PDA

View Full Version : New Poly Win32 and W32/Sdbot.worm found, help disinfecting



yossi_s1
2008-01-18, 20:52
ok, so, i dont have antivirus on my system and those viruses got in.
i cant do anything, when i try to lunch antivirus program i get error: not valid win32 app...
safe mode dosent work, get blue screen.
heres some logs:
McAfee Online scan:

C:\Documents and Settings\...\b64_3[1].jpg New Poly Win32
C:\Documents and Settings\...\b64_2[1].jpg W32/Sdbot.worm
C:\Documents and Settings\...\b64_3[1].jpg New Poly Win32
C:\Documents and Settings\...\b64_3[2].jpg New Poly Win32
C:\Documents and Settings\...\b64_2[1].jpg W32/Sdbot.worm
C:\Program Files\FlashGet\fgiebar.dll Adware-FlashGet
C:\Program Files\FlashGet\flashget.exe Adware-FlashGet
C:\Program Files\FlashGet\Jccatch.dll Adware-FlashGet
C:\Program Files\FlashGet\UninstallLib.exe Adware-FlashGet
C:\WINDOWS\system32\drivers\down\102312.exe New Poly Win32
C:\WINDOWS\system32\drivers\down\110328.exe New Poly Win32
C:\WINDOWS\system32\drivers\down\1384984.exe W32/Sdbot.worm
C:\WINDOWS\system32\drivers\down\1395890.exe New Poly Win32
C:\WINDOWS\system32\drivers\down\149718.exe New Poly Win32
C:\WINDOWS\system32\drivers\down\45359.exe New Poly Win32
C:\WINDOWS\system32\drivers\down\50125.exe New Poly Win32
C:\WINDOWS\system32\drivers\down\52125.exe New Poly Win32
C:\WINDOWS\system32\drivers\down\53828.exe New Poly Win32
C:\WINDOWS\system32\drivers\down\54343.exe New Poly Win32
C:\WINDOWS\system32\drivers\down\54937.exe New Poly Win32
C:\WINDOWS\system32\drivers\down\57968.exe New Poly Win32
C:\WINDOWS\system32\drivers\down\58312.exe New Poly Win32
C:\WINDOWS\system32\drivers\down\58937.exe New Poly Win32
C:\WINDOWS\system32\drivers\down\60296.exe New Poly Win32
C:\WINDOWS\system32\drivers\down\61343.exe New Poly Win32

