KevinSartori
2007-12-31, 20:29
Hello. Could someone here help me with the removal of Vitrumonde/Vondu? I've tried two different removal tools and have tried Spyware Doctor, SuperAntiSpyware and Ad-Aware. They keep coming back. I have in my windows/system32 folder:
jkklm.exe, jkklm.dll, mlkkj.ini and mlkkj.ini2
I've just discovered Spybot and this forum. I'm following the directions in the "BEFORE you POST" thread.
First I ran Kaspersky Online Scanner:
-------------------------------------------------------------------------------
KASPERSKY ONLINE SCANNER REPORT
Monday, December 31, 2007 12:12:49 PM
Operating System: Microsoft Windows Vista Home Edition, (Build 6000)
Kaspersky Online Scanner version: 5.0.98.0
Kaspersky Anti-Virus database last update: 31/12/2007
Kaspersky Anti-Virus database records: 500758
-------------------------------------------------------------------------------
Scan Settings:
Scan using the following antivirus database: extended
Scan Archives: true
Scan Mail Bases: true
Scan Target - My Computer:
A:\
C:\
D:\
E:\
Scan Statistics:
Total number of scanned objects: 129492
Number of viruses found: 3
Number of infected objects: 25
Number of suspicious objects: 0
Duration of the scan process: 01:19:26
Infected Object Name / Virus Name / Last Action
C:\Boot\BCD Object is locked skipped
C:\Boot\BCD.LOG Object is locked skipped
C:\Program Files\Adobe\Photoshop Album Starter Edition\3.2\Apps\apdproxy.exe Infected: Trojan-Dropper.Win32.Agent.dgo skipped
C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe Infected: Trojan-Dropper.Win32.Agent.dgo skipped
C:\Program Files\Alwil Software\Avast4\ashDisp.exe Infected: Trojan-Dropper.Win32.Agent.dgo skipped
C:\Program Files\Alwil Software\Avast4\DATA\aswResp.dat Object is locked skipped
C:\Program Files\Alwil Software\Avast4\DATA\Avast4.db Object is locked skipped
C:\Program Files\Alwil Software\Avast4\DATA\integ\avast.int Object is locked skipped
C:\Program Files\Alwil Software\Avast4\DATA\log\AshWebSv.ws Object is locked skipped
C:\Program Files\Alwil Software\Avast4\DATA\log\aswMaiSv.log Object is locked skipped
C:\Program Files\Alwil Software\Avast4\DATA\log\nshield.log Object is locked skipped
C:\Program Files\Alwil Software\Avast4\DATA\report\Resident protection.txt Object is locked skipped
C:\Program Files\Common Files\Ahead\Lib\NeroCheck.exe Infected: Trojan-Dropper.Win32.Agent.dgo skipped
C:\Program Files\Common Files\Ahead\Lib\NMBgMonitor.exe Infected: Trojan-Dropper.Win32.Agent.dgo skipped
C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe Infected: Trojan-Dropper.Win32.Agent.dgo skipped
C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe Infected: Trojan-Dropper.Win32.Agent.dgo skipped
C:\Program Files\Microsoft IntelliType Pro\itype.exe Infected: Trojan-Dropper.Win32.Agent.dgo skipped
C:\Program Files\NVIDIA Corporation\nTune\nTuneCmd.exe Infected: Trojan-Dropper.Win32.Agent.dgo skipped
C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe Infected: Trojan-Dropper.Win32.Agent.dgo skipped
C:\Program Files\TVersity\Media Server\db\medialib.db Object is locked skipped
C:\Program Files\WinDates\events.wdt Object is locked skipped
C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\7740f4002c34e2f57cd35144980da23d_c6b78850-fb05-4b44-a282-edcb5ed62801 Object is locked skipped
C:\ProgramData\Microsoft\Network\Downloader\qmgr0.dat Object is locked skipped
C:\ProgramData\Microsoft\Network\Downloader\qmgr1.dat Object is locked skipped
C:\ProgramData\Microsoft\Search\Data\Applications\Windows\GatherLogs\SystemIndex\SystemIndex.136.Crwl Object is locked skipped
