ComboFix Log
."Larry" - 2007-06-30 15:54:39 - ComboFix 07-06-27.7 - Service Pack 2 NTFS
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
C:\Program Files\winpop
((((((((((((((((((((((((( Files Created from 2007-05-28 to 2007-06-30 )))))))))))))))))))))))))))))))
2007-06-30 02:36 d-------- C:\Burning Crusade
2007-06-28 14:42 d-------- C:\Program Files\CCleaner
2007-06-27 14:31 786,432 --ah----- C:\DOCUME~1\ADMINI~1\NTUSER.DAT
2007-06-27 01:53 53,248 --a------ C:\WINDOWS\system32\Process.exe
2007-06-27 01:53 51,200 --a------ C:\WINDOWS\system32\dumphive.exe
2007-06-27 01:53 288,417 --a------ C:\WINDOWS\system32\SrchSTS.exe
2007-06-27 01:53 2,482 --a------ C:\WINDOWS\system32\tmp.reg
2007-06-26 00:44 d-------- C:\Program Files\backups
2007-06-25 23:04 49,152 --a------ C:\WINDOWS\nircmd.exe
2007-06-25 22:51 664 --a------ C:\WINDOWS\system32\d3d9caps.dat
2007-06-25 21:26 d-------- C:\WINDOWS\system32\ActiveScan
2007-06-25 20:41 1,308,216 --a------ C:\Program Files\imsubtle.exe
2007-06-25 20:24 83,024 --a------ C:\WINDOWS\system32\drivers\iksyssec.sys
2007-06-25 20:24 57,424 --a------ C:\WINDOWS\system32\drivers\iksysflt.sys
2007-06-25 20:24 53,840 --a------ C:\WINDOWS\system32\drivers\ikfilesec.sys
2007-06-25 20:24 39,376 --a------ C:\WINDOWS\system32\drivers\ikfileflt.sys
2007-06-25 20:24 29,264 --a------ C:\WINDOWS\system32\drivers\kcom.sys
2007-06-25 20:24 d-------- C:\Program Files\Spyware Doctor
2007-06-25 20:24 d-------- C:\DOCUME~1\Larry\APPLIC~1\PC Tools
2007-06-25 20:24 d-------- C:\DOCUME~1\ALLUSE~1\APPLIC~1\Google
2007-06-25 00:50 59,264 --a------ C:\WINDOWS\system32\drivers\USBAUDIO.sys
2007-06-24 22:05 d-------- C:\Program Files\Psicraft
2007-06-24 22:05 d-------- C:\DOCUME~1\Larry\APPLIC~1\Psicraft
2007-06-24 21:35 d-------- C:\Program Files\Line6
2007-06-24 21:35 d-------- C:\DOCUME~1\Larry\APPLIC~1\Line 6
2007-05-08 21:53 443,752 --a------ C:\WINDOWS\system32\d3dx10_33.dll
2007-05-08 21:53 3,495,784 --a------ C:\WINDOWS\system32\d3dx9_33.dll
2007-05-08 21:53 261,480 --a------ C:\WINDOWS\system32\xactengine2_7.dll
2007-05-08 21:53 255,848 --a------ C:\WINDOWS\system32\xactengine2_6.dll
2007-05-08 21:53 251,672 --a------ C:\WINDOWS\system32\xactengine2_5.dll
2007-05-08 21:53 1,123,696 --a------ C:\WINDOWS\system32\D3DCompiler_33.dll
2007-05-08 21:52 d--h----- C:\WINDOWS\msdownld.tmp
2007-05-08 21:51 d-------- C:\WINDOWS\system32\AGEIA
2007-05-08 21:51 d-------- C:\Program Files\AGEIA Technologies
2007-05-08 21:46 d-------- C:\Program Files\Timeline Interactive
2007-05-05 02:55 90,112 --a------ C:\WINDOWS\unvise32.exe
2007-05-05 02:52 d-------- C:\Program Files\e frontier
2007-05-01 18:24 3,968 --a------ C:\WINDOWS\system32\drivers\AvgAsCln.sys
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
2007-06-30 19:52:38 -------- d-----w C:\DOCUME~1\Larry\APPLIC~1\Xfire
2007-06-30 07:49:58 -------- d-s---w C:\Program Files\Xfire
2007-06-30 07:44:47 -------- d-----w C:\Program Files\NavNT
2007-06-30 07:44:47 -------- d-----w C:\Program Files\ewido anti-spyware 4.0
2007-06-30 07:44:22 -------- d-----w C:\Program Files\AIM
2007-06-29 06:29:50 -------- d-----w C:\Program Files\World of Warcraft
