Remove the RECYCLER.exe virus
Closed
Hello,
please I have a problem with the RECYCLER.exe virus.
When I sent a folder from my PC to my flash drive which was empty before, I found a folder called RECYCLER.exe. It told me it was a virus; I scanned my flash drive but the antivirus didn't detect any viruses, which is strange. And since I copied the folder from my PC, it means this virus is inside, but when I did a full scan, I found nothing.
It told me to show hidden folders by using Control Panel --> Folder Options --> Show hidden files and folders, but the folders remain hidden and when I go back to the folder options, I find the option to show hidden files and folders disabled. I don't know why this problem exists and I can't solve it.
Please help me to destroy this virus and if you have other ideas, please let me know.
Thanks in advance.
please I have a problem with the RECYCLER.exe virus.
When I sent a folder from my PC to my flash drive which was empty before, I found a folder called RECYCLER.exe. It told me it was a virus; I scanned my flash drive but the antivirus didn't detect any viruses, which is strange. And since I copied the folder from my PC, it means this virus is inside, but when I did a full scan, I found nothing.
It told me to show hidden folders by using Control Panel --> Folder Options --> Show hidden files and folders, but the folders remain hidden and when I go back to the folder options, I find the option to show hidden files and folders disabled. I don't know why this problem exists and I can't solve it.
Please help me to destroy this virus and if you have other ideas, please let me know.
Thanks in advance.
Configuration: Windows XP Internet Explorer 7.0
26 answers
-
Security ContributorHey there
No panic
C_XX & Chiquitine29 have created what you need!
Download and install UsbFix from C_XX & Chiquitine29
Connect your external data sources to your PC (USB stick, external hard drive, etc...) that may have been infected without opening them
# Double click on the UsbFix shortcut present on your desktop.
# Choose option 1 (Search)
# Let the tool work.
# Then post the UsbFix.txt report that will appear.
# Note: The UsbFix.txt report is saved at the root of the drive. (C:\UsbFix.txt)
(CTRL+A to select all, CTRL+C to copy and CTRL+V to paste)
# Note: "Process.exe", a component of the tool, is detected by some antivirus software (AntiVir, Dr.Web, Kaspersky Anti-Virus) as a RiskTool.
It is not a virus, but a utility designed to terminate processes.
In the wrong hands, this utility could stop security software (Antivirus, Firewall...) hence the alert issued by these antivirus programs.-
-
-
-
Good evening, I have the same problem and here is my report:
############################## | UsbFix V 7.109 | [Removal]
User: michel bernard (Administrator) # YOUR-409757439B
Updated on 22/02/2013 by El Desaparecido
Launched at 11:41:55 | 25/02/2013
Website: https://www.sosvirus.net/
Contact: contact@sosvirus.org
PC: TOSHIBA (TOSHIBA NB200) (X86-based PC)
CPU: Intel(R) Atom(TM) CPU N280 @ 1.66GHz (1662)
RAM -> [Total: 1014 | Free: 260]
BIOS: Ver 1.00PARTTBL4
BOOT: Normal boot
OS: Microsoft Windows XP Home Edition (5.1.2600 32-Bit) # Service Pack 3
WB: Windows Internet Explorer 7.0.5730.13
SC: Security Center Service [Enabled]
WU: Windows Update Service [Enabled]
