Link to files and folders
hi-wave
Posted messages
87
Status
Member
-
gen-hackman -
gen-hackman -
Hello everyone
since this afternoon all my files and folders on the disk have become links. they all have their names underlined and I only need to click once to open them. I would like to know if this is caused by a virus or something like that, or maybe I'm mistaken.
help me, it really scares me
Configuration: Windows XP / Firefox 3.6.8
since this afternoon all my files and folders on the disk have become links. they all have their names underlined and I only need to click once to open them. I would like to know if this is caused by a virus or something like that, or maybe I'm mistaken.
help me, it really scares me
Configuration: Windows XP / Firefox 3.6.8
21 answers
- 1
- 2
Next
-
Hello
* Download here: USBFIX on your desktop
/!\ Temporarily disable only while using USBFIX, the real-time protection of your Antivirus and Anti-spyware software, which may significantly hinder the search and cleaning procedure of the tool.
If you have XP => double-click
If you have Vista or Windows 7 => right-click "run as...."
on the Usbfix icon located on your Desktop.
On the page, click the button:
“Search”
/!\ Connect your external data sources to your PC (USB stick, external hard drive, etc...) that may have been infected without opening them
- then click OK
- Let the tool work.
- Post the report that appears at the end.
the report can be found at C:\ UsbFix.txt
Note: "Process.exe", a component of the tool, is detected by some antivirus (AntiVir, Dr.Web, Kaspersky Anti-Virus) as a RiskTool.
It is not a virus, but a utility designed to end processes.
In the wrong hands, this utility could stop security software (Antivirus, Firewall...) hence the alert issued by these antivirus programs.
--
♦G3и-н@¢км@и™©®♦ -
-
here is the report
CPU: Intel(R) Pentium(R) 4 CPU 1.60GHz
Microsoft Windows XP Professional (5.1.2600 32-Bit) # Service Pack 3
Internet Explorer 8.0.6001.18702
Windows Firewall: Enabled
Antivirus: AntiVir Desktop 9.0.1.32 [Enabled | Updated]
RAM -> 1023 MB
C:\ (%systemdrive%) -> Fixed disk # 29 GB (4 GB free - 14%) [Local Disk] # NTFS
D:\ -> Fixed disk # 19 GB (1 GB free - 6%) [] # NTFS
E:\ -> CD-ROM
F:\ -> Removable disk # 2 GB (2 GB free - 100%) [NEW NAME] # FAT
G:\ -> CD-ROM
H:\ -> Removable disk # 964 MB (964 MB free - 100%) [STORE'N'GO] # FAT
################## | Infectious items |
Present! C:\DOCUME~1\CEPLUS\LOCALS~1\Temp\xmlUpdater.exe
Present! C:\Documents and Settings\CEPLUS\ctfmon.exe
Present! D:\Autorun.inf
Present! F:\Autorun.inf
Present! H:\Autorun.inf
Present! D:\image.jpg
Present! F:\image.jpg
Present! F:\DOBRERIBE
Present! D:\DALFOLO (E)\7up\ceplus\CCP\CyberCafePro.5.Server.Client.Full\Ccp5-Client.exe
Present! D:\DALFOLO (E)\7up\ceplus\CCP\CyberCafePro.5.Server.Client.Full\CyberCafePro.5.Server.Client.Full\Ccp5-Client.exe
Present! D:\DALFOLO (E)\7up\ceplus\Ccp5-Client.exe
################## | Registry |
Present! HKLM\software\microsoft\windows nt\currentversion\winlogon|Taskman
Present! HKCU\Software\Microsoft\Windows\CurrentVersion\Run|cdoosoft
################## | Mountpoints2 |
HKCU\.\.\.\.\Explorer\MountPoints2\{01c6b7d6-7224-11df-abcc-0004231cf8e5}
Shell\AutoRun\Command = F:\MSN\D\Mic.exe
Shell\open\Command = F:\MSN\D\Mic.exe
HKCU\.\.\.\.\Explorer\MountPoints2\{08ca7d04-2dce-11db-ac23-0004231cf8e5}
Shell\AutOplAy\Command = F:\jbeaa.exe
Shell\AutoRun\Command = F:\jbeaa.exe
Shell\explore\Command = F:\jbeaa.exe
Shell\open\Command = F:\jbeaa.exe
HKCU\.\.\.\.\Explorer\MountPoints2\{09b7a874-593d-11df-aba2-0004231cf8e5}
Shell\AutoRun\Command = F:\MSN\D\Mic.exe
Shell\open\Command = F:\MSN\D\Mic.exe
HKCU\.\.\.\.\Explorer\MountPoints2\{0d368e94-73bf-11df-abce-0004231cf8e5}
Shell\AutoRun\Command = F:\ARE\RUNNING\oF.exe
Shell\open\Command = F:\ARE\RUNNING\oF.exe
HKCU\.\.\.\.\Explorer\MountPoints2\{0e74c8b0-9a25-11df-ac0d-0004231cf8e5}
Shell\AutoRun\Command = bar/bar32.exe
Shell\exPLore\Command = bar/////////bar32.exe
Shell\oPEn\Command = bar\\\\\\\\\\\bar32.exe
HKCU\.\.\.\.\Explorer\MountPoints2\{10c1e159-ac3b-11df-ac2e-0004231cf8e5}
Shell\AutoRun\Command = F:\DOBRERIBE/ziza.exe
Shell\explore\Command = F:\DOBRERIBE/ziza.exe
Shell\open\Command = F:\DOBRERIBE/ziza.exe
HKCU\.\.\.\.\Explorer\MountPoints2\{10c1e15c-ac3b-11df-ac2e-0004231cf8e5}
Shell\AutoRun\Command = PehxXt.eXe
Shell\oPEN\Command = pehXXT.eXE
HKCU\.\.\.\.\Explorer\MountPoints2\{10c1e15d-ac3b-11df-ac2e-0004231cf8e5}
Shell\AutoRun\Command = C:\WINDOWS\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL nUeEx.exE
HKCU\.\.\.\.\Explorer\MountPoints2\{200de8f4-7d1c-11df-abdb-0004231cf8e5}
Shell\AutoRun\Command = F:\marko\\kraljevic.exe
Shell\explore\Command = F:\marko\\\kraljevic.exe
Shell\open\Command = F:\marko\\\kraljevic.exe
HKCU\.\.\.\.\Explorer\MountPoints2\{29b3081a-95a9-11df-ac08-0004231cf8e5}
Shell\autoplay\Command = pjvqgw.cmd
Shell\AutoRun\Command = pjvqgw.cmd
Shell\eXPloRe\Command = pjvqgw.cmd
Shell\open\Command = pjvqgw.cmd
HKCU\.\.\.\.\Explorer\MountPoints2\{2af49ee4-4a2d-11df-ab7f-0004231cf8e5}
Shell\AutoRun\Command = nqdymj.exe
Shell\open\Command = nqdymj.exe
HKCU\.\.\.\.\Explorer\MountPoints2\{2afd70f5-9faf-11df-ac14-0004231cf8e5}
Shell\AutoRun\Command = F:\DOBRERIBE/ziza.exe
Shell\explore\Command = F:\DOBRERIBE/ziza.exe
Shell\open\Command = F:\DOBRERIBE/ziza.exe
HKCU\.\.\.\.\Explorer\MountPoints2\{3e6c0c5d-5c0f-11df-aba6-0004231cf8e5}
Shell\AutoRun\Command = mirk\\okitab.exe
Shell\explore\Command = mirk\\\okitab.exe
Shell\open\Command = mirk\\\okitab.exe
HKCU\.\.\.\.\Explorer\MountPoints2\{3e7f3ea4-4656-11df-ab67-00e04c3902b6}
Shell\AutoRun\Command = DOBRERIBE/ziza.exe
Shell\explore\Command = DOBRERIBE/ziza.exe
Shell\open\Command = DOBRERIBE/ziza.exe
HKCU\.\.\.\.\Explorer\MountPoints2\{480993d8-918e-11df-ac03-0004231cf8e5}
Shell\AutoRun\Command = F:\mirk\\okitab.exe
Shell\explore\Command = F:\mirk\\\okitab.exe
Shell\open\Command = F:\mirk\\\okitab.exe
HKCU\.\.\.\.\Explorer\MountPoints2\{480993d9-918e-11df-ac03-0004231cf8e5}
Shell\AutoRun\Command = F:\mirk\\okitab.exe
Shell\explore\Command = F:\mirk\\\okitab.exe
Shell\open\Command = F:\mirk\\\okitab.exe
HKCU\.\.\.\.\Explorer\MountPoints2\{4d12573b-67e4-11df-abbc-0004231cf8e5}
Shell\AutoRun\Command = F:\DOBRERIBE/ziza.exe
Shell\explore\Command = F:\DOBRERIBE/ziza.exe
Shell\open\Command = F:\DOBRERIBE/ziza.exe
HKCU\.\.\.\.\Explorer\MountPoints2\{4d12573d-67e4-11df-abbc-0004231cf8e5}
Shell\AutoRun\Command = F:\DOBRERIBE/ziza.exe
Shell\explore\Command = F:\DOBRERIBE/ziza.exe
Shell\open\Command = F:\DOBRERIBE/ziza.exe
HKCU\.\.\.\.\Explorer\MountPoints2\{5152fb50-6d54-11df-abc3-0004231cf8e5}
Shell\AutoRun\Command = G:\mirk\\okitab.exe
Shell\explore\Command = G:\mirk\\\okitab.exe
Shell\open\Command = G:\mirk\\\okitab.exe
HKCU\.\.\.\.\Explorer\MountPoints2\{55e45d91-7923-11df-abd6-0004231cf8e5}
Shell\AutoRun\Command = F:\muza\\sguza.exe
Shell\explore\Command = F:\
Shell\open\Command = F:\muza\\\sguza.exe
HKCU\.\.\.\.\Explorer\MountPoints2\{55e45d9b-7923-11df-abd6-0004231cf8e5}
Shell\AutoRun\Command = F:\muza\\sguza.exe
Shell\explore\Command = F:\muza\\\sguza.exe
Shell\open\Command = F:\muza\\\sguza.exe
HKCU\.\.\.\.\Explorer\MountPoints2\{568e15bc-7860-11df-abd5-0004231cf8e5}
Shell\AutoRun\Command = F:\muza\\sguza.exe
Shell\explore\Command = F:\muza\\\sguza.exe
Shell\open\Command = F:\muza\\\sguza.exe
HKCU\.\.\.\.\Explorer\MountPoints2\{569515b3-9af0-11df-ac0e-0004231cf8e5}
Shell\AutopLay\Command = F:\lpwpe.exe
Shell\AutoRun\Command = F:\lpwpe.exe
