############################## | UsbFix 7.059 | [Deletion]
User: natsof (Administrator) # NATSOF-PC [Gigabyte Technology Co., Ltd. GA-N650SLI-DS4L]
Updated 16/09/2011 by El Desaparecido
Started at 12:05:17 | 25/07/2012
Website:
http://eldesaparecido.com
Submit your sample:
http://eldesaparecido.com/support.php
Contact:
contact@eldesaparecido.com
CPU: Intel(R) Core(TM)2 Duo CPU E4500 @ 2.20GHz
CPU 2: Intel(R) Core(TM)2 Duo CPU E4500 @ 2.20GHz
Microsoft Windows 7 Ultimate (6.1.7601 32-Bit) # Service Pack 1
Internet Explorer 8.0.7601.17514
Windows Firewall: Disabled /!\
RAM -> 3328 Mb
C:\ (%systemdrive%) -> Fixed drive # 98 Gb (67 Mb free - 69%) [] # NTFS
D:\ -> Fixed drive # 195 Gb (175 Mb free - 90%) [film a hry] # NTFS
E:\ -> Fixed drive # 173 Gb (173 Mb free - 100%) [fota] # NTFS
F:\ -> CD-ROM
G:\ -> Removable drive # 7 Gb (5 Mb free - 69%) [STORE N GO] # NTFS
H:\ -> CD-ROM
I:\ -> CD-ROM
################## | Files # Infected Folders |
Deleted ! C:\$RECYCLE.BIN\S-1-5-21-3734077389-2202423189-3181031338-1001
Deleted ! D:\$RECYCLE.BIN\S-1-5-21-3734077389-2202423189-3181031338-1001
Deleted ! E:\$RECYCLE.BIN\S-1-5-21-3734077389-2202423189-3181031338-1001
Not deleted ! H:\autorun.inf
(!) Temporary files deleted.
################## | Registry |
################## | Mountpoints2 |
################## | Listing |
[25/07/2012 - 12:06:47 | SHD ] C:\$Recycle.Bin
[10/06/2009 - 23:42:20 | N | 24] C:\autoexec.bat
[24/07/2012 - 11:43:07 | RSHD ] C:\autorun.inf
[14/07/2012 - 23:13:38 | D ] C:\Boot
[28/06/2012 - 13:56:05 | N | 211] C:\Boot.BAK
[14/07/2012 - 23:13:38 | N | 355] C:\Boot.ini.saved
[25/10/2001 - 14:00:00 | N | 4952] C:\Bootfont.bin
[20/11/2010 - 23:29:06 | RASH | 383786] C:\bootmgr
[14/07/2012 - 23:13:39 | N | 8192] C:\BOOTSECT.BAK
[24/07/2012 - 11:43:07 | RSHD ] C:\comment.htt
[10/06/2009 - 23:42:20 | N | 10] C:\config.sys
[24/07/2012 - 11:43:07 | D ] C:\desktop.ini
[14/07/2009 - 06:53:55 | SHD ] C:\Documents and Settings
[28/06/2012 - 15:38:22 | D ] C:\driver
[04/07/2012 - 10:39:31 | D ] C:\found.000
[25/07/2012 - 11:53:11 | ASH | 2616893440] C:\hiberfil.sys
[28/06/2012 - 14:03:48 | N | 0] C:\IO.SYS
[28/06/2012 - 15:10:08 | N | 35832930] C:\motherboard_driver_chipset_nvidia_vistax86.exe
[28/06/2012 - 14:03:48 | N | 0] C:\MSDOS.SYS
[28/06/2012 - 14:06:59 | N | 817468] C:\NETFX11install.log
[28/06/2012 - 14:07:02 | N | 409434] C:\NETFX11LNGinstall.log
[28/06/2012 - 14:05:33 | N | 5081446] C:\NETFX20install.log
[28/06/2012 - 14:05:42 | N | 862304] C:\NETFX20LNGinstall.log
[28/06/2012 - 14:06:26 | N | 1368434] C:\NETFX30install.log
[28/06/2012 - 14:06:34 | N | 401494] C:\NETFX30LNGinstall.log
[28/06/2012 - 14:06:46 | N | 1265902] C:\NETFX35install.log
[28/06/2012 - 14:06:50 | N | 524270] C:\NETFX35LNGinstall.log
[28/06/2012 - 15:54:00 | D ] C:\Nová složka
[13/07/2012 - 21:45:38 | D ] C:\Nová složka (2)
[13/04/2008 - 22:13:04 | N | 47564] C:\NTDETECT.COM
[14/04/2008 - 00:01:48 | N | 250576] C:\ntldr
[28/06/2012 - 20:29:49 | D ] C:\NVIDIA
[28/06/2012 - 15:41:00 | D ] C:\NVIDIA_258.96_Win7_Vista32
[28/06/2012 - 15:27:24 | N | 138359416] C:\NVIDIA_258.96_Win7_Vista32.zip
[25/07/2012 - 11:53:19 | ASH | 3489193984] C:\pagefile.sys
[14/07/2009 - 04:37:05 | D ] C:\PerfLogs
[24/07/2012 - 21:21:52 | N | 512] C:\PhysicalMBR.bin
