po třetím skenu se zahlásil i telefon a byl taky proveden další sken...
############################## | UsbFix V 7.171 | [Clean]
User: spravce (Administrator) # LENOVO-PC
Updated 18/05/2014 by El Desaparecido - SosVirus
Started at 08:48:15 | 25/05/2014
Website :
http://www.en.usbfix.net/
Changelog :
http://www.en.usbfix.net/changelog/
Support :
http://en.kioskea.net/forum/viruses-security-7
Upload Malware :
http://www.sosvirus.net/upload_malware.php
Contact :
http://www.en.usbfix.net/contact/
PC: LENOVO (G700)
CPU: Intel(R) Pentium(R) CPU 2020M @ 2.40GHz
RAM -> [Total : 3975 Mo| Free : 2551 Mo]
Bios: LENOVO
Boot: Normal boot
OS: Microsoft Windows 7 Ultimate (6.1.7601 64-Bit) Service Pack 1
WB: Windows Internet Explorer : 11.0.9600.17107
WB: Mozilla Firefox : 29.0.1
SC: Security Center [Enabled]
WU: Windows Update [Enabled]
AV: avast! Antivirus [Enabled | Updated]
AS: Windows Defender [Enabled | Updated]
AS: avast! Antivirus [Enabled | Updated]
FW: ZoneAlarm Free Firewall Firewall [Enabled]
FW: Windows FireWall [Enabled]
C:\ (%SystemDrive%) -> Fixed drive # 368 Gb (219 Mb free - 60%) [] # NTFS
D:\ -> Fixed drive # 98 Gb (97 Mb free - 99%) [] # NTFS
E:\ -> CD-ROM
F:\ -> CD-ROM
G:\ -> Removable drive # 2 Gb (618 Mb free - 33%) [PHONE CARD] # FAT
H:\ -> Removable drive # 2 Gb (1 Mb free - 73%) [] # FAT32
I:\ -> Removable drive # 7 Gb (3 Mb free - 43%) [Transcend] # FAT32
################## | Stopped processes |
C:\Windows\System32\nvvsvc.exe (ID: 520|ParentID: 800)
C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe (ID: 544|ParentID: 800)
C:\Program Files\IDT\WDM\stacsv64.exe (ID: 1128|ParentID: 800)
C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe (ID: 1516|ParentID: 520)
C:\Windows\System32\nvvsvc.exe (ID: 1524|ParentID: 520)
C:\Windows\System32\wlanext.exe (ID: 1712|ParentID: 924)
C:\Windows\System32\spoolsv.exe (ID: 1960|ParentID: 800|SYSTEM)
C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe (ID: 1456|ParentID: 800|SYSTEM)
C:\Program Files (x86)\Bluetooth Suite\AdminService.exe (ID: 1792|ParentID: 800|SYSTEM)
C:\Program Files (x86)\Skype\Toolbars\AutoUpdate\SkypeC2CAutoUpdateSvc.exe (ID: 1200|ParentID: 800|SYSTEM)
C:\Program Files (x86)\Skype\Toolbars\PNRSvc\SkypeC2CPNRSvc.exe (ID: 2064|ParentID: 800|NETWORK SERVICE)
C:\Program Files\Intel\iCLS Client\HeciServer.exe (ID: 2112|ParentID: 800|SYSTEM)
C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\Jhi_service.exe (ID: 2188|ParentID: 800|SYSTEM)
C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamscheduler.exe (ID: 2216|ParentID: 800|SYSTEM)
C:\Program Files (x86)\Skype\Updater\Updater.exe (ID: 2400|ParentID: 800|SYSTEM)
