Ccleaner impossible to download!

juju29 -  
jacques.gache Posted messages 34829 Status Security Contributor -
Hello everyone!
I don't understand, some software is impossible for me to download... like Ccleaner; I get an error message that says "can't initialize Plug-ins directory"!
What should I do?
Thanks in advance.
Configuration: Windows XP Internet Explorer 7.0

11 answers

  1. jacques.gache Posted messages 34829 Status Security Contributor 1 645
     
    Hello, if it's a rootkit that's blocking you, it's going to be hard to disinfect.
    0
    1. juju29
       
      what can I do if it is indeed a rootkit?
      is it detectable?
      does it show up in a log?
      thank you for your answers
      0
      1. jacques.gache Posted messages 34829 Status Security Contributor 1 645 > juju29
         
        start by running Malwarebytes and CCleaner from the provided sites; if that doesn't work, we'll reassess.
        0
  2. Cesel45 Posted messages 13762 Registration date   Status Contributor Last intervention   2 845
     
    Hello

    This issue can occur in a restricted session.

    If that's not your case, then the problem lies elsewhere.

    Restart in "safe mode with networking (F8)....... "Administrator"

    --
    I don't have all the answers. I'm just here to help you.
    0
  3. jacques.gache Posted messages 34829 Status Security Contributor 1 645
     
    Hello again, start by running Malwarebytes followed by CCleaner in both cleaner and registry modes and an online virus scan with Bitdefender using Internet Explorer and post the Bitdefender report.
    1) Malwarebytes: https://www.malekal.com/tutoriel-malwarebyte-anti-malware/
    2) CCleaner: https://www.malekal.com/tutoriel-ccleaner/
    3) Online scan: http://www.commentcamarche.net/faq/sujet 8872 online scanner with Bitdefender
    Read the tutorials carefully to apply them correctly, do them in order, thanks.
    0
  4. Benjamin83260 Posted messages 133 Status Member 2
     
    Hello, I’m quite familiar with computers, but to solve your problem, I need to know 3 simple things

    1) Are you trying to install CCleaner? Why? Virus detection? To secure the computer? ...

    2) Which platform are you installing it on? CCM? Windows Antivirus? ...

    3) What other security measures do you have in place? For example: AVAST, NORTON, SPYBOT, HITJACKS ...

    I look forward to your response as soon as possible

    Best regards, Benjamin83260
    0
    1. jacques.gache Posted messages 34829 Status Security Contributor 1 645
       
      Benjamin83260 hello, Ccleaner is not a virus search tool but a cleaning software for all traces of the internet and the registry.
      0
      1. Benjamin83260 Posted messages 133 Status Member 2 > jacques.gache Posted messages 34829 Status Security Contributor
         
        I know well, but I am not talking about virus detection by CCleaner. I was saying that if it was because she or he found a virus on their PC that this person wants to install it.


        Sincerely, Benjamin83260
        0
      2. jacques.gache Posted messages 34829 Status Security Contributor 1 645 > Benjamin83260 Posted messages 133 Status Member
         
        ok I didn't want to argue but since it's Avast as an antivirus, you shouldn't be surprised that it didn't catch it.
        0
    2. juju29
       
      1) I'm trying to install it to do a little cleaning... until yesterday, I couldn't open Hotmail because IE was having a problem... the problem is resolved! But a weird envelope that appears in the taskbar (near the clock) every time a web page loads is worrying me a bit!
      The fact that I can't download CCleaner reinforces my belief that something is off...
      I tried via 01.net
      Otherwise, I have Avast, Ad-aware, Spybot.
      0
  5. jacques.gache Posted messages 34829 Status Security Contributor 1 645
     
    If CCleaner doesn't work, try Malwarebytes and the online scan.
    0
    1. juju29
       
      The malware analysis is complete; here is the report!

      Malwarebytes' Anti-Malware 1.11
      Database version: 662

      Scan type: Full scan (C:\|F:\|)
      Items scanned: 104414
      Elapsed time: 40 minute(s), 26 second(s)

      Infected memory process(es): 0
      Infected memory module(s): 0
      Infected Registry key(s): 1
      Infected Registry value(s): 0
      Infected Registry data item(s): 0
      Infected folder(s): 1
      Infected file(s): 4

      Infected memory process(es):
      (No malicious items detected)

      Infected memory module(s):
      (No malicious items detected)

      Infected Registry key(s):
      HKEY_LOCAL_MACHINE\SOFTWARE\Tencent (Adware.Agent) -> Quarantined and deleted successfully.

      Infected Registry value(s):
      (No malicious items detected)

      Infected Registry data item(s):
      (No malicious items detected)

      Infected folder(s):
      C:\Documents and Settings\Julien\Local Settings\Temp\NI.UGA6PV_0001_N122M2910 (Rogue.Multiple) -> Quarantined and deleted successfully.

      Infected file(s):
      C:\Documents and Settings\Julien\Local Settings\Temp\is-MDEGM.tmp\is-16K56.tmp (Trojan.Toolbar) -> Quarantined and deleted successfully.
      C:\Documents and Settings\Julien\Local Settings\Temp\NI.UGA6PV_0001_N122M2910\settings.ini (Rogue.Multiple) -> Quarantined and deleted successfully.
      C:\WINDOWS\Fonts\ducahier.zip (Trojan.Downloader) -> Quarantined and deleted successfully.
      C:\WINDOWS\svchost.MSNFix (Heuristics.Reserved.Word.Exploit) -> Quarantined and deleted successfully.
      0
  6. Benjamin83260 Posted messages 133 Status Member 2
     
    Dacor, so I'm sending you everything you need, but please, your email address to send it to you, otherwise it's impossible.

    Sincerely, Benjamin83260
    0
    1. jacques.gache Posted messages 34829 Status Security Contributor 1 645
       
      Benjamin83260, who do you want the address for to send what? I don't follow you anymore, whereas on the forum you can post your analysis reports.
      0
      1. Benjamin83260 Posted messages 133 Status Member 2 > jacques.gache Posted messages 34829 Status Security Contributor
         
        I want Juju's address to send him the personal files of the CCLener downloads.

        Best regards, Benjamin83260
        0
      2. jacques.gache Posted messages 34829 Status Security Contributor 1 645 > Benjamin83260 Posted messages 133 Status Member
         
        For CCleaner, he can find it at the address I gave him or even here https://filehippo.com/download_ccleaner/. Otherwise, you can ask him to sign up, and that way you can send him a personal message.
        0
      3. juju29 > jacques.gache Posted messages 34829 Status Security Contributor
         
        Here you go! I scanned online with Bitdefender and it removed some viruses! Thanks!!
        However, still can't download CCleaner: "can't initialize Plug-ins directory" shows up in an error window..
        And then there's this kind of envelope that blinks in the taskbar when a web page is loading... I don't know what it could be!
        Thanks again for everything Jacques.gache
        0
  7. jacques.gache Posted messages 34829 Status Security Contributor 1 645
     
    I was asking you for the Bitdefender report for verification of the disinfection, but if you say it's fine, okay, it's your PC
    still run SmitFraudFix http://www.malekal.com/tutorial_SmitFraudfix.php
    0
    1. juju29
       
      autant pour moi... I'm sending you all of that!!

