HELP infected computer

Solved
turbulent13 Posted messages 41 Status Membre -  
crapoulou Posted messages 28002 Registration date   Status Modérateur, Contributeur sécurité Last intervention   -
Hello,
Hello everyone,
I'm writing to you today because I'm having quite a few issues with my PC. Since it wasn't running fast, I tried running scans with various software to locate the problem, followed by antivirus programs which
despite what their reports indicated, didn't seem to work, as the computer still has bugs that I can't resolve.

For example:
when I want to uninstall a program, the "add or remove programs" window takes 5 minutes to open.
Anyway, I imagine my PC is still infected, so if anyone could kindly give me some information to help me get rid of these little problems for good, it would be really nice.

Thanks in advance.
Configuration: Windows XP Firefox 3.0.10

57 réponses

  • 1
  • 2
  • 3
dydoudu09om
 
Hi, download Spybot because it's the best antivirus https://www.01net.com/telecharger/windows/Securite/anti-spyware/fiches/26157.html
it goes super fast and if it bugs again, do a defragmentation.
4
darkpoet Posted messages 1696 Status Contributeur sécurité 62
 
download Hijackthis: http://www.trendsecure.com/portal/en-US/tools/security_tools­/hijackthis

.click on download
.click on download Hijackthis installer
.save it to the desktop
.Close all open programs including the browser. except your antivirus and firewall
.install it, it will install by default in C:\Program Files\Trend Micro\HijackThis
.Click on "Do a system scan and save the logfile"
.This will open a notepad at the end of the scan.
.Copy its content and post it in your next message. otherwise the report is in C:\Program Files\Trend Micro\HijackThis\ hijackthis "text document"

if you need help with the installation: https://www.malekal.com/tutoriel-hijackthis/

--
teaching is always learning
0
Anonymous user
 
Hey,

to follow

--
alcohol kills slowly, we don't care, we're not in a hurry......
0
crapoulou Posted messages 28002 Registration date   Status Modérateur, Contributeur sécurité Last intervention   8 046
 
Hi,
Wow! I just learned that Spybot was an antivirus!
You're surprising all the helpers!
I'm sure V-X and darkpoet didn't know that!
See you later and good luck.
--
Got a problem? Head over to CCM!
There is no problem without a solution.
0
darkpoet Posted messages 1696 Status Contributeur sécurité 62
 
Yes, and with CCleaner, you turn your PC into a liquid-cooled machine with neon lights and an infinitely memory disk, lol

--
to teach is always to learn
0
turbulent13 Posted messages 41 Status Membre
 
Hi everyone, here is the HijackThis report, hoping there’s nothing too serious... waiting for your responses. Thanks a lot.

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 19:12:42, on 01/06/2009
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v8.00 (8.00.6001.18702)
Boot mode: Normal

Running processes:
D:\WINDOWS\System32\smss.exe
D:\WINDOWS\system32\winlogon.exe
D:\WINDOWS\system32\services.exe
D:\WINDOWS\system32\lsass.exe
D:\WINDOWS\system32\svchost.exe
D:\WINDOWS\System32\svchost.exe
D:\WINDOWS\system32\svchost.exe
D:\WINDOWS\system32\spoolsv.exe
D:\Program Files\Common Files\ArcSoft\Connection Service\Bin\ACService.exe
D:\PROGRA~1\COMMON~1\AOL\ACS\AOLacsd.exe
D:\Program Files\Orange\AntivirusFirewall\Anti-Virus\fsgk32st.exe
D:\Program Files\Orange\AntivirusFirewall\Common\FSMA32.EXE
D:\Program Files\Orange\AntivirusFirewall\Anti-Virus\FSGK32.EXE
D:\WINDOWS\system32\nvsvc32.exe
D:\Program Files\Orange\AntivirusFirewall\Common\FSMB32.EXE
D:\WINDOWS\system32\svchost.exe
D:\Program Files\Orange\AntivirusFirewall\Common\FCH32.EXE
D:\Program Files\Orange\AntivirusFirewall\Common\FAMEH32.EXE
D:\Program Files\Orange\AntivirusFirewall\Anti-Virus\fsqh.exe
D:\Program Files\Orange\AntivirusFirewall\FSAUA\program\fsaua.exe
D:\Program Files\Orange\AntivirusFirewall\FWES\Program\fsdfwd.exe
D:\Program Files\Orange\AntivirusFirewall\Anti-Virus\fssm32.exe
D:\Program Files\Orange\AntivirusFirewall\FSAUA\program\fsus.exe
D:\Program Files\Orange\AntivirusFirewall\Anti-Virus\fsav32.exe
D:\WINDOWS\system32\WgaTray.exe
D:\WINDOWS\Explorer.EXE
D:\Program Files\Real\RealPlayer\RealPlay.exe
D:\Program Files\Orange\AntivirusFirewall\Common\FSM32.EXE
D:\WINDOWS\system32\ctfmon.exe
D:\Program Files\Orange\AntivirusFirewall\FSGUI\fsguidll.exe
D:\WINDOWS\system32\wuauclt.exe
D:\Program Files\Mozilla Firefox\firefox.exe
D:\WINDOWS\system32\wuauclt.exe
D:\Program Files\Trend Micro\HijackThis\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = https://www.msn.com/fr-fr/?ocid=iehp
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = https://www.orange.fr/portail?kw=
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://google.atcomet.com/b/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = https://www.msn.com/fr-fr/?ocid=iehp
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.msn.com/fr-fr/?ocid=iehp
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Links
R3 - URLSearchHook: Search Class - {08C06D61-F1F3-4799-86F8-BE1A89362C85} - D:\Program Files\OrangeHSS\SearchURLHook\SearchPageURL.dll (file missing)
O2 - BHO: EoRezoBHO - {64F56FC1-1272-44CD-BA6E-39723696E350} - (no file)
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - D:\Program Files\Java\jre1.6.0_06\bin\ssv.dll
O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
O2 - BHO: Windows Live Sign-In Assistant Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - D:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: SWEETIE - {EEE6C35C-6118-11DC-9C72-001320C79847} - (no file)
O3 - Toolbar: (no name) - {EEE6C35B-6118-11DC-9C72-001320C79847} - (no file)
O3 - Toolbar: AOL Toolbar - {4982D40A-C53B-4615-B15B-B5B5E98D167C} - D:\Program Files\AOL Toolbar\toolbar.dll (file missing)
O4 - HKLM\..\Run: [RealTray] D:\Program Files\Real\RealPlayer\RealPlay.exe SYSTEMBOOTHIDEPLAYER
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE D:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [F-Secure Manager] "D:\Program Files\Orange\AntivirusFirewall\Common\FSM32.EXE" /splash
O4 - HKLM\..\Run: [F-Secure TNB] "D:\Program Files\Orange\AntivirusFirewall\FSGUI\TNBUtil.exe" /CHECKALL /WAITFORSW
O4 - HKCU\..\Run: [ctfmon.exe] D:\WINDOWS\system32\ctfmon.exe
O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] D:\WINDOWS\system32\CTFMON.EXE (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-19\..\RunOnce: [nltide_3] rundll32 advpack.dll,LaunchINFSectionEx nLite.inf,C,,4,N (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] D:\WINDOWS\system32\CTFMON.EXE (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-20\..\RunOnce: [nltide_3] rundll32 advpack.dll,LaunchINFSectionEx nLite.inf,C,,4,N (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] D:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\S-1-5-18\..\RunOnce: [nltide_3] rundll32 advpack.dll,LaunchINFSectionEx nLite.inf,C,,4,N (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] D:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
O4 - HKUS\.DEFAULT\..\RunOnce: [nltide_3] rundll32 advpack.dll,LaunchINFSectionEx nLite.inf,C,,4,N (User 'Default user')
O8 - Extra context menu item: &Search AOL Toolbar - res://D:\Program Files\AOL Toolbar\toolbar.dll/SEARCH.HTML
O8 - Extra context menu item: Add to AMV Converter... - C:\AMVConverter\grab.html
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\Office10\EXCEL.EXE/3000
O8 - Extra context menu item: MediaManager tool grab multimedia file - C:\MediaManager\grab.html
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - D:\Program Files\Java\jre1.6.0_06\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Java Console (Sun) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - D:\Program Files\Java\jre1.6.0_06\bin\ssv.dll
O9 - Extra button: AOL Toolbar - {4982D40A-C53B-4615-B15B-B5B5E98D167C} - D:\Program Files\AOL Toolbar\toolbar.dll (file missing)
O9 - Extra 'Tools' menuitem: AOL Toolbar - {4982D40A-C53B-4615-B15B-B5B5E98D167C} - D:\Program Files\AOL Toolbar\toolbar.dll (file missing)
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - D:\WINDOWS\system32\Shdocvw.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - D:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - D:\Program Files\Messenger\msmsgs.exe
O10 - Unknown file in Winsock LSP: d:\windows\system32\nwprovau.dll
O17 - HKLM\System\CCS\Services\Tcpip\..\{CB32D5A6-B35C-4DD8-8A18-D5C55C029EC9}: NameServer = 86.64.145.144,84.103.237.144
O23 - Service: ArcSoft Connect Daemon (ACDaemon) - ArcSoft Inc. - D:\Program Files\Common Files\ArcSoft\Connection Service\Bin\ACService.exe
O23 - Service: AOL Connectivity Service (AOL ACS) - America Online, Inc. - D:\PROGRA~1\COMMON~1\AOL\ACS\AOLacsd.exe
O23 - Service: FSGKHS (F-Secure Gatekeeper Handler Starter) - F-Secure Corporation - D:\Program Files\Orange\AntivirusFirewall\Anti-Virus\fsgk32st.exe
O23 - Service: Firebird Server - MAGIX Instance (FirebirdServerMAGIXInstance) - Unknown owner - E:\Program Files\MAGIX\Common\Database\bin\fbserver.exe (file missing)
O23 - Service: F-Secure Automatic Update Agent (FSAUA) - F-Secure Corporation - D:\Program Files\Orange\AntivirusFirewall\FSAUA\program\fsaua.exe
O23 - Service: F-Secure Anti-Virus Firewall Daemon (FSDFWD) - F-Secure Corporation - D:\Program Files\Orange\AntivirusFirewall\FWES\Program\fsdfwd.exe
O23 - Service: F-Secure Management Agent (FSMA) - F-Secure Corporation - D:\Program Files\Orange\AntivirusFirewall\Common\FSMA32.EXE
O23 - Service: F-Secure ORSP Client (FSORSPClient) - F-Secure Corporation - D:\Program Files\Orange\AntivirusFirewall\ORSP Client\fsorsp.exe
O23 - Service: Ma-Config Service (maconfservice) - Unknown owner - C:\maconfservice.exe (file missing)
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - D:\WINDOWS\system32\nvsvc32.exe

