Re: LNK/Agent.AK
Napsal: 18 črc 2014 23:37
Posílám log z USBFix:
UsbFix V 7.134 | [Deletion]
User: Milan (Administrator) # MILAN-PC
Updated 06/09/2013 by El Desaparecido
Started at 00:49:59 | 19/07/2014
Website: http://www.sosvirus.net/
Upload Malware: http://www.sosvirus.net/upload_malware.php
Contact: eldesaparecido@sosvirus.net
PC: MICRO-STAR INTERNATIONAL CO., LTD (MS-7125) (X86-based PC)
CPU: AMD Athlon(tm) 64 Processor 3000+ (1808)
RAM -> [Total : 2048 | Free : 1058]
BIOS: Phoenix - AwardBIOS v6.00PG
BOOT: Normal boot
OS: Microsoft Windows 7 Professional (6.1.7601 32-Bit) # Service Pack 1
WB: Windows Internet Explorer 11.0.9600.17207
SC: Security Center Service [Enabled]
WU: Windows Update Service [Enabled]
AV: ESET Smart Security 7.0 [(!) Disabled | Updated]
FW: Windows FireWall Service [Enabled]
A:\ -> Removable drive # 1 Mb (1 Mb free - 84%) [] # FAT
C:\ (%systemdrive%) -> Fixed drive # 75 Gb (11 Mb free - 14%) [] # NTFS
D:\ -> CD-ROM
E:\ -> Fixed drive # 596 Gb (62 Mb free - 10%) [Sklad-640GB] # NTFS
F:\ -> Fixed drive # 149 Gb (9 Mb free - 6%) [Místní disk-160GB] # NTFS
G:\ -> Fixed drive # 298 Gb (6 Mb free - 2%) [Místní disk-320GB] # NTFS
H:\ -> Removable drive # 4 Gb (4 Mb free - 100%) [] # FAT32
I:\ -> Fixed drive # 931 Gb (2 Mb free - 0%) [My Passport] # NTFS
J:\ -> Removable drive # 7 Gb (7 Mb free - 100%) [USB DISK] # FAT32
K:\ -> Removable drive # 4 Gb (1 Mb free - 33%) [KINGSTON] # FAT32
################## | El Desaparecido Section |
HKLM\SOFTWARE | Run : [CTxfiHlp] - CTXFIHLP.EXE
HKLM\SOFTWARE | Run : [NVRaidService] - C:\Program Files\NVIDIA Corporation\Raid\nvraidservice.exe
HKLM\SOFTWARE | Run : [SoundMan] - SOUNDMAN.EXE
HKLM\SOFTWARE | Run : [PAC7302_Monitor] - C:\Windows\PixArt\PAC7302\Monitor.exe
HKLM\SOFTWARE | Run : [StartCCC] - "C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" MSRun
HKLM\SOFTWARE | Run : [GrooveMonitor] - "C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe"
HKLM\SOFTWARE | Run : [LifeCam] - "C:\Program Files\Microsoft LifeCam\LifeExp.exe"
HKLM\SOFTWARE | Run : [APSDaemon] - "C:\Program Files\Common Files\Apple\Apple Application Support\APSDaemon.exe"
HKLM\SOFTWARE | Run : [egui] - "C:\Program Files\ESET\ESET Smart Security\egui.exe" /hide /waitservice
HKLM\SOFTWARE | Run : [Logitech Utility] - Logi_MwX.Exe
HKLM\SOFTWARE | RunOnce : [] -
HKU\S-1-5-19\SOFTWARE | Run : [Sidebar] - %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun
HKU\S-1-5-20\SOFTWARE | Run : [Sidebar] - %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun
HKU\S-1-5-21-2536137262-3142679929-2204209605-1000\SOFTWARE | Run : [Sidebar] - C:\Program Files\Windows Sidebar\sidebar.exe /autoRun
HKU\S-1-5-21-2536137262-3142679929-2204209605-1000\SOFTWARE | Run : [Clock Widget (HTC Home)] - "C:\Program Files\HTC Home\Clock.exe"
HKU\S-1-5-21-2536137262-3142679929-2204209605-1000\SOFTWARE | Run : [IDMan] - C:\Program Files\Internet Download Manager\IDMan.exe /onboot
HKU\S-1-5-18\SOFTWARE | Run : [GarminExpressTrayApp] - "C:\Program Files\Garmin\Express Tray\ExpressTray.exe"
HKU\S-1-5-19\SOFTWARE | RunOnce : [mctadmin] - C:\Windows\System32\mctadmin.exe
HKU\S-1-5-20\SOFTWARE | RunOnce : [mctadmin] - C:\Windows\System32\mctadmin.exe
################## | Stopped processes |
Stopped! C:\Program Files\ESET\ESET Smart Security\ekrn.exe (1888)
Stopped! C:\Program Files\ESET\ESET Smart Security\egui.exe (3772)
Stopped! C:\Windows\System32\WUDFHost.exe (692)
Stopped! C:\Windows\System32\rundll32.exe (4160)
Stopped! C:\Windows\system32\SearchIndexer.exe (2640)
Stopped! C:\Windows\System32\spoolsv.exe (1928)
Stopped! C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe (2076)
Stopped! C:\Program Files\Garmin\Core Update Service\Garmin.Cartography.MapUpdate.CoreService.exe (5440)
Stopped! C:\Windows\system32\DllHost.exe (3492)
Stopped! c:\program files\windows defender\MpCmdRun.exe (1848)
Stopped! C:\Windows\system32\SearchProtocolHost.exe (2280)
Stopped! C:\Windows\system32\SearchFilterHost.exe (3904)
################## | Files # Infected Folders |
Deleted ! A:\autoactivation.vbs
Deleted ! H:\autoactivation.vbs
(!) Temporary files deleted.
