7 answers
Hello,
▶ Download FindyKill to your desktop:
http://sd-1.archive-host.com/membres/up/127028005715545653/FindyKill.exe
! Disconnect and close all running applications!
• Double-click on "FindyKill.exe" to start the installation and leave the installation settings as default.
• Connect your external data sources to your PC (USB key, external hard drive, etc...)
• Double-click on the FindyKill shortcut on your desktop to launch the tool.
• In the main menu, choose the option " F " for French and press [Enter].
• In the second menu, choose the option " 1 " (search) and press [Enter].
▶ Let the tool do its work and do not touch anything...
--> Post the report that appears at the end on the forum...
(the report is also saved under C:\FindyKill.txt)
(CTRL+A to select all, CTRL+C to copy, and CTRL+V to paste)
• Note: "Process.exe", a component of the tool, is detected by some antivirus programs (AntiVir, Dr.Web, Kaspersky Anti-Virus) as a RiskTool.
It is not a virus, but a utility designed to terminate processes.
In the wrong hands, this utility could stop security software (Antivirus, Firewall...) which is why these antivirus programs issue an alert.
--
@+
▶ Download FindyKill to your desktop:
http://sd-1.archive-host.com/membres/up/127028005715545653/FindyKill.exe
! Disconnect and close all running applications!
• Double-click on "FindyKill.exe" to start the installation and leave the installation settings as default.
• Connect your external data sources to your PC (USB key, external hard drive, etc...)
• Double-click on the FindyKill shortcut on your desktop to launch the tool.
• In the main menu, choose the option " F " for French and press [Enter].
• In the second menu, choose the option " 1 " (search) and press [Enter].
▶ Let the tool do its work and do not touch anything...
--> Post the report that appears at the end on the forum...
(the report is also saved under C:\FindyKill.txt)
(CTRL+A to select all, CTRL+C to copy, and CTRL+V to paste)
• Note: "Process.exe", a component of the tool, is detected by some antivirus programs (AntiVir, Dr.Web, Kaspersky Anti-Virus) as a RiskTool.
It is not a virus, but a utility designed to terminate processes.
In the wrong hands, this utility could stop security software (Antivirus, Firewall...) which is why these antivirus programs issue an alert.
--
@+
Hello, USBFix no longer exists as it has merged with another tool.
Why do you want to download USBFix? Who recommended it to you?
--
♦G3и-н@¢ки™©®♦
Why do you want to download USBFix? Who recommended it to you?
--
♦G3и-н@¢ки™©®♦
############################## | FindyKill V6.005 |
# User : Administrator (Administrators) # ORDI-XPSP2
# Update on 11/07/09 by Chiquitine29 & C_XX
# Start at: 13:05:33 | 11/07/2009
# Website : http://pagesperso-orange.fr/NosTools/index.html
# Intel(R) Pentium(R) 4 CPU 1.80GHz
# Microsoft Windows XP Professional (5.1.2600 32-bit) # Service Pack 2
# Internet Explorer 8.0.6001.18702
# Windows Firewall Status : Enabled
# AV : Kaspersky Anti-Virus 8.0.0.506 [ Enabled | Updated ]
# A:\ # 3.5 inch Floppy Drive
# C:\ # Local Hard Disk # 9.77 Go (509.07 Mo free) # NTFS
# D:\ # Local Hard Disk # 27.49 Go (25.84 Go free) # NTFS
# E:\ # CD-ROM
# F:\ # Removable Drive # 250.36 Mo (0.49 Mo free) [ROSA] # FAT32
# G:\ # Removable Drive # 970.72 Mo (953.06 Mo free) [FLASH-DISK] # FAT
############################## | Active Processes |
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\csrss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Panda USB Vaccine\USBVaccine.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\WINDOWS\system32\wscript.exe
C:\Program Files\Java\jre6\bin\jusched.exe