Shell\eXPlore\Command = F:\lpwpe.exe
Shell\open\Command = F:\lpwpe.exe
HKCU\.\.\.\.\Explorer\MountPoints2\{571aa53e-7ab5-11df-abd9-0004231cf8e5}
Shell\AutoRun\Command = ACC1\F1C1\acc1.exe
Shell\open\Command = ACC1\F1C1\acc1.exe
HKCU\.\.\.\.\Explorer\MountPoints2\{5d005704-995b-11df-ac0c-0004231cf8e5}
Shell\AutoRun\Command = DOBRERIBE/ziza.exe
Shell\explore\Command = DOBRERIBE/ziza.exe
Shell\open\Command = DOBRERIBE/ziza.exe
HKCU\.\.\.\.\Explorer\MountPoints2\{5d005708-995b-11df-ac0c-0004231cf8e5}
Shell\AutoRun\Command = F:\ALKOHOLU///zdravooo.exe
Shell\explore\Command = F:\ALKOHOLU///zdravooo.exe
Shell\open\Command = F:\ALKOHOLU///zdravooo.exe
HKCU\.\.\.\.\Explorer\MountPoints2\{5ed40a23-9ee2-11df-ac12-0004231cf8e5}
Shell\AutoRun\Command = F:\DOBRERIBE/ziza.exe
Shell\explore\Command = F:\DOBRERIBE/ziza.exe
Shell\open\Command = F:\DOBRERIBE/ziza.exe
HKCU\.\.\.\.\Explorer\MountPoints2\{6331e4de-696e-11df-abbf-0004231cf8e5}
Shell\AutoRun\Command = F:\RECYCLERS32\autorun.exe
Shell\open\Command = F:\RECYCLERS32\autorun.exe
HKCU\.\.\.\.\Explorer\MountPoints2\{68fcef5c-7471-11df-abcf-0004231cf8e5}
Shell\AutoRun\Command = H:\LaunchU3.exe -a
HKCU\.\.\.\.\Explorer\MountPoints2\{6e0db4a1-8dac-11df-abfb-0004231cf8e5}
Shell\AutoRun\Command = G:\
Shell\explore\Command = G:\
Shell\open\Command = G:\
HKCU\.\.\.\.\Explorer\MountPoints2\{6fe2a32f-7dd7-11df-abdc-0004231cf8e5}
Shell\AutoRun\Command = G:\1thes92p.exe
Shell\open\Command = G:\1thes92p.exe
HKCU\.\.\.\.\Explorer\MountPoints2\{6fe2a330-7dd7-11df-abdc-0004231cf8e5}
Shell\AutoRun\Command = F:\RECYCLER\S-51-9-25-3434476501-1644491933-601314628-1214\Instmiv.exe
Shell\open\Command = F:\RECYCLER\S-51-9-25-3434476501-1644491933-601314628-1214\Instmiv.exe
HKCU\.\.\.\.\Explorer\MountPoints2\{6fe2a331-7dd7-11df-abdc-0004231cf8e5}
Shell\AutoRun\Command = F:\setise\\zeljko.exe
Shell\explore\Command = F:\setise\\\zeljko.exe
Shell\open\Command = F:\setise\\\zeljko.exe
HKCU\.\.\.\.\Explorer\MountPoints2\{737e1d7c-a459-11df-ac19-0004231cf8e5}
Shell\AutoRun\Command = BOZANA/vujinovic.exe
Shell\open\Command = BOZANA/vujinovic.exe
HKCU\.\.\.\.\Explorer\MountPoints2\{75a5b53c-ab77-11df-ac2a-0004231cf8e5}
Shell\AutoRun\Command = F:\LaunchU3.exe -a
HKCU\.\.\.\.\Explorer\MountPoints2\{75a5b53d-ab77-11df-ac2a-0004231cf8e5}
Shell\AutoRun\Command = G:\DOBRERIBE/ziza.exe
Shell\explore\Command = G:\DOBRERIBE/ziza.exe
Shell\open\Command = G:\DOBRERIBE/ziza.exe
HKCU\.\.\.\.\Explorer\MountPoints2\{7c08a94c-79e9-11df-abd7-0004231cf8e5}
Shell\AutoRun\Command = F:\DOBRERIBE/ziza.exe
Shell\explore\Command = F:\DOBRERIBE/ziza.exe
Shell\open\Command = F:\DOBRERIBE/ziza.exe
HKCU\.\.\.\.\Explorer\MountPoints2\{89b3928b-6fbb-11df-abca-0004231cf8e5}
Shell\AutoRun\Command = I:\POGRJESILA\\maychi.exe
Shell\explore\Command = I:\POGRJESILA\\\maychi.exe
Shell\open\Command = I:\POGRJESILA\\\maychi.exe
HKCU\.\.\.\.\Explorer\MountPoints2\{8bbea173-8105-11df-abe1-0004231cf8e5}
Shell\AutoRun\Command = F:\rane\\kure.exe
Shell\explore\Command = F:\rane\\\kure.exe
Shell\open\Command = F:\rane\\\kure.exe
HKCU\.\.\.\.\Explorer\MountPoints2\{8f17a22e-8e64-11df-abfc-0004231cf8e5}
Shell\AutoRun\Command = G:\mirk\\okitab.exe
Shell\explore\Command = G:\mirk\\\okitab.exe
Shell\open\Command = G:\mirk\\\okitab.exe
HKCU\.\.\.\.\Explorer\MountPoints2\{8f960fdc-835b-11df-abe4-0004231cf8e5}
Shell\AutoRun\Command = READER_SL.EXE
HKCU\.\.\.\.\Explorer\MountPoints2\{9195ecbe-a78b-11df-ac1e-0004231cf8e5}
Shell\AutoRun\Command = G:\mane\\strane.exe
Shell\explore\Command = G:\mane\\\strane.exe
Shell\open\Command = G:\mane\\\strane.exe
HKCU\.\.\.\.\Explorer\MountPoints2\{94445804-a527-11df-ac1a-0004231cf8e5}
Shell\AutoRun\Command = F:\mane\\strane.exe
Shell\explore\Command = F:\mane\\\strane.exe
Shell\open\Command = F:\mane\\\strane.exe
HKCU\.\.\.\.\Explorer\MountPoints2\{96d6adf4-4879-11df-ab70-00e04c3902b6}
Shell\AutoRun\Command = F:\PICHEK///mrakacha.exe
Shell\open\Command = F:\PICHEK///mrakacha.exe
HKCU\.\.\.\.\Explorer\MountPoints2\{97da635a-5ce4-11df-aba7-0004231cf8e5}
Shell\auto\Command = G:\explorer.exe
Shell\AutoRun\Command = C:\WINDOWS\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL explorer.exe
HKCU\.\.\.\.\Explorer\MountPoints2\{97da635c-5ce4-11df-aba7-0004231cf8e5}
Shell\AutoRun\Command = G:\mirk\\okitab.exe
Shell\explore\Command = G:\mirk\\\okitab.exe
Shell\open\Command = G:\mirk\\\okitab.exe
HKCU\.\.\.\.\Explorer\MountPoints2\{97da6361-5ce4-11df-aba7-0004231cf8e5}
Shell\AutoRun\Command = F:\lphfa.exe
Shell\open\Command = F:\lphfa.exe
HKCU\.\.\.\.\Explorer\MountPoints2\{9c712794-6b0d-11df-abc1-0004231cf8e5}
Shell\AutoRun\Command = F:\THE\DANCE\DeaTH.exe
Shell\open\Command = F:\THE\DANCE\DeaTH.exe
HKCU\.\.\.\.\Explorer\MountPoints2\{b0ded568-6c96-11df-abc2-0004231cf8e5}
Shell\AutoRun\Command = F:\trazim_previse\od_ovih\rima.exe
Shell\open\Command = F:\trazim_previse\od_ovih\rima.exe
HKCU\.\.\.\.\Explorer\MountPoints2\{b4cd131c-8fee-11df-ac01-0004231cf8e5}
Shell\AutoRun\Command = F:\DOBRERIBE/ziza.exe
Shell\explore\Command = F:\DOBRERIBE/ziza.exe
Shell\open\Command = F:\DOBRERIBE/ziza.exe
HKCU\.\.\.\.\Explorer\MountPoints2\{c5957b40-2d16-11db-ac21-0004231cf8e5}
Shell\Auto\Command = F:\winlogon.exe
Shell\AutoRun\Command = C:\WINDOWS\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL winlogon.exe
Shell\open\Command = F:\winlogon.exe
HKCU\.\.\.\.\Explorer\MountPoints2\{eee10856-6f00-11df-abc5-0004231cf8e5}
Shell\AutoRun\Command = Driver\Files\DT.exe
Shell\open\Command = Driver\Files\DT.exe
HKCU\.\.\.\.\Explorer\MountPoints2\{f6c88650-829c-11df-abe3-0004231cf8e5}
Shell\AutoRun\Command = F:\POGRJESILA\\maychi.exe
Shell\explore\Command = F:\POGRJESILA\\\maychi.exe
Shell\open\Command = F:\POGRJESILA\\\maychi.exe
HKCU\.\.\.\.\Explorer\MountPoints2\{f6c88652-829c-11df-abe3-0004231cf8e5}
Shell\AutoRun\Command = F:\DOBRERIBE/ziza.exe
Shell\explore\Command = F:\DOBRERIBE/ziza.exe
Shell\open\Command = F:\DOBRERIBE/ziza.exe
HKCU\.\.\.\.\Explorer\MountPoints2\{f6c88658-829c-11df-abe3-0004231cf8e5}
Shell\AutoRun\Command = F:\yhh.bat
Shell\open\Command = F:\yhh.bat
HKCU\.\.\.\.\Explorer\MountPoints2\{f733b1f8-47a7-11df-ab6b-00e04c3902b6}
Shell\AutoRun\Command = F:\DOBRERIBE/ziza.exe
Shell\explore\Command = F:\DOBRERIBE/ziza.exe
Shell\open\Command = F:\DOBRERIBE/ziza.exe
HKCU\.\.\.\.\Explorer\MountPoints2\{faa0d0ff-5115-11df-ab94-0004231cf8e5}
Shell\AutoRun\Command = G:\DOBRERIBE/ziza.exe
Shell\explore\Command = G:\DOBRERIBE/ziza.exe
Shell\open\Command = G:\DOBRERIBE/ziza.exe
HKCU\.\.\.\.\Explorer\MountPoints2\{faa0d102-5115-11df-ab94-0004231cf8e5}
Shell\AutoRun\Command = G:\DOBRERIBE/ziza.exe
Shell\explore\Command = G:\DOBRERIBE/ziza.exe
Shell\open\Command = G:\DOBRERIBE/ziza.exe
HKCU\.\.\.\.\Explorer\MountPoints2\{ff3d7a6c-67d9-11df-abbb-0004231cf8e5}
Shell\AutoRun\Command = C:\WINDOWS\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL .\\\\name\\\\\\\\\\\\less.exe
Shell\explore\Command = F:\name\\\\\\\\\\\\less.exe
Shell\open\Command = F:\name\\\\\\\\\\\\less.exe
################## | Vaccine |
(!) This computer is not vaccinated!
################## | E.O.F | -
▶ (!) Plug in your external data sources to your PC (USB flash drive, external hard drive, etc.) that may have been infected without opening them
▶ Double click (right-click "run as administrator" for Vista/7) on the UsbFix shortcut on your desktop
▶ In the main menu, choose the (Removal) option and press [enter]
▶ Your desktop will disappear; UsbFix will scan your PC, let the tool work.
▶ Then post the UsbFix.txt report that will appear with the desktop.
