Random Passerby
2008-06-01, 06:26
:sad: Been working at getting rid of the Virtuomonde Trojan...but it never disappears...Any help would be greatly appreciated. Thank you for your time in advanced!
HJT Log:
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 5:32:39 PM, on 31/05/2008
Platform: Windows Vista (WinNT 6.00.1904)
MSIE: Internet Explorer v7.00 (7.00.6000.16643)
Boot mode: Safe mode with network support
Running processes:
C:\Program Files\Windows Media Player\wmpnscfg.exe
C:\Program Files\Windows Live\Messenger\msnmsgr.exe
C:\Windows\explorer.exe
C:\Program Files\Grisoft\AVG7\avgwb.dat
C:\Program Files\Nero\Nero8\Nero Burning Rom\nero.exe
C:\Program Files\Spybot - Search & Destroy\SpybotSD.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\Adobe\Reader 8.0\Reader\AcroRd32Info.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://xenophase.net/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iehome&locale=EN_US&c=73&bd=Pavilion&pf=desktop
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iehome&locale=EN_US&c=73&bd=Pavilion&pf=desktop
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
R3 - URLSearchHook: Winamp Search Class - {57BCA5FA-5DBB-45a2-B558-1755C3F6253B} - C:\Program Files\Winamp Toolbar\winamptb.dll
O1 - Hosts: ::1 localhost
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: Winamp Toolbar Loader - {25CEE8EC-5730-41bc-8B58-22DDC8AB8C20} - C:\Program Files\Winamp Toolbar\winamptb.dll
O2 - BHO: BitComet ClickCapture - {39F7E362-828A-4B5A-BCAF-5B79BFDFEA60} - C:\Program Files\BitComet\tools\BitCometBHO_1.2.2.28.dll
O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\PROGRA~1\MICROS~3\Office12\GRA8E1~1.DLL
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar1.dll
O2 - BHO: WebPerform - {AB692F9B-27FE-4511-8885-ED62BB45197B} - C:\Windows\system32\webperform.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll
O3 - Toolbar: Winamp Toolbar - {EBF2BA02-9094-4c5a-858B-BB198F3D8DE2} - C:\Program Files\Winamp Toolbar\winamptb.dll
O4 - HKLM\..\Run: [Windows Defender] %ProgramFiles%\Windows Defender\MSASCui.exe -hide
O4 - HKLM\..\Run: [hpsysdrv] c:\hp\support\hpsysdrv.exe
O4 - HKLM\..\Run: [KBD] C:\HP\KBD\KbdStub.EXE
O4 - HKLM\..\Run: [OsdMaestro] "C:\Program Files\Hewlett-Packard\On-Screen OSD Indicator\OSD.exe"
O4 - HKLM\..\Run: [SnapfishMediaDetector] C:\Program Files\Snapfish Media Detector\SnapfishMediaDetector.exe
O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\Grisoft\AVG7\avgcc.exe /STARTUP
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [NvSvc] RUNDLL32.EXE C:\Windows\system32\nvsvc.dll,nvsvcStart
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\Windows\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\Windows\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [WinampAgent] "C:\Program Files\Winamp\winampa.exe"
O4 - HKLM\..\Run: [HP Component Manager] "C:\Program Files\HP\hpcoretech\hpcmpmgr.exe"
O4 - HKLM\..\Run: [DXDllRegExe] dxdllreg.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe"
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [RtHDVCpl] RtHDVCpl.exe
O4 - HKLM\..\Run: [GrooveMonitor] "C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe"
O4 - HKLM\..\Run: [MSServer] rundll32.exe C:\Windows\system32\jkkKBrSM.dll,#1
O4 - HKLM\..\Run: [NBKeyScan] "C:\Program Files\Nero\Nero8\Nero BackItUp\NBKeyScan.exe"
O4 - HKLM\..\RunOnce: [Launcher] %WINDIR%\SMINST\launcher.exe
O4 - HKCU\..\Run: [Sidebar] C:\Program Files\Windows Sidebar\sidebar.exe /autoRun
O4 - HKCU\..\Run: [HPADVISOR] C:\Program Files\Hewlett-Packard\HP Advisor\HPAdvisor.exe autoRun
O4 - HKCU\..\Run: [ehTray.exe] C:\Windows\ehome\ehTray.exe
O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\1.2.1128.5462\GoogleToolbarNotifier.exe
O4 - HKCU\..\Run: [WMPNSCFG] C:\Program Files\Windows Media Player\WMPNSCFG.exe
O4 - HKCU\..\Run: [IndxStoreSvr_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] "C:\Program Files\Common Files\Nero\Lib\NMIndexStoreSvr.exe" ASO-616B5711-6DAE-4795-A05F-39A1E5104020
O4 - HKCU\..\Run: [MSServer] rundll32.exe C:\Users\k625\AppData\Local\Temp\urqOGXqR.dll,#1
O4 - HKCU\..\Run: [28f09281] rundll32.exe "C:\Users\k625\AppData\Local\Temp\jexbhoyx.dll",b
O4 - HKCU\..\Run: [cmds] rundll32.exe C:\Users\k625\AppData\Local\Temp\hgGxUNHy.dll,c
O4 - HKCU\..\Run: Rundll32.exe "C:\Users\k625\AppData\Local\Temp\hoggvrky.dll",s
O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-19\..\Run: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCenter (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-19\..\Run: [AVG7_Run] C:\PROGRA~1\Grisoft\AVG7\avgw.exe /RUNONCE (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-18\..\Run: [AVG7_Run] C:\PROGRA~1\Grisoft\AVG7\avgw.exe /RUNONCE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [AVG7_Run] C:\PROGRA~1\Grisoft\AVG7\avgw.exe /RUNONCE (User 'Default user')
O4 - Startup: OneNote 2007 Screen Clipper and Launcher.lnk = C:\Program Files\Microsoft Office\Office12\ONENOTEM.EXE
O4 - Startup: Rainmeter.lnk = C:\Program Files\Rainmeter\Rainmeter.exe
O4 - Startup: Stardock ObjectDock.lnk = C:\Program Files\Stardock\ObjectDock\ObjectDock.exe
O4 - Global Startup: msadvisor.exe
O4 - Global Startup: Snapfish Media Detector.lnk = C:\Program Files\Snapfish Media Detector\SnapfishMediaDetector.exe
O8 - Extra context menu item: &D&ownload &with BitComet - res://C:\Program Files\BitComet\BitComet.exe/AddLink.htm
O8 - Extra context menu item: &D&ownload all video with BitComet - res://C:\Program Files\BitComet\BitComet.exe/AddVideo.htm
O8 - Extra context menu item: &D&ownload all with BitComet - res://C:\Program Files\BitComet\BitComet.exe/AddAllLink.htm
O8 - Extra context menu item: &Winamp Search - C:\ProgramData\Winamp Toolbar\ieToolbar\resources\en-US\local\search.html
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~3\Office12\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
O9 - Extra button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~3\Office12\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: S&end to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~3\Office12\ONBttnIE.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~3\Office12\REFIEBAR.DLL
