Hello - new to this and need assistance. My computer has the slow CPU issue and the constant pop-ups suggesting that it is infected and showing me web-sites to fix. This started a few days ago so I am not sure how much damage has happened. I have run the kaspersky scan - took 4 hours. I also ran Hijackthis and Combofix - both in safemode, with tea turned off and with an internet connection - pulled the ethernet cord. So, here are my results. I am hoping that you can review and let me know what is next. (One strange problem that also started was that the 'Found New Hardware Wizard' keeps starting on boot and there is no new HW....
Any help you can provide would be greatly appreciated!!!!
First Kaspersky Logfile - before Hijack this or Combofix was run:
(I will post Hijack This and Combofix in separate posts...)
-------------------------------------------------------------------------------
KASPERSKY ONLINE SCANNER REPORT
Tuesday, April 08, 2008 10:20:05 PM
Operating System: Microsoft Windows XP Home Edition, Service Pack 2 (Build 2600)
Kaspersky Online Scanner version: 5.0.98.0
Kaspersky Anti-Virus database last update: 8/04/2008
Kaspersky Anti-Virus database records: 690768
-------------------------------------------------------------------------------
Scan Settings:
Scan using the following antivirus database: extended
Scan Archives: true
Scan Mail Bases: true
Scan Target - My Computer:
A:\
C:\
D:\
E:\
F:\
H:\
Scan Statistics:
Total number of scanned objects: 106359
Number of viruses found: 10
Number of infected objects: 29
Number of suspicious objects: 0
Duration of the scan process: 05:35:00
Infected Object Name / Virus Name / Last Action
C:\Documents and Settings\All Users\Application Data\Bell\Security Manager\Logs\FirewallService04-08-2008--08-20-07.log Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Dr Watson\user.dmp Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Network\Downloader\qmgr0.dat Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Network\Downloader\qmgr1.dat Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Pure Networks\Log\logfile.nmctxth_exe.txt Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Pure Networks\Log\logfile.nmsrvc_exe.txt Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\06673101.cla Infected: Exploit.Java.Gimsh.a skipped
C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\0D6F374C.htm Infected: Exploit.HTML.IframeBof skipped
C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\0D8A072F.htm Infected: Exploit.HTML.IframeBof skipped
C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\0D9D031A.htm Infected: Exploit.HTML.IframeBof skipped
C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\39FD1BE1.wma Infected: Trojan-Downloader.WMA.Wimad.d skipped
C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\3A036FDA.wma Infected: Trojan-Downloader.WMA.Wimad.d skipped
C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\3A0619D6.wma Infected: Trojan-Downloader.WMA.Wimad.d skipped
C:\Documents and Settings\LocalService\Cookies\index.dat Object is locked skipped
C:\Documents and Settings\LocalService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat Object is locked skipped
C:\Documents and Settings\LocalService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped
C:\Documents and Settings\LocalService\Local Settings\History\History.IE5\index.dat Object is locked skipped
C:\Documents and Settings\LocalService\Local Settings\Temporary Internet Files\Content.IE5\index.dat Object is locked skipped
C:\Documents and Settings\LocalService\NTUSER.DAT Object is locked skipped
C:\Documents and Settings\LocalService\ntuser.dat.LOG Object is locked skipped
C:\Documents and Settings\NetworkService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat Object is locked skipped
C:\Documents and Settings\NetworkService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped
C:\Documents and Settings\NetworkService\NTUSER.DAT Object is locked skipped
