I noticed recently that my machine was slowing down. In the task manager I noticed a new process flec006.exe and when it was not there, wintems.exe
I was unable to end wintems.exe (Error message of "The operation could not be completed. Access is denied."), but flec006 has ceased.
Read through a lot of these threads, and tried a few things-
Downloaded Spybot - installed but wouldn't run "not valid win32 app"
D'loaded Hijackthis - installed but wouldn't run "not valid win32 app"
Tried to run machine in safe mode - get through screens and then blue screen
D'loaded Malwarebytes - installed and ran but would NOT save log, it would however remove (or at least it appeared to) some of the listed items, only if I stopped the scan part way through. Removed the DRIVERS/down folder and a lot of random numbers.exe
Kapersky online scan worked and thats all I have- I hope someone can help? Thanks in advance.
KASPERSKY ONLINE SCANNER REPORT
Thursday, April 10, 2008 9:37:26 AM
Operating System: Microsoft Windows XP Home Edition, Service Pack 2 (Build 2600)
Kaspersky Online Scanner version: 5.0.98.0
Kaspersky Anti-Virus database last update: 9/04/2008
Kaspersky Anti-Virus database records: 692312
-------------------------------------------------------------------------------
Scan Settings:
Scan using the following antivirus database: extended
Scan Archives: true
Scan Mail Bases: true
Scan Target - My Computer:
A:\
C:\
D:\
E:\
Scan Statistics:
Total number of scanned objects: 92433
Number of viruses found: 10
Number of infected objects: 109
Number of suspicious objects: 0
Duration of the scan process: 10:21:26
Infected Object Name / Virus Name / Last Action
C:\Documents and Settings\All Users\Application Data\Microsoft\Network\Downloader\qmgr0.dat Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Network\Downloader\qmgr1.dat Object is locked skipped
C:\Documents and Settings\browser\Application Data\m\data.oct Infected: Trojan-Downloader.Win32.Bagle.mw skipped
C:\Documents and Settings\browser\Cookies\INDEX.DAT Object is locked skipped
C:\Documents and Settings\browser\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat Object is locked skipped
C:\Documents and Settings\browser\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped
C:\Documents and Settings\browser\Local Settings\History\History.IE5\INDEX.DAT Object is locked skipped
C:\Documents and Settings\browser\Local Settings\Temp\~DF1B6C.tmp Object is locked skipped
C:\Documents and Settings\browser\Local Settings\Temp\~DF1B78.tmp Object is locked skipped
C:\Documents and Settings\browser\Local Settings\Temporary Internet Files\AntiPhishing\B3BB5BBA-E7D5-40AB-A041-A5B1C0B26C8F.dat Object is locked skipped
C:\Documents and Settings\browser\Local Settings\Temporary Internet Files\Content.IE5\index.dat Object is locked skipped
C:\Documents and Settings\browser\Local Settings\Temporary Internet Files\Content.IE5\ZIGZ5WEV\b64[1].jpg Infected: Email-Worm.Win32.Bagle.of skipped
C:\Documents and Settings\browser\ntuser.dat Object is locked skipped
C:\Documents and Settings\browser\ntuser.dat.LOG Object is locked skipped
C:\Documents and Settings\LocalService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat Object is locked skipped
C:\Documents and Settings\LocalService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped
C:\Documents and Settings\LocalService\NTUSER.DAT Object is locked skipped
C:\Documents and Settings\LocalService\ntuser.dat.LOG Object is locked skipped
C:\Documents and Settings\NetworkService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat Object is locked skipped
C:\Documents and Settings\NetworkService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped
C:\Documents and Settings\NetworkService\NTUSER.DAT Object is locked skipped
C:\Documents and Settings\NetworkService\ntuser.dat.LOG Object is locked skipped
C:\Program Files\InstallShield Installation Information\{0DEA94ED-915A-4834-A87E-388D012C8E02}\setup.ilg Object is locked skipped
C:\Program Files\PestPatrol\Quarantine\20040905205623000.zip/WINDOWS/SYSTEM32/Com/oboe32/systray.exe Infected: Backdoor.Win32.Iroffer.1213.a skipped
C:\Program Files\PestPatrol\Quarantine\20040905205623000.zip ZIP: infected - 1 skipped
C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP1432\A0096618.exe Infected: Trojan-Downloader.Win32.Bagle.lb skipped
C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP1432\A0096619.sys Infected: Trojan-Downloader.Win32.Bagle.mm skipped
C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP1432\A0097618.sys Infected: Trojan-Downloader.Win32.Bagle.ky skipped
C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP1432\A0097637.sys Infected: Trojan-Downloader.Win32.Bagle.ky skipped
C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP1433\A0097641.exe Infected: Email-Worm.Win32.Bagle.of skipped
