dmitry3000
2007-10-11, 07:07
Hello there. Few days ago my PC started to behave funny. Windows warning massages : "Your system is infected. Download security software now!", background changed, all the processes slewed down.
I run Kaspersky online scanner and it reported that my system is infected. Here is the Kaspersky report and HJT log
KASPERSKY ONLINE SCANNER REPORT
Wednesday, October 10, 2007 8:15:08 PM
Operating System: Microsoft Windows XP Professional, Service Pack 2 (Build 2600)
Kaspersky Online Scanner version: 5.0.98.0
Kaspersky Anti-Virus database last update: 11/10/2007
Kaspersky Anti-Virus database records: 430659
-------------------------------------------------------------------------------
Scan Settings:
Scan using the following antivirus database: extended
Scan Archives: true
Scan Mail Bases: true
Scan Target - My Computer:
C:\
D:\
F:\
G:\
H:\
I:\
Scan Statistics:
Total number of scanned objects: 44639
Number of viruses found: 5
Number of infected objects: 13
Number of suspicious objects: 0
Duration of the scan process: 00:37:01
Infected Object Name / Virus Name / Last Action
C:\Documents and Settings\All Users\Application Data\Microsoft\eHome\logs\ehRecvr.log Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Network\Downloader\qmgr0.dat Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Network\Downloader\qmgr1.dat Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Symantec\Common Client\settings.dat Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Symantec\HPPAppActivity.log Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Symantec\HPPHomePageActivity.log Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Symantec\LiveUpdate\2007-10-10_Log.ALUSchedulerSvc.LiveUpdate Object is locked skipped
C:\Documents and Settings\All Users\Documents\Recorded TV\TempRec\TempSBE\MSDVRMM_3762438294_131072_253 Object is locked skipped
C:\Documents and Settings\All Users\Documents\Recorded TV\TempRec\TempSBE\MSDVRMM_3762438294_262144_248 Object is locked skipped
C:\Documents and Settings\All Users\Documents\Recorded TV\TempRec\TempSBE\SBE2.tmp Object is locked skipped
C:\Documents and Settings\All Users\Documents\Recorded TV\TempRec\TempSBE\SBE3.tmp Object is locked skipped
C:\Documents and Settings\All Users\Documents\Recorded TV\TempRec\{00150282-F97C-47DD-B88F-E18CC312BE8B}.TmpSBE Object is locked skipped
C:\Documents and Settings\All Users\Documents\Recorded TV\TempRec\{8CA5EE98-9673-4A0E-B8B3-45FB51CC1E66}.TmpSBE Object is locked skipped
C:\Documents and Settings\All Users\DRM\drmstore.hds Object is locked skipped
C:\Documents and Settings\Dmitry\Application Data\Mozilla\Firefox\Profiles\jawptwhw.default\cert8.db Object is locked skipped
C:\Documents and Settings\Dmitry\Application Data\Mozilla\Firefox\Profiles\jawptwhw.default\formhistory.dat Object is locked skipped
C:\Documents and Settings\Dmitry\Application Data\Mozilla\Firefox\Profiles\jawptwhw.default\GoogleToolbarData\googlesafebrowsing.db Object is locked skipped
C:\Documents and Settings\Dmitry\Application Data\Mozilla\Firefox\Profiles\jawptwhw.default\history.dat Object is locked skipped
C:\Documents and Settings\Dmitry\Application Data\Mozilla\Firefox\Profiles\jawptwhw.default\key3.db Object is locked skipped
C:\Documents and Settings\Dmitry\Application Data\Mozilla\Firefox\Profiles\jawptwhw.default\parent.lock Object is locked skipped
C:\Documents and Settings\Dmitry\Application Data\Mozilla\Firefox\Profiles\jawptwhw.default\search.sqlite Object is locked skipped
C:\Documents and Settings\Dmitry\Application Data\Mozilla\Firefox\Profiles\jawptwhw.default\urlclassifier2.sqlite Object is locked skipped
C:\Documents and Settings\Dmitry\Application Data\Symantec\PendingAlertsQueue.log Object is locked skipped
