Hi. my laptop seems to have become infected with a virus. This was received via MSN when i clicked on a link from a known friend saying 'your photos have been placed on facebook'.
I am running CA eTrust AntiVirus which although after an initial scan found no problems has since detected a win32\matcash worm a couple of times during realtime scanning.
Attached are my kapersky and hijack this logs. The SpyBot scan found no immediate threats. Every time i reboot the laptop spybot asks if i want to allow a reg change for Flash Media in hklm\software\microsoft\windows\currentversion\run
-------------------------------------------------------------------------------
KASPERSKY ONLINE SCANNER REPORT
Wednesday, March 19, 2008 8:01:24 AM
Operating System: Microsoft Windows XP Professional, Service Pack 2 (Build 2600)
Kaspersky Online Scanner version: 5.0.98.0
Kaspersky Anti-Virus database last update: 18/03/2008
Kaspersky Anti-Virus database records: 638211
-------------------------------------------------------------------------------
Scan Settings:
Scan using the following antivirus database: extended
Scan Archives: true
Scan Mail Bases: true
Scan Target - My Computer:
C:\
D:\
E:\
Scan Statistics:
Total number of scanned objects: 64719
Number of viruses found: 1
Number of infected objects: 2
Number of suspicious objects: 0
Duration of the scan process: 02:52:31
Infected Object Name / Virus Name / Last Action
C:\SYSMGT\ETRAV6\DB\rtmaster.dbf Object is locked skipped
C:\SYSMGT\ETRAV6\DB\rtmaster.ntx Object is locked skipped
C:\System Volume Information\MountPointManagerRemoteDatabase Object is locked skipped
C:\System Volume Information\_restore{40AF1343-9B93-4851-9EB7-55CBB3CB6D44}\RP466\change.log Object is locked skipped
C:\WINNT\$NtUninstallKB824141$\user32.dll Object is locked skipped
C:\WINNT\$NtUninstallKB824141$\win32k.sys Object is locked skipped
C:\WINNT\$NtUninstallKB828035$\msgsvc.dll Object is locked skipped
C:\WINNT\$NtUninstallKB828035$\wkssvc.dll Object is locked skipped
C:\WINNT\$NtUninstallKB828741$\catsrv.dll Object is locked skipped
C:\WINNT\$NtUninstallKB828741$\catsrvut.dll Object is locked skipped
C:\WINNT\$NtUninstallKB828741$\clbcatex.dll Object is locked skipped
C:\WINNT\$NtUninstallKB828741$\clbcatq.dll Object is locked skipped
C:\WINNT\$NtUninstallKB828741$\colbact.dll Object is locked skipped
C:\WINNT\$NtUninstallKB828741$\comadmin.dll Object is locked skipped
C:\WINNT\$NtUninstallKB828741$\comrepl.exe Object is locked skipped
C:\WINNT\$NtUninstallKB828741$\comsvcs.dll Object is locked skipped
C:\WINNT\$NtUninstallKB828741$\comuid.dll Object is locked skipped
C:\WINNT\$NtUninstallKB828741$\es.dll Object is locked skipped
C:\WINNT\$NtUninstallKB828741$\migregdb.exe Object is locked skipped
C:\WINNT\$NtUninstallKB828741$\msdtcprx.dll Object is locked skipped
C:\WINNT\$NtUninstallKB828741$\msdtctm.dll Object is locked skipped
C:\WINNT\$NtUninstallKB828741$\msdtcuiu.dll Object is locked skipped
C:\WINNT\$NtUninstallKB828741$\mtxclu.dll Object is locked skipped
C:\WINNT\$NtUninstallKB828741$\mtxoci.dll Object is locked skipped
C:\WINNT\$NtUninstallKB828741$\ole32.dll Object is locked skipped
C:\WINNT\$NtUninstallKB828741$\rpcrt4.dll Object is locked skipped
