Remove the RECYCLER.exe virus

Closed
Hello,
please I have a problem with the RECYCLER.exe virus.
When I sent a folder from my PC to my flash drive which was empty before, I found a folder called RECYCLER.exe. It told me it was a virus; I scanned my flash drive but the antivirus didn't detect any viruses, which is strange. And since I copied the folder from my PC, it means this virus is inside, but when I did a full scan, I found nothing.
It told me to show hidden folders by using Control Panel --> Folder Options --> Show hidden files and folders, but the folders remain hidden and when I go back to the folder options, I find the option to show hidden files and folders disabled. I don't know why this problem exists and I can't solve it.
Please help me to destroy this virus and if you have other ideas, please let me know.
Thanks in advance.
Configuration: Windows XP Internet Explorer 7.0

26 answers

  1. Security Contributor
    Hey there

    No panic
    C_XX & Chiquitine29 have created what you need!

    Download and install UsbFix from C_XX & Chiquitine29

    Connect your external data sources to your PC (USB stick, external hard drive, etc...) that may have been infected without opening them

    # Double click on the UsbFix shortcut present on your desktop.

    # Choose option 1 (Search)

    # Let the tool work.

    # Then post the UsbFix.txt report that will appear.

    # Note: The UsbFix.txt report is saved at the root of the drive. (C:\UsbFix.txt)

    (CTRL+A to select all, CTRL+C to copy and CTRL+V to paste)

    # Note: "Process.exe", a component of the tool, is detected by some antivirus software (AntiVir, Dr.Web, Kaspersky Anti-Virus) as a RiskTool.
    It is not a virus, but a utility designed to terminate processes.
    In the wrong hands, this utility could stop security software (Antivirus, Firewall...) hence the alert issued by these antivirus programs.
    6
    1. Hello and Happy New Year
      I can't get rid of the diskrun.exe virus, do you have any idea? Thank you.
      0
    2. Hi, thanks for this solution.
      What address should we send the report to?
      0
    3. Thank you very much, sir.
      0
    4. Good evening, I have the same problem and here is my report:
      ############################## | UsbFix V 7.109 | [Removal]

      User: michel bernard (Administrator) # YOUR-409757439B
      Updated on 22/02/2013 by El Desaparecido
      Launched at 11:41:55 | 25/02/2013

      Website: https://www.sosvirus.net/
      Contact: contact@sosvirus.org

      PC: TOSHIBA (TOSHIBA NB200) (X86-based PC)
      CPU: Intel(R) Atom(TM) CPU N280 @ 1.66GHz (1662)
      RAM -> [Total: 1014 | Free: 260]
      BIOS: Ver 1.00PARTTBL4
      BOOT: Normal boot

      OS: Microsoft Windows XP Home Edition (5.1.2600 32-Bit) # Service Pack 3
      WB: Windows Internet Explorer 7.0.5730.13

      SC: Security Center Service [Enabled]
      WU: Windows Update Service [Enabled]
      FW: Windows FireWall Service [Enabled]

      C:\ (%systemdrive%) -> Hard Disk # 75 Go (39 Go free - 53%) [XP] # NTFS
      D:\ -> Hard Disk # 73 Go (69 Go free - 94%) [Data] # NTFS
      E:\ -> Hard Disk # 298 Go (9 Go free - 3%) [SAMSUNG] # NTFS
      F:\ -> Removable Disk # 4 Go (2 Go free - 47%) [] # FAT32
      G:\ -> Removable Disk # 8 Go (4 Go free - 55%) [] # FAT32

