Hi!
I'm pretty nervous with the situation of my mom's computer. She doesn't know much about computers.
I won't be here at my mom's house all week, just today and a little of tomorrow but I'd like to get rid of Virtumonde asap, so it's ok for my mom.
I really, really appreciate it to anyone who might help us!
Thanks so much in advance.
Here is my Hijack and Kaspersky logs...
Running processes:
C:\Windows\system32\Dwm.exe
C:\Windows\system32\taskeng.exe
C:\Program Files\Windows Defender\MSASCui.exe
C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe
C:\Windows\sttray.exe
C:\Program Files\Intel\Intel Matrix Storage Manager\IAAnotif.exe
C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxWatchTray9.exe
C:\Program Files\Roxio\Drag-to-Disc\DrgToDsc.exe
C:\Program Files\McAfee\MSK\mskagent.exe
C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe
C:\Program Files\TELUS_eCare_Lite\eCareTrayApp.exe
C:\Program Files\Hp\HP Software Update\hpwuSchd2.exe
C:\Program Files\Grisoft\AVG7\avgcc.exe
C:\Program Files\QuickTime\QTTask.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\Windows Sidebar\sidebar.exe
C:\Program Files\DellSupport\DSAgnt.exe
C:\Program Files\Google\Google Desktop Search\GoogleDesktopIndex.exe
C:\Windows\ehome\ehtray.exe
C:\Program Files\MSN Messenger\msnmsgr.exe
C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
C:\Program Files\ATI Technologies\ATI.ACE\CLI.EXE
C:\Windows\ehome\ehmsas.exe
C:\Windows\System32\rundll32.exe
C:\Program Files\Hp\Digital Imaging\bin\hpqtra08.exe
C:\PROGRA~1\McAfee.com\Agent\mcagent.exe
C:\Program Files\McAfee\MPS\mpsevh.exe
C:\Program Files\Google\Google Desktop Search\GoogleDesktopCrawl.exe
C:\Program Files\Windows Mail\WinMail.exe
C:\Windows\system32\wbem\unsecapp.exe
C:\Program Files\Internet Explorer\ieuser.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Yahoo!\Messenger\ymsgr_tray.exe
C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\CPSHelpRunner.exe
C:\Program Files\HP\Digital Imaging\bin\hpqSTE08.exe
C:\Program Files\ATI Technologies\ATI.ACE\CLI.exe
C:\Program Files\ATI Technologies\ATI.ACE\CLI.exe
C:\Windows\System32\notepad.exe
C:\Windows\system32\rundll32.exe
C:\Windows\explorer.exe
C:\Windows\system32\wuauclt.exe
C:\Users\Melanie\Desktop\HiJackThis.exe
--
End of file - 2266 bytes
...And the KASPERSKY log.
-------------------------------------------------------------------------------
KASPERSKY ONLINE SCANNER REPORT
Wednesday, May 14, 2008 8:38:20 PM
Operating System: Microsoft Windows Vista Home Edition, (Build 6000)
Kaspersky Online Scanner version: 5.0.98.0
Kaspersky Anti-Virus database last update: 15/05/2008
Kaspersky Anti-Virus database records: 774093
-------------------------------------------------------------------------------
Scan Settings:
Scan using the following antivirus database: extended
Scan Archives: true
Scan Mail Bases: true
Scan Target - My Computer:
C:\
D:\
E:\
F:\
Scan Statistics:
Total number of scanned objects: 184911
Number of viruses found: 2
Number of infected objects: 9
Number of suspicious objects: 0
Duration of the scan process: 01:20:51
Infected Object Name / Virus Name / Last Action
C:\$Recycle.Bin\S-1-5-21-1706969126-3419066595-1923259787-1001\$RJK6M04.zip/Setup.exe Infected: not-a-virus:AdWare.Win32.Agent.zk skipped
C:\$Recycle.Bin\S-1-5-21-1706969126-3419066595-1923259787-1001\$RJK6M04.zip ZIP: infected - 1 skipped
C:\Program Files\InstallShield Installation Information\{5CD29180-A95E-11D3-A4EB-00C04F7BDB2C}\setup.ilg Object is locked skipped
C:\Program Files\InstallShield Installation Information\{72DF62BD-FF36-424E-AA5F-D89BAFF2C249}\setup.ilg Object is locked skipped
C:\ProgramData\McAfee\MSC\Logs\Events.dat Object is locked skipped
C:\ProgramData\McAfee\MSC\Logs\{17E9AA34-5FE6-479B-B9DB-7D104FC082EF}.log Object is locked skipped
C:\ProgramData\McAfee\MSC\Logs\{A93C7B2B-2AB3-4A70-8622-8CCCC01AAE63}.log Object is locked skipped
C:\ProgramData\McAfee\MSC\Logs\{B1DACB9D-4B45-43F9-8D92-6AEDEE83379F}.log Object is locked skipped
C:\ProgramData\McAfee\MSC\McUsers.dat Object is locked skipped
C:\ProgramData\McAfee\MNA\NAData Object is locked skipped
C:\ProgramData\McAfee\MPF\data\log.edb Object is locked skipped
C:\ProgramData\McAfee\MSK\MSKWMDB.dat Object is locked skipped
C:\ProgramData\McAfee\MSK\RBLDB.dat Object is locked skipped
C:\ProgramData\McAfee\MSK\settingsdb.dat Object is locked skipped
C:\ProgramData\McAfee\VirusScan\Data\TFR9FA8.tmp Object is locked skipped
C:\ProgramData\McAfee\VirusScan\Logs\OAS.Log Object is locked skipped
C:\ProgramData\Grisoft\Avg7Data\avg7log.log Object is locked skipped
C:\ProgramData\Grisoft\Avg7Data\avg7log.log.lck Object is locked skipped
C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\0345dfa9c7f9628afe2107f9c58205f5_f0549bda-9590-449e-b539-1f57badbaaec Object is locked skipped
C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\dell.txt Object is locked skipped
C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\f686aace6942fb7f7ceb231212eef4a4_f0549bda-9590-449e-b539-1f57badbaaec Object is locked skipped
C:\ProgramData\Microsoft\eHome\logs\eHomeLog01.sqm Object is locked skipped
C:\ProgramData\Microsoft\User Account Pictures\admin.dat Object is locked skipped
C:\ProgramData\Microsoft\User Account Pictures\Guest.dat Object is locked skipped
C:\ProgramData\Microsoft\User Account Pictures\Julia.dat Object is locked skipped
C:\ProgramData\Microsoft\User Account Pictures\Veronica.dat Object is locked skipped
C:\Users\Melanie\AppData\Local\Google\Google Desktop\1d1beb2165b1\dbc2e.ht1 Object is locked skipped
C:\Users\Melanie\AppData\Local\Google\Google Desktop\1d1beb2165b1\dbdam Object is locked skipped
