PDA

View Full Version : pmnnn.dll in AppData\Local\Temp\ folder...won't leave!



gra.ham
2008-01-11, 21:20
Hi there, this is my first post here,

McAfee keeps telling me on startup that it has found and removed a trojan (pmnnn.dll) with the address in the AppData\Local\Temp\ folder. I have read online and see this is normally located in the windows directory - so not sure why mine is in C:\users\...\appdata.... folder. Everytime I start the message comes up - and I cannot delete the pmnnn.dll file.

I have dowloaded HJT and this is the log:

Logfile of Trend Micro HijackThis v2.0.0 (BETA)
Scan saved at 06:04:58, on 12/01/2008
Platform: Windows Vista (WinNT 6.00.1904)
Boot mode: Normal

Running processes:
C:\Windows\system32\Dwm.exe
C:\Windows\Explorer.EXE
C:\PROGRA~1\McAfee.com\Agent\mcagent.exe
C:\Program Files\McAfee\MPS\mpsevh.exe
C:\Windows\system32\taskeng.exe
C:\Windows\system32\wbem\unsecapp.exe
C:\Program Files\Windows Defender\MSASCui.exe
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\Program Files\Java\jre1.6.0\bin\jusched.exe
C:\Windows\sttray.exe
C:\Windows\System32\WLTRAY.EXE
C:\Program Files\ATI Technologies\ATI.ACE\CLI.EXE
C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxWatchTray9.exe
C:\Program Files\Roxio\Drag-to-Disc\DrgToDsc.exe
C:\Program Files\McAfee\MSK\mskagent.exe
C:\Program Files\QuickTime\qttask.exe
C:\Program Files\MSN Messenger\msnmsgr.exe
C:\Program Files\NewsPiper\newspiper.exe
C:\Windows\ehome\ehtray.exe
C:\Program Files\Windows Media Player\wmpnscfg.exe
C:\Windows\System32\rundll32.exe
C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
C:\Program Files\Digital Line Detect\DLG.exe
C:\Program Files\Dell\QuickSet\quickset.exe
C:\Program Files\Star Alliance Auto Update Conduit (English)\en\st_conduit_en.exe
C:\Windows\ehome\ehmsas.exe
C:\Program Files\Windows Mail\WinMail.exe
C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\CPSHelpRunner.exe
C:\Program Files\ATI Technologies\ATI.ACE\CLI.exe
C:\Program Files\ATI Technologies\ATI.ACE\CLI.exe
C:\Users\Graham\Desktop\HJT\HiJackThis_v2.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Windows\system32\DllHost.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.google.co.uk/ig/dell?hl=en&client=dell-usuk&channel=uk&ibd=5070313
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Internet Explorer provided by Dell
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
F3 - REG:win.ini: load=C:\Users\Graham\AppData\Local\Temp\pmnnn.exe
O1 - Hosts: ::1 localhost
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: Skype add-on (mastermind) - {22BF413B-C6D2-4d91-82A9-A0F997BA588C} - C:\Program Files\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll
O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - c:\Program Files\Java\jre1.6.0\bin\ssv.dll
O2 - BHO: scriptproxy - {7DB2D5A0-7241-4E79-B68D-6309F01C5231} - c:\PROGRA~1\mcafee\VIRUSS~1\scriptcl.dll
O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: Browser Address Error Redirector - {CA6319C0-31B7-401E-A518-A07C3DB8F777} - C:\Program Files\BAE\BAE.dll
O4 - HKLM\..\Run: [Windows Defender] %ProgramFiles%\Windows Defender\MSASCui.exe -hide
O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] "c:\Program Files\Java\jre1.6.0\bin\jusched.exe"
O4 - HKLM\..\Run: [ATICCC] "C:\Program Files\ATI Technologies\ATI.ACE\CLIStart.exe"
O4 - HKLM\..\Run: [SigmatelSysTrayApp] sttray.exe
O4 - HKLM\..\Run: [Broadcom Wireless Manager UI] C:\Windows\system32\WLTRAY.exe
