Link to files and folders

hi-wave Posted messages 87 Status Member -  
 gen-hackman -
Hello everyone
since this afternoon all my files and folders on the disk have become links. they all have their names underlined and I only need to click once to open them. I would like to know if this is caused by a virus or something like that, or maybe I'm mistaken.
help me, it really scares me

Configuration: Windows XP / Firefox 3.6.8

21 answers

  • 1
  • 2
  1. gen-hackman
     
    Hello

    * Download here: USBFIX on your desktop

    /!\ Temporarily disable only while using USBFIX, the real-time protection of your Antivirus and Anti-spyware software, which may significantly hinder the search and cleaning procedure of the tool.

    If you have XP => double-click
    If you have Vista or Windows 7 => right-click "run as...."


    on the Usbfix icon located on your Desktop.
    On the page, click the button:

    “Search”

    /!\ Connect your external data sources to your PC (USB stick, external hard drive, etc...) that may have been infected without opening them

    - then click OK
    - Let the tool work.
    - Post the report that appears at the end.
    the report can be found at C:\ UsbFix.txt

    Note: "Process.exe", a component of the tool, is detected by some antivirus (AntiVir, Dr.Web, Kaspersky Anti-Virus) as a RiskTool.
    It is not a virus, but a utility designed to end processes.
    In the wrong hands, this utility could stop security software (Antivirus, Firewall...) hence the alert issued by these antivirus programs.
    --
    ♦G3и-н@¢км@и™©®♦
    0
  2. hi-wave Posted messages 87 Status Member 3
     
    Okay, I'm on it.
    0
  3. hi-wave Posted messages 87 Status Member 3
     
    here is the report

    CPU: Intel(R) Pentium(R) 4 CPU 1.60GHz
    Microsoft Windows XP Professional (5.1.2600 32-Bit) # Service Pack 3
    Internet Explorer 8.0.6001.18702

    Windows Firewall: Enabled
    Antivirus: AntiVir Desktop 9.0.1.32 [Enabled | Updated]
    RAM -> 1023 MB
    C:\ (%systemdrive%) -> Fixed disk # 29 GB (4 GB free - 14%) [Local Disk] # NTFS
    D:\ -> Fixed disk # 19 GB (1 GB free - 6%) [] # NTFS
    E:\ -> CD-ROM
    F:\ -> Removable disk # 2 GB (2 GB free - 100%) [NEW NAME] # FAT
    G:\ -> CD-ROM
    H:\ -> Removable disk # 964 MB (964 MB free - 100%) [STORE'N'GO] # FAT

    ################## | Infectious items |

    Present! C:\DOCUME~1\CEPLUS\LOCALS~1\Temp\xmlUpdater.exe
    Present! C:\Documents and Settings\CEPLUS\ctfmon.exe
    Present! D:\Autorun.inf
    Present! F:\Autorun.inf
    Present! H:\Autorun.inf
    Present! D:\image.jpg
    Present! F:\image.jpg
    Present! F:\DOBRERIBE
    Present! D:\DALFOLO (E)\7up\ceplus\CCP\CyberCafePro.5.Server.Client.Full\Ccp5-Client.exe
    Present! D:\DALFOLO (E)\7up\ceplus\CCP\CyberCafePro.5.Server.Client.Full\CyberCafePro.5.Server.Client.Full\Ccp5-Client.exe
    Present! D:\DALFOLO (E)\7up\ceplus\Ccp5-Client.exe

    ################## | Registry |

    Present! HKLM\software\microsoft\windows nt\currentversion\winlogon|Taskman
    Present! HKCU\Software\Microsoft\Windows\CurrentVersion\Run|cdoosoft

    ################## | Mountpoints2 |

    HKCU\.\.\.\.\Explorer\MountPoints2\{01c6b7d6-7224-11df-abcc-0004231cf8e5}
    Shell\AutoRun\Command = F:\MSN\D\Mic.exe
    Shell\open\Command = F:\MSN\D\Mic.exe

    HKCU\.\.\.\.\Explorer\MountPoints2\{08ca7d04-2dce-11db-ac23-0004231cf8e5}
    Shell\AutOplAy\Command = F:\jbeaa.exe
    Shell\AutoRun\Command = F:\jbeaa.exe
    Shell\explore\Command = F:\jbeaa.exe
    Shell\open\Command = F:\jbeaa.exe

    HKCU\.\.\.\.\Explorer\MountPoints2\{09b7a874-593d-11df-aba2-0004231cf8e5}
    Shell\AutoRun\Command = F:\MSN\D\Mic.exe
    Shell\open\Command = F:\MSN\D\Mic.exe

    HKCU\.\.\.\.\Explorer\MountPoints2\{0d368e94-73bf-11df-abce-0004231cf8e5}
    Shell\AutoRun\Command = F:\ARE\RUNNING\oF.exe
    Shell\open\Command = F:\ARE\RUNNING\oF.exe

    HKCU\.\.\.\.\Explorer\MountPoints2\{0e74c8b0-9a25-11df-ac0d-0004231cf8e5}
    Shell\AutoRun\Command = bar/bar32.exe
    Shell\exPLore\Command = bar/////////bar32.exe
    Shell\oPEn\Command = bar\\\\\\\\\\\bar32.exe

    HKCU\.\.\.\.\Explorer\MountPoints2\{10c1e159-ac3b-11df-ac2e-0004231cf8e5}
    Shell\AutoRun\Command = F:\DOBRERIBE/ziza.exe
    Shell\explore\Command = F:\DOBRERIBE/ziza.exe
    Shell\open\Command = F:\DOBRERIBE/ziza.exe

    HKCU\.\.\.\.\Explorer\MountPoints2\{10c1e15c-ac3b-11df-ac2e-0004231cf8e5}
    Shell\AutoRun\Command = PehxXt.eXe
    Shell\oPEN\Command = pehXXT.eXE

    HKCU\.\.\.\.\Explorer\MountPoints2\{10c1e15d-ac3b-11df-ac2e-0004231cf8e5}
    Shell\AutoRun\Command = C:\WINDOWS\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL nUeEx.exE

    HKCU\.\.\.\.\Explorer\MountPoints2\{200de8f4-7d1c-11df-abdb-0004231cf8e5}
    Shell\AutoRun\Command = F:\marko\\kraljevic.exe
    Shell\explore\Command = F:\marko\\\kraljevic.exe
    Shell\open\Command = F:\marko\\\kraljevic.exe

    HKCU\.\.\.\.\Explorer\MountPoints2\{29b3081a-95a9-11df-ac08-0004231cf8e5}
    Shell\autoplay\Command = pjvqgw.cmd
    Shell\AutoRun\Command = pjvqgw.cmd
    Shell\eXPloRe\Command = pjvqgw.cmd
    Shell\open\Command = pjvqgw.cmd

    HKCU\.\.\.\.\Explorer\MountPoints2\{2af49ee4-4a2d-11df-ab7f-0004231cf8e5}
    Shell\AutoRun\Command = nqdymj.exe
    Shell\open\Command = nqdymj.exe

    HKCU\.\.\.\.\Explorer\MountPoints2\{2afd70f5-9faf-11df-ac14-0004231cf8e5}
    Shell\AutoRun\Command = F:\DOBRERIBE/ziza.exe
    Shell\explore\Command = F:\DOBRERIBE/ziza.exe
    Shell\open\Command = F:\DOBRERIBE/ziza.exe

    HKCU\.\.\.\.\Explorer\MountPoints2\{3e6c0c5d-5c0f-11df-aba6-0004231cf8e5}
    Shell\AutoRun\Command = mirk\\okitab.exe
    Shell\explore\Command = mirk\\\okitab.exe
    Shell\open\Command = mirk\\\okitab.exe

    HKCU\.\.\.\.\Explorer\MountPoints2\{3e7f3ea4-4656-11df-ab67-00e04c3902b6}
    Shell\AutoRun\Command = DOBRERIBE/ziza.exe
    Shell\explore\Command = DOBRERIBE/ziza.exe
    Shell\open\Command = DOBRERIBE/ziza.exe

    HKCU\.\.\.\.\Explorer\MountPoints2\{480993d8-918e-11df-ac03-0004231cf8e5}
    Shell\AutoRun\Command = F:\mirk\\okitab.exe
    Shell\explore\Command = F:\mirk\\\okitab.exe
    Shell\open\Command = F:\mirk\\\okitab.exe

    HKCU\.\.\.\.\Explorer\MountPoints2\{480993d9-918e-11df-ac03-0004231cf8e5}
    Shell\AutoRun\Command = F:\mirk\\okitab.exe
    Shell\explore\Command = F:\mirk\\\okitab.exe
    Shell\open\Command = F:\mirk\\\okitab.exe

    HKCU\.\.\.\.\Explorer\MountPoints2\{4d12573b-67e4-11df-abbc-0004231cf8e5}
    Shell\AutoRun\Command = F:\DOBRERIBE/ziza.exe
    Shell\explore\Command = F:\DOBRERIBE/ziza.exe
    Shell\open\Command = F:\DOBRERIBE/ziza.exe

    HKCU\.\.\.\.\Explorer\MountPoints2\{4d12573d-67e4-11df-abbc-0004231cf8e5}
    Shell\AutoRun\Command = F:\DOBRERIBE/ziza.exe
    Shell\explore\Command = F:\DOBRERIBE/ziza.exe
    Shell\open\Command = F:\DOBRERIBE/ziza.exe

    HKCU\.\.\.\.\Explorer\MountPoints2\{5152fb50-6d54-11df-abc3-0004231cf8e5}
    Shell\AutoRun\Command = G:\mirk\\okitab.exe
    Shell\explore\Command = G:\mirk\\\okitab.exe
    Shell\open\Command = G:\mirk\\\okitab.exe

    HKCU\.\.\.\.\Explorer\MountPoints2\{55e45d91-7923-11df-abd6-0004231cf8e5}
    Shell\AutoRun\Command = F:\muza\\sguza.exe
    Shell\explore\Command = F:\
    Shell\open\Command = F:\muza\\\sguza.exe

    HKCU\.\.\.\.\Explorer\MountPoints2\{55e45d9b-7923-11df-abd6-0004231cf8e5}
    Shell\AutoRun\Command = F:\muza\\sguza.exe
    Shell\explore\Command = F:\muza\\\sguza.exe
    Shell\open\Command = F:\muza\\\sguza.exe

    HKCU\.\.\.\.\Explorer\MountPoints2\{568e15bc-7860-11df-abd5-0004231cf8e5}
    Shell\AutoRun\Command = F:\muza\\sguza.exe
    Shell\explore\Command = F:\muza\\\sguza.exe
    Shell\open\Command = F:\muza\\\sguza.exe

    HKCU\.\.\.\.\Explorer\MountPoints2\{569515b3-9af0-11df-ac0e-0004231cf8e5}
    Shell\AutopLay\Command = F:\lpwpe.exe
    Shell\AutoRun\Command = F:\lpwpe.exe
    Shell\eXPlore\Command = F:\lpwpe.exe
    Shell\open\Command = F:\lpwpe.exe

    HKCU\.\.\.\.\Explorer\MountPoints2\{571aa53e-7ab5-11df-abd9-0004231cf8e5}
    Shell\AutoRun\Command = ACC1\F1C1\acc1.exe
    Shell\open\Command = ACC1\F1C1\acc1.exe

    HKCU\.\.\.\.\Explorer\MountPoints2\{5d005704-995b-11df-ac0c-0004231cf8e5}
    Shell\AutoRun\Command = DOBRERIBE/ziza.exe
    Shell\explore\Command = DOBRERIBE/ziza.exe
    Shell\open\Command = DOBRERIBE/ziza.exe

    HKCU\.\.\.\.\Explorer\MountPoints2\{5d005708-995b-11df-ac0c-0004231cf8e5}
    Shell\AutoRun\Command = F:\ALKOHOLU///zdravooo.exe
    Shell\explore\Command = F:\ALKOHOLU///zdravooo.exe
    Shell\open\Command = F:\ALKOHOLU///zdravooo.exe

