Shortcut virus

Closed
madlaminy Posts 3 Registration date Tuesday April 1, 2014 Status Member Last seen April 2, 2014 - Apr 1, 2014 at 10:51 AM
madlaminy Posts 3 Registration date Tuesday April 1, 2014 Status Member Last seen April 2, 2014 - Apr 2, 2014 at 02:44 PM
hi guys , can you please assist me here... my laptop has got a shortcut virus, when ever I create a shortcut it becomes infected and I cant access my other shortcuts. please help, thank you in advance
Related:

3 responses

¡El Desaparecido! Posts 1519 Registration date Tuesday October 4, 2011 Status Member Last seen October 23, 2015 3
Apr 1, 2014 at 10:53 AM
Hello ,

Welcome : )

# Download UsbFix on your computer, and execute it.
# It will launch automatically, and a shortcut will be created on your desktop.
# Connect all your external data sources to your PC (Usb keys, external drives, etc...) Do not open them.
# Choose " Deletion " option.


#The computer wille re-start, and it may be longer than usually.


# UsbFix will display a message at re-start.


# Click "OK" to start cleaning.
# Copy/paste the report here.

Tutorial : http://www.en.usbfix.net/2014/02/usbfix-tutorial-clean-option/
0
madlaminy Posts 3 Registration date Tuesday April 1, 2014 Status Member Last seen April 2, 2014
Apr 2, 2014 at 02:40 PM
############################## | UsbFix V 7.169 | [Deletion]

User: User (Administrator) # USER-PC
Updated 31/03/2014 by El Desaparecido - Team SosVirus
Started at 20:23:29 | 02/04/2014

Website : http://www.en.usbfix.net/
Changelog : http://www.en.usbfix.net/changelog/
Support : https://ccm.net/forum/viruses-security-7
Upload Malware : http://www.sosvirus.net/upload_malware.php
Contact : http://www.en.usbfix.net/contact/

PC: GIGABYTE (Q2006)
CPU: Intel(R) Atom(TM) CPU N2800 @ 1.86GHz
RAM -> [Total : 2009 Mo| Free : 847 Mo]
Bios: Phoenix Technologies Ltd.
Boot: Normal boot

OS: Microsoft Windows 7 Starter (6.1.7601 32-Bit) Service Pack 1
WB: Windows Internet Explorer : 11.0.9600.16521

SC: Security Center [Enabled]
WU: Windows Update [Enabled]
AV: AVG AntiVirus 2014 [Enabled | Updated]
AS: Windows Defender [(!) Disabled | Updated]
AS: AVG AntiVirus 2014 [Enabled | Updated]
FW: Windows FireWall [(!) Disabled]

C:\ (%systemdrive%) -> Fixed drive # 100 Gb (75 Mb free - 75%) [SYSTEM] # NTFS
D:\ -> Fixed drive # 190 Gb (190 Mb free - 100%) [DATA] # NTFS