      BitDefender Online Scanner



      Analysis report generated on: Sun, Apr 20, 2008 - 18:26:54





      Scan path: A:\;C:\;D:\;E:\;F:\;G:\;H:\;I:\;J:\;







      Statistics

      Time
      00:27:43

      Files
      81405

      Directories
      6390

      Boot sectors
      3

      Archives
      931

      Program packages
      8287




      Results

      Identified viruses
      2

      Infected files
      8

      Suspicious files
      0

      Warnings
      0

      Disinfected
      0

      Deleted files
      6




      Info on the engines

      Virus definition
      1166889

      Engine version
      AVCORE v1.0 (build 2422) (i386) (Sep 25 2007 08:26:36)

      Plugin analysis
      16

      Plugin archive
      41

      Plugin unpack
      7

      Email plugins
      6

      System plugins
      5




      Scan settings

      First action
      Disinfected

      Second action
      Deleted

      Heuristic
      Yes

      Accept warnings
      Yes

      Analyzed extensions
      exe;com;dll;ocx;scr;bin;dat;386;vxd;sys;wdm;cla;class;ovl;ole;hlp;doc;dot;xls;ppt;wbk;wiz;pot;ppa;xla;xlt;vbs;vbe;mdb;rtf;htm;hta;html;xml;xtp;php;asp;js;shs;chm;lnk;pif;prc;url;smm;pfd;msi;ini;csc;cmd;bas;

      Exclude extensions


      Email analysis
      Yes

      Archive analysis
      Yes

      Analyze program packages
      Yes

      File analysis
      Yes

      Boot scan
      Yes




      File analyzed
      Status

      C:\!KillBox\GbPluggin\gbiehcef.dll
      Infected by: Generic.Banker.Delf.F6C70493

      C:\!KillBox\GbPluggin\gbiehcef.dll
      Disinfection failed

      C:\!KillBox\GbPluggin\gbiehcef.dll
      Deleted

      C:\!KillBox\GbPluggin\gbpdist.dll
      Infected by: Trojan.Banker.Delf.YDZ

      C:\!KillBox\GbPluggin\gbpdist.dll
      Deleted

      C:\Program Files\GbPluggin\gbiehcef.dll
      Infected by: Generic.Banker.Delf.F6C70493

      C:\Program Files\GbPluggin\gbiehcef.dll
      Disinfection failed

      C:\Program Files\GbPluggin\gbiehcef.dll
      Deletion failed

      C:\Program Files\GbPluggin\gbpdist.dll
      Infected by: Trojan.Banker.Delf.YDZ

      C:\Program Files\GbPluggin\gbpdist.dll
      Disinfection failed

      C:\Program Files\GbPluggin\gbpdist.dll
      Deletion failed

      C:\System Volume Information\_restore{187191F8-378D-4B61-9872-B83152D14471}\RP503\A0133963.dll
      Infected by: Generic.Banker.Delf.F6C70493

      C:\System Volume Information\_restore{187191F8-378D-4B61-9872-B83152D14471}\RP503\A0133963.dll
      Disinfection failed

      C:\System Volume Information\_restore{187191F8-378D-4B61-9872-B83152D14471}\RP503\A0133963.dll
      Deleted

      C:\System Volume Information\_restore{187191F8-378D-4B61-9872-B83152D14471}\RP503\A0133964.dll
      Infected by: Trojan.Banker.Delf.YDZ

      C:\System Volume Information\_restore{187191F8-378D-4B61-9872-B83152D14471}\RP503\A0133964.dll
      Deleted

      C:\System Volume Information\_restore{187191F8-378D-4B61-9872-B83152D14471}\RP503\A0133986.dll
      Infected by: Generic.Banker.Delf.F6C70493

      C:\System Volume Information\_restore{187191F8-378D-4B61-9872-B83152D14471}\RP503\A0133986.dll
      Disinfection failed

      C:\System Volume Information\_restore{187191F8-378D-4B61-9872-B83152D14471}\RP503\A0133986.dll
      Deleted

      C:\System Volume Information\_restore{187191F8-378D-4B61-9872-B83152D14471}\RP503\A0133987.dll
      Infected by: Trojan.Banker.Delf.YDZ

      C:\System Volume Information\_restore{187191F8-378D-4B61-9872-B83152D14471}\RP503\A0133987.dll
      Deleted
      0
    2. juju29
       
      Here is the Smitfraudfix report... should I follow the disinfection report in safe mode?

      SmitFraudFix v2.315

      Report created at 18:58:11.14, 20/04/2008
      Executed from C:\Documents and Settings\Desktop\SmitfraudFix
      OS: Microsoft Windows XP [version 5.1.2600] - Windows_NT
      The file system type is NTFS
      Fix executed in normal mode

      »»»»»»»»»»»»»»»»»»»»»»»» Process

      C:\WINDOWS\System32\smss.exe
      C:\WINDOWS\system32\csrss.exe
      C:\WINDOWS\SYSTEM32\winlogon.exe
      C:\WINDOWS\system32\services.exe
      C:\WINDOWS\system32\lsass.exe
      C:\WINDOWS\system32\svchost.exe
      C:\WINDOWS\system32\svchost.exe
      C:\WINDOWS\System32\svchost.exe
      C:\WINDOWS\system32\svchost.exe
      C:\WINDOWS\system32\svchost.exe
      C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
      C:\Program Files\Alwil Software\Avast4\ashServ.exe
      C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
      C:\Program Files\Common Files\EPSON\EBAPI\eEBSVC.exe
      C:\Program Files\Common Files\EPSON\EBAPI\SAgent2.exe
      C:\WINDOWS\PMJ151LA.BIN
      C:\WINDOWS\system32\HPZipm12.exe
      C:\WINDOWS\system32\svchost.exe
      C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
      C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
      C:\WINDOWS\System32\alg.exe
      C:\Program Files\Internet Explorer\IEXPLORE.EXE
      C:\Program Files\Adobe\Reader 8.0\Reader\AcroRd32.exe
      C:\WINDOWS\explorer.exe
      C:\WINDOWS\system32\spoolsv.exe
      C:\WINDOWS\system32\cmd.exe
      C:\WINDOWS\system32\wbem\wmiprvse.exe

      »»»»»»»»»»»»»»»»»»»»»»»» hosts

      Corrupted hosts file!