C:\ProgramData\Microsoft\Search\Data\Applications\Windows\GatherLogs\SystemIndex\SystemIndex.136.gthr Object is locked skipped
C:\ProgramData\Microsoft\Search\Data\Applications\Windows\MSS.log Object is locked skipped
C:\ProgramData\Microsoft\Search\Data\Applications\Windows\MSStmp.log Object is locked skipped
C:\ProgramData\Microsoft\Search\Data\Applications\Windows\Projects\SystemIndex\Indexer\CiFiles\00010001.wid Object is locked skipped
C:\ProgramData\Microsoft\Search\Data\Applications\Windows\Projects\SystemIndex\Indexer\CiFiles\00010002.wid Object is locked skipped
C:\ProgramData\Microsoft\Search\Data\Applications\Windows\Projects\SystemIndex\Indexer\CiFiles\00010003.wid Object is locked skipped
C:\ProgramData\Microsoft\Search\Data\Applications\Windows\Projects\SystemIndex\Indexer\CiFiles\00010004.wid Object is locked skipped
C:\ProgramData\Microsoft\Search\Data\Applications\Windows\Projects\SystemIndex\Indexer\CiFiles\00010005.wid Object is locked skipped
C:\ProgramData\Microsoft\Search\Data\Applications\Windows\Projects\SystemIndex\Indexer\CiFiles\00010006.ci Object is locked skipped
C:\ProgramData\Microsoft\Search\Data\Applications\Windows\Projects\SystemIndex\Indexer\CiFiles\00010006.wid Object is locked skipped
C:\ProgramData\Microsoft\Search\Data\Applications\Windows\Projects\SystemIndex\Indexer\CiFiles\00010006.wsb Object is locked skipped
C:\ProgramData\Microsoft\Search\Data\Applications\Windows\Projects\SystemIndex\Indexer\CiFiles\00010007.wid Object is locked skipped
C:\ProgramData\Microsoft\Search\Data\Applications\Windows\Projects\SystemIndex\Indexer\CiFiles\00010008.wid Object is locked skipped
C:\ProgramData\Microsoft\Search\Data\Applications\Windows\Projects\SystemIndex\Indexer\CiFiles\00010009.wid Object is locked skipped
C:\ProgramData\Microsoft\Search\Data\Applications\Windows\Projects\SystemIndex\Indexer\CiFiles\0001000A.wid Object is locked skipped
C:\ProgramData\Microsoft\Search\Data\Applications\Windows\Projects\SystemIndex\Indexer\CiFiles\0001000B.wid Object is locked skipped
C:\ProgramData\Microsoft\Search\Data\Applications\Windows\Projects\SystemIndex\Indexer\CiFiles\0001001C.wid Object is locked skipped
C:\ProgramData\Microsoft\Search\Data\Applications\Windows\Projects\SystemIndex\Indexer\CiFiles\0001001F.wid Object is locked skipped
C:\ProgramData\Microsoft\Search\Data\Applications\Windows\Projects\SystemIndex\Indexer\CiFiles\00010037.wid Object is locked skipped
C:\ProgramData\Microsoft\Search\Data\Applications\Windows\Projects\SystemIndex\Indexer\CiFiles\INDEX.000 Object is locked skipped
C:\ProgramData\Microsoft\Search\Data\Applications\Windows\Projects\SystemIndex\PropMap\CiPT0000.000 Object is locked skipped
C:\ProgramData\Microsoft\Search\Data\Applications\Windows\Projects\SystemIndex\PropMap\Used0000.000 Object is locked skipped
C:\ProgramData\Microsoft\Search\Data\Applications\Windows\Projects\SystemIndex\SecStore\CiST0000.000 Object is locked skipped
C:\ProgramData\Microsoft\Search\Data\Applications\Windows\Projects\SystemIndex\SystemIndex.chk1.gthr Object is locked skipped
C:\ProgramData\Microsoft\Search\Data\Applications\Windows\Projects\SystemIndex\SystemIndex.chk2.gthr Object is locked skipped
C:\ProgramData\Microsoft\Search\Data\Applications\Windows\Projects\SystemIndex\SystemIndex.Ntfy495.gthr Object is locked skipped
C:\ProgramData\Microsoft\Search\Data\Applications\Windows\tmp.edb Object is locked skipped
C:\ProgramData\Microsoft\Search\Data\Applications\Windows\Windows.edb Object is locked skipped
C:\ProgramData\Microsoft\Search\Data\Temp\usgthrsvc\Ntf2FB6.tmp Object is locked skipped
