melissa_may1
New member
Hi helpers!
My Sony VAIO notebook, running XP home, is running so slow all of a sudden. I first suspected an MFT problem, since one utility said it was 98% full. But another said there was plenty of room.
Symptoms: Very slow to open programs. Saving a file hangs the system, and a long (30-50 minute?) wait ?might? allow it to come back. System hangs when accessing Start menu. System hangs when switching between open program windows. System hangs when attempting to shutdown or restart.
I've run the procedure outlined up top, so here are my logs, starting with Kaspersky and then HiJackThis.
Thanks in advance for any help you can give. I'm about 3 seconds from wiping this thing out and starting over!!!

KASPERSKY ONLINE SCANNER REPORT
Wednesday, March 05, 2008 4:59:06 AM
Operating System: Microsoft Windows XP Home Edition, Service Pack 2 (Build 2600)
Kaspersky Online Scanner version: 5.0.98.0
Kaspersky Anti-Virus database last update: 5/03/2008
Kaspersky Anti-Virus database records: 597488
Scan Settings
Scan using the following antivirus database extended
Scan Archives true
Scan Mail Bases true
Scan Target My Computer
C:\
E:\
F:\
Scan Statistics
Total number of scanned objects 133120
Number of viruses found 11
Number of infected objects 24
Number of suspicious objects 0
Duration of the scan process 02:25:03
Infected Object Name Virus Name Last Action
C:\Documents and Settings\Administrator.WKSTA1.001\Cookies\index.dat Object is locked skipped
C:\Documents and Settings\Administrator.WKSTA1.001\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat Object is locked skipped
C:\Documents and Settings\Administrator.WKSTA1.001\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped
C:\Documents and Settings\Administrator.WKSTA1.001\Local Settings\History\History.IE5\index.dat Object is locked skipped
C:\Documents and Settings\Administrator.WKSTA1.001\Local Settings\History\History.IE5\MSHist012008030420080305\index.dat Object is locked skipped
C:\Documents and Settings\Administrator.WKSTA1.001\Local Settings\Temporary Internet Files\Content.IE5\index.dat Object is locked skipped
C:\Documents and Settings\Administrator.WKSTA1.001\Local Settings\Temporary Internet Files\Content.IE5\S9YF4HAZ\picnic_pies_aol_for0_2[1].swf Object is locked skipped
C:\Documents and Settings\Administrator.WKSTA1.001\NTUSER.DAT Object is locked skipped
C:\Documents and Settings\Administrator.WKSTA1.001\ntuser.dat.LOG Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Windows Defender\Support\MPLog-12102006-233514.log Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\648D7BCD.tmp/bpk.exe Infected: not-a-virus:Monitor.Win32.Perflogger.bt skipped
C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\648D7BCD.tmp/bpkun.exe Infected: not-a-virus:Monitor.Win32.Perflogger.bu skipped
C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\648D7BCD.tmp/bpkvw.exe Infected: not-a-virus:Monitor.Win32.Perflogger.bv skipped
C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\648D7BCD.tmp/Setup.exe Infected: not-a-virus:Monitor.Win32.Perflogger.bx skipped
C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\648D7BCD.tmp/bpkhk.dll Infected: not-a-virus:Monitor.Win32.Perflogger.163 skipped
C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\648D7BCD.tmp/bpkr.exe Infected: Trojan.Win32.KillAV.is skipped
C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\648D7BCD.tmp RAR: infected - 6 skipped
C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\648D7BCD.tmp CryptFF: infected - 6 skipped
