Author Topic: [Resolved K] virus in "C:\RECYCLER" "C:\WINDOWS\system32" "C:\WINDOWS"...  (Read 5051 times)

0 Members and 1 Guest are viewing this topic.

Offline saina92

  • Bronze Member
  • Posts: 39
Re: [Resolved K] virus in "C:\RECYCLER" "C:\WINDOWS\system32" "C:\WINDOWS"...
« Reply #45 on: September 24, 2011, 06:21:08 AM »
ESETSmartInstaller@High as downloader log:
all ok
# version=7
# OnlineScannerApp.exe=1.0.0.1
# OnlineScanner.ocx=1.0.0.6528
# api_version=3.0.2
# EOSSerial=9b6d4f9de99f8a4d8fe84c56ca3cdaed
# end=finished
# remove_checked=false
# archives_checked=true
# unwanted_checked=true
# unsafe_checked=false
# antistealth_checked=true
# utc_time=2011-09-24 12:17:12
# local_time=2011-09-24 02:17:12 (+0100, Central Europe Standard Time)
# country="Serbia and Montenegro"
# lang=1033
# osver=5.1.2600 NT Service Pack 3, v.3311
# compatibility_mode=768 16777215 100 0 28955345 28955345 0 0
# compatibility_mode=2304 16777215 100 0 0 0 0 0
# compatibility_mode=8199 39157077 100 100 1625817 23923955 0 0
# scanned=242663
# found=166
# cleaned=0
# scan_time=6033
# nod_component=V3 Build:0x30000000
C:\Qoobox\Quarantine\C\WINDOWS\aadrive32.exe.vir   IRC/SdBot trojan (unable to clean)   00000000000000000000000000000000   I
C:\Qoobox\Quarantine\C\WINDOWS\system32\00.exe.vir   Win32/AutoRun.KS worm (unable to clean)   00000000000000000000000000000000   I
C:\Qoobox\Quarantine\C\WINDOWS\system32\smsc.exe.vir   a variant of Win32/AutoRun.IRCBot.FC worm (unable to clean)   00000000000000000000000000000000   I
C:\System Volume Information\_restore{45C0B463-D268-4C26-ABC2-2A3E39280952}\RP50\A0141556.exe   a variant of Win32/Injector.IUD trojan (unable to clean)   00000000000000000000000000000000   I
C:\System Volume Information\_restore{45C0B463-D268-4C26-ABC2-2A3E39280952}\RP50\A0141578.exe   a variant of Win32/Injector.IWT trojan (unable to clean)   00000000000000000000000000000000   I
C:\System Volume Information\_restore{45C0B463-D268-4C26-ABC2-2A3E39280952}\RP50\A0141619.exe   a variant of Win32/Injector.IXF trojan (unable to clean)   00000000000000000000000000000000   I
C:\System Volume Information\_restore{45C0B463-D268-4C26-ABC2-2A3E39280952}\RP50\A0141620.exe   Win32/Dorkbot.A worm (unable to clean)   00000000000000000000000000000000   I
C:\System Volume Information\_restore{45C0B463-D268-4C26-ABC2-2A3E39280952}\RP50\A0141672.exe   a variant of Win32/Injector.IXF trojan (unable to clean)   00000000000000000000000000000000   I
C:\System Volume Information\_restore{45C0B463-D268-4C26-ABC2-2A3E39280952}\RP50\A0141673.exe   a variant of Win32/Injector.IXF trojan (unable to clean)   00000000000000000000000000000000   I
C:\System Volume Information\_restore{45C0B463-D268-4C26-ABC2-2A3E39280952}\RP50\A0141680.exe   a variant of Win32/Injector.IXS trojan (unable to clean)   00000000000000000000000000000000   I
C:\System Volume Information\_restore{45C0B463-D268-4C26-ABC2-2A3E39280952}\RP50\A0141681.exe   a variant of Win32/Injector.IXS trojan (unable to clean)   00000000000000000000000000000000   I
C:\System Volume Information\_restore{45C0B463-D268-4C26-ABC2-2A3E39280952}\RP50\A0141682.exe   a variant of Win32/Injector.IXS trojan (unable to clean)   00000000000000000000000000000000   I
C:\System Volume Information\_restore{45C0B463-D268-4C26-ABC2-2A3E39280952}\RP50\A0141698.exe   IRC/SdBot trojan (unable to clean)   00000000000000000000000000000000   I
C:\System Volume Information\_restore{45C0B463-D268-4C26-ABC2-2A3E39280952}\RP50\A0141716.exe   Win32/TrojanClicker.VB.NJT trojan (unable to clean)   00000000000000000000000000000000   I
C:\System Volume Information\_restore{45C0B463-D268-4C26-ABC2-2A3E39280952}\RP50\A0141717.exe   Win32/TrojanClicker.VB.NJT trojan (unable to clean)   00000000000000000000000000000000   I
C:\System Volume Information\_restore{45C0B463-D268-4C26-ABC2-2A3E39280952}\RP50\A0141718.exe   a variant of Win32/Injector.IXS trojan (unable to clean)   00000000000000000000000000000000   I
C:\System Volume Information\_restore{45C0B463-D268-4C26-ABC2-2A3E39280952}\RP50\A0141721.exe   Win32/Lethic.AA trojan (unable to clean)   00000000000000000000000000000000   I
C:\System Volume Information\_restore{45C0B463-D268-4C26-ABC2-2A3E39280952}\RP50\A0141849.exe   IRC/SdBot trojan (unable to clean)   00000000000000000000000000000000   I
C:\System Volume Information\_restore{45C0B463-D268-4C26-ABC2-2A3E39280952}\RP50\A0141889.exe   Win32/Dorkbot.A worm (unable to clean)   00000000000000000000000000000000   I
C:\System Volume Information\_restore{45C0B463-D268-4C26-ABC2-2A3E39280952}\RP50\A0141916.exe   Win32/Lethic.AA trojan (unable to clean)   00000000000000000000000000000000   I
C:\System Volume Information\_restore{45C0B463-D268-4C26-ABC2-2A3E39280952}\RP50\A0141937.exe   Win32/Lethic.AA trojan (unable to clean)   00000000000000000000000000000000   I
C:\System Volume Information\_restore{45C0B463-D268-4C26-ABC2-2A3E39280952}\RP50\A0141940.exe   IRC/SdBot trojan (unable to clean)   00000000000000000000000000000000   I
C:\System Volume Information\_restore{45C0B463-D268-4C26-ABC2-2A3E39280952}\RP50\A0141963.exe   Win32/Dorkbot.A worm (unable to clean)   00000000000000000000000000000000   I
C:\System Volume Information\_restore{45C0B463-D268-4C26-ABC2-2A3E39280952}\RP50\A0141978.exe   a variant of Win32/Injector.IXF trojan (unable to clean)   00000000000000000000000000000000   I
C:\System Volume Information\_restore{45C0B463-D268-4C26-ABC2-2A3E39280952}\RP50\A0142992.exe   Win32/Lethic.AA trojan (unable to clean)   00000000000000000000000000000000   I
C:\System Volume Information\_restore{45C0B463-D268-4C26-ABC2-2A3E39280952}\RP50\A0142993.exe   Win32/Lethic.AA trojan (unable to clean)   00000000000000000000000000000000   I
C:\System Volume Information\_restore{45C0B463-D268-4C26-ABC2-2A3E39280952}\RP50\A0144999.exe   a variant of Win32/Injector.IXS trojan (unable to clean)   00000000000000000000000000000000   I
C:\System Volume Information\_restore{45C0B463-D268-4C26-ABC2-2A3E39280952}\RP50\A0145048.exe   Win32/Dorkbot.A worm (unable to clean)   00000000000000000000000000000000   I
C:\System Volume Information\_restore{45C0B463-D268-4C26-ABC2-2A3E39280952}\RP50\A0145119.exe   a variant of Win32/AutoRun.IRCBot.FC worm (unable to clean)   00000000000000000000000000000000   I
