PDA

View Full Version : unable to stop what appear to be pop ups



scoleson
2007-11-26, 17:06
Kaspersky scan was run under safe mode, as was seach and destroy

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 8:45:52 AM, on 11/26/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16544)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
C:\Program Files\Common Files\Symantec Shared\AppCore\AppSvc32.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\ATI\Catalyst Media Center\Kernel\TV\CLCapSvc.exe
C:\WINDOWS\System32\CTsvcCDA.EXE
C:\Program Files\Gateway\EzTune\DTSRVC.exe
C:\Program Files\Common Files\Microsoft Shared\VS7Debug\mdm.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
C:\Program Files\ATI\Catalyst Media Center\Kernel\TV\CLSched.exe
C:\Program Files\Scansoft\PaperPort\pptd40nt.exe
C:\PROGRA~1\VISION~2\ONETOU~2.EXE
C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe
C:\WINDOWS\vVX3000.exe
C:\Program Files\Portrait Displays\Pivot Software\wpctrl.exe
C:\Program Files\Adobe\Acrobat 8.0\Acrobat\Acrotray.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\Program Files\Common Files\Symantec Shared\ccApp.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
C:\Program Files\SlySoft\AnyDVD\AnyDVD.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Program Files\Portrait Displays\Pivot Software\floater.exe
C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL =

http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = :0
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx
O3 - Toolbar: Windows Live Toolbar - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\Windows Live

Toolbar\msntb.dll
O3 - Toolbar: Adobe PDF - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files\Adobe\Acrobat

8.0\Acrobat\AcroIEFavClient.dll
O3 - Toolbar: Show Norton Toolbar - {90222687-F593-4738-B738-FBEE9C7B26DF} - C:\Program Files\Common Files\Symantec

Shared\coShared\Browser\1.7\UIBHO.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar2.dll
O4 - HKLM\..\Run: [CTStartup] C:\Program Files\Creative\SBAudigy\Program\CTEaxSpl.EXE /run
O4 - HKLM\..\Run: [PaperPort PTD] C:\Program Files\Scansoft\PaperPort\pptd40nt.exe
O4 - HKLM\..\Run: [OneTouch Monitor] C:\PROGRA~1\VISION~2\ONETOU~2.EXE
O4 - HKLM\..\Run: [KavSvc] C:\WINDOWS\System32\rararr.exe reg_run
O4 - HKLM\..\Run: [UpdReg] C:\WINDOWS\Updreg.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe"
O4 - HKLM\..\Run: [IndexSearch] C:\Program Files\Scansoft\PaperPort\IndexSearch.exe
O4 - HKLM\..\Run: [CTHelper] CTHELPER.EXE
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [VX3000] C:\WINDOWS\vVX3000.exe
O4 - HKLM\..\Run: [PivotSoftware] "C:\Program Files\Portrait Displays\Pivot Software\wpctrl.exe"
O4 - HKLM\..\Run: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k
O4 - HKLM\..\Run: [Acrobat Assistant 8.0] "C:\Program Files\Adobe\Acrobat 8.0\Acrobat\Acrotray.exe"
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [osCheck] "C:\Program Files\Norton Internet Security\osCheck.exe"
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [AnyDVD] C:\Program Files\SlySoft\AnyDVD\AnyDVD.exe
O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
O4 - HKCU\..\Run: [EPSON Stylus Photo R380 Series] C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_FATIBOA.EXE /FU

"C:\DOCUME~1\STEVEC~1\LOCALS~1\Temp\E_SB1D.tmp" /EF "HKCU"
O4 - HKUS\S-1-5-18\..\Run: [Symantec Network Driver Update Warning] C:\PROGRA~1\Symantec\LIVEUP~1\SNDWarn.EXE (User

'SYSTEM')
O4 - HKUS\S-1-5-18\..\Run: [ALUAlert] C:\Program Files\Symantec\LiveUpdate\ALUNotify.exe (User 'SYSTEM')
O4 - HKUS\S-1-5-18\..\Run: [Symantec NetDriver Warning] C:\PROGRA~1\SYMNET~1\SNDWarn.exe (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [Symantec Network Driver Update Warning] C:\PROGRA~1\Symantec\LIVEUP~1\SNDWarn.EXE (User

'Default user')
O4 - Startup: Check for OneTouch Updates.lnk = C:\Program Files\Visioneer OneTouch\WiseUpdt.exe
O4 - Global Startup: Adobe Gamma Loader.exe.lnk = C:\Program Files\Adobe\Photoshop 5.0\Extras\Calibration\Adobe

Gamma Loader.exe
O8 - Extra context menu item: &Windows Live Search - res://C:\Program Files\Windows Live

Toolbar\msntb.dll/search.htm
O8 - Extra context menu item: Allow personal info to reach this site - file://C:\Program

Files\GhostSurf\info.allow.html
O8 - Extra context menu item: Allow popups on this site - file://C:\Program Files\GhostSurf\popup.allow.html
O8 - Extra context menu item: Allow this advertisement - file://C:\Program Files\GhostSurf\menu.allowimg.html
O8 - Extra context menu item: Append to existing PDF - res://C:\Program Files\Adobe\Acrobat

8.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
O8 - Extra context menu item: Block personal info from this site - file://C:\Program Files\GhostSurf\info.block.html
O8 - Extra context menu item: Block popups on this site - file://C:\Program Files\GhostSurf\popup.block.html
O8 - Extra context menu item: Block this advertisement - file://C:\Program Files\GhostSurf\menu.blockimg.html
O8 - Extra context menu item: Convert link target to Adobe PDF - res://C:\Program Files\Adobe\Acrobat

