Nuage suspect 4

Hello,

Norton found a heuristic virus on my computer named suspicious cloud 4. After several scans with another antivirus, nothing was found. Should I be worried????

Configuration: Windows 7 / Internet Explorer 8.0

--
Find solutions for my computer and my partner's.

25 answers

  1. ok
    --
    Find solutions for my computer and my partner's.
    1
    1. DISABLE YOUR ANTIVIRUS AND FIREWALL IF PRESENT !!!!! (as it is mistakenly detected as an infection)

      ▶ Download here: List_Kill'em

      and save it on your desktop

      if you have XP => double click
      if you have Vista or Windows 7 => right click "run as...."


      on the shortcut on your desktop to start the installation

      Keep checked:

      ♦ Run List_Kill'em

      once finished, click on "finish" and the program will start automatically

      It will first download and install its updates, then will give you its menu

      choose the Search option

      ▶ let the tool work

      a dialog box may open, in that case click "ok" or "Agree"

      when the white window appears, it may take a little while, that's normal, it's a supplementary search for hidden files, the program is not stuck.

      ▶ Post the content of the report that opens at 100% of the scan on the screen "COMPLETED"

      ▶▶▶ DO NOT POST IT ON THE FORUM

      To send it to me click on this link: http://www.cijoint.fr/

      ▶ Click on Browse and search for the file C:\List'em.txt

      ▶ Click on Open.

      ▶ Click on "Click here to drop the file".

      A link of this form:

      http://www.cijoint.fr/cjlink.php?file=265368/cijSKAP5fU.txt

      is added on the page.

      ▶ Copy this link in your reply.

      ▶ Do the same with more.txt which is on your desktop
      --
      ♦G3и-н@¢ки™©®♦
      1
      1. Hi, is anyone there????
        --
        Looking for solutions for my computer and my partner's.
        0
        1. I did another analysis. Is it normal for Norton to ignore so many files???
          --
          Find solutions for my computer and my partner's.
          0
          1. Analysis stats:
            Duration of analysis: 3913 second(s)
            Analysis options:
            Analysis targets: C:\
            Counts:
            Total number of items analyzed: 564,271
            - Files and directories: 552,749
            - Registry entries: 522
            - Processes and startup items: 8,063
            - Network and browser items: 2,930
            - Other: 4
            - Approved files: 5,443
            - Ignored files: 18,774

            Total number of security risks detected: 86
            Total number of items resolved: 86
            Total number of items to be checked: 0

