USB vir
Napsal: 19 čer 2014 17:16
Dobrý den, vyskytl se mi USB vir, na který jsem podle návodu použil UsbFix. Ten smáznul jeden soubor, ale další dva označil, že nebyly smazány. Přikládám LOG a děkuji za pomoc.
############################## | UsbFix V 7.134 | [Deletion]
User: Martin Slovják (Administrator) # C02-613A
Updated 06/09/2013 by El Desaparecido
Started at 17:47:52 | 19/06/2014
Website: http://www.sosvirus.net/
Upload Malware: http://www.sosvirus.net/upload_malware.php
Contact: eldesaparecido@sosvirus.net
PC: Hewlett-Packard (HP ProBook 4530s) (x64-based PC)
CPU: Intel(R) Core(TM) i3-2330M CPU @ 2.20GHz (2200)
RAM -> [Total : 4030 | Free : 1859]
BIOS: Default System BIOS
BOOT: Normal boot
OS: Microsoft Windows 7 Home Premium (6.1.7601 64-Bit) # Service Pack 1
WB: Windows Internet Explorer 11.0.9600.17126
SC: Security Center Service [Enabled]
WU: Windows Update Service [Enabled]
AV: Avira Desktop [(!) Disabled | Updated]
FW: Windows FireWall Service [Enabled]
C:\ (%systemdrive%) -> Fixed drive # 379 Gb (266 Mb free - 70%) [] # NTFS
D:\ -> Fixed drive # 195 Gb (95 Mb free - 49%) [Data] # NTFS
E:\ -> Fixed drive # 17 Gb (3 Mb free - 15%) [HP_RECOVERY] # NTFS
F:\ -> Fixed drive # 5 Gb (2 Mb free - 42%) [HP_TOOLS] # FAT32
G:\ -> CD-ROM
H:\ -> CD-ROM
################## | El Desaparecido Section |
HKLM\SOFTWARE | Run : [QLBController] - C:\Program Files (x86)\Hewlett-Packard\HP HotKey Support\QLBController.exe /start
HKLM\SOFTWARE | Run : [File Sanitizer] - C:\Program Files (x86)\Hewlett-Packard\File Sanitizer\CoreShredder.exe
HKLM\SOFTWARE | Run : [IAStorIcon] - C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe
HKLM\SOFTWARE | Run : [NUSB3MON] - "c:\Program Files (x86)\Renesas Electronics\USB 3.0 Host Controller Driver\Application\nusb3mon.exe"
HKLM\SOFTWARE | Run : [HPConnectionManager] - c:\Program Files (x86)\Hewlett-Packard\HP Connection Manager\HPCMDelayStart.exe
HKLM\SOFTWARE | Run : [] -
HKLM\SOFTWARE | Run : [NWEReboot] -
HKLM\SOFTWARE | Run : [Adobe ARM] - "C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
HKLM\SOFTWARE | Run : [StartCCC] - "c:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" MSRun
HKLM\SOFTWARE | Run : [avgnt] - "C:\Program Files (x86)\Avira\AntiVir Desktop\avgnt.exe" /min
HKLM\SOFTWARE | Run : [SunJavaUpdateSched] - "C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe"
HKLM\SOFTWARE | Run : [HPQuickWebProxy] - "C:\Program Files (x86)\Hewlett-Packard\HP QuickWeb\hpqwutils.exe"
HKLM\SOFTWARE\wow6432Node | Run : [QLBController] - C:\Program Files (x86)\Hewlett-Packard\HP HotKey Support\QLBController.exe /start
HKLM\SOFTWARE\wow6432Node | Run : [File Sanitizer] - C:\Program Files (x86)\Hewlett-Packard\File Sanitizer\CoreShredder.exe
HKLM\SOFTWARE\wow6432Node | Run : [IAStorIcon] - C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe
HKLM\SOFTWARE\wow6432Node | Run : [NUSB3MON] - "c:\Program Files (x86)\Renesas Electronics\USB 3.0 Host Controller Driver\Application\nusb3mon.exe"
HKLM\SOFTWARE\wow6432Node | Run : [HPConnectionManager] - c:\Program Files (x86)\Hewlett-Packard\HP Connection Manager\HPCMDelayStart.exe
HKLM\SOFTWARE\wow6432Node | Run : [] -
HKLM\SOFTWARE\wow6432Node | Run : [NWEReboot] -
HKLM\SOFTWARE\wow6432Node | Run : [Adobe ARM] - "C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
HKLM\SOFTWARE\wow6432Node | Run : [StartCCC] - "c:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" MSRun
HKLM\SOFTWARE\wow6432Node | Run : [avgnt] - "C:\Program Files (x86)\Avira\AntiVir Desktop\avgnt.exe" /min
HKLM\SOFTWARE\wow6432Node | Run : [SunJavaUpdateSched] - "C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe"
