can't get rid of the virus, hijack included

force123

New Member
Hi,

[a bit history]
I plugged a flash to my computer, which had a virus named "soundmix.exe" (I knew it from past). I forgot to check the flash first, So I got the virus.
then I run Flash_Disinfector.exe, It got rid of the soundmix.exe virus.
[/a bit history]

After that, when I turn on my pc and windows come up (xp sp2), it shows the desktop image, the taskbar and quick lunc. but then the windows hangs. I press ctrl+alt+delete, and go to task manager, and I end process the explorer.exe, after it is closed, I goto file->run new task, and I type explorer there, and this time explorer runs fine, and that's how I'm working with windows now.

being hung everytime I start windows, I decided to run a full malwarebyte scan.
It found like 103 items. I removed all.
facing the problem again, I just did another scan with it. This time it found 2 files, all where in my :
E:\Documents and Settings\Alborz\Local Settings\temp
folder. and malware needed to reboot to delete them at startup.
after rebooting, I did another scan with malware, this time it found 3 files, again in that folder. But this time their name was changed. (something creating these files?)

I went to safe mode and run the malwarebyte there, and it deleted those successfully. I check the folder, there was nothing in it this time.

I reboot and come to normal mode, I checked that folder, again 2 new files were created with different names.

files name pattern are the same. like bj01.tmp (172 kb) . wd01.tmp (172 kb)

the sizes and the names are similar that why I say these are from same virus.
the malware labeled these files as backdoor.prorat or something.

finally, I did a hijackthis log :

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 14:41, on 2009-01-28
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Boot mode: Normal

Running processes:
E:\WINDOWS\System32\smss.exe
E:\WINDOWS\system32\winlogon.exe
E:\WINDOWS\system32\services.exe
E:\WINDOWS\system32\lsass.exe
E:\WINDOWS\system32\svchost.exe
E:\WINDOWS\System32\svchost.exe
E:\WINDOWS\system32\spoolsv.exe
F:\Program Files\CyberLink\PowerDVD\PDVDServ.exe
F:\Program Files\VirtualCloneDrive\VCDDaemon.exe
E:\Program Files\Apache2.2\bin\httpd.exe
E:\Program Files\Bonjour\mDNSResponder.exe
F:\Program Files\WIDCOMM\Bluetooth Software\bin\btwdins.exe
E:\Program Files\MySQL\MySQL Server 5.0\bin\mysqld-nt.exe
E:\Program Files\Apache2.2\bin\httpd.exe
E:\Program Files\Nero\Nero8\Nero BackItUp\NBService.exe
E:\WINDOWS\system32\nvsvc32.exe
E:\WINDOWS\system32\PnkBstrA.exe
E:\WINDOWS\system32\PSIService.exe
E:\WINDOWS\system32\svchost.exe
E:\WINDOWS\explorer.exe
E:\Program Files\Mozilla Firefox\firefox.exe
F:\Program Files\HijackThis\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - E:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll (file missing)
O2 - BHO: Megaupload Toolbar - {4E7BD74F-2B8D-469E-CCB0-B130EEDBE97C} - E:\PROGRA~1\MEGAUP~1\MEGAUP~1.DLL
O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - f:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - F:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
O2 - BHO: Catcher Class - {ADECBED6-0366-4377-A739-E69DFBA04663} - f:\Program Files\FLV Downloader\MoyeaCth.dll
O2 - BHO: QUICKfind BHO Object - {C08DF07A-3E49-4E25-9AB0-D3882835F153} - f:\PROGRA~1\LONGMA~1\LAD001PE\setup\qf\IEHelp.dll
O3 - Toolbar: Megaupload Toolbar - {4E7BD74F-2B8D-469E-CCB0-B130EEDBE97C} - E:\PROGRA~1\MEGAUP~1\MEGAUP~1.DLL
O4 - HKLM\..\Run: [IMJPMIG8.1] "E:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE" /Spoil /RemAdvDef /Migration32
O4 - HKLM\..\Run: [PHIME2002ASync] E:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /SYNC
O4 - HKLM\..\Run: [PHIME2002A] E:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /IMEName
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE E:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [RemoteControl] "f:\Program Files\CyberLink\PowerDVD\PDVDServ.exe"
O4 - HKLM\..\Run: [VirtualCloneDrive] "f:\Program Files\VirtualCloneDrive\VCDDaemon.exe" /s
O4 - HKLM\..\Run: [CloneCDTray] "f:\Program Files\CloneCD\CloneCDTray.exe" /s
O4 - HKLM\..\Run: [ISUSPM Startup] "E:\Program Files\Common Files\InstallShield\UpdateService\ISUSPM.exe" -startup
O4 - HKLM\..\Run: [ISUSScheduler] "E:\Program Files\Common Files\InstallShield\UpdateService\issch.exe" -start
O4 - HKLM\..\Run: [FmctrlTray] Fmctrl.EXE
O4 - HKLM\..\Run: [NeroFilterCheck] E:\Program Files\Common Files\Nero\Lib\NeroCheck.exe
O4 - HKLM\..\Run: [NBKeyScan] "E:\Program Files\Nero\Nero8\Nero BackItUp\NBKeyScan.exe"
O4 - HKLM\..\Run: [SunJavaUpdateSched] "F:\Program Files\Java\jre1.6.0_05\bin\jusched.exe"
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE E:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [QuickTime Task] "F:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKCU\..\Run: [ctfmon.exe] E:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [IECheck] E:\WINDOWS\IECheck.exe
O4 - HKUS\S-1-5-18\..\Run: [ctfmon.exe] E:\WINDOWS\system32\ctfmon.exe (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [ctfmon.exe] E:\WINDOWS\system32\ctfmon.exe (User 'Default user')
O4 - Global Startup: Adobe Reader Speed Launch.lnk = E:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O8 - Extra context menu item: &Clean Traces - F:\Program Files\DAP\Privacy Package\dapcleanerie.htm
O8 - Extra context menu item: &Download with &DAP - F:\Program Files\DAP\dapextie.htm
O8 - Extra context menu item: Download &all with DAP - F:\Program Files\DAP\dapextie2.htm
O8 - Extra context menu item: E&xport to Microsoft Excel - res://E:\PROGRA~1\MICROS~2\Office12\EXCEL.EXE/3000
O8 - Extra context menu item: Send to &Bluetooth Device... - F:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie_ctx.htm
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - F:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - F:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - F:\PROGRA~1\MICROS~1\Office12\REFIEBAR.DLL
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - f:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - f:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra button: ICQ6 - {E59EB121-F339-4851-A3BA-FE49C35617C2} - f:\Program Files\ICQ6\ICQ.exe
O9 - Extra 'Tools' menuitem: ICQ6 - {E59EB121-F339-4851-A3BA-FE49C35617C2} - f:\Program Files\ICQ6\ICQ.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - E:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - E:\Program Files\Messenger\msmsgs.exe
O17 - HKLM\System\CCS\Services\Tcpip\..\{33DECB99-D7B7-4170-B79D-8D7848592871}: NameServer = 81.12.74.3 81.12.92.3
O17 - HKLM\System\CCS\Services\Tcpip\..\{BE40051E-E6D6-4EA2-B283-08CDF7E28DB4}: NameServer = 217.218.127.104,4.2.2.4
O23 - Service: Apache2.2 - Apache Software Foundation - E:\Program Files\Apache2.2\bin\httpd.exe
O23 - Service: ##Id_String1.6844F930_1628_4223_B5CC_5BB94B879762## (Bonjour Service) - Apple Computer, Inc. - E:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: Bluetooth Service (btwdins) - Broadcom Corporation. - F:\Program Files\WIDCOMM\Bluetooth Software\bin\btwdins.exe
O23 - Service: FLEXnet Licensing Service - Macrovision Europe Ltd. - E:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - E:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: MySql - Unknown owner - E:/mysql/bin/mysqld-nt.exe (file missing)
O23 - Service: MySQL5 - Unknown owner - E:\Program.exe (file missing)
O23 - Service: Nero BackItUp Scheduler 3 - Nero AG - E:\Program Files\Nero\Nero8\Nero BackItUp\NBService.exe
O23 - Service: NMIndexingService - Nero AG - E:\Program Files\Common Files\Nero\Lib\NMIndexingService.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - E:\WINDOWS\system32\nvsvc32.exe
O23 - Service: PnkBstrA - Unknown owner - E:\WINDOWS\system32\PnkBstrA.exe
O23 - Service: ProtexisLicensing - Unknown owner - E:\WINDOWS\system32\PSIService.exe

--
End of file - 7451 bytes
 
Last edited:
What you need is a good AV not a spyware program like Malwarebytes. What you have is a virus not spyware. I recommend either NOD32 or Norton AV 2009. And you shoudl fully format your flash drive to remove the virus.
 
Hi,

[a bit history]
I plugged a flash to my computer, which had a virus named "soundmix.exe" (I knew it from past). I forgot to check the flash first, So I got the virus.
then I run Flash_Disinfector.exe, It got rid of the soundmix.exe virus.
[/a bit history]

After that, when I turn on my pc and windows come up (xp sp2), it shows the desktop image, the taskbar and quick lunc. but then the windows hangs. I press ctrl+alt+delete, and go to task manager, and I end process the explorer.exe, after it is closed, I goto file->run new task, and I type explorer there, and this time explorer runs fine, and that's how I'm working with windows now.

being hung everytime I start windows, I decided to run a full malwarebyte scan.
It found like 103 items. I removed all.
facing the problem again, I just did another scan with it. This time it found 2 files, all where in my :
E:\Documents and Settings\Alborz\Local Settings\temp
folder. and malware needed to reboot to delete them at startup.
after rebooting, I did another scan with malware, this time it found 3 files, again in that folder. But this time their name was changed. (something creating these files?)

I went to safe mode and run the malwarebyte there, and it deleted those successfully. I check the folder, there was nothing in it this time.

I reboot and come to normal mode, I checked that folder, again 2 new files were created with different names.

files name pattern are the same. like bj01.tmp (172 kb) . wd01.tmp (172 kb)

the sizes and the names are similar that why I say these are from same virus.
the malware labeled these files as backdoor.prorat or something.

finally, I did a hijackthis log :

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 14:41, on 2009-01-28
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Boot mode: Normal

Running processes:
E:\WINDOWS\System32\smss.exe
E:\WINDOWS\system32\winlogon.exe
E:\WINDOWS\system32\services.exe
E:\WINDOWS\system32\lsass.exe
E:\WINDOWS\system32\svchost.exe
E:\WINDOWS\System32\svchost.exe
E:\WINDOWS\system32\spoolsv.exe
F:\Program Files\CyberLink\PowerDVD\PDVDServ.exe
F:\Program Files\VirtualCloneDrive\VCDDaemon.exe
E:\Program Files\Apache2.2\bin\httpd.exe
E:\Program Files\Bonjour\mDNSResponder.exe
F:\Program Files\WIDCOMM\Bluetooth Software\bin\btwdins.exe
E:\Program Files\MySQL\MySQL Server 5.0\bin\mysqld-nt.exe
E:\Program Files\Apache2.2\bin\httpd.exe
E:\Program Files\Nero\Nero8\Nero BackItUp\NBService.exe
E:\WINDOWS\system32\nvsvc32.exe
E:\WINDOWS\system32\PnkBstrA.exe
E:\WINDOWS\system32\PSIService.exe
E:\WINDOWS\system32\svchost.exe
E:\WINDOWS\explorer.exe
E:\Program Files\Mozilla Firefox\firefox.exe
F:\Program Files\HijackThis\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - E:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll (file missing)
O2 - BHO: Megaupload Toolbar - {4E7BD74F-2B8D-469E-CCB0-B130EEDBE97C} - E:\PROGRA~1\MEGAUP~1\MEGAUP~1.DLL
O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - f:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - F:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
O2 - BHO: Catcher Class - {ADECBED6-0366-4377-A739-E69DFBA04663} - f:\Program Files\FLV Downloader\MoyeaCth.dll
O2 - BHO: QUICKfind BHO Object - {C08DF07A-3E49-4E25-9AB0-D3882835F153} - f:\PROGRA~1\LONGMA~1\LAD001PE\setup\qf\IEHelp.dll
O3 - Toolbar: Megaupload Toolbar - {4E7BD74F-2B8D-469E-CCB0-B130EEDBE97C} - E:\PROGRA~1\MEGAUP~1\MEGAUP~1.DLL
O4 - HKLM\..\Run: [IMJPMIG8.1] "E:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE" /Spoil /RemAdvDef /Migration32
O4 - HKLM\..\Run: [PHIME2002ASync] E:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /SYNC
O4 - HKLM\..\Run: [PHIME2002A] E:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /IMEName
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE E:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [RemoteControl] "f:\Program Files\CyberLink\PowerDVD\PDVDServ.exe"
O4 - HKLM\..\Run: [VirtualCloneDrive] "f:\Program Files\VirtualCloneDrive\VCDDaemon.exe" /s
O4 - HKLM\..\Run: [CloneCDTray] "f:\Program Files\CloneCD\CloneCDTray.exe" /s
O4 - HKLM\..\Run: [ISUSPM Startup] "E:\Program Files\Common Files\InstallShield\UpdateService\ISUSPM.exe" -startup
O4 - HKLM\..\Run: [ISUSScheduler] "E:\Program Files\Common Files\InstallShield\UpdateService\issch.exe" -start
O4 - HKLM\..\Run: [FmctrlTray] Fmctrl.EXE
O4 - HKLM\..\Run: [NeroFilterCheck] E:\Program Files\Common Files\Nero\Lib\NeroCheck.exe
O4 - HKLM\..\Run: [NBKeyScan] "E:\Program Files\Nero\Nero8\Nero BackItUp\NBKeyScan.exe"
O4 - HKLM\..\Run: [SunJavaUpdateSched] "F:\Program Files\Java\jre1.6.0_05\bin\jusched.exe"
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE E:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [QuickTime Task] "F:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKCU\..\Run: [ctfmon.exe] E:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [IECheck] E:\WINDOWS\IECheck.exe
O4 - HKUS\S-1-5-18\..\Run: [ctfmon.exe] E:\WINDOWS\system32\ctfmon.exe (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [ctfmon.exe] E:\WINDOWS\system32\ctfmon.exe (User 'Default user')
O4 - Global Startup: Adobe Reader Speed Launch.lnk = E:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O8 - Extra context menu item: &Clean Traces - F:\Program Files\DAP\Privacy Package\dapcleanerie.htm
O8 - Extra context menu item: &Download with &DAP - F:\Program Files\DAP\dapextie.htm
O8 - Extra context menu item: Download &all with DAP - F:\Program Files\DAP\dapextie2.htm
O8 - Extra context menu item: E&xport to Microsoft Excel - res://E:\PROGRA~1\MICROS~2\Office12\EXCEL.EXE/3000
O8 - Extra context menu item: Send to &Bluetooth Device... - F:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie_ctx.htm
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - F:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - F:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - F:\PROGRA~1\MICROS~1\Office12\REFIEBAR.DLL
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - f:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - f:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra button: ICQ6 - {E59EB121-F339-4851-A3BA-FE49C35617C2} - f:\Program Files\ICQ6\ICQ.exe
O9 - Extra 'Tools' menuitem: ICQ6 - {E59EB121-F339-4851-A3BA-FE49C35617C2} - f:\Program Files\ICQ6\ICQ.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - E:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - E:\Program Files\Messenger\msmsgs.exe
O17 - HKLM\System\CCS\Services\Tcpip\..\{33DECB99-D7B7-4170-B79D-8D7848592871}: NameServer = 81.12.74.3 81.12.92.3
O17 - HKLM\System\CCS\Services\Tcpip\..\{BE40051E-E6D6-4EA2-B283-08CDF7E28DB4}: NameServer = 217.218.127.104,4.2.2.4
O23 - Service: Apache2.2 - Apache Software Foundation - E:\Program Files\Apache2.2\bin\httpd.exe
O23 - Service: ##Id_String1.6844F930_1628_4223_B5CC_5BB94B879762## (Bonjour Service) - Apple Computer, Inc. - E:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: Bluetooth Service (btwdins) - Broadcom Corporation. - F:\Program Files\WIDCOMM\Bluetooth Software\bin\btwdins.exe
O23 - Service: FLEXnet Licensing Service - Macrovision Europe Ltd. - E:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - E:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: MySql - Unknown owner - E:/mysql/bin/mysqld-nt.exe (file missing)
O23 - Service: MySQL5 - Unknown owner - E:\Program.exe (file missing)
O23 - Service: Nero BackItUp Scheduler 3 - Nero AG - E:\Program Files\Nero\Nero8\Nero BackItUp\NBService.exe
O23 - Service: NMIndexingService - Nero AG - E:\Program Files\Common Files\Nero\Lib\NMIndexingService.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - E:\WINDOWS\system32\nvsvc32.exe
O23 - Service: PnkBstrA - Unknown owner - E:\WINDOWS\system32\PnkBstrA.exe
O23 - Service: ProtexisLicensing - Unknown owner - E:\WINDOWS\system32\PSIService.exe
O24 - Desktop Component 0: The Ultimate Site - The ultimate Site - http://www.tus-wa.com/

--
End of file - 7451 bytes

Please follow the instructions here and post the requested logs back here.
 
Yesterday I noticed my media player classic (k-lite codec pack) is not working at all. So I downloaded the latest version and I installed it.

I did a malware scan and hijackthis again, here's the logs.
malware found about 1200 files infected which I strongly believe they are all k-lite codec pack files. I didn't remove them with malwar,e cause if I did, my media player would stop working again.

malwarebyte log:
Malwarebytes' Anti-Malware 1.33
Database version: 1704
Windows 5.1.2600 Service Pack 2

2009-01-29 08:18:34
1.txt

Scan type: Quick Scan
Objects scanned: 55929
Time elapsed: 3 minute(s), 56 second(s)

Memory Processes Infected: 0
Memory Modules Infected: 1
Registry Keys Infected: 0
Registry Values Infected: 0
Registry Data Items Infected: 0
Folders Infected: 0
Files Infected: 1251

Memory Processes Infected:
(No malicious items detected)

Memory Modules Infected:
E:\Documents and Settings\Alborz\Local Settings\temp\bja1.tmp (Backdoor.ProRat) -> No action taken.

Registry Keys Infected:
(No malicious items detected)

Registry Values Infected:
(No malicious items detected)

Registry Data Items Infected:
(No malicious items detected)

Folders Infected:
(No malicious items detected)