[24/07/2012 - 18:02:44 | D ] C:\Program Files
[24/07/2012 - 11:43:11 | HD ] C:\ProgramData
[14/07/2012 - 22:24:10 | SHD ] C:\Recovery
[24/07/2012 - 18:02:57 | D ] C:\rsit
[17/07/2012 - 22:01:02 | D ] C:\stahuj
[25/07/2012 - 12:01:47 | SHD ] C:\System Volume Information
[23/07/2012 - 11:05:35 | D ] C:\Tošovice 2012
[25/07/2012 - 12:06:47 | D ] C:\UsbFix
[25/07/2012 - 12:05:23 | A | 3772] C:\UsbFix.txt
[14/07/2012 - 22:24:23 | D ] C:\Users
[18/07/2012 - 12:32:58 | D ] C:\VritualRoot
[24/07/2012 - 17:53:53 | D ] C:\Windows
[14/07/2012 - 23:04:00 | D ] C:\Windows.old
[25/07/2012 - 12:06:47 | SHD ] D:\$RECYCLE.BIN
[24/07/2012 - 11:43:07 | RSHD ] D:\autorun.inf
[24/07/2012 - 11:43:07 | RSHD ] D:\comment.htt
[24/07/2012 - 11:43:07 | D ] D:\desktop.ini
[23/07/2012 - 11:10:21 | D ] D:\ol
[19/07/2012 - 20:28:37 | SHD ] D:\System Volume Information
[25/07/2012 - 12:06:47 | SHD ] E:\$RECYCLE.BIN
[24/07/2012 - 11:43:07 | RSHD ] E:\autorun.inf
[24/07/2012 - 11:43:07 | RSHD ] E:\comment.htt
[24/07/2012 - 11:43:07 | D ] E:\desktop.ini
[19/07/2012 - 20:28:37 | SHD ] E:\System Volume Information
[22/06/2012 - 14:37:48 | AD ] F:\Broučci
[22/06/2012 - 14:38:38 | AD ] F:\dětičky
[22/06/2012 - 14:40:30 | AD ] F:\dopravní hřiště
[22/06/2012 - 14:41:28 | AD ] F:\fotky
[22/06/2012 - 14:43:32 | AD ] F:\hledání stříbrného koně
[24/07/2012 - 11:43:07 | RSHD ] G:\autorun.inf
[24/07/2012 - 11:43:07 | RSHD ] G:\comment.htt
[24/07/2012 - 11:43:07 | D ] G:\desktop.ini
[12/06/2012 - 04:49:04 | D ] G:\Filmy
[05/07/2012 - 13:40:26 | D ] G:\tisk
[05/07/2012 - 14:23:13 | D ] G:\Tošovice 5.7.2012
[23/05/2012 - 06:54:33 | R | 149436] H:\London 2012- The Official Video Game of the Olympic Games_disk1.sim
[23/05/2012 - 06:54:33 | R | 435] H:\London 2012- The Official Video Game of the Olympic Games_disk1.sis
[23/05/2012 - 06:49:32 | R | 1493593632] H:\London 2012- The Official Video Game of the Olympic Games_disk1_0.sid
[23/05/2012 - 06:51:08 | R | 1493576392] H:\London 2012- The Official Video Game of the Olympic Games_disk1_1.sid
[23/05/2012 - 06:52:35 | R | 1493250576] H:\London 2012- The Official Video Game of the Olympic Games_disk1_2.sid
[23/05/2012 - 06:53:54 | R | 1493466728] H:\London 2012- The Official Video Game of the Olympic Games_disk1_3.sid
[23/05/2012 - 06:54:33 | R | 695653216] H:\London 2012- The Official Video Game of the Olympic Games_disk1_4.sid
[09/05/2012 - 02:33:06 | R | 355920] H:\Setup.exe
[09/05/2012 - 02:33:06 | R | 411016] H:\SteamService.exe
[29/06/2012 - 00:39:27 | R | 63] H:\autorun.inf
[09/05/2012 - 02:33:06 | R | 26694] H:\icon.ico
[29/06/2012 - 03:18:55 | R | 9865825] H:\install-1.bin
[29/06/2012 - 03:18:55 | R | 424062] H:\install.exe
[28/06/2012 - 23:26:37 | D ] H:\resources
[09/05/2012 - 02:33:08 | R | 1274] H:\setup.ini
[18/05/2012 - 10:53:25 | R | 258738] H:\splash.tga
################## | Vaccin |
C:\Autorun.inf -> Vaccine created by UsbFix (TeamXscript)
D:\Autorun.inf -> Vaccine created by UsbFix (TeamXscript)
E:\Autorun.inf -> Vaccine created by UsbFix (TeamXscript)
G:\Autorun.inf -> Vaccine created by UsbFix (TeamXscript)
################## | Upload |
Please send the file: C:\UsbFix_Upload_Me_NATSOF-PC.zip
http://eldesaparecido.com/support.php
Thank you for your contribution.