FW: Windows FireWall Service [Enabled]
C:\ (%systemdrive%) -> Hard Disk # 75 Go (39 Go free - 53%) [XP] # NTFS
D:\ -> Hard Disk # 73 Go (69 Go free - 94%) [Data] # NTFS
E:\ -> Hard Disk # 298 Go (9 Go free - 3%) [SAMSUNG] # NTFS
F:\ -> Removable Disk # 4 Go (2 Go free - 47%) [] # FAT32
G:\ -> Removable Disk # 8 Go (4 Go free - 55%) [] # FAT32
################## | Stopped Processes |
Stopped! C:\WINDOWS\system32\spoolsv.exe (1860)
Stopped! C:\WINDOWS\Explorer.EXE (1868)
Stopped! C:\WINDOWS\system32\acs.exe (1916)
Stopped! C:\Program Files\TOSHIBA\ConfigFree\CFSvcs.exe (432)
Stopped! C:\WINDOWS\system32\ThpSrv.exe (728)
Stopped! C:\WINDOWS\system32\TODDSrv.exe (792)
Stopped! c:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosBtSrv.exe (856)
Stopped! C:\WINDOWS\system32\SearchIndexer.exe (1416)
Stopped! C:\WINDOWS\system32\igfxtray.exe (260)
Stopped! C:\WINDOWS\system32\igfxsrvc.exe (1248)
Stopped! C:\WINDOWS\system32\hkcmd.exe (580)
Stopped! C:\WINDOWS\system32\igfxpers.exe (636)
Stopped! C:\WINDOWS\RTHDCPL.EXE (724)
Stopped! C:\Program Files\TOSHIBA\ConfigFree\NDSTray.exe (516)
Stopped! C:\Program Files\TOSHIBA\E-KEY\CeEKey.exe (532)
Stopped! C:\WINDOWS\system32\TDispVol.exe (872)
Stopped! C:\Program Files\TOSHIBA\TOSHIBA Zoom Utility\SmoothView.exe (1344)
Stopped! C:\WINDOWS\system32\ZoomingHook.exe (1396)
Stopped! C:\Program Files\TOSHIBA\TouchPad\TPTray.exe (1884)
Stopped! C:\WINDOWS\system32\thpsrv.exe (1644)
Stopped! C:\Program Files\Atheros\ACU.exe (1704)
Stopped! C:\Program Files\Apoint2K\Apoint.exe (1820)
Stopped! C:\Program Files\Camera Assistant Software for Toshiba\traybar.exe (1996)
Stopped! C:\Program Files\AVG Secure Search\vprot.exe (2068)
Stopped! C:\WINDOWS\system32\TPSBattM.exe (2132)
Stopped! C:\WINDOWS\system32\ctfmon.exe (2144)
Stopped! C:\Program Files\TOSHIBA\Toshiba Online Product Information\topi.exe (2168)
Stopped! C:\Program Files\Messenger\msmsgs.exe (2208)
Stopped! C:\Program Files\Microsoft ActiveSync\wcescomm.exe (2232)
Stopped! C:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosBtMng.exe (2288)
Stopped! C:\Program Files\McAfee Security Scan\3.0.318\SSScheduler.exe (2312)
Stopped! C:\PROGRA~1\MICROS~4\rapimgr.exe (2332)
Stopped! C:\Program Files\Windows Desktop Search\WindowsSearch.exe (2340)
Stopped! c:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosA2dp.exe (3560)
Stopped! c:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosBtHid.exe (3752)
Stopped! c:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosBtHsp.exe (2916)
Stopped! C:\Program Files\Apoint2K\Apntex.exe (3712)
Stopped! C:\WINDOWS\system32\wuauclt.exe (1744)
Stopped! C:\Program Files\Mozilla Firefox\firefox.exe (1684)
################## | Infectious Items |
Deleted! C:\DOCUME~1\MICHEL~1\LOCALS~1\Temp\DataCard_Setup.exe
Deleted! C:\DOCUME~1\MICHEL~1\LOCALS~1\Temp\ose00000.exe
Deleted! D:\setupSNK.exe
Deleted! D:\AUTORUN.INF
(!) Temporary files deleted.
################## | Registry |
################## | Mountpoints2 |
Deleted! HKCU\.\.\.\.\Explorer\MountPoints2\{03b4c672-2219-11e1-8e7d-002308a5455f}
Deleted! HKCU\.\.\.\.\Explorer\MountPoints2\{0fb37812-14cf-11e1-8e67-002308a5455f}
Deleted! HKCU\.\.\.\.\Explorer\MountPoints2\{35e283db-254f-11de-8ca7-00235a07d42c}
Deleted! HKCU\.\.\.\.\Explorer\MountPoints2\{6ea21dd2-f9d9-11de-8db2-00235afc9474}