HKLM\SOFTWARE\wow6432Node | Run : [HPQuickWebProxy] - "C:\Program Files (x86)\Hewlett-Packard\HP QuickWeb\hpqwutils.exe"
HKLM\SOFTWARE | RunOnce : [] -
HKLM\SOFTWARE\wow6432Node | RunOnce : [] -
HKU\S-1-5-19\SOFTWARE | Run : [Sidebar] - %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun
HKU\S-1-5-20\SOFTWARE | Run : [Sidebar] - %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun
HKU\S-1-5-21-249382291-896437109-2814540638-1001\SOFTWARE | Run : [NextLive] - C:\windows\SysWOW64\rundll32.exe "C:\Users\Martin Slovják\AppData\Roaming\newnext.me\nengine.dll",EntryPoint -m l
HKU\S-1-5-21-249382291-896437109-2814540638-1001\SOFTWARE | Run : [Google Update] - "C:\Users\Martin Slovják\AppData\Local\Google\Update\GoogleUpdate.exe" /c
HKU\S-1-5-21-249382291-896437109-2814540638-1001\SOFTWARE | Run : [DAEMON Tools Lite] - "D:\DAEMON\DTLite.exe" -autorun
HKU\S-1-5-19\SOFTWARE | RunOnce : [mctadmin] - C:\Windows\System32\mctadmin.exe
HKU\S-1-5-20\SOFTWARE | RunOnce : [mctadmin] - C:\Windows\System32\mctadmin.exe
################## | Stopped processes |
Stopped! C:\Program Files (x86)\Hewlett-Packard\File Sanitizer\HPFSService.exe (900)
Stopped! c:\Program Files\Microsoft Security Client\MsMpEng.exe (1016)
Stopped! C:\windows\system32\atiesrxx.exe (488)
Stopped! C:\Program Files\IDT\WDM\STacSV64.exe (1136)
Stopped! C:\windows\system32\atieclxx.exe (1448)
Stopped! C:\windows\system32\Hpservice.exe (1460)
Stopped! C:\windows\system32\vcsFPService.exe (1492)
Stopped! C:\windows\System32\spoolsv.exe (1700)
Stopped! c:\Program Files\Hewlett-Packard\HP ProtectTools Security Manager\Bin\DpHostW.exe (1744)
Stopped! C:\Program Files (x86)\Avira\AntiVir Desktop\sched.exe (1888)
Stopped! C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe (1404)
Stopped! C:\Program Files\IDT\WDM\AESTSr64.exe (1600)
Stopped! C:\Program Files (x86)\Avira\AntiVir Desktop\avguard.exe (1084)
Stopped! C:\Program Files (x86)\Bluetooth Suite\Ath_CoexAgent.exe (1056)
Stopped! C:\Program Files (x86)\Bluetooth Suite\adminservice.exe (2084)
Stopped! C:\Program Files (x86)\Dokan\DokanLibrary\mounter.exe (2132)
Stopped! C:\Program Files (x86)\Hewlett-Packard\HP Hotkey Support\HpHotkeyMonitor.exe (2160)
Stopped! C:\Program Files (x86)\Intel\Services\IPT\jhi_service.exe (2200)
Stopped! C:\Program Files\Hewlett-Packard\Drive Encryption\EEAgent\MfeEpeHost.exe (2232)
Stopped! D:\Autodesk\Inventor 2012\Moldflow\bin\mitsijm.exe (2308)
Stopped! C:\Program Files (x86)\Common Files\Portrait Displays\Drivers\pdisrvc.exe (2344)
Stopped! C:\Program Files (x86)\Microsoft Application Virtualization Client\sftvsa.exe (2620)
Stopped! C:\windows\SysWow64\ArcVCapRender\uArcCapture.exe (2740)
Stopped! C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE (2888)
Stopped! C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe (3056)
Stopped! C:\Program Files (x86)\Microsoft Application Virtualization Client\sftlist.exe (3100)
Stopped! C:\Program Files (x86)\Avira\AntiVir Desktop\avshadow.exe (3268)
Stopped! C:\Program Files (x86)\Common Files\Microsoft Shared\Virtualization Handler\CVHSVC.EXE (3288)
Stopped! C:\Program Files (x86)\Hewlett-Packard\Shared\hpqWmiEx.exe (3548)
Stopped! c:\Program Files (x86)\Hewlett-Packard\2009 Password Filter for HP ProtectTools\PTChangeFilterService.exe (3604)
Stopped! C:\windows\servicing\TrustedInstaller.exe (4064)
Stopped! C:\windows\system32\taskhost.exe (3768)
Stopped! C:\Program Files (x86)\Bluetooth Suite\BtvStack.exe (3192)
Stopped! C:\Program Files (x86)\Bluetooth Suite\AthBtTray.exe (4104)
Stopped! C:\Program Files\IDT\WDM\sttray64.exe (4116)
Stopped! C:\Program Files\Hewlett-Packard\Drive Encryption\EpePcMonitor.exe (4124)
