Hi Shaba,
Things are running more smoothly now, but I did another scan with Kaspersky online after I disabled and enabled the system restore. I seem to still have infections in there, in which I thought they would be gone after re-enabling the system restore. Can you please take a look at this... (A downloader Trojan is in there as well...)
Logfile of HijackThis v1.99.1
Scan saved at 7:22:48 PM, on 21/07/2006
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\MSN Messenger\msnmsgr.exe
C:\Program Files\Messenger\msmsgs.exe
C:\Vet\isafe.exe
C:\Program Files\Common Files\EPSON\EBAPI\SAgent2.exe
C:\Program Files\LogMeIn\RaMaint.exe
C:\Program Files\LogMeIn\LogMeIn.exe
C:\WINDOWS\system32\svchost.exe
C:\Vet\VetMsg.exe
C:\Program Files\LogMeIn\LogMeInSystray.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\devldr32.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Documents and Settings\yeak.YEAKY\Desktop\Virus stuff\HijackThis.exe
F2 - REG:system.ini: UserInit=C:\WINDOWS\system32\Userinit.exe
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\MSN Messenger\msnmsgr.exe" /background
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O16 - DPF: {00B71CFB-6864-4346-A978-C0A14556272C} (Checkers Class) -
http://messenger.zon...kr.cab31267.cabO16 - DPF: {0EB0E74A-2A76-4AB3-A7FB-9BD8C29F7F75} (CKAVWebScan Object) -
http://www.kaspersky...can_unicode.cabO16 - DPF: {8E0D4DE5-3180-4024-A327-4DFAD1796A8D} (MessengerStatsClient Class) -
http://messenger.zon...nt.cab31267.cabO16 - DPF: {FD0B6769-6490-4A91-AA0A-B5AE0DC75AC9} (Performance Viewer Activex Control) -
https://secure.logme...trl.cab?lmi=100O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O20 - Winlogon Notify: LMIinit - C:\WINDOWS\SYSTEM32\LMIinit.dll
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: ATI Smart - Unknown owner - C:\WINDOWS\system32\ati2sgag.exe
O23 - Service: CA ISafe (CAISafe) - Computer Associates International, Inc. - C:\Vet\isafe.exe
O23 - Service: EPSON Printer Status Agent2 (EPSONStatusAgent2) - SEIKO EPSON CORPORATION - C:\Program Files\Common Files\EPSON\EBAPI\SAgent2.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: LogMeIn Maintenance Service (LMIMaint) - LogMeIn, Inc. - C:\Program Files\LogMeIn\RaMaint.exe
O23 - Service: LogMeIn - LogMeIn, Inc. - C:\Program Files\LogMeIn\LogMeIn.exe
O23 - Service: VET Message Service (VETMSGNT) - Computer Associates International, Inc. - C:\Vet\VetMsg.exe
-------------------------------------------------------------------------------
KASPERSKY ONLINE SCANNER REPORT
Friday, July 21, 2006 7:21:29 PM
Operating System: Microsoft Windows XP Professional, Service Pack 2 (Build 2600)
Kaspersky Online Scanner version: 5.0.83.0
Kaspersky Anti-Virus database last update: 21/07/2006
Kaspersky Anti-Virus database records: 208951
-------------------------------------------------------------------------------
Scan Settings:
Scan using the following antivirus database: extended
Scan Archives: true
Scan Mail Bases: true
Scan Target - My Computer:
C:\
D:\
G:\
Scan Statistics:
Total number of scanned objects: 49746
Number of viruses found: 19
Number of infected objects: 45 / 0
Number of suspicious objects: 4
