Jump to content

Build Theme!
  •  
  • Infected?

WE'RE SURE THAT YOU'LL LOVE US!

Hey there! :wub: Looks like you're enjoying the discussion, but you're not signed up for an account. When you create an account, we remember exactly what you've read, so you always come right back where you left off. You also get notifications, here and via email, whenever new posts are made. You can like posts to share the love. :D Join 93105 other members! Anybody can ask, anybody can answer. Consistently helpful members may be invited to become staff. Here's how it works. Virus cleanup? Start here -> Malware Removal Forum.

Try What the Tech -- It's free!


Photo

[Closed] Vundo...and More Vundo


  • This topic is locked This topic is locked
14 replies to this topic

#1 Master Luke

Master Luke

    New Member

  • Authentic Member
  • Pip
  • 8 posts

Posted 14 August 2007 - 03:35 PM

Norton Antivirus has told me numerous times that Trojan Vundo has been removed from my computer, but also tells me that portions of it remain. I have tried their removal tool and one from another company, but files like geedb.dll keep coming back for more, along with it's buddy bdeep, or something like that.

I am getting unwanted launchings of IE Explorer (which I have calmed down by denying it web access through Zone Alarm...), but even Firefox is getting pop-ups I can well do without.

Please tell me how to get rid of this unremovable pest! I am posting a Hijack This Log below:

Logfile of HijackThis v1.99.1
Scan saved at 14:54:58, on 08/14/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16473)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Ahead\InCD\InCDsrv.exe
C:\WINDOWS\system32\ZoneLabs\vsmon.exe
C:\WINDOWS\system32\LEXBCES.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\LEXPPS.EXE
C:\Program Files\APC\APC PowerChute Personal Edition\mainserv.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
C:\Program Files\FolderSize\FolderSizeSvc.exe
C:\Program Files\Norton SystemWorks\Norton Ghost\GhostStartService.exe
C:\Program Files\Norton SystemWorks\Norton AntiVirus\navapsvc.exe
C:\Program Files\Norton SystemWorks\Norton Utilities\NPROTECT.EXE
C:\WINDOWS\System32\snmp.exe
C:\PROGRA~1\NORTON~2\SPEEDD~1\nopdb.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosBtSrv.exe
C:\WINDOWS\system32\taskmgr.exe
C:\WINDOWS\explorer.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\WINDOWS\system32\ctfmon.exe
C:\WINDOWS\system32\wuauclt.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Program Files\Outlook Express\msimn.exe
C:\Program Files\Messenger\msmsgs.exe
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\WINDOWS\system32\wuauclt.exe
C:\Program Files\Hijackthis\HijackThis.exe
C:\WINDOWS\SoftwareDistribution\Download\fbd74e253a9131770d5798b356214bc9\update\update.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://home.peoplepc.com/search
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://myembarq.com
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft....k/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft....k/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://srch-us5.hpwis.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft....k/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft....k/?LinkId=69157
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = 127.0.0.1
O3 - Toolbar: &hp toolkit - {B2847E28-5D7D-4DEB-8B67-05D28BCF79F5} - C:\HP\EXPLOREBAR\HPTOOLKT.DLL
O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - C:\Program Files\Norton SystemWorks\Norton AntiVirus\NavShExt.dll
O3 - Toolbar: PeoplePal Toolbar - {A8FB8EB3-183B-4598-924D-86F0E5E37085} - C:\Program Files\PeoplePC\Toolbar\PPCToolbar.dll
O4 - HKLM\..\Run: [hpsysdrv] c:\windows\system\hpsysdrv.exe
O4 - HKLM\..\Run: [PreloadApp] c:\hp\drivers\printers\photosmart\hphprld.exe c:\hp\drivers\printers\photosmart\setup.exe -d
O4 - HKLM\..\Run: [KBD] C:\HP\KBD\KBD.EXE
O4 - HKLM\..\Run: [DDCM] "C:\Program Files\WildTangent\DDC\DDCManager\DDCMan.exe" -Background
O4 - HKLM\..\Run: [DDCActiveMenu] "C:\Program Files\WildTangent\DDC\ActiveMenu\DDCActiveMenu.exe" -boot
O4 - HKLM\..\Run: [Recguard] C:\WINDOWS\SMINST\RECGUARD.EXE
O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\System32\igfxtray.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\System32\hkcmd.exe
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE NvQTwk,NvCplDaemon initialize
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [S3apphk] S3apphk.exe
O4 - HKLM\..\Run: [PS2] C:\WINDOWS\system32\ps2.exe
O4 - HKLM\..\Run: [LTMSG] LTMSG.exe 7
O4 - HKLM\..\Run: [BluetoothAuthenticationAgent] rundll32.exe bthprops.cpl,,BluetoothAuthenticationAgent
O4 - HKLM\..\Run: [ccApp] C:\Program Files\Common Files\Symantec Shared\ccApp.exe
O4 - HKLM\..\Run: [ccRegVfy] C:\Program Files\Common Files\Symantec Shared\ccRegVfy.exe
O4 - HKLM\..\Run: [GhostStartTrayApp] C:\Program Files\Norton SystemWorks\Norton Ghost\GhostStartTrayApp.exe
O4 - HKLM\..\Run: [PCTVRemote] C:\Program Files\Pinnacle\Pinnacle PCTV\Remote\Remoterm.exe
O4 - HKLM\..\Run: [FLMOFFICE4DMOUSE] C:\Program Files\Labtec\Mouse\2.1\moffice.exe
O4 - HKLM\..\Run: [ZoneAlarm Client] "C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe"
O4 - HKLM\..\Run: [hp Update 2100C] C:\Program Files\Hewlett-Packard\HP PrecisionScan\sj644\hpupdate.exe
O4 - HKLM\..\Run: [UltraSaver] "C:\Program Files\G7PS\4X UltraSaver\UltraSaver.exe" /hide
O4 - HKLM\..\Run: [PrinTray] C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\printray.exe
O4 - HKLM\..\Run: [LXSUPMON] C:\WINDOWS\system32\LXSUPMON.EXE RUN
O4 - HKLM\..\Run: [Microsoft Works Portfolio] C:\Program Files\Microsoft Works\WksSb.exe /AllUsers
O4 - HKLM\..\Run: [Microsoft Works Update Detection] C:\Program Files\Microsoft Works\WkDetect.exe
O4 - HKLM\..\Run: [Bart Station] C:\Program Files\PeoplePC\ISP6330\BIN\PPCOLink.exe -STATION
O4 - HKLM\..\Run: [RemoteControl] "C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe"
O4 - HKLM\..\Run: [LWBKEYBOARD] C:\Program Files\Labtec\Media Keyboard\V5.0\KbdAp32A.exe
O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [InCD] C:\Program Files\Ahead\InCD\InCD.exe
O4 - HKLM\..\Run: [Motive SmartBridge] C:\PROGRA~1\VIRTUA~1\SMARTB~1\SprintDSLAlert.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_02\bin\jusched.exe"
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\MSN Messenger\MsnMsgr.Exe" /background
O4 - HKCU\..\Run: [Microsoft Works Update Detection] c:\Program Files\Microsoft Works\WkDetect.exe
O4 - HKCU\..\Run: [Weather] C:\Program Files\AWS\WeatherBug\Weather.exe 1
O4 - HKCU\..\Run: [updateMgr] "C:\Program Files\Adobe\Acrobat 7.0\Reader\AdobeUpdateManager.exe" AcRdB7_0_0
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - Global Startup: APC UPS Status.lnk = C:\Program Files\APC\APC PowerChute Personal Edition\Display.exe
O4 - Global Startup: Bluetooth Manager.lnk = ?
O4 - Global Startup: PowerMenu.lnk = C:\Program Files\PowerMenu\PowerMenu.exe
O4 - Global Startup: SpeedFan 4.28.lnk = C:\Program Files\SpeedFan\speedfan.exe
O4 - Global Startup: Virtual Assistant.lnk = C:\Program Files\Virtual Assistant\bin\matcli.exe
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_02\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_02\bin\ssv.dll
O9 - Extra button: MoneySide - {E023F504-0C5A-4750-A1E7-A9046DEA8A21} - c:\Program Files\Microsoft Money\System\mnyviewer.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O11 - Options group: [INTERNATIONAL] International*
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.micros...b?1180089289734
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.micros...b?1181970103437
O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - http://acs.pandasoft...free/asinst.cab
O16 - DPF: {DF780F87-FF2B-4DF8-92D0-73DB16A1543A} (PopCapLoader Object) - http://www.shockwave...ploader_v10.cab
O18 - Protocol: g7ps - {9EACF0FB-4FC7-436E-989B-3197142AD979} - C:\Program Files\Common Files\G7PS\Shared Files\G7PSDLL\G7PS.dll
O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O21 - SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll
O23 - Service: APC UPS Service - American Power Conversion Corporation - C:\Program Files\APC\APC PowerChute Personal Edition\mainserv.exe
O23 - Service: Apple Mobile Device - Apple, Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
O23 - Service: Symantec Password Validation Service (ccPwdSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccPwdSvc.exe
O23 - Service: Folder Size (FolderSize) - Brio - C:\Program Files\FolderSize\FolderSizeSvc.exe
O23 - Service: g7bs_device - - C:\WINDOWS\system32\g7bscoms.exe
O23 - Service: GhostStartService - Symantec Corporation - C:\Program Files\Norton SystemWorks\Norton Ghost\GhostStartService.exe
O23 - Service: InCD Helper (InCDsrv) - Nero AG - C:\Program Files\Ahead\InCD\InCDsrv.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: LexBce Server (LexBceS) - Lexmark International, Inc. - C:\WINDOWS\system32\LEXBCES.EXE
O23 - Service: Norton AntiVirus Auto Protect Service (navapsvc) - Symantec Corporation - C:\Program Files\Norton SystemWorks\Norton AntiVirus\navapsvc.exe
O23 - Service: Norton Unerase Protection (NProtectService) - Symantec Corporation - C:\Program Files\Norton SystemWorks\Norton Utilities\NPROTECT.EXE
O23 - Service: NVIDIA Driver Helper Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\System32\nvsvc32.exe
O23 - Service: ScriptBlocking Service (SBService) - Symantec Corporation - C:\PROGRA~1\COMMON~1\SYMANT~1\SCRIPT~1\SBServ.exe
O23 - Service: Speed Disk service - Symantec Corporation - C:\PROGRA~1\NORTON~2\SPEEDD~1\nopdb.exe
O23 - Service: TOSHIBA Bluetooth Service - TOSHIBA CORPORATION - C:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosBtSrv.exe
O23 - Service: TrueVector Internet Monitor (vsmon) - Zone Labs, LLC - C:\WINDOWS\system32\ZoneLabs\vsmon.exe

Looking forward to hearing from you, and thank you for your assistance...Master Luke

    Advertisements

Register to Remove


#2 Trevuren

Trevuren

    Teacher Emeritus

  • Authentic Member
  • PipPipPipPipPipPip
  • 8,632 posts
  • Interests:Woodworking

Posted 14 August 2007 - 03:47 PM

Hello Master Luke and welcome to the TomCoyote Forums

My name is Trevuren and I will be helping you with your problem.


A. Please provide a list of uninstallable programs.

To Provide a List of Installed Programs
  • Run HijackThis.
  • Click Config>>Miscellaneous Tools>>Open Uninstall Manager>>Save List
  • Save list to Desktop
  • Copy the Notepad list and Paste it into this thread.

B. Some trojans have a way of masking their presence from the HijackThis program when they recognize the name. I think that this is the case here because there are no 02 or 020 entries visible in your log.

Please locate the following file on your desktop: HijackThis.exe
Next, right click on the file and from the popup menu that appears, choose the RENAME option and rename the file Killer.exe.

From now on, when I ask you to start HijackThis, just click on the Killer.exe file.


C. Please download this file - combofix.exe by sUBs
  • You must download it to and run it from your Desktop
  • Double click combofix.exe & follow the prompts.
  • When finished, it will produce a log. Please save that log to post in your next reply along with a fresh HJT log.
Note:
Do not mouse-click combofix's window while it is running. That may cause it to stall.


D. Reports/logs to Post:
  • List of Uninstallable Programs
  • ComboFix.txt
  • Fresh HijackThis log
Regards,

Trevuren

Microsoft MVP Consumer Security 2008 - 2009


Proud graduate of TC/WTT Classroom



The help you receive here is free. If you wish to show your appreciation, then you may donate to help keep us online.

Want to help others? Join the ClassRoom and learn how.


Posted Image

#3 Master Luke

Master Luke

    New Member

  • Authentic Member
  • Pip
  • 8 posts

Posted 14 August 2007 - 05:34 PM

Thank you for your prompt reply Trevuren

Here are the logs you requested:

a) Uninstall Log:

4X UltraSaver
Adobe ActiveShare 1.3.1
Adobe Flash Player 9 ActiveX
Adobe Reader 7.0.9
APC PowerChute Personal Edition
Apple Mobile Device Support
Apple Software Update
ArcSoft Software Suite
Atomic Pop
Avery DesignPro
Baby Names
Betty Bad
BibleVerseArt4 Screen Saver
Blasterball Wild
Bluetooth Stack for Windows by Toshiba
Board Games
ClickArt® Christian Value
Cobian Backup 8
Dark Orbit
DFX for Windows Media Player
FileMaker Pro 7
Folder Size for Windows
FoneSync
GemMaster 2
Hijackthis 1.99.1
HijackThis 1.99.1
Hotfix for Windows Media Format 11 SDK (KB929399)
Hotfix for Windows XP (KB896344)
Hotfix for Windows XP (KB915865)
Hotfix for Windows XP (KB926239)
hp center
hp deskjet 630c series
HP Instant Support
HP Photo Printing Software
HP PrecisionScan LTX
HP Scan-to-Web Wizard
Inactive HP Printer Drivers (Remove only)
InCD
Intel® 845G Chipset Graphics Driver Software
iTunes
Java™ 6 Update 2
KBD
Kublox
Label Publisher with Wizards
Label Sort and Print Utility
Labtec Media Keyboard V5.0
Labtec Mouse V2.1
Lernout & Hauspie TruVoice American English TTS Engine
LiveReg (Symantec Corporation)
LiveUpdate 1.80 (Symantec Corporation)
Mavis Beacon Teaches Typing 9.0.0
Metafile Companion 1.10
Microsoft .NET Framework 2.0
Microsoft Compression Client Pack 1.0 for Windows XP
Microsoft Internationalized Domain Names Mitigation APIs
Microsoft Money 2002
Microsoft Money 2002 System Pack
Microsoft National Language Support Downlevel APIs
Microsoft Streets and Trips 2001
Microsoft User-Mode Driver Framework Feature Pack 1.0
Microsoft Word 2000 SR-1
Microsoft Works 2001 Setup Launcher
Microsoft Works 6.0
Microsoft Works 6.0
Microsoft Works and Money 2002 Setup Launcher
Microsoft Works Suite Add-in for Microsoft Word
MidiNotate
Mozilla Firefox (2.0.0.6)
MSXML 6.0 Parser (KB933579)
Nero Digital
Nero Media Player
Nero OEM
NeroMIX
Norton SystemWorks 2003
NVIDIA Windows 2000/XP Display Drivers
Panda ActiveScan
PC-Doctor for Windows
PCTV
PeoplePC Online
PeoplePC:PeoplePal Toolbar 6.3
PigPen
Pinnacle TRex
PL-2303 USB-to-Serial
PowerDVD
PrintKey2000
PS2
Python 1.5 combined Win32 extensions
Python 1.5.2 (final)
QuickTime
RealPlayer
Replay Radio and Replay A/V 7
SabreWing 2
Security Update for Microsoft .NET Framework 2.0 (KB928365)
Security Update for Step By Step Interactive Training (KB923723)
Security Update for Windows Internet Explorer 7 (KB933566)
Security Update for Windows Internet Explorer 7 (KB937143)
Security Update for Windows Internet Explorer 7 (KB938127)
Security Update for Windows Media Player (KB911564)
Security Update for Windows Media Player 11 (KB936782)
Security Update for Windows Media Player 6.4 (KB925398)
Security Update for Windows XP (KB890046)
Security Update for Windows XP (KB893756)
Security Update for Windows XP (KB896358)
Security Update for Windows XP (KB896423)
Security Update for Windows XP (KB896428)
Security Update for Windows XP (KB899587)
Security Update for Windows XP (KB899591)
Security Update for Windows XP (KB900725)
Security Update for Windows XP (KB901017)
Security Update for Windows XP (KB901190)
Security Update for Windows XP (KB901214)
Security Update for Windows XP (KB902400)
Security Update for Windows XP (KB904706)
Security Update for Windows XP (KB905414)
Security Update for Windows XP (KB905749)
Security Update for Windows XP (KB908519)
Security Update for Windows XP (KB911562)
Security Update for Windows XP (KB911927)
Security Update for Windows XP (KB913580)
Security Update for Windows XP (KB914388)
Security Update for Windows XP (KB914389)
Security Update for Windows XP (KB917344)
Security Update for Windows XP (KB917953)
Security Update for Windows XP (KB918118)
Security Update for Windows XP (KB918439)
Security Update for Windows XP (KB919007)
Security Update for Windows XP (KB920213)
Security Update for Windows XP (KB920670)
Security Update for Windows XP (KB920683)
Security Update for Windows XP (KB920685)
Security Update for Windows XP (KB921503)
Security Update for Windows XP (KB922819)
Security Update for Windows XP (KB923191)
Security Update for Windows XP (KB923414)
Security Update for Windows XP (KB923980)
Security Update for Windows XP (KB924191)
Security Update for Windows XP (KB924270)
Security Update for Windows XP (KB924496)
Security Update for Windows XP (KB924667)
Security Update for Windows XP (KB925902)
Security Update for Windows XP (KB926255)
Security Update for Windows XP (KB926436)
Security Update for Windows XP (KB927779)
Security Update for Windows XP (KB927802)
Security Update for Windows XP (KB928255)
Security Update for Windows XP (KB928843)
Security Update for Windows XP (KB929123)
Security Update for Windows XP (KB930178)
Security Update for Windows XP (KB931261)
Security Update for Windows XP (KB931784)
Security Update for Windows XP (KB932168)
Security Update for Windows XP (KB933566)
Security Update for Windows XP (KB935839)
Security Update for Windows XP (KB935840)
Security Update for Windows XP (KB936021)
Security Update for Windows XP (KB938829)
Shred 2 (PC Magazine)
SoundMAX
Space Rocks
SpeedFan (remove only)
Speedway
Tcl 8.0.5 for Windows
TrueCrypt
Update for Windows XP (KB894391)
Update for Windows XP (KB898461)
Update for Windows XP (KB900485)
Update for Windows XP (KB904942)
Update for Windows XP (KB908531)
Update for Windows XP (KB910437)
Update for Windows XP (KB911280)
Update for Windows XP (KB920872)
Update for Windows XP (KB927891)
Update for Windows XP (KB930916)
Update for Windows XP (KB931836)
Update for Windows XP (KB936357)
Update for Windows XP (KB938828)
Veo Digital Studio
Veo Stingray
VersaCheck 2003 Personal Premier
VersaJette M300
Virtual Assistant
Virtual Warfare
Voyetra Music Write Plus
WeatherBug
WildTangent Channel Manager
Winamp (remove only)
Windows Installer 3.1 (KB893803)
Windows Internet Explorer 7
Windows Live Messenger
Windows Media Format 11 runtime
Windows Media Format 11 runtime
Windows Media Player 11
Windows Media Player 11
Windows XP Hotfix - KB873339
Windows XP Hotfix - KB885835
Windows XP Hotfix - KB885836
Windows XP Hotfix - KB886185
Windows XP Hotfix - KB887472
Windows XP Hotfix - KB888302
Windows XP Hotfix - KB890859
Windows XP Hotfix - KB891781
Windows XP Service Pack 2
WinZip 11.1
Yahoo! Music Jukebox
You Know What 2 - Arts and Entertainment
You Know What 2 - History and Geography
You Know What 2 - Potpourri
You Know What 2 - Science and Nature
You Know What 2 - Sports and Games
ZoneAlarm


B) Combofix log file:

ComboFix 07-08-14.6 - "Master Luke" 2007-08-14 16:58:38.1 - NTFSx86
Microsoft Windows XP Home Edition 5.1.2600.2.1252.1.1033.18.125 [GMT -6:00]
* Created a new restore point


((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))


C:\WINDOWS\system32\_000005_.tmp.dll
C:\WINDOWS\system32\bdeeg.bak1
C:\WINDOWS\system32\bdeeg.bak2
C:\WINDOWS\system32\bdeeg.ini
C:\WINDOWS\system32\fjitqdgx.exe
C:\WINDOWS\system32\geedb.dll
C:\WINDOWS\system32\ginxwmux.exe
C:\WINDOWS\system32\ieifhhxb.exe
C:\WINDOWS\system32\pjqvjedt.exe
C:\WINDOWS\system32\rjogcwjv.exe
C:\WINDOWS\system32\windows.scr


((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))


-------\LEGACY_DOMAINSERVICE
-------\DomainService


((((((((((((((((((((((((( Files Created from 2007-07-14 to 2007-08-14 )))))))))))))))))))))))))))))))


2007-08-14 16:46 51,200 --a------ C:\WINDOWS\nircmd.exe
2007-08-11 13:13 <DIR> d-------- C:\WINDOWS\system32\ActiveScan
2007-08-11 11:36 1,048,576 --ah----- C:\DOCUME~1\JESS\NTUSER.DAT
2007-08-11 11:36 <DIR> d-------- C:\DOCUME~1\JESS\WINDOWS
2007-08-11 11:36 <DIR> d-------- C:\DOCUME~1\JESS\APPLIC~1\VERITAS
2007-08-11 11:36 <DIR> d-------- C:\DOCUME~1\JESS\APPLIC~1\Symantec
2007-08-11 11:36 <DIR> d-------- C:\DOCUME~1\JESS\APPLIC~1\InterTrust
2007-08-11 11:36 <DIR> d-------- C:\DOCUME~1\JESS\APPLIC~1\Corel
2007-08-11 11:27 <DIR> d-------- C:\VundoFix Backups
2007-08-09 22:14 1,310,720 --ah----- C:\DOCUME~1\ADMINI~1.RAC\NTUSER.DAT
2007-08-09 22:14 <DIR> d-------- C:\DOCUME~1\ADMINI~1.RAC\WINDOWS
2007-08-09 22:14 <DIR> d-------- C:\DOCUME~1\ADMINI~1.RAC\APPLIC~1\VERITAS
2007-08-09 22:14 <DIR> d-------- C:\DOCUME~1\ADMINI~1.RAC\APPLIC~1\Symantec
2007-08-09 22:14 <DIR> d-------- C:\DOCUME~1\ADMINI~1.RAC\APPLIC~1\InterTrust
2007-08-09 22:14 <DIR> d-------- C:\DOCUME~1\ADMINI~1.RAC\APPLIC~1\Corel
2007-08-08 10:40 <DIR> d-------- C:\DOCUME~1\ALLUSE~1\APPLIC~1\WinZip
2007-08-08 10:31 <DIR> d-------- C:\DOCUME~1\MASTER~2\APPLIC~1\WinRAR
2007-08-06 22:24 <DIR> d-------- C:\DOCUME~1\ALLUSE~1\APPLIC~1\YAHOO
2007-08-06 22:23 <DIR> d-------- C:\Program Files\Common Files\SureThing Shared
2007-07-24 10:30 <DIR> d-------- C:\DOCUME~1\MASTER~2\APPLIC~1\Lavasoft
2007-07-20 18:38 <DIR> d-------- C:\DOCUME~1\MASTER~2\APPLIC~1\Real
2007-07-16 19:17 <DIR> d-------- C:\DOCUME~1\MASTER~2\APPLIC~1\Ahead


(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))

2007-08-14 17:17 --------- d-------- C:\Program Files\SpeedFan
2007-08-14 17:16 --------- d-------- C:\Program Files\Common Files\Symantec Shared
2007-08-13 15:52 --------- d-------- C:\DOCUME~1\MASTER~2\APPLIC~1\WeatherBug
2007-08-10 23:20 680 --a------ C:\WINDOWS\AUTOLNCH.REG
2007-08-06 22:24 --------- d-------- C:\Program Files\Yahoo!
2007-08-06 11:18 --------- d-------- C:\Program Files\iTunes
2007-08-06 11:18 --------- d-------- C:\Program Files\iPod
2007-08-05 08:29 --------- d-------- C:\Program Files\HS
2007-07-21 18:48 --------- d-------- C:\Program Files\Replay7
2007-07-21 09:20 --------- d-------- C:\DOCUME~1\MASTER~2\APPLIC~1\Winamp
2007-07-20 18:42 --------- d-------- C:\Program Files\Common Files\Real
2007-07-19 00:59 3583488 --a--c--- C:\WINDOWS\system32\dllcache\mshtml.dll
2007-07-16 18:51 --------- d-------- C:\DOCUME~1\MASTER~2\APPLIC~1\Apple Computer
2007-07-12 17:31 765952 --a--c--- C:\WINDOWS\system32\dllcache\vgx.dll
2007-07-12 12:02 --------- d-------- C:\Program Files\QuickTime
2007-07-12 11:49 --------- d-------- C:\Program Files\Apple Software Update
2007-07-12 11:43 --------- d-------- C:\Program Files\Common Files\Apple
2007-07-11 00:50 --------- d-------- C:\Program Files\STARWARS
2007-06-29 15:23 --------- d-------- C:\Program Files\Common Files\Motive
2007-06-29 00:25 --------- d-------- C:\Program Files\MSN Messenger
2007-06-28 11:51 --------- d-------- C:\Program Files\FreedomBox 2.0
2007-06-28 11:51 --------- d-------- C:\DOCUME~1\MASTER~2\APPLIC~1\FreedomBox
2007-06-27 08:34 823808 --a--c--- C:\WINDOWS\system32\dllcache\wininet.dll
2007-06-27 08:34 671232 --a--c--- C:\WINDOWS\system32\dllcache\mstime.dll
2007-06-27 08:34 6058496 --a--c--- C:\WINDOWS\system32\dllcache\ieframe.dll
2007-06-27 08:34 52224 --a--c--- C:\WINDOWS\system32\dllcache\msfeedsbs.dll
2007-06-27 08:34 477696 --a--c--- C:\WINDOWS\system32\dllcache\mshtmled.dll
2007-06-27 08:34 459264 --a--c--- C:\WINDOWS\system32\dllcache\msfeeds.dll
2007-06-27 08:34 44544 --a--c--- C:\WINDOWS\system32\dllcache\iernonce.dll
2007-06-27 08:34 384512 --a--c--- C:\WINDOWS\system32\dllcache\iedkcs32.dll
2007-06-27 08:34 383488 --a--c--- C:\WINDOWS\system32\dllcache\ieapfltr.dll
2007-06-27 08:34 27648 --a--c--- C:\WINDOWS\system32\dllcache\jsproxy.dll
2007-06-27 08:34 267776 --a--c--- C:\WINDOWS\system32\dllcache\iertutil.dll
2007-06-27 08:34 232960 --a--c--- C:\WINDOWS\system32\dllcache\webcheck.dll
2007-06-27 08:34 230400 --a--c--- C:\WINDOWS\system32\dllcache\ieaksie.dll
2007-06-27 08:34 193024 --a--c--- C:\WINDOWS\system32\dllcache\msrating.dll
2007-06-27 08:34 153088 --a--c--- C:\WINDOWS\system32\dllcache\ieakeng.dll
2007-06-27 08:34 132608 --a--c--- C:\WINDOWS\system32\dllcache\extmgr.dll
2007-06-27 08:34 124928 --a--c--- C:\WINDOWS\system32\dllcache\advpack.dll
2007-06-27 08:34 1152000 --a--c--- C:\WINDOWS\system32\dllcache\urlmon.dll
2007-06-27 08:34 105984 --a--c--- C:\WINDOWS\system32\dllcache\url.dll
2007-06-27 08:34 102400 --a--c--- C:\WINDOWS\system32\dllcache\occache.dll
2007-06-27 02:27 63488 --a--c--- C:\WINDOWS\system32\dllcache\ie4uinit.exe
2007-06-27 02:27 625152 --a--c--- C:\WINDOWS\system32\dllcache\iexplore.exe
2007-06-27 02:27 13824 --a--c--- C:\WINDOWS\system32\dllcache\ieudinit.exe
2007-06-27 01:00 161792 --a--c--- C:\WINDOWS\system32\dllcache\ieakui.dll
2007-06-26 00:08 1104896 --a--c--- C:\WINDOWS\system32\dllcache\msxml3.dll
2007-06-26 00:08 1104896 --a------ C:\WINDOWS\system32\msxml3.dll
2007-06-23 16:07 --------- d-------- C:\Program Files\Virtual Assistant
2007-06-23 15:10 --------- d-------- C:\Program Files\Motive
2007-06-23 01:17 --------- d-------- C:\Program Files\Aveo
2007-06-19 11:51 --------- d--h----- C:\Program Files\WindowsUpdate
2007-06-19 07:31 282112 --a--c--- C:\WINDOWS\system32\dllcache\gdi32.dll
2007-06-19 07:31 282112 --a------ C:\WINDOWS\system32\gdi32.dll
2007-06-18 23:32 --------- d-------- C:\Program Files\Winamp
2007-06-18 17:59 --------- d-------- C:\Program Files\FolderSize
2007-06-18 16:57 --------- d-------- C:\DOCUME~1\MASTER~2\APPLIC~1\TOSHIBA
2007-06-18 16:45 --------- d-------- C:\Program Files\Toshiba
2007-06-16 03:41 --------- d-------- C:\Program Files\Messenger
2007-06-13 04:23 1033216 --a--c--- C:\WINDOWS\system32\dllcache\explorer.exe
2007-06-13 04:23 1033216 --a------ C:\WINDOWS\explorer.exe
2007-06-11 23:51 10834944 --a--c--- C:\WINDOWS\system32\dllcache\wmp.dll
2007-06-08 20:06 44 --a------ C:\WINDOWS\system32\msssc.dll
2007-05-26 03:27 737280 --a------ C:\WINDOWS\iun6002.exe
2007-05-26 00:53 9728 --a------ C:\WINDOWS\system32\UnInstall BibleVerseArt4.exe
2007-05-26 00:53 4521290 --a------ C:\WINDOWS\system32\BibleVerseArt4.scr
2007-05-24 00:36 3576 --a------ C:\WINDOWS\pchealth\HELPCTR\PackageStore\SkuStore.bin
2007-05-24 00:34 9546 --a------ C:\WINDOWS\pchealth\HELPCTR\Config\Cntstore.bin
2007-05-17 05:28 549376 --ahs---- C:\WINDOWS\system32\oleaut32.dll
2007-05-17 05:28 549376 --a-sc--- C:\WINDOWS\system32\dllcache\oleaut32.dll
2007-05-16 09:12 86528 --a--c--- C:\WINDOWS\system32\dllcache\directdb.dll
2007-05-16 09:12 85504 --a--c--- C:\WINDOWS\system32\dllcache\wabimp.dll
2007-05-16 09:12 683520 --a--c--- C:\WINDOWS\system32\dllcache\inetcomm.dll
2007-05-16 09:12 683520 --a------ C:\WINDOWS\system32\inetcomm.dll
2007-05-16 09:12 510976 --a--c--- C:\WINDOWS\system32\dllcache\wab32.dll
2007-05-16 09:12 1314816 --a--c--- C:\WINDOWS\system32\dllcache\msoe.dll
2007-05-15 15:43 1320800 --a------ C:\WINDOWS\system32\msxml6.dll
2002-07-09 08:46 53701 --a------ C:\WINDOWS\inf\Gemplus\gcr432.sys
2002-07-09 08:46 28864 --a------ C:\WINDOWS\inf\Gemplus\GCR412.sys
2001-08-18 12:00:00 94,784 --sh--w C:\WINDOWS\twain.dll
2004-08-04 05:56:48 50,688 --sh--w C:\WINDOWS\twain_32.dll
2004-08-04 05:56:44 1,028,096 --sha-w C:\WINDOWS\system32\mfc42.dll
2004-08-04 05:56:44 54,784 --sha-w C:\WINDOWS\system32\msvcirt.dll
2004-08-04 05:56:44 413,696 --sha-w C:\WINDOWS\system32\msvcp60.dll
2004-08-04 05:56:44 343,040 --sha-w C:\WINDOWS\system32\msvcrt.dll
2004-08-04 05:56:46 83,456 --sha-w C:\WINDOWS\system32\olepro32.dll
2004-08-04 05:56:56 11,776 --sha-w C:\WINDOWS\system32\regsvr32.exe
2006-06-23 03:43:02 68 --sha-w C:\WINDOWS\system32\windzfa0.sys


((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))


*Note* empty entries & legit default entries are not shown

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{A8FB8EB3-183B-4598-924D-86F0E5E37085}]
2006-01-24 17:07 220672 --a------ C:\Program Files\PeoplePC\Toolbar\PPCToolbar.dll

[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser]
"{A8FB8EB3-183B-4598-924D-86F0E5E37085}"= C:\Program Files\PeoplePC\Toolbar\PPCToolbar.dll [2006-01-24 17:07 220672]

[HKEY_CLASSES_ROOT\CLSID\{A8FB8EB3-183B-4598-924D-86F0E5E37085}]
[HKEY_CLASSES_ROOT\PeoplePal Toolbar]
[HKEY_CLASSES_ROOT\TypeLib\{994D628D-4D22-4DB9-B6DB-F7D9F1635817}]
[HKEY_CLASSES_ROOT\PeoplePal Toolbar]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"hpsysdrv"="c:\windows\system\hpsysdrv.exe" [1998-05-07 17:04]
"PreloadApp"="c:\hp\drivers\printers\photosmart\hphprld.exe" [2001-12-13 00:05]
"KBD"="C:\HP\KBD\KBD.EXE" [2001-07-06 21:56]
"DDCM"="C:\Program Files\WildTangent\DDC\DDCManager\DDCMan.exe" [2001-12-12 22:52]
"DDCActiveMenu"="C:\Program Files\WildTangent\DDC\ActiveMenu\DDCActiveMenu.exe" [2001-12-12 22:59]
"Recguard"="C:\WINDOWS\SMINST\RECGUARD.EXE" [2001-12-19 00:39]
"IgfxTray"="C:\WINDOWS\System32\igfxtray.exe" [2001-08-08 01:25]
"HotKeysCmds"="C:\WINDOWS\System32\hkcmd.exe" [2001-08-08 00:36]
"NvCplDaemon"="NvQTwk" []
"nwiz"="nwiz.exe" [2002-03-09 17:53 C:\WINDOWS\system32\nwiz.exe]
"S3apphk"="S3apphk.exe" [2002-03-15 23:51 C:\WINDOWS\system32\S3apphk.exe]
"PS2"="C:\WINDOWS\system32\ps2.exe" [2001-07-03 21:13]
"LTMSG"="LTMSG.exe" [2003-07-14 10:52 C:\WINDOWS\ltmsg.exe]
"BluetoothAuthenticationAgent"="bthprops.cpl" [2004-08-04 00:56 C:\WINDOWS\system32\bthprops.cpl]
"ccApp"="C:\Program Files\Common Files\Symantec Shared\ccApp.exe" [2002-08-19 21:22]
"ccRegVfy"="C:\Program Files\Common Files\Symantec Shared\ccRegVfy.exe" [2002-08-19 21:23]
"GhostStartTrayApp"="C:\Program Files\Norton SystemWorks\Norton Ghost\GhostStartTrayApp.exe" [2002-08-14 14:21]
"PCTVRemote"="C:\Program Files\Pinnacle\Pinnacle PCTV\Remote\Remoterm.exe" [2002-01-28 18:12]
"FLMOFFICE4DMOUSE"="C:\Program Files\Labtec\Mouse\2.1\moffice.exe" [2007-05-24 02:17]
"ZoneAlarm Client"="C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe" [2007-03-08 23:02]
"hp Update 2100C"="C:\Program Files\Hewlett-Packard\HP PrecisionScan\sj644\hpupdate.exe" [2002-01-24 16:24]
"UltraSaver"="C:\Program Files\G7PS\4X UltraSaver\UltraSaver.exe" [2006-09-20 14:50]
"PrinTray"="C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\printray.exe" [2002-03-29 04:44]
"LXSUPMON"="C:\WINDOWS\system32\LXSUPMON.exe" [2002-03-29 04:44]
"Microsoft Works Portfolio"="C:\Program Files\Microsoft Works\WksSb.exe" [2001-08-23 22:52]
"Microsoft Works Update Detection"="C:\Program Files\Microsoft Works\WkDetect.exe" [2000-08-01 14:00]
"Bart Station"="C:\Program Files\PeoplePC\ISP6330\BIN\PPCOLink.exe" [2006-04-18 16:42]
"RemoteControl"="C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe" [2004-11-02 19:24]
"LWBKEYBOARD"="C:\Program Files\Labtec\Media Keyboard\V5.0\KbdAp32A.exe" [2005-01-28 04:23]
"NeroFilterCheck"="C:\WINDOWS\system32\NeroCheck.exe" [2001-07-09 10:50]
"InCD"="C:\Program Files\Ahead\InCD\InCD.exe" [2006-03-23 17:06]
"Motive SmartBridge"="C:\PROGRA~1\VIRTUA~1\SMARTB~1\SprintDSLAlert.exe" [2006-04-21 15:41]
"QuickTime Task"="C:\Program Files\QuickTime\QTTask.exe" [2007-06-29 06:24]
"SunJavaUpdateSched"="C:\Program Files\Java\jre1.6.0_02\bin\jusched.exe" [2007-07-12 04:00]
"TkBellExe"="C:\Program Files\Common Files\Real\Update_OB\realsched.exe" [2007-07-20 18:38]
"iTunesHelper"="C:\Program Files\iTunes\iTunesHelper.exe" [2007-07-31 18:44]

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"MsnMsgr"="C:\Program Files\MSN Messenger\MsnMsgr.exe" [2007-01-19 12:54]
"Microsoft Works Update Detection"="c:\Program Files\Microsoft Works\WkDetect.exe" [2000-08-01 14:00]
"Weather"="C:\Program Files\AWS\WeatherBug\Weather.exe" [2005-06-07 12:58]
"updateMgr"="C:\Program Files\Adobe\Acrobat 7.0\Reader\AdobeUpdateManager.exe" [2006-03-30 16:45]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-03 23:56]

C:\Documents and Settings\All Users\Start Menu\Programs\Startup\
APC UPS Status.lnk - C:\Program Files\APC\APC PowerChute Personal Edition\Display.exe [2007-05-25 00:09:05]
Bluetooth Manager.lnk - C:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosBtMng.exe [2007-01-18 14:48:42]
PowerMenu.lnk - C:\Program Files\PowerMenu\PowerMenu.exe [2007-04-13 21:47:19]
SpeedFan 4.28.lnk - C:\Program Files\SpeedFan\speedfan.exe [2006-02-08 15:38:36]
Virtual Assistant.lnk - C:\Program Files\Virtual Assistant\bin\matcli.exe [2007-06-23 15:09:47]

R1 GhPciScan;GhostPciScanner;\??\C:\Program Files\Norton SystemWorks\Norton Ghost\ghpciscan.sys
R2 ROB_A;Pinnacle WDM PCTV Audio Capture;C:\WINDOWS\system32\DRIVERS\rob_a.sys
R2 ROB_V;Pinnacle WDM PCTV Video Capture;C:\WINDOWS\system32\drivers\rob_v.sys
R2 TOSHIBA Bluetooth Service;TOSHIBA Bluetooth Service;C:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosBtSrv.exe
R3 DCamUSBVeo532;Veo Web Camera;C:\WINDOWS\system32\Drivers\ubVeo532.sys
R3 NPDriver;Norton Unerase Protection Driver;\??\C:\WINDOWS\System32\Drivers\NPDRIVER.SYS
R3 pctvvbi;PCTVVBI;C:\WINDOWS\system32\DRIVERS\pctvvbi.sys
S3 APLMp50;APLMp50 NDIS Protocol Driver;C:\WINDOWS\system32\Drivers\APLMp50.sys
S3 g7bs_device;g7bs_device;C:\WINDOWS\system32\g7bscoms.exe -service
S3 trid3d;trid3d;C:\WINDOWS\system32\DRIVERS\trid3dm.sys


Contents of the 'Scheduled Tasks' folder
2007-08-13 16:42:12 C:\WINDOWS\Tasks\AppleSoftwareUpdate.job
2007-08-14 07:52:00 C:\WINDOWS\Tasks\MP Scheduled Scan.job - C:\Program Files\Windows Defender\MpCmdRun.exe
2007-08-12 15:30:00 C:\WINDOWS\Tasks\Norton AntiVirus - Scan my computer.job - C:\PROGRA~1\NORTON~2\NORTON~1\NAVW32.exe
2007-08-03 23:30:00 C:\WINDOWS\Tasks\Norton SystemWorks One Button Checkup.job
2007-08-14 23:16:33 C:\WINDOWS\Tasks\Symantec NetDetect.job - C:\Program Files\Symantec\LiveUpdate\NDETECT.EXE

**************************************************************************

catchme 0.3.1061 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2007-08-14 17:15:27
Windows 5.1.2600 Service Pack 2 NTFS

scanning hidden processes ...

scanning hidden autostart entries ...

scanning hidden files ...

scan completed successfully
hidden files: 0

**************************************************************************

Completion time: 2007-08-14 17:21:37 - machine was rebooted
C:\ComboFix-quarantined-files.txt ... 2007-08-14 17:21

--- E O F ---


c) A New Hijack This Log:


Logfile of HijackThis v1.99.1
Scan saved at 17:27:53, on 08/14/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16512)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Ahead\InCD\InCDsrv.exe
C:\WINDOWS\system32\ZoneLabs\vsmon.exe
C:\WINDOWS\system32\LEXBCES.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\LEXPPS.EXE
C:\WINDOWS\Explorer.EXE
C:\Program Files\APC\APC PowerChute Personal Edition\mainserv.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
C:\Program Files\FolderSize\FolderSizeSvc.exe
C:\Program Files\Norton SystemWorks\Norton Ghost\GhostStartService.exe
C:\Program Files\Norton SystemWorks\Norton AntiVirus\navapsvc.exe
C:\Program Files\Norton SystemWorks\Norton Utilities\NPROTECT.EXE
C:\WINDOWS\System32\snmp.exe
C:\PROGRA~1\NORTON~2\SPEEDD~1\nopdb.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosBtSrv.exe
C:\windows\system\hpsysdrv.exe
C:\HP\KBD\KBD.EXE
C:\Program Files\WildTangent\DDC\DDCManager\DDCMan.exe
C:\WINDOWS\System32\hkcmd.exe
C:\WINDOWS\system32\S3apphk.exe
C:\WINDOWS\LTMSG.exe
C:\WINDOWS\system32\rundll32.exe
C:\Program Files\Common Files\Symantec Shared\ccApp.exe
C:\Program Files\Norton SystemWorks\Norton Ghost\GhostStartTrayApp.exe
C:\Program Files\Pinnacle\Pinnacle PCTV\Remote\Remoterm.exe
C:\Program Files\Labtec\Mouse\2.1\moffice.exe
C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe
C:\Program Files\G7PS\4X UltraSaver\UltraSaver.exe
C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\printray.exe
C:\WINDOWS\system32\LXSUPMON.EXE
C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe
C:\Program Files\Labtec\Mouse\2.1\MOUSE32A.EXE
C:\Program Files\Labtec\Media Keyboard\V5.0\KbdAp32A.exe
C:\Program Files\PeoplePC\ISP6330\Browser\Bartshel.exe
C:\Program Files\Ahead\InCD\InCD.exe
C:\PROGRA~1\VIRTUA~1\SMARTB~1\SprintDSLAlert.exe
C:\Program Files\Java\jre1.6.0_02\bin\jusched.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\MSN Messenger\MsnMsgr.Exe
C:\Program Files\AWS\WeatherBug\Weather.exe
C:\WINDOWS\system32\ctfmon.exe
C:\PROGRA~1\PeoplePC\ISP6330\Browser\PPShared.exe
C:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosBtMng.exe
C:\Program Files\PowerMenu\PowerMenu.exe
C:\Program Files\SpeedFan\speedfan.exe
C:\Program Files\APC\APC PowerChute Personal Edition\apcsystray.exe
C:\Program Files\Virtual Assistant\bin\mpbtn.exe
C:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosA2dp.exe
C:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosBtHid.exe
C:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosBtHsp.exe
C:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosAVRC.exe
C:\Program Files\MSN Messenger\usnsvc.exe
C:\Program Files\Toshiba\Bluetooth Toshiba Stack\tosOBEX.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Program Files\Toshiba\Bluetooth Toshiba Stack\tosBtProc.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\Messenger\msmsgs.exe
C:\Documents and Settings\Master Luke\Desktop\Killer.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://myembarq.com
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft....k/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft....k/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://srch-us5.hpwis.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft....k/?LinkId=54896
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = 127.0.0.1
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_02\bin\ssv.dll
O2 - BHO: PeoplePC ScamGuard - {7E3659A6-4BC5-4d93-B3FD-8B5ACC2FEDED} - C:\Program Files\PeoplePC\Toolbar\ScamGrd.dll
O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
O2 - BHO: PeoplePal Toolbar - {A8FB8EB3-183B-4598-924D-86F0E5E37085} - C:\Program Files\PeoplePC\Toolbar\PPCToolbar.dll
O2 - BHO: NAV Helper - {BDF3E430-B101-42AD-A544-FADC6B084872} - C:\Program Files\Norton SystemWorks\Norton AntiVirus\NavShExt.dll
O2 - BHO: (no name) - {FDD3B846-8D59-4ffb-8758-209B6AD74ACC} - c:\Program Files\Microsoft Money\System\mnyviewer.dll
O3 - Toolbar: &hp toolkit - {B2847E28-5D7D-4DEB-8B67-05D28BCF79F5} - C:\HP\EXPLOREBAR\HPTOOLKT.DLL
O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - C:\Program Files\Norton SystemWorks\Norton AntiVirus\NavShExt.dll
O3 - Toolbar: PeoplePal Toolbar - {A8FB8EB3-183B-4598-924D-86F0E5E37085} - C:\Program Files\PeoplePC\Toolbar\PPCToolbar.dll
O4 - HKLM\..\Run: [hpsysdrv] c:\windows\system\hpsysdrv.exe
O4 - HKLM\..\Run: [PreloadApp] c:\hp\drivers\printers\photosmart\hphprld.exe c:\hp\drivers\printers\photosmart\setup.exe -d
O4 - HKLM\..\Run: [KBD] C:\HP\KBD\KBD.EXE
O4 - HKLM\..\Run: [DDCM] "C:\Program Files\WildTangent\DDC\DDCManager\DDCMan.exe" -Background
O4 - HKLM\..\Run: [DDCActiveMenu] "C:\Program Files\WildTangent\DDC\ActiveMenu\DDCActiveMenu.exe" -boot
O4 - HKLM\..\Run: [Recguard] C:\WINDOWS\SMINST\RECGUARD.EXE
O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\System32\igfxtray.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\System32\hkcmd.exe
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE NvQTwk,NvCplDaemon initialize
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [S3apphk] S3apphk.exe
O4 - HKLM\..\Run: [PS2] C:\WINDOWS\system32\ps2.exe
O4 - HKLM\..\Run: [LTMSG] LTMSG.exe 7
O4 - HKLM\..\Run: [BluetoothAuthenticationAgent] rundll32.exe bthprops.cpl,,BluetoothAuthenticationAgent
O4 - HKLM\..\Run: [ccApp] C:\Program Files\Common Files\Symantec Shared\ccApp.exe
O4 - HKLM\..\Run: [ccRegVfy] C:\Program Files\Common Files\Symantec Shared\ccRegVfy.exe
O4 - HKLM\..\Run: [GhostStartTrayApp] C:\Program Files\Norton SystemWorks\Norton Ghost\GhostStartTrayApp.exe
O4 - HKLM\..\Run: [PCTVRemote] C:\Program Files\Pinnacle\Pinnacle PCTV\Remote\Remoterm.exe
O4 - HKLM\..\Run: [FLMOFFICE4DMOUSE] C:\Program Files\Labtec\Mouse\2.1\moffice.exe
O4 - HKLM\..\Run: [ZoneAlarm Client] "C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe"
O4 - HKLM\..\Run: [hp Update 2100C] C:\Program Files\Hewlett-Packard\HP PrecisionScan\sj644\hpupdate.exe
O4 - HKLM\..\Run: [UltraSaver] "C:\Program Files\G7PS\4X UltraSaver\UltraSaver.exe" /hide
O4 - HKLM\..\Run: [PrinTray] C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\printray.exe
O4 - HKLM\..\Run: [LXSUPMON] C:\WINDOWS\system32\LXSUPMON.EXE RUN
O4 - HKLM\..\Run: [Microsoft Works Portfolio] C:\Program Files\Microsoft Works\WksSb.exe /AllUsers
O4 - HKLM\..\Run: [Microsoft Works Update Detection] C:\Program Files\Microsoft Works\WkDetect.exe
O4 - HKLM\..\Run: [Bart Station] C:\Program Files\PeoplePC\ISP6330\BIN\PPCOLink.exe -STATION
O4 - HKLM\..\Run: [RemoteControl] "C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe"
O4 - HKLM\..\Run: [LWBKEYBOARD] C:\Program Files\Labtec\Media Keyboard\V5.0\KbdAp32A.exe
O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [InCD] C:\Program Files\Ahead\InCD\InCD.exe
O4 - HKLM\..\Run: [Motive SmartBridge] C:\PROGRA~1\VIRTUA~1\SMARTB~1\SprintDSLAlert.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_02\bin\jusched.exe"
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\MSN Messenger\MsnMsgr.Exe" /background
O4 - HKCU\..\Run: [Microsoft Works Update Detection] c:\Program Files\Microsoft Works\WkDetect.exe
O4 - HKCU\..\Run: [Weather] C:\Program Files\AWS\WeatherBug\Weather.exe 1
O4 - HKCU\..\Run: [updateMgr] "C:\Program Files\Adobe\Acrobat 7.0\Reader\AdobeUpdateManager.exe" AcRdB7_0_0
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - Global Startup: APC UPS Status.lnk = C:\Program Files\APC\APC PowerChute Personal Edition\Display.exe
O4 - Global Startup: Bluetooth Manager.lnk = ?
O4 - Global Startup: PowerMenu.lnk = C:\Program Files\PowerMenu\PowerMenu.exe
O4 - Global Startup: SpeedFan 4.28.lnk = C:\Program Files\SpeedFan\speedfan.exe
O4 - Global Startup: Virtual Assistant.lnk = C:\Program Files\Virtual Assistant\bin\matcli.exe
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_02\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_02\bin\ssv.dll
O9 - Extra button: MoneySide - {E023F504-0C5A-4750-A1E7-A9046DEA8A21} - c:\Program Files\Microsoft Money\System\mnyviewer.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O11 - Options group: [INTERNATIONAL] International*
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.micros...b?1180089289734
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.micros...b?1181970103437
O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - http://acs.pandasoft...free/asinst.cab
O16 - DPF: {DF780F87-FF2B-4DF8-92D0-73DB16A1543A} (PopCapLoader Object) - http://www.shockwave...ploader_v10.cab
O18 - Protocol: g7ps - {9EACF0FB-4FC7-436E-989B-3197142AD979} - C:\Program Files\Common Files\G7PS\Shared Files\G7PSDLL\G7PS.dll
O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O20 - Winlogon Notify: igfxcui - C:\WINDOWS\SYSTEM32\igfxsrvc.dll
O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll
O21 - SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll
O23 - Service: APC UPS Service - American Power Conversion Corporation - C:\Program Files\APC\APC PowerChute Personal Edition\mainserv.exe
O23 - Service: Apple Mobile Device - Apple, Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
O23 - Service: Symantec Password Validation Service (ccPwdSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccPwdSvc.exe
O23 - Service: Folder Size (FolderSize) - Brio - C:\Program Files\FolderSize\FolderSizeSvc.exe
O23 - Service: g7bs_device - - C:\WINDOWS\system32\g7bscoms.exe
O23 - Service: GhostStartService - Symantec Corporation - C:\Program Files\Norton SystemWorks\Norton Ghost\GhostStartService.exe
O23 - Service: InCD Helper (InCDsrv) - Nero AG - C:\Program Files\Ahead\InCD\InCDsrv.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: LexBce Server (LexBceS) - Lexmark International, Inc. - C:\WINDOWS\system32\LEXBCES.EXE
O23 - Service: Norton AntiVirus Auto Protect Service (navapsvc) - Symantec Corporation - C:\Program Files\Norton SystemWorks\Norton AntiVirus\navapsvc.exe
O23 - Service: Norton Unerase Protection (NProtectService) - Symantec Corporation - C:\Program Files\Norton SystemWorks\Norton Utilities\NPROTECT.EXE
O23 - Service: NVIDIA Driver Helper Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\System32\nvsvc32.exe
O23 - Service: ScriptBlocking Service (SBService) - Symantec Corporation - C:\PROGRA~1\COMMON~1\SYMANT~1\SCRIPT~1\SBServ.exe
O23 - Service: Speed Disk service - Symantec Corporation - C:\PROGRA~1\NORTON~2\SPEEDD~1\nopdb.exe
O23 - Service: TOSHIBA Bluetooth Service - TOSHIBA CORPORATION - C:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosBtSrv.exe
O23 - Service: TrueVector Internet Monitor (vsmon) - Zone Labs, LLC - C:\WINDOWS\system32\ZoneLabs\vsmon.exe

Thank you again so much for your help, looking forward to your reply! Master Luke.

#4 Trevuren

Trevuren

    Teacher Emeritus

  • Authentic Member
  • PipPipPipPipPipPip
  • 8,632 posts
  • Interests:Woodworking

Posted 14 August 2007 - 08:38 PM

A. Using the Add/Remove Programs module in your Control Panel, please UNINSTALL the following programs that are either malware or come bundled with malware or they are foistware, i-e programs that are usually installed without the user's consent.

See the following if you want a more in-depth explanation:

http://www.bleepingc...nstall/all.html

and/or

http://www.spywarewa...re.htm#products


PeoplePC Online
PeoplePC:PeoplePal Toolbar 6.3
WeatherBug
WildTangent Channel Manager



B. 1. Please open Notepad
  • Click Start , then Run
  • Type notepad .exe in the Run Box.
2. Now copy/paste the entire content of the codebox below into the Notepad window:

File::
C:\DOCUME~1\MASTER~2\APPLIC~1\WeatherBug
C:\WINDOWS\AUTOLNCH.REG
C:\WINDOWS\system32\msssc.dll
C:\WINDOWS\iun6002.exe
C:\WINDOWS\system32\windzfa0.sys
C:\WINDOWS\system32\g7bscoms.exe

Folder::
C:\Program Files\Aveo
C:\Program Files\PeoplePC
C:\Program Files\WildTangent
C:\Program Files\AWS

Driver::
g7bs_device

Registry::
[-HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{A8FB8EB3-183B-4598-924D-86F0E5E37085}]
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser]
"{A8FB8EB3-183B-4598-924D-86F0E5E37085}"=-
[-HKEY_CLASSES_ROOT\CLSID\{A8FB8EB3-183B-4598-924D-86F0E5E37085}]
[-HKEY_CLASSES_ROOT\PeoplePal Toolbar]
[-HKEY_CLASSES_ROOT\TypeLib\{994D628D-4D22-4DB9-B6DB-F7D9F1635817}]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Bart Station"=-
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Weather"=-
[-HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{7E853D72-626A-48EC-A868-BA8D5E23E045}]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"DDCM"=-


3. Save the above as CFScript.txt

4. Then drag the CFScript.txt into ComboFix.exe as depicted in the animation below. This will start ComboFix again.

Posted Image


5. After reboot, (in case it asks to reboot), please post the following reports/logs into your next reply:
  • Combofix.txt
  • A new HijackThis log.


C. Please use the Internet Explorer browser, and do an online scan with Kaspersky Online Scanner
Click Yes, when prompted to install its ActiveX component.
(Note.. for Internet Explorer 7 users: If at any time you have trouble with the "Accept" button of the license, click on the "Zoom" tool located at the bottom right of the IE window and set the zoom to 75 %. Once the license has been accepted, reset to 100%.)
The program launches and downloads the latest definition files.
  • Once the files are downloaded click on Next
  • Click on Scan Settings and configure as follows:
    • Scan using the following Anti-Virus database:
      • Extended
    • Scan Options:Scan Archives
      Scan Mail Bases
  • Click OK and, under select a target to scan, select My Computer
When the scan is done, in the Scan is completed window (below), any infection is displayed.
There is no option to clean/disinfect, however, we need to analyze the information on the report.
Posted Image
Posted Image
To obtain the report:
Click on: Save Report As (above - red blinking arrow)
Next, in the Save as prompt, Save in area, select: Desktop
In the File name area, use KScan, or something similar
In Save as type, click the drop arrow and select: Text file [*.txt]
Then, click: Save
Please post the Kaspersky Online Scanner Report in your reply, along with a fresh HijackThis log
Microsoft MVP Consumer Security 2008 - 2009


Proud graduate of TC/WTT Classroom



The help you receive here is free. If you wish to show your appreciation, then you may donate to help keep us online.

Want to help others? Join the ClassRoom and learn how.


Posted Image

#5 Trevuren

Trevuren

    Teacher Emeritus

  • Authentic Member
  • PipPipPipPipPipPip
  • 8,632 posts
  • Interests:Woodworking

Posted 19 August 2007 - 07:22 PM

I hope you are well and not experiencing any difficulties carrying out my last set of instructions. If you are, do not hesitate to ask for further explanations. If however, your problem has been solved or you no longer require our assistance, please advise us accordingly and we will archive your topic.

Trevuren
Microsoft MVP Consumer Security 2008 - 2009


Proud graduate of TC/WTT Classroom



The help you receive here is free. If you wish to show your appreciation, then you may donate to help keep us online.

Want to help others? Join the ClassRoom and learn how.


Posted Image

#6 Master Luke

Master Luke

    New Member

  • Authentic Member
  • Pip
  • 8 posts

Posted 19 August 2007 - 10:02 PM

Hi Trevuren

Sorry for the delay. I was re-building two computers for a friend and didn't have time to get back and fix my own!

Okay, the Combofix scan was actually ran last week, but I didn't have time to get it posted back to you. I am sending you it along with a fresh Hijack This log. I will start the Kapersky Scan here in a few and see what transpires.

Since removing the geedb.dll file I have encountered virtually no problems, but I wanna be sure we have all of the bugs outta here!

God Bless you, and looking forward to your reply!

Master Luke

Combofix Scan:

ComboFix 07-08-14.6 - "Master Luke" 2007-08-14 21:00:58.2 - NTFSx86
Microsoft Windows XP Home Edition 5.1.2600.2.1252.1.1033.18.121 [GMT -6:00]
Command switches used :: C:\Documents and Settings\Master Luke\Desktop\CFScript.txt
* Created a new restore point

FILE::
C:\DOCUME~1\MASTER~2\APPLIC~1\WeatherBug
C:\WINDOWS\AUTOLNCH.REG
C:\WINDOWS\system32\msssc.dll
C:\WINDOWS\iun6002.exe
C:\WINDOWS\system32\windzfa0.sys
C:\WINDOWS\system32\g7bscoms.exe

/wow section not completed

Hijack This Logfile:

Logfile of HijackThis v1.99.1
Scan saved at 21:48, on 08/19/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16512)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Ahead\InCD\InCDsrv.exe
C:\WINDOWS\system32\ZoneLabs\vsmon.exe
C:\WINDOWS\system32\LEXBCES.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\LEXPPS.EXE
C:\Program Files\APC\APC PowerChute Personal Edition\mainserv.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
C:\Program Files\FolderSize\FolderSizeSvc.exe
C:\Program Files\Norton SystemWorks\Norton Ghost\GhostStartService.exe
C:\Program Files\Norton SystemWorks\Norton AntiVirus\navapsvc.exe
C:\Program Files\Norton SystemWorks\Norton Utilities\NPROTECT.EXE
C:\WINDOWS\System32\snmp.exe
C:\PROGRA~1\NORTON~2\SPEEDD~1\nopdb.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosBtSrv.exe
C:\WINDOWS\Explorer.EXE
C:\windows\system\hpsysdrv.exe
C:\HP\KBD\KBD.EXE
C:\WINDOWS\System32\hkcmd.exe
C:\WINDOWS\system32\S3apphk.exe
C:\WINDOWS\LTMSG.exe
C:\WINDOWS\system32\rundll32.exe
C:\Program Files\Common Files\Symantec Shared\ccApp.exe
C:\Program Files\Norton SystemWorks\Norton Ghost\GhostStartTrayApp.exe
C:\Program Files\Pinnacle\Pinnacle PCTV\Remote\Remoterm.exe
C:\Program Files\Labtec\Mouse\2.1\moffice.exe
C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe
C:\Program Files\G7PS\4X UltraSaver\UltraSaver.exe
C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\printray.exe
C:\WINDOWS\system32\LXSUPMON.EXE
C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe
C:\Program Files\Labtec\Mouse\2.1\MOUSE32A.EXE
C:\Program Files\Labtec\Media Keyboard\V5.0\KbdAp32A.exe
C:\Program Files\Ahead\InCD\InCD.exe
C:\PROGRA~1\VIRTUA~1\SMARTB~1\SprintDSLAlert.exe
C:\Program Files\Java\jre1.6.0_02\bin\jusched.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\MSN Messenger\MsnMsgr.Exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosBtMng.exe
C:\Program Files\PowerMenu\PowerMenu.exe
C:\Program Files\SpeedFan\speedfan.exe
C:\Program Files\APC\APC PowerChute Personal Edition\apcsystray.exe
C:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosA2dp.exe
C:\Program Files\Virtual Assistant\bin\mpbtn.exe
C:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosBtHid.exe
C:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosBtHsp.exe
C:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosAVRC.exe
C:\Program Files\Toshiba\Bluetooth Toshiba Stack\tosOBEX.exe
C:\Program Files\MSN Messenger\usnsvc.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Program Files\Toshiba\Bluetooth Toshiba Stack\tosBtProc.exe
C:\WINDOWS\system32\ntvdm.exe
C:\Program Files\TrueCrypt\TrueCrypt.exe
C:\Program Files\Outlook Express\msimn.exe
C:\Program Files\Messenger\msmsgs.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\PrintKey2000\Printkey2000.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\Documents and Settings\Master Luke\Desktop\Killer.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://myembarq.com
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft....k/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft....k/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://srch-us5.hpwis.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft....k/?LinkId=54896
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = 127.0.0.1
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_02\bin\ssv.dll
O2 - BHO: PeoplePC ScamGuard - {7E3659A6-4BC5-4d93-B3FD-8B5ACC2FEDED} - C:\Program Files\PeoplePC\Toolbar\ScamGrd.dll (file missing)
O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
O2 - BHO: PeoplePal Toolbar - {A8FB8EB3-183B-4598-924D-86F0E5E37085} - C:\Program Files\PeoplePC\Toolbar\PPCToolbar.dll (file missing)
O2 - BHO: NAV Helper - {BDF3E430-B101-42AD-A544-FADC6B084872} - C:\Program Files\Norton SystemWorks\Norton AntiVirus\NavShExt.dll
O2 - BHO: (no name) - {FDD3B846-8D59-4ffb-8758-209B6AD74ACC} - c:\Program Files\Microsoft Money\System\mnyviewer.dll
O3 - Toolbar: &hp toolkit - {B2847E28-5D7D-4DEB-8B67-05D28BCF79F5} - C:\HP\EXPLOREBAR\HPTOOLKT.DLL
O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - C:\Program Files\Norton SystemWorks\Norton AntiVirus\NavShExt.dll
O3 - Toolbar: PeoplePal Toolbar - {A8FB8EB3-183B-4598-924D-86F0E5E37085} - C:\Program Files\PeoplePC\Toolbar\PPCToolbar.dll (file missing)
O4 - HKLM\..\Run: [hpsysdrv] c:\windows\system\hpsysdrv.exe
O4 - HKLM\..\Run: [PreloadApp] c:\hp\drivers\printers\photosmart\hphprld.exe c:\hp\drivers\printers\photosmart\setup.exe -d
O4 - HKLM\..\Run: [KBD] C:\HP\KBD\KBD.EXE
O4 - HKLM\..\Run: [Recguard] C:\WINDOWS\SMINST\RECGUARD.EXE
O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\System32\igfxtray.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\System32\hkcmd.exe
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE NvQTwk,NvCplDaemon initialize
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [S3apphk] S3apphk.exe
O4 - HKLM\..\Run: [PS2] C:\WINDOWS\system32\ps2.exe
O4 - HKLM\..\Run: [LTMSG] LTMSG.exe 7
O4 - HKLM\..\Run: [BluetoothAuthenticationAgent] rundll32.exe bthprops.cpl,,BluetoothAuthenticationAgent
O4 - HKLM\..\Run: [ccApp] C:\Program Files\Common Files\Symantec Shared\ccApp.exe
O4 - HKLM\..\Run: [ccRegVfy] C:\Program Files\Common Files\Symantec Shared\ccRegVfy.exe
O4 - HKLM\..\Run: [GhostStartTrayApp] C:\Program Files\Norton SystemWorks\Norton Ghost\GhostStartTrayApp.exe
O4 - HKLM\..\Run: [PCTVRemote] C:\Program Files\Pinnacle\Pinnacle PCTV\Remote\Remoterm.exe
O4 - HKLM\..\Run: [FLMOFFICE4DMOUSE] C:\Program Files\Labtec\Mouse\2.1\moffice.exe
O4 - HKLM\..\Run: [ZoneAlarm Client] "C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe"
O4 - HKLM\..\Run: [hp Update 2100C] C:\Program Files\Hewlett-Packard\HP PrecisionScan\sj644\hpupdate.exe
O4 - HKLM\..\Run: [UltraSaver] "C:\Program Files\G7PS\4X UltraSaver\UltraSaver.exe" /hide
O4 - HKLM\..\Run: [PrinTray] C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\printray.exe
O4 - HKLM\..\Run: [LXSUPMON] C:\WINDOWS\system32\LXSUPMON.EXE RUN
O4 - HKLM\..\Run: [Microsoft Works Portfolio] C:\Program Files\Microsoft Works\WksSb.exe /AllUsers
O4 - HKLM\..\Run: [Microsoft Works Update Detection] C:\Program Files\Microsoft Works\WkDetect.exe
O4 - HKLM\..\Run: [RemoteControl] "C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe"
O4 - HKLM\..\Run: [LWBKEYBOARD] C:\Program Files\Labtec\Media Keyboard\V5.0\KbdAp32A.exe
O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [InCD] C:\Program Files\Ahead\InCD\InCD.exe
O4 - HKLM\..\Run: [Motive SmartBridge] C:\PROGRA~1\VIRTUA~1\SMARTB~1\SprintDSLAlert.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_02\bin\jusched.exe"
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\MSN Messenger\MsnMsgr.Exe" /background
O4 - HKCU\..\Run: [Microsoft Works Update Detection] c:\Program Files\Microsoft Works\WkDetect.exe
O4 - HKCU\..\Run: [updateMgr] "C:\Program Files\Adobe\Acrobat 7.0\Reader\AdobeUpdateManager.exe" AcRdB7_0_0
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - Global Startup: APC UPS Status.lnk = C:\Program Files\APC\APC PowerChute Personal Edition\Display.exe
O4 - Global Startup: Bluetooth Manager.lnk = ?
O4 - Global Startup: PowerMenu.lnk = C:\Program Files\PowerMenu\PowerMenu.exe
O4 - Global Startup: SpeedFan 4.28.lnk = C:\Program Files\SpeedFan\speedfan.exe
O4 - Global Startup: Virtual Assistant.lnk = C:\Program Files\Virtual Assistant\bin\matcli.exe
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_02\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_02\bin\ssv.dll
O9 - Extra button: MoneySide - {E023F504-0C5A-4750-A1E7-A9046DEA8A21} - c:\Program Files\Microsoft Money\System\mnyviewer.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O11 - Options group: [INTERNATIONAL] International*
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.micros...b?1180089289734
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.micros...b?1181970103437
O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - http://acs.pandasoft...free/asinst.cab
O16 - DPF: {DF780F87-FF2B-4DF8-92D0-73DB16A1543A} (PopCapLoader Object) - http://www.shockwave...ploader_v10.cab
O18 - Protocol: g7ps - {9EACF0FB-4FC7-436E-989B-3197142AD979} - C:\Program Files\Common Files\G7PS\Shared Files\G7PSDLL\G7PS.dll
O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O20 - Winlogon Notify: igfxcui - C:\WINDOWS\SYSTEM32\igfxsrvc.dll
O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll
O21 - SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll
O23 - Service: APC UPS Service - American Power Conversion Corporation - C:\Program Files\APC\APC PowerChute Personal Edition\mainserv.exe
O23 - Service: Apple Mobile Device - Apple, Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
O23 - Service: Symantec Password Validation Service (ccPwdSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccPwdSvc.exe
O23 - Service: Folder Size (FolderSize) - Brio - C:\Program Files\FolderSize\FolderSizeSvc.exe
O23 - Service: GhostStartService - Symantec Corporation - C:\Program Files\Norton SystemWorks\Norton Ghost\GhostStartService.exe
O23 - Service: InCD Helper (InCDsrv) - Nero AG - C:\Program Files\Ahead\InCD\InCDsrv.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: LexBce Server (LexBceS) - Lexmark International, Inc. - C:\WINDOWS\system32\LEXBCES.EXE
O23 - Service: Norton AntiVirus Auto Protect Service (navapsvc) - Symantec Corporation - C:\Program Files\Norton SystemWorks\Norton AntiVirus\navapsvc.exe
O23 - Service: Norton Unerase Protection (NProtectService) - Symantec Corporation - C:\Program Files\Norton SystemWorks\Norton Utilities\NPROTECT.EXE
O23 - Service: NVIDIA Driver Helper Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\System32\nvsvc32.exe
O23 - Service: ScriptBlocking Service (SBService) - Symantec Corporation - C:\PROGRA~1\COMMON~1\SYMANT~1\SCRIPT~1\SBServ.exe
O23 - Service: Speed Disk service - Symantec Corporation - C:\PROGRA~1\NORTON~2\SPEEDD~1\nopdb.exe
O23 - Service: TOSHIBA Bluetooth Service - TOSHIBA CORPORATION - C:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosBtSrv.exe
O23 - Service: TrueVector Internet Monitor (vsmon) - Zone Labs, LLC - C:\WINDOWS\system32\ZoneLabs\vsmon.exe

#7 Trevuren

Trevuren

    Teacher Emeritus

  • Authentic Member
  • PipPipPipPipPipPip
  • 8,632 posts
  • Interests:Woodworking

Posted 19 August 2007 - 10:22 PM

The ComboFix text was not successfully run. Please delete your current copy of ComboFix and download the newest version from
HERE

Then please perform the Uninstall of the programs Listed

Third run the CFScript previously written for you and finally do the Kasperksy scan.


Trevuren
Microsoft MVP Consumer Security 2008 - 2009


Proud graduate of TC/WTT Classroom



The help you receive here is free. If you wish to show your appreciation, then you may donate to help keep us online.

Want to help others? Join the ClassRoom and learn how.


Posted Image

#8 Master Luke

Master Luke

    New Member

  • Authentic Member
  • Pip
  • 8 posts

Posted 20 August 2007 - 03:03 PM

Trevuren

I ran the Kapersky scan all night last night before you asked me to do the Combfix over again. Now I have even more questions as to what you want me to do now.

1) The new Combofix (I just ran it) shows no programs to uninstall. The ones you told me to uninstall earlier are uninstalled.

2) The Kapersky log from last night showed numerous bad files.

I am attaching the logs from both of these events and a fresh Hijack this log. Should I go ahead and run the CF Script again in Combofix and then do the Kapersky over, or do you have other advice? Please advise!


LOGFILES:

1) Kapersky Virus Scan performed last night PART ONE:

-------------------------------------------------------------------------------
KASPERSKY ONLINE SCANNER REPORT
Monday, August 20, 2007 13:59
Operating System: Microsoft Windows XP Home Edition, Service Pack 2 (Build 2600)
Kaspersky Online Scanner version: 5.0.93.0
Kaspersky Anti-Virus database last update: 20/08/2007
Kaspersky Anti-Virus database records: 385319
-------------------------------------------------------------------------------

Scan Settings:
Scan using the following antivirus database: extended
Scan Archives: true
Scan Mail Bases: true

Scan Target - My Computer:
A:\
C:\
D:\
E:\
F:\
G:\
P:\
Q:\
R:\
S:\

Scan Statistics:
Total number of scanned objects: 279934
Number of viruses found: 36
Number of infected objects: 176
Number of suspicious objects: 0
Duration of the scan process: 14:04:44