      ################## | Stopped Processes |

      Stopped! C:\WINDOWS\system32\spoolsv.exe (1860)
      Stopped! C:\WINDOWS\Explorer.EXE (1868)
      Stopped! C:\WINDOWS\system32\acs.exe (1916)
      Stopped! C:\Program Files\TOSHIBA\ConfigFree\CFSvcs.exe (432)
      Stopped! C:\WINDOWS\system32\ThpSrv.exe (728)
      Stopped! C:\WINDOWS\system32\TODDSrv.exe (792)
      Stopped! c:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosBtSrv.exe (856)
      Stopped! C:\WINDOWS\system32\SearchIndexer.exe (1416)
      Stopped! C:\WINDOWS\system32\igfxtray.exe (260)
      Stopped! C:\WINDOWS\system32\igfxsrvc.exe (1248)
      Stopped! C:\WINDOWS\system32\hkcmd.exe (580)
      Stopped! C:\WINDOWS\system32\igfxpers.exe (636)
      Stopped! C:\WINDOWS\RTHDCPL.EXE (724)
      Stopped! C:\Program Files\TOSHIBA\ConfigFree\NDSTray.exe (516)
      Stopped! C:\Program Files\TOSHIBA\E-KEY\CeEKey.exe (532)
      Stopped! C:\WINDOWS\system32\TDispVol.exe (872)
      Stopped! C:\Program Files\TOSHIBA\TOSHIBA Zoom Utility\SmoothView.exe (1344)
      Stopped! C:\WINDOWS\system32\ZoomingHook.exe (1396)
      Stopped! C:\Program Files\TOSHIBA\TouchPad\TPTray.exe (1884)
      Stopped! C:\WINDOWS\system32\thpsrv.exe (1644)
      Stopped! C:\Program Files\Atheros\ACU.exe (1704)
      Stopped! C:\Program Files\Apoint2K\Apoint.exe (1820)
      Stopped! C:\Program Files\Camera Assistant Software for Toshiba\traybar.exe (1996)
      Stopped! C:\Program Files\AVG Secure Search\vprot.exe (2068)
      Stopped! C:\WINDOWS\system32\TPSBattM.exe (2132)
      Stopped! C:\WINDOWS\system32\ctfmon.exe (2144)
      Stopped! C:\Program Files\TOSHIBA\Toshiba Online Product Information\topi.exe (2168)
      Stopped! C:\Program Files\Messenger\msmsgs.exe (2208)
      Stopped! C:\Program Files\Microsoft ActiveSync\wcescomm.exe (2232)
      Stopped! C:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosBtMng.exe (2288)
      Stopped! C:\Program Files\McAfee Security Scan\3.0.318\SSScheduler.exe (2312)
      Stopped! C:\PROGRA~1\MICROS~4\rapimgr.exe (2332)
      Stopped! C:\Program Files\Windows Desktop Search\WindowsSearch.exe (2340)
      Stopped! c:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosA2dp.exe (3560)
      Stopped! c:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosBtHid.exe (3752)
      Stopped! c:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosBtHsp.exe (2916)
      Stopped! C:\Program Files\Apoint2K\Apntex.exe (3712)
      Stopped! C:\WINDOWS\system32\wuauclt.exe (1744)
      Stopped! C:\Program Files\Mozilla Firefox\firefox.exe (1684)

      ################## | Infectious Items |

      Deleted! C:\DOCUME~1\MICHEL~1\LOCALS~1\Temp\DataCard_Setup.exe
      Deleted! C:\DOCUME~1\MICHEL~1\LOCALS~1\Temp\ose00000.exe
      Deleted! D:\setupSNK.exe
      Deleted! D:\AUTORUN.INF

      (!) Temporary files deleted.

      ################## | Registry |

      ################## | Mountpoints2 |

      Deleted! HKCU\.\.\.\.\Explorer\MountPoints2\{03b4c672-2219-11e1-8e7d-002308a5455f}
      Deleted! HKCU\.\.\.\.\Explorer\MountPoints2\{0fb37812-14cf-11e1-8e67-002308a5455f}
      Deleted! HKCU\.\.\.\.\Explorer\MountPoints2\{35e283db-254f-11de-8ca7-00235a07d42c}
      Deleted! HKCU\.\.\.\.\Explorer\MountPoints2\{6ea21dd2-f9d9-11de-8db2-00235afc9474}
      Deleted! HKCU\.\.\.\.\Explorer\MountPoints2\{7f4ce2a8-255d-11de-96e5-00235a07d42c}
      Deleted! HKCU\.\.\.\.\Explorer\MountPoints2\{a7fb5a43-17ed-11e1-8e71-002308a5455f}
      Deleted! HKCU\.\.\.\.\Explorer\MountPoints2\{aaccac64-2f49-11df-8dba-002258fb4a8c}

