Hi,
My PC has been infected with Virtumonde, and it keeps coming back again and again. I've done the Kaspersky scan, (see below). However when I used Spybot in safe mode, Virtumonde was always found even though I've cleaned 4 times already. Grateful for any help you guys can give! Thanks!
-------------------------------------------------------------------------------
KASPERSKY ONLINE SCANNER REPORT
Tuesday, April 22, 2008 8:21:49 AM
Operating System: Microsoft Windows Vista Home Edition, (Build 6000)
Kaspersky Online Scanner version: 5.0.98.0
Kaspersky Anti-Virus database last update: 21/04/2008
Kaspersky Anti-Virus database records: 718713
-------------------------------------------------------------------------------
Scan Settings:
Scan using the following antivirus database: extended
Scan Archives: true
Scan Mail Bases: true
Scan Target - My Computer:
C:\
D:\
E:\
F:\
G:\
Scan Statistics:
Total number of scanned objects: 196163
Number of viruses found: 6
Number of infected objects: 39
Number of suspicious objects: 0
Duration of the scan process: 03:23:18
Infected Object Name / Virus Name / Last Action
C:\boot\bcd Object is locked skipped
C:\boot\BCD.LOG Object is locked skipped
C:\is151942.exe Infected: Packed.Win32.Monder.gen skipped
C:\Program Files\Common Files\Symantec Shared\EENGINE\EPERSIST.DAT Object is locked skipped
C:\Program Files\Common Files\Symantec Shared\NFWEVT.LOG Object is locked skipped
C:\Program Files\Norton Internet Security\Norton AntiVirus\AVApp.log Object is locked skipped
C:\Program Files\Norton Internet Security\Norton AntiVirus\AVError.log Object is locked skipped
C:\Program Files\Norton Internet Security\Norton AntiVirus\AVVirus.log Object is locked skipped
C:\Program Files\Vonage\EasySetupGuide\Xtras\regxtra121.x32 Infected: Backdoor.Win32.RAdmin.ag skipped
C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\1f06bdd465de983deb2273bf05d5d29e_cbfecabc-f6dc-4cf1-abca-86c5dae1869f Object is locked skipped
C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\2b2effc925a836fafbfe6ab5b73fae7b_cbfecabc-f6dc-4cf1-abca-86c5dae1869f Object is locked skipped
C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\2f14738406d1415380d61821ec9690e7_cbfecabc-f6dc-4cf1-abca-86c5dae1869f Object is locked skipped
C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\4c06ac1796db8b2972548b9a5368701e_cbfecabc-f6dc-4cf1-abca-86c5dae1869f Object is locked skipped
C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\4dd74855cd590dfeda3872e7da814677_cbfecabc-f6dc-4cf1-abca-86c5dae1869f Object is locked skipped
C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\5c1a56bd2a1df4f7487a9fa7ce2cb3fd_cbfecabc-f6dc-4cf1-abca-86c5dae1869f Object is locked skipped
C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\ae469a39d43a8078b98963b014bf74c3_cbfecabc-f6dc-4cf1-abca-86c5dae1869f Object is locked skipped
C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\c382082bbce79ebf4231939807966e21_cbfecabc-f6dc-4cf1-abca-86c5dae1869f Object is locked skipped
C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\c571eabdf318f6b8af646d6d7e8e7f17_cbfecabc-f6dc-4cf1-abca-86c5dae1869f Object is locked skipped
C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\f2c43cfb16d18beb675c2fa850972067_cbfecabc-f6dc-4cf1-abca-86c5dae1869f Object is locked skipped
C:\ProgramData\Microsoft\Network\Downloader\qmgr0.dat Object is locked skipped
C:\ProgramData\Microsoft\Network\Downloader\qmgr1.dat Object is locked skipped
C:\ProgramData\Microsoft\Windows\DRM\Cache\Indiv01.tmp Object is locked skipped
C:\ProgramData\Microsoft\Windows\DRM\drmstore.hds Object is locked skipped
C:\ProgramData\NetZero\Isp\BootExceptions.log Object is locked skipped
C:\ProgramData\NetZero\Isp\ExecExceptions.log Object is locked skipped
C:\ProgramData\NetZero\Isp\IspDblog.txt Object is locked skipped
C:\ProgramData\NetZero\Isp\MainExceptions.log Object is locked skipped
C:\ProgramData\Symantec\Common Client\ccSubSDK\submissions.idx Object is locked skipped
C:\ProgramData\Symantec\Common Client\settings.DAT Object is locked skipped
C:\ProgramData\Symantec\Common Client\volatile.DAT Object is locked skipped
C:\ProgramData\Symantec\Common Client\{37551BB3-07AF-4B6E-BA6F-0583FC4E95E4}.DAT Object is locked skipped
C:\ProgramData\Symantec\Common Client\{F88AE57A-C83B-4D79-B0FA-017A9D1275DA}.DAT Object is locked skipped
C:\ProgramData\Symantec\Common Client\{FFF41699-B03C-4BAE-BDE1-E5A6E1DDB61C}.DAT Object is locked skipped
C:\ProgramData\Symantec\LiveUpdate\2008-04-21_Log.ALUSchedulerSvc.LiveUpdate Object is locked skipped
C:\ProgramData\Symantec\LiveUpdate\Log.LiveUpdate Object is locked skipped
C:\ProgramData\Symantec\SPBBC\BBConfig.log Object is locked skipped
C:\ProgramData\Symantec\SPBBC\BBDebug.log Object is locked skipped
C:\ProgramData\Symantec\SPBBC\BBDetect.log Object is locked skipped
C:\ProgramData\Symantec\SPBBC\BBNotify.log Object is locked skipped
C:\ProgramData\Symantec\SPBBC\BBRefr.log Object is locked skipped
C:\ProgramData\Symantec\SPBBC\BBSetCfg.log Object is locked skipped
C:\ProgramData\Symantec\SPBBC\BBSetCfg2.log Object is locked skipped
C:\ProgramData\Symantec\SPBBC\BBSetDev.log Object is locked skipped
C:\ProgramData\Symantec\SPBBC\BBSetLoc.log Object is locked skipped
C:\ProgramData\Symantec\SPBBC\BBSetUsr.log Object is locked skipped
C:\ProgramData\Symantec\SPBBC\BBStHash.log Object is locked skipped
C:\ProgramData\Symantec\SPBBC\BBValid.log Object is locked skipped
C:\ProgramData\Symantec\SPBBC\Shl_{C9AAC4A7-5CAA-49AB-BA08-1CDCBA97E206}.ldb Object is locked skipped
C:\ProgramData\Symantec\SPBBC\Shl_{C9AAC4A7-5CAA-49AB-BA08-1CDCBA97E206}.sds Object is locked skipped
C:\ProgramData\Symantec\SPBBC\SPPolicy.log Object is locked skipped
C:\ProgramData\Symantec\SPBBC\SPStart.log Object is locked skipped
C:\ProgramData\Symantec\SPBBC\SPStop.log Object is locked skipped
C:\ProgramData\Symantec\SRTSP\SrtErEvt.log Object is locked skipped
C:\ProgramData\Symantec\SRTSP\SrtETmp\9E3D4604.TMP Object is locked skipped