C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP1433\A0097642.exe Infected: Email-Worm.Win32.Bagle.of skipped
C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP1433\A0097657.sys Infected: Trojan-Downloader.Win32.Bagle.ky skipped
C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP1433\A0097660.exe Infected: Email-Worm.Win32.Bagle.of skipped
C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP1433\A0097661.exe Infected: Email-Worm.Win32.Bagle.of skipped
C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP1434\A0097676.exe Infected: Email-Worm.Win32.Bagle.of skipped
C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP1434\A0097677.exe Infected: Email-Worm.Win32.Bagle.of skipped
C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP1434\A0098657.sys Infected: Trojan-Downloader.Win32.Bagle.ky skipped
C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP1434\A0098663.exe Infected: Email-Worm.Win32.Bagle.of skipped
C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP1434\A0098664.exe Infected: Email-Worm.Win32.Bagle.of skipped
C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP1436\A0098842.exe Infected: Email-Worm.Win32.Bagle.of skipped
C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP1436\A0098843.exe Infected: Email-Worm.Win32.Bagle.of skipped
C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP1436\A0099658.sys Infected: Trojan-Downloader.Win32.Bagle.ky skipped
C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP1438\A0100657.sys Infected: Trojan-Downloader.Win32.Bagle.ky skipped
C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP1438\A0100671.exe Infected: Email-Worm.Win32.Bagle.of skipped
C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP1438\A0100672.exe Infected: Email-Worm.Win32.Bagle.of skipped
C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP1440\A0100702.exe Infected: Email-Worm.Win32.Bagle.of skipped
C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP1440\A0100703.exe Infected: Email-Worm.Win32.Bagle.of skipped
C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP1441\A0100714.exe Infected: Email-Worm.Win32.Bagle.of skipped
C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP1441\A0100715.exe Infected: Email-Worm.Win32.Bagle.of skipped
C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP1441\A0100740.sys Infected: Trojan-Downloader.Win32.Bagle.ky skipped
C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP1441\A0100747.sys Infected: Trojan-Downloader.Win32.Bagle.ky skipped
C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP1441\A0100750.exe Infected: Email-Worm.Win32.Bagle.of skipped
C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP1441\A0100751.exe Infected: Email-Worm.Win32.Bagle.of skipped
C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP1442\A0100758.exe Infected: Email-Worm.Win32.Bagle.of skipped
C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP1442\A0100759.exe Infected: Email-Worm.Win32.Bagle.of skipped
C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP1443\A0100764.exe Infected: Email-Worm.Win32.Bagle.of skipped
C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP1443\A0100765.exe Infected: Email-Worm.Win32.Bagle.of skipped
C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP1444\A0100774.exe Infected: Email-Worm.Win32.Bagle.of skipped
C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP1444\A0100775.exe Infected: Email-Worm.Win32.Bagle.of skipped
C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP1445\A0100790.exe Infected: Email-Worm.Win32.Bagle.of skipped
C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP1445\A0100791.exe Infected: Email-Worm.Win32.Bagle.of skipped
C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP1446\A0100801.exe Infected: Email-Worm.Win32.Bagle.of skipped
C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP1446\A0100802.exe Infected: Email-Worm.Win32.Bagle.of skipped
C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP1447\A0100818.exe Infected: Email-Worm.Win32.Bagle.of skipped
C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP1447\A0100819.exe Infected: Email-Worm.Win32.Bagle.of skipped
C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP1448\A0100833.exe Infected: Email-Worm.Win32.Bagle.of skipped
C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP1448\A0100834.exe Infected: Email-Worm.Win32.Bagle.of skipped
C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP1450\A0100882.exe Infected: Email-Worm.Win32.Bagle.of skipped
C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP1450\A0100883.exe Infected: Email-Worm.Win32.Bagle.of skipped
C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP1453\A0100906.exe Infected: Email-Worm.Win32.Bagle.of skipped
C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP1453\A0100907.exe Infected: Email-Worm.Win32.Bagle.of skipped
