rmundell
2008-06-05, 00:30
Ok, i think the virus has been removed, as my pc is almost back to normal. Still have a few things the firewall blocks and i do not allow, as i am unsure, and my pc is at least working again. here are my logs per the post at the top of this forum. Help would be greatly appreciated. Thanks, Rob.
-------------------------------------------------------------------------------
KASPERSKY ONLINE SCANNER REPORT
Wednesday, June 04, 2008 14:10: VIRUS PMLERT!
Operating System: Microsoft Windows XP Professional, Service Pack 1 (Build 2600)
Kaspersky Online Scanner version: 5.0.98.0
Kaspersky Anti-Virus database last update: 4/06/2008
Kaspersky Anti-Virus database records: 829085
-------------------------------------------------------------------------------
Scan Settings:
Scan using the following antivirus database: extended
Scan Archives: true
Scan Mail Bases: true
Scan Target - My Computer:
A:\
C:\
D:\
M:\
U:\
X:\
Scan Statistics:
Total number of scanned objects: 71784
Number of viruses found: 7
Number of infected objects: 14
Number of suspicious objects: 2
Duration of the scan process: 01:37:27
Infected Object Name / Virus Name / Last Action
C:\Documents and Settings\administrator.TWI.000\Cookies\index.dat Object is locked skipped
C:\Documents and Settings\administrator.TWI.000\Local Settings\History\History.IE5\index.dat Object is locked skipped
C:\Documents and Settings\administrator.TWI.000\Local Settings\Temporary Internet Files\Content.IE5\index.dat Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\0410ed250a5d2dddd7365066da921b02_0b970814-ba4f-4506-ba54-ab3a6ee8ae9e Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\080a463d3b94bcf5c23e330efdf37a1c_0b970814-ba4f-4506-ba54-ab3a6ee8ae9e Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\082d37396edf953fb2d5cd863c92671a_0b970814-ba4f-4506-ba54-ab3a6ee8ae9e Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\0aa8f2fd44d7c3d2faf3f6ae01870858_0b970814-ba4f-4506-ba54-ab3a6ee8ae9e Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\100bbb54e60f7be13d224ad9ad8f4c3e_0b970814-ba4f-4506-ba54-ab3a6ee8ae9e Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\1062b2ecbad8a30255a0ff7c9c2caddb_0b970814-ba4f-4506-ba54-ab3a6ee8ae9e Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\110a01bd4a9787766432af90feceea75_0b970814-ba4f-4506-ba54-ab3a6ee8ae9e Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\177ec0e8f76ce35f3a07b9e41572b86c_0b970814-ba4f-4506-ba54-ab3a6ee8ae9e Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\1b7c087f6ef5110e1bd7394707b2da0b_0b970814-ba4f-4506-ba54-ab3a6ee8ae9e Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\1d7cd73a778d5cf6fa382c50db30579c_0b970814-ba4f-4506-ba54-ab3a6ee8ae9e Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\1f0204d37c0a86b7906aab0a56bc21cf_0b970814-ba4f-4506-ba54-ab3a6ee8ae9e Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\1fb04235c5d1116ce0bdd7295eaad217_0b970814-ba4f-4506-ba54-ab3a6ee8ae9e Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\20308be89fdce02dc9aaeabfa8a028eb_0b970814-ba4f-4506-ba54-ab3a6ee8ae9e Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\228c1b78f49ed8edf9f0b25cac9c1965_0b970814-ba4f-4506-ba54-ab3a6ee8ae9e Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\28f632e8e3c56bb1ab900147ab487870_0b970814-ba4f-4506-ba54-ab3a6ee8ae9e Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\2c671a0413fe288e256d8422456a0811_0b970814-ba4f-4506-ba54-ab3a6ee8ae9e Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\3053c90eeb34d1e2f522ea6b30d803ef_0b970814-ba4f-4506-ba54-ab3a6ee8ae9e Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\3bdcc8d95d53c0d05151509f12e89cb9_0b970814-ba4f-4506-ba54-ab3a6ee8ae9e Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\3c60f589cc255b377dc129ac185612e1_0b970814-ba4f-4506-ba54-ab3a6ee8ae9e Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\3c956f8f451f3ef9c23aa0b00bde6d22_0b970814-ba4f-4506-ba54-ab3a6ee8ae9e Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\3d65ca31cbae8224f0d5321d5e43447f_0b970814-ba4f-4506-ba54-ab3a6ee8ae9e Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\44d59f5532738a0bb7537438a0cc022b_0b970814-ba4f-4506-ba54-ab3a6ee8ae9e Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\456f1fd8a319cace7774b0dd2835df73_0b970814-ba4f-4506-ba54-ab3a6ee8ae9e Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\474ff5261149e7be96e1cd1f523ae064_0b970814-ba4f-4506-ba54-ab3a6ee8ae9e Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\490ce0e0c6e6ae71d70d87456f4b334d_0b970814-ba4f-4506-ba54-ab3a6ee8ae9e Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\496c597b6e3f0110cee989a97bdd1ad4_0b970814-ba4f-4506-ba54-ab3a6ee8ae9e Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\497ba477e79f6c7e4bd4939e9e956b5c_0b970814-ba4f-4506-ba54-ab3a6ee8ae9e Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\4a1b954f53461e7956b8b9d7591bc571_0b970814-ba4f-4506-ba54-ab3a6ee8ae9e Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\4abb8a2e665bac5a773255594520719e_0b970814-ba4f-4506-ba54-ab3a6ee8ae9e Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\4b54e3a597d203c83b718691d491c9ff_0b970814-ba4f-4506-ba54-ab3a6ee8ae9e Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\4e9f09afccf16811e81ae6aeb09742be_0b970814-ba4f-4506-ba54-ab3a6ee8ae9e Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\4f64ac1dd507db4e966b5e9726f6dc54_0b970814-ba4f-4506-ba54-ab3a6ee8ae9e Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\545dd6423944901a3887b63f4b36db01_0b970814-ba4f-4506-ba54-ab3a6ee8ae9e Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\5b1df77d9ceb783d3aeee6938d805f55_0b970814-ba4f-4506-ba54-ab3a6ee8ae9e Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\5ebe9d0dde74477bfb78bc00ae3de754_0b970814-ba4f-4506-ba54-ab3a6ee8ae9e Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\6041df0796dfc813829a5c72ffd0c449_0b970814-ba4f-4506-ba54-ab3a6ee8ae9e Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\60d7d1f4b181cbcc4f1ad194f8b502c2_0b970814-ba4f-4506-ba54-ab3a6ee8ae9e Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\629b7b135c0c3eab5f71ec2fef495afb_0b970814-ba4f-4506-ba54-ab3a6ee8ae9e Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\62f61c1c61f6c6a0b6966bff07ecf4d3_0b970814-ba4f-4506-ba54-ab3a6ee8ae9e Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\6313d3f6276ff1763d5f005f596daa15_0b970814-ba4f-4506-ba54-ab3a6ee8ae9e Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