################## | Registry |
################## | Mountpoints2 |
################## | Listing |
[12/10/2013 - 03:15:50 | N | 141824] A:\wscript.exe
[08/05/2014 - 08:36:50 | N | 4630] A:\KROJZL_MILAN_ING.p12
[07/07/2012 - 15:35:30 | D ] A:\stare certifikaty
[30/07/2013 - 18:27:04 | SHD ] C:\$Recycle.Bin
[01/09/2013 - 13:58:19 | D ] C:\Autodesk
[10/06/2009 - 23:42:20 | N | 24] C:\autoexec.bat
[19/07/2014 - 00:26:40 | RASHD ] C:\Autorun.inf
[30/06/2014 - 21:02:57 | SHD ] C:\Boot
[20/11/2010 - 14:40:07 | RASH | 383786] C:\bootmgr
[30/07/2013 - 19:08:11 | N | 8192] C:\BOOTSECT.BAK
[05/02/2014 - 21:40:53 | D ] C:\Brother's Keeper 6
[17/12/1993 - 01:11:10 | N | 94720] C:\CARDFILE.EXE
[10/06/2009 - 23:42:20 | N | 10] C:\config.sys
[14/07/2009 - 06:53:55 | SHD ] C:\Documents and Settings
[07/11/2007 - 08:00:40 | N | 17734] C:\eula.1028.txt
[07/11/2007 - 08:00:40 | N | 17734] C:\eula.1031.txt
[07/11/2007 - 08:00:40 | N | 10134] C:\eula.1033.txt
[07/11/2007 - 08:00:40 | N | 17734] C:\eula.1036.txt
[07/11/2007 - 08:00:40 | N | 17734] C:\eula.1040.txt
[07/11/2007 - 08:00:40 | N | 118] C:\eula.1041.txt
[07/11/2007 - 08:00:40 | N | 17734] C:\eula.1042.txt
[07/11/2007 - 08:00:40 | N | 17734] C:\eula.2052.txt
[07/11/2007 - 08:00:40 | N | 17734] C:\eula.3082.txt
[18/07/2014 - 22:29:34 | D ] C:\FRST
[11/08/2013 - 00:02:35 | D ] C:\Garmin
[07/11/2007 - 08:00:40 | N | 1110] C:\globdata.ini
[18/07/2014 - 22:28:32 | ASH | 1610260480] C:\hiberfil.sys
[17/08/2013 - 08:23:54 | D ] C:\Install
[07/11/2007 - 08:03:18 | N | 562688] C:\install.exe
[07/11/2007 - 08:00:40 | N | 843] C:\install.ini
[07/11/2007 - 08:03:18 | N | 76304] C:\install.res.1028.dll
[07/11/2007 - 08:03:18 | N | 96272] C:\install.res.1031.dll
[07/11/2007 - 08:03:18 | N | 91152] C:\install.res.1033.dll
[07/11/2007 - 08:03:18 | N | 97296] C:\install.res.1036.dll
[07/11/2007 - 08:03:18 | N | 95248] C:\install.res.1040.dll
[07/11/2007 - 08:03:18 | N | 81424] C:\install.res.1041.dll
[07/11/2007 - 08:03:18 | N | 79888] C:\install.res.1042.dll
[07/11/2007 - 08:03:18 | N | 75792] C:\install.res.2052.dll
[07/11/2007 - 08:03:18 | N | 96272] C:\install.res.3082.dll
[07/08/2013 - 23:08:04 | N | 0] C:\IO.SYS
[15/03/2014 - 01:29:14 | N | 415] C:\LOGFILE.TXT
[07/08/2013 - 23:08:04 | N | 0] C:\MSDOS.SYS
[10/08/2013 - 16:44:37 | RHD ] C:\MSOCache
[30/07/2013 - 18:24:46 | N | 374434] C:\NTHFV
[18/07/2014 - 22:28:34 | ASH | 2147016704] C:\pagefile.sys
[14/07/2009 - 04:37:05 | D ] C:\PerfLogs
[18/07/2014 - 22:24:20 | D ] C:\Program Files
[18/07/2014 - 22:13:21 | HD ] C:\ProgramData
[30/07/2013 - 18:24:44 | SHD ] C:\Recovery
[18/07/2014 - 21:53:56 | SHD ] C:\System Volume Information
[19/07/2014 - 00:52:05 | D ] C:\UsbFix
[19/07/2014 - 00:26:41 | N | 16315] C:\UsbFix [Clean 1] MILAN-PC.txt
[19/07/2014 - 00:52:31 | A | 7110] C:\UsbFix [Clean 2] MILAN-PC.txt
[30/07/2013 - 18:26:51 | D ] C:\Users
[07/11/2007 - 08:00:40 | N | 5686] C:\vcredist.bmp
[07/11/2007 - 08:09:22 | N | 1442522] C:\VC_RED.cab
[07/11/2007 - 08:12:28 | N | 232960] C:\VC_RED.MSI
[18/07/2014 - 19:28:37 | D ] C:\Windows
[30/07/2013 - 18:24:46 | N | 20] C:\winx.ld
[01/09/2013 - 20:37:50 | D ] C:\_Záloha
[17/07/2014 - 17:39:27 | SHDC ] E:\$RECYCLE.BIN
[19/07/2014 - 00:26:40 | RASHDC ] E:\Autorun.inf
[18/05/2014 - 21:46:27 | DC ] E:\Filmy
[14/07/2014 - 16:55:09 | DC ] E:\Filmy_duchovní
[11/05/2014 - 23:16:57 | DC ] E:\Milan
[16/01/2010 - 12:56:07 | SHD ] E:\System Volume Information
[25/03/2013 - 07:08:03 | DC ] E:\Vesmír