C:\WINNT\$NtUninstallKB828741$\rpcss.dll Object is locked skipped
C:\WINNT\$NtUninstallKB828741$\txflog.dll Object is locked skipped
C:\WINNT\$NtUninstallKB833407$\bssym7.ttf Object is locked skipped
C:\WINNT\$NtUninstallKB835732$\callcont.dll Object is locked skipped
C:\WINNT\$NtUninstallKB835732$\cmdevtgprov.dll Object is locked skipped
C:\WINNT\$NtUninstallKB835732$\evtgprov.dll Object is locked skipped
C:\WINNT\$NtUninstallKB835732$\gdi32.dll Object is locked skipped
C:\WINNT\$NtUninstallKB835732$\h323.tsp Object is locked skipped
C:\WINNT\$NtUninstallKB835732$\h323msp.dll Object is locked skipped
C:\WINNT\$NtUninstallKB835732$\ipnathlp.dll Object is locked skipped
C:\WINNT\$NtUninstallKB835732$\lsasrv.dll Object is locked skipped
C:\WINNT\$NtUninstallKB835732$\mf3216.dll Object is locked skipped
C:\WINNT\$NtUninstallKB835732$\msasn1.dll Object is locked skipped
C:\WINNT\$NtUninstallKB835732$\msgina.dll Object is locked skipped
C:\WINNT\$NtUninstallKB835732$\mst120.dll Object is locked skipped
C:\WINNT\$NtUninstallKB835732$\nmcom.dll Object is locked skipped
C:\WINNT\$NtUninstallKB835732$\rtcdll.dll Object is locked skipped
C:\WINNT\$NtUninstallKB835732$\schannel.dll Object is locked skipped
C:\WINNT\$NtUninstallKB837001$\dao360.dll Object is locked skipped
C:\WINNT\$NtUninstallKB837001$\msexcl40.dll Object is locked skipped
C:\WINNT\$NtUninstallKB837001$\msjet40.dll Object is locked skipped
C:\WINNT\$NtUninstallKB837001$\msjetol1.dll Object is locked skipped
C:\WINNT\$NtUninstallKB837001$\msjetoledb40.dll Object is locked skipped
C:\WINNT\$NtUninstallKB837001$\msjtes40.dll Object is locked skipped
C:\WINNT\$NtUninstallKB837001$\mspbde40.dll Object is locked skipped
C:\WINNT\$NtUninstallKB837001$\msrepl40.dll Object is locked skipped
C:\WINNT\$NtUninstallKB837001$\mstext40.dll Object is locked skipped
C:\WINNT\$NtUninstallKB837001$\msxbde40.dll Object is locked skipped
C:\WINNT\$NtUninstallKB839645$\fldrclnr.dll Object is locked skipped
C:\WINNT\$NtUninstallKB839645$\shell32.dll Object is locked skipped
C:\WINNT\$NtUninstallKB839645$\shlwapi.dll Object is locked skipped
C:\WINNT\$NtUninstallKB839645$\sxs.dll Object is locked skipped
C:\WINNT\$NtUninstallKB839645$\xpsp2res.dll Object is locked skipped
C:\WINNT\$NtUninstallQ828026$\msdxm.ocx Object is locked skipped
C:\WINNT\$NtUninstallQ828026$\wmp.dll Object is locked skipped
C:\WINNT\CSC\00000001 Object is locked skipped
C:\WINNT\Debug\Netlogon.log Object is locked skipped
C:\WINNT\Debug\PASSWD.LOG Object is locked skipped
C:\WINNT\Internet Logs\Fujitsu Services_1205148649899.RDB Object is locked skipped
C:\WINNT\Internet Logs\IAMDB.RDB Object is locked skipped
C:\WINNT\Internet Logs\tvDebug.log Object is locked skipped
C:\WINNT\Internet Logs\UK090213LT.ldb Object is locked skipped
C:\WINNT\SchedLgU.Txt Object is locked skipped
C:\WINNT\SoftwareDistribution\DataStore\DataStore.edb Object is locked skipped
C:\WINNT\SoftwareDistribution\DataStore\Logs\edb.log Object is locked skipped
C:\WINNT\SoftwareDistribution\DataStore\Logs\tmp.edb Object is locked skipped
C:\WINNT\SoftwareDistribution\ReportingEvents.log Object is locked skipped
C:\WINNT\Sti_Trace.log Object is locked skipped
