Jump to content


 


Register a free account to unlock additional features at BleepingComputer.com
Welcome to BleepingComputer, a free community where people like yourself come together to discuss and learn how to use their computers. Using the site is easy and fun. As a guest, you can browse and view the various discussions in the forums, but can not create a new topic or reply to an existing one unless you are logged in. Other benefits of registering an account are subscribing to topics and forums, creating a blog, and having no ads shown anywhere on the site.


Click here to Register a free account now! or read our Welcome Guide to learn how to use this site.

Photo

New Year, New Infection! Help... Hijack Log Attached


  • This topic is locked This topic is locked
16 replies to this topic

#1 strobie

strobie

  • Members
  • 9 posts
  • OFFLINE
  •  
  • Local time:10:12 AM

Posted 03 January 2007 - 02:03 AM

i got a trojan/virus and several attempts with anti-virus software/cleaners still didn't do too much, which leads me back to good ol' tom coyote!

any help would be appreciated, thanks in advance... here's the log:


Logfile of HijackThis v1.99.1
Scan saved at 12:19:08 PM, on 03/01/2007
Platform: Windows XP SP1 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\csrss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\System32\alg.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 6.0\avp.exe
C:\Program Files\Dell\Bluetooth Software\bin\btwdins.exe
C:\Program Files\ewido anti-malware\ewidoctrl.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\WINDOWS\system32\nvsvc32.exe
C:\WINDOWS\System32\wltrysvc.exe
C:\WINDOWS\System32\bcmwltry.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\System32\ctfmon.exe
C:\Program Files\Apoint\Apoint.exe
C:\WINDOWS\System32\BacsTray.exe
C:\Program Files\Dell\QuickSet\quickset.exe
C:\Program Files\Java\jre1.5.0_09\bin\jusched.exe
C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 6.0\avp.exe
C:\Program Files\Apoint\Apntex.exe
C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
C:\Program Files\Digital Line Detect\DLG.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Documents and Settings\Peter C\My Documents\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.dell.com
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page =
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page =
O1 - Hosts: 222.208.183.175 www.kirinkwy.com.cn
O1 - Hosts: 222.208.183.175 kirinkwy.com.cn
O1 - Hosts: 222.208.183.175 www.7282214.cn
O1 - Hosts: 222.208.183.175 www.wg77169.cn
O1 - Hosts: 222.208.183.175 www.233049.com
O1 - Hosts: 222.208.183.175 sou.m369m.com
O1 - Hosts: 222.208.183.175 www.79793.com
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: DriveLetterAccess - {5CA3D70E-1895-11CF-8E15-001234567890} - C:\WINDOWS\system32\dla\tfswshx.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_09\bin\ssv.dll
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [Apoint] C:\Program Files\Apoint\Apoint.exe
O4 - HKLM\..\Run: [bacstray] BacsTray.exe
O4 - HKLM\..\Run: [Dell QuickSet] C:\Program Files\Dell\QuickSet\quickset.exe
O4 - HKLM\..\Run: [IMJPMIG8.1] "C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE" /Spoil /RemAdvDef /Migration32
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.5.0_09\bin\jusched.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [mhs2] C:\DOCUME~1\PETERC~2\LOCALS~1\Temp\mhs2.exe
O4 - HKLM\..\Run: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k
O4 - HKLM\..\Run: [AVP] "C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 6.0\avp.exe"
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\System32\ctfmon.exe
O4 - HKCU\..\Run: [myZt2] C:\DOCUME~1\PETERC~1\LOCALS~1\Temp\Zt2\SVCH0ST.EXE
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O4 - Global Startup: Digital Line Detect.lnk = ?
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_09\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_09\bin\ssv.dll
O9 - Extra button: Web Anti-Virus - {1F460357-8A94-4D71-9CA3-AA4ACF32ED8E} - C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 6.0\scieplugin.dll
O16 - DPF: {0E5F0222-96B9-11D3-8997-00104BD12D94} (PCPitstop Utility) - http://www.pcpitstop.com/pcpitstop/PCPitStop.CAB
O16 - DPF: {14B87622-7E19-4EA8-93B3-97215F77A6BC} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/Messe...nt.cab30149.cab
O16 - DPF: {193C772A-87BE-4B19-A7BB-445B226FE9A1} (ewidoOnlineScan Control) - http://download.ewido.net/ewidoOnlineScan.cab
O16 - DPF: {2917297F-F02B-4B9D-81DF-494B6333150B} (Minesweeper Flags Class) - http://messenger.zone.msn.com/binary/MineS...er.cab30149.cab
O16 - DPF: {2B323CD9-50E3-11D3-9466-00A0C9700498} (Yahoo! Audio Conferencing) - http://us.chat1.yimg.com/us.yimg.com/i/cha...v45/yacscom.cab
O16 - DPF: {5D86DDB5-BDF9-441B-9E9E-D4730F4EE499} (BDSCANONLINE Control) - http://www.bitdefender.com/scan8/oscan8.cab
O16 - DPF: {5E943D9C-F8DC-4258-8E3F-A61BB3405A33} (ZingBatchAXDwnl Class) - http://www.imagestation.com/common/classes...ion=4,3,2,20802
O16 - DPF: {6BEA1C48-1850-486C-8F58-C7354BA3165E} (Install Class) - http://updates.lifescapeinc.com/installers...ll/pinstall.cab
O16 - DPF: {74D05D43-3236-11D4-BDCD-00C04F9A3B61} (HouseCall Control) - http://a840.g.akamai.net/7/840/537/2004061...all/xscan53.cab
O16 - DPF: {7B297BFD-85E4-4092-B2AF-16A91B2EA103} (WScanCtl Class) - http://www3.ca.com/securityadvisor/virusinfo/webscan.cab
O16 - DPF: {7D1E9C49-BD6A-11D3-87A8-009027A35D73} (Yahoo! Audio UI1) - http://chat.yahoo.com/cab/yacsui.cab
O16 - DPF: {8E0D4DE5-3180-4024-A327-4DFAD1796A8D} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/Messe...nt.cab28578.cab
O16 - DPF: {B38870E4-7ECB-40DA-8C6A-595F0A5519FF} (MsnMessengerSetupDownloadControl Class) - http://messenger.msn.com/download/MsnMesse...pDownloader.cab
O16 - DPF: {B817734E-046C-11D3-B674-00104BA25195} - http://pmb001.3m.com/pub/psnotes/psnudate.cab
O16 - DPF: {B8BE5E93-A60C-4D26-A2DC-220313175592} (ZoneIntro Class) - http://zone.msn.com/binFramework/v10/ZIntro.cab34246.cab
O16 - DPF: {BA2D9665-D672-446F-98F4-E3E41FA12A01} (PCAObj Class) - http://www.mypccenter.com/PCA.cab
O16 - DPF: {BD393C14-72AD-4790-A095-76522973D6B8} (CBreakshotControl Class) - http://messenger.zone.msn.com/binary/Bankshot.cab30149.cab
O16 - DPF: {E154E3CC-0C3A-4101-91D8-6B4876F0FD64} (PrintScreen Class) - http://www.myemo.com/my_picture/Flash2Image.cab
O16 - DPF: {E9A7F56F-C40F-4928-8C6F-7A72F2A25222} (AxRUploadControl Object) - http://www.imagestation.com/common/classes....cab?v=1,0,0,32
O16 - DPF: {F6BF0D00-0B2A-4A75-BF7B-F385591623AF} (Solitaire Showdown Class) - http://messenger.zone.msn.com/binary/Solit...wn.cab30149.cab
O20 - AppInit_DLLs: MsgPlusLoader.dll
O20 - Winlogon Notify: klogon - C:\WINDOWS\System32\klogon.dll
O23 - Service: AVG Anti-Spyware Guard - Anti-Malware Development a.s. - C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
O23 - Service: Kaspersky Anti-Virus 6.0 (AVP) - Kaspersky Lab - C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 6.0\avp.exe
O23 - Service: Bluetooth Service (btwdins) - Unknown owner - C:\Program Files\Dell\Bluetooth Software\bin\btwdins.exe
O23 - Service: ewido security suite control - ewido networks - C:\Program Files\ewido anti-malware\ewidoctrl.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: WLTRYSVC - Unknown owner - C:\WINDOWS\System32\wltrysvc.exe

BC AdBot (Login to Remove)

 


#2 Daemon

Daemon

    Security Expert


  • Members
  • 1,446 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:UK
  • Local time:01:12 AM

Posted 03 January 2007 - 02:56 AM

Could you uninstall ewido as it has now been replaced by AVG Antispyware.

Then do this - download SUPERAntiSpyware Home Edition (free version)
  • Install it and double-click the icon on your desktop to run it.
  • It will ask if you want to update the program definitions, click Yes.
  • Under Configuration and Preferences, click the Preferences button.
  • Click the Scanning Control tab.
  • Under Scanner Options make sure the following are checked:
    • Close browsers before scanning
    • Scan for tracking cookies
    • Terminate memory threats before quarantining.
    • Please leave the others unchecked.
    • Click the Close button to leave the control center screen.
  • On the main screen, under Scan for Harmful Software click Scan your computer.
  • On the left check C:\Fixed Drive.
  • On the right, under Complete Scan, choose Perform Complete Scan.
  • Click Next to start the scan. Please be patient while it scans your computer.
  • After the scan is complete a summary box will appear. Click OK.
  • Make sure everything in the white box has a check next to it, then click Next.
  • It will quarantine what it found and if it asks if you want to reboot, click Yes.
  • To retrieve the removal information for me please do the following:
    • After reboot, double-click the SUPERAntispyware icon on your desktop.
    • Click Preferences. Click the Statistics/Logs tab.
    • Under Scanner Logs, double-click SUPERAntiSpyware Scan Log.
    • It will open in your default text editor (such as Notepad/Wordpad).
    • Please highlight everything in the notepad, then right-click and choose copy.
  • Click close and close again to exit the program.
  • Please paste that information here for me with a new HijackThis log.

Edited by Daemon, 03 January 2007 - 02:58 AM.

Posted Image

Have I helped you? Please consider donating to help me continue with the fight against malware. Click here

#3 strobie

strobie
  • Topic Starter

  • Members
  • 9 posts
  • OFFLINE
  •  
  • Local time:10:12 AM

Posted 03 January 2007 - 03:12 AM

---------------------------------------------------------
AVG Anti-Spyware - Scan Report
---------------------------------------------------------

+ Created at: 12:47:28 AM 03/01/2007

+ Scan result:



Nothing found.



::Report end


Now doing the SUPERAntiSpyware...

#4 Daemon

Daemon

    Security Expert


  • Members
  • 1,446 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:UK
  • Local time:01:12 AM

Posted 03 January 2007 - 03:18 AM

Do you recognise the sites/IP in your O1 entries?
Posted Image

Have I helped you? Please consider donating to help me continue with the fight against malware. Click here

#5 strobie

strobie
  • Topic Starter

  • Members
  • 9 posts
  • OFFLINE
  •  
  • Local time:10:12 AM

Posted 03 January 2007 - 04:35 AM

Negatory. Never seen em before.

SUPERAntiSpyware still running...