      ################## | Listing |

      [24/08/2010 - 17:06:49 | D ] C:\$AVG
      [15/03/2010 - 00:42:46 | N | 34802] C:\ASLog.txt
      [09/04/2009 - 05:13:23 | N | 0] C:\AUTOEXEC.BAT
      [31/12/2009 - 17:16:36 | N | 233] C:\boot.ini
      [14/04/2008 - 13:00:00 | N | 4952] C:\Bootfont.bin
      [25/02/2013 - 06:11:56 | D ] C:\Config.Msi
      [09/04/2009 - 05:13:23 | N | 0] C:\CONFIG.SYS
      [31/12/2009 - 17:17:21 | D ] C:\Documents and Settings
      [25/02/2013 - 06:08:00 | ASH | 1063702528] C:\hiberfil.sys
      [09/04/2009 - 05:38:03 | D ] C:\I386
      [31/12/2009 - 17:18:06 | D ] C:\Intel
      [09/04/2009 - 05:13:23 | N | 0] C:\IO.SYS
      [23/01/2013 - 11:41:19 | D ] C:\kleaner.tmp
      [09/04/2009 - 05:13:23 | N | 0] C:\MSDOS.SYS
      [02/11/2011 - 20:59:07 | RHD ] C:\MSOCache
      [14/04/2008 - 13:00:00 | N | 47564] C:\NTDETECT.COM
      [14/04/2008 - 13:00:00 | N | 252240] C:\ntldr
      [25/02/2013 - 06:07:59 | ASH | 1598029824] C:\pagefile.sys
      [25/02/2013 - 11:17:40 | D ] C:\Program Files
      [13/03/2010 - 20:00:51 | SHD ] C:\RECYCLER
      [09/04/2009 - 06:11:42 | N | 1832] C:\RHDSetup.log
      [09/04/2009 - 05:38:10 | D ] C:\SUPPORT
      [08/04/2009 - 17:57:49 | N | 176] C:\SWSTAMP.TXT
      [25/01/2013 - 07:05:33 | SHD ] C:\System Volume Information
      [10/04/2009 - 00:53:01 | D ] C:\Toshiba
      [25/02/2013 - 11:44:31 | D ] C:\UsbFix
      [25/02/2013 - 11:45:11 | A | 5610] C:\UsbFix [Clean 1] YOUR-409757439B.txt
      [06/06/2010 - 16:22:28 | D ] C:\VALUEADD
      [25/02/2013 - 06:10:44 | D ] C:\WINDOWS
      [16/05/2012 - 08:58:38 | D ] D:\0db2b9e0c081ab041e8d0acead0e
      [17/05/2012 - 10:39:20 | D ] D:\1143c195d0e1151fc9fb
      [04/01/2010 - 00:04:09 | D ] D:\12bb6241e6a29abcc68954
      [17/05/2012 - 01:46:14 | D ] D:\3f3424430d474e6734d9cfa7aaf1b790
      [03/01/2010 - 20:07:26 | D ] D:\597c43a6ec0ca845ffab
      [03/01/2010 - 22:25:40 | D ] D:\7c6680354387b167cad4a4550f
      [18/05/2012 - 14:58:24 | D ] D:\84a3bdb6e92ab652b2041e8e6a
      [03/01/2010 - 22:25:33 | D ] D:\945b1a8bc35789d42b3e7f7481
      [03/01/2010 - 20:07:32 | D ] D:\c19856bcd2ea7e3afc5c
      [22/05/2012 - 14:49:59 | D ] D:\ec8112c4e2a16e562951a22f49
      [22/05/2012 - 13:42:32 | D ] D:\ef89866d4a37491dfacf04b54a01db9a
      [01/01/2010 - 03:11:40 | D ] D:\HDDRecovery
      [20/04/2009 - 18:49:48 | N | 11] D:\R10806FR.tag
      [09/10/2011 - 19:39:18 | SHD ] D:\RECYCLER
      [29/02/2012 - 07:05:13 | D ] D:\SMRTNTKY
      [24/01/2013 - 07:55:08 | SHD ] D:\System Volume Information

      ################## | Vaccine |

      C:\Autorun.inf -> Vaccine created by UsbFix (El Desaparecido)
      D:\Autorun.inf -> Vaccine created by UsbFix (El Desaparecido)

      ################## | E.O.F | https://www.sosvirus.net/ |

      Can you help me?

      Thank you
      0
    5. ############################## | UsbFix V 7.152 | [Search]

      User: WINDOWS (Administrator) # WINDOWS-PC
      Last updated on 20/11/2013 by El Desaparecido - Team SosVirus
      Launched at 11:43:19 | 04/12/2013

      Website: http://www.usbfix.net
      Forum: http://www.sosvirus.net/
      Upload Malware: http://www.sosvirus.net/upload_malware.php
      Contact: http://www.usbfix.net/contact/

      PC: Hewlett-Packard (308A)
      CPU: Intel(R) Core(TM)2 Duo CPU T5870 @ 2.00GHz
      RAM -> [Total: 3063 | Free: 1570]
      Bios: Hewlett-Packard
      Boot: Normal boot

      OS: Microsoft Windows 7 Ultimate (6.1.7600 32-Bit)
      WB: Windows Internet Explorer: 9.0.8112.16421
      WB: Mozilla Firefox: 15.0.1

      SC: Security Center Service [Enabled]
      WU: Windows Update Service [Enabled]
      AV: avast! Antivirus [Enabled | Updated]
      AS: Windows Defender: 6.1.7600.16385 (win7_rtm.090713-1255)
      FW: Windows Firewall Service [Enabled]

      C:\ (%systemdrive%) -> Fixed Drive # 146 GB (72 GB free - 49%) [] # NTFS
      D:\ -> Fixed Drive # 152 GB (32 GB free - 21%) [] # NTFS
      E:\ -> CD-ROM
      G:\ -> Removable Drive # 7 GB (6 GB free - 80%) [USB TOSHIBA] # FAT32