Infected Object Name / Virus Name / Last Action
C:\Documents and Settings\All Users\Application Data\Microsoft\Dr Watson\user.dmp Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Network\Downloader\qmgr0.dat Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Network\Downloader\qmgr1.dat Object is locked skipped
C:\Documents and Settings\LocalService\Cookies\index.dat Object is locked skipped
C:\Documents and Settings\LocalService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat Object is locked skipped
C:\Documents and Settings\LocalService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped
C:\Documents and Settings\LocalService\Local Settings\History\History.IE5\index.dat Object is locked skipped
C:\Documents and Settings\LocalService\Local Settings\Temp\Cookies\index.dat Object is locked skipped
C:\Documents and Settings\LocalService\Local Settings\Temp\History\History.IE5\index.dat Object is locked skipped
C:\Documents and Settings\LocalService\Local Settings\Temp\Temporary Internet Files\Content.IE5\index.dat Object is locked skipped
C:\Documents and Settings\LocalService\Local Settings\Temporary Internet Files\Content.IE5\index.dat Object is locked skipped
C:\Documents and Settings\LocalService\NTUSER.DAT Object is locked skipped
C:\Documents and Settings\LocalService\ntuser.dat.LOG Object is locked skipped
C:\Documents and Settings\Master Luke\Application Data\Mozilla\Firefox\Profiles\ju2axb3h.default\cert8.db Object is locked skipped
C:\Documents and Settings\Master Luke\Application Data\Mozilla\Firefox\Profiles\ju2axb3h.default\formhistory.dat Object is locked skipped
C:\Documents and Settings\Master Luke\Application Data\Mozilla\Firefox\Profiles\ju2axb3h.default\history.dat Object is locked skipped
C:\Documents and Settings\Master Luke\Application Data\Mozilla\Firefox\Profiles\ju2axb3h.default\key3.db Object is locked skipped
C:\Documents and Settings\Master Luke\Application Data\Mozilla\Firefox\Profiles\ju2axb3h.default\parent.lock Object is locked skipped
C:\Documents and Settings\Master Luke\Application Data\Mozilla\Firefox\Profiles\ju2axb3h.default\search.sqlite Object is locked skipped
C:\Documents and Settings\Master Luke\Application Data\Mozilla\Firefox\Profiles\ju2axb3h.default\urlclassifier2.sqlite Object is locked skipped
C:\Documents and Settings\Master Luke\Cookies\index.dat Object is locked skipped
C:\Documents and Settings\Master Luke\Local Settings\Application Data\Identities\{17CB74D8-EB9E-4A3B-A3C5-2DB80A9ED793}\Microsoft\Outlook Express\Former Deleted Items.dbx/[From Unsecured G O L D <hey@reply.gfts-mail.net>][Date Sun, 15 Jun 2003 20:59:30 -0400]/UNNAMED/napv2b8.exe.exe Infected: Email-Worm.Win32.Tanatos.b skipped
C:\Documents and Settings\Master Luke\Local Settings\Application Data\Identities\{17CB74D8-EB9E-4A3B-A3C5-2DB80A9ED793}\Microsoft\Outlook Express\Former Deleted Items.dbx/[From Unsecured G O L D <hey@reply.gfts-mail.net>][Date Sun, 15 Jun 2003 20:59:30 -0400]/UNNAMED Infected: Email-Worm.Win32.Tanatos.b skipped
C:\Documents and Settings\Master Luke\Local Settings\Application Data\Identities\{17CB74D8-EB9E-4A3B-A3C5-2DB80A9ED793}\Microsoft\Outlook Express\Former Deleted Items.dbx/[From Confirmation Center<Theo@pontiac.com>][Date Sun, 22 Jun 2003 17:43:51 -0400]/UNNAMED/napv2b8.exe.scr Infected: Email-Worm.Win32.Tanatos.b.dam skipped
C:\Documents and Settings\Master Luke\Local Settings\Application Data\Identities\{17CB74D8-EB9E-4A3B-A3C5-2DB80A9ED793}\Microsoft\Outlook Express\Former Deleted Items.dbx/[From Confirmation Center<Theo@pontiac.com>][Date Sun, 22 Jun 2003 17:43:51 -0400]/UNNAMED Infected: Email-Worm.Win32.Tanatos.b.dam skipped
C:\Documents and Settings\Master Luke\Local Settings\Application Data\Identities\{17CB74D8-EB9E-4A3B-A3C5-2DB80A9ED793}\Microsoft\Outlook Express\Former Deleted Items.dbx/[From <fitforthekingdom@juno.com>][Date Sun, 29 Jun 2003 20:48:50 --0500]/UNNAMED/your_details.zip/details.pif Infected: Email-Worm.Win32.Sobig.e skipped
C:\Documents and Settings\Master Luke\Local Settings\Application Data\Identities\{17CB74D8-EB9E-4A3B-A3C5-2DB80A9ED793}\Microsoft\Outlook Express\Former Deleted Items.dbx/[From <fitforthekingdom@juno.com>][Date Sun, 29 Jun 2003 20:48:50 --0500]/UNNAMED/your_details.zip Infected: Email-Worm.Win32.Sobig.e skipped
C:\Documents and Settings\Master Luke\Local Settings\Application Data\Identities\{17CB74D8-EB9E-4A3B-A3C5-2DB80A9ED793}\Microsoft\Outlook Express\Former Deleted Items.dbx/[From <fitforthekingdom@juno.com>][Date Sun, 29 Jun 2003 20:48:50 --0500]/UNNAMED Infected: Email-Worm.Win32.Sobig.e skipped
C:\Documents and Settings\Master Luke\Local Settings\Application Data\Identities\{17CB74D8-EB9E-4A3B-A3C5-2DB80A9ED793}\Microsoft\Outlook Express\Former Deleted Items.dbx Mail MS Outlook 5: infected - 7 skipped
C:\Documents and Settings\Master Luke\Local Settings\Application Data\Microsoft\Messenger\masterlukezh@peoplepc.com\SharingMetadata\Logs\Dfsr00005.log Object is locked skipped
C:\Documents and Settings\Master Luke\Local Settings\Application Data\Microsoft\Messenger\masterlukezh@peoplepc.com\SharingMetadata\pending.dat Object is locked skipped
C:\Documents and Settings\Master Luke\Local Settings\Application Data\Microsoft\Messenger\masterlukezh@peoplepc.com\SharingMetadata\Working\database_9234_35FB_3435_E2C1\dfsr.db Object is locked skipped
C:\Documents and Settings\Master Luke\Local Settings\Application Data\Microsoft\Messenger\masterlukezh@peoplepc.com\SharingMetadata\Working\database_9234_35FB_3435_E2C1\fsr.log Object is locked skipped
C:\Documents and Settings\Master Luke\Local Settings\Application Data\Microsoft\Messenger\masterlukezh@peoplepc.com\SharingMetadata\Working\database_9234_35FB_3435_E2C1\fsrtmp.log Object is locked skipped
C:\Documents and Settings\Master Luke\Local Settings\Application Data\Microsoft\Messenger\masterlukezh@peoplepc.com\SharingMetadata\Working\database_9234_35FB_3435_E2C1\tmp.edb Object is locked skipped
C:\Documents and Settings\Master Luke\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat Object is locked skipped
C:\Documents and Settings\Master Luke\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped
C:\Documents and Settings\Master Luke\Local Settings\Application Data\Microsoft\Windows Live Contacts\masterlukezh@peoplepc.com\real\members.stg Object is locked skipped
C:\Documents and Settings\Master Luke\Local Settings\Application Data\Microsoft\Windows Live Contacts\masterlukezh@peoplepc.com\shadow\members.stg Object is locked skipped
C:\Documents and Settings\Master Luke\Local Settings\Application Data\Mozilla\Firefox\Profiles\ju2axb3h.default\Cache\_CACHE_001_ Object is locked skipped
C:\Documents and Settings\Master Luke\Local Settings\Application Data\Mozilla\Firefox\Profiles\ju2axb3h.default\Cache\_CACHE_002_ Object is locked skipped
C:\Documents and Settings\Master Luke\Local Settings\Application Data\Mozilla\Firefox\Profiles\ju2axb3h.default\Cache\_CACHE_003_ Object is locked skipped
C:\Documents and Settings\Master Luke\Local Settings\Application Data\Mozilla\Firefox\Profiles\ju2axb3h.default\Cache\_CACHE_MAP_ Object is locked skipped
C:\Documents and Settings\Master Luke\Local Settings\History\History.IE5\index.dat Object is locked skipped
C:\Documents and Settings\Master Luke\Local Settings\Temp\Perflib_Perfdata_82c.dat Object is locked skipped
C:\Documents and Settings\Master Luke\Local Settings\Temp\~DFB04F.tmp Object is locked skipped
C:\Documents and Settings\Master Luke\Local Settings\Temp\~DFB175.tmp Object is locked skipped
C:\Documents and Settings\Master Luke\Local Settings\Temp\~DFF899.tmp Object is locked skipped
C:\Documents and Settings\Master Luke\Local Settings\Temp\~DFF8BA.tmp Object is locked skipped
C:\Documents and Settings\Master Luke\Local Settings\Temporary Internet Files\AntiPhishing\B3BB5BBA-E7D5-40AB-A041-A5B1C0B26C8F.dat Object is locked skipped
C:\Documents and Settings\Master Luke\Local Settings\Temporary Internet Files\Content.IE5\index.dat Object is locked skipped
C:\Documents and Settings\Master Luke\My Documents\C 06 Archived Files\C 07-8 JONVY'S PROGRAMS & UTILITIES\應用軟體\fgbeta.zip/setup.exe/WISE0077.BIN Infected: not-a-virus:AdWare.Win32.Aureate.a skipped
C:\Documents and Settings\Master Luke\My Documents\C 06 Archived Files\C 07-8 JONVY'S PROGRAMS & UTILITIES\應用軟體\fgbeta.zip/setup.exe/WISE0078.BIN Infected: not-a-virus:AdWare.Win32.Aureate.a skipped
C:\Documents and Settings\Master Luke\My Documents\C 06 Archived Files\C 07-8 JONVY'S PROGRAMS & UTILITIES\應用軟體\fgbeta.zip/setup.exe/WISE0079.BIN Infected: not-a-virus:AdWare.Win32.Aureate.a skipped
C:\Documents and Settings\Master Luke\My Documents\C 06 Archived Files\C 07-8 JONVY'S PROGRAMS & UTILITIES\應用軟體\fgbeta.zip/setup.exe/WISE0080.BIN Infected: not-a-virus:AdWare.Win32.Aureate.a skipped
C:\Documents and Settings\Master Luke\My Documents\C 06 Archived Files\C 07-8 JONVY'S PROGRAMS & UTILITIES\應用軟體\fgbeta.zip/setup.exe/WISE0081.BIN Infected: not-a-virus:AdWare.Win32.Aureate.a skipped
C:\Documents and Settings\Master Luke\My Documents\C 06 Archived Files\C 07-8 JONVY'S PROGRAMS & UTILITIES\應用軟體\fgbeta.zip/setup.exe Infected: not-a-virus:AdWare.Win32.Aureate.a skipped
C:\Documents and Settings\Master Luke\My Documents\C 06 Archived Files\C 07-8 JONVY'S PROGRAMS & UTILITIES\應用軟體\fgbeta.zip ZIP: infected - 6 skipped
C:\Documents and Settings\Master Luke\My Documents\C 06 Archived Files\C 07-8 JONVY'S PROGRAMS & UTILITIES\應用軟體\flashget_v1.40.rar/fg140.exe/WISE0016.BIN/cd_clint.dll Infected: not-a-virus:AdWare.Win32.Cydoor skipped
C:\Documents and Settings\Master Luke\My Documents\C 06 Archived Files\C 07-8 JONVY'S PROGRAMS & UTILITIES\應用軟體\flashget_v1.40.rar/fg140.exe/WISE0016.BIN Infected: not-a-virus:AdWare.Win32.Cydoor skipped
C:\Documents and Settings\Master Luke\My Documents\C 06 Archived Files\C 07-8 JONVY'S PROGRAMS & UTILITIES\應用軟體\flashget_v1.40.rar/fg140.exe Infected: not-a-virus:AdWare.Win32.Cydoor skipped
C:\Documents and Settings\Master Luke\My Documents\C 06 Archived Files\C 07-8 JONVY'S PROGRAMS & UTILITIES\應用軟體\flashget_v1.40.rar RAR: infected - 3 skipped
C:\Documents and Settings\Master Luke\My Documents\C 06 Archived Files\C 07-8 JONVY'S PROGRAMS & UTILITIES\應用軟體\[NEW!!!看DVD影片新程式]\DivXPro503GAINBundle.exe/Gain_Trickler.exe Infected: not-a-virus:AdWare.Win32.Gator.3202 skipped
C:\Documents and Settings\Master Luke\My Documents\C 06 Archived Files\C 07-8 JONVY'S PROGRAMS & UTILITIES\應用軟體\[NEW!!!看DVD影片新程式]\DivXPro503GAINBundle.exe Vise: infected - 1 skipped
C:\Documents and Settings\Master Luke\My Documents\E 02 Downloaded Programs\An Awesome God Desktop Theme.exe/WISE0017.BIN Infected: not-a-virus:AdWare.Win32.Quick.a skipped
C:\Documents and Settings\Master Luke\My Documents\E 02 Downloaded Programs\An Awesome God Desktop Theme.exe/WISE0018.BIN Infected: not-a-virus:AdWare.Win32.NewDotNet skipped
C:\Documents and Settings\Master Luke\My Documents\E 02 Downloaded Programs\An Awesome God Desktop Theme.exe/WISE0019.BIN Infected: Trojan-Downloader.Win32.Small.akj skipped
C:\Documents and Settings\Master Luke\My Documents\E 02 Downloaded Programs\An Awesome God Desktop Theme.exe/WISE0020.BIN Infected: Trojan-Downloader.Win32.Agent.er skipped
C:\Documents and Settings\Master Luke\My Documents\E 02 Downloaded Programs\An Awesome God Desktop Theme.exe/WISE0021.BIN Infected: not-a-virus:AdWare.Win32.EZula.z skipped
C:\Documents and Settings\Master Luke\My Documents\E 02 Downloaded Programs\An Awesome God Desktop Theme.exe WiseSFX: infected - 5 skipped
C:\Documents and Settings\Master Luke\My Documents\E 02 Downloaded Programs\Angel Icons.exe/WISE0017.BIN Infected: not-a-virus:AdWare.Win32.Quick.a skipped
C:\Documents and Settings\Master Luke\My Documents\E 02 Downloaded Programs\Angel Icons.exe/WISE0018.BIN Infected: not-a-virus:AdWare.Win32.NewDotNet skipped
C:\Documents and Settings\Master Luke\My Documents\E 02 Downloaded Programs\Angel Icons.exe/WISE0019.BIN Infected: not-a-virus:AdWare.Win32.Gator.3103 skipped
C:\Documents and Settings\Master Luke\My Documents\E 02 Downloaded Programs\Angel Icons.exe/WISE0020.BIN Infected: Trojan-Downloader.Win32.Agent.er skipped
C:\Documents and Settings\Master Luke\My Documents\E 02 Downloaded Programs\Angel Icons.exe/WISE0021.BIN Infected: not-a-virus:AdWare.Win32.EZula.u skipped
C:\Documents and Settings\Master Luke\My Documents\E 02 Downloaded Programs\Angel Icons.exe WiseSFX: infected - 5 skipped
C:\Documents and Settings\Master Luke\My Documents\E 02 Downloaded Programs\Baby Goats Desktop Theme.exe/WISE0014.BIN Infected: not-a-virus:AdWare.Win32.EZula.j skipped
C:\Documents and Settings\Master Luke\My Documents\E 02 Downloaded Programs\Baby Goats Desktop Theme.exe/WISE0015.BIN/data0002 Infected: not-a-virus:AdWare.Win32.Sidesearch.d skipped
C:\Documents and Settings\Master Luke\My Documents\E 02 Downloaded Programs\Baby Goats Desktop Theme.exe/WISE0015.BIN Infected: not-a-virus:AdWare.Win32.Sidesearch.d skipped
C:\Documents and Settings\Master Luke\My Documents\E 02 Downloaded Programs\Baby Goats Desktop Theme.exe WiseSFX: infected - 3 skipped
C:\Documents and Settings\Master Luke\My Documents\E 02 Downloaded Programs\Book of Mormon Verse Screensaver.exe/WISE0018.BIN/data0003/data0002 Infected: not-a-virus:AdWare.Win32.BargainBuddy.l skipped
C:\Documents and Settings\Master Luke\My Documents\E 02 Downloaded Programs\Book of Mormon Verse Screensaver.exe/WISE0018.BIN/data0003/data0003 Infected: not-a-virus:AdWare.Win32.BargainBuddy.a skipped
C:\Documents and Settings\Master Luke\My Documents\E 02 Downloaded Programs\Book of Mormon Verse Screensaver.exe/WISE0018.BIN/data0003 Infected: not-a-virus:AdWare.Win32.BargainBuddy.a skipped
C:\Documents and Settings\Master Luke\My Documents\E 02 Downloaded Programs\Book of Mormon Verse Screensaver.exe/WISE0018.BIN Infected: not-a-virus:AdWare.Win32.BargainBuddy.a skipped
C:\Documents and Settings\Master Luke\My Documents\E 02 Downloaded Programs\Book of Mormon Verse Screensaver.exe WiseSFX: infected - 4 skipped
C:\Documents and Settings\Master Luke\My Documents\E 02 Downloaded Programs\Christian Icons.exe/WISE0017.BIN Infected: not-a-virus:AdWare.Win32.Quick.a skipped
C:\Documents and Settings\Master Luke\My Documents\E 02 Downloaded Programs\Christian Icons.exe/WISE0018.BIN Infected: not-a-virus:AdWare.Win32.NewDotNet skipped
C:\Documents and Settings\Master Luke\My Documents\E 02 Downloaded Programs\Christian Icons.exe/WISE0019.BIN Infected: not-a-virus:AdWare.Win32.Gator.3103 skipped
C:\Documents and Settings\Master Luke\My Documents\E 02 Downloaded Programs\Christian Icons.exe/WISE0020.BIN Infected: Trojan-Downloader.Win32.Agent.er skipped
C:\Documents and Settings\Master Luke\My Documents\E 02 Downloaded Programs\Christian Icons.exe/WISE0021.BIN Infected: not-a-virus:AdWare.Win32.EZula.u skipped
C:\Documents and Settings\Master Luke\My Documents\E 02 Downloaded Programs\Christian Icons.exe WiseSFX: infected - 5 skipped
C:\Documents and Settings\Master Luke\My Documents\E 02 Downloaded Programs\Computerbug 2 Desktop Theme.exe/WISE0015.BIN/data0002 Infected: not-a-virus:AdWare.Win32.Sidesearch.d skipped
C:\Documents and Settings\Master Luke\My Documents\E 02 Downloaded Programs\Computerbug 2 Desktop Theme.exe/WISE0015.BIN Infected: not-a-virus:AdWare.Win32.Sidesearch.d skipped
C:\Documents and Settings\Master Luke\My Documents\E 02 Downloaded Programs\Computerbug 2 Desktop Theme.exe/WISE0016.BIN Infected: not-a-virus:AdWare.Win32.Gator.3103 skipped
C:\Documents and Settings\Master Luke\My Documents\E 02 Downloaded Programs\Computerbug 2 Desktop Theme.exe/WISE0017.BIN Infected: not-a-virus:AdWare.Win32.NewDotNet skipped
C:\Documents and Settings\Master Luke\My Documents\E 02 Downloaded Programs\Computerbug 2 Desktop Theme.exe WiseSFX: infected - 4 skipped
C:\Documents and Settings\Master Luke\My Documents\E 02 Downloaded Programs\Cross Icons.exe/WISE0017.BIN Infected: not-a-virus:AdWare.Win32.Quick.a skipped
C:\Documents and Settings\Master Luke\My Documents\E 02 Downloaded Programs\Cross Icons.exe/WISE0018.BIN Infected: not-a-virus:AdWare.Win32.NewDotNet skipped
C:\Documents and Settings\Master Luke\My Documents\E 02 Downloaded Programs\Cross Icons.exe/WISE0019.BIN Infected: not-a-virus:AdWare.Win32.Gator.3103 skipped
C:\Documents and Settings\Master Luke\My Documents\E 02 Downloaded Programs\Cross Icons.exe/WISE0020.BIN Infected: Trojan-Downloader.Win32.Agent.er skipped
C:\Documents and Settings\Master Luke\My Documents\E 02 Downloaded Programs\Cross Icons.exe/WISE0021.BIN Infected: not-a-virus:AdWare.Win32.EZula.u skipped
C:\Documents and Settings\Master Luke\My Documents\E 02 Downloaded Programs\Cross Icons.exe WiseSFX: infected - 5 skipped
C:\Documents and Settings\Master Luke\My Documents\E 02 Downloaded Programs\Mackinac Bridge Desktop Theme.exe/WISE0014.BIN/data0002 Infected: not-a-virus:AdWare.Win32.Sidesearch.d skipped
C:\Documents and Settings\Master Luke\My Documents\E 02 Downloaded Programs\Mackinac Bridge Desktop Theme.exe/WISE0014.BIN Infected: not-a-virus:AdWare.Win32.Sidesearch.d skipped
C:\Documents and Settings\Master Luke\My Documents\E 02 Downloaded Programs\Mackinac Bridge Desktop Theme.exe/WISE0015.BIN/WISE0011.BIN Infected: not-a-virus:AdWare.Win32.Exact.a skipped
C:\Documents and Settings\Master Luke\My Documents\E 02 Downloaded Programs\Mackinac Bridge Desktop Theme.exe/WISE0015.BIN/WISE0012.BIN Infected: not-a-virus:AdWare.Win32.Exact.a skipped
C:\Documents and Settings\Master Luke\My Documents\E 02 Downloaded Programs\Mackinac Bridge Desktop Theme.exe/WISE0015.BIN/WISE0013.BIN Infected: not-a-virus:AdWare.Win32.Exact.a skipped
C:\Documents and Settings\Master Luke\My Documents\E 02 Downloaded Programs\Mackinac Bridge Desktop Theme.exe/WISE0015.BIN Infected: not-a-virus:AdWare.Win32.Exact.a skipped
C:\Documents and Settings\Master Luke\My Documents\E 02 Downloaded Programs\Mackinac Bridge Desktop Theme.exe/WISE0016.BIN Infected: not-a-virus:AdWare.Win32.NewDotNet skipped
C:\Documents and Settings\Master Luke\My Documents\E 02 Downloaded Programs\Mackinac Bridge Desktop Theme.exe WiseSFX: infected - 7 skipped
C:\Documents and Settings\Master Luke\My Documents\E 02 Downloaded Programs\MSN-Winks - sherv.net.exe/stream/data0007/stream/data0004 Infected: not-a-virus:AdWare.Win32.180Solutions skipped
C:\Documents and Settings\Master Luke\My Documents\E 02 Downloaded Programs\MSN-Winks - sherv.net.exe/stream/data0007/stream/data0005/data.rar/whAgent.exe Infected: not-a-virus:AdWare.Win32.WebHancer.351 skipped
C:\Documents and Settings\Master Luke\My Documents\E 02 Downloaded Programs\MSN-Winks - sherv.net.exe/stream/data0007/stream/data0005/data.rar/whInstaller.exe Infected: not-a-virus:AdWare.Win32.WebHancer skipped
C:\Documents and Settings\Master Luke\My Documents\E 02 Downloaded Programs\MSN-Winks - sherv.net.exe/stream/data0007/stream/data0005/data.rar/whSurvey.exe Infected: not-a-virus:AdWare.Win32.WebHancer skipped
C:\Documents and Settings\Master Luke\My Documents\E 02 Downloaded Programs\MSN-Winks - sherv.net.exe/stream/data0007/stream/data0005/data.rar/webhdll.dll Infected: not-a-virus:AdWare.Win32.WebHancer skipped
C:\Documents and Settings\Master Luke\My Documents\E 02 Downloaded Programs\MSN-Winks - sherv.net.exe/stream/data0007/stream/data0005/data.rar/whiehlpr.dll Infected: not-a-virus:AdWare.Win32.WebHancer skipped
C:\Documents and Settings\Master Luke\My Documents\E 02 Downloaded Programs\MSN-Winks - sherv.net.exe/stream/data0007/stream/data0005/data.rar Infected: not-a-virus:AdWare.Win32.WebHancer skipped
C:\Documents and Settings\Master Luke\My Documents\E 02 Downloaded Programs\MSN-Winks - sherv.net.exe/stream/data0007/stream/data0005 Infected: not-a-virus:AdWare.Win32.WebHancer skipped
C:\Documents and Settings\Master Luke\My Documents\E 02 Downloaded Programs\MSN-Winks - sherv.net.exe/stream/data0007/stream Infected: not-a-virus:AdWare.Win32.WebHancer skipped
C:\Documents and Settings\Master Luke\My Documents\E 02 Downloaded Programs\MSN-Winks - sherv.net.exe/stream/data0007 Infected: not-a-virus:AdWare.Win32.WebHancer skipped
C:\Documents and Settings\Master Luke\My Documents\E 02 Downloaded Programs\MSN-Winks - sherv.net.exe/stream Infected: not-a-virus:AdWare.Win32.WebHancer skipped
C:\Documents and Settings\Master Luke\My Documents\E 02 Downloaded Programs\MSN-Winks - sherv.net.exe NSIS: infected - 11 skipped
C:\Documents and Settings\Master Luke\My Documents\E 02 Downloaded Programs\NASCAR Desktop Theme.exe/WISE0014.BIN Infected: not-a-virus:AdWare.Win32.NewDotNet skipped
C:\Documents and Settings\Master Luke\My Documents\E 02 Downloaded Programs\NASCAR Desktop Theme.exe/WISE0015.BIN Infected: not-a-virus:AdTool.Win32.WhenU.a skipped
C:\Documents and Settings\Master Luke\My Documents\E 02 Downloaded Programs\NASCAR Desktop Theme.exe/WISE0016.BIN Infected: not-a-virus:AdTool.Win32.WhenU.a skipped
C:\Documents and Settings\Master Luke\My Documents\E 02 Downloaded Programs\NASCAR Desktop Theme.exe WiseSFX: infected - 3 skipped
C:\Documents and Settings\Master Luke\My Documents\E 02 Downloaded Programs\NASCAR Desktop Theme.exe WiseSFX Dropper: infected - 3 skipped
C:\Documents and Settings\Master Luke\My Documents\E 02 Downloaded Programs\Praying Hands Icons.exe/WISE0017.BIN Infected: not-a-virus:AdWare.Win32.Quick.a skipped
C:\Documents and Settings\Master Luke\My Documents\E 02 Downloaded Programs\Praying Hands Icons.exe/WISE0018.BIN Infected: not-a-virus:AdWare.Win32.NewDotNet skipped
C:\Documents and Settings\Master Luke\My Documents\E 02 Downloaded Programs\Praying Hands Icons.exe/WISE0019.BIN Infected: Trojan-Downloader.Win32.Small.akj skipped
C:\Documents and Settings\Master Luke\My Documents\E 02 Downloaded Programs\Praying Hands Icons.exe/WISE0020.BIN Infected: Trojan-Downloader.Win32.Agent.er skipped
C:\Documents and Settings\Master Luke\My Documents\E 02 Downloaded Programs\Praying Hands Icons.exe/WISE0021.BIN Infected: not-a-virus:AdWare.Win32.EZula.z skipped
C:\Documents and Settings\Master Luke\My Documents\E 02 Downloaded Programs\Praying Hands Icons.exe WiseSFX: infected - 5 skipped
C:\Documents and Settings\Master Luke\My Documents\E 02 Downloaded Programs\School Desktop Theme.exe/WISE0017.BIN Infected: not-a-virus:AdWare.Win32.Quick.a skipped
C:\Documents and Settings\Master Luke\My Documents\E 02 Downloaded Programs\School Desktop Theme.exe/WISE0018.BIN Infected: not-a-virus:AdWare.Win32.NewDotNet skipped
C:\Documents and Settings\Master Luke\My Documents\E 02 Downloaded Programs\School Desktop Theme.exe/WISE0019.BIN Infected: Trojan-Downloader.Win32.Small.akj skipped
C:\Documents and Settings\Master Luke\My Documents\E 02 Downloaded Programs\School Desktop Theme.exe/WISE0020.BIN Infected: Trojan-Downloader.Win32.Agent.er skipped
C:\Documents and Settings\Master Luke\My Documents\E 02 Downloaded Programs\School Desktop Theme.exe/WISE0021.BIN Infected: not-a-virus:AdWare.Win32.EZula.z skipped
C:\Documents and Settings\Master Luke\My Documents\E 02 Downloaded Programs\School Desktop Theme.exe WiseSFX: infected - 5 skipped
C:\Documents and Settings\Master Luke\My Documents\E 02 Downloaded Programs\Sponge Bob Theme.exe/WISE0018.BIN Infected: not-a-virus:AdWare.Win32.Quick.a skipped
C:\Documents and Settings\Master Luke\My Documents\E 02 Downloaded Programs\Sponge Bob Theme.exe/WISE0019.BIN Infected: not-a-virus:AdWare.Win32.NewDotNet skipped
C:\Documents and Settings\Master Luke\My Documents\E 02 Downloaded Programs\Sponge Bob Theme.exe/WISE0020.BIN Infected: not-a-virus:AdWare.Win32.WebRebates.t skipped
C:\Documents and Settings\Master Luke\My Documents\E 02 Downloaded Programs\Sponge Bob Theme.exe/WISE0021.BIN Infected: not-a-virus:AdWare.Win32.EZula.u skipped
C:\Documents and Settings\Master Luke\My Documents\E 02 Downloaded Programs\Sponge Bob Theme.exe/WISE0022.BIN Infected: not-a-virus:AdWare.Win32.Gator.3103 skipped
C:\Documents and Settings\Master Luke\My Documents\E 02 Downloaded Programs\Sponge Bob Theme.exe WiseSFX: infected - 5 skipped
C:\Documents and Settings\Master Luke\My Documents\E 02 Downloaded Programs\Weather Bug Setup 60b6.04.0.9m.EXE/WISE0016.BIN Infected: not-a-virus:AdWare.Win32.MyWay.j skipped
C:\Documents and Settings\Master Luke\My Documents\E 02 Downloaded Programs\Weather Bug Setup 60b6.04.0.9m.EXE WiseSFX: infected - 1 skipped
C:\Documents and Settings\Master Luke\My Documents\E 02 Downloaded Programs\Weather Bug Setup 60b6.04.0.9m.EXE WiseSFX Dropper: infected - 1 skipped
C:\Documents and Settings\Master Luke\NTUSER.DAT Object is locked skipped
C:\Documents and Settings\Master Luke\ntuser.dat.LOG Object is locked skipped
C:\Documents and Settings\Master Luke Old\Local Settings\Temp\hsperfdata_Master Luke\5540 Object is locked skipped
C:\Documents and Settings\Master Luke Old\Local Settings\Temp\Install-Emoticons.exe/stream/data0004 Infected: not-a-virus:AdWare.Win32.180Solutions skipped
C:\Documents and Settings\Master Luke Old\Local Settings\Temp\Install-Emoticons.exe/stream/data0005/data.rar/whAgent.exe Infected: not-a-virus:AdWare.Win32.WebHancer.351 skipped
C:\Documents and Settings\Master Luke Old\Local Settings\Temp\Install-Emoticons.exe/stream/data0005/data.rar/whInstaller.exe Infected: not-a-virus:AdWare.Win32.WebHancer skipped
C:\Documents and Settings\Master Luke Old\Local Settings\Temp\Install-Emoticons.exe/stream/data0005/data.rar/whSurvey.exe Infected: not-a-virus:AdWare.Win32.WebHancer skipped
C:\Documents and Settings\Master Luke Old\Local Settings\Temp\Install-Emoticons.exe/stream/data0005/data.rar/webhdll.dll Infected: not-a-virus:AdWare.Win32.WebHancer skipped
C:\Documents and Settings\Master Luke Old\Local Settings\Temp\Install-Emoticons.exe/stream/data0005/data.rar/whiehlpr.dll Infected: not-a-virus:AdWare.Win32.WebHancer skipped
C:\Documents and Settings\Master Luke Old\Local Settings\Temp\Install-Emoticons.exe/stream/data0005/data.rar Infected: not-a-virus:AdWare.Win32.WebHancer skipped
C:\Documents and Settings\Master Luke Old\Local Settings\Temp\Install-Emoticons.exe/stream/data0005 Infected: not-a-virus:AdWare.Win32.WebHancer skipped
C:\Documents and Settings\Master Luke Old\Local Settings\Temp\Install-Emoticons.exe/stream Infected: not-a-virus:AdWare.Win32.WebHancer skipped
C:\Documents and Settings\Master Luke Old\Local Settings\Temp\Install-Emoticons.exe NSIS: infected - 9 skipped
C:\Documents and Settings\Master Luke Old\Local Settings\Temp\ppc17.tmp/stream/data0248/data0002 Infected: not-a-virus:AdWare.Win32.Agent.ac skipped
C:\Documents and Settings\Master Luke Old\Local Settings\Temp\ppc17.tmp/stream/data0248 Infected: not-a-virus:AdWare.Win32.Agent.ac skipped
C:\Documents and Settings\Master Luke Old\Local Settings\Temp\ppc17.tmp/stream Infected: not-a-virus:AdWare.Win32.Agent.ac skipped
C:\Documents and Settings\Master Luke Old\Local Settings\Temp\ppc17.tmp NSIS: infected - 3 skipped
C:\Documents and Settings\Master Luke Old\Local Settings\Temporary Internet Files\AntiPhishing\6729BBF9-D54C-48CB-A4D7-AD400339D808.dat Object is locked skipped
C:\Documents and Settings\Master Luke Old\Local Settings\Temporary Internet Files\AntiPhishing\B3BB5BBA-E7D5-40AB-A041-A5B1C0B26C8F.dat Object is locked skipped
C:\Documents and Settings\NetworkService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat Object is locked skipped
C:\Documents and Settings\NetworkService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped
C:\Documents and Settings\NetworkService\NTUSER.DAT Object is locked skipped
C:\Documents and Settings\NetworkService\ntuser.dat.LOG Object is locked skipped
C:\hp\bin\KillWind.exe Infected: not-a-virus:RiskTool.Win32.PsKill.p skipped
C:\Program Files\Cobian Backup 8\Settings\Master Luke Last Used.ini Object is locked skipped
C:\Program Files\InstallShield Installation Information\{8A708DD8-A5E6-11D4-A706-000629E95E20}\setup.ilg Object is locked skipped
C:\Program Files\Norton SystemWorks\Norton AntiVirus\AVApp.log Object is locked skipped
C:\Program Files\Norton SystemWorks\Norton AntiVirus\AVError.log Object is locked skipped
C:\Program Files\Norton SystemWorks\Norton AntiVirus\AVVirus.log Object is locked skipped
C:\Program Files\Norton SystemWorks\Norton AntiVirus\QuarantineCDF4112 Infected: Trojan-Downloader.Win32.Tiny.id skipped
C:\Program Files\Norton SystemWorks\Norton AntiVirus\Quarantine\15F63A2F Infected: Trojan-Downloader.Win32.Tiny.id skipped
C:\Program Files\Norton SystemWorks\Norton AntiVirus\Quarantine\181149DE Infected: Trojan-Downloader.Win32.Tiny.id skipped
C:\Program Files\Norton SystemWorks\Norton AntiVirus\Quarantine\479F5740 Infected: Trojan-Downloader.Win32.Tiny.id skipped
C:\Program Files\Norton SystemWorks\Norton AntiVirus\Quarantine\4D230008 Infected: Trojan-Downloader.Win32.Tiny.id skipped
C:\Program Files\Norton SystemWorks\Norton AntiVirus\Quarantine\53141EA5 Infected: Trojan-Downloader.Win32.Tiny.id skipped
C:\Program Files\Norton SystemWorks\Norton AntiVirus\Quarantine\59C43B04 Infected: Trojan-Downloader.Win32.Tiny.id skipped
C:\Program Files\Norton SystemWorks\Norton AntiVirus\Quarantine\603C4279 Infected: Trojan-Downloader.Win32.Tiny.id skipped
C:\Program Files\Norton SystemWorks\Norton AntiVirus\Quarantine\64C37B7D Infected: Trojan-Downloader.Win32.Tiny.id skipped
C:\Program Files\Norton SystemWorks\Norton AntiVirus\Quarantine\79846811 Infected: Trojan-Downloader.Win32.Tiny.id skipped
C:\Program Files\Viewpoint\Viewpoint Media Player\Components\AtmoHWConfig.txt Object is locked skipped
C:\Program Files\Viewpoint\Viewpoint Media Player\Components\AvatarsDefault.prf Object is locked skipped
C:\Program Files\Viewpoint\Viewpoint Media Player\Components\BookmarksDefault.prf Object is locked skipped
C:\Program Files\Viewpoint\Viewpoint Media Player\Components\DefaultAvatarIcon.jpg Object is locked skipped
C:\Program Files\Viewpoint\Viewpoint Media Player\Components\DefaultWorldIcon.jpg Object is locked skipped
C:\Program Files\Viewpoint\Viewpoint Media Player\Components\InternetChatHelp.url Object is locked skipped
C:\Program Files\Viewpoint\Viewpoint Media Player\Components\VETsdk.dll Object is locked skipped
C:\Program Files\Virtual Assistant\log\mpbtn.log Object is locked skipped
C:\Program Files\Virtual Assistant\SmartBridge\AlertFilter.log Object is locked skipped
C:\Program Files\Virtual Assistant\SmartBridge\log\httpclient.log Object is locked skipped
C:\Program Files\Virtual Assistant\SmartBridge\SmartBridge.log Object is locked skipped
C:\RECYCLER\S-1-5-21-1303909375-1294642078-4094575798-1006\Dc38\30DC6D06 Infected: Trojan.Java.ClassLoader.ao skipped
C:\RECYCLER\S-1-5-21-1303909375-1294642078-4094575798-1006\Dc38\45551FB7.exe Infected: P2P-Worm.Win32.VB.dw skipped
C:\RECYCLER\S-1-5-21-1303909375-1294642078-4094575798-1006\Dc38\4B2B1B03 Infected: Trojan.Java.ClassLoader.ao skipped
C:\RECYCLER\S-1-5-21-1303909375-1294642078-4094575798-1006\Dc38\4D8F6757.class Infected: Exploit.Java.ByteVerify skipped
C:\RECYCLER\S-1-5-21-1303909375-1294642078-4094575798-1006\Dc38\4D921154.class Infected: Trojan.Java.ClassLoader.Dummy.d skipped
C:\RECYCLER\S-1-5-21-1303909375-1294642078-4094575798-1006\Dc38\4D921154.wmf Infected: Trojan-Downloader.Win32.Agent.acd skipped
C:\RECYCLER\S-1-5-21-1303909375-1294642078-4094575798-1006\Dc38\4D99654C.class Infected: Exploit.Java.ByteVerify skipped
C:\RECYCLER\S-1-5-21-1303909375-1294642078-4094575798-1006\Dc38\5F3F29C4 Infected: Trojan.Java.ClassLoader.ao skipped
C:\RECYCLER\S-1-5-21-1303909375-1294642078-4094575798-1006\Dc38\64425342 Infected: Rootkit.Win32.Agent.dh skipped
C:\RECYCLER\S-1-5-21-1303909375-1294642078-4094575798-1006\Dc38\69B52517.htm Infected: Exploit.HTML.Mht skipped
C:\RECYCLER\S-1-5-21-1303909375-1294642078-4094575798-1006\Dc38\75ED7219 Infected: Rootkit.Win32.Agent.dh skipped
C:\RECYCLER\S-1-5-21-1303909375-1294642078-4094575798-1006\Dc38\779C2769.htm Infected: Exploit.HTML.Mht skipped
C:\System Volume Information\MountPointManagerRemoteDatabase Object is locked skipped
C:\System Volume Information\_restore{07067F02-601B-445E-AF8E-8602C05A674E}\RP8\change.log Object is locked skipped
C:\WINDOWS\$NtServicePackUninstall$\5n53brb5.dat Object is locked skipped
C:\WINDOWS\$NtServicePackUninstall$\6kuvvlv7.zip Object is locked skipped
C:\WINDOWS\$NtServicePackUninstall$\6to4svc.dll Object is locked skipped
C:\WINDOWS\$NtServicePackUninstall$\7pzt7rlr.dat Object is locked skipped
C:\WINDOWS\$NtServicePackUninstall$\8jlbvtzx.dat Object is locked skipped
C:\WINDOWS\$NtServicePackUninstall$\8jlbvtzx.zip Object is locked skipped
C:\WINDOWS\$NtServicePackUninstall$\9j5rpfdn.zip Object is locked skipped
C:\WINDOWS\$NtServicePackUninstall$\a5nrzbd7.dat Object is locked skipped
C:\WINDOWS\$NtServicePackUninstall$\a5nrzbd7.zip Object is locked skipped
C:\WINDOWS\$NtServicePackUninstall$\acadproc.dll Object is locked skipped
C:\WINDOWS\$NtServicePackUninstall$\access.cpl Object is locked skipped
C:\WINDOWS\$NtServicePackUninstall$\accessor.inf Object is locked skipped
C:\WINDOWS\$NtServicePackUninstall$\accwiz.exe Object is locked skipped
C:\WINDOWS\$NtServicePackUninstall$\acgenral.dll Object is locked skipped
C:\WINDOWS\$NtServicePackUninstall$\aclayers.dll Object is locked skipped
C:\WINDOWS\$NtServicePackUninstall$\aclua.dll Object is locked skipped
C:\WINDOWS\$NtServicePackUninstall$\aclui.dll Object is locked skipped
C:\WINDOWS\$NtServicePackUninstall$\acpi.inf Object is locked skipped
C:\WINDOWS\$NtServicePackUninstall$\acpi.sys Object is locked skipped
C:\WINDOWS\$NtServicePackUninstall$\acspecfc.dll Object is locked skipped
C:\WINDOWS\$NtServicePackUninstall$\activ.htm Object is locked skipped
C:\WINDOWS\$NtServicePackUninstall$\activeds.dll Object is locked skipped
C:\WINDOWS\$NtServicePackUninstall$\activsvc.htm Object is locked skipped
C:\WINDOWS\$NtServicePackUninstall$\actlan.htm Object is locked skipped
C:\WINDOWS\$NtServicePackUninstall$\actmovie.exe Object is locked skipped
C:\WINDOWS\$NtServicePackUninstall$\actshell.htm Object is locked skipped
C:\WINDOWS\$NtServicePackUninstall$\actxprxy.dll Object is locked skipped
C:\WINDOWS\$NtServicePackUninstall$\acverfyr.dll Object is locked skipped
C:\WINDOWS\$NtServicePackUninstall$\acxtrnal.dll Object is locked skipped
C:\WINDOWS\$NtServicePackUninstall$\adcjavas.inc Object is locked skipped
C:\WINDOWS\$NtServicePackUninstall$\adcvbs.inc Object is locked skipped
C:\WINDOWS\$NtServicePackUninstall$\adeskerr.htm Object is locked skipped
C:\WINDOWS\$NtServicePackUninstall$\admin.dll Object is locked skipped
C:\WINDOWS\$NtServicePackUninstall$\admin.exe Object is locked skipped
C:\WINDOWS\$NtServicePackUninstall$\admparse.dll Object is locked skipped
C:\WINDOWS\$NtServicePackUninstall$\adojavas.inc Object is locked skipped
C:\WINDOWS\$NtServicePackUninstall$\adovbs.inc Object is locked skipped
C:\WINDOWS\$NtServicePackUninstall$\adsldp.dll Object is locked skipped
C:\WINDOWS\$NtServicePackUninstall$\adsldpc.dll Object is locked skipped
C:\WINDOWS\$NtServicePackUninstall$\adsmsext.dll Object is locked skipped
C:\WINDOWS\$NtServicePackUninstall$\adsnt.dll Object is locked skipped
C:\WINDOWS\$NtServicePackUninstall$\advapi32.dll Object is locked skipped
C:\WINDOWS\$NtServicePackUninstall$\advpack.dll Object is locked skipped
C:\WINDOWS\$NtServicePackUninstall$\aec.sys Object is locked skipped
C:\WINDOWS\$NtServicePackUninstall$\afd.sys Object is locked skipped
C:\WINDOWS\$NtServicePackUninstall$\agentanm.dll Object is locked skipped
C:\WINDOWS\$NtServicePackUninstall$\agentctl.dll Object is locked skipped
C:\WINDOWS\$NtServicePackUninstall$\agentdp2.dll Object is locked skipped
C:\WINDOWS\$NtServicePackUninstall$\agentdpv.dll Object is locked skipped
C:\WINDOWS\$NtServicePackUninstall$\agentmpx.dll Object is locked skipped
C:\WINDOWS\$NtServicePackUninstall$\agentpsh.dll Object is locked skipped
C:\WINDOWS\$NtServicePackUninstall$\agentsr.dll Object is locked skipped
C:\WINDOWS\$NtServicePackUninstall$\agentsvr.exe Object is locked skipped
C:\WINDOWS\$NtServicePackUninstall$\agp440.sys Object is locked skipped
C:\WINDOWS\$NtServicePackUninstall$\agtctl15.tlb Object is locked skipped
C:\WINDOWS\$NtServicePackUninstall$\agtintl.dll Object is locked skipped
C:\WINDOWS\$NtServicePackUninstall$\agtscrpt.js Object is locked skipped
C:\WINDOWS\$NtServicePackUninstall$\ahui.exe Object is locked skipped
C:\WINDOWS\$NtServicePackUninstall$\alg.exe Object is locked skipped
C:\WINDOWS\$NtServicePackUninstall$\alrsvc.dll Object is locked skipped
C:\WINDOWS\$NtServicePackUninstall$\amdk6.sys Object is locked skipped
C:\WINDOWS\$NtServicePackUninstall$\amstream.dll Object is locked skipped
C:\WINDOWS\$NtServicePackUninstall$\apphelp.dll Object is locked skipped
C:\WINDOWS\$NtServicePackUninstall$\apphelp.sdb Object is locked skipped
C:\WINDOWS\$NtServicePackUninstall$\apph_sp.sdb Object is locked skipped
C:\WINDOWS\$NtServicePackUninstall$\apps.chm Object is locked skipped
C:\WINDOWS\$NtServicePackUninstall$\appwiz.cpl Object is locked skipped
C:\WINDOWS\$NtServicePackUninstall$\arial.ttf Object is locked skipped
C:\WINDOWS\$NtServicePackUninstall$\arialbd.ttf Object is locked skipped
C:\WINDOWS\$NtServicePackUninstall$\arp1394.sys Object is locked skipped
C:\WINDOWS\$NtServicePackUninstall$\asctrls.ocx Object is locked skipped
C:\WINDOWS\$NtServicePackUninstall$\asferror.dll Object is locked skipped
C:\WINDOWS\$NtServicePackUninstall$\asfsipc.dll Object is locked skipped
C:\WINDOWS\$NtServicePackUninstall$\asycfilt.dll Object is locked skipped
C:\WINDOWS\$NtServicePackUninstall$\asyncmac.sys Object is locked skipped
C:\WINDOWS\$NtServicePackUninstall$\at.exe Object is locked skipped
C:\WINDOWS\$NtServicePackUninstall$\atapi.sys Object is locked skipped
C:\WINDOWS\$NtServicePackUninstall$\atiradn1.inf Object is locked skipped
C:\WINDOWS\$NtServicePackUninstall$\atl.dll Object is locked skipped
C:\WINDOWS\$NtServicePackUninstall$\atm.chm Object is locked skipped
C:\WINDOWS\$NtServicePackUninstall$\atmadm.exe Object is locked skipped
C:\WINDOWS\$NtServicePackUninstall$\atmarpc.sys Object is locked skipped
C:\WINDOWS\$NtServicePackUninstall$\atmfd.dll Object is locked skipped
C:\WINDOWS\$NtServicePackUninstall$\atmlane.sys Object is locked skipped
C:\WINDOWS\$NtServicePackUninstall$\atmlib.dll Object is locked skipped
C:\WINDOWS\$NtServicePackUninstall$\au.inf Object is locked skipped
C:\WINDOWS\$NtServicePackUninstall$\audiosrv.dll Object is locked skipped
C:\WINDOWS\$NtServicePackUninstall$\author.dll Object is locked skipped
C:\WINDOWS\$NtServicePackUninstall$\author.exe Object is locked skipped