[02/04/2014 - 14:23:16 | SHD ] F:\$RECYCLE.BIN
[20/06/2012 - 18:29:20 | N | 0] F:\AUTOEXEC.BAT
[19/07/2014 - 00:26:40 | RASHD ] F:\Autorun.inf
[29/07/2013 - 18:55:23 | N | 238] F:\boot.ini
[24/03/2013 - 20:56:45 | N | 211] F:\boot.iniiiiii
[02/08/2007 - 14:00:00 | N | 4952] F:\Bootfont.bin
[27/10/2012 - 21:11:19 | D ] F:\Brother's Keeper 6
[17/12/1993 - 03:11:10 | N | 94720] F:\CARDFILE.EXE
[20/07/2013 - 23:18:06 | D ] F:\Config.Msi
[20/06/2012 - 18:29:20 | N | 0] F:\CONFIG.SYS
[10/08/2013 - 16:32:16 | D ] F:\Documents and Settings
[05/01/2014 - 14:13:29 | D ] F:\Dokumenty
[03/11/2013 - 00:16:24 | D ] F:\Downloads
[13/09/2012 - 22:15:25 | N | 190] F:\drwtsn32.log
[07/11/2007 - 08:00:40 | N | 17734] F:\eula.1028.txt
[07/11/2007 - 08:00:40 | N | 17734] F:\eula.1031.txt
[07/11/2007 - 08:00:40 | N | 10134] F:\eula.1033.txt
[07/11/2007 - 08:00:40 | N | 17734] F:\eula.1036.txt
[07/11/2007 - 08:00:40 | N | 17734] F:\eula.1040.txt
[07/11/2007 - 08:00:40 | N | 118] F:\eula.1041.txt
[07/11/2007 - 08:00:40 | N | 17734] F:\eula.1042.txt
[07/11/2007 - 08:00:40 | N | 17734] F:\eula.2052.txt
[07/11/2007 - 08:00:40 | N | 17734] F:\eula.3082.txt
[29/12/2012 - 11:22:29 | D ] F:\found.000
[10/07/2014 - 22:37:06 | D ] F:\Garmin
[07/11/2007 - 08:00:40 | N | 1110] F:\globdata.ini
[07/11/2007 - 08:03:18 | N | 562688] F:\install.exe
[07/11/2007 - 08:00:40 | N | 843] F:\install.ini
[07/11/2007 - 08:03:18 | N | 76304] F:\install.res.1028.dll
[07/11/2007 - 08:03:18 | N | 96272] F:\install.res.1031.dll
[07/11/2007 - 08:03:18 | N | 91152] F:\install.res.1033.dll
[07/11/2007 - 08:03:18 | N | 97296] F:\install.res.1036.dll
[07/11/2007 - 08:03:18 | N | 95248] F:\install.res.1040.dll
[07/11/2007 - 08:03:18 | N | 81424] F:\install.res.1041.dll
[07/11/2007 - 08:03:18 | N | 79888] F:\install.res.1042.dll
[07/11/2007 - 08:03:18 | N | 75792] F:\install.res.2052.dll
[07/11/2007 - 08:03:18 | N | 96272] F:\install.res.3082.dll
[20/06/2012 - 18:29:20 | N | 0] F:\IO.SYS
[17/10/2012 - 20:25:07 | N | 0] F:\KbList.txt
[28/11/2012 - 22:16:57 | N | 3145] F:\LOGFILE.TXT
[20/06/2012 - 18:29:20 | N | 0] F:\MSDOS.SYS
[25/06/2012 - 22:12:23 | RHD ] F:\MSOCache
[13/04/2008 - 22:13:04 | N | 47564] F:\NTDETECT.COM
[14/04/2008 - 00:01:48 | N | 250576] F:\ntldr
[19/06/2013 - 20:34:02 | N | 57632] F:\PA7302.DAT
[29/07/2013 - 20:41:51 | N | 120586240] F:\PAGEFILE.SYS
[30/12/2013 - 22:35:46 | D ] F:\Program Files
[24/06/2012 - 22:26:40 | SHD ] F:\RECYCLER
[06/08/2012 - 12:39:32 | N | 85882] F:\SROUBY.CRD
[02/11/2013 - 21:46:28 | D ] F:\Sygic
[20/06/2012 - 18:34:43 | SHD ] F:\System Volume Information
[08/12/2012 - 09:02:23 | N | 50] F:\user.js
[07/11/2007 - 08:00:40 | N | 5686] F:\vcredist.bmp
[07/11/2007 - 08:09:22 | N | 1442522] F:\VC_RED.cab
[07/11/2007 - 08:12:28 | N | 232960] F:\VC_RED.MSI
[12/01/2013 - 21:24:37 | DC ] G:\!Dokumenty
[04/05/2014 - 00:00:09 | SHDC ] G:\$RECYCLE.BIN
[05/02/2012 - 17:48:50 | DC ] G:\4583ecfc210a97d9b15eccf78864
[14/05/2014 - 21:37:24 | DC ] G:\aaa
[21/06/2012 - 03:04:48 | DC ] G:\Any Converters
[17/05/2014 - 18:56:36 | DC ] G:\Arakain
[18/07/2014 - 19:21:24 | DC ] G:\Autodesk
[19/07/2014 - 00:26:40 | RASHDC ] G:\Autorun.inf
[17/05/2014 - 18:59:31 | DC ] G:\Boogie-Woogie
[20/02/2012 - 23:12:35 | DC ] G:\Brother's Keeper 6
[12/01/2013 - 21:15:50 | DC ] G:\Bývalé disky_C
[31/12/2013 - 15:21:18 | DC ] G:\Chata Kameňák
[31/12/2013 - 13:17:02 | DC ] G:\Cigánski diabli
[31/12/2013 - 14:01:22 | DC ] G:\Cikáni-jdou-do-nebe
[31/12/2013 - 13:28:56 | DC ] G:\Cimbálová muzika Moravia