8.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
O8 - Extra context menu item: Convert link target to existing PDF - res://C:\Program Files\Adobe\Acrobat

8.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
O8 - Extra context menu item: Convert selected links to Adobe PDF - res://C:\Program Files\Adobe\Acrobat

8.0\Acrobat\AcroIEFavClient.dll/AcroIECaptureSelLinks.html
O8 - Extra context menu item: Convert selected links to existing PDF - res://C:\Program Files\Adobe\Acrobat

8.0\Acrobat\AcroIEFavClient.dll/AcroIEAppendSelLinks.html
O8 - Extra context menu item: Convert selection to Adobe PDF - res://C:\Program Files\Adobe\Acrobat

8.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
O8 - Extra context menu item: Convert selection to existing PDF - res://C:\Program Files\Adobe\Acrobat

8.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
O8 - Extra context menu item: Convert to Adobe PDF - res://C:\Program Files\Adobe\Acrobat

8.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office12\EXCEL.EXE/3000
O9 - Extra button: (no name) - AutorunsDisabled - (no file)
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program

Files\Java\jre1.6.0_03\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program

Files\Java\jre1.6.0_03\bin\ssv.dll
O9 - Extra button: Skype - {77BF5300-1474-4EC7-9980-D32B190E9B07} - C:\Program Files\Skype\Toolbars\Internet

Explorer\SkypeIEPlugin.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network

Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program

Files\Messenger\msmsgs.exe
O16 - DPF: {0A5FD7C5-A45C-49FC-ADB5-9952547D5715} (Creative Software AutoUpdate) -

http://us.creative.com/support/downloads/su/ocx/12119/CTSUEng.cab
O16 - DPF: {0E5F0222-96B9-11D3-8997-00104BD12D94} (PCPitstop Utility) -

http://www.pcpitstop.com/pcpitstop/PCPitStop.CAB
O16 - DPF: {0EB0E74A-2A76-4AB3-A7FB-9BD8C29F7F75} (CKAVWebScan Object) -

http://www.kaspersky.com/kos/english/kavwebscan_unicode.cab
O16 - DPF: {1842B0EE-B597-11D4-8997-00104BD12D94} (iCC Class) - http://www.pcpitstop.com/internet/pcpConnCheck.cab
O16 - DPF: {2B96D5CC-C5B5-49A5-A69D-CC0A30F9028C} (MiniBugTransporterX Class) -

http://wdownload.weatherbug.com/minibug/tricklers/AWS/MiniBugTransporter.cab?
O16 - DPF: {2BC66F54-93A8-11D3-BEB6-00105AA9B6AE} (Symantec AntiVirus scanner) -

http://security.symantec.com/sscv6/SharedContent/vc/bin/AvSniff.cab
O16 - DPF: {2ED9BC2B-4DF1-472E-9B5E-55477D2C97F5} (Microsoft Data Collection Control) -

https://support.microsoft.com/OAS/ActiveX/odc.cab
O16 - DPF: {41F17733-B041-4099-A042-B518BB6A408C} -

http://a1540.g.akamai.net/7/1540/52/20021205/qtinstall.info.apple.com/drakken/us/win/QuickTimeInstaller.exe
O16 - DPF: {56336BCB-3D8A-11D6-A00B-0050DA18DE71} -

http://software-dl.real.com/2894717e64564610dd23/netzip/RdxIE601.cab
O16 - DPF: {5D9E4B6D-CD17-4D85-99D4-6A52B394EC3B} (WSDownloader Control) -

http://www.webshots.com/samplers/WSDownloader.ocx
O16 - DPF: {644E432F-49D3-41A1-8DD5-E099162EEEC5} (Symantec RuFSI Utility Class) -

http://security.symantec.com/sscv6/SharedContent/common/bin/cabsa.cab
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) -

http://update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/muweb_site.cab?1131879881794
O16 - DPF: {9600F64D-755F-11D4-A47F-0001023E6D5A} (Shutterfly Picture Upload Plugin) -

http://web1.shutterfly.com/downloads/Uploader.cab
O16 - DPF: {DED22F57-FEE2-11D0-953B-00C04FD9152D} (CarPoint Auto-Pricer Control) -

http://autos.msn.com/components/ocx/autopricer/autopricer.cab
O16 - DPF: {F6ACF75C-C32C-447B-9BEF-46B766368D29} (Creative Software AutoUpdate Support Package) -

http://us.creative.com/support/downloads/su/ocx/12119/CTPID.cab
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL
O23 - Service: Automatic LiveUpdate Scheduler - Symantec Corporation - C:\Program

Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec

Shared\ccSvcHst.exe
O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec

Shared\ccSvcHst.exe
O23 - Service: CyberLink Background Capture Service (CBCS) (CLCapSvc) - Unknown owner - C:\Program

Files\ATI\Catalyst Media Center\Kernel\TV\CLCapSvc.exe
O23 - Service: CyberLink Task Scheduler (CTS) (CLSched) - Unknown owner - C:\Program Files\ATI\Catalyst Media

Center\Kernel\TV\CLSched.exe
O23 - Service: Symantec Lic NetConnect service (CLTNetCnService) - Symantec Corporation - C:\Program Files\Common

Files\Symantec Shared\ccSvcHst.exe
O23 - Service: COM Host (comHost) - Symantec Corporation - C:\Program Files\Common Files\Symantec

Shared\VAScanner\comHost.exe
O23 - Service: Creative Service for CDROM Access - Creative Technology Ltd - C:\WINDOWS\System32\CTsvcCDA.EXE
O23 - Service: CyberLink Media Library Service - Cyberlink - C:\Program Files\ATI\Catalyst Media

