Avast WEBforum

Other => Viruses and worms => Topic started by: frankocean89 on October 08, 2013, 03:22:07 PM

Title: These Trojan Horse Twins called 80000032.@ and 80000064.@ are destrying my life
Post by: frankocean89 on October 08, 2013, 03:22:07 PM
At 12:24 today, I downloaded a file without knowing it was a Trojan horse.
 Now Avast keeps reminding me every few minutes that a threat has been detected and SUCCESSFULLY BEEN DEALT WITH when it has not.
[I have attached the pics, I hope they are showing(]

Yet despite the fact that I have gone to the file location, scanned it with Avast and deleted the threats SEVERAL TIMES, they are not going anywhere. Avast says they have been deleted but few minutes later the same message about threats being detected pops up.
I have tried to download malwarebytes from Cnet.com to remove them but since they have infected my laptop, I CANT DOWNLOAD ANYTHING NOT EVEN A PICTURE OFF THE INTERNET and my laptop has been slowing down. I am extremely upset and feel upset right now and fear for my laptop, my files  :'(

Please help me
Title: Re: These Trojan Horse Twins called 80000032.@ and 80000064.@ are destrying my life
Post by: magna86 on October 08, 2013, 03:28:01 PM
Hi,

We need to check that first.
---------------------------------------------------------------------------------------------

Please download Farbar Recovery Scan Tool (http://www.bleepingcomputer.com/download/farbar-recovery-scan-tool/) and save it to your desktop.

Note: You need to run the version compatibale with your system. If you are not sure which version applies to your system download both of them and try to run them.
Only one of them will run on your system, that will be the right version.


Title: Re: These Trojan Horse Twins called 80000032.@ and 80000064.@ are destrying my life
Post by: Eddy on October 08, 2013, 03:31:42 PM
Perform a bootscan with avast then do as Magna suggested.
Title: Re: These Trojan Horse Twins called 80000032.@ and 80000064.@ are destrying my life
Post by: magna86 on October 08, 2013, 03:36:12 PM
Perform a bootscan with avast then do as Magna suggested.
Hi Eddy,  :)
This type of malware uses embedded nulls and permissions are broken on malware related keys (malware's loading point), malware also has two loading point (one as backup launcher)  therefore AV can not target ZA loading points.
As ZA uses uses embedded to hide full path of loading files, you can't aim these file like that. Avast boot time scan is a good thing for post cleaning or in case of some other lightware infections, but in ZA cases, it is waste of time.  ;)
Title: Re: These Trojan Horse Twins called 80000032.@ and 80000064.@ are destrying my life
Post by: frankocean89 on October 08, 2013, 03:38:04 PM
Thanks for your swift replies (^_^) I have Avast full system scan running right now, should I stopped it or pausing it is enough?
Also to Eddy, I have no idea what a bootscan is
Title: Re: These Trojan Horse Twins called 80000032.@ and 80000064.@ are destrying my life
Post by: magna86 on October 08, 2013, 03:41:31 PM
Thanks for your swift replies (^_^) I have Avast full system scan running right now, should I stopped it or pausing it is enough?
Also to Eddy, I have no idea what a bootscan is

If you have been start boot time scan, don't stop it. Finish it first.
avast shall warn you to preform boot time scan, just press Yes and follow the prompts.
Title: Re: These Trojan Horse Twins called 80000032.@ and 80000064.@ are destrying my life
Post by: frankocean89 on October 08, 2013, 03:48:14 PM
Thanks for your swift replies (^_^) I have Avast full system scan running right now, should I stopped it or pausing it is enough?
Also to Eddy, I have no idea what a bootscan is

If you have been start boot time scan, don't stop it. Finish it first.
avast shall warn you to preform boot time scan, just press Yes and follow the prompts.

But i dont know what boot time scan is. I am only using Avast full system scan and it has been running for about an hour and 45 and scanned 25% of my system.
So I fear that if the scan takes too long, the Trojan Horse will have destroyed my laptop by the time the scan is finished and also, I have important documents to download off my email account :/
Title: Re: These Trojan Horse Twins called 80000032.@ and 80000064.@ are destrying my life
Post by: magna86 on October 08, 2013, 03:53:21 PM
Quote
But i dont know what boot time scan is. I am only using Avast full system scan and it has been running for about an hour and 45 and scanned 25% of my system.
So I fear that if the scan takes too long, the Trojan Horse will have destroyed my laptop by the time the scan is finished and also, I have important documents to download off my email account :/
Boot time scan is preforming virus scanning by avast before windows files load in. All in sistem is shutdown and avast can target and kill all malware. Malware is inactiv and it can't defend itself.
But this malware uses some technique to hide the full path from AV and other security tools.
You may preform virus scanning some other time. Stop scan and preform FRST.

