Jump to content

BackDoor.IRCBot


Recommended Posts

Hello, I've been experiencing this virus infection for the past week. I've tried so many Anti-virus/spyware software and it didn't work. I also tried Malware bytes'. The software detected the infected files, and always delete on reboot. But it came back after every reboot. Please help me ASAP!!

Log File:

Logfile of Trend Micro HijackThis v2.0.2

Scan saved at 12:31:11 PM, on 3/13/2009

Platform: Windows XP SP2 (WinNT 5.01.2600)

MSIE: Internet Explorer v7.00 (7.00.6000.16674)

Boot mode: Normal

Running processes:

C:\WINDOWS\System32\smss.exe

C:\WINDOWS\system32\winlogon.exe

C:\WINDOWS\system32\services.exe

C:\WINDOWS\system32\lsass.exe

C:\WINDOWS\system32\svchost.exe

C:\WINDOWS\System32\svchost.exe

C:\WINDOWS\system32\spoolsv.exe

C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe

C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe

C:\Program Files\Bonjour\mDNSResponder.exe

C:\WINDOWS\Explorer.EXE

C:\Program Files\Java\jre6\bin\jqs.exe

C:\Program Files\Common Files\Microsoft Shared\VS7Debug\mdm.exe

C:\WINDOWS\System32\nvsvc32.exe

C:\WINDOWS\System32\svchost.exe

C:\PROGRA~1\AVG\AVG8\avgemc.exe

C:\PROGRA~1\AVG\AVG8\avgam.exe

C:\PROGRA~1\AVG\AVG8\avgrsx.exe

C:\PROGRA~1\AVG\AVG8\avgnsx.exe

C:\Program Files\AVG\AVG8\avgcsrvx.exe

C:\WINDOWS\RTHDCPL.EXE

C:\WINDOWS\system32\RUNDLL32.EXE

C:\WINDOWS\System32\taskswitch.exe

C:\Program Files\HP\HP Software Update\HPWuSchd2.exe

C:\Program Files\Yahoo!\Search Protection\SearchProtection.exe

C:\Program Files\HP\hpcoretech\hpcmpmgr.exe

C:\Program Files\Winamp\winampa.exe

C:\Program Files\Java\jre6\bin\jusched.exe

C:\PROGRA~1\AVG\AVG8\avgtray.exe

C:\Program Files\iTunes\iTunesHelper.exe

C:\Program Files\Malwarebytes' Anti-Malware\mbamgui.exe

C:\WINDOWS\system32\ctfmon.exe

C:\WINDOWS\System32\svchost.exe

C:\Program Files\D-Link\D-Link DSL-200I USB ADSL Modem\dslmon.exe

C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe

C:\Program Files\Logitech\Desktop Messenger\8876480\Program\LogitechDesktopMessenger.exe

C:\Program Files\Logitech\SetPoint\SetPoint.exe

C:\Program Files\uTorrent Turbo Booster\uTorrent Turbo Booster.exe

C:\Program Files\Common Files\Logishrd\KHAL2\KHALMNPR.EXE

C:\Program Files\iPod\bin\iPodService.exe

C:\Program Files\mIRC\IRC Bot\services.exe

C:\Program Files\HP\Digital Imaging\bin\hpqgalry.exe

C:\Program Files\uTorrent\uTorrent.exe

C:\Program Files\Internet Explorer\iexplore.exe

F:\Ijud Punyer\Visual Basic\Applications\HijackThis.exe

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896

R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://us.rd.yahoo.com/customize/ycomp/def...//www.yahoo.com

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page = \blank.htm

R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = local

R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\PROGRA~1\Yahoo!\Companion\Installs\cpn2\yt.dll

O2 - BHO: &Yahoo! Toolbar Helper - {02478D38-C3F9-4efb-9B51-7695ECA05670} - C:\PROGRA~1\Yahoo!\Companion\Installs\cpn2\yt.dll

O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll

O2 - BHO: WormRadar.com IESiteBlocker.NavFilter - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files\AVG\AVG8\avgssie.dll

O2 - BHO: (no name) - {427B37EF-B6C5-4823-A97C-10B88977E398} - (no file)

O2 - BHO: Megaupload Toolbar - {4E7BD74F-2B8D-469E-CCB0-B130EEDBE97C} - C:\PROGRA~1\MEGAUP~2\MEGAUP~1.DLL

O2 - BHO: Yahoo! IE Services Button - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\Program Files\Yahoo!\Common\yiesrvc.dll

O2 - BHO: Java Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre6\bin\ssv.dll

O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)

O2 - BHO: Java Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll

O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll

O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\PROGRA~1\Yahoo!\Companion\Installs\cpn2\yt.dll

O3 - Toolbar: Megaupload Toolbar - {4E7BD74F-2B8D-469E-CCB0-B130EEDBE97C} - C:\PROGRA~1\MEGAUP~2\MEGAUP~1.DLL

O4 - HKLM\..\Run: [skyTel] SkyTel.EXE

O4 - HKLM\..\Run: [GBB36X Configure] C:\WINDOWS\System32\JMRaidTool.exe boot

O4 - HKLM\..\Run: [RTHDCPL] RTHDCPL.EXE

O4 - HKLM\..\Run: [Alcmtr] ALCMTR.EXE

O4 - HKLM\..\Run: [Tweak UI] RUNDLL32.EXE TWEAKUI.CPL,TweakMeUp

O4 - HKLM\..\Run: [EasyTuneV] C:\Program Files\Gigabyte\ET5\GUI.exe

O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\System32\NvCpl.dll,NvStartup

O4 - HKLM\..\Run: [nwiz] nwiz.exe /install

O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\System32\NvMcTray.dll,NvTaskbarInit

O4 - HKLM\..\Run: [CoolSwitch] C:\WINDOWS\System32\taskswitch.exe

O4 - HKLM\..\Run: [NeroFilterCheck] C:\Program Files\Common Files\Ahead\Lib\NeroCheck.exe

O4 - HKLM\..\Run: [Logitech Hardware Abstraction Layer] KHALMNPR.EXE

O4 - HKLM\..\Run: [HP Software Update] "C:\Program Files\HP\HP Software Update\HPWuSchd2.exe"

O4 - HKLM\..\Run: [YSearchProtection] "C:\Program Files\Yahoo!\Search Protection\SearchProtection.exe"

O4 - HKLM\..\Run: [HP Component Manager] "C:\Program Files\HP\hpcoretech\hpcmpmgr.exe"

O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"

O4 - HKLM\..\Run: [Kernel and Hardware Abstraction Layer] KHALMNPR.EXE

O4 - HKLM\..\Run: [WinampAgent] "C:\Program Files\Winamp\winampa.exe"

O4 - HKLM\..\Run: [sunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe"

O4 - HKLM\..\Run: [AVG8_TRAY] C:\PROGRA~1\AVG\AVG8\avgtray.exe

O4 - HKLM\..\Run: [PC Suite for Smartphones] "C:\Program Files\Sony Ericsson\Mobile4\Application Launcher\Application Launcher.exe" /startoptions

O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime

O4 - HKLM\..\Run: [AppleSyncNotifier] C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleSyncNotifier.exe

O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"

O4 - HKLM\..\Run: [Malwarebytes' Anti-Malware] "C:\Program Files\Malwarebytes' Anti-Malware\mbamgui.exe" /starttray

O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe

O4 - HKCU\..\Run: [uTorrent] "C:\Program Files\uTorrent\uTorrent.exe"

O4 - HKUS\S-1-5-18\..\Run: [msnmsgr] "C:\Program Files\MSN Messenger\msnmsgr.exe" /background (User 'SYSTEM')

O4 - HKUS\.DEFAULT\..\Run: [msnmsgr] "C:\Program Files\MSN Messenger\msnmsgr.exe" /background (User 'Default user')

O4 - Startup: Adobe Gamma Loader.com

O4 - Startup: uTorrent Turbo Booster.lnk = C:\Program Files\uTorrent Turbo Booster\uTorrent Turbo Booster.exe

O4 - Global Startup: Adobe Gamma Loader.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe

O4 - Global Startup: DSLMON.lnk = ?

O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe

O4 - Global Startup: HP Image Zone Fast Start.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqthb08.exe

O4 - Global Startup: Logitech Desktop Messenger.lnk = C:\Program Files\Logitech\Desktop Messenger\8876480\Program\LogitechDesktopMessenger.exe

O4 - Global Startup: Logitech SetPoint.lnk = C:\Program Files\Logitech\SetPoint\SetPoint.exe

O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~3\OFFICE11\EXCEL.EXE/3000

O8 - Extra context menu item: E&xportar para o Microsoft Excel - res://C:\PROGRA~1\MICROS~3\Office10\EXCEL.EXE/3000

O9 - Extra button: Yahoo! Services - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\Program Files\Yahoo!\Common\yiesrvc.dll

O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~3\OFFICE11\REFIEBAR.DLL

O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe

O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe

O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe

O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe

O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (Installation Support) - C:\Program Files\Yahoo!\Common\Yinsthelper.dll

O17 - HKLM\System\CCS\Services\Tcpip\..\{4833954F-1E33-488A-8EE5-D3CE72394F1D}: NameServer = 202.188.0.133 202.188.1.5

O17 - HKLM\System\CS3\Services\Tcpip\..\{4833954F-1E33-488A-8EE5-D3CE72394F1D}: NameServer = 202.188.0.133 202.188.1.5

O18 - Protocol: bwfile-8876480 - {9462A756-7B47-47BC-8C80-C34B9B80B32B} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\GAPlugProtocol-8876480.dll

O18 - Protocol: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files\AVG\AVG8\avgpp.dll

O20 - Winlogon Notify: avgrsstarter - C:\WINDOWS\SYSTEM32\avgrsstx.dll

O20 - Winlogon Notify: rxughy - rxughy.dll (file missing)

O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe

O23 - Service: AVG8 E-mail Scanner (avg8emc) - AVG Technologies CZ, s.r.o. - C:\PROGRA~1\AVG\AVG8\avgemc.exe

O23 - Service: AVG8 WatchDog (avg8wd) - AVG Technologies CZ, s.r.o. - C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe

O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe

O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1150\Intel 32\IDriverT.exe

O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe

O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe

O23 - Service: Logitech Bluetooth Service (LBTServ) - Logitech, Inc. - C:\Program Files\Common Files\Logitech\Bluetooth\LBTServ.exe

O23 - Service: Macromedia Licensing Service - Unknown owner - C:\Program Files\Common Files\Macromedia Shared\Service\Macromedia Licensing.exe

O23 - Service: MBAMService - Malwarebytes Corporation - C:\Program Files\Malwarebytes' Anti-Malware\mbamservice.exe

O23 - Service: NBService - Nero AG - C:\Program Files\Nero\Nero 7\Nero BackItUp\NBService.exe

O23 - Service: NMIndexingService - Nero AG - C:\Program Files\Common Files\Ahead\Lib\NMIndexingService.exe

O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\System32\nvsvc32.exe

O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe

--

End of file - 10772 bytes

Link to post
Share on other sites

This is malware bytes' log file..

PLEASE NOTE THAT I ENDED THE "WINWORD.EXE" PROCESS AFTER REBOOT BECAUSE I KNOW IT IS A VIRUS.

Malwarebytes' Anti-Malware 1.34

Database version: 1839

Windows 5.1.2600 Service Pack 2

3/13/2009 11:58:55 AM

mbam-log-2009-03-13 (11-58-55).txt

Scan type: Quick Scan

Objects scanned: 80075

Time elapsed: 5 minute(s), 38 second(s)

Memory Processes Infected: 1

Memory Modules Infected: 0

Registry Keys Infected: 5

Registry Values Infected: 0

Registry Data Items Infected: 0

Folders Infected: 0

Files Infected: 2

Memory Processes Infected:

C:\Program Files\mIRC\IRC Bot\services.exe (Backdoor.Bot) -> Unloaded process successfully.

Memory Modules Infected:

(No malicious items detected)

Registry Keys Infected:

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\Acha.exe (Security.Hijack) -> Quarantined and deleted successfully.

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\AmyMastura.exe (Security.Hijack) -> Quarantined and deleted successfully.

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\csrsz.exe (Security.Hijack) -> Quarantined and deleted successfully.

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\registry.exe (Security.Hijack) -> Quarantined and deleted successfully.

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\wscript.exe (Security.Hijack) -> Quarantined and deleted successfully.

Registry Values Infected:

(No malicious items detected)

Registry Data Items Infected:

(No malicious items detected)

Folders Infected:

(No malicious items detected)

Files Infected:

C:\Program Files\Microsoft Office\WINWORD.EXE (Backdoor.Bot) -> Delete on reboot.

C:\Program Files\mIRC\IRC Bot\services.exe (Backdoor.Bot) -> Quarantined and deleted successfully.

Link to post
Share on other sites

  • Root Admin

Please visit this webpage for instructions for downloading ComboFix to your
DESKTOP
:
how-to-use-combofix

Please ensure you read this guide carefully and install the Recovery Console first.

NOTE!!:

You must save and run
ComboFix.exe
on your DESKTOP and not from any other folder.

Also,
DO NOT
click the mouse or launch any other applications while this is running or it may stall the program

Additional links to download the tool:

Note:

The
Windows Recovery Console
will allow you to boot up into a special recovery (repair) mode. This allows us to more easily help you should your computer have a problem after an attempted removal of malware. It is a simple procedure that will only take a few moments of your time.

Once installed, you should see a blue screen prompt that says:

The Recovery Console was successfully installed.

Please continue as follows:
  • Close/disable all anti virus and anti malware programs so they do not interfere with the running of ComboFix.
  • Click
    Yes
    to allow ComboFix to continue scanning for malware.

  • When the tool is finished, it will produce a report for you.

  • Please post the
    C:\ComboFix.txt
    along with a
    new HijackThis log
    so we may continue cleaning the system.

Link to post
Share on other sites

Here is the ComboFix log:

ComboFix 09-03-12.01 - Shahril Izwan 2009-03-13 19:55:07.1 - NTFSx86

Microsoft Windows XP Professional 5.1.2600.2.1252.1.1033.18.1023.482 [GMT 8:00]

Running from: c:\documents and settings\Shahril Izwan\Desktop\ComboFix.exe

AV: AVG Anti-Virus *On-access scanning disabled* (Updated)

* Created a new restore point

.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))

.

c:\documents and settings\Shahril Izwan\Application Data\.#

c:\documents and settings\Shahril Izwan\Application Data\inst.exe

c:\documents and settings\Shahril Izwan\Start Menu\Programs\Startup\Adobe Gamma Loader.com

c:\program files\Microsoft Office\WINWORD.EXE

c:\program files\mIRC\IRC Bot

c:\program files\mIRC\IRC Bot\Anjing_Malingsia.sys

c:\program files\mIRC\IRC Bot\censored.sys

c:\program files\mIRC\IRC Bot\Channel_Babi.sys

c:\program files\mIRC\IRC Bot\control.ini

c:\program files\mIRC\IRC Bot\censored.sys

c:\program files\mIRC\IRC Bot\kontol.mrc

c:\program files\mIRC\IRC Bot\Nama_Anjing.sys

c:\program files\mIRC\IRC Bot\Nama_Babi.sys

c:\program files\mIRC\IRC Bot\perampok_budaya.sys

c:\program files\mIRC\IRC Bot\remote.ini

c:\program files\mIRC\IRC Bot\services.exe

c:\program files\mIRC\IRC Bot\Stupid.sys

c:\program files\mIRC\IRC Bot\svchost.exe

c:\windows\system\_sv_CMD_

c:\windows\system32\aabIknnn.ini

c:\windows\system32\aabIknnn.ini2

c:\windows\system32\AutoRun.inf

c:\windows\system32\ldyrpgqo.ini

c:\windows\system32\mdm.exe

c:\windows\system32\pthreadGC2.dll

c:\windows\system32\yfndtnin.ini

.

((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))

.

-------\Legacy_ICF

-------\Legacy_TCPSR

((((((((((((((((((((((((( Files Created from 2009-02-13 to 2009-03-13 )))))))))))))))))))))))))))))))

.

2009-03-13 15:06 . 2009-03-13 15:06 2,560 --a------ c:\windows\_MSRSTRT.EXE

2009-03-12 22:48 . 2009-03-12 22:49 <DIR> d-------- c:\program files\ThreatExpert Memory Scanner

2009-03-12 21:28 . 2008-07-08 13:54 148,496 --a------ c:\windows\system32\drivers\55711518.sys

2009-03-12 20:04 . 2009-03-12 20:04 <DIR> d-------- c:\program files\Common Files\Download Manager

2009-03-12 17:55 . 2008-07-08 13:54 148,496 --a------ c:\windows\system32\drivers\23517218.sys

2009-03-11 01:23 . 2008-09-17 03:23 168,448 --a------ c:\windows\system32\unrar.dll

2009-03-11 01:22 . 2009-03-11 01:23 <DIR> d-------- c:\program files\K-Lite Codec Pack

2009-03-11 01:22 . 2008-11-07 00:37 3,596,288 --a------ c:\windows\system32\qt-dx331.dll

2009-03-11 01:22 . 2008-09-25 02:41 839,680 --a------ c:\windows\system32\lameACM.acm

2009-03-11 01:22 . 2008-12-08 02:08 795,648 --a------ c:\windows\system32\xvidcore.dll

2009-03-11 01:22 . 2008-11-07 00:33 684,032 --a------ c:\windows\system32\divx.dll

2009-03-11 01:22 . 2004-01-26 00:18 217,088 --a------ c:\windows\system32\yv12vfw.dll

2009-03-11 01:22 . 2008-12-08 02:08 130,048 --a------ c:\windows\system32\xvidvfw.dll

2009-03-11 01:22 . 2007-09-21 08:52 118,784 --a------ c:\windows\system32\ac3acm.acm

2009-03-11 01:22 . 2008-12-11 08:33 86,016 --a------ c:\windows\system32\dpl100.dll

2009-03-11 01:22 . 2009-02-10 02:56 67,584 --a------ c:\windows\system32\ff_vfw.dll

2009-03-11 01:22 . 2007-07-11 00:10 547 --a------ c:\windows\system32\ff_vfw.dll.manifest

2009-03-11 01:22 . 2008-10-03 20:30 414 --a------ c:\windows\system32\lame_acm.xml

2009-03-10 01:06 . 2009-03-10 01:06 <DIR> d-------- c:\windows\Curse of the Pharaoh Napoleons Secret

2009-03-10 01:06 . 2009-03-10 01:06 <DIR> d-------- c:\program files\Curse of the Pharaoh Napoleons Secret

2009-03-09 17:08 . 2009-03-09 17:10 <DIR> d-------- C:\OutputFolder

2009-03-09 17:04 . 2009-03-09 17:04 <DIR> d-------- c:\program files\FLV to AVI MPEG WMV 3GP MP4 iPod Converter

2009-03-05 00:47 . 2009-03-05 00:55 <DIR> d-------- C:\Mp3 Output

2009-03-05 00:11 . 2009-03-05 00:11 <DIR> d-------- c:\program files\Drewbuzz Radio

2009-03-03 20:55 . 2002-06-24 12:30 45,568 -ra------ c:\windows\system32\drivers\DLKRTL.SYS

2009-03-01 21:55 . 2009-03-01 21:55 <DIR> d-------- c:\windows\Youda Farmer

2009-03-01 21:55 . 2009-03-01 21:55 <DIR> d-------- c:\program files\Youda Farmer

2009-03-01 21:55 . 2009-03-01 21:55 <DIR> d-------- c:\documents and settings\Shahril Izwan\Application Data\YoudaGames

2009-02-27 23:22 . 2009-02-27 23:22 <DIR> d-------- c:\windows\Ice Blast

2009-02-27 23:22 . 2009-02-27 23:22 <DIR> d-------- c:\program files\Ice Blast

2009-02-23 21:20 . 2009-02-23 21:20 <DIR> d-------- c:\windows\Twinkle Toes Skating

2009-02-23 16:32 . 2009-02-23 16:32 0 -rahs---- C:\khq

2009-02-19 22:14 . 2009-02-19 22:14 <DIR> d-------- c:\program files\Malwarebytes' Anti-Malware

2009-02-19 22:14 . 2009-02-19 22:14 <DIR> d-------- c:\documents and settings\Shahril Izwan\Application Data\Malwarebytes

2009-02-19 22:14 . 2009-02-19 22:14 <DIR> d-------- c:\documents and settings\All Users\Application Data\Malwarebytes

2009-02-19 22:14 . 2009-02-11 10:19 38,496 --a------ c:\windows\system32\drivers\mbamswissarmy.sys

2009-02-19 22:14 . 2009-02-11 10:19 15,504 --a------ c:\windows\system32\drivers\mbam.sys

2009-02-19 22:04 . 2009-02-19 22:04 <DIR> d--h----- c:\windows\PIF

2009-02-19 20:41 . 2009-02-19 20:41 244 --ah----- C:\sqmnoopt05.sqm

2009-02-19 20:41 . 2009-02-19 20:41 232 --ah----- C:\sqmdata05.sqm

2009-02-19 20:39 . 2009-02-19 20:39 244 --ah----- C:\sqmnoopt04.sqm

2009-02-19 20:39 . 2009-02-19 20:39 232 --ah----- C:\sqmdata04.sqm

2009-02-19 20:35 . 2009-02-19 20:35 244 --ah----- C:\sqmnoopt03.sqm

2009-02-19 20:35 . 2009-02-19 20:35 232 --ah----- C:\sqmdata03.sqm

2009-02-19 16:34 . 2009-02-19 16:42 <DIR> d-------- c:\documents and settings\Shahril Izwan\eee

2009-02-19 16:33 . 2009-02-19 22:25 2 --a------ C:\-1138931453

2009-02-19 16:31 . 2009-02-19 16:31 351,275 --a------ c:\windows\system32\rtcshares.exe

2009-02-19 16:31 . 2009-02-19 16:31 186 --a------ c:\windows\system32\c.bat

2009-02-19 16:30 . 2009-02-19 16:31 45,984 --a------ c:\windows\system32\cardvr.exe

2009-02-18 21:44 . 2009-02-18 21:44 <DIR> d-------- c:\program files\iTunes

2009-02-18 21:44 . 2009-02-18 21:44 <DIR> d-------- c:\program files\iPod

2009-02-18 21:44 . 2009-02-18 21:44 <DIR> d-------- c:\documents and settings\All Users\Application Data\{3276BE95_AF08_429F_A64F_CA64CB79BCF6}

2009-02-18 20:58 . 2009-02-11 00:05 952,832 --a------ c:\windows\system32\javac.exe

.

(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))

.

2009-03-13 11:59 1,276,016,672 --sha-w c:\windows\system32\drivers\fidbox.dat

2009-03-13 11:59 --------- d-----w c:\documents and settings\Shahril Izwan\Application Data\uTorrent

2009-03-13 11:57 14,957,060 --sha-w c:\windows\system32\drivers\fidbox.idx

2009-03-13 11:55 --------- d-----w c:\program files\mIRC

2009-03-13 03:09 --------- d-----w c:\documents and settings\All Users\Application Data\avg8

2009-03-13 02:27 --------- d-----w c:\program files\uTorrent

2009-03-12 17:49 --------- d---a-w c:\documents and settings\All Users\Application Data\TEMP

2009-03-11 19:40 --------- d-----w c:\documents and settings\Shahril Izwan\Application Data\mIRC

2009-03-10 01:00 --------- d-----w c:\documents and settings\Shahril Izwan\Application Data\Vso

2009-03-09 07:01 --------- d-----w c:\documents and settings\Shahril Izwan\Application Data\MyPhoneExplorer

2009-02-27 15:18 --------- d-----w c:\program files\Wonderland Online

2009-02-26 09:17 --------- d-----w c:\documents and settings\Shahril Izwan\Application Data\MegauploadToolbar

2009-02-18 13:44 --------- d-----w c:\program files\Common Files\Apple

2009-02-18 13:09 --------- d-----w c:\documents and settings\All Users\Application Data\Apple Computer

2009-02-18 13:01 --------- d-----w c:\program files\QuickTime

2009-02-06 10:46 --------- d-----w c:\program files\CCleaner

2009-01-27 03:39 --------- d-----w c:\program files\Bonjour

2009-01-25 11:12 --------- d-----w c:\program files\Fitness Dash

2009-01-25 11:12 --------- d-----w c:\documents and settings\Shahril Izwan\Application Data\PlayFirst

2009-01-25 11:12 --------- d-----w c:\documents and settings\All Users\Application Data\PlayFirst

2009-01-16 16:53 --------- d-----w c:\program files\Winamp

2009-01-15 16:14 325,128 ----a-w c:\windows\system32\drivers\avgldx86.sys

2009-01-15 15:17 --------- d-----w c:\program files\Magic Encyclopedia First Story

2009-01-13 11:17 --------- d-----w c:\program files\Web Publish

2008-03-06 12:00 47,360 ----a-w c:\documents and settings\Shahril Izwan\Application Data\pcouffin.sys

2009-01-01 05:17 67,688 ----a-w c:\program files\mozilla firefox\components\jar50.dll

2009-01-01 05:17 54,368 ----a-w c:\program files\mozilla firefox\components\jsd3250.dll

2009-01-01 05:17 34,944 ----a-w c:\program files\mozilla firefox\components\myspell.dll

2009-01-01 05:17 46,712 ----a-w c:\program files\mozilla firefox\components\spellchk.dll

2009-01-01 05:17 172,136 ----a-w c:\program files\mozilla firefox\components\xpinstal.dll

2004-08-04 07:56 1,392,671 --sh--r c:\windows\system32\msvbvm60.dll

.

((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))

.

.

*Note* empty entries & legit default entries are not shown

REGEDIT4

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]

"ctfmon.exe"="c:\windows\system32\ctfmon.exe" [2004-08-04 15360]

"uTorrent"="c:\program files\uTorrent\uTorrent.exe" [2008-04-14 219952]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]

"GBB36X Configure"="c:\windows\System32\JMRaidTool.exe" [2006-06-02 385024]

"EasyTuneV"="c:\program files\Gigabyte\ET5\GUI.exe" [2004-06-14 200704]

"NvCplDaemon"="c:\windows\System32\NvCpl.dll" [2007-09-06 8486912]

"NvMediaCenter"="c:\windows\System32\NvMcTray.dll" [2007-09-06 81920]

"CoolSwitch"="c:\windows\System32\taskswitch.exe" [2002-03-19 45632]

"NeroFilterCheck"="c:\program files\Common Files\Ahead\Lib\NeroCheck.exe" [2007-03-09 153136]

"HP Software Update"="c:\program files\HP\HP Software Update\HPWuSchd2.exe" [2004-02-12 49152]

"YSearchProtection"="c:\program files\Yahoo!\Search Protection\SearchProtection.exe" [2008-10-07 111856]

"HP Component Manager"="c:\program files\HP\hpcoretech\hpcmpmgr.exe" [2004-05-12 241664]

"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2008-01-11 39792]

"WinampAgent"="c:\program files\Winamp\winampa.exe" [2008-07-09 36352]

"SunJavaUpdateSched"="c:\program files\Java\jre6\bin\jusched.exe" [2008-11-10 136600]

"AVG8_TRAY"="c:\progra~1\AVG\AVG8\avgtray.exe" [2009-01-09 1601304]

"PC Suite for Smartphones"="c:\program files\Sony Ericsson\Mobile4\Application Launcher\Application Launcher.exe" [2007-12-25 548864]

"QuickTime Task"="c:\program files\QuickTime\qttask.exe" [2009-01-05 413696]

"AppleSyncNotifier"="c:\program files\Common Files\Apple\Mobile Device Support\bin\AppleSyncNotifier.exe" [2008-11-07 111936]

"iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2009-01-06 290088]

"Malwarebytes' Anti-Malware"="c:\program files\Malwarebytes' Anti-Malware\mbamgui.exe" [2009-02-11 399504]

"SkyTel"="SkyTel.EXE" [2006-05-16 c:\windows\SkyTel.exe]

"RTHDCPL"="RTHDCPL.EXE" [2006-05-27 c:\windows\RTHDCPL.EXE]

"Tweak UI"="TWEAKUI.CPL" [2000-06-18 c:\windows\system32\TWEAKUI.CPL]

"nwiz"="nwiz.exe" [2007-09-06 c:\windows\system32\nwiz.exe]

"Logitech Hardware Abstraction Layer"="KHALMNPR.EXE" [2008-02-29 c:\windows\KHALMNPR.Exe]

"Kernel and Hardware Abstraction Layer"="KHALMNPR.EXE" [2008-02-29 c:\windows\KHALMNPR.Exe]

[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]

"msnmsgr"="c:\program files\MSN Messenger\msnmsgr.exe" [2007-01-19 5674352]

c:\documents and settings\Shahril Izwan\Start Menu\Programs\Startup\

uTorrent Turbo Booster.lnk - c:\program files\uTorrent Turbo Booster\uTorrent Turbo Booster.exe [2008-08-25 371712]

c:\documents and settings\All Users\Start Menu\Programs\Startup\

Adobe Gamma Loader.lnk - c:\program files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe [2008-01-25 113664]

DSLMON.lnk - c:\program files\D-Link\D-Link DSL-200I USB ADSL Modem\dslmon.exe [2007-10-16 917601]

HP Digital Imaging Monitor.lnk - c:\program files\HP\Digital Imaging\bin\hpqtra08.exe [2004-05-28 241664]

HP Image Zone Fast Start.lnk - c:\program files\HP\Digital Imaging\bin\hpqthb08.exe [2004-05-28 53248]

Logitech Desktop Messenger.lnk - c:\program files\Logitech\Desktop Messenger\8876480\Program\LogitechDesktopMessenger.exe [2007-09-28 67128]

Logitech SetPoint.lnk - c:\program files\Logitech\SetPoint\SetPoint.exe [2008-08-08 805392]

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\explorer]

"ForceClassicControlPanel"= 1 (0x1)

"NoSMConfigurePrograms"= 1 (0x1)

[HKEY_CURRENT_USER\software\microsoft\windows nt\currentversion\winlogon]

"Shell"="Explorer.exe, c:\program files\Microsoft Office\WINWORD.EXE"

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\LBTWlgn]

2008-05-02 02:42 72208 c:\program files\Common Files\Logitech\Bluetooth\LBTWLgn.dll

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\avgrsstarter]

2009-01-09 01:15 10520 c:\windows\system32\avgrsstx.dll

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\ati2hrxx.sys]

@="Driver"

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\ati3wlxx.sys]

@="Driver"

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\ati6mpxx.sys]

@="Driver"

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\ati7cxxx.sys]

@="Driver"

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\ati8hoxx.sys]

@="Driver"

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\ati8krxx.sys]

@="Driver"

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Wdf01000.sys]

@="Driver"

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WdfLoadGroup]

@=""

[HKEY_LOCAL_MACHINE\software\microsoft\security center]

"AntiVirusDisableNotify"=dword:00000001

"UpdatesDisableNotify"=dword:00000001

"AntiVirusOverride"=dword:00000001

"FirewallOverride"=dword:00000001

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]

"%windir%\\system32\\sessmgr.exe"=

"c:\\Program Files\\uTorrent\\uTorrent.exe"=

"c:\\Program Files\\MSN Messenger\\msnmsgr.exe"=

"c:\\Program Files\\MSN Messenger\\livecall.exe"=

"c:\\Program Files\\Yahoo!\\Messenger\\YahooMessenger.exe"=

"c:\\Program Files\\Logitech\\Desktop Messenger\\8876480\\Program\\LogitechDesktopMessenger.exe"=

"c:\\Program Files\\Sports Interactive\\Football Manager 2008\\fm.exe"=

"c:\\Program Files\\mIRC\\mirc.exe"=

"%windir%\\Network Diagnostic\\xpnetdiag.exe"=

"c:\\Program Files\\Mozilla Firefox\\firefox.exe"=

"c:\\Program Files\\Java\\jre1.6.0_07\\bin\\javaw.exe"=

"c:\\Program Files\\AVG\\AVG8\\avgam.exe"=

"c:\\Program Files\\AVG\\AVG8\\avgemc.exe"=

"c:\\Program Files\\AVG\\AVG8\\avgupd.exe"=

"c:\\Program Files\\AVG\\AVG8\\avgnsx.exe"=

"c:\\Program Files\\Sony Ericsson\\Sony Ericsson Media Manager\\MediaManager.exe"=

"c:\\Program Files\\Intuwave\\Shared\\mRouterRuntime\\mRouterRuntime.exe"=

"c:\\Program Files\\MyPhoneExplorer\\MyPhoneExplorer.exe"=

"c:\\Program Files\\Microsoft Visual Studio\\Common\\Tools\\VS-Ent98\\Vanalyzr\\VARPC.EXE"=

"f:\\Ijud Punyer\\Visual Basic\\Applications\\Ratio\\RatioMaster.exe"=

"c:\\Program Files\\Bonjour\\mDNSResponder.exe"=

"c:\\Program Files\\iTunes\\iTunes.exe"=

"c:\\Program Files\\Drewbuzz Radio\\Drewbuzz Radio.exe"=

R0 AvgRkx86;avgrkx86.sys;c:\windows\system32\drivers\avgrkx86.sys [2008-12-07 12552]

R1 AvgLdx86;AVG AVI Loader Driver x86;c:\windows\system32\drivers\avgldx86.sys [2008-12-07 325128]

R1 AvgTdiX;AVG8 Network Redirector;c:\windows\system32\drivers\avgtdix.sys [2008-12-07 107272]

R1 is-G8L4Sdrv;is-G8L4Sdrv;c:\windows\system32\drivers\23517218.sys [2009-03-12 148496]

R1 is-JFNC0drv;is-JFNC0drv;c:\windows\system32\drivers\44490575.sys [2009-01-18 148496]

R1 is-K425Gdrv;is-K425Gdrv;c:\windows\system32\drivers\01823800.sys [2008-12-12 22:16:58 148496]

R2 avg8emc;AVG8 E-mail Scanner;c:\progra~1\AVG\AVG8\avgemc.exe [2009-01-09 903960]

R2 avg8wd;AVG8 WatchDog;c:\progra~1\AVG\AVG8\avgwdsvc.exe [2009-01-09 298264]

R2 MBAMService;MBAMService;c:\program files\Malwarebytes' Anti-Malware\mbamservice.exe [2009-02-19 179856]

R3 DFE528TX;D-Link DFE-528TX PCI Adapter;c:\windows\system32\drivers\DLKRTL.SYS [2009-03-03 45568]

R3 MBAMProtector;MBAMProtector;c:\windows\system32\drivers\mbam.sys [2009-02-19 15504]

S0 ati2hrxx;ati2hrxx;c:\windows\system32\Drivers\ati2hrxx.sys --> c:\windows\system32\Drivers\ati2hrxx.sys [?]

S0 ati3wlxx;ati3wlxx;c:\windows\system32\Drivers\ati3wlxx.sys --> c:\windows\system32\Drivers\ati3wlxx.sys [?]

S0 ati6mpxx;ati6mpxx;c:\windows\system32\Drivers\ati6mpxx.sys --> c:\windows\system32\Drivers\ati6mpxx.sys [?]

S0 ati7cxxx;ati7cxxx;c:\windows\system32\Drivers\ati7cxxx.sys --> c:\windows\system32\Drivers\ati7cxxx.sys [?]

S0 ati8hoxx;ati8hoxx;c:\windows\system32\Drivers\ati8hoxx.sys --> c:\windows\system32\Drivers\ati8hoxx.sys [?]

S0 ati8krxx;ati8krxx;c:\windows\system32\Drivers\ati8krxx.sys --> c:\windows\system32\Drivers\ati8krxx.sys [?]