Duration of the scan process: 01:29:59
Infected Object Name / Virus Name / Last Action
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\DloaderAgentWN.zip/crackmasters.exe Suspicious: Password-protected-EXE skipped
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\DloaderAgentWN.zip ZIP: suspicious - 1 skipped
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\DownloaderTsupdateL5.zip/svchostsys.exe Suspicious: Password-protected-EXE skipped
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\DownloaderTsupdateL5.zip ZIP: suspicious - 1 skipped
C:\Documents and Settings\LocalService.NT AUTHORITY\Cookies\index.dat Object is locked skipped
C:\Documents and Settings\LocalService.NT AUTHORITY\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat Object is locked skipped
C:\Documents and Settings\LocalService.NT AUTHORITY\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped
C:\Documents and Settings\LocalService.NT AUTHORITY\Local Settings\History\History.IE5\index.dat Object is locked skipped
C:\Documents and Settings\LocalService.NT AUTHORITY\Local Settings\Temporary Internet Files\Content.IE5\index.dat Object is locked skipped
C:\Documents and Settings\LocalService.NT AUTHORITY\NTUSER.DAT Object is locked skipped
C:\Documents and Settings\LocalService.NT AUTHORITY\NTUSER.DAT.LOG Object is locked skipped
C:\Documents and Settings\NetworkService.NT AUTHORITY\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat Object is locked skipped
C:\Documents and Settings\NetworkService.NT AUTHORITY\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped
C:\Documents and Settings\NetworkService.NT AUTHORITY\NTUSER.DAT Object is locked skipped
C:\Documents and Settings\NetworkService.NT AUTHORITY\NTUSER.DAT.LOG Object is locked skipped
C:\Documents and Settings\yeak.YEAKY\Cookies\index.dat Object is locked skipped
C:\Documents and Settings\yeak.YEAKY\Desktop\LogMeIn.exe/data.rar/LogMeIn.msi/data.cab/ramaint.exe Infected: not-a-virus:RemoteAdmin.Win32.RemotelyAnywhere.a skipped
C:\Documents and Settings\yeak.YEAKY\Desktop\LogMeIn.exe/data.rar/LogMeIn.msi/data.cab Infected: not-a-virus:RemoteAdmin.Win32.RemotelyAnywhere.a skipped
C:\Documents and Settings\yeak.YEAKY\Desktop\LogMeIn.exe/data.rar/LogMeIn.msi Infected: not-a-virus:RemoteAdmin.Win32.RemotelyAnywhere.a skipped
C:\Documents and Settings\yeak.YEAKY\Desktop\LogMeIn.exe/data.rar Infected: not-a-virus:RemoteAdmin.Win32.RemotelyAnywhere.a skipped
C:\Documents and Settings\yeak.YEAKY\Desktop\LogMeIn.exe RarSFX: infected - 4 skipped
C:\Documents and Settings\yeak.YEAKY\Local Settings\Application Data\Microsoft\Messenger\
[email protected]\SharingMetadata\infected.dat Object is locked skipped
C:\Documents and Settings\yeak.YEAKY\Local Settings\Application Data\Microsoft\Messenger\
[email protected]\SharingMetadata\Logs\Dfsr.log Object is locked skipped
C:\Documents and Settings\yeak.YEAKY\Local Settings\Application Data\Microsoft\Messenger\
[email protected]\SharingMetadata\pending.dat Object is locked skipped
C:\Documents and Settings\yeak.YEAKY\Local Settings\Application Data\Microsoft\Messenger\
[email protected]\SharingMetadata\Working\database_60E8_D6EA_E8D6_BD8A\dfsr.db Object is locked skipped