C:\WINNT\system32\config\AppEvent.Evt Object is locked skipped
C:\WINNT\system32\config\default Object is locked skipped
C:\WINNT\system32\config\default.LOG Object is locked skipped
C:\WINNT\system32\config\Internet.evt Object is locked skipped
C:\WINNT\system32\config\SAM Object is locked skipped
C:\WINNT\system32\config\SAM.LOG Object is locked skipped
C:\WINNT\system32\config\SecEvent.Evt Object is locked skipped
C:\WINNT\system32\config\SECURITY Object is locked skipped
C:\WINNT\system32\config\SECURITY.LOG Object is locked skipped
C:\WINNT\system32\config\software Object is locked skipped
C:\WINNT\system32\config\software.LOG Object is locked skipped
C:\WINNT\system32\config\SysEvent.Evt Object is locked skipped
C:\WINNT\system32\config\system Object is locked skipped
C:\WINNT\system32\config\system.LOG Object is locked skipped
C:\WINNT\system32\h323log.txt Object is locked skipped
C:\WINNT\system32\LogFiles\WUDF\WUDFTrace.etl Object is locked skipped
C:\WINNT\system32\wbem\Repository\FS\INDEX.BTR Object is locked skipped
C:\WINNT\system32\wbem\Repository\FS\INDEX.MAP Object is locked skipped
C:\WINNT\system32\wbem\Repository\FS\MAPPING.VER Object is locked skipped
C:\WINNT\system32\wbem\Repository\FS\MAPPING1.MAP Object is locked skipped
C:\WINNT\system32\wbem\Repository\FS\MAPPING2.MAP Object is locked skipped
C:\WINNT\system32\wbem\Repository\FS\OBJECTS.DATA Object is locked skipped
C:\WINNT\system32\wbem\Repository\FS\OBJECTS.MAP Object is locked skipped
C:\WINNT\Temp\Perflib_Perfdata_5a8.dat Object is locked skipped
C:\WINNT\Temp\vmware-vmount.log Object is locked skipped
C:\WINNT\Temp\ZLT03b4c.TMP Object is locked skipped
C:\WINNT\wiadebug.log Object is locked skipped
C:\WINNT\wiaservc.log Object is locked skipped
C:\WINNT\WindowsUpdate.log Object is locked skipped
D:\profiles\All Users\Application Data\Microsoft\Dr Watson\user.dmp Object is locked skipped
D:\profiles\All Users\Application Data\Microsoft\Network\Downloader\qmgr0.dat Object is locked skipped
D:\profiles\All Users\Application Data\Microsoft\Network\Downloader\qmgr1.dat Object is locked skipped
D:\profiles\All Users\Application Data\VMware\vmnetdhcp.leases Object is locked skipped
D:\profiles\LocalService.NT AUTHORITY.001\Cookies\index.dat Object is locked skipped
D:\profiles\LocalService.NT AUTHORITY.001\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat Object is locked skipped
D:\profiles\LocalService.NT AUTHORITY.001\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped
D:\profiles\LocalService.NT AUTHORITY.001\Local Settings\History\History.IE5\index.dat Object is locked skipped
D:\profiles\LocalService.NT AUTHORITY.001\Local Settings\Temporary Internet Files\Content.IE5\index.dat Object is locked skipped
D:\profiles\LocalService.NT AUTHORITY.001\NTUSER.DAT Object is locked skipped
D:\profiles\LocalService.NT AUTHORITY.001\NTUSER.DAT.LOG Object is locked skipped
D:\profiles\NetworkService.NT AUTHORITY.001\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat Object is locked skipped
D:\profiles\NetworkService.NT AUTHORITY.001\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped
D:\profiles\NetworkService.NT AUTHORITY.001\NTUSER.DAT Object is locked skipped