HJT

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 19:31:09, on 1/18/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16574)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\CTHELPER.EXE
C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\MOM.EXE
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\ccc.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\FlashGet\flashget.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O2 - BHO: IeCatch2 Class - {A5366673-E8CA-11D3-9CD9-0090271D075B} - C:\PROGRA~1\FlashGet\jccatch.dll
O3 - Toolbar: FlashGet Bar - {E0E899AB-F487-11D5-8D29-0050BA6940E3} - C:\PROGRA~1\FlashGet\fgiebar.dll
O3 - Toolbar: BitDefender Toolbar - {381FFDE8-2394-4f90-B10D-FC6124A40F8C} - C:\Program Files\BitDefender\BitDefender 2008\IEToolbar.dll
O4 - HKLM\..\Run: [WINDVDPatch] CTHELPER.EXE
O4 - HKLM\..\Run: [UpdReg] C:\WINDOWS\UpdReg.EXE
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe"
O4 - HKLM\..\Run: [StartCCC] "C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe"
O4 - HKLM\..\Run: [Jet Detection] "C:\Program Files\Creative\SBAudigy\PROGRAM%t.exeÞt.exe"
O4 - HKLM\..\Run: [CTStartup] C:\Program Files\Creative\Splash Screen\CTEaxSpl.EXE /run
O4 - HKLM\..\Run: [BitDefender Antiphishing Helper] "C:\Program Files\BitDefender\BitDefender 2008\IEShow.exe"
O4 - HKLM\..\Run: [BDAgent] "C:\Program Files\BitDefender\BitDefender 2008\bdagent.exe"
O4 - HKLM\..\Run: [Babylon Client] C:\Program Files\Babylon\Babylon-Pro\Babylon.exe -AutoStart
O4 - HKLM\..\Run: [ATITool] "C:\Program Files\ATITool\ATITool.exe" -s
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office12\EXCEL.EXE/3000
O8 - Extra context menu item: הורד באמצעות פלאש-גט - C:\Program Files\FlashGet\jc_link.htm
O8 - Extra context menu item: הורד הכל באמצעות פלאש-גט - C:\Program Files\FlashGet\jc_all.htm
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O9 - Extra button: FlashGet - {D6E814A0-E0C5-11d4-8D29-0050BA6940E3} - C:\PROGRA~1\FlashGet\flashget.exe
O9 - Extra 'Tools' menuitem: &FlashGet - {D6E814A0-E0C5-11d4-8D29-0050BA6940E3} - C:\PROGRA~1\FlashGet\flashget.exe
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {0A5FD7C5-A45C-49FC-ADB5-9952547D5715} (Creative Software AutoUpdate) - http://www.creative.com/su/ocx/15031/CTSUEng.cab
O16 - DPF: {0EB0E74A-2A76-4AB3-A7FB-9BD8C29F7F75} (CKAVWebScan Object) - http://www.kaspersky.com/kos/eng/partner/default/kavwebscan_unicode.cab
O16 - DPF: {EF791A6B-FC12-4C68-99EF-FB9E207A39E6} (McFreeScan Class) - http://download.mcafee.com/molbin/iss-loc/mcfscan/2,2,0,5210/mcfscan.cab
O16 - DPF: {F6ACF75C-C32C-447B-9BEF-46B766368D29} (Creative Software AutoUpdate Support Package) - http://www.creative.com/su/ocx/15034/CTPID.cab
O23 - Service: ATI Smart - Unknown owner - C:\WINDOWS\system32\ati2sgag.exe
O23 - Service: ##Id_String1.6844F930_1628_4223_B5CC_5BB94B879762## (Bonjour Service) - Unknown owner - C:\Program Files\Bonjour\mDNSResponder.exe (file missing)
O23 - Service: FLEXnet Licensing Service - Macrovision Europe Ltd. - C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe
O23 - Service: BitDefender Desktop Update Service (LIVESRV) - BitDefender S.R.L. - C:\Program Files\Common Files\BitDefender\BitDefender Update Service\livesrv.exe
O23 - Service: SageTV - SageTV, LLC - C:\Program Files\SageTV\SageTV\SageTVService.exe

--
End of file - 5834 bytes

kaspersky takes time but near end so ill add it soon...
one more thing, i think file wintems.exe related...

yossi_s1
2008-01-18, 21:15
no edit button?
anyway...
Kaspersky Scan:
-------------------------------------------------------------------------------
KASPERSKY ONLINE SCANNER REPORT
Friday, January 18, 2008 21:12:02
Operating System: Microsoft Windows XP Professional, Service Pack 2 (Build 2600)
Kaspersky Online Scanner version: 5.0.98.0
Kaspersky Anti-Virus database last update: 18/01/2008
Kaspersky Anti-Virus database records: 522081
-------------------------------------------------------------------------------

Scan Settings:
Scan using the following antivirus database: extended
Scan Archives: true
Scan Mail Bases: true

