kwschumm
2008-06-01, 19:21
New member here, Spybot S&D keeps reporting Virtumonde but can't seem to clean it up. Windows Defender cannot either. This machine did not have a spyware checker prior to infection and in my attempts at googling for solutions I disabled system restore so there are no restore points (it has since been reenabled).
I have read the "Do this first" section and performed all the steps listed. The indicated log files are presented below. Thanks so much for any help you can offer.
The Kasperky log files:
-------------------------------------------------------------------------------
KASPERSKY ONLINE SCANNER REPORT
Sunday, June 01, 2008 8:27:33 AM
Operating System: Microsoft Windows XP Professional, Service Pack 2 (Build 2600)
Kaspersky Online Scanner version: 5.0.98.0
Kaspersky Anti-Virus database last update: 1/06/2008
Kaspersky Anti-Virus database records: 729780
-------------------------------------------------------------------------------
Scan Settings:
Scan using the following antivirus database: standard
Scan Archives: true
Scan Mail Bases: true
Scan Target - My Computer:
C:\
D:\
E:\
Scan Statistics:
Total number of scanned objects: 43127
Number of viruses found: 6
Number of infected objects: 15
Number of suspicious objects: 3
Duration of the scan process: 00:56:07
Infected Object Name / Virus Name / Last Action
C:\Documents and Settings\All Users\Application Data\avg7\Log\emc.log Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Dell\QuickSet\QSLLPSVCShare Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Grisoft\Avg7Data\avg7log.log Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Grisoft\Avg7Data\avg7log.log.lck Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Memeo\AutoBackup\logs\MemeoBackup.exe.log-2008-6-1.log Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Network\Downloader\qmgr0.dat Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Network\Downloader\qmgr1.dat Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Windows Defender\Support\MPLog-05312008-191727.log Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Wave Systems Corp\AuthManager\AuthPkg.txt Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Wave Systems Corp\AuthManager\biolsp.txt Object is locked skipped
C:\Documents and Settings\LocalService\Cookies\index.dat Object is locked skipped
C:\Documents and Settings\LocalService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat Object is locked skipped
C:\Documents and Settings\LocalService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped
C:\Documents and Settings\LocalService\Local Settings\History\History.IE5\index.dat Object is locked skipped
C:\Documents and Settings\LocalService\Local Settings\Temporary Internet Files\Content.IE5\index.dat Object is locked skipped
C:\Documents and Settings\LocalService\NTUSER.DAT Object is locked skipped
C:\Documents and Settings\LocalService\ntuser.dat.LOG Object is locked skipped
C:\Documents and Settings\NetworkService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat Object is locked skipped
C:\Documents and Settings\NetworkService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped
C:\Documents and Settings\NetworkService\Local Settings\Application Data\NTRU Cryptosystems\tcsd_log.txt Object is locked skipped
C:\Documents and Settings\NetworkService\NTUSER.DAT Object is locked skipped
C:\Documents and Settings\NetworkService\ntuser.dat.LOG Object is locked skipped
C:\Documents and Settings\Susan Schumm\Application Data\Microsoft\Outlook\outlook.pst/uu) 1999 H2/Migrated cc:Mail Archives/99H1IN.cca/14 Jan 1999 21:32 to /o=Intel/ou=Americas01/cn=Workers/cn=Schumm/360ICF~1.DOC Infected: Virus.MSWord.Class.fm skipped