\63a599bbf83f504b484c285a9646ed77_0b970814-ba4f-4506-ba54-ab3a6ee8ae9e Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\649c1a9754b21ae4d657a2fb65b630d9_0b970814-ba4f-4506-ba54-ab3a6ee8ae9e Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\6b6037da78ebb81a38d9e8375a0ac776_0b970814-ba4f-4506-ba54-ab3a6ee8ae9e Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\6d07575f7c38253feca4c19b0b89b636_0b970814-ba4f-4506-ba54-ab3a6ee8ae9e Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\6d93d3883ba7822f4253f7704ef57156_0b970814-ba4f-4506-ba54-ab3a6ee8ae9e Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\724ef4c3701be22363d6b077ad959d69_0b970814-ba4f-4506-ba54-ab3a6ee8ae9e Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\7912663e59b7180a79ee1d094e925932_0b970814-ba4f-4506-ba54-ab3a6ee8ae9e Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\7a39bdd6b121959a8e81f46897330022_0b970814-ba4f-4506-ba54-ab3a6ee8ae9e Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\7b5d1dd0e7174974e1f5352bfdedcbf6_0b970814-ba4f-4506-ba54-ab3a6ee8ae9e Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\7c70406f68a201f2499f3f74b72b75f3_0b970814-ba4f-4506-ba54-ab3a6ee8ae9e Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\7ce5950b7e4bad7e905a74ea9bae7836_0b970814-ba4f-4506-ba54-ab3a6ee8ae9e Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\7d4d1e954bd8baca556d1da737bc5dd7_0b970814-ba4f-4506-ba54-ab3a6ee8ae9e Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\8215509b79862a98fd512f88eb9a0f56_0b970814-ba4f-4506-ba54-ab3a6ee8ae9e Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\82a998e1e75bf1a776e09295ff6b297b_0b970814-ba4f-4506-ba54-ab3a6ee8ae9e Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\832ddf1bdb66529723062dc2e5766365_0b970814-ba4f-4506-ba54-ab3a6ee8ae9e Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\85dc6f8f6f36dd2952519fa65342fd20_0b970814-ba4f-4506-ba54-ab3a6ee8ae9e Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\868f408f655c61833f991a53afbe1a43_0b970814-ba4f-4506-ba54-ab3a6ee8ae9e Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\86d522958b378ffa33870ee5bdcd9d4b_0b970814-ba4f-4506-ba54-ab3a6ee8ae9e Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\8a973a6ccaeb320e2928e964021de1f3_0b970814-ba4f-4506-ba54-ab3a6ee8ae9e Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\906f7d9774428df637c490e21a1563ae_0b970814-ba4f-4506-ba54-ab3a6ee8ae9e Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\90c613cc3f7149869a7f90ef7d1fabb1_0b970814-ba4f-4506-ba54-ab3a6ee8ae9e Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\9425ca2f03553878ebe6352782fb1349_0b970814-ba4f-4506-ba54-ab3a6ee8ae9e Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\95d4953ca69527945bb973d574235111_0b970814-ba4f-4506-ba54-ab3a6ee8ae9e Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\969eddcaa037e241811a438868293baa_0b970814-ba4f-4506-ba54-ab3a6ee8ae9e Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\9722ddefe33f246c1caad712a535970d_0b970814-ba4f-4506-ba54-ab3a6ee8ae9e Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\977ff6b5478aed8f28fa505f1a432d7f_0b970814-ba4f-4506-ba54-ab3a6ee8ae9e Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\9a03ccf22f1f06a93c1b9cc26e0d221b_0b970814-ba4f-4506-ba54-ab3a6ee8ae9e Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\9ace309a6ae7643fb3e9bb2f0b18f92c_0b970814-ba4f-4506-ba54-ab3a6ee8ae9e Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\9dfae7c6879e3f5e031899f228fcc5e2_0b970814-ba4f-4506-ba54-ab3a6ee8ae9e Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\a068ebc6b9592baf4a541053941856b7_0b970814-ba4f-4506-ba54-ab3a6ee8ae9e Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\a6d7918c469ebf5f5504d3797d1a6eb2_0b970814-ba4f-4506-ba54-ab3a6ee8ae9e Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\a7f4ed5afadc8248128e23d5591df408_0b970814-ba4f-4506-ba54-ab3a6ee8ae9e Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\acc70d1f281678e93f518b566da9823f_0b970814-ba4f-4506-ba54-ab3a6ee8ae9e Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\ad34635a95b9f6e67dc6da00c5fcd30b_0b970814-ba4f-4506-ba54-ab3a6ee8ae9e Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\b0649270b1cf9d0ba27c383cd2ab6a49_0b970814-ba4f-4506-ba54-ab3a6ee8ae9e Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\b4819763ad3b187a933a465791e67bff_0b970814-ba4f-4506-ba54-ab3a6ee8ae9e Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\b928beb930cb59cd15e6304ca48e6766_0b970814-ba4f-4506-ba54-ab3a6ee8ae9e Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\bf1cf2f545f94b4e6d0a096de3a2a09f_0b970814-ba4f-4506-ba54-ab3a6ee8ae9e Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\cc60225d2efb3389be171bf0c31e6e49_0b970814-ba4f-4506-ba54-ab3a6ee8ae9e Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\cfd051ae534574fe27cae0f263ca2be9_0b970814-ba4f-4506-ba54-ab3a6ee8ae9e Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\d1ab1aa8c663893c838807bcb97c696e_0b970814-ba4f-4506-ba54-ab3a6ee8ae9e Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\d7cb2d391e22da3f41a043ad2cb4fca3_0b970814-ba4f-4506-ba54-ab3a6ee8ae9e Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\d992ac7da79b96217569c3591e7266ea_0b970814-ba4f-4506-ba54-ab3a6ee8ae9e Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\dc25519fda7a8050ee05bc3559e73d7e_0b970814-ba4f-4506-ba54-ab3a6ee8ae9e Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\dc6bcb3e2fcc28c89be663b3880b954a_0b970814-ba4f-4506-ba54-ab3a6ee8ae9e Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\dd8a86021bdfff7d5666fdc177ed3f13_0b970814-ba4f-4506-ba54-ab3a6ee8ae9e Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\e1eb9663534192409dc0824e52ef6ca1_0b970814-ba4f-4506-ba54-ab3a6ee8ae9e Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\e1ec7d530f156e262d1735c027a0d63f_0b970814-ba4f-4506-ba54-ab3a6ee8ae9e Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\e4f6eae94957d360bdccce77d16adba9_0b970814-ba4f-4506-ba54-ab3a6ee8ae9e Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\e73ec46d9d6900db0368f6cab0ec8f9d_0b970814-ba4f-4506-ba54-ab3a6ee8ae9e Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\e878938555d432791ad774655ac4c271_0b970814-ba4f-4506-ba54-ab3a6ee8ae9e Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\e9125e1990eeeb65c59b103b0608dbb1_0b970814-ba4f-4506-ba54-ab3a6ee8ae9e Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\ea1fd982a2651bbbb2e94c500415d384_0b970814-ba4f-