C:\System Volume Information\_restore{45C0B463-D268-4C26-ABC2-2A3E39280952}\RP50\A0145135.exe   a variant of Win32/Injector.JAG trojan (unable to clean)   00000000000000000000000000000000   I
C:\System Volume Information\_restore{45C0B463-D268-4C26-ABC2-2A3E39280952}\RP50\A0145215.exe   a variant of Win32/Injector.JAO trojan (unable to clean)   00000000000000000000000000000000   I
C:\System Volume Information\_restore{45C0B463-D268-4C26-ABC2-2A3E39280952}\RP50\A0145455.exe   a variant of Win32/Injector.JEC trojan (unable to clean)   00000000000000000000000000000000   I
C:\System Volume Information\_restore{45C0B463-D268-4C26-ABC2-2A3E39280952}\RP50\A0145464.exe   Win32/Lethic.AA trojan (unable to clean)   00000000000000000000000000000000   I
C:\System Volume Information\_restore{45C0B463-D268-4C26-ABC2-2A3E39280952}\RP50\A0145466.exe   Win32/Lethic.AA trojan (unable to clean)   00000000000000000000000000000000   I
C:\System Volume Information\_restore{45C0B463-D268-4C26-ABC2-2A3E39280952}\RP51\A0146481.exe   a variant of Win32/Injector.JEC trojan (unable to clean)   00000000000000000000000000000000   I
C:\System Volume Information\_restore{45C0B463-D268-4C26-ABC2-2A3E39280952}\RP51\A0146482.exe   Win32/AutoRun.KS worm (unable to clean)   00000000000000000000000000000000   I
C:\System Volume Information\_restore{45C0B463-D268-4C26-ABC2-2A3E39280952}\RP52\A0147557.exe   Win32/AutoRun.KS worm (unable to clean)   00000000000000000000000000000000   I
C:\System Volume Information\_restore{45C0B463-D268-4C26-ABC2-2A3E39280952}\RP52\A0147735.exe   a variant of Win32/Injector.JGG trojan (unable to clean)   00000000000000000000000000000000   I
C:\System Volume Information\_restore{45C0B463-D268-4C26-ABC2-2A3E39280952}\RP52\A0147736.exe   a variant of Win32/Injector.JGG trojan (unable to clean)   00000000000000000000000000000000   I
C:\System Volume Information\_restore{45C0B463-D268-4C26-ABC2-2A3E39280952}\RP52\A0147737.exe   a variant of Win32/Injector.JGG trojan (unable to clean)   00000000000000000000000000000000   I
C:\System Volume Information\_restore{45C0B463-D268-4C26-ABC2-2A3E39280952}\RP52\A0147738.exe   a variant of Win32/Injector.JGG trojan (unable to clean)   00000000000000000000000000000000   I
C:\System Volume Information\_restore{45C0B463-D268-4C26-ABC2-2A3E39280952}\RP52\A0147739.exe   a variant of Win32/Injector.JGG trojan (unable to clean)   00000000000000000000000000000000   I
C:\System Volume Information\_restore{45C0B463-D268-4C26-ABC2-2A3E39280952}\RP52\A0147745.exe   a variant of Win32/Injector.JGG trojan (unable to clean)   00000000000000000000000000000000   I
C:\System Volume Information\_restore{45C0B463-D268-4C26-ABC2-2A3E39280952}\RP52\A0147761.exe   Win32/Lethic.AA trojan (unable to clean)   00000000000000000000000000000000   I
C:\System Volume Information\_restore{45C0B463-D268-4C26-ABC2-2A3E39280952}\RP52\A0147763.exe   a variant of Win32/Injector.JDR trojan (unable to clean)   00000000000000000000000000000000   I
C:\System Volume Information\_restore{45C0B463-D268-4C26-ABC2-2A3E39280952}\RP52\A0147765.exe   a variant of Win32/Injector.JGG trojan (unable to clean)   00000000000000000000000000000000   I
C:\System Volume Information\_restore{45C0B463-D268-4C26-ABC2-2A3E39280952}\RP52\A0147766.exe   a variant of Win32/Injector.JGG trojan (unable to clean)   00000000000000000000000000000000   I
C:\System Volume Information\_restore{45C0B463-D268-4C26-ABC2-2A3E39280952}\RP52\A0147767.exe   a variant of Win32/Injector.JGG trojan (unable to clean)   00000000000000000000000000000000   I
C:\System Volume Information\_restore{45C0B463-D268-4C26-ABC2-2A3E39280952}\RP52\A0147768.exe   IRC/SdBot trojan (unable to clean)   00000000000000000000000000000000   I
C:\System Volume Information\_restore{45C0B463-D268-4C26-ABC2-2A3E39280952}\RP52\A0147790.exe   a variant of Win32/Injector.JGG trojan (unable to clean)   00000000000000000000000000000000   I
C:\System Volume Information\_restore{45C0B463-D268-4C26-ABC2-2A3E39280952}\RP52\A0147804.exe   IRC/SdBot trojan (unable to clean)   00000000000000000000000000000000   I
C:\System Volume Information\_restore{45C0B463-D268-4C26-ABC2-2A3E39280952}\RP52\A0147806.exe   a variant of Win32/Injector.JGG trojan (unable to clean)   00000000000000000000000000000000   I
C:\System Volume Information\_restore{45C0B463-D268-4C26-ABC2-2A3E39280952}\RP52\A0147807.exe   a variant of Win32/Injector.JGG trojan (unable to clean)   00000000000000000000000000000000   I
C:\System Volume Information\_restore{45C0B463-D268-4C26-ABC2-2A3E39280952}\RP52\A0147810.exe   Win32/Lethic.AA trojan (unable to clean)   00000000000000000000000000000000   I
C:\System Volume Information\_restore{45C0B463-D268-4C26-ABC2-2A3E39280952}\RP52\A0147812.exe   a variant of Win32/Injector.JDR trojan (unable to clean)   00000000000000000000000000000000   I
C:\System Volume Information\_restore{45C0B463-D268-4C26-ABC2-2A3E39280952}\RP52\A0147814.exe   a variant of Win32/Injector.JGG trojan (unable to clean)   00000000000000000000000000000000   I
C:\System Volume Information\_restore{45C0B463-D268-4C26-ABC2-2A3E39280952}\RP52\A0147816.exe   IRC/SdBot trojan (unable to clean)   00000000000000000000000000000000   I
C:\System Volume Information\_restore{45C0B463-D268-4C26-ABC2-2A3E39280952}\RP52\A0147817.exe   a variant of Win32/Injector.JGG trojan (unable to clean)   00000000000000000000000000000000   I
C:\System Volume Information\_restore{45C0B463-D268-4C26-ABC2-2A3E39280952}\RP52\A0147819.exe   Win32/Lethic.AA trojan (unable to clean)   00000000000000000000000000000000   I
C:\System Volume Information\_restore{45C0B463-D268-4C26-ABC2-2A3E39280952}\RP52\A0147821.exe   Win32/Lethic.AA trojan (unable to clean)   00000000000000000000000000000000   I
C:\System Volume Information\_restore{45C0B463-D268-4C26-ABC2-2A3E39280952}\RP52\A0148836.exe   a variant of Win32/Injector.JGG trojan (unable to clean)   00000000000000000000000000000000   I
C:\System Volume Information\_restore{45C0B463-D268-4C26-ABC2-2A3E39280952}\RP52\A0148837.exe   a variant of Win32/Injector.JGG trojan (unable to clean)   00000000000000000000000000000000   I
C:\System Volume Information\_restore{45C0B463-D268-4C26-ABC2-2A3E39280952}\RP52\A0148933.exe   a variant of Win32/Injector.JGG trojan (unable to clean)   00000000000000000000000000000000   I