    HKCU\.\.\.\.\Explorer\MountPoints2\{5ed40a23-9ee2-11df-ac12-0004231cf8e5}
    Shell\AutoRun\Command = F:\DOBRERIBE/ziza.exe
    Shell\explore\Command = F:\DOBRERIBE/ziza.exe
    Shell\open\Command = F:\DOBRERIBE/ziza.exe

    HKCU\.\.\.\.\Explorer\MountPoints2\{6331e4de-696e-11df-abbf-0004231cf8e5}
    Shell\AutoRun\Command = F:\RECYCLERS32\autorun.exe
    Shell\open\Command = F:\RECYCLERS32\autorun.exe

    HKCU\.\.\.\.\Explorer\MountPoints2\{68fcef5c-7471-11df-abcf-0004231cf8e5}
    Shell\AutoRun\Command = H:\LaunchU3.exe -a

    HKCU\.\.\.\.\Explorer\MountPoints2\{6e0db4a1-8dac-11df-abfb-0004231cf8e5}
    Shell\AutoRun\Command = G:\
    Shell\explore\Command = G:\
    Shell\open\Command = G:\

    HKCU\.\.\.\.\Explorer\MountPoints2\{6fe2a32f-7dd7-11df-abdc-0004231cf8e5}
    Shell\AutoRun\Command = G:\1thes92p.exe
    Shell\open\Command = G:\1thes92p.exe

    HKCU\.\.\.\.\Explorer\MountPoints2\{6fe2a330-7dd7-11df-abdc-0004231cf8e5}
    Shell\AutoRun\Command = F:\RECYCLER\S-51-9-25-3434476501-1644491933-601314628-1214\Instmiv.exe
    Shell\open\Command = F:\RECYCLER\S-51-9-25-3434476501-1644491933-601314628-1214\Instmiv.exe

    HKCU\.\.\.\.\Explorer\MountPoints2\{6fe2a331-7dd7-11df-abdc-0004231cf8e5}
    Shell\AutoRun\Command = F:\setise\\zeljko.exe
    Shell\explore\Command = F:\setise\\\zeljko.exe
    Shell\open\Command = F:\setise\\\zeljko.exe

    HKCU\.\.\.\.\Explorer\MountPoints2\{737e1d7c-a459-11df-ac19-0004231cf8e5}
    Shell\AutoRun\Command = BOZANA/vujinovic.exe
    Shell\open\Command = BOZANA/vujinovic.exe

    HKCU\.\.\.\.\Explorer\MountPoints2\{75a5b53c-ab77-11df-ac2a-0004231cf8e5}
    Shell\AutoRun\Command = F:\LaunchU3.exe -a

    HKCU\.\.\.\.\Explorer\MountPoints2\{75a5b53d-ab77-11df-ac2a-0004231cf8e5}
    Shell\AutoRun\Command = G:\DOBRERIBE/ziza.exe
    Shell\explore\Command = G:\DOBRERIBE/ziza.exe
    Shell\open\Command = G:\DOBRERIBE/ziza.exe

    HKCU\.\.\.\.\Explorer\MountPoints2\{7c08a94c-79e9-11df-abd7-0004231cf8e5}
    Shell\AutoRun\Command = F:\DOBRERIBE/ziza.exe
    Shell\explore\Command = F:\DOBRERIBE/ziza.exe
    Shell\open\Command = F:\DOBRERIBE/ziza.exe

    HKCU\.\.\.\.\Explorer\MountPoints2\{89b3928b-6fbb-11df-abca-0004231cf8e5}
    Shell\AutoRun\Command = I:\POGRJESILA\\maychi.exe
    Shell\explore\Command = I:\POGRJESILA\\\maychi.exe
    Shell\open\Command = I:\POGRJESILA\\\maychi.exe

    HKCU\.\.\.\.\Explorer\MountPoints2\{8bbea173-8105-11df-abe1-0004231cf8e5}
    Shell\AutoRun\Command = F:\rane\\kure.exe
    Shell\explore\Command = F:\rane\\\kure.exe
    Shell\open\Command = F:\rane\\\kure.exe

    HKCU\.\.\.\.\Explorer\MountPoints2\{8f17a22e-8e64-11df-abfc-0004231cf8e5}
    Shell\AutoRun\Command = G:\mirk\\okitab.exe
    Shell\explore\Command = G:\mirk\\\okitab.exe
    Shell\open\Command = G:\mirk\\\okitab.exe

    HKCU\.\.\.\.\Explorer\MountPoints2\{8f960fdc-835b-11df-abe4-0004231cf8e5}
    Shell\AutoRun\Command = READER_SL.EXE

    HKCU\.\.\.\.\Explorer\MountPoints2\{9195ecbe-a78b-11df-ac1e-0004231cf8e5}
    Shell\AutoRun\Command = G:\mane\\strane.exe
    Shell\explore\Command = G:\mane\\\strane.exe
    Shell\open\Command = G:\mane\\\strane.exe

    HKCU\.\.\.\.\Explorer\MountPoints2\{94445804-a527-11df-ac1a-0004231cf8e5}
    Shell\AutoRun\Command = F:\mane\\strane.exe
    Shell\explore\Command = F:\mane\\\strane.exe
    Shell\open\Command = F:\mane\\\strane.exe

    HKCU\.\.\.\.\Explorer\MountPoints2\{96d6adf4-4879-11df-ab70-00e04c3902b6}
    Shell\AutoRun\Command = F:\PICHEK///mrakacha.exe
    Shell\open\Command = F:\PICHEK///mrakacha.exe

    HKCU\.\.\.\.\Explorer\MountPoints2\{97da635a-5ce4-11df-aba7-0004231cf8e5}
    Shell\auto\Command = G:\explorer.exe
    Shell\AutoRun\Command = C:\WINDOWS\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL explorer.exe

    HKCU\.\.\.\.\Explorer\MountPoints2\{97da635c-5ce4-11df-aba7-0004231cf8e5}
    Shell\AutoRun\Command = G:\mirk\\okitab.exe
    Shell\explore\Command = G:\mirk\\\okitab.exe
    Shell\open\Command = G:\mirk\\\okitab.exe

    HKCU\.\.\.\.\Explorer\MountPoints2\{97da6361-5ce4-11df-aba7-0004231cf8e5}
    Shell\AutoRun\Command = F:\lphfa.exe
    Shell\open\Command = F:\lphfa.exe

    HKCU\.\.\.\.\Explorer\MountPoints2\{9c712794-6b0d-11df-abc1-0004231cf8e5}
    Shell\AutoRun\Command = F:\THE\DANCE\DeaTH.exe
    Shell\open\Command = F:\THE\DANCE\DeaTH.exe

    HKCU\.\.\.\.\Explorer\MountPoints2\{b0ded568-6c96-11df-abc2-0004231cf8e5}
    Shell\AutoRun\Command = F:\trazim_previse\od_ovih\rima.exe
    Shell\open\Command = F:\trazim_previse\od_ovih\rima.exe

    HKCU\.\.\.\.\Explorer\MountPoints2\{b4cd131c-8fee-11df-ac01-0004231cf8e5}
    Shell\AutoRun\Command = F:\DOBRERIBE/ziza.exe
    Shell\explore\Command = F:\DOBRERIBE/ziza.exe
    Shell\open\Command = F:\DOBRERIBE/ziza.exe

    HKCU\.\.\.\.\Explorer\MountPoints2\{c5957b40-2d16-11db-ac21-0004231cf8e5}
    Shell\Auto\Command = F:\winlogon.exe
    Shell\AutoRun\Command = C:\WINDOWS\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL winlogon.exe
    Shell\open\Command = F:\winlogon.exe

    HKCU\.\.\.\.\Explorer\MountPoints2\{eee10856-6f00-11df-abc5-0004231cf8e5}
    Shell\AutoRun\Command = Driver\Files\DT.exe
    Shell\open\Command = Driver\Files\DT.exe

    HKCU\.\.\.\.\Explorer\MountPoints2\{f6c88650-829c-11df-abe3-0004231cf8e5}
    Shell\AutoRun\Command = F:\POGRJESILA\\maychi.exe
    Shell\explore\Command = F:\POGRJESILA\\\maychi.exe
    Shell\open\Command = F:\POGRJESILA\\\maychi.exe

    HKCU\.\.\.\.\Explorer\MountPoints2\{f6c88652-829c-11df-abe3-0004231cf8e5}
    Shell\AutoRun\Command = F:\DOBRERIBE/ziza.exe
    Shell\explore\Command = F:\DOBRERIBE/ziza.exe
    Shell\open\Command = F:\DOBRERIBE/ziza.exe

    HKCU\.\.\.\.\Explorer\MountPoints2\{f6c88658-829c-11df-abe3-0004231cf8e5}
    Shell\AutoRun\Command = F:\yhh.bat
    Shell\open\Command = F:\yhh.bat

    HKCU\.\.\.\.\Explorer\MountPoints2\{f733b1f8-47a7-11df-ab6b-00e04c3902b6}
    Shell\AutoRun\Command = F:\DOBRERIBE/ziza.exe
    Shell\explore\Command = F:\DOBRERIBE/ziza.exe
    Shell\open\Command = F:\DOBRERIBE/ziza.exe

    HKCU\.\.\.\.\Explorer\MountPoints2\{faa0d0ff-5115-11df-ab94-0004231cf8e5}
    Shell\AutoRun\Command = G:\DOBRERIBE/ziza.exe
    Shell\explore\Command = G:\DOBRERIBE/ziza.exe
    Shell\open\Command = G:\DOBRERIBE/ziza.exe

    HKCU\.\.\.\.\Explorer\MountPoints2\{faa0d102-5115-11df-ab94-0004231cf8e5}
    Shell\AutoRun\Command = G:\DOBRERIBE/ziza.exe
    Shell\explore\Command = G:\DOBRERIBE/ziza.exe
    Shell\open\Command = G:\DOBRERIBE/ziza.exe

    HKCU\.\.\.\.\Explorer\MountPoints2\{ff3d7a6c-67d9-11df-abbb-0004231cf8e5}
    Shell\AutoRun\Command = C:\WINDOWS\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL .\\\\name\\\\\\\\\\\\less.exe
    Shell\explore\Command = F:\name\\\\\\\\\\\\less.exe
    Shell\open\Command = F:\name\\\\\\\\\\\\less.exe

    ################## | Vaccine |

    (!) This computer is not vaccinated!

    ################## | E.O.F |
    0
  4. gen-hackman
     
    (!) Plug in your external data sources to your PC (USB flash drive, external hard drive, etc.) that may have been infected without opening them

    ▶ Double click (right-click "run as administrator" for Vista/7) on the UsbFix shortcut on your desktop

    ▶ In the main menu, choose the (Removal) option and press [enter]

    ▶ Your desktop will disappear; UsbFix will scan your PC, let the tool work.

    ▶ Then post the UsbFix.txt report that will appear with the desktop.

