Advertisement
Guest User

Untitled

a guest
Jan 26th, 2014
62
0
Never
Not a member of Pastebin yet? Sign Up, it unlocks many cool features!
text 9.04 KB | None | 0 0
  1. ############################## | UsbFix V 7.161 | [Deletion]
  2.  
  3. User: Fedycki (Administrator) # FEDYCKI-KOMPUTE
  4. Updated 15/01/2014 by El Desaparecido - Team SosVirus
  5. Started at 15:58:18 | 26/01/2014
  6.  
  7. Website : http://www.en.usbfix.net
  8. Changelog : http://www.usbfix.net/maj/
  9. Support : http://www.sosvirus.net/
  10. Upload Malware : http://www.sosvirus.net/upload_malware.php
  11. Contact : http://www.en.usbfix.net/contact/
  12.  
  13. PC: ASUSTeK Computer INC. (P5G41T-M LX)
  14. CPU: Pentium(R) Dual-Core CPU E6700 @ 3.20GHz
  15. RAM -> [Total : 2047 Mo| Free : 843 Mo]
  16. Bios: American Megatrends Inc.
  17. Boot: Normal boot
  18.  
  19. OS: Microsoft Windows 7 Professional (6.1.7601 64-Bit) Service Pack 1
  20. WB: Windows Internet Explorer : 8.0.7601.17514
  21. WB: Google Chrome : 31.0.1650.63
  22.  
  23. SC: Security Center Service [(!) Disabled]
  24. WU: Windows Update Service [(!) Disabled]
  25. AV: Microsoft Security Essentials [Enabled | Updated]
  26. AS: Windows Defender : 6.1.7600.16385 (win7_rtm.090713-1255)
  27. FW: Windows FireWall Service [(!) Disabled]
  28.  
  29. C:\ (%systemdrive%) -> Fixed drive # 146 Gb (98 Mb free - 67%) [Zastrzeżone przez system] # NTFS
  30. D:\ -> Fixed drive # 146 Gb (80 Mb free - 54%) [Programy] # NTFS
  31. E:\ -> Fixed drive # 173 Gb (140 Mb free - 81%) [GRY] # NTFS
  32. F:\ -> CD-ROM
  33.  
  34. ################## | Stopped processes |
  35.  
  36. Stopped! C:\Windows\Explorer.EXE (ID: 2444 |ParentID: 2376)
  37. Stopped! C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE (ID: 4728 |ParentID: 496)
  38. Stopped! C:\Windows\system32\SearchIndexer.exe (ID: 4660 |ParentID: 496)
  39. Stopped! C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe (ID: 4612 |ParentID: 4728)
  40. Stopped! C:\Program Files\Microsoft Security Client\Antimalware\MsMpEng.exe (ID: 2068 |ParentID: 496)
  41. Stopped! C:\Program Files\Microsoft Security Client\Antimalware\NisSrv.exe (ID: 940 |ParentID: 496)
  42. Stopped! C:\Program Files\Windows Media Player\wmpnetwk.exe (ID: 3564 |ParentID: 496)
  43. Stopped! C:\Windows\System32\spoolsv.exe (ID: 4616 |ParentID: 496)
  44. Stopped! C:\Windows\system32\SearchProtocolHost.exe (ID: 2544 |ParentID: 4660)
  45. Stopped! C:\Windows\system32\SearchFilterHost.exe (ID: 1132 |ParentID: 4660)
  46.  
  47. ################## | Regedit Run |
  48.  
  49. 04 - HKLM\..\Run : [OrderReminder] C:\Program Files (x86)\Hewlett-Packard\OrderReminder\OrderReminder.exe
  50. 04 - HKLM\..\Run : [Adobe ARM] "C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
  51. 04 - HKLM\..\Run : [SunJavaUpdateSched] "C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe"
  52. 04 - HKLM\..\Run : [SwitchBoard] C:\Program Files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe
  53. 04 - HKLM\..\Run : [AdobeCS6ServiceManager] "C:\Program Files (x86)\Common Files\Adobe\CS6ServiceManager\CS6ServiceManager.exe" -launchedbylogin
  54. 04 - HKLM\..\Run : [KiesTrayAgent] E:\Kies\KiesTrayAgent.exe
  55. 04 - HKLM\..\Run : [StartCCC] "C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\amd64\CLIStart.exe" MSRun
  56. 04 - HKLM64\..\Run : [MSC] "C:\Program Files\Microsoft Security Client\msseces.exe" -hide -runkey
  57. 04 - HKLM64\..\Run : [MouseDriver] TiltWheelMouse.exe
  58. 04 - HKLM64\..\Run : [AdobeAAMUpdater-1.0] "C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe"
  59. 04 - HKU\S-1-5-19\..\Run : [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun
  60. 04 - HKU\S-1-5-20\..\Run : [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun
  61. 04 - HKU\S-1-5-21-1345903610-1416389592-3977813581-1000\..\Run : [DAEMON Tools Lite] "D:\DAEMON Tools Lite\DTLite.exe" -autorun
  62. 04 - HKU\S-1-5-21-1345903610-1416389592-3977813581-1000\..\Run : [KiesPreload] E:\Kies\Kies.exe /preload
  63. 04 - HKU\S-1-5-21-1345903610-1416389592-3977813581-1000\..\Run : [] E:\Kies\External\FirmwareUpdate\KiesPDLR.exe
  64. 04 - HKU\S-1-5-21-1345903610-1416389592-3977813581-1000\..\Run : [eRclient] "C:\Users\Fedycki\AppData\Roaming\eRclient\eRclient.exe"
  65. 04 - HKU\S-1-5-21-1345903610-1416389592-3977813581-1000\..\Run : [HydraVisionDesktopManager] "C:\Program Files (x86)\ATI Technologies\HydraVision\HydraDM.exe"
  66. 04 - HKU\S-1-5-19\..\RunOnce : [mctadmin] C:\Windows\System32\mctadmin.exe
  67. 04 - HKU\S-1-5-20\..\RunOnce : [mctadmin] C:\Windows\System32\mctadmin.exe
  68.  