      127.0.0.1 www.legal-at-spybot.info
      127.0.0.1 legal-at-spybot.info

      »»»»»»»»»»»»»»»»»»»»»»»» C:\


      »»»»»»»»»»»»»»»»»»»»»»»» C:\WINDOWS


      »»»»»»»»»»»»»»»»»»»»»»»» C:\WINDOWS\system


      »»»»»»»»»»»»»»»»»»»»»»»» C:\WINDOWS\Web


      »»»»»»»»»»»»»»»»»»»»»»»» C:\WINDOWS\system32


      »»»»»»»»»»»»»»»»»»»»»»»» C:\WINDOWS\system32\LogFiles


      »»»»»»»»»»»»»»»»»»»»»»»» C:\Documents and Settings\Julien


      »»»»»»»»»»»»»»»»»»»»»»»» C:\Documents and Settings\Julien\Application Data


      »»»»»»»»»»»»»»»»»»»»»»»» Start Menu


      »»»»»»»»»»»»»»»»»»»»»»»» C:\DOCUME~1\Julien\Favorites


      »»»»»»»»»»»»»»»»»»»»»»»» Desktop


      »»»»»»»»»»»»»»»»»»»»»»»» C:\Program Files


      »»»»»»»»»»»»»»»»»»»»»»»» Corrupted keys


      »»»»»»»»»»»»»»»»»»»»»»»» Desktop items

      [HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Desktop\Components\0]
      "Source"="http://gfx2.hotmail.com/tab.bg.dln.gif"
      "SubscribedURL"="http://gfx2.hotmail.com/tab.bg.dln.gif"
      "FriendlyName"=""

      [HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Desktop\Components\1]
      "Source"="About:Home"
      "SubscribedURL"="About:Home"
      "FriendlyName"="My homepage"

      »»»»»»»»»»»»»»»»»»»»»»»» IEDFix
      !!!Warning, the keys that follow are not necessarily infected!!!

      IEDFix
      Credits: Malware Analysis & Diagnostic
      Code: S!Ri


      »»»»»»»»»»»»»»»»»»»»»»»» VACFix
      !!!Warning, the keys that follow are not necessarily infected!!!

      VACFix
      Credits: Malware Analysis & Diagnostic
      Code: S!Ri


      »»»»»»»»»»»»»»»»»»»»»»»» Sharedtaskscheduler
      !!!Warning, the keys that follow are not necessarily infected!!!

      SrchSTS.exe by S!Ri
      Search SharedTaskScheduler's .dll


      »»»»»»»»»»»»»»»»»»»»»»»» AppInit_DLLs
      !!!Warning, the keys that follow are not necessarily infected!!!

      [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows]
      "AppInit_DLLs"=""


      »»»»»»»»»»»»»»»»»»»»»»»» Winlogon
      !!!Warning, the keys that follow are not necessarily infected!!!

      [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon]
      "Userinit"="C:\\WINDOWS\\system32\\userinit.exe,"
      "System"=""


      »»»»»»»»»»»»»»»»»»»»»»»» Rustock



      »»»»»»»»»»»»»»»»»»»»»»»» DNS

      Description: NVIDIA nForce Networking Controller - Packet Scheduler Miniport
      DNS Server Search Order: 192.168.30.1
      DNS Server Search Order: 0.0.0.0

      HKLM\SYSTEM\CCS\Services\Tcpip\..\{1701CD20-FBE9-4A10-94F0-39F4F55919F8}: DhcpNameServer=192.168.30.1 0.0.0.0
      HKLM\SYSTEM\CS1\Services\Tcpip\..\{1701CD20-FBE9-4A10-94F0-39F4F55919F8}: DhcpNameServer=192.168.30.1 0.0.0.0
      HKLM\SYSTEM\CS2\Services\Tcpip\..\{1701CD20-FBE9-4A10-94F0-39F4F55919F8}: DhcpNameServer=192.168.30.1 0.0.0.0
      HKLM\SYSTEM\CCS\Services\Tcpip\Parameters: DhcpNameServer=192.168.30.1 0.0.0.0
      HKLM\SYSTEM\CS1\Services\Tcpip\Parameters: DhcpNameServer=192.168.30.1 0.0.0.0
      HKLM\SYSTEM\CS2\Services\Tcpip\Parameters: DhcpNameServer=192.168.30.1 0.0.0.0


      »»»»»»»»»»»»»»»»»»»»»»»» Searching for wininet.dll infection


      »»»»»»»»»»»»»»»»»»»»»»»» End
      0
  8. jacques.gache Posted messages 34829 Status Security Contributor 1 645
     
    Okay, you disable and then re-enable System Restore as explained here http://service1.symantec.com/SUPPORT/INTER/tsgeninfointl.nsf/fdocid/20020830101856924
    and you run smitfraudfix as I added in the previous message.
    0
    1. juju29
       
      I did what you told me! Here is the second SmitFraudFix report:

      SmitFraudFix v2.315

      Report made at 19:09:49,46, 20/04/2008
      Executed from C:\Documents and Settings\Desktop\SmitfraudFix
      OS: Microsoft Windows XP [version 5.1.2600] - Windows_NT
      The file system type is NTFS
      Fix executed in normal mode

      »»»»»»»»»»»»»»»»»»»»»»»» Process

      C:\WINDOWS\System32\smss.exe
      C:\WINDOWS\system32\csrss.exe
      C:\WINDOWS\SYSTEM32\winlogon.exe
      C:\WINDOWS\system32\services.exe
      C:\WINDOWS\system32\lsass.exe
      C:\WINDOWS\system32\svchost.exe
      C:\WINDOWS\system32\svchost.exe
      C:\WINDOWS\System32\svchost.exe
      C:\WINDOWS\system32\svchost.exe
      C:\WINDOWS\system32\svchost.exe
      C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
      C:\Program Files\Alwil Software\Avast4\ashServ.exe
      C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
      C:\Program Files\Common Files\EPSON\EBAPI\eEBSVC.exe
      C:\Program Files\Common Files\EPSON\EBAPI\SAgent2.exe
      C:\WINDOWS\PMJ151LA.BIN
      C:\WINDOWS\system32\HPZipm12.exe
      C:\WINDOWS\system32\svchost.exe
      C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
      C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
      C:\WINDOWS\System32\alg.exe
      C:\Program Files\Internet Explorer\IEXPLORE.EXE
      C:\Program Files\Adobe\Reader 8.0\Reader\AcroRd32.exe
      C:\WINDOWS\explorer.exe
      C:\WINDOWS\system32\spoolsv.exe
      C:\WINDOWS\system32\cmd.exe
      C:\WINDOWS\system32\cmd.exe
      C:\WINDOWS\system32\wbem\wmiprvse.exe

      »»»»»»»»»»»»»»»»»»»»»»»» hosts

      Corrupted hosts file!

