Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 2:04:14 PM, on 6/8/2008
Platform: Windows Vista (WinNT 6.00.1904)
MSIE: Internet Explorer v7.00 (7.00.6000.16643)
Boot mode: Normal
Running processes:
C:\Windows\system32\taskeng.exe
C:\Windows\system32\Dwm.exe
C:\Program Files\ActivIdentity\ActivClient\accrdsub.exe
C:\Windows\System32\WLTRAY.EXE
C:\Program Files\Tumbleweed\Desktop Validator\DVTrayApp.exe
C:\Windows\System32\mmlweb.exe
C:\Program Files\UltraMon\UltraMon.exe
C:\Program Files\Common Files\Symantec Shared\ccApp.exe
C:\Program Files\Symantec AntiVirus\VPTray.exe
C:\Program Files\Adobe\Acrobat 7.0\Distillr\acrotray.exe
C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe
C:\Windows\System32\rundll32.exe
C:\Program Files\Windows Sidebar\sidebar.exe
C:\Program Files\SlySoft\AnyDVD\AnyDVDtray.exe
C:\Program Files\Common Files\Ahead\Lib\NMBgMonitor.exe
C:\Program Files\Common Files\ACD Systems\EN\DevDetect.exe
C:\Windows\System32\rundll32.exe
C:\Windows\System32\rundll32.exe
C:\Program Files\ActivIdentity\ActivClient\acsagent.exe
C:\Program Files\WinZip\WZQKPICK.EXE
C:\Program Files\Common Files\Ahead\Lib\NMIndexStoreSvr.exe
C:\Program Files\ActivIdentity\ActivClient\acevents.exe
C:\Program Files\Internet Explorer\ieuser.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\Program Files\UltraMon\UltraMonTaskbar.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\WINDOWS\system32\Macromed\Flash\FlashUtil9f.exe
C:\Windows\Explorer.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://public.travis.amc.af.mil/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
O1 - Hosts: ::1 localhost
O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: (no name) - {53AF0310-DE20-445F-A487-170F547B5916} - C:\Windows\system32\xxyaxxUo.dll (file missing)
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
O2 - BHO: (no name) - {95D28845-B98B-4C0A-8885-08E32A97FAE7} - C:\Windows\system32\iifFWmlL.dll (file missing)
O2 - BHO: (no name) - {C83F6149-4782-4DAB-A478-96F195A376A2} - C:\Windows\system32\wvULcyAT.dll
O3 - Toolbar: Adobe PDF - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll
O4 - HKLM\..\Run: [Windows Defender] %ProgramFiles%\Windows Defender\MSASCui.exe -hide
O4 - HKLM\..\Run: [accrdsub] "C:\Program Files\ActivIdentity\ActivClient\accrdsub.exe"
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [Broadcom Wireless Manager UI] C:\WINDOWS\system32\WLTRAY.exe
O4 - HKLM\..\Run: [DVTrayApp] C:\Program Files\Tumbleweed\Desktop Validator\DVTrayApp.exe
O4 - HKLM\..\Run: [IntelWireless] "C:\Program Files\Intel\Wireless\Bin\ifrmewrk.exe" /tf Intel PROSet/Wireless
O4 - HKLM\..\Run: [IntelZeroConfig] "C:\Program Files\Intel\Wireless\bin\ZCfgSvc.exe"
O4 - HKLM\..\Run: [masqform.exe] C:\Program Files\PureEdge\Viewer 6.5\masqform.exe -RunOnce
O4 - HKLM\..\Run: [mmlweb] C:\WINDOWS\system32\mmlweb.exe
O4 - HKLM\..\Run: [nwiz] nwiz.exe /installquiet
O4 - HKLM\..\Run: [PWRISOVM.EXE] C:\Program Files\PowerISO\PWRISOVM.EXE
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime
O4 - HKLM\..\Run: [UltraMon] "C:\Program Files\UltraMon\UltraMon.exe" /auto
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [vptray] C:\PROGRA~1\SYMANT~1\VPTray.exe
O4 - HKLM\..\Run: [Acrobat Assistant 7.0] "C:\Program Files\Adobe\Acrobat 7.0\Distillr\Acrotray.exe"
O4 - HKLM\..\Run: [RemoteControl] "C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe"
O4 - HKLM\..\Run: [NeroFilterCheck] C:\Program Files\Common Files\Ahead\Lib\NeroCheck.exe
O4 - HKLM\..\Run: [6c4daf7c] rundll32.exe "C:\Windows\system32\lfdbtpxc.dll",b
O4 - HKLM\..\Run: [BM6f7e9ce0] Rundll32.exe "C:\Windows\system32\nafmudre.dll",s
O4 - HKLM\..\Run: [MSServer] rundll32.exe C:\Windows\system32\wvULcyAT.dll,#1
O4 - HKCU\..\Run: [Sidebar] C:\Program Files\Windows Sidebar\sidebar.exe /autoRun
O4 - HKCU\..\Run: [AnyDVD] C:\Program Files\SlySoft\AnyDVD\AnyDVDtray.exe
O4 - HKCU\..\Run: [BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] "C:\Program Files\Common Files\Ahead\Lib\NMBgMonitor.exe"
O4 - HKCU\..\Run: [Svconr] C:\Program Files\Svconr\Svconr.exe
O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
O4 - HKCU\..\Run: [Device Detector] DevDetect.exe -autorun
O4 - HKCU\..\Run: [MSServer] rundll32.exe C:\Users\snpperhd\AppData\Local\Temp\nnnLCrOE.dll,#1
O4 - HKCU\..\Run: [cmds] rundll32.exe C:\Users\snpperhd\AppData\Local\Temp\byXPgfCr.dll,c
O4 - HKCU\..\Run: [6c4daf7c] rundll32.exe "C:\Users\snpperhd\AppData\Local\Temp\itovcgrr.dll",b
O4 - HKCU\..\Run: [BM6f7e9ce0] Rundll32.exe "C:\Windows\system32\nafmudre.dll",s
O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-19\..\Run: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCenter (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'NETWORK SERVICE')
O4 - Global Startup: ActivClient Agent.lnk = C:\Program Files\ActivIdentity\ActivClient\acsagent.exe
O4 - Global Startup: Adobe Acrobat Speed Launcher.lnk = ?
O4 - Global Startup: Cisco Systems VPN Client.lnk = C:\Program Files\Cisco Systems\VPN Client\vpngui.exe
O4 - Global Startup: WinZip Quick Pick.lnk = C:\Program Files\WinZip\WZQKPICK.EXE
O8 - Extra context menu item: Convert link target to Adobe PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
O8 - Extra context menu item: Convert link target to existing PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
O8 - Extra context menu item: Convert selected links to Adobe PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECaptureSelLinks.html
O8 - Extra context menu item: Convert selected links to existing PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppendSelLinks.html
O8 - Extra context menu item: Convert selection to Adobe PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
O8 - Extra context menu item: Convert selection to existing PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
O8 - Extra context menu item: Convert to Adobe PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
O8 - Extra context menu item: Convert to existing PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~4\Office12\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~4\Office12\REFIEBAR.DLL
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\Windows\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\Windows\Network Diagnostic\xpnetdiag.exe
O13 - Gopher Prefix:
O16 - DPF: {01A88BB1-1174-41EC-ACCB-963509EAE56B} (SysProWmi Class) - http://support.dell.com/systemprofiler/SysPro.CAB
O16 - DPF: {0EB0E74A-2A76-4AB3-A7FB-9BD8C29F7F75} (CKAVWebScan Object) - http://www.kaspersky.com/kos/eng/partner/us/kavwebscan_unicode.cab
O20 - Winlogon Notify: ackpbsc - C:\WINDOWS\system32\ackpbsc.dll
O20 - Winlogon Notify: acunlock - C:\Program Files\ActivIdentity\ActivClient\acunlock.dll
O23 - Service: ActivClient Authentication Service (acachsrv) - ActivIdentity - C:\Program Files\ActivIdentity\ActivClient\acachsrv.exe
O23 - Service: ActivClient Auto-Update Service (acautoup) - ActivIdentity - C:\Program Files\ActivIdentity\ActivClient\acautoup.exe
O23 - Service: ActivClient Middleware Service (accoca) - ActivIdentity - C:\Program Files\ActivIdentity\ActivClient\accoca.exe
O23 - Service: Adobe LM Service - Adobe Systems - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
O23 - Service: Cisco Systems, Inc. VPN Service (CVPND) - Cisco Systems, Inc. - C:\Program Files\Cisco Systems\VPN Client\cvpnd.exe
O23 - Service: Symantec AntiVirus Definition Watcher (DefWatch) - Symantec Corporation - C:\Program Files\Symantec AntiVirus\DefWatch.exe
O23 - Service: DameWare Mini Remote Control (DWMRCS) - DameWare Development LLC - C:\WINDOWS\SYSTEM32\DWRCS.EXE
O23 - Service: Intel(R) PROSet/Wireless Event Log (EvtEng) - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\EvtEng.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1150\Intel 32\IDriverT.exe
O23 - Service: LiveUpdate - Symantec Corporation - C:\PROGRA~1\Symantec\LIVEUP~1\LUCOMS~1.EXE
O23 - Service: NBService - Nero AG - C:\Program Files\Nero\Nero 7\Nero BackItUp\NBService.exe
O23 - Service: NMIndexingService - Nero AG - C:\Program Files\Common Files\Ahead\Lib\NMIndexingService.exe
O23 - Service: Intel(R) PROSet/Wireless Registry Service (RegSrvc) - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe
O23 - Service: SAVRoam (SavRoam) - symantec - C:\Program Files\Symantec AntiVirus\SavRoam.exe
O23 - Service: SBSD Security Center Service (SBSDWSCService) - Safer Networking Ltd. - C:\Program Files\Spybot - Search & Destroy\SDWinSec.exe
O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
O23 - Service: Symantec AntiVirus - Symantec Corporation - C:\Program Files\Symantec AntiVirus\Rtvscan.exe
O23 - Service: Tumbleweed Desktop Validator - Tumbleweed Communications Inc. - C:\Program Files\Tumbleweed\Desktop Validator\DVService.exe
O23 - Service: Intel(R) PROSet/Wireless SSO Service (WLANKEEPER) - Intel(R) Corporation - C:\Program Files\Intel\Wireless\Bin\WLKeeper.exe
O23 - Service: Dell Wireless WLAN Tray Service (wltrysvc) - Unknown owner - C:\WINDOWS\System32\WLTRYSVC.EXE
--
End of file - 11762 bytes
KASPERSKY ONLINE SCANNER REPORT
Sunday, June 08, 2008 1:49:39 PM
Operating System: Microsoft Windows Vista Professional, (Build 6000)
Kaspersky Online Scanner version: 5.0.98.0
Kaspersky Anti-Virus database last update: 8/06/2008
Kaspersky Anti-Virus database records: 838913
Scan Settings
Scan using the following antivirus database extended
Scan Archives true
Scan Mail Bases true
Scan Target My Computer
C:\
D:\
Z:\
Scan Statistics
Total number of scanned objects 185296
Number of viruses found 4
Number of infected objects 6
Number of suspicious objects 0
Duration of the scan process 13:29:12
Infected Object Name Virus Name Last Action
C:\Boot\BCD Object is locked skipped
C:\Boot\BCD.LOG Object is locked skipped
C:\boot.ini Object is locked skipped
C:\From Rick\Ahead.Nero.v7.8.5.0.Incl.Keygen-EMBRACE\Ahead.Nero.v7.8.5.0.Incl.Keygen-EMBRACE\Nero-7.8.5.0_eng_trial.exe/Toolbar.exe Infected: not-a-virus:AdTool.Win32.MyWebSearch.bm skipped
C:\From Rick\Ahead.Nero.v7.8.5.0.Incl.Keygen-EMBRACE\Ahead.Nero.v7.8.5.0.Incl.Keygen-EMBRACE\Nero-7.8.5.0_eng_trial.exe RAR: infected - 1 skipped
C:\NTDETECT.COM Object is locked skipped
C:\ntldr Object is locked skipped
C:\Program Files\Common Files\Symantec Shared\EENGINE\EPERSIST.DAT Object is locked skipped
C:\Program Files\InstallShield Installation Information\{0B718C90-B510-11D6-A31B-00104B6F326C}\setup.ilg Object is locked skipped
C:\Program Files\InstallShield Installation Information\{1406B840-510C-11D8-A328-00104B6F326C}\setup.ilg Object is locked skipped
C:\Program Files\InstallShield Installation Information\{5624C000-B109-11D4-9DB4-00E0290FCAC5}\setup.ilg Object is locked skipped