Scan Target - Folders:
C:\$RECYCLE.BIN\
C:\Boot\
C:\Config.Msi\
C:\Documents and Settings\All Users\
C:\Documents and Settings\Default User\
C:\Documents and Settings\LocalService\
C:\Documents and Settings\NetworkService\
C:\Documents and Settings\Yossi\Application Data\
C:\Documents and Settings\Yossi\Cookies\
C:\Documents and Settings\Yossi\Desktop\
C:\Documents and Settings\Yossi\Favorites\
C:\Documents and Settings\Yossi\Local Settings\
C:\Documents and Settings\Yossi\My Documents\ICQ Received Files\
C:\Documents and Settings\Yossi\My Documents\Mobile\
C:\Documents and Settings\Yossi\My Documents\My Music\
C:\Documents and Settings\Yossi\My Documents\My Pictures\
C:\Documents and Settings\Yossi\My Documents\My Videos\
C:\Documents and Settings\Yossi\My Documents\Visual Studio 2008\
C:\Documents and Settings\Yossi\My Documents\אזרחות\
C:\Documents and Settings\Yossi\My Documents\אנגלית\
C:\Documents and Settings\Yossi\My Documents\ביולוגיה\
C:\Documents and Settings\Yossi\My Documents\היסטוריה\
C:\Documents and Settings\Yossi\My Documents\כימיה\
C:\Documents and Settissi\Yossi\My Documents\מחשבים\
C:\Documents and Settings\Yossi\My Documents\מתמטיקה\
C:\Documents and Settings\Yossi\My Documents\ספרות\
C:\Documents and Settings\Yossi\My Documents\פסיקה\
C:\Documents and Settings\Yossi\My Documents\שונות\
C:\Documents and Settings\Yossi\My Documents\תעבורה\
C:\Documents and Settings\Yossi\My Recent Documents\
C:\Documents and Settings\Yossi\NetHood\
C:\Documents and Settings\Yossi\PrintHood\
C:\Documents and Settings\Yossi\SendTo\
C:\Documents and Settings\Yossi\Start Menu\
C:\Documents and Settings\Yossi\Templates\
C:\kav\
C:\MSOCache\
C:\Program Files\Adobe\
C:\Program Files\Ahead\
C:\Program Files\ATI Technologies\
C:\Program Files\ATITool\
C:\Program Files\Babylon\
C:\Program Files\BitDefender\
C:\Program Files\Bonjour\
C:\Program Files\Common Files\
C:\Program Files\ComPlus Applications\
C:\Program Files\Creative\
C:\Program Files\eMule\config\
C:\Program Files\eMule\Incoming\
C:\Program Files\eMule\lang\
C:\Program Files\eMule\license\
C:\Program Files\eMule\skins\
C:\Program Files\eMule\Temp\
C:\Program Files\eMule\webserver\
C:\Program Files\ESET\
C:\Program Files\FlashGet\
C:\Program Files\Foxit Software\
C:\Program Files\InstallShield Installation Information\
C:\Program Files\Internet Explorer\
C:\Program Files\Java\
C:\Program Files\Messenger\
C:\Program Files\microsoft frontpage\
C:\Program Files\Microsoft Office\
C:\Program Files\Microsoft SDKs\
C:\Program Files\Microsoft SQL Server Compact Edition\
C:\Program Files\Microsoft Synchronization Services\
C:\Program Files\Microsoft Visual Studio 9.0\
C:\Program Files\Miranda IM\
C:\Program Files\Movie Maker\
C:\Program Files\MSBuild\
C:\Program Files\MSN\
C:\Program Files\MSN Gaming Zone\
C:\Program Files\MSXML 6.0\
C:\Program Files\NetMeeting\
C:\Program Files\Norton AntiVirus\
C:\Program Files\Online Services\
C:\Program Files\Outlook Express\
C:\Program Files\Realtek\
C:\Program Files\Reference Assemblies\
C:\Program Files\SageTV\
C:\Program Files\SpeedFan\
C:\Program Files\Spybot - Search & Destroy\
C:\Program Files\Trend Micro\
C:\Program Files\Uninstall Information\
C:\Program Files\uTorrent\
C:\Program Files\Winamp\
C:\Program Files\Windows Media Connect 2\
C:\Program Files\Windows Media Player\
C:\Program Files\Windows NT\
C:\Program Files\WindowsUpdate\
C:\Program Files\WinRAR\
C:\Program Files\xerox\
C:\RECYCLER\
C:\System Volume Information\
C:\WINDOWS\

Scan Statistics:
Total number of scanned objects: 56066
Number of viruses found: 2
Number of infected objects: 31
Number of suspicious objects: 0
Duration of the scan process: 01:33:10