D:\profiles\NetworkService.NT AUTHORITY.001\NTUSER.DAT.LOG Object is locked skipped
D:\profiles\O'NeillR\Cookies\index.dat Object is locked skipped
D:\profiles\O'NeillR\Local Settings\Application Data\Microsoft\CardSpace\CardSpace.db Object is locked skipped
D:\profiles\O'NeillR\Local Settings\Application Data\Microsoft\CardSpace\CardSpace.db.shadow Object is locked skipped
D:\profiles\O'NeillR\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat Object is locked skipped
D:\profiles\O'NeillR\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped
D:\profiles\O'NeillR\Local Settings\History\History.IE5\index.dat Object is locked skipped
D:\profiles\O'NeillR\Local Settings\Temp\services.exe Object is locked skipped
D:\profiles\O'NeillR\Local Settings\Temp\~DF779.tmp Object is locked skipped
D:\profiles\O'NeillR\Local Settings\Temp\~DF79E.tmp Object is locked skipped
D:\profiles\O'NeillR\Local Settings\Temporary Internet Files\AntiPhishing\B3BB5BBA-E7D5-40AB-A041-A5B1C0B26C8F.dat Object is locked skipped
D:\profiles\O'NeillR\Local Settings\Temporary Internet Files\Content.IE5\7IJHE232\6736f989[1].exe Infected: Trojan-Downloader.Win32.Small.sth skipped
D:\profiles\O'NeillR\Local Settings\Temporary Internet Files\Content.IE5\index.dat Object is locked skipped
D:\profiles\O'NeillR\ntuser.dat Object is locked skipped
D:\profiles\O'NeillR\NTUSER.DAT.LOG Object is locked skipped
D:\profiles\O'NeillR\zriqhj.exe Infected: Trojan-Downloader.Win32.Small.sth skipped
D:\System Volume Information\_restore{40AF1343-9B93-4851-9EB7-55CBB3CB6D44}\RP466\change.log Object is locked skipped
Scan process completed.
---------------------------
Hijack this log posted in next post....
I am running CA eTrust AntiVirus which although after an initial scan found no problems has since detected a win32\matcash worm a couple of times during realtime scanning.
Attached are my kapersky and hijack this logs. The SpyBot scan found no immediate threats. Every time i reboot the laptop spybot asks if i want to allow a reg change for Flash Media in hklm\software\microsoft\windows\currentversion\run
-------------------------------------------------------------------------------
KASPERSKY ONLINE SCANNER REPORT
Wednesday, March 19, 2008 8:01:24 AM
Operating System: Microsoft Windows XP Professional, Service Pack 2 (Build 2600)
Kaspersky Online Scanner version: 5.0.98.0
Kaspersky Anti-Virus database last update: 18/03/2008
Kaspersky Anti-Virus database records: 638211
-------------------------------------------------------------------------------
Scan Settings:
Scan using the following antivirus database: extended
Scan Archives: true
Scan Mail Bases: true
Scan Target - My Computer:
C:\
D:\
E:\
Scan Statistics:
Total number of scanned objects: 64719
Number of viruses found: 1
Number of infected objects: 2
Number of suspicious objects: 0
Duration of the scan process: 02:52:31
Infected Object Name / Virus Name / Last Action
C:\SYSMGT\ETRAV6\DB\rtmaster.dbf Object is locked skipped
C:\SYSMGT\ETRAV6\DB\rtmaster.ntx Object is locked skipped
C:\System Volume Information\MountPointManagerRemoteDatabase Object is locked skipped
C:\System Volume Information\_restore{40AF1343-9B93-4851-9EB7-55CBB3CB6D44}\RP466\change.log Object is locked skipped