C:\Program Files\InstallShield Installation Information\{609E54B0-6771-11D6-A31A-00104B6F326C}\setup.ilg Object is locked skipped
C:\Program Files\InstallShield Installation Information\{64A77F14-0E08-4A97-A859-E93CFF428756}\Setup.ilg Object is locked skipped
C:\Program Files\InstallShield Installation Information\{6FF66210-7EEA-11D6-A31A-00104B6F326C}\setup.ilg Object is locked skipped
C:\Program Files\InstallShield Installation Information\{73B4AA80-9E49-11D6-A31B-00104B6F326C}\setup.ilg Object is locked skipped
C:\Program Files\InstallShield Installation Information\{7A99D100-2AE9-11D6-A31A-00104B6F326C}\setup.ilg Object is locked skipped
C:\Program Files\InstallShield Installation Information\{7F142D56-3326-11D5-B229-002078017FBF}\setup.ilg Object is locked skipped
C:\Program Files\InstallShield Installation Information\{987F4E10-753A-11D5-A313-00104B6F326C}\setup.ilg Object is locked skipped
C:\Program Files\InstallShield Installation Information\{9F72EF8B-AEC9-4CA5-B483-143980AFD6FD}\setup.ilg Object is locked skipped
C:\Program Files\InstallShield Installation Information\{BE6890C7-31EF-478C-812E-1E2899ABFCA9}\Setup.ilg Object is locked skipped
C:\Program Files\InstallShield Installation Information\{C7F36150-3AC9-11D7-A322-00104B6F326C}\setup.ilg Object is locked skipped
C:\Program Files\InstallShield Installation Information\{E421B280-772B-11D7-A324-00104B6F326C}\setup.ilg Object is locked skipped
C:\Program Files\PowerISO\PWRISOVM.EXE Object is locked skipped
C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\19c5cf9c7b5dc9de3e548adb70398402_7ed3b18f-621d-418c-a665-883026a00249 Object is locked skipped
C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\7f315e812ffd0a877ef958b7a14567e5_7ed3b18f-621d-418c-a665-883026a00249 Object is locked skipped
C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\f686aace6942fb7f7ceb231212eef4a4_7ed3b18f-621d-418c-a665-883026a00249 Object is locked skipped
C:\ProgramData\Microsoft\User Account Pictures\Administrator.dat Object is locked skipped
C:\ProgramData\Microsoft\User Account Pictures\troy.ham.dat Object is locked skipped
C:\ProgramData\Symantec\Common Client\settings.bak Object is locked skipped
C:\ProgramData\Symantec\Common Client\settings.dat Object is locked skipped
C:\ProgramData\Symantec\SPBBC\BBConfig.log Object is locked skipped
C:\ProgramData\Symantec\SPBBC\BBDebug.log Object is locked skipped
C:\ProgramData\Symantec\SPBBC\BBDetect.log Object is locked skipped
C:\ProgramData\Symantec\SPBBC\BBNotify.log Object is locked skipped
C:\ProgramData\Symantec\SPBBC\BBRefr.log Object is locked skipped
C:\ProgramData\Symantec\SPBBC\BBSetCfg.log Object is locked skipped
C:\ProgramData\Symantec\SPBBC\BBSetCfg2.log Object is locked skipped
C:\ProgramData\Symantec\SPBBC\BBSetDev.log Object is locked skipped
C:\ProgramData\Symantec\SPBBC\BBSetLoc.log Object is locked skipped
C:\ProgramData\Symantec\SPBBC\BBSetUsr.log Object is locked skipped
C:\ProgramData\Symantec\SPBBC\BBStHash.log Object is locked skipped
C:\ProgramData\Symantec\SPBBC\BBValid.log Object is locked skipped
C:\ProgramData\Symantec\SPBBC\SPPolicy.log Object is locked skipped
C:\ProgramData\Symantec\SPBBC\SPStart.log Object is locked skipped
C:\ProgramData\Symantec\SPBBC\SPStop.log Object is locked skipped
C:\ProgramData\Symantec\SRTSP\SrtErEvt.log Object is locked skipped
C:\ProgramData\Symantec\SRTSP\SrtETmp\AD638B54.TMP Object is locked skipped
C:\ProgramData\Symantec\SRTSP\SrtETmp\FD03EC16.TMP Object is locked skipped
C:\ProgramData\Symantec\SRTSP\SrtMoEvt.log Object is locked skipped
C:\ProgramData\Symantec\SRTSP\SrtNvEvt.log Object is locked skipped
C:\ProgramData\Symantec\SRTSP\SrtScEvt.log Object is locked skipped
C:\ProgramData\Symantec\SRTSP\SrtTxFEvt.log Object is locked skipped
C:\ProgramData\Symantec\SRTSP\SrtViEvt.log Object is locked skipped
C:\Users\snpperhd\AppData\Local\Ahead\Nero Home\bl.db Object is locked skipped
C:\Users\snpperhd\AppData\Local\Ahead\Nero Home\is2.db Object is locked skipped
C:\Users\snpperhd\AppData\Local\Microsoft\Feeds Cache\index.dat Object is locked skipped
C:\Users\snpperhd\AppData\Local\Microsoft\Internet Explorer\MSIMGSIZ.DAT Object is locked skipped
C:\Users\snpperhd\AppData\Local\Microsoft\Windows\Explorer\thumbcache_1024.db Object is locked skipped
C:\Users\snpperhd\AppData\Local\Microsoft\Windows\Explorer\thumbcache_256.db Object is locked skipped
C:\Users\snpperhd\AppData\Local\Microsoft\Windows\Explorer\thumbcache_32.db Object is locked skipped
C:\Users\snpperhd\AppData\Local\Microsoft\Windows\Explorer\thumbcache_96.db Object is locked skipped
C:\Users\snpperhd\AppData\Local\Microsoft\Windows\Explorer\thumbcache_idx.db Object is locked skipped
C:\Users\snpperhd\AppData\Local\Microsoft\Windows\Explorer\thumbcache_sr.db Object is locked skipped
C:\Users\snpperhd\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat Object is locked skipped
C:\Users\snpperhd\AppData\Local\Microsoft\Windows\History\Low\History.IE5\index.dat Object is locked skipped
C:\Users\snpperhd\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat Object is locked skipped
C:\Users\snpperhd\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\AntiPhishing\B3BB5BBA-E7D5-40AB-A041-A5B1C0B26C8F.dat Object is locked skipped
C:\Users\snpperhd\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\index.dat Object is locked skipped
C:\Users\snpperhd\AppData\Local\Microsoft\Windows\UsrClass.dat Object is locked skipped
C:\Users\snpperhd\AppData\Local\Microsoft\Windows\UsrClass.dat.LOG1 Object is locked skipped
C:\Users\snpperhd\AppData\Local\Microsoft\Windows\UsrClass.dat.LOG2 Object is locked skipped
C:\Users\snpperhd\AppData\Local\Microsoft\Windows\UsrClass.dat{2c0b102e-2ec2-11dd-a3c9-00123fe51903}.TM.blf Object is locked skipped
C:\Users\snpperhd\AppData\Local\Microsoft\Windows\UsrClass.dat{2c0b102e-2ec2-11dd-a3c9-00123fe51903}.TMContainer00000000000000000001.regtrans-ms Object is locked skipped
C:\Users\snpperhd\AppData\Local\Microsoft\Windows\UsrClass.dat{2c0b102e-2ec2-11dd-a3c9-00123fe51903}.TMContainer00000000000000000002.regtrans-ms Object is locked skipped
C:\Users\snpperhd\AppData\Local\Microsoft\Windows Sidebar\Settings.ini Object is locked skipped
C:\Users\snpperhd\AppData\Local\Temp\FXSAPIDebugLogFile.txt Object is locked skipped
C:\Users\snpperhd\AppData\Roaming\Microsoft\Windows\Cookies\index.dat Object is locked skipped
C:\Users\snpperhd\AppData\Roaming\Microsoft\Windows\Cookies\Low\index.dat Object is locked skipped
C:\Users\snpperhd\NTUSER.DAT Object is locked skipped
C:\Users\snpperhd\ntuser.dat.LOG1 Object is locked skipped
C:\Users\snpperhd\ntuser.dat.LOG2 Object is locked skipped
C:\Users\snpperhd\NTUSER.DAT{0f69446d-6a70-11db-8eb3-985e31beb686}.TM.blf Object is locked skipped
C:\Users\snpperhd\NTUSER.DAT{0f69446d-6a70-11db-8eb3-985e31beb686}.TMContainer00000000000000000001.regtrans-ms Object is locked skipped
C:\Users\snpperhd\NTUSER.DAT{0f69446d-6a70-11db-8eb3-985e31beb686}.TMContainer00000000000000000002.regtrans-ms Object is locked skipped
C:\Users\troy.ham.amc-2k\Local Settings\Temp\NeroDemo12550\Toolbar.exe Infected: not-a-virus:AdTool.Win32.MyWebSearch.bm skipped
C:\Windows\Debug\PASSWD.LOG Object is locked skipped
C:\Windows\Debug\sam.log Object is locked skipped
C:\Windows\Debug\WIA\wiatrace.log Object is locked skipped
C:\Windows\diagerr.xml Object is locked skipped
C:\Windows\diagwrn.xml Object is locked skipped
C:\Windows\Internet Logs\tvDebug.log Object is locked skipped
C:\Windows\Logs\DPX\setupact.log Object is locked skipped
C:\Windows\Logs\DPX\setuperr.log Object is locked skipped
C:\Windows\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\SMSvcHost.exe.config Object is locked skipped
C:\Windows\Panther\catalogs\OfflineUpgradeStore.dat Object is locked skipped
C:\Windows\Panther\catalogs\OnlineEnvStore.dat Object is locked skipped
C:\Windows\Panther\catalogs\OnlineMigStore.dat Object is locked skipped
C:\Windows\Panther\catalogs\OnlineUpgradeStore.dat Object is locked skipped
C:\Windows\Panther\UnattendGC\diagerr.xml Object is locked skipped
C:\Windows\Panther\UnattendGC\diagwrn.xml Object is locked skipped
C:\Windows\Panther\UnattendGC\setupact.log Object is locked skipped
C:\Windows\Panther\UnattendGC\setuperr.log Object is locked skipped
C:\Windows\SchedLgU.Txt Object is locked skipped
C:\Windows\SE6BCF415.tmp Object is locked skipped
C:\Windows\security\database\secedit.sdb Object is locked skipped
C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-0.C7483456-A289-439d-8115-601632D005A0 Object is locked skipped
C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-1.C7483456-A289-439d-8115-601632D005A0 Object is locked skipped
C:\Windows\System32\ackwnbcl.dll Infected: Trojan.Win32.Pakes.day skipped
C:\Windows\System32\catroot2\edb.log Object is locked skipped
C:\Windows\System32\catroot2\{127D0A1D-4EF2-11D1-8608-00C04FC295EE}\catdb Object is locked skipped
C:\Windows\System32\catroot2\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\catdb Object is locked skipped
C:\Windows\System32\CCM\AAInst.mof Object is locked skipped
C:\Windows\System32\CCM\AAprov.dll Object is locked skipped
C:\Windows\System32\CCM\AdvertSched.dll Object is locked skipped
C:\Windows\System32\CCM\AssetAdvisor.dll Object is locked skipped
C:\Windows\System32\CCM\Bits_v15_Client_Setup.exe Object is locked skipped
C:\Windows\System32\CCM\Cache\XDM001B6.1.System\psshutdown.exe Infected: not-a-virus:RiskTool.Win32.PsShutdown.101 skipped
C:\Windows\System32\CCM\CCMAuthMessageHook.dll Object is locked skipped
C:\Windows\System32\CCM\ccmauthmessagehook.mof Object is locked skipped
C:\Windows\System32\CCM\ccmclasses.mof Object is locked skipped
C:\Windows\System32\CCM\CcmCTM.dll Object is locked skipped
C:\Windows\System32\CCM\CcmCTM_ps.dll Object is locked skipped
C:\Windows\System32\CCM\CcmDefaults.mof Object is locked skipped
C:\Windows\System32\CCM\CcmDTS.dll Object is locked skipped
C:\Windows\System32\CCM\ccmdump.exe Object is locked skipped
C:\Windows\System32\CCM\ccmevent.dll Object is locked skipped
C:\Windows\System32\CCM\CcmExec.mof Object is locked skipped
C:\Windows\System32\CCM\CcmExec_Global.mof Object is locked skipped
C:\Windows\System32\CCM\ccmhttp.dll Object is locked skipped
C:\Windows\System32\CCM\ccmid.dll Object is locked skipped
C:\Windows\System32\CCM\ccmident.dll Object is locked skipped
C:\Windows\System32\CCM\ccmperf.dll Object is locked skipped
C:\Windows\System32\CCM\ccmrepair.exe Object is locked skipped
C:\Windows\System32\CCM\ccmsenslogon.dll Object is locked skipped
C:\Windows\System32\CCM\CcmTask.dll Object is locked skipped
C:\Windows\System32\CCM\compver.ini Object is locked skipped
C:\Windows\System32\CCM\ContentAccess.dll Object is locked skipped
C:\Windows\System32\CCM\ContentTransferManager.mof Object is locked skipped
