Zarky
2008-04-16, 12:56
Hi guys, i am having a prob getting rid of the above stated trojan.
When my computer reboots AVG picks up this virus and then 'cleans' it (There is another virus as well called virtumone that also keeps popping up). BUT when i restart my comp the same viruses appear all over again.
I have used CCleaner, spybot, ATF cleaner and AVG to try and find the root of the prob (As well as hijack this). I use mainly firefox to browse, but sometimes i use IE7.
Here is my hijack this report
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 09:37:24 AM, on 16/04/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16608)
Boot mode: Normal
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgemc.exe
C:\WINDOWS\system32\CarryLaunch.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\Documents and Settings\All Users\Application Data\ruvcbgfe\lorklwjc.exe
C:\WINDOWS\system32\hkcmd.exe
C:\WINDOWS\SOUNDMAN.EXE
C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe
C:\Program Files\QuickTime\qttask.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\Yahoo!\Search Protection\SearchProtection.exe
C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe
C:\WINDOWS\system32\igfxpers.exe
C:\Program Files\MSN Messenger\MsnMsgr.Exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
C:\Program Files\Windows Media Player\WMPNSCFG.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\PROGRA~1\INCRED~1\bin\IMApp.exe
C:\PROGRA~1\Magentic\bin\MgApp.exe
C:\Program Files\CaseWare\CWIN32.exe
C:\Program Files\CaseWare\cwcs.exe
C:\WINDOWS\system32\wuauclt.exe
C:\WINDOWS\system32\svchost.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgwb.dat
C:\Program Files\Microsoft Office\OFFICE11\EXCEL.EXE
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLLoginProxy.exe
C:\Program Files\CaseWare\CVWIN32.EXE
C:\Program Files\CaseWare\CVWIN32.EXE
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.yahoo.com
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com
R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://www.mecer.co.za/
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Windows Internet Explorer provided by Yahoo!
R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn1\yt.dll
O2 - BHO: &Yahoo! Toolbar Helper - {02478D38-C3F9-4EFB-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn1\yt.dll
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O2 - BHO: (no name) - {7819A53B-E11E-45F6-B5FB-52A353BF5E1E} - (no file)
O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar3.dll
O2 - BHO: (no name) - {EEC73EA5-1367-49D1-93F4-CA1D8C22E9F9} - (no file)
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn1\yt.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar3.dll
O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\system32\hkcmd.exe
O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe /STARTUP
O4 - HKLM\..\Run: [YCentral] c:\progra~1\yahoo!\YCentral\YahooCentral.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [YSearchProtection] "C:\Program Files\Yahoo!\Search Protection\SearchProtection.exe"
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe"
O4 - HKLM\..\Run: [Persistence] C:\WINDOWS\system32\igfxpers.exe
O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\MSN Messenger\MsnMsgr.Exe" /background
O4 - HKCU\..\Run: [IncrediMail] C:\Program Files\IncrediMail\bin\IncMail.exe /c
O4 - HKCU\..\Run: [Magentic] C:\PROGRA~1\Magentic\bin\Magentic.exe /c
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [YSearchProtection] C:\Program Files\Yahoo!\Search Protection\SearchProtection.exe
O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
O4 - HKCU\..\Run: [updateMgr] "C:\Program Files\Adobe\Acrobat 7.0\Reader\AdobeUpdateManager.exe" AcRdB7_0_7 -reboot 1
O4 - HKCU\..\Run: [WMPNSCFG] C:\Program Files\Windows Media Player\WMPNSCFG.exe
O4 - HKLM\..\Policies\Explorer\Run: [Go41CNVkOa] C:\Documents and Settings\All Users\Application Data\ruvcbgfe\lorklwjc.exe
O4 - HKUS\S-1-5-19\..\Run: [AVG7_Run] C:\PROGRA~1\Grisoft\AVGFRE~1\avgw.exe /RUNONCE (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [AVG7_Run] C:\PROGRA~1\Grisoft\AVGFRE~1\avgw.exe /RUNONCE (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-18\..\Run: [AVG7_Run] C:\PROGRA~1\Grisoft\AVGFRE~1\avgw.exe /RUNONCE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [AVG7_Run] C:\PROGRA~1\Grisoft\AVGFRE~1\avgw.exe /RUNONCE (User 'Default user')
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O4 - Global Startup: QuickBooks Update Agent.lnk = C:\Program Files\Common Files\Intuit\QuickBooks\QBUpdate\qbupdate.exe
O8 - Extra context menu item: &eBay Search - res://C:\Program Files\eBay\eBay Toolbar2\eBayTb.dll/RCSearch.html
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O14 - IERESET.INF: START_PAGE_URL=http://www.mecer.co.za
O16 - DPF: {0EB0E74A-2A76-4AB3-A7FB-9BD8C29F7F75} (CKAVWebScan Object) - http://www.kaspersky.com/kos/english/kavwebscan_unicode.cab
O16 - DPF: {20A60F0D-9AFA-4515-A0FD-83BD84642501} (Checkers Class) - http://messenger.zone.msn.com/binary/msgrchkr.cab56986.cab
O16 - DPF: {5D6F45B3-9043-443D-A792-115447494D24} (UnoCtrl Class) - http://messenger.zone.msn.com/EN-ZA/a-UNO1/GAME_UNO1.cab
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/windowsupdate/v6/V5Controls/en/x86/client/wuweb_site.cab?1129854071593