      127.0.0.1 www.legal-at-spybot.info
      127.0.0.1 legal-at-spybot.info

      »»»»»»»»»»»»»»»»»»»»»»»» C:\


      »»»»»»»»»»»»»»»»»»»»»»»» C:\WINDOWS


      »»»»»»»»»»»»»»»»»»»»»»»» C:\WINDOWS\system


      »»»»»»»»»»»»»»»»»»»»»»»» C:\WINDOWS\Web


      »»»»»»»»»»»»»»»»»»»»»»»» C:\WINDOWS\system32


      »»»»»»»»»»»»»»»»»»»»»»»» C:\WINDOWS\system32\LogFiles


      »»»»»»»»»»»»»»»»»»»»»»»» C:\Documents and Settings\Julien


      »»»»»»»»»»»»»»»»»»»»»»»» C:\Documents and Settings\Julien\Application Data


      »»»»»»»»»»»»»»»»»»»»»»»» Start Menu


      »»»»»»»»»»»»»»»»»»»»»»»» C:\DOCUME~1\Julien\Favorites


      »»»»»»»»»»»»»»»»»»»»»»»» Desktop


      »»»»»»»»»»»»»»»»»»»»»»»» C:\Program Files


      »»»»»»»»»»»»»»»»»»»»»»»» Corrupted keys


      »»»»»»»»»»»»»»»»»»»»»»»» Desktop items

      [HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Desktop\Components\0]
      "Source"="http://gfx2.hotmail.com/tab.bg.dln.gif"
      "SubscribedURL"="http://gfx2.hotmail.com/tab.bg.dln.gif"
      "FriendlyName"=""

      [HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Desktop\Components\1]
      "Source"="About:Home"
      "SubscribedURL"="About:Home"
      "FriendlyName"="My homepage"

      »»»»»»»»»»»»»»»»»»»»»»»» IEDFix
      !!! Attention, the keys that follow are not necessarily infected!!!

      IEDFix
      Credits: Malware Analysis & Diagnostic
      Code: S!Ri


      »»»»»»»»»»»»»»»»»»»»»»»» VACFix
      !!! Attention, the keys that follow are not necessarily infected!!!

      VACFix
      Credits: Malware Analysis & Diagnostic
      Code: S!Ri


      »»»»»»»»»»»»»»»»»»»»»»»» Sharedtaskscheduler
      !!! Attention, the keys that follow are not necessarily infected!!!

      SrchSTS.exe by S!Ri
      Search SharedTaskScheduler's .dll


      »»»»»»»»»»»»»»»»»»»»»»»» AppInit_DLLs
      !!! Attention, the keys that follow are not necessarily infected!!!

      [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows]
      "AppInit_DLLs"=""


      »»»»»»»»»»»»»»»»»»»»»»»» Winlogon
      !!! Attention, the keys that follow are not necessarily infected!!!

      [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon]
      "Userinit"="C:\\WINDOWS\\system32\\userinit.exe,"
      "System"=""


      »»»»»»»»»»»»»»»»»»»»»»»» Rustock



      »»»»»»»»»»»»»»»»»»»»»»»» DNS

      Description: NVIDIA nForce Networking Controller - Packet Scheduler Miniport
      DNS Server Search Order: 192.168.30.1
      DNS Server Search Order: 0.0.0.0

      HKLM\SYSTEM\CCS\Services\Tcpip\..\{1701CD20-FBE9-4A10-94F0-39F4F55919F8}: DhcpNameServer=192.168.30.1 0.0.0.0
      HKLM\SYSTEM\CS1\Services\Tcpip\..\{1701CD20-FBE9-4A10-94F0-39F4F55919F8}: DhcpNameServer=192.168.30.1 0.0.0.0
      HKLM\SYSTEM\CS2\Services\Tcpip\..\{1701CD20-FBE9-4A10-94F0-39F4F55919F8}: DhcpNameServer=192.168.30.1 0.0.0.0
      HKLM\SYSTEM\CCS\Services\Tcpip\Parameters: DhcpNameServer=192.168.30.1 0.0.0.0
      HKLM\SYSTEM\CS1\Services\Tcpip\Parameters: DhcpNameServer=192.168.30.1 0.0.0.0
      HKLM\SYSTEM\CS2\Services\Tcpip\Parameters: DhcpNameServer=192.168.30.1 0.0.0.0


      »»»»»»»»»»»»»»»»»»»»»»»» Wininet.dll infection search


      »»»»»»»»»»»»»»»»»»»»»»»» End
      0
  9. jacques.gache Posted messages 34829 Status Security Contributor 1 645
     
    yes go all the way
    0
  10. jacques.gache Posted messages 34829 Status Security Contributor 1 645
     
    You performed the disinfection in safe mode for smitfraudfix, so it should be fine. You uninstall ccleaner from add or remove programs if it’s there, and then go to your hard drive, program files, and if there’s a ccleaner folder, you delete it. Then you try to reinstall it either from malekal.com where you have the tutorial to understand, or here http://www.commentcamarche.net/telecharger/telecharger 168 ccleaner. If it installs successfully, you use it in its two modes: cleaner and registry.
    0
    1. juju29
       
      I'm sending you the report in safe mode:
      I'm also doing what you told me for CCleaner...

      SmitFraudFix v2.315

      Report made at 19:32:08,00, 20/04/2008
      Executed from C:\Documents and Settings\Desktop\SmitfraudFix
      OS: Microsoft Windows XP [version 5.1.2600] - Windows_NT
      The file system type is NTFS
      Fix executed in safe mode

      »»»»»»»»»»»»»»»»»»»»»»»» SharedTaskScheduler Before SmitFraudFix
      !!!Attention, the following keys are not necessarily infected!!!