4506-ba54-ab3a6ee8ae9e Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\ea47d348b39a2ea7401cecd0b6e2dff8_0b970814-ba4f-4506-ba54-ab3a6ee8ae9e Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\ead2368b3b624f79e9ad7111bd8d94a2_0b970814-ba4f-4506-ba54-ab3a6ee8ae9e Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\ec6fa48bfc1c64f980553617213acac4_0b970814-ba4f-4506-ba54-ab3a6ee8ae9e Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\ec99085cf4f9fb25b63b34c56831136e_0b970814-ba4f-4506-ba54-ab3a6ee8ae9e Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\ecc58b4d43339e3f0060a3adced51e62_0b970814-ba4f-4506-ba54-ab3a6ee8ae9e Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\ef5359ad2b209e10879264fbe67279b4_0b970814-ba4f-4506-ba54-ab3a6ee8ae9e Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\f0f5f61a7007d7bbbc3a0e1baca5b396_0b970814-ba4f-4506-ba54-ab3a6ee8ae9e Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\f3111330c8e749dd13c102f8969ab446_0b970814-ba4f-4506-ba54-ab3a6ee8ae9e Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\fc11040ee083cac0ee949f390b28cf76_0b970814-ba4f-4506-ba54-ab3a6ee8ae9e Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\fd08e82879f38cbdd1bc448263943ccd_0b970814-ba4f-4506-ba54-ab3a6ee8ae9e Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\ff5f3e67e396a2a711cfe17697d4c756_0b970814-ba4f-4506-ba54-ab3a6ee8ae9e Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Dr Watson\user.dmp Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Network\Downloader\qmgr0.dat Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Network\Downloader\qmgr1.dat Object is locked skipped
C:\Documents and Settings\LocalService\Cookies\index.dat Object is locked skipped
C:\Documents and Settings\LocalService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat Object is locked skipped
C:\Documents and Settings\LocalService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped
C:\Documents and Settings\LocalService\Local Settings\History\History.IE5\index.dat Object is locked skipped
C:\Documents and Settings\LocalService\Local Settings\Temporary Internet Files\Content.IE5\index.dat Object is locked skipped
C:\Documents and Settings\LocalService\NTUSER.DAT Object is locked skipped
C:\Documents and Settings\LocalService\ntuser.dat.LOG Object is locked skipped
C:\Documents and Settings\NetworkService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat Object is locked skipped
C:\Documents and Settings\NetworkService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped
C:\Documents and Settings\NetworkService\NTUSER.DAT Object is locked skipped
C:\Documents and Settings\NetworkService\ntuser.dat.LOG Object is locked skipped
C:\Documents and Settings\rmundell\ntuser.dat Object is locked skipped
C:\Documents and Settings\rmundell\ntuser.dat.LOG Object is locked skipped
C:\Documents and Settings\rmundell.TWI\Application Data\MailFrontier\ASD.log Object is locked skipped
C:\Documents and Settings\rmundell.TWI\Cookies\index.dat Object is locked skipped
C:\Documents and Settings\rmundell.TWI\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat Object is locked skipped
C:\Documents and Settings\rmundell.TWI\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped
C:\Documents and Settings\rmundell.TWI\Local Settings\History\History.IE5\index.dat Object is locked skipped
C:\Documents and Settings\rmundell.TWI\Local Settings\Temp\~DFDD7D.tmp Object is locked skipped
C:\Documents and Settings\rmundell.TWI\Local Settings\Temporary Internet Files\Content.IE5\index.dat Object is locked skipped
C:\Documents and Settings\rmundell.TWI\NTUSER.DAT Object is locked skipped
C:\Documents and Settings\rmundell.TWI\ntuser.dat.LOG Object is locked skipped
C:\Documents and Settings\rmundell.TWIK\Local Settings\Application Data\Identities\{DE2F43EE-75C5-4AA9-AF8D-34223AC8D033}\Microsoft\Outlook Express\Deleted Items.dbx/[From RegionsNet Bank <OnlineBanking@regionsnet.com>][Date Sat, 26 Jan 2008 18:29:48 -0800]/html Suspicious: Trojan-Spy.HTML.Fraud.gen skipped
C:\Documents and Settings\rmundell.TWIK\Local Settings\Application Data\Identities\{DE2F43EE-75C5-4AA9-AF8D-34223AC8D033}\Microsoft\Outlook Express\Deleted Items.dbx MailMSOutlook5: suspicious - 1 skipped
C:\Program Files\Common Files\Intuit\QuickBooks\QBUpdate\Log\CHANNEL.LOG Object is locked skipped
C:\Program Files\Intuit\QuickBooks Enterprise Solutions 6.0\Components\DownloadQB16\Guide\.update\.QBLock.lck Object is locked skipped
C:\Program Files\Research In Motion\BlackBerry\Transaction Manager\ComponentData\Eventlogs\TMEventlog.log Object is locked skipped
C:\System Volume Information\MountPointManagerRemoteDatabase Object is locked skipped
C:\System Volume Information\_restore{5CB1E4DF-28C2-479A-AE86-328C29F74AAD}\RP1\A0000137.dll Infected: Trojan.Win32.Vapsup.fyz skipped
C:\System Volume Information\_restore{5CB1E4DF-28C2-479A-AE86-328C29F74AAD}\RP1\A0000138.exe Infected: Trojan.Win32.Vapsup.fwt skipped
C:\System Volume Information\_restore{5CB1E4DF-28C2-479A-AE86-328C29F74AAD}\RP1\A0000139.exe Infected: Trojan.Win32.Vapsup.fyx skipped
C:\System Volume Information\_restore{5CB1E4DF-28C2-479A-AE86-328C29F74AAD}\RP1\A0000140.exe Infected: Trojan.Win32.Vapsup.fwa skipped
C:\System Volume Information\_restore{5CB1E4DF-28C2-479A-AE86-328C29F74AAD}\RP1\A0000141.dll Infected: Trojan.Win32.Vapsup.fxu skipped
C:\System Volume Information\_restore{5CB1E4DF-28C2-479A-AE86-328C29F74AAD}\RP1\A0000142.dll Infected: Trojan.Win32.Vapsup.fxv skipped
C:\System Volume Information\_restore{5CB1E4DF-28C2-479A-AE86-328C29F74AAD}\RP1\A0000143.exe Infected: Trojan.Win32.Vapsup.fyz skipped
C:\System Volume Information\_restore{5CB1E4DF-28C2-479A-AE86-328C29F74AAD}\RP1\A0000163.exe Infected: Trojan.Win32.Vapsup.fwt skipped
C:\System Volume Information\_restore{5CB1E4DF-28C2-479A-AE86-328C29F74AAD}\RP1\A0000164.exe Infected: Trojan.Win32.Vapsup.fyz skipped
C:\System Volume Information\_restore{5CB1E4DF-28C2-479A-AE86-328C29F74AAD}\RP1\A0000165.dll Infected: Trojan.Win32.Vapsup.fyz skipped
C:\System Volume Information\_restore{5CB1E4DF-28C2-479A-AE86-328C29F74AAD}\RP1\A0000166.exe Infected: Trojan.Win32.Vapsup.fyx skipped
C:\System Volume Information\_restore{5CB1E4DF-28C2-479A-AE86-328C29F74AAD}\RP1\A0000167.exe Infected: Trojan.Win32.Vapsup.fwa skipped
C:\System Volume Information\_restore{5CB1E4DF-28C2-479A-AE86-328C29F74AAD}\RP1\A0000168.dll Infected: Trojan.Win32.Vapsup.fxu skipped
