Přípona txt není povolena. takže tady to je.
############################## | UsbFix V 7.165 | [Research]
User: Luca (Administrator) # LUCA-PC
Updated16/02/2014 by El Desaparecido - Team SosVirus
Started at 19:28:02 | 17/02/2014
Website :
http://www.en.usbfix.net/
Changelog :
http://www.en.usbfix.net/changelog/
Support :
http://www.sosvirus.net/
Upload Malware :
http://www.sosvirus.net/upload_malware.php
Contact :
http://www.en.usbfix.net/contact/
PC: ASRock (P5B-DE)
CPU: Intel(R) Celeron(R) CPU E3400 @ 2.60GHz
RAM -> [Total : 3071 Mo| Free : 952 Mo]
Bios: American Megatrends Inc.
Boot: Normal boot
OS: Microsoft Windows 7 Home Premium (6.1.7601 64-Bit) Service Pack 1
WB: Windows Internet Explorer : 11.0.9600.16518
WB: Google Chrome : 32.0.1700.107
SC: Security Center [Enabled]
WU: Windows Update [Enabled]
AS: Windows Defender [Enabled | Updated]
FW: Windows FireWall [(!) Disabled]
C:\ -> Fixed drive # 49 Gb (7 Mb free - 15%) [] # NTFS
D:\ -> Fixed drive # 49 Gb (4 Mb free - 7%) [Plocha 2] # NTFS
E:\ -> Fixed drive # 91 Gb (4 Mb free - 5%) [Hry] # NTFS
F:\ (%systemdrive%) -> Fixed drive # 100 Gb (3 Mb free - 3%) [DATA] # NTFS
G:\ -> CD-ROM
H:\ -> CD-ROM
I:\ -> CD-ROM
J:\ -> Removable drive # 29 Gb (457 Mb free - 2%) [PENDRIVE] # FAT32
################## | Active Processes |
F:\Windows\system32\csrss.exe (ID: 372 |ParentID: 356)
F:\Windows\system32\wininit.exe (ID: 452 |ParentID: 356)
F:\Windows\system32\csrss.exe (ID: 468 |ParentID: 444)
F:\Windows\system32\services.exe (ID: 500 |ParentID: 452)
F:\Windows\system32\lsass.exe (ID: 516 |ParentID: 452)
F:\Windows\system32\lsm.exe (ID: 524 |ParentID: 452)
F:\Windows\system32\svchost.exe (ID: 648 |ParentID: 500)
F:\Windows\system32\svchost.exe (ID: 712 |ParentID: 500)
F:\Windows\system32\atiesrxx.exe (ID: 764 |ParentID: 500)
F:\Windows\system32\winlogon.exe (ID: 824 |ParentID: 444)
F:\Windows\System32\svchost.exe (ID: 864 |ParentID: 500)
F:\Windows\System32\svchost.exe (ID: 908 |ParentID: 500)
F:\Windows\system32\svchost.exe (ID: 944 |ParentID: 500)
F:\Windows\system32\svchost.exe (ID: 972 |ParentID: 500)
F:\Windows\system32\svchost.exe (ID: 1064 |ParentID: 500)
F:\Windows\system32\atieclxx.exe (ID: 1120 |ParentID: 764)
F:\Windows\SYSTEM32\WISPTIS.EXE (ID: 1136 |ParentID: 908)
F:\Windows\System32\spoolsv.exe (ID: 1248 |ParentID: 500)
F:\Windows\system32\svchost.exe (ID: 1280 |ParentID: 500)
F:\Program Files (x86)\Autodesk\Content Service\Connect.Service.ContentService.exe (ID: 1448 |ParentID: 500)
F:\Windows\system32\svchost.exe (ID: 1536 |ParentID: 500)
F:\Program Files (x86)\Firebird\bin\fbguard.exe (ID: 1560 |ParentID: 500)
F:\Program Files (x86)\HP\HPLaserJetService\HPLaserJetService.exe (ID: 1644 |ParentID: 500)
F:\Windows\SysWOW64\svchost.exe (ID: 1692 |ParentID: 500)
F:\Windows\System32\svchost.exe (ID: 1712 |ParentID: 500)
F:\Windows\System32\svchost.exe (ID: 1816 |ParentID: 500)
F:\Windows\SysWOW64\PnkBstrA.exe (ID: 1836 |ParentID: 500)
F:\Program Files (x86)\TeamViewer\Version8\TeamViewer_Service.exe (ID: 1180 |ParentID: 500)
F:\Windows\system32\Dwm.exe (ID: 1740 |ParentID: 908)
F:\Windows\system32\taskhost.exe (ID: 2028 |ParentID: 500)
F:\Windows\SYSTEM32\WISPTIS.EXE (ID: 1748 |ParentID: 908)
F:\Program Files\Common Files\microsoft shared\ink\TabTip.exe (ID: 2060 |ParentID: 908)
F:\Program Files (x86)\Common Files\Microsoft Shared\Ink\TabTip32.exe (ID: 2132 |ParentID: 2060)