O9 - Extra button: BitComet - {D18A0B52-D63C-4ed0-AFC6-C1E3DC1AF43A} - res://C:\Program Files\BitComet\tools\BitCometBHO_1.2.2.28.dll/206 (file missing)
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O13 - Gopher Prefix:
O18 - Protocol: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - C:\PROGRA~1\MICROS~3\Office12\GR99D3~1.DLL
O20 - Winlogon Notify: avgwlntf - C:\Windows\SYSTEM32\avgwlntf.dll
O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe
O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe
O23 - Service: AVG7 Resident Shield Service (AvgCoreSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgrssvc.exe
O23 - Service: AVG E-mail Scanner (AVGEMS) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgemc.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - c:\Program Files\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe
O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - c:\Program Files\Common Files\LightScribe\LSSrvc.exe
O23 - Service: Nero BackItUp Scheduler 3 - Nero AG - C:\Program Files\Nero\Nero8\Nero BackItUp\NBService.exe
O23 - Service: NMIndexingService - Nero AG - C:\Program Files\Common Files\Nero\Lib\NMIndexingService.exe
O23 - Service: npkcmsvc - INCA Internet Co., Ltd. - C:\Nexon\Mabinogi\npkcmsvc.exe
O23 - Service: PLFlash DeviceIoControl Service - Prolific Technology Inc. - C:\Windows\system32\IoctlSvc.exe
O23 - Service: RoxMediaDB9 - Sonic Solutions - c:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxMediaDB9.exe
O23 - Service: SBSD Security Center Service (SBSDWSCService) - Safer Networking Ltd. - C:\Program Files\Spybot - Search & Destroy\SDWinSec.exe
O23 - Service: stllssvr - MicroVision Development, Inc. - c:\Program Files\Common Files\SureThing Shared\stllssvr.exe
O23 - Service: XAudioService - Conexant Systems, Inc. - C:\Windows\system32\DRIVERS\xaudio.exe
--
End of file - 10687 bytes
[B]Kaspersky Report
-------------------------------------------------------------------------------
KASPERSKY ONLINE SCANNER REPORT
Saturday, May 31, 2008 8:11:50 PM
Operating System: Microsoft Windows Vista Home Edition, (Build 6000)
Kaspersky Online Scanner version: 5.0.98.0
Kaspersky Anti-Virus database last update: 31/05/2008
Kaspersky Anti-Virus database records: 819549
-------------------------------------------------------------------------------
Scan Settings:
Scan using the following antivirus database: extended
Scan Archives: true
Scan Mail Bases: true
Scan Target - My Computer:
C:\
D:\
E:\
F:\
G:\
H:\
I:\
Scan Statistics:
Total number of scanned objects: 185294
Number of viruses found: 5
Number of infected objects: 34
Number of suspicious objects: 0
Duration of the scan process: 02:11:04
Infected Object Name / Virus Name / Last Action
C:\$Recycle.Bin\S-1-5-21-2082219412-4052029633-3517061324-1000\$RFMA7PT.rar/Nero-8.3.2.1_eng_f.u.l.l/Nero-8.3.2.1_eng_trial_2.exe/data0000.cab/NERO-8~1.EXE/Toolbar.exe Infected: not-a-virus:AdTool.Win32.MyWebSearch.bm skipped
C:\$Recycle.Bin\S-1-5-21-2082219412-4052029633-3517061324-1000\$RFMA7PT.rar/Nero-8.3.2.1_eng_f.u.l.l/Nero-8.3.2.1_eng_trial_2.exe/data0000.cab/NERO-8~1.EXE Infected: not-a-virus:AdTool.Win32.MyWebSearch.bm skipped
C:\$Recycle.Bin\S-1-5-21-2082219412-4052029633-3517061324-1000\$RFMA7PT.rar/Nero-8.3.2.1_eng_f.u.l.l/Nero-8.3.2.1_eng_trial_2.exe/data0000.cab Infected: not-a-virus:AdTool.Win32.MyWebSearch.bm skipped
C:\$Recycle.Bin\S-1-5-21-2082219412-4052029633-3517061324-1000\$RFMA7PT.rar/Nero-8.3.2.1_eng_f.u.l.l/Nero-8.3.2.1_eng_trial_2.exe Infected: not-a-virus:AdTool.Win32.MyWebSearch.bm skipped
C:\$Recycle.Bin\S-1-5-21-2082219412-4052029633-3517061324-1000\$RFMA7PT.rar RAR: infected - 4 skipped
C:\Boot\BCD Object is locked skipped
C:\Boot\BCD.LOG Object is locked skipped
C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\1ed9b1b05f2aa109a72079fc7f60a9a3_46c94899-1d93-4a6a-bdfe-0f23b5092831 Object is locked skipped
C:\ProgramData\Microsoft\Windows Defender\Support\MPLog-11022006-050241.log Object is locked skipped
C:\System Volume Information\MountPointManagerRemoteDatabase Object is locked skipped
C:\Users\k625\AppData\Local\Microsoft\Feeds Cache\index.dat Object is locked skipped
C:\Users\k625\AppData\Local\Microsoft\Internet Explorer\MSIMGSIZ.DAT Object is locked skipped
C:\Users\k625\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat Object is locked skipped
C:\Users\k625\AppData\Local\Microsoft\Windows\History\History.IE5\MSHist012008053120080601\index.dat Object is locked skipped
C:\Users\k625\AppData\Local\Microsoft\Windows\Temporary Internet Files\AntiPhishing\B3BB5BBA-E7D5-40AB-A041-A5B1C0B26C8F.dat Object is locked skipped
C:\Users\k625\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\7VE7I117\kb456456[1] Infected: not-a-virus:AdWare.Win32.Virtumonde.vqd skipped
C:\Users\k625\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\7VE7I117\kb516107[1] Infected: not-a-virus:AdWare.Win32.Virtumonde.vqh skipped
C:\Users\k625\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat Object is locked skipped
C:\Users\k625\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\X3QRNCBG\kb767887CA1Z4D80 Infected: not-a-virus:AdWare.Win32.Virtumonde.wdd skipped
C:\Users\k625\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\X3QRNCBG\kb767887CA1ZP09N Infected: not-a-virus:AdWare.Win32.Virtumonde.wdd skipped
C:\Users\k625\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\X3QRNCBG\kb767887CA24QA2N Infected: not-a-virus:AdWare.Win32.Virtumonde.wdd skipped
C:\Users\k625\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\X3QRNCBG\kb767887CA2GHEJR Infected: not-a-virus:AdWare.Win32.Virtumonde.wdd skipped
C:\Users\k625\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\X3QRNCBG\kb767887CA2T80ZT Infected: not-a-virus:AdWare.Win32.Virtumonde.wdd skipped
C:\Users\k625\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\X3QRNCBG\kb767887CA4HG2QH Infected: not-a-virus:AdWare.Win32.Virtumonde.wdd skipped
C:\Users\k625\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\X3QRNCBG\kb767887CA4SQP8X Infected: not-a-virus:AdWare.Win32.Virtumonde.wdd skipped
C:\Users\k625\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\X3QRNCBG\kb767887CA5VO5PR Infected: not-a-virus:AdWare.Win32.Virtumonde.wdd skipped