C:\System Volume Information\_restore{45C0B463-D268-4C26-ABC2-2A3E39280952}\RP52\A0148934.exe   a variant of Win32/Injector.JGG trojan (unable to clean)   00000000000000000000000000000000   I
C:\System Volume Information\_restore{45C0B463-D268-4C26-ABC2-2A3E39280952}\RP52\A0148935.exe   a variant of Win32/Injector.JGG trojan (unable to clean)   00000000000000000000000000000000   I
C:\System Volume Information\_restore{45C0B463-D268-4C26-ABC2-2A3E39280952}\RP52\A0148936.exe   a variant of Win32/Injector.JGG trojan (unable to clean)   00000000000000000000000000000000   I
C:\System Volume Information\_restore{45C0B463-D268-4C26-ABC2-2A3E39280952}\RP52\A0148937.exe   a variant of Win32/Injector.JGG trojan (unable to clean)   00000000000000000000000000000000   I
C:\System Volume Information\_restore{45C0B463-D268-4C26-ABC2-2A3E39280952}\RP52\A0148938.exe   a variant of Win32/Injector.JGG trojan (unable to clean)   00000000000000000000000000000000   I
C:\System Volume Information\_restore{45C0B463-D268-4C26-ABC2-2A3E39280952}\RP52\A0148941.exe   a variant of Win32/Injector.JGG trojan (unable to clean)   00000000000000000000000000000000   I
C:\System Volume Information\_restore{45C0B463-D268-4C26-ABC2-2A3E39280952}\RP52\A0148961.exe   a variant of Win32/Injector.JGG trojan (unable to clean)   00000000000000000000000000000000   I
C:\System Volume Information\_restore{45C0B463-D268-4C26-ABC2-2A3E39280952}\RP52\A0148963.exe   a variant of Win32/Injector.JGG trojan (unable to clean)   00000000000000000000000000000000   I
C:\System Volume Information\_restore{45C0B463-D268-4C26-ABC2-2A3E39280952}\RP52\A0148978.exe   a variant of Win32/Injector.JGG trojan (unable to clean)   00000000000000000000000000000000   I
C:\System Volume Information\_restore{45C0B463-D268-4C26-ABC2-2A3E39280952}\RP52\A0148989.exe   probably a variant of Win32/Injector.JDR trojan (unable to clean)   00000000000000000000000000000000   I
C:\System Volume Information\_restore{45C0B463-D268-4C26-ABC2-2A3E39280952}\RP52\A0148991.exe   probably a variant of Win32/Injector.JDR trojan (unable to clean)   00000000000000000000000000000000   I
C:\System Volume Information\_restore{45C0B463-D268-4C26-ABC2-2A3E39280952}\RP52\A0149974.exe   probably a variant of Win32/Injector.JDR trojan (unable to clean)   00000000000000000000000000000000   I
C:\System Volume Information\_restore{45C0B463-D268-4C26-ABC2-2A3E39280952}\RP52\A0149975.exe   a variant of Win32/Injector.JGG trojan (unable to clean)   00000000000000000000000000000000   I
C:\System Volume Information\_restore{45C0B463-D268-4C26-ABC2-2A3E39280952}\RP52\A0149992.exe   probably a variant of Win32/Injector.JDR trojan (unable to clean)   00000000000000000000000000000000   I
C:\System Volume Information\_restore{45C0B463-D268-4C26-ABC2-2A3E39280952}\RP52\A0149994.exe   probably a variant of Win32/Injector.JDR trojan (unable to clean)   00000000000000000000000000000000   I
C:\System Volume Information\_restore{45C0B463-D268-4C26-ABC2-2A3E39280952}\RP52\A0149995.exe   probably a variant of Win32/Injector.JDR trojan (unable to clean)   00000000000000000000000000000000   I
C:\System Volume Information\_restore{45C0B463-D268-4C26-ABC2-2A3E39280952}\RP52\A0149996.exe   a variant of Win32/Injector.JGG trojan (unable to clean)   00000000000000000000000000000000   I
C:\System Volume Information\_restore{45C0B463-D268-4C26-ABC2-2A3E39280952}\RP52\A0149997.exe   a variant of Win32/Injector.JGG trojan (unable to clean)   00000000000000000000000000000000   I
C:\System Volume Information\_restore{45C0B463-D268-4C26-ABC2-2A3E39280952}\RP52\A0150977.exe   a variant of Win32/Injector.JGG trojan (unable to clean)   00000000000000000000000000000000   I
C:\System Volume Information\_restore{45C0B463-D268-4C26-ABC2-2A3E39280952}\RP52\A0151005.exe   probably a variant of Win32/Injector.JDR trojan (unable to clean)   00000000000000000000000000000000   I
C:\System Volume Information\_restore{45C0B463-D268-4C26-ABC2-2A3E39280952}\RP52\A0151007.exe   a variant of Win32/Injector.JGG trojan (unable to clean)   00000000000000000000000000000000   I
C:\System Volume Information\_restore{45C0B463-D268-4C26-ABC2-2A3E39280952}\RP52\A0151010.exe   probably a variant of Win32/Injector.JDR trojan (unable to clean)   00000000000000000000000000000000   I
C:\System Volume Information\_restore{45C0B463-D268-4C26-ABC2-2A3E39280952}\RP52\A0151012.exe   probably a variant of Win32/Injector.JDR trojan (unable to clean)   00000000000000000000000000000000   I
C:\System Volume Information\_restore{45C0B463-D268-4C26-ABC2-2A3E39280952}\RP52\A0151030.exe   a variant of Win32/Injector.JGG trojan (unable to clean)   00000000000000000000000000000000   I
C:\System Volume Information\_restore{45C0B463-D268-4C26-ABC2-2A3E39280952}\RP52\A0151033.exe   a variant of Win32/Injector.JGG trojan (unable to clean)   00000000000000000000000000000000   I
C:\System Volume Information\_restore{45C0B463-D268-4C26-ABC2-2A3E39280952}\RP52\A0151043.exe   probably a variant of Win32/Injector.JDR trojan (unable to clean)   00000000000000000000000000000000   I
C:\System Volume Information\_restore{45C0B463-D268-4C26-ABC2-2A3E39280952}\RP52\A0151044.exe   a variant of Win32/Injector.JGG trojan (unable to clean)   00000000000000000000000000000000   I
C:\System Volume Information\_restore{45C0B463-D268-4C26-ABC2-2A3E39280952}\RP52\A0151046.exe   probably a variant of Win32/Injector.JDR trojan (unable to clean)   00000000000000000000000000000000   I
C:\System Volume Information\_restore{45C0B463-D268-4C26-ABC2-2A3E39280952}\RP52\A0151048.exe   probably a variant of Win32/Injector.JDR trojan (unable to clean)   00000000000000000000000000000000   I
C:\System Volume Information\_restore{45C0B463-D268-4C26-ABC2-2A3E39280952}\RP52\A0151050.exe   a variant of Win32/Injector.JGG trojan (unable to clean)   00000000000000000000000000000000   I
C:\System Volume Information\_restore{45C0B463-D268-4C26-ABC2-2A3E39280952}\RP52\A0151051.exe   a variant of Win32/Injector.JGG trojan (unable to clean)   00000000000000000000000000000000   I
C:\System Volume Information\_restore{45C0B463-D268-4C26-ABC2-2A3E39280952}\RP52\A0151052.exe   a variant of Win32/Injector.JGG trojan (unable to clean)   00000000000000000000000000000000   I
C:\System Volume Information\_restore{45C0B463-D268-4C26-ABC2-2A3E39280952}\RP52\A0151076.exe   a variant of Win32/Injector.JGG trojan (unable to clean)   00000000000000000000000000000000   I