C:\Users\Melanie\AppData\Local\Google\Google Desktop\1d1beb2165b1\dbdao Object is locked skipped
C:\Users\Melanie\AppData\Local\Google\Google Desktop\1d1beb2165b1\dbeam Object is locked skipped
C:\Users\Melanie\AppData\Local\Google\Google Desktop\1d1beb2165b1\dbeao Object is locked skipped
C:\Users\Melanie\AppData\Local\Google\Google Desktop\1d1beb2165b1\dbm Object is locked skipped
C:\Users\Melanie\AppData\Local\Google\Google Desktop\1d1beb2165b1\dbu2d.ht1 Object is locked skipped
C:\Users\Melanie\AppData\Local\Google\Google Desktop\1d1beb2165b1\dbvm.cf1 Object is locked skipped
C:\Users\Melanie\AppData\Local\Google\Google Desktop\1d1beb2165b1\dbvmh.ht1 Object is locked skipped
C:\Users\Melanie\AppData\Local\Google\Google Desktop\1d1beb2165b1\fii.cf1 Object is locked skipped
C:\Users\Melanie\AppData\Local\Google\Google Desktop\1d1beb2165b1\fiih.ht1 Object is locked skipped
C:\Users\Melanie\AppData\Local\Google\Google Desktop\1d1beb2165b1\hp Object is locked skipped
C:\Users\Melanie\AppData\Local\Google\Google Desktop\1d1beb2165b1\hpt2i.ht1 Object is locked skipped
C:\Users\Melanie\AppData\Local\Google\Google Desktop\1d1beb2165b1\rpm.cf1 Object is locked skipped
C:\Users\Melanie\AppData\Local\Google\Google Desktop\1d1beb2165b1\rpm1m.cf1 Object is locked skipped
C:\Users\Melanie\AppData\Local\Google\Google Desktop\1d1beb2165b1\rpm1mh.ht1 Object is locked skipped
C:\Users\Melanie\AppData\Local\Google\Google Desktop\1d1beb2165b1\rpmh.ht1 Object is locked skipped
C:\Users\Melanie\AppData\Local\Microsoft\Windows\TEMPOR~1\Content.IE5\index.dat Object is locked skipped
C:\Users\Melanie\AppData\Local\Microsoft\Windows\TEMPOR~1\Content.IE5\SQG6941H\hctp[1] Object is locked skipped
C:\Users\Melanie\AppData\Local\Microsoft\Windows\TEMPOR~1\Low\AntiPhishing\B3BB5BBA-E7D5-40AB-A041-A5B1C0B26C8F.dat Object is locked skipped
C:\Users\Melanie\AppData\Local\Microsoft\Windows\TEMPOR~1\Low\Content.IE5\index.dat Object is locked skipped
C:\Users\Melanie\AppData\Local\Microsoft\Windows\TEMPOR~1\Virtualized\C\Users\Melanie\AppData\Local\Temp\IDC1.tmp\[1]popcaploader_v10[1].cab/PopCapLoader.dll Infected: not-a-virus
ownloader.Win32.PopCap.b skipped
C:\Users\Melanie\AppData\Local\Microsoft\Windows\TEMPOR~1\Virtualized\C\Users\Melanie\AppData\Local\Temp\IDC1.tmp\[1]popcaploader_v10[1].cab CAB: infected - 1 skipped
C:\Users\Melanie\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat Object is locked skipped
C:\Users\Melanie\AppData\Local\Microsoft\Windows\History\History.IE5\MSHist012008051220080513\index.dat Object is locked skipped
C:\Users\Melanie\AppData\Local\Microsoft\Windows\History\Low\History.IE5\index.dat Object is locked skipped
C:\Users\Melanie\AppData\Local\Microsoft\Windows\History\Low\History.IE5\MSHist012008051420080515\index.dat Object is locked skipped
C:\Users\Melanie\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat Object is locked skipped
C:\Users\Melanie\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\SQG6941H\hctp[1] Object is locked skipped
C:\Users\Melanie\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\AntiPhishing\B3BB5BBA-E7D5-40AB-A041-A5B1C0B26C8F.dat Object is locked skipped
C:\Users\Melanie\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\index.dat Object is locked skipped
C:\Users\Melanie\AppData\Local\Microsoft\Windows\Temporary Internet Files\Virtualized\C\Users\Melanie\AppData\Local\Temp\IDC1.tmp\[1]popcaploader_v10[1].cab/PopCapLoader.dll Infected: not-a-virus
ownloader.Win32.PopCap.b skipped
C:\Users\Melanie\AppData\Local\Microsoft\Windows\Temporary Internet Files\Virtualized\C\Users\Melanie\AppData\Local\Temp\IDC1.tmp\[1]popcaploader_v10[1].cab CAB: infected - 1 skipped
C:\Users\Melanie\AppData\Local\Microsoft\Windows\UsrClass.dat Object is locked skipped
C:\Users\Melanie\AppData\Local\Microsoft\Windows\UsrClass.dat.LOG1 Object is locked skipped
C:\Users\Melanie\AppData\Local\Microsoft\Windows\UsrClass.dat.LOG2 Object is locked skipped
C:\Users\Melanie\AppData\Local\Microsoft\Windows\UsrClass.dat{e06a4eb1-e3da-11db-9bc7-0019d14f57d5}.TM.blf Object is locked skipped
C:\Users\Melanie\AppData\Local\Microsoft\Windows\UsrClass.dat{e06a4eb1-e3da-11db-9bc7-0019d14f57d5}.TMContainer00000000000000000001.regtrans-ms Object is locked skipped
C:\Users\Melanie\AppData\Local\Microsoft\Windows\UsrClass.dat{e06a4eb1-e3da-11db-9bc7-0019d14f57d5}.TMContainer00000000000000000002.regtrans-ms Object is locked skipped
C:\Users\Melanie\AppData\Local\Microsoft\Windows\WindowsUpdate.log Object is locked skipped
C:\Users\Melanie\AppData\Local\Microsoft\Feeds Cache\index.dat Object is locked skipped
C:\Users\Melanie\AppData\Local\Microsoft\Internet Explorer\MSIMGSIZ.DAT Object is locked skipped
C:\Users\Melanie\AppData\Local\Microsoft\Windows Defender\FileTracker\{CE5CE5CE-D657-494F-8685-EA14CD867DFB} Object is locked skipped
C:\Users\Melanie\AppData\Local\Microsoft\Windows Mail\edb.log Object is locked skipped
C:\Users\Melanie\AppData\Local\Microsoft\Windows Mail\edbtmp.log Object is locked skipped
C:\Users\Melanie\AppData\Local\Microsoft\Windows Mail\tmp.edb Object is locked skipped
C:\Users\Melanie\AppData\Local\Microsoft\Windows Mail\WindowsMail.MSMessageStore Object is locked skipped
C:\Users\Melanie\AppData\Local\Microsoft\Windows Sidebar\Settings.ini Object is locked skipped
C:\Users\Melanie\AppData\Local\Temp\IDC1.tmp\[1]popcaploader_v10[1].cab/PopCapLoader.dll Infected: not-a-virus
ownloader.Win32.PopCap.b skipped
C:\Users\Melanie\AppData\Local\Temp\IDC1.tmp\[1]popcaploader_v10[1].cab CAB: infected - 1 skipped
C:\Users\Melanie\AppData\Local\Temp\~DF752A.tmp Object is locked skipped