Center\Kernel\CLML_NTService\CLMLServer.exe
O23 - Service: Portrait Displays Display Tune Service (DTSRVC) - Unknown owner - C:\Program

Files\Gateway\EzTune\DTSRVC.exe
O23 - Service: FLEXnet Licensing Service - Macrovision Europe Ltd. - C:\Program Files\Common Files\Macrovision

Shared\FLEXnet Publisher\FNPLicensingService.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google

Updater\GoogleUpdaterService.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common

Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: Symantec IS Password Validation (ISPwdSvc) - Symantec Corporation - C:\Program Files\Norton Internet

Security\isPwdSvc.exe
O23 - Service: LiveUpdate - Symantec Corporation - C:\PROGRA~1\Symantec\LIVEUP~1\LUCOMS~1.EXE
O23 - Service: Symantec Core LC - Unknown owner - C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
O23 - Service: Symantec AppCore Service (SymAppCore) - Symantec Corporation - C:\Program Files\Common Files\Symantec

Shared\AppCore\AppSvc32.exe
O24 - Desktop Component 0: (no name) - http://images.webshots.com/ProThumbs/67/36567_wallpaper280.jpg

--
End of file - 12862 bytes

scoleson
2007-11-26, 17:13
KASPERSKY ONLINE SCANNER REPORT
Monday, November 26, 2007 5:15:44 AM
Operating System: Microsoft Windows XP Home Edition, Service Pack 2 (Build 2600)
Kaspersky Online Scanner version: 5.0.98.0
Kaspersky Anti-Virus database last update: 26/11/2007
Kaspersky Anti-Virus database records: 436395
-------------------------------------------------------------------------------

Scan Settings:
Scan using the following antivirus database: standard
Scan Archives: true
Scan Mail Bases: true

Scan Target - My Computer:
A:\
C:\
D:\
E:\
F:\
H:\
I:\
J:\

Scan Statistics:
Total number of scanned objects: 175157
Number of viruses found: 37
Number of infected objects: 155
Number of suspicious objects: 2
Duration of the scan process: 09:37:51