      ################## | Active Processes |

      C:\Windows\system32\csrss.exe (ID: 404 |ParentID: 396)
      C:\Windows\system32\wininit.exe (ID: 460 |ParentID: 396)
      C:\Windows\system32\csrss.exe (ID: 468 |ParentID: 448)
      C:\Windows\system32\services.exe (ID: 520 |ParentID: 460)
      C:\Windows\system32\lsass.exe (ID: 536 |ParentID: 460)
      C:\Windows\system32\lsm.exe (ID: 544 |ParentID: 460)
      C:\Windows\system32\winlogon.exe (ID: 684 |ParentID: 448)
      C:\Windows\system32\svchost.exe (ID: 708 |ParentID: 520)
      C:\Windows\system32\svchost.exe (ID: 804 |ParentID: 520)
      C:\Windows\System32\svchost.exe (ID: 860 |ParentID: 520)
      C:\Windows\System32\svchost.exe (ID: 964 |ParentID: 520)
      C:\Windows\system32\svchost.exe (ID: 1004 |ParentID: 520)
      C:\Windows\system32\svchost.exe (ID: 1176 |ParentID: 520)
      C:\Windows\system32\svchost.exe (ID: 1280 |ParentID: 520)
      C:\Windows\system32\svchost.exe (ID: 1472 |ParentID: 520)
      C:\Program Files\AVAST Software\Avast\AvastSvc.exe (ID: 1504 |ParentID: 520)
      C:\Windows\System32\spoolsv.exe (ID: 1872 |ParentID: 520)
      C:\Program Files\Common Files\DeviceHelper\DeviceManager.exe (ID: 2028 |ParentID: 520)
      C:\Windows\system32\HPSIsvc.exe (ID: 368 |ParentID: 520)
      C:\Windows\system32\taskhost.exe (ID: 452 |ParentID: 520)
      C:\Windows\system32\Dwm.exe (ID: 1264 |ParentID: 964)
      C:\Windows\Explorer.EXE (ID: 1536 |ParentID: 1092)
      C:\Windows\system32\taskeng.exe (ID: 1376 |ParentID: 1004)
      C:\Windows\system32\Rundll32.exe (ID: 1380 |ParentID: 1376)
      C:\Program Files\Protected Search\ProtectedSearch.exe (ID: 2008 |ParentID: 1376)
      C:\ProgramData\DatacardService\HWDeviceService.exe (ID: 1980 |ParentID: 520)
      C:\ProgramData\DatacardService\DCSHelper.exe (ID: 2100 |ParentID: 1980)
      C:\Program Files\Google\Update\1.3.21.165\GoogleCrashHandler.exe (ID: 2216 |ParentID: 1732)
      C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe (ID: 2432 |ParentID: 1536)
      C:\Windows\System32\hkcmd.exe (ID: 2580 |ParentID: 1536)
      C:\Windows\System32\igfxpers.exe (ID: 2596 |ParentID: 1536)
      C:\Windows\system32\igfxsrvc.exe (ID: 2640 |ParentID: 708)
      C:\Program Files\Activ Software\ActivDriver\ActivControl2.exe (ID: 2716 |ParentID: 1536)
      C:\Program Files\USB Disk Security\USBGuard.exe (ID: 2744 |ParentID: 1536)
      C:\Program Files\AVAST Software\Avast\avastui.exe (ID: 2756 |ParentID: 1536)
      C:\Program Files\Winamp\winampa.exe (ID: 2808 |ParentID: 1536)
      C:\Program Files\Activ Software\ActivDriver\activmgr.exe (ID: 2816 |ParentID: 2716)
      C:\Program Files\LG Electronics\LG EV-DO Rev.A USB Modem\Modem Software\REVAService.exe (ID: 2848 |ParentID: 1536)
      C:\Program Files\Skype\Phone\Skype.exe (ID: 2860 |ParentID: 1536)
      C:\Users\WINDOWS\AppData\Roaming\SkypEmoticons\SE.exe (ID: 2940 |ParentID: 1536)
      C:\Users\WINDOWS\AppData\Local\iLivid\iLivid.exe (ID: 2960 |ParentID: 1536)
      C:\Program Files\Internet Download Manager\IDMan.exe (ID: 3048 |ParentID: 1536)
      C:\Users\WINDOWS\AppData\Local\CatalinaGroup\Update\1.3.25.204\CatalinaCrashHandler.exe (ID: 3068 |ParentID: 2972)
      C:\Program Files\RioStudio\Server\Server.exe (ID: 3244 |ParentID: 1536)
      C:\Program Files\Nitro PDF\Reader 2\NitroPDFReaderDriverService2.exe (ID: 3436 |ParentID: 520)
      C:\Program Files\Photodex\ProShowGold\ScsiAccess.exe (ID: 3572 |ParentID: 520)
      C:\ProgramData\Skype\Toolbars\Skype C2C Service\c2c_service.exe (ID: 3652 |ParentID: 520)
      C:\Windows\system32\svchost.exe (ID: 4000 |ParentID: 520)
      C:\Program Files\LemurLeap\updateLemurLeap.exe (ID: 4088 |ParentID: 520)
      C:\Program Files\LemurLeap\bin\utilLemurLeap.exe (ID: 352 |ParentID: 520)
      C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE (ID: 2368 |ParentID: 520)
      C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe (ID: 2564 |ParentID: 2368)
      C:\Windows\system32\SearchIndexer.exe (ID: 2888 |ParentID: 520)
      C:\Windows\system32\svchost.exe (ID: 3452 |ParentID: 520)
      C:\Windows\system32\svchost.exe (ID: 3156 |ParentID: 520)
      C:\Windows\system32\svchost.exe (ID: 3904 |ParentID: 520)
      C:\Program Files\Windows Media Player\wmpnetwk.exe (ID: 4312 |ParentID: 520)
      C:\Users\WINDOWS\AppData\Local\Google\Chrome\Application\chrome.exe (ID: 4768 |ParentID: 1536)
      C:\Users\WINDOWS\AppData\Local\Google\Chrome\Application\chrome.exe (ID: 4924 |ParentID: 4768)
      C:\Users\WINDOWS\AppData\Local\Google\Chrome\Application\chrome.exe (ID: 5244 |ParentID: 4768)
      C:\Users\WINDOWS\AppData\Local\Google\Chrome\Application\chrome.exe (ID: 5532 |ParentID: 4768)
      C:\Windows\System32\svchost.exe (ID: 6080 |ParentID: 520)
      C:\Windows\system32\wuauclt.exe (ID: 1884 |ParentID: 1004)
      C:\Users\WINDOWS\AppData\Local\Google\Chrome\Application\chrome.exe (ID: 6072 |ParentID: 4768)
      C:\Windows\system32\cmd.exe (ID: 648 |ParentID: 1536)
      C:\Windows\system32\conhost.exe (ID: 5008 |ParentID: 468)
      C:\Users\WINDOWS\AppData\Local\Google\Chrome\Application\chrome.exe (ID: 928 |ParentID: 4768)
      C:\Users\WINDOWS\AppData\Local\Google\Chrome\Application\chrome.exe (ID: 1888 |ParentID: 4768)
      C:\UsbFix\Go.exe (ID: 4600 |ParentID: 1540)
      C:\Windows\System32\WUDFHost.exe (ID: 3424 |ParentID: 964)
      \\?\C:\Windows\system32\wbem\WMIADAP.EXE (ID: 896 |ParentID: 1004)
      C:\Windows\system32\wbem\wmiprvse.exe (ID: 2900 |ParentID: 708)
      C:\Windows\system32\wbem\wmiprvse.exe (ID: 168 |ParentID: 708)