C:\System Volume Information\_restore{5CB1E4DF-28C2-479A-AE86-328C29F74AAD}\RP1\A0000169.dll Infected: Trojan.Win32.Vapsup.fxv skipped
C:\System Volume Information\_restore{5CB1E4DF-28C2-479A-AE86-328C29F74AAD}\RP15\change.log Object is locked skipped
C:\WINDOWS\CSC\00000001 Object is locked skipped
C:\WINDOWS\Debug\Netlogon.log Object is locked skipped
C:\WINDOWS\Debug\oakley.log Object is locked skipped
C:\WINDOWS\Debug\PASSWD.LOG Object is locked skipped
C:\WINDOWS\Internet Logs\fwdbglog.txt Object is locked skipped
C:\WINDOWS\Internet Logs\fwpktlog.txt Object is locked skipped
C:\WINDOWS\Internet Logs\IAMDB.RDB Object is locked skipped
C:\WINDOWS\Internet Logs\tvDebug.log Object is locked skipped
C:\WINDOWS\Internet Logs\TWI02.ldb Object is locked skipped
C:\WINDOWS\SchedLgU.Txt Object is locked skipped
C:\WINDOWS\SoftwareDistribution\EventCache\{C5675D12-CD28-45CE-A09D-2222D0968E29}.bin Object is locked skipped
C:\WINDOWS\SoftwareDistribution\ReportingEvents.log Object is locked skipped
C:\WINDOWS\Sti_Trace.log Object is locked skipped
C:\WINDOWS\system32\config\AppEvent.Evt Object is locked skipped
C:\WINDOWS\system32\config\default Object is locked skipped
C:\WINDOWS\system32\config\default.LOG Object is locked skipped
C:\WINDOWS\system32\config\Internet.evt Object is locked skipped
C:\WINDOWS\system32\config\SAM Object is locked skipped
C:\WINDOWS\system32\config\SAM.LOG Object is locked skipped
C:\WINDOWS\system32\config\SecEvent.Evt Object is locked skipped
C:\WINDOWS\system32\config\SECURITY Object is locked skipped
C:\WINDOWS\system32\config\SECURITY.LOG Object is locked skipped
C:\WINDOWS\system32\config\software Object is locked skipped
C:\WINDOWS\system32\config\software.LOG Object is locked skipped
C:\WINDOWS\system32\config\SysEvent.Evt Object is locked skipped
C:\WINDOWS\system32\config\system Object is locked skipped
C:\WINDOWS\system32\config\system.LOG Object is locked skipped
C:\WINDOWS\system32\drivers\fidbox.dat Object is locked skipped
C:\WINDOWS\system32\drivers\fidbox.idx Object is locked skipped
C:\WINDOWS\system32\drivers\fidbox2.dat Object is locked skipped
C:\WINDOWS\system32\drivers\fidbox2.idx Object is locked skipped
C:\WINDOWS\system32\h323log.txt Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\INDEX.BTR Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\OBJECTS.DATA Object is locked skipped
C:\WINDOWS\Temp\ZLT04dbf.TMP Object is locked skipped
C:\WINDOWS\Temp\ZLT04dc2.TMP Object is locked skipped
C:\WINDOWS\wiadebug.log Object is locked skipped
C:\WINDOWS\wiaservc.log Object is locked skipped
C:\WINDOWS\WindowsUpdate.log Object is locked skipped
Scan process completed.
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 14:17: VIRUS ALERT!, on 6/4/2008
Platform: Windows XP SP1 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)
Boot mode: Normal
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\ZoneLabs\vsmon.exe
C:\WINDOWS\system32\crypserv.exe
C:\Program Files\NavNT\DefWatch.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Analog Devices\SoundMAX\Smtray.exe
C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe
C:\WINDOWS\SOUNDMAN.EXE
C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
C:\WINDOWS\System32\ctfmon.exe
C:\Program Files\Common Files\Intuit\QuickBooks\QBUpdate\qbupdate.exe
C:\PROGRA~1\ZONELA~1\ZONEAL~1\MAILFR~1\mantispm.exe
C:\Program Files\Messenger\msmsgs.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://forums.spybot.info/index.php
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {0D7ED1CB-3905-4335-AE9A-44BDE12BD5DC} - (no file)
O2 - BHO: (no name) - {14C50195-DBA9-4E7B-A5F7-D0BBB78CA130} - C:\WINDOWS\system32\byXQJabB.dll (file missing)
O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: (no name) - {96134ABB-AD7C-4135-A927-329B735D524F} - C:\WINDOWS\system32\pmnOEwut.dll
O3 - Toolbar: (no name) - {9FE5B166-BC73-48F4-8696-A66ADB1485AE} - (no file)
O3 - Toolbar: atfxqogp - {0FAAC4A8-2E74-4D58-9AC0-95201C69185A} - C:\WINDOWS\atfxqogp.dll (file missing)
O3 - Toolbar: atfxqogp - {23649E36-60C6-4433-880A-9DF59FC27342} - C:\WINDOWS\atfxqogp.dll (file missing)
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx
O4 - HKLM\..\Run: [Smapp] C:\Program Files\Analog Devices\SoundMAX\Smtray.exe
O4 - HKLM\..\Run: [ZoneAlarm Client] "C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe"
O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\System32\ctfmon.exe
O4 - Global Startup: Adobe Reader Speed Launch.lnk = Adobe\Acrobat 7.0\Reader\reader_sl.exe
O4 - Global Startup: Microsoft Office.lnk = Microsoft Office\Office10\OSA.EXE
O4 - Global Startup: QuickBooks Update Agent.lnk = Common Files\Intuit\QuickBooks\QBUpdate\qbupdate.exe
O4 - Global Startup: Service Manager.lnk.disabled
O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~3\Office10\EXCEL.EXE/3000
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O15 - Trusted Zone: http://www.kaspersky.com
O15 - Trusted Zone: http://www.sirius.com
O15 - Trusted Zone: http://www.trendsecure.com
O15 - Trusted Zone: http://download.windowsupdate.com
O16 - DPF: {0EB0E74A-2A76-4AB3-A7FB-9BD8C29F7F75} (CKAVWebScan Object) - http://www.kaspersky.com/kos/eng/partner/us/kavwebscan_unicode.cab
O16 - DPF: {5AE58FCF-6F6A-49B2-B064-02492C66E3F4} (MUCatalogWebControl Class) - http://catalog.update.microsoft.com/v7/site/ClientControl/en/x86/MuCatalogWebControl.cab?1212604876420
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: Domain = twi.pri
O17 - HKLM\Software\..\Telephony: DomainName = twi.pri
O20 - Winlogon Notify: pmnOEwut - C:\WINDOWS\SYSTEM32\pmnOEwut.dll
O21 - SSODL: vregfwlx - {70521286-63D7-4893-B574-D85BE1FBD30A} - C:\WINDOWS\vregfwlx.dll (file missing)
O23 - Service: Crypkey License - CrypKey (Canada) Ltd. - C:\WINDOWS\SYSTEM32\crypserv.exe
O23 - Service: DefWatch - Symantec Corporation - C:\Program Files\NavNT\DefWatch.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1150\Intel 32\IDriverT.exe
O23 - Service: Macromedia Licensing Service - Unknown owner - C:\Program Files\Common Files\Macromedia Shared\Service\Macromedia Licensing.exe
O23 - Service: QuickBooksDB - Intuit, Inc. - C:\PROGRA~1\Intuit\QUICKB~2.0\QBDBMgrN.exe
O23 - Service: TrueVector Internet Monitor (vsmon) - Zone Labs, LLC - C:\WINDOWS\system32\ZoneLabs\vsmon.exe
--
End of file - 5479 bytes
-------------------------------------------------------------------------------
KASPERSKY ONLINE SCANNER REPORT
Wednesday, June 04, 2008 14:10: VIRUS PMLERT!