ZA will not brake your system. His misions is to steal information from you, not to brake computer.  ;D
Title: Re: These Trojan Horse Twins called 80000032.@ and 80000064.@ are destrying my life
Post by: frankocean89 on October 08, 2013, 04:00:56 PM
Quote
But i dont know what boot time scan is. I am only using Avast full system scan and it has been running for about an hour and 45 and scanned 25% of my system.
So I fear that if the scan takes too long, the Trojan Horse will have destroyed my laptop by the time the scan is finished and also, I have important documents to download off my email account :/
Boot time scan is preforming virus scanning by avast before windows files load in. All in sistem is shutdown and avast can target and kill all malware. Malware is inactiv and it can't defend itself.
But this malware uses some technique to hide the full path from AV and other security tools.
You may preform virus scanning some other time. Stop scan and preform FRST.

ZA will not brake your system. His misions is to steal information from you, not to brake computer.  ;D

I am soooo relieved!! At first I thought I was about to lose everything on my laptop since I have been too lazy to back up. GREAT !! ;D
"Stop scan and preform FRST"
Sorry for my ignorance but i am not really good with IT  :-[.
So you want me to STOP Avast full scan right??
What is FRST?
Also since I have checked my email account several times since I got infected, are people in my contact list at risk of getting infected too?

Title: Re: These Trojan Horse Twins called 80000032.@ and 80000064.@ are destrying my life
Post by: Pondus on October 08, 2013, 04:09:26 PM
Quote
So you want me to STOP Avast full scan right??
yes


Quote
What is FRST?
follow instructions magna86 gave you in first post


Title: Re: These Trojan Horse Twins called 80000032.@ and 80000064.@ are destrying my life
Post by: frankocean89 on October 08, 2013, 04:22:20 PM
Quote
So you want me to STOP Avast full scan right??
yes


Quote
What is FRST?
follow instructions magna86 gave you in first post

Thanks for the head up.
I have tried downloading the Farbar scan several times ( I am on firefox right now) but I cant. I cant find it in its location folder. I said in my OP that I couldnt download anything off the internet since my laptop got infected, that is my main problem.
Title: Re: These Trojan Horse Twins called 80000032.@ and 80000064.@ are destrying my life
Post by: frankocean89 on October 08, 2013, 04:28:38 PM
Hey, I have tried Real player browser and so far it is working , I am downloading it right now! I think the issue was with my browsers, I  will get back to you soon.
Title: Re: These Trojan Horse Twins called 80000032.@ and 80000064.@ are destrying my life
Post by: frankocean89 on October 08, 2013, 04:37:19 PM
 :'(
NOPE it is not downloading. i cant see them anywhere even in the Downloads folder ;_;
OMG I am terrified, is there any other way out of this if I cant download off the internet? I am really desperate now ;_;
Title: Re: These Trojan Horse Twins called 80000032.@ and 80000064.@ are destrying my life
Post by: Eddy on October 08, 2013, 04:38:25 PM
Often when you can not download through a web-browser, ftp is still working.

You can also create a Bart-pe bootcd with the utils on it and run them from there.
Title: Re: These Trojan Horse Twins called 80000032.@ and 80000064.@ are destrying my life
Post by: frankocean89 on October 08, 2013, 04:39:28 PM
Often when you can not download through a web-browser, ftp is still working.
what is ftp?
Title: Re: These Trojan Horse Twins called 80000032.@ and 80000064.@ are destrying my life
Post by: Secondmineboy on October 08, 2013, 04:42:22 PM
http://en.wikipedia.org/wiki/File_Transfer_Protocol

FileZilla is an ftp program, and there are many others.
Title: Re: These Trojan Horse Twins called 80000032.@ and 80000064.@ are destrying my life
Post by: Eddy on October 08, 2013, 04:43:07 PM
Almost all browsers support the ftp protocol.
Title: Re: These Trojan Horse Twins called 80000032.@ and 80000064.@ are destrying my life
Post by: frankocean89 on October 08, 2013, 04:47:54 PM
Almost all browsers support the ftp protocol.