O4 - HKLM\..\Run: [ISUSScheduler] "C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe" -start
O4 - HKLM\..\Run: [RoxWatchTray] "C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxWatchTray9.exe"
O4 - HKLM\..\Run: [RoxioDragToDisc] "C:\Program Files\Roxio\Drag-to-Disc\DrgToDsc.exe"
O4 - HKLM\..\Run: [MskAgentexe] C:\Program Files\McAfee\MSK\MskAgent.exe
O4 - HKLM\..\Run: [ECenter] c:\dell\E-Center\EULALauncher.exe
O4 - HKLM\..\Run: [OM_Monitor] C:\Program Files\OLYMPUS\OLYMPUS Master\FirstStart.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [!AVG Anti-Spyware] "C:\Users\Graham\Desktop\AVG\AVG Anti-Spyware 7.5\avgas.exe" /minimized
O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\MSN Messenger\MsnMsgr.Exe" /background
O4 - HKCU\..\Run: [Newspiper] C:\Program Files\NewsPiper\newspiper.exe
O4 - HKCU\..\Run: [OM_Monitor] C:\Program Files\OLYMPUS\OLYMPUS Master\Monitor.exe -NoStart
O4 - HKCU\..\Run: [ehTray.exe] C:\Windows\ehome\ehTray.exe
O4 - HKCU\..\Run: [WMPNSCFG] C:\Program Files\Windows Media Player\WMPNSCFG.exe
O4 - HKCU\..\Run: [cmds] rundll32.exe C:\Users\Graham\AppData\Local\Temp\pmnnn.dll,c
O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
O4 - HKUS\S-1-5-18\..\RunOnce: [DelayShred] "c:\program files\mcafee\mshr\ShrCL.EXE" /P7 /q C:\Users\Graham\AppData\Local\Temp\~DFFE9C.tmp C:\Users\Graham\AppData\Local\Temp\~DFF984.tmp C:\Users\Graham\AppData\Local\Temp\~DFF894.tmp C:\Users\Graham\AppData\Local\Temp\~DFF720.tmp C:\Users\Graham\AppData\Local\Temp\~DFDB7D.tmp C:\Users\Graham\AppData\Local\Temp\~DFCDB0.tmp C:\Users\Graham\AppData\Local\Temp\~DFCD92.tmp C:\Users\Graham\AppData\Local\Temp\~DFCC73.tmp C:\Users\Graham\AppData\Local\Temp\~DFCC64.tmp C:\Users\Graham\AppData\Local\Temp\~DFC4FB.tmp C:\Users\Graham\AppData\Local\Temp\~DFBBCD.tmp C:\Users\Graham\AppData\Local\Temp\~DFB63E.tmp C:\Users\Graham\AppData\Local\Temp\~DFB62F.tmp C:\Users\Graham\AppData\Local\Temp\~DFB46E.tmp C:\Users\Graham\AppData\Local\Temp\~DFAEF4.tmp C:\Users\Graham\AppData\Local\Temp\~DFAC35.tmp C:\Users\Graham\AppData\Local\Temp\~DFAC1F.tmp C:\Users\Graham\AppData\Local\Temp\~DFA888.tmp C:\Users\Graham\AppData\Local\Temp\~DFA59F.tmp C:\Users\Graham\AppData\Local\Temp\~DFA
O4 - HKUS\.DEFAULT\..\RunOnce: [DelayShred] "c:\program files\mcafee\mshr\ShrCL.EXE" /P7 /q C:\Users\Graham\AppData\Local\Temp\~DFFE9C.tmp C:\Users\Graham\AppData\Local\Temp\~DFF984.tmp C:\Users\Graham\AppData\Local\Temp\~DFF894.tmp C:\Users\Graham\AppData\Local\Temp\~DFF720.tmp C:\Users\Graham\AppData\Local\Temp\~DFDB7D.tmp C:\Users\Graham\AppData\Local\Temp\~DFCDB0.tmp C:\Users\Graham\AppData\Local\Temp\~DFCD92.tmp C:\Users\Graham\AppData\Local\Temp\~DFCC73.tmp C:\Users\Graham\AppData\Local\Temp\~DFCC64.tmp C:\Users\Graham\AppData\Local\Temp\~DFC4FB.tmp C:\Users\Graham\AppData\Local\Temp\~DFBBCD.tmp C:\Users\Graham\AppData\Local\Temp\~DFB63E.tmp C:\Users\Graham\AppData\Local\Temp\~DFB62F.tmp C:\Users\Graham\AppData\Local\Temp\~DFB46E.tmp C:\Users\Graham\AppData\Local\Temp\~DFAEF4.tmp C:\Users\Graham\AppData\Local\Temp\~DFAC35.tmp C:\Users\Graham\AppData\Local\Temp\~DFAC1F.tmp C:\Users\Graham\AppData\Local\Temp\~DFA888.tmp C:\Users\Graham\AppData\Local\Temp\~DFA59F.tmp C:\Users\Graham\AppData\Local\Temp\~DFA
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O4 - Global Startup: Digital Line Detect.lnk = C:\Program Files\Digital Line Detect\DLG.exe
O4 - Global Startup: QuickSet.lnk = ?
O4 - Global Startup: Star Alliance Auto Update Conduit (English).lnk = C:\Program Files\Star Alliance Auto Update Conduit (English)\en\st_conduit_en.exe