2007-06-29 05:12:10 -------- d-----w C:\Program Files\Total Video Converter
2007-06-28 07:47:50 -------- d-----w C:\Program Files\Steam
2007-06-27 20:59:37 -------- d-----w C:\Program Files\Windows NT
2007-06-26 03:40:17 -------- d-----w C:\Program Files\BraveTree
2007-06-26 03:35:42 -------- d-----w C:\Program Files\Google
2007-06-26 02:51:45 1,100 ----a-w C:\WINDOWS\system32\d3d8caps.dat
2007-06-26 00:35:57 -------- d-----w C:\DOCUME~1\Larry\APPLIC~1\Google
2007-06-19 19:04:30 -------- d-----w C:\Program Files\GCH Guitar academy
2007-06-19 03:43:07 -------- d-----w C:\DOCUME~1\Larry\APPLIC~1\IGN_DLM
2007-06-16 05:16:32 -------- d-----w C:\Program Files\Mp3 My Mp3 2.0
2007-06-08 03:42:21 -------- d--h--w C:\Program Files\InstallShield Installation Information
2007-05-20 00:20:05 43,520 ----a-w C:\WINDOWS\system32\CmdLineExt03.dll
2007-05-16 15:12:02 683,520 ----a-w C:\WINDOWS\system32\inetcomm.dll
2007-05-09 01:51:14 -------- d-----w C:\Program Files\Common Files\Wise Installation Wizard
2007-04-25 14:21:15 144,896 ----a-w C:\WINDOWS\system32\schannel.dll
2007-04-19 17:26:00 888,832 ----a-w C:\WINDOWS\system32\nvmobls.dll
2007-04-19 17:26:00 86,016 ----a-w C:\WINDOWS\system32\nvmctray.dll
2007-04-19 17:26:00 81,920 ----a-w C:\WINDOWS\system32\nvwddi.dll
2007-04-19 17:26:00 794,624 ----a-w C:\WINDOWS\system32\nvcplui.exe
2007-04-19 17:26:00 7,700,480 ----a-w C:\WINDOWS\system32\nvcpl.dll
2007-04-19 17:26:00 581,632 ----a-w C:\WINDOWS\system32\nvhwvid.dll
2007-04-19 17:26:00 5,644,288 ----a-w C:\WINDOWS\system32\nvoglnt.dll
2007-04-19 17:26:00 5,619,712 ----a-w C:\WINDOWS\system32\nvdisps.dll
2007-04-19 17:26:00 5,255,168 ----a-w C:\WINDOWS\system32\nvdispsr.dll
2007-04-19 17:26:00 466,944 ----a-w C:\WINDOWS\system32\nvshell.dll
2007-04-19 17:26:00 458,752 ----a-w C:\WINDOWS\system32\nvmccssr.dll
2007-04-19 17:26:00 45,056 ----a-w C:\WINDOWS\system32\nvmccsrs.dll
2007-04-19 17:26:00 442,368 ----a-w C:\WINDOWS\system32\nvappbar.exe
2007-04-19 17:26:00 425,984 ----a-w C:\WINDOWS\system32\keystone.exe
2007-04-19 17:26:00 4,543,616 ----a-w C:\WINDOWS\system32\nv4_disp.dll
2007-04-19 17:26:00 35,840 ----a-w C:\WINDOWS\system32\nvcodins.dll
2007-04-19 17:26:00 35,840 ----a-w C:\WINDOWS\system32\nvcod.dll
2007-04-19 17:26:00 335,872 ----a-w C:\WINDOWS\system32\nvwrses.dll
2007-04-19 17:26:00 335,872 ----a-w C:\WINDOWS\system32\nvwrsel.dll
2007-04-19 17:26:00 327,680 ----a-w C:\WINDOWS\system32\nvwrsfr.dll
2007-04-19 17:26:00 327,680 ----a-w C:\WINDOWS\system32\nvwrsesm.dll
2007-04-19 17:26:00 323,584 ----a-w C:\WINDOWS\system32\nvwrspt.dll
2007-04-19 17:26:00 323,584 ----a-w C:\WINDOWS\system32\nvwrsit.dll
2007-04-19 17:26:00 323,584 ----a-w C:\WINDOWS\system32\nvrshe.dll
2007-04-19 17:26:00 323,584 ----a-w C:\WINDOWS\system32\nvrsar.dll
2007-04-19 17:26:00 319,488 ----a-w C:\WINDOWS\system32\nvwrsptb.dll
2007-04-19 17:26:00 319,488 ----a-w C:\WINDOWS\system32\nvwrsnl.dll
2007-04-19 17:26:00 315,392 ----a-w C:\WINDOWS\system32\nvwrsru.dll
2007-04-19 17:26:00 315,392 ----a-w C:\WINDOWS\system32\nvwrshu.dll
2007-04-19 17:26:00 311,296 ----a-w C:\WINDOWS\system32\nvwrsde.dll
2007-04-19 17:26:00 311,296 ----a-w C:\WINDOWS\system32\nvexpbar.dll