C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP1454\A0100991.exe Infected: Email-Worm.Win32.Bagle.of skipped
C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP1454\A0100992.exe Infected: Email-Worm.Win32.Bagle.of skipped
C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP1454\A0100998.sys Infected: Trojan-Downloader.Win32.Bagle.ky skipped
C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP1455\A0101004.exe Infected: Email-Worm.Win32.Bagle.of skipped
C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP1455\A0101005.exe Infected: Email-Worm.Win32.Bagle.of skipped
C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP1455\A0101014.sys Infected: Trojan-Downloader.Win32.Bagle.ky skipped
C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP1456\A0101025.exe Infected: Email-Worm.Win32.Bagle.of skipped
C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP1456\A0101026.exe Infected: Email-Worm.Win32.Bagle.of skipped
C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP1457\A0101030.exe Infected: Email-Worm.Win32.Bagle.of skipped
C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP1457\A0101031.exe Infected: Email-Worm.Win32.Bagle.of skipped
C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP1458\A0101054.exe Infected: Email-Worm.Win32.Bagle.of skipped
C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP1458\A0101055.exe Infected: Email-Worm.Win32.Bagle.of skipped
C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP1459\A0101063.exe Infected: Email-Worm.Win32.Bagle.of skipped
C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP1459\A0101064.exe Infected: Email-Worm.Win32.Bagle.of skipped
C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP1459\A0102014.sys Infected: Trojan-Downloader.Win32.Bagle.ky skipped
C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP1459\A0102017.exe Infected: Email-Worm.Win32.Bagle.of skipped
C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP1459\A0102018.exe Infected: Email-Worm.Win32.Bagle.of skipped
C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP1459\A0102019.exe Infected: Email-Worm.Win32.Bagle.of skipped
C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP1461\A0102026.exe Infected: Email-Worm.Win32.Bagle.of skipped
C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP1461\A0102027.exe Infected: Email-Worm.Win32.Bagle.of skipped
C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP1461\A0102028.exe Infected: Email-Worm.Win32.Bagle.of skipped
C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP1461\A0102099.exe Infected: Trojan-Downloader.Win32.Bagle.lb skipped
C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP1462\A0102235.sys Infected: Trojan-Downloader.Win32.Bagle.ky skipped
C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP1462\A0102238.exe Infected: Email-Worm.Win32.Bagle.of skipped
C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP1463\A0102374.exe Infected: Email-Worm.Win32.Bagle.of skipped
C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP1463\A0102380.sys Infected: Trojan-Downloader.Win32.Bagle.ky skipped
C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP1463\A0102386.exe Infected: not-a-virus:Client-IRC.Win32.mIRC.62 skipped
C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP1463\A0102398.exe Infected: Email-Worm.Win32.Bagle.of skipped
C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP1464\A0102404.sys Infected: Trojan-Downloader.Win32.Bagle.ky skipped
C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP1464\A0102409.exe Infected: Email-Worm.Win32.Bagle.of skipped
C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP1464\A0102495.sys Infected: Trojan-Downloader.Win32.Bagle.ky skipped
C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP1464\A0102507.sys Infected: Trojan-Downloader.Win32.Bagle.ky skipped
C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP1465\A0102519.sys Infected: Trojan-Downloader.Win32.Bagle.ky skipped
C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP1465\A0102522.exe Infected: Email-Worm.Win32.Bagle.of skipped
C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP1466\A0104213.exe Infected: Trojan.Win32.Pakes.ciw skipped
C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP1466\A0104215.exe Infected: Email-Worm.Win32.Bagle.of skipped
C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP1466\A0104218.exe Infected: Email-Worm.Win32.Bagle.of skipped
C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP1466\A0104235.exe Infected: Trojan.Win32.Pakes.ciw skipped
C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP1466\A0104259.exe Infected: Trojan.Win32.Pakes.ciw skipped
C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP1466\A0104261.exe Infected: Email-Worm.Win32.Bagle.of skipped