C:\Windows\System32\CCM\CPApplet.mof Object is locked skipped
C:\Windows\System32\CCM\DataTransferService.mof Object is locked skipped
C:\Windows\System32\CCM\ddrprov.dll Object is locked skipped
C:\Windows\System32\CCM\ddrprov.mof Object is locked skipped
C:\Windows\System32\CCM\EventClasses.mof Object is locked skipped
C:\Windows\System32\CCM\EventProvider.mof Object is locked skipped
C:\Windows\System32\CCM\ExecEngn.dll Object is locked skipped
C:\Windows\System32\CCM\execmgr.dll Object is locked skipped
C:\Windows\System32\CCM\FrameworkEvents.mof Object is locked skipped
C:\Windows\System32\CCM\FrameworkPerf.dll Object is locked skipped
C:\Windows\System32\CCM\hermes.ico Object is locked skipped
C:\Windows\System32\CCM\ImgDeployEvents.mof Object is locked skipped
C:\Windows\System32\CCM\InvCollectionTask.dll Object is locked skipped
C:\Windows\System32\CCM\InvDataStore.dll Object is locked skipped
C:\Windows\System32\CCM\InvEndPoint.dll Object is locked skipped
C:\Windows\System32\CCM\Inventory\Temp\skpswi.dat Object is locked skipped
C:\Windows\System32\CCM\InventoryAgentEndpoint.mof Object is locked skipped
C:\Windows\System32\CCM\InventoryAgentEvents.mof Object is locked skipped
C:\Windows\System32\CCM\InventoryAgentSchema.mof Object is locked skipped
C:\Windows\System32\CCM\InventoryDefaultPolicy.mof Object is locked skipped
C:\Windows\System32\CCM\InvFileCollectionTask.dll Object is locked skipped
C:\Windows\System32\CCM\InvFileSystemCollectionTask.dll Object is locked skipped
C:\Windows\System32\CCM\InvFileSystemQueryTask.dll Object is locked skipped
C:\Windows\System32\CCM\InvReportTask.dll Object is locked skipped
C:\Windows\System32\CCM\LocationServices.mof Object is locked skipped
C:\Windows\System32\CCM\LoggingClasses.mof Object is locked skipped
C:\Windows\System32\CCM\LoggingDefaults.mof Object is locked skipped
C:\Windows\System32\CCM\Logs\CAS.log Object is locked skipped
C:\Windows\System32\CCM\Logs\CcmExec.log Object is locked skipped
C:\Windows\System32\CCM\Logs\CertificateMaintenance.log Object is locked skipped
C:\Windows\System32\CCM\Logs\ClientIDManagerStartup.log Object is locked skipped
C:\Windows\System32\CCM\Logs\DataTransferService.log Object is locked skipped
C:\Windows\System32\CCM\Logs\execmgr.log Object is locked skipped
C:\Windows\System32\CCM\Logs\FileSystemFile.log Object is locked skipped
C:\Windows\System32\CCM\Logs\InventoryAgent.log Object is locked skipped
C:\Windows\System32\CCM\Logs\LocationServices.log Object is locked skipped
C:\Windows\System32\CCM\Logs\mtrmgr.log Object is locked skipped
C:\Windows\System32\CCM\Logs\PatchInstall.log Object is locked skipped
C:\Windows\System32\CCM\Logs\PatchUIMonitor.log Object is locked skipped
C:\Windows\System32\CCM\Logs\PolicyAgent.log Object is locked skipped
C:\Windows\System32\CCM\Logs\PolicyAgentProvider.log Object is locked skipped
C:\Windows\System32\CCM\Logs\PolicyEvaluator.log Object is locked skipped
C:\Windows\System32\CCM\Logs\Scheduler.log Object is locked skipped
C:\Windows\System32\CCM\Logs\SrcUpdateMgr.log Object is locked skipped
C:\Windows\System32\CCM\Logs\StatusAgent.log Object is locked skipped
C:\Windows\System32\CCM\lsdefault.mof Object is locked skipped
C:\Windows\System32\CCM\LSInterface.dll Object is locked skipped
C:\Windows\System32\CCM\mifprov.dll Object is locked skipped
C:\Windows\System32\CCM\mifprov.mof Object is locked skipped
C:\Windows\System32\CCM\MtrMgr.dll Object is locked skipped
C:\Windows\System32\CCM\PatchInstall.dll Object is locked skipped
C:\Windows\System32\CCM\PatchMgmtEvents.mof Object is locked skipped
C:\Windows\System32\CCM\PatchMgr.mof Object is locked skipped
C:\Windows\System32\CCM\PatchUIMonitor.dll Object is locked skipped
C:\Windows\System32\CCM\Perf\CcmFramework.h Object is locked skipped
C:\Windows\System32\CCM\Perf\CcmFramework.ini Object is locked skipped
C:\Windows\System32\CCM\PolicyAgentEndpoint.dll Object is locked skipped
C:\Windows\System32\CCM\PolicyAgentEvents.mof Object is locked skipped
C:\Windows\System32\CCM\PolicyAgentProvider.dll Object is locked skipped
C:\Windows\System32\CCM\PolicyClasses.mof Object is locked skipped
C:\Windows\System32\CCM\PolicyDefaults.mof Object is locked skipped
C:\Windows\System32\CCM\PolicyNamespaces.mof Object is locked skipped
C:\Windows\System32\CCM\PolicyProvider.mof Object is locked skipped
C:\Windows\System32\CCM\PolicyProvider2.mof Object is locked skipped
C:\Windows\System32\CCM\Prep.dll Object is locked skipped
C:\Windows\System32\CCM\PrepDrv.sys Object is locked skipped
C:\Windows\System32\CCM\RemoteToolsRegistryEvents.mof Object is locked skipped
C:\Windows\System32\CCM\RemoteToolsSchema.mof Object is locked skipped
C:\Windows\System32\CCM\RTConfiguration.dll Object is locked skipped
C:\Windows\System32\CCM\RTEndPoint.dll Object is locked skipped
C:\Windows\System32\CCM\Sched.dll Object is locked skipped
C:\Windows\System32\CCM\Scheduler.mof Object is locked skipped
C:\Windows\System32\CCM\ServiceData\LocalPayload\{0E58CB08-6DD6-4661-B3A6-1C3E297E6121} Object is locked skipped
C:\Windows\System32\CCM\ServiceData\LocalPayload\{324413E8-0950-4A0E-A67F-A2610EFEB719} Object is locked skipped
C:\Windows\System32\CCM\ServiceData\LocalPayload\{3EC9A507-EBA5-4C1E-AF14-0902EF80C629} Object is locked skipped
C:\Windows\System32\CCM\ServiceData\LocalPayload\{405BCDC0-6634-4665-983A-F05200E44718} Object is locked skipped
C:\Windows\System32\CCM\ServiceData\LocalPayload\{D9906031-7E58-44C7-9E5E-FCCA552F3EA5} Object is locked skipped
C:\Windows\System32\CCM\ServiceData\LocalPayload\{DD5EC5AA-D490-4A74-BB49-B4D6B340867F} Object is locked skipped
C:\Windows\System32\CCM\ServiceData\LocalPayload\{DE369DDB-CF4D-4026-A6AD-1E26D79C281E} Object is locked skipped
C:\Windows\System32\CCM\ServiceData\LocalPayload\{DE79A298-1EDB-4357-BF8E-79C2E1D2A610} Object is locked skipped
C:\Windows\System32\CCM\ServiceData\LocalPayload\{E353072B-B5E2-4F9F-86F3-133F0A93BC05} Object is locked skipped
C:\Windows\System32\CCM\ServiceData\Messaging\EndpointQueues\CertificateMaintenanceEndpoint\0000001P.msg Object is locked skipped
C:\Windows\System32\CCM\ServiceData\Messaging\EndpointQueues\CertificateMaintenanceEndpoint\0000001P.que Object is locked skipped
C:\Windows\System32\CCM\ServiceData\Messaging\EndpointQueues\CTMDTSReply\0000000B.msg Object is locked skipped
C:\Windows\System32\CCM\ServiceData\Messaging\EndpointQueues\CTMDTSReply\0000000B.que Object is locked skipped
C:\Windows\System32\CCM\ServiceData\Messaging\EndpointQueues\execmgr\0000001L.msg Object is locked skipped
C:\Windows\System32\CCM\ServiceData\Messaging\EndpointQueues\execmgr\0000001L.que Object is locked skipped
C:\Windows\System32\CCM\ServiceData\Messaging\EndpointQueues\InventoryAgent\00000034.msg Object is locked skipped
C:\Windows\System32\CCM\ServiceData\Messaging\EndpointQueues\InventoryAgent\00000034.que Object is locked skipped
C:\Windows\System32\CCM\ServiceData\Messaging\EndpointQueues\LS_ReplyLocations\0000000G.msg Object is locked skipped
C:\Windows\System32\CCM\ServiceData\Messaging\EndpointQueues\LS_ReplyLocations\0000000G.que Object is locked skipped
C:\Windows\System32\CCM\ServiceData\Messaging\EndpointQueues\LS_ScheduledCleanup\0000001U.msg Object is locked skipped
C:\Windows\System32\CCM\ServiceData\Messaging\EndpointQueues\LS_ScheduledCleanup\0000001U.que Object is locked skipped
C:\Windows\System32\CCM\ServiceData\Messaging\EndpointQueues\MtrMgr\00000001.msg Object is locked skipped
C:\Windows\System32\CCM\ServiceData\Messaging\EndpointQueues\MtrMgr\00000001.que Object is locked skipped
C:\Windows\System32\CCM\ServiceData\Messaging\EndpointQueues\PatchUIMonitor\00000001.msg Object is locked skipped
C:\Windows\System32\CCM\ServiceData\Messaging\EndpointQueues\PatchUIMonitor\00000001.que Object is locked skipped
C:\Windows\System32\CCM\ServiceData\Messaging\EndpointQueues\PolicyAgent_Cleanup\00000003.msg Object is locked skipped
C:\Windows\System32\CCM\ServiceData\Messaging\EndpointQueues\PolicyAgent_Cleanup\00000003.que Object is locked skipped
C:\Windows\System32\CCM\ServiceData\Messaging\EndpointQueues\PolicyAgent_PolicyDownload\00000004.msg Object is locked skipped
C:\Windows\System32\CCM\ServiceData\Messaging\EndpointQueues\PolicyAgent_PolicyDownload\00000004.que Object is locked skipped
C:\Windows\System32\CCM\ServiceData\Messaging\EndpointQueues\PolicyAgent_PolicyEvaluator\000000AY.msg Object is locked skipped
C:\Windows\System32\CCM\ServiceData\Messaging\EndpointQueues\PolicyAgent_PolicyEvaluator\000000AY.que Object is locked skipped
C:\Windows\System32\CCM\ServiceData\Messaging\EndpointQueues\PolicyAgent_ReplyAssignments\00000016.msg Object is locked skipped
C:\Windows\System32\CCM\ServiceData\Messaging\EndpointQueues\PolicyAgent_ReplyAssignments\00000016.que Object is locked skipped
C:\Windows\System32\CCM\ServiceData\Messaging\EndpointQueues\PolicyAgent_RequestAssignments\0000002W.msg Object is locked skipped
C:\Windows\System32\CCM\ServiceData\Messaging\EndpointQueues\PolicyAgent_RequestAssignments\0000002W.que Object is locked skipped
C:\Windows\System32\CCM\ServiceData\Messaging\EndpointQueues\PolicyAgent_ReRequestPolicy\00000001.msg Object is locked skipped
C:\Windows\System32\CCM\ServiceData\Messaging\EndpointQueues\PolicyAgent_ReRequestPolicy\00000001.que Object is locked skipped
C:\Windows\System32\CCM\ServiceData\Messaging\EndpointQueues\RemoteToolsAgent\00000001.msg Object is locked skipped
C:\Windows\System32\CCM\ServiceData\Messaging\EndpointQueues\RemoteToolsAgent\00000001.que Object is locked skipped
C:\Windows\System32\CCM\ServiceData\Messaging\EndpointQueues\SrcUpdateMgr\00000001.msg Object is locked skipped
C:\Windows\System32\CCM\ServiceData\Messaging\EndpointQueues\SrcUpdateMgr\00000001.que Object is locked skipped
C:\Windows\System32\CCM\ServiceData\Messaging\EndpointQueues\SWMTRReportGen\00000001.msg Object is locked skipped
C:\Windows\System32\CCM\ServiceData\Messaging\EndpointQueues\SWMTRReportGen\00000001.que Object is locked skipped
C:\Windows\System32\CCM\ServiceData\Messaging\EndpointQueues\UpdatesInstallMgr\00000001.msg Object is locked skipped
C:\Windows\System32\CCM\ServiceData\Messaging\EndpointQueues\UpdatesInstallMgr\00000001.que Object is locked skipped
C:\Windows\System32\CCM\ServiceData\Messaging\EndpointQueues\UploadProtocol\00000001.msg Object is locked skipped
C:\Windows\System32\CCM\ServiceData\Messaging\EndpointQueues\UploadProtocol\00000001.que Object is locked skipped
C:\Windows\System32\CCM\ServiceData\Messaging\OutgoingQueues\amp_[http]mp_locationmanager\00000005.msg Object is locked skipped
C:\Windows\System32\CCM\ServiceData\Messaging\OutgoingQueues\amp_[http]mp_locationmanager\00000005.que Object is locked skipped
