1. Computer problem? Tech Support Guy is completely free -- paid for by advertisers and donations. Click here to join today! If you're new to Tech Support Guy, we highly recommend that you visit our Guide for New Members.

Solved: Please help! Trojan.vundo infection and unable to boot in safe mode

Discussion in 'Virus & Other Malware Removal' started by sesharam, Nov 9, 2007.

Thread Status:
Not open for further replies.
Advertisement
  1. sesharam

    sesharam Thread Starter

    Joined:
    Nov 9, 2007
    Messages:
    4
    Hi,

    my OS is Windows XP Home (SP2). I have Symantec Antivirus. My system's been infected with this virus since yesterday. Have tried Symantc antivitus and numerous spyware removal tools but none would remove the trojan completely.

    Moreover, since today, my computer wont boot in safe mode. I keep getting a popup asking me to confirm if i want to boot in safe mode. Even after saying yes, it pops again within a second. This goes in a loop.

    Any help is much appreciated.

    Attached below is my Hijack This log:

    Logfile of HijackThis v1.99.1
    Scan saved at 12:04:44 PM, on 11/9/2007
    Platform: Windows XP SP2 (WinNT 5.01.2600)
    MSIE: Internet Explorer v7.00 (7.00.6000.16544)

    Running processes:
    C:\WINDOWS\System32\smss.exe
    C:\WINDOWS\system32\winlogon.exe
    C:\WINDOWS\system32\services.exe
    C:\WINDOWS\system32\lsass.exe
    C:\WINDOWS\system32\svchost.exe
    C:\Program Files\Windows Defender\MsMpEng.exe
    C:\WINDOWS\System32\svchost.exe
    C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
    C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
    C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe
    C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
    C:\WINDOWS\system32\spoolsv.exe
    C:\WINDOWS\system32\cisvc.exe
    C:\Program Files\Symantec AntiVirus\DefWatch.exe
    C:\WINDOWS\system32\CBA\pds.exe
    C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
    C:\Program Files\Dell Support Center\bin\sprtsvc.exe
    C:\WINDOWS\system32\svchost.exe
    C:\Program Files\Symantec AntiVirus\Rtvscan.exe
    C:\Program Files\Canon\CAL\CALMAIN.exe
    C:\WINDOWS\Explorer.EXE
    C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe
    C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
    C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
    C:\Program Files\CyberLink\PowerDVD\DVDLauncher.exe
    C:\WINDOWS\system32\dla\tfswctrl.exe
    C:\WINDOWS\system32\hkcmd.exe
    C:\WINDOWS\system32\igfxpers.exe
    C:\Program Files\Lexmark 8300 Series\ezprint.exe
    C:\WINDOWS\system32\igfxsrvc.exe
    C:\Program Files\Windows Defender\MSASCui.exe
    C:\Program Files\Verizon\McciTrayApp.exe
    C:\Program Files\Common Files\Real\Update_OB\realsched.exe
    C:\WINDOWS\system32\lxcjcoms.exe
    C:\Program Files\Common Files\Symantec Shared\ccApp.exe
    C:\PROGRA~1\SYMANT~1\VPTray.exe
    C:\WINDOWS\system32\ctfmon.exe
    C:\Program Files\DellSupport\DSAgnt.exe
    C:\Program Files\Microsoft ActiveSync\wcescomm.exe
    C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
    C:\Program Files\Dell Support Center\bin\sprtcmd.exe
    C:\PROGRA~1\MI3AA1~1\rapimgr.exe
    C:\Program Files\Adobe\Acrobat 6.0\Distillr\acrotray.exe
    C:\WINDOWS\system32\cidaemon.exe
    C:\WINDOWS\system32\taskmgr.exe
    C:\PROGRA~1\WINZIP\winzip32.exe
    C:\Documents and Settings\Kavi\Local Settings\Temp\HijackThis.exe