    Note: The UsbFix.txt report is saved to the root of the disk. (C:\UsbFix.txt)

    ( CTRL+A to select all, CTRL+C to copy, and CTRL+V to paste )
    --
    ♦G3и-н@¢км@и™©®♦
    0
  5. hi-wave Posted messages 87 Status Member 3
     
    ############################## | UsbFix 7.021 | [Removal]

    User: CEPLUS (Administrator) # SERVER [ ]
    Updated on 20/08/10 by El Desaparecido / C_XX
    Launched at 19:17:21 | 25/08/2010
    Website: http://pagesperso-orange.fr/NosTools/index.html
    Contact: FindyKill.Contact@gmail.com

    CPU: Intel(R) Pentium(R) 4 CPU 1.60GHz
    Microsoft Windows XP Professional (5.1.2600 32-Bit) # Service Pack 3
    Internet Explorer 8.0.6001.18702

    Windows Firewall: Enabled
    Antivirus: AntiVir Desktop 9.0.1.32 [Enabled | Updated]
    RAM -> 1023 MB
    C:\ (%systemdrive%) -> Fixed disk # 29 GB (7 GB free - 23%) [Local disk] # NTFS
    D:\ -> Fixed disk # 19 GB (1 GB free - 6%) [] # NTFS
    E:\ -> CD-ROM
    F:\ -> Removable disk # 2 GB (2 GB free - 100%) [NEW NAME] # FAT
    G:\ -> CD-ROM
    H:\ -> Removable disk # 964 MB (964 MB free - 100%) [STORE'N'GO] # FAT

    ################## | Infectious Elements |

    Deleted! C:\DOCUME~1\CEPLUS\LOCALS~1\Temp\xmlUpdater.exe
    Deleted! C:\Documents and Settings\CEPLUS\ctfmon.exe
    Deleted! D:\Autorun.inf
    Deleted! F:\Autorun.inf
    Deleted! H:\Autorun.inf
    Deleted! D:\image.jpg
    Not deleted! F:\image.jpg
    Deleted! F:\DOBRERIBE
    Deleted! D:\DALFOLO (E)\7up\ceplus\CCP\CyberCafePro.5.Server.Client.Full\Ccp5-Client.exe
    Deleted! D:\DALFOLO (E)\7up\ceplus\CCP\CyberCafePro.5.Server.Client.Full\CyberCafePro.5.Server.Client.Full\Ccp5-Client.exe
    Deleted! D:\DALFOLO (E)\7up\ceplus\Ccp5-Client.exe

    ################## | Registry |

    Deleted! HKLM\software\microsoft\windows nt\currentversion\winlogon|Taskman
    Deleted! HKCU\Software\Microsoft\Windows\CurrentVersion\Run|cdoosoft

    ################## | Mountpoints2 |

    Deleted! HKCU\.\.\.\.\Explorer\MountPoints2\{01c6b7d6-7224-11df-abcc-0004231cf8e5}
    Deleted! HKCU\.\.\.\.\Explorer\MountPoints2\{08ca7d04-2dce-11db-ac23-0004231cf8e5}
    Deleted! HKCU\.\.\.\.\Explorer\MountPoints2\{09b7a874-593d-11df-aba2-0004231cf8e5}
    Deleted! HKCU\.\.\.\.\Explorer\MountPoints2\{0d368e94-73bf-11df-abce-0004231cf8e5}
    Deleted! HKCU\.\.\.\.\Explorer\MountPoints2\{0e74c8b0-9a25-11df-ac0d-0004231cf8e5}
    Deleted! HKCU\.\.\.\.\Explorer\MountPoints2\{10c1e159-ac3b-11df-ac2e-0004231cf8e5}
    Deleted! HKCU\.\.\.\.\Explorer\MountPoints2\{10c1e15d-ac3b-11df-ac2e-0004231cf8e5}
    Deleted! HKCU\.\.\.\.\Explorer\MountPoints2\{200de8f4-7d1c-11df-abdb-0004231cf8e5}
    Deleted! HKCU\.\.\.\.\Explorer\MountPoints2\{29b3081a-95a9-11df-ac08-0004231cf8e5}
    Deleted! HKCU\.\.\.\.\Explorer\MountPoints2\{2af49ee4-4a2d-11df-ab7f-0004231cf8e5}
    Deleted! HKCU\.\.\.\.\Explorer\MountPoints2\{2afd70f5-9faf-11df-ac14-0004231cf8e5}
    Deleted! HKCU\.\.\.\.\Explorer\MountPoints2\{3e6c0c5d-5c0f-11df-aba6-0004231cf8e5}
    Deleted! HKCU\.\.\.\.\Explorer\MountPoints2\{480993d8-918e-11df-ac03-0004231cf8e5}
    Deleted! HKCU\.\.\.\.\Explorer\MountPoints2\{4d12573b-67e4-11df-abbc-0004231cf8e5}
    Deleted! HKCU\.\.\.\.\Explorer\MountPoints2\{5152fb50-6d54-11df-abc3-0004231cf8e5}
    Deleted! HKCU\.\.\.\.\Explorer\MountPoints2\{55e45d91-7923-11df-abd6-0004231cf8e5}
    Deleted! HKCU\.\.\.\.\Explorer\MountPoints2\{55e45d9b-7923-11df-ac2e-0004231cf8e5}
    Deleted! HKCU\.\.\.\.\Explorer\MountPoints2\{568e15bc-7860-11df-abd5-0004231cf8e5}
    Deleted! HKCU\.\.\.\.\Explorer\MountPoints2\{569515b3-9af0-11df-ac0e-0004231cf8e5}
    Deleted! HKCU\.\.\.\.\Explorer\MountPoints2\{5d005704-995b-11df-ac0c-0004231cf8e5}
    Deleted! HKCU\.\.\.\.\Explorer\MountPoints2\{5d005708-995b-11df-ac0c-0004231cf8e5}
    Deleted! HKCU\.\.\.\.\Explorer\MountPoints2\{6331e4de-696e-11df-abbf-0004231cf8e5}
    Deleted! HKCU\.\.\.\.\Explorer\MountPoints2\{68fcef5c-7471-11df-abcf-0004231cf8e5}
    Deleted! HKCU\.\.\.\.\Explorer\MountPoints2\{6e0db4a1-8dac-11df-abfb-0004231cf8e5}
    Deleted! HKCU\.\.\.\.\Explorer\MountPoints2\{6fe2a32f-7dd7-11df-abdc-0004231cf8e5}
    Deleted! HKCU\.\.\.\.\Explorer\MountPoints2\{6fe2a331-7dd7-11df-abdc-0004231cf8e5}
    Deleted! HKCU\.\.\.\.\Explorer\MountPoints2\{737e1d7c-a459-11df-ac19-0004231cf8e5}
    Deleted! HKCU\.\.\.\.\Explorer\MountPoints2\{75a5b53d-ab77-11df-ac2a-0004231cf8e5}
    Deleted! HKCU\.\.\.\.\Explorer\MountPoints2\{7c08a94c-79e9-11df-abd7-0004231cf8e5}
    Deleted! HKCU\.\.\.\.\Explorer\MountPoints2\{89b3928b-6fbb-11df-abca-0004231cf8e5}
    Deleted! HKCU\.\.\.\.\Explorer\MountPoints2\{8f17a22e-8e64-11df-abfc-0004231cf8e5}
    Deleted! HKCU\.\.\.\.\Explorer\MountPoints2\{9195ecbe-a78b-11df-ac1e-0004231cf8e5}
    Deleted! HKCU\.\.\.\.\Explorer\MountPoints2\{94445804-a527-11df-ac1a-0004231cf8e5}
    Deleted! HKCU\.\.\.\.\Explorer\MountPoints2\{96d6adf4-4879-11df-ab70-00e04c3902b6}
    Deleted! HKCU\.\.\.\.\Explorer\MountPoints2\{97da635a-5ce4-11df-aba7-0004231cf8e5}
    Deleted! HKCU\.\.\.\.\Explorer\MountPoints2\{97da6361-5ce4-11df-aba7-0004231cf8e5}
    Deleted! HKCU\.\.\.\.\Explorer\MountPoints2\{9c712794-6b0d-11df-abc1-0004231cf8e5}
    Deleted! HKCU\.\.\.\.\Explorer\MountPoints2\{b0ded568-6c96-11df-abc2-0004231cf8e5}
    Deleted! HKCU\.\.\.\.\Explorer\MountPoints2\{b4cd131c-8fee-11df-ac01-0004231cf8e5}
    Deleted! HKCU\.\.\.\.\Explorer\MountPoints2\{c5957b40-2d16-11db-ac21-0004231cf8e5}
    Deleted! HKCU\.\.\.\.\Explorer\MountPoints2\{eee10856-6f00-11df-abc5-0004231cf8e5}
    Deleted! HKCU\.\.\.\.\Explorer\MountPoints2\{f6c88650-829c-11df-abe3-0004231cf8e5}
    Deleted! HKCU\.\.\.\.\Explorer\MountPoints2\{f6c88658-829c-11df-abe3-0004231cf8e5}
    Deleted! HKCU\.\.\.\.\Explorer\MountPoints2\{faa0d0ff-5115-11df-ab94-0004231cf8e5}
    Deleted! HKCU\.\.\.\.\Explorer\MountPoints2\{ff3d7a6c-67d9-11df-abbb-0004231cf8e5}

