PDA

View Full Version : No Symptoms Yet, but Worm.VBS.KakWorm and Others Found in Kaspersky Scan



MJWolter
2008-06-13, 18:55
Because of the Trojans found in .pst files of my Dell 640M in the course of my earlier thread (http://forums.spybot.info/showthread.php?t=28610), I ran the Kaspersky scan on the C and F drives of my primary computer. The logs are reproduced below [(a) & (b)], along with the obligatory HijackThis (HJT) log [(c)]. I am hoping these infections can be cured without deleting entire .pst files; any chance of that?

a) Kaspersky Report, C drive:

--------------------------------------------------------------------------------
KASPERSKY ONLINE SCANNER 7 REPORT
Thursday, June 12, 2008
Operating System: Microsoft Windows Vista Home Premium Edition, 32-bit (build 6000)
Kaspersky Online Scanner 7 version: 7.0.25.0
Program database last update: Thursday, June 12, 2008 14:57:30
Records in database: 856010
--------------------------------------------------------------------------------

Scan settings:
Scan using the following database: extended
Scan archives: yes
Scan mail databases: yes

Scan area - Folder:
C:\

Scan statistics:
Files scanned: 112155
Threat name: 2
Infected objects: 4
Suspicious objects: 1
Duration of the scan: 01:50:53


File name / Threat name / Threats count
C:\Users\Michael J. Wolter\Documents\To be Copied to Desktop\Outlook\From Inspiron 640M\Archived Calendars, Journals, and Tasks, MJW @ M-20 (Current).pst Suspicious: Trojan-Spy.HTML.Fraud.gen 1
C:\Users\Michael J. Wolter\Documents\To be Copied to Desktop\Outlook\Personal Folders - X-Current Files (Aug 89-Jul 01), 010702.pst Infected: Email-Worm.VBS.KakWorm 4

The selected area was scanned.

b) Kaspersky Report, F drive:

--------------------------------------------------------------------------------
KASPERSKY ONLINE SCANNER 7 REPORT
Thursday, June 12, 2008
Operating System: Microsoft Windows Vista Home Premium Edition, 32-bit (build 6000)
Kaspersky Online Scanner 7 version: 7.0.25.0
Program database last update: Thursday, June 12, 2008 14:57:30
Records in database: 856010
--------------------------------------------------------------------------------

Scan settings:
Scan using the following database: extended
Scan archives: yes
Scan mail databases: yes

Scan area - Folder:
F:\

Scan statistics:
Files scanned: 40107
Threat name: 5
Infected objects: 17
Suspicious objects: 1
Duration of the scan: 02:33:29


File name / Threat name / Threats count
F:\WINDOWS\Desktop\mail_mcea115.exe Infected: not-a-virus:AdWare.Win32.BargainBuddy.l 1
F:\WINDOWS\Desktop\mail_mcea115.exe Infected: not-a-virus:AdWare.Win32.BargainBuddy.a 1
F:\My Documents, MJW's 600m (070429)\Outlook\Personal Folders - X-Current Files (Aug 89-Jul 01), 010702.pst Infected: Email-Worm.VBS.KakWorm 4
F:\My Documents, MJW's 600m (071105)\To be Copied to Desktop\Outlook\Personal Folders - X-Current Files (Aug 89-Jul 01), 010702.pst Infected: Email-Worm.VBS.KakWorm 4
F:\My Documents, MJW's 600m (071105)\To be Copied to Desktop\Downloads\reference.exe Infected: not-a-virus:AdWare.Win32.Comet.az 1
F:\Update, 071105-071205, to My Documents, MJW's 600m\Downloads\reference.exe Infected: not-a-virus:AdWare.Win32.Comet.az 1
F:\2bctd (080222)\To be Copied to Desktop\Outlook\Personal Folders - X-Current Files (Aug 89-Jul 01), 010702.pst Infected: Email-Worm.VBS.KakWorm 4
F:\2bctd (080222)\To be Copied to Desktop\Outlook\From Inspiron 640M\Archived Calendars, Journals, and Tasks, MJW @ M-20 (Current).pst Suspicious: Trojan-Spy.HTML.Fraud.gen 1
F:\2bctd (080222)\To be Copied to Desktop\Downloads\reference.exe Infected: not-a-virus:AdWare.Win32.Comet.az 1

The selected area was scanned.


c) HJT Report, C drive:

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 10:26:58, on 13 Jun 08
Platform: Windows Vista SP1 (WinNT 6.00.1905)
MSIE: Internet Explorer v7.00 (7.00.6001.18000)
Boot mode: Normal