C:\Documents and Settings\NetworkService\ntuser.dat.LOG Object is locked skipped
C:\Documents and Settings\Paul Zakoor\Application Data\Bell\Sympatico Security Advisor\client_gateway.log Object is locked skipped
C:\Documents and Settings\Paul Zakoor\Cookies\index.dat Object is locked skipped
C:\Documents and Settings\Paul Zakoor\Desktop\SmitfraudFix\Reboot.exe Infected: not-a-virus:RiskTool.Win32.Reboot.f skipped
C:\Documents and Settings\Paul Zakoor\Local Settings\Application Data\Microsoft\Feeds Cache\index.dat Object is locked skipped
C:\Documents and Settings\Paul Zakoor\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat Object is locked skipped
C:\Documents and Settings\Paul Zakoor\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped
C:\Documents and Settings\Paul Zakoor\Local Settings\History\History.IE5\index.dat Object is locked skipped
C:\Documents and Settings\Paul Zakoor\Local Settings\History\History.IE5\MSHist012008040820080409\index.dat Object is locked skipped
C:\Documents and Settings\Paul Zakoor\Local Settings\Temporary Internet Files\AntiPhishing\B3BB5BBA-E7D5-40AB-A041-A5B1C0B26C8F.dat Object is locked skipped
C:\Documents and Settings\Paul Zakoor\Local Settings\Temporary Internet Files\Content.IE5\1FM94O0S\tWIV_0020_front[1].png Object is locked skipped
C:\Documents and Settings\Paul Zakoor\Local Settings\Temporary Internet Files\Content.IE5\index.dat Object is locked skipped
C:\Documents and Settings\Paul Zakoor\Local Settings\Temporary Internet Files\Content.IE5\VORA3YEM\t0PjoCeQCoze[1].jpg Object is locked skipped
C:\Documents and Settings\Paul Zakoor\Local Settings\Temporary Internet Files\Content.IE5\XU83RQWP\tPK_0246_front[1].png Object is locked skipped
C:\Documents and Settings\Paul Zakoor\NTUSER.DAT Object is locked skipped
C:\Documents and Settings\Paul Zakoor\ntuser.dat.LOG Object is locked skipped
C:\Program Files\CA\PPRT\logs\2008-04-08.csv Object is locked skipped
C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcrst.dll Object is locked skipped
C:\Program Files\Common Files\Symantec Shared\EENGINE\EPERSIST.DAT Object is locked skipped
C:\Program Files\LimeWire\Search Music\arcade fire.zip/Setup.exe Infected: not-a-virus:AdWare.Win32.Agent.zk skipped
C:\Program Files\LimeWire\Search Music\arcade fire.zip ZIP: infected - 1 skipped
C:\Program Files\SMART Technologies Inc\SMART Board Software\SMARTBoardService.log Object is locked skipped
C:\Program Files\Xpoint\agent\log\xpagent.log Object is locked skipped
C:\Program Files\Xpoint\agent\pages\lurknote.txt Object is locked skipped
C:\Program Files\Xpoint\SAS\bin\hotview.exe Infected: not-a-virus:RemoteAdmin.Win32.WinVNC.333 skipped
C:\Program Files\Xpoint\SAS\dat\ASYNCH-TSS\left\Admin.redolog Object is locked skipped
C:\Program Files\Xpoint\SAS\dat\ASYNCH-TSS\left\Galaxy.redolog Object is locked skipped
C:\Program Files\Xpoint\SAS\dat\ASYNCH-TSS\right\DISCO_ASYNCH_TSIN.redolog Object is locked skipped
C:\Program Files\Xpoint\SAS\dat\ASYNCH-TSS\right\DISCO_ASYNCH_TSMSG.redolog Object is locked skipped
C:\Program Files\Xpoint\SAS\dat\ASYNCH-TSS\right\DISCO_ASYNCH_TSOUT.redolog Object is locked skipped
C:\Program Files\Xpoint\SAS\logfile1.log Object is locked skipped
C:\Program Files\Xpoint\SAS\tssdebug.log Object is locked skipped
C:\Program Files\Xpoint\SAS\tsserver.log Object is locked skipped
C:\System Volume Information\MountPointManagerRemoteDatabase Object is locked skipped
C:\System Volume Information\_restore{ED3BE9FF-4CC6-4147-8470-65D902FC3376}\RP1152\A0197072.ini Infected: not-a-virus:AdWare.Win32.Sahat.ao skipped
C:\System Volume Information\_restore{ED3BE9FF-4CC6-4147-8470-65D902FC3376}\RP1152\A0197212.dll Infected: Packed.Win32.Monder.gen skipped
C:\System Volume Information\_restore{ED3BE9FF-4CC6-4147-8470-65D902FC3376}\RP1152\A0197214.dll Infected: Packed.Win32.Monder.gen skipped
C:\System Volume Information\_restore{ED3BE9FF-4CC6-4147-8470-65D902FC3376}\RP1153\A0197237.dll Infected: Packed.Win32.Monder.gen skipped