C:\Users\k625\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\X3QRNCBG\kb767887CA6VDDTN Infected: not-a-virus:AdWare.Win32.Virtumonde.wdd skipped
C:\Users\k625\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\X3QRNCBG\kb767887CA804FTM Infected: not-a-virus:AdWare.Win32.Virtumonde.wdd skipped
C:\Users\k625\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\X3QRNCBG\kb767887CACGRBL1 Infected: not-a-virus:AdWare.Win32.Virtumonde.wdd skipped
C:\Users\k625\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\X3QRNCBG\kb767887CAD2QT7H Infected: not-a-virus:AdWare.Win32.Virtumonde.wdd skipped
C:\Users\k625\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\X3QRNCBG\kb767887CAL239AK Infected: not-a-virus:AdWare.Win32.Virtumonde.wdd skipped
C:\Users\k625\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\X3QRNCBG\kb767887CARY17Q2 Infected: not-a-virus:AdWare.Win32.Virtumonde.wdd skipped
C:\Users\k625\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\X3QRNCBG\kb767887CAS17RV7 Infected: not-a-virus:AdWare.Win32.Virtumonde.wdd skipped
C:\Users\k625\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\X3QRNCBG\kb767887CAS7I8MU Infected: not-a-virus:AdWare.Win32.Virtumonde.wdd skipped
C:\Users\k625\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\X3QRNCBG\kb767887CASM2KZM Infected: not-a-virus:AdWare.Win32.Virtumonde.wdd skipped
C:\Users\k625\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\X3QRNCBG\kb767887CATC2LJB Infected: not-a-virus:AdWare.Win32.Virtumonde.wdd skipped
C:\Users\k625\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\X3QRNCBG\kb767887CATZWYQ0 Infected: not-a-virus:AdWare.Win32.Virtumonde.wdd skipped
C:\Users\k625\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\X3QRNCBG\kb767887CAXO4NDS Infected: not-a-virus:AdWare.Win32.Virtumonde.wdd skipped
C:\Users\k625\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\X3QRNCBG\kb767887CAZM15EX Infected: not-a-virus:AdWare.Win32.Virtumonde.wdd skipped
C:\Users\k625\AppData\Local\Microsoft\Windows\UsrClass.dat Object is locked skipped
C:\Users\k625\AppData\Local\Microsoft\Windows\UsrClass.dat.LOG1 Object is locked skipped
C:\Users\k625\AppData\Local\Microsoft\Windows\UsrClass.dat.LOG2 Object is locked skipped
C:\Users\k625\AppData\Local\Microsoft\Windows\UsrClass.dat{95eb5394-bca0-11dc-a932-001bb987dc11}.TM.blf Object is locked skipped
C:\Users\k625\AppData\Local\Microsoft\Windows\UsrClass.dat{95eb5394-bca0-11dc-a932-001bb987dc11}.TMContainer00000000000000000001.regtrans-ms Object is locked skipped
C:\Users\k625\AppData\Local\Microsoft\Windows\UsrClass.dat{95eb5394-bca0-11dc-a932-001bb987dc11}.TMContainer00000000000000000002.regtrans-ms Object is locked skipped
C:\Users\k625\AppData\Local\Microsoft\Windows\WER\ReportArchive\Report0c33531e\Report.cab/urqOGXqR.dll.xor Infected: Trojan.Win32.Agent.qrv skipped
C:\Users\k625\AppData\Local\Microsoft\Windows\WER\ReportArchive\Report0c33531e\Report.cab CAB: infected - 1 skipped
C:\Users\k625\AppData\Local\Microsoft\Windows\WER\ReportArchive\Report0c6a9433\Report.cab/fccyvUnL.dll.xor Infected: Trojan.Win32.Agent.qrv skipped
C:\Users\k625\AppData\Local\Microsoft\Windows\WER\ReportArchive\Report0c6a9433\Report.cab CAB: infected - 1 skipped
C:\Users\k625\AppData\Local\Microsoft\Windows\WER\ReportArchive\Report0c6e3ee3\Report.cab/hgGabCUN.dll.xor Infected: Trojan.Win32.Agent.qrv skipped
C:\Users\k625\AppData\Local\Microsoft\Windows\WER\ReportArchive\Report0c6e3ee3\Report.cab CAB: infected - 1 skipped
C:\Users\k625\AppData\Local\Microsoft\Windows Live Contacts\endless-serenade@hotmail.com\real\members.stg Object is locked skipped
C:\Users\k625\AppData\Local\Microsoft\Windows Live Contacts\endless-serenade@hotmail.com\shadow\members.stg Object is locked skipped
C:\Users\k625\AppData\Local\Mozilla\Firefox\Profiles\oxbg8rgu.default\Cache\_CACHE_001_ Object is locked skipped
C:\Users\k625\AppData\Local\Mozilla\Firefox\Profiles\oxbg8rgu.default\Cache\_CACHE_002_ Object is locked skipped
C:\Users\k625\AppData\Local\Mozilla\Firefox\Profiles\oxbg8rgu.default\Cache\_CACHE_003_ Object is locked skipped
C:\Users\k625\AppData\Local\Mozilla\Firefox\Profiles\oxbg8rgu.default\Cache\_CACHE_MAP_ Object is locked skipped
C:\Users\k625\AppData\Local\Mozilla\Firefox\Profiles\oxbg8rgu.default\XUL.mfl Object is locked skipped
C:\Users\k625\AppData\Local\Temp\~DF2339.tmp Object is locked skipped
C:\Users\k625\AppData\Local\Temp\~DF2343.tmp Object is locked skipped
C:\Users\k625\AppData\Local\Temp\~DFB8A7.tmp Object is locked skipped
C:\Users\k625\AppData\Local\Temp\~DFF156.tmp Object is locked skipped
C:\Users\k625\AppData\Local\Temp\~DFF227.tmp Object is locked skipped
C:\Users\k625\AppData\Roaming\Microsoft\Windows\Cookies\index.dat Object is locked skipped
C:\Users\k625\AppData\Roaming\Mozilla\Firefox\Profiles\oxbg8rgu.default\cert8.db Object is locked skipped
C:\Users\k625\AppData\Roaming\Mozilla\Firefox\Profiles\oxbg8rgu.default\formhistory.dat Object is locked skipped
C:\Users\k625\AppData\Roaming\Mozilla\Firefox\Profiles\oxbg8rgu.default\history.dat Object is locked skipped
C:\Users\k625\AppData\Roaming\Mozilla\Firefox\Profiles\oxbg8rgu.default\key3.db Object is locked skipped
C:\Users\k625\AppData\Roaming\Mozilla\Firefox\Profiles\oxbg8rgu.default\parent.lock Object is locked skipped
C:\Users\k625\AppData\Roaming\Mozilla\Firefox\Profiles\oxbg8rgu.default\search.sqlite Object is locked skipped
C:\Users\k625\AppData\Roaming\Mozilla\Firefox\Profiles\oxbg8rgu.default\urlclassifier2.sqlite Object is locked skipped
C:\Users\k625\Documents\My Chat Logs\May 2008\a_b248@hotmail.com.html Object is locked skipped
C:\Users\k625\ntuser.dat Object is locked skipped
C:\Users\k625\ntuser.dat.LOG1 Object is locked skipped
C:\Users\k625\ntuser.dat.LOG2 Object is locked skipped
C:\Users\k625\ntuser.dat{28a3e59d-2ed4-11dd-9ed5-001bb987dc11}.TM.blf Object is locked skipped
C:\Users\k625\ntuser.dat{28a3e59d-2ed4-11dd-9ed5-001bb987dc11}.TMContainer00000000000000000001.regtrans-ms Object is locked skipped
C:\Users\k625\ntuser.dat{28a3e59d-2ed4-11dd-9ed5-001bb987dc11}.TMContainer00000000000000000002.regtrans-ms Object is locked skipped
C:\Windows\Debug\PASSWD.LOG Object is locked skipped
C:\Windows\Debug\sam.log Object is locked skipped
