derek873
2008-06-05, 15:57
I have ongoing adware virus activity on my PC after I have removed Virtumonde using Spybot-S&D. I have read and followed your "Before You Post" document. I have run Kaspersky and HJT scans and the logs are below. Please assist yet another victim of the Virtumonde.
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 10:34:07 PM, on 5/06/2008
Platform: Windows Vista (WinNT 6.00.1904)
MSIE: Internet Explorer v7.00 (7.00.6000.16643)
Boot mode: Normal
Running processes:
C:\Windows\system32\taskeng.exe
C:\Windows\system32\taskeng.exe
C:\Program Files\ASUS\ASUS Live Update\ALU.exe
C:\Windows\system32\Dwm.exe
C:\Windows\Explorer.EXE
C:\Program Files\Windows Defender\MSASCui.exe
C:\Program Files\Motorola\SMSERIAL\sm56hlpr.exe
C:\Windows\RtHDVCpl.exe
C:\Windows\vsnp2std.exe
C:\Program Files\ASUS\ATK Media\DMedia.exe
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\Program Files\Common Files\Symantec Shared\ccApp.exe
C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe
C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\Windows Sidebar\sidebar.exe
C:\Program Files\Google\GoogleToolbarNotifier\1.2.1128.5462\GoogleToolbarNotifier.exe
C:\Program Files\ASUS\Asus MultiFrame\MultiFrame.exe
C:\Windows\System32\rundll32.exe
C:\Windows\system32\Taskmgr.exe
C:\Windows\system32\wuauclt.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.asus.com
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
O1 - Hosts: ::1 localhost
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {1E8A6170-7264-4D0F-BEAE-D42A53123C75} - C:\Program Files\Common Files\Symantec Shared\coShared\Browser\1.0\NppBho.dll
O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\Program Files\Microsoft Office\Office12\GrooveShellExtensions.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar2.dll
O3 - Toolbar: Show Norton Toolbar - {90222687-F593-4738-B738-FBEE9C7B26DF} - C:\Program Files\Common Files\Symantec Shared\coShared\Browser\1.0\UIBHO.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar2.dll
O4 - HKLM\..\Run: [Windows Defender] %ProgramFiles%\Windows Defender\MSASCui.exe -hide
O4 - HKLM\..\Run: [SMSERIAL] C:\Program Files\Motorola\SMSERIAL\sm56hlpr.exe
O4 - HKLM\..\Run: [RtHDVCpl] RtHDVCpl.exe
O4 - HKLM\..\Run: [snp2std] C:\Windows\vsnp2std.exe
O4 - HKLM\..\Run: [ATKMEDIA] C:\Program Files\ASUS\ATK Media\DMEDIA.EXE
O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [osCheck] "C:\Program Files\Norton Internet Security\osCheck.exe"
O4 - HKLM\..\Run: [NvSvc] RUNDLL32.EXE C:\Windows\system32\nvsvc.dll,nvsvcStart
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\Windows\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\Windows\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [NeroFilterCheck] C:\Program Files\Common Files\Ahead\Lib\NeroCheck.exe
O4 - HKLM\..\Run: [ALUAlert] C:\Program Files\Symantec\LiveUpdate\ALuNotify.exe
O4 - HKLM\..\Run: [GrooveMonitor] "C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe"
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe"
O4 - HKLM\..\Run: [Symantec PIF AlertEng] "C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc.exe" /a /m "C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\AlertEng.dll"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [MSConfig] "C:\Windows\system32\msconfig.exe" /auto
O4 - HKCU\..\Run: [Sidebar] C:\Program Files\Windows Sidebar\sidebar.exe /autoRun
O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\1.2.1128.5462\GoogleToolbarNotifier.exe
O4 - HKCU\..\Run: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCenter
O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-19\..\Run: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCenter (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'NETWORK SERVICE')
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O4 - Global Startup: MultiFrame.lnk = ?
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office12\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
O9 - Extra button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: S&end to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\Office12\REFIEBAR.DLL
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O13 - Gopher Prefix:
O16 - DPF: {0EB0E74A-2A76-4AB3-A7FB-9BD8C29F7F75} (CKAVWebScan Object) - http://www.kaspersky.com/kos/eng/partner/default/kavwebscan_unicode.cab
O16 - DPF: {44990301-3C9D-426D-81DF-AAB636FA4345} (Symantec Script Runner Class) - https://www-secure.symantec.com/techsupp/asa/ss/sa/sa_cabs/tgctlsr.cab
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab
O18 - Protocol: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - C:\Program Files\Microsoft Office\Office12\GrooveSystemServices.dll
O23 - Service: Apple Mobile Device - Apple, Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: ASLDR Service (ASLDRService) - Unknown owner - C:\Program Files\ATK Hotkey\ASLDRSrv.exe
O23 - Service: Automatic LiveUpdate Scheduler - Symantec Corporation - C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
O23 - Service: Symantec Lic NetConnect service (CLTNetCnService) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
O23 - Service: COM Host (comHost) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\VAScanner\comHost.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: Symantec IS Password Validation (ISPwdSvc) - Symantec Corporation - C:\Program Files\Norton Internet Security\isPwdSvc.exe
O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:\Program Files\Common Files\LightScribe\LSSrvc.exe
O23 - Service: LiveUpdate - Symantec Corporation - C:\PROGRA~1\Symantec\LIVEUP~1\LUCOMS~1.EXE
O23 - Service: LiveUpdate Notice Service Ex (LiveUpdate Notice Ex) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
O23 - Service: LiveUpdate Notice Service - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc.exe
O23 - Service: MediaManagerService - Unknown owner - C:\Program Files\Media Manager\Viiv\MediaManager.Service.exe
O23 - Service: NBService - Nero AG - C:\Program Files\Nero\Nero 7\Nero BackItUp\NBService.exe
O23 - Service: NMIndexingService - Nero AG - C:\Program Files\Common Files\Ahead\Lib\NMIndexingService.exe
O23 - Service: SBSD Security Center Service (SBSDWSCService) - Safer Networking Ltd. - C:\Program Files\Spybot - Search & Destroy\SDWinSec.exe
O23 - Service: spmgr - Unknown owner - C:\Program Files\ASUS\NB Probe\SPM\spmgr.exe
O23 - Service: Symantec Core LC - Unknown owner - C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
O23 - Service: Symantec AppCore Service (SymAppCore) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\AppCore\AppSvc32.exe
--
End of file - 9907 bytes
-------------------------------------------------------------------------------
KASPERSKY ONLINE SCANNER REPORT
Friday, May 30, 2008 7:13:19 AM
Operating System: Microsoft Windows Vista Home Edition, (Build 6000)
Kaspersky Online Scanner version: 5.0.98.0
Kaspersky Anti-Virus database last update: 29/05/2008
Kaspersky Anti-Virus database records: 812078
-------------------------------------------------------------------------------
Scan Settings:
Scan using the following antivirus database: extended
Scan Archives: true
Scan Mail Bases: true
Scan Target - My Computer:
C:\
D:\
E:\
Scan Statistics:
Total number of scanned objects: 89893
Number of viruses found: 4
Number of infected objects: 9
Number of suspicious objects: 0
Duration of the scan process: 00:41:15
Infected Object Name / Virus Name / Last Action
C:\Boot\BCD Object is locked skipped
C:\Boot\BCD.LOG Object is locked skipped
C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcrst.dll Object is locked skipped
C:\Program Files\Common Files\Symantec Shared\EENGINE\EPERSIST.DAT Object is locked skipped
C:\Program Files\Common Files\Symantec Shared\NFWEVT.LOG Object is locked skipped
C:\Program Files\InstallShield Installation Information\{139B0FFA-187E-4BA1-BCA6-6B56B2B6AB8C}\setup.ilg Object is locked skipped
C:\Program Files\InstallShield Installation Information\{2C164906-E68F-462A-9010-70DD022223EF}\Setup.ilg Object is locked skipped
C:\Program Files\InstallShield Installation Information\{6324A1EF-CEF4-43E3-8BCD-9EF3F67317FD}\setup.ilg Object is locked skipped
C:\Program Files\InstallShield Installation Information\{9518F764-C54D-47B2-9E73-154B21E79FD2}\Setup.ilg Object is locked skipped
C:\Program Files\InstallShield Installation Information\{9D48531D-2135-49FC-BC29-ACCDA5396A76}\setup.ilg Object is locked skipped