Can anyone then tell me how i can use the ftp protocol to download off the internet or any other alternative?? Also I dont understand IT jargon and at this point I feel totally helpless because I have no clue what to do
Title: Re: These Trojan Horse Twins called 80000032.@ and 80000064.@ are destrying my life
Post by: magna86 on October 08, 2013, 04:48:59 PM
@   frankocean89
Quote
NOPE it is not downloading. i cant see them anywhere even in the Downloads folder ;_;
OMG I am terrified, is there any other way out of this if I cant download off the internet? I am really desperate now ;_;

We shall run FRST in RE.


On a clean machine, please download Farbar Recovery Scan Tool (http://www.bleepingcomputer.com/download/farbar-recovery-scan-tool/) and save it to a flash drive.

Note: You need to run the version compatible with your system.

Plug the flashdrive into the infected PC.
To enter System Recovery Options from the Advanced Boot Options:
Note: In case you can not enter System Recovery Options by using F8 method, you can use Windows installation disc, or make a repair disc. Any Windows installation disc or a repair disc made on another computer can be used.
To make a repair disk on Windows 7 consult: http://www.sevenforums.com/tutorials/2083-system-repair-disc-create.html (http://www.sevenforums.com/tutorials/2083-system-repair-disc-create.html)

To enter System Recovery Options by using Windows installation disc:
On the System Recovery Options menu you will get the following options:

Startup Repair
System Restore
Windows Complete PC Restore
Windows Memory Diagnostic Tool
Command Prompt


(http://i1090.photobucket.com/albums/i366/garyr56/W7InstallDisk2.png)

Select Command Prompt

Once in the Command Prompt:
Title: Re: These Trojan Horse Twins called 80000032.@ and 80000064.@ are destrying my life
Post by: frankocean89 on October 08, 2013, 05:36:51 PM
Sorry for the delay, I had to run to an Internet cafe to download it. Since I am here, is there any other document I would need later that I should download now before going back home?? It is 4:35 and the cafe closes at 5.
I need to go home to start the scan since i cant connect my laptop using the internet cafe connect.
Title: Re: These Trojan Horse Twins called 80000032.@ and 80000064.@ are destrying my life
Post by: frankocean89 on October 08, 2013, 05:59:25 PM
DONE! I hope it worked!
Title: Re: These Trojan Horse Twins called 80000032.@ and 80000064.@ are destrying my life
Post by: frankocean89 on October 08, 2013, 06:24:39 PM
Does anyone knows what I should do next??
Title: Re: These Trojan Horse Twins called 80000032.@ and 80000064.@ are destrying my life
Post by: magna86 on October 08, 2013, 06:26:38 PM
You don't need internet any more. When I look at FRST log I shall write FRST Script for killing and fixing this rootkit.

I will be back soon.
Title: Re: These Trojan Horse Twins called 80000032.@ and 80000064.@ are destrying my life
Post by: mchain on October 08, 2013, 06:30:52 PM
Often when you can not download through a web-browser, ftp is still working.
what is ftp?
hi frankocean89,

When in a bind, do the simplest things first.  That is, get to where you are following magna's original instructions.

Workaround re no internet access:

Simplest way to do that is to download all files you need on a clean computer and transfer over to your sick system via an USB stick.  To prevent infections on your clean system via USB, install this tool on it first:  http://www.mcshield.net/ (http://www.mcshield.net/)   You'll not need to worry about transferring malware from your sick system to the clean one if this is installed and in place before you begin.  You'll be able to transfer needed programs over, or needed logs back to the clean system to post back here as you go along.
Title: Re: These Trojan Horse Twins called 80000032.@ and 80000064.@ are destrying my life
Post by: magna86 on October 08, 2013, 06:34:40 PM
 Frankocean89,
This will kill ZA rootkit and all his related files.