O16 - DPF: {C3F79A2B-B9B4-4A66-B012-3EE46475B072} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/MessengerStatsPAClient.cab56907.cab
O18 - Protocol: cwt - {774E529C-2458-48A2-8F57-3ED3105D8612} - C:\Program Files\CaseWare\cwproto.dll
O20 - Winlogon Notify: vtUkkkHx - vtUkkkHx.dll (file missing)
O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
O23 - Service: AVG E-mail Scanner (AVGEMS) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgemc.exe
O23 - Service: Carry it Easy Launcher (CarryLaunch) - Unknown owner - C:\WINDOWS\system32\CarryLaunch.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: iPod Service - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
And here is Kaspersky report. (am not sure why there are any locked files)
KASPERSKY ONLINE SCANNER REPORT
Wednesday, April 16, 2008 11:26:04 AM
Operating System: Microsoft Windows XP Professional, Service Pack 2 (Build 2600)
Kaspersky Online Scanner version: 5.0.98.0
Kaspersky Anti-Virus database last update: 16/04/2008
Kaspersky Anti-Virus database records: 709546
-------------------------------------------------------------------------------
Scan Settings:
Scan using the following antivirus database: extended
Scan Archives: true
Scan Mail Bases: true
Scan Target - Folders:
C:\
G:\
Scan Statistics:
Total number of scanned objects: 75138
Number of viruses found: 0
Number of infected objects: 0
Number of suspicious objects: 0
Duration of the scan process: 01:24:59
Infected Object Name / Virus Name / Last Action
C:\Documents and Settings\All Users\Application Data\avg7\Log\emc.log Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Grisoft\Avg7Data\avg7log.log Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Grisoft\Avg7Data\avg7log.log.lck Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Network\Downloader\qmgr0.dat Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Network\Downloader\qmgr1.dat Object is locked skipped
C:\Documents and Settings\Gordan_B\Cookies\index.dat Object is locked skipped
C:\Documents and Settings\Gordan_B\Local Settings\Application Data\CaseWare\Store\clients.cdx Object is locked skipped
C:\Documents and Settings\Gordan_B\Local Settings\Application Data\CaseWare\Store\clients.dbf Object is locked skipped
C:\Documents and Settings\Gordan_B\Local Settings\Application Data\CaseWare\Store\clients.fpt Object is locked skipped
C:\Documents and Settings\Gordan_B\Local Settings\Application Data\CaseWare\Store\files.cdx Object is locked skipped
C:\Documents and Settings\Gordan_B\Local Settings\Application Data\CaseWare\Store\files.dbf Object is locked skipped
C:\Documents and Settings\Gordan_B\Local Settings\Application Data\CaseWare\Store\files.fpt Object is locked skipped
C:\Documents and Settings\Gordan_B\Local Settings\Application Data\CaseWare\Store\projects.cdx Object is locked skipped
C:\Documents and Settings\Gordan_B\Local Settings\Application Data\CaseWare\Store\projects.dbf Object is locked skipped
C:\Documents and Settings\Gordan_B\Local Settings\Application Data\CaseWare\Store\store.clg Object is locked skipped
C:\Documents and Settings\Gordan_B\Local Settings\Application Data\CaseWare\Store\users.cdx Object is locked skipped
C:\Documents and Settings\Gordan_B\Local Settings\Application Data\CaseWare\Store\users.dbf Object is locked skipped
C:\Documents and Settings\Gordan_B\Local Settings\Application Data\CaseWare\Store\users.fpt Object is locked skipped
C:\Documents and Settings\Gordan_B\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat Object is locked skipped
C:\Documents and Settings\Gordan_B\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped
C:\Documents and Settings\Gordan_B\Local Settings\History\History.IE5\index.dat Object is locked skipped
C:\Documents and Settings\Gordan_B\Local Settings\History\History.IE5\MSHist012008041620080417\index.dat Object is locked skipped
C:\Documents and Settings\Gordan_B\Local Settings\Temp\~DF1C00.tmp Object is locked skipped
C:\Documents and Settings\Gordan_B\Local Settings\Temp\~DF35FC.tmp Object is locked skipped
C:\Documents and Settings\Gordan_B\Local Settings\Temporary Internet Files\AntiPhishing\B3BB5BBA-E7D5-40AB-A041-A5B1C0B26C8F.dat Object is locked skipped
C:\Documents and Settings\Gordan_B\Local Settings\Temporary Internet Files\Content.IE5\index.dat Object is locked skipped
C:\Documents and Settings\Gordan_B\NTUSER.DAT Object is locked skipped
C:\Documents and Settings\Gordan_B\ntuser.dat.LOG Object is locked skipped
C:\Documents and Settings\LocalService\Cookies\index.dat Object is locked skipped
C:\Documents and Settings\LocalService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat Object is locked skipped
C:\Documents and Settings\LocalService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped
C:\Documents and Settings\LocalService\Local Settings\History\History.IE5\index.dat Object is locked skipped
C:\Documents and Settings\LocalService\Local Settings\Temporary Internet Files\Content.IE5\index.dat Object is locked skipped
C:\Documents and Settings\LocalService\NTUSER.DAT Object is locked skipped
C:\Documents and Settings\LocalService\ntuser.dat.LOG Object is locked skipped
C:\Documents and Settings\NetworkService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat Object is locked skipped
C:\Documents and Settings\NetworkService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped
C:\Documents and Settings\NetworkService\NTUSER.DAT Object is locked skipped
C:\Documents and Settings\NetworkService\ntuser.dat.LOG Object is locked skipped
C:\GordonW\Other\To do.xls Object is locked skipped
C:\Program Files\CaseWare\classes.CDX Object is locked skipped
C:\Program Files\CaseWare\classes.dbf Object is locked skipped
C:\Program Files\CaseWare\im.CDX Object is locked skipped
C:\Program Files\CaseWare\im.DBF Object is locked skipped
C:\Program Files\CaseWare\periods.cdx Object is locked skipped
C:\Program Files\CaseWare\periods.dbf Object is locked skipped
C:\Program Files\CaseWare\sysinfo.cdx Object is locked skipped
C:\Program Files\CaseWare\sysinfo.dbf Object is locked skipped
C:\Program Files\CaseWare\systable.cdx Object is locked skipped
C:\Program Files\CaseWare\systable.dbf Object is locked skipped
C:\Program Files\CaseWare\sysview.cdx Object is locked skipped
C:\Program Files\CaseWare\sysview.dbf Object is locked skipped
C:\Program Files\CaseWare\sysview.fpt Object is locked skipped
C:\Program Files\CaseWare\tp3.cdx Object is locked skipped
C:\Program Files\CaseWare\tp3.dbf Object is locked skipped
C:\System Volume Information\MountPointManagerRemoteDatabase Object is locked skipped
C:\System Volume Information\_restore{6A74F5E8-AC99-470A-A8F1-301FA37CC42A}\RP1\change.log Object is locked skipped
C:\WINDOWS\Debug\PASSWD.LOG Object is locked skipped
C:\WINDOWS\SchedLgU.Txt Object is locked skipped
C:\WINDOWS\SoftwareDistribution\ReportingEvents.log Object is locked skipped
C:\WINDOWS\Sti_Trace.log Object is locked skipped
C:\WINDOWS\system32\CatRoot2\edb.log Object is locked skipped
C:\WINDOWS\system32\CatRoot2\tmp.edb Object is locked skipped
C:\WINDOWS\system32\config\AppEvent.Evt Object is locked skipped
C:\WINDOWS\system32\config\default Object is locked skipped
C:\WINDOWS\system32\config\default.LOG Object is locked skipped
C:\WINDOWS\system32\config\Internet.evt Object is locked skipped
C:\WINDOWS\system32\config\SAM Object is locked skipped
C:\WINDOWS\system32\config\SAM.LOG Object is locked skipped
C:\WINDOWS\system32\config\SecEvent.Evt Object is locked skipped
C:\WINDOWS\system32\config\SECURITY Object is locked skipped
C:\WINDOWS\system32\config\SECURITY.LOG Object is locked skipped
C:\WINDOWS\system32\config\software Object is locked skipped
C:\WINDOWS\system32\config\software.LOG Object is locked skipped
C:\WINDOWS\system32\config\SysEvent.Evt Object is locked skipped
C:\WINDOWS\system32\config\system Object is locked skipped
C:\WINDOWS\system32\config\system.LOG Object is locked skipped
C:\WINDOWS\system32\h323log.txt Object is locked skipped
C:\WINDOWS\system32\spool\PRINTERS\FP00000.SHD Object is locked skipped
C:\WINDOWS\system32\spool\PRINTERS\FP00000.SPL Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\INDEX.BTR Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\INDEX.MAP Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\MAPPING.VER Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\MAPPING1.MAP Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\MAPPING2.MAP Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\OBJECTS.DATA Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\OBJECTS.MAP Object is locked skipped
C:\WINDOWS\wiadebug.log Object is locked skipped
C:\WINDOWS\wiaservc.log Object is locked skipped
C:\WINDOWS\WindowsUpdate.log Object is locked skipped
G:\Annual financial statements\WIP\2007\Delicious trading 2 (P)L\01.30.24.xls Object is locked skipped
G:\Annual financial statements\WIP\2007\Delicious trading 2 (P)L\Delicious trading 2 (P)L.clg Object is locked skipped
G:\Annual financial statements\WIP\2007\Delicious trading 2 (P)L\Delicious trading 2 (P)L.csc Object is locked skipped
G:\Annual financial statements\WIP\2007\Delicious trading 2 (P)L\Delicious trading 2 (P)LAC.cdx Object is locked skipped
G:\Annual financial statements\WIP\2007\Delicious trading 2 (P)L\Delicious trading 2 (P)LAC.dbf Object is locked skipped
G:\Annual financial statements\WIP\2007\Delicious trading 2 (P)L\Delicious trading 2 (P)LAC.fpt Object is locked skipped
G:\Annual financial statements\WIP\2007\Delicious trading 2 (P)L\Delicious trading 2 (P)LAM.cdx Object is locked skipped
G:\Annual financial statements\WIP\2007\Delicious trading 2 (P)L\Delicious trading 2 (P)LAM.dbf Object is locked skipped
G:\Annual financial statements\WIP\2007\Delicious trading 2 (P)L\Delicious trading 2 (P)LAM.fpt Object is locked skipped
G:\Annual financial statements\WIP\2007\Delicious trading 2 (P)L\Delicious trading 2 (P)LAN.cdx Object is locked skipped
G:\Annual financial statements\WIP\2007\Delicious trading 2 (P)L\Delicious trading 2 (P)LAN.dbf Object is locked skipped
G:\Annual financial statements\WIP\2007\Delicious trading 2 (P)L\Delicious trading 2 (P)LAN.fpt Object is locked skipped
G:\Annual financial statements\WIP\2007\Delicious trading 2 (P)L\Delicious trading 2 (P)LBL.cdx Object is locked skipped
G:\Annual financial statements\WIP\2007\Delicious trading 2 (P)L\Delicious trading 2 (P)LBL.dbf Object is locked skipped
G:\Annual financial statements\WIP\2007\Delicious trading 2 (P)L\Delicious trading 2 (P)LCE.cdx Object is locked skipped
G:\Annual financial statements\WIP\2007\Delicious trading 2 (P)L\Delicious trading 2 (P)LCE.dbf Object is locked skipped
G:\Annual financial statements\WIP\2007\Delicious trading 2 (P)L\Delicious trading 2 (P)LCE.fpt Object is locked skipped