C:\Program Files\InstallShield Installation Information\{B9B9863A-32FD-4133-ADB7-46244ED77694}\Setup.ilg Object is locked skipped
C:\Program Files\InstallShield Installation Information\{DE10AB76-4756-4913-BE25-55D1C1051F9A}\setup.ilg Object is locked skipped
C:\Program Files\InstallShield Installation Information\{DE286975-ACF1-45B8-9EF7-34E162B2C817}\Setup.ilg Object is locked skipped
C:\Program Files\InstallShield Installation Information\{E657B243-9AD4-4ECC-BE81-4CCF8D667FD0}\setup.ilg Object is locked skipped
C:\Program Files\InstallShield Installation Information\{EF4C7EB0-D71B-43A3-9552-8053DE4B0401}\Setup.ilg Object is locked skipped
C:\Program Files\InstallShield Installation Information\{F37942A8-B21B-4C5A-A1D2-B676BF55EAE0}\Setup.ilg Object is locked skipped
C:\Program Files\Norton Internet Security\Norton AntiVirus\AVApp.log Object is locked skipped
C:\Program Files\Norton Internet Security\Norton AntiVirus\AVError.log Object is locked skipped
C:\Program Files\Norton Internet Security\Norton AntiVirus\AVVirus.log Object is locked skipped
C:\ProgramData\Symantec\Common Client\settings.bak Object is locked skipped
C:\ProgramData\Symantec\Common Client\settings.dat Object is locked skipped
C:\ProgramData\Symantec\LiveUpdate\2008-05-30_Log.ALUSchedulerSvc.LiveUpdate Object is locked skipped
C:\ProgramData\Symantec\SPBBC\BBConfig.log Object is locked skipped
C:\ProgramData\Symantec\SPBBC\BBDebug.log Object is locked skipped
C:\ProgramData\Symantec\SPBBC\BBDetect.log Object is locked skipped
C:\ProgramData\Symantec\SPBBC\BBNotify.log Object is locked skipped
C:\ProgramData\Symantec\SPBBC\BBRefr.log Object is locked skipped
C:\ProgramData\Symantec\SPBBC\BBSetCfg.log Object is locked skipped
C:\ProgramData\Symantec\SPBBC\BBSetCfg2.log Object is locked skipped
C:\ProgramData\Symantec\SPBBC\BBSetDev.log Object is locked skipped
C:\ProgramData\Symantec\SPBBC\BBSetLoc.log Object is locked skipped
C:\ProgramData\Symantec\SPBBC\BBSetUsr.log Object is locked skipped
C:\ProgramData\Symantec\SPBBC\BBStHash.log Object is locked skipped
C:\ProgramData\Symantec\SPBBC\BBValid.log Object is locked skipped
C:\ProgramData\Symantec\SPBBC\SPPolicy.log Object is locked skipped
C:\ProgramData\Symantec\SPBBC\SPStart.log Object is locked skipped
C:\ProgramData\Symantec\SPBBC\SPStop.log Object is locked skipped
C:\ProgramData\Symantec\SRTSP\SrtErEvt.log Object is locked skipped
C:\ProgramData\Symantec\SRTSP\SrtMoEvt.log Object is locked skipped
C:\ProgramData\Symantec\SRTSP\SrtNvEvt.log Object is locked skipped
C:\ProgramData\Symantec\SRTSP\SrtScEvt.log Object is locked skipped
C:\ProgramData\Symantec\SRTSP\SrtTxFEvt.log Object is locked skipped
C:\ProgramData\Symantec\SRTSP\SrtViEvt.log Object is locked skipped
C:\ProgramData\Symantec\SubEng\submissions.idx Object is locked skipped
C:\ProgramData\Symantec\SymNetDrv\SNDALRT.log Object is locked skipped
C:\ProgramData\Symantec\SymNetDrv\SNDCON.log Object is locked skipped
C:\ProgramData\Symantec\SymNetDrv\SNDDBG.log Object is locked skipped
C:\ProgramData\Symantec\SymNetDrv\SNDFW.log Object is locked skipped
C:\ProgramData\Symantec\SymNetDrv\SNDIDS.log Object is locked skipped
C:\ProgramData\Symantec\SymNetDrv\SNDSYS.log Object is locked skipped
C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\cbfb3a0a20b8daad5ddfe850309a2758_789de25b-be5d-46b0-b6ee-77ef0e0a8162 Object is locked skipped
C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\fc1e3851f429ea606d6ff1e01a5229f1_789de25b-be5d-46b0-b6ee-77ef0e0a8162 Object is locked skipped
C:\ProgramData\Microsoft\eHome\logs\eHomeLog00.sqm Object is locked skipped
C:\ProgramData\Microsoft\eHome\logs\eHomeLog01.sqm Object is locked skipped
C:\ProgramData\Microsoft\eHome\logs\eHomeLog02.sqm Object is locked skipped
C:\ProgramData\Microsoft\eHome\logs\eHomeLog03.sqm Object is locked skipped
C:\ProgramData\Microsoft\eHome\logs\eHomeLog04.sqm Object is locked skipped
C:\ProgramData\Microsoft\eHome\logs\eHomeLog05.sqm Object is locked skipped
C:\ProgramData\Microsoft\eHome\logs\eHomeLog06.sqm Object is locked skipped
C:\ProgramData\Microsoft\eHome\logs\eHomeLog07.sqm Object is locked skipped
C:\ProgramData\Microsoft\User Account Pictures\Derek.dat Object is locked skipped
C:\ProgramData\Microsoft\User Account Pictures\Russell.dat Object is locked skipped
C:\ProgramData\Microsoft\Windows\DRM\Cache\Indiv01.tmp Object is locked skipped
C:\ProgramData\Microsoft\Windows\DRM\drmstore.hds Object is locked skipped
C:\ProgramData\{B0B64EEB-1DEA-4E4C-B465-C90BBF9E8EE5}\offline\1280377A\2AB9919B\App.ico Object is locked skipped
C:\ProgramData\{B0B64EEB-1DEA-4E4C-B465-C90BBF9E8EE5}\offline\16E96B81\D122F2F2\Microsoft.mshtml.dll Object is locked skipped
C:\ProgramData\{B0B64EEB-1DEA-4E4C-B465-C90BBF9E8EE5}\offline\1C1F87FE\D122F2F2\log4net.dll Object is locked skipped
C:\ProgramData\{B0B64EEB-1DEA-4E4C-B465-C90BBF9E8EE5}\offline\1F6FC04D\2CE1328F\policy.1.0.MediaManager.Platforms.Viiv.Framework.dll Object is locked skipped
C:\ProgramData\{B0B64EEB-1DEA-4E4C-B465-C90BBF9E8EE5}\offline\238AD7FB\2CE1328F\policy.1.0.WindowsMediaFormat.xml Object is locked skipped
C:\ProgramData\{B0B64EEB-1DEA-4E4C-B465-C90BBF9E8EE5}\offline\2503188D\2CE1328F\policy.1.0.MediaManager.Core.dll Object is locked skipped
C:\ProgramData\{B0B64EEB-1DEA-4E4C-B465-C90BBF9E8EE5}\offline\29E5B010\2CE1328F\policy.1.0.MediaManager.Platforms.Viiv.Framework.xml Object is locked skipped
C:\ProgramData\{B0B64EEB-1DEA-4E4C-B465-C90BBF9E8EE5}\offline\2BD84DFE\2CE1328F\policy.3.5.MediaManager.Core.dll Object is locked skipped
C:\ProgramData\{B0B64EEB-1DEA-4E4C-B465-C90BBF9E8EE5}\offline\2E832D7F\D122F2F2\SHDocVw.dll Object is locked skipped
C:\ProgramData\{B0B64EEB-1DEA-4E4C-B465-C90BBF9E8EE5}\offline\2EFD349B\2AB9919B\License.rtf Object is locked skipped
C:\ProgramData\{B0B64EEB-1DEA-4E4C-B465-C90BBF9E8EE5}\offline\3B7E8D3A\2AB9919B\Popup.wav Object is locked skipped
C:\ProgramData\{B0B64EEB-1DEA-4E4C-B465-C90BBF9E8EE5}\offline\45646D5A\DCCD58AC\MediaManager.Service.exe Object is locked skipped
C:\ProgramData\{B0B64EEB-1DEA-4E4C-B465-C90BBF9E8EE5}\offline\4AFF6640\7B3515C7\Interop.CMMS.dll Object is locked skipped
C:\ProgramData\{B0B64EEB-1DEA-4E4C-B465-C90BBF9E8EE5}\offline\4CEBBB84\D122F2F2\AxInterop.WMPLib.dll Object is locked skipped
C:\ProgramData\{B0B64EEB-1DEA-4E4C-B465-C90BBF9E8EE5}\offline\5F332148\F2930322\WMP_Upgrade.wma Object is locked skipped
C:\ProgramData\{B0B64EEB-1DEA-4E4C-B465-C90BBF9E8EE5}\offline\5F8C991B\3C66D2F6\MediaManager.resources Object is locked skipped
C:\ProgramData\{B0B64EEB-1DEA-4E4C-B465-C90BBF9E8EE5}\offline\64E5A4E4\2CE1328F\policy.3.5.MediaManager.Platforms.Viiv.Framework.xml Object is locked skipped
C:\ProgramData\{B0B64EEB-1DEA-4E4C-B465-C90BBF9E8EE5}\offline\7132B421\D122F2F2\wmppia.dll Object is locked skipped
C:\ProgramData\{B0B64EEB-1DEA-4E4C-B465-C90BBF9E8EE5}\offline\73031766\2CE1328F\policy.3.5.WindowsMediaFormat.dll Object is locked skipped
C:\ProgramData\{B0B64EEB-1DEA-4E4C-B465-C90BBF9E8EE5}\offline\764EC703\F2930322\AxSHDocVw.dll Object is locked skipped
C:\ProgramData\{B0B64EEB-1DEA-4E4C-B465-C90BBF9E8EE5}\offline\7849FE98\C85D87C4\MediaManager.ActiveX.Sniffer.dll Object is locked skipped
C:\ProgramData\{B0B64EEB-1DEA-4E4C-B465-C90BBF9E8EE5}\offline\786E6DAD\2CE1328F\policy.3.0.WindowsMediaFormat.xml Object is locked skipped
C:\ProgramData\{B0B64EEB-1DEA-4E4C-B465-C90BBF9E8EE5}\offline\84CA1B5F\2AB9919B\readme.rtf Object is locked skipped
C:\ProgramData\{B0B64EEB-1DEA-4E4C-B465-C90BBF9E8EE5}\offline\853EC73C\F2930322\MediaManager.exe.config Object is locked skipped
C:\ProgramData\{B0B64EEB-1DEA-4E4C-B465-C90BBF9E8EE5}\offline\85D3DD96\2AB9919B\Help.chm Object is locked skipped
C:\ProgramData\{B0B64EEB-1DEA-4E4C-B465-C90BBF9E8EE5}\offline\88CF50D0\D122F2F2\Interop.WMPLib.dll Object is locked skipped
C:\ProgramData\{B0B64EEB-1DEA-4E4C-B465-C90BBF9E8EE5}\offline\8A099DC5\2CE1328F\policy.3.5.MediaManager.Platforms.Viiv.Framework.dll Object is locked skipped
C:\ProgramData\{B0B64EEB-1DEA-4E4C-B465-C90BBF9E8EE5}\offline\8B3B523\F2930322\UserInterface.dll Object is locked skipped
C:\ProgramData\{B0B64EEB-1DEA-4E4C-B465-C90BBF9E8EE5}\offline\921F110F\D4A1F967\Deregister.exe Object is locked skipped
C:\ProgramData\{B0B64EEB-1DEA-4E4C-B465-C90BBF9E8EE5}\offline\926B4195\2CE1328F\policy.3.0.MediaManager.Core.dll Object is locked skipped