S1 is-561OMdrv;is-561OMdrv;c:\windows\system32\drivers\55711518.sys [2009-03-12 148496]

S2 dhfiecas;Installer Update;c:\windows\system32\svchost.exe -k netsvcs [2001-08-23 14336]

S3 ggflt;SEMC USB Flash Driver Filter;c:\windows\system32\drivers\ggflt.sys [2008-12-09 10976]

S3 s816bus;Sony Ericsson Device 816 driver (WDM);c:\windows\system32\drivers\s816bus.sys [2008-06-06 81832]

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Svchost - NetSvcs

dhfiecas

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{35bdf491-7ac3-11dc-8c02-0016e65d557b}]

\Shell\Auto\command - MicrosoftPowerPoint.exe

\Shell\AutoRun\command - c:\windows\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL MicrosoftPowerPoint.exe

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{84300d32-dda8-11dd-905e-0016e65d557b}]

\Shell\AutoRun\command - sugtgu.exe

\Shell\explore\Command - sugtgu.exe

\Shell\open\Command - sugtgu.exe

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{a94b068e-8ba3-11dc-8c43-0016e65d557b}]

\Shell\AutoRun\command - c:\windows\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL Flash.10.Setup.exe

\Shell\Explore\command - Flash.10.Setup.exe

\Shell\Open\command - Flash.10.Setup.exe

\Shell\Scan for Viruses\command - Scanner.exe

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{da4ed1b9-a271-11dc-8cb5-0016e65d557b}]

\Shell\AutoRun\command - I:\LaunchU3.exe -a

.

Contents of the 'Scheduled Tasks' folder

2009-03-13 c:\windows\Tasks\A893E0F8906894EC.job

- c:\docume~1\shahri~1\applic~1\byteba~1\Compcoolamen.exe []

2009-03-12 c:\windows\Tasks\Ad-Aware Update (Daily).job

- c:\program files\Lavasoft\Ad-Aware\Ad-AwareAdmin.exe []

2009-03-10 c:\windows\Tasks\AppleSoftwareUpdate.job

- c:\program files\Apple Software Update\SoftwareUpdate.exe [2008-07-30 12:34]

2009-03-13 c:\windows\Tasks\At1.job

- c:\documents and settings\Shahril Izwan\Templates\16248-NendangBro.com []

2009-03-13 c:\windows\Tasks\At2.job

- c:\documents and settings\Shahril Izwan\Templates\16248-NendangBro.com []

2009-03-12 c:\windows\Tasks\WebReg 20080523230406.job

- c:\program files\HP\Digital Imaging\bin\hpqwrg.exe [2004-05-28 22:47]

.

- - - - ORPHANS REMOVED - - - -

HKLM-Run-UnlockerAssistant - c:\program files\Unlocker\UnlockerAssistant.exe

HKLM-Run-ZTE ADSL - (no file)

Notify-rxughy - rxughy.dll

SafeBoot-ati3gnxx.sys

.

------- Supplementary Scan -------

.

uStart Page = hxxp://www.google.com/

uLocal Page = \blank.htm

mStart Page = hxxp://www.google.com/

uInternet Connection Wizard,ShellNext = iexplore

uInternet Settings,ProxyOverride = local

uSearchURL,(Default) = hxxp://us.rd.yahoo.com/customize/ycomp/defaults/su/*http://www.yahoo.com

IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~3\OFFICE11\EXCEL.EXE/3000

IE: E&xportar para o Microsoft Excel - c:\progra~1\MICROS~3\Office10\EXCEL.EXE/3000

Handler: bwfile-8876480 - {9462A756-7B47-47BC-8C80-C34B9B80B32B} - c:\program files\Logitech\Desktop Messenger\8876480\Program\GAPlugProtocol-8876480.dll

DPF: DirectAnimation Java Classes - file://c:\windows\Java\classes\dajava.cab

DPF: Microsoft XML Parser for Java - file://c:\windows\Java\classes\xmldso.cab

FF - ProfilePath - c:\documents and settings\Shahril Izwan\Application Data\Mozilla\Firefox\Profiles\9wp3u9p9.default\

FF - component: c:\program files\AVG\AVG8\Firefox\components\avgssff.dll

FF - component: c:\program files\Mozilla Firefox\components\xpinstal.dll

.

**************************************************************************

catchme 0.3.1367 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net

Rootkit scan 2009-03-13 19:58:55

Windows 5.1.2600 Service Pack 2 NTFS

scanning hidden processes ...

scanning hidden autostart entries ...

scanning hidden files ...

scan completed successfully

hidden files: 0

**************************************************************************

[HKEY_LOCAL_MACHINE\System\ControlSet003\Services\dhfiecas]

"ServiceDll"="c:\windows\system32\mmuiq.dll"

.

--------------------- LOCKED REGISTRY KEYS ---------------------

[HKEY_USERS\S-1-5-21-515967899-1708537768-725345543-1003\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved\{A92EF9CA-AB88-0B40-1139-8CBD68DA9347}*]

@Allowed: (Read) (RestrictedCode)

@Allowed: (Read) (RestrictedCode)

.

--------------------- DLLs Loaded Under Running Processes ---------------------

- - - - - - - > 'winlogon.exe'(616)

c:\program files\common files\logitech\bluetooth\LBTWlgn.dll

c:\program files\common files\logitech\bluetooth\LBTServ.dll

.

------------------------ Other Running Processes ------------------------

.

c:\program files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe

c:\program files\Bonjour\mDNSResponder.exe

c:\program files\Java\jre6\bin\jqs.exe

c:\program files\Common Files\Microsoft Shared\VS7Debug\mdm.exe

c:\windows\system32\nvsvc32.exe

c:\progra~1\AVG\AVG8\avgam.exe

c:\program files\AVG\AVG8\avgrsx.exe

c:\progra~1\AVG\AVG8\avgnsx.exe

c:\program files\AVG\AVG8\avgcsrvx.exe

c:\windows\system32\rundll32.exe

c:\program files\HP\Digital Imaging\bin\hpqgalry.exe

c:\program files\Common Files\Logishrd\KHAL2\KHALMNPR.exe

c:\program files\iPod\bin\iPodService.exe

.

**************************************************************************

.

Completion time: 2009-03-13 20:02:57 - machine was rebooted

ComboFix-quarantined-files.txt 2009-03-13 12:02:53

Pre-Run: 10,296,823,808 bytes free

Post-Run: 10,464,886,784 bytes free

WindowsXP-KB310994-SP2-Pro-BootDisk-ENU.exe

[boot loader]

timeout=2

default=multi(0)disk(0)rdisk(0)partition(1)\WINDOWS

[operating systems]

c:\cmdcons\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons

multi(0)disk(0)rdisk(0)partition(1)\WINDOWS="Microsoft Windows XP Professional" /fastdetect /NoExecute=OptIn

354 --- E O F --- 2008-07-09 01:05:41

Link to post
Share on other sites

and here is the HijakThis log:

Logfile of Trend Micro HijackThis v2.0.2

Scan saved at 8:06:11 PM, on 3/13/2009

Platform: Windows XP SP2 (WinNT 5.01.2600)

MSIE: Internet Explorer v7.00 (7.00.6000.16674)

Boot mode: Normal

Running processes:

C:\WINDOWS\System32\smss.exe

C:\WINDOWS\system32\winlogon.exe

C:\WINDOWS\system32\services.exe

C:\WINDOWS\system32\lsass.exe

C:\WINDOWS\system32\svchost.exe

C:\WINDOWS\System32\svchost.exe

C:\WINDOWS\system32\spoolsv.exe

C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe

C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe

C:\Program Files\Bonjour\mDNSResponder.exe

C:\Program Files\Java\jre6\bin\jqs.exe

C:\Program Files\Malwarebytes' Anti-Malware\mbamservice.exe

C:\Program Files\Common Files\Microsoft Shared\VS7Debug\mdm.exe

C:\WINDOWS\System32\nvsvc32.exe

C:\PROGRA~1\AVG\AVG8\avgam.exe

C:\PROGRA~1\AVG\AVG8\avgrsx.exe

C:\WINDOWS\System32\svchost.exe

C:\PROGRA~1\AVG\AVG8\avgnsx.exe

C:\PROGRA~1\AVG\AVG8\avgemc.exe

C:\Program Files\AVG\AVG8\avgcsrvx.exe

C:\WINDOWS\RTHDCPL.EXE

C:\WINDOWS\system32\RUNDLL32.EXE

C:\WINDOWS\System32\taskswitch.exe

C:\Program Files\HP\HP Software Update\HPWuSchd2.exe

C:\Program Files\Yahoo!\Search Protection\SearchProtection.exe

C:\Program Files\HP\hpcoretech\hpcmpmgr.exe

C:\Program Files\Winamp\winampa.exe

C:\Program Files\Java\jre6\bin\jusched.exe

C:\PROGRA~1\AVG\AVG8\avgtray.exe

C:\Program Files\iTunes\iTunesHelper.exe

C:\WINDOWS\system32\ctfmon.exe

C:\Program Files\uTorrent\uTorrent.exe

C:\Program Files\D-Link\D-Link DSL-200I USB ADSL Modem\dslmon.exe

C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe

C:\Program Files\Logitech\Desktop Messenger\8876480\Program\LogitechDesktopMessenger.exe

C:\Program Files\Logitech\SetPoint\SetPoint.exe

C:\Program Files\uTorrent Turbo Booster\uTorrent Turbo Booster.exe

C:\Program Files\HP\Digital Imaging\bin\hpqgalry.exe

C:\Program Files\Common Files\Logishrd\KHAL2\KHALMNPR.EXE

C:\Program Files\iPod\bin\iPodService.exe

C:\WINDOWS\explorer.exe

C:\WINDOWS\system32\notepad.exe

C:\Program Files\Internet Explorer\iexplore.exe

F:\Ijud Punyer\Visual Basic\Applications\HijackThis.exe

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896

R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://us.rd.yahoo.com/customize/ycomp/def...//www.yahoo.com

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page = \blank.htm

R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = local

R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\PROGRA~1\Yahoo!\Companion\Installs\cpn2\yt.dll

O2 - BHO: &Yahoo! Toolbar Helper - {02478D38-C3F9-4efb-9B51-7695ECA05670} - C:\PROGRA~1\Yahoo!\Companion\Installs\cpn2\yt.dll

O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll

O2 - BHO: WormRadar.com IESiteBlocker.NavFilter - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files\AVG\AVG8\avgssie.dll

O2 - BHO: Megaupload Toolbar - {4E7BD74F-2B8D-469E-CCB0-B130EEDBE97C} - C:\PROGRA~1\MEGAUP~2\MEGAUP~1.DLL

O2 - BHO: Yahoo! IE Services Button - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\Program Files\Yahoo!\Common\yiesrvc.dll

O2 - BHO: Java Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre6\bin\ssv.dll

O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)

O2 - BHO: Java Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll

O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll

O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\PROGRA~1\Yahoo!\Companion\Installs\cpn2\yt.dll

O3 - Toolbar: Megaupload Toolbar - {4E7BD74F-2B8D-469E-CCB0-B130EEDBE97C} - C:\PROGRA~1\MEGAUP~2\MEGAUP~1.DLL

O4 - HKLM\..\Run: [skyTel] SkyTel.EXE

O4 - HKLM\..\Run: [GBB36X Configure] C:\WINDOWS\System32\JMRaidTool.exe boot

O4 - HKLM\..\Run: [RTHDCPL] RTHDCPL.EXE

O4 - HKLM\..\Run: [Tweak UI] RUNDLL32.EXE TWEAKUI.CPL,TweakMeUp

O4 - HKLM\..\Run: [EasyTuneV] C:\Program Files\Gigabyte\ET5\GUI.exe

O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\System32\NvCpl.dll,NvStartup

O4 - HKLM\..\Run: [nwiz] nwiz.exe /install

O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\System32\NvMcTray.dll,NvTaskbarInit

O4 - HKLM\..\Run: [CoolSwitch] C:\WINDOWS\System32\taskswitch.exe

O4 - HKLM\..\Run: [NeroFilterCheck] C:\Program Files\Common Files\Ahead\Lib\NeroCheck.exe

O4 - HKLM\..\Run: [Logitech Hardware Abstraction Layer] KHALMNPR.EXE

O4 - HKLM\..\Run: [HP Software Update] "C:\Program Files\HP\HP Software Update\HPWuSchd2.exe"

O4 - HKLM\..\Run: [YSearchProtection] "C:\Program Files\Yahoo!\Search Protection\SearchProtection.exe"

O4 - HKLM\..\Run: [HP Component Manager] "C:\Program Files\HP\hpcoretech\hpcmpmgr.exe"

O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"

O4 - HKLM\..\Run: [Kernel and Hardware Abstraction Layer] KHALMNPR.EXE

O4 - HKLM\..\Run: [WinampAgent] "C:\Program Files\Winamp\winampa.exe"

O4 - HKLM\..\Run: [sunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe"

O4 - HKLM\..\Run: [AVG8_TRAY] C:\PROGRA~1\AVG\AVG8\avgtray.exe

O4 - HKLM\..\Run: [PC Suite for Smartphones] "C:\Program Files\Sony Ericsson\Mobile4\Application Launcher\Application Launcher.exe" /startoptions

O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime

O4 - HKLM\..\Run: [AppleSyncNotifier] C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleSyncNotifier.exe

O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"

O4 - HKLM\..\Run: [Malwarebytes' Anti-Malware] "C:\Program Files\Malwarebytes' Anti-Malware\mbamgui.exe" /starttray

O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe

O4 - HKCU\..\Run: [uTorrent] "C:\Program Files\uTorrent\uTorrent.exe"

O4 - HKUS\S-1-5-18\..\Run: [msnmsgr] "C:\Program Files\MSN Messenger\msnmsgr.exe" /background (User 'SYSTEM')

O4 - HKUS\.DEFAULT\..\Run: [msnmsgr] "C:\Program Files\MSN Messenger\msnmsgr.exe" /background (User 'Default user')

O4 - Startup: uTorrent Turbo Booster.lnk = C:\Program Files\uTorrent Turbo Booster\uTorrent Turbo Booster.exe

O4 - Global Startup: Adobe Gamma Loader.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe

O4 - Global Startup: DSLMON.lnk = ?

O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe

O4 - Global Startup: HP Image Zone Fast Start.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqthb08.exe

O4 - Global Startup: Logitech Desktop Messenger.lnk = C:\Program Files\Logitech\Desktop Messenger\8876480\Program\LogitechDesktopMessenger.exe

O4 - Global Startup: Logitech SetPoint.lnk = C:\Program Files\Logitech\SetPoint\SetPoint.exe

O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~3\OFFICE11\EXCEL.EXE/3000

O8 - Extra context menu item: E&xportar para o Microsoft Excel - res://C:\PROGRA~1\MICROS~3\Office10\EXCEL.EXE/3000

O9 - Extra button: Yahoo! Services - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\Program Files\Yahoo!\Common\yiesrvc.dll

O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~3\OFFICE11\REFIEBAR.DLL

O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe

O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe

O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe

O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe

O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (Installation Support) - C:\Program Files\Yahoo!\Common\Yinsthelper.dll

O17 - HKLM\System\CCS\Services\Tcpip\..\{4833954F-1E33-488A-8EE5-D3CE72394F1D}: NameServer = 202.188.0.133 202.188.1.5

O17 - HKLM\System\CS1\Services\Tcpip\..\{4833954F-1E33-488A-8EE5-D3CE72394F1D}: NameServer = 202.188.0.133 202.188.1.5

O17 - HKLM\System\CS3\Services\Tcpip\..\{4833954F-1E33-488A-8EE5-D3CE72394F1D}: NameServer = 202.188.0.133 202.188.1.5

O18 - Protocol: bwfile-8876480 - {9462A756-7B47-47BC-8C80-C34B9B80B32B} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\GAPlugProtocol-8876480.dll

O18 - Protocol: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files\AVG\AVG8\avgpp.dll

O20 - Winlogon Notify: avgrsstarter - C:\WINDOWS\SYSTEM32\avgrsstx.dll

O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe

O23 - Service: AVG8 E-mail Scanner (avg8emc) - AVG Technologies CZ, s.r.o. - C:\PROGRA~1\AVG\AVG8\avgemc.exe

O23 - Service: AVG8 WatchDog (avg8wd) - AVG Technologies CZ, s.r.o. - C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe

O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe

O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1150\Intel 32\IDriverT.exe

O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe

O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe

O23 - Service: Logitech Bluetooth Service (LBTServ) - Logitech, Inc. - C:\Program Files\Common Files\Logitech\Bluetooth\LBTServ.exe

O23 - Service: Macromedia Licensing Service - Unknown owner - C:\Program Files\Common Files\Macromedia Shared\Service\Macromedia Licensing.exe

O23 - Service: MBAMService - Malwarebytes Corporation - C:\Program Files\Malwarebytes' Anti-Malware\mbamservice.exe

O23 - Service: NBService - Nero AG - C:\Program Files\Nero\Nero 7\Nero BackItUp\NBService.exe

O23 - Service: NMIndexingService - Nero AG - C:\Program Files\Common Files\Ahead\Lib\NMIndexingService.exe

O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\System32\nvsvc32.exe

O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe

--

End of file - 10753 bytes

*It appears that I still have the Adobe Gamma Loader on my startup. Is this still considered as a virus?

Link to post
Share on other sites

Done, after that....?

HijackThis Log:

Logfile of Trend Micro HijackThis v2.0.2

Scan saved at 9:06:47 AM, on 3/14/2009

Platform: Windows XP SP2 (WinNT 5.01.2600)

MSIE: Internet Explorer v7.00 (7.00.6000.16674)

Boot mode: Normal

Running processes:

C:\WINDOWS\System32\smss.exe

C:\WINDOWS\system32\winlogon.exe

C:\WINDOWS\system32\services.exe

C:\WINDOWS\system32\lsass.exe

C:\WINDOWS\system32\svchost.exe

C:\WINDOWS\System32\svchost.exe

C:\WINDOWS\system32\spoolsv.exe

C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe

C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe

C:\Program Files\Bonjour\mDNSResponder.exe

C:\Program Files\Java\jre6\bin\jqs.exe

C:\Program Files\Common Files\Microsoft Shared\VS7Debug\mdm.exe

C:\WINDOWS\System32\nvsvc32.exe

C:\PROGRA~1\AVG\AVG8\avgam.exe

C:\PROGRA~1\AVG\AVG8\avgrsx.exe

C:\WINDOWS\System32\svchost.exe

C:\PROGRA~1\AVG\AVG8\avgemc.exe

C:\Program Files\AVG\AVG8\avgcsrvx.exe

C:\WINDOWS\RTHDCPL.EXE

C:\WINDOWS\system32\RUNDLL32.EXE

C:\WINDOWS\System32\taskswitch.exe

C:\Program Files\HP\HP Software Update\HPWuSchd2.exe

C:\Program Files\Yahoo!\Search Protection\SearchProtection.exe

C:\Program Files\HP\hpcoretech\hpcmpmgr.exe

C:\Program Files\Winamp\winampa.exe

C:\Program Files\Java\jre6\bin\jusched.exe

C:\PROGRA~1\AVG\AVG8\avgtray.exe

C:\Program Files\iTunes\iTunesHelper.exe

C:\WINDOWS\system32\ctfmon.exe

C:\Program Files\D-Link\D-Link DSL-200I USB ADSL Modem\dslmon.exe

C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe

C:\Program Files\Logitech\Desktop Messenger\8876480\Program\LogitechDesktopMessenger.exe

C:\Program Files\Logitech\SetPoint\SetPoint.exe

C:\Program Files\HP\Digital Imaging\bin\hpqgalry.exe

C:\Program Files\Common Files\Logishrd\KHAL2\KHALMNPR.EXE

C:\Program Files\iPod\bin\iPodService.exe

C:\WINDOWS\explorer.exe

C:\Program Files\Malwarebytes' Anti-Malware\mbamgui.exe

C:\Program Files\Mozilla Firefox\firefox.exe

C:\PROGRA~1\Intuwave\Shared\MROUTE~1\MROUTE~2.EXE

C:\Program Files\Yahoo!\Messenger\ymsgr_tray.exe

C:\Program Files\K-Lite Codec Pack\Media Player Classic\mplayerc.exe

C:\Program Files\Internet Explorer\iexplore.exe

C:\PROGRA~1\AVG\AVG8\avgnsx.exe

F:\Ijud Punyer\Visual Basic\Applications\HijackThis.exe

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896

R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://us.rd.yahoo.com/customize/ycomp/def...//www.yahoo.com

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page = \blank.htm

R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = local

R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\PROGRA~1\Yahoo!\Companion\Installs\cpn2\yt.dll

O2 - BHO: &Yahoo! Toolbar Helper - {02478D38-C3F9-4efb-9B51-7695ECA05670} - C:\PROGRA~1\Yahoo!\Companion\Installs\cpn2\yt.dll

O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll

O2 - BHO: WormRadar.com IESiteBlocker.NavFilter - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files\AVG\AVG8\avgssie.dll

O2 - BHO: Megaupload Toolbar - {4E7BD74F-2B8D-469E-CCB0-B130EEDBE97C} - C:\PROGRA~1\MEGAUP~2\MEGAUP~1.DLL

O2 - BHO: Yahoo! IE Services Button - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\Program Files\Yahoo!\Common\yiesrvc.dll

O2 - BHO: Java Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre6\bin\ssv.dll

O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)

O2 - BHO: Java Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll

O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll

O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\PROGRA~1\Yahoo!\Companion\Installs\cpn2\yt.dll

O3 - Toolbar: Megaupload Toolbar - {4E7BD74F-2B8D-469E-CCB0-B130EEDBE97C} - C:\PROGRA~1\MEGAUP~2\MEGAUP~1.DLL

O4 - HKLM\..\Run: [skyTel] SkyTel.EXE

O4 - HKLM\..\Run: [GBB36X Configure] C:\WINDOWS\System32\JMRaidTool.exe boot

O4 - HKLM\..\Run: [RTHDCPL] RTHDCPL.EXE

O4 - HKLM\..\Run: [Tweak UI] RUNDLL32.EXE TWEAKUI.CPL,TweakMeUp

O4 - HKLM\..\Run: [EasyTuneV] C:\Program Files\Gigabyte\ET5\GUI.exe

O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\System32\NvCpl.dll,NvStartup

O4 - HKLM\..\Run: [nwiz] nwiz.exe /install

O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\System32\NvMcTray.dll,NvTaskbarInit

O4 - HKLM\..\Run: [CoolSwitch] C:\WINDOWS\System32\taskswitch.exe

O4 - HKLM\..\Run: [NeroFilterCheck] C:\Program Files\Common Files\Ahead\Lib\NeroCheck.exe

O4 - HKLM\..\Run: [Logitech Hardware Abstraction Layer] KHALMNPR.EXE

O4 - HKLM\..\Run: [HP Software Update] "C:\Program Files\HP\HP Software Update\HPWuSchd2.exe"

O4 - HKLM\..\Run: [YSearchProtection] "C:\Program Files\Yahoo!\Search Protection\SearchProtection.exe"

O4 - HKLM\..\Run: [HP Component Manager] "C:\Program Files\HP\hpcoretech\hpcmpmgr.exe"

O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"

O4 - HKLM\..\Run: [Kernel and Hardware Abstraction Layer] KHALMNPR.EXE

O4 - HKLM\..\Run: [WinampAgent] "C:\Program Files\Winamp\winampa.exe"

O4 - HKLM\..\Run: [sunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe"

O4 - HKLM\..\Run: [AVG8_TRAY] C:\PROGRA~1\AVG\AVG8\avgtray.exe

O4 - HKLM\..\Run: [PC Suite for Smartphones] "C:\Program Files\Sony Ericsson\Mobile4\Application Launcher\Application Launcher.exe" /startoptions

O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime

O4 - HKLM\..\Run: [AppleSyncNotifier] C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleSyncNotifier.exe

O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"

O4 - HKLM\..\Run: [Malwarebytes' Anti-Malware] "C:\Program Files\Malwarebytes' Anti-Malware\mbamgui.exe" /starttray

O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe

O4 - HKCU\..\Run: [uTorrent] "C:\Program Files\uTorrent\uTorrent.exe"

O4 - HKUS\S-1-5-18\..\Run: [msnmsgr] "C:\Program Files\MSN Messenger\msnmsgr.exe" /background (User 'SYSTEM')

O4 - HKUS\.DEFAULT\..\Run: [msnmsgr] "C:\Program Files\MSN Messenger\msnmsgr.exe" /background (User 'Default user')

O4 - Startup: uTorrent Turbo Booster.lnk = C:\Program Files\uTorrent Turbo Booster\uTorrent Turbo Booster.exe

O4 - Global Startup: Adobe Gamma Loader.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe

O4 - Global Startup: DSLMON.lnk = ?

O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe

O4 - Global Startup: HP Image Zone Fast Start.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqthb08.exe

O4 - Global Startup: Logitech Desktop Messenger.lnk = C:\Program Files\Logitech\Desktop Messenger\8876480\Program\LogitechDesktopMessenger.exe

O4 - Global Startup: Logitech SetPoint.lnk = C:\Program Files\Logitech\SetPoint\SetPoint.exe

O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~3\OFFICE11\EXCEL.EXE/3000

O8 - Extra context menu item: E&xportar para o Microsoft Excel - res://C:\PROGRA~1\MICROS~3\Office10\EXCEL.EXE/3000

O9 - Extra button: Yahoo! Services - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\Program Files\Yahoo!\Common\yiesrvc.dll

O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~3\OFFICE11\REFIEBAR.DLL

O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe

O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe

O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe

O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe

O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (Installation Support) - C:\Program Files\Yahoo!\Common\Yinsthelper.dll

O17 - HKLM\System\CCS\Services\Tcpip\..\{4833954F-1E33-488A-8EE5-D3CE72394F1D}: NameServer = 202.188.0.133 202.188.1.5

O17 - HKLM\System\CS1\Services\Tcpip\..\{4833954F-1E33-488A-8EE5-D3CE72394F1D}: NameServer = 202.188.0.133 202.188.1.5

O17 - HKLM\System\CS3\Services\Tcpip\..\{4833954F-1E33-488A-8EE5-D3CE72394F1D}: NameServer = 202.188.0.133 202.188.1.5

O18 - Protocol: bwfile-8876480 - {9462A756-7B47-47BC-8C80-C34B9B80B32B} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\GAPlugProtocol-8876480.dll

O18 - Protocol: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files\AVG\AVG8\avgpp.dll

O20 - Winlogon Notify: avgrsstarter - C:\WINDOWS\SYSTEM32\avgrsstx.dll

O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe

O23 - Service: AVG8 E-mail Scanner (avg8emc) - AVG Technologies CZ, s.r.o. - C:\PROGRA~1\AVG\AVG8\avgemc.exe

O23 - Service: AVG8 WatchDog (avg8wd) - AVG Technologies CZ, s.r.o. - C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe

O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe

O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1150\Intel 32\IDriverT.exe

O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe

O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe

O23 - Service: Logitech Bluetooth Service (LBTServ) - Logitech, Inc. - C:\Program Files\Common Files\Logitech\Bluetooth\LBTServ.exe

O23 - Service: Macromedia Licensing Service - Unknown owner - C:\Program Files\Common Files\Macromedia Shared\Service\Macromedia Licensing.exe

O23 - Service: MBAMService - Malwarebytes Corporation - C:\Program Files\Malwarebytes' Anti-Malware\mbamservice.exe

O23 - Service: NBService - Nero AG - C:\Program Files\Nero\Nero 7\Nero BackItUp\NBService.exe

O23 - Service: NMIndexingService - Nero AG - C:\Program Files\Common Files\Ahead\Lib\NMIndexingService.exe

O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\System32\nvsvc32.exe

O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe

--

End of file - 10825 bytes

Link to post
Share on other sites

  • Root Admin

Did you set those 017 Name Servers yourself?

STEP 01

Download but do not yet run ComboFix

If you have a previous version of Combofix.exe, delete it and download a fresh copy.

Download it to your DESKTOP - it MUST run from the Desktop

download.bleepingcomputer.com/sUBs/ComboFix.exe

subs.geekstogo.com/ComboFix.exe

Using your mouse, Highlight and then Right-click | Copy the entire contents of the Code box below, including blank lines

KILLALL::

File::
c:\windows\system32\drivers\55711518.sys
c:\windows\system32\drivers\23517218.sys
c:\windows\system32\c.bat
c:\windows\system32\drivers\23517218.sys
c:\windows\system32\drivers\44490575.sys
c:\windows\system32\drivers\01823800.sys
c:\windows\system32\Drivers\ati2hrxx.sys
c:\windows\system32\Drivers\ati3wlxx.sys
c:\windows\system32\Drivers\ati6mpxx.sys
c:\windows\system32\Drivers\ati7cxxx.sys
c:\windows\system32\Drivers\ati8hoxx.sys
c:\windows\system32\Drivers\ati8krxx.sys
c:\windows\system32\drivers\55711518.sys
c:\windows\Tasks\A893E0F8906894EC.job
c:\docume~1\shahri~1\applic~1\byteba~1\Compcoolamen.exe
c:\windows\Tasks\At1.job
c:\documents and settings\Shahril Izwan\Templates\16248-NendangBro.com
c:\windows\Tasks\At2.job
c:\windows\system32\mmuiq.dll


Folder::
C:\-1138931453

Driver::
is-G8L4Sdrv
is-JFNC0drv
is-K425Gdrv
ati2hrxx
ati3wlxx
ati6mpxx
ati7cxxx
ati8hoxx
ati8krxx
is-561OMdrv
dhfiecas

Registry::
[-HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{35bdf491-7ac3-11dc-8c02-0016e65d557b}]
[-HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{84300d32-dda8-11dd-905e-0016e65d557b}]
[-HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{a94b068e-8ba3-11dc-8c43-0016e65d557b}]
[-HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{da4ed1b9-a271-11dc-8cb5-0016e65d557b}]
[-HKEY_LOCAL_MACHINE\System\ControlSet003\Services\dhfiecas]

RegLock::
[HKEY_USERS\S-1-5-21-515967899-1708537768-725345543-1003\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved\{A92EF9CA-AB88-0B40-1139-8CBD68DA9347}*]
RegNull::
[HKEY_USERS\S-1-5-21-515967899-1708537768-725345543-1003\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved\{A92EF9CA-AB88-0B40-1139-8CBD68DA9347}*]
RegLock::
[HKEY_USERS\S-1-5-21-515967899-1708537768-725345543-1003\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved\{A92EF9CA-AB88-0B40-1139-8CBD68DA9347}*]
RegNull::
[HKEY_USERS\S-1-5-21-515967899-1708537768-725345543-1003\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved\{A92EF9CA-AB88-0B40-1139-8CBD68DA9347}*]

Open a new Notepad session (Do not use a Word Processor or WordPad). Click "Format" and be certain that Word Wrap is not enabled. Right-click | Paste the Code box contents from above into Notepad. Click File, Save as..., and set the location to your Desktop, and enter (including quotation marks) as the filename: "CFscript.txt" .

Using your mouse, drag the new file CFscript.txt and drop it on the Combo-Fix.exe icon as shown:

CFScript.gif

  • Important: Have no other programs running. Your Task Bar should be clear of any program entries including your Browser.
  • Disconnect from the Internet.
  • Disable your Antivirus software. If it has Script Blocking features, please disable these as well.
  • A window may open with a series of Disclaimers. Accept the Disclaimers to start the fix.
  • It may identify that Recovery Console is not installed. Please accept when asked if you wish it to be installed.
    When the scan completes Notepad will open with with your results log open. Do a File, Exit.

A caution - Do not run Combofix more than once. Do not touch your mouse/keyboard until the scan has completed, as this may cause the process to stall or your computer to lock. The scan will temporarily disable your desktop, and if interrupted may leave your desktop disabled. If this occurs, please reboot to restore the desktop. Even when ComboFix appears to be doing nothing, look at your Drive light. If it is flashing, Combofix is still at work.

Post back the Combofix log on your next reply.

STEP 02

Update and Scan with Malwarebytes' Anti-Malware

  • Start MalwareBytes AntiMalware (Vista users must Right click and choose RunAs Admin)
  • Please DO NOT run MBAM in Safe Mode unless requested to, you MUST run it in normal Windows mode.
    • Update Malwarebytes' Anti-Malware
    • Select the Update tab
    • Click Update

    [*]When the update is complete, select the Scanner tab

    [*]Select Perform quick scan, then click Scan.

    [*]When the scan is complete, click OK, then Show Results to view the results.

    [*]Be sure that everything is checked, and click Remove Selected.

    [*]When completed, a log will open in Notepad. please copy and paste the log into your next reply

    • If you accidently close it, the log file is saved here and will be named like this:
    • C:\Documents and Settings\Username\Application Data\Malwarebytes\Malwarebytes' Anti-Malware\Logs\mbam-log-date (time).txt

Then post back the MBAM log and a new Hijackthis log.

Link to post
Share on other sites

Here's the MBAM's log:

Malwarebytes' Anti-Malware 1.34

Database version: 1848

Windows 5.1.2600 Service Pack 2

3/14/2009 9:43:55 PM

mbam-log-2009-03-14 (21-43-55).txt

Scan type: Full Scan (C:\|)

Objects scanned: 167522

Time elapsed: 33 minute(s), 47 second(s)

Memory Processes Infected: 0

Memory Modules Infected: 0

Registry Keys Infected: 0

Registry Values Infected: 0

Registry Data Items Infected: 0

Folders Infected: 0

Files Infected: 0

Memory Processes Infected:

(No malicious items detected)

Memory Modules Infected:

(No malicious items detected)

Registry Keys Infected:

(No malicious items detected)

Registry Values Infected:

(No malicious items detected)

Registry Data Items Infected:

(No malicious items detected)

Folders Infected:

(No malicious items detected)

Files Infected:

(No malicious items detected)

Link to post
Share on other sites

Here's the ComboFix's log:

ComboFix 09-03-13.02 - Shahril Izwan 2009-03-14 20:22:39.2 - NTFSx86

Microsoft Windows XP Professional 5.1.2600.2.1252.1.1033.18.1023.512 [GMT 8:00]

Running from: c:\documents and settings\Shahril Izwan\Desktop\ComboFix.exe

Command switches used :: c:\documents and settings\Shahril Izwan\Desktop\CFscript.txt

AV: AVG Anti-Virus *On-access scanning disabled* (Updated)

* Created a new restore point

FILE ::

c:\docume~1\shahri~1\applic~1\byteba~1\Compcoolamen.exe

c:\documents and settings\Shahril Izwan\Templates\16248-NendangBro.com

c:\windows\system32\c.bat

c:\windows\system32\drivers\01823800.sys

c:\windows\system32\drivers\23517218.sys

c:\windows\system32\drivers\44490575.sys

c:\windows\system32\drivers\55711518.sys

c:\windows\system32\Drivers\ati2hrxx.sys

c:\windows\system32\Drivers\ati3wlxx.sys

c:\windows\system32\Drivers\ati6mpxx.sys

c:\windows\system32\Drivers\ati7cxxx.sys

c:\windows\system32\Drivers\ati8hoxx.sys

c:\windows\system32\Drivers\ati8krxx.sys

c:\windows\system32\mmuiq.dll

c:\windows\Tasks\A893E0F8906894EC.job

c:\windows\Tasks\At1.job

c:\windows\Tasks\At2.job

.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))

.

c:\-1138931453\

c:\windows\system32\c.bat

c:\windows\system32\drivers\01823800.sys

c:\windows\system32\drivers\23517218.sys

c:\windows\system32\drivers\44490575.sys

c:\windows\system32\drivers\55711518.sys

c:\windows\Tasks\A893E0F8906894EC.job

c:\windows\Tasks\At1.job

c:\windows\Tasks\At2.job

.