Infected Object Name / Virus Name / Last Action
C:\Documents and Settings\Administrator\Cookies\index.dat Object is locked skipped
C:\Documents and Settings\Administrator\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat Object is locked skipped
C:\Documents and Settings\Administrator\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped
C:\Documents and Settings\Administrator\Local Settings\History\History.IE5\index.dat Object is locked skipped
C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\AntiPhishing\B3BB5BBA-E7D5-40AB-A041-A5B1C0B26C8F.dat Object is locked skipped
C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\index.dat Object is locked skipped
C:\Documents and Settings\Administrator\ntuser.dat Object is locked skipped
C:\Documents and Settings\Administrator\NTUSER.DAT.LOG Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Dr Watson\user.dmp Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\01BF27F2 Infected: Email-Worm.Win32.Sobig.f skipped
C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\02C11CD6 Infected: Email-Worm.Win32.Sobig.f skipped
C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\073C6D6E.exe Infected: Trojan-Downloader.Win32.Qoologic.q skipped
C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\07424167.dat Infected: Trojan-Downloader.Win32.Qoologic.o skipped
C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\07424167.dll Infected: Trojan-Downloader.Win32.Qoologic.q skipped
C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\07424167.exe Infected: Trojan-Downloader.Win32.Qoologic.o skipped
C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\09DC6055.exe Infected: Trojan.Win32.Obfuscated.kp skipped
C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\1110126F.exe Infected: Trojan-Dropper.Win32.Agent.hl skipped
C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\12A6529B Infected: Trojan.Win32.Pakes skipped
C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\12B37A8C Infected: Trojan-Downloader.Win32.Apropo.g skipped
C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\12B62489 Infected: Trojan.Win32.Pakes skipped
C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\12BD7882 Infected: Trojan.Win32.Pakes skipped
C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\12C0227E Infected: Trojan.Win32.Pakes skipped
C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\12C0227E.exe Infected: Trojan-Downloader.Win32.Apropo.bd skipped
C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\12C77677 Infected: Trojan-Downloader.Win32.Apropo.g skipped
C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\12C77677.exe Infected: Trojan-Downloader.Win32.Qoologic.q skipped
C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\12CD4A70.exe Infected: Trojan-Downloader.Win32.Qoologic.o skipped
C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\12D0746C.dat Infected: Trojan-Downloader.Win32.Qoologic.o skipped
C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\12D0746C.exe Infected: Trojan.Win32.Small.cy skipped
C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\12D41E68.cpl Infected: Trojan-Downloader.Win32.Qoologic.p skipped
C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\166334F8.asq Infected: Trojan-Downloader.Win32.Qoologic.o skipped
C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\1E7037F4 Infected: Email-Worm.Win32.Swen skipped
C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\21620D0E Infected: Trojan.Win32.Pakes skipped
C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\22001423.exe Infected: Trojan-Dropper.Win32.Agent.hv skipped
C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\25CC4A2D.dat Infected: P2P-Worm.Win32.SdDrop.e skipped
C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\2E414DDB Infected: Email-Worm.Win32.Swen skipped
C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\2EC0334F Infected: Email-Worm.Win32.Swen skipped
C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\2F0E22F9 Infected: Email-Worm.Win32.Swen skipped
C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\34F32881.exe Infected: Trojan-Downloader.Win32.Apropo.ai skipped
C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\37FD07F3 Infected: Email-Worm.Win32.Sobig.f skipped
C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\3883050B Infected: Trojan-Downloader.Win32.Small.abd skipped
C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\393C56C2 Infected: Trojan-Downloader.Win32.Tiny.id skipped
C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\3A950C21.exe Infected: Trojan-Downloader.Win32.Qoologic.n skipped
C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\3CC86D46.exe/data0002 Infected: Trojan.Win32.Registrator.b skipped
C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\3CC86D46.exe/data0003 Infected: Trojan-Downloader.Win32.Small.ayh skipped
C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\3CC86D46.exe NSIS: infected - 2 skipped
C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\3CC86D46.exe CryptFF: infected - 2 skipped
C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\3CE37C14 Infected: Email-Worm.Win32.Swen skipped
C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\3F6963AD.exe Infected: Trojan-Downloader.Win32.Qoologic.n skipped
C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\3F6C0DA9.exe Infected: Trojan-Downloader.Win32.Dyfuca.dp skipped
C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\3F760B9E.exe Infected: Trojan-Downloader.Win32.Apropo.ai skipped
C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\3F7C5F97.exe Infected: Trojan-Downloader.Win32.Apropo.u skipped
C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\3F833390.exe Infected: Trojan-Downloader.Win32.Apropo.bd skipped
C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\3F8D3185.dll Infected: Trojan-Downloader.Win32.Qoologic.n skipped
C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\3F8D3185.exe Infected: Trojan-Downloader.Win32.Qoologic.n skipped
C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\3F905B82.dll Infected: Trojan.Win32.Pakes skipped
C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\3F93057E.exe Infected: Trojan.Win32.Pakes skipped
C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\3F9D0373.exe Infected: Trojan-Downloader.Win32.Qoologic.n skipped
C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\3FA02D70.exe Infected: Trojan-Downloader.Win32.Qoologic.l skipped
C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\3FBB7D53.exe Infected: Trojan.Win32.StartPage.nk skipped