C:\ProgramData\{B0B64EEB-1DEA-4E4C-B465-C90BBF9E8EE5}\offline\9978D476\2CE1328F\policy.3.5.MediaManager.Core.xml Object is locked skipped
C:\ProgramData\{B0B64EEB-1DEA-4E4C-B465-C90BBF9E8EE5}\offline\A09F98A7\2CE1328F\policy.1.0.WindowsMediaFormat.dll Object is locked skipped
C:\ProgramData\{B0B64EEB-1DEA-4E4C-B465-C90BBF9E8EE5}\offline\A3021C3F\2AB9919B\Logger.xml Object is locked skipped
C:\ProgramData\{B0B64EEB-1DEA-4E4C-B465-C90BBF9E8EE5}\offline\A35C03FE\2CE1328F\policy.3.5.WindowsMediaFormat.xml Object is locked skipped
C:\ProgramData\{B0B64EEB-1DEA-4E4C-B465-C90BBF9E8EE5}\offline\A9A3E40A\2CE1328F\policy.3.0.MediaManager.Platforms.Viiv.Framework.xml Object is locked skipped
C:\ProgramData\{B0B64EEB-1DEA-4E4C-B465-C90BBF9E8EE5}\offline\AE8319A8\51091F58\MediaManager.Platforms.Viiv.dll Object is locked skipped
C:\ProgramData\{B0B64EEB-1DEA-4E4C-B465-C90BBF9E8EE5}\offline\AFF0C643\5AD6617F\Interop.IntelDH.dll Object is locked skipped
C:\ProgramData\{B0B64EEB-1DEA-4E4C-B465-C90BBF9E8EE5}\offline\B14F658A\2AB9919B\Release.txt Object is locked skipped
C:\ProgramData\{B0B64EEB-1DEA-4E4C-B465-C90BBF9E8EE5}\offline\BAFFDC79\6AF9272B\MediaManager.Core.dll Object is locked skipped
C:\ProgramData\{B0B64EEB-1DEA-4E4C-B465-C90BBF9E8EE5}\offline\C327E189\22CC3605\WindowsMediaFormat.dll Object is locked skipped
C:\ProgramData\{B0B64EEB-1DEA-4E4C-B465-C90BBF9E8EE5}\offline\C64E75E1\F2930322\Configuration.dll Object is locked skipped
C:\ProgramData\{B0B64EEB-1DEA-4E4C-B465-C90BBF9E8EE5}\offline\C898ABE2\D122F2F2\Interop.MSNETOBJLib.dll Object is locked skipped
C:\ProgramData\{B0B64EEB-1DEA-4E4C-B465-C90BBF9E8EE5}\offline\CD779512\2181DEFC\MediaManager.ActiveX.dll Object is locked skipped
C:\ProgramData\{B0B64EEB-1DEA-4E4C-B465-C90BBF9E8EE5}\offline\D57066F6\2CE1328F\policy.3.0.WindowsMediaFormat.dll Object is locked skipped
C:\ProgramData\{B0B64EEB-1DEA-4E4C-B465-C90BBF9E8EE5}\offline\D642EBE0\3E656A07\MediaManager.Platforms.Viiv.dll Object is locked skipped
C:\ProgramData\{B0B64EEB-1DEA-4E4C-B465-C90BBF9E8EE5}\offline\DD7AB08D\F2930322\MediaManager.exe Object is locked skipped
C:\ProgramData\{B0B64EEB-1DEA-4E4C-B465-C90BBF9E8EE5}\offline\E08EF901\5AD6617F\Interop.CMMS.dll Object is locked skipped
C:\ProgramData\{B0B64EEB-1DEA-4E4C-B465-C90BBF9E8EE5}\offline\E0ED4B67\7B3515C7\Interop.IntelDH.dll Object is locked skipped
C:\ProgramData\{B0B64EEB-1DEA-4E4C-B465-C90BBF9E8EE5}\offline\E14B4D3E\3057B55F\MediaManager.Platforms.Viiv.Framework.dll Object is locked skipped
C:\ProgramData\{B0B64EEB-1DEA-4E4C-B465-C90BBF9E8EE5}\offline\E471124F\2CE1328F\policy.3.0.MediaManager.Core.xml Object is locked skipped
C:\ProgramData\{B0B64EEB-1DEA-4E4C-B465-C90BBF9E8EE5}\offline\E6D8F098\2CE1328F\policy.1.0.MediaManager.Core.xml Object is locked skipped
C:\ProgramData\{B0B64EEB-1DEA-4E4C-B465-C90BBF9E8EE5}\offline\F7454224\2CE1328F\policy.3.0.MediaManager.Platforms.Viiv.Framework.dll Object is locked skipped
C:\ProgramData\{B0B64EEB-1DEA-4E4C-B465-C90BBF9E8EE5}\offline\FA485697\2AB9919B\Configuration.xml.encrypted Object is locked skipped
C:\Users\Admin\AppData\Local\Microsoft\Feeds Cache\index.dat Object is locked skipped
C:\Users\Admin\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat Object is locked skipped
C:\Users\Admin\AppData\Local\Microsoft\Windows\History\Low\History.IE5\index.dat Object is locked skipped
C:\Users\Admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat Object is locked skipped
C:\Users\Admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\index.dat Object is locked skipped
C:\Users\Admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\MSIMGSIZ.DAT Object is locked skipped
C:\Users\Admin\AppData\Local\Microsoft\Windows\UsrClass.dat Object is locked skipped
C:\Users\Admin\AppData\Local\Microsoft\Windows\UsrClass.dat.LOG1 Object is locked skipped
C:\Users\Admin\AppData\Local\Microsoft\Windows\UsrClass.dat.LOG2 Object is locked skipped
C:\Users\Admin\AppData\Local\Microsoft\Windows\UsrClass.dat{91d7b65d-0574-11dd-9a0a-001bfc387327}.TM.blf Object is locked skipped
C:\Users\Admin\AppData\Local\Microsoft\Windows\UsrClass.dat{91d7b65d-0574-11dd-9a0a-001bfc387327}.TMContainer00000000000000000001.regtrans-ms Object is locked skipped
C:\Users\Admin\AppData\Local\Microsoft\Windows\UsrClass.dat{91d7b65d-0574-11dd-9a0a-001bfc387327}.TMContainer00000000000000000002.regtrans-ms Object is locked skipped
C:\Users\Admin\AppData\Local\Microsoft\Windows Defender\FileTracker\{687B9D18-84EB-4EDE-AE15-CDAA4368B24B} Object is locked skipped
C:\Users\Admin\AppData\Local\Microsoft\Windows Sidebar\Settings.ini Object is locked skipped
C:\Users\Admin\AppData\Local\Temp\Low\~DFEC02.tmp Object is locked skipped
C:\Users\Admin\AppData\Local\Temp\Low\~DFEC5E.tmp Object is locked skipped
C:\Users\Admin\AppData\Local\Temp\~DFC03.tmp Object is locked skipped
C:\Users\Admin\AppData\Local\Temp\~DFC6F.tmp Object is locked skipped
C:\Users\Admin\AppData\Roaming\Microsoft\Windows\Cookies\index.dat Object is locked skipped
C:\Users\Admin\AppData\Roaming\Microsoft\Windows\Cookies\Low\index.dat Object is locked skipped
C:\Users\Admin\NTUSER.DAT Object is locked skipped
C:\Users\Admin\ntuser.dat.LOG1 Object is locked skipped
C:\Users\Admin\ntuser.dat.LOG2 Object is locked skipped
C:\Users\Admin\NTUSER.DAT{3a539871-6a70-11db-887c-d362bd253390}.TM.blf Object is locked skipped
C:\Users\Admin\NTUSER.DAT{3a539871-6a70-11db-887c-d362bd253390}.TMContainer00000000000000000001.regtrans-ms Object is locked skipped
C:\Users\Admin\NTUSER.DAT{3a539871-6a70-11db-887c-d362bd253390}.TMContainer00000000000000000002.regtrans-ms Object is locked skipped
C:\Users\Derek\AppData\Local\Temp\bgpgtdgh.dll Infected: Trojan.Win32.Monder.gen skipped
C:\Users\Derek\AppData\Local\Temp\bsqmojhr.dll Infected: Trojan.Win32.Monder.gen skipped
C:\Users\Derek\AppData\Local\Temp\fpbectyw.dll Infected: Trojan.Win32.Monder.gen skipped
C:\Users\Derek\AppData\Local\Temp\hddimqkn.dll Infected: Trojan.Win32.Monder.gen skipped
C:\Users\Derek\AppData\Local\Temp\jcovvnmw.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.szt skipped
C:\Users\Derek\AppData\Local\Temp\kbpfjmmi.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.szt skipped
C:\Users\Derek\AppData\Local\Temp\kgivljkk.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.szj skipped
C:\Users\Derek\AppData\Local\Temp\qwqcuvnj.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.szj skipped
C:\Users\Derek\AppData\Local\Temp\wmplog00.sqm Object is locked skipped
C:\Users\Derek\AppData\Local\Temp\wmplog01.sqm Object is locked skipped
C:\Users\Derek\AppData\Local\Temp\wmplog02.sqm Object is locked skipped
C:\Users\Derek\AppData\Local\Temp\wmplog03.sqm Object is locked skipped
C:\Users\Derek\Shared\Andrea Bocelli - A Night in Tuscany DivX by.avi Infected: Trojan-Downloader.WMA.GetCodec.b skipped
C:\Users\Public\Recorded TV\TempRec\TempSBE\MSDVRMM_471491471_1507328_93916 Object is locked skipped
C:\Users\Public\Recorded TV\TempRec\TempSBE\MSDVRMM_471491471_786432_93924 Object is locked skipped
C:\Users\Public\Recorded TV\TempRec\TempSBE\SBE1747.tmp Object is locked skipped
C:\Users\Public\Recorded TV\TempRec\TempSBE\SBE1851.tmp Object is locked skipped
C:\Users\Public\Recorded TV\TempRec\{7DB76741-C07B-4EC1-94CC-93592DCF07CE}.TmpSBE Object is locked skipped
C:\Users\Public\Recorded TV\TempRec\{9180B563-1061-4217-BEE3-DCF69D51EA43}.TmpSBE Object is locked skipped
C:\Windows\bthservsdp.dat Object is locked skipped
C:\Windows\Debug\PASSWD.LOG Object is locked skipped
C:\Windows\Debug\sam.log Object is locked skipped
C:\Windows\Debug\WIA\wiatrace.log Object is locked skipped
C:\Windows\Logs\CBS\CBS.log Object is locked skipped
C:\Windows\Logs\CBS\CBS.persist.log Object is locked skipped
C:\Windows\Logs\DPX\setupact.log Object is locked skipped
C:\Windows\Logs\DPX\setuperr.log Object is locked skipped
C:\Windows\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\SMSvcHost.exe.config Object is locked skipped
C:\Windows\Panther\UnattendGC\diagerr.xml Object is locked skipped
C:\Windows\Panther\UnattendGC\diagwrn.xml Object is locked skipped
C:\Windows\Panther\UnattendGC\setupact.log Object is locked skipped
C:\Windows\Panther\UnattendGC\setuperr.log Object is locked skipped
C:\Windows\security\database\secedit.sdb Object is locked skipped
C:\Windows\SoftwareDistribution\DataStore\DataStore.edb Object is locked skipped