C:\ProgramData\Symantec\SRTSP\SrtETmp\F727CA9D.TMP Object is locked skipped
C:\ProgramData\Symantec\SRTSP\SrtMoEvt.log Object is locked skipped
C:\ProgramData\Symantec\SRTSP\SrtNvEvt.log Object is locked skipped
C:\ProgramData\Symantec\SRTSP\SrtScEvt.log Object is locked skipped
C:\ProgramData\Symantec\SRTSP\SrtTxFEvt.log Object is locked skipped
C:\ProgramData\Symantec\SRTSP\SrtViEvt.log Object is locked skipped
C:\ProgramData\Symantec\SymNetDrv\SNDALRT.log Object is locked skipped
C:\ProgramData\Symantec\SymNetDrv\SNDCON.log Object is locked skipped
C:\ProgramData\Symantec\SymNetDrv\SNDDBG.log Object is locked skipped
C:\ProgramData\Symantec\SymNetDrv\SNDFW.log Object is locked skipped
C:\ProgramData\Symantec\SymNetDrv\SNDIDS.log Object is locked skipped
C:\ProgramData\Symantec\SymNetDrv\SNDSYS.log Object is locked skipped
C:\System Volume Information\MountPointManagerRemoteDatabase Object is locked skipped
C:\Users\marc\AppData\Local\Apple Computer\Safari\Cache.db Object is locked skipped
C:\Users\marc\AppData\Local\Apple Computer\Safari\WebpageIcons.db Object is locked skipped
C:\Users\marc\AppData\Local\Microsoft\Feeds Cache\index.dat Object is locked skipped
C:\Users\marc\AppData\Local\Microsoft\Internet Explorer\MSIMGSIZ.DAT Object is locked skipped
C:\Users\marc\AppData\Local\Microsoft\Media Player\CurrentDatabase_360.wmdb Object is locked skipped
C:\Users\marc\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat Object is locked skipped
C:\Users\marc\AppData\Local\Microsoft\Windows\Temporary Internet Files\AntiPhishing\B3BB5BBA-E7D5-40AB-A041-A5B1C0B26C8F.dat Object is locked skipped
C:\Users\marc\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\0QFLZ49J\kriv[1] Infected: not-a-virus:AdWare.Win32.Virtumonde.pmw skipped
C:\Users\marc\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\0QFLZ49J\kriv[2] Infected: not-a-virus:AdWare.Win32.Virtumonde.pmw skipped
C:\Users\marc\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\BBQH5U2D\kriv[1] Infected: not-a-virus:AdWare.Win32.Virtumonde.pmw skipped
C:\Users\marc\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat Object is locked skipped
C:\Users\marc\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\JDYXEAVF\idkfa[1] Infected: not-a-virus:AdWare.Win32.Virtumonde.plw skipped
C:\Users\marc\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\T9A2OR8C\idkfa[1] Infected: not-a-virus:AdWare.Win32.Virtumonde.pmx skipped
C:\Users\marc\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\T9A2OR8C\kriv[1] Infected: not-a-virus:AdWare.Win32.Virtumonde.pmw skipped
C:\Users\marc\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\YCHAEVHL\idkfa[1] Infected: not-a-virus:AdWare.Win32.Virtumonde.plw skipped
C:\Users\marc\AppData\Local\Microsoft\Windows\UsrClass.dat Object is locked skipped
C:\Users\marc\AppData\Local\Microsoft\Windows\UsrClass.dat.LOG1 Object is locked skipped
C:\Users\marc\AppData\Local\Microsoft\Windows\UsrClass.dat.LOG2 Object is locked skipped
C:\Users\marc\AppData\Local\Microsoft\Windows\UsrClass.dat{b7aad9ac-0835-11dc-98d2-0019d2593fe3}.TM.blf Object is locked skipped
C:\Users\marc\AppData\Local\Microsoft\Windows\UsrClass.dat{b7aad9ac-0835-11dc-98d2-0019d2593fe3}.TMContainer00000000000000000001.regtrans-ms Object is locked skipped
C:\Users\marc\AppData\Local\Microsoft\Windows\UsrClass.dat{b7aad9ac-0835-11dc-98d2-0019d2593fe3}.TMContainer00000000000000000002.regtrans-ms Object is locked skipped
C:\Users\marc\AppData\Local\Microsoft\Windows Sidebar\Settings.ini Object is locked skipped
C:\Users\marc\AppData\Local\Temp\tmp0001e0bd Infected: Packed.Win32.Monder.gen skipped
C:\Users\marc\AppData\Local\Temp\tmp0002c8d9 Infected: Packed.Win32.Monder.gen skipped
C:\Users\marc\AppData\Local\Temp\tmp0002eea2 Infected: Packed.Win32.Monder.gen skipped
C:\Users\marc\AppData\Local\Temp\tmp00030694 Infected: Packed.Win32.Monder.gen skipped
C:\Users\marc\AppData\Local\Temp\tmp000324de Infected: Packed.Win32.Monder.gen skipped
C:\Users\marc\AppData\Local\Temp\tmp000340a7 Infected: Packed.Win32.Monder.gen skipped
C:\Users\marc\AppData\Local\Temp\tmp00037223 Infected: Packed.Win32.Monder.gen skipped
C:\Users\marc\AppData\Local\Temp\tmp0003b1d1 Infected: Packed.Win32.Monder.gen skipped
C:\Users\marc\AppData\Local\Temp\tmp0003d0c6 Infected: Packed.Win32.Monder.gen skipped
C:\Users\marc\AppData\Local\Temp\tmp0003e474 Infected: Packed.Win32.Monder.gen skipped
C:\Users\marc\AppData\Local\Temp\tmp0003fb2f Infected: Packed.Win32.Monder.gen skipped
C:\Users\marc\AppData\Local\Temp\tmp0003fef6 Infected: Packed.Win32.Monder.gen skipped
C:\Users\marc\AppData\Local\Temp\tmp00041e87 Infected: Packed.Win32.Monder.gen skipped
C:\Users\marc\AppData\Local\Temp\tmp000457b0 Infected: Packed.Win32.Monder.gen skipped
C:\Users\marc\AppData\Local\Temp\tmp0004f797 Infected: Packed.Win32.Monder.gen skipped
C:\Users\marc\AppData\Local\Temp\tmp000567f5 Infected: Packed.Win32.Monder.gen skipped
C:\Users\marc\AppData\Local\Temp\tmp0006c8ab Infected: Packed.Win32.Monder.gen skipped
C:\Users\marc\AppData\Local\Temp\tmp00074401 Infected: Packed.Win32.Monder.gen skipped
C:\Users\marc\AppData\Local\Temp\tmp000f2413 Infected: Packed.Win32.Monder.gen skipped
C:\Users\marc\AppData\Local\Temp\tmp00163f9e Infected: Packed.Win32.Monder.gen skipped
C:\Users\marc\AppData\Local\Temp\tmp01963b43 Infected: Packed.Win32.Monder.gen skipped
C:\Users\marc\AppData\Roaming\Apple Computer\Safari\PubSub\Database\Database.sqlite3 Object is locked skipped
C:\Users\marc\AppData\Roaming\Microsoft\Windows\Cookies\index.dat Object is locked skipped
C:\Users\marc\Documents\personal_folder.pst/Archive Folders/Inbox/Personal/03 Sep 2005 06:35 from Marc Edwards:Text info/Windows_XP_Service_Pack_2_by_Unknown_www.crack.cd_.zip/WinXP keyChanger.exe/data.rar/xpkey.exe Infected: not-a-virus
SWTool.Win32.RAS.a skipped
C:\Users\marc\Documents\personal_folder.pst/Archive Folders/Inbox/Personal/03 Sep 2005 06:35 from Marc Edwards:Text info/Windows_XP_Service_Pack_2_by_Unknown_www.crack.cd_.zip/WinXP keyChanger.exe/data.rar/officekey.exe Infected: not-a-virus