C:\Documents and Settings\Dmitry\Cookies\index.dat Object is locked skipped
C:\Documents and Settings\Dmitry\Desktop\SDFix\backups_old4\backups.zip/backups/VideoAccessCodec.ocx Infected: Trojan.Win32.Agent.bvq skipped
C:\Documents and Settings\Dmitry\Desktop\SDFix\backups_old4\backups.zip ZIP: infected - 1 skipped
C:\Documents and Settings\Dmitry\Local Settings\Application Data\ApplicationHistory\Acer.Empowering.Framework.Launcher.exe.7c55249b.ini.inuse Object is locked skipped
C:\Documents and Settings\Dmitry\Local Settings\Application Data\ApplicationHistory\SysMonitor.exe.49302a1.ini.inuse Object is locked skipped
C:\Documents and Settings\Dmitry\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat Object is locked skipped
C:\Documents and Settings\Dmitry\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped
C:\Documents and Settings\Dmitry\Local Settings\Application Data\Mozilla\Firefox\Profiles\jawptwhw.default\Cache\_CACHE_001_ Object is locked skipped
C:\Documents and Settings\Dmitry\Local Settings\Application Data\Mozilla\Firefox\Profiles\jawptwhw.default\Cache\_CACHE_002_ Object is locked skipped
C:\Documents and Settings\Dmitry\Local Settings\Application Data\Mozilla\Firefox\Profiles\jawptwhw.default\Cache\_CACHE_003_ Object is locked skipped
C:\Documents and Settings\Dmitry\Local Settings\Application Data\Mozilla\Firefox\Profiles\jawptwhw.default\Cache\_CACHE_MAP_ Object is locked skipped
C:\Documents and Settings\Dmitry\Local Settings\History\History.IE5\index.dat Object is locked skipped
C:\Documents and Settings\Dmitry\Local Settings\History\History.IE5\MSHist012007101020071011\index.dat Object is locked skipped
C:\Documents and Settings\Dmitry\Local Settings\Temp\veoh_data_store.tmp Object is locked skipped
C:\Documents and Settings\Dmitry\Local Settings\Temp\~DF2BD7.tmp Object is locked skipped
C:\Documents and Settings\Dmitry\Local Settings\Temp\~DFF506.tmp Object is locked skipped
C:\Documents and Settings\Dmitry\Local Settings\Temporary Internet Files\Content.IE5\index.dat Object is locked skipped
C:\Documents and Settings\Dmitry\NTUSER.DAT Object is locked skipped
C:\Documents and Settings\Dmitry\ntuser.dat.LOG Object is locked skipped
C:\Documents and Settings\Dmitry\UserData\index.dat Object is locked skipped
C:\Documents and Settings\LocalService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat Object is locked skipped
C:\Documents and Settings\LocalService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped
C:\Documents and Settings\LocalService\NTUSER.DAT Object is locked skipped
C:\Documents and Settings\LocalService\ntuser.dat.LOG Object is locked skipped
C:\Documents and Settings\NetworkService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat Object is locked skipped
C:\Documents and Settings\NetworkService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped
C:\Documents and Settings\NetworkService\NTUSER.DAT Object is locked skipped
C:\Documents and Settings\NetworkService\ntuser.dat.LOG Object is locked skipped
C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcrst.dll Object is locked skipped
C:\Program Files\Common Files\Symantec Shared\EENGINE\EPERSIST.DAT Object is locked skipped
C:\Program Files\Common Files\Symantec Shared\SNDALRT.log Object is locked skipped
C:\Program Files\Common Files\Symantec Shared\SNDCON.log Object is locked skipped
C:\Program Files\Common Files\Symantec Shared\SNDDBG.log Object is locked skipped
C:\Program Files\Common Files\Symantec Shared\SNDFW.log Object is locked skipped
C:\Program Files\Common Files\Symantec Shared\SNDIDS.log Object is locked skipped
C:\Program Files\Common Files\Symantec Shared\SNDSYS.log Object is locked skipped