C:\Windows\System32\CCM\ServiceData\Messaging\OutgoingQueues\mp_mp_ddrendpoint\00000001.msg Object is locked skipped
C:\Windows\System32\CCM\ServiceData\Messaging\OutgoingQueues\mp_mp_ddrendpoint\00000001.que Object is locked skipped
C:\Windows\System32\CCM\ServiceData\Messaging\OutgoingQueues\mp_mp_hinvendpoint\00000006.msg Object is locked skipped
C:\Windows\System32\CCM\ServiceData\Messaging\OutgoingQueues\mp_mp_hinvendpoint\00000006.que Object is locked skipped
C:\Windows\System32\CCM\ServiceData\Messaging\OutgoingQueues\mp_mp_hinvendpoint\00000007.msg Object is locked skipped
C:\Windows\System32\CCM\ServiceData\Messaging\OutgoingQueues\mp_mp_hinvendpoint\00000007.que Object is locked skipped
C:\Windows\System32\CCM\ServiceData\Messaging\OutgoingQueues\mp_mp_sinvendpoint\00000005.msg Object is locked skipped
C:\Windows\System32\CCM\ServiceData\Messaging\OutgoingQueues\mp_mp_sinvendpoint\00000005.que Object is locked skipped
C:\Windows\System32\CCM\ServiceData\Messaging\OutgoingQueues\mp_statusreceiver\0000001E.msg Object is locked skipped
C:\Windows\System32\CCM\ServiceData\Messaging\OutgoingQueues\mp_statusreceiver\0000001E.que Object is locked skipped
C:\Windows\System32\CCM\ServiceData\Messaging\OutgoingQueues\mp_statusreceiver\0000001F.msg Object is locked skipped
C:\Windows\System32\CCM\ServiceData\Messaging\OutgoingQueues\mp_statusreceiver\0000001F.que Object is locked skipped
C:\Windows\System32\CCM\ServiceData\Messaging\OutgoingQueues\mp_[http]mp_locationmanager\0000000T.msg Object is locked skipped
C:\Windows\System32\CCM\ServiceData\Messaging\OutgoingQueues\mp_[http]mp_locationmanager\0000000T.que Object is locked skipped
C:\Windows\System32\CCM\ServiceData\Messaging\OutgoingQueues\mp_[http]mp_policymanager\0000002S.msg Object is locked skipped
C:\Windows\System32\CCM\ServiceData\Messaging\OutgoingQueues\mp_[http]mp_policymanager\0000002S.que Object is locked skipped
C:\Windows\System32\CCM\smsccmld.dll Object is locked skipped
C:\Windows\System32\CCM\smsccmld.mof Object is locked skipped
C:\Windows\System32\CCM\SmsClient.mof Object is locked skipped
C:\Windows\System32\CCM\SmsClientProviders.mof Object is locked skipped
C:\Windows\System32\CCM\SmsCommon.mof Object is locked skipped
C:\Windows\System32\CCM\SmsEventClasses.mof Object is locked skipped
C:\Windows\System32\CCM\SmsEventLog.dll Object is locked skipped
C:\Windows\System32\CCM\SmsEventLogForwarderDefaults.mof Object is locked skipped
C:\Windows\System32\CCM\SmsInventoryProviders.mof Object is locked skipped
C:\Windows\System32\CCM\smsproc.dll Object is locked skipped
C:\Windows\System32\CCM\smsprov.mof Object is locked skipped
C:\Windows\System32\CCM\SmsRemoteControlProviders.mof Object is locked skipped
C:\Windows\System32\CCM\SrcUpdateEvents.mof Object is locked skipped
C:\Windows\System32\CCM\SrcUpdateMgr.dll Object is locked skipped
C:\Windows\System32\CCM\SrcUpdateMgr_ps.dll Object is locked skipped
C:\Windows\System32\CCM\SrcUpdatePolicy.mof Object is locked skipped
C:\Windows\System32\CCM\SrcUpdateSchema.mof Object is locked skipped
C:\Windows\System32\CCM\StandardEventForwarder.dll Object is locked skipped
C:\Windows\System32\CCM\StandardEventForwarderClasses.mof Object is locked skipped
C:\Windows\System32\CCM\StandardEventForwarderDefaults.mof Object is locked skipped
C:\Windows\System32\CCM\StatusAgent.dll Object is locked skipped
C:\Windows\System32\CCM\SWDistEvents.mof Object is locked skipped
C:\Windows\System32\CCM\SWDistPolicy.mof Object is locked skipped
C:\Windows\System32\CCM\SWDistSchema.mof Object is locked skipped
C:\Windows\System32\CCM\swmreport.dll Object is locked skipped
C:\Windows\System32\CCM\SWMtrEvents.mof Object is locked skipped
C:\Windows\System32\CCM\SWMtrPolicy.mof Object is locked skipped
C:\Windows\System32\CCM\SWMtrSchema.mof Object is locked skipped
C:\Windows\System32\CCM\UpdatesEvaluator.dll Object is locked skipped
C:\Windows\System32\CCM\Win32_USBDevice.mof Object is locked skipped
C:\Windows\System32\config\COMPONENTS Object is locked skipped
C:\Windows\System32\config\COMPONENTS.LOG1 Object is locked skipped
C:\Windows\System32\config\COMPONENTS.LOG2 Object is locked skipped
C:\Windows\System32\config\DEFAULT Object is locked skipped
C:\Windows\System32\config\DEFAULT.LOG1 Object is locked skipped
C:\Windows\System32\config\DEFAULT.LOG2 Object is locked skipped
C:\Windows\System32\config\SAM Object is locked skipped
C:\Windows\System32\config\SAM.LOG1 Object is locked skipped
C:\Windows\System32\config\SAM.LOG2 Object is locked skipped
C:\Windows\System32\config\SECURITY Object is locked skipped
C:\Windows\System32\config\SECURITY.LOG1 Object is locked skipped
C:\Windows\System32\config\SECURITY.LOG2 Object is locked skipped
C:\Windows\System32\config\SOFTWARE Object is locked skipped
C:\Windows\System32\config\SOFTWARE.LOG1 Object is locked skipped
C:\Windows\System32\config\SOFTWARE.LOG2 Object is locked skipped
C:\Windows\System32\config\SYSTEM Object is locked skipped
C:\Windows\System32\config\SYSTEM.LOG1 Object is locked skipped
C:\Windows\System32\config\SYSTEM.LOG2 Object is locked skipped
C:\Windows\System32\config\TxR\{250834B7-750C-494d-BDC3-DA86B6E2101B}.TM.blf Object is locked skipped
C:\Windows\System32\config\TxR\{250834B7-750C-494d-BDC3-DA86B6E2101B}.TMContainer00000000000000000001.regtrans-ms Object is locked skipped
C:\Windows\System32\config\TxR\{250834B7-750C-494d-BDC3-DA86B6E2101B}.TMContainer00000000000000000002.regtrans-ms Object is locked skipped
C:\Windows\System32\config\TxR\{250834B7-750C-494d-BDC3-DA86B6E2101B}.TMContainer00000000000000000003.regtrans-ms Object is locked skipped
C:\Windows\System32\config\TxR\{250834B7-750C-494d-BDC3-DA86B6E2101B}.TMContainer00000000000000000004.regtrans-ms Object is locked skipped
C:\Windows\System32\LogFiles\Scm\SCM.EVM Object is locked skipped
C:\Windows\System32\LogFiles\WUDF\WUDFTrace.etl Object is locked skipped
C:\Windows\System32\restore\MachineGuid.txt Object is locked skipped
C:\Windows\System32\spool\SpoolerETW.etl Object is locked skipped
C:\Windows\System32\vkmmbtys.dll Infected: Trojan-Downloader.Win32.Agent.seh skipped
C:\Windows\System32\wbem\AutoRecover\2B8B1A8B0ACD3EE28B421D3918DC1F29.mof Object is locked skipped
C:\Windows\System32\wbem\AutoRecover\3460B7617E0429A960E481B197F238A3.mof Object is locked skipped
C:\Windows\System32\wbem\Logs\WMITracing.log Object is locked skipped
C:\Windows\System32\wbem\Repository\INDEX.BTR Object is locked skipped
C:\Windows\System32\wbem\Repository\MAPPING1.MAP Object is locked skipped
C:\Windows\System32\wbem\Repository\MAPPING2.MAP Object is locked skipped
C:\Windows\System32\wbem\Repository\OBJECTS.DATA Object is locked skipped
C:\Windows\System32\winevt\Logs\Application.evtx Object is locked skipped
C:\Windows\System32\winevt\Logs\DFS Replication.evtx Object is locked skipped
C:\Windows\System32\winevt\Logs\HardwareEvents.evtx Object is locked skipped
C:\Windows\System32\winevt\Logs\Internet Explorer.evtx Object is locked skipped
C:\Windows\System32\winevt\Logs\Key Management Service.evtx Object is locked skipped
C:\Windows\System32\winevt\Logs\Media Center.evtx Object is locked skipped
C:\Windows\System32\winevt\Logs\Microsoft-Windows-Bits-Client%4Operational.evtx Object is locked skipped
C:\Windows\System32\winevt\Logs\Microsoft-Windows-CodeIntegrity%4Operational.evtx Object is locked skipped
C:\Windows\System32\winevt\Logs\Microsoft-Windows-Diagnosis-DPS%4Operational.evtx Object is locked skipped
C:\Windows\System32\winevt\Logs\Microsoft-Windows-Diagnosis-PLA%4Operational.evtx Object is locked skipped
C:\Windows\System32\winevt\Logs\Microsoft-Windows-Diagnostics-Networking%4Operational.evtx Object is locked skipped
C:\Windows\System32\winevt\Logs\Microsoft-Windows-Diagnostics-Performance%4Operational.evtx Object is locked skipped
C:\Windows\System32\winevt\Logs\Microsoft-Windows-DiskDiagnosticDataCollector%4Operational.evtx Object is locked skipped
C:\Windows\System32\winevt\Logs\Microsoft-Windows-DriverFrameworks-UserMode%4Operational.evtx Object is locked skipped
C:\Windows\System32\winevt\Logs\Microsoft-Windows-GroupPolicy%4Operational.evtx Object is locked skipped
C:\Windows\System32\winevt\Logs\Microsoft-Windows-International%4Operational.evtx Object is locked skipped
C:\Windows\System32\winevt\Logs\Microsoft-Windows-Kernel-WHEA.evtx Object is locked skipped
C:\Windows\System32\winevt\Logs\Microsoft-Windows-LanguagePackSetup%4Operational.evtx Object is locked skipped
C:\Windows\System32\winevt\Logs\Microsoft-Windows-MUI%4Operational.evtx Object is locked skipped
C:\Windows\System32\winevt\Logs\Microsoft-Windows-NetworkAccessProtection%4Operational.evtx Object is locked skipped
C:\Windows\System32\winevt\Logs\Microsoft-Windows-ReadyBoost%4Operational.evtx Object is locked skipped
C:\Windows\System32\winevt\Logs\Microsoft-Windows-ReliabilityAnalysisComponent%4Operational.evtx Object is locked skipped
C:\Windows\System32\winevt\Logs\Microsoft-Windows-RemoteAssistance%4Admin.evtx Object is locked skipped
C:\Windows\System32\winevt\Logs\Microsoft-Windows-RemoteAssistance%4Operational.evtx Object is locked skipped
C:\Windows\System32\winevt\Logs\Microsoft-Windows-Resource-Exhaustion-Detector%4Operational.evtx Object is locked skipped
C:\Windows\System32\winevt\Logs\Microsoft-Windows-Resource-Exhaustion-Resolver%4Operational.evtx Object is locked skipped
C:\Windows\System32\winevt\Logs\Microsoft-Windows-Resource-Leak-Diagnostic%4Operational.evtx Object is locked skipped
C:\Windows\System32\winevt\Logs\Microsoft-Windows-RestartManager%4Operational.evtx Object is locked skipped
C:\Windows\System32\winevt\Logs\Microsoft-Windows-TaskScheduler%4Operational.evtx Object is locked skipped
C:\Windows\System32\winevt\Logs\Microsoft-Windows-UAC-FileVirtualization%4Operational.evtx Object is locked skipped
C:\Windows\System32\winevt\Logs\Microsoft-Windows-WindowsUpdateClient%4Operational.evtx Object is locked skipped
C:\Windows\System32\winevt\Logs\Microsoft-Windows-WLAN-AutoConfig%4Operational.evtx Object is locked skipped
C:\Windows\System32\winevt\Logs\ODiag.evtx Object is locked skipped
C:\Windows\System32\winevt\Logs\OSession.evtx Object is locked skipped
C:\Windows\System32\winevt\Logs\Security.evtx Object is locked skipped
C:\Windows\System32\winevt\Logs\Setup.evtx Object is locked skipped
C:\Windows\System32\winevt\Logs\System.evtx Object is locked skipped
C:\Windows\System32\winevt\Logs\Tumbleweed.evtx Object is locked skipped
C:\Windows\System32\wpa.bak Object is locked skipped
C:\Windows\Tasks\desktop.ini Object is locked skipped
C:\Windows\winsxs\x86_microsoft-windows-n..n_service_datastore_31bf3856ad364e35_6.0.6000.16386_none_cef7ceb03914a67f\dnary.xsd Object is locked skipped
Scan process completed.