Open notepad.
Code: [Select]
START
HKLM\...\Run: [ApnTBMon] - C:\Program Files\AskPartnerNetwork\Toolbar\Updater\TBNotifier.exe [1673680 2013-10-01] (APN)
S2 APNMCP; C:\Program Files\AskPartnerNetwork\Toolbar\apnmcp.exe [164816 2013-10-01] (APN LLC.)
C:\Program Files\AskPartnerNetwork
S2 *etadpug; "C:\Program Files\Google\Desktop\Install\{a9dc3b77-a104-26f7-d8cc-b3ee5a1d846e}\   \...\???\{a9dc3b77-a104-26f7-d8cc-b3ee5a1d846e}\GoogleUpdate.exe" < <==== ATTENTION (ZeroAccess)
C:\Windows\assembly\GAC\Desktop.ini
C:\Users\SAMSUNG\AppData\Local\Google\Desktop\Install
C:\Program Files\Google\Desktop\Install
C:\Users\SAMSUNG\AppData\Local\Temp\InstallFlashPlayer.exe
C:\Users\SAMSUNG\AppData\Local\Temp\lowproc.exe
C:\Users\SAMSUNG\AppData\Local\Temp\msimg32.dll
C:\Users\SAMSUNG\AppData\Local\Temp\Offercast2802_MYC_.exe
C:\Users\SAMSUNG\AppData\Local\Temp\rnsetup0.exe
C:\Users\SAMSUNG\AppData\Local\Temp\SkypeSetup.exe
C:\Users\SAMSUNG\AppData\Local\Temp\stubhelper.dll
C:\Users\SAMSUNG\AppData\Local\Temp\The History of Love Downloader.exe
DeleteJunctionsIndirectory: C:\Program Files\Windows Defender
END

Save it to your USB flashdrive as fixlist.txt
[/list]

=> Or you may download attached file. It's created fixlist.txt for FRST.

>>  Boot into Recovery Environment


Start FRST in a similar manner to when you ran a scan earlier, but this time when it opens ....
>>  Exit out of Recovery Environment and post me the log please.


-------------------- Next -----------------


Can you please boot back to normal mode Windows, and re-run FRST;

Title: Re: These Trojan Horse Twins called 80000032.@ and 80000064.@ are destrying my life
Post by: frankocean89 on October 08, 2013, 06:55:11 PM
Thanks mchain I will look into that when my system is cleaned :)
 magna86 I have attached the log :)
Title: Re: These Trojan Horse Twins called 80000032.@ and 80000064.@ are destrying my life
Post by: frankocean89 on October 08, 2013, 07:13:19 PM
Done
Title: Re: These Trojan Horse Twins called 80000032.@ and 80000064.@ are destrying my life
Post by: magna86 on October 08, 2013, 07:22:38 PM
This fix you shall deploy from normal mode as some malicius services are still loaded.






1. Open notepad and copy/paste the text present inside the code box below.
To do this highlight the contents of the box and right click on it. Paste this into the open notepad.
NOTICE: This script was written specifically for this user, for use on that particular machine. Running this on another machine may cause damage to the operating system

