Hmm… I’m not sure how you ended up with an old version of HJT. I just tried the link I gave you and it gives me the newest version 2.0.2. If you had an old version, please delete it and download a new one.
I would say you have attached an infected usb drive to this computer, going by the number of autorun infection that there is evidence of. There are at least 3 more drive letters. O,P and Q,
Please leave your drives connected as they where before. I see you have all five drives present and acounted for, good. It will make this easier.
Please download
OTMoveIt2 by OldTimer.
Save it to your desktop.
Please double-click OTMoveIt2.exe to run it.
Copy the file paths below to the clipboard by highlighting ALL of them and pressing CTRL + C (or, after highlighting, right-click and choose Copy):
[b]
C:\Temp\WPDNSE
C:\Temp\k2fvpt.dll
C:\Temp\svg6c.tmp
C:\Temp\plugtmp
C:\Temp\e7sf4.dll
C:\Temp\pdfdownload
C:\Temp~nsu.tmp
C:\Temp\UCDebugger
C:\Temp\asqhbf.dll
C:\Temp{4B9BB601-13E9-4042-A3BC-E7955BF4A98F}
C:\Temp\pft5.tmp
C:\Temp\pft3.tmp
C:\oufddh.exe
E:\oufddh.exe
H:\oufddh.exe
L:\oufddh.exe
N:\oufddh.exe
C:\Temp\n8.dll
C:\Temp\whyghu.dll
C:\McRegWizz.exe /s
E:\McRegWizz.exe /s
H:\McRegWizz.exe /s
L:\McRegWizz.exe /s
N:\McRegWizz.exe /s
C:\RavMon.exe
H:\RavMon.exe
E:\RavMon.exe
L:\RavMon.exe
N:\RavMon.exe
C:\fooool.exe /s
E:\fooool.exe /s
H:\fooool.exe /s
L:\fooool.exe /s
C:\fooool.exe /s
E:\Knight.exe /S
H:\Knight.exe /S
L:\Knight.exe /S
N:\Knight.exe /S
C:\copy.exe
E:\copy.exe
H:\copy.exe
L:\copy.exe
N:\copy.exe
C:\Recycled\ctfmon.exe
E:\Recycled\ctfmon.exe
H:\Recycled\ctfmon.exe
L:\Recycled\ctfmon.exe
N:\Recycled\ctfmon.exe
C:\ekugb3.bat
E:\ekugb3.bat
L:\ekugb3.bat
H:\ekugb3.bat
N:\ekugb3.bat
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2{35ce2e7c-c44f-11dc-a5e8-0018f3c7fea4}
HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2{c90ce0bd-7025-11dc-a51e-0018f3c7fea4}
HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2{a2b59323-70f8-11dc-a51f-0018f3c7fea4}
HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2{c898d1b7-a27c-11dc-a593-0018f3c7fea4}
HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2{379e7a82-db5f-11dc-a649-0018f3c7fea4}
HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2{178d63a8-bd2c-11dc-a5d5-0018f3c7fea4}
HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2{42dd107f-9d10-11dc-a587-0018f3c7fea4}
HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2{9b95f6ff-afe7-11dc-a5b3-0018f3c7fea4}
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2{44aedaa4-6b64-11da-b3c2-8823223bd43e}
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2{6e702fbc-57fd-11db-91b5-806d6172696f}
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2{8604638a-a42f-11dc-a598-0018f3c7fea4}
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2{9334b02b-8feb-11dc-a566-0018f3c7fea4}
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2{9962925a-ad82-11dc-a5b0-0018f3c7fea4}
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2{9e955e4e-a8bc-11db-a727-806d6172696f}
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2{e5957814-e224-4f7e-a864-886c4e8119e0}
[/b]
Return to OTMoveIt2, right click in the “Paste List Of Files/Patterns To Search For and Move” window (under the yellow bar) and choose Paste.
Click the red Moveit! button.
Copy everything in the Results window (under the green bar) to the clipboard by highlighting ALL of them and pressing CTRL + C (or, after highlighting, right-click and choose copy), and paste it in your next reply.
Close OTMoveIt2
If a file or folder cannot be moved immediately you may be asked to reboot the machine to finish the move process. If you are asked to reboot the machine choose Yes.
NOTE: If OTMOVEITE reboots, before you can get the ruslts they can be found here
C:_OTMoveIt\MovedFiles**_.log
(where “**_” is the “date_time”)