Files Infected:
E:\Documents and Settings\Alborz\Local Settings\temp\bja1.tmp (Backdoor.ProRat) -> No action taken.
E:\WINDOWS\ach4AA.tmp (Backdoor.ProRat) -> No action taken.
E:\WINDOWS\aco1A5.tmp (Backdoor.ProRat) -> No action taken.
E:\WINDOWS\acr229.tmp (Backdoor.ProRat) -> No action taken.
E:\WINDOWS\mvq204.tmp (Backdoor.ProRat) -> No action taken.
E:\WINDOWS\mvt28F.tmp (Backdoor.ProRat) -> No action taken.
E:\WINDOWS\mvt2CF.tmp (Backdoor.ProRat) -> No action taken.
E:\WINDOWS\mwe6B.tmp (Backdoor.ProRat) -> No action taken.
E:\WINDOWS\mwf91.tmp (Backdoor.ProRat) -> No action taken.
E:\WINDOWS\mwgA8.tmp (Backdoor.ProRat) -> No action taken.
E:\WINDOWS\mwi4EC.tmp (Backdoor.ProRat) -> No action taken.
E:\WINDOWS\mwk12B.tmp (Backdoor.ProRat) -> No action taken.
E:\WINDOWS\mxc3D0.tmp (Backdoor.ProRat) -> No action taken.
E:\WINDOWS\mxh4B0.tmp (Backdoor.ProRat) -> No action taken.
E:\WINDOWS\myj51C.tmp (Backdoor.ProRat) -> No action taken.
E:\WINDOWS\myv334.tmp (Backdoor.ProRat) -> No action taken.
E:\WINDOWS\mzf45B.tmp (Backdoor.ProRat) -> No action taken.
E:\WINDOWS\mzw365.tmp (Backdoor.ProRat) -> No action taken.
E:\WINDOWS\nac16.tmp (Backdoor.ProRat) -> No action taken.
E:\WINDOWS\nae5B.tmp (Backdoor.ProRat) -> No action taken.
E:\WINDOWS\nay398.tmp (Backdoor.ProRat) -> No action taken.
E:\WINDOWS\nbe43F.tmp (Backdoor.ProRat) -> No action taken.
E:\WINDOWS\nccF.tmp (Backdoor.ProRat) -> No action taken.
E:\WINDOWS\ndf88.tmp (Backdoor.ProRat) -> No action taken.
E:\WINDOWS\ndu2F4.tmp (Backdoor.ProRat) -> No action taken.
E:\WINDOWS\nfg491.tmp (Backdoor.ProRat) -> No action taken.
E:\WINDOWS\nfk52B.tmp (Backdoor.ProRat) -> No action taken.
E:\WINDOWS\sfe448.tmp (Backdoor.ProRat) -> No action taken.
E:\WINDOWS\sfe6C.tmp (Backdoor.ProRat) -> No action taken.
E:\WINDOWS\sfe76.tmp (Backdoor.ProRat) -> No action taken.
E:\WINDOWS\sfi4E9.tmp (Backdoor.ProRat) -> No action taken.
E:\WINDOWS\sfj50D.tmp (Backdoor.ProRat) -> No action taken.
E:\WINDOWS\sgiEE.tmp (Backdoor.ProRat) -> No action taken.
E:\WINDOWS\shh4AE.tmp (Backdoor.ProRat) -> No action taken.
E:\WINDOWS\shs26A.tmp (Backdoor.ProRat) -> No action taken.
E:\WINDOWS\sht2A2.tmp (Backdoor.ProRat) -> No action taken.
E:\WINDOWS\sji4D8.tmp (Backdoor.ProRat) -> No action taken.
E:\WINDOWS\ske59.tmp (Backdoor.ProRat) -> No action taken.
E:\WINDOWS\skj4F6.tmp (Backdoor.ProRat) -> No action taken.
E:\WINDOWS\skl561.tmp (Backdoor.ProRat) -> No action taken.
E:\WINDOWS\sko1BD.tmp (Backdoor.ProRat) -> No action taken.
E:\WINDOWS\skv340.tmp (Backdoor.ProRat) -> No action taken.
E:\WINDOWS\sms24B.tmp (Backdoor.ProRat) -> No action taken.
E:\WINDOWS\son1A0.tmp (Backdoor.ProRat) -> No action taken.
E:\WINDOWS\ezo1B5.tmp (Backdoor.ProRat) -> No action taken.
E:\WINDOWS\ezp1D9.tmp (Backdoor.ProRat) -> No action taken.
E:\WINDOWS\ezq1FE.tmp (Backdoor.ProRat) -> No action taken.
E:\WINDOWS\fbf7E.tmp (Backdoor.ProRat) -> No action taken.
E:\WINDOWS\fbk53C.tmp (Backdoor.ProRat) -> No action taken.
E:\WINDOWS\fbv32D.tmp (Backdoor.ProRat) -> No action taken.
E:\WINDOWS\fct2B2.tmp (Backdoor.ProRat) -> No action taken.
E:\WINDOWS\fdl15D.tmp (Backdoor.ProRat) -> No action taken.
E:\WINDOWS\fdl560.tmp (Backdoor.ProRat) -> No action taken.
E:\WINDOWS\fdr21C.tmp (Backdoor.ProRat) -> No action taken.
E:\WINDOWS\ffp1D0.tmp (Backdoor.ProRat) -> No action taken.
E:\WINDOWS\fft28A.tmp (Backdoor.ProRat) -> No action taken.
E:\WINDOWS\ffv33E.tmp (Backdoor.ProRat) -> No action taken.
E:\WINDOWS\fhd3B.tmp (Backdoor.ProRat) -> No action taken.
E:\WINDOWS\fhk527.tmp (Backdoor.ProRat) -> No action taken.
E:\WINDOWS\fhx36E.tmp (Backdoor.ProRat) -> No action taken.
E:\WINDOWS\fhx376.tmp (Backdoor.ProRat) -> No action taken.
E:\WINDOWS\fiiEB.tmp (Backdoor.ProRat) -> No action taken.
E:\WINDOWS\fjj4FD.tmp (Backdoor.ProRat) -> No action taken.
E:\WINDOWS\fjt2C0.tmp (Backdoor.ProRat) -> No action taken.
E:\WINDOWS\fkm16B.tmp (Backdoor.ProRat) -> No action taken.
E:\WINDOWS\fkq1ED.tmp (Backdoor.ProRat) -> No action taken.
E:\WINDOWS\flt292.tmp (Backdoor.ProRat) -> No action taken.
E:\WINDOWS\flu2FD.tmp (Backdoor.ProRat) -> No action taken.
E:\WINDOWS\flz3A2.tmp (Backdoor.ProRat) -> No action taken.
E:\WINDOWS\fmf7C.tmp (Backdoor.ProRat) -> No action taken.
E:\WINDOWS\fnk52D.tmp (Backdoor.ProRat) -> No action taken.
E:\WINDOWS\fnq203.tmp (Backdoor.ProRat) -> No action taken.
E:\WINDOWS\fns258.tmp (Backdoor.ProRat) -> No action taken.
E:\WINDOWS\fpiE2.tmp (Backdoor.ProRat) -> No action taken.
E:\WINDOWS\txp1CF.tmp (Backdoor.ProRat) -> No action taken.
E:\WINDOWS\tyf468.tmp (Backdoor.ProRat) -> No action taken.
E:\WINDOWS\tygB2.tmp (Backdoor.ProRat) -> No action taken.
E:\WINDOWS\tzd3A.tmp (Backdoor.ProRat) -> No action taken.
E:\WINDOWS\uaiEA.tmp (Backdoor.ProRat) -> No action taken.
E:\WINDOWS\ubk125.tmp (Backdoor.ProRat) -> No action taken.
E:\WINDOWS\ubo1BF.tmp (Backdoor.ProRat) -> No action taken.
E:\WINDOWS\ubs22F.tmp (Backdoor.ProRat) -> No action taken.
E:\WINDOWS\ubs238.tmp (Backdoor.ProRat) -> No action taken.
E:\WINDOWS\ubs245.tmp (Backdoor.ProRat) -> No action taken.
E:\WINDOWS\ucgB9.tmp (Backdoor.ProRat) -> No action taken.
E:\WINDOWS\udd41.tmp (Backdoor.ProRat) -> No action taken.
E:\WINDOWS\udd4B.tmp (Backdoor.ProRat) -> No action taken.
E:\WINDOWS\udi4E1.tmp (Backdoor.ProRat) -> No action taken.
E:\WINDOWS\udo1AF.tmp (Backdoor.ProRat) -> No action taken.
E:\WINDOWS\udy389.tmp (Backdoor.ProRat) -> No action taken.
E:\WINDOWS\uel56A.tmp (Backdoor.ProRat) -> No action taken.
E:\WINDOWS\ufb3C4.tmp (Backdoor.ProRat) -> No action taken.
E:\WINDOWS\ufe437.tmp (Backdoor.ProRat) -> No action taken.
E:\WINDOWS\uge427.tmp (Backdoor.ProRat) -> No action taken.
E:\WINDOWS\ugs239.tmp (Backdoor.ProRat) -> No action taken.
E:\WINDOWS\ugt2CC.tmp (Backdoor.ProRat) -> No action taken.
E:\WINDOWS\uhj11C.tmp (Backdoor.ProRat) -> No action taken.
E:\WINDOWS\uij51A.tmp (Backdoor.ProRat) -> No action taken.
E:\WINDOWS\uil14A.tmp (Backdoor.ProRat) -> No action taken.
E:\WINDOWS\uiq209.tmp (Backdoor.ProRat) -> No action taken.
E:\WINDOWS\ujs271.tmp (Backdoor.ProRat) -> No action taken.
E:\WINDOWS\ule43D.tmp (Backdoor.ProRat) -> No action taken.
E:\WINDOWS\uli4D4.tmp (Backdoor.ProRat) -> No action taken.
E:\WINDOWS\umm168.tmp (Backdoor.ProRat) -> No action taken.
E:\WINDOWS\umr210.tmp (Backdoor.ProRat) -> No action taken.
E:\WINDOWS\unhD8.tmp (Backdoor.ProRat) -> No action taken.
E:\WINDOWS\ret2D3.tmp (Backdoor.ProRat) -> No action taken.
E:\WINDOWS\reu30E.tmp (Backdoor.ProRat) -> No action taken.
E:\WINDOWS\rev31D.tmp (Backdoor.ProRat) -> No action taken.
E:\WINDOWS\rfiFB.tmp (Backdoor.ProRat) -> No action taken.
E:\WINDOWS\rfl143.tmp (Backdoor.ProRat) -> No action taken.
E:\WINDOWS\rft2AB.tmp (Backdoor.ProRat) -> No action taken.
E:\WINDOWS\rfx37A.tmp (Backdoor.ProRat) -> No action taken.
E:\WINDOWS\rgd52.tmp (Backdoor.ProRat) -> No action taken.
E:\WINDOWS\rgi4EA.tmp (Backdoor.ProRat) -> No action taken.
E:\WINDOWS\rhd3F6.tmp (Backdoor.ProRat) -> No action taken.
E:\WINDOWS\rhs25D.tmp (Backdoor.ProRat) -> No action taken.
E:\WINDOWS\rhx37E.tmp (Backdoor.ProRat) -> No action taken.
E:\WINDOWS\rii4CD.tmp (Backdoor.ProRat) -> No action taken.
E:\WINDOWS\rik53D.tmp (Backdoor.ProRat) -> No action taken.
E:\WINDOWS\rje66.tmp (Backdoor.ProRat) -> No action taken.
E:\WINDOWS\rjt2BF.tmp (Backdoor.ProRat) -> No action taken.
E:\WINDOWS\rjv330.tmp (Backdoor.ProRat) -> No action taken.
E:\WINDOWS\rkc3CB.tmp (Backdoor.ProRat) -> No action taken.
E:\WINDOWS\rks24A.tmp (Backdoor.ProRat) -> No action taken.
E:\WINDOWS\rkt2B4.tmp (Backdoor.ProRat) -> No action taken.
E:\WINDOWS\rle42E.tmp (Backdoor.ProRat) -> No action taken.
E:\WINDOWS\rljFF.tmp (Backdoor.ProRat) -> No action taken.
E:\WINDOWS\rll15E.tmp (Backdoor.ProRat) -> No action taken.
E:\WINDOWS\rlm175.tmp (Backdoor.ProRat) -> No action taken.
E:\WINDOWS\bjk13D.tmp (Backdoor.ProRat) -> No action taken.
E:\WINDOWS\bwc1C.tmp (Backdoor.ProRat) -> No action taken.
E:\WINDOWS\chb3C5.tmp (Backdoor.ProRat) -> No action taken.
E:\WINDOWS\dcf95.tmp (Backdoor.ProRat) -> No action taken.
E:\WINDOWS\egr20C.tmp (Backdoor.ProRat) -> No action taken.
E:\WINDOWS\fpp1CE.tmp (Backdoor.ProRat) -> No action taken.
E:\WINDOWS\gae40E.tmp (Backdoor.ProRat) -> No action taken.
E:\WINDOWS\gkc2B.tmp (Backdoor.ProRat) -> No action taken.
E:\WINDOWS\hdjFE.tmp (Backdoor.ProRat) -> No action taken.
E:\WINDOWS\jnh4B2.tmp (Backdoor.ProRat) -> No action taken.
E:\WINDOWS\jys268.tmp (Backdoor.ProRat) -> No action taken.
E:\WINDOWS\kqj110.tmp (Backdoor.ProRat) -> No action taken.
E:\WINDOWS\lef455.tmp (Backdoor.ProRat) -> No action taken.
E:\WINDOWS\mbo1B2.tmp (Backdoor.ProRat) -> No action taken.
E:\WINDOWS\mjj119.tmp (Backdoor.ProRat) -> No action taken.
E:\WINDOWS\mpj4FE.tmp (Backdoor.ProRat) -> No action taken.
E:\WINDOWS\jay39A.tmp (Backdoor.ProRat) -> No action taken.
E:\WINDOWS\jbr21F.tmp (Backdoor.ProRat) -> No action taken.
E:\WINDOWS\jcv33D.tmp (Backdoor.ProRat) -> No action taken.
E:\WINDOWS\jde43A.tmp (Backdoor.ProRat) -> No action taken.
E:\WINDOWS\jdn181.tmp (Backdoor.ProRat) -> No action taken.
E:\WINDOWS\jfe5F.tmp (Backdoor.ProRat) -> No action taken.
E:\WINDOWS\jgg482.tmp (Backdoor.ProRat) -> No action taken.
E:\WINDOWS\jhb3BA.tmp (Backdoor.ProRat) -> No action taken.
E:\WINDOWS\jhe445.tmp (Backdoor.ProRat) -> No action taken.
E:\WINDOWS\jie73.tmp (Backdoor.ProRat) -> No action taken.
E:\WINDOWS\jif8C.tmp (Backdoor.ProRat) -> No action taken.
E:\WINDOWS\jir216.tmp (Backdoor.ProRat) -> No action taken.
E:\WINDOWS\jjhC7.tmp (Backdoor.ProRat) -> No action taken.
E:\WINDOWS\jjt29D.tmp (Backdoor.ProRat) -> No action taken.
E:\WINDOWS\jjv321.tmp (Backdoor.ProRat) -> No action taken.
E:\WINDOWS\jkh4CA.tmp (Backdoor.ProRat) -> No action taken.
E:\WINDOWS\jks27B.tmp (Backdoor.ProRat) -> No action taken.
E:\WINDOWS\jlv32B.tmp (Backdoor.ProRat) -> No action taken.
E:\WINDOWS\jlz3A0.tmp (Backdoor.ProRat) -> No action taken.
E:\WINDOWS\jmv331.tmp (Backdoor.ProRat) -> No action taken.
E:\WINDOWS\cot28D.tmp (Backdoor.ProRat) -> No action taken.
E:\WINDOWS\cps25F.tmp (Backdoor.ProRat) -> No action taken.
E:\WINDOWS\cqm16F.tmp (Backdoor.ProRat) -> No action taken.
E:\WINDOWS\csd3E7.tmp (Backdoor.ProRat) -> No action taken.
E:\WINDOWS\cso1A7.tmp (Backdoor.ProRat) -> No action taken.
E:\WINDOWS\css235.tmp (Backdoor.ProRat) -> No action taken.
E:\WINDOWS\ctj100.tmp (Backdoor.ProRat) -> No action taken.
E:\WINDOWS\ctn19A.tmp (Backdoor.ProRat) -> No action taken.
E:\WINDOWS\ctx380.tmp (Backdoor.ProRat) -> No action taken.
E:\WINDOWS\cwb3BD.tmp (Backdoor.ProRat) -> No action taken.
E:\WINDOWS\cwi4ED.tmp (Backdoor.ProRat) -> No action taken.
E:\WINDOWS\cwl14F.tmp (Backdoor.ProRat) -> No action taken.
E:\WINDOWS\cxo1B8.tmp (Backdoor.ProRat) -> No action taken.
E:\WINDOWS\cyg49F.tmp (Backdoor.ProRat) -> No action taken.
E:\WINDOWS\czgA5.tmp (Backdoor.ProRat) -> No action taken.
E:\WINDOWS\czt2A1.tmp (Backdoor.ProRat) -> No action taken.
E:\WINDOWS\dac3CF.tmp (Backdoor.ProRat) -> No action taken.
E:\WINDOWS\dat283.tmp (Backdoor.ProRat) -> No action taken.
E:\WINDOWS\dbs230.tmp (Backdoor.ProRat) -> No action taken.
E:\WINDOWS\dbt2A8.tmp (Backdoor.ProRat) -> No action taken.
E:\WINDOWS\dbt2B9.tmp (Backdoor.ProRat) -> No action taken.
E:\WINDOWS\dce411.tmp (Backdoor.ProRat) -> No action taken.
E:\WINDOWS\wjn19C.tmp (Backdoor.ProRat) -> No action taken.
E:\WINDOWS\wjt2BD.tmp (Backdoor.ProRat) -> No action taken.
E:\WINDOWS\wkn182.tmp (Backdoor.ProRat) -> No action taken.
E:\WINDOWS\wkp1E1.tmp (Backdoor.ProRat) -> No action taken.
E:\WINDOWS\wlj504.tmp (Backdoor.ProRat) -> No action taken.
E:\WINDOWS\wlp1D4.tmp (Backdoor.ProRat) -> No action taken.
E:\WINDOWS\upe42F.tmp (Backdoor.ProRat) -> No action taken.
E:\WINDOWS\uqd50.tmp (Backdoor.ProRat) -> No action taken.
E:\WINDOWS\uqiEC.tmp (Backdoor.ProRat) -> No action taken.
E:\WINDOWS\uqo1AA.tmp (Backdoor.ProRat) -> No action taken.
E:\WINDOWS\uqo1C1.tmp (Backdoor.ProRat) -> No action taken.
E:\WINDOWS\uqq1F3.tmp (Backdoor.ProRat) -> No action taken.
E:\WINDOWS\urn190.tmp (Backdoor.ProRat) -> No action taken.
E:\WINDOWS\usk53B.tmp (Backdoor.ProRat) -> No action taken.
E:\WINDOWS\usq207.tmp (Backdoor.ProRat) -> No action taken.
E:\WINDOWS\usu2E5.tmp (Backdoor.ProRat) -> No action taken.
E:\WINDOWS\ute64.tmp (Backdoor.ProRat) -> No action taken.
E:\WINDOWS\uts260.tmp (Backdoor.ProRat) -> No action taken.
E:\WINDOWS\uuf94.tmp (Backdoor.ProRat) -> No action taken.
E:\WINDOWS\uul55F.tmp (Backdoor.ProRat) -> No action taken.
E:\WINDOWS\uvh4B3.tmp (Backdoor.ProRat) -> No action taken.
E:\WINDOWS\uwc1D.tmp (Backdoor.ProRat) -> No action taken.
E:\WINDOWS\uwv339.tmp (Backdoor.ProRat) -> No action taken.
E:\WINDOWS\uxd3EB.tmp (Backdoor.ProRat) -> No action taken.
E:\WINDOWS\uxg47B.tmp (Backdoor.ProRat) -> No action taken.
E:\WINDOWS\uybE.tmp (Backdoor.ProRat) -> No action taken.
E:\WINDOWS\uzk526.tmp (Backdoor.ProRat) -> No action taken.
E:\WINDOWS\vau314.tmp (Backdoor.ProRat) -> No action taken.
E:\WINDOWS\vbp1D6.tmp (Backdoor.ProRat) -> No action taken.
E:\WINDOWS\vbq1FB.tmp (Backdoor.ProRat) -> No action taken.
E:\WINDOWS\vcu2DC.tmp (Backdoor.ProRat) -> No action taken.
E:\WINDOWS\vdt2B3.tmp (Backdoor.ProRat) -> No action taken.
E:\WINDOWS\veh4A5.tmp (Backdoor.ProRat) -> No action taken.
E:\WINDOWS\ves270.tmp (Backdoor.ProRat) -> No action taken.
E:\WINDOWS\ves27A.tmp (Backdoor.ProRat) -> No action taken.
E:\WINDOWS\vet291.tmp (Backdoor.ProRat) -> No action taken.
E:\WINDOWS\szc23.tmp (Backdoor.ProRat) -> No action taken.
E:\WINDOWS\tao1A8.tmp (Backdoor.ProRat) -> No action taken.
E:\WINDOWS\tbg488.tmp (Backdoor.ProRat) -> No action taken.
E:\WINDOWS\tbj506.tmp (Backdoor.ProRat) -> No action taken.
E:\WINDOWS\tcm16A.tmp (Backdoor.ProRat) -> No action taken.
E:\WINDOWS\tdt290.tmp (Backdoor.ProRat) -> No action taken.
E:\WINDOWS\tef7B.tmp (Backdoor.ProRat) -> No action taken.
E:\WINDOWS\ofx37B.tmp (Backdoor.ProRat) -> No action taken.
E:\WINDOWS\ogh4A0.tmp (Backdoor.ProRat) -> No action taken.
E:\WINDOWS\ogk129.tmp (Backdoor.ProRat) -> No action taken.
E:\WINDOWS\ogl567.tmp (Backdoor.ProRat) -> No action taken.
E:\WINDOWS\ohgA6.tmp (Backdoor.ProRat) -> No action taken.
E:\WINDOWS\ohj105.tmp (Backdoor.ProRat) -> No action taken.
E:\WINDOWS\oie400.tmp (Backdoor.ProRat) -> No action taken.
E:\WINDOWS\oie415.tmp (Backdoor.ProRat) -> No action taken.
E:\WINDOWS\oiw353.tmp (Backdoor.ProRat) -> No action taken.
E:\WINDOWS\ojiDE.tmp (Backdoor.ProRat) -> No action taken.
E:\WINDOWS\okhD1.tmp (Backdoor.ProRat) -> No action taken.
E:\WINDOWS\okp1CA.tmp (Backdoor.ProRat) -> No action taken.
E:\WINDOWS\oku312.tmp (Backdoor.ProRat) -> No action taken.
E:\WINDOWS\olh4B5.tmp (Backdoor.ProRat) -> No action taken.
E:\WINDOWS\oln199.tmp (Backdoor.ProRat) -> No action taken.
E:\WINDOWS\omp1DE.tmp (Backdoor.ProRat) -> No action taken.
E:\WINDOWS\omt295.tmp (Backdoor.ProRat) -> No action taken.
E:\WINDOWS\omv33B.tmp (Backdoor.ProRat) -> No action taken.
E:\WINDOWS\onhC1.tmp (Backdoor.ProRat) -> No action taken.
E:\WINDOWS\hru2E4.tmp (Backdoor.ProRat) -> No action taken.
E:\WINDOWS\hsc13.tmp (Backdoor.ProRat) -> No action taken.
E:\WINDOWS\hsu318.tmp (Backdoor.ProRat) -> No action taken.
E:\WINDOWS\htg487.tmp (Backdoor.ProRat) -> No action taken.
E:\WINDOWS\htx37F.tmp (Backdoor.ProRat) -> No action taken.
E:\WINDOWS\huu30C.tmp (Backdoor.ProRat) -> No action taken.
E:\WINDOWS\hve7A.tmp (Backdoor.ProRat) -> No action taken.
E:\WINDOWS\hvhD9.tmp (Backdoor.ProRat) -> No action taken.
E:\WINDOWS\hvi4E0.tmp (Backdoor.ProRat) -> No action taken.
E:\WINDOWS\hwl142.tmp (Backdoor.ProRat) -> No action taken.
E:\WINDOWS\hwn18A.tmp (Backdoor.ProRat) -> No action taken.
E:\WINDOWS\hxt2A7.tmp (Backdoor.ProRat) -> No action taken.
E:\WINDOWS\hyhC9.tmp (Backdoor.ProRat) -> No action taken.
E:\WINDOWS\hziE0.tmp (Backdoor.ProRat) -> No action taken.
E:\WINDOWS\iah4AD.tmp (Backdoor.ProRat) -> No action taken.
E:\WINDOWS\iaj519.tmp (Backdoor.ProRat) -> No action taken.
E:\WINDOWS\ibf465.tmp (Backdoor.ProRat) -> No action taken.
E:\WINDOWS\icd37.tmp (Backdoor.ProRat) -> No action taken.
E:\WINDOWS\icj4F3.tmp (Backdoor.ProRat) -> No action taken.
E:\WINDOWS\idw367.tmp (Backdoor.ProRat) -> No action taken.
E:\WINDOWS\lov338.tmp (Backdoor.ProRat) -> No action taken.
E:\WINDOWS\lpt286.tmp (Backdoor.ProRat) -> No action taken.
E:\WINDOWS\lqx36C.tmp (Backdoor.ProRat) -> No action taken.
E:\WINDOWS\lre443.tmp (Backdoor.ProRat) -> No action taken.
E:\WINDOWS\lrk13E.tmp (Backdoor.ProRat) -> No action taken.
E:\WINDOWS\lsu317.tmp (Backdoor.ProRat) -> No action taken.
E:\WINDOWS\ltn18D.tmp (Backdoor.ProRat) -> No action taken.
E:\WINDOWS\ltp1D5.tmp (Backdoor.ProRat) -> No action taken.
E:\WINDOWS\lts236.tmp (Backdoor.ProRat) -> No action taken.
E:\WINDOWS\lue6E.tmp (Backdoor.ProRat) -> No action taken.
E:\WINDOWS\luo1A4.tmp (Backdoor.ProRat) -> No action taken.
E:\WINDOWS\lvt2B1.tmp (Backdoor.ProRat) -> No action taken.
E:\WINDOWS\lxi4EF.tmp (Backdoor.ProRat) -> No action taken.
E:\WINDOWS\lxm170.tmp (Backdoor.ProRat) -> No action taken.
E:\WINDOWS\lxo1AB.tmp (Backdoor.ProRat) -> No action taken.
E:\WINDOWS\lxz39C.tmp (Backdoor.ProRat) -> No action taken.
E:\WINDOWS\lys237.tmp (Backdoor.ProRat) -> No action taken.
E:\WINDOWS\lyt2CA.tmp (Backdoor.ProRat) -> No action taken.
E:\WINDOWS\lzf81.tmp (Backdoor.ProRat) -> No action taken.
E:\WINDOWS\lzj11B.tmp (Backdoor.ProRat) -> No action taken.
E:\WINDOWS\maf98.tmp (Backdoor.ProRat) -> No action taken.
E:\WINDOWS\maj4F9.tmp (Backdoor.ProRat) -> No action taken.
E:\WINDOWS\mbm160.tmp (Backdoor.ProRat) -> No action taken.
E:\WINDOWS\mbn19B.tmp (Backdoor.ProRat) -> No action taken.
E:\WINDOWS\aqe401.tmp (Backdoor.ProRat) -> No action taken.
E:\WINDOWS\asj518.tmp (Backdoor.ProRat) -> No action taken.
E:\WINDOWS\atc3D1.tmp (Backdoor.ProRat) -> No action taken.
E:\WINDOWS\atk13B.tmp (Backdoor.ProRat) -> No action taken.
E:\WINDOWS\auiF3.tmp (Backdoor.ProRat) -> No action taken.
E:\WINDOWS\aup1DF.tmp (Backdoor.ProRat) -> No action taken.
E:\WINDOWS\avd3EE.tmp (Backdoor.ProRat) -> No action taken.
E:\WINDOWS\avhC2.tmp (Backdoor.ProRat) -> No action taken.
E:\WINDOWS\awp1C5.tmp (Backdoor.ProRat) -> No action taken.
E:\WINDOWS\awr20E.tmp (Backdoor.ProRat) -> No action taken.
E:\WINDOWS\aws277.tmp (Backdoor.ProRat) -> No action taken.
E:\WINDOWS\axk52A.tmp (Backdoor.ProRat) -> No action taken.
E:\WINDOWS\azm17A.tmp (Backdoor.ProRat) -> No action taken.
E:\WINDOWS\bab3B6.tmp (Backdoor.ProRat) -> No action taken.
E:\WINDOWS\bac2D.tmp (Backdoor.ProRat) -> No action taken.
E:\WINDOWS\bae42A.tmp (Backdoor.ProRat) -> No action taken.
E:\WINDOWS\bae72.tmp (Backdoor.ProRat) -> No action taken.
E:\WINDOWS\bam16D.tmp (Backdoor.ProRat) -> No action taken.
E:\WINDOWS\baq1EF.tmp (Backdoor.ProRat) -> No action taken.
E:\WINDOWS\bbd4E.tmp (Backdoor.ProRat) -> No action taken.
E:\WINDOWS\bbe3FF.tmp (Backdoor.ProRat) -> No action taken.
E:\WINDOWS\bbi4D7.tmp (Backdoor.ProRat) -> No action taken.
E:\WINDOWS\bcl146.tmp (Backdoor.ProRat) -> No action taken.
E:\WINDOWS\bcu2DD.tmp (Backdoor.ProRat) -> No action taken.
E:\WINDOWS\bds25C.tmp (Backdoor.ProRat) -> No action taken.
E:\WINDOWS\bei4F0.tmp (Backdoor.ProRat) -> No action taken.
E:\WINDOWS\bes248.tmp (Backdoor.ProRat) -> No action taken.
E:\WINDOWS\bgc3D4.tmp (Backdoor.ProRat) -> No action taken.
E:\WINDOWS\bgi4D0.tmp (Backdoor.ProRat) -> No action taken.
E:\WINDOWS\bgl14D.tmp (Backdoor.ProRat) -> No action taken.
E:\WINDOWS\bgp1C3.tmp (Backdoor.ProRat) -> No action taken.
E:\WINDOWS\bhx36F.tmp (Backdoor.ProRat) -> No action taken.
E:\WINDOWS\bit284.tmp (Backdoor.ProRat) -> No action taken.
E:\WINDOWS\bix371.tmp (Backdoor.ProRat) -> No action taken.
E:\WINDOWS\dqj51B.tmp (Backdoor.ProRat) -> No action taken.
E:\WINDOWS\dqt2D8.tmp (Backdoor.ProRat) -> No action taken.
E:\WINDOWS\dre5A.tmp (Backdoor.ProRat) -> No action taken.
E:\WINDOWS\dri4D9.tmp (Backdoor.ProRat) -> No action taken.
E:\WINDOWS\dsb3AF.tmp (Backdoor.ProRat) -> No action taken.
E:\WINDOWS\dsb3C2.tmp (Backdoor.ProRat) -> No action taken.
E:\WINDOWS\dsc15.tmp (Backdoor.ProRat) -> No action taken.
E:\WINDOWS\dst2B6.tmp (Backdoor.ProRat) -> No action taken.
E:\WINDOWS\dtbC.tmp (Backdoor.ProRat) -> No action taken.
E:\WINDOWS\dur211.tmp (Backdoor.ProRat) -> No action taken.
E:\WINDOWS\dvf87.tmp (Backdoor.ProRat) -> No action taken.
E:\WINDOWS\dvu2F2.tmp (Backdoor.ProRat) -> No action taken.
E:\WINDOWS\dwf46E.tmp (Backdoor.ProRat) -> No action taken.
E:\WINDOWS\dwgB5.tmp (Backdoor.ProRat) -> No action taken.
E:\WINDOWS\dyq1F4.tmp (Backdoor.ProRat) -> No action taken.
E:\WINDOWS\dyu319.tmp (Backdoor.ProRat) -> No action taken.
E:\WINDOWS\dzv323.tmp (Backdoor.ProRat) -> No action taken.
E:\WINDOWS\eae410.tmp (Backdoor.ProRat) -> No action taken.
E:\WINDOWS\eas22C.tmp (Backdoor.ProRat) -> No action taken.
E:\WINDOWS\ebe65.tmp (Backdoor.ProRat) -> No action taken.
E:\WINDOWS\ebs262.tmp (Backdoor.ProRat) -> No action taken.
E:\WINDOWS\ecj10B.tmp (Backdoor.ProRat) -> No action taken.
E:\WINDOWS\ecs255.tmp (Backdoor.ProRat) -> No action taken.
E:\WINDOWS\edn198.tmp (Backdoor.ProRat) -> No action taken.
E:\WINDOWS\eek520.tmp (Backdoor.ProRat) -> No action taken.
E:\WINDOWS\eev33A.tmp (Backdoor.ProRat) -> No action taken.
E:\WINDOWS\efp1DD.tmp (Backdoor.ProRat) -> No action taken.
E:\WINDOWS\eft2AC.tmp (Backdoor.ProRat) -> No action taken.
E:\WINDOWS\efv336.tmp (Backdoor.ProRat) -> No action taken.
E:\WINDOWS\efv33F.tmp (Backdoor.ProRat) -> No action taken.
E:\WINDOWS\egd3EC.tmp (Backdoor.ProRat) -> No action taken.
E:\WINDOWS\eggB3.tmp (Backdoor.ProRat) -> No action taken.
E:\WINDOWS\wxf45E.tmp (Backdoor.ProRat) -> No action taken.
E:\WINDOWS\wxu2EC.tmp (Backdoor.ProRat) -> No action taken.
 