2007-04-19 17:26:00 303,104 ----a-w C:\WINDOWS\system32\nvwrstr.dll
2007-04-19 17:26:00 303,104 ----a-w C:\WINDOWS\system32\nvwrssl.dll
2007-04-19 17:26:00 303,104 ----a-w C:\WINDOWS\system32\nvwrsfi.dll
2007-04-19 17:26:00 3,203,072 ----a-w C:\WINDOWS\system32\nvgamesr.dll
2007-04-19 17:26:00 3,035,136 ----a-w C:\WINDOWS\system32\nvgames.dll
2007-04-19 17:26:00 299,008 ----a-w C:\WINDOWS\system32\nvwrssk.dll
2007-04-19 17:26:00 299,008 ----a-w C:\WINDOWS\system32\nvwrsno.dll
2007-04-19 17:26:00 294,912 ----a-w C:\WINDOWS\system32\nvwrssv.dll
2007-04-19 17:26:00 294,912 ----a-w C:\WINDOWS\system32\nvwrspl.dll
2007-04-19 17:26:00 294,912 ----a-w C:\WINDOWS\system32\nvwrsda.dll
2007-04-19 17:26:00 286,720 ----a-w C:\WINDOWS\system32\nvwrseng.dll
2007-04-19 17:26:00 286,720 ----a-w C:\WINDOWS\system32\nvwrscs.dll
2007-04-19 17:26:00 286,720 ----a-w C:\WINDOWS\system32\nvnt4cpl.dll
2007-04-19 17:26:00 282,624 ----a-w C:\WINDOWS\system32\nvwrsar.dll
2007-04-19 17:26:00 278,528 ----a-w C:\WINDOWS\system32\nvwrshe.dll
2007-04-19 17:26:00 278,528 ----a-w C:\WINDOWS\system32\nvrsfr.dll
2007-04-19 17:26:00 274,432 ----a-w C:\WINDOWS\system32\nvrsit.dll
2007-04-19 17:26:00 274,432 ----a-w C:\WINDOWS\system32\nvrses.dll
2007-04-19 17:26:00 274,432 ----a-w C:\WINDOWS\system32\nvrsel.dll
2007-04-19 17:26:00 270,336 ----a-w C:\WINDOWS\system32\nvrsde.dll
2007-04-19 17:26:00 266,240 ----a-w C:\WINDOWS\system32\nvrspt.dll
2007-04-19 17:26:00 266,240 ----a-w C:\WINDOWS\system32\nvrsnl.dll
2007-04-19 17:26:00 266,240 ----a-w C:\WINDOWS\system32\nvrsesm.dll
2007-04-19 17:26:00 262,144 ----a-w C:\WINDOWS\system32\nvrsru.dll
2007-04-19 17:26:00 262,144 ----a-w C:\WINDOWS\system32\nvrsptb.dll
2007-04-19 17:26:00 262,144 ----a-w C:\WINDOWS\system32\nvrsja.dll
2007-04-19 17:26:00 258,048 ----a-w C:\WINDOWS\system32\nvrsko.dll
2007-04-19 17:26:00 253,952 ----a-w C:\WINDOWS\system32\nvrshu.dll
2007-04-19 17:26:00 249,856 ----a-w C:\WINDOWS\system32\nvrstr.dll
2007-04-19 17:26:00 249,856 ----a-w C:\WINDOWS\system32\nvrssl.dll
2007-04-19 17:26:00 249,856 ----a-w C:\WINDOWS\system32\nvrssk.dll
2007-04-19 17:26:00 249,856 ----a-w C:\WINDOWS\system32\nvrspl.dll
2007-04-19 17:26:00 249,856 ----a-w C:\WINDOWS\system32\nvrsno.dll
2007-04-19 17:26:00 245,760 ----a-w C:\WINDOWS\system32\nvrssv.dll
2007-04-19 17:26:00 245,760 ----a-w C:\WINDOWS\system32\nvrsda.dll
2007-04-19 17:26:00 241,664 ----a-w C:\WINDOWS\system32\nvrsfi.dll
2007-04-19 17:26:00 241,664 ----a-w C:\WINDOWS\system32\nvrseng.dll
2007-04-19 17:26:00 241,664 ----a-w C:\WINDOWS\system32\nvrscs.dll
2007-04-19 17:26:00 229,376 ----a-w C:\WINDOWS\system32\nvmccs.dll
2007-04-19 17:26:00 221,184 ----a-w C:\WINDOWS\system32\nvrszhc.dll
2007-04-19 17:26:00 212,992 ----a-w C:\WINDOWS\system32\nvwrsja.dll
2007-04-19 17:26:00 212,992 ----a-w C:\WINDOWS\system32\nvapi.dll
2007-04-19 17:26:00 2,973,696 ----a-w C:\WINDOWS\system32\nvvitvsr.dll
2007-04-19 17:26:00 2,924,544 ----a-w C:\WINDOWS\system32\nvvitvs.dll
2007-04-19 17:26:00 2,859,008 ----a-w C:\WINDOWS\system32\nvmoblsr.dll
2007-04-19 17:26:00 196,608 ----a-w C:\WINDOWS\system32\nvwrsko.dll