Running processes:
C:\Windows\system32\taskeng.exe
C:\Windows\system32\Dwm.exe
C:\Windows\Explorer.EXE
C:\Windows\RtHDVCpl.exe
C:\Acer\Empowering Technology\eAudio\eAudio.exe
C:\Acer\Empowering Technology\eDataSecurity\eDSLoader.exe
C:\Program Files\Windows Media Player\wmpnscfg.exe
C:\Program Files\Launch Manager\LManager.exe
C:\Program Files\Acer Arcade Deluxe\Play Movie\PMVService.exe
C:\Program Files\Intel\Intel Matrix Storage Manager\IAAnotif.exe
C:\Program Files\Apoint2K\Apoint.exe
C:\Windows\System32\igfxtray.exe
C:\Windows\System32\hkcmd.exe
C:\Windows\System32\igfxpers.exe
C:\Program Files\Common Files\Symantec Shared\ccApp.exe
C:\Windows\system32\igfxsrvc.exe
C:\Program Files\Java\jre1.6.0_06\bin\jusched.exe
C:\Program Files\Windows Sidebar\sidebar.exe
C:\Windows\ehome\ehtray.exe
C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
C:\Program Files\Adobe\Acrobat 5.0\Distillr\AcroTray.exe
C:\Program Files\Microsoft Office\Office12\ONENOTEM.EXE
C:\Acer\Empowering Technology\ENET\ENMTRAY.EXE
C:\Acer\Empowering Technology\EPOWER\EPOWER_DMC.EXE
C:\Windows\system32\igfxext.exe
C:\Windows\system32\igfxsrvc.exe
C:\Acer\Empowering Technology\ACER.EMPOWERING.FRAMEWORK.SUPERVISOR.EXE
C:\Acer\Empowering Technology\eRecovery\ERAGENT.EXE
C:\Windows\ehome\ehmsas.exe
C:\Users\MICHAE~1.WOL\AppData\Local\Temp\RtkBtMnt.exe
C:\Program Files\Apoint2K\ApMsgFwd.exe
C:\Program Files\Apoint2K\Apntex.exe
C:\Program Files\Internet Explorer\IEUser.exe
C:\Program Files\Yahoo!\Messenger\ymsgr_tray.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://en.us.acer.yahoo.com
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://en.us.acer.yahoo.com
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = localhost
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
R3 - URLSearchHook: Yahoo! ¤u¨ã¦C - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\PROGRA~1\Yahoo!\Companion\Installs\cpn0\yt.dll
R3 - URLSearchHook: WorldTV Bar Toolbar - {44c0b463-5a8a-452c-8e72-dc751dac6ec1} - C:\Program Files\WorldTV_Bar\tbWorl.dll
O1 - Hosts: ::1 localhost
O2 - BHO: &Yahoo! Toolbar Helper - {02478D38-C3F9-4EFB-9B51-7695ECA05670} - C:\PROGRA~1\Yahoo!\Companion\Installs\cpn0\yt.dll
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {1E8A6170-7264-4D0F-BEAE-D42A53123C75} - C:\Program Files\Common Files\Symantec Shared\coShared\Browser\1.5\NppBho.dll
O2 - BHO: WorldTV Bar Toolbar - {44c0b463-5a8a-452c-8e72-dc751dac6ec1} - C:\Program Files\WorldTV_Bar\tbWorl.dll
O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: Yahoo! IE Services Button - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\Program Files\Yahoo!\Common\yiesrvc.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_06\bin\ssv.dll
O2 - BHO: ShowBarObj Class - {83A2F9B1-01A2-4AA5-87D1-45B6B8505E96} - C:\Windows\system32\ActiveToolBand.dll
O3 - Toolbar: Acer eDataSecurity Management - {5CBE3B7C-1E47-477e-A7DD-396DB0476E29} - C:\Windows\system32\eDStoolbar.dll
O3 - Toolbar: Yahoo! ¤u¨ã¦C - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\PROGRA~1\Yahoo!\Companion\Installs\cpn0\yt.dll
O3 - Toolbar: Show Norton Toolbar - {90222687-F593-4738-B738-FBEE9C7B26DF} - C:\Program Files\Common Files\Symantec Shared\coShared\Browser\1.5\UIBHO.dll
O3 - Toolbar: WorldTV Bar Toolbar - {44c0b463-5a8a-452c-8e72-dc751dac6ec1} - C:\Program Files\WorldTV_Bar\tbWorl.dll
O4 - HKLM\..\Run: [Windows Defender] %ProgramFiles%\Windows Defender\MSASCui.exe -hide
O4 - HKLM\..\Run: [ALaunch] C:\Acer\ALaunch\AlaunchClient.exe
O4 - HKLM\..\Run: [RtHDVCpl] RtHDVCpl.exe
O4 - HKLM\..\Run: [eAudio] "C:\Acer\Empowering Technology\eAudio\eAudio.exe"
O4 - HKLM\..\Run: [eDataSecurity Loader] C:\Acer\Empowering Technology\eDataSecurity\eDSloader.exe
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [PLFSet] rundll32.exe C:\Windows\PLFSet.dll,PLFDefSetting
O4 - HKLM\..\Run: [LManager] C:\PROGRA~1\LAUNCH~1\LManager.exe
O4 - HKLM\..\Run: [PlayMovie] "C:\Program Files\Acer Arcade Deluxe\Play Movie\PMVService.exe"
O4 - HKLM\..\Run: [IAAnotif] "C:\Program Files\Intel\Intel Matrix Storage Manager\Iaanotif.exe"
O4 - HKLM\..\Run: [Apoint] C:\Program Files\Apoint2K\Apoint.exe
O4 - HKLM\..\Run: [Acer Product Registration] "C:\Program Files\Acer Registration\ACE1.exe" /startup
O4 - HKLM\..\Run: [Acer Assist Launcher] C:\Program Files\Acer Assist\launcher.exe
O4 - HKLM\..\Run: [Acer Tour Reminder] C:\Acer\AcerTour\Reminder.exe
O4 - HKLM\..\Run: [SetPanel] C:\Acer\APanel\APanel.cmd
O4 - HKLM\..\Run: [IgfxTray] C:\Windows\system32\igfxtray.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\Windows\system32\hkcmd.exe
O4 - HKLM\..\Run: [Persistence] C:\Windows\system32\igfxpers.exe
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [Symantec PIF AlertEng] "C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc.exe" /a /m "C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\AlertEng.dll"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_06\bin\jusched.exe"
O4 - HKLM\..\Run: [Skytel] Skytel.exe
O4 - HKCU\..\Run: [Sidebar] C:\Program Files\Windows Sidebar\sidebar.exe /autoRun
O4 - HKCU\..\Run: [ehTray.exe] C:\Windows\ehome\ehTray.exe
O4 - HKCU\..\Run: [Yahoo! Pager] "C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe" -quiet
O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
O4 - HKCU\..\Run: [WMPNSCFG] C:\Program Files\Windows Media Player\WMPNSCFG.exe
O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-19\..\Run: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCenter (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'NETWORK SERVICE')
O4 - Startup: OneNote 2007 Screen Clipper and Launcher.lnk = C:\Program Files\Microsoft Office\Office12\ONENOTEM.EXE
O4 - Startup: Orion.lnk = C:\Convesoft\Orion\Messenger.exe
O4 - Global Startup: Acrobat Assistant.lnk = C:\Program Files\Adobe\Acrobat 5.0\Distillr\AcroTray.exe
O4 - Global Startup: Empowering Technology Launcher.lnk = ?
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office12\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_06\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_06\bin\ssv.dll
O9 - Extra button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: S&end to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll
O9 - Extra button: Yahoo! Services - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\Program Files\Yahoo!\Common\yiesrvc.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\Office12\REFIEBAR.DLL
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll
O13 - Gopher Prefix:
O16 - DPF: {02BF25D5-8C17-4B23-BC80-D3488ABDDC6B} (QuickTime Object) - http://appldnld.apple.com.edgesuite.net/content.info.apple.com/QuickTime/qtactivex/qtplugin.cab
O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (Installation Support) - C:\Program Files\Yahoo!\Common\Yinsthelper.dll
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} (Java Runtime Environment 1.6.0) - http://sdlc-esd.sun.com/ESD42/JSCDL/jre/6u6-b90/jinstall-6u6-windows-i586-jc.cab?AuthParam=1213231817_44f2966c00ab82602ef3c9535ddbea3a&GroupName=JSC&BHost=javadl.sun.com&FilePath=/ESD42/JSCDL/jre/6u6-b90/jinstall-6u6-windows-i586-jc.cab&File=jinstall-6u6-windows-i586-jc.cab
O20 - AppInit_DLLs: eNetHook.dll
O23 - Service: Lavasoft Ad-Aware Service (aawservice) - Lavasoft - C:\Program Files\Lavasoft\Ad-Aware\aawservice.exe
O23 - Service: ALaunch Service (ALaunchService) - Unknown owner - C:\Acer\ALaunch\ALaunchSvc.exe
O23 - Service: ccEvtMgr - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
O23 - Service: ccSetMgr - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
O23 - Service: Symantec Lic NetConnect service (CLTNetCnService) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
O23 - Service: COM Host (comHost) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\VAScanner\comHost.exe
O23 - Service: eDataSecurity Service - HiTRSUT - C:\Acer\Empowering Technology\eDataSecurity\eDSService.exe
O23 - Service: eLock Service (eLockService) - Acer Inc. - C:\Acer\Empowering Technology\eLock\Service\eLockServ.exe
O23 - Service: eNet Service - Acer Inc. - C:\Acer\Empowering Technology\eNet\eNet Service.exe
O23 - Service: eRecovery Service (eRecoveryService) - Acer Inc. - C:\Acer\Empowering Technology\eRecovery\eRecoveryService.exe
O23 - Service: eSettings Service (eSettingsService) - Unknown owner - C:\Acer\Empowering Technology\eSettings\Service\capuserv.exe
O23 - Service: Intel(R) Matrix Storage Event Monitor (IAANTMON) - Intel Corporation - C:\Program Files\Intel\Intel Matrix Storage Manager\Iaantmon.exe
O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:\Program Files\Common Files\LightScribe\LSSrvc.exe
O23 - Service: LiveUpdate - Symantec Corporation - C:\PROGRA~1\Symantec\LIVEUP~1\LUCOMS~1.EXE
O23 - Service: LiveUpdate Notice Service Ex (LiveUpdate Notice Ex) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
O23 - Service: LiveUpdate Notice Service - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc.exe
O23 - Service: MobilityService - Unknown owner - C:\Acer\Mobility Center\MobilityService.exe
O23 - Service: Cyberlink RichVideo Service(CRVS) (RichVideo) - Unknown owner - C:\Program Files\CyberLink\Shared Files\RichVideo.exe
O23 - Service: SBSD Security Center Service (SBSDWSCService) - Safer Networking Ltd. - C:\Program Files\Spybot - Search & Destroy\SDWinSec.exe
O23 - Service: Symantec Core LC - Unknown owner - C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
O23 - Service: ePower Service (WMIService) - acer - C:\Acer\Empowering Technology\ePower\ePowerSvc.exe
O23 - Service: XAudioService - Conexant Systems, Inc. - C:\Windows\system32\DRIVERS\xaudio.exe

--
End of file - 12120 bytes

Blade81
2008-06-21, 14:43
Hi

Delete following files:
F:\WINDOWS\Desktop\mail_mcea115.exe
F:\My Documents, MJW's 600m (071105)\To be Copied to Desktop\Downloads\reference.exe
F:\Update, 071105-071205, to My Documents, MJW's 600m\Downloads\reference.exe
F:\2bctd (080222)\To be Copied to Desktop\Downloads\reference.exe

Kaspersky's new online scanner doesn't list infected mail messages so we need to use old version which is luckily still available.


Please run an online scan with Kaspersky Online Scanner (http://www.kaspersky.nl/scanforvirus-en/kavwebscan.html). You will be prompted to install an ActiveX component from Kaspersky, click Yes.
The program will launch and start to download the latest definition files.
Once the scanner is installed and the definitions downloaded, click Next.
Now click on Scan Settings and select the following:
Scan using the following Anti-Virus database:
Extended (If available, otherwise Standard)
Scan Options:
Scan Archives
Scan Mail Bases
Click OK.
Under
select a target to scan
, select My Computer.
The scan will take a while so be patient and let it run. As it scans your machine very deeply it could take hours to complete, Kaspersky suggests running it during a time of low activity.Once the scan is complete:
Click on the Save as Text button.
Save the file to your desktop.
Copy and paste that information into your next post if the AV content will fit into one post only.