C:\WINNT\$NtUninstallKB824141$\user32.dll Object is locked skipped
C:\WINNT\$NtUninstallKB824141$\win32k.sys Object is locked skipped
C:\WINNT\$NtUninstallKB828035$\msgsvc.dll Object is locked skipped
C:\WINNT\$NtUninstallKB828035$\wkssvc.dll Object is locked skipped
C:\WINNT\$NtUninstallKB828741$\catsrv.dll Object is locked skipped
C:\WINNT\$NtUninstallKB828741$\catsrvut.dll Object is locked skipped
C:\WINNT\$NtUninstallKB828741$\clbcatex.dll Object is locked skipped
C:\WINNT\$NtUninstallKB828741$\clbcatq.dll Object is locked skipped
C:\WINNT\$NtUninstallKB828741$\colbact.dll Object is locked skipped
C:\WINNT\$NtUninstallKB828741$\comadmin.dll Object is locked skipped
C:\WINNT\$NtUninstallKB828741$\comrepl.exe Object is locked skipped
C:\WINNT\$NtUninstallKB828741$\comsvcs.dll Object is locked skipped
C:\WINNT\$NtUninstallKB828741$\comuid.dll Object is locked skipped
C:\WINNT\$NtUninstallKB828741$\es.dll Object is locked skipped
C:\WINNT\$NtUninstallKB828741$\migregdb.exe Object is locked skipped
C:\WINNT\$NtUninstallKB828741$\msdtcprx.dll Object is locked skipped
C:\WINNT\$NtUninstallKB828741$\msdtctm.dll Object is locked skipped
C:\WINNT\$NtUninstallKB828741$\msdtcuiu.dll Object is locked skipped
C:\WINNT\$NtUninstallKB828741$\mtxclu.dll Object is locked skipped
C:\WINNT\$NtUninstallKB828741$\mtxoci.dll Object is locked skipped
C:\WINNT\$NtUninstallKB828741$\ole32.dll Object is locked skipped
C:\WINNT\$NtUninstallKB828741$\rpcrt4.dll Object is locked skipped
C:\WINNT\$NtUninstallKB828741$\rpcss.dll Object is locked skipped
C:\WINNT\$NtUninstallKB828741$\txflog.dll Object is locked skipped
C:\WINNT\$NtUninstallKB833407$\bssym7.ttf Object is locked skipped
C:\WINNT\$NtUninstallKB835732$\callcont.dll Object is locked skipped
C:\WINNT\$NtUninstallKB835732$\cmdevtgprov.dll Object is locked skipped
C:\WINNT\$NtUninstallKB835732$\evtgprov.dll Object is locked skipped
C:\WINNT\$NtUninstallKB835732$\gdi32.dll Object is locked skipped
C:\WINNT\$NtUninstallKB835732$\h323.tsp Object is locked skipped
C:\WINNT\$NtUninstallKB835732$\h323msp.dll Object is locked skipped
C:\WINNT\$NtUninstallKB835732$\ipnathlp.dll Object is locked skipped
C:\WINNT\$NtUninstallKB835732$\lsasrv.dll Object is locked skipped
C:\WINNT\$NtUninstallKB835732$\mf3216.dll Object is locked skipped
C:\WINNT\$NtUninstallKB835732$\msasn1.dll Object is locked skipped
C:\WINNT\$NtUninstallKB835732$\msgina.dll Object is locked skipped
C:\WINNT\$NtUninstallKB835732$\mst120.dll Object is locked skipped
C:\WINNT\$NtUninstallKB835732$\nmcom.dll Object is locked skipped
C:\WINNT\$NtUninstallKB835732$\rtcdll.dll Object is locked skipped
C:\WINNT\$NtUninstallKB835732$\schannel.dll Object is locked skipped
C:\WINNT\$NtUninstallKB837001$\dao360.dll Object is locked skipped
C:\WINNT\$NtUninstallKB837001$\msexcl40.dll Object is locked skipped
C:\WINNT\$NtUninstallKB837001$\msjet40.dll Object is locked skipped
C:\WINNT\$NtUninstallKB837001$\msjetol1.dll Object is locked skipped
C:\WINNT\$NtUninstallKB837001$\msjetoledb40.dll Object is locked skipped
C:\WINNT\$NtUninstallKB837001$\msjtes40.dll Object is locked skipped
C:\WINNT\$NtUninstallKB837001$\mspbde40.dll Object is locked skipped