--
0
darkpoet Posted messages 1696 Status Contributeur sécurité 62
 
The accumulation of antivirus software can significantly slow down the system; it is advised to have only one antivirus. Here, I would keep Antivir and remove Orange.

Then do this:

Download http://sd-1.archive-host.com/membres/up/16506160323759868/AD-R.exe]Ad-Remover (by Cyrildu17 / C_XX) to your Desktop.

/!\ Disconnect and close all running applications /!\

Double-click the installer, and install it in its default location (C:\Program files).
Double-click the Ad-Remover shortcut located on your Desktop.
(On Vista, right-click the Ad-Remover shortcut and choose Run as administrator)
In the main menu, choose option A.
Post the report that appears at the end (C:\Ad-Report-Scan-(date).log).

(CTRL+A to select all, CTRL+C to copy, and CTRL+V to paste)

Note: "Process.exe," a component of the tool, is detected by some antivirus software (AntiVir, Dr.Web, Kaspersky Anti-Virus) as a RiskTool.--
To teach is to always learn.
0
crapoulou Posted messages 28002 Registration date   Status Modérateur, Contributeur sécurité Last intervention   8 046
 
There is no more option A ...
Just launch it and that's enough :D
--
Got a problem? Head over to CCM!
There is no problem without a solution.
0
darkpoet Posted messages 1696 Status Contributeur sécurité 62
 
Thank you, I’m updating my information
--
to teach is always to learn
0
darkpoet Posted messages 1696 Status Contributeur sécurité 62
 
here you go

▶ Download Ad-remover (from C_XX) to your desktop:

! Log out and close all running applications !

▶ Double-click on "Ad-R.exe" to start the installation and leave the installation settings at default.

▶ Double-click on the shortcut Ad-remover on your desktop to launch the tool.

▶ In the main menu, choose the option "L" and press [enter].

▶ Let the tool work and don’t touch anything ...

▶ Post the report that appears at the end on the forum ...

( The report is also saved under C:\Ad-report.log )
( CTRL+A to select all, CTRL+C to copy, and CTRL+V to paste )

Note: "Process.exe", a component of the tool, is detected by some antivirus software (AntiVir, Dr.Web, Kaspersky Anti-Virus) as a RiskTool.
It is not a virus, but a utility designed to terminate processes.
In the wrong hands, this utility could stop security software (Antivirus, Firewall...) hence the alert issued by these antivirus programs.

--
teaching is always learning
0
turbulent13 Posted messages 41 Status Membre
 
THANK YOU FOR GIVING ME A HAND, HERE IS THE AD-REMOVER REPORT:

.
======= AD-REMOVER REPORT 1.1.4.5_B | WINDOWS XP/VISTA ONLY =======
.
Updated by C_XX on 06/01/2009 at 11:50 AM
Contact: AdRemover.contact@gmail.com
Website: http://pagesperso-orange.fr/NosTools/ad_remover.html
.
Launched at: 21:03:25, 06/01/2009 | Normal Mode | Option: CLEAN
Executed from: D:\Program Files\Ad-remover\
Operating System: Microsoft® Windows XP™ Service Pack 2 v5.1.2600
PC Name: PAULO | Current User: POLO
.
Not Administrator: ASPNET
Not Administrator: HelpAssistant *Disabled*
Not Administrator: Guest
Administrator: LogMeInRemoteUser
Administrator: Mika *Disabled*
Administrator: POLO
Not Administrator: SUPPORT_388945a0 *Disabled*
.
============== NEUTRALIZED ITEM(S) ==============
.
.
HKCR\Interface\{B0D071A1-36B3-4757-A126-14C89C56013A}
HKCR\Typelib\{B4C656C9-F2E9-4E77-B3F4-443DF2BD778F}
HKCU\Software\EoRezo
HKCU\Software\FunWebProducts
HKCU\Software\Grand Virtual
HKCU\Software\ItsLabel
HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{EEE6C360-6118-11DC-9C72-001320C79847}
HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{64F56FC1-1272-44CD-BA6E-39723696E350}
HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{EEE6C35B-6118-11DC-9C72-001320C79847}
HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{EEE6C35C-6118-11DC-9C72-001320C79847}
HKCU\Software\PartyGaming
HKCU\Software\Popsicle
HKCU\Software\SweetIM
HKLM\Software\Microsoft\Internet Explorer\SearchScopes\{EEE6C360-6118-11DC-9C72-001320C79847}
HKLM\Software\Microsoft\Shared Tools\MSconfig\Startupreg\My Web Search Bar Search Scope Monitor
HKLM\Software\Microsoft\Windows\CurrentVersion\App Management\ARPCache\MyWebSearch bar Uninstall
HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{64F56FC1-1272-44CD-BA6E-39723696E350}
HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{EEE6C35B-6118-11DC-9C72-001320C79847}
HKLM\Software\Microsoft\Windows\CurrentVersion\Uninstall\{A8955948-E02C-4738-AF22-53CA0F24C90B}_is1
HKLM\Software\SweetIM
HKLM\SYSTEM\ControlSet002\Enum\Root\LEGACY_MYWEBSEARCHSERVICE
HKLM\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_MYWEBSEARCHSERVICE
HKLM\Software\Microsoft\Internet Explorer\Toolbar\\{EEE6C35B-6118-11DC-9C72-001320C79847}
HKCU\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser\\{EEE6C35B-6118-11DC-9C72-001320C79847}
HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\Userdata\S-1-5-18\Components\980289C22F80A7C4BB9323DC61255E4E
HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\Userdata\S-1-5-18\Components\FA96423FE2B98E248A3B23548D1E22D9
.
D:\DOCUME~1\ALLUSE~1\APPLIC~1\SweetIM\Messenger
D:\DOCUME~1\ALLUSE~1\APPLIC~1\SweetIM\Toolbars
D:\DOCUME~1\ALLUSE~1\APPLIC~1\SweetIM\Messenger\conf
D:\DOCUME~1\ALLUSE~1\APPLIC~1\SweetIM\Messenger\data
D:\DOCUME~1\ALLUSE~1\APPLIC~1\SweetIM\Messenger\conf\users
D:\DOCUME~1\ALLUSE~1\APPLIC~1\SweetIM\Messenger\conf\users\koccinel@hotmail.fr
D:\DOCUME~1\ALLUSE~1\APPLIC~1\SweetIM\Messenger\conf\users\main_user_config.xml
D:\DOCUME~1\ALLUSE~1\APPLIC~1\SweetIM\Messenger\conf\users\turbulent13@hotmail.fr
D:\DOCUME~1\ALLUSE~1\APPLIC~1\SweetIM\Messenger\conf\users\koccinel@hotmail.fr\emoticons_shortcut.xml
D:\DOCUME~1\ALLUSE~1\APPLIC~1\SweetIM\Messenger\conf\users\koccinel@hotmail.fr\user_config.xml
D:\DOCUME~1\ALLUSE~1\APPLIC~1\SweetIM\Messenger\conf\users\turbulent13@hotmail.fr\emoticons_shortcut.xml
D:\DOCUME~1\ALLUSE~1\APPLIC~1\SweetIM\Messenger\conf\users\turbulent13@hotmail.fr\lastuse_SpecialFX.xml
D:\DOCUME~1\ALLUSE~1\APPLIC~1\SweetIM\Messenger\conf\users\turbulent13@hotmail.fr\user_config.xml
D:\DOCUME~1\ALLUSE~1\APPLIC~1\SweetIM\Messenger\data\contentdb
D:\DOCUME~1\ALLUSE~1\APPLIC~1\SweetIM\Messenger\data\contentdb\000100B7.dat
D:\DOCUME~1\ALLUSE~1\APPLIC~1\SweetIM\Messenger\data\contentdb\0001081A.dat
D:\DOCUME~1\ALLUSE~1\APPLIC~1\SweetIM\Messenger\data\contentdb\00010859.dat
D:\DOCUME~1\ALLUSE~1\APPLIC~1\SweetIM\Messenger\data\contentdb\0001086F.dat
D:\DOCUME~1\ALLUSE~1\APPLIC~1\SweetIM\Messenger\data\contentdb\00010893.dat
D:\DOCUME~1\ALLUSE~1\APPLIC~1\SweetIM\Messenger\data\contentdb\0001089E.dat
D:\DOCUME~1\ALLUSE~1\APPLIC~1\SweetIM\Messenger\data\contentdb\000108B4.dat
D:\DOCUME~1\ALLUSE~1\APPLIC~1\SweetIM\Messenger\data\contentdb\00020190.dat
D:\DOCUME~1\ALLUSE~1\APPLIC~1\SweetIM\Messenger\data\contentdb\0002020D.dat
D:\DOCUME~1\ALLUSE~1\APPLIC~1\SweetIM\Messenger\data\contentdb\000202C0.dat
D:\DOCUME~1\ALLUSE~1\APPLIC~1\SweetIM\Messenger\data\contentdb\0008000B.dat
D:\DOCUME~1\ALLUSE~1\APPLIC~1\SweetIM\Messenger\data\contentdb\00080011.dat
D:\DOCUME~1\ALLUSE~1\APPLIC~1\SweetIM\Messenger\data\contentdb\0008001E.dat
D:\DOCUME~1\ALLUSE~1\APPLIC~1\SweetIM\Messenger\data\contentdb\0008001F.dat
D:\DOCUME~1\ALLUSE~1\APPLIC~1\SweetIM\Messenger\data\contentdb\00080026.dat
D:\DOCUME~1\ALLUSE~1\APPLIC~1\SweetIM\Messenger\data\contentdb\01050002.dat
D:\DOCUME~1\ALLUSE~1\APPLIC~1\SweetIM\Messenger\data\contentdb\cache_indx.dat
D:\DOCUME~1\ALLUSE~1\APPLIC~1\SweetIM\Toolbars\Internet Explorer
D:\DOCUME~1\ALLUSE~1\APPLIC~1\SweetIM\Toolbars\Internet Explorer\cache
D:\DOCUME~1\ALLUSE~1\APPLIC~1\SweetIM\Toolbars\Internet Explorer\cache\f64a71f602d078aa84829e36b8992194.toolbar31.xml
D:\DOCUME~1\ALLUSE~1\APPLIC~1\SweetIM
D:\DOCUME~1\ALLUSE~1\MENUDM~1\PROGRA~1\EoRezo\EoEngine.lnk
D:\DOCUME~1\ALLUSE~1\MENUDM~1\PROGRA~1\EoRezo
D:\DOCUME~1\POLO\APPLIC~1\EoRezo\cmhost.cyp
D:\DOCUME~1\POLO\APPLIC~1\EoRezo\ConfMedia.cyp
D:\DOCUME~1\POLO\APPLIC~1\EoRezo\db
D:\DOCUME~1\POLO\APPLIC~1\EoRezo\eoDesktop
D:\DOCUME~1\POLO\APPLIC~1\EoRezo\host.cyp
D:\DOCUME~1\POLO\APPLIC~1\EoRezo\user.cyp
D:\DOCUME~1\POLO\APPLIC~1\EoRezo\db\cat.cyp
D:\DOCUME~1\POLO\APPLIC~1\EoRezo\eoDesktop\config.xml
D:\DOCUME~1\POLO\APPLIC~1\EoRezo\eoDesktop\eoDesktop.html
D:\DOCUME~1\POLO\APPLIC~1\EoRezo\eoDesktop\userConfig.xml
D:\DOCUME~1\POLO\APPLIC~1\EoRezo
D:\DOCUME~1\POLO\APPLIC~1\ItsLabel\ItsTV
D:\DOCUME~1\POLO\APPLIC~1\ItsLabel\ItsTV\itsTV.xml
D:\DOCUME~1\POLO\APPLIC~1\ItsLabel
D:\DOCUME~1\ALLUSE~1\DOCUME~1\Foxicle\FFADVPro.dll
D:\DOCUME~1\ALLUSE~1\DOCUME~1\Foxicle\FFADVPro3.dll
D:\DOCUME~1\ALLUSE~1\DOCUME~1\Foxicle\IFFADVPro.xpt
D:\DOCUME~1\ALLUSE~1\DOCUME~1\Foxicle\IFFADVPro3.xpt
D:\DOCUME~1\ALLUSE~1\DOCUME~1\Foxicle\Logo.gif
D:\DOCUME~1\ALLUSE~1\DOCUME~1\Foxicle\main.db
D:\DOCUME~1\ALLUSE~1\DOCUME~1\Foxicle\main.db-journal
D:\DOCUME~1\ALLUSE~1\DOCUME~1\Foxicle\RegistrySearcher.exe
D:\DOCUME~1\ALLUSE~1\DOCUME~1\Foxicle\unins000.dat
D:\DOCUME~1\ALLUSE~1\DOCUME~1\Foxicle\unins000.exe
D:\DOCUME~1\ALLUSE~1\DOCUME~1\Foxicle
D:\WINDOWS\Downloaded Program Files\f3initialsetup1.0.1.0.inf
D:\Program Files\Mozilla FireFox\regxpcom.exe
D:\WINDOWS\Installer\{59971D79-8111-42C2-9E40-883A0C277E78}\ARPPRODUCTICON.exe
D:\WINDOWS\Installer\{59971D79-8111-42C2-9E40-883A0C277E78}
D:\Documents and Settings\Guest\Application Data\Eorezo\ConfMedia.cyp
D:\Documents and Settings\Guest\Application Data\Eorezo\db
D:\Documents and Settings\Guest\Application Data\Eorezo\eoDesktop
D:\Documents and Settings\Guest\Application Data\Eorezo\host.cyp
D:\Documents and Settings\Guest\Application Data\Eorezo\user.cyp
D:\Documents and Settings\Guest\Application Data\Eorezo\db\cat.cyp
D:\Documents and Settings\Guest\Application Data\Eorezo\eoDesktop\config.xml
D:\Documents and Settings\Guest\Application Data\Eorezo\eoDesktop\eoDesktop.html
D:\Documents and Settings\Guest\Application Data\Eorezo\eoDesktop\userConfig.xml
D:\Documents and Settings\Guest\Application Data\Eorezo
D:\Documents and Settings\Guest\Application Data\ItsLabel\ItsTV
D:\Documents and Settings\Guest\Application Data\ItsLabel\ItsTV\itsTV.xml
D:\Documents and Settings\Guest\Application Data\ItsLabel
D:\WINDOWS\Installer\100bcf57.msi
D:\WINDOWS\Prefetch\EVEREST CASINO.EXE-06F073A4.pf

(!) -- Temporary files deleted.

.
============== Additional Scan ==============

* Mozilla FireFox Version 3.0.10 *

Profile Name: p2g8qcd4.default (POLO)
.
(Prefs.js) user_pref("browser.search.selectedEngine", "YouGoo");
(Prefs.js) user_pref("browser.startup.homepage", "hxxp://www.google.fr/firefox");
(Prefs.js) user_pref("browser.startup.homepage_override.mstone", "rv:1.9.0.10");
.
.

* Internet Explorer Version 8.0.6001.18702 *

[HKEY_CURRENT_USER\..\Internet Explorer\Main]

Default_Page_URL: hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&pver=6&ar=msnhome
Default_Search_URL: hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
Search bar: hxxp://go.microsoft.com/fwlink/?linkid=54896
Search Page: hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
Start Page: hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&pver=6&ar=msnhome
Start Page: hxxp://fr.msn.com/?ocid=iehp

[HKEY_LOCAL_MACHINE\..\Internet Explorer\Main]

Default_Page_URL: hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&pver=6&ar=msnhome
Default_Search_URL: hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
Search bar: hxxp://search.msn.com/spbasic.htm
Search Page: hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
Start Page: hxxp://fr.msn.com/

[HKEY_LOCAL_MACHINE\..\Internet Explorer\ABOUTURLS]

Tabs: res://ieframe.dll/tabswelcome.htm

============== Suspect (Cracks, Serials ...) ==============

.

+---------------------------------------------------------------------------+

9582 Bytes - D:\Ad-Report-CLEAN.log

17 File(s) - D:\Program Files\Ad-remover\BACKUP
33 File(s) - D:\Program Files\Ad-remover\QUARANTINE

End at: 21:11:05 | 06/01/2009
.
============== E.O.F ==============
0
darkpoet Posted messages 1696 Status Contributeur sécurité 62
 
Download https://www.majorgeeks.com/­ml MalwareByte's Anti-Malware to your Desktop.

Install it by double-clicking the file Download_mbam-setup.exe.
Once the installation and update are complete:
Restart your computer in safe mode
- At startup, after the BIOS loads, press the F8 key repeatedly until a menu with a black background appears. Once you reach this stage, use the keyboard to select Safe Mode.
-- In this mode, you do not have Internet access, and you will be in a different visual configuration (no wallpaper, very large icons). So don’t be surprised.
--- For these different reasons, I invite you to print, note down, or save the following information in a text document so that you do not get lost.
---- ! Do not start your computer in safe mode via MSConfig!
Why? Some infections break the safe mode keys, which would cause your computer to crash.