SWTool.Win32.RAS.a skipped
C:\Users\marc\Documents\personal_folder.pst/Archive Folders/Inbox/Personal/03 Sep 2005 06:35 from Marc Edwards:Text info/Windows_XP_Service_Pack_2_by_Unknown_www.crack.cd_.zip/WinXP keyChanger.exe/data.rar Infected: not-a-virus
SWTool.Win32.RAS.a skipped
C:\Users\marc\Documents\personal_folder.pst/Archive Folders/Inbox/Personal/03 Sep 2005 06:35 from Marc Edwards:Text info/Windows_XP_Service_Pack_2_by_Unknown_www.crack.cd_.zip/WinXP keyChanger.exe Infected: not-a-virus
SWTool.Win32.RAS.a skipped
C:\Users\marc\Documents\personal_folder.pst/Archive Folders/Inbox/Personal/03 Sep 2005 06:35 from Marc Edwards:Text info/Windows_XP_Service_Pack_2_by_Unknown_www.crack.cd_.zip Infected: not-a-virus
SWTool.Win32.RAS.a skipped
C:\Users\marc\Documents\personal_folder.pst Mail MS Mail: infected - 5 skipped
C:\Users\marc\ntuser.dat Object is locked skipped
C:\Users\marc\ntuser.dat.LOG1 Object is locked skipped
C:\Users\marc\ntuser.dat.LOG2 Object is locked skipped
C:\Users\marc\ntuser.dat{9c53bf42-d22f-11dc-b3ed-0016d39ac21f}.TM.blf Object is locked skipped
C:\Users\marc\ntuser.dat{9c53bf42-d22f-11dc-b3ed-0016d39ac21f}.TMContainer00000000000000000001.regtrans-ms Object is locked skipped
C:\Users\marc\ntuser.dat{9c53bf42-d22f-11dc-b3ed-0016d39ac21f}.TMContainer00000000000000000002.regtrans-ms Object is locked skipped
C:\Windows\Debug\PASSWD.LOG Object is locked skipped
C:\Windows\Debug\sam.log Object is locked skipped
C:\Windows\Debug\WIA\wiatrace.log Object is locked skipped
C:\Windows\ServiceProfiles\LocalService\AppData\Local\lastalive0.dat Object is locked skipped
C:\Windows\ServiceProfiles\LocalService\AppData\Local\lastalive1.dat Object is locked skipped
C:\Windows\ServiceProfiles\LocalService\AppData\Local\Microsoft\Windows\WindowsUpdate.log Object is locked skipped
C:\Windows\ServiceProfiles\LocalService\NTUSER.DAT Object is locked skipped
C:\Windows\ServiceProfiles\LocalService\ntuser.dat.LOG1 Object is locked skipped
C:\Windows\ServiceProfiles\LocalService\ntuser.dat.LOG2 Object is locked skipped
C:\Windows\ServiceProfiles\LocalService\NTUSER.DAT{d8932e65-6a6f-11db-b6ab-a038f15a5785}.TM.blf Object is locked skipped
C:\Windows\ServiceProfiles\LocalService\NTUSER.DAT{d8932e65-6a6f-11db-b6ab-a038f15a5785}.TMContainer00000000000000000001.regtrans-ms Object is locked skipped
C:\Windows\ServiceProfiles\LocalService\NTUSER.DAT{d8932e65-6a6f-11db-b6ab-a038f15a5785}.TMContainer00000000000000000002.regtrans-ms Object is locked skipped
C:\Windows\ServiceProfiles\NetworkService\NTUSER.DAT Object is locked skipped
C:\Windows\ServiceProfiles\NetworkService\ntuser.dat.LOG1 Object is locked skipped
C:\Windows\ServiceProfiles\NetworkService\ntuser.dat.LOG2 Object is locked skipped
C:\Windows\ServiceProfiles\NetworkService\NTUSER.DAT{d8932e61-6a6f-11db-b6ab-a038f15a5785}.TM.blf Object is locked skipped
C:\Windows\ServiceProfiles\NetworkService\NTUSER.DAT{d8932e61-6a6f-11db-b6ab-a038f15a5785}.TMContainer00000000000000000001.regtrans-ms Object is locked skipped
C:\Windows\ServiceProfiles\NetworkService\NTUSER.DAT{d8932e61-6a6f-11db-b6ab-a038f15a5785}.TMContainer00000000000000000002.regtrans-ms Object is locked skipped
C:\Windows\SoftwareDistribution\ReportingEvents.log Object is locked skipped
C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-0.C7483456-A289-439d-8115-601632D005A0 Object is locked skipped
C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-1.C7483456-A289-439d-8115-601632D005A0 Object is locked skipped
C:\Windows\System32\catroot2\edb.log Object is locked skipped
C:\Windows\System32\catroot2\{127D0A1D-4EF2-11D1-8608-00C04FC295EE}\catdb Object is locked skipped
C:\Windows\System32\catroot2\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\catdb Object is locked skipped
C:\Windows\System32\config\COMPONENTS Object is locked skipped
C:\Windows\System32\config\COMPONENTS.LOG1 Object is locked skipped
C:\Windows\System32\config\COMPONENTS.LOG2 Object is locked skipped
C:\Windows\System32\config\DEFAULT Object is locked skipped
C:\Windows\System32\config\DEFAULT.LOG1 Object is locked skipped
C:\Windows\System32\config\DEFAULT.LOG2 Object is locked skipped
C:\Windows\System32\config\RegBack\COMPONENTS Object is locked skipped
C:\Windows\System32\config\RegBack\DEFAULT Object is locked skipped
C:\Windows\System32\config\RegBack\SAM Object is locked skipped
C:\Windows\System32\config\RegBack\SECURITY Object is locked skipped
C:\Windows\System32\config\RegBack\SOFTWARE Object is locked skipped
C:\Windows\System32\config\RegBack\SYSTEM Object is locked skipped
C:\Windows\System32\config\SAM Object is locked skipped
C:\Windows\System32\config\SAM.LOG1 Object is locked skipped
C:\Windows\System32\config\SAM.LOG2 Object is locked skipped
C:\Windows\System32\config\SECURITY Object is locked skipped
C:\Windows\System32\config\SECURITY.LOG1 Object is locked skipped
C:\Windows\System32\config\SECURITY.LOG2 Object is locked skipped
C:\Windows\System32\config\SOFTWARE Object is locked skipped
C:\Windows\System32\config\SOFTWARE.LOG1 Object is locked skipped
C:\Windows\System32\config\SOFTWARE.LOG2 Object is locked skipped
C:\Windows\System32\config\SYSTEM Object is locked skipped
C:\Windows\System32\config\SYSTEM.LOG1 Object is locked skipped
C:\Windows\System32\config\SYSTEM.LOG2 Object is locked skipped
C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat Object is locked skipped
C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat Object is locked skipped
C:\Windows\System32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\index.dat Object is locked skipped
C:\Windows\System32\config\TxR\{250834B7-750C-494d-BDC3-DA86B6E2101B}.TM.blf Object is locked skipped
C:\Windows\System32\config\TxR\{250834B7-750C-494d-BDC3-DA86B6E2101B}.TMContainer00000000000000000001.regtrans-ms Object is locked skipped
C:\Windows\System32\config\TxR\{250834B7-750C-494d-BDC3-DA86B6E2101B}.TMContainer00000000000000000002.regtrans-ms Object is locked skipped