    ################## | Listing |

    [12/04/2010 - 16:04:29 | A | 0] C:\AUTOEXEC.BAT
    [12/04/2010 - 15:57:02 | SH | 212] C:\boot.ini
    [28/08/2001 - 14:00:00 | RASH | 4952] C:\Bootfont.bin
    [12/04/2010 - 16:04:29 | A | 0] C:\CONFIG.SYS
    [16/07/2010 - 14:51:52 | D ] C:\D6
    [16/04/2010 - 09:33:21 | D ] C:\Documents and Settings
    [31/07/2010 - 19:36:39 | D ] C:\Downloads
    [25/08/2010 - 08:33:54 | ASH | 1073270784] C:\hiberfil.sys
    [12/04/2010 - 16:04:29 | RASH | 0] C:\IO.SYS
    [23/08/2010 - 19:13:14 | A | 413] C:\My documents.lnk
    [12/04/2010 - 16:04:29 | RASH | 0] C:\MSDOS.SYS
    [13/04/2010 - 11:21:38 | RHD ] C:\MSOCache
    [13/04/2008 - 09:43:04 | RASH | 47564] C:\NTDETECT.COM
    [13/04/2008 - 11:31:52 | RASH | 252240] C:\ntldr
    [25/08/2010 - 08:33:53 | ASH | 1610612736] C:\pagefile.sys
    [24/08/2010 - 18:50:26 | RD ] C:\Program Files
    [25/08/2010 - 19:29:00 | SHD ] C:\RECYCLER
    [13/07/2010 - 13:08:45 | A | 183] C:\sgbx.log
    [12/04/2010 - 16:09:55 | SHD ] C:\System Volume Information
    [25/08/2010 - 19:29:00 | D ] C:\UsbFix
    [25/08/2010 - 19:29:17 | A | 3982] C:\UsbFix.txt
    [25/08/2010 - 08:40:47 | D ] C:\WINDOWS
    [21/11/2009 - 03:32:50 | A | 734115840] D:\7 Plans Before My 30 Years_by thierry.avi
    [23/10/2009 - 10:02:00 | A | 33280] D:\ademci.doc
    [07/07/2010 - 17:52:14 | A | 15011] D:\agence nass.docx
    [12/06/2010 - 10:10:47 | D ] D:\AKON
    [24/04/2010 - 16:48:29 | D ] D:\ALORS
    [26/02/2010 - 20:04:20 | A | 380416] D:\annversaire.doc
    [27/01/2010 - 14:18:27 | D ] D:\ARAFATE MP3 ALL LAST
    [05/11/2009 - 09:27:39 | D ] D:\Atomix Virtual DJ 1.09 Full+Crack+skins+Effects (by charled v1.1)
    [18/02/2010 - 09:57:26 | A | 22528] D:\SALE CERTIFICATE.doc
    [30/12/2009 - 20:29:54 | A | 743220278] D:\Avatar.2009.FRENCH.REPACK.1CD.TS.MD.XViD.avi
    [20/08/2010 - 18:32:15 | A | 21526] D:\BATIM.xlsx
    [01/03/2010 - 13:13:45 | D ] D:\ccp
    [17/10/2009 - 17:00:11 | D ] D:\ccp(2)
    [16/10/2009 - 15:18:26 | A | 16496] D:\client.jpg
    [16/10/2009 - 15:23:24 | A | 15858] D:\client02.jpg
    [03/07/2009 - 14:57:14 | A | 734058496] D:\Code Omega The Prophecy of Shadows II.avi
    [06/03/2010 - 19:21:39 | A | 852480] D:\How to repair Vista with or without DVD.doc
    [09/03/2009 - 09:11:32 | A | 115072589] D:\Companion_Suite_IH_W_V1_1__2.exe
    [27/01/2010 - 17:08:31 | D ] D:\DALFOLO (E)
    [25/02/2010 - 09:46:42 | A | 25088] D:\job application.doc
    [27/01/2010 - 14:46:21 | D ] D:\DEZY 45 STUDENTS
    [06/02/2010 - 10:36:52 | D ] D:\Folder
    [22/05/2010 - 11:53:07 | D ] D:\important folder
    [03/02/2010 - 10:55:02 | A | 3169784] D:\DriverScanner.exe
    [11/09/2009 - 14:37:51 | A | 15514] D:\header (WordFIX).doc
    [02/05/2009 - 15:18:53 | A | 28672] D:\header.doc
    [05/05/2009 - 10:35:56 | D ] D:\HOPE MP3
    [12/10/2009 - 16:50:11 | A | 32768] D:\INVOICE FEELING.doc
    [01/03/2010 - 09:43:18 | A | 27136] D:\fanny.doc
    [17/02/2010 - 12:48:22 | A | 24064] D:\Faye.doc
    [01/03/2010 - 11:14:28 | A | 22528] D:\Faye2.doc
    [29/10/2009 - 14:12:06 | A | 6519272] D:\free-mp3-wma-converter_free_mp3_wma_converter_1.8_french_34863.exe
    [01/02/2009 - 17:54:13 | A | 8649058] D:\Free-YouTube-Downloader.exe
    [04/07/2009 - 11:06:01 | D ] D:\GARAGISTS
    [11/09/2009 - 16:20:10 | D ] D:\GARAGISTS MP3
    [30/07/2010 - 16:38:09 | A | 38912] D:\glacier.doc
    [10/05/2010 - 18:55:43 | A | 132926] D:\installation guide win98.docx
    [25/11/2009 - 14:33:16 | A | 3136288] D:\idman518.exe
    [26/08/2009 - 14:12:38 | D ] D:\Images
    [04/12/2009 - 09:10:42 | D ] D:\important
    [09/06/2010 - 11:30:55 | A | 5018624] D:\INTRODUCTIONS TO COMPUTERS AND WINDOWS.doc
    [27/04/2010 - 16:34:52 | A | 97525032] D:\iTunesSetup.exe
    [12/07/2010 - 12:32:32 | A | 54272] D:\KOUAME.doc
    [24/04/2010 - 12:37:47 | A | 50688] D:\RECEIPT OF ORDER ARTICLES.doc
    [23/04/2010 - 17:54:00 | A | 57344] D:\RECEIPT OF ORDERED ARTICLES.doc
    [25/02/2010 - 08:40:26 | A | 23040] D:\sponsorship request letter.doc
    [03/03/2010 - 10:17:13 | A | 32256] D:\letter.doc
    [29/03/2010 - 19:47:28 | A | 84480] D:\libraries.doc
    [06/06/2009 - 16:37:36 | A | 16510368] D:\LimeWireWin.exe
    [11/05/2009 - 17:29:11 | D ] D:\lodane
    [27/04/2009 - 14:54:41 | D ] D:\MADOUSSOU
    [19/05/2009 - 14:54:46 | A | 742] D:\Mario Forever.lnk
    [19/05/2009 - 14:53:38 | A | 21538712] D:\Mario_Forever41.exe
    [12/08/2010 - 17:47:12 | RD ] D:\my courses
    [06/02/2002 - 16:27:00 | A | 30633521] D:\moviexone.exe
    [16/11/2009 - 15:06:55 | RD ] D:\mp3
    [20/06/2009 - 10:54:19 | D ] D:\MPEGAV
    [22/09/2009 - 09:49:42 | RHD ] D:\MSOCache
    [20/11/2009 - 15:47:29 | RD ] D:\Music
    [12/11/2009 - 16:52:20 | A | 65148610] D:\NamoWebEditor8EnuTrial.exe
    [10/07/2010 - 11:00:40 | A | 14494] D:\OUR NEEDS.docx
    [22/12/2009 - 12:33:48 | RD ] D:\New folder
    [15/10/2009 - 14:37:32 | D ] D:\New folder (2)
    [27/04/2010 - 19:24:30 | D ] D:\New folder (3)
    [18/06/2009 - 17:21:23 | D ] D:\New folder1
    [27/01/2010 - 14:46:26 | D ] D:\PATIENCE DABANI
    [15/05/2009 - 12:06:07 | A | 130433] D:\Photo (5).jpg
    [05/06/2009 - 15:56:57 | A | 84992] D:\creation_plan1_06.doc
    [27/04/2010 - 19:21:59 | D ] D:\for iphone
    [26/02/2010 - 16:38:44 | A | 25088] D:\PROTOCOL D.doc
    [25/08/2010 - 19:29:00 | SHD ] D:\RECYCLER
    [14/08/2010 - 11:03:45 | A | 161280] D:\romaric.doc
    [01/12/2009 - 17:36:26 | A | 6343388] D:\Setup_FreeFlvConverter.exe
    [27/01/2010 - 11:35:02 | D ] D:\religious sound
    [18/06/2009 - 17:21:24 | RD ] D:\Sounds
    [06/05/2009 - 14:58:22 | A | 45568] D:\LAPTOP STOCKS.doc
    [12/04/2010 - 16:17:30 | SHD ] D:\System Volume Information
    [12/08/2010 - 17:47:10 | ASH | 8192] D:\Thumbs.db
    [05/05/2009 - 10:35:09 | D ] D:\Tiken Jah MP 3
    [23/06/2009 - 14:21:29 | A | 170052568] D:\TrueImageServerEcho_d_en.exe
    [14/11/2009 - 17:06:48 | D ] D:\Videos
    [30/05/2009 - 20:52:46 | A | 170203312] D:\VideoSpin_2_0_Setup.exe
    [28/07/2009 - 13:28:03 | D ] D:\Zook
    [24/03/2010 - 14:30:40 | AH | 162] D:\~$sponsorship request letter.doc
    [25/08/2010 - 16:10:10 | A | 73975] F:\commerce tools.jpg
    [25/08/2010 - 16:10:12 | A | 64282] F:\commerce tools (2).jpg
    [25/08/2010 - 16:10:12 | A | 66132] F:\commerce tools (3).jpg
    [25/08/2010 - 16:10:14 | A | 68105] F:\commerce tools (4).jpg
    [25/08/2010 - 16:10:16 | A | 68254] F:\commerce tools (5).jpg
    [25/08/2010 - 16:10:18 | A | 67594] F:\commerce tools (6).jpg
    [25/08/2010 - 16:10:18 | A | 75400] F:\commerce tools (7).jpg
    [25/08/2010 - 16:08:04 | RSHD ] F:\POGRJESILA
    [25/08/2010 - 18:49:46 | RSHD ] H:\POGRJESILA

    ################## | Vaccine |

    C:\Autorun.inf -> Folder created by UsbFix (El Desaparecido & C_XX)
    D:\Autorun.inf -> Folder created by UsbFix (El Desaparecido & C_XX)
    F:\Autorun.inf -> Folder created by UsbFix (El Desaparecido & C_XX)
    H:\Autorun.inf -> Folder created by UsbFix (El Desaparecido & C_XX)

    ################## | Upload |

    Please send the file: C:\UsbFix_Upload_Me_SERVER.zip
    https://www.ionos.fr/?affiliate_id=77097
    Thank you for your contribution.

    ################## | E.O.F |
    0
  6. gen-hackman
     
    DISABLE YOUR ANTIVIRUS AND FIREWALL IF PRESENT !!!!!(as it is mistakenly detected as an infection)

    ▶ Download here :List_Kill'em

    and save it to your desktop

    if you have XP => double click
    if you have Vista or Windows 7 => right-click "run as...."


    on the shortcut on your desktop to start the installation

    Leave checked:

    ♦ Run List_Kill'em

    once completed, click "finish" and the program will start automatically

    choose the Search option

    ▶ let the tool work

    a dialog box may open, in which case click "ok" or "Agree"

    when the white window appears, it takes a while, it's normal, it's an additional search for hidden files, the program is not frozen.

    ▶ Post the content of the report that opens at 100 % of the scan on the screen "COMPLETED"

    ▶▶▶ DO NOT POST IT ON THE FORUM

    To send it to me click on this link: http://www.cijoint.fr/

    ▶ Click on Browse and find the file C:\List'em.txt

    ▶ Click Open.

    ▶ Click "Click here to upload the file".

    A link of this form:

    http://www.cijoint.fr/cjlink.php?file=265368/cijSKAP5fU.txt

    is added to the page.

    ▶ Copy this link in your reply.

    ▶ Do the same with more.txt which is located on your desktop
    --
    ♦G3и-н@¢км@и™©®♦
    0
  7. hi-wave Posted messages 87 Status Member 3
     
    The link to download list_kill'em doesn't work. I'm not sure why, I'm going to look for a link where I can quickly get this log. Please don't drop the discussion. Thank you.
    0
  8. gen-hackman
     
    try here if you haven't found

    http://www.cijoint.fr/cjlink.php?file=cj201008/cijDmY9YpR.zip

    ?G3?-?@¢??@?(TM)©®?
    0
  9. hi-wave Posted messages 87 Status Member 3
     
    Thank you for the link. I was indeed able to download the log, but its analysis doesn't go beyond 30%, and it keeps going back to the HKU and HKLM hives. Is that normal?
    0
  10. hi-wave Posted messages 87 Status Member 3
     
    Voici le lien du fichier
    http://www.cijoint.fr/cjlink.php?file=cj201008/cijMnGtnjE.txt
    0
  11. hi-wave Posted messages 87 Status Member 3
     
    There is also a file more.txt; I don't know if you need that as well?
    0
  12. gen-hackman
     
    It proves that you don't read what I write
    --
    ♦G3и-н@¢ки™©®♦
    0
  13. hi-wave Posted messages 87 Status Member 3
     
    Excuse me, I wasn't paying proper attention.
    Here is the link to the file more.txt
    http://www.cijoint.fr/cjlink.php?file=cj201008/cijsdF75gP.txt
    0
  14. gen-hackman
     
    Analyze the following file(s) on Virustotal:

    Virus Total

    * * Paste the file paths directly, one by one, in the "Browse" space after each analysis:

    c:\windows\system32\drivers\HttpUsb.sys
    c:\windows\system32\drivers\mfxnt.sys
    C:\WINDOWS\System32\sgbxih.exe
    C:\WINDOWS\System32\csfpm.dll
    C:\WINDOWS\System32\dao360.dll
    C:\WINDOWS\System32\vwipxspx.dll


    * Now click on Send file and wait while "Current situation: analyzing" is displayed.
    * The file may be queued due to a large number of analysis requests. In this case, you will have to wait without refreshing the page.
    * When the analysis is complete, paste the link(s) to the page(s) in your next response.

    Then:

    If you have XP => double-click
    If you have Vista or Windows 7 => right-click "run as...."


    ▶ Relaunch List_Kill'em using the shortcut on your desktop.

    But this time:

    ▶ Choose the Clean Option

    Let the tool work.

    At the end of the scan, the window will close, and you will have a report named Kill'em.txt on your desktop,

    ▶ Paste the content in your response

    Then:


    ▶ Download here: Ad-remover to your desktop:

    ▶ Disconnect and close all running applications!

    If you have XP => double-click
    If you have Vista or Windows 7 => right-click "run as...."


    ▶ On "Ad-R.exe" to start the installation and keep the default installation settings.

    ▶ Click the Ad-remover shortcut that is on your desktop to launch the tool.

    ▶ In the main menu, choose "Clean option" and press [enter].

    ▶ Let the tool work and don't touch anything...

    ▶ Post the report that appears at the end on the forum...

    ( The report is also saved under C:\Ad-report.log )
    ( CTRL+A to select all, CTRL+C to copy, and CTRL+V to paste )

    ▶ Note: "Process.exe," a component of the tool, is detected by some antivirus (AntiVir, Dr.Web, Kaspersky Anti-Virus) as a RiskTool.
    It is not a virus, but a utility intended to terminate processes.
    In the wrong hands, this utility could stop security software (Antivirus, Firewall...) hence the alert issued by these antivirus programs.