C:\Documents and Settings\Susan Schumm\Application Data\Microsoft\Outlook\outlook.pst/uu) 1999 H2/Migrated cc:Mail Archives/98H2IN.cca/29 Oct 1998 00:41 to /o=Intel/ou=Americas01/cn=Workers/cn=Walker/epssup~1.xls Infected: Virus.MSExcel.Paix skipped
C:\Documents and Settings\Susan Schumm\Application Data\Microsoft\Outlook\outlook.pst/uu) 1999 H2/Migrated cc:Mail Archives/98H2IN.cca/03 Nov 1998 02:52 to /o=Intel/ou=Americas01/cn=Workers/cn=Benner/interf~1.xls Infected: Virus.MSExcel.Paix skipped
C:\Documents and Settings\Susan Schumm\Application Data\Microsoft\Outlook\outlook.pst/uu) 1999 H2/Migrated cc:Mail Archives/98H2IN.cca/10 Nov 1998 17:25 to /o=Intel/ou=Americas01/cn=Workers/cn=Schumm/epssup~1.xls Infected: Virus.MSExcel.Paix skipped
C:\Documents and Settings\Susan Schumm\Application Data\Microsoft\Outlook\outlook.pst/uu) 1999 H2/Migrated cc:Mail Archives/98H2IN.cca/10 Dec 1998 00:10 to /o=Intel/ou=Americas01/cn=Workers/cn=Bernun/opsrev~1.zip/smmitops1210.ppt Infected: Virus.MSExcel.Paix skipped
C:\Documents and Settings\Susan Schumm\Application Data\Microsoft\Outlook\outlook.pst/uu) 1999 H2/Migrated cc:Mail Archives/98H2IN.cca/10 Dec 1998 00:10 to /o=Intel/ou=Americas01/cn=Workers/cn=Bernun/opsrev~1.zip Infected: Virus.MSExcel.Paix skipped
C:\Documents and Settings\Susan Schumm\Application Data\Microsoft\Outlook\outlook.pst MailMSMaill: infected - 6 skipped
C:\Documents and Settings\Susan Schumm\Cookies\index.dat Object is locked skipped
C:\Documents and Settings\Susan Schumm\Local Settings\Application Data\Microsoft\Outlook\r) 2005 Q1.pst/r) 2005 Q1/Q105in/29 Mar 2005 20:05 from Regions Bank Customer Service Center:Acco.html Infected: Trojan-Spy.HTML.Bankfraud.cm skipped
C:\Documents and Settings\Susan Schumm\Local Settings\Application Data\Microsoft\Outlook\r) 2005 Q1.pst MailMSMaill: infected - 1 skipped
C:\Documents and Settings\Susan Schumm\Local Settings\Application Data\Microsoft\Outlook\t) 2003 Q1.pst/t) 2003 Q1/Q103in/24 Feb 2003 16:00 from Schaefer, Ed:Re: WorstResortNameEver /midsong.exe Infected: Email-Worm.Win32.LovGate.c skipped
C:\Documents and Settings\Susan Schumm\Local Settings\Application Data\Microsoft\Outlook\t) 2003 Q1.pst/t) 2003 Q1/Q103in/24 Feb 2003 16:01 from Schaefer, Ed:Re: Very punny /news_doc.exe Infected: Email-Worm.Win32.LovGate.c skipped
C:\Documents and Settings\Susan Schumm\Local Settings\Application Data\Microsoft\Outlook\t) 2003 Q1.pst/t) 2003 Q1/Q103in/24 Feb 2003 16:01 from Schaefer, Ed:Re: RE: Talking Dog for Sale/humor.exe Infected: Email-Worm.Win32.LovGate.c skipped
C:\Documents and Settings\Susan Schumm\Local Settings\Application Data\Microsoft\Outlook\t) 2003 Q1.pst/t) 2003 Q1/Q103in/24 Feb 2003 16:07 from Bringuel, Teresa:Re: EDW Materials Feb18t/docs.exe Infected: Email-Worm.Win32.LovGate.c skipped
C:\Documents and Settings\Susan Schumm\Local Settings\Application Data\Microsoft\Outlook\t) 2003 Q1.pst MailMSMaill: infected - 4 skipped
C:\Documents and Settings\Susan Schumm\Local Settings\Application Data\Microsoft\Outlook\t) 2003 Q3.pst/t) 2003 Q3/Q303in/24 Sep 2003 03:09 from inet mail system:notice.html Suspicious: Exploit.HTML.Iframe.FileDownload skipped
C:\Documents and Settings\Susan Schumm\Local Settings\Application Data\Microsoft\Outlook\t) 2003 Q3.pst/t) 2003 Q3/Q303in/24 Sep 2003 03:09 from inet mail system:notice.rtf Suspicious: Exploit.HTML.Iframe.FileDownload skipped
C:\Documents and Settings\Susan Schumm\Local Settings\Application Data\Microsoft\Outlook\t) 2003 Q3.pst MailMSMaill: suspicious - 2 skipped
C:\Documents and Settings\Susan Schumm\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat Object is locked skipped
C:\Documents and Settings\Susan Schumm\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped
C:\Documents and Settings\Susan Schumm\Local Settings\Application Data\Microsoft\Windows Defender\FileTracker\{5B7222D1-726C-4B52-9850-3FC082A30B32} Object is locked skipped
C:\Documents and Settings\Susan Schumm\Local Settings\History\History.IE5\index.dat Object is locked skipped
C:\Documents and Settings\Susan Schumm\Local Settings\Temp\j22.exe Infected: Trojan-Downloader.Win32.Small.wmo skipped
C:\Documents and Settings\Susan Schumm\Local Settings\Temporary Internet Files\AntiPhishing\B3BB5BBA-E7D5-40AB-A041-A5B1C0B26C8F.dat Object is locked skipped
C:\Documents and Settings\Susan Schumm\Local Settings\Temporary Internet Files\Content.IE5\index.dat Object is locked skipped
C:\Documents and Settings\Susan Schumm\NTUSER.DAT Object is locked skipped
C:\Documents and Settings\Susan Schumm\ntuser.dat.LOG Object is locked skipped
C:\scrumworks\bin\velocity.log Object is locked skipped
C:\scrumworks\server\scrumworks\data\hypersonic\localDB.data Object is locked skipped
C:\scrumworks\server\scrumworks\data\hypersonic\localDB.lck Object is locked skipped
C:\scrumworks\server\scrumworks\data\hypersonic\localDB.log Object is locked skipped
C:\scrumworks\server\scrumworks\data\hypersonic\scrumworks.lck Object is locked skipped
C:\scrumworks\server\scrumworks\data\hypersonic\scrumworks.log Object is locked skipped
C:\scrumworks\server\scrumworks\log\server.log Object is locked skipped
C:\System Volume Information\MountPointManagerRemoteDatabase Object is locked skipped
C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP1\change.log Object is locked skipped
C:\WINDOWS\Debug\PASSWD.LOG Object is locked skipped
C:\WINDOWS\Registration\{02D4B3F1-FD88-11D1-960D-00805FC79235}.{5E0B2098-33E7-4516-BC40-DE966D1FF333}.crmlog Object is locked skipped
C:\WINDOWS\SchedLgU.Txt Object is locked skipped
C:\WINDOWS\SoftwareDistribution\ReportingEvents.log Object is locked skipped
C:\WINDOWS\system32\CatRoot2\edb.log Object is locked skipped
C:\WINDOWS\system32\CatRoot2\tmp.edb Object is locked skipped
C:\WINDOWS\system32\config\AppEvent.Evt Object is locked skipped
C:\WINDOWS\system32\config\DEFAULT Object is locked skipped
C:\WINDOWS\system32\config\default.LOG Object is locked skipped
C:\WINDOWS\system32\config\Internet.evt Object is locked skipped
C:\WINDOWS\system32\config\ODiag.evt Object is locked skipped
C:\WINDOWS\system32\config\OSession.evt Object is locked skipped
C:\WINDOWS\system32\config\SAM Object is locked skipped
C:\WINDOWS\system32\config\SAM.LOG Object is locked skipped
C:\WINDOWS\system32\config\SecEvent.Evt Object is locked skipped
C:\WINDOWS\system32\config\SECURITY Object is locked skipped
C:\WINDOWS\system32\config\SECURITY.LOG Object is locked skipped
C:\WINDOWS\system32\config\SOFTWARE Object is locked skipped
C:\WINDOWS\system32\config\software.LOG Object is locked skipped
C:\WINDOWS\system32\config\SysEvent.Evt Object is locked skipped
C:\WINDOWS\system32\config\SYSTEM Object is locked skipped
C:\WINDOWS\system32\config\system.LOG Object is locked skipped
C:\WINDOWS\system32\MsDtc\MSDTC.LOG Object is locked skipped
C:\WINDOWS\system32\MsDtc\Trace\dtctrace.log Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\INDEX.BTR Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\INDEX.MAP Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\MAPPING.VER Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\MAPPING1.MAP Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\MAPPING2.MAP Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\OBJECTS.DATA Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\OBJECTS.MAP Object is locked skipped
C:\WINDOWS\Temp\hsperfdata_SYSTEM\472 Object is locked skipped
C:\WINDOWS\WindowsUpdate.log Object is locked skipped
Scan process completed.