[14/05/2014 - 21:36:02 | DC ] G:\Dokumenty
[18/07/2014 - 19:22:30 | DC ] G:\Downloads
[31/12/2013 - 14:00:12 | DC ] G:\FaLun_KungFu
[11/05/2014 - 21:53:52 | DC ] G:\Filmy
[12/01/2014 - 01:25:23 | DC ] G:\Install
[09/07/2014 - 16:00:09 | DC ] G:\Kontrabas
[14/05/2014 - 21:45:55 | DC ] G:\Letadla
[11/05/2014 - 23:18:43 | DC ] G:\Milan
[31/12/2013 - 15:26:52 | DC ] G:\Náramek
[14/05/2014 - 21:39:14 | DC ] G:\Náramek-Hanka
[08/08/2013 - 21:29:19 | DC ] G:\PCTeacher
[17/03/2014 - 18:55:51 | DC ] G:\PCTranslator
[13/01/2014 - 22:43:30 | DC ] G:\Pole
[17/02/2013 - 17:31:56 | RDC ] G:\Program Files-Smazat!!!!!!
[21/06/2012 - 00:55:32 | DC ] G:\Průkazové foto
[24/06/2012 - 22:47:35 | SHDC ] G:\RECYCLER
[14/05/2014 - 21:39:14 | DC ] G:\Sbor
[04/02/2012 - 18:22:47 | SHD ] G:\System Volume Information
[14/02/2014 - 17:54:00 | DC ] G:\The Universe
[31/12/2013 - 13:21:43 | DC ] G:\Tragacnice---generálka-výběr_2
[31/12/2013 - 01:20:16 | DC ] G:\Translat
[21/04/2013 - 15:37:11 | DC ] G:\Vaření - Tim Ferriss
[25/02/2012 - 16:16:39 | DC ] G:\WinFast WorkArea
[11/05/2014 - 22:19:48 | DC ] G:\Záloha
[29/01/2013 - 23:36:20 | DC ] G:\česká-škola-lyžování---běžky
[07/07/2012 - 15:35:30 | D ] H:\stare certifikaty
[08/05/2014 - 08:36:50 | N | 4630] H:\KROJZL_MILAN_ING.p12
[16/07/2014 - 10:22:57 | SHD ] I:\$RECYCLE.BIN
[04/05/2014 - 17:02:23 | D ] I:\1. Fotky - pořádek
[04/05/2014 - 17:01:40 | D ] I:\2. Hanka
[08/05/2014 - 23:12:04 | D ] I:\3. Milan
[04/05/2014 - 16:51:37 | D ] I:\4. Společné
[19/07/2014 - 00:26:41 | RASHD ] I:\Autorun.inf
[08/07/2014 - 07:20:51 | D ] I:\MAA
[07/07/2014 - 13:54:15 | D ] I:\Prezentace
[04/05/2014 - 16:38:30 | SHD ] I:\RECYCLER
[08/07/2014 - 11:40:23 | SHD ] I:\System Volume Information
[10/03/2011 - 00:43:50 | N | 3290480] I:\WD Quick Formatter.exe
[10/03/2011 - 00:43:44 | N | 4246384] I:\WD SmartWare.exe
[19/07/2014 - 00:26:42 | RASHD ] J:\Autorun.inf
[05/09/2013 - 20:40:12 | D ] K:\Videokurz Revoluční cvičení 6ti minutovka
[09/10/2013 - 12:27:52 | D ] K:\Kontrabas-old
[10/10/2013 - 16:59:04 | N | 18231] K:\Přehled - banky k 10.10.2013.xlsx
[24/10/2013 - 05:57:58 | D ] K:\Kontrabas
[29/06/2014 - 11:17:42 | D ] K:\50 Acoustic Blues licks you must know
[19/07/2014 - 00:26:42 | RASHD ] K:\Autorun.inf
################## | Vaccin |
A:\Autorun.inf -> Vaccine created by UsbFix (El Desaparecido)
C:\Autorun.inf -> Vaccine created by UsbFix (El Desaparecido)
E:\Autorun.inf -> Vaccine created by UsbFix (El Desaparecido)
F:\Autorun.inf -> Vaccine created by UsbFix (El Desaparecido)
G:\Autorun.inf -> Vaccine created by UsbFix (El Desaparecido)
H:\Autorun.inf -> Vaccine created by UsbFix (El Desaparecido)
I:\Autorun.inf -> Vaccine created by UsbFix (El Desaparecido)
J:\Autorun.inf -> Vaccine created by UsbFix (El Desaparecido)
K:\Autorun.inf -> Vaccine created by UsbFix (El Desaparecido)
################## | E.O.F | http://www.sosvirus.net |
UsbFix V 7.134 | [Deletion]
User: Milan (Administrator) # MILAN-PC
Updated 06/09/2013 by El Desaparecido
Started at 00:49:59 | 19/07/2014
Website: http://www.sosvirus.net/
Upload Malware: http://www.sosvirus.net/upload_malware.php
Contact: eldesaparecido@sosvirus.net
PC: MICRO-STAR INTERNATIONAL CO., LTD (MS-7125) (X86-based PC)
CPU: AMD Athlon(tm) 64 Processor 3000+ (1808)
RAM -> [Total : 2048 | Free : 1058]
BIOS: Phoenix - AwardBIOS v6.00PG
BOOT: Normal boot
OS: Microsoft Windows 7 Professional (6.1.7601 32-Bit) # Service Pack 1
WB: Windows Internet Explorer 11.0.9600.17207