C:\System Volume Information\_restore{45C0B463-D268-4C26-ABC2-2A3E39280952}\RP52\A0151086.exe   a variant of Win32/Injector.JGG trojan (unable to clean)   00000000000000000000000000000000   I
C:\System Volume Information\_restore{45C0B463-D268-4C26-ABC2-2A3E39280952}\RP52\A0151088.exe   probably a variant of Win32/Injector.JDR trojan (unable to clean)   00000000000000000000000000000000   I
C:\System Volume Information\_restore{45C0B463-D268-4C26-ABC2-2A3E39280952}\RP52\A0151090.exe   probably a variant of Win32/Injector.JDR trojan (unable to clean)   00000000000000000000000000000000   I
C:\System Volume Information\_restore{45C0B463-D268-4C26-ABC2-2A3E39280952}\RP52\A0151091.exe   probably a variant of Win32/Injector.JDR trojan (unable to clean)   00000000000000000000000000000000   I
C:\System Volume Information\_restore{45C0B463-D268-4C26-ABC2-2A3E39280952}\RP52\A0151418.exe   IRC/SdBot trojan (unable to clean)   00000000000000000000000000000000   I
C:\System Volume Information\_restore{45C0B463-D268-4C26-ABC2-2A3E39280952}\RP52\A0151420.exe   Win32/AutoRun.AFQ worm (unable to clean)   00000000000000000000000000000000   I
C:\System Volume Information\_restore{45C0B463-D268-4C26-ABC2-2A3E39280952}\RP52\A0151422.exe   Win32/AutoRun.AFQ worm (unable to clean)   00000000000000000000000000000000   I
C:\System Volume Information\_restore{45C0B463-D268-4C26-ABC2-2A3E39280952}\RP52\A0151423.exe   a variant of Win32/Injector.JJN trojan (unable to clean)   00000000000000000000000000000000   I
C:\System Volume Information\_restore{45C0B463-D268-4C26-ABC2-2A3E39280952}\RP52\A0151426.exe   Win32/Lethic.AA trojan (unable to clean)   00000000000000000000000000000000   I
C:\System Volume Information\_restore{45C0B463-D268-4C26-ABC2-2A3E39280952}\RP52\A0151428.exe   Win32/Lethic.AA trojan (unable to clean)   00000000000000000000000000000000   I
C:\System Volume Information\_restore{45C0B463-D268-4C26-ABC2-2A3E39280952}\RP52\A0151431.exe   Win32/AutoRun.AFQ worm (unable to clean)   00000000000000000000000000000000   I
C:\System Volume Information\_restore{45C0B463-D268-4C26-ABC2-2A3E39280952}\RP52\A0151452.exe   IRC/SdBot trojan (unable to clean)   00000000000000000000000000000000   I
C:\System Volume Information\_restore{45C0B463-D268-4C26-ABC2-2A3E39280952}\RP52\A0151454.exe   Win32/Lethic.AA trojan (unable to clean)   00000000000000000000000000000000   I
C:\System Volume Information\_restore{45C0B463-D268-4C26-ABC2-2A3E39280952}\RP52\A0151456.exe   Win32/Lethic.AA trojan (unable to clean)   00000000000000000000000000000000   I
C:\System Volume Information\_restore{45C0B463-D268-4C26-ABC2-2A3E39280952}\RP52\A0151499.exe   a variant of Win32/Injector.JJN trojan (unable to clean)   00000000000000000000000000000000   I
C:\System Volume Information\_restore{45C0B463-D268-4C26-ABC2-2A3E39280952}\RP52\A0151534.exe   Win32/AutoRun.AFQ worm (unable to clean)   00000000000000000000000000000000   I
C:\System Volume Information\_restore{45C0B463-D268-4C26-ABC2-2A3E39280952}\RP52\A0151539.exe   Win32/AutoRun.AFQ worm (unable to clean)   00000000000000000000000000000000   I
C:\System Volume Information\_restore{45C0B463-D268-4C26-ABC2-2A3E39280952}\RP52\A0151582.exe   IRC/SdBot trojan (unable to clean)   00000000000000000000000000000000   I
C:\System Volume Information\_restore{45C0B463-D268-4C26-ABC2-2A3E39280952}\RP52\A0151585.exe   Win32/Lethic.AA trojan (unable to clean)   00000000000000000000000000000000   I
C:\System Volume Information\_restore{45C0B463-D268-4C26-ABC2-2A3E39280952}\RP52\A0152569.exe   a variant of Win32/Injector.JJN trojan (unable to clean)   00000000000000000000000000000000   I
C:\System Volume Information\_restore{45C0B463-D268-4C26-ABC2-2A3E39280952}\RP52\A0152635.exe   Win32/AutoRun.KS worm (unable to clean)   00000000000000000000000000000000   I
C:\System Volume Information\_restore{45C0B463-D268-4C26-ABC2-2A3E39280952}\RP52\A0152636.exe   Win32/AutoRun.KS worm (unable to clean)   00000000000000000000000000000000   I
C:\System Volume Information\_restore{45C0B463-D268-4C26-ABC2-2A3E39280952}\RP52\A0152639.exe   Win32/Lethic.AA trojan (unable to clean)   00000000000000000000000000000000   I
C:\System Volume Information\_restore{45C0B463-D268-4C26-ABC2-2A3E39280952}\RP52\A0152642.exe   Win32/AutoRun.KS worm (unable to clean)   00000000000000000000000000000000   I
C:\System Volume Information\_restore{45C0B463-D268-4C26-ABC2-2A3E39280952}\RP52\A0152658.exe   Win32/Lethic.AA trojan (unable to clean)   00000000000000000000000000000000   I
C:\System Volume Information\_restore{45C0B463-D268-4C26-ABC2-2A3E39280952}\RP52\A0152674.exe   a variant of Win32/Injector.JJN trojan (unable to clean)   00000000000000000000000000000000   I
C:\System Volume Information\_restore{45C0B463-D268-4C26-ABC2-2A3E39280952}\RP52\A0152675.exe   a variant of Win32/Injector.JJN trojan (unable to clean)   00000000000000000000000000000000   I
C:\System Volume Information\_restore{45C0B463-D268-4C26-ABC2-2A3E39280952}\RP52\A0152703.exe   a variant of Win32/Injector.JJN trojan (unable to clean)   00000000000000000000000000000000   I
C:\System Volume Information\_restore{45C0B463-D268-4C26-ABC2-2A3E39280952}\RP52\A0152714.exe   a variant of Win32/Injector.JJN trojan (unable to clean)   00000000000000000000000000000000   I
C:\System Volume Information\_restore{45C0B463-D268-4C26-ABC2-2A3E39280952}\RP52\A0152715.exe   Win32/AutoRun.KS worm (unable to clean)   00000000000000000000000000000000   I
C:\System Volume Information\_restore{45C0B463-D268-4C26-ABC2-2A3E39280952}\RP52\A0152831.exe   Win32/AutoRun.KS worm (unable to clean)   00000000000000000000000000000000   I
C:\System Volume Information\_restore{45C0B463-D268-4C26-ABC2-2A3E39280952}\RP52\A0152908.exe   a variant of Win32/Injector.JJN trojan (unable to clean)   00000000000000000000000000000000   I
C:\System Volume Information\_restore{45C0B463-D268-4C26-ABC2-2A3E39280952}\RP52\A0152928.exe   IRC/SdBot trojan (unable to clean)   00000000000000000000000000000000   I
C:\System Volume Information\_restore{45C0B463-D268-4C26-ABC2-2A3E39280952}\RP52\A0152929.exe   Win32/AutoRun.KS worm (unable to clean)   00000000000000000000000000000000   I