I have read the "Do this first" section and performed all the steps listed. The indicated log files are presented below. Thanks so much for any help you can offer.
The Kasperky log files:
-------------------------------------------------------------------------------
KASPERSKY ONLINE SCANNER REPORT
Sunday, June 01, 2008 8:27:33 AM
Operating System: Microsoft Windows XP Professional, Service Pack 2 (Build 2600)
Kaspersky Online Scanner version: 5.0.98.0
Kaspersky Anti-Virus database last update: 1/06/2008
Kaspersky Anti-Virus database records: 729780
-------------------------------------------------------------------------------
Scan Settings:
Scan using the following antivirus database: standard
Scan Archives: true
Scan Mail Bases: true
Scan Target - My Computer:
C:\
D:\
E:\
Scan Statistics:
Total number of scanned objects: 43127
Number of viruses found: 6
Number of infected objects: 15
Number of suspicious objects: 3
Duration of the scan process: 00:56:07
Infected Object Name / Virus Name / Last Action
C:\Documents and Settings\All Users\Application Data\avg7\Log\emc.log Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Dell\QuickSet\QSLLPSVCShare Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Grisoft\Avg7Data\avg7log.log Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Grisoft\Avg7Data\avg7log.log.lck Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Memeo\AutoBackup\logs\MemeoBackup.exe.log-2008-6-1.log Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Network\Downloader\qmgr0.dat Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Network\Downloader\qmgr1.dat Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Windows Defender\Support\MPLog-05312008-191727.log Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Wave Systems Corp\AuthManager\AuthPkg.txt Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Wave Systems Corp\AuthManager\biolsp.txt Object is locked skipped
C:\Documents and Settings\LocalService\Cookies\index.dat Object is locked skipped
C:\Documents and Settings\LocalService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat Object is locked skipped
C:\Documents and Settings\LocalService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped
C:\Documents and Settings\LocalService\Local Settings\History\History.IE5\index.dat Object is locked skipped
C:\Documents and Settings\LocalService\Local Settings\Temporary Internet Files\Content.IE5\index.dat Object is locked skipped
C:\Documents and Settings\LocalService\NTUSER.DAT Object is locked skipped
C:\Documents and Settings\LocalService\ntuser.dat.LOG Object is locked skipped
C:\Documents and Settings\NetworkService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat Object is locked skipped
C:\Documents and Settings\NetworkService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped
C:\Documents and Settings\NetworkService\Local Settings\Application Data\NTRU Cryptosystems\tcsd_log.txt Object is locked skipped
C:\Documents and Settings\NetworkService\NTUSER.DAT Object is locked skipped
C:\Documents and Settings\NetworkService\ntuser.dat.LOG Object is locked skipped
C:\Documents and Settings\Susan Schumm\Application Data\Microsoft\Outlook\outlook.pst/uu) 1999 H2/Migrated cc:Mail Archives/99H1IN.cca/14 Jan 1999 21:32 to /o=Intel/ou=Americas01/cn=Workers/cn=Schumm/360ICF~1.DOC Infected: Virus.MSWord.Class.fm skipped
C:\Documents and Settings\Susan Schumm\Application Data\Microsoft\Outlook\outlook.pst/uu) 1999 H2/Migrated cc:Mail Archives/98H2IN.cca/29 Oct 1998 00:41 to /o=Intel/ou=Americas01/cn=Workers/cn=Walker/epssup~1.xls Infected: Virus.MSExcel.Paix skipped