C:\Program Files\Common Files\Symantec Shared\SPBBC\LOGS\BBConfig.log Object is locked skipped
C:\Program Files\Common Files\Symantec Shared\SPBBC\LOGS\BBDebug.log Object is locked skipped
C:\Program Files\Common Files\Symantec Shared\SPBBC\LOGS\BBDetect.log Object is locked skipped
C:\Program Files\Common Files\Symantec Shared\SPBBC\LOGS\BBNotify.log Object is locked skipped
C:\Program Files\Common Files\Symantec Shared\SPBBC\LOGS\BBRefr.log Object is locked skipped
C:\Program Files\Common Files\Symantec Shared\SPBBC\LOGS\BBSetCfg.log Object is locked skipped
C:\Program Files\Common Files\Symantec Shared\SPBBC\LOGS\BBSetCfg2.log Object is locked skipped
C:\Program Files\Common Files\Symantec Shared\SPBBC\LOGS\BBSetDev.log Object is locked skipped
C:\Program Files\Common Files\Symantec Shared\SPBBC\LOGS\BBSetLoc.log Object is locked skipped
C:\Program Files\Common Files\Symantec Shared\SPBBC\LOGS\BBSetUsr.log Object is locked skipped
C:\Program Files\Common Files\Symantec Shared\SPBBC\LOGS\BBSMNot.log Object is locked skipped
C:\Program Files\Common Files\Symantec Shared\SPBBC\LOGS\BBSMReg.log Object is locked skipped
C:\Program Files\Common Files\Symantec Shared\SPBBC\LOGS\BBSMRSt.log Object is locked skipped
C:\Program Files\Common Files\Symantec Shared\SPBBC\LOGS\BBStHash.log Object is locked skipped
C:\Program Files\Common Files\Symantec Shared\SPBBC\LOGS\BBStMSI.log Object is locked skipped
C:\Program Files\Common Files\Symantec Shared\SPBBC\LOGS\BBValid.log Object is locked skipped
C:\Program Files\Common Files\Symantec Shared\SPBBC\LOGS\SPPolicy.log Object is locked skipped
C:\Program Files\Common Files\Symantec Shared\SPBBC\LOGS\SPStart.log Object is locked skipped
C:\Program Files\Common Files\Symantec Shared\SPBBC\LOGS\SPStop.log Object is locked skipped
C:\Program Files\Norton AntiVirus\AVApp.log Object is locked skipped
C:\Program Files\Norton AntiVirus\AVError.log Object is locked skipped
C:\Program Files\Norton AntiVirus\AVVirus.log Object is locked skipped
C:\Program Files\Norton AntiVirus\Savrt\0348NAV~.TMP Object is locked skipped
C:\Program Files\Norton AntiVirus\Savrt\0585NAV~.TMP Object is locked skipped
C:\Program Files\Veoh Networks\Veoh\client.log Object is locked skipped
C:\Program Files\Veoh Networks\Veoh\upload.log Object is locked skipped
C:\System Volume Information\MountPointManagerRemoteDatabase Object is locked skipped
C:\System Volume Information\_restore{FD813455-4B32-4C50-8332-5E60580B76D4}\RP2\change.log Object is locked skipped
C:\WINDOWS\bndsronw.dll Infected: not-a-virus:AdWare.Win32.Vapsup.ab skipped
C:\WINDOWS\Debug\PASSWD.LOG Object is locked skipped
C:\WINDOWS\msvb.dll Infected: not-a-virus:AdWare.Win32.Vapsup.ab skipped
C:\WINDOWS\Registration\{02D4B3F1-FD88-11D1-960D-00805FC79235}.{3E7AE2D9-7138-408E-98BB-2F2CF882A42A}.crmlog Object is locked skipped
C:\WINDOWS\SchedLgU.Txt Object is locked skipped
C:\WINDOWS\SoftwareDistribution\ReportingEvents.log Object is locked skipped
C:\WINDOWS\sysdx.dll Infected: not-a-virus:AdWare.Win32.Vapsup.ab skipped
C:\WINDOWS\system32\CatRoot2\edb.log Object is locked skipped
C:\WINDOWS\system32\CatRoot2\tmp.edb Object is locked skipped
C:\WINDOWS\system32\config\AppEvent.Evt Object is locked skipped
C:\WINDOWS\system32\config\default Object is locked skipped
C:\WINDOWS\system32\config\default.LOG Object is locked skipped
C:\WINDOWS\system32\config\Media Ce.evt Object is locked skipped
C:\WINDOWS\system32\config\SAM Object is locked skipped
C:\WINDOWS\system32\config\SAM.LOG Object is locked skipped
C:\WINDOWS\system32\config\SecEvent.Evt Object is locked skipped
C:\WINDOWS\system32\config\SECURITY Object is locked skipped
C:\WINDOWS\system32\config\SECURITY.LOG Object is locked skipped
C:\WINDOWS\system32\config\software Object is locked skipped