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~3\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - c:\Program Files\Java\jre1.6.0\bin\npjpi160.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - c:\Program Files\Java\jre1.6.0\bin\npjpi160.dll
O9 - Extra button: Skype - {77BF5300-1474-4EC7-9980-D32B190E9B07} - C:\Program Files\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~3\OFFICE11\REFIEBAR.DLL
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O13 - Gopher Prefix:
O16 - DPF: {C3F79A2B-B9B4-4A66-B012-3EE46475B072} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/MessengerStatsPAClient.cab56907.cab
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL
O22 - SharedTaskScheduler: Component Categories cache daemon - {8C7461EF-2B13-11d2-BE35-3078302C2030} - C:\Windows\system32\browseui.dll
O23 - Service: Ati External Event Utility - ATI Technologies Inc. - C:\Windows\system32\Ati2evxx.exe
O23 - Service: AVG Anti-Spyware Guard - GRISOFT s.r.o. - C:\Users\Graham\Desktop\AVG\AVG Anti-Spyware 7.5\guard.exe
O23 - Service: McAfee E-mail Proxy (Emproxy) - McAfee, Inc. - C:\PROGRA~1\COMMON~1\McAfee\EmProxy\emproxy.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe
O23 - Service: McAfee HackerWatch Service - McAfee, Inc. - C:\Program Files\Common Files\McAfee\HackerWatch\HWAPI.exe
O23 - Service: McAfee Update Manager (mcmispupdmgr) - McAfee, Inc. - C:\PROGRA~1\McAfee\MSC\mcupdmgr.exe
O23 - Service: McAfee Services (mcmscsvc) - McAfee, Inc. - C:\PROGRA~1\McAfee\MSC\mcmscsvc.exe
O23 - Service: McAfee Network Agent (McNASvc) - McAfee, Inc. - c:\program files\common files\mcafee\mna\mcnasvc.exe
O23 - Service: McAfee Scanner (McODS) - McAfee, Inc. - C:\PROGRA~1\McAfee\VIRUSS~1\mcods.exe
O23 - Service: McAfee Protection Manager (mcpromgr) - McAfee, Inc. - C:\PROGRA~1\McAfee\MSC\mcpromgr.exe
O23 - Service: McAfee Proxy Service (McProxy) - McAfee, Inc. - c:\PROGRA~1\COMMON~1\mcafee\mcproxy\mcproxy.exe
O23 - Service: McAfee Redirector Service (McRedirector) - McAfee, Inc. - c:\PROGRA~1\COMMON~1\mcafee\redirsvc\redirsvc.exe
O23 - Service: McAfee Real-time Scanner (McShield) - McAfee, Inc. - C:\PROGRA~1\McAfee\VIRUSS~1\mcshield.exe
O23 - Service: McAfee SystemGuards (McSysmon) - McAfee, Inc. - C:\PROGRA~1\McAfee\VIRUSS~1\mcsysmon.exe
O23 - Service: McAfee Personal Firewall Service (MpfService) - McAfee, Inc. - C:\Program Files\McAfee\MPF\MPFSrv.exe
O23 - Service: McAfee Privacy Service (MPS9) - McAfee, Inc. - C:\PROGRA~1\McAfee\MPS\mps.exe
O23 - Service: McAfee SpamKiller Service (MSK80Service) - McAfee Inc. - C:\Program Files\McAfee\MSK\MskSrver.exe
O23 - Service: RoxMediaDB9 - Sonic Solutions - C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxMediaDB9.exe
O23 - Service: Roxio Hard Drive Watcher 9 (RoxWatch9) - Sonic Solutions - C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxWatch9.exe
O23 - Service: SBSD Security Center Service (SBSDWSCService) - Safer Networking Ltd. - C:\Program Files\Spybot - Search & Destroy\SDWinSec.exe
O23 - Service: SigmaTel Audio Service (STacSV) - SigmaTel, Inc. - C:\Program Files\SigmaTel\C-Major Audio\WDM\STacSV.exe
O23 - Service: stllssvr - MicroVision Development, Inc. - C:\Program Files\Common Files\SureThing Shared\stllssvr.exe
O23 - Service: Dell Wireless WLAN Tray Service (wltrysvc) - Unknown owner - C:\Windows\System32\WLTRYSVC.EXE
O23 - Service: XAudioService - Conexant Systems, Inc. - C:\Windows\system32\DRIVERS\xaudio.exe