G:\Annual financial statements\WIP\2007\Delicious trading 2 (P)L\Delicious trading 2 (P)LCV.cdx Object is locked skipped
G:\Annual financial statements\WIP\2007\Delicious trading 2 (P)L\Delicious trading 2 (P)LCV.dbf Object is locked skipped
G:\Annual financial statements\WIP\2007\Delicious trading 2 (P)L\Delicious trading 2 (P)LCV.fpt Object is locked skipped
G:\Annual financial statements\WIP\2007\Delicious trading 2 (P)L\Delicious trading 2 (P)LEC.cdx Object is locked skipped
G:\Annual financial statements\WIP\2007\Delicious trading 2 (P)L\Delicious trading 2 (P)LEC.dbf Object is locked skipped
G:\Annual financial statements\WIP\2007\Delicious trading 2 (P)L\Delicious trading 2 (P)LEC.FPT Object is locked skipped
G:\Annual financial statements\WIP\2007\Delicious trading 2 (P)L\Delicious trading 2 (P)LFP.cdx Object is locked skipped
G:\Annual financial statements\WIP\2007\Delicious trading 2 (P)L\Delicious trading 2 (P)LFP.dbf Object is locked skipped
G:\Annual financial statements\WIP\2007\Delicious trading 2 (P)L\Delicious trading 2 (P)LGL.cdx Object is locked skipped
G:\Annual financial statements\WIP\2007\Delicious trading 2 (P)L\Delicious trading 2 (P)LGL.dbf Object is locked skipped
G:\Annual financial statements\WIP\2007\Delicious trading 2 (P)L\Delicious trading 2 (P)LGL.fpt Object is locked skipped
G:\Annual financial statements\WIP\2007\Delicious trading 2 (P)L\Delicious trading 2 (P)LGR.cdx Object is locked skipped
G:\Annual financial statements\WIP\2007\Delicious trading 2 (P)L\Delicious trading 2 (P)LGR.dbf Object is locked skipped
G:\Annual financial statements\WIP\2007\Delicious trading 2 (P)L\Delicious trading 2 (P)LGR.fpt Object is locked skipped
G:\Annual financial statements\WIP\2007\Delicious trading 2 (P)L\Delicious trading 2 (P)LGS.cdx Object is locked skipped
G:\Annual financial statements\WIP\2007\Delicious trading 2 (P)L\Delicious trading 2 (P)LGS.dbf Object is locked skipped
G:\Annual financial statements\WIP\2007\Delicious trading 2 (P)L\Delicious trading 2 (P)LHI.cdx Object is locked skipped
G:\Annual financial statements\WIP\2007\Delicious trading 2 (P)L\Delicious trading 2 (P)LHI.dbf Object is locked skipped
G:\Annual financial statements\WIP\2007\Delicious trading 2 (P)L\Delicious trading 2 (P)LHI.fpt Object is locked skipped
G:\Annual financial statements\WIP\2007\Delicious trading 2 (P)L\Delicious trading 2 (P)LMP.cdx Object is locked skipped
G:\Annual financial statements\WIP\2007\Delicious trading 2 (P)L\Delicious trading 2 (P)LMP.dbf Object is locked skipped
G:\Annual financial statements\WIP\2007\Delicious trading 2 (P)L\Delicious trading 2 (P)LMP.fpt Object is locked skipped
G:\Annual financial statements\WIP\2007\Delicious trading 2 (P)L\Delicious trading 2 (P)LPR.cdx Object is locked skipped
G:\Annual financial statements\WIP\2007\Delicious trading 2 (P)L\Delicious trading 2 (P)LPR.dbf Object is locked skipped
G:\Annual financial statements\WIP\2007\Delicious trading 2 (P)L\Delicious trading 2 (P)LPR.fpt Object is locked skipped
G:\Annual financial statements\WIP\2007\Delicious trading 2 (P)L\Delicious trading 2 (P)LRA.cdx Object is locked skipped
G:\Annual financial statements\WIP\2007\Delicious trading 2 (P)L\Delicious trading 2 (P)LRA.dbf Object is locked skipped
G:\Annual financial statements\WIP\2007\Delicious trading 2 (P)L\Delicious trading 2 (P)LRL.cdx Object is locked skipped
G:\Annual financial statements\WIP\2007\Delicious trading 2 (P)L\Delicious trading 2 (P)LRL.dbf Object is locked skipped
G:\Annual financial statements\WIP\2007\Delicious trading 2 (P)L\Delicious trading 2 (P)LSH.cdx Object is locked skipped
G:\Annual financial statements\WIP\2007\Delicious trading 2 (P)L\Delicious trading 2 (P)LSH.dbf Object is locked skipped
G:\Annual financial statements\WIP\2007\Delicious trading 2 (P)L\Delicious trading 2 (P)LSH.fpt Object is locked skipped
G:\Annual financial statements\WIP\2007\Delicious trading 2 (P)L\Delicious trading 2 (P)LTM.cdx Object is locked skipped
G:\Annual financial statements\WIP\2007\Delicious trading 2 (P)L\Delicious trading 2 (P)LTM.dbf Object is locked skipped
G:\Annual financial statements\WIP\2007\Delicious trading 2 (P)L\Delicious trading 2 (P)LTP.cdx Object is locked skipped
G:\Annual financial statements\WIP\2007\Delicious trading 2 (P)L\Delicious trading 2 (P)LTP.dbf Object is locked skipped
G:\Annual financial statements\WIP\2007\Delicious trading 2 (P)L\Delicious trading 2 (P)LTS.cdx Object is locked skipped
G:\Annual financial statements\WIP\2007\Delicious trading 2 (P)L\Delicious trading 2 (P)LTS.dbf Object is locked skipped
G:\Annual financial statements\WIP\2007\Delicious trading 2 (P)L\Delicious trading 2 (P)LTS.fpt Object is locked skipped
G:\Annual financial statements\WIP\2007\Delicious trading 2 (P)L\Delicious trading 2 (P)LWR.cdx Object is locked skipped
G:\Annual financial statements\WIP\2007\Delicious trading 2 (P)L\Delicious trading 2 (P)LWR.dbf Object is locked skipped
G:\Annual financial statements\WIP\2007\Delicious trading 2 (P)L\Delicious trading 2 (P)LWR.fpt Object is locked skipped
G:\Annual financial statements\WIP\2007\Delicious trading 2 (P)L\Delicious trading 2 (P)LWT.cdx Object is locked skipped
G:\Annual financial statements\WIP\2007\Delicious trading 2 (P)L\Delicious trading 2 (P)LWT.dbf Object is locked skipped
Scan process completed.