C:\WINDOWS\system32\config\software.LOG Object is locked skipped
C:\WINDOWS\system32\config\SysEvent.Evt Object is locked skipped
C:\WINDOWS\system32\config\system Object is locked skipped
C:\WINDOWS\system32\config\system.LOG Object is locked skipped
C:\WINDOWS\system32\h323log.txt Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\INDEX.BTR Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\INDEX.MAP Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\MAPPING.VER Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\MAPPING1.MAP Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\MAPPING2.MAP Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\OBJECTS.DATA Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\OBJECTS.MAP Object is locked skipped
C:\WINDOWS\temp\Perflib_Perfdata_130.dat Object is locked skipped
C:\WINDOWS\WindowsUpdate.log Object is locked skipped
C:\WINDOWS\wsremover.exe Infected: not-a-virus:AdWare.Win32.Agent.mq skipped
D:\software\nero\Keygens&Cracks\Nero.Burning.ROM.v5.5.10.20.Enterprise.Edition.WinALL.Keygen.Only-TNO.zip/Nero.Burning.ROM.v5.5.10.20.Enterprise.Edition.WinALL.Keygen.Only-TNO/tno_n520.zip/tno_n520.exe Infected: Trojan-PSW.Win32.Delf.zj skipped
D:\software\nero\Keygens&Cracks\Nero.Burning.ROM.v5.5.10.20.Enterprise.Edition.WinALL.Keygen.Only-TNO.zip/Nero.Burning.ROM.v5.5.10.20.Enterprise.Edition.WinALL.Keygen.Only-TNO/tno_n520.zip Infected: Trojan-PSW.Win32.Delf.zj skipped
D:\software\nero\Keygens&Cracks\Nero.Burning.ROM.v5.5.10.20.Enterprise.Edition.WinALL.Keygen.Only-TNO.zip ZIP: infected - 2 skipped
D:\software\nero\Nero-7.5.9.0A_eng.exe/Toolbar.exe Infected: not-a-virus:AdTool.Win32.MyWebSearch skipped
D:\software\nero\Nero-7.5.9.0A_eng.exe RAR: infected - 1 skipped
D:\SDFix\backups_old1\backups.zip/backups/VideoAccessCodec.ocx Infected: Trojan.Win32.Agent.bvq skipped
D:\SDFix\backups_old1\backups.zip ZIP: infected - 1 skipped
Scan process completed.
______________________________
I run Kaspersky online scanner and it reported that my system is infected. Here is the Kaspersky report and HJT log
KASPERSKY ONLINE SCANNER REPORT
Wednesday, October 10, 2007 8:15:08 PM
Operating System: Microsoft Windows XP Professional, Service Pack 2 (Build 2600)
Kaspersky Online Scanner version: 5.0.98.0
Kaspersky Anti-Virus database last update: 11/10/2007
Kaspersky Anti-Virus database records: 430659
-------------------------------------------------------------------------------
Scan Settings:
Scan using the following antivirus database: extended
Scan Archives: true
Scan Mail Bases: true
Scan Target - My Computer:
C:\
D:\
F:\
G:\
H:\
I:\
Scan Statistics:
Total number of scanned objects: 44639
Number of viruses found: 5
Number of infected objects: 13
Number of suspicious objects: 0
Duration of the scan process: 00:37:01
Infected Object Name / Virus Name / Last Action
C:\Documents and Settings\All Users\Application Data\Microsoft\eHome\logs\ehRecvr.log Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Network\Downloader\qmgr0.dat Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Network\Downloader\qmgr1.dat Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Symantec\Common Client\settings.dat Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Symantec\HPPAppActivity.log Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Symantec\HPPHomePageActivity.log Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Symantec\LiveUpdate\2007-10-10_Log.ALUSchedulerSvc.LiveUpdate Object is locked skipped
C:\Documents and Settings\All Users\Documents\Recorded TV\TempRec\TempSBE\MSDVRMM_3762438294_131072_253 Object is locked skipped
C:\Documents and Settings\All Users\Documents\Recorded TV\TempRec\TempSBE\MSDVRMM_3762438294_262144_248 Object is locked skipped