--
End of file - 11971 bytes

I have also run Kaspersky Online which identified four viruses - including the pmnnn.dll file. Unfortunately, when I try to save the log it does not succeed - though not sure why.

Any help to remove this file would be greatly appreciated!

Cheers
Graham

gra.ham
2008-01-11, 21:25
Just found the Kaspersky log :oops:


-------------------------------------------------------------------------------
KASPERSKY ONLINE SCANNER REPORT
Saturday, January 12, 2008 3:25:44 AM
Operating System: Microsoft Windows Vista Home Edition, (Build 6000)
Kaspersky Online Scanner version: 5.0.98.0
Kaspersky Anti-Virus database last update: 11/01/2008
Kaspersky Anti-Virus database records: 507550
-------------------------------------------------------------------------------

Scan Settings:
Scan using the following antivirus database: extended
Scan Archives: true
Scan Mail Bases: true

Scan Target - My Computer:
C:\
D:\
E:\

Scan Statistics:
Total number of scanned objects: 145272
Number of viruses found: 4
Number of infected objects: 10
Number of suspicious objects: 0
Duration of the scan process: 02:59:15

Infected Object Name / Virus Name / Last Action
C:\$Recycle.Bin\S-1-5-21-2472841126-2312384153-82178587-1000\$R2P606B\SmitfraudFix\Process.exe Object is locked skipped
C:\$Recycle.Bin\S-1-5-21-2472841126-2312384153-82178587-1000\$RIHB55I.zip\SmitfraudFix\Process.exe Object is locked skipped
C:\$Recycle.Bin\S-1-5-21-2472841126-2312384153-82178587-1000\$RJ29I1K.zip/SmitfraudFix/Reboot.exe Infected: not-a-virus:RiskTool.Win32.Reboot.f skipped
C:\$Recycle.Bin\S-1-5-21-2472841126-2312384153-82178587-1000\$RJ29I1K.zip ZIP: infected - 1 skipped
C:\$Recycle.Bin\S-1-5-21-2472841126-2312384153-82178587-1000\$RSLO0JR.dll Infected: Virus.Win32.Trats.d skipped
C:\$Recycle.Bin\S-1-5-21-2472841126-2312384153-82178587-1000\$RYY5S88.dll Infected: Virus.Win32.Trats.d skipped
C:\Boot\BCD Object is locked skipped
C:\Boot\BCD.LOG Object is locked skipped
C:\DELL\E-Center\EULALauncher.exe Infected: not-a-virus:AdWare.Win32.Virtumonde.cli skipped
C:\Program Files\InstallShield Installation Information\{5CD29180-A95E-11D3-A4EB-00C04F7BDB2C}\setup.ilg Object is locked skipped
C:\ProgramData\McAfee\MNA\NAData Object is locked skipped
C:\ProgramData\McAfee\MPF\data\log.edb Object is locked skipped
C:\ProgramData\McAfee\MPF\data\logout.edb Object is locked skipped
C:\ProgramData\McAfee\MSC\Logs\Events.dat Object is locked skipped
C:\ProgramData\McAfee\MSC\Logs\{4E0F4FFA-C045-42F6-9512-63EE2533ED87}.log Object is locked skipped
C:\ProgramData\McAfee\MSC\Logs\{A658E6D6-604E-4421-BC56-6A354F4C91BE}.log Object is locked skipped
C:\ProgramData\McAfee\MSC\Logs\{EAC66C37-1C66-46AF-AD6F-5D9EC3083D58}.log Object is locked skipped
C:\ProgramData\McAfee\MSC\McUsers.dat Object is locked skipped
C:\ProgramData\McAfee\MSK\MSKWMDB.dat Object is locked skipped
C:\ProgramData\McAfee\MSK\RBLDB.dat Object is locked skipped
C:\ProgramData\McAfee\MSK\settingsdb.dat Object is locked skipped
C:\ProgramData\McAfee\VirusScan\Data\TFR8889.tmp Object is locked skipped
C:\ProgramData\McAfee\VirusScan\Logs\OAS.Log Object is locked skipped
C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\499fcc2affe07f63827c361cde44a029_996767d3-79e5-4c9c-9e8d-ab962e75d050 Object is locked skipped
C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\71623db67d52ee0ec139f217d0fe3106_996767d3-79e5-4c9c-9e8d-ab962e75d050 Object is locked skipped
C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\d54d6b4beece26c4e2399271863b479c_996767d3-79e5-4c9c-9e8d-ab962e75d050 Object is locked skipped
C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\dell.txt Object is locked skipped
C:\ProgramData\Microsoft\Windows\DRM\drmstore.hds Object is locked skipped
C:\Users\Graham\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat Object is locked skipped