Note: The UsbFix.txt report is saved to the root of the disk. (C:\UsbFix.txt)
( CTRL+A to select all, CTRL+C to copy, and CTRL+V to paste )
--
♦G3и-н@¢км@и™©®♦ -
############################## | UsbFix 7.021 | [Removal]
User: CEPLUS (Administrator) # SERVER [ ]
Updated on 20/08/10 by El Desaparecido / C_XX
Launched at 19:17:21 | 25/08/2010
Website: http://pagesperso-orange.fr/NosTools/index.html
Contact: FindyKill.Contact@gmail.com
CPU: Intel(R) Pentium(R) 4 CPU 1.60GHz
Microsoft Windows XP Professional (5.1.2600 32-Bit) # Service Pack 3
Internet Explorer 8.0.6001.18702
Windows Firewall: Enabled
Antivirus: AntiVir Desktop 9.0.1.32 [Enabled | Updated]
RAM -> 1023 MB
C:\ (%systemdrive%) -> Fixed disk # 29 GB (7 GB free - 23%) [Local disk] # NTFS
D:\ -> Fixed disk # 19 GB (1 GB free - 6%) [] # NTFS
E:\ -> CD-ROM
F:\ -> Removable disk # 2 GB (2 GB free - 100%) [NEW NAME] # FAT
G:\ -> CD-ROM
H:\ -> Removable disk # 964 MB (964 MB free - 100%) [STORE'N'GO] # FAT
################## | Infectious Elements |
Deleted! C:\DOCUME~1\CEPLUS\LOCALS~1\Temp\xmlUpdater.exe
Deleted! C:\Documents and Settings\CEPLUS\ctfmon.exe
Deleted! D:\Autorun.inf
Deleted! F:\Autorun.inf
Deleted! H:\Autorun.inf
Deleted! D:\image.jpg
Not deleted! F:\image.jpg
Deleted! F:\DOBRERIBE
Deleted! D:\DALFOLO (E)\7up\ceplus\CCP\CyberCafePro.5.Server.Client.Full\Ccp5-Client.exe
Deleted! D:\DALFOLO (E)\7up\ceplus\CCP\CyberCafePro.5.Server.Client.Full\CyberCafePro.5.Server.Client.Full\Ccp5-Client.exe
Deleted! D:\DALFOLO (E)\7up\ceplus\Ccp5-Client.exe
################## | Registry |
Deleted! HKLM\software\microsoft\windows nt\currentversion\winlogon|Taskman
Deleted! HKCU\Software\Microsoft\Windows\CurrentVersion\Run|cdoosoft
################## | Mountpoints2 |
Deleted! HKCU\.\.\.\.\Explorer\MountPoints2\{01c6b7d6-7224-11df-abcc-0004231cf8e5}
Deleted! HKCU\.\.\.\.\Explorer\MountPoints2\{08ca7d04-2dce-11db-ac23-0004231cf8e5}
Deleted! HKCU\.\.\.\.\Explorer\MountPoints2\{09b7a874-593d-11df-aba2-0004231cf8e5}
Deleted! HKCU\.\.\.\.\Explorer\MountPoints2\{0d368e94-73bf-11df-abce-0004231cf8e5}
Deleted! HKCU\.\.\.\.\Explorer\MountPoints2\{0e74c8b0-9a25-11df-ac0d-0004231cf8e5}
Deleted! HKCU\.\.\.\.\Explorer\MountPoints2\{10c1e159-ac3b-11df-ac2e-0004231cf8e5}
Deleted! HKCU\.\.\.\.\Explorer\MountPoints2\{10c1e15d-ac3b-11df-ac2e-0004231cf8e5}
Deleted! HKCU\.\.\.\.\Explorer\MountPoints2\{200de8f4-7d1c-11df-abdb-0004231cf8e5}
Deleted! HKCU\.\.\.\.\Explorer\MountPoints2\{29b3081a-95a9-11df-ac08-0004231cf8e5}
Deleted! HKCU\.\.\.\.\Explorer\MountPoints2\{2af49ee4-4a2d-11df-ab7f-0004231cf8e5}
Deleted! HKCU\.\.\.\.\Explorer\MountPoints2\{2afd70f5-9faf-11df-ac14-0004231cf8e5}
Deleted! HKCU\.\.\.\.\Explorer\MountPoints2\{3e6c0c5d-5c0f-11df-aba6-0004231cf8e5}
Deleted! HKCU\.\.\.\.\Explorer\MountPoints2\{480993d8-918e-11df-ac03-0004231cf8e5}
Deleted! HKCU\.\.\.\.\Explorer\MountPoints2\{4d12573b-67e4-11df-abbc-0004231cf8e5}
Deleted! HKCU\.\.\.\.\Explorer\MountPoints2\{5152fb50-6d54-11df-abc3-0004231cf8e5}
Deleted! HKCU\.\.\.\.\Explorer\MountPoints2\{55e45d91-7923-11df-abd6-0004231cf8e5}
Deleted! HKCU\.\.\.\.\Explorer\MountPoints2\{55e45d9b-7923-11df-ac2e-0004231cf8e5}
Deleted! HKCU\.\.\.\.\Explorer\MountPoints2\{568e15bc-7860-11df-abd5-0004231cf8e5}
Deleted! HKCU\.\.\.\.\Explorer\MountPoints2\{569515b3-9af0-11df-ac0e-0004231cf8e5}
Deleted! HKCU\.\.\.\.\Explorer\MountPoints2\{5d005704-995b-11df-ac0c-0004231cf8e5}
Deleted! HKCU\.\.\.\.\Explorer\MountPoints2\{5d005708-995b-11df-ac0c-0004231cf8e5}
Deleted! HKCU\.\.\.\.\Explorer\MountPoints2\{6331e4de-696e-11df-abbf-0004231cf8e5}
Deleted! HKCU\.\.\.\.\Explorer\MountPoints2\{68fcef5c-7471-11df-abcf-0004231cf8e5}
Deleted! HKCU\.\.\.\.\Explorer\MountPoints2\{6e0db4a1-8dac-11df-abfb-0004231cf8e5}
Deleted! HKCU\.\.\.\.\Explorer\MountPoints2\{6fe2a32f-7dd7-11df-abdc-0004231cf8e5}
Deleted! HKCU\.\.\.\.\Explorer\MountPoints2\{6fe2a331-7dd7-11df-abdc-0004231cf8e5}
Deleted! HKCU\.\.\.\.\Explorer\MountPoints2\{737e1d7c-a459-11df-ac19-0004231cf8e5}
Deleted! HKCU\.\.\.\.\Explorer\MountPoints2\{75a5b53d-ab77-11df-ac2a-0004231cf8e5}
Deleted! HKCU\.\.\.\.\Explorer\MountPoints2\{7c08a94c-79e9-11df-abd7-0004231cf8e5}
Deleted! HKCU\.\.\.\.\Explorer\MountPoints2\{89b3928b-6fbb-11df-abca-0004231cf8e5}
Deleted! HKCU\.\.\.\.\Explorer\MountPoints2\{8f17a22e-8e64-11df-abfc-0004231cf8e5}
Deleted! HKCU\.\.\.\.\Explorer\MountPoints2\{9195ecbe-a78b-11df-ac1e-0004231cf8e5}
Deleted! HKCU\.\.\.\.\Explorer\MountPoints2\{94445804-a527-11df-ac1a-0004231cf8e5}
Deleted! HKCU\.\.\.\.\Explorer\MountPoints2\{96d6adf4-4879-11df-ab70-00e04c3902b6}
Deleted! HKCU\.\.\.\.\Explorer\MountPoints2\{97da635a-5ce4-11df-aba7-0004231cf8e5}
Deleted! HKCU\.\.\.\.\Explorer\MountPoints2\{97da6361-5ce4-11df-aba7-0004231cf8e5}
Deleted! HKCU\.\.\.\.\Explorer\MountPoints2\{9c712794-6b0d-11df-abc1-0004231cf8e5}
Deleted! HKCU\.\.\.\.\Explorer\MountPoints2\{b0ded568-6c96-11df-abc2-0004231cf8e5}
Deleted! HKCU\.\.\.\.\Explorer\MountPoints2\{b4cd131c-8fee-11df-ac01-0004231cf8e5}
Deleted! HKCU\.\.\.\.\Explorer\MountPoints2\{c5957b40-2d16-11db-ac21-0004231cf8e5}
Deleted! HKCU\.\.\.\.\Explorer\MountPoints2\{eee10856-6f00-11df-abc5-0004231cf8e5}
Deleted! HKCU\.\.\.\.\Explorer\MountPoints2\{f6c88650-829c-11df-abe3-0004231cf8e5}
Deleted! HKCU\.\.\.\.\Explorer\MountPoints2\{f6c88658-829c-11df-abe3-0004231cf8e5}
Deleted! HKCU\.\.\.\.\Explorer\MountPoints2\{faa0d0ff-5115-11df-ab94-0004231cf8e5}
Deleted! HKCU\.\.\.\.\Explorer\MountPoints2\{ff3d7a6c-67d9-11df-abbb-0004231cf8e5}
################## | Listing |
[12/04/2010 - 16:04:29 | A | 0] C:\AUTOEXEC.BAT
[12/04/2010 - 15:57:02 | SH | 212] C:\boot.ini
[28/08/2001 - 14:00:00 | RASH | 4952] C:\Bootfont.bin
[12/04/2010 - 16:04:29 | A | 0] C:\CONFIG.SYS
[16/07/2010 - 14:51:52 | D ] C:\D6
[16/04/2010 - 09:33:21 | D ] C:\Documents and Settings
[31/07/2010 - 19:36:39 | D ] C:\Downloads
[25/08/2010 - 08:33:54 | ASH | 1073270784] C:\hiberfil.sys
[12/04/2010 - 16:04:29 | RASH | 0] C:\IO.SYS
[23/08/2010 - 19:13:14 | A | 413] C:\My documents.lnk
[12/04/2010 - 16:04:29 | RASH | 0] C:\MSDOS.SYS
[13/04/2010 - 11:21:38 | RHD ] C:\MSOCache
[13/04/2008 - 09:43:04 | RASH | 47564] C:\NTDETECT.COM
[13/04/2008 - 11:31:52 | RASH | 252240] C:\ntldr
[25/08/2010 - 08:33:53 | ASH | 1610612736] C:\pagefile.sys
[24/08/2010 - 18:50:26 | RD ] C:\Program Files
[25/08/2010 - 19:29:00 | SHD ] C:\RECYCLER
[13/07/2010 - 13:08:45 | A | 183] C:\sgbx.log
[12/04/2010 - 16:09:55 | SHD ] C:\System Volume Information
[25/08/2010 - 19:29:00 | D ] C:\UsbFix
[25/08/2010 - 19:29:17 | A | 3982] C:\UsbFix.txt
[25/08/2010 - 08:40:47 | D ] C:\WINDOWS
[21/11/2009 - 03:32:50 | A | 734115840] D:\7 Plans Before My 30 Years_by thierry.avi
[23/10/2009 - 10:02:00 | A | 33280] D:\ademci.doc
[07/07/2010 - 17:52:14 | A | 15011] D:\agence nass.docx
[12/06/2010 - 10:10:47 | D ] D:\AKON
[24/04/2010 - 16:48:29 | D ] D:\ALORS
[26/02/2010 - 20:04:20 | A | 380416] D:\annversaire.doc
[27/01/2010 - 14:18:27 | D ] D:\ARAFATE MP3 ALL LAST
[05/11/2009 - 09:27:39 | D ] D:\Atomix Virtual DJ 1.09 Full+Crack+skins+Effects (by charled v1.1)
[18/02/2010 - 09:57:26 | A | 22528] D:\SALE CERTIFICATE.doc
[30/12/2009 - 20:29:54 | A | 743220278] D:\Avatar.2009.FRENCH.REPACK.1CD.TS.MD.XViD.avi
[20/08/2010 - 18:32:15 | A | 21526] D:\BATIM.xlsx
[01/03/2010 - 13:13:45 | D ] D:\ccp
[17/10/2009 - 17:00:11 | D ] D:\ccp(2)
[16/10/2009 - 15:18:26 | A | 16496] D:\client.jpg
[16/10/2009 - 15:23:24 | A | 15858] D:\client02.jpg
[03/07/2009 - 14:57:14 | A | 734058496] D:\Code Omega The Prophecy of Shadows II.avi
[06/03/2010 - 19:21:39 | A | 852480] D:\How to repair Vista with or without DVD.doc
[09/03/2009 - 09:11:32 | A | 115072589] D:\Companion_Suite_IH_W_V1_1__2.exe
[27/01/2010 - 17:08:31 | D ] D:\DALFOLO (E)
[25/02/2010 - 09:46:42 | A | 25088] D:\job application.doc
[27/01/2010 - 14:46:21 | D ] D:\DEZY 45 STUDENTS
[06/02/2010 - 10:36:52 | D ] D:\Folder
[22/05/2010 - 11:53:07 | D ] D:\important folder
[03/02/2010 - 10:55:02 | A | 3169784] D:\DriverScanner.exe
[11/09/2009 - 14:37:51 | A | 15514] D:\header (WordFIX).doc
[02/05/2009 - 15:18:53 | A | 28672] D:\header.doc