C:\System Volume Information\_restore{ED3BE9FF-4CC6-4147-8470-65D902FC3376}\RP1153\A0197239.dll Infected: Packed.Win32.Monder.gen skipped
C:\System Volume Information\_restore{ED3BE9FF-4CC6-4147-8470-65D902FC3376}\RP1153\A0197333.exe Infected: not-a-virus:RiskTool.Win32.Reboot.f skipped
C:\System Volume Information\_restore{ED3BE9FF-4CC6-4147-8470-65D902FC3376}\RP1153\A0197362.dll Infected: Packed.Win32.Monder.gen skipped
C:\System Volume Information\_restore{ED3BE9FF-4CC6-4147-8470-65D902FC3376}\RP1153\A0197365.dll Infected: Packed.Win32.Monder.gen skipped
C:\System Volume Information\_restore{ED3BE9FF-4CC6-4147-8470-65D902FC3376}\RP1153\A0198395.dll Infected: Packed.Win32.Monder.gen skipped
C:\System Volume Information\_restore{ED3BE9FF-4CC6-4147-8470-65D902FC3376}\RP1153\A0198397.dll Infected: Packed.Win32.Monder.gen skipped
C:\System Volume Information\_restore{ED3BE9FF-4CC6-4147-8470-65D902FC3376}\RP1153\change.log Object is locked skipped
C:\WINDOWS\Debug\PASSWD.LOG Object is locked skipped
C:\WINDOWS\Registration\{02D4B3F1-FD88-11D1-960D-00805FC79235}.{F5AF8574-3251-4AEB-9010-9FB1CCD486D9}.crmlog Object is locked skipped
C:\WINDOWS\SchedLgU.Txt Object is locked skipped
C:\WINDOWS\SoftwareDistribution\ReportingEvents.log Object is locked skipped
C:\WINDOWS\Sti_Trace.log Object is locked skipped
C:\WINDOWS\system32\CatRoot2\edb.log Object is locked skipped
C:\WINDOWS\system32\CatRoot2\tmp.edb Object is locked skipped
C:\WINDOWS\system32\config\ACEEvent.evt Object is locked skipped
C:\WINDOWS\system32\config\AppEvent.Evt Object is locked skipped
C:\WINDOWS\system32\config\DEFAULT Object is locked skipped
C:\WINDOWS\system32\config\default.LOG Object is locked skipped
C:\WINDOWS\system32\config\Internet.evt Object is locked skipped
C:\WINDOWS\system32\config\SAM Object is locked skipped
C:\WINDOWS\system32\config\SAM.LOG Object is locked skipped
C:\WINDOWS\system32\config\SecEvent.Evt Object is locked skipped
C:\WINDOWS\system32\config\SECURITY Object is locked skipped
C:\WINDOWS\system32\config\SECURITY.LOG Object is locked skipped
C:\WINDOWS\system32\config\SOFTWARE Object is locked skipped
C:\WINDOWS\system32\config\software.LOG Object is locked skipped
C:\WINDOWS\system32\config\SysEvent.Evt Object is locked skipped
C:\WINDOWS\system32\config\SYSTEM Object is locked skipped
C:\WINDOWS\system32\config\system.LOG Object is locked skipped
C:\WINDOWS\system32\MsDtc\MSDTC.LOG Object is locked skipped
C:\WINDOWS\system32\MsDtc\Trace\dtctrace.log Object is locked skipped
C:\WINDOWS\system32\opnlLDss.dll Infected: Packed.Win32.Monder.gen skipped
C:\WINDOWS\system32\pmnllklM.dll_old Infected: Packed.Win32.Monder.gen skipped
C:\WINDOWS\system32\rttrqkpd.dll_old Infected: Packed.Win32.Monder.gen skipped
C:\WINDOWS\system32\wbem\Repository\FS\INDEX.BTR Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\INDEX.MAP Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\MAPPING.VER Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\MAPPING1.MAP Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\MAPPING2.MAP Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\OBJECTS.DATA Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\OBJECTS.MAP Object is locked skipped
C:\WINDOWS\Web\def.htm Infected: not-virus:Hoax.HTML.Secureinvites.c skipped
C:\WINDOWS\wiadebug.log Object is locked skipped
C:\WINDOWS\wiaservc.log Object is locked skipped
C:\WINDOWS\WindowsUpdate.log Object is locked skipped
F:\System Volume Information\_restore{ED3BE9FF-4CC6-4147-8470-65D902FC3376}\RP1153\change.log Object is locked skipped
H:\Downloads\SmitfraudFix.exe/data.rar/SmitfraudFix/Reboot.exe Infected: not-a-virus:RiskTool.Win32.Reboot.f skipped
H:\Downloads\SmitfraudFix.exe/data.rar Infected: not-a-virus:RiskTool.Win32.Reboot.f skipped
H:\Downloads\SmitfraudFix.exe RarSFX: infected - 2 skipped
H:\iTunes Music\Feb 2008\elliot moose.mp3 Infected: Trojan-Downloader.WMA.Wimad.n skipped
H:\System Volume Information\_restore{ED3BE9FF-4CC6-4147-8470-65D902FC3376}\RP1153\change.log Object is locked skipped
Scan process completed.