C:\Users\Melanie\AppData\Local\Temp\~DF8A4F.tmp Object is locked skipped
C:\Users\Melanie\AppData\Roaming\GTek\GTUpdate\AUpdate\DellSupport\DSAgnt.log Object is locked skipped
C:\Users\Melanie\AppData\Roaming\GTek\GTUpdate\AUpdate\DellSupport\DSAgnt_GTActions.log Object is locked skipped
C:\Users\Melanie\AppData\Roaming\GTek\GTUpdate\AUpdate\DellSupport\gdql_d_DSAgnt.log Object is locked skipped
C:\Users\Melanie\AppData\Roaming\GTek\GTUpdate\AUpdate\DellSupport\glog.log Object is locked skipped
C:\Users\Melanie\AppData\Roaming\Microsoft\Windows\Cookies\index.dat Object is locked skipped
C:\Users\Melanie\AppData\Roaming\Microsoft\Windows\Cookies\Low\index.dat Object is locked skipped
C:\Users\Melanie\Music\iTunes\iTunes Library.itl Object is locked skipped
C:\Users\Melanie\NTUSER.DAT Object is locked skipped
C:\Users\Melanie\ntuser.dat.LOG1 Object is locked skipped
C:\Users\Melanie\ntuser.dat.LOG2 Object is locked skipped
C:\Users\Melanie\NTUSER.DAT{3a539871-6a70-11db-887c-d362bd253390}.TM.blf Object is locked skipped
C:\Users\Melanie\NTUSER.DAT{3a539871-6a70-11db-887c-d362bd253390}.TMContainer00000000000000000001.regtrans-ms Object is locked skipped
C:\Users\Melanie\NTUSER.DAT{3a539871-6a70-11db-887c-d362bd253390}.TMContainer00000000000000000002.regtrans-ms Object is locked skipped
C:\Windows\Debug\PASSWD.LOG Object is locked skipped
C:\Windows\Debug\sam.log Object is locked skipped
C:\Windows\Debug\WIA\wiatrace.log Object is locked skipped
C:\Windows\Downloaded Program Files\popcaploader.dll Infected: not-a-virus
ownloader.Win32.PopCap.b skipped
C:\Windows\Logs\CBS\CBS.log Object is locked skipped
C:\Windows\Logs\CBS\CBS.persist.log Object is locked skipped
C:\Windows\Logs\DPX\setupact.log Object is locked skipped
C:\Windows\Logs\DPX\setuperr.log Object is locked skipped
C:\Windows\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\SMSvcHost.exe.config Object is locked skipped
C:\Windows\Panther\UnattendGC\diagerr.xml Object is locked skipped
C:\Windows\Panther\UnattendGC\diagwrn.xml Object is locked skipped
C:\Windows\Panther\UnattendGC\setupact.log Object is locked skipped
C:\Windows\Panther\UnattendGC\setuperr.log Object is locked skipped
C:\Windows\security\database\secedit.sdb Object is locked skipped
C:\Windows\SoftwareDistribution\ReportingEvents.log Object is locked skipped
C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-0.C7483456-A289-439d-8115-601632D005A0 Object is locked skipped
C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-1.C7483456-A289-439d-8115-601632D005A0 Object is locked skipped
C:\Windows\System32\catroot2\edb.log Object is locked skipped
C:\Windows\System32\catroot2\{127D0A1D-4EF2-11D1-8608-00C04FC295EE}\catdb Object is locked skipped
C:\Windows\System32\catroot2\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\catdb Object is locked skipped
C:\Windows\System32\config\COMPONENTS Object is locked skipped
C:\Windows\System32\config\COMPONENTS.LOG1 Object is locked skipped
C:\Windows\System32\config\COMPONENTS.LOG2 Object is locked skipped
C:\Windows\System32\config\DEFAULT Object is locked skipped
C:\Windows\System32\config\DEFAULT.LOG1 Object is locked skipped
C:\Windows\System32\config\DEFAULT.LOG2 Object is locked skipped
C:\Windows\System32\config\SAM Object is locked skipped
C:\Windows\System32\config\SAM.LOG1 Object is locked skipped
C:\Windows\System32\config\SAM.LOG2 Object is locked skipped
C:\Windows\System32\config\SECURITY Object is locked skipped
C:\Windows\System32\config\SECURITY.LOG1 Object is locked skipped
C:\Windows\System32\config\SECURITY.LOG2 Object is locked skipped
C:\Windows\System32\config\SOFTWARE Object is locked skipped
C:\Windows\System32\config\SOFTWARE.LOG1 Object is locked skipped
C:\Windows\System32\config\SOFTWARE.LOG2 Object is locked skipped
C:\Windows\System32\config\SYSTEM Object is locked skipped
C:\Windows\System32\config\SYSTEM.LOG1 Object is locked skipped
C:\Windows\System32\config\SYSTEM.LOG2 Object is locked skipped
C:\Windows\System32\config\TxR\{250834b7-750c-494d-bdc3-da86b6e2101a}.TxR.0.regtrans-ms Object is locked skipped
C:\Windows\System32\config\TxR\{250834b7-750c-494d-bdc3-da86b6e2101a}.TxR.1.regtrans-ms Object is locked skipped
C:\Windows\System32\config\TxR\{250834b7-750c-494d-bdc3-da86b6e2101a}.TxR.2.regtrans-ms Object is locked skipped
C:\Windows\System32\config\TxR\{250834b7-750c-494d-bdc3-da86b6e2101a}.TxR.blf Object is locked skipped
C:\Windows\System32\config\TxR\{250834B7-750C-494d-BDC3-DA86B6E2101B}.TM.blf Object is locked skipped
C:\Windows\System32\config\TxR\{250834B7-750C-494d-BDC3-DA86B6E2101B}.TMContainer00000000000000000001.regtrans-ms Object is locked skipped
C:\Windows\System32\config\TxR\{250834B7-750C-494d-BDC3-DA86B6E2101B}.TMContainer00000000000000000002.regtrans-ms Object is locked skipped
C:\Windows\System32\config\TxR\{250834B7-750C-494d-BDC3-DA86B6E2101B}.TMContainer00000000000000000003.regtrans-ms Object is locked skipped
C:\Windows\System32\config\TxR\{250834B7-750C-494d-BDC3-DA86B6E2101B}.TMContainer00000000000000000004.regtrans-ms Object is locked skipped
C:\Windows\System32\LogFiles\Scm\SCM.EVM Object is locked skipped
C:\Windows\System32\LogFiles\WUDF\WUDFTrace.etl Object is locked skipped
C:\Windows\System32\restore\MachineGuid.txt Object is locked skipped
C:\Windows\System32\SMI\Store\Machine\SCHEMA.DAT Object is locked skipped
C:\Windows\System32\SMI\Store\Machine\schema.dat.LOG1 Object is locked skipped
C:\Windows\System32\SMI\Store\Machine\schema.dat.LOG2 Object is locked skipped
C:\Windows\System32\SMI\Store\Machine\SCHEMA.DAT{3a53986d-6a70-11db-887c-d362bd253390}.TM.blf Object is locked skipped