C:\System Volume Information\_restore{45C0B463-D268-4C26-ABC2-2A3E39280952}\RP52\A0152930.exe   Win32/AutoRun.KS worm (unable to clean)   00000000000000000000000000000000   I
C:\System Volume Information\_restore{45C0B463-D268-4C26-ABC2-2A3E39280952}\RP52\A0152932.exe   Win32/Lethic.AA trojan (unable to clean)   00000000000000000000000000000000   I
C:\System Volume Information\_restore{45C0B463-D268-4C26-ABC2-2A3E39280952}\RP52\A0152934.exe   Win32/Lethic.AA trojan (unable to clean)   00000000000000000000000000000000   I
C:\System Volume Information\_restore{45C0B463-D268-4C26-ABC2-2A3E39280952}\RP52\A0153929.exe   Win32/AutoRun.KS worm (unable to clean)   00000000000000000000000000000000   I
C:\System Volume Information\_restore{45C0B463-D268-4C26-ABC2-2A3E39280952}\RP52\A0153932.exe   Win32/AutoRun.KS worm (unable to clean)   00000000000000000000000000000000   I
C:\System Volume Information\_restore{45C0B463-D268-4C26-ABC2-2A3E39280952}\RP52\A0153933.exe   a variant of Win32/Injector.JJN trojan (unable to clean)   00000000000000000000000000000000   I
C:\System Volume Information\_restore{45C0B463-D268-4C26-ABC2-2A3E39280952}\RP52\A0153934.exe   Win32/AutoRun.KS worm (unable to clean)   00000000000000000000000000000000   I
C:\System Volume Information\_restore{45C0B463-D268-4C26-ABC2-2A3E39280952}\RP52\A0153935.exe   a variant of Win32/Injector.JJN trojan (unable to clean)   00000000000000000000000000000000   I
C:\System Volume Information\_restore{45C0B463-D268-4C26-ABC2-2A3E39280952}\RP52\A0153936.exe   IRC/SdBot trojan (unable to clean)   00000000000000000000000000000000   I
C:\System Volume Information\_restore{45C0B463-D268-4C26-ABC2-2A3E39280952}\RP52\A0153938.exe   Win32/Lethic.AA trojan (unable to clean)   00000000000000000000000000000000   I
C:\System Volume Information\_restore{45C0B463-D268-4C26-ABC2-2A3E39280952}\RP52\A0153940.exe   Win32/Lethic.AA trojan (unable to clean)   00000000000000000000000000000000   I
C:\System Volume Information\_restore{45C0B463-D268-4C26-ABC2-2A3E39280952}\RP52\A0153942.exe   Win32/AutoRun.KS worm (unable to clean)   00000000000000000000000000000000   I
C:\System Volume Information\_restore{45C0B463-D268-4C26-ABC2-2A3E39280952}\RP52\A0153959.exe   a variant of Win32/Injector.JJN trojan (unable to clean)   00000000000000000000000000000000   I
C:\System Volume Information\_restore{45C0B463-D268-4C26-ABC2-2A3E39280952}\RP52\A0153961.exe   Win32/AutoRun.KS worm (unable to clean)   00000000000000000000000000000000   I
C:\System Volume Information\_restore{45C0B463-D268-4C26-ABC2-2A3E39280952}\RP52\A0153979.exe   Win32/AutoRun.KS worm (unable to clean)   00000000000000000000000000000000   I
C:\System Volume Information\_restore{45C0B463-D268-4C26-ABC2-2A3E39280952}\RP52\A0153993.exe   a variant of Win32/Injector.JJN trojan (unable to clean)   00000000000000000000000000000000   I
C:\System Volume Information\_restore{45C0B463-D268-4C26-ABC2-2A3E39280952}\RP52\A0153999.exe   Win32/AutoRun.KS worm (unable to clean)   00000000000000000000000000000000   I
C:\System Volume Information\_restore{45C0B463-D268-4C26-ABC2-2A3E39280952}\RP52\A0154000.exe   Win32/AutoRun.KS worm (unable to clean)   00000000000000000000000000000000   I
C:\System Volume Information\_restore{45C0B463-D268-4C26-ABC2-2A3E39280952}\RP52\A0154004.exe   Win32/AutoRun.KS worm (unable to clean)   00000000000000000000000000000000   I
C:\System Volume Information\_restore{45C0B463-D268-4C26-ABC2-2A3E39280952}\RP52\A0154057.exe   IRC/SdBot trojan (unable to clean)   00000000000000000000000000000000   I
C:\System Volume Information\_restore{45C0B463-D268-4C26-ABC2-2A3E39280952}\RP52\A0154060.exe   Win32/Lethic.AA trojan (unable to clean)   00000000000000000000000000000000   I
C:\System Volume Information\_restore{45C0B463-D268-4C26-ABC2-2A3E39280952}\RP52\A0154062.exe   Win32/Lethic.AA trojan (unable to clean)   00000000000000000000000000000000   I
C:\System Volume Information\_restore{45C0B463-D268-4C26-ABC2-2A3E39280952}\RP53\A0154250.exe   a variant of Win32/Injector.JJN trojan (unable to clean)   00000000000000000000000000000000   I
C:\System Volume Information\_restore{45C0B463-D268-4C26-ABC2-2A3E39280952}\RP53\A0154401.exe   Win32/AutoRun.KS worm (unable to clean)   00000000000000000000000000000000   I
C:\System Volume Information\_restore{45C0B463-D268-4C26-ABC2-2A3E39280952}\RP53\A0154403.exe   Win32/AutoRun.KS worm (unable to clean)   00000000000000000000000000000000   I
C:\System Volume Information\_restore{45C0B463-D268-4C26-ABC2-2A3E39280952}\RP53\A0155283.exe   Win32/Virut.AV virus (unable to clean)   00000000000000000000000000000000   I
C:\System Volume Information\_restore{45C0B463-D268-4C26-ABC2-2A3E39280952}\RP53\A0155287.exe   IRC/SdBot trojan (unable to clean)   00000000000000000000000000000000   I
C:\System Volume Information\_restore{45C0B463-D268-4C26-ABC2-2A3E39280952}\RP53\A0155288.exe   Win32/AutoRun.KS worm (unable to clean)   00000000000000000000000000000000   I
C:\System Volume Information\_restore{45C0B463-D268-4C26-ABC2-2A3E39280952}\RP53\A0155290.exe   Win32/Lethic.AA trojan (unable to clean)   00000000000000000000000000000000   I
C:\System Volume Information\_restore{45C0B463-D268-4C26-ABC2-2A3E39280952}\RP53\A0155292.exe   Win32/Lethic.AA trojan (unable to clean)   00000000000000000000000000000000   I
C:\System Volume Information\_restore{45C0B463-D268-4C26-ABC2-2A3E39280952}\RP56\A0155806.exe   Win32/Lethic.AA trojan (unable to clean)   00000000000000000000000000000000   I
C:\System Volume Information\_restore{45C0B463-D268-4C26-ABC2-2A3E39280952}\RP56\A0155808.exe   Win32/Lethic.AA trojan (unable to clean)   00000000000000000000000000000000   I
C:\System Volume Information\_restore{45C0B463-D268-4C26-ABC2-2A3E39280952}\RP57\A0155948.exe   Win32/Lethic.AA trojan (unable to clean)   00000000000000000000000000000000   I
C:\System Volume Information\_restore{45C0B463-D268-4C26-ABC2-2A3E39280952}\RP57\A0155951.exe   Win32/Lethic.AA trojan (unable to clean)   00000000000000000000000000000000   I
C:\System Volume Information\_restore{45C0B463-D268-4C26-ABC2-2A3E39280952}\RP57\A0155953.exe   Win32/Lethic.AA trojan (unable to clean)   00000000000000000000000000000000   I
C:\System Volume Information\_restore{45C0B463-D268-4C26-ABC2-2A3E39280952}\RP57\A0155980.exe   a variant of Win32/Injector.JJN trojan (unable to clean)   00000000000000000000000000000000   I