Operating System: Microsoft Windows XP Professional, Service Pack 1 (Build 2600)
Kaspersky Online Scanner version: 5.0.98.0
Kaspersky Anti-Virus database last update: 4/06/2008
Kaspersky Anti-Virus database records: 829085
-------------------------------------------------------------------------------
Scan Settings:
Scan using the following antivirus database: extended
Scan Archives: true
Scan Mail Bases: true
Scan Target - My Computer:
A:\
C:\
D:\
M:\
U:\
X:\
Scan Statistics:
Total number of scanned objects: 71784
Number of viruses found: 7
Number of infected objects: 14
Number of suspicious objects: 2
Duration of the scan process: 01:37:27
Infected Object Name / Virus Name / Last Action
C:\Documents and Settings\administrator.TWI.000\Cookies\index.dat Object is locked skipped
C:\Documents and Settings\administrator.TWI.000\Local Settings\History\History.IE5\index.dat Object is locked skipped
C:\Documents and Settings\administrator.TWI.000\Local Settings\Temporary Internet Files\Content.IE5\index.dat Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\0410ed250a5d2dddd7365066da921b02_0b970814-ba4f-4506-ba54-ab3a6ee8ae9e Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\080a463d3b94bcf5c23e330efdf37a1c_0b970814-ba4f-4506-ba54-ab3a6ee8ae9e Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\082d37396edf953fb2d5cd863c92671a_0b970814-ba4f-4506-ba54-ab3a6ee8ae9e Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\0aa8f2fd44d7c3d2faf3f6ae01870858_0b970814-ba4f-4506-ba54-ab3a6ee8ae9e Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\100bbb54e60f7be13d224ad9ad8f4c3e_0b970814-ba4f-4506-ba54-ab3a6ee8ae9e Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\1062b2ecbad8a30255a0ff7c9c2caddb_0b970814-ba4f-4506-ba54-ab3a6ee8ae9e Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\110a01bd4a9787766432af90feceea75_0b970814-ba4f-4506-ba54-ab3a6ee8ae9e Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\177ec0e8f76ce35f3a07b9e41572b86c_0b970814-ba4f-4506-ba54-ab3a6ee8ae9e Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\1b7c087f6ef5110e1bd7394707b2da0b_0b970814-ba4f-4506-ba54-ab3a6ee8ae9e Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\1d7cd73a778d5cf6fa382c50db30579c_0b970814-ba4f-4506-ba54-ab3a6ee8ae9e Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\1f0204d37c0a86b7906aab0a56bc21cf_0b970814-ba4f-4506-ba54-ab3a6ee8ae9e Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\1fb04235c5d1116ce0bdd7295eaad217_0b970814-ba4f-4506-ba54-ab3a6ee8ae9e Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\20308be89fdce02dc9aaeabfa8a028eb_0b970814-ba4f-4506-ba54-ab3a6ee8ae9e Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\228c1b78f49ed8edf9f0b25cac9c1965_0b970814-ba4f-4506-ba54-ab3a6ee8ae9e Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\28f632e8e3c56bb1ab900147ab487870_0b970814-ba4f-4506-ba54-ab3a6ee8ae9e Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\2c671a0413fe288e256d8422456a0811_0b970814-ba4f-4506-ba54-ab3a6ee8ae9e Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\3053c90eeb34d1e2f522ea6b30d803ef_0b970814-ba4f-4506-ba54-ab3a6ee8ae9e Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\3bdcc8d95d53c0d05151509f12e89cb9_0b970814-ba4f-4506-ba54-ab3a6ee8ae9e Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\3c60f589cc255b377dc129ac185612e1_0b970814-ba4f-4506-ba54-ab3a6ee8ae9e Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\3c956f8f451f3ef9c23aa0b00bde6d22_0b970814-ba4f-4506-ba54-ab3a6ee8ae9e Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\3d65ca31cbae8224f0d5321d5e43447f_0b970814-ba4f-4506-ba54-ab3a6ee8ae9e Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\44d59f5532738a0bb7537438a0cc022b_0b970814-ba4f-4506-ba54-ab3a6ee8ae9e Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\456f1fd8a319cace7774b0dd2835df73_0b970814-ba4f-4506-ba54-ab3a6ee8ae9e Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\474ff5261149e7be96e1cd1f523ae064_0b970814-ba4f-4506-ba54-ab3a6ee8ae9e Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\490ce0e0c6e6ae71d70d87456f4b334d_0b970814-ba4f-4506-ba54-ab3a6ee8ae9e Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\496c597b6e3f0110cee989a97bdd1ad4_0b970814-ba4f-4506-ba54-ab3a6ee8ae9e Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\497ba477e79f6c7e4bd4939e9e956b5c_0b970814-ba4f-4506-ba54-ab3a6ee8ae9e Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\4a1b954f53461e7956b8b9d7591bc571_0b970814-ba4f-4506-ba54-ab3a6ee8ae9e Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\4abb8a2e665bac5a773255594520719e_0b970814-ba4f-4506-ba54-ab3a6ee8ae9e Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\4b54e3a597d203c83b718691d491c9ff_0b970814-ba4f-4506-ba54-ab3a6ee8ae9e Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\4e9f09afccf16811e81ae6aeb09742be_0b970814-ba4f-4506-ba54-ab3a6ee8ae9e Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\4f64ac1dd507db4e966b5e9726f6dc54_0b970814-ba4f-4506-ba54-ab3a6ee8ae9e Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\545dd6423944901a3887b63f4b36db01_0b970814-ba4f-4506-ba54-ab3a6ee8ae9e Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\5b1df77d9ceb783d3aeee6938d805f55_0b970814-ba4f-4506-ba54-ab3a6ee8ae9e Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\5ebe9d0dde74477bfb78bc00ae3de754_0b970814-ba4f-4506-ba54-ab3a6ee8ae9e Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\6041df0796dfc813829a5c72ffd0c449_0b970814-ba4f-4506-ba54-ab3a6ee8ae9e Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\60d7d1f4b181cbcc4f1ad194f8b502c2_0b970814-ba4f-4506-ba54-ab3a6ee8ae9e Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\629b7b135c0c3eab5f71ec2fef495afb_0b970814-ba4f-4506-ba54-ab3a6ee8ae9e Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\62f61c1c61f6c6a0b6966bff07ecf4d3_0b970814-ba4f-4506-ba54-ab3a6ee8ae9e Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\6313d3f6276ff1763d5f005f596daa15_0b970814-ba4f-4506-ba54-ab3a6ee8ae9e Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\63a599bbf83f504b484c285a9646ed77_0b970814-ba4f-4506-ba54-ab3a6ee8ae9e Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\649c1a9754b21ae4d657a2fb65b630d9_0b970814-ba4f-4506-ba54-ab3a6ee8ae9e Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\6b6037da78ebb81a38d9e8375a0ac776_0b970814-ba4f-4506-ba54-ab3a