Stopped! C:\Program Files\Microsoft Security Client\msseces.exe (4172)
Stopped! C:\Windows\System32\igfxtray.exe (4192)
Stopped! C:\Windows\System32\hkcmd.exe (4200)
Stopped! C:\Windows\System32\igfxpers.exe (4216)
Stopped! C:\Program Files\Synaptics\SynTP\SynTPEnh.exe (4240)
Stopped! C:\Program Files (x86)\Hewlett-Packard\HP HotKey Support\QLBController.exe (4836)
Stopped! C:\Program Files (x86)\Hewlett-Packard\File Sanitizer\coreshredder.exe (4844)
Stopped! C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe (4856)
Stopped! C:\Program Files (x86)\Renesas Electronics\USB 3.0 Host Controller Driver\Application\nusb3mon.exe (4872)
Stopped! C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe (4952)
Stopped! C:\Program Files (x86)\Avira\AntiVir Desktop\avgnt.exe (4972)
Stopped! C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe (4980)
Stopped! C:\Program Files (x86)\Hewlett-Packard\HP QuickWeb\hpqwutils.exe (4992)
Stopped! C:\windows\system32\SearchIndexer.exe (4596)
Stopped! C:\PROGRAM FILES\SYNAPTICS\SYNTP\SYNTPHELPER.EXE (4292)
Stopped! C:\Program Files\Windows Media Player\wmpnetwk.exe (4416)
Stopped! c:\Program Files\Hewlett-Packard\HP ProtectTools Security Manager\Bin\DPAgent.exe (5360)
Stopped! C:\Users\Martin Slovják\AppData\Local\Google\Chrome\Application\chrome.exe (5836)
Stopped! C:\Users\Martin Slovják\AppData\Local\Google\Chrome\Application\chrome.exe (4448)
Stopped! c:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\MOM.exe (5164)
Stopped! C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CCC.exe (4332)
Stopped! C:\Program Files\Hewlett-Packard\HP Power Assistant\HPPA_Service.exe (4488)
Stopped! C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\hpsa_service.exe (6068)
Stopped! C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe (5208)
Stopped! C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe (1168)
Stopped! C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe (3128)
Stopped! C:\Program Files\Hewlett-Packard\HP Power Assistant\HPPA_Main.exe (5332)
Stopped! C:\Program Files (x86)\Common Files\Portrait Displays\Drivers\SDKCOMServer.exe (2516)
Stopped! C:\windows\Microsoft.Net\Framework64\v3.0\WPF\PresentationFontCache.exe (1808)
Stopped! C:\Program Files (x86)\Common Files\Portrait Displays\Drivers\pdiSdkHelperx64.exe (4664)
Stopped! C:\windows\system32\igfxext.exe (5740)
Stopped! C:\windows\system32\igfxsrvc.exe (5400)
Stopped! C:\Users\Martin Slovják\AppData\Local\Google\Chrome\Application\chrome.exe (884)
Stopped! C:\windows\system32\vssvc.exe (3788)
Stopped! C:\windows\system32\SearchProtocolHost.exe (4888)
Stopped! C:\Users\Martin Slovják\AppData\Local\Google\Chrome\Application\chrome.exe (2556)
Stopped! C:\Users\Martin Slovják\AppData\Local\Google\Chrome\Application\chrome.exe (4280)
Stopped! C:\Users\Martin Slovják\AppData\Local\Google\Chrome\Application\chrome.exe (2856)
Stopped! C:\windows\system32\SearchFilterHost.exe (5496)
Stopped! C:\windows\system32\RunDll32.exe (5888)
################## | Files # Infected Folders |
Deleted ! C:\Users\Martin Slovják\AppData\Roaming\dll-files.com
Not deleted ! H:\Setup.exe
Not deleted ! H:\autorun.inf
(!) Temporary files deleted.
################## | Registry |
################## | Mountpoints2 |
Deleted ! HKCU\.\.\.\.\Explorer\MountPoints2\{d490a465-df58-11e0-ab13-806e6f6e6963}
Deleted ! HKCU\.\.\.\.\Explorer\MountPoints2\{ee4d05d8-a884-11e1-b6c9-101f74e92695}
################## | Listing |
[09/11/2011 - 17:11:40 | SHD ] C:\$Recycle.Bin
[29/03/2013 - 07:57:03 | N | 1492] C:\AdwCleaner[R1].txt
[02/04/2013 - 15:44:05 | N | 1110] C:\AdwCleaner[R2].txt