Scan saved at 2:04:14 PM, on 6/8/2008
Platform: Windows Vista (WinNT 6.00.1904)
MSIE: Internet Explorer v7.00 (7.00.6000.16643)
Boot mode: Normal
Running processes:
C:\Windows\system32\taskeng.exe
C:\Windows\system32\Dwm.exe
C:\Program Files\ActivIdentity\ActivClient\accrdsub.exe
C:\Windows\System32\WLTRAY.EXE
C:\Program Files\Tumbleweed\Desktop Validator\DVTrayApp.exe
C:\Windows\System32\mmlweb.exe
C:\Program Files\UltraMon\UltraMon.exe
C:\Program Files\Common Files\Symantec Shared\ccApp.exe
C:\Program Files\Symantec AntiVirus\VPTray.exe
C:\Program Files\Adobe\Acrobat 7.0\Distillr\acrotray.exe
C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe
C:\Windows\System32\rundll32.exe
C:\Program Files\Windows Sidebar\sidebar.exe
C:\Program Files\SlySoft\AnyDVD\AnyDVDtray.exe
C:\Program Files\Common Files\Ahead\Lib\NMBgMonitor.exe
C:\Program Files\Common Files\ACD Systems\EN\DevDetect.exe
C:\Windows\System32\rundll32.exe
C:\Windows\System32\rundll32.exe
C:\Program Files\ActivIdentity\ActivClient\acsagent.exe
C:\Program Files\WinZip\WZQKPICK.EXE
C:\Program Files\Common Files\Ahead\Lib\NMIndexStoreSvr.exe
C:\Program Files\ActivIdentity\ActivClient\acevents.exe
C:\Program Files\Internet Explorer\ieuser.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\Program Files\UltraMon\UltraMonTaskbar.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\WINDOWS\system32\Macromed\Flash\FlashUtil9f.exe
C:\Windows\Explorer.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://public.travis.amc.af.mil/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
O1 - Hosts: ::1 localhost
O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: (no name) - {53AF0310-DE20-445F-A487-170F547B5916} - C:\Windows\system32\xxyaxxUo.dll (file missing)
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
O2 - BHO: (no name) - {95D28845-B98B-4C0A-8885-08E32A97FAE7} - C:\Windows\system32\iifFWmlL.dll (file missing)
O2 - BHO: (no name) - {C83F6149-4782-4DAB-A478-96F195A376A2} - C:\Windows\system32\wvULcyAT.dll
O3 - Toolbar: Adobe PDF - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll
O4 - HKLM\..\Run: [Windows Defender] %ProgramFiles%\Windows Defender\MSASCui.exe -hide
O4 - HKLM\..\Run: [accrdsub] "C:\Program Files\ActivIdentity\ActivClient\accrdsub.exe"
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [Broadcom Wireless Manager UI] C:\WINDOWS\system32\WLTRAY.exe
O4 - HKLM\..\Run: [DVTrayApp] C:\Program Files\Tumbleweed\Desktop Validator\DVTrayApp.exe
O4 - HKLM\..\Run: [IntelWireless] "C:\Program Files\Intel\Wireless\Bin\ifrmewrk.exe" /tf Intel PROSet/Wireless
O4 - HKLM\..\Run: [IntelZeroConfig] "C:\Program Files\Intel\Wireless\bin\ZCfgSvc.exe"
O4 - HKLM\..\Run: [masqform.exe] C:\Program Files\PureEdge\Viewer 6.5\masqform.exe -RunOnce
O4 - HKLM\..\Run: [mmlweb] C:\WINDOWS\system32\mmlweb.exe
O4 - HKLM\..\Run: [nwiz] nwiz.exe /installquiet
O4 - HKLM\..\Run: [PWRISOVM.EXE] C:\Program Files\PowerISO\PWRISOVM.EXE
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime
O4 - HKLM\..\Run: [UltraMon] "C:\Program Files\UltraMon\UltraMon.exe" /auto
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [vptray] C:\PROGRA~1\SYMANT~1\VPTray.exe
O4 - HKLM\..\Run: [Acrobat Assistant 7.0] "C:\Program Files\Adobe\Acrobat 7.0\Distillr\Acrotray.exe"
O4 - HKLM\..\Run: [RemoteControl] "C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe"
O4 - HKLM\..\Run: [NeroFilterCheck] C:\Program Files\Common Files\Ahead\Lib\NeroCheck.exe
O4 - HKLM\..\Run: [6c4daf7c] rundll32.exe "C:\Windows\system32\lfdbtpxc.dll",b
O4 - HKLM\..\Run: [BM6f7e9ce0] Rundll32.exe "C:\Windows\system32\nafmudre.dll",s
O4 - HKLM\..\Run: [MSServer] rundll32.exe C:\Windows\system32\wvULcyAT.dll,#1
O4 - HKCU\..\Run: [Sidebar] C:\Program Files\Windows Sidebar\sidebar.exe /autoRun
O4 - HKCU\..\Run: [AnyDVD] C:\Program Files\SlySoft\AnyDVD\AnyDVDtray.exe
O4 - HKCU\..\Run: [BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] "C:\Program Files\Common Files\Ahead\Lib\NMBgMonitor.exe"
O4 - HKCU\..\Run: [Svconr] C:\Program Files\Svconr\Svconr.exe
O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
O4 - HKCU\..\Run: [Device Detector] DevDetect.exe -autorun
O4 - HKCU\..\Run: [MSServer] rundll32.exe C:\Users\snpperhd\AppData\Local\Temp\nnnLCrOE.dll,#1
O4 - HKCU\..\Run: [cmds] rundll32.exe C:\Users\snpperhd\AppData\Local\Temp\byXPgfCr.dll,c
O4 - HKCU\..\Run: [6c4daf7c] rundll32.exe "C:\Users\snpperhd\AppData\Local\Temp\itovcgrr.dll",b
O4 - HKCU\..\Run: [BM6f7e9ce0] Rundll32.exe "C:\Windows\system32\nafmudre.dll",s
O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-19\..\Run: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCenter (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'NETWORK SERVICE')
O4 - Global Startup: ActivClient Agent.lnk = C:\Program Files\ActivIdentity\ActivClient\acsagent.exe
O4 - Global Startup: Adobe Acrobat Speed Launcher.lnk = ?
O4 - Global Startup: Cisco Systems VPN Client.lnk = C:\Program Files\Cisco Systems\VPN Client\vpngui.exe
O4 - Global Startup: WinZip Quick Pick.lnk = C:\Program Files\WinZip\WZQKPICK.EXE
O8 - Extra context menu item: Convert link target to Adobe PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
O8 - Extra context menu item: Convert link target to existing PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
O8 - Extra context menu item: Convert selected links to Adobe PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECaptureSelLinks.html
O8 - Extra context menu item: Convert selected links to existing PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppendSelLinks.html
O8 - Extra context menu item: Convert selection to Adobe PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
O8 - Extra context menu item: Convert selection to existing PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
O8 - Extra context menu item: Convert to Adobe PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
O8 - Extra context menu item: Convert to existing PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~4\Office12\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~4\Office12\REFIEBAR.DLL
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\Windows\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\Windows\Network Diagnostic\xpnetdiag.exe
O13 - Gopher Prefix:
O16 - DPF: {01A88BB1-1174-41EC-ACCB-963509EAE56B} (SysProWmi Class) - http://support.dell.com/systemprofiler/SysPro.CAB
O16 - DPF: {0EB0E74A-2A76-4AB3-A7FB-9BD8C29F7F75} (CKAVWebScan Object) - http://www.kaspersky.com/kos/eng/partner/us/kavwebscan_unicode.cab
O20 - Winlogon Notify: ackpbsc - C:\WINDOWS\system32\ackpbsc.dll
O20 - Winlogon Notify: acunlock - C:\Program Files\ActivIdentity\ActivClient\acunlock.dll
O23 - Service: ActivClient Authentication Service (acachsrv) - ActivIdentity - C:\Program Files\ActivIdentity\ActivClient\acachsrv.exe
O23 - Service: ActivClient Auto-Update Service (acautoup) - ActivIdentity - C:\Program Files\ActivIdentity\ActivClient\acautoup.exe
O23 - Service: ActivClient Middleware Service (accoca) - ActivIdentity - C:\Program Files\ActivIdentity\ActivClient\accoca.exe
O23 - Service: Adobe LM Service - Adobe Systems - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
O23 - Service: Cisco Systems, Inc. VPN Service (CVPND) - Cisco Systems, Inc. - C:\Program Files\Cisco Systems\VPN Client\cvpnd.exe
O23 - Service: Symantec AntiVirus Definition Watcher (DefWatch) - Symantec Corporation - C:\Program Files\Symantec AntiVirus\DefWatch.exe
O23 - Service: DameWare Mini Remote Control (DWMRCS) - DameWare Development LLC - C:\WINDOWS\SYSTEM32\DWRCS.EXE
O23 - Service: Intel(R) PROSet/Wireless Event Log (EvtEng) - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\EvtEng.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1150\Intel 32\IDriverT.exe
O23 - Service: LiveUpdate - Symantec Corporation - C:\PROGRA~1\Symantec\LIVEUP~1\LUCOMS~1.EXE
O23 - Service: NBService - Nero AG - C:\Program Files\Nero\Nero 7\Nero BackItUp\NBService.exe
O23 - Service: NMIndexingService - Nero AG - C:\Program Files\Common Files\Ahead\Lib\NMIndexingService.exe
O23 - Service: Intel(R) PROSet/Wireless Registry Service (RegSrvc) - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe
O23 - Service: SAVRoam (SavRoam) - symantec - C:\Program Files\Symantec AntiVirus\SavRoam.exe
O23 - Service: SBSD Security Center Service (SBSDWSCService) - Safer Networking Ltd. - C:\Program Files\Spybot - Search & Destroy\SDWinSec.exe
O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
O23 - Service: Symantec AntiVirus - Symantec Corporation - C:\Program Files\Symantec AntiVirus\Rtvscan.exe
O23 - Service: Tumbleweed Desktop Validator - Tumbleweed Communications Inc. - C:\Program Files\Tumbleweed\Desktop Validator\DVService.exe
O23 - Service: Intel(R) PROSet/Wireless SSO Service (WLANKEEPER) - Intel(R) Corporation - C:\Program Files\Intel\Wireless\Bin\WLKeeper.exe
O23 - Service: Dell Wireless WLAN Tray Service (wltrysvc) - Unknown owner - C:\WINDOWS\System32\WLTRYSVC.EXE
--
End of file - 11762 bytes
KASPERSKY ONLINE SCANNER REPORT
Sunday, June 08, 2008 1:49:39 PM
Operating System: Microsoft Windows Vista Professional, (Build 6000)
Kaspersky Online Scanner version: 5.0.98.0
Kaspersky Anti-Virus database last update: 8/06/2008
Kaspersky Anti-Virus database records: 838913
Scan Settings
Scan using the following antivirus database extended
Scan Archives true
Scan Mail Bases true
Scan Target My Computer
C:\
D:\
Z:\
Scan Statistics
Total number of scanned objects 185296
Number of viruses found 4
Number of infected objects 6
Number of suspicious objects 0
Duration of the scan process 13:29:12
Infected Object Name Virus Name Last Action
C:\Boot\BCD Object is locked skipped
C:\Boot\BCD.LOG Object is locked skipped
C:\boot.ini Object is locked skipped
C:\From Rick\Ahead.Nero.v7.8.5.0.Incl.Keygen-EMBRACE\Ahead.Nero.v7.8.5.0.Incl.Keygen-EMBRACE\Nero-7.8.5.0_eng_trial.exe/Toolbar.exe Infected: not-a-virus:AdTool.Win32.MyWebSearch.bm skipped
C:\From Rick\Ahead.Nero.v7.8.5.0.Incl.Keygen-EMBRACE\Ahead.Nero.v7.8.5.0.Incl.Keygen-EMBRACE\Nero-7.8.5.0_eng_trial.exe RAR: infected - 1 skipped
C:\NTDETECT.COM Object is locked skipped
C:\ntldr Object is locked skipped
C:\Program Files\Common Files\Symantec Shared\EENGINE\EPERSIST.DAT Object is locked skipped
C:\Program Files\InstallShield Installation Information\{0B718C90-B510-11D6-A31B-00104B6F326C}\setup.ilg Object is locked skipped
C:\Program Files\InstallShield Installation Information\{1406B840-510C-11D8-A328-00104B6F326C}\setup.ilg Object is locked skipped
C:\Program Files\InstallShield Installation Information\{5624C000-B109-11D4-9DB4-00E0290FCAC5}\setup.ilg Object is locked skipped
C:\Program Files\InstallShield Installation Information\{609E54B0-6771-11D6-A31A-00104B6F326C}\setup.ilg Object is locked skipped