Deleted! HKCU\.\.\.\.\Explorer\MountPoints2\{7f4ce2a8-255d-11de-96e5-00235a07d42c}
Deleted! HKCU\.\.\.\.\Explorer\MountPoints2\{a7fb5a43-17ed-11e1-8e71-002308a5455f}
Deleted! HKCU\.\.\.\.\Explorer\MountPoints2\{aaccac64-2f49-11df-8dba-002258fb4a8c}
################## | Listing |
[24/08/2010 - 17:06:49 | D ] C:\$AVG
[15/03/2010 - 00:42:46 | N | 34802] C:\ASLog.txt
[09/04/2009 - 05:13:23 | N | 0] C:\AUTOEXEC.BAT
[31/12/2009 - 17:16:36 | N | 233] C:\boot.ini
[14/04/2008 - 13:00:00 | N | 4952] C:\Bootfont.bin
[25/02/2013 - 06:11:56 | D ] C:\Config.Msi
[09/04/2009 - 05:13:23 | N | 0] C:\CONFIG.SYS
[31/12/2009 - 17:17:21 | D ] C:\Documents and Settings
[25/02/2013 - 06:08:00 | ASH | 1063702528] C:\hiberfil.sys
[09/04/2009 - 05:38:03 | D ] C:\I386
[31/12/2009 - 17:18:06 | D ] C:\Intel
[09/04/2009 - 05:13:23 | N | 0] C:\IO.SYS
[23/01/2013 - 11:41:19 | D ] C:\kleaner.tmp
[09/04/2009 - 05:13:23 | N | 0] C:\MSDOS.SYS
[02/11/2011 - 20:59:07 | RHD ] C:\MSOCache
[14/04/2008 - 13:00:00 | N | 47564] C:\NTDETECT.COM
[14/04/2008 - 13:00:00 | N | 252240] C:\ntldr
[25/02/2013 - 06:07:59 | ASH | 1598029824] C:\pagefile.sys
[25/02/2013 - 11:17:40 | D ] C:\Program Files
[13/03/2010 - 20:00:51 | SHD ] C:\RECYCLER
[09/04/2009 - 06:11:42 | N | 1832] C:\RHDSetup.log
[09/04/2009 - 05:38:10 | D ] C:\SUPPORT
[08/04/2009 - 17:57:49 | N | 176] C:\SWSTAMP.TXT
[25/01/2013 - 07:05:33 | SHD ] C:\System Volume Information
[10/04/2009 - 00:53:01 | D ] C:\Toshiba
[25/02/2013 - 11:44:31 | D ] C:\UsbFix
[25/02/2013 - 11:45:11 | A | 5610] C:\UsbFix [Clean 1] YOUR-409757439B.txt
[06/06/2010 - 16:22:28 | D ] C:\VALUEADD
[25/02/2013 - 06:10:44 | D ] C:\WINDOWS
[16/05/2012 - 08:58:38 | D ] D:\0db2b9e0c081ab041e8d0acead0e
[17/05/2012 - 10:39:20 | D ] D:\1143c195d0e1151fc9fb
[04/01/2010 - 00:04:09 | D ] D:\12bb6241e6a29abcc68954
[17/05/2012 - 01:46:14 | D ] D:\3f3424430d474e6734d9cfa7aaf1b790
[03/01/2010 - 20:07:26 | D ] D:\597c43a6ec0ca845ffab
[03/01/2010 - 22:25:40 | D ] D:\7c6680354387b167cad4a4550f
[18/05/2012 - 14:58:24 | D ] D:\84a3bdb6e92ab652b2041e8e6a
[03/01/2010 - 22:25:33 | D ] D:\945b1a8bc35789d42b3e7f7481
[03/01/2010 - 20:07:32 | D ] D:\c19856bcd2ea7e3afc5c
[22/05/2012 - 14:49:59 | D ] D:\ec8112c4e2a16e562951a22f49
[22/05/2012 - 13:42:32 | D ] D:\ef89866d4a37491dfacf04b54a01db9a
[01/01/2010 - 03:11:40 | D ] D:\HDDRecovery
[20/04/2009 - 18:49:48 | N | 11] D:\R10806FR.tag
[09/10/2011 - 19:39:18 | SHD ] D:\RECYCLER
[29/02/2012 - 07:05:13 | D ] D:\SMRTNTKY
[24/01/2013 - 07:55:08 | SHD ] D:\System Volume Information
################## | Vaccine |
C:\Autorun.inf -> Vaccine created by UsbFix (El Desaparecido)
D:\Autorun.inf -> Vaccine created by UsbFix (El Desaparecido)
################## | E.O.F | https://www.sosvirus.net/ |
Can you help me?
Thank you -
############################## | UsbFix V 7.152 | [Search]
User: WINDOWS (Administrator) # WINDOWS-PC
Last updated on 20/11/2013 by El Desaparecido - Team SosVirus
Launched at 11:43:19 | 04/12/2013
Website: http://www.usbfix.net
Forum: http://www.sosvirus.net/
Upload Malware: http://www.sosvirus.net/upload_malware.php
Contact: http://www.usbfix.net/contact/
PC: Hewlett-Packard (308A)
CPU: Intel(R) Core(TM)2 Duo CPU T5870 @ 2.00GHz
RAM -> [Total: 3063 | Free: 1570]
Bios: Hewlett-Packard
Boot: Normal boot
OS: Microsoft Windows 7 Ultimate (6.1.7600 32-Bit)