C:\ProgramData\Microsoft\Search\Data\Temp\usgthrsvc\Ntf2FB7.tmp Object is locked skipped
C:\ProgramData\Microsoft\Windows Defender\Support\MPLog-11022006-050241.log Object is locked skipped
C:\Users\Kevin Sartori\AppData\Local\Microsoft\Feeds Cache\index.dat Object is locked skipped
C:\Users\Kevin Sartori\AppData\Local\Microsoft\Internet Explorer\MSIMGSIZ.DAT Object is locked skipped
C:\Users\Kevin Sartori\AppData\Local\Microsoft\Windows\Explorer\thumbcache_1024.db Object is locked skipped
C:\Users\Kevin Sartori\AppData\Local\Microsoft\Windows\Explorer\thumbcache_256.db Object is locked skipped
C:\Users\Kevin Sartori\AppData\Local\Microsoft\Windows\Explorer\thumbcache_32.db Object is locked skipped
C:\Users\Kevin Sartori\AppData\Local\Microsoft\Windows\Explorer\thumbcache_96.db Object is locked skipped
C:\Users\Kevin Sartori\AppData\Local\Microsoft\Windows\Explorer\thumbcache_idx.db Object is locked skipped
C:\Users\Kevin Sartori\AppData\Local\Microsoft\Windows\Explorer\thumbcache_sr.db Object is locked skipped
C:\Users\Kevin Sartori\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat Object is locked skipped
C:\Users\Kevin Sartori\AppData\Local\Microsoft\Windows\History\History.IE5\MSHist012007123120080101\index.dat Object is locked skipped
C:\Users\Kevin Sartori\AppData\Local\Microsoft\Windows\Temporary Internet Files\AntiPhishing\B3BB5BBA-E7D5-40AB-A041-A5B1C0B26C8F.dat Object is locked skipped
C:\Users\Kevin Sartori\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat Object is locked skipped
C:\Users\Kevin Sartori\AppData\Local\Microsoft\Windows\UsrClass.dat Object is locked skipped
C:\Users\Kevin Sartori\AppData\Local\Microsoft\Windows\UsrClass.dat.LOG1 Object is locked skipped
C:\Users\Kevin Sartori\AppData\Local\Microsoft\Windows\UsrClass.dat.LOG2 Object is locked skipped
C:\Users\Kevin Sartori\AppData\Local\Microsoft\Windows\UsrClass.dat{3f61732d-4c5e-11dc-bade-001558a4b04a}.TM.blf Object is locked skipped
C:\Users\Kevin Sartori\AppData\Local\Microsoft\Windows\UsrClass.dat{3f61732d-4c5e-11dc-bade-001558a4b04a}.TMContainer00000000000000000001.regtrans-ms Object is locked skipped
C:\Users\Kevin Sartori\AppData\Local\Microsoft\Windows\UsrClass.dat{3f61732d-4c5e-11dc-bade-001558a4b04a}.TMContainer00000000000000000002.regtrans-ms Object is locked skipped
C:\Users\Kevin Sartori\AppData\Local\Microsoft\Windows Defender\FileTracker\{C15323E8-5C0E-4197-85F3-6D1BDF368889} Object is locked skipped
C:\Users\Kevin Sartori\AppData\Local\Microsoft\Windows Sidebar\Settings.ini Object is locked skipped
C:\Users\Kevin Sartori\AppData\Local\Temp\rd9684.tmp\rd981B.tmp Object is locked skipped
C:\Users\Kevin Sartori\AppData\Local\Temp\tmp00007d97 Infected: not-a-virus:AdWare.Win32.Virtumonde.clc skipped
C:\Users\Kevin Sartori\AppData\Local\Temp\tmp00007f4c Infected: not-a-virus:AdWare.Win32.Virtumonde.clc skipped
C:\Users\Kevin Sartori\AppData\Local\Temp\tmp00007fd9 Infected: not-a-virus:AdWare.Win32.Virtumonde.clc skipped
C:\Users\Kevin Sartori\AppData\Local\Temp\tmp00008371 Infected: not-a-virus:AdWare.Win32.Virtumonde.clc skipped
C:\Users\Kevin Sartori\AppData\Local\Temp\tmp00008989 Infected: not-a-virus:AdWare.Win32.Virtumonde.clc skipped
C:\Users\Kevin Sartori\AppData\Local\Temp\tmp000090aa Infected: not-a-virus:AdWare.Win32.Virtumonde.clc skipped
C:\Users\Kevin Sartori\AppData\Local\Temp\tmp000093a7 Infected: not-a-virus:AdWare.Win32.Virtumonde.clc skipped
C:\Users\Kevin Sartori\AppData\Local\Temp\tmp00009e9f Infected: not-a-virus:AdWare.Win32.Virtumonde.clc skipped
C:\Users\Kevin Sartori\AppData\Local\Temp\tmp0000a746 Infected: not-a-virus:AdWare.Win32.Virtumonde.clc skipped