C:\Program Files (x86)\Bluetooth Suite\Ath_CoexAgent.exe (ID: 2660|ParentID: 800|SYSTEM)
C:\Windows\System32\WUDFHost.exe (ID: 3400|ParentID: 924|LOCAL SERVICE)
C:\Windows\System32\taskhost.exe (ID: 3612|ParentID: 800|spravce)
C:\Windows\explorer.exe (ID: 4016|ParentID: 3840|spravce)
C:\Program Files (x86)\Malwarebytes Anti-Malware\mbam.exe (ID: 3788|ParentID: 2324|spravce)
C:\Program Files\Elantech\ETDCtrl.exe (ID: 3776|ParentID: 4016|spravce)
C:\Program Files (x86)\Dolby Advanced Audio v2\pcee4.exe (ID: 1036|ParentID: 4016|spravce)
C:\Windows\System32\igfxtray.exe (ID: 4236|ParentID: 4016|spravce)
C:\Program Files\Elantech\ETDCtrlHelper.exe (ID: 4572|ParentID: 3776|spravce)
C:\Program Files\NVIDIA Corporation\Display\nvtray.exe (ID: 4616|ParentID: 1516|spravce)
C:\Windows\System32\hkcmd.exe (ID: 4752|ParentID: 4016|spravce)
C:\Program Files\Elantech\ETDIntelligent.exe (ID: 4920|ParentID: 3776|spravce)
C:\Windows\System32\igfxpers.exe (ID: 5032|ParentID: 4016|spravce)
C:\Program Files (x86)\Intel\Intel(R) Integrated Clock Controller Service\ICCProxy.exe (ID: 736|ParentID: 800|SYSTEM)
C:\Program Files (x86)\Lenovo\Energy Management\Energy Management.exe (ID: 4432|ParentID: 4016|spravce)
C:\Windows\System32\SearchIndexer.exe (ID: 5008|ParentID: 800|SYSTEM)
C:\Program Files (x86)\Lenovo\Energy Management\utility.exe (ID: 4400|ParentID: 4016|spravce)
C:\Windows\System32\SearchProtocolHost.exe (ID: 4848|ParentID: 5008|SYSTEM)
C:\Users\spravce\AppData\Roaming\Seznam.cz\szninstall.exe (ID: 4500|ParentID: 4016|spravce)
C:\Program Files (x86)\Intel\Intel(R) USB 3.0 eXtensible Host Controller Driver\Application\iusb3mon.exe (ID: 4776|ParentID: 1228|spravce)
C:\Users\spravce\AppData\Roaming\Seznam.cz\bin\chromeUpdatePref.exe (ID: 4888|ParentID: 4624|spravce)
C:\Users\spravce\AppData\Roaming\Seznam.cz\bin\szndesktop.exe (ID: 4784|ParentID: 4656|spravce)
C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe (ID: 4108|ParentID: 1228|spravce)
C:\Windows\System32\wbem\unsecapp.exe (ID: 4476|ParentID: 988|spravce)
################## | Autorun |
################## | Generic Research |
(!) Temporary files deleted.
################## | Registry |
################## | Regedit Run |
F2 - HKLM\..\Winlogon : [Shell] explorer.exe
F2 - [x64] HKLM\..\Winlogon : [Shell] Explorer.exe
F2 - HKLM\..\Winlogon : [Userinit] C:\Windows\system32\userinit.exe,
F2 - [x64] HKLM\..\Winlogon : [Userinit] C:\Windows\system32\userinit.exe,
04 - HKCU\..\Run : [Seznam.chromeUpdatePref] C:\Users\spravce\AppData\Roaming\Seznam.cz\bin\chromeUpdatePref.exe 12454
04 - HKCU\..\Run : [cz.seznam.software.szndesktop] "C:\Users\spravce\AppData\Roaming\Seznam.cz\bin\wszndesktop.exe" -q