6ee8ae9e Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\6d07575f7c38253feca4c19b0b89b636_0b970814-ba4f-4506-ba54-ab3a6ee8ae9e Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\6d93d3883ba7822f4253f7704ef57156_0b970814-ba4f-4506-ba54-ab3a6ee8ae9e Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\724ef4c3701be22363d6b077ad959d69_0b970814-ba4f-4506-ba54-ab3a6ee8ae9e Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\7912663e59b7180a79ee1d094e925932_0b970814-ba4f-4506-ba54-ab3a6ee8ae9e Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\7a39bdd6b121959a8e81f46897330022_0b970814-ba4f-4506-ba54-ab3a6ee8ae9e Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\7b5d1dd0e7174974e1f5352bfdedcbf6_0b970814-ba4f-4506-ba54-ab3a6ee8ae9e Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\7c70406f68a201f2499f3f74b72b75f3_0b970814-ba4f-4506-ba54-ab3a6ee8ae9e Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\7ce5950b7e4bad7e905a74ea9bae7836_0b970814-ba4f-4506-ba54-ab3a6ee8ae9e Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\7d4d1e954bd8baca556d1da737bc5dd7_0b970814-ba4f-4506-ba54-ab3a6ee8ae9e Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\8215509b79862a98fd512f88eb9a0f56_0b970814-ba4f-4506-ba54-ab3a6ee8ae9e Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\82a998e1e75bf1a776e09295ff6b297b_0b970814-ba4f-4506-ba54-ab3a6ee8ae9e Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\832ddf1bdb66529723062dc2e5766365_0b970814-ba4f-4506-ba54-ab3a6ee8ae9e Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\85dc6f8f6f36dd2952519fa65342fd20_0b970814-ba4f-4506-ba54-ab3a6ee8ae9e Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\868f408f655c61833f991a53afbe1a43_0b970814-ba4f-4506-ba54-ab3a6ee8ae9e Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\86d522958b378ffa33870ee5bdcd9d4b_0b970814-ba4f-4506-ba54-ab3a6ee8ae9e Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\8a973a6ccaeb320e2928e964021de1f3_0b970814-ba4f-4506-ba54-ab3a6ee8ae9e Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\906f7d9774428df637c490e21a1563ae_0b970814-ba4f-4506-ba54-ab3a6ee8ae9e Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\90c613cc3f7149869a7f90ef7d1fabb1_0b970814-ba4f-4506-ba54-ab3a6ee8ae9e Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\9425ca2f03553878ebe6352782fb1349_0b970814-ba4f-4506-ba54-ab3a6ee8ae9e Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\95d4953ca69527945bb973d574235111_0b970814-ba4f-4506-ba54-ab3a6ee8ae9e Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\969eddcaa037e241811a438868293baa_0b970814-ba4f-4506-ba54-ab3a6ee8ae9e Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\9722ddefe33f246c1caad712a535970d_0b970814-ba4f-4506-ba54-ab3a6ee8ae9e Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\977ff6b5478aed8f28fa505f1a432d7f_0b970814-ba4f-4506-ba54-ab3a6ee8ae9e Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\9a03ccf22f1f06a93c1b9cc26e0d221b_0b970814-ba4f-4506-ba54-ab3a6ee8ae9e Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\9ace309a6ae7643fb3e9bb2f0b18f92c_0b970814-ba4f-4506-ba54-ab3a6ee8ae9e Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\9dfae7c6879e3f5e031899f228fcc5e2_0b970814-ba4f-4506-ba54-ab3a6ee8ae9e Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\a068ebc6b9592baf4a541053941856b7_0b970814-ba4f-4506-ba54-ab3a6ee8ae9e Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\a6d7918c469ebf5f5504d3797d1a6eb2_0b970814-ba4f-4506-ba54-ab3a6ee8ae9e Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\a7f4ed5afadc8248128e23d5591df408_0b970814-ba4f-4506-ba54-ab3a6ee8ae9e Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\acc70d1f281678e93f518b566da9823f_0b970814-ba4f-4506-ba54-ab3a6ee8ae9e Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\ad34635a95b9f6e67dc6da00c5fcd30b_0b970814-ba4f-4506-ba54-ab3a6ee8ae9e Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\b0649270b1cf9d0ba27c383cd2ab6a49_0b970814-ba4f-4506-ba54-ab3a6ee8ae9e Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\b4819763ad3b187a933a465791e67bff_0b970814-ba4f-4506-ba54-ab3a6ee8ae9e Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\b928beb930cb59cd15e6304ca48e6766_0b970814-ba4f-4506-ba54-ab3a6ee8ae9e Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\bf1cf2f545f94b4e6d0a096de3a2a09f_0b970814-ba4f-4506-ba54-ab3a6ee8ae9e Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\cc60225d2efb3389be171bf0c31e6e49_0b970814-ba4f-4506-ba54-ab3a6ee8ae9e Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\cfd051ae534574fe27cae0f263ca2be9_0b970814-ba4f-4506-ba54-ab3a6ee8ae9e Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\d1ab1aa8c663893c838807bcb97c696e_0b970814-ba4f-4506-ba54-ab3a6ee8ae9e Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\d7cb2d391e22da3f41a043ad2cb4fca3_0b970814-ba4f-4506-ba54-ab3a6ee8ae9e Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\d992ac7da79b96217569c3591e7266ea_0b970814-ba4f-4506-ba54-ab3a6ee8ae9e Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\dc25519fda7a8050ee05bc3559e73d7e_0b970814-ba4f-4506-ba54-ab3a6ee8ae9e Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\dc6bcb3e2fcc28c89be663b3880b954a_0b970814-ba4f-4506-ba54-ab3a6ee8ae9e Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\dd8a86021bdfff7d5666fdc177ed3f13_0b970814-ba4f-4506-ba54-ab3a6ee8ae9e Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\e1eb9663534192409dc0824e52ef6ca1_0b970814-ba4f-4506-ba54-ab3a6ee8ae9e Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\e1ec7d530f156e262d1735c027a0d63f_0b970814-ba4f-4506-ba54-ab3a6ee8ae9e Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\e4f6eae94957d360bdccce77d16adba9_0b970814-ba4f-4506-ba54-ab3a6ee8ae9e Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\e73ec46d9d6900db0368f6cab0ec8f9d_0b970814-ba4f-4506-ba54-ab3a6ee8ae9e Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\e878938555d432791ad774655ac4c271_0b970814-ba4f-4506-ba54-ab3a6ee8ae9e Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\e9125e1990eeeb65c59b103b0608dbb1_0b970814-ba4f-4506-ba54-ab3a6ee8ae9e Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\ea1fd982a2651bbbb2e94c500415d384_0b970814-ba4f-4506-ba54-ab3a6ee8ae9e Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\ea47d348b39a2ea7401cecd0b6e2dff8_0b970814-ba4f-4506-ba54-ab3a6ee8ae9e Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\ead2368b3b624f79e9ad7111bd8d94a2_0b970814-ba4f-4506-ba54-ab3a6ee8ae9e Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\ec6fa48bfc1c64f980553617213acac4_0b970814-ba4f-4506-ba54-ab3a6ee8ae9e Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\ec99085cf4f9fb25b63b34c56831136e_0b970814-ba4f-4506-ba54-ab3a6ee8ae9e Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\ecc58b4d43339e3f0060a3adced51e62_0b970814-ba4f-4506-ba54-ab3a6ee8ae9e Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\ef5359ad2b209e10879264fbe67279b4_0b970814-ba4f-4506-ba54-ab3a6ee8ae9e Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\f0f5f61a7007d7bbbc3a0e1baca5b396_0b970814-ba4f-4506-ba54-ab3a6ee8ae9e Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\f3111330c8e749dd13c102f8969ab446_0b970814-ba4f-4506-ba54-ab3a6ee8ae9e Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\fc11040ee083cac0ee949f390b28cf76_0b970814-ba4f-4506-ba54-ab3a6ee8ae9e Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\fd08e82879f38cbdd1bc448263943ccd_0b970814-ba4f-4506-ba54-ab3a6ee8ae9e Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\ff5f3e67e396a2a711cfe17697d4c756_0b970814-ba4f-4506-ba54-ab3a6ee8ae9e Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Dr Watson\user.dmp Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Network\Downloader\qmgr0.dat Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Network\Downloader\qmgr1.dat Object is locked skipped
C:\Documents and Settings\LocalService\Cookies\index.dat Object is locked skipped
C:\Documents and Settings\LocalService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat Object is locked skipped
C:\Documents and Settings\LocalService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped
C:\Documents and Settings\LocalService\Local Settings\History\History.IE5\index.dat Object is locked skipped
C:\Documents and Settings\LocalService\Local Settings\Temporary Internet Files\Content.IE5\index.dat Object is locked skipped
C:\Documents and Settings\LocalService\NTUSER.DAT Object is locked skipped
C:\Documents and Settings\LocalService\ntuser.dat.LOG Object is locked skipped
C:\Documents and Settings\NetworkService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat Object is locked skipped
C:\Documents and Settings\NetworkService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped
C:\Documents and Settings\NetworkService\NTUSER.DAT Object is locked skipped
C:\Documents and Settings\NetworkService\ntuser.dat.LOG Object is locked skipped
C:\Documents and Settings\rmundell\ntuser.dat Object is locked skipped
C:\Documents and Settings\rmundell\ntuser.dat.LOG Object is locked skipped
C:\Documents and Settings\rmundell.TWI\Application Data\MailFrontier\ASD.log Object is locked skipped
C:\Documents and Settings\rmundell.TWI\Cookies\index.dat Object is locked skipped
C:\Documents and Settings\rmundell.TWI\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat Object is locked skipped
C:\Documents and Settings\rmundell.TWI\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped
C:\Documents and Settings\rmundell.TWI\Local Settings\History\History.IE5\index.dat Object is locked skipped
C:\Documents and Settings\rmundell.TWI\Local Settings\Temp\~DFDD7D.tmp Object is locked skipped
C:\Documents and Settings\rmundell.TWI\Local Settings\Temporary Internet Files\Content.IE5\index.dat Object is locked skipped
C:\Documents and Settings\rmundell.TWI\NTUSER.DAT Object is locked skipped
C:\Documents and Settings\rmundell.TWI\ntuser.dat.LOG Object is locked skipped
C:\Documents and Settings\rmundell.TWIK\Local Settings\Application Data\Identities\{DE2F43EE-75C5-4AA9-AF8D-34223AC8D033}\Microsoft\Outlook Express\Deleted Items.dbx/[From RegionsNet Bank <OnlineBanking@regionsnet.com>][Date Sat, 26 Jan 2008 18:29:48 -0800]/html Suspicious: Trojan-Spy.HTML.Fraud.gen skipped
C:\Documents and Settings\rmundell.TWIK\Local Settings\Application Data\Identities\{DE2F43EE-75C5-4AA9-AF8D-34223AC8D033}\Microsoft\Outlook Express\Deleted Items.dbx MailMSOutlook5: suspicious - 1 skipped
C:\Program Files\Common Files\Intuit\QuickBooks\QBUpdate\Log\CHANNEL.LOG Object is locked skipped
C:\Program Files\Intuit\QuickBooks Enterprise Solutions 6.0\Components\DownloadQB16\Guide\.update\.QBLock.lck Object is locked skipped
C:\Program Files\Research In Motion\BlackBerry\Transaction Manager\ComponentData\Eventlogs\TMEventlog.log Object is locked skipped
C:\System Volume Information\MountPointManagerRemoteDatabase Object is locked skipped
C:\System Volume Information\_restore{5CB1E4DF-28C2-479A-AE86-328C29F74AAD}\RP1\A0000137.dll Infected: Trojan.Win32.Vapsup.fyz skipped
C:\System Volume Information\_restore{5CB1E4DF-28C2-479A-AE86-328C29F74AAD}\RP1\A0000138.exe Infected: Trojan.Win32.Vapsup.fwt skipped
C:\System Volume Information\_restore{5CB1E4DF-28C2-479A-AE86-328C29F74AAD}\RP1\A0000139.exe Infected: Trojan.Win32.Vapsup.fyx skipped
C:\System Volume Information\_restore{5CB1E4DF-28C2-479A-AE86-328C29F74AAD}\RP1\A0000140.exe Infected: Trojan.Win32.Vapsup.fwa skipped
C:\System Volume Information\_restore{5CB1E4DF-28C2-479A-AE86-328C29F74AAD}\RP1\A0000141.dll Infected: Trojan.Win32.Vapsup.fxu skipped
C:\System Volume Information\_restore{5CB1E4DF-28C2-479A-AE86-328C29F74AAD}\RP1\A0000142.dll Infected: Trojan.Win32.Vapsup.fxv skipped
C:\System Volume Information\_restore{5CB1E4DF-28C2-479A-AE86-328C29F74AAD}\RP1\A0000143.exe Infected: Trojan.Win32.Vapsup.fyz skipped
C:\System Volume Information\_restore{5CB1E4DF-28C2-479A-AE86-328C29F74AAD}\RP1\A0000163.exe Infected: Trojan.Win32.Vapsup.fwt skipped
C:\System Volume Information\_restore{5CB1E4DF-28C2-479A-AE86-328C29F74AAD}\RP1\A0000164.exe Infected: Trojan.Win32.Vapsup.fyz skipped
C:\System Volume Information\_restore{5CB1E4DF-28C2-479A-AE86-328C29F74AAD}\RP1\A0000165.dll Infected: Trojan.Win32.Vapsup.fyz skipped
C:\System Volume Information\_restore{5CB1E4DF-28C2-479A-AE86-328C29F74AAD}\RP1\A0000166.exe Infected: Trojan.Win32.Vapsup.fyx skipped
C:\System Volume Information\_restore{5CB1E4DF-28C2-479A-AE86-328C29F74AAD}\RP1\A0000167.exe Infected: Trojan.Win32.Vapsup.fwa skipped
C:\System Volume Information\_restore{5CB1E4DF-28C2-479A-AE86-328C29F74AAD}\RP1\A0000168.dll Infected: Trojan.Win32.Vapsup.fxu skipped