#6 strobie

strobie
  • Topic Starter

  • Members
  • 9 posts
  • OFFLINE
  •  
  • Local time:10:12 AM

Posted 03 January 2007 - 11:37 AM

First off, thanks again for your gracious help! Here (after 7 hours...) is the SUPERAnti Log:

SUPERAntiSpyware Scan Log
Generated 01/04/2007 at 00:00 AM

Application Version : 3.4.1000

Core Rules Database Version : 3158
Trace Rules Database Version: 1171

Scan type : Complete Scan
Total Scan Time : 06:45:47

Memory items scanned : 417
Memory threats detected : 0
Registry items scanned : 6896
Registry threats detected : 1
File items scanned : 58952
File threats detected : 30

Bogus MS SVCHOST.EXE
[myZt2] C:\DOCUME~1\PETERC~1\LOCALS~1\Temp\Zt2\SVCH0ST.EXE
C:\DOCUME~1\PETERC~1\LOCALS~1\Temp\Zt2\SVCH0ST.EXE

Adware.Tracking Cookie
C:\Documents and Settings\Peter C\Cookies\peter c@ads.tbs[1].txt
C:\Documents and Settings\Peter C\Cookies\peter c@xtendmedia[1].txt
C:\Documents and Settings\Peter C\Cookies\peter c@toplist[1].txt
C:\Documents and Settings\Peter C\Cookies\peter c@adultadworld[1].txt
C:\Documents and Settings\Peter C\Cookies\peter c@clicktorrent[2].txt
C:\Documents and Settings\Peter C\Cookies\peter c@ad.yieldmanager[2].txt
C:\Documents and Settings\Peter C\Cookies\peter c@rotator.adjuggler[2].txt
C:\Documents and Settings\Peter C\Cookies\peter c@adbrite[2].txt
C:\Documents and Settings\Peter C\Cookies\peter c@adecn[2].txt
C:\Documents and Settings\Peter C\Cookies\peter c@ad2.adecn[1].txt
C:\Documents and Settings\Peter C\Cookies\peter c@ipstat[2].txt
C:\Documents and Settings\Peter C\Cookies\peter c@1072722497[1].txt
C:\Documents and Settings\Peter C\Cookies\peter c@www.banneradmin.rai[2].txt
C:\Documents and Settings\Peter C\Cookies\peter c@kanoodle[1].txt
C:\Documents and Settings\Peter C\Cookies\peter c@ad1.emediate[2].txt
C:\Documents and Settings\Peter C\Cookies\peter c@www.burstnet[2].txt
C:\Documents and Settings\Peter C\Cookies\peter c@www.jackpotmadness[1].txt
C:\Documents and Settings\Peter C\Cookies\peter c@ads.mixi[1].txt
C:\Documents and Settings\Peter C\Cookies\peter c@1063922152[1].txt
C:\Documents and Settings\Peter C\Cookies\peter c@burstnet[2].txt
C:\Documents and Settings\Peter C\Cookies\peter c@revsci[2].txt
C:\Documents and Settings\Peter C\Cookies\peter c@hit.stat[1].txt
C:\Documents and Settings\Peter C\Cookies\peter c@drivecleaner[1].txt
C:\Documents and Settings\Administrator.PETER.000\Cookies\administrator@adbrite[2].txt
C:\Documents and Settings\Administrator.PETER.000\Cookies\administrator@burstnet[2].txt
C:\Documents and Settings\Administrator.PETER.000\Cookies\administrator@gostats[2].txt
C:\Documents and Settings\Administrator.PETER.000\Cookies\administrator@tacoda[1].txt
C:\Documents and Settings\Administrator.PETER.000\Cookies\administrator@toplist[1].txt
C:\Documents and Settings\Administrator.PETER.000\Cookies\administrator@www.burstnet[2].txt





and the new HIJACK LOG:
(Also, my anti-virus program is still picking up the Net-Worm.Win32.Allaple.b virus attached to many files.)



Logfile of HijackThis v1.99.1
Scan saved at 1:39:54 AM, on 04/01/2007
Platform: Windows XP SP1 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 6.0\avp.exe
C:\Program Files\Dell\Bluetooth Software\bin\btwdins.exe
C:\Program Files\ewido anti-malware\ewidoctrl.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\WINDOWS\system32\nvsvc32.exe
C:\WINDOWS\System32\wltrysvc.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\System32\bcmwltry.exe
C:\WINDOWS\System32\ctfmon.exe
C:\Program Files\Apoint\Apoint.exe
C:\WINDOWS\System32\BacsTray.exe
C:\Program Files\Dell\QuickSet\quickset.exe
C:\Program Files\Java\jre1.5.0_09\bin\jusched.exe
C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 6.0\avp.exe
C:\Program Files\Apoint\Apntex.exe
C:\Program Files\Digital Line Detect\DLG.exe
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\Documents and Settings\Peter C\My Documents\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.dell.com
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page =
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page =
O1 - Hosts: 222.208.183.175 www.kirinkwy.com.cn
O1 - Hosts: 222.208.183.175 kirinkwy.com.cn
O1 - Hosts: 222.208.183.175 www.7282214.cn
O1 - Hosts: 222.208.183.175 www.wg77169.cn
O1 - Hosts: 222.208.183.175 www.233049.com
O1 - Hosts: 222.208.183.175 sou.m369m.com
O1 - Hosts: 222.208.183.175 www.79793.com
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: DriveLetterAccess - {5CA3D70E-1895-11CF-8E15-001234567890} - C:\WINDOWS\system32\dla\tfswshx.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_09\bin\ssv.dll
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [Apoint] C:\Program Files\Apoint\Apoint.exe
O4 - HKLM\..\Run: [bacstray] BacsTray.exe
O4 - HKLM\..\Run: [Dell QuickSet] C:\Program Files\Dell\QuickSet\quickset.exe
O4 - HKLM\..\Run: [IMJPMIG8.1] "C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE" /Spoil /RemAdvDef /Migration32
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.5.0_09\bin\jusched.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [mhs2] C:\DOCUME~1\PETERC~2\LOCALS~1\Temp\mhs2.exe
O4 - HKLM\..\Run: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k
O4 - HKLM\..\Run: [AVP] "C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 6.0\avp.exe"
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\System32\ctfmon.exe
O4 - HKCU\..\Run: [SUPERAntiSpyware] C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O4 - Global Startup: Digital Line Detect.lnk = ?
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_09\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_09\bin\ssv.dll
O9 - Extra button: Web Anti-Virus - {1F460357-8A94-4D71-9CA3-AA4ACF32ED8E} - C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 6.0\scieplugin.dll
O16 - DPF: {0E5F0222-96B9-11D3-8997-00104BD12D94} (PCPitstop Utility) - http://www.pcpitstop.com/pcpitstop/PCPitStop.CAB
O16 - DPF: {14B87622-7E19-4EA8-93B3-97215F77A6BC} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/Messe...nt.cab30149.cab
O16 - DPF: {193C772A-87BE-4B19-A7BB-445B226FE9A1} (ewidoOnlineScan Control) - http://download.ewido.net/ewidoOnlineScan.cab
O16 - DPF: {2917297F-F02B-4B9D-81DF-494B6333150B} (Minesweeper Flags Class) - http://messenger.zone.msn.com/binary/MineS...er.cab30149.cab
O16 - DPF: {2B323CD9-50E3-11D3-9466-00A0C9700498} (Yahoo! Audio Conferencing) - http://us.chat1.yimg.com/us.yimg.com/i/cha...v45/yacscom.cab
O16 - DPF: {5D86DDB5-BDF9-441B-9E9E-D4730F4EE499} (BDSCANONLINE Control) - http://www.bitdefender.com/scan8/oscan8.cab
O16 - DPF: {5E943D9C-F8DC-4258-8E3F-A61BB3405A33} (ZingBatchAXDwnl Class) - http://www.imagestation.com/common/classes...ion=4,3,2,20802
O16 - DPF: {6BEA1C48-1850-486C-8F58-C7354BA3165E} (Install Class) - http://updates.lifescapeinc.com/installers...ll/pinstall.cab
O16 - DPF: {74D05D43-3236-11D4-BDCD-00C04F9A3B61} (HouseCall Control) - http://a840.g.akamai.net/7/840/537/2004061...all/xscan53.cab
O16 - DPF: {7B297BFD-85E4-4092-B2AF-16A91B2EA103} (WScanCtl Class) - http://www3.ca.com/securityadvisor/virusinfo/webscan.cab
O16 - DPF: {7D1E9C49-BD6A-11D3-87A8-009027A35D73} (Yahoo! Audio UI1) - http://chat.yahoo.com/cab/yacsui.cab
O16 - DPF: {8E0D4DE5-3180-4024-A327-4DFAD1796A8D} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/Messe...nt.cab28578.cab
O16 - DPF: {B38870E4-7ECB-40DA-8C6A-595F0A5519FF} (MsnMessengerSetupDownloadControl Class) - http://messenger.msn.com/download/MsnMesse...pDownloader.cab
O16 - DPF: {B817734E-046C-11D3-B674-00104BA25195} - http://pmb001.3m.com/pub/psnotes/psnudate.cab
O16 - DPF: {B8BE5E93-A60C-4D26-A2DC-220313175592} (ZoneIntro Class) - http://zone.msn.com/binFramework/v10/ZIntro.cab34246.cab
O16 - DPF: {BA2D9665-D672-446F-98F4-E3E41FA12A01} (PCAObj Class) - http://www.mypccenter.com/PCA.cab
O16 - DPF: {BD393C14-72AD-4790-A095-76522973D6B8} (CBreakshotControl Class) - http://messenger.zone.msn.com/binary/Bankshot.cab30149.cab
O16 - DPF: {E154E3CC-0C3A-4101-91D8-6B4876F0FD64} (PrintScreen Class) - http://www.myemo.com/my_picture/Flash2Image.cab
O16 - DPF: {E9A7F56F-C40F-4928-8C6F-7A72F2A25222} (AxRUploadControl Object) - http://www.imagestation.com/common/classes....cab?v=1,0,0,32
O16 - DPF: {F6BF0D00-0B2A-4A75-BF7B-F385591623AF} (Solitaire Showdown Class) - http://messenger.zone.msn.com/binary/Solit...wn.cab30149.cab
O20 - AppInit_DLLs: MsgPlusLoader.dll
O20 - Winlogon Notify: !SASWinLogon - C:\Program Files\SUPERAntiSpyware\SASWINLO.dll
O20 - Winlogon Notify: klogon - C:\WINDOWS\System32\klogon.dll
O23 - Service: AVG Anti-Spyware Guard - Anti-Malware Development a.s. - C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
O23 - Service: Kaspersky Anti-Virus 6.0 (AVP) - Kaspersky Lab - C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 6.0\avp.exe
O23 - Service: Bluetooth Service (btwdins) - Unknown owner - C:\Program Files\Dell\Bluetooth Software\bin\btwdins.exe
O23 - Service: ewido security suite control - ewido networks - C:\Program Files\ewido anti-malware\ewidoctrl.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: WLTRYSVC - Unknown owner - C:\WINDOWS\System32\wltrysvc.exe

#7 Daemon

Daemon

    Security Expert


  • Members
  • 1,446 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:UK
  • Local time:01:12 AM

Posted 03 January 2007 - 02:46 PM

Click here to download the Hoster. Extract it from the zip file into a folder and doubleclick on hoster.exe. Press "Restore Original Hosts" and press "OK". Exit the program.

Can you post a log from your antivirus?
Posted Image

Have I helped you? Please consider donating to help me continue with the fight against malware. Click here

#8 strobie

strobie
  • Topic Starter

  • Members
  • 9 posts
  • OFFLINE
  •  
  • Local time:10:12 AM

Posted 03 January 2007 - 11:50 PM

Ok I did that host thing, I thought those hosts/IP addresses looked kind of alien to me. I did a google of those servers and they only showed up on malware sites.

The Kapersky log file is quite huge... over 12.4 MB(!) in notepad. There were more than 2500 infections and scanning is not finished yet. I can't seem to get rid of the invader and the allaple.b one. Here is the file, as much as I can fit into this reply box.... thanks! :thumbsup:







Scan My Computer
----------------
Scanned: 111226
Detected: 1657
Untreated: 0
Start time: 04/01/2007 5:13:55 AM
Duration: 03:20:19
Finish time: 04/01/2007 8:34:14 AM