      ################## | Regedit Run |

      04 - HKLM\SOFTWARE | Run: [GrooveMonitor] - "C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe"
      04 - HKLM\SOFTWARE | Run: [NeroCheck] - C:\Windows\system32\NeroCheck.exe
      04 - HKLM\SOFTWARE | Run: [TkBellExe] - "C:\Program Files\Real\RealPlayer\update\realsched.exe" -osboot
      04 - HKLM\SOFTWARE | Run: [IgfxTray] - C:\Windows\system32\igfxtray.exe
      04 - HKLM\SOFTWARE | Run: [HotKeysCmds] - C:\Windows\system32\hkcmd.exe
      04 - HKLM\SOFTWARE | Run: [Persistence] - C:\Windows\system32\igfxpers.exe
      04 - HKLM\SOFTWARE | Run: [ActivControl] - C:\Program Files\Activ Software\ActivDriver\ActivControl2.exe
      04 - HKLM\SOFTWARE | Run: [USB Security] - C:\Program Files\USB Disk Security\USBGuard.exe
      04 - HKLM\SOFTWARE | Run: [AvastUI.exe] - "C:\Program Files\AVAST Software\Avast\AvastUI.exe" /nogui
      04 - HKLM\SOFTWARE | Run: [WinampAgent] - "C:\Program Files\Winamp\winampa.exe"
      04 - HKLM\SOFTWARE | Run: [20131121] - C:\Program Files\AVAST Software\Avast\setup\emupdate\25d669ff-fa6b-4e77-95be-072b15d2b673.exe /check
      04 - HKLM\SOFTWARE | RunOnce: [] -
      04 - HKU\S-1-5-19\SOFTWARE | Run: [Sidebar] - %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun
      04 - HKU\S-1-5-20\SOFTWARE | Run: [Sidebar] - %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun
      04 - HKU\S-1-5-21-363042910-2385499109-2152790226-1000\SOFTWARE | Run: [uTorrent] - "C:\Program Files\uTorrent\uTorrent.exe" /MINIMIZED
      04 - HKU\S-1-5-21-363042910-2385499109-2152790226-1000\SOFTWARE | Run: [REVAService] - C:\Program Files\LG Electronics\LG EV-DO Rev.A USB Modem\Modem Software\REVAService.exe
      04 - HKU\S-1-5-21-363042910-2385499109-2152790226-1000\SOFTWARE | Run: [Media Finder] - "C:\Program Files\Media Finder\Media Finder.exe" /opentotray
      04 - HKU\S-1-5-21-363042910-2385499109-2152790226-1000\SOFTWARE | Run: [Skype] - "C:\Program Files\Skype\Phone\Skype.exe" /minimized /regrun
      04 - HKU\S-1-5-21-363042910-2385499109-2152790226-1000\SOFTWARE | Run: [Facebook Update] - "C:\Users\WINDOWS\AppData\Local\Facebook\Update\FacebookUpdate.exe" /c /nocrashserver
      04 - HKU\S-1-5-21-363042910-2385499109-2152790226-1000\SOFTWARE | Run: [Serviecs.vbs] - "C:\Users\WINDOWS\AppData\Local\Temp\Serviecs.vbs"
      04 - HKU\S-1-5-21-363042910-2385499109-2152790226-1000\SOFTWARE | Run: [Viber] - "C:\Users\WINDOWS\AppData\Local\Viber\Viber.exe" StartMinimized
      04 - HKU\S-1-5-21-363042910-2385499109-2152790226-1000\SOFTWARE | Run: [se] - "C:\Users\WINDOWS\AppData\Roaming\SkypEmoticons\SE.exe" /minimized
      04 - HKU\S-1-5-21-363042910-2385499109-2152790226-1000\SOFTWARE | Run: [iLivid] - "C:\Users\WINDOWS\AppData\Local\iLivid\iLivid.exe" -autorun
      04 - HKU\S-1-5-21-363042910-2385499109-2152790226-1000\SOFTWARE | Run: [CatalinaGroup Update] - "C:\Users\WINDOWS\AppData\Local\CatalinaGroup\Update\CatalinaUpdate.exe" /c
      04 - HKU\S-1-5-21-363042910-2385499109-2152790226-1000\SOFTWARE | Run: [BackgroundContainer] - "C:\Windows\system32\Rundll32.exe" "C:\Users\WINDOWS\AppData\Local\Conduit\BackgroundContainer\BackgroundContainer.dll",DllRun
      04 - HKU\S-1-5-21-363042910-2385499109-2152790226-1000\SOFTWARE | Run: [IDMan] - C:\Program Files\Internet Download Manager\IDMan.exe /onboot
      04 - HKU\S-1-5-19\SOFTWARE | RunOnce: [mctadmin] - C:\Windows\System32\mctadmin.exe
      04 - HKU\S-1-5-20\SOFTWARE | RunOnce: [mctadmin] - C:\Windows\System32\mctadmin.exe
      04 - HKU\S-1-5-18\SOFTWARE | RunOnce: [SPReview] - "C:\Windows\System32\SPReview\SPReview.exe" /sp:1 /errorfwlink:"http://go.microsoft.com/fwlink/?LinkID=122915" /build:7601