Any help you can provide would be greatly appreciated!!!!
First Kaspersky Logfile - before Hijack this or Combofix was run:
(I will post Hijack This and Combofix in separate posts...)
-------------------------------------------------------------------------------
KASPERSKY ONLINE SCANNER REPORT
Tuesday, April 08, 2008 10:20:05 PM
Operating System: Microsoft Windows XP Home Edition, Service Pack 2 (Build 2600)
Kaspersky Online Scanner version: 5.0.98.0
Kaspersky Anti-Virus database last update: 8/04/2008
Kaspersky Anti-Virus database records: 690768
-------------------------------------------------------------------------------
Scan Settings:
Scan using the following antivirus database: extended
Scan Archives: true
Scan Mail Bases: true
Scan Target - My Computer:
A:\
C:\
D:\
E:\
F:\
H:\
Scan Statistics:
Total number of scanned objects: 106359
Number of viruses found: 10
Number of infected objects: 29
Number of suspicious objects: 0
Duration of the scan process: 05:35:00
Infected Object Name / Virus Name / Last Action
C:\Documents and Settings\All Users\Application Data\Bell\Security Manager\Logs\FirewallService04-08-2008--08-20-07.log Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Dr Watson\user.dmp Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Network\Downloader\qmgr0.dat Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Network\Downloader\qmgr1.dat Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Pure Networks\Log\logfile.nmctxth_exe.txt Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Pure Networks\Log\logfile.nmsrvc_exe.txt Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\06673101.cla Infected: Exploit.Java.Gimsh.a skipped
C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\0D6F374C.htm Infected: Exploit.HTML.IframeBof skipped
C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\0D8A072F.htm Infected: Exploit.HTML.IframeBof skipped
C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\0D9D031A.htm Infected: Exploit.HTML.IframeBof skipped
C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\39FD1BE1.wma Infected: Trojan-Downloader.WMA.Wimad.d skipped
C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\3A036FDA.wma Infected: Trojan-Downloader.WMA.Wimad.d skipped
C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\3A0619D6.wma Infected: Trojan-Downloader.WMA.Wimad.d skipped
C:\Documents and Settings\LocalService\Cookies\index.dat Object is locked skipped
C:\Documents and Settings\LocalService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat Object is locked skipped
C:\Documents and Settings\LocalService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped
C:\Documents and Settings\LocalService\Local Settings\History\History.IE5\index.dat Object is locked skipped
C:\Documents and Settings\LocalService\Local Settings\Temporary Internet Files\Content.IE5\index.dat Object is locked skipped
C:\Documents and Settings\LocalService\NTUSER.DAT Object is locked skipped
C:\Documents and Settings\LocalService\ntuser.dat.LOG Object is locked skipped
C:\Documents and Settings\NetworkService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat Object is locked skipped
C:\Documents and Settings\NetworkService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped
C:\Documents and Settings\NetworkService\NTUSER.DAT Object is locked skipped
C:\Documents and Settings\NetworkService\ntuser.dat.LOG Object is locked skipped
C:\Documents and Settings\Paul Zakoor\Application Data\Bell\Sympatico Security Advisor\client_gateway.log Object is locked skipped
C:\Documents and Settings\Paul Zakoor\Cookies\index.dat Object is locked skipped
C:\Documents and Settings\Paul Zakoor\Desktop\SmitfraudFix\Reboot.exe Infected: not-a-virus:RiskTool.Win32.Reboot.f skipped