[05/05/2009 - 10:35:56 | D ] D:\HOPE MP3
[12/10/2009 - 16:50:11 | A | 32768] D:\INVOICE FEELING.doc
[01/03/2010 - 09:43:18 | A | 27136] D:\fanny.doc
[17/02/2010 - 12:48:22 | A | 24064] D:\Faye.doc
[01/03/2010 - 11:14:28 | A | 22528] D:\Faye2.doc
[29/10/2009 - 14:12:06 | A | 6519272] D:\free-mp3-wma-converter_free_mp3_wma_converter_1.8_french_34863.exe
[01/02/2009 - 17:54:13 | A | 8649058] D:\Free-YouTube-Downloader.exe
[04/07/2009 - 11:06:01 | D ] D:\GARAGISTS
[11/09/2009 - 16:20:10 | D ] D:\GARAGISTS MP3
[30/07/2010 - 16:38:09 | A | 38912] D:\glacier.doc
[10/05/2010 - 18:55:43 | A | 132926] D:\installation guide win98.docx
[25/11/2009 - 14:33:16 | A | 3136288] D:\idman518.exe
[26/08/2009 - 14:12:38 | D ] D:\Images
[04/12/2009 - 09:10:42 | D ] D:\important
[09/06/2010 - 11:30:55 | A | 5018624] D:\INTRODUCTIONS TO COMPUTERS AND WINDOWS.doc
[27/04/2010 - 16:34:52 | A | 97525032] D:\iTunesSetup.exe
[12/07/2010 - 12:32:32 | A | 54272] D:\KOUAME.doc
[24/04/2010 - 12:37:47 | A | 50688] D:\RECEIPT OF ORDER ARTICLES.doc
[23/04/2010 - 17:54:00 | A | 57344] D:\RECEIPT OF ORDERED ARTICLES.doc
[25/02/2010 - 08:40:26 | A | 23040] D:\sponsorship request letter.doc
[03/03/2010 - 10:17:13 | A | 32256] D:\letter.doc
[29/03/2010 - 19:47:28 | A | 84480] D:\libraries.doc
[06/06/2009 - 16:37:36 | A | 16510368] D:\LimeWireWin.exe
[11/05/2009 - 17:29:11 | D ] D:\lodane
[27/04/2009 - 14:54:41 | D ] D:\MADOUSSOU
[19/05/2009 - 14:54:46 | A | 742] D:\Mario Forever.lnk
[19/05/2009 - 14:53:38 | A | 21538712] D:\Mario_Forever41.exe
[12/08/2010 - 17:47:12 | RD ] D:\my courses
[06/02/2002 - 16:27:00 | A | 30633521] D:\moviexone.exe
[16/11/2009 - 15:06:55 | RD ] D:\mp3
[20/06/2009 - 10:54:19 | D ] D:\MPEGAV
[22/09/2009 - 09:49:42 | RHD ] D:\MSOCache
[20/11/2009 - 15:47:29 | RD ] D:\Music
[12/11/2009 - 16:52:20 | A | 65148610] D:\NamoWebEditor8EnuTrial.exe
[10/07/2010 - 11:00:40 | A | 14494] D:\OUR NEEDS.docx
[22/12/2009 - 12:33:48 | RD ] D:\New folder
[15/10/2009 - 14:37:32 | D ] D:\New folder (2)
[27/04/2010 - 19:24:30 | D ] D:\New folder (3)
[18/06/2009 - 17:21:23 | D ] D:\New folder1
[27/01/2010 - 14:46:26 | D ] D:\PATIENCE DABANI
[15/05/2009 - 12:06:07 | A | 130433] D:\Photo (5).jpg
[05/06/2009 - 15:56:57 | A | 84992] D:\creation_plan1_06.doc
[27/04/2010 - 19:21:59 | D ] D:\for iphone
[26/02/2010 - 16:38:44 | A | 25088] D:\PROTOCOL D.doc
[25/08/2010 - 19:29:00 | SHD ] D:\RECYCLER
[14/08/2010 - 11:03:45 | A | 161280] D:\romaric.doc
[01/12/2009 - 17:36:26 | A | 6343388] D:\Setup_FreeFlvConverter.exe
[27/01/2010 - 11:35:02 | D ] D:\religious sound
[18/06/2009 - 17:21:24 | RD ] D:\Sounds
[06/05/2009 - 14:58:22 | A | 45568] D:\LAPTOP STOCKS.doc
[12/04/2010 - 16:17:30 | SHD ] D:\System Volume Information
[12/08/2010 - 17:47:10 | ASH | 8192] D:\Thumbs.db
[05/05/2009 - 10:35:09 | D ] D:\Tiken Jah MP 3
[23/06/2009 - 14:21:29 | A | 170052568] D:\TrueImageServerEcho_d_en.exe
[14/11/2009 - 17:06:48 | D ] D:\Videos
[30/05/2009 - 20:52:46 | A | 170203312] D:\VideoSpin_2_0_Setup.exe
[28/07/2009 - 13:28:03 | D ] D:\Zook
[24/03/2010 - 14:30:40 | AH | 162] D:\~$sponsorship request letter.doc
[25/08/2010 - 16:10:10 | A | 73975] F:\commerce tools.jpg
[25/08/2010 - 16:10:12 | A | 64282] F:\commerce tools (2).jpg
[25/08/2010 - 16:10:12 | A | 66132] F:\commerce tools (3).jpg
[25/08/2010 - 16:10:14 | A | 68105] F:\commerce tools (4).jpg
[25/08/2010 - 16:10:16 | A | 68254] F:\commerce tools (5).jpg
[25/08/2010 - 16:10:18 | A | 67594] F:\commerce tools (6).jpg
[25/08/2010 - 16:10:18 | A | 75400] F:\commerce tools (7).jpg
[25/08/2010 - 16:08:04 | RSHD ] F:\POGRJESILA
[25/08/2010 - 18:49:46 | RSHD ] H:\POGRJESILA
################## | Vaccine |
C:\Autorun.inf -> Folder created by UsbFix (El Desaparecido & C_XX)
D:\Autorun.inf -> Folder created by UsbFix (El Desaparecido & C_XX)
F:\Autorun.inf -> Folder created by UsbFix (El Desaparecido & C_XX)
H:\Autorun.inf -> Folder created by UsbFix (El Desaparecido & C_XX)
################## | Upload |
Please send the file: C:\UsbFix_Upload_Me_SERVER.zip
https://www.ionos.fr/?affiliate_id=77097
Thank you for your contribution.
################## | E.O.F | -
DISABLE YOUR ANTIVIRUS AND FIREWALL IF PRESENT !!!!!(as it is mistakenly detected as an infection)
▶ Download here :List_Kill'em
and save it to your desktop
if you have XP => double click
if you have Vista or Windows 7 => right-click "run as...."
on the shortcut on your desktop to start the installation
Leave checked:
♦ Run List_Kill'em
once completed, click "finish" and the program will start automatically
choose the Search option
▶ let the tool work
a dialog box may open, in which case click "ok" or "Agree"
when the white window appears, it takes a while, it's normal, it's an additional search for hidden files, the program is not frozen.
▶ Post the content of the report that opens at 100 % of the scan on the screen "COMPLETED"
▶▶▶ DO NOT POST IT ON THE FORUM
To send it to me click on this link: http://www.cijoint.fr/
▶ Click on Browse and find the file C:\List'em.txt
▶ Click Open.
▶ Click "Click here to upload the file".
A link of this form:
http://www.cijoint.fr/cjlink.php?file=265368/cijSKAP5fU.txt
is added to the page.
▶ Copy this link in your reply.
▶ Do the same with more.txt which is located on your desktop
--
♦G3и-н@¢км@и™©®♦ -
The link to download list_kill'em doesn't work. I'm not sure why, I'm going to look for a link where I can quickly get this log. Please don't drop the discussion. Thank you.
-
try here if you haven't found
http://www.cijoint.fr/cjlink.php?file=cj201008/cijDmY9YpR.zip
?G3?-?@¢??@?(TM)©®? -
Thank you for the link. I was indeed able to download the log, but its analysis doesn't go beyond 30%, and it keeps going back to the HKU and HKLM hives. Is that normal?
-
Voici le lien du fichier
http://www.cijoint.fr/cjlink.php?file=cj201008/cijMnGtnjE.txt -
There is also a file more.txt; I don't know if you need that as well?
-
-
Excuse me, I wasn't paying proper attention.
Here is the link to the file more.txt
http://www.cijoint.fr/cjlink.php?file=cj201008/cijsdF75gP.txt -
Analyze the following file(s) on Virustotal:
Virus Total
* * Paste the file paths directly, one by one, in the "Browse" space after each analysis:
c:\windows\system32\drivers\HttpUsb.sys
c:\windows\system32\drivers\mfxnt.sys
C:\WINDOWS\System32\sgbxih.exe
C:\WINDOWS\System32\csfpm.dll
C:\WINDOWS\System32\dao360.dll
C:\WINDOWS\System32\vwipxspx.dll
* Now click on Send file and wait while "Current situation: analyzing" is displayed.
* The file may be queued due to a large number of analysis requests. In this case, you will have to wait without refreshing the page.
* When the analysis is complete, paste the link(s) to the page(s) in your next response.
Then:
If you have XP => double-click
If you have Vista or Windows 7 => right-click "run as...."
▶ Relaunch List_Kill'em using the shortcut on your desktop.
But this time:
▶ Choose the Clean Option
Let the tool work.
At the end of the scan, the window will close, and you will have a report named Kill'em.txt on your desktop,
▶ Paste the content in your response
Then:
▶ Download here: Ad-remover to your desktop:
▶ Disconnect and close all running applications!
If you have XP => double-click
If you have Vista or Windows 7 => right-click "run as...."
▶ On "Ad-R.exe" to start the installation and keep the default installation settings.
▶ Click the Ad-remover shortcut that is on your desktop to launch the tool.
▶ In the main menu, choose "Clean option" and press [enter].
▶ Let the tool work and don't touch anything...
▶ Post the report that appears at the end on the forum...
( The report is also saved under C:\Ad-report.log )
( CTRL+A to select all, CTRL+C to copy, and CTRL+V to paste )
▶ Note: "Process.exe," a component of the tool, is detected by some antivirus (AntiVir, Dr.Web, Kaspersky Anti-Virus) as a RiskTool.
It is not a virus, but a utility intended to terminate processes.
In the wrong hands, this utility could stop security software (Antivirus, Firewall...) hence the alert issued by these antivirus programs.