Detected
--------
Status Object
------ ------
disinfected: virus Net-Worm.Win32.Allaple.a File: C:\Program Files\Microsoft Office\OFFICE11\HTML\context.html
deleted: virus Net-Worm.Win32.Allaple.b File: C:\Program Files\Microsoft Office\OFFICE11\HTML\lklnereh.exe
deleted: virus Net-Worm.Win32.Allaple.b File: C:\Program Files\Microsoft Office\OFFICE11\VS Runtime\1033\brnrkzjt.exe
disinfected: virus Net-Worm.Win32.Allaple.a File: C:\Program Files\Microsoft Office\OFFICE11\VS Runtime\1033\EMPTY.HTM
disinfected: virus Net-Worm.Win32.Allaple.a File: C:\Program Files\Microsoft Office\OFFICE11\VS Runtime\1033\HelpWatermark.htm
deleted: virus Net-Worm.Win32.Allaple.b File: C:\Program Files\Microsoft Office\OFFICE11\VS Runtime\1033\vbxbwqre.exe
deleted: virus Net-Worm.Win32.Allaple.b File: C:\Program Files\Microsoft Office\Stationery\1033\bkvqxrrt.exe
deleted: virus Net-Worm.Win32.Allaple.b File: C:\Program Files\Microsoft Office\Stationery\1033\blbsrqzv.exe
disinfected: virus Net-Worm.Win32.Allaple.a File: C:\Program Files\Microsoft Office\Stationery\1033\CURRENCY.HTM
disinfected: virus Net-Worm.Win32.Allaple.a File: C:\Program Files\Microsoft Office\Stationery\1033\DADSHIRT.HTM
deleted: virus Net-Worm.Win32.Allaple.b File: C:\Program Files\Microsoft Office\Stationery\1033\henzzblz.exe
deleted: virus Net-Worm.Win32.Allaple.b File: C:\Program Files\Microsoft Office\Stationery\1033\hlrkkkeb.exe
disinfected: virus Net-Worm.Win32.Allaple.a File: C:\Program Files\Microsoft Office\Stationery\1033\JUDGESCH.HTM
disinfected: virus Net-Worm.Win32.Allaple.a File: C:\Program Files\Microsoft Office\Stationery\1033\JUNGLE.HTM
deleted: virus Net-Worm.Win32.Allaple.b File: C:\Program Files\Microsoft Office\Stationery\1033\klstcbss.exe
deleted: virus Net-Worm.Win32.Allaple.b File: C:\Program Files\Microsoft Office\Stationery\1033\lektkhtx.exe
deleted: virus Net-Worm.Win32.Allaple.b File: C:\Program Files\Microsoft Office\Stationery\1033\nkjbekrr.exe
disinfected: virus Net-Worm.Win32.Allaple.a File: C:\Program Files\Microsoft Office\Stationery\1033\NOTEBOOK.HTM
disinfected: virus Net-Worm.Win32.Allaple.a File: C:\Program Files\Microsoft Office\Stationery\1033\OFFISUPP.HTM
disinfected: virus Net-Worm.Win32.Allaple.a File: C:\Program Files\Microsoft Office\Stationery\1033\PAWPRINT.HTM
disinfected: virus Net-Worm.Win32.Allaple.a File: C:\Program Files\Microsoft Office\Stationery\1033\PINELUMB.HTM
disinfected: virus Net-Worm.Win32.Allaple.a File: C:\Program Files\Microsoft Office\Stationery\1033\SEAMARBL.HTM
disinfected: virus Net-Worm.Win32.Allaple.a File: C:\Program Files\Microsoft Office\Stationery\1033\TECHTOOL.HTM
deleted: virus Net-Worm.Win32.Allaple.b File: C:\Program Files\Microsoft Office\Stationery\1033\tlqbtbvz.exe
deleted: virus Net-Worm.Win32.Allaple.b File: C:\Program Files\Microsoft Office\Stationery\1033\tnckxcvt.exe
deleted: virus Net-Worm.Win32.Allaple.b File: C:\Program Files\Microsoft Office\Stationery\1033\wrejrjns.exe
disinfected: virus Net-Worm.Win32.Allaple.a File: C:\Program Files\Microsoft Office\Templates\MseNewFileItems\HTMLPAGE.HTM
deleted: virus Net-Worm.Win32.Allaple.b File: C:\Program Files\Microsoft Office\Templates\MseNewFileItems\qntnktlz.exe
disinfected: virus Net-Worm.Win32.Allaple.a File: C:\Program Files\Modem Helper\Default.htm
deleted: virus Net-Worm.Win32.Allaple.b File: C:\Program Files\Modem Helper\lherjkjq.exe
deleted: virus Net-Worm.Win32.Allaple.b File: C:\Program Files\Modem Helper\rxthtzec.exe
disinfected: virus Net-Worm.Win32.Allaple.a File: C:\Program Files\Modem Helper\Template.htm
deleted: virus Net-Worm.Win32.Allaple.b File: C:\Program Files\MSN\MSNCoreFiles\hkbkkvrn.exe
disinfected: virus Net-Worm.Win32.Allaple.a File: C:\Program Files\MSN\MSNCoreFiles\MSNREAD.HTM
disinfected: virus Net-Worm.Win32.Allaple.a File: C:\Program Files\NetMeeting\netmeet.htm
deleted: virus Net-Worm.Win32.Allaple.b File: C:\Program Files\NetMeeting\rsewzjqn.exe
deleted: virus Net-Worm.Win32.Allaple.b File: C:\Program Files\QuickTime\zhhwxjkh.exe
deleted: virus Net-Worm.Win32.Allaple.b File: C:\Program Files\ReadWrite Hiragana\ksnckrlr.exe
disinfected: virus Net-Worm.Win32.Allaple.a File: C:\Program Files\ReadWrite Hiragana\registration.htm
deleted: virus Net-Worm.Win32.Allaple.b File: C:\Program Files\ReadWrite Kanji\hwnrkslb.exe
disinfected: virus Net-Worm.Win32.Allaple.a File: C:\Program Files\ReadWrite Kanji\registration.htm
disinfected: virus Net-Worm.Win32.Allaple.a File: C:\Program Files\ReadWrite Kanji\help\help.htm
deleted: virus Net-Worm.Win32.Allaple.b File: C:\Program Files\ReadWrite Kanji\help\jkjhstsr.exe
deleted: virus Net-Worm.Win32.Allaple.b File: C:\Program Files\ReadWrite Kanji\help\nwjbkzlr.exe
deleted: virus Net-Worm.Win32.Allaple.b File: C:\Program Files\ReadWrite Kanji\help\szezsrsz.exe
deleted: virus Net-Worm.Win32.Allaple.b File: C:\Program Files\Real\RealOne Player\btettlts.exe
disinfected: virus Net-Worm.Win32.Allaple.a File: C:\Program Files\Real\RealOne Player\playrlic.html
deleted: virus Net-Worm.Win32.Allaple.b File: C:\Program Files\Real\RealOne Player\qvnvlhwb.exe
disinfected: virus Net-Worm.Win32.Allaple.a File: C:\Program Files\Real\RealOne Player\RealNetworks License.html
deleted: virus Net-Worm.Win32.Allaple.b File: C:\Program Files\Real\RealOne Player\tzzvhrrb.exe
deleted: virus Net-Worm.Win32.Allaple.b File: C:\Program Files\Real\RealOne Player\DataCache\Devices\jxrhchhh.exe
deleted: virus Net-Worm.Win32.Allaple.b File: C:\Program Files\Real\RealOne Player\DataCache\Devices\zebslxjl.exe
deleted: virus Net-Worm.Win32.Allaple.b File: C:\Program Files\Real\RealOne Player\DataCache\GetMedia\bhklrsqx.exe
deleted: virus Net-Worm.Win32.Allaple.b File: C:\Program Files\Real\RealOne Player\DataCache\GetMedia\bjvkhbwt.exe
deleted: virus Net-Worm.Win32.Allaple.b File: C:\Program Files\Real\RealOne Player\DataCache\GetMedia\hljbrsrl.exe
deleted: virus Net-Worm.Win32.Allaple.b File: C:\Program Files\Real\RealOne Player\DataCache\GetMedia\jtrklntt.exe
deleted: virus Net-Worm.Win32.Allaple.b File: C:\Program Files\Real\RealOne Player\DataCache\GetMedia\lzjcssze.exe
deleted: virus Net-Worm.Win32.Allaple.b File: C:\Program Files\Real\RealOne Player\DataCache\GetMedia\scvteeql.exe
disinfected: virus Net-Worm.Win32.Allaple.a File: C:\Program Files\Real\RealOne Player\DataCache\GetMedia\upsell.htm
deleted: virus Net-Worm.Win32.Allaple.b File: C:\Program Files\Real\RealOne Player\DataCache\GetMedia\vhqktkzj.exe
deleted: virus Net-Worm.Win32.Allaple.b File: C:\Program Files\Real\RealOne Player\DataCache\GetMedia\zqescejh.exe
deleted: virus Net-Worm.Win32.Allaple.b File: C:\Program Files\Real\RealOne Player\DataCache\Login\nretlqrn.exe
deleted: virus Net-Worm.Win32.Allaple.b File: C:\Program Files\Real\RealOne Player\DataCache\Login\rekebrlb.exe
deleted: virus Net-Worm.Win32.Allaple.b File: C:\Program Files\Real\RealOne Player\DataCache\Login\swhxcqqj.exe
disinfected: virus Net-Worm.Win32.Allaple.a File: C:\Program Files\Real\RealOne Player\DataCache\Login\welcome.html
deleted: virus Net-Worm.Win32.Allaple.b File: C:\Program Files\Real\RealOne Player\Firstrun\celbttkj.exe
deleted: virus Net-Worm.Win32.Allaple.b File: C:\Program Files\Real\RealOne Player\Firstrun\kksztbsc.exe
deleted: virus Net-Worm.Win32.Allaple.b File: C:\Program Files\Real\RealOne Player\Firstrun\kqjbchtk.exe
deleted: virus Net-Worm.Win32.Allaple.b File: C:\Program Files\Smith Micro\StuffIt\StartStandard\stnvnlch.exe
deleted: virus Net-Worm.Win32.Allaple.b File: C:\Program Files\Sonic\MyDVD\Documentation\ReadMe\ENGLISH\txxcnekx.exe
deleted: virus Net-Worm.Win32.Allaple.b File: C:\Program Files\Sonic\MyDVD\Documentation\ReadMe\JAPANESE\chjsbvsv.exe
deleted: virus Net-Worm.Win32.Allaple.b File: C:\Program Files\Sonic\MyDVD\SonicResources\kjhsjrvj.exe
deleted: virus Net-Worm.Win32.Allaple.b File: C:\Program Files\Sonic\MyDVD\Tutorial\Chinese(S)\bblzqerb.exe
deleted: virus Net-Worm.Win32.Allaple.b File: C:\Program Files\Sonic\MyDVD\Tutorial\Chinese(S)\blcjssbs.exe
deleted: virus Net-Worm.Win32.Allaple.b File: C:\Program Files\Sonic\MyDVD\Tutorial\Chinese(S)\eeeetlcb.exe
deleted: virus Net-Worm.Win32.Allaple.b File: C:\Program Files\Sonic\MyDVD\Tutorial\Chinese(S)\enqshxbx.exe
deleted: virus Net-Worm.Win32.Allaple.b File: C:\Program Files\Sonic\MyDVD\Tutorial\Chinese(S)\ernjkbls.exe
deleted: virus Net-Worm.Win32.Allaple.b File: C:\Program Files\Sonic\MyDVD\Tutorial\Chinese(S)\hjljlerr.exe
deleted: virus Net-Worm.Win32.Allaple.b File: C:\Program Files\Sonic\MyDVD\Tutorial\Chinese(S)\hrkhhlxk.exe
deleted: virus Net-Worm.Win32.Allaple.b File: C:\Program Files\Sonic\MyDVD\Tutorial\Chinese(S)\jelbwlns.exe
deleted: virus Net-Worm.Win32.Allaple.b File: C:\Program Files\Sonic\MyDVD\Tutorial\Chinese(S)\kbtqqcrj.exe
deleted: virus Net-Worm.Win32.Allaple.b File: C:\Program Files\Sonic\MyDVD\Tutorial\Chinese(S)\kebecnnx.exe
deleted: virus Net-Worm.Win32.Allaple.b File: C:\Program Files\Sonic\MyDVD\Tutorial\Chinese(S)\khzwsznj.exe
deleted: virus Net-Worm.Win32.Allaple.b File: C:\Program Files\Sonic\MyDVD\Tutorial\Chinese(S)\kkjxsnbx.exe
deleted: virus Net-Worm.Win32.Allaple.b File: C:\Program Files\Sonic\MyDVD\Tutorial\Chinese(S)\ksktrrxs.exe
deleted: virus Net-Worm.Win32.Allaple.b File: C:\Program Files\Sonic\MyDVD\Tutorial\Chinese(S)\lsvrhvtj.exe
deleted: virus Net-Worm.Win32.Allaple.b File: C:\Program Files\Sonic\MyDVD\Tutorial\Chinese(S)\njhbrxtb.exe
deleted: virus Net-Worm.Win32.Allaple.b File: C:\Program Files\Sonic\MyDVD\Tutorial\Chinese(S)\nrllnlvr.exe
deleted: virus Net-Worm.Win32.Allaple.b File: C:\Program Files\Sonic\MyDVD\Tutorial\Chinese(S)\rbtlkksl.exe
deleted: virus Net-Worm.Win32.Allaple.b File: C:\Program Files\Sonic\MyDVD\Tutorial\Chinese(S)\reznbtbn.exe