Note for Internet Explorer 7 users: If at any time you have trouble with the Accept button of the license, click on the Zoom tool located at the bottom right of the IE window and set the zoom to 75 %. Once the license has been accepted, reset to 100%.

If having a problme doing the above

Make sure that your Internet security settings are set to default values.

To set default security settings for Internet Explorer:

* Open Internet Explorer.
* Go to the Tools menu, then choose Internet Options.
* Click on the Security tab.
* Make sure that all four item (Internet, Local intranet, Trusted sites, and Restricted sites) are set to their default settings.

MJWolter
2008-06-22, 18:27
Hello, Blade81. Thank you for helping me with this. Here is the log:

KASPERSKY ONLINE SCANNER REPORT
Sunday, 22 June, 2008 02:35:04
Operating System: Microsoft Windows Vista Home Edition, Service Pack 1 (Build 6001)
Kaspersky Online Scanner version: 5.0.98.0
Kaspersky Anti-Virus database last update: 21/06/2008
Kaspersky Anti-Virus database records: 880072

Scan Settings
Scan using the following antivirus database extended
Scan Archives true
Scan Mail Bases true

Scan Target My Computer
C:\
D:\
E:\
F:\

Scan Statistics
Total number of scanned objects 166989
Number of viruses found 4
Number of infected objects 48
Number of suspicious objects 0
Duration of the scan process 07:34:12