      SrchSTS.exe by S!Ri
      Search SharedTaskScheduler's .dll

      »»»»»»»»»»»»»»»»»»»»»»»» Stopping processes


      »»»»»»»»»»»»»»»»»»»»»»»» hosts


      127.0.0.1 localhost
      127.0.0.1 www.007guard.com
      127.0.0.1 007guard.com
      127.0.0.1 008i.com
      127.0.0.1 www.008k.com
      127.0.0.1 008k.com
      127.0.0.1 www.00hq.com
      127.0.0.1 00hq.com
      127.0.0.1 010402.com
      127.0.0.1 www.032439.com
      127.0.0.1 032439.com
      127.0.0.1 www.1001-search.info
      127.0.0.1 1001-search.info
      127.0.0.1 www.100888290cs.com
      127.0.0.1 100888290cs.com
      127.0.0.1 www.100sexlinks.com
      127.0.0.1 100sexlinks.com
      127.0.0.1 www.10sek.com
      127.0.0.1 10sek.com
      127.0.0.1 www.123topsearch.com
      127.0.0.1 123topsearch.com
      127.0.0.1 www.132.com
      127.0.0.1 132.com
      127.0.0.1 www.136136.net
      127.0.0.1 136136.net
      127.0.0.1 www.139mm.com
      127.0.0.1 139mm.com
      127.0.0.1 www.163ns.com
      127.0.0.1 163ns.com
      127.0.0.1 171203.com
      127.0.0.1 17-plus.com
      127.0.0.1 www.1800searchonline.com
      127.0.0.1 1800searchonline.com
      127.0.0.1 www.180searchassistant.com
      127.0.0.1 180searchassistant.com
      127.0.0.1 www.180solutions.com
      127.0.0.1 180solutions.com
      127.0.0.1 www.181.365soft.info
      127.0.0.1 181.365soft.info
      127.0.0.1 www.1987324.com
      127.0.0.1 1987324.com
      127.0.0.1 www.1-domains-registrations.com
      127.0.0.1 1-domains-registrations.com
      127.0.0.1 www.1-extreme.biz
      127.0.0.1 1-extreme.biz
      127.0.0.1 www.1sexparty.com
      127.0.0.1 1sexparty.com
      127.0.0.1 www.1stantivirus.com
      127.0.0.1 1stantivirus.com
      127.0.0.1 www.1stpagehere.com
      127.0.0.1 1stpagehere.com
      127.0.0.1 www.1stsearchportal.com
      127.0.0.1 1stsearchportal.com
      127.0.0.1 2.82211.net
      127.0.0.1 www.2006ooo.com
      127.0.0.1 www.2007-download.com
      127.0.0.1 2007-download.com
      127.0.0.1 www.2020search.com
      127.0.0.1 2020search.com
      127.0.0.1 20x2p.com
      127.0.0.1 www.24.365soft.info
      127.0.0.1 24.365soft.info
      127.0.0.1 www.24-7pharmacy.info
      127.0.0.1 24-7pharmacy.info
      127.0.0.1 www.24-7searching-and-more.com
      127.0.0.1 24-7searching-and-more.com
      127.0.0.1 www.24teen.com
      127.0.0.1 24teen.com
      127.0.0.1 www.2every.net
      127.0.0.1 2every.net
      127.0.0.1 2ndpower.com
      127.0.0.1 www.2search.com
      127.0.0.1 2search.com
      127.0.0.1 www.2search.org
      127.0.0.1 2search.org
      127.0.0.1 www.2squared.com
      127.0.0.1 2squared.com
      127.0.0.1 www.3322.org
      127.0.0.1 3322.org
      127.0.0.1 365soft.info
      127.0.0.1 www.36site.com
      127.0.0.1 36site.com
      127.0.0.1 3721.com
      127.0.0.1 39-93.com
      127.0.0.1 www.3abetterinternet.com
      127.0.0.1 3abetterinternet.com
      127.0.0.1 www.3bay.it
      127.0.0.1 3bay.it
      127.0.0.1 www.3ebay.it
      127.0.0.1 3ebay.it
      127.0.0.1 www.3xclipsonline.com
      127.0.0.1 3xclipsonline.com
      127.0.0.1 www.3xcurves.com
      127.0.0.1 3xcurves.com
      127.0.0.1 www.3xfestival.com
      127.0.0.1 3xfestival.com
      127.0.0.1 www.3x-festival.com
      127.0.0.1 3x-festival.com
      127.0.0.1 www.3x-galls.com
      127.0.0.1 3x-galls.com
      127.0.0.1 www.3xmiracle.com
      127.0.0.1 3xmiracle.com
      127.0.0.1 www.3xmoviesblog.com
      127.0.0.1 3xmoviesblog.com
      127.0.0.1 www.404dns.com
      127.0.0.1 404dns.com
      127.0.0.1 www.4199.com
      127.0.0.1 4199.com
      127.0.0.1 www.4corn.net
      127.0.0.1 4corn.net
      127.0.0.1 www.4ebay.it
      127.0.0.1 4ebay.it
      127.0.0.1 4klm.com
      127.0.0.1 www.4mpg.com
      127.0.0.1 4mpg.com
      127.0.0.1 www.4repubblica.it
      127.0.0.1 4repubblica.it
      127.0.0.1 www.4softget.com
      127.0.0.1 4softget.com
      127.0.0.1 www.5iscali.it
      127.0.0.1 5iscali.it
      127.0.0.1 www.5repubblica.it
      127.0.0.1 5repubblica.it
      127.0.0.1 www.5starvideos.com
      127.0.0.1 5starvideos.com
      127.0.0.1 www.5tiscali.it
      127.0.0.1 5tiscali.it
      127.0.0.1 www.5zgmu7o20kt5d8yq.com
      127.0.0.1 5zgmu7o20kt5d8yq.com
      127.0.0.1 www.680180.net
      127.0.0.1 680180.net
      127.0.0.1 www.6iscali.it
      127.0.0.1 6iscali.it
      127.0.0.1 www.6njaga.com
      127.0.0.1 6njaga.com
      127.0.0.1 www.6sek.com
      127.0.0.1 6sek.com
      127.0.0.1 www.6tiscali.it
      127.0.0.1 6tiscali.it
      127.0.0.1 www.70-music.com
      127.0.0.1 70-music.com
      127.0.0.1 www.7322.com
      127.0.0.1 7322.com
      127.0.0.1 75tz.com
      127.0.0.1 www.777search.com
      127.0.0.1 777search.com
      127.0.0.1 www.777top.com
      127.0.0.1 777top.com
      127.0.0.1 www.7939.com
      127.0.0.1 7939.com
      127.0.0.1 www.7search.com
      127.0.0.1 7search.com
      127.0.0.1 80gw6ry3i3x3qbrkwhxhw.032439.com
      127.0.0.1 www.80-music.com
      127.0.0.1 80-music.com
      127.0.0.1 82211.net
      127.0.0.1 8866.org
      127.0.0.1 www.888.com
      127.0.0.1 888.com
      127.0.0.1 www.8ad.com
      127.0.0.1 8ad.com
      127.0.0.1 www.90-music.com
      127.0.0.1 90-music.com
      127.0.0.1 www.9505.com
      127.0.0.1 9505.com
      127.0.0.1 www.971searchbox.com
      127.0.0.1 971searchbox.com
      127.0.0.1 a.bestmanage.org
      127.0.0.1 www.aaabesthomepage.com
      127.0.0.1 aaabesthomepage.com
      127.0.0.1 aaasexypics.com
      127.0.0.1 www.aaawebfinder.com
      127.0.0.1 aaawebfinder.com
      127.0.0.1 www.aaqadarsztriv.com
      127.0.0.1 aaqadarsztriv.com
      127.0.0.1 www.aaqada-rsztriv.com
      127.0.0.1 aaqada-rsztriv.com
      127.0.0.1 www.aaqadaueorn.com
      127.0.0.1 aaqadaueorn.com
      127.0.0.1 www.aaqada-ueorn.com
      127.0.0.1 aaqada-ueorn.com
      127.0.0.1 www.aaqada-ygco.com
      127.0.0.1 aaqada-ygco.com
      127.0.0.1 www.aaqada-ymct.com
      127.0.0.1 aaqada-ymct.com
      127.0.0.1 aavc.com
      127.0.0.1 www.abcdperformance.com
      127.0.0.1 abcdperformance.com
      127.0.0.1 www.abc-find.info
      127.0.0.1 abc-find.info
      127.0.0.1 www.abcsearch.com
      127.0.0.1 abcsearch.com
      127.0.0.1 www.abetterinternet.com
      127.0.0.1 abetterinternet.com
      127.0.0.1 www.abnetsoft.info
      127.0.0.1 abnetsoft.info
      127.0.0.1 www.aboutclicker.com
      127.0.0.1 aboutclicker.com
      127.0.0.1 www.abrp.net
      127.0.0.1 abrp.net
      127.0.0.1 www.absolutee.com
      127.0.0.1 absolutee.com
      127.0.0.1 www.abyssmedia.com