C:\Windows\SoftwareDistribution\DataStore\Logs\edb.log Object is locked skipped
C:\Windows\SoftwareDistribution\DataStore\Logs\tmp.edb Object is locked skipped
C:\Windows\SoftwareDistribution\EventCache\{B39CEF9F-7771-4EE2-A3A4-D9F2EB4EA1C2}.bin Object is locked skipped
C:\Windows\SoftwareDistribution\ReportingEvents.log Object is locked skipped
C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-0.C7483456-A289-439d-8115-601632D005A0 Object is locked skipped
C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-1.C7483456-A289-439d-8115-601632D005A0 Object is locked skipped
C:\Windows\System32\catroot2\edb.log Object is locked skipped
C:\Windows\System32\catroot2\{127D0A1D-4EF2-11D1-8608-00C04FC295EE}\catdb Object is locked skipped
C:\Windows\System32\catroot2\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\catdb Object is locked skipped
C:\Windows\System32\config\COMPONENTS Object is locked skipped
C:\Windows\System32\config\COMPONENTS.LOG1 Object is locked skipped
C:\Windows\System32\config\COMPONENTS.LOG2 Object is locked skipped
C:\Windows\System32\config\DEFAULT Object is locked skipped
C:\Windows\System32\config\DEFAULT.LOG1 Object is locked skipped
C:\Windows\System32\config\DEFAULT.LOG2 Object is locked skipped
C:\Windows\System32\config\SAM Object is locked skipped
C:\Windows\System32\config\SAM.LOG1 Object is locked skipped
C:\Windows\System32\config\SAM.LOG2 Object is locked skipped
C:\Windows\System32\config\SECURITY Object is locked skipped
C:\Windows\System32\config\SECURITY.LOG1 Object is locked skipped
C:\Windows\System32\config\SECURITY.LOG2 Object is locked skipped
C:\Windows\System32\config\SOFTWARE Object is locked skipped
C:\Windows\System32\config\SOFTWARE.LOG1 Object is locked skipped
C:\Windows\System32\config\SOFTWARE.LOG2 Object is locked skipped
C:\Windows\System32\config\SYSTEM Object is locked skipped
C:\Windows\System32\config\SYSTEM.LOG1 Object is locked skipped
C:\Windows\System32\config\SYSTEM.LOG2 Object is locked skipped
C:\Windows\System32\config\TxR\{250834b7-750c-494d-bdc3-da86b6e2101a}.TxR.0.regtrans-ms Object is locked skipped
C:\Windows\System32\config\TxR\{250834b7-750c-494d-bdc3-da86b6e2101a}.TxR.1.regtrans-ms Object is locked skipped
C:\Windows\System32\config\TxR\{250834b7-750c-494d-bdc3-da86b6e2101a}.TxR.2.regtrans-ms Object is locked skipped
C:\Windows\System32\config\TxR\{250834B7-750C-494d-BDC3-DA86B6E2101A}.TxR.3.regtrans-ms Object is locked skipped
C:\Windows\System32\config\TxR\{250834B7-750C-494d-BDC3-DA86B6E2101A}.TxR.4.regtrans-ms Object is locked skipped
C:\Windows\System32\config\TxR\{250834b7-750c-494d-bdc3-da86b6e2101a}.TxR.blf Object is locked skipped
C:\Windows\System32\config\TxR\{250834B7-750C-494d-BDC3-DA86B6E2101B}.TM.blf Object is locked skipped
C:\Windows\System32\config\TxR\{250834B7-750C-494d-BDC3-DA86B6E2101B}.TMContainer00000000000000000001.regtrans-ms Object is locked skipped
C:\Windows\System32\config\TxR\{250834B7-750C-494d-BDC3-DA86B6E2101B}.TMContainer00000000000000000002.regtrans-ms Object is locked skipped
C:\Windows\System32\LogFiles\Scm\SCM.EVM Object is locked skipped
C:\Windows\System32\LogFiles\WUDF\WUDFTrace.etl Object is locked skipped
C:\Windows\System32\restore\MachineGuid.txt Object is locked skipped
C:\Windows\System32\spool\SpoolerETW.etl Object is locked skipped
C:\Windows\System32\sysprep\Panther\diagerr.xml Object is locked skipped
C:\Windows\System32\sysprep\Panther\diagwrn.xml Object is locked skipped
C:\Windows\System32\sysprep\Panther\setupact.log Object is locked skipped
C:\Windows\System32\sysprep\Panther\setuperr.log Object is locked skipped
C:\Windows\System32\wbem\AutoRecover\3460B7617E0429A960E481B197F238A3.mof Object is locked skipped
C:\Windows\System32\wbem\AutoRecover\E478A5DB75C9721E744C05D78DBACFD3.mof Object is locked skipped
C:\Windows\System32\wbem\Logs\WMITracing.log Object is locked skipped
C:\Windows\System32\wbem\Repository\INDEX.BTR Object is locked skipped
C:\Windows\System32\wbem\Repository\MAPPING1.MAP Object is locked skipped
C:\Windows\System32\wbem\Repository\MAPPING2.MAP Object is locked skipped
C:\Windows\System32\wbem\Repository\OBJECTS.DATA Object is locked skipped
C:\Windows\System32\winevt\Logs\Application.evtx Object is locked skipped
C:\Windows\System32\winevt\Logs\DFS Replication.evtx Object is locked skipped
C:\Windows\System32\winevt\Logs\HardwareEvents.evtx Object is locked skipped
C:\Windows\System32\winevt\Logs\Internet Explorer.evtx Object is locked skipped
C:\Windows\System32\winevt\Logs\Key Management Service.evtx Object is locked skipped
C:\Windows\System32\winevt\Logs\Media Center.evtx Object is locked skipped
C:\Windows\System32\winevt\Logs\MediaManagerServiceEventLog.evtx Object is locked skipped
C:\Windows\System32\winevt\Logs\Microsoft-Windows-Bits-Client%4Operational.evtx Object is locked skipped
C:\Windows\System32\winevt\Logs\Microsoft-Windows-CodeIntegrity%4Operational.evtx Object is locked skipped
C:\Windows\System32\winevt\Logs\Microsoft-Windows-Diagnosis-DPS%4Operational.evtx Object is locked skipped
C:\Windows\System32\winevt\Logs\Microsoft-Windows-Diagnostics-Networking%4Operational.evtx Object is locked skipped
C:\Windows\System32\winevt\Logs\Microsoft-Windows-Diagnostics-Performance%4Operational.evtx Object is locked skipped
C:\Windows\System32\winevt\Logs\Microsoft-Windows-DiskDiagnosticDataCollector%4Operational.evtx Object is locked skipped
C:\Windows\System32\winevt\Logs\Microsoft-Windows-DriverFrameworks-UserMode%4Operational.evtx Object is locked skipped
C:\Windows\System32\winevt\Logs\Microsoft-Windows-GroupPolicy%4Operational.evtx Object is locked skipped
C:\Windows\System32\winevt\Logs\Microsoft-Windows-Help%4Operational.evtx Object is locked skipped
C:\Windows\System32\winevt\Logs\Microsoft-Windows-International%4Operational.evtx Object is locked skipped
C:\Windows\System32\winevt\Logs\Microsoft-Windows-Kernel-WHEA.evtx Object is locked skipped
C:\Windows\System32\winevt\Logs\Microsoft-Windows-LanguagePackSetup%4Operational.evtx Object is locked skipped
C:\Windows\System32\winevt\Logs\Microsoft-Windows-MUI%4Operational.evtx Object is locked skipped
C:\Windows\System32\winevt\Logs\Microsoft-Windows-NetworkAccessProtection%4Operational.evtx Object is locked skipped
C:\Windows\System32\winevt\Logs\Microsoft-Windows-Program-Compatibility-Assistant%4Operational.evtx Object is locked skipped
C:\Windows\System32\winevt\Logs\Microsoft-Windows-ReadyBoost%4Operational.evtx Object is locked skipped
C:\Windows\System32\winevt\Logs\Microsoft-Windows-ReliabilityAnalysisComponent%4Operational.evtx Object is locked skipped
C:\Windows\System32\winevt\Logs\Microsoft-Windows-Resource-Exhaustion-Detector%4Operational.evtx Object is locked skipped
C:\Windows\System32\winevt\Logs\Microsoft-Windows-Resource-Exhaustion-Resolver%4Operational.evtx Object is locked skipped
C:\Windows\System32\winevt\Logs\Microsoft-Windows-Resource-Leak-Diagnostic%4Operational.evtx Object is locked skipped
C:\Windows\System32\winevt\Logs\Microsoft-Windows-RestartManager%4Operational.evtx Object is locked skipped
C:\Windows\System32\winevt\Logs\Microsoft-Windows-TaskScheduler%4Operational.evtx Object is locked skipped
C:\Windows\System32\winevt\Logs\Microsoft-Windows-UAC%4Operational.evtx Object is locked skipped
C:\Windows\System32\winevt\Logs\Microsoft-Windows-UAC-FileVirtualization%4Operational.evtx Object is locked skipped
C:\Windows\System32\winevt\Logs\Microsoft-Windows-WindowsUpdateClient%4Operational.evtx Object is locked skipped
C:\Windows\System32\winevt\Logs\Microsoft-Windows-WLAN-AutoConfig%4Operational.evtx Object is locked skipped
C:\Windows\System32\winevt\Logs\ODiag.evtx Object is locked skipped
C:\Windows\System32\winevt\Logs\OSession.evtx Object is locked skipped
C:\Windows\System32\winevt\Logs\Security.evtx Object is locked skipped
C:\Windows\System32\winevt\Logs\Setup.evtx Object is locked skipped
C:\Windows\System32\winevt\Logs\System.evtx Object is locked skipped
C:\Windows\Tasks\Norton Internet Security - Run Full System Scan - Derek.job Object is locked skipped
C:\Windows\Tasks\SCHEDLGU.TXT Object is locked skipped
C:\Windows\Temp\fwtsqmfile00.sqm Object is locked skipped
C:\Windows\WindowsUpdate.log Object is locked skipped
C:\Windows\winsxs\x86_microsoft-windows-n..n_service_datastore_31bf3856ad364e35_6.0.6000.16386_none_cef7ceb03914a67f\dnary.xsd Object is locked skipped
Scan process completed.