C:\Windows\System32\SMI\Store\Machine\SCHEMA.DAT{3a53986d-6a70-11db-887c-d362bd253390}.TMContainer00000000000000000001.regtrans-ms Object is locked skipped
C:\Windows\System32\SMI\Store\Machine\SCHEMA.DAT{3a53986d-6a70-11db-887c-d362bd253390}.TMContainer00000000000000000002.regtrans-ms Object is locked skipped
C:\Windows\System32\spool\SpoolerETW.etl Object is locked skipped
C:\Windows\System32\sysprep\Panther\diagerr.xml Object is locked skipped
C:\Windows\System32\sysprep\Panther\diagwrn.xml Object is locked skipped
C:\Windows\System32\sysprep\Panther\setupact.log Object is locked skipped
C:\Windows\System32\sysprep\Panther\setuperr.log Object is locked skipped
C:\Windows\System32\wbem\AutoRecover\3460B7617E0429A960E481B197F238A3.mof Object is locked skipped
C:\Windows\System32\wbem\Logs\WMITracing.log Object is locked skipped
C:\Windows\System32\wbem\Repository\INDEX.BTR Object is locked skipped
C:\Windows\System32\wbem\Repository\MAPPING1.MAP Object is locked skipped
C:\Windows\System32\wbem\Repository\MAPPING2.MAP Object is locked skipped
C:\Windows\System32\wbem\Repository\OBJECTS.DATA Object is locked skipped
C:\Windows\System32\winevt\Logs\Application.evtx Object is locked skipped
C:\Windows\System32\winevt\Logs\DFS Replication.evtx Object is locked skipped
C:\Windows\System32\winevt\Logs\HardwareEvents.evtx Object is locked skipped
C:\Windows\System32\winevt\Logs\Internet Explorer.evtx Object is locked skipped
C:\Windows\System32\winevt\Logs\Key Management Service.evtx Object is locked skipped
C:\Windows\System32\winevt\Logs\Media Center.evtx Object is locked skipped
C:\Windows\System32\winevt\Logs\Microsoft-Windows-Bits-Client%4Operational.evtx Object is locked skipped
C:\Windows\System32\winevt\Logs\Microsoft-Windows-CodeIntegrity%4Operational.evtx Object is locked skipped
C:\Windows\System32\winevt\Logs\Microsoft-Windows-Diagnosis-DPS%4Operational.evtx Object is locked skipped
C:\Windows\System32\winevt\Logs\Microsoft-Windows-Diagnosis-PLA%4Operational.evtx Object is locked skipped
C:\Windows\System32\winevt\Logs\Microsoft-Windows-Diagnostics-Networking%4Operational.evtx Object is locked skipped
C:\Windows\System32\winevt\Logs\Microsoft-Windows-Diagnostics-Performance%4Operational.evtx Object is locked skipped
C:\Windows\System32\winevt\Logs\Microsoft-Windows-DiskDiagnosticDataCollector%4Operational.evtx Object is locked skipped
C:\Windows\System32\winevt\Logs\Microsoft-Windows-DriverFrameworks-UserMode%4Operational.evtx Object is locked skipped
C:\Windows\System32\winevt\Logs\Microsoft-Windows-GroupPolicy%4Operational.evtx Object is locked skipped
C:\Windows\System32\winevt\Logs\Microsoft-Windows-Help%4Operational.evtx Object is locked skipped
C:\Windows\System32\winevt\Logs\Microsoft-Windows-International%4Operational.evtx Object is locked skipped
C:\Windows\System32\winevt\Logs\Microsoft-Windows-Kernel-WHEA.evtx Object is locked skipped
C:\Windows\System32\winevt\Logs\Microsoft-Windows-LanguagePackSetup%4Operational.evtx Object is locked skipped
C:\Windows\System32\winevt\Logs\Microsoft-Windows-MUI%4Operational.evtx Object is locked skipped
C:\Windows\System32\winevt\Logs\Microsoft-Windows-NetworkAccessProtection%4Operational.evtx Object is locked skipped
C:\Windows\System32\winevt\Logs\Microsoft-Windows-ParentalControls%4Operational.evtx Object is locked skipped
C:\Windows\System32\winevt\Logs\Microsoft-Windows-Program-Compatibility-Assistant%4Operational.evtx Object is locked skipped
C:\Windows\System32\winevt\Logs\Microsoft-Windows-ReadyBoost%4Operational.evtx Object is locked skipped
C:\Windows\System32\winevt\Logs\Microsoft-Windows-ReliabilityAnalysisComponent%4Operational.evtx Object is locked skipped
C:\Windows\System32\winevt\Logs\Microsoft-Windows-Resource-Exhaustion-Detector%4Operational.evtx Object is locked skipped
C:\Windows\System32\winevt\Logs\Microsoft-Windows-Resource-Exhaustion-Resolver%4Operational.evtx Object is locked skipped
C:\Windows\System32\winevt\Logs\Microsoft-Windows-Resource-Leak-Diagnostic%4Operational.evtx Object is locked skipped
C:\Windows\System32\winevt\Logs\Microsoft-Windows-RestartManager%4Operational.evtx Object is locked skipped
C:\Windows\System32\winevt\Logs\Microsoft-Windows-TaskScheduler%4Operational.evtx Object is locked skipped
C:\Windows\System32\winevt\Logs\Microsoft-Windows-UAC%4Operational.evtx Object is locked skipped
C:\Windows\System32\winevt\Logs\Microsoft-Windows-UAC-FileVirtualization%4Operational.evtx Object is locked skipped
C:\Windows\System32\winevt\Logs\Microsoft-Windows-WindowsUpdateClient%4Operational.evtx Object is locked skipped
C:\Windows\System32\winevt\Logs\Microsoft-Windows-Winlogon%4Operational.evtx Object is locked skipped
C:\Windows\System32\winevt\Logs\Microsoft-Windows-Winsock-WS2HELP%4Operational.evtx Object is locked skipped
C:\Windows\System32\winevt\Logs\Microsoft-Windows-WLAN-AutoConfig%4Operational.evtx Object is locked skipped
C:\Windows\System32\winevt\Logs\Security.evtx Object is locked skipped
C:\Windows\System32\winevt\Logs\Setup.evtx Object is locked skipped
C:\Windows\System32\winevt\Logs\System.evtx Object is locked skipped
C:\Windows\Tasks\SCHEDLGU.TXT Object is locked skipped
C:\Windows\Tasks\User_Feed_Synchronization-{6E0EC77F-69E6-42B0-85AE-A1E06E64EEC9}.job Object is locked skipped
C:\Windows\Tasks\User_Feed_Synchronization-{B63364F3-7B03-4707-B66F-9ACDF5C2151E}.job Object is locked skipped
C:\Windows\WindowsUpdate.log Object is locked skipped
C:\Windows\winsxs\x86_microsoft-windows-n..n_service_datastore_31bf3856ad364e35_6.0.6000.16386_none_cef7ceb03914a67f\dnary.xsd Object is locked skipped
D:\Windows\security\database\secedit.sdb Object is locked skipped
Scan process completed.