      127.0.0.1 abyssmedia.com
      127.0.0.1 www.ac66.cn
      127.0.0.1 ac66.cn
      127.0.0.1 access.navinetwork.com
      127.0.0.1 access.rapid-pass.net
      127.0.0.1 www.accessactivexvideo.com
      127.0.0.1 accessactivexvideo.com
      127.0.0.1 www.accessclips.com
      127.0.0.1 accessclips.com
      127.0.0.1 www.access-dvd.com
      127.0.0.1 access-dvd.com
      127.0.0.1 www.accesskeygenerator.com
      127.0.0.1 accesskeygenerator.com
      127.0.0.1 www.accessthefuture.net
      127.0.0.1 accessthefuture.net
      127.0.0.1 www.accessvid.net
      127.0.0.1 accessvid.net
      127.0.0.1 www.acemedic.com
      127.0.0.1 acemedic.com
      127.0.0.1 www.ace-webmaster.com
      127.0.0.1 ace-webmaster.com
      127.0.0.1 acjp.com
      127.0.0.1 www.acrobat-2007.com
      127.0.0.1 acrobat-2007.com
      127.0.0.1 www.acrobat-8.com
      127.0.0.1 acrobat-8.com
      127.0.0.1 www.acrobat-center.com
      127.0.0.1 acrobat-center.com
      127.0.0.1 www.acrobat-hq.com
      127.0.0.1 acrobat-hq.com
      127.0.0.1 www.acrobatreader-8.com
      127.0.0.1 acrobatreader-8.com
      127.0.0.1 www.acrobat-reader-8.de
      127.0.0.1 acrobat-reader-8.de
      127.0.0.1 www.acrobat-stop.com
      127.0.0.1 acrobat-stop.com
      127.0.0.1 www.actionbreastcancer.org
      127.0.0.1 actionbreastcancer.org
      127.0.0.1 www.activesearcher.info
      127.0.0.1 activesearcher.info
      127.0.0.1 www.activexaccessobject.com
      127.0.0.1 activexaccessobject.com
      127.0.0.1 www.activexaccessvideo.com
      127.0.0.1 activexaccessvideo.com
      127.0.0.1 www.activexemedia.com
      127.0.0.1 activexemedia.com
      127.0.0.1 www.activexmediaobject.com
      127.0.0.1 activexmediaobject.com
      127.0.0.1 www.activexmediapro.com
      127.0.0.1 activexmediapro.com
      127.0.0.1 www.activexmediasite.com
      127.0.0.1 activexmediasite.com
      127.0.0.1 www.activexmediasoftware.com
      127.0.0.1 activexmediasoftware.com
      127.0.0.1 www.activexmediasource.com
      127.0.0.1 activexmediasource.com
      127.0.0.1 www.activexmediatool.com
      127.0.0.1 activexmediatool.com
      127.0.0.1 www.activexmediatour.com
      127.0.0.1 activexmediatour.com
      127.0.0.1 www.activexsoftwares.com
      127.0.0.1 activexsoftwares.com
      127.0.0.1 www.activexsource.com
      127.0.0.1 activexsource.com
      127.0.0.1 www.activexupdate.com
      127.0.0.1 activexupdate.com
      127.0.0.1 www.activexvideo.com
      127.0.0.1 activexvideo.com
      127.0.0.1 www.activexvideotool.com
      127.0.0.1 activexvideotool.com
      127.0.0.1 www.ad.marketingsector.com
      127.0.0.1 ad.marketingsector.com
      127.0.0.1 www.ad.mokead.com
      127.0.0.1 ad.mokead.com
      127.0.0.1 ad.oinadserver.com
      127.0.0.1 ad.outerinfoads.com
      127.0.0.1 www.ad25.com
      127.0.0.1 ad25.com
      127.0.0.1 www.ad45.com
      127.0.0.1 ad45.com
      127.0.0.1 www.ad77.com
      127.0.0.1 ad77.com
      127.0.0.1 www.ad86.com
      127.0.0.1 ad86.com
      127.0.0.1 www.adamsupportgroup.org
      127.0.0.1 adamsupportgroup.org
      127.0.0.1 www.adarmor.com
      127.0.0.1 adarmor.com
      127.0.0.1 www.adasearch.com
      127.0.0.1 adasearch.com
      127.0.0.1 adaware.cc
      127.0.0.1 www.adawarenow.com
      127.0.0.1 adawarenow.com
      127.0.0.1 adchannel.contextplus.net
      127.0.0.1 www.addetect.com
      127.0.0.1 addetect.com
      127.0.0.1 www.add-hhh.info
      127.0.0.1 add-hhh.info
      127.0.0.1 www.addictivetechnologies.com
      127.0.0.1 addictivetechnologies.com
      127.0.0.1 www.addictivetechnologies.net
      127.0.0.1 addictivetechnologies.net
      127.0.0.1 www.addioerrori.com
      127.0.0.1 addioerrori.com
      127.0.0.1 www.add-manager.com
      127.0.0.1 add-manager.com
      127.0.0.1 www.adgate.info
      127.0.0.1 adgate.info
      127.0.0.1 www.adintelligence.net
      127.0.0.1 adintelligence.net
      127.0.0.1 www.adioserrores.com
      127.0.0.1 adioserrores.com
      127.0.0.1 www.adipics.com
      127.0.0.1 adipics.com
      127.0.0.1 www.adlogix.com
      127.0.0.1 adlogix.com
      127.0.0.1 www.admin2cash.biz
      127.0.0.1 admin2cash.biz
      127.0.0.1 adnet-plus.com
      127.0.0.1 www.adnetserver.com
      127.0.0.1 adnetserver.com
      127.0.0.1 adobe-download-now.com
      127.0.0.1 www.adobe-downloads.com
      127.0.0.1 adobe-downloads.com
      127.0.0.1 www.adobe-reader-8.fr
      127.0.0.1 adobe-reader-8.fr
      127.0.0.1 www.adprotect.com
      127.0.0.1 adprotect.com
      127.0.0.1 ads.centralmedia.ws
      127.0.0.1 ads.k8l.info
      127.0.0.1 ads.kmpads.com
      127.0.0.1 ads.kw.revenue.net
      127.0.0.1 ads.marketingsector.com
      127.0.0.1 ads.searchingbooth.com
      127.0.0.1 ads.z-quest.com
      127.0.0.1 ads1.revenue.net
      127.0.0.1 www.ads183.com
      127.0.0.1 ads183.com
      127.0.0.1 www.adscontex.com
      127.0.0.1 adscontex.com
      127.0.0.1 www.adservices1.enhance.com
      127.0.0.1 adservices1.enhance.com
      127.0.0.1 adservs.com
      127.0.0.1 www.adsextend.net
      127.0.0.1 adsextend.net
      127.0.0.1 www.adshttp.com
      127.0.0.1 adshttp.com
      127.0.0.1 www.adsniffer.com
      127.0.0.1 adsniffer.com
      127.0.0.1 www.adsonwww.com
      127.0.0.1 adsonwww.com
      127.0.0.1 www.adspics.com
      127.0.0.1 adspics.com
      127.0.0.1 www.adsrevenue.net
      127.0.0.1 adsrevenue.net
      127.0.0.1 www.adtrak.net
      127.0.0.1 adtrak.net
      127.0.0.1 adtrgt.com
      127.0.0.1 www.adult777search.info
      127.0.0.1 adult777search.info
      127.0.0.1 www.adultan.com
      127.0.0.1 adultan.com
      127.0.0.1 www.adult-engine-search.com
      127.0.0.1 adult-engine-search.com
      127.0.0.1 www.adult-erotic-guide.net
      127.0.0.1 adult-erotic-guide.net
      127.0.0.1 www.adultfilmsite.com
      127.0.0.1 adultfilmsite.com
      127.0.0.1 www.adult-friends-finder.net
      127.0.0.1 adult-friends-finder.net
      127.0.0.1 adultgambling.org
      127.0.0.1 adult-host.org
      127.0.0.1 www.adulthyperlinks.com
      127.0.0.1 adulthyperlinks.com
      127.0.0.1 www.adultmovieplus.com
      127.0.0.1 adultmovieplus.com
      127.0.0.1 www.adult-mpg.net
      127.0.0.1 adult-mpg.net
      127.0.0.1 adult-personal.us
      127.0.0.1 adultsgames.net
      127.0.0.1 www.adultsonlyvids.com
      127.0.0.1 adultsonlyvids.com
      127.0.0.1 www.adultsper.com
      127.0.0.1 adultsper.com
      127.0.0.1 www.adulttds.com
      127.0.0.1 adulttds.com
      127.0.0.1 www.adultzoneworld.com
      127.0.0.1 adultzoneworld.com
      127.0.0.1 www.advancedcleaner.com