C:\Documents and Settings\All Users\Application Data\Symantec\SRTSP\Quarantine\etr1D.tmp Infected: Trojan-Downloader.JS.Zapchast.f skipped
C:\Documents and Settings\All Users\Application Data\Symantec\SRTSP\SrtETmp\36F958C4.TMP Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Symantec\SRTSP\SrtETmp\605016C6.TMP Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Symantec\SRTSP\SrtETmp(2)\99EA2962.TMP Object is locked skipped
C:\Documents and Settings\LocalService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat Object is locked skipped
C:\Documents and Settings\LocalService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped
C:\Documents and Settings\LocalService\ntuser.dat Object is locked skipped
C:\Documents and Settings\LocalService\ntuser.dat.LOG Object is locked skipped
C:\Documents and Settings\username\Application Data\Thunderbird\Profiles\1okwu791.default\Mail\Local Folders\Inbox/[From "Robert G. Morris" ][Date Wed, 4 Oct 2006 10:50:58 -0400]/UNNAMED/[From =?ISO-8859-1?Q?casa?= ][Date 04 Oct 2006 11:26:14 -0400]/text/[From [Norton AntiSpam] melissa, Happy New Year from Hercules Hook][Date Wed, 24 Jan 2007 14:28:47 -0600]/UNNAMED/[From Chris Bloom ][Date Wed, 24 Jan 2007 17:11:31 -0500 (EST)]/text/[From ][Date Wed, 24 Jan 2007 18:28:07 -0800]/UNNAMED Infected: Email-Worm.Win32.Zhelatin.dam skipped
C:\Documents and Settings\username\Application Data\Thunderbird\Profiles\1okwu791.default\Mail\Local Folders\Inbox/[From "Robert G. Morris" ][Date Wed, 4 Oct 2006 10:50:58 -0400]/UNNAMED/[From =?ISO-8859-1?Q?casa?= ][Date 04 Oct 2006 11:26:14 -0400]/text/[From [Norton AntiSpam] melissa, Happy New Year from Hercules Hook][Date Wed, 24 Jan 2007 14:28:47 -0600]/UNNAMED/[From Chris Bloom ][Date Wed, 24 Jan 2007 17:11:31 -0500 (EST)]/text Infected: Email-Worm.Win32.Zhelatin.dam skipped
C:\Documents and Settings\username\Application Data\Thunderbird\Profiles\1okwu791.default\Mail\Local Folders\Inbox/[From "Robert G. Morris" ][Date Wed, 4 Oct 2006 10:50:58 -0400]/UNNAMED/[From =?ISO-8859-1?Q?casa?= ][Date 04 Oct 2006 11:26:14 -0400]/text/[From [Norton AntiSpam] melissa, Happy New Year from Hercules Hook][Date Wed, 24 Jan 2007 14:28:47 -0600]/UNNAMED Infected: Email-Worm.Win32.Zhelatin.dam skipped
C:\Documents and Settings\username\Application Data\Thunderbird\Profiles\1okwu791.default\Mail\Local Folders\Inbox/[From "Robert G. Morris" ][Date Wed, 4 Oct 2006 10:50:58 -0400]/UNNAMED/[From =?ISO-8859-1?Q?casa?= ][Date 04 Oct 2006 11:26:14 -0400]/text/[From "Porta Jump" ][Date Wed, 28 Feb 2007 09:48:55 -0600]/UNNAMED/[From "RingTone Shop" ][Date Wed, 28 Feb 2007 11:11:13 -0 ... /[From "Branch Banking and Trust" ][Date Wed, 28 Feb 2007 15:57:15 -0500]/UNNAMED Infected: Trojan-Spy.HTML.Bankfraud.ri skipped
C:\Documents and Settings\username\Application Data\Thunderbird\Profiles\1okwu791.default\Mail\Local Folders\Inbox/[From "Robert G. Morris" ][Date Wed, 4 Oct 2006 10:50:58 -0400]/UNNAMED/[From =?ISO-8859-1?Q?casa?= ][Date 04 Oct 2006 11:26:14 -0400]/text/[From "Porta Jump" ][Date Wed, 28 Feb 2007 09:48:55 -0600]/UNNAMED/[From "RingTone Shop" ][Date Wed, 28 Feb 2007 11:11:13 -0500]/html Infected: Trojan-Spy.HTML.Bankfraud.ri skipped
C:\Documents and Settings\username\Application Data\Thunderbird\Profiles\1okwu791.default\Mail\Local Folders\Inbox/[From "Robert G. Morris" ][Date Wed, 4 Oct 2006 10:50:58 -0400]/UNNAMED/[From =?ISO-8859-1?Q?casa?= ][Date 04 Oct 2006 11:26:14 -0400]/text/[From "Porta Jump" ][Date Wed, 28 Feb 2007 09:48:55 -0600]/UNNAMED Infected: Trojan-Spy.HTML.Bankfraud.ri skipped