Infected Object Name / Virus Naast Ac Last Action
C:\Documents and Settings\LocalService\Cookies\index.dat Object is locked skipped
C:\Documents and Settings\LocalService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat Object is locked skipped
C:\Documents and Settings\LocalService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped
C:\Documents and Settings\LocalService\Local Settings\History\History.IE5\index.dat Object is locked skipped
C:\Documents and Settings\LocalService\Local Settings\Temporary Internet Files\Content.IE5\index.dat Object is locked skipped
C:\Documents and Settings\LocalService\NTUSER.DAT Object is locked skipped
C:\Documents and Settings\LocalService\ntuser.dat.LOG Object is locked skipped
C:\Documents and Settings\NetworkService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat Object is locked skipped
C:\Documents and Settings\NetworkService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped
C:\Documents and Settings\NetworkService\NTUSER.DAT Object is locked skipped
C:\Documents and Settings\NetworkService\ntuser.dat.LOG Object is locked skipped
C:\Documents and Settings\Yossi\Cookies\index.dat Object is locked skipped
C:\Documents and Settings\Yossi\Local Settings\Application Data\Microsoft\Feeds Cache\index.dat Object is locked skipped
C:\Documents and Settings\Yossi\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat Object is locked skipped
C:\Documents and Settings\Yossi\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped
C:\Documents and Settings\Yossi\Local Settings\History\History.IE5\index.dat Object is locked skipped
C:\Documents and Settings\Yossi\Local Settings\History\History.IE5\MSHist012008011820080119\index.dat Object is locked skipped
C:\Documents and Settings\Yossi\Local Settings\Temp\~DF8B1C.tmp Object is locked skipped
C:\Documents and Settings\Yossi\Local Settings\Temp\~DF8B21.tmp Object is locked skipped
C:\Documents and Settings\Yossi\Local Settings\Temporary Internet Files\AntiPhishing\B3BB5BBA-E7D5-40AB-A041-A5B1C0B26C8F.dat Object is locked skipped
C:\Documents and Settings\Yossi\Local Settings\Temporary Internet Files\Content.IE5\3BSS3X2K\b64_3[1].jpg Infected: Email-Worm.Win32.Bagle.of skipped
C:\Documents and Settings\Yossi\Local Settings\Temporary Internet Files\Content.IE5\4VNA0I6U\b64_2[1].jpg Infected: Trojan.Win32.Pakes.bwy skipped
C:\Documents and Settings\Yossi\Local Settings\Temporary Internet Files\Content.IE5\4VNA0I6U\b64_3[1].jpg Infected: Email-Worm.Win32.Bagle.of skipped
C:\Documents and Settings\Yossi\Local Settings\Temporary Internet Files\Content.IE5\4VNA0I6U\b64_3[2].jpg Infected: Email-Worm.Win32.Bagle.of skipped
C:\Documents and Settings\Yossi\Local Settings\Temporary Internet Files\Content.IE5\index.dat Object is locked skipped
C:\Documents and Settings\Yossi\Local Settings\Temporary Internet Files\Content.IE5\OW69CEUK\b64_2[1].jpg Infected: Trojan.Win32.Pakes.bwy skipped
C:\Program Files\Miranda IM\Profile.dat Object is locked skipped
C:\Program Files\SageTV\SageTV\tv.sage.mod.0.log Object is locked skipped
C:\Program Files\SageTV\SageTV\tv.sage.mod.0.log.lck Object is locked skipped
C:\Program Files\SageTV\SageTV\Wiz.bin Object is locked skipped
C:\System Volume Information\MountPointManagerRemoteDatabase Object is locked skipped
C:\WINDOWS\$hf_mig$\KB890859\SP2QFE\ntkrnlpa.exe Object is locked skipped
C:\WINDOWS\$hf_mig$\KB931784\SP2QFE\ntkrnlpa.exe Object is locked skipped
C:\WINDOWS\$NtUninstallKB890859$\ntkrnlpa.exe Object is locked skipped
C:\WINDOWS\$NtUninstallKB931784$\ntkrnlpa.exe Object is locked skipped
C:\WINDOWS\Debug\PASSWD.LOG Object is locked skipped
C:\WINDOWS\Driver Cache\i386\ntkrnlpa.exe Object is locked skipped
C:\WINDOWS\SchedLgU.Txt Object is locked skipped
C:\WINDOWS\SoftwareDistribution\Download\10e16e65c532d077de7c89a212bd8df8\sp2gdr\ntkrnlpa.exe Object is locked skipped
C:\WINDOWS\SoftwareDistribution\Download\10e16e65c532d077de7c89a212bd8df8\sp2qfe\ntkrnlpa.exe Object is locked skipped
C:\WINDOWS\SoftwareDistribution\Download\dc3b8fb011c281dea1cb7a45f880da78\sp2gdr\ntkrnlpa.exe Object is locked skipped
C:\WINDOWS\SoftwareDistribution\Download\dc3b8fb011c281dea1cb7a45f880da78\sp2qfe\ntkrnlpa.exe Object is locked skipped