################## | E.O.F |
All processes killed
========== OTL ==========
Service VGPU stopped successfully!
Service VGPU deleted successfully!
File System32\drivers\rdvgkmd.sys not found.
Error: No service named atcgx6nk was found to stop!
Service\Driver key atcgx6nk not found.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\\DefaultScope| /E : value set successfully!
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}\ not found.
Registry value HKEY_USERS\.DEFAULT\Software\Microsoft\Internet Explorer\URLSearchHooks\\{EEE6C35D-6118-11DC-9C72-001320C79847} deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{EEE6C35D-6118-11DC-9C72-001320C79847}\ deleted successfully.
C:\Program Files\SweetIM\Toolbars\Internet Explorer\mgHelper.dll moved successfully.
HKEY_USERS\.DEFAULT\Software\Microsoft\Internet Explorer\SearchScopes\\DefaultScope| /E : value set successfully!
Registry value HKEY_USERS\S-1-5-18\Software\Microsoft\Internet Explorer\URLSearchHooks\\{EEE6C35D-6118-11DC-9C72-001320C79847} not found.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{EEE6C35D-6118-11DC-9C72-001320C79847}\ not found.
File C:\Program Files\SweetIM\Toolbars\Internet Explorer\mgHelper.dll not found.
HKEY_USERS\S-1-5-18\Software\Microsoft\Internet Explorer\SearchScopes\\DefaultScope| /E : value set successfully!
Registry value HKEY_USERS\S-1-5-21-3734077389-2202423189-3181031338-1001\Software\Microsoft\Internet Explorer\URLSearchHooks\\{EEE6C35D-6118-11DC-9C72-001320C79847} deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{EEE6C35D-6118-11DC-9C72-001320C79847}\ not found.
File C:\Program Files\SweetIM\Toolbars\Internet Explorer\mgHelper.dll not found.
HKEY_USERS\S-1-5-21-3734077389-2202423189-3181031338-1001\Software\Microsoft\Internet Explorer\SearchScopes\\DefaultScope| /E : value set successfully!
Registry key HKEY_USERS\S-1-5-21-3734077389-2202423189-3181031338-1001\Software\Microsoft\Internet Explorer\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}\ not found.
Registry key HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{BC1A4275-EBD7-C096-4DF4-0F02699F086C}\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{BC1A4275-EBD7-C096-4DF4-0F02699F086C}\ not found.
Registry key HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{EEE6C35C-6118-11DC-9C72-001320C79847}\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{EEE6C35C-6118-11DC-9C72-001320C79847}\ deleted successfully.
C:\Program Files\SweetIM\Toolbars\Internet Explorer\mgToolbarIE.dll moved successfully.
Registry value HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Toolbar\\{EEE6C35B-6118-11DC-9C72-001320C79847} deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{EEE6C35B-6118-11DC-9C72-001320C79847}\ deleted successfully.
File C:\Program Files\SweetIM\Toolbars\Internet Explorer\mgToolbarIE.dll not found.
Registry value HKEY_USERS\.DEFAULT\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser\\{EEE6C35B-6118-11DC-9C72-001320C79847} deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{EEE6C35B-6118-11DC-9C72-001320C79847}\ not found.
File C:\Program Files\SweetIM\Toolbars\Internet Explorer\mgToolbarIE.dll not found.
Registry value HKEY_USERS\S-1-5-18\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser\\{EEE6C35B-6118-11DC-9C72-001320C79847} not found.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{EEE6C35B-6118-11DC-9C72-001320C79847}\ not found.
File C:\Program Files\SweetIM\Toolbars\Internet Explorer\mgToolbarIE.dll not found.
Registry value HKEY_USERS\S-1-5-21-3734077389-2202423189-3181031338-1001\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser\\{EEE6C35B-6118-11DC-9C72-001320C79847} deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{EEE6C35B-6118-11DC-9C72-001320C79847}\ not found.
