard\Logs\Fw_Session.log Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Virgin Broadband\PCguard\Logs\SafetyConsoleLog10-07-2007--19-59-50.log Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Virgin Broadband\PCguard\Logs\ServiceModel10-07-2007--19-59-50.log Object is locked skipped
C:\Documents and Settings\LocalService\Cookies\index.dat Object is locked skipped
C:\Documents and Settings\LocalService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat Object is locked skipped
C:\Documents and Settings\LocalService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped
C:\Documents and Settings\LocalService\Local Settings\History\History.IE5\index.dat Object is locked skipped
C:\Documents and Settings\LocalService\Local Settings\Temp\Cookies\index.dat Object is locked skipped
C:\Documents and Settings\LocalService\Local Settings\Temp\History\History.IE5\index.dat Object is locked skipped
C:\Documents and Settings\LocalService\Local Settings\Temp\Temporary Internet Files\Content.IE5\index.dat Object is locked skipped
C:\Documents and Settings\LocalService\Local Settings\Temporary Internet Files\Content.IE5\index.dat Object is locked skipped
C:\Documents and Settings\LocalService\NTUSER.DAT Object is locked skipped
C:\Documents and Settings\LocalService\NTUSER.DAT.LOG Object is locked skipped
C:\Documents and Settings\NetworkService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat Object is locked skipped
C:\Documents and Settings\NetworkService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped
C:\Documents and Settings\NetworkService\Local Settings\Application Data\Mozilla\Firefox\Profiles\dq0f60gj.default\Cache\23A27049d01 Object is locked skipped
C:\Documents and Settings\NetworkService\NTUSER.DAT Object is locked skipped
C:\Documents and Settings\NetworkService\NTUSER.DAT.LOG Object is locked skipped
C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\2t1c68r7.default\cert8.db Object is locked skipped
C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\2t1c68r7.default\extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}\chrome\adblockplus.jar Object is locked skipped
C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\2t1c68r7.default\history.dat Object is locked skipped
C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\2t1c68r7.default\key3.db Object is locked skipped
C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\2t1c68r7.default\parent.lock Object is locked skipped
C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\2t1c68r7.default\search.sqlite Object is locked skipped
C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\2t1c68r7.default\urlclassifier2.sqlite Object is locked skipped
C:\Documents and Settings\Owner\Application Data\Virgin Broadband\advisor\client_gateway.log Object is locked skipped
C:\Documents and Settings\Owner\Cookies\index.dat Object is locked skipped
C:\Documents and Settings\Owner\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat Object is locked skipped
C:\Documents and Settings\Owner\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped
C:\Documents and Settings\Owner\Local Settings\Application Data\Mozilla\Firefox\Profiles\2t1c68r7.default\Cache\_CACHE_001_ Object is locked skipped
C:\Documents and Settings\Owner\Local Settings\Application Data\Mozilla\Firefox\Profiles\2t1c68r7.default\Cache\_CACHE_002_ Object is locked skipped
C:\Documents and Settings\Owner\Local Settings\Application Data\Mozilla\Firefox\Profiles\2t1c68r7.default\Cache\_CACHE_003_ Object is locked skipped
C:\Documents and Settings\Owner\Local Settings\Application Data\Mozilla\Firefox\Profiles\2t1c68r7.default\Cache\_CACHE_MAP_ Object is locked skipped
C:\Documents and Settings\Owner\Local Settings\History\History.IE5\index.dat Object is locked skipped
C:\Documents and Settings\Owner\Local Settings\Temporary Internet Files\Content.IE5\index.dat Object is locked skipped
C:\Documents and Settings\Owner\My Documents\Downloads\carl_cox_-_3_deck_colors.zip Object is locked skipped
C:\Documents and Settings\Owner\NTUSER.DAT Object is locked skipped
C:\Documents and Settings\Owner\NTUSER.DAT.LOG Object is locked skipped
C:\hp\bin\KillWind.exe Infected: not-a-virus:RiskTool.Win32.PsKill.p skipped
C:\pnpgoj.exe Infected: Trojan-Downloader.Win32.Agent.ddl skipped
C:\Program Files\CA\PPRT\logs\2007-10-07.csv Object is locked skipped
C:\Program Files\HP Pavilion PC Help\Pavilion\XPHWWBP4\plugin\bin\motdeusr.zip Object is locked skipped
C:\Program Files\HP Pavilion PC Help\Pavilion\XPHWWBP4\plugin\bin\pchplugin.zip Object is locked skipped
C:\Program Files\Java\j2re1.4.2_03\javaws\javaws.jar Object is locked skipped
C:\Program Files\Java\j2re1.4.2_03\lib\jsse.jar Object is locked skipped
C:\Program Files\Java\j2re1.4.2_04\javaws\javaws.jar Object is locked skipped
C:\Program Files\Java\jre1.5(2).0_06\lib(2)\deploy.jar Object is locked skipped