################## | Active Processes |

C:\PROGRA~1\AVG\AVG2014\avgrsx.exe (ID: 360 |ParentID: 348)
C:\Program Files\AVG\AVG2014\avgcsrvx.exe (ID: 456 |ParentID: 360)
C:\Windows\system32\csrss.exe (ID: 720 |ParentID: 712)
C:\Windows\system32\wininit.exe (ID: 764 |ParentID: 712)
C:\Windows\system32\csrss.exe (ID: 772 |ParentID: 756)
C:\Windows\system32\services.exe (ID: 820 |ParentID: 764)
C:\Windows\system32\lsass.exe (ID: 832 |ParentID: 764)
C:\Windows\system32\lsm.exe (ID: 840 |ParentID: 764)
C:\Windows\system32\svchost.exe (ID: 960 |ParentID: 820)
C:\Windows\system32\winlogon.exe (ID: 1028 |ParentID: 756)
C:\Windows\system32\svchost.exe (ID: 1080 |ParentID: 820)
C:\Windows\System32\svchost.exe (ID: 1152 |ParentID: 820)
C:\Windows\System32\svchost.exe (ID: 1188 |ParentID: 820)
C:\Windows\system32\svchost.exe (ID: 1228 |ParentID: 820)
C:\Windows\system32\svchost.exe (ID: 1260 |ParentID: 820)
C:\Program Files\PC Speed Up\PCSUService.exe (ID: 1444 |ParentID: 820)
C:\Windows\system32\svchost.exe (ID: 1540 |ParentID: 820)
C:\Windows\System32\spoolsv.exe (ID: 1680 |ParentID: 820)
C:\Windows\system32\svchost.exe (ID: 1732 |ParentID: 820)
C:\PROGRA~1\ALLIN1~2\bar\1.bin\8hbarsvc.exe (ID: 1884 |ParentID: 820)
C:\Program Files\AVG\AVG2014\avgidsagent.exe (ID: 1908 |ParentID: 820)
C:\Program Files\AVG\AVG2014\avgwdsvc.exe (ID: 1928 |ParentID: 820)
C:\Program Files\Microsoft\BingBar\7.1.362.0\BBSvc.exe (ID: 1952 |ParentID: 820)
C:\Program Files\REALTEK\Realtek Bluetooth\BTDevMgr.exe (ID: 1988 |ParentID: 820)
C:\Windows\system32\svchost.exe (ID: 2028 |ParentID: 820)
C:\PROGRA~1\MYSCRA~2\bar\1.bin\12barsvc.exe (ID: 120 |ParentID: 820)
C:\Program Files\Hotkey\PowerBiosServer.exe (ID: 680 |ParentID: 820)
C:\Program Files\Microsoft Application Virtualization Client\sftvsa.exe (ID: 2184 |ParentID: 820)
C:\Windows\system32\svchost.exe (ID: 2208 |ParentID: 820)
C:\Windows\system32\viakaraokesrv.exe (ID: 2240 |ParentID: 820)
C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE (ID: 2292 |ParentID: 820)
C:\Program Files\Microsoft Application Virtualization Client\sftlist.exe (ID: 2364 |ParentID: 820)
C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe (ID: 2448 |ParentID: 2292)
C:\Program Files\Vodafone\Vodafone Mobile Connect\Bin\VMCService.exe (ID: 2660 |ParentID: 820)
C:\Windows\system32\wbem\wmiprvse.exe (ID: 2736 |ParentID: 960)
C:\Windows\system32\taskhost.exe (ID: 2852 |ParentID: 820)
C:\Program Files\REALTEK\Realtek Bluetooth\BTServer.exe (ID: 2912 |ParentID: 1988)
C:\Windows\system32\Dwm.exe (ID: 3024 |ParentID: 1188)
C:\Windows\Explorer.EXE (ID: 3040 |ParentID: 3012)
C:\Program Files\AVG\AVG2014\avgnsx.exe (ID: 3220 |ParentID: 1928)
C:\Windows\system32\runonce.exe (ID: 3232 |ParentID: 3040)
C:\Program Files\AVG\AVG2014\avgemcx.exe (ID: 3240 |ParentID: 1928)
C:\Program Files\REALTEK\Realtek Bluetooth\PluginHelper.exe (ID: 3312 |ParentID: 2912)
C:\Windows\system32\wbem\unsecapp.exe (ID: 3420 |ParentID: 960)
C:\Program Files\Common Files\Microsoft Shared\Virtualization Handler\CVHSVC.EXE (ID: 3740 |ParentID: 820)
C:\Windows\system32\svchost.exe (ID: 3888 |ParentID: 820)
C:\Windows\System32\WUDFHost.exe (ID: 4076 |ParentID: 1188)

################## | Generic Research |


(!) Temporary files deleted.