C:\Users\Kevin Sartori\AppData\Local\Temp\tmp0000bd65 Infected: not-a-virus:AdWare.Win32.Virtumonde.clc skipped
C:\Users\Kevin Sartori\AppData\Local\Temp\tmp0000c12c Infected: not-a-virus:AdWare.Win32.Virtumonde.clc skipped
C:\Users\Kevin Sartori\AppData\Local\Temp\~DF9A71.tmp Object is locked skipped
C:\Users\Kevin Sartori\AppData\Local\Temp\~DF9AA2.tmp Object is locked skipped
C:\Users\Kevin Sartori\AppData\Roaming\Microsoft\Windows\Cookies\index.dat Object is locked skipped
C:\Users\Kevin Sartori\AppData\Roaming\NewsLeecher\cacheV3\download\!!default!!.nc2 Object is locked skipped
C:\Users\Kevin Sartori\AppData\Roaming\NewsLeecher\cacheV3\search\!!default!!.nc2 Object is locked skipped
C:\Users\Kevin Sartori\AppData\Roaming\NewsLeecher\cacheV3\supersearch\!!default!!.nc2 Object is locked skipped
C:\Users\Kevin Sartori\NTUSER.DAT Object is locked skipped
C:\Users\Kevin Sartori\ntuser.dat.LOG1 Object is locked skipped
C:\Users\Kevin Sartori\ntuser.dat.LOG2 Object is locked skipped
C:\Users\Kevin Sartori\NTUSER.DAT{3a539871-6a70-11db-887c-d362bd253390}.TM.blf Object is locked skipped
C:\Users\Kevin Sartori\NTUSER.DAT{3a539871-6a70-11db-887c-d362bd253390}.TMContainer00000000000000000001.regtrans-ms Object is locked skipped
C:\Users\Kevin Sartori\NTUSER.DAT{3a539871-6a70-11db-887c-d362bd253390}.TMContainer00000000000000000002.regtrans-ms Object is locked skipped
C:\Windows\Debug\PASSWD.LOG Object is locked skipped
C:\Windows\Debug\sam.log Object is locked skipped
C:\Windows\Debug\WIA\wiatrace.log Object is locked skipped
C:\Windows\ServiceProfiles\LocalService\AppData\Local\lastalive0.dat Object is locked skipped
C:\Windows\ServiceProfiles\LocalService\AppData\Local\lastalive1.dat Object is locked skipped
C:\Windows\ServiceProfiles\LocalService\AppData\Local\Microsoft\Windows\WindowsUpdate.log Object is locked skipped
C:\Windows\ServiceProfiles\LocalService\NTUSER.DAT Object is locked skipped
C:\Windows\ServiceProfiles\LocalService\ntuser.dat.LOG1 Object is locked skipped
C:\Windows\ServiceProfiles\LocalService\ntuser.dat.LOG2 Object is locked skipped
C:\Windows\ServiceProfiles\LocalService\NTUSER.DAT{3a539869-6a70-11db-887c-d362bd253390}.TM.blf Object is locked skipped
C:\Windows\ServiceProfiles\LocalService\NTUSER.DAT{3a539869-6a70-11db-887c-d362bd253390}.TMContainer00000000000000000001.regtrans-ms Object is locked skipped
C:\Windows\ServiceProfiles\LocalService\NTUSER.DAT{3a539869-6a70-11db-887c-d362bd253390}.TMContainer00000000000000000002.regtrans-ms Object is locked skipped
C:\Windows\ServiceProfiles\NetworkService\NTUSER.DAT Object is locked skipped
C:\Windows\ServiceProfiles\NetworkService\ntuser.dat.LOG1 Object is locked skipped
C:\Windows\ServiceProfiles\NetworkService\ntuser.dat.LOG2 Object is locked skipped
C:\Windows\ServiceProfiles\NetworkService\NTUSER.DAT{3a539865-6a70-11db-887c-d362bd253390}.TM.blf Object is locked skipped
C:\Windows\ServiceProfiles\NetworkService\NTUSER.DAT{3a539865-6a70-11db-887c-d362bd253390}.TMContainer00000000000000000001.regtrans-ms Object is locked skipped
C:\Windows\ServiceProfiles\NetworkService\NTUSER.DAT{3a539865-6a70-11db-887c-d362bd253390}.TMContainer00000000000000000002.regtrans-ms Object is locked skipped
C:\Windows\SoftwareDistribution\EventCache\{B2AF08B8-DC43-466C-9232-6E8DFF96E293}.bin Object is locked skipped
C:\Windows\SoftwareDistribution\ReportingEvents.log Object is locked skipped
jkklm.exe, jkklm.dll, mlkkj.ini and mlkkj.ini2
I've just discovered Spybot and this forum. I'm following the directions in the "BEFORE you POST" thread.