C:\Windows\System32\config\TxR\{9c53bf27-d22f-11dc-b3ed-0016d39ac21f}.TxR.0.regtrans-ms Object is locked skipped
C:\Windows\System32\config\TxR\{9c53bf27-d22f-11dc-b3ed-0016d39ac21f}.TxR.1.regtrans-ms Object is locked skipped
C:\Windows\System32\config\TxR\{9c53bf27-d22f-11dc-b3ed-0016d39ac21f}.TxR.2.regtrans-ms Object is locked skipped
C:\Windows\System32\config\TxR\{9c53bf27-d22f-11dc-b3ed-0016d39ac21f}.TxR.blf Object is locked skipped
C:\Windows\System32\Ikeext.etl Object is locked skipped
C:\Windows\System32\LogFiles\Scm\SCM.EVM Object is locked skipped
C:\Windows\System32\LogFiles\WUDF\WUDFTrace.etl Object is locked skipped
C:\Windows\System32\mljjhgf.dll Infected: Packed.Win32.Monder.gen skipped
C:\Windows\System32\Msdtc\KtmRmTm.blf Object is locked skipped
C:\Windows\System32\Msdtc\KtmRmTmContainer00000000000000000001 Object is locked skipped
C:\Windows\System32\Msdtc\KtmRmTmContainer00000000000000000002 Object is locked skipped
C:\Windows\System32\pmkhijh.dll Infected: Packed.Win32.Monder.gen skipped
C:\Windows\System32\spool\SpoolerETW.etl Object is locked skipped
C:\Windows\System32\tusrr.dll Infected: Packed.Win32.Monder.gen skipped
C:\Windows\System32\wbem\Logs\WMITracing.log Object is locked skipped
C:\Windows\System32\wbem\repository\INDEX.BTR Object is locked skipped
C:\Windows\System32\wbem\repository\MAPPING1.MAP Object is locked skipped
C:\Windows\System32\wbem\repository\MAPPING2.MAP Object is locked skipped
C:\Windows\System32\wbem\repository\OBJECTS.DATA Object is locked skipped
C:\Windows\System32\WDI\LogFiles\WdiContextLog.etl.002 Object is locked skipped
C:\Windows\System32\wfp\wfpdiag.etl Object is locked skipped
C:\Windows\System32\winevt\Logs\Application.evtx Object is locked skipped
C:\Windows\System32\winevt\Logs\DFS Replication.evtx Object is locked skipped
C:\Windows\System32\winevt\Logs\HardwareEvents.evtx Object is locked skipped
C:\Windows\System32\winevt\Logs\Internet Explorer.evtx Object is locked skipped
C:\Windows\System32\winevt\Logs\Key Management Service.evtx Object is locked skipped
C:\Windows\System32\winevt\Logs\Microsoft-Windows-Bits-Client%4Operational.evtx Object is locked skipped
C:\Windows\System32\winevt\Logs\Microsoft-Windows-CodeIntegrity%4Operational.evtx Object is locked skipped
C:\Windows\System32\winevt\Logs\Microsoft-Windows-Diagnosis-DPS%4Operational.evtx Object is locked skipped
C:\Windows\System32\winevt\Logs\Microsoft-Windows-Diagnostics-Performance%4Operational.evtx Object is locked skipped
C:\Windows\System32\winevt\Logs\Microsoft-Windows-DriverFrameworks-UserMode%4Operational.evtx Object is locked skipped
C:\Windows\System32\winevt\Logs\Microsoft-Windows-GroupPolicy%4Operational.evtx Object is locked skipped
C:\Windows\System32\winevt\Logs\Microsoft-Windows-International%4Operational.evtx Object is locked skipped
C:\Windows\System32\winevt\Logs\Microsoft-Windows-Kernel-WHEA.evtx Object is locked skipped
C:\Windows\System32\winevt\Logs\Microsoft-Windows-LanguagePackSetup%4Operational.evtx Object is locked skipped
C:\Windows\System32\winevt\Logs\Microsoft-Windows-NetworkAccessProtection%4Operational.evtx Object is locked skipped
C:\Windows\System32\winevt\Logs\Microsoft-Windows-ReadyBoost%4Operational.evtx Object is locked skipped
C:\Windows\System32\winevt\Logs\Microsoft-Windows-ReliabilityAnalysisComponent%4Operational.evtx Object is locked skipped
C:\Windows\System32\winevt\Logs\Microsoft-Windows-Resource-Exhaustion-Detector%4Operational.evtx Object is locked skipped
C:\Windows\System32\winevt\Logs\Microsoft-Windows-Resource-Exhaustion-Resolver%4Operational.evtx Object is locked skipped
C:\Windows\System32\winevt\Logs\Microsoft-Windows-Resource-Leak-Diagnostic%4Operational.evtx Object is locked skipped
C:\Windows\System32\winevt\Logs\Microsoft-Windows-RestartManager%4Operational.evtx Object is locked skipped
C:\Windows\System32\winevt\Logs\Microsoft-Windows-TaskScheduler%4Operational.evtx Object is locked skipped
C:\Windows\System32\winevt\Logs\Microsoft-Windows-WindowsUpdateClient%4Operational.evtx Object is locked skipped
C:\Windows\System32\winevt\Logs\Security.evtx Object is locked skipped
C:\Windows\System32\winevt\Logs\System.evtx Object is locked skipped
C:\Windows\Tasks\SCHEDLGU.TXT Object is locked skipped
C:\Windows\Temp\JETD3B2.tmp Object is locked skipped
C:\Windows\tracing\BAP.LOG Object is locked skipped
C:\Windows\tracing\IpHlpSvc.LOG Object is locked skipped
C:\Windows\tracing\kerberos\MARCANDLAN_kerberos_1_6_0_6000_0_0__300_6_0_6000_16386__vista_rtm_061101_2205_.etl Object is locked skipped
C:\Windows\tracing\KMDDSP.LOG Object is locked skipped
C:\Windows\tracing\NDPTSP.LOG Object is locked skipped
C:\Windows\tracing\PPP.LOG Object is locked skipped
C:\Windows\tracing\RASAPI32.LOG Object is locked skipped
C:\Windows\tracing\RASBACP.LOG Object is locked skipped
C:\Windows\tracing\RASCCP.LOG Object is locked skipped
C:\Windows\tracing\RASDLG.LOG Object is locked skipped
C:\Windows\tracing\RASEAP.LOG Object is locked skipped
C:\Windows\tracing\RASIPCP.LOG Object is locked skipped
C:\Windows\tracing\RASIPHLP.LOG Object is locked skipped
C:\Windows\tracing\RASIPV6CP.LOG Object is locked skipped
C:\Windows\tracing\RASMAN.LOG Object is locked skipped
C:\Windows\tracing\RASPAP.LOG Object is locked skipped
C:\Windows\tracing\RASQEC.LOG Object is locked skipped
C:\Windows\tracing\RASTAPI.LOG Object is locked skipped
C:\Windows\tracing\svchost_RASCHAP.LOG Object is locked skipped
C:\Windows\tracing\svchost_RASTLS.LOG Object is locked skipped
C:\Windows\tracing\tapi32.LOG Object is locked skipped
C:\Windows\tracing\tapisrv.LOG Object is locked skipped
C:\Windows\WindowsUpdate.log Object is locked skipped
D:\System Volume Information\Desktop.ini Object is locked skipped
D:\System Volume Information\Folder.htt Object is locked skipped
D:\System Volume Information\MountPointManagerRemoteDatabase Object is locked skipped
D:\System Volume Information\Protect.ed Object is locked skipped
Scan process completed.