      ################## | Generic Search |

      Present! D:\Clock to install...exe
      Present! D:\zPharaoh.exe
      Present! G:\oomra 2013-1434.exe
      Present! G:\svt.exe
      Present! G:\students in Europe.exe
      Present! G:\RECYCLER.exe
      Present! G:\oomra 2013-1434 .exe
      Present! G:\SVT .exe
      Present! G:\students in Europe .exe
      Present! G:\RECYCLER .exe
      Present! C:\Users\WINDOWS\AppData\Local\NERDF87.tmp
      Present! C:\Users\WINDOWS\AppData\Roaming\Microsoft\SYSTEM\cste
      Present! C:\Users\WINDOWS\AppData\Local\Temp\APNSetup.exe.tmp
      Present! C:\Users\WINDOWS\AppData\Local\Temp\APNSetup1.exe.tmp
      Present! C:\Users\WINDOWS\AppData\Local\Temp\ADMIN.vbe
      Present! C:\Users\WINDOWS\AppData\Local\Temp\CPBA.bat
      Present! C:\Windows\Tasks\Update23.job
      Present! G:\Recycler\S-8-7-51-6701716238-7502128570-118303462-0338\nFEEDunT.cpl
      Present! G:\Recycler\S-8-7-51-6701716238-7502128570-118303462-0338
      Present! G:\Recycler\S-8-7-51-6701716238-7502128570-118303462-0338\nmwPHrfY.cpl
      Present! G:\Recycler\S-8-7-51-6701716238-7502128570-118303462-0338\lGcZFiWd.cpl
      Present! G:\Recycler\S-8-7-51-6701716238-7502128570-118303462-0338\vviHIFIm.cpl
      Present! G:\Recycler\S-8-7-51-6701716238-7502128570-118303462-0338\UtLSJHms.cpl
      Present! G:\Recycler\S-8-7-51-6701716238-7502128570-118303462-0338\vBlArZIV.cpl
      Present! G:\Recycler\S-8-7-51-6701716238-7502128570-118303462-0338\nqqPuMoE.cpl
      Present! G:\Recycler\S-8-7-51-6701716238-7502128570-118303462-0338\MurNOhLa.cpl
      Present! G:\Recycler\S-8-7-51-6701716238-7502128570-118303462-0338\qIZlMFiB.cpl
      Present! G:\Recycler\S-8-7-51-6701716238-7502128570-118303462-0338\aNkjCrYu.cpl
      Present! G:\Recycler\S-8-7-51-6701716238-7502128570-118303462-0338\NYWmWKPu.cpl
      Present! G:\Recycler\S-8-7-51-6701716238-7502128570-118303462-0338\BcCVIVke.cpl
      Present! G:\Recycler\S-8-7-51-6701716238-7502128570-118303462-0338\DWmZlXqK.cpl
      Present! G:\Recycler\S-8-7-51-6701716238-7502128570-118303462-0338\digTBZrr.cpl
      Present! G:\Recycler\S-8-7-51-6701716238-7502128570-118303462-0338\dBycKTax.cpl
      Present! G:\Recycler\S-8-7-51-6701716238-7502128570-118303462-0338\LAkeEPXh.cpl
      Present! G:\Recycler\S-8-7-51-6701716238-7502128570-118303462-0338\gsBLcpZm.cpl
      Present! G:\Recycler\S-8-7-51-6701716238-7502128570-118303462-0338\XAitJLJi.cpl
      Present! G:\Recycler\S-8-7-51-6701716238-7502128570-118303462-0338\WlkGYCit.cpl
      Present! G:\Recycler\S-8-7-51-6701716238-7502128570-118303462-0338\SRrqcCxX.cpl
      Present! G:\Recycler\S-8-7-51-6701716238-7502128570-118303462-0338\QKGgLFoI.cpl
      Present! G:\Recycler\S-8-7-51-6701716238-7502128570-118303462-0338\JvLZpsOj.cpl
      Present! G:\Recycler\S-8-7-51-6701716238-7502128570-118303462-0338\sYoTFIWG.cpl
      Present! G:\Recycler\S-8-7-51-6701716238-7502128570-118303462-0338\mEsQjTxn.cpl
      Present! G:\Recycler\S-8-7-51-6701716238-7502128570-118303462-0338\LdIbbNfC.cpl