C:\Users\Graham\AppData\Local\Microsoft\Windows\History\Low\History.IE5\index.dat Object is locked skipped
C:\Users\Graham\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\0E6B7C2L\ptch[1] Infected: not-a-virus:AdWare.Win32.SuperJuan.cm skipped
C:\Users\Graham\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat Object is locked skipped
C:\Users\Graham\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\AntiPhishing\B3BB5BBA-E7D5-40AB-A041-A5B1C0B26C8F.dat Object is locked skipped
C:\Users\Graham\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\index.dat Object is locked skipped
C:\Users\Graham\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\MSIMGSIZ.DAT Object is locked skipped
C:\Users\Graham\AppData\Local\Microsoft\Windows\UsrClass.dat Object is locked skipped
C:\Users\Graham\AppData\Local\Microsoft\Windows\UsrClass.dat.LOG1 Object is locked skipped
C:\Users\Graham\AppData\Local\Microsoft\Windows\UsrClass.dat.LOG2 Object is locked skipped
C:\Users\Graham\AppData\Local\Microsoft\Windows\UsrClass.dat{01063ed8-d324-11db-800d-0019b959e64e}.TM.blf Object is locked skipped
C:\Users\Graham\AppData\Local\Microsoft\Windows\UsrClass.dat{01063ed8-d324-11db-800d-0019b959e64e}.TMContainer00000000000000000001.regtrans-ms Object is locked skipped
C:\Users\Graham\AppData\Local\Microsoft\Windows\UsrClass.dat{01063ed8-d324-11db-800d-0019b959e64e}.TMContainer00000000000000000002.regtrans-ms Object is locked skipped
C:\Users\Graham\AppData\Local\Microsoft\Feeds Cache\index.dat Object is locked skipped
C:\Users\Graham\AppData\Local\Microsoft\Windows Defender\FileTracker\{46DD3B7B-6CB9-4A7B-98EB-A0F0970A221B} Object is locked skipped
C:\Users\Graham\AppData\Local\Microsoft\Windows Mail\edb.log Object is locked skipped
C:\Users\Graham\AppData\Local\Microsoft\Windows Mail\tmp.edb Object is locked skipped
C:\Users\Graham\AppData\Local\Microsoft\Windows Mail\WindowsMail.MSMessageStore Object is locked skipped
C:\Users\Graham\AppData\Local\Mozilla\Firefox\Profiles\3nsuq3m5.default\Cache\633285D9d01/SmitfraudFix/Reboot.exe Infected: not-a-virus:RiskTool.Win32.Reboot.f skipped
C:\Users\Graham\AppData\Local\Mozilla\Firefox\Profiles\3nsuq3m5.default\Cache\633285D9d01 ZIP: infected - 1 skipped
C:\Users\Graham\AppData\Local\Mozilla\Firefox\Profiles\3nsuq3m5.default\Cache\_CACHE_001_ Object is locked skipped
C:\Users\Graham\AppData\Local\Mozilla\Firefox\Profiles\3nsuq3m5.default\Cache\_CACHE_002_ Object is locked skipped
C:\Users\Graham\AppData\Local\Mozilla\Firefox\Profiles\3nsuq3m5.default\Cache\_CACHE_003_ Object is locked skipped
C:\Users\Graham\AppData\Local\Mozilla\Firefox\Profiles\3nsuq3m5.default\Cache\_CACHE_MAP_ Object is locked skipped
C:\Users\Graham\AppData\Local\Temp\pmnnn.dll Infected: Virus.Win32.Trats.d skipped
C:\Users\Graham\AppData\Local\Temp\~ROMFN_000016E4 Object is locked skipped
C:\Users\Graham\AppData\Roaming\microsoft\Windows\Cookies\index.dat Object is locked skipped
C:\Users\Graham\AppData\Roaming\microsoft\Windows\Cookies\Low\index.dat Object is locked skipped
C:\Users\Graham\AppData\Roaming\Mozilla\Firefox\Profiles\3nsuq3m5.default\cert8.db Object is locked skipped
C:\Users\Graham\AppData\Roaming\Mozilla\Firefox\Profiles\3nsuq3m5.default\history.dat Object is locked skipped
C:\Users\Graham\AppData\Roaming\Mozilla\Firefox\Profiles\3nsuq3m5.default\key3.db Object is locked skipped
C:\Users\Graham\AppData\Roaming\Mozilla\Firefox\Profiles\3nsuq3m5.default\parent.lock Object is locked skipped
C:\Users\Graham\AppData\Roaming\Mozilla\Firefox\Profiles\3nsuq3m5.default\search.sqlite Object is locked skipped
C:\Users\Graham\AppData\Roaming\Mozilla\Firefox\Profiles\3nsuq3m5.default\urlclassifier2.sqlite Object is locked skipped
C:\Users\Graham\AppData\Roaming\Roxio\MediaManager9\Album.ldb Object is locked skipped
C:\Users\Graham\AppData\Roaming\Roxio\MediaManager9\Album.psod Object is locked skipped
C:\Users\Graham\AppData\Roaming\Roxio\PlasmaLog.txt Object is locked skipped