2007-04-19 17:26:00 188,416 ----a-w C:\WINDOWS\system32\nvmccss.dll
2007-04-19 17:26:00 167,936 ----a-w C:\WINDOWS\system32\nvwrszht.dll
2007-02-23 07:57:59 88 --sh--r C:\WINDOWS\system32\4BFB238848.sys
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
*Note* empty entries & legit default entries are not shown
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects]
{02478D38-C3F9-4EFB-9B51-7695ECA05670}=C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll [2006-10-26 11:28]
{761497BB-D6F0-462C-B6EB-D4DAF1D92D43}=C:\Program Files\Java\jre1.6.0_01\bin\ssv.dll [2007-03-14 03:43]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"vptray"="C:\Program Files\NavNT\vptray.exe" [2001-09-24 07:59]
"nwiz"="nwiz.exe" [2007-04-19 13:26 C:\WINDOWS\system32\nwiz.exe]
"Logitech Hardware Abstraction Layer"="C:\Program Files\Common Files\Logitech\khalshared\KHALMNPR.EXE" []
"ViewMgr"="C:\Program Files\Viewpoint\Viewpoint Manager\ViewMgr.exe" []
"Cmaudio"="cmicnfg.cpl" []
"@"="" []
"Kernel and Hardware Abstraction Layer"="KHALMNPR.EXE" []
"atwtusb"="atwtusb.exe" [2005-02-03 10:37 C:\WINDOWS\system32\atwtusb.exe]
"QuickTime Task"="C:\Program Files\QuickTime\qttask.exe" [2006-09-01 16:57]
"SunJavaUpdateSched"="C:\Program Files\Java\jre1.6.0_01\bin\jusched.exe" [2007-03-14 03:43]
"AVG7_CC"="C:\PROGRA~1\Grisoft\AVG7\avgcc.exe" [2007-06-26 02:30]
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"igndlm.exe"="C:\Program Files\IGN\Download Manager\DLM.exe" [2006-11-07 18:22]
"DAEMON Tools"="C:\Program Files\DAEMON Tools\daemon.exe" [2006-11-12 06:48]
"MsnMsgr"="C:\Program Files\MSN Messenger\MsnMsgr.exe" [2007-01-19 13:54]
"Steam"="" []
"Yahoo! Pager"="C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe" [2007-01-19 13:49]
[HKEY_USERS\.default\software\microsoft\windows\currentversion\runonce]
"RunNarrator"=Narrator.exe
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks]
"{57B86673-276A-48B2-BAE7-C6DBB3020EB8}"="C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\shellexecutehook.dll" [2006-09-28 10:13]
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\safeboot\minimal\sdauxservice]
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\safeboot\minimal\sdcoreservice]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Adobe Gamma Loader.lnk]
path=C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Adobe Gamma Loader.lnk
backup=C:\WINDOWS\pss\Adobe Gamma Loader.lnkCommon Startup
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Adobe Reader Speed Launch.lnk]
path=C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Adobe Reader Speed Launch.lnk
backup=C:\WINDOWS\pss\Adobe Reader Speed Launch.lnkCommon Startup
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MsnMsgr]
"C:\Program Files\MSN Messenger\MsnMsgr.Exe" /background
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Steam]
"C:\Program Files\Steam\Steam.exe" -silent
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Yahoo! Pager]
"C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe" -quiet
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{2a15a5a0-aa57-11db-a05a-9ccc57198468}]
AutoRun\command- F:\LaunchU3.exe -a