    Then:

    Uninstall AD-Remover

    Then:

    * Download here: USBFIX to your desktop

    /!\ Temporarily disable only while using USBFIX, the real-time protection of your Antivirus and antispyware, which may significantly hinder the search and cleaning procedure of the tool.

    If you have XP => double-click
    If you have Vista or Windows 7 => right-click "run as...."


    On the Usbfix icon located on your Desktop.
    On the page, click the button:

    "Search"

    /!\ Plug in your external data sources to your PC (USB stick, external hard drive, etc...) that may have been infected without opening them

    - then click OK
    - Let the tool work.
    - Post the report that appears at the end.
    The report can be found at C:\UsbFix.txt

    Note: "Process.exe," a component of the tool, is detected by some antivirus (AntiVir, Dr.Web, Kaspersky Anti-Virus) as a RiskTool.
    It is not a virus, but a utility intended to terminate processes.
    In the wrong hands, this utility could stop security software (Antivirus, Firewall...) hence the alert issued by these antivirus.

    Then:

    (!) Plug in your external data sources to your PC (USB stick, external hard drive, etc...) that may have been infected without opening them

    ▶ Double click (right-click "as administrator" for Vista/7) on the shortcut UsbFix present on your desktop

    ▶ In the main menu, choose the option (Removal) and press [enter]

    ▶ Your desktop will disappear; UsbFix will scan your PC, let the tool work.

    ▶ Then post the report UsbFix.txt that will appear with the desktop.

    Note: The report UsbFix.txt is saved at the root of the disk. ( C:\UsbFix.txt )

    ( CTRL+A to select all, CTRL+C to copy, and CTRL+V to paste )

    Then:

    Uninstall usbfix

    While waiting for all reports in order
    --
    ♦G3и-н@¢км@и™©®♦
    0
  15. hi-wave Posted messages 87 Status Member 3
     
    Here are the results of the analyses on VirusTotal

    http://www.virustotal.com/file-scan/report.html?id=318414f8015a7021aa4ce31d14c3b985c792c7228dff5af6ed0dbdbfde8b58b3-1282832528

    http://www.virustotal.com/file-scan/report.html?id=a5f743fc84abfbd01b10e174198bf7e4fcdbf272653d40b3b38c0e3374d035d6-1282833896

    http://www.virustotal.com/file-scan/report.html?id=3781f45b5015b57fd2303597df1f76bbb86b7f5f94e7df98f01a60a670b7b566-1282834071

    http://www.virustotal.com/file-scan/report.html?id=3f2a8baa1d7431f8f2f4586a55069955ddc7ca7b701f8a796a35ca73d3dbf181-1282834275

    http://www.virustotal.com/file-scan/report.html?id=8f8f07dd6fd46105e9751c6183c03bc346e292736736c2f9e01dcf4c7a99232c-1264209216

    http://www.virustotal.com/file-scan/report.html?id=479f464f85b70d27f933d27380415ada1330c9354dc5dff34c8ac27e5ab8ca71-1244313095
    0
  16. hi-wave Posted messages 87 Status Member 3
     
    Here is the 2nd report of list_kill'em

    ¤¤¤¤¤¤¤¤¤¤ Kill'em by g3n-h@ckm@n 2.1.0.0 ¤¤¤¤¤¤¤¤¤¤

    User: CEPLUS (Users)
    Update on 24/08/2010 by g3n-h@ckm@n ::::: 23.20
    Start at: 14:59:35 | 26/08/2010

    Intel(R) Pentium(R) 4 CPU 1.60GHz
    Microsoft Windows XP Professional (5.1.2600 32-bit) # Service Pack 3
    Internet Explorer 8.0.6001.18702
    Windows Firewall Status: Enabled
    AV: AntiVir Desktop 9.0.1.32 [ Enabled | Updated ]

    A:\ -> 3.5-inch Floppy Drive
    C:\ -> Local hard disk | 28.62 Go (6.61 Go free) [Local Disk] | NTFS
    D:\ -> Local hard disk | 18.99 Go (1.2 Go free) | NTFS
    E:\ -> CD-ROM Drive
    G:\ -> CD-ROM Drive

    ¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤ Processes ------- Memory(Ko)

    C:\WINDOWS\System32\smss.exe ----0 Ko
    C:\WINDOWS\system32\csrss.exe ----0 Ko
    C:\WINDOWS\system32\winlogon.exe ----0 Ko
    C:\WINDOWS\system32\services.exe ----0 Ko
    C:\WINDOWS\system32\lsass.exe ----0 Ko
    C:\WINDOWS\system32\svchost.exe ----0 Ko
    C:\WINDOWS\system32\svchost.exe ----0 Ko
    C:\WINDOWS\System32\svchost.exe ----0 Ko
    C:\WINDOWS\system32\svchost.exe ----0 Ko
    C:\WINDOWS\system32\svchost.exe ----0 Ko
    C:\WINDOWS\system32\spoolsv.exe ----0 Ko
    C:\Program Files\Avira\AntiVir Desktop\sched.exe ----0 Ko
    C:\WINDOWS\system32\svchost.exe ----0 Ko
    C:\Program Files\Emsisoft Anti-Malware\a2service.exe ----0 Ko
    C:\Program Files\Avira\AntiVir Desktop\avguard.exe ----0 Ko
    C:\Program Files\Java\jre6\bin\jqs.exe ----0 Ko
    C:\WINDOWS\system32\svchost.exe ----0 Ko
    C:\WINDOWS\system32\wbem\wmiapsrv.exe ----0 Ko
    C:\WINDOWS\System32\alg.exe ----0 Ko
    C:\WINDOWS\Explorer.EXE ----0 Ko
    C:\Program Files\Avira\AntiVir Desktop\avgnt.exe ----0 Ko
    C:\Program Files\Common Files\Java\Java Update\jusched.exe ----0 Ko
    C:\PROGRA~1\COMPAN~2\ONETOU~3.EXE ----0 Ko
    C:\Program Files\Companion Suite IH\MFServices.exe ----0 Ko
    C:\Program Files\Companion Suite IH\MFPrintServer.exe ----0 Ko
    C:\Program Files\Companion OneTouch\MFLaunchOT.exe ----0 Ko
    C:\WINDOWS\system32\ctfmon.exe ----0 Ko
    C:\Program Files\SuperCopier2\SuperCopier2.exe ----0 Ko
    C:\Program Files\VisualTaskTips\VisualTaskTips.exe ----0 Ko
    C:\Program Files\BitComet\BitComet.exe ----0 Ko
    C:\Program Files\Messenger\msmsgs.exe ----0 Ko
    C:\Program Files\MagicDisc\MagicDisc.exe ----0 Ko
    C:\WINDOWS\BricoPacks\Vista Inspirat 2\RocketDock\RocketDock.exe ----0 Ko
    C:\WINDOWS\BricoPacks\Vista Inspirat 2\UberIcon\UberIcon Manager.exe ----0 Ko
    C:\Program Files\Cybera Server\cybserv.exe ----0 Ko
    C:\WINDOWS\System32\svchost.exe ----0 Ko
    C:\Program Files\VideoLAN\VLC\vlc.exe ----0 Ko
    C:\WINDOWS\system32\cmd.exe ----0 Ko
    C:\WINDOWS\system32\wbem\wmiprvse.exe ----0 Ko
    C:\Program Files\List_Kill'em\ERUNT.EXE ----0 Ko
    C:\Program Files\List_Kill'em\pv.exe ----0 Ko

    ¤¤¤¤¤¤¤¤¤¤ Files/folders:

    Quarantined & Deleted !!: C:\WINDOWS\SET3.tmp
    Quarantined & Deleted !!: C:\WINDOWS\SET4.tmp
    Quarantined & Deleted !!: C:\WINDOWS\SET8.tmp

    Quarantined & Deleted !!: C:\WINDOWS\Temp\nsc5.tmp
    Quarantined & Deleted !!: C:\Documents and Settings\CEPLUS\Local Settings\Temp\2.tmp
    Quarantined & Deleted !!: C:\Documents and Settings\CEPLUS\Local Settings\Temp\amt.log
    Quarantined & Deleted !!: C:\Documents and Settings\CEPLUS\Local Settings\Temp\bc5.tmp
    Quarantined & Deleted !!: C:\Documents and Settings\CEPLUS\Local Settings\Temp\bc7.tmp
    Quarantined & Deleted !!: C:\Documents and Settings\CEPLUS\Local Settings\Temp\bc8.tmp
    Quarantined & Deleted !!: C:\Documents and Settings\CEPLUS\Local Settings\Temp\bcA.tmp
    Quarantined & Deleted !!: C:\Documents and Settings\CEPLUS\Local Settings\Temp\bcB.tmp
    Quarantined & Deleted !!: C:\Documents and Settings\CEPLUS\Local Settings\Temp\bcC.tmp
    Quarantined & Deleted !!: C:\Documents and Settings\CEPLUS\Local Settings\Temp\bcD.tmp
    Quarantined & Deleted !!: C:\Documents and Settings\CEPLUS\Local Settings\Temp\bcE.tmp
    Quarantined & Deleted !!: C:\Documents and Settings\CEPLUS\Local Settings\Temp\dw.log
    Quarantined & Deleted !!: C:\Documents and Settings\CEPLUS\Local Settings\Temp\FS2.tmp
    Quarantined & Deleted !!: C:\Documents and Settings\CEPLUS\Local Settings\Temp\FS3.tmp
    Quarantined & Deleted !!: C:\Documents and Settings\CEPLUS\LOCAL Settings\Temp\A~NSISu_.exe
    Quarantined & Deleted !!: C:\Documents and Settings\CEPLUS\LOCAL Settings\Temp\FCTBSetup.exe
    Quarantined & Deleted !!: C:\Documents and Settings\CEPLUS\LOCAL Settings\Temp\ose00000.exe
    Quarantined & Deleted !!: C:\Documents and Settings\CEPLUS\LOCAL Settings\Temp\setup.exe
    Quarantined & Deleted !!: C:\Documents and Settings\CEPLUS\LOCAL Settings\Temp\acufutls.dll
    Quarantined & Deleted !!: C:\Documents and Settings\CEPLUS\LOCAL Settings\Temp\tbFree.dll
    Quarantined & Deleted !!: C:\Documents and Settings\CEPLUS\Local Settings\Temporary Internet Files\SuggestedSites.dat