C:\Documents and Settings\Susan Schumm\Application Data\Microsoft\Outlook\outlook.pst/uu) 1999 H2/Migrated cc:Mail Archives/98H2IN.cca/03 Nov 1998 02:52 to /o=Intel/ou=Americas01/cn=Workers/cn=Benner/interf~1.xls Infected: Virus.MSExcel.Paix skipped
C:\Documents and Settings\Susan Schumm\Application Data\Microsoft\Outlook\outlook.pst/uu) 1999 H2/Migrated cc:Mail Archives/98H2IN.cca/10 Nov 1998 17:25 to /o=Intel/ou=Americas01/cn=Workers/cn=Schumm/epssup~1.xls Infected: Virus.MSExcel.Paix skipped
C:\Documents and Settings\Susan Schumm\Application Data\Microsoft\Outlook\outlook.pst/uu) 1999 H2/Migrated cc:Mail Archives/98H2IN.cca/10 Dec 1998 00:10 to /o=Intel/ou=Americas01/cn=Workers/cn=Bernun/opsrev~1.zip/smmitops1210.ppt Infected: Virus.MSExcel.Paix skipped
C:\Documents and Settings\Susan Schumm\Application Data\Microsoft\Outlook\outlook.pst/uu) 1999 H2/Migrated cc:Mail Archives/98H2IN.cca/10 Dec 1998 00:10 to /o=Intel/ou=Americas01/cn=Workers/cn=Bernun/opsrev~1.zip Infected: Virus.MSExcel.Paix skipped
C:\Documents and Settings\Susan Schumm\Application Data\Microsoft\Outlook\outlook.pst MailMSMaill: infected - 6 skipped
C:\Documents and Settings\Susan Schumm\Cookies\index.dat Object is locked skipped
C:\Documents and Settings\Susan Schumm\Local Settings\Application Data\Microsoft\Outlook\r) 2005 Q1.pst/r) 2005 Q1/Q105in/29 Mar 2005 20:05 from Regions Bank Customer Service Center:Acco.html Infected: Trojan-Spy.HTML.Bankfraud.cm skipped
C:\Documents and Settings\Susan Schumm\Local Settings\Application Data\Microsoft\Outlook\r) 2005 Q1.pst MailMSMaill: infected - 1 skipped
C:\Documents and Settings\Susan Schumm\Local Settings\Application Data\Microsoft\Outlook\t) 2003 Q1.pst/t) 2003 Q1/Q103in/24 Feb 2003 16:00 from Schaefer, Ed:Re: WorstResortNameEver /midsong.exe Infected: Email-Worm.Win32.LovGate.c skipped
C:\Documents and Settings\Susan Schumm\Local Settings\Application Data\Microsoft\Outlook\t) 2003 Q1.pst/t) 2003 Q1/Q103in/24 Feb 2003 16:01 from Schaefer, Ed:Re: Very punny /news_doc.exe Infected: Email-Worm.Win32.LovGate.c skipped
C:\Documents and Settings\Susan Schumm\Local Settings\Application Data\Microsoft\Outlook\t) 2003 Q1.pst/t) 2003 Q1/Q103in/24 Feb 2003 16:01 from Schaefer, Ed:Re: RE: Talking Dog for Sale/humor.exe Infected: Email-Worm.Win32.LovGate.c skipped
C:\Documents and Settings\Susan Schumm\Local Settings\Application Data\Microsoft\Outlook\t) 2003 Q1.pst/t) 2003 Q1/Q103in/24 Feb 2003 16:07 from Bringuel, Teresa:Re: EDW Materials Feb18t/docs.exe Infected: Email-Worm.Win32.LovGate.c skipped
C:\Documents and Settings\Susan Schumm\Local Settings\Application Data\Microsoft\Outlook\t) 2003 Q1.pst MailMSMaill: infected - 4 skipped
C:\Documents and Settings\Susan Schumm\Local Settings\Application Data\Microsoft\Outlook\t) 2003 Q3.pst/t) 2003 Q3/Q303in/24 Sep 2003 03:09 from inet mail system:notice.html Suspicious: Exploit.HTML.Iframe.FileDownload skipped
C:\Documents and Settings\Susan Schumm\Local Settings\Application Data\Microsoft\Outlook\t) 2003 Q3.pst/t) 2003 Q3/Q303in/24 Sep 2003 03:09 from inet mail system:notice.rtf Suspicious: Exploit.HTML.Iframe.FileDownload skipped
C:\Documents and Settings\Susan Schumm\Local Settings\Application Data\Microsoft\Outlook\t) 2003 Q3.pst MailMSMaill: suspicious - 2 skipped
C:\Documents and Settings\Susan Schumm\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat Object is locked skipped
C:\Documents and Settings\Susan Schumm\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped
C:\Documents and Settings\Susan Schumm\Local Settings\Application Data\Microsoft\Windows Defender\FileTracker\{5B7222D1-726C-4B52-9850-3FC082A30B32} Object is locked skipped
