log po proběhnutí UsbFix:
############################## | UsbFix 7.014 | [Deletion]
User: Aleš (Administrator) # ALES-PC [System manufacturer P5E]
Updated 24/06/10 by El Desaparecido / C_XX
Started at 12:35:45 | 04/08/2011
Website:
http://pagesperso-orange.fr/NosTools/index.htmlContact:
FindyKill.Contact@gmail.comCPU: Intel(R) Core(TM)2 Quad CPU Q9550 @ 2.83GHz
CPU 2: Intel(R) Core(TM)2 Quad CPU Q9550 @ 2.83GHz
Microsoft® Windows Vista™ Business (6.0.6002 64-Bit) # Service Pack 2
Internet Explorer 9.0.8112.16421
Windows Firewall: Disabled /!\
RAM -> 4094 Mb
C:\ (%systemdrive%) -> Fixed drive # 39 Gb (2 Mb free - 5%) [Vista] # NTFS
D:\ -> Fixed drive # 195 Gb (32 Mb free - 16%) [data_0] # NTFS
E:\ -> Fixed drive # 1544 Gb (67 Mb free - 4%) [data_1] # NTFS
H:\ -> CD-ROM
I:\ -> Fixed drive # 436 Gb (40 Mb free - 9%) [data_2] # NTFS
J:\ -> Fixed drive # 29 Gb (17 Mb free - 57%) [WinXP] # NTFS
K:\ -> Fixed drive # 298 Gb (128 Mb free - 43%) [WD] # NTFS
################## | Files # Infected Folders |
################## | Registry |
Deleted ! HKLM\Software\Microsoft\Windows\CurrentVersion\Policies\System|DisableRegistryTools
Deleted ! HKLM\Software\Microsoft\Windows\CurrentVersion\Policies\explorer|NoDrives
Deleted ! HKCU\Software\Microsoft\Windows\CurrentVersion\Policies\explorer|NoDrives
################## | Mountpoints2 |
################## | Listing |
[04/08/2011 - 12:41:39 | SHD ] C:\$RECYCLE.BIN
[05/02/2011 - 17:04:18 | A | 4608] C:\6XSourceFilter.grf
[13/12/2010 - 04:37:21 | A | 356736] C:\AnalysisLog.sr0
[03/08/2011 - 02:38:12 | A | 0] C:\autoexec.bat
[14/04/2010 - 19:59:49 | D ] C:\Boot
[10/04/2009 - 23:36:38 | RASH | 333257] C:\bootmgr
[13/04/2010 - 00:27:02 | RAS | 8192] C:\BOOTSECT.BAK
[03/08/2011 - 16:05:36 | A | 65493] C:\ComboFix.txt
[03/08/2011 - 15:12:02 | D ] C:\Config.Msi
[02/11/2006 - 17:39:21 | SHD ] C:\Documents and Settings
[03/08/2011 - 03:50:54 | RSH | 103140] C:\ehiyvc.exe
[03/08/2011 - 15:07:34 | D ] C:\Garmin
[03/08/2011 - 00:53:12 | D ] C:\GvTemp
[12/04/2010 - 23:45:30 | D ] C:\Intel
[03/08/2011 - 15:18:15 | RSH | 103140] C:\jctidx.exe
[04/08/2011 - 12:23:56 | ASH | 4607631360] C:\pagefile.sys
[14/04/2010 - 14:19:08 | D ] C:\PerfLogs
[03/08/2011 - 02:37:55 | RD ] C:\Program Files
[03/08/2011 - 15:04:17 | RD ] C:\Program Files (x86)
[03/08/2011 - 14:50:05 | D ] C:\ProgramData
[03/08/2011 - 16:05:38 | AD ] C:\Qoobox
[03/08/2011 - 14:55:45 | D ] C:\sh4ldr
[03/08/2011 - 03:43:56 | A | 2157] C:\spyhunter.fix