C:\WINNT\$NtUninstallKB837001$\msrepl40.dll Object is locked skipped
C:\WINNT\$NtUninstallKB837001$\mstext40.dll Object is locked skipped
C:\WINNT\$NtUninstallKB837001$\msxbde40.dll Object is locked skipped
C:\WINNT\$NtUninstallKB839645$\fldrclnr.dll Object is locked skipped
C:\WINNT\$NtUninstallKB839645$\shell32.dll Object is locked skipped
C:\WINNT\$NtUninstallKB839645$\shlwapi.dll Object is locked skipped
C:\WINNT\$NtUninstallKB839645$\sxs.dll Object is locked skipped
C:\WINNT\$NtUninstallKB839645$\xpsp2res.dll Object is locked skipped
C:\WINNT\$NtUninstallQ828026$\msdxm.ocx Object is locked skipped
C:\WINNT\$NtUninstallQ828026$\wmp.dll Object is locked skipped
C:\WINNT\CSC\00000001 Object is locked skipped
C:\WINNT\Debug\Netlogon.log Object is locked skipped
C:\WINNT\Debug\PASSWD.LOG Object is locked skipped
C:\WINNT\Internet Logs\Fujitsu Services_1205148649899.RDB Object is locked skipped
C:\WINNT\Internet Logs\IAMDB.RDB Object is locked skipped
C:\WINNT\Internet Logs\tvDebug.log Object is locked skipped
C:\WINNT\Internet Logs\UK090213LT.ldb Object is locked skipped
C:\WINNT\SchedLgU.Txt Object is locked skipped
C:\WINNT\SoftwareDistribution\DataStore\DataStore.edb Object is locked skipped
C:\WINNT\SoftwareDistribution\DataStore\Logs\edb.log Object is locked skipped
C:\WINNT\SoftwareDistribution\DataStore\Logs\tmp.edb Object is locked skipped
C:\WINNT\SoftwareDistribution\ReportingEvents.log Object is locked skipped
C:\WINNT\Sti_Trace.log Object is locked skipped
C:\WINNT\system32\config\AppEvent.Evt Object is locked skipped
C:\WINNT\system32\config\default Object is locked skipped
C:\WINNT\system32\config\default.LOG Object is locked skipped
C:\WINNT\system32\config\Internet.evt Object is locked skipped
C:\WINNT\system32\config\SAM Object is locked skipped
C:\WINNT\system32\config\SAM.LOG Object is locked skipped
C:\WINNT\system32\config\SecEvent.Evt Object is locked skipped
C:\WINNT\system32\config\SECURITY Object is locked skipped
C:\WINNT\system32\config\SECURITY.LOG Object is locked skipped
C:\WINNT\system32\config\software Object is locked skipped
C:\WINNT\system32\config\software.LOG Object is locked skipped
C:\WINNT\system32\config\SysEvent.Evt Object is locked skipped
C:\WINNT\system32\config\system Object is locked skipped
C:\WINNT\system32\config\system.LOG Object is locked skipped
C:\WINNT\system32\h323log.txt Object is locked skipped
C:\WINNT\system32\LogFiles\WUDF\WUDFTrace.etl Object is locked skipped
C:\WINNT\system32\wbem\Repository\FS\INDEX.BTR Object is locked skipped
C:\WINNT\system32\wbem\Repository\FS\INDEX.MAP Object is locked skipped
C:\WINNT\system32\wbem\Repository\FS\MAPPING.VER Object is locked skipped
C:\WINNT\system32\wbem\Repository\FS\MAPPING1.MAP Object is locked skipped
C:\WINNT\system32\wbem\Repository\FS\MAPPING2.MAP Object is locked skipped
C:\WINNT\system32\wbem\Repository\FS\OBJECTS.DATA Object is locked skipped
C:\WINNT\system32\wbem\Repository\FS\OBJECTS.MAP Object is locked skipped
C:\WINNT\Temp\Perflib_Perfdata_5a8.dat Object is locked skipped
C:\WINNT\Temp\vmware-vmount.log Object is locked skipped
C:\WINNT\Temp\ZLT03b4c.TMP Object is locked skipped
C:\WINNT\wiadebug.log Object is locked skipped