C:\System Volume Information\_restore{5CB1E4DF-28C2-479A-AE86-328C29F74AAD}\RP1\A0000169.dll Infected: Trojan.Win32.Vapsup.fxv skipped
C:\System Volume Information\_restore{5CB1E4DF-28C2-479A-AE86-328C29F74AAD}\RP15\change.log Object is locked skipped
C:\WINDOWS\CSC\00000001 Object is locked skipped
C:\WINDOWS\Debug\Netlogon.log Object is locked skipped
C:\WINDOWS\Debug\oakley.log Object is locked skipped
C:\WINDOWS\Debug\PASSWD.LOG Object is locked skipped
C:\WINDOWS\Internet Logs\fwdbglog.txt Object is locked skipped
C:\WINDOWS\Internet Logs\fwpktlog.txt Object is locked skipped
C:\WINDOWS\Internet Logs\IAMDB.RDB Object is locked skipped
C:\WINDOWS\Internet Logs\tvDebug.log Object is locked skipped
C:\WINDOWS\Internet Logs\TWI02.ldb Object is locked skipped
C:\WINDOWS\SchedLgU.Txt Object is locked skipped
C:\WINDOWS\SoftwareDistribution\EventCache\{C5675D12-CD28-45CE-A09D-2222D0968E29}.bin Object is locked skipped
C:\WINDOWS\SoftwareDistribution\ReportingEvents.log Object is locked skipped
C:\WINDOWS\Sti_Trace.log Object is locked skipped
C:\WINDOWS\system32\config\AppEvent.Evt Object is locked skipped
C:\WINDOWS\system32\config\default Object is locked skipped
C:\WINDOWS\system32\config\default.LOG Object is locked skipped
C:\WINDOWS\system32\config\Internet.evt Object is locked skipped
C:\WINDOWS\system32\config\SAM Object is locked skipped
C:\WINDOWS\system32\config\SAM.LOG Object is locked skipped
C:\WINDOWS\system32\config\SecEvent.Evt Object is locked skipped
C:\WINDOWS\system32\config\SECURITY Object is locked skipped
C:\WINDOWS\system32\config\SECURITY.LOG Object is locked skipped
C:\WINDOWS\system32\config\software Object is locked skipped
C:\WINDOWS\system32\config\software.LOG Object is locked skipped
C:\WINDOWS\system32\config\SysEvent.Evt Object is locked skipped
C:\WINDOWS\system32\config\system Object is locked skipped
C:\WINDOWS\system32\config\system.LOG Object is locked skipped
C:\WINDOWS\system32\drivers\fidbox.dat Object is locked skipped
C:\WINDOWS\system32\drivers\fidbox.idx Object is locked skipped
C:\WINDOWS\system32\drivers\fidbox2.dat Object is locked skipped
C:\WINDOWS\system32\drivers\fidbox2.idx Object is locked skipped
C:\WINDOWS\system32\h323log.txt Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\INDEX.BTR Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\OBJECTS.DATA Object is locked skipped
C:\WINDOWS\Temp\ZLT04dbf.TMP Object is locked skipped
C:\WINDOWS\Temp\ZLT04dc2.TMP Object is locked skipped
C:\WINDOWS\wiadebug.log Object is locked skipped
C:\WINDOWS\wiaservc.log Object is locked skipped
C:\WINDOWS\WindowsUpdate.log Object is locked skipped
Scan process completed.
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 14:17: VIRUS ALERT!, on 6/4/2008
Platform: Windows XP SP1 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)
Boot mode: Normal
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\ZoneLabs\vsmon.exe
C:\WINDOWS\system32\crypserv.exe
C:\Program Files\NavNT\DefWatch.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Analog Devices\SoundMAX\Smtray.exe
C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe
C:\WINDOWS\SOUNDMAN.EXE
C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
C:\WINDOWS\System32\ctfmon.exe
C:\Program Files\Common Files\Intuit\QuickBooks\QBUpdate\qbupdate.exe
C:\PROGRA~1\ZONELA~1\ZONEAL~1\MAILFR~1\mantispm.exe
C:\Program Files\Messenger\msmsgs.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://forums.spybot.info/index.php
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {0D7ED1CB-3905-4335-AE9A-44BDE12BD5DC} - (no file)
O2 - BHO: (no name) - {14C50195-DBA9-4E7B-A5F7-D0BBB78CA130} - C:\WINDOWS\system32\byXQJabB.dll (file missing)
O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: (no name) - {96134ABB-AD7C-4135-A927-329B735D524F} - C:\WINDOWS\system32\pmnOEwut.dll
O3 - Toolbar: (no name) - {9FE5B166-BC73-48F4-8696-A66ADB1485AE} - (no file)
O3 - Toolbar: atfxqogp - {0FAAC4A8-2E74-4D58-9AC0-95201C69185A} - C:\WINDOWS\atfxqogp.dll (file missing)
O3 - Toolbar: atfxqogp - {23649E36-60C6-4433-880A-9DF59FC27342} - C:\WINDOWS\atfxqogp.dll (file missing)
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx
O4 - HKLM\..\Run: [Smapp] C:\Program Files\Analog Devices\SoundMAX\Smtray.exe
O4 - HKLM\..\Run: [ZoneAlarm Client] "C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe"
O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\System32\ctfmon.exe
O4 - Global Startup: Adobe Reader Speed Launch.lnk = Adobe\Acrobat 7.0\Reader\reader_sl.exe
O4 - Global Startup: Microsoft Office.lnk = Microsoft Office\Office10\OSA.EXE
O4 - Global Startup: QuickBooks Update Agent.lnk = Common Files\Intuit\QuickBooks\QBUpdate\qbupdate.exe
O4 - Global Startup: Service Manager.lnk.disabled
O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~3\Office10\EXCEL.EXE/3000
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O15 - Trusted Zone: http://www.kaspersky.com
O15 - Trusted Zone: http://www.sirius.com
O15 - Trusted Zone: http://www.trendsecure.com
O15 - Trusted Zone: http://download.windowsupdate.com
O16 - DPF: {0EB0E74A-2A76-4AB3-A7FB-9BD8C29F7F75} (CKAVWebScan Object) - http://www.kaspersky.com/kos/eng/partner/us/kavwebscan_unicode.cab
O16 - DPF: {5AE58FCF-6F6A-49B2-B064-02492C66E3F4} (MUCatalogWebControl Class) - http://catalog.update.microsoft.com/v7/site/ClientControl/en/x86/MuCatalogWebControl.cab?1212604876420
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: Domain = twi.pri
O17 - HKLM\Software\..\Telephony: DomainName = twi.pri
O20 - Winlogon Notify: pmnOEwut - C:\WINDOWS\SYSTEM32\pmnOEwut.dll
O21 - SSODL: vregfwlx - {70521286-63D7-4893-B574-D85BE1FBD30A} - C:\WINDOWS\vregfwlx.dll (file missing)
O23 - Service: Crypkey License - CrypKey (Canada) Ltd. - C:\WINDOWS\SYSTEM32\crypserv.exe
O23 - Service: DefWatch - Symantec Corporation - C:\Program Files\NavNT\DefWatch.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1150\Intel 32\IDriverT.exe
O23 - Service: Macromedia Licensing Service - Unknown owner - C:\Program Files\Common Files\Macromedia Shared\Service\Macromedia Licensing.exe
O23 - Service: QuickBooksDB - Intuit, Inc. - C:\PROGRA~1\Intuit\QUICKB~2.0\QBDBMgrN.exe
O23 - Service: TrueVector Internet Monitor (vsmon) - Zone Labs, LLC - C:\WINDOWS\system32\ZoneLabs\vsmon.exe
--
End of file - 5479 bytes