deleted: virus Net-Worm.Win32.Allaple.b File: C:\Program Files\Sonic\MyDVD\Tutorial\Chinese(S)\rhkcxtct.exe
deleted: virus Net-Worm.Win32.Allaple.b File: C:\Program Files\Sonic\MyDVD\Tutorial\Chinese(S)\rljeexse.exe
deleted: virus Net-Worm.Win32.Allaple.b File: C:\Program Files\Sonic\MyDVD\Tutorial\Chinese(S)\tjsvrese.exe
deleted: virus Net-Worm.Win32.Allaple.b File: C:\Program Files\Sonic\MyDVD\Tutorial\Chinese(S)\tnxtqrwv.exe
deleted: virus Net-Worm.Win32.Allaple.b File: C:\Program Files\Sonic\MyDVD\Tutorial\Chinese(S)\txthwnzq.exe
deleted: virus Net-Worm.Win32.Allaple.b File: C:\Program Files\Sonic\MyDVD\Tutorial\Chinese(S)\wbqhnvqb.exe
deleted: virus Net-Worm.Win32.Allaple.b File: C:\Program Files\Sonic\MyDVD\Tutorial\Chinese(S)\wenlkeet.exe
deleted: virus Net-Worm.Win32.Allaple.b File: C:\Program Files\Sonic\MyDVD\Tutorial\Chinese(S)\zrebjlrn.exe
deleted: virus Net-Worm.Win32.Allaple.b File: C:\Program Files\Sonic\MyDVD\Tutorial\Chinese(T)\ctkrrhks.exe
deleted: virus Net-Worm.Win32.Allaple.b File: C:\Program Files\Sonic\MyDVD\Tutorial\Chinese(T)\ebtksrjb.exe
deleted: virus Net-Worm.Win32.Allaple.b File: C:\Program Files\Sonic\MyDVD\Tutorial\Chinese(T)\ecxlhzbx.exe
deleted: virus Net-Worm.Win32.Allaple.b File: C:\Program Files\Sonic\MyDVD\Tutorial\Chinese(T)\elxqnssn.exe
deleted: virus Net-Worm.Win32.Allaple.b File: C:\Program Files\Sonic\MyDVD\Tutorial\Chinese(T)\ernhqtet.exe
deleted: virus Net-Worm.Win32.Allaple.b File: C:\Program Files\Sonic\MyDVD\Tutorial\Chinese(T)\erzbxbqb.exe
deleted: virus Net-Worm.Win32.Allaple.b File: C:\Program Files\Sonic\MyDVD\Tutorial\Chinese(T)\essqeeen.exe
deleted: virus Net-Worm.Win32.Allaple.b File: C:\Program Files\Sonic\MyDVD\Tutorial\Chinese(T)\ezblcnjs.exe
deleted: virus Net-Worm.Win32.Allaple.b File: C:\Program Files\Sonic\MyDVD\Tutorial\Chinese(T)\hbnwsswt.exe
deleted: virus Net-Worm.Win32.Allaple.b File: C:\Program Files\Sonic\MyDVD\Tutorial\Chinese(T)\hnjsjker.exe
deleted: virus Net-Worm.Win32.Allaple.b File: C:\Program Files\Sonic\MyDVD\Tutorial\Chinese(T)\jbxbqehj.exe
deleted: virus Net-Worm.Win32.Allaple.b File: C:\Program Files\Sonic\MyDVD\Tutorial\Chinese(T)\jhlsellr.exe
deleted: virus Net-Worm.Win32.Allaple.b File: C:\Program Files\Sonic\MyDVD\Tutorial\Chinese(T)\jvnrcjzt.exe
deleted: virus Net-Worm.Win32.Allaple.b File: C:\Program Files\Sonic\MyDVD\Tutorial\Chinese(T)\jzklkxxk.exe
deleted: virus Net-Worm.Win32.Allaple.b File: C:\Program Files\Sonic\MyDVD\Tutorial\Chinese(T)\keseljzs.exe
deleted: virus Net-Worm.Win32.Allaple.b File: C:\Program Files\Sonic\MyDVD\Tutorial\Chinese(T)\ketceljn.exe
deleted: virus Net-Worm.Win32.Allaple.b File: C:\Program Files\Sonic\MyDVD\Tutorial\Chinese(T)\kksverck.exe
deleted: virus Net-Worm.Win32.Allaple.b File: C:\Program Files\Sonic\MyDVD\Tutorial\Chinese(T)\knntejjr.exe
deleted: virus Net-Worm.Win32.Allaple.b File: C:\Program Files\Sonic\MyDVD\Tutorial\Chinese(T)\qwexjevh.exe
deleted: virus Net-Worm.Win32.Allaple.b File: C:\Program Files\Sonic\MyDVD\Tutorial\Chinese(T)\scnvrrls.exe
deleted: virus Net-Worm.Win32.Allaple.b File: C:\Program Files\Sonic\MyDVD\Tutorial\Chinese(T)\sshlhknw.exe
deleted: virus Net-Worm.Win32.Allaple.b File: C:\Program Files\Sonic\MyDVD\Tutorial\Chinese(T)\tsethxbz.exe
deleted: virus Net-Worm.Win32.Allaple.b File: C:\Program Files\Sonic\MyDVD\Tutorial\Chinese(T)\wcjjnhnt.exe
deleted: virus Net-Worm.Win32.Allaple.b File: C:\Program Files\Sonic\MyDVD\Tutorial\Chinese(T)\wskjejle.exe
deleted: virus Net-Worm.Win32.Allaple.b File: C:\Program Files\Sonic\MyDVD\Tutorial\Chinese(T)\ztkkczzq.exe
deleted: virus Net-Worm.Win32.Allaple.b File: C:\Program Files\Sonic\MyDVD\Tutorial\Chinese(T)\zzelsjlw.exe
disinfected: virus Net-Worm.Win32.Allaple.a File: C:\Program Files\Sonic\MyDVD\Tutorial\Dutch\1.0.htm
disinfected: virus Net-Worm.Win32.Allaple.a File: C:\Program Files\Sonic\MyDVD\Tutorial\Dutch\1.1.htm
disinfected: virus Net-Worm.Win32.Allaple.a File: C:\Program Files\Sonic\MyDVD\Tutorial\Dutch\1.2.htm
disinfected: virus Net-Worm.Win32.Allaple.a File: C:\Program Files\Sonic\MyDVD\Tutorial\Dutch\1.3.htm
disinfected: virus Net-Worm.Win32.Allaple.a File: C:\Program Files\Sonic\MyDVD\Tutorial\Dutch\1.3b.htm
disinfected: virus Net-Worm.Win32.Allaple.a File: C:\Program Files\Sonic\MyDVD\Tutorial\Dutch\1.4.htm
disinfected: virus Net-Worm.Win32.Allaple.a File: C:\Program Files\Sonic\MyDVD\Tutorial\Dutch\1.5.htm
disinfected: virus Net-Worm.Win32.Allaple.a File: C:\Program Files\Sonic\MyDVD\Tutorial\Dutch\1.6.htm
disinfected: virus Net-Worm.Win32.Allaple.a File: C:\Program Files\Sonic\MyDVD\Tutorial\Dutch\2.0.htm
disinfected: virus Net-Worm.Win32.Allaple.a File: C:\Program Files\Sonic\MyDVD\Tutorial\Dutch\2.1.htm
disinfected: virus Net-Worm.Win32.Allaple.a File: C:\Program Files\Sonic\MyDVD\Tutorial\Dutch\2.2.htm
disinfected: virus Net-Worm.Win32.Allaple.a File: C:\Program Files\Sonic\MyDVD\Tutorial\Dutch\2.3.htm
disinfected: virus Net-Worm.Win32.Allaple.a File: C:\Program Files\Sonic\MyDVD\Tutorial\Dutch\3.0.htm
disinfected: virus Net-Worm.Win32.Allaple.a File: C:\Program Files\Sonic\MyDVD\Tutorial\Dutch\3.1.htm
disinfected: virus Net-Worm.Win32.Allaple.a File: C:\Program Files\Sonic\MyDVD\Tutorial\Dutch\3.2.htm
disinfected: virus Net-Worm.Win32.Allaple.a File: C:\Program Files\Sonic\MyDVD\Tutorial\Dutch\3.2b.htm
disinfected: virus Net-Worm.Win32.Allaple.a File: C:\Program Files\Sonic\MyDVD\Tutorial\Dutch\3.3.htm
disinfected: virus Net-Worm.Win32.Allaple.a File: C:\Program Files\Sonic\MyDVD\Tutorial\Dutch\3.4.htm
disinfected: virus Net-Worm.Win32.Allaple.a File: C:\Program Files\Sonic\MyDVD\Tutorial\Dutch\3.5.htm
disinfected: virus Net-Worm.Win32.Allaple.a File: C:\Program Files\Sonic\MyDVD\Tutorial\Dutch\3.6.htm
disinfected: virus Net-Worm.Win32.Allaple.a File: C:\Program Files\Sonic\MyDVD\Tutorial\Dutch\4.0.htm
disinfected: virus Net-Worm.Win32.Allaple.a File: C:\Program Files\Sonic\MyDVD\Tutorial\Dutch\4.1.htm
disinfected: virus Net-Worm.Win32.Allaple.a File: C:\Program Files\Sonic\MyDVD\Tutorial\Dutch\4.2.htm
disinfected: virus Net-Worm.Win32.Allaple.a File: C:\Program Files\Sonic\MyDVD\Tutorial\Dutch\5.0.htm
deleted: virus Net-Worm.Win32.Allaple.b File: C:\Program Files\Sonic\MyDVD\Tutorial\Dutch\bsvkbrkb.exe
deleted: virus Net-Worm.Win32.Allaple.b File: C:\Program Files\Sonic\MyDVD\Tutorial\Dutch\bxhtjvtk.exe
deleted: virus Net-Worm.Win32.Allaple.b File: C:\Program Files\Sonic\MyDVD\Tutorial\Dutch\ecnscsel.exe
deleted: virus Net-Worm.Win32.Allaple.b File: C:\Program Files\Sonic\MyDVD\Tutorial\Dutch\ehscqelr.exe
deleted: virus Net-Worm.Win32.Allaple.b File: C:\Program Files\Sonic\MyDVD\Tutorial\Dutch\ejsrrxhs.exe
deleted: virus Net-Worm.Win32.Allaple.b File: C:\Program Files\Sonic\MyDVD\Tutorial\Dutch\erkveccb.exe
deleted: virus Net-Worm.Win32.Allaple.b File: C:\Program Files\Sonic\MyDVD\Tutorial\Dutch\etnbevqx.exe
disinfected: virus Net-Worm.Win32.Allaple.a File: C:\Program Files\Sonic\MyDVD\Tutorial\Dutch\glossary.htm
deleted: virus Net-Worm.Win32.Allaple.b File: C:\Program Files\Sonic\MyDVD\Tutorial\Dutch\hbkctnxl.exe
deleted: virus Net-Worm.Win32.Allaple.b File: C:\Program Files\Sonic\MyDVD\Tutorial\Dutch\hesxhnkj.exe
deleted: virus Net-Worm.Win32.Allaple.b File: C:\Program Files\Sonic\MyDVD\Tutorial\Dutch\hhvhshsn.exe
deleted: virus Net-Worm.Win32.Allaple.b File: C:\Program Files\Sonic\MyDVD\Tutorial\Dutch\hlttrkse.exe
disinfected: virus Net-Worm.Win32.Allaple.a File: C:\Program Files\Sonic\MyDVD\Tutorial\Dutch\index.htm
deleted: virus Net-Worm.Win32.Allaple.b File: C:\Program Files\Sonic\MyDVD\Tutorial\Dutch\jbhtcqse.exe
deleted: virus Net-Worm.Win32.Allaple.b File: C:\Program Files\Sonic\MyDVD\Tutorial\Dutch\kcsrcbsj.exe
deleted: virus Net-Worm.Win32.Allaple.b File: C:\Program Files\Sonic\MyDVD\Tutorial\Dutch\lxestrtc.exe
deleted: virus Net-Worm.Win32.Allaple.b File: C:\Program Files\Sonic\MyDVD\Tutorial\Dutch\ntjkvekt.exe
deleted: virus Net-Worm.Win32.Allaple.b File: C:\Program Files\Sonic\MyDVD\Tutorial\Dutch\rlrkjllc.exe
deleted: virus Net-Worm.Win32.Allaple.b File: C:\Program Files\Sonic\MyDVD\Tutorial\Dutch\rwtczkcv.exe
deleted: virus Net-Worm.Win32.Allaple.b File: C:\Program Files\Sonic\MyDVD\Tutorial\Dutch\sszthsln.exe
deleted: virus Net-Worm.Win32.Allaple.b File: C:\Program Files\Sonic\MyDVD\Tutorial\Dutch\stnbjhnl.exe
deleted: virus Net-Worm.Win32.Allaple.b File: C:\Program Files\Sonic\MyDVD\Tutorial\Dutch\stshhlvl.exe
deleted: virus Net-Worm.Win32.Allaple.b File: C:\Program Files\Sonic\MyDVD\Tutorial\Dutch\tjhknbjn.exe
deleted: virus Net-Worm.Win32.Allaple.b File: C:\Program Files\Sonic\MyDVD\Tutorial\Dutch\tnzlejej.exe
deleted: virus Net-Worm.Win32.Allaple.b File: C:\Program Files\Sonic\MyDVD\Tutorial\Dutch\tqhcxlsh.exe
deleted: virus Net-Worm.Win32.Allaple.b File: C:\Program Files\Sonic\MyDVD\Tutorial\Dutch\zqslxjss.exe
deleted: virus Net-Worm.Win32.Allaple.b File: C:\Program Files\Sonic\MyDVD\Tutorial\Dutch\zwkxzrbb.exe
deleted: virus Net-Worm.Win32.Allaple.b File: C:\Program Files\Sonic\MyDVD\Tutorial\Dutch\zzenjeqn.exe
disinfected: virus Net-Worm.Win32.Allaple.a File: C:\Program Files\Sonic\MyDVD\Tutorial\English\1.0.htm
disinfected: virus Net-Worm.Win32.Allaple.a File: C:\Program Files\Sonic\MyDVD\Tutorial\English\1.1.htm
disinfected: virus Net-Worm.Win32.Allaple.a File: C:\Program Files\Sonic\MyDVD\Tutorial\English\1.2.htm
disinfected: virus Net-Worm.Win32.Allaple.a File: C:\Program Files\Sonic\MyDVD\Tutorial\English\1.3.htm
disinfected: virus Net-Worm.Win32.Allaple.a File: C:\Program Files\Sonic\MyDVD\Tutorial\English\1.3b.htm
disinfected: virus Net-Worm.Win32.Allaple.a File: C:\Program Files\Sonic\MyDVD\Tutorial\English\1.4.htm
disinfected: virus Net-Worm.Win32.Allaple.a File: C:\Program Files\Sonic\MyDVD\Tutorial\English\1.5.htm
disinfected: virus Net-Worm.Win32.Allaple.a File: C:\Program Files\Sonic\MyDVD\Tutorial\English\1.6.htm