            Resolved threats:
            86 tracking cookies
            Type: Anomaly
            Risk: Low (Low Stealth, Low Removal, Low Performance, Low Privacy)
            Categories : Cookie
            Status: Completely resolved
            -----------
            86 tracking cookies
            Cookie:xxx@mediaplex.com/ - Deleted
            Cookie:xxx@questionmarket.com/ - Deleted
            Cookie:xxx@atdmt.com/ - Deleted
            Cookie:xxx@doubleclick.net/ - Deleted
            Cookie:xxx@bs.serving-sys.com/ - Deleted
            Cookie:xxx@apmebf.com/ - Deleted
            Cookie:xxx@quantserve.com/ - Deleted
            Cookie:xxx@serving-sys.com/ - Deleted
            .2o7.net - Deleted
            .weborama.fr - Deleted
            .cetelem.solution.weborama.fr - Deleted
            .adtech.de - Deleted
            .doubleclick.net - Deleted
            ad.yieldmanager.com - Deleted
            fl01.ct2.comclick.com - Deleted
            .advertising.com - Deleted
            .bluestreak.com - Deleted
            .apmebf.com - Deleted
            .mediaplex.com - Deleted
            .tradedoubler.com - Deleted
            .content.yieldmanager.com - Deleted
            .smartadserver.com - Deleted
            .bs.serving-sys.com - Deleted
            .serving-sys.com - Deleted
            .xiti.com - Deleted
            .bouyguestelecom.solution.weborama.fr - Deleted
            .atdmt.com - Deleted
            .specificclick.net - Deleted
            .adviva.net - Deleted
            Cookie:xxx@mediaplex.com/ - Deleted
            Cookie:xxx@cetelem.solution.weborama.fr/ - Deleted
            Cookie:xxx@fr.at.atwola.com/ - Deleted
            Cookie:xxx@msnportal.112.2o7.net/ - Deleted
            Cookie:xxx@pixel.rubiconproject.com/ - Deleted
            Cookie:xxx@xiti.com/ - Deleted
            Cookie:xxx@adviva.net/ - Deleted
            Cookie:xxx@bluestreak.com/ - Deleted
            Cookie:xxx@karavel.112.2o7.net/ - Deleted
            Cookie:xxx@estat.com/ - Deleted
            Cookie:xxx@smartadserver.com/ - Deleted
            Cookie:xxx@atdmt.com/ - Deleted
            Cookie:xxx@cnam.solution.weborama.fr/ - Deleted
            Cookie:xxx@adbrite.com/ - Deleted
            Cookie:xxx@revsci.net/ - Deleted
            Cookie:xxx@2o7.net/ - Deleted
            Cookie:xxx@advertstream.com/a - Deleted
            Cookie:xxx@bouyguestelecom.solution.weborama.fr/ - Deleted
            Cookie:xxx@content.yieldmanager.com/ak/ - Deleted
            Cookie:xxx@doubleclick.net/ - Deleted
            Cookie:xxx@bs.serving-sys.com/ - Deleted
            Cookie:xxx@ehg-dig.hitbox.com/ - Deleted
            Cookie:xxx@m.webtrends.com/ - Deleted
            Cookie:xxx@solution.weborama.fr/ - Deleted
            Cookie:xxx@kontera.com/ - Deleted
            Cookie:xxx@overture.com/ - Deleted
            Cookie:xxx@tradedoubler.com/ - Deleted
            Cookie:xxx@fastclick.net/ - Deleted
            Cookie:xxx@aimfar.solution.weborama.fr/ - Deleted
            Cookie:xxx@ttbmanutan.solution.weborama.fr/ - Deleted
            Cookie:xxx@cybermonitor.com/ - Deleted
            Cookie:xxx@fl01.ct2.comclick.com/ - Deleted
            Cookie:xxx@boursoramabanque.solution.weborama.fr/ - Deleted
            Cookie:xxx@247realmedia.com/ - Deleted
            Cookie:xxx@apmebf.com/ - Deleted
            Cookie:xxx@weborama.fr/ - Deleted
            Cookie:xxx@ad.zanox.com/ - Deleted
            Cookie:xxx@specificclick.net/ - Deleted
            Cookie:xxx@statcounter.com/ - Deleted
            Cookie:xxx@ad.yieldmanager.com/ - Deleted
            Cookie:xxx@quantserve.com/ - Deleted
            Cookie:xxx@serving-sys.com/ - Deleted
            Cookie:xxx@microsoftinternetexplorer.112.2o7.net/ - Deleted
            Cookie:xxx@adtech.de/ - Deleted
            Cookie:xxx@content.yieldmanager.com/ - Deleted
            Cookie:xxx@privateoutlet.112.2o7.net/ - Deleted
            Cookie:xxx@intellitxt.com/ - Deleted
            Cookie:xxx@divx.112.2o7.net/ - Deleted
            Cookie:xxx@ttbsagetpepme.solution.weborama.fr/ - Deleted
            Cookie:xxx@interflora2.solution.weborama.fr/ - Deleted
            Cookie:xxx@numericable.solution.weborama.fr/ - Deleted
            Cookie:xxx@bubblestat.com/ - Deleted
            Cookie:xxx@adfarm1.adition.com/ - Deleted
            Cookie:xxx@rubiconproject.com/ - Deleted
            Cookie:xxx@hitbox.com/ - Deleted
            - Deleted
            - Deleted

            Unresolved threats:
            No unresolved risks--
            Find solutions for my computer and my partner's.
            0
            1. Can you do a Norton analysis and submit the report?
              --
              ♦G3и-н@¢ки™©®♦
              0
              1. Yes, because I didn't think to copy ---> paste, nor to save it. I realized it too late.
                I just printed the list.
                So what's the result???
                --
                Find solutions for my computer and my partner's.
                0
                1. The list is really long to write.