C:\WINDOWS\$NtServicePackUninstall$\authz.dll Object is locked skipped
C:\WINDOWS\$NtServicePackUninstall$\autochk.exe Object is locked skipped
C:\WINDOWS\$NtServicePackUninstall$\autoconv.exe Object is locked skipped
C:\WINDOWS\$NtServicePackUninstall$\autofmt.exe Object is locked skipped
C:\WINDOWS\$NtServicePackUninstall$\autolfn.exe Object is locked skipped
C:\WINDOWS\$NtServicePackUninstall$\avifil32.dll Object is locked skipped
C:\WINDOWS\$NtServicePackUninstall$\awpzx3f5.zip Object is locked skipped
C:\WINDOWS\$NtServicePackUninstall$\basesrv.dll Object is locked skipped
C:\WINDOWS\$NtServicePackUninstall$\batmeter.dll Object is locked skipped
C:\WINDOWS\$NtServicePackUninstall$\batt.dll Object is locked skipped
C:\WINDOWS\$NtServicePackUninstall$\bda.inf Object is locked skipped
C:\WINDOWS\$NtServicePackUninstall$\bidispl.dll Object is locked skipped
C:\WINDOWS\$NtServicePackUninstall$\biosinfo.inf Object is locked skipped
C:\WINDOWS\$NtServicePackUninstall$\blackbox.dll Object is locked skipped
C:\WINDOWS\$NtServicePackUninstall$\bridge.sys Object is locked skipped
C:\WINDOWS\$NtServicePackUninstall$\browselc.dll Object is locked skipped
C:\WINDOWS\$NtServicePackUninstall$\browser.dll Object is locked skipped
C:\WINDOWS\$NtServicePackUninstall$\browseui.dll Object is locked skipped
C:\WINDOWS\$NtServicePackUninstall$\browsewm.dll Object is locked skipped
C:\WINDOWS\$NtServicePackUninstall$\cabinet.dll Object is locked skipped
C:\WINDOWS\$NtServicePackUninstall$\cabview.dll Object is locked skipped
C:\WINDOWS\$NtServicePackUninstall$\callcont.dll Object is locked skipped
C:\WINDOWS\$NtServicePackUninstall$\camocx.dll Object is locked skipped
C:\WINDOWS\$NtServicePackUninstall$\catsrv.dll Object is locked skipped
C:\WINDOWS\$NtServicePackUninstall$\catsrvps.dll Object is locked skipped
C:\WINDOWS\$NtServicePackUninstall$\catsrvut.dll Object is locked skipped
C:\WINDOWS\$NtServicePackUninstall$\cdfs.sys Object is locked skipped
C:\WINDOWS\$NtServicePackUninstall$\cdfview.dll Object is locked skipped
C:\WINDOWS\$NtServicePackUninstall$\cdm.dll Object is locked skipped
C:\WINDOWS\$NtServicePackUninstall$\cdosys.dll Object is locked skipped
C:\WINDOWS\$NtServicePackUninstall$\cdrom.inf Object is locked skipped
C:\WINDOWS\$NtServicePackUninstall$\cdrom.sys Object is locked skipped
C:\WINDOWS\$NtServicePackUninstall$\certcli.dll Object is locked skipped
C:\WINDOWS\$NtServicePackUninstall$\certmgr.dll Object is locked skipped
C:\WINDOWS\$NtServicePackUninstall$\cewmdm.dll Object is locked skipped
C:\WINDOWS\$NtServicePackUninstall$\cfgbkend.dll Object is locked skipped
C:\WINDOWS\$NtServicePackUninstall$\cfgmgr32.dll Object is locked skipped
C:\WINDOWS\$NtServicePackUninstall$\cfgwiz.exe Object is locked skipped
C:\WINDOWS\$NtServicePackUninstall$\ci6v973r.dat Object is locked skipped
C:\WINDOWS\$NtServicePackUninstall$\ci6v973r.zip Object is locked skipped
C:\WINDOWS\$NtServicePackUninstall$\cimwin32.dll Object is locked skipped
C:\WINDOWS\$NtServicePackUninstall$\cimwin32.mfl Object is locked skipped
C:\WINDOWS\$NtServicePackUninstall$\cimwin32.mof Object is locked skipped
C:\WINDOWS\$NtServicePackUninstall$\ciodm.dll Object is locked skipped
C:\WINDOWS\$NtServicePackUninstall$\cisvc.exe Object is locked skipped
C:\WINDOWS\$NtServicePackUninstall$\classpnp.sys Object is locked skipped
C:\WINDOWS\$NtServicePackUninstall$\clbcatex.dll Object is locked skipped
C:\WINDOWS\$NtServicePackUninstall$\clbcatq.dll Object is locked skipped
C:\WINDOWS\$NtServicePackUninstall$\cleanmgr.exe Object is locked skipped
C:\WINDOWS\$NtServicePackUninstall$\cliconfg.dll Object is locked skipped
C:\WINDOWS\$NtServicePackUninstall$\cliconfg.exe Object is locked skipped
C:\WINDOWS\$NtServicePackUninstall$\cliconfg.rll Object is locked skipped
C:\WINDOWS\$NtServicePackUninstall$\clipbrd.exe Object is locked skipped
C:\WINDOWS\$NtServicePackUninstall$\clipsrv.exe Object is locked skipped
C:\WINDOWS\$NtServicePackUninstall$\clusapi.dll Object is locked skipped
C:\WINDOWS\$NtServicePackUninstall$\cmcfg32.dll Object is locked skipped
C:\WINDOWS\$NtServicePackUninstall$\cmd.exe Object is locked skipped
C:\WINDOWS\$NtServicePackUninstall$\cmdial32.dll Object is locked skipped
C:\WINDOWS\$NtServicePackUninstall$\cmdl32.exe Object is locked skipped
C:\WINDOWS\$NtServicePackUninstall$\cmmon32.exe Object is locked skipped
C:\WINDOWS\$NtServicePackUninstall$\cmprops.dll Object is locked skipped
C:\WINDOWS\$NtServicePackUninstall$\cmstp.exe Object is locked skipped
C:\WINDOWS\$NtServicePackUninstall$\cmutil.dll Object is locked skipped
C:\WINDOWS\$NtServicePackUninstall$\cnbjmon.dll Object is locked skipped
C:\WINDOWS\$NtServicePackUninstall$\colbact.dll Object is locked skipped
C:\WINDOWS\$NtServicePackUninstall$\comadmin.dll Object is locked skipped
C:\WINDOWS\$NtServicePackUninstall$\comctl32.dll Object is locked skipped
C:\WINDOWS\$NtServicePackUninstall$\comdlg32.dll Object is locked skipped
C:\WINDOWS\$NtServicePackUninstall$\comexp.chm Object is locked skipped
C:\WINDOWS\$NtServicePackUninstall$\comic.ttf Object is locked skipped
C:\WINDOWS\$NtServicePackUninstall$\compact.wmz Object is locked skipped
C:\WINDOWS\$NtServicePackUninstall$\compatui.dll Object is locked skipped
C:\WINDOWS\$NtServicePackUninstall$\compstui.dll Object is locked skipped
C:\WINDOWS\$NtServicePackUninstall$\comrepl.exe Object is locked skipped
C:\WINDOWS\$NtServicePackUninstall$\comres.dll Object is locked skipped
C:\WINDOWS\$NtServicePackUninstall$\comsvcs.dll Object is locked skipped
C:\WINDOWS\$NtServicePackUninstall$\comuid.dll Object is locked skipped
C:\WINDOWS\$NtServicePackUninstall$\conf.exe Object is locked skipped
C:\WINDOWS\$NtServicePackUninstall$\confmrsl.dll Object is locked skipped
C:\WINDOWS\$NtServicePackUninstall$\conime.exe Object is locked skipped
C:\WINDOWS\$NtServicePackUninstall$\connected_data.htm Object is locked skipped
C:\WINDOWS\$NtServicePackUninstall$\connected_fr.htm Object is locked skipped
C:\WINDOWS\$NtServicePackUninstall$\connected_multiple.htm Object is locked skipped
C:\WINDOWS\$NtServicePackUninstall$\connected_networks.htm Object is locked skipped
C:\WINDOWS\$NtServicePackUninstall$\connected_wizard.htm Object is locked skipped
C:\WINDOWS\$NtServicePackUninstall$\corpol.dll Object is locked skipped
C:\WINDOWS\$NtServicePackUninstall$\courtney.acs Object is locked skipped
C:\WINDOWS\$NtServicePackUninstall$\cpanel.chq Object is locked skipped
C:\WINDOWS\$NtServicePackUninstall$\cpu.inf Object is locked skipped
C:\WINDOWS\$NtServicePackUninstall$\credui.dll Object is locked skipped
C:\WINDOWS\$NtServicePackUninstall$\crusoe.sys Object is locked skipped
C:\WINDOWS\$NtServicePackUninstall$\crypt32.dll Object is locked skipped
C:\WINDOWS\$NtServicePackUninstall$\cryptdlg.dll Object is locked skipped
C:\WINDOWS\$NtServicePackUninstall$\cryptdll.dll Object is locked skipped
C:\WINDOWS\$NtServicePackUninstall$\cryptext.dll Object is locked skipped
C:\WINDOWS\$NtServicePackUninstall$\cryptnet.dll Object is locked skipped
C:\WINDOWS\$NtServicePackUninstall$\cryptsvc.dll Object is locked skipped
C:\WINDOWS\$NtServicePackUninstall$\cryptui.dll Object is locked skipped
C:\WINDOWS\$NtServicePackUninstall$\cs2tb1bx.zip Object is locked skipped
C:\WINDOWS\$NtServicePackUninstall$\cscdll.dll Object is locked skipped
C:\WINDOWS\$NtServicePackUninstall$\cscript.exe Object is locked skipped
C:\WINDOWS\$NtServicePackUninstall$\cscui.dll Object is locked skipped
C:\WINDOWS\$NtServicePackUninstall$\csrsrv.dll Object is locked skipped
C:\WINDOWS\$NtServicePackUninstall$\csrss.exe Object is locked skipped
C:\WINDOWS\$NtServicePackUninstall$\ctfmon.exe Object is locked skipped
C:\WINDOWS\$NtServicePackUninstall$\d3d8.dll Object is locked skipped
C:\WINDOWS\$NtServicePackUninstall$\d3d8thk.dll Object is locked skipped
C:\WINDOWS\$NtServicePackUninstall$\d3dim700.dll Object is locked skipped
C:\WINDOWS\$NtServicePackUninstall$\danim.dll Object is locked skipped
C:\WINDOWS\$NtServicePackUninstall$\dao360.dll Object is locked skipped
C:\WINDOWS\$NtServicePackUninstall$\dataclen.dll Object is locked skipped
C:\WINDOWS\$NtServicePackUninstall$\dataspec.xml Object is locked skipped
C:\WINDOWS\$NtServicePackUninstall$\datetime.chm Object is locked skipped
C:\WINDOWS\$NtServicePackUninstall$\davclnt.dll Object is locked skipped
C:\WINDOWS\$NtServicePackUninstall$\daxctle.ocx Object is locked skipped
C:\WINDOWS\$NtServicePackUninstall$\dbghelp.dll Object is locked skipped
C:\WINDOWS\$NtServicePackUninstall$\dbmsrpcn.dll Object is locked skipped
C:\WINDOWS\$NtServicePackUninstall$\dbnetlib.dll Object is locked skipped
C:\WINDOWS\$NtServicePackUninstall$\dbnmpntw.dll Object is locked skipped
C:\WINDOWS\$NtServicePackUninstall$\dcache.bin Object is locked skipped
C:\WINDOWS\$NtServicePackUninstall$\dcap32.dll Object is locked skipped
C:\WINDOWS\$NtServicePackUninstall$\dciman32.dll Object is locked skipped
C:\WINDOWS\$NtServicePackUninstall$\ddeshare.exe Object is locked skipped
C:\WINDOWS\$NtServicePackUninstall$\ddraw.dll Object is locked skipped
C:\WINDOWS\$NtServicePackUninstall$\ddrawex.dll Object is locked skipped
C:\WINDOWS\$NtServicePackUninstall$\default.htm Object is locked skipped
C:\WINDOWS\$NtServicePackUninstall$\defltwk.inf Object is locked skipped
C:\WINDOWS\$NtServicePackUninstall$\defrag.exe Object is locked skipped
C:\WINDOWS\$NtServicePackUninstall$\desk.cpl Object is locked skipped
C:\WINDOWS\$NtServicePackUninstall$\devenum.dll Object is locked skipped
C:\WINDOWS\$NtServicePackUninstall$\devmgr.dll Object is locked skipped
C:\WINDOWS\$NtServicePackUninstall$\devxprop.inf Object is locked skipped
C:\WINDOWS\$NtServicePackUninstall$\dfrgfat.exe Object is locked skipped
C:\WINDOWS\$NtServicePackUninstall$\dfrgntfs.exe Object is locked skipped
C:\WINDOWS\$NtServicePackUninstall$\dfrgsnap.dll Object is locked skipped
C:\WINDOWS\$NtServicePackUninstall$\dfrgui.dll Object is locked skipped
C:\WINDOWS\$NtServicePackUninstall$\dfsshlex.dll Object is locked skipped
C:\WINDOWS\$NtServicePackUninstall$\dgnet.dll Object is locked skipped
C:\WINDOWS\$NtServicePackUninstall$\dhcpcsvc.dll Object is locked skipped
C:\WINDOWS\$NtServicePackUninstall$\dhtmled.ocx Object is locked skipped
C:\WINDOWS\$NtServicePackUninstall$\dialer.exe Object is locked skipped
C:\WINDOWS\$NtServicePackUninstall$\diantz.exe Object is locked skipped
C:\WINDOWS\$NtServicePackUninstall$\digest.dll Object is locked skipped
C:\WINDOWS\$NtServicePackUninstall$\dinput.dll Object is locked skipped
C:\WINDOWS\$NtServicePackUninstall$\dinput8.dll Object is locked skipped
C:\WINDOWS\$NtServicePackUninstall$\directdb.dll Object is locked skipped
C:\WINDOWS\$NtServicePackUninstall$\disk.inf Object is locked skipped
C:\WINDOWS\$NtServicePackUninstall$\disk.sys Object is locked skipped
C:\WINDOWS\$NtServicePackUninstall$\diskdump.sys Object is locked skipped
C:\WINDOWS\$NtServicePackUninstall$\diskpart.exe Object is locked skipped
C:\WINDOWS\$NtServicePackUninstall$\dlimport.exe Object is locked skipped
C:\WINDOWS\$NtServicePackUninstall$\dllhost.exe Object is locked skipped
C:\WINDOWS\$NtServicePackUninstall$\dmadmin.exe Object is locked skipped
C:\WINDOWS\$NtServicePackUninstall$\dmband.dll Object is locked skipped
C:\WINDOWS\$NtServicePackUninstall$\dmboot.sys Object is locked skipped
C:\WINDOWS\$NtServicePackUninstall$\dmcompos.dll Object is locked skipped
C:\WINDOWS\$NtServicePackUninstall$\dmdskmgr.dll Object is locked skipped
C:\WINDOWS\$NtServicePackUninstall$\dmime.dll Object is locked skipped
C:\WINDOWS\$NtServicePackUninstall$\dmio.sys Object is locked skipped
C:\WINDOWS\$NtServicePackUninstall$\dmloader.dll Object is locked skipped
C:\WINDOWS\$NtServicePackUninstall$\dmremote.exe Object is locked skipped
C:\WINDOWS\$NtServicePackUninstall$\dmscript.dll Object is locked skipped
C:\WINDOWS\$NtServicePackUninstall$\dmserver.dll Object is locked skipped
C:\WINDOWS\$NtServicePackUninstall$\dmstyle.dll Object is locked skipped
C:\WINDOWS\$NtServicePackUninstall$\dmsynth.dll Object is locked skipped
C:\WINDOWS\$NtServicePackUninstall$\dmusic.dll Object is locked skipped
C:\WINDOWS\$NtServicePackUninstall$\dmusic.sys Object is locked skipped
C:\WINDOWS\$NtServicePackUninstall$\dmutil.dll Object is locked skipped
C:\WINDOWS\$NtServicePackUninstall$\dnsapi.dll Object is locked skipped
C:\WINDOWS\$NtServicePackUninstall$\dnsrslvr.dll Object is locked skipped
C:\WINDOWS\$NtServicePackUninstall$\docprop2.dll Object is locked skipped
C:\WINDOWS\$NtServicePackUninstall$\dosx.exe Object is locked skipped
C:\WINDOWS\$NtServicePackUninstall$\dpcdll.dll Object is locked skipped
C:\WINDOWS\$NtServicePackUninstall$\dplaysvr.exe Object is locked skipped
C:\WINDOWS\$NtServicePackUninstall$\dplayx.dll Object is locked skipped
C:\WINDOWS\$NtServicePackUninstall$\dpmodemx.dll Object is locked skipped
C:\WINDOWS\$NtServicePackUninstall$\dpnaddr.dll Object is locked skipped
C:\WINDOWS\$NtServicePackUninstall$\dpnet.dll Object is locked skipped
C:\WINDOWS\$NtServicePackUninstall$\dpnhpast.dll Object is locked skipped
C:\WINDOWS\$NtServicePackUninstall$\dpnhupnp.dll Object is locked skipped
C:\WINDOWS\$NtServicePackUninstall$\dpnlobby.dll Object is locked skipped
C:\WINDOWS\$NtServicePackUninstall$\dpnsvr.exe Object is locked skipped
C:\WINDOWS\$NtServicePackUninstall$\dpvacm.dll Object is locked skipped
C:\WINDOWS\$NtServicePackUninstall$\dpvoice.dll Object is locked skipped
C:\WINDOWS\$NtServicePackUninstall$\dpvsetup.exe Object is locked skipped
C:\WINDOWS\$NtServicePackUninstall$\dpvvox.dll Object is locked skipped
C:\WINDOWS\$NtServicePackUninstall$\dpwsockx.dll Object is locked skipped
C:\WINDOWS\$NtServicePackUninstall$\drmclien.dll Object is locked skipped
C:\WINDOWS\$NtServicePackUninstall$\drmk.sys Object is locked skipped
C:\WINDOWS\$NtServicePackUninstall$\drmkaud.sys Object is locked skipped
C:\WINDOWS\$NtServicePackUninstall$\drmstor.dll Object is locked skipped
C:\WINDOWS\$NtServicePackUninstall$\drmv2clt.dll Object is locked skipped
C:\WINDOWS\$NtServicePackUninstall$\drprov.dll Object is locked skipped
C:\WINDOWS\$NtServicePackUninstall$\drvindex.inf Object is locked skipped
C:\WINDOWS\$NtServicePackUninstall$\drvmain.sdb Object is locked skipped
C:\WINDOWS\$NtServicePackUninstall$\ds32gt.dll Object is locked skipped
C:\WINDOWS\$NtServicePackUninstall$\dsdmo.dll Object is locked skipped
C:\WINDOWS\$NtServicePackUninstall$\dsdmoprp.dll Object is locked skipped
C:\WINDOWS\$NtServicePackUninstall$\dskquota.dll Object is locked skipped
C:\WINDOWS\$NtServicePackUninstall$\dskquoui.chm Object is locked skipped
C:\WINDOWS\$NtServicePackUninstall$\dsound.dll Object is locked skipped
C:\WINDOWS\$NtServicePackUninstall$\dsound3d.dll Object is locked skipped
C:\WINDOWS\$NtServicePackUninstall$\dsprop.dll Object is locked skipped
C:\WINDOWS\$NtServicePackUninstall$\dsquery.dll Object is locked skipped
C:\WINDOWS\$NtServicePackUninstall$\dssec.dll Object is locked skipped
C:\WINDOWS\$NtServicePackUninstall$\dssenh.dll Object is locked skipped
C:\WINDOWS\$NtServicePackUninstall$\dsuiext.dll Object is locked skipped
C:\WINDOWS\$NtServicePackUninstall$\dswave.dll Object is locked skipped
C:\WINDOWS\$NtServicePackUninstall$\dtsgnup.htm Object is locked skipped
C:\WINDOWS\$NtServicePackUninstall$\dumprep.exe Object is locked skipped
C:\WINDOWS\$NtServicePackUninstall$\duser.dll Object is locked skipped
C:\WINDOWS\$NtServicePackUninstall$\dvdupgrd.exe Object is locked skipped
C:\WINDOWS\$NtServicePackUninstall$\dwup.inf Object is locked skipped
C:\WINDOWS\$NtServicePackUninstall$\dwwin.exe Object is locked skipped
C:\WINDOWS\$NtServicePackUninstall$\dx7vb.dll Object is locked skipped
C:\WINDOWS\$NtServicePackUninstall$\dx8vb.dll Object is locked skipped
C:\WINDOWS\$NtServicePackUninstall$\dxdiag.chm Object is locked skipped
C:\WINDOWS\$NtServicePackUninstall$\dxdiag.exe Object is locked skipped
C:\WINDOWS\$NtServicePackUninstall$\dxg.sys Object is locked skipped
C:\WINDOWS\$NtServicePackUninstall$\dxmasf.dll Object is locked skipped
C:\WINDOWS\$NtServicePackUninstall$\dxmrtp.dll Object is locked skipped
C:\WINDOWS\$NtServicePackUninstall$\dxtmsft.dll Object is locked skipped
C:\WINDOWS\$NtServicePackUninstall$\dxtrans.dll Object is locked skipped
C:\WINDOWS\$NtServicePackUninstall$\earl.acs Object is locked skipped
C:\WINDOWS\$NtServicePackUninstall$\els.dll Object is locked skipped
C:\WINDOWS\$NtServicePackUninstall$\error.js Object is locked skipped
C:\WINDOWS\$NtServicePackUninstall$\ersvc.dll Object is locked skipped
C:\WINDOWS\$NtServicePackUninstall$\es.dll Object is locked skipped
C:\WINDOWS\$NtServicePackUninstall$\esent.dll Object is locked skipped
C:\WINDOWS\$NtServicePackUninstall$\esscli.dll Object is locked skipped
C:\WINDOWS\$NtServicePackUninstall$\eudcedit.exe Object is locked skipped
C:\WINDOWS\$NtServicePackUninstall$\evconcepts.chm Object is locked skipped
C:\WINDOWS\$NtServicePackUninstall$\eventlog.dll Object is locked skipped
C:\WINDOWS\$NtServicePackUninstall$\evntagnt.dll Object is locked skipped
C:\WINDOWS\$NtServicePackUninstall$\evntcmd.exe Object is locked skipped
C:\WINDOWS\$NtServicePackUninstall$\evntrprv.dll Object is locked skipped
C:\WINDOWS\$NtServicePackUninstall$\evntwin.exe Object is locked skipped
C:\WINDOWS\$NtServicePackUninstall$\explorer.exe Object is locked skipped
C:\WINDOWS\$NtServicePackUninstall$\expsrv.dll Object is locked skipped
C:\WINDOWS\$NtServicePackUninstall$\extrac32.exe Object is locked skipped
C:\WINDOWS\$NtServicePackUninstall$\fastfat.sys Object is locked skipped
C:\WINDOWS\$NtServicePackUninstall$\fastprox.dll Object is locked skipped
C:\WINDOWS\$NtServicePackUninstall$\faultrep.dll Object is locked skipped
C:\WINDOWS\$NtServicePackUninstall$\fdc.sys Object is locked skipped
C:\WINDOWS\$NtServicePackUninstall$\feclient.dll Object is locked skipped
C:\WINDOWS\$NtServicePackUninstall$\filefold.chm Object is locked skipped
C:\WINDOWS\$NtServicePackUninstall$\filelist.xml Object is locked skipped
C:\WINDOWS\$NtServicePackUninstall$\filemgmt.dll Object is locked skipped
C:\WINDOWS\$NtServicePackUninstall$\file_srv.chm Object is locked skipped
C:\WINDOWS\$NtServicePackUninstall$\findstr.exe Object is locked skipped
C:\WINDOWS\$NtServicePackUninstall$\fldrclnr.dll Object is locked skipped
C:\WINDOWS\$NtServicePackUninstall$\flpydisk.sys Object is locked skipped
C:\WINDOWS\$NtServicePackUninstall$\fontext.dll Object is locked skipped
C:\WINDOWS\$NtServicePackUninstall$\fontview.exe Object is locked skipped
C:\WINDOWS\$NtServicePackUninstall$\footer.htm Object is locked skipped
C:\WINDOWS\$NtServicePackUninstall$\fp4.cat Object is locked skipped
C:\WINDOWS\$NtServicePackUninstall$\fp40ext.dll Object is locked skipped
C:\WINDOWS\$NtServicePackUninstall$\fp40ext.inf Object is locked skipped
C:\WINDOWS\$NtServicePackUninstall$\fp4amsft.dll Object is locked skipped
C:\WINDOWS\$NtServicePackUninstall$\fp4anscp.dll Object is locked skipped
C:\WINDOWS\$NtServicePackUninstall$\fp4apws.dll Object is locked skipped
C:\WINDOWS\$NtServicePackUninstall$\fp4areg.dll Object is locked skipped
C:\WINDOWS\$NtServicePackUninstall$\fp4atxt.dll Object is locked skipped
C:\WINDOWS\$NtServicePackUninstall$\fp4autl.dll Object is locked skipped
C:\WINDOWS\$NtServicePackUninstall$\fp4avnb.dll Object is locked skipped
C:\WINDOWS\$NtServicePackUninstall$\fp4avss.dll Object is locked skipped
C:\WINDOWS\$NtServicePackUninstall$\fp4awebs.dll Object is locked skipped
C:\WINDOWS\$NtServicePackUninstall$\fp4awel.dll Object is locked skipped
C:\WINDOWS\$NtServicePackUninstall$\fp98sadm.exe Object is locked skipped
C:\WINDOWS\$NtServicePackUninstall$\fp98swin.exe Object is locked skipped
C:\WINDOWS\$NtServicePackUninstall$\fpadmcgi.exe Object is locked skipped
C:\WINDOWS\$NtServicePackUninstall$\fpadmdll.dll Object is locked skipped
C:\WINDOWS\$NtServicePackUninstall$\fpcount.exe Object is locked skipped
C:\WINDOWS\$NtServicePackUninstall$\fpencode.dll Object is locked skipped
C:\WINDOWS\$NtServicePackUninstall$\fpexedll.dll Object is locked skipped
C:\WINDOWS\$NtServicePackUninstall$\fpmmc.dll Object is locked skipped
C:\WINDOWS\$NtServicePackUninstall$\fpmmcsat.dll Object is locked skipped
C:\WINDOWS\$NtServicePackUninstall$\fpremadm.exe Object is locked skipped
C:\WINDOWS\$NtServicePackUninstall$\framebuf.dll Object is locked skipped
C:\WINDOWS\$NtServicePackUninstall$\framedyn.dll Object is locked skipped
C:\WINDOWS\$NtServicePackUninstall$\ftp.exe Object is locked skipped
C:\WINDOWS\$NtServicePackUninstall$\fxsapi.dll Object is locked skipped
C:\WINDOWS\$NtServicePackUninstall$\fxsclnt.exe Object is locked skipped
C:\WINDOWS\$NtServicePackUninstall$\fxscom.dll Object is locked skipped
C:\WINDOWS\$NtServicePackUninstall$\fxscomex.dll Object is locked skipped
C:\WINDOWS\$NtServicePackUninstall$\fxscover.exe Object is locked skipped
C:\WINDOWS\$NtServicePackUninstall$\fxsdrv.dll Object is locked skipped
C:\WINDOWS\$NtServicePackUninstall$\fxsevent.dll Object is locked skipped
C:\WINDOWS\$NtServicePackUninstall$\fxsext32.dll Object is locked skipped
C:\WINDOWS\$NtServicePackUninstall$\fxsmon.dll Object is locked skipped
C:\WINDOWS\$NtServicePackUninstall$\fxsocm.dll Object is locked skipped
C:\WINDOWS\$NtServicePackUninstall$\fxsocm.inf Object is locked skipped
C:\WINDOWS\$NtServicePackUninstall$\fxsperf.dll Object is locked skipped
C:\WINDOWS\$NtServicePackUninstall$\fxsres.dll Object is locked skipped
C:\WINDOWS\$NtServicePackUninstall$\fxsst.dll Object is locked skipped
C:\WINDOWS\$NtServicePackUninstall$\fxssvc.exe Object is locked skipped
C:\WINDOWS\$NtServicePackUninstall$\fxst30.dll Object is locked skipped
C:\WINDOWS\$NtServicePackUninstall$\fxstiff.dll Object is locked skipped
C:\WINDOWS\$NtServicePackUninstall$\fxsui.dll Object is locked skipped
C:\WINDOWS\$NtServicePackUninstall$\fxswzrd.dll Object is locked skipped
C:\WINDOWS\$NtServicePackUninstall$\fxsxp32.dll Object is locked skipped
C:\WINDOWS\$NtServicePackUninstall$\g400.inf Object is locked skipped
C:\WINDOWS\$NtServicePackUninstall$\gameenum.sys Object is locked skipped
C:\WINDOWS\$NtServicePackUninstall$\gdi32.dll Object is locked skipped
C:\WINDOWS\$NtServicePackUninstall$\georgia.ttf Object is locked skipped
C:\WINDOWS\$NtServicePackUninstall$\glu32.dll Object is locked skipped
C:\WINDOWS\$NtServicePackUninstall$\gpkrsrc.dll Object is locked skipped
C:\WINDOWS\$NtServicePackUninstall$\grpconv.exe Object is locked skipped
C:\WINDOWS\$NtServicePackUninstall$\guitrn.dll Object is locked skipped
C:\WINDOWS\$NtServicePackUninstall$\guitrn_a.dll Object is locked skipped
C:\WINDOWS\$NtServicePackUninstall$\h323.tsp Object is locked skipped
C:\WINDOWS\$NtServicePackUninstall$\h323cc.dll Object is locked skipped
C:\WINDOWS\$NtServicePackUninstall$\h323msp.dll Object is locked skipped
C:\WINDOWS\$NtServicePackUninstall$\hal.dll Object is locked skipped
C:\WINDOWS\$NtServicePackUninstall$\hardware.chm Object is locked skipped
C:\WINDOWS\$NtServicePackUninstall$\hccoin.dll Object is locked skipped
C:\WINDOWS\$NtServicePackUninstall$\hdwwiz.cpl Object is locked skipped
C:\WINDOWS\$NtServicePackUninstall$\helpctr.exe Object is locked skipped
C:\WINDOWS\$NtServicePackUninstall$\helpsvc.exe Object is locked skipped
C:\WINDOWS\$NtServicePackUninstall$\hh.exe Object is locked skipped
C:\WINDOWS\$NtServicePackUninstall$\hhctrl.ocx Object is locked skipped
C:\WINDOWS\$NtServicePackUninstall$\hhsetup.dll Object is locked skipped
C:\WINDOWS\$NtServicePackUninstall$\hid.dll Object is locked skipped
C:\WINDOWS\$NtServicePackUninstall$\hidclass.sys Object is locked skipped
C:\WINDOWS\$NtServicePackUninstall$\hidparse.sys Object is locked skipped
C:\WINDOWS\$NtServicePackUninstall$\hidphone.tsp Object is locked skipped
C:\WINDOWS\$NtServicePackUninstall$\hidserv.inf Object is locked skipped
C:\WINDOWS\$NtServicePackUninstall$\hmmapi.dll Object is locked skipped
C:\WINDOWS\$NtServicePackUninstall$\hnetcfg.dll Object is locked skipped
C:\WINDOWS\$NtServicePackUninstall$\hnetwiz.dll Object is locked skipped
C:\WINDOWS\$NtServicePackUninstall$\homepage.inf Object is locked skipped
C:\WINDOWS\$NtServicePackUninstall$\hostmib.dll Object is locked skipped
C:\WINDOWS\$NtServicePackUninstall$\hotplug.dll Object is locked skipped
C:\WINDOWS\$NtServicePackUninstall$\howto.chm Object is locked skipped
C:\WINDOWS\$NtServicePackUninstall$\hschelp.chm Object is locked skipped
C:\WINDOWS\$NtServicePackUninstall$\html32.cnv Object is locked skipped
C:\WINDOWS\$NtServicePackUninstall$\htui.dll Object is locked skipped
C:\WINDOWS\$NtServicePackUninstall$\hvzzlvdb.dat Object is locked skipped
C:\WINDOWS\$NtServicePackUninstall$\hypertrm.dll Object is locked skipped
C:\WINDOWS\$NtServicePackUninstall$\i1fbxfdb.zip Object is locked skipped
C:\WINDOWS\$NtServicePackUninstall$\i8042prt.sys Object is locked skipped
C:\WINDOWS\$NtServicePackUninstall$\i81xdnt5.dll Object is locked skipped
C:\WINDOWS\$NtServicePackUninstall$\i81xnt5.inf Object is locked skipped
C:\WINDOWS\$NtServicePackUninstall$\i81xnt5.sys Object is locked skipped
C:\WINDOWS\$NtServicePackUninstall$\i81xwfp0.inf Object is locked skipped
C:\WINDOWS\$NtServicePackUninstall$\i81xwfp1.inf Object is locked skipped
C:\WINDOWS\$NtServicePackUninstall$\i81xwfp2.inf Object is locked skipped
C:\WINDOWS\$NtServicePackUninstall$\i81xwfp3.inf Object is locked skipped
C:\WINDOWS\$NtServicePackUninstall$\i81xwfp4.inf Object is locked skipped
C:\WINDOWS\$NtServicePackUninstall$\i81xwtv0.inf Object is locked skipped
C:\WINDOWS\$NtServicePackUninstall$\i81xwtv1.inf Object is locked skipped
C:\WINDOWS\$NtServicePackUninstall$\i81xwtv2.inf Object is locked skipped
C:\WINDOWS\$NtServicePackUninstall$\i81xwtv3.inf Object is locked skipped
C:\WINDOWS\$NtServicePackUninstall$\i81xwtv4.inf Object is locked skipped
C:\WINDOWS\$NtServicePackUninstall$\iac25_32.ax Object is locked skipped
C:\WINDOWS\$NtServicePackUninstall$\iasrad.dll Object is locked skipped
C:\WINDOWS\$NtServicePackUninstall$\icaapi.dll Object is locked skipped
C:\WINDOWS\$NtServicePackUninstall$\iccvid.dll Object is locked skipped
C:\WINDOWS\$NtServicePackUninstall$\icm32.dll Object is locked skipped
C:\WINDOWS\$NtServicePackUninstall$\icmp.dll Object is locked skipped
C:\WINDOWS\$NtServicePackUninstall$\iconlib.dll Object is locked skipped
C:\WINDOWS\$NtServicePackUninstall$\ics.htm Object is locked skipped
C:\WINDOWS\$NtServicePackUninstall$\icsmgr.js Object is locked skipped
C:\WINDOWS\$NtServicePackUninstall$\icwconn.dll Object is locked skipped
C:\WINDOWS\$NtServicePackUninstall$\icwconn1.exe Object is locked skipped
C:\WINDOWS\$NtServicePackUninstall$\icwconn2.exe Object is locked skipped
C:\WINDOWS\$NtServicePackUninstall$\icwdial.dll Object is locked skipped
C:\WINDOWS\$NtServicePackUninstall$\icwdl.dll Object is locked skipped
C:\WINDOWS\$NtServicePackUninstall$\icwhelp.dll Object is locked skipped
C:\WINDOWS\$NtServicePackUninstall$\icwphbk.dll Object is locked skipped
C:\WINDOWS\$NtServicePackUninstall$\icwrmind.exe Object is locked skipped
C:\WINDOWS\$NtServicePackUninstall$\icwutil.dll Object is locked skipped
C:\WINDOWS\$NtServicePackUninstall$\idq.dll Object is locked skipped
C:\WINDOWS\$NtServicePackUninstall$\ie.inf Object is locked skipped
C:\WINDOWS\$NtServicePackUninstall$\ie4uinit.exe Object is locked skipped
C:\WINDOWS\$NtServicePackUninstall$\ieaccess.inf Object is locked skipped
C:\WINDOWS\$NtServicePackUninstall$\ieakeng.dll Object is locked skipped
C:\WINDOWS\$NtServicePackUninstall$\ieaksie.dll Object is locked skipped
C:\WINDOWS\$NtServicePackUninstall$\iedkcs32.dll Object is locked skipped
C:\WINDOWS\$NtServicePackUninstall$\iepeers.dll Object is locked skipped
C:\WINDOWS\$NtServicePackUninstall$\iernonce.dll Object is locked skipped
C:\WINDOWS\$NtServicePackUninstall$\iesetup.dll Object is locked skipped
C:\WINDOWS\$NtServicePackUninstall$\ieuinit.inf Object is locked skipped
C:\WINDOWS\$NtServicePackUninstall$\iexplore.chm Object is locked skipped
C:\WINDOWS\$NtServicePackUninstall$\iexplore.exe Object is locked skipped
C:\WINDOWS\$NtServicePackUninstall$\iexpress.exe Object is locked skipped
C:\WINDOWS\$NtServicePackUninstall$\ifmon.dll Object is locked skipped
C:\WINDOWS\$NtServicePackUninstall$\igmpagnt.dll Object is locked skipped
C:\WINDOWS\$NtServicePackUninstall$\iis.dll Object is locked skipped
C:\WINDOWS\$NtServicePackUninstall$\ils.dll Object is locked skipped
C:\WINDOWS\$NtServicePackUninstall$\imaadp32.acm Object is locked skipped
C:\WINDOWS\$NtServicePackUninstall$\imagehlp.dll Object is locked skipped
C:\WINDOWS\$NtServicePackUninstall$\imapi.exe Object is locked skipped
C:\WINDOWS\$NtServicePackUninstall$\imapi.sys Object is locked skipped
C:\WINDOWS\$NtServicePackUninstall$\imeshare.dll Object is locked skipped
C:\WINDOWS\$NtServicePackUninstall$\imgutil.dll Object is locked skipped
C:\WINDOWS\$NtServicePackUninstall$\imm32.dll Object is locked skipped
C:\WINDOWS\$NtServicePackUninstall$\ims.cat Object is locked skipped
C:\WINDOWS\$NtServicePackUninstall$\ims.inf Object is locked skipped
C:\WINDOWS\$NtServicePackUninstall$\inetcfg.dll Object is locked skipped
C:\WINDOWS\$NtServicePackUninstall$\inetcomm.dll Object is locked skipped
C:\WINDOWS\$NtServicePackUninstall$\inetcpl.cpl Object is locked skipped
C:\WINDOWS\$NtServicePackUninstall$\inetmib1.dll Object is locked skipped
C:\WINDOWS\$NtServicePackUninstall$\inetpp.dll Object is locked skipped
C:\WINDOWS\$NtServicePackUninstall$\inetppui.dll Object is locked skipped
C:\WINDOWS\$NtServicePackUninstall$\inetpref.xml Object is locked skipped
C:\WINDOWS\$NtServicePackUninstall$\inetres.dll Object is locked skipped
C:\WINDOWS\$NtServicePackUninstall$\inetwiz.exe Object is locked skipped
C:\WINDOWS\$NtServicePackUninstall$\infrared.chm Object is locked skipped
C:\WINDOWS\$NtServicePackUninstall$\initpki.dll Object is locked skipped
C:\WINDOWS\$NtServicePackUninstall$\input.chm Object is locked skipped
C:\WINDOWS\$NtServicePackUninstall$\input.dll Object is locked skipped
C:\WINDOWS\$NtServicePackUninstall$\input.hlp Object is locked skipped
C:\WINDOWS\$NtServicePackUninstall$\input.inf Object is locked skipped
C:\WINDOWS\$NtServicePackUninstall$\inseng.dll Object is locked skipped
C:\WINDOWS\$NtServicePackUninstall$\instcat.sql Object is locked skipped
C:\WINDOWS\$NtServicePackUninstall$\intelide.sys Object is locked skipped
C:\WINDOWS\$NtServicePackUninstall$\intl.cpl Object is locked skipped
C:\WINDOWS\$NtServicePackUninstall$\intl.inf Object is locked skipped
C:\WINDOWS\$NtServicePackUninstall$\ipconf.tsp Object is locked skipped
C:\WINDOWS\$NtServicePackUninstall$\ipconfig.exe Object is locked skipped
C:\WINDOWS\$NtServicePackUninstall$\iphlpapi.dll Object is locked skipped
C:\WINDOWS\$NtServicePackUninstall$\ipinip.sys Object is locked skipped
C:\WINDOWS\$NtServicePackUninstall$\ipnat.sys Object is locked skipped
C:\WINDOWS\$NtServicePackUninstall$\ipnathlp.dll Object is locked skipped
C:\WINDOWS\$NtServicePackUninstall$\ippromon.dll Object is locked skipped
C:\WINDOWS\$NtServicePackUninstall$\ipp_0001.asp Object is locked skipped
C:\WINDOWS\$NtServicePackUninstall$\ipp_0002.asp Object is locked skipped
C:\WINDOWS\$NtServicePackUninstall$\ipp_0004.asp Object is locked skipped
C:\WINDOWS\$NtServicePackUninstall$\ipp_0005.asp Object is locked skipped
C:\WINDOWS\$NtServicePackUninstall$\ipp_0006.asp Object is locked skipped
C:\WINDOWS\$NtServicePackUninstall$\ipp_0007.asp Object is locked skipped
C:\WINDOWS\$NtServicePackUninstall$\ipp_0008.asp Object is locked skipped
C:\WINDOWS\$NtServicePackUninstall$\ipp_0009.asp Object is locked skipped
C:\WINDOWS\$NtServicePackUninstall$\ipp_0010.asp Object is locked skipped
C:\WINDOWS\$NtServicePackUninstall$\ipp_0011.asp Object is locked skipped
C:\WINDOWS\$NtServicePackUninstall$\ipp_0012.asp Object is locked skipped
C:\WINDOWS\$NtServicePackUninstall$\ipp_0013.asp Object is locked skipped
C:\WINDOWS\$NtServicePackUninstall$\ipp_0014.asp Object is locked skipped
C:\WINDOWS\$NtServicePackUninstall$\ipp_0016.asp Object is locked skipped
C:\WINDOWS\$NtServicePackUninstall$\ipp_util.inc Object is locked skipped
C:\WINDOWS\$NtServicePackUninstall$\iprip.dll Object is locked skipped
C:\WINDOWS\$NtServicePackUninstall$\ipsec.sys Object is locked skipped
C:\WINDOWS\$NtServicePackUninstall$\ipsecconcepts.chm Object is locked skipped
C:\WINDOWS\$NtServicePackUninstall$\ipsecsnp.dll Object is locked skipped
C:\WINDOWS\$NtServicePackUninstall$\ipsecsvc.dll Object is locked skipped
C:\WINDOWS\$NtServicePackUninstall$\ipsmsnap.dll Object is locked skipped
C:\WINDOWS\$NtServicePackUninstall$\ipv6.chm Object is locked skipped
C:\WINDOWS\$NtServicePackUninstall$\ipv6.exe Object is locked skipped
C:\WINDOWS\$NtServicePackUninstall$\ipv6mon.dll Object is locked skipped
C:\WINDOWS\$NtServicePackUninstall$\ipxroute.exe Object is locked skipped
C:\WINDOWS\$NtServicePackUninstall$\ir41_32.ax Object is locked skipped
C:\WINDOWS\$NtServicePackUninstall$\ir41_qc.dll Object is locked skipped
C:\WINDOWS\$NtServicePackUninstall$\ir41_qcx.dll Object is locked skipped
C:\WINDOWS\$NtServicePackUninstall$\ir50_32.dll Object is locked skipped
C:\WINDOWS\$NtServicePackUninstall$\ir50_qc.dll Object is locked skipped
C:\WINDOWS\$NtServicePackUninstall$\ir50_qcx.dll Object is locked skipped
C:\WINDOWS\$NtServicePackUninstall$\irenum.sys Object is locked skipped
C:\WINDOWS\$NtServicePackUninstall$\isign32.dll Object is locked skipped
C:\WINDOWS\$NtServicePackUninstall$\isrdbg32.dll Object is locked skipped
C:\WINDOWS\$NtServicePackUninstall$\itircl.dll Object is locked skipped
C:\WINDOWS\$NtServicePackUninstall$\itss.dll Object is locked skipped
C:\WINDOWS\$NtServicePackUninstall$\iuctl.dll Object is locked skipped
C:\WINDOWS\$NtServicePackUninstall$\iuengine.dll Object is locked skipped
C:\WINDOWS\$NtServicePackUninstall$\ivfsrc.ax Object is locked skipped
C:\WINDOWS\$NtServicePackUninstall$\ixsso.dll Object is locked skipped
C:\WINDOWS\$NtServicePackUninstall$\iyuv_32.dll Object is locked skipped
C:\WINDOWS\$NtServicePackUninstall$\joy.cpl Object is locked skipped
C:\WINDOWS\$NtServicePackUninstall$\jrbz9ztr.zip Object is locked skipped
C:\WINDOWS\$NtServicePackUninstall$\jscript.dll Object is locked skipped
C:\WINDOWS\$NtServicePackUninstall$\jsproxy.dll Object is locked skipped
C:\WINDOWS\$NtServicePackUninstall$\kbdclass.sys Object is locked skipped
C:\WINDOWS\$NtServicePackUninstall$\kd1394.dll Object is locked skipped
C:\WINDOWS\$NtServicePackUninstall$\kerberos.dll Object is locked skipped
C:\WINDOWS\$NtServicePackUninstall$\kernel32.dll Object is locked skipped
C:\WINDOWS\$NtServicePackUninstall$\keyboard.inf Object is locked skipped
C:\WINDOWS\$NtServicePackUninstall$\keyboard.sys Object is locked skipped
C:\WINDOWS\$NtServicePackUninstall$\keymgr.dll Object is locked skipped
C:\WINDOWS\$NtServicePackUninstall$\kmddsp.tsp Object is locked skipped
C:\WINDOWS\$NtServicePackUninstall$\kmixer.sys Object is locked skipped
C:\WINDOWS\$NtServicePackUninstall$\krnl386.exe Object is locked skipped
C:\WINDOWS\$NtServicePackUninstall$\krnlprov.dll Object is locked skipped
C:\WINDOWS\$NtServicePackUninstall$\ks.inf Object is locked skipped
C:\WINDOWS\$NtServicePackUninstall$\ks.sys Object is locked skipped
C:\WINDOWS\$NtServicePackUninstall$\kscaptur.inf Object is locked skipped
C:\WINDOWS\$NtServicePackUninstall$\ksecdd.sys Object is locked skipped
C:\WINDOWS\$NtServicePackUninstall$\ksfilter.inf Object is locked skipped
C:\WINDOWS\$NtServicePackUninstall$\ksproxy.ax Object is locked skipped
C:\WINDOWS\$NtServicePackUninstall$\kstvtune.ax Object is locked skipped
C:\WINDOWS\$NtServicePackUninstall$\ksuser.dll Object is locked skipped
C:\WINDOWS\$NtServicePackUninstall$\kswdmcap.ax Object is locked skipped
C:\WINDOWS\$NtServicePackUninstall$\ksxbar.ax Object is locked skipped
C:\WINDOWS\$NtServicePackUninstall$\l3codeca.acm Object is locked skipped
C:\WINDOWS\$NtServicePackUninstall$\langbar.chm Object is locked skipped
C:\WINDOWS\$NtServicePackUninstall$\laprxy.dll Object is locked skipped
C:\WINDOWS\$NtServicePackUninstall$\layout.inf Object is locked skipped
C:\WINDOWS\$NtServicePackUninstall$\lcladvd.xml Object is locked skipped
C:\WINDOWS\$NtServicePackUninstall$\lcldocs.xml Object is locked skipped
C:\WINDOWS\$NtServicePackUninstall$\lclmm.xml Object is locked skipped
C:\WINDOWS\$NtServicePackUninstall$\licdll.dll Object is locked skipped
C:\WINDOWS\$NtServicePackUninstall$\license.chm Object is locked skipped
C:\WINDOWS\$NtServicePackUninstall$\licmgr10.dll Object is locked skipped
C:\WINDOWS\$NtServicePackUninstall$\licwmi.dll Object is locked skipped
C:\WINDOWS\$NtServicePackUninstall$\licwmi.mof Object is locked skipped
C:\WINDOWS\$NtServicePackUninstall$\linkinfo.dll Object is locked skipped
C:\WINDOWS\$NtServicePackUninstall$\lmhsvc.dll Object is locked skipped
C:\WINDOWS\$NtServicePackUninstall$\lmmib2.dll Object is locked skipped
C:\WINDOWS\$NtServicePackUninstall$\lmrt.dll Object is locked skipped
C:\WINDOWS\$NtServicePackUninstall$\loadperf.dll Object is locked skipped
C:\WINDOWS\$NtServicePackUninstall$\locale.nls Object is locked skipped
C:\WINDOWS\$NtServicePackUninstall$\localsec.dll Object is locked skipped
C:\WINDOWS\$NtServicePackUninstall$\localspl.dll Object is locked skipped
C:\WINDOWS\$NtServicePackUninstall$\localui.dll Object is locked skipped
C:\WINDOWS\$NtServicePackUninstall$\locator.exe Object is locked skipped
C:\WINDOWS\$NtServicePackUninstall$\log.dll Object is locked skipped
C:\WINDOWS\$NtServicePackUninstall$\logagent.exe Object is locked skipped
C:\WINDOWS\$NtServicePackUninstall$\logon.scr Object is locked skipped
C:\WINDOWS\$NtServicePackUninstall$\logonui.exe Object is locked skipped
C:\WINDOWS\$NtServicePackUninstall$\lpdsvc.dll Object is locked skipped
C:\WINDOWS\$NtServicePackUninstall$\lpk.dll Object is locked skipped
C:\WINDOWS\$NtServicePackUninstall$\lprhelp.dll Object is locked skipped
C:\WINDOWS\$NtServicePackUninstall$\lprmon.dll Object is locked skipped
C:\WINDOWS\$NtServicePackUninstall$\lrh31ftv.dat Object is locked skipped
C:\WINDOWS\$NtServicePackUninstall$\lrh31ftv.zip Object is locked skipped
C:\WINDOWS\$NtServicePackUninstall$\lsasrv.dll Object is locked skipped
C:\WINDOWS\$NtServicePackUninstall$\lsass.exe Object is locked skipped
C:\WINDOWS\$NtServicePackUninstall$\luna.msstyles Object is locked skipped
C:\WINDOWS\$NtServicePackUninstall$\luna.mst Object is locked skipped
C:\WINDOWS\$NtServicePackUninstall$\lxaesdrv.bud Object is locked skipped