C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP1466\A0104264.exe Infected: Email-Worm.Win32.Bagle.of skipped
C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP1466\A0104281.exe Infected: Trojan.Win32.Pakes.ciw skipped
C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP1466\A0104285.exe Infected: Email-Worm.Win32.Bagle.of skipped
C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP1466\A0104320.exe Infected: Email-Worm.Win32.Bagle.of skipped
C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP1466\A0104338.exe Infected: Trojan.Win32.Pakes.ciw skipped
C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP1466\A0104340.exe Infected: Email-Worm.Win32.Bagle.of skipped
C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP1466\A0104359.exe Infected: Email-Worm.Win32.Bagle.of skipped
C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP1466\A0104361.exe Infected: Email-Worm.Win32.Bagle.of skipped
C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP1466\A0104377.exe Infected: Trojan.Win32.Pakes.ciw skipped
C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP1466\A0104379.exe Infected: Trojan.Win32.Pakes.ciw skipped
C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP1466\A0104382.exe Infected: Email-Worm.Win32.Bagle.of skipped
C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP1466\A0104399.sys Infected: Trojan-Downloader.Win32.Bagle.ky skipped
C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP1466\A0104420.exe Infected: Trojan.Win32.Pakes.ciw skipped
C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP1466\A0104422.exe Infected: Email-Worm.Win32.Bagle.of skipped
C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP1466\A0104498.exe Infected: Email-Worm.Win32.Bagle.of skipped
C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP1466\change.log Object is locked skipped
C:\WINDOWS\$hf_mig$\KB890859\SP2QFE\ntoskrnl.exe Object is locked skipped
C:\WINDOWS\$hf_mig$\KB929338\SP2QFE\ntoskrnl.exe Object is locked skipped
C:\WINDOWS\$hf_mig$\KB931784\SP2QFE\ntoskrnl.exe Object is locked skipped
C:\WINDOWS\$NtServicePackUninstall$\ntoskrnl.exe Object is locked skipped
C:\WINDOWS\$NtUninstallKB890859$\ntoskrnl.exe Object is locked skipped
C:\WINDOWS\$NtUninstallKB929338$\ntoskrnl.exe Object is locked skipped
C:\WINDOWS\$NtUninstallKB931784$\ntoskrnl.exe Object is locked skipped
C:\WINDOWS\$NtUninstallQ811493$\ntoskrnl.exe Object is locked skipped
C:\WINDOWS\Debug\PASSWD.LOG Object is locked skipped
C:\WINDOWS\Driver Cache\I386\ntoskrnl.exe Object is locked skipped
C:\WINDOWS\SchedLgU.Txt Object is locked skipped
C:\WINDOWS\ServicePackFiles\i386\ntoskrnl.exe Object is locked skipped
C:\WINDOWS\Sti_Trace.log Object is locked skipped
C:\WINDOWS\SYSTEM32\1.exe Infected: Email-Worm.Win32.Bagle.of skipped
C:\WINDOWS\SYSTEM32\CatRoot2\edb.log Object is locked skipped
C:\WINDOWS\SYSTEM32\CatRoot2\tmp.edb Object is locked skipped
C:\WINDOWS\SYSTEM32\Com\oboe32\shell32.exe Infected: not-a-virus:Server-FTP.Win32.Serv-U.4002 skipped
C:\WINDOWS\SYSTEM32\CONFIG\AppEvent.Evt Object is locked skipped
C:\WINDOWS\SYSTEM32\CONFIG\DEFAULT Object is locked skipped
C:\WINDOWS\SYSTEM32\CONFIG\DEFAULT.LOG Object is locked skipped
C:\WINDOWS\SYSTEM32\CONFIG\Internet.evt Object is locked skipped
C:\WINDOWS\SYSTEM32\CONFIG\SAM Object is locked skipped
C:\WINDOWS\SYSTEM32\CONFIG\SAM.LOG Object is locked skipped
C:\WINDOWS\SYSTEM32\CONFIG\SecEvent.Evt Object is locked skipped
C:\WINDOWS\SYSTEM32\CONFIG\SECURITY Object is locked skipped
C:\WINDOWS\SYSTEM32\CONFIG\SECURITY.LOG Object is locked skipped
C:\WINDOWS\SYSTEM32\CONFIG\SOFTWARE Object is locked skipped
C:\WINDOWS\SYSTEM32\CONFIG\SOFTWARE.LOG Object is locked skipped
C:\WINDOWS\SYSTEM32\CONFIG\SysEvent.Evt Object is locked skipped
C:\WINDOWS\SYSTEM32\CONFIG\SYSTEM Object is locked skipped
C:\WINDOWS\SYSTEM32\CONFIG\SYSTEM.LOG Object is locked skipped
C:\WINDOWS\SYSTEM32\H323LOG.TXT Object is locked skipped
C:\WINDOWS\SYSTEM32\LogFiles\WUDF\WUDFTrace.etl Object is locked skipped
C:\WINDOWS\SYSTEM32\mdelk.exe Infected: Email-Worm.Win32.Bagle.of skipped
C:\WINDOWS\SYSTEM32\WBEM\Repository\FS\INDEX.BTR Object is locked skipped
C:\WINDOWS\SYSTEM32\WBEM\Repository\FS\INDEX.MAP Object is locked skipped
C:\WINDOWS\SYSTEM32\WBEM\Repository\FS\MAPPING.VER Object is locked skipped
C:\WINDOWS\SYSTEM32\WBEM\Repository\FS\MAPPING1.MAP Object is locked skipped
C:\WINDOWS\SYSTEM32\WBEM\Repository\FS\MAPPING2.MAP Object is locked skipped
C:\WINDOWS\SYSTEM32\WBEM\Repository\FS\OBJECTS.DATA Object is locked skipped
C:\WINDOWS\SYSTEM32\WBEM\Repository\FS\OBJECTS.MAP Object is locked skipped
C:\WINDOWS\SYSTEM32\wi1.exe Infected: Trojan-Proxy.Win32.Mitglieder.gen skipped
C:\WINDOWS\WIADEBUG.LOG Object is locked skipped
C:\WINDOWS\WIASERVC.LOG Object is locked skipped
Scan process completed.