*************************************
Thank You
Derek
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 10:34:07 PM, on 5/06/2008
Platform: Windows Vista (WinNT 6.00.1904)
MSIE: Internet Explorer v7.00 (7.00.6000.16643)
Boot mode: Normal
Running processes:
C:\Windows\system32\taskeng.exe
C:\Windows\system32\taskeng.exe
C:\Program Files\ASUS\ASUS Live Update\ALU.exe
C:\Windows\system32\Dwm.exe
C:\Windows\Explorer.EXE
C:\Program Files\Windows Defender\MSASCui.exe
C:\Program Files\Motorola\SMSERIAL\sm56hlpr.exe
C:\Windows\RtHDVCpl.exe
C:\Windows\vsnp2std.exe
C:\Program Files\ASUS\ATK Media\DMedia.exe
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\Program Files\Common Files\Symantec Shared\ccApp.exe
C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe
C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\Windows Sidebar\sidebar.exe
C:\Program Files\Google\GoogleToolbarNotifier\1.2.1128.5462\GoogleToolbarNotifier.exe
C:\Program Files\ASUS\Asus MultiFrame\MultiFrame.exe
C:\Windows\System32\rundll32.exe
C:\Windows\system32\Taskmgr.exe
C:\Windows\system32\wuauclt.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.asus.com
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
O1 - Hosts: ::1 localhost
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {1E8A6170-7264-4D0F-BEAE-D42A53123C75} - C:\Program Files\Common Files\Symantec Shared\coShared\Browser\1.0\NppBho.dll
O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\Program Files\Microsoft Office\Office12\GrooveShellExtensions.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar2.dll
O3 - Toolbar: Show Norton Toolbar - {90222687-F593-4738-B738-FBEE9C7B26DF} - C:\Program Files\Common Files\Symantec Shared\coShared\Browser\1.0\UIBHO.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar2.dll
O4 - HKLM\..\Run: [Windows Defender] %ProgramFiles%\Windows Defender\MSASCui.exe -hide
O4 - HKLM\..\Run: [SMSERIAL] C:\Program Files\Motorola\SMSERIAL\sm56hlpr.exe
O4 - HKLM\..\Run: [RtHDVCpl] RtHDVCpl.exe
O4 - HKLM\..\Run: [snp2std] C:\Windows\vsnp2std.exe
O4 - HKLM\..\Run: [ATKMEDIA] C:\Program Files\ASUS\ATK Media\DMEDIA.EXE
O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [osCheck] "C:\Program Files\Norton Internet Security\osCheck.exe"
O4 - HKLM\..\Run: [NvSvc] RUNDLL32.EXE C:\Windows\system32\nvsvc.dll,nvsvcStart
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\Windows\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\Windows\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [NeroFilterCheck] C:\Program Files\Common Files\Ahead\Lib\NeroCheck.exe
O4 - HKLM\..\Run: [ALUAlert] C:\Program Files\Symantec\LiveUpdate\ALuNotify.exe
O4 - HKLM\..\Run: [GrooveMonitor] "C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe"
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe"
O4 - HKLM\..\Run: [Symantec PIF AlertEng] "C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc.exe" /a /m "C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\AlertEng.dll"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [MSConfig] "C:\Windows\system32\msconfig.exe" /auto
O4 - HKCU\..\Run: [Sidebar] C:\Program Files\Windows Sidebar\sidebar.exe /autoRun
O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\1.2.1128.5462\GoogleToolbarNotifier.exe
O4 - HKCU\..\Run: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCenter
O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-19\..\Run: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCenter (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'NETWORK SERVICE')
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O4 - Global Startup: MultiFrame.lnk = ?
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office12\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
O9 - Extra button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: S&end to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\Office12\REFIEBAR.DLL
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O13 - Gopher Prefix:
O16 - DPF: {0EB0E74A-2A76-4AB3-A7FB-9BD8C29F7F75} (CKAVWebScan Object) - http://www.kaspersky.com/kos/eng/partner/default/kavwebscan_unicode.cab
O16 - DPF: {44990301-3C9D-426D-81DF-AAB636FA4345} (Symantec Script Runner Class) - https://www-secure.symantec.com/techsupp/asa/ss/sa/sa_cabs/tgctlsr.cab
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab
O18 - Protocol: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - C:\Program Files\Microsoft Office\Office12\GrooveSystemServices.dll
O23 - Service: Apple Mobile Device - Apple, Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: ASLDR Service (ASLDRService) - Unknown owner - C:\Program Files\ATK Hotkey\ASLDRSrv.exe
O23 - Service: Automatic LiveUpdate Scheduler - Symantec Corporation - C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
O23 - Service: Symantec Lic NetConnect service (CLTNetCnService) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
O23 - Service: COM Host (comHost) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\VAScanner\comHost.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: Symantec IS Password Validation (ISPwdSvc) - Symantec Corporation - C:\Program Files\Norton Internet Security\isPwdSvc.exe
O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:\Program Files\Common Files\LightScribe\LSSrvc.exe
O23 - Service: LiveUpdate - Symantec Corporation - C:\PROGRA~1\Symantec\LIVEUP~1\LUCOMS~1.EXE
O23 - Service: LiveUpdate Notice Service Ex (LiveUpdate Notice Ex) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
O23 - Service: LiveUpdate Notice Service - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc.exe
O23 - Service: MediaManagerService - Unknown owner - C:\Program Files\Media Manager\Viiv\MediaManager.Service.exe
O23 - Service: NBService - Nero AG - C:\Program Files\Nero\Nero 7\Nero BackItUp\NBService.exe
O23 - Service: NMIndexingService - Nero AG - C:\Program Files\Common Files\Ahead\Lib\NMIndexingService.exe
O23 - Service: SBSD Security Center Service (SBSDWSCService) - Safer Networking Ltd. - C:\Program Files\Spybot - Search & Destroy\SDWinSec.exe
O23 - Service: spmgr - Unknown owner - C:\Program Files\ASUS\NB Probe\SPM\spmgr.exe
O23 - Service: Symantec Core LC - Unknown owner - C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
O23 - Service: Symantec AppCore Service (SymAppCore) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\AppCore\AppSvc32.exe
--
End of file - 9907 bytes
-------------------------------------------------------------------------------
KASPERSKY ONLINE SCANNER REPORT
Friday, May 30, 2008 7:13:19 AM
Operating System: Microsoft Windows Vista Home Edition, (Build 6000)
Kaspersky Online Scanner version: 5.0.98.0
Kaspersky Anti-Virus database last update: 29/05/2008
Kaspersky Anti-Virus database records: 812078
-------------------------------------------------------------------------------
Scan Settings:
Scan using the following antivirus database: extended
Scan Archives: true
Scan Mail Bases: true
Scan Target - My Computer:
C:\
D:\
E:\
Scan Statistics:
Total number of scanned objects: 89893
Number of viruses found: 4
Number of infected objects: 9
Number of suspicious objects: 0
Duration of the scan process: 00:41:15
Infected Object Name / Virus Name / Last Action
C:\Boot\BCD Object is locked skipped
C:\Boot\BCD.LOG Object is locked skipped
C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcrst.dll Object is locked skipped
C:\Program Files\Common Files\Symantec Shared\EENGINE\EPERSIST.DAT Object is locked skipped
C:\Program Files\Common Files\Symantec Shared\NFWEVT.LOG Object is locked skipped
C:\Program Files\InstallShield Installation Information\{139B0FFA-187E-4BA1-BCA6-6B56B2B6AB8C}\setup.ilg Object is locked skipped
C:\Program Files\InstallShield Installation Information\{2C164906-E68F-462A-9010-70DD022223EF}\Setup.ilg Object is locked skipped
C:\Program Files\InstallShield Installation Information\{6324A1EF-CEF4-43E3-8BCD-9EF3F67317FD}\setup.ilg Object is locked skipped
C:\Program Files\InstallShield Installation Information\{9518F764-C54D-47B2-9E73-154B21E79FD2}\Setup.ilg Object is locked skipped
C:\Program Files\InstallShield Installation Information\{9D48531D-2135-49FC-BC29-ACCDA5396A76}\setup.ilg Object is locked skipped
C:\Program Files\InstallShield Installation Information\{B9B9863A-32FD-4133-ADB7-46244ED77694}\Setup.ilg Object is locked skipped