#9 Master Luke

Master Luke

    New Member

  • Authentic Member
  • Pip
  • 8 posts

Posted 20 August 2007 - 03:05 PM

LOGFILES: (PART TWO) Second Part of Kapersky Scan from last night: :\WINDOWS\$NtServicePackUninstall$\machine.inf Object is locked skipped C:\WINDOWS\$NtServicePackUninstall$\magnify.exe Object is locked skipped C:\WINDOWS\$NtServicePackUninstall$\makecab.exe Object is locked skipped C:\WINDOWS\$NtServicePackUninstall$\mcastmib.dll Object is locked skipped C:\WINDOWS\$NtServicePackUninstall$\mchgr.inf Object is locked skipped C:\WINDOWS\$NtServicePackUninstall$\mciavi32.dll Object is locked skipped C:\WINDOWS\$NtServicePackUninstall$\mciqtz32.dll Object is locked skipped C:\WINDOWS\$NtServicePackUninstall$\mciseq.dll Object is locked skipped C:\WINDOWS\$NtServicePackUninstall$\mciwave.dll Object is locked skipped C:\WINDOWS\$NtServicePackUninstall$\mdac.inf Object is locked skipped C:\WINDOWS\$NtServicePackUninstall$\mdmetech.inf Object is locked skipped C:\WINDOWS\$NtServicePackUninstall$\mdminst.dll Object is locked skipped C:\WINDOWS\$NtServicePackUninstall$\mdmirmdm.inf Object is locked skipped C:\WINDOWS\$NtServicePackUninstall$\mdmlt3.inf Object is locked skipped C:\WINDOWS\$NtServicePackUninstall$\mdmrpci.inf Object is locked skipped C:\WINDOWS\$NtServicePackUninstall$\mdmsuprv.inf Object is locked skipped C:\WINDOWS\$NtServicePackUninstall$\mf.sys Object is locked skipped C:\WINDOWS\$NtServicePackUninstall$\mf3216.dll Object is locked skipped C:\WINDOWS\$NtServicePackUninstall$\mfc42.dll Object is locked skipped C:\WINDOWS\$NtServicePackUninstall$\mfc42u.dll Object is locked skipped C:\WINDOWS\$NtServicePackUninstall$\mfcsubs.dll Object is locked skipped C:\WINDOWS\$NtServicePackUninstall$\mgmtapi.dll Object is locked skipped C:\WINDOWS\$NtServicePackUninstall$\micross.ttf Object is locked skipped C:\WINDOWS\$NtServicePackUninstall$\midimap.dll Object is locked skipped C:\WINDOWS\$NtServicePackUninstall$\migapp.inf Object is locked skipped C:\WINDOWS\$NtServicePackUninstall$\migip.dun Object is locked skipped C:\WINDOWS\$NtServicePackUninstall$\migism.dll Object is locked skipped C:\WINDOWS\$NtServicePackUninstall$\migism.inf Object is locked skipped C:\WINDOWS\$NtServicePackUninstall$\migism_a.dll Object is locked skipped C:\WINDOWS\$NtServicePackUninstall$\miglibnt.dll Object is locked skipped C:\WINDOWS\$NtServicePackUninstall$\migload.exe Object is locked skipped C:\WINDOWS\$NtServicePackUninstall$\migrate.js Object is locked skipped C:\WINDOWS\$NtServicePackUninstall$\migrate.obe Object is locked skipped C:\WINDOWS\$NtServicePackUninstall$\migregdb.exe Object is locked skipped C:\WINDOWS\$NtServicePackUninstall$\migsys.inf Object is locked skipped C:\WINDOWS\$NtServicePackUninstall$\miguser.inf Object is locked skipped C:\WINDOWS\$NtServicePackUninstall$\migwiz.exe Object is locked skipped C:\WINDOWS\$NtServicePackUninstall$\migwiz.inf Object is locked skipped C:\WINDOWS\$NtServicePackUninstall$\migwiz_a.exe Object is locked skipped C:\WINDOWS\$NtServicePackUninstall$\misc.chm Object is locked skipped C:\WINDOWS\$NtServicePackUninstall$\mlang.dll Object is locked skipped C:\WINDOWS\$NtServicePackUninstall$\mmc.exe Object is locked skipped C:\WINDOWS\$NtServicePackUninstall$\mmcbase.dll Object is locked skipped C:\WINDOWS\$NtServicePackUninstall$\mmcndmgr.dll Object is locked skipped C:\WINDOWS\$NtServicePackUninstall$\mmcshext.dll Object is locked skipped C:\WINDOWS\$NtServicePackUninstall$\mmfutil.dll Object is locked skipped C:\WINDOWS\$NtServicePackUninstall$\mmsys.cpl Object is locked skipped C:\WINDOWS\$NtServicePackUninstall$\mmsystem.dll Object is locked skipped C:\WINDOWS\$NtServicePackUninstall$\mnmdd.dll Object is locked skipped C:\WINDOWS\$NtServicePackUninstall$\mnmsrvc.exe Object is locked skipped C:\WINDOWS\$NtServicePackUninstall$\mobsync.dll Object is locked skipped C:\WINDOWS\$NtServicePackUninstall$\mobsync.exe Object is locked skipped C:\WINDOWS\$NtServicePackUninstall$\mode.chm Object is locked skipped C:\WINDOWS\$NtServicePackUninstall$\modem.sys Object is locked skipped C:\WINDOWS\$NtServicePackUninstall$\modemui.dll Object is locked skipped C:\WINDOWS\$NtServicePackUninstall$\mofcomp.exe Object is locked skipped C:\WINDOWS\$NtServicePackUninstall$\mofd.dll Object is locked skipped C:\WINDOWS\$NtServicePackUninstall$\moricons.dll Object is locked skipped C:\WINDOWS\$NtServicePackUninstall$\mouclass.sys Object is locked skipped C:\WINDOWS\$NtServicePackUninstall$\mountmgr.sys Object is locked skipped C:\WINDOWS\$NtServicePackUninstall$\moviemk.chm Object is locked skipped C:\WINDOWS\$NtServicePackUninstall$\moviemk.exe Object is locked skipped C:\WINDOWS\$NtServicePackUninstall$\moviemk.inf Object is locked skipped C:\WINDOWS\$NtServicePackUninstall$\mpe.inf Object is locked skipped C:\WINDOWS\$NtServicePackUninstall$\mpg2splt.ax Object is locked skipped C:\WINDOWS\$NtServicePackUninstall$\mpg4dmod.dll Object is locked skipped C:\WINDOWS\$NtServicePackUninstall$\mpg4ds32.ax Object is locked skipped C:\WINDOWS\$NtServicePackUninstall$\mplay32.exe Object is locked skipped C:\WINDOWS\$NtServicePackUninstall$\mplayer2.exe Object is locked skipped C:\WINDOWS\$NtServicePackUninstall$\mplayer2.inf Object is locked skipped C:\WINDOWS\$NtServicePackUninstall$\mpr.dll Object is locked skipped C:\WINDOWS\$NtServicePackUninstall$\mprapi.dll Object is locked skipped C:\WINDOWS\$NtServicePackUninstall$\mrxdav.sys Object is locked skipped C:\WINDOWS\$NtServicePackUninstall$\mrxsmb.sys Object is locked skipped C:\WINDOWS\$NtServicePackUninstall$\msacm32.dll Object is locked skipped C:\WINDOWS\$NtServicePackUninstall$\msadce.dll Object is locked skipped C:\WINDOWS\$NtServicePackUninstall$\msadcer.dll Object is locked skipped C:\WINDOWS\$NtServicePackUninstall$\msadcf.dll Object is locked skipped C:\WINDOWS\$NtServicePackUninstall$\msadcfr.dll Object is locked skipped C:\WINDOWS\$NtServicePackUninstall$\msadco.dll Object is locked skipped C:\WINDOWS\$NtServicePackUninstall$\msadcor.dll Object is locked skipped C:\WINDOWS\$NtServicePackUninstall$\msadcs.dll Object is locked skipped C:\WINDOWS\$NtServicePackUninstall$\msadds.dll Object is locked skipped C:\WINDOWS\$NtServicePackUninstall$\msadds32.ax Object is locked skipped C:\WINDOWS\$NtServicePackUninstall$\msaddsr.dll Object is locked skipped C:\WINDOWS\$NtServicePackUninstall$\msader15.dll Object is locked skipped C:\WINDOWS\$NtServicePackUninstall$\msado15.dll Object is locked skipped C:\WINDOWS\$NtServicePackUninstall$\msado20.tlb Object is locked skipped C:\WINDOWS\$NtServicePackUninstall$\msado21.tlb Object is locked skipped C:\WINDOWS\$NtServicePackUninstall$\msado25.tlb Object is locked skipped C:\WINDOWS\$NtServicePackUninstall$\msado26.tlb Object is locked skipped C:\WINDOWS\$NtServicePackUninstall$\msadomd.dll Object is locked skipped C:\WINDOWS\$NtServicePackUninstall$\msador15.dll Object is locked skipped C:\WINDOWS\$NtServicePackUninstall$\msadox.dll Object is locked skipped C:\WINDOWS\$NtServicePackUninstall$\msadp32.acm Object is locked skipped C:\WINDOWS\$NtServicePackUninstall$\msadrh15.dll Object is locked skipped C:\WINDOWS\$NtServicePackUninstall$\msafd.dll Object is locked skipped C:\WINDOWS\$NtServicePackUninstall$\msapsspc.dll Object is locked skipped C:\WINDOWS\$NtServicePackUninstall$\msasn1.dll Object is locked skipped C:\WINDOWS\$NtServicePackUninstall$\msaud32.acm Object is locked skipped C:\WINDOWS\$NtServicePackUninstall$\mscandui.dll Object is locked skipped C:\WINDOWS\$NtServicePackUninstall$\mscms.dll Object is locked skipped C:\WINDOWS\$NtServicePackUninstall$\msconf.dll Object is locked skipped C:\WINDOWS\$NtServicePackUninstall$\msconfig.exe Object is locked skipped C:\WINDOWS\$NtServicePackUninstall$\msconv97.dll Object is locked skipped C:\WINDOWS\$NtServicePackUninstall$\mscpx32r.dll Object is locked skipped C:\WINDOWS\$NtServicePackUninstall$\mscpxl32.dll Object is locked skipped C:\WINDOWS\$NtServicePackUninstall$\msctf.dll Object is locked skipped C:\WINDOWS\$NtServicePackUninstall$\msctfp.dll Object is locked skipped C:\WINDOWS\$NtServicePackUninstall$\msdadc.dll Object is locked skipped C:\WINDOWS\$NtServicePackUninstall$\msdaenum.dll Object is locked skipped C:\WINDOWS\$NtServicePackUninstall$\msdaer.dll Object is locked skipped C:\WINDOWS\$NtServicePackUninstall$\msdaipp.dll Object is locked skipped C:\WINDOWS\$NtServicePackUninstall$\msdaora.dll Object is locked skipped C:\WINDOWS\$NtServicePackUninstall$\msdaorar.dll Object is locked skipped C:\WINDOWS\$NtServicePackUninstall$\msdaosp.dll Object is locked skipped C:\WINDOWS\$NtServicePackUninstall$\msdaprsr.dll Object is locked skipped C:\WINDOWS\$NtServicePackUninstall$\msdaprst.dll Object is locked skipped C:\WINDOWS\$NtServicePackUninstall$\msdaps.dll Object is locked skipped C:\WINDOWS\$NtServicePackUninstall$\msdarem.dll Object is locked skipped C:\WINDOWS\$NtServicePackUninstall$\msdaremr.dll Object is locked skipped C:\WINDOWS\$NtServicePackUninstall$\msdart.dll Object is locked skipped C:\WINDOWS\$NtServicePackUninstall$\msdasc.dll Object is locked skipped C:\WINDOWS\$NtServicePackUninstall$\msdasql.dll Object is locked skipped C:\WINDOWS\$NtServicePackUninstall$\msdasqlr.dll Object is locked skipped C:\WINDOWS\$NtServicePackUninstall$\msdatl3.dll Object is locked skipped C:\WINDOWS\$NtServicePackUninstall$\msdatsrc.tlb Object is locked skipped C:\WINDOWS\$NtServicePackUninstall$\msdatt.dll Object is locked skipped C:\WINDOWS\$NtServicePackUninstall$\msdaurl.dll Object is locked skipped C:\WINDOWS\$NtServicePackUninstall$\msdfmap.dll Object is locked skipped C:\WINDOWS\$NtServicePackUninstall$\msdmo.dll Object is locked skipped C:\WINDOWS\$NtServicePackUninstall$\msdtc.exe Object is locked skipped C:\WINDOWS\$NtServicePackUninstall$\msdtclog.dll Object is locked skipped C:\WINDOWS\$NtServicePackUninstall$\msdtcprx.dll Object is locked skipped C:\WINDOWS\$NtServicePackUninstall$\msdtctm.dll Object is locked skipped C:\WINDOWS\$NtServicePackUninstall$\msdtcuiu.dll Object is locked skipped C:\WINDOWS\$NtServicePackUninstall$\msdvdopt.dll Object is locked skipped C:\WINDOWS\$NtServicePackUninstall$\msdxm.ocx Object is locked skipped C:\WINDOWS\$NtServicePackUninstall$\msdxmlc.dll Object is locked skipped C:\WINDOWS\$NtServicePackUninstall$\msexch40.dll Object is locked skipped C:\WINDOWS\$NtServicePackUninstall$\msexcl40.dll Object is locked skipped C:\WINDOWS\$NtServicePackUninstall$\msfs.sys Object is locked skipped C:\WINDOWS\$NtServicePackUninstall$\msgina.dll Object is locked skipped C:\WINDOWS\$NtServicePackUninstall$\msgpc.sys Object is locked skipped C:\WINDOWS\$NtServicePackUninstall$\msgr3en.dll Object is locked skipped C:\WINDOWS\$NtServicePackUninstall$\msgrocm.dll Object is locked skipped C:\WINDOWS\$NtServicePackUninstall$\msgsc.dll Object is locked skipped C:\WINDOWS\$NtServicePackUninstall$\msgslang.dll Object is locked skipped C:\WINDOWS\$NtServicePackUninstall$\msgsvc.dll Object is locked skipped C:\WINDOWS\$NtServicePackUninstall$\msh261.drv Object is locked skipped C:\WINDOWS\$NtServicePackUninstall$\msh263.drv Object is locked skipped C:\WINDOWS\$NtServicePackUninstall$\mshdc.inf Object is locked skipped C:\WINDOWS\$NtServicePackUninstall$\mshta.exe Object is locked skipped C:\WINDOWS\$NtServicePackUninstall$\mshtml.dll Object is locked skipped C:\WINDOWS\$NtServicePackUninstall$\mshtml.tlb Object is locked skipped C:\WINDOWS\$NtServicePackUninstall$\mshtmled.dll Object is locked skipped C:\WINDOWS\$NtServicePackUninstall$\mshtmler.dll Object is locked skipped C:\WINDOWS\$NtServicePackUninstall$\msi.dll Object is locked skipped C:\WINDOWS\$NtServicePackUninstall$\msident.dll Object is locked skipped C:\WINDOWS\$NtServicePackUninstall$\msidle.dll Object is locked skipped C:\WINDOWS\$NtServicePackUninstall$\msieftp.dll Object is locked skipped C:\WINDOWS\$NtServicePackUninstall$\msiexec.exe Object is locked skipped C:\WINDOWS\$NtServicePackUninstall$\msihnd.dll Object is locked skipped C:\WINDOWS\$NtServicePackUninstall$\msimain.sdb Object is locked skipped C:\WINDOWS\$NtServicePackUninstall$\msimg32.dll Object is locked skipped C:\WINDOWS\$NtServicePackUninstall$\msimn.exe Object is locked skipped C:\WINDOWS\$NtServicePackUninstall$\msimsg.dll Object is locked skipped C:\WINDOWS\$NtServicePackUninstall$\msimtf.dll Object is locked skipped C:\WINDOWS\$NtServicePackUninstall$\msinfo.dll Object is locked skipped C:\WINDOWS\$NtServicePackUninstall$\msinfo32.chm Object is locked skipped C:\WINDOWS\$NtServicePackUninstall$\msiregmv.exe Object is locked skipped C:\WINDOWS\$NtServicePackUninstall$\msisip.dll Object is locked skipped C:\WINDOWS\$NtServicePackUninstall$\msjet40.dll Object is locked skipped C:\WINDOWS\$NtServicePackUninstall$\msjetol1.dll Object is locked skipped C:\WINDOWS\$NtServicePackUninstall$\msjetoledb40.dll Object is locked skipped C:\WINDOWS\$NtServicePackUninstall$\msjint40.dll Object is locked skipped C:\WINDOWS\$NtServicePackUninstall$\msjro.dll Object is locked skipped C:\WINDOWS\$NtServicePackUninstall$\msjter40.dll Object is locked skipped C:\WINDOWS\$NtServicePackUninstall$\msjtes40.dll Object is locked skipped C:\WINDOWS\$NtServicePackUninstall$\mskssrv.sys Object is locked skipped C:\WINDOWS\$NtServicePackUninstall$\mslbui.dll Object is locked skipped C:\WINDOWS\$NtServicePackUninstall$\msltus40.dll Object is locked skipped C:\WINDOWS\$NtServicePackUninstall$\mslwvtts.dll Object is locked skipped C:\WINDOWS\$NtServicePackUninstall$\msmsgs.cat Object is locked skipped C:\WINDOWS\$NtServicePackUninstall$\msmsgs.exe Object is locked skipped C:\WINDOWS\$NtServicePackUninstall$\msmsgs.inf Object is locked skipped C:\WINDOWS\$NtServicePackUninstall$\msn7.cat Object is locked skipped C:\WINDOWS\$NtServicePackUninstall$\msn9.cat Object is locked skipped C:\WINDOWS\$NtServicePackUninstall$\msnetmtg.inf Object is locked skipped C:\WINDOWS\$NtServicePackUninstall$\msnetobj.dll Object is locked skipped C:\WINDOWS\$NtServicePackUninstall$\msnmsn.inf Object is locked skipped C:\WINDOWS\$NtServicePackUninstall$\msnsspc.dll Object is locked skipped C:\WINDOWS\$NtServicePackUninstall$\msobcomm.dll Object is locked skipped C:\WINDOWS\$NtServicePackUninstall$\msobdl.dll Object is locked skipped C:\WINDOWS\$NtServicePackUninstall$\msobe.isp Object is locked skipped C:\WINDOWS\$NtServicePackUninstall$\msobmain.dll Object is locked skipped C:\WINDOWS\$NtServicePackUninstall$\msobshel.dll Object is locked skipped C:\WINDOWS\$NtServicePackUninstall$\msobshel.htm Object is locked skipped C:\WINDOWS\$NtServicePackUninstall$\msobweb.dll Object is locked skipped C:\WINDOWS\$NtServicePackUninstall$\msoe.chm Object is locked skipped C:\WINDOWS\$NtServicePackUninstall$\msoe.dll Object is locked skipped C:\WINDOWS\$NtServicePackUninstall$\msoe50.inf Object is locked skipped C:\WINDOWS\$NtServicePackUninstall$\msoeacct.dll Object is locked skipped C:\WINDOWS\$NtServicePackUninstall$\msoeres.dll Object is locked skipped C:\WINDOWS\$NtServicePackUninstall$\msoert2.dll Object is locked skipped C:\WINDOWS\$NtServicePackUninstall$\msorc32r.dll Object is locked skipped C:\WINDOWS\$NtServicePackUninstall$\msorcl32.dll Object is locked skipped C:\WINDOWS\$NtServicePackUninstall$\mspaint.exe Object is locked skipped C:\WINDOWS\$NtServicePackUninstall$\mspatcha.dll Object is locked skipped C:\WINDOWS\$NtServicePackUninstall$\mspbde40.dll Object is locked skipped C:\WINDOWS\$NtServicePackUninstall$\mspclock.sys Object is locked skipped C:\WINDOWS\$NtServicePackUninstall$\mspmsp.dll Object is locked skipped C:\WINDOWS\$NtServicePackUninstall$\mspmspsv.dll Object is locked skipped C:\WINDOWS\$NtServicePackUninstall$\mspqm.sys Object is locked skipped C:\WINDOWS\$NtServicePackUninstall$\msprivs.dll Object is locked skipped C:\WINDOWS\$NtServicePackUninstall$\msrating.dll Object is locked skipped C:\WINDOWS\$NtServicePackUninstall$\msrd2x40.dll Object is locked skipped C:\WINDOWS\$NtServicePackUninstall$\msrd3x40.dll Object is locked skipped C:\WINDOWS\$NtServicePackUninstall$\msrepl40.dll Object is locked skipped C:\WINDOWS\$NtServicePackUninstall$\msrle32.dll Object is locked skipped C:\WINDOWS\$NtServicePackUninstall$\msscds32.ax Object is locked skipped C:\WINDOWS\$NtServicePackUninstall$\msscp.dll Object is locked skipped C:\WINDOWS\$NtServicePackUninstall$\msscript.ocx Object is locked skipped C:\WINDOWS\$NtServicePackUninstall$\mst120.dll Object is locked skipped C:\WINDOWS\$NtServicePackUninstall$\mst123.dll Object is locked skipped C:\WINDOWS\$NtServicePackUninstall$\mstape.inf Object is locked skipped C:\WINDOWS\$NtServicePackUninstall$\mstask.chm Object is locked skipped C:\WINDOWS\$NtServicePackUninstall$\mstask.dll Object is locked skipped C:\WINDOWS\$NtServicePackUninstall$\mstext40.dll Object is locked skipped C:\WINDOWS\$NtServicePackUninstall$\mstime.dll Object is locked skipped C:\WINDOWS\$NtServicePackUninstall$\mstinit.exe Object is locked skipped C:\WINDOWS\$NtServicePackUninstall$\mstlsapi.dll Object is locked skipped C:\WINDOWS\$NtServicePackUninstall$\mstsc.chm Object is locked skipped C:\WINDOWS\$NtServicePackUninstall$\mstsc.exe Object is locked skipped C:\WINDOWS\$NtServicePackUninstall$\mstscax.dll Object is locked skipped C:\WINDOWS\$NtServicePackUninstall$\mstsweb.cat Object is locked skipped C:\WINDOWS\$NtServicePackUninstall$\mstvca.dll Object is locked skipped C:\WINDOWS\$NtServicePackUninstall$\mstvgs.dll Object is locked skipped C:\WINDOWS\$NtServicePackUninstall$\msutb.dll Object is locked skipped C:\WINDOWS\$NtServicePackUninstall$\msv1_0.dll Object is locked skipped C:\WINDOWS\$NtServicePackUninstall$\msvbvm60.dll Object is locked skipped C:\WINDOWS\$NtServicePackUninstall$\msvcirt.dll Object is locked skipped C:\WINDOWS\$NtServicePackUninstall$\msvcp60.dll Object is locked skipped C:\WINDOWS\$NtServicePackUninstall$\msvcrt.dll Object is locked skipped C:\WINDOWS\$NtServicePackUninstall$\msvcrt40.dll Object is locked skipped C:\WINDOWS\$NtServicePackUninstall$\msvfw32.dll Object is locked skipped C:\WINDOWS\$NtServicePackUninstall$\msvidctl.dll Object is locked skipped C:\WINDOWS\$NtServicePackUninstall$\msw3prt.dll Object is locked skipped C:\WINDOWS\$NtServicePackUninstall$\mswdat10.dll Object is locked skipped C:\WINDOWS\$NtServicePackUninstall$\mswebdvd.dll Object is locked skipped C:\WINDOWS\$NtServicePackUninstall$\mswmdm.dll Object is locked skipped C:\WINDOWS\$NtServicePackUninstall$\mswsock.dll Object is locked skipped C:\WINDOWS\$NtServicePackUninstall$\mswstr10.dll Object is locked skipped C:\WINDOWS\$NtServicePackUninstall$\msxactps.dll Object is locked skipped C:\WINDOWS\$NtServicePackUninstall$\msxbde40.dll Object is locked skipped C:\WINDOWS\$NtServicePackUninstall$\msxml.dll Object is locked skipped C:\WINDOWS\$NtServicePackUninstall$\msxml2.dll Object is locked skipped C:\WINDOWS\$NtServicePackUninstall$\msxml3.dll Object is locked skipped C:\WINDOWS\$NtServicePackUninstall$\msyuv.dll Object is locked skipped C:\WINDOWS\$NtServicePackUninstall$\mtxclu.dll Object is locked skipped C:\WINDOWS\$NtServicePackUninstall$\mtxoci.dll Object is locked skipped C:\WINDOWS\$NtServicePackUninstall$\muisetup.exe Object is locked skipped C:\WINDOWS\$NtServicePackUninstall$\multimed.inf Object is locked skipped C:\WINDOWS\$NtServicePackUninstall$\mup.sys Object is locked skipped C:\WINDOWS\$NtServicePackUninstall$\mydocs.dll Object is locked skipped C:\WINDOWS\$NtServicePackUninstall$\mymusic.inf Object is locked skipped C:\WINDOWS\$NtServicePackUninstall$\nabtsfec.inf Object is locked skipped C:\WINDOWS\$NtServicePackUninstall$\nac.dll Object is locked skipped C:\WINDOWS\$NtServicePackUninstall$\narrator.exe Object is locked skipped C:\WINDOWS\$NtServicePackUninstall$\ncobjapi.dll Object is locked skipped C:\WINDOWS\$NtServicePackUninstall$\ncprov.dll Object is locked skipped C:\WINDOWS\$NtServicePackUninstall$\nddeapi.dll Object is locked skipped C:\WINDOWS\$NtServicePackUninstall$\nddeapir.exe Object is locked skipped C:\WINDOWS\$NtServicePackUninstall$\nddenb32.dll Object is locked skipped C:\WINDOWS\$NtServicePackUninstall$\ndis.sys Object is locked skipped C:\WINDOWS\$NtServicePackUninstall$\ndisip.inf Object is locked skipped C:\WINDOWS\$NtServicePackUninstall$\ndisnpp.dll Object is locked skipped C:\WINDOWS\$NtServicePackUninstall$\ndisuio.sys Object is locked skipped C:\WINDOWS\$NtServicePackUninstall$\ndiswan.sys Object is locked skipped C:\WINDOWS\$NtServicePackUninstall$\ndptsp.tsp Object is locked skipped C:\WINDOWS\$NtServicePackUninstall$\net.exe Object is locked skipped C:\WINDOWS\$NtServicePackUninstall$\net1.exe Object is locked skipped C:\WINDOWS\$NtServicePackUninstall$\netac300.inf Object is locked skipped C:\WINDOWS\$NtServicePackUninstall$\netapi32.dll Object is locked skipped C:\WINDOWS\$NtServicePackUninstall$\netbios.sys Object is locked skipped C:\WINDOWS\$NtServicePackUninstall$\netbt.sys Object is locked skipped C:\WINDOWS\$NtServicePackUninstall$\netcfg.chm Object is locked skipped C:\WINDOWS\$NtServicePackUninstall$\netcfgx.dll Object is locked skipped C:\WINDOWS\$NtServicePackUninstall$\netdde.exe Object is locked skipped C:\WINDOWS\$NtServicePackUninstall$\netid.dll Object is locked skipped C:\WINDOWS\$NtServicePackUninstall$\netip6.inf Object is locked skipped C:\WINDOWS\$NtServicePackUninstall$\netklsi.inf Object is locked skipped C:\WINDOWS\$NtServicePackUninstall$\netlogon.dll Object is locked skipped C:\WINDOWS\$NtServicePackUninstall$\netman.dll Object is locked skipped C:\WINDOWS\$NtServicePackUninstall$\netmeet.htm Object is locked skipped C:\WINDOWS\$NtServicePackUninstall$\netmscli.inf Object is locked skipped C:\WINDOWS\$NtServicePackUninstall$\netnm.inf Object is locked skipped C:\WINDOWS\$NtServicePackUninstall$\netoc.dll Object is locked skipped C:\WINDOWS\$NtServicePackUninstall$\netoc.inf Object is locked skipped C:\WINDOWS\$NtServicePackUninstall$\netplwiz.dll Object is locked skipped C:\WINDOWS\$NtServicePackUninstall$\netrap.dll Object is locked skipped C:\WINDOWS\$NtServicePackUninstall$\netrass.inf Object is locked skipped C:\WINDOWS\$NtServicePackUninstall$\netrtsnt.inf Object is locked skipped C:\WINDOWS\$NtServicePackUninstall$\netsetup.exe Object is locked skipped C:\WINDOWS\$NtServicePackUninstall$\netsh.exe Object is locked skipped C:\WINDOWS\$NtServicePackUninstall$\netshell.dll Object is locked skipped C:\WINDOWS\$NtServicePackUninstall$\netstat.exe Object is locked skipped C:\WINDOWS\$NtServicePackUninstall$\nettcpip.inf Object is locked skipped C:\WINDOWS\$NtServicePackUninstall$\netui0.dll Object is locked skipped C:\WINDOWS\$NtServicePackUninstall$\netui1.dll Object is locked skipped C:\WINDOWS\$NtServicePackUninstall$\netupnph.inf Object is locked skipped C:\WINDOWS\$NtServicePackUninstall$\netwlan.inf Object is locked skipped C:\WINDOWS\$NtServicePackUninstall$\netwlan2.inf Object is locked skipped C:\WINDOWS\$NtServicePackUninstall$\network.chm Object is locked skipped C:\WINDOWS\$NtServicePackUninstall$\netwv48.inf Object is locked skipped C:\WINDOWS\$NtServicePackUninstall$\netwzc.inf Object is locked skipped C:\WINDOWS\$NtServicePackUninstall$\newalert.wav Object is locked skipped C:\WINDOWS\$NtServicePackUninstall$\newdev.dll Object is locked skipped C:\WINDOWS\$NtServicePackUninstall$\newemail.wav Object is locked skipped C:\WINDOWS\$NtServicePackUninstall$\neweula.htm Object is locked skipped C:\WINDOWS\$NtServicePackUninstall$\nic1394.sys Object is locked skipped C:\WINDOWS\$NtServicePackUninstall$\nlhtml.dll Object is locked skipped C:\WINDOWS\$NtServicePackUninstall$\nmas.dll Object is locked skipped C:\WINDOWS\$NtServicePackUninstall$\nmasnt.dll Object is locked skipped C:\WINDOWS\$NtServicePackUninstall$\nmchat.dll Object is locked skipped C:\WINDOWS\$NtServicePackUninstall$\nmcom.dll Object is locked skipped C:\WINDOWS\$NtServicePackUninstall$\nmft.dll Object is locked skipped C:\WINDOWS\$NtServicePackUninstall$\nmmkcert.dll Object is locked skipped C:\WINDOWS\$NtServicePackUninstall$\nmnt.sys Object is locked skipped C:\WINDOWS\$NtServicePackUninstall$\nmoldwb.dll Object is locked skipped C:\WINDOWS\$NtServicePackUninstall$\nmwb.dll Object is locked skipped C:\WINDOWS\$NtServicePackUninstall$\nnvtr7dr.dat Object is locked skipped C:\WINDOWS\$NtServicePackUninstall$\nnvtr7dr.zip Object is locked skipped C:\WINDOWS\$NtServicePackUninstall$\notepad.exe Object is locked skipped C:\WINDOWS\$NtServicePackUninstall$\npdrmv2.dll Object is locked skipped C:\WINDOWS\$NtServicePackUninstall$\npdsplay.dll Object is locked skipped C:\WINDOWS\$NtServicePackUninstall$\npfs.sys Object is locked skipped C:\WINDOWS\$NtServicePackUninstall$\nppagent.exe Object is locked skipped C:\WINDOWS\$NtServicePackUninstall$\npptools.dll Object is locked skipped C:\WINDOWS\$NtServicePackUninstall$\npwmsdrm.dll Object is locked skipped C:\WINDOWS\$NtServicePackUninstall$\nslookup.exe Object is locked skipped C:\WINDOWS\$NtServicePackUninstall$\nt5.cat Object is locked skipped C:\WINDOWS\$NtServicePackUninstall$\nt5inf.cat Object is locked skipped C:\WINDOWS\$NtServicePackUninstall$\ntchowto.chm Object is locked skipped C:\WINDOWS\$NtServicePackUninstall$\ntdef.chm Object is locked skipped C:\WINDOWS\$NtServicePackUninstall$\ntdetect.com Object is locked skipped C:\WINDOWS\$NtServicePackUninstall$\ntdll.dll Object is locked skipped C:\WINDOWS\$NtServicePackUninstall$\ntdsapi.dll Object is locked skipped C:\WINDOWS\$NtServicePackUninstall$\ntevt.dll Object is locked skipped C:\WINDOWS\$NtServicePackUninstall$\ntfs.sys Object is locked skipped C:\WINDOWS\$NtServicePackUninstall$\ntio.sys Object is locked skipped C:\WINDOWS\$NtServicePackUninstall$\ntio404.sys Object is locked skipped C:\WINDOWS\$NtServicePackUninstall$\ntio411.sys Object is locked skipped C:\WINDOWS\$NtServicePackUninstall$\ntio412.sys Object is locked skipped C:\WINDOWS\$NtServicePackUninstall$\ntio804.sys Object is locked skipped C:\WINDOWS\$NtServicePackUninstall$\ntkrnlpa.exe Object is locked skipped C:\WINDOWS\$NtServicePackUninstall$\ntlanman.dll Object is locked skipped C:\WINDOWS\$NtServicePackUninstall$\ntldr Object is locked skipped C:\WINDOWS\$NtServicePackUninstall$\ntlsapi.dll Object is locked skipped C:\WINDOWS\$NtServicePackUninstall$\ntmarta.dll Object is locked skipped C:\WINDOWS\$NtServicePackUninstall$\ntmsapi.dll Object is locked skipped C:\WINDOWS\$NtServicePackUninstall$\ntmsdba.dll Object is locked skipped C:\WINDOWS\$NtServicePackUninstall$\ntmsmgr.dll Object is locked skipped C:\WINDOWS\$NtServicePackUninstall$\ntmssvc.dll Object is locked skipped C:\WINDOWS\$NtServicePackUninstall$\ntoc.dll Object is locked skipped C:\WINDOWS\$NtServicePackUninstall$\ntoskrnl.exe Object is locked skipped C:\WINDOWS\$NtServicePackUninstall$\ntprint.cat Object is locked skipped C:\WINDOWS\$NtServicePackUninstall$\ntprint.dll Object is locked skipped C:\WINDOWS\$NtServicePackUninstall$\ntprint.inf Object is locked skipped C:\WINDOWS\$NtServicePackUninstall$\ntshrui.dll Object is locked skipped C:\WINDOWS\$NtServicePackUninstall$\ntvdm.exe Object is locked skipped C:\WINDOWS\$NtServicePackUninstall$\nusrmgr.chm Object is locked skipped C:\WINDOWS\$NtServicePackUninstall$\nusrmgr.cpl Object is locked skipped C:\WINDOWS\$NtServicePackUninstall$\nwlnkipx.sys Object is locked skipped C:\WINDOWS\$NtServicePackUninstall$\nwprovau.dll Object is locked skipped C:\WINDOWS\$NtServicePackUninstall$\oakley.dll Object is locked skipped C:\WINDOWS\$NtServicePackUninstall$\obeip.dun Object is locked skipped C:\WINDOWS\$NtServicePackUninstall$\objsel.dll Object is locked skipped C:\WINDOWS\$NtServicePackUninstall$\occache.dll Object is locked skipped C:\WINDOWS\$NtServicePackUninstall$\ocgen.dll Object is locked skipped C:\WINDOWS\$NtServicePackUninstall$\ocmsn.dll Object is locked skipped C:\WINDOWS\$NtServicePackUninstall$\odbc32.dll Object is locked skipped C:\WINDOWS\$NtServicePackUninstall$\odbc32gt.dll Object is locked skipped C:\WINDOWS\$NtServicePackUninstall$\odbcad32.exe Object is locked skipped C:\WINDOWS\$NtServicePackUninstall$\odbcbcp.dll Object is locked skipped C:\WINDOWS\$NtServicePackUninstall$\odbcconf.dll Object is locked skipped C:\WINDOWS\$NtServicePackUninstall$\odbcconf.exe Object is locked skipped C:\WINDOWS\$NtServicePackUninstall$\odbcconf.rsp Object is locked skipped C:\WINDOWS\$NtServicePackUninstall$\odbccp32.cpl Object is locked skipped C:\WINDOWS\$NtServicePackUninstall$\odbccp32.dll Object is locked skipped C:\WINDOWS\$NtServicePackUninstall$\odbccr32.dll Object is locked skipped C:\WINDOWS\$NtServicePackUninstall$\odbccu32.dll Object is locked skipped C:\WINDOWS\$NtServicePackUninstall$\odbcint.dll Object is locked skipped C:\WINDOWS\$NtServicePackUninstall$\odbcji32.dll Object is locked skipped C:\WINDOWS\$NtServicePackUninstall$\odbcjt32.dll Object is locked skipped C:\WINDOWS\$NtServicePackUninstall$\odbcp32r.dll Object is locked skipped C:\WINDOWS\$NtServicePackUninstall$\odbctrac.dll Object is locked skipped C:\WINDOWS\$NtServicePackUninstall$\oddbse32.dll Object is locked skipped C:\WINDOWS\$NtServicePackUninstall$\odexl32.dll Object is locked skipped C:\WINDOWS\$NtServicePackUninstall$\odfox32.dll Object is locked skipped C:\WINDOWS\$NtServicePackUninstall$\odpdx32.dll Object is locked skipped C:\WINDOWS\$NtServicePackUninstall$\odtext32.dll Object is locked skipped C:\WINDOWS\$NtServicePackUninstall$\oeimport.dll Object is locked skipped C:\WINDOWS\$NtServicePackUninstall$\oemig50.exe Object is locked skipped C:\WINDOWS\$NtServicePackUninstall$\oemiglib.dll Object is locked skipped C:\WINDOWS\$NtServicePackUninstall$\offfilt.dll Object is locked skipped C:\WINDOWS\$NtServicePackUninstall$\ole32.dll Object is locked skipped C:\WINDOWS\$NtServicePackUninstall$\oleaut32.dll Object is locked skipped C:\WINDOWS\$NtServicePackUninstall$\oledb32.dll Object is locked skipped C:\WINDOWS\$NtServicePackUninstall$\oledb32r.dll Object is locked skipped C:\WINDOWS\$NtServicePackUninstall$\oleprn.dll Object is locked skipped C:\WINDOWS\$NtServicePackUninstall$\olepro32.dll Object is locked skipped C:\WINDOWS\$NtServicePackUninstall$\online.wav Object is locked skipped C:\WINDOWS\$NtServicePackUninstall$\oobe.inf Object is locked skipped C:\WINDOWS\$NtServicePackUninstall$\oobebaln.exe Object is locked skipped C:\WINDOWS\$NtServicePackUninstall$\oobeutil.js Object is locked skipped C:\WINDOWS\$NtServicePackUninstall$\opengl32.dll Object is locked skipped C:\WINDOWS\$NtServicePackUninstall$\osk.exe Object is locked skipped C:\WINDOWS\$NtServicePackUninstall$\osuninst.dll Object is locked skipped C:\WINDOWS\$NtServicePackUninstall$\ozljjblb.dat Object is locked skipped C:\WINDOWS\$NtServicePackUninstall$\p3.sys Object is locked skipped C:\WINDOWS\$NtServicePackUninstall$\packager.exe Object is locked skipped C:\WINDOWS\$NtServicePackUninstall$\page1.asp Object is locked skipped C:\WINDOWS\$NtServicePackUninstall$\parport.sys Object is locked skipped C:\WINDOWS\$NtServicePackUninstall$\password.chm Object is locked skipped C:\WINDOWS\$NtServicePackUninstall$\pautoenr.dll Object is locked skipped C:\WINDOWS\$NtServicePackUninstall$\pchealth.inf Object is locked skipped C:\WINDOWS\$NtServicePackUninstall$\pchshell.dll Object is locked skipped C:\WINDOWS\$NtServicePackUninstall$\pchsvc.dll Object is locked skipped C:\WINDOWS\$NtServicePackUninstall$\pci.sys Object is locked skipped C:\WINDOWS\$NtServicePackUninstall$\pciidex.sys Object is locked skipped C:\WINDOWS\$NtServicePackUninstall$\pcmcia.sys Object is locked skipped C:\WINDOWS\$NtServicePackUninstall$\pdh.dll Object is locked skipped C:\WINDOWS\$NtServicePackUninstall$\perfctrs.dll Object is locked skipped C:\WINDOWS\$NtServicePackUninstall$\perfdisk.dll Object is locked skipped C:\WINDOWS\$NtServicePackUninstall$\perfmon.exe Object is locked skipped C:\WINDOWS\$NtServicePackUninstall$\perfos.dll Object is locked skipped C:\WINDOWS\$NtServicePackUninstall$\perfproc.dll Object is locked skipped C:\WINDOWS\$NtServicePackUninstall$\phone.icw Object is locked skipped C:\WINDOWS\$NtServicePackUninstall$\phone.inf Object is locked skipped C:\WINDOWS\$NtServicePackUninstall$\phone.obe Object is locked skipped C:\WINDOWS\$NtServicePackUninstall$\photowiz.dll Object is locked skipped C:\WINDOWS\$NtServicePackUninstall$\pid.dll Object is locked skipped C:\WINDOWS\$NtServicePackUninstall$\pidgen.dll Object is locked skipped C:\WINDOWS\$NtServicePackUninstall$\pinball.exe Object is locked skipped C:\WINDOWS\$NtServicePackUninstall$\ping.exe Object is locked skipped C:\WINDOWS\$NtServicePackUninstall$\pjlmon.dll Object is locked skipped C:\WINDOWS\$NtServicePackUninstall$\plyr_err.chm Object is locked skipped C:\WINDOWS\$NtServicePackUninstall$\pngfilt.dll Object is locked skipped C:\WINDOWS\$NtServicePackUninstall$\pnpscsi.inf Object is locked skipped C:\WINDOWS\$NtServicePackUninstall$\polstore.dll Object is locked skipped C:\WINDOWS\$NtServicePackUninstall$\portcls.sys Object is locked skipped C:\WINDOWS\$NtServicePackUninstall$\powercfg.cpl Object is locked skipped C:\WINDOWS\$NtServicePackUninstall$\powrprof.dll Object is locked skipped C:\WINDOWS\$NtServicePackUninstall$\printing.chm Object is locked skipped C:\WINDOWS\$NtServicePackUninstall$\printui.dll Object is locked skipped C:\WINDOWS\$NtServicePackUninstall$\processr.sys Object is locked skipped C:\WINDOWS\$NtServicePackUninstall$\proctexe.ocx Object is locked skipped C:\WINDOWS\$NtServicePackUninstall$\profmap.dll Object is locked skipped C:\WINDOWS\$NtServicePackUninstall$\progman.exe Object is locked skipped C:\WINDOWS\$NtServicePackUninstall$\proquota.exe Object is locked skipped C:\WINDOWS\$NtServicePackUninstall$\provthrd.dll Object is locked skipped C:\WINDOWS\$NtServicePackUninstall$\psapi.dll Object is locked skipped C:\WINDOWS\$NtServicePackUninstall$\psbase.dll Object is locked skipped C:\WINDOWS\$NtServicePackUninstall$\psched.sys Object is locked skipped C:\WINDOWS\$NtServicePackUninstall$\pstorec.dll Object is locked skipped C:\WINDOWS\$NtServicePackUninstall$\pstorsvc.dll Object is locked skipped C:\WINDOWS\$NtServicePackUninstall$\qasf.dll Object is locked skipped C:\WINDOWS\$NtServicePackUninstall$\qcap.dll Object is locked skipped C:\WINDOWS\$NtServicePackUninstall$\qdv.dll Object is locked skipped C:\WINDOWS\$NtServicePackUninstall$\qdvd.dll Object is locked skipped C:\WINDOWS\$NtServicePackUninstall$\qedit.dll Object is locked skipped C:\WINDOWS\$NtServicePackUninstall$\qedwipes.dll Object is locked skipped C:\WINDOWS\$NtServicePackUninstall$\qmgr.dll Object is locked skipped C:\WINDOWS\$NtServicePackUninstall$\qmgr.inf Object is locked skipped C:\WINDOWS\$NtServicePackUninstall$\qmgrprxy.dll Object is locked skipped C:\WINDOWS\$NtServicePackUninstall$\qprocess.exe Object is locked skipped C:\WINDOWS\$NtServicePackUninstall$\quartz.dll Object is locked skipped C:\WINDOWS\$NtServicePackUninstall$\query.dll Object is locked skipped C:\WINDOWS\$NtServicePackUninstall$\racpldlg.dll Object is locked skipped C:\WINDOWS\$NtServicePackUninstall$\rasadhlp.dll Object is locked skipped C:\WINDOWS\$NtServicePackUninstall$\rasapi32.dll Object is locked skipped C:\WINDOWS\$NtServicePackUninstall$\rasauto.dll Object is locked skipped C:\WINDOWS\$NtServicePackUninstall$\raschap.dll Object is locked skipped C:\WINDOWS\$NtServicePackUninstall$\rasdlg.dll Object is locked skipped C:\WINDOWS\$NtServicePackUninstall$\rasl2tp.sys Object is locked skipped C:\WINDOWS\$NtServicePackUninstall$\rasman.dll Object is locked skipped C:\WINDOWS\$NtServicePackUninstall$\rasmans.dll Object is locked skipped C:\WINDOWS\$NtServicePackUninstall$\rasphone.exe Object is locked skipped C:\WINDOWS\$NtServicePackUninstall$\rasppp.dll Object is locked skipped C:\WINDOWS\$NtServicePackUninstall$\raspppoe.sys Object is locked skipped C:\WINDOWS\$NtServicePackUninstall$\raspptp.sys Object is locked skipped C:\WINDOWS\$NtServicePackUninstall$\rassapi.dll Object is locked skipped C:\WINDOWS\$NtServicePackUninstall$\rastapi.dll Object is locked skipped C:\WINDOWS\$NtServicePackUninstall$\rastls.dll Object is locked skipped C:\WINDOWS\$NtServicePackUninstall$\rcbdyctl.dll Object is locked skipped C:\WINDOWS\$NtServicePackUninstall$\rcimlby.exe Object is locked skipped C:\WINDOWS\$NtServicePackUninstall$\rcp.exe Object is locked skipped C:\WINDOWS\$NtServicePackUninstall$\rdbss.sys Object is locked skipped C:\WINDOWS\$NtServicePackUninstall$\rdchost.dll Object is locked skipped C:\WINDOWS\$NtServicePackUninstall$\rdpclip.exe Object is locked skipped C:\WINDOWS\$NtServicePackUninstall$\rdpdd.dll Object is locked skipped C:\WINDOWS\$NtServicePackUninstall$\rdpdr.sys Object is locked skipped C:\WINDOWS\$NtServicePackUninstall$\rdpsnd.dll Object is locked skipped C:\WINDOWS\$NtServicePackUninstall$\rdpwd.sys Object is locked skipped C:\WINDOWS\$NtServicePackUninstall$\rdpwsx.dll Object is locked skipped C:\WINDOWS\$NtServicePackUninstall$\rdsaddin.exe Object is locked skipped C:\WINDOWS\$NtServicePackUninstall$\rdshost.exe Object is locked skipped C:\WINDOWS\$NtServicePackUninstall$\redbook.sys Object is locked skipped C:\WINDOWS\$NtServicePackUninstall$\redir.exe Object is locked skipped C:\WINDOWS\$NtServicePackUninstall$\reg.exe Object is locked skipped C:\WINDOWS\$NtServicePackUninstall$\regapi.dll Object is locked skipped C:\WINDOWS\$NtServicePackUninstall$\regedit.exe Object is locked skipped C:\WINDOWS\$NtServicePackUninstall$\regopt.chm Object is locked skipped C:\WINDOWS\$NtServicePackUninstall$\regsvc.dll Object is locked skipped C:\WINDOWS\$NtServicePackUninstall$\regsvr32.exe Object is locked skipped C:\WINDOWS\$NtServicePackUninstall$\regwizc.dll Object is locked skipped C:\WINDOWS\$NtServicePackUninstall$\related.htm Object is locked skipped C:\WINDOWS\$NtServicePackUninstall$\remasst.chm Object is locked skipped C:\WINDOWS\$NtServicePackUninstall$\remotepg.dll Object is locked skipped C:\WINDOWS\$NtServicePackUninstall$\remotesp.tsp Object is locked skipped C:\WINDOWS\$NtServicePackUninstall$\repdrvfs.dll Object is locked skipped C:\WINDOWS\$NtServicePackUninstall$\resutils.dll Object is locked skipped C:\WINDOWS\$NtServicePackUninstall$\rexec.exe Object is locked skipped C:\WINDOWS\$NtServicePackUninstall$\riched20.dll Object is locked skipped C:\WINDOWS\$NtServicePackUninstall$\rndismp.sys Object is locked skipped C:\WINDOWS\$NtServicePackUninstall$\rpcrt4.dll Object is locked skipped C:\WINDOWS\$NtServicePackUninstall$\rpcss.dll Object is locked skipped C:\WINDOWS\$NtServicePackUninstall$\rrcm.dll Object is locked skipped C:\WINDOWS\$NtServicePackUninstall$\rsaenh.dll Object is locked skipped C:\WINDOWS\$NtServicePackUninstall$\rsh.exe Object is locked skipped C:\WINDOWS\$NtServicePackUninstall$\rshx32.dll Object is locked skipped C:\WINDOWS\$NtServicePackUninstall$\rsmps.dll Object is locked skipped C:\WINDOWS\$NtServicePackUninstall$\rstrui.exe Object is locked skipped C:\WINDOWS\$NtServicePackUninstall$\rtcdll.dll Object is locked skipped C:\WINDOWS\$NtServicePackUninstall$\rtcshare.exe Object is locked skipped C:\WINDOWS\$NtServicePackUninstall$\rtipxmib.dll Object is locked skipped C:\WINDOWS\$NtServicePackUninstall$\rtutils.dll Object is locked skipped C:\WINDOWS\$NtServicePackUninstall$\rundll32.exe Object is locked skipped C:\WINDOWS\$NtServicePackUninstall$\runonce.exe Object is locked skipped C:\WINDOWS\$NtServicePackUninstall$\s3nb.inf Object is locked skipped C:\WINDOWS\$NtServicePackUninstall$\safemode.htt Object is locked skipped C:\WINDOWS\$NtServicePackUninstall$\safe_better.htm Object is locked skipped C:\WINDOWS\$NtServicePackUninstall$\safe_easier.htm Object is locked skipped C:\WINDOWS\$NtServicePackUninstall$\safe_faster.htm Object is locked skipped C:\WINDOWS\$NtServicePackUninstall$\safe_fr.htm Object is locked skipped C:\WINDOWS\$NtServicePackUninstall$\safrcdlg.dll Object is locked skipped C:\WINDOWS\$NtServicePackUninstall$\safrdm.dll Object is locked skipped C:\WINDOWS\$NtServicePackUninstall$\safrslv.dll Object is locked skipped C:\WINDOWS\$NtServicePackUninstall$\samlib.dll Object is locked skipped C:\WINDOWS\$NtServicePackUninstall$\samsrv.dll Object is locked skipped C:\WINDOWS\$NtServicePackUninstall$\sapi.cpl Object is locked skipped C:\WINDOWS\$NtServicePackUninstall$\sapi.dll Object is locked skipped C:\WINDOWS\$NtServicePackUninstall$\savedump.exe Object is locked skipped C:\WINDOWS\$NtServicePackUninstall$\scarddlg.dll Object is locked skipped C:\WINDOWS\$NtServicePackUninstall$\scardsvr.exe Object is locked skipped C:\WINDOWS\$NtServicePackUninstall$\sccbase.dll Object is locked skipped C:\WINDOWS\$NtServicePackUninstall$\sccsccp.dll Object is locked skipped C:\WINDOWS\$NtServicePackUninstall$\scecli.dll Object is locked skipped C:\WINDOWS\$NtServicePackUninstall$\sceregvl.inf Object is locked skipped C:\WINDOWS\$NtServicePackUninstall$\scesrv.dll Object is locked skipped C:\WINDOWS\$NtServicePackUninstall$\schannel.dll Object is locked skipped C:\WINDOWS\$NtServicePackUninstall$\schedsvc.dll Object is locked skipped C:\WINDOWS\$NtServicePackUninstall$\sclgntfy.dll Object is locked skipped C:\WINDOWS\$NtServicePackUninstall$\scrcons.exe Object is locked skipped C:\WINDOWS\$NtServicePackUninstall$\script.dll Object is locked skipped C:\WINDOWS\$NtServicePackUninstall$\script_a.dll Object is locked skipped C:\WINDOWS\$NtServicePackUninstall$\scrnsave.scr Object is locked skipped C:\WINDOWS\$NtServicePackUninstall$\scrobj.dll Object is locked skipped C:\WINDOWS\$NtServicePackUninstall$\scrrun.dll Object is locked skipped C:\WINDOWS\$NtServicePackUninstall$\scsi.inf Object is locked skipped C:\WINDOWS\$NtServicePackUninstall$\scsiport.sys Object is locked skipped C:\WINDOWS\$NtServicePackUninstall$\sdbinst.exe Object is locked skipped C:\WINDOWS\$NtServicePackUninstall$\seclogon.dll Object is locked skipped C:\WINDOWS\$NtServicePackUninstall$\secrecs.inf Object is locked skipped C:\WINDOWS\$NtServicePackUninstall$\secur32.dll Object is locked skipped C:\WINDOWS\$NtServicePackUninstall$\security center.lnk Object is locked skipped C:\WINDOWS\$NtServicePackUninstall$\security.dll Object is locked skipped C:\WINDOWS\$NtServicePackUninstall$\sendcmsg.chm Object is locked skipped C:\WINDOWS\$NtServicePackUninstall$\sendcmsg.dll Object is locked skipped C:\WINDOWS\$NtServicePackUninstall$\sendmail.dll Object is locked skipped C:\WINDOWS\$NtServicePackUninstall$\sens.dll Object is locked skipped C:\WINDOWS\$NtServicePackUninstall$\sensapi.dll Object is locked skipped C:\WINDOWS\$NtServicePackUninstall$\serenum.sys Object is locked skipped C:\WINDOWS\$NtServicePackUninstall$\serial.sys Object is locked skipped C:\WINDOWS\$NtServicePackUninstall$\servdeps.dll Object is locked skipped C:\WINDOWS\$NtServicePackUninstall$\services.exe Object is locked skipped