Code: [Select]
START
() C:\Users\SAMSUNG\AppData\Local\GetBooks\GetBooks.exe
HKCU\...\Run: [GetBooks] - C:\Users\SAMSUNG\AppData\Local\GetBooks\GetBooks.exe [509440 2013-05-15] ()
C:\Users\SAMSUNG\AppData\Local\GetBooks
HKCU\...\Run: [Google Update*] - [x] <===== ATTENTION (ZeroAccess rootkit hidden path)
HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://feed.snap.do/?publisher=Download&dpid=Download&co=GB&userid=00c0ab9a-df4a-455b-aec2-db82b7a2f123&searchtype=ds&q={searchTerms}
HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://feed.snap.do/?publisher=Download&dpid=Download&co=GB&userid=00c0ab9a-df4a-455b-aec2-db82b7a2f123&searchtype=ds&q={searchTerms}
SearchScopes: HKLM - {006ee092-9658-4fd6-bd8e-a21a348e59f5} URL = http://feed.snap.do/?publisher=Download&dpid=Download&co=GB&userid=00c0ab9a-df4a-455b-aec2-db82b7a2f123&searchtype=ds&q={searchTerms}
SearchScopes: HKCU - {006ee092-9658-4fd6-bd8e-a21a348e59f5} URL =
Toolbar: HKLM -  No Name - {ae07101b-46d4-4a98-af68-0333ea26e113} -  No File
Winsock: Catalog5 01 mswsock.dll File Not found (Microsoft Corporation) ATTENTION: The LibraryPath should be "%SystemRoot%\system32\NLAapi.dll"
Winsock: Catalog5 06 mswsock.dll File Not found (Microsoft Corporation) ATTENTION: The LibraryPath should be "%SystemRoot%\System32\mswsock.dll"
CHR Extension: (Ask Toolbar) - C:\Users\SAMSUNG\AppData\Local\Google\Chrome\User Data\Default\Extensions\aaaajpbjobobnmcnepdoldijfgmgogbe\21.54118_0
C:\Users\SAMSUNG\AppData\Local\Google\Chrome\User Data\Default\Extensions\aaaajpbjobobnmcnepdoldijfgmgogbe
CHR Extension: (Missing e) - C:\Users\SAMSUNG\AppData\Local\Google\Chrome\User Data\Default\Extensions\bcjbagclppcgdbpobcpoojdjdmcjhpid\2.14.3_0
C:\Users\SAMSUNG\AppData\Local\Google\Chrome\User Data\Default\Extensions\bcjbagclppcgdbpobcpoojdjdmcjhpid
CHR Extension: (UnfollowHater) - C:\Users\SAMSUNG\AppData\Local\Google\Chrome\User Data\Default\Extensions\cpjobkfnjnakiggjoafelkncclbonjhm\1.0.13_0
C:\Users\SAMSUNG\AppData\Local\Google\Chrome\User Data\Default\Extensions\cpjobkfnjnakiggjoafelkncclbonjhm
CHR Extension: (Chrome In-App Payments service) - C:\Users\SAMSUNG\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda\0.0.4.11_0
C:\Users\SAMSUNG\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda
CHR HKLM\...\Chrome\Extension: [aaaajpbjobobnmcnepdoldijfgmgogbe] - C:\ProgramData\AskPartnerNetwork\Toolbar\MYC3-V7\CRX\ToolbarCR.crx
C:\ProgramData\AskPartnerNetwork
U2 *etadpug; "C:\Program Files\Google\Desktop\Install\{a9dc3b77-a104-26f7-d8cc-b3ee5a1d846e}\   \...\???\{a9dc3b77-a104-26f7-d8cc-b3ee5a1d846e}\GoogleUpdate.exe" < <==== ATTENTION (ZeroAccess)
DeleteJunctionsIndirectory: C:\Program Files\Windows Defender
CMD: netsh winsock reset
CMD: ipconfig /flushdns
END
2. Save notepad as fixlist.txt to your Desktop.
NOTE: => It's important that both files, FRST and fixlist.txt are in the same location or the fix will not work.


3. Run FRST/FRST64 and press the Fix button just once and wait.
If the tool needed a restart please make sure you let the system to restart normally and let the tool completes its run after restart.

The tool will make a log on the Desktop (Fixlog.txt). Please attach it to your reply.
Note: If the tool warned you about the outdated version please download and run the updated version.



------ next -------



Reboot(restart) mashine once more time....




------ next -------



Re-run FRST, just press Scan button and post me fresh created FRST log.

Title: Re: These Trojan Horse Twins called 80000032.@ and 80000064.@ are destrying my life
Post by: frankocean89 on October 08, 2013, 08:13:18 PM
Thanks soooooo much. I checked the location of the trojan horses and they have been deleted :*
Title: Re: These Trojan Horse Twins called 80000032.@ and 80000064.@ are destrying my life
Post by: magna86 on October 08, 2013, 08:43:53 PM
Quote
Thanks soooooo much. I checked the location of the trojan horses and they have been deleted :*
8)




We have not finished yet. I shall qoute myself again:

  • I will be working on your Malware issues this may or may not solve other issues you have with your machine.
  • The fixes are specific to your problem and should only be used for this issue on this machine.
  • If you don't know or understand something, please don't hesitate to ask.
  • Please refrain from making any further changes to your computer (Install/Uninstall programs, delete files, edit the registry, etc...)
  • Please DO NOT run any other tools or scans whilst I am helping you.
  • It is important that you reply to this thread. Do not start a new topic.
  • Your security programs may give warnings for some of the tools I will ask you to use. Be assured, any links I give are safe.
  • Absence of symptoms does not mean that everything is clear.
---------------------------------------------------------------------------------------------



=> Run Chrome > (http://fotkica.com/imgs2/256965_224774706_SNP_2696434_en_v1.png) > Settings
Under "On startup" part of options, check box for "Open a specific page or set of pages" and click "Set pages".
Under "Add new page" type: "www.google.com" and press Ok.