[03/08/2011 - 15:59:46 | SHD ] C:\System Volume Information
[02/08/2011 - 23:39:48 | D ] C:\TEMP
[04/08/2011 - 12:41:39 | D ] C:\UsbFix
[04/08/2011 - 12:35:45 | A | 0] C:\UsbFix.txt
[23/07/2011 - 10:45:57 | RD ] C:\Users
[03/08/2011 - 15:18:47 | RSH | 103140] C:\uwgsjs.exe
[03/08/2011 - 16:05:37 | D ] C:\Windows
[04/08/2011 - 12:41:39 | D ] D:\$RECYCLE.BIN
[03/08/2011 - 15:13:48 | D ] D:\Config.Msi
[02/08/2011 - 13:44:11 | RD ] D:\Dokumenty
[04/08/2011 - 12:33:37 | D ] D:\Download
[02/08/2011 - 13:07:56 | D ] D:\Download_Torrent
[28/04/2011 - 01:35:24 | D ] D:\Garmin
[02/08/2011 - 13:22:05 | D ] D:\Hry
[03/08/2011 - 02:54:52 | RSH | 103140] D:\ipfkb.exe
[03/08/2011 - 15:19:51 | RSH | 103140] D:\jlpot.exe
[03/08/2011 - 15:16:41 | RSH | 103140] D:\kmmoh.exe
[29/07/2011 - 13:25:01 | D ] D:\Mix
[14/07/2010 - 13:48:43 | RD ] D:\MSOCache
[03/08/2011 - 14:50:05 | D ] D:\Programy
[04/08/2011 - 12:36:18 | D ] D:\RECYCLER
[03/08/2011 - 03:43:56 | A | 114] D:\spyhunter.fix
[21/12/2009 - 15:28:06 | SHD ] D:\System Volume Information
[03/08/2011 - 15:18:16 | RSH | 103140] D:\tnqvu.exe
[03/08/2011 - 03:50:54 | RSH | 103140] D:\xmecdk.exe
[04/08/2011 - 12:41:39 | D ] E:\$RECYCLE.BIN
[03/08/2011 - 15:17:14 | RSH | 103140] E:\aayvf.exe
[13/07/2011 - 13:07:31 | D ] E:\adaptec
[14/07/2011 - 15:53:17 | D ] E:\Flac
[03/08/2011 - 15:19:20 | RSH | 103140] E:\ilxmrf.exe
[29/04/2011 - 02:42:53 | D ] E:\Image
[04/10/2009 - 04:16:28 | D ] E:\Install
[03/08/2011 - 15:10:02 | RSH | 103140] E:\irhgh.exe
[27/05/2011 - 15:38:05 | D ] E:\MP3
[14/03/2011 - 16:00:01 | D ] E:\MP3_____X
[31/10/2010 - 13:14:07 | D ] E:\msdownld.tmp
[03/10/2009 - 19:15:55 | RD ] E:\MSOCache
[03/08/2011 - 15:17:45 | RSH | 103140] E:\ojhxal.exe
[28/07/2011 - 16:01:11 | D ] E:\Práce
[04/08/2011 - 12:36:18 | D ] E:\RECYCLER
[03/08/2011 - 02:54:52 | RSH | 103140] E:\ruvjj.exe
[21/12/2009 - 15:28:06 | SHD ] E:\System Volume Information
[17/10/2010 - 02:49:17 | D ] E:\Video
[04/10/2009 - 00:12:52 | D ] E:\Záloha
[04/08/2011 - 12:41:39 | D ] I:\$RECYCLE.BIN
[29/05/2011 - 23:54:28 | D ] I:\Any Video Converter
[03/08/2011 - 15:19:21 | RSH | 103140] I:\hvuewv.exe
[03/08/2011 - 15:18:49 | RSH | 103140] I:\kamyqm.exe
[03/08/2011 - 01:29:44 | RSH | 103140] I:\ntiagg.exe
[03/08/2011 - 15:10:02 | RSH | 103140] I:\ohalod.exe
[03/08/2011 - 02:54:52 | RSH | 103140] I:\punvgp.exe
[04/08/2011 - 12:36:19 | D ] I:\RECYCLER
[07/04/2011 - 03:22:09 | D ] I:\Star Trek 01 - Film