C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\3FC1514C.exe Infected: Trojan-Dropper.Win32.Small.wc skipped
C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\3FC47B48.dat Infected: Trojan-Downloader.Win32.Qoologic.n skipped
C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\3FC47B48.exe Infected: Trojan-Downloader.Win32.VB.eu skipped
C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\3FD54D36.dll Infected: Trojan-Clicker.Win32.Small.et skipped
C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\3FD87733.cpl Infected: Trojan-Dropper.Win32.Small.wc skipped
C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\3FDB212F.dll Infected: Trojan-Downloader.Win32.Dyfuca.dt skipped
C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\3FDB212F.exe Infected: Trojan-Dropper.Win32.Agent.hl skipped
C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\44DC4CA6 Infected: Email-Worm.Win32.Sobig.f skipped
C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\46E84731 Infected: Email-Worm.Win32.Swen skipped
C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\47C01A43 Infected: Email-Worm.Win32.Swen skipped
C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\51140426 Infected: Email-Worm.Win32.Swen skipped
C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\516273D0 Infected: Email-Worm.Win32.Swen skipped
C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\51961396 Infected: Email-Worm.Win32.Swen skipped
C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\51AF7283.exe Infected: Trojan-Downloader.Win32.Small.ayh skipped
C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\526C3B0E.exe Infected: Trojan-Downloader.Win32.Small.gll skipped
C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\549A79BE.scr Infected: Backdoor.Win32.Xenozbot skipped
C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\578922C3 Infected: Email-Worm.Win32.Swen skipped
C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\585E3D94.log Suspicious: Exploit.HTML.Mht skipped
C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\58A0054C.asq Infected: Trojan-Downloader.Win32.Qoologic.o skipped
C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\58A65945.asq Infected: Trojan-Downloader.Win32.Qoologic.o skipped
C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\58A65945.exe Infected: Trojan-Downloader.Win32.Agent.dbj skipped
C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\5E1624D7.asq Infected: Trojan-Downloader.Win32.Qoologic.o skipped
C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\607B1334 Infected: Email-Worm.Win32.Swen skipped
C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\60A20B09 Infected: Email-Worm.Win32.Swen skipped
C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\60BC5AEC Infected: Email-Worm.Win32.Swen skipped
C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\63AA605A.exe Infected: Trojan-Downloader.Win32.Dyfuca.dp skipped
C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\63F27C0B.exe Infected: Trojan-Downloader.Win32.Dyfuca.dp skipped
C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\641973E0.exe Infected: Trojan-Downloader.Win32.Dyfuca.de skipped
C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\641F47D9.exe Infected: Trojan-Downloader.Win32.Dyfuca.de skipped
C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\64261BD2.exe Infected: Trojan-Downloader.Win32.Dyfuca.de skipped
C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\645E6595.dll Infected: Trojan-Downloader.Win32.Dyfuca.gen skipped
C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\646E3783.exe Infected: Trojan.Win32.Small.cy skipped
C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\64783578.exe Infected: Trojan.Win32.Small.cy skipped
C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\648F5B5F.dll Infected: Trojan-Downloader.Win32.Dyfuca.dt skipped
C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\68E34DB1.exe Infected: Backdoor.Win32.CyberSpy.85 skipped
C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\6B720139 Infected: Trojan-Downloader.Win32.Tiny.id skipped
C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\6CCA466E Infected: Email-Worm.Win32.Sobig.f skipped
C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\6DB4190C.htm Suspicious: Exploit.HTML.Mht skipped
C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\6F1C1FE0 Infected: Email-Worm.Win32.Sobig.f skipped
C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\70D61B0A.exe Infected: Trojan-Downloader.Win32.Pacer.d skipped
C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\77781DE8 Infected: Email-Worm.Win32.Swen skipped
C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\77F649B3 Infected: Trojan-Downloader.Win32.Small.abd skipped
C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\77F973B0.exe Infected: Trojan-Downloader.Win32.Apropo.ai skipped
C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\77FF47A8.exe Infected: Trojan-Downloader.Win32.Apropo.bd skipped
C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\780371A5.dll Infected: Trojan-Downloader.Win32.Qoologic.n skipped
C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\78061BA1.exe Infected: Trojan-Downloader.Win32.Qoologic.n skipped
C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\7809459E.exe Infected: Trojan-Downloader.Win32.Qoologic.n skipped
C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\78101996.dat Infected: Trojan-Downloader.Win32.Qoologic.n skipped
C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\7C36633B Infected: Email-Worm.Win32.Swen skipped
C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\7C61050C Infected: Email-Worm.Win32.Swen skipped
C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\7C772AF3 Infected: Email-Worm.Win32.Swen skipped
C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\7C8128E8 Infected: Email-Worm.Win32.Swen skipped
C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\7C8B26DD Infected: Email-Worm.Win32.Swen skipped
C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\7C9524D3 Infected: Email-Worm.Win32.Swen skipped
C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\7CA24CC4 Infected: Email-Worm.Win32.Swen skipped
C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\7CAC4AB9 Infected: Email-Worm.Win32.Swen skipped
C:\Documents and Settings\All Users\Application Data\Symantec\SRTSP\SrtETmp\65C41B5C.TMP Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Symantec\SRTSP\SrtETmp\65EBA84F.TMP Object is locked skipped
C:\Documents and Settings\LocalService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat Object is locked skipped