Offline kevinf80

  • Malware Removal Staff
  • Diamond Member
  • Posts: 6345
Re: [Resolved K] virus in "C:\RECYCLER" "C:\WINDOWS\system32" "C:\WINDOWS"...
« Reply #46 on: September 24, 2011, 04:49:32 PM »
Hiya saina92,

Apologies for the late reply, continue as follows please :-

Step 1

Please download OTM by OldTimer.
Alternative Mirror 1
Alternative Mirror 2 
Save it to your desktop.
Double click OTM.exe to start the tool. Vista or Windows 7 users right click and select Run as Administrator
  • Copy the text between the dotted lines below to the clipboard by highlighting ALL of them and pressing CTRL + C (or, after highlighting, right-click and choose Copy):

    -------------------------------------------------------------------

    :Reg
    [-HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Microsoft Driver Setup]
    [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
    "6887:UDP"=-
    "57590:TCP"=-
    :Files
    netsh firewall reset /c
    ipconfig /flushdns /c
    c:\windows\aadrive32.exe
    c:\documents and settings\Miloš\Local Settings\Application Data\PackageAware

    :Commands
    [ClearAllRestorePoints]
    [EmptyFlash]
    [EmptyTemp]
    [Reboot]
     

    ---------------------------------------------------------------------

  • Return to OTMoveIt3, right click in the "Paste Instructions for Items to be Moved" window (under the yellow bar) and choose Paste.
  • Click the red button.
  • Copy everything in the Results window (under the green bar) to the clipboard by highlighting ALL of them and pressing CTRL + C (or, after highlighting, right-click and choose copy), and paste it in your next reply.
  • Close OTM
Note: If a file or folder cannot be moved immediately you may be asked to reboot the machine to finish the move process. If you are asked to reboot the machine choose Yes.

If the machine reboots, the Results log can be found here:

c:\_OTMoveIt\MovedFiles\mmddyyyy_hhmmss.log

Where mmddyyyy_hhmmss is the date of the tool run.