C:\Documents and Settings\yeak.YEAKY\Local Settings\Application Data\Microsoft\Messenger\
[email protected]\SharingMetadata\Working\database_60E8_D6EA_E8D6_BD8A\fsr.log Object is locked skipped
C:\Documents and Settings\yeak.YEAKY\Local Settings\Application Data\Microsoft\Messenger\
[email protected]\SharingMetadata\Working\database_60E8_D6EA_E8D6_BD8A\fsrtmp.log Object is locked skipped
C:\Documents and Settings\yeak.YEAKY\Local Settings\Application Data\Microsoft\Messenger\
[email protected]\SharingMetadata\Working\database_60E8_D6EA_E8D6_BD8A\tmp.edb Object is locked skipped
C:\Documents and Settings\yeak.YEAKY\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat Object is locked skipped
C:\Documents and Settings\yeak.YEAKY\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped
C:\Documents and Settings\yeak.YEAKY\Local Settings\Application Data\Microsoft\Windows Live Contacts\
[email protected]\shadow\e86d31d3-e172-458a-903d-60a81e05a9d0.WindowsLiveContact Object is locked skipped
C:\Documents and Settings\yeak.YEAKY\Local Settings\Application Data\Microsoft\Windows Live Contacts\
[email protected]\real\members.stg Object is locked skipped
C:\Documents and Settings\yeak.YEAKY\Local Settings\Application Data\Microsoft\Windows Live Contacts\
[email protected]\shadow\members.stg Object is locked skipped
C:\Documents and Settings\yeak.YEAKY\Local Settings\Application Data\Mozilla\Firefox\Profiles\z4we4y9s.default\Cache\7B83016Fd01 Object is locked skipped
C:\Documents and Settings\yeak.YEAKY\Local Settings\History\History.IE5\index.dat Object is locked skipped
C:\Documents and Settings\yeak.YEAKY\Local Settings\History\History.IE5\MSHist012006072120060722\index.dat Object is locked skipped
C:\Documents and Settings\yeak.YEAKY\Local Settings\Temp\~DF6B10.tmp Object is locked skipped
C:\Documents and Settings\yeak.YEAKY\Local Settings\Temp\~DF6C1A.tmp Object is locked skipped
C:\Documents and Settings\yeak.YEAKY\Local Settings\Temp\~DFBCD5.tmp Object is locked skipped
C:\Documents and Settings\yeak.YEAKY\Local Settings\Temp\~DFBCFE.tmp Object is locked skipped
C:\Documents and Settings\yeak.YEAKY\Local Settings\Temporary Internet Files\Content.IE5\13DW9IW8\spacerx[1].gif Object is locked skipped
C:\Documents and Settings\yeak.YEAKY\Local Settings\Temporary Internet Files\Content.IE5\A1385O3I\down[9].htm Object is locked skipped
C:\Documents and Settings\yeak.YEAKY\Local Settings\Temporary Internet Files\Content.IE5\A1385O3I\r[1].js Object is locked skipped
C:\Documents and Settings\yeak.YEAKY\Local Settings\Temporary Internet Files\Content.IE5\ALNARRH2\down[17].htm Object is locked skipped
C:\Documents and Settings\yeak.YEAKY\Local Settings\Temporary Internet Files\Content.IE5\ALNARRH2\down[20].htm Object is locked skipped
C:\Documents and Settings\yeak.YEAKY\Local Settings\Temporary Internet Files\Content.IE5\ALNARRH2\onepage_lp_inf_09[1].gif Object is locked skipped
C:\Documents and Settings\yeak.YEAKY\Local Settings\Temporary Internet Files\Content.IE5\index.dat Object is locked skipped
C:\Documents and Settings\yeak.YEAKY\Local Settings\Temporary Internet Files\Content.IE5\LWG79DG9\icon_mail[1].gif Object is locked skipped