C:\Windows\ServiceProfiles\LocalService\AppData\Local\lastalive0.dat Object is locked skipped
C:\Windows\ServiceProfiles\LocalService\AppData\Local\lastalive1.dat Object is locked skipped
C:\Windows\ServiceProfiles\LocalService\ntuser.dat Object is locked skipped
C:\Windows\ServiceProfiles\LocalService\ntuser.dat.LOG1 Object is locked skipped
C:\Windows\ServiceProfiles\LocalService\ntuser.dat.LOG2 Object is locked skipped
C:\Windows\ServiceProfiles\LocalService\NTUSER.DAT{3a539869-6a70-11db-887c-d362bd253390}.TM.blf Object is locked skipped
C:\Windows\ServiceProfiles\LocalService\NTUSER.DAT{3a539869-6a70-11db-887c-d362bd253390}.TMContainer00000000000000000001.regtrans-ms Object is locked skipped
C:\Windows\ServiceProfiles\LocalService\NTUSER.DAT{3a539869-6a70-11db-887c-d362bd253390}.TMContainer00000000000000000002.regtrans-ms Object is locked skipped
C:\Windows\ServiceProfiles\NetworkService\ntuser.dat Object is locked skipped
C:\Windows\ServiceProfiles\NetworkService\ntuser.dat.LOG1 Object is locked skipped
C:\Windows\ServiceProfiles\NetworkService\ntuser.dat.LOG2 Object is locked skipped
C:\Windows\ServiceProfiles\NetworkService\NTUSER.DAT{3a539865-6a70-11db-887c-d362bd253390}.TM.blf Object is locked skipped
C:\Windows\ServiceProfiles\NetworkService\NTUSER.DAT{3a539865-6a70-11db-887c-d362bd253390}.TMContainer00000000000000000001.regtrans-ms Object is locked skipped
C:\Windows\ServiceProfiles\NetworkService\NTUSER.DAT{3a539865-6a70-11db-887c-d362bd253390}.TMContainer00000000000000000002.regtrans-ms Object is locked skipped
C:\Windows\System32\catroot2\edb.log Object is locked skipped
C:\Windows\System32\catroot2\{127D0A1D-4EF2-11D1-8608-00C04FC295EE}\catdb Object is locked skipped
C:\Windows\System32\catroot2\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\catdb Object is locked skipped
C:\Windows\System32\config\components Object is locked skipped
C:\Windows\System32\config\COMPONENTS.LOG1 Object is locked skipped
C:\Windows\System32\config\COMPONENTS.LOG2 Object is locked skipped
C:\Windows\System32\config\default Object is locked skipped
C:\Windows\System32\config\DEFAULT.LOG1 Object is locked skipped
C:\Windows\System32\config\DEFAULT.LOG2 Object is locked skipped
C:\Windows\System32\config\RegBack\COMPONENTS Object is locked skipped
C:\Windows\System32\config\RegBack\DEFAULT Object is locked skipped
C:\Windows\System32\config\RegBack\SAM Object is locked skipped
C:\Windows\System32\config\RegBack\SECURITY Object is locked skipped
C:\Windows\System32\config\RegBack\SOFTWARE Object is locked skipped
C:\Windows\System32\config\RegBack\SYSTEM Object is locked skipped
C:\Windows\System32\config\sam Object is locked skipped
C:\Windows\System32\config\SAM.LOG1 Object is locked skipped
C:\Windows\System32\config\SAM.LOG2 Object is locked skipped
C:\Windows\System32\config\security Object is locked skipped
C:\Windows\System32\config\SECURITY.LOG1 Object is locked skipped
C:\Windows\System32\config\SECURITY.LOG2 Object is locked skipped
C:\Windows\System32\config\software Object is locked skipped
C:\Windows\System32\config\SOFTWARE.LOG1 Object is locked skipped
C:\Windows\System32\config\SOFTWARE.LOG2 Object is locked skipped
C:\Windows\System32\config\system Object is locked skipped
C:\Windows\System32\config\SYSTEM.LOG1 Object is locked skipped
C:\Windows\System32\config\SYSTEM.LOG2 Object is locked skipped
C:\Windows\System32\config\TxR\{250834b7-750c-494d-bdc3-da86b6e2101a}.TxR.0.regtrans-ms Object is locked skipped
C:\Windows\System32\config\TxR\{250834b7-750c-494d-bdc3-da86b6e2101a}.TxR.1.regtrans-ms Object is locked skipped
C:\Windows\System32\config\TxR\{250834b7-750c-494d-bdc3-da86b6e2101a}.TxR.2.regtrans-ms Object is locked skipped
C:\Windows\System32\config\TxR\{250834b7-750c-494d-bdc3-da86b6e2101a}.TxR.blf Object is locked skipped
C:\Windows\System32\config\TxR\{250834B7-750C-494d-BDC3-DA86B6E2101B}.TM.blf Object is locked skipped
C:\Windows\System32\config\TxR\{250834B7-750C-494d-BDC3-DA86B6E2101B}.TMContainer00000000000000000001.regtrans-ms Object is locked skipped
C:\Windows\System32\config\TxR\{250834B7-750C-494d-BDC3-DA86B6E2101B}.TMContainer00000000000000000002.regtrans-ms Object is locked skipped
C:\Windows\System32\LogFiles\Scm\SCM.EVM Object is locked skipped
C:\Windows\System32\LogFiles\WMI\RtBackup\EtwRTMsMpPsSession.etl Object is locked skipped
C:\Windows\System32\wbem\Logs\WMITracing.log Object is locked skipped
C:\Windows\System32\wbem\repository\INDEX.BTR Object is locked skipped
C:\Windows\System32\wbem\repository\MAPPING1.MAP Object is locked skipped
C:\Windows\System32\wbem\repository\MAPPING2.MAP Object is locked skipped
C:\Windows\System32\wbem\repository\OBJECTS.DATA Object is locked skipped
C:\Windows\System32\WDI\LogFiles\WdiContextLog.etl.003 Object is locked skipped
C:\Windows\System32\wfp\wfpdiag.etl Object is locked skipped
C:\Windows\System32\winevt\Logs\Application.evtx Object is locked skipped
C:\Windows\System32\winevt\Logs\DFS Replication.evtx Object is locked skipped
C:\Windows\System32\winevt\Logs\HardwareEvents.evtx Object is locked skipped
C:\Windows\System32\winevt\Logs\Internet Explorer.evtx Object is locked skipped
C:\Windows\System32\winevt\Logs\Key Management Service.evtx Object is locked skipped
C:\Windows\System32\winevt\Logs\Media Center.evtx Object is locked skipped
C:\Windows\System32\winevt\Logs\Microsoft-Windows-CodeIntegrity%4Operational.evtx Object is locked skipped
C:\Windows\System32\winevt\Logs\Microsoft-Windows-International%4Operational.evtx Object is locked skipped
C:\Windows\System32\winevt\Logs\Microsoft-Windows-Kernel-WHEA.evtx Object is locked skipped
C:\Windows\System32\winevt\Logs\Microsoft-Windows-NetworkAccessProtection%4Operational.evtx Object is locked skipped
C:\Windows\System32\winevt\Logs\ODiag.evtx Object is locked skipped
C:\Windows\System32\winevt\Logs\OSession.evtx Object is locked skipped
C:\Windows\System32\winevt\Logs\Security.evtx Object is locked skipped
C:\Windows\System32\winevt\Logs\Setup.evtx Object is locked skipped
C:\Windows\System32\winevt\Logs\System.evtx Object is locked skipped
D:\System Volume Information\MountPointManagerRemoteDatabase Object is locked skipped
Scan process completed.
