Re: Extremne pomaly notebook (WIN 7)
Napsal: 04 úno 2012 14:56
############################## | UsbFix 7.059 | [Deletion]
User: Michal (Administrator) # MICHAL-PC [Hewlett-Packard HP Pavilion dv7 Notebook PC]
Updated 16/09/2011 by El Desaparecido
Started at 14:34:20 | 04/02/2012
Website: http://eldesaparecido.com
Submit your sample: http://eldesaparecido.com/support.php
Contact: contact@eldesaparecido.com
CPU: Intel(R) Core(TM)2 Duo CPU T6600 @ 2.20GHz
CPU 2: Intel(R) Core(TM)2 Duo CPU T6600 @ 2.20GHz
Microsoft Windows 7 Home Premium (6.1.7601 64-Bit) # Service Pack 1
Internet Explorer 9.0.8112.16421
Windows Firewall: Enabled
RAM -> 3069 Mb
C:\ (%systemdrive%) -> Fixed drive # 186 Gb (37 Mb free - 20%) [] # NTFS
E:\ -> CD-ROM
F:\ -> Fixed drive # 932 Gb (635 Mb free - 68%) [Transcend] # NTFS
################## | Files # Infected Folders |
Deleted ! C:\Aktualizovat ESET licenci.lnk
Deleted ! C:\$RECYCLE.BIN\S-1-5-21-2117403692-1824965856-2576885780-1001
Deleted ! F:\$RECYCLE.BIN\S-1-5-21-1246708047-709834187-3332473997-1000
Deleted ! F:\$RECYCLE.BIN\S-1-5-21-2117403692-1824965856-2576885780-1001
Deleted ! F:\$RECYCLE.BIN\S-1-5-21-2318351912-2155151090-1007949156-1000
Deleted ! F:\$RECYCLE.BIN\S-1-5-21-3304809216-3030257038-3387024096-1001
Deleted ! F:\Recycler\S-1-5-21-1220945662-515967899-725345543-1004
(!) Temporary files deleted.
################## | Registry |
Deleted ! HKLM\Software\Microsoft\Windows\CurrentVersion\Policies\System|DisableRegistryTools
Deleted ! HKLM\Software\Microsoft\Windows\CurrentVersion\Policies\explorer|NoDrives
Deleted ! HKCU\Software\Microsoft\Windows\CurrentVersion\Policies\explorer|NoDrives
################## | Mountpoints2 |
################## | Listing |
[04/02/2012 - 14:52:55 | SHD ] C:\$RECYCLE.BIN
[04/12/2011 - 13:22:37 | D ] C:\.Xilinx
[24/08/2011 - 09:27:12 | D ] C:\520bab0869dae5021f9174
[22/12/2010 - 10:07:58 | N | 132597] C:\aaw7boot.log
[24/08/2011 - 09:59:50 | D ] C:\AMD
[24/08/2011 - 10:02:30 | D ] C:\ATI
[27/07/2011 - 20:53:15 | D ] C:\boot
[20/11/2010 - 13:40:07 | RASH | 383786] C:\bootmgr
[04/02/2012 - 14:15:48 | N | 35214] C:\ComboFix.txt
[02/02/2012 - 10:52:21 | D ] C:\Config.Msi
[19/10/2011 - 03:10:34 | D ] C:\cygwin
[14/07/2009 - 06:08:56 | SHD ] C:\Documents and Settings
[27/06/2010 - 14:45:34 | D ] C:\found.000
[27/05/2011 - 19:12:09 | D ] C:\FPC
[25/08/2009 - 01:06:08 | D ] C:\HP
[28/05/2011 - 07:27:51 | D ] C:\lazarus
[08/11/2011 - 17:10:51 | N | 18321] C:\M1319.log
[28/12/2010 - 12:20:50 | D ] C:\MentorGraphics
[27/12/2011 - 00:03:16 | D ] C:\Michal
[12/10/2011 - 10:33:38 | D ] C:\MinGW
[23/09/2005 - 00:39:38 | N | 894976] C:\msdia80.dll
[05/01/2010 - 11:10:24 | RD ] C:\MSOCache
[02/12/2011 - 13:59:02 | D ] C:\mspgcc
[22/05/2010 - 17:02:25 | D ] C:\NLPIS
[04/02/2012 - 11:37:54 | ASH | 3218276352] C:\pagefile.sys
[14/07/2009 - 04:20:08 | D ] C:\PerfLogs
[03/02/2012 - 14:03:13 | D ] C:\Program Files
[04/02/2012 - 14:10:27 | D ] C:\Program Files (x86)
[31/01/2012 - 15:14:10 | D ] C:\ProgramData
[16/02/2010 - 20:53:27 | D ] C:\Python26