C:\Documents and Settings\All Users\Documents\Recorded TV\TempRec\TempSBE\SBE2.tmp Object is locked skipped
C:\Documents and Settings\All Users\Documents\Recorded TV\TempRec\TempSBE\SBE3.tmp Object is locked skipped
C:\Documents and Settings\All Users\Documents\Recorded TV\TempRec\{00150282-F97C-47DD-B88F-E18CC312BE8B}.TmpSBE Object is locked skipped
C:\Documents and Settings\All Users\Documents\Recorded TV\TempRec\{8CA5EE98-9673-4A0E-B8B3-45FB51CC1E66}.TmpSBE Object is locked skipped
C:\Documents and Settings\All Users\DRM\drmstore.hds Object is locked skipped
C:\Documents and Settings\Dmitry\Application Data\Mozilla\Firefox\Profiles\jawptwhw.default\cert8.db Object is locked skipped
C:\Documents and Settings\Dmitry\Application Data\Mozilla\Firefox\Profiles\jawptwhw.default\formhistory.dat Object is locked skipped
C:\Documents and Settings\Dmitry\Application Data\Mozilla\Firefox\Profiles\jawptwhw.default\GoogleToolbarData\googlesafebrowsing.db Object is locked skipped
C:\Documents and Settings\Dmitry\Application Data\Mozilla\Firefox\Profiles\jawptwhw.default\history.dat Object is locked skipped
C:\Documents and Settings\Dmitry\Application Data\Mozilla\Firefox\Profiles\jawptwhw.default\key3.db Object is locked skipped
C:\Documents and Settings\Dmitry\Application Data\Mozilla\Firefox\Profiles\jawptwhw.default\parent.lock Object is locked skipped
C:\Documents and Settings\Dmitry\Application Data\Mozilla\Firefox\Profiles\jawptwhw.default\search.sqlite Object is locked skipped
C:\Documents and Settings\Dmitry\Application Data\Mozilla\Firefox\Profiles\jawptwhw.default\urlclassifier2.sqlite Object is locked skipped
C:\Documents and Settings\Dmitry\Application Data\Symantec\PendingAlertsQueue.log Object is locked skipped
C:\Documents and Settings\Dmitry\Cookies\index.dat Object is locked skipped
C:\Documents and Settings\Dmitry\Desktop\SDFix\backups_old4\backups.zip/backups/VideoAccessCodec.ocx Infected: Trojan.Win32.Agent.bvq skipped
C:\Documents and Settings\Dmitry\Desktop\SDFix\backups_old4\backups.zip ZIP: infected - 1 skipped
C:\Documents and Settings\Dmitry\Local Settings\Application Data\ApplicationHistory\Acer.Empowering.Framework.Launcher.exe.7c55249b.ini.inuse Object is locked skipped
C:\Documents and Settings\Dmitry\Local Settings\Application Data\ApplicationHistory\SysMonitor.exe.49302a1.ini.inuse Object is locked skipped
C:\Documents and Settings\Dmitry\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat Object is locked skipped
C:\Documents and Settings\Dmitry\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped
C:\Documents and Settings\Dmitry\Local Settings\Application Data\Mozilla\Firefox\Profiles\jawptwhw.default\Cache\_CACHE_001_ Object is locked skipped
C:\Documents and Settings\Dmitry\Local Settings\Application Data\Mozilla\Firefox\Profiles\jawptwhw.default\Cache\_CACHE_002_ Object is locked skipped
C:\Documents and Settings\Dmitry\Local Settings\Application Data\Mozilla\Firefox\Profiles\jawptwhw.default\Cache\_CACHE_003_ Object is locked skipped
C:\Documents and Settings\Dmitry\Local Settings\Application Data\Mozilla\Firefox\Profiles\jawptwhw.default\Cache\_CACHE_MAP_ Object is locked skipped
C:\Documents and Settings\Dmitry\Local Settings\History\History.IE5\index.dat Object is locked skipped
C:\Documents and Settings\Dmitry\Local Settings\History\History.IE5\MSHist012007101020071011\index.dat Object is locked skipped
C:\Documents and Settings\Dmitry\Local Settings\Temp\veoh_data_store.tmp Object is locked skipped
C:\Documents and Settings\Dmitry\Local Settings\Temp\~DF2BD7.tmp Object is locked skipped
C:\Documents and Settings\Dmitry\Local Settings\Temp\~DFF506.tmp Object is locked skipped