I was unable to end wintems.exe (Error message of "The operation could not be completed. Access is denied."), but flec006 has ceased.
Read through a lot of these threads, and tried a few things-
Downloaded Spybot - installed but wouldn't run "not valid win32 app"
D'loaded Hijackthis - installed but wouldn't run "not valid win32 app"
Tried to run machine in safe mode - get through screens and then blue screen
D'loaded Malwarebytes - installed and ran but would NOT save log, it would however remove (or at least it appeared to) some of the listed items, only if I stopped the scan part way through. Removed the DRIVERS/down folder and a lot of random numbers.exe
Kapersky online scan worked and thats all I have- I hope someone can help? Thanks in advance.
KASPERSKY ONLINE SCANNER REPORT
Thursday, April 10, 2008 9:37:26 AM
Operating System: Microsoft Windows XP Home Edition, Service Pack 2 (Build 2600)
Kaspersky Online Scanner version: 5.0.98.0
Kaspersky Anti-Virus database last update: 9/04/2008
Kaspersky Anti-Virus database records: 692312
-------------------------------------------------------------------------------
Scan Settings:
Scan using the following antivirus database: extended
Scan Archives: true
Scan Mail Bases: true
Scan Target - My Computer:
A:\
C:\
D:\
E:\
Scan Statistics:
Total number of scanned objects: 92433
Number of viruses found: 10
Number of infected objects: 109
Number of suspicious objects: 0
Duration of the scan process: 10:21:26
Infected Object Name / Virus Name / Last Action
C:\Documents and Settings\All Users\Application Data\Microsoft\Network\Downloader\qmgr0.dat Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Network\Downloader\qmgr1.dat Object is locked skipped
C:\Documents and Settings\browser\Application Data\m\data.oct Infected: Trojan-Downloader.Win32.Bagle.mw skipped
C:\Documents and Settings\browser\Cookies\INDEX.DAT Object is locked skipped
C:\Documents and Settings\browser\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat Object is locked skipped
C:\Documents and Settings\browser\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped
C:\Documents and Settings\browser\Local Settings\History\History.IE5\INDEX.DAT Object is locked skipped
C:\Documents and Settings\browser\Local Settings\Temp\~DF1B6C.tmp Object is locked skipped
C:\Documents and Settings\browser\Local Settings\Temp\~DF1B78.tmp Object is locked skipped
C:\Documents and Settings\browser\Local Settings\Temporary Internet Files\AntiPhishing\B3BB5BBA-E7D5-40AB-A041-A5B1C0B26C8F.dat Object is locked skipped
C:\Documents and Settings\browser\Local Settings\Temporary Internet Files\Content.IE5\index.dat Object is locked skipped
C:\Documents and Settings\browser\Local Settings\Temporary Internet Files\Content.IE5\ZIGZ5WEV\b64[1].jpg Infected: Email-Worm.Win32.Bagle.of skipped
C:\Documents and Settings\browser\ntuser.dat Object is locked skipped
C:\Documents and Settings\browser\ntuser.dat.LOG Object is locked skipped
C:\Documents and Settings\LocalService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat Object is locked skipped
C:\Documents and Settings\LocalService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped
C:\Documents and Settings\LocalService\NTUSER.DAT Object is locked skipped
C:\Documents and Settings\LocalService\ntuser.dat.LOG Object is locked skipped
C:\Documents and Settings\NetworkService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat Object is locked skipped
C:\Documents and Settings\NetworkService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped
C:\Documents and Settings\NetworkService\NTUSER.DAT Object is locked skipped
C:\Documents and Settings\NetworkService\ntuser.dat.LOG Object is locked skipped
C:\Program Files\InstallShield Installation Information\{0DEA94ED-915A-4834-A87E-388D012C8E02}\setup.ilg Object is locked skipped
C:\Program Files\PestPatrol\Quarantine\20040905205623000.zip/WINDOWS/SYSTEM32/Com/oboe32/systray.exe Infected: Backdoor.Win32.Iroffer.1213.a skipped
C:\Program Files\PestPatrol\Quarantine\20040905205623000.zip ZIP: infected - 1 skipped
C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP1432\A0096618.exe Infected: Trojan-Downloader.Win32.Bagle.lb skipped
C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP1432\A0096619.sys Infected: Trojan-Downloader.Win32.Bagle.mm skipped
C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP1432\A0097618.sys Infected: Trojan-Downloader.Win32.Bagle.ky skipped
C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP1432\A0097637.sys Infected: Trojan-Downloader.Win32.Bagle.ky skipped
C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP1433\A0097641.exe Infected: Email-Worm.Win32.Bagle.of skipped
C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP1433\A0097642.exe Infected: Email-Worm.Win32.Bagle.of skipped