[31/03/2013 - 11:36:28 | N | 1503] C:\AdwCleaner[S1].txt
[23/11/2012 - 15:12:15 | D ] C:\AMD
[15/01/2012 - 16:33:57 | D ] C:\ATI
[14/11/2011 - 21:04:26 | D ] C:\Autodesk
[27/07/2009 - 17:04:41 | SHD ] C:\boot
[14/07/2009 - 03:38:58 | RASH | 383562] C:\bootmgr
[14/07/2009 - 07:08:56 | SHD ] C:\Documents and Settings
[10/05/2011 - 21:24:02 | D ] C:\EFI
[19/06/2014 - 17:33:31 | ASH | 4226138112] C:\hiberfil.sys
[10/05/2011 - 22:29:07 | D ] C:\hp
[25/08/2013 - 20:10:50 | D ] C:\Intel
[18/09/2012 - 22:02:31 | D ] C:\MITSI 2012 Temporary Files
[19/06/2014 - 17:33:35 | ASH | 4226138112] C:\pagefile.sys
[11/02/2012 - 22:58:01 | D ] C:\PerfLogs
[15/11/2011 - 20:28:16 | D ] C:\PFiles
[23/05/2014 - 10:44:39 | D ] C:\Program Files
[23/05/2014 - 10:45:37 | D ] C:\Program Files (x86)
[31/03/2014 - 15:07:54 | HD ] C:\ProgramData
[05/03/2014 - 19:57:10 | D ] C:\swsetup
[19/06/2014 - 17:44:58 | SHD ] C:\System Volume Information
[09/11/2011 - 17:37:38 | D ] C:\SYSTEM.SAV
[19/06/2014 - 17:58:33 | D ] C:\UsbFix
[19/06/2014 - 17:58:47 | A | 12233] C:\UsbFix [Clean 1] C02-613A.txt
[16/09/2012 - 12:53:39 | D ] C:\Users
[23/05/2014 - 10:45:40 | D ] C:\Windows
[02/02/2012 - 08:08:24 | SHD ] D:\$RECYCLE.BIN
[21/04/2014 - 20:35:10 | D ] D:\Autocad 2007
[20/03/2014 - 20:54:32 | D ] D:\Autodesk
[11/02/2014 - 15:15:18 | D ] D:\Cities XL
[06/08/2013 - 19:14:48 | D ] D:\CS.NS
[28/05/2012 - 13:08:19 | D ] D:\DAEMON
[28/04/2014 - 22:49:46 | D ] D:\ddd
[09/07/2012 - 12:56:37 | D ] D:\Empire Earth
[23/01/2014 - 21:48:48 | D ] D:\Fire
[19/12/2012 - 12:21:58 | D ] D:\IL
[16/08/2012 - 21:08:32 | D ] D:\IL-2
[28/05/2012 - 13:24:43 | D ] D:\KONAMI
[11/03/2013 - 18:25:32 | N | 3510632] D:\LeagueofLegends.exe
[20/12/2013 - 11:50:49 | D ] D:\LoL
[16/04/2014 - 10:35:06 | D ] D:\MC server
[26/03/2013 - 19:27:20 | D ] D:\mumble
[26/05/2013 - 15:12:31 | D ] D:\music
[13/02/2012 - 18:42:07 | D ] D:\Nokia
[26/06/2013 - 19:50:09 | D ] D:\Race Driver 3
[19/05/2013 - 17:12:01 | D ] D:\rtw
[07/06/2012 - 17:16:38 | D ] D:\SetPoint
[08/08/2012 - 08:43:39 | D ] D:\Sierra
[23/02/2014 - 11:11:42 | D ] D:\Sketchup
[26/02/2014 - 20:48:11 | D ] D:\Steam
[20/11/2012 - 16:28:48 | SHD ] D:\System Volume Information
[16/08/2012 - 15:32:33 | D ] D:\TmN
[02/01/2014 - 15:15:17 | D ] D:\TS3
[02/02/2013 - 12:39:05 | D ] D:\VHE
[25/04/2014 - 22:13:05 | D ] D:\VLC
[04/06/2014 - 15:32:34 | D ] D:\WarThunder
[18/06/2014 - 15:09:58 | D ] D:\WoT
[01/04/2014 - 13:58:31 | D ] D:\Zástupci - Plocha
[09/11/2011 - 17:11:40 | SHD ] E:\$RECYCLE.BIN
[09/11/2011 - 17:01:48 | ASHD ] E:\boot
[14/07/2009 - 03:38:58 | ASH | 383562] E:\bootmgr
[25/10/2012 - 16:17:58 | N | 21] E:\HPSF_Rep.txt
[15/09/2011 - 07:35:33 | N | 0] E:\HP_WINRE
[29/11/2011 - 16:10:44 | N | 8] E:\HP_WSD.dat
[09/11/2011 - 17:01:46 | ASHD ] E:\Recovery
[09/11/2011 - 23:17:06 | SHD ] E:\System Volume Information
[15/09/2011 - 07:35:34 | D ] E:\system.sav
[14/09/2011 - 21:32:32 | N | 33] F:\HP_Tools
[14/09/2011 - 21:52:18 | SHD ] F:\$RECYCLE.BIN
[25/10/2012 - 16:18:00 | N | 21] F:\HPSF_Rep.txt
[29/11/2011 - 15:10:46 | N | 8] F:\HP_WSD.dat
[14/09/2011 - 22:13:58 | D ] F:\Hewlett-Packard
[03/05/2006 - 17:57:04 | D ] H:\Bin
[03/05/2006 - 17:57:54 | D ] H:\MediaBrowser
[22/10/2004 - 03:38:02 | R | 126976] H:\MediaBrowser.exe
[31/01/2006 - 18:13:33 | R | 435] H:\MediaBrowser.ini
[16/12/2005 - 09:30:27 | R | 53248] H:\Setup.exe
[22/02/2002 - 21:35:36 | R | 43] H:\autorun.inf
################## | Vaccin |
C:\Autorun.inf -> Vaccine created by UsbFix (El Desaparecido)
D:\Autorun.inf -> Vaccine created by UsbFix (El Desaparecido)
E:\Autorun.inf -> Vaccine created by UsbFix (El Desaparecido)