Infected Object Name Virus Name Last Action
C:\Boot\BCD Object is locked skipped
C:\Boot\BCD.LOG Object is locked skipped
C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcrst.dll Object is locked skipped
C:\Program Files\Common Files\Symantec Shared\coShared\WA\1.5\NCOWAD.dat Object is locked skipped
C:\Program Files\Common Files\Symantec Shared\coShared\WA\1.5\NCOWADMT.dat Object is locked skipped
C:\Program Files\Common Files\Symantec Shared\coShared\WA\1.5\NCOWAS.dat Object is locked skipped
C:\Program Files\Common Files\Symantec Shared\coShared\WA\1.5\NCOWAS.ldb Object is locked skipped
C:\Program Files\Common Files\Symantec Shared\EENGINE\EPERSIST.DAT Object is locked skipped
C:\Program Files\Norton 360\Log\AutoProtect.log Object is locked skipped
C:\Program Files\Norton 360\Log\AVContext.log Object is locked skipped
C:\Program Files\Norton 360\Log\AVManual.log Object is locked skipped
C:\Program Files\Norton 360\Log\Backup.log Object is locked skipped
C:\Program Files\Norton 360\Log\CUInternetPageViewHistory.log Object is locked skipped
C:\Program Files\Norton 360\Log\CUInternetSearchHistory.log Object is locked skipped
C:\Program Files\Norton 360\Log\CUInternetTempFiles.log Object is locked skipped
C:\Program Files\Norton 360\Log\CUWindowsTempFiles.log Object is locked skipped
C:\Program Files\Norton 360\Log\EmailScan.log Object is locked skipped
C:\Program Files\Norton 360\Log\InternetSecurity.log Object is locked skipped
C:\Program Files\Norton 360\Log\ISIntrusionPrevented.log Object is locked skipped
C:\Program Files\Norton 360\Log\ISIOTraffic.log Object is locked skipped
C:\Program Files\Norton 360\Log\ISNewNetwork.log Object is locked skipped
C:\Program Files\Norton 360\Log\LiveUpdate.log Object is locked skipped
C:\Program Files\Norton 360\Log\NCO.log Object is locked skipped
C:\Program Files\Norton 360\Log\VABrowserSettings.log Object is locked skipped
C:\Program Files\Norton 360\Log\VAIPAddresses.log Object is locked skipped
C:\Program Files\Norton 360\Log\VAWeakPasswords.log Object is locked skipped
C:\Program Files\Norton 360\Log\WDFScanner.log Object is locked skipped
C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\0402aaeb112e4cb9fd3afdd7fa0f12dd_1c7a0d1b-bf6d-47e4-b269-337d228e6673 Object is locked skipped
C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\058a9056a359e890dfe20e6419364e73_1c7a0d1b-bf6d-47e4-b269-337d228e6673 Object is locked skipped
C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\08abe9cfc68548b56b87c80eb2a6ac34_1c7a0d1b-bf6d-47e4-b269-337d228e6673 Object is locked skipped
C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\10ede3afa9512585bb3758657d96a3fd_1c7a0d1b-bf6d-47e4-b269-337d228e6673 Object is locked skipped
C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\11b5b913f861944a119912d95f928d2a_1c7a0d1b-bf6d-47e4-b269-337d228e6673 Object is locked skipped
C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\151996172a588ed10668cbca1db33a7d_1c7a0d1b-bf6d-47e4-b269-337d228e6673 Object is locked skipped
C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\1a7644dc6668c6bd981845b86a71dac6_1c7a0d1b-bf6d-47e4-b269-337d228e6673 Object is locked skipped
C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\1bf74792c52f5f9974d9d090b352d4e2_1c7a0d1b-bf6d-47e4-b269-337d228e6673 Object is locked skipped
C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\1ef9827bc919ec11043a467d928423f1_1c7a0d1b-bf6d-47e4-b269-337d228e6673 Object is locked skipped
C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\1f114d3786b0a2f6def37d9f8bbbf4ed_1c7a0d1b-bf6d-47e4-b269-337d228e6673 Object is locked skipped
C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\1fa5193f31d881e30c0b220f44b31fe1_1c7a0d1b-bf6d-47e4-b269-337d228e6673 Object is locked skipped
C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\1fcb42d215c1fa8a2aedd335bcb97973_1c7a0d1b-bf6d-47e4-b269-337d228e6673 Object is locked skipped
C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\26a2fd1a226245148044588efc935081_1c7a0d1b-bf6d-47e4-b269-337d228e6673 Object is locked skipped
C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\2ee942b1b1cda6cccad1bb1b5f6fef75_1c7a0d1b-bf6d-47e4-b269-337d228e6673 Object is locked skipped
C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\2fcd5ae570eb9704bb450f239c67604d_1c7a0d1b-bf6d-47e4-b269-337d228e6673 Object is locked skipped
C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\30e718d5648710bc4025f046ab488d16_1c7a0d1b-bf6d-47e4-b269-337d228e6673 Object is locked skipped
C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\350760e3f461fc695e5bb75380f4e173_1c7a0d1b-bf6d-47e4-b269-337d228e6673 Object is locked skipped
C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\3578fddd7aec0378d2a8ee19036d0a4b_1c7a0d1b-bf6d-47e4-b269-337d228e6673 Object is locked skipped
C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\384b7b11cad30c7c8d9a584d5cc4c803_1c7a0d1b-bf6d-47e4-b269-337d228e6673 Object is locked skipped
C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\3af2c851635c6c3e43789c14982fdfc3_1c7a0d1b-bf6d-47e4-b269-337d228e6673 Object is locked skipped
C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\3e61fc64e45aeefdcb255b46937ec0e6_1c7a0d1b-bf6d-47e4-b269-337d228e6673 Object is locked skipped
C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\4a163f6346d3aaa66680996e5f0b3af1_1c7a0d1b-bf6d-47e4-b269-337d228e6673 Object is locked skipped
C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\4e2222e72b280d1f480a08062697af91_1c7a0d1b-bf6d-47e4-b269-337d228e6673 Object is locked skipped
C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\4f26768ae60ebc9c5ecc502b8be65084_1c7a0d1b-bf6d-47e4-b269-337d228e6673 Object is locked skipped
C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\5135d633aa3611858ea8521a1f0952fc_1c7a0d1b-bf6d-47e4-b269-337d228e6673 Object is locked skipped
C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\6642f6eadd7df4077098d1687f3a3bee_1c7a0d1b-bf6d-47e4-b269-337d228e6673 Object is locked skipped
C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\68a174dbe3e71534a310620615d0cd00_1c7a0d1b-bf6d-47e4-b269-337d228e6673 Object is locked skipped
C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\6c3c8f3af62d094595be0a620c00edb5_1c7a0d1b-bf6d-47e4-b269-337d228e6673 Object is locked skipped
C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\6d7564440dfc0a2a87e0dd0d49d89330_1c7a0d1b-bf6d-47e4-b269-337d228e6673 Object is locked skipped
C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\6f89751eb4e910890231a53fac571931_1c7a0d1b-bf6d-47e4-b269-337d228e6673 Object is locked skipped
C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\73225951831a2338d1a88df81c60f1b5_1c7a0d1b-bf6d-47e4-b269-337d228e6673 Object is locked skipped
C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\74a6f07a9374181506c87ad2e3d9cbd7_1c7a0d1b-bf6d-47e4-b269-337d228e6673 Object is locked skipped
C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\78143c9544ef09fc9cd33c80904cbce3_1c7a0d1b-bf6d-47e4-b269-337d228e6673 Object is locked skipped
C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\7840fea5cc148a2329c1c27a32256af9_1c7a0d1b-bf6d-47e4-b269-337d228e6673 Object is locked skipped
C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\7b18e0c86736ae7d7152bfbc94a37636_1c7a0d1b-bf6d-47e4-b269-337d228e6673 Object is locked skipped
C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\7cef221929ddaf020dba4cca5915b00b_1c7a0d1b-bf6d-47e4-b269-337d228e6673 Object is locked skipped
C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\8c874f736c4f9dce2434c7c95a771974_1c7a0d1b-bf6d-47e4-b269-337d228e6673 Object is locked skipped
C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\95da5582becf2431c09f8f3030427e65_1c7a0d1b-bf6d-47e4-b269-337d228e6673 Object is locked skipped
C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\996a545df43f08d74d2d47ba7cb7c3da_1c7a0d1b-bf6d-47e4-b269-337d228e6673 Object is locked skipped
C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\9b33b3013106b23c07c9203b99edaf77_1c7a0d1b-bf6d-47e4-b269-337d228e6673 Object is locked skipped
C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\a073baa48ba8fde095be2dd29f56b97e_1c7a0d1b-bf6d-47e4-b269-337d228e6673 Object is locked skipped
C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\af53dd40800324cfec449e8908600ce1_1c7a0d1b-bf6d-47e4-b269-337d228e6673 Object is locked skipped
C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\afc74611f2656142f249d87d6ed972d4_1c7a0d1b-bf6d-47e4-b269-337d228e6673 Object is locked skipped
C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\b2d002aabe077919a515f62005117837_1c7a0d1b-bf6d-47e4-b269-337d228e6673 Object is locked skipped
C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\b7155d6d63f6439fb2dfe01f60321911_1c7a0d1b-bf6d-47e4-b269-337d228e6673 Object is locked skipped
C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\bcdaa4eac609de99860fbeab35e1f939_1c7a0d1b-bf6d-47e4-b269-337d228e6673 Object is locked skipped
C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\bfc7fd1fa2169b870292524aae1699b4_1c7a0d1b-bf6d-47e4-b269-337d228e6673 Object is locked skipped
C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\c1e6e1bb9f99bd0ada9858ce01dfdf99_1c7a0d1b-bf6d-47e4-b269-337d228e6673 Object is locked skipped
C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\c21b439ca4a202a8e0e27b1383ada264_1c7a0d1b-bf6d-47e4-b269-337d228e6673 Object is locked skipped
C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\d517b95162e15f7b760dad0079ab2c70_1c7a0d1b-bf6d-47e4-b269-337d228e6673 Object is locked skipped
C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\d9936f9be3a4e376a86cbdec0978a37d_1c7a0d1b-bf6d-47e4-b269-337d228e6673 Object is locked skipped