C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP1433\A0097657.sys Infected: Trojan-Downloader.Win32.Bagle.ky skipped
C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP1433\A0097660.exe Infected: Email-Worm.Win32.Bagle.of skipped
C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP1433\A0097661.exe Infected: Email-Worm.Win32.Bagle.of skipped
C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP1434\A0097676.exe Infected: Email-Worm.Win32.Bagle.of skipped
C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP1434\A0097677.exe Infected: Email-Worm.Win32.Bagle.of skipped
C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP1434\A0098657.sys Infected: Trojan-Downloader.Win32.Bagle.ky skipped
C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP1434\A0098663.exe Infected: Email-Worm.Win32.Bagle.of skipped
C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP1434\A0098664.exe Infected: Email-Worm.Win32.Bagle.of skipped
C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP1436\A0098842.exe Infected: Email-Worm.Win32.Bagle.of skipped
C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP1436\A0098843.exe Infected: Email-Worm.Win32.Bagle.of skipped
C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP1436\A0099658.sys Infected: Trojan-Downloader.Win32.Bagle.ky skipped
C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP1438\A0100657.sys Infected: Trojan-Downloader.Win32.Bagle.ky skipped
C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP1438\A0100671.exe Infected: Email-Worm.Win32.Bagle.of skipped
C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP1438\A0100672.exe Infected: Email-Worm.Win32.Bagle.of skipped
C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP1440\A0100702.exe Infected: Email-Worm.Win32.Bagle.of skipped
C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP1440\A0100703.exe Infected: Email-Worm.Win32.Bagle.of skipped
C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP1441\A0100714.exe Infected: Email-Worm.Win32.Bagle.of skipped
C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP1441\A0100715.exe Infected: Email-Worm.Win32.Bagle.of skipped
C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP1441\A0100740.sys Infected: Trojan-Downloader.Win32.Bagle.ky skipped
C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP1441\A0100747.sys Infected: Trojan-Downloader.Win32.Bagle.ky skipped
C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP1441\A0100750.exe Infected: Email-Worm.Win32.Bagle.of skipped
C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP1441\A0100751.exe Infected: Email-Worm.Win32.Bagle.of skipped
C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP1442\A0100758.exe Infected: Email-Worm.Win32.Bagle.of skipped
C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP1442\A0100759.exe Infected: Email-Worm.Win32.Bagle.of skipped
C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP1443\A0100764.exe Infected: Email-Worm.Win32.Bagle.of skipped
C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP1443\A0100765.exe Infected: Email-Worm.Win32.Bagle.of skipped
C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP1444\A0100774.exe Infected: Email-Worm.Win32.Bagle.of skipped
C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP1444\A0100775.exe Infected: Email-Worm.Win32.Bagle.of skipped
C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP1445\A0100790.exe Infected: Email-Worm.Win32.Bagle.of skipped
C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP1445\A0100791.exe Infected: Email-Worm.Win32.Bagle.of skipped
C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP1446\A0100801.exe Infected: Email-Worm.Win32.Bagle.of skipped
C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP1446\A0100802.exe Infected: Email-Worm.Win32.Bagle.of skipped
C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP1447\A0100818.exe Infected: Email-Worm.Win32.Bagle.of skipped
C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP1447\A0100819.exe Infected: Email-Worm.Win32.Bagle.of skipped
C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP1448\A0100833.exe Infected: Email-Worm.Win32.Bagle.of skipped
C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP1448\A0100834.exe Infected: Email-Worm.Win32.Bagle.of skipped
C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP1450\A0100882.exe Infected: Email-Worm.Win32.Bagle.of skipped
C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP1450\A0100883.exe Infected: Email-Worm.Win32.Bagle.of skipped
C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP1453\A0100906.exe Infected: Email-Worm.Win32.Bagle.of skipped
C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP1453\A0100907.exe Infected: Email-Worm.Win32.Bagle.of skipped