Step 2

Re-run Malwarebytes, make sure to check for updates then carry out a Quick scan, kill anything it finds..

Let me see those two logs in your next reply, also give update on current issues/concerns..

Kevin

Offline saina92

  • Bronze Member
  • Posts: 39
Re: [Resolved K] virus in "C:\RECYCLER" "C:\WINDOWS\system32" "C:\WINDOWS"...
« Reply #47 on: September 25, 2011, 06:20:16 AM »
heres the 1st log

All processes killed
========== REGISTRY ==========
Registry key HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Microsoft Driver Setup\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List not found.
Registry key HKEY_LOCAL_MACHINE\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List not found.
========== FILES ==========
< netsh firewall reset /c >
Ok.
C:\Documents and Settings\All Users\Desktop\cmd.bat deleted successfully.
C:\Documents and Settings\All Users\Desktop\cmd.txt deleted successfully.
< ipconfig /flushdns /c >
Windows IP Configuration
Successfully flushed the DNS Resolver Cache.
C:\Documents and Settings\All Users\Desktop\cmd.bat deleted successfully.
C:\Documents and Settings\All Users\Desktop\cmd.txt deleted successfully.
File/Folder c:\windows\aadrive32.exe not found.
c:\documents and settings\Miloš\Local Settings\Application Data\PackageAware folder moved successfully.
========== COMMANDS ==========
 
Restore points cleared and new OTM Restore Point set!
 
[EMPTYTEMP]
 
User: Administrator
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 67 bytes
->Flash cache emptied: 41044 bytes
 
User: All Users
 
User: Default User
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 33170 bytes
->Flash cache emptied: 41044 bytes
 
User: LocalService
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 32902 bytes
 
User: Milosaves
 
User: Miloç
->Temporary Internet Files folder emptied: 180626 bytes
->Google Chrome cache emptied: 6405262 bytes
 
User: Miloš
->Temp folder emptied: 717025 bytes
->Temporary Internet Files folder emptied: 117556 bytes
->Java cache emptied: 0 bytes
->FireFox cache emptied: 44080500 bytes
->Google Chrome cache emptied: 227247898 bytes
->Flash cache emptied: 42615 bytes
 
User: NetworkService
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 67 bytes
 
%systemdrive% .tmp files removed: 0 bytes
%systemroot% .tmp files removed: 2396859 bytes
%systemroot%\System32 .tmp files removed: 20912 bytes
%systemroot%\System32\dllcache .tmp files removed: 0 bytes
%systemroot%\System32\drivers .tmp files removed: 0 bytes
Windows Temp folder emptied: 46540 bytes
%systemroot%\system32\config\systemprofile\Local Settings\Temp folder emptied: 0 bytes
%systemroot%\system32\config\systemprofile\Local Settings\Temporary Internet Files folder emptied: 2180432 bytes
RecycleBin emptied: 0 bytes
 
Total Files Cleaned = 270,00 mb
 
 
OTM by OldTimer - Version 3.1.18.0 log created on 09252011_141559

Files moved on Reboot...
File C:\WINDOWS\temp\Perflib_Perfdata_728.dat not found!
C:\WINDOWS\temp\Perflib_Perfdata_c24.dat moved successfully.

Registry entries deleted on Reboot...

Offline saina92

  • Bronze Member
  • Posts: 39
Re: [Resolved K] virus in "C:\RECYCLER" "C:\WINDOWS\system32" "C:\WINDOWS"...
« Reply #48 on: September 25, 2011, 06:33:04 AM »
i got no concerns whatsoever,i believe in u fixing my pc...about issues ill let u know as soon as 1 pops up:) and np about slow responses as we'r in totaly different time zones

Offline saina92

  • Bronze Member
  • Posts: 39
Re: [Resolved K] virus in "C:\RECYCLER" "C:\WINDOWS\system32" "C:\WINDOWS"...
« Reply #49 on: September 25, 2011, 06:47:46 AM »
heres the Mbam log

Offline saina92

  • Bronze Member
  • Posts: 39
Re: [Resolved K] virus in "C:\RECYCLER" "C:\WINDOWS\system32" "C:\WINDOWS"...
« Reply #50 on: September 25, 2011, 06:50:29 AM »
Malwarebytes' Anti-Malware 1.51.2.1300
www.malwarebytes.org

Database version: 7795

Windows 5.1.2600 Service Pack 3, v.3311
Internet Explorer 7.0.5730.13

25.9.2011 14:45:46
mbam-log-2011-09-25 (14-45-46).txt

Scan type: Quick scan
Objects scanned: 197813
Time elapsed: 24 minute(s), 46 second(s)

Memory Processes Infected: 0
Memory Modules Infected: 0
Registry Keys Infected: 0
Registry Values Infected: 0
Registry Data Items Infected: 0
Folders Infected: 0
Files Infected: 0

Memory Processes Infected:
(No malicious items detected)

Memory Modules Infected:
(No malicious items detected)

Registry Keys Infected:
(No malicious items detected)

Registry Values Infected:
(No malicious items detected)

Registry Data Items Infected:
(No malicious items detected)

Folders Infected:
(No malicious items detected)

Files Infected:
(No malicious items detected)

Offline kevinf80

  • Malware Removal Staff
  • Diamond Member
  • Posts: 6345
Re: [Resolved K] virus in "C:\RECYCLER" "C:\WINDOWS\system32" "C:\WINDOWS"...
« Reply #51 on: September 25, 2011, 08:22:45 AM »
Ok continue as follows :-

Step 1

Remove Combofix now that we're done with it
  • Please press the Windows Key and R on your keyboard. This will bring up the Run... command.
  • Now type in Combofix /Uninstall in the runbox and click OK. (Notice the space between the "x" and "/")


  • Please follow the prompts to uninstall Combofix.
  • You will then recieve a message saying Combofix was uninstalled successfully once it's done uninstalling itself.
The above procedure will delete the following:
  • ComboFix and its associated files and folders.
  • VundoFix backups, if present
  • The C:_OtMoveIt folder, if present
  • Reset the clock settings.
  • Hide file extensions, if required.
  • Hide System/Hidden files, if required.
  • Reset System Restore.

It is very important that you get a successful uninstall because of the extra functions done at the same time, let me know if this does not happen.

Step 2[/b

  • Download OTC by OldTimer and save it to your desktop. Alternative mirror
  • Double click icon to start the program.
    If you are using Vista or Windows 7, please right-click and choose run as administrator
  • Then Click the big button.
  • You will get a prompt saying "Begining Cleanup Process". Please select Yes.
  • Restart your computer when prompted.
  • This will remove tools we have used and itself. Any tools/logs remaining on the Desktop can be deleted.
Step 3

We need to remove ESET Online Scanner.