Your help will be greatly appreciated, thanks.
When my computer reboots AVG picks up this virus and then 'cleans' it (There is another virus as well called virtumone that also keeps popping up). BUT when i restart my comp the same viruses appear all over again.
I have used CCleaner, spybot, ATF cleaner and AVG to try and find the root of the prob (As well as hijack this). I use mainly firefox to browse, but sometimes i use IE7.
Here is my hijack this report
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 09:37:24 AM, on 16/04/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16608)
Boot mode: Normal
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgemc.exe
C:\WINDOWS\system32\CarryLaunch.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\Documents and Settings\All Users\Application Data\ruvcbgfe\lorklwjc.exe
C:\WINDOWS\system32\hkcmd.exe
C:\WINDOWS\SOUNDMAN.EXE
C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe
C:\Program Files\QuickTime\qttask.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\Yahoo!\Search Protection\SearchProtection.exe
C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe
C:\WINDOWS\system32\igfxpers.exe
C:\Program Files\MSN Messenger\MsnMsgr.Exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
C:\Program Files\Windows Media Player\WMPNSCFG.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\PROGRA~1\INCRED~1\bin\IMApp.exe
C:\PROGRA~1\Magentic\bin\MgApp.exe
C:\Program Files\CaseWare\CWIN32.exe
C:\Program Files\CaseWare\cwcs.exe
C:\WINDOWS\system32\wuauclt.exe
C:\WINDOWS\system32\svchost.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgwb.dat
C:\Program Files\Microsoft Office\OFFICE11\EXCEL.EXE
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLLoginProxy.exe
C:\Program Files\CaseWare\CVWIN32.EXE
C:\Program Files\CaseWare\CVWIN32.EXE
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.yahoo.com
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com
R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://www.mecer.co.za/
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Windows Internet Explorer provided by Yahoo!
R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn1\yt.dll
O2 - BHO: &Yahoo! Toolbar Helper - {02478D38-C3F9-4EFB-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn1\yt.dll
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O2 - BHO: (no name) - {7819A53B-E11E-45F6-B5FB-52A353BF5E1E} - (no file)
O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar3.dll
O2 - BHO: (no name) - {EEC73EA5-1367-49D1-93F4-CA1D8C22E9F9} - (no file)
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn1\yt.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar3.dll
O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\system32\hkcmd.exe
O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe /STARTUP
O4 - HKLM\..\Run: [YCentral] c:\progra~1\yahoo!\YCentral\YahooCentral.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [YSearchProtection] "C:\Program Files\Yahoo!\Search Protection\SearchProtection.exe"
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe"
O4 - HKLM\..\Run: [Persistence] C:\WINDOWS\system32\igfxpers.exe
O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\MSN Messenger\MsnMsgr.Exe" /background
O4 - HKCU\..\Run: [IncrediMail] C:\Program Files\IncrediMail\bin\IncMail.exe /c
O4 - HKCU\..\Run: [Magentic] C:\PROGRA~1\Magentic\bin\Magentic.exe /c
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [YSearchProtection] C:\Program Files\Yahoo!\Search Protection\SearchProtection.exe
O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
O4 - HKCU\..\Run: [updateMgr] "C:\Program Files\Adobe\Acrobat 7.0\Reader\AdobeUpdateManager.exe" AcRdB7_0_7 -reboot 1
O4 - HKCU\..\Run: [WMPNSCFG] C:\Program Files\Windows Media Player\WMPNSCFG.exe
O4 - HKLM\..\Policies\Explorer\Run: [Go41CNVkOa] C:\Documents and Settings\All Users\Application Data\ruvcbgfe\lorklwjc.exe
O4 - HKUS\S-1-5-19\..\Run: [AVG7_Run] C:\PROGRA~1\Grisoft\AVGFRE~1\avgw.exe /RUNONCE (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [AVG7_Run] C:\PROGRA~1\Grisoft\AVGFRE~1\avgw.exe /RUNONCE (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-18\..\Run: [AVG7_Run] C:\PROGRA~1\Grisoft\AVGFRE~1\avgw.exe /RUNONCE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [AVG7_Run] C:\PROGRA~1\Grisoft\AVGFRE~1\avgw.exe /RUNONCE (User 'Default user')
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O4 - Global Startup: QuickBooks Update Agent.lnk = C:\Program Files\Common Files\Intuit\QuickBooks\QBUpdate\qbupdate.exe
O8 - Extra context menu item: &eBay Search - res://C:\Program Files\eBay\eBay Toolbar2\eBayTb.dll/RCSearch.html
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O14 - IERESET.INF: START_PAGE_URL=http://www.mecer.co.za
O16 - DPF: {0EB0E74A-2A76-4AB3-A7FB-9BD8C29F7F75} (CKAVWebScan Object) - http://www.kaspersky.com/kos/english/kavwebscan_unicode.cab
O16 - DPF: {20A60F0D-9AFA-4515-A0FD-83BD84642501} (Checkers Class) - http://messenger.zone.msn.com/binary/msgrchkr.cab56986.cab
O16 - DPF: {5D6F45B3-9043-443D-A792-115447494D24} (UnoCtrl Class) - http://messenger.zone.msn.com/EN-ZA/a-UNO1/GAME_UNO1.cab
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/windowsupdate/v6/V5Controls/en/x86/client/wuweb_site.cab?1129854071593
O16 - DPF: {C3F79A2B-B9B4-4A66-B012-3EE46475B072} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/MessengerStatsPAClient.cab56907.cab