    ¤¤¤¤¤¤¤¤¤¤ Hosts ¤¤¤¤¤¤¤¤¤¤

    127.0.0.1 localhost

    ¤¤¤¤¤¤¤¤¤¤ Registry ¤¤¤¤¤¤¤¤¤¤

    Deleted: HKLM\Software\Microsoft\Windows\CurrentVersion\Run: My Web Search Bar Search Scope Monitor
    Deleted: HKLM\SOFTWARE\Microsoft\Internet Explorer\Toolbar: {07B18EA9-A523-4961-B6BB-170DE4475CCA}
    Deleted: HKCU\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser: {0E5CBF21-D15F-11D0-8301-00AA005B4383}
    Deleted: HKCU\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser: {D4027C7F-154A-4066-A1AD-4243D8127440}
    Deleted: "HKCU\SOFTWARE\Microsoft\Internet Explorer\MenuExt\&Search"
    Deleted: "HKCU\software\microsoft\internet explorer\searchscopes\{171DEBEB-C3D4-40b7-AC73-056A5EBA4A7E}"
    Deleted: "HKCU\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{56256A51-B582-467e-B8D4-7786EDA79AE0}"
    Deleted: "HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{AFDBDDAA-5D3F-42EE-B79C-185A7020515B}"
    Deleted: "HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{59C7FC09-1C83-4648-B3E6-003D2BBC7481}"
    Deleted: "HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{68af847f-6e91-45dd-9b68-d6a12c30e5d7}"
    Deleted: "HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{9170B96C-28D4-4626-8358-27E6CAEEF907}"
    Deleted: "HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{D1A71FA0-FF48-48dd-9B6D-7A13A3E42127}"
    Deleted: "HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{DDB1968E-EAD6-40fd-8DAE-FF14757F60C7}"
    Deleted: "HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{F138D901-86F0-4383-99B6-9CDD406036DA}"
    Deleted: "HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{56256A51-B582-467e-B8D4-7786EDA79AE0}"
    Deleted: "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\Install.exe"
    Deleted: "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\Setup.exe"
    Deleted: HKCR\CLSID\{248dd896-bb45-11cf-9abc-0080c7e7b78d}
    Deleted: HKCR\CLSID\{248dd897-bb45-11cf-9abc-0080c7e7b78d}
    Deleted: HKCR\CLSID\{84da4fdf-a1cf-4195-8688-3e961f505983}
    Deleted: HKCR\CLSID\{9afb8248-617f-460d-9366-d71cdeda3179}
    Deleted: HKCR\Interface\{248dd892-bb45-11cf-9abc-0080c7e7b78d}
    Deleted: HKCR\Interface\{248dd893-bb45-11cf-9abc-0080c7e7b78d}
    Deleted: HKCR\interface\{3E53E2CB-86DB-4A4A-8BD9-FFEB7A64DF82}
    Deleted: HKCR\Interface\{63d0ed2d-b45b-4458-8b3b-60c69bbbd83c}
    Deleted: HKCR\Interface\{72ee7f04-15bd-4845-a005-d6711144d86a}
    Deleted: HKCR\Interface\{7473d293-b7bb-4f24-ae82-7e2ce94bb6a9}
    Deleted: HKCR\Interface\{a626cdbd-3d13-4f78-b819-440a28d7e8fc}
    Deleted: HKCR\interface\{cf54be1c-9359-4395-8533-1657cf209cfe}
    Deleted: HKCR\Interface\{e342af55-b78a-4cd0-a2bb-da7f52d9d25f}
    Deleted: HKCR\Interface\{e79dfbc9-5697-4fbd-94e5-5b2a9c7c1612}
    Deleted: HKCR\Interface\{e79dfbcb-5697-4fbd-94e5-5b2a9c7c1612}
    Deleted: HKCR\Interface\{f87d7fb5-9dc5-4c8c-b998-d8dfe02e2978}
    Deleted: HKCR\TypeLib\{248dd890-bb45-11cf-9abc-0080c7e7b78d}
    Deleted: HKCR\TypeLib\{D518921A-4A03-425E-9873-B9A71756821E}
    Deleted: HKCR\TypeLib\{E79DFBC0-5697-4FBD-94E5-5B2A9C7C1612}
    Deleted: HKCU\Software\Conduit
    Deleted: HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{00a6faf1-072e-44cf-8957-5838f569a31d}
    Deleted: HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{07b18ea1-a523-4961-b6bb-170de4475cca}
    Deleted: HKLM\Software\Conduit
    Deleted: HKLM\SOFTWARE\FocusInteractive
    Deleted: HKLM\SOFTWARE\Microsoft\Multimedia\WMPlayer\Schemes\f3pss
    Deleted: HKLM\Software\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{07B18EAB-A523-4961-B6BB-170DE4475CCA}
    Deleted: HKLM\Software\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{25560540-9571-4D7B-9389-0F166788785A}
    Deleted: HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{3dc201fb-e9c9-499c-a11f-23c360d7c3f8}
    Deleted: HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{3e720452-b472-4954-b7aa-33069eb53906}
    Deleted: HKLM\Software\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{63D0ED2C-B45B-4458-8B3B-60C69BBBD83C}
    Deleted: HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{7473d294-b7bb-4f24-ae82-7e2ce94bb6a9}
    Deleted: HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{98d9753d-d73b-42d5-8c85-4469cda897ab}
    Deleted: HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{9ff05104-b030-46fc-94b8-81276e4e27df}
    Deleted: HKLM\Software\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{E79DFBCA-5697-4FBD-94E5-5B2A9C7C1612}

    ¤¤¤¤¤¤¤¤¤¤ Internet Explorer ¤¤¤¤¤¤¤¤¤¤

    [HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Main]
    Start Page = https://www.msn.com/fr-fr/?ocid=iehp
    Local Page = C:\WINDOWS\system32\blank.htm
    Default_Search_URL = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
    Default_Page_URL = https://www.msn.com/fr-fr/?ocid=iehp
    Search Page = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF

    [HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main]
    Start Page = https://www.google.com/?gws_rd=ssl
    Local Page = C:\WINDOWS\system32\blank.htm
    Search Page = http://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch

    ¤¤¤¤¤¤¤¤¤¤ Security Center ¤¤¤¤¤¤¤¤¤¤

    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
    FirstRunDisabled = 1 ()
    AntiVirusDisableNotify = 0 (0x0)
    FirewallDisableNotify = 0 (0x0)
    UpdatesDisableNotify = 0 (0x0)
    AntiVirusOverride = 1 ()
    FirewallOverride = 1 ()

    ¤¤¤¤¤¤¤¤¤¤ Services ¤¤¤¤¤¤¤¤¤¤

    Ndisuio: Start = 3
    EapHost: Start = 2
    Ip6Fw: Start = 2
    SharedAccess: Start = 2
    wuauserv: Start = 2
    wscsvc: Start = 2

    ¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤
    Disk Cleaned
    anti-ver blaster: OK
    Prefetch cleaned
    ¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤

    FEATURE_BROWSER_EMULATION | svchost:
    ====================================

    Stealth MBR rootkit/Mebroot/Sinowal detector 0.3.7 by Gmer, http://www.gmer.net

    device: opened successfully
    user: MBR read successfully
    called modules: ntoskrnl.exe CLASSPNP.SYS disk.sys ACPI.sys hal.dll atapi.sys intelide.sys PCIIDEX.SYS
    kernel: MBR read successfully
    user & kernel MBR OK

    ¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤ ( EOF ) ¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤
    0
  17. hi-wave Posted messages 87 Status Member 3
     
    Here is the Ad-Remover report
    ======= AD-REMOVER REPORT 2.0.0.1,D | Windows XP/Vista/7 ONLY =======

    Updated by C_XX on 07/26/10 at 12:00
    Contact: AdRemover.contact[AT]gmail.com
    Website: http://pagesperso-orange.fr/NosTools/ad_remover.html

    C:\Program Files\Ad-Remover\main.exe (SCAN [1]) -> Launched at 16:09:05 on 08/26/2010, Normal mode

    Microsoft Windows XP Professional Service Pack 3 (X86)
    CEPLUS@SERVER ( )

    ============== SEARCH ==============

    0,Folder found: C:\DOCUME~1\CEPLUS\LOCALS~1\Temp\AskSearch
    0,File found: C:\DOCUME~1\CEPLUS\LOCALS~1\Temp\ASKSUTBLOG
    0,File found: C:\DOCUME~1\CEPLUS\LOCALS~1\Temp\Del_AskHPRFF.VBS

    1,Key found: HKLM\Software\Classes\CLSID\{799391D3-EB86-4bac-9BD3-CBFEA58A0E15}
    1,Key found: HKLM\Software\Classes\CLSID\{D858DAFC-9573-4811-B323-7011A3AA7E61}
    0,Key found: HKLM\Software\Classes\MyWebSearch.MultipleButton
    0,Key found: HKLM\Software\Classes\MyWebSearch.MultipleButton.1
    0,Key found: HKLM\Software\Classes\MyWebSearch.UrlAlertButton
    0,Key found: HKLM\Software\Classes\MyWebSearch.UrlAlertButton.1
    0,Key found: HKLM\Software\Classes\Toolbar.CT1060933
    0,Key found: HKLM\Software\Classes\Toolbar.CT2247187
    0,Key found: HKCU\Software\PopCap
    0,Key found: HKLM\Software\Microsoft\Internet Explorer\Low Rights\RunDll32Policy\f3ScrCtr.dll
    0,Key found: HKLM\Software\MozillaPlugins\@mywebsearch.com/Plugin

    0,Value found: HKLM\Software\Microsoft\Windows\CurrentVersion\Internet Settings\User Agent\post platform|FunWebProducts
    0,Value found: HKLM\Software\Mozilla\Firefox\Extensions|m3ffxtbr@mywebsearch.com

    ============== ADDITIONAL SCAN ==============

    ** Mozilla Firefox Version [3.6.8 (en)] **

    -- C:\Documents and Settings\CEPLUS\Application Data\Mozilla\FireFox\Profiles\7b4iyaqx.default\Prefs.js --
    browser.download.lastDir, D:\\my courses\\my music
    browser.startup.homepage_override.mstone, rv:1.9.2.8

    ========================================

    ** Internet Explorer Version [8.0.6001.18702] **

    [HKCU\Software\Microsoft\Internet Explorer\Main]
    Default_Page_URL: hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&pver=6&ar=msnhome
    Default_Search_URL: hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
    Do404Search: 0x01000000
    Enable Browser Extensions: yes
    Local Page: C:\WINDOWS\system32\blank.htm
    Search bar: hxxp://go.microsoft.com/fwlink/?linkid=54896
    Search Page: hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
    Show_ToolBar: yes
    Start Page: hxxp://www.google.com/
    Use Search Asst: no

    [HKLM\Software\Microsoft\Internet Explorer\Main]
    Default_Page_URL: hxxp://go.microsoft.com/fwlink/?LinkId=69157
    Default_Search_URL: hxxp://go.microsoft.com/fwlink/?LinkId=54896
    Delete_Temp_Files_On_Exit: yes
    Local Page: C:\WINDOWS\system32\blank.htm
    Search bar: hxxp://search.msn.com/spbasic.htm
    Search Page: hxxp://go.microsoft.com/fwlink/?LinkId=54896
    Start Page: hxxp://go.microsoft.com/fwlink/?LinkId=69157

    [HKLM\Software\Microsoft\Internet Explorer\ABOUTURLS]
    Tabs: res://ieframe.dll/tabswelcome.htm
    Blank: res://mshtml.dll/blank.htm

    ========================================

    C:\Program Files\Ad-Remover\Quarantine: 0 File(s)
    C:\Program Files\Ad-Remover\Backup: 1 File(s)

    C:\Ad-Report-SCAN[1].txt - 08/26/2010 (1599 Bytes)

    End at: 16:19:05, 08/26/2010

    ============== E.O.F ==============
    0
  18. hi-wave Posted messages 87 Status Member 3
     
    excuse me for my multiple mistakes
    here is the cleaning report

    ======= AD-REMOVER REPORT 2.0.0.1,D | WINDOWS XP/VISTA/7 ONLY =======

    Updated by C_XX on 07/26/10 at 12:00
    Contact: AdRemover.contact[AT]gmail.com
    Website: http://pagesperso-orange.fr/NosTools/ad_remover.html

    C:\Program Files\Ad-Remover\main.exe (CLEAN [1]) -> Launched at 16:31:32 on 08/26/2010, Normal mode

    Microsoft Windows XP Professional Service Pack 3 (X86)
    CEPLUS@SERVER ( )

    ============== ACTION(S) ==============

    0,Folder deleted: C:\DOCUME~1\CEPLUS\LOCALS~1\Temp\AskSearch
    0,File deleted: C:\DOCUME~1\CEPLUS\LOCALS~1\Temp\ASKSUTBLOG
    0,File deleted: C:\DOCUME~1\CEPLUS\LOCALS~1\Temp\Del_AskHPRFF.VBS

    (!) -- Temporary files deleted.