E:\WINDOWS\wyh4BB.tmp (Backdoor.ProRat) -> No action taken.
E:\WINDOWS\wyl556.tmp (Backdoor.ProRat) -> No action taken.
E:\WINDOWS\wyn187.tmp (Backdoor.ProRat) -> No action taken.
E:\WINDOWS\wzr222.tmp (Backdoor.ProRat) -> No action taken.
E:\WINDOWS\xar215.tmp (Backdoor.ProRat) -> No action taken.
E:\WINDOWS\xbc3D3.tmp (Backdoor.ProRat) -> No action taken.
E:\WINDOWS\xce6F.tmp (Backdoor.ProRat) -> No action taken.
E:\WINDOWS\xcj516.tmp (Backdoor.ProRat) -> No action taken.
E:\WINDOWS\xcn18E.tmp (Backdoor.ProRat) -> No action taken.
E:\WINDOWS\xed3DC.tmp (Backdoor.ProRat) -> No action taken.
E:\WINDOWS\xej108.tmp (Backdoor.ProRat) -> No action taken.
E:\WINDOWS\xet2D4.tmp (Backdoor.ProRat) -> No action taken.
E:\WINDOWS\xfgA9.tmp (Backdoor.ProRat) -> No action taken.
E:\WINDOWS\xfh4B1.tmp (Backdoor.ProRat) -> No action taken.
E:\WINDOWS\xgj51D.tmp (Backdoor.ProRat) -> No action taken.
E:\WINDOWS\xgk540.tmp (Backdoor.ProRat) -> No action taken.
E:\WINDOWS\xgm171.tmp (Backdoor.ProRat) -> No action taken.
E:\WINDOWS\xhc19.tmp (Backdoor.ProRat) -> No action taken.
E:\WINDOWS\xhf45C.tmp (Backdoor.ProRat) -> No action taken.
E:\WINDOWS\xhi4DB.tmp (Backdoor.ProRat) -> No action taken.
E:\WINDOWS\xho1B6.tmp (Backdoor.ProRat) -> No action taken.
E:\WINDOWS\tfs256.tmp (Backdoor.ProRat) -> No action taken.
E:\WINDOWS\thc17.tmp (Backdoor.ProRat) -> No action taken.
E:\WINDOWS\thd44.tmp (Backdoor.ProRat) -> No action taken.
E:\WINDOWS\the69.tmp (Backdoor.ProRat) -> No action taken.
E:\WINDOWS\thiE1.tmp (Backdoor.ProRat) -> No action taken.
E:\WINDOWS\tie414.tmp (Backdoor.ProRat) -> No action taken.
E:\WINDOWS\tif44F.tmp (Backdoor.ProRat) -> No action taken.
E:\WINDOWS\tit2BB.tmp (Backdoor.ProRat) -> No action taken.
E:\WINDOWS\tku311.tmp (Backdoor.ProRat) -> No action taken.
E:\WINDOWS\tlb3C7.tmp (Backdoor.ProRat) -> No action taken.
E:\WINDOWS\tmk544.tmp (Backdoor.ProRat) -> No action taken.
E:\WINDOWS\tnd3FA.tmp (Backdoor.ProRat) -> No action taken.
E:\WINDOWS\tob3C0.tmp (Backdoor.ProRat) -> No action taken.
E:\WINDOWS\tot2CD.tmp (Backdoor.ProRat) -> No action taken.
E:\WINDOWS\tpiF9.tmp (Backdoor.ProRat) -> No action taken.
E:\WINDOWS\trgBB.tmp (Backdoor.ProRat) -> No action taken.
E:\WINDOWS\trp1D8.tmp (Backdoor.ProRat) -> No action taken.
E:\WINDOWS\trq1FD.tmp (Backdoor.ProRat) -> No action taken.
E:\WINDOWS\pro1B4.tmp (Backdoor.ProRat) -> No action taken.
E:\WINDOWS\psd3FE.tmp (Backdoor.ProRat) -> No action taken.
E:\WINDOWS\psd4D.tmp (Backdoor.ProRat) -> No action taken.
E:\WINDOWS\psm16C.tmp (Backdoor.ProRat) -> No action taken.
E:\WINDOWS\pthC5.tmp (Backdoor.ProRat) -> No action taken.
E:\WINDOWS\pti4D6.tmp (Backdoor.ProRat) -> No action taken.
E:\WINDOWS\ptt296.tmp (Backdoor.ProRat) -> No action taken.
E:\WINDOWS\ptv31F.tmp (Backdoor.ProRat) -> No action taken.
E:\WINDOWS\pul145.tmp (Backdoor.ProRat) -> No action taken.
E:\WINDOWS\pus274.tmp (Backdoor.ProRat) -> No action taken.
E:\WINDOWS\pvv329.tmp (Backdoor.ProRat) -> No action taken.
E:\WINDOWS\pws276.tmp (Backdoor.ProRat) -> No action taken.
E:\WINDOWS\pwu307.tmp (Backdoor.ProRat) -> No action taken.
E:\WINDOWS\pxc1F.tmp (Backdoor.ProRat) -> No action taken.
E:\WINDOWS\pxj11E.tmp (Backdoor.ProRat) -> No action taken.
E:\WINDOWS\pyz3A6.tmp (Backdoor.ProRat) -> No action taken.
E:\WINDOWS\qaiF7.tmp (Backdoor.ProRat) -> No action taken.
E:\WINDOWS\qat282.tmp (Backdoor.ProRat) -> No action taken.
E:\WINDOWS\qbs22D.tmp (Backdoor.ProRat) -> No action taken.
E:\WINDOWS\qed3D9.tmp (Backdoor.ProRat) -> No action taken.
E:\WINDOWS\qed3DB.tmp (Backdoor.ProRat) -> No action taken.
E:\WINDOWS\qej115.tmp (Backdoor.ProRat) -> No action taken.
E:\WINDOWS\qel150.tmp (Backdoor.ProRat) -> No action taken.
E:\WINDOWS\qen18B.tmp (Backdoor.ProRat) -> No action taken.
E:\WINDOWS\qeq1F8.tmp (Backdoor.ProRat) -> No action taken.
E:\WINDOWS\qfe77.tmp (Backdoor.ProRat) -> No action taken.
E:\WINDOWS\qfq202.tmp (Backdoor.ProRat) -> No action taken.
E:\WINDOWS\qgb3B9.tmp (Backdoor.ProRat) -> No action taken.
E:\WINDOWS\qgf8F.tmp (Backdoor.ProRat) -> No action taken.
E:\WINDOWS\bwf454.tmp (Backdoor.ProRat) -> No action taken.
E:\WINDOWS\bwm166.tmp (Backdoor.ProRat) -> No action taken.
E:\WINDOWS\bwn1A1.tmp (Backdoor.ProRat) -> No action taken.
E:\WINDOWS\bye75.tmp (Backdoor.ProRat) -> No action taken.
E:\WINDOWS\byi4E7.tmp (Backdoor.ProRat) -> No action taken.
E:\WINDOWS\byj509.tmp (Backdoor.ProRat) -> No action taken.
E:\WINDOWS\byk128.tmp (Backdoor.ProRat) -> No action taken.
E:\WINDOWS\cahBC.tmp (Backdoor.ProRat) -> No action taken.
E:\WINDOWS\cak549.tmp (Backdoor.ProRat) -> No action taken.
E:\WINDOWS\cbiDD.tmp (Backdoor.ProRat) -> No action taken.
E:\WINDOWS\cchD0.tmp (Backdoor.ProRat) -> No action taken.
E:\WINDOWS\ccj118.tmp (Backdoor.ProRat) -> No action taken.
E:\WINDOWS\cdk139.tmp (Backdoor.ProRat) -> No action taken.
E:\WINDOWS\cds269.tmp (Backdoor.ProRat) -> No action taken.
E:\WINDOWS\cdu2F5.tmp (Backdoor.ProRat) -> No action taken.
E:\WINDOWS\ced34.tmp (Backdoor.ProRat) -> No action taken.
E:\WINDOWS\cff85.tmp (Backdoor.ProRat) -> No action taken.
E:\WINDOWS\cfhC0.tmp (Backdoor.ProRat) -> No action taken.
E:\WINDOWS\cfk11F.tmp (Backdoor.ProRat) -> No action taken.
E:\WINDOWS\cgg9C.tmp (Backdoor.ProRat) -> No action taken.
E:\WINDOWS\saq1E3.tmp (Backdoor.ProRat) -> No action taken.
E:\WINDOWS\sbgA2.tmp (Backdoor.ProRat) -> No action taken.
E:\WINDOWS\sbz39F.tmp (Backdoor.ProRat) -> No action taken.
E:\WINDOWS\scr212.tmp (Backdoor.ProRat) -> No action taken.
E:\WINDOWS\sde436.tmp (Backdoor.ProRat) -> No action taken.
E:\WINDOWS\sdhDA.tmp (Backdoor.ProRat) -> No action taken.
E:\WINDOWS\gkd4C.tmp (Backdoor.ProRat) -> No action taken.
E:\WINDOWS\glt293.tmp (Backdoor.ProRat) -> No action taken.
E:\WINDOWS\glx375.tmp (Backdoor.ProRat) -> No action taken.
E:\WINDOWS\gme449.tmp (Backdoor.ProRat) -> No action taken.
E:\WINDOWS\gmj109.tmp (Backdoor.ProRat) -> No action taken.
E:\WINDOWS\gms272.tmp (Backdoor.ProRat) -> No action taken.
E:\WINDOWS\goiEF.tmp (Backdoor.ProRat) -> No action taken.
E:\WINDOWS\gpf83.tmp (Backdoor.ProRat) -> No action taken.
E:\WINDOWS\gpf9A.tmp (Backdoor.ProRat) -> No action taken.
E:\WINDOWS\gpn193.tmp (Backdoor.ProRat) -> No action taken.
E:\WINDOWS\gqx36D.tmp (Backdoor.ProRat) -> No action taken.
E:\WINDOWS\grs273.tmp (Backdoor.ProRat) -> No action taken.
E:\WINDOWS\gsl562.tmp (Backdoor.ProRat) -> No action taken.
E:\WINDOWS\gss280.tmp (Backdoor.ProRat) -> No action taken.
E:\WINDOWS\gte43E.tmp (Backdoor.ProRat) -> No action taken.
E:\WINDOWS\gts24D.tmp (Backdoor.ProRat) -> No action taken.
E:\WINDOWS\gum169.tmp (Backdoor.ProRat) -> No action taken.
E:\WINDOWS\guq1EB.tmp (Backdoor.ProRat) -> No action taken.
E:\WINDOWS\gus251.tmp (Backdoor.ProRat) -> No action taken.
E:\WINDOWS\gvq1F7.tmp (Backdoor.ProRat) -> No action taken.
E:\WINDOWS\gvs252.tmp (Backdoor.ProRat) -> No action taken.
E:\WINDOWS\gwc1E.tmp (Backdoor.ProRat) -> No action taken.
E:\WINDOWS\gxv326.tmp (Backdoor.ProRat) -> No action taken.
E:\WINDOWS\gyd51.tmp (Backdoor.ProRat) -> No action taken.
E:\WINDOWS\gyiED.tmp (Backdoor.ProRat) -> No action taken.
E:\WINDOWS\gyt289.tmp (Backdoor.ProRat) -> No action taken.
E:\WINDOWS\gzb3B4.tmp (Backdoor.ProRat) -> No action taken.
E:\WINDOWS\hag478.tmp (Backdoor.ProRat) -> No action taken.
E:\WINDOWS\han191.tmp (Backdoor.ProRat) -> No action taken.
E:\WINDOWS\hcd3D8.tmp (Backdoor.ProRat) -> No action taken.
E:\WINDOWS\hcd3E0.tmp (Backdoor.ProRat) -> No action taken.
E:\WINDOWS\hcs246.tmp (Backdoor.ProRat) -> No action taken.
E:\WINDOWS\kqn186.tmp (Backdoor.ProRat) -> No action taken.
E:\WINDOWS\krbA.tmp (Backdoor.ProRat) -> No action taken.
E:\WINDOWS\ksi4E3.tmp (Backdoor.ProRat) -> No action taken.
E:\WINDOWS\ksiE9.tmp (Backdoor.ProRat) -> No action taken.
E:\WINDOWS\ksk131.tmp (Backdoor.ProRat) -> No action taken.
E:\WINDOWS\ksu313.tmp (Backdoor.ProRat) -> No action taken.
E:\WINDOWS\ktf457.tmp (Backdoor.ProRat) -> No action taken.
E:\WINDOWS\ktf8A.tmp (Backdoor.ProRat) -> No action taken.
E:\WINDOWS\ktq1FA.tmp (Backdoor.ProRat) -> No action taken.
E:\WINDOWS\kvd40.tmp (Backdoor.ProRat) -> No action taken.
E:\WINDOWS\kve61.tmp (Backdoor.ProRat) -> No action taken.
E:\WINDOWS\kwh4A4.tmp (Backdoor.ProRat) -> No action taken.
E:\WINDOWS\kwj107.tmp (Backdoor.ProRat) -> No action taken.
E:\WINDOWS\kwl569.tmp (Backdoor.ProRat) -> No action taken.
E:\WINDOWS\kxk54C.tmp (Backdoor.ProRat) -> No action taken.
E:\WINDOWS\kxm17D.tmp (Backdoor.ProRat) -> No action taken.
E:\WINDOWS\kxs254.tmp (Backdoor.ProRat) -> No action taken.
E:\WINDOWS\kyk53F.tmp (Backdoor.ProRat) -> No action taken.
E:\WINDOWS\kyo1C2.tmp (Backdoor.ProRat) -> No action taken.
E:\WINDOWS\kzc22.tmp (Backdoor.ProRat) -> No action taken.
E:\WINDOWS\lahD3.tmp (Backdoor.ProRat) -> No action taken.
E:\WINDOWS\lap1CC.tmp (Backdoor.ProRat) -> No action taken.
E:\WINDOWS\lbk523.tmp (Backdoor.ProRat) -> No action taken.
E:\WINDOWS\lbs22E.tmp (Backdoor.ProRat) -> No action taken.
E:\WINDOWS\lcd3D7.tmp (Backdoor.ProRat) -> No action taken.
E:\WINDOWS\ylg486.tmp (Backdoor.ProRat) -> No action taken.
E:\WINDOWS\ymc28.tmp (Backdoor.ProRat) -> No action taken.
E:\WINDOWS\ymf456.tmp (Backdoor.ProRat) -> No action taken.
E:\WINDOWS\yml151.tmp (Backdoor.ProRat) -> No action taken.
E:\WINDOWS\yni4DF.tmp (Backdoor.ProRat) -> No action taken.
E:\WINDOWS\yof90.tmp (Backdoor.ProRat) -> No action taken.
E:\WINDOWS\yoh4A1.tmp (Backdoor.ProRat) -> No action taken.
E:\WINDOWS\ypk54B.tmp (Backdoor.ProRat) -> No action taken.
E:\WINDOWS\yqc11.tmp (Backdoor.ProRat) -> No action taken.
E:\WINDOWS\yqc2F.tmp (Backdoor.ProRat) -> No action taken.
E:\WINDOWS\yrj11A.tmp (Backdoor.ProRat) -> No action taken.
E:\WINDOWS\yrs259.tmp (Backdoor.ProRat) -> No action taken.
E:\WINDOWS\yru2FF.tmp (Backdoor.ProRat) -> No action taken.
E:\WINDOWS\ysb3C1.tmp (Backdoor.ProRat) -> No action taken.
E:\WINDOWS\ytk529.tmp (Backdoor.ProRat) -> No action taken.
E:\WINDOWS\yts26D.tmp (Backdoor.ProRat) -> No action taken.
E:\WINDOWS\yus243.tmp (Backdoor.ProRat) -> No action taken.
E:\WINDOWS\yvl15C.tmp (Backdoor.ProRat) -> No action taken.
E:\WINDOWS\yvv348.tmp (Backdoor.ProRat) -> No action taken.
E:\WINDOWS\ywb3BF.tmp (Backdoor.ProRat) -> No action taken.
E:\WINDOWS\ywe41E.tmp (Backdoor.ProRat) -> No action taken.
E:\WINDOWS\yxe5E.tmp (Backdoor.ProRat) -> No action taken.
E:\WINDOWS\yyc21.tmp (Backdoor.ProRat) -> No action taken.
E:\WINDOWS\yyl566.tmp (Backdoor.ProRat) -> No action taken.
E:\WINDOWS\yzg48D.tmp (Backdoor.ProRat) -> No action taken.
E:\WINDOWS\zbf8B.tmp (Backdoor.ProRat) -> No action taken.
E:\WINDOWS\zbhC6.tmp (Backdoor.ProRat) -> No action taken.
E:\WINDOWS\zbt29B.tmp (Backdoor.ProRat) -> No action taken.
E:\WINDOWS\zbt2A9.tmp (Backdoor.ProRat) -> No action taken.
E:\WINDOWS\zcg475.tmp (Backdoor.ProRat) -> No action taken.
E:\WINDOWS\zcs279.tmp (Backdoor.ProRat) -> No action taken.
E:\WINDOWS\mjt2C1.tmp (Backdoor.ProRat) -> No action taken.
E:\WINDOWS\mkg476.tmp (Backdoor.ProRat) -> No action taken.
E:\WINDOWS\mks257.tmp (Backdoor.ProRat) -> No action taken.
E:\WINDOWS\mld35.tmp (Backdoor.ProRat) -> No action taken.
E:\WINDOWS\mle42C.tmp (Backdoor.ProRat) -> No action taken.
E:\WINDOWS\mle63.tmp (Backdoor.ProRat) -> No action taken.
E:\WINDOWS\mlk13A.tmp (Backdoor.ProRat) -> No action taken.
E:\WINDOWS\mlu2F7.tmp (Backdoor.ProRat) -> No action taken.
E:\WINDOWS\mmiF2.tmp (Backdoor.ProRat) -> No action taken.
E:\WINDOWS\mmm17F.tmp (Backdoor.ProRat) -> No action taken.
E:\WINDOWS\mms241.tmp (Backdoor.ProRat) -> No action taken.
E:\WINDOWS\mne438.tmp (Backdoor.ProRat) -> No action taken.
E:\WINDOWS\mni4D1.tmp (Backdoor.ProRat) -> No action taken.
E:\WINDOWS\mnk120.tmp (Backdoor.ProRat) -> No action taken.
E:\WINDOWS\mnl15B.tmp (Backdoor.ProRat) -> No action taken.
E:\WINDOWS\vzx368.tmp (Backdoor.ProRat) -> No action taken.
E:\WINDOWS\wag49B.tmp (Backdoor.ProRat) -> No action taken.
E:\WINDOWS\wai4E4.tmp (Backdoor.ProRat) -> No action taken.
E:\WINDOWS\wbz39D.tmp (Backdoor.ProRat) -> No action taken.
E:\WINDOWS\wcc2A.tmp (Backdoor.ProRat) -> No action taken.
E:\WINDOWS\wce434.tmp (Backdoor.ProRat) -> No action taken.
E:\WINDOWS\wcf44B.tmp (Backdoor.ProRat) -> No action taken.
E:\WINDOWS\wde62.tmp (Backdoor.ProRat) -> No action taken.
E:\WINDOWS\wfb3B7.tmp (Backdoor.ProRat) -> No action taken.
E:\WINDOWS\wfm17E.tmp (Backdoor.ProRat) -> No action taken.
E:\WINDOWS\whe43C.tmp (Backdoor.ProRat) -> No action taken.
E:\WINDOWS\whp1CD.tmp (Backdoor.ProRat) -> No action taken.
E:\WINDOWS\wig479.tmp (Backdoor.ProRat) -> No action taken.
E:\WINDOWS\wim161.tmp (Backdoor.ProRat) -> No action taken.
E:\WINDOWS\ije416.tmp (Backdoor.ProRat) -> No action taken.
E:\WINDOWS\ijx378.tmp (Backdoor.ProRat) -> No action taken.
E:\WINDOWS\ilo1B0.tmp (Backdoor.ProRat) -> No action taken.
E:\WINDOWS\imt2AE.tmp (Backdoor.ProRat) -> No action taken.
E:\WINDOWS\imt2D7.tmp (Backdoor.ProRat) -> No action taken.
E:\WINDOWS\imu30A.tmp (Backdoor.ProRat) -> No action taken.
E:\WINDOWS\imv341.tmp (Backdoor.ProRat) -> No action taken.
E:\WINDOWS\ingAA.tmp (Backdoor.ProRat) -> No action taken.
E:\WINDOWS\ins265.tmp (Backdoor.ProRat) -> No action taken.
E:\WINDOWS\iok541.tmp (Backdoor.ProRat) -> No action taken.
E:\WINDOWS\ipd3F7.tmp (Backdoor.ProRat) -> No action taken.
E:\WINDOWS\iqm162.tmp (Backdoor.ProRat) -> No action taken.
E:\WINDOWS\iqt2C6.tmp (Backdoor.ProRat) -> No action taken.
E:\WINDOWS\iqv343.tmp (Backdoor.ProRat) -> No action taken.
E:\WINDOWS\ird39.tmp (Backdoor.ProRat) -> No action taken.
E:\WINDOWS\iriF6.tmp (Backdoor.ProRat) -> No action taken.
E:\WINDOWS\isk124.tmp (Backdoor.ProRat) -> No action taken.
E:\WINDOWS\iso1BE.tmp (Backdoor.ProRat) -> No action taken.
E:\WINDOWS\itbB.tmp (Backdoor.ProRat) -> No action taken.
E:\WINDOWS\itd3F1.tmp (Backdoor.ProRat) -> No action taken.
E:\WINDOWS\itgA1.tmp (Backdoor.ProRat) -> No action taken.
E:\WINDOWS\ivd4A.tmp (Backdoor.ProRat) -> No action taken.
E:\WINDOWS\iwj50C.tmp (Backdoor.ProRat) -> No action taken.
E:\WINDOWS\ixd3DF.tmp (Backdoor.ProRat) -> No action taken.
E:\WINDOWS\ixe420.tmp (Backdoor.ProRat) -> No action taken.
E:\WINDOWS\ixe430.tmp (Backdoor.ProRat) -> No action taken.
E:\WINDOWS\iyc30.tmp (Backdoor.ProRat) -> No action taken.
E:\WINDOWS\izt2A0.tmp (Backdoor.ProRat) -> No action taken.
E:\WINDOWS\jaj10E.tmp (Backdoor.ProRat) -> No action taken.
E:\WINDOWS\jal149.tmp (Backdoor.ProRat) -> No action taken.
E:\WINDOWS\jas25B.tmp (Backdoor.ProRat) -> No action taken.
E:\WINDOWS\npe41A.tmp (Backdoor.ProRat) -> No action taken.
E:\WINDOWS\npu2EA.tmp (Backdoor.ProRat) -> No action taken.
E:\WINDOWS\nqe41B.tmp (Backdoor.ProRat) -> No action taken.
E:\WINDOWS\nrs23C.tmp (Backdoor.ProRat) -> No action taken.
E:\WINDOWS\nsg499.tmp (Backdoor.ProRat) -> No action taken.
E:\WINDOWS\nsq1E7.tmp (Backdoor.ProRat) -> No action taken.
E:\WINDOWS\nsr214.tmp (Backdoor.ProRat) -> No action taken.
E:\WINDOWS\ntw352.tmp (Backdoor.ProRat) -> No action taken.
E:\WINDOWS\nue44A.tmp (Backdoor.ProRat) -> No action taken.
E:\WINDOWS\nuq1E9.tmp (Backdoor.ProRat) -> No action taken.
E:\WINDOWS\nwc3D2.tmp (Backdoor.ProRat) -> No action taken.
E:\WINDOWS\unu2F0.tmp (Backdoor.ProRat) -> No action taken.
E:\WINDOWS\uoe79.tmp (Backdoor.ProRat) -> No action taken.
E:\WINDOWS\uoj50B.tmp (Backdoor.ProRat) -> No action taken.
E:\WINDOWS\uol141.tmp (Backdoor.ProRat) -> No action taken.
E:\WINDOWS\uor224.tmp (Backdoor.ProRat) -> No action taken.
E:\WINDOWS\fqc10.tmp (Backdoor.ProRat) -> No action taken.
E:\WINDOWS\fql14B.tmp (Backdoor.ProRat) -> No action taken.
E:\WINDOWS\frd3E6.tmp (Backdoor.ProRat) -> No action taken.
E:\WINDOWS\fsp1E2.tmp (Backdoor.ProRat) -> No action taken.
E:\WINDOWS\ftm176.tmp (Backdoor.ProRat) -> No action taken.
E:\WINDOWS\fuk545.tmp (Backdoor.ProRat) -> No action taken.
E:\WINDOWS\fvd3FB.tmp (Backdoor.ProRat) -> No action taken.
E:\WINDOWS\fvt28E.tmp (Backdoor.ProRat) -> No action taken.
E:\WINDOWS\fvt2D0.tmp (Backdoor.ProRat) -> No action taken.
E:\WINDOWS\fwb3C3.tmp (Backdoor.ProRat) -> No action taken.
E:\WINDOWS\fwc26.tmp (Backdoor.ProRat) -> No action taken.
E:\WINDOWS\fwe447.tmp (Backdoor.ProRat) -> No action taken.
E:\WINDOWS\fwr225.tmp (Backdoor.ProRat) -> No action taken.
E:\WINDOWS\fwu31C.tmp (Backdoor.ProRat) -> No action taken.
E:\WINDOWS\fxiFA.tmp (Backdoor.ProRat) -> No action taken.
E:\WINDOWS\fyc20.tmp (Backdoor.ProRat) -> No action taken.
E:\WINDOWS\fyf8E.tmp (Backdoor.ProRat) -> No action taken.
E:\WINDOWS\fzd3F5.tmp (Backdoor.ProRat) -> No action taken.
E:\WINDOWS\fzl156.tmp (Backdoor.ProRat) -> No action taken.
E:\WINDOWS\ehc24.tmp (Backdoor.ProRat) -> No action taken.
E:\WINDOWS\ehiF8.tmp (Backdoor.ProRat) -> No action taken.
E:\WINDOWS\ehx370.tmp (Backdoor.ProRat) -> No action taken.
E:\WINDOWS\eiq1E4.tmp (Backdoor.ProRat) -> No action taken.
E:\WINDOWS\eiu315.tmp (Backdoor.ProRat) -> No action taken.
E:\WINDOWS\ejgA3.tmp (Backdoor.ProRat) -> No action taken.
E:\WINDOWS\ejj4F4.tmp (Backdoor.ProRat) -> No action taken.
E:\WINDOWS\ejs23A.tmp (Backdoor.ProRat) -> No action taken.
E:\WINDOWS\elt2B5.tmp (Backdoor.ProRat) -> No action taken.
E:\WINDOWS\emh4A6.tmp (Backdoor.ProRat) -> No action taken.
E:\WINDOWS\emj511.tmp (Backdoor.ProRat) -> No action taken.
E:\WINDOWS\eml144.tmp (Backdoor.ProRat) -> No action taken.
E:\WINDOWS\emr227.tmp (Backdoor.ProRat) -> No action taken.
E:\WINDOWS\emv342.tmp (Backdoor.ProRat) -> No action taken.
E:\WINDOWS\end3D.tmp (Backdoor.ProRat) -> No action taken.
E:\WINDOWS\eniFC.tmp (Backdoor.ProRat) -> No action taken.
E:\WINDOWS\enu2F9.tmp (Backdoor.ProRat) -> No action taken.
E:\WINDOWS\env328.tmp (Backdoor.ProRat) -> No action taken.
E:\WINDOWS\eod53.tmp (Backdoor.ProRat) -> No action taken.
E:\WINDOWS\eot2CE.tmp (Backdoor.ProRat) -> No action taken.
E:\WINDOWS\epj11D.tmp (Backdoor.ProRat) -> No action taken.
E:\WINDOWS\eqq20A.tmp (Backdoor.ProRat) -> No action taken.
E:\WINDOWS\esn183.tmp (Backdoor.ProRat) -> No action taken.
E:\WINDOWS\eue41D.tmp (Backdoor.ProRat) -> No action taken.
E:\WINDOWS\euw359.tmp (Backdoor.ProRat) -> No action taken.
E:\WINDOWS\evg484.tmp (Backdoor.ProRat) -> No action taken.
E:\WINDOWS\evj114.tmp (Backdoor.ProRat) -> No action taken.
E:\WINDOWS\evo1AE.tmp (Backdoor.ProRat) -> No action taken.
E:\WINDOWS\ewg490.tmp (Backdoor.ProRat) -> No action taken.
E:\WINDOWS\ewh4BF.tmp (Backdoor.ProRat) -> No action taken.
E:\WINDOWS\ews244.tmp (Backdoor.ProRat) -> No action taken.
E:\WINDOWS\ewt2D1.tmp (Backdoor.ProRat) -> No action taken.
E:\WINDOWS\exd47.tmp (Backdoor.ProRat) -> No action taken.
E:\WINDOWS\exe422.tmp (Backdoor.ProRat) -> No action taken.
E:\WINDOWS\hdm174.tmp (Backdoor.ProRat) -> No action taken.
E:\WINDOWS\hdo1BC.tmp (Backdoor.ProRat) -> No action taken.
E:\WINDOWS\hei4D3.tmp (Backdoor.ProRat) -> No action taken.
E:\WINDOWS\hep1C6.tmp (Backdoor.ProRat) -> No action taken.
E:\WINDOWS\hfj500.tmp (Backdoor.ProRat) -> No action taken.
E:\WINDOWS\hgf469.tmp (Backdoor.ProRat) -> No action taken.
E:\WINDOWS\hghD7.tmp (Backdoor.ProRat) -> No action taken.
E:\WINDOWS\hhg48E.tmp (Backdoor.ProRat) -> No action taken.
E:\WINDOWS\hhl140.tmp (Backdoor.ProRat) -> No action taken.
E:\WINDOWS\hhl557.tmp (Backdoor.ProRat) -> No action taken.
E:\WINDOWS\hio1C0.tmp (Backdoor.ProRat) -> No action taken.
E:\WINDOWS\hiw34E.tmp (Backdoor.ProRat) -> No action taken.
E:\WINDOWS\hjl154.tmp (Backdoor.ProRat) -> No action taken.
E:\WINDOWS\hjp1D7.tmp (Backdoor.ProRat) -> No action taken.
E:\WINDOWS\hjy38C.tmp (Backdoor.ProRat) -> No action taken.
E:\WINDOWS\hke70.tmp (Backdoor.ProRat) -> No action taken.
E:\WINDOWS\hkn18F.tmp (Backdoor.ProRat) -> No action taken.
E:\WINDOWS\hlk53A.tmp (Backdoor.ProRat) -> No action taken.
E:\WINDOWS\hmf93.tmp (Backdoor.ProRat) -> No action taken.
E:\WINDOWS\hmhCE.tmp (Backdoor.ProRat) -> No action taken.
E:\WINDOWS\hms27C.tmp (Backdoor.ProRat) -> No action taken.
E:\WINDOWS\hnk137.tmp (Backdoor.ProRat) -> No action taken.
E:\WINDOWS\hnl54E.tmp (Backdoor.ProRat) -> No action taken.
E:\WINDOWS\hnm172.tmp (Backdoor.ProRat) -> No action taken.
E:\WINDOWS\hod32.tmp (Backdoor.ProRat) -> No action taken.
E:\WINDOWS\hop1DB.tmp (Backdoor.ProRat) -> No action taken.
E:\WINDOWS\hos23B.tmp (Backdoor.ProRat) -> No action taken.
E:\WINDOWS\hot2A4.tmp (Backdoor.ProRat) -> No action taken.
E:\WINDOWS\how351.tmp (Backdoor.ProRat) -> No action taken.
E:\WINDOWS\bjl554.tmp (Backdoor.ProRat) -> No action taken.
E:\WINDOWS\bjo1B3.tmp (Backdoor.ProRat) -> No action taken.
E:\WINDOWS\bkg496.tmp (Backdoor.ProRat) -> No action taken.
E:\WINDOWS\bku305.tmp (Backdoor.ProRat) -> No action taken.
E:\WINDOWS\bmg473.tmp (Backdoor.ProRat) -> No action taken.
E:\WINDOWS\bmv31E.tmp (Backdoor.ProRat) -> No action taken.
E:\WINDOWS\bnd49.tmp (Backdoor.ProRat) -> No action taken.
E:\WINDOWS\bnt2AF.tmp (Backdoor.ProRat) -> No action taken.
E:\WINDOWS\bohCB.tmp (Backdoor.ProRat) -> No action taken.
E:\WINDOWS\boi4EB.tmp (Backdoor.ProRat) -> No action taken.
E:\WINDOWS\bpe6A.tmp (Backdoor.ProRat) -> No action taken.
E:\WINDOWS\bphBE.tmp (Backdoor.ProRat) -> No action taken.
E:\WINDOWS\bpl158.tmp (Backdoor.ProRat) -> No action taken.
E:\WINDOWS\bqf450.tmp (Backdoor.ProRat) -> No action taken.
E:\WINDOWS\bqi4CE.tmp (Backdoor.ProRat) -> No action taken.
E:\WINDOWS\bqk53E.tmp (Backdoor.ProRat) -> No action taken.
E:\WINDOWS\bqv333.tmp (Backdoor.ProRat) -> No action taken.
E:\WINDOWS\brb9.tmp (Backdoor.ProRat) -> No action taken.
E:\WINDOWS\brj4F8.tmp (Backdoor.ProRat) -> No action taken.
E:\WINDOWS\bsgAE.tmp (Backdoor.ProRat) -> No action taken.
E:\WINDOWS\bshD2.tmp (Backdoor.ProRat) -> No action taken.
E:\WINDOWS\bsl15F.tmp (Backdoor.ProRat) -> No action taken.
E:\WINDOWS\bss24C.tmp (Backdoor.ProRat) -> No action taken.
E:\WINDOWS\btk522.tmp (Backdoor.ProRat) -> No action taken.
E:\WINDOWS\btr21E.tmp (Backdoor.ProRat) -> No action taken.
E:\WINDOWS\bts24E.tmp (Backdoor.ProRat) -> No action taken.
E:\WINDOWS\buiE6.tmp (Backdoor.ProRat) -> No action taken.
E:\WINDOWS\bvg9E.tmp (Backdoor.ProRat) -> No action taken.
E:\WINDOWS\bvj502.tmp (Backdoor.ProRat) -> No action taken.
E:\WINDOWS\bvp1D2.tmp (Backdoor.ProRat) -> No action taken.
E:\WINDOWS\qgt28B.tmp (Backdoor.ProRat) -> No action taken.
E:\WINDOWS\qju2FC.tmp (Backdoor.ProRat) -> No action taken.
E:\WINDOWS\qkj4F7.tmp (Backdoor.ProRat) -> No action taken.
E:\WINDOWS\qlk521.tmp (Backdoor.ProRat) -> No action taken.
E:\WINDOWS\qlr21D.tmp (Backdoor.ProRat) -> No action taken.
E:\WINDOWS\qme418.tmp (Backdoor.ProRat) -> No action taken.
E:\WINDOWS\qmp1C7.tmp (Backdoor.ProRat) -> No action taken.
E:\WINDOWS\qof453.tmp (Backdoor.ProRat) -> No action taken.
E:\WINDOWS\qol56B.tmp (Backdoor.ProRat) -> No action taken.
E:\WINDOWS\qom165.tmp (Backdoor.ProRat) -> No action taken.
E:\WINDOWS\qor20D.tmp (Backdoor.ProRat) -> No action taken.
E:\WINDOWS\qpe419.tmp (Backdoor.ProRat) -> No action taken.
E:\WINDOWS\qpe5D.tmp (Backdoor.ProRat) -> No action taken.
E:\WINDOWS\qqg49E.tmp (Backdoor.ProRat) -> No action taken.
E:\WINDOWS\qqj103.tmp (Backdoor.ProRat) -> No action taken.
E:\WINDOWS\qqk127.tmp (Backdoor.ProRat) -> No action taken.
E:\WINDOWS\qrd3F4.tmp (Backdoor.ProRat) -> No action taken.
E:\WINDOWS\qrm179.tmp (Backdoor.ProRat) -> No action taken.
E:\WINDOWS\qrs27D.tmp (Backdoor.ProRat) -> No action taken.
E:\WINDOWS\qrz3A5.tmp (Backdoor.ProRat) -> No action taken.
E:\WINDOWS\qsq1EE.tmp (Backdoor.ProRat) -> No action taken.
E:\WINDOWS\qst2C8.tmp (Backdoor.ProRat) -> No action taken.
E:\WINDOWS\dcgAC.tmp (Backdoor.ProRat) -> No action taken.
E:\WINDOWS\ddh4B4.tmp (Backdoor.ProRat) -> No action taken.
E:\WINDOWS\dfiE4.tmp (Backdoor.ProRat) -> No action taken.
E:\WINDOWS\dfu2DE.tmp (Backdoor.ProRat) -> No action taken.
E:\WINDOWS\dfv32F.tmp (Backdoor.ProRat) -> No action taken.
E:\WINDOWS\dhu2E8.tmp (Backdoor.ProRat) -> No action taken.
E:\WINDOWS\dhx377.tmp (Backdoor.ProRat) -> No action taken.
E:\WINDOWS\diu2E0.tmp (Backdoor.ProRat) -> No action taken.
E:\WINDOWS\diw34F.tmp (Backdoor.ProRat) -> No action taken.
E:\WINDOWS\djg48A.tmp (Backdoor.ProRat) -> No action taken.
E:\WINDOWS\djj102.tmp (Backdoor.ProRat) -> No action taken.
E:\WINDOWS\dki4E2.tmp (Backdoor.ProRat) -> No action taken.
E:\WINDOWS\dkk547.tmp (Backdoor.ProRat) -> No action taken.
E:\WINDOWS\dkr213.tmp (Backdoor.ProRat) -> No action taken.
E:\WINDOWS\dkx372.tmp (Backdoor.ProRat) -> No action taken.
E:\WINDOWS\dld3FD.tmp (Backdoor.ProRat) -> No action taken.
E:\WINDOWS\dlhC4.tmp (Backdoor.ProRat) -> No action taken.
E:\WINDOWS\dlhDB.tmp (Backdoor.ProRat) -> No action taken.
E:\WINDOWS\dno1BA.tmp (Backdoor.ProRat) -> No action taken.
E:\WINDOWS\dos26C.tmp (Backdoor.ProRat) -> No action taken.
E:\WINDOWS\dph4AF.tmp (Backdoor.ProRat) -> No action taken.
E:\WINDOWS\vfr219.tmp (Backdoor.ProRat) -> No action taken.
E:\WINDOWS\vfu2EF.tmp (Backdoor.ProRat) -> No action taken.
E:\WINDOWS\vfv327.tmp (Backdoor.ProRat) -> No action taken.
E:\WINDOWS\vgd31.tmp (Backdoor.ProRat) -> No action taken.
E:\WINDOWS\vhf82.tmp (Backdoor.ProRat) -> No action taken.
E:\WINDOWS\vhn192.tmp (Backdoor.ProRat) -> No action taken.
E:\WINDOWS\vhx37C.tmp (Backdoor.ProRat) -> No action taken.
E:\WINDOWS\vjd38.tmp (Backdoor.ProRat) -> No action taken.
E:\WINDOWS\vju2E2.tmp (Backdoor.ProRat) -> No action taken.
E:\WINDOWS\vkd3E2.tmp (Backdoor.ProRat) -> No action taken.
E:\WINDOWS\vku304.tmp (Backdoor.ProRat) -> No action taken.
E:\WINDOWS\vll551.tmp (Backdoor.ProRat) -> No action taken.
E:\WINDOWS\vmt294.tmp (Backdoor.ProRat) -> No action taken.
E:\WINDOWS\von189.tmp (Backdoor.ProRat) -> No action taken.
E:\WINDOWS\vox36B.tmp (Backdoor.ProRat) -> No action taken.
E:\WINDOWS\vpr217.tmp (Backdoor.ProRat) -> No action taken.
E:\WINDOWS\vpv325.tmp (Backdoor.ProRat) -> No action taken.
E:\WINDOWS\vqf8D.tmp (Backdoor.ProRat) -> No action taken.
E:\WINDOWS\vqhC8.tmp (Backdoor.ProRat) -> No action taken.
E:\WINDOWS\vqt287.tmp (Backdoor.ProRat) -> No action taken.
E:\WINDOWS\vrt29E.tmp (Backdoor.ProRat) -> No action taken.
E:\WINDOWS\vsf44D.tmp (Backdoor.ProRat) -> No action taken.
E:\WINDOWS\vsl148.tmp (Backdoor.ProRat) -> No action taken.
E:\WINDOWS\vto1B1.tmp (Backdoor.ProRat) -> No action taken.
E:\WINDOWS\vuy395.tmp (Backdoor.ProRat) -> No action taken.
E:\WINDOWS\vvi4D2.tmp (Backdoor.ProRat) -> No action taken.
E:\WINDOWS\vvj51F.tmp (Backdoor.ProRat) -> No action taken.
 