O18 - Protocol: cwt - {774E529C-2458-48A2-8F57-3ED3105D8612} - C:\Program Files\CaseWare\cwproto.dll
O20 - Winlogon Notify: vtUkkkHx - vtUkkkHx.dll (file missing)
O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
O23 - Service: AVG E-mail Scanner (AVGEMS) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgemc.exe
O23 - Service: Carry it Easy Launcher (CarryLaunch) - Unknown owner - C:\WINDOWS\system32\CarryLaunch.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: iPod Service - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
And here is Kaspersky report. (am not sure why there are any locked files)
KASPERSKY ONLINE SCANNER REPORT
Wednesday, April 16, 2008 11:26:04 AM
Operating System: Microsoft Windows XP Professional, Service Pack 2 (Build 2600)
Kaspersky Online Scanner version: 5.0.98.0
Kaspersky Anti-Virus database last update: 16/04/2008
Kaspersky Anti-Virus database records: 709546
-------------------------------------------------------------------------------
Scan Settings:
Scan using the following antivirus database: extended
Scan Archives: true
Scan Mail Bases: true
Scan Target - Folders:
C:\
G:\
Scan Statistics:
Total number of scanned objects: 75138
Number of viruses found: 0
Number of infected objects: 0
Number of suspicious objects: 0
Duration of the scan process: 01:24:59
Infected Object Name / Virus Name / Last Action
C:\Documents and Settings\All Users\Application Data\avg7\Log\emc.log Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Grisoft\Avg7Data\avg7log.log Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Grisoft\Avg7Data\avg7log.log.lck Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Network\Downloader\qmgr0.dat Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Network\Downloader\qmgr1.dat Object is locked skipped
C:\Documents and Settings\Gordan_B\Cookies\index.dat Object is locked skipped
C:\Documents and Settings\Gordan_B\Local Settings\Application Data\CaseWare\Store\clients.cdx Object is locked skipped
C:\Documents and Settings\Gordan_B\Local Settings\Application Data\CaseWare\Store\clients.dbf Object is locked skipped
C:\Documents and Settings\Gordan_B\Local Settings\Application Data\CaseWare\Store\clients.fpt Object is locked skipped
C:\Documents and Settings\Gordan_B\Local Settings\Application Data\CaseWare\Store\files.cdx Object is locked skipped
C:\Documents and Settings\Gordan_B\Local Settings\Application Data\CaseWare\Store\files.dbf Object is locked skipped
C:\Documents and Settings\Gordan_B\Local Settings\Application Data\CaseWare\Store\files.fpt Object is locked skipped
C:\Documents and Settings\Gordan_B\Local Settings\Application Data\CaseWare\Store\projects.cdx Object is locked skipped
C:\Documents and Settings\Gordan_B\Local Settings\Application Data\CaseWare\Store\projects.dbf Object is locked skipped
C:\Documents and Settings\Gordan_B\Local Settings\Application Data\CaseWare\Store\store.clg Object is locked skipped
C:\Documents and Settings\Gordan_B\Local Settings\Application Data\CaseWare\Store\users.cdx Object is locked skipped
C:\Documents and Settings\Gordan_B\Local Settings\Application Data\CaseWare\Store\users.dbf Object is locked skipped
C:\Documents and Settings\Gordan_B\Local Settings\Application Data\CaseWare\Store\users.fpt Object is locked skipped
C:\Documents and Settings\Gordan_B\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat Object is locked skipped
C:\Documents and Settings\Gordan_B\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped
C:\Documents and Settings\Gordan_B\Local Settings\History\History.IE5\index.dat Object is locked skipped
C:\Documents and Settings\Gordan_B\Local Settings\History\History.IE5\MSHist012008041620080417\index.dat Object is locked skipped
C:\Documents and Settings\Gordan_B\Local Settings\Temp\~DF1C00.tmp Object is locked skipped
C:\Documents and Settings\Gordan_B\Local Settings\Temp\~DF35FC.tmp Object is locked skipped
C:\Documents and Settings\Gordan_B\Local Settings\Temporary Internet Files\AntiPhishing\B3BB5BBA-E7D5-40AB-A041-A5B1C0B26C8F.dat Object is locked skipped
C:\Documents and Settings\Gordan_B\Local Settings\Temporary Internet Files\Content.IE5\index.dat Object is locked skipped
C:\Documents and Settings\Gordan_B\NTUSER.DAT Object is locked skipped
C:\Documents and Settings\Gordan_B\ntuser.dat.LOG Object is locked skipped
C:\Documents and Settings\LocalService\Cookies\index.dat Object is locked skipped
C:\Documents and Settings\LocalService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat Object is locked skipped
C:\Documents and Settings\LocalService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped
C:\Documents and Settings\LocalService\Local Settings\History\History.IE5\index.dat Object is locked skipped
C:\Documents and Settings\LocalService\Local Settings\Temporary Internet Files\Content.IE5\index.dat Object is locked skipped
C:\Documents and Settings\LocalService\NTUSER.DAT Object is locked skipped
C:\Documents and Settings\LocalService\ntuser.dat.LOG Object is locked skipped
C:\Documents and Settings\NetworkService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat Object is locked skipped
C:\Documents and Settings\NetworkService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped
C:\Documents and Settings\NetworkService\NTUSER.DAT Object is locked skipped