    1,Key deleted: HKLM\Software\Classes\CLSID\{799391D3-EB86-4bac-9BD3-CBFEA58A0E15}
    1,Key deleted: HKLM\Software\Classes\CLSID\{D858DAFC-9573-4811-B323-7011A3AA7E61}
    0,Key deleted: HKLM\Software\Classes\MyWebSearch.MultipleButton
    0,Key deleted: HKLM\Software\Classes\MyWebSearch.MultipleButton.1
    0,Key deleted: HKLM\Software\Classes\MyWebSearch.UrlAlertButton
    0,Key deleted: HKLM\Software\Classes\MyWebSearch.UrlAlertButton.1
    0,Key deleted: HKLM\Software\Classes\Toolbar.CT1060933
    0,Key deleted: HKLM\Software\Classes\Toolbar.CT2247187
    0,Key deleted: HKCU\Software\PopCap
    0,Key deleted: HKLM\Software\Microsoft\Internet Explorer\Low Rights\RunDll32Policy\f3ScrCtr.dll
    0,Key deleted: HKLM\Software\MozillaPlugins\@mywebsearch.com/Plugin

    0,Value deleted: HKLM\Software\Microsoft\Windows\CurrentVersion\Internet Settings\User Agent\post platform|FunWebProducts
    0,Value deleted: HKLM\Software\Mozilla\Firefox\Extensions|m3ffxtbr@mywebsearch.com

    ============== ADDITIONAL SCAN ==============

    ** Mozilla Firefox Version [3.6.8 (fr)] **

    -- C:\Documents and Settings\CEPLUS\Application Data\Mozilla\FireFox\Profiles\7b4iyaqx.default\Prefs.js --
    browser.download.lastDir, D:\\my courses\\my music
    browser.startup.homepage_override.mstone, rv:1.9.2.8

    ========================================

    ** Internet Explorer Version [8.0.6001.18702] **

    [HKCU\Software\Microsoft\Internet Explorer\Main]
    Default_Page_URL: hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&pver=6&ar=msnhome
    Default_Search_URL: hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
    Do404Search: 0x01000000
    Enable Browser Extensions: yes
    Local Page: C:\WINDOWS\system32\blank.htm
    Search bar: hxxp://go.microsoft.com/fwlink/?linkid=54896
    Show_ToolBar: yes
    Start Page: hxxp://fr.msn.com/
    Use Search Asst: no

    [HKLM\Software\Microsoft\Internet Explorer\Main]
    Default_Page_URL: hxxp://go.microsoft.com/fwlink/?LinkId=54896
    Default_Search_URL: hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
    Delete_Temp_Files_On_Exit: yes
    Local Page: C:\WINDOWS\system32\blank.htm
    Search bar: hxxp://search.msn.com/spbasic.htm
    Search Page: hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
    Start Page: hxxp://fr.msn.com/

    [HKLM\Software\Microsoft\Internet Explorer\ABOUTURLS]
    Tabs: res://ieframe.dll/tabswelcome.htm
    Blank: res://mshtml.dll/blank.htm

    ========================================

    C:\Program Files\Ad-Remover\Quarantine: 3 File(s)
    C:\Program Files\Ad-Remover\Backup: 14 File(s)

    C:\Ad-Report-CLEAN[1].txt - 08/26/2010 (692 Byte(s))
    C:\Ad-Report-SCAN[1].txt - 08/26/2010 (3370 Byte(s))

    Finished at: 16:33:26, 08/26/2010

    ============== E.O.F ==============
    0
  19. hi-wave Posted messages 87 Status Member 3
     
    Here is the USBFIX report after disabling my antivirus and connecting all my peripherals.

    ############################## | UsbFix 7.021 | [Search]

    User: CEPLUS (Administrator) # SERVER [ ]
    Updated on 20/08/10 by El Desaparecido / C_XX
    Started at 16:57:52 | 26/08/2010
    Website: http://pagesperso-orange.fr/NosTools/index.html
    Contact: FindyKill.Contact@gmail.com

    CPU: Intel(R) Pentium(R) 4 CPU 1.60GHz
    Microsoft Windows XP Professional (5.1.2600 32-Bit) # Service Pack 3
    Internet Explorer 8.0.6001.18702

    Windows Firewall: Enabled
    Antivirus: AntiVir Desktop 9.0.1.32 [(!) Disabled | Updated]
    RAM -> 1023 Mo
    C:\ (%systemdrive%) -> Fixed Drive # 29 Go (7 Go free - 23%) [Local Disk] # NTFS
    D:\ -> Fixed Drive # 19 Go (1 Go free - 6%) [] # NTFS
    E:\ -> CD-ROM
    F:\ -> Removable Drive # 964 Mo (962 Mo free - 100%) [STORE'N'GO] # FAT
    G:\ -> CD-ROM
    H:\ -> Removable Drive # 2 Go (2 Go free - 100%) [NEW NAME] # FAT

    ################## | Infectious Elements |

    Present! H:\Autorun.inf
    Present! H:\image.jpg
    Present! H:\DOBRERIBE

    ################## | Registry |

    ################## | Mountpoints2 |

    HKCU\.\.\.\.\Explorer\MountPoints2\{10c1e15c-ac3b-11df-ac2e-0004231cf8e5}
    Shell\AutoRun\Command = PehxXt.eXe
    Shell\oPEN\Command = pehXXT.eXE

    HKCU\.\.\.\.\Explorer\MountPoints2\{3e7f3ea4-4656-11df-ab67-00e04c3902b6}
    Shell\AutoRun\Command = DOBRERIBE/ziza.exe
    Shell\explore\Command = DOBRERIBE/ziza.exe
    Shell\open\Command = DOBRERIBE/ziza.exe

    HKCU\.\.\.\.\Explorer\MountPoints2\{480993d9-918e-11df-ac03-0004231cf8e5}
    Shell\AutoRun\Command = F:\mirk\\okitab.exe
    Shell\explore\Command = F:\mirk\\\okitab.exe
    Shell\open\Command = F:\mirk\\\okitab.exe

    HKCU\.\.\.\.\Explorer\MountPoints2\{4d12573d-67e4-11df-abbc-0004231cf8e5}
    Shell\AutoRun\Command = F:\DOBRERIBE/ziza.exe
    Shell\explore\Command = F:\DOBRERIBE/ziza.exe
    Shell\open\Command = F:\DOBRERIBE/ziza.exe

    HKCU\.\.\.\.\Explorer\MountPoints2\{571aa53e-7ab5-11df-abd9-0004231cf8e5}
    Shell\AutoRun\Command = ACC1\F1C1\acc1.exe
    Shell\open\Command = ACC1\F1C1\acc1.exe

    HKCU\.\.\.\.\Explorer\MountPoints2\{5ed40a23-9ee2-11df-ac12-0004231cf8e5}
    Shell\AutoRun\Command = F:\DOBRERIBE/ziza.exe
    Shell\explore\Command = F:\DOBRERIBE/ziza.exe
    Shell\open\Command = F:\DOBRERIBE/ziza.exe

    HKCU\.\.\.\.\Explorer\MountPoints2\{6fe2a330-7dd7-11df-abdc-0004231cf8e5}
    Shell\AutoRun\Command = F:\RECYCLER\S-51-9-25-3434476501-1644491933-601314628-1214\Instmiv.exe
    Shell\open\Command = F:\RECYCLER\S-51-9-25-3434476501-1644491933-601314628-1214\Instmiv.exe

    HKCU\.\.\.\.\Explorer\MountPoints2\{75a5b53c-ab77-11df-ac2a-0004231cf8e5}
    Shell\AutoRun\Command = F:\LaunchU3.exe -a

    HKCU\.\.\.\.\Explorer\MountPoints2\{8bbea173-8105-11df-abe1-0004231cf8e5}
    Shell\AutoRun\Command = F:\rane\\kure.exe
    Shell\explore\Command = F:\rane\\\kure.exe
    Shell\open\Command = F:\rane\\\kure.exe

    HKCU\.\.\.\.\Explorer\MountPoints2\{8f960fdc-835b-11df-abe4-0004231cf8e5}
    Shell\AutoRun\Command = READER_SL.EXE

    HKCU\.\.\.\.\Explorer\MountPoints2\{97da635c-5ce4-11df-aba7-0004231cf8e5}
    Shell\AutoRun\Command = G:\mirk\\okitab.exe
    Shell\explore\Command = G:\mirk\\\okitab.exe
    Shell\open\Command = G:\mirk\\\okitab.exe

    HKCU\.\.\.\.\Explorer\MountPoints2\{f6c88652-829c-11df-abe3-0004231cf8e5}
    Shell\AutoRun\Command = F:\DOBRERIBE/ziza.exe
    Shell\explore\Command = F:\DOBRERIBE/ziza.exe
    Shell\open\Command = F:\DOBRERIBE/ziza.exe

    HKCU\.\.\.\.\Explorer\MountPoints2\{faa0d102-5115-11df-ab94-0004231cf8e5}
    Shell\AutoRun\Command = G:\DOBRERIBE/ziza.exe
    Shell\explore\Command = G:\DOBRERIBE/ziza.exe
    Shell\open\Command = G:\DOBRERIBE/ziza.exe

    ################## | Vaccine |

    C:\Autorun.inf -> Folder created by UsbFix (El Desaparecido & C_XX)
    D:\Autorun.inf -> Folder created by UsbFix (El Desaparecido & C_XX)
    F:\Autorun.inf -> Folder created by UsbFix (El Desaparecido & C_XX)

    ################## | E.O.F |
    0
  20. hi-wave Posted messages 87 Status Member 3
     
    Here is the result of the UsbFix removal.
    ############################## | UsbFix 7.021 | [Removal]

    User: CEPLUS (Administrator) # SERVER [ ]
    Updated on 20/08/10 by El Desaparecido / C_XX
    Launched at 17:10:12 | 26/08/2010
    Website: http://pagesperso-orange.fr/NosTools/index.html
    Contact: FindyKill.Contact@gmail.com

    CPU: Intel(R) Pentium(R) 4 CPU 1.60GHz
    Microsoft Windows XP Professional (5.1.2600 32-Bit) # Service Pack 3
    Internet Explorer 8.0.6001.18702

    Windows Firewall: Enabled
    Antivirus: AntiVir Desktop 9.0.1.32 [Enabled | Updated]
    RAM -> 1023 MB
    C:\ (%systemdrive%) -> Local Disk # 29 GB (7 GB free - 23%) [Local Disk] # NTFS
    D:\ -> Local Disk # 19 GB (1 GB free - 6%) [] # NTFS
    E:\ -> CD-ROM
    F:\ -> Removable Disk # 964 MB (962 MB free - 100%) [STORE'N'GO] # FAT
    G:\ -> CD-ROM
    H:\ -> Removable Disk # 2 GB (2 GB free - 100%) [NEW NAME] # FAT

    ################## | Infectious Items |

    Deleted! H:\Autorun.inf
    Not deleted! H:\image.jpg
    Deleted! H:\DOBRERIBE

    ################## | Registry |

    ################## | Mountpoints2 |

    Deleted! HKCU\.\.\.\.\Explorer\MountPoints2\{10c1e15c-ac3b-11df-ac2e-0004231cf8e5}
    Deleted! HKCU\.\.\.\.\Explorer\MountPoints2\{3e7f3ea4-4656-11df-ab67-00e04c3902b6}
    Deleted! HKCU\.\.\.\.\Explorer\MountPoints2\{480993d9-918e-11df-ac03-0004231cf8e5}
    Deleted! HKCU\.\.\.\.\Explorer\MountPoints2\{4d12573d-67e4-11df-abbc-0004231cf8e5}
    Deleted! HKCU\.\.\.\.\Explorer\MountPoints2\{571aa53e-7ab5-11df-abd9-0004231cf8e5}
    Deleted! HKCU\.\.\.\.\Explorer\MountPoints2\{5ed40a23-9ee2-11df-ac12-0004231cf8e5}
    Deleted! HKCU\.\.\.\.\Explorer\MountPoints2\{6fe2a330-7dd7-11df-abdc-0004231cf8e5}
    Deleted! HKCU\.\.\.\.\Explorer\MountPoints2\{75a5b53c-ab77-11df-ac2a-0004231cf8e5}
    Deleted! HKCU\.\.\.\.\Explorer\MountPoints2\{8bbea173-8105-11df-abe1-0004231cf8e5}
    Deleted! HKCU\.\.\.\.\Explorer\MountPoints2\{8f960fdc-835b-11df-abe4-0004231cf8e5}
    Deleted! HKCU\.\.\.\.\Explorer\MountPoints2\{97da635c-5ce4-11df-aba7-0004231cf8e5}
    Deleted! HKCU\.\.\.\.\Explorer\MountPoints2\{f6c88652-829c-11df-abe3-0004231cf8e5}
    Deleted! HKCU\.\.\.\.\Explorer\MountPoints2\{faa0d102-5115-11df-ab94-0004231cf8e5}