[06/07/2010 - 18:24:23 | D ] C:\Python30
[04/02/2012 - 14:15:51 | D ] C:\Qoobox
[05/01/2010 - 11:28:05 | D ] C:\Recovery
[03/02/2012 - 14:03:21 | D ] C:\rsit
[14/12/2011 - 10:26:01 | D ] C:\Skola
[05/04/2011 - 20:20:53 | D ] C:\SwSetup
[01/11/2010 - 18:39:26 | SHD ] C:\System Volume Information
[05/01/2010 - 11:28:15 | D ] C:\SYSTEM.SAV
[01/03/2011 - 10:07:39 | D ] C:\Temp
[27/05/2011 - 19:13:48 | D ] C:\TP
[04/02/2012 - 14:52:55 | D ] C:\UsbFix
[04/02/2012 - 14:34:22 | A | 817] C:\UsbFix.txt
[05/01/2010 - 11:08:11 | D ] C:\Users
[08/03/2010 - 17:36:29 | D ] C:\watcom-1.3
[04/02/2012 - 14:15:50 | D ] C:\Windows
[03/10/2011 - 12:30:27 | D ] C:\xampp
[04/12/2011 - 13:22:23 | D ] C:\Xilinx
[14/01/2012 - 08:29:24 | D ] C:\_AcroTemp
[04/02/2012 - 14:52:55 | D ] F:\$RECYCLE.BIN
[24/01/2012 - 09:40:34 | D ] F:\badea4850e90e37ec4124d
[03/02/2012 - 09:21:51 | D ] F:\Filmy
[07/01/2012 - 22:11:07 | D ] F:\Hudba
[03/02/2012 - 09:39:52 | D ] F:\Install
[08/12/2011 - 14:44:12 | D ] F:\ISA
[03/11/2011 - 20:29:25 | D ] F:\Itálie
[05/01/2002 - 03:38:38 | N | 54784] F:\msvci70.dll
[31/01/2012 - 14:41:06 | D ] F:\NFS
[19/09/2011 - 20:00:12 | D ] F:\old
[13/10/2011 - 08:36:11 | D ] F:\Prednasky
[20/01/2012 - 15:21:33 | D ] F:\RECYCLER
[15/10/2011 - 15:52:31 | SHD ] F:\System Volume Information
[29/01/2012 - 15:49:52 | D ] F:\Tancak
[22/01/2012 - 21:10:28 | N | 431647] F:\VirtualDJ Local Database v6.xml
[03/02/2012 - 18:08:53 | D ] F:\ZalohaMichalNtb
################## | Vaccin |
C:\Autorun.inf -> Vaccine created by UsbFix (TeamXscript)
F:\Autorun.inf -> Vaccine created by UsbFix (TeamXscript)
################## | Upload |
Please send the file: C:\UsbFix_Upload_Me_MICHAL-PC.zip
http://eldesaparecido.com/support.php
Thank you for your contribution.
################## | E.O.F |
User: Michal (Administrator) # MICHAL-PC [Hewlett-Packard HP Pavilion dv7 Notebook PC]
Updated 16/09/2011 by El Desaparecido
Started at 14:34:20 | 04/02/2012
Website: http://eldesaparecido.com
Submit your sample: http://eldesaparecido.com/support.php
Contact: contact@eldesaparecido.com
CPU: Intel(R) Core(TM)2 Duo CPU T6600 @ 2.20GHz
CPU 2: Intel(R) Core(TM)2 Duo CPU T6600 @ 2.20GHz
Microsoft Windows 7 Home Premium (6.1.7601 64-Bit) # Service Pack 1
Internet Explorer 9.0.8112.16421
Windows Firewall: Enabled
RAM -> 3069 Mb
C:\ (%systemdrive%) -> Fixed drive # 186 Gb (37 Mb free - 20%) [] # NTFS
E:\ -> CD-ROM
F:\ -> Fixed drive # 932 Gb (635 Mb free - 68%) [Transcend] # NTFS
################## | Files # Infected Folders |
Deleted ! C:\Aktualizovat ESET licenci.lnk
Deleted ! C:\$RECYCLE.BIN\S-1-5-21-2117403692-1824965856-2576885780-1001
Deleted ! F:\$RECYCLE.BIN\S-1-5-21-1246708047-709834187-3332473997-1000
Deleted ! F:\$RECYCLE.BIN\S-1-5-21-2117403692-1824965856-2576885780-1001
Deleted ! F:\$RECYCLE.BIN\S-1-5-21-2318351912-2155151090-1007949156-1000
Deleted ! F:\$RECYCLE.BIN\S-1-5-21-3304809216-3030257038-3387024096-1001
Deleted ! F:\Recycler\S-1-5-21-1220945662-515967899-725345543-1004
(!) Temporary files deleted.