      127.0.0.1 advancedcleaner.com
      127.0.0.1 www.advcash.biz
      127.0.0.1 advcash.biz
      127.0.0.1 advert.exaccess.ru
      127.0.0.1 www.advertisemoney.info
      127.0.0.1 advertisemoney.info
      127.0.0.1 advertising.paltalk.com
      127.0.0.1 www.advertising-money.info
      127.0.0.1 advertising-money.info
      127.0.0.1 ad-ware.cc
      127.0.0.1 www.ad-w-a-r-e.com
      127.0.0.1 ad-w-a-r-e.com
      127.0.0.1 www.a-d-w-a-r-e.com
      127.0.0.1 a-d-w-a-r-e.com
      127.0.0.1 www.adware.pro
      127.0.0.1 adware.pro
      127.0.0.1 www.adwarealert.com
      127.0.0.1 adwarealert.com
      127.0.0.1 www.ad-warealert.com
      127.0.0.1 ad-warealert.com
      127.0.0.1 www.adwarearrest.com
      127.0.0.1 adwarearrest.com
      127.0.0.1 www.adwarebazooka.com
      127.0.0.1 adwarebazooka.com
      127.0.0.1 www.adwarecommander.com
      127.0.0.1 adwarecommander.com
      127.0.0.1 www.adwarefinder.com
      127.0.0.1 adwarefinder.com
      127.0.0.1 www.adwaregold.com
      127.0.0.1 adwaregold.com
      127.0.0.1 www.adwarepatrol.com
      127.0.0.1 adwarepatrol.com
      127.0.0.1 www.adwareplatinum.com
      127.0.0.1 adwareplatinum.com
      127.0.0.1 www.adwareprotectionsite.com
      127.0.0.1 adwareprotectionsite.com
      127.0.0.1 www.adwarepunisher.com
      127.0.0.1 adwarepunisher.com
      127.0.0.1 www.adwareremover.ws
      127.0.0.1 adwareremover.ws
      127.0.0.1 www.adwaresafety.com
      127.0.0.1 adwaresafety.com
      127.0.0.1 www.adwarexp.com
      127.0.0.1 adwarexp.com
      127.0.0.1 affiliate.idownload.com
      127.0.0.1 www.aflgate.com
      127.0.0.1 aflgate.com
      127.0.0.1 africaspromise.org
      127.0.0.1 agava.com
      127.0.0.1 agava.ru
      127.0.0.1 agentstudio.com
      127.0.0.1 www.aginegialle.it
      127.0.0.1 aginegialle.it
      127.0.0.1 www.ahnenforschung.de
      127.0.0.1 ahnenforschung.de
      127.0.0.1 aifind.info
      127.0.0.1 www.aifind.info
      127.0.0.1 www.airtleworld.com
      127.0.0.1 airtleworld.com
      127.0.0.1 www.aitalia.it
      127.0.0.1 aitalia.it
      127.0.0.1 akamai.downloadv3.com
      127.0.0.1 www.aklitalia.it
      127.0.0.1 aklitalia.it
      127.0.0.1 akril.com
      127.0.0.1 alcatel.ws
      127.0.0.1 www.alertspy.com
      127.0.0.1 alertspy.com
      127.0.0.1 www.alfacleaner.com
      127.0.0.1 alfacleaner.com
      127.0.0.1 alfa-search.com
      127.0.0.1 www.alialia.it
      127.0.0.1 alialia.it
      127.0.0.1 www.aliotalia.it
      127.0.0.1 aliotalia.it
      127.0.0.1 www.alirtalia.it
      127.0.0.1 alirtalia.it
      127.0.0.1 www.alitaia.it
      127.0.0.1 alitaia.it
      127.0.0.1 www.alitaklia.it
      127.0.0.1 alitaklia.it
      127.0.0.1 www.alitala.it
      127.0.0.1 alitala.it
      127.0.0.1 www.alitali.it
      127.0.0.1 alitali.it
      127.0.0.1 www.alitaliaq.it
      127.0.0.1 alitaliaq.it
      127.0.0.1 www.alitalias.it
      127.0.0.1 alitalias.it
      127.0.0.1 www.alitaliaz.it
      127.0.0.1 alitaliaz.it
      127.0.0.1 www.alitalioa.it
      127.0.0.1 alitalioa.it
      127.0.0.1 www.alitalisa.it
      127.0.0.1 alitalisa.it
      127.0.0.1 www.alitaliua.it
      127.0.0.1 alitaliua.it
      127.0.0.1 www.alitalkia.it
      127.0.0.1 alitalkia.it
      127.0.0.1 www.alitaloia.it
      127.0.0.1 alitaloia.it
      127.0.0.1 www.alitaluia.it
      127.0.0.1 alitaluia.it
      127.0.0.1 www.alitaslia.it
      127.0.0.1 alitaslia.it
      127.0.0.1 www.alitlia.it
      127.0.0.1 alitlia.it
      127.0.0.1 www.alitralia.it
      127.0.0.1 alitralia.it
      127.0.0.1 www.alitsalia.it
      127.0.0.1 alitsalia.it
      127.0.0.1 www.aliutalia.it
      127.0.0.1 aliutalia.it
      127.0.0.1 www.all1count.net
      127.0.0.1 all1count.net
      127.0.0.1 www.all4internet.com
      127.0.0.1 all4internet.com
      127.0.0.1 allabtcars.com
      127.0.0.1 allabtjeeps.com
      127.0.0.1 www.all-bittorrent.com
      127.0.0.1 all-bittorrent.com
      127.0.0.1 www.allcollisions.com
      127.0.0.1 allcollisions.com
      127.0.0.1 allcybersearch.com
      127.0.0.1 www.allcybersearch.com
      127.0.0.1 www.alldnserrors.com
      127.0.0.1 alldnserrors.com
      127.0.0.1 www.all-downloads-now.com
      127.0.0.1 all-downloads-now.com
      127.0.0.1 www.all-edonkey.com
      127.0.0.1 all-edonkey.com
      127.0.0.1 www.allertaminacce.com
      127.0.0.1 allertaminacce.com
      127.0.0.1 allforadult.com
      127.0.0.1 allhyperlinks.com
      127.0.0.1 www.alliesecurity.com
      127.0.0.1 alliesecurity.com
      127.0.0.1 all-inet.com
      127.0.0.1 allinternetbusiness.com
      127.0.0.1 www.all-limewire.com
      127.0.0.1 all-limewire.com
      127.0.0.1 www.allmegabucks.com
      127.0.0.1 allmegabucks.com
      127.0.0.1 www.allprotections.com
      127.0.0.1 allprotections.com
      127.0.0.1 www.allresultz.net
      127.0.0.1 allresultz.net
      127.0.0.1 www.allsearch.us
      127.0.0.1 allsearch.us
      127.0.0.1 www.allsecuritynotes.com
      127.0.0.1 allsecuritynotes.com
      127.0.0.1 www.allsecuritysite.com
      127.0.0.1 allsecuritysite.com
      127.0.0.1 www.allstarsvideos.net
      127.0.0.1 allstarsvideos.net
      127.0.0.1 www.alltiettantivirus.com
      127.0.0.1 alltiettantivirus.com
      127.0.0.1 www.alltruesoftware.com
      127.0.0.1 alltruesoftware.com
      127.0.0.1 www.allvideoactivex.com
      127.0.0.1 allvideoactivex.com
      127.0.0.1 www.almanah.biz
      127.0.0.1 almanah.biz
      127.0.0.1 almarvideos.com
      127.0.0.1 www.aloitalia.it
      127.0.0.1 aloitalia.it
      127.0.0.1 www.aluitalia.it
      127.0.0.1 aluitalia.it
      127.0.0.1 www.amaena.com
      127.0.0.1 amaena.com
      127.0.0.1 amandamountains.com
      127.0.0.1 www.amateurliveshow.com
      127.0.0.1 amateurliveshow.com
      127.0.0.1 www.amediasoftware.com
      127.0.0.1 amediasoftware.com
      127.0.0.1 www.amediasource.com
      127.0.0.1 amediasource.com
      127.0.0.1 www.americanautobargains.com
      127.0.0.1 americanautobargains.com
      127.0.0.1 www.americancarbargains.com
      127.0.0.1 americancarbargains.com
      127.0.0.1 american-teens.net
      127.0.0.1 amigeek.com
      127.0.0.1 www.amigobore.com
      127.0.0.1 amigobore.com
      127.0.0.1 amisbusiness.com
      127.0.0.1 www.ampmsearch.com
      127.0.0.1 ampmsearch.com
      127.0.0.1 www.analcord.com
      127.0.0.1 analcord.com
      127.0.0.1 analmovi.com
      127.0.0.1 www.anarchylolita.com
      127.0.0.1 anarchylolita.com
      127.0.0.1 anarchyporn.com
      127.0.0.1 www.andromedical.com
      0
    2. juju29
       