C:\Documents and Settings\username\Application Data\Thunderbird\Profiles\1okwu791.default\Mail\Local Folders\Inbox/[From "Robert G. Morris" ][Date Wed, 4 Oct 2006 10:50:58 -0400]/UNNAMED/[From =?ISO-8859-1?Q?casa?= ][Date 04 Oct 2006 11:26:14 -0400]/text Infected: Trojan-Spy.HTML.Bankfraud.ri skipped
C:\Documents and Settings\username\Application Data\Thunderbird\Profiles\1okwu791.default\Mail\Local Folders\Inbox/[From "Robert G. Morris" ][Date Wed, 4 Oct 2006 10:50:58 -0400]/UNNAMED Infected: Trojan-Spy.HTML.Bankfraud.ri skipped
C:\Documents and Settings\username\Application Data\Thunderbird\Profiles\1okwu791.default\Mail\Local Folders\Inbox Mail Berkeley mbox: infected - 8 skipped
C:\Documents and Settings\username\Desktop\Downloads\AceHTMLPro\acehtml6pro.exe/data0007/data0146 Infected: not-a-virus:AdWare.Win32.BHO.w skipped
C:\Documents and Settings\username\Desktop\Downloads\AceHTMLPro\acehtml6pro.exe/data0007 Infected: not-a-virus:AdWare.Win32.BHO.w skipped
C:\Documents and Settings\username\Desktop\Downloads\AceHTMLPro\acehtml6pro.exe NSIS: infected - 2 skipped
C:\Documents and Settings\username\Desktop\Downloads\Rootkit Revealer\PsTools\pskill.exe Infected: not-a-virus:RiskTool.Win32.PsKill.k skipped
C:\Documents and Settings\username\Desktop\Downloads\Rootkit Revealer\PsTools.zip/pskill.exe Infected: not-a-virus:RiskTool.Win32.PsKill.k skipped
C:\Documents and Settings\username\Desktop\Downloads\Rootkit Revealer\PsTools.zip ZIP: infected - 1 skipped
C:\Documents and Settings\NetworkService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat Object is locked skipped
C:\Documents and Settings\NetworkService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped
C:\Documents and Settings\NetworkService\NTUSER.DAT Object is locked skipped
C:\Documents and Settings\NetworkService\ntuser.dat.LOG Object is locked skipped
C:\e690693f15bf96506769a1f716238b\msxml4-KB927978-enu.log Object is locked skipped
C:\System Volume Information\MountPointManagerRemoteDatabase Object is locked skipped
C:\System Volume Information\_restore{E28BBD50-0570-405B-9B46-4310F2CE5171}\RP209\change.log Object is locked skipped
C:\WINDOWS\Debug\PASSWD.LOG Object is locked skipped
C:\WINDOWS\system32\config\AppEvent.Evt Object is locked skipped
C:\WINDOWS\system32\config\default Object is locked skipped
C:\WINDOWS\system32\config\default.LOG Object is locked skipped
C:\WINDOWS\system32\config\SAM Object is locked skipped
C:\WINDOWS\system32\config\SAM.LOG Object is locked skipped
C:\WINDOWS\system32\config\SecEvent.Evt Object is locked skipped
C:\WINDOWS\system32\config\SECURITY Object is locked skipped
C:\WINDOWS\system32\config\SECURITY.LOG Object is locked skipped
C:\WINDOWS\system32\config\software Object is locked skipped
C:\WINDOWS\system32\config\software.LOG Object is locked skipped
C:\WINDOWS\system32\config\SysEvent.Evt Object is locked skipped
C:\WINDOWS\system32\config\system Object is locked skipped
C:\WINDOWS\system32\config\system.LOG Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\INDEX.BTR Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\INDEX.MAP Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\MAPPING.VER Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\MAPPING1.MAP Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\MAPPING2.MAP Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\OBJECTS.DATA Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\OBJECTS.MAP Object is locked skipped
Scan process completed.