C:\WINDOWS\$NtServicePackUninstall$\sessmgr.exe Object is locked skipped C:\WINDOWS\$NtServicePackUninstall$\sethc.exe Object is locked skipped C:\WINDOWS\$NtServicePackUninstall$\setup.exe Object is locked skipped C:\WINDOWS\$NtServicePackUninstall$\setup50.exe Object is locked skipped C:\WINDOWS\$NtServicePackUninstall$\setupapi.dll Object is locked skipped C:\WINDOWS\$NtServicePackUninstall$\setupqry.dll Object is locked skipped C:\WINDOWS\$NtServicePackUninstall$\setupqry.inf Object is locked skipped C:\WINDOWS\$NtServicePackUninstall$\setup_wm.exe Object is locked skipped C:\WINDOWS\$NtServicePackUninstall$\sfc.dll Object is locked skipped C:\WINDOWS\$NtServicePackUninstall$\sfcfiles.dll Object is locked skipped C:\WINDOWS\$NtServicePackUninstall$\sfc_os.dll Object is locked skipped C:\WINDOWS\$NtServicePackUninstall$\sfloppy.sys Object is locked skipped C:\WINDOWS\$NtServicePackUninstall$\shdoclc.dll Object is locked skipped C:\WINDOWS\$NtServicePackUninstall$\shdocvw.dll Object is locked skipped C:\WINDOWS\$NtServicePackUninstall$\shell.inf Object is locked skipped C:\WINDOWS\$NtServicePackUninstall$\shell32.dll Object is locked skipped C:\WINDOWS\$NtServicePackUninstall$\shfolder.dll Object is locked skipped C:\WINDOWS\$NtServicePackUninstall$\shgina.dll Object is locked skipped C:\WINDOWS\$NtServicePackUninstall$\shimeng.dll Object is locked skipped C:\WINDOWS\$NtServicePackUninstall$\shimgvw.dll Object is locked skipped C:\WINDOWS\$NtServicePackUninstall$\shlwapi.dll Object is locked skipped C:\WINDOWS\$NtServicePackUninstall$\shl_img.inf Object is locked skipped C:\WINDOWS\$NtServicePackUninstall$\shmedia.dll Object is locked skipped C:\WINDOWS\$NtServicePackUninstall$\shmgrate.exe Object is locked skipped C:\WINDOWS\$NtServicePackUninstall$\shrpubw.exe Object is locked skipped C:\WINDOWS\$NtServicePackUninstall$\shscrap.dll Object is locked skipped C:\WINDOWS\$NtServicePackUninstall$\shsvcs.dll Object is locked skipped C:\WINDOWS\$NtServicePackUninstall$\shtml.dll Object is locked skipped C:\WINDOWS\$NtServicePackUninstall$\shtml.exe Object is locked skipped C:\WINDOWS\$NtServicePackUninstall$\shutdown.exe Object is locked skipped C:\WINDOWS\$NtServicePackUninstall$\sigtab.dll Object is locked skipped C:\WINDOWS\$NtServicePackUninstall$\sigverif.exe Object is locked skipped C:\WINDOWS\$NtServicePackUninstall$\simpdata.tlb Object is locked skipped C:\WINDOWS\$NtServicePackUninstall$\skeys.exe Object is locked skipped C:\WINDOWS\$NtServicePackUninstall$\skins.inf Object is locked skipped C:\WINDOWS\$NtServicePackUninstall$\slayerxp.dll Object is locked skipped C:\WINDOWS\$NtServicePackUninstall$\slbcsp.dll Object is locked skipped C:\WINDOWS\$NtServicePackUninstall$\slbiop.dll Object is locked skipped C:\WINDOWS\$NtServicePackUninstall$\slip.inf Object is locked skipped C:\WINDOWS\$NtServicePackUninstall$\sl_anet.acm Object is locked skipped C:\WINDOWS\$NtServicePackUninstall$\smartcrd.inf Object is locked skipped C:\WINDOWS\$NtServicePackUninstall$\smi2smir.exe Object is locked skipped C:\WINDOWS\$NtServicePackUninstall$\smlogcfg.dll Object is locked skipped C:\WINDOWS\$NtServicePackUninstall$\smlogsvc.exe Object is locked skipped C:\WINDOWS\$NtServicePackUninstall$\smss.exe Object is locked skipped C:\WINDOWS\$NtServicePackUninstall$\sndrec32.exe Object is locked skipped C:\WINDOWS\$NtServicePackUninstall$\sniffpol.dll Object is locked skipped C:\WINDOWS\$NtServicePackUninstall$\snmp.exe Object is locked skipped C:\WINDOWS\$NtServicePackUninstall$\snmpapi.dll Object is locked skipped C:\WINDOWS\$NtServicePackUninstall$\snmpcl.dll Object is locked skipped C:\WINDOWS\$NtServicePackUninstall$\snmpincl.dll Object is locked skipped C:\WINDOWS\$NtServicePackUninstall$\snmpmib.dll Object is locked skipped C:\WINDOWS\$NtServicePackUninstall$\snmpsmir.dll Object is locked skipped C:\WINDOWS\$NtServicePackUninstall$\snmpsnap.dll Object is locked skipped C:\WINDOWS\$NtServicePackUninstall$\snmpthrd.dll Object is locked skipped C:\WINDOWS\$NtServicePackUninstall$\snmptrap.exe Object is locked skipped C:\WINDOWS\$NtServicePackUninstall$\softkbd.dll Object is locked skipped C:\WINDOWS\$NtServicePackUninstall$\sonydcam.sys Object is locked skipped C:\WINDOWS\$NtServicePackUninstall$\sorttbls.nls Object is locked skipped C:\WINDOWS\$NtServicePackUninstall$\sp2.cat Object is locked skipped C:\WINDOWS\$NtServicePackUninstall$\spider.exe Object is locked skipped C:\WINDOWS\$NtServicePackUninstall$\splitter.sys Object is locked skipped C:\WINDOWS\$NtServicePackUninstall$\spoolss.dll Object is locked skipped C:\WINDOWS\$NtServicePackUninstall$\spoolsv.exe Object is locked skipped C:\WINDOWS\$NtServicePackUninstall$\sptip.dll Object is locked skipped C:\WINDOWS\$NtServicePackUninstall$\sqloledb.dll Object is locked skipped C:\WINDOWS\$NtServicePackUninstall$\sqloledb.rll Object is locked skipped C:\WINDOWS\$NtServicePackUninstall$\sqlsrv32.dll Object is locked skipped C:\WINDOWS\$NtServicePackUninstall$\sqlsrv32.rll Object is locked skipped C:\WINDOWS\$NtServicePackUninstall$\sqlunirl.dll Object is locked skipped C:\WINDOWS\$NtServicePackUninstall$\sqlxmlx.dll Object is locked skipped C:\WINDOWS\$NtServicePackUninstall$\sqlxmlx.rll Object is locked skipped C:\WINDOWS\$NtServicePackUninstall$\sr.sys Object is locked skipped C:\WINDOWS\$NtServicePackUninstall$\srchctls.dll Object is locked skipped C:\WINDOWS\$NtServicePackUninstall$\srchui.dll Object is locked skipped C:\WINDOWS\$NtServicePackUninstall$\srclient.dll Object is locked skipped C:\WINDOWS\$NtServicePackUninstall$\srrstr.dll Object is locked skipped C:\WINDOWS\$NtServicePackUninstall$\srsvc.dll Object is locked skipped C:\WINDOWS\$NtServicePackUninstall$\srv.sys Object is locked skipped C:\WINDOWS\$NtServicePackUninstall$\srvsvc.dll Object is locked skipped C:\WINDOWS\$NtServicePackUninstall$\sr_ui.chm Object is locked skipped C:\WINDOWS\$NtServicePackUninstall$\ss3dfo.scr Object is locked skipped C:\WINDOWS\$NtServicePackUninstall$\ssbezier.scr Object is locked skipped C:\WINDOWS\$NtServicePackUninstall$\ssdpapi.dll Object is locked skipped C:\WINDOWS\$NtServicePackUninstall$\ssdpsrv.dll Object is locked skipped C:\WINDOWS\$NtServicePackUninstall$\ssflwbox.scr Object is locked skipped C:\WINDOWS\$NtServicePackUninstall$\ssmarque.scr Object is locked skipped C:\WINDOWS\$NtServicePackUninstall$\ssmypics.scr Object is locked skipped C:\WINDOWS\$NtServicePackUninstall$\ssmyst.scr Object is locked skipped C:\WINDOWS\$NtServicePackUninstall$\sspipes.scr Object is locked skipped C:\WINDOWS\$NtServicePackUninstall$\ssstars.scr Object is locked skipped C:\WINDOWS\$NtServicePackUninstall$\sstext3d.scr Object is locked skipped C:\WINDOWS\$NtServicePackUninstall$\sstub.dll Object is locked skipped C:\WINDOWS\$NtServicePackUninstall$\startoc.cat Object is locked skipped C:\WINDOWS\$NtServicePackUninstall$\start_control.htm Object is locked skipped C:\WINDOWS\$NtServicePackUninstall$\start_desktop.htm Object is locked skipped C:\WINDOWS\$NtServicePackUninstall$\start_ending.htm Object is locked skipped C:\WINDOWS\$NtServicePackUninstall$\start_files.htm Object is locked skipped C:\WINDOWS\$NtServicePackUninstall$\start_fr.htm Object is locked skipped C:\WINDOWS\$NtServicePackUninstall$\start_icons.htm Object is locked skipped C:\WINDOWS\$NtServicePackUninstall$\start_menu.htm Object is locked skipped C:\WINDOWS\$NtServicePackUninstall$\start_taskbar.htm Object is locked skipped C:\WINDOWS\$NtServicePackUninstall$\start_windows.htm Object is locked skipped C:\WINDOWS\$NtServicePackUninstall$\stdprov.dll Object is locked skipped C:\WINDOWS\$NtServicePackUninstall$\sti.dll Object is locked skipped C:\WINDOWS\$NtServicePackUninstall$\stimon.exe Object is locked skipped C:\WINDOWS\$NtServicePackUninstall$\sti_ci.dll Object is locked skipped C:\WINDOWS\$NtServicePackUninstall$\stobject.dll Object is locked skipped C:\WINDOWS\$NtServicePackUninstall$\storprop.dll Object is locked skipped C:\WINDOWS\$NtServicePackUninstall$\stream.sys Object is locked skipped C:\WINDOWS\$NtServicePackUninstall$\streamip.inf Object is locked skipped C:\WINDOWS\$NtServicePackUninstall$\strmdll.dll Object is locked skipped C:\WINDOWS\$NtServicePackUninstall$\svchost.exe Object is locked skipped C:\WINDOWS\$NtServicePackUninstall$\swenum.sys Object is locked skipped C:\WINDOWS\$NtServicePackUninstall$\swflash.inf Object is locked skipped C:\WINDOWS\$NtServicePackUninstall$\swflash.ocx Object is locked skipped C:\WINDOWS\$NtServicePackUninstall$\sxs.dll Object is locked skipped C:\WINDOWS\$NtServicePackUninstall$\synceng.dll Object is locked skipped C:\WINDOWS\$NtServicePackUninstall$\syncui.dll Object is locked skipped C:\WINDOWS\$NtServicePackUninstall$\sysaudio.sys Object is locked skipped C:\WINDOWS\$NtServicePackUninstall$\sysdm.cpl Object is locked skipped C:\WINDOWS\$NtServicePackUninstall$\sysfiles.inf Object is locked skipped C:\WINDOWS\$NtServicePackUninstall$\sysmain.sdb Object is locked skipped C:\WINDOWS\$NtServicePackUninstall$\sysmod.dll Object is locked skipped C:\WINDOWS\$NtServicePackUninstall$\sysmod_a.dll Object is locked skipped C:\WINDOWS\$NtServicePackUninstall$\sysmon.ocx Object is locked skipped C:\WINDOWS\$NtServicePackUninstall$\sysoc.inf Object is locked skipped C:\WINDOWS\$NtServicePackUninstall$\sysocmgr.exe Object is locked skipped C:\WINDOWS\$NtServicePackUninstall$\sysrestore.chm Object is locked skipped C:\WINDOWS\$NtServicePackUninstall$\syssetup.dll Object is locked skipped C:\WINDOWS\$NtServicePackUninstall$\syssetup.inf Object is locked skipped C:\WINDOWS\$NtServicePackUninstall$\sys_srv.chm Object is locked skipped C:\WINDOWS\$NtServicePackUninstall$\t2embed.dll Object is locked skipped C:\WINDOWS\$NtServicePackUninstall$\tahoma.ttf Object is locked skipped C:\WINDOWS\$NtServicePackUninstall$\tahomabd.ttf Object is locked skipped C:\WINDOWS\$NtServicePackUninstall$\tape.inf Object is locked skipped C:\WINDOWS\$NtServicePackUninstall$\tape.sys Object is locked skipped C:\WINDOWS\$NtServicePackUninstall$\tapi3.dll Object is locked skipped C:\WINDOWS\$NtServicePackUninstall$\tapi32.dll Object is locked skipped C:\WINDOWS\$NtServicePackUninstall$\tapisrv.dll Object is locked skipped C:\WINDOWS\$NtServicePackUninstall$\taskmgr.exe Object is locked skipped C:\WINDOWS\$NtServicePackUninstall$\tcpip.sys Object is locked skipped C:\WINDOWS\$NtServicePackUninstall$\tcpip6.sys Object is locked skipped C:\WINDOWS\$NtServicePackUninstall$\tcpmib.dll Object is locked skipped C:\WINDOWS\$NtServicePackUninstall$\tcpmon.dll Object is locked skipped C:\WINDOWS\$NtServicePackUninstall$\tcpmon.ini Object is locked skipped C:\WINDOWS\$NtServicePackUninstall$\tcpmonui.dll Object is locked skipped C:\WINDOWS\$NtServicePackUninstall$\tcptest.exe Object is locked skipped C:\WINDOWS\$NtServicePackUninstall$\tcptsat.dll Object is locked skipped C:\WINDOWS\$NtServicePackUninstall$\tdc.ocx Object is locked skipped C:\WINDOWS\$NtServicePackUninstall$\tdi.sys Object is locked skipped C:\WINDOWS\$NtServicePackUninstall$\tdpipe.sys Object is locked skipped C:\WINDOWS\$NtServicePackUninstall$\tdtcp.sys Object is locked skipped C:\WINDOWS\$NtServicePackUninstall$\telnet.exe Object is locked skipped C:\WINDOWS\$NtServicePackUninstall$\termdd.sys Object is locked skipped C:\WINDOWS\$NtServicePackUninstall$\termmgr.dll Object is locked skipped C:\WINDOWS\$NtServicePackUninstall$\termsrv.dll Object is locked skipped C:\WINDOWS\$NtServicePackUninstall$\themeui.dll Object is locked skipped C:\WINDOWS\$NtServicePackUninstall$\timedate.cpl Object is locked skipped C:\WINDOWS\$NtServicePackUninstall$\times.ttf Object is locked skipped C:\WINDOWS\$NtServicePackUninstall$\timesbd.ttf Object is locked skipped C:\WINDOWS\$NtServicePackUninstall$\tip.htm Object is locked skipped C:\WINDOWS\$NtServicePackUninstall$\tourstart.exe Object is locked skipped C:\WINDOWS\$NtServicePackUninstall$\tourstrt.exe Object is locked skipped C:\WINDOWS\$NtServicePackUninstall$\tracert.exe Object is locked skipped C:\WINDOWS\$NtServicePackUninstall$\trebuc.ttf Object is locked skipped C:\WINDOWS\$NtServicePackUninstall$\triedit.dll Object is locked skipped C:\WINDOWS\$NtServicePackUninstall$\trkwks.dll Object is locked skipped C:\WINDOWS\$NtServicePackUninstall$\tscfgwmi.dll Object is locked skipped C:\WINDOWS\$NtServicePackUninstall$\tscfgwmi.mfl Object is locked skipped C:\WINDOWS\$NtServicePackUninstall$\tscfgwmi.mof Object is locked skipped C:\WINDOWS\$NtServicePackUninstall$\tscupgrd.exe Object is locked skipped C:\WINDOWS\$NtServicePackUninstall$\tsddd.dll Object is locked skipped C:\WINDOWS\$NtServicePackUninstall$\tshoot.chm Object is locked skipped C:\WINDOWS\$NtServicePackUninstall$\tshoot.dll Object is locked skipped C:\WINDOWS\$NtServicePackUninstall$\tsoc.dll Object is locked skipped C:\WINDOWS\$NtServicePackUninstall$\tsoc.inf Object is locked skipped C:\WINDOWS\$NtServicePackUninstall$\twain_32.dll Object is locked skipped C:\WINDOWS\$NtServicePackUninstall$\txflog.dll Object is locked skipped C:\WINDOWS\$NtServicePackUninstall$\tz5zzxjd.dat Object is locked skipped C:\WINDOWS\$NtServicePackUninstall$\tz5zzxjd.zip Object is locked skipped C:\WINDOWS\$NtServicePackUninstall$\udfs.sys Object is locked skipped C:\WINDOWS\$NtServicePackUninstall$\udhisapi.dll Object is locked skipped C:\WINDOWS\$NtServicePackUninstall$\ulib.dll Object is locked skipped C:\WINDOWS\$NtServicePackUninstall$\umandlg.dll Object is locked skipped C:\WINDOWS\$NtServicePackUninstall$\umpnpmgr.dll Object is locked skipped C:\WINDOWS\$NtServicePackUninstall$\unimdm.tsp Object is locked skipped C:\WINDOWS\$NtServicePackUninstall$\unimdmat.dll Object is locked skipped C:\WINDOWS\$NtServicePackUninstall$\uniplat.dll Object is locked skipped C:\WINDOWS\$NtServicePackUninstall$\unlock_built.htm Object is locked skipped C:\WINDOWS\$NtServicePackUninstall$\unlock_fr.htm Object is locked skipped C:\WINDOWS\$NtServicePackUninstall$\unlock_optimized.htm Object is locked skipped C:\WINDOWS\$NtServicePackUninstall$\unlock_playing.htm Object is locked skipped C:\WINDOWS\$NtServicePackUninstall$\unregmp2.exe Object is locked skipped C:\WINDOWS\$NtServicePackUninstall$\untfs.dll Object is locked skipped C:\WINDOWS\$NtServicePackUninstall$\update.sys Object is locked skipped C:\WINDOWS\$NtServicePackUninstall$\uploadm.exe Object is locked skipped C:\WINDOWS\$NtServicePackUninstall$\upnp.dll Object is locked skipped C:\WINDOWS\$NtServicePackUninstall$\upnpcont.exe Object is locked skipped C:\WINDOWS\$NtServicePackUninstall$\upnphost.dll Object is locked skipped C:\WINDOWS\$NtServicePackUninstall$\upnpui.dll Object is locked skipped C:\WINDOWS\$NtServicePackUninstall$\ups.exe Object is locked skipped C:\WINDOWS\$NtServicePackUninstall$\url.dll Object is locked skipped C:\WINDOWS\$NtServicePackUninstall$\urlmon.dll Object is locked skipped C:\WINDOWS\$NtServicePackUninstall$\usb8023.sys Object is locked skipped C:\WINDOWS\$NtServicePackUninstall$\usbehci.sys Object is locked skipped C:\WINDOWS\$NtServicePackUninstall$\usbhub.sys Object is locked skipped C:\WINDOWS\$NtServicePackUninstall$\usbintel.sys Object is locked skipped C:\WINDOWS\$NtServicePackUninstall$\usbmon.dll Object is locked skipped C:\WINDOWS\$NtServicePackUninstall$\usbohci.sys Object is locked skipped C:\WINDOWS\$NtServicePackUninstall$\usbport.inf Object is locked skipped C:\WINDOWS\$NtServicePackUninstall$\usbport.sys Object is locked skipped C:\WINDOWS\$NtServicePackUninstall$\usbuhci.sys Object is locked skipped C:\WINDOWS\$NtServicePackUninstall$\usbui.dll Object is locked skipped C:\WINDOWS\$NtServicePackUninstall$\user32.dll Object is locked skipped C:\WINDOWS\$NtServicePackUninstall$\useract.chm Object is locked skipped C:\WINDOWS\$NtServicePackUninstall$\userenv.dll Object is locked skipped C:\WINDOWS\$NtServicePackUninstall$\userinit.exe Object is locked skipped C:\WINDOWS\$NtServicePackUninstall$\usmtdef.inf Object is locked skipped C:\WINDOWS\$NtServicePackUninstall$\usp10.dll Object is locked skipped C:\WINDOWS\$NtServicePackUninstall$\utilman.exe Object is locked skipped C:\WINDOWS\$NtServicePackUninstall$\uxtheme.dll Object is locked skipped C:\WINDOWS\$NtServicePackUninstall$\vbajet32.dll Object is locked skipped C:\WINDOWS\$NtServicePackUninstall$\vbisurf.ax Object is locked skipped C:\WINDOWS\$NtServicePackUninstall$\vbscript.dll Object is locked skipped C:\WINDOWS\$NtServicePackUninstall$\vdmdbg.dll Object is locked skipped C:\WINDOWS\$NtServicePackUninstall$\vdmredir.dll Object is locked skipped C:\WINDOWS\$NtServicePackUninstall$\verdana.ttf Object is locked skipped C:\WINDOWS\$NtServicePackUninstall$\version.dll Object is locked skipped C:\WINDOWS\$NtServicePackUninstall$\vfwwdm32.dll Object is locked skipped C:\WINDOWS\$NtServicePackUninstall$\vga.sys Object is locked skipped C:\WINDOWS\$NtServicePackUninstall$\vgx.dll Object is locked skipped C:\WINDOWS\$NtServicePackUninstall$\viaagp.sys Object is locked skipped C:\WINDOWS\$NtServicePackUninstall$\viaide.sys Object is locked skipped C:\WINDOWS\$NtServicePackUninstall$\videoprt.sys Object is locked skipped C:\WINDOWS\$NtServicePackUninstall$\viewprov.dll Object is locked skipped C:\WINDOWS\$NtServicePackUninstall$\volsnap.sys Object is locked skipped C:\WINDOWS\$NtServicePackUninstall$\vssapi.dll Object is locked skipped C:\WINDOWS\$NtServicePackUninstall$\vssvc.exe Object is locked skipped C:\WINDOWS\$NtServicePackUninstall$\w32time.dll Object is locked skipped C:\WINDOWS\$NtServicePackUninstall$\w95upgnt.dll Object is locked skipped C:\WINDOWS\$NtServicePackUninstall$\wab.exe Object is locked skipped C:\WINDOWS\$NtServicePackUninstall$\wab32.dll Object is locked skipped C:\WINDOWS\$NtServicePackUninstall$\wab32res.dll Object is locked skipped C:\WINDOWS\$NtServicePackUninstall$\wabfind.dll Object is locked skipped C:\WINDOWS\$NtServicePackUninstall$\wabimp.dll Object is locked skipped C:\WINDOWS\$NtServicePackUninstall$\wabmig.exe Object is locked skipped C:\WINDOWS\$NtServicePackUninstall$\wadv01nt.sys Object is locked skipped C:\WINDOWS\$NtServicePackUninstall$\wadv02nt.sys Object is locked skipped C:\WINDOWS\$NtServicePackUninstall$\wadv05nt.sys Object is locked skipped C:\WINDOWS\$NtServicePackUninstall$\wanarp.sys Object is locked skipped C:\WINDOWS\$NtServicePackUninstall$\watchdog.sys Object is locked skipped C:\WINDOWS\$NtServicePackUninstall$\watv01nt.sys Object is locked skipped C:\WINDOWS\$NtServicePackUninstall$\watv02nt.sys Object is locked skipped C:\WINDOWS\$NtServicePackUninstall$\watv04nt.sys Object is locked skipped C:\WINDOWS\$NtServicePackUninstall$\wbemcntl.dll Object is locked skipped C:\WINDOWS\$NtServicePackUninstall$\wbemcomn.dll Object is locked skipped C:\WINDOWS\$NtServicePackUninstall$\wbemcons.dll Object is locked skipped C:\WINDOWS\$NtServicePackUninstall$\wbemcore.dll Object is locked skipped C:\WINDOWS\$NtServicePackUninstall$\wbemdisp.dll Object is locked skipped C:\WINDOWS\$NtServicePackUninstall$\wbemess.dll Object is locked skipped C:\WINDOWS\$NtServicePackUninstall$\wbemperf.dll Object is locked skipped C:\WINDOWS\$NtServicePackUninstall$\wbemprox.dll Object is locked skipped C:\WINDOWS\$NtServicePackUninstall$\wbemsvc.dll Object is locked skipped C:\WINDOWS\$NtServicePackUninstall$\wbemtest.exe Object is locked skipped C:\WINDOWS\$NtServicePackUninstall$\wbemupgd.dll Object is locked skipped C:\WINDOWS\$NtServicePackUninstall$\wch7xxnt.sys Object is locked skipped C:\WINDOWS\$NtServicePackUninstall$\wdigest.dll Object is locked skipped C:\WINDOWS\$NtServicePackUninstall$\wdmaud.drv Object is locked skipped C:\WINDOWS\$NtServicePackUninstall$\wdmaud.sys Object is locked skipped C:\WINDOWS\$NtServicePackUninstall$\wdma_ali.inf Object is locked skipped C:\WINDOWS\$NtServicePackUninstall$\wdma_int.inf Object is locked skipped C:\WINDOWS\$NtServicePackUninstall$\wdma_via.inf Object is locked skipped C:\WINDOWS\$NtServicePackUninstall$\webcheck.dll Object is locked skipped C:\WINDOWS\$NtServicePackUninstall$\webclnt.dll Object is locked skipped C:\WINDOWS\$NtServicePackUninstall$\webfldrs.msi Object is locked skipped C:\WINDOWS\$NtServicePackUninstall$\webpub.chm Object is locked skipped C:\WINDOWS\$NtServicePackUninstall$\webvw.dll Object is locked skipped C:\WINDOWS\$NtServicePackUninstall$\welcome.htm Object is locked skipped C:\WINDOWS\$NtServicePackUninstall$\wextract.exe Object is locked skipped C:\WINDOWS\$NtServicePackUninstall$\whatsnew.chm Object is locked skipped C:\WINDOWS\$NtServicePackUninstall$\wiaacmgr.exe Object is locked skipped C:\WINDOWS\$NtServicePackUninstall$\wiadefui.dll Object is locked skipped C:\WINDOWS\$NtServicePackUninstall$\wiadss.dll Object is locked skipped C:\WINDOWS\$NtServicePackUninstall$\wiascr.dll Object is locked skipped C:\WINDOWS\$NtServicePackUninstall$\wiaservc.dll Object is locked skipped C:\WINDOWS\$NtServicePackUninstall$\wiashext.dll Object is locked skipped C:\WINDOWS\$NtServicePackUninstall$\wiavideo.dll Object is locked skipped C:\WINDOWS\$NtServicePackUninstall$\win32k.sys Object is locked skipped C:\WINDOWS\$NtServicePackUninstall$\win32spl.dll Object is locked skipped C:\WINDOWS\$NtServicePackUninstall$\windows.chq Object is locked skipped C:\WINDOWS\$NtServicePackUninstall$\winhlp32.exe Object is locked skipped C:\WINDOWS\$NtServicePackUninstall$\wininet.dll Object is locked skipped C:\WINDOWS\$NtServicePackUninstall$\winipsec.dll Object is locked skipped C:\WINDOWS\$NtServicePackUninstall$\winlogon.exe Object is locked skipped C:\WINDOWS\$NtServicePackUninstall$\winmm.dll Object is locked skipped C:\WINDOWS\$NtServicePackUninstall$\winntbbu.dll Object is locked skipped C:\WINDOWS\$NtServicePackUninstall$\winrnr.dll Object is locked skipped C:\WINDOWS\$NtServicePackUninstall$\winscard.dll Object is locked skipped C:\WINDOWS\$NtServicePackUninstall$\winspool.drv Object is locked skipped C:\WINDOWS\$NtServicePackUninstall$\winsrv.dll Object is locked skipped C:\WINDOWS\$NtServicePackUninstall$\winsta.dll Object is locked skipped C:\WINDOWS\$NtServicePackUninstall$\wintrust.dll Object is locked skipped C:\WINDOWS\$NtServicePackUninstall$\winver.exe Object is locked skipped C:\WINDOWS\$NtServicePackUninstall$\wkssvc.dll Object is locked skipped C:\WINDOWS\$NtServicePackUninstall$\wldap32.dll Object is locked skipped C:\WINDOWS\$NtServicePackUninstall$\wlnotify.dll Object is locked skipped C:\WINDOWS\$NtServicePackUninstall$\wmadmod.dll Object is locked skipped C:\WINDOWS\$NtServicePackUninstall$\wmadmoe.dll Object is locked skipped C:\WINDOWS\$NtServicePackUninstall$\wmasf.dll Object is locked skipped C:\WINDOWS\$NtServicePackUninstall$\wmdmlog.dll Object is locked skipped C:\WINDOWS\$NtServicePackUninstall$\wmdmps.dll Object is locked skipped C:\WINDOWS\$NtServicePackUninstall$\wmerrenu.cat Object is locked skipped C:\WINDOWS\$NtServicePackUninstall$\wmi.dll Object is locked skipped C:\WINDOWS\$NtServicePackUninstall$\wmi.mof Object is locked skipped C:\WINDOWS\$NtServicePackUninstall$\wmiadap.exe Object is locked skipped C:\WINDOWS\$NtServicePackUninstall$\wmiapres.dll Object is locked skipped C:\WINDOWS\$NtServicePackUninstall$\wmiaprpl.dll Object is locked skipped C:\WINDOWS\$NtServicePackUninstall$\wmiapsrv.exe Object is locked skipped C:\WINDOWS\$NtServicePackUninstall$\wmicookr.dll Object is locked skipped C:\WINDOWS\$NtServicePackUninstall$\wmidcprv.dll Object is locked skipped C:\WINDOWS\$NtServicePackUninstall$\wmipcima.dll Object is locked skipped C:\WINDOWS\$NtServicePackUninstall$\wmipdskq.dll Object is locked skipped C:\WINDOWS\$NtServicePackUninstall$\wmipiprt.dll Object is locked skipped C:\WINDOWS\$NtServicePackUninstall$\wmipjobj.dll Object is locked skipped C:\WINDOWS\$NtServicePackUninstall$\wmiprov.dll Object is locked skipped C:\WINDOWS\$NtServicePackUninstall$\wmiprvsd.dll Object is locked skipped C:\WINDOWS\$NtServicePackUninstall$\wmiprvse.exe Object is locked skipped C:\WINDOWS\$NtServicePackUninstall$\wmipsess.dll Object is locked skipped C:\WINDOWS\$NtServicePackUninstall$\wmisvc.dll Object is locked skipped C:\WINDOWS\$NtServicePackUninstall$\wmiutils.dll Object is locked skipped C:\WINDOWS\$NtServicePackUninstall$\wmnetmgr.dll Object is locked skipped C:\WINDOWS\$NtServicePackUninstall$\wmp.inf Object is locked skipped C:\WINDOWS\$NtServicePackUninstall$\wmp.ocx Object is locked skipped C:\WINDOWS\$NtServicePackUninstall$\wmpcd.dll Object is locked skipped C:\WINDOWS\$NtServicePackUninstall$\wmpcore.dll Object is locked skipped C:\WINDOWS\$NtServicePackUninstall$\wmplayer.chm Object is locked skipped C:\WINDOWS\$NtServicePackUninstall$\wmplayer.exe Object is locked skipped C:\WINDOWS\$NtServicePackUninstall$\wmploc.dll Object is locked skipped C:\WINDOWS\$NtServicePackUninstall$\wmpshell.dll Object is locked skipped C:\WINDOWS\$NtServicePackUninstall$\wmpui.dll Object is locked skipped C:\WINDOWS\$NtServicePackUninstall$\wmsdmod.dll Object is locked skipped C:\WINDOWS\$NtServicePackUninstall$\wmsdmoe.dll Object is locked skipped C:\WINDOWS\$NtServicePackUninstall$\wmstream.dll Object is locked skipped C:\WINDOWS\$NtServicePackUninstall$\wmv8ds32.ax Object is locked skipped C:\WINDOWS\$NtServicePackUninstall$\wmvcore.dll Object is locked skipped C:\WINDOWS\$NtServicePackUninstall$\wmvdmod.dll Object is locked skipped C:\WINDOWS\$NtServicePackUninstall$\wmvds32.ax Object is locked skipped C:\WINDOWS\$NtServicePackUninstall$\wordpad.exe Object is locked skipped C:\WINDOWS\$NtServicePackUninstall$\wordpad.inf Object is locked skipped C:\WINDOWS\$NtServicePackUninstall$\wow32.dll Object is locked skipped C:\WINDOWS\$NtServicePackUninstall$\wpabaln.exe Object is locked skipped C:\WINDOWS\$NtServicePackUninstall$\wpnpinst.exe Object is locked skipped C:\WINDOWS\$NtServicePackUninstall$\ws2help.dll Object is locked skipped C:\WINDOWS\$NtServicePackUninstall$\ws2_32.dll Object is locked skipped C:\WINDOWS\$NtServicePackUninstall$\wscript.exe Object is locked skipped C:\WINDOWS\$NtServicePackUninstall$\wshcon.dll Object is locked skipped C:\WINDOWS\$NtServicePackUninstall$\wshext.dll Object is locked skipped C:\WINDOWS\$NtServicePackUninstall$\wship6.dll Object is locked skipped C:\WINDOWS\$NtServicePackUninstall$\wshom.ocx Object is locked skipped C:\WINDOWS\$NtServicePackUninstall$\wshrm.dll Object is locked skipped C:\WINDOWS\$NtServicePackUninstall$\wshtcpip.dll Object is locked skipped C:\WINDOWS\$NtServicePackUninstall$\wsiintxx.sys Object is locked skipped C:\WINDOWS\$NtServicePackUninstall$\wsnmp32.dll Object is locked skipped C:\WINDOWS\$NtServicePackUninstall$\wsock32.dll Object is locked skipped C:\WINDOWS\$NtServicePackUninstall$\wstcodec.inf Object is locked skipped C:\WINDOWS\$NtServicePackUninstall$\wstdecod.dll Object is locked skipped C:\WINDOWS\$NtServicePackUninstall$\wtsapi32.dll Object is locked skipped C:\WINDOWS\$NtServicePackUninstall$\wuauclt.exe Object is locked skipped C:\WINDOWS\$NtServicePackUninstall$\wuaueng.dll Object is locked skipped C:\WINDOWS\$NtServicePackUninstall$\wuauserv.dll Object is locked skipped C:\WINDOWS\$NtServicePackUninstall$\wupdinfo.dll Object is locked skipped C:\WINDOWS\$NtServicePackUninstall$\wuv3is.dll Object is locked skipped C:\WINDOWS\$NtServicePackUninstall$\wvchntxx.sys Object is locked skipped C:\WINDOWS\$NtServicePackUninstall$\wzcdlg.dll Object is locked skipped C:\WINDOWS\$NtServicePackUninstall$\wzcsapi.dll Object is locked skipped C:\WINDOWS\$NtServicePackUninstall$\wzcsvc.dll Object is locked skipped C:\WINDOWS\$NtServicePackUninstall$\xactsrv.dll Object is locked skipped C:\WINDOWS\$NtServicePackUninstall$\xbp3tb9z.dat Object is locked skipped C:\WINDOWS\$NtServicePackUninstall$\xcopy.exe Object is locked skipped C:\WINDOWS\$NtServicePackUninstall$\xenroll.dll Object is locked skipped C:\WINDOWS\$NtServicePackUninstall$\xolehlp.dll Object is locked skipped C:\WINDOWS\$NtServicePackUninstall$\xvzt3bln.zip Object is locked skipped C:\WINDOWS\$NtServicePackUninstall$\z9f7zr79.dat Object is locked skipped C:\WINDOWS\$NtServicePackUninstall$\zipfldr.dll Object is locked skipped C:\WINDOWS\$NtUninstallKB828741$\catsrv.dll Object is locked skipped C:\WINDOWS\$NtUninstallKB828741$\catsrvut.dll Object is locked skipped C:\WINDOWS\$NtUninstallKB828741$\clbcatex.dll Object is locked skipped C:\WINDOWS\$NtUninstallKB828741$\clbcatq.dll Object is locked skipped C:\WINDOWS\$NtUninstallKB828741$\colbact.dll Object is locked skipped C:\WINDOWS\$NtUninstallKB828741$\comadmin.dll Object is locked skipped C:\WINDOWS\$NtUninstallKB828741$\comsvcs.dll Object is locked skipped C:\WINDOWS\$NtUninstallKB828741$\comuid.dll Object is locked skipped C:\WINDOWS\$NtUninstallKB828741$\es.dll Object is locked skipped C:\WINDOWS\$NtUninstallKB828741$\kb828741.cat Object is locked skipped C:\WINDOWS\$NtUninstallKB828741$\msdtcprx.dll Object is locked skipped C:\WINDOWS\$NtUninstallKB828741$\msdtctm.dll Object is locked skipped C:\WINDOWS\$NtUninstallKB828741$\msdtcuiu.dll Object is locked skipped C:\WINDOWS\$NtUninstallKB828741$\mtxclu.dll Object is locked skipped C:\WINDOWS\$NtUninstallKB828741$\mtxoci.dll Object is locked skipped C:\WINDOWS\$NtUninstallKB828741$\ole32.dll Object is locked skipped C:\WINDOWS\$NtUninstallKB828741$\rpcrt4.dll Object is locked skipped C:\WINDOWS\$NtUninstallKB828741$\rpcss.dll Object is locked skipped C:\WINDOWS\$NtUninstallKB828741$\txflog.dll Object is locked skipped C:\WINDOWS\$NtUninstallKB828741_RTM$\catsrv.dll Object is locked skipped C:\WINDOWS\$NtUninstallKB828741_RTM$\catsrvut.dll Object is locked skipped C:\WINDOWS\$NtUninstallKB828741_RTM$\clbcatex.dll Object is locked skipped C:\WINDOWS\$NtUninstallKB828741_RTM$\clbcatq.dll Object is locked skipped C:\WINDOWS\$NtUninstallKB828741_RTM$\colbact.dll Object is locked skipped C:\WINDOWS\$NtUninstallKB828741_RTM$\comadmin.dll Object is locked skipped C:\WINDOWS\$NtUninstallKB828741_RTM$\comrepl.exe Object is locked skipped C:\WINDOWS\$NtUninstallKB828741_RTM$\comsvcs.dll Object is locked skipped C:\WINDOWS\$NtUninstallKB828741_RTM$\comuid.dll Object is locked skipped C:\WINDOWS\$NtUninstallKB828741_RTM$\es.dll Object is locked skipped C:\WINDOWS\$NtUninstallKB828741_RTM$\migregdb.exe Object is locked skipped C:\WINDOWS\$NtUninstallKB828741_RTM$\msdtcprx.dll Object is locked skipped C:\WINDOWS\$NtUninstallKB828741_RTM$\msdtctm.dll Object is locked skipped C:\WINDOWS\$NtUninstallKB828741_RTM$\msdtcuiu.dll Object is locked skipped C:\WINDOWS\$NtUninstallKB828741_RTM$\mtxclu.dll Object is locked skipped C:\WINDOWS\$NtUninstallKB828741_RTM$\mtxoci.dll Object is locked skipped C:\WINDOWS\$NtUninstallKB828741_RTM$\ole32.dll Object is locked skipped C:\WINDOWS\$NtUninstallKB828741_RTM$\rpcrt4.dll Object is locked skipped C:\WINDOWS\$NtUninstallKB828741_RTM$\rpcss.dll Object is locked skipped C:\WINDOWS\$NtUninstallKB828741_RTM$\txflog.dll Object is locked skipped C:\WINDOWS\$NtUninstallKB833987$\kb833987.cat Object is locked skipped C:\WINDOWS\$NtUninstallKB833987_RTM$\sxs.dll Object is locked skipped C:\WINDOWS\$NtUninstallKB835732$\callcont.dll Object is locked skipped C:\WINDOWS\$NtUninstallKB835732$\evtgprov.dll Object is locked skipped C:\WINDOWS\$NtUninstallKB835732$\h323.tsp Object is locked skipped C:\WINDOWS\$NtUninstallKB835732$\h323msp.dll Object is locked skipped C:\WINDOWS\$NtUninstallKB835732$\helpctr.exe Object is locked skipped C:\WINDOWS\$NtUninstallKB835732$\ipnathlp.dll Object is locked skipped C:\WINDOWS\$NtUninstallKB835732$\kb835732.cat Object is locked skipped C:\WINDOWS\$NtUninstallKB835732$\lsasrv.dll Object is locked skipped C:\WINDOWS\$NtUninstallKB835732$\msasn1.dll Object is locked skipped C:\WINDOWS\$NtUninstallKB835732$\msgina.dll Object is locked skipped C:\WINDOWS\$NtUninstallKB835732$\mst120.dll Object is locked skipped C:\WINDOWS\$NtUninstallKB835732$\netapi32.dll Object is locked skipped C:\WINDOWS\$NtUninstallKB835732$\nmcom.dll Object is locked skipped C:\WINDOWS\$NtUninstallKB835732$\rtcdll.dll Object is locked skipped C:\WINDOWS\$NtUninstallKB835732$\schannel.dll Object is locked skipped C:\WINDOWS\$NtUninstallKB835732_RTM$\browser.dll Object is locked skipped C:\WINDOWS\$NtUninstallKB835732_RTM$\callcont.dll Object is locked skipped C:\WINDOWS\$NtUninstallKB835732_RTM$\gdi32.dll Object is locked skipped C:\WINDOWS\$NtUninstallKB835732_RTM$\h323.tsp Object is locked skipped C:\WINDOWS\$NtUninstallKB835732_RTM$\h323msp.dll Object is locked skipped C:\WINDOWS\$NtUninstallKB835732_RTM$\helpctr.exe Object is locked skipped C:\WINDOWS\$NtUninstallKB835732_RTM$\ipnathlp.dll Object is locked skipped C:\WINDOWS\$NtUninstallKB835732_RTM$\lsasrv.dll Object is locked skipped C:\WINDOWS\$NtUninstallKB835732_RTM$\mf3216.dll Object is locked skipped C:\WINDOWS\$NtUninstallKB835732_RTM$\msasn1.dll Object is locked skipped C:\WINDOWS\$NtUninstallKB835732_RTM$\msgina.dll Object is locked skipped C:\WINDOWS\$NtUninstallKB835732_RTM$\mst120.dll Object is locked skipped C:\WINDOWS\$NtUninstallKB835732_RTM$\netapi32.dll Object is locked skipped C:\WINDOWS\$NtUninstallKB835732_RTM$\nmcom.dll Object is locked skipped C:\WINDOWS\$NtUninstallKB835732_RTM$\rtcdll.dll Object is locked skipped C:\WINDOWS\$NtUninstallKB835732_RTM$\schannel.dll Object is locked skipped C:\WINDOWS\$NtUninstallQ329048$\reg00001 Object is locked skipped C:\WINDOWS\$NtUninstallQ329390$\reg00001 Object is locked skipped C:\WINDOWS\$NtUninstallQ329834$\reg00001 Object is locked skipped C:\WINDOWS\Debug\PASSWD.LOG Object is locked skipped C:\WINDOWS\Downloaded Program Files\CONFLICT.1\popcaploader.dll Infected: not-a-virus:Downloader.Win32.PopCap.b skipped C:\WINDOWS\Downloaded Program Files\popcaploader.dll Infected: not-a-virus:Downloader.Win32.PopCap.b skipped C:\WINDOWS\Internet Logs\fwdbglog.txt Object is locked skipped C:\WINDOWS\Internet Logs\fwpktlog.txt Object is locked skipped C:\WINDOWS\Internet Logs\IAMDB.RDB Object is locked skipped C:\WINDOWS\Internet Logs\RACHAEL.ldb Object is locked skipped C:\WINDOWS\Internet Logs\tvDebug.log Object is locked skipped C:\WINDOWS\SchedLgU.Txt Object is locked skipped C:\WINDOWS\SoftwareDistribution\EventCache\{C12B6E7C-4231-45BE-A106-2086FD33ABAB}.bin Object is locked skipped C:\WINDOWS\SoftwareDistribution\ReportingEvents.log Object is locked skipped C:\WINDOWS\Sti_Trace.log Object is locked skipped C:\WINDOWS\system32\CatRoot2\edb.log Object is locked skipped C:\WINDOWS\system32\CatRoot2\tmp.edb Object is locked skipped C:\WINDOWS\system32\config\AppEvent.Evt Object is locked skipped C:\WINDOWS\system32\config\default Object is locked skipped C:\WINDOWS\system32\config\default.LOG Object is locked skipped C:\WINDOWS\system32\config\Internet.evt Object is locked skipped C:\WINDOWS\system32\config\SAM Object is locked skipped C:\WINDOWS\system32\config\SAM.LOG Object is locked skipped C:\WINDOWS\system32\config\SecEvent.Evt Object is locked skipped C:\WINDOWS\system32\config\SECURITY Object is locked skipped C:\WINDOWS\system32\config\SECURITY.LOG Object is locked skipped C:\WINDOWS\system32\config\software Object is locked skipped C:\WINDOWS\system32\config\software.LOG Object is locked skipped C:\WINDOWS\system32\config\SysEvent.Evt Object is locked skipped C:\WINDOWS\system32\config\system Object is locked skipped C:\WINDOWS\system32\config\system.LOG Object is locked skipped C:\WINDOWS\system32\h323log.txt Object is locked skipped C:\WINDOWS\system32\wbem\Repository\FS\INDEX.BTR Object is locked skipped C:\WINDOWS\system32\wbem\Repository\FS\INDEX.MAP Object is locked skipped C:\WINDOWS\system32\wbem\Repository\FS\MAPPING.VER Object is locked skipped C:\WINDOWS\system32\wbem\Repository\FS\MAPPING1.MAP Object is locked skipped C:\WINDOWS\system32\wbem\Repository\FS\MAPPING2.MAP Object is locked skipped C:\WINDOWS\system32\wbem\Repository\FS\OBJECTS.DATA Object is locked skipped C:\WINDOWS\system32\wbem\Repository\FS\OBJECTS.MAP Object is locked skipped C:\WINDOWS\temp\Perflib_Perfdata_704.dat Object is locked skipped C:\WINDOWS\temp\Perflib_Perfdata_e4.dat Object is locked skipped C:\WINDOWS\temp\ZLT03015.TMP Object is locked skipped C:\WINDOWS\temp\ZLT03018.TMP Object is locked skipped C:\WINDOWS\wiadebug.log Object is locked skipped C:\WINDOWS\wiaservc.log Object is locked skipped C:\WINDOWS\WindowsUpdate.log Object is locked skipped G:\New Items to be included in Drive C\Additonal Programs that may need to be moved\Magical Jellybean Keyfinder\Magical Jellybean Keyfinder V 1.41.exe/data.rar/xpkey.exe Infected: not-a-virus:PSWTool.Win32.RAS.a skipped G:\New Items to be included in Drive C\Additonal Programs that may need to be moved\Magical Jellybean Keyfinder\Magical Jellybean Keyfinder V 1.41.exe/data.rar/officekey.exe Infected: not-a-virus:PSWTool.Win32.RAS.a skipped G:\New Items to be included in Drive C\Additonal Programs that may need to be moved\Magical Jellybean Keyfinder\Magical Jellybean Keyfinder V 1.41.exe/data.rar Infected: not-a-virus:PSWTool.Win32.RAS.a skipped G:\New Items to be included in Drive C\Additonal Programs that may need to be moved\Magical Jellybean Keyfinder\Magical Jellybean Keyfinder V 1.41.exe RarSFX: infected - 3 skipped G:\New Items to be included in Drive C\Additonal Programs that may need to be moved\Downloaded Programs\Baby Goats Desktop Theme.exe/WISE0014.BIN Infected: not-a-virus:AdWare.Win32.EZula.j skipped G:\New Items to be included in Drive C\Additonal Programs that may need to be moved\Downloaded Programs\Baby Goats Desktop Theme.exe/WISE0015.BIN/data0002 Infected: not-a-virus:AdWare.Win32.Sidesearch.d skipped G:\New Items to be included in Drive C\Additonal Programs that may need to be moved\Downloaded Programs\Baby Goats Desktop Theme.exe/WISE0015.BIN Infected: not-a-virus:AdWare.Win32.Sidesearch.d skipped G:\New Items to be included in Drive C\Additonal Programs that may need to be moved\Downloaded Programs\Baby Goats Desktop Theme.exe WiseSFX: infected - 3 skipped G:\New Items to be included in Drive C\Additonal Programs that may need to be moved\Downloaded Programs\Book of Mormon Verse Screensaver.exe/WISE0018.BIN/data0003/data0002 Infected: not-a-virus:AdWare.Win32.BargainBuddy.l skipped G:\New Items to be included in Drive C\Additonal Programs that may need to be moved\Downloaded Programs\Book of Mormon Verse Screensaver.exe/WISE0018.BIN/data0003/data0003 Infected: not-a-virus:AdWare.Win32.BargainBuddy.a skipped G:\New Items to be included in Drive C\Additonal Programs that may need to be moved\Downloaded Programs\Book of Mormon Verse Screensaver.exe/WISE0018.BIN/data0003 Infected: not-a-virus:AdWare.Win32.BargainBuddy.a skipped G:\New Items to be included in Drive C\Additonal Programs that may need to be moved\Downloaded Programs\Book of Mormon Verse Screensaver.exe/WISE0018.BIN Infected: not-a-virus:AdWare.Win32.BargainBuddy.a skipped G:\New Items to be included in Drive C\Additonal Programs that may need to be moved\Downloaded Programs\Book of Mormon Verse Screensaver.exe WiseSFX: infected - 4 skipped G:\New Items to be included in Drive C\Additonal Programs that may need to be moved\Downloaded Programs\Computerbug 2 Desktop Theme.exe/WISE0015.BIN/data0002 Infected: not-a-virus:AdWare.Win32.Sidesearch.d skipped G:\New Items to be included in Drive C\Additonal Programs that may need to be moved\Downloaded Programs\Computerbug 2 Desktop Theme.exe/WISE0015.BIN Infected: not-a-virus:AdWare.Win32.Sidesearch.d skipped G:\New Items to be included in Drive C\Additonal Programs that may need to be moved\Downloaded Programs\Computerbug 2 Desktop Theme.exe/WISE0016.BIN Infected: not-a-virus:AdWare.Win32.Gator.3103 skipped G:\New Items to be included in Drive C\Additonal Programs that may need to be moved\Downloaded Programs\Computerbug 2 Desktop Theme.exe/WISE0017.BIN Infected: not-a-virus:AdWare.Win32.NewDotNet skipped G:\New Items to be included in Drive C\Additonal Programs that may need to be moved\Downloaded Programs\Computerbug 2 Desktop Theme.exe WiseSFX: infected - 4 skipped G:\New Items to be included in Drive C\Additonal Programs that may need to be moved\Downloaded Programs\Mackinac Bridge Desktop Theme.exe/WISE0014.BIN/data0002 Infected: not-a-virus:AdWare.Win32.Sidesearch.d skipped G:\New Items to be included in Drive C\Additonal Programs that may need to be moved\Downloaded Programs\Mackinac Bridge Desktop Theme.exe/WISE0014.BIN Infected: not-a-virus:AdWare.Win32.Sidesearch.d skipped G:\New Items to be included in Drive C\Additonal Programs that may need to be moved\Downloaded Programs\Mackinac Bridge Desktop Theme.exe/WISE0015.BIN/WISE0011.BIN Infected: not-a-virus:AdWare.Win32.Exact.a skipped G:\New Items to be included in Drive C\Additonal Programs that may need to be moved\Downloaded Programs\Mackinac Bridge Desktop Theme.exe/WISE0015.BIN/WISE0012.BIN Infected: not-a-virus:AdWare.Win32.Exact.a skipped G:\New Items to be included in Drive C\Additonal Programs that may need to be moved\Downloaded Programs\Mackinac Bridge Desktop Theme.exe/WISE0015.BIN/WISE0013.BIN Infected: not-a-virus:AdWare.Win32.Exact.a skipped G:\New Items to be included in Drive C\Additonal Programs that may need to be moved\Downloaded Programs\Mackinac Bridge Desktop Theme.exe/WISE0015.BIN Infected: not-a-virus:AdWare.Win32.Exact.a skipped G:\New Items to be included in Drive C\Additonal Programs that may need to be moved\Downloaded Programs\Mackinac Bridge Desktop Theme.exe/WISE0016.BIN Infected: not-a-virus:AdWare.Win32.NewDotNet skipped G:\New Items to be included in Drive C\Additonal Programs that may need to be moved\Downloaded Programs\Mackinac Bridge Desktop Theme.exe WiseSFX: infected - 7 skipped G:\New Items to be included in Drive C\Additonal Programs that may need to be moved\Downloaded Programs\Sponge Bob Theme.exe/WISE0018.BIN Infected: not-a-virus:AdWare.Win32.Quick.a skipped G:\New Items to be included in Drive C\Additonal Programs that may need to be moved\Downloaded Programs\Sponge Bob Theme.exe/WISE0019.BIN Infected: not-a-virus:AdWare.Win32.NewDotNet skipped G:\New Items to be included in Drive C\Additonal Programs that may need to be moved\Downloaded Programs\Sponge Bob Theme.exe/WISE0020.BIN Infected: not-a-virus:AdWare.Win32.WebRebates.t skipped G:\New Items to be included in Drive C\Additonal Programs that may need to be moved\Downloaded Programs\Sponge Bob Theme.exe/WISE0021.BIN Infected: not-a-virus:AdWare.Win32.EZula.u skipped G:\New Items to be included in Drive C\Additonal Programs that may need to be moved\Downloaded Programs\Sponge Bob Theme.exe/WISE0022.BIN Infected: not-a-virus:AdWare.Win32.Gator.3103 skipped G:\New Items to be included in Drive C\Additonal Programs that may need to be moved\Downloaded Programs\Sponge Bob Theme.exe WiseSFX: infected - 5 skipped G:\System Volume Information\_restore{07067F02-601B-445E-AF8E-8602C05A674E}\RP8\change.log Object is locked skipped Scan process completed. Combofix log & new Hijack This Log in next posting...