C:\Documents and Settings\yeak.YEAKY\Local Settings\Temporary Internet Files\Content.IE5\LWG79DG9\search[1].gif Object is locked skipped
C:\Documents and Settings\yeak.YEAKY\Local Settings\Temporary Internet Files\Content.IE5\OEUQ32TD\down[18].htm Object is locked skipped
C:\Documents and Settings\yeak.YEAKY\Local Settings\Temporary Internet Files\Content.IE5\S1UV45AF\down[1].htm Object is locked skipped
C:\Documents and Settings\yeak.YEAKY\Local Settings\Temporary Internet Files\Content.IE5\STA3G9QF\down[10].htm Object is locked skipped
C:\Documents and Settings\yeak.YEAKY\My Documents\Han Stuff\CA Foundations [bleep]\SoloMike\owl52t.dll Object is locked skipped
C:\Documents and Settings\yeak.YEAKY\My Documents\Han Stuff\CA Foundations [bleep]\SoloMike\vpDATA.dll Object is locked skipped
C:\Documents and Settings\yeak.YEAKY\My Documents\Han Stuff\CA Foundations [bleep]\SoloMike\vpDIALOG.dll Object is locked skipped
C:\Documents and Settings\yeak.YEAKY\My Documents\Image Transfer\'03_09_17_01\DCIM\101MSDCF\DSC01353.JPG Object is locked skipped
C:\Documents and Settings\yeak.YEAKY\My Documents\Image Transfer\'04_09_22_01\DCIM\101MSDCF\DSC02586.JPG Object is locked skipped
C:\Documents and Settings\yeak.YEAKY\My Documents\Image Transfer\'04_09_22_02\SONYCOPY.IND Object is locked skipped
C:\Documents and Settings\yeak.YEAKY\My Documents\My Pictures\pups\101_0197.JPG Object is locked skipped
C:\Documents and Settings\yeak.YEAKY\My Documents\Super Saiyaijin Yang\2006\2 - February 2006 Malaysia - Singapore Trip\CIMG0147.avi Object is locked skipped
C:\Documents and Settings\yeak.YEAKY\NTUSER.DAT Object is locked skipped
C:\Documents and Settings\yeak.YEAKY\NTUSER.DAT.LOG Object is locked skipped
C:\Program Files\LogMeIn\LMIinit.dll Infected: not-a-virus:RemoteAdmin.Win32.RemotelyAnywhere.a skipped
C:\Program Files\LogMeIn\LogMeIn.exe Infected: not-a-virus:RemoteAdmin.Win32.RemotelyAnywhere.a skipped
C:\Program Files\LogMeIn\ramaint.exe Infected: not-a-virus:RemoteAdmin.Win32.RemotelyAnywhere.a skipped
C:\Program Files\LogMeIn\update\2-30-545.bak\ramaint.exe Infected: not-a-virus:RemoteAdmin.Win32.RemotelyAnywhere.a skipped
C:\System Volume Information\MountPointManagerRemoteDatabase Object is locked skipped
C:\System Volume Information\_restore{4B00A451-6FD7-4282-B7E5-F2E39AF7D81C}\RP205\A0162237.exe Infected: not-a-virus:AdWare.Win32.ClearSearch.aj skipped
C:\System Volume Information\_restore{4B00A451-6FD7-4282-B7E5-F2E39AF7D81C}\RP205\A0162239.dll Infected: not-a-virus:AdWare.Win32.ClearSearch.z skipped
C:\System Volume Information\_restore{4B00A451-6FD7-4282-B7E5-F2E39AF7D81C}\RP205\A0162240.exe Infected: not-a-virus:AdWare.Win32.ClearSearch.ac skipped
C:\System Volume Information\_restore{4B00A451-6FD7-4282-B7E5-F2E39AF7D81C}\RP205\A0162245.DLL Infected: not-a-virus:AdWare.Win32.ClearSearch.ag skipped
C:\System Volume Information\_restore{8B9DCABC-642D-47B8-8301-563EA8650419}\RP50\A0027379.exe Infected: Trojan-Downloader.Win32.IstBar.hv skipped
C:\System Volume Information\_restore{8B9DCABC-642D-47B8-8301-563EA8650419}\RP50\A0027392.exe Infected: not-a-virus:AdWare.Win32.EliteBar.ac skipped