F:\Windows\Explorer.EXE (ID: 2212 |ParentID: 1756)
F:\Windows\system32\atwtusb.exe (ID: 2584 |ParentID: 500)
F:\Windows\system32\atwtusb.exe (ID: 2696 |ParentID: 2584)
F:\Program Files (x86)\Firebird\bin\fbserver.exe (ID: 2844 |ParentID: 500)
F:\Windows\system32\wbem\wmiprvse.exe (ID: 3064 |ParentID: 648)
F:\Windows\system32\svchost.exe (ID: 2464 |ParentID: 500)
F:\Program Files (x86)\TeamViewer\Version8\TeamViewer.exe (ID: 2420 |ParentID: 1180)
F:\Program Files (x86)\TeamViewer\Version8\tv_w32.exe (ID: 3112 |ParentID: 1180)
F:\Program Files (x86)\TeamViewer\Version8\tv_x64.exe (ID: 3120 |ParentID: 1180)
F:\Windows\system32\SearchIndexer.exe (ID: 3660 |ParentID: 500)
F:\Windows\System32\rundll32.exe (ID: 3704 |ParentID: 648)
F:\Program Files\Common Files\Microsoft Shared\Ink\InputPersonalization.exe (ID: 368 |ParentID: 500)
F:\Windows\System32\svchost.exe (ID: 284 |ParentID: 500)
F:\Program Files\Windows Media Player\wmpnetwk.exe (ID: 192 |ParentID: 500)
F:\Windows\System32\WTMKM.exe (ID: 2924 |ParentID: 2212)
F:\Program Files (x86)\HP\hp laserjet m1522\hppfaxprintersrv.exe (ID: 2820 |ParentID: 2212)
F:\Program Files (x86)\BitTorrent\BitTorrent.exe (ID: 2568 |ParentID: 2212)
F:\Program Files (x86)\Skype\Phone\Skype.exe (ID: 956 |ParentID: 2212)
F:\Users\Luca\AppData\Roaming\.minecraft\MinecraftTweakerUpdater.exe (ID: 928 |ParentID: 2212)
C:\Program Files\Kooperativa\KoopPxBN\KoopPDFServerSA.exe (ID: 1864 |ParentID: 2212)
F:\Program Files (x86)\HP\ToolboxFX\bin\HPTLBXFX.exe (ID: 3268 |ParentID: 2020)
F:\Program Files (x86)\HP\HP Software Update\hpwuSchd2.exe (ID: 2100 |ParentID: 2020)
F:\Program Files (x86)\HP\HP UT\bin\hppusg.exe (ID: 2240 |ParentID: 2020)
F:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe (ID: 1592 |ParentID: 2020)
C:\Program Files\OpenOffice.org 3\program\soffice.exe (ID: 2024 |ParentID: 3276)
F:\Users\Public\MSJ-Driver-4532-56324-6224\winrsnbc.exe (ID: 1996 |ParentID: 476)
C:\Program Files\OpenOffice.org 3\program\soffice.bin (ID: 3864 |ParentID: 2024)
F:\Windows\System32\svchost.exe (ID: 2260 |ParentID: 500)
F:\Program Files (x86)\Google\Chrome\Application\chrome.exe (ID: 4812 |ParentID: 2212)
F:\Program Files (x86)\Google\Chrome\Application\chrome.exe (ID: 1572 |ParentID: 4812)
F:\Program Files (x86)\Google\Chrome\Application\chrome.exe (ID: 4944 |ParentID: 4812)
F:\Program Files (x86)\Google\Chrome\Application\chrome.exe (ID: 4496 |ParentID: 4812)
F:\Program Files (x86)\Google\Chrome\Application\chrome.exe (ID: 4504 |ParentID: 4812)
F:\Program Files (x86)\Google\Chrome\Application\chrome.exe (ID: 3988 |ParentID: 4812)
F:\Program Files (x86)\Google\Chrome\Application\chrome.exe (ID: 3248 |ParentID: 4812)
F:\Program Files (x86)\Google\Chrome\Application\chrome.exe (ID: 4820 |ParentID: 4812)
F:\Program Files (x86)\Google\Chrome\Application\chrome.exe (ID: 4320 |ParentID: 4812)
F:\Program Files (x86)\Google\Chrome\Application\chrome.exe (ID: 2896 |ParentID: 4812)
F:\Windows\System32\WUDFHost.exe (ID: 4152 |ParentID: 908)
F:\Program Files (x86)\Windows Media Player\wmplayer.exe (ID: 5092 |ParentID: 648)
F:\Program Files (x86)\Google\Chrome\Application\chrome.exe (ID: 3992 |ParentID: 4812)
F:\Program Files (x86)\Google\Chrome\Application\chrome.exe (ID: 3508 |ParentID: 4812)
F:\Windows\system32\SearchProtocolHost.exe (ID: 3408 |ParentID: 3660)
F:\Windows\system32\SearchFilterHost.exe (ID: 1512 |ParentID: 3660)
################## | Regedit Run |