C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP1454\A0100991.exe Infected: Email-Worm.Win32.Bagle.of skipped
C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP1454\A0100992.exe Infected: Email-Worm.Win32.Bagle.of skipped
C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP1454\A0100998.sys Infected: Trojan-Downloader.Win32.Bagle.ky skipped
C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP1455\A0101004.exe Infected: Email-Worm.Win32.Bagle.of skipped
C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP1455\A0101005.exe Infected: Email-Worm.Win32.Bagle.of skipped
C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP1455\A0101014.sys Infected: Trojan-Downloader.Win32.Bagle.ky skipped
C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP1456\A0101025.exe Infected: Email-Worm.Win32.Bagle.of skipped
C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP1456\A0101026.exe Infected: Email-Worm.Win32.Bagle.of skipped
C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP1457\A0101030.exe Infected: Email-Worm.Win32.Bagle.of skipped
C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP1457\A0101031.exe Infected: Email-Worm.Win32.Bagle.of skipped
C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP1458\A0101054.exe Infected: Email-Worm.Win32.Bagle.of skipped
C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP1458\A0101055.exe Infected: Email-Worm.Win32.Bagle.of skipped
C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP1459\A0101063.exe Infected: Email-Worm.Win32.Bagle.of skipped
C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP1459\A0101064.exe Infected: Email-Worm.Win32.Bagle.of skipped
C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP1459\A0102014.sys Infected: Trojan-Downloader.Win32.Bagle.ky skipped
C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP1459\A0102017.exe Infected: Email-Worm.Win32.Bagle.of skipped
C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP1459\A0102018.exe Infected: Email-Worm.Win32.Bagle.of skipped
C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP1459\A0102019.exe Infected: Email-Worm.Win32.Bagle.of skipped
C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP1461\A0102026.exe Infected: Email-Worm.Win32.Bagle.of skipped
C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP1461\A0102027.exe Infected: Email-Worm.Win32.Bagle.of skipped
C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP1461\A0102028.exe Infected: Email-Worm.Win32.Bagle.of skipped
C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP1461\A0102099.exe Infected: Trojan-Downloader.Win32.Bagle.lb skipped
C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP1462\A0102235.sys Infected: Trojan-Downloader.Win32.Bagle.ky skipped
C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP1462\A0102238.exe Infected: Email-Worm.Win32.Bagle.of skipped
C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP1463\A0102374.exe Infected: Email-Worm.Win32.Bagle.of skipped
C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP1463\A0102380.sys Infected: Trojan-Downloader.Win32.Bagle.ky skipped
C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP1463\A0102386.exe Infected: not-a-virus:Client-IRC.Win32.mIRC.62 skipped
C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP1463\A0102398.exe Infected: Email-Worm.Win32.Bagle.of skipped
C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP1464\A0102404.sys Infected: Trojan-Downloader.Win32.Bagle.ky skipped
C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP1464\A0102409.exe Infected: Email-Worm.Win32.Bagle.of skipped
C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP1464\A0102495.sys Infected: Trojan-Downloader.Win32.Bagle.ky skipped
C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP1464\A0102507.sys Infected: Trojan-Downloader.Win32.Bagle.ky skipped
C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP1465\A0102519.sys Infected: Trojan-Downloader.Win32.Bagle.ky skipped
C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP1465\A0102522.exe Infected: Email-Worm.Win32.Bagle.of skipped
C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP1466\A0104213.exe Infected: Trojan.Win32.Pakes.ciw skipped
C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP1466\A0104215.exe Infected: Email-Worm.Win32.Bagle.of skipped
C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP1466\A0104218.exe Infected: Email-Worm.Win32.Bagle.of skipped
C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP1466\A0104235.exe Infected: Trojan.Win32.Pakes.ciw skipped
C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP1466\A0104259.exe Infected: Trojan.Win32.Pakes.ciw skipped
C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP1466\A0104261.exe Infected: Email-Worm.Win32.Bagle.of skipped