F:\Autorun.inf -> Vaccine created by UsbFix (El Desaparecido)
################## | E.O.F | http://www.sosvirus.net |
############################## | UsbFix V 7.134 | [Deletion]
User: Martin Slovják (Administrator) # C02-613A
Updated 06/09/2013 by El Desaparecido
Started at 17:47:52 | 19/06/2014
Website: http://www.sosvirus.net/
Upload Malware: http://www.sosvirus.net/upload_malware.php
Contact: eldesaparecido@sosvirus.net
PC: Hewlett-Packard (HP ProBook 4530s) (x64-based PC)
CPU: Intel(R) Core(TM) i3-2330M CPU @ 2.20GHz (2200)
RAM -> [Total : 4030 | Free : 1859]
BIOS: Default System BIOS
BOOT: Normal boot
OS: Microsoft Windows 7 Home Premium (6.1.7601 64-Bit) # Service Pack 1
WB: Windows Internet Explorer 11.0.9600.17126
SC: Security Center Service [Enabled]
WU: Windows Update Service [Enabled]
AV: Avira Desktop [(!) Disabled | Updated]
FW: Windows FireWall Service [Enabled]
C:\ (%systemdrive%) -> Fixed drive # 379 Gb (266 Mb free - 70%) [] # NTFS
D:\ -> Fixed drive # 195 Gb (95 Mb free - 49%) [Data] # NTFS
E:\ -> Fixed drive # 17 Gb (3 Mb free - 15%) [HP_RECOVERY] # NTFS
F:\ -> Fixed drive # 5 Gb (2 Mb free - 42%) [HP_TOOLS] # FAT32
G:\ -> CD-ROM
H:\ -> CD-ROM
################## | El Desaparecido Section |
HKLM\SOFTWARE | Run : [QLBController] - C:\Program Files (x86)\Hewlett-Packard\HP HotKey Support\QLBController.exe /start
HKLM\SOFTWARE | Run : [File Sanitizer] - C:\Program Files (x86)\Hewlett-Packard\File Sanitizer\CoreShredder.exe
HKLM\SOFTWARE | Run : [IAStorIcon] - C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe
HKLM\SOFTWARE | Run : [NUSB3MON] - "c:\Program Files (x86)\Renesas Electronics\USB 3.0 Host Controller Driver\Application\nusb3mon.exe"
HKLM\SOFTWARE | Run : [HPConnectionManager] - c:\Program Files (x86)\Hewlett-Packard\HP Connection Manager\HPCMDelayStart.exe
HKLM\SOFTWARE | Run : [] -
HKLM\SOFTWARE | Run : [NWEReboot] -
HKLM\SOFTWARE | Run : [Adobe ARM] - "C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
HKLM\SOFTWARE | Run : [StartCCC] - "c:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" MSRun
HKLM\SOFTWARE | Run : [avgnt] - "C:\Program Files (x86)\Avira\AntiVir Desktop\avgnt.exe" /min
HKLM\SOFTWARE | Run : [SunJavaUpdateSched] - "C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe"
HKLM\SOFTWARE | Run : [HPQuickWebProxy] - "C:\Program Files (x86)\Hewlett-Packard\HP QuickWeb\hpqwutils.exe"
HKLM\SOFTWARE\wow6432Node | Run : [QLBController] - C:\Program Files (x86)\Hewlett-Packard\HP HotKey Support\QLBController.exe /start
HKLM\SOFTWARE\wow6432Node | Run : [File Sanitizer] - C:\Program Files (x86)\Hewlett-Packard\File Sanitizer\CoreShredder.exe
HKLM\SOFTWARE\wow6432Node | Run : [IAStorIcon] - C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe
HKLM\SOFTWARE\wow6432Node | Run : [NUSB3MON] - "c:\Program Files (x86)\Renesas Electronics\USB 3.0 Host Controller Driver\Application\nusb3mon.exe"
HKLM\SOFTWARE\wow6432Node | Run : [HPConnectionManager] - c:\Program Files (x86)\Hewlett-Packard\HP Connection Manager\HPCMDelayStart.exe
HKLM\SOFTWARE\wow6432Node | Run : [] -
HKLM\SOFTWARE\wow6432Node | Run : [NWEReboot] -
HKLM\SOFTWARE\wow6432Node | Run : [Adobe ARM] - "C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
HKLM\SOFTWARE\wow6432Node | Run : [StartCCC] - "c:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" MSRun
HKLM\SOFTWARE\wow6432Node | Run : [avgnt] - "C:\Program Files (x86)\Avira\AntiVir Desktop\avgnt.exe" /min
HKLM\SOFTWARE\wow6432Node | Run : [SunJavaUpdateSched] - "C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe"
HKLM\SOFTWARE\wow6432Node | Run : [HPQuickWebProxy] - "C:\Program Files (x86)\Hewlett-Packard\HP QuickWeb\hpqwutils.exe"