((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))

.

-------\Legacy_DHFIECAS

-------\Legacy_IS-G8L4SDRV

-------\Legacy_IS-JFNC0DRV

-------\Legacy_IS-K425GDRV

-------\Service_ati2hrxx

-------\Service_ati3wlxx

-------\Service_ati6mpxx

-------\Service_ati7cxxx

-------\Service_ati8hoxx

-------\Service_ati8krxx

-------\Service_dhfiecas

-------\Service_is-561OMdrv

-------\Service_is-G8L4Sdrv

-------\Service_is-JFNC0drv

-------\Service_is-K425Gdrv

((((((((((((((((((((((((( Files Created from 2009-02-14 to 2009-03-14 )))))))))))))))))))))))))))))))

.

2009-03-14 14:08 . 2008-11-07 00:37 3,596,288 --a------ c:\windows\system32\qt-dx331.dll

2009-03-14 14:08 . 2008-11-07 00:33 684,032 --a------ c:\windows\system32\divx.dll

2009-03-14 14:08 . 2008-12-11 08:33 86,016 --a------ c:\windows\system32\dpl100.dll

2009-03-13 15:06 . 2009-03-13 15:06 2,560 --a------ c:\windows\_MSRSTRT.EXE

2009-03-12 22:48 . 2009-03-12 22:49 <DIR> d-------- c:\program files\ThreatExpert Memory Scanner

2009-03-12 20:04 . 2009-03-12 20:04 <DIR> d-------- c:\program files\Common Files\Download Manager

2009-03-11 01:23 . 2008-09-17 03:23 168,448 --a------ c:\windows\system32\unrar.dll

2009-03-11 01:22 . 2009-03-14 14:08 <DIR> d-------- c:\program files\K-Lite Codec Pack

2009-03-11 01:22 . 2008-09-25 02:41 839,680 --a------ c:\windows\system32\lameACM.acm

2009-03-11 01:22 . 2008-12-08 02:08 795,648 --a------ c:\windows\system32\xvidcore.dll

2009-03-11 01:22 . 2004-01-26 00:18 217,088 --a------ c:\windows\system32\yv12vfw.dll

2009-03-11 01:22 . 2008-12-08 02:08 130,048 --a------ c:\windows\system32\xvidvfw.dll

2009-03-11 01:22 . 2007-09-21 08:52 118,784 --a------ c:\windows\system32\ac3acm.acm

2009-03-11 01:22 . 2009-02-10 02:56 67,584 --a------ c:\windows\system32\ff_vfw.dll

2009-03-11 01:22 . 2007-07-11 00:10 547 --a------ c:\windows\system32\ff_vfw.dll.manifest

2009-03-11 01:22 . 2008-10-03 20:30 414 --a------ c:\windows\system32\lame_acm.xml

2009-03-10 01:06 . 2009-03-10 01:06 <DIR> d-------- c:\windows\Curse of the Pharaoh Napoleons Secret

2009-03-10 01:06 . 2009-03-10 01:06 <DIR> d-------- c:\program files\Curse of the Pharaoh Napoleons Secret

2009-03-09 17:08 . 2009-03-09 17:10 <DIR> d-------- C:\OutputFolder

2009-03-09 17:04 . 2009-03-09 17:04 <DIR> d-------- c:\program files\FLV to AVI MPEG WMV 3GP MP4 iPod Converter

2009-03-05 00:47 . 2009-03-05 00:55 <DIR> d-------- C:\Mp3 Output

2009-03-05 00:11 . 2009-03-05 00:11 <DIR> d-------- c:\program files\Drewbuzz Radio

2009-03-03 20:55 . 2002-06-24 12:30 45,568 -ra------ c:\windows\system32\drivers\DLKRTL.SYS

2009-03-01 21:55 . 2009-03-01 21:55 <DIR> d-------- c:\windows\Youda Farmer

2009-03-01 21:55 . 2009-03-01 21:55 <DIR> d-------- c:\program files\Youda Farmer

2009-03-01 21:55 . 2009-03-01 21:55 <DIR> d-------- c:\documents and settings\Shahril Izwan\Application Data\YoudaGames

2009-02-27 23:22 . 2009-02-27 23:22 <DIR> d-------- c:\windows\Ice Blast

2009-02-27 23:22 . 2009-02-27 23:22 <DIR> d-------- c:\program files\Ice Blast

2009-02-23 21:20 . 2009-02-23 21:20 <DIR> d-------- c:\windows\Twinkle Toes Skating

2009-02-23 16:32 . 2009-02-23 16:32 0 -rahs---- C:\khq

2009-02-19 22:14 . 2009-02-19 22:14 <DIR> d-------- c:\program files\Malwarebytes' Anti-Malware

2009-02-19 22:14 . 2009-02-19 22:14 <DIR> d-------- c:\documents and settings\Shahril Izwan\Application Data\Malwarebytes

2009-02-19 22:14 . 2009-02-19 22:14 <DIR> d-------- c:\documents and settings\All Users\Application Data\Malwarebytes

2009-02-19 22:14 . 2009-02-11 10:19 38,496 --a------ c:\windows\system32\drivers\mbamswissarmy.sys

2009-02-19 22:14 . 2009-02-11 10:19 15,504 --a------ c:\windows\system32\drivers\mbam.sys

2009-02-19 22:04 . 2009-02-19 22:04 <DIR> d--h----- c:\windows\PIF

2009-02-19 20:41 . 2009-02-19 20:41 244 --ah----- C:\sqmnoopt05.sqm

2009-02-19 20:41 . 2009-02-19 20:41 232 --ah----- C:\sqmdata05.sqm

2009-02-19 20:39 . 2009-02-19 20:39 244 --ah----- C:\sqmnoopt04.sqm

2009-02-19 20:39 . 2009-02-19 20:39 232 --ah----- C:\sqmdata04.sqm

2009-02-19 20:35 . 2009-02-19 20:35 244 --ah----- C:\sqmnoopt03.sqm

2009-02-19 20:35 . 2009-02-19 20:35 232 --ah----- C:\sqmdata03.sqm

2009-02-19 20:33 . 2009-02-19 20:33 <DIR> d-------- c:\windows\system32\config\systemprofile\Application Data\Yahoo!

2009-02-19 20:33 . 2009-02-19 21:19 <DIR> d-------- c:\windows\system32\config\systemprofile\Application Data\MEGAUPLOADTOOLBAR

2009-02-19 16:34 . 2009-02-19 16:42 <DIR> d-------- c:\documents and settings\Shahril Izwan\eee

2009-02-19 16:33 . 2009-02-19 22:25 2 --a------ C:\-1138931453

2009-02-19 16:31 . 2009-02-19 16:31 351,275 --a------ c:\windows\system32\rtcshares.exe

2009-02-19 16:30 . 2009-02-19 16:31 45,984 --a------ c:\windows\system32\cardvr.exe

2009-02-18 21:44 . 2009-02-18 21:44 <DIR> d-------- c:\program files\iTunes

2009-02-18 21:44 . 2009-02-18 21:44 <DIR> d-------- c:\program files\iPod

2009-02-18 21:44 . 2009-02-18 21:44 <DIR> d-------- c:\documents and settings\All Users\Application Data\{3276BE95_AF08_429F_A64F_CA64CB79BCF6}

2009-02-18 20:58 . 2009-02-11 00:05 952,832 --a------ c:\windows\system32\javac.exe

.

(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))

.

2009-03-14 12:25 15,126,812 --sha-w c:\windows\system32\drivers\fidbox.idx

2009-03-14 12:25 1,290,373,152 --sha-w c:\windows\system32\drivers\fidbox.dat

2009-03-14 12:18 --------- d-----w c:\documents and settings\Shahril Izwan\Application Data\uTorrent

2009-03-14 06:05 --------- d-----w c:\program files\DivX

2009-03-14 05:51 --------- d-----w c:\documents and settings\Shahril Izwan\Application Data\mIRC

2009-03-14 05:13 --------- d-----w c:\program files\mIRC

2009-03-14 01:42 --------- d-----w c:\program files\uTorrent

2009-03-13 15:14 --------- d---a-w c:\documents and settings\All Users\Application Data\TEMP

2009-03-13 03:09 --------- d-----w c:\documents and settings\All Users\Application Data\avg8

2009-03-10 01:00 --------- d-----w c:\documents and settings\Shahril Izwan\Application Data\Vso

2009-03-09 07:01 --------- d-----w c:\documents and settings\Shahril Izwan\Application Data\MyPhoneExplorer

2009-02-27 15:18 --------- d-----w c:\program files\Wonderland Online

2009-02-26 09:17 --------- d-----w c:\documents and settings\Shahril Izwan\Application Data\MegauploadToolbar

2009-02-18 13:44 --------- d-----w c:\program files\Common Files\Apple

2009-02-18 13:09 --------- d-----w c:\documents and settings\All Users\Application Data\Apple Computer

2009-02-18 13:01 --------- d-----w c:\program files\QuickTime

2009-02-06 10:46 --------- d-----w c:\program files\CCleaner

2009-01-27 03:39 --------- d-----w c:\program files\Bonjour

2009-01-25 11:12 --------- d-----w c:\program files\Fitness Dash

2009-01-25 11:12 --------- d-----w c:\documents and settings\Shahril Izwan\Application Data\PlayFirst

2009-01-25 11:12 --------- d-----w c:\documents and settings\All Users\Application Data\PlayFirst

2009-01-16 16:53 --------- d-----w c:\program files\Winamp

2009-01-15 16:14 325,128 ----a-w c:\windows\system32\drivers\avgldx86.sys

2009-01-15 15:17 --------- d-----w c:\program files\Magic Encyclopedia First Story

2008-03-06 12:00 47,360 ----a-w c:\documents and settings\Shahril Izwan\Application Data\pcouffin.sys

2009-01-01 05:17 67,688 ----a-w c:\program files\mozilla firefox\components\jar50.dll

2009-01-01 05:17 54,368 ----a-w c:\program files\mozilla firefox\components\jsd3250.dll

2009-01-01 05:17 34,944 ----a-w c:\program files\mozilla firefox\components\myspell.dll

2009-01-01 05:17 46,712 ----a-w c:\program files\mozilla firefox\components\spellchk.dll

2009-01-01 05:17 172,136 ----a-w c:\program files\mozilla firefox\components\xpinstal.dll

2004-08-04 07:56 1,392,671 --sh--r c:\windows\system32\msvbvm60.dll

.

((((((((((((((((((((((((((((( SnapShot@2009-03-13_20.01.41.34 )))))))))))))))))))))))))))))))))))))))))

.

+ 2001-06-22 23:31:20 278,528 ----a-w c:\windows\system32\pncrt.dll

+ 1998-03-26 02:57:34 6,656 ----a-w c:\windows\system32\pndx5016.dll

+ 1998-05-12 18:36:42 5,632 ----a-w c:\windows\system32\pndx5032.dll

+ 2008-09-10 19:56:28 185,920 ----a-w c:\windows\system32\rmoc3260.dll

+ 2009-03-14 12:26:53 16,384 ----atw c:\windows\temp\Perflib_Perfdata_5f0.dat

.

((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))

.

.

*Note* empty entries & legit default entries are not shown

REGEDIT4

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]

"ctfmon.exe"="c:\windows\system32\ctfmon.exe" [2004-08-04 15360]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]

"GBB36X Configure"="c:\windows\System32\JMRaidTool.exe" [2006-06-02 385024]

"EasyTuneV"="c:\program files\Gigabyte\ET5\GUI.exe" [2004-06-14 200704]

"NvCplDaemon"="c:\windows\System32\NvCpl.dll" [2007-09-06 8486912]

"NvMediaCenter"="c:\windows\System32\NvMcTray.dll" [2007-09-06 81920]

"CoolSwitch"="c:\windows\System32\taskswitch.exe" [2002-03-19 45632]

"NeroFilterCheck"="c:\program files\Common Files\Ahead\Lib\NeroCheck.exe" [2007-03-09 153136]

"HP Software Update"="c:\program files\HP\HP Software Update\HPWuSchd2.exe" [2004-02-12 49152]

"YSearchProtection"="c:\program files\Yahoo!\Search Protection\SearchProtection.exe" [2008-10-07 111856]

"HP Component Manager"="c:\program files\HP\hpcoretech\hpcmpmgr.exe" [2004-05-12 241664]

"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2008-01-11 39792]

"WinampAgent"="c:\program files\Winamp\winampa.exe" [2008-07-09 36352]

"SunJavaUpdateSched"="c:\program files\Java\jre6\bin\jusched.exe" [2008-11-10 136600]

"AVG8_TRAY"="c:\progra~1\AVG\AVG8\avgtray.exe" [2009-01-09 1601304]

"PC Suite for Smartphones"="c:\program files\Sony Ericsson\Mobile4\Application Launcher\Application Launcher.exe" [2007-12-25 548864]

"QuickTime Task"="c:\program files\QuickTime\qttask.exe" [2009-01-05 413696]

"AppleSyncNotifier"="c:\program files\Common Files\Apple\Mobile Device Support\bin\AppleSyncNotifier.exe" [2008-11-07 111936]

"iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2009-01-06 290088]

"Malwarebytes' Anti-Malware"="c:\program files\Malwarebytes' Anti-Malware\mbamgui.exe" [2009-02-11 399504]

"SkyTel"="SkyTel.EXE" [2006-05-16 c:\windows\SkyTel.exe]

"RTHDCPL"="RTHDCPL.EXE" [2006-05-27 c:\windows\RTHDCPL.EXE]

"Tweak UI"="TWEAKUI.CPL" [2000-06-18 c:\windows\system32\TWEAKUI.CPL]

"nwiz"="nwiz.exe" [2007-09-06 c:\windows\system32\nwiz.exe]

"Logitech Hardware Abstraction Layer"="KHALMNPR.EXE" [2008-02-29 c:\windows\KHALMNPR.Exe]

"Kernel and Hardware Abstraction Layer"="KHALMNPR.EXE" [2008-02-29 c:\windows\KHALMNPR.Exe]

[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]

"msnmsgr"="c:\program files\MSN Messenger\msnmsgr.exe" [2007-01-19 5674352]

c:\documents and settings\Shahril Izwan\Start Menu\Programs\Startup\

uTorrent Turbo Booster.lnk - c:\program files\uTorrent Turbo Booster\uTorrent Turbo Booster.exe [2008-08-25 371712]

c:\documents and settings\All Users\Start Menu\Programs\Startup\

Adobe Gamma Loader.lnk - c:\program files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe [2008-01-25 113664]

DSLMON.lnk - c:\program files\D-Link\D-Link DSL-200I USB ADSL Modem\dslmon.exe [2007-10-16 917601]

HP Digital Imaging Monitor.lnk - c:\program files\HP\Digital Imaging\bin\hpqtra08.exe [2004-05-28 241664]

HP Image Zone Fast Start.lnk - c:\program files\HP\Digital Imaging\bin\hpqthb08.exe [2004-05-28 53248]

Logitech Desktop Messenger.lnk - c:\program files\Logitech\Desktop Messenger\8876480\Program\LogitechDesktopMessenger.exe [2007-09-28 67128]

Logitech SetPoint.lnk - c:\program files\Logitech\SetPoint\SetPoint.exe [2008-08-08 805392]

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\explorer]

"ForceClassicControlPanel"= 1 (0x1)

"NoSMConfigurePrograms"= 1 (0x1)

[HKEY_CURRENT_USER\software\microsoft\windows nt\currentversion\winlogon]

"Shell"="Explorer.exe, c:\program files\Microsoft Office\WINWORD.EXE"

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\LBTWlgn]

2008-05-02 02:42 72208 c:\program files\Common Files\Logitech\Bluetooth\LBTWLgn.dll

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\avgrsstarter]

2009-01-09 01:15 10520 c:\windows\system32\avgrsstx.dll

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Wdf01000.sys]

@="Driver"

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WdfLoadGroup]

@=""

[HKEY_LOCAL_MACHINE\software\microsoft\security center]

"AntiVirusDisableNotify"=dword:00000001

"UpdatesDisableNotify"=dword:00000001

"AntiVirusOverride"=dword:00000001

"FirewallOverride"=dword:00000001

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]

"%windir%\\system32\\sessmgr.exe"=

"c:\\Program Files\\uTorrent\\uTorrent.exe"=

"c:\\Program Files\\MSN Messenger\\msnmsgr.exe"=

"c:\\Program Files\\MSN Messenger\\livecall.exe"=

"c:\\Program Files\\Yahoo!\\Messenger\\YahooMessenger.exe"=

"c:\\Program Files\\Logitech\\Desktop Messenger\\8876480\\Program\\LogitechDesktopMessenger.exe"=

"c:\\Program Files\\Sports Interactive\\Football Manager 2008\\fm.exe"=

"c:\\Program Files\\mIRC\\mirc.exe"=

"%windir%\\Network Diagnostic\\xpnetdiag.exe"=

"c:\\Program Files\\Mozilla Firefox\\firefox.exe"=

"c:\\Program Files\\Java\\jre1.6.0_07\\bin\\javaw.exe"=

"c:\\Program Files\\AVG\\AVG8\\avgam.exe"=

"c:\\Program Files\\AVG\\AVG8\\avgemc.exe"=

"c:\\Program Files\\AVG\\AVG8\\avgupd.exe"=

"c:\\Program Files\\AVG\\AVG8\\avgnsx.exe"=

"c:\\Program Files\\Sony Ericsson\\Sony Ericsson Media Manager\\MediaManager.exe"=

"c:\\Program Files\\Intuwave\\Shared\\mRouterRuntime\\mRouterRuntime.exe"=

"c:\\Program Files\\MyPhoneExplorer\\MyPhoneExplorer.exe"=

"c:\\Program Files\\Microsoft Visual Studio\\Common\\Tools\\VS-Ent98\\Vanalyzr\\VARPC.EXE"=

"f:\\Ijud Punyer\\Visual Basic\\Applications\\Ratio\\RatioMaster.exe"=

"c:\\Program Files\\Bonjour\\mDNSResponder.exe"=

"c:\\Program Files\\iTunes\\iTunes.exe"=

"c:\\Program Files\\Drewbuzz Radio\\Drewbuzz Radio.exe"=

R0 AvgRkx86;avgrkx86.sys;c:\windows\system32\drivers\avgrkx86.sys [2008-12-07 12552]

R1 AvgLdx86;AVG AVI Loader Driver x86;c:\windows\system32\drivers\avgldx86.sys [2008-12-07 325128]

R1 AvgTdiX;AVG8 Network Redirector;c:\windows\system32\drivers\avgtdix.sys [2008-12-07 107272]

R2 avg8emc;AVG8 E-mail Scanner;c:\progra~1\AVG\AVG8\avgemc.exe [2009-01-09 903960]

R2 avg8wd;AVG8 WatchDog;c:\progra~1\AVG\AVG8\avgwdsvc.exe [2009-01-09 298264]

R2 MBAMService;MBAMService;c:\program files\Malwarebytes' Anti-Malware\mbamservice.exe [2009-02-19 179856]

R3 DFE528TX;D-Link DFE-528TX PCI Adapter;c:\windows\system32\drivers\DLKRTL.SYS [2009-03-03 45568]

R3 MBAMProtector;MBAMProtector;c:\windows\system32\drivers\mbam.sys [2009-02-19 15504]

S3 ggflt;SEMC USB Flash Driver Filter;c:\windows\system32\drivers\ggflt.sys [2008-12-09 10976]

S3 s816bus;Sony Ericsson Device 816 driver (WDM);c:\windows\system32\drivers\s816bus.sys [2008-06-06 81832]

.

Contents of the 'Scheduled Tasks' folder

2009-03-13 c:\windows\Tasks\Ad-Aware Update (Daily).job

- c:\program files\Lavasoft\Ad-Aware\Ad-AwareAdmin.exe []

2009-03-10 c:\windows\Tasks\AppleSoftwareUpdate.job

- c:\program files\Apple Software Update\SoftwareUpdate.exe [2008-07-30 12:34]

2009-03-13 c:\windows\Tasks\WebReg 20080523230406.job

- c:\program files\HP\Digital Imaging\bin\hpqwrg.exe [2004-05-28 22:47]

.

- - - - ORPHANS REMOVED - - - -

SafeBoot-ati2hrxx.sys

SafeBoot-ati3wlxx.sys

SafeBoot-ati6mpxx.sys

SafeBoot-ati7cxxx.sys

SafeBoot-ati8hoxx.sys

SafeBoot-ati8krxx.sys

.

------- Supplementary Scan -------

.

uStart Page = hxxp://www.google.com/

uLocal Page = \blank.htm

mStart Page = hxxp://www.google.com/

uInternet Connection Wizard,ShellNext = iexplore

uInternet Settings,ProxyOverride = local

uSearchURL,(Default) = hxxp://us.rd.yahoo.com/customize/ycomp/defaults/su/*http://www.yahoo.com

IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~3\OFFICE11\EXCEL.EXE/3000

IE: E&xportar para o Microsoft Excel - c:\progra~1\MICROS~3\Office10\EXCEL.EXE/3000

Handler: bwfile-8876480 - {9462A756-7B47-47BC-8C80-C34B9B80B32B} - c:\program files\Logitech\Desktop Messenger\8876480\Program\GAPlugProtocol-8876480.dll

DPF: DirectAnimation Java Classes - file://c:\windows\Java\classes\dajava.cab

DPF: Microsoft XML Parser for Java - file://c:\windows\Java\classes\xmldso.cab

FF - ProfilePath - c:\documents and settings\Shahril Izwan\Application Data\Mozilla\Firefox\Profiles\9wp3u9p9.default\

FF - component: c:\program files\AVG\AVG8\Firefox\components\avgssff.dll

FF - component: c:\program files\Mozilla Firefox\components\xpinstal.dll

.

**************************************************************************

catchme 0.3.1367 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net

Rootkit scan 2009-03-14 20:27:04

Windows 5.1.2600 Service Pack 2 NTFS

scanning hidden processes ...

scanning hidden autostart entries ...

scanning hidden files ...

scan completed successfully

hidden files: 0

**************************************************************************

.

--------------------- DLLs Loaded Under Running Processes ---------------------

- - - - - - - > 'winlogon.exe'(612)

c:\program files\common files\logitech\bluetooth\LBTWlgn.dll

c:\program files\common files\logitech\bluetooth\LBTServ.dll

.

------------------------ Other Running Processes ------------------------

.

c:\program files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe

c:\program files\Bonjour\mDNSResponder.exe

c:\program files\Java\jre6\bin\jqs.exe

c:\program files\Common Files\Microsoft Shared\VS7Debug\mdm.exe

c:\windows\system32\nvsvc32.exe

c:\progra~1\AVG\AVG8\avgam.exe

c:\program files\AVG\AVG8\avgrsx.exe

c:\progra~1\AVG\AVG8\avgnsx.exe

c:\program files\AVG\AVG8\avgcsrvx.exe

c:\windows\system32\rundll32.exe

c:\program files\Common Files\Logishrd\KHAL2\KHALMNPR.exe

c:\program files\iPod\bin\iPodService.exe

c:\program files\HP\Digital Imaging\bin\hpqgalry.exe

.

**************************************************************************

.

Completion time: 2009-03-14 20:30:40 - machine was rebooted

ComboFix-quarantined-files.txt 2009-03-14 12:30:23

ComboFix2.txt 2009-03-13 12:02:58

Pre-Run: 10,367,143,936 bytes free

Post-Run: 10,368,352,256 bytes free

319 --- E O F --- 2008-07-09 01:05:41

Link to post
Share on other sites

about the 017 servers, no I didn't set it.

Here's HJT's log:

Logfile of Trend Micro HijackThis v2.0.2

Scan saved at 9:44:48 PM, on 3/14/2009

Platform: Windows XP SP2 (WinNT 5.01.2600)

MSIE: Internet Explorer v7.00 (7.00.6000.16674)

Boot mode: Normal

Running processes:

C:\WINDOWS\System32\smss.exe

C:\WINDOWS\system32\winlogon.exe

C:\WINDOWS\system32\services.exe

C:\WINDOWS\system32\lsass.exe

C:\WINDOWS\system32\svchost.exe

C:\WINDOWS\System32\svchost.exe

C:\WINDOWS\system32\spoolsv.exe

C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe

C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe

C:\Program Files\Bonjour\mDNSResponder.exe

C:\Program Files\Java\jre6\bin\jqs.exe

C:\Program Files\Common Files\Microsoft Shared\VS7Debug\mdm.exe

C:\WINDOWS\System32\nvsvc32.exe

C:\WINDOWS\System32\svchost.exe

C:\PROGRA~1\AVG\AVG8\avgemc.exe

C:\PROGRA~1\AVG\AVG8\avgam.exe

C:\PROGRA~1\AVG\AVG8\avgrsx.exe

C:\PROGRA~1\AVG\AVG8\avgnsx.exe

C:\Program Files\AVG\AVG8\avgcsrvx.exe

C:\WINDOWS\RTHDCPL.EXE

C:\WINDOWS\system32\RUNDLL32.EXE

C:\WINDOWS\System32\taskswitch.exe

C:\Program Files\HP\HP Software Update\HPWuSchd2.exe

C:\Program Files\Yahoo!\Search Protection\SearchProtection.exe

C:\Program Files\HP\hpcoretech\hpcmpmgr.exe

C:\Program Files\Winamp\winampa.exe

C:\Program Files\Java\jre6\bin\jusched.exe

C:\PROGRA~1\AVG\AVG8\avgtray.exe

C:\Program Files\iTunes\iTunesHelper.exe

C:\WINDOWS\system32\ctfmon.exe

C:\Program Files\D-Link\D-Link DSL-200I USB ADSL Modem\dslmon.exe

C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe

C:\Program Files\Logitech\Desktop Messenger\8876480\Program\LogitechDesktopMessenger.exe

C:\Program Files\Logitech\SetPoint\SetPoint.exe

C:\Program Files\uTorrent Turbo Booster\uTorrent Turbo Booster.exe

C:\Program Files\Common Files\Logishrd\KHAL2\KHALMNPR.EXE

C:\Program Files\iPod\bin\iPodService.exe

C:\Program Files\HP\Digital Imaging\bin\hpqgalry.exe

C:\WINDOWS\system32\notepad.exe

C:\WINDOWS\explorer.exe

C:\Program Files\Malwarebytes' Anti-Malware\mbam.exe

C:\Program Files\internet explorer\iexplore.exe

C:\Program Files\Malwarebytes' Anti-Malware\mbamgui.exe

C:\WINDOWS\system32\NOTEPAD.EXE

F:\Ijud Punyer\Visual Basic\Applications\HijackThis.exe

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896

R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://us.rd.yahoo.com/customize/ycomp/def...//www.yahoo.com

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page = \blank.htm

R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = local

R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\PROGRA~1\Yahoo!\Companion\Installs\cpn2\yt.dll

O2 - BHO: &Yahoo! Toolbar Helper - {02478D38-C3F9-4efb-9B51-7695ECA05670} - C:\PROGRA~1\Yahoo!\Companion\Installs\cpn2\yt.dll

O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll

O2 - BHO: WormRadar.com IESiteBlocker.NavFilter - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files\AVG\AVG8\avgssie.dll

O2 - BHO: Megaupload Toolbar - {4E7BD74F-2B8D-469E-CCB0-B130EEDBE97C} - C:\PROGRA~1\MEGAUP~2\MEGAUP~1.DLL

O2 - BHO: Yahoo! IE Services Button - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\Program Files\Yahoo!\Common\yiesrvc.dll

O2 - BHO: Java Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre6\bin\ssv.dll

O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)

O2 - BHO: Java Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll

O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll

O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\PROGRA~1\Yahoo!\Companion\Installs\cpn2\yt.dll

O3 - Toolbar: Megaupload Toolbar - {4E7BD74F-2B8D-469E-CCB0-B130EEDBE97C} - C:\PROGRA~1\MEGAUP~2\MEGAUP~1.DLL

O4 - HKLM\..\Run: [skyTel] SkyTel.EXE

O4 - HKLM\..\Run: [GBB36X Configure] C:\WINDOWS\System32\JMRaidTool.exe boot

O4 - HKLM\..\Run: [RTHDCPL] RTHDCPL.EXE

O4 - HKLM\..\Run: [Tweak UI] RUNDLL32.EXE TWEAKUI.CPL,TweakMeUp

O4 - HKLM\..\Run: [EasyTuneV] C:\Program Files\Gigabyte\ET5\GUI.exe

O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\System32\NvCpl.dll,NvStartup

O4 - HKLM\..\Run: [nwiz] nwiz.exe /install

O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\System32\NvMcTray.dll,NvTaskbarInit

O4 - HKLM\..\Run: [CoolSwitch] C:\WINDOWS\System32\taskswitch.exe

O4 - HKLM\..\Run: [NeroFilterCheck] C:\Program Files\Common Files\Ahead\Lib\NeroCheck.exe

O4 - HKLM\..\Run: [Logitech Hardware Abstraction Layer] KHALMNPR.EXE

O4 - HKLM\..\Run: [HP Software Update] "C:\Program Files\HP\HP Software Update\HPWuSchd2.exe"

O4 - HKLM\..\Run: [YSearchProtection] "C:\Program Files\Yahoo!\Search Protection\SearchProtection.exe"

O4 - HKLM\..\Run: [HP Component Manager] "C:\Program Files\HP\hpcoretech\hpcmpmgr.exe"

O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"

O4 - HKLM\..\Run: [Kernel and Hardware Abstraction Layer] KHALMNPR.EXE

O4 - HKLM\..\Run: [WinampAgent] "C:\Program Files\Winamp\winampa.exe"

O4 - HKLM\..\Run: [sunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe"

O4 - HKLM\..\Run: [AVG8_TRAY] C:\PROGRA~1\AVG\AVG8\avgtray.exe

O4 - HKLM\..\Run: [PC Suite for Smartphones] "C:\Program Files\Sony Ericsson\Mobile4\Application Launcher\Application Launcher.exe" /startoptions

O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime

O4 - HKLM\..\Run: [AppleSyncNotifier] C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleSyncNotifier.exe

O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"

O4 - HKLM\..\Run: [Malwarebytes' Anti-Malware] "C:\Program Files\Malwarebytes' Anti-Malware\mbamgui.exe" /starttray

O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe

O4 - HKUS\S-1-5-18\..\Run: [msnmsgr] "C:\Program Files\MSN Messenger\msnmsgr.exe" /background (User 'SYSTEM')

O4 - HKUS\.DEFAULT\..\Run: [msnmsgr] "C:\Program Files\MSN Messenger\msnmsgr.exe" /background (User 'Default user')

O4 - Startup: uTorrent Turbo Booster.lnk = C:\Program Files\uTorrent Turbo Booster\uTorrent Turbo Booster.exe

O4 - Global Startup: Adobe Gamma Loader.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe

O4 - Global Startup: DSLMON.lnk = ?

O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe

O4 - Global Startup: HP Image Zone Fast Start.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqthb08.exe

O4 - Global Startup: Logitech Desktop Messenger.lnk = C:\Program Files\Logitech\Desktop Messenger\8876480\Program\LogitechDesktopMessenger.exe

O4 - Global Startup: Logitech SetPoint.lnk = C:\Program Files\Logitech\SetPoint\SetPoint.exe

O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~3\OFFICE11\EXCEL.EXE/3000

O8 - Extra context menu item: E&xportar para o Microsoft Excel - res://C:\PROGRA~1\MICROS~3\Office10\EXCEL.EXE/3000

O9 - Extra button: Yahoo! Services - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\Program Files\Yahoo!\Common\yiesrvc.dll

O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~3\OFFICE11\REFIEBAR.DLL

O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe

O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe

O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe

O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe

O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (Installation Support) - C:\Program Files\Yahoo!\Common\Yinsthelper.dll

O17 - HKLM\System\CCS\Services\Tcpip\..\{4833954F-1E33-488A-8EE5-D3CE72394F1D}: NameServer = 202.188.0.133 202.188.1.5

O17 - HKLM\System\CS3\Services\Tcpip\..\{4833954F-1E33-488A-8EE5-D3CE72394F1D}: NameServer = 202.188.0.133 202.188.1.5

O18 - Protocol: bwfile-8876480 - {9462A756-7B47-47BC-8C80-C34B9B80B32B} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\GAPlugProtocol-8876480.dll

O18 - Protocol: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files\AVG\AVG8\avgpp.dll

O20 - Winlogon Notify: avgrsstarter - C:\WINDOWS\SYSTEM32\avgrsstx.dll

O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe

O23 - Service: AVG8 E-mail Scanner (avg8emc) - AVG Technologies CZ, s.r.o. - C:\PROGRA~1\AVG\AVG8\avgemc.exe

O23 - Service: AVG8 WatchDog (avg8wd) - AVG Technologies CZ, s.r.o. - C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe

O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe

O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1150\Intel 32\IDriverT.exe

O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe

O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe

O23 - Service: Logitech Bluetooth Service (LBTServ) - Logitech, Inc. - C:\Program Files\Common Files\Logitech\Bluetooth\LBTServ.exe

O23 - Service: Macromedia Licensing Service - Unknown owner - C:\Program Files\Common Files\Macromedia Shared\Service\Macromedia Licensing.exe

O23 - Service: MBAMService - Malwarebytes Corporation - C:\Program Files\Malwarebytes' Anti-Malware\mbamservice.exe

O23 - Service: NBService - Nero AG - C:\Program Files\Nero\Nero 7\Nero BackItUp\NBService.exe

O23 - Service: NMIndexingService - Nero AG - C:\Program Files\Common Files\Ahead\Lib\NMIndexingService.exe

O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\System32\nvsvc32.exe

O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe

--

End of file - 10645 bytes

Link to post
Share on other sites

Sorry, my bad.

Now, I have uninstall utorrent software.