C:\Users\Graham\NTUSER.DAT Object is locked skipped
C:\Users\Graham\ntuser.dat.LOG1 Object is locked skipped
C:\Users\Graham\ntuser.dat.LOG2 Object is locked skipped
C:\Users\Graham\NTUSER.DAT{bccf46cc-bfae-11dc-9758-0019b959e64e}.TM.blf Object is locked skipped
C:\Users\Graham\NTUSER.DAT{bccf46cc-bfae-11dc-9758-0019b959e64e}.TMContainer00000000000000000001.regtrans-ms Object is locked skipped
C:\Users\Graham\NTUSER.DAT{bccf46cc-bfae-11dc-9758-0019b959e64e}.TMContainer00000000000000000002.regtrans-ms Object is locked skipped
C:\VundoFix Backups\pmnnn.dll.bad Infected: Virus.Win32.Trats.d skipped
C:\Windows\Debug\PASSWD.LOG Object is locked skipped
C:\Windows\Debug\sam.log Object is locked skipped
C:\Windows\Debug\WIA\wiatrace.log Object is locked skipped
C:\Windows\Logs\CBS\CBS.log Object is locked skipped
C:\Windows\Logs\CBS\CBS.persist.log Object is locked skipped
C:\Windows\Logs\DPX\setupact.log Object is locked skipped
C:\Windows\Logs\DPX\setuperr.log Object is locked skipped
C:\Windows\MEMORY.DMP Object is locked skipped
C:\Windows\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\SMSvcHost.exe.config Object is locked skipped
C:\Windows\Panther\UnattendGC\diagerr.xml Object is locked skipped
C:\Windows\Panther\UnattendGC\diagwrn.xml Object is locked skipped
C:\Windows\Panther\UnattendGC\setupact.log Object is locked skipped
C:\Windows\Panther\UnattendGC\setuperr.log Object is locked skipped
C:\Windows\security\database\secedit.sdb Object is locked skipped
C:\Windows\SoftwareDistribution\DataStore\DataStore.edb Object is locked skipped
C:\Windows\SoftwareDistribution\DataStore\Logs\edb.log Object is locked skipped
C:\Windows\SoftwareDistribution\DataStore\Logs\tmp.edb Object is locked skipped
C:\Windows\SoftwareDistribution\ReportingEvents.log Object is locked skipped
C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-0.C7483456-A289-439d-8115-601632D005A0 Object is locked skipped
C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-1.C7483456-A289-439d-8115-601632D005A0 Object is locked skipped
C:\Windows\System32\catroot2\edb.log Object is locked skipped
C:\Windows\System32\catroot2\{127D0A1D-4EF2-11D1-8608-00C04FC295EE}\catdb Object is locked skipped
C:\Windows\System32\catroot2\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\catdb Object is locked skipped
C:\Windows\System32\config\COMPONENTS Object is locked skipped
C:\Windows\System32\config\COMPONENTS.LOG1 Object is locked skipped
C:\Windows\System32\config\COMPONENTS.LOG2 Object is locked skipped
C:\Windows\System32\config\DEFAULT Object is locked skipped
C:\Windows\System32\config\DEFAULT.LOG1 Object is locked skipped
C:\Windows\System32\config\DEFAULT.LOG2 Object is locked skipped
C:\Windows\System32\config\SAM Object is locked skipped
C:\Windows\System32\config\SAM.LOG1 Object is locked skipped
C:\Windows\System32\config\SAM.LOG2 Object is locked skipped
C:\Windows\System32\config\SECURITY Object is locked skipped
C:\Windows\System32\config\SECURITY.LOG1 Object is locked skipped
C:\Windows\System32\config\SECURITY.LOG2 Object is locked skipped
C:\Windows\System32\config\SOFTWARE Object is locked skipped
C:\Windows\System32\config\SOFTWARE.LOG1 Object is locked skipped
C:\Windows\System32\config\SOFTWARE.LOG2 Object is locked skipped
C:\Windows\System32\config\SYSTEM Object is locked skipped
C:\Windows\System32\config\SYSTEM.LOG1 Object is locked skipped
C:\Windows\System32\config\SYSTEM.LOG2 Object is locked skipped
C:\Windows\System32\config\TxR\{250834B7-750C-494d-BDC3-DA86B6E2101B}.TM.blf Object is locked skipped
C:\Windows\System32\config\TxR\{250834B7-750C-494d-BDC3-DA86B6E2101B}.TMContainer00000000000000000001.regtrans-ms Object is locked skipped
C:\Windows\System32\config\TxR\{250834B7-750C-494d-BDC3-DA86B6E2101B}.TMContainer00000000000000000002.regtrans-ms Object is locked skipped
C:\Windows\System32\config\TxR\{bccf46b1-bfae-11dc-9758-0019b959e64e}.TxR.0.regtrans-ms Object is locked skipped