C:\System Volume Information\_restore{8B9DCABC-642D-47B8-8301-563EA8650419}\RP50\A0027393.exe Infected: not-a-virus:AdWare.Win32.EliteBar.q skipped
C:\System Volume Information\_restore{8B9DCABC-642D-47B8-8301-563EA8650419}\RP50\A0027825.exe/WISE0016.BIN Infected: not-a-virus:AdWare.Win32.180Solutions skipped
C:\System Volume Information\_restore{8B9DCABC-642D-47B8-8301-563EA8650419}\RP50\A0027825.exe/WISE0017.BIN Infected: not-a-virus:AdWare.Win32.F1Organizer.h skipped
C:\System Volume Information\_restore{8B9DCABC-642D-47B8-8301-563EA8650419}\RP50\A0027825.exe/WISE0018.BIN/data0001.cab/VVSN.exe Infected: not-a-virus:AdWare.Win32.SaveNow.z skipped
C:\System Volume Information\_restore{8B9DCABC-642D-47B8-8301-563EA8650419}\RP50\A0027825.exe/WISE0018.BIN/data0001.cab Infected: not-a-virus:AdWare.Win32.SaveNow.z skipped
C:\System Volume Information\_restore{8B9DCABC-642D-47B8-8301-563EA8650419}\RP50\A0027825.exe/WISE0018.BIN Infected: not-a-virus:AdWare.Win32.SaveNow.z skipped
C:\System Volume Information\_restore{8B9DCABC-642D-47B8-8301-563EA8650419}\RP50\A0027825.exe/WISE0019.BIN Infected: Backdoor.Win32.Ruledor.c skipped
C:\System Volume Information\_restore{8B9DCABC-642D-47B8-8301-563EA8650419}\RP50\A0027825.exe WiseSFX: infected - 6 skipped
C:\System Volume Information\_restore{8B9DCABC-642D-47B8-8301-563EA8650419}\RP50\A0027846.EXE Infected: not-a-virus:AdWare.Win32.MyWay.z skipped
C:\System Volume Information\_restore{8B9DCABC-642D-47B8-8301-563EA8650419}\RP50\A0027855.EXE Infected: not-a-virus:AdWare.Win32.MyWay.z skipped
C:\System Volume Information\_restore{8B9DCABC-642D-47B8-8301-563EA8650419}\RP50\A0027858.exe/WISE0060.BIN Infected: not-a-virus:AdWare.Win32.Gator.3013 skipped
C:\System Volume Information\_restore{8B9DCABC-642D-47B8-8301-563EA8650419}\RP50\A0027858.exe WiseSFX: infected - 1 skipped
C:\System Volume Information\_restore{8B9DCABC-642D-47B8-8301-563EA8650419}\RP50\A0028304.exe/data0005 Infected: not-a-virus:AdWare.Win32.SaveNow.bx skipped
C:\System Volume Information\_restore{8B9DCABC-642D-47B8-8301-563EA8650419}\RP50\A0028304.exe NSIS: infected - 1 skipped
C:\System Volume Information\_restore{8B9DCABC-642D-47B8-8301-563EA8650419}\RP50\A0028793.exe Infected: not-a-virus:AdWare.Win32.ClearSearch.aj skipped
C:\System Volume Information\_restore{8B9DCABC-642D-47B8-8301-563EA8650419}\RP50\A0028799.DLL Infected: not-a-virus:AdWare.Win32.ClearSearch.ag skipped
C:\System Volume Information\_restore{8B9DCABC-642D-47B8-8301-563EA8650419}\RP50\A0028801.dll Infected: not-a-virus:AdWare.Win32.ClearSearch.z skipped
C:\System Volume Information\_restore{8B9DCABC-642D-47B8-8301-563EA8650419}\RP50\A0028802.exe Infected: not-a-virus:AdWare.Win32.ClearSearch.ac skipped
C:\System Volume Information\_restore{8B9DCABC-642D-47B8-8301-563EA8650419}\RP50\A0031516.exe Infected: not-a-virus:AdWare.Win32.F1Organizer.h skipped
C:\System Volume Information\_restore{8B9DCABC-642D-47B8-8301-563EA8650419}\RP50\A0033624.dll/data0001 Infected: Trojan-Downloader.Win32.IstBar.iu skipped
C:\System Volume Information\_restore{8B9DCABC-642D-47B8-8301-563EA8650419}\RP50\A0033624.dll/data0003 Infected: Trojan-Downloader.Win32.IstBar.nn skipped
C:\System Volume Information\_restore{8B9DCABC-642D-47B8-8301-563EA8650419}\RP50\A0033624.dll NSIS: infected - 2 skipped
