tak som dal clean a naslo toho celkom dost
############################## | UsbFix V 7.804 | [Clean]
User: Roman (Administrator) # ROMANPC
Updated 24/11/2014 by El Desaparecido - SosVirus
Started at 18:16:17 | 26/11/2014
Website :
http://www.en.usbfix.net/
Changelog :
http://www.en.usbfix.net/changelog/
Support :
http://www.sosvirus.net/
Upload Malware :
http://www.sosvirus.net/upload_malware.php
Live detection :
http://how-to-remove.us/
Contact :
http://www.en.usbfix.net/contact/
################## | System information |
CPU: AMD Athlon(tm) XP 2200+
RAM -> [Total : 255 Mo | Free : 89 Mo]
Boot: Normal boot
OS: Microsoft Windows XP (5.1.2600 32-Bit) Service Pack 3
WB: Internet Explorer : 6.00.2900.5512
WB: Mozilla Firefox : 33.1.1
################## | Security Information |
FW: Windows Firewall [Enabled]
SC: Security Center [Enabled]
WU: Windows Update [
(!) Disabled]
################## | Disk Information |
C:\ (%SystemDrive%) -> Fixed disk # 244 Gb (227 Gb free - 93%) [System] # NTFS
D:\ -> Removable disk # 7 Gb (7 Gb free - 99%) [FLASH DRIVE] # NTFS
################## | Generic Research |
Deleted! C:\Documents and Settings\Roman\Application Data\c731200
Deleted! C:\Documents and Settings\Roman\Application Data\Update\Explorer.exe
Deleted! C:\Documents and Settings\Roman\Application Data\Update\MSupdate.exe
Deleted! C:\DOCUME~1\Roman\LOCALS~1\Temp\c731200
Deleted! D:\10-03DB2A7F-2168419-960.jpg.lnk
Deleted! D:\10-25421F3F-877713-960.jpg.lnk
Deleted! D:\10-26C086DA-1460338-960.jpg.lnk
Deleted! D:\10-26F6F7DE-1585973-960.jpg.lnk
Deleted! D:\10-2A60A91C-833304-960.jpg.lnk
Deleted! D:\10-3C095337-1922318-960.jpg.lnk
Deleted! D:\10-3F494BDF-2192505-960.jpg.lnk
Deleted! D:\10-4FEB46C6-1351807-960.jpg.lnk
Deleted! D:\10-76814F78-905689-960.jpg.lnk
Deleted! D:\10-7F8599FC-1416700-960.jpg.lnk
Deleted! D:\10-883B3345-1783306-960.jpg.lnk
Deleted! D:\10-9C6D8101-1833598-960.jpg.lnk
Deleted! C:\Documents and Settings\Roman\Local Settings\Application Data\dt.dat
Deleted! C:\Documents and Settings\Roman\Local Settings\Temp\anpeg.exe
Deleted! C:\Documents and Settings\Roman\Local Settings\Temp\fpeqb.exe
Deleted! D:\pTRvwnW.exe
(!) Temporary files deleted. (8.09532260894775 MB)
################## | Registry |
Repaired ! HKLM\Software\Microsoft\Windows NT\CurrentVersion\Winlogon|Taskman ("")
Deleted! HKU\S-1-5-21-842925246-2052111302-1606980848-1003\Software\Microsoft\Windows\CurrentVersion\Run|Windows Explorer Manager
Deleted! HKU\S-1-5-21-842925246-2052111302-1606980848-1003\Software\Microsoft\Windows\CurrentVersion\Run|Windows Update Manager
################## | Regedit Run |
F2 - HKLM\..\Winlogon : [Shell] Explorer.exe
F2 - HKLM\..\Winlogon : [TaskMan]
F2 - HKLM\..\Winlogon : [Userinit] C:\WINDOWS\system32\userinit.exe,
04 - HKU\S-1-5-19\..\Run : [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE
04 - HKU\S-1-5-20\..\Run : [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE
04 - HKU\S-1-5-18\..\Run : [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE
################## | UsbFix - Information |
UsbFix has detected on your computer, an infection which a Keylogger function.
After cleaning with UsbFix, please modify all your passwords.
If you made purchases on Internet,
please contact your bank to enviseager an opposition on your bank card.
Info :
How to remove shortcut virus on flash disk (Video)
Info :
Shortcut virus on flash disk, What is it ?