scoleson
2007-11-26, 17:16
C:\Documents and Settings\LocalService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped
C:\Documents and Settings\LocalService\NTUSER.DAT Object is locked skipped
C:\Documents and Settings\LocalService\ntuser.dat.LOG Object is locked skipped
C:\Documents and Settings\NetworkService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat Object is locked skipped
C:\Documents and Settings\NetworkService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped
C:\Documents and Settings\NetworkService\NTUSER.DAT Object is locked skipped
C:\Documents and Settings\NetworkService\ntuser.dat.LOG Object is locked skipped
C:\Documents and Settings\Steve Coleson\Local Settings\Temp\cdvyukuv.exe Infected: Trojan.Win32.Obfuscated.kp skipped
C:\Documents and Settings\Steve Coleson\Local Settings\Temp\qjvauumo.exe Infected: Trojan.Win32.Obfuscated.kp skipped
C:\Documents and Settings\Steve Coleson\Local Settings\Temp\xlcmlxsc.exe Infected: Trojan.Win32.Obfuscated.kp skipped
C:\Documents and Settings\Steve Coleson\My Documents\Attachments\carmen_5670.xls.zip/p-zipped_file_data .pif Infected: Email-Worm.Win32.Sober.g skipped
C:\Documents and Settings\Steve Coleson\My Documents\Attachments\carmen_5670.xls.zip ZIP: infected - 1 skipped
C:\Documents and Settings\Steve Coleson\My Documents\Attachments\carmen_5670.xls.zip CryptFF.b: infected - 1 skipped
C:\Documents and Settings\Steve Coleson\My Documents\Attachments\check_this-440.doc.zip/p-zipped_file_data .pif Infected: Email-Worm.Win32.Sober.g skipped
C:\Documents and Settings\Steve Coleson\My Documents\Attachments\check_this-440.doc.zip ZIP: infected - 1 skipped
C:\Documents and Settings\Steve Coleson\My Documents\Attachments\check_this-440.doc.zip CryptFF.b: infected - 1 skipped
C:\Documents and Settings\Steve Coleson\My Documents\Attachments\hotmail_3783.DOC.zip/p-zipped_file_data .pif Infected: Email-Worm.Win32.Sober.g skipped
C:\Documents and Settings\Steve Coleson\My Documents\Attachments\hotmail_3783.DOC.zip ZIP: infected - 1 skipped
C:\Documents and Settings\Steve Coleson\My Documents\Attachments\hotmail_3783.DOC.zip CryptFF.b: infected - 1 skipped
C:\Documents and Settings\Steve Coleson\My Documents\Attachments\mail.txt.zip/p-zipped_file_data .pif Infected: Email-Worm.Win32.Sober.g skipped
C:\Documents and Settings\Steve Coleson\My Documents\Attachments\mail.txt.zip ZIP: infected - 1 skipped
C:\Documents and Settings\Steve Coleson\My Documents\Attachments\mail.txt.zip CryptFF.b: infected - 1 skipped
C:\Documents and Settings\Steve Coleson\My Documents\Attachments\mail.zip/p-zipped_file_data .pif Infected: Email-Worm.Win32.Sober.g skipped
C:\Documents and Settings\Steve Coleson\My Documents\Attachments\mail.zip ZIP: infected - 1 skipped
C:\Documents and Settings\Steve Coleson\My Documents\Attachments\mail.zip CryptFF.b: infected - 1 skipped
C:\Documents and Settings\Steve Coleson\My Documents\Attachments\message.zip/message.scr Infected: Email-Worm.Win32.Mydoom.a skipped
C:\Documents and Settings\Steve Coleson\My Documents\Attachments\message.zip ZIP: infected - 1 skipped
C:\Documents and Settings\Steve Coleson\My Documents\Attachments\message.zip CryptFF.b: infected - 1 skipped
C:\Documents and Settings\Steve Coleson\My Documents\Attachments\photo-7907.zip/p-zipped_file_data .pif Infected: Email-Worm.Win32.Sober.g skipped
C:\Documents and Settings\Steve Coleson\My Documents\Attachments\photo-7907.zip ZIP: infected - 1 skipped
C:\Documents and Settings\Steve Coleson\My Documents\Attachments\photo-7907.zip CryptFF.b: infected - 1 skipped
C:\Documents and Settings\Steve Coleson\My Documents\Attachments\photo_209.zip/p-zipped_file_data .pif Infected: Email-Worm.Win32.Sober.g skipped
C:\Documents and Settings\Steve Coleson\My Documents\Attachments\photo_209.zip ZIP: infected - 1 skipped
C:\Documents and Settings\Steve Coleson\My Documents\Attachments\photo_209.zip CryptFF.b: infected - 1 skipped
C:\Documents and Settings\Steve Coleson\My Documents\Attachments\photo_9178.zip/p-zipped_file_data .pif Infected: Email-Worm.Win32.Sober.g skipped
C:\Documents and Settings\Steve Coleson\My Documents\Attachments\photo_9178.zip ZIP: infected - 1 skipped
C:\Documents and Settings\Steve Coleson\My Documents\Attachments\photo_9178.zip CryptFF.b: infected - 1 skipped
C:\Documents and Settings\Steve Coleson\My Documents\Attachments\p_message-2272.word.zip/p-zipped_file_data .pif Infected: Email-Worm.Win32.Sober.g skipped
C:\Documents and Settings\Steve Coleson\My Documents\Attachments\p_message-2272.word.zip ZIP: infected - 1 skipped
C:\Documents and Settings\Steve Coleson\My Documents\Attachments\p_message-2272.word.zip CryptFF.b: infected - 1 skipped
C:\Documents and Settings\Steve Coleson\My Documents\Attachments\p_message_4574.txt.zip/p-zipped_file_data .pif Infected: Email-Worm.Win32.Sober.g skipped
C:\Documents and Settings\Steve Coleson\My Documents\Attachments\p_message_4574.txt.zip ZIP: infected - 1 skipped
C:\Documents and Settings\Steve Coleson\My Documents\Attachments\p_message_4574.txt.zip CryptFF.b: infected - 1 skipped
C:\Documents and Settings\Steve Coleson\My Documents\Attachments\ReMailer.zip/p-zipped_file_data .pif Infected: Email-Worm.Win32.Sober.g skipped
C:\Documents and Settings\Steve Coleson\My Documents\Attachments\ReMailer.zip ZIP: infected - 1 skipped
C:\Documents and Settings\Steve Coleson\My Documents\Attachments\ReMailer.zip CryptFF.b: infected - 1 skipped