04 - HKCU\..\Run : [cz.seznam.software.autoupdate] "C:\Users\spravce\AppData\Roaming\Seznam.cz\szninstall.exe" -c
04 - HKLM\..\Run : [Dolby Advanced Audio v2] "C:\Program Files (x86)\Dolby Advanced Audio v2\pcee4.exe" -autostart
04 - HKLM\..\Run : [USB3MON] "C:\Program Files (x86)\Intel\Intel(R) USB 3.0 eXtensible Host Controller Driver\Application\iusb3mon.exe"
04 - HKLM\..\Run : [seznam-listicka-distribuce] "C:\Program Files (x86)\Seznam.cz\distribution\szninstall.exe" -s -d listicka 1 szn-software-listicka cz.seznam.software.autoupdate
04 - HKLM\..\Run : [AvastUI.exe] "C:\Program Files\AVAST Software\Avast\AvastUI.exe" /nogui
04 - HKLM\..\Run : [ZoneAlarm] "C:\Program Files (x86)\CheckPoint\ZoneAlarm\zatray.exe"
04 - HKLM\..\Run : [Adobe ARM] "C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
04 - HKLM\..\Run : [SunJavaUpdateSched] "C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe"
04 - [x64] HKLM\..\Run : [ETDCtrl] %ProgramFiles%\Elantech\ETDCtrl.exe
04 - [x64] HKLM\..\Run : [DolbyTrayApp] c:\program files (x86)\Dolby Advanced Audio v2\pcee4.exe -autostart
04 - [x64] HKLM\..\Run : [IgfxTray] C:\Windows\system32\igfxtray.exe
04 - [x64] HKLM\..\Run : [HotKeysCmds] C:\Windows\system32\hkcmd.exe
04 - [x64] HKLM\..\Run : [Persistence] C:\Windows\system32\igfxpers.exe
04 - [x64] HKLM\..\Run : [Energy Management] C:\Program Files (x86)\Lenovo\Energy Management\Energy Management.exe
04 - [x64] HKLM\..\Run : [EnergyUtility] C:\Program Files (x86)\Lenovo\Energy Management\Utility.exe
04 - HKU\S-1-5-21-2337024723-3800431968-2900454187-1003\..\Run : [Seznam.chromeUpdatePref] C:\Users\spravce\AppData\Roaming\Seznam.cz\bin\chromeUpdatePref.exe 12454
04 - HKU\S-1-5-21-2337024723-3800431968-2900454187-1003\..\Run : [cz.seznam.software.szndesktop] "C:\Users\spravce\AppData\Roaming\Seznam.cz\bin\wszndesktop.exe" -q
04 - HKU\S-1-5-21-2337024723-3800431968-2900454187-1003\..\Run : [cz.seznam.software.autoupdate] "C:\Users\spravce\AppData\Roaming\Seznam.cz\szninstall.exe" -c
04 - HKU\S-1-5-21-2337024723-3800431968-2900454187-1004\..\Run : [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun
04 - HKU\S-1-5-21-2337024723-3800431968-2900454187-1004\..\RunOnce : [mctadmin] C:\Windows\System32\mctadmin.exe
################## | C:\ %SystemDrive% - Fixed drive (NTFS) |
[13/05/2014 - 07:02:37 | N | 2 Ko] - C:\face.txt
[13/05/2014 - 08:47:21 | N | 13 Ko] - C:\ComboFix.txt
[25/05/2014 - 08:46:06 | ASH | 3053072 Ko] - C:\hiberfil.sys
[25/05/2014 - 08:46:22 | ASH | 4070764 Ko] - C:\pagefile.sys
[13/05/2014 - 09:06:52 | SHD] - C:\$RECYCLE.BIN
[14/07/2009 - 05:20:08 | D] - C:\PerfLogs