    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.dell4me.com/myway
    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://us.rd.yahoo.com/customize/ie/...ch/search.html
    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://us.rd.yahoo.com/customize/ie/.../www.yahoo.com
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://us.rd.yahoo.com/customize/ie/...ch/search.html
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
    R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
    R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://us.rd.yahoo.com/customize/ie/.../www.yahoo.com
    R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://www.dell4me.com/myway
    R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
    R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn3\yt.dll
    O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn3\yt.dll
    O3 - Toolbar: DAP Bar - {62999427-33FC-4baf-9C9C-BCE6BD127F08} - C:\Program Files\DAP\DAPIEBar.dll
    O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll
    O3 - Toolbar: Adobe PDF - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files\Adobe\Acrobat 6.0\Acrobat\AcroIEFavClient.dll
    O3 - Toolbar: (no name) - {11A69AE4-FBED-4832-A2BF-45AF82825583} - (no file)
    O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe"
    O4 - HKLM\..\Run: [SynTPLpr] C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
    O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
    O4 - HKLM\..\Run: [DVDLauncher] "C:\Program Files\CyberLink\PowerDVD\DVDLauncher.exe"
    O4 - HKLM\..\Run: [UpdateManager] "C:\Program Files\Common Files\Sonic\Update Manager\sgtray.exe" /r
    O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
    O4 - HKLM\..\Run: [dla] C:\WINDOWS\system32\dla\tfswctrl.exe
    O4 - HKLM\..\Run: [EPSON Stylus C84 Series] C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_S4I2D1.EXE /P23 "EPSON Stylus C84 Series" /O6 "USB002" /M "Stylus C84"
    O4 - HKLM\..\Run: [Auto EPSON Stylus C84 Series on KRD-PC] C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_S4I2D1.EXE /P38 "Auto EPSON Stylus C84 Series on KRD-PC" /O36 "\\KRD-PC\Epson Stylus C84 on KRD-PC " /M "Stylus C84"
    O4 - HKLM\..\Run: [igfxtray] C:\WINDOWS\system32\igfxtray.exe
    O4 - HKLM\..\Run: [igfxhkcmd] C:\WINDOWS\system32\hkcmd.exe
    O4 - HKLM\..\Run: [igfxpers] C:\WINDOWS\system32\igfxpers.exe
    O4 - HKLM\..\Run: [\\KRD-PC\EPSON Stylus C84 Series] C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_S4I2D1.EXE /P32 "\\KRD-PC\EPSON Stylus C84 Series" /O6 "USB003" /M "Stylus C84"
    O4 - HKLM\..\Run: [lxcjmon.exe] "C:\Program Files\Lexmark 8300 Series\lxcjmon.exe"
    O4 - HKLM\..\Run: [EzPrint] "C:\Program Files\Lexmark 8300 Series\ezprint.exe"
    O4 - HKLM\..\Run: [Windows Defender] "C:\Program Files\Windows Defender\MSASCui.exe" -hide
    O4 - HKLM\..\Run: [Verizon_McciTrayApp] C:\Program Files\Verizon\McciTrayApp.exe
    O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
    O4 - HKLM\..\Run: [DownloadAccelerator] "C:\Program Files\DAP\DAP.EXE" /STARTUP
    O4 - HKLM\..\Run: [Adobe Photo Downloader] "C:\Program Files\Adobe\Photoshop Album Starter Edition\3.2\Apps\apdproxy.exe"
    O4 - HKLM\..\Run: [dscactivate] C:\Program Files\Dell Support Center\gs_agent\custom\dsca.exe
    O4 - HKLM\..\Run: [d0b069cb] rundll32.exe "C:\WINDOWS\system32\phgmwgqc.dll",b
    O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
    O4 - HKLM\..\Run: [vptray] C:\PROGRA~1\SYMANT~1\VPTray.exe
    O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
    O4 - HKCU\..\Run: [DellSupport] "C:\Program Files\DellSupport\DSAgnt.exe" /startup
    O4 - HKCU\..\Run: [H/PC Connection Agent] "C:\Program Files\Microsoft ActiveSync\wcescomm.exe"
    O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
    O4 - HKCU\..\Run: [DellSupportCenter] "C:\Program Files\Dell Support Center\bin\sprtcmd.exe" /P DellSupportCenter
    O4 - Global Startup: Acrobat Assistant.lnk = C:\Program Files\Adobe\Acrobat 6.0\Distillr\acrotray.exe
    O8 - Extra context menu item: &Clean Traces - C:\Program Files\DAP\Privacy Package\dapcleanerie.htm
    O8 - Extra context menu item: &Dictionary - http://files.db3nf.com/scripts/ie.htm
    O8 - Extra context menu item: &Download with &DAP - C:\Program Files\DAP\dapextie.htm
    O8 - Extra context menu item: &eBay Search - res://C:\Program Files\eBay\eBay Toolbar2\eBayTb.dll/RCSearch.html
    O8 - Extra context menu item: &Encyclopedia - http://files.db3nf.com/scripts/ie-e.htm
    O8 - Extra context menu item: &Yahoo! Search - file:///C:\Program Files\Yahoo!\Common/ycsrch.htm
    O8 - Extra context menu item: Download &all with DAP - C:\Program Files\DAP\dapextie2.htm
    O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~4\OFFICE11\EXCEL.EXE/3000
    O8 - Extra context menu item: Yahoo! &Dictionary - file:///C:\Program Files\Yahoo!\Common/ycdict.htm
    O8 - Extra context menu item: Yahoo! &Maps - file:///C:\Program Files\Yahoo!\Common/ycmap.htm
    O8 - Extra context menu item: Yahoo! &SMS - file:///C:\Program Files\Yahoo!\Common/ycsms.htm
    O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
    O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
    O9 - Extra button: Create Mobile Favorite - {2EAF5BB1-070F-11D3-9307-00C04FAE2D4F} - C:\PROGRA~1\MI3AA1~1\INetRepl.dll