WB: Windows Internet Explorer: 9.0.8112.16421
WB: Mozilla Firefox: 15.0.1
SC: Security Center Service [Enabled]
WU: Windows Update Service [Enabled]
AV: avast! Antivirus [Enabled | Updated]
AS: Windows Defender: 6.1.7600.16385 (win7_rtm.090713-1255)
FW: Windows Firewall Service [Enabled]
C:\ (%systemdrive%) -> Fixed Drive # 146 GB (72 GB free - 49%) [] # NTFS
D:\ -> Fixed Drive # 152 GB (32 GB free - 21%) [] # NTFS
E:\ -> CD-ROM
G:\ -> Removable Drive # 7 GB (6 GB free - 80%) [USB TOSHIBA] # FAT32
################## | Active Processes |
C:\Windows\system32\csrss.exe (ID: 404 |ParentID: 396)
C:\Windows\system32\wininit.exe (ID: 460 |ParentID: 396)
C:\Windows\system32\csrss.exe (ID: 468 |ParentID: 448)
C:\Windows\system32\services.exe (ID: 520 |ParentID: 460)
C:\Windows\system32\lsass.exe (ID: 536 |ParentID: 460)
C:\Windows\system32\lsm.exe (ID: 544 |ParentID: 460)
C:\Windows\system32\winlogon.exe (ID: 684 |ParentID: 448)
C:\Windows\system32\svchost.exe (ID: 708 |ParentID: 520)
C:\Windows\system32\svchost.exe (ID: 804 |ParentID: 520)
C:\Windows\System32\svchost.exe (ID: 860 |ParentID: 520)
C:\Windows\System32\svchost.exe (ID: 964 |ParentID: 520)
C:\Windows\system32\svchost.exe (ID: 1004 |ParentID: 520)
C:\Windows\system32\svchost.exe (ID: 1176 |ParentID: 520)
C:\Windows\system32\svchost.exe (ID: 1280 |ParentID: 520)
C:\Windows\system32\svchost.exe (ID: 1472 |ParentID: 520)
C:\Program Files\AVAST Software\Avast\AvastSvc.exe (ID: 1504 |ParentID: 520)
C:\Windows\System32\spoolsv.exe (ID: 1872 |ParentID: 520)
C:\Program Files\Common Files\DeviceHelper\DeviceManager.exe (ID: 2028 |ParentID: 520)
C:\Windows\system32\HPSIsvc.exe (ID: 368 |ParentID: 520)
C:\Windows\system32\taskhost.exe (ID: 452 |ParentID: 520)
C:\Windows\system32\Dwm.exe (ID: 1264 |ParentID: 964)
C:\Windows\Explorer.EXE (ID: 1536 |ParentID: 1092)
C:\Windows\system32\taskeng.exe (ID: 1376 |ParentID: 1004)
C:\Windows\system32\Rundll32.exe (ID: 1380 |ParentID: 1376)
C:\Program Files\Protected Search\ProtectedSearch.exe (ID: 2008 |ParentID: 1376)
C:\ProgramData\DatacardService\HWDeviceService.exe (ID: 1980 |ParentID: 520)
C:\ProgramData\DatacardService\DCSHelper.exe (ID: 2100 |ParentID: 1980)
C:\Program Files\Google\Update\1.3.21.165\GoogleCrashHandler.exe (ID: 2216 |ParentID: 1732)
C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe (ID: 2432 |ParentID: 1536)
C:\Windows\System32\hkcmd.exe (ID: 2580 |ParentID: 1536)
C:\Windows\System32\igfxpers.exe (ID: 2596 |ParentID: 1536)
C:\Windows\system32\igfxsrvc.exe (ID: 2640 |ParentID: 708)
C:\Program Files\Activ Software\ActivDriver\ActivControl2.exe (ID: 2716 |ParentID: 1536)
C:\Program Files\USB Disk Security\USBGuard.exe (ID: 2744 |ParentID: 1536)
C:\Program Files\AVAST Software\Avast\avastui.exe (ID: 2756 |ParentID: 1536)
C:\Program Files\Winamp\winampa.exe (ID: 2808 |ParentID: 1536)
C:\Program Files\Activ Software\ActivDriver\activmgr.exe (ID: 2816 |ParentID: 2716)
C:\Program Files\LG Electronics\LG EV-DO Rev.A USB Modem\Modem Software\REVAService.exe (ID: 2848 |ParentID: 1536)
C:\Program Files\Skype\Phone\Skype.exe (ID: 2860 |ParentID: 1536)
C:\Users\WINDOWS\AppData\Roaming\SkypEmoticons\SE.exe (ID: 2940 |ParentID: 1536)
C:\Users\WINDOWS\AppData\Local\iLivid\iLivid.exe (ID: 2960 |ParentID: 1536)