HJT Log:
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 5:32:39 PM, on 31/05/2008
Platform: Windows Vista (WinNT 6.00.1904)
MSIE: Internet Explorer v7.00 (7.00.6000.16643)
Boot mode: Safe mode with network support
Running processes:
C:\Program Files\Windows Media Player\wmpnscfg.exe
C:\Program Files\Windows Live\Messenger\msnmsgr.exe
C:\Windows\explorer.exe
C:\Program Files\Grisoft\AVG7\avgwb.dat
C:\Program Files\Nero\Nero8\Nero Burning Rom\nero.exe
C:\Program Files\Spybot - Search & Destroy\SpybotSD.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\Adobe\Reader 8.0\Reader\AcroRd32Info.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://xenophase.net/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iehome&locale=EN_US&c=73&bd=Pavilion&pf=desktop
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iehome&locale=EN_US&c=73&bd=Pavilion&pf=desktop
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
R3 - URLSearchHook: Winamp Search Class - {57BCA5FA-5DBB-45a2-B558-1755C3F6253B} - C:\Program Files\Winamp Toolbar\winamptb.dll
O1 - Hosts: ::1 localhost
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: Winamp Toolbar Loader - {25CEE8EC-5730-41bc-8B58-22DDC8AB8C20} - C:\Program Files\Winamp Toolbar\winamptb.dll
O2 - BHO: BitComet ClickCapture - {39F7E362-828A-4B5A-BCAF-5B79BFDFEA60} - C:\Program Files\BitComet\tools\BitCometBHO_1.2.2.28.dll
O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\PROGRA~1\MICROS~3\Office12\GRA8E1~1.DLL
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar1.dll
O2 - BHO: WebPerform - {AB692F9B-27FE-4511-8885-ED62BB45197B} - C:\Windows\system32\webperform.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll
O3 - Toolbar: Winamp Toolbar - {EBF2BA02-9094-4c5a-858B-BB198F3D8DE2} - C:\Program Files\Winamp Toolbar\winamptb.dll
O4 - HKLM\..\Run: [Windows Defender] %ProgramFiles%\Windows Defender\MSASCui.exe -hide
O4 - HKLM\..\Run: [hpsysdrv] c:\hp\support\hpsysdrv.exe
O4 - HKLM\..\Run: [KBD] C:\HP\KBD\KbdStub.EXE
O4 - HKLM\..\Run: [OsdMaestro] "C:\Program Files\Hewlett-Packard\On-Screen OSD Indicator\OSD.exe"
O4 - HKLM\..\Run: [SnapfishMediaDetector] C:\Program Files\Snapfish Media Detector\SnapfishMediaDetector.exe
O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\Grisoft\AVG7\avgcc.exe /STARTUP
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [NvSvc] RUNDLL32.EXE C:\Windows\system32\nvsvc.dll,nvsvcStart
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\Windows\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\Windows\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [WinampAgent] "C:\Program Files\Winamp\winampa.exe"
O4 - HKLM\..\Run: [HP Component Manager] "C:\Program Files\HP\hpcoretech\hpcmpmgr.exe"
O4 - HKLM\..\Run: [DXDllRegExe] dxdllreg.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe"
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [RtHDVCpl] RtHDVCpl.exe
O4 - HKLM\..\Run: [GrooveMonitor] "C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe"
O4 - HKLM\..\Run: [MSServer] rundll32.exe C:\Windows\system32\jkkKBrSM.dll,#1
O4 - HKLM\..\Run: [NBKeyScan] "C:\Program Files\Nero\Nero8\Nero BackItUp\NBKeyScan.exe"
O4 - HKLM\..\RunOnce: [Launcher] %WINDIR%\SMINST\launcher.exe
O4 - HKCU\..\Run: [Sidebar] C:\Program Files\Windows Sidebar\sidebar.exe /autoRun
O4 - HKCU\..\Run: [HPADVISOR] C:\Program Files\Hewlett-Packard\HP Advisor\HPAdvisor.exe autoRun
O4 - HKCU\..\Run: [ehTray.exe] C:\Windows\ehome\ehTray.exe
O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\1.2.1128.5462\GoogleToolbarNotifier.exe
O4 - HKCU\..\Run: [WMPNSCFG] C:\Program Files\Windows Media Player\WMPNSCFG.exe
O4 - HKCU\..\Run: [IndxStoreSvr_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] "C:\Program Files\Common Files\Nero\Lib\NMIndexStoreSvr.exe" ASO-616B5711-6DAE-4795-A05F-39A1E5104020
O4 - HKCU\..\Run: [MSServer] rundll32.exe C:\Users\k625\AppData\Local\Temp\urqOGXqR.dll,#1
O4 - HKCU\..\Run: [28f09281] rundll32.exe "C:\Users\k625\AppData\Local\Temp\jexbhoyx.dll",b
O4 - HKCU\..\Run: [cmds] rundll32.exe C:\Users\k625\AppData\Local\Temp\hgGxUNHy.dll,c
O4 - HKCU\..\Run: Rundll32.exe "C:\Users\k625\AppData\Local\Temp\hoggvrky.dll",s
O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-19\..\Run: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCenter (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-19\..\Run: [AVG7_Run] C:\PROGRA~1\Grisoft\AVG7\avgw.exe /RUNONCE (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-18\..\Run: [AVG7_Run] C:\PROGRA~1\Grisoft\AVG7\avgw.exe /RUNONCE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [AVG7_Run] C:\PROGRA~1\Grisoft\AVG7\avgw.exe /RUNONCE (User 'Default user')
O4 - Startup: OneNote 2007 Screen Clipper and Launcher.lnk = C:\Program Files\Microsoft Office\Office12\ONENOTEM.EXE
O4 - Startup: Rainmeter.lnk = C:\Program Files\Rainmeter\Rainmeter.exe
O4 - Startup: Stardock ObjectDock.lnk = C:\Program Files\Stardock\ObjectDock\ObjectDock.exe
O4 - Global Startup: msadvisor.exe
O4 - Global Startup: Snapfish Media Detector.lnk = C:\Program Files\Snapfish Media Detector\SnapfishMediaDetector.exe
O8 - Extra context menu item: &D&ownload &with BitComet - res://C:\Program Files\BitComet\BitComet.exe/AddLink.htm
O8 - Extra context menu item: &D&ownload all video with BitComet - res://C:\Program Files\BitComet\BitComet.exe/AddVideo.htm
O8 - Extra context menu item: &D&ownload all with BitComet - res://C:\Program Files\BitComet\BitComet.exe/AddAllLink.htm
O8 - Extra context menu item: &Winamp Search - C:\ProgramData\Winamp Toolbar\ieToolbar\resources\en-US\local\search.html
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~3\Office12\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
O9 - Extra button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~3\Office12\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: S&end to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~3\Office12\ONBttnIE.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~3\Office12\REFIEBAR.DLL
O9 - Extra button: BitComet - {D18A0B52-D63C-4ed0-AFC6-C1E3DC1AF43A} - res://C:\Program Files\BitComet\tools\BitCometBHO_1.2.2.28.dll/206 (file missing)