I'm pretty nervous with the situation of my mom's computer. She doesn't know much about computers.
I won't be here at my mom's house all week, just today and a little of tomorrow but I'd like to get rid of Virtumonde asap, so it's ok for my mom.
I really, really appreciate it to anyone who might help us!
Thanks so much in advance.
Here is my Hijack and Kaspersky logs...
Running processes:
C:\Windows\system32\Dwm.exe
C:\Windows\system32\taskeng.exe
C:\Program Files\Windows Defender\MSASCui.exe
C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe
C:\Windows\sttray.exe
C:\Program Files\Intel\Intel Matrix Storage Manager\IAAnotif.exe
C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxWatchTray9.exe
C:\Program Files\Roxio\Drag-to-Disc\DrgToDsc.exe
C:\Program Files\McAfee\MSK\mskagent.exe
C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe
C:\Program Files\TELUS_eCare_Lite\eCareTrayApp.exe
C:\Program Files\Hp\HP Software Update\hpwuSchd2.exe
C:\Program Files\Grisoft\AVG7\avgcc.exe
C:\Program Files\QuickTime\QTTask.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\Windows Sidebar\sidebar.exe
C:\Program Files\DellSupport\DSAgnt.exe
C:\Program Files\Google\Google Desktop Search\GoogleDesktopIndex.exe
C:\Windows\ehome\ehtray.exe
C:\Program Files\MSN Messenger\msnmsgr.exe
C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
C:\Program Files\ATI Technologies\ATI.ACE\CLI.EXE
C:\Windows\ehome\ehmsas.exe
C:\Windows\System32\rundll32.exe
C:\Program Files\Hp\Digital Imaging\bin\hpqtra08.exe
C:\PROGRA~1\McAfee.com\Agent\mcagent.exe
C:\Program Files\McAfee\MPS\mpsevh.exe
C:\Program Files\Google\Google Desktop Search\GoogleDesktopCrawl.exe
C:\Program Files\Windows Mail\WinMail.exe
C:\Windows\system32\wbem\unsecapp.exe
C:\Program Files\Internet Explorer\ieuser.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Yahoo!\Messenger\ymsgr_tray.exe
C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\CPSHelpRunner.exe
C:\Program Files\HP\Digital Imaging\bin\hpqSTE08.exe
C:\Program Files\ATI Technologies\ATI.ACE\CLI.exe
C:\Program Files\ATI Technologies\ATI.ACE\CLI.exe
C:\Windows\System32\notepad.exe
C:\Windows\system32\rundll32.exe
C:\Windows\explorer.exe
C:\Windows\system32\wuauclt.exe
C:\Users\Melanie\Desktop\HiJackThis.exe
--
End of file - 2266 bytes
...And the KASPERSKY log.
-------------------------------------------------------------------------------
KASPERSKY ONLINE SCANNER REPORT
Wednesday, May 14, 2008 8:38:20 PM
Operating System: Microsoft Windows Vista Home Edition, (Build 6000)
Kaspersky Online Scanner version: 5.0.98.0
Kaspersky Anti-Virus database last update: 15/05/2008
Kaspersky Anti-Virus database records: 774093
-------------------------------------------------------------------------------
Scan Settings:
Scan using the following antivirus database: extended
Scan Archives: true
Scan Mail Bases: true
Scan Target - My Computer:
C:\
D:\
E:\
F:\
Scan Statistics:
Total number of scanned objects: 184911
Number of viruses found: 2
Number of infected objects: 9
Number of suspicious objects: 0
Duration of the scan process: 01:20:51
Infected Object Name / Virus Name / Last Action
C:\$Recycle.Bin\S-1-5-21-1706969126-3419066595-1923259787-1001\$RJK6M04.zip/Setup.exe Infected: not-a-virus:AdWare.Win32.Agent.zk skipped
C:\$Recycle.Bin\S-1-5-21-1706969126-3419066595-1923259787-1001\$RJK6M04.zip ZIP: infected - 1 skipped
C:\Program Files\InstallShield Installation Information\{5CD29180-A95E-11D3-A4EB-00C04F7BDB2C}\setup.ilg Object is locked skipped
C:\Program Files\InstallShield Installation Information\{72DF62BD-FF36-424E-AA5F-D89BAFF2C249}\setup.ilg Object is locked skipped
C:\ProgramData\McAfee\MSC\Logs\Events.dat Object is locked skipped
C:\ProgramData\McAfee\MSC\Logs\{17E9AA34-5FE6-479B-B9DB-7D104FC082EF}.log Object is locked skipped
C:\ProgramData\McAfee\MSC\Logs\{A93C7B2B-2AB3-4A70-8622-8CCCC01AAE63}.log Object is locked skipped
C:\ProgramData\McAfee\MSC\Logs\{B1DACB9D-4B45-43F9-8D92-6AEDEE83379F}.log Object is locked skipped
C:\ProgramData\McAfee\MSC\McUsers.dat Object is locked skipped
C:\ProgramData\McAfee\MNA\NAData Object is locked skipped
C:\ProgramData\McAfee\MPF\data\log.edb Object is locked skipped
C:\ProgramData\McAfee\MSK\MSKWMDB.dat Object is locked skipped
C:\ProgramData\McAfee\MSK\RBLDB.dat Object is locked skipped
C:\ProgramData\McAfee\MSK\settingsdb.dat Object is locked skipped
C:\ProgramData\McAfee\VirusScan\Data\TFR9FA8.tmp Object is locked skipped
C:\ProgramData\McAfee\VirusScan\Logs\OAS.Log Object is locked skipped
C:\ProgramData\Grisoft\Avg7Data\avg7log.log Object is locked skipped
C:\ProgramData\Grisoft\Avg7Data\avg7log.log.lck Object is locked skipped
C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\0345dfa9c7f9628afe2107f9c58205f5_f0549bda-9590-449e-b539-1f57badbaaec Object is locked skipped
C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\dell.txt Object is locked skipped
C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\f686aace6942fb7f7ceb231212eef4a4_f0549bda-9590-449e-b539-1f57badbaaec Object is locked skipped
C:\ProgramData\Microsoft\eHome\logs\eHomeLog01.sqm Object is locked skipped
C:\ProgramData\Microsoft\User Account Pictures\admin.dat Object is locked skipped
C:\ProgramData\Microsoft\User Account Pictures\Guest.dat Object is locked skipped
C:\ProgramData\Microsoft\User Account Pictures\Julia.dat Object is locked skipped
C:\ProgramData\Microsoft\User Account Pictures\Veronica.dat Object is locked skipped
C:\Users\Melanie\AppData\Local\Google\Google Desktop\1d1beb2165b1\dbc2e.ht1 Object is locked skipped
C:\Users\Melanie\AppData\Local\Google\Google Desktop\1d1beb2165b1\dbdam Object is locked skipped