C:\Program Files\Internet Download Manager\IDMan.exe (ID: 3048 |ParentID: 1536)
C:\Users\WINDOWS\AppData\Local\CatalinaGroup\Update\1.3.25.204\CatalinaCrashHandler.exe (ID: 3068 |ParentID: 2972)
C:\Program Files\RioStudio\Server\Server.exe (ID: 3244 |ParentID: 1536)
C:\Program Files\Nitro PDF\Reader 2\NitroPDFReaderDriverService2.exe (ID: 3436 |ParentID: 520)
C:\Program Files\Photodex\ProShowGold\ScsiAccess.exe (ID: 3572 |ParentID: 520)
C:\ProgramData\Skype\Toolbars\Skype C2C Service\c2c_service.exe (ID: 3652 |ParentID: 520)
C:\Windows\system32\svchost.exe (ID: 4000 |ParentID: 520)
C:\Program Files\LemurLeap\updateLemurLeap.exe (ID: 4088 |ParentID: 520)
C:\Program Files\LemurLeap\bin\utilLemurLeap.exe (ID: 352 |ParentID: 520)
C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE (ID: 2368 |ParentID: 520)
C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe (ID: 2564 |ParentID: 2368)
C:\Windows\system32\SearchIndexer.exe (ID: 2888 |ParentID: 520)
C:\Windows\system32\svchost.exe (ID: 3452 |ParentID: 520)
C:\Windows\system32\svchost.exe (ID: 3156 |ParentID: 520)
C:\Windows\system32\svchost.exe (ID: 3904 |ParentID: 520)
C:\Program Files\Windows Media Player\wmpnetwk.exe (ID: 4312 |ParentID: 520)
C:\Users\WINDOWS\AppData\Local\Google\Chrome\Application\chrome.exe (ID: 4768 |ParentID: 1536)
C:\Users\WINDOWS\AppData\Local\Google\Chrome\Application\chrome.exe (ID: 4924 |ParentID: 4768)
C:\Users\WINDOWS\AppData\Local\Google\Chrome\Application\chrome.exe (ID: 5244 |ParentID: 4768)
C:\Users\WINDOWS\AppData\Local\Google\Chrome\Application\chrome.exe (ID: 5532 |ParentID: 4768)
C:\Windows\System32\svchost.exe (ID: 6080 |ParentID: 520)
C:\Windows\system32\wuauclt.exe (ID: 1884 |ParentID: 1004)
C:\Users\WINDOWS\AppData\Local\Google\Chrome\Application\chrome.exe (ID: 6072 |ParentID: 4768)
C:\Windows\system32\cmd.exe (ID: 648 |ParentID: 1536)
C:\Windows\system32\conhost.exe (ID: 5008 |ParentID: 468)
C:\Users\WINDOWS\AppData\Local\Google\Chrome\Application\chrome.exe (ID: 928 |ParentID: 4768)
C:\Users\WINDOWS\AppData\Local\Google\Chrome\Application\chrome.exe (ID: 1888 |ParentID: 4768)
C:\UsbFix\Go.exe (ID: 4600 |ParentID: 1540)
C:\Windows\System32\WUDFHost.exe (ID: 3424 |ParentID: 964)
\\?\C:\Windows\system32\wbem\WMIADAP.EXE (ID: 896 |ParentID: 1004)
C:\Windows\system32\wbem\wmiprvse.exe (ID: 2900 |ParentID: 708)
C:\Windows\system32\wbem\wmiprvse.exe (ID: 168 |ParentID: 708)
################## | Regedit Run |
04 - HKLM\SOFTWARE | Run: [GrooveMonitor] - "C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe"
04 - HKLM\SOFTWARE | Run: [NeroCheck] - C:\Windows\system32\NeroCheck.exe
04 - HKLM\SOFTWARE | Run: [TkBellExe] - "C:\Program Files\Real\RealPlayer\update\realsched.exe" -osboot
04 - HKLM\SOFTWARE | Run: [IgfxTray] - C:\Windows\system32\igfxtray.exe
04 - HKLM\SOFTWARE | Run: [HotKeysCmds] - C:\Windows\system32\hkcmd.exe
04 - HKLM\SOFTWARE | Run: [Persistence] - C:\Windows\system32\igfxpers.exe
04 - HKLM\SOFTWARE | Run: [ActivControl] - C:\Program Files\Activ Software\ActivDriver\ActivControl2.exe
04 - HKLM\SOFTWARE | Run: [USB Security] - C:\Program Files\USB Disk Security\USBGuard.exe
04 - HKLM\SOFTWARE | Run: [AvastUI.exe] - "C:\Program Files\AVAST Software\Avast\AvastUI.exe" /nogui
04 - HKLM\SOFTWARE | Run: [WinampAgent] - "C:\Program Files\Winamp\winampa.exe"