C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\da4562024d26e86230dc94e0d3ae1f08_1c7a0d1b-bf6d-47e4-b269-337d228e6673 Object is locked skipped
C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\dd108018d8304b0266504ee09c69fde5_1c7a0d1b-bf6d-47e4-b269-337d228e6673 Object is locked skipped
C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\dec1ccff68205231e28c46b076ba50ad_1c7a0d1b-bf6d-47e4-b269-337d228e6673 Object is locked skipped
C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\dee1719ed9226ba40999ea60e91de5b6_1c7a0d1b-bf6d-47e4-b269-337d228e6673 Object is locked skipped
C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\e1ef8af4d52557d7bba65197bc7043c3_1c7a0d1b-bf6d-47e4-b269-337d228e6673 Object is locked skipped
C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\e361d3bbe757bd025779961b34369f47_1c7a0d1b-bf6d-47e4-b269-337d228e6673 Object is locked skipped
C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\e83952d982e6706ba0e3f0cb774a6ab5_1c7a0d1b-bf6d-47e4-b269-337d228e6673 Object is locked skipped
C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\ef1a6588d92f48d54da6abbe24f968ee_1c7a0d1b-bf6d-47e4-b269-337d228e6673 Object is locked skipped
C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\f38d3d0f93f6fb42d5c857d59f0e8811_1c7a0d1b-bf6d-47e4-b269-337d228e6673 Object is locked skipped
C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\f48c9a3963cdbfbf745cc488137add75_1c7a0d1b-bf6d-47e4-b269-337d228e6673 Object is locked skipped
C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\f4d7d09289978ab647a4e017589a6d3c_1c7a0d1b-bf6d-47e4-b269-337d228e6673 Object is locked skipped
C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\f9f4468408c0807fc44e4f830225fffe_1c7a0d1b-bf6d-47e4-b269-337d228e6673 Object is locked skipped
C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\fb906dd484712ab9120ad47058f66a48_1c7a0d1b-bf6d-47e4-b269-337d228e6673 Object is locked skipped
C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\fc440ee23a4fa532280866aaa32b39e8_1c7a0d1b-bf6d-47e4-b269-337d228e6673 Object is locked skipped
C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\fcd83448310c9b82be23939fd9263a5d_1c7a0d1b-bf6d-47e4-b269-337d228e6673 Object is locked skipped
C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\fcea4dce8e23c3c16ac80653a9d5ecd0_1c7a0d1b-bf6d-47e4-b269-337d228e6673 Object is locked skipped
C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\fd771bf7f18217c79130d44151cb18e9_1c7a0d1b-bf6d-47e4-b269-337d228e6673 Object is locked skipped
C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\ff0ca490adccd08daeffd41e89c2a204_1c7a0d1b-bf6d-47e4-b269-337d228e6673 Object is locked skipped
C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\ff1e05db7615fe6620d6cfa5cdc2a3ff_1c7a0d1b-bf6d-47e4-b269-337d228e6673 Object is locked skipped
C:\ProgramData\Microsoft\Network\Downloader\qmgr0.dat Object is locked skipped
C:\ProgramData\Microsoft\Network\Downloader\qmgr1.dat Object is locked skipped
C:\ProgramData\Microsoft\Search\Data\Applications\Windows\GatherLogs\SystemIndex\SystemIndex.99.Crwl Object is locked skipped
C:\ProgramData\Microsoft\Search\Data\Applications\Windows\GatherLogs\SystemIndex\SystemIndex.99.gthr Object is locked skipped
C:\ProgramData\Microsoft\Search\Data\Applications\Windows\MSS.log Object is locked skipped
C:\ProgramData\Microsoft\Search\Data\Applications\Windows\MSStmp.log Object is locked skipped
C:\ProgramData\Microsoft\Search\Data\Applications\Windows\Projects\SystemIndex\Indexer\CiFiles\00010010.wid Object is locked skipped
C:\ProgramData\Microsoft\Search\Data\Applications\Windows\Projects\SystemIndex\Indexer\CiFiles\00010012.wid Object is locked skipped
C:\ProgramData\Microsoft\Search\Data\Applications\Windows\Projects\SystemIndex\Indexer\CiFiles\0001002D.ci Object is locked skipped
C:\ProgramData\Microsoft\Search\Data\Applications\Windows\Projects\SystemIndex\Indexer\CiFiles\0001002D.wid Object is locked skipped
C:\ProgramData\Microsoft\Search\Data\Applications\Windows\Projects\SystemIndex\Indexer\CiFiles\0001002D.wsb Object is locked skipped
C:\ProgramData\Microsoft\Search\Data\Applications\Windows\Projects\SystemIndex\Indexer\CiFiles\INDEX.000 Object is locked skipped
C:\ProgramData\Microsoft\Search\Data\Applications\Windows\Projects\SystemIndex\PropMap\CiPT0000.000 Object is locked skipped
C:\ProgramData\Microsoft\Search\Data\Applications\Windows\Projects\SystemIndex\PropMap\Used0000.000 Object is locked skipped
C:\ProgramData\Microsoft\Search\Data\Applications\Windows\Projects\SystemIndex\SecStore\CiST0000.000 Object is locked skipped
C:\ProgramData\Microsoft\Search\Data\Applications\Windows\Projects\SystemIndex\SystemIndex.chk1.gthr Object is locked skipped
C:\ProgramData\Microsoft\Search\Data\Applications\Windows\Projects\SystemIndex\SystemIndex.chk2.gthr Object is locked skipped
C:\ProgramData\Microsoft\Search\Data\Applications\Windows\Projects\SystemIndex\SystemIndex.Crwl23.gthr Object is locked skipped
C:\ProgramData\Microsoft\Search\Data\Applications\Windows\Projects\SystemIndex\SystemIndex.Crwl24.gthr Object is locked skipped
C:\ProgramData\Microsoft\Search\Data\Applications\Windows\Projects\SystemIndex\SystemIndex.Ntfy28.gthr Object is locked skipped
C:\ProgramData\Microsoft\Search\Data\Applications\Windows\Projects\SystemIndex\SystemIndex.Ntfy29.gthr Object is locked skipped
C:\ProgramData\Microsoft\Search\Data\Applications\Windows\tmp.edb Object is locked skipped
C:\ProgramData\Microsoft\Search\Data\Applications\Windows\Windows.edb Object is locked skipped
C:\ProgramData\Microsoft\Search\Data\Temp\usgthrsvc\NtfA2F2.tmp Object is locked skipped
C:\ProgramData\Microsoft\Search\Data\Temp\usgthrsvc\NtfA303.tmp Object is locked skipped
C:\ProgramData\Microsoft\Windows\DRM\Cache\Indiv01.tmp Object is locked skipped
C:\ProgramData\Microsoft\Windows\DRM\drmstore.hds Object is locked skipped
C:\ProgramData\Symantec\Common Client\settings.dat Object is locked skipped
C:\ProgramData\Symantec\Shared\QBackup\index.qbs Object is locked skipped
C:\ProgramData\Symantec\SPBBC\BBConfig.log Object is locked skipped
C:\ProgramData\Symantec\SPBBC\BBDebug.log Object is locked skipped
C:\ProgramData\Symantec\SPBBC\BBDetect.log Object is locked skipped
C:\ProgramData\Symantec\SPBBC\BBNotify.log Object is locked skipped
C:\ProgramData\Symantec\SPBBC\BBRefr.log Object is locked skipped
C:\ProgramData\Symantec\SPBBC\BBSetCfg.log Object is locked skipped
C:\ProgramData\Symantec\SPBBC\BBSetCfg2.log Object is locked skipped
C:\ProgramData\Symantec\SPBBC\BBSetDev.log Object is locked skipped
C:\ProgramData\Symantec\SPBBC\BBSetLoc.log Object is locked skipped
C:\ProgramData\Symantec\SPBBC\BBSetUsr.log Object is locked skipped
C:\ProgramData\Symantec\SPBBC\BBStHash.log Object is locked skipped
C:\ProgramData\Symantec\SPBBC\BBValid.log Object is locked skipped
C:\ProgramData\Symantec\SPBBC\SPPolicy.log Object is locked skipped
C:\ProgramData\Symantec\SPBBC\SPStart.log Object is locked skipped
C:\ProgramData\Symantec\SPBBC\SPStop.log Object is locked skipped
C:\ProgramData\Symantec\SRTSP\SrtErEvt.log Object is locked skipped
C:\ProgramData\Symantec\SRTSP\SrtETmp\9FC49081.TMP Object is locked skipped
C:\ProgramData\Symantec\SRTSP\SrtETmp\E3283286.TMP Object is locked skipped
C:\ProgramData\Symantec\SRTSP\SrtMoEvt.log Object is locked skipped
C:\ProgramData\Symantec\SRTSP\SrtNvEvt.log Object is locked skipped
C:\ProgramData\Symantec\SRTSP\SrtScEvt.log Object is locked skipped
C:\ProgramData\Symantec\SRTSP\SrtTxFEvt.log Object is locked skipped
C:\ProgramData\Symantec\SRTSP\SrtViEvt.log Object is locked skipped
C:\ProgramData\Symantec\SymNetDrv\SNDALRT.log Object is locked skipped
C:\ProgramData\Symantec\SymNetDrv\SNDCON.log Object is locked skipped
C:\ProgramData\Symantec\SymNetDrv\SNDDBG.log Object is locked skipped
C:\ProgramData\Symantec\SymNetDrv\SNDFW.log Object is locked skipped
C:\ProgramData\Symantec\SymNetDrv\SNDIDS.log Object is locked skipped
C:\ProgramData\Symantec\SymNetDrv\SNDSYS.log Object is locked skipped
C:\System Volume Information\MountPointManagerRemoteDatabase Object is locked skipped
C:\Users\Michael J. Wolter\AppData\Local\Microsoft\Feeds Cache\index.dat Object is locked skipped
C:\Users\Michael J. Wolter\AppData\Local\Microsoft\Internet Explorer\MSIMGSIZ.DAT Object is locked skipped
C:\Users\Michael J. Wolter\AppData\Local\Microsoft\Media Player\CurrentDatabase_360.wmdb Object is locked skipped
C:\Users\Michael J. Wolter\AppData\Local\Microsoft\Windows\History\History.IE5\INDEX.DAT Object is locked skipped
C:\Users\Michael J. Wolter\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat Object is locked skipped
C:\Users\Michael J. Wolter\AppData\Local\Microsoft\Windows\UsrClass.dat Object is locked skipped
C:\Users\Michael J. Wolter\AppData\Local\Microsoft\Windows\UsrClass.dat.LOG1 Object is locked skipped
C:\Users\Michael J. Wolter\AppData\Local\Microsoft\Windows\UsrClass.dat.LOG2 Object is locked skipped
C:\Users\Michael J. Wolter\AppData\Local\Microsoft\Windows\UsrClass.dat{f6cc15a9-df2d-11dc-8309-001b77d750a2}.TM.blf Object is locked skipped
C:\Users\Michael J. Wolter\AppData\Local\Microsoft\Windows\UsrClass.dat{f6cc15a9-df2d-11dc-8309-001b77d750a2}.TMContainer00000000000000000001.regtrans-ms Object is locked skipped
C:\Users\Michael J. Wolter\AppData\Local\Microsoft\Windows\UsrClass.dat{f6cc15a9-df2d-11dc-8309-001b77d750a2}.TMContainer00000000000000000002.regtrans-ms Object is locked skipped
C:\Users\Michael J. Wolter\AppData\Local\Microsoft\Windows Sidebar\Settings.ini Object is locked skipped
C:\Users\Michael J. Wolter\AppData\Local\Temp\~DF1DB6.tmp Object is locked skipped
C:\Users\Michael J. Wolter\AppData\Roaming\Microsoft\Windows\Cookies\INDEX.DAT Object is locked skipped