################## | Hijack |
Restored! [N] D:\10-03DB2A7F-2168419-960.jpg
Restored! [N] D:\10-25421F3F-877713-960.jpg
Restored! [N] D:\10-26C086DA-1460338-960.jpg
Restored! [N] D:\10-26F6F7DE-1585973-960.jpg
Restored! [N] D:\10-2A60A91C-833304-960.jpg
Restored! [N] D:\10-3C095337-1922318-960.jpg
Restored! [N] D:\10-3F494BDF-2192505-960.jpg
Restored! [N] D:\10-4FEB46C6-1351807-960.jpg
Restored! [N] D:\10-76814F78-905689-960.jpg
Restored! [N] D:\10-7F8599FC-1416700-960.jpg
Restored! [N] D:\10-883B3345-1783306-960.jpg
Restored! [N] D:\10-9C6D8101-1833598-960.jpg
################## | C:\ %SystemDrive% - Fixed drive (NTFS) |
[08/05/2012 - 21:15:24 | RASH | 0 Ko] - C:\MSDOS.SYS
[08/05/2012 - 21:15:24 | A | 0 Ko] - C:\CONFIG.SYS
[08/05/2012 - 21:15:24 | RASH | 0 Ko] - C:\IO.SYS
[26/11/2014 - 18:05:44 | ASH | 392424 Ko] - C:\pagefile.sys
[26/11/2014 - 18:05:46 | ASH | 261684 Ko] - C:\hiberfil.sys
[06/02/2013 - 14:50:53 | D] - C:\Config.Msi
[22/06/2012 - 18:22:51 | A | 0 Ko] - C:\GuardMailRu.log
[19/06/2012 - 15:45:48 | A | 0 Ko] - C:\user.js
[22/06/2012 - 18:40:53 | SH | 0 Ko] - C:\boot.ini
[13/04/2008 - 21:13:04 | N | 46 Ko] - C:\NTDETECT.COM
[08/05/2012 - 21:15:24 | A | 0 Ko] - C:\AUTOEXEC.BAT
[01/01/2003 - 00:04:35 | RD] - C:\Dokumenty
[01/01/2003 - 06:29:22 | D] - C:\WINDOWS
[01/01/2003 - 06:29:23 | D] - C:\meuhampxq
[01/01/2003 - 07:59:28 | D] - C:\mcmkydylt
[02/01/2003 - 00:49:38 | D] - C:\gqigiluea
[13/04/2008 - 23:01:44 | RASH | 244 Ko] - C:\ntldr
[08/05/2012 - 21:19:33 | SHD] - C:\System Volume Information
[08/05/2012 - 21:23:38 | D] - C:\Documents and Settings
[08/05/2012 - 22:32:51 | D] - C:\Stary
[08/05/2012 - 23:01:56 | D] - C:\Programy
[11/05/2012 - 18:47:09 | D] - C:\bin
[16/05/2012 - 17:12:27 | D] - C:\install
[07/12/2012 - 20:55:58 | D] - C:\temp
[23/11/2014 - 17:56:02 | RD] - C:\Program Files
[23/11/2014 - 19:29:01 | D] - C:\AdwCleaner
[26/11/2014 - 18:12:39 | D] - C:\UsbFix
[26/11/2014 - 18:17:05 | SHD] - C:\RECYCLER
################## | D:\ - Removable drive (NTFS) |
[08/08/2013 - 12:00:16 | N | 10 Ko] - D:\10-3C095337-1922318-960.jpg
[06/04/2014 - 12:27:42 | N | 12 Ko] - D:\10-26F6F7DE-1585973-960.jpg
[06/04/2014 - 12:27:42 | N | 12 Ko] - D:\10-25421F3F-877713-960.jpg
[07/04/2014 - 11:37:04 | N | 10 Ko] - D:\10-2A60A91C-833304-960.jpg
[10/04/2014 - 16:10:34 | N | 9 Ko] - D:\10-4FEB46C6-1351807-960.jpg
[12/04/2014 - 10:34:08 | N | 9 Ko] - D:\10-76814F78-905689-960.jpg
[25/07/2014 - 12:25:32 | N | 14 Ko] - D:\10-883B3345-1783306-960.jpg
[02/08/2014 - 15:58:08 | N | 13 Ko] - D:\10-7F8599FC-1416700-960.jpg
[13/08/2014 - 12:30:08 | N | 12 Ko] - D:\10-3F494BDF-2192505-960.jpg
[13/08/2014 - 12:30:36 | N | 12 Ko] - D:\10-03DB2A7F-2168419-960.jpg
[06/09/2014 - 20:29:54 | N | 13 Ko] - D:\10-9C6D8101-1833598-960.jpg
[07/09/2014 - 20:37:08 | N | 12 Ko] - D:\10-26C086DA-1460338-960.jpg
################## | Vaccin |
C:\Autorun.inf -> Vaccine created by UsbFix (El Desaparecido)
D:\Autorun.inf -> Vaccine created by UsbFix (El Desaparecido)
################## | E.O.F | http://www.sosvirus.net/ | http://www.en.usbfix.net/ |
a este ked som spustil PC tak sa mi po chvili sam od seba spustil Internet explorer aj s nejakou otravnou vyskakovacou reklamou typu: "vyhral si iphone, klikni sem", cize nejaky bordel tam zrejme este zostal.