#10 Master Luke

Master Luke

    New Member

  • Authentic Member
  • Pip
  • 8 posts

Posted 20 August 2007 - 03:07 PM

LOGFILES (PART THREE)

Combofix scan from a few minutes ago:
ComboFix 07-08-17.2 - "Master Luke" 2007-08-20 14:18:54.3 - NTFSx86
Microsoft Windows XP Home Edition 5.1.2600.2.1252.1.1033.18.174 [GMT -6:00]
* Created a new restore point


((((((((((((((((((((((((( Files Created from 2007-07-20 to 2007-08-20 )))))))))))))))))))))))))))))))


2007-08-19 22:07 <DIR> d-------- C:\DOCUME~1\ALLUSE~1\APPLIC~1\Kaspersky Lab
2007-08-19 22:06 <DIR> d-------- C:\WINDOWS\system32\Kaspersky Lab
2007-08-19 22:06 <DIR> d-------- C:\WINDOWS\LastGood
2007-08-14 16:46 51,200 --a------ C:\WINDOWS\nircmd.exe
2007-08-11 13:13 <DIR> d-------- C:\WINDOWS\system32\ActiveScan
2007-08-11 11:36 1,048,576 --ah----- C:\DOCUME~1\JESS\NTUSER.DAT
2007-08-11 11:36 <DIR> d-------- C:\DOCUME~1\JESS\WINDOWS
2007-08-11 11:36 <DIR> d-------- C:\DOCUME~1\JESS\APPLIC~1\VERITAS
2007-08-11 11:36 <DIR> d-------- C:\DOCUME~1\JESS\APPLIC~1\Symantec
2007-08-11 11:36 <DIR> d-------- C:\DOCUME~1\JESS\APPLIC~1\InterTrust
2007-08-11 11:36 <DIR> d-------- C:\DOCUME~1\JESS\APPLIC~1\Corel
2007-08-09 22:14 1,310,720 --ah----- C:\DOCUME~1\ADMINI~1.RAC\NTUSER.DAT
2007-08-09 22:14 <DIR> d-------- C:\DOCUME~1\ADMINI~1.RAC\WINDOWS
2007-08-09 22:14 <DIR> d-------- C:\DOCUME~1\ADMINI~1.RAC\APPLIC~1\VERITAS
2007-08-09 22:14 <DIR> d-------- C:\DOCUME~1\ADMINI~1.RAC\APPLIC~1\Symantec
2007-08-09 22:14 <DIR> d-------- C:\DOCUME~1\ADMINI~1.RAC\APPLIC~1\InterTrust
2007-08-09 22:14 <DIR> d-------- C:\DOCUME~1\ADMINI~1.RAC\APPLIC~1\Corel
2007-08-08 10:40 <DIR> d-------- C:\DOCUME~1\ALLUSE~1\APPLIC~1\WinZip
2007-08-08 10:31 <DIR> d-------- C:\DOCUME~1\MASTER~2\APPLIC~1\WinRAR
2007-08-06 22:24 <DIR> d-------- C:\DOCUME~1\ALLUSE~1\APPLIC~1\YAHOO
2007-08-06 22:23 <DIR> d-------- C:\Program Files\Common Files\SureThing Shared
2007-07-24 10:30 <DIR> d-------- C:\DOCUME~1\MASTER~2\APPLIC~1\Lavasoft
2007-07-20 18:38 <DIR> d-------- C:\DOCUME~1\MASTER~2\APPLIC~1\Real


(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))

2007-08-20 00:00 --------- d-------- C:\Program Files\SpeedFan
2007-08-19 07:54 --------- d-------- C:\Program Files\HS
2007-08-18 20:24 --------- d-------- C:\Program Files\Common Files\Symantec Shared
2007-08-14 20:50 --------- d-------- C:\Program Files\WildTangent
2007-08-14 20:47 --------- d-------- C:\Program Files\PeoplePC
2007-08-06 22:24 --------- d-------- C:\Program Files\Yahoo!
2007-08-06 11:18 --------- d-------- C:\Program Files\iTunes
2007-08-06 11:18 --------- d-------- C:\Program Files\iPod
2007-07-21 18:48 --------- d-------- C:\Program Files\Replay7
2007-07-21 09:20 --------- d-------- C:\DOCUME~1\MASTER~2\APPLIC~1\Winamp
2007-07-20 18:42 --------- d-------- C:\Program Files\Common Files\Real
2007-07-16 19:17 --------- d-------- C:\DOCUME~1\MASTER~2\APPLIC~1\Ahead
2007-07-16 18:51 --------- d-------- C:\DOCUME~1\MASTER~2\APPLIC~1\Apple Computer
2007-07-12 12:02 --------- d-------- C:\Program Files\QuickTime
2007-07-12 11:49 --------- d-------- C:\Program Files\Apple Software Update
2007-07-12 11:43 --------- d-------- C:\Program Files\Common Files\Apple
2007-07-11 00:50 --------- d-------- C:\Program Files\STARWARS
2007-06-29 15:23 --------- d-------- C:\Program Files\Common Files\Motive
2007-06-29 00:25 --------- d-------- C:\Program Files\MSN Messenger
2007-06-28 11:51 --------- d-------- C:\Program Files\FreedomBox 2.0
2007-06-28 11:51 --------- d-------- C:\DOCUME~1\MASTER~2\APPLIC~1\FreedomBox
2007-06-26 00:08 1104896 --a------ C:\WINDOWS\system32\msxml3.dll
2007-06-23 16:07 --------- d-------- C:\Program Files\Virtual Assistant
2007-06-23 15:10 --------- d-------- C:\Program Files\Motive
2007-06-23 01:17 --------- d-------- C:\Program Files\Aveo
2007-06-19 07:31 282112 --a------ C:\WINDOWS\system32\gdi32.dll
2007-06-13 04:23 1033216 --a------ C:\WINDOWS\explorer.exe
2007-06-08 20:06 44 --a------ C:\WINDOWS\system32\msssc.dll
2007-05-26 03:27 737280 --a------ C:\WINDOWS\iun6002.exe
2007-05-26 00:53 9728 --a------ C:\WINDOWS\system32\UnInstall BibleVerseArt4.exe
2007-05-26 00:53 4521290 --a------ C:\WINDOWS\system32\BibleVerseArt4.scr
2007-05-24 00:36 3576 --a------ C:\WINDOWS\pchealth\HELPCTR\PackageStore\SkuStore.bin
2007-05-24 00:34 9546 --a------ C:\WINDOWS\pchealth\HELPCTR\Config\Cntstore.bin
2002-07-09 08:46 53701 --a------ C:\WINDOWS\inf\Gemplus\gcr432.sys
2002-07-09 08:46 28864 --a------ C:\WINDOWS\inf\Gemplus\GCR412.sys
2001-08-18 12:00:00 94,784 --sh--w C:\WINDOWS\twain.dll
2004-08-04 05:56:48 50,688 --sh--w C:\WINDOWS\twain_32.dll
2004-08-04 05:56:44 1,028,096 --sha-w C:\WINDOWS\system32\mfc42.dll
2004-08-04 05:56:44 54,784 --sha-w C:\WINDOWS\system32\msvcirt.dll
2004-08-04 05:56:44 413,696 --sha-w C:\WINDOWS\system32\msvcp60.dll
2004-08-04 05:56:44 343,040 --sha-w C:\WINDOWS\system32\msvcrt.dll
2007-05-17 11:28:05 549,376 --sha-w C:\WINDOWS\system32\oleaut32.dll
2004-08-04 05:56:46 83,456 --sha-w C:\WINDOWS\system32\olepro32.dll
2004-08-04 05:56:56 11,776 --sha-w C:\WINDOWS\system32\regsvr32.exe
2006-06-23 03:43:02 68 --sha-w C:\WINDOWS\system32\windzfa0.sys


((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))


*Note* empty entries & legit default entries are not shown

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{A8FB8EB3-183B-4598-924D-86F0E5E37085}]
C:\Program Files\PeoplePC\Toolbar\PPCToolbar.dll

[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser]
"{A8FB8EB3-183B-4598-924D-86F0E5E37085}"= C:\Program Files\PeoplePC\Toolbar\PPCToolbar.dll [ ]

[HKEY_CLASSES_ROOT\CLSID\{A8FB8EB3-183B-4598-924D-86F0E5E37085}]
[HKEY_CLASSES_ROOT\PeoplePal Toolbar]
[HKEY_CLASSES_ROOT\TypeLib\{994D628D-4D22-4DB9-B6DB-F7D9F1635817}]
[HKEY_CLASSES_ROOT\PeoplePal Toolbar]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"hpsysdrv"="c:\windows\system\hpsysdrv.exe" [1998-05-07 17:04]
"PreloadApp"="c:\hp\drivers\printers\photosmart\hphprld.exe" [2001-12-13 00:05]
"KBD"="C:\HP\KBD\KBD.EXE" [2001-07-06 21:56]
"Recguard"="C:\WINDOWS\SMINST\RECGUARD.EXE" [2001-12-19 00:39]
"IgfxTray"="C:\WINDOWS\System32\igfxtray.exe" [2001-08-08 01:25]
"HotKeysCmds"="C:\WINDOWS\System32\hkcmd.exe" [2001-08-08 00:36]
"NvCplDaemon"="NvQTwk" []
"nwiz"="nwiz.exe" [2002-03-09 17:53 C:\WINDOWS\system32\nwiz.exe]
"S3apphk"="S3apphk.exe" [2002-03-15 23:51 C:\WINDOWS\system32\S3apphk.exe]
"PS2"="C:\WINDOWS\system32\ps2.exe" [2001-07-03 21:13]
"LTMSG"="LTMSG.exe" [2003-07-14 10:52 C:\WINDOWS\ltmsg.exe]
"BluetoothAuthenticationAgent"="bthprops.cpl" [2004-08-04 00:56 C:\WINDOWS\system32\bthprops.cpl]
"ccApp"="C:\Program Files\Common Files\Symantec Shared\ccApp.exe" [2002-08-19 21:22]
"ccRegVfy"="C:\Program Files\Common Files\Symantec Shared\ccRegVfy.exe" [2002-08-19 21:23]
"GhostStartTrayApp"="C:\Program Files\Norton SystemWorks\Norton Ghost\GhostStartTrayApp.exe" [2002-08-14 14:21]
"PCTVRemote"="C:\Program Files\Pinnacle\Pinnacle PCTV\Remote\Remoterm.exe" [2002-01-28 18:12]
"FLMOFFICE4DMOUSE"="C:\Program Files\Labtec\Mouse\2.1\moffice.exe" [2007-05-24 02:17]
"ZoneAlarm Client"="C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe" [2007-03-08 23:02]
"hp Update 2100C"="C:\Program Files\Hewlett-Packard\HP PrecisionScan\sj644\hpupdate.exe" [2002-01-24 16:24]
"UltraSaver"="C:\Program Files\G7PS\4X UltraSaver\UltraSaver.exe" [2006-09-20 14:50]
"PrinTray"="C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\printray.exe" [2002-03-29 04:44]
"LXSUPMON"="C:\WINDOWS\system32\LXSUPMON.exe" [2002-03-29 04:44]
"Microsoft Works Portfolio"="C:\Program Files\Microsoft Works\WksSb.exe" [2001-08-23 22:52]
"Microsoft Works Update Detection"="C:\Program Files\Microsoft Works\WkDetect.exe" [2000-08-01 14:00]
"RemoteControl"="C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe" [2004-11-02 19:24]
"LWBKEYBOARD"="C:\Program Files\Labtec\Media Keyboard\V5.0\KbdAp32A.exe" [2005-01-28 04:23]
"NeroFilterCheck"="C:\WINDOWS\system32\NeroCheck.exe" [2001-07-09 10:50]
"InCD"="C:\Program Files\Ahead\InCD\InCD.exe" [2006-03-23 17:06]
"Motive SmartBridge"="C:\PROGRA~1\VIRTUA~1\SMARTB~1\SprintDSLAlert.exe" [2006-04-21 15:41]
"QuickTime Task"="C:\Program Files\QuickTime\QTTask.exe" [2007-06-29 06:24]
"SunJavaUpdateSched"="C:\Program Files\Java\jre1.6.0_02\bin\jusched.exe" [2007-07-12 04:00]
"TkBellExe"="C:\Program Files\Common Files\Real\Update_OB\realsched.exe" [2007-07-20 18:38]
"iTunesHelper"="C:\Program Files\iTunes\iTunesHelper.exe" [2007-07-31 18:44]