################## | Registry |


################## | Regedit Run |

F2 - HKLM\..\Winlogon : [Shell] explorer.exe
F2 - [x64] HKLM\..\Winlogon : [Shell] explorer.exe
F2 - HKLM\..\Winlogon : [Userinit] C:\Windows\system32\userinit.exe,
F2 - [x64] HKLM\..\Winlogon : [Userinit] C:\Windows\system32\userinit.exe,
04 - HKCU\..\Run : [PCSpeedUp] C:\Program Files\PC Speed Up\PCSUNotifier.exe
04 - HKCU\..\Run : [iLivid] "C:\Users\User\AppData\Local\iLivid\iLivid.exe" -autorun
04 - HKCU\..\Run : [Sidebar] C:\Program Files\Windows Sidebar\sidebar.exe /autoRun
04 - HKLM\..\Run : [IgfxTray] C:\Windows\system32\igfxtray.exe
04 - HKLM\..\Run : [HotKeysCmds] C:\Windows\system32\hkcmd.exe
04 - HKLM\..\Run : [Persistence] C:\Windows\system32\igfxpers.exe
04 - HKLM\..\Run : [GfxServiceInstall] C:\Windows\system32\GfxCUIServiceInstall.vbs
04 - HKLM\..\Run : [fspuip] %ProgramFiles%\FSP\fspuip.exe
04 - HKLM\..\Run : [IAStorIcon] C:\Program Files\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe
04 - HKLM\..\Run : [HDAudDeck] C:\Program Files\VIA\VIAudioi\VDeck\VDeck.exe -r
04 - HKLM\..\Run : [BtServer] "C:\Program Files\REALTEK\Realtek Bluetooth\BTServer.exe"
04 - HKLM\..\Run : [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe"
04 - HKLM\..\Run : [Adobe ARM] "C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
04 - HKLM\..\Run : [RemoteControl10] "C:\Program Files\CyberLink\PowerDVD10\PDVD10Serv.exe"
04 - HKLM\..\Run : [SideBar] %ProgramFiles%\Windows Sidebar\sidebar.exe /autoRun
04 - HKLM\..\Run : [AVG_UI] "C:\Program Files\AVG\AVG2014\avgui.exe" /TRAYONLY
04 - HKLM\..\Run : [MobileConnect] %programfiles%\Vodafone\Vodafone Mobile Connect\Bin\MobileConnect.exe /silent
04 - HKLM\..\Run : [AdobeAAMUpdater-1.0] "C:\Program Files\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe"
04 - HKLM\..\Run : [Adobe Creative Cloud] "C:\Program Files\Adobe\Adobe Creative Cloud\ACC\Creative Cloud.exe" --showwindow=false --onOSstartup=true
04 - HKLM\..\Run : [My Scrap Nook EPM Support] "C:\PROGRA~1\MYSCRA~2\bar\1.bin\12medint.exe" T8EPMSUP.DLL,S
04 - HKLM\..\Run : [My Scrap Nook Home Page Guard 32 bit] "C:\PROGRA~1\MYSCRA~2\bar\1.bin\AppIntegrator.exe"
04 - HKLM\..\Run : [My Scrap Nook Search Scope Monitor] "C:\PROGRA~1\MYSCRA~2\bar\1.bin\12srchmn.exe" /m=2 /w /h
04 - HKLM\..\Run : [MyScrapNook_12 Browser Plugin Loader] C:\PROGRA~1\MYSCRA~2\bar\1.bin\12brmon.exe
04 - HKLM\..\Run : [Mapix Antivirus] C:\Program Files\Mapixsoft\Mapix Antivirus\MapixAV.exe /U %1
04 - HKLM\..\Run : [Allin1Convert EPM Support] "C:\PROGRA~1\ALLIN1~2\bar\1.bin\8hmedint.exe" T8EPMSUP.DLL,S
04 - HKLM\..\Run : [Allin1Convert Home Page Guard 32 bit] "C:\PROGRA~1\ALLIN1~2\bar\1.bin\AppIntegrator.exe"
04 - HKLM\..\Run : [Allin1Convert Search Scope Monitor] "C:\PROGRA~1\ALLIN1~2\bar\1.bin\8hsrchmn.exe" /m=2 /w /h
04 - HKLM\..\Run : [Allin1Convert_8h Browser Plugin Loader] C:\PROGRA~1\ALLIN1~2\bar\1.bin\8hbrmon.exe
04 - HKU\S-1-5-19\..\Run : [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun
04 - HKU\S-1-5-20\..\Run : [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun
04 - HKU\S-1-5-21-2795781179-838482959-200977271-1000\..\Run : [PCSpeedUp] C:\Program Files\PC Speed Up\PCSUNotifier.exe
04 - HKU\S-1-5-21-2795781179-838482959-200977271-1000\..\Run : [iLivid] "C:\Users\User\AppData\Local\iLivid\iLivid.exe" -autorun
04 - HKU\S-1-5-21-2795781179-838482959-200977271-1000\..\Run : [Sidebar] C:\Program Files\Windows Sidebar\sidebar.exe /autoRun
04 - HKU\S-1-5-19\..\RunOnce : [mctadmin] C:\Windows\System32\mctadmin.exe
04 - HKU\S-1-5-20\..\RunOnce : [mctadmin] C:\Windows\System32\mctadmin.exe