C:\Users\Melanie\AppData\Local\Google\Google Desktop\1d1beb2165b1\dbdao Object is locked skipped
C:\Users\Melanie\AppData\Local\Google\Google Desktop\1d1beb2165b1\dbeam Object is locked skipped
C:\Users\Melanie\AppData\Local\Google\Google Desktop\1d1beb2165b1\dbeao Object is locked skipped
C:\Users\Melanie\AppData\Local\Google\Google Desktop\1d1beb2165b1\dbm Object is locked skipped
C:\Users\Melanie\AppData\Local\Google\Google Desktop\1d1beb2165b1\dbu2d.ht1 Object is locked skipped
C:\Users\Melanie\AppData\Local\Google\Google Desktop\1d1beb2165b1\dbvm.cf1 Object is locked skipped
C:\Users\Melanie\AppData\Local\Google\Google Desktop\1d1beb2165b1\dbvmh.ht1 Object is locked skipped
C:\Users\Melanie\AppData\Local\Google\Google Desktop\1d1beb2165b1\fii.cf1 Object is locked skipped
C:\Users\Melanie\AppData\Local\Google\Google Desktop\1d1beb2165b1\fiih.ht1 Object is locked skipped
C:\Users\Melanie\AppData\Local\Google\Google Desktop\1d1beb2165b1\hp Object is locked skipped
C:\Users\Melanie\AppData\Local\Google\Google Desktop\1d1beb2165b1\hpt2i.ht1 Object is locked skipped
C:\Users\Melanie\AppData\Local\Google\Google Desktop\1d1beb2165b1\rpm.cf1 Object is locked skipped
C:\Users\Melanie\AppData\Local\Google\Google Desktop\1d1beb2165b1\rpm1m.cf1 Object is locked skipped
C:\Users\Melanie\AppData\Local\Google\Google Desktop\1d1beb2165b1\rpm1mh.ht1 Object is locked skipped
C:\Users\Melanie\AppData\Local\Google\Google Desktop\1d1beb2165b1\rpmh.ht1 Object is locked skipped
C:\Users\Melanie\AppData\Local\Microsoft\Windows\TEMPOR~1\Content.IE5\index.dat Object is locked skipped
C:\Users\Melanie\AppData\Local\Microsoft\Windows\TEMPOR~1\Content.IE5\SQG6941H\hctp[1] Object is locked skipped
C:\Users\Melanie\AppData\Local\Microsoft\Windows\TEMPOR~1\Low\AntiPhishing\B3BB5BBA-E7D5-40AB-A041-A5B1C0B26C8F.dat Object is locked skipped
C:\Users\Melanie\AppData\Local\Microsoft\Windows\TEMPOR~1\Low\Content.IE5\index.dat Object is locked skipped
C:\Users\Melanie\AppData\Local\Microsoft\Windows\TEMPOR~1\Virtualized\C\Users\Melanie\AppData\Local\Temp\IDC1.tmp\[1]popcaploader_v10[1].cab/PopCapLoader.dll Infected: not-a-virus

C:\Users\Melanie\AppData\Local\Microsoft\Windows\TEMPOR~1\Virtualized\C\Users\Melanie\AppData\Local\Temp\IDC1.tmp\[1]popcaploader_v10[1].cab CAB: infected - 1 skipped
C:\Users\Melanie\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat Object is locked skipped
C:\Users\Melanie\AppData\Local\Microsoft\Windows\History\History.IE5\MSHist012008051220080513\index.dat Object is locked skipped
C:\Users\Melanie\AppData\Local\Microsoft\Windows\History\Low\History.IE5\index.dat Object is locked skipped
C:\Users\Melanie\AppData\Local\Microsoft\Windows\History\Low\History.IE5\MSHist012008051420080515\index.dat Object is locked skipped
C:\Users\Melanie\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat Object is locked skipped
C:\Users\Melanie\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\SQG6941H\hctp[1] Object is locked skipped
C:\Users\Melanie\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\AntiPhishing\B3BB5BBA-E7D5-40AB-A041-A5B1C0B26C8F.dat Object is locked skipped
C:\Users\Melanie\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\index.dat Object is locked skipped
C:\Users\Melanie\AppData\Local\Microsoft\Windows\Temporary Internet Files\Virtualized\C\Users\Melanie\AppData\Local\Temp\IDC1.tmp\[1]popcaploader_v10[1].cab/PopCapLoader.dll Infected: not-a-virus

C:\Users\Melanie\AppData\Local\Microsoft\Windows\Temporary Internet Files\Virtualized\C\Users\Melanie\AppData\Local\Temp\IDC1.tmp\[1]popcaploader_v10[1].cab CAB: infected - 1 skipped
C:\Users\Melanie\AppData\Local\Microsoft\Windows\UsrClass.dat Object is locked skipped
C:\Users\Melanie\AppData\Local\Microsoft\Windows\UsrClass.dat.LOG1 Object is locked skipped
C:\Users\Melanie\AppData\Local\Microsoft\Windows\UsrClass.dat.LOG2 Object is locked skipped
C:\Users\Melanie\AppData\Local\Microsoft\Windows\UsrClass.dat{e06a4eb1-e3da-11db-9bc7-0019d14f57d5}.TM.blf Object is locked skipped
C:\Users\Melanie\AppData\Local\Microsoft\Windows\UsrClass.dat{e06a4eb1-e3da-11db-9bc7-0019d14f57d5}.TMContainer00000000000000000001.regtrans-ms Object is locked skipped
C:\Users\Melanie\AppData\Local\Microsoft\Windows\UsrClass.dat{e06a4eb1-e3da-11db-9bc7-0019d14f57d5}.TMContainer00000000000000000002.regtrans-ms Object is locked skipped
C:\Users\Melanie\AppData\Local\Microsoft\Windows\WindowsUpdate.log Object is locked skipped
C:\Users\Melanie\AppData\Local\Microsoft\Feeds Cache\index.dat Object is locked skipped
C:\Users\Melanie\AppData\Local\Microsoft\Internet Explorer\MSIMGSIZ.DAT Object is locked skipped
C:\Users\Melanie\AppData\Local\Microsoft\Windows Defender\FileTracker\{CE5CE5CE-D657-494F-8685-EA14CD867DFB} Object is locked skipped
C:\Users\Melanie\AppData\Local\Microsoft\Windows Mail\edb.log Object is locked skipped
C:\Users\Melanie\AppData\Local\Microsoft\Windows Mail\edbtmp.log Object is locked skipped
C:\Users\Melanie\AppData\Local\Microsoft\Windows Mail\tmp.edb Object is locked skipped
C:\Users\Melanie\AppData\Local\Microsoft\Windows Mail\WindowsMail.MSMessageStore Object is locked skipped
C:\Users\Melanie\AppData\Local\Microsoft\Windows Sidebar\Settings.ini Object is locked skipped
C:\Users\Melanie\AppData\Local\Temp\IDC1.tmp\[1]popcaploader_v10[1].cab/PopCapLoader.dll Infected: not-a-virus

C:\Users\Melanie\AppData\Local\Temp\IDC1.tmp\[1]popcaploader_v10[1].cab CAB: infected - 1 skipped
C:\Users\Melanie\AppData\Local\Temp\~DF752A.tmp Object is locked skipped
C:\Users\Melanie\AppData\Local\Temp\~DF8A4F.tmp Object is locked skipped