    O9 - Extra button: (no name) - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\PROGRA~1\MI3AA1~1\INetRepl.dll
    O9 - Extra 'Tools' menuitem: Create Mobile Favorite... - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\PROGRA~1\MI3AA1~1\INetRepl.dll
    O9 - Extra button: PalTalk - {4EAFEF58-EEFA-4116-983D-03B49BCBFFFE} - C:\Program Files\Paltalk Messenger\Paltalk.exe (file missing)
    O9 - Extra button: Yahoo! Services - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\Program Files\Yahoo!\Common\yiesrvc.dll
    O9 - Extra button: Run DAP - {669695BC-A811-4A9D-8CDF-BA8C795F261C} - C:\PROGRA~1\DAP\DAP.EXE
    O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\system32\Shdocvw.dll
    O9 - Extra button: Open Last Closed Tab - {e05e75e9-a653-42a3-8d05-f2f7e309bdca} - mscoree.dll (file missing)
    O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
    O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
    O9 - Extra button: Yahoo! Messenger - {E5D12C4E-7B4F-11D3-B5C9-0050045C3C96} - C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe
    O9 - Extra 'Tools' menuitem: Yahoo! Messenger - {E5D12C4E-7B4F-11D3-B5C9-0050045C3C96} - C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe
    O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
    O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
    O11 - Options group: [INTERNATIONAL] International*
    O16 - DPF: vzTCPConfig - http://www2.verizon.net/help/dsl_set...zTCPConfig.CAB
    O16 - DPF: {01A88BB1-1174-41EC-ACCB-963509EAE56B} (SysProWmi Class) - http://support.dell.com/systemprofiler/SysPro.CAB
    O16 - DPF: {0246ECA8-996F-11D1-BE2F-00A0C9037DFE} (TDServer Control) - http://www.xpres-net.com/wfplayer/tdserver.cab
    O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (YInstStarter Class) - C:\Program Files\Yahoo!\Common\yinsthelper.dll
    O16 - DPF: {3BA3B159-7533-4F96-A2CE-EE5894BBD3D5} (Scanner.SysScanner) - http://i.dell.com/images/global/js/s...SYSSCANNER.cab
    O16 - DPF: {3EA4FA88-E0BE-419A-A732-9B79B87A6ED0} (CTVUAxCtrl Object) - http://dl.tvunetworks.com/TVUAx.cab
    O16 - DPF: {406B5949-7190-4245-91A9-30A17DE16AD0} (Snapfish Activia) - http://photos.walmart.com/WalmartActivia.cab
    O16 - DPF: {4EC8E993-32C1-47F5-A07A-5B0574655AD4} (WXcom Class) - http://us.dl1.yimg.com/download.yaho...tr_current.cab
    O16 - DPF: {64696FB5-BA15-4920-B789-F35D3FC0A36A} (myax Control) - http://www.icannnews.com/app/ST/ax.ocx
    O16 - DPF: {A90A5822-F108-45AD-8482-9BC8B12DD539} (Crucial cpcScan) - http://www.crucial.com/controls/cpcScanner.cab
    O16 - DPF: {C5E28B9D-0A68-4B50-94E9-E8F6B4697514} (NsvPlayX Control) - http://www.nullsoft.com/nsv/embed/nsvplayx_vp3_mp3.cab
    O16 - DPF: {C606BA60-AB76-48B6-96A7-2C4D5C386F70} (PreQualifier Class) - http://www.verizon.net/whatsnext/che...ivePreQual.cab
    O16 - DPF: {E06E2E99-0AA1-11D4-ABA6-0060082AA75C} (GpcContainer Class) - https://pc.mywebexpc.com/client/v_my...ra/ieatgpc.cab
    O16 - DPF: {FCF289D4-0AC8-4ED8-BE31-E8AF09606AB5} (download_35mb_com.applet) - http://static.35mb.com/applet/applet_o.cab
    O16 - DPF: {FD0B6769-6490-4A91-AA0A-B5AE0DC75AC9} (Performance Viewer Activex Control) - https://secure.logmein.com/activex/ractrl.cab?lmi=100
    O17 - HKLM\System\CCS\Services\Tcpip\..\{EA297B4F-91B8-44BC-9D7B-3D896B715FDA}: NameServer = 192.168.0.1
    O21 - SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll
    O23 - Service: Ad-Aware 2007 Service (aawservice) - Lavasoft AB - C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
    O23 - Service: Adobe LM Service - Adobe Systems - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe
    O23 - Service: Canon Camera Access Library 8 (CCALib8) - Canon Inc. - C:\Program Files\Canon\CAL\CALMAIN.exe
    O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
    O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
    O23 - Service: Symantec AntiVirus Definition Watcher (DefWatch) - Symantec Corporation - C:\Program Files\Symantec AntiVirus\DefWatch.exe
    O23 - Service: DSBrokerService - Unknown owner - C:\Program Files\DellSupport\brkrsvc.exe
    O23 - Service: Sun ONE Web Server 6.1 Administration Server (https-admserv61) - Sun Microsystems, Inc. - C:\Sun\WebServer6.1\bin\https\bin\webservd-wdog.exe
    O23 - Service: Sun ONE Web Server 6.1 (https-KRD-DNB) (https-KRD-DNB) - Sun Microsystems, Inc. - C:\Sun\WebServer6.1\bin\https\bin\webservd-wdog.exe
    O23 - Service: Intel PDS - LANDesk Software Ltd. - C:\WINDOWS\system32\CBA\pds.exe
    O23 - Service: LiveUpdate - Symantec Corporation - C:\PROGRA~1\Symantec\LIVEUP~1\LUCOMS~1.EXE
    O23 - Service: lxcj_device - - C:\WINDOWS\system32\lxcjcoms.exe
    O23 - Service: Macromedia Licensing Service - Unknown owner - C:\Program Files\Common Files\Macromedia Shared\Service\Macromedia Licensing.exe
    O23 - Service: SonicWall VPN Client Service (RampartSvc) - SonicWALL, Inc. - C:\Program Files\SonicWALL\SonicWALL Global VPN Client\RampartSvc.exe
    O23 - Service: Symantec SPBBCSvc (SPBBCSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe
    O23 - Service: SupportSoft Sprocket Service (dellsupportcenter) (sprtsvc_dellsupportcenter) - SupportSoft, Inc. - C:\Program Files\Dell Support Center\bin\sprtsvc.exe
    O23 - Service: Symantec AntiVirus - Symantec Corporation - C:\Program Files\Symantec AntiVirus\Rtvscan.exe
     