My PC has been infected with Virtumonde, and it keeps coming back again and again. I've done the Kaspersky scan, (see below). However when I used Spybot in safe mode, Virtumonde was always found even though I've cleaned 4 times already. Grateful for any help you guys can give! Thanks!
-------------------------------------------------------------------------------
KASPERSKY ONLINE SCANNER REPORT
Tuesday, April 22, 2008 8:21:49 AM
Operating System: Microsoft Windows Vista Home Edition, (Build 6000)
Kaspersky Online Scanner version: 5.0.98.0
Kaspersky Anti-Virus database last update: 21/04/2008
Kaspersky Anti-Virus database records: 718713
-------------------------------------------------------------------------------
Scan Settings:
Scan using the following antivirus database: extended
Scan Archives: true
Scan Mail Bases: true
Scan Target - My Computer:
C:\
D:\
E:\
F:\
G:\
Scan Statistics:
Total number of scanned objects: 196163
Number of viruses found: 6
Number of infected objects: 39
Number of suspicious objects: 0
Duration of the scan process: 03:23:18
Infected Object Name / Virus Name / Last Action
C:\boot\bcd Object is locked skipped
C:\boot\BCD.LOG Object is locked skipped
C:\is151942.exe Infected: Packed.Win32.Monder.gen skipped
C:\Program Files\Common Files\Symantec Shared\EENGINE\EPERSIST.DAT Object is locked skipped
C:\Program Files\Common Files\Symantec Shared\NFWEVT.LOG Object is locked skipped
C:\Program Files\Norton Internet Security\Norton AntiVirus\AVApp.log Object is locked skipped
C:\Program Files\Norton Internet Security\Norton AntiVirus\AVError.log Object is locked skipped
C:\Program Files\Norton Internet Security\Norton AntiVirus\AVVirus.log Object is locked skipped
C:\Program Files\Vonage\EasySetupGuide\Xtras\regxtra121.x32 Infected: Backdoor.Win32.RAdmin.ag skipped
C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\1f06bdd465de983deb2273bf05d5d29e_cbfecabc-f6dc-4cf1-abca-86c5dae1869f Object is locked skipped
C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\2b2effc925a836fafbfe6ab5b73fae7b_cbfecabc-f6dc-4cf1-abca-86c5dae1869f Object is locked skipped
C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\2f14738406d1415380d61821ec9690e7_cbfecabc-f6dc-4cf1-abca-86c5dae1869f Object is locked skipped
C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\4c06ac1796db8b2972548b9a5368701e_cbfecabc-f6dc-4cf1-abca-86c5dae1869f Object is locked skipped
C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\4dd74855cd590dfeda3872e7da814677_cbfecabc-f6dc-4cf1-abca-86c5dae1869f Object is locked skipped
C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\5c1a56bd2a1df4f7487a9fa7ce2cb3fd_cbfecabc-f6dc-4cf1-abca-86c5dae1869f Object is locked skipped
C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\ae469a39d43a8078b98963b014bf74c3_cbfecabc-f6dc-4cf1-abca-86c5dae1869f Object is locked skipped
C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\c382082bbce79ebf4231939807966e21_cbfecabc-f6dc-4cf1-abca-86c5dae1869f Object is locked skipped
C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\c571eabdf318f6b8af646d6d7e8e7f17_cbfecabc-f6dc-4cf1-abca-86c5dae1869f Object is locked skipped
C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\f2c43cfb16d18beb675c2fa850972067_cbfecabc-f6dc-4cf1-abca-86c5dae1869f Object is locked skipped
C:\ProgramData\Microsoft\Network\Downloader\qmgr0.dat Object is locked skipped
C:\ProgramData\Microsoft\Network\Downloader\qmgr1.dat Object is locked skipped
C:\ProgramData\Microsoft\Windows\DRM\Cache\Indiv01.tmp Object is locked skipped
C:\ProgramData\Microsoft\Windows\DRM\drmstore.hds Object is locked skipped
C:\ProgramData\NetZero\Isp\BootExceptions.log Object is locked skipped
C:\ProgramData\NetZero\Isp\ExecExceptions.log Object is locked skipped
C:\ProgramData\NetZero\Isp\IspDblog.txt Object is locked skipped
C:\ProgramData\NetZero\Isp\MainExceptions.log Object is locked skipped
C:\ProgramData\Symantec\Common Client\ccSubSDK\submissions.idx Object is locked skipped
C:\ProgramData\Symantec\Common Client\settings.DAT Object is locked skipped
C:\ProgramData\Symantec\Common Client\volatile.DAT Object is locked skipped
C:\ProgramData\Symantec\Common Client\{37551BB3-07AF-4B6E-BA6F-0583FC4E95E4}.DAT Object is locked skipped
C:\ProgramData\Symantec\Common Client\{F88AE57A-C83B-4D79-B0FA-017A9D1275DA}.DAT Object is locked skipped
C:\ProgramData\Symantec\Common Client\{FFF41699-B03C-4BAE-BDE1-E5A6E1DDB61C}.DAT Object is locked skipped
C:\ProgramData\Symantec\LiveUpdate\2008-04-21_Log.ALUSchedulerSvc.LiveUpdate Object is locked skipped
C:\ProgramData\Symantec\LiveUpdate\Log.LiveUpdate Object is locked skipped
C:\ProgramData\Symantec\SPBBC\BBConfig.log Object is locked skipped
C:\ProgramData\Symantec\SPBBC\BBDebug.log Object is locked skipped
C:\ProgramData\Symantec\SPBBC\BBDetect.log Object is locked skipped
C:\ProgramData\Symantec\SPBBC\BBNotify.log Object is locked skipped
C:\ProgramData\Symantec\SPBBC\BBRefr.log Object is locked skipped
C:\ProgramData\Symantec\SPBBC\BBSetCfg.log Object is locked skipped
C:\ProgramData\Symantec\SPBBC\BBSetCfg2.log Object is locked skipped
C:\ProgramData\Symantec\SPBBC\BBSetDev.log Object is locked skipped
C:\ProgramData\Symantec\SPBBC\BBSetLoc.log Object is locked skipped
C:\ProgramData\Symantec\SPBBC\BBSetUsr.log Object is locked skipped
C:\ProgramData\Symantec\SPBBC\BBStHash.log Object is locked skipped
C:\ProgramData\Symantec\SPBBC\BBValid.log Object is locked skipped
C:\ProgramData\Symantec\SPBBC\Shl_{C9AAC4A7-5CAA-49AB-BA08-1CDCBA97E206}.ldb Object is locked skipped
C:\ProgramData\Symantec\SPBBC\Shl_{C9AAC4A7-5CAA-49AB-BA08-1CDCBA97E206}.sds Object is locked skipped
C:\ProgramData\Symantec\SPBBC\SPPolicy.log Object is locked skipped
C:\ProgramData\Symantec\SPBBC\SPStart.log Object is locked skipped
C:\ProgramData\Symantec\SPBBC\SPStop.log Object is locked skipped
C:\ProgramData\Symantec\SRTSP\SrtErEvt.log Object is locked skipped
C:\ProgramData\Symantec\SRTSP\SrtETmp\9E3D4604.TMP Object is locked skipped