                  ??????????????????????????????????????

                  Are you copying everything by hand?????????????????????
                  --
                  ♦G3и-н@¢км@и™©®♦
                  0
                  1. Continuation of the listing
                    31/08/2010 -14:09:17 l SHD ] C:\ $ Reclycle. bin
                    14/07/2009 -03:38.58 l RASH l 383562
                    27/07/2009 -22h40:53 l RASH l 8192] C\:BOOTSECT.BAK
                    14/07/2009 -07:08:56 l SHD ] C:\ Document and Settings
                    21/08/2010 -02:41:32 l DC] c:\element
                    07/11/2007- 08:00:40 A l 17734] C:\eula.1028.txt
                    07/11/2007- 08:00:40 A l 17734] C:\eula.1031.txt
                    07/11/2007- 08:00:40 A l 10134] C:\eula.1033.txt
                    07/11/2007- 08:00:40 A l 17734] C:\eula.1036.txt
                    07/11/2007- 08:00:40 A l 17734] C:\eula.1040.txt
                    07/11/2007- 08:00:40 A l 118] C:\eula.1041.txt
                    07/11/2007- 08:00:40 A l 17734] C:\eula.1042.txt
                    07/11/2007- 08:00:40 A l 17734] C:\eula.2052.txt
                    07/11/2007- 08:00:40 A l 17734] C:\eula.3082.txt
                    07/11/2007- 08:00:40 A l 1110] C:\globdata.ini
                    31/08/2010- 12:56:02 ASH l 3018461184] C:\hiberfil.sys
                    07/11/2007- 08:44:20 A l 855040] C:\ install.exe
                    07/11/2007- 08:44:20 A l 843] C:\ install.ini
                    07/11/2007- 08:44:20 A l 75280] C:\ install.res.1028.dll
                    07/11/2007- 08:44:20 A l 95248] C:\ install.res.1031.dll
                    07/11/2007- 08:44:20 A l 90128] C:\ install.res.1033.dll
                    07/11/2007- 08:44:20 A l 96272] C:\ install.res.1036.dll
                    07/11/2007- 08:44:20 A l 94224] C:\ install.res.1040.dll
                    07/11/2007- 08:44:20 A l 80400] C:\ install.res.1041.dll
                    07/11/2007- 08:44:20 A l 78864] C:\ install.res.1042.dll
                    07/11/2007- 08:44:20 A l 74768] C:\ install.res.2052.dll
                    07/11/2007- 08:44:20 A l 95248] C:\ install.res.3082.dll
                    25/03/2010- 21:45:10 RHD ] C:\MSOCache
                    23/08/2010- 16:57:38 HD ] C:\oem
                    31/08/2010- 12:56:06 ASH l 4024614912] C:\pagefile.sys
                    01/04/2010- 05:51:23 RASH l 1893] C:\Patch.rev
                    14/07/2009- 05:20:08 D ] C:\PerfLogs
                    21/08/2010- 02:35:51 l RASH l 221] C:\Preload.rev
                    30/08/2010- 21:44:30 l RD ] C:\ Program Files
                    30/08/2010- 22:08:17 l RD ] C:\ Program Files (x86)
                    30/08/2010- 21:40:03 l HD ] C:\ ProgramData
                    21/08/2010- 02:35:39 l SHD ]C:\Recovery
                    19/05/2010- 02:18:07 l A l 2142] C:\RHDSetup. log
                    31/08/2010- 13:01:55 l SHD] C:\System Volume Information
                    31/08/2010- 14:09: 17 l D ] C:\ UsbFix
                    31/08/2010- 14:07:36 l A l 3021] C:\ UsbFix.txt
                    23/08/2010- 19:03:2010l RD ] C:\Users
                    07/11/2007- 08:00:40 l A l 5686] C:\vcredist.bmp
                    07/11/2007- 08:50:40 l A l 1927956]C:\VC_RED.cab
                    07/11/2007- 08:53:12 l A l 242176 C:\VC_RED.MSI
                    31/08/2010- 09/29/57 l AD ] C:\ Windows
                    ################### l Vaccine l
                    C:\Autorun.inf-> Folder created by Usbfix (El Desaparecido $ C_xx)
                    ################### l E.O.F l
                    ------------------------------------------------------------------------------
                    So what does this report mean????? Thank you!!!!
                    0
                    1. I am sharing the result; the list is really long to write. Here we go!!!