First I ran Kaspersky Online Scanner:
-------------------------------------------------------------------------------
KASPERSKY ONLINE SCANNER REPORT
Monday, December 31, 2007 12:12:49 PM
Operating System: Microsoft Windows Vista Home Edition, (Build 6000)
Kaspersky Online Scanner version: 5.0.98.0
Kaspersky Anti-Virus database last update: 31/12/2007
Kaspersky Anti-Virus database records: 500758
-------------------------------------------------------------------------------
Scan Settings:
Scan using the following antivirus database: extended
Scan Archives: true
Scan Mail Bases: true
Scan Target - My Computer:
A:\
C:\
D:\
E:\
Scan Statistics:
Total number of scanned objects: 129492
Number of viruses found: 3
Number of infected objects: 25
Number of suspicious objects: 0
Duration of the scan process: 01:19:26
Infected Object Name / Virus Name / Last Action
C:\Boot\BCD Object is locked skipped
C:\Boot\BCD.LOG Object is locked skipped
C:\Program Files\Adobe\Photoshop Album Starter Edition\3.2\Apps\apdproxy.exe Infected: Trojan-Dropper.Win32.Agent.dgo skipped
C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe Infected: Trojan-Dropper.Win32.Agent.dgo skipped
C:\Program Files\Alwil Software\Avast4\ashDisp.exe Infected: Trojan-Dropper.Win32.Agent.dgo skipped
C:\Program Files\Alwil Software\Avast4\DATA\aswResp.dat Object is locked skipped
C:\Program Files\Alwil Software\Avast4\DATA\Avast4.db Object is locked skipped
C:\Program Files\Alwil Software\Avast4\DATA\integ\avast.int Object is locked skipped
C:\Program Files\Alwil Software\Avast4\DATA\log\AshWebSv.ws Object is locked skipped
C:\Program Files\Alwil Software\Avast4\DATA\log\aswMaiSv.log Object is locked skipped
C:\Program Files\Alwil Software\Avast4\DATA\log\nshield.log Object is locked skipped
C:\Program Files\Alwil Software\Avast4\DATA\report\Resident protection.txt Object is locked skipped
C:\Program Files\Common Files\Ahead\Lib\NeroCheck.exe Infected: Trojan-Dropper.Win32.Agent.dgo skipped
C:\Program Files\Common Files\Ahead\Lib\NMBgMonitor.exe Infected: Trojan-Dropper.Win32.Agent.dgo skipped
C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe Infected: Trojan-Dropper.Win32.Agent.dgo skipped
C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe Infected: Trojan-Dropper.Win32.Agent.dgo skipped
C:\Program Files\Microsoft IntelliType Pro\itype.exe Infected: Trojan-Dropper.Win32.Agent.dgo skipped
C:\Program Files\NVIDIA Corporation\nTune\nTuneCmd.exe Infected: Trojan-Dropper.Win32.Agent.dgo skipped
C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe Infected: Trojan-Dropper.Win32.Agent.dgo skipped
C:\Program Files\TVersity\Media Server\db\medialib.db Object is locked skipped
C:\Program Files\WinDates\events.wdt Object is locked skipped
C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\7740f4002c34e2f57cd35144980da23d_c6b78850-fb05-4b44-a282-edcb5ed62801 Object is locked skipped
C:\ProgramData\Microsoft\Network\Downloader\qmgr0.dat Object is locked skipped
C:\ProgramData\Microsoft\Network\Downloader\qmgr1.dat Object is locked skipped
C:\ProgramData\Microsoft\Search\Data\Applications\Windows\GatherLogs\SystemIndex\SystemIndex.136.Crwl Object is locked skipped
C:\ProgramData\Microsoft\Search\Data\Applications\Windows\GatherLogs\SystemIndex\SystemIndex.136.gthr Object is locked skipped
C:\ProgramData\Microsoft\Search\Data\Applications\Windows\MSS.log Object is locked skipped
C:\ProgramData\Microsoft\Search\Data\Applications\Windows\MSStmp.log Object is locked skipped