Then:
Uninstall AD-Remover
Then:
* Download here: USBFIX to your desktop
/!\ Temporarily disable only while using USBFIX, the real-time protection of your Antivirus and antispyware, which may significantly hinder the search and cleaning procedure of the tool.
If you have XP => double-click
If you have Vista or Windows 7 => right-click "run as...."
On the Usbfix icon located on your Desktop.
On the page, click the button:
"Search"
/!\ Plug in your external data sources to your PC (USB stick, external hard drive, etc...) that may have been infected without opening them
- then click OK
- Let the tool work.
- Post the report that appears at the end.
The report can be found at C:\UsbFix.txt
Note: "Process.exe," a component of the tool, is detected by some antivirus (AntiVir, Dr.Web, Kaspersky Anti-Virus) as a RiskTool.
It is not a virus, but a utility intended to terminate processes.
In the wrong hands, this utility could stop security software (Antivirus, Firewall...) hence the alert issued by these antivirus.
Then:
▶ (!) Plug in your external data sources to your PC (USB stick, external hard drive, etc...) that may have been infected without opening them
▶ Double click (right-click "as administrator" for Vista/7) on the shortcut UsbFix present on your desktop
▶ In the main menu, choose the option (Removal) and press [enter]
▶ Your desktop will disappear; UsbFix will scan your PC, let the tool work.
▶ Then post the report UsbFix.txt that will appear with the desktop.
Note: The report UsbFix.txt is saved at the root of the disk. ( C:\UsbFix.txt )
( CTRL+A to select all, CTRL+C to copy, and CTRL+V to paste )
Then:
Uninstall usbfix
While waiting for all reports in order
--
♦G3и-н@¢км@и™©®♦ -
Here are the results of the analyses on VirusTotal
http://www.virustotal.com/file-scan/report.html?id=318414f8015a7021aa4ce31d14c3b985c792c7228dff5af6ed0dbdbfde8b58b3-1282832528
http://www.virustotal.com/file-scan/report.html?id=a5f743fc84abfbd01b10e174198bf7e4fcdbf272653d40b3b38c0e3374d035d6-1282833896
http://www.virustotal.com/file-scan/report.html?id=3781f45b5015b57fd2303597df1f76bbb86b7f5f94e7df98f01a60a670b7b566-1282834071
http://www.virustotal.com/file-scan/report.html?id=3f2a8baa1d7431f8f2f4586a55069955ddc7ca7b701f8a796a35ca73d3dbf181-1282834275
http://www.virustotal.com/file-scan/report.html?id=8f8f07dd6fd46105e9751c6183c03bc346e292736736c2f9e01dcf4c7a99232c-1264209216
http://www.virustotal.com/file-scan/report.html?id=479f464f85b70d27f933d27380415ada1330c9354dc5dff34c8ac27e5ab8ca71-1244313095 -
Here is the 2nd report of list_kill'em
¤¤¤¤¤¤¤¤¤¤ Kill'em by g3n-h@ckm@n 2.1.0.0 ¤¤¤¤¤¤¤¤¤¤
User: CEPLUS (Users)
Update on 24/08/2010 by g3n-h@ckm@n ::::: 23.20
Start at: 14:59:35 | 26/08/2010
Intel(R) Pentium(R) 4 CPU 1.60GHz
Microsoft Windows XP Professional (5.1.2600 32-bit) # Service Pack 3
Internet Explorer 8.0.6001.18702
Windows Firewall Status: Enabled
AV: AntiVir Desktop 9.0.1.32 [ Enabled | Updated ]
A:\ -> 3.5-inch Floppy Drive
C:\ -> Local hard disk | 28.62 Go (6.61 Go free) [Local Disk] | NTFS
D:\ -> Local hard disk | 18.99 Go (1.2 Go free) | NTFS
E:\ -> CD-ROM Drive
G:\ -> CD-ROM Drive
¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤ Processes ------- Memory(Ko)
C:\WINDOWS\System32\smss.exe ----0 Ko
C:\WINDOWS\system32\csrss.exe ----0 Ko
C:\WINDOWS\system32\winlogon.exe ----0 Ko
C:\WINDOWS\system32\services.exe ----0 Ko
C:\WINDOWS\system32\lsass.exe ----0 Ko
C:\WINDOWS\system32\svchost.exe ----0 Ko
C:\WINDOWS\system32\svchost.exe ----0 Ko
C:\WINDOWS\System32\svchost.exe ----0 Ko
C:\WINDOWS\system32\svchost.exe ----0 Ko
C:\WINDOWS\system32\svchost.exe ----0 Ko
C:\WINDOWS\system32\spoolsv.exe ----0 Ko
C:\Program Files\Avira\AntiVir Desktop\sched.exe ----0 Ko
C:\WINDOWS\system32\svchost.exe ----0 Ko
C:\Program Files\Emsisoft Anti-Malware\a2service.exe ----0 Ko
C:\Program Files\Avira\AntiVir Desktop\avguard.exe ----0 Ko
C:\Program Files\Java\jre6\bin\jqs.exe ----0 Ko
C:\WINDOWS\system32\svchost.exe ----0 Ko
C:\WINDOWS\system32\wbem\wmiapsrv.exe ----0 Ko
C:\WINDOWS\System32\alg.exe ----0 Ko
C:\WINDOWS\Explorer.EXE ----0 Ko
C:\Program Files\Avira\AntiVir Desktop\avgnt.exe ----0 Ko
C:\Program Files\Common Files\Java\Java Update\jusched.exe ----0 Ko
C:\PROGRA~1\COMPAN~2\ONETOU~3.EXE ----0 Ko
C:\Program Files\Companion Suite IH\MFServices.exe ----0 Ko
C:\Program Files\Companion Suite IH\MFPrintServer.exe ----0 Ko
C:\Program Files\Companion OneTouch\MFLaunchOT.exe ----0 Ko
C:\WINDOWS\system32\ctfmon.exe ----0 Ko
C:\Program Files\SuperCopier2\SuperCopier2.exe ----0 Ko
C:\Program Files\VisualTaskTips\VisualTaskTips.exe ----0 Ko
C:\Program Files\BitComet\BitComet.exe ----0 Ko
C:\Program Files\Messenger\msmsgs.exe ----0 Ko
C:\Program Files\MagicDisc\MagicDisc.exe ----0 Ko
C:\WINDOWS\BricoPacks\Vista Inspirat 2\RocketDock\RocketDock.exe ----0 Ko
C:\WINDOWS\BricoPacks\Vista Inspirat 2\UberIcon\UberIcon Manager.exe ----0 Ko
C:\Program Files\Cybera Server\cybserv.exe ----0 Ko
C:\WINDOWS\System32\svchost.exe ----0 Ko
C:\Program Files\VideoLAN\VLC\vlc.exe ----0 Ko
C:\WINDOWS\system32\cmd.exe ----0 Ko
C:\WINDOWS\system32\wbem\wmiprvse.exe ----0 Ko
C:\Program Files\List_Kill'em\ERUNT.EXE ----0 Ko
C:\Program Files\List_Kill'em\pv.exe ----0 Ko
¤¤¤¤¤¤¤¤¤¤ Files/folders:
Quarantined & Deleted !!: C:\WINDOWS\SET3.tmp
Quarantined & Deleted !!: C:\WINDOWS\SET4.tmp
Quarantined & Deleted !!: C:\WINDOWS\SET8.tmp
Quarantined & Deleted !!: C:\WINDOWS\Temp\nsc5.tmp
Quarantined & Deleted !!: C:\Documents and Settings\CEPLUS\Local Settings\Temp\2.tmp
Quarantined & Deleted !!: C:\Documents and Settings\CEPLUS\Local Settings\Temp\amt.log
Quarantined & Deleted !!: C:\Documents and Settings\CEPLUS\Local Settings\Temp\bc5.tmp
Quarantined & Deleted !!: C:\Documents and Settings\CEPLUS\Local Settings\Temp\bc7.tmp
Quarantined & Deleted !!: C:\Documents and Settings\CEPLUS\Local Settings\Temp\bc8.tmp
Quarantined & Deleted !!: C:\Documents and Settings\CEPLUS\Local Settings\Temp\bcA.tmp
Quarantined & Deleted !!: C:\Documents and Settings\CEPLUS\Local Settings\Temp\bcB.tmp
Quarantined & Deleted !!: C:\Documents and Settings\CEPLUS\Local Settings\Temp\bcC.tmp
Quarantined & Deleted !!: C:\Documents and Settings\CEPLUS\Local Settings\Temp\bcD.tmp
Quarantined & Deleted !!: C:\Documents and Settings\CEPLUS\Local Settings\Temp\bcE.tmp
Quarantined & Deleted !!: C:\Documents and Settings\CEPLUS\Local Settings\Temp\dw.log
Quarantined & Deleted !!: C:\Documents and Settings\CEPLUS\Local Settings\Temp\FS2.tmp
Quarantined & Deleted !!: C:\Documents and Settings\CEPLUS\Local Settings\Temp\FS3.tmp
Quarantined & Deleted !!: C:\Documents and Settings\CEPLUS\LOCAL Settings\Temp\A~NSISu_.exe
Quarantined & Deleted !!: C:\Documents and Settings\CEPLUS\LOCAL Settings\Temp\FCTBSetup.exe
Quarantined & Deleted !!: C:\Documents and Settings\CEPLUS\LOCAL Settings\Temp\ose00000.exe
Quarantined & Deleted !!: C:\Documents and Settings\CEPLUS\LOCAL Settings\Temp\setup.exe
Quarantined & Deleted !!: C:\Documents and Settings\CEPLUS\LOCAL Settings\Temp\acufutls.dll
Quarantined & Deleted !!: C:\Documents and Settings\CEPLUS\LOCAL Settings\Temp\tbFree.dll
Quarantined & Deleted !!: C:\Documents and Settings\CEPLUS\Local Settings\Temporary Internet Files\SuggestedSites.dat
¤¤¤¤¤¤¤¤¤¤ Hosts ¤¤¤¤¤¤¤¤¤¤
127.0.0.1 localhost
¤¤¤¤¤¤¤¤¤¤ Registry ¤¤¤¤¤¤¤¤¤¤
Deleted: HKLM\Software\Microsoft\Windows\CurrentVersion\Run: My Web Search Bar Search Scope Monitor
Deleted: HKLM\SOFTWARE\Microsoft\Internet Explorer\Toolbar: {07B18EA9-A523-4961-B6BB-170DE4475CCA}
Deleted: HKCU\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser: {0E5CBF21-D15F-11D0-8301-00AA005B4383}
Deleted: HKCU\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser: {D4027C7F-154A-4066-A1AD-4243D8127440}
Deleted: "HKCU\SOFTWARE\Microsoft\Internet Explorer\MenuExt\&Search"
Deleted: "HKCU\software\microsoft\internet explorer\searchscopes\{171DEBEB-C3D4-40b7-AC73-056A5EBA4A7E}"
Deleted: "HKCU\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{56256A51-B582-467e-B8D4-7786EDA79AE0}"
Deleted: "HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{AFDBDDAA-5D3F-42EE-B79C-185A7020515B}"
Deleted: "HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{59C7FC09-1C83-4648-B3E6-003D2BBC7481}"
Deleted: "HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{68af847f-6e91-45dd-9b68-d6a12c30e5d7}"
Deleted: "HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{9170B96C-28D4-4626-8358-27E6CAEEF907}"
Deleted: "HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{D1A71FA0-FF48-48dd-9B6D-7A13A3E42127}"