SC: Security Center Service [Enabled]
WU: Windows Update Service [Enabled]
AV: ESET Smart Security 7.0 [(!) Disabled | Updated]
FW: Windows FireWall Service [Enabled]
A:\ -> Removable drive # 1 Mb (1 Mb free - 84%) [] # FAT
C:\ (%systemdrive%) -> Fixed drive # 75 Gb (11 Mb free - 14%) [] # NTFS
D:\ -> CD-ROM
E:\ -> Fixed drive # 596 Gb (62 Mb free - 10%) [Sklad-640GB] # NTFS
F:\ -> Fixed drive # 149 Gb (9 Mb free - 6%) [Místní disk-160GB] # NTFS
G:\ -> Fixed drive # 298 Gb (6 Mb free - 2%) [Místní disk-320GB] # NTFS
H:\ -> Removable drive # 4 Gb (4 Mb free - 100%) [] # FAT32
I:\ -> Fixed drive # 931 Gb (2 Mb free - 0%) [My Passport] # NTFS
J:\ -> Removable drive # 7 Gb (7 Mb free - 100%) [USB DISK] # FAT32
K:\ -> Removable drive # 4 Gb (1 Mb free - 33%) [KINGSTON] # FAT32
################## | El Desaparecido Section |
HKLM\SOFTWARE | Run : [CTxfiHlp] - CTXFIHLP.EXE
HKLM\SOFTWARE | Run : [NVRaidService] - C:\Program Files\NVIDIA Corporation\Raid\nvraidservice.exe
HKLM\SOFTWARE | Run : [SoundMan] - SOUNDMAN.EXE
HKLM\SOFTWARE | Run : [PAC7302_Monitor] - C:\Windows\PixArt\PAC7302\Monitor.exe
HKLM\SOFTWARE | Run : [StartCCC] - "C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" MSRun
HKLM\SOFTWARE | Run : [GrooveMonitor] - "C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe"
HKLM\SOFTWARE | Run : [LifeCam] - "C:\Program Files\Microsoft LifeCam\LifeExp.exe"
HKLM\SOFTWARE | Run : [APSDaemon] - "C:\Program Files\Common Files\Apple\Apple Application Support\APSDaemon.exe"
HKLM\SOFTWARE | Run : [egui] - "C:\Program Files\ESET\ESET Smart Security\egui.exe" /hide /waitservice
HKLM\SOFTWARE | Run : [Logitech Utility] - Logi_MwX.Exe
HKLM\SOFTWARE | RunOnce : [] -
HKU\S-1-5-19\SOFTWARE | Run : [Sidebar] - %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun
HKU\S-1-5-20\SOFTWARE | Run : [Sidebar] - %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun
HKU\S-1-5-21-2536137262-3142679929-2204209605-1000\SOFTWARE | Run : [Sidebar] - C:\Program Files\Windows Sidebar\sidebar.exe /autoRun
HKU\S-1-5-21-2536137262-3142679929-2204209605-1000\SOFTWARE | Run : [Clock Widget (HTC Home)] - "C:\Program Files\HTC Home\Clock.exe"
HKU\S-1-5-21-2536137262-3142679929-2204209605-1000\SOFTWARE | Run : [IDMan] - C:\Program Files\Internet Download Manager\IDMan.exe /onboot
HKU\S-1-5-18\SOFTWARE | Run : [GarminExpressTrayApp] - "C:\Program Files\Garmin\Express Tray\ExpressTray.exe"
HKU\S-1-5-19\SOFTWARE | RunOnce : [mctadmin] - C:\Windows\System32\mctadmin.exe
HKU\S-1-5-20\SOFTWARE | RunOnce : [mctadmin] - C:\Windows\System32\mctadmin.exe
################## | Stopped processes |
Stopped! C:\Program Files\ESET\ESET Smart Security\ekrn.exe (1888)
Stopped! C:\Program Files\ESET\ESET Smart Security\egui.exe (3772)
Stopped! C:\Windows\System32\WUDFHost.exe (692)
Stopped! C:\Windows\System32\rundll32.exe (4160)
Stopped! C:\Windows\system32\SearchIndexer.exe (2640)
Stopped! C:\Windows\System32\spoolsv.exe (1928)
Stopped! C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe (2076)
Stopped! C:\Program Files\Garmin\Core Update Service\Garmin.Cartography.MapUpdate.CoreService.exe (5440)
Stopped! C:\Windows\system32\DllHost.exe (3492)
Stopped! c:\program files\windows defender\MpCmdRun.exe (1848)
Stopped! C:\Windows\system32\SearchProtocolHost.exe (2280)
Stopped! C:\Windows\system32\SearchFilterHost.exe (3904)
################## | Files # Infected Folders |
Deleted ! A:\autoactivation.vbs
Deleted ! H:\autoactivation.vbs
(!) Temporary files deleted.