My Sony VAIO notebook, running XP home, is running so slow all of a sudden. I first suspected an MFT problem, since one utility said it was 98% full. But another said there was plenty of room.
Symptoms: Very slow to open programs. Saving a file hangs the system, and a long (30-50 minute?) wait ?might? allow it to come back. System hangs when accessing Start menu. System hangs when switching between open program windows. System hangs when attempting to shutdown or restart.
I've run the procedure outlined up top, so here are my logs, starting with Kaspersky and then HiJackThis.
Thanks in advance for any help you can give. I'm about 3 seconds from wiping this thing out and starting over!!!

KASPERSKY ONLINE SCANNER REPORT
Wednesday, March 05, 2008 4:59:06 AM
Operating System: Microsoft Windows XP Home Edition, Service Pack 2 (Build 2600)
Kaspersky Online Scanner version: 5.0.98.0
Kaspersky Anti-Virus database last update: 5/03/2008
Kaspersky Anti-Virus database records: 597488
Scan Settings
Scan using the following antivirus database extended
Scan Archives true
Scan Mail Bases true
Scan Target My Computer
C:\
E:\
F:\
Scan Statistics
Total number of scanned objects 133120
Number of viruses found 11
Number of infected objects 24
Number of suspicious objects 0
Duration of the scan process 02:25:03
Infected Object Name Virus Name Last Action
C:\Documents and Settings\Administrator.WKSTA1.001\Cookies\index.dat Object is locked skipped
C:\Documents and Settings\Administrator.WKSTA1.001\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat Object is locked skipped
C:\Documents and Settings\Administrator.WKSTA1.001\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped
C:\Documents and Settings\Administrator.WKSTA1.001\Local Settings\History\History.IE5\index.dat Object is locked skipped
C:\Documents and Settings\Administrator.WKSTA1.001\Local Settings\History\History.IE5\MSHist012008030420080305\index.dat Object is locked skipped
C:\Documents and Settings\Administrator.WKSTA1.001\Local Settings\Temporary Internet Files\Content.IE5\index.dat Object is locked skipped
C:\Documents and Settings\Administrator.WKSTA1.001\Local Settings\Temporary Internet Files\Content.IE5\S9YF4HAZ\picnic_pies_aol_for0_2[1].swf Object is locked skipped
C:\Documents and Settings\Administrator.WKSTA1.001\NTUSER.DAT Object is locked skipped
C:\Documents and Settings\Administrator.WKSTA1.001\ntuser.dat.LOG Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Windows Defender\Support\MPLog-12102006-233514.log Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\648D7BCD.tmp/bpk.exe Infected: not-a-virus:Monitor.Win32.Perflogger.bt skipped
C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\648D7BCD.tmp/bpkun.exe Infected: not-a-virus:Monitor.Win32.Perflogger.bu skipped
C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\648D7BCD.tmp/bpkvw.exe Infected: not-a-virus:Monitor.Win32.Perflogger.bv skipped
C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\648D7BCD.tmp/Setup.exe Infected: not-a-virus:Monitor.Win32.Perflogger.bx skipped
C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\648D7BCD.tmp/bpkhk.dll Infected: not-a-virus:Monitor.Win32.Perflogger.163 skipped
C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\648D7BCD.tmp/bpkr.exe Infected: Trojan.Win32.KillAV.is skipped
C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\648D7BCD.tmp RAR: infected - 6 skipped
C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\648D7BCD.tmp CryptFF: infected - 6 skipped