Deleted: "HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{DDB1968E-EAD6-40fd-8DAE-FF14757F60C7}"
Deleted: "HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{F138D901-86F0-4383-99B6-9CDD406036DA}"
Deleted: "HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{56256A51-B582-467e-B8D4-7786EDA79AE0}"
Deleted: "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\Install.exe"
Deleted: "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\Setup.exe"
Deleted: HKCR\CLSID\{248dd896-bb45-11cf-9abc-0080c7e7b78d}
Deleted: HKCR\CLSID\{248dd897-bb45-11cf-9abc-0080c7e7b78d}
Deleted: HKCR\CLSID\{84da4fdf-a1cf-4195-8688-3e961f505983}
Deleted: HKCR\CLSID\{9afb8248-617f-460d-9366-d71cdeda3179}
Deleted: HKCR\Interface\{248dd892-bb45-11cf-9abc-0080c7e7b78d}
Deleted: HKCR\Interface\{248dd893-bb45-11cf-9abc-0080c7e7b78d}
Deleted: HKCR\interface\{3E53E2CB-86DB-4A4A-8BD9-FFEB7A64DF82}
Deleted: HKCR\Interface\{63d0ed2d-b45b-4458-8b3b-60c69bbbd83c}
Deleted: HKCR\Interface\{72ee7f04-15bd-4845-a005-d6711144d86a}
Deleted: HKCR\Interface\{7473d293-b7bb-4f24-ae82-7e2ce94bb6a9}
Deleted: HKCR\Interface\{a626cdbd-3d13-4f78-b819-440a28d7e8fc}
Deleted: HKCR\interface\{cf54be1c-9359-4395-8533-1657cf209cfe}
Deleted: HKCR\Interface\{e342af55-b78a-4cd0-a2bb-da7f52d9d25f}
Deleted: HKCR\Interface\{e79dfbc9-5697-4fbd-94e5-5b2a9c7c1612}
Deleted: HKCR\Interface\{e79dfbcb-5697-4fbd-94e5-5b2a9c7c1612}
Deleted: HKCR\Interface\{f87d7fb5-9dc5-4c8c-b998-d8dfe02e2978}
Deleted: HKCR\TypeLib\{248dd890-bb45-11cf-9abc-0080c7e7b78d}
Deleted: HKCR\TypeLib\{D518921A-4A03-425E-9873-B9A71756821E}
Deleted: HKCR\TypeLib\{E79DFBC0-5697-4FBD-94E5-5B2A9C7C1612}
Deleted: HKCU\Software\Conduit
Deleted: HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{00a6faf1-072e-44cf-8957-5838f569a31d}
Deleted: HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{07b18ea1-a523-4961-b6bb-170de4475cca}
Deleted: HKLM\Software\Conduit
Deleted: HKLM\SOFTWARE\FocusInteractive
Deleted: HKLM\SOFTWARE\Microsoft\Multimedia\WMPlayer\Schemes\f3pss
Deleted: HKLM\Software\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{07B18EAB-A523-4961-B6BB-170DE4475CCA}
Deleted: HKLM\Software\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{25560540-9571-4D7B-9389-0F166788785A}
Deleted: HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{3dc201fb-e9c9-499c-a11f-23c360d7c3f8}
Deleted: HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{3e720452-b472-4954-b7aa-33069eb53906}
Deleted: HKLM\Software\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{63D0ED2C-B45B-4458-8B3B-60C69BBBD83C}
Deleted: HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{7473d294-b7bb-4f24-ae82-7e2ce94bb6a9}
Deleted: HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{98d9753d-d73b-42d5-8c85-4469cda897ab}
Deleted: HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{9ff05104-b030-46fc-94b8-81276e4e27df}
Deleted: HKLM\Software\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{E79DFBCA-5697-4FBD-94E5-5B2A9C7C1612}
¤¤¤¤¤¤¤¤¤¤ Internet Explorer ¤¤¤¤¤¤¤¤¤¤
[HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Main]
Start Page = https://www.msn.com/fr-fr/?ocid=iehp
Local Page = C:\WINDOWS\system32\blank.htm
Default_Search_URL = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
Default_Page_URL = https://www.msn.com/fr-fr/?ocid=iehp
Search Page = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main]
Start Page = https://www.google.com/?gws_rd=ssl
Local Page = C:\WINDOWS\system32\blank.htm
Search Page = http://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
¤¤¤¤¤¤¤¤¤¤ Security Center ¤¤¤¤¤¤¤¤¤¤
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
FirstRunDisabled = 1 ()
AntiVirusDisableNotify = 0 (0x0)
FirewallDisableNotify = 0 (0x0)
UpdatesDisableNotify = 0 (0x0)
AntiVirusOverride = 1 ()
FirewallOverride = 1 ()
¤¤¤¤¤¤¤¤¤¤ Services ¤¤¤¤¤¤¤¤¤¤
Ndisuio: Start = 3
EapHost: Start = 2
Ip6Fw: Start = 2
SharedAccess: Start = 2
wuauserv: Start = 2
wscsvc: Start = 2
¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤
Disk Cleaned
anti-ver blaster: OK
Prefetch cleaned
¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤
FEATURE_BROWSER_EMULATION | svchost:
====================================
Stealth MBR rootkit/Mebroot/Sinowal detector 0.3.7 by Gmer, http://www.gmer.net
device: opened successfully
user: MBR read successfully
called modules: ntoskrnl.exe CLASSPNP.SYS disk.sys ACPI.sys hal.dll atapi.sys intelide.sys PCIIDEX.SYS
kernel: MBR read successfully
user & kernel MBR OK
¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤ ( EOF ) ¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤ -
Here is the Ad-Remover report
======= AD-REMOVER REPORT 2.0.0.1,D | Windows XP/Vista/7 ONLY =======
Updated by C_XX on 07/26/10 at 12:00
Contact: AdRemover.contact[AT]gmail.com
Website: http://pagesperso-orange.fr/NosTools/ad_remover.html
C:\Program Files\Ad-Remover\main.exe (SCAN [1]) -> Launched at 16:09:05 on 08/26/2010, Normal mode
Microsoft Windows XP Professional Service Pack 3 (X86)
CEPLUS@SERVER ( )
============== SEARCH ==============
0,Folder found: C:\DOCUME~1\CEPLUS\LOCALS~1\Temp\AskSearch
0,File found: C:\DOCUME~1\CEPLUS\LOCALS~1\Temp\ASKSUTBLOG
0,File found: C:\DOCUME~1\CEPLUS\LOCALS~1\Temp\Del_AskHPRFF.VBS
1,Key found: HKLM\Software\Classes\CLSID\{799391D3-EB86-4bac-9BD3-CBFEA58A0E15}
1,Key found: HKLM\Software\Classes\CLSID\{D858DAFC-9573-4811-B323-7011A3AA7E61}
0,Key found: HKLM\Software\Classes\MyWebSearch.MultipleButton
0,Key found: HKLM\Software\Classes\MyWebSearch.MultipleButton.1
0,Key found: HKLM\Software\Classes\MyWebSearch.UrlAlertButton
0,Key found: HKLM\Software\Classes\MyWebSearch.UrlAlertButton.1
0,Key found: HKLM\Software\Classes\Toolbar.CT1060933
0,Key found: HKLM\Software\Classes\Toolbar.CT2247187
0,Key found: HKCU\Software\PopCap
0,Key found: HKLM\Software\Microsoft\Internet Explorer\Low Rights\RunDll32Policy\f3ScrCtr.dll
0,Key found: HKLM\Software\MozillaPlugins\@mywebsearch.com/Plugin
0,Value found: HKLM\Software\Microsoft\Windows\CurrentVersion\Internet Settings\User Agent\post platform|FunWebProducts
0,Value found: HKLM\Software\Mozilla\Firefox\Extensions|m3ffxtbr@mywebsearch.com
============== ADDITIONAL SCAN ==============
** Mozilla Firefox Version [3.6.8 (en)] **
-- C:\Documents and Settings\CEPLUS\Application Data\Mozilla\FireFox\Profiles\7b4iyaqx.default\Prefs.js --
browser.download.lastDir, D:\\my courses\\my music
browser.startup.homepage_override.mstone, rv:1.9.2.8
========================================
** Internet Explorer Version [8.0.6001.18702] **
[HKCU\Software\Microsoft\Internet Explorer\Main]
Default_Page_URL: hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&pver=6&ar=msnhome
Default_Search_URL: hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
Do404Search: 0x01000000
Enable Browser Extensions: yes
Local Page: C:\WINDOWS\system32\blank.htm
Search bar: hxxp://go.microsoft.com/fwlink/?linkid=54896
Search Page: hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
Show_ToolBar: yes
Start Page: hxxp://www.google.com/
Use Search Asst: no
[HKLM\Software\Microsoft\Internet Explorer\Main]
Default_Page_URL: hxxp://go.microsoft.com/fwlink/?LinkId=69157
Default_Search_URL: hxxp://go.microsoft.com/fwlink/?LinkId=54896
Delete_Temp_Files_On_Exit: yes
Local Page: C:\WINDOWS\system32\blank.htm
Search bar: hxxp://search.msn.com/spbasic.htm
Search Page: hxxp://go.microsoft.com/fwlink/?LinkId=54896
Start Page: hxxp://go.microsoft.com/fwlink/?LinkId=69157
[HKLM\Software\Microsoft\Internet Explorer\ABOUTURLS]
Tabs: res://ieframe.dll/tabswelcome.htm
Blank: res://mshtml.dll/blank.htm
========================================
C:\Program Files\Ad-Remover\Quarantine: 0 File(s)
C:\Program Files\Ad-Remover\Backup: 1 File(s)
C:\Ad-Report-SCAN[1].txt - 08/26/2010 (1599 Bytes)
End at: 16:19:05, 08/26/2010
============== E.O.F ============== -
excuse me for my multiple mistakes
here is the cleaning report
======= AD-REMOVER REPORT 2.0.0.1,D | WINDOWS XP/VISTA/7 ONLY =======
Updated by C_XX on 07/26/10 at 12:00
Contact: AdRemover.contact[AT]gmail.com
Website: http://pagesperso-orange.fr/NosTools/ad_remover.html
C:\Program Files\Ad-Remover\main.exe (CLEAN [1]) -> Launched at 16:31:32 on 08/26/2010, Normal mode
Microsoft Windows XP Professional Service Pack 3 (X86)
CEPLUS@SERVER ( )
============== ACTION(S) ==============
0,Folder deleted: C:\DOCUME~1\CEPLUS\LOCALS~1\Temp\AskSearch
0,File deleted: C:\DOCUME~1\CEPLUS\LOCALS~1\Temp\ASKSUTBLOG
0,File deleted: C:\DOCUME~1\CEPLUS\LOCALS~1\Temp\Del_AskHPRFF.VBS
(!) -- Temporary files deleted.