  2. sesharam

    sesharam Thread Starter

    Joined:
    Nov 9, 2007
    Messages:
    4
    To give additional info:
    Infection was first detected when too many pop-ups sprung up all of a sudden. Scanning with Symantec anti-virus revealed numerous trojan files and 100s of count of each. Symantec apparently cleaned some but for many it could not clean immediately and asked for reboot. But i guess it didn't really remove the trojans because after reconnecting to the net, pop-ups would start coming back.

    (The infected laptop connects wirelessly to the internet but since the problem is persistent, I have switched off the wifi since yesterday).

    I tried Symantec's FixVundo but it is unable to find the vundo trojan. So I tried VundoFix and this was able to find one type that Symantec failed to find. This was last thing I tried. Now am waiting for some expert assistance from you.

    Many Thanks in advance once again.
     
  3. sesharam

    sesharam Thread Starter

    Joined:
    Nov 9, 2007
    Messages:
    4
    Update:

    I ran the Kaspersky online virus scanner. Attached below is the log:

    -------------------------------------------------------------------------------
    KASPERSKY ONLINE SCANNER REPORT
    Friday, November 09, 2007 7:56:53 PM
    Operating System: Microsoft Windows XP Home Edition, Service Pack 2 (Build 2600)
    Kaspersky Online Scanner version: 5.0.98.0
    Kaspersky Anti-Virus database last update: 10/11/2007
    Kaspersky Anti-Virus database records: 455609
    -------------------------------------------------------------------------------

    Scan Settings:
    Scan using the following antivirus database: extended
    Scan Archives: true
    Scan Mail Bases: true

    Scan Target - My Computer:
    C:\
    D:\

    Scan Statistics:
    Total number of scanned objects: 96428
    Number of viruses found: 4
    Number of infected objects: 9
    Number of suspicious objects: 0
    Duration of the scan process: 02:06:38