C:\Windows\System32\config\TxR\{bccf46b1-bfae-11dc-9758-0019b959e64e}.TxR.1.regtrans-ms Object is locked skipped
C:\Windows\System32\config\TxR\{bccf46b1-bfae-11dc-9758-0019b959e64e}.TxR.2.regtrans-ms Object is locked skipped
C:\Windows\System32\config\TxR\{bccf46b1-bfae-11dc-9758-0019b959e64e}.TxR.blf Object is locked skipped
C:\Windows\System32\LogFiles\Scm\SCM.EVM Object is locked skipped
C:\Windows\System32\LogFiles\WUDF\WUDFTrace.etl Object is locked skipped
C:\Windows\System32\restore\MachineGuid.txt Object is locked skipped
C:\Windows\System32\spool\SpoolerETW.etl Object is locked skipped
C:\Windows\System32\sysprep\Panther\diagerr.xml Object is locked skipped
C:\Windows\System32\sysprep\Panther\diagwrn.xml Object is locked skipped
C:\Windows\System32\sysprep\Panther\setupact.log Object is locked skipped
C:\Windows\System32\sysprep\Panther\setuperr.log Object is locked skipped
C:\Windows\System32\wbem\AutoRecover\3460B7617E0429A960E481B197F238A3.mof Object is locked skipped
C:\Windows\System32\wbem\AutoRecover\8A94AF24F162D580E3D9889344A3A317.mof Object is locked skipped
C:\Windows\System32\wbem\Logs\WMITracing.log Object is locked skipped
C:\Windows\System32\wbem\repository\INDEX.BTR Object is locked skipped
C:\Windows\System32\wbem\repository\MAPPING1.MAP Object is locked skipped
C:\Windows\System32\wbem\repository\MAPPING2.MAP Object is locked skipped
C:\Windows\System32\wbem\repository\OBJECTS.DATA Object is locked skipped
C:\Windows\System32\winevt\Logs\Application.evtx Object is locked skipped
C:\Windows\System32\winevt\Logs\Broadcom Wireless LAN.evtx Object is locked skipped
C:\Windows\System32\winevt\Logs\DFS Replication.evtx Object is locked skipped
C:\Windows\System32\winevt\Logs\HardwareEvents.evtx Object is locked skipped
C:\Windows\System32\winevt\Logs\Internet Explorer.evtx Object is locked skipped
C:\Windows\System32\winevt\Logs\Key Management Service.evtx Object is locked skipped
C:\Windows\System32\winevt\Logs\Media Center.evtx Object is locked skipped
C:\Windows\System32\winevt\Logs\Microsoft-Windows-Bits-Client%4Operational.evtx Object is locked skipped
C:\Windows\System32\winevt\Logs\Microsoft-Windows-CodeIntegrity%4Operational.evtx Object is locked skipped
C:\Windows\System32\winevt\Logs\Microsoft-Windows-Diagnosis-DPS%4Operational.evtx Object is locked skipped
C:\Windows\System32\winevt\Logs\Microsoft-Windows-Diagnosis-PLA%4Operational.evtx Object is locked skipped
C:\Windows\System32\winevt\Logs\Microsoft-Windows-Diagnostics-Networking%4Operational.evtx Object is locked skipped
C:\Windows\System32\winevt\Logs\Microsoft-Windows-Diagnostics-Performance%4Operational.evtx Object is locked skipped
C:\Windows\System32\winevt\Logs\Microsoft-Windows-DiskDiagnosticDataCollector%4Operational.evtx Object is locked skipped
C:\Windows\System32\winevt\Logs\Microsoft-Windows-DriverFrameworks-UserMode%4Operational.evtx Object is locked skipped
C:\Windows\System32\winevt\Logs\Microsoft-Windows-GroupPolicy%4Operational.evtx Object is locked skipped
C:\Windows\System32\winevt\Logs\Microsoft-Windows-Help%4Operational.evtx Object is locked skipped
C:\Windows\System32\winevt\Logs\Microsoft-Windows-International%4Operational.evtx Object is locked skipped
C:\Windows\System32\winevt\Logs\Microsoft-Windows-Kernel-WHEA.evtx Object is locked skipped
C:\Windows\System32\winevt\Logs\Microsoft-Windows-LanguagePackSetup%4Operational.evtx Object is locked skipped
C:\Windows\System32\winevt\Logs\Microsoft-Windows-MUI%4Operational.evtx Object is locked skipped
C:\Windows\System32\winevt\Logs\Microsoft-Windows-NetworkAccessProtection%4Operational.evtx Object is locked skipped
C:\Windows\System32\winevt\Logs\Microsoft-Windows-ParentalControls%4Operational.evtx Object is locked skipped
C:\Windows\System32\winevt\Logs\Microsoft-Windows-Program-Compatibility-Assistant%4Operational.evtx Object is locked skipped