[14/07/2009 - 07:08:56 | SHD] - C:\Documents and Settings
[25/10/2013 - 06:17:08 | D] - C:\Recovery
[25/10/2013 - 06:26:53 | D] - C:\Intel
[25/10/2013 - 10:14:41 | D] - C:\drivers
[25/10/2013 - 12:07:09 | D] - C:\UserGuidePDF
[28/10/2013 - 21:11:21 | D] - C:\PPK
[06/01/2014 - 18:42:18 | D] - C:\first_launch
[12/02/2014 - 12:30:40 | D] - C:\totalcmd
[11/05/2014 - 07:13:32 | D] - C:\FRST
[11/05/2014 - 21:41:15 | D] - C:\AdwCleaner
[13/05/2014 - 08:47:24 | D] - C:\Qoobox
[13/05/2014 - 09:05:14 | D] - C:\Users
[15/05/2014 - 08:36:34 | D] - C:\Program Files
[20/05/2014 - 06:54:10 | D] - C:\Program Files (x86)
[20/05/2014 - 06:54:11 | D] - C:\ProgramData
[21/05/2014 - 05:42:30 | SHD] - C:\System Volume Information
[24/05/2014 - 06:41:18 | D] - C:\Windows
[25/05/2014 - 08:26:19 | D] - C:\UsbFix
################## | D:\ - Fixed drive (NTFS) |
[07/05/2014 - 23:25:26 | D] - D:\$RECYCLE.BIN
[25/10/2013 - 10:17:14 | SHD] - D:\System Volume Information
[25/10/2013 - 12:09:36 | D] - D:\LENOVO_G700_drive_nemazat_W7
################## | G:\ - Removable drive (FAT) |
[05/04/2014 - 13:30:16 | N | 8 Ko] - G:\default-capability.xml
[16/01/2013 - 21:52:30 | N | 21 Ko] - G:\00001.vcf
[21/06/2013 - 09:00:40 | N | 25 Ko] - G:\sendAll.vcf
[04/10/2013 - 18:55:44 | N | 0 Ko] - G:\vCard.vcf
[05/04/2014 - 13:30:52 | N | 33 Ko] - G:\00002.vcf
[21/12/2010 - 14:53:40 | N | 0 Ko] - G:\CDAInfo.txt
[22/02/2011 - 10:26:26 | N | 0 Ko] - G:\Traceability.txt
[22/02/2011 - 10:26:26 | N | 0 Ko] - G:\MemStickInfo.txt
[10/05/2014 - 19:58:22 | D] - G:\.temp
[20/07/2013 - 05:25:02 | D] - G:\.com.mobisystems.office
[21/12/2010 - 14:53:40 | N | 0 Ko] - G:\MEMSTICK.IND
[21/12/2010 - 14:53:40 | N | 0 Ko] - G:\MSTK_PRO.IND
[06/01/1980 - 00:05:46 | D] - G:\LOST.DIR
[21/12/2010 - 14:54:42 | D] - G:\.demovideo
[05/04/2014 - 23:31:32 | D] - G:\.dataviz
[07/05/2014 - 19:16:36 | N | 0 Ko] - G:\.avg
[05/04/2014 - 19:37:16 | D] - G:\.android_secure
[08/04/2014 - 14:27:56 | N | 0 Ko] - G:\.adups
[21/12/2010 - 14:54:42 | D] - G:\music
[21/12/2010 - 14:54:42 | D] - G:\notifications
[21/12/2010 - 14:54:42 | D] - G:\alarms
[21/12/2010 - 14:54:44 | D] - G:\others
[21/12/2010 - 14:58:40 | D] - G:\PCCompanion
[21/12/2010 - 14:58:46 | D] - G:\ringtones
[03/06/2012 - 18:18:00 | D] - G:\media
[05/06/2012 - 13:03:00 | D] - G:\playnow
[04/03/2013 - 10:37:42 | D] - G:\image
[04/07/2013 - 08:22:48 | D] - G:\data
[18/12/2013 - 07:37:30 | D] - G:\download
[05/04/2014 - 13:39:04 | D] - G:\skymobi
[05/04/2014 - 19:37:26 | D] - G:\zoiper
[05/04/2014 - 23:02:28 | D] - G:\DCIM
[05/04/2014 - 23:31:32 | D] - G:\Android
[05/04/2014 - 23:31:34 | D] - G:\documents
[07/04/2014 - 20:57:44 | D] - G:\WhatsApp