**************************************************************************
catchme 0.3.721 W2K/XP/Vista - userland rootkit detector by Gmer, http://www.gmer.net
Rootkit scan 2007-06-30 15:58:16
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
Completion time: 2007-06-30 15:58:39
C:\ComboFix-quarantined-files.txt ... 2007-06-25 23:23
--- E O F ---
Kaspersky log
Scan SettingsScan using the following antivirus databaseextendedScan ArchivestrueScan Mail BasestrueScan TargetMy ComputerA:\
C:\
D:\
E:\ Scan StatisticsTotal number of scanned objects166298Number of viruses found2Number of infected objects7Number of suspicious objects0Duration of the scan process02:30:44
Infected Object NameVirus NameLast ActionC:\Documents and Settings\All Users\Application Data\avg7\Log\emc.log Object is locked skipped C:\Documents and Settings\All Users\Application Data\Grisoft\Avg7Data\avg7log.log Object is locked skipped C:\Documents and Settings\All Users\Application Data\Grisoft\Avg7Data\avg7log.log.lck Object is locked skipped C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus Corporate Edition\7.5\Quarantine\021C0000.VBN Infected: Exploit.HTML.IESlice.d skipped C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus Corporate Edition\7.5\Quarantine\02680000.VBN Infected: Exploit.HTML.IESlice.d skipped C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus Corporate Edition\7.5\Quarantine\02A80000.VBN Infected: Exploit.HTML.IESlice.d skipped C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus Corporate Edition\7.5\Quarantine\04A00000.VBN Infected: Exploit.HTML.IESlice.d skipped C:\Documents and Settings\Larry\Application Data\Aim\lwbhvxqj\stormreaver226\cert8.db Object is locked skipped C:\Documents and Settings\Larry\Application Data\Aim\lwbhvxqj\stormreaver226\key3.db Object is locked skipped C:\Documents and Settings\Larry\Cookies\index.dat Object is locked skipped C:\Documents and Settings\Larry\Desktop\SmitfraudFix\Reboot.exe Infected: not-a-virus:RiskTool.Win32.Reboot.f skipped C:\Documents and Settings\Larry\Desktop\SmitfraudFix.zip/SmitfraudFix/Reboot.exe Infected: not-a-virus:RiskTool.Win32.Reboot.f skipped C:\Documents and Settings\Larry\Desktop\SmitfraudFix.zip ZIP: infected - 1 skipped C:\Documents and Settings\Larry\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat Object is locked skipped C:\Documents and Settings\Larry\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped C:\Documents and Settings\Larry\Local Settings\History\History.IE5\index.dat Object is locked skipped C:\Documents and Settings\Larry\Local Settings\History\History.IE5\MSHist012007063020070701\index.dat Object is locked skipped C:\Documents and Settings\Larry\Local Settings\Temporary Internet Files\Content.IE5\index.dat Object is locked skipped C:\Documents and Settings\Larry\ntuser.dat Object is locked skipped C:\Documents and Settings\Larry\ntuser.dat.LOG Object is locked skipped C:\Documents and Settings\LocalService\Cookies\index.dat Object is locked skipped C:\Documents and Settings\LocalService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat Object is locked skipped C:\Documents and Settings\LocalService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped C:\Documents and Settings\LocalService\Local Settings\History\History.IE5\index.dat Object is locked skipped C:\Documents and Settings\LocalService\Local Settings\Temporary Internet Files\Content.IE5\index.dat Object is locked skipped C:\Documents and Settings\LocalService\NTUSER.DAT Object is locked skipped C:\Documents and Settings\LocalService\ntuser.dat.LOG Object is locked skipped C:\Documents and Settings\NetworkService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat Object is locked skipped C:\Documents and Settings\NetworkService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped C:\Documents and Settings\NetworkService\NTUSER.DAT Object is locked skipped C:\Documents and Settings\NetworkService\ntuser.dat.LOG Object is locked skipped C:\Program Files\World of Warcraft\Logs\gx.log Object is locked skipped C:\Program Files\World of Warcraft\Logs\Sound.log Object is locked skipped C:\System Volume Information\MountPointManagerRemoteDatabase Object is locked skipped C:\System Volume Information\_restore{2AA6384C-372E-4275-91A5-6E131A766022}\RP308\change.log Object is locked skipped C:\WINDOWS\Debug\PASSWD.LOG Object is locked skipped C:\WINDOWS\SchedLgU.Txt Object is locked skipped C:\WINDOWS\SoftwareDistribution\ReportingEvents.log Object is locked skipped C:\WINDOWS\Sti_Trace.log Object is locked skipped C:\WINDOWS\system32\CatRoot2\edb.log Object is locked skipped C:\WINDOWS\system32\CatRoot2\tmp.edb Object is locked skipped C:\WINDOWS\system32\config\AppEvent.Evt Object is locked skipped C:\WINDOWS\system32\config\default Object is locked skipped C:\WINDOWS\system32\config\default.LOG Object is locked skipped C:\WINDOWS\system32\config\SAM Object is locked skipped C:\WINDOWS\system32\config\SAM.LOG Object is locked skipped C:\WINDOWS\system32\config\SecEvent.Evt Object is locked skipped C:\WINDOWS\system32\config\SECURITY Object is locked skipped C:\WINDOWS\system32\config\SECURITY.LOG Object is locked skipped C:\WINDOWS\system32\config\software Object is locked skipped C:\WINDOWS\system32\config\software.LOG Object is locked skipped C:\WINDOWS\system32\config\SysEvent.Evt Object is locked skipped C:\WINDOWS\system32\config\system Object is locked skipped C:\WINDOWS\system32\config\system.LOG Object is locked skipped C:\WINDOWS\system32\drivers\sptd.sys Object is locked skipped C:\WINDOWS\system32\h323log.txt Object is locked skipped C:\WINDOWS\system32\wbem\Repository\FS\INDEX.BTR Object is locked skipped C:\WINDOWS\system32\wbem\Repository\FS\INDEX.MAP Object is locked skipped C:\WINDOWS\system32\wbem\Repository\FS\MAPPING.VER Object is locked skipped C:\WINDOWS\system32\wbem\Repository\FS\MAPPING1.MAP Object is locked skipped C:\WINDOWS\system32\wbem\Repository\FS\MAPPING2.MAP Object is locked skipped C:\WINDOWS\system32\wbem\Repository\FS\OBJECTS.DATA Object is locked skipped C:\WINDOWS\system32\wbem\Repository\FS\OBJECTS.MAP Object is locked skipped C:\WINDOWS\TempFile Object is locked skipped C:\WINDOWS\wiadebug.log Object is locked skipped C:\WINDOWS\wiaservc.log Object is locked skipped C:\WINDOWS\WindowsUpdate.log Object is locked skipped Scan process completed.