C:\ProgramData\Symantec\SRTSP\SrtETmp\F727CA9D.TMP Object is locked skipped
C:\ProgramData\Symantec\SRTSP\SrtMoEvt.log Object is locked skipped
C:\ProgramData\Symantec\SRTSP\SrtNvEvt.log Object is locked skipped
C:\ProgramData\Symantec\SRTSP\SrtScEvt.log Object is locked skipped
C:\ProgramData\Symantec\SRTSP\SrtTxFEvt.log Object is locked skipped
C:\ProgramData\Symantec\SRTSP\SrtViEvt.log Object is locked skipped
C:\ProgramData\Symantec\SymNetDrv\SNDALRT.log Object is locked skipped
C:\ProgramData\Symantec\SymNetDrv\SNDCON.log Object is locked skipped
C:\ProgramData\Symantec\SymNetDrv\SNDDBG.log Object is locked skipped
C:\ProgramData\Symantec\SymNetDrv\SNDFW.log Object is locked skipped
C:\ProgramData\Symantec\SymNetDrv\SNDIDS.log Object is locked skipped
C:\ProgramData\Symantec\SymNetDrv\SNDSYS.log Object is locked skipped
C:\System Volume Information\MountPointManagerRemoteDatabase Object is locked skipped
C:\Users\marc\AppData\Local\Apple Computer\Safari\Cache.db Object is locked skipped
C:\Users\marc\AppData\Local\Apple Computer\Safari\WebpageIcons.db Object is locked skipped
C:\Users\marc\AppData\Local\Microsoft\Feeds Cache\index.dat Object is locked skipped
C:\Users\marc\AppData\Local\Microsoft\Internet Explorer\MSIMGSIZ.DAT Object is locked skipped
C:\Users\marc\AppData\Local\Microsoft\Media Player\CurrentDatabase_360.wmdb Object is locked skipped
C:\Users\marc\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat Object is locked skipped
C:\Users\marc\AppData\Local\Microsoft\Windows\Temporary Internet Files\AntiPhishing\B3BB5BBA-E7D5-40AB-A041-A5B1C0B26C8F.dat Object is locked skipped
C:\Users\marc\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\0QFLZ49J\kriv[1] Infected: not-a-virus:AdWare.Win32.Virtumonde.pmw skipped
C:\Users\marc\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\0QFLZ49J\kriv[2] Infected: not-a-virus:AdWare.Win32.Virtumonde.pmw skipped
C:\Users\marc\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\BBQH5U2D\kriv[1] Infected: not-a-virus:AdWare.Win32.Virtumonde.pmw skipped
C:\Users\marc\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat Object is locked skipped
C:\Users\marc\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\JDYXEAVF\idkfa[1] Infected: not-a-virus:AdWare.Win32.Virtumonde.plw skipped
C:\Users\marc\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\T9A2OR8C\idkfa[1] Infected: not-a-virus:AdWare.Win32.Virtumonde.pmx skipped
C:\Users\marc\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\T9A2OR8C\kriv[1] Infected: not-a-virus:AdWare.Win32.Virtumonde.pmw skipped
C:\Users\marc\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\YCHAEVHL\idkfa[1] Infected: not-a-virus:AdWare.Win32.Virtumonde.plw skipped
C:\Users\marc\AppData\Local\Microsoft\Windows\UsrClass.dat Object is locked skipped
C:\Users\marc\AppData\Local\Microsoft\Windows\UsrClass.dat.LOG1 Object is locked skipped
C:\Users\marc\AppData\Local\Microsoft\Windows\UsrClass.dat.LOG2 Object is locked skipped
C:\Users\marc\AppData\Local\Microsoft\Windows\UsrClass.dat{b7aad9ac-0835-11dc-98d2-0019d2593fe3}.TM.blf Object is locked skipped
C:\Users\marc\AppData\Local\Microsoft\Windows\UsrClass.dat{b7aad9ac-0835-11dc-98d2-0019d2593fe3}.TMContainer00000000000000000001.regtrans-ms Object is locked skipped
C:\Users\marc\AppData\Local\Microsoft\Windows\UsrClass.dat{b7aad9ac-0835-11dc-98d2-0019d2593fe3}.TMContainer00000000000000000002.regtrans-ms Object is locked skipped
C:\Users\marc\AppData\Local\Microsoft\Windows Sidebar\Settings.ini Object is locked skipped
C:\Users\marc\AppData\Local\Temp\tmp0001e0bd Infected: Packed.Win32.Monder.gen skipped
C:\Users\marc\AppData\Local\Temp\tmp0002c8d9 Infected: Packed.Win32.Monder.gen skipped
C:\Users\marc\AppData\Local\Temp\tmp0002eea2 Infected: Packed.Win32.Monder.gen skipped
C:\Users\marc\AppData\Local\Temp\tmp00030694 Infected: Packed.Win32.Monder.gen skipped
C:\Users\marc\AppData\Local\Temp\tmp000324de Infected: Packed.Win32.Monder.gen skipped
C:\Users\marc\AppData\Local\Temp\tmp000340a7 Infected: Packed.Win32.Monder.gen skipped
C:\Users\marc\AppData\Local\Temp\tmp00037223 Infected: Packed.Win32.Monder.gen skipped
C:\Users\marc\AppData\Local\Temp\tmp0003b1d1 Infected: Packed.Win32.Monder.gen skipped
C:\Users\marc\AppData\Local\Temp\tmp0003d0c6 Infected: Packed.Win32.Monder.gen skipped
C:\Users\marc\AppData\Local\Temp\tmp0003e474 Infected: Packed.Win32.Monder.gen skipped
C:\Users\marc\AppData\Local\Temp\tmp0003fb2f Infected: Packed.Win32.Monder.gen skipped
C:\Users\marc\AppData\Local\Temp\tmp0003fef6 Infected: Packed.Win32.Monder.gen skipped
C:\Users\marc\AppData\Local\Temp\tmp00041e87 Infected: Packed.Win32.Monder.gen skipped
C:\Users\marc\AppData\Local\Temp\tmp000457b0 Infected: Packed.Win32.Monder.gen skipped
C:\Users\marc\AppData\Local\Temp\tmp0004f797 Infected: Packed.Win32.Monder.gen skipped
C:\Users\marc\AppData\Local\Temp\tmp000567f5 Infected: Packed.Win32.Monder.gen skipped
C:\Users\marc\AppData\Local\Temp\tmp0006c8ab Infected: Packed.Win32.Monder.gen skipped
C:\Users\marc\AppData\Local\Temp\tmp00074401 Infected: Packed.Win32.Monder.gen skipped
C:\Users\marc\AppData\Local\Temp\tmp000f2413 Infected: Packed.Win32.Monder.gen skipped
C:\Users\marc\AppData\Local\Temp\tmp00163f9e Infected: Packed.Win32.Monder.gen skipped
C:\Users\marc\AppData\Local\Temp\tmp01963b43 Infected: Packed.Win32.Monder.gen skipped
C:\Users\marc\AppData\Roaming\Apple Computer\Safari\PubSub\Database\Database.sqlite3 Object is locked skipped
C:\Users\marc\AppData\Roaming\Microsoft\Windows\Cookies\index.dat Object is locked skipped
C:\Users\marc\Documents\personal_folder.pst/Archive Folders/Inbox/Personal/03 Sep 2005 06:35 from Marc Edwards:Text info/Windows_XP_Service_Pack_2_by_Unknown_www.crack.cd_.zip/WinXP keyChanger.exe/data.rar/xpkey.exe Infected: not-a-virus

C:\Users\marc\Documents\personal_folder.pst/Archive Folders/Inbox/Personal/03 Sep 2005 06:35 from Marc Edwards:Text info/Windows_XP_Service_Pack_2_by_Unknown_www.crack.cd_.zip/WinXP keyChanger.exe/data.rar/officekey.exe Infected: not-a-virus