Logfile of Trend Micro HijackThis v2.0.2

Scan saved at 3:54:53 PM, on 3/16/2009

Platform: Windows XP SP2 (WinNT 5.01.2600)

MSIE: Internet Explorer v7.00 (7.00.6000.16674)

Boot mode: Normal

Running processes:

C:\WINDOWS\System32\smss.exe

C:\WINDOWS\system32\winlogon.exe

C:\WINDOWS\system32\services.exe

C:\WINDOWS\system32\lsass.exe

C:\WINDOWS\system32\svchost.exe

C:\WINDOWS\System32\svchost.exe

C:\WINDOWS\system32\spoolsv.exe

C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe

C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe

C:\WINDOWS\Explorer.EXE

C:\Program Files\Bonjour\mDNSResponder.exe

C:\Program Files\Java\jre6\bin\jqs.exe

C:\Program Files\Malwarebytes' Anti-Malware\mbamservice.exe

C:\Program Files\Common Files\Microsoft Shared\VS7Debug\mdm.exe

C:\WINDOWS\System32\nvsvc32.exe

C:\WINDOWS\System32\svchost.exe

C:\PROGRA~1\AVG\AVG8\avgemc.exe

C:\PROGRA~1\AVG\AVG8\avgam.exe

C:\PROGRA~1\AVG\AVG8\avgrsx.exe

C:\PROGRA~1\AVG\AVG8\avgnsx.exe

C:\Program Files\AVG\AVG8\avgcsrvx.exe

C:\WINDOWS\RTHDCPL.EXE

C:\WINDOWS\system32\RUNDLL32.EXE

C:\WINDOWS\System32\taskswitch.exe

C:\Program Files\HP\HP Software Update\HPWuSchd2.exe

C:\Program Files\Yahoo!\Search Protection\SearchProtection.exe

C:\Program Files\HP\hpcoretech\hpcmpmgr.exe

C:\Program Files\Winamp\winampa.exe

C:\Program Files\Java\jre6\bin\jusched.exe

C:\PROGRA~1\AVG\AVG8\avgtray.exe

C:\Program Files\iTunes\iTunesHelper.exe

C:\WINDOWS\system32\ctfmon.exe

C:\Program Files\D-Link\D-Link DSL-200I USB ADSL Modem\dslmon.exe

C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe

C:\Program Files\Logitech\Desktop Messenger\8876480\Program\LogitechDesktopMessenger.exe

C:\Program Files\Logitech\SetPoint\SetPoint.exe

C:\Program Files\Common Files\Logishrd\KHAL2\KHALMNPR.EXE

C:\Program Files\iPod\bin\iPodService.exe

C:\Program Files\HP\Digital Imaging\bin\hpqgalry.exe

C:\Program Files\internet explorer\iexplore.exe

C:\Program Files\MSN Messenger\usnsvc.exe

F:\Ijud Punyer\Visual Basic\Applications\HijackThis.exe

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896

R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://us.rd.yahoo.com/customize/ycomp/def...//www.yahoo.com

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page = \blank.htm

R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = local

R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\PROGRA~1\Yahoo!\Companion\Installs\cpn2\yt.dll

O2 - BHO: &Yahoo! Toolbar Helper - {02478D38-C3F9-4efb-9B51-7695ECA05670} - C:\PROGRA~1\Yahoo!\Companion\Installs\cpn2\yt.dll

O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll

O2 - BHO: WormRadar.com IESiteBlocker.NavFilter - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files\AVG\AVG8\avgssie.dll

O2 - BHO: Megaupload Toolbar - {4E7BD74F-2B8D-469E-CCB0-B130EEDBE97C} - C:\PROGRA~1\MEGAUP~2\MEGAUP~1.DLL

O2 - BHO: Yahoo! IE Services Button - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\Program Files\Yahoo!\Common\yiesrvc.dll

O2 - BHO: Java Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre6\bin\ssv.dll

O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)

O2 - BHO: Java Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll

O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll

O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\PROGRA~1\Yahoo!\Companion\Installs\cpn2\yt.dll

O3 - Toolbar: Megaupload Toolbar - {4E7BD74F-2B8D-469E-CCB0-B130EEDBE97C} - C:\PROGRA~1\MEGAUP~2\MEGAUP~1.DLL

O4 - HKLM\..\Run: [skyTel] SkyTel.EXE

O4 - HKLM\..\Run: [GBB36X Configure] C:\WINDOWS\System32\JMRaidTool.exe boot

O4 - HKLM\..\Run: [RTHDCPL] RTHDCPL.EXE

O4 - HKLM\..\Run: [Tweak UI] RUNDLL32.EXE TWEAKUI.CPL,TweakMeUp

O4 - HKLM\..\Run: [EasyTuneV] C:\Program Files\Gigabyte\ET5\GUI.exe

O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\System32\NvCpl.dll,NvStartup

O4 - HKLM\..\Run: [nwiz] nwiz.exe /install

O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\System32\NvMcTray.dll,NvTaskbarInit

O4 - HKLM\..\Run: [CoolSwitch] C:\WINDOWS\System32\taskswitch.exe

O4 - HKLM\..\Run: [NeroFilterCheck] C:\Program Files\Common Files\Ahead\Lib\NeroCheck.exe

O4 - HKLM\..\Run: [Logitech Hardware Abstraction Layer] KHALMNPR.EXE

O4 - HKLM\..\Run: [HP Software Update] "C:\Program Files\HP\HP Software Update\HPWuSchd2.exe"

O4 - HKLM\..\Run: [YSearchProtection] "C:\Program Files\Yahoo!\Search Protection\SearchProtection.exe"

O4 - HKLM\..\Run: [HP Component Manager] "C:\Program Files\HP\hpcoretech\hpcmpmgr.exe"

O4 - HKLM\..\Run: [Kernel and Hardware Abstraction Layer] KHALMNPR.EXE

O4 - HKLM\..\Run: [WinampAgent] "C:\Program Files\Winamp\winampa.exe"

O4 - HKLM\..\Run: [sunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe"

O4 - HKLM\..\Run: [AVG8_TRAY] C:\PROGRA~1\AVG\AVG8\avgtray.exe

O4 - HKLM\..\Run: [PC Suite for Smartphones] "C:\Program Files\Sony Ericsson\Mobile4\Application Launcher\Application Launcher.exe" /startoptions

O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime

O4 - HKLM\..\Run: [AppleSyncNotifier] C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleSyncNotifier.exe

O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"

O4 - HKLM\..\Run: [Malwarebytes' Anti-Malware] "C:\Program Files\Malwarebytes' Anti-Malware\mbamgui.exe" /starttray

O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"

O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe

O4 - HKUS\S-1-5-18\..\Run: [msnmsgr] "C:\Program Files\MSN Messenger\msnmsgr.exe" /background (User 'SYSTEM')

O4 - HKUS\.DEFAULT\..\Run: [msnmsgr] "C:\Program Files\MSN Messenger\msnmsgr.exe" /background (User 'Default user')

O4 - Global Startup: Adobe Gamma Loader.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe

O4 - Global Startup: DSLMON.lnk = ?

O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe

O4 - Global Startup: HP Image Zone Fast Start.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqthb08.exe

O4 - Global Startup: Logitech Desktop Messenger.lnk = C:\Program Files\Logitech\Desktop Messenger\8876480\Program\LogitechDesktopMessenger.exe

O4 - Global Startup: Logitech SetPoint.lnk = C:\Program Files\Logitech\SetPoint\SetPoint.exe

O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~3\OFFICE11\EXCEL.EXE/3000

O8 - Extra context menu item: E&xportar para o Microsoft Excel - res://C:\PROGRA~1\MICROS~3\Office10\EXCEL.EXE/3000

O9 - Extra button: Yahoo! Services - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\Program Files\Yahoo!\Common\yiesrvc.dll

O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~3\OFFICE11\REFIEBAR.DLL

O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe

O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe

O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe

O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe

O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (Installation Support) - C:\Program Files\Yahoo!\Common\Yinsthelper.dll

O17 - HKLM\System\CCS\Services\Tcpip\..\{4833954F-1E33-488A-8EE5-D3CE72394F1D}: NameServer = 202.188.0.133 202.188.1.5

O17 - HKLM\System\CS3\Services\Tcpip\..\{4833954F-1E33-488A-8EE5-D3CE72394F1D}: NameServer = 202.188.0.133 202.188.1.5

O18 - Protocol: bwfile-8876480 - {9462A756-7B47-47BC-8C80-C34B9B80B32B} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\GAPlugProtocol-8876480.dll

O18 - Protocol: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files\AVG\AVG8\avgpp.dll

O20 - Winlogon Notify: avgrsstarter - C:\WINDOWS\SYSTEM32\avgrsstx.dll

O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe

O23 - Service: AVG8 E-mail Scanner (avg8emc) - AVG Technologies CZ, s.r.o. - C:\PROGRA~1\AVG\AVG8\avgemc.exe

O23 - Service: AVG8 WatchDog (avg8wd) - AVG Technologies CZ, s.r.o. - C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe

O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe

O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1150\Intel 32\IDriverT.exe

O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe

O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe

O23 - Service: Logitech Bluetooth Service (LBTServ) - Logitech, Inc. - C:\Program Files\Common Files\Logitech\Bluetooth\LBTServ.exe

O23 - Service: Macromedia Licensing Service - Unknown owner - C:\Program Files\Common Files\Macromedia Shared\Service\Macromedia Licensing.exe

O23 - Service: MBAMService - Malwarebytes Corporation - C:\Program Files\Malwarebytes' Anti-Malware\mbamservice.exe

O23 - Service: NBService - Nero AG - C:\Program Files\Nero\Nero 7\Nero BackItUp\NBService.exe

O23 - Service: NMIndexingService - Nero AG - C:\Program Files\Common Files\Ahead\Lib\NMIndexingService.exe

O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\System32\nvsvc32.exe

O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe

--

End of file - 10603 bytes

Link to post
Share on other sites

  • Root Admin

Please download to your Desktop: Dr.Web CureIt

  • After the file has downloaded, disable your current Anti-Virus and disconnect from the Internet
  • Doubleclick the drweb-cureit.exe file, then click the Start button, then the OK button to perform an Express Scan.
  • This will scan the files currently running in memory and when something is found, click the yes button when it asks you if you want to cure it.
  • Once the short scan has finished, Click on the Complete scan radio button.
  • Then click on the Settings menu on top, the select Change Settings or press the F9 key. You can also change the Language
  • Choose the Scanning tab and I recomend leaving the Heuristic analysis enabled (this can lead to False Positives though)
  • On the File types tab ensure you select All files
  • Click on the Actions tab and set the following:
    • Objects Infected objects = Cure, Incurable objects = Move, Suspicious objects = Report
    • Infected packages Archive = Move, E-mails = Report, Containers = Move
    • Malware Adware = Move, Dialers = Move, Jokes = Move, Riskware = Move, Hacktools = Move
    • Do not change the Rename extension - default is: #??
    • Leave the default save path for Moved files here: %USERPROFILE%\DoctorWeb\Quarantine\
    • Leave prompt on Action checked

    [*]On the Log file tab leave the Log to file checked.

    [*]Leave the log file path alone: %USERPROFILE%\DoctorWeb\CureIt.log

    [*]Log mode = Append

    [*]Encoding = ANSI

    [*]Details Leave Names of file packers and Statistics checked.

    [*]Limit log file size = 2048 KB and leave the check mark on the Maximum log file size.

    [*]On the General tab leave the Scan Priority on High

    [*]Click the Apply button at the bottom, and then the OK button.

    [*]On the right side under the Dr Web Anti-Virus Logo you will see 3 little buttons. Click the left VCR style Start button.

    [*]In this mode it will scan Boot sectors of all disks, All removable media, and all local drives

    [*]The more files and folders you have the longer the scan will take. On large drives it can take hours to complete.

    [*]When the Cure option is selected, an additional context menu will open. Select the necessary action of the program, if the curing fails.

    [*]Click 'Yes to all' if it asks if you want to cure/move the files.

    [*]This will move it to the %USERPROFILE%\DoctorWeb\Quarantine\ folder if it can't be cured. (in this case we need samples)

    [*]After selecting, in the Dr.Web CureIt menu on top, click file and choose save report list

    [*]Save the report to your Desktop. The report will be called DrWeb.csv

    [*]Close Dr.Web Cureit.

    [*]Reboot your computer!! Because it could be possible that files in use will be moved/deleted during reboot.

    [*]After reboot, post the contents of the log from Dr.Web you saved previously to your Desktop in your next reply with a new hijackthis log.

    drweb.jpg

Link to post
Share on other sites

I'm sorry, but it seems that I was unable to download the software somehow. I tried to download it from multiple sites but still no prompt to save it to my desktop. My IE kept saying "page cannot be found" or something like that.

Is it just my browser or the official site itself is having a problem?

Link to post
Share on other sites

Here is the HJT log:

Logfile of Trend Micro HijackThis v2.0.2

Scan saved at 2:46:20 PM, on 3/19/2009

Platform: Windows XP SP2 (WinNT 5.01.2600)

MSIE: Internet Explorer v7.00 (7.00.6000.16674)

Boot mode: Normal

Running processes:

C:\WINDOWS\System32\smss.exe

C:\WINDOWS\system32\winlogon.exe

C:\WINDOWS\system32\services.exe

C:\WINDOWS\system32\lsass.exe

C:\WINDOWS\system32\svchost.exe

C:\WINDOWS\System32\svchost.exe

C:\WINDOWS\system32\spoolsv.exe

C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe

C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe

C:\Program Files\Bonjour\mDNSResponder.exe

C:\Program Files\Java\jre6\bin\jqs.exe

C:\Program Files\Malwarebytes' Anti-Malware\mbamservice.exe

C:\WINDOWS\Explorer.EXE

C:\Program Files\Common Files\Microsoft Shared\VS7Debug\mdm.exe

C:\WINDOWS\System32\nvsvc32.exe

C:\WINDOWS\System32\svchost.exe

C:\PROGRA~1\AVG\AVG8\avgemc.exe

C:\PROGRA~1\AVG\AVG8\avgam.exe

C:\PROGRA~1\AVG\AVG8\avgrsx.exe

C:\PROGRA~1\AVG\AVG8\avgnsx.exe

C:\Program Files\AVG\AVG8\avgcsrvx.exe

C:\WINDOWS\RTHDCPL.EXE

C:\WINDOWS\system32\RUNDLL32.EXE

C:\WINDOWS\System32\taskswitch.exe

C:\Program Files\HP\HP Software Update\HPWuSchd2.exe

C:\Program Files\Yahoo!\Search Protection\SearchProtection.exe

C:\Program Files\HP\hpcoretech\hpcmpmgr.exe

C:\Program Files\Winamp\winampa.exe

C:\Program Files\Java\jre6\bin\jusched.exe

C:\PROGRA~1\AVG\AVG8\avgtray.exe

C:\Program Files\iTunes\iTunesHelper.exe

C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe

C:\WINDOWS\system32\ctfmon.exe

C:\Program Files\D-Link\D-Link DSL-200I USB ADSL Modem\dslmon.exe

C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe

C:\Program Files\Logitech\Desktop Messenger\8876480\Program\LogitechDesktopMessenger.exe

C:\Program Files\Logitech\SetPoint\SetPoint.exe

C:\Program Files\iPod\bin\iPodService.exe

C:\Program Files\Common Files\Logishrd\KHAL2\KHALMNPR.EXE

C:\Program Files\HP\Digital Imaging\bin\hpqgalry.exe

C:\Program Files\AVG\AVG8\avgupd.exe

F:\Ijud Punyer\Visual Basic\Applications\HijackThis.exe

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896

R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://us.rd.yahoo.com/customize/ycomp/def...//www.yahoo.com

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page = \blank.htm

R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = local

R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\PROGRA~1\Yahoo!\Companion\Installs\cpn2\yt.dll

O2 - BHO: &Yahoo! Toolbar Helper - {02478D38-C3F9-4efb-9B51-7695ECA05670} - C:\PROGRA~1\Yahoo!\Companion\Installs\cpn2\yt.dll

O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll

O2 - BHO: WormRadar.com IESiteBlocker.NavFilter - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files\AVG\AVG8\avgssie.dll

O2 - BHO: Megaupload Toolbar - {4E7BD74F-2B8D-469E-CCB0-B130EEDBE97C} - C:\PROGRA~1\MEGAUP~2\MEGAUP~1.DLL

O2 - BHO: Yahoo! IE Services Button - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\Program Files\Yahoo!\Common\yiesrvc.dll

O2 - BHO: Java Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre6\bin\ssv.dll

O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)

O2 - BHO: Java Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll

O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll

O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\PROGRA~1\Yahoo!\Companion\Installs\cpn2\yt.dll

O3 - Toolbar: Megaupload Toolbar - {4E7BD74F-2B8D-469E-CCB0-B130EEDBE97C} - C:\PROGRA~1\MEGAUP~2\MEGAUP~1.DLL

O4 - HKLM\..\Run: [skyTel] SkyTel.EXE

O4 - HKLM\..\Run: [GBB36X Configure] C:\WINDOWS\System32\JMRaidTool.exe boot

O4 - HKLM\..\Run: [RTHDCPL] RTHDCPL.EXE

O4 - HKLM\..\Run: [Tweak UI] RUNDLL32.EXE TWEAKUI.CPL,TweakMeUp

O4 - HKLM\..\Run: [EasyTuneV] C:\Program Files\Gigabyte\ET5\GUI.exe

O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\System32\NvCpl.dll,NvStartup

O4 - HKLM\..\Run: [nwiz] nwiz.exe /install

O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\System32\NvMcTray.dll,NvTaskbarInit

O4 - HKLM\..\Run: [CoolSwitch] C:\WINDOWS\System32\taskswitch.exe

O4 - HKLM\..\Run: [NeroFilterCheck] C:\Program Files\Common Files\Ahead\Lib\NeroCheck.exe

O4 - HKLM\..\Run: [Logitech Hardware Abstraction Layer] KHALMNPR.EXE

O4 - HKLM\..\Run: [HP Software Update] "C:\Program Files\HP\HP Software Update\HPWuSchd2.exe"

O4 - HKLM\..\Run: [YSearchProtection] "C:\Program Files\Yahoo!\Search Protection\SearchProtection.exe"

O4 - HKLM\..\Run: [HP Component Manager] "C:\Program Files\HP\hpcoretech\hpcmpmgr.exe"

O4 - HKLM\..\Run: [Kernel and Hardware Abstraction Layer] KHALMNPR.EXE

O4 - HKLM\..\Run: [WinampAgent] "C:\Program Files\Winamp\winampa.exe"

O4 - HKLM\..\Run: [sunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe"

O4 - HKLM\..\Run: [AVG8_TRAY] C:\PROGRA~1\AVG\AVG8\avgtray.exe

O4 - HKLM\..\Run: [PC Suite for Smartphones] "C:\Program Files\Sony Ericsson\Mobile4\Application Launcher\Application Launcher.exe" /startoptions

O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime

O4 - HKLM\..\Run: [AppleSyncNotifier] C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleSyncNotifier.exe

O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"

O4 - HKLM\..\Run: [Malwarebytes' Anti-Malware] "C:\Program Files\Malwarebytes' Anti-Malware\mbamgui.exe" /starttray

O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"

O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe

O4 - HKUS\S-1-5-18\..\Run: [msnmsgr] "C:\Program Files\MSN Messenger\msnmsgr.exe" /background (User 'SYSTEM')

O4 - HKUS\.DEFAULT\..\Run: [msnmsgr] "C:\Program Files\MSN Messenger\msnmsgr.exe" /background (User 'Default user')

O4 - Global Startup: Adobe Gamma Loader.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe

O4 - Global Startup: DSLMON.lnk = ?

O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe

O4 - Global Startup: HP Image Zone Fast Start.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqthb08.exe

O4 - Global Startup: Logitech Desktop Messenger.lnk = C:\Program Files\Logitech\Desktop Messenger\8876480\Program\LogitechDesktopMessenger.exe

O4 - Global Startup: Logitech SetPoint.lnk = C:\Program Files\Logitech\SetPoint\SetPoint.exe

O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~3\OFFICE11\EXCEL.EXE/3000

O8 - Extra context menu item: E&xportar para o Microsoft Excel - res://C:\PROGRA~1\MICROS~3\Office10\EXCEL.EXE/3000

O9 - Extra button: Yahoo! Services - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\Program Files\Yahoo!\Common\yiesrvc.dll

O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~3\OFFICE11\REFIEBAR.DLL

O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe

O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe

O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe

O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe

O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (Installation Support) - C:\Program Files\Yahoo!\Common\Yinsthelper.dll

O18 - Protocol: bwfile-8876480 - {9462A756-7B47-47BC-8C80-C34B9B80B32B} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\GAPlugProtocol-8876480.dll

O18 - Protocol: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files\AVG\AVG8\avgpp.dll

O20 - Winlogon Notify: avgrsstarter - C:\WINDOWS\SYSTEM32\avgrsstx.dll

O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe

O23 - Service: AVG8 E-mail Scanner (avg8emc) - AVG Technologies CZ, s.r.o. - C:\PROGRA~1\AVG\AVG8\avgemc.exe

O23 - Service: AVG8 WatchDog (avg8wd) - AVG Technologies CZ, s.r.o. - C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe

O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe

O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1150\Intel 32\IDriverT.exe

O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe

O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe

O23 - Service: Logitech Bluetooth Service (LBTServ) - Logitech, Inc. - C:\Program Files\Common Files\Logitech\Bluetooth\LBTServ.exe

O23 - Service: Macromedia Licensing Service - Unknown owner - C:\Program Files\Common Files\Macromedia Shared\Service\Macromedia Licensing.exe

O23 - Service: MBAMService - Malwarebytes Corporation - C:\Program Files\Malwarebytes' Anti-Malware\mbamservice.exe

O23 - Service: NBService - Nero AG - C:\Program Files\Nero\Nero 7\Nero BackItUp\NBService.exe

O23 - Service: NMIndexingService - Nero AG - C:\Program Files\Common Files\Ahead\Lib\NMIndexingService.exe

O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\System32\nvsvc32.exe

O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe

--

End of file - 10294 bytes

Link to post
Share on other sites

So, here is the DrWeb log, I opened and copy it from notepad.

data002;C:\Documents and Settings\Shahril Izwan\Desktop;Archive contains infected objects;;

ComboFix.exe;C:\Documents and Settings\Shahril Izwan\Desktop;Container contains infected objects;Moved.;

ComboFix.exe/data002\32788R22FWJFW\c.bat;C:\Documents and Settings\Shahril Izwan\Desktop\ComboFix.exe/data002;Probably BATCH.Virus;;

ComboFix.exe/data002\32788R22FWJFW\psexec.cfexe;C:\Documents and Settings\Shahril Izwan\Desktop\ComboFix.exe/data002;Program.PsExec.171;;

mirc.exe;C:\Program Files\mIRC;Program.mIRC.623;Moved.;

Adobe Gamma Loader.com.vir;C:\Qoobox\Quarantine\C\Documents and Settings\Shahril Izwan\Start Menu\Programs\Startup;Trojan.MulDrop.29268;Deleted.;

WINWORD.EXE.vir;C:\Qoobox\Quarantine\C\Program Files\Microsoft Office;Trojan.MulDrop.29268;Deleted.;

services.exe.vir;C:\Qoobox\Quarantine\C\Program Files\mIRC\IRC Bot;Trojan.MulDrop.29268;Deleted.;

A0000014.EXE;C:\System Volume Information\_restore{5BAC1D37-A855-4708-8BF8-0DE091F86EF1}\RP2;Trojan.MulDrop.29268;Deleted.;

A0000024.exe;C:\System Volume Information\_restore{5BAC1D37-A855-4708-8BF8-0DE091F86EF1}\RP2;Trojan.MulDrop.29268;Deleted.;

A0000032.com;C:\System Volume Information\_restore{5BAC1D37-A855-4708-8BF8-0DE091F86EF1}\RP2;Trojan.MulDrop.29268;Deleted.;

A0000051.bat;C:\System Volume Information\_restore{5BAC1D37-A855-4708-8BF8-0DE091F86EF1}\RP2;Probably BATCH.Virus;Incurable.Renamed.;

A0000073.EXE;C:\System Volume Information\_restore{5BAC1D37-A855-4708-8BF8-0DE091F86EF1}\RP2;Program.PsExec.170;Moved.;

data002;C:\System Volume Information\_restore{5BAC1D37-A855-4708-8BF8-0DE091F86EF1}\RP2;Archive contains infected objects;;

A0000602.exe;C:\System Volume Information\_restore{5BAC1D37-A855-4708-8BF8-0DE091F86EF1}\RP2;Container contains infected objects;Moved.;

A0000602.exe/data002\32788R22FWJFW\c.bat;C:\System Volume Information\_restore{5BAC1D37-A855-4708-8BF8-0DE091F86EF1}\RP2\A0000602.exe/data002;Probably BATCH.Virus;;

A0000602.exe/data002\32788R22FWJFW\psexec.cfexe;C:\System Volume Information\_restore{5BAC1D37-A855-4708-8BF8-0DE091F86EF1}\RP2\A0000602.exe/data002;Program.PsExec.171;;

A0000640.bat;C:\System Volume Information\_restore{5BAC1D37-A855-4708-8BF8-0DE091F86EF1}\RP3;Probably BATCH.Virus;Incurable.Renamed.;

A0000661.EXE;C:\System Volume Information\_restore{5BAC1D37-A855-4708-8BF8-0DE091F86EF1}\RP3;Program.PsExec.170;Moved.;

data002;C:\System Volume Information\_restore{5BAC1D37-A855-4708-8BF8-0DE091F86EF1}\RP6;Archive contains infected objects;;

A0003872.exe;C:\System Volume Information\_restore{5BAC1D37-A855-4708-8BF8-0DE091F86EF1}\RP6;Container contains infected objects;Moved.;

A0003873.exe;C:\System Volume Information\_restore{5BAC1D37-A855-4708-8BF8-0DE091F86EF1}\RP6;Program.mIRC.623;Moved.;

A0003872.exe/data002\32788R22FWJFW\c.bat;C:\System Volume Information\_restore{5BAC1D37-A855-4708-8BF8-0DE091F86EF1}\RP6\A0003872.exe/data002;Probably BATCH.Virus;;

A0003872.exe/data002\32788R22FWJFW\psexec.cfexe;C:\System Volume Information\_restore{5BAC1D37-A855-4708-8BF8-0DE091F86EF1}\RP6\A0003872.exe/data002;Program.PsExec.171;;

mirc621.exe;D:\Installer;Archive contains infected objects;Moved.;

Nero-7.0.1.4b_eng_no_yt.exe;D:\Installer\Audio Video Software\Nero 7;Archive contains infected objects;Moved.;

Nero-7.0.1.4b_eng_no_yt.exe\1060.mst;D:\Installer\Audio Video Software\Nero 7\Nero-7.0.1.4b_eng_no_yt.exe;Modification of VBS.LoveLetter;;

data002;D:\Installer\Mirc;Archive contains infected objects;;

mirc631.exe;D:\Installer\Mirc;Archive contains infected objects;Moved.;

mirc631.exe/data002\data015;D:\Installer\Mirc\mirc631.exe/data002;Program.mIRC.623;;

mirc621.exe\data009;D:\Installer\mirc621.exe;Program.mIRC.621;;

Roar.exe;D:\Installer\UTorrent.Turbo.Booster.v2.0.3.0.Cracked-F4CG\Setup;Archive contains infected objects;;

utorrentturbobooster_installer.exe;D:\Installer\UTorrent.Turbo.Booster.v2.0.3.0.Cracked-F4CG\Setup;Archive contains infected objects;Moved.;

utorrentturbobooster_installer.exe/Roar.exe\roar.bat;D:\Installer\UTorrent.Turbo.Booster.v2.0.3.0.Cracked-F4CG\Setup\utorrentturbobooster_installer.exe/Roar.exe;BAT.DownLoader.3;;

A0000608.INF;D:\System Volume Information\_restore{0B6A4FE1-B831-46BE-A554-94D147EAA517}\RP10;Win32.HLLW.Autoruner.131;Deleted.;

A0001594.exe;D:\System Volume Information\_restore{0B6A4FE1-B831-46BE-A554-94D147EAA517}\RP10;Archive contains infected objects;Moved.;

A0001594.exe\data009;D:\System Volume Information\_restore{0B6A4FE1-B831-46BE-A554-94D147EAA517}\RP10\A0001594.exe;Program.mIRC.621;;

A0001603.INF;D:\System Volume Information\_restore{0B6A4FE1-B831-46BE-A554-94D147EAA517}\RP11;Win32.HLLW.Autoruner.131;Deleted.;

A0002585.INF;D:\System Volume Information\_restore{0B6A4FE1-B831-46BE-A554-94D147EAA517}\RP11;Win32.HLLW.Autoruner.131;Deleted.;

A0003586.INF;D:\System Volume Information\_restore{0B6A4FE1-B831-46BE-A554-94D147EAA517}\RP11;Win32.HLLW.Autoruner.131;Deleted.;

A0000529.INF;D:\System Volume Information\_restore{0B6A4FE1-B831-46BE-A554-94D147EAA517}\RP6;Win32.HLLW.Autoruner.131;Deleted.;

A0000535.INF;D:\System Volume Information\_restore{0B6A4FE1-B831-46BE-A554-94D147EAA517}\RP7;Win32.HLLW.Autoruner.131;Deleted.;

A0000553.INF;D:\System Volume Information\_restore{0B6A4FE1-B831-46BE-A554-94D147EAA517}\RP7;Win32.HLLW.Autoruner.131;Deleted.;

A0000565.INF;D:\System Volume Information\_restore{0B6A4FE1-B831-46BE-A554-94D147EAA517}\RP7;Win32.HLLW.Autoruner.131;Deleted.;

A0000571.INF;D:\System Volume Information\_restore{0B6A4FE1-B831-46BE-A554-94D147EAA517}\RP8;Win32.HLLW.Autoruner.131;Deleted.;

A0000589.INF;D:\System Volume Information\_restore{0B6A4FE1-B831-46BE-A554-94D147EAA517}\RP8;Win32.HLLW.Autoruner.131;Deleted.;

A0000597.INF;D:\System Volume Information\_restore{0B6A4FE1-B831-46BE-A554-94D147EAA517}\RP9;Win32.HLLW.Autoruner.131;Deleted.;

A0044766.exe;D:\System Volume Information\_restore{10DC53BA-FEBE-4F63-B72E-68E255DD178F}\RP13;Archive contains infected objects;Moved.;

A0044766.exe\data009;D:\System Volume Information\_restore{10DC53BA-FEBE-4F63-B72E-68E255DD178F}\RP13\A0044766.exe;Program.mIRC.621;;

A0000188.INF;D:\System Volume Information\_restore{129EDFBE-FF99-4AF1-A33B-4CDB23FB2979}\RP5;Win32.HLLW.Autoruner.131;Deleted.;

A0000201.INF;D:\System Volume Information\_restore{129EDFBE-FF99-4AF1-A33B-4CDB23FB2979}\RP5;Win32.HLLW.Autoruner.131;Deleted.;

A0000213.INF;D:\System Volume Information\_restore{129EDFBE-FF99-4AF1-A33B-4CDB23FB2979}\RP5;Win32.HLLW.Autoruner.131;Deleted.;

A0000219.INF;D:\System Volume Information\_restore{129EDFBE-FF99-4AF1-A33B-4CDB23FB2979}\RP6;Win32.HLLW.Autoruner.131;Deleted.;

A0000237.INF;D:\System Volume Information\_restore{129EDFBE-FF99-4AF1-A33B-4CDB23FB2979}\RP6;Win32.HLLW.Autoruner.131;Deleted.;

A0000255.INF;D:\System Volume Information\_restore{129EDFBE-FF99-4AF1-A33B-4CDB23FB2979}\RP7;Win32.HLLW.Autoruner.131;Deleted.;

A0000271.INF;D:\System Volume Information\_restore{129EDFBE-FF99-4AF1-A33B-4CDB23FB2979}\RP7;Win32.HLLW.Autoruner.131;Deleted.;

A0000283.INF;D:\System Volume Information\_restore{129EDFBE-FF99-4AF1-A33B-4CDB23FB2979}\RP7;Win32.HLLW.Autoruner.131;Deleted.;

A0000014.INF;D:\System Volume Information\_restore{1345B462-7196-41B6-B6EC-34014899BE5C}\RP1;Win32.HLLW.Autoruner.131;Deleted.;

A0000057.INF;D:\System Volume Information\_restore{1345B462-7196-41B6-B6EC-34014899BE5C}\RP1;Win32.HLLW.Autoruner.131;Deleted.;

A0000708.INF;D:\System Volume Information\_restore{1345B462-7196-41B6-B6EC-34014899BE5C}\RP11;Win32.HLLW.Autoruner.131;Deleted.;

A0000733.INF;D:\System Volume Information\_restore{1345B462-7196-41B6-B6EC-34014899BE5C}\RP12;Win32.HLLW.Autoruner.131;Deleted.;

A0000761.INF;D:\System Volume Information\_restore{1345B462-7196-41B6-B6EC-34014899BE5C}\RP13;Win32.HLLW.Autoruner.131;Deleted.;

A0001700.INF;D:\System Volume Information\_restore{1345B462-7196-41B6-B6EC-34014899BE5C}\RP14;Win32.HLLW.Autoruner.131;Deleted.;

A0002680.INF;D:\System Volume Information\_restore{1345B462-7196-41B6-B6EC-34014899BE5C}\RP14;Win32.HLLW.Autoruner.131;Deleted.;

A0002709.INF;D:\System Volume Information\_restore{1345B462-7196-41B6-B6EC-34014899BE5C}\RP15;Win32.HLLW.Autoruner.131;Deleted.;

A0002796.INF;D:\System Volume Information\_restore{1345B462-7196-41B6-B6EC-34014899BE5C}\RP16;Win32.HLLW.Autoruner.131;Deleted.;

A0002837.INF;D:\System Volume Information\_restore{1345B462-7196-41B6-B6EC-34014899BE5C}\RP17;Win32.HLLW.Autoruner.131;Deleted.;

A0000073.INF;D:\System Volume Information\_restore{1345B462-7196-41B6-B6EC-34014899BE5C}\RP2;Win32.HLLW.Autoruner.131;Deleted.;

A0002936.INF;D:\System Volume Information\_restore{1345B462-7196-41B6-B6EC-34014899BE5C}\RP20;Win32.HLLW.Autoruner.131;Deleted.;

A0002955.INF;D:\System Volume Information\_restore{1345B462-7196-41B6-B6EC-34014899BE5C}\RP21;Win32.HLLW.Autoruner.131;Deleted.;

A0003213.INF;D:\System Volume Information\_restore{1345B462-7196-41B6-B6EC-34014899BE5C}\RP28;Win32.HLLW.Autoruner.131;Deleted.;

A0000137.INF;D:\System Volume Information\_restore{1345B462-7196-41B6-B6EC-34014899BE5C}\RP3;Win32.HLLW.Autoruner.131;Deleted.;

A0003305.INF;D:\System Volume Information\_restore{1345B462-7196-41B6-B6EC-34014899BE5C}\RP31;Win32.HLLW.Autoruner.131;Deleted.;

A0003337.INF;D:\System Volume Information\_restore{1345B462-7196-41B6-B6EC-34014899BE5C}\RP32;Win32.HLLW.Autoruner.131;Deleted.;

A0003477.INF;D:\System Volume Information\_restore{1345B462-7196-41B6-B6EC-34014899BE5C}\RP37;Win32.HLLW.Autoruner.131;Deleted.;

A0000165.INF;D:\System Volume Information\_restore{1345B462-7196-41B6-B6EC-34014899BE5C}\RP4;Win32.HLLW.Autoruner.131;Deleted.;

A0003611.INF;D:\System Volume Information\_restore{1345B462-7196-41B6-B6EC-34014899BE5C}\RP41;Win32.HLLW.Autoruner.131;Deleted.;

A0003762.INF;D:\System Volume Information\_restore{1345B462-7196-41B6-B6EC-34014899BE5C}\RP42;Win32.HLLW.Autoruner.131;Deleted.;

A0004763.INF;D:\System Volume Information\_restore{1345B462-7196-41B6-B6EC-34014899BE5C}\RP42;Win32.HLLW.Autoruner.131;Deleted.;

A0004778.INF;D:\System Volume Information\_restore{1345B462-7196-41B6-B6EC-34014899BE5C}\RP42;Win32.HLLW.Autoruner.131;Deleted.;

A0000183.INF;D:\System Volume Information\_restore{1345B462-7196-41B6-B6EC-34014899BE5C}\RP5;Win32.HLLW.Autoruner.131;Deleted.;

A0000243.INF;D:\System Volume Information\_restore{1345B462-7196-41B6-B6EC-34014899BE5C}\RP5;Win32.HLLW.Autoruner.131;Deleted.;

A0000314.INF;D:\System Volume Information\_restore{1345B462-7196-41B6-B6EC-34014899BE5C}\RP6;Win32.HLLW.Autoruner.131;Deleted.;

A0000544.INF;D:\System Volume Information\_restore{1345B462-7196-41B6-B6EC-34014899BE5C}\RP6;Win32.HLLW.Autoruner.131;Deleted.;

A0000588.INF;D:\System Volume Information\_restore{1345B462-7196-41B6-B6EC-34014899BE5C}\RP7;Win32.HLLW.Autoruner.131;Deleted.;