E:\WINDOWS\vvn197.tmp (Backdoor.ProRat) -> No action taken.
E:\WINDOWS\vvr21B.tmp (Backdoor.ProRat) -> No action taken.
E:\WINDOWS\vwb3B1.tmp (Backdoor.ProRat) -> No action taken.
E:\WINDOWS\vxe431.tmp (Backdoor.ProRat) -> No action taken.
E:\WINDOWS\vxhD6.tmp (Backdoor.ProRat) -> No action taken.
E:\WINDOWS\vxi4DD.tmp (Backdoor.ProRat) -> No action taken.
E:\WINDOWS\vxt288.tmp (Backdoor.ProRat) -> No action taken.
E:\WINDOWS\vym163.tmp (Backdoor.ProRat) -> No action taken.
E:\WINDOWS\vze444.tmp (Backdoor.ProRat) -> No action taken.
E:\WINDOWS\phhBD.tmp (Backdoor.ProRat) -> No action taken.
E:\WINDOWS\php1DA.tmp (Backdoor.ProRat) -> No action taken.
E:\WINDOWS\pit2BC.tmp (Backdoor.ProRat) -> No action taken.
E:\WINDOWS\piu2E9.tmp (Backdoor.ProRat) -> No action taken.
E:\WINDOWS\pkf96.tmp (Backdoor.ProRat) -> No action taken.
E:\WINDOWS\pkgAD.tmp (Backdoor.ProRat) -> No action taken.
E:\WINDOWS\pkj517.tmp (Backdoor.ProRat) -> No action taken.
E:\WINDOWS\pnd3E.tmp (Backdoor.ProRat) -> No action taken.
E:\WINDOWS\png9D.tmp (Backdoor.ProRat) -> No action taken.
E:\WINDOWS\pnp1D1.tmp (Backdoor.ProRat) -> No action taken.
E:\WINDOWS\pnt28C.tmp (Backdoor.ProRat) -> No action taken.
E:\WINDOWS\pogB4.tmp (Backdoor.ProRat) -> No action taken.
E:\WINDOWS\pol14E.tmp (Backdoor.ProRat) -> No action taken.
E:\WINDOWS\poo1AD.tmp (Backdoor.ProRat) -> No action taken.
E:\WINDOWS\pop1C4.tmp (Backdoor.ProRat) -> No action taken.
E:\WINDOWS\ppk528.tmp (Backdoor.ProRat) -> No action taken.
E:\WINDOWS\pqq1E5.tmp (Backdoor.ProRat) -> No action taken.
E:\WINDOWS\nfr226.tmp (Backdoor.ProRat) -> No action taken.
E:\WINDOWS\nws26E.tmp (Backdoor.ProRat) -> No action taken.
E:\WINDOWS\ood3ED.tmp (Backdoor.ProRat) -> No action taken.
E:\WINDOWS\pfo1B9.tmp (Backdoor.ProRat) -> No action taken.
E:\WINDOWS\prgA4.tmp (Backdoor.ProRat) -> No action taken.
E:\WINDOWS\qghCA.tmp (Backdoor.ProRat) -> No action taken.
E:\WINDOWS\qthDC.tmp (Backdoor.ProRat) -> No action taken.
E:\WINDOWS\rnf86.tmp (Backdoor.ProRat) -> No action taken.
E:\WINDOWS\sos242.tmp (Backdoor.ProRat) -> No action taken.
E:\WINDOWS\trt29F.tmp (Backdoor.ProRat) -> No action taken.
E:\WINDOWS\vfk136.tmp (Backdoor.ProRat) -> No action taken.
E:\WINDOWS\vzk13F.tmp (Backdoor.ProRat) -> No action taken.
E:\WINDOWS\wnd3F.tmp (Backdoor.ProRat) -> No action taken.
E:\WINDOWS\xif99.tmp (Backdoor.ProRat) -> No action taken.
E:\WINDOWS\xpt2A5.tmp (Backdoor.ProRat) -> No action taken.
E:\WINDOWS\xyt2C9.tmp (Backdoor.ProRat) -> No action taken.
E:\WINDOWS\ykk123.tmp (Backdoor.ProRat) -> No action taken.
E:\WINDOWS\zcv320.tmp (Backdoor.ProRat) -> No action taken.
E:\WINDOWS\xpt2C5.tmp (Backdoor.ProRat) -> No action taken.
E:\WINDOWS\xre67.tmp (Backdoor.ProRat) -> No action taken.
E:\WINDOWS\xriDF.tmp (Backdoor.ProRat) -> No action taken.
E:\WINDOWS\xrs27F.tmp (Backdoor.ProRat) -> No action taken.
E:\WINDOWS\xsb3B0.tmp (Backdoor.ProRat) -> No action taken.
E:\WINDOWS\xsf464.tmp (Backdoor.ProRat) -> No action taken.
E:\WINDOWS\xsj10D.tmp (Backdoor.ProRat) -> No action taken.
E:\WINDOWS\xth4B6.tmp (Backdoor.ProRat) -> No action taken.
E:\WINDOWS\xud3DE.tmp (Backdoor.ProRat) -> No action taken.
E:\WINDOWS\xui4F2.tmp (Backdoor.ProRat) -> No action taken.
E:\WINDOWS\xum180.tmp (Backdoor.ProRat) -> No action taken.
E:\WINDOWS\xup1C8.tmp (Backdoor.ProRat) -> No action taken.
E:\WINDOWS\xve439.tmp (Backdoor.ProRat) -> No action taken.
E:\WINDOWS\xvk121.tmp (Backdoor.ProRat) -> No action taken.
E:\WINDOWS\xxe40C.tmp (Backdoor.ProRat) -> No action taken.
E:\WINDOWS\xxj111.tmp (Backdoor.ProRat) -> No action taken.
E:\WINDOWS\xxj4FF.tmp (Backdoor.ProRat) -> No action taken.
E:\WINDOWS\xyn19E.tmp (Backdoor.ProRat) -> No action taken.
E:\WINDOWS\xys23E.tmp (Backdoor.ProRat) -> No action taken.
E:\WINDOWS\rng483.tmp (Backdoor.ProRat) -> No action taken.
E:\WINDOWS\rnj501.tmp (Backdoor.ProRat) -> No action taken.
E:\WINDOWS\rof46A.tmp (Backdoor.ProRat) -> No action taken.
E:\WINDOWS\roh4BE.tmp (Backdoor.ProRat) -> No action taken.
E:\WINDOWS\roj113.tmp (Backdoor.ProRat) -> No action taken.
E:\WINDOWS\rpc25.tmp (Backdoor.ProRat) -> No action taken.
E:\WINDOWS\rpd46.tmp (Backdoor.ProRat) -> No action taken.
E:\WINDOWS\rqu316.tmp (Backdoor.ProRat) -> No action taken.
E:\WINDOWS\rrj508.tmp (Backdoor.ProRat) -> No action taken.
E:\WINDOWS\rrl155.tmp (Backdoor.ProRat) -> No action taken.
E:\WINDOWS\rse71.tmp (Backdoor.ProRat) -> No action taken.
E:\WINDOWS\rsq1E6.tmp (Backdoor.ProRat) -> No action taken.
E:\WINDOWS\rtf7D.tmp (Backdoor.ProRat) -> No action taken.
E:\WINDOWS\rtj117.tmp (Backdoor.ProRat) -> No action taken.
E:\WINDOWS\ruj10A.tmp (Backdoor.ProRat) -> No action taken.
E:\WINDOWS\ruo1BB.tmp (Backdoor.ProRat) -> No action taken.
E:\WINDOWS\ruq1E8.tmp (Backdoor.ProRat) -> No action taken.
E:\WINDOWS\rut2DB.tmp (Backdoor.ProRat) -> No action taken.
E:\WINDOWS\rux383.tmp (Backdoor.ProRat) -> No action taken.
E:\WINDOWS\ruy397.tmp (Backdoor.ProRat) -> No action taken.
E:\WINDOWS\rvs25A.tmp (Backdoor.ProRat) -> No action taken.
E:\WINDOWS\rvs267.tmp (Backdoor.ProRat) -> No action taken.
E:\WINDOWS\rwd33.tmp (Backdoor.ProRat) -> No action taken.
E:\WINDOWS\rws23D.tmp (Backdoor.ProRat) -> No action taken.
E:\WINDOWS\rxbD.tmp (Backdoor.ProRat) -> No action taken.
E:\WINDOWS\rxe433.tmp (Backdoor.ProRat) -> No action taken.
E:\WINDOWS\rxf9B.tmp (Backdoor.ProRat) -> No action taken.
E:\WINDOWS\rxiE3.tmp (Backdoor.ProRat) -> No action taken.
E:\WINDOWS\rxz39B.tmp (Backdoor.ProRat) -> No action taken.
E:\WINDOWS\ryl14C.tmp (Backdoor.ProRat) -> No action taken.
E:\WINDOWS\rzu2E6.tmp (Backdoor.ProRat) -> No action taken.
E:\WINDOWS\rzw364.tmp (Backdoor.ProRat) -> No action taken.
E:\WINDOWS\jzu302.tmp (Backdoor.ProRat) -> No action taken.
E:\WINDOWS\kbe441.tmp (Backdoor.ProRat) -> No action taken.
E:\WINDOWS\kbk13C.tmp (Backdoor.ProRat) -> No action taken.
E:\WINDOWS\kbs26F.tmp (Backdoor.ProRat) -> No action taken.
E:\WINDOWS\kce58.tmp (Backdoor.ProRat) -> No action taken.
E:\WINDOWS\kdk122.tmp (Backdoor.ProRat) -> No action taken.
E:\WINDOWS\kdp1D3.tmp (Backdoor.ProRat) -> No action taken.
E:\WINDOWS\ker20F.tmp (Backdoor.ProRat) -> No action taken.
E:\WINDOWS\kgt2D5.tmp (Backdoor.ProRat) -> No action taken.
E:\WINDOWS\khj50A.tmp (Backdoor.ProRat) -> No action taken.
E:\WINDOWS\khr223.tmp (Backdoor.ProRat) -> No action taken.
E:\WINDOWS\kie42B.tmp (Backdoor.ProRat) -> No action taken.
E:\WINDOWS\kjy386.tmp (Backdoor.ProRat) -> No action taken.
E:\WINDOWS\kkh4AB.tmp (Backdoor.ProRat) -> No action taken.
E:\WINDOWS\kkr22A.tmp (Backdoor.ProRat) -> No action taken.
E:\WINDOWS\kks232.tmp (Backdoor.ProRat) -> No action taken.
E:\WINDOWS\klf463.tmp (Backdoor.ProRat) -> No action taken.
E:\WINDOWS\klq206.tmp (Backdoor.ProRat) -> No action taken.
E:\WINDOWS\kmk12D.tmp (Backdoor.ProRat) -> No action taken.
E:\WINDOWS\kml55B.tmp (Backdoor.ProRat) -> No action taken.
E:\WINDOWS\knr21A.tmp (Backdoor.ProRat) -> No action taken.
E:\WINDOWS\kns233.tmp (Backdoor.ProRat) -> No action taken.
E:\WINDOWS\kpc1B.tmp (Backdoor.ProRat) -> No action taken.
E:\WINDOWS\kpf45D.tmp (Backdoor.ProRat) -> No action taken.
E:\WINDOWS\zfl15A.tmp (Backdoor.ProRat) -> No action taken.
E:\WINDOWS\zfn195.tmp (Backdoor.ProRat) -> No action taken.
E:\WINDOWS\zge403.tmp (Backdoor.ProRat) -> No action taken.
E:\WINDOWS\zgv337.tmp (Backdoor.ProRat) -> No action taken.
E:\WINDOWS\zhj4FA.tmp (Backdoor.ProRat) -> No action taken.
E:\WINDOWS\zkiF5.tmp (Backdoor.ProRat) -> No action taken.
E:\WINDOWS\zmd3E4.tmp (Backdoor.ProRat) -> No action taken.
E:\WINDOWS\zmg492.tmp (Backdoor.ProRat) -> No action taken.
E:\WINDOWS\zmh4C4.tmp (Backdoor.ProRat) -> No action taken.
E:\WINDOWS\zmo1A3.tmp (Backdoor.ProRat) -> No action taken.
E:\WINDOWS\znd3E5.tmp (Backdoor.ProRat) -> No action taken.
E:\WINDOWS\znk52C.tmp (Backdoor.ProRat) -> No action taken.
E:\WINDOWS\zpu2EB.tmp (Backdoor.ProRat) -> No action taken.
E:\WINDOWS\zqs234.tmp (Backdoor.ProRat) -> No action taken.
E:\WINDOWS\zqt2C7.tmp (Backdoor.ProRat) -> No action taken.
E:\WINDOWS\zrf45A.tmp (Backdoor.ProRat) -> No action taken.
E:\WINDOWS\zrf80.tmp (Backdoor.ProRat) -> No action taken.
E:\WINDOWS\zrp1CB.tmp (Backdoor.ProRat) -> No action taken.
E:\WINDOWS\zrs266.tmp (Backdoor.ProRat) -> No action taken.
E:\WINDOWS\zsf97.tmp (Backdoor.ProRat) -> No action taken.
E:\WINDOWS\zud57.tmp (Backdoor.ProRat) -> No action taken.
E:\WINDOWS\zuk12E.tmp (Backdoor.ProRat) -> No action taken.
E:\WINDOWS\zuv33C.tmp (Backdoor.ProRat) -> No action taken.
E:\WINDOWS\zxs253.tmp (Backdoor.ProRat) -> No action taken.
E:\WINDOWS\zyj104.tmp (Backdoor.ProRat) -> No action taken.
E:\WINDOWS\mciF4.tmp (Backdoor.ProRat) -> No action taken.
E:\WINDOWS\mcp1E0.tmp (Backdoor.ProRat) -> No action taken.
E:\WINDOWS\mdg9F.tmp (Backdoor.ProRat) -> No action taken.
E:\WINDOWS\mdiE7.tmp (Backdoor.ProRat) -> No action taken.
E:\WINDOWS\mdj503.tmp (Backdoor.ProRat) -> No action taken.
E:\WINDOWS\mdw366.tmp (Backdoor.ProRat) -> No action taken.
E:\WINDOWS\med3DA.tmp (Backdoor.ProRat) -> No action taken.
E:\WINDOWS\med3EF.tmp (Backdoor.ProRat) -> No action taken.
E:\WINDOWS\meg46F.tmp (Backdoor.ProRat) -> No action taken.
E:\WINDOWS\megB6.tmp (Backdoor.ProRat) -> No action taken.
E:\WINDOWS\meu30F.tmp (Backdoor.ProRat) -> No action taken.
E:\WINDOWS\mfc27.tmp (Backdoor.ProRat) -> No action taken.
E:\WINDOWS\mfi4DE.tmp (Backdoor.ProRat) -> No action taken.
E:\WINDOWS\mgu31A.tmp (Backdoor.ProRat) -> No action taken.
E:\WINDOWS\mhc18.tmp (Backdoor.ProRat) -> No action taken.
E:\WINDOWS\mhd42.tmp (Backdoor.ProRat) -> No action taken.
E:\WINDOWS\mhm17B.tmp (Backdoor.ProRat) -> No action taken.
E:\WINDOWS\mht2A3.tmp (Backdoor.ProRat) -> No action taken.
E:\WINDOWS\mjf459.tmp (Backdoor.ProRat) -> No action taken.
E:\WINDOWS\spg48F.tmp (Backdoor.ProRat) -> No action taken.
E:\WINDOWS\sqe74.tmp (Backdoor.ProRat) -> No action taken.
E:\WINDOWS\sqi4E6.tmp (Backdoor.ProRat) -> No action taken.
E:\WINDOWS\srv322.tmp (Backdoor.ProRat) -> No action taken.
E:\WINDOWS\ssc14.tmp (Backdoor.ProRat) -> No action taken.
E:\WINDOWS\ssc2C.tmp (Backdoor.ProRat) -> No action taken.
E:\WINDOWS\sss281.tmp (Backdoor.ProRat) -> No action taken.
E:\WINDOWS\stt297.tmp (Backdoor.ProRat) -> No action taken.
E:\WINDOWS\sugAB.tmp (Backdoor.ProRat) -> No action taken.
E:\WINDOWS\sut2B0.tmp (Backdoor.ProRat) -> No action taken.
E:\WINDOWS\swb3B3.tmp (Backdoor.ProRat) -> No action taken.
E:\WINDOWS\swk542.tmp (Backdoor.ProRat) -> No action taken.
E:\WINDOWS\sxd3F8.tmp (Backdoor.ProRat) -> No action taken.
E:\WINDOWS\sye40D.tmp (Backdoor.ProRat) -> No action taken.
E:\WINDOWS\trz3A3.tmp (Backdoor.ProRat) -> No action taken.
E:\WINDOWS\tsl56C.tmp (Backdoor.ProRat) -> No action taken.
E:\WINDOWS\tsr22B.tmp (Backdoor.ProRat) -> No action taken.
E:\WINDOWS\tsv32C.tmp (Backdoor.ProRat) -> No action taken.
E:\WINDOWS\tts250.tmp (Backdoor.ProRat) -> No action taken.
E:\WINDOWS\tuhCF.tmp (Backdoor.ProRat) -> No action taken.
E:\WINDOWS\tviFD.tmp (Backdoor.ProRat) -> No action taken.
E:\WINDOWS\tvk138.tmp (Backdoor.ProRat) -> No action taken.
E:\WINDOWS\tvu2F3.tmp (Backdoor.ProRat) -> No action taken.
E:\WINDOWS\twe41F.tmp (Backdoor.ProRat) -> No action taken.
E:\WINDOWS\twiF0.tmp (Backdoor.ProRat) -> No action taken.
E:\WINDOWS\twp1DC.tmp (Backdoor.ProRat) -> No action taken.
E:\WINDOWS\tws275.tmp (Backdoor.ProRat) -> No action taken.
E:\WINDOWS\adf462.tmp (Backdoor.ProRat) -> No action taken.
E:\WINDOWS\adk539.tmp (Backdoor.ProRat) -> No action taken.
E:\WINDOWS\adq205.tmp (Backdoor.ProRat) -> No action taken.
E:\WINDOWS\aed55.tmp (Backdoor.ProRat) -> No action taken.
E:\WINDOWS\aehCD.tmp (Backdoor.ProRat) -> No action taken.
E:\WINDOWS\aeiF1.tmp (Backdoor.ProRat) -> No action taken.
E:\WINDOWS\aek12C.tmp (Backdoor.ProRat) -> No action taken.
E:\WINDOWS\aes23F.tmp (Backdoor.ProRat) -> No action taken.
E:\WINDOWS\aft2AD.tmp (Backdoor.ProRat) -> No action taken.
E:\WINDOWS\agf452.tmp (Backdoor.ProRat) -> No action taken.
E:\WINDOWS\ahc1A.tmp (Backdoor.ProRat) -> No action taken.
E:\WINDOWS\ain185.tmp (Backdoor.ProRat) -> No action taken.
E:\WINDOWS\ait2BA.tmp (Backdoor.ProRat) -> No action taken.
E:\WINDOWS\ajr220.tmp (Backdoor.ProRat) -> No action taken.
E:\WINDOWS\ajt2C2.tmp (Backdoor.ProRat) -> No action taken.
E:\WINDOWS\akb3C6.tmp (Backdoor.ProRat) -> No action taken.
E:\WINDOWS\akk130.tmp (Backdoor.ProRat) -> No action taken.
E:\WINDOWS\aku310.tmp (Backdoor.ProRat) -> No action taken.
E:\WINDOWS\amq1F9.tmp (Backdoor.ProRat) -> No action taken.
E:\WINDOWS\anw350.tmp (Backdoor.ProRat) -> No action taken.
E:\WINDOWS\aoj106.tmp (Backdoor.ProRat) -> No action taken.
E:\WINDOWS\aol568.tmp (Backdoor.ProRat) -> No action taken.
E:\WINDOWS\apgA7.tmp (Backdoor.ProRat) -> No action taken.
E:\WINDOWS\apm17C.tmp (Backdoor.ProRat) -> No action taken.
E:\WINDOWS\ngq1F5.tmp (Backdoor.ProRat) -> No action taken.
E:\WINDOWS\nhl157.tmp (Backdoor.ProRat) -> No action taken.
E:\WINDOWS\nhq1FF.tmp (Backdoor.ProRat) -> No action taken.
E:\WINDOWS\nhv324.tmp (Backdoor.ProRat) -> No action taken.
E:\WINDOWS\nim16E.tmp (Backdoor.ProRat) -> No action taken.
E:\WINDOWS\nit285.tmp (Backdoor.ProRat) -> No action taken.
E:\WINDOWS\njf7F.tmp (Backdoor.ProRat) -> No action taken.
E:\WINDOWS\njs231.tmp (Backdoor.ProRat) -> No action taken.
E:\WINDOWS\njs264.tmp (Backdoor.ProRat) -> No action taken.
E:\WINDOWS\njy384.tmp (Backdoor.ProRat) -> No action taken.
E:\WINDOWS\nkj10C.tmp (Backdoor.ProRat) -> No action taken.