HKLM\SOFTWARE | RunOnce : [] -
HKLM\SOFTWARE\wow6432Node | RunOnce : [] -
HKU\S-1-5-19\SOFTWARE | Run : [Sidebar] - %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun
HKU\S-1-5-20\SOFTWARE | Run : [Sidebar] - %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun
HKU\S-1-5-21-249382291-896437109-2814540638-1001\SOFTWARE | Run : [NextLive] - C:\windows\SysWOW64\rundll32.exe "C:\Users\Martin Slovják\AppData\Roaming\newnext.me\nengine.dll",EntryPoint -m l
HKU\S-1-5-21-249382291-896437109-2814540638-1001\SOFTWARE | Run : [Google Update] - "C:\Users\Martin Slovják\AppData\Local\Google\Update\GoogleUpdate.exe" /c
HKU\S-1-5-21-249382291-896437109-2814540638-1001\SOFTWARE | Run : [DAEMON Tools Lite] - "D:\DAEMON\DTLite.exe" -autorun
HKU\S-1-5-19\SOFTWARE | RunOnce : [mctadmin] - C:\Windows\System32\mctadmin.exe
HKU\S-1-5-20\SOFTWARE | RunOnce : [mctadmin] - C:\Windows\System32\mctadmin.exe
################## | Stopped processes |
Stopped! C:\Program Files (x86)\Hewlett-Packard\File Sanitizer\HPFSService.exe (900)
Stopped! c:\Program Files\Microsoft Security Client\MsMpEng.exe (1016)
Stopped! C:\windows\system32\atiesrxx.exe (488)
Stopped! C:\Program Files\IDT\WDM\STacSV64.exe (1136)
Stopped! C:\windows\system32\atieclxx.exe (1448)
Stopped! C:\windows\system32\Hpservice.exe (1460)
Stopped! C:\windows\system32\vcsFPService.exe (1492)
Stopped! C:\windows\System32\spoolsv.exe (1700)
Stopped! c:\Program Files\Hewlett-Packard\HP ProtectTools Security Manager\Bin\DpHostW.exe (1744)
Stopped! C:\Program Files (x86)\Avira\AntiVir Desktop\sched.exe (1888)
Stopped! C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe (1404)
Stopped! C:\Program Files\IDT\WDM\AESTSr64.exe (1600)
Stopped! C:\Program Files (x86)\Avira\AntiVir Desktop\avguard.exe (1084)
Stopped! C:\Program Files (x86)\Bluetooth Suite\Ath_CoexAgent.exe (1056)
Stopped! C:\Program Files (x86)\Bluetooth Suite\adminservice.exe (2084)
Stopped! C:\Program Files (x86)\Dokan\DokanLibrary\mounter.exe (2132)
Stopped! C:\Program Files (x86)\Hewlett-Packard\HP Hotkey Support\HpHotkeyMonitor.exe (2160)
Stopped! C:\Program Files (x86)\Intel\Services\IPT\jhi_service.exe (2200)
Stopped! C:\Program Files\Hewlett-Packard\Drive Encryption\EEAgent\MfeEpeHost.exe (2232)
Stopped! D:\Autodesk\Inventor 2012\Moldflow\bin\mitsijm.exe (2308)
Stopped! C:\Program Files (x86)\Common Files\Portrait Displays\Drivers\pdisrvc.exe (2344)
Stopped! C:\Program Files (x86)\Microsoft Application Virtualization Client\sftvsa.exe (2620)
Stopped! C:\windows\SysWow64\ArcVCapRender\uArcCapture.exe (2740)
Stopped! C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE (2888)
Stopped! C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe (3056)
Stopped! C:\Program Files (x86)\Microsoft Application Virtualization Client\sftlist.exe (3100)
Stopped! C:\Program Files (x86)\Avira\AntiVir Desktop\avshadow.exe (3268)
Stopped! C:\Program Files (x86)\Common Files\Microsoft Shared\Virtualization Handler\CVHSVC.EXE (3288)
Stopped! C:\Program Files (x86)\Hewlett-Packard\Shared\hpqWmiEx.exe (3548)
Stopped! c:\Program Files (x86)\Hewlett-Packard\2009 Password Filter for HP ProtectTools\PTChangeFilterService.exe (3604)
Stopped! C:\windows\servicing\TrustedInstaller.exe (4064)
Stopped! C:\windows\system32\taskhost.exe (3768)
Stopped! C:\Program Files (x86)\Bluetooth Suite\BtvStack.exe (3192)
Stopped! C:\Program Files (x86)\Bluetooth Suite\AthBtTray.exe (4104)
Stopped! C:\Program Files\IDT\WDM\sttray64.exe (4116)
Stopped! C:\Program Files\Hewlett-Packard\Drive Encryption\EpePcMonitor.exe (4124)
Stopped! C:\Program Files\Microsoft Security Client\msseces.exe (4172)