04 - HKLM\SOFTWARE | Run: [20131121] - C:\Program Files\AVAST Software\Avast\setup\emupdate\25d669ff-fa6b-4e77-95be-072b15d2b673.exe /check
04 - HKLM\SOFTWARE | RunOnce: [] -
04 - HKU\S-1-5-19\SOFTWARE | Run: [Sidebar] - %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun
04 - HKU\S-1-5-20\SOFTWARE | Run: [Sidebar] - %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun
04 - HKU\S-1-5-21-363042910-2385499109-2152790226-1000\SOFTWARE | Run: [uTorrent] - "C:\Program Files\uTorrent\uTorrent.exe" /MINIMIZED
04 - HKU\S-1-5-21-363042910-2385499109-2152790226-1000\SOFTWARE | Run: [REVAService] - C:\Program Files\LG Electronics\LG EV-DO Rev.A USB Modem\Modem Software\REVAService.exe
04 - HKU\S-1-5-21-363042910-2385499109-2152790226-1000\SOFTWARE | Run: [Media Finder] - "C:\Program Files\Media Finder\Media Finder.exe" /opentotray
04 - HKU\S-1-5-21-363042910-2385499109-2152790226-1000\SOFTWARE | Run: [Skype] - "C:\Program Files\Skype\Phone\Skype.exe" /minimized /regrun
04 - HKU\S-1-5-21-363042910-2385499109-2152790226-1000\SOFTWARE | Run: [Facebook Update] - "C:\Users\WINDOWS\AppData\Local\Facebook\Update\FacebookUpdate.exe" /c /nocrashserver
04 - HKU\S-1-5-21-363042910-2385499109-2152790226-1000\SOFTWARE | Run: [Serviecs.vbs] - "C:\Users\WINDOWS\AppData\Local\Temp\Serviecs.vbs"
04 - HKU\S-1-5-21-363042910-2385499109-2152790226-1000\SOFTWARE | Run: [Viber] - "C:\Users\WINDOWS\AppData\Local\Viber\Viber.exe" StartMinimized
04 - HKU\S-1-5-21-363042910-2385499109-2152790226-1000\SOFTWARE | Run: [se] - "C:\Users\WINDOWS\AppData\Roaming\SkypEmoticons\SE.exe" /minimized
04 - HKU\S-1-5-21-363042910-2385499109-2152790226-1000\SOFTWARE | Run: [iLivid] - "C:\Users\WINDOWS\AppData\Local\iLivid\iLivid.exe" -autorun
04 - HKU\S-1-5-21-363042910-2385499109-2152790226-1000\SOFTWARE | Run: [CatalinaGroup Update] - "C:\Users\WINDOWS\AppData\Local\CatalinaGroup\Update\CatalinaUpdate.exe" /c
04 - HKU\S-1-5-21-363042910-2385499109-2152790226-1000\SOFTWARE | Run: [BackgroundContainer] - "C:\Windows\system32\Rundll32.exe" "C:\Users\WINDOWS\AppData\Local\Conduit\BackgroundContainer\BackgroundContainer.dll",DllRun
04 - HKU\S-1-5-21-363042910-2385499109-2152790226-1000\SOFTWARE | Run: [IDMan] - C:\Program Files\Internet Download Manager\IDMan.exe /onboot
04 - HKU\S-1-5-19\SOFTWARE | RunOnce: [mctadmin] - C:\Windows\System32\mctadmin.exe
04 - HKU\S-1-5-20\SOFTWARE | RunOnce: [mctadmin] - C:\Windows\System32\mctadmin.exe
04 - HKU\S-1-5-18\SOFTWARE | RunOnce: [SPReview] - "C:\Windows\System32\SPReview\SPReview.exe" /sp:1 /errorfwlink:"http://go.microsoft.com/fwlink/?LinkID=122915" /build:7601
################## | Generic Search |
Present! D:\Clock to install...exe
Present! D:\zPharaoh.exe
Present! G:\oomra 2013-1434.exe
Present! G:\svt.exe
Present! G:\students in Europe.exe
Present! G:\RECYCLER.exe
Present! G:\oomra 2013-1434 .exe
Present! G:\SVT .exe
Present! G:\students in Europe .exe
Present! G:\RECYCLER .exe
Present! C:\Users\WINDOWS\AppData\Local\NERDF87.tmp
Present! C:\Users\WINDOWS\AppData\Roaming\Microsoft\SYSTEM\cste
Present! C:\Users\WINDOWS\AppData\Local\Temp\APNSetup.exe.tmp
Present! C:\Users\WINDOWS\AppData\Local\Temp\APNSetup1.exe.tmp
Present! C:\Users\WINDOWS\AppData\Local\Temp\ADMIN.vbe
Present! C:\Users\WINDOWS\AppData\Local\Temp\CPBA.bat
Present! C:\Windows\Tasks\Update23.job