Now run [b]MalwareByte's Anti-Malware. If you haven't already, select "Run a Full Scan".
To start the search, click on "Search".
Once the scan is complete, a window will open, click OK. Two options are available to you:

~ If the program found nothing, press OK. A report will appear, close it.
~~ If infections are present, click on "Show Results" then on "Remove Selected". Save the report to your Desktop.
~~~~ Restart your computer normally and post the report in your next response.

NOTE: If MalwareByte's Anti-Malware needs to restart to complete the removal, accept by clicking OK

[b]Note/b: If you can't download MBAM from MajorGeeks, you can download it https://www.besttechie.com/resources/malwarebytes/

Help: http://www.infos-du-net.com/forum/278396-11-tuto-malwarebytes-anti-malware-mbam
http://www.infos-du-net.com/forum/272325-11-tuto-demarrer-mode-echec]How to start your computer in safe mode

--
teaching is always learning
0
turbulent13 Posted messages 41 Status Membre
 
hi
finally back from work, I just ran the analysis with MalwareByte's Anti-Malware in safe mode here is the report

Malwarebytes' Anti-Malware 1.37
Database version: 2214
Windows 5.1.2600 Service Pack 2

02/06/2009 18:29:56
Report safe mode mbam-log-2009-06-02 (18-29-36)

Scan type: Full Scan (C:\|D:\|E:\|)
Objects scanned: 143485
Time elapsed: 31 minute(s), 1 second(s)

Memory Processes Infected: 0
Memory Modules Infected: 0
Registry Keys Infected: 0
Registry Values Infected: 0
Registry Data Items Infected: 0
Folders Infected: 0
Files Infected: 10

Memory Processes Infected:
(No malicious items detected)

Memory Modules Infected:
(No malicious items detected)

Registry Keys Infected:
(No malicious items detected)

Registry Values Infected:
(No malicious items detected)

Registry Data Items Infected:
(No malicious items detected)

Folders Infected:
(No malicious items detected)

Files Infected:
d:\system volume information\_restore{64bd409b-71b8-4529-9e0e-682a29e94023}\RP231\A0158630.dll (Adware.MyWebSearch) -> No action taken.
d:\system volume information\_restore{64bd409b-71b8-4529-9e0e-682a29e94023}\RP231\A0158631.DLL (Adware.MyWebSearch) -> No action taken.
d:\system volume information\_restore{64bd409b-71b8-4529-9e0e-682a29e94023}\RP231\A0158634.DLL (Adware.MyWeb) -> No action taken.
d:\system volume information\_restore{64bd409b-71b8-4529-9e0e-682a29e94023}\RP231\A0158637.DLL (Adware.MyWebSearch) -> No action taken.
d:\system volume information\_restore{64bd409b-71b8-4529-9e0e-682a29e94023}\RP231\A0158657.DLL (Adware.MyWebSearch) -> No action taken.
d:\system volume information\_restore{64bd409b-71b8-4529-9e0e-682a29e94023}\RP231\A0158665.EXE (Adware.MyWeb) -> No action taken.
d:\system volume information\_restore{64bd409b-71b8-4529-9e0e-682a29e94023}\RP231\A0158666.EXE (Adware.MyWeb) -> No action taken.
d:\system volume information\_restore{64bd409b-71b8-4529-9e0e-682a29e94023}\RP231\A0158667.EXE (Adware.MyWeb) -> No action taken.
d:\system volume information\_restore{64bd409b-71b8-4529-9e0e-682a29e94023}\RP231\A0158669.EXE (Adware.MyWeb) -> No action taken.
d:\system volume information\_restore{64bd409b-71b8-4529-9e0e-682a29e94023}\RP231\A0158673.DLL (Adware.MyWeb) -> No action taken.

following that I ran the scan with Malwarebytes again still in safe mode and now no infections. waiting for your instructions...THANK YOU
0
darkpoet Posted messages 1696 Status Contributeur sécurité 62
 
hello

open malwarebytes in normal mode and go to the quarantine tab: empty everything that's there

Download https://77b4795d-a-62cb3a1a-s-sites.googlegroups.com/site/eric71mespages/ToolBarSD.exe?attachauth=ANoY7cqJWPphpudyTqv7TRo5RQ3nm_Sx8JluVMO59X5E9cyE3j3LqKlmStIqiDqJdIgMJLi7MXn2nKVajQfoWuVvZZ2wIx_vkqO4k4P0K9jh-ra9jaKPXdZcoaVF2UqJZNH8ubL_42uIwh6f35xJ2GJMuzddVj2Qth1DgZ839lxEIFGkgWz3TdfvNMy-YtxfA3gqBUrj4U4LFeAPiWr3ClmjIP0t_Xs5PQ%3D%3D&attredirects=2 on your Desktop.

Run the installation of the program by executing the downloaded file.
Double-click now on the Toolbar-S&D shortcut.
Select the desired language by typing the letter of your choice and confirming with the Enter key.
Now choose option 1 (Search). Wait until the search is complete.
Post the generated report. (C:\TB.txt)
--
to teach is to always learn
0
turbulent13 Posted messages 41 Status Membre
 
Here is this monster report; apparently, it's all I could download... Do you think I should soon see the end of the road?

-----------\\ ToolBar S&D 1.2.8 XP/Vista

Microsoft Windows XP Professional (v5.1.2600) Service Pack 2
X86-based PC (Uniprocessor Free: Mobile AMD Sempron(tm) Processor 3600+)
BIOS: PhoenixBIOS 4.0 Release 6.1
USER: POLO (Administrator)
BOOT: Normal boot
Antivirus: AntiVir Desktop 9.0.1.26 (Activated)
C:\ (Local Disk) - NTFS - Total: 69 Go (Free: 32 Go)
D:\ (Local Disk) - NTFS - Total: 34 Go (Free: 11 Go)
E:\ (Local Disk) - NTFS - Total: 35 Go (Free: 5 Go)
F:\ (CD or DVD)

"D:\ToolBar SD" (UPDATE: 21-12-2008|20:47)
Option: [1] (02/06/2009|22:32)

-----------\\ File/Folder Search...

D:\Program Files\BitLord
D:\Program Files\BitLord\BitLord.exe
D:\Program Files\BitLord\BitLord.url
D:\Program Files\BitLord\BitLord.xml
D:\Program Files\BitLord\Downloads
D:\Program Files\BitLord\Downloads.xml
D:\Program Files\BitLord\lang
D:\Program Files\BitLord\License.txt
D:\Program Files\BitLord\rules
D:\Program Files\BitLord\Torrents
D:\Program Files\BitLord\uninst.exe
D:\Program Files\BitLord\Downloads\da_melissa_lauren.wmv
D:\Program Files\BitLord\lang\lang_ar_ae.xml
D:\Program Files\BitLord\lang\lang_bg_bg.xml
D:\Program Files\BitLord\lang\lang_ca_es.xml
D:\Program Files\BitLord\lang\lang_cz_cz.xml
D:\Program Files\BitLord\lang\lang_da_dk.xml
D:\Program Files\BitLord\lang\lang_de_de.xml
D:\Program Files\BitLord\lang\lang_el_gr.xml
D:\Program Files\BitLord\lang\lang_en_us.xml
D:\Program Files\BitLord\lang\lang_es_ar.xml
D:\Program Files\BitLord\lang\lang_es_es.xml
D:\Program Files\BitLord\lang\lang_et_ee.xml
D:\Program Files\BitLord\lang\lang_fi_fi.xml
D:\Program Files\BitLord\lang\lang_fr_fr.xml
D:\Program Files\BitLord\lang\lang_gl_es.xml
D:\Program Files\BitLord\lang\lang_he_il.xml
D:\Program Files\BitLord\lang\lang_hu_hu.xml
D:\Program Files\BitLord\lang\lang_it_it.xml
D:\Program Files\BitLord\lang\lang_jp_jp.xml
D:\Program Files\BitLord\lang\lang_ko_kr.xml
D:\Program Files\BitLord\lang\lang_nb_no.xml
D:\Program Files\BitLord\lang\lang_nl_nl.xml
D:\Program Files\BitLord\lang\lang_pl_pl.xml
D:\Program Files\BitLord\lang\lang_pt_br.xml
D:\Program Files\BitLord\lang\lang_pt_pt.xml
D:\Program Files\BitLord\lang\lang_ro_ro.xml
D:\Program Files\BitLord\lang\lang_ru_ru.xml
D:\Program Files\BitLord\lang\lang_sk_sk.xml
D:\Program Files\BitLord\lang\lang_sl_si.xml
D:\Program Files\BitLord\lang\lang_sr_sr.xml
D:\Program Files\BitLord\lang\lang_sv_se.xml
D:\Program Files\BitLord\lang\lang_th_th.xml