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O13 - Gopher Prefix:
O18 - Protocol: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - C:\PROGRA~1\MICROS~3\Office12\GR99D3~1.DLL
O20 - Winlogon Notify: avgwlntf - C:\Windows\SYSTEM32\avgwlntf.dll
O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe
O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe
O23 - Service: AVG7 Resident Shield Service (AvgCoreSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgrssvc.exe
O23 - Service: AVG E-mail Scanner (AVGEMS) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgemc.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - c:\Program Files\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe
O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - c:\Program Files\Common Files\LightScribe\LSSrvc.exe
O23 - Service: Nero BackItUp Scheduler 3 - Nero AG - C:\Program Files\Nero\Nero8\Nero BackItUp\NBService.exe
O23 - Service: NMIndexingService - Nero AG - C:\Program Files\Common Files\Nero\Lib\NMIndexingService.exe
O23 - Service: npkcmsvc - INCA Internet Co., Ltd. - C:\Nexon\Mabinogi\npkcmsvc.exe
O23 - Service: PLFlash DeviceIoControl Service - Prolific Technology Inc. - C:\Windows\system32\IoctlSvc.exe
O23 - Service: RoxMediaDB9 - Sonic Solutions - c:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxMediaDB9.exe
O23 - Service: SBSD Security Center Service (SBSDWSCService) - Safer Networking Ltd. - C:\Program Files\Spybot - Search & Destroy\SDWinSec.exe
O23 - Service: stllssvr - MicroVision Development, Inc. - c:\Program Files\Common Files\SureThing Shared\stllssvr.exe
O23 - Service: XAudioService - Conexant Systems, Inc. - C:\Windows\system32\DRIVERS\xaudio.exe
--
End of file - 10687 bytes
[B]Kaspersky Report
-------------------------------------------------------------------------------
KASPERSKY ONLINE SCANNER REPORT
Saturday, May 31, 2008 8:11:50 PM
Operating System: Microsoft Windows Vista Home Edition, (Build 6000)
Kaspersky Online Scanner version: 5.0.98.0
Kaspersky Anti-Virus database last update: 31/05/2008
Kaspersky Anti-Virus database records: 819549
-------------------------------------------------------------------------------
Scan Settings:
Scan using the following antivirus database: extended
Scan Archives: true
Scan Mail Bases: true
Scan Target - My Computer:
C:\
D:\
E:\
F:\
G:\
H:\
I:\
Scan Statistics:
Total number of scanned objects: 185294
Number of viruses found: 5
Number of infected objects: 34
Number of suspicious objects: 0
Duration of the scan process: 02:11:04
Infected Object Name / Virus Name / Last Action
C:\$Recycle.Bin\S-1-5-21-2082219412-4052029633-3517061324-1000\$RFMA7PT.rar/Nero-8.3.2.1_eng_f.u.l.l/Nero-8.3.2.1_eng_trial_2.exe/data0000.cab/NERO-8~1.EXE/Toolbar.exe Infected: not-a-virus:AdTool.Win32.MyWebSearch.bm skipped
C:\$Recycle.Bin\S-1-5-21-2082219412-4052029633-3517061324-1000\$RFMA7PT.rar/Nero-8.3.2.1_eng_f.u.l.l/Nero-8.3.2.1_eng_trial_2.exe/data0000.cab/NERO-8~1.EXE Infected: not-a-virus:AdTool.Win32.MyWebSearch.bm skipped
C:\$Recycle.Bin\S-1-5-21-2082219412-4052029633-3517061324-1000\$RFMA7PT.rar/Nero-8.3.2.1_eng_f.u.l.l/Nero-8.3.2.1_eng_trial_2.exe/data0000.cab Infected: not-a-virus:AdTool.Win32.MyWebSearch.bm skipped
C:\$Recycle.Bin\S-1-5-21-2082219412-4052029633-3517061324-1000\$RFMA7PT.rar/Nero-8.3.2.1_eng_f.u.l.l/Nero-8.3.2.1_eng_trial_2.exe Infected: not-a-virus:AdTool.Win32.MyWebSearch.bm skipped
C:\$Recycle.Bin\S-1-5-21-2082219412-4052029633-3517061324-1000\$RFMA7PT.rar RAR: infected - 4 skipped
C:\Boot\BCD Object is locked skipped
C:\Boot\BCD.LOG Object is locked skipped
C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\1ed9b1b05f2aa109a72079fc7f60a9a3_46c94899-1d93-4a6a-bdfe-0f23b5092831 Object is locked skipped
C:\ProgramData\Microsoft\Windows Defender\Support\MPLog-11022006-050241.log Object is locked skipped
C:\System Volume Information\MountPointManagerRemoteDatabase Object is locked skipped
C:\Users\k625\AppData\Local\Microsoft\Feeds Cache\index.dat Object is locked skipped
C:\Users\k625\AppData\Local\Microsoft\Internet Explorer\MSIMGSIZ.DAT Object is locked skipped
C:\Users\k625\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat Object is locked skipped
C:\Users\k625\AppData\Local\Microsoft\Windows\History\History.IE5\MSHist012008053120080601\index.dat Object is locked skipped
C:\Users\k625\AppData\Local\Microsoft\Windows\Temporary Internet Files\AntiPhishing\B3BB5BBA-E7D5-40AB-A041-A5B1C0B26C8F.dat Object is locked skipped
C:\Users\k625\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\7VE7I117\kb456456[1] Infected: not-a-virus:AdWare.Win32.Virtumonde.vqd skipped
C:\Users\k625\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\7VE7I117\kb516107[1] Infected: not-a-virus:AdWare.Win32.Virtumonde.vqh skipped
C:\Users\k625\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat Object is locked skipped
C:\Users\k625\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\X3QRNCBG\kb767887CA1Z4D80 Infected: not-a-virus:AdWare.Win32.Virtumonde.wdd skipped
C:\Users\k625\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\X3QRNCBG\kb767887CA1ZP09N Infected: not-a-virus:AdWare.Win32.Virtumonde.wdd skipped
C:\Users\k625\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\X3QRNCBG\kb767887CA24QA2N Infected: not-a-virus:AdWare.Win32.Virtumonde.wdd skipped
C:\Users\k625\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\X3QRNCBG\kb767887CA2GHEJR Infected: not-a-virus:AdWare.Win32.Virtumonde.wdd skipped
C:\Users\k625\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\X3QRNCBG\kb767887CA2T80ZT Infected: not-a-virus:AdWare.Win32.Virtumonde.wdd skipped
C:\Users\k625\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\X3QRNCBG\kb767887CA4HG2QH Infected: not-a-virus:AdWare.Win32.Virtumonde.wdd skipped
C:\Users\k625\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\X3QRNCBG\kb767887CA4SQP8X Infected: not-a-virus:AdWare.Win32.Virtumonde.wdd skipped
C:\Users\k625\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\X3QRNCBG\kb767887CA5VO5PR Infected: not-a-virus:AdWare.Win32.Virtumonde.wdd skipped
C:\Users\k625\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\X3QRNCBG\kb767887CA6VDDTN Infected: not-a-virus:AdWare.Win32.Virtumonde.wdd skipped