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"MsnMsgr"="C:\Program Files\MSN Messenger\MsnMsgr.exe" [2007-01-19 12:54]
"Microsoft Works Update Detection"="c:\Program Files\Microsoft Works\WkDetect.exe" [2000-08-01 14:00]
"updateMgr"="C:\Program Files\Adobe\Acrobat 7.0\Reader\AdobeUpdateManager.exe" [2006-03-30 16:45]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-03 23:56]

C:\Documents and Settings\All Users\Start Menu\Programs\Startup\
APC UPS Status.lnk - C:\Program Files\APC\APC PowerChute Personal Edition\Display.exe [2007-05-25 00:09:05]
Bluetooth Manager.lnk - C:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosBtMng.exe [2007-01-18 14:48:42]
PowerMenu.lnk - C:\Program Files\PowerMenu\PowerMenu.exe [2007-04-13 21:47:19]
SpeedFan 4.28.lnk - C:\Program Files\SpeedFan\speedfan.exe [2006-02-08 15:38:36]
Virtual Assistant.lnk - C:\Program Files\Virtual Assistant\bin\matcli.exe [2007-06-23 15:09:47]

R1 GhPciScan;GhostPciScanner;\??\C:\Program Files\Norton SystemWorks\Norton Ghost\ghpciscan.sys
R2 ROB_A;Pinnacle WDM PCTV Audio Capture;C:\WINDOWS\system32\DRIVERS\rob_a.sys
R2 ROB_V;Pinnacle WDM PCTV Video Capture;C:\WINDOWS\system32\drivers\rob_v.sys
R2 TOSHIBA Bluetooth Service;TOSHIBA Bluetooth Service;C:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosBtSrv.exe
R3 DCamUSBVeo532;Veo Web Camera;C:\WINDOWS\system32\Drivers\ubVeo532.sys
R3 NPDriver;Norton Unerase Protection Driver;\??\C:\WINDOWS\System32\Drivers\NPDRIVER.SYS
R3 pctvvbi;PCTVVBI;C:\WINDOWS\system32\DRIVERS\pctvvbi.sys
S3 APLMp50;APLMp50 NDIS Protocol Driver;C:\WINDOWS\system32\Drivers\APLMp50.sys
S3 trid3d;trid3d;C:\WINDOWS\system32\DRIVERS\trid3dm.sys


Contents of the 'Scheduled Tasks' folder
2007-08-20 16:46:36 C:\WINDOWS\Tasks\AppleSoftwareUpdate.job
2007-08-20 07:52:04 C:\WINDOWS\Tasks\MP Scheduled Scan.job - C:\Program Files\Windows Defender\MpCmdRun.exe
2007-08-19 15:30:00 C:\WINDOWS\Tasks\Norton AntiVirus - Scan my computer.job - C:\PROGRA~1\NORTON~2\NORTON~1\NAVW32.exe
2007-08-17 23:30:00 C:\WINDOWS\Tasks\Norton SystemWorks One Button Checkup.job
2007-08-20 19:34:20 C:\WINDOWS\Tasks\Symantec NetDetect.job - C:\Program Files\Symantec\LiveUpdate\NDETECT.EXE

**************************************************************************

catchme 0.3.1061 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2007-08-20 14:27:17
Windows 5.1.2600 Service Pack 2 NTFS

scanning hidden processes ...

scanning hidden autostart entries ...

scanning hidden files ...

scan completed successfully
hidden files: 0

**************************************************************************

Completion time: 2007-08-20 14:32:49
C:\ComboFix-quarantined-files.txt ... 2007-08-20 14:32
C:\ComboFix2.txt ... 2007-08-14 17:21

--- E O F ---


A New Hijack This Log from a few minutes ago:

Logfile of HijackThis v1.99.1
Scan saved at 14:53:12, on 08/20/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16512)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Ahead\InCD\InCDsrv.exe
C:\WINDOWS\system32\ZoneLabs\vsmon.exe
C:\WINDOWS\system32\LEXBCES.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\LEXPPS.EXE
C:\Program Files\APC\APC PowerChute Personal Edition\mainserv.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
C:\Program Files\FolderSize\FolderSizeSvc.exe
C:\Program Files\Norton SystemWorks\Norton Ghost\GhostStartService.exe
C:\Program Files\Norton SystemWorks\Norton AntiVirus\navapsvc.exe
C:\Program Files\Norton SystemWorks\Norton Utilities\NPROTECT.EXE
C:\WINDOWS\System32\snmp.exe
C:\PROGRA~1\NORTON~2\SPEEDD~1\nopdb.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosBtSrv.exe
C:\windows\system\hpsysdrv.exe
C:\HP\KBD\KBD.EXE
C:\WINDOWS\System32\hkcmd.exe
C:\WINDOWS\system32\S3apphk.exe
C:\WINDOWS\LTMSG.exe
C:\WINDOWS\system32\rundll32.exe
C:\Program Files\Common Files\Symantec Shared\ccApp.exe
C:\Program Files\Norton SystemWorks\Norton Ghost\GhostStartTrayApp.exe
C:\Program Files\Pinnacle\Pinnacle PCTV\Remote\Remoterm.exe
C:\Program Files\Labtec\Mouse\2.1\moffice.exe
C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe
C:\Program Files\G7PS\4X UltraSaver\UltraSaver.exe
C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\printray.exe
C:\WINDOWS\system32\LXSUPMON.EXE
C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe
C:\Program Files\Labtec\Mouse\2.1\MOUSE32A.EXE
C:\Program Files\Labtec\Media Keyboard\V5.0\KbdAp32A.exe
C:\Program Files\Ahead\InCD\InCD.exe
C:\PROGRA~1\VIRTUA~1\SMARTB~1\SprintDSLAlert.exe
C:\Program Files\Java\jre1.6.0_02\bin\jusched.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\MSN Messenger\MsnMsgr.Exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosBtMng.exe
C:\Program Files\PowerMenu\PowerMenu.exe
C:\Program Files\SpeedFan\speedfan.exe
C:\Program Files\APC\APC PowerChute Personal Edition\apcsystray.exe
C:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosA2dp.exe
C:\Program Files\Virtual Assistant\bin\mpbtn.exe
C:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosBtHid.exe
C:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosBtHsp.exe
C:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosAVRC.exe
C:\Program Files\Toshiba\Bluetooth Toshiba Stack\tosOBEX.exe
C:\Program Files\MSN Messenger\usnsvc.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Program Files\Toshiba\Bluetooth Toshiba Stack\tosBtProc.exe
C:\WINDOWS\system32\ntvdm.exe
C:\Program Files\TrueCrypt\TrueCrypt.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\WINDOWS\explorer.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\Windows Media Player\wmplayer.exe
C:\Documents and Settings\Master Luke\Desktop\Killer.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://myembarq.com
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft....k/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft....k/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://srch-us5.hpwis.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft....k/?LinkId=54896
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = 127.0.0.1
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_02\bin\ssv.dll
O2 - BHO: PeoplePC ScamGuard - {7E3659A6-4BC5-4d93-B3FD-8B5ACC2FEDED} - C:\Program Files\PeoplePC\Toolbar\ScamGrd.dll (file missing)
O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
O2 - BHO: PeoplePal Toolbar - {A8FB8EB3-183B-4598-924D-86F0E5E37085} - C:\Program Files\PeoplePC\Toolbar\PPCToolbar.dll (file missing)
O2 - BHO: NAV Helper - {BDF3E430-B101-42AD-A544-FADC6B084872} - C:\Program Files\Norton SystemWorks\Norton AntiVirus\NavShExt.dll
O2 - BHO: (no name) - {FDD3B846-8D59-4ffb-8758-209B6AD74ACC} - c:\Program Files\Microsoft Money\System\mnyviewer.dll
O3 - Toolbar: &hp toolkit - {B2847E28-5D7D-4DEB-8B67-05D28BCF79F5} - C:\HP\EXPLOREBAR\HPTOOLKT.DLL
O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - C:\Program Files\Norton SystemWorks\Norton AntiVirus\NavShExt.dll
O3 - Toolbar: PeoplePal Toolbar - {A8FB8EB3-183B-4598-924D-86F0E5E37085} - C:\Program Files\PeoplePC\Toolbar\PPCToolbar.dll (file missing)
O4 - HKLM\..\Run: [hpsysdrv] c:\windows\system\hpsysdrv.exe
O4 - HKLM\..\Run: [PreloadApp] c:\hp\drivers\printers\photosmart\hphprld.exe c:\hp\drivers\printers\photosmart\setup.exe -d
O4 - HKLM\..\Run: [KBD] C:\HP\KBD\KBD.EXE
O4 - HKLM\..\Run: [Recguard] C:\WINDOWS\SMINST\RECGUARD.EXE
O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\System32\igfxtray.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\System32\hkcmd.exe
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE NvQTwk,NvCplDaemon initialize
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [S3apphk] S3apphk.exe
O4 - HKLM\..\Run: [PS2] C:\WINDOWS\system32\ps2.exe
O4 - HKLM\..\Run: [LTMSG] LTMSG.exe 7
O4 - HKLM\..\Run: [BluetoothAuthenticationAgent] rundll32.exe bthprops.cpl,,BluetoothAuthenticationAgent
O4 - HKLM\..\Run: [ccApp] C:\Program Files\Common Files\Symantec Shared\ccApp.exe
O4 - HKLM\..\Run: [ccRegVfy] C:\Program Files\Common Files\Symantec Shared\ccRegVfy.exe
O4 - HKLM\..\Run: [GhostStartTrayApp] C:\Program Files\Norton SystemWorks\Norton Ghost\GhostStartTrayApp.exe
O4 - HKLM\..\Run: [PCTVRemote] C:\Program Files\Pinnacle\Pinnacle PCTV\Remote\Remoterm.exe
O4 - HKLM\..\Run: [FLMOFFICE4DMOUSE] C:\Program Files\Labtec\Mouse\2.1\moffice.exe
O4 - HKLM\..\Run: [ZoneAlarm Client] "C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe"
O4 - HKLM\..\Run: [hp Update 2100C] C:\Program Files\Hewlett-Packard\HP PrecisionScan\sj644\hpupdate.exe
O4 - HKLM\..\Run: [UltraSaver] "C:\Program Files\G7PS\4X UltraSaver\UltraSaver.exe" /hide
O4 - HKLM\..\Run: [PrinTray] C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\printray.exe
O4 - HKLM\..\Run: [LXSUPMON] C:\WINDOWS\system32\LXSUPMON.EXE RUN
O4 - HKLM\..\Run: [Microsoft Works Portfolio] C:\Program Files\Microsoft Works\WksSb.exe /AllUsers
O4 - HKLM\..\Run: [Microsoft Works Update Detection] C:\Program Files\Microsoft Works\WkDetect.exe
O4 - HKLM\..\Run: [RemoteControl] "C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe"
O4 - HKLM\..\Run: [LWBKEYBOARD] C:\Program Files\Labtec\Media Keyboard\V5.0\KbdAp32A.exe
O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [InCD] C:\Program Files\Ahead\InCD\InCD.exe
O4 - HKLM\..\Run: [Motive SmartBridge] C:\PROGRA~1\VIRTUA~1\SMARTB~1\SprintDSLAlert.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_02\bin\jusched.exe"
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\MSN Messenger\MsnMsgr.Exe" /background
O4 - HKCU\..\Run: [Microsoft Works Update Detection] c:\Program Files\Microsoft Works\WkDetect.exe
O4 - HKCU\..\Run: [updateMgr] "C:\Program Files\Adobe\Acrobat 7.0\Reader\AdobeUpdateManager.exe" AcRdB7_0_0
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - Global Startup: APC UPS Status.lnk = C:\Program Files\APC\APC PowerChute Personal Edition\Display.exe
O4 - Global Startup: Bluetooth Manager.lnk = ?
O4 - Global Startup: PowerMenu.lnk = C:\Program Files\PowerMenu\PowerMenu.exe
O4 - Global Startup: SpeedFan 4.28.lnk = C:\Program Files\SpeedFan\speedfan.exe
O4 - Global Startup: Virtual Assistant.lnk = C:\Program Files\Virtual Assistant\bin\matcli.exe
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_02\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_02\bin\ssv.dll
O9 - Extra button: MoneySide - {E023F504-0C5A-4750-A1E7-A9046DEA8A21} - c:\Program Files\Microsoft Money\System\mnyviewer.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O11 - Options group: [INTERNATIONAL] International*
O16 - DPF: {0EB0E74A-2A76-4AB3-A7FB-9BD8C29F7F75} (CKAVWebScan Object) - http://www.kaspersky...can_unicode.cab
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.micros...b?1180089289734
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.micros...b?1181970103437
O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - http://acs.pandasoft...free/asinst.cab
O16 - DPF: {DF780F87-FF2B-4DF8-92D0-73DB16A1543A} (PopCapLoader Object) - http://www.shockwave...ploader_v10.cab
O18 - Protocol: g7ps - {9EACF0FB-4FC7-436E-989B-3197142AD979} - C:\Program Files\Common Files\G7PS\Shared Files\G7PSDLL\G7PS.dll
O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O20 - Winlogon Notify: igfxcui - C:\WINDOWS\SYSTEM32\igfxsrvc.dll
O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll
O21 - SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll
O23 - Service: APC UPS Service - American Power Conversion Corporation - C:\Program Files\APC\APC PowerChute Personal Edition\mainserv.exe
O23 - Service: Apple Mobile Device - Apple, Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
O23 - Service: Symantec Password Validation Service (ccPwdSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccPwdSvc.exe
O23 - Service: Folder Size (FolderSize) - Brio - C:\Program Files\FolderSize\FolderSizeSvc.exe
O23 - Service: GhostStartService - Symantec Corporation - C:\Program Files\Norton SystemWorks\Norton Ghost\GhostStartService.exe
O23 - Service: InCD Helper (InCDsrv) - Nero AG - C:\Program Files\Ahead\InCD\InCDsrv.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: LexBce Server (LexBceS) - Lexmark International, Inc. - C:\WINDOWS\system32\LEXBCES.EXE
O23 - Service: Norton AntiVirus Auto Protect Service (navapsvc) - Symantec Corporation - C:\Program Files\Norton SystemWorks\Norton AntiVirus\navapsvc.exe
O23 - Service: Norton Unerase Protection (NProtectService) - Symantec Corporation - C:\Program Files\Norton SystemWorks\Norton Utilities\NPROTECT.EXE
O23 - Service: NVIDIA Driver Helper Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\System32\nvsvc32.exe
O23 - Service: ScriptBlocking Service (SBService) - Symantec Corporation - C:\PROGRA~1\COMMON~1\SYMANT~1\SCRIPT~1\SBServ.exe
O23 - Service: Speed Disk service - Symantec Corporation - C:\PROGRA~1\NORTON~2\SPEEDD~1\nopdb.exe
O23 - Service: TOSHIBA Bluetooth Service - TOSHIBA CORPORATION - C:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosBtSrv.exe
O23 - Service: TrueVector Internet Monitor (vsmon) - Zone Labs, LLC - C:\WINDOWS\system32\ZoneLabs\vsmon.exe

#11 Master Luke

Master Luke

    New Member

  • Authentic Member
  • Pip
  • 8 posts

Posted 20 August 2007 - 03:12 PM

Trevuren I am dense today! You want an Uninstall Log too! Here it is! 4X UltraSaver Adobe ActiveShare 1.3.1 Adobe Flash Player 9 ActiveX Adobe Reader 7.0.9 APC PowerChute Personal Edition Apple Mobile Device Support Apple Software Update ArcSoft Software Suite Atomic Pop Avery DesignPro Baby Names Betty Bad BibleVerseArt4 Screen Saver Blasterball Wild Bluetooth Stack for Windows by Toshiba Board Games ClickArt® Christian Value Cobian Backup 8 Dark Orbit DFX for Windows Media Player FileMaker Pro 7 Folder Size for Windows FoneSync GemMaster 2 Hijackthis 1.99.1 HijackThis 1.99.1 Hotfix for Windows Media Format 11 SDK (KB929399) Hotfix for Windows XP (KB896344) Hotfix for Windows XP (KB915865) Hotfix for Windows XP (KB926239) hp center hp deskjet 630c series HP Instant Support HP Photo Printing Software HP PrecisionScan LTX HP Scan-to-Web Wizard Inactive HP Printer Drivers (Remove only) InCD Intel® 845G Chipset Graphics Driver Software iTunes Java™ 6 Update 2 Kaspersky Online Scanner KBD Kublox Label Publisher with Wizards Label Sort and Print Utility Labtec Media Keyboard V5.0 Labtec Mouse V2.1 Lernout & Hauspie TruVoice American English TTS Engine LiveReg (Symantec Corporation) LiveUpdate 1.80 (Symantec Corporation) Mavis Beacon Teaches Typing 9.0.0 Metafile Companion 1.10 Microsoft .NET Framework 2.0 Microsoft Compression Client Pack 1.0 for Windows XP Microsoft Internationalized Domain Names Mitigation APIs Microsoft Money 2002 Microsoft Money 2002 System Pack Microsoft National Language Support Downlevel APIs Microsoft Streets and Trips 2001 Microsoft User-Mode Driver Framework Feature Pack 1.0 Microsoft Word 2000 SR-1 Microsoft Works 2001 Setup Launcher Microsoft Works 6.0 Microsoft Works 6.0 Microsoft Works and Money 2002 Setup Launcher Microsoft Works Suite Add-in for Microsoft Word MidiNotate Mozilla Firefox (2.0.0.6) MSXML 6.0 Parser (KB933579) Nero Digital Nero Media Player Nero OEM NeroMIX Norton SystemWorks 2003 NVIDIA Windows 2000/XP Display Drivers Panda ActiveScan PC-Doctor for Windows PCTV PigPen Pinnacle TRex PL-2303 USB-to-Serial PowerDVD PrintKey2000 PS2 Python 1.5 combined Win32 extensions Python 1.5.2 (final) QuickTime RealPlayer Replay Radio and Replay A/V 7 SabreWing 2 Security Update for Microsoft .NET Framework 2.0 (KB928365) Security Update for Step By Step Interactive Training (KB923723) Security Update for Windows Internet Explorer 7 (KB933566) Security Update for Windows Internet Explorer 7 (KB937143) Security Update for Windows Internet Explorer 7 (KB938127) Security Update for Windows Media Player (KB911564) Security Update for Windows Media Player 11 (KB936782) Security Update for Windows Media Player 6.4 (KB925398) Security Update for Windows XP (KB890046) Security Update for Windows XP (KB893756) Security Update for Windows XP (KB896358) Security Update for Windows XP (KB896423) Security Update for Windows XP (KB896428) Security Update for Windows XP (KB899587) Security Update for Windows XP (KB899591) Security Update for Windows XP (KB900725) Security Update for Windows XP (KB901017) Security Update for Windows XP (KB901190) Security Update for Windows XP (KB901214) Security Update for Windows XP (KB902400) Security Update for Windows XP (KB904706) Security Update for Windows XP (KB905414) Security Update for Windows XP (KB905749) Security Update for Windows XP (KB908519) Security Update for Windows XP (KB911562) Security Update for Windows XP (KB911927) Security Update for Windows XP (KB913580) Security Update for Windows XP (KB914388) Security Update for Windows XP (KB914389) Security Update for Windows XP (KB917344) Security Update for Windows XP (KB917953) Security Update for Windows XP (KB918118) Security Update for Windows XP (KB918439) Security Update for Windows XP (KB919007) Security Update for Windows XP (KB920213) Security Update for Windows XP (KB920670) Security Update for Windows XP (KB920683) Security Update for Windows XP (KB920685) Security Update for Windows XP (KB921503) Security Update for Windows XP (KB922819) Security Update for Windows XP (KB923191) Security Update for Windows XP (KB923414) Security Update for Windows XP (KB923980) Security Update for Windows XP (KB924191) Security Update for Windows XP (KB924270) Security Update for Windows XP (KB924496) Security Update for Windows XP (KB924667) Security Update for Windows XP (KB925902) Security Update for Windows XP (KB926255) Security Update for Windows XP (KB926436) Security Update for Windows XP (KB927779) Security Update for Windows XP (KB927802) Security Update for Windows XP (KB928255) Security Update for Windows XP (KB928843) Security Update for Windows XP (KB929123) Security Update for Windows XP (KB930178) Security Update for Windows XP (KB931261) Security Update for Windows XP (KB931784) Security Update for Windows XP (KB932168) Security Update for Windows XP (KB933566) Security Update for Windows XP (KB935839) Security Update for Windows XP (KB935840) Security Update for Windows XP (KB936021) Security Update for Windows XP (KB938829) Shred 2 (PC Magazine) SoundMAX Space Rocks SpeedFan (remove only) Speedway Tcl 8.0.5 for Windows TrueCrypt Update for Windows XP (KB894391) Update for Windows XP (KB898461) Update for Windows XP (KB900485) Update for Windows XP (KB904942) Update for Windows XP (KB908531) Update for Windows XP (KB910437) Update for Windows XP (KB911280) Update for Windows XP (KB920872) Update for Windows XP (KB927891) Update for Windows XP (KB930916) Update for Windows XP (KB931836) Update for Windows XP (KB936357) Update for Windows XP (KB938828) Veo Digital Studio Veo Stingray VersaCheck 2003 Personal Premier VersaJette M300 Virtual Assistant Virtual Warfare Voyetra Music Write Plus Winamp (remove only) Windows Installer 3.1 (KB893803) Windows Internet Explorer 7 Windows Live Messenger Windows Media Format 11 runtime Windows Media Format 11 runtime Windows Media Player 11 Windows Media Player 11 Windows XP Hotfix - KB873339 Windows XP Hotfix - KB885835 Windows XP Hotfix - KB885836 Windows XP Hotfix - KB886185 Windows XP Hotfix - KB887472 Windows XP Hotfix - KB888302 Windows XP Hotfix - KB890859 Windows XP Hotfix - KB891781 Windows XP Service Pack 2 WinZip 11.1 Yahoo! Music Jukebox You Know What 2 - Arts and Entertainment You Know What 2 - History and Geography You Know What 2 - Potpourri You Know What 2 - Science and Nature You Know What 2 - Sports and Games ZoneAlarm

#12 Trevuren

Trevuren

    Teacher Emeritus

  • Authentic Member
  • PipPipPipPipPipPip
  • 8,632 posts
  • Interests:Woodworking

Posted 20 August 2007 - 06:45 PM

A. Using the Add/Remove feature in your Control Panel, please UNINSTALL the following program:

4X UltraSaver


B. A. Please RUN HijackThis
  • Click the SCAN button to produce a log.

  • Place a check mark beside each one of the following items:

    O2 - BHO: PeoplePC ScamGuard - {7E3659A6-4BC5-4d93-B3FD-8B5ACC2FEDED} - C:\Program Files\PeoplePC\Toolbar\ScamGrd.dll (file missing)
    O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
    O2 - BHO: PeoplePal Toolbar - {A8FB8EB3-183B-4598-924D-86F0E5E37085} - C:\Program Files\PeoplePC\Toolbar\PPCToolbar.dll (file missing)
    O3 - Toolbar: PeoplePal Toolbar - {A8FB8EB3-183B-4598-924D-86F0E5E37085} - C:\Program Files\PeoplePC\Toolbar\PPCToolbar.dll (file missing)
    O4 - HKLM\..\Run: [UltraSaver] "C:\Program Files\G7PS\4X UltraSaver\UltraSaver.exe" /hide



  • Now with all the items selected, and all windows closed except for HJT, delete them by clicking the FIX checked button. Close the HijackThis window.

B. 1. Please open Notepad
  • Click Start , then Run
  • Type notepad .exe in the Run Box.
2. Now copy/paste the entire content of the codebox below into the Notepad window:

File::
C:\WINDOWS\system32\windzfa0.sys
C:\WINDOWS\system32\msssc.dll
C:\WINDOWS\iun6002.exe
C:\Documents and Settings\Master Luke\My Documents\E 02 Downloaded Programs\An Awesome God Desktop Theme.exe
C:\Documents and Settings\Master Luke\My Documents\E 02 Downloaded Programs\Angel Icons.exe
C:\Documents and Settings\Master Luke\My Documents\E 02 Downloaded Programs\Baby Goats Desktop Theme.exe
C:\Documents and Settings\Master Luke\My Documents\E 02 Downloaded Programs\Book of Mormon Verse Screensaver.exe
C:\Documents and Settings\Master Luke\My Documents\E 02 Downloaded Programs\Christian Icons.exe
C:\Documents and Settings\Master Luke\My Documents\E 02 Downloaded Programs\Computerbug 2 Desktop Theme.exe
C:\Documents and Settings\Master Luke\My Documents\E 02 Downloaded Programs\Cross Icons.exe
C:\Documents and Settings\Master Luke\My Documents\E 02 Downloaded Programs\Mackinac Bridge Desktop Theme.exe
C:\Documents and Settings\Master Luke\My Documents\E 02 Downloaded Programs\MSN-Winks - sherv.net.exe
C:\Documents and Settings\Master Luke\My Documents\E 02 Downloaded Programs\NASCAR Desktop Theme.exe
C:\Documents and Settings\Master Luke\My Documents\E 02 Downloaded Programs\Praying Hands Icons.exe
C:\Documents and Settings\Master Luke\My Documents\E 02 Downloaded Programs\School Desktop Theme.exe
C:\Documents and Settings\Master Luke\My Documents\E 02 Downloaded Programs\Sponge Bob Theme.exe
C:\Documents and Settings\Master Luke\My Documents\E 02 Downloaded Programs\Weather Bug Setup 60b6.04.0.9m.EXE
C:\Documents and Settings\Master Luke Old\Local Settings\Temp\Install-Emoticons.exe
C:\Documents and Settings\Master Luke Old\Local Settings\Temp\ppc17.tmp
C:\hp\bin\KillWind.exe
C:\WINDOWS\Downloaded Program Files\CONFLICT.1\popcaploader.dll
C:\WINDOWS\Downloaded Program Files\popcaploader.dll
G:\New Items to be included in Drive C\Additonal Programs that may need to be moved\Magical Jellybean Keyfinder\Magical Jellybean Keyfinder V 1.41.exe
G:\New Items to be included in Drive C\Additonal Programs that may need to be moved\Downloaded Programs\Baby Goats Desktop Theme.exe
G:\New Items to be included in Drive C\Additonal Programs that may need to be moved\Downloaded Programs\Book of Mormon Verse Screensaver.exe
G:\New Items to be included in Drive C\Additonal Programs that may need to be moved\Downloaded Programs\Computerbug 2 Desktop Theme.exe
G:\New Items to be included in Drive C\Additonal Programs that may need to be moved\Downloaded Programs\Mackinac Bridge Desktop Theme.exe
G:\New Items to be included in Drive C\Additonal Programs that may need to be moved\Downloaded Programs\Sponge Bob Theme.exe

Folder::
C:\Program Files\Aveo
C:\Program Files\PeoplePC
C:\Program Files\WildTangent
C:\Program Files\AWS
C:\Program Files\G7PS\4X UltraSaver


3. Save the above as CFScript.txt

4. Then drag the CFScript.txt into ComboFix.exe as depicted in the animation below. This will start ComboFix again.

Posted Image


5. After reboot, (in case it asks to reboot), please post the following reports/logs into your next reply:
  • Combofix.txt
  • A new HijackThis log.

Microsoft MVP Consumer Security 2008 - 2009


Proud graduate of TC/WTT Classroom



The help you receive here is free. If you wish to show your appreciation, then you may donate to help keep us online.

Want to help others? Join the ClassRoom and learn how.


Posted Image

#13 Master Luke

Master Luke

    New Member

  • Authentic Member
  • Pip
  • 8 posts

Posted 24 August 2007 - 10:36 PM

Hi Trevuren:

I ran the latest round of instructions earlier today, and generated an absolutely huge, and I mean huge COMBOFIX logfile. Attempting to load it into here has virtually proved fruitless; is it permissable for me to put it up on SENDSPACE and provide you with the link? Otherwise it may take me a great while to get it to you.

I will attach the latest HiJack This scan to this post. Please advise on the other log.

God Bless and Thank You! Master Luke



Logfile of HijackThis v1.99.1
Scan saved at 17:46:56, on 08/24/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16512)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Ahead\InCD\InCDsrv.exe
C:\WINDOWS\system32\ZoneLabs\vsmon.exe
C:\WINDOWS\system32\LEXBCES.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\LEXPPS.EXE
C:\Program Files\APC\APC PowerChute Personal Edition\mainserv.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
C:\Program Files\FolderSize\FolderSizeSvc.exe
C:\Program Files\Norton SystemWorks\Norton Ghost\GhostStartService.exe
C:\Program Files\Norton SystemWorks\Norton AntiVirus\navapsvc.exe
C:\Program Files\Norton SystemWorks\Norton Utilities\NPROTECT.EXE
C:\WINDOWS\System32\snmp.exe
C:\PROGRA~1\NORTON~2\SPEEDD~1\nopdb.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosBtSrv.exe
C:\WINDOWS\Explorer.EXE
C:\windows\system\hpsysdrv.exe
C:\HP\KBD\KBD.EXE
C:\WINDOWS\System32\hkcmd.exe
C:\WINDOWS\system32\S3apphk.exe
C:\WINDOWS\LTMSG.exe
C:\WINDOWS\system32\rundll32.exe
C:\Program Files\Common Files\Symantec Shared\ccApp.exe
C:\Program Files\Norton SystemWorks\Norton Ghost\GhostStartTrayApp.exe
C:\Program Files\Pinnacle\Pinnacle PCTV\Remote\Remoterm.exe
C:\Program Files\Labtec\Mouse\2.1\moffice.exe
C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe
C:\Program Files\Labtec\Mouse\2.1\MOUSE32A.EXE
C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\printray.exe
C:\WINDOWS\system32\LXSUPMON.EXE
C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe
C:\Program Files\Labtec\Media Keyboard\V5.0\KbdAp32A.exe
C:\Program Files\Ahead\InCD\InCD.exe
C:\PROGRA~1\VIRTUA~1\SMARTB~1\SprintDSLAlert.exe
C:\Program Files\Java\jre1.6.0_02\bin\jusched.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\MSN Messenger\MsnMsgr.Exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosBtMng.exe
C:\Program Files\PowerMenu\PowerMenu.exe
C:\Program Files\SpeedFan\speedfan.exe
C:\Program Files\APC\APC PowerChute Personal Edition\apcsystray.exe
C:\Program Files\Virtual Assistant\bin\mpbtn.exe
C:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosA2dp.exe
C:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosBtHid.exe
C:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosBtHsp.exe
C:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosAVRC.exe
C:\Program Files\Toshiba\Bluetooth Toshiba Stack\tosOBEX.exe
C:\Program Files\MSN Messenger\usnsvc.exe
C:\Program Files\Toshiba\Bluetooth Toshiba Stack\tosBtProc.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\WINDOWS\system32\notepad.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\Messenger\msmsgs.exe
C:\Documents and Settings\Master Luke\Desktop\Killer.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://myembarq.com
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft....k/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft....k/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://srch-us5.hpwis.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft....k/?LinkId=54896
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = 127.0.0.1
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_02\bin\ssv.dll
O2 - BHO: NAV Helper - {BDF3E430-B101-42AD-A544-FADC6B084872} - C:\Program Files\Norton SystemWorks\Norton AntiVirus\NavShExt.dll
O2 - BHO: (no name) - {FDD3B846-8D59-4ffb-8758-209B6AD74ACC} - c:\Program Files\Microsoft Money\System\mnyviewer.dll
O3 - Toolbar: &hp toolkit - {B2847E28-5D7D-4DEB-8B67-05D28BCF79F5} - C:\HP\EXPLOREBAR\HPTOOLKT.DLL
O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - C:\Program Files\Norton SystemWorks\Norton AntiVirus\NavShExt.dll
O4 - HKLM\..\Run: [hpsysdrv] c:\windows\system\hpsysdrv.exe
O4 - HKLM\..\Run: [PreloadApp] c:\hp\drivers\printers\photosmart\hphprld.exe c:\hp\drivers\printers\photosmart\setup.exe -d
O4 - HKLM\..\Run: [KBD] C:\HP\KBD\KBD.EXE
O4 - HKLM\..\Run: [Recguard] C:\WINDOWS\SMINST\RECGUARD.EXE
O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\System32\igfxtray.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\System32\hkcmd.exe
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE NvQTwk,NvCplDaemon initialize
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [S3apphk] S3apphk.exe
O4 - HKLM\..\Run: [PS2] C:\WINDOWS\system32\ps2.exe
O4 - HKLM\..\Run: [LTMSG] LTMSG.exe 7
O4 - HKLM\..\Run: [BluetoothAuthenticationAgent] rundll32.exe bthprops.cpl,,BluetoothAuthenticationAgent
O4 - HKLM\..\Run: [ccApp] C:\Program Files\Common Files\Symantec Shared\ccApp.exe
O4 - HKLM\..\Run: [ccRegVfy] C:\Program Files\Common Files\Symantec Shared\ccRegVfy.exe
O4 - HKLM\..\Run: [GhostStartTrayApp] C:\Program Files\Norton SystemWorks\Norton Ghost\GhostStartTrayApp.exe
O4 - HKLM\..\Run: [PCTVRemote] C:\Program Files\Pinnacle\Pinnacle PCTV\Remote\Remoterm.exe
O4 - HKLM\..\Run: [FLMOFFICE4DMOUSE] C:\Program Files\Labtec\Mouse\2.1\moffice.exe
O4 - HKLM\..\Run: [ZoneAlarm Client] "C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe"
O4 - HKLM\..\Run: [hp Update 2100C] C:\Program Files\Hewlett-Packard\HP PrecisionScan\sj644\hpupdate.exe
O4 - HKLM\..\Run: [PrinTray] C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\printray.exe
O4 - HKLM\..\Run: [LXSUPMON] C:\WINDOWS\system32\LXSUPMON.EXE RUN
O4 - HKLM\..\Run: [Microsoft Works Portfolio] C:\Program Files\Microsoft Works\WksSb.exe /AllUsers
O4 - HKLM\..\Run: [Microsoft Works Update Detection] C:\Program Files\Microsoft Works\WkDetect.exe
O4 - HKLM\..\Run: [RemoteControl] "C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe"
O4 - HKLM\..\Run: [LWBKEYBOARD] C:\Program Files\Labtec\Media Keyboard\V5.0\KbdAp32A.exe
O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [InCD] C:\Program Files\Ahead\InCD\InCD.exe
O4 - HKLM\..\Run: [Motive SmartBridge] C:\PROGRA~1\VIRTUA~1\SMARTB~1\SprintDSLAlert.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_02\bin\jusched.exe"
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\MSN Messenger\MsnMsgr.Exe" /background
O4 - HKCU\..\Run: [Microsoft Works Update Detection] c:\Program Files\Microsoft Works\WkDetect.exe
O4 - HKCU\..\Run: [updateMgr] "C:\Program Files\Adobe\Acrobat 7.0\Reader\AdobeUpdateManager.exe" AcRdB7_0_0
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - Global Startup: APC UPS Status.lnk = C:\Program Files\APC\APC PowerChute Personal Edition\Display.exe
O4 - Global Startup: Bluetooth Manager.lnk = ?
O4 - Global Startup: PowerMenu.lnk = C:\Program Files\PowerMenu\PowerMenu.exe
O4 - Global Startup: SpeedFan 4.28.lnk = C:\Program Files\SpeedFan\speedfan.exe
O4 - Global Startup: Virtual Assistant.lnk = C:\Program Files\Virtual Assistant\bin\matcli.exe
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_02\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_02\bin\ssv.dll
O9 - Extra button: MoneySide - {E023F504-0C5A-4750-A1E7-A9046DEA8A21} - c:\Program Files\Microsoft Money\System\mnyviewer.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O11 - Options group: [INTERNATIONAL] International*
O16 - DPF: {0EB0E74A-2A76-4AB3-A7FB-9BD8C29F7F75} (CKAVWebScan Object) - http://www.kaspersky...can_unicode.cab
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.micros...b?1180089289734
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.micros...b?1181970103437
O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - http://acs.pandasoft...free/asinst.cab
O16 - DPF: {DF780F87-FF2B-4DF8-92D0-73DB16A1543A} (PopCapLoader Object) - http://www.shockwave...ploader_v10.cab
O18 - Protocol: g7ps - {9EACF0FB-4FC7-436E-989B-3197142AD979} - C:\Program Files\Common Files\G7PS\Shared Files\G7PSDLL\G7PS.dll
O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O20 - Winlogon Notify: igfxcui - C:\WINDOWS\SYSTEM32\igfxsrvc.dll
O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll
O21 - SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll
O23 - Service: APC UPS Service - American Power Conversion Corporation - C:\Program Files\APC\APC PowerChute Personal Edition\mainserv.exe
O23 - Service: Apple Mobile Device - Apple, Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
O23 - Service: Symantec Password Validation Service (ccPwdSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccPwdSvc.exe
O23 - Service: Folder Size (FolderSize) - Brio - C:\Program Files\FolderSize\FolderSizeSvc.exe
O23 - Service: GhostStartService - Symantec Corporation - C:\Program Files\Norton SystemWorks\Norton Ghost\GhostStartService.exe
O23 - Service: InCD Helper (InCDsrv) - Nero AG - C:\Program Files\Ahead\InCD\InCDsrv.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: LexBce Server (LexBceS) - Lexmark International, Inc. - C:\WINDOWS\system32\LEXBCES.EXE
O23 - Service: Norton AntiVirus Auto Protect Service (navapsvc) - Symantec Corporation - C:\Program Files\Norton SystemWorks\Norton AntiVirus\navapsvc.exe
O23 - Service: Norton Unerase Protection (NProtectService) - Symantec Corporation - C:\Program Files\Norton SystemWorks\Norton Utilities\NPROTECT.EXE
O23 - Service: NVIDIA Driver Helper Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\System32\nvsvc32.exe
O23 - Service: ScriptBlocking Service (SBService) - Symantec Corporation - C:\PROGRA~1\COMMON~1\SYMANT~1\SCRIPT~1\SBServ.exe
O23 - Service: Speed Disk service - Symantec Corporation - C:\PROGRA~1\NORTON~2\SPEEDD~1\nopdb.exe
O23 - Service: TOSHIBA Bluetooth Service - TOSHIBA CORPORATION - C:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosBtSrv.exe
O23 - Service: TrueVector Internet Monitor (vsmon) - Zone Labs, LLC - C:\WINDOWS\system32\ZoneLabs\vsmon.exe

#14 Trevuren

Trevuren

    Teacher Emeritus

  • Authentic Member
  • PipPipPipPipPipPip
  • 8,632 posts
  • Interests:Woodworking

Posted 24 August 2007 - 10:49 PM

Never mind. I would not be able to analyze it if it is that big. Instead, please run ComboFix.exe again but not using the Script . The text should be much smaller and I will be able to see what I may have missed the first time. That is all that really matters.


Thanks just the same, (Your HijackThis log is looking pretty good)

Trevuren
Microsoft MVP Consumer Security 2008 - 2009


Proud graduate of TC/WTT Classroom



The help you receive here is free. If you wish to show your appreciation, then you may donate to help keep us online.

Want to help others? Join the ClassRoom and learn how.


Posted Image

#15 Trevuren

Trevuren

    Teacher Emeritus

  • Authentic Member
  • PipPipPipPipPipPip
  • 8,632 posts
  • Interests:Woodworking

Posted 08 September 2007 - 08:52 PM

Due to inactivity this topic will be closed. If you need help please start a new thread and post a new HJT log
Microsoft MVP Consumer Security 2008 - 2009


Proud graduate of TC/WTT Classroom



The help you receive here is free. If you wish to show your appreciation, then you may donate to help keep us online.

Want to help others? Join the ClassRoom and learn how.


Posted Image

Related Topics



0 user(s) are reading this topic

0 members, 0 guests, 0 anonymous users