Present! G:\Recycler\S-8-7-51-6701716238-7502128570-118303462-0338\nFEEDunT.cpl
Present! G:\Recycler\S-8-7-51-6701716238-7502128570-118303462-0338
Present! G:\Recycler\S-8-7-51-6701716238-7502128570-118303462-0338\nmwPHrfY.cpl
Present! G:\Recycler\S-8-7-51-6701716238-7502128570-118303462-0338\lGcZFiWd.cpl
Present! G:\Recycler\S-8-7-51-6701716238-7502128570-118303462-0338\vviHIFIm.cpl
Present! G:\Recycler\S-8-7-51-6701716238-7502128570-118303462-0338\UtLSJHms.cpl
Present! G:\Recycler\S-8-7-51-6701716238-7502128570-118303462-0338\vBlArZIV.cpl
Present! G:\Recycler\S-8-7-51-6701716238-7502128570-118303462-0338\nqqPuMoE.cpl
Present! G:\Recycler\S-8-7-51-6701716238-7502128570-118303462-0338\MurNOhLa.cpl
Present! G:\Recycler\S-8-7-51-6701716238-7502128570-118303462-0338\qIZlMFiB.cpl
Present! G:\Recycler\S-8-7-51-6701716238-7502128570-118303462-0338\aNkjCrYu.cpl
Present! G:\Recycler\S-8-7-51-6701716238-7502128570-118303462-0338\NYWmWKPu.cpl
Present! G:\Recycler\S-8-7-51-6701716238-7502128570-118303462-0338\BcCVIVke.cpl
Present! G:\Recycler\S-8-7-51-6701716238-7502128570-118303462-0338\DWmZlXqK.cpl
Present! G:\Recycler\S-8-7-51-6701716238-7502128570-118303462-0338\digTBZrr.cpl
Present! G:\Recycler\S-8-7-51-6701716238-7502128570-118303462-0338\dBycKTax.cpl
Present! G:\Recycler\S-8-7-51-6701716238-7502128570-118303462-0338\LAkeEPXh.cpl
Present! G:\Recycler\S-8-7-51-6701716238-7502128570-118303462-0338\gsBLcpZm.cpl
Present! G:\Recycler\S-8-7-51-6701716238-7502128570-118303462-0338\XAitJLJi.cpl
Present! G:\Recycler\S-8-7-51-6701716238-7502128570-118303462-0338\WlkGYCit.cpl
Present! G:\Recycler\S-8-7-51-6701716238-7502128570-118303462-0338\SRrqcCxX.cpl
Present! G:\Recycler\S-8-7-51-6701716238-7502128570-118303462-0338\QKGgLFoI.cpl
Present! G:\Recycler\S-8-7-51-6701716238-7502128570-118303462-0338\JvLZpsOj.cpl
Present! G:\Recycler\S-8-7-51-6701716238-7502128570-118303462-0338\sYoTFIWG.cpl
Present! G:\Recycler\S-8-7-51-6701716238-7502128570-118303462-0338\mEsQjTxn.cpl
Present! G:\Recycler\S-8-7-51-6701716238-7502128570-118303462-0338\LdIbbNfC.cpl
Present! G:\Recycler\S-8-7-51-6701716238-7502128570-118303462-0338\RRUbxSxf.cpl
Present! G:\Recycler\S-8-7-51-6701716238-7502128570-118303462-0338\OpNiWPxR.cpl
Present! G:\Recycler\S-8-7-51-6701716238-7502128570-118303462-0338\pUCwGfwT.cpl
Present! G:\Recycler\S-8-7-51-6701716238-7502128570-118303462-0338\bpMfTPuD.cpl
Present! G:\Recycler\S-8-7-51-6701716238-7502128570-118303462-0338\ryUPQXTc.cpl
Present! G:\Recycler\S-8-7-51-6701716238-7502128570-118303462-0338\BDJTSxOl.cpl
Present! G:\Recycler\S-8-7-51-6701716238-7502128570-118303462-0338\LrLSqARf.cpl
Present! G:\Recycler\S-8-7-51-6701716238-7502128570-118303462-0338\qvDbwrhI.cpl
Present! G:\Recycler\S-8-7-51-6701716238-7502128570-118303462-0338\ylCjAEsO.cpl
Present! G:\Recycler\S-8-7-51-6701716238-7502128570-118303462-0338\EqhboyxV.cpl
Present! G:\Recycler\S-8-7-51-6701716238-7502128570-118303462-0338\fursHUGA.cpl
Present! G:\Recycler\S-8-7-51-6701716238-7502128570-118303462-0338\mloZagmJ.cpl
Present! G:\Recycler\S-8-7-51-6701716238-7502128570-118303462-0338\ubWaWHac.cpl
Present! G:\Recycler\S-8-7-51-6701716238-7502128570-118303462-0338\PhcRiqmE.cpl
Present! G:\Recycler\S-8-7-51-6701716238-7502128570-118303462-0338\JVxRfkAw.cpl
Present! G:\Recycler\S-8-7-51-6701716238-7502128570-118303462-0338\kbLwOjoB.cpl