C:\Documents and Settings\Paul Zakoor\Local Settings\Application Data\Microsoft\Feeds Cache\index.dat Object is locked skipped
C:\Documents and Settings\Paul Zakoor\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat Object is locked skipped
C:\Documents and Settings\Paul Zakoor\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped
C:\Documents and Settings\Paul Zakoor\Local Settings\History\History.IE5\index.dat Object is locked skipped
C:\Documents and Settings\Paul Zakoor\Local Settings\History\History.IE5\MSHist012008040820080409\index.dat Object is locked skipped
C:\Documents and Settings\Paul Zakoor\Local Settings\Temporary Internet Files\AntiPhishing\B3BB5BBA-E7D5-40AB-A041-A5B1C0B26C8F.dat Object is locked skipped
C:\Documents and Settings\Paul Zakoor\Local Settings\Temporary Internet Files\Content.IE5\1FM94O0S\tWIV_0020_front[1].png Object is locked skipped
C:\Documents and Settings\Paul Zakoor\Local Settings\Temporary Internet Files\Content.IE5\index.dat Object is locked skipped
C:\Documents and Settings\Paul Zakoor\Local Settings\Temporary Internet Files\Content.IE5\VORA3YEM\t0PjoCeQCoze[1].jpg Object is locked skipped
C:\Documents and Settings\Paul Zakoor\Local Settings\Temporary Internet Files\Content.IE5\XU83RQWP\tPK_0246_front[1].png Object is locked skipped
C:\Documents and Settings\Paul Zakoor\NTUSER.DAT Object is locked skipped
C:\Documents and Settings\Paul Zakoor\ntuser.dat.LOG Object is locked skipped
C:\Program Files\CA\PPRT\logs\2008-04-08.csv Object is locked skipped
C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcrst.dll Object is locked skipped
C:\Program Files\Common Files\Symantec Shared\EENGINE\EPERSIST.DAT Object is locked skipped
C:\Program Files\LimeWire\Search Music\arcade fire.zip/Setup.exe Infected: not-a-virus:AdWare.Win32.Agent.zk skipped
C:\Program Files\LimeWire\Search Music\arcade fire.zip ZIP: infected - 1 skipped
C:\Program Files\SMART Technologies Inc\SMART Board Software\SMARTBoardService.log Object is locked skipped
C:\Program Files\Xpoint\agent\log\xpagent.log Object is locked skipped
C:\Program Files\Xpoint\agent\pages\lurknote.txt Object is locked skipped
C:\Program Files\Xpoint\SAS\bin\hotview.exe Infected: not-a-virus:RemoteAdmin.Win32.WinVNC.333 skipped
C:\Program Files\Xpoint\SAS\dat\ASYNCH-TSS\left\Admin.redolog Object is locked skipped
C:\Program Files\Xpoint\SAS\dat\ASYNCH-TSS\left\Galaxy.redolog Object is locked skipped
C:\Program Files\Xpoint\SAS\dat\ASYNCH-TSS\right\DISCO_ASYNCH_TSIN.redolog Object is locked skipped
C:\Program Files\Xpoint\SAS\dat\ASYNCH-TSS\right\DISCO_ASYNCH_TSMSG.redolog Object is locked skipped
C:\Program Files\Xpoint\SAS\dat\ASYNCH-TSS\right\DISCO_ASYNCH_TSOUT.redolog Object is locked skipped
C:\Program Files\Xpoint\SAS\logfile1.log Object is locked skipped
C:\Program Files\Xpoint\SAS\tssdebug.log Object is locked skipped
C:\Program Files\Xpoint\SAS\tsserver.log Object is locked skipped
C:\System Volume Information\MountPointManagerRemoteDatabase Object is locked skipped
C:\System Volume Information\_restore{ED3BE9FF-4CC6-4147-8470-65D902FC3376}\RP1152\A0197072.ini Infected: not-a-virus:AdWare.Win32.Sahat.ao skipped
C:\System Volume Information\_restore{ED3BE9FF-4CC6-4147-8470-65D902FC3376}\RP1152\A0197212.dll Infected: Packed.Win32.Monder.gen skipped
C:\System Volume Information\_restore{ED3BE9FF-4CC6-4147-8470-65D902FC3376}\RP1152\A0197214.dll Infected: Packed.Win32.Monder.gen skipped
C:\System Volume Information\_restore{ED3BE9FF-4CC6-4147-8470-65D902FC3376}\RP1153\A0197237.dll Infected: Packed.Win32.Monder.gen skipped
C:\System Volume Information\_restore{ED3BE9FF-4CC6-4147-8470-65D902FC3376}\RP1153\A0197239.dll Infected: Packed.Win32.Monder.gen skipped
C:\System Volume Information\_restore{ED3BE9FF-4CC6-4147-8470-65D902FC3376}\RP1153\A0197333.exe Infected: not-a-virus:RiskTool.Win32.Reboot.f skipped