################## | Registry |
################## | Mountpoints2 |
################## | Listing |
[12/10/2013 - 03:15:50 | N | 141824] A:\wscript.exe
[08/05/2014 - 08:36:50 | N | 4630] A:\KROJZL_MILAN_ING.p12
[07/07/2012 - 15:35:30 | D ] A:\stare certifikaty
[30/07/2013 - 18:27:04 | SHD ] C:\$Recycle.Bin
[01/09/2013 - 13:58:19 | D ] C:\Autodesk
[10/06/2009 - 23:42:20 | N | 24] C:\autoexec.bat
[19/07/2014 - 00:26:40 | RASHD ] C:\Autorun.inf
[30/06/2014 - 21:02:57 | SHD ] C:\Boot
[20/11/2010 - 14:40:07 | RASH | 383786] C:\bootmgr
[30/07/2013 - 19:08:11 | N | 8192] C:\BOOTSECT.BAK
[05/02/2014 - 21:40:53 | D ] C:\Brother's Keeper 6
[17/12/1993 - 01:11:10 | N | 94720] C:\CARDFILE.EXE
[10/06/2009 - 23:42:20 | N | 10] C:\config.sys
[14/07/2009 - 06:53:55 | SHD ] C:\Documents and Settings
[07/11/2007 - 08:00:40 | N | 17734] C:\eula.1028.txt
[07/11/2007 - 08:00:40 | N | 17734] C:\eula.1031.txt
[07/11/2007 - 08:00:40 | N | 10134] C:\eula.1033.txt
[07/11/2007 - 08:00:40 | N | 17734] C:\eula.1036.txt
[07/11/2007 - 08:00:40 | N | 17734] C:\eula.1040.txt
[07/11/2007 - 08:00:40 | N | 118] C:\eula.1041.txt
[07/11/2007 - 08:00:40 | N | 17734] C:\eula.1042.txt
[07/11/2007 - 08:00:40 | N | 17734] C:\eula.2052.txt
[07/11/2007 - 08:00:40 | N | 17734] C:\eula.3082.txt
[18/07/2014 - 22:29:34 | D ] C:\FRST
[11/08/2013 - 00:02:35 | D ] C:\Garmin
[07/11/2007 - 08:00:40 | N | 1110] C:\globdata.ini
[18/07/2014 - 22:28:32 | ASH | 1610260480] C:\hiberfil.sys
[17/08/2013 - 08:23:54 | D ] C:\Install
[07/11/2007 - 08:03:18 | N | 562688] C:\install.exe
[07/11/2007 - 08:00:40 | N | 843] C:\install.ini
[07/11/2007 - 08:03:18 | N | 76304] C:\install.res.1028.dll
[07/11/2007 - 08:03:18 | N | 96272] C:\install.res.1031.dll
[07/11/2007 - 08:03:18 | N | 91152] C:\install.res.1033.dll
[07/11/2007 - 08:03:18 | N | 97296] C:\install.res.1036.dll
[07/11/2007 - 08:03:18 | N | 95248] C:\install.res.1040.dll
[07/11/2007 - 08:03:18 | N | 81424] C:\install.res.1041.dll
[07/11/2007 - 08:03:18 | N | 79888] C:\install.res.1042.dll
[07/11/2007 - 08:03:18 | N | 75792] C:\install.res.2052.dll
[07/11/2007 - 08:03:18 | N | 96272] C:\install.res.3082.dll
[07/08/2013 - 23:08:04 | N | 0] C:\IO.SYS
[15/03/2014 - 01:29:14 | N | 415] C:\LOGFILE.TXT
[07/08/2013 - 23:08:04 | N | 0] C:\MSDOS.SYS
[10/08/2013 - 16:44:37 | RHD ] C:\MSOCache
[30/07/2013 - 18:24:46 | N | 374434] C:\NTHFV
[18/07/2014 - 22:28:34 | ASH | 2147016704] C:\pagefile.sys
[14/07/2009 - 04:37:05 | D ] C:\PerfLogs
[18/07/2014 - 22:24:20 | D ] C:\Program Files
[18/07/2014 - 22:13:21 | HD ] C:\ProgramData
[30/07/2013 - 18:24:44 | SHD ] C:\Recovery
[18/07/2014 - 21:53:56 | SHD ] C:\System Volume Information
[19/07/2014 - 00:52:05 | D ] C:\UsbFix
[19/07/2014 - 00:26:41 | N | 16315] C:\UsbFix [Clean 1] MILAN-PC.txt
[19/07/2014 - 00:52:31 | A | 7110] C:\UsbFix [Clean 2] MILAN-PC.txt
[30/07/2013 - 18:26:51 | D ] C:\Users
[07/11/2007 - 08:00:40 | N | 5686] C:\vcredist.bmp
[07/11/2007 - 08:09:22 | N | 1442522] C:\VC_RED.cab
[07/11/2007 - 08:12:28 | N | 232960] C:\VC_RED.MSI
[18/07/2014 - 19:28:37 | D ] C:\Windows
[30/07/2013 - 18:24:46 | N | 20] C:\winx.ld
[01/09/2013 - 20:37:50 | D ] C:\_Záloha
[17/07/2014 - 17:39:27 | SHDC ] E:\$RECYCLE.BIN
[19/07/2014 - 00:26:40 | RASHDC ] E:\Autorun.inf
[18/05/2014 - 21:46:27 | DC ] E:\Filmy