C:\Users\k625\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\X3QRNCBG\kb767887CA804FTM Infected: not-a-virus:AdWare.Win32.Virtumonde.wdd skipped
C:\Users\k625\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\X3QRNCBG\kb767887CACGRBL1 Infected: not-a-virus:AdWare.Win32.Virtumonde.wdd skipped
C:\Users\k625\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\X3QRNCBG\kb767887CAD2QT7H Infected: not-a-virus:AdWare.Win32.Virtumonde.wdd skipped
C:\Users\k625\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\X3QRNCBG\kb767887CAL239AK Infected: not-a-virus:AdWare.Win32.Virtumonde.wdd skipped
C:\Users\k625\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\X3QRNCBG\kb767887CARY17Q2 Infected: not-a-virus:AdWare.Win32.Virtumonde.wdd skipped
C:\Users\k625\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\X3QRNCBG\kb767887CAS17RV7 Infected: not-a-virus:AdWare.Win32.Virtumonde.wdd skipped
C:\Users\k625\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\X3QRNCBG\kb767887CAS7I8MU Infected: not-a-virus:AdWare.Win32.Virtumonde.wdd skipped
C:\Users\k625\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\X3QRNCBG\kb767887CASM2KZM Infected: not-a-virus:AdWare.Win32.Virtumonde.wdd skipped
C:\Users\k625\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\X3QRNCBG\kb767887CATC2LJB Infected: not-a-virus:AdWare.Win32.Virtumonde.wdd skipped
C:\Users\k625\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\X3QRNCBG\kb767887CATZWYQ0 Infected: not-a-virus:AdWare.Win32.Virtumonde.wdd skipped
C:\Users\k625\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\X3QRNCBG\kb767887CAXO4NDS Infected: not-a-virus:AdWare.Win32.Virtumonde.wdd skipped
C:\Users\k625\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\X3QRNCBG\kb767887CAZM15EX Infected: not-a-virus:AdWare.Win32.Virtumonde.wdd skipped
C:\Users\k625\AppData\Local\Microsoft\Windows\UsrClass.dat Object is locked skipped
C:\Users\k625\AppData\Local\Microsoft\Windows\UsrClass.dat.LOG1 Object is locked skipped
C:\Users\k625\AppData\Local\Microsoft\Windows\UsrClass.dat.LOG2 Object is locked skipped
C:\Users\k625\AppData\Local\Microsoft\Windows\UsrClass.dat{95eb5394-bca0-11dc-a932-001bb987dc11}.TM.blf Object is locked skipped
C:\Users\k625\AppData\Local\Microsoft\Windows\UsrClass.dat{95eb5394-bca0-11dc-a932-001bb987dc11}.TMContainer00000000000000000001.regtrans-ms Object is locked skipped
C:\Users\k625\AppData\Local\Microsoft\Windows\UsrClass.dat{95eb5394-bca0-11dc-a932-001bb987dc11}.TMContainer00000000000000000002.regtrans-ms Object is locked skipped
C:\Users\k625\AppData\Local\Microsoft\Windows\WER\ReportArchive\Report0c33531e\Report.cab/urqOGXqR.dll.xor Infected: Trojan.Win32.Agent.qrv skipped
C:\Users\k625\AppData\Local\Microsoft\Windows\WER\ReportArchive\Report0c33531e\Report.cab CAB: infected - 1 skipped
C:\Users\k625\AppData\Local\Microsoft\Windows\WER\ReportArchive\Report0c6a9433\Report.cab/fccyvUnL.dll.xor Infected: Trojan.Win32.Agent.qrv skipped
C:\Users\k625\AppData\Local\Microsoft\Windows\WER\ReportArchive\Report0c6a9433\Report.cab CAB: infected - 1 skipped
C:\Users\k625\AppData\Local\Microsoft\Windows\WER\ReportArchive\Report0c6e3ee3\Report.cab/hgGabCUN.dll.xor Infected: Trojan.Win32.Agent.qrv skipped
C:\Users\k625\AppData\Local\Microsoft\Windows\WER\ReportArchive\Report0c6e3ee3\Report.cab CAB: infected - 1 skipped
C:\Users\k625\AppData\Local\Microsoft\Windows Live Contacts\endless-serenade@hotmail.com\real\members.stg Object is locked skipped
C:\Users\k625\AppData\Local\Microsoft\Windows Live Contacts\endless-serenade@hotmail.com\shadow\members.stg Object is locked skipped
C:\Users\k625\AppData\Local\Mozilla\Firefox\Profiles\oxbg8rgu.default\Cache\_CACHE_001_ Object is locked skipped
C:\Users\k625\AppData\Local\Mozilla\Firefox\Profiles\oxbg8rgu.default\Cache\_CACHE_002_ Object is locked skipped
C:\Users\k625\AppData\Local\Mozilla\Firefox\Profiles\oxbg8rgu.default\Cache\_CACHE_003_ Object is locked skipped
C:\Users\k625\AppData\Local\Mozilla\Firefox\Profiles\oxbg8rgu.default\Cache\_CACHE_MAP_ Object is locked skipped
C:\Users\k625\AppData\Local\Mozilla\Firefox\Profiles\oxbg8rgu.default\XUL.mfl Object is locked skipped
C:\Users\k625\AppData\Local\Temp\~DF2339.tmp Object is locked skipped
C:\Users\k625\AppData\Local\Temp\~DF2343.tmp Object is locked skipped
C:\Users\k625\AppData\Local\Temp\~DFB8A7.tmp Object is locked skipped
C:\Users\k625\AppData\Local\Temp\~DFF156.tmp Object is locked skipped
C:\Users\k625\AppData\Local\Temp\~DFF227.tmp Object is locked skipped
C:\Users\k625\AppData\Roaming\Microsoft\Windows\Cookies\index.dat Object is locked skipped
C:\Users\k625\AppData\Roaming\Mozilla\Firefox\Profiles\oxbg8rgu.default\cert8.db Object is locked skipped
C:\Users\k625\AppData\Roaming\Mozilla\Firefox\Profiles\oxbg8rgu.default\formhistory.dat Object is locked skipped
C:\Users\k625\AppData\Roaming\Mozilla\Firefox\Profiles\oxbg8rgu.default\history.dat Object is locked skipped
C:\Users\k625\AppData\Roaming\Mozilla\Firefox\Profiles\oxbg8rgu.default\key3.db Object is locked skipped
C:\Users\k625\AppData\Roaming\Mozilla\Firefox\Profiles\oxbg8rgu.default\parent.lock Object is locked skipped
C:\Users\k625\AppData\Roaming\Mozilla\Firefox\Profiles\oxbg8rgu.default\search.sqlite Object is locked skipped
C:\Users\k625\AppData\Roaming\Mozilla\Firefox\Profiles\oxbg8rgu.default\urlclassifier2.sqlite Object is locked skipped
C:\Users\k625\Documents\My Chat Logs\May 2008\a_b248@hotmail.com.html Object is locked skipped
C:\Users\k625\ntuser.dat Object is locked skipped
C:\Users\k625\ntuser.dat.LOG1 Object is locked skipped
C:\Users\k625\ntuser.dat.LOG2 Object is locked skipped
C:\Users\k625\ntuser.dat{28a3e59d-2ed4-11dd-9ed5-001bb987dc11}.TM.blf Object is locked skipped
C:\Users\k625\ntuser.dat{28a3e59d-2ed4-11dd-9ed5-001bb987dc11}.TMContainer00000000000000000001.regtrans-ms Object is locked skipped
C:\Users\k625\ntuser.dat{28a3e59d-2ed4-11dd-9ed5-001bb987dc11}.TMContainer00000000000000000002.regtrans-ms Object is locked skipped
C:\Windows\Debug\PASSWD.LOG Object is locked skipped
C:\Windows\Debug\sam.log Object is locked skipped