disinfected: virus Net-Worm.Win32.Allaple.a File: C:\Program Files\Sonic\MyDVD\Tutorial\English\2.0.htm
disinfected: virus Net-Worm.Win32.Allaple.a File: C:\Program Files\Sonic\MyDVD\Tutorial\English\2.1.htm
disinfected: virus Net-Worm.Win32.Allaple.a File: C:\Program Files\Sonic\MyDVD\Tutorial\English\2.2.htm
disinfected: virus Net-Worm.Win32.Allaple.a File: C:\Program Files\Sonic\MyDVD\Tutorial\English\2.3.htm
disinfected: virus Net-Worm.Win32.Allaple.a File: C:\Program Files\Sonic\MyDVD\Tutorial\English\3.0.htm
disinfected: virus Net-Worm.Win32.Allaple.a File: C:\Program Files\Sonic\MyDVD\Tutorial\English\3.1.htm
disinfected: virus Net-Worm.Win32.Allaple.a File: C:\Program Files\Sonic\MyDVD\Tutorial\English\3.2.htm
disinfected: virus Net-Worm.Win32.Allaple.a File: C:\Program Files\Sonic\MyDVD\Tutorial\English\3.2b.htm
disinfected: virus Net-Worm.Win32.Allaple.a File: C:\Program Files\Sonic\MyDVD\Tutorial\English\3.3.htm
disinfected: virus Net-Worm.Win32.Allaple.a File: C:\Program Files\Sonic\MyDVD\Tutorial\English\3.4.htm
disinfected: virus Net-Worm.Win32.Allaple.a File: C:\Program Files\Sonic\MyDVD\Tutorial\English\3.5.htm
disinfected: virus Net-Worm.Win32.Allaple.a File: C:\Program Files\Sonic\MyDVD\Tutorial\English\3.6.htm
disinfected: virus Net-Worm.Win32.Allaple.a File: C:\Program Files\Sonic\MyDVD\Tutorial\English\4.0.htm
disinfected: virus Net-Worm.Win32.Allaple.a File: C:\Program Files\Sonic\MyDVD\Tutorial\English\4.1.htm
disinfected: virus Net-Worm.Win32.Allaple.a File: C:\Program Files\Sonic\MyDVD\Tutorial\English\4.2.htm
disinfected: virus Net-Worm.Win32.Allaple.a File: C:\Program Files\Sonic\MyDVD\Tutorial\English\5.0.htm
deleted: virus Net-Worm.Win32.Allaple.b File: C:\Program Files\Sonic\MyDVD\Tutorial\English\bqwebsbj.exe
deleted: virus Net-Worm.Win32.Allaple.b File: C:\Program Files\Sonic\MyDVD\Tutorial\English\ehqnhcxh.exe
deleted: virus Net-Worm.Win32.Allaple.b File: C:\Program Files\Sonic\MyDVD\Tutorial\English\elrskrvn.exe
deleted: virus Net-Worm.Win32.Allaple.b File: C:\Program Files\Sonic\MyDVD\Tutorial\English\escqnknn.exe
disinfected: virus Net-Worm.Win32.Allaple.a File: C:\Program Files\Sonic\MyDVD\Tutorial\English\glossary.htm
deleted: virus Net-Worm.Win32.Allaple.b File: C:\Program Files\Sonic\MyDVD\Tutorial\English\hzenksel.exe
disinfected: virus Net-Worm.Win32.Allaple.a File: C:\Program Files\Sonic\MyDVD\Tutorial\English\index.htm
deleted: virus Net-Worm.Win32.Allaple.b File: C:\Program Files\Sonic\MyDVD\Tutorial\English\jnevkjsc.exe
deleted: virus Net-Worm.Win32.Allaple.b File: C:\Program Files\Sonic\MyDVD\Tutorial\English\jqkxectk.exe
deleted: virus Net-Worm.Win32.Allaple.b File: C:\Program Files\Sonic\MyDVD\Tutorial\English\jqsqsjts.exe
deleted: virus Net-Worm.Win32.Allaple.b File: C:\Program Files\Sonic\MyDVD\Tutorial\English\jwkesnbw.exe
deleted: virus Net-Worm.Win32.Allaple.b File: C:\Program Files\Sonic\MyDVD\Tutorial\English\lcsbcczs.exe
deleted: virus Net-Worm.Win32.Allaple.b File: C:\Program Files\Sonic\MyDVD\Tutorial\English\ljbvkshq.exe
deleted: virus Net-Worm.Win32.Allaple.b File: C:\Program Files\Sonic\MyDVD\Tutorial\English\lrtztbrb.exe
deleted: virus Net-Worm.Win32.Allaple.b File: C:\Program Files\Sonic\MyDVD\Tutorial\English\ltlwbnte.exe
deleted: virus Net-Worm.Win32.Allaple.b File: C:\Program Files\Sonic\MyDVD\Tutorial\English\nxljxbsk.exe
deleted: virus Net-Worm.Win32.Allaple.b File: C:\Program Files\Sonic\MyDVD\Tutorial\English\nxsbhlcn.exe
deleted: virus Net-Worm.Win32.Allaple.b File: C:\Program Files\Sonic\MyDVD\Tutorial\English\rjvkttkn.exe
deleted: virus Net-Worm.Win32.Allaple.b File: C:\Program Files\Sonic\MyDVD\Tutorial\English\rrbvxnee.exe
deleted: virus Net-Worm.Win32.Allaple.b File: C:\Program Files\Sonic\MyDVD\Tutorial\English\rsesjnhb.exe
deleted: virus Net-Worm.Win32.Allaple.b File: C:\Program Files\Sonic\MyDVD\Tutorial\English\rwhkwbvl.exe
deleted: virus Net-Worm.Win32.Allaple.b File: C:\Program Files\Sonic\MyDVD\Tutorial\English\shsnnbwk.exe
deleted: virus Net-Worm.Win32.Allaple.b File: C:\Program Files\Sonic\MyDVD\Tutorial\English\swklsshh.exe
deleted: virus Net-Worm.Win32.Allaple.b File: C:\Program Files\Sonic\MyDVD\Tutorial\English\wzhsjtkk.exe
deleted: virus Net-Worm.Win32.Allaple.b File: C:\Program Files\Sonic\MyDVD\Tutorial\English\xehbcqch.exe
deleted: virus Net-Worm.Win32.Allaple.b File: C:\Program Files\Sonic\MyDVD\Tutorial\English\zewklnth.exe
deleted: virus Net-Worm.Win32.Allaple.b File: C:\Program Files\Sonic\MyDVD\Tutorial\English\zrkrnhxt.exe
deleted: virus Net-Worm.Win32.Allaple.b File: C:\Program Files\Sonic\MyDVD\Tutorial\English\zwrnclhh.exe
disinfected: virus Net-Worm.Win32.Allaple.a File: C:\Program Files\Sonic\MyDVD\Tutorial\French\1.0.htm
disinfected: virus Net-Worm.Win32.Allaple.a File: C:\Program Files\Sonic\MyDVD\Tutorial\French\1.1.htm
disinfected: virus Net-Worm.Win32.Allaple.a File: C:\Program Files\Sonic\MyDVD\Tutorial\French\1.2.htm
disinfected: virus Net-Worm.Win32.Allaple.a File: C:\Program Files\Sonic\MyDVD\Tutorial\French\1.3.htm
disinfected: virus Net-Worm.Win32.Allaple.a File: C:\Program Files\Sonic\MyDVD\Tutorial\French\1.3b.htm
disinfected: virus Net-Worm.Win32.Allaple.a File: C:\Program Files\Sonic\MyDVD\Tutorial\French\1.4.htm
disinfected: virus Net-Worm.Win32.Allaple.a File: C:\Program Files\Sonic\MyDVD\Tutorial\French\1.5.htm
disinfected: virus Net-Worm.Win32.Allaple.a File: C:\Program Files\Sonic\MyDVD\Tutorial\French\1.6.htm
disinfected: virus Net-Worm.Win32.Allaple.a File: C:\Program Files\Sonic\MyDVD\Tutorial\French\2.0.htm
disinfected: virus Net-Worm.Win32.Allaple.a File: C:\Program Files\Sonic\MyDVD\Tutorial\French\2.1.htm
disinfected: virus Net-Worm.Win32.Allaple.a File: C:\Program Files\Sonic\MyDVD\Tutorial\French\2.2.htm
disinfected: virus Net-Worm.Win32.Allaple.a File: C:\Program Files\Sonic\MyDVD\Tutorial\French\2.3.htm
disinfected: virus Net-Worm.Win32.Allaple.a File: C:\Program Files\Sonic\MyDVD\Tutorial\French\3.0.htm
disinfected: virus Net-Worm.Win32.Allaple.a File: C:\Program Files\Sonic\MyDVD\Tutorial\French\3.1.htm
disinfected: virus Net-Worm.Win32.Allaple.a File: C:\Program Files\Sonic\MyDVD\Tutorial\French\3.2.htm
disinfected: virus Net-Worm.Win32.Allaple.a File: C:\Program Files\Sonic\MyDVD\Tutorial\French\3.2b.htm
disinfected: virus Net-Worm.Win32.Allaple.a File: C:\Program Files\Sonic\MyDVD\Tutorial\French\3.3.htm
disinfected: virus Net-Worm.Win32.Allaple.a File: C:\Program Files\Sonic\MyDVD\Tutorial\French\3.4.htm
disinfected: virus Net-Worm.Win32.Allaple.a File: C:\Program Files\Sonic\MyDVD\Tutorial\French\3.5.htm
disinfected: virus Net-Worm.Win32.Allaple.a File: C:\Program Files\Sonic\MyDVD\Tutorial\French\3.6.htm
disinfected: virus Net-Worm.Win32.Allaple.a File: C:\Program Files\Sonic\MyDVD\Tutorial\French\4.0.htm
disinfected: virus Net-Worm.Win32.Allaple.a File: C:\Program Files\Sonic\MyDVD\Tutorial\French\4.1.htm
disinfected: virus Net-Worm.Win32.Allaple.a File: C:\Program Files\Sonic\MyDVD\Tutorial\French\4.2.htm
disinfected: virus Net-Worm.Win32.Allaple.a File: C:\Program Files\Sonic\MyDVD\Tutorial\French\5.0.htm
deleted: virus Net-Worm.Win32.Allaple.b File: C:\Program Files\Sonic\MyDVD\Tutorial\French\esbjbjhh.exe
deleted: virus Net-Worm.Win32.Allaple.b File: C:\Program Files\Sonic\MyDVD\Tutorial\French\evsswrkh.exe
deleted: virus Net-Worm.Win32.Allaple.b File: C:\Program Files\Sonic\MyDVD\Tutorial\French\hwnhnnht.exe
disinfected: virus Net-Worm.Win32.Allaple.a File: C:\Program Files\Sonic\MyDVD\Tutorial\French\index.htm
deleted: virus Net-Worm.Win32.Allaple.b File: C:\Program Files\Sonic\MyDVD\Tutorial\French\jjrlhejz.exe
deleted: virus Net-Worm.Win32.Allaple.b File: C:\Program Files\Sonic\MyDVD\Tutorial\French\jjrtzlhj.exe
deleted: virus Net-Worm.Win32.Allaple.b File: C:\Program Files\Sonic\MyDVD\Tutorial\French\jkqklthj.exe
deleted: virus Net-Worm.Win32.Allaple.b File: C:\Program Files\Sonic\MyDVD\Tutorial\French\jswevxwt.exe
deleted: virus Net-Worm.Win32.Allaple.b File: C:\Program Files\Sonic\MyDVD\Tutorial\French\kshelweq.exe
deleted: virus Net-Worm.Win32.Allaple.b File: C:\Program Files\Sonic\MyDVD\Tutorial\French\ktlxrwkv.exe
deleted: virus Net-Worm.Win32.Allaple.b File: C:\Program Files\Sonic\MyDVD\Tutorial\French\lnhblcxe.exe
deleted: virus Net-Worm.Win32.Allaple.b File: C:\Program Files\Sonic\MyDVD\Tutorial\French\lzblkwen.exe
deleted: virus Net-Worm.Win32.Allaple.b File: C:\Program Files\Sonic\MyDVD\Tutorial\French\nrtnbnqq.exe
deleted: virus Net-Worm.Win32.Allaple.b File: C:\Program Files\Sonic\MyDVD\Tutorial\French\qntehttv.exe
deleted: virus Net-Worm.Win32.Allaple.b File: C:\Program Files\Sonic\MyDVD\Tutorial\French\qznlhhte.exe
deleted: virus Net-Worm.Win32.Allaple.b File: C:\Program Files\Sonic\MyDVD\Tutorial\French\rbwkexve.exe
deleted: virus Net-Worm.Win32.Allaple.b File: C:\Program Files\Sonic\MyDVD\Tutorial\French\rljhtvkn.exe
deleted: virus Net-Worm.Win32.Allaple.b File: C:\Program Files\Sonic\MyDVD\Tutorial\French\sbkjxrql.exe
deleted: virus Net-Worm.Win32.Allaple.b File: C:\Program Files\Sonic\MyDVD\Tutorial\French\skzebnsj.exe
deleted: virus Net-Worm.Win32.Allaple.b File: C:\Program Files\Sonic\MyDVD\Tutorial\French\teherthr.exe
deleted: virus Net-Worm.Win32.Allaple.b File: C:\Program Files\Sonic\MyDVD\Tutorial\French\tjertqej.exe
deleted: virus Net-Worm.Win32.Allaple.b File: C:\Program Files\Sonic\MyDVD\Tutorial\French\tkjbzlqj.exe
deleted: virus Net-Worm.Win32.Allaple.b File: C:\Program Files\Sonic\MyDVD\Tutorial\French\tnvttsbe.exe
deleted: virus Net-Worm.Win32.Allaple.b File: C:\Program Files\Sonic\MyDVD\Tutorial\French\wtxljtkk.exe
deleted: virus Net-Worm.Win32.Allaple.b File: C:\Program Files\Sonic\MyDVD\Tutorial\French\wtzbzttk.exe