C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP1466\A0104264.exe Infected: Email-Worm.Win32.Bagle.of skipped
C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP1466\A0104281.exe Infected: Trojan.Win32.Pakes.ciw skipped
C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP1466\A0104285.exe Infected: Email-Worm.Win32.Bagle.of skipped
C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP1466\A0104320.exe Infected: Email-Worm.Win32.Bagle.of skipped
C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP1466\A0104338.exe Infected: Trojan.Win32.Pakes.ciw skipped
C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP1466\A0104340.exe Infected: Email-Worm.Win32.Bagle.of skipped
C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP1466\A0104359.exe Infected: Email-Worm.Win32.Bagle.of skipped
C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP1466\A0104361.exe Infected: Email-Worm.Win32.Bagle.of skipped
C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP1466\A0104377.exe Infected: Trojan.Win32.Pakes.ciw skipped
C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP1466\A0104379.exe Infected: Trojan.Win32.Pakes.ciw skipped
C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP1466\A0104382.exe Infected: Email-Worm.Win32.Bagle.of skipped
C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP1466\A0104399.sys Infected: Trojan-Downloader.Win32.Bagle.ky skipped
C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP1466\A0104420.exe Infected: Trojan.Win32.Pakes.ciw skipped
C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP1466\A0104422.exe Infected: Email-Worm.Win32.Bagle.of skipped
C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP1466\A0104498.exe Infected: Email-Worm.Win32.Bagle.of skipped
C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP1466\change.log Object is locked skipped
C:\WINDOWS\$hf_mig$\KB890859\SP2QFE\ntoskrnl.exe Object is locked skipped
C:\WINDOWS\$hf_mig$\KB929338\SP2QFE\ntoskrnl.exe Object is locked skipped
C:\WINDOWS\$hf_mig$\KB931784\SP2QFE\ntoskrnl.exe Object is locked skipped
C:\WINDOWS\$NtServicePackUninstall$\ntoskrnl.exe Object is locked skipped
C:\WINDOWS\$NtUninstallKB890859$\ntoskrnl.exe Object is locked skipped
C:\WINDOWS\$NtUninstallKB929338$\ntoskrnl.exe Object is locked skipped
C:\WINDOWS\$NtUninstallKB931784$\ntoskrnl.exe Object is locked skipped
C:\WINDOWS\$NtUninstallQ811493$\ntoskrnl.exe Object is locked skipped
C:\WINDOWS\Debug\PASSWD.LOG Object is locked skipped
C:\WINDOWS\Driver Cache\I386\ntoskrnl.exe Object is locked skipped
C:\WINDOWS\SchedLgU.Txt Object is locked skipped
C:\WINDOWS\ServicePackFiles\i386\ntoskrnl.exe Object is locked skipped
C:\WINDOWS\Sti_Trace.log Object is locked skipped
C:\WINDOWS\SYSTEM32\1.exe Infected: Email-Worm.Win32.Bagle.of skipped
C:\WINDOWS\SYSTEM32\CatRoot2\edb.log Object is locked skipped
C:\WINDOWS\SYSTEM32\CatRoot2\tmp.edb Object is locked skipped
C:\WINDOWS\SYSTEM32\Com\oboe32\shell32.exe Infected: not-a-virus:Server-FTP.Win32.Serv-U.4002 skipped
C:\WINDOWS\SYSTEM32\CONFIG\AppEvent.Evt Object is locked skipped
C:\WINDOWS\SYSTEM32\CONFIG\DEFAULT Object is locked skipped
C:\WINDOWS\SYSTEM32\CONFIG\DEFAULT.LOG Object is locked skipped
C:\WINDOWS\SYSTEM32\CONFIG\Internet.evt Object is locked skipped
C:\WINDOWS\SYSTEM32\CONFIG\SAM Object is locked skipped
C:\WINDOWS\SYSTEM32\CONFIG\SAM.LOG Object is locked skipped
C:\WINDOWS\SYSTEM32\CONFIG\SecEvent.Evt Object is locked skipped
C:\WINDOWS\SYSTEM32\CONFIG\SECURITY Object is locked skipped
C:\WINDOWS\SYSTEM32\CONFIG\SECURITY.LOG Object is locked skipped
C:\WINDOWS\SYSTEM32\CONFIG\SOFTWARE Object is locked skipped
C:\WINDOWS\SYSTEM32\CONFIG\SOFTWARE.LOG Object is locked skipped
C:\WINDOWS\SYSTEM32\CONFIG\SysEvent.Evt Object is locked skipped
C:\WINDOWS\SYSTEM32\CONFIG\SYSTEM Object is locked skipped
C:\WINDOWS\SYSTEM32\CONFIG\SYSTEM.LOG Object is locked skipped
C:\WINDOWS\SYSTEM32\H323LOG.TXT Object is locked skipped
C:\WINDOWS\SYSTEM32\LogFiles\WUDF\WUDFTrace.etl Object is locked skipped
C:\WINDOWS\SYSTEM32\mdelk.exe Infected: Email-Worm.Win32.Bagle.of skipped
C:\WINDOWS\SYSTEM32\WBEM\Repository\FS\INDEX.BTR Object is locked skipped
C:\WINDOWS\SYSTEM32\WBEM\Repository\FS\INDEX.MAP Object is locked skipped
C:\WINDOWS\SYSTEM32\WBEM\Repository\FS\MAPPING.VER Object is locked skipped
C:\WINDOWS\SYSTEM32\WBEM\Repository\FS\MAPPING1.MAP Object is locked skipped
C:\WINDOWS\SYSTEM32\WBEM\Repository\FS\MAPPING2.MAP Object is locked skipped
C:\WINDOWS\SYSTEM32\WBEM\Repository\FS\OBJECTS.DATA Object is locked skipped
C:\WINDOWS\SYSTEM32\WBEM\Repository\FS\OBJECTS.MAP Object is locked skipped
C:\WINDOWS\SYSTEM32\wi1.exe Infected: Trojan-Proxy.Win32.Mitglieder.gen skipped
C:\WINDOWS\WIADEBUG.LOG Object is locked skipped
C:\WINDOWS\WIASERVC.LOG Object is locked skipped
Scan process completed.