C:\Program Files\InstallShield Installation Information\{DE10AB76-4756-4913-BE25-55D1C1051F9A}\setup.ilg Object is locked skipped
C:\Program Files\InstallShield Installation Information\{DE286975-ACF1-45B8-9EF7-34E162B2C817}\Setup.ilg Object is locked skipped
C:\Program Files\InstallShield Installation Information\{E657B243-9AD4-4ECC-BE81-4CCF8D667FD0}\setup.ilg Object is locked skipped
C:\Program Files\InstallShield Installation Information\{EF4C7EB0-D71B-43A3-9552-8053DE4B0401}\Setup.ilg Object is locked skipped
C:\Program Files\InstallShield Installation Information\{F37942A8-B21B-4C5A-A1D2-B676BF55EAE0}\Setup.ilg Object is locked skipped
C:\Program Files\Norton Internet Security\Norton AntiVirus\AVApp.log Object is locked skipped
C:\Program Files\Norton Internet Security\Norton AntiVirus\AVError.log Object is locked skipped
C:\Program Files\Norton Internet Security\Norton AntiVirus\AVVirus.log Object is locked skipped
C:\ProgramData\Symantec\Common Client\settings.bak Object is locked skipped
C:\ProgramData\Symantec\Common Client\settings.dat Object is locked skipped
C:\ProgramData\Symantec\LiveUpdate\2008-05-30_Log.ALUSchedulerSvc.LiveUpdate Object is locked skipped
C:\ProgramData\Symantec\SPBBC\BBConfig.log Object is locked skipped
C:\ProgramData\Symantec\SPBBC\BBDebug.log Object is locked skipped
C:\ProgramData\Symantec\SPBBC\BBDetect.log Object is locked skipped
C:\ProgramData\Symantec\SPBBC\BBNotify.log Object is locked skipped
C:\ProgramData\Symantec\SPBBC\BBRefr.log Object is locked skipped
C:\ProgramData\Symantec\SPBBC\BBSetCfg.log Object is locked skipped
C:\ProgramData\Symantec\SPBBC\BBSetCfg2.log Object is locked skipped
C:\ProgramData\Symantec\SPBBC\BBSetDev.log Object is locked skipped
C:\ProgramData\Symantec\SPBBC\BBSetLoc.log Object is locked skipped
C:\ProgramData\Symantec\SPBBC\BBSetUsr.log Object is locked skipped
C:\ProgramData\Symantec\SPBBC\BBStHash.log Object is locked skipped
C:\ProgramData\Symantec\SPBBC\BBValid.log Object is locked skipped
C:\ProgramData\Symantec\SPBBC\SPPolicy.log Object is locked skipped
C:\ProgramData\Symantec\SPBBC\SPStart.log Object is locked skipped
C:\ProgramData\Symantec\SPBBC\SPStop.log Object is locked skipped
C:\ProgramData\Symantec\SRTSP\SrtErEvt.log Object is locked skipped
C:\ProgramData\Symantec\SRTSP\SrtMoEvt.log Object is locked skipped
C:\ProgramData\Symantec\SRTSP\SrtNvEvt.log Object is locked skipped
C:\ProgramData\Symantec\SRTSP\SrtScEvt.log Object is locked skipped
C:\ProgramData\Symantec\SRTSP\SrtTxFEvt.log Object is locked skipped
C:\ProgramData\Symantec\SRTSP\SrtViEvt.log Object is locked skipped
C:\ProgramData\Symantec\SubEng\submissions.idx Object is locked skipped
C:\ProgramData\Symantec\SymNetDrv\SNDALRT.log Object is locked skipped
C:\ProgramData\Symantec\SymNetDrv\SNDCON.log Object is locked skipped
C:\ProgramData\Symantec\SymNetDrv\SNDDBG.log Object is locked skipped
C:\ProgramData\Symantec\SymNetDrv\SNDFW.log Object is locked skipped
C:\ProgramData\Symantec\SymNetDrv\SNDIDS.log Object is locked skipped
C:\ProgramData\Symantec\SymNetDrv\SNDSYS.log Object is locked skipped
C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\cbfb3a0a20b8daad5ddfe850309a2758_789de25b-be5d-46b0-b6ee-77ef0e0a8162 Object is locked skipped
C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\fc1e3851f429ea606d6ff1e01a5229f1_789de25b-be5d-46b0-b6ee-77ef0e0a8162 Object is locked skipped
C:\ProgramData\Microsoft\eHome\logs\eHomeLog00.sqm Object is locked skipped
C:\ProgramData\Microsoft\eHome\logs\eHomeLog01.sqm Object is locked skipped
C:\ProgramData\Microsoft\eHome\logs\eHomeLog02.sqm Object is locked skipped
C:\ProgramData\Microsoft\eHome\logs\eHomeLog03.sqm Object is locked skipped
C:\ProgramData\Microsoft\eHome\logs\eHomeLog04.sqm Object is locked skipped
C:\ProgramData\Microsoft\eHome\logs\eHomeLog05.sqm Object is locked skipped
C:\ProgramData\Microsoft\eHome\logs\eHomeLog06.sqm Object is locked skipped
C:\ProgramData\Microsoft\eHome\logs\eHomeLog07.sqm Object is locked skipped
C:\ProgramData\Microsoft\User Account Pictures\Derek.dat Object is locked skipped
C:\ProgramData\Microsoft\User Account Pictures\Russell.dat Object is locked skipped
C:\ProgramData\Microsoft\Windows\DRM\Cache\Indiv01.tmp Object is locked skipped
C:\ProgramData\Microsoft\Windows\DRM\drmstore.hds Object is locked skipped
C:\ProgramData\{B0B64EEB-1DEA-4E4C-B465-C90BBF9E8EE5}\offline\1280377A\2AB9919B\App.ico Object is locked skipped
C:\ProgramData\{B0B64EEB-1DEA-4E4C-B465-C90BBF9E8EE5}\offline\16E96B81\D122F2F2\Microsoft.mshtml.dll Object is locked skipped
C:\ProgramData\{B0B64EEB-1DEA-4E4C-B465-C90BBF9E8EE5}\offline\1C1F87FE\D122F2F2\log4net.dll Object is locked skipped
C:\ProgramData\{B0B64EEB-1DEA-4E4C-B465-C90BBF9E8EE5}\offline\1F6FC04D\2CE1328F\policy.1.0.MediaManager.Platforms.Viiv.Framework.dll Object is locked skipped
C:\ProgramData\{B0B64EEB-1DEA-4E4C-B465-C90BBF9E8EE5}\offline\238AD7FB\2CE1328F\policy.1.0.WindowsMediaFormat.xml Object is locked skipped
C:\ProgramData\{B0B64EEB-1DEA-4E4C-B465-C90BBF9E8EE5}\offline\2503188D\2CE1328F\policy.1.0.MediaManager.Core.dll Object is locked skipped
C:\ProgramData\{B0B64EEB-1DEA-4E4C-B465-C90BBF9E8EE5}\offline\29E5B010\2CE1328F\policy.1.0.MediaManager.Platforms.Viiv.Framework.xml Object is locked skipped
C:\ProgramData\{B0B64EEB-1DEA-4E4C-B465-C90BBF9E8EE5}\offline\2BD84DFE\2CE1328F\policy.3.5.MediaManager.Core.dll Object is locked skipped
C:\ProgramData\{B0B64EEB-1DEA-4E4C-B465-C90BBF9E8EE5}\offline\2E832D7F\D122F2F2\SHDocVw.dll Object is locked skipped
C:\ProgramData\{B0B64EEB-1DEA-4E4C-B465-C90BBF9E8EE5}\offline\2EFD349B\2AB9919B\License.rtf Object is locked skipped
C:\ProgramData\{B0B64EEB-1DEA-4E4C-B465-C90BBF9E8EE5}\offline\3B7E8D3A\2AB9919B\Popup.wav Object is locked skipped
C:\ProgramData\{B0B64EEB-1DEA-4E4C-B465-C90BBF9E8EE5}\offline\45646D5A\DCCD58AC\MediaManager.Service.exe Object is locked skipped
C:\ProgramData\{B0B64EEB-1DEA-4E4C-B465-C90BBF9E8EE5}\offline\4AFF6640\7B3515C7\Interop.CMMS.dll Object is locked skipped
C:\ProgramData\{B0B64EEB-1DEA-4E4C-B465-C90BBF9E8EE5}\offline\4CEBBB84\D122F2F2\AxInterop.WMPLib.dll Object is locked skipped
C:\ProgramData\{B0B64EEB-1DEA-4E4C-B465-C90BBF9E8EE5}\offline\5F332148\F2930322\WMP_Upgrade.wma Object is locked skipped
C:\ProgramData\{B0B64EEB-1DEA-4E4C-B465-C90BBF9E8EE5}\offline\5F8C991B\3C66D2F6\MediaManager.resources Object is locked skipped
C:\ProgramData\{B0B64EEB-1DEA-4E4C-B465-C90BBF9E8EE5}\offline\64E5A4E4\2CE1328F\policy.3.5.MediaManager.Platforms.Viiv.Framework.xml Object is locked skipped
C:\ProgramData\{B0B64EEB-1DEA-4E4C-B465-C90BBF9E8EE5}\offline\7132B421\D122F2F2\wmppia.dll Object is locked skipped
C:\ProgramData\{B0B64EEB-1DEA-4E4C-B465-C90BBF9E8EE5}\offline\73031766\2CE1328F\policy.3.5.WindowsMediaFormat.dll Object is locked skipped
C:\ProgramData\{B0B64EEB-1DEA-4E4C-B465-C90BBF9E8EE5}\offline\764EC703\F2930322\AxSHDocVw.dll Object is locked skipped
C:\ProgramData\{B0B64EEB-1DEA-4E4C-B465-C90BBF9E8EE5}\offline\7849FE98\C85D87C4\MediaManager.ActiveX.Sniffer.dll Object is locked skipped
C:\ProgramData\{B0B64EEB-1DEA-4E4C-B465-C90BBF9E8EE5}\offline\786E6DAD\2CE1328F\policy.3.0.WindowsMediaFormat.xml Object is locked skipped
C:\ProgramData\{B0B64EEB-1DEA-4E4C-B465-C90BBF9E8EE5}\offline\84CA1B5F\2AB9919B\readme.rtf Object is locked skipped
C:\ProgramData\{B0B64EEB-1DEA-4E4C-B465-C90BBF9E8EE5}\offline\853EC73C\F2930322\MediaManager.exe.config Object is locked skipped
C:\ProgramData\{B0B64EEB-1DEA-4E4C-B465-C90BBF9E8EE5}\offline\85D3DD96\2AB9919B\Help.chm Object is locked skipped
C:\ProgramData\{B0B64EEB-1DEA-4E4C-B465-C90BBF9E8EE5}\offline\88CF50D0\D122F2F2\Interop.WMPLib.dll Object is locked skipped
C:\ProgramData\{B0B64EEB-1DEA-4E4C-B465-C90BBF9E8EE5}\offline\8A099DC5\2CE1328F\policy.3.5.MediaManager.Platforms.Viiv.Framework.dll Object is locked skipped
C:\ProgramData\{B0B64EEB-1DEA-4E4C-B465-C90BBF9E8EE5}\offline\8B3B523\F2930322\UserInterface.dll Object is locked skipped
C:\ProgramData\{B0B64EEB-1DEA-4E4C-B465-C90BBF9E8EE5}\offline\921F110F\D4A1F967\Deregister.exe Object is locked skipped
C:\ProgramData\{B0B64EEB-1DEA-4E4C-B465-C90BBF9E8EE5}\offline\926B4195\2CE1328F\policy.3.0.MediaManager.Core.dll Object is locked skipped
C:\ProgramData\{B0B64EEB-1DEA-4E4C-B465-C90BBF9E8EE5}\offline\9978D476\2CE1328F\policy.3.5.MediaManager.Core.xml Object is locked skipped