A0000604.INF;D:\System Volume Information\_restore{1345B462-7196-41B6-B6EC-34014899BE5C}\RP7;Win32.HLLW.Autoruner.131;Deleted.;

A0000610.INF;D:\System Volume Information\_restore{1345B462-7196-41B6-B6EC-34014899BE5C}\RP8;Win32.HLLW.Autoruner.131;Deleted.;

A0000628.INF;D:\System Volume Information\_restore{1345B462-7196-41B6-B6EC-34014899BE5C}\RP8;Win32.HLLW.Autoruner.131;Deleted.;

A0000637.INF;D:\System Volume Information\_restore{1345B462-7196-41B6-B6EC-34014899BE5C}\RP9;Win32.HLLW.Autoruner.131;Deleted.;

A0000692.INF;D:\System Volume Information\_restore{1345B462-7196-41B6-B6EC-34014899BE5C}\RP9;Win32.HLLW.Autoruner.131;Deleted.;

A0001168.INF;D:\System Volume Information\_restore{5B4CDF95-73FB-4AEE-B50A-C8E0EDFB00D5}\RP2;Win32.HLLW.Autoruner.131;Deleted.;

A0001180.INF;D:\System Volume Information\_restore{5B4CDF95-73FB-4AEE-B50A-C8E0EDFB00D5}\RP2;Win32.HLLW.Autoruner.131;Deleted.;

A0003874.exe;D:\System Volume Information\_restore{5BAC1D37-A855-4708-8BF8-0DE091F86EF1}\RP6;Archive contains infected objects;Moved.;

A0003875.exe;D:\System Volume Information\_restore{5BAC1D37-A855-4708-8BF8-0DE091F86EF1}\RP6;Archive contains infected objects;Moved.;

data002;D:\System Volume Information\_restore{5BAC1D37-A855-4708-8BF8-0DE091F86EF1}\RP6;Archive contains infected objects;;

A0003876.exe;D:\System Volume Information\_restore{5BAC1D37-A855-4708-8BF8-0DE091F86EF1}\RP6;Archive contains infected objects;Moved.;

Roar.exe;D:\System Volume Information\_restore{5BAC1D37-A855-4708-8BF8-0DE091F86EF1}\RP6;Archive contains infected objects;;

A0003877.exe;D:\System Volume Information\_restore{5BAC1D37-A855-4708-8BF8-0DE091F86EF1}\RP6;Archive contains infected objects;Moved.;

A0003874.exe\data009;D:\System Volume Information\_restore{5BAC1D37-A855-4708-8BF8-0DE091F86EF1}\RP6\A0003874.exe;Program.mIRC.621;;

A0003875.exe\1060.mst;D:\System Volume Information\_restore{5BAC1D37-A855-4708-8BF8-0DE091F86EF1}\RP6\A0003875.exe;Modification of VBS.LoveLetter;;

A0003876.exe/data002\data015;D:\System Volume Information\_restore{5BAC1D37-A855-4708-8BF8-0DE091F86EF1}\RP6\A0003876.exe/data002;Program.mIRC.623;;

A0003877.exe/Roar.exe\roar.bat;D:\System Volume Information\_restore{5BAC1D37-A855-4708-8BF8-0DE091F86EF1}\RP6\A0003877.exe/Roar.exe;BAT.DownLoader.3;;

A0000743.INF;D:\System Volume Information\_restore{5DD88F84-DC55-4B90-9C98-B4E376391E7A}\RP15;Win32.HLLW.Autoruner.131;Deleted.;

A0000752.INF;D:\System Volume Information\_restore{5DD88F84-DC55-4B90-9C98-B4E376391E7A}\RP16;Win32.HLLW.Autoruner.131;Deleted.;

A0000859.INF;D:\System Volume Information\_restore{5DD88F84-DC55-4B90-9C98-B4E376391E7A}\RP17;Win32.HLLW.Autoruner.131;Deleted.;

A0000887.INF;D:\System Volume Information\_restore{5DD88F84-DC55-4B90-9C98-B4E376391E7A}\RP19;Win32.HLLW.Autoruner.131;Deleted.;

A0000935.INF;D:\System Volume Information\_restore{5DD88F84-DC55-4B90-9C98-B4E376391E7A}\RP20;Win32.HLLW.Autoruner.131;Deleted.;

A0000971.INF;D:\System Volume Information\_restore{5DD88F84-DC55-4B90-9C98-B4E376391E7A}\RP21;Win32.HLLW.Autoruner.131;Deleted.;

A0001017.INF;D:\System Volume Information\_restore{5DD88F84-DC55-4B90-9C98-B4E376391E7A}\RP22;Win32.HLLW.Autoruner.131;Deleted.;

A0001031.INF;D:\System Volume Information\_restore{5DD88F84-DC55-4B90-9C98-B4E376391E7A}\RP23;Win32.HLLW.Autoruner.131;Deleted.;

A0001102.INF;D:\System Volume Information\_restore{5DD88F84-DC55-4B90-9C98-B4E376391E7A}\RP24;Win32.HLLW.Autoruner.131;Deleted.;

A0001164.INF;D:\System Volume Information\_restore{5DD88F84-DC55-4B90-9C98-B4E376391E7A}\RP25;Win32.HLLW.Autoruner.131;Deleted.;

A0001201.INF;D:\System Volume Information\_restore{5DD88F84-DC55-4B90-9C98-B4E376391E7A}\RP27;Win32.HLLW.Autoruner.131;Deleted.;

A0001254.INF;D:\System Volume Information\_restore{5DD88F84-DC55-4B90-9C98-B4E376391E7A}\RP28;Win32.HLLW.Autoruner.131;Deleted.;

A0001299.INF;D:\System Volume Information\_restore{5DD88F84-DC55-4B90-9C98-B4E376391E7A}\RP30;Win32.HLLW.Autoruner.131;Deleted.;

A0001353.INF;D:\System Volume Information\_restore{5DD88F84-DC55-4B90-9C98-B4E376391E7A}\RP31;Win32.HLLW.Autoruner.131;Deleted.;

A0001386.INF;D:\System Volume Information\_restore{5DD88F84-DC55-4B90-9C98-B4E376391E7A}\RP32;Win32.HLLW.Autoruner.131;Deleted.;

A0001423.INF;D:\System Volume Information\_restore{5DD88F84-DC55-4B90-9C98-B4E376391E7A}\RP33;Win32.HLLW.Autoruner.131;Deleted.;

A0001462.INF;D:\System Volume Information\_restore{5DD88F84-DC55-4B90-9C98-B4E376391E7A}\RP35;Win32.HLLW.Autoruner.131;Deleted.;

A0001514.INF;D:\System Volume Information\_restore{5DD88F84-DC55-4B90-9C98-B4E376391E7A}\RP36;Win32.HLLW.Autoruner.131;Deleted.;

A0001554.INF;D:\System Volume Information\_restore{5DD88F84-DC55-4B90-9C98-B4E376391E7A}\RP37;Win32.HLLW.Autoruner.131;Deleted.;

A0001612.INF;D:\System Volume Information\_restore{5DD88F84-DC55-4B90-9C98-B4E376391E7A}\RP39;Win32.HLLW.Autoruner.131;Deleted.;

A0001650.INF;D:\System Volume Information\_restore{5DD88F84-DC55-4B90-9C98-B4E376391E7A}\RP40;Win32.HLLW.Autoruner.131;Deleted.;

A0001700.INF;D:\System Volume Information\_restore{5DD88F84-DC55-4B90-9C98-B4E376391E7A}\RP41;Win32.HLLW.Autoruner.131;Deleted.;

A0001740.INF;D:\System Volume Information\_restore{5DD88F84-DC55-4B90-9C98-B4E376391E7A}\RP43;Win32.HLLW.Autoruner.131;Deleted.;

A0001785.INF;D:\System Volume Information\_restore{5DD88F84-DC55-4B90-9C98-B4E376391E7A}\RP44;Win32.HLLW.Autoruner.131;Deleted.;

A0001798.INF;D:\System Volume Information\_restore{5DD88F84-DC55-4B90-9C98-B4E376391E7A}\RP45;Win32.HLLW.Autoruner.131;Deleted.;

A0001850.INF;D:\System Volume Information\_restore{5DD88F84-DC55-4B90-9C98-B4E376391E7A}\RP46;Win32.HLLW.Autoruner.131;Deleted.;

A0001920.INF;D:\System Volume Information\_restore{5DD88F84-DC55-4B90-9C98-B4E376391E7A}\RP47;Win32.HLLW.Autoruner.131;Deleted.;

A0001996.INF;D:\System Volume Information\_restore{5DD88F84-DC55-4B90-9C98-B4E376391E7A}\RP48;Win32.HLLW.Autoruner.131;Deleted.;

A0002051.INF;D:\System Volume Information\_restore{5DD88F84-DC55-4B90-9C98-B4E376391E7A}\RP49;Win32.HLLW.Autoruner.131;Deleted.;

A0002083.INF;D:\System Volume Information\_restore{5DD88F84-DC55-4B90-9C98-B4E376391E7A}\RP50;Win32.HLLW.Autoruner.131;Deleted.;

A0002125.INF;D:\System Volume Information\_restore{5DD88F84-DC55-4B90-9C98-B4E376391E7A}\RP51;Win32.HLLW.Autoruner.131;Deleted.;

A0002167.INF;D:\System Volume Information\_restore{5DD88F84-DC55-4B90-9C98-B4E376391E7A}\RP52;Win32.HLLW.Autoruner.131;Deleted.;

A0002220.INF;D:\System Volume Information\_restore{5DD88F84-DC55-4B90-9C98-B4E376391E7A}\RP53;Win32.HLLW.Autoruner.131;Deleted.;

A0002252.INF;D:\System Volume Information\_restore{5DD88F84-DC55-4B90-9C98-B4E376391E7A}\RP54;Win32.HLLW.Autoruner.131;Deleted.;

A0002284.INF;D:\System Volume Information\_restore{5DD88F84-DC55-4B90-9C98-B4E376391E7A}\RP55;Win32.HLLW.Autoruner.131;Deleted.;

A0002316.INF;D:\System Volume Information\_restore{5DD88F84-DC55-4B90-9C98-B4E376391E7A}\RP57;Win32.HLLW.Autoruner.131;Deleted.;

A0002353.INF;D:\System Volume Information\_restore{5DD88F84-DC55-4B90-9C98-B4E376391E7A}\RP58;Win32.HLLW.Autoruner.131;Deleted.;

A0002415.INF;D:\System Volume Information\_restore{5DD88F84-DC55-4B90-9C98-B4E376391E7A}\RP60;Win32.HLLW.Autoruner.131;Deleted.;

A0002453.INF;D:\System Volume Information\_restore{5DD88F84-DC55-4B90-9C98-B4E376391E7A}\RP61;Win32.HLLW.Autoruner.131;Deleted.;

A0002493.INF;D:\System Volume Information\_restore{5DD88F84-DC55-4B90-9C98-B4E376391E7A}\RP62;Win32.HLLW.Autoruner.131;Deleted.;

A0002528.INF;D:\System Volume Information\_restore{5DD88F84-DC55-4B90-9C98-B4E376391E7A}\RP63;Win32.HLLW.Autoruner.131;Deleted.;

A0002560.INF;D:\System Volume Information\_restore{5DD88F84-DC55-4B90-9C98-B4E376391E7A}\RP64;Win32.HLLW.Autoruner.131;Deleted.;

A0002602.INF;D:\System Volume Information\_restore{5DD88F84-DC55-4B90-9C98-B4E376391E7A}\RP65;Win32.HLLW.Autoruner.131;Deleted.;

A0002642.INF;D:\System Volume Information\_restore{5DD88F84-DC55-4B90-9C98-B4E376391E7A}\RP66;Win32.HLLW.Autoruner.131;Deleted.;

A0002676.INF;D:\System Volume Information\_restore{5DD88F84-DC55-4B90-9C98-B4E376391E7A}\RP67;Win32.HLLW.Autoruner.131;Deleted.;

A0002858.INF;D:\System Volume Information\_restore{5DD88F84-DC55-4B90-9C98-B4E376391E7A}\RP67;Win32.HLLW.Autoruner.131;Deleted.;

A0003858.INF;D:\System Volume Information\_restore{5DD88F84-DC55-4B90-9C98-B4E376391E7A}\RP67;Win32.HLLW.Autoruner.131;Deleted.;

A0003865.INF;D:\System Volume Information\_restore{5DD88F84-DC55-4B90-9C98-B4E376391E7A}\RP68;Win32.HLLW.Autoruner.131;Deleted.;

A0003892.INF;D:\System Volume Information\_restore{5DD88F84-DC55-4B90-9C98-B4E376391E7A}\RP69;Win32.HLLW.Autoruner.131;Deleted.;

A0003940.INF;D:\System Volume Information\_restore{5DD88F84-DC55-4B90-9C98-B4E376391E7A}\RP70;Win32.HLLW.Autoruner.131;Deleted.;

A0003979.INF;D:\System Volume Information\_restore{5DD88F84-DC55-4B90-9C98-B4E376391E7A}\RP71;Win32.HLLW.Autoruner.131;Deleted.;

A0003991.INF;D:\System Volume Information\_restore{5DD88F84-DC55-4B90-9C98-B4E376391E7A}\RP72;Win32.HLLW.Autoruner.131;Deleted.;

A0004022.INF;D:\System Volume Information\_restore{5DD88F84-DC55-4B90-9C98-B4E376391E7A}\RP73;Win32.HLLW.Autoruner.131;Deleted.;

A0004043.INF;D:\System Volume Information\_restore{5DD88F84-DC55-4B90-9C98-B4E376391E7A}\RP74;Win32.HLLW.Autoruner.131;Deleted.;

A0004864.INF;D:\System Volume Information\_restore{5DD88F84-DC55-4B90-9C98-B4E376391E7A}\RP74;Win32.HLLW.Autoruner.131;Deleted.;

A0004872.INF;D:\System Volume Information\_restore{5DD88F84-DC55-4B90-9C98-B4E376391E7A}\RP75;Win32.HLLW.Autoruner.131;Deleted.;

A0004888.INF;D:\System Volume Information\_restore{5DD88F84-DC55-4B90-9C98-B4E376391E7A}\RP76;Win32.HLLW.Autoruner.131;Deleted.;

A0004941.INF;D:\System Volume Information\_restore{5DD88F84-DC55-4B90-9C98-B4E376391E7A}\RP79;Win32.HLLW.Autoruner.131;Deleted.;

A0000518.INF;D:\System Volume Information\_restore{5DD88F84-DC55-4B90-9C98-B4E376391E7A}\RP8;Win32.HLLW.Autoruner.131;Deleted.;

A0004963.INF;D:\System Volume Information\_restore{5DD88F84-DC55-4B90-9C98-B4E376391E7A}\RP82;Win32.HLLW.Autoruner.131;Deleted.;

A0005059.INF;D:\System Volume Information\_restore{5DD88F84-DC55-4B90-9C98-B4E376391E7A}\RP84;Win32.HLLW.Autoruner.131;Deleted.;

A0008121.INF;D:\System Volume Information\_restore{5DD88F84-DC55-4B90-9C98-B4E376391E7A}\RP84;Win32.HLLW.Autoruner.131;Deleted.;

A0008137.INF;D:\System Volume Information\_restore{5DD88F84-DC55-4B90-9C98-B4E376391E7A}\RP84;Win32.HLLW.Autoruner.131;Deleted.;

A0008156.INF;D:\System Volume Information\_restore{5DD88F84-DC55-4B90-9C98-B4E376391E7A}\RP84;Win32.HLLW.Autoruner.131;Deleted.;

A0003128.exe;D:\System Volume Information\_restore{745A203A-1590-47A5-8C4B-BC4DA1793E38}\RP12;Archive contains infected objects;Moved.;

A0003128.exe\data009;D:\System Volume Information\_restore{745A203A-1590-47A5-8C4B-BC4DA1793E38}\RP12\A0003128.exe;Program.mIRC.621;;

A0001440.INF;D:\System Volume Information\_restore{7822AE1E-E88E-471A-8819-18A6C64EB057}\RP10;Win32.HLLW.Autoruner.131;Deleted.;

A0001461.INF;D:\System Volume Information\_restore{7822AE1E-E88E-471A-8819-18A6C64EB057}\RP10;Win32.HLLW.Autoruner.131;Deleted.;

A0002520.INF;D:\System Volume Information\_restore{7822AE1E-E88E-471A-8819-18A6C64EB057}\RP11;Win32.HLLW.Autoruner.131;Deleted.;

A0004477.INF;D:\System Volume Information\_restore{7822AE1E-E88E-471A-8819-18A6C64EB057}\RP12;Win32.HLLW.Autoruner.131;Deleted.;

A0005474.INF;D:\System Volume Information\_restore{7822AE1E-E88E-471A-8819-18A6C64EB057}\RP12;Win32.HLLW.Autoruner.131;Deleted.;

A0006474.INF;D:\System Volume Information\_restore{7822AE1E-E88E-471A-8819-18A6C64EB057}\RP12;Win32.HLLW.Autoruner.131;Deleted.;

A0006487.INF;D:\System Volume Information\_restore{7822AE1E-E88E-471A-8819-18A6C64EB057}\RP12;Win32.HLLW.Autoruner.131;Deleted.;

A0006500.INF;D:\System Volume Information\_restore{7822AE1E-E88E-471A-8819-18A6C64EB057}\RP12;Win32.HLLW.Autoruner.131;Deleted.;

A0006513.INF;D:\System Volume Information\_restore{7822AE1E-E88E-471A-8819-18A6C64EB057}\RP12;Win32.HLLW.Autoruner.131;Deleted.;

A0006546.INF;D:\System Volume Information\_restore{7822AE1E-E88E-471A-8819-18A6C64EB057}\RP12;Win32.HLLW.Autoruner.131;Deleted.;

A0007546.INF;D:\System Volume Information\_restore{7822AE1E-E88E-471A-8819-18A6C64EB057}\RP12;Win32.HLLW.Autoruner.131;Deleted.;

A0007644.INF;D:\System Volume Information\_restore{7822AE1E-E88E-471A-8819-18A6C64EB057}\RP13;Win32.HLLW.Autoruner.131;Deleted.;

A0007817.INF;D:\System Volume Information\_restore{7822AE1E-E88E-471A-8819-18A6C64EB057}\RP13;Win32.HLLW.Autoruner.131;Deleted.;

A0007912.INF;D:\System Volume Information\_restore{7822AE1E-E88E-471A-8819-18A6C64EB057}\RP14;Win32.HLLW.Autoruner.131;Deleted.;

A0007950.INF;D:\System Volume Information\_restore{7822AE1E-E88E-471A-8819-18A6C64EB057}\RP14;Win32.HLLW.Autoruner.131;Deleted.;

A0007979.INF;D:\System Volume Information\_restore{7822AE1E-E88E-471A-8819-18A6C64EB057}\RP14;Win32.HLLW.Autoruner.131;Deleted.;

A0008979.INF;D:\System Volume Information\_restore{7822AE1E-E88E-471A-8819-18A6C64EB057}\RP14;Win32.HLLW.Autoruner.131;Deleted.;

A0010979.INF;D:\System Volume Information\_restore{7822AE1E-E88E-471A-8819-18A6C64EB057}\RP14;Win32.HLLW.Autoruner.131;Deleted.;

A0011979.INF;D:\System Volume Information\_restore{7822AE1E-E88E-471A-8819-18A6C64EB057}\RP14;Win32.HLLW.Autoruner.131;Deleted.;

A0012979.INF;D:\System Volume Information\_restore{7822AE1E-E88E-471A-8819-18A6C64EB057}\RP14;Win32.HLLW.Autoruner.131;Deleted.;

A0013979.INF;D:\System Volume Information\_restore{7822AE1E-E88E-471A-8819-18A6C64EB057}\RP14;Win32.HLLW.Autoruner.131;Deleted.;

A0015979.INF;D:\System Volume Information\_restore{7822AE1E-E88E-471A-8819-18A6C64EB057}\RP14;Win32.HLLW.Autoruner.131;Deleted.;

A0017979.INF;D:\System Volume Information\_restore{7822AE1E-E88E-471A-8819-18A6C64EB057}\RP14;Win32.HLLW.Autoruner.131;Deleted.;

A0018979.INF;D:\System Volume Information\_restore{7822AE1E-E88E-471A-8819-18A6C64EB057}\RP14;Win32.HLLW.Autoruner.131;Deleted.;

A0019007.INF;D:\System Volume Information\_restore{7822AE1E-E88E-471A-8819-18A6C64EB057}\RP14;Win32.HLLW.Autoruner.131;Deleted.;

A0020008.INF;D:\System Volume Information\_restore{7822AE1E-E88E-471A-8819-18A6C64EB057}\RP14;Win32.HLLW.Autoruner.131;Deleted.;

A0021007.INF;D:\System Volume Information\_restore{7822AE1E-E88E-471A-8819-18A6C64EB057}\RP14;Win32.HLLW.Autoruner.131;Deleted.;

A0022007.INF;D:\System Volume Information\_restore{7822AE1E-E88E-471A-8819-18A6C64EB057}\RP14;Win32.HLLW.Autoruner.131;Deleted.;

A0023007.INF;D:\System Volume Information\_restore{7822AE1E-E88E-471A-8819-18A6C64EB057}\RP14;Win32.HLLW.Autoruner.131;Deleted.;

A0024007.INF;D:\System Volume Information\_restore{7822AE1E-E88E-471A-8819-18A6C64EB057}\RP14;Win32.HLLW.Autoruner.131;Deleted.;

A0025005.INF;D:\System Volume Information\_restore{7822AE1E-E88E-471A-8819-18A6C64EB057}\RP15;Win32.HLLW.Autoruner.131;Deleted.;

A0025023.INF;D:\System Volume Information\_restore{7822AE1E-E88E-471A-8819-18A6C64EB057}\RP15;Win32.HLLW.Autoruner.131;Deleted.;

A0026023.INF;D:\System Volume Information\_restore{7822AE1E-E88E-471A-8819-18A6C64EB057}\RP15;Win32.HLLW.Autoruner.131;Deleted.;

A0026043.INF;D:\System Volume Information\_restore{7822AE1E-E88E-471A-8819-18A6C64EB057}\RP15;Win32.HLLW.Autoruner.131;Deleted.;

A0027043.INF;D:\System Volume Information\_restore{7822AE1E-E88E-471A-8819-18A6C64EB057}\RP15;Win32.HLLW.Autoruner.131;Deleted.;

A0028043.INF;D:\System Volume Information\_restore{7822AE1E-E88E-471A-8819-18A6C64EB057}\RP15;Win32.HLLW.Autoruner.131;Deleted.;

A0029065.INF;D:\System Volume Information\_restore{7822AE1E-E88E-471A-8819-18A6C64EB057}\RP15;Win32.HLLW.Autoruner.131;Deleted.;

A0030065.INF;D:\System Volume Information\_restore{7822AE1E-E88E-471A-8819-18A6C64EB057}\RP15;Win32.HLLW.Autoruner.131;Deleted.;

A0031066.INF;D:\System Volume Information\_restore{7822AE1E-E88E-471A-8819-18A6C64EB057}\RP15;Win32.HLLW.Autoruner.131;Deleted.;

A0033065.INF;D:\System Volume Information\_restore{7822AE1E-E88E-471A-8819-18A6C64EB057}\RP15;Win32.HLLW.Autoruner.131;Deleted.;

A0034065.INF;D:\System Volume Information\_restore{7822AE1E-E88E-471A-8819-18A6C64EB057}\RP15;Win32.HLLW.Autoruner.131;Deleted.;

A0036078.INF;D:\System Volume Information\_restore{7822AE1E-E88E-471A-8819-18A6C64EB057}\RP15;Win32.HLLW.Autoruner.131;Deleted.;

A0038082.INF;D:\System Volume Information\_restore{7822AE1E-E88E-471A-8819-18A6C64EB057}\RP15;Win32.HLLW.Autoruner.131;Deleted.;

A0038100.INF;D:\System Volume Information\_restore{7822AE1E-E88E-471A-8819-18A6C64EB057}\RP15;Win32.HLLW.Autoruner.131;Deleted.;

A0039100.INF;D:\System Volume Information\_restore{7822AE1E-E88E-471A-8819-18A6C64EB057}\RP15;Win32.HLLW.Autoruner.131;Deleted.;

A0040100.INF;D:\System Volume Information\_restore{7822AE1E-E88E-471A-8819-18A6C64EB057}\RP15;Win32.HLLW.Autoruner.131;Deleted.;

A0000305.INF;D:\System Volume Information\_restore{7822AE1E-E88E-471A-8819-18A6C64EB057}\RP6;Win32.HLLW.Autoruner.131;Deleted.;

A0000317.INF;D:\System Volume Information\_restore{7822AE1E-E88E-471A-8819-18A6C64EB057}\RP6;Win32.HLLW.Autoruner.131;Deleted.;

A0000323.INF;D:\System Volume Information\_restore{7822AE1E-E88E-471A-8819-18A6C64EB057}\RP7;Win32.HLLW.Autoruner.131;Deleted.;

A0000350.INF;D:\System Volume Information\_restore{7822AE1E-E88E-471A-8819-18A6C64EB057}\RP7;Win32.HLLW.Autoruner.131;Deleted.;

A0000356.INF;D:\System Volume Information\_restore{7822AE1E-E88E-471A-8819-18A6C64EB057}\RP8;Win32.HLLW.Autoruner.131;Deleted.;

A0000370.INF;D:\System Volume Information\_restore{7822AE1E-E88E-471A-8819-18A6C64EB057}\RP8;Win32.HLLW.Autoruner.131;Deleted.;

A0000405.INF;D:\System Volume Information\_restore{7822AE1E-E88E-471A-8819-18A6C64EB057}\RP8;Win32.HLLW.Autoruner.131;Deleted.;

A0001419.INF;D:\System Volume Information\_restore{7822AE1E-E88E-471A-8819-18A6C64EB057}\RP9;Win32.HLLW.Autoruner.131;Deleted.;

A0000014.INF;D:\System Volume Information\_restore{7A2AFE90-FF0C-48A8-A3D9-667F16F0CC74}\RP1;Win32.HLLW.Autoruner.131;Deleted.;

A0000061.INF;D:\System Volume Information\_restore{7A2AFE90-FF0C-48A8-A3D9-667F16F0CC74}\RP1;Win32.HLLW.Autoruner.131;Deleted.;

A0000450.INF;D:\System Volume Information\_restore{7A2AFE90-FF0C-48A8-A3D9-667F16F0CC74}\RP10;Win32.HLLW.Autoruner.131;Deleted.;

A0001436.INF;D:\System Volume Information\_restore{7A2AFE90-FF0C-48A8-A3D9-667F16F0CC74}\RP10;Win32.HLLW.Autoruner.131;Deleted.;

A0001448.INF;D:\System Volume Information\_restore{7A2AFE90-FF0C-48A8-A3D9-667F16F0CC74}\RP10;Win32.HLLW.Autoruner.131;Deleted.;

A0001461.INF;D:\System Volume Information\_restore{7A2AFE90-FF0C-48A8-A3D9-667F16F0CC74}\RP10;Win32.HLLW.Autoruner.131;Deleted.;

A0003462.INF;D:\System Volume Information\_restore{7A2AFE90-FF0C-48A8-A3D9-667F16F0CC74}\RP10;Win32.HLLW.Autoruner.131;Deleted.;

A0012487.INF;D:\System Volume Information\_restore{7A2AFE90-FF0C-48A8-A3D9-667F16F0CC74}\RP11;Win32.HLLW.Autoruner.131;Deleted.;

A0016487.INF;D:\System Volume Information\_restore{7A2AFE90-FF0C-48A8-A3D9-667F16F0CC74}\RP11;Win32.HLLW.Autoruner.131;Deleted.;

A0022487.INF;D:\System Volume Information\_restore{7A2AFE90-FF0C-48A8-A3D9-667F16F0CC74}\RP11;Win32.HLLW.Autoruner.131;Deleted.;

A0026491.INF;D:\System Volume Information\_restore{7A2AFE90-FF0C-48A8-A3D9-667F16F0CC74}\RP12;Win32.HLLW.Autoruner.131;Deleted.;

A0027487.INF;D:\System Volume Information\_restore{7A2AFE90-FF0C-48A8-A3D9-667F16F0CC74}\RP12;Win32.HLLW.Autoruner.131;Deleted.;

A0032487.INF;D:\System Volume Information\_restore{7A2AFE90-FF0C-48A8-A3D9-667F16F0CC74}\RP12;Win32.HLLW.Autoruner.131;Deleted.;

A0035488.INF;D:\System Volume Information\_restore{7A2AFE90-FF0C-48A8-A3D9-667F16F0CC74}\RP12;Win32.HLLW.Autoruner.131;Deleted.;

A0036490.INF;D:\System Volume Information\_restore{7A2AFE90-FF0C-48A8-A3D9-667F16F0CC74}\RP12;Win32.HLLW.Autoruner.131;Deleted.;

A0037487.INF;D:\System Volume Information\_restore{7A2AFE90-FF0C-48A8-A3D9-667F16F0CC74}\RP12;Win32.HLLW.Autoruner.131;Deleted.;

A0038487.INF;D:\System Volume Information\_restore{7A2AFE90-FF0C-48A8-A3D9-667F16F0CC74}\RP12;Win32.HLLW.Autoruner.131;Deleted.;

A0039487.INF;D:\System Volume Information\_restore{7A2AFE90-FF0C-48A8-A3D9-667F16F0CC74}\RP12;Win32.HLLW.Autoruner.131;Deleted.;

A0000067.INF;D:\System Volume Information\_restore{7A2AFE90-FF0C-48A8-A3D9-667F16F0CC74}\RP2;Win32.HLLW.Autoruner.131;Deleted.;

A0000147.INF;D:\System Volume Information\_restore{7A2AFE90-FF0C-48A8-A3D9-667F16F0CC74}\RP3;Win32.HLLW.Autoruner.131;Deleted.;

A0000155.INF;D:\System Volume Information\_restore{7A2AFE90-FF0C-48A8-A3D9-667F16F0CC74}\RP4;Win32.HLLW.Autoruner.131;Deleted.;

A0000185.INF;D:\System Volume Information\_restore{7A2AFE90-FF0C-48A8-A3D9-667F16F0CC74}\RP5;Win32.HLLW.Autoruner.131;Deleted.;

A0000222.INF;D:\System Volume Information\_restore{7A2AFE90-FF0C-48A8-A3D9-667F16F0CC74}\RP5;Win32.HLLW.Autoruner.131;Deleted.;

A0000233.INF;D:\System Volume Information\_restore{7A2AFE90-FF0C-48A8-A3D9-667F16F0CC74}\RP6;Win32.HLLW.Autoruner.131;Deleted.;

A0000390.INF;D:\System Volume Information\_restore{7A2AFE90-FF0C-48A8-A3D9-667F16F0CC74}\RP6;Win32.HLLW.Autoruner.131;Deleted.;

A0000415.INF;D:\System Volume Information\_restore{7A2AFE90-FF0C-48A8-A3D9-667F16F0CC74}\RP7;Win32.HLLW.Autoruner.131;Deleted.;

A0000421.INF;D:\System Volume Information\_restore{7A2AFE90-FF0C-48A8-A3D9-667F16F0CC74}\RP8;Win32.HLLW.Autoruner.131;Deleted.;

A0000435.INF;D:\System Volume Information\_restore{7A2AFE90-FF0C-48A8-A3D9-667F16F0CC74}\RP8;Win32.HLLW.Autoruner.131;Deleted.;

A0000441.INF;D:\System Volume Information\_restore{7A2AFE90-FF0C-48A8-A3D9-667F16F0CC74}\RP9;Win32.HLLW.Autoruner.131;Deleted.;

A0000447.INF;D:\System Volume Information\_restore{7E23BCF0-B49B-4603-9C02-A4AED1C84B80}\RP10;Win32.HLLW.Autoruner.131;Deleted.;

A0000462.INF;D:\System Volume Information\_restore{7E23BCF0-B49B-4603-9C02-A4AED1C84B80}\RP10;Win32.HLLW.Autoruner.131;Deleted.;

A0001462.INF;D:\System Volume Information\_restore{7E23BCF0-B49B-4603-9C02-A4AED1C84B80}\RP10;Win32.HLLW.Autoruner.131;Deleted.;

A0001485.INF;D:\System Volume Information\_restore{7E23BCF0-B49B-4603-9C02-A4AED1C84B80}\RP10;Win32.HLLW.Autoruner.131;Deleted.;

A0001512.INF;D:\System Volume Information\_restore{7E23BCF0-B49B-4603-9C02-A4AED1C84B80}\RP10;Win32.HLLW.Autoruner.131;Deleted.;

A0001524.INF;D:\System Volume Information\_restore{7E23BCF0-B49B-4603-9C02-A4AED1C84B80}\RP10;Win32.HLLW.Autoruner.131;Deleted.;

A0001544.INF;D:\System Volume Information\_restore{7E23BCF0-B49B-4603-9C02-A4AED1C84B80}\RP10;Win32.HLLW.Autoruner.131;Deleted.;

A0002556.INF;D:\System Volume Information\_restore{7E23BCF0-B49B-4603-9C02-A4AED1C84B80}\RP10;Win32.HLLW.Autoruner.131;Deleted.;

A0002570.INF;D:\System Volume Information\_restore{7E23BCF0-B49B-4603-9C02-A4AED1C84B80}\RP10;Win32.HLLW.Autoruner.131;Deleted.;

A0002584.INF;D:\System Volume Information\_restore{7E23BCF0-B49B-4603-9C02-A4AED1C84B80}\RP10;Win32.HLLW.Autoruner.131;Deleted.;

A0002598.INF;D:\System Volume Information\_restore{7E23BCF0-B49B-4603-9C02-A4AED1C84B80}\RP10;Win32.HLLW.Autoruner.131;Deleted.;

A0002612.INF;D:\System Volume Information\_restore{7E23BCF0-B49B-4603-9C02-A4AED1C84B80}\RP10;Win32.HLLW.Autoruner.131;Deleted.;

A0002626.INF;D:\System Volume Information\_restore{7E23BCF0-B49B-4603-9C02-A4AED1C84B80}\RP10;Win32.HLLW.Autoruner.131;Deleted.;

A0002639.INF;D:\System Volume Information\_restore{7E23BCF0-B49B-4603-9C02-A4AED1C84B80}\RP10;Win32.HLLW.Autoruner.131;Deleted.;

A0000527.exe;D:\System Volume Information\_restore{A23EAF02-A108-45AB-8A40-CE079A519A4E}\RP6;Archive contains infected objects;Moved.;

A0000527.exe\data009;D:\System Volume Information\_restore{A23EAF02-A108-45AB-8A40-CE079A519A4E}\RP6\A0000527.exe;Program.mIRC.621;;

A0004354.INF;D:\System Volume Information\_restore{B86296AA-1D2B-461F-9801-995BFEF44743}\RP11;Win32.HLLW.Autoruner.131;Deleted.;

A0004367.INF;D:\System Volume Information\_restore{B86296AA-1D2B-461F-9801-995BFEF44743}\RP11;Win32.HLLW.Autoruner.131;Deleted.;

A0004381.INF;D:\System Volume Information\_restore{B86296AA-1D2B-461F-9801-995BFEF44743}\RP11;Win32.HLLW.Autoruner.131;Deleted.;

A0004395.INF;D:\System Volume Information\_restore{B86296AA-1D2B-461F-9801-995BFEF44743}\RP11;Win32.HLLW.Autoruner.131;Deleted.;

A0004416.INF;D:\System Volume Information\_restore{B86296AA-1D2B-461F-9801-995BFEF44743}\RP12;Win32.HLLW.Autoruner.131;Deleted.;