C:\Users\marc\Documents\personal_folder.pst/Archive Folders/Inbox/Personal/03 Sep 2005 06:35 from Marc Edwards:Text info/Windows_XP_Service_Pack_2_by_Unknown_www.crack.cd_.zip/WinXP keyChanger.exe/data.rar Infected: not-a-virus

C:\Users\marc\Documents\personal_folder.pst/Archive Folders/Inbox/Personal/03 Sep 2005 06:35 from Marc Edwards:Text info/Windows_XP_Service_Pack_2_by_Unknown_www.crack.cd_.zip/WinXP keyChanger.exe Infected: not-a-virus

C:\Users\marc\Documents\personal_folder.pst/Archive Folders/Inbox/Personal/03 Sep 2005 06:35 from Marc Edwards:Text info/Windows_XP_Service_Pack_2_by_Unknown_www.crack.cd_.zip Infected: not-a-virus

C:\Users\marc\Documents\personal_folder.pst Mail MS Mail: infected - 5 skipped
C:\Users\marc\ntuser.dat Object is locked skipped
C:\Users\marc\ntuser.dat.LOG1 Object is locked skipped
C:\Users\marc\ntuser.dat.LOG2 Object is locked skipped
C:\Users\marc\ntuser.dat{9c53bf42-d22f-11dc-b3ed-0016d39ac21f}.TM.blf Object is locked skipped
C:\Users\marc\ntuser.dat{9c53bf42-d22f-11dc-b3ed-0016d39ac21f}.TMContainer00000000000000000001.regtrans-ms Object is locked skipped
C:\Users\marc\ntuser.dat{9c53bf42-d22f-11dc-b3ed-0016d39ac21f}.TMContainer00000000000000000002.regtrans-ms Object is locked skipped
C:\Windows\Debug\PASSWD.LOG Object is locked skipped
C:\Windows\Debug\sam.log Object is locked skipped
C:\Windows\Debug\WIA\wiatrace.log Object is locked skipped
C:\Windows\ServiceProfiles\LocalService\AppData\Local\lastalive0.dat Object is locked skipped
C:\Windows\ServiceProfiles\LocalService\AppData\Local\lastalive1.dat Object is locked skipped
C:\Windows\ServiceProfiles\LocalService\AppData\Local\Microsoft\Windows\WindowsUpdate.log Object is locked skipped
C:\Windows\ServiceProfiles\LocalService\NTUSER.DAT Object is locked skipped
C:\Windows\ServiceProfiles\LocalService\ntuser.dat.LOG1 Object is locked skipped
C:\Windows\ServiceProfiles\LocalService\ntuser.dat.LOG2 Object is locked skipped
C:\Windows\ServiceProfiles\LocalService\NTUSER.DAT{d8932e65-6a6f-11db-b6ab-a038f15a5785}.TM.blf Object is locked skipped
C:\Windows\ServiceProfiles\LocalService\NTUSER.DAT{d8932e65-6a6f-11db-b6ab-a038f15a5785}.TMContainer00000000000000000001.regtrans-ms Object is locked skipped
C:\Windows\ServiceProfiles\LocalService\NTUSER.DAT{d8932e65-6a6f-11db-b6ab-a038f15a5785}.TMContainer00000000000000000002.regtrans-ms Object is locked skipped
C:\Windows\ServiceProfiles\NetworkService\NTUSER.DAT Object is locked skipped
C:\Windows\ServiceProfiles\NetworkService\ntuser.dat.LOG1 Object is locked skipped
C:\Windows\ServiceProfiles\NetworkService\ntuser.dat.LOG2 Object is locked skipped
C:\Windows\ServiceProfiles\NetworkService\NTUSER.DAT{d8932e61-6a6f-11db-b6ab-a038f15a5785}.TM.blf Object is locked skipped
C:\Windows\ServiceProfiles\NetworkService\NTUSER.DAT{d8932e61-6a6f-11db-b6ab-a038f15a5785}.TMContainer00000000000000000001.regtrans-ms Object is locked skipped
C:\Windows\ServiceProfiles\NetworkService\NTUSER.DAT{d8932e61-6a6f-11db-b6ab-a038f15a5785}.TMContainer00000000000000000002.regtrans-ms Object is locked skipped
C:\Windows\SoftwareDistribution\ReportingEvents.log Object is locked skipped
C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-0.C7483456-A289-439d-8115-601632D005A0 Object is locked skipped
C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-1.C7483456-A289-439d-8115-601632D005A0 Object is locked skipped
C:\Windows\System32\catroot2\edb.log Object is locked skipped
C:\Windows\System32\catroot2\{127D0A1D-4EF2-11D1-8608-00C04FC295EE}\catdb Object is locked skipped
C:\Windows\System32\catroot2\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\catdb Object is locked skipped
C:\Windows\System32\config\COMPONENTS Object is locked skipped
C:\Windows\System32\config\COMPONENTS.LOG1 Object is locked skipped
C:\Windows\System32\config\COMPONENTS.LOG2 Object is locked skipped
C:\Windows\System32\config\DEFAULT Object is locked skipped
C:\Windows\System32\config\DEFAULT.LOG1 Object is locked skipped
C:\Windows\System32\config\DEFAULT.LOG2 Object is locked skipped
C:\Windows\System32\config\RegBack\COMPONENTS Object is locked skipped
C:\Windows\System32\config\RegBack\DEFAULT Object is locked skipped
C:\Windows\System32\config\RegBack\SAM Object is locked skipped
C:\Windows\System32\config\RegBack\SECURITY Object is locked skipped
C:\Windows\System32\config\RegBack\SOFTWARE Object is locked skipped
C:\Windows\System32\config\RegBack\SYSTEM Object is locked skipped
C:\Windows\System32\config\SAM Object is locked skipped
C:\Windows\System32\config\SAM.LOG1 Object is locked skipped
C:\Windows\System32\config\SAM.LOG2 Object is locked skipped
C:\Windows\System32\config\SECURITY Object is locked skipped
C:\Windows\System32\config\SECURITY.LOG1 Object is locked skipped
C:\Windows\System32\config\SECURITY.LOG2 Object is locked skipped
C:\Windows\System32\config\SOFTWARE Object is locked skipped
C:\Windows\System32\config\SOFTWARE.LOG1 Object is locked skipped
C:\Windows\System32\config\SOFTWARE.LOG2 Object is locked skipped
C:\Windows\System32\config\SYSTEM Object is locked skipped
C:\Windows\System32\config\SYSTEM.LOG1 Object is locked skipped
C:\Windows\System32\config\SYSTEM.LOG2 Object is locked skipped
C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat Object is locked skipped
C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat Object is locked skipped
C:\Windows\System32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\index.dat Object is locked skipped
C:\Windows\System32\config\TxR\{250834B7-750C-494d-BDC3-DA86B6E2101B}.TM.blf Object is locked skipped
C:\Windows\System32\config\TxR\{250834B7-750C-494d-BDC3-DA86B6E2101B}.TMContainer00000000000000000001.regtrans-ms Object is locked skipped
C:\Windows\System32\config\TxR\{250834B7-750C-494d-BDC3-DA86B6E2101B}.TMContainer00000000000000000002.regtrans-ms Object is locked skipped