D:\Program Files\BitLord\lang\lang_tr_tr.xml
D:\Program Files\BitLord\lang\lang_va_es.xml
D:\Program Files\BitLord\lang\lang_zh_tw.xml
D:\Program Files\BitLord\rules\ipfilter.dat
D:\Program Files\BitLord\rules\tracker.dat
D:\Program Files\BitLord\Torrents\(TT).Dr.House.S04E07-13.FRENCH.LD.HDTV.XVID-JMT.torrent
D:\Program Files\BitLord\Torrents\(TT).Dr.House.S04E07-13.FRENCH.LD.HDTV.XVID-JMT[0].torrent
D:\Program Files\BitLord\Torrents\17_J irai Dormir chez vous - Emirats Arabes Unis.mp4.torrent
D:\Program Files\BitLord\Torrents\17_J irai Dormir chez vous - Emirats Arabes Unis.mp4[0].torrent
D:\Program Files\BitLord\Torrents\24h - saison 4.torrent
D:\Program Files\BitLord\Torrents\24h - saison 4.xml
D:\Program Files\BitLord\Torrents\24_heures_chrono-saison3-fr-french-complete.torrent
D:\Program Files\BitLord\Torrents\40.Ans.Toujours.Puceau.FR.avi.torrent
D:\Program Files\BitLord\Torrents\6.Bourgeoises.FRENCH.XXX.(2008).DVDRip.XviD-YUMYUM.torrent
D:\Program Files\BitLord\Torrents\6.Bourgeoises.FRENCH.XXX.(2008).DVDRip.XviD-YUMYUM.xml
D:\Program Files\BitLord\Torrents\9th_Wonder_&_Murs-Sweet_Lord-2008-MIXFIEND.torrent
D:\Program Files\BitLord\Torrents\Appel D'Urgence - La Bac De Marseillle.avi.torrent
D:\Program Files\BitLord\Torrents\Appels.D.Urgences(Vol.Agression.Braquage.Flics.De.Choc.Contre.Voyous.Pret.a.Tous).FRENCH.DOC.TV.2009.Upload[AXE31].avi.torrent
D:\Program Files\BitLord\Torrents\Au.Secours.J.Ai.30 Ans DVDRip Fr DivX.avi.torrent
D:\Program Files\BitLord\Torrents\BAC.De.Nuit.Au.Coeur.De.L.Action.avi.torrent
D:\Program Files\BitLord\Torrents\Bailey - TryTeens.wmv.torrent
D:\Program Files\BitLord\Torrents\Barrington Levy - 1998 - Too experienced.torrent
D:\Program Files\BitLord\Torrents\Barrington Levy - Prison Oval Rock.torrent
D:\Program Files\BitLord\Torrents\Big Naturals 7 XXX [DVDRIP][Big Boobs].www.lokotorrents.com.torrent
D:\Program Files\BitLord\Torrents\Big Tits Boss 5 XXX [DVDRip][Big Boobs][www.lokotorrents.com].torrent
D:\Program Files\BitLord\Torrents\Big Tits Boss 5 XXX [DVDRip][Big Boobs][www.lokotorrents.com].xml
D:\Program Files\BitLord\Torrents\Big Tits Curvy Asses - Maria Moore As Busty Red Riding Hood!.wmv.torrent
D:\Program Files\BitLord\Torrents\Black Snake Moan.torrent
D:\Program Files\BitLord\Torrents\blow fr dvdrip.avi.torrent
D:\Program Files\BitLord\Torrents\Bob Marley & The Wailers - Babylon By Bus [www.p2p-world.dl.am].torrent
D:\Program Files\BitLord\Torrents\bos-yaledi.avi.torrent
D:\Program Files\BitLord\Torrents\Boulevard de la mort.torrent
D:\Program Files\BitLord\Torrents\Boulevard de la mort.xml
D:\Program Files\BitLord\Torrents\Busting The Babysitter XXX [DVDRip][Big Boobs].www.lokotorrents.com.torrent
D:\Program Files\BitLord\Torrents\cantona-the complete collection.torrent
D:\Program Files\BitLord\Torrents\Chinese Man Records - The Groove Sessions Vol.2 (FLAC LEVEL 8) + VidA©os HQ.rar.torrent
D:\Program Files\BitLord\Torrents\Chinese Man Records - The Groove Sessions Vol.2 (FLAC LEVEL 8) + VidA©os HQ.rar.xml
D:\Program Files\BitLord\Torrents\Chinese_Man-The_Indi_Groove_EP-Vinyl-2007-MVP.rar.torrent
D:\Program Files\BitLord\Torrents\Chroniques de Mars-vol.1 by skytorrentfr.torrent
D:\Program Files\BitLord\Torrents\Chroniques de Mars-vol.1 by skytorrentfr.xml
D:\Program Files\BitLord\Torrents\Compil Son De Teuf hardtek Tribe Tribecore By Tom.torrent
D:\Program Files\BitLord\Torrents\Compilation Rap Francais Alternatif - Quand L Underground Debarque - French.torrent
D:\Program Files\BitLord\Torrents\CSI Las Vegas S06 E01 - E13 French.rar.torrent
D:\Program Files\BitLord\Torrents\CSI las vegas s07 complA¨te.torrent
D:\Program Files\BitLord\Torrents\CSI Las Vegas Saison 5 FRENCH.torrent
D:\Program Files\BitLord\Torrents\CSI Las Vegas Saison 6 FRENCH.torrent
D:\Program Files\BitLord\Torrents\CSI Las Vegas Saison 6 FRENCH[0].torrent
D:\Program Files\BitLord\Torrents\CSI.Las.Vegas.S07E05.avi.torrent
D:\Program Files\BitLord\Torrents\CSI.Las.Vegas.s07e04.avi.torrent
D:\Program Files\BitLord\Torrents\CSI.Las.Vegas.S07E01-03.FRENCH.HDTV.XviD-JMT.torrent
D:\Program Files\BitLord\Torrents\CSI.Las.Vegas.S07E06-10.FRENCH.DVDRiP.XViD-ANDR0S.torrent
D:\Program Files\BitLord\Torrents\CSI.Las.Vegas.S07E06-10.FRENCH.DVDRiP.XViD-ANDR0S.xml
D:\Program Files\BitLord\Torrents\CSI.Las.Vegas.S07E11-16.FRENCH.DVDRiP.XViD-ANDR0S.torrent
D:\Program Files\BitLord\Torrents\CSI.Las.Vegas.S07E11-16.FRENCH.DVDRiP.XViD-ANDR0S.xml
D:\Program Files\BitLord\Torrents\CSI.Las.Vegas.S07E21-22.FRENCH.HDTV.XviD-JMT.torrent
D:\Program Files\BitLord\Torrents\CSI.Las.Vegas.S09E02.FRENCH.LD.HDTV.XviD-JMT[trackersurfer].avi.torrent
D:\Program Files\BitLord\Torrents\csi.lv.s09e01-jmt.avi.torrent
D:\Program Files\BitLord\Torrents\csi.lv.s09e01-jmt.avi.xml
D:\Program Files\BitLord\Torrents\csi.lv.s09e02-jmt.avi.torrent
D:\Program Files\BitLord\Torrents\csi.lv.s09e02-jmt.avi.xml
D:\Program Files\BitLord\Torrents\CSI.Miami.S05E13.FRENCH.HDTV.XviD-JMT.avi.torrent
D:\Program Files\BitLord\Torrents\CSI.Miami.S06 partage.torrent
D:\Program Files\BitLord\Torrents\CSI.Miami.vostf.Saison-7.Ep-1,2,3,4.torrent
D:\Program Files\BitLord\Torrents\CSI.New.York.S03E13.FRENCH.HDTV.XviD-JMT.avi.torrent
D:\Program Files\BitLord\Torrents\CSI.New.York.S03E13.FRENCH.HDTV.XviD-JMT.avi[0].torrent
D:\Program Files\BitLord\Torrents\CSI.New.York.S03E14.FRENCH.HDTV.XviD-JMT.avi.torrent
D:\Program Files\BitLord\Torrents\CSI.New.York.S03E15.FRENCH.HDTV.XviD-JMT.avi.torrent
D:\Program Files\BitLord\Torrents\CSI.New.York.S03E15.FRENCH.HDTV.XviD-JMT.avi[0].torrent
D:\Program Files\BitLord\Torrents\CSI.New.York.S03E16.FRENCH.HDTV.XviD-JMT.avi.torrent
D:\Program Files\BitLord\Torrents\CSI.New.York.S03E17.FRENCH.HDTV.XviD-JMT.avi.torrent
D:\Program Files\BitLord\Torrents\CSI.New.York.S03E20.FRENCH.DVTV.XviD-JMT.avi.torrent
D:\Program Files\BitLord\Torrents\CSI.New.York.S03E21.FRENCH.DVTV.XviD-JMT.avi.torrent
D:\Program Files\BitLord\Torrents\CSI.New.York.S03E21.FRENCH.DVTV.XviD-JMT.avi[0].torrent
D:\Program Files\BitLord\Torrents\CSI.New.York.S04 partage.torrent
D:\Program Files\BitLord\Torrents\CSI.New.York.S04 partage[0].torrent
D:\Program Files\BitLord\Torrents\CSI.New.York.S04 partage[1].torrent
D:\Program Files\BitLord\Torrents\CSI.New.York.S04 partage[2].torrent
D:\Program Files\BitLord\Torrents\CSI.New.York.S04E01-03.FRENCH.HDTV.XviD-JMT.torrent
D:\Program Files\BitLord\Torrents\CSI.New.York.S04E01-03.FRENCH.HDTV.XviD-JMT[0].torrent
D:\Program Files\BitLord\Torrents\CSI.New.York.S04E04.FRENCH.LD.HDTV.XviD-JMT.avi.torrent
D:\Program Files\BitLord\Torrents\CSI.New.York.S04E04.FRENCH.LD.HDTV.XviD-JMT.avi[0].torrent
D:\Program Files\BitLord\Torrents\CSI.New.York.S04E05.FRENCH.HDTV.XviD-JMT.avi.torrent
D:\Program Files\BitLord\Torrents\CSI.New.York.S04E07.FRENCH.LD.HDTV.XviD-JMT.avi.torrent
D:\Program Files\BitLord\Torrents\CSI.New.York.S04E07.FRENCH.LD.HDTV.XviD-JMT.avi[0].torrent