C:\Program Files\Java\jre1.5.0_02\lib\deploy.jar Object is locked skipped
C:\Program Files\Java\jre1.5.0_04\lib\deploy.jar Object is locked skipped
C:\Program Files\Java\jre1.6.0_01\lib\ext\sunjce_provider.jar Object is locked skipped
C:\Program Files\Java\jre1.6.0_01\lib\ext\sunpkcs11.jar Object is locked skipped
C:\Program Files\Java\jre1.6.0_01\lib\javaws.jar Object is locked skipped
C:\Program Files\Online Services\BTopenworldAnytime\Narrowband\Signup\Anytime\SignupLt.exe/btwebcontrol.dll Infected: not-a-virus:Dialer.Win32.BT.b skipped
C:\Program Files\Online Services\BTopenworldAnytime\Narrowband\Signup\Anytime\SignupLt.exe CAB: infected - 1 skipped
C:\Program Files\Online Services\BTopenworldAnytime\Narrowband\Signup\Reinstall\SignupLt.exe/btwebcontrol.dll Infected: not-a-virus:Dialer.Win32.BT.b skipped
C:\Program Files\Online Services\BTopenworldAnytime\Narrowband\Signup\Reinstall\SignupLt.exe CAB: infected - 1 skipped
C:\Program Files\Online Services\BTopenworldAnytime\Narrowband\Signup\Standard\SignupLt.exe/btwebcontrol.dll Infected: not-a-virus:Dialer.Win32.BT.b skipped
C:\Program Files\Online Services\BTopenworldAnytime\Narrowband\Signup\Standard\SignupLt.exe CAB: infected - 1 skipped
C:\Program Files\PC-Doctor for Windows\Java\classes\consumerui.jar Object is locked skipped
C:\Program Files\PC-Doctor for Windows\Java\classes\log4j.jar Object is locked skipped
C:\Program Files\PC-Doctor for Windows\Java\jre\lib\ext\localedata.jar Object is locked skipped
C:\Program Files\PC-Doctor for Windows\Java\jre\lib\im\indicim.jar Object is locked skipped
C:\Program Files\PC-Doctor for Windows\Java\jre\lib\jaws.jar Object is locked skipped
C:\Program Files\PC-Doctor for Windows\Java\Native Help\de\webhelp.jar Object is locked skipped
C:\Program Files\PC-Doctor for Windows\Java\Native Help\en\webhelp.jar Object is locked skipped
C:\Program Files\PC-Doctor for Windows\Java\Native Help\en\webhelp0.zip Object is locked skipped
C:\Program Files\PC-Doctor for Windows\Java\Native Help\fr\webhelp.jar Object is locked skipped
C:\Program Files\PC-Doctor for Windows\Java\Native Help\ja\webhelp.jar Object is locked skipped
C:\Program Files\PC-Doctor for Windows\Java\Native Help\nl\webhelp.jar Object is locked skipped
C:\Program Files\Trend Micro\HijackThis\SmitfraudFix\Reboot.exe Infected: not-a-virus:RiskTool.Win32.Reboot.f skipped
C:\Program Files\Windows Media Player\Skins\Atomic.wmz Object is locked skipped
C:\Program Files\Windows Media Player\Skins\compact.wmz Object is locked skipped
C:\Program Files\Windows Media Player\Skins\QuickSilver.wmz Object is locked skipped
C:\Program Files\Windows Media Player\Skins\splat.wmz Object is locked skipped
C:\Program Files\Windows Media Player\Skins\Windows Classic.wmz Object is locked skipped
C:\System Volume Information\MountPointManagerRemoteDatabase Object is locked skipped
C:\System Volume Information\_restore{64D353BC-F70D-499F-9163-3CEC028719CD}\RP27\change.log Object is locked skipped
C:\WINDOWS\$NtUninstallQ828026$\msdxm.ocx Object is locked skipped
C:\WINDOWS\Debug\PASSWD.LOG Object is locked skipped
C:\WINDOWS\SchedLgU.Txt Object is locked skipped
C:\WINDOWS\SoftwareDistribution\ReportingEvents.log Object is locked skipped
C:\WINDOWS\Sti_Trace.log Object is locked skipped
C:\WINDOWS\system32\CatRoot2\edb.log Object is locked skipped
C:\WINDOWS\system32\CatRoot2\tmp.edb Object is locked skipped
C:\WINDOWS\system32\config\AppEvent.Evt Object is locked skipped
C:\WINDOWS\system32\config\default Object is locked skipped
C:\WINDOWS\system32\config\default.LOG Object is locked skipped
C:\WINDOWS\system32\config\SAM Object is locked skipped
C:\WINDOWS\system32\config\SAM.LOG Object is locked skipped
C:\WINDOWS\system32\config\SecEvent.Evt Object is locked skipped
C:\WINDOWS\system32\config\SECURITY Object is locked skipped
C:\WINDOWS\system32\config\SECURITY.LOG Object is locked skipped
C:\WINDOWS\system32\config\software Object is locked skipped
C:\WINDOWS\system32\config\software.LOG Object is locked skipped
C:\WINDOWS\system32\config\SysEvent.Evt Object is locked skipped
C:\WINDOWS\system32\config\system Object is locked skipped
C:\WINDOWS\system32\config\system.LOG Object is locked skipped
C:\WINDOWS\system32\h323log.txt Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\INDEX.BTR Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\INDEX.MAP Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\MAPPING.VER Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\MAPPING1.MAP Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\MAPPING2.MAP Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\OBJECTS.DATA Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\OBJECTS.MAP Object is locked skipped
C:\WINDOWS\wiadebug.log Object is locked skipped
C:\WINDOWS\wiaservc.log Object is locked skipped
C:\WINDOWS\WindowsUpdate.log Object is locked skipped
Scan process completed.