C:\Windows\System32\winevt\Logs\Microsoft-Windows-ReadyBoost%4Operational.evtx Object is locked skipped
C:\Windows\System32\winevt\Logs\Microsoft-Windows-ReliabilityAnalysisComponent%4Operational.evtx Object is locked skipped
C:\Windows\System32\winevt\Logs\Microsoft-Windows-Resource-Exhaustion-Detector%4Operational.evtx Object is locked skipped
C:\Windows\System32\winevt\Logs\Microsoft-Windows-Resource-Exhaustion-Resolver%4Operational.evtx Object is locked skipped
C:\Windows\System32\winevt\Logs\Microsoft-Windows-Resource-Leak-Diagnostic%4Operational.evtx Object is locked skipped
C:\Windows\System32\winevt\Logs\Microsoft-Windows-RestartManager%4Operational.evtx Object is locked skipped
C:\Windows\System32\winevt\Logs\Microsoft-Windows-TaskScheduler%4Operational.evtx Object is locked skipped
C:\Windows\System32\winevt\Logs\Microsoft-Windows-UAC%4Operational.evtx Object is locked skipped
C:\Windows\System32\winevt\Logs\Microsoft-Windows-UAC-FileVirtualization%4Operational.evtx Object is locked skipped
C:\Windows\System32\winevt\Logs\Microsoft-Windows-WindowsUpdateClient%4Operational.evtx Object is locked skipped
C:\Windows\System32\winevt\Logs\Microsoft-Windows-WLAN-AutoConfig%4Operational.evtx Object is locked skipped
C:\Windows\System32\winevt\Logs\Security.evtx Object is locked skipped
C:\Windows\System32\winevt\Logs\Setup.evtx Object is locked skipped
C:\Windows\System32\winevt\Logs\System.evtx Object is locked skipped
C:\Windows\Tasks\SCHEDLGU.TXT Object is locked skipped
C:\Windows\Temp\fwtsqmfile00.sqm Object is locked skipped
C:\Windows\Temp\fwtsqmfile01.sqm Object is locked skipped
C:\Windows\Temp\fwtsqmfile02.sqm Object is locked skipped
C:\Windows\Temp\fwtsqmfile03.sqm Object is locked skipped
C:\Windows\Temp\fwtsqmfile04.sqm Object is locked skipped
C:\Windows\Temp\fwtsqmfile05.sqm Object is locked skipped
C:\Windows\Temp\fwtsqmfile06.sqm Object is locked skipped
C:\Windows\Temp\fwtsqmfile07.sqm Object is locked skipped
C:\Windows\Temp\fwtsqmfile08.sqm Object is locked skipped
C:\Windows\Temp\fwtsqmfile09.sqm Object is locked skipped
C:\Windows\Temp\fwtsqmfile10.sqm Object is locked skipped
C:\Windows\Temp\fwtsqmfile11.sqm Object is locked skipped
C:\Windows\Temp\fwtsqmfile12.sqm Object is locked skipped
C:\Windows\Temp\fwtsqmfile13.sqm Object is locked skipped
C:\Windows\Temp\fwtsqmfile14.sqm Object is locked skipped
C:\Windows\Temp\fwtsqmfile15.sqm Object is locked skipped
C:\Windows\Temp\fwtsqmfile16.sqm Object is locked skipped
C:\Windows\Temp\fwtsqmfile17.sqm Object is locked skipped
C:\Windows\Temp\fwtsqmfile18.sqm Object is locked skipped
C:\Windows\Temp\fwtsqmfile19.sqm Object is locked skipped
C:\Windows\Temp\JETD428.tmp Object is locked skipped
C:\Windows\Temp\mcafee_ecy87WJzNoqbKcn Object is locked skipped
C:\Windows\Temp\mcafee_J7aFTLRh88wGoVg Object is locked skipped
C:\Windows\Temp\mcmsc_7NZbcbrPjyAAKft Object is locked skipped
C:\Windows\Temp\mcmsc_bd3Z92dhVZYzqzX Object is locked skipped
C:\Windows\Temp\mcmsc_eaywVodWSga4xZX Object is locked skipped
C:\Windows\Temp\mcmsc_gBnbPed8GP7nhJx Object is locked skipped
C:\Windows\Temp\mcmsc_kYbW1IXEtzQvg61 Object is locked skipped
C:\Windows\Temp\mcmsc_qWfYzr3KedeLBTa Object is locked skipped
C:\Windows\Temp\sqlite_8ccoEkcbL04TqaZ Object is locked skipped
C:\Windows\Temp\sqlite_cWBy1jr8gYA2b3T Object is locked skipped
C:\Windows\Temp\sqlite_KTQiiSn6as4zdRK Object is locked skipped
C:\Windows\Temp\sqlite_lA6t4MLoDneRokY Object is locked skipped
C:\Windows\Temp\TMP00000070B391ACE1EF49B6A6 Object is locked skipped
C:\Windows\Temp\TMP000000771D452830BE0E7EE8 Object is locked skipped
C:\Windows\WindowsUpdate.log Object is locked skipped
C:\Windows\winsxs\x86_microsoft-windows-n..n_service_datastore_31bf3856ad364e35_6.0.6000.16386_none_cef7ceb03914a67f\dnary.xsd Object is locked skipped
D:\Windows\security\database\secedit.sdb Object is locked skipped

Scan process completed.