C:\Users\Michael J. Wolter\Documents\To be Copied to Desktop\Outlook\Personal Folders - X-Current Files (Aug 89-Jul 01), 010702.pst/Personal Folders (Aug 89-Jul 01)/X-Current Files (Aug 89-Jul 00; Dec 00 - Present)/Accounts/NVRA/25 Jun 2000 23:38 from Sharon Lambert:Re: Voice Recognition Tech.html Infected: Email-Worm.VBS.KakWorm skipped
C:\Users\Michael J. Wolter\Documents\To be Copied to Desktop\Outlook\Personal Folders - X-Current Files (Aug 89-Jul 01), 010702.pst/Personal Folders (Aug 89-Jul 01)/X-Current Files (Aug 89-Jul 00; Dec 00 - Present)/Accounts/NVRA/28 Jun 2000 21:33 from Sharon Lambert:Re: Voice Recognition Tech.html Infected: Email-Worm.VBS.KakWorm skipped
C:\Users\Michael J. Wolter\Documents\To be Copied to Desktop\Outlook\Personal Folders - X-Current Files (Aug 89-Jul 01), 010702.pst MailMSMaill: infected - 2 skipped
C:\Users\Michael J. Wolter\NTUSER.DAT Object is locked skipped
C:\Users\Michael J. Wolter\ntuser.dat.LOG1 Object is locked skipped
C:\Users\Michael J. Wolter\ntuser.dat.LOG2 Object is locked skipped
C:\Users\Michael J. Wolter\NTUSER.DAT{3a539871-6a70-11db-887c-d362bd253390}.TM.blf Object is locked skipped
C:\Users\Michael J. Wolter\NTUSER.DAT{3a539871-6a70-11db-887c-d362bd253390}.TMContainer00000000000000000001.regtrans-ms Object is locked skipped
C:\Users\Michael J. Wolter\NTUSER.DAT{3a539871-6a70-11db-887c-d362bd253390}.TMContainer00000000000000000002.regtrans-ms Object is locked skipped
C:\Windows\Debug\PASSWD.LOG Object is locked skipped
C:\Windows\Debug\WIA\wiatrace.log Object is locked skipped
C:\Windows\ServiceProfiles\LocalService\AppData\Local\lastalive0.dat Object is locked skipped
C:\Windows\ServiceProfiles\LocalService\AppData\Local\lastalive1.dat Object is locked skipped
C:\Windows\ServiceProfiles\LocalService\AppData\Local\Microsoft\Windows\WindowsUpdate.log Object is locked skipped
C:\Windows\ServiceProfiles\LocalService\NTUSER.DAT Object is locked skipped
C:\Windows\ServiceProfiles\LocalService\ntuser.dat.LOG1 Object is locked skipped
C:\Windows\ServiceProfiles\LocalService\ntuser.dat.LOG2 Object is locked skipped
C:\Windows\ServiceProfiles\LocalService\NTUSER.DAT{3a539869-6a70-11db-887c-d362bd253390}.TM.blf Object is locked skipped
C:\Windows\ServiceProfiles\LocalService\NTUSER.DAT{3a539869-6a70-11db-887c-d362bd253390}.TMContainer00000000000000000001.regtrans-ms Object is locked skipped
C:\Windows\ServiceProfiles\LocalService\NTUSER.DAT{3a539869-6a70-11db-887c-d362bd253390}.TMContainer00000000000000000002.regtrans-ms Object is locked skipped
C:\Windows\ServiceProfiles\NetworkService\NTUSER.DAT Object is locked skipped
C:\Windows\ServiceProfiles\NetworkService\ntuser.dat.LOG1 Object is locked skipped
C:\Windows\ServiceProfiles\NetworkService\ntuser.dat.LOG2 Object is locked skipped
C:\Windows\ServiceProfiles\NetworkService\NTUSER.DAT{3a539865-6a70-11db-887c-d362bd253390}.TM.blf Object is locked skipped
C:\Windows\ServiceProfiles\NetworkService\NTUSER.DAT{3a539865-6a70-11db-887c-d362bd253390}.TMContainer00000000000000000001.regtrans-ms Object is locked skipped
C:\Windows\ServiceProfiles\NetworkService\NTUSER.DAT{3a539865-6a70-11db-887c-d362bd253390}.TMContainer00000000000000000002.regtrans-ms Object is locked skipped
C:\Windows\SoftwareDistribution\ReportingEvents.log Object is locked skipped
C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-0.C7483456-A289-439d-8115-601632D005A0 Object is locked skipped
C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-1.C7483456-A289-439d-8115-601632D005A0 Object is locked skipped
C:\Windows\System32\catroot2\edb.log Object is locked skipped
C:\Windows\System32\catroot2\{127D0A1D-4EF2-11D1-8608-00C04FC295EE}\catdb Object is locked skipped
C:\Windows\System32\catroot2\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\catdb Object is locked skipped
C:\Windows\System32\config\COMPONENTS Object is locked skipped
C:\Windows\System32\config\COMPONENTS.LOG1 Object is locked skipped
C:\Windows\System32\config\COMPONENTS.LOG2 Object is locked skipped
C:\Windows\System32\config\DEFAULT Object is locked skipped
C:\Windows\System32\config\DEFAULT.LOG1 Object is locked skipped
C:\Windows\System32\config\DEFAULT.LOG2 Object is locked skipped
C:\Windows\System32\config\RegBack\COMPONENTS Object is locked skipped
C:\Windows\System32\config\RegBack\DEFAULT Object is locked skipped
C:\Windows\System32\config\RegBack\SAM Object is locked skipped
C:\Windows\System32\config\RegBack\SECURITY Object is locked skipped
C:\Windows\System32\config\RegBack\SOFTWARE Object is locked skipped
C:\Windows\System32\config\RegBack\SYSTEM Object is locked skipped
C:\Windows\System32\config\SAM Object is locked skipped
C:\Windows\System32\config\SAM.LOG1 Object is locked skipped
C:\Windows\System32\config\SAM.LOG2 Object is locked skipped
C:\Windows\System32\config\SECURITY Object is locked skipped
C:\Windows\System32\config\SECURITY.LOG1 Object is locked skipped
C:\Windows\System32\config\SECURITY.LOG2 Object is locked skipped
C:\Windows\System32\config\SOFTWARE Object is locked skipped
C:\Windows\System32\config\SOFTWARE.LOG1 Object is locked skipped
C:\Windows\System32\config\SOFTWARE.LOG2 Object is locked skipped
C:\Windows\System32\config\SYSTEM Object is locked skipped
C:\Windows\System32\config\SYSTEM.LOG1 Object is locked skipped
C:\Windows\System32\config\SYSTEM.LOG2 Object is locked skipped
C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat Object is locked skipped
C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat Object is locked skipped
C:\Windows\System32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\index.dat Object is locked skipped
C:\Windows\System32\config\TxR\{250834b7-750c-494d-bdc3-da86b6e2101a}.TxR.0.regtrans-ms Object is locked skipped
C:\Windows\System32\config\TxR\{250834b7-750c-494d-bdc3-da86b6e2101a}.TxR.1.regtrans-ms Object is locked skipped
C:\Windows\System32\config\TxR\{250834b7-750c-494d-bdc3-da86b6e2101a}.TxR.2.regtrans-ms Object is locked skipped
C:\Windows\System32\config\TxR\{250834b7-750c-494d-bdc3-da86b6e2101a}.TxR.blf Object is locked skipped
C:\Windows\System32\config\TxR\{250834B7-750C-494d-BDC3-DA86B6E2101B}.TM.blf Object is locked skipped
C:\Windows\System32\config\TxR\{250834B7-750C-494d-BDC3-DA86B6E2101B}.TMContainer00000000000000000001.regtrans-ms Object is locked skipped
C:\Windows\System32\config\TxR\{250834B7-750C-494d-BDC3-DA86B6E2101B}.TMContainer00000000000000000002.regtrans-ms Object is locked skipped
C:\Windows\System32\config\TxR\{250834B7-750C-494d-BDC3-DA86B6E2101B}.TMContainer00000000000000000003.regtrans-ms Object is locked skipped
C:\Windows\System32\config\TxR\{250834B7-750C-494d-BDC3-DA86B6E2101B}.TMContainer00000000000000000004.regtrans-ms Object is locked skipped
C:\Windows\System32\drivers\etc\Hosts.bak Object is locked skipped
C:\Windows\System32\LogFiles\Scm\SCM.EVM Object is locked skipped
C:\Windows\System32\LogFiles\WUDF\WUDFTrace.etl Object is locked skipped
C:\Windows\System32\Msdtc\KtmRmTm.blf Object is locked skipped
C:\Windows\System32\Msdtc\KtmRmTmContainer00000000000000000001 Object is locked skipped
C:\Windows\System32\Msdtc\KtmRmTmContainer00000000000000000002 Object is locked skipped
C:\Windows\System32\spool\SpoolerETW.etl Object is locked skipped
C:\Windows\System32\wbem\Logs\WMITracing.log Object is locked skipped
C:\Windows\System32\wbem\Repository\INDEX.BTR Object is locked skipped
C:\Windows\System32\wbem\Repository\MAPPING1.MAP Object is locked skipped
C:\Windows\System32\wbem\Repository\MAPPING2.MAP Object is locked skipped
C:\Windows\System32\wbem\Repository\OBJECTS.DATA Object is locked skipped
C:\Windows\System32\WDI\LogFiles\WdiContextLog.etl.002 Object is locked skipped
C:\Windows\System32\wfp\wfpdiag.etl Object is locked skipped
C:\Windows\System32\winevt\Logs\Application.evtx Object is locked skipped
C:\Windows\System32\winevt\Logs\DFS Replication.evtx Object is locked skipped
C:\Windows\System32\winevt\Logs\HardwareEvents.evtx Object is locked skipped
C:\Windows\System32\winevt\Logs\Internet Explorer.evtx Object is locked skipped
C:\Windows\System32\winevt\Logs\Key Management Service.evtx Object is locked skipped
C:\Windows\System32\winevt\Logs\Media Center.evtx Object is locked skipped
C:\Windows\System32\winevt\Logs\Microsoft-Windows-Bits-Client%4Operational.evtx Object is locked skipped
C:\Windows\System32\winevt\Logs\Microsoft-Windows-CodeIntegrity%4Operational.evtx Object is locked skipped
C:\Windows\System32\winevt\Logs\Microsoft-Windows-Diagnosis-DPS%4Operational.evtx Object is locked skipped
C:\Windows\System32\winevt\Logs\Microsoft-Windows-Diagnostics-Performance%4Operational.evtx Object is locked skipped
C:\Windows\System32\winevt\Logs\Microsoft-Windows-DriverFrameworks-UserMode%4Operational.evtx Object is locked skipped
C:\Windows\System32\winevt\Logs\Microsoft-Windows-GroupPolicy%4Operational.evtx Object is locked skipped
C:\Windows\System32\winevt\Logs\Microsoft-Windows-International%4Operational.evtx Object is locked skipped
C:\Windows\System32\winevt\Logs\Microsoft-Windows-Kernel-WHEA.evtx Object is locked skipped
C:\Windows\System32\winevt\Logs\Microsoft-Windows-LanguagePackSetup%4Operational.evtx Object is locked skipped
C:\Windows\System32\winevt\Logs\Microsoft-Windows-NetworkAccessProtection%4Operational.evtx Object is locked skipped
C:\Windows\System32\winevt\Logs\Microsoft-Windows-Program-Compatibility-Assistant%4Operational.evtx Object is locked skipped
C:\Windows\System32\winevt\Logs\Microsoft-Windows-ReadyBoost%4Operational.evtx Object is locked skipped
C:\Windows\System32\winevt\Logs\Microsoft-Windows-ReliabilityAnalysisComponent%4Metrics.evtx Object is locked skipped
C:\Windows\System32\winevt\Logs\Microsoft-Windows-ReliabilityAnalysisComponent%4Operational.evtx Object is locked skipped
C:\Windows\System32\winevt\Logs\Microsoft-Windows-Resource-Exhaustion-Detector%4Operational.evtx Object is locked skipped