deleted: virus Net-Worm.Win32.Allaple.b File: C:\Program Files\Sonic\MyDVD\Tutorial\French\zcxnbbtv.exe
deleted: virus Net-Worm.Win32.Allaple.b File: C:\Program Files\Sonic\MyDVD\Tutorial\French\zsvezrlr.exe
disinfected: virus Net-Worm.Win32.Allaple.a File: C:\Program Files\Sonic\MyDVD\Tutorial\German\1.0.htm
disinfected: virus Net-Worm.Win32.Allaple.a File: C:\Program Files\Sonic\MyDVD\Tutorial\German\1.1.htm
disinfected: virus Net-Worm.Win32.Allaple.a File: C:\Program Files\Sonic\MyDVD\Tutorial\German\1.2.htm
disinfected: virus Net-Worm.Win32.Allaple.a File: C:\Program Files\Sonic\MyDVD\Tutorial\German\1.3.htm
disinfected: virus Net-Worm.Win32.Allaple.a File: C:\Program Files\Sonic\MyDVD\Tutorial\German\1.3b.htm
disinfected: virus Net-Worm.Win32.Allaple.a File: C:\Program Files\Sonic\MyDVD\Tutorial\German\1.4.htm
disinfected: virus Net-Worm.Win32.Allaple.a File: C:\Program Files\Sonic\MyDVD\Tutorial\German\1.5.htm
disinfected: virus Net-Worm.Win32.Allaple.a File: C:\Program Files\Sonic\MyDVD\Tutorial\German\1.6.htm
disinfected: virus Net-Worm.Win32.Allaple.a File: C:\Program Files\Sonic\MyDVD\Tutorial\German\2.0.htm
disinfected: virus Net-Worm.Win32.Allaple.a File: C:\Program Files\Sonic\MyDVD\Tutorial\German\2.1.htm
disinfected: virus Net-Worm.Win32.Allaple.a File: C:\Program Files\Sonic\MyDVD\Tutorial\German\2.2.htm
disinfected: virus Net-Worm.Win32.Allaple.a File: C:\Program Files\Sonic\MyDVD\Tutorial\German\2.3.htm
disinfected: virus Net-Worm.Win32.Allaple.a File: C:\Program Files\Sonic\MyDVD\Tutorial\German\3.0.htm
disinfected: virus Net-Worm.Win32.Allaple.a File: C:\Program Files\Sonic\MyDVD\Tutorial\German\3.1.htm
disinfected: virus Net-Worm.Win32.Allaple.a File: C:\Program Files\Sonic\MyDVD\Tutorial\German\3.2.htm
disinfected: virus Net-Worm.Win32.Allaple.a File: C:\Program Files\Sonic\MyDVD\Tutorial\German\3.2b.htm
disinfected: virus Net-Worm.Win32.Allaple.a File: C:\Program Files\Sonic\MyDVD\Tutorial\German\3.3.htm
disinfected: virus Net-Worm.Win32.Allaple.a File: C:\Program Files\Sonic\MyDVD\Tutorial\German\3.4.htm
disinfected: virus Net-Worm.Win32.Allaple.a File: C:\Program Files\Sonic\MyDVD\Tutorial\German\3.5.htm
disinfected: virus Net-Worm.Win32.Allaple.a File: C:\Program Files\Sonic\MyDVD\Tutorial\German\3.6.htm
disinfected: virus Net-Worm.Win32.Allaple.a File: C:\Program Files\Sonic\MyDVD\Tutorial\German\4.0.htm
disinfected: virus Net-Worm.Win32.Allaple.a File: C:\Program Files\Sonic\MyDVD\Tutorial\German\4.1.htm
disinfected: virus Net-Worm.Win32.Allaple.a File: C:\Program Files\Sonic\MyDVD\Tutorial\German\4.2.htm
disinfected: virus Net-Worm.Win32.Allaple.a File: C:\Program Files\Sonic\MyDVD\Tutorial\German\5.0.htm
deleted: virus Net-Worm.Win32.Allaple.b File: C:\Program Files\Sonic\MyDVD\Tutorial\German\bhbslnne.exe
deleted: virus Net-Worm.Win32.Allaple.b File: C:\Program Files\Sonic\MyDVD\Tutorial\German\bjxblxer.exe
deleted: virus Net-Worm.Win32.Allaple.b File: C:\Program Files\Sonic\MyDVD\Tutorial\German\ckhcwest.exe
deleted: virus Net-Worm.Win32.Allaple.b File: C:\Program Files\Sonic\MyDVD\Tutorial\German\cxewvnzl.exe
deleted: virus Net-Worm.Win32.Allaple.b File: C:\Program Files\Sonic\MyDVD\Tutorial\German\cxthewtv.exe
deleted: virus Net-Worm.Win32.Allaple.b File: C:\Program Files\Sonic\MyDVD\Tutorial\German\ecetknss.exe
deleted: virus Net-Worm.Win32.Allaple.b File: C:\Program Files\Sonic\MyDVD\Tutorial\German\ehhljbks.exe
deleted: virus Net-Worm.Win32.Allaple.b File: C:\Program Files\Sonic\MyDVD\Tutorial\German\elhhklkw.exe
deleted: virus Net-Worm.Win32.Allaple.b File: C:\Program Files\Sonic\MyDVD\Tutorial\German\estblhtx.exe
disinfected: virus Net-Worm.Win32.Allaple.a File: C:\Program Files\Sonic\MyDVD\Tutorial\German\glossary.htm
deleted: virus Net-Worm.Win32.Allaple.b File: C:\Program Files\Sonic\MyDVD\Tutorial\German\hnnshbkv.exe
deleted: virus Net-Worm.Win32.Allaple.b File: C:\Program Files\Sonic\MyDVD\Tutorial\German\hsrjhjzq.exe
disinfected: virus Net-Worm.Win32.Allaple.a File: C:\Program Files\Sonic\MyDVD\Tutorial\German\index.htm
deleted: virus Net-Worm.Win32.Allaple.b File: C:\Program Files\Sonic\MyDVD\Tutorial\German\kjtnkbqt.exe
deleted: virus Net-Worm.Win32.Allaple.b File: C:\Program Files\Sonic\MyDVD\Tutorial\German\krclclqx.exe
deleted: virus Net-Worm.Win32.Allaple.b File: C:\Program Files\Sonic\MyDVD\Tutorial\German\kthekhnr.exe
deleted: virus Net-Worm.Win32.Allaple.b File: C:\Program Files\Sonic\MyDVD\Tutorial\German\kvscrsbl.exe
deleted: virus Net-Worm.Win32.Allaple.b File: C:\Program Files\Sonic\MyDVD\Tutorial\German\lxbbtnew.exe
deleted: virus Net-Worm.Win32.Allaple.b File: C:\Program Files\Sonic\MyDVD\Tutorial\German\nkehtrsl.exe
deleted: virus Net-Worm.Win32.Allaple.b File: C:\Program Files\Sonic\MyDVD\Tutorial\German\nkrejrne.exe
deleted: virus Net-Worm.Win32.Allaple.b File: C:\Program Files\Sonic\MyDVD\Tutorial\German\rejserln.exe
deleted: virus Net-Worm.Win32.Allaple.b File: C:\Program Files\Sonic\MyDVD\Tutorial\German\snhblxhl.exe
deleted: virus Net-Worm.Win32.Allaple.b File: C:\Program Files\Sonic\MyDVD\Tutorial\German\sntrnrlv.exe
deleted: virus Net-Worm.Win32.Allaple.b File: C:\Program Files\Sonic\MyDVD\Tutorial\German\tbthbkjj.exe
deleted: virus Net-Worm.Win32.Allaple.b File: C:\Program Files\Sonic\MyDVD\Tutorial\German\tlbjwhzh.exe
deleted: virus Net-Worm.Win32.Allaple.b File: C:\Program Files\Sonic\MyDVD\Tutorial\German\tthkrcbh.exe
deleted: virus Net-Worm.Win32.Allaple.b File: C:\Program Files\Sonic\MyDVD\Tutorial\German\xwsnhbvq.exe
deleted: virus Net-Worm.Win32.Allaple.b File: C:\Program Files\Sonic\MyDVD\Tutorial\German\zxttbjtb.exe
disinfected: virus Net-Worm.Win32.Allaple.a File: C:\Program Files\Sonic\MyDVD\Tutorial\Italian\1.0.htm
disinfected: virus Net-Worm.Win32.Allaple.a File: C:\Program Files\Sonic\MyDVD\Tutorial\Italian\1.1.htm
disinfected: virus Net-Worm.Win32.Allaple.a File: C:\Program Files\Sonic\MyDVD\Tutorial\Italian\1.2.htm
disinfected: virus Net-Worm.Win32.Allaple.a File: C:\Program Files\Sonic\MyDVD\Tutorial\Italian\1.3.htm
disinfected: virus Net-Worm.Win32.Allaple.a File: C:\Program Files\Sonic\MyDVD\Tutorial\Italian\1.3b.htm
disinfected: virus Net-Worm.Win32.Allaple.a File: C:\Program Files\Sonic\MyDVD\Tutorial\Italian\1.4.htm
disinfected: virus Net-Worm.Win32.Allaple.a File: C:\Program Files\Sonic\MyDVD\Tutorial\Italian\1.5.htm
disinfected: virus Net-Worm.Win32.Allaple.a File: C:\Program Files\Sonic\MyDVD\Tutorial\Italian\1.6.htm
disinfected: virus Net-Worm.Win32.Allaple.a File: C:\Program Files\Sonic\MyDVD\Tutorial\Italian\2.0.htm
disinfected: virus Net-Worm.Win32.Allaple.a File: C:\Program Files\Sonic\MyDVD\Tutorial\Italian\2.1.htm
disinfected: virus Net-Worm.Win32.Allaple.a File: C:\Program Files\Sonic\MyDVD\Tutorial\Italian\2.2.htm
disinfected: virus Net-Worm.Win32.Allaple.a File: C:\Program Files\Sonic\MyDVD\Tutorial\Italian\2.3.htm
disinfected: virus Net-Worm.Win32.Allaple.a File: C:\Program Files\Sonic\MyDVD\Tutorial\Italian\3.0.htm
disinfected: virus Net-Worm.Win32.Allaple.a File: C:\Program Files\Sonic\MyDVD\Tutorial\Italian\3.1.htm
disinfected: virus Net-Worm.Win32.Allaple.a File: C:\Program Files\Sonic\MyDVD\Tutorial\Italian\3.2.htm
disinfected: virus Net-Worm.Win32.Allaple.a File: C:\Program Files\Sonic\MyDVD\Tutorial\Italian\3.2b.htm
disinfected: virus Net-Worm.Win32.Allaple.a File: C:\Program Files\Sonic\MyDVD\Tutorial\Italian\3.3.htm
disinfected: virus Net-Worm.Win32.Allaple.a File: C:\Program Files\Sonic\MyDVD\Tutorial\Italian\3.4.htm
disinfected: virus Net-Worm.Win32.Allaple.a File: C:\Program Files\Sonic\MyDVD\Tutorial\Italian\3.5.htm
disinfected: virus Net-Worm.Win32.Allaple.a File: C:\Program Files\Sonic\MyDVD\Tutorial\Italian\3.6.htm
disinfected: virus Net-Worm.Win32.Allaple.a File: C:\Program Files\Sonic\MyDVD\Tutorial\Italian\4.0.htm
disinfected: virus Net-Worm.Win32.Allaple.a File: C:\Program Files\Sonic\MyDVD\Tutorial\Italian\4.1.htm
disinfected: virus Net-Worm.Win32.Allaple.a File: C:\Program Files\Sonic\MyDVD\Tutorial\Italian\4.2.htm
disinfected: virus Net-Worm.Win32.Allaple.a File: C:\Program Files\Sonic\MyDVD\Tutorial\Italian\5.0.htm
deleted: virus Net-Worm.Win32.Allaple.b File: C:\Program Files\Sonic\MyDVD\Tutorial\Italian\bskbltbl.exe
deleted: virus Net-Worm.Win32.Allaple.b File: C:\Program Files\Sonic\MyDVD\Tutorial\Italian\cnhxbjtv.exe
deleted: virus Net-Worm.Win32.Allaple.b File: C:\Program Files\Sonic\MyDVD\Tutorial\Italian\ebqnjewb.exe
disinfected: virus Net-Worm.Win32.Allaple.a File: C:\Program Files\Sonic\MyDVD\Tutorial\Italian\glossary.htm
deleted: virus Net-Worm.Win32.Allaple.b File: C:\Program Files\Sonic\MyDVD\Tutorial\Italian\hnllwtxs.exe
disinfected: virus Net-Worm.Win32.Allaple.a File: C:\Program Files\Sonic\MyDVD\Tutorial\Italian\index.htm
deleted: virus Net-Worm.Win32.Allaple.b File: C:\Program Files\Sonic\MyDVD\Tutorial\Italian\jesjhkns.exe
deleted: virus Net-Worm.Win32.Allaple.b File: C:\Program Files\Sonic\MyDVD\Tutorial\Italian\jrrctjej.exe
deleted: virus Net-Worm.Win32.Allaple.b File: C:\Program Files\Sonic\MyDVD\Tutorial\Italian\kcesjlnb.exe
deleted: virus Net-Worm.Win32.Allaple.b File: C:\Program Files\Sonic\MyDVD\Tutorial\Italian\knbknlkn.exe
deleted: virus Net-Worm.Win32.Allaple.b File: C:\Program Files\Sonic\MyDVD\Tutorial\Italian\kxvnqtqx.exe
deleted: virus Net-Worm.Win32.Allaple.b File: C:\Program Files\Sonic\MyDVD\Tutorial\Italian\lhbhtvwe.exe
deleted: virus Net-Worm.Win32.Allaple.b File: C:\Program Files\Sonic\MyDVD\Tutorial\Italian\lqhjcjkl.exe
deleted: virus Net-Worm.Win32.Allaple.b File: C:\Program Files\Sonic\MyDVD\Tutorial\Italian\lzskhctq.exe
deleted: virus Net-Worm.Win32.Allaple.b File: C:\Program Files\Sonic\MyDVD\Tutorial\Italian\ncnxsrjb.exe
deleted: virus Net-Worm.Win32.Allaple.b File: C:\Program Files\Sonic\MyDVD\Tutorial\Italian\nnbtsljh.exe