C:\Windows\ServiceProfiles\LocalService\AppData\Local\lastalive0.dat Object is locked skipped
C:\Windows\ServiceProfiles\LocalService\AppData\Local\lastalive1.dat Object is locked skipped
C:\Windows\ServiceProfiles\LocalService\ntuser.dat Object is locked skipped
C:\Windows\ServiceProfiles\LocalService\ntuser.dat.LOG1 Object is locked skipped
C:\Windows\ServiceProfiles\LocalService\ntuser.dat.LOG2 Object is locked skipped
C:\Windows\ServiceProfiles\LocalService\NTUSER.DAT{3a539869-6a70-11db-887c-d362bd253390}.TM.blf Object is locked skipped
C:\Windows\ServiceProfiles\LocalService\NTUSER.DAT{3a539869-6a70-11db-887c-d362bd253390}.TMContainer00000000000000000001.regtrans-ms Object is locked skipped
C:\Windows\ServiceProfiles\LocalService\NTUSER.DAT{3a539869-6a70-11db-887c-d362bd253390}.TMContainer00000000000000000002.regtrans-ms Object is locked skipped
C:\Windows\ServiceProfiles\NetworkService\ntuser.dat Object is locked skipped
C:\Windows\ServiceProfiles\NetworkService\ntuser.dat.LOG1 Object is locked skipped
C:\Windows\ServiceProfiles\NetworkService\ntuser.dat.LOG2 Object is locked skipped
C:\Windows\ServiceProfiles\NetworkService\NTUSER.DAT{3a539865-6a70-11db-887c-d362bd253390}.TM.blf Object is locked skipped
C:\Windows\ServiceProfiles\NetworkService\NTUSER.DAT{3a539865-6a70-11db-887c-d362bd253390}.TMContainer00000000000000000001.regtrans-ms Object is locked skipped
C:\Windows\ServiceProfiles\NetworkService\NTUSER.DAT{3a539865-6a70-11db-887c-d362bd253390}.TMContainer00000000000000000002.regtrans-ms Object is locked skipped
C:\Windows\System32\catroot2\edb.log Object is locked skipped
C:\Windows\System32\catroot2\{127D0A1D-4EF2-11D1-8608-00C04FC295EE}\catdb Object is locked skipped
C:\Windows\System32\catroot2\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\catdb Object is locked skipped
C:\Windows\System32\config\components Object is locked skipped
C:\Windows\System32\config\COMPONENTS.LOG1 Object is locked skipped
C:\Windows\System32\config\COMPONENTS.LOG2 Object is locked skipped
C:\Windows\System32\config\default Object is locked skipped
C:\Windows\System32\config\DEFAULT.LOG1 Object is locked skipped
C:\Windows\System32\config\DEFAULT.LOG2 Object is locked skipped
C:\Windows\System32\config\RegBack\COMPONENTS Object is locked skipped
C:\Windows\System32\config\RegBack\DEFAULT Object is locked skipped
C:\Windows\System32\config\RegBack\SAM Object is locked skipped
C:\Windows\System32\config\RegBack\SECURITY Object is locked skipped
C:\Windows\System32\config\RegBack\SOFTWARE Object is locked skipped
C:\Windows\System32\config\RegBack\SYSTEM Object is locked skipped
C:\Windows\System32\config\sam Object is locked skipped
C:\Windows\System32\config\SAM.LOG1 Object is locked skipped
C:\Windows\System32\config\SAM.LOG2 Object is locked skipped
C:\Windows\System32\config\security Object is locked skipped
C:\Windows\System32\config\SECURITY.LOG1 Object is locked skipped
C:\Windows\System32\config\SECURITY.LOG2 Object is locked skipped
C:\Windows\System32\config\software Object is locked skipped
C:\Windows\System32\config\SOFTWARE.LOG1 Object is locked skipped
C:\Windows\System32\config\SOFTWARE.LOG2 Object is locked skipped
C:\Windows\System32\config\system Object is locked skipped
C:\Windows\System32\config\SYSTEM.LOG1 Object is locked skipped
C:\Windows\System32\config\SYSTEM.LOG2 Object is locked skipped
C:\Windows\System32\config\TxR\{250834b7-750c-494d-bdc3-da86b6e2101a}.TxR.0.regtrans-ms Object is locked skipped
C:\Windows\System32\config\TxR\{250834b7-750c-494d-bdc3-da86b6e2101a}.TxR.1.regtrans-ms Object is locked skipped
C:\Windows\System32\config\TxR\{250834b7-750c-494d-bdc3-da86b6e2101a}.TxR.2.regtrans-ms Object is locked skipped
C:\Windows\System32\config\TxR\{250834b7-750c-494d-bdc3-da86b6e2101a}.TxR.blf Object is locked skipped
C:\Windows\System32\config\TxR\{250834B7-750C-494d-BDC3-DA86B6E2101B}.TM.blf Object is locked skipped
C:\Windows\System32\config\TxR\{250834B7-750C-494d-BDC3-DA86B6E2101B}.TMContainer00000000000000000001.regtrans-ms Object is locked skipped
C:\Windows\System32\config\TxR\{250834B7-750C-494d-BDC3-DA86B6E2101B}.TMContainer00000000000000000002.regtrans-ms Object is locked skipped
C:\Windows\System32\LogFiles\Scm\SCM.EVM Object is locked skipped
C:\Windows\System32\LogFiles\WMI\RtBackup\EtwRTMsMpPsSession.etl Object is locked skipped
C:\Windows\System32\wbem\Logs\WMITracing.log Object is locked skipped
C:\Windows\System32\wbem\repository\INDEX.BTR Object is locked skipped
C:\Windows\System32\wbem\repository\MAPPING1.MAP Object is locked skipped
C:\Windows\System32\wbem\repository\MAPPING2.MAP Object is locked skipped
C:\Windows\System32\wbem\repository\OBJECTS.DATA Object is locked skipped
C:\Windows\System32\WDI\LogFiles\WdiContextLog.etl.003 Object is locked skipped
C:\Windows\System32\wfp\wfpdiag.etl Object is locked skipped
C:\Windows\System32\winevt\Logs\Application.evtx Object is locked skipped
C:\Windows\System32\winevt\Logs\DFS Replication.evtx Object is locked skipped
C:\Windows\System32\winevt\Logs\HardwareEvents.evtx Object is locked skipped
C:\Windows\System32\winevt\Logs\Internet Explorer.evtx Object is locked skipped
C:\Windows\System32\winevt\Logs\Key Management Service.evtx Object is locked skipped
C:\Windows\System32\winevt\Logs\Media Center.evtx Object is locked skipped
C:\Windows\System32\winevt\Logs\Microsoft-Windows-CodeIntegrity%4Operational.evtx Object is locked skipped
C:\Windows\System32\winevt\Logs\Microsoft-Windows-International%4Operational.evtx Object is locked skipped
C:\Windows\System32\winevt\Logs\Microsoft-Windows-Kernel-WHEA.evtx Object is locked skipped
C:\Windows\System32\winevt\Logs\Microsoft-Windows-NetworkAccessProtection%4Operational.evtx Object is locked skipped
C:\Windows\System32\winevt\Logs\ODiag.evtx Object is locked skipped
C:\Windows\System32\winevt\Logs\OSession.evtx Object is locked skipped
C:\Windows\System32\winevt\Logs\Security.evtx Object is locked skipped
C:\Windows\System32\winevt\Logs\Setup.evtx Object is locked skipped
C:\Windows\System32\winevt\Logs\System.evtx Object is locked skipped
D:\System Volume Information\MountPointManagerRemoteDatabase Object is locked skipped
Scan process completed.