C:\Windows\System32\winevt\Logs\Microsoft-Windows-Resource-Exhaustion-Resolver%4Operational.evtx Object is locked skipped
C:\Windows\System32\winevt\Logs\Microsoft-Windows-Resource-Leak-Diagnostic%4Operational.evtx Object is locked skipped
C:\Windows\System32\winevt\Logs\Microsoft-Windows-RestartManager%4Operational.evtx Object is locked skipped
C:\Windows\System32\winevt\Logs\Microsoft-Windows-TaskScheduler%4Operational.evtx Object is locked skipped
C:\Windows\System32\winevt\Logs\Microsoft-Windows-UAC-FileVirtualization%4Operational.evtx Object is locked skipped
C:\Windows\System32\winevt\Logs\Microsoft-Windows-WindowsUpdateClient%4Operational.evtx Object is locked skipped
C:\Windows\System32\winevt\Logs\Microsoft-Windows-WLAN-AutoConfig%4Operational.evtx Object is locked skipped
C:\Windows\System32\winevt\Logs\ODiag.evtx Object is locked skipped
C:\Windows\System32\winevt\Logs\OSession.evtx Object is locked skipped
C:\Windows\System32\winevt\Logs\Security.evtx Object is locked skipped
C:\Windows\System32\winevt\Logs\System.evtx Object is locked skipped
C:\Windows\Tasks\SCHEDLGU.TXT Object is locked skipped
C:\Windows\Temp\JET7280.tmp Object is locked skipped
C:\Windows\Temp\JET72CE.tmp Object is locked skipped
C:\Windows\WindowsUpdate.log Object is locked skipped
D:\System Volume Information\MountPointManagerRemoteDatabase Object is locked skipped
F:\FOUND.000\FILE0189.CHK/My Documents/Outlook/Personal Folders - X-Current Files (Aug 89-Jul 01), 010702.pst/Personal Folders/X-Current Files (Aug 89-Jul 00; Dec 00 - Present)/Accounts/NVRA/25 Jun 2000 23:38 from Sharon Lambert:Re: Voice Recognition Tech.html Infected: Email-Worm.VBS.KakWorm skipped
F:\FOUND.000\FILE0189.CHK/My Documents/Outlook/Personal Folders - X-Current Files (Aug 89-Jul 01), 010702.pst/Personal Folders/X-Current Files (Aug 89-Jul 00; Dec 00 - Present)/Accounts/NVRA/28 Jun 2000 21:33 from Sharon Lambert:Re: Voice Recognition Tech.html Infected: Email-Worm.VBS.KakWorm skipped
F:\FOUND.000\FILE0189.CHK/My Documents/Outlook/Personal Folders - X-Current Files (Aug 89-Jul 01), 010702.pst Infected: Email-Worm.VBS.KakWorm skipped
F:\FOUND.000\FILE0189.CHK/My Documents/Outlook/outlook.pst/Personal Folders/X-Current Files (Aug 89-Jul 00; Dec 00 - Present)/Accounts/NVRA/28 Jun 2000 21:33 from Sharon Lambert:Re: Voice Recognition Tech.html Infected: Email-Worm.VBS.KakWorm skipped
F:\FOUND.000\FILE0189.CHK/My Documents/Outlook/outlook.pst/Personal Folders/X-Current Files (Aug 89-Jul 00; Dec 00 - Present)/Accounts/NVRA/25 Jun 2000 23:38 from Sharon Lambert:Re: Voice Recognition Tech.html Infected: Email-Worm.VBS.KakWorm skipped
F:\FOUND.000\FILE0189.CHK/My Documents/Outlook/outlook.pst Infected: Email-Worm.VBS.KakWorm skipped
F:\FOUND.000\FILE0189.CHK ZIP: infected - 6 skipped
F:\FOUND.000\FILE0818.CHK/Personal Folders (Aug 89-Jul 01)/X-Current Files (Aug 89-Jul 00; Dec 00 - Present)/Accounts/NVRA/25 Jun 2000 23:38 from Sharon Lambert:Re: Voice Recognition Tech.html Infected: Email-Worm.VBS.KakWorm skipped
F:\FOUND.000\FILE0818.CHK/Personal Folders (Aug 89-Jul 01)/X-Current Files (Aug 89-Jul 00; Dec 00 - Present)/Accounts/NVRA/28 Jun 2000 21:33 from Sharon Lambert:Re: Voice Recognition Tech.html Infected: Email-Worm.VBS.KakWorm skipped
F:\FOUND.000\FILE0818.CHK MailMSMaill: infected - 2 skipped
F:\FOUND.000\FILE0825.CHK/Personal Folders/X-Current Files (Aug 89-Jul 00; Dec 00 - Present)/Accounts/NVRA/28 Jun 2000 21:33 from Sharon Lambert:Re: Voice Recognition Tech.html Infected: Email-Worm.VBS.KakWorm skipped
F:\FOUND.000\FILE0825.CHK/Personal Folders/X-Current Files (Aug 89-Jul 00; Dec 00 - Present)/Accounts/NVRA/25 Jun 2000 23:38 from Sharon Lambert:Re: Voice Recognition Tech.html Infected: Email-Worm.VBS.KakWorm skipped
F:\FOUND.000\FILE0825.CHK MailMSMaill: infected - 2 skipped
F:\My Documents, Desktop (070429)\My Documents\Backup of Desktop.zip/My Documents/Outlook/Personal Folders - X-Current Files (Aug 89-Jul 01), 010702.pst/Personal Folders/X-Current Files (Aug 89-Jul 00; Dec 00 - Present)/Accounts/NVRA/25 Jun 2000 23:38 from Sharon Lambert:Re: Voice Recognition Tech.html Infected: Email-Worm.VBS.KakWorm skipped
F:\My Documents, Desktop (070429)\My Documents\Backup of Desktop.zip/My Documents/Outlook/Personal Folders - X-Current Files (Aug 89-Jul 01), 010702.pst/Personal Folders/X-Current Files (Aug 89-Jul 00; Dec 00 - Present)/Accounts/NVRA/28 Jun 2000 21:33 from Sharon Lambert:Re: Voice Recognition Tech.html Infected: Email-Worm.VBS.KakWorm skipped
F:\My Documents, Desktop (070429)\My Documents\Backup of Desktop.zip/My Documents/Outlook/Personal Folders - X-Current Files (Aug 89-Jul 01), 010702.pst Infected: Email-Worm.VBS.KakWorm skipped
F:\My Documents, Desktop (070429)\My Documents\Backup of Desktop.zip/My Documents/Outlook/outlook.pst/Personal Folders/X-Current Files (Aug 89-Jul 00; Dec 00 - Present)/Accounts/NVRA/28 Jun 2000 21:33 from Sharon Lambert:Re: Voice Recognition Tech.html Infected: Email-Worm.VBS.KakWorm skipped
F:\My Documents, Desktop (070429)\My Documents\Backup of Desktop.zip/My Documents/Outlook/outlook.pst/Personal Folders/X-Current Files (Aug 89-Jul 00; Dec 00 - Present)/Accounts/NVRA/25 Jun 2000 23:38 from Sharon Lambert:Re: Voice Recognition Tech.html Infected: Email-Worm.VBS.KakWorm skipped
F:\My Documents, Desktop (070429)\My Documents\Backup of Desktop.zip/My Documents/Outlook/outlook.pst Infected: Email-Worm.VBS.KakWorm skipped
F:\My Documents, Desktop (070429)\My Documents\Backup of Desktop.zip ZIP: infected - 6 skipped
F:\My Documents, MJW's 600m (070429)\Outlook\Personal Folders - X-Current Files (Aug 89-Jul 01), 010702.pst/Personal Folders (Aug 89-Jul 01)/X-Current Files (Aug 89-Jul 00; Dec 00 - Present)/Accounts/NVRA/25 Jun 2000 23:38 from Sharon Lambert:Re: Voice Recognition Tech.html Infected: Email-Worm.VBS.KakWorm skipped
F:\My Documents, MJW's 600m (070429)\Outlook\Personal Folders - X-Current Files (Aug 89-Jul 01), 010702.pst/Personal Folders (Aug 89-Jul 01)/X-Current Files (Aug 89-Jul 00; Dec 00 - Present)/Accounts/NVRA/28 Jun 2000 21:33 from Sharon Lambert:Re: Voice Recognition Tech.html Infected: Email-Worm.VBS.KakWorm skipped
F:\My Documents, MJW's 600m (070429)\Outlook\Personal Folders - X-Current Files (Aug 89-Jul 01), 010702.pst MailMSMaill: infected - 2 skipped
F:\My Documents, MJW's 600m (071105)\To be Copied to Desktop\Outlook\Personal Folders - X-Current Files (Aug 89-Jul 01), 010702.pst/Personal Folders (Aug 89-Jul 01)/X-Current Files (Aug 89-Jul 00; Dec 00 - Present)/Accounts/NVRA/25 Jun 2000 23:38 from Sharon Lambert:Re: Voice Recognition Tech.html Infected: Email-Worm.VBS.KakWorm skipped
F:\My Documents, MJW's 600m (071105)\To be Copied to Desktop\Outlook\Personal Folders - X-Current Files (Aug 89-Jul 01), 010702.pst/Personal Folders (Aug 89-Jul 01)/X-Current Files (Aug 89-Jul 00; Dec 00 - Present)/Accounts/NVRA/28 Jun 2000 21:33 from Sharon Lambert:Re: Voice Recognition Tech.html Infected: Email-Worm.VBS.KakWorm skipped
F:\My Documents, MJW's 600m (071105)\To be Copied to Desktop\Outlook\Personal Folders - X-Current Files (Aug 89-Jul 01), 010702.pst MailMSMaill: infected - 2 skipped
F:\2bctd (080222)\To be Copied to Desktop\Outlook\Personal Folders - X-Current Files (Aug 89-Jul 01), 010702.pst/Personal Folders (Aug 89-Jul 01)/X-Current Files (Aug 89-Jul 00; Dec 00 - Present)/Accounts/NVRA/25 Jun 2000 23:38 from Sharon Lambert:Re: Voice Recognition Tech.html Infected: Email-Worm.VBS.KakWorm skipped
F:\2bctd (080222)\To be Copied to Desktop\Outlook\Personal Folders - X-Current Files (Aug 89-Jul 01), 010702.pst/Personal Folders (Aug 89-Jul 01)/X-Current Files (Aug 89-Jul 00; Dec 00 - Present)/Accounts/NVRA/28 Jun 2000 21:33 from Sharon Lambert:Re: Voice Recognition Tech.html Infected: Email-Worm.VBS.KakWorm skipped
F:\2bctd (080222)\To be Copied to Desktop\Outlook\Personal Folders - X-Current Files (Aug 89-Jul 01), 010702.pst MailMSMaill: infected - 2 skipped
F:\$RECYCLE.BIN\$RXOIOZW.exe/stream/data0008 Infected: not-a-virus:AdWare.Win32.Comet.az skipped
F:\$RECYCLE.BIN\$RXOIOZW.exe/stream Infected: not-a-virus:AdWare.Win32.Comet.az skipped
F:\$RECYCLE.BIN\$RXOIOZW.exe NSIS: infected - 2 skipped
F:\$RECYCLE.BIN\$RWFU77T.exe/stream/data0008 Infected: not-a-virus:AdWare.Win32.Comet.az skipped
F:\$RECYCLE.BIN\$RWFU77T.exe/stream Infected: not-a-virus:AdWare.Win32.Comet.az skipped
F:\$RECYCLE.BIN\$RWFU77T.exe NSIS: infected - 2 skipped
F:\$RECYCLE.BIN\$RFJ85B7.exe/stream/data0008 Infected: not-a-virus:AdWare.Win32.Comet.az skipped
F:\$RECYCLE.BIN\$RFJ85B7.exe/stream Infected: not-a-virus:AdWare.Win32.Comet.az skipped
F:\$RECYCLE.BIN\$RFJ85B7.exe NSIS: infected - 2 skipped
F:\$RECYCLE.BIN\$RDG854N.exe/data0003/data0002 Infected: not-a-virus:AdWare.Win32.BargainBuddy.l skipped
F:\$RECYCLE.BIN\$RDG854N.exe/data0003/data0003 Infected: not-a-virus:AdWare.Win32.BargainBuddy.a skipped
F:\$RECYCLE.BIN\$RDG854N.exe/data0003 Infected: not-a-virus:AdWare.Win32.BargainBuddy.a skipped
F:\$RECYCLE.BIN\$RDG854N.exe NSIS: infected - 3 skipped
F:\My Documents, Acer (080614)\To be Copied to Desktop\Outlook\Personal Folders - X-Current Files (Aug 89-Jul 01), 010702.pst/Personal Folders (Aug 89-Jul 01)/X-Current Files (Aug 89-Jul 00; Dec 00 - Present)/Accounts/NVRA/25 Jun 2000 23:38 from Sharon Lambert:Re: Voice Recognition Tech.html Infected: Email-Worm.VBS.KakWorm skipped
F:\My Documents, Acer (080614)\To be Copied to Desktop\Outlook\Personal Folders - X-Current Files (Aug 89-Jul 01), 010702.pst/Personal Folders (Aug 89-Jul 01)/X-Current Files (Aug 89-Jul 00; Dec 00 - Present)/Accounts/NVRA/28 Jun 2000 21:33 from Sharon Lambert:Re: Voice Recognition Tech.html Infected: Email-Worm.VBS.KakWorm skipped
F:\My Documents, Acer (080614)\To be Copied to Desktop\Outlook\Personal Folders - X-Current Files (Aug 89-Jul 01), 010702.pst MailMSMaill: infected - 2 skipped
Scan process completed.