C:\Program Files\InstallShield Installation Information\{64A77F14-0E08-4A97-A859-E93CFF428756}\Setup.ilg Object is locked skipped
C:\Program Files\InstallShield Installation Information\{6FF66210-7EEA-11D6-A31A-00104B6F326C}\setup.ilg Object is locked skipped
C:\Program Files\InstallShield Installation Information\{73B4AA80-9E49-11D6-A31B-00104B6F326C}\setup.ilg Object is locked skipped
C:\Program Files\InstallShield Installation Information\{7A99D100-2AE9-11D6-A31A-00104B6F326C}\setup.ilg Object is locked skipped
C:\Program Files\InstallShield Installation Information\{7F142D56-3326-11D5-B229-002078017FBF}\setup.ilg Object is locked skipped
C:\Program Files\InstallShield Installation Information\{987F4E10-753A-11D5-A313-00104B6F326C}\setup.ilg Object is locked skipped
C:\Program Files\InstallShield Installation Information\{9F72EF8B-AEC9-4CA5-B483-143980AFD6FD}\setup.ilg Object is locked skipped
C:\Program Files\InstallShield Installation Information\{BE6890C7-31EF-478C-812E-1E2899ABFCA9}\Setup.ilg Object is locked skipped
C:\Program Files\InstallShield Installation Information\{C7F36150-3AC9-11D7-A322-00104B6F326C}\setup.ilg Object is locked skipped
C:\Program Files\InstallShield Installation Information\{E421B280-772B-11D7-A324-00104B6F326C}\setup.ilg Object is locked skipped
C:\Program Files\PowerISO\PWRISOVM.EXE Object is locked skipped
C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\19c5cf9c7b5dc9de3e548adb70398402_7ed3b18f-621d-418c-a665-883026a00249 Object is locked skipped
C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\7f315e812ffd0a877ef958b7a14567e5_7ed3b18f-621d-418c-a665-883026a00249 Object is locked skipped
C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\f686aace6942fb7f7ceb231212eef4a4_7ed3b18f-621d-418c-a665-883026a00249 Object is locked skipped
C:\ProgramData\Microsoft\User Account Pictures\Administrator.dat Object is locked skipped
C:\ProgramData\Microsoft\User Account Pictures\troy.ham.dat Object is locked skipped
C:\ProgramData\Symantec\Common Client\settings.bak Object is locked skipped
C:\ProgramData\Symantec\Common Client\settings.dat Object is locked skipped
C:\ProgramData\Symantec\SPBBC\BBConfig.log Object is locked skipped
C:\ProgramData\Symantec\SPBBC\BBDebug.log Object is locked skipped
C:\ProgramData\Symantec\SPBBC\BBDetect.log Object is locked skipped
C:\ProgramData\Symantec\SPBBC\BBNotify.log Object is locked skipped
C:\ProgramData\Symantec\SPBBC\BBRefr.log Object is locked skipped
C:\ProgramData\Symantec\SPBBC\BBSetCfg.log Object is locked skipped
C:\ProgramData\Symantec\SPBBC\BBSetCfg2.log Object is locked skipped
C:\ProgramData\Symantec\SPBBC\BBSetDev.log Object is locked skipped
C:\ProgramData\Symantec\SPBBC\BBSetLoc.log Object is locked skipped
C:\ProgramData\Symantec\SPBBC\BBSetUsr.log Object is locked skipped
C:\ProgramData\Symantec\SPBBC\BBStHash.log Object is locked skipped
C:\ProgramData\Symantec\SPBBC\BBValid.log Object is locked skipped
C:\ProgramData\Symantec\SPBBC\SPPolicy.log Object is locked skipped
C:\ProgramData\Symantec\SPBBC\SPStart.log Object is locked skipped
C:\ProgramData\Symantec\SPBBC\SPStop.log Object is locked skipped
C:\ProgramData\Symantec\SRTSP\SrtErEvt.log Object is locked skipped
C:\ProgramData\Symantec\SRTSP\SrtETmp\AD638B54.TMP Object is locked skipped
C:\ProgramData\Symantec\SRTSP\SrtETmp\FD03EC16.TMP Object is locked skipped
C:\ProgramData\Symantec\SRTSP\SrtMoEvt.log Object is locked skipped
C:\ProgramData\Symantec\SRTSP\SrtNvEvt.log Object is locked skipped
C:\ProgramData\Symantec\SRTSP\SrtScEvt.log Object is locked skipped
C:\ProgramData\Symantec\SRTSP\SrtTxFEvt.log Object is locked skipped
C:\ProgramData\Symantec\SRTSP\SrtViEvt.log Object is locked skipped
C:\Users\snpperhd\AppData\Local\Ahead\Nero Home\bl.db Object is locked skipped
C:\Users\snpperhd\AppData\Local\Ahead\Nero Home\is2.db Object is locked skipped
C:\Users\snpperhd\AppData\Local\Microsoft\Feeds Cache\index.dat Object is locked skipped
C:\Users\snpperhd\AppData\Local\Microsoft\Internet Explorer\MSIMGSIZ.DAT Object is locked skipped
C:\Users\snpperhd\AppData\Local\Microsoft\Windows\Explorer\thumbcache_1024.db Object is locked skipped
C:\Users\snpperhd\AppData\Local\Microsoft\Windows\Explorer\thumbcache_256.db Object is locked skipped
C:\Users\snpperhd\AppData\Local\Microsoft\Windows\Explorer\thumbcache_32.db Object is locked skipped
C:\Users\snpperhd\AppData\Local\Microsoft\Windows\Explorer\thumbcache_96.db Object is locked skipped
C:\Users\snpperhd\AppData\Local\Microsoft\Windows\Explorer\thumbcache_idx.db Object is locked skipped
C:\Users\snpperhd\AppData\Local\Microsoft\Windows\Explorer\thumbcache_sr.db Object is locked skipped
C:\Users\snpperhd\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat Object is locked skipped
C:\Users\snpperhd\AppData\Local\Microsoft\Windows\History\Low\History.IE5\index.dat Object is locked skipped
C:\Users\snpperhd\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat Object is locked skipped
C:\Users\snpperhd\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\AntiPhishing\B3BB5BBA-E7D5-40AB-A041-A5B1C0B26C8F.dat Object is locked skipped
C:\Users\snpperhd\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\index.dat Object is locked skipped
C:\Users\snpperhd\AppData\Local\Microsoft\Windows\UsrClass.dat Object is locked skipped
C:\Users\snpperhd\AppData\Local\Microsoft\Windows\UsrClass.dat.LOG1 Object is locked skipped
C:\Users\snpperhd\AppData\Local\Microsoft\Windows\UsrClass.dat.LOG2 Object is locked skipped
C:\Users\snpperhd\AppData\Local\Microsoft\Windows\UsrClass.dat{2c0b102e-2ec2-11dd-a3c9-00123fe51903}.TM.blf Object is locked skipped
C:\Users\snpperhd\AppData\Local\Microsoft\Windows\UsrClass.dat{2c0b102e-2ec2-11dd-a3c9-00123fe51903}.TMContainer00000000000000000001.regtrans-ms Object is locked skipped
C:\Users\snpperhd\AppData\Local\Microsoft\Windows\UsrClass.dat{2c0b102e-2ec2-11dd-a3c9-00123fe51903}.TMContainer00000000000000000002.regtrans-ms Object is locked skipped
C:\Users\snpperhd\AppData\Local\Microsoft\Windows Sidebar\Settings.ini Object is locked skipped
C:\Users\snpperhd\AppData\Local\Temp\FXSAPIDebugLogFile.txt Object is locked skipped
C:\Users\snpperhd\AppData\Roaming\Microsoft\Windows\Cookies\index.dat Object is locked skipped
C:\Users\snpperhd\AppData\Roaming\Microsoft\Windows\Cookies\Low\index.dat Object is locked skipped
C:\Users\snpperhd\NTUSER.DAT Object is locked skipped
C:\Users\snpperhd\ntuser.dat.LOG1 Object is locked skipped
C:\Users\snpperhd\ntuser.dat.LOG2 Object is locked skipped
C:\Users\snpperhd\NTUSER.DAT{0f69446d-6a70-11db-8eb3-985e31beb686}.TM.blf Object is locked skipped
C:\Users\snpperhd\NTUSER.DAT{0f69446d-6a70-11db-8eb3-985e31beb686}.TMContainer00000000000000000001.regtrans-ms Object is locked skipped
C:\Users\snpperhd\NTUSER.DAT{0f69446d-6a70-11db-8eb3-985e31beb686}.TMContainer00000000000000000002.regtrans-ms Object is locked skipped
C:\Users\troy.ham.amc-2k\Local Settings\Temp\NeroDemo12550\Toolbar.exe Infected: not-a-virus:AdTool.Win32.MyWebSearch.bm skipped
C:\Windows\Debug\PASSWD.LOG Object is locked skipped
C:\Windows\Debug\sam.log Object is locked skipped
C:\Windows\Debug\WIA\wiatrace.log Object is locked skipped
C:\Windows\diagerr.xml Object is locked skipped
C:\Windows\diagwrn.xml Object is locked skipped
C:\Windows\Internet Logs\tvDebug.log Object is locked skipped
C:\Windows\Logs\DPX\setupact.log Object is locked skipped
C:\Windows\Logs\DPX\setuperr.log Object is locked skipped
C:\Windows\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\SMSvcHost.exe.config Object is locked skipped
C:\Windows\Panther\catalogs\OfflineUpgradeStore.dat Object is locked skipped
C:\Windows\Panther\catalogs\OnlineEnvStore.dat Object is locked skipped
C:\Windows\Panther\catalogs\OnlineMigStore.dat Object is locked skipped
C:\Windows\Panther\catalogs\OnlineUpgradeStore.dat Object is locked skipped
C:\Windows\Panther\UnattendGC\diagerr.xml Object is locked skipped
C:\Windows\Panther\UnattendGC\diagwrn.xml Object is locked skipped
C:\Windows\Panther\UnattendGC\setupact.log Object is locked skipped
C:\Windows\Panther\UnattendGC\setuperr.log Object is locked skipped
C:\Windows\SchedLgU.Txt Object is locked skipped
C:\Windows\SE6BCF415.tmp Object is locked skipped
C:\Windows\security\database\secedit.sdb Object is locked skipped
C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-0.C7483456-A289-439d-8115-601632D005A0 Object is locked skipped
C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-1.C7483456-A289-439d-8115-601632D005A0 Object is locked skipped
C:\Windows\System32\ackwnbcl.dll Infected: Trojan.Win32.Pakes.day skipped
C:\Windows\System32\catroot2\edb.log Object is locked skipped
C:\Windows\System32\catroot2\{127D0A1D-4EF2-11D1-8608-00C04FC295EE}\catdb Object is locked skipped
C:\Windows\System32\catroot2\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\catdb Object is locked skipped
C:\Windows\System32\CCM\AAInst.mof Object is locked skipped
C:\Windows\System32\CCM\AAprov.dll Object is locked skipped
C:\Windows\System32\CCM\AdvertSched.dll Object is locked skipped
C:\Windows\System32\CCM\AssetAdvisor.dll Object is locked skipped
C:\Windows\System32\CCM\Bits_v15_Client_Setup.exe Object is locked skipped
C:\Windows\System32\CCM\Cache\XDM001B6.1.System\psshutdown.exe Infected: not-a-virus:RiskTool.Win32.PsShutdown.101 skipped
C:\Windows\System32\CCM\CCMAuthMessageHook.dll Object is locked skipped
C:\Windows\System32\CCM\ccmauthmessagehook.mof Object is locked skipped
C:\Windows\System32\CCM\ccmclasses.mof Object is locked skipped
C:\Windows\System32\CCM\CcmCTM.dll Object is locked skipped
C:\Windows\System32\CCM\CcmCTM_ps.dll Object is locked skipped
C:\Windows\System32\CCM\CcmDefaults.mof Object is locked skipped
C:\Windows\System32\CCM\CcmDTS.dll Object is locked skipped
C:\Windows\System32\CCM\ccmdump.exe Object is locked skipped
C:\Windows\System32\CCM\ccmevent.dll Object is locked skipped
C:\Windows\System32\CCM\CcmExec.mof Object is locked skipped
C:\Windows\System32\CCM\CcmExec_Global.mof Object is locked skipped
C:\Windows\System32\CCM\ccmhttp.dll Object is locked skipped
C:\Windows\System32\CCM\ccmid.dll Object is locked skipped
C:\Windows\System32\CCM\ccmident.dll Object is locked skipped
C:\Windows\System32\CCM\ccmperf.dll Object is locked skipped
C:\Windows\System32\CCM\ccmrepair.exe Object is locked skipped
C:\Windows\System32\CCM\ccmsenslogon.dll Object is locked skipped
C:\Windows\System32\CCM\CcmTask.dll Object is locked skipped
C:\Windows\System32\CCM\compver.ini Object is locked skipped
C:\Windows\System32\CCM\ContentAccess.dll Object is locked skipped
C:\Windows\System32\CCM\ContentTransferManager.mof Object is locked skipped