04 - HKCU\..\Run : [BitTorrent] "F:\Program Files (x86)\BitTorrent\BitTorrent.exe" /MINIMIZED
04 - HKCU\..\Run : [SugarSync] "F:\Program Files (x86)\SugarSync\SugarSync.exe" -startInTray -usedelay=true
04 - HKCU\..\Run : [Skype] "F:\Program Files (x86)\Skype\Phone\Skype.exe" /minimized /regrun
04 - HKCU\..\Run : [Minecraft Tweaker Updater] F:\Users\Luca\AppData\Roaming\.minecraft\MinecraftTweakerUpdater.exe
04 - HKCU\..\Run : [AdobeBridge]
04 - HKCU\..\Run : [MicrosoftCFGDriver] F:\Users\Public\MSJ-Driver-4532-56324-6224\winrsnbc.exe
04 - HKLM\..\Run : [AdobeCS6ServiceManager] "F:\Program Files (x86)\Common Files\Adobe\CS6ServiceManager\CS6ServiceManager.exe" -launchedbylogin
04 - HKLM\..\Run : [ToolBoxFX] "F:\Program Files (x86)\HP\ToolBoxFX\bin\HPTLBXFX.exe" /enum:on /alerts:on /notifications:on /fl:on /fr:on /appData:on /tmcp:on
04 - HKLM\..\Run : [HP Software Update] F:\Program Files (x86)\HP\HP Software Update\HPWuSchd2.exe
04 - HKLM\..\Run : []
04 - HKLM\..\Run : [HPUsageTracking] "F:\Program Files (x86)\HP\HP UT\bin\hppusg.exe" "F:\Program Files (x86)\HP\HP UT\"
04 - HKLM\..\Run : [SunJavaUpdateSched] "F:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe"
04 - HKLM\..\RunOnce : []
04 - HKLM64\..\Run : [Autodesk Sync] F:\Program Files\Autodesk\Autodesk Sync\AdSync.exe
04 - HKLM64\..\Run : [AdobeAAMUpdater-1.0] "F:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe"
04 - HKLM64\..\Run : [MacrokeyManager] WTMKM.exe
04 - HKLM64\..\Run : [HP LaserJet M1522 MFP Series Fax] F:\Program Files (x86)\HP\hp LaserJet M1522\hppfaxprintersrv.exe "HP LaserJet M1522 MFP Series Fax"
04 - HKU\S-1-5-19\..\Run : [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun
04 - HKU\S-1-5-20\..\Run : [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun
04 - HKU\S-1-5-21-3704559939-2404346838-333775225-1001\..\Run : [BitTorrent] "F:\Program Files (x86)\BitTorrent\BitTorrent.exe" /MINIMIZED
04 - HKU\S-1-5-21-3704559939-2404346838-333775225-1001\..\Run : [SugarSync] "F:\Program Files (x86)\SugarSync\SugarSync.exe" -startInTray -usedelay=true
04 - HKU\S-1-5-21-3704559939-2404346838-333775225-1001\..\Run : [Skype] "F:\Program Files (x86)\Skype\Phone\Skype.exe" /minimized /regrun
04 - HKU\S-1-5-21-3704559939-2404346838-333775225-1001\..\Run : [Minecraft Tweaker Updater] F:\Users\Luca\AppData\Roaming\.minecraft\MinecraftTweakerUpdater.exe
04 - HKU\S-1-5-21-3704559939-2404346838-333775225-1001\..\Run : [AdobeBridge]
04 - HKU\S-1-5-21-3704559939-2404346838-333775225-1001\..\Run : [MicrosoftCFGDriver] F:\Users\Public\MSJ-Driver-4532-56324-6224\winrsnbc.exe
04 - HKU\S-1-5-19\..\RunOnce : [mctadmin] F:\Windows\System32\mctadmin.exe
04 - HKU\S-1-5-20\..\RunOnce : [mctadmin] F:\Windows\System32\mctadmin.exe
04 - HKU\S-1-5-18\..\RunOnce : [SPReview] "F:\Windows\System32\SPReview\SPReview.exe" /sp:1 /errorfwlink:"
http://go.microsoft.com/fwlink/?LinkID=122915" /build:7601
################## | Generic Research |
Found ! J:\Kalkula´torys.lnk
Found ! J:\Dancˇas.lnk
Found ! J:\Photoshops.lnk
Found ! J:\Governor.of.Poker.2.Premium.Edition.v1.7.multi6.cracked-THETAs.lnk
Found ! J:\IV. Rocˇni´ks.lnk
Found ! J:\Adobe Photoshop CS5 CZs.lnk
Found ! J:\USBs.lnk
Found ! J:\Dokumentys.lnk
Found ! J:\Pra´ces.lnk
Found ! J:\fotoss.lnk
Found ! J:\8585485
################## | Registry |
################## | E.O.F |
http://www.en.usbfix.net/ -
http://www.sosvirus.net |