Stopped! C:\Windows\System32\igfxtray.exe (4192)
Stopped! C:\Windows\System32\hkcmd.exe (4200)
Stopped! C:\Windows\System32\igfxpers.exe (4216)
Stopped! C:\Program Files\Synaptics\SynTP\SynTPEnh.exe (4240)
Stopped! C:\Program Files (x86)\Hewlett-Packard\HP HotKey Support\QLBController.exe (4836)
Stopped! C:\Program Files (x86)\Hewlett-Packard\File Sanitizer\coreshredder.exe (4844)
Stopped! C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe (4856)
Stopped! C:\Program Files (x86)\Renesas Electronics\USB 3.0 Host Controller Driver\Application\nusb3mon.exe (4872)
Stopped! C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe (4952)
Stopped! C:\Program Files (x86)\Avira\AntiVir Desktop\avgnt.exe (4972)
Stopped! C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe (4980)
Stopped! C:\Program Files (x86)\Hewlett-Packard\HP QuickWeb\hpqwutils.exe (4992)
Stopped! C:\windows\system32\SearchIndexer.exe (4596)
Stopped! C:\PROGRAM FILES\SYNAPTICS\SYNTP\SYNTPHELPER.EXE (4292)
Stopped! C:\Program Files\Windows Media Player\wmpnetwk.exe (4416)
Stopped! c:\Program Files\Hewlett-Packard\HP ProtectTools Security Manager\Bin\DPAgent.exe (5360)
Stopped! C:\Users\Martin Slovják\AppData\Local\Google\Chrome\Application\chrome.exe (5836)
Stopped! C:\Users\Martin Slovják\AppData\Local\Google\Chrome\Application\chrome.exe (4448)
Stopped! c:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\MOM.exe (5164)
Stopped! C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CCC.exe (4332)
Stopped! C:\Program Files\Hewlett-Packard\HP Power Assistant\HPPA_Service.exe (4488)
Stopped! C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\hpsa_service.exe (6068)
Stopped! C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe (5208)
Stopped! C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe (1168)
Stopped! C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe (3128)
Stopped! C:\Program Files\Hewlett-Packard\HP Power Assistant\HPPA_Main.exe (5332)
Stopped! C:\Program Files (x86)\Common Files\Portrait Displays\Drivers\SDKCOMServer.exe (2516)
Stopped! C:\windows\Microsoft.Net\Framework64\v3.0\WPF\PresentationFontCache.exe (1808)
Stopped! C:\Program Files (x86)\Common Files\Portrait Displays\Drivers\pdiSdkHelperx64.exe (4664)
Stopped! C:\windows\system32\igfxext.exe (5740)
Stopped! C:\windows\system32\igfxsrvc.exe (5400)
Stopped! C:\Users\Martin Slovják\AppData\Local\Google\Chrome\Application\chrome.exe (884)
Stopped! C:\windows\system32\vssvc.exe (3788)
Stopped! C:\windows\system32\SearchProtocolHost.exe (4888)
Stopped! C:\Users\Martin Slovják\AppData\Local\Google\Chrome\Application\chrome.exe (2556)
Stopped! C:\Users\Martin Slovják\AppData\Local\Google\Chrome\Application\chrome.exe (4280)
Stopped! C:\Users\Martin Slovják\AppData\Local\Google\Chrome\Application\chrome.exe (2856)
Stopped! C:\windows\system32\SearchFilterHost.exe (5496)
Stopped! C:\windows\system32\RunDll32.exe (5888)
################## | Files # Infected Folders |
Deleted ! C:\Users\Martin Slovják\AppData\Roaming\dll-files.com
Not deleted ! H:\Setup.exe
Not deleted ! H:\autorun.inf
(!) Temporary files deleted.
################## | Registry |
################## | Mountpoints2 |
Deleted ! HKCU\.\.\.\.\Explorer\MountPoints2\{d490a465-df58-11e0-ab13-806e6f6e6963}
Deleted ! HKCU\.\.\.\.\Explorer\MountPoints2\{ee4d05d8-a884-11e1-b6c9-101f74e92695}
################## | Listing |
[09/11/2011 - 17:11:40 | SHD ] C:\$Recycle.Bin
[29/03/2013 - 07:57:03 | N | 1492] C:\AdwCleaner[R1].txt
[02/04/2013 - 15:44:05 | N | 1110] C:\AdwCleaner[R2].txt
[31/03/2013 - 11:36:28 | N | 1503] C:\AdwCleaner[S1].txt
[23/11/2012 - 15:12:15 | D ] C:\AMD