deleted: virus Net-Worm.Win32.Allaple.b File: C:\Program Files\Sonic\MyDVD\Tutorial\Italian\rljcnqvh.exe
deleted: virus Net-Worm.Win32.Allaple.b File: C:\Program Files\Sonic\MyDVD\Tutorial\Italian\rnrnsrrl.exe
deleted: virus Net-Worm.Win32.Allaple.b File: C:\Program Files\Sonic\MyDVD\Tutorial\Italian\slsjrbtk.exe
deleted: virus Net-Worm.Win32.Allaple.b File: C:\Program Files\Sonic\MyDVD\Tutorial\Italian\sreezvrx.exe
deleted: virus Net-Worm.Win32.Allaple.b File: C:\Program Files\Sonic\MyDVD\Tutorial\Italian\srxlnhls.exe
deleted: virus Net-Worm.Win32.Allaple.b File: C:\Program Files\Sonic\MyDVD\Tutorial\Italian\tbqnlbhn.exe
deleted: virus Net-Worm.Win32.Allaple.b File: C:\Program Files\Sonic\MyDVD\Tutorial\Italian\tjekehzz.exe
deleted: virus Net-Worm.Win32.Allaple.b File: C:\Program Files\Sonic\MyDVD\Tutorial\Italian\txkbcsrv.exe
deleted: virus Net-Worm.Win32.Allaple.b File: C:\Program Files\Sonic\MyDVD\Tutorial\Italian\vnxsetkx.exe
deleted: virus Net-Worm.Win32.Allaple.b File: C:\Program Files\Sonic\MyDVD\Tutorial\Italian\weerlbez.exe
deleted: virus Net-Worm.Win32.Allaple.b File: C:\Program Files\Sonic\MyDVD\Tutorial\Italian\xljrsezs.exe
deleted: virus Net-Worm.Win32.Allaple.b File: C:\Program Files\Sonic\MyDVD\Tutorial\Italian\zjwletht.exe
disinfected: virus Net-Worm.Win32.Allaple.a File: C:\Program Files\Sonic\MyDVD\Tutorial\Japanese\1.0.htm
disinfected: virus Net-Worm.Win32.Allaple.a File: C:\Program Files\Sonic\MyDVD\Tutorial\Japanese\1.1.htm
disinfected: virus Net-Worm.Win32.Allaple.a File: C:\Program Files\Sonic\MyDVD\Tutorial\Japanese\1.2.htm
disinfected: virus Net-Worm.Win32.Allaple.a File: C:\Program Files\Sonic\MyDVD\Tutorial\Japanese\1.3.htm
disinfected: virus Net-Worm.Win32.Allaple.a File: C:\Program Files\Sonic\MyDVD\Tutorial\Japanese\1.3b.htm
disinfected: virus Net-Worm.Win32.Allaple.a File: C:\Program Files\Sonic\MyDVD\Tutorial\Japanese\1.4.htm
disinfected: virus Net-Worm.Win32.Allaple.a File: C:\Program Files\Sonic\MyDVD\Tutorial\Japanese\1.5.htm
disinfected: virus Net-Worm.Win32.Allaple.a File: C:\Program Files\Sonic\MyDVD\Tutorial\Japanese\1.6.htm
disinfected: virus Net-Worm.Win32.Allaple.a File: C:\Program Files\Sonic\MyDVD\Tutorial\Japanese\2.0.htm
disinfected: virus Net-Worm.Win32.Allaple.a File: C:\Program Files\Sonic\MyDVD\Tutorial\Japanese\2.1.htm
disinfected: virus Net-Worm.Win32.Allaple.a File: C:\Program Files\Sonic\MyDVD\Tutorial\Japanese\2.2.htm
disinfected: virus Net-Worm.Win32.Allaple.a File: C:\Program Files\Sonic\MyDVD\Tutorial\Japanese\2.3.htm
disinfected: virus Net-Worm.Win32.Allaple.a File: C:\Program Files\Sonic\MyDVD\Tutorial\Japanese\3.0.htm
disinfected: virus Net-Worm.Win32.Allaple.a File: C:\Program Files\Sonic\MyDVD\Tutorial\Japanese\3.1.htm
disinfected: virus Net-Worm.Win32.Allaple.a File: C:\Program Files\Sonic\MyDVD\Tutorial\Japanese\3.2.htm
disinfected: virus Net-Worm.Win32.Allaple.a File: C:\Program Files\Sonic\MyDVD\Tutorial\Japanese\3.2b.htm
disinfected: virus Net-Worm.Win32.Allaple.a File: C:\Program Files\Sonic\MyDVD\Tutorial\Japanese\3.3.htm
disinfected: virus Net-Worm.Win32.Allaple.a File: C:\Program Files\Sonic\MyDVD\Tutorial\Japanese\3.4.htm
disinfected: virus Net-Worm.Win32.Allaple.a File: C:\Program Files\Sonic\MyDVD\Tutorial\Japanese\3.5.htm
disinfected: virus Net-Worm.Win32.Allaple.a File: C:\Program Files\Sonic\MyDVD\Tutorial\Japanese\3.6.htm
disinfected: virus Net-Worm.Win32.Allaple.a File: C:\Program Files\Sonic\MyDVD\Tutorial\Japanese\4.0.htm
disinfected: virus Net-Worm.Win32.Allaple.a File: C:\Program Files\Sonic\MyDVD\Tutorial\Japanese\4.1.htm
disinfected: virus Net-Worm.Win32.Allaple.a File: C:\Program Files\Sonic\MyDVD\Tutorial\Japanese\4.2.htm
disinfected: virus Net-Worm.Win32.Allaple.a File: C:\Program Files\Sonic\MyDVD\Tutorial\Japanese\5.0.htm
deleted: virus Net-Worm.Win32.Allaple.b File: C:\Program Files\Sonic\MyDVD\Tutorial\Japanese\chrehnww.exe
deleted: virus Net-Worm.Win32.Allaple.b File: C:\Program Files\Sonic\MyDVD\Tutorial\Japanese\cjjenrbh.exe
deleted: virus Net-Worm.Win32.Allaple.b File: C:\Program Files\Sonic\MyDVD\Tutorial\Japanese\ckkzrtwv.exe
deleted: virus Net-Worm.Win32.Allaple.b File: C:\Program Files\Sonic\MyDVD\Tutorial\Japanese\elnzvenn.exe
deleted: virus Net-Worm.Win32.Allaple.b File: C:\Program Files\Sonic\MyDVD\Tutorial\Japanese\enxwwzqs.exe
deleted: virus Net-Worm.Win32.Allaple.b File: C:\Program Files\Sonic\MyDVD\Tutorial\Japanese\ezwcrwsb.exe
disinfected: virus Net-Worm.Win32.Allaple.a File: C:\Program Files\Sonic\MyDVD\Tutorial\Japanese\glossary.htm
deleted: virus Net-Worm.Win32.Allaple.b File: C:\Program Files\Sonic\MyDVD\Tutorial\Japanese\hbcskbvt.exe
deleted: virus Net-Worm.Win32.Allaple.b File: C:\Program Files\Sonic\MyDVD\Tutorial\Japanese\hhvnrvtb.exe
deleted: virus Net-Worm.Win32.Allaple.b File: C:\Program Files\Sonic\MyDVD\Tutorial\Japanese\hvzwbekb.exe
disinfected: virus Net-Worm.Win32.Allaple.a File: C:\Program Files\Sonic\MyDVD\Tutorial\Japanese\index.htm
deleted: virus Net-Worm.Win32.Allaple.b File: C:\Program Files\Sonic\MyDVD\Tutorial\Japanese\khqhlqht.exe
deleted: virus Net-Worm.Win32.Allaple.b File: C:\Program Files\Sonic\MyDVD\Tutorial\Japanese\lentlbjs.exe
deleted: virus Net-Worm.Win32.Allaple.b File: C:\Program Files\Sonic\MyDVD\Tutorial\Japanese\lwzsehjl.exe
deleted: virus Net-Worm.Win32.Allaple.b File: C:\Program Files\Sonic\MyDVD\Tutorial\Japanese\lzlxehne.exe
deleted: virus Net-Worm.Win32.Allaple.b File: C:\Program Files\Sonic\MyDVD\Tutorial\Japanese\nesbrktl.exe
deleted: virus Net-Worm.Win32.Allaple.b File: C:\Program Files\Sonic\MyDVD\Tutorial\Japanese\qjnltzze.exe
deleted: virus Net-Worm.Win32.Allaple.b File: C:\Program Files\Sonic\MyDVD\Tutorial\Japanese\resrvqxk.exe
deleted: virus Net-Worm.Win32.Allaple.b File: C:\Program Files\Sonic\MyDVD\Tutorial\Japanese\shrtqsbt.exe
deleted: virus Net-Worm.Win32.Allaple.b File: C:\Program Files\Sonic\MyDVD\Tutorial\Japanese\slvtxttl.exe
deleted: virus Net-Worm.Win32.Allaple.b File: C:\Program Files\Sonic\MyDVD\Tutorial\Japanese\ssbvwvzv.exe
deleted: virus Net-Worm.Win32.Allaple.b File: C:\Program Files\Sonic\MyDVD\Tutorial\Japanese\tezwbbxt.exe
deleted: virus Net-Worm.Win32.Allaple.b File: C:\Program Files\Sonic\MyDVD\Tutorial\Japanese\theztzer.exe
deleted: virus Net-Worm.Win32.Allaple.b File: C:\Program Files\Sonic\MyDVD\Tutorial\Japanese\ttcnxzek.exe
deleted: virus Net-Worm.Win32.Allaple.b File: C:\Program Files\Sonic\MyDVD\Tutorial\Japanese\tvrrkttt.exe
deleted: virus Net-Worm.Win32.Allaple.b File: C:\Program Files\Sonic\MyDVD\Tutorial\Japanese\vztqllej.exe
deleted: virus Net-Worm.Win32.Allaple.b File: C:\Program Files\Sonic\MyDVD\Tutorial\Japanese\xscncjes.exe
deleted: virus Net-Worm.Win32.Allaple.b File: C:\Program Files\Sonic\MyDVD\Tutorial\Japanese\zktvrbej.exe
disinfected: virus Net-Worm.Win32.Allaple.a File: C:\Program Files\Sonic\MyDVD\Tutorial\Korean\1.0.htm
disinfected: virus Net-Worm.Win32.Allaple.a File: C:\Program Files\Sonic\MyDVD\Tutorial\Korean\1.1.htm
disinfected: virus Net-Worm.Win32.Allaple.a File: C:\Program Files\Sonic\MyDVD\Tutorial\Korean\1.2.htm
disinfected: virus Net-Worm.Win32.Allaple.a File: C:\Program Files\Sonic\MyDVD\Tutorial\Korean\1.3.htm
disinfected: virus Net-Worm.Win32.Allaple.a File: C:\Program Files\Sonic\MyDVD\Tutorial\Korean\1.3b.htm
disinfected: virus Net-Worm.Win32.Allaple.a File: C:\Program Files\Sonic\MyDVD\Tutorial\Korean\1.4.htm
disinfected: virus Net-Worm.Win32.Allaple.a File: C:\Program Files\Sonic\MyDVD\Tutorial\Korean\1.5.htm
disinfected: virus Net-Worm.Win32.Allaple.a File: C:\Program Files\Sonic\MyDVD\Tutorial\Korean\1.6.htm
disinfected: virus Net-Worm.Win32.Allaple.a File: C:\Program Files\Sonic\MyDVD\Tutorial\Korean\2.0.htm
disinfected: virus Net-Worm.Win32.Allaple.a File: C:\Program Files\Sonic\MyDVD\Tutorial\Korean\2.1.htm
disinfected: virus Net-Worm.Win32.Allaple.a File: C:\Program Files\Sonic\MyDVD\Tutorial\Korean\2.2.htm
disinfected: virus Net-Worm.Win32.Allaple.a File: C:\Program Files\Sonic\MyDVD\Tutorial\Korean\2.3.htm
disinfected: virus Net-Worm.Win32.Allaple.a File: C:\Program Files\Sonic\MyDVD\Tutorial\Korean\3.0.htm
disinfected: virus Net-Worm.Win32.Allaple.a File: C:\Program Files\Sonic\MyDVD\Tutorial\Korean\3.1.htm
disinfected: virus Net-Worm.Win32.Allaple.a File: C:\Program Files\Sonic\MyDVD\Tutorial\Korean\3.2.htm
disinfected: virus Net-Worm.Win32.Allaple.a File: C:\Program Files\Sonic\MyDVD\Tutorial\Korean\3.2b.htm
disinfected: virus Net-Worm.Win32.Allaple.a File: C:\Program Files\Sonic\MyDVD\Tutorial\Korean\3.3.htm
disinfected: virus Net-Worm.Win32.Allaple.a File: C:\Program Files\Sonic\MyDVD\Tutorial\Korean\3.4.htm
disinfected: virus Net-Worm.Win32.Allaple.a File: C:\Program Files\Sonic\MyDVD\Tutorial\Korean\3.5.htm
disinfected: virus Net-Worm.Win32.Allaple.a File: C:\Program Files\Sonic\MyDVD\Tutorial\Korean\3.6.htm
disinfected: virus Net-Worm.Win32.Allaple.a File: C:\Program Files\Sonic\MyDVD\Tutorial\Korean\4.0.htm
disinfected: virus Net-Worm.Win32.Allaple.a File: C:\Program Files\Sonic\MyDVD\Tutorial\Korean\4.1.htm
disinfected: virus Net-Worm.Win32.Allaple.a File: C:\Program Files\Sonic\MyDVD\Tutorial\Korean\4.2.htm
disinfected: virus Net-Worm.Win32.Allaple.a File: C:\Program Files\Sonic\MyDVD\Tutorial\Korean\5.0.htm
deleted: virus Net-Worm.Win32.Allaple.b File: C:\Program Files\Sonic\MyDVD\Tutorial\Korean\btntrtec.exe
deleted: virus Net-Worm.Win32.Allaple.b File: C:\Program Files\Sonic\MyDVD\Tutorial\Korean\bzjwnxqj.exe
deleted: virus Net-Worm.Win32.Allaple.b File: C:\Program Files\Sonic\MyDVD\Tutorial\Korean\ehrrkxej.exe
deleted: virus Net-Worm.Win32.Allaple.b File: C:\Program Files\Sonic\MyDVD\Tutorial\Korean\ekrcseht.exe
deleted: virus Net-Worm.Win32.Allaple.b File: C:\Program Files\Sonic\MyDVD\Tutorial\Korean\eskknvsq.exe
disinfected: virus Net-Worm.Win32.Allap