C:\Users\Melanie\AppData\Roaming\GTek\GTUpdate\AUpdate\DellSupport\DSAgnt.log Object is locked skipped
C:\Users\Melanie\AppData\Roaming\GTek\GTUpdate\AUpdate\DellSupport\DSAgnt_GTActions.log Object is locked skipped
C:\Users\Melanie\AppData\Roaming\GTek\GTUpdate\AUpdate\DellSupport\gdql_d_DSAgnt.log Object is locked skipped
C:\Users\Melanie\AppData\Roaming\GTek\GTUpdate\AUpdate\DellSupport\glog.log Object is locked skipped
C:\Users\Melanie\AppData\Roaming\Microsoft\Windows\Cookies\index.dat Object is locked skipped
C:\Users\Melanie\AppData\Roaming\Microsoft\Windows\Cookies\Low\index.dat Object is locked skipped
C:\Users\Melanie\Music\iTunes\iTunes Library.itl Object is locked skipped
C:\Users\Melanie\NTUSER.DAT Object is locked skipped
C:\Users\Melanie\ntuser.dat.LOG1 Object is locked skipped
C:\Users\Melanie\ntuser.dat.LOG2 Object is locked skipped
C:\Users\Melanie\NTUSER.DAT{3a539871-6a70-11db-887c-d362bd253390}.TM.blf Object is locked skipped
C:\Users\Melanie\NTUSER.DAT{3a539871-6a70-11db-887c-d362bd253390}.TMContainer00000000000000000001.regtrans-ms Object is locked skipped
C:\Users\Melanie\NTUSER.DAT{3a539871-6a70-11db-887c-d362bd253390}.TMContainer00000000000000000002.regtrans-ms Object is locked skipped
C:\Windows\Debug\PASSWD.LOG Object is locked skipped
C:\Windows\Debug\sam.log Object is locked skipped
C:\Windows\Debug\WIA\wiatrace.log Object is locked skipped
C:\Windows\Downloaded Program Files\popcaploader.dll Infected: not-a-virus

C:\Windows\Logs\CBS\CBS.log Object is locked skipped
C:\Windows\Logs\CBS\CBS.persist.log Object is locked skipped
C:\Windows\Logs\DPX\setupact.log Object is locked skipped
C:\Windows\Logs\DPX\setuperr.log Object is locked skipped
C:\Windows\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\SMSvcHost.exe.config Object is locked skipped
C:\Windows\Panther\UnattendGC\diagerr.xml Object is locked skipped
C:\Windows\Panther\UnattendGC\diagwrn.xml Object is locked skipped
C:\Windows\Panther\UnattendGC\setupact.log Object is locked skipped
C:\Windows\Panther\UnattendGC\setuperr.log Object is locked skipped
C:\Windows\security\database\secedit.sdb Object is locked skipped
C:\Windows\SoftwareDistribution\ReportingEvents.log Object is locked skipped
C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-0.C7483456-A289-439d-8115-601632D005A0 Object is locked skipped
C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-1.C7483456-A289-439d-8115-601632D005A0 Object is locked skipped
C:\Windows\System32\catroot2\edb.log Object is locked skipped
C:\Windows\System32\catroot2\{127D0A1D-4EF2-11D1-8608-00C04FC295EE}\catdb Object is locked skipped
C:\Windows\System32\catroot2\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\catdb Object is locked skipped
C:\Windows\System32\config\COMPONENTS Object is locked skipped
C:\Windows\System32\config\COMPONENTS.LOG1 Object is locked skipped
C:\Windows\System32\config\COMPONENTS.LOG2 Object is locked skipped
C:\Windows\System32\config\DEFAULT Object is locked skipped
C:\Windows\System32\config\DEFAULT.LOG1 Object is locked skipped
C:\Windows\System32\config\DEFAULT.LOG2 Object is locked skipped
C:\Windows\System32\config\SAM Object is locked skipped
C:\Windows\System32\config\SAM.LOG1 Object is locked skipped
C:\Windows\System32\config\SAM.LOG2 Object is locked skipped
C:\Windows\System32\config\SECURITY Object is locked skipped
C:\Windows\System32\config\SECURITY.LOG1 Object is locked skipped
C:\Windows\System32\config\SECURITY.LOG2 Object is locked skipped
C:\Windows\System32\config\SOFTWARE Object is locked skipped
C:\Windows\System32\config\SOFTWARE.LOG1 Object is locked skipped
C:\Windows\System32\config\SOFTWARE.LOG2 Object is locked skipped
C:\Windows\System32\config\SYSTEM Object is locked skipped
C:\Windows\System32\config\SYSTEM.LOG1 Object is locked skipped
C:\Windows\System32\config\SYSTEM.LOG2 Object is locked skipped
C:\Windows\System32\config\TxR\{250834b7-750c-494d-bdc3-da86b6e2101a}.TxR.0.regtrans-ms Object is locked skipped
C:\Windows\System32\config\TxR\{250834b7-750c-494d-bdc3-da86b6e2101a}.TxR.1.regtrans-ms Object is locked skipped
C:\Windows\System32\config\TxR\{250834b7-750c-494d-bdc3-da86b6e2101a}.TxR.2.regtrans-ms Object is locked skipped
C:\Windows\System32\config\TxR\{250834b7-750c-494d-bdc3-da86b6e2101a}.TxR.blf Object is locked skipped
C:\Windows\System32\config\TxR\{250834B7-750C-494d-BDC3-DA86B6E2101B}.TM.blf Object is locked skipped
C:\Windows\System32\config\TxR\{250834B7-750C-494d-BDC3-DA86B6E2101B}.TMContainer00000000000000000001.regtrans-ms Object is locked skipped
C:\Windows\System32\config\TxR\{250834B7-750C-494d-BDC3-DA86B6E2101B}.TMContainer00000000000000000002.regtrans-ms Object is locked skipped
C:\Windows\System32\config\TxR\{250834B7-750C-494d-BDC3-DA86B6E2101B}.TMContainer00000000000000000003.regtrans-ms Object is locked skipped
C:\Windows\System32\config\TxR\{250834B7-750C-494d-BDC3-DA86B6E2101B}.TMContainer00000000000000000004.regtrans-ms Object is locked skipped
C:\Windows\System32\LogFiles\Scm\SCM.EVM Object is locked skipped
C:\Windows\System32\LogFiles\WUDF\WUDFTrace.etl Object is locked skipped
C:\Windows\System32\restore\MachineGuid.txt Object is locked skipped
C:\Windows\System32\SMI\Store\Machine\SCHEMA.DAT Object is locked skipped
C:\Windows\System32\SMI\Store\Machine\schema.dat.LOG1 Object is locked skipped
C:\Windows\System32\SMI\Store\Machine\schema.dat.LOG2 Object is locked skipped
C:\Windows\System32\SMI\Store\Machine\SCHEMA.DAT{3a53986d-6a70-11db-887c-d362bd253390}.TM.blf Object is locked skipped