  69. ################## | Generic Research |
  70.  
  71. Deleted ! C:\Users\Fedycki\AppData\Roaming\003CD0D6.exe
  72. Deleted ! E:\The Banner Saga — skrót.lnk
  73. Deleted ! C:\_OTL\MovedFiles\01262014_152523\C_ProgramData\msankaydb.exe
  74. Deleted ! C:\_OTL\MovedFiles\01262014_152523\C_ProgramData\msroxqa.exe
  75. Deleted ! C:\_OTL\MovedFiles\01262014_152523\C_Users\Fedycki\AppData\Roaming\0005666F.exe
  76. Deleted ! C:\_OTL\MovedFiles\01262014_152523\C_Users\Fedycki\AppData\Roaming\0005CDC9.exe
  77. Deleted ! C:\_OTL\MovedFiles\01262014_152523\C_Users\Fedycki\AppData\Roaming\0020ACF1.exe
  78. Deleted ! C:\_OTL\MovedFiles\01262014_152523\C_Users\Fedycki\AppData\Roaming\0057A42C.exe
  79.  
  80. (!) Temporary files deleted.
  81.  
  82. ################## | Registry |
  83.  
  84. Repaired ! HKLM\Software\Microsoft\Windows\CurrentVersion\Policies\System|EnableLUA -> 1
  85. Repaired ! HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced|Start_ShowMyGames -> 1
  86. Deleted ! HKU\S-1-5-21-1345903610-1416389592-3977813581-1000\Software\.\.\.\.\Mountpoints2\{4164822c-4398-11e2-a02f-0023481c491b}
  87. Deleted ! HKU\S-1-5-21-1345903610-1416389592-3977813581-1000\Software\.\.\.\.\Mountpoints2\{b4239810-694a-11e2-a3c1-0023481c491b}
  88.  
  89. ################## | Listing |
  90.  
  91. [18/12/2013 - 21:11:04 | SHD] - C:\$Recycle.Bin
  92. [13/06/2012 - 19:23:16 | D] - C:\16c32dfb7f1f6d8038b10a78fe9966
  93. [26/01/2014 - 13:59:58 | D] - C:\AdwCleaner
  94. [24/11/2013 - 13:45:23 | D] - C:\AMD
  95. [11/12/2011 - 19:48:42 | D] - C:\ATI
  96. [17/11/2011 - 17:47:54 | SHD] - C:\Boot
  97. [20/11/2010 - 13:40:07 | RASH | 375 Ko] - C:\bootmgr
  98. [14/05/2011 - 21:28:40 | N | 8 Ko] - C:\BOOTSECT.BAK
  99. [14/07/2009 - 06:08:56 | SHD] - C:\Documents and Settings
  100. [26/01/2014 - 15:28:59 | ASH | 1572184 Ko] - C:\hiberfil.sys
  101. [21/02/2012 - 16:17:31 | RHD] - C:\MSOCache
  102. [26/01/2014 - 15:29:01 | ASH | 2096248 Ko] - C:\pagefile.sys
  103. [14/07/2009 - 04:20:08 | D] - C:\PerfLogs
  104. [13/11/2012 - 13:21:07 | D] - C:\Plugins
  105. [28/07/2013 - 17:21:20 | D] - C:\Program Files
  106. [26/01/2014 - 13:59:22 | D] - C:\Program Files (x86)
  107. [26/01/2014 - 15:25:27 | HD] - C:\ProgramData
  108. [14/05/2011 - 14:35:01 | SHD] - C:\Recovery
  109. [25/01/2014 - 13:59:35 | SHD] - C:\System Volume Information
  110. [26/01/2014 - 15:58:19 | D] - C:\UsbFix
  111. [26/01/2014 - 16:01:07 | A | 6 Ko | 9F1DB1BBDD1E8101009F71C6BA7921B1] - C:\UsbFix [Clean 1] FEDYCKI-KOMPUTE.txt
  112. [26/01/2014 - 15:41:29 | N | 9 Ko | E9531F15A5E728619F5C4102FA18A5BA] - C:\UsbFix [Scan 1] FEDYCKI-KOMPUTE.txt
  113. [26/01/2014 - 15:57:50 | N | 7 Ko | D1428C220A744A34B4546481049D2BEA] - C:\UsbFix [Scan 2] FEDYCKI-KOMPUTE.txt
  114. [14/05/2011 - 14:35:05 | D] - C:\Users