C:\Documents and Settings\Susan Schumm\Local Settings\History\History.IE5\index.dat Object is locked skipped
C:\Documents and Settings\Susan Schumm\Local Settings\Temp\j22.exe Infected: Trojan-Downloader.Win32.Small.wmo skipped
C:\Documents and Settings\Susan Schumm\Local Settings\Temporary Internet Files\AntiPhishing\B3BB5BBA-E7D5-40AB-A041-A5B1C0B26C8F.dat Object is locked skipped
C:\Documents and Settings\Susan Schumm\Local Settings\Temporary Internet Files\Content.IE5\index.dat Object is locked skipped
C:\Documents and Settings\Susan Schumm\NTUSER.DAT Object is locked skipped
C:\Documents and Settings\Susan Schumm\ntuser.dat.LOG Object is locked skipped
C:\scrumworks\bin\velocity.log Object is locked skipped
C:\scrumworks\server\scrumworks\data\hypersonic\localDB.data Object is locked skipped
C:\scrumworks\server\scrumworks\data\hypersonic\localDB.lck Object is locked skipped
C:\scrumworks\server\scrumworks\data\hypersonic\localDB.log Object is locked skipped
C:\scrumworks\server\scrumworks\data\hypersonic\scrumworks.lck Object is locked skipped
C:\scrumworks\server\scrumworks\data\hypersonic\scrumworks.log Object is locked skipped
C:\scrumworks\server\scrumworks\log\server.log Object is locked skipped
C:\System Volume Information\MountPointManagerRemoteDatabase Object is locked skipped
C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP1\change.log Object is locked skipped
C:\WINDOWS\Debug\PASSWD.LOG Object is locked skipped
C:\WINDOWS\Registration\{02D4B3F1-FD88-11D1-960D-00805FC79235}.{5E0B2098-33E7-4516-BC40-DE966D1FF333}.crmlog Object is locked skipped
C:\WINDOWS\SchedLgU.Txt Object is locked skipped
C:\WINDOWS\SoftwareDistribution\ReportingEvents.log Object is locked skipped
C:\WINDOWS\system32\CatRoot2\edb.log Object is locked skipped
C:\WINDOWS\system32\CatRoot2\tmp.edb Object is locked skipped
C:\WINDOWS\system32\config\AppEvent.Evt Object is locked skipped
C:\WINDOWS\system32\config\DEFAULT Object is locked skipped
C:\WINDOWS\system32\config\default.LOG Object is locked skipped
C:\WINDOWS\system32\config\Internet.evt Object is locked skipped
C:\WINDOWS\system32\config\ODiag.evt Object is locked skipped
C:\WINDOWS\system32\config\OSession.evt Object is locked skipped
C:\WINDOWS\system32\config\SAM Object is locked skipped
C:\WINDOWS\system32\config\SAM.LOG Object is locked skipped
C:\WINDOWS\system32\config\SecEvent.Evt Object is locked skipped
C:\WINDOWS\system32\config\SECURITY Object is locked skipped
C:\WINDOWS\system32\config\SECURITY.LOG Object is locked skipped
C:\WINDOWS\system32\config\SOFTWARE Object is locked skipped
C:\WINDOWS\system32\config\software.LOG Object is locked skipped
C:\WINDOWS\system32\config\SysEvent.Evt Object is locked skipped
C:\WINDOWS\system32\config\SYSTEM Object is locked skipped
C:\WINDOWS\system32\config\system.LOG Object is locked skipped
C:\WINDOWS\system32\MsDtc\MSDTC.LOG Object is locked skipped
C:\WINDOWS\system32\MsDtc\Trace\dtctrace.log Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\INDEX.BTR Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\INDEX.MAP Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\MAPPING.VER Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\MAPPING1.MAP Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\MAPPING2.MAP Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\OBJECTS.DATA Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\OBJECTS.MAP Object is locked skipped
C:\WINDOWS\Temp\hsperfdata_SYSTEM\472 Object is locked skipped
C:\WINDOWS\WindowsUpdate.log Object is locked skipped
Scan process completed.