C:\System Volume Information\_restore{ED3BE9FF-4CC6-4147-8470-65D902FC3376}\RP1153\A0197362.dll Infected: Packed.Win32.Monder.gen skipped
C:\System Volume Information\_restore{ED3BE9FF-4CC6-4147-8470-65D902FC3376}\RP1153\A0197365.dll Infected: Packed.Win32.Monder.gen skipped
C:\System Volume Information\_restore{ED3BE9FF-4CC6-4147-8470-65D902FC3376}\RP1153\A0198395.dll Infected: Packed.Win32.Monder.gen skipped
C:\System Volume Information\_restore{ED3BE9FF-4CC6-4147-8470-65D902FC3376}\RP1153\A0198397.dll Infected: Packed.Win32.Monder.gen skipped
C:\System Volume Information\_restore{ED3BE9FF-4CC6-4147-8470-65D902FC3376}\RP1153\change.log Object is locked skipped
C:\WINDOWS\Debug\PASSWD.LOG Object is locked skipped
C:\WINDOWS\Registration\{02D4B3F1-FD88-11D1-960D-00805FC79235}.{F5AF8574-3251-4AEB-9010-9FB1CCD486D9}.crmlog Object is locked skipped
C:\WINDOWS\SchedLgU.Txt Object is locked skipped
C:\WINDOWS\SoftwareDistribution\ReportingEvents.log Object is locked skipped
C:\WINDOWS\Sti_Trace.log Object is locked skipped
C:\WINDOWS\system32\CatRoot2\edb.log Object is locked skipped
C:\WINDOWS\system32\CatRoot2\tmp.edb Object is locked skipped
C:\WINDOWS\system32\config\ACEEvent.evt Object is locked skipped
C:\WINDOWS\system32\config\AppEvent.Evt Object is locked skipped
C:\WINDOWS\system32\config\DEFAULT Object is locked skipped
C:\WINDOWS\system32\config\default.LOG Object is locked skipped
C:\WINDOWS\system32\config\Internet.evt Object is locked skipped
C:\WINDOWS\system32\config\SAM Object is locked skipped
C:\WINDOWS\system32\config\SAM.LOG Object is locked skipped
C:\WINDOWS\system32\config\SecEvent.Evt Object is locked skipped
C:\WINDOWS\system32\config\SECURITY Object is locked skipped
C:\WINDOWS\system32\config\SECURITY.LOG Object is locked skipped
C:\WINDOWS\system32\config\SOFTWARE Object is locked skipped
C:\WINDOWS\system32\config\software.LOG Object is locked skipped
C:\WINDOWS\system32\config\SysEvent.Evt Object is locked skipped
C:\WINDOWS\system32\config\SYSTEM Object is locked skipped
C:\WINDOWS\system32\config\system.LOG Object is locked skipped
C:\WINDOWS\system32\MsDtc\MSDTC.LOG Object is locked skipped
C:\WINDOWS\system32\MsDtc\Trace\dtctrace.log Object is locked skipped
C:\WINDOWS\system32\opnlLDss.dll Infected: Packed.Win32.Monder.gen skipped
C:\WINDOWS\system32\pmnllklM.dll_old Infected: Packed.Win32.Monder.gen skipped
C:\WINDOWS\system32\rttrqkpd.dll_old Infected: Packed.Win32.Monder.gen skipped
C:\WINDOWS\system32\wbem\Repository\FS\INDEX.BTR Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\INDEX.MAP Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\MAPPING.VER Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\MAPPING1.MAP Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\MAPPING2.MAP Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\OBJECTS.DATA Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\OBJECTS.MAP Object is locked skipped
C:\WINDOWS\Web\def.htm Infected: not-virus:Hoax.HTML.Secureinvites.c skipped
C:\WINDOWS\wiadebug.log Object is locked skipped
C:\WINDOWS\wiaservc.log Object is locked skipped
C:\WINDOWS\WindowsUpdate.log Object is locked skipped
F:\System Volume Information\_restore{ED3BE9FF-4CC6-4147-8470-65D902FC3376}\RP1153\change.log Object is locked skipped
H:\Downloads\SmitfraudFix.exe/data.rar/SmitfraudFix/Reboot.exe Infected: not-a-virus:RiskTool.Win32.Reboot.f skipped
H:\Downloads\SmitfraudFix.exe/data.rar Infected: not-a-virus:RiskTool.Win32.Reboot.f skipped
H:\Downloads\SmitfraudFix.exe RarSFX: infected - 2 skipped
H:\iTunes Music\Feb 2008\elliot moose.mp3 Infected: Trojan-Downloader.WMA.Wimad.n skipped
H:\System Volume Information\_restore{ED3BE9FF-4CC6-4147-8470-65D902FC3376}\RP1153\change.log Object is locked skipped
Scan process completed.