################## | Listing |

[26/03/2014 - 10:06:00 | D] - C:\$AVG
[05/02/2013 - 14:24:05 | D] - C:\$Recycle.Bin
[10/06/2009 - 23:42:20 | A | 0 Ko] - C:\autoexec.bat
[17/10/2012 - 04:58:29 | N | 0 Ko] - C:\BTServer.log
[10/06/2009 - 23:42:20 | N | 0 Ko] - C:\config.sys
[02/04/2014 - 19:36:59 | N | 30 Ko | CDAC29B84195310012A83A9B33A29710] - C:\debug1214.txt
[14/07/2009 - 06:53:55 | SHD] - C:\Documents and Settings
[02/04/2014 - 20:22:35 | ASH | 1542804 Ko] - C:\hiberfil.sys
[16/10/2012 - 23:36:13 | D] - C:\Intel
[12/06/2013 - 10:47:13 | RHD] - C:\MSOCache
[17/10/2012 - 00:23:27 | D] - C:\OEMLOGO
[02/04/2014 - 20:22:35 | ASH | 2364272 Ko] - C:\pagefile.sys
[14/07/2009 - 04:37:05 | D] - C:\PerfLogs
[02/04/2014 - 19:59:29 | D] - C:\Program Files
[05/03/2014 - 16:15:30 | D] - C:\ProgramData
[05/02/2013 - 14:23:10 | SHD] - C:\Recovery
[17/10/2012 - 00:38:08 | N | 0 Ko | 477DECE9BED4A440496FC719085755DD] - C:\ShipID.txt
[04/03/2014 - 12:26:02 | D] - C:\Support
[04/04/2013 - 17:02:43 | SHD] - C:\System Volume Information
[02/04/2014 - 20:19:16 | D] - C:\UsbFix
[02/04/2014 - 19:56:04 | N | 16 Ko | 88E34377B7661DD69310DDB2921E254F] - C:\UsbFix [Clean 2] USER-PC.txt
[02/04/2014 - 20:24:55 | A | 9 Ko | 20BEE7AE9A9629F7D96101D3551C1E37] - C:\UsbFix [Clean 4] USER-PC.txt
[05/02/2013 - 14:23:21 | D] - C:\Users
[06/03/2014 - 09:38:31 | D] - C:\Windows
[17/10/2012 - 18:35:15 | D] - D:\$RECYCLE.BIN
[17/10/2012 - 18:33:52 | SHD] - D:\System Volume Information

################## | Vaccin |

D:\Autorun.inf -> Vaccine created by UsbFix (El Desaparecido)

################## | E.O.F | http://www.en.usbfix.net/ - https://www.sosvirus.net/ |
0
madlaminy Posts 3 Registration date Tuesday April 1, 2014 Status Member Last seen April 2, 2014
Apr 2, 2014 at 02:44 PM
hello iEl Desaparecido!

thank you so much for your response, I did all the steps you've given me but my laptop still has that shortcut virus... another thing the USB I got the virus from was not mine so I couldn't scan it I only scanned my laptop.
0