C:\Windows\System32\CCM\CPApplet.mof Object is locked skipped
C:\Windows\System32\CCM\DataTransferService.mof Object is locked skipped
C:\Windows\System32\CCM\ddrprov.dll Object is locked skipped
C:\Windows\System32\CCM\ddrprov.mof Object is locked skipped
C:\Windows\System32\CCM\EventClasses.mof Object is locked skipped
C:\Windows\System32\CCM\EventProvider.mof Object is locked skipped
C:\Windows\System32\CCM\ExecEngn.dll Object is locked skipped
C:\Windows\System32\CCM\execmgr.dll Object is locked skipped
C:\Windows\System32\CCM\FrameworkEvents.mof Object is locked skipped
C:\Windows\System32\CCM\FrameworkPerf.dll Object is locked skipped
C:\Windows\System32\CCM\hermes.ico Object is locked skipped
C:\Windows\System32\CCM\ImgDeployEvents.mof Object is locked skipped
C:\Windows\System32\CCM\InvCollectionTask.dll Object is locked skipped
C:\Windows\System32\CCM\InvDataStore.dll Object is locked skipped
C:\Windows\System32\CCM\InvEndPoint.dll Object is locked skipped
C:\Windows\System32\CCM\Inventory\Temp\skpswi.dat Object is locked skipped
C:\Windows\System32\CCM\InventoryAgentEndpoint.mof Object is locked skipped
C:\Windows\System32\CCM\InventoryAgentEvents.mof Object is locked skipped
C:\Windows\System32\CCM\InventoryAgentSchema.mof Object is locked skipped
C:\Windows\System32\CCM\InventoryDefaultPolicy.mof Object is locked skipped
C:\Windows\System32\CCM\InvFileCollectionTask.dll Object is locked skipped
C:\Windows\System32\CCM\InvFileSystemCollectionTask.dll Object is locked skipped
C:\Windows\System32\CCM\InvFileSystemQueryTask.dll Object is locked skipped
C:\Windows\System32\CCM\InvReportTask.dll Object is locked skipped
C:\Windows\System32\CCM\LocationServices.mof Object is locked skipped
C:\Windows\System32\CCM\LoggingClasses.mof Object is locked skipped
C:\Windows\System32\CCM\LoggingDefaults.mof Object is locked skipped
C:\Windows\System32\CCM\Logs\CAS.log Object is locked skipped
C:\Windows\System32\CCM\Logs\CcmExec.log Object is locked skipped
C:\Windows\System32\CCM\Logs\CertificateMaintenance.log Object is locked skipped
C:\Windows\System32\CCM\Logs\ClientIDManagerStartup.log Object is locked skipped
C:\Windows\System32\CCM\Logs\DataTransferService.log Object is locked skipped
C:\Windows\System32\CCM\Logs\execmgr.log Object is locked skipped
C:\Windows\System32\CCM\Logs\FileSystemFile.log Object is locked skipped
C:\Windows\System32\CCM\Logs\InventoryAgent.log Object is locked skipped
C:\Windows\System32\CCM\Logs\LocationServices.log Object is locked skipped
C:\Windows\System32\CCM\Logs\mtrmgr.log Object is locked skipped
C:\Windows\System32\CCM\Logs\PatchInstall.log Object is locked skipped
C:\Windows\System32\CCM\Logs\PatchUIMonitor.log Object is locked skipped
C:\Windows\System32\CCM\Logs\PolicyAgent.log Object is locked skipped
C:\Windows\System32\CCM\Logs\PolicyAgentProvider.log Object is locked skipped
C:\Windows\System32\CCM\Logs\PolicyEvaluator.log Object is locked skipped
C:\Windows\System32\CCM\Logs\Scheduler.log Object is locked skipped
C:\Windows\System32\CCM\Logs\SrcUpdateMgr.log Object is locked skipped
C:\Windows\System32\CCM\Logs\StatusAgent.log Object is locked skipped
C:\Windows\System32\CCM\lsdefault.mof Object is locked skipped
C:\Windows\System32\CCM\LSInterface.dll Object is locked skipped
C:\Windows\System32\CCM\mifprov.dll Object is locked skipped
C:\Windows\System32\CCM\mifprov.mof Object is locked skipped
C:\Windows\System32\CCM\MtrMgr.dll Object is locked skipped
C:\Windows\System32\CCM\PatchInstall.dll Object is locked skipped
C:\Windows\System32\CCM\PatchMgmtEvents.mof Object is locked skipped
C:\Windows\System32\CCM\PatchMgr.mof Object is locked skipped
C:\Windows\System32\CCM\PatchUIMonitor.dll Object is locked skipped
C:\Windows\System32\CCM\Perf\CcmFramework.h Object is locked skipped
C:\Windows\System32\CCM\Perf\CcmFramework.ini Object is locked skipped
C:\Windows\System32\CCM\PolicyAgentEndpoint.dll Object is locked skipped
C:\Windows\System32\CCM\PolicyAgentEvents.mof Object is locked skipped
C:\Windows\System32\CCM\PolicyAgentProvider.dll Object is locked skipped
C:\Windows\System32\CCM\PolicyClasses.mof Object is locked skipped
C:\Windows\System32\CCM\PolicyDefaults.mof Object is locked skipped
C:\Windows\System32\CCM\PolicyNamespaces.mof Object is locked skipped
C:\Windows\System32\CCM\PolicyProvider.mof Object is locked skipped
C:\Windows\System32\CCM\PolicyProvider2.mof Object is locked skipped
C:\Windows\System32\CCM\Prep.dll Object is locked skipped
C:\Windows\System32\CCM\PrepDrv.sys Object is locked skipped
C:\Windows\System32\CCM\RemoteToolsRegistryEvents.mof Object is locked skipped
C:\Windows\System32\CCM\RemoteToolsSchema.mof Object is locked skipped
C:\Windows\System32\CCM\RTConfiguration.dll Object is locked skipped
C:\Windows\System32\CCM\RTEndPoint.dll Object is locked skipped
C:\Windows\System32\CCM\Sched.dll Object is locked skipped
C:\Windows\System32\CCM\Scheduler.mof Object is locked skipped
C:\Windows\System32\CCM\ServiceData\LocalPayload\{0E58CB08-6DD6-4661-B3A6-1C3E297E6121} Object is locked skipped
C:\Windows\System32\CCM\ServiceData\LocalPayload\{324413E8-0950-4A0E-A67F-A2610EFEB719} Object is locked skipped
C:\Windows\System32\CCM\ServiceData\LocalPayload\{3EC9A507-EBA5-4C1E-AF14-0902EF80C629} Object is locked skipped
C:\Windows\System32\CCM\ServiceData\LocalPayload\{405BCDC0-6634-4665-983A-F05200E44718} Object is locked skipped
C:\Windows\System32\CCM\ServiceData\LocalPayload\{D9906031-7E58-44C7-9E5E-FCCA552F3EA5} Object is locked skipped
C:\Windows\System32\CCM\ServiceData\LocalPayload\{DD5EC5AA-D490-4A74-BB49-B4D6B340867F} Object is locked skipped
C:\Windows\System32\CCM\ServiceData\LocalPayload\{DE369DDB-CF4D-4026-A6AD-1E26D79C281E} Object is locked skipped
C:\Windows\System32\CCM\ServiceData\LocalPayload\{DE79A298-1EDB-4357-BF8E-79C2E1D2A610} Object is locked skipped
C:\Windows\System32\CCM\ServiceData\LocalPayload\{E353072B-B5E2-4F9F-86F3-133F0A93BC05} Object is locked skipped
C:\Windows\System32\CCM\ServiceData\Messaging\EndpointQueues\CertificateMaintenanceEndpoint\0000001P.msg Object is locked skipped
C:\Windows\System32\CCM\ServiceData\Messaging\EndpointQueues\CertificateMaintenanceEndpoint\0000001P.que Object is locked skipped
C:\Windows\System32\CCM\ServiceData\Messaging\EndpointQueues\CTMDTSReply\0000000B.msg Object is locked skipped
C:\Windows\System32\CCM\ServiceData\Messaging\EndpointQueues\CTMDTSReply\0000000B.que Object is locked skipped
C:\Windows\System32\CCM\ServiceData\Messaging\EndpointQueues\execmgr\0000001L.msg Object is locked skipped
C:\Windows\System32\CCM\ServiceData\Messaging\EndpointQueues\execmgr\0000001L.que Object is locked skipped
C:\Windows\System32\CCM\ServiceData\Messaging\EndpointQueues\InventoryAgent\00000034.msg Object is locked skipped
C:\Windows\System32\CCM\ServiceData\Messaging\EndpointQueues\InventoryAgent\00000034.que Object is locked skipped
C:\Windows\System32\CCM\ServiceData\Messaging\EndpointQueues\LS_ReplyLocations\0000000G.msg Object is locked skipped
C:\Windows\System32\CCM\ServiceData\Messaging\EndpointQueues\LS_ReplyLocations\0000000G.que Object is locked skipped
C:\Windows\System32\CCM\ServiceData\Messaging\EndpointQueues\LS_ScheduledCleanup\0000001U.msg Object is locked skipped
C:\Windows\System32\CCM\ServiceData\Messaging\EndpointQueues\LS_ScheduledCleanup\0000001U.que Object is locked skipped
C:\Windows\System32\CCM\ServiceData\Messaging\EndpointQueues\MtrMgr\00000001.msg Object is locked skipped
C:\Windows\System32\CCM\ServiceData\Messaging\EndpointQueues\MtrMgr\00000001.que Object is locked skipped
C:\Windows\System32\CCM\ServiceData\Messaging\EndpointQueues\PatchUIMonitor\00000001.msg Object is locked skipped
C:\Windows\System32\CCM\ServiceData\Messaging\EndpointQueues\PatchUIMonitor\00000001.que Object is locked skipped
C:\Windows\System32\CCM\ServiceData\Messaging\EndpointQueues\PolicyAgent_Cleanup\00000003.msg Object is locked skipped
C:\Windows\System32\CCM\ServiceData\Messaging\EndpointQueues\PolicyAgent_Cleanup\00000003.que Object is locked skipped
C:\Windows\System32\CCM\ServiceData\Messaging\EndpointQueues\PolicyAgent_PolicyDownload\00000004.msg Object is locked skipped
C:\Windows\System32\CCM\ServiceData\Messaging\EndpointQueues\PolicyAgent_PolicyDownload\00000004.que Object is locked skipped
C:\Windows\System32\CCM\ServiceData\Messaging\EndpointQueues\PolicyAgent_PolicyEvaluator\000000AY.msg Object is locked skipped
C:\Windows\System32\CCM\ServiceData\Messaging\EndpointQueues\PolicyAgent_PolicyEvaluator\000000AY.que Object is locked skipped
C:\Windows\System32\CCM\ServiceData\Messaging\EndpointQueues\PolicyAgent_ReplyAssignments\00000016.msg Object is locked skipped
C:\Windows\System32\CCM\ServiceData\Messaging\EndpointQueues\PolicyAgent_ReplyAssignments\00000016.que Object is locked skipped
C:\Windows\System32\CCM\ServiceData\Messaging\EndpointQueues\PolicyAgent_RequestAssignments\0000002W.msg Object is locked skipped
C:\Windows\System32\CCM\ServiceData\Messaging\EndpointQueues\PolicyAgent_RequestAssignments\0000002W.que Object is locked skipped
C:\Windows\System32\CCM\ServiceData\Messaging\EndpointQueues\PolicyAgent_ReRequestPolicy\00000001.msg Object is locked skipped
C:\Windows\System32\CCM\ServiceData\Messaging\EndpointQueues\PolicyAgent_ReRequestPolicy\00000001.que Object is locked skipped
C:\Windows\System32\CCM\ServiceData\Messaging\EndpointQueues\RemoteToolsAgent\00000001.msg Object is locked skipped
C:\Windows\System32\CCM\ServiceData\Messaging\EndpointQueues\RemoteToolsAgent\00000001.que Object is locked skipped
C:\Windows\System32\CCM\ServiceData\Messaging\EndpointQueues\SrcUpdateMgr\00000001.msg Object is locked skipped
C:\Windows\System32\CCM\ServiceData\Messaging\EndpointQueues\SrcUpdateMgr\00000001.que Object is locked skipped
C:\Windows\System32\CCM\ServiceData\Messaging\EndpointQueues\SWMTRReportGen\00000001.msg Object is locked skipped
C:\Windows\System32\CCM\ServiceData\Messaging\EndpointQueues\SWMTRReportGen\00000001.que Object is locked skipped
C:\Windows\System32\CCM\ServiceData\Messaging\EndpointQueues\UpdatesInstallMgr\00000001.msg Object is locked skipped
C:\Windows\System32\CCM\ServiceData\Messaging\EndpointQueues\UpdatesInstallMgr\00000001.que Object is locked skipped
C:\Windows\System32\CCM\ServiceData\Messaging\EndpointQueues\UploadProtocol\00000001.msg Object is locked skipped
C:\Windows\System32\CCM\ServiceData\Messaging\EndpointQueues\UploadProtocol\00000001.que Object is locked skipped
C:\Windows\System32\CCM\ServiceData\Messaging\OutgoingQueues\amp_[http]mp_locationmanager\00000005.msg Object is locked skipped
C:\Windows\System32\CCM\ServiceData\Messaging\OutgoingQueues\amp_[http]mp_locationmanager\00000005.que Object is locked skipped