    Infected Object Name / Virus Name / Last Action
    C:\1b214f75ede4ee3eca51799d\update\5bfab1e7877da30ab93bd10b\admparse.dll Object is locked skipped
    C:\1b214f75ede4ee3eca51799d\update\5bfab1e7877da30ab93bd10b\advpack.dll Object is locked skipped
    C:\1b214f75ede4ee3eca51799d\update\5bfab1e7877da30ab93bd10b\browseui.dll Object is locked skipped
    C:\1b214f75ede4ee3eca51799d\update\5bfab1e7877da30ab93bd10b\corpol.dll Object is locked skipped
    C:\1b214f75ede4ee3eca51799d\update\5bfab1e7877da30ab93bd10b\custsat.dll Object is locked skipped
    C:\1b214f75ede4ee3eca51799d\update\5bfab1e7877da30ab93bd10b\dhtmled.ocx Object is locked skipped
    C:\1b214f75ede4ee3eca51799d\update\5bfab1e7877da30ab93bd10b\dxtmsft.dll Object is locked skipped
    C:\1b214f75ede4ee3eca51799d\update\5bfab1e7877da30ab93bd10b\dxtrans.dll Object is locked skipped
    C:\1b214f75ede4ee3eca51799d\update\5bfab1e7877da30ab93bd10b\extmgr.dll Object is locked skipped
    C:\1b214f75ede4ee3eca51799d\update\5bfab1e7877da30ab93bd10b\feeddisc.wav Object is locked skipped
    C:\1b214f75ede4ee3eca51799d\update\5bfab1e7877da30ab93bd10b\hmmapi.dll Object is locked skipped
    C:\1b214f75ede4ee3eca51799d\update\5bfab1e7877da30ab93bd10b\html.iec Object is locked skipped
    C:\1b214f75ede4ee3eca51799d\update\5bfab1e7877da30ab93bd10b\icardie.dll Object is locked skipped
    C:\1b214f75ede4ee3eca51799d\update\5bfab1e7877da30ab93bd10b\idndl.dll Object is locked skipped
    C:\1b214f75ede4ee3eca51799d\update\5bfab1e7877da30ab93bd10b\ie4uinit.exe Object is locked skipped
    C:\1b214f75ede4ee3eca51799d\update\5bfab1e7877da30ab93bd10b\ieakeng.dll Object is locked skipped
    C:\1b214f75ede4ee3eca51799d\update\5bfab1e7877da30ab93bd10b\ieakmmc.chm Object is locked skipped
    C:\1b214f75ede4ee3eca51799d\update\5bfab1e7877da30ab93bd10b\ieaksie.dll Object is locked skipped
    C:\1b214f75ede4ee3eca51799d\update\5bfab1e7877da30ab93bd10b\ieakui.dll Object is locked skipped
    C:\1b214f75ede4ee3eca51799d\update\5bfab1e7877da30ab93bd10b\ieapfltr.dat Object is locked skipped
    C:\1b214f75ede4ee3eca51799d\update\5bfab1e7877da30ab93bd10b\ieapfltr.dll Object is locked skipped
    C:\1b214f75ede4ee3eca51799d\update\5bfab1e7877da30ab93bd10b\iecustom.dll Object is locked skipped
    C:\1b214f75ede4ee3eca51799d\update\5bfab1e7877da30ab93bd10b\iedkcs32.dll Object is locked skipped
    C:\1b214f75ede4ee3eca51799d\update\5bfab1e7877da30ab93bd10b\iedw.exe Object is locked skipped
    C:\1b214f75ede4ee3eca51799d\update\5bfab1e7877da30ab93bd10b\ieencode.dll Object is locked skipped
    C:\1b214f75ede4ee3eca51799d\update\5bfab1e7877da30ab93bd10b\ieeula.chm Object is locked skipped
    C:\1b214f75ede4ee3eca51799d\update\5bfab1e7877da30ab93bd10b\ieframe.dll Object is locked skipped
    C:\1b214f75ede4ee3eca51799d\update\5bfab1e7877da30ab93bd10b\iepeers.dll Object is locked skipped
    C:\1b214f75ede4ee3eca51799d\update\5bfab1e7877da30ab93bd10b\ieproxy.dll Object is locked skipped
    C:\1b214f75ede4ee3eca51799d\update\5bfab1e7877da30ab93bd10b\iernonce.dll Object is locked skipped
    C:\1b214f75ede4ee3eca51799d\update\5bfab1e7877da30ab93bd10b\iertutil.dll Object is locked skipped
    C:\1b214f75ede4ee3eca51799d\update\5bfab1e7877da30ab93bd10b\iesetup.dll Object is locked skipped
    C:\1b214f75ede4ee3eca51799d\update\5bfab1e7877da30ab93bd10b\iesupp.chm Object is locked skipped
    C:\1b214f75ede4ee3eca51799d\update\5bfab1e7877da30ab93bd10b\ieui.dll Object is locked skipped
    C:\1b214f75ede4ee3eca51799d\update\5bfab1e7877da30ab93bd10b\ieuinit.inf Object is locked skipped
    C:\1b214f75ede4ee3eca51799d\update\5bfab1e7877da30ab93bd10b\iexplore.chm Object is locked skipped
    C:\1b214f75ede4ee3eca51799d\update\5bfab1e7877da30ab93bd10b\iexplore.exe Object is locked skipped
    C:\1b214f75ede4ee3eca51799d\update\5bfab1e7877da30ab93bd10b\imgutil.dll Object is locked skipped
    C:\1b214f75ede4ee3eca51799d\update\5bfab1e7877da30ab93bd10b\inetcorp.adm Object is locked skipped
    C:\1b214f75ede4ee3eca51799d\update\5bfab1e7877da30ab93bd10b\inetcpl.cpl Object is locked skipped
    C:\1b214f75ede4ee3eca51799d\update\5bfab1e7877da30ab93bd10b\inetset.adm Object is locked skipped
    C:\1b214f75ede4ee3eca51799d\update\5bfab1e7877da30ab93bd10b\infobar.wav Object is locked skipped
    C:\1b214f75ede4ee3eca51799d\update\5bfab1e7877da30ab93bd10b\inseng.dll Object is locked skipped
    C:\1b214f75ede4ee3eca51799d\update\5bfab1e7877da30ab93bd10b\install.ins Object is locked skipped
    C:\1b214f75ede4ee3eca51799d\update\5bfab1e7877da30ab93bd10b\jgaw400.dll Object is locked skipped
    C:\1b214f75ede4ee3eca51799d\update\5bfab1e7877da30ab93bd10b\jgdw400.dll Object is locked skipped
    C:\1b214f75ede4ee3eca51799d\update\5bfab1e7877da30ab93bd10b\jgmd400.dll Object is locked skipped
    C:\1b214f75ede4ee3eca51799d\update\5bfab1e7877da30ab93bd10b\jgpl400.dll Object is locked skipped
    C:\1b214f75ede4ee3eca51799d\update\5bfab1e7877da30ab93bd10b\jgsd400.dll Object is locked skipped
    C:\1b214f75ede4ee3eca51799d\update\5bfab1e7877da30ab93bd10b\jgsh400.dll Object is locked skipped
    C:\1b214f75ede4ee3eca51799d\update\5bfab1e7877da30ab93bd10b\jscript.dll Object is locked skipped
    C:\1b214f75ede4ee3eca51799d\update\5bfab1e7877da30ab93bd10b\jsproxy.dll Object is locked skipped
    C:\1b214f75ede4ee3eca51799d\update\5bfab1e7877da30ab93bd10b\licmgr10.dll Object is locked skipped
    C:\1b214f75ede4ee3eca51799d\update\5bfab1e7877da30ab93bd10b\msfeeds.dll Object is locked skipped
    C:\1b214f75ede4ee3eca51799d\update\5bfab1e7877da30ab93bd10b\msfeedsbs.dll Object is locked skipped
    C:\1b214f75ede4ee3eca51799d\update\5bfab1e7877da30ab93bd10b\mshta.exe Object is locked skipped
    C:\1b214f75ede4ee3eca51799d\update\5bfab1e7877da30ab93bd10b\mshtml.dll Object is locked skipped