  • Click Start, click Run, type control appwiz.cpl in the Open box, and then press ENTER.
  • Click to select ESET Online Scanner from the application list, and then click Remove. Only re-boot if prompted
Step 4

To re-enable your Emulation drivers, double click DeFogger to run the tool.
  • The application window will appear
  • Click the Re-enable button to re-enable your CD Emulation drivers
  • Click Yes to continue
  • A 'Finished!' message will appear
  • Click OK
  • DeFogger will now ask to reboot the machine - click OK
IMPORTANT! If you receive an error message while running DeFogger, please post the log defogger_enable which will appear on your desktop.
Your Emulation drivers are now re-enabled.

Step 5[/b

You will have several programs installed, these maybe outdated and vulnerable to exploits also. To be certain, please run the free online scan by Secunia, available Here   Before clicking the Start scan  button, please check the box for the option Enable thorough system inspection. Just below the "Scan Options:" section, you'll see the status of what's currently processing....
...when the scan completes, the message "Detection completed successfully" will appear in the Programs/Result section. For each problem detected, Secunia will offer a "Solution" option. Please follow those instructions to download updated versions of the programs as recommended by Secunia.

Let me know if the above steps complete OK, also tell me if you have any remaining issues or concerns..

Kevin :t

Offline saina92

  • Bronze Member
  • Posts: 39
Re: [Resolved K] virus in "C:\RECYCLER" "C:\WINDOWS\system32" "C:\WINDOWS"...
« Reply #52 on: September 25, 2011, 09:04:03 AM »
1st 4 steps went smooth...im having problems understanding the last one...this part "Before clicking the Start scan  button, please check the box for the option Enable thorough system inspection."

Offline saina92

  • Bronze Member
  • Posts: 39
Re: [Resolved K] virus in "C:\RECYCLER" "C:\WINDOWS\system32" "C:\WINDOWS"...
« Reply #53 on: September 25, 2011, 09:16:54 AM »
it says..there might b a problem loading Java applet in your browser...press ok to continue anyway

Offline kevinf80

  • Malware Removal Staff
  • Diamond Member
  • Posts: 6345
Re: [Resolved K] virus in "C:\RECYCLER" "C:\WINDOWS\system32" "C:\WINDOWS"...
« Reply #54 on: September 25, 2011, 09:30:49 AM »
OK, leave Secunia if you are having issues with it. Do the following:

Go Here and get the FileHippo update checker, install and run the program. This will check your software for updates and give suitable links...

Kevin :t

Offline saina92

  • Bronze Member
  • Posts: 39
Re: [Resolved K] virus in "C:\RECYCLER" "C:\WINDOWS\system32" "C:\WINDOWS"...
« Reply #55 on: September 25, 2011, 09:58:09 AM »
i dont rly see any important updates there...but ill still install some....got another question..if my pc is clean now...can i download league of legends again...as i can guarantee its 100% safe as its one of the most popular games atm?  :(1

Offline kevinf80

  • Malware Removal Staff
  • Diamond Member
  • Posts: 6345
Re: [Resolved K] virus in "C:\RECYCLER" "C:\WINDOWS\system32" "C:\WINDOWS"...
« Reply #56 on: September 25, 2011, 10:07:15 AM »
This is your decision to make, it is your PC you can do as you wish. If you have no remaining issues are you ok for me to close out?

This is my standard closure speech, have a read:

Your latest logs are clean and you say that your system is running well, it would be an excellent idea to keep it that way. The following advice will go along way to keeping you secure so that you can enjoy safe and happy surfing.

Here are some tips to reduce the potential for malware infection in the future; I strongly recommend  that you read them and take them to heart so that you don't have to endure the process of cleaning your computer again.

Make proper use of your antivirus and firewall

Antivirus and Firewall programs are integral to your computer security. However, just having them installed isn't enough. The definitions of these programs are frequently updated to detect the latest malware, if you don't keep up with these updates then you'll be vulnerable to infection. Many antivirus and firewall programs have automatic update features, make use of those if you can. If your program doesn't, then get in the habit of routinely performing manual updates, because it's important.

You should keep your antivirus and firewall guard enabled at all times, NEVER turn them off unless there's a specific reason to do so. Also, regularly performing a full system scan with your antivirus program is a good idea to make sure you're system remains clean. Once a week should be adequate. You can set the scan to run during a time when you don't plan to use the computer and just leave it to complete on its own.

Install and use WinPatrol  This will inform you of any attempted unauthorized changes to your system.

WinPatrol features explained Here

Use a safer web browser

Internet Explorer is not the most secure tool for browsing the web. It has been known to be very susceptible to infection, and there are a few good free alternatives:
 
Firefox,

Opera, and

Chrome.
 
All of these are excellent faster, safer, more powerful and functional free alternatives to Internet Explorer. It's definitely worth the short period of adjustment to start using one of these. If you wish to continue using Internet Explorer, it would be a good idea to follow the tutorial HERE which will help you to make IE MUCH safer.

These browser add-ons will help to make your browser safer:

Web of Trust warns you about risky websites that try to scam visitors, deliver malware or send spam. WOT's color-coded icons show you ratings for 21 million websites, helping you avoid the dangerous ones:

Available for Firefox and Internet Explorer.

Green to go,
Yellow for caution, and
Red to stop.


Available for Firefox only. NoScript helps to block malicious scripts and in general gives you much better control over what types of things webpages can do to your computer while you're browsing.

These are just a couple of the most popular add-ons, if you're interested in more, take a look at THIS article.

Here a couple of links by two security experts that will give some excellent tips and advice.

So how did I get infected in the first place by Tony Klein

How to prevent Malware by Miekiemoes

Finally this link HERE will give a comprehensive upto date list of free Security programs. To include - Antivirus, Antispyware, Firewall, Antimalware, Online scanners and rescue CD`s.

Don`t forget, the best form of defense is common sense. If you don`t recognize it, don`t open it. If something looks to good to be true, then it aint.

If no remaining issues are you OK for me to close out your thread?

Take care,

Kevin  :t

Offline saina92

  • Bronze Member
  • Posts: 39
Re: [Resolved K] virus in "C:\RECYCLER" "C:\WINDOWS\system32" "C:\WINDOWS"...
« Reply #57 on: September 25, 2011, 10:10:56 AM »
tnx a lot...ur like a cyber superhero of some sort :LOL ur doing a awsome thing by helping a lot of ppl....yh close it,once againt thank u :b

Offline kevinf80

  • Malware Removal Staff
  • Diamond Member
  • Posts: 6345
Re: [Resolved K] virus in "C:\RECYCLER" "C:\WINDOWS\system32" "C:\WINDOWS"...
« Reply #58 on: September 25, 2011, 10:17:05 AM »
Since this issue appears to be resolved the topic has been closed. Glad we could help. :t 

If you're the topic starter, and need this topic reopened, please contact a staff member with the address of the thread.

Everyone else please begin a New Topic.

The fixes and advice in this thread are for this System only. Do not apply the instructions from this thread to your own System. Please start a new thread describing your issue and someone will be along to assist you.