C:\Documents and Settings\All Users\Application Data\Symantec\SRTSP\Quarantine\etr1D.tmp Infected: Trojan-Downloader.JS.Zapchast.f skipped
C:\Documents and Settings\All Users\Application Data\Symantec\SRTSP\SrtETmp\36F958C4.TMP Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Symantec\SRTSP\SrtETmp\605016C6.TMP Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Symantec\SRTSP\SrtETmp(2)\99EA2962.TMP Object is locked skipped
C:\Documents and Settings\LocalService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat Object is locked skipped
C:\Documents and Settings\LocalService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped
C:\Documents and Settings\LocalService\ntuser.dat Object is locked skipped
C:\Documents and Settings\LocalService\ntuser.dat.LOG Object is locked skipped
C:\Documents and Settings\username\Application Data\Thunderbird\Profiles\1okwu791.default\Mail\Local Folders\Inbox/[From "Robert G. Morris" ][Date Wed, 4 Oct 2006 10:50:58 -0400]/UNNAMED/[From =?ISO-8859-1?Q?casa?= ][Date 04 Oct 2006 11:26:14 -0400]/text/[From [Norton AntiSpam] melissa, Happy New Year from Hercules Hook][Date Wed, 24 Jan 2007 14:28:47 -0600]/UNNAMED/[From Chris Bloom ][Date Wed, 24 Jan 2007 17:11:31 -0500 (EST)]/text/[From ][Date Wed, 24 Jan 2007 18:28:07 -0800]/UNNAMED Infected: Email-Worm.Win32.Zhelatin.dam skipped
C:\Documents and Settings\username\Application Data\Thunderbird\Profiles\1okwu791.default\Mail\Local Folders\Inbox/[From "Robert G. Morris" ][Date Wed, 4 Oct 2006 10:50:58 -0400]/UNNAMED/[From =?ISO-8859-1?Q?casa?= ][Date 04 Oct 2006 11:26:14 -0400]/text/[From [Norton AntiSpam] melissa, Happy New Year from Hercules Hook][Date Wed, 24 Jan 2007 14:28:47 -0600]/UNNAMED/[From Chris Bloom ][Date Wed, 24 Jan 2007 17:11:31 -0500 (EST)]/text Infected: Email-Worm.Win32.Zhelatin.dam skipped
C:\Documents and Settings\username\Application Data\Thunderbird\Profiles\1okwu791.default\Mail\Local Folders\Inbox/[From "Robert G. Morris" ][Date Wed, 4 Oct 2006 10:50:58 -0400]/UNNAMED/[From =?ISO-8859-1?Q?casa?= ][Date 04 Oct 2006 11:26:14 -0400]/text/[From [Norton AntiSpam] melissa, Happy New Year from Hercules Hook][Date Wed, 24 Jan 2007 14:28:47 -0600]/UNNAMED Infected: Email-Worm.Win32.Zhelatin.dam skipped
C:\Documents and Settings\username\Application Data\Thunderbird\Profiles\1okwu791.default\Mail\Local Folders\Inbox/[From "Robert G. Morris" ][Date Wed, 4 Oct 2006 10:50:58 -0400]/UNNAMED/[From =?ISO-8859-1?Q?casa?= ][Date 04 Oct 2006 11:26:14 -0400]/text/[From "Porta Jump" ][Date Wed, 28 Feb 2007 09:48:55 -0600]/UNNAMED/[From "RingTone Shop" ][Date Wed, 28 Feb 2007 11:11:13 -0 ... /[From "Branch Banking and Trust" ][Date Wed, 28 Feb 2007 15:57:15 -0500]/UNNAMED Infected: Trojan-Spy.HTML.Bankfraud.ri skipped
C:\Documents and Settings\username\Application Data\Thunderbird\Profiles\1okwu791.default\Mail\Local Folders\Inbox/[From "Robert G. Morris" ][Date Wed, 4 Oct 2006 10:50:58 -0400]/UNNAMED/[From =?ISO-8859-1?Q?casa?= ][Date 04 Oct 2006 11:26:14 -0400]/text/[From "Porta Jump" ][Date Wed, 28 Feb 2007 09:48:55 -0600]/UNNAMED/[From "RingTone Shop" ][Date Wed, 28 Feb 2007 11:11:13 -0500]/html Infected: Trojan-Spy.HTML.Bankfraud.ri skipped
C:\Documents and Settings\username\Application Data\Thunderbird\Profiles\1okwu791.default\Mail\Local Folders\Inbox/[From "Robert G. Morris" ][Date Wed, 4 Oct 2006 10:50:58 -0400]/UNNAMED/[From =?ISO-8859-1?Q?casa?= ][Date 04 Oct 2006 11:26:14 -0400]/text/[From "Porta Jump" ][Date Wed, 28 Feb 2007 09:48:55 -0600]/UNNAMED Infected: Trojan-Spy.HTML.Bankfraud.ri skipped