    ################## | Listing |

    [26/08/2010 - 15:52:13 | A | 4] C:\AUTOEXEC.BAT
    [25/08/2010 - 19:29:18 | RASHD ] C:\Autorun.inf
    [12/04/2010 - 15:57:02 | SH | 212] C:\boot.ini
    [28/08/2001 - 14:00:00 | RASH | 4952] C:\Bootfont.bin
    [12/04/2010 - 16:04:29 | A | 0] C:\CONFIG.SYS
    [16/07/2010 - 14:51:52 | D ] C:\D6
    [16/04/2010 - 09:33:21 | D ] C:\Documents and Settings
    [31/07/2010 - 19:36:39 | D ] C:\Downloads
    [26/08/2010 - 16:43:59 | ASH | 1073270784] C:\hiberfil.sys
    [12/04/2010 - 16:04:29 | RASH | 0] C:\IO.SYS
    [26/08/2010 - 14:59:38 | D ] C:\Kill'em
    [26/08/2010 - 09:53:36 | A | 47984] C:\List'em.txt
    [23/08/2010 - 19:13:14 | A | 413] C:\My documents.lnk
    [12/04/2010 - 16:04:29 | RASH | 0] C:\MSDOS.SYS
    [13/04/2010 - 11:21:38 | RHD ] C:\MSOCache
    [13/04/2008 - 09:43:04 | RASH | 47564] C:\NTDETECT.COM
    [13/04/2008 - 11:31:52 | RASH | 252240] C:\ntldr
    [26/08/2010 - 16:43:58 | ASH | 1610612736] C:\pagefile.sys
    [26/08/2010 - 16:50:23 | RD ] C:\Program Files
    [26/08/2010 - 17:14:05 | SHD ] C:\RECYCLER
    [13/07/2010 - 13:08:45 | A | 183] C:\sgbx.log
    [12/04/2010 - 16:09:55 | SHD ] C:\System Volume Information
    [26/08/2010 - 17:14:05 | D ] C:\UsbFix
    [26/08/2010 - 17:14:06 | A | 1038] C:\UsbFix.txt
    [25/08/2010 - 19:29:20 | A | 48943] C:\UsbFix_Upload_Me_SERVER.zip
    [26/08/2010 - 14:59:56 | D ] C:\WINDOWS
    [21/11/2009 - 03:32:50 | A | 734115840] D:\7 Plans Before My 30 Years_by thierry.avi
    [23/10/2009 - 10:02:00 | A | 33280] D:\ademci.doc
    [07/07/2010 - 17:52:14 | A | 15011] D:\agency nass.docx
    [12/06/2010 - 10:10:47 | D ] D:\AKON
    [24/04/2010 - 16:48:29 | D ] D:\SO THEN
    [26/02/2010 - 20:04:20 | A | 380416] D:\anniversary.doc
    [27/01/2010 - 14:18:27 | D ] D:\ARAFATE MP3 LAST
    [05/11/2009 - 09:27:27 | D ] D:\Atomix Virtual DJ 1.09 Full+Crack+skins+Effects (by charled v1.1)
    [18/02/2010 - 09:57:26 | A | 22528] D:\SALE CERTIFICATE.doc
    [25/08/2010 - 19:29:18 | RASHD ] D:\Autorun.inf
    [30/12/2009 - 20:29:54 | A | 743220278] D:\Avatar.2009.FRENCH.REPACK.1CD.TS.MD.XViD.avi
    [20/08/2010 - 18:32:15 | A | 21526] D:\BATIM.xlsx
    [01/03/2010 - 13:13:45 | D ] D:\ccp
    [17/10/2009 - 17:00:11 | D ] D:\ccp(2)
    [16/10/2009 - 15:18:26 | A | 16496] D:\client.jpg
    [16/10/2009 - 15:23:24 | A | 15858] D:\client02.jpg
    [03/07/2009 - 14:57:14 | A | 734058496] D:\Code Omega The Prophecy of Darkness II.avi
    [06/03/2010 - 19:21:39 | A | 852480] D:\How to fix Vista with or without DVD.doc
    [09/03/2009 - 09:11:32 | A | 115072589] D:\Companion_Suite_IH_W_V1_1__2.exe
    [27/01/2010 - 17:08:31 | D ] D:\DALFOLO (E)
    [25/02/2010 - 09:46:42 | A | 25088] D:\job application.doc
    [27/01/2010 - 14:46:21 | D ] D:\DEZY 45 STUDENTS
    [06/02/2010 - 10:36:52 | D ] D:\Folder
    [22/05/2010 - 11:53:07 | D ] D:\important folder
    [03/02/2010 - 10:55:02 | A | 3169784] D:\DriverScanner.exe
    [11/09/2009 - 14:37:51 | A | 15514] D:\header (WordFIX).doc
    [02/05/2009 - 15:18:53 | A | 28672] D:\header.doc
    [05/05/2009 - 10:35:56 | D ] D:\HOPE MP3
    [12/10/2009 - 16:50:11 | A | 32768] D:\INVOICE FEELING.doc
    [01/03/2010 - 09:43:18 | A | 27136] D:\fanny.doc
    [17/02/2010 - 12:48:22 | A | 24064] D:\Faye.doc
    [01/03/2010 - 11:14:28 | A | 22528] D:\Faye2.doc
    [29/10/2009 - 14:12:06 | A | 6519272] D:\free-mp3-wma-converter_free_mp3_wma_converter_1.8_french_34863.exe
    [01/02/2009 - 17:54:13 | A | 8649058] D:\Free-YouTube-Downloader.exe
    [04/07/2009 - 11:06:01 | D ] D:\GARAGE OWNERS
    [11/09/2009 - 16:20:10 | D ] D:\GARAGE OWNERS MP3
    [30/07/2010 - 16:38:09 | A | 38912] D:\glacier.doc
    [10/05/2010 - 18:55:43 | A | 132926] D:\installation guide win98.docx
    [25/11/2009 - 14:33:16 | A | 3136288] D:\idman518.exe
    [26/08/2009 - 14:12:38 | D ] D:\Images
    [04/12/2009 - 09:10:42 | D ] D:\important
    [09/06/2010 - 11:30:55 | A | 5018624] D:\INTRODUCTIONS TO COMPUTERS AND WINDOWS.doc
    [27/04/2010 - 16:34:52 | A | 97525032] D:\iTunesSetup.exe
    [12/07/2010 - 12:32:32 | A | 54272] D:\KOUAME.doc
    [24/04/2010 - 12:37:47 | A | 50688] D:\RECEPTION OF ORDERED ITEMS.doc
    [23/04/2010 - 17:54:00 | A | 57344] D:\RECEPTION OF ORDERED ITEMS.doc
    [25/02/2010 - 08:40:26 | A | 23040] D:\sponsorship request letter.doc
    [03/03/2010 - 10:17:13 | A | 32256] D:\letter.doc
    [29/03/2010 - 19:47:28 | A | 84480] D:\libraries.doc
    [06/06/2009 - 16:37:36 | A | 16510368] D:\LimeWireWin.exe
    [11/05/2009 - 17:29:11 | D ] D:\lodane
    [27/04/2009 - 14:54:41 | D ] D:\MADOUSSOU
    [19/05/2009 - 14:54:46 | A | 742] D:\Mario Forever.lnk
    [19/05/2009 - 14:53:38 | A | 21538712] D:\Mario_Forever41.exe
    [12/08/2010 - 17:47:12 | RD ] D:\my courses
    [06/02/2002 - 16:27:00 | A | 30633521] D:\moviexone.exe
    [16/11/2009 - 15:06:55 | RD ] D:\mp3
    [20/06/2009 - 10:54:19 | D ] D:\MPEGAV
    [22/09/2009 - 09:49:42 | RHD ] D:\MSOCache
    [20/11/2009 - 15:47:29 | RD ] D:\Music
    [12/11/2009 - 16:52:20 | A | 65148610] D:\NamoWebEditor8EnuTrial.exe
    [10/07/2010 - 11:00:40 | A | 14494] D:\OUR NEEDS.docx
    [22/12/2009 - 12:33:48 | RD ] D:\New folder
    [15/10/2009 - 14:37:32 | D ] D:\New folder (2)
    [27/04/2010 - 19:24:30 | D ] D:\New folder (3)
    [18/06/2009 - 17:21:23 | D ] D:\New folder1
    [27/01/2010 - 14:46:26 | D ] D:\PATIENCE DABANI
    [15/05/2009 - 12:06:07 | A | 130433] D:\Photo (5).jpg
    [05/06/2009 - 15:56:57 | A | 84992] D:\creation_plan1_06.doc
    [27/04/2010 - 19:21:59 | D ] D:\for iphone
    [26/02/2010 - 16:38:44 | A | 25088] D:\PROTOCOL D.doc
    [26/08/2010 - 17:14:05 | SHD ] D:\RECYCLER
    [14/08/2010 - 11:03:45 | A | 161280] D:\romaric.doc
    [01/12/2009 - 17:36:26 | A | 6343388] D:\Setup_FreeFlvConverter.exe
    [27/01/2010 - 11:35:02 | D ] D:\religious sound
    [18/06/2009 - 17:21:24 | RD ] D:\Sounds
    [06/05/2009 - 14:58:22 | A | 45568] D:\STOCKS OF PORTABLE.doc
    [12/04/2010 - 16:17:30 | SHD ] D:\System Volume Information
    [12/08/2010 - 17:47:10 | ASH | 8192] D:\Thumbs.db
    [05/05/2009 - 10:35:09 | D ] D:\Tiken Jah MP 3
    [23/06/2009 - 14:21:29 | A | 170052568] D:\TrueImageServerEcho_d_en.exe
    [14/11/2009 - 17:06:48 | D ] D:\Videos
    [30/05/2009 - 20:52:46 | A | 170203312] D:\VideoSpin_2_0_Setup.exe
    [28/07/2009 - 13:28:03 | D ] D:\Zook
    [24/03/2010 - 14:30:40 | AH | 162] D:\~$request for sponsorship letter.doc
    [25/08/2010 - 18:49:46 | RSHD ] F:\POGRJESILA
    [25/08/2010 - 19:29:20 | D ] F:\Autorun.inf
    [24/08/2010 - 15:34:36 | D ] F:\steve
    [26/08/2010 - 11:33:46 | A | 24362] H:\OCR0001.rtf
    [26/08/2010 - 11:54:28 | RSHD ] H:\POGRJESILA
    [24/08/2010 - 11:25:44 | A | 368640] H:\receipt.doc
    [24/08/2010 - 11:25:56 | A | 510464] H:\thumbnail.doc
    [24/08/2010 - 11:25:14 | A | 558592] H:\logistics.doc
    [24/08/2010 - 11:21:00 | A | 480768] H:\Declaration.doc
    [26/08/2010 - 14:43:30 | A | 62857] H:\face 1.jpg
    [26/08/2010 - 14:43:32 | A | 51563] H:\face 2.jpg

    ################## | Vaccine |

    C:\Autorun.inf -> Folder created by UsbFix (El Desaparecido & C_XX)
    D:\Autorun.inf -> Folder created by UsbFix (El Desaparecido & C_XX)
    F:\Autorun.inf -> Folder created by UsbFix (El Desaparecido & C_XX)
    H:\Autorun.inf -> Folder created by UsbFix (El Desaparecido & C_XX)

    ################## | Upload |

    Please send the file: C:\UsbFix_Upload_Me_SERVER.zip
    https://www.ionos.fr/?affiliate_id=77097
    Thank you for your contribution.

    ################## | E.O.F |
    0
  • 1
  • 2