C:\Documents and Settings\NetworkService\ntuser.dat.LOG Object is locked skipped
C:\GordonW\Other\To do.xls Object is locked skipped
C:\Program Files\CaseWare\classes.CDX Object is locked skipped
C:\Program Files\CaseWare\classes.dbf Object is locked skipped
C:\Program Files\CaseWare\im.CDX Object is locked skipped
C:\Program Files\CaseWare\im.DBF Object is locked skipped
C:\Program Files\CaseWare\periods.cdx Object is locked skipped
C:\Program Files\CaseWare\periods.dbf Object is locked skipped
C:\Program Files\CaseWare\sysinfo.cdx Object is locked skipped
C:\Program Files\CaseWare\sysinfo.dbf Object is locked skipped
C:\Program Files\CaseWare\systable.cdx Object is locked skipped
C:\Program Files\CaseWare\systable.dbf Object is locked skipped
C:\Program Files\CaseWare\sysview.cdx Object is locked skipped
C:\Program Files\CaseWare\sysview.dbf Object is locked skipped
C:\Program Files\CaseWare\sysview.fpt Object is locked skipped
C:\Program Files\CaseWare\tp3.cdx Object is locked skipped
C:\Program Files\CaseWare\tp3.dbf Object is locked skipped
C:\System Volume Information\MountPointManagerRemoteDatabase Object is locked skipped
C:\System Volume Information\_restore{6A74F5E8-AC99-470A-A8F1-301FA37CC42A}\RP1\change.log Object is locked skipped
C:\WINDOWS\Debug\PASSWD.LOG Object is locked skipped
C:\WINDOWS\SchedLgU.Txt Object is locked skipped
C:\WINDOWS\SoftwareDistribution\ReportingEvents.log Object is locked skipped
C:\WINDOWS\Sti_Trace.log Object is locked skipped
C:\WINDOWS\system32\CatRoot2\edb.log Object is locked skipped
C:\WINDOWS\system32\CatRoot2\tmp.edb Object is locked skipped
C:\WINDOWS\system32\config\AppEvent.Evt Object is locked skipped
C:\WINDOWS\system32\config\default Object is locked skipped
C:\WINDOWS\system32\config\default.LOG Object is locked skipped
C:\WINDOWS\system32\config\Internet.evt Object is locked skipped
C:\WINDOWS\system32\config\SAM Object is locked skipped
C:\WINDOWS\system32\config\SAM.LOG Object is locked skipped
C:\WINDOWS\system32\config\SecEvent.Evt Object is locked skipped
C:\WINDOWS\system32\config\SECURITY Object is locked skipped
C:\WINDOWS\system32\config\SECURITY.LOG Object is locked skipped
C:\WINDOWS\system32\config\software Object is locked skipped
C:\WINDOWS\system32\config\software.LOG Object is locked skipped
C:\WINDOWS\system32\config\SysEvent.Evt Object is locked skipped
C:\WINDOWS\system32\config\system Object is locked skipped
C:\WINDOWS\system32\config\system.LOG Object is locked skipped
C:\WINDOWS\system32\h323log.txt Object is locked skipped
C:\WINDOWS\system32\spool\PRINTERS\FP00000.SHD Object is locked skipped
C:\WINDOWS\system32\spool\PRINTERS\FP00000.SPL Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\INDEX.BTR Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\INDEX.MAP Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\MAPPING.VER Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\MAPPING1.MAP Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\MAPPING2.MAP Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\OBJECTS.DATA Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\OBJECTS.MAP Object is locked skipped
C:\WINDOWS\wiadebug.log Object is locked skipped
C:\WINDOWS\wiaservc.log Object is locked skipped
C:\WINDOWS\WindowsUpdate.log Object is locked skipped
G:\Annual financial statements\WIP\2007\Delicious trading 2 (P)L\01.30.24.xls Object is locked skipped
G:\Annual financial statements\WIP\2007\Delicious trading 2 (P)L\Delicious trading 2 (P)L.clg Object is locked skipped
G:\Annual financial statements\WIP\2007\Delicious trading 2 (P)L\Delicious trading 2 (P)L.csc Object is locked skipped
G:\Annual financial statements\WIP\2007\Delicious trading 2 (P)L\Delicious trading 2 (P)LAC.cdx Object is locked skipped
G:\Annual financial statements\WIP\2007\Delicious trading 2 (P)L\Delicious trading 2 (P)LAC.dbf Object is locked skipped
G:\Annual financial statements\WIP\2007\Delicious trading 2 (P)L\Delicious trading 2 (P)LAC.fpt Object is locked skipped
G:\Annual financial statements\WIP\2007\Delicious trading 2 (P)L\Delicious trading 2 (P)LAM.cdx Object is locked skipped
G:\Annual financial statements\WIP\2007\Delicious trading 2 (P)L\Delicious trading 2 (P)LAM.dbf Object is locked skipped
G:\Annual financial statements\WIP\2007\Delicious trading 2 (P)L\Delicious trading 2 (P)LAM.fpt Object is locked skipped
G:\Annual financial statements\WIP\2007\Delicious trading 2 (P)L\Delicious trading 2 (P)LAN.cdx Object is locked skipped
G:\Annual financial statements\WIP\2007\Delicious trading 2 (P)L\Delicious trading 2 (P)LAN.dbf Object is locked skipped
G:\Annual financial statements\WIP\2007\Delicious trading 2 (P)L\Delicious trading 2 (P)LAN.fpt Object is locked skipped
G:\Annual financial statements\WIP\2007\Delicious trading 2 (P)L\Delicious trading 2 (P)LBL.cdx Object is locked skipped
G:\Annual financial statements\WIP\2007\Delicious trading 2 (P)L\Delicious trading 2 (P)LBL.dbf Object is locked skipped
G:\Annual financial statements\WIP\2007\Delicious trading 2 (P)L\Delicious trading 2 (P)LCE.cdx Object is locked skipped
G:\Annual financial statements\WIP\2007\Delicious trading 2 (P)L\Delicious trading 2 (P)LCE.dbf Object is locked skipped
G:\Annual financial statements\WIP\2007\Delicious trading 2 (P)L\Delicious trading 2 (P)LCE.fpt Object is locked skipped