      Good evening Jacques.gache!
      It is impossible to download CCleaner... but the worst part is that the problem I thought I had resolved last night has come back... namely, when I go to my Hotmail page, the internet page freezes and an error message appears "Internet Explorer has encountered a problem..." everything is blocked!! I can only restart the PC through the "start" menu!
      What should I do?
      Moreover, I ran another scan with Bitdefender online and the infected files cannot be deleted... there is a Gbplugin folder in C: but I cannot delete it!
      Thank you


      BitDefender Online Scanner



      Scan report generated on: Sun, Apr 20, 2008 - 21:10:03





      Scan paths: A:\;C:\;D:\;E:\;F:\;G:\;H:\;I:\;J:\;







      Statistics

      Time
      00:20:10

      Files
      76858

      Directories
      6243

      Boot sectors
      3

      Archives
      806

      Program packages
      7812




      Results

      Identified viruses
      2

      Infected files
      2

      Suspected files
      0

      Warnings
      0

      Disinfected
      0

      Files deleted
      0




      Engine info

      Virus definition
      1167103

      Engine version
      AVCORE v1.0 (build 2422) (i386) (Sep 25 2007 08:26:36)

      Plugin analysis
      16

      Plugin archive
      41

      Plugin unpack
      7

      Email plugins
      6

      System plugins
      5




      Scan settings

      First action
      Disinfect

      Second Action
      Deleted

      Heuristic
      Yes

      Accept warnings
      Yes

      Extensions scanned
      exe;com;dll;ocx;scr;bin;dat;386;vxd;sys;wdm;cla;class;ovl;ole;hlp;doc;dot;xls;ppt;wbk;wiz;pot;ppa;xla;xlt;vbs;vbe;mdb;rtf;htm;hta;html;xml;xtp;php;asp;js;shs;chm;lnk;pif;prc;url;smm;pfd;msi;ini;csc;cmd;bas;

      Exclude extensions


      Email analysis
      Yes

      Archive analysis
      Yes

      Program package scanning
      Yes

      File analysis
      Yes

      Boot analysis
      Yes




      File analyzed
      Status

      C:\Program Files\GbPluggin\gbiehcef.dll
      Infected by: Generic.Banker.Delf.F6C70493

      C:\Program Files\GbPluggin\gbiehcef.dll
      Disinfection failed

      C:\Program Files\GbPluggin\gbiehcef.dll
      Deletion failed

      C:\Program Files\GbPluggin\gbpdist.dll
      Infected by: Trojan.Banker.Delf.YDZ

      C:\Program Files\GbPluggin\gbpdist.dll
      Disinfection failed

      C:\Program Files\GbPluggin\gbpdist.dll
      Deletion failed
      0