C:\ProgramData\{B0B64EEB-1DEA-4E4C-B465-C90BBF9E8EE5}\offline\A09F98A7\2CE1328F\policy.1.0.WindowsMediaFormat.dll Object is locked skipped
C:\ProgramData\{B0B64EEB-1DEA-4E4C-B465-C90BBF9E8EE5}\offline\A3021C3F\2AB9919B\Logger.xml Object is locked skipped
C:\ProgramData\{B0B64EEB-1DEA-4E4C-B465-C90BBF9E8EE5}\offline\A35C03FE\2CE1328F\policy.3.5.WindowsMediaFormat.xml Object is locked skipped
C:\ProgramData\{B0B64EEB-1DEA-4E4C-B465-C90BBF9E8EE5}\offline\A9A3E40A\2CE1328F\policy.3.0.MediaManager.Platforms.Viiv.Framework.xml Object is locked skipped
C:\ProgramData\{B0B64EEB-1DEA-4E4C-B465-C90BBF9E8EE5}\offline\AE8319A8\51091F58\MediaManager.Platforms.Viiv.dll Object is locked skipped
C:\ProgramData\{B0B64EEB-1DEA-4E4C-B465-C90BBF9E8EE5}\offline\AFF0C643\5AD6617F\Interop.IntelDH.dll Object is locked skipped
C:\ProgramData\{B0B64EEB-1DEA-4E4C-B465-C90BBF9E8EE5}\offline\B14F658A\2AB9919B\Release.txt Object is locked skipped
C:\ProgramData\{B0B64EEB-1DEA-4E4C-B465-C90BBF9E8EE5}\offline\BAFFDC79\6AF9272B\MediaManager.Core.dll Object is locked skipped
C:\ProgramData\{B0B64EEB-1DEA-4E4C-B465-C90BBF9E8EE5}\offline\C327E189\22CC3605\WindowsMediaFormat.dll Object is locked skipped
C:\ProgramData\{B0B64EEB-1DEA-4E4C-B465-C90BBF9E8EE5}\offline\C64E75E1\F2930322\Configuration.dll Object is locked skipped
C:\ProgramData\{B0B64EEB-1DEA-4E4C-B465-C90BBF9E8EE5}\offline\C898ABE2\D122F2F2\Interop.MSNETOBJLib.dll Object is locked skipped
C:\ProgramData\{B0B64EEB-1DEA-4E4C-B465-C90BBF9E8EE5}\offline\CD779512\2181DEFC\MediaManager.ActiveX.dll Object is locked skipped
C:\ProgramData\{B0B64EEB-1DEA-4E4C-B465-C90BBF9E8EE5}\offline\D57066F6\2CE1328F\policy.3.0.WindowsMediaFormat.dll Object is locked skipped
C:\ProgramData\{B0B64EEB-1DEA-4E4C-B465-C90BBF9E8EE5}\offline\D642EBE0\3E656A07\MediaManager.Platforms.Viiv.dll Object is locked skipped
C:\ProgramData\{B0B64EEB-1DEA-4E4C-B465-C90BBF9E8EE5}\offline\DD7AB08D\F2930322\MediaManager.exe Object is locked skipped
C:\ProgramData\{B0B64EEB-1DEA-4E4C-B465-C90BBF9E8EE5}\offline\E08EF901\5AD6617F\Interop.CMMS.dll Object is locked skipped
C:\ProgramData\{B0B64EEB-1DEA-4E4C-B465-C90BBF9E8EE5}\offline\E0ED4B67\7B3515C7\Interop.IntelDH.dll Object is locked skipped
C:\ProgramData\{B0B64EEB-1DEA-4E4C-B465-C90BBF9E8EE5}\offline\E14B4D3E\3057B55F\MediaManager.Platforms.Viiv.Framework.dll Object is locked skipped
C:\ProgramData\{B0B64EEB-1DEA-4E4C-B465-C90BBF9E8EE5}\offline\E471124F\2CE1328F\policy.3.0.MediaManager.Core.xml Object is locked skipped
C:\ProgramData\{B0B64EEB-1DEA-4E4C-B465-C90BBF9E8EE5}\offline\E6D8F098\2CE1328F\policy.1.0.MediaManager.Core.xml Object is locked skipped
C:\ProgramData\{B0B64EEB-1DEA-4E4C-B465-C90BBF9E8EE5}\offline\F7454224\2CE1328F\policy.3.0.MediaManager.Platforms.Viiv.Framework.dll Object is locked skipped
C:\ProgramData\{B0B64EEB-1DEA-4E4C-B465-C90BBF9E8EE5}\offline\FA485697\2AB9919B\Configuration.xml.encrypted Object is locked skipped
C:\Users\Admin\AppData\Local\Microsoft\Feeds Cache\index.dat Object is locked skipped
C:\Users\Admin\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat Object is locked skipped
C:\Users\Admin\AppData\Local\Microsoft\Windows\History\Low\History.IE5\index.dat Object is locked skipped
C:\Users\Admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat Object is locked skipped
C:\Users\Admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\index.dat Object is locked skipped
C:\Users\Admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\MSIMGSIZ.DAT Object is locked skipped
C:\Users\Admin\AppData\Local\Microsoft\Windows\UsrClass.dat Object is locked skipped
C:\Users\Admin\AppData\Local\Microsoft\Windows\UsrClass.dat.LOG1 Object is locked skipped
C:\Users\Admin\AppData\Local\Microsoft\Windows\UsrClass.dat.LOG2 Object is locked skipped
C:\Users\Admin\AppData\Local\Microsoft\Windows\UsrClass.dat{91d7b65d-0574-11dd-9a0a-001bfc387327}.TM.blf Object is locked skipped
C:\Users\Admin\AppData\Local\Microsoft\Windows\UsrClass.dat{91d7b65d-0574-11dd-9a0a-001bfc387327}.TMContainer00000000000000000001.regtrans-ms Object is locked skipped
C:\Users\Admin\AppData\Local\Microsoft\Windows\UsrClass.dat{91d7b65d-0574-11dd-9a0a-001bfc387327}.TMContainer00000000000000000002.regtrans-ms Object is locked skipped
C:\Users\Admin\AppData\Local\Microsoft\Windows Defender\FileTracker\{687B9D18-84EB-4EDE-AE15-CDAA4368B24B} Object is locked skipped
C:\Users\Admin\AppData\Local\Microsoft\Windows Sidebar\Settings.ini Object is locked skipped
C:\Users\Admin\AppData\Local\Temp\Low\~DFEC02.tmp Object is locked skipped
C:\Users\Admin\AppData\Local\Temp\Low\~DFEC5E.tmp Object is locked skipped
C:\Users\Admin\AppData\Local\Temp\~DFC03.tmp Object is locked skipped
C:\Users\Admin\AppData\Local\Temp\~DFC6F.tmp Object is locked skipped
C:\Users\Admin\AppData\Roaming\Microsoft\Windows\Cookies\index.dat Object is locked skipped
C:\Users\Admin\AppData\Roaming\Microsoft\Windows\Cookies\Low\index.dat Object is locked skipped
C:\Users\Admin\NTUSER.DAT Object is locked skipped
C:\Users\Admin\ntuser.dat.LOG1 Object is locked skipped
C:\Users\Admin\ntuser.dat.LOG2 Object is locked skipped
C:\Users\Admin\NTUSER.DAT{3a539871-6a70-11db-887c-d362bd253390}.TM.blf Object is locked skipped
C:\Users\Admin\NTUSER.DAT{3a539871-6a70-11db-887c-d362bd253390}.TMContainer00000000000000000001.regtrans-ms Object is locked skipped
C:\Users\Admin\NTUSER.DAT{3a539871-6a70-11db-887c-d362bd253390}.TMContainer00000000000000000002.regtrans-ms Object is locked skipped
C:\Users\Derek\AppData\Local\Temp\bgpgtdgh.dll Infected: Trojan.Win32.Monder.gen skipped
C:\Users\Derek\AppData\Local\Temp\bsqmojhr.dll Infected: Trojan.Win32.Monder.gen skipped
C:\Users\Derek\AppData\Local\Temp\fpbectyw.dll Infected: Trojan.Win32.Monder.gen skipped
C:\Users\Derek\AppData\Local\Temp\hddimqkn.dll Infected: Trojan.Win32.Monder.gen skipped
C:\Users\Derek\AppData\Local\Temp\jcovvnmw.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.szt skipped
C:\Users\Derek\AppData\Local\Temp\kbpfjmmi.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.szt skipped
C:\Users\Derek\AppData\Local\Temp\kgivljkk.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.szj skipped
C:\Users\Derek\AppData\Local\Temp\qwqcuvnj.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.szj skipped
C:\Users\Derek\AppData\Local\Temp\wmplog00.sqm Object is locked skipped
C:\Users\Derek\AppData\Local\Temp\wmplog01.sqm Object is locked skipped
C:\Users\Derek\AppData\Local\Temp\wmplog02.sqm Object is locked skipped
C:\Users\Derek\AppData\Local\Temp\wmplog03.sqm Object is locked skipped
C:\Users\Derek\Shared\Andrea Bocelli - A Night in Tuscany DivX by.avi Infected: Trojan-Downloader.WMA.GetCodec.b skipped
C:\Users\Public\Recorded TV\TempRec\TempSBE\MSDVRMM_471491471_1507328_93916 Object is locked skipped
C:\Users\Public\Recorded TV\TempRec\TempSBE\MSDVRMM_471491471_786432_93924 Object is locked skipped
C:\Users\Public\Recorded TV\TempRec\TempSBE\SBE1747.tmp Object is locked skipped
C:\Users\Public\Recorded TV\TempRec\TempSBE\SBE1851.tmp Object is locked skipped
C:\Users\Public\Recorded TV\TempRec\{7DB76741-C07B-4EC1-94CC-93592DCF07CE}.TmpSBE Object is locked skipped
C:\Users\Public\Recorded TV\TempRec\{9180B563-1061-4217-BEE3-DCF69D51EA43}.TmpSBE Object is locked skipped
C:\Windows\bthservsdp.dat Object is locked skipped
C:\Windows\Debug\PASSWD.LOG Object is locked skipped
C:\Windows\Debug\sam.log Object is locked skipped
C:\Windows\Debug\WIA\wiatrace.log Object is locked skipped
C:\Windows\Logs\CBS\CBS.log Object is locked skipped
C:\Windows\Logs\CBS\CBS.persist.log Object is locked skipped
C:\Windows\Logs\DPX\setupact.log Object is locked skipped
C:\Windows\Logs\DPX\setuperr.log Object is locked skipped
C:\Windows\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\SMSvcHost.exe.config Object is locked skipped
C:\Windows\Panther\UnattendGC\diagerr.xml Object is locked skipped
C:\Windows\Panther\UnattendGC\diagwrn.xml Object is locked skipped
C:\Windows\Panther\UnattendGC\setupact.log Object is locked skipped
C:\Windows\Panther\UnattendGC\setuperr.log Object is locked skipped
C:\Windows\security\database\secedit.sdb Object is locked skipped
C:\Windows\SoftwareDistribution\DataStore\DataStore.edb Object is locked skipped
C:\Windows\SoftwareDistribution\DataStore\Logs\edb.log Object is locked skipped
