Nie wyświetla mi plików na pendrivie.
HiJackThis:
Przy skanowaniu wyskoczyły takie błędy:
Logi:
Gmer:
- Kod: Zaznacz wszystko
GMER 2.1.19163 - http://www.gmer.net
Rootkit scan 2013-07-25 15:08:03
Windows 6.1.7601 Service Pack 1 x64 \Device\Harddisk0\DR0 -> \Device\Ide\IAAStorageDevice-1 ST950032 rev.0001 465,76GB
Running: gmer.exe; Driver: C:\Users\ADMINI~1\AppData\Local\Temp\kfgdqfoc.sys
---- Threads - GMER 2.1 ----
Thread C:\Windows\syswow64\svchost.exe [4292:4432] 00000000002a10e0
---- EOF - GMER 2.1 ----
USBFix
- Kod: Zaznacz wszystko
############################## | UsbFix V 7.129 | [Deletion]
User: Administrator1 (Administrator) # Administrator12
Updated 24/06/2013 by El Desaparecido
Started at 15:13:25 | 25/07/2013
Website: http://sosvirus.net/
Upload Malware: http://www.sosvirus.net/upload-malware-pour-analyse-t489.html
Contact: [email protected]
PC: Acer (Aspire E1-571G) (x64-based PC)
CPU: Intel(R) Core(TM) i3-2370M CPU @ 2.40GHz (2400)
RAM -> [Total : 3932 | Free : 2122]
BIOS: InsydeH2O Version 03.71.48V1.07
BOOT: Normal boot
OS: Microsoft Windows 7 Home Premium (6.1.7601 64-Bit) # Service Pack 1
WB: Windows Internet Explorer 9.0.8112.16421
SC: Security Center Service [Enabled]
WU: Windows Update Service [Enabled]
AV: McAfee Anti-Virus i Anti-Spyware [Enabled | Updated]
FW: Windows FireWall Service [Enabled]
C:\ (%systemdrive%) -> Fixed drive # 448 Gb (343 Mb free - 77%) [Acer] # NTFS
D:\ -> CD-ROM
E:\ -> Removable drive # 2 Gb (2 Mb free - 100%) [GODDRIVE] # FAT
################## | El Desaparecido Section |
HKLM\SOFTWARE | Run : [mcui_exe] - "C:\Program Files\McAfee.com\Agent\mcagent.exe" /runkey
HKLM\SOFTWARE | Run : [SuiteTray] - "C:\Program Files (x86)\EgisTec MyWinLockerSuite\x86\SuiteTray.exe"
HKLM\SOFTWARE | Run : [Norton Online Backup] - C:\Program Files (x86)\Symantec\Norton Online Backup\NOBuClient.exe
HKLM\SOFTWARE | Run : [Adobe ARM] - "C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
HKLM\SOFTWARE | Run : [BackupManagerTray] - "C:\Program Files (x86)\NTI\Acer Backup Manager\BackupManagerTray.exe" -h -k
HKLM\SOFTWARE | Run : [LManager] - C:\Program Files (x86)\Launch Manager\LManager.exe
HKLM\SOFTWARE | Run : [GrooveMonitor] - "C:\Program Files (x86)\Microsoft Office\Office12\GrooveMonitor.exe"
HKLM\SOFTWARE | Run : [SunJavaUpdateSched] - "C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe"
HKLM\SOFTWARE | Run : [APSDaemon] - "C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe"
HKLM\SOFTWARE | Run : [QuickTime Task] - "C:\Program Files (x86)\QuickTime\QTTask.exe" -atboottime
HKLM\SOFTWARE\wow6432Node | Run : [mcui_exe] - "C:\Program Files\McAfee.com\Agent\mcagent.exe" /runkey
HKLM\SOFTWARE\wow6432Node | Run : [SuiteTray] - "C:\Program Files (x86)\EgisTec MyWinLockerSuite\x86\SuiteTray.exe"
HKLM\SOFTWARE\wow6432Node | Run : [Norton Online Backup] - C:\Program Files (x86)\Symantec\Norton Online Backup\NOBuClient.exe
HKLM\SOFTWARE\wow6432Node | Run : [Adobe ARM] - "C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
HKLM\SOFTWARE\wow6432Node | Run : [BackupManagerTray] - "C:\Program Files (x86)\NTI\Acer Backup Manager\BackupManagerTray.exe" -h -k
HKLM\SOFTWARE\wow6432Node | Run : [LManager] - C:\Program Files (x86)\Launch Manager\LManager.exe
HKLM\SOFTWARE\wow6432Node | Run : [GrooveMonitor] - "C:\Program Files (x86)\Microsoft Office\Office12\GrooveMonitor.exe"
HKLM\SOFTWARE\wow6432Node | Run : [SunJavaUpdateSched] - "C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe"
HKLM\SOFTWARE\wow6432Node | Run : [APSDaemon] - "C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe"
HKLM\SOFTWARE\wow6432Node | Run : [QuickTime Task] - "C:\Program Files (x86)\QuickTime\QTTask.exe" -atboottime
HKLM\SOFTWARE | RunOnce : [] -