File C:\Program Files\SweetIM\Toolbars\Internet Explorer\mgToolbarIE.dll not found.
Registry value HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\RunOnceEx\\Flags deleted successfully.
Registry value HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\RunOnceEx\\Title deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\URL\Prefixes\\gopher|:gopher:// /E : value set successfully!
Registry value HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\\VMApplet:/pagefile deleted successfully.
Registry value HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad\\WebCheck deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{E6FB5E20-DE35-11CF-9C87-00AA005127ED}\ not found.
C:\Windows\assembly\NativeImages_v2.0.50727_32\Temp\ZAP5E64.tmp folder deleted successfully.
C:\Windows\assembly\NativeImages_v2.0.50727_32\Temp\ZAP7C7F.tmp folder deleted successfully.
C:\Windows\assembly\NativeImages_v2.0.50727_32\Temp\ZAP8545.tmp folder deleted successfully.
C:\Windows\Installer\MSI3D54.tmp deleted successfully.
C:\Windows\Installer\MSI5A77.tmp deleted successfully.
C:\Windows\Installer\MSI6FAD.tmp deleted successfully.
C:\Windows\Installer\MSI70A8.tmp deleted successfully.
C:\Windows\Installer\MSI7422.tmp deleted successfully.
C:\Windows\Installer\MSIDC71.tmp deleted successfully.
========== REGISTRY ==========
Registry value HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run\\Skype deleted successfully.
Registry value HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run\\DAEMON Tools Lite deleted successfully.
========== FILES ==========
C:\Program Files\SweetIM\Toolbars\Internet Explorer\resources\orange folder moved successfully.
C:\Program Files\SweetIM\Toolbars\Internet Explorer\resources\green folder moved successfully.
C:\Program Files\SweetIM\Toolbars\Internet Explorer\resources\blue folder moved successfully.
C:\Program Files\SweetIM\Toolbars\Internet Explorer\resources folder moved successfully.
C:\Program Files\SweetIM\Toolbars\Internet Explorer\Microsoft.VC90.CRT folder moved successfully.
C:\Program Files\SweetIM\Toolbars\Internet Explorer\conf folder moved successfully.
C:\Program Files\SweetIM\Toolbars\Internet Explorer folder moved successfully.
C:\Program Files\SweetIM\Toolbars folder moved successfully.
C:\Program Files\SweetIM\Communicator\resources\sqlite folder moved successfully.
C:\Program Files\SweetIM\Communicator\resources folder moved successfully.
C:\Program Files\SweetIM\Communicator\Microsoft.VC90.CRT folder moved successfully.
C:\Program Files\SweetIM\Communicator folder moved successfully.
C:\Program Files\SweetIM folder moved successfully.
C:\Windows\Temp\mrt3A41.tmp folder moved successfully.
C:\Windows\Temp\mrt47B9.tmp folder moved successfully.
C:\Windows\Temp\mrt5E83.tmp folder moved successfully.
C:\Windows\Temp\mrt646C.tmp folder moved successfully.
C:\Windows\Temp\mrt71A6.tmp folder moved successfully.
File/Folder C:\Windows\system32\*.tmp.dll not found.
File/Folder C:\Windows\system32\SET*.tmp not found.
File/Folder C:\Windows\*.tmp not found.
========== COMMANDS ==========
C:\Windows\System32\drivers\etc\Hosts moved successfully.
HOSTS file reset successfully
[EMPTYTEMP]
User: All Users
User: Default
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 0 bytes
User: Default User
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 0 bytes
User: natsof
->Temp folder emptied: 448342 bytes
->Temporary Internet Files folder emptied: 14179862 bytes
->Opera cache emptied: 334925009 bytes
->Flash cache emptied: 1656 bytes
User: Public
%systemdrive% .tmp files removed: 0 bytes
%systemroot% .tmp files removed: 0 bytes
%systemroot%\System32 .tmp files removed: 0 bytes
%systemroot%\System32\drivers .tmp files removed: 0 bytes
Windows Temp folder emptied: 0 bytes
RecycleBin emptied: 0 bytes
Total Files Cleaned = 333,00 mb
[EMPTYFLASH]
User: All Users
User: Default
User: Default User
User: natsof
->Flash cache emptied: 0 bytes
User: Public
Total Flash Files Cleaned = 0,00 mb
[EMPTYJAVA]
User: All Users
User: Default
User: Default User
User: natsof
User: Public
Total Java Files Cleaned = 0,00 mb
OTL by OldTimer - Version 3.2.54.1 log created on 07252012_121154
Files\Folders moved on Reboot...
PendingFileRenameOperations files...
Registry entries deleted on Reboot...