C:\WINNT\wiaservc.log Object is locked skipped
C:\WINNT\WindowsUpdate.log Object is locked skipped
D:\profiles\All Users\Application Data\Microsoft\Dr Watson\user.dmp Object is locked skipped
D:\profiles\All Users\Application Data\Microsoft\Network\Downloader\qmgr0.dat Object is locked skipped
D:\profiles\All Users\Application Data\Microsoft\Network\Downloader\qmgr1.dat Object is locked skipped
D:\profiles\All Users\Application Data\VMware\vmnetdhcp.leases Object is locked skipped
D:\profiles\LocalService.NT AUTHORITY.001\Cookies\index.dat Object is locked skipped
D:\profiles\LocalService.NT AUTHORITY.001\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat Object is locked skipped
D:\profiles\LocalService.NT AUTHORITY.001\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped
D:\profiles\LocalService.NT AUTHORITY.001\Local Settings\History\History.IE5\index.dat Object is locked skipped
D:\profiles\LocalService.NT AUTHORITY.001\Local Settings\Temporary Internet Files\Content.IE5\index.dat Object is locked skipped
D:\profiles\LocalService.NT AUTHORITY.001\NTUSER.DAT Object is locked skipped
D:\profiles\LocalService.NT AUTHORITY.001\NTUSER.DAT.LOG Object is locked skipped
D:\profiles\NetworkService.NT AUTHORITY.001\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat Object is locked skipped
D:\profiles\NetworkService.NT AUTHORITY.001\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped
D:\profiles\NetworkService.NT AUTHORITY.001\NTUSER.DAT Object is locked skipped
D:\profiles\NetworkService.NT AUTHORITY.001\NTUSER.DAT.LOG Object is locked skipped
D:\profiles\O'NeillR\Cookies\index.dat Object is locked skipped
D:\profiles\O'NeillR\Local Settings\Application Data\Microsoft\CardSpace\CardSpace.db Object is locked skipped
D:\profiles\O'NeillR\Local Settings\Application Data\Microsoft\CardSpace\CardSpace.db.shadow Object is locked skipped
D:\profiles\O'NeillR\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat Object is locked skipped
D:\profiles\O'NeillR\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped
D:\profiles\O'NeillR\Local Settings\History\History.IE5\index.dat Object is locked skipped
D:\profiles\O'NeillR\Local Settings\Temp\services.exe Object is locked skipped
D:\profiles\O'NeillR\Local Settings\Temp\~DF779.tmp Object is locked skipped
D:\profiles\O'NeillR\Local Settings\Temp\~DF79E.tmp Object is locked skipped
D:\profiles\O'NeillR\Local Settings\Temporary Internet Files\AntiPhishing\B3BB5BBA-E7D5-40AB-A041-A5B1C0B26C8F.dat Object is locked skipped
D:\profiles\O'NeillR\Local Settings\Temporary Internet Files\Content.IE5\7IJHE232\6736f989[1].exe Infected: Trojan-Downloader.Win32.Small.sth skipped
D:\profiles\O'NeillR\Local Settings\Temporary Internet Files\Content.IE5\index.dat Object is locked skipped
D:\profiles\O'NeillR\ntuser.dat Object is locked skipped
D:\profiles\O'NeillR\NTUSER.DAT.LOG Object is locked skipped
D:\profiles\O'NeillR\zriqhj.exe Infected: Trojan-Downloader.Win32.Small.sth skipped
D:\System Volume Information\_restore{40AF1343-9B93-4851-9EB7-55CBB3CB6D44}\RP466\change.log Object is locked skipped
Scan process completed.
---------------------------
Hijack this log posted in next post....