C:\Windows\System32\config\TxR\{9c53bf27-d22f-11dc-b3ed-0016d39ac21f}.TxR.0.regtrans-ms Object is locked skipped
C:\Windows\System32\config\TxR\{9c53bf27-d22f-11dc-b3ed-0016d39ac21f}.TxR.1.regtrans-ms Object is locked skipped
C:\Windows\System32\config\TxR\{9c53bf27-d22f-11dc-b3ed-0016d39ac21f}.TxR.2.regtrans-ms Object is locked skipped
C:\Windows\System32\config\TxR\{9c53bf27-d22f-11dc-b3ed-0016d39ac21f}.TxR.blf Object is locked skipped
C:\Windows\System32\Ikeext.etl Object is locked skipped
C:\Windows\System32\LogFiles\Scm\SCM.EVM Object is locked skipped
C:\Windows\System32\LogFiles\WUDF\WUDFTrace.etl Object is locked skipped
C:\Windows\System32\mljjhgf.dll Infected: Packed.Win32.Monder.gen skipped
C:\Windows\System32\Msdtc\KtmRmTm.blf Object is locked skipped
C:\Windows\System32\Msdtc\KtmRmTmContainer00000000000000000001 Object is locked skipped
C:\Windows\System32\Msdtc\KtmRmTmContainer00000000000000000002 Object is locked skipped
C:\Windows\System32\pmkhijh.dll Infected: Packed.Win32.Monder.gen skipped
C:\Windows\System32\spool\SpoolerETW.etl Object is locked skipped
C:\Windows\System32\tusrr.dll Infected: Packed.Win32.Monder.gen skipped
C:\Windows\System32\wbem\Logs\WMITracing.log Object is locked skipped
C:\Windows\System32\wbem\repository\INDEX.BTR Object is locked skipped
C:\Windows\System32\wbem\repository\MAPPING1.MAP Object is locked skipped
C:\Windows\System32\wbem\repository\MAPPING2.MAP Object is locked skipped
C:\Windows\System32\wbem\repository\OBJECTS.DATA Object is locked skipped
C:\Windows\System32\WDI\LogFiles\WdiContextLog.etl.002 Object is locked skipped
C:\Windows\System32\wfp\wfpdiag.etl Object is locked skipped
C:\Windows\System32\winevt\Logs\Application.evtx Object is locked skipped
C:\Windows\System32\winevt\Logs\DFS Replication.evtx Object is locked skipped
C:\Windows\System32\winevt\Logs\HardwareEvents.evtx Object is locked skipped
C:\Windows\System32\winevt\Logs\Internet Explorer.evtx Object is locked skipped
C:\Windows\System32\winevt\Logs\Key Management Service.evtx Object is locked skipped
C:\Windows\System32\winevt\Logs\Microsoft-Windows-Bits-Client%4Operational.evtx Object is locked skipped
C:\Windows\System32\winevt\Logs\Microsoft-Windows-CodeIntegrity%4Operational.evtx Object is locked skipped
C:\Windows\System32\winevt\Logs\Microsoft-Windows-Diagnosis-DPS%4Operational.evtx Object is locked skipped
C:\Windows\System32\winevt\Logs\Microsoft-Windows-Diagnostics-Performance%4Operational.evtx Object is locked skipped
C:\Windows\System32\winevt\Logs\Microsoft-Windows-DriverFrameworks-UserMode%4Operational.evtx Object is locked skipped
C:\Windows\System32\winevt\Logs\Microsoft-Windows-GroupPolicy%4Operational.evtx Object is locked skipped
C:\Windows\System32\winevt\Logs\Microsoft-Windows-International%4Operational.evtx Object is locked skipped
C:\Windows\System32\winevt\Logs\Microsoft-Windows-Kernel-WHEA.evtx Object is locked skipped
C:\Windows\System32\winevt\Logs\Microsoft-Windows-LanguagePackSetup%4Operational.evtx Object is locked skipped
C:\Windows\System32\winevt\Logs\Microsoft-Windows-NetworkAccessProtection%4Operational.evtx Object is locked skipped
C:\Windows\System32\winevt\Logs\Microsoft-Windows-ReadyBoost%4Operational.evtx Object is locked skipped
C:\Windows\System32\winevt\Logs\Microsoft-Windows-ReliabilityAnalysisComponent%4Operational.evtx Object is locked skipped
C:\Windows\System32\winevt\Logs\Microsoft-Windows-Resource-Exhaustion-Detector%4Operational.evtx Object is locked skipped
C:\Windows\System32\winevt\Logs\Microsoft-Windows-Resource-Exhaustion-Resolver%4Operational.evtx Object is locked skipped
C:\Windows\System32\winevt\Logs\Microsoft-Windows-Resource-Leak-Diagnostic%4Operational.evtx Object is locked skipped
C:\Windows\System32\winevt\Logs\Microsoft-Windows-RestartManager%4Operational.evtx Object is locked skipped
C:\Windows\System32\winevt\Logs\Microsoft-Windows-TaskScheduler%4Operational.evtx Object is locked skipped
C:\Windows\System32\winevt\Logs\Microsoft-Windows-WindowsUpdateClient%4Operational.evtx Object is locked skipped
C:\Windows\System32\winevt\Logs\Security.evtx Object is locked skipped
C:\Windows\System32\winevt\Logs\System.evtx Object is locked skipped
C:\Windows\Tasks\SCHEDLGU.TXT Object is locked skipped
C:\Windows\Temp\JETD3B2.tmp Object is locked skipped
C:\Windows\tracing\BAP.LOG Object is locked skipped
C:\Windows\tracing\IpHlpSvc.LOG Object is locked skipped
C:\Windows\tracing\kerberos\MARCANDLAN_kerberos_1_6_0_6000_0_0__300_6_0_6000_16386__vista_rtm_061101_2205_.etl Object is locked skipped
C:\Windows\tracing\KMDDSP.LOG Object is locked skipped
C:\Windows\tracing\NDPTSP.LOG Object is locked skipped
C:\Windows\tracing\PPP.LOG Object is locked skipped
C:\Windows\tracing\RASAPI32.LOG Object is locked skipped
C:\Windows\tracing\RASBACP.LOG Object is locked skipped
C:\Windows\tracing\RASCCP.LOG Object is locked skipped
C:\Windows\tracing\RASDLG.LOG Object is locked skipped
C:\Windows\tracing\RASEAP.LOG Object is locked skipped
C:\Windows\tracing\RASIPCP.LOG Object is locked skipped
C:\Windows\tracing\RASIPHLP.LOG Object is locked skipped
C:\Windows\tracing\RASIPV6CP.LOG Object is locked skipped
C:\Windows\tracing\RASMAN.LOG Object is locked skipped
C:\Windows\tracing\RASPAP.LOG Object is locked skipped
C:\Windows\tracing\RASQEC.LOG Object is locked skipped
C:\Windows\tracing\RASTAPI.LOG Object is locked skipped
C:\Windows\tracing\svchost_RASCHAP.LOG Object is locked skipped
C:\Windows\tracing\svchost_RASTLS.LOG Object is locked skipped
C:\Windows\tracing\tapi32.LOG Object is locked skipped
C:\Windows\tracing\tapisrv.LOG Object is locked skipped
C:\Windows\WindowsUpdate.log Object is locked skipped
D:\System Volume Information\Desktop.ini Object is locked skipped
D:\System Volume Information\Folder.htt Object is locked skipped
D:\System Volume Information\MountPointManagerRemoteDatabase Object is locked skipped
D:\System Volume Information\Protect.ed Object is locked skipped
Scan process completed.