#9 Daemon

Daemon

    Security Expert


  • Members
  • 1,446 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:UK
  • Local time:01:12 AM

Posted 04 January 2007 - 02:08 AM

It seems to have attached itself to a lot of files. When Kaspersky has finished this clean-up, reboot and carry out a full system scan again - post the log file from that scan.
Posted Image

Have I helped you? Please consider donating to help me continue with the fight against malware. Click here

#10 strobie

strobie
  • Topic Starter

  • Members
  • 9 posts
  • OFFLINE
  •  
  • Local time:10:12 AM

Posted 04 January 2007 - 02:34 AM

Okay. This seems like a toughie... a search for this virus on virus search engines show it as relatively new and unknown still.

#11 Daemon

Daemon

    Security Expert


  • Members
  • 1,446 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:UK
  • Local time:01:12 AM

Posted 04 January 2007 - 02:38 AM

Yes, but Kaspersky is detecting and cleaning it. If you come back clean after the second scan you should be OK, otherwise there may be a reinfector and we will have to dig deeper.
Posted Image

Have I helped you? Please consider donating to help me continue with the fight against malware. Click here

#12 strobie

strobie
  • Topic Starter

  • Members
  • 9 posts
  • OFFLINE
  •  
  • Local time:10:12 AM

Posted 04 January 2007 - 04:11 AM

for the 2nd time, i got the blue screen of death (which was what prompted my initial realization that my computer was infected) came up.

stop 0x0000007F (0x00000008 .... 0x80042000)

I am in safe mode now scanning.

#13 strobie

strobie
  • Topic Starter

  • Members
  • 9 posts
  • OFFLINE
  •  
  • Local time:10:12 AM

Posted 04 January 2007 - 05:00 AM

Ran the Kaspersky scan in safemode.
Same virus still present and spreading itself around my computer...
Once again, this is note the whole list due to space constraints
Await your further instructions.



Scan My Computer
----------------
Scanned: 40366
Detected: 168
Untreated: 0
Start time: 04/01/2007 6:00:05 PM
Duration: 00:56:42
Finish time: 04/01/2007 6:56:47 PM


Detected
--------
Status Object
------ ------
deleted: virus Net-Worm.Win32.Allaple.b File: C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP85\A0019092.exe
deleted: virus Net-Worm.Win32.Allaple.b File: C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP85\A0019093.exe
deleted: virus Net-Worm.Win32.Allaple.b File: C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP85\A0019094.exe
deleted: virus Net-Worm.Win32.Allaple.b File: C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP85\A0019095.exe
deleted: virus Net-Worm.Win32.Allaple.b File: C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP85\A0019096.exe
deleted: virus Net-Worm.Win32.Allaple.b File: C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP85\A0019097.exe
deleted: virus Net-Worm.Win32.Allaple.b File: C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP85\A0019098.exe
deleted: virus Net-Worm.Win32.Allaple.b File: C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP85\A0019099.exe
deleted: virus Net-Worm.Win32.Allaple.b File: C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP85\A0019100.exe
deleted: virus Net-Worm.Win32.Allaple.b File: C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP85\A0019101.exe
deleted: virus Net-Worm.Win32.Allaple.b File: C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP85\A0019102.exe
deleted: virus Net-Worm.Win32.Allaple.b File: C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP85\A0019103.exe
deleted: virus Net-Worm.Win32.Allaple.b File: C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP85\A0019104.exe
deleted: virus Net-Worm.Win32.Allaple.b File: C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP85\A0019105.exe
deleted: virus Net-Worm.Win32.Allaple.b File: C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP85\A0019106.exe
deleted: virus Net-Worm.Win32.Allaple.b File: C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP85\A0019107.exe
deleted: virus Net-Worm.Win32.Allaple.b File: C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP85\A0019108.exe
deleted: virus Net-Worm.Win32.Allaple.b File: C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP85\A0019109.exe
deleted: virus Net-Worm.Win32.Allaple.b File: C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP85\A0019110.exe

etc.

#14 Daemon

Daemon

    Security Expert


  • Members
  • 1,446 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:UK
  • Local time:01:12 AM

Posted 04 January 2007 - 03:36 PM

That's OK - it's just your restore files. See if you can carry out a full scan in Normal Mode and post the Kaspersky log here.
Posted Image

Have I helped you? Please consider donating to help me continue with the fight against malware. Click here

#15 Daemon

Daemon

    Security Expert


  • Members
  • 1,446 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:UK
  • Local time:01:12 AM

Posted 07 January 2007 - 02:26 PM

Please reply if you still require assistance otherwise I will close the topic.
Posted Image

Have I helped you? Please consider donating to help me continue with the fight against malware. Click here




0 user(s) are reading this topic

0 members, 0 guests, 0 anonymous users