Blade81
2008-06-22, 19:11
Hi

Delete those mail messages listed in Kaspersky log. Empty recycler bin too. Otherwise looks ok :)

MJWolter
2008-06-23, 02:58
Thank you, Blade81.

I just want to check, before I begin noodling around and possibly activating the lousy worm: How do I delete what appears to be a single e-mail or string of e-mails to/from the same person? Must I load each .pst file into Outlook, look for the e-mail, and delete it; or is there a way to zero in on, and delete, the e-mail as it sits dormant in the archive?

MJWolter

Blade81
2008-06-23, 09:57
How do I delete what appears to be a single e-mail or string of e-mails to/from the same person? Must I load each .pst file into Outlook, look for the e-mail, and delete it; or is there a way to zero in on, and delete, the e-mail as it sits dormant in the archive?Easiest way is probably load .pst files separately into Outlook and do deleting there (as you described) :)

Blade81
2008-06-29, 13:47
Since this issue appears to be resolved ... this Topic has been closed. Glad I could help. :)

Note:If it has been five days or more since your last post, and the helper assisting you posted a response to that post to which you did not reply, your topic will not be reopened. At that point, if you still require help, please start a new topic and include a fresh HijackThis log and a link to your previous thread.

If it has been less than five days since your last response and you need the thread re-opened, please send me or MOD a private message (pm). A valid, working link to the closed topic is required.