1,Key deleted: HKLM\Software\Classes\CLSID\{799391D3-EB86-4bac-9BD3-CBFEA58A0E15}
1,Key deleted: HKLM\Software\Classes\CLSID\{D858DAFC-9573-4811-B323-7011A3AA7E61}
0,Key deleted: HKLM\Software\Classes\MyWebSearch.MultipleButton
0,Key deleted: HKLM\Software\Classes\MyWebSearch.MultipleButton.1
0,Key deleted: HKLM\Software\Classes\MyWebSearch.UrlAlertButton
0,Key deleted: HKLM\Software\Classes\MyWebSearch.UrlAlertButton.1
0,Key deleted: HKLM\Software\Classes\Toolbar.CT1060933
0,Key deleted: HKLM\Software\Classes\Toolbar.CT2247187
0,Key deleted: HKCU\Software\PopCap
0,Key deleted: HKLM\Software\Microsoft\Internet Explorer\Low Rights\RunDll32Policy\f3ScrCtr.dll
0,Key deleted: HKLM\Software\MozillaPlugins\@mywebsearch.com/Plugin
0,Value deleted: HKLM\Software\Microsoft\Windows\CurrentVersion\Internet Settings\User Agent\post platform|FunWebProducts
0,Value deleted: HKLM\Software\Mozilla\Firefox\Extensions|m3ffxtbr@mywebsearch.com
============== ADDITIONAL SCAN ==============
** Mozilla Firefox Version [3.6.8 (fr)] **
-- C:\Documents and Settings\CEPLUS\Application Data\Mozilla\FireFox\Profiles\7b4iyaqx.default\Prefs.js --
browser.download.lastDir, D:\\my courses\\my music
browser.startup.homepage_override.mstone, rv:1.9.2.8
========================================
** Internet Explorer Version [8.0.6001.18702] **
[HKCU\Software\Microsoft\Internet Explorer\Main]
Default_Page_URL: hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&pver=6&ar=msnhome
Default_Search_URL: hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
Do404Search: 0x01000000
Enable Browser Extensions: yes
Local Page: C:\WINDOWS\system32\blank.htm
Search bar: hxxp://go.microsoft.com/fwlink/?linkid=54896
Show_ToolBar: yes
Start Page: hxxp://fr.msn.com/
Use Search Asst: no
[HKLM\Software\Microsoft\Internet Explorer\Main]
Default_Page_URL: hxxp://go.microsoft.com/fwlink/?LinkId=54896
Default_Search_URL: hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
Delete_Temp_Files_On_Exit: yes
Local Page: C:\WINDOWS\system32\blank.htm
Search bar: hxxp://search.msn.com/spbasic.htm
Search Page: hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
Start Page: hxxp://fr.msn.com/
[HKLM\Software\Microsoft\Internet Explorer\ABOUTURLS]
Tabs: res://ieframe.dll/tabswelcome.htm
Blank: res://mshtml.dll/blank.htm
========================================
C:\Program Files\Ad-Remover\Quarantine: 3 File(s)
C:\Program Files\Ad-Remover\Backup: 14 File(s)
C:\Ad-Report-CLEAN[1].txt - 08/26/2010 (692 Byte(s))
C:\Ad-Report-SCAN[1].txt - 08/26/2010 (3370 Byte(s))
Finished at: 16:33:26, 08/26/2010
============== E.O.F ============== -
Here is the USBFIX report after disabling my antivirus and connecting all my peripherals.
############################## | UsbFix 7.021 | [Search]
User: CEPLUS (Administrator) # SERVER [ ]
Updated on 20/08/10 by El Desaparecido / C_XX
Started at 16:57:52 | 26/08/2010
Website: http://pagesperso-orange.fr/NosTools/index.html
Contact: FindyKill.Contact@gmail.com
CPU: Intel(R) Pentium(R) 4 CPU 1.60GHz
Microsoft Windows XP Professional (5.1.2600 32-Bit) # Service Pack 3
Internet Explorer 8.0.6001.18702
Windows Firewall: Enabled
Antivirus: AntiVir Desktop 9.0.1.32 [(!) Disabled | Updated]
RAM -> 1023 Mo
C:\ (%systemdrive%) -> Fixed Drive # 29 Go (7 Go free - 23%) [Local Disk] # NTFS
D:\ -> Fixed Drive # 19 Go (1 Go free - 6%) [] # NTFS
E:\ -> CD-ROM
F:\ -> Removable Drive # 964 Mo (962 Mo free - 100%) [STORE'N'GO] # FAT
G:\ -> CD-ROM
H:\ -> Removable Drive # 2 Go (2 Go free - 100%) [NEW NAME] # FAT
################## | Infectious Elements |
Present! H:\Autorun.inf
Present! H:\image.jpg
Present! H:\DOBRERIBE
################## | Registry |
################## | Mountpoints2 |
HKCU\.\.\.\.\Explorer\MountPoints2\{10c1e15c-ac3b-11df-ac2e-0004231cf8e5}
Shell\AutoRun\Command = PehxXt.eXe
Shell\oPEN\Command = pehXXT.eXE
HKCU\.\.\.\.\Explorer\MountPoints2\{3e7f3ea4-4656-11df-ab67-00e04c3902b6}
Shell\AutoRun\Command = DOBRERIBE/ziza.exe
Shell\explore\Command = DOBRERIBE/ziza.exe
Shell\open\Command = DOBRERIBE/ziza.exe
HKCU\.\.\.\.\Explorer\MountPoints2\{480993d9-918e-11df-ac03-0004231cf8e5}
Shell\AutoRun\Command = F:\mirk\\okitab.exe
Shell\explore\Command = F:\mirk\\\okitab.exe
Shell\open\Command = F:\mirk\\\okitab.exe
HKCU\.\.\.\.\Explorer\MountPoints2\{4d12573d-67e4-11df-abbc-0004231cf8e5}
Shell\AutoRun\Command = F:\DOBRERIBE/ziza.exe
Shell\explore\Command = F:\DOBRERIBE/ziza.exe
Shell\open\Command = F:\DOBRERIBE/ziza.exe
HKCU\.\.\.\.\Explorer\MountPoints2\{571aa53e-7ab5-11df-abd9-0004231cf8e5}
Shell\AutoRun\Command = ACC1\F1C1\acc1.exe
Shell\open\Command = ACC1\F1C1\acc1.exe
HKCU\.\.\.\.\Explorer\MountPoints2\{5ed40a23-9ee2-11df-ac12-0004231cf8e5}
Shell\AutoRun\Command = F:\DOBRERIBE/ziza.exe
Shell\explore\Command = F:\DOBRERIBE/ziza.exe
Shell\open\Command = F:\DOBRERIBE/ziza.exe
HKCU\.\.\.\.\Explorer\MountPoints2\{6fe2a330-7dd7-11df-abdc-0004231cf8e5}
Shell\AutoRun\Command = F:\RECYCLER\S-51-9-25-3434476501-1644491933-601314628-1214\Instmiv.exe
Shell\open\Command = F:\RECYCLER\S-51-9-25-3434476501-1644491933-601314628-1214\Instmiv.exe
HKCU\.\.\.\.\Explorer\MountPoints2\{75a5b53c-ab77-11df-ac2a-0004231cf8e5}
Shell\AutoRun\Command = F:\LaunchU3.exe -a
HKCU\.\.\.\.\Explorer\MountPoints2\{8bbea173-8105-11df-abe1-0004231cf8e5}
Shell\AutoRun\Command = F:\rane\\kure.exe
Shell\explore\Command = F:\rane\\\kure.exe
Shell\open\Command = F:\rane\\\kure.exe
HKCU\.\.\.\.\Explorer\MountPoints2\{8f960fdc-835b-11df-abe4-0004231cf8e5}
Shell\AutoRun\Command = READER_SL.EXE
HKCU\.\.\.\.\Explorer\MountPoints2\{97da635c-5ce4-11df-aba7-0004231cf8e5}
Shell\AutoRun\Command = G:\mirk\\okitab.exe
Shell\explore\Command = G:\mirk\\\okitab.exe
Shell\open\Command = G:\mirk\\\okitab.exe
HKCU\.\.\.\.\Explorer\MountPoints2\{f6c88652-829c-11df-abe3-0004231cf8e5}
Shell\AutoRun\Command = F:\DOBRERIBE/ziza.exe
Shell\explore\Command = F:\DOBRERIBE/ziza.exe
Shell\open\Command = F:\DOBRERIBE/ziza.exe
HKCU\.\.\.\.\Explorer\MountPoints2\{faa0d102-5115-11df-ab94-0004231cf8e5}
Shell\AutoRun\Command = G:\DOBRERIBE/ziza.exe
Shell\explore\Command = G:\DOBRERIBE/ziza.exe
Shell\open\Command = G:\DOBRERIBE/ziza.exe
################## | Vaccine |
C:\Autorun.inf -> Folder created by UsbFix (El Desaparecido & C_XX)
D:\Autorun.inf -> Folder created by UsbFix (El Desaparecido & C_XX)
F:\Autorun.inf -> Folder created by UsbFix (El Desaparecido & C_XX)
################## | E.O.F | -
Here is the result of the UsbFix removal.