    C:\1b214f75ede4ee3eca51799d\update\5bfab1e7877da30ab93bd10b\mshtml.tlb Object is locked skipped
    C:\1b214f75ede4ee3eca51799d\update\5bfab1e7877da30ab93bd10b\mshtmled.dll Object is locked skipped
    C:\1b214f75ede4ee3eca51799d\update\5bfab1e7877da30ab93bd10b\mshtmler.dll Object is locked skipped
    C:\1b214f75ede4ee3eca51799d\update\5bfab1e7877da30ab93bd10b\msls31.dll Object is locked skipped
    C:\1b214f75ede4ee3eca51799d\update\5bfab1e7877da30ab93bd10b\msrating.dll Object is locked skipped
    C:\1b214f75ede4ee3eca51799d\update\5bfab1e7877da30ab93bd10b\mstime.dll Object is locked skipped
    C:\1b214f75ede4ee3eca51799d\update\5bfab1e7877da30ab93bd10b\navstart.wav Object is locked skipped
    C:\1b214f75ede4ee3eca51799d\update\5bfab1e7877da30ab93bd10b\normaliz.dll Object is locked skipped
    C:\1b214f75ede4ee3eca51799d\update\5bfab1e7877da30ab93bd10b\normidna.nls Object is locked skipped
    C:\1b214f75ede4ee3eca51799d\update\5bfab1e7877da30ab93bd10b\normnfc.nls Object is locked skipped
    C:\1b214f75ede4ee3eca51799d\update\5bfab1e7877da30ab93bd10b\normnfd.nls Object is locked skipped
    C:\1b214f75ede4ee3eca51799d\update\5bfab1e7877da30ab93bd10b\normnfkc.nls Object is locked skipped
    C:\1b214f75ede4ee3eca51799d\update\5bfab1e7877da30ab93bd10b\normnfkd.nls Object is locked skipped
    C:\1b214f75ede4ee3eca51799d\update\5bfab1e7877da30ab93bd10b\occache.dll Object is locked skipped
    C:\1b214f75ede4ee3eca51799d\update\5bfab1e7877da30ab93bd10b\occache.ini Object is locked skipped
    C:\1b214f75ede4ee3eca51799d\update\5bfab1e7877da30ab93bd10b\pngfilt.dll Object is locked skipped
    C:\1b214f75ede4ee3eca51799d\update\5bfab1e7877da30ab93bd10b\popupblk.wav Object is locked skipped
    C:\1b214f75ede4ee3eca51799d\update\5bfab1e7877da30ab93bd10b\rsaci.rat Object is locked skipped
    C:\1b214f75ede4ee3eca51799d\update\5bfab1e7877da30ab93bd10b\shdocvw.dll Object is locked skipped
    C:\1b214f75ede4ee3eca51799d\update\5bfab1e7877da30ab93bd10b\shlwapi.dll Object is locked skipped
    C:\1b214f75ede4ee3eca51799d\update\5bfab1e7877da30ab93bd10b\spmsg.dll Object is locked skipped
    C:\1b214f75ede4ee3eca51799d\update\5bfab1e7877da30ab93bd10b\spuninst.exe Object is locked skipped
    C:\1b214f75ede4ee3eca51799d\update\5bfab1e7877da30ab93bd10b\spupdsvc.exe Object is locked skipped
    C:\1b214f75ede4ee3eca51799d\update\5bfab1e7877da30ab93bd10b\tdc.ocx Object is locked skipped
    C:\1b214f75ede4ee3eca51799d\update\5bfab1e7877da30ab93bd10b\triedit.dll Object is locked skipped
    C:\1b214f75ede4ee3eca51799d\update\5bfab1e7877da30ab93bd10b\update\eula.rtf Object is locked skipped
    C:\1b214f75ede4ee3eca51799d\update\5bfab1e7877da30ab93bd10b\update\eula.txt Object is locked skipped
    C:\1b214f75ede4ee3eca51799d\update\5bfab1e7877da30ab93bd10b\update\ie7bet2p.cat Object is locked skipped
    C:\1b214f75ede4ee3eca51799d\update\5bfab1e7877da30ab93bd10b\update\iecustom.dll Object is locked skipped
    C:\1b214f75ede4ee3eca51799d\update\5bfab1e7877da30ab93bd10b\update\iecustom.dll.manifest Object is locked skipped
    C:\1b214f75ede4ee3eca51799d\update\5bfab1e7877da30ab93bd10b\update\iesetup.exe Object is locked skipped
    C:\1b214f75ede4ee3eca51799d\update\5bfab1e7877da30ab93bd10b\update\kb904942.cat Object is locked skipped
    C:\1b214f75ede4ee3eca51799d\update\5bfab1e7877da30ab93bd10b\update\legitlib.dll Object is locked skipped
    C:\1b214f75ede4ee3eca51799d\update\5bfab1e7877da30ab93bd10b\update\update.exe Object is locked skipped
    C:\1b214f75ede4ee3eca51799d\update\5bfab1e7877da30ab93bd10b\update\update.exe.manifest Object is locked skipped
    C:\1b214f75ede4ee3eca51799d\update\5bfab1e7877da30ab93bd10b\update\update.inf Object is locked skipped
    C:\1b214f75ede4ee3eca51799d\update\5bfab1e7877da30ab93bd10b\update\update.ver Object is locked skipped
    C:\1b214f75ede4ee3eca51799d\update\5bfab1e7877da30ab93bd10b\update\updspapi.dll Object is locked skipped
    C:\1b214f75ede4ee3eca51799d\update\5bfab1e7877da30ab93bd10b\url.dll Object is locked skipped
    C:\1b214f75ede4ee3eca51799d\update\5bfab1e7877da30ab93bd10b\urlmon.dll Object is locked skipped
    C:\1b214f75ede4ee3eca51799d\update\5bfab1e7877da30ab93bd10b\vgx.dll Object is locked skipped
    C:\1b214f75ede4ee3eca51799d\update\5bfab1e7877da30ab93bd10b\wdigest.dll Object is locked skipped
    C:\1b214f75ede4ee3eca51799d\update\5bfab1e7877da30ab93bd10b\webcheck.dll Object is locked skipped
    C:\1b214f75ede4ee3eca51799d\update\5bfab1e7877da30ab93bd10b\webcheck.ini Object is locked skipped
    C:\1b214f75ede4ee3eca51799d\update\5bfab1e7877da30ab93bd10b\winfxdocobj.exe Object is locked skipped
    C:\1b214f75ede4ee3eca51799d\update\5bfab1e7877da30ab93bd10b\wininet.dll Object is locked skipped
    C:\1b214f75ede4ee3eca51799d\update\5bfab1e7877da30ab93bd10b\xmllite.dll Object is locked skipped
    C:\Documents and Settings\All Users\Application Data\Microsoft\Network\Downloader\qmgr0.dat Object is locked skipped
    C:\Documents and Settings\All Users\Application Data\Microsoft\Network\Downloader\qmgr1.dat Object is locked skipped
    C:\Documents and Settings\All Users\Application Data\Microsoft\VISIO\catalog.wci\00000002.ps1 Object is locked skipped
    C:\Documents and Settings\All Users\Application Data\Microsoft\VISIO\catalog.wci\00000002.ps2 Object is locked skipped
    C:\Documents and Settings\All Users\Application Data\Microsoft\VISIO\catalog.wci\00010003.ci Object is locked skipped
    C:\Documents and Settings\All Users\Application Data\Microsoft\VISIO\catalog.wci\cicat.fid Object is locked skipped
    C:\Documents and Settings\All Users\Application Data\Microsoft\VISIO\catalog.wci\cicat.hsh Object is locked skipped
    C:\Documents and Settings\All Users\Application Data\Microsoft\VISIO\catalog.wci\CiCL0001.000 Object is locked skipped