      Present! G:\Recycler\S-8-7-51-6701716238-7502128570-118303462-0338\RRUbxSxf.cpl
      Present! G:\Recycler\S-8-7-51-6701716238-7502128570-118303462-0338\OpNiWPxR.cpl
      Present! G:\Recycler\S-8-7-51-6701716238-7502128570-118303462-0338\pUCwGfwT.cpl
      Present! G:\Recycler\S-8-7-51-6701716238-7502128570-118303462-0338\bpMfTPuD.cpl
      Present! G:\Recycler\S-8-7-51-6701716238-7502128570-118303462-0338\ryUPQXTc.cpl
      Present! G:\Recycler\S-8-7-51-6701716238-7502128570-118303462-0338\BDJTSxOl.cpl
      Present! G:\Recycler\S-8-7-51-6701716238-7502128570-118303462-0338\LrLSqARf.cpl
      Present! G:\Recycler\S-8-7-51-6701716238-7502128570-118303462-0338\qvDbwrhI.cpl
      Present! G:\Recycler\S-8-7-51-6701716238-7502128570-118303462-0338\ylCjAEsO.cpl
      Present! G:\Recycler\S-8-7-51-6701716238-7502128570-118303462-0338\EqhboyxV.cpl
      Present! G:\Recycler\S-8-7-51-6701716238-7502128570-118303462-0338\fursHUGA.cpl
      Present! G:\Recycler\S-8-7-51-6701716238-7502128570-118303462-0338\mloZagmJ.cpl
      Present! G:\Recycler\S-8-7-51-6701716238-7502128570-118303462-0338\ubWaWHac.cpl
      Present! G:\Recycler\S-8-7-51-6701716238-7502128570-118303462-0338\PhcRiqmE.cpl
      Present! G:\Recycler\S-8-7-51-6701716238-7502128570-118303462-0338\JVxRfkAw.cpl
      Present! G:\Recycler\S-8-7-51-6701716238-7502128570-118303462-0338\kbLwOjoB.cpl
      Present! G:\Recycler\S-8-7-51-6701716238-7502128570-118303462-0338\fVPkeEVJ.cpl
      Present! G:\Recycler\S-8-7-51-6701716238-7502128570-118303462-0338\aTxsrpti.cpl
      Present! G:\Recycler\S-8-7-51-6701716238-7502128570-118303462-0338\YFaHYEir.cpl
      Present! G:\Recycler\S-8-7-51-6701716238-7502128570-118303462-0338\yyKbSxiX.cpl
      Present! G:\Recycler\S-8-7-51-6701716238-7502128570-118303462-0338\ZVTTXugD.cpl
      Present! G:\Recycler\S-8-7-51-6701716238-7502128570-118303462-0338\BQZXoEwp.cpl
      Present! G:\Recycler\S-8-7-51-6701716238-7502128570-118303462-0338\mnRYuByK.cpl
      Present! G:\Recycler\S-8-7-51-6701716238-7502128570-118303462-0338\LgkRUHnp.cpl
      Present! G:\Recycler\S-8-7-51-6701716238-7502128570-118303462-0338\WBcQReNm.cpl
      Present! G:\Recycler\S-8-7-51-6701716238-7502128570-118303462-0338\xvUpLUem.cpl
      Present! G:\Recycler\S-8-7-51-6701716238-7502128570-118303462-0338\XpEvtAeK.cpl
      Present! G:\Recycler\S-8-7-51-6701716238-7502128570-118303462-0338\BwZMvspi.cpl
      Present! G:\Recycler\S-8-7-51-6701716238-7502128570-118303462-0338\SbDVGaGq.cpl
      Present! G:\Recycler\S-8-7-51-6701716238-7502128570-118303462-0338\COBQBoId.cpl
      Present! G:\Recycler\S-8-7-51-6701716238-7502128570-118303462-0338\GiqMuvIp.cpl
      Present! G:\Recycler\S-8-7-51-6701716238-7502128570-118303462-0338\ZLYkBaAi.cpl
      Present! G:\Recycler\S-8-7-51-6701716238-7502128570-118303462-0338\pvpypoat.cpl
      Present! G:\Recycler\S-8-7-51-6701716238-7502128570-118303462-0338\amNZJajH.cpl
      Present! G:\Recycler\S-8-7-51-6701716238-7502128570-118303462-0338\qQtdCvwX.cpl
      Present! G:\Recycler\S-8-7-51-6701716238-7502128570-118303462-0338\KjxCHOol.cpl