[11/04/2008 - 07:26:02 | D ] I:\Star Trek 02 - Khanův Hněv
[17/02/2011 - 00:55:07 | D ] I:\Star Trek 03 - The Search for Spock
[02/01/2010 - 13:59:53 | SHD ] I:\System Volume Information
[03/08/2011 - 15:19:52 | RSH | 103140] I:\urjaci.exe
[22/12/2010 - 22:40:28 | D ] I:\Video_N
[03/08/2011 - 15:00:10 | A | 103140] I:\ysthd.exe
[04/05/2011 - 11:38:21 | D ] I:\_filmy pro mamku
[02/08/2011 - 13:07:14 | D ] I:\_filmy pro Péťu
[04/08/2011 - 12:41:39 | D ] J:\$RECYCLE.BIN
[20/07/2010 - 14:07:23 | D ] J:\Adaptec
[03/08/2011 - 15:16:12 | RSH | 103140] J:\anjgkg.exe
[24/01/2011 - 20:12:54 | D ] J:\ApolloDVD
[03/08/2011 - 15:18:50 | RSH | 103140] J:\arskl.exe
[20/12/2009 - 23:55:41 | A | 0] J:\AUTOEXEC.BAT
[20/12/2009 - 23:51:55 | SH | 211] J:\boot.ini
[18/08/2004 - 12:00:00 | RASH | 4952] J:\Bootfont.bin
[20/12/2009 - 23:55:41 | A | 0] J:\CONFIG.SYS
[03/08/2011 - 00:46:55 | D ] J:\Documents and Settings
[25/01/2011 - 00:53:57 | D ] J:\DVDPean Output
[25/05/2011 - 16:46:26 | D ] J:\Hry
[21/12/2009 - 13:43:49 | D ] J:\Intel
[20/12/2009 - 23:55:41 | RASH | 0] J:\IO.SYS
[20/12/2009 - 23:55:41 | RASH | 0] J:\MSDOS.SYS
[18/08/2004 - 12:00:00 | RASH | 47564] J:\NTDETECT.COM
[18/08/2004 - 12:00:00 | RASH | 250048] J:\ntldr
[19/07/2010 - 01:23:47 | D ] J:\NVIDIA
[03/08/2011 - 00:41:17 | ASH | 2145386496] J:\pagefile.sys
[19/07/2011 - 20:36:07 | RD ] J:\Program Files
[04/08/2011 - 12:36:19 | D ] J:\RECYCLER
[03/08/2011 - 15:18:19 | RSH | 103140] J:\stkbum.exe
[21/12/2009 - 01:53:22 | SHD ] J:\System Volume Information
[28/04/2011 - 00:15:19 | D ] J:\Temp
[03/08/2011 - 00:46:14 | D ] J:\WINDOWS
################## | Vaccin |
C:\Autorun.inf -> Folder created by UsbFix (El Desaparecido & C_XX)
D:\Autorun.inf -> Folder created by UsbFix (El Desaparecido & C_XX)
E:\Autorun.inf -> Folder created by UsbFix (El Desaparecido & C_XX)
I:\Autorun.inf -> Folder created by UsbFix (El Desaparecido & C_XX)
J:\Autorun.inf -> Folder created by UsbFix (El Desaparecido & C_XX)
################## | E.O.F |
Pár podivných .exe souborů ještě na jednotkách zbylo tak jsem je smáznul ručně.
Ale normální režim stále nefunguje, mám podezření že se nějak seknul Combofix.
Když jsem ho spouštěl poprvé tak v jeho průběhu došlo k restartování počítače a po něm se po naběhnutí do oken objevilo modré okno Combofixu a počítač zamrz (neprobral se ani po půl hodině). Tak jsem ho restartoval a od té doby pokračuji v nouzovém režimu přotože normální po něděhnutí stále zamrzá, combofix /uninstall nepomohlo.