    C:\Documents and Settings\All Users\Application Data\Microsoft\VISIO\catalog.wci\CiP10000.000 Object is locked skipped
    C:\Documents and Settings\All Users\Application Data\Microsoft\VISIO\catalog.wci\CiP20000.000 Object is locked skipped
    C:\Documents and Settings\All Users\Application Data\Microsoft\VISIO\catalog.wci\CiPT0000.000 Object is locked skipped
    C:\Documents and Settings\All Users\Application Data\Microsoft\VISIO\catalog.wci\CiSL0001.000 Object is locked skipped
    C:\Documents and Settings\All Users\Application Data\Microsoft\VISIO\catalog.wci\CiSP0000.000 Object is locked skipped
    C:\Documents and Settings\All Users\Application Data\Microsoft\VISIO\catalog.wci\CiST0000.000 Object is locked skipped
    C:\Documents and Settings\All Users\Application Data\Microsoft\VISIO\catalog.wci\CiVP0000.000 Object is locked skipped
    C:\Documents and Settings\All Users\Application Data\Microsoft\VISIO\catalog.wci\INDEX.000 Object is locked skipped
    C:\Documents and Settings\All Users\Application Data\Microsoft\VISIO\catalog.wci\propstor.bk1 Object is locked skipped
    C:\Documents and Settings\All Users\Application Data\Microsoft\VISIO\catalog.wci\propstor.bk2 Object is locked skipped
    C:\Documents and Settings\All Users\Application Data\Microsoft\Windows Defender\Support\MPLog-05112007-083348.log Object is locked skipped
    C:\Documents and Settings\All Users\Application Data\SupportSoft\DellSupportCenter\SYSTEM\state\logs\sprtcmd.log Object is locked skipped
    C:\Documents and Settings\All Users\Application Data\Symantec\Common Client\settings.dat Object is locked skipped
    C:\Documents and Settings\All Users\Application Data\Symantec\Symantec AntiVirus Corporate Edition\7.5\Quarantine\08480001\4F7BDF6F.VBN Infected: not-a-virus:AdWare.Win32.Virtumonde.ahr skipped
    C:\Documents and Settings\Dhruv.KRD-DNB\Local Settings\Temporary Internet Files\AntiPhishing\07FB382D-AA75-4683-82F4-EAB265A275CB.dat Object is locked skipped
    C:\Documents and Settings\Dhruv.KRD-DNB\Local Settings\Temporary Internet Files\AntiPhishing\6729BBF9-D54C-48CB-A4D7-AD400339D808.dat Object is locked skipped
    C:\Documents and Settings\Kavi\Application Data\$_hpcst$.hpc Object is locked skipped
    C:\Documents and Settings\Kavi\Application Data\Gtek\GTUpdate\AUpdate\DellSupport\DSAgnt.log Object is locked skipped
    C:\Documents and Settings\Kavi\Application Data\Gtek\GTUpdate\AUpdate\DellSupport\DSAgnt_GTActions.log Object is locked skipped
    C:\Documents and Settings\Kavi\Application Data\Gtek\GTUpdate\AUpdate\DellSupport\gdql_d_DSAgnt.log Object is locked skipped
    C:\Documents and Settings\Kavi\Application Data\Gtek\GTUpdate\AUpdate\DellSupport\glog.log Object is locked skipped
    C:\Documents and Settings\Kavi\Cookies\index.dat Object is locked skipped
    C:\Documents and Settings\Kavi\Local Settings\Application Data\Microsoft\Feeds Cache\index.dat Object is locked skipped
    C:\Documents and Settings\Kavi\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat Object is locked skipped
    C:\Documents and Settings\Kavi\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped
    C:\Documents and Settings\Kavi\Local Settings\Application Data\Microsoft\Windows Defender\FileTracker\{58AEBDE8-6FC9-4AD9-8DFD-C1D875B22387} Object is locked skipped
    C:\Documents and Settings\Kavi\Local Settings\Application Data\SupportSoft\DellSupportCenter\Kavi\state\logs\sprtcmd.log Object is locked skipped
    C:\Documents and Settings\Kavi\Local Settings\History\History.IE5\index.dat Object is locked skipped
    C:\Documents and Settings\Kavi\Local Settings\History\History.IE5\MSHist012007110920071110\index.dat Object is locked skipped
    C:\Documents and Settings\Kavi\Local Settings\Temp\WCESLog.log Object is locked skipped
    C:\Documents and Settings\Kavi\Local Settings\Temp\xpre.exe Infected: Trojan-Downloader.Win32.VB.axa skipped
    C:\Documents and Settings\Kavi\Local Settings\Temporary Internet Files\AntiPhishing\B3BB5BBA-E7D5-40AB-A041-A5B1C0B26C8F.dat Object is locked skipped
    C:\Documents and Settings\Kavi\Local Settings\Temporary Internet Files\Content.IE5\index.dat Object is locked skipped
    C:\Documents and Settings\Kavi\NTUSER.DAT Object is locked skipped
    C:\Documents and Settings\Kavi\ntuser.dat.LOG Object is locked skipped
    C:\Documents and Settings\LocalService\Cookies\index.dat Object is locked skipped
    C:\Documents and Settings\LocalService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat Object is locked skipped
    C:\Documents and Settings\LocalService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped
    C:\Documents and Settings\LocalService\Local Settings\History\History.IE5\index.dat Object is locked skipped
    C:\Documents and Settings\LocalService\Local Settings\Temporary Internet Files\Content.IE5\index.dat Object is locked skipped
    C:\Documents and Settings\LocalService\NTUSER.DAT Object is locked skipped
    C:\Documents and Settings\LocalService\ntuser.dat.LOG Object is locked skipped
    C:\Documents and Settings\NetworkService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat Object is locked skipped
    C:\Documents and Settings\NetworkService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped
    C:\Documents and Settings\NetworkService\NTUSER.DAT Object is locked skipped
    C:\Documents and Settings\NetworkService\ntuser.dat.LOG Object is locked skipped
    C:\Program Files\Common Files\Symantec Shared\EENGINE\EPERSIST.DAT Object is locked skipped
    C:\Program Files\Common Files\Symantec Shared\SPBBC\LOGS\BBConfig.log Object is locked skipped
    C:\Program Files\Common Files\Symantec Shared\SPBBC\LOGS\BBDebug.log Object is locked skipped
    C:\Program Files\Common Files\Symantec Shared\SPBBC\LOGS\BBDetect.log Object is locked skipped