C:\System Volume Information\_restore{8B9DCABC-642D-47B8-8301-563EA8650419}\RP50\A0033624.dll Exe2Dll: infected - 2 skipped
C:\System Volume Information\_restore{8B9DCABC-642D-47B8-8301-563EA8650419}\RP50\A0033624.dll UPX: infected - 2 skipped
C:\System Volume Information\_restore{8B9DCABC-642D-47B8-8301-563EA8650419}\RP50\A0033625.exe/data0001 Infected: Trojan-Downloader.Win32.IstBar.iu skipped
C:\System Volume Information\_restore{8B9DCABC-642D-47B8-8301-563EA8650419}\RP50\A0033625.exe/data0003 Infected: Trojan-Downloader.Win32.IstBar.nn skipped
C:\System Volume Information\_restore{8B9DCABC-642D-47B8-8301-563EA8650419}\RP50\A0033625.exe NSIS: infected - 2 skipped
C:\System Volume Information\_restore{AB26917B-E4EA-4C6B-84F5-9DC8BB47E109}\RP450\change.log Object is locked skipped
C:\WINDOWS\Debug\PASSWD.LOG Object is locked skipped
C:\WINDOWS\hosts.sam Infected: Trojan.Win32.Qhost.hl skipped
C:\WINDOWS\SchedLgU.Txt Object is locked skipped
C:\WINDOWS\SoftwareDistribution\ReportingEvents.log Object is locked skipped
C:\WINDOWS\Sti_Trace.log Object is locked skipped
C:\WINDOWS\system32\CatRoot2\edb.log Object is locked skipped
C:\WINDOWS\system32\CatRoot2\tmp.edb Object is locked skipped
C:\WINDOWS\system32\CatRoot2\{127D0A1D-4EF2-11D1-8608-00C04FC295EE}\catdb Object is locked skipped
C:\WINDOWS\system32\config\AppEvent.Evt Object is locked skipped
C:\WINDOWS\system32\config\default Object is locked skipped
C:\WINDOWS\system32\config\DEFAULT.LOG Object is locked skipped
C:\WINDOWS\system32\config\SAM Object is locked skipped
C:\WINDOWS\system32\config\SAM.LOG Object is locked skipped
C:\WINDOWS\system32\config\SecEvent.Evt Object is locked skipped
C:\WINDOWS\system32\config\SECURITY Object is locked skipped
C:\WINDOWS\system32\config\SECURITY.LOG Object is locked skipped
C:\WINDOWS\system32\config\SOFTWARE Object is locked skipped
C:\WINDOWS\system32\config\SOFTWARE.LOG Object is locked skipped
C:\WINDOWS\system32\config\SysEvent.Evt Object is locked skipped
C:\WINDOWS\system32\config\system Object is locked skipped
C:\WINDOWS\system32\config\SYSTEM.LOG Object is locked skipped
C:\WINDOWS\system32\drivers\etc\hosts.20060719-174238.backup Infected: Trojan.Win32.Qhost.hl skipped
C:\WINDOWS\system32\h323log.txt Object is locked skipped
C:\WINDOWS\system32\LMIinit.dll Infected: not-a-virus:RemoteAdmin.Win32.RemotelyAnywhere.a skipped
C:\WINDOWS\system32\wbem\Repository\FS\INDEX.BTR Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\INDEX.MAP Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\MAPPING.VER Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\MAPPING1.MAP Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\MAPPING2.MAP Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\OBJECTS.DATA Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\OBJECTS.MAP Object is locked skipped
C:\WINDOWS\wiadebug.log Object is locked skipped
C:\WINDOWS\wiaservc.log Object is locked skipped
C:\WINDOWS\WindowsUpdate.log Object is locked skipped
Scan process completed.
Please advise me on what to do. Thanks a lot for your help so far because my uploading and downloading seems to be faster on msn now! Cheers!