C:\Documents and Settings\Dmitry\Local Settings\Temporary Internet Files\Content.IE5\index.dat Object is locked skipped
C:\Documents and Settings\Dmitry\NTUSER.DAT Object is locked skipped
C:\Documents and Settings\Dmitry\ntuser.dat.LOG Object is locked skipped
C:\Documents and Settings\Dmitry\UserData\index.dat Object is locked skipped
C:\Documents and Settings\LocalService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat Object is locked skipped
C:\Documents and Settings\LocalService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped
C:\Documents and Settings\LocalService\NTUSER.DAT Object is locked skipped
C:\Documents and Settings\LocalService\ntuser.dat.LOG Object is locked skipped
C:\Documents and Settings\NetworkService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat Object is locked skipped
C:\Documents and Settings\NetworkService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped
C:\Documents and Settings\NetworkService\NTUSER.DAT Object is locked skipped
C:\Documents and Settings\NetworkService\ntuser.dat.LOG Object is locked skipped
C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcrst.dll Object is locked skipped
C:\Program Files\Common Files\Symantec Shared\EENGINE\EPERSIST.DAT Object is locked skipped
C:\Program Files\Common Files\Symantec Shared\SNDALRT.log Object is locked skipped
C:\Program Files\Common Files\Symantec Shared\SNDCON.log Object is locked skipped
C:\Program Files\Common Files\Symantec Shared\SNDDBG.log Object is locked skipped
C:\Program Files\Common Files\Symantec Shared\SNDFW.log Object is locked skipped
C:\Program Files\Common Files\Symantec Shared\SNDIDS.log Object is locked skipped
C:\Program Files\Common Files\Symantec Shared\SNDSYS.log Object is locked skipped
C:\Program Files\Common Files\Symantec Shared\SPBBC\LOGS\BBConfig.log Object is locked skipped
C:\Program Files\Common Files\Symantec Shared\SPBBC\LOGS\BBDebug.log Object is locked skipped
C:\Program Files\Common Files\Symantec Shared\SPBBC\LOGS\BBDetect.log Object is locked skipped
C:\Program Files\Common Files\Symantec Shared\SPBBC\LOGS\BBNotify.log Object is locked skipped
C:\Program Files\Common Files\Symantec Shared\SPBBC\LOGS\BBRefr.log Object is locked skipped
C:\Program Files\Common Files\Symantec Shared\SPBBC\LOGS\BBSetCfg.log Object is locked skipped
C:\Program Files\Common Files\Symantec Shared\SPBBC\LOGS\BBSetCfg2.log Object is locked skipped
C:\Program Files\Common Files\Symantec Shared\SPBBC\LOGS\BBSetDev.log Object is locked skipped
C:\Program Files\Common Files\Symantec Shared\SPBBC\LOGS\BBSetLoc.log Object is locked skipped
C:\Program Files\Common Files\Symantec Shared\SPBBC\LOGS\BBSetUsr.log Object is locked skipped
C:\Program Files\Common Files\Symantec Shared\SPBBC\LOGS\BBSMNot.log Object is locked skipped
C:\Program Files\Common Files\Symantec Shared\SPBBC\LOGS\BBSMReg.log Object is locked skipped
C:\Program Files\Common Files\Symantec Shared\SPBBC\LOGS\BBSMRSt.log Object is locked skipped
C:\Program Files\Common Files\Symantec Shared\SPBBC\LOGS\BBStHash.log Object is locked skipped
C:\Program Files\Common Files\Symantec Shared\SPBBC\LOGS\BBStMSI.log Object is locked skipped
C:\Program Files\Common Files\Symantec Shared\SPBBC\LOGS\BBValid.log Object is locked skipped
C:\Program Files\Common Files\Symantec Shared\SPBBC\LOGS\SPPolicy.log Object is locked skipped
C:\Program Files\Common Files\Symantec Shared\SPBBC\LOGS\SPStart.log Object is locked skipped
C:\Program Files\Common Files\Symantec Shared\SPBBC\LOGS\SPStop.log Object is locked skipped
C:\Program Files\Norton AntiVirus\AVApp.log Object is locked skipped
C:\Program Files\Norton AntiVirus\AVError.log Object is locked skipped
C:\Program Files\Norton AntiVirus\AVVirus.log Object is locked skipped