C:\Windows\System32\CCM\ServiceData\Messaging\OutgoingQueues\mp_mp_ddrendpoint\00000001.msg Object is locked skipped
C:\Windows\System32\CCM\ServiceData\Messaging\OutgoingQueues\mp_mp_ddrendpoint\00000001.que Object is locked skipped
C:\Windows\System32\CCM\ServiceData\Messaging\OutgoingQueues\mp_mp_hinvendpoint\00000006.msg Object is locked skipped
C:\Windows\System32\CCM\ServiceData\Messaging\OutgoingQueues\mp_mp_hinvendpoint\00000006.que Object is locked skipped
C:\Windows\System32\CCM\ServiceData\Messaging\OutgoingQueues\mp_mp_hinvendpoint\00000007.msg Object is locked skipped
C:\Windows\System32\CCM\ServiceData\Messaging\OutgoingQueues\mp_mp_hinvendpoint\00000007.que Object is locked skipped
C:\Windows\System32\CCM\ServiceData\Messaging\OutgoingQueues\mp_mp_sinvendpoint\00000005.msg Object is locked skipped
C:\Windows\System32\CCM\ServiceData\Messaging\OutgoingQueues\mp_mp_sinvendpoint\00000005.que Object is locked skipped
C:\Windows\System32\CCM\ServiceData\Messaging\OutgoingQueues\mp_statusreceiver\0000001E.msg Object is locked skipped
C:\Windows\System32\CCM\ServiceData\Messaging\OutgoingQueues\mp_statusreceiver\0000001E.que Object is locked skipped
C:\Windows\System32\CCM\ServiceData\Messaging\OutgoingQueues\mp_statusreceiver\0000001F.msg Object is locked skipped
C:\Windows\System32\CCM\ServiceData\Messaging\OutgoingQueues\mp_statusreceiver\0000001F.que Object is locked skipped
C:\Windows\System32\CCM\ServiceData\Messaging\OutgoingQueues\mp_[http]mp_locationmanager\0000000T.msg Object is locked skipped
C:\Windows\System32\CCM\ServiceData\Messaging\OutgoingQueues\mp_[http]mp_locationmanager\0000000T.que Object is locked skipped
C:\Windows\System32\CCM\ServiceData\Messaging\OutgoingQueues\mp_[http]mp_policymanager\0000002S.msg Object is locked skipped
C:\Windows\System32\CCM\ServiceData\Messaging\OutgoingQueues\mp_[http]mp_policymanager\0000002S.que Object is locked skipped
C:\Windows\System32\CCM\smsccmld.dll Object is locked skipped
C:\Windows\System32\CCM\smsccmld.mof Object is locked skipped
C:\Windows\System32\CCM\SmsClient.mof Object is locked skipped
C:\Windows\System32\CCM\SmsClientProviders.mof Object is locked skipped
C:\Windows\System32\CCM\SmsCommon.mof Object is locked skipped
C:\Windows\System32\CCM\SmsEventClasses.mof Object is locked skipped
C:\Windows\System32\CCM\SmsEventLog.dll Object is locked skipped
C:\Windows\System32\CCM\SmsEventLogForwarderDefaults.mof Object is locked skipped
C:\Windows\System32\CCM\SmsInventoryProviders.mof Object is locked skipped
C:\Windows\System32\CCM\smsproc.dll Object is locked skipped
C:\Windows\System32\CCM\smsprov.mof Object is locked skipped
C:\Windows\System32\CCM\SmsRemoteControlProviders.mof Object is locked skipped
C:\Windows\System32\CCM\SrcUpdateEvents.mof Object is locked skipped
C:\Windows\System32\CCM\SrcUpdateMgr.dll Object is locked skipped
C:\Windows\System32\CCM\SrcUpdateMgr_ps.dll Object is locked skipped
C:\Windows\System32\CCM\SrcUpdatePolicy.mof Object is locked skipped
C:\Windows\System32\CCM\SrcUpdateSchema.mof Object is locked skipped
C:\Windows\System32\CCM\StandardEventForwarder.dll Object is locked skipped
C:\Windows\System32\CCM\StandardEventForwarderClasses.mof Object is locked skipped
C:\Windows\System32\CCM\StandardEventForwarderDefaults.mof Object is locked skipped
C:\Windows\System32\CCM\StatusAgent.dll Object is locked skipped
C:\Windows\System32\CCM\SWDistEvents.mof Object is locked skipped
C:\Windows\System32\CCM\SWDistPolicy.mof Object is locked skipped
C:\Windows\System32\CCM\SWDistSchema.mof Object is locked skipped
C:\Windows\System32\CCM\swmreport.dll Object is locked skipped
C:\Windows\System32\CCM\SWMtrEvents.mof Object is locked skipped
C:\Windows\System32\CCM\SWMtrPolicy.mof Object is locked skipped
C:\Windows\System32\CCM\SWMtrSchema.mof Object is locked skipped
C:\Windows\System32\CCM\UpdatesEvaluator.dll Object is locked skipped
C:\Windows\System32\CCM\Win32_USBDevice.mof Object is locked skipped
C:\Windows\System32\config\COMPONENTS Object is locked skipped
C:\Windows\System32\config\COMPONENTS.LOG1 Object is locked skipped
C:\Windows\System32\config\COMPONENTS.LOG2 Object is locked skipped
C:\Windows\System32\config\DEFAULT Object is locked skipped
C:\Windows\System32\config\DEFAULT.LOG1 Object is locked skipped
C:\Windows\System32\config\DEFAULT.LOG2 Object is locked skipped
C:\Windows\System32\config\SAM Object is locked skipped
C:\Windows\System32\config\SAM.LOG1 Object is locked skipped
C:\Windows\System32\config\SAM.LOG2 Object is locked skipped
C:\Windows\System32\config\SECURITY Object is locked skipped
C:\Windows\System32\config\SECURITY.LOG1 Object is locked skipped
C:\Windows\System32\config\SECURITY.LOG2 Object is locked skipped
C:\Windows\System32\config\SOFTWARE Object is locked skipped
C:\Windows\System32\config\SOFTWARE.LOG1 Object is locked skipped
C:\Windows\System32\config\SOFTWARE.LOG2 Object is locked skipped
C:\Windows\System32\config\SYSTEM Object is locked skipped
C:\Windows\System32\config\SYSTEM.LOG1 Object is locked skipped
C:\Windows\System32\config\SYSTEM.LOG2 Object is locked skipped
C:\Windows\System32\config\TxR\{250834B7-750C-494d-BDC3-DA86B6E2101B}.TM.blf Object is locked skipped
C:\Windows\System32\config\TxR\{250834B7-750C-494d-BDC3-DA86B6E2101B}.TMContainer00000000000000000001.regtrans-ms Object is locked skipped
C:\Windows\System32\config\TxR\{250834B7-750C-494d-BDC3-DA86B6E2101B}.TMContainer00000000000000000002.regtrans-ms Object is locked skipped
C:\Windows\System32\config\TxR\{250834B7-750C-494d-BDC3-DA86B6E2101B}.TMContainer00000000000000000003.regtrans-ms Object is locked skipped
C:\Windows\System32\config\TxR\{250834B7-750C-494d-BDC3-DA86B6E2101B}.TMContainer00000000000000000004.regtrans-ms Object is locked skipped
C:\Windows\System32\LogFiles\Scm\SCM.EVM Object is locked skipped
C:\Windows\System32\LogFiles\WUDF\WUDFTrace.etl Object is locked skipped
C:\Windows\System32\restore\MachineGuid.txt Object is locked skipped
C:\Windows\System32\spool\SpoolerETW.etl Object is locked skipped
C:\Windows\System32\vkmmbtys.dll Infected: Trojan-Downloader.Win32.Agent.seh skipped
C:\Windows\System32\wbem\AutoRecover\2B8B1A8B0ACD3EE28B421D3918DC1F29.mof Object is locked skipped
C:\Windows\System32\wbem\AutoRecover\3460B7617E0429A960E481B197F238A3.mof Object is locked skipped
C:\Windows\System32\wbem\Logs\WMITracing.log Object is locked skipped
C:\Windows\System32\wbem\Repository\INDEX.BTR Object is locked skipped
C:\Windows\System32\wbem\Repository\MAPPING1.MAP Object is locked skipped
C:\Windows\System32\wbem\Repository\MAPPING2.MAP Object is locked skipped
C:\Windows\System32\wbem\Repository\OBJECTS.DATA Object is locked skipped
C:\Windows\System32\winevt\Logs\Application.evtx Object is locked skipped
C:\Windows\System32\winevt\Logs\DFS Replication.evtx Object is locked skipped
C:\Windows\System32\winevt\Logs\HardwareEvents.evtx Object is locked skipped
C:\Windows\System32\winevt\Logs\Internet Explorer.evtx Object is locked skipped
C:\Windows\System32\winevt\Logs\Key Management Service.evtx Object is locked skipped
C:\Windows\System32\winevt\Logs\Media Center.evtx Object is locked skipped
C:\Windows\System32\winevt\Logs\Microsoft-Windows-Bits-Client%4Operational.evtx Object is locked skipped
C:\Windows\System32\winevt\Logs\Microsoft-Windows-CodeIntegrity%4Operational.evtx Object is locked skipped
C:\Windows\System32\winevt\Logs\Microsoft-Windows-Diagnosis-DPS%4Operational.evtx Object is locked skipped
C:\Windows\System32\winevt\Logs\Microsoft-Windows-Diagnosis-PLA%4Operational.evtx Object is locked skipped
C:\Windows\System32\winevt\Logs\Microsoft-Windows-Diagnostics-Networking%4Operational.evtx Object is locked skipped
C:\Windows\System32\winevt\Logs\Microsoft-Windows-Diagnostics-Performance%4Operational.evtx Object is locked skipped
C:\Windows\System32\winevt\Logs\Microsoft-Windows-DiskDiagnosticDataCollector%4Operational.evtx Object is locked skipped
C:\Windows\System32\winevt\Logs\Microsoft-Windows-DriverFrameworks-UserMode%4Operational.evtx Object is locked skipped
C:\Windows\System32\winevt\Logs\Microsoft-Windows-GroupPolicy%4Operational.evtx Object is locked skipped
C:\Windows\System32\winevt\Logs\Microsoft-Windows-International%4Operational.evtx Object is locked skipped
C:\Windows\System32\winevt\Logs\Microsoft-Windows-Kernel-WHEA.evtx Object is locked skipped
C:\Windows\System32\winevt\Logs\Microsoft-Windows-LanguagePackSetup%4Operational.evtx Object is locked skipped
C:\Windows\System32\winevt\Logs\Microsoft-Windows-MUI%4Operational.evtx Object is locked skipped
C:\Windows\System32\winevt\Logs\Microsoft-Windows-NetworkAccessProtection%4Operational.evtx Object is locked skipped
C:\Windows\System32\winevt\Logs\Microsoft-Windows-ReadyBoost%4Operational.evtx Object is locked skipped
C:\Windows\System32\winevt\Logs\Microsoft-Windows-ReliabilityAnalysisComponent%4Operational.evtx Object is locked skipped
C:\Windows\System32\winevt\Logs\Microsoft-Windows-RemoteAssistance%4Admin.evtx Object is locked skipped
C:\Windows\System32\winevt\Logs\Microsoft-Windows-RemoteAssistance%4Operational.evtx Object is locked skipped
C:\Windows\System32\winevt\Logs\Microsoft-Windows-Resource-Exhaustion-Detector%4Operational.evtx Object is locked skipped
C:\Windows\System32\winevt\Logs\Microsoft-Windows-Resource-Exhaustion-Resolver%4Operational.evtx Object is locked skipped
C:\Windows\System32\winevt\Logs\Microsoft-Windows-Resource-Leak-Diagnostic%4Operational.evtx Object is locked skipped
C:\Windows\System32\winevt\Logs\Microsoft-Windows-RestartManager%4Operational.evtx Object is locked skipped
C:\Windows\System32\winevt\Logs\Microsoft-Windows-TaskScheduler%4Operational.evtx Object is locked skipped
C:\Windows\System32\winevt\Logs\Microsoft-Windows-UAC-FileVirtualization%4Operational.evtx Object is locked skipped
C:\Windows\System32\winevt\Logs\Microsoft-Windows-WindowsUpdateClient%4Operational.evtx Object is locked skipped
C:\Windows\System32\winevt\Logs\Microsoft-Windows-WLAN-AutoConfig%4Operational.evtx Object is locked skipped
C:\Windows\System32\winevt\Logs\ODiag.evtx Object is locked skipped
C:\Windows\System32\winevt\Logs\OSession.evtx Object is locked skipped
C:\Windows\System32\winevt\Logs\Security.evtx Object is locked skipped
C:\Windows\System32\winevt\Logs\Setup.evtx Object is locked skipped
C:\Windows\System32\winevt\Logs\System.evtx Object is locked skipped
C:\Windows\System32\winevt\Logs\Tumbleweed.evtx Object is locked skipped
C:\Windows\System32\wpa.bak Object is locked skipped
C:\Windows\Tasks\desktop.ini Object is locked skipped
C:\Windows\winsxs\x86_microsoft-windows-n..n_service_datastore_31bf3856ad364e35_6.0.6000.16386_none_cef7ceb03914a67f\dnary.xsd Object is locked skipped
Scan process completed.