Present! G:\Recycler\S-8-7-51-6701716238-7502128570-118303462-0338\fVPkeEVJ.cpl
Present! G:\Recycler\S-8-7-51-6701716238-7502128570-118303462-0338\aTxsrpti.cpl
Present! G:\Recycler\S-8-7-51-6701716238-7502128570-118303462-0338\YFaHYEir.cpl
Present! G:\Recycler\S-8-7-51-6701716238-7502128570-118303462-0338\yyKbSxiX.cpl
Present! G:\Recycler\S-8-7-51-6701716238-7502128570-118303462-0338\ZVTTXugD.cpl
Present! G:\Recycler\S-8-7-51-6701716238-7502128570-118303462-0338\BQZXoEwp.cpl
Present! G:\Recycler\S-8-7-51-6701716238-7502128570-118303462-0338\mnRYuByK.cpl
Present! G:\Recycler\S-8-7-51-6701716238-7502128570-118303462-0338\LgkRUHnp.cpl
Present! G:\Recycler\S-8-7-51-6701716238-7502128570-118303462-0338\WBcQReNm.cpl
Present! G:\Recycler\S-8-7-51-6701716238-7502128570-118303462-0338\xvUpLUem.cpl
Present! G:\Recycler\S-8-7-51-6701716238-7502128570-118303462-0338\XpEvtAeK.cpl
Present! G:\Recycler\S-8-7-51-6701716238-7502128570-118303462-0338\BwZMvspi.cpl
Present! G:\Recycler\S-8-7-51-6701716238-7502128570-118303462-0338\SbDVGaGq.cpl
Present! G:\Recycler\S-8-7-51-6701716238-7502128570-118303462-0338\COBQBoId.cpl
Present! G:\Recycler\S-8-7-51-6701716238-7502128570-118303462-0338\GiqMuvIp.cpl
Present! G:\Recycler\S-8-7-51-6701716238-7502128570-118303462-0338\ZLYkBaAi.cpl
Present! G:\Recycler\S-8-7-51-6701716238-7502128570-118303462-0338\pvpypoat.cpl
Present! G:\Recycler\S-8-7-51-6701716238-7502128570-118303462-0338\amNZJajH.cpl
Present! G:\Recycler\S-8-7-51-6701716238-7502128570-118303462-0338\qQtdCvwX.cpl
Present! G:\Recycler\S-8-7-51-6701716238-7502128570-118303462-0338\KjxCHOol.cpl
################## | MD5 Comparison Reference |
Md5: E11A368AAA023AC803DFF823CC918920 -> C:\Users\WINDOWS\AppData\Local\Temp\ADMIN.vbe
Md5: 6983856C4F46B13309C7CBDDFB5E0A01 -> G:\RECYCLER.exe
Md5: C6B2F301DA7E51FE40E146E5E2A2E3F7 -> G:\RECYCLER .exe
Md5: 6983856C4F46B13309C7CBDDFB5E0A01 -> G:\RECYCLER.exe
Md5: C6B2F301DA7E51FE40E146E5E2A2E3F7 -> G:\RECYCLER .exe
Md5: 6983856C4F46B13309C7CBDDFB5E0A01 -> G:\RECYCLER.exe
################## | MD5 Comparison |
Present! Md5: E11A368AAA023AC803DFF823CC918920 -> C:\Users\WINDOWS\AppData\Local\Temp\ADMIN.vbe
Present! Md5: 6983856C4F46B13309C7CBDDFB5E0A01 -> G:\RECYCLER.exe
Present! Md5: C6B2F301DA7E51FE40E146E5E2A2E3F7 -> G:\oomra 2013-1434 .exe
Present! Md5: C6B2F301DA7E51FE40E146E5E2A2E3F7 -> G:\SVT .exe
Present! Md5: C6B2F301DA7E51FE40E146E5E2A2E3F7 -> G:\students in Europe .exe
Present! Md5: C6B2F301DA7E51FE40E146E5E2A2E3F7 -> G:\RECYCLER .exe
################## | Registry |
Present! HKLM\Software\Microsoft\Windows\CurrentVersion\Policies\System|EnableLUA -> 0
Present! HKLM\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\bitguard.exe
Present! HKLM\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\bprotect.exe
Present! HKLM\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\browserdefender.exe
Present! HKLM\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\browserprotect.exe
Present! HKU\S-1-5-21-363042910-2385499109-2152790226-1000\Software\Microsoft\Windows\CurrentVersion\Run|Serviecs.vbs
Present! HKCU\Software\Microsoft\Windows\CurrentVersion\Run|Serviecs.vbs
################## | Vaccine |
(!) This computer is not vaccinated!
################## | E.O.F | http://www.usbfix.net - http://www.sosvirus.net |
-