C:\Program Files\Norton AntiVirus\Savrt\0348NAV~.TMP Object is locked skipped
C:\Program Files\Norton AntiVirus\Savrt\0585NAV~.TMP Object is locked skipped
C:\Program Files\Veoh Networks\Veoh\client.log Object is locked skipped
C:\Program Files\Veoh Networks\Veoh\upload.log Object is locked skipped
C:\System Volume Information\MountPointManagerRemoteDatabase Object is locked skipped
C:\System Volume Information\_restore{FD813455-4B32-4C50-8332-5E60580B76D4}\RP2\change.log Object is locked skipped
C:\WINDOWS\bndsronw.dll Infected: not-a-virus:AdWare.Win32.Vapsup.ab skipped
C:\WINDOWS\Debug\PASSWD.LOG Object is locked skipped
C:\WINDOWS\msvb.dll Infected: not-a-virus:AdWare.Win32.Vapsup.ab skipped
C:\WINDOWS\Registration\{02D4B3F1-FD88-11D1-960D-00805FC79235}.{3E7AE2D9-7138-408E-98BB-2F2CF882A42A}.crmlog Object is locked skipped
C:\WINDOWS\SchedLgU.Txt Object is locked skipped
C:\WINDOWS\SoftwareDistribution\ReportingEvents.log Object is locked skipped
C:\WINDOWS\sysdx.dll Infected: not-a-virus:AdWare.Win32.Vapsup.ab skipped
C:\WINDOWS\system32\CatRoot2\edb.log Object is locked skipped
C:\WINDOWS\system32\CatRoot2\tmp.edb Object is locked skipped
C:\WINDOWS\system32\config\AppEvent.Evt Object is locked skipped
C:\WINDOWS\system32\config\default Object is locked skipped
C:\WINDOWS\system32\config\default.LOG Object is locked skipped
C:\WINDOWS\system32\config\Media Ce.evt Object is locked skipped
C:\WINDOWS\system32\config\SAM Object is locked skipped
C:\WINDOWS\system32\config\SAM.LOG Object is locked skipped
C:\WINDOWS\system32\config\SecEvent.Evt Object is locked skipped
C:\WINDOWS\system32\config\SECURITY Object is locked skipped
C:\WINDOWS\system32\config\SECURITY.LOG Object is locked skipped
C:\WINDOWS\system32\config\software Object is locked skipped
C:\WINDOWS\system32\config\software.LOG Object is locked skipped
C:\WINDOWS\system32\config\SysEvent.Evt Object is locked skipped
C:\WINDOWS\system32\config\system Object is locked skipped
C:\WINDOWS\system32\config\system.LOG Object is locked skipped
C:\WINDOWS\system32\h323log.txt Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\INDEX.BTR Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\INDEX.MAP Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\MAPPING.VER Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\MAPPING1.MAP Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\MAPPING2.MAP Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\OBJECTS.DATA Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\OBJECTS.MAP Object is locked skipped
C:\WINDOWS\temp\Perflib_Perfdata_130.dat Object is locked skipped
C:\WINDOWS\WindowsUpdate.log Object is locked skipped
C:\WINDOWS\wsremover.exe Infected: not-a-virus:AdWare.Win32.Agent.mq skipped
D:\software\nero\Keygens&Cracks\Nero.Burning.ROM.v5.5.10.20.Enterprise.Edition.WinALL.Keygen.Only-TNO.zip/Nero.Burning.ROM.v5.5.10.20.Enterprise.Edition.WinALL.Keygen.Only-TNO/tno_n520.zip/tno_n520.exe Infected: Trojan-PSW.Win32.Delf.zj skipped
D:\software\nero\Keygens&Cracks\Nero.Burning.ROM.v5.5.10.20.Enterprise.Edition.WinALL.Keygen.Only-TNO.zip/Nero.Burning.ROM.v5.5.10.20.Enterprise.Edition.WinALL.Keygen.Only-TNO/tno_n520.zip Infected: Trojan-PSW.Win32.Delf.zj skipped
D:\software\nero\Keygens&Cracks\Nero.Burning.ROM.v5.5.10.20.Enterprise.Edition.WinALL.Keygen.Only-TNO.zip ZIP: infected - 2 skipped
D:\software\nero\Nero-7.5.9.0A_eng.exe/Toolbar.exe Infected: not-a-virus:AdTool.Win32.MyWebSearch skipped
D:\software\nero\Nero-7.5.9.0A_eng.exe RAR: infected - 1 skipped
D:\SDFix\backups_old1\backups.zip/backups/VideoAccessCodec.ocx Infected: Trojan.Win32.Agent.bvq skipped
D:\SDFix\backups_old1\backups.zip ZIP: infected - 1 skipped
Scan process completed.
______________________________