D:\Program Files\BitLord\Torrents\CSI.New.York.S04E16.Right Next Door.HDTV.XviD-LOL.SUB FR.slayerFR.avi.torrent
D:\Program Files\BitLord\Torrents\CSI.New.York.S04E18.HDTV.XviD-LOL.VOST FR.slayerFR.avi.torrent
D:\Program Files\BitLord\Torrents\CSI.New.York.S05E01.FRENCH.LD.HDTV.XviD-JMT[up by sahokyu.free.fr].torrent
D:\Program Files\BitLord\Torrents\CSI.New.York.S05E02.FRENCH.LD.HDTV.XviD-JMT[up by sahokyu.free.fr].torrent
D:\Program Files\BitLord\Torrents\CSI.New.York.S05E03E04.FRENCH.LD.HDTV.XviD-JMT[up by sahokyu.free.fr].torrent
D:\Program Files\BitLord\Torrents\CSI.New.York.S05E03E04.FRENCH.LD.HDTV.XviD-JMT[up by sahokyu.free.fr][0].torrent
D:\Program Files\BitLord\Torrents\CSI.New.York.S05E04.FRENCH.LD.HDTV.XviD-JMT.torrent
D:\Program Files\BitLord\Torrents\CSI.New.York.S05E05.FRENCH.LD.HDTV.XviD-JMT[by tracker-series.fr.cc].torrent
D:\Program Files\BitLord\Torrents\CSI.New.York.S05E07et08.FRENCH.LD.HDTV.XviD-JMT.torrent
D:\Program Files\BitLord\Torrents\CSI.New.York.S05E07et08.FRENCH.LD.HDTV.XviD-JMT[0].torrent
D:\Program Files\BitLord\Torrents\CSI.NY.S02E01.E24.FINAL.FRENCH.DVDRip.XviD.torrent
D:\Program Files\BitLord\Torrents\CSI.NY.S04E02.VOSTFR.HDTV.XviD-ELiTE.torrent
D:\Program Files\BitLord\Torrents\Cut Killer - Street Francais Vol.4 by Marshall73.rar.torrent
D:\Program Files\BitLord\Torrents\Cut Killer - Street Francais Vol.4 by Marshall73.rar[0].torrent
D:\Program Files\BitLord\Torrents\Davia Ardell & Jessica Lynn - BigTitsAtSchool.wmv.torrent
D:\Program Files\BitLord\Torrents\Davia Ardell & Jessica Lynn - BigTitsAtSchool.wmv.xml
D:\Program Files\BitLord\Torrents\Daz Dillinger - Tha Dogg Pound Gangsta LP (2005) Rap - www.torrentazos.com By FEFE2003.rar.torrent
D:\Program Files\BitLord\Torrents\da_melissa_lauren.wmv.torrent
D:\Program Files\BitLord\Torrents\da_melissa_lauren.wmv.xml
D:\Program Files\BitLord\Torrents\Deux jours a tuer french dvdrip xvid [L@ndTe@m].torrent
D:\Program Files\BitLord\Torrents\Deux jours a tuer french dvdrip xvid [L@ndTe@m].xml
D:\Program Files\BitLord\Torrents\Dexter.S01E01-06.FRENCH.DVDRip.XviD-JMT.torrent
D:\Program Files\BitLord\Torrents\Dexter.S01E01-12.HR.HDTV.XviD.torrent
D:\Program Files\BitLord\Torrents\Dexter.S01E01-12.HR.HDTV.XviD.xml
D:\Program Files\BitLord\Torrents\Dexter.S01E05.HDTV.XviD-NoTV[www.moviex.info].torrent
D:\Program Files\BitLord\Torrents\Dexter.S01E05.HDTV.XviD-NoTV[www.moviex.info].xml
D:\Program Files\BitLord\Torrents\Dr House - Saison 2.torrent
D:\Program Files\BitLord\Torrents\Dr House - Saison 2.xml
D:\Program Files\BitLord\Torrents\Dr House - Saison 2[0].torrent
D:\Program Files\BitLord\Torrents\Dr House S04 Ep 1 A 12 by gsxr1000.torrent
D:\Program Files\BitLord\Torrents\Dr House S04 Ep 1 A 12 by gsxr1000[0].torrent
D:\Program Files\BitLord\Torrents\Dr House saison 4.torrent
D:\Program Files\BitLord\Torrents\Dr._Dre_feat._RBX__KRS-One__B-Real__Nas___Scarface_-_East_Coast_West_Coast_Killas.avi.torrent
D:\Program Files\BitLord\Torrents\Dr._Dre_feat._RBX__KRS-One__B-Real__Nas___Scarface_-_East_Coast_West_Coast_Killas.avi.xml
D:\Program Files\BitLord\Torrents\Eminem - Crack A Bottle Feat Dr Dre & 50 Cent-MIXFIEND-2009.mp3.torrent
D:\Program Files\BitLord\Torrents\Eminem - Return Of The Bad Guy Pt2[2009].torrent
D:\Program Files\BitLord\Torrents\Eminem - The Recovery (mixtape 2009) [trackersurfer.fr].torrent
D:\Program Files\BitLord\Torrents\Entre.Les.Murs.FRENCH.DVDRip.XviD.torrent
D:\Program Files\BitLord\Torrents\Entre.Les.Murs.FRENCH.DVDRip.XviD.xml
D:\Program Files\BitLord\Torrents\Eric The King.torrent
D:\Program Files\BitLord\Torrents\Florence.Foresti.And.Friends.Sketchs.Inedits.2009.French.Dvdrip.Xvid-RLD.Upload.(Steph53).Mininova.org..avi.torrent
D:\Program Files\BitLord\Torrents\Florence.Foresti.And.Friends.Sketchs.Inedits.2009.French.Dvdrip.Xvid-RLD.Upload.(Steph53).Mininova.org..avi[0].torrent
D:\Program Files\BitLord\Torrents\Florence.Foresti.And.Friends.Sketchs.Inedits.2009.French.Dvdrip.Xvid-RLD.Upload.(Steph53).Mininova.org..avi[1].torrent
D:\Program Files\BitLord\Torrents\Fraiches.Et.Salopes.FRENCH.XXX.DVDRip.DivX.REPACK.1CD_ALLTEAM.torrent
D:\Program Files\BitLord\Torrents\Fraiches.Et.Salopes.FRENCH.XXX.DVDRip.DivX.REPACK.1CD_ALLTEAM.xml
D:\Program Files\BitLord\Torrents\FratHouseFuckFest.E12.Victoria.Sweet.XXX.WMV-DiXXX.torrent
D:\Program Files\BitLord\Torrents\Funk Party - 3cds(split tracks + covers).torrent
D:\Program Files\BitLord\Torrents\Funk Sessions (2 CD).torrent
D:\Program Files\BitLord\Torrents\Funkoars (2008) The Hangover.torrent
D:\Program Files\BitLord\Torrents\G-unit - Best Volume 1 (2005) - Rap - www.torrentazos.com By FEFE2003.rar.torrent
D:\Program Files\BitLord\Torrents\G-unit - Best Volume 1 (2005) - Rap - www.xmlazos.com By FEFE2003.rar.xml
D:\Program Files\BitLord\Torrents\gaous french dvdrip [chicoun].AVI.torrent
D:\Program Files\BitLord\Torrents\gaous french dvdrip [chicoun].AVI.xml
D:\Program Files\BitLord\Torrents\GdoGs Mixtape Vol 1 Kaim & Riskey.torrent
D:\Program Files\BitLord\Torrents\Hardcore Ravers Volume Two.zip.torrent
D:\Program Files\BitLord\Torrents\Hip Hop Underground n°3 - Rap Francais - French Rap.torrent
D:\Program Files\BitLord\Torrents\Hot Fuzz.torrent
D:\Program Files\BitLord\Torrents\Hot Fuzz.xml
D:\Program Files\BitLord\Torrents\House.4x02.La.tete.dans.les.étoiles.Hdtv.avi.torrent
D:\Program Files\BitLord\Torrents\House.S04E11.FRENCH.LD.HDTV.XViD-ASC.torrent
D:\Program Files\BitLord\Torrents\House.S04E11.FRENCH.LD.HDTV.XViD-ASC.xml
D:\Program Files\BitLord\Torrents\House.S04E12.FRENCH.LD.HDTV.XViD-ASC.torrent
D:\Program Files\BitLord\Torrents\House.S04E13.FRENCH.LD.DVDRip.XViD-ASC.avi.torrent
D:\Program Files\BitLord\Torrents\House.S04E14.FRENCH.LD.DVDRip.XViD-ASC.torrent
D:\Program Files\BitLord\Torrents\House.S05E05.FRENCH.LD.HDTV.XViD-JMT[trackersurfer].avi.torrent
D:\Program Files\BitLord\Torrents\House.S05E07.FRENCH.LD.HDTV.XViD-JMT[trackersurfer].avi.torrent
D:\Program Files\BitLord\Torrents\Ice-T - O.G. Original Gangster.torrent
D:\Program Files\BitLord\Torrents\ichi le tueur DVDRip XviD French {appocalipteam.mine.nu}.avi.torrent
D:\Program Files\BitLord\Torrents\J irais Dormir chez vous.torrent
D:\Program Files\BitLord\Torrents\Jirai dormir chez vous...Chili.avi.torrent
D:\Program Files\BitLord\Torrents\Jirai dormir chez vous...Chili.avi[0].torrent
D:\Program Files\BitLord\Torrents\Jusqu'a la Mort-DVD R[www.appocalipteam.mine.nu french].torrent
D:\Program Files\BitLord\Torrents\Kill Shot ((2008)) Limited DVDrip(divx)BigbrO.torrent
D:\Program Files\BitLord\Torrents\Killshot.FRENCH.DVDRip.Xvid-THEWARRIOR777.avi.torrent
D:\Program Files\BitLord\Torrents\King.Guillaume.FRENCH.READNFO.TS.XViD-RaCcOoN(Smartorrent).torrent
D:\Program Files\BitLord\Torrents\KRS One - The Fundamentals of Hip Hop.torrent
D:\Program Files\BitLord\Torrents\KRS-ONE (Boogie Down Productions) - Retrospective [FLAC] [h33t] - Kitlope.torrent