E:\WINDOWS\nko1A6.tmp (Backdoor.ProRat) -> No action taken.
E:\WINDOWS\nls26B.tmp (Backdoor.ProRat) -> No action taken.
E:\WINDOWS\nlx374.tmp (Backdoor.ProRat) -> No action taken.
E:\WINDOWS\nmd56.tmp (Backdoor.ProRat) -> No action taken.
E:\WINDOWS\nmi4F1.tmp (Backdoor.ProRat) -> No action taken.
E:\WINDOWS\nmu309.tmp (Backdoor.ProRat) -> No action taken.
E:\WINDOWS\nniE5.tmp (Backdoor.ProRat) -> No action taken.
E:\WINDOWS\noe407.tmp (Backdoor.ProRat) -> No action taken.
E:\WINDOWS\chd45.tmp (Backdoor.ProRat) -> No action taken.
E:\WINDOWS\che43B.tmp (Backdoor.ProRat) -> No action taken.
E:\WINDOWS\cie5C.tmp (Backdoor.ProRat) -> No action taken.
E:\WINDOWS\cil564.tmp (Backdoor.ProRat) -> No action taken.
E:\WINDOWS\cjm178.tmp (Backdoor.ProRat) -> No action taken.
E:\WINDOWS\cjt2C3.tmp (Backdoor.ProRat) -> No action taken.
E:\WINDOWS\cke428.tmp (Backdoor.ProRat) -> No action taken.
E:\WINDOWS\ckx373.tmp (Backdoor.ProRat) -> No action taken.
E:\WINDOWS\ckx379.tmp (Backdoor.ProRat) -> No action taken.
E:\WINDOWS\clj116.tmp (Backdoor.ProRat) -> No action taken.
E:\WINDOWS\clu2FE.tmp (Backdoor.ProRat) -> No action taken.
E:\WINDOWS\cme6D.tmp (Backdoor.ProRat) -> No action taken.
E:\WINDOWS\cmn18C.tmp (Backdoor.ProRat) -> No action taken.
E:\WINDOWS\cmt2D6.tmp (Backdoor.ProRat) -> No action taken.
E:\WINDOWS\cnv332.tmp (Backdoor.ProRat) -> No action taken.
E:\WINDOWS\cok12A.tmp (Backdoor.ProRat) -> No action taken.
E:\WINDOWS\gaf44E.tmp (Backdoor.ProRat) -> No action taken.
E:\WINDOWS\gai4CC.tmp (Backdoor.ProRat) -> No action taken.
E:\WINDOWS\gau2E7.tmp (Backdoor.ProRat) -> No action taken.
E:\WINDOWS\gbq208.tmp (Backdoor.ProRat) -> No action taken.
E:\WINDOWS\gbu2FB.tmp (Backdoor.ProRat) -> No action taken.
E:\WINDOWS\gcp1C9.tmp (Backdoor.ProRat) -> No action taken.
E:\WINDOWS\gcs247.tmp (Backdoor.ProRat) -> No action taken.
E:\WINDOWS\gdl550.tmp (Backdoor.ProRat) -> No action taken.
E:\WINDOWS\gee413.tmp (Backdoor.ProRat) -> No action taken.
E:\WINDOWS\gek543.tmp (Backdoor.ProRat) -> No action taken.
E:\WINDOWS\gfd3F9.tmp (Backdoor.ProRat) -> No action taken.
E:\WINDOWS\gfu2EE.tmp (Backdoor.ProRat) -> No action taken.
E:\WINDOWS\gfu308.tmp (Backdoor.ProRat) -> No action taken.
E:\WINDOWS\ggh4BD.tmp (Backdoor.ProRat) -> No action taken.
E:\WINDOWS\ggm164.tmp (Backdoor.ProRat) -> No action taken.
E:\WINDOWS\ghd43.tmp (Backdoor.ProRat) -> No action taken.
E:\WINDOWS\ghu303.tmp (Backdoor.ProRat) -> No action taken.
E:\WINDOWS\gig49D.tmp (Backdoor.ProRat) -> No action taken.
E:\WINDOWS\gik126.tmp (Backdoor.ProRat) -> No action taken.
E:\WINDOWS\gio1A9.tmp (Backdoor.ProRat) -> No action taken.
E:\WINDOWS\gjd3F3.tmp (Backdoor.ProRat) -> No action taken.
E:\WINDOWS\gjgBA.tmp (Backdoor.ProRat) -> No action taken.
E:\WINDOWS\gjj507.tmp (Backdoor.ProRat) -> No action taken.
E:\WINDOWS\gjq1FC.tmp (Backdoor.ProRat) -> No action taken.
E:\WINDOWS\lem167.tmp (Backdoor.ProRat) -> No action taken.
E:\WINDOWS\lff45F.tmp (Backdoor.ProRat) -> No action taken.
E:\WINDOWS\lge78.tmp (Backdoor.ProRat) -> No action taken.
E:\WINDOWS\lgn188.tmp (Backdoor.ProRat) -> No action taken.
E:\WINDOWS\lic2E.tmp (Backdoor.ProRat) -> No action taken.
E:\WINDOWS\lid4F.tmp (Backdoor.ProRat) -> No action taken.
E:\WINDOWS\lik54A.tmp (Backdoor.ProRat) -> No action taken.
E:\WINDOWS\liw354.tmp (Backdoor.ProRat) -> No action taken.
E:\WINDOWS\ljt29C.tmp (Backdoor.ProRat) -> No action taken.
E:\WINDOWS\ljy38A.tmp (Backdoor.ProRat) -> No action taken.
E:\WINDOWS\lkf44C.tmp (Backdoor.ProRat) -> No action taken.
E:\WINDOWS\lkl147.tmp (Backdoor.ProRat) -> No action taken.
E:\WINDOWS\lku2E3.tmp (Backdoor.ProRat) -> No action taken.
E:\WINDOWS\lls25E.tmp (Backdoor.ProRat) -> No action taken.
E:\WINDOWS\lmd3DD.tmp (Backdoor.ProRat) -> No action taken.
E:\WINDOWS\lnd3C.tmp (Backdoor.ProRat) -> No action taken.
E:\WINDOWS\nwt2D2.tmp (Backdoor.ProRat) -> No action taken.
E:\WINDOWS\nxl159.tmp (Backdoor.ProRat) -> No action taken.
E:\WINDOWS\nxs261.tmp (Backdoor.ProRat) -> No action taken.
E:\WINDOWS\nye402.tmp (Backdoor.ProRat) -> No action taken.
E:\WINDOWS\nzi4DA.tmp (Backdoor.ProRat) -> No action taken.
E:\WINDOWS\oad3E8.tmp (Backdoor.ProRat) -> No action taken.
E:\WINDOWS\oagAF.tmp (Backdoor.ProRat) -> No action taken.
E:\WINDOWS\oan184.tmp (Backdoor.ProRat) -> No action taken.
E:\WINDOWS\obe423.tmp (Backdoor.ProRat) -> No action taken.
E:\WINDOWS\obe440.tmp (Backdoor.ProRat) -> No action taken.
E:\WINDOWS\obh4B7.tmp (Backdoor.ProRat) -> No action taken.
E:\WINDOWS\ock12F.tmp (Backdoor.ProRat) -> No action taken.
E:\WINDOWS\odg485.tmp (Backdoor.ProRat) -> No action taken.
E:\WINDOWS\oeh4C3.tmp (Backdoor.ProRat) -> No action taken.
E:\WINDOWS\oei4E8.tmp (Backdoor.ProRat) -> No action taken.
E:\WINDOWS\oeo1A2.tmp (Backdoor.ProRat) -> No action taken.
E:\WINDOWS\ofd48.tmp (Backdoor.ProRat) -> No action taken.
E:\WINDOWS\jnn196.tmp (Backdoor.ProRat) -> No action taken.
E:\WINDOWS\jnu2F1.tmp (Backdoor.ProRat) -> No action taken.
E:\WINDOWS\jnu2F8.tmp (Backdoor.ProRat) -> No action taken.
E:\WINDOWS\joj51E.tmp (Backdoor.ProRat) -> No action taken.
E:\WINDOWS\jpg47A.tmp (Backdoor.ProRat) -> No action taken.
E:\WINDOWS\jpi4DC.tmp (Backdoor.ProRat) -> No action taken.
E:\WINDOWS\jqd3EA.tmp (Backdoor.ProRat) -> No action taken.
E:\WINDOWS\jqf467.tmp (Backdoor.ProRat) -> No action taken.
E:\WINDOWS\jqgB1.tmp (Backdoor.ProRat) -> No action taken.
E:\WINDOWS\jqhD5.tmp (Backdoor.ProRat) -> No action taken.
E:\WINDOWS\jrh4B9.tmp (Backdoor.ProRat) -> No action taken.
E:\WINDOWS\jrk525.tmp (Backdoor.ProRat) -> No action taken.
E:\WINDOWS\jtgB8.tmp (Backdoor.ProRat) -> No action taken.
E:\WINDOWS\jtj505.tmp (Backdoor.ProRat) -> No action taken.
E:\WINDOWS\jtl552.tmp (Backdoor.ProRat) -> No action taken.
E:\WINDOWS\jug493.tmp (Backdoor.ProRat) -> No action taken.
E:\WINDOWS\jvk52F.tmp (Backdoor.ProRat) -> No action taken.
E:\WINDOWS\jwhCC.tmp (Backdoor.ProRat) -> No action taken.
E:\WINDOWS\jws278.tmp (Backdoor.ProRat) -> No action taken.
E:\WINDOWS\jxk135.tmp (Backdoor.ProRat) -> No action taken.
E:\WINDOWS\jxq201.tmp (Backdoor.ProRat) -> No action taken.
E:\WINDOWS\jxr218.tmp (Backdoor.ProRat) -> No action taken.
E:\WINDOWS\jxu2ED.tmp (Backdoor.ProRat) -> No action taken.
E:\WINDOWS\jye68.tmp (Backdoor.ProRat) -> No action taken.
E:\WINDOWS\qtt299.tmp (Backdoor.ProRat) -> No action taken.
E:\WINDOWS\quu300.tmp (Backdoor.ProRat) -> No action taken.
E:\WINDOWS\qux381.tmp (Backdoor.ProRat) -> No action taken.
E:\WINDOWS\qwt2A6.tmp (Backdoor.ProRat) -> No action taken.
E:\WINDOWS\qxf84.tmp (Backdoor.ProRat) -> No action taken.
E:\WINDOWS\qxhBF.tmp (Backdoor.ProRat) -> No action taken.
E:\WINDOWS\qxi4CF.tmp (Backdoor.ProRat) -> No action taken.
E:\WINDOWS\qzx369.tmp (Backdoor.ProRat) -> No action taken.
E:\WINDOWS\rbd3F2.tmp (Backdoor.ProRat) -> No action taken.
E:\WINDOWS\rbl553.tmp (Backdoor.ProRat) -> No action taken.
E:\WINDOWS\rce424.tmp (Backdoor.ProRat) -> No action taken.
E:\WINDOWS\rck546.tmp (Backdoor.ProRat) -> No action taken.
E:\WINDOWS\rcq1EC.tmp (Backdoor.ProRat) -> No action taken.
E:\WINDOWS\rcu30D.tmp (Backdoor.ProRat) -> No action taken.
E:\WINDOWS\rdd3FC.tmp (Backdoor.ProRat) -> No action taken.
E:\WINDOWS\rdg494.tmp (Backdoor.ProRat) -> No action taken.
E:\WINDOWS\rdhC3.tmp (Backdoor.ProRat) -> No action taken.
E:\WINDOWS\ies249.tmp (Backdoor.ProRat) -> No action taken.
E:\WINDOWS\iev335.tmp (Backdoor.ProRat) -> No action taken.
E:\WINDOWS\ifv32E.tmp (Backdoor.ProRat) -> No action taken.
E:\WINDOWS\igj112.tmp (Backdoor.ProRat) -> No action taken.
E:\WINDOWS\ign19F.tmp (Backdoor.ProRat) -> No action taken.
E:\WINDOWS\igs240.tmp (Backdoor.ProRat) -> No action taken.
E:\WINDOWS\igt2CB.tmp (Backdoor.ProRat) -> No action taken.
E:\WINDOWS\ihb3BC.tmp (Backdoor.ProRat) -> No action taken.
E:\WINDOWS\iii4E5.tmp (Backdoor.ProRat) -> No action taken.
E:\WINDOWS\iik133.tmp (Backdoor.ProRat) -> No action taken.
E:\WINDOWS\iiq1F2.tmp (Backdoor.ProRat) -> No action taken.
E:\WINDOWS\xihD4.tmp (Backdoor.ProRat) -> No action taken.
E:\WINDOWS\xij10F.tmp (Backdoor.ProRat) -> No action taken.
E:\WINDOWS\xiu2E1.tmp (Backdoor.ProRat) -> No action taken.
E:\WINDOWS\xje442.tmp (Backdoor.ProRat) -> No action taken.
E:\WINDOWS\xjf466.tmp (Backdoor.ProRat) -> No action taken.
E:\WINDOWS\xjk524.tmp (Backdoor.ProRat) -> No action taken.
E:\WINDOWS\xkiE8.tmp (Backdoor.ProRat) -> No action taken.
E:\WINDOWS\xld3E3.tmp (Backdoor.ProRat) -> No action taken.
E:\WINDOWS\xld3F0.tmp (Backdoor.ProRat) -> No action taken.
E:\WINDOWS\xlf89.tmp (Backdoor.ProRat) -> No action taken.
E:\WINDOWS\xlgA0.tmp (Backdoor.ProRat) -> No action taken.
E:\WINDOWS\xlu2F6.tmp (Backdoor.ProRat) -> No action taken.
E:\WINDOWS\xlw355.tmp (Backdoor.ProRat) -> No action taken.
E:\WINDOWS\xmgB7.tmp (Backdoor.ProRat) -> No action taken.
E:\WINDOWS\xmu30B.tmp (Backdoor.ProRat) -> No action taken.
E:\WINDOWS\xnf460.tmp (Backdoor.ProRat) -> No action taken.
E:\WINDOWS\xnq1F6.tmp (Backdoor.ProRat) -> No action taken.
E:\WINDOWS\xox36A.tmp (Backdoor.ProRat) -> No action taken.
E:\WINDOWS\xpl558.tmp (Backdoor.ProRat) -> No action taken.
E:\WINDOWS\xpq200.tmp (Backdoor.ProRat) -> No action taken.
E:\WINDOWS\mpo1B7.tmp (Backdoor.ProRat) -> No action taken.
E:\WINDOWS\mrg48C.tmp (Backdoor.ProRat) -> No action taken.
E:\WINDOWS\mrl555.tmp (Backdoor.ProRat) -> No action taken.
E:\WINDOWS\mrn19D.tmp (Backdoor.ProRat) -> No action taken.
E:\WINDOWS\mrr221.tmp (Backdoor.ProRat) -> No action taken.
E:\WINDOWS\mrs27E.tmp (Backdoor.ProRat) -> No action taken.
E:\WINDOWS\mrv344.tmp (Backdoor.ProRat) -> No action taken.
E:\WINDOWS\msk548.tmp (Backdoor.ProRat) -> No action taken.
E:\WINDOWS\mth4A8.tmp (Backdoor.ProRat) -> No action taken.
E:\WINDOWS\mtl152.tmp (Backdoor.ProRat) -> No action taken.
E:\WINDOWS\mts24F.tmp (Backdoor.ProRat) -> No action taken.
E:\WINDOWS\mtt298.tmp (Backdoor.ProRat) -> No action taken.
E:\WINDOWS\mtt2DA.tmp (Backdoor.ProRat) -> No action taken.
E:\WINDOWS\muc29.tmp (Backdoor.ProRat) -> No action taken.
E:\WINDOWS\muh4C8.tmp (Backdoor.ProRat) -> No action taken.
E:\WINDOWS\yak132.tmp (Backdoor.ProRat) -> No action taken.
E:\WINDOWS\ybf458.tmp (Backdoor.ProRat) -> No action taken.
E:\WINDOWS\ybl153.tmp (Backdoor.ProRat) -> No action taken.
E:\WINDOWS\ybt29A.tmp (Backdoor.ProRat) -> No action taken.
E:\WINDOWS\ych4C9.tmp (Backdoor.ProRat) -> No action taken.
E:\WINDOWS\ydv32A.tmp (Backdoor.ProRat) -> No action taken.
E:\WINDOWS\ydy387.tmp (Backdoor.ProRat) -> No action taken.
E:\WINDOWS\yef92.tmp (Backdoor.ProRat) -> No action taken.
E:\WINDOWS\yet2AA.tmp (Backdoor.ProRat) -> No action taken.
E:\WINDOWS\yfe425.tmp (Backdoor.ProRat) -> No action taken.
E:\WINDOWS\yfl54D.tmp (Backdoor.ProRat) -> No action taken.
E:\WINDOWS\yfl55A.tmp (Backdoor.ProRat) -> No action taken.
E:\WINDOWS\yfs263.tmp (Backdoor.ProRat) -> No action taken.
E:\WINDOWS\yfu2DF.tmp (Backdoor.ProRat) -> No action taken.
E:\WINDOWS\ygo1AC.tmp (Backdoor.ProRat) -> No action taken.
E:\WINDOWS\yid3E9.tmp (Backdoor.ProRat) -> No action taken.
E:\WINDOWS\yigB0.tmp (Backdoor.ProRat) -> No action taken.
E:\WINDOWS\yij4FB.tmp (Backdoor.ProRat) -> No action taken.
E:\WINDOWS\yjh4B8.tmp (Backdoor.ProRat) -> No action taken.
E:\WINDOWS\yjt2BE.tmp (Backdoor.ProRat) -> No action taken.
E:\WINDOWS\wne60.tmp (Backdoor.ProRat) -> No action taken.
E:\WINDOWS\woe446.tmp (Backdoor.ProRat) -> No action taken.
E:\WINDOWS\wou306.tmp (Backdoor.ProRat) -> No action taken.
E:\WINDOWS\wou31B.tmp (Backdoor.ProRat) -> No action taken.
E:\WINDOWS\wpk134.tmp (Backdoor.ProRat) -> No action taken.
E:\WINDOWS\wpt2C4.tmp (Backdoor.ProRat) -> No action taken.
E:\WINDOWS\wrh4AC.tmp (Backdoor.ProRat) -> No action taken.
E:\WINDOWS\wrt2D9.tmp (Backdoor.ProRat) -> No action taken.
E:\WINDOWS\wsg477.tmp (Backdoor.ProRat) -> No action taken.
E:\WINDOWS\wsh4CB.tmp (Backdoor.ProRat) -> No action taken.
E:\WINDOWS\wtd36.tmp (Backdoor.ProRat) -> No action taken.
E:\WINDOWS\wtu2FA.tmp (Backdoor.ProRat) -> No action taken.
E:\WINDOWS\wuq1EA.tmp (Backdoor.ProRat) -> No action taken.
E:\WINDOWS\wuu301.tmp (Backdoor.ProRat) -> No action taken.
E:\WINDOWS\wvl54F.tmp (Backdoor.ProRat) -> No action taken.
E:\WINDOWS\wvm173.tmp (Backdoor.ProRat) -> No action taken.
E:\WINDOWS\wwe408.tmp (Backdoor.ProRat) -> No action taken.
E:\WINDOWS\oql565.tmp (Backdoor.ProRat) -> No action taken.
E:\WINDOWS\osc12.tmp (Backdoor.ProRat) -> No action taken.
E:\WINDOWS\ose429.tmp (Backdoor.ProRat) -> No action taken.
E:\WINDOWS\ost2B7.tmp (Backdoor.ProRat) -> No action taken.
E:\WINDOWS\oug474.tmp (Backdoor.ProRat) -> No action taken.
E:\WINDOWS\ouj512.tmp (Backdoor.ProRat) -> No action taken.
E:\WINDOWS\our228.tmp (Backdoor.ProRat) -> No action taken.
E:\WINDOWS\ovf461.tmp (Backdoor.ProRat) -> No action taken.
E:\WINDOWS\owd54.tmp (Backdoor.ProRat) -> No action taken.
E:\WINDOWS\owl559.tmp (Backdoor.ProRat) -> No action taken.
E:\WINDOWS\oxn194.tmp (Backdoor.ProRat) -> No action taken.
E:\WINDOWS\oyf451.tmp (Backdoor.ProRat) -> No action taken.
E:\WINDOWS\oyq20B.tmp (Backdoor.ProRat) -> No action taken.
E:\WINDOWS\oyz3A8.tmp (Backdoor.ProRat) -> No action taken.
E:\WINDOWS\pal563.tmp (Backdoor.ProRat) -> No action taken.
E:\WINDOWS\pat2B8.tmp (Backdoor.ProRat) -> No action taken.
E:\WINDOWS\pbj101.tmp (Backdoor.ProRat) -> No action taken.
E:\WINDOWS\pbm177.tmp (Backdoor.ProRat) -> No action taken.
E:\WINDOWS\ped3E1.tmp (Backdoor.ProRat) -> No action taken.
 