C:\Documents and Settings\username\Application Data\Thunderbird\Profiles\1okwu791.default\Mail\Local Folders\Inbox/[From "Robert G. Morris" ][Date Wed, 4 Oct 2006 10:50:58 -0400]/UNNAMED/[From =?ISO-8859-1?Q?casa?= ][Date 04 Oct 2006 11:26:14 -0400]/text Infected: Trojan-Spy.HTML.Bankfraud.ri skipped
C:\Documents and Settings\username\Application Data\Thunderbird\Profiles\1okwu791.default\Mail\Local Folders\Inbox/[From "Robert G. Morris" ][Date Wed, 4 Oct 2006 10:50:58 -0400]/UNNAMED Infected: Trojan-Spy.HTML.Bankfraud.ri skipped
C:\Documents and Settings\username\Application Data\Thunderbird\Profiles\1okwu791.default\Mail\Local Folders\Inbox Mail Berkeley mbox: infected - 8 skipped
C:\Documents and Settings\username\Desktop\Downloads\AceHTMLPro\acehtml6pro.exe/data0007/data0146 Infected: not-a-virus:AdWare.Win32.BHO.w skipped
C:\Documents and Settings\username\Desktop\Downloads\AceHTMLPro\acehtml6pro.exe/data0007 Infected: not-a-virus:AdWare.Win32.BHO.w skipped
C:\Documents and Settings\username\Desktop\Downloads\AceHTMLPro\acehtml6pro.exe NSIS: infected - 2 skipped
C:\Documents and Settings\username\Desktop\Downloads\Rootkit Revealer\PsTools\pskill.exe Infected: not-a-virus:RiskTool.Win32.PsKill.k skipped
C:\Documents and Settings\username\Desktop\Downloads\Rootkit Revealer\PsTools.zip/pskill.exe Infected: not-a-virus:RiskTool.Win32.PsKill.k skipped
C:\Documents and Settings\username\Desktop\Downloads\Rootkit Revealer\PsTools.zip ZIP: infected - 1 skipped
C:\Documents and Settings\NetworkService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat Object is locked skipped
C:\Documents and Settings\NetworkService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped
C:\Documents and Settings\NetworkService\NTUSER.DAT Object is locked skipped
C:\Documents and Settings\NetworkService\ntuser.dat.LOG Object is locked skipped
C:\e690693f15bf96506769a1f716238b\msxml4-KB927978-enu.log Object is locked skipped
C:\System Volume Information\MountPointManagerRemoteDatabase Object is locked skipped
C:\System Volume Information\_restore{E28BBD50-0570-405B-9B46-4310F2CE5171}\RP209\change.log Object is locked skipped
C:\WINDOWS\Debug\PASSWD.LOG Object is locked skipped
C:\WINDOWS\system32\config\AppEvent.Evt Object is locked skipped
C:\WINDOWS\system32\config\default Object is locked skipped
C:\WINDOWS\system32\config\default.LOG Object is locked skipped
C:\WINDOWS\system32\config\SAM Object is locked skipped
C:\WINDOWS\system32\config\SAM.LOG Object is locked skipped
C:\WINDOWS\system32\config\SecEvent.Evt Object is locked skipped
C:\WINDOWS\system32\config\SECURITY Object is locked skipped
C:\WINDOWS\system32\config\SECURITY.LOG Object is locked skipped
C:\WINDOWS\system32\config\software Object is locked skipped
C:\WINDOWS\system32\config\software.LOG Object is locked skipped
C:\WINDOWS\system32\config\SysEvent.Evt Object is locked skipped
C:\WINDOWS\system32\config\system Object is locked skipped
C:\WINDOWS\system32\config\system.LOG Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\INDEX.BTR Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\INDEX.MAP Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\MAPPING.VER Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\MAPPING1.MAP Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\MAPPING2.MAP Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\OBJECTS.DATA Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\OBJECTS.MAP Object is locked skipped
Scan process completed.