C:\Program Files\Windows Live\Messenger\msnmsgr.exe
C:\WINDOWS\system32\ctfmon.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\alg.exe
C:\WINDOWS\system32\wbem\wmiprvse.exe
################## | Startup Registry |
HKCU_Main: "Local Page"="C:\\WINDOWS\\system32\\blank.htm"
HKCU_Main: "Search Page"="http://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch"
HKCU_Main: "Start Page"="https://www.google.fr/?gws_rd=ssl"
HKLM_logon: "Userinit"="C:\\WINDOWS\\system32\\userinit.exe,"
HKLM_logon: "DefaultUserName"="Administrator"
HKLM_logon: "AltDefaultUserName"="Administrator"
HKLM_logon: "LegalNoticeCaption"=""
HKLM_logon: "LegalNoticeText"=""
HKLM_Run: AVP="C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 2009\avp.exe"
HKLM_Run: Adobe Reader Speed Launcher="C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe"
HKLM_Run: CTFMON=C:\WINDOWS\system32\wscript.exe /E:vbs C:\WINDOWS\system32\winjpg.jpg
HKLM_Run: SunJavaUpdateSched="C:\Program Files\Java\jre6\bin\jusched.exe"
HKLM_Run: regdiit=C:\WINDOWS\system32\winxp.exe
HKLM_Run: HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run\OptionalComponents=
HKCU_Run: msnmsgr="C:\Program Files\Windows Live\Messenger\msnmsgr.exe" /background
HKCU_Run: ctfmon.exe=C:\WINDOWS\system32\ctfmon.exe
################## | Infectious Files # Folders |
Present! C:\WINDOWS\system32\winjpg.jpg [e14385b8c42986357c61de6665f6d9bb]
################## | C:\Documents and Settings\Administrator\Temporary Internet Files |
################## | All Drives ... |
Present! C:\winfile.jpg [e14385b8c42986357c61de6665f6d9bb]
Present! D:\winfile.jpg [e14385b8c42986357c61de6665f6d9bb]
Present! F:\winfile.jpg [e14385b8c42986357c61de6665f6d9bb]
Present! G:\winfile.jpg [e14385b8c42986357c61de6665f6d9bb]
Present! G:\autorun.inf [bc35f37b00f5e8e52e713b2404294344]
################## | Infectious Registry # Run Keys |
Present! HKLM\Software\Microsoft\Windows\CurrentVersion\Run "CTFMON"
Present! HKLM\Software\Microsoft\Windows\CurrentVersion\Run "regdiit"
Present! HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\msconfig.exe
Present! HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\procexp.exe
Present! HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\regedit.exe
Present! HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\taskmgr.exe
Present! HKLM\software\microsoft\windows nt\currentversion\image file execution options\drwtsn32.exe
Present! HKLM\software\microsoft\windows nt\currentversion\image file execution options\dwwinxp.exe
Present! HKLM\software\microsoft\windows nt\currentversion\image file execution options\MSConfig.exe
Present! HKLM\software\microsoft\windows nt\currentversion\image file execution options\rstrui.exe
Present! HKLM\software\microsoft\security center "AntiVirusOverride" ( 0x1 )
Present! HKLM\software\microsoft\security center "FirewallOverride" ( 0x1 )
Present! HKLM\software\microsoft\security center "UpdatesDisableNotify" ( 0x1 )
################## | Registry # Mountpoints2 |
################## | State / Services / Information |
# Viewing hidden files: OK
# Safe mode: OK
# Ndisuio -> Start = 3 ( Good = 3 | Bad = 4 )
# Ip6Fw -> Start = 3 ( Good = 2 | Bad = 4 )
# SharedAccess -> Start = 2 ( Good = 2 | Bad = 4 )
# (!) wuauserv -> Start = 4 ( Good = 2 | Bad = 4 )
# (!) wscsvc -> Start = 4 ( Good = 2 | Bad = 4 )
# C:\autorun.inf ( # Not infected ) -> Folder created by Flash_Disinfector.
# D:\autorun.inf ( # Not infected ) -> Folder created by Flash_Disinfector.
################## | Cracks / Keygens / Serials |
################## | ! End of report # FindyKill V6.005 ! |
! Disconnect and close all running applications (including the browser).