C:\WINDOWS\system32\config\ACEEvent.evt Object is locked skipped
C:\WINDOWS\system32\config\AppEvent.Evt Object is locked skipped
C:\WINDOWS\system32\config\default Object is locked skipped
C:\WINDOWS\system32\config\default.LOG Object is locked skipped
C:\WINDOWS\system32\config\Internet.evt Object is locked skipped
C:\WINDOWS\system32\config\ODiag.evt Object is locked skipped
C:\WINDOWS\system32\config\OSession.evt Object is locked skipped
C:\WINDOWS\system32\config\SAM Object is locked skipped
C:\WINDOWS\system32\config\SAM.LOG Object is locked skipped
C:\WINDOWS\system32\config\SecEvent.Evt Object is locked skipped
C:\WINDOWS\system32\config\SECURITY Object is locked skipped
C:\WINDOWS\system32\config\SECURITY.LOG Object is locked skipped
C:\WINDOWS\system32\config\software Object is locked skipped
C:\WINDOWS\system32\config\software.LOG Object is locked skipped
C:\WINDOWS\system32\config\SysEvent.Evt Object is locked skipped
C:\WINDOWS\system32\config\system Object is locked skipped
C:\WINDOWS\system32\config\system.LOG Object is locked skipped
C:\WINDOWS\system32\dllcache\ntkrnlpa.exe Object is locked skipped
C:\WINDOWS\system32\drivers\down\102312.exe Infected: Email-Worm.Win32.Bagle.of skipped
C:\WINDOWS\system32\drivers\down\110328.exe Infected: Email-Worm.Win32.Bagle.of skipped
C:\WINDOWS\system32\drivers\down\1384984.exe Infected: Trojan.Win32.Pakes.bwy skipped
C:\WINDOWS\system32\drivers\down\1395890.exe Infected: Email-Worm.Win32.Bagle.of skipped
C:\WINDOWS\system32\drivers\down\149718.exe Infected: Email-Worm.Win32.Bagle.of skipped
C:\WINDOWS\system32\drivers\down\45359.exe Infected: Email-Worm.Win32.Bagle.of skipped
C:\WINDOWS\system32\drivers\down\50125.exe Infected: Email-Worm.Win32.Bagle.of skipped
C:\WINDOWS\system32\drivers\down\52125.exe Infected: Email-Worm.Win32.Bagle.of skipped
C:\WINDOWS\system32\drivers\down\53828.exe Infected: Email-Worm.Win32.Bagle.of skipped
C:\WINDOWS\system32\drivers\down\54343.exe Infected: Email-Worm.Win32.Bagle.of skipped
C:\WINDOWS\system32\drivers\down\54937.exe Infected: Email-Worm.Win32.Bagle.of skipped
C:\WINDOWS\system32\drivers\down\57968.exe Infected: Email-Worm.Win32.Bagle.of skipped
C:\WINDOWS\system32\drivers\down\58312.exe Infected: Email-Worm.Win32.Bagle.of skipped
C:\WINDOWS\system32\drivers\down\58937.exe Infected: Email-Worm.Win32.Bagle.of skipped
C:\WINDOWS\system32\drivers\down\60296.exe Infected: Email-Worm.Win32.Bagle.of skipped
C:\WINDOWS\system32\drivers\down\61343.exe Infected: Email-Worm.Win32.Bagle.of skipped
C:\WINDOWS\system32\drivers\down\65765.exe Infected: Email-Worm.Win32.Bagle.of skipped
C:\WINDOWS\system32\drivers\down\66171.exe Infected: Trojan.Win32.Pakes.bwy skipped
C:\WINDOWS\system32\drivers\down\66187.exe Infected: Trojan.Win32.Pakes.bwy skipped
C:\WINDOWS\system32\drivers\down\67031.exe Infected: Trojan.Win32.Pakes.bwy skipped
C:\WINDOWS\system32\drivers\down\70656.exe Infected: Email-Worm.Win32.Bagle.of skipped
C:\WINDOWS\system32\drivers\down\72171.exe Infected: Email-Worm.Win32.Bagle.of skipped
C:\WINDOWS\system32\drivers\down\88859.exe Infected: Email-Worm.Win32.Bagle.of skipped
C:\WINDOWS\system32\drivers\down\94390.exe Infected: Email-Worm.Win32.Bagle.of skipped
C:\WINDOWS\system32\drivers\down\99890.exe Infected: Email-Worm.Win32.Bagle.of skipped
C:\WINDOWS\system32\drivers\sptd.sys Object is locked skipped
C:\WINDOWS\system32\h323log.txt Object is locked skipped
C:\WINDOWS\system32\mdelk.exe Infected: Email-Worm.Win32.Bagle.of skipped
C:\WINDOWS\system32\ntkrnlpa.exe Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\INDEX.BTR Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\INDEX.MAP Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\MAPPING.VER Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\MAPPING1.MAP Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\MAPPING2.MAP Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\OBJECTS.DATA Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\OBJECTS.MAP Object is locked skipped
C:\WINDOWS\{00000005-00000000-00000002-00001102-00000004-00531102}.CDF Object is locked skipped

Scan process completed.