C:\Documents and Settings\Steve Coleson\My Documents\Attachments\shock5393.zip/p-zipped_file_data .pif Infected: Email-Worm.Win32.Sober.g skipped
C:\Documents and Settings\Steve Coleson\My Documents\Attachments\shock5393.zip ZIP: infected - 1 skipped
C:\Documents and Settings\Steve Coleson\My Documents\Attachments\shock5393.zip CryptFF.b: infected - 1 skipped
C:\Documents and Settings\Steve Coleson\My Documents\Attachments\stuff.zip/p-zipped_file_data .pif Infected: Email-Worm.Win32.Sober.g skipped
C:\Documents and Settings\Steve Coleson\My Documents\Attachments\stuff.zip ZIP: infected - 1 skipped
C:\Documents and Settings\Steve Coleson\My Documents\Attachments\stuff.zip CryptFF.b: infected - 1 skipped
C:\Documents and Settings\Steve Coleson\My Documents\Attachments\stuff1.zip/p-zipped_file_data .pif Infected: Email-Worm.Win32.Sober.g skipped
C:\Documents and Settings\Steve Coleson\My Documents\Attachments\stuff1.zip ZIP: infected - 1 skipped
C:\Documents and Settings\Steve Coleson\My Documents\Attachments\stuff1.zip CryptFF.b: infected - 1 skipped
C:\Documents and Settings\Steve Coleson\My Documents\Attachments\stuff6875.zip/p-zipped_file_data .pif Infected: Email-Worm.Win32.Sober.g skipped
C:\Documents and Settings\Steve Coleson\My Documents\Attachments\stuff6875.zip ZIP: infected - 1 skipped
C:\Documents and Settings\Steve Coleson\My Documents\Attachments\stuff6875.zip CryptFF.b: infected - 1 skipped
C:\Program Files\Gateway\EzTune\GWY\common\pdi_globals_tmp.js Object is locked skipped
C:\System Volume Information\MountPointManagerRemoteDatabase Object is locked skipped
C:\WINDOWS\$NtUninstallKB828741$\catsrv.dll Object is locked skipped
C:\WINDOWS\$NtUninstallKB828741$\catsrvut.dll Object is locked skipped
C:\WINDOWS\$NtUninstallKB828741$\clbcatex.dll Object is locked skipped
C:\WINDOWS\$NtUninstallKB828741$\clbcatq.dll Object is locked skipped
C:\WINDOWS\$NtUninstallKB828741$\colbact.dll Object is locked skipped
C:\WINDOWS\$NtUninstallKB828741$\comadmin.dll Object is locked skipped
C:\WINDOWS\$NtUninstallKB828741$\comrepl.exe Object is locked skipped
C:\WINDOWS\$NtUninstallKB828741$\comsvcs.dll Object is locked skipped
C:\WINDOWS\$NtUninstallKB828741$\comuid.dll Object is locked skipped
C:\WINDOWS\$NtUninstallKB828741$\es.dll Object is locked skipped
C:\WINDOWS\$NtUninstallKB828741$\migregdb.exe Object is locked skipped
C:\WINDOWS\$NtUninstallKB828741$\msdtcprx.dll Object is locked skipped
C:\WINDOWS\$NtUninstallKB828741$\msdtctm.dll Object is locked skipped
C:\WINDOWS\$NtUninstallKB828741$\msdtcuiu.dll Object is locked skipped
C:\WINDOWS\$NtUninstallKB828741$\mtxclu.dll Object is locked skipped
C:\WINDOWS\$NtUninstallKB828741$\mtxoci.dll Object is locked skipped
C:\WINDOWS\$NtUninstallKB828741$\ole32.dll Object is locked skipped
C:\WINDOWS\$NtUninstallKB828741$\rpcrt4.dll Object is locked skipped
C:\WINDOWS\$NtUninstallKB828741$\rpcss.dll Object is locked skipped
C:\WINDOWS\$NtUninstallKB828741$\txflog.dll Object is locked skipped
C:\WINDOWS\$NtUninstallKB835732$\browser.dll Object is locked skipped
C:\WINDOWS\$NtUninstallKB835732$\callcont.dll Object is locked skipped
C:\WINDOWS\$NtUninstallKB835732$\gdi32.dll Object is locked skipped
C:\WINDOWS\$NtUninstallKB835732$\h323.tsp Object is locked skipped
C:\WINDOWS\$NtUninstallKB835732$\h323msp.dll Object is locked skipped
C:\WINDOWS\$NtUninstallKB835732$\helpctr.exe Object is locked skipped
C:\WINDOWS\$NtUninstallKB835732$\ipnathlp.dll Object is locked skipped
C:\WINDOWS\$NtUninstallKB835732$\lsasrv.dll Object is locked skipped
C:\WINDOWS\$NtUninstallKB835732$\mf3216.dll Object is locked skipped
C:\WINDOWS\$NtUninstallKB835732$\msasn1.dll Object is locked skipped
C:\WINDOWS\$NtUninstallKB835732$\msgina.dll Object is locked skipped
C:\WINDOWS\$NtUninstallKB835732$\mst120.dll Object is locked skipped
C:\WINDOWS\$NtUninstallKB835732$\netapi32.dll Object is locked skipped
C:\WINDOWS\$NtUninstallKB835732$\nmcom.dll Object is locked skipped
C:\WINDOWS\$NtUninstallKB835732$\rtcdll.dll Object is locked skipped
C:\WINDOWS\$NtUninstallKB835732$\schannel.dll Object is locked skipped
C:\WINDOWS\$NtUninstallQ329048$\reg00002 Object is locked skipped
C:\WINDOWS\$NtUninstallQ329115$\reg00002 Object is locked skipped
C:\WINDOWS\$NtUninstallQ329115$\reg00003 Object is locked skipped
C:\WINDOWS\$NtUninstallQ329390$\reg00002 Object is locked skipped
C:\WINDOWS\Debug\PASSWD.LOG Object is locked skipped
C:\WINDOWS\system32\CatRoot2\edb.log Object is locked skipped
C:\WINDOWS\system32\CatRoot2\tmp.edb Object is locked skipped
C:\WINDOWS\system32\config\AppEvent.Evt Object is locked skipped
C:\WINDOWS\system32\config\default Object is locked skipped
C:\WINDOWS\system32\config\default.LOG Object is locked skipped
C:\WINDOWS\system32\config\Internet.evt Object is locked skipped
C:\WINDOWS\system32\config\ODiag.evt Object is locked skipped
C:\WINDOWS\system32\config\OSession.evt Object is locked skipped
C:\WINDOWS\system32\config\SAM Object is locked skipped
C:\WINDOWS\system32\config\SAM.LOG Object is locked skipped
C:\WINDOWS\system32\config\SecEvent.Evt Object is locked skipped
C:\WINDOWS\system32\config\SECURITY Object is locked skipped
C:\WINDOWS\system32\config\SECURITY.LOG Object is locked skipped
C:\WINDOWS\system32\config\software Object is locked skipped
C:\WINDOWS\system32\config\software.LOG Object is locked skipped
C:\WINDOWS\system32\config\SysEvent.Evt Object is locked skipped
C:\WINDOWS\system32\config\system Object is locked skipped
C:\WINDOWS\system32\config\system.LOG Object is locked skipped