[06/05/2014 - 16:24:26 | D] - G:\kbatterydoctor
[06/05/2014 - 16:52:52 | D] - G:\video
[07/05/2014 - 17:51:58 | D] - G:\Meteoservis
[12/05/2014 - 16:46:30 | D] - G:\viber
[12/05/2014 - 17:45:04 | D] - G:\MusicPlayer
[18/05/2014 - 18:17:00 | D] - G:\MyFavorite
[21/05/2014 - 18:55:44 | D] - G:\Recording
[25/05/2014 - 18:39:10 | D] - G:\backup
################## | H:\ - Removable drive (FAT32) |
[01/01/2014 - 00:01:06 | D] - H:\LOST.DIR
[01/01/2014 - 00:01:06 | D] - H:\.android_secure
[04/04/2014 - 18:09:38 | N | 0 Ko] - H:\.adups
[01/01/2014 - 00:00:00 | D] - H:\Podcasts
[01/01/2014 - 00:00:00 | D] - H:\Ringtones
[01/01/2014 - 00:00:00 | D] - H:\Alarms
[01/01/2014 - 00:00:00 | D] - H:\Notifications
[01/01/2014 - 00:00:00 | D] - H:\Download
[01/01/2014 - 00:00:00 | D] - H:\Music
[01/01/2014 - 00:00:00 | D] - H:\Movies
[01/01/2014 - 00:00:06 | D] - H:\Android
[01/01/2014 - 00:07:36 | D] - H:\skymobi
[04/04/2014 - 17:57:08 | D] - H:\zoiper
[04/04/2014 - 18:04:24 | D] - H:\DCIM
[04/04/2014 - 22:22:34 | D] - H:\Meteoservis
[06/05/2014 - 16:52:38 | D] - H:\Pictures
################## | I:\ - Removable drive (FAT32) |
[24/03/2014 - 12:44:58 | N | 830045 Ko] - I:\Globální oteplování nebo globální vláda[72].wmv
[13/05/2014 - 08:49:26 | N | 13 Ko] - I:\log.txt
[19/05/2014 - 04:35:50 | N | 1 Ko] - I:\visa.txt
[15/05/2014 - 01:22:24 | N | 77 Ko] - I:\správce zařízení.rar
[15/05/2014 - 01:20:16 | N | 117 Ko] - I:\správce zařízení.png
[19/03/2014 - 13:49:46 | N | 860497 Ko] - I:\Inside-Job-(CZ-dabing).mp4
[15/05/2014 - 01:20:32 | N | 77 Ko] - I:\správce zařízení.gif
[24/03/2014 - 12:48:46 | N | 575177 Ko] - I:\Velký-podvod-s-globálním-oteplováním---The-Great-Global-Warming-Swindle.flv
[13/05/2014 - 17:44:54 | N | 3258 Ko |
VirusTotal - (0/51)] - I:\lan120ww.exe
[13/05/2014 - 17:49:20 | N | 63063 Ko | SHA1: 8111DBC17191E2D1D6355909060CBF95F4D99A32] - I:\wlan120w7.exe
[13/05/2014 - 18:02:24 | N | 382998 Ko |
VirusTotal - (0/47)] - I:\wlanbt120w7.exe
[15/05/2014 - 01:20:52 | N | 4219 Ko] - I:\správce zařízení.bmp
[17/02/2014 - 18:24:56 | N | 716818 Ko] - I:\Drsný-časy---2005,akční-drama-USA,cz-dabing.avi
[31/10/2013 - 07:25:00 | D] - I:\Microsoft Office
[06/05/2014 - 06:40:56 | D] - I:\NOVÝ ZÉLAND
[11/05/2014 - 21:46:40 | D] - I:\Nová složka
[13/05/2014 - 17:39:12 | D] - I:\sprava
################## | Vaccin |
D:\Autorun.inf -> Vaccine created by UsbFix (El Desaparecido)
G:\Autorun.inf -> Vaccine created by UsbFix (El Desaparecido)
H:\Autorun.inf -> Vaccine created by UsbFix (El Desaparecido)
I:\Autorun.inf -> Vaccine created by UsbFix (El Desaparecido)
################## | E.O.F | http://www.sosvirus.net/ | http://www.en.usbfix.net/ |