• Connect your external data sources to your PC (USB key, external hard drive, etc.).
• Relaunch "FindyKill": in the main menu, choose option "F" for French and press [enter].
• In the second menu, choose option 2 (deletion) and press [enter].
• The PC will restart automatically...
▶ the program will work, do not touch anything..., your desktop will not be accessible, this is normal!
--> Post the report that appears at the end (the report is also saved under C:\FindyKill.txt)
/!\ If the desktop does not reappear, press Ctrl + Alt + Del, Tab "File", "New Task", type explorer.exe and validate
--
@+
• Connect your external data sources to your PC (USB key, external hard drive, etc.).
• Relaunch "FindyKill": in the main menu, choose option "F" for French and press [enter].
• In the second menu, choose option 2 (deletion) and press [enter].
• The PC will restart automatically...
▶ the program will work, do not touch anything..., your desktop will not be accessible, this is normal!
--> Post the report that appears at the end (the report is also saved under C:\FindyKill.txt)
/!\ If the desktop does not reappear, press Ctrl + Alt + Del, Tab "File", "New Task", type explorer.exe and validate
--
@+
############################## | FindyKill V6.005 |
# User : Administrator (Administrators) # ORDI-XPSP2
# Update on 11/07/09 by Chiquitine29 & C_XX
# Start at: 13:27:16 | 11/07/2009
# Website : http://pagesperso-orange.fr/NosTools/index.html
# Intel(R) Pentium(R) 4 CPU 1.80GHz
# Microsoft Windows XP Professional (5.1.2600 32-bit) # Service Pack 2
# Internet Explorer 8.0.6001.18702
# Windows Firewall Status : Enabled
# AV : Kaspersky Anti-Virus 8.0.0.506 [ Enabled | Updated ]
# A:\ # 3.5-inch Floppy Disk Drive
# C:\ # Local Hard Drive # 9.77 Go (562.61 Mo free) # NTFS
# D:\ # Local Hard Drive # 27.49 Go (25.84 Go free) # NTFS
# E:\ # CD-ROM Drive
# F:\ # Removable Drive # 250.36 Mo (0.88 Mo free) [ROSA] # FAT32
# G:\ # Removable Drive
############################## | Active Processes |
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\csrss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\logonui.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Java\jre6\bin\jqs.exe
C:\Program Files\Panda USB Vaccine\USBVaccine.exe
C:\WINDOWS\System32\alg.exe
C:\WINDOWS\system32\wbem\wmiprvse.exe
################## | Infectious Files # Folders |
Deleted! C:\WINDOWS\system32\winjpg.jpg
################## | C:\Documents and Settings\Administrator\Temporary Internet Files |
################## | All Drives ... |
Deleted! C:\winfile.jpg
Deleted! D:\winfile.jpg
Deleted! F:\winfile.jpg
(!) Not deleted! F:\autorun.inf
################## | Others ... |
################## | Registry # Infectious Run Keys |
Deleted! HKLM\Software\Microsoft\Windows\CurrentVersion\Run "CTFMON"
Deleted! HKLM\Software\Microsoft\Windows\CurrentVersion\Run "regdiit"
Deleted! HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\msconfig.exe
Deleted! HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\procexp.exe
Deleted! HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\regedit.exe
Deleted! HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\taskmgr.exe
Deleted! HKLM\software\microsoft\windows nt\currentversion\image file execution options\drwtsn32.exe
Deleted! HKLM\software\microsoft\windows nt\currentversion\image file execution options\dwwinxp.exe
Deleted! HKLM\software\microsoft\windows nt\currentversion\image file execution options\rstrui.exe