C:\ProgramData\Microsoft\Search\Data\Applications\Windows\Projects\SystemIndex\Indexer\CiFiles\00010001.wid Object is locked skipped
C:\ProgramData\Microsoft\Search\Data\Applications\Windows\Projects\SystemIndex\Indexer\CiFiles\00010002.wid Object is locked skipped
C:\ProgramData\Microsoft\Search\Data\Applications\Windows\Projects\SystemIndex\Indexer\CiFiles\00010003.wid Object is locked skipped
C:\ProgramData\Microsoft\Search\Data\Applications\Windows\Projects\SystemIndex\Indexer\CiFiles\00010004.wid Object is locked skipped
C:\ProgramData\Microsoft\Search\Data\Applications\Windows\Projects\SystemIndex\Indexer\CiFiles\00010005.wid Object is locked skipped
C:\ProgramData\Microsoft\Search\Data\Applications\Windows\Projects\SystemIndex\Indexer\CiFiles\00010006.ci Object is locked skipped
C:\ProgramData\Microsoft\Search\Data\Applications\Windows\Projects\SystemIndex\Indexer\CiFiles\00010006.wid Object is locked skipped
C:\ProgramData\Microsoft\Search\Data\Applications\Windows\Projects\SystemIndex\Indexer\CiFiles\00010006.wsb Object is locked skipped
C:\ProgramData\Microsoft\Search\Data\Applications\Windows\Projects\SystemIndex\Indexer\CiFiles\00010007.wid Object is locked skipped
C:\ProgramData\Microsoft\Search\Data\Applications\Windows\Projects\SystemIndex\Indexer\CiFiles\00010008.wid Object is locked skipped
C:\ProgramData\Microsoft\Search\Data\Applications\Windows\Projects\SystemIndex\Indexer\CiFiles\00010009.wid Object is locked skipped
C:\ProgramData\Microsoft\Search\Data\Applications\Windows\Projects\SystemIndex\Indexer\CiFiles\0001000A.wid Object is locked skipped
C:\ProgramData\Microsoft\Search\Data\Applications\Windows\Projects\SystemIndex\Indexer\CiFiles\0001000B.wid Object is locked skipped
C:\ProgramData\Microsoft\Search\Data\Applications\Windows\Projects\SystemIndex\Indexer\CiFiles\0001001C.wid Object is locked skipped
C:\ProgramData\Microsoft\Search\Data\Applications\Windows\Projects\SystemIndex\Indexer\CiFiles\0001001F.wid Object is locked skipped
C:\ProgramData\Microsoft\Search\Data\Applications\Windows\Projects\SystemIndex\Indexer\CiFiles\00010037.wid Object is locked skipped
C:\ProgramData\Microsoft\Search\Data\Applications\Windows\Projects\SystemIndex\Indexer\CiFiles\INDEX.000 Object is locked skipped
C:\ProgramData\Microsoft\Search\Data\Applications\Windows\Projects\SystemIndex\PropMap\CiPT0000.000 Object is locked skipped
C:\ProgramData\Microsoft\Search\Data\Applications\Windows\Projects\SystemIndex\PropMap\Used0000.000 Object is locked skipped
C:\ProgramData\Microsoft\Search\Data\Applications\Windows\Projects\SystemIndex\SecStore\CiST0000.000 Object is locked skipped
C:\ProgramData\Microsoft\Search\Data\Applications\Windows\Projects\SystemIndex\SystemIndex.chk1.gthr Object is locked skipped
C:\ProgramData\Microsoft\Search\Data\Applications\Windows\Projects\SystemIndex\SystemIndex.chk2.gthr Object is locked skipped
C:\ProgramData\Microsoft\Search\Data\Applications\Windows\Projects\SystemIndex\SystemIndex.Ntfy495.gthr Object is locked skipped
C:\ProgramData\Microsoft\Search\Data\Applications\Windows\tmp.edb Object is locked skipped
C:\ProgramData\Microsoft\Search\Data\Applications\Windows\Windows.edb Object is locked skipped
C:\ProgramData\Microsoft\Search\Data\Temp\usgthrsvc\Ntf2FB6.tmp Object is locked skipped
C:\ProgramData\Microsoft\Search\Data\Temp\usgthrsvc\Ntf2FB7.tmp Object is locked skipped