      ################## | MD5 Comparison Reference |

      Md5: E11A368AAA023AC803DFF823CC918920 -> C:\Users\WINDOWS\AppData\Local\Temp\ADMIN.vbe
      Md5: 6983856C4F46B13309C7CBDDFB5E0A01 -> G:\RECYCLER.exe
      Md5: C6B2F301DA7E51FE40E146E5E2A2E3F7 -> G:\RECYCLER .exe
      Md5: 6983856C4F46B13309C7CBDDFB5E0A01 -> G:\RECYCLER.exe
      Md5: C6B2F301DA7E51FE40E146E5E2A2E3F7 -> G:\RECYCLER .exe
      Md5: 6983856C4F46B13309C7CBDDFB5E0A01 -> G:\RECYCLER.exe

      ################## | MD5 Comparison |

      Present! Md5: E11A368AAA023AC803DFF823CC918920 -> C:\Users\WINDOWS\AppData\Local\Temp\ADMIN.vbe
      Present! Md5: 6983856C4F46B13309C7CBDDFB5E0A01 -> G:\RECYCLER.exe
      Present! Md5: C6B2F301DA7E51FE40E146E5E2A2E3F7 -> G:\oomra 2013-1434 .exe
      Present! Md5: C6B2F301DA7E51FE40E146E5E2A2E3F7 -> G:\SVT .exe
      Present! Md5: C6B2F301DA7E51FE40E146E5E2A2E3F7 -> G:\students in Europe .exe
      Present! Md5: C6B2F301DA7E51FE40E146E5E2A2E3F7 -> G:\RECYCLER .exe

      ################## | Registry |

      Present! HKLM\Software\Microsoft\Windows\CurrentVersion\Policies\System|EnableLUA -> 0
      Present! HKLM\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\bitguard.exe
      Present! HKLM\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\bprotect.exe
      Present! HKLM\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\browserdefender.exe
      Present! HKLM\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\browserprotect.exe
      Present! HKU\S-1-5-21-363042910-2385499109-2152790226-1000\Software\Microsoft\Windows\CurrentVersion\Run|Serviecs.vbs
      Present! HKCU\Software\Microsoft\Windows\CurrentVersion\Run|Serviecs.vbs

      ################## | Vaccine |

      (!) This computer is not vaccinated!

      ################## | E.O.F | http://www.usbfix.net - http://www.sosvirus.net |
      0