# HKLM\software\microsoft\security center "AntiVirusOverride" # -> Reset successfully!
# HKLM\software\microsoft\security center "FirewallOverride" # -> Reset successfully!
# HKLM\software\microsoft\security center "UpdatesDisableNotify" # -> Reset successfully!
################## | Registry # Mountpoints2 |
################## | Listing of Present Files |
[15/06/2009 13:47|--a------|0] - C:\AUTOEXEC.BAT
[15/06/2009 13:41|--a------|212] - C:\Boot.bak
[24/06/2009 16:17|-rahs----|282] - C:\boot.ini
[24/08/2001 14:00|-rahs----|4952] - C:\Bootfont.bin
[03/08/2004 23:00|--a------|263488] - C:\cmldr
[15/06/2009 13:47|--a------|0] - C:\CONFIG.SYS
[10/07/2009 14:17|--a------|172] - C:\curr_ver.tmp
[11/07/2009 14:11|--a------|3462] - C:\FindyKill.txt
[15/06/2009 13:47|-rahs----|0] - C:\IO.SYS
[15/06/2009 13:47|-rahs----|0] - C:\MSDOS.SYS
[03/08/2004 22:38|-rahs----|47564] - C:\NTDETECT.COM
[03/08/2004 22:59|-rahs----|251712] - C:\ntldr
[?|?|?] - C:\pagefile.sys
[08/06/2009 15:23|--a------|1708853] - F:\DSC00669.JPG
[08/06/2009 15:26|--a------|1672761] - F:\DSC00717.JPG
[?|?|?] - F:\autorun.inf
[09/07/2009 12:58|--a------|2808130] - F:\DSC01672.JPG
[16/06/2009 18:24|--a------|2689812] - F:\DSC01199.JPG
[09/07/2009 12:24|--a------|2714728] - F:\DSC01625.JPG
[02/07/2009 20:21|-rahs----|110] - F:\AUTORUN_.INF
################## | Vaccination |
# C:\autorun.inf ( # Not infected ) -> Folder created by Flash_Disinfector.
# D:\autorun.inf ( # Not infected ) -> Folder created by Flash_Disinfector.
################## | State / Services / Information |
# Safe Mode : OK
# Show Hidden Files : OK
# Ndisuio -> Start = 3 ( Good = 3 | Bad = 4 )
# Ip6Fw -> Start = 2 ( Good = 2 | Bad = 4 )
# SharedAccess -> Start = 2 ( Good = 2 | Bad = 4 )
# wuauserv -> Start = 2 ( Good = 2 | Bad = 4 )
# wscsvc -> Start = 2 ( Good = 2 | Bad = 4 )
################## | PEH ... |
################## | Cracks / Keygens / Serials |
################## | ! End of report # FindyKill V6.005 ! |
Download Malwarebytes
https://www.malwarebytes.com/
Install it; the program will automatically update.
Once updated, the program will launch; click on the settings tab, and check the box: "Stop Internet Explorer during removal."
Now click on the scan tab and check the box: "Run a quick scan."
Then click on "Scan."
Let it scan the PC...
If any items are found > click on "Remove Selected."
If you're asked to restart > click "Yes."
At the end a report will open; save it so you can find it to post it on the forum.
Please copy and paste the report.
P.S.: Reports are also stored in the reports/log tab
--
See you!
https://www.malwarebytes.com/
Install it; the program will automatically update.
Once updated, the program will launch; click on the settings tab, and check the box: "Stop Internet Explorer during removal."
Now click on the scan tab and check the box: "Run a quick scan."
Then click on "Scan."
Let it scan the PC...
If any items are found > click on "Remove Selected."
If you're asked to restart > click "Yes."
At the end a report will open; save it so you can find it to post it on the forum.
Please copy and paste the report.
P.S.: Reports are also stored in the reports/log tab
--
See you!