C:\ProgramData\Microsoft\Windows Defender\Support\MPLog-11022006-050241.log Object is locked skipped
C:\Users\Kevin Sartori\AppData\Local\Microsoft\Feeds Cache\index.dat Object is locked skipped
C:\Users\Kevin Sartori\AppData\Local\Microsoft\Internet Explorer\MSIMGSIZ.DAT Object is locked skipped
C:\Users\Kevin Sartori\AppData\Local\Microsoft\Windows\Explorer\thumbcache_1024.db Object is locked skipped
C:\Users\Kevin Sartori\AppData\Local\Microsoft\Windows\Explorer\thumbcache_256.db Object is locked skipped
C:\Users\Kevin Sartori\AppData\Local\Microsoft\Windows\Explorer\thumbcache_32.db Object is locked skipped
C:\Users\Kevin Sartori\AppData\Local\Microsoft\Windows\Explorer\thumbcache_96.db Object is locked skipped
C:\Users\Kevin Sartori\AppData\Local\Microsoft\Windows\Explorer\thumbcache_idx.db Object is locked skipped
C:\Users\Kevin Sartori\AppData\Local\Microsoft\Windows\Explorer\thumbcache_sr.db Object is locked skipped
C:\Users\Kevin Sartori\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat Object is locked skipped
C:\Users\Kevin Sartori\AppData\Local\Microsoft\Windows\History\History.IE5\MSHist012007123120080101\index.dat Object is locked skipped
C:\Users\Kevin Sartori\AppData\Local\Microsoft\Windows\Temporary Internet Files\AntiPhishing\B3BB5BBA-E7D5-40AB-A041-A5B1C0B26C8F.dat Object is locked skipped
C:\Users\Kevin Sartori\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat Object is locked skipped
C:\Users\Kevin Sartori\AppData\Local\Microsoft\Windows\UsrClass.dat Object is locked skipped
C:\Users\Kevin Sartori\AppData\Local\Microsoft\Windows\UsrClass.dat.LOG1 Object is locked skipped
C:\Users\Kevin Sartori\AppData\Local\Microsoft\Windows\UsrClass.dat.LOG2 Object is locked skipped
C:\Users\Kevin Sartori\AppData\Local\Microsoft\Windows\UsrClass.dat{3f61732d-4c5e-11dc-bade-001558a4b04a}.TM.blf Object is locked skipped
C:\Users\Kevin Sartori\AppData\Local\Microsoft\Windows\UsrClass.dat{3f61732d-4c5e-11dc-bade-001558a4b04a}.TMContainer00000000000000000001.regtrans-ms Object is locked skipped
C:\Users\Kevin Sartori\AppData\Local\Microsoft\Windows\UsrClass.dat{3f61732d-4c5e-11dc-bade-001558a4b04a}.TMContainer00000000000000000002.regtrans-ms Object is locked skipped
C:\Users\Kevin Sartori\AppData\Local\Microsoft\Windows Defender\FileTracker\{C15323E8-5C0E-4197-85F3-6D1BDF368889} Object is locked skipped
C:\Users\Kevin Sartori\AppData\Local\Microsoft\Windows Sidebar\Settings.ini Object is locked skipped
C:\Users\Kevin Sartori\AppData\Local\Temp\rd9684.tmp\rd981B.tmp Object is locked skipped
C:\Users\Kevin Sartori\AppData\Local\Temp\tmp00007d97 Infected: not-a-virus:AdWare.Win32.Virtumonde.clc skipped
C:\Users\Kevin Sartori\AppData\Local\Temp\tmp00007f4c Infected: not-a-virus:AdWare.Win32.Virtumonde.clc skipped
C:\Users\Kevin Sartori\AppData\Local\Temp\tmp00007fd9 Infected: not-a-virus:AdWare.Win32.Virtumonde.clc skipped
C:\Users\Kevin Sartori\AppData\Local\Temp\tmp00008371 Infected: not-a-virus:AdWare.Win32.Virtumonde.clc skipped
C:\Users\Kevin Sartori\AppData\Local\Temp\tmp00008989 Infected: not-a-virus:AdWare.Win32.Virtumonde.clc skipped
C:\Users\Kevin Sartori\AppData\Local\Temp\tmp000090aa Infected: not-a-virus:AdWare.Win32.Virtumonde.clc skipped
C:\Users\Kevin Sartori\AppData\Local\Temp\tmp000093a7 Infected: not-a-virus:AdWare.Win32.Virtumonde.clc skipped
C:\Users\Kevin Sartori\AppData\Local\Temp\tmp00009e9f Infected: not-a-virus:AdWare.Win32.Virtumonde.clc skipped