C:\WINDOWS\system32\drivers\sptd.sys Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\INDEX.BTR Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\INDEX.MAP Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\MAPPING.VER Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\MAPPING1.MAP Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\MAPPING2.MAP Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\OBJECTS.DATA Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\OBJECTS.MAP Object is locked skipped
D:\System Volume Information\MountPointManagerRemoteDatabase Object is locked skipped
D:\System Volume Information\_restore{A3CFA17A-33D3-481A-905E-2CC2F7EABEEB}\RP34\A0014835.ver Object is locked skipped
D:\System Volume Information\_restore{A3CFA17A-33D3-481A-905E-2CC2F7EABEEB}\RP34\A0014836.inf Object is locked skipped
D:\System Volume Information\_restore{A3CFA17A-33D3-481A-905E-2CC2F7EABEEB}\RP34\A0014837.exe Object is locked skipped
D:\System Volume Information\_restore{A3CFA17A-33D3-481A-905E-2CC2F7EABEEB}\RP34\A0014838.dll Object is locked skipped
D:\System Volume Information\_restore{A3CFA17A-33D3-481A-905E-2CC2F7EABEEB}\RP34\A0014839.cat Object is locked skipped
D:\System Volume Information\_restore{A3CFA17A-33D3-481A-905E-2CC2F7EABEEB}\RP34\A0014840.sys Object is locked skipped
D:\System Volume Information\_restore{A3CFA17A-33D3-481A-905E-2CC2F7EABEEB}\RP34\A0014841.exe Object is locked skipped
D:\System Volume Information\_restore{A3CFA17A-33D3-481A-905E-2CC2F7EABEEB}\RP34\A0014842.dll Object is locked skipped
D:\System Volume Information\_restore{A3CFA17A-33D3-481A-905E-2CC2F7EABEEB}\RP4\A0002124.dll Object is locked skipped
D:\System Volume Information\_restore{A3CFA17A-33D3-481A-905E-2CC2F7EABEEB}\RP4\A0002125.exe Object is locked skipped
D:\System Volume Information\_restore{A3CFA17A-33D3-481A-905E-2CC2F7EABEEB}\RP4\A0002126.sys Object is locked skipped
D:\System Volume Information\_restore{A3CFA17A-33D3-481A-905E-2CC2F7EABEEB}\RP4\A0002127.cat Object is locked skipped
D:\System Volume Information\_restore{A3CFA17A-33D3-481A-905E-2CC2F7EABEEB}\RP4\A0002128.inf Object is locked skipped
D:\System Volume Information\_restore{A3CFA17A-33D3-481A-905E-2CC2F7EABEEB}\RP4\A0002129.ver Object is locked skipped
D:\System Volume Information\_restore{A3CFA17A-33D3-481A-905E-2CC2F7EABEEB}\RP4\A0002130.exe Object is locked skipped
D:\System Volume Information\_restore{A3CFA17A-33D3-481A-905E-2CC2F7EABEEB}\RP4\A0002131.dll Object is locked skipped
D:\System Volume Information\_restore{A3CFA17A-33D3-481A-905E-2CC2F7EABEEB}\RP5\A0002210.dll Object is locked skipped
D:\System Volume Information\_restore{A3CFA17A-33D3-481A-905E-2CC2F7EABEEB}\RP5\A0002211.exe Object is locked skipped
D:\System Volume Information\_restore{A3CFA17A-33D3-481A-905E-2CC2F7EABEEB}\RP5\A0002212.cat Object is locked skipped
D:\System Volume Information\_restore{A3CFA17A-33D3-481A-905E-2CC2F7EABEEB}\RP5\A0002213.inf Object is locked skipped
D:\System Volume Information\_restore{A3CFA17A-33D3-481A-905E-2CC2F7EABEEB}\RP5\A0002214.ver Object is locked skipped
D:\System Volume Information\_restore{A3CFA17A-33D3-481A-905E-2CC2F7EABEEB}\RP5\A0002215.dll Object is locked skipped
D:\System Volume Information\_restore{A3CFA17A-33D3-481A-905E-2CC2F7EABEEB}\RP5\A0002216.sys Object is locked skipped
D:\System Volume Information\_restore{A3CFA17A-33D3-481A-905E-2CC2F7EABEEB}\RP5\A0002217.dll Object is locked skipped
D:\System Volume Information\_restore{A3CFA17A-33D3-481A-905E-2CC2F7EABEEB}\RP5\A0002218.dll Object is locked skipped
D:\System Volume Information\_restore{A3CFA17A-33D3-481A-905E-2CC2F7EABEEB}\RP5\A0002219.exe Object is locked skipped
D:\System Volume Information\_restore{A3CFA17A-33D3-481A-905E-2CC2F7EABEEB}\RP5\A0002220.dll Object is locked skipped
D:\System Volume Information\_restore{A3CFA17A-33D3-481A-905E-2CC2F7EABEEB}\RP5\A0002221.exe Object is locked skipped
D:\System Volume Information\_restore{A3CFA17A-33D3-481A-905E-2CC2F7EABEEB}\RP5\A0002222.dll Object is locked skipped
D:\System Volume Information\_restore{A3CFA17A-33D3-481A-905E-2CC2F7EABEEB}\RP5\A0002223.exe Object is locked skipped
D:\System Volume Information\_restore{A3CFA17A-33D3-481A-905E-2CC2F7EABEEB}\RP5\A0002224.ver Object is locked skipped
D:\System Volume Information\_restore{A3CFA17A-33D3-481A-905E-2CC2F7EABEEB}\RP5\A0002225.inf Object is locked skipped
D:\System Volume Information\_restore{A3CFA17A-33D3-481A-905E-2CC2F7EABEEB}\RP5\A0002226.cat Object is locked skipped
D:\System Volume Information\_restore{A3CFA17A-33D3-481A-905E-2CC2F7EABEEB}\RP5\A0002227.sys Object is locked skipped
D:\System Volume Information\_restore{A3CFA17A-33D3-481A-905E-2CC2F7EABEEB}\RP5\A0002228.dll Object is locked skipped
D:\System Volume Information\_restore{A3CFA17A-33D3-481A-905E-2CC2F7EABEEB}\RP5\A0002229.dll Object is locked skipped
D:\System Volume Information\_restore{A3CFA17A-33D3-481A-905E-2CC2F7EABEEB}\RP5\A0002230.exe Object is locked skipped
D:\System Volume Information\_restore{A3CFA17A-33D3-481A-905E-2CC2F7EABEEB}\RP5\A0002231.exe Object is locked skipped
D:\System Volume Information\_restore{A3CFA17A-33D3-481A-905E-2CC2F7EABEEB}\RP5\A0002232.dll Object is locked skipped
D:\System Volume Information\_restore{A3CFA17A-33D3-481A-905E-2CC2F7EABEEB}\RP5\A0002233.dll Object is locked skipped
D:\System Volume Information\_restore{A3CFA17A-33D3-481A-905E-2CC2F7EABEEB}\RP5\A0002234.exe Object is locked skipped

Scan process completed.