[14/07/2014 - 16:55:09 | DC ] E:\Filmy_duchovní
[11/05/2014 - 23:16:57 | DC ] E:\Milan
[16/01/2010 - 12:56:07 | SHD ] E:\System Volume Information
[25/03/2013 - 07:08:03 | DC ] E:\Vesmír
[02/04/2014 - 14:23:16 | SHD ] F:\$RECYCLE.BIN
[20/06/2012 - 18:29:20 | N | 0] F:\AUTOEXEC.BAT
[19/07/2014 - 00:26:40 | RASHD ] F:\Autorun.inf
[29/07/2013 - 18:55:23 | N | 238] F:\boot.ini
[24/03/2013 - 20:56:45 | N | 211] F:\boot.iniiiiii
[02/08/2007 - 14:00:00 | N | 4952] F:\Bootfont.bin
[27/10/2012 - 21:11:19 | D ] F:\Brother's Keeper 6
[17/12/1993 - 03:11:10 | N | 94720] F:\CARDFILE.EXE
[20/07/2013 - 23:18:06 | D ] F:\Config.Msi
[20/06/2012 - 18:29:20 | N | 0] F:\CONFIG.SYS
[10/08/2013 - 16:32:16 | D ] F:\Documents and Settings
[05/01/2014 - 14:13:29 | D ] F:\Dokumenty
[03/11/2013 - 00:16:24 | D ] F:\Downloads
[13/09/2012 - 22:15:25 | N | 190] F:\drwtsn32.log
[07/11/2007 - 08:00:40 | N | 17734] F:\eula.1028.txt
[07/11/2007 - 08:00:40 | N | 17734] F:\eula.1031.txt
[07/11/2007 - 08:00:40 | N | 10134] F:\eula.1033.txt
[07/11/2007 - 08:00:40 | N | 17734] F:\eula.1036.txt
[07/11/2007 - 08:00:40 | N | 17734] F:\eula.1040.txt
[07/11/2007 - 08:00:40 | N | 118] F:\eula.1041.txt
[07/11/2007 - 08:00:40 | N | 17734] F:\eula.1042.txt
[07/11/2007 - 08:00:40 | N | 17734] F:\eula.2052.txt
[07/11/2007 - 08:00:40 | N | 17734] F:\eula.3082.txt
[29/12/2012 - 11:22:29 | D ] F:\found.000
[10/07/2014 - 22:37:06 | D ] F:\Garmin
[07/11/2007 - 08:00:40 | N | 1110] F:\globdata.ini
[07/11/2007 - 08:03:18 | N | 562688] F:\install.exe
[07/11/2007 - 08:00:40 | N | 843] F:\install.ini
[07/11/2007 - 08:03:18 | N | 76304] F:\install.res.1028.dll
[07/11/2007 - 08:03:18 | N | 96272] F:\install.res.1031.dll
[07/11/2007 - 08:03:18 | N | 91152] F:\install.res.1033.dll
[07/11/2007 - 08:03:18 | N | 97296] F:\install.res.1036.dll
[07/11/2007 - 08:03:18 | N | 95248] F:\install.res.1040.dll
[07/11/2007 - 08:03:18 | N | 81424] F:\install.res.1041.dll
[07/11/2007 - 08:03:18 | N | 79888] F:\install.res.1042.dll
[07/11/2007 - 08:03:18 | N | 75792] F:\install.res.2052.dll
[07/11/2007 - 08:03:18 | N | 96272] F:\install.res.3082.dll
[20/06/2012 - 18:29:20 | N | 0] F:\IO.SYS
[17/10/2012 - 20:25:07 | N | 0] F:\KbList.txt
[28/11/2012 - 22:16:57 | N | 3145] F:\LOGFILE.TXT
[20/06/2012 - 18:29:20 | N | 0] F:\MSDOS.SYS
[25/06/2012 - 22:12:23 | RHD ] F:\MSOCache
[13/04/2008 - 22:13:04 | N | 47564] F:\NTDETECT.COM
[14/04/2008 - 00:01:48 | N | 250576] F:\ntldr
[19/06/2013 - 20:34:02 | N | 57632] F:\PA7302.DAT
[29/07/2013 - 20:41:51 | N | 120586240] F:\PAGEFILE.SYS
[30/12/2013 - 22:35:46 | D ] F:\Program Files
[24/06/2012 - 22:26:40 | SHD ] F:\RECYCLER
[06/08/2012 - 12:39:32 | N | 85882] F:\SROUBY.CRD
[02/11/2013 - 21:46:28 | D ] F:\Sygic
[20/06/2012 - 18:34:43 | SHD ] F:\System Volume Information
[08/12/2012 - 09:02:23 | N | 50] F:\user.js
[07/11/2007 - 08:00:40 | N | 5686] F:\vcredist.bmp
[07/11/2007 - 08:09:22 | N | 1442522] F:\VC_RED.cab
[07/11/2007 - 08:12:28 | N | 232960] F:\VC_RED.MSI
[12/01/2013 - 21:24:37 | DC ] G:\!Dokumenty
[04/05/2014 - 00:00:09 | SHDC ] G:\$RECYCLE.BIN
[05/02/2012 - 17:48:50 | DC ] G:\4583ecfc210a97d9b15eccf78864
[14/05/2014 - 21:37:24 | DC ] G:\aaa
[21/06/2012 - 03:04:48 | DC ] G:\Any Converters
[17/05/2014 - 18:56:36 | DC ] G:\Arakain
[18/07/2014 - 19:21:24 | DC ] G:\Autodesk