  115. [26/02/2013 - 18:55:03 | D] - C:\video_output
  116. [26/01/2014 - 15:27:35 | D] - C:\Windows
  117. [26/01/2014 - 15:25:23 | D] - C:\_OTL
  118. [14/05/2011 - 15:06:35 | SHD] - D:\$RECYCLE.BIN
  119. [06/07/2013 - 19:11:45 | D] - D:\Config.Msi
  120. [16/05/2012 - 16:45:34 | D] - D:\DAEMON Tools Lite
  121. [31/07/2013 - 16:27:58 | D] - D:\EVEREST Home Edition
  122. [12/01/2014 - 14:03:32 | D] - D:\Filmy
  123. [11/01/2014 - 20:24:58 | D] - D:\foobar2000
  124. [17/12/2013 - 09:47:25 | D] - D:\Game Booster 3
  125. [11/01/2014 - 20:29:38 | D] - D:\Last.fm
  126. [19/12/2012 - 17:51:08 | D] - D:\LOLReplay
  127. [06/01/2014 - 13:15:05 | D] - D:\Mesajah.Jestem.Stad.2012.320kbps
  128. [29/04/2012 - 18:58:25 | D] - D:\Microsoft Visual C++
  129. [06/09/2013 - 17:30:05 | D] - D:\muzyka
  130. [18/02/2013 - 16:43:55 | D] - D:\NapiProjekt
  131. [06/04/2013 - 15:51:25 | D] - D:\PDFCreator
  132. [13/09/2013 - 17:58:44 | D] - D:\Photoshop
  133. [11/03/2012 - 14:35:22 | D] - D:\PITy
  134. [10/01/2014 - 21:08:54 | D] - D:\playlists
  135. [22/01/2014 - 12:47:25 | D] - D:\POBRANE
  136. [12/05/2013 - 16:10:04 | D] - D:\Program Files (x86)
  137. [12/01/2014 - 14:16:26 | D] - D:\RegCleaner
  138. [21/12/2012 - 21:27:50 | D] - D:\Samsung
  139. [12/01/2014 - 13:59:07 | D] - D:\SpeedFan
  140. [14/05/2011 - 15:25:13 | SHD] - D:\System Volume Information
  141. [21/12/2012 - 21:22:59 | D] - D:\USB Drivers
  142. [15/03/2013 - 18:46:16 | N | 0 Ko | 5BE710676E567F00BA6935D08CF3E6CB] - D:\ValveUnhandledExceptionFilter.txt
  143. [06/01/2014 - 13:14:56 | D] - D:\vavamuffin - vabang!-DW-Ryszardes-02-04-13
  144. [06/01/2014 - 13:14:58 | D] - D:\Vavamuffin.Solresol.2013
  145. [12/02/2013 - 17:30:45 | D] - D:\VLC
  146. [14/05/2011 - 15:29:00 | SHD] - E:\$RECYCLE.BIN
  147. [06/01/2014 - 13:12:27 | D] - E:\Artur
  148. [23/01/2014 - 16:59:24 | D] - E:\Battle.net
  149. [17/01/2014 - 19:40:24 | D] - E:\Config.Msi
  150. [06/01/2014 - 13:43:24 | D] - E:\Gadu-Gadu 10
  151. [12/01/2014 - 13:49:49 | D] - E:\Gierki
  152. [14/09/2013 - 12:13:25 | D] - E:\Kies
  153. [19/01/2014 - 15:22:29 | D] - E:\King's Bounty - Warriors of the North
  154. [06/01/2014 - 13:13:02 | D] - E:\KRÓLIKI
  155. [14/05/2011 - 17:45:48 | D] - E:\LeagueofLegends
  156. [06/01/2014 - 13:12:58 | D] - E:\Rooney
  157. [14/05/2011 - 15:25:13 | SHD] - E:\System Volume Information
  158. [16/01/2014 - 17:36:00 | D] - E:\The Banner Saga
  159. [11/01/2014 - 21:48:02 | D] - E:\Winamp
  160.  
  161. ################## | Vaccin |
  162.  
  163. D:\Autorun.inf -> Vaccine created by UsbFix (El Desaparecido)
  164. E:\Autorun.inf -> Vaccine created by UsbFix (El Desaparecido)
  165.  
  166. ################## | E.O.F | http://www.usbfix.net - http://www.sosvirus.net |
Advertisement
Add Comment
Please, Sign In to add comment
Advertisement