                      User: xxx
                      Updated on 29/08/2010 by El Desaparecido/ c_xx
                      Website: http:\pagesperso-orange.fr\NosTools\index.htlm
                      Contact: Findykill. contact@gmail.com

                      CPU: ----
                      CUP2:---

                      Microsoft Windows 7 Home Premium Edition
                      Internet Explorer 8 ...

                      Windows Firewall enabled
                      RAM-> 3838 Mo
                      C:\ (%systemdrive%)-> hard drive # 450 Go Free (s)
                      D:\ -> CD-ROM

                      ################### l Infectious Elements l
                      ################### l Registry l
                      ################### l Mountpoints2 l
                      ################### l Listing l
                      0
                      1. make the deletion option with usbfix
                        --
                        ♦G3и-н@¢ки™©®♦
                        0
                        1. Hello,

                          I have tried everything, there’s nothing I can do. I disabled the smart firewall and Norton auto-protect antivirus. Still nothing. I even disabled the Windows Firewall.
                          But it still seems to be protected.
                          I wonder if it's because I'm on Wi-Fi, on my laptop.
                          --
                          Looking for solutions for my computer and my partner's.
                          0
                          1. ok see you tomorrow :)
                            --
                            ♦G3и-н@¢ки™©®♦
                            0
                            1. I will start over tomorrow, then. Have a good evening!!!
                              --
                              Finding solutions for my computer and my partner's.
                              0
                              1. What does my report mean then????
                                --
                                Find solutions for my computer and my partner's.
                                0
                                1. you executed it with the right click "run as ????"
                                  --
                                  ♦G3и-н@¢ки™©®♦
                                  0
                                  1. Yes, I turned everything off
                                    --
                                    Finding solutions for my computer and my partner's.
                                    0
                                    1. Have you disabled Norton as requested?
                                      --
                                      ♦G3и-н@¢км@и™©®♦
                                      0
                                      1. Here is the report.

                                        I don't understand because I disabled my firewall until I restarted my computer.

                                        User: xxx
                                        Updated on 08/29/2010 by El Desaparecido/ c_xx
                                        Website: http:\pagesperso-orange.fr\NosTools\index.htlm
                                        Contact: Findykill. contact@gmail.com

                                        CPU: ----
                                        CUP2:---

                                        Microsoft Windows 7 Home Premium Edition
                                        Internet Explorer 8 ...

                                        Windows Firewall enabled
                                        RAM-> 3838 MB
                                        C:\ (%systemdrive%)-> Hard Drive # 450 GB Free(s)
                                        D:\ -> CD-ROM

                                        ################### l Infectious Elements l
                                        ################### l Registry
                                        ################### l Mountpoints2
                                        ################### l Vaccine
                                        (!) This computer is not vaccinated!
                                        ################### l E.O.F l
                                        --
                                        Find solutions for my computer and my partner's.
                                        0
                                        1. Good evening,

                                          I haven't downloaded USBFIX yet, as I'm waiting for my partner. Norton has quarantined the suspicious cloud files. It detected them since Sunday, August 29 (which is one detection) and 3 detections today, Monday, August 30, 2010.

                                          --
                                          Find solutions for my computer and my partner's.
                                          0
                                          • 1
                                          • 2