C:\Windows\System32\SMI\Store\Machine\SCHEMA.DAT{3a53986d-6a70-11db-887c-d362bd253390}.TMContainer00000000000000000001.regtrans-ms Object is locked skipped
C:\Windows\System32\SMI\Store\Machine\SCHEMA.DAT{3a53986d-6a70-11db-887c-d362bd253390}.TMContainer00000000000000000002.regtrans-ms Object is locked skipped
C:\Windows\System32\spool\SpoolerETW.etl Object is locked skipped
C:\Windows\System32\sysprep\Panther\diagerr.xml Object is locked skipped
C:\Windows\System32\sysprep\Panther\diagwrn.xml Object is locked skipped
C:\Windows\System32\sysprep\Panther\setupact.log Object is locked skipped
C:\Windows\System32\sysprep\Panther\setuperr.log Object is locked skipped
C:\Windows\System32\wbem\AutoRecover\3460B7617E0429A960E481B197F238A3.mof Object is locked skipped
C:\Windows\System32\wbem\Logs\WMITracing.log Object is locked skipped
C:\Windows\System32\wbem\Repository\INDEX.BTR Object is locked skipped
C:\Windows\System32\wbem\Repository\MAPPING1.MAP Object is locked skipped
C:\Windows\System32\wbem\Repository\MAPPING2.MAP Object is locked skipped
C:\Windows\System32\wbem\Repository\OBJECTS.DATA Object is locked skipped
C:\Windows\System32\winevt\Logs\Application.evtx Object is locked skipped
C:\Windows\System32\winevt\Logs\DFS Replication.evtx Object is locked skipped
C:\Windows\System32\winevt\Logs\HardwareEvents.evtx Object is locked skipped
C:\Windows\System32\winevt\Logs\Internet Explorer.evtx Object is locked skipped
C:\Windows\System32\winevt\Logs\Key Management Service.evtx Object is locked skipped
C:\Windows\System32\winevt\Logs\Media Center.evtx Object is locked skipped
C:\Windows\System32\winevt\Logs\Microsoft-Windows-Bits-Client%4Operational.evtx Object is locked skipped
C:\Windows\System32\winevt\Logs\Microsoft-Windows-CodeIntegrity%4Operational.evtx Object is locked skipped
C:\Windows\System32\winevt\Logs\Microsoft-Windows-Diagnosis-DPS%4Operational.evtx Object is locked skipped
C:\Windows\System32\winevt\Logs\Microsoft-Windows-Diagnosis-PLA%4Operational.evtx Object is locked skipped
C:\Windows\System32\winevt\Logs\Microsoft-Windows-Diagnostics-Networking%4Operational.evtx Object is locked skipped
C:\Windows\System32\winevt\Logs\Microsoft-Windows-Diagnostics-Performance%4Operational.evtx Object is locked skipped
C:\Windows\System32\winevt\Logs\Microsoft-Windows-DiskDiagnosticDataCollector%4Operational.evtx Object is locked skipped
C:\Windows\System32\winevt\Logs\Microsoft-Windows-DriverFrameworks-UserMode%4Operational.evtx Object is locked skipped
C:\Windows\System32\winevt\Logs\Microsoft-Windows-GroupPolicy%4Operational.evtx Object is locked skipped
C:\Windows\System32\winevt\Logs\Microsoft-Windows-Help%4Operational.evtx Object is locked skipped
C:\Windows\System32\winevt\Logs\Microsoft-Windows-International%4Operational.evtx Object is locked skipped
C:\Windows\System32\winevt\Logs\Microsoft-Windows-Kernel-WHEA.evtx Object is locked skipped
C:\Windows\System32\winevt\Logs\Microsoft-Windows-LanguagePackSetup%4Operational.evtx Object is locked skipped
C:\Windows\System32\winevt\Logs\Microsoft-Windows-MUI%4Operational.evtx Object is locked skipped
C:\Windows\System32\winevt\Logs\Microsoft-Windows-NetworkAccessProtection%4Operational.evtx Object is locked skipped
C:\Windows\System32\winevt\Logs\Microsoft-Windows-ParentalControls%4Operational.evtx Object is locked skipped
C:\Windows\System32\winevt\Logs\Microsoft-Windows-Program-Compatibility-Assistant%4Operational.evtx Object is locked skipped
C:\Windows\System32\winevt\Logs\Microsoft-Windows-ReadyBoost%4Operational.evtx Object is locked skipped
C:\Windows\System32\winevt\Logs\Microsoft-Windows-ReliabilityAnalysisComponent%4Operational.evtx Object is locked skipped
C:\Windows\System32\winevt\Logs\Microsoft-Windows-Resource-Exhaustion-Detector%4Operational.evtx Object is locked skipped
C:\Windows\System32\winevt\Logs\Microsoft-Windows-Resource-Exhaustion-Resolver%4Operational.evtx Object is locked skipped
C:\Windows\System32\winevt\Logs\Microsoft-Windows-Resource-Leak-Diagnostic%4Operational.evtx Object is locked skipped
C:\Windows\System32\winevt\Logs\Microsoft-Windows-RestartManager%4Operational.evtx Object is locked skipped
C:\Windows\System32\winevt\Logs\Microsoft-Windows-TaskScheduler%4Operational.evtx Object is locked skipped
C:\Windows\System32\winevt\Logs\Microsoft-Windows-UAC%4Operational.evtx Object is locked skipped
C:\Windows\System32\winevt\Logs\Microsoft-Windows-UAC-FileVirtualization%4Operational.evtx Object is locked skipped
C:\Windows\System32\winevt\Logs\Microsoft-Windows-WindowsUpdateClient%4Operational.evtx Object is locked skipped
C:\Windows\System32\winevt\Logs\Microsoft-Windows-Winlogon%4Operational.evtx Object is locked skipped
C:\Windows\System32\winevt\Logs\Microsoft-Windows-Winsock-WS2HELP%4Operational.evtx Object is locked skipped
C:\Windows\System32\winevt\Logs\Microsoft-Windows-WLAN-AutoConfig%4Operational.evtx Object is locked skipped
C:\Windows\System32\winevt\Logs\Security.evtx Object is locked skipped
C:\Windows\System32\winevt\Logs\Setup.evtx Object is locked skipped
C:\Windows\System32\winevt\Logs\System.evtx Object is locked skipped
C:\Windows\Tasks\SCHEDLGU.TXT Object is locked skipped
C:\Windows\Tasks\User_Feed_Synchronization-{6E0EC77F-69E6-42B0-85AE-A1E06E64EEC9}.job Object is locked skipped
C:\Windows\Tasks\User_Feed_Synchronization-{B63364F3-7B03-4707-B66F-9ACDF5C2151E}.job Object is locked skipped
C:\Windows\WindowsUpdate.log Object is locked skipped
C:\Windows\winsxs\x86_microsoft-windows-n..n_service_datastore_31bf3856ad364e35_6.0.6000.16386_none_cef7ceb03914a67f\dnary.xsd Object is locked skipped
D:\Windows\security\database\secedit.sdb Object is locked skipped
Scan process completed.