G:\Annual financial statements\WIP\2007\Delicious trading 2 (P)L\Delicious trading 2 (P)LCV.cdx Object is locked skipped
G:\Annual financial statements\WIP\2007\Delicious trading 2 (P)L\Delicious trading 2 (P)LCV.dbf Object is locked skipped
G:\Annual financial statements\WIP\2007\Delicious trading 2 (P)L\Delicious trading 2 (P)LCV.fpt Object is locked skipped
G:\Annual financial statements\WIP\2007\Delicious trading 2 (P)L\Delicious trading 2 (P)LEC.cdx Object is locked skipped
G:\Annual financial statements\WIP\2007\Delicious trading 2 (P)L\Delicious trading 2 (P)LEC.dbf Object is locked skipped
G:\Annual financial statements\WIP\2007\Delicious trading 2 (P)L\Delicious trading 2 (P)LEC.FPT Object is locked skipped
G:\Annual financial statements\WIP\2007\Delicious trading 2 (P)L\Delicious trading 2 (P)LFP.cdx Object is locked skipped
G:\Annual financial statements\WIP\2007\Delicious trading 2 (P)L\Delicious trading 2 (P)LFP.dbf Object is locked skipped
G:\Annual financial statements\WIP\2007\Delicious trading 2 (P)L\Delicious trading 2 (P)LGL.cdx Object is locked skipped
G:\Annual financial statements\WIP\2007\Delicious trading 2 (P)L\Delicious trading 2 (P)LGL.dbf Object is locked skipped
G:\Annual financial statements\WIP\2007\Delicious trading 2 (P)L\Delicious trading 2 (P)LGL.fpt Object is locked skipped
G:\Annual financial statements\WIP\2007\Delicious trading 2 (P)L\Delicious trading 2 (P)LGR.cdx Object is locked skipped
G:\Annual financial statements\WIP\2007\Delicious trading 2 (P)L\Delicious trading 2 (P)LGR.dbf Object is locked skipped
G:\Annual financial statements\WIP\2007\Delicious trading 2 (P)L\Delicious trading 2 (P)LGR.fpt Object is locked skipped
G:\Annual financial statements\WIP\2007\Delicious trading 2 (P)L\Delicious trading 2 (P)LGS.cdx Object is locked skipped
G:\Annual financial statements\WIP\2007\Delicious trading 2 (P)L\Delicious trading 2 (P)LGS.dbf Object is locked skipped
G:\Annual financial statements\WIP\2007\Delicious trading 2 (P)L\Delicious trading 2 (P)LHI.cdx Object is locked skipped
G:\Annual financial statements\WIP\2007\Delicious trading 2 (P)L\Delicious trading 2 (P)LHI.dbf Object is locked skipped
G:\Annual financial statements\WIP\2007\Delicious trading 2 (P)L\Delicious trading 2 (P)LHI.fpt Object is locked skipped
G:\Annual financial statements\WIP\2007\Delicious trading 2 (P)L\Delicious trading 2 (P)LMP.cdx Object is locked skipped
G:\Annual financial statements\WIP\2007\Delicious trading 2 (P)L\Delicious trading 2 (P)LMP.dbf Object is locked skipped
G:\Annual financial statements\WIP\2007\Delicious trading 2 (P)L\Delicious trading 2 (P)LMP.fpt Object is locked skipped
G:\Annual financial statements\WIP\2007\Delicious trading 2 (P)L\Delicious trading 2 (P)LPR.cdx Object is locked skipped
G:\Annual financial statements\WIP\2007\Delicious trading 2 (P)L\Delicious trading 2 (P)LPR.dbf Object is locked skipped
G:\Annual financial statements\WIP\2007\Delicious trading 2 (P)L\Delicious trading 2 (P)LPR.fpt Object is locked skipped
G:\Annual financial statements\WIP\2007\Delicious trading 2 (P)L\Delicious trading 2 (P)LRA.cdx Object is locked skipped
G:\Annual financial statements\WIP\2007\Delicious trading 2 (P)L\Delicious trading 2 (P)LRA.dbf Object is locked skipped
G:\Annual financial statements\WIP\2007\Delicious trading 2 (P)L\Delicious trading 2 (P)LRL.cdx Object is locked skipped
G:\Annual financial statements\WIP\2007\Delicious trading 2 (P)L\Delicious trading 2 (P)LRL.dbf Object is locked skipped
G:\Annual financial statements\WIP\2007\Delicious trading 2 (P)L\Delicious trading 2 (P)LSH.cdx Object is locked skipped
G:\Annual financial statements\WIP\2007\Delicious trading 2 (P)L\Delicious trading 2 (P)LSH.dbf Object is locked skipped
G:\Annual financial statements\WIP\2007\Delicious trading 2 (P)L\Delicious trading 2 (P)LSH.fpt Object is locked skipped
G:\Annual financial statements\WIP\2007\Delicious trading 2 (P)L\Delicious trading 2 (P)LTM.cdx Object is locked skipped
G:\Annual financial statements\WIP\2007\Delicious trading 2 (P)L\Delicious trading 2 (P)LTM.dbf Object is locked skipped
G:\Annual financial statements\WIP\2007\Delicious trading 2 (P)L\Delicious trading 2 (P)LTP.cdx Object is locked skipped
G:\Annual financial statements\WIP\2007\Delicious trading 2 (P)L\Delicious trading 2 (P)LTP.dbf Object is locked skipped
G:\Annual financial statements\WIP\2007\Delicious trading 2 (P)L\Delicious trading 2 (P)LTS.cdx Object is locked skipped
G:\Annual financial statements\WIP\2007\Delicious trading 2 (P)L\Delicious trading 2 (P)LTS.dbf Object is locked skipped
G:\Annual financial statements\WIP\2007\Delicious trading 2 (P)L\Delicious trading 2 (P)LTS.fpt Object is locked skipped
G:\Annual financial statements\WIP\2007\Delicious trading 2 (P)L\Delicious trading 2 (P)LWR.cdx Object is locked skipped
G:\Annual financial statements\WIP\2007\Delicious trading 2 (P)L\Delicious trading 2 (P)LWR.dbf Object is locked skipped
G:\Annual financial statements\WIP\2007\Delicious trading 2 (P)L\Delicious trading 2 (P)LWR.fpt Object is locked skipped
G:\Annual financial statements\WIP\2007\Delicious trading 2 (P)L\Delicious trading 2 (P)LWT.cdx Object is locked skipped
G:\Annual financial statements\WIP\2007\Delicious trading 2 (P)L\Delicious trading 2 (P)LWT.dbf Object is locked skipped
Scan process completed.
Your help will be greatly appreciated, thanks.