-----------------------------

Rootkit is killed. ZA is no more. But we need to check/repair the all damage caused by ZA rootkit.

We shall re-check with Combofix and therefor I wanna you tu run another Farbar tool named FSS
With FSS we shall check is there any damage caused by rootkit.




Scan with Combofix:
----- next -----


Please download Farbar Service Scanner (http://www.bleepingcomputer.com/download/farbar-service-scanner/dl/62/) and run it on the computer with the issue.


Title: Re: These Trojan Horse Twins called 80000032.@ and 80000064.@ are destrying my life
Post by: frankocean89 on October 08, 2013, 10:36:06 PM
Sorry it took so long :/
Combofix took about an hour to scan whn I thought it will only last for 10 min. This makes me fear for the health of my laptop :(
I had issue disabling Avast despite doing exactly what was advised in teh links you posted. I right-clicked on it and disabled it for an hour but Combofix kept on saying that it wasnt disabled
Title: Re: These Trojan Horse Twins called 80000032.@ and 80000064.@ are destrying my life
Post by: magna86 on October 09, 2013, 12:25:14 AM
All looks clean. How's your computer running now?
Title: Re: These Trojan Horse Twins called 80000032.@ and 80000064.@ are destrying my life
Post by: frankocean89 on October 09, 2013, 01:09:55 AM
GREAT
GREAT
GREAT!!!
Thanks so much!! I could hug you right now. I was so distressed earlier toady you saved me! Thanks  :-* :-* :-*
Title: Re: These Trojan Horse Twins called 80000032.@ and 80000064.@ are destrying my life
Post by: Pondus on October 09, 2013, 01:22:23 AM
magna is probably in bed now...check back tomorrow and he will remove the tools used   ;)

Title: Re: These Trojan Horse Twins called 80000032.@ and 80000064.@ are destrying my life
Post by: frankocean89 on October 09, 2013, 11:00:18 AM
magna is probably in bed now...check back tomorrow and he will remove the tools used   ;)

Good morning everyone.
Which tool do i have to remove and how ? :)
Title: Re: These Trojan Horse Twins called 80000032.@ and 80000064.@ are destrying my life
Post by: magna86 on October 09, 2013, 11:11:58 AM
Now that your machine is clean and safe, I suggest you to change all your important passwords on your computer, from your bank accounts and stuff the like ...

First we need to remove FRST Quarantine.





1. Open notepad and copy/paste the text present inside the code box below.
To do this highlight the contents of the box and right click on it. Paste this into the open notepad.
NOTICE: This script was written specifically for this user, for use on that particular machine. Running this on another machine may cause damage to the operating system

Code: [Select]
DeleteQuarantine:
2. Save notepad as fixlist.txt to your Desktop.
NOTE: => It's important that both files, FRST and fixlist.txt are in the same location or the fix will not work.


3. Run FRST/FRST64 and press the Fix button just once and wait.
If the tool needed a restart please make sure you let the system to restart normally and let the tool completes its run after restart.

The tool will make a log on the Desktop (Fixlog.txt).
Note: If the tool warned you about the outdated version please download and run the updated version.






--------- next ---------






It is necessary to uninstall ComboFix :
Code: [Select]
ComboFix /Uninstall Note that there is a space between "  ComboFix  " and "  /Uninstall  " .

Wait for the uninstall process is complete.






--------- next ---------




Please download  DelFix (http://general-changelog-team.fr/fr/downloads/finish/20-outils-de-xplode/9-delfix) by "Xplode" to your Desktop.

Run the tool and check the following boxes below;

Now click on "Run" button. Wait for the programme completes his work.
All the tools we used should be gone.
Tool will create and open an log report (DelFix.txt)
Note: The report will also be stored on C:\DelFix.txt


> I don't need DelFix log report.



------------------------------------------------------------------


I recommend you to use MCShield if you will.
You may download MCShield from one of the following links:

MyCity -  Official download link (http://www.mcshield.net)
Softpedija - Mirror download link (http://www.softpedia.com/get/Antivirus/MCShield.shtml)

It will prevent infection by computer via USB flash drive, mobile phone or any other memory card.
And not only will prevent infection, but it will immediately clean flash drive, memory card or external HDD.




Be safe.  :)