############################## | UsbFix 7.021 | [Removal]
User: CEPLUS (Administrator) # SERVER [ ]
Updated on 20/08/10 by El Desaparecido / C_XX
Launched at 17:10:12 | 26/08/2010
Website: http://pagesperso-orange.fr/NosTools/index.html
Contact: FindyKill.Contact@gmail.com
CPU: Intel(R) Pentium(R) 4 CPU 1.60GHz
Microsoft Windows XP Professional (5.1.2600 32-Bit) # Service Pack 3
Internet Explorer 8.0.6001.18702
Windows Firewall: Enabled
Antivirus: AntiVir Desktop 9.0.1.32 [Enabled | Updated]
RAM -> 1023 MB
C:\ (%systemdrive%) -> Local Disk # 29 GB (7 GB free - 23%) [Local Disk] # NTFS
D:\ -> Local Disk # 19 GB (1 GB free - 6%) [] # NTFS
E:\ -> CD-ROM
F:\ -> Removable Disk # 964 MB (962 MB free - 100%) [STORE'N'GO] # FAT
G:\ -> CD-ROM
H:\ -> Removable Disk # 2 GB (2 GB free - 100%) [NEW NAME] # FAT
################## | Infectious Items |
Deleted! H:\Autorun.inf
Not deleted! H:\image.jpg
Deleted! H:\DOBRERIBE
################## | Registry |
################## | Mountpoints2 |
Deleted! HKCU\.\.\.\.\Explorer\MountPoints2\{10c1e15c-ac3b-11df-ac2e-0004231cf8e5}
Deleted! HKCU\.\.\.\.\Explorer\MountPoints2\{3e7f3ea4-4656-11df-ab67-00e04c3902b6}
Deleted! HKCU\.\.\.\.\Explorer\MountPoints2\{480993d9-918e-11df-ac03-0004231cf8e5}
Deleted! HKCU\.\.\.\.\Explorer\MountPoints2\{4d12573d-67e4-11df-abbc-0004231cf8e5}
Deleted! HKCU\.\.\.\.\Explorer\MountPoints2\{571aa53e-7ab5-11df-abd9-0004231cf8e5}
Deleted! HKCU\.\.\.\.\Explorer\MountPoints2\{5ed40a23-9ee2-11df-ac12-0004231cf8e5}
Deleted! HKCU\.\.\.\.\Explorer\MountPoints2\{6fe2a330-7dd7-11df-abdc-0004231cf8e5}
Deleted! HKCU\.\.\.\.\Explorer\MountPoints2\{75a5b53c-ab77-11df-ac2a-0004231cf8e5}
Deleted! HKCU\.\.\.\.\Explorer\MountPoints2\{8bbea173-8105-11df-abe1-0004231cf8e5}
Deleted! HKCU\.\.\.\.\Explorer\MountPoints2\{8f960fdc-835b-11df-abe4-0004231cf8e5}
Deleted! HKCU\.\.\.\.\Explorer\MountPoints2\{97da635c-5ce4-11df-aba7-0004231cf8e5}
Deleted! HKCU\.\.\.\.\Explorer\MountPoints2\{f6c88652-829c-11df-abe3-0004231cf8e5}
Deleted! HKCU\.\.\.\.\Explorer\MountPoints2\{faa0d102-5115-11df-ab94-0004231cf8e5}
################## | Listing |
[26/08/2010 - 15:52:13 | A | 4] C:\AUTOEXEC.BAT
[25/08/2010 - 19:29:18 | RASHD ] C:\Autorun.inf
[12/04/2010 - 15:57:02 | SH | 212] C:\boot.ini
[28/08/2001 - 14:00:00 | RASH | 4952] C:\Bootfont.bin
[12/04/2010 - 16:04:29 | A | 0] C:\CONFIG.SYS
[16/07/2010 - 14:51:52 | D ] C:\D6
[16/04/2010 - 09:33:21 | D ] C:\Documents and Settings
[31/07/2010 - 19:36:39 | D ] C:\Downloads
[26/08/2010 - 16:43:59 | ASH | 1073270784] C:\hiberfil.sys
[12/04/2010 - 16:04:29 | RASH | 0] C:\IO.SYS
[26/08/2010 - 14:59:38 | D ] C:\Kill'em
[26/08/2010 - 09:53:36 | A | 47984] C:\List'em.txt
[23/08/2010 - 19:13:14 | A | 413] C:\My documents.lnk
[12/04/2010 - 16:04:29 | RASH | 0] C:\MSDOS.SYS
[13/04/2010 - 11:21:38 | RHD ] C:\MSOCache
[13/04/2008 - 09:43:04 | RASH | 47564] C:\NTDETECT.COM
[13/04/2008 - 11:31:52 | RASH | 252240] C:\ntldr
[26/08/2010 - 16:43:58 | ASH | 1610612736] C:\pagefile.sys
[26/08/2010 - 16:50:23 | RD ] C:\Program Files
[26/08/2010 - 17:14:05 | SHD ] C:\RECYCLER
[13/07/2010 - 13:08:45 | A | 183] C:\sgbx.log
[12/04/2010 - 16:09:55 | SHD ] C:\System Volume Information
[26/08/2010 - 17:14:05 | D ] C:\UsbFix
[26/08/2010 - 17:14:06 | A | 1038] C:\UsbFix.txt
[25/08/2010 - 19:29:20 | A | 48943] C:\UsbFix_Upload_Me_SERVER.zip
[26/08/2010 - 14:59:56 | D ] C:\WINDOWS
[21/11/2009 - 03:32:50 | A | 734115840] D:\7 Plans Before My 30 Years_by thierry.avi
[23/10/2009 - 10:02:00 | A | 33280] D:\ademci.doc
[07/07/2010 - 17:52:14 | A | 15011] D:\agency nass.docx
[12/06/2010 - 10:10:47 | D ] D:\AKON
[24/04/2010 - 16:48:29 | D ] D:\SO THEN
[26/02/2010 - 20:04:20 | A | 380416] D:\anniversary.doc
[27/01/2010 - 14:18:27 | D ] D:\ARAFATE MP3 LAST
[05/11/2009 - 09:27:27 | D ] D:\Atomix Virtual DJ 1.09 Full+Crack+skins+Effects (by charled v1.1)
[18/02/2010 - 09:57:26 | A | 22528] D:\SALE CERTIFICATE.doc
[25/08/2010 - 19:29:18 | RASHD ] D:\Autorun.inf
[30/12/2009 - 20:29:54 | A | 743220278] D:\Avatar.2009.FRENCH.REPACK.1CD.TS.MD.XViD.avi
[20/08/2010 - 18:32:15 | A | 21526] D:\BATIM.xlsx
[01/03/2010 - 13:13:45 | D ] D:\ccp
[17/10/2009 - 17:00:11 | D ] D:\ccp(2)
[16/10/2009 - 15:18:26 | A | 16496] D:\client.jpg
[16/10/2009 - 15:23:24 | A | 15858] D:\client02.jpg
[03/07/2009 - 14:57:14 | A | 734058496] D:\Code Omega The Prophecy of Darkness II.avi
[06/03/2010 - 19:21:39 | A | 852480] D:\How to fix Vista with or without DVD.doc
[09/03/2009 - 09:11:32 | A | 115072589] D:\Companion_Suite_IH_W_V1_1__2.exe
[27/01/2010 - 17:08:31 | D ] D:\DALFOLO (E)
[25/02/2010 - 09:46:42 | A | 25088] D:\job application.doc
[27/01/2010 - 14:46:21 | D ] D:\DEZY 45 STUDENTS
[06/02/2010 - 10:36:52 | D ] D:\Folder
[22/05/2010 - 11:53:07 | D ] D:\important folder
[03/02/2010 - 10:55:02 | A | 3169784] D:\DriverScanner.exe
[11/09/2009 - 14:37:51 | A | 15514] D:\header (WordFIX).doc
[02/05/2009 - 15:18:53 | A | 28672] D:\header.doc
[05/05/2009 - 10:35:56 | D ] D:\HOPE MP3
[12/10/2009 - 16:50:11 | A | 32768] D:\INVOICE FEELING.doc
[01/03/2010 - 09:43:18 | A | 27136] D:\fanny.doc
[17/02/2010 - 12:48:22 | A | 24064] D:\Faye.doc
[01/03/2010 - 11:14:28 | A | 22528] D:\Faye2.doc
[29/10/2009 - 14:12:06 | A | 6519272] D:\free-mp3-wma-converter_free_mp3_wma_converter_1.8_french_34863.exe
[01/02/2009 - 17:54:13 | A | 8649058] D:\Free-YouTube-Downloader.exe
[04/07/2009 - 11:06:01 | D ] D:\GARAGE OWNERS
[11/09/2009 - 16:20:10 | D ] D:\GARAGE OWNERS MP3
[30/07/2010 - 16:38:09 | A | 38912] D:\glacier.doc
[10/05/2010 - 18:55:43 | A | 132926] D:\installation guide win98.docx
[25/11/2009 - 14:33:16 | A | 3136288] D:\idman518.exe
[26/08/2009 - 14:12:38 | D ] D:\Images
[04/12/2009 - 09:10:42 | D ] D:\important
[09/06/2010 - 11:30:55 | A | 5018624] D:\INTRODUCTIONS TO COMPUTERS AND WINDOWS.doc
[27/04/2010 - 16:34:52 | A | 97525032] D:\iTunesSetup.exe
[12/07/2010 - 12:32:32 | A | 54272] D:\KOUAME.doc
[24/04/2010 - 12:37:47 | A | 50688] D:\RECEPTION OF ORDERED ITEMS.doc
[23/04/2010 - 17:54:00 | A | 57344] D:\RECEPTION OF ORDERED ITEMS.doc
[25/02/2010 - 08:40:26 | A | 23040] D:\sponsorship request letter.doc
[03/03/2010 - 10:17:13 | A | 32256] D:\letter.doc
[29/03/2010 - 19:47:28 | A | 84480] D:\libraries.doc
[06/06/2009 - 16:37:36 | A | 16510368] D:\LimeWireWin.exe
[11/05/2009 - 17:29:11 | D ] D:\lodane
[27/04/2009 - 14:54:41 | D ] D:\MADOUSSOU
[19/05/2009 - 14:54:46 | A | 742] D:\Mario Forever.lnk
[19/05/2009 - 14:53:38 | A | 21538712] D:\Mario_Forever41.exe
[12/08/2010 - 17:47:12 | RD ] D:\my courses
[06/02/2002 - 16:27:00 | A | 30633521] D:\moviexone.exe
[16/11/2009 - 15:06:55 | RD ] D:\mp3
[20/06/2009 - 10:54:19 | D ] D:\MPEGAV
[22/09/2009 - 09:49:42 | RHD ] D:\MSOCache
[20/11/2009 - 15:47:29 | RD ] D:\Music
[12/11/2009 - 16:52:20 | A | 65148610] D:\NamoWebEditor8EnuTrial.exe
[10/07/2010 - 11:00:40 | A | 14494] D:\OUR NEEDS.docx
[22/12/2009 - 12:33:48 | RD ] D:\New folder
[15/10/2009 - 14:37:32 | D ] D:\New folder (2)
[27/04/2010 - 19:24:30 | D ] D:\New folder (3)
[18/06/2009 - 17:21:23 | D ] D:\New folder1
[27/01/2010 - 14:46:26 | D ] D:\PATIENCE DABANI
[15/05/2009 - 12:06:07 | A | 130433] D:\Photo (5).jpg
[05/06/2009 - 15:56:57 | A | 84992] D:\creation_plan1_06.doc
[27/04/2010 - 19:21:59 | D ] D:\for iphone
[26/02/2010 - 16:38:44 | A | 25088] D:\PROTOCOL D.doc
[26/08/2010 - 17:14:05 | SHD ] D:\RECYCLER
[14/08/2010 - 11:03:45 | A | 161280] D:\romaric.doc
[01/12/2009 - 17:36:26 | A | 6343388] D:\Setup_FreeFlvConverter.exe
[27/01/2010 - 11:35:02 | D ] D:\religious sound
[18/06/2009 - 17:21:24 | RD ] D:\Sounds
[06/05/2009 - 14:58:22 | A | 45568] D:\STOCKS OF PORTABLE.doc
[12/04/2010 - 16:17:30 | SHD ] D:\System Volume Information
[12/08/2010 - 17:47:10 | ASH | 8192] D:\Thumbs.db
[05/05/2009 - 10:35:09 | D ] D:\Tiken Jah MP 3
[23/06/2009 - 14:21:29 | A | 170052568] D:\TrueImageServerEcho_d_en.exe
[14/11/2009 - 17:06:48 | D ] D:\Videos
[30/05/2009 - 20:52:46 | A | 170203312] D:\VideoSpin_2_0_Setup.exe
[28/07/2009 - 13:28:03 | D ] D:\Zook
[24/03/2010 - 14:30:40 | AH | 162] D:\~$request for sponsorship letter.doc
[25/08/2010 - 18:49:46 | RSHD ] F:\POGRJESILA
[25/08/2010 - 19:29:20 | D ] F:\Autorun.inf
[24/08/2010 - 15:34:36 | D ] F:\steve
[26/08/2010 - 11:33:46 | A | 24362] H:\OCR0001.rtf
[26/08/2010 - 11:54:28 | RSHD ] H:\POGRJESILA
[24/08/2010 - 11:25:44 | A | 368640] H:\receipt.doc
[24/08/2010 - 11:25:56 | A | 510464] H:\thumbnail.doc
[24/08/2010 - 11:25:14 | A | 558592] H:\logistics.doc
[24/08/2010 - 11:21:00 | A | 480768] H:\Declaration.doc
[26/08/2010 - 14:43:30 | A | 62857] H:\face 1.jpg
[26/08/2010 - 14:43:32 | A | 51563] H:\face 2.jpg
################## | Vaccine |
C:\Autorun.inf -> Folder created by UsbFix (El Desaparecido & C_XX)
D:\Autorun.inf -> Folder created by UsbFix (El Desaparecido & C_XX)
F:\Autorun.inf -> Folder created by UsbFix (El Desaparecido & C_XX)
H:\Autorun.inf -> Folder created by UsbFix (El Desaparecido & C_XX)
################## | Upload |
Please send the file: C:\UsbFix_Upload_Me_SERVER.zip
https://www.ionos.fr/?affiliate_id=77097
Thank you for your contribution.
################## | E.O.F |
- 1
- 2
Next