C:\Windows\SoftwareDistribution\DataStore\Logs\tmp.edb Object is locked skipped
C:\Windows\SoftwareDistribution\EventCache\{B39CEF9F-7771-4EE2-A3A4-D9F2EB4EA1C2}.bin Object is locked skipped
C:\Windows\SoftwareDistribution\ReportingEvents.log Object is locked skipped
C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-0.C7483456-A289-439d-8115-601632D005A0 Object is locked skipped
C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-1.C7483456-A289-439d-8115-601632D005A0 Object is locked skipped
C:\Windows\System32\catroot2\edb.log Object is locked skipped
C:\Windows\System32\catroot2\{127D0A1D-4EF2-11D1-8608-00C04FC295EE}\catdb Object is locked skipped
C:\Windows\System32\catroot2\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\catdb Object is locked skipped
C:\Windows\System32\config\COMPONENTS Object is locked skipped
C:\Windows\System32\config\COMPONENTS.LOG1 Object is locked skipped
C:\Windows\System32\config\COMPONENTS.LOG2 Object is locked skipped
C:\Windows\System32\config\DEFAULT Object is locked skipped
C:\Windows\System32\config\DEFAULT.LOG1 Object is locked skipped
C:\Windows\System32\config\DEFAULT.LOG2 Object is locked skipped
C:\Windows\System32\config\SAM Object is locked skipped
C:\Windows\System32\config\SAM.LOG1 Object is locked skipped
C:\Windows\System32\config\SAM.LOG2 Object is locked skipped
C:\Windows\System32\config\SECURITY Object is locked skipped
C:\Windows\System32\config\SECURITY.LOG1 Object is locked skipped
C:\Windows\System32\config\SECURITY.LOG2 Object is locked skipped
C:\Windows\System32\config\SOFTWARE Object is locked skipped
C:\Windows\System32\config\SOFTWARE.LOG1 Object is locked skipped
C:\Windows\System32\config\SOFTWARE.LOG2 Object is locked skipped
C:\Windows\System32\config\SYSTEM Object is locked skipped
C:\Windows\System32\config\SYSTEM.LOG1 Object is locked skipped
C:\Windows\System32\config\SYSTEM.LOG2 Object is locked skipped
C:\Windows\System32\config\TxR\{250834b7-750c-494d-bdc3-da86b6e2101a}.TxR.0.regtrans-ms Object is locked skipped
C:\Windows\System32\config\TxR\{250834b7-750c-494d-bdc3-da86b6e2101a}.TxR.1.regtrans-ms Object is locked skipped
C:\Windows\System32\config\TxR\{250834b7-750c-494d-bdc3-da86b6e2101a}.TxR.2.regtrans-ms Object is locked skipped
C:\Windows\System32\config\TxR\{250834B7-750C-494d-BDC3-DA86B6E2101A}.TxR.3.regtrans-ms Object is locked skipped
C:\Windows\System32\config\TxR\{250834B7-750C-494d-BDC3-DA86B6E2101A}.TxR.4.regtrans-ms Object is locked skipped
C:\Windows\System32\config\TxR\{250834b7-750c-494d-bdc3-da86b6e2101a}.TxR.blf Object is locked skipped
C:\Windows\System32\config\TxR\{250834B7-750C-494d-BDC3-DA86B6E2101B}.TM.blf Object is locked skipped
C:\Windows\System32\config\TxR\{250834B7-750C-494d-BDC3-DA86B6E2101B}.TMContainer00000000000000000001.regtrans-ms Object is locked skipped
C:\Windows\System32\config\TxR\{250834B7-750C-494d-BDC3-DA86B6E2101B}.TMContainer00000000000000000002.regtrans-ms Object is locked skipped
C:\Windows\System32\LogFiles\Scm\SCM.EVM Object is locked skipped
C:\Windows\System32\LogFiles\WUDF\WUDFTrace.etl Object is locked skipped
C:\Windows\System32\restore\MachineGuid.txt Object is locked skipped
C:\Windows\System32\spool\SpoolerETW.etl Object is locked skipped
C:\Windows\System32\sysprep\Panther\diagerr.xml Object is locked skipped
C:\Windows\System32\sysprep\Panther\diagwrn.xml Object is locked skipped
C:\Windows\System32\sysprep\Panther\setupact.log Object is locked skipped
C:\Windows\System32\sysprep\Panther\setuperr.log Object is locked skipped
C:\Windows\System32\wbem\AutoRecover\3460B7617E0429A960E481B197F238A3.mof Object is locked skipped
C:\Windows\System32\wbem\AutoRecover\E478A5DB75C9721E744C05D78DBACFD3.mof Object is locked skipped
C:\Windows\System32\wbem\Logs\WMITracing.log Object is locked skipped
C:\Windows\System32\wbem\Repository\INDEX.BTR Object is locked skipped
C:\Windows\System32\wbem\Repository\MAPPING1.MAP Object is locked skipped
C:\Windows\System32\wbem\Repository\MAPPING2.MAP Object is locked skipped
C:\Windows\System32\wbem\Repository\OBJECTS.DATA Object is locked skipped
C:\Windows\System32\winevt\Logs\Application.evtx Object is locked skipped
C:\Windows\System32\winevt\Logs\DFS Replication.evtx Object is locked skipped
C:\Windows\System32\winevt\Logs\HardwareEvents.evtx Object is locked skipped
C:\Windows\System32\winevt\Logs\Internet Explorer.evtx Object is locked skipped
C:\Windows\System32\winevt\Logs\Key Management Service.evtx Object is locked skipped
C:\Windows\System32\winevt\Logs\Media Center.evtx Object is locked skipped
C:\Windows\System32\winevt\Logs\MediaManagerServiceEventLog.evtx Object is locked skipped
C:\Windows\System32\winevt\Logs\Microsoft-Windows-Bits-Client%4Operational.evtx Object is locked skipped
C:\Windows\System32\winevt\Logs\Microsoft-Windows-CodeIntegrity%4Operational.evtx Object is locked skipped
C:\Windows\System32\winevt\Logs\Microsoft-Windows-Diagnosis-DPS%4Operational.evtx Object is locked skipped
C:\Windows\System32\winevt\Logs\Microsoft-Windows-Diagnostics-Networking%4Operational.evtx Object is locked skipped
C:\Windows\System32\winevt\Logs\Microsoft-Windows-Diagnostics-Performance%4Operational.evtx Object is locked skipped
C:\Windows\System32\winevt\Logs\Microsoft-Windows-DiskDiagnosticDataCollector%4Operational.evtx Object is locked skipped
C:\Windows\System32\winevt\Logs\Microsoft-Windows-DriverFrameworks-UserMode%4Operational.evtx Object is locked skipped
C:\Windows\System32\winevt\Logs\Microsoft-Windows-GroupPolicy%4Operational.evtx Object is locked skipped
C:\Windows\System32\winevt\Logs\Microsoft-Windows-Help%4Operational.evtx Object is locked skipped
C:\Windows\System32\winevt\Logs\Microsoft-Windows-International%4Operational.evtx Object is locked skipped
C:\Windows\System32\winevt\Logs\Microsoft-Windows-Kernel-WHEA.evtx Object is locked skipped
C:\Windows\System32\winevt\Logs\Microsoft-Windows-LanguagePackSetup%4Operational.evtx Object is locked skipped
C:\Windows\System32\winevt\Logs\Microsoft-Windows-MUI%4Operational.evtx Object is locked skipped
C:\Windows\System32\winevt\Logs\Microsoft-Windows-NetworkAccessProtection%4Operational.evtx Object is locked skipped
C:\Windows\System32\winevt\Logs\Microsoft-Windows-Program-Compatibility-Assistant%4Operational.evtx Object is locked skipped
C:\Windows\System32\winevt\Logs\Microsoft-Windows-ReadyBoost%4Operational.evtx Object is locked skipped
C:\Windows\System32\winevt\Logs\Microsoft-Windows-ReliabilityAnalysisComponent%4Operational.evtx Object is locked skipped
C:\Windows\System32\winevt\Logs\Microsoft-Windows-Resource-Exhaustion-Detector%4Operational.evtx Object is locked skipped
C:\Windows\System32\winevt\Logs\Microsoft-Windows-Resource-Exhaustion-Resolver%4Operational.evtx Object is locked skipped
C:\Windows\System32\winevt\Logs\Microsoft-Windows-Resource-Leak-Diagnostic%4Operational.evtx Object is locked skipped
C:\Windows\System32\winevt\Logs\Microsoft-Windows-RestartManager%4Operational.evtx Object is locked skipped
C:\Windows\System32\winevt\Logs\Microsoft-Windows-TaskScheduler%4Operational.evtx Object is locked skipped
C:\Windows\System32\winevt\Logs\Microsoft-Windows-UAC%4Operational.evtx Object is locked skipped
C:\Windows\System32\winevt\Logs\Microsoft-Windows-UAC-FileVirtualization%4Operational.evtx Object is locked skipped
C:\Windows\System32\winevt\Logs\Microsoft-Windows-WindowsUpdateClient%4Operational.evtx Object is locked skipped
C:\Windows\System32\winevt\Logs\Microsoft-Windows-WLAN-AutoConfig%4Operational.evtx Object is locked skipped
C:\Windows\System32\winevt\Logs\ODiag.evtx Object is locked skipped
C:\Windows\System32\winevt\Logs\OSession.evtx Object is locked skipped
C:\Windows\System32\winevt\Logs\Security.evtx Object is locked skipped
C:\Windows\System32\winevt\Logs\Setup.evtx Object is locked skipped
C:\Windows\System32\winevt\Logs\System.evtx Object is locked skipped
C:\Windows\Tasks\Norton Internet Security - Run Full System Scan - Derek.job Object is locked skipped
C:\Windows\Tasks\SCHEDLGU.TXT Object is locked skipped
C:\Windows\Temp\fwtsqmfile00.sqm Object is locked skipped
C:\Windows\WindowsUpdate.log Object is locked skipped
C:\Windows\winsxs\x86_microsoft-windows-n..n_service_datastore_31bf3856ad364e35_6.0.6000.16386_none_cef7ceb03914a67f\dnary.xsd Object is locked skipped
Scan process completed.
*************************************
Thank You
Derek