A0006460.INF;D:\System Volume Information\_restore{B86296AA-1D2B-461F-9801-995BFEF44743}\RP12;Win32.HLLW.Autoruner.131;Deleted.;

A0007479.INF;D:\System Volume Information\_restore{B86296AA-1D2B-461F-9801-995BFEF44743}\RP12;Win32.HLLW.Autoruner.131;Deleted.;

A0009478.INF;D:\System Volume Information\_restore{B86296AA-1D2B-461F-9801-995BFEF44743}\RP12;Win32.HLLW.Autoruner.131;Deleted.;

A0011479.INF;D:\System Volume Information\_restore{B86296AA-1D2B-461F-9801-995BFEF44743}\RP12;Win32.HLLW.Autoruner.131;Deleted.;

A0013507.INF;D:\System Volume Information\_restore{B86296AA-1D2B-461F-9801-995BFEF44743}\RP13;Win32.HLLW.Autoruner.131;Deleted.;

A0014505.INF;D:\System Volume Information\_restore{B86296AA-1D2B-461F-9801-995BFEF44743}\RP13;Win32.HLLW.Autoruner.131;Deleted.;

A0014528.INF;D:\System Volume Information\_restore{B86296AA-1D2B-461F-9801-995BFEF44743}\RP13;Win32.HLLW.Autoruner.131;Deleted.;

A0015530.INF;D:\System Volume Information\_restore{B86296AA-1D2B-461F-9801-995BFEF44743}\RP13;Win32.HLLW.Autoruner.131;Deleted.;

A0001092.INF;D:\System Volume Information\_restore{D00B1226-0A1E-42C3-BA26-AEDDFFB059AA}\RP6;Win32.HLLW.Autoruner.131;Deleted.;

A0001106.INF;D:\System Volume Information\_restore{D00B1226-0A1E-42C3-BA26-AEDDFFB059AA}\RP6;Win32.HLLW.Autoruner.131;Deleted.;

A0001118.INF;D:\System Volume Information\_restore{D00B1226-0A1E-42C3-BA26-AEDDFFB059AA}\RP6;Win32.HLLW.Autoruner.131;Deleted.;

A0001130.INF;D:\System Volume Information\_restore{D00B1226-0A1E-42C3-BA26-AEDDFFB059AA}\RP6;Win32.HLLW.Autoruner.131;Deleted.;

A0001142.INF;D:\System Volume Information\_restore{D00B1226-0A1E-42C3-BA26-AEDDFFB059AA}\RP6;Win32.HLLW.Autoruner.131;Deleted.;

A0002142.INF;D:\System Volume Information\_restore{D00B1226-0A1E-42C3-BA26-AEDDFFB059AA}\RP6;Win32.HLLW.Autoruner.131;Deleted.;

A0002154.INF;D:\System Volume Information\_restore{D00B1226-0A1E-42C3-BA26-AEDDFFB059AA}\RP6;Win32.HLLW.Autoruner.131;Deleted.;

A0002166.INF;D:\System Volume Information\_restore{D00B1226-0A1E-42C3-BA26-AEDDFFB059AA}\RP6;Win32.HLLW.Autoruner.131;Deleted.;

A0002178.INF;D:\System Volume Information\_restore{D00B1226-0A1E-42C3-BA26-AEDDFFB059AA}\RP6;Win32.HLLW.Autoruner.131;Deleted.;

A0002191.INF;D:\System Volume Information\_restore{D00B1226-0A1E-42C3-BA26-AEDDFFB059AA}\RP6;Win32.HLLW.Autoruner.131;Deleted.;

A0002203.INF;D:\System Volume Information\_restore{D00B1226-0A1E-42C3-BA26-AEDDFFB059AA}\RP6;Win32.HLLW.Autoruner.131;Deleted.;

A0000610.INF;E:\System Volume Information\_restore{0B6A4FE1-B831-46BE-A554-94D147EAA517}\RP10;Win32.HLLW.Autoruner.131;Deleted.;

A0001605.INF;E:\System Volume Information\_restore{0B6A4FE1-B831-46BE-A554-94D147EAA517}\RP11;Win32.HLLW.Autoruner.131;Deleted.;

A0002586.INF;E:\System Volume Information\_restore{0B6A4FE1-B831-46BE-A554-94D147EAA517}\RP11;Win32.HLLW.Autoruner.131;Deleted.;

A0003587.INF;E:\System Volume Information\_restore{0B6A4FE1-B831-46BE-A554-94D147EAA517}\RP11;Win32.HLLW.Autoruner.131;Deleted.;

A0000530.INF;E:\System Volume Information\_restore{0B6A4FE1-B831-46BE-A554-94D147EAA517}\RP6;Win32.HLLW.Autoruner.131;Deleted.;

A0000537.INF;E:\System Volume Information\_restore{0B6A4FE1-B831-46BE-A554-94D147EAA517}\RP7;Win32.HLLW.Autoruner.131;Deleted.;

A0000554.INF;E:\System Volume Information\_restore{0B6A4FE1-B831-46BE-A554-94D147EAA517}\RP7;Win32.HLLW.Autoruner.131;Deleted.;

A0000566.INF;E:\System Volume Information\_restore{0B6A4FE1-B831-46BE-A554-94D147EAA517}\RP7;Win32.HLLW.Autoruner.131;Deleted.;

A0000573.INF;E:\System Volume Information\_restore{0B6A4FE1-B831-46BE-A554-94D147EAA517}\RP8;Win32.HLLW.Autoruner.131;Deleted.;

A0000590.INF;E:\System Volume Information\_restore{0B6A4FE1-B831-46BE-A554-94D147EAA517}\RP8;Win32.HLLW.Autoruner.131;Deleted.;

A0000599.INF;E:\System Volume Information\_restore{0B6A4FE1-B831-46BE-A554-94D147EAA517}\RP9;Win32.HLLW.Autoruner.131;Deleted.;

A0000189.INF;E:\System Volume Information\_restore{129EDFBE-FF99-4AF1-A33B-4CDB23FB2979}\RP5;Win32.HLLW.Autoruner.131;Deleted.;

A0000202.INF;E:\System Volume Information\_restore{129EDFBE-FF99-4AF1-A33B-4CDB23FB2979}\RP5;Win32.HLLW.Autoruner.131;Deleted.;

A0000214.INF;E:\System Volume Information\_restore{129EDFBE-FF99-4AF1-A33B-4CDB23FB2979}\RP5;Win32.HLLW.Autoruner.131;Deleted.;

A0000221.INF;E:\System Volume Information\_restore{129EDFBE-FF99-4AF1-A33B-4CDB23FB2979}\RP6;Win32.HLLW.Autoruner.131;Deleted.;

A0000238.INF;E:\System Volume Information\_restore{129EDFBE-FF99-4AF1-A33B-4CDB23FB2979}\RP6;Win32.HLLW.Autoruner.131;Deleted.;

A0000256.INF;E:\System Volume Information\_restore{129EDFBE-FF99-4AF1-A33B-4CDB23FB2979}\RP7;Win32.HLLW.Autoruner.131;Deleted.;

A0000272.INF;E:\System Volume Information\_restore{129EDFBE-FF99-4AF1-A33B-4CDB23FB2979}\RP7;Win32.HLLW.Autoruner.131;Deleted.;

A0000284.INF;E:\System Volume Information\_restore{129EDFBE-FF99-4AF1-A33B-4CDB23FB2979}\RP7;Win32.HLLW.Autoruner.131;Deleted.;

A0000015.INF;E:\System Volume Information\_restore{1345B462-7196-41B6-B6EC-34014899BE5C}\RP1;Win32.HLLW.Autoruner.131;Deleted.;

A0000058.INF;E:\System Volume Information\_restore{1345B462-7196-41B6-B6EC-34014899BE5C}\RP1;Win32.HLLW.Autoruner.131;Deleted.;

A0000710.INF;E:\System Volume Information\_restore{1345B462-7196-41B6-B6EC-34014899BE5C}\RP11;Win32.HLLW.Autoruner.131;Deleted.;

A0000736.INF;E:\System Volume Information\_restore{1345B462-7196-41B6-B6EC-34014899BE5C}\RP12;Win32.HLLW.Autoruner.131;Deleted.;

A0000763.INF;E:\System Volume Information\_restore{1345B462-7196-41B6-B6EC-34014899BE5C}\RP13;Win32.HLLW.Autoruner.131;Deleted.;

A0001702.INF;E:\System Volume Information\_restore{1345B462-7196-41B6-B6EC-34014899BE5C}\RP14;Win32.HLLW.Autoruner.131;Deleted.;

A0002681.INF;E:\System Volume Information\_restore{1345B462-7196-41B6-B6EC-34014899BE5C}\RP14;Win32.HLLW.Autoruner.131;Deleted.;

A0002759.INF;E:\System Volume Information\_restore{1345B462-7196-41B6-B6EC-34014899BE5C}\RP15;Win32.HLLW.Autoruner.131;Deleted.;

A0002812.INF;E:\System Volume Information\_restore{1345B462-7196-41B6-B6EC-34014899BE5C}\RP16;Win32.HLLW.Autoruner.131;Deleted.;

A0000075.INF;E:\System Volume Information\_restore{1345B462-7196-41B6-B6EC-34014899BE5C}\RP2;Win32.HLLW.Autoruner.131;Deleted.;

A0002937.INF;E:\System Volume Information\_restore{1345B462-7196-41B6-B6EC-34014899BE5C}\RP20;Win32.HLLW.Autoruner.131;Deleted.;

A0003150.INF;E:\System Volume Information\_restore{1345B462-7196-41B6-B6EC-34014899BE5C}\RP26;Win32.HLLW.Autoruner.131;Deleted.;

A0000139.INF;E:\System Volume Information\_restore{1345B462-7196-41B6-B6EC-34014899BE5C}\RP3;Win32.HLLW.Autoruner.131;Deleted.;

A0003306.INF;E:\System Volume Information\_restore{1345B462-7196-41B6-B6EC-34014899BE5C}\RP31;Win32.HLLW.Autoruner.131;Deleted.;

A0000167.INF;E:\System Volume Information\_restore{1345B462-7196-41B6-B6EC-34014899BE5C}\RP4;Win32.HLLW.Autoruner.131;Deleted.;

A0003763.INF;E:\System Volume Information\_restore{1345B462-7196-41B6-B6EC-34014899BE5C}\RP42;Win32.HLLW.Autoruner.131;Deleted.;

A0004764.INF;E:\System Volume Information\_restore{1345B462-7196-41B6-B6EC-34014899BE5C}\RP42;Win32.HLLW.Autoruner.131;Deleted.;

A0004779.INF;E:\System Volume Information\_restore{1345B462-7196-41B6-B6EC-34014899BE5C}\RP42;Win32.HLLW.Autoruner.131;Deleted.;

A0000185.INF;E:\System Volume Information\_restore{1345B462-7196-41B6-B6EC-34014899BE5C}\RP5;Win32.HLLW.Autoruner.131;Deleted.;

A0000244.INF;E:\System Volume Information\_restore{1345B462-7196-41B6-B6EC-34014899BE5C}\RP5;Win32.HLLW.Autoruner.131;Deleted.;

A0000316.INF;E:\System Volume Information\_restore{1345B462-7196-41B6-B6EC-34014899BE5C}\RP6;Win32.HLLW.Autoruner.131;Deleted.;

A0000547.INF;E:\System Volume Information\_restore{1345B462-7196-41B6-B6EC-34014899BE5C}\RP6;Win32.HLLW.Autoruner.131;Deleted.;

A0000590.INF;E:\System Volume Information\_restore{1345B462-7196-41B6-B6EC-34014899BE5C}\RP7;Win32.HLLW.Autoruner.131;Deleted.;

A0000605.INF;E:\System Volume Information\_restore{1345B462-7196-41B6-B6EC-34014899BE5C}\RP7;Win32.HLLW.Autoruner.131;Deleted.;

A0000612.INF;E:\System Volume Information\_restore{1345B462-7196-41B6-B6EC-34014899BE5C}\RP8;Win32.HLLW.Autoruner.131;Deleted.;

A0000629.INF;E:\System Volume Information\_restore{1345B462-7196-41B6-B6EC-34014899BE5C}\RP8;Win32.HLLW.Autoruner.131;Deleted.;

A0000639.INF;E:\System Volume Information\_restore{1345B462-7196-41B6-B6EC-34014899BE5C}\RP9;Win32.HLLW.Autoruner.131;Deleted.;

A0000693.INF;E:\System Volume Information\_restore{1345B462-7196-41B6-B6EC-34014899BE5C}\RP9;Win32.HLLW.Autoruner.131;Deleted.;

A0001169.INF;E:\System Volume Information\_restore{5B4CDF95-73FB-4AEE-B50A-C8E0EDFB00D5}\RP2;Win32.HLLW.Autoruner.131;Deleted.;

A0001181.INF;E:\System Volume Information\_restore{5B4CDF95-73FB-4AEE-B50A-C8E0EDFB00D5}\RP2;Win32.HLLW.Autoruner.131;Deleted.;

A0000744.INF;E:\System Volume Information\_restore{5DD88F84-DC55-4B90-9C98-B4E376391E7A}\RP15;Win32.HLLW.Autoruner.131;Deleted.;

A0000754.INF;E:\System Volume Information\_restore{5DD88F84-DC55-4B90-9C98-B4E376391E7A}\RP16;Win32.HLLW.Autoruner.131;Deleted.;

A0000861.INF;E:\System Volume Information\_restore{5DD88F84-DC55-4B90-9C98-B4E376391E7A}\RP17;Win32.HLLW.Autoruner.131;Deleted.;

A0000889.INF;E:\System Volume Information\_restore{5DD88F84-DC55-4B90-9C98-B4E376391E7A}\RP19;Win32.HLLW.Autoruner.131;Deleted.;

A0000937.INF;E:\System Volume Information\_restore{5DD88F84-DC55-4B90-9C98-B4E376391E7A}\RP20;Win32.HLLW.Autoruner.131;Deleted.;

A0000973.INF;E:\System Volume Information\_restore{5DD88F84-DC55-4B90-9C98-B4E376391E7A}\RP21;Win32.HLLW.Autoruner.131;Deleted.;

A0001019.INF;E:\System Volume Information\_restore{5DD88F84-DC55-4B90-9C98-B4E376391E7A}\RP22;Win32.HLLW.Autoruner.131;Deleted.;

A0001034.INF;E:\System Volume Information\_restore{5DD88F84-DC55-4B90-9C98-B4E376391E7A}\RP23;Win32.HLLW.Autoruner.131;Deleted.;

A0001104.INF;E:\System Volume Information\_restore{5DD88F84-DC55-4B90-9C98-B4E376391E7A}\RP24;Win32.HLLW.Autoruner.131;Deleted.;

A0001166.INF;E:\System Volume Information\_restore{5DD88F84-DC55-4B90-9C98-B4E376391E7A}\RP25;Win32.HLLW.Autoruner.131;Deleted.;

A0001203.INF;E:\System Volume Information\_restore{5DD88F84-DC55-4B90-9C98-B4E376391E7A}\RP27;Win32.HLLW.Autoruner.131;Deleted.;

A0001256.INF;E:\System Volume Information\_restore{5DD88F84-DC55-4B90-9C98-B4E376391E7A}\RP28;Win32.HLLW.Autoruner.131;Deleted.;

A0001301.INF;E:\System Volume Information\_restore{5DD88F84-DC55-4B90-9C98-B4E376391E7A}\RP30;Win32.HLLW.Autoruner.131;Deleted.;

A0001355.INF;E:\System Volume Information\_restore{5DD88F84-DC55-4B90-9C98-B4E376391E7A}\RP31;Win32.HLLW.Autoruner.131;Deleted.;

A0001388.INF;E:\System Volume Information\_restore{5DD88F84-DC55-4B90-9C98-B4E376391E7A}\RP32;Win32.HLLW.Autoruner.131;Deleted.;

A0001425.INF;E:\System Volume Information\_restore{5DD88F84-DC55-4B90-9C98-B4E376391E7A}\RP33;Win32.HLLW.Autoruner.131;Deleted.;

A0001464.INF;E:\System Volume Information\_restore{5DD88F84-DC55-4B90-9C98-B4E376391E7A}\RP35;Win32.HLLW.Autoruner.131;Deleted.;

A0001516.INF;E:\System Volume Information\_restore{5DD88F84-DC55-4B90-9C98-B4E376391E7A}\RP36;Win32.HLLW.Autoruner.131;Deleted.;

A0001556.INF;E:\System Volume Information\_restore{5DD88F84-DC55-4B90-9C98-B4E376391E7A}\RP37;Win32.HLLW.Autoruner.131;Deleted.;

A0001614.INF;E:\System Volume Information\_restore{5DD88F84-DC55-4B90-9C98-B4E376391E7A}\RP39;Win32.HLLW.Autoruner.131;Deleted.;

A0001652.INF;E:\System Volume Information\_restore{5DD88F84-DC55-4B90-9C98-B4E376391E7A}\RP40;Win32.HLLW.Autoruner.131;Deleted.;

A0001702.INF;E:\System Volume Information\_restore{5DD88F84-DC55-4B90-9C98-B4E376391E7A}\RP41;Win32.HLLW.Autoruner.131;Deleted.;

A0001742.INF;E:\System Volume Information\_restore{5DD88F84-DC55-4B90-9C98-B4E376391E7A}\RP43;Win32.HLLW.Autoruner.131;Deleted.;

A0001787.INF;E:\System Volume Information\_restore{5DD88F84-DC55-4B90-9C98-B4E376391E7A}\RP44;Win32.HLLW.Autoruner.131;Deleted.;

A0001800.INF;E:\System Volume Information\_restore{5DD88F84-DC55-4B90-9C98-B4E376391E7A}\RP45;Win32.HLLW.Autoruner.131;Deleted.;

A0001852.INF;E:\System Volume Information\_restore{5DD88F84-DC55-4B90-9C98-B4E376391E7A}\RP46;Win32.HLLW.Autoruner.131;Deleted.;

A0001922.INF;E:\System Volume Information\_restore{5DD88F84-DC55-4B90-9C98-B4E376391E7A}\RP47;Win32.HLLW.Autoruner.131;Deleted.;

A0001998.INF;E:\System Volume Information\_restore{5DD88F84-DC55-4B90-9C98-B4E376391E7A}\RP48;Win32.HLLW.Autoruner.131;Deleted.;

A0002053.INF;E:\System Volume Information\_restore{5DD88F84-DC55-4B90-9C98-B4E376391E7A}\RP49;Win32.HLLW.Autoruner.131;Deleted.;

A0002085.INF;E:\System Volume Information\_restore{5DD88F84-DC55-4B90-9C98-B4E376391E7A}\RP50;Win32.HLLW.Autoruner.131;Deleted.;

A0002127.INF;E:\System Volume Information\_restore{5DD88F84-DC55-4B90-9C98-B4E376391E7A}\RP51;Win32.HLLW.Autoruner.131;Deleted.;

A0002169.INF;E:\System Volume Information\_restore{5DD88F84-DC55-4B90-9C98-B4E376391E7A}\RP52;Win32.HLLW.Autoruner.131;Deleted.;

A0002222.INF;E:\System Volume Information\_restore{5DD88F84-DC55-4B90-9C98-B4E376391E7A}\RP53;Win32.HLLW.Autoruner.131;Deleted.;

A0002254.INF;E:\System Volume Information\_restore{5DD88F84-DC55-4B90-9C98-B4E376391E7A}\RP54;Win32.HLLW.Autoruner.131;Deleted.;

A0002286.INF;E:\System Volume Information\_restore{5DD88F84-DC55-4B90-9C98-B4E376391E7A}\RP55;Win32.HLLW.Autoruner.131;Deleted.;

A0002318.INF;E:\System Volume Information\_restore{5DD88F84-DC55-4B90-9C98-B4E376391E7A}\RP57;Win32.HLLW.Autoruner.131;Deleted.;

A0002355.INF;E:\System Volume Information\_restore{5DD88F84-DC55-4B90-9C98-B4E376391E7A}\RP58;Win32.HLLW.Autoruner.131;Deleted.;

A0002417.INF;E:\System Volume Information\_restore{5DD88F84-DC55-4B90-9C98-B4E376391E7A}\RP60;Win32.HLLW.Autoruner.131;Deleted.;

A0002455.INF;E:\System Volume Information\_restore{5DD88F84-DC55-4B90-9C98-B4E376391E7A}\RP61;Win32.HLLW.Autoruner.131;Deleted.;

A0002495.INF;E:\System Volume Information\_restore{5DD88F84-DC55-4B90-9C98-B4E376391E7A}\RP62;Win32.HLLW.Autoruner.131;Deleted.;

A0002530.INF;E:\System Volume Information\_restore{5DD88F84-DC55-4B90-9C98-B4E376391E7A}\RP63;Win32.HLLW.Autoruner.131;Deleted.;

A0002562.INF;E:\System Volume Information\_restore{5DD88F84-DC55-4B90-9C98-B4E376391E7A}\RP64;Win32.HLLW.Autoruner.131;Deleted.;

A0002604.INF;E:\System Volume Information\_restore{5DD88F84-DC55-4B90-9C98-B4E376391E7A}\RP65;Win32.HLLW.Autoruner.131;Deleted.;

A0002644.INF;E:\System Volume Information\_restore{5DD88F84-DC55-4B90-9C98-B4E376391E7A}\RP66;Win32.HLLW.Autoruner.131;Deleted.;

A0002678.INF;E:\System Volume Information\_restore{5DD88F84-DC55-4B90-9C98-B4E376391E7A}\RP67;Win32.HLLW.Autoruner.131;Deleted.;

A0002859.INF;E:\System Volume Information\_restore{5DD88F84-DC55-4B90-9C98-B4E376391E7A}\RP67;Win32.HLLW.Autoruner.131;Deleted.;

A0003859.INF;E:\System Volume Information\_restore{5DD88F84-DC55-4B90-9C98-B4E376391E7A}\RP67;Win32.HLLW.Autoruner.131;Deleted.;

A0003867.INF;E:\System Volume Information\_restore{5DD88F84-DC55-4B90-9C98-B4E376391E7A}\RP68;Win32.HLLW.Autoruner.131;Deleted.;

A0003896.INF;E:\System Volume Information\_restore{5DD88F84-DC55-4B90-9C98-B4E376391E7A}\RP69;Win32.HLLW.Autoruner.131;Deleted.;

A0003942.INF;E:\System Volume Information\_restore{5DD88F84-DC55-4B90-9C98-B4E376391E7A}\RP70;Win32.HLLW.Autoruner.131;Deleted.;

A0003981.INF;E:\System Volume Information\_restore{5DD88F84-DC55-4B90-9C98-B4E376391E7A}\RP71;Win32.HLLW.Autoruner.131;Deleted.;

A0003993.INF;E:\System Volume Information\_restore{5DD88F84-DC55-4B90-9C98-B4E376391E7A}\RP72;Win32.HLLW.Autoruner.131;Deleted.;

A0004024.INF;E:\System Volume Information\_restore{5DD88F84-DC55-4B90-9C98-B4E376391E7A}\RP73;Win32.HLLW.Autoruner.131;Deleted.;

A0004045.INF;E:\System Volume Information\_restore{5DD88F84-DC55-4B90-9C98-B4E376391E7A}\RP74;Win32.HLLW.Autoruner.131;Deleted.;

A0004865.INF;E:\System Volume Information\_restore{5DD88F84-DC55-4B90-9C98-B4E376391E7A}\RP74;Win32.HLLW.Autoruner.131;Deleted.;

A0004874.INF;E:\System Volume Information\_restore{5DD88F84-DC55-4B90-9C98-B4E376391E7A}\RP75;Win32.HLLW.Autoruner.131;Deleted.;

A0004890.INF;E:\System Volume Information\_restore{5DD88F84-DC55-4B90-9C98-B4E376391E7A}\RP76;Win32.HLLW.Autoruner.131;Deleted.;

A0004943.INF;E:\System Volume Information\_restore{5DD88F84-DC55-4B90-9C98-B4E376391E7A}\RP79;Win32.HLLW.Autoruner.131;Deleted.;

A0000519.INF;E:\System Volume Information\_restore{5DD88F84-DC55-4B90-9C98-B4E376391E7A}\RP8;Win32.HLLW.Autoruner.131;Deleted.;

A0004965.INF;E:\System Volume Information\_restore{5DD88F84-DC55-4B90-9C98-B4E376391E7A}\RP82;Win32.HLLW.Autoruner.131;Deleted.;

A0005061.INF;E:\System Volume Information\_restore{5DD88F84-DC55-4B90-9C98-B4E376391E7A}\RP84;Win32.HLLW.Autoruner.131;Deleted.;

A0008122.INF;E:\System Volume Information\_restore{5DD88F84-DC55-4B90-9C98-B4E376391E7A}\RP84;Win32.HLLW.Autoruner.131;Deleted.;

A0008138.INF;E:\System Volume Information\_restore{5DD88F84-DC55-4B90-9C98-B4E376391E7A}\RP84;Win32.HLLW.Autoruner.131;Deleted.;

A0008157.INF;E:\System Volume Information\_restore{5DD88F84-DC55-4B90-9C98-B4E376391E7A}\RP84;Win32.HLLW.Autoruner.131;Deleted.;

A0001442.INF;E:\System Volume Information\_restore{7822AE1E-E88E-471A-8819-18A6C64EB057}\RP10;Win32.HLLW.Autoruner.131;Deleted.;

A0001462.INF;E:\System Volume Information\_restore{7822AE1E-E88E-471A-8819-18A6C64EB057}\RP10;Win32.HLLW.Autoruner.131;Deleted.;

A0002522.INF;E:\System Volume Information\_restore{7822AE1E-E88E-471A-8819-18A6C64EB057}\RP11;Win32.HLLW.Autoruner.131;Deleted.;

A0004478.INF;E:\System Volume Information\_restore{7822AE1E-E88E-471A-8819-18A6C64EB057}\RP12;Win32.HLLW.Autoruner.131;Deleted.;

A0005475.INF;E:\System Volume Information\_restore{7822AE1E-E88E-471A-8819-18A6C64EB057}\RP12;Win32.HLLW.Autoruner.131;Deleted.;

A0006475.INF;E:\System Volume Information\_restore{7822AE1E-E88E-471A-8819-18A6C64EB057}\RP12;Win32.HLLW.Autoruner.131;Deleted.;

A0006488.INF;E:\System Volume Information\_restore{7822AE1E-E88E-471A-8819-18A6C64EB057}\RP12;Win32.HLLW.Autoruner.131;Deleted.;

A0006501.INF;E:\System Volume Information\_restore{7822AE1E-E88E-471A-8819-18A6C64EB057}\RP12;Win32.HLLW.Autoruner.131;Deleted.;

A0006514.INF;E:\System Volume Information\_restore{7822AE1E-E88E-471A-8819-18A6C64EB057}\RP12;Win32.HLLW.Autoruner.131;Deleted.;

A0006547.INF;E:\System Volume Information\_restore{7822AE1E-E88E-471A-8819-18A6C64EB057}\RP12;Win32.HLLW.Autoruner.131;Deleted.;

A0007547.INF;E:\System Volume Information\_restore{7822AE1E-E88E-471A-8819-18A6C64EB057}\RP12;Win32.HLLW.Autoruner.131;Deleted.;

A0007646.INF;E:\System Volume Information\_restore{7822AE1E-E88E-471A-8819-18A6C64EB057}\RP13;Win32.HLLW.Autoruner.131;Deleted.;

A0007818.INF;E:\System Volume Information\_restore{7822AE1E-E88E-471A-8819-18A6C64EB057}\RP13;Win32.HLLW.Autoruner.131;Deleted.;

A0007914.INF;E:\System Volume Information\_restore{7822AE1E-E88E-471A-8819-18A6C64EB057}\RP14;Win32.HLLW.Autoruner.131;Deleted.;

A0007951.INF;E:\System Volume Information\_restore{7822AE1E-E88E-471A-8819-18A6C64EB057}\RP14;Win32.HLLW.Autoruner.131;Deleted.;

A0007980.INF;E:\System Volume Information\_restore{7822AE1E-E88E-471A-8819-18A6C64EB057}\RP14;Win32.HLLW.Autoruner.131;Deleted.;

A0008980.INF;E:\System Volume Information\_restore{7822AE1E-E88E-471A-8819-18A6C64EB057}\RP14;Win32.HLLW.Autoruner.131;Deleted.;

A0010980.INF;E:\System Volume Information\_restore{7822AE1E-E88E-471A-8819-18A6C64EB057}\RP14;Win32.HLLW.Autoruner.131;Deleted.;

A0011980.INF;E:\System Volume Information\_restore{7822AE1E-E88E-471A-8819-18A6C64EB057}\RP14;Win32.HLLW.Autoruner.131;Deleted.;

A0012980.INF;E:\System Volume Information\_restore{7822AE1E-E88E-471A-8819-18A6C64EB057}\RP14;Win32.HLLW.Autoruner.131;Deleted.;

A0013980.INF;E:\System Volume Information\_restore{7822AE1E-E88E-471A-8819-18A6C64EB057}\RP14;Win32.HLLW.Autoruner.131;Deleted.;

A0017980.INF;E:\System Volume Information\_restore{7822AE1E-E88E-471A-8819-18A6C64EB057}\RP14;Win32.HLLW.Autoruner.131;Deleted.;

A0018980.INF;E:\System Volume Information\_restore{7822AE1E-E88E-471A-8819-18A6C64EB057}\RP14;Win32.HLLW.Autoruner.131;Deleted.;

A0019008.INF;E:\System Volume Information\_restore{7822AE1E-E88E-471A-8819-18A6C64EB057}\RP14;Win32.HLLW.Autoruner.131;Deleted.;

A0020009.INF;E:\System Volume Information\_restore{7822AE1E-E88E-471A-8819-18A6C64EB057}\RP14;Win32.HLLW.Autoruner.131;Deleted.;

A0021008.INF;E:\System Volume Information\_restore{7822AE1E-E88E-471A-8819-18A6C64EB057}\RP14;Win32.HLLW.Autoruner.131;Deleted.;

A0023008.INF;E:\System Volume Information\_restore{7822AE1E-E88E-471A-8819-18A6C64EB057}\RP14;Win32.HLLW.Autoruner.131;Deleted.;

A0024008.INF;E:\System Volume Information\_restore{7822AE1E-E88E-471A-8819-18A6C64EB057}\RP14;Win32.HLLW.Autoruner.131;Deleted.;

A0025006.INF;E:\System Volume Information\_restore{7822AE1E-E88E-471A-8819-18A6C64EB057}\RP15;Win32.HLLW.Autoruner.131;Deleted.;

A0025024.INF;E:\System Volume Information\_restore{7822AE1E-E88E-471A-8819-18A6C64EB057}\RP15;Win32.HLLW.Autoruner.131;Deleted.;

A0026024.INF;E:\System Volume Information\_restore{7822AE1E-E88E-471A-8819-18A6C64EB057}\RP15;Win32.HLLW.Autoruner.131;Deleted.;

A0026044.INF;E:\System Volume Information\_restore{7822AE1E-E88E-471A-8819-18A6C64EB057}\RP15;Win32.HLLW.Autoruner.131;Deleted.;

A0027044.INF;E:\System Volume Information\_restore{7822AE1E-E88E-471A-8819-18A6C64EB057}\RP15;Win32.HLLW.Autoruner.131;Deleted.;

A0028044.INF;E:\System Volume Information\_restore{7822AE1E-E88E-471A-8819-18A6C64EB057}\RP15;Win32.HLLW.Autoruner.131;Deleted.;

A0029066.INF;E:\System Volume Information\_restore{7822AE1E-E88E-471A-8819-18A6C64EB057}\RP15;Win32.HLLW.Autoruner.131;Deleted.;

A0030066.INF;E:\System Volume Information\_restore{7822AE1E-E88E-471A-8819-18A6C64EB057}\RP15;Win32.HLLW.Autoruner.131;Deleted.;

A0031067.INF;E:\System Volume Information\_restore{7822AE1E-E88E-471A-8819-18A6C64EB057}\RP15;Win32.HLLW.Autoruner.131;Deleted.;

A0033066.INF;E:\System Volume Information\_restore{7822AE1E-E88E-471A-8819-18A6C64EB057}\RP15;Win32.HLLW.Autoruner.131;Deleted.;

A0034066.INF;E:\System Volume Information\_restore{7822AE1E-E88E-471A-8819-18A6C64EB057}\RP15;Win32.HLLW.Autoruner.131;Deleted.;

A0036079.INF;E:\System Volume Information\_restore{7822AE1E-E88E-471A-8819-18A6C64EB057}\RP15;Win32.HLLW.Autoruner.131;Deleted.;

A0038083.INF;E:\System Volume Information\_restore{7822AE1E-E88E-471A-8819-18A6C64EB057}\RP15;Win32.HLLW.Autoruner.131;Deleted.;

A0038101.INF;E:\System Volume Information\_restore{7822AE1E-E88E-471A-8819-18A6C64EB057}\RP15;Win32.HLLW.Autoruner.131;Deleted.;

A0039101.INF;E:\System Volume Information\_restore{7822AE1E-E88E-471A-8819-18A6C64EB057}\RP15;Win32.HLLW.Autoruner.131;Deleted.;

A0040101.INF;E:\System Volume Information\_restore{7822AE1E-E88E-471A-8819-18A6C64EB057}\RP15;Win32.HLLW.Autoruner.131;Deleted.;

A0000306.INF;E:\System Volume Information\_restore{7822AE1E-E88E-471A-8819-18A6C64EB057}\RP6;Win32.HLLW.Autoruner.131;Deleted.;

A0000318.INF;E:\System Volume Information\_restore{7822AE1E-E88E-471A-8819-18A6C64EB057}\RP6;Win32.HLLW.Autoruner.131;Deleted.;

A0000325.INF;E:\System Volume Information\_restore{7822AE1E-E88E-471A-8819-18A6C64EB057}\RP7;Win32.HLLW.Autoruner.131;Deleted.;

A0000351.INF;E:\System Volume Information\_restore{7822AE1E-E88E-471A-8819-18A6C64EB057}\RP7;Win32.HLLW.Autoruner.131;Deleted.;

A0000358.INF;E:\System Volume Information\_restore{7822AE1E-E88E-471A-8819-18A6C64EB057}\RP8;Win32.HLLW.Autoruner.131;Deleted.;

A0000371.INF;E:\System Volume Information\_restore{7822AE1E-E88E-471A-8819-18A6C64EB057}\RP8;Win32.HLLW.Autoruner.131;Deleted.;

A0000406.INF;E:\System Volume Information\_restore{7822AE1E-E88E-471A-8819-18A6C64EB057}\RP8;Win32.HLLW.Autoruner.131;Deleted.;

A0001421.INF;E:\System Volume Information\_restore{7822AE1E-E88E-471A-8819-18A6C64EB057}\RP9;Win32.HLLW.Autoruner.131;Deleted.;

A0000015.INF;E:\System Volume Information\_restore{7A2AFE90-FF0C-48A8-A3D9-667F16F0CC74}\RP1;Win32.HLLW.Autoruner.131;Deleted.;

A0000062.INF;E:\System Volume Information\_restore{7A2AFE90-FF0C-48A8-A3D9-667F16F0CC74}\RP1;Win32.HLLW.Autoruner.131;Deleted.;

A0000452.INF;E:\System Volume Information\_restore{7A2AFE90-FF0C-48A8-A3D9-667F16F0CC74}\RP10;Win32.HLLW.Autoruner.131;Deleted.;

A0001437.INF;E:\System Volume Information\_restore{7A2AFE90-FF0C-48A8-A3D9-667F16F0CC74}\RP10;Win32.HLLW.Autoruner.131;Deleted.;

A0001449.INF;E:\System Volume Information\_restore{7A2AFE90-FF0C-48A8-A3D9-667F16F0CC74}\RP10;Win32.HLLW.Autoruner.131;Deleted.;

A0001462.INF;E:\System Volume Information\_restore{7A2AFE90-FF0C-48A8-A3D9-667F16F0CC74}\RP10;Win32.HLLW.Autoruner.131;Deleted.;

A0003463.INF;E:\System Volume Information\_restore{7A2AFE90-FF0C-48A8-A3D9-667F16F0CC74}\RP10;Win32.HLLW.Autoruner.131;Deleted.;

A0012488.INF;E:\System Volume Information\_restore{7A2AFE90-FF0C-48A8-A3D9-667F16F0CC74}\RP11;Win32.HLLW.Autoruner.131;Deleted.;

A0016488.INF;E:\System Volume Information\_restore{7A2AFE90-FF0C-48A8-A3D9-667F16F0CC74}\RP11;Win32.HLLW.Autoruner.131;Deleted.;

A0022488.INF;E:\System Volume Information\_restore{7A2AFE90-FF0C-48A8-A3D9-667F16F0CC74}\RP11;Win32.HLLW.Autoruner.131;Deleted.;

A0026492.INF;E:\System Volume Information\_restore{7A2AFE90-FF0C-48A8-A3D9-667F16F0CC74}\RP12;Win32.HLLW.Autoruner.131;Deleted.;

A0027488.INF;E:\System Volume Information\_restore{7A2AFE90-FF0C-48A8-A3D9-667F16F0CC74}\RP12;Win32.HLLW.Autoruner.131;Deleted.;

A0032488.INF;E:\System Volume Information\_restore{7A2AFE90-FF0C-48A8-A3D9-667F16F0CC74}\RP12;Win32.HLLW.Autoruner.131;Deleted.;

A0035489.INF;E:\System Volume Information\_restore{7A2AFE90-FF0C-48A8-A3D9-667F16F0CC74}\RP12;Win32.HLLW.Autoruner.131;Deleted.;

A0036491.INF;E:\System Volume Information\_restore{7A2AFE90-FF0C-48A8-A3D9-667F16F0CC74}\RP12;Win32.HLLW.Autoruner.131;Deleted.;

A0037488.INF;E:\System Volume Information\_restore{7A2AFE90-FF0C-48A8-A3D9-667F16F0CC74}\RP12;Win32.HLLW.Autoruner.131;Deleted.;

A0038488.INF;E:\System Volume Information\_restore{7A2AFE90-FF0C-48A8-A3D9-667F16F0CC74}\RP12;Win32.HLLW.Autoruner.131;Deleted.;

A0039488.INF;E:\System Volume Information\_restore{7A2AFE90-FF0C-48A8-A3D9-667F16F0CC74}\RP12;Win32.HLLW.Autoruner.131;Deleted.;

A0000069.INF;E:\System Volume Information\_restore{7A2AFE90-FF0C-48A8-A3D9-667F16F0CC74}\RP2;Win32.HLLW.Autoruner.131;Deleted.;

A0000149.INF;E:\System Volume Information\_restore{7A2AFE90-FF0C-48A8-A3D9-667F16F0CC74}\RP3;Win32.HLLW.Autoruner.131;Deleted.;

A0000157.INF;E:\System Volume Information\_restore{7A2AFE90-FF0C-48A8-A3D9-667F16F0CC74}\RP4;Win32.HLLW.Autoruner.131;Deleted.;

A0000187.INF;E:\System Volume Information\_restore{7A2AFE90-FF0C-48A8-A3D9-667F16F0CC74}\RP5;Win32.HLLW.Autoruner.131;Deleted.;

A0000223.INF;E:\System Volume Information\_restore{7A2AFE90-FF0C-48A8-A3D9-667F16F0CC74}\RP5;Win32.HLLW.Autoruner.131;Deleted.;

A0000235.INF;E:\System Volume Information\_restore{7A2AFE90-FF0C-48A8-A3D9-667F16F0CC74}\RP6;Win32.HLLW.Autoruner.131;Deleted.;

A0000391.INF;E:\System Volume Information\_restore{7A2AFE90-FF0C-48A8-A3D9-667F16F0CC74}\RP6;Win32.HLLW.Autoruner.131;Deleted.;

A0000416.INF;E:\System Volume Information\_restore{7A2AFE90-FF0C-48A8-A3D9-667F16F0CC74}\RP7;Win32.HLLW.Autoruner.131;Deleted.;

A0000423.INF;E:\System Volume Information\_restore{7A2AFE90-FF0C-48A8-A3D9-667F16F0CC74}\RP8;Win32.HLLW.Autoruner.131;Deleted.;

A0000436.INF;E:\System Volume Information\_restore{7A2AFE90-FF0C-48A8-A3D9-667F16F0CC74}\RP8;Win32.HLLW.Autoruner.131;Deleted.;

A0000443.INF;E:\System Volume Information\_restore{7A2AFE90-FF0C-48A8-A3D9-667F16F0CC74}\RP9;Win32.HLLW.Autoruner.131;Deleted.;

A0000449.INF;E:\System Volume Information\_restore{7E23BCF0-B49B-4603-9C02-A4AED1C84B80}\RP10;Win32.HLLW.Autoruner.131;Deleted.;

A0000463.INF;E:\System Volume Information\_restore{7E23BCF0-B49B-4603-9C02-A4AED1C84B80}\RP10;Win32.HLLW.Autoruner.131;Deleted.;

A0001463.INF;E:\System Volume Information\_restore{7E23BCF0-B49B-4603-9C02-A4AED1C84B80}\RP10;Win32.HLLW.Autoruner.131;Deleted.;

A0001513.INF;E:\System Volume Information\_restore{7E23BCF0-B49B-4603-9C02-A4AED1C84B80}\RP10;Win32.HLLW.Autoruner.131;Deleted.;

A0001525.INF;E:\System Volume Information\_restore{7E23BCF0-B49B-4603-9C02-A4AED1C84B80}\RP10;Win32.HLLW.Autoruner.131;Deleted.;

A0001545.INF;E:\System Volume Information\_restore{7E23BCF0-B49B-4603-9C02-A4AED1C84B80}\RP10;Win32.HLLW.Autoruner.131;Deleted.;

A0002557.INF;E:\System Volume Information\_restore{7E23BCF0-B49B-4603-9C02-A4AED1C84B80}\RP10;Win32.HLLW.Autoruner.131;Deleted.;

A0002571.INF;E:\System Volume Information\_restore{7E23BCF0-B49B-4603-9C02-A4AED1C84B80}\RP10;Win32.HLLW.Autoruner.131;Deleted.;

A0002585.INF;E:\System Volume Information\_restore{7E23BCF0-B49B-4603-9C02-A4AED1C84B80}\RP10;Win32.HLLW.Autoruner.131;Deleted.;

A0002599.INF;E:\System Volume Information\_restore{7E23BCF0-B49B-4603-9C02-A4AED1C84B80}\RP10;Win32.HLLW.Autoruner.131;Deleted.;

A0002613.INF;E:\System Volume Information\_restore{7E23BCF0-B49B-4603-9C02-A4AED1C84B80}\RP10;Win32.HLLW.Autoruner.131;Deleted.;

A0002627.INF;E:\System Volume Information\_restore{7E23BCF0-B49B-4603-9C02-A4AED1C84B80}\RP10;Win32.HLLW.Autoruner.131;Deleted.;

A0002640.INF;E:\System Volume Information\_restore{7E23BCF0-B49B-4603-9C02-A4AED1C84B80}\RP10;Win32.HLLW.Autoruner.131;Deleted.;

A0004355.INF;E:\System Volume Information\_restore{B86296AA-1D2B-461F-9801-995BFEF44743}\RP11;Win32.HLLW.Autoruner.131;Deleted.;

A0004368.INF;E:\System Volume Information\_restore{B86296AA-1D2B-461F-9801-995BFEF44743}\RP11;Win32.HLLW.Autoruner.131;Deleted.;

A0004382.INF;E:\System Volume Information\_restore{B86296AA-1D2B-461F-9801-995BFEF44743}\RP11;Win32.HLLW.Autoruner.131;Deleted.;

A0004396.INF;E:\System Volume Information\_restore{B86296AA-1D2B-461F-9801-995BFEF44743}\RP11;Win32.HLLW.Autoruner.131;Deleted.;

A0004418.INF;E:\System Volume Information\_restore{B86296AA-1D2B-461F-9801-995BFEF44743}\RP12;Win32.HLLW.Autoruner.131;Deleted.;

A0006461.INF;E:\System Volume Information\_restore{B86296AA-1D2B-461F-9801-995BFEF44743}\RP12;Win32.HLLW.Autoruner.131;Deleted.;

A0007480.INF;E:\System Volume Information\_restore{B86296AA-1D2B-461F-9801-995BFEF44743}\RP12;Win32.HLLW.Autoruner.131;Deleted.;

A0009479.INF;E:\System Volume Information\_restore{B86296AA-1D2B-461F-9801-995BFEF44743}\RP12;Win32.HLLW.Autoruner.131;Deleted.;

A0011480.INF;E:\System Volume Information\_restore{B86296AA-1D2B-461F-9801-995BFEF44743}\RP12;Win32.HLLW.Autoruner.131;Deleted.;

A0013508.INF;E:\System Volume Information\_restore{B86296AA-1D2B-461F-9801-995BFEF44743}\RP13;Win32.HLLW.Autoruner.131;Deleted.;

A0014506.INF;E:\System Volume Information\_restore{B86296AA-1D2B-461F-9801-995BFEF44743}\RP13;Win32.HLLW.Autoruner.131;Deleted.;

A0014529.INF;E:\System Volume Information\_restore{B86296AA-1D2B-461F-9801-995BFEF44743}\RP13;Win32.HLLW.Autoruner.131;Deleted.;

A0015531.INF;E:\System Volume Information\_restore{B86296AA-1D2B-461F-9801-995BFEF44743}\RP13;Win32.HLLW.Autoruner.131;Deleted.;

A0001093.INF;E:\System Volume Information\_restore{D00B1226-0A1E-42C3-BA26-AEDDFFB059AA}\RP6;Win32.HLLW.Autoruner.131;Deleted.;

A0001107.INF;E:\System Volume Information\_restore{D00B1226-0A1E-42C3-BA26-AEDDFFB059AA}\RP6;Win32.HLLW.Autoruner.131;Deleted.;

A0001119.INF;E:\System Volume Information\_restore{D00B1226-0A1E-42C3-BA26-AEDDFFB059AA}\RP6;Win32.HLLW.Autoruner.131;Deleted.;

A0001131.INF;E:\System Volume Information\_restore{D00B1226-0A1E-42C3-BA26-AEDDFFB059AA}\RP6;Win32.HLLW.Autoruner.131;Deleted.;

A0001143.INF;E:\System Volume Information\_restore{D00B1226-0A1E-42C3-BA26-AEDDFFB059AA}\RP6;Win32.HLLW.Autoruner.131;Deleted.;

A0002143.INF;E:\System Volume Information\_restore{D00B1226-0A1E-42C3-BA26-AEDDFFB059AA}\RP6;Win32.HLLW.Autoruner.131;Deleted.;

A0002155.INF;E:\System Volume Information\_restore{D00B1226-0A1E-42C3-BA26-AEDDFFB059AA}\RP6;Win32.HLLW.Autoruner.131;Deleted.;

A0002167.INF;E:\System Volume Information\_restore{D00B1226-0A1E-42C3-BA26-AEDDFFB059AA}\RP6;Win32.HLLW.Autoruner.131;Deleted.;

A0002179.INF;E:\System Volume Information\_restore{D00B1226-0A1E-42C3-BA26-AEDDFFB059AA}\RP6;Win32.HLLW.Autoruner.131;Deleted.;

A0002192.INF;E:\System Volume Information\_restore{D00B1226-0A1E-42C3-BA26-AEDDFFB059AA}\RP6;Win32.HLLW.Autoruner.131;Deleted.;

A0002204.INF;E:\System Volume Information\_restore{D00B1226-0A1E-42C3-BA26-AEDDFFB059AA}\RP6;Win32.HLLW.Autoruner.131;Deleted.;

A0000612.INF;F:\System Volume Information\_restore{0B6A4FE1-B831-46BE-A554-94D147EAA517}\RP10;Win32.HLLW.Autoruner.131;Deleted.;

A0001607.INF;F:\System Volume Information\_restore{0B6A4FE1-B831-46BE-A554-94D147EAA517}\RP11;Win32.HLLW.Autoruner.131;Deleted.;

A0002587.INF;F:\System Volume Information\_restore{0B6A4FE1-B831-46BE-A554-94D147EAA517}\RP11;Win32.HLLW.Autoruner.131;Deleted.;

A0003588.INF;F:\System Volume Information\_restore{0B6A4FE1-B831-46BE-A554-94D147EAA517}\RP11;Win32.HLLW.Autoruner.131;Deleted.;

A0000531.INF;F:\System Volume Information\_restore{0B6A4FE1-B831-46BE-A554-94D147EAA517}\RP6;Win32.HLLW.Autoruner.131;Deleted.;

A0000539.INF;F:\System Volume Information\_restore{0B6A4FE1-B831-46BE-A554-94D147EAA517}\RP7;Win32.HLLW.Autoruner.131;Deleted.;

A0000555.INF;F:\System Volume Information\_restore{0B6A4FE1-B831-46BE-A554-94D147EAA517}\RP7;Win32.HLLW.Autoruner.131;Deleted.;

A0000567.INF;F:\System Volume Information\_restore{0B6A4FE1-B831-46BE-A554-94D147EAA517}\RP7;Win32.HLLW.Autoruner.131;Deleted.;

A0000575.INF;F:\System Volume Information\_restore{0B6A4FE1-B831-46BE-A554-94D147EAA517}\RP8;Win32.HLLW.Autoruner.131;Deleted.;

A0000591.INF;F:\System Volume Information\_restore{0B6A4FE1-B831-46BE-A554-94D147EAA517}\RP8;Win32.HLLW.Autoruner.131;Deleted.;

A0000601.INF;F:\System Volume Information\_restore{0B6A4FE1-B831-46BE-A554-94D147EAA517}\RP9;Win32.HLLW.Autoruner.131;Deleted.;

A0000190.INF;F:\System Volume Information\_restore{129EDFBE-FF99-4AF1-A33B-4CDB23FB2979}\RP5;Win32.HLLW.Autoruner.131;Deleted.;

A0000203.INF;F:\System Volume Information\_restore{129EDFBE-FF99-4AF1-A33B-4CDB23FB2979}\RP5;Win32.HLLW.Autoruner.131;Deleted.;

A0000215.INF;F:\System Volume Information\_restore{129EDFBE-FF99-4AF1-A33B-4CDB23FB2979}\RP5;Win32.HLLW.Autoruner.131;Deleted.;

A0000223.INF;F:\System Volume Information\_restore{129EDFBE-FF99-4AF1-A33B-4CDB23FB2979}\RP6;Win32.HLLW.Autoruner.131;Deleted.;

A0000239.INF;F:\System Volume Information\_restore{129EDFBE-FF99-4AF1-A33B-4CDB23FB2979}\RP6;Win32.HLLW.Autoruner.131;Deleted.;

A0000257.INF;F:\System Volume Information\_restore{129EDFBE-FF99-4AF1-A33B-4CDB23FB2979}\RP7;Win32.HLLW.Autoruner.131;Deleted.;

A0000273.INF;F:\System Volume Information\_restore{129EDFBE-FF99-4AF1-A33B-4CDB23FB2979}\RP7;Win32.HLLW.Autoruner.131;Deleted.;

A0000285.INF;F:\System Volume Information\_restore{129EDFBE-FF99-4AF1-A33B-4CDB23FB2979}\RP7;Win32.HLLW.Autoruner.131;Deleted.;

A0000016.INF;F:\System Volume Information\_restore{1345B462-7196-41B6-B6EC-34014899BE5C}\RP1;Win32.HLLW.Autoruner.131;Deleted.;

A0000059.INF;F:\System Volume Information\_restore{1345B462-7196-41B6-B6EC-34014899BE5C}\RP1;Win32.HLLW.Autoruner.131;Deleted.;

A0000712.INF;F:\System Volume Information\_restore{1345B462-7196-41B6-B6EC-34014899BE5C}\RP11;Win32.HLLW.Autoruner.131;Deleted.;

A0000738.INF;F:\System Volume Information\_restore{1345B462-7196-41B6-B6EC-34014899BE5C}\RP12;Win32.HLLW.Autoruner.131;Deleted.;

A0000765.INF;F:\System Volume Information\_restore{1345B462-7196-41B6-B6EC-34014899BE5C}\RP13;Win32.HLLW.Autoruner.131;Deleted.;

A0001704.INF;F:\System Volume Information\_restore{1345B462-7196-41B6-B6EC-34014899BE5C}\RP14;Win32.HLLW.Autoruner.131;Deleted.;

A0002682.INF;F:\System Volume Information\_restore{1345B462-7196-41B6-B6EC-34014899BE5C}\RP14;Win32.HLLW.Autoruner.131;Deleted.;

A0002760.INF;F:\System Volume Information\_restore{1345B462-7196-41B6-B6EC-34014899BE5C}\RP15;Win32.HLLW.Autoruner.131;Deleted.;

A0000077.INF;F:\System Volume Information\_restore{1345B462-7196-41B6-B6EC-34014899BE5C}\RP2;Win32.HLLW.Autoruner.131;Deleted.;

A0000141.INF;F:\System Volume Information\_restore{1345B462-7196-41B6-B6EC-34014899BE5C}\RP3;Win32.HLLW.Autoruner.131;Deleted.;

A0000169.INF;F:\System Volume Information\_restore{1345B462-7196-41B6-B6EC-34014899BE5C}\RP4;Win32.HLLW.Autoruner.131;Deleted.;

A0003749.INF;F:\System Volume Information\_restore{1345B462-7196-41B6-B6EC-34014899BE5C}\RP42;Win32.HLLW.Autoruner.131;Deleted.;

A0003764.INF;F:\System Volume Information\_restore{1345B462-7196-41B6-B6EC-34014899BE5C}\RP42;Win32.HLLW.Autoruner.131;Deleted.;

A0004765.INF;F:\System Volume Information\_restore{1345B462-7196-41B6-B6EC-34014899BE5C}\RP42;Win32.HLLW.Autoruner.131;Deleted.;

A0004780.INF;F:\System Volume Information\_restore{1345B462-7196-41B6-B6EC-34014899BE5C}\RP42;Win32.HLLW.Autoruner.131;Deleted.;

A0000187.INF;F:\System Volume Information\_restore{1345B462-7196-41B6-B6EC-34014899BE5C}\RP5;Win32.HLLW.Autoruner.131;Deleted.;

A0000245.INF;F:\System Volume Information\_restore{1345B462-7196-41B6-B6EC-34014899BE5C}\RP5;Win32.HLLW.Autoruner.131;Deleted.;

A0000318.INF;F:\System Volume Information\_restore{1345B462-7196-41B6-B6EC-34014899BE5C}\RP6;Win32.HLLW.Autoruner.131;Deleted.;

A0000552.INF;F:\System Volume Information\_restore{1345B462-7196-41B6-B6EC-34014899BE5C}\RP6;Win32.HLLW.Autoruner.131;Deleted.;

A0000592.INF;F:\System Volume Information\_restore{1345B462-7196-41B6-B6EC-34014899BE5C}\RP7;Win32.HLLW.Autoruner.131;Deleted.;

A0000606.INF;F:\System Volume Information\_restore{1345B462-7196-41B6-B6EC-34014899BE5C}\RP7;Win32.HLLW.Autoruner.131;Deleted.;

A0000614.INF;F:\System Volume Information\_restore{1345B462-7196-41B6-B6EC-34014899BE5C}\RP8;Win32.HLLW.Autoruner.131;Deleted.;

A0000630.INF;F:\System Volume Information\_restore{1345B462-7196-41B6-B6EC-34014899BE5C}\RP8;Win32.HLLW.Autoruner.131;Deleted.;

A0000641.INF;F:\System Volume Information\_restore{1345B462-7196-41B6-B6EC-34014899BE5C}\RP9;Win32.HLLW.Autoruner.131;Deleted.;

A0000694.INF;F:\System Volume Information\_restore{1345B462-7196-41B6-B6EC-34014899BE5C}\RP9;Win32.HLLW.Autoruner.131;Deleted.;

A0001170.INF;F:\System Volume Information\_restore{5B4CDF95-73FB-4AEE-B50A-C8E0EDFB00D5}\RP2;Win32.HLLW.Autoruner.131;Deleted.;

A0001182.INF;F:\System Volume Information\_restore{5B4CDF95-73FB-4AEE-B50A-C8E0EDFB00D5}\RP2;Win32.HLLW.Autoruner.131;Deleted.;

A0000745.INF;F:\System Volume Information\_restore{5DD88F84-DC55-4B90-9C98-B4E376391E7A}\RP15;Win32.HLLW.Autoruner.131;Deleted.;

A0000756.INF;F:\System Volume Information\_restore{5DD88F84-DC55-4B90-9C98-B4E376391E7A}\RP16;Win32.HLLW.Autoruner.131;Deleted.;

A0000863.INF;F:\System Volume Information\_restore{5DD88F84-DC55-4B90-9C98-B4E376391E7A}\RP17;Win32.HLLW.Autoruner.131;Deleted.;

A0000891.INF;F:\System Volume Information\_restore{5DD88F84-DC55-4B90-9C98-B4E376391E7A}\RP19;Win32.HLLW.Autoruner.131;Deleted.;

A0000939.INF;F:\System Volume Information\_restore{5DD88F84-DC55-4B90-9C98-B4E376391E7A}\RP20;Win32.HLLW.Autoruner.131;Deleted.;

A0000975.INF;F:\System Volume Information\_restore{5DD88F84-DC55-4B90-9C98-B4E376391E7A}\RP21;Win32.HLLW.Autoruner.131;Deleted.;

A0001021.INF;F:\System Volume Information\_restore{5DD88F84-DC55-4B90-9C98-B4E376391E7A}\RP22;Win32.HLLW.Autoruner.131;Deleted.;

A0001036.INF;F:\System Volume Information\_restore{5DD88F84-DC55-4B90-9C98-B4E376391E7A}\RP23;Win32.HLLW.Autoruner.131;Deleted.;

A0001106.INF;F:\System Volume Information\_restore{5DD88F84-DC55-4B90-9C98-B4E376391E7A}\RP24;Win32.HLLW.Autoruner.131;Deleted.;

A0001168.INF;F:\System Volume Information\_restore{5DD88F84-DC55-4B90-9C98-B4E376391E7A}\RP25;Win32.HLLW.Autoruner.131;Deleted.;

A0001205.INF;F:\System Volume Information\_restore{5DD88F84-DC55-4B90-9C98-B4E376391E7A}\RP27;Win32.HLLW.Autoruner.131;Deleted.;

A0001258.INF;F:\System Volume Information\_restore{5DD88F84-DC55-4B90-9C98-B4E376391E7A}\RP28;Win32.HLLW.Autoruner.131;Deleted.;

A0001303.INF;F:\System Volume Information\_restore{5DD88F84-DC55-4B90-9C98-B4E376391E7A}\RP30;Win32.HLLW.Autoruner.131;Deleted.;

A0001357.INF;F:\System Volume Information\_restore{5DD88F84-DC55-4B90-9C98-B4E376391E7A}\RP31;Win32.HLLW.Autoruner.131;Deleted.;

A0001390.INF;F:\System Volume Information\_restore{5DD88F84-DC55-4B90-9C98-B4E376391E7A}\RP32;Win32.HLLW.Autoruner.131;Deleted.;

A0001427.INF;F:\System Volume Information\_restore{5DD88F84-DC55-4B90-9C98-B4E376391E7A}\RP33;Win32.HLLW.Autoruner.131;Deleted.;

A0001466.INF;F:\System Volume Information\_restore{5DD88F84-DC55-4B90-9C98-B4E376391E7A}\RP35;Win32.HLLW.Autoruner.131;Deleted.;

A0001518.INF;F:\System Volume Information\_restore{5DD88F84-DC55-4B90-9C98-B4E376391E7A}\RP36;Win32.HLLW.Autoruner.131;Deleted.;

A0001558.INF;F:\System Volume Information\_restore{5DD88F84-DC55-4B90-9C98-B4E376391E7A}\RP37;Win32.HLLW.Autoruner.131;Deleted.;

A0001616.INF;F:\System Volume Information\_restore{5DD88F84-DC55-4B90-9C98-B4E376391E7A}\RP39;Win32.HLLW.Autoruner.131;Deleted.;

A0001654.INF;F:\System Volume Information\_restore{5DD88F84-DC55-4B90-9C98-B4E376391E7A}\RP40;Win32.HLLW.Autoruner.131;Deleted.;

A0001704.INF;F:\System Volume Information\_restore{5DD88F84-DC55-4B90-9C98-B4E376391E7A}\RP41;Win32.HLLW.Autoruner.131;Deleted.;

A0001744.INF;F:\System Volume Information\_restore{5DD88F84-DC55-4B90-9C98-B4E376391E7A}\RP43;Win32.HLLW.Autoruner.131;Deleted.;

A0001789.INF;F:\System Volume Information\_restore{5DD88F84-DC55-4B90-9C98-B4E376391E7A}\RP44;Win32.HLLW.Autoruner.131;Deleted.;

A0001802.INF;F:\System Volume Information\_restore{5DD88F84-DC55-4B90-9C98-B4E376391E7A}\RP45;Win32.HLLW.Autoruner.131;Deleted.;

A0001854.INF;F:\System Volume Information\_restore{5DD88F84-DC55-4B90-9C98-B4E376391E7A}\RP46;Win32.HLLW.Autoruner.131;Deleted.;

A0001924.INF;F:\System Volume Information\_restore{5DD88F84-DC55-4B90-9C98-B4E376391E7A}\RP47;Win32.HLLW.Autoruner.131;Deleted.;

A0002000.INF;F:\System Volume Information\_restore{5DD88F84-DC55-4B90-9C98-B4E376391E7A}\RP48;Win32.HLLW.Autoruner.131;Deleted.;

A0002055.INF;F:\System Volume Information\_restore{5DD88F84-DC55-4B90-9C98-B4E376391E7A}\RP49;Win32.HLLW.Autoruner.131;Deleted.;

A0002087.INF;F:\System Volume Information\_restore{5DD88F84-DC55-4B90-9C98-B4E376391E7A}\RP50;Win32.HLLW.Autoruner.131;Deleted.;

A0002129.INF;F:\System Volume Information\_restore{5DD88F84-DC55-4B90-9C98-B4E376391E7A}\RP51;Win32.HLLW.Autoruner.131;Deleted.;

A0002171.INF;F:\System Volume Information\_restore{5DD88F84-DC55-4B90-9C98-B4E376391E7A}\RP52;Win32.HLLW.Autoruner.131;Deleted.;

A0002224.INF;F:\System Volume Information\_restore{5DD88F84-DC55-4B90-9C98-B4E376391E7A}\RP53;Win32.HLLW.Autoruner.131;Deleted.;

A0002256.INF;F:\System Volume Information\_restore{5DD88F84-DC55-4B90-9C98-B4E376391E7A}\RP54;Win32.HLLW.Autoruner.131;Deleted.;

A0002288.INF;F:\System Volume Information\_restore{5DD88F84-DC55-4B90-9C98-B4E376391E7A}\RP55;Win32.HLLW.Autoruner.131;Deleted.;

A0002320.INF;F:\System Volume Information\_restore{5DD88F84-DC55-4B90-9C98-B4E376391E7A}\RP57;Win32.HLLW.Autoruner.131;Deleted.;

A0002357.INF;F:\System Volume Information\_restore{5DD88F84-DC55-4B90-9C98-B4E376391E7A}\RP58;Win32.HLLW.Autoruner.131;Deleted.;

A0002419.INF;F:\System Volume Information\_restore{5DD88F84-DC55-4B90-9C98-B4E376391E7A}\RP60;Win32.HLLW.Autoruner.131;Deleted.;

A0002457.INF;F:\System Volume Information\_restore{5DD88F84-DC55-4B90-9C98-B4E376391E7A}\RP61;Win32.HLLW.Autoruner.131;Deleted.;

A0002497.INF;F:\System Volume Information\_restore{5DD88F84-DC55-4B90-9C98-B4E376391E7A}\RP62;Win32.HLLW.Autoruner.131;Deleted.;

A0002532.INF;F:\System Volume Information\_restore{5DD88F84-DC55-4B90-9C98-B4E376391E7A}\RP63;Win32.HLLW.Autoruner.131;Deleted.;

A0002564.INF;F:\System Volume Information\_restore{5DD88F84-DC55-4B90-9C98-B4E376391E7A}\RP64;Win32.HLLW.Autoruner.131;Deleted.;

A0002606.INF;F:\System Volume Information\_restore{5DD88F84-DC55-4B90-9C98-B4E376391E7A}\RP65;Win32.HLLW.Autoruner.131;Deleted.;

A0002646.INF;F:\System Volume Information\_restore{5DD88F84-DC55-4B90-9C98-B4E376391E7A}\RP66;Win32.HLLW.Autoruner.131;Deleted.;

A0002680.INF;F:\System Volume Information\_restore{5DD88F84-DC55-4B90-9C98-B4E376391E7A}\RP67;Win32.HLLW.Autoruner.131;Deleted.;

A0002860.INF;F:\System Volume Information\_restore{5DD88F84-DC55-4B90-9C98-B4E376391E7A}\RP67;Win32.HLLW.Autoruner.131;Deleted.;

A0003860.INF;F:\System Volume Information\_restore{5DD88F84-DC55-4B90-9C98-B4E376391E7A}\RP67;Win32.HLLW.Autoruner.131;Deleted.;

A0003869.INF;F:\System Volume Information\_restore{5DD88F84-DC55-4B90-9C98-B4E376391E7A}\RP68;Win32.HLLW.Autoruner.131;Deleted.;

A0003898.INF;F:\System Volume Information\_restore{5DD88F84-DC55-4B90-9C98-B4E376391E7A}\RP69;Win32.HLLW.Autoruner.131;Deleted.;

A0003945.INF;F:\System Volume Information\_restore{5DD88F84-DC55-4B90-9C98-B4E376391E7A}\RP70;Win32.HLLW.Autoruner.131;Deleted.;

A0003983.INF;F:\System Volume Information\_restore{5DD88F84-DC55-4B90-9C98-B4E376391E7A}\RP71;Win32.HLLW.Autoruner.131;Deleted.;

A0003995.INF;F:\System Volume Information\_restore{5DD88F84-DC55-4B90-9C98-B4E376391E7A}\RP72;Win32.HLLW.Autoruner.131;Deleted.;

A0004027.INF;F:\System Volume Information\_restore{5DD88F84-DC55-4B90-9C98-B4E376391E7A}\RP73;Win32.HLLW.Autoruner.131;Deleted.;

A0004047.INF;F:\System Volume Information\_restore{5DD88F84-DC55-4B90-9C98-B4E376391E7A}\RP74;Win32.HLLW.Autoruner.131;Deleted.;

A0004866.INF;F:\System Volume Information\_restore{5DD88F84-DC55-4B90-9C98-B4E376391E7A}\RP74;Win32.HLLW.Autoruner.131;Deleted.;

A0004876.INF;F:\System Volume Information\_restore{5DD88F84-DC55-4B90-9C98-B4E376391E7A}\RP75;Win32.HLLW.Autoruner.131;Deleted.;

A0004892.INF;F:\System Volume Information\_restore{5DD88F84-DC55-4B90-9C98-B4E376391E7A}\RP76;Win32.HLLW.Autoruner.131;Deleted.;

A0004945.INF;F:\System Volume Information\_restore{5DD88F84-DC55-4B90-9C98-B4E376391E7A}\RP79;Win32.HLLW.Autoruner.131;Deleted.;

A0000520.INF;F:\System Volume Information\_restore{5DD88F84-DC55-4B90-9C98-B4E376391E7A}\RP8;Win32.HLLW.Autoruner.131;Deleted.;

A0004967.INF;F:\System Volume Information\_restore{5DD88F84-DC55-4B90-9C98-B4E376391E7A}\RP82;Win32.HLLW.Autoruner.131;Deleted.;

A0005063.INF;F:\System Volume Information\_restore{5DD88F84-DC55-4B90-9C98-B4E376391E7A}\RP84;Win32.HLLW.Autoruner.131;Deleted.;

A0008123.INF;F:\System Volume Information\_restore{5DD88F84-DC55-4B90-9C98-B4E376391E7A}\RP84;Win32.HLLW.Autoruner.131;Deleted.;

A0008139.INF;F:\System Volume Information\_restore{5DD88F84-DC55-4B90-9C98-B4E376391E7A}\RP84;Win32.HLLW.Autoruner.131;Deleted.;

A0008158.INF;F:\System Volume Information\_restore{5DD88F84-DC55-4B90-9C98-B4E376391E7A}\RP84;Win32.HLLW.Autoruner.131;Deleted.;

A0001444.INF;F:\System Volume Information\_restore{7822AE1E-E88E-471A-8819-18A6C64EB057}\RP10;Win32.HLLW.Autoruner.131;Deleted.;

A0001463.INF;F:\System Volume Information\_restore{7822AE1E-E88E-471A-8819-18A6C64EB057}\RP10;Win32.HLLW.Autoruner.131;Deleted.;

A0002524.INF;F:\System Volume Information\_restore{7822AE1E-E88E-471A-8819-18A6C64EB057}\RP11;Win32.HLLW.Autoruner.131;Deleted.;

A0004479.INF;F:\System Volume Information\_restore{7822AE1E-E88E-471A-8819-18A6C64EB057}\RP12;Win32.HLLW.Autoruner.131;Deleted.;

A0006476.INF;F:\System Volume Information\_restore{7822AE1E-E88E-471A-8819-18A6C64EB057}\RP12;Win32.HLLW.Autoruner.131;Deleted.;

A0006489.INF;F:\System Volume Information\_restore{7822AE1E-E88E-471A-8819-18A6C64EB057}\RP12;Win32.HLLW.Autoruner.131;Deleted.;

A0006502.INF;F:\System Volume Information\_restore{7822AE1E-E88E-471A-8819-18A6C64EB057}\RP12;Win32.HLLW.Autoruner.131;Deleted.;

A0006515.INF;F:\System Volume Information\_restore{7822AE1E-E88E-471A-8819-18A6C64EB057}\RP12;Win32.HLLW.Autoruner.131;Deleted.;

A0006548.INF;F:\System Volume Information\_restore{7822AE1E-E88E-471A-8819-18A6C64EB057}\RP12;Win32.HLLW.Autoruner.131;Deleted.;

A0007548.INF;F:\System Volume Information\_restore{7822AE1E-E88E-471A-8819-18A6C64EB057}\RP12;Win32.HLLW.Autoruner.131;Deleted.;

A0007648.INF;F:\System Volume Information\_restore{7822AE1E-E88E-471A-8819-18A6C64EB057}\RP13;Win32.HLLW.Autoruner.131;Deleted.;

A0007819.INF;F:\System Volume Information\_restore{7822AE1E-E88E-471A-8819-18A6C64EB057}\RP13;Win32.HLLW.Autoruner.131;Deleted.;

A0007916.INF;F:\System Volume Information\_restore{7822AE1E-E88E-471A-8819-18A6C64EB057}\RP14;Win32.HLLW.Autoruner.131;Deleted.;

A0007952.INF;F:\System Volume Information\_restore{7822AE1E-E88E-471A-8819-18A6C64EB057}\RP14;Win32.HLLW.Autoruner.131;Deleted.;

A0007981.INF;F:\System Volume Information\_restore{7822AE1E-E88E-471A-8819-18A6C64EB057}\RP14;Win32.HLLW.Autoruner.131;Deleted.;

A0008981.INF;F:\System Volume Information\_restore{7822AE1E-E88E-471A-8819-18A6C64EB057}\RP14;Win32.HLLW.Autoruner.131;Deleted.;

A0010981.INF;F:\System Volume Information\_restore{7822AE1E-E88E-471A-8819-18A6C64EB057}\RP14;Win32.HLLW.Autoruner.131;Deleted.;

A0011981.INF;F:\System Volume Information\_restore{7822AE1E-E88E-471A-8819-18A6C64EB057}\RP14;Win32.HLLW.Autoruner.131;Deleted.;

A0012981.INF;F:\System Volume Information\_restore{7822AE1E-E88E-471A-8819-18A6C64EB057}\RP14;Win32.HLLW.Autoruner.131;Deleted.;

A0013981.INF;F:\System Volume Information\_restore{7822AE1E-E88E-471A-8819-18A6C64EB057}\RP14;Win32.HLLW.Autoruner.131;Deleted.;

A0017981.INF;F:\System Volume Information\_restore{7822AE1E-E88E-471A-8819-18A6C64EB057}\RP14;Win32.HLLW.Autoruner.131;Deleted.;

A0018981.INF;F:\System Volume Information\_restore{7822AE1E-E88E-471A-8819-18A6C64EB057}\RP14;Win32.HLLW.Autoruner.131;Deleted.;

A0019009.INF;F:\System Volume Information\_restore{7822AE1E-E88E-471A-8819-18A6C64EB057}\RP14;Win32.HLLW.Autoruner.131;Deleted.;

A0020010.INF;F:\System Volume Information\_restore{7822AE1E-E88E-471A-8819-18A6C64EB057}\RP14;Win32.HLLW.Autoruner.131;Deleted.;

A0021009.INF;F:\System Volume Information\_restore{7822AE1E-E88E-471A-8819-18A6C64EB057}\RP14;Win32.HLLW.Autoruner.131;Deleted.;

A0024009.INF;F:\System Volume Information\_restore{7822AE1E-E88E-471A-8819-18A6C64EB057}\RP14;Win32.HLLW.Autoruner.131;Deleted.;

A0025007.INF;F:\System Volume Information\_restore{7822AE1E-E88E-471A-8819-18A6C64EB057}\RP15;Win32.HLLW.Autoruner.131;Deleted.;

A0025025.INF;F:\System Volume Information\_restore{7822AE1E-E88E-471A-8819-18A6C64EB057}\RP15;Win32.HLLW.Autoruner.131;Deleted.;

A0026025.INF;F:\System Volume Information\_restore{7822AE1E-E88E-471A-8819-18A6C64EB057}\RP15;Win32.HLLW.Autoruner.131;Deleted.;

A0026045.INF;F:\System Volume Information\_restore{7822AE1E-E88E-471A-8819-18A6C64EB057}\RP15;Win32.HLLW.Autoruner.131;Deleted.;

A0027045.INF;F:\System Volume Information\_restore{7822AE1E-E88E-471A-8819-18A6C64EB057}\RP15;Win32.HLLW.Autoruner.131;Deleted.;

A0028045.INF;F:\System Volume Information\_restore{7822AE1E-E88E-471A-8819-18A6C64EB057}\RP15;Win32.HLLW.Autoruner.131;Deleted.;

A0029067.INF;F:\System Volume Information\_restore{7822AE1E-E88E-471A-8819-18A6C64EB057}\RP15;Win32.HLLW.Autoruner.131;Deleted.;

A0030067.INF;F:\System Volume Information\_restore{7822AE1E-E88E-471A-8819-18A6C64EB057}\RP15;Win32.HLLW.Autoruner.131;Deleted.;

A0031068.INF;F:\System Volume Information\_restore{7822AE1E-E88E-471A-8819-18A6C64EB057}\RP15;Win32.HLLW.Autoruner.131;Deleted.;

A0033067.INF;F:\System Volume Information\_restore{7822AE1E-E88E-471A-8819-18A6C64EB057}\RP15;Win32.HLLW.Autoruner.131;Deleted.;

A0034067.INF;F:\System Volume Information\_restore{7822AE1E-E88E-471A-8819-18A6C64EB057}\RP15;Win32.HLLW.Autoruner.131;Deleted.;

A0036080.INF;F:\System Volume Information\_restore{7822AE1E-E88E-471A-8819-18A6C64EB057}\RP15;Win32.HLLW.Autoruner.131;Deleted.;

A0038084.INF;F:\System Volume Information\_restore{7822AE1E-E88E-471A-8819-18A6C64EB057}\RP15;Win32.HLLW.Autoruner.131;Deleted.;

A0038102.INF;F:\System Volume Information\_restore{7822AE1E-E88E-471A-8819-18A6C64EB057}\RP15;Win32.HLLW.Autoruner.131;Deleted.;

A0039102.INF;F:\System Volume Information\_restore{7822AE1E-E88E-471A-8819-18A6C64EB057}\RP15;Win32.HLLW.Autoruner.131;Deleted.;

A0040102.INF;F:\System Volume Information\_restore{7822AE1E-E88E-471A-8819-18A6C64EB057}\RP15;Win32.HLLW.Autoruner.131;Deleted.;

A0000307.INF;F:\System Volume Information\_restore{7822AE1E-E88E-471A-8819-18A6C64EB057}\RP6;Win32.HLLW.Autoruner.131;Deleted.;

A0000319.INF;F:\System Volume Information\_restore{7822AE1E-E88E-471A-8819-18A6C64EB057}\RP6;Win32.HLLW.Autoruner.131;Deleted.;

A0000327.INF;F:\System Volume Information\_restore{7822AE1E-E88E-471A-8819-18A6C64EB057}\RP7;Win32.HLLW.Autoruner.131;Deleted.;

A0000352.INF;F:\System Volume Information\_restore{7822AE1E-E88E-471A-8819-18A6C64EB057}\RP7;Win32.HLLW.Autoruner.131;Deleted.;

A0000360.INF;F:\System Volume Information\_restore{7822AE1E-E88E-471A-8819-18A6C64EB057}\RP8;Win32.HLLW.Autoruner.131;Deleted.;

A0000372.INF;F:\System Volume Information\_restore{7822AE1E-E88E-471A-8819-18A6C64EB057}\RP8;Win32.HLLW.Autoruner.131;Deleted.;

A0000407.INF;F:\System Volume Information\_restore{7822AE1E-E88E-471A-8819-18A6C64EB057}\RP8;Win32.HLLW.Autoruner.131;Deleted.;

A0001423.INF;F:\System Volume Information\_restore{7822AE1E-E88E-471A-8819-18A6C64EB057}\RP9;Win32.HLLW.Autoruner.131;Deleted.;

A0000016.INF;F:\System Volume Information\_restore{7A2AFE90-FF0C-48A8-A3D9-667F16F0CC74}\RP1;Win32.HLLW.Autoruner.131;Deleted.;

A0000063.INF;F:\System Volume Information\_restore{7A2AFE90-FF0C-48A8-A3D9-667F16F0CC74}\RP1;Win32.HLLW.Autoruner.131;Deleted.;

A0000454.INF;F:\System Volume Information\_restore{7A2AFE90-FF0C-48A8-A3D9-667F16F0CC74}\RP10;Win32.HLLW.Autoruner.131;Deleted.;

A0001438.INF;F:\System Volume Information\_restore{7A2AFE90-FF0C-48A8-A3D9-667F16F0CC74}\RP10;Win32.HLLW.Autoruner.131;Deleted.;

A0001450.INF;F:\System Volume Information\_restore{7A2AFE90-FF0C-48A8-A3D9-667F16F0CC74}\RP10;Win32.HLLW.Autoruner.131;Deleted.;

A0001463.INF;F:\System Volume Information\_restore{7A2AFE90-FF0C-48A8-A3D9-667F16F0CC74}\RP10;Win32.HLLW.Autoruner.131;Deleted.;

A0003464.INF;F:\System Volume Information\_restore{7A2AFE90-FF0C-48A8-A3D9-667F16F0CC74}\RP10;Win32.HLLW.Autoruner.131;Deleted.;

A0012489.INF;F:\System Volume Information\_restore{7A2AFE90-FF0C-48A8-A3D9-667F16F0CC74}\RP11;Win32.HLLW.Autoruner.131;Deleted.;

A0016489.INF;F:\System Volume Information\_restore{7A2AFE90-FF0C-48A8-A3D9-667F16F0CC74}\RP11;Win32.HLLW.Autoruner.131;Deleted.;

A0022489.INF;F:\System Volume Information\_restore{7A2AFE90-FF0C-48A8-A3D9-667F16F0CC74}\RP11;Win32.HLLW.Autoruner.131;Deleted.;

A0026493.INF;F:\System Volume Information\_restore{7A2AFE90-FF0C-48A8-A3D9-667F16F0CC74}\RP12;Win32.HLLW.Autoruner.131;Deleted.;

A0027489.INF;F:\System Volume Information\_restore{7A2AFE90-FF0C-48A8-A3D9-667F16F0CC74}\RP12;Win32.HLLW.Autoruner.131;Deleted.;

A0032489.INF;F:\System Volume Information\_restore{7A2AFE90-FF0C-48A8-A3D9-667F16F0CC74}\RP12;Win32.HLLW.Autoruner.131;Deleted.;

A0035490.INF;F:\System Volume Information\_restore{7A2AFE90-FF0C-48A8-A3D9-667F16F0CC74}\RP12;Win32.HLLW.Autoruner.131;Deleted.;

A0036492.INF;F:\System Volume Information\_restore{7A2AFE90-FF0C-48A8-A3D9-667F16F0CC74}\RP12;Win32.HLLW.Autoruner.131;Deleted.;

A0037489.INF;F:\System Volume Information\_restore{7A2AFE90-FF0C-48A8-A3D9-667F16F0CC74}\RP12;Win32.HLLW.Autoruner.131;Deleted.;

A0038489.INF;F:\System Volume Information\_restore{7A2AFE90-FF0C-48A8-A3D9-667F16F0CC74}\RP12;Win32.HLLW.Autoruner.131;Deleted.;

A0039489.INF;F:\System Volume Information\_restore{7A2AFE90-FF0C-48A8-A3D9-667F16F0CC74}\RP12;Win32.HLLW.Autoruner.131;Deleted.;

A0000071.INF;F:\System Volume Information\_restore{7A2AFE90-FF0C-48A8-A3D9-667F16F0CC74}\RP2;Win32.HLLW.Autoruner.131;Deleted.;

A0000151.INF;F:\System Volume Information\_restore{7A2AFE90-FF0C-48A8-A3D9-667F16F0CC74}\RP3;Win32.HLLW.Autoruner.131;Deleted.;

A0000159.INF;F:\System Volume Information\_restore{7A2AFE90-FF0C-48A8-A3D9-667F16F0CC74}\RP4;Win32.HLLW.Autoruner.131;Deleted.;

A0000189.INF;F:\System Volume Information\_restore{7A2AFE90-FF0C-48A8-A3D9-667F16F0CC74}\RP5;Win32.HLLW.Autoruner.131;Deleted.;

A0000224.INF;F:\System Volume Information\_restore{7A2AFE90-FF0C-48A8-A3D9-667F16F0CC74}\RP5;Win32.HLLW.Autoruner.131;Deleted.;

A0000237.INF;F:\System Volume Information\_restore{7A2AFE90-FF0C-48A8-A3D9-667F16F0CC74}\RP6;Win32.HLLW.Autoruner.131;Deleted.;

A0000392.INF;F:\System Volume Information\_restore{7A2AFE90-FF0C-48A8-A3D9-667F16F0CC74}\RP6;Win32.HLLW.Autoruner.131;Deleted.;

A0000417.INF;F:\System Volume Information\_restore{7A2AFE90-FF0C-48A8-A3D9-667F16F0CC74}\RP7;Win32.HLLW.Autoruner.131;Deleted.;

A0000425.INF;F:\System Volume Information\_restore{7A2AFE90-FF0C-48A8-A3D9-667F16F0CC74}\RP8;Win32.HLLW.Autoruner.131;Deleted.;

A0000437.INF;F:\System Volume Information\_restore{7A2AFE90-FF0C-48A8-A3D9-667F16F0CC74}\RP8;Win32.HLLW.Autoruner.131;Deleted.;

A0000445.INF;F:\System Volume Information\_restore{7A2AFE90-FF0C-48A8-A3D9-667F16F0CC74}\RP9;Win32.HLLW.Autoruner.131;Deleted.;

A0000451.INF;F:\System Volume Information\_restore{7E23BCF0-B49B-4603-9C02-A4AED1C84B80}\RP10;Win32.HLLW.Autoruner.131;Deleted.;

A0000464.INF;F:\System Volume Information\_restore{7E23BCF0-B49B-4603-9C02-A4AED1C84B80}\RP10;Win32.HLLW.Autoruner.131;Deleted.;

A0001464.INF;F:\System Volume Information\_restore{7E23BCF0-B49B-4603-9C02-A4AED1C84B80}\RP10;Win32.HLLW.Autoruner.131;Deleted.;

A0001500.INF;F:\System Volume Information\_restore{7E23BCF0-B49B-4603-9C02-A4AED1C84B80}\RP10;Win32.HLLW.Autoruner.131;Deleted.;

A0001514.INF;F:\System Volume Information\_restore{7E23BCF0-B49B-4603-9C02-A4AED1C84B80}\RP10;Win32.HLLW.Autoruner.131;Deleted.;

A0001526.INF;F:\System Volume Information\_restore{7E23BCF0-B49B-4603-9C02-A4AED1C84B80}\RP10;Win32.HLLW.Autoruner.131;Deleted.;

A0001546.INF;F:\System Volume Information\_restore{7E23BCF0-B49B-4603-9C02-A4AED1C84B80}\RP10;Win32.HLLW.Autoruner.131;Deleted.;

A0002558.INF;F:\System Volume Information\_restore{7E23BCF0-B49B-4603-9C02-A4AED1C84B80}\RP10;Win32.HLLW.Autoruner.131;Deleted.;

A0002572.INF;F:\System Volume Information\_restore{7E23BCF0-B49B-4603-9C02-A4AED1C84B80}\RP10;Win32.HLLW.Autoruner.131;Deleted.;

A0002586.INF;F:\System Volume Information\_restore{7E23BCF0-B49B-4603-9C02-A4AED1C84B80}\RP10;Win32.HLLW.Autoruner.131;Deleted.;

A0002600.INF;F:\System Volume Information\_restore{7E23BCF0-B49B-4603-9C02-A4AED1C84B80}\RP10;Win32.HLLW.Autoruner.131;Deleted.;

A0002614.INF;F:\System Volume Information\_restore{7E23BCF0-B49B-4603-9C02-A4AED1C84B80}\RP10;Win32.HLLW.Autoruner.131;Deleted.;

A0002628.INF;F:\System Volume Information\_restore{7E23BCF0-B49B-4603-9C02-A4AED1C84B80}\RP10;Win32.HLLW.Autoruner.131;Deleted.;

A0002641.INF;F:\System Volume Information\_restore{7E23BCF0-B49B-4603-9C02-A4AED1C84B80}\RP10;Win32.HLLW.Autoruner.131;Deleted.;

A0004356.INF;F:\System Volume Information\_restore{B86296AA-1D2B-461F-9801-995BFEF44743}\RP11;Win32.HLLW.Autoruner.131;Deleted.;

A0004369.INF;F:\System Volume Information\_restore{B86296AA-1D2B-461F-9801-995BFEF44743}\RP11;Win32.HLLW.Autoruner.131;Deleted.;

A0004383.INF;F:\System Volume Information\_restore{B86296AA-1D2B-461F-9801-995BFEF44743}\RP11;Win32.HLLW.Autoruner.131;Deleted.;

A0004397.INF;F:\System Volume Information\_restore{B86296AA-1D2B-461F-9801-995BFEF44743}\RP11;Win32.HLLW.Autoruner.131;Deleted.;

A0004420.INF;F:\System Volume Information\_restore{B86296AA-1D2B-461F-9801-995BFEF44743}\RP12;Win32.HLLW.Autoruner.131;Deleted.;

A0007481.INF;F:\System Volume Information\_restore{B86296AA-1D2B-461F-9801-995BFEF44743}\RP12;Win32.HLLW.Autoruner.131;Deleted.;

A0009480.INF;F:\System Volume Information\_restore{B86296AA-1D2B-461F-9801-995BFEF44743}\RP12;Win32.HLLW.Autoruner.131;Deleted.;

A0011481.INF;F:\System Volume Information\_restore{B86296AA-1D2B-461F-9801-995BFEF44743}\RP12;Win32.HLLW.Autoruner.131;Deleted.;

A0013509.INF;F:\System Volume Information\_restore{B86296AA-1D2B-461F-9801-995BFEF44743}\RP13;Win32.HLLW.Autoruner.131;Deleted.;

A0014507.INF;F:\System Volume Information\_restore{B86296AA-1D2B-461F-9801-995BFEF44743}\RP13;Win32.HLLW.Autoruner.131;Deleted.;

A0014530.INF;F:\System Volume Information\_restore{B86296AA-1D2B-461F-9801-995BFEF44743}\RP13;Win32.HLLW.Autoruner.131;Deleted.;

A0001094.INF;F:\System Volume Information\_restore{D00B1226-0A1E-42C3-BA26-AEDDFFB059AA}\RP6;Win32.HLLW.Autoruner.131;Deleted.;

A0001108.INF;F:\System Volume Information\_restore{D00B1226-0A1E-42C3-BA26-AEDDFFB059AA}\RP6;Win32.HLLW.Autoruner.131;Deleted.;

A0001120.INF;F:\System Volume Information\_restore{D00B1226-0A1E-42C3-BA26-AEDDFFB059AA}\RP6;Win32.HLLW.Autoruner.131;Deleted.;

A0001132.INF;F:\System Volume Information\_restore{D00B1226-0A1E-42C3-BA26-AEDDFFB059AA}\RP6;Win32.HLLW.Autoruner.131;Deleted.;

A0001144.INF;F:\System Volume Information\_restore{D00B1226-0A1E-42C3-BA26-AEDDFFB059AA}\RP6;Win32.HLLW.Autoruner.131;Deleted.;

A0002144.INF;F:\System Volume Information\_restore{D00B1226-0A1E-42C3-BA26-AEDDFFB059AA}\RP6;Win32.HLLW.Autoruner.131;Deleted.;

A0002156.INF;F:\System Volume Information\_restore{D00B1226-0A1E-42C3-BA26-AEDDFFB059AA}\RP6;Win32.HLLW.Autoruner.131;Deleted.;

A0002168.INF;F:\System Volume Information\_restore{D00B1226-0A1E-42C3-BA26-AEDDFFB059AA}\RP6;Win32.HLLW.Autoruner.131;Deleted.;

A0002180.INF;F:\System Volume Information\_restore{D00B1226-0A1E-42C3-BA26-AEDDFFB059AA}\RP6;Win32.HLLW.Autoruner.131;Deleted.;

A0002193.INF;F:\System Volume Information\_restore{D00B1226-0A1E-42C3-BA26-AEDDFFB059AA}\RP6;Win32.HLLW.Autoruner.131;Deleted.;

A0002205.INF;F:\System Volume Information\_restore{D00B1226-0A1E-42C3-BA26-AEDDFFB059AA}\RP6;Win32.HLLW.Autoruner.131;Deleted.;

Link to post
Share on other sites

  • Staff

Hi,

I'm taking over this thread since AdvancedSetup is busy with other stuff...

Please run this online scan to help look for remnants.

Establish an internet connection & perform an online scan with Internet Explorer at Kaspersky Online Scanner

Click Accept, when prompted to download and install the program files and database of malware definitions.

  • Click Run at the Security prompt.
  • The program will then begin downloading and installing and will also update the database.
  • Please be patient as this can take several minutes.
  • Once the update is complete, click on My Computer under the green Scan bar to the left to start the scan.
  • Once the scan is complete, it will display if your system has been infected. It does not provide an option to clean/disinfect. We only require a report from it.
  • Do NOT be alarmed by what you see in the report. Many of the finds have likely been quarantined.
  • Click View scan report at the bottom.
  • Click the Save Report As... button.
  • Click the Save as Text button to save the file to your desktop so that you may post it in your next reply together with a new HijackThislog.

**Note**

To optimize scanning time and produce a more sensible report for review:

  • Close any open programs.
  • Turn off the real-time scanner of all antivirus or antispyware programs while performing the online scan.

Note for Internet Explorer 7 users: If at any time you have trouble viewing the accept button of the license, click on the Zoom tool located at the bottom right of the IE window and set the zoom to 75%. Once the license is accepted, reset to 100%.

Link to post
Share on other sites

Hello, Here is the Kaspersky's Scanner report:

--------------------------------------------------------------------------------

KASPERSKY ONLINE SCANNER 7 REPORT

Friday, March 20, 2009

Operating System: Microsoft Windows XP Professional Service Pack 2 (build 2600)

Kaspersky Online Scanner 7 version: 7.0.25.0

Program database last update: Thursday, March 19, 2009 21:02:23

Records in database: 1934944

--------------------------------------------------------------------------------

Scan settings:

Scan using the following database: extended

Scan archives: yes

Scan mail databases: yes

Scan area - My Computer:

A:\

C:\

D:\

E:\

F:\

G:\

H:\

Scan statistics:

Files scanned: 110891

Threat name: 3

Infected objects: 11

Suspicious objects: 0

Duration of the scan: 02:46:51

File name / Threat name / Threats count

C:\Documents and Settings\Shahril Izwan\DoctorWeb\Quarantine\A0000527.exe Infected: not-a-virus:Client-IRC.Win32.mIRC.621 1

C:\Documents and Settings\Shahril Izwan\DoctorWeb\Quarantine\A0001594.exe Infected: not-a-virus:Client-IRC.Win32.mIRC.621 1

C:\Documents and Settings\Shahril Izwan\DoctorWeb\Quarantine\A0003128.exe Infected: not-a-virus:Client-IRC.Win32.mIRC.621 1

C:\Documents and Settings\Shahril Izwan\DoctorWeb\Quarantine\A0003873.exe Infected: not-a-virus:Client-IRC.Win32.mIRC.631 1

C:\Documents and Settings\Shahril Izwan\DoctorWeb\Quarantine\A0003874.exe Infected: not-a-virus:Client-IRC.Win32.mIRC.621 1

C:\Documents and Settings\Shahril Izwan\DoctorWeb\Quarantine\A0003876.exe Infected: not-a-virus:Client-IRC.Win32.mIRC.631 1

C:\Documents and Settings\Shahril Izwan\DoctorWeb\Quarantine\A0044766.exe Infected: not-a-virus:Client-IRC.Win32.mIRC.621 1

C:\Documents and Settings\Shahril Izwan\DoctorWeb\Quarantine\mirc.exe Infected: not-a-virus:Client-IRC.Win32.mIRC.631 1

C:\Documents and Settings\Shahril Izwan\DoctorWeb\Quarantine\mirc621.exe Infected: not-a-virus:Client-IRC.Win32.mIRC.621 1

C:\Documents and Settings\Shahril Izwan\DoctorWeb\Quarantine\mirc631.exe Infected: not-a-virus:Client-IRC.Win32.mIRC.631 1

F:\Ijud Punyer\Visual Basic\Applications\NetworkActivPIAFCTMv1.5.exe Infected: not-a-virus:NetTool.Win32.Piafctm.152 1

The selected area was scanned.

Link to post
Share on other sites

..and here is the HJT log:

Logfile of Trend Micro HijackThis v2.0.2

Scan saved at 2:11:39 PM, on 3/20/2009

Platform: Windows XP SP2 (WinNT 5.01.2600)

MSIE: Internet Explorer v7.00 (7.00.6000.16674)

Boot mode: Normal

Running processes:

C:\WINDOWS\System32\smss.exe

C:\WINDOWS\system32\winlogon.exe

C:\WINDOWS\system32\services.exe

C:\WINDOWS\system32\lsass.exe

C:\WINDOWS\system32\svchost.exe

C:\WINDOWS\System32\svchost.exe

C:\WINDOWS\system32\spoolsv.exe

C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe

C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe

C:\Program Files\Bonjour\mDNSResponder.exe

C:\Program Files\Java\jre6\bin\jqs.exe

C:\WINDOWS\Explorer.EXE

C:\Program Files\Common Files\Microsoft Shared\VS7Debug\mdm.exe

C:\WINDOWS\System32\nvsvc32.exe

C:\WINDOWS\System32\svchost.exe

C:\PROGRA~1\AVG\AVG8\avgemc.exe

C:\PROGRA~1\AVG\AVG8\avgam.exe

C:\PROGRA~1\AVG\AVG8\avgrsx.exe

C:\PROGRA~1\AVG\AVG8\avgnsx.exe

C:\Program Files\AVG\AVG8\avgcsrvx.exe

C:\WINDOWS\RTHDCPL.EXE

C:\WINDOWS\system32\RUNDLL32.EXE

C:\WINDOWS\System32\taskswitch.exe

C:\Program Files\HP\HP Software Update\HPWuSchd2.exe

C:\Program Files\Yahoo!\Search Protection\SearchProtection.exe

C:\Program Files\HP\hpcoretech\hpcmpmgr.exe

C:\Program Files\Winamp\winampa.exe

C:\Program Files\Java\jre6\bin\jusched.exe

C:\Program Files\iTunes\iTunesHelper.exe

C:\WINDOWS\system32\ctfmon.exe

C:\Program Files\D-Link\D-Link DSL-200I USB ADSL Modem\dslmon.exe

C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe

C:\Program Files\Logitech\Desktop Messenger\8876480\Program\LogitechDesktopMessenger.exe

C:\Program Files\Logitech\SetPoint\SetPoint.exe

C:\Program Files\iPod\bin\iPodService.exe

C:\Program Files\Common Files\Logishrd\KHAL2\KHALMNPR.EXE

C:\Program Files\HP\Digital Imaging\bin\hpqgalry.exe

C:\Program Files\internet explorer\iexplore.exe

C:\Program Files\Java\jre6\bin\java.exe

C:\Program Files\Java\jre6\bin\jucheck.exe

F:\Ijud Punyer\Visual Basic\Applications\HijackThis.exe

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896

R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://us.rd.yahoo.com/customize/ycomp/def...//www.yahoo.com

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page = \blank.htm

R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = local

R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\PROGRA~1\Yahoo!\Companion\Installs\cpn2\yt.dll

O2 - BHO: &Yahoo! Toolbar Helper - {02478D38-C3F9-4efb-9B51-7695ECA05670} - C:\PROGRA~1\Yahoo!\Companion\Installs\cpn2\yt.dll

O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll

O2 - BHO: WormRadar.com IESiteBlocker.NavFilter - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files\AVG\AVG8\avgssie.dll

O2 - BHO: Megaupload Toolbar - {4E7BD74F-2B8D-469E-CCB0-B130EEDBE97C} - C:\PROGRA~1\MEGAUP~2\MEGAUP~1.DLL

O2 - BHO: Yahoo! IE Services Button - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\Program Files\Yahoo!\Common\yiesrvc.dll

O2 - BHO: Java Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre6\bin\ssv.dll

O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)

O2 - BHO: Java Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll

O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll

O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\PROGRA~1\Yahoo!\Companion\Installs\cpn2\yt.dll

O3 - Toolbar: Megaupload Toolbar - {4E7BD74F-2B8D-469E-CCB0-B130EEDBE97C} - C:\PROGRA~1\MEGAUP~2\MEGAUP~1.DLL

O4 - HKLM\..\Run: [skyTel] SkyTel.EXE

O4 - HKLM\..\Run: [GBB36X Configure] C:\WINDOWS\System32\JMRaidTool.exe boot

O4 - HKLM\..\Run: [RTHDCPL] RTHDCPL.EXE

O4 - HKLM\..\Run: [Tweak UI] RUNDLL32.EXE TWEAKUI.CPL,TweakMeUp

O4 - HKLM\..\Run: [EasyTuneV] C:\Program Files\Gigabyte\ET5\GUI.exe

O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\System32\NvCpl.dll,NvStartup

O4 - HKLM\..\Run: [nwiz] nwiz.exe /install

O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\System32\NvMcTray.dll,NvTaskbarInit

O4 - HKLM\..\Run: [CoolSwitch] C:\WINDOWS\System32\taskswitch.exe

O4 - HKLM\..\Run: [NeroFilterCheck] C:\Program Files\Common Files\Ahead\Lib\NeroCheck.exe

O4 - HKLM\..\Run: [Logitech Hardware Abstraction Layer] KHALMNPR.EXE

O4 - HKLM\..\Run: [HP Software Update] "C:\Program Files\HP\HP Software Update\HPWuSchd2.exe"

O4 - HKLM\..\Run: [YSearchProtection] "C:\Program Files\Yahoo!\Search Protection\SearchProtection.exe"

O4 - HKLM\..\Run: [HP Component Manager] "C:\Program Files\HP\hpcoretech\hpcmpmgr.exe"

O4 - HKLM\..\Run: [Kernel and Hardware Abstraction Layer] KHALMNPR.EXE

O4 - HKLM\..\Run: [WinampAgent] "C:\Program Files\Winamp\winampa.exe"

O4 - HKLM\..\Run: [sunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe"

O4 - HKLM\..\Run: [AVG8_TRAY] C:\PROGRA~1\AVG\AVG8\avgtray.exe

O4 - HKLM\..\Run: [PC Suite for Smartphones] "C:\Program Files\Sony Ericsson\Mobile4\Application Launcher\Application Launcher.exe" /startoptions

O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime

O4 - HKLM\..\Run: [AppleSyncNotifier] C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleSyncNotifier.exe

O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"

O4 - HKLM\..\Run: [Malwarebytes' Anti-Malware] "C:\Program Files\Malwarebytes' Anti-Malware\mbamgui.exe" /starttray

O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"

O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe

O4 - HKUS\S-1-5-18\..\Run: [msnmsgr] "C:\Program Files\MSN Messenger\msnmsgr.exe" /background (User 'SYSTEM')

O4 - HKUS\.DEFAULT\..\Run: [msnmsgr] "C:\Program Files\MSN Messenger\msnmsgr.exe" /background (User 'Default user')

O4 - Global Startup: Adobe Gamma Loader.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe

O4 - Global Startup: DSLMON.lnk = ?

O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe

O4 - Global Startup: HP Image Zone Fast Start.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqthb08.exe

O4 - Global Startup: Logitech Desktop Messenger.lnk = C:\Program Files\Logitech\Desktop Messenger\8876480\Program\LogitechDesktopMessenger.exe

O4 - Global Startup: Logitech SetPoint.lnk = C:\Program Files\Logitech\SetPoint\SetPoint.exe

O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~3\OFFICE11\EXCEL.EXE/3000

O8 - Extra context menu item: E&xportar para o Microsoft Excel - res://C:\PROGRA~1\MICROS~3\Office10\EXCEL.EXE/3000

O9 - Extra button: Yahoo! Services - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\Program Files\Yahoo!\Common\yiesrvc.dll

O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~3\OFFICE11\REFIEBAR.DLL

O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe

O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe

O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe

O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe

O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (Installation Support) - C:\Program Files\Yahoo!\Common\Yinsthelper.dll

O17 - HKLM\System\CCS\Services\Tcpip\..\{4833954F-1E33-488A-8EE5-D3CE72394F1D}: NameServer = 202.188.0.133 202.188.1.5

O17 - HKLM\System\CS3\Services\Tcpip\..\{4833954F-1E33-488A-8EE5-D3CE72394F1D}: NameServer = 202.188.0.133 202.188.1.5

O18 - Protocol: bwfile-8876480 - {9462A756-7B47-47BC-8C80-C34B9B80B32B} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\GAPlugProtocol-8876480.dll

O18 - Protocol: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files\AVG\AVG8\avgpp.dll

O20 - Winlogon Notify: avgrsstarter - C:\WINDOWS\SYSTEM32\avgrsstx.dll

O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe

O23 - Service: AVG8 E-mail Scanner (avg8emc) - AVG Technologies CZ, s.r.o. - C:\PROGRA~1\AVG\AVG8\avgemc.exe

O23 - Service: AVG8 WatchDog (avg8wd) - AVG Technologies CZ, s.r.o. - C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe

O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe

O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1150\Intel 32\IDriverT.exe

O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe

O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe

O23 - Service: Logitech Bluetooth Service (LBTServ) - Logitech, Inc. - C:\Program Files\Common Files\Logitech\Bluetooth\LBTServ.exe

O23 - Service: Macromedia Licensing Service - Unknown owner - C:\Program Files\Common Files\Macromedia Shared\Service\Macromedia Licensing.exe

O23 - Service: MBAMService - Malwarebytes Corporation - C:\Program Files\Malwarebytes' Anti-Malware\mbamservice.exe

O23 - Service: NBService - Nero AG - C:\Program Files\Nero\Nero 7\Nero BackItUp\NBService.exe

O23 - Service: NMIndexingService - Nero AG - C:\Program Files\Common Files\Ahead\Lib\NMIndexingService.exe

O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\System32\nvsvc32.exe

O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe

--

End of file - 10550 bytes

Link to post
Share on other sites

  • Staff

Hi,

What Kaspersky found was already quarantined by DoctorWeb and was not a real thread anyway.

This file that Kaspersky flagged is Ok as well: F:\Ijud Punyer\Visual Basic\Applications\NetworkActivPIAFCTMv1.5.exe

Your HijackThislog looks clean again as well. I however see you have the MegaUpload Toolbar installed. This one contains some spyware functionality.

Your choice whether you want to keep it or not.

Let me know in your next reply how things are now.

Link to post
Share on other sites

Hello,

Things are back to normal now. I've uninstalled MegaUpload toolbar.

Since everything is ok now, could you tell me how to remove DrWeb CureIt?

And also I have this "Qoobox" folder in my C:\ after performing malware removal with ComboFix.

Should I just delete the folder to remove it? Since ComboFix has been quaratined by DrWeb CureIt, it has no more use at this time.

Thanks to you and AdvanceSetup for helping me cleaning up my PC.

Link to post
Share on other sites

  • Staff

Hi,

For Qoobox, yes, delete that folder manually since DrWeb already deleted the main file which was also needed to uninstall Combofix (and delete its related folder(s)).

DRweb misidentified Combofix, because it sees some commandline tools Combofix uses as unwanted while there's nothing wrong with it.

To delete DrWeb, you can delete it manually as well.

Delete this folder:

C:\Documents and Settings\Shahril Izwan\DoctorWeb

Glad we could help. :(

Please read my Prevention page with lots of info and tips how to prevent this in the future.

And if you want to improve speed/system performance after malware removal, take a look here.

Extra note: Make sure your programs are up to date - because older versions may contain Security Leaks. To find out what programs need to be updated, please run the Secunia Software Inspector Scan.

Happy Surfing again!

Link to post
Share on other sites

  • Staff

Since this issue appears resolved ... this Topic is closed.

If you need this topic reopened for continuations of existing problems, please request this by sending me a PM with the address of the thread. This applies only to the original topic starter.

Everyone else please begin a New Topic.

Link to post
Share on other sites

Guest
This topic is now closed to further replies.
  • Recently Browsing   0 members

    • No registered users viewing this page.
Back to top
×
×
  • Create New...

Important Information

This site uses cookies - We have placed cookies on your device to help make this website better. You can adjust your cookie settings, otherwise we'll assume you're okay to continue.