D:\Program Files\BitLord\Torrents\KRS-ONE (Boogie Down Productions) - Retrospective [FLAC] [h33t] - Kitlope.xml
D:\Program Files\BitLord\Torrents\L.Annee.Du.Zapping.2008.2EME.PARTIE.FRENCH.avi.torrent
D:\Program Files\BitLord\Torrents\L.Annee.Du.Zapping.2008.2EME.PARTIE.FRENCH.avi.xml
D:\Program Files\BitLord\Torrents\La Swija-Au Sourire Levant(2009).torrent
D:\Program Files\BitLord\Torrents\La.Realite.En.Images.Special.Drogue.DOC.FRENCH.DVDRiP.XViD-SCiENCES.avi.torrent
D:\Program Files\BitLord\Torrents\Laughing.Out.Loud.FRENCH.TS.MD.XViD-RaCcOoN(Smartorrent).torrent
D:\Program Files\BitLord\Torrents\LA_CITE_DE_DIEU.AVI.torrent
D:\Program Files\BitLord\Torrents\Le droit de savoir - Drogues 'Enquete sur la nouvelle guerre des stups' by Juli1 (www.foromtorrent.com).avi.torrent
D:\Program Files\BitLord\Torrents\Le.Divorce.FRENCH.DVDRip.XViD-SEQ.avi.torrent
D:\Program Files\BitLord\Torrents\Les experts las vegas saison 4 episode 1a12 dvdrip french divx.torrent
D:\Program Files\BitLord\Torrents\Les Experts 2x03 - Regression Mortelle.avi.torrent
D:\Program Files\BitLord\Torrents\Les Experts Las Vegas - Saison 8.torrent
D:\Program Files\BitLord\Torrents\Les experts Miami S4 Pack 1 TVRIP FR.torrent
D:\Program Files\BitLord\Torrents\Les experts Miami S4 Pack 1 TVRIP FR.xml
D:\Program Files\BitLord\Torrents\Les parrains french dvdrip xvid [L@ndTe@m].torrent
D:\Program Files\BitLord\Torrents\Les randonneurs a st tropez french dvdrip xvid [L@ndTe@m].torrent
D:\Program Files\BitLord\Torrents\Les.Experts 2x05 - Permis de demolir.AVI.torrent
D:\Program Files\BitLord\Torrents\Les.Lascars.S02.DVDRip.XviD.FR.2008 [phoenix-tk].rar.torrent
D:\Program Files\BitLord\Torrents\Les.Promesses.De.L.Ombre.DVDrip.VOST.Fr.by.JzX-FraKtal.avi.torrent
D:\Program Files\BitLord\Torrents\Lethal Injection.torrent
D:\Program Files\BitLord\Torrents\Lethal Injection.xml
D:\Program Files\BitLord\Torrents\Lets go to prison French DVDRIP.avi.torrent
D:\Program Files\BitLord\Torrents\Lil Kim - The Notorious K.I.M 20008-TRI_INT seeded by www.p2p-crew.to.rar.torrent
D:\Program Files\BitLord\Torrents\Ma.Femme.Est.A.Louer.FRENCH.XXX.DVDRip.XviD-YUMYUM.avi.torrent
D:\Program Files\BitLord\Torrents\mafiosa le clan S02E01.avi.torrent
D:\Program Files\BitLord\Torrents\mafiosa le clan S02E02.avi.torrent
D:\Program Files\BitLord\Torrents\Mafiosa.S02E06.FRENCH.HDTV.XviD-JMT.torrent
D:\Program Files\BitLord\Torrents\Mafiosa.S02E06.FRENCH.HDTV.XviD-JMT.xml
D:\Program Files\BitLord\Torrents\Malcolm Saison 4.torrent
D:\Program Files\BitLord\Torrents\Manipulations.ROYALTORRENT.avi.torrent
D:\Program Files\BitLord\Torrents\manipulations.torrent
D:\Program Files\BitLord\Torrents\manipulations.xml
D:\Program Files\BitLord\Torrents\Marc Dorcel - Natacha [Monica Sweetheart, Vanessa, Lea De Mae, Lara Stevens, Tiffany Diamond...].torrent
D:\Program Files\BitLord\Torrents\Medine.Don't.Panik.MixTape.2008.by.PGX.rar.torrent
D:\Program Files\BitLord\Torrents\Meet The Twins 11 XXX [DVDRIP][Big Boobs].www.lokotorrents.com.torrent
D:\Program Files\BitLord\Torrents\MIXTAPE 10 ANS DE RAP FRANCAIS - 2008.rar.torrent
D:\Program Files\BitLord\Torrents\MR 73 (2008) [DvdRip] [Xvid] {1337x}-Noir.torrent
D:\Program Files\BitLord\Torrents\MR 73 (2008) [DvdRip] [Xvid] {1337x}-Noir.xml
D:\Program Files\BitLord\Torrents\MSN-Webcam-Capture-Liv.mov.torrent
D:\Program Files\BitLord\Torrents\MSN-Webcam-Capture-Liv.mov.xml
D:\Program Files\BitLord\Torrents\Musee.Haut.Musee.Bas.FRENCH.DVDRip.XviD-UNSKiLLED.MZISYS.avi.torrent
D:\Program Files\BitLord\Torrents\Musee.Haut.Musee.Bas.FRENCH.DVDRip.XviD-UNSKiLLED.MZISYS.avi.xml
D:\Program Files\BitLord\Torrents\naruto french vf 160-188.torrent
D:\Program Files\BitLord\Torrents\Notorious BIG - King Of New York [TK].torrent
D:\Program Files\BitLord\Torrents\Notorious BIG - King Of New York [TK].xml
D:\Program Files\BitLord\Torrents\Notorious Big - Life After Death.torrent
D:\Program Files\BitLord\Torrents\Notorious Big - Life After Death[0].torrent
D:\Program Files\BitLord\Torrents\Notorious Big - Life After Death[0].xml
D:\Program Files\BitLord\Torrents\Passengers.LiMiTED.720p.FRENCH.BluRay.x264-ForceBleue.torrent
D:\Program Files\BitLord\Torrents\Private Practice S02E13 XviD VOSTFR --Antoine 4011--.avi.torrent
D:\Program Files\BitLord\Torrents\Private Practice S02E15 XviD VOSTFR --Antoine 4011--.avi.torrent
D:\Program Files\BitLord\Torrents\PROMESSES_OMBRE.ISO.torrent
D:\Program Files\BitLord\Torrents\PROMESSES_OMBRE.ISO.xml
D:\Program Files\BitLord\Torrents\PUISSANCE RAP 2009 - SPÉCIAL RAP FRANCAIS.rar.torrent
D:\Program Files\BitLord\Torrents\Rage Against The Machine.torrent
D:\Program Files\BitLord\Torrents\Raggasonic 2 album complet.rar.torrent
D:\Program Files\BitLord\Torrents\Raggasonic 2 album complet.rar[0].torrent
D:\Program Files\BitLord\Torrents\Raggasonic albumz.torrent
D:\Program Files\BitLord\Torrents\Raggasonic.torrent
D:\Program Files\BitLord\Torrents\Rap-Francais-Fuck-Skyrock-2CD-French-2006.torrent
D:\Program Files\BitLord\Torrents\Reporters.torrent
D:\Program Files\BitLord\Torrents\Reporters.xml
D:\Program Files\BitLord\Torrents\ROHFF-LE.CAUCHEMAR.DU.RAP.FRANCAIS.CHAPITRE.1_-FR-2007 LuDivX.torrent
D:\Program Files\BitLord\Torrents\Role.Models.UNRATED.FRENCH.DVDRip.XviD-ULTRASON.torrent
D:\Program Files\BitLord\Torrents\Role.Models.UNRATED.FRENCH.DVDRip.XviD-ULTRASON.xml
D:\Program Files\BitLord\Torrents\SarahSunshine_BigBoobsPOV.wmv.torrent
D:\Program Files\BitLord\Torrents\Schoolgirls On Fire XXX [DVDRip][www.zonatorrent.com].torrent
D:\Program Files\BitLord\Torrents\Scrubs.S08E02.VOSTFR.HDTV.XViD-OQS.avi.torrent
0
darkpoet Posted messages 1696 Status Contributeur sécurité 62
 
Delete all cracks as they are a source of infections:

D:\DOCUME~1\POLO\My Documents\Ableton\Library\Presets\Audio Effects\Vinyl Distortion\Crack.adv
D:\DOCUME~1\POLO\My Documents\My Music\French Rap\MA 6-t va craquer\Ma 6-T va crack-er
D:\DOCUME~1\POLO\My Documents\My Music\French Rap\MA 6-t va craquer\Ma 6-T va crack-er\01 The French Connection.wma
D:\DOCUME~1\POLO\My Documents\My Music\French Rap\MA 6-t va craquer\Ma 6-T va crack-er\02 Les flammes du mal.wma
D:\DOCUME~1\POLO\My Documents\My Music\French Rap\MA 6-t va craquer\Ma 6-T va crack-er\04 La sédition.wma
D:\DOCUME~1\POLO\My Documents\My Music\French Rap\MA 6-t va craquer\Ma 6-T va crack-er\05 Savoir dire non.wma
D:\DOCUME~1\POLO\My Documents\My Music\French Rap\MA 6-t va craquer\Ma 6-T va crack-er\06 Ma T-ci va K-kra.wma
D:\DOCUME~1\POLO\My Documents\My Music\French Rap\MA 6-t va craquer\Ma 6-T va crack-er\07 Le temps des opprimés.wma
D:\DOCUME~1\POLO\My Documents\My Music\French Rap\MA 6-t va craquer\Ma 6-T va crack-er\08 La roue tourne.wma
D:\DOCUME~1\POLO\My Documents\My Music\French Rap\MA 6-t va craquer\Ma 6-T va crack-er\09 C'est donc ça nos vies.wma