################## | Registry |
Deleted ! HKLM\Software\Microsoft\Windows\CurrentVersion\Policies\System|DisableRegistryTools
Deleted ! HKLM\Software\Microsoft\Windows\CurrentVersion\Policies\explorer|NoDrives
Deleted ! HKCU\Software\Microsoft\Windows\CurrentVersion\Policies\explorer|NoDrives
################## | Mountpoints2 |
################## | Listing |
[04/02/2012 - 14:52:55 | SHD ] C:\$RECYCLE.BIN
[04/12/2011 - 13:22:37 | D ] C:\.Xilinx
[24/08/2011 - 09:27:12 | D ] C:\520bab0869dae5021f9174
[22/12/2010 - 10:07:58 | N | 132597] C:\aaw7boot.log
[24/08/2011 - 09:59:50 | D ] C:\AMD
[24/08/2011 - 10:02:30 | D ] C:\ATI
[27/07/2011 - 20:53:15 | D ] C:\boot
[20/11/2010 - 13:40:07 | RASH | 383786] C:\bootmgr
[04/02/2012 - 14:15:48 | N | 35214] C:\ComboFix.txt
[02/02/2012 - 10:52:21 | D ] C:\Config.Msi
[19/10/2011 - 03:10:34 | D ] C:\cygwin
[14/07/2009 - 06:08:56 | SHD ] C:\Documents and Settings
[27/06/2010 - 14:45:34 | D ] C:\found.000
[27/05/2011 - 19:12:09 | D ] C:\FPC
[25/08/2009 - 01:06:08 | D ] C:\HP
[28/05/2011 - 07:27:51 | D ] C:\lazarus
[08/11/2011 - 17:10:51 | N | 18321] C:\M1319.log
[28/12/2010 - 12:20:50 | D ] C:\MentorGraphics
[27/12/2011 - 00:03:16 | D ] C:\Michal
[12/10/2011 - 10:33:38 | D ] C:\MinGW
[23/09/2005 - 00:39:38 | N | 894976] C:\msdia80.dll
[05/01/2010 - 11:10:24 | RD ] C:\MSOCache
[02/12/2011 - 13:59:02 | D ] C:\mspgcc
[22/05/2010 - 17:02:25 | D ] C:\NLPIS
[04/02/2012 - 11:37:54 | ASH | 3218276352] C:\pagefile.sys
[14/07/2009 - 04:20:08 | D ] C:\PerfLogs
[03/02/2012 - 14:03:13 | D ] C:\Program Files
[04/02/2012 - 14:10:27 | D ] C:\Program Files (x86)
[31/01/2012 - 15:14:10 | D ] C:\ProgramData
[16/02/2010 - 20:53:27 | D ] C:\Python26
[06/07/2010 - 18:24:23 | D ] C:\Python30
[04/02/2012 - 14:15:51 | D ] C:\Qoobox
[05/01/2010 - 11:28:05 | D ] C:\Recovery
[03/02/2012 - 14:03:21 | D ] C:\rsit
[14/12/2011 - 10:26:01 | D ] C:\Skola
[05/04/2011 - 20:20:53 | D ] C:\SwSetup
[01/11/2010 - 18:39:26 | SHD ] C:\System Volume Information
[05/01/2010 - 11:28:15 | D ] C:\SYSTEM.SAV
[01/03/2011 - 10:07:39 | D ] C:\Temp
[27/05/2011 - 19:13:48 | D ] C:\TP
[04/02/2012 - 14:52:55 | D ] C:\UsbFix
[04/02/2012 - 14:34:22 | A | 817] C:\UsbFix.txt
[05/01/2010 - 11:08:11 | D ] C:\Users
[08/03/2010 - 17:36:29 | D ] C:\watcom-1.3
[04/02/2012 - 14:15:50 | D ] C:\Windows
[03/10/2011 - 12:30:27 | D ] C:\xampp
[04/12/2011 - 13:22:23 | D ] C:\Xilinx
[14/01/2012 - 08:29:24 | D ] C:\_AcroTemp
[04/02/2012 - 14:52:55 | D ] F:\$RECYCLE.BIN
[24/01/2012 - 09:40:34 | D ] F:\badea4850e90e37ec4124d
[03/02/2012 - 09:21:51 | D ] F:\Filmy
[07/01/2012 - 22:11:07 | D ] F:\Hudba
[03/02/2012 - 09:39:52 | D ] F:\Install
[08/12/2011 - 14:44:12 | D ] F:\ISA
[03/11/2011 - 20:29:25 | D ] F:\Itálie
[05/01/2002 - 03:38:38 | N | 54784] F:\msvci70.dll
[31/01/2012 - 14:41:06 | D ] F:\NFS
[19/09/2011 - 20:00:12 | D ] F:\old
[13/10/2011 - 08:36:11 | D ] F:\Prednasky
[20/01/2012 - 15:21:33 | D ] F:\RECYCLER
[15/10/2011 - 15:52:31 | SHD ] F:\System Volume Information
[29/01/2012 - 15:49:52 | D ] F:\Tancak
[22/01/2012 - 21:10:28 | N | 431647] F:\VirtualDJ Local Database v6.xml
[03/02/2012 - 18:08:53 | D ] F:\ZalohaMichalNtb
################## | Vaccin |
C:\Autorun.inf -> Vaccine created by UsbFix (TeamXscript)
F:\Autorun.inf -> Vaccine created by UsbFix (TeamXscript)
################## | Upload |
Please send the file: C:\UsbFix_Upload_Me_MICHAL-PC.zip
http://eldesaparecido.com/support.php
Thank you for your contribution.
################## | E.O.F |