C:\Users\Kevin Sartori\AppData\Local\Temp\tmp0000a746 Infected: not-a-virus:AdWare.Win32.Virtumonde.clc skipped
C:\Users\Kevin Sartori\AppData\Local\Temp\tmp0000bd65 Infected: not-a-virus:AdWare.Win32.Virtumonde.clc skipped
C:\Users\Kevin Sartori\AppData\Local\Temp\tmp0000c12c Infected: not-a-virus:AdWare.Win32.Virtumonde.clc skipped
C:\Users\Kevin Sartori\AppData\Local\Temp\~DF9A71.tmp Object is locked skipped
C:\Users\Kevin Sartori\AppData\Local\Temp\~DF9AA2.tmp Object is locked skipped
C:\Users\Kevin Sartori\AppData\Roaming\Microsoft\Windows\Cookies\index.dat Object is locked skipped
C:\Users\Kevin Sartori\AppData\Roaming\NewsLeecher\cacheV3\download\!!default!!.nc2 Object is locked skipped
C:\Users\Kevin Sartori\AppData\Roaming\NewsLeecher\cacheV3\search\!!default!!.nc2 Object is locked skipped
C:\Users\Kevin Sartori\AppData\Roaming\NewsLeecher\cacheV3\supersearch\!!default!!.nc2 Object is locked skipped
C:\Users\Kevin Sartori\NTUSER.DAT Object is locked skipped
C:\Users\Kevin Sartori\ntuser.dat.LOG1 Object is locked skipped
C:\Users\Kevin Sartori\ntuser.dat.LOG2 Object is locked skipped
C:\Users\Kevin Sartori\NTUSER.DAT{3a539871-6a70-11db-887c-d362bd253390}.TM.blf Object is locked skipped
C:\Users\Kevin Sartori\NTUSER.DAT{3a539871-6a70-11db-887c-d362bd253390}.TMContainer00000000000000000001.regtrans-ms Object is locked skipped
C:\Users\Kevin Sartori\NTUSER.DAT{3a539871-6a70-11db-887c-d362bd253390}.TMContainer00000000000000000002.regtrans-ms Object is locked skipped
C:\Windows\Debug\PASSWD.LOG Object is locked skipped
C:\Windows\Debug\sam.log Object is locked skipped
C:\Windows\Debug\WIA\wiatrace.log Object is locked skipped
C:\Windows\ServiceProfiles\LocalService\AppData\Local\lastalive0.dat Object is locked skipped
C:\Windows\ServiceProfiles\LocalService\AppData\Local\lastalive1.dat Object is locked skipped
C:\Windows\ServiceProfiles\LocalService\AppData\Local\Microsoft\Windows\WindowsUpdate.log Object is locked skipped
C:\Windows\ServiceProfiles\LocalService\NTUSER.DAT Object is locked skipped
C:\Windows\ServiceProfiles\LocalService\ntuser.dat.LOG1 Object is locked skipped
C:\Windows\ServiceProfiles\LocalService\ntuser.dat.LOG2 Object is locked skipped
C:\Windows\ServiceProfiles\LocalService\NTUSER.DAT{3a539869-6a70-11db-887c-d362bd253390}.TM.blf Object is locked skipped
C:\Windows\ServiceProfiles\LocalService\NTUSER.DAT{3a539869-6a70-11db-887c-d362bd253390}.TMContainer00000000000000000001.regtrans-ms Object is locked skipped
C:\Windows\ServiceProfiles\LocalService\NTUSER.DAT{3a539869-6a70-11db-887c-d362bd253390}.TMContainer00000000000000000002.regtrans-ms Object is locked skipped
C:\Windows\ServiceProfiles\NetworkService\NTUSER.DAT Object is locked skipped
C:\Windows\ServiceProfiles\NetworkService\ntuser.dat.LOG1 Object is locked skipped
C:\Windows\ServiceProfiles\NetworkService\ntuser.dat.LOG2 Object is locked skipped
C:\Windows\ServiceProfiles\NetworkService\NTUSER.DAT{3a539865-6a70-11db-887c-d362bd253390}.TM.blf Object is locked skipped
C:\Windows\ServiceProfiles\NetworkService\NTUSER.DAT{3a539865-6a70-11db-887c-d362bd253390}.TMContainer00000000000000000001.regtrans-ms Object is locked skipped
C:\Windows\ServiceProfiles\NetworkService\NTUSER.DAT{3a539865-6a70-11db-887c-d362bd253390}.TMContainer00000000000000000002.regtrans-ms Object is locked skipped
C:\Windows\SoftwareDistribution\EventCache\{B2AF08B8-DC43-466C-9232-6E8DFF96E293}.bin Object is locked skipped
C:\Windows\SoftwareDistribution\ReportingEvents.log Object is locked skipped