[19/07/2014 - 00:26:40 | RASHDC ] G:\Autorun.inf
[17/05/2014 - 18:59:31 | DC ] G:\Boogie-Woogie
[20/02/2012 - 23:12:35 | DC ] G:\Brother's Keeper 6
[12/01/2013 - 21:15:50 | DC ] G:\Bývalé disky_C
[31/12/2013 - 15:21:18 | DC ] G:\Chata Kameňák
[31/12/2013 - 13:17:02 | DC ] G:\Cigánski diabli
[31/12/2013 - 14:01:22 | DC ] G:\Cikáni-jdou-do-nebe
[31/12/2013 - 13:28:56 | DC ] G:\Cimbálová muzika Moravia
[14/05/2014 - 21:36:02 | DC ] G:\Dokumenty
[18/07/2014 - 19:22:30 | DC ] G:\Downloads
[31/12/2013 - 14:00:12 | DC ] G:\FaLun_KungFu
[11/05/2014 - 21:53:52 | DC ] G:\Filmy
[12/01/2014 - 01:25:23 | DC ] G:\Install
[09/07/2014 - 16:00:09 | DC ] G:\Kontrabas
[14/05/2014 - 21:45:55 | DC ] G:\Letadla
[11/05/2014 - 23:18:43 | DC ] G:\Milan
[31/12/2013 - 15:26:52 | DC ] G:\Náramek
[14/05/2014 - 21:39:14 | DC ] G:\Náramek-Hanka
[08/08/2013 - 21:29:19 | DC ] G:\PCTeacher
[17/03/2014 - 18:55:51 | DC ] G:\PCTranslator
[13/01/2014 - 22:43:30 | DC ] G:\Pole
[17/02/2013 - 17:31:56 | RDC ] G:\Program Files-Smazat!!!!!!
[21/06/2012 - 00:55:32 | DC ] G:\Průkazové foto
[24/06/2012 - 22:47:35 | SHDC ] G:\RECYCLER
[14/05/2014 - 21:39:14 | DC ] G:\Sbor
[04/02/2012 - 18:22:47 | SHD ] G:\System Volume Information
[14/02/2014 - 17:54:00 | DC ] G:\The Universe
[31/12/2013 - 13:21:43 | DC ] G:\Tragacnice---generálka-výběr_2
[31/12/2013 - 01:20:16 | DC ] G:\Translat
[21/04/2013 - 15:37:11 | DC ] G:\Vaření - Tim Ferriss
[25/02/2012 - 16:16:39 | DC ] G:\WinFast WorkArea
[11/05/2014 - 22:19:48 | DC ] G:\Záloha
[29/01/2013 - 23:36:20 | DC ] G:\česká-škola-lyžování---běžky
[07/07/2012 - 15:35:30 | D ] H:\stare certifikaty
[08/05/2014 - 08:36:50 | N | 4630] H:\KROJZL_MILAN_ING.p12
[16/07/2014 - 10:22:57 | SHD ] I:\$RECYCLE.BIN
[04/05/2014 - 17:02:23 | D ] I:\1. Fotky - pořádek
[04/05/2014 - 17:01:40 | D ] I:\2. Hanka
[08/05/2014 - 23:12:04 | D ] I:\3. Milan
[04/05/2014 - 16:51:37 | D ] I:\4. Společné
[19/07/2014 - 00:26:41 | RASHD ] I:\Autorun.inf
[08/07/2014 - 07:20:51 | D ] I:\MAA
[07/07/2014 - 13:54:15 | D ] I:\Prezentace
[04/05/2014 - 16:38:30 | SHD ] I:\RECYCLER
[08/07/2014 - 11:40:23 | SHD ] I:\System Volume Information
[10/03/2011 - 00:43:50 | N | 3290480] I:\WD Quick Formatter.exe
[10/03/2011 - 00:43:44 | N | 4246384] I:\WD SmartWare.exe
[19/07/2014 - 00:26:42 | RASHD ] J:\Autorun.inf
[05/09/2013 - 20:40:12 | D ] K:\Videokurz Revoluční cvičení 6ti minutovka
[09/10/2013 - 12:27:52 | D ] K:\Kontrabas-old
[10/10/2013 - 16:59:04 | N | 18231] K:\Přehled - banky k 10.10.2013.xlsx
[24/10/2013 - 05:57:58 | D ] K:\Kontrabas
[29/06/2014 - 11:17:42 | D ] K:\50 Acoustic Blues licks you must know
[19/07/2014 - 00:26:42 | RASHD ] K:\Autorun.inf
################## | Vaccin |
A:\Autorun.inf -> Vaccine created by UsbFix (El Desaparecido)
C:\Autorun.inf -> Vaccine created by UsbFix (El Desaparecido)
E:\Autorun.inf -> Vaccine created by UsbFix (El Desaparecido)
F:\Autorun.inf -> Vaccine created by UsbFix (El Desaparecido)
G:\Autorun.inf -> Vaccine created by UsbFix (El Desaparecido)
H:\Autorun.inf -> Vaccine created by UsbFix (El Desaparecido)
I:\Autorun.inf -> Vaccine created by UsbFix (El Desaparecido)
J:\Autorun.inf -> Vaccine created by UsbFix (El Desaparecido)
K:\Autorun.inf -> Vaccine created by UsbFix (El Desaparecido)
################## | E.O.F | http://www.sosvirus.net |