    C:\Program Files\Common Files\Symantec Shared\SPBBC\LOGS\BBNotify.log Object is locked skipped
    C:\Program Files\Common Files\Symantec Shared\SPBBC\LOGS\BBRefr.log Object is locked skipped
    C:\Program Files\Common Files\Symantec Shared\SPBBC\LOGS\BBSetCfg.log Object is locked skipped
    C:\Program Files\Common Files\Symantec Shared\SPBBC\LOGS\BBSetCfg2.log Object is locked skipped
    C:\Program Files\Common Files\Symantec Shared\SPBBC\LOGS\BBSetDev.log Object is locked skipped
    C:\Program Files\Common Files\Symantec Shared\SPBBC\LOGS\BBSetLoc.log Object is locked skipped
    C:\Program Files\Common Files\Symantec Shared\SPBBC\LOGS\BBSetUsr.log Object is locked skipped
    C:\Program Files\Common Files\Symantec Shared\SPBBC\LOGS\BBSMNot.log Object is locked skipped
    C:\Program Files\Common Files\Symantec Shared\SPBBC\LOGS\BBSMReg.log Object is locked skipped
    C:\Program Files\Common Files\Symantec Shared\SPBBC\LOGS\BBSMRSt.log Object is locked skipped
    C:\Program Files\Common Files\Symantec Shared\SPBBC\LOGS\BBStHash.log Object is locked skipped
    C:\Program Files\Common Files\Symantec Shared\SPBBC\LOGS\BBStMSI.log Object is locked skipped
    C:\Program Files\Common Files\Symantec Shared\SPBBC\LOGS\BBValid.log Object is locked skipped
    C:\Program Files\Common Files\Symantec Shared\SPBBC\LOGS\SPPolicy.log Object is locked skipped
    C:\Program Files\Common Files\Symantec Shared\SPBBC\LOGS\SPStart.log Object is locked skipped
    C:\Program Files\Common Files\Symantec Shared\SPBBC\LOGS\SPStop.log Object is locked skipped
    C:\Program Files\DAP\Offers\spo3.exe/WISE0010.BIN Infected: not-a-virus:AdTool.Win32.MyWebSearch.bk skipped
    C:\Program Files\DAP\Offers\spo3.exe WiseSFX: infected - 1 skipped
    C:\Program Files\DAP\Offers\spo3.exe WiseSFX Dropper: infected - 1 skipped
    C:\Program Files\DAP\Offers\VA21_DAPSO_US.exe/WISE0009.BIN Infected: not-a-virus:AdTool.Win32.MyWebSearch.bk skipped
    C:\Program Files\DAP\Offers\VA21_DAPSO_US.exe WiseSFX: infected - 1 skipped
    C:\Program Files\DAP\Offers\VA21_DAPSO_US.exe WiseSFX Dropper: infected - 1 skipped
    C:\Program Files\Symantec AntiVirus\SAVRT\0018NAV~.TMP Object is locked skipped
    C:\Program Files\Symantec AntiVirus\SAVRT\0528NAV~.TMP Object is locked skipped
    C:\System Volume Information\MountPointManagerRemoteDatabase Object is locked skipped
    C:\WINDOWS\Debug\PASSWD.LOG Object is locked skipped
    C:\WINDOWS\Downloaded Program Files\tdserver.ocx Infected: not-a-virus:AdWare.Win32.AdWeb.a skipped
    C:\WINDOWS\SchedLgU.Txt Object is locked skipped
    C:\WINDOWS\SoftwareDistribution\ReportingEvents.log Object is locked skipped
    C:\WINDOWS\Sti_Trace.log Object is locked skipped
    C:\WINDOWS\system32\CatRoot2\edb.log Object is locked skipped
    C:\WINDOWS\system32\CatRoot2\tmp.edb Object is locked skipped
    C:\WINDOWS\system32\config\AppEvent.Evt Object is locked skipped
    C:\WINDOWS\system32\config\DEFAULT Object is locked skipped
    C:\WINDOWS\system32\config\default.LOG Object is locked skipped
    C:\WINDOWS\system32\config\Internet.evt Object is locked skipped
    C:\WINDOWS\system32\config\ODiag.evt Object is locked skipped
    C:\WINDOWS\system32\config\OSession.evt Object is locked skipped
    C:\WINDOWS\system32\config\SAM Object is locked skipped
    C:\WINDOWS\system32\config\SAM.LOG Object is locked skipped
    C:\WINDOWS\system32\config\SecEvent.Evt Object is locked skipped
    C:\WINDOWS\system32\config\SECURITY Object is locked skipped
    C:\WINDOWS\system32\config\SECURITY.LOG Object is locked skipped
    C:\WINDOWS\system32\config\SOFTWARE Object is locked skipped
    C:\WINDOWS\system32\config\software.LOG Object is locked skipped
    C:\WINDOWS\system32\config\SysEvent.Evt Object is locked skipped
    C:\WINDOWS\system32\config\SYSTEM Object is locked skipped
    C:\WINDOWS\system32\config\system.LOG Object is locked skipped
    C:\WINDOWS\system32\h323log.txt Object is locked skipped
    C:\WINDOWS\system32\wbem\Repository\FS\INDEX.BTR Object is locked skipped
    C:\WINDOWS\system32\wbem\Repository\FS\INDEX.MAP Object is locked skipped
    C:\WINDOWS\system32\wbem\Repository\FS\MAPPING.VER Object is locked skipped
    C:\WINDOWS\system32\wbem\Repository\FS\MAPPING1.MAP Object is locked skipped
    C:\WINDOWS\system32\wbem\Repository\FS\MAPPING2.MAP Object is locked skipped
    C:\WINDOWS\system32\wbem\Repository\FS\OBJECTS.DATA Object is locked skipped
    C:\WINDOWS\system32\wbem\Repository\FS\OBJECTS.MAP Object is locked skipped
    C:\WINDOWS\wiadebug.log Object is locked skipped
    C:\WINDOWS\wiaservc.log Object is locked skipped
    C:\WINDOWS\WindowsUpdate.log Object is locked skipped

    Scan process completed.

    ---------------------------------------End of log ---------------------------

    Computer is extremely slow. Takes incredibly long to start as well.

    Many thanks in advance! Appreciate your time and advice.
     
  4. sesharam

    sesharam Thread Starter

    Joined:
    Nov 9, 2007
    Messages:
    4
    Update:

    Formatted my HD and reinstalled everything.

    Thanks.
     
As Seen On
As Seen On...

Welcome to Tech Support Guy!

Are you looking for the solution to your computer problem? Join our site today to ask your question. This site is completely free -- paid for by advertisers and donations.

If you're not already familiar with forums, watch our Welcome Guide to get started.

Join over 733,556 other people just like you!

Loading...
Thread Status:
Not open for further replies.

Short URL to this thread: https://techguy.org/649829

  1. This site uses cookies to help personalise content, tailor your experience and to keep you logged in if you register.
    By continuing to use this site, you are consenting to our use of cookies.
    Dismiss Notice