D:\DOCUME~1\POLO\My Documents\My Music\French Rap\MA 6-t va craquer\Ma 6-T va crack-er\10 Retour aux pyramides.wma
D:\DOCUME~1\POLO\My Documents\My Music\French Rap\MA 6-t va craquer\Ma 6-T va crack-er\11 Trop dur.wma
D:\DOCUME~1\POLO\My Documents\My Music\French Rap\MA 6-t va craquer\Ma 6-T va crack-er\12 Le Biz.wma
D:\DOCUME~1\POLO\My Documents\My Music\French Rap\MA 6-t va craquer\Ma 6-T va crack-er\13 Avoir le pouvoir.wma
D:\DOCUME~1\POLO\My Documents\My Music\French Rap\MA 6-t va craquer\Ma 6-T va crack-er\14 Le prix requis.wma
D:\DOCUME~1\POLO\My Documents\My Music\French Rap\MA 6-t va craquer\Ma 6-T va crack-er\15 L'Œle de l'inconscient.wma
D:\DOCUME~1\POLO\My Documents\My Music\French Rap\MA 6-t va craquer\Ma 6-T va crack-er\desktop.ini
D:\DOCUME~1\POLO\My Documents\My Music\US RAP\eminem\04) CRACK A BOTTLE FT DR DRE 50 CENT.mp3
D:\DOCUME~1\POLO\My Documents\My Music\US RAP\eminem\11) CRACK SMOKE.mp3
D:\DOCUME~1\POLO\My Documents\My Music\US RAP\NOTORIOUS BIG\NOTORIOUS BIS II\Notorious B.I.G. - Ten Crack Commandments.mp3
D:\DOCUME~1\POLO\Recent\Notorious B.I.G. - Ten Crack Commandments.lnk

Then restart ToolbarSD

this time choose option 2 (deletion)

please post the generated report

--
to teach is always to learn
0
turbulent13 Posted messages 41 Status Membre
 
Excuse me, but I'm really a klutz with computers. Just to clarify, when you say to delete all "the following cracks," how do I do that? Like, do I go into my music and look for, for example, my 6T will crack, and do I delete the whole album????
0
darkpoet Posted messages 1696 Status Contributeur sécurité 62
 
Yes, you follow the access path to: (drive) document /polo etcetc

you can access it via the workstation, you select your drive and follow the path
--
to teach is always to learn
0
darkpoet Posted messages 1696 Status Contributeur sécurité 62
 
Alright, I'm leaving you for tonight, I'll resume tomorrow morning. Post the tolbarsd report (option 2) and then do this for the checks please. Good night

- Download Random's System Information Tool (RSIT) (by random/random) to your Desktop.
http://images.malwareremoval.com/random/RSIT.exe

- Double-click on RSIT.exe to launch the program.

- Click on Continue at the Disclaimer screen.

- If the HijackThis tool (updated version) is not present or not detected on the computer, RSIT will download it (allow access in your firewall, if prompted) and you will need to accept the license.

- When the scan is complete, two text files will open. Post the contents of log.txt (the one that appears on the screen) as well as info.txt (which you will see in the taskbar).

Note: Reports are saved in the folder C:\rsit.
--
Teaching is always learning
0
turbulent13 Posted messages 41 Status Membre
 
HERE IT SEEMS TO HAVE REMOVED A MOVIE FILE CALLED NEW BITLORD? HERE'S THE REPORT.

-----------\\ ToolBar S&D 1.2.8 XP/Vista

Microsoft Windows XP Professional ( v5.1.2600 ) Service Pack 2
X86-based PC ( Uniprocessor Free : Mobile AMD Sempron(tm) Processor 3600+ )
BIOS : PhoenixBIOS 4.0 Release 6.1
USER : POLO ( Administrator )
BOOT : Normal boot
Antivirus : AntiVir Desktop 9.0.1.26 (Activated)
C:\ (Local Disk) - NTFS - Total:69 Go (Free:32 Go)
D:\ (Local Disk) - NTFS - Total:34 Go (Free:12 Go)
E:\ (Local Disk) - NTFS - Total:35 Go (Free:5 Go)
F:\ (CD or DVD)

"D:\ToolBar SD" ( UPDATE : 21-12-2008|20:47 )
Option : [2] ( 02/06/2009|23:25 )

-----------\\ DELETION

Deleted! - D:\Program Files\BitLord\BitLord.exe
Deleted! - D:\Program Files\BitLord\BitLord.url
Deleted! - D:\Program Files\BitLord\BitLord.xml
Deleted! - D:\Program Files\BitLord\Downloads
Deleted! - D:\Program Files\BitLord\Downloads.xml
Deleted! - D:\Program Files\BitLord\lang
Deleted! - D:\Program Files\BitLord\License.txt
Deleted! - D:\Program Files\BitLord\rules
Deleted! - D:\Program Files\BitLord\Torrents
Deleted! - D:\Program Files\BitLord\uninst.exe
Deleted! - D:\DOCUME~1\POLO\Desktop\BitLord.lnk
Deleted! - D:\DOCUME~1\POLO\Desktop\NEW BITLORD
Deleted! - D:\WINDOWS\Prefetch\BITLORD.EXE-27A8448C.pf
Deleted! - D:\DOCUME~1\POLO\MENUDM~1\PROGRA~1\BitLord
Deleted! - D:\DOCUME~1\POLO\Cookies\polo@bitlord[1].txt
Deleted! - D:\DOCUME~1\POLO\Cookies\polo@bitlord[2].txt
Deleted! - D:\DOCUME~1\POLO\Cookies\polo@bitlord[4].txt
Deleted! - D:\Program Files\Burn4Free\bass.dll
Deleted! - D:\Program Files\Burn4Free\basscd.dll
Deleted! - D:\Program Files\Burn4Free\bassflac.dll
Deleted! - D:\Program Files\Burn4Free\basswma.dll
Deleted! - D:\Program Files\Burn4Free\basswv.dll
Deleted! - D:\Program Files\Burn4Free\bass_ape.dll
Deleted! - D:\Program Files\Burn4Free\bass_mpc.dll
Deleted! - D:\Program Files\Burn4Free\BURN4FREE.CFG
Deleted! - D:\Program Files\Burn4Free\Burn4Free.exe
Deleted! - D:\Program Files\Burn4Free\languages
Deleted! - D:\Program Files\Burn4Free\queue
Deleted! - D:\Program Files\Burn4Free\temp
Deleted! - D:\Program Files\Burn4Free\wav
Deleted! - D:\DOCUME~1\POLO\Cookies\polo@iredirect.burn4free[1].txt
Deleted! - D:\Program Files\BitLord
Deleted! - D:\Program Files\Burn4Free

-----------\\ File / Folder Search ...

-----------\\ Extensions

(POLO) - {635abd67-4fe9-1b23-4f01-e679fa7484c1} => ytoolbar
(POLO) - {7c5c0f58-e061-457d-9033-77307f5ed00c} => torrentman
(POLO) - {b9db16a4-6edc-47ec-a1f4-b86292ed211d} => dwhelper

-----------\\ [..\Internet Explorer\Main]

[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main]
"Start Page"="http://www.microsoft.com/isapi/redir.dll?prd=ie&pver=6&ar=msnhome"
"Local Page"="D:\\WINDOWS\\system32\\blank.htm"
"Search Page"="http://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch"
"Default_Page_URL"="http://www.microsoft.com/isapi/redir.dll?prd=ie&pver=6&ar=msnhome"
"Start Page Redirect Cache"="https://www.msn.com/fr-fr?ocid=iehp"
"Search Bar"="https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF"
"Default_search_url"="http://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch"
"Window Title"="http://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch"

[HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Main]
"Default_Page_URL"="http://www.microsoft.com/isapi/redir.dll?prd=ie&pver=6&ar=msnhome"
"Default_Search_URL"="http://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch"
"Search Page"="http://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch"
"Local Page"="D:\\WINDOWS\\system32\\blank.htm"
"Start Page"="https://www.msn.com/fr-fr/"
"Search bar"="http://www.bing.com/spresults.aspx"

--------------------\\ Search for other infections

--------------------\\ Cracks & Keygens ..

D:\DOCUME~1\POLO\Recent\Notorious B.I.G. - Ten Crack Commandments.lnk

1 - "D:\ToolBar SD\TB_1.txt" - 02/06/2009|22:32 - Option : [1]
2 - "D:\ToolBar SD\TB_2.txt" - 02/06/2009|23:03 - Option : [1]
3 - "D:\ToolBar SD\TB_3.txt" - 02/06/2009|23:29 - Option : [2]

-----------\\ End of report at 23:29:46,60
0
  • 1
  • 2
  • 3