[15/01/2012 - 16:33:57 | D ] C:\ATI
[14/11/2011 - 21:04:26 | D ] C:\Autodesk
[27/07/2009 - 17:04:41 | SHD ] C:\boot
[14/07/2009 - 03:38:58 | RASH | 383562] C:\bootmgr
[14/07/2009 - 07:08:56 | SHD ] C:\Documents and Settings
[10/05/2011 - 21:24:02 | D ] C:\EFI
[19/06/2014 - 17:33:31 | ASH | 4226138112] C:\hiberfil.sys
[10/05/2011 - 22:29:07 | D ] C:\hp
[25/08/2013 - 20:10:50 | D ] C:\Intel
[18/09/2012 - 22:02:31 | D ] C:\MITSI 2012 Temporary Files
[19/06/2014 - 17:33:35 | ASH | 4226138112] C:\pagefile.sys
[11/02/2012 - 22:58:01 | D ] C:\PerfLogs
[15/11/2011 - 20:28:16 | D ] C:\PFiles
[23/05/2014 - 10:44:39 | D ] C:\Program Files
[23/05/2014 - 10:45:37 | D ] C:\Program Files (x86)
[31/03/2014 - 15:07:54 | HD ] C:\ProgramData
[05/03/2014 - 19:57:10 | D ] C:\swsetup
[19/06/2014 - 17:44:58 | SHD ] C:\System Volume Information
[09/11/2011 - 17:37:38 | D ] C:\SYSTEM.SAV
[19/06/2014 - 17:58:33 | D ] C:\UsbFix
[19/06/2014 - 17:58:47 | A | 12233] C:\UsbFix [Clean 1] C02-613A.txt
[16/09/2012 - 12:53:39 | D ] C:\Users
[23/05/2014 - 10:45:40 | D ] C:\Windows
[02/02/2012 - 08:08:24 | SHD ] D:\$RECYCLE.BIN
[21/04/2014 - 20:35:10 | D ] D:\Autocad 2007
[20/03/2014 - 20:54:32 | D ] D:\Autodesk
[11/02/2014 - 15:15:18 | D ] D:\Cities XL
[06/08/2013 - 19:14:48 | D ] D:\CS.NS
[28/05/2012 - 13:08:19 | D ] D:\DAEMON
[28/04/2014 - 22:49:46 | D ] D:\ddd
[09/07/2012 - 12:56:37 | D ] D:\Empire Earth
[23/01/2014 - 21:48:48 | D ] D:\Fire
[19/12/2012 - 12:21:58 | D ] D:\IL
[16/08/2012 - 21:08:32 | D ] D:\IL-2
[28/05/2012 - 13:24:43 | D ] D:\KONAMI
[11/03/2013 - 18:25:32 | N | 3510632] D:\LeagueofLegends.exe
[20/12/2013 - 11:50:49 | D ] D:\LoL
[16/04/2014 - 10:35:06 | D ] D:\MC server
[26/03/2013 - 19:27:20 | D ] D:\mumble
[26/05/2013 - 15:12:31 | D ] D:\music
[13/02/2012 - 18:42:07 | D ] D:\Nokia
[26/06/2013 - 19:50:09 | D ] D:\Race Driver 3
[19/05/2013 - 17:12:01 | D ] D:\rtw
[07/06/2012 - 17:16:38 | D ] D:\SetPoint
[08/08/2012 - 08:43:39 | D ] D:\Sierra
[23/02/2014 - 11:11:42 | D ] D:\Sketchup
[26/02/2014 - 20:48:11 | D ] D:\Steam
[20/11/2012 - 16:28:48 | SHD ] D:\System Volume Information
[16/08/2012 - 15:32:33 | D ] D:\TmN
[02/01/2014 - 15:15:17 | D ] D:\TS3
[02/02/2013 - 12:39:05 | D ] D:\VHE
[25/04/2014 - 22:13:05 | D ] D:\VLC
[04/06/2014 - 15:32:34 | D ] D:\WarThunder
[18/06/2014 - 15:09:58 | D ] D:\WoT
[01/04/2014 - 13:58:31 | D ] D:\Zástupci - Plocha
[09/11/2011 - 17:11:40 | SHD ] E:\$RECYCLE.BIN
[09/11/2011 - 17:01:48 | ASHD ] E:\boot
[14/07/2009 - 03:38:58 | ASH | 383562] E:\bootmgr
[25/10/2012 - 16:17:58 | N | 21] E:\HPSF_Rep.txt
[15/09/2011 - 07:35:33 | N | 0] E:\HP_WINRE
[29/11/2011 - 16:10:44 | N | 8] E:\HP_WSD.dat
[09/11/2011 - 17:01:46 | ASHD ] E:\Recovery
[09/11/2011 - 23:17:06 | SHD ] E:\System Volume Information
[15/09/2011 - 07:35:34 | D ] E:\system.sav
[14/09/2011 - 21:32:32 | N | 33] F:\HP_Tools
[14/09/2011 - 21:52:18 | SHD ] F:\$RECYCLE.BIN
[25/10/2012 - 16:18:00 | N | 21] F:\HPSF_Rep.txt
[29/11/2011 - 15:10:46 | N | 8] F:\HP_WSD.dat
[14/09/2011 - 22:13:58 | D ] F:\Hewlett-Packard
[03/05/2006 - 17:57:04 | D ] H:\Bin
[03/05/2006 - 17:57:54 | D ] H:\MediaBrowser
[22/10/2004 - 03:38:02 | R | 126976] H:\MediaBrowser.exe
[31/01/2006 - 18:13:33 | R | 435] H:\MediaBrowser.ini
[16/12/2005 - 09:30:27 | R | 53248] H:\Setup.exe
[22/02/2002 - 21:35:36 | R | 43] H:\autorun.inf
################## | Vaccin |
C:\Autorun.inf -> Vaccine created by UsbFix (El Desaparecido)
D:\Autorun.inf -> Vaccine created by UsbFix (El Desaparecido)
E:\Autorun.inf -> Vaccine created by UsbFix (El Desaparecido)
F:\Autorun.inf -> Vaccine created by UsbFix (El Desaparecido)
################## | E.O.F | http://www.sosvirus.net |