hijackthis log


Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 08:37, on 2009-01-29
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Boot mode: Normal

Running processes:
E:\WINDOWS\System32\smss.exe
E:\WINDOWS\system32\winlogon.exe
E:\WINDOWS\system32\services.exe
E:\WINDOWS\system32\lsass.exe
E:\WINDOWS\system32\svchost.exe
E:\WINDOWS\System32\svchost.exe
E:\WINDOWS\system32\spoolsv.exe
F:\Program Files\CyberLink\PowerDVD\PDVDServ.exe
F:\Program Files\VirtualCloneDrive\VCDDaemon.exe
E:\Program Files\Apache2.2\bin\httpd.exe
E:\Program Files\Bonjour\mDNSResponder.exe
F:\Program Files\WIDCOMM\Bluetooth Software\bin\btwdins.exe
E:\Program Files\MySQL\MySQL Server 5.0\bin\mysqld-nt.exe
E:\Program Files\Apache2.2\bin\httpd.exe
E:\Program Files\Nero\Nero8\Nero BackItUp\NBService.exe
E:\WINDOWS\system32\nvsvc32.exe
E:\WINDOWS\system32\PnkBstrA.exe
E:\WINDOWS\system32\PSIService.exe
E:\WINDOWS\system32\svchost.exe
E:\WINDOWS\explorer.exe
E:\Program Files\Mozilla Firefox\firefox.exe
F:\Program Files\Malwarebytes' Anti-Malware\mbam.exe
E:\WINDOWS\system32\NOTEPAD.EXE
F:\Program Files\HijackThis\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - E:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll (file missing)
O2 - BHO: Megaupload Toolbar - {4E7BD74F-2B8D-469E-CCB0-B130EEDBE97C} - E:\PROGRA~1\MEGAUP~1\MEGAUP~1.DLL
O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - f:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - F:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
O2 - BHO: Catcher Class - {ADECBED6-0366-4377-A739-E69DFBA04663} - f:\Program Files\FLV Downloader\MoyeaCth.dll
O2 - BHO: QUICKfind BHO Object - {C08DF07A-3E49-4E25-9AB0-D3882835F153} - f:\PROGRA~1\LONGMA~1\LAD001PE\setup\qf\IEHelp.dll
O3 - Toolbar: Megaupload Toolbar - {4E7BD74F-2B8D-469E-CCB0-B130EEDBE97C} - E:\PROGRA~1\MEGAUP~1\MEGAUP~1.DLL
O4 - HKLM\..\Run: [IMJPMIG8.1] "E:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE" /Spoil /RemAdvDef /Migration32
O4 - HKLM\..\Run: [PHIME2002ASync] E:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /SYNC
O4 - HKLM\..\Run: [PHIME2002A] E:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /IMEName
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE E:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [RemoteControl] "f:\Program Files\CyberLink\PowerDVD\PDVDServ.exe"
O4 - HKLM\..\Run: [VirtualCloneDrive] "f:\Program Files\VirtualCloneDrive\VCDDaemon.exe" /s
O4 - HKLM\..\Run: [CloneCDTray] "f:\Program Files\CloneCD\CloneCDTray.exe" /s
O4 - HKLM\..\Run: [ISUSPM Startup] "E:\Program Files\Common Files\InstallShield\UpdateService\ISUSPM.exe" -startup
O4 - HKLM\..\Run: [ISUSScheduler] "E:\Program Files\Common Files\InstallShield\UpdateService\issch.exe" -start
O4 - HKLM\..\Run: [FmctrlTray] Fmctrl.EXE
O4 - HKLM\..\Run: [NeroFilterCheck] E:\Program Files\Common Files\Nero\Lib\NeroCheck.exe
O4 - HKLM\..\Run: [NBKeyScan] "E:\Program Files\Nero\Nero8\Nero BackItUp\NBKeyScan.exe"
O4 - HKLM\..\Run: [SunJavaUpdateSched] "F:\Program Files\Java\jre1.6.0_05\bin\jusched.exe"
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE E:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [QuickTime Task] "F:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKCU\..\Run: [ctfmon.exe] E:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [IECheck] E:\WINDOWS\IECheck.exe
O4 - HKUS\S-1-5-18\..\Run: [ctfmon.exe] E:\WINDOWS\system32\ctfmon.exe (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [ctfmon.exe] E:\WINDOWS\system32\ctfmon.exe (User 'Default user')
O4 - Global Startup: Adobe Reader Speed Launch.lnk = E:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O8 - Extra context menu item: &Clean Traces - F:\Program Files\DAP\Privacy Package\dapcleanerie.htm
O8 - Extra context menu item: &Download with &DAP - F:\Program Files\DAP\dapextie.htm
O8 - Extra context menu item: Download &all with DAP - F:\Program Files\DAP\dapextie2.htm
O8 - Extra context menu item: E&xport to Microsoft Excel - res://E:\PROGRA~1\MICROS~2\Office12\EXCEL.EXE/3000
O8 - Extra context menu item: Send to &Bluetooth Device... - F:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie_ctx.htm
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - F:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - F:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - F:\PROGRA~1\MICROS~1\Office12\REFIEBAR.DLL
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - f:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - f:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra button: ICQ6 - {E59EB121-F339-4851-A3BA-FE49C35617C2} - f:\Program Files\ICQ6\ICQ.exe
O9 - Extra 'Tools' menuitem: ICQ6 - {E59EB121-F339-4851-A3BA-FE49C35617C2} - f:\Program Files\ICQ6\ICQ.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - E:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - E:\Program Files\Messenger\msmsgs.exe
O17 - HKLM\System\CCS\Services\Tcpip\..\{33DECB99-D7B7-4170-B79D-8D7848592871}: NameServer = 81.12.74.3 81.12.92.3
O17 - HKLM\System\CCS\Services\Tcpip\..\{BE40051E-E6D6-4EA2-B283-08CDF7E28DB4}: NameServer = 217.218.127.104,4.2.2.4
O23 - Service: Apache2.2 - Apache Software Foundation - E:\Program Files\Apache2.2\bin\httpd.exe
O23 - Service: ##Id_String1.6844F930_1628_4223_B5CC_5BB94B879762## (Bonjour Service) - Apple Computer, Inc. - E:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: Bluetooth Service (btwdins) - Broadcom Corporation. - F:\Program Files\WIDCOMM\Bluetooth Software\bin\btwdins.exe
O23 - Service: FLEXnet Licensing Service - Macrovision Europe Ltd. - E:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - E:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: MySql - Unknown owner - E:/mysql/bin/mysqld-nt.exe (file missing)
O23 - Service: MySQL5 - Unknown owner - E:\Program.exe (file missing)
O23 - Service: Nero BackItUp Scheduler 3 - Nero AG - E:\Program Files\Nero\Nero8\Nero BackItUp\NBService.exe
O23 - Service: NMIndexingService - Nero AG - E:\Program Files\Common Files\Nero\Lib\NMIndexingService.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - E:\WINDOWS\system32\nvsvc32.exe
O23 - Service: PnkBstrA - Unknown owner - E:\WINDOWS\system32\PnkBstrA.exe
O23 - Service: ProtexisLicensing - Unknown owner - E:\WINDOWS\system32\PSIService.exe

--
End of file - 7538 bytes
 
Last edited:
Did you click on remove selected when you did the Malwarebytes scan? The log shows no action was taken, And those items are not from the codecs. You need to remove them. If you didn't, rerun the scan and remove them and then do another hijackthis log and post back with both of them.
 
I deleted all this time.
but windows hung at the end. I had to reset.
when windows came up this time, I scanned again with malwarebytes and it only found 1 items.
it gives me this log :

Malwarebytes' Anti-Malware 1.33
Database version: 1704
Windows 5.1.2600 Service Pack 2

2009-01-29 21:01:21
mbam-log-2009-01-29 (21-01-21).txt

Scan type: Quick Scan
Objects scanned: 57985
Time elapsed: 5 minute(s), 47 second(s)

Memory Processes Infected: 0
Memory Modules Infected: 1
Registry Keys Infected: 0
Registry Values Infected: 0
Registry Data Items Infected: 0
Folders Infected: 0
Files Infected: 1

Memory Processes Infected:
(No malicious items detected)

Memory Modules Infected:
E:\Documents and Settings\Alborz\Local Settings\temp\doaB.tmp (Backdoor.ProRat) -> Delete on reboot.

Registry Keys Infected:
(No malicious items detected)

Registry Values Infected:
(No malicious items detected)

Registry Data Items Infected:
(No malicious items detected)

Folders Infected:
(No malicious items detected)

Files Infected:
E:\Documents and Settings\Alborz\Local Settings\temp\doaB.tmp (Backdoor.ProRat) -> Delete on reboot.



after reboot it deleted that file, but now some file with different name but similar is created. Something is creating it over and over again :/

I scanned again with malwarebytes after that, now it found 4 items.

I just copy and paste the log, its useless to remove them again, it will be created again :


Malwarebytes' Anti-Malware 1.33
Database version: 1704
Windows 5.1.2600 Service Pack 2

2009-01-29 21:21:00
mbam-log-2009-01-29 (21-20-53).txt

Scan type: Quick Scan
Objects scanned: 57940
Time elapsed: 5 minute(s), 42 second(s)

Memory Processes Infected: 0
Memory Modules Infected: 2
Registry Keys Infected: 0
Registry Values Infected: 0
Registry Data Items Infected: 0
Folders Infected: 0
Files Infected: 2

Memory Processes Infected:
(No malicious items detected)

Memory Modules Infected:
E:\Documents and Settings\Alborz\Local Settings\temp\gja1.tmp (Backdoor.ProRat) -> No action taken.
E:\Documents and Settings\Alborz\Local Settings\temp\yka6.tmp (Backdoor.ProRat) -> No action taken.

Registry Keys Infected:
(No malicious items detected)

Registry Values Infected:
(No malicious items detected)

Registry Data Items Infected:
(No malicious items detected)

Folders Infected:
(No malicious items detected)

Files Infected:
E:\Documents and Settings\Alborz\Local Settings\temp\gja1.tmp (Backdoor.ProRat) -> No action taken.
E:\Documents and Settings\Alborz\Local Settings\temp\yka6.tmp (Backdoor.ProRat) -> No action taken.




and here's the hijack this :



Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 21:22, on 2009-01-29
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Boot mode: Normal

Running processes:
E:\WINDOWS\System32\smss.exe
E:\WINDOWS\system32\winlogon.exe
E:\WINDOWS\system32\services.exe
E:\WINDOWS\system32\lsass.exe
E:\WINDOWS\system32\svchost.exe
E:\WINDOWS\System32\svchost.exe
E:\WINDOWS\system32\spoolsv.exe
F:\Program Files\CyberLink\PowerDVD\PDVDServ.exe
F:\Program Files\VirtualCloneDrive\VCDDaemon.exe
E:\WINDOWS\system32\Fmctrl.EXE
E:\Program Files\Apache2.2\bin\httpd.exe
E:\Program Files\Bonjour\mDNSResponder.exe
F:\Program Files\WIDCOMM\Bluetooth Software\bin\btwdins.exe
E:\Program Files\MySQL\MySQL Server 5.0\bin\mysqld-nt.exe
E:\Program Files\Apache2.2\bin\httpd.exe
E:\Program Files\Nero\Nero8\Nero BackItUp\NBService.exe
E:\WINDOWS\system32\nvsvc32.exe
E:\WINDOWS\system32\PnkBstrA.exe
E:\WINDOWS\system32\PSIService.exe
E:\WINDOWS\system32\svchost.exe
E:\WINDOWS\system32\wscntfy.exe
E:\WINDOWS\explorer.exe
F:\Program Files\Malwarebytes' Anti-Malware\mbam.exe
E:\Program Files\Mozilla Firefox\firefox.exe
E:\WINDOWS\system32\NOTEPAD.EXE
F:\Program Files\HijackThis\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - E:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll (file missing)
O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - F:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - F:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
O2 - BHO: Catcher Class - {ADECBED6-0366-4377-A739-E69DFBA04663} - f:\Program Files\FLV Downloader\MoyeaCth.dll
O2 - BHO: QUICKfind BHO Object - {C08DF07A-3E49-4E25-9AB0-D3882835F153} - f:\PROGRA~1\LONGMA~1\LAD001PE\setup\qf\IEHelp.dll
O3 - Toolbar: (no name) - {4E7BD74F-2B8D-469E-CCB0-B130EEDBE97C} - (no file)
O4 - HKLM\..\Run: [IMJPMIG8.1] "E:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE" /Spoil /RemAdvDef /Migration32
O4 - HKLM\..\Run: [PHIME2002ASync] E:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /SYNC
O4 - HKLM\..\Run: [PHIME2002A] E:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /IMEName
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE E:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [RemoteControl] "f:\Program Files\CyberLink\PowerDVD\PDVDServ.exe"
O4 - HKLM\..\Run: [VirtualCloneDrive] "f:\Program Files\VirtualCloneDrive\VCDDaemon.exe" /s
O4 - HKLM\..\Run: [CloneCDTray] "f:\Program Files\CloneCD\CloneCDTray.exe" /s
O4 - HKLM\..\Run: [ISUSPM Startup] "E:\Program Files\Common Files\InstallShield\UpdateService\ISUSPM.exe" -startup
O4 - HKLM\..\Run: [ISUSScheduler] "E:\Program Files\Common Files\InstallShield\UpdateService\issch.exe" -start
O4 - HKLM\..\Run: [FmctrlTray] Fmctrl.EXE
O4 - HKLM\..\Run: [NeroFilterCheck] E:\Program Files\Common Files\Nero\Lib\NeroCheck.exe
O4 - HKLM\..\Run: [NBKeyScan] "E:\Program Files\Nero\Nero8\Nero BackItUp\NBKeyScan.exe"
O4 - HKLM\..\Run: [SunJavaUpdateSched] "F:\Program Files\Java\jre1.6.0_05\bin\jusched.exe"
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE E:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [QuickTime Task] "F:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKCU\..\Run: [ctfmon.exe] E:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [IECheck] E:\WINDOWS\IECheck.exe
O4 - HKUS\S-1-5-18\..\Run: [ctfmon.exe] E:\WINDOWS\system32\ctfmon.exe (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [ctfmon.exe] E:\WINDOWS\system32\ctfmon.exe (User 'Default user')
O4 - Global Startup: Adobe Reader Speed Launch.lnk = E:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O8 - Extra context menu item: &Clean Traces - F:\Program Files\DAP\Privacy Package\dapcleanerie.htm
O8 - Extra context menu item: &Download with &DAP - F:\Program Files\DAP\dapextie.htm
O8 - Extra context menu item: Download &all with DAP - F:\Program Files\DAP\dapextie2.htm
O8 - Extra context menu item: E&xport to Microsoft Excel - res://E:\PROGRA~1\MICROS~2\Office12\EXCEL.EXE/3000
O8 - Extra context menu item: Send to &Bluetooth Device... - F:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie_ctx.htm
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - F:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - F:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - F:\PROGRA~1\MICROS~1\Office12\REFIEBAR.DLL
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - F:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - F:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra button: ICQ6 - {E59EB121-F339-4851-A3BA-FE49C35617C2} - f:\Program Files\ICQ6\ICQ.exe
O9 - Extra 'Tools' menuitem: ICQ6 - {E59EB121-F339-4851-A3BA-FE49C35617C2} - f:\Program Files\ICQ6\ICQ.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - E:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - E:\Program Files\Messenger\msmsgs.exe
O17 - HKLM\System\CCS\Services\Tcpip\..\{33DECB99-D7B7-4170-B79D-8D7848592871}: NameServer = 81.12.74.3 81.12.92.3
O17 - HKLM\System\CCS\Services\Tcpip\..\{BE40051E-E6D6-4EA2-B283-08CDF7E28DB4}: NameServer = 217.218.127.104,4.2.2.4
O23 - Service: Apache2.2 - Apache Software Foundation - E:\Program Files\Apache2.2\bin\httpd.exe
O23 - Service: ##Id_String1.6844F930_1628_4223_B5CC_5BB94B879762## (Bonjour Service) - Apple Computer, Inc. - E:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: Bluetooth Service (btwdins) - Broadcom Corporation. - F:\Program Files\WIDCOMM\Bluetooth Software\bin\btwdins.exe
O23 - Service: FLEXnet Licensing Service - Macrovision Europe Ltd. - E:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - E:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: MySql - Unknown owner - E:/mysql/bin/mysqld-nt.exe (file missing)
O23 - Service: MySQL5 - Unknown owner - E:\Program.exe (file missing)
O23 - Service: Nero BackItUp Scheduler 3 - Nero AG - E:\Program Files\Nero\Nero8\Nero BackItUp\NBService.exe
O23 - Service: NMIndexingService - Nero AG - E:\Program Files\Common Files\Nero\Lib\NMIndexingService.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - E:\WINDOWS\system32\nvsvc32.exe
O23 - Service: PnkBstrA - Unknown owner - E:\WINDOWS\system32\PnkBstrA.exe
O23 - Service: ProtexisLicensing - Unknown owner - E:\WINDOWS\system32\PSIService.exe


--
End of file - 7463 bytes
 
Download and run combofix, follow the instructions here. After it scans please post the log that it displays at the end along with a new hijackthis log.
 
Here's combo fix log :

ComboFix 09-01-21.04 - Alborz 2009-01-29 22:46:01.21 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.2.1256.981.1033.18.3326.2770 [GMT 3.5:30]
Running from: e:\documents and settings\Alborz\Desktop\ComboFix.exe

WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!
.

((((((((((((((((((((((((( Files Created from 2008-12-28 to 2009-01-29 )))))))))))))))))))))))))))))))
.

2009-01-29 22:45 . 2009-01-29 22:45 176,128 --a------ e:\windows\tlj73.tmp
2009-01-29 22:44 . 2009-01-29 22:44 176,128 --a------ e:\windows\xvj71.tmp
2009-01-29 22:44 . 2009-01-29 22:44 176,128 --a------ e:\windows\nnj70.tmp
2009-01-29 22:44 . 2009-01-29 22:44 176,128 --a------ e:\windows\hdj72.tmp
2009-01-29 22:43 . 2009-01-29 22:43 176,128 --a------ e:\windows\qxj6E.tmp
2009-01-29 22:43 . 2009-01-29 22:43 176,128 --a------ e:\windows\jpj6D.tmp
2009-01-29 22:43 . 2009-01-29 22:43 176,128 --a------ e:\windows\bfj6F.tmp
2009-01-29 22:42 . 2009-01-29 22:42 176,128 --a------ e:\windows\xhj6C.tmp
2009-01-29 22:42 . 2009-01-29 22:42 176,128 --a------ e:\windows\mzj6B.tmp
2009-01-29 22:42 . 2009-01-29 22:42 176,128 --a------ e:\windows\drj6A.tmp
2009-01-29 22:41 . 2009-01-29 22:41 176,128 --a------ e:\windows\zti67.tmp
2009-01-29 22:41 . 2009-01-29 22:41 176,128 --a------ e:\windows\ujj69.tmp
2009-01-29 22:41 . 2009-01-29 22:41 176,128 --a------ e:\windows\lbj68.tmp
2009-01-29 22:40 . 2009-01-29 22:40 176,128 --a------ e:\windows\ovi64.tmp
2009-01-29 22:40 . 2009-01-29 22:40 176,128 --a------ e:\windows\nmi66.tmp
2009-01-29 22:40 . 2009-01-29 22:40 176,128 --a------ e:\windows\aei65.tmp
2009-01-29 22:39 . 2009-01-29 22:39 176,128 --a------ e:\windows\ygi62.tmp
2009-01-29 22:39 . 2009-01-29 22:39 176,128 --a------ e:\windows\oyi61.tmp
2009-01-29 22:39 . 2009-01-29 22:39 176,128 --a------ e:\windows\foi63.tmp
2009-01-29 22:38 . 2009-01-29 22:38 176,128 --a------ e:\windows\uii5F.tmp
2009-01-29 22:38 . 2009-01-29 22:38 176,128 --a------ e:\windows\hai5E.tmp
2009-01-29 22:38 . 2009-01-29 22:38 176,128 --a------ e:\windows\cqi60.tmp
2009-01-29 22:37 . 2009-01-29 22:37 176,128 --a------ e:\windows\ysi5D.tmp
2009-01-29 22:37 . 2009-01-29 22:37 176,128 --a------ e:\windows\pki5C.tmp
2009-01-29 22:37 . 2009-01-29 22:37 176,128 --a------ e:\windows\ici5B.tmp
2009-01-29 22:36 . 2009-01-29 22:36 176,128 --a------ e:\windows\wui5A.tmp
2009-01-29 22:36 . 2009-01-29 22:36 176,128 --a------ e:\windows\kmi59.tmp
2009-01-29 22:36 . 2009-01-29 22:36 176,128 --a------ e:\windows\afi58.tmp
2009-01-29 22:35 . 2009-01-29 22:35 176,128 --a------ e:\windows\xhi55.tmp
2009-01-29 22:35 . 2009-01-29 22:35 176,128 --a------ e:\windows\qwi57.tmp
2009-01-29 22:35 . 2009-01-29 22:35 176,128 --a------ e:\windows\gpi56.tmp
2009-01-29 22:34 . 2009-01-29 22:34 176,128 --a------ e:\windows\zri53.tmp
2009-01-29 22:34 . 2009-01-29 22:34 176,128 --a------ e:\windows\oji52.tmp
2009-01-29 22:34 . 2009-01-29 22:34 176,128 --a------ e:\windows\myi54.tmp
2009-01-29 22:33 . 2009-01-29 22:33 176,128 --a------ e:\windows\uti50.tmp
2009-01-29 22:33 . 2009-01-29 22:33 176,128 --a------ e:\windows\mli4F.tmp
2009-01-29 22:33 . 2009-01-29 22:33 176,128 --a------ e:\windows\dbi51.tmp
2009-01-29 22:32 . 2009-01-29 22:32 176,128 --a------ e:\windows\qvi4D.tmp
2009-01-29 22:32 . 2009-01-29 22:32 176,128 --a------ e:\windows\ini4C.tmp
2009-01-29 22:32 . 2009-01-29 22:32 176,128 --a------ e:\windows\cdi4E.tmp
2009-01-29 22:31 . 2009-01-29 22:31 176,128 --a------ e:\windows\wfi4B.tmp
2009-01-29 22:31 . 2009-01-29 22:31 176,128 --a------ e:\windows\kxi4A.tmp
2009-01-29 22:31 . 2009-01-29 22:31 176,128 --a------ e:\windows\bpi49.tmp
2009-01-29 22:30 . 2009-01-29 22:30 176,128 --a------ e:\windows\wrh46.tmp
2009-01-29 22:30 . 2009-01-29 22:30 176,128 --a------ e:\windows\pii48.tmp
2009-01-29 22:30 . 2009-01-29 22:30 176,128 --a------ e:\windows\iai47.tmp
2009-01-29 22:29 . 2009-01-29 22:29 176,128 --a------ e:\windows\puh43.tmp
2009-01-29 22:29 . 2009-01-29 22:29 176,128 --a------ e:\windows\kkh45.tmp
2009-01-29 22:29 . 2009-01-29 22:29 176,128 --a------ e:\windows\bch44.tmp
2009-01-29 22:28 . 2009-01-29 22:28 176,128 --a------ e:\windows\teh41.tmp
2009-01-29 22:28 . 2009-01-29 22:28 176,128 --a------ e:\windows\hwh40.tmp
2009-01-29 22:28 . 2009-01-29 22:28 176,128 --a------ e:\windows\emh42.tmp
2009-01-29 22:27 . 2009-01-29 22:27 176,128 --a------ e:\windows\uoh3F.tmp
2009-01-29 22:27 . 2009-01-29 22:27 176,128 --a------ e:\windows\mgh3E.tmp
2009-01-29 22:27 . 2009-01-29 22:27 176,128 --a------ e:\windows\byh3D.tmp
2009-01-29 22:26 . 2009-01-29 22:26 176,128 --a------ e:\windows\sbh3A.tmp
2009-01-29 22:26 . 2009-01-29 22:26 176,128 --a------ e:\windows\nqh3C.tmp
2009-01-29 22:26 . 2009-01-29 22:26 176,128 --a------ e:\windows\eih3B.tmp
2009-01-29 22:25 . 2009-01-29 22:25 176,128 --a------ e:\windows\xkh38.tmp
2009-01-29 22:25 . 2009-01-29 22:25 176,128 --a------ e:\windows\pdh37.tmp
2009-01-29 22:25 . 2009-01-29 22:25 176,128 --a------ e:\windows\hsh39.tmp
2009-01-29 22:24 . 2009-01-29 22:24 176,128 --a------ e:\windows\rnh35.tmp
2009-01-29 22:24 . 2009-01-29 22:24 176,128 --a------ e:\windows\ffh34.tmp
2009-01-29 22:24 . 2009-01-29 22:24 176,128 --a------ e:\windows\duh36.tmp
2009-01-29 22:23 . 2009-01-29 22:23 176,128 --a------ e:\windows\vxh33.tmp
2009-01-29 22:23 . 2009-01-29 22:23 176,128 --a------ e:\windows\vhh31.tmp
2009-01-29 22:23 . 2009-01-29 22:23 176,128 --a------ e:\windows\jph32.tmp
2009-01-29 22:22 . 2009-01-29 22:22 176,128 --a------ e:\windows\pjh2E.tmp
2009-01-29 22:22 . 2009-01-29 22:22 176,128 --a------ e:\windows\lzh30.tmp
2009-01-29 22:22 . 2009-01-29 22:22 176,128 --a------ e:\windows\brh2F.tmp
2009-01-29 22:21 . 2009-01-29 22:21 176,128 --a------ e:\windows\sth2C.tmp
2009-01-29 22:21 . 2009-01-29 22:21 176,128 --a------ e:\windows\hlh2B.tmp
2009-01-29 22:21 . 2009-01-29 22:21 176,128 --a------ e:\windows\dbh2D.tmp
2009-01-29 22:20 . 2009-01-29 22:20 176,128 --a------ e:\windows\ydh2A.tmp
2009-01-29 22:20 . 2009-01-29 22:20 176,128 --a------ e:\windows\pvh29.tmp
2009-01-29 22:20 . 2009-01-29 22:20 176,128 --a------ e:\windows\foh28.tmp
2009-01-29 22:19 . 2009-01-29 22:19 176,128 --a------ e:\windows\vqg25.tmp
2009-01-29 22:19 . 2009-01-29 22:19 176,128 --a------ e:\windows\rgh27.tmp
2009-01-29 22:19 . 2009-01-29 22:19 176,128 --a------ e:\windows\gyg26.tmp
2009-01-29 22:18 . 2009-01-29 22:18 176,128 --a------ e:\windows\zag23.tmp
2009-01-29 22:18 . 2009-01-29 22:18 176,128 --a------ e:\windows\qsg22.tmp
2009-01-29 22:18 . 2009-01-29 22:18 176,128 --a------ e:\windows\lig24.tmp
2009-01-29 22:17 . 2009-01-29 22:17 176,128 --a------ e:\windows\rcg20.tmp
2009-01-29 22:17 . 2009-01-29 22:17 176,128 --a------ e:\windows\gug1F.tmp
2009-01-29 22:17 . 2009-01-29 22:17 176,128 --a------ e:\windows\dkg21.tmp
2009-01-29 22:16 . 2009-01-29 22:16 176,128 --a------ e:\windows\wmg1E.tmp
2009-01-29 22:16 . 2009-01-29 22:16 176,128 --a------ e:\windows\meg1D.tmp
2009-01-29 22:16 . 2009-01-29 22:16 176,128 --a------ e:\windows\dwg1C.tmp
2009-01-29 22:15 . 2009-01-29 22:15 176,128 --a------ e:\windows\sog1B.tmp
2009-01-29 22:15 . 2009-01-29 22:15 176,128 --a------ e:\windows\qyg19.tmp
2009-01-29 22:15 . 2009-01-29 22:15 176,128 --a------ e:\windows\ehg1A.tmp
2009-01-29 22:14 . 2009-01-29 22:14 176,128 --a------ e:\windows\ujg17.tmp
2009-01-29 22:14 . 2009-01-29 22:14 176,128 --a------ e:\windows\jbg16.tmp
2009-01-29 22:14 . 2009-01-29 22:14 176,128 --a------ e:\windows\iag14.tmp
2009-01-29 22:14 . 2009-01-29 22:14 176,128 --a------ e:\windows\fag15.tmp
2009-01-29 22:14 . 2009-01-29 22:14 176,128 --a------ e:\windows\erg18.tmp
2009-01-29 22:13 . 2009-01-29 22:13 176,128 --a------ e:\windows\yrgE.tmp
2009-01-29 22:13 . 2009-01-29 22:13 176,128 --a------ e:\windows\wsg12.tmp
2009-01-29 22:13 . 2009-01-29 22:13 176,128 --a------ e:\windows\vrgF.tmp
2009-01-29 22:13 . 2009-01-29 22:13 176,128 --a------ e:\windows\qsg10.tmp
2009-01-29 22:13 . 2009-01-29 22:13 176,128 --a------ e:\windows\nsg11.tmp
2009-01-29 22:13 . 2009-01-29 22:13 176,128 --a------ e:\windows\ctg13.tmp
2009-01-29 21:01 . 2009-01-29 21:01 823,296 --a------ e:\windows\isRS-000.tmp
2009-01-29 20:35 . 2009-01-29 20:48 <DIR> d-------- E:\SDFix
2009-01-29 18:48 . 2009-01-29 18:48 176,128 --a------ e:\windows\mfhA99.tmp
2009-01-29 18:47 . 2009-01-29 18:47 176,128 --a------ e:\windows\zxhA98.tmp
2009-01-29 18:47 . 2009-01-29 18:47 176,128 --a------ e:\windows\uhhA96.tmp
2009-01-29 18:47 . 2009-01-29 18:47 176,128 --a------ e:\windows\iphA97.tmp
2009-01-29 18:46 . 2009-01-29 18:46 176,128 --a------ e:\windows\prhA94.tmp
2009-01-29 18:46 . 2009-01-29 18:46 176,128 --a------ e:\windows\fjhA93.tmp
2009-01-29 18:46 . 2009-01-29 18:46 176,128 --a------ e:\windows\dzhA95.tmp
2009-01-29 18:44 . 2009-01-29 18:44 176,128 --a------ e:\windows\uohA8D.tmp
2009-01-29 18:44 . 2009-01-29 18:44 176,128 --a------ e:\windows\kwhA8E.tmp
2009-01-29 18:44 . 2009-01-29 18:44 176,128 --a------ e:\windows\behA8F.tmp
2009-01-29 18:43 . 2009-01-29 18:43 176,128 --a------ e:\windows\gghA8C.tmp
2009-01-29 18:43 . 2009-01-29 18:43 176,128 --a------ e:\windows\cqhA8A.tmp
2009-01-29 18:42 . 2009-01-29 18:42 176,128 --a------ e:\windows\pihA89.tmp
2009-01-29 18:42 . 2009-01-29 18:42 176,128 --a------ e:\windows\oshA87.tmp
2009-01-29 18:42 . 2009-01-29 18:42 176,128 --a------ e:\windows\aahA88.tmp
2009-01-29 18:41 . 2009-01-29 18:41 176,128 --a------ e:\windows\xugA84.tmp
2009-01-29 18:41 . 2009-01-29 18:41 176,128 --a------ e:\windows\qchA85.tmp
2009-01-29 18:41 . 2009-01-29 18:41 176,128 --a------ e:\windows\ckhA86.tmp
2009-01-29 18:40 . 2009-01-29 18:40 176,128 --a------ e:\windows\ywgA81.tmp
2009-01-29 18:40 . 2009-01-29 18:40 176,128 --a------ e:\windows\mfgA82.tmp
2009-01-29 18:40 . 2009-01-29 18:40 176,128 --a------ e:\windows\gmgA83.tmp

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-01-29 15:34 --------- d-----w e:\documents and settings\Alborz\Application Data\uTorrent
2009-01-29 08:11 176,128 ----a-w e:\windows\ydt1DA.tmp
2009-01-29 08:09 176,128 ----a-w e:\windows\zqt1CA.tmp
2009-01-29 08:09 176,128 ----a-w e:\windows\tet1D2.tmp
2009-01-29 08:09 176,128 ----a-w e:\windows\rwt1CD.tmp
2009-01-29 08:09 176,128 ----a-w e:\windows\rrt1CB.tmp
2009-01-29 08:09 176,128 ----a-w e:\windows\pot1C8.tmp
2009-01-29 08:09 176,128 ----a-w e:\windows\oit1C7.tmp
2009-01-29 08:09 176,128 ----a-w e:\windows\jwt1CE.tmp
2009-01-29 08:09 176,128 ----a-w e:\windows\jht1C6.tmp
2009-01-29 08:09 176,128 ----a-w e:\windows\iyt1CF.tmp
2009-01-29 08:09 176,128 ----a-w e:\windows\iut1CC.tmp
2009-01-29 08:09 176,128 ----a-w e:\windows\get1D1.tmp
2009-01-29 08:09 176,128 ----a-w e:\windows\fet1D0.tmp
2009-01-29 08:09 176,128 ----a-w e:\windows\cet1D3.tmp
2009-01-29 07:12 --------- d-----w e:\documents and settings\Alborz\Application Data\FileZilla
2009-01-26 13:20 6,110 -csha-w e:\windows\system32\KGyGaAvL.sys
2009-01-26 13:19 --------- d---a-w e:\documents and settings\All Users\Application Data\TEMP
2009-01-21 20:36 --------- d-----w e:\documents and settings\Alborz\Application Data\MySQL
2009-01-14 12:41 38,496 ----a-w e:\windows\system32\drivers\mbamswissarmy.sys
2009-01-14 12:41 15,504 ----a-w e:\windows\system32\drivers\mbam.sys
2008-12-28 22:48 2,330,643 ----a-w e:\windows\system32\x264vfw.dll
2008-12-11 00:33 86,016 ----a-w e:\windows\system32\dpl100.dll
2008-12-08 11:53 57,344 ----a-w e:\windows\system32\ff_vfw.dll
2008-12-07 18:08 795,648 ----a-w e:\windows\system32\xvidcore.dll
2008-12-07 18:08 130,048 ----a-w e:\windows\system32\xvidvfw.dll
2008-12-06 16:57 --------- d-----w e:\program files\MSXML 6.0
2008-12-06 16:56 --------- d-----w e:\program files\MSBuild
2008-12-06 16:55 --------- d-----w e:\program files\Reference Assemblies
2008-12-06 16:53 --------- d--h--w e:\program files\InstallShield Installation Information
2008-12-06 10:28 --------- d-----w e:\documents and settings\Alborz\Application Data\Xfire
2008-11-20 20:44 42,320 ----a-w e:\windows\system32\xfcodec.dll
2008-11-06 16:37 3,596,288 ----a-w e:\windows\system32\qt-dx331.dll
2008-11-06 16:33 684,032 ----a-w e:\windows\system32\divx.dll
2008-09-10 14:04 1,503,948,100 ----a-w e:\program files\full_backup.rar
2007-12-03 08:43 67,696 ----a-w e:\program files\mozilla firefox\components\jar50.dll
2007-12-03 08:43 54,376 ----a-w e:\program files\mozilla firefox\components\jsd3250.dll
2007-12-03 08:43 34,952 ----a-w e:\program files\mozilla firefox\components\myspell.dll
2007-12-03 08:43 46,720 ----a-w e:\program files\mozilla firefox\components\spellchk.dll
2007-12-03 08:43 172,144 ----a-w e:\program files\mozilla firefox\components\xpinstal.dll
2007-08-09 07:55 8 --sh--r e:\windows\system32\85FC424469.sys
2008-05-27 08:27 88 --sh--r e:\windows\system32\D58D4D8297.sys
.

------- Sigcheck -------

2004-09-01 11:30 359040 7b11118b078b88f87183fe69eda43137 e:\windows\system32\drivers\tcpip.sys

2004-09-01 11:30 215552 a77219a971029dc2fb683e8513713803 e:\windows\system32\termsrv.dll
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="e:\windows\system32\ctfmon.exe" [2004-09-01 15360]
"IECheck"="e:\windows\IECheck.exe" [2005-11-17 286174]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"IMJPMIG8.1"="e:\windows\IME\imjp8_1\IMJPMIG.EXE" [2004-09-01 208952]
"PHIME2002ASync"="e:\windows\system32\IME\TINTLGNT\TINTSETP.EXE" [2004-09-01 455168]
"PHIME2002A"="e:\windows\system32\IME\TINTLGNT\TINTSETP.EXE" [2004-09-01 455168]
"NvCplDaemon"="e:\windows\system32\NvCpl.dll" [2008-01-08 8523776]
"RemoteControl"="f:\program files\CyberLink\PowerDVD\PDVDServ.exe" [2004-11-02 32768]
"VirtualCloneDrive"="f:\program files\VirtualCloneDrive\VCDDaemon.exe" [2006-04-29 94208]
"CloneCDTray"="f:\program files\CloneCD\CloneCDTray.exe" [2005-05-19 234970]
"ISUSPM Startup"="e:\program files\Common Files\InstallShield\UpdateService\ISUSPM.exe" [2005-08-11 427476]
"ISUSScheduler"="e:\program files\Common Files\InstallShield\UpdateService\issch.exe" [2005-08-11 259548]
"NeroFilterCheck"="e:\program files\Common Files\Nero\Lib\NeroCheck.exe" [2007-03-01 333280]
"NBKeyScan"="e:\program files\Nero\Nero8\Nero BackItUp\NBKeyScan.exe" [2007-09-20 2016732]
"SunJavaUpdateSched"="f:\program files\Java\jre1.6.0_05\bin\jusched.exe" [2008-02-22 325088]
"NvMediaCenter"="e:\windows\system32\NvMcTray.dll" [2008-01-08 81920]
"QuickTime Task"="f:\program files\QuickTime\qttask.exe" [2008-09-06 591326]
"nwiz"="nwiz.exe" [2008-01-08 e:\windows\system32\nwiz.exe]
"FmctrlTray"="Fmctrl.EXE" [2001-11-06 e:\windows\system32\fmctrl.exe]

[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="e:\windows\system32\ctfmon.exe" [2004-09-01 15360]

e:\documents and settings\All Users\Start Menu\Programs\Startup\
Adobe Reader Speed Launch.lnk - e:\program files\Adobe\Acrobat 7.0\Reader\reader_sl.exe [2008-04-23 207326]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"VIDC.ACDV"= ACDV.dll
"msacm.l3codec"= l3codecp.acm
"VIDC.XFR1"= xfcodec.dll
"msacm.l3fhg"= mp3fhg.acm
"msacm.divxa32"= divxa32.acm
"VIDC.X264"= x264vfw.dll
"VIDC.HFYU"= huffyuv.dll
"vidc.i263"= i263_32.drv

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"e:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=
"e:\\Program Files\\Windows Live\\Messenger\\livecall.exe"=
"e:\\Program Files\\uTorrent\\uTorrent.exe"=
"f:\\Program Files\\wa\\WA.exe"=
"f:\\Program Files\\Yahoo! Messenger\\YahooMessenger.exe"=
"f:\\Program Files\\Yahoo! Messenger\\YServer.exe"=
"e:\\Program Files\\SlonAx\\slnx_client.exe"=

R3 gameport;Genius SM-Live Series PCI Joystick;e:\windows\system32\drivers\fmjoy.sys [2007-10-06 9728]
R3 SKYNET;TechniSat DVB-PC TV Star PCI;e:\windows\system32\drivers\SkyNET.sys [2007-07-31 349184]
R3 wdm_fm801;Genius SM-Live Series PCI Audio (WDM);e:\windows\system32\drivers\fm801.sys [2007-10-06 320163]
R4 Apache2.2;Apache2.2;e:\program files\Apache2.2\bin\httpd.exe [2007-09-05 24635]
R4 MySQL5;MySQL5;"e:\program files\MySQL\MySQL Server 5.0\bin\mysqld-nt" --defaults-file="e:\program files\MySQL\MySQL Server 5.0\my.ini" MySQL5 --> e:\program files\MySQL\MySQL Server 5.0\bin\mysqld-nt [?]
S1 rxp;rxp;\??\e:\windows\system32\drivers\rxp.sys --> e:\windows\system32\drivers\rxp.sys [?]

--- Other Services/Drivers In Memory ---

*Deregistered* - BootScreen

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{5b3e0f2a-35e3-11dd-aa6b-00d0d714a718}]
\Shell\Auto\command - sunny.exe
\Shell\AutoRun\command - e:\windows\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL sunny.exe

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{660b21a9-4989-11dc-a765-00d0d714a718}]
\Shell\AutoRun\command - P:\autorun.exe
.
.
------- Supplementary Scan -------
.
uStart Page = about:blank
uInternet Settings,ProxyOverride = <local>
IE: &Clean Traces - f:\program files\DAP\Privacy Package\dapcleanerie.htm
IE: &Download with &DAP - f:\program files\DAP\dapextie.htm
IE: Download &all with DAP - f:\program files\DAP\dapextie2.htm
IE: E&xport to Microsoft Excel - e:\progra~1\MICROS~2\Office12\EXCEL.EXE/3000
IE: Send to &Bluetooth Device... - f:\program files\WIDCOMM\Bluetooth Software\btsendto_ie_ctx.htm
TCP: {33DECB99-D7B7-4170-B79D-8D7848592871} = 81.12.74.3 81.12.92.3
TCP: {BE40051E-E6D6-4EA2-B283-08CDF7E28DB4} = 217.218.127.104,4.2.2.4
FF - ProfilePath - e:\documents and settings\Alborz\Application Data\Mozilla\Firefox\Profiles\a58asg4q.default\
FF - prefs.js: browser.search.selectedEngine - Google
FF - prefs.js: browser.startup.homepage -
FF - prefs.js: keyword.URL - hxxp://search.yahoo.com/search?ei=utf-8&fr=megaup&p=
FF - component: e:\program files\Mozilla Firefox\components\xpinstal.dll
FF - component: f:\program files\DAP\DAPFireFox\components\DAPFireFox.dll
.

**************************************************************************

catchme 0.3.1367 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2009-01-29 22:46:36
Windows 5.1.2600 Service Pack 2 NTFS

scanning hidden processes ...

scanning hidden autostart entries ...

scanning hidden files ...

scan completed successfully
hidden files: 0

**************************************************************************

[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\MySql]
"ImagePath"="E:/mysql/bin/mysqld-nt.exe"

[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\MySql]
"ImagePath"="E:/mysql/bin/mysqld-nt.exe"

[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\MySQL5]
"ImagePath"="\"e:\program files\MySQL\MySQL Server 5.0\bin\mysqld-nt\" --defaults-file=\"e:\program files\MySQL\MySQL Server 5.0\my.ini\" MySQL5"
.
--------------------- LOCKED REGISTRY KEYS ---------------------

[HKEY_USERS\S-1-5-21-1960408961-261903793-839522115-1003\Software\SecuROM\!CAUTION! NEVER A OR CHANGE ANY KEY*]
"??"=hex:a8,18,db,f7,2f,5f,bd,f5,c5,fe,9b,e2,83,6b,b2,4d,38,1c,97,01,df,dc,0c,
89,c7,07,22,a2,fb,d7,a5,7c,33,22,82,6c,b7,62,f5,9f,c3,93,ee,1e,13,6a,b5,43,\
"??"=hex:8f,38,87,ab,37,16,a3,70,d8,a4,e5,27,7f,89,e7,4f
.
Completion time: 2009-01-29 22:47:42
ComboFix-quarantined-files.txt 2009-01-29 19:17:21
ComboFix2.txt 2009-01-28 11:00:50

Pre-Run: 61,176,377,344 bytes free
Post-Run: 61,171,773,440 bytes free

291


hijackthis

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 22:50, on 2009-01-29
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Boot mode: Normal

Running processes:
E:\WINDOWS\System32\smss.exe
E:\WINDOWS\system32\winlogon.exe
E:\WINDOWS\system32\services.exe
E:\WINDOWS\system32\lsass.exe
E:\WINDOWS\system32\svchost.exe
E:\WINDOWS\System32\svchost.exe
E:\WINDOWS\system32\spoolsv.exe
F:\Program Files\CyberLink\PowerDVD\PDVDServ.exe
F:\Program Files\VirtualCloneDrive\VCDDaemon.exe
E:\WINDOWS\system32\Fmctrl.EXE
E:\Program Files\Apache2.2\bin\httpd.exe
E:\Program Files\Bonjour\mDNSResponder.exe
F:\Program Files\WIDCOMM\Bluetooth Software\bin\btwdins.exe
E:\Program Files\MySQL\MySQL Server 5.0\bin\mysqld-nt.exe
E:\Program Files\Apache2.2\bin\httpd.exe
E:\Program Files\Nero\Nero8\Nero BackItUp\NBService.exe
E:\WINDOWS\system32\nvsvc32.exe
E:\WINDOWS\system32\PnkBstrA.exe
E:\WINDOWS\system32\PSIService.exe
E:\WINDOWS\system32\svchost.exe
E:\WINDOWS\system32\wscntfy.exe
E:\WINDOWS\system32\notepad.exe
E:\WINDOWS\explorer.exe
E:\Program Files\Mozilla Firefox\firefox.exe
F:\Program Files\HijackThis\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - E:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll (file missing)
O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - F:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - F:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
O2 - BHO: Catcher Class - {ADECBED6-0366-4377-A739-E69DFBA04663} - f:\Program Files\FLV Downloader\MoyeaCth.dll
O2 - BHO: QUICKfind BHO Object - {C08DF07A-3E49-4E25-9AB0-D3882835F153} - f:\PROGRA~1\LONGMA~1\LAD001PE\setup\qf\IEHelp.dll
O3 - Toolbar: (no name) - {4E7BD74F-2B8D-469E-CCB0-B130EEDBE97C} - (no file)
O4 - HKLM\..\Run: [IMJPMIG8.1] "E:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE" /Spoil /RemAdvDef /Migration32
O4 - HKLM\..\Run: [PHIME2002ASync] E:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /SYNC
O4 - HKLM\..\Run: [PHIME2002A] E:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /IMEName
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE E:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [RemoteControl] "f:\Program Files\CyberLink\PowerDVD\PDVDServ.exe"
O4 - HKLM\..\Run: [VirtualCloneDrive] "f:\Program Files\VirtualCloneDrive\VCDDaemon.exe" /s
O4 - HKLM\..\Run: [CloneCDTray] "f:\Program Files\CloneCD\CloneCDTray.exe" /s
O4 - HKLM\..\Run: [ISUSPM Startup] "E:\Program Files\Common Files\InstallShield\UpdateService\ISUSPM.exe" -startup
O4 - HKLM\..\Run: [ISUSScheduler] "E:\Program Files\Common Files\InstallShield\UpdateService\issch.exe" -start
O4 - HKLM\..\Run: [FmctrlTray] Fmctrl.EXE
O4 - HKLM\..\Run: [NeroFilterCheck] E:\Program Files\Common Files\Nero\Lib\NeroCheck.exe
O4 - HKLM\..\Run: [NBKeyScan] "E:\Program Files\Nero\Nero8\Nero BackItUp\NBKeyScan.exe"
O4 - HKLM\..\Run: [SunJavaUpdateSched] "F:\Program Files\Java\jre1.6.0_05\bin\jusched.exe"
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE E:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [QuickTime Task] "F:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKCU\..\Run: [ctfmon.exe] E:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [IECheck] E:\WINDOWS\IECheck.exe
O4 - HKUS\S-1-5-18\..\Run: [ctfmon.exe] E:\WINDOWS\system32\ctfmon.exe (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [ctfmon.exe] E:\WINDOWS\system32\ctfmon.exe (User 'Default user')
O4 - Global Startup: Adobe Reader Speed Launch.lnk = E:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O8 - Extra context menu item: &Clean Traces - F:\Program Files\DAP\Privacy Package\dapcleanerie.htm
O8 - Extra context menu item: &Download with &DAP - F:\Program Files\DAP\dapextie.htm
O8 - Extra context menu item: Download &all with DAP - F:\Program Files\DAP\dapextie2.htm
O8 - Extra context menu item: E&xport to Microsoft Excel - res://E:\PROGRA~1\MICROS~2\Office12\EXCEL.EXE/3000
O8 - Extra context menu item: Send to &Bluetooth Device... - F:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie_ctx.htm
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - F:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - F:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - F:\PROGRA~1\MICROS~1\Office12\REFIEBAR.DLL
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - F:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - F:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra button: ICQ6 - {E59EB121-F339-4851-A3BA-FE49C35617C2} - f:\Program Files\ICQ6\ICQ.exe
O9 - Extra 'Tools' menuitem: ICQ6 - {E59EB121-F339-4851-A3BA-FE49C35617C2} - f:\Program Files\ICQ6\ICQ.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - E:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - E:\Program Files\Messenger\msmsgs.exe
O17 - HKLM\System\CCS\Services\Tcpip\..\{33DECB99-D7B7-4170-B79D-8D7848592871}: NameServer = 81.12.74.3 81.12.92.3
O17 - HKLM\System\CCS\Services\Tcpip\..\{BE40051E-E6D6-4EA2-B283-08CDF7E28DB4}: NameServer = 217.218.127.104,4.2.2.4
O23 - Service: Apache2.2 - Apache Software Foundation - E:\Program Files\Apache2.2\bin\httpd.exe
O23 - Service: ##Id_String1.6844F930_1628_4223_B5CC_5BB94B879762## (Bonjour Service) - Apple Computer, Inc. - E:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: Bluetooth Service (btwdins) - Broadcom Corporation. - F:\Program Files\WIDCOMM\Bluetooth Software\bin\btwdins.exe
O23 - Service: FLEXnet Licensing Service - Macrovision Europe Ltd. - E:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - E:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: MySql - Unknown owner - E:/mysql/bin/mysqld-nt.exe (file missing)
O23 - Service: MySQL5 - Unknown owner - E:\Program.exe (file missing)
O23 - Service: Nero BackItUp Scheduler 3 - Nero AG - E:\Program Files\Nero\Nero8\Nero BackItUp\NBService.exe
O23 - Service: NMIndexingService - Nero AG - E:\Program Files\Common Files\Nero\Lib\NMIndexingService.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - E:\WINDOWS\system32\nvsvc32.exe
O23 - Service: PnkBstrA - Unknown owner - E:\WINDOWS\system32\PnkBstrA.exe
O23 - Service: ProtexisLicensing - Unknown owner - E:\WINDOWS\system32\PSIService.exe

--
End of file - 7409 bytes
 
Last edited:
I've pm'd a mod (ceewi1) to help you out. He most likely won't be online until later tonight since he lives in Australia. He'll respond as soon as he can.
 
Your log reveals a backdoor trojan. These can severely compromise personal information which could lead to identity theft.

I would counsel you to disconnect this PC from the Internet immediately. If you do any banking or other financial transactions on the PC or it if it contains any other sensitive information, please get to a known clean computer and change all passwords where applicable, and it would be wise to contact those same financial institutions to apprise them of your situation.

Though the Trojan has been identified and can be killed, because of it's backdoor functionality, your PC may already be compromised and there is no way to be sure your computer can ever again be trusted. Many experts in the security community believe that once infected with this type of Trojan, the best course of action would be a reformat and reinstall of the OS. Please read these for more information:

How Do I Handle Possible Identify Theft, Internet Fraud and CC Fraud?

When Should I Format, How Should I Reinstall

If you choose to proceed with disinfection, please follow the instructions below:

* Download Dr.Web CureIt to the desktop:
ftp://ftp.drweb.com/pub/drweb/cureit/drweb-cureit.exe
  • Doubleclick the drweb-cureit.exe file and Allow to run the express scan
  • This will scan the files currently running in memory and when something is found, click the yes button when it asks you if you want to cure it. This is only a short scan.
  • Once the short scan has finished, Click Options > Change settings
  • Choose the Scan-tab, remove the mark at Heuristic analysis.
  • Back at the main window, mark the drives that you want to scan.
  • Select all drives. A red dot shows which drives have been chosen.
  • Click the green arrow at the right, and the scan will start.
  • Click 'Yes to all' if it asks if you want to cure/move the file.
  • When the scan has finished, look if you can click next icon next to the files found:
    check.gif
  • If so, click it and then click the next icon right below and select Move incurable as you'll see in next image:
    move.gif

    This will move it to the %userprofile%\DoctorWeb\quarantaine-folder if it can't be cured. (this in case if we need samples)
  • After selecting, in the Dr.Web CureIt menu on top, click file and choose save report list
  • Save the report to your desktop. The report will be called DrWeb.csv
  • Close Dr.Web Cureit.
  • Reboot your computer!! Because it could be possible that files in use will be moved/deleted during reboot.
  • After reboot, post the contents of the log from Dr.Web you saved previously in your next reply.

Please download the OTMoveIt3 by OldTimer.
  • Save it to your desktop.
  • Please double-click OTMoveIt3.exe to run it.
  • Copy the contents of the codebox below to the clipboard by highlighting ALL of them and pressing CTRL + C (or, after highlighting, right-click and choose Copy):

    Code:
    :processes
    explorer.exe
    
    :files
    e:\windows\*.tmp
    E:\Documents and Settings\Alborz\Local Settings\temp\*.tmp
    
    :reg
    [-HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{5b3e0f2a-35e3-11dd-aa6b-00d0d714a718}]
    [-HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{660b21a9-4989-11dc-a765-00d0d714a718}]
    
    :commands
    [emptytemp]
    [start explorer]
  • Return to OTMoveIt3, right click in the Paste List of Files/Folders to Move window (under the yellow bar) and choose Paste.
  • Click the red Moveit! button.
  • Copy everything in the Results window (under the green bar) to the clipboard by highlighting ALL of them and pressing CTRL + C (or, after highlighting, right-click and choose copy), and paste it in your next reply. These results are also located at C:\_OTMoveIt\MovedFiles\Date_Time.log, where Date_Time is the date and time you ran OTMoveIt.
  • Close OTMoveIt3
If a file or folder cannot be moved immediately you may be asked to reboot the machine to finish the move process. If you are asked to reboot the machine choose Yes.

Once done, please delete your current version of ComboFix. Download and run updated an version from http://download.bleepingcomputer.com/sUBs/ComboFix.exe

Please post
  • The Dr. Web CureIt log
  • The OTMoveIt3 log
  • The updated ComboFix log
  • A new HijackThis log
 
Thanks for the replay ceewi1

it is the second scan log. in the first time, in the middle of the scan windows showed a black screen, I had to reset and scan again. this is the second scan log.

some logs were TOO long, I had to split all in like 5-6 posts. So I uploaded them somewhere.


The Dr. Web CureIt log

MOVEIT3 log

combofix log

hijackthis log


btw, after dr web first scan, my windows come up fine and I don't have to close explorer and restart it again.
and dr web found like thousands of files infected with its first scan, I was shocked to see it.
 
Last edited:
I just edited my post ^^

btw, I downloaded combofix again, and when i run it, it said it has been expired.
I thought there was something wrong. So I run "combofix /u". and I downloaded again combofix. but again it told me it is expired, so I run it anyway with its "reduced functionality" .
 
Well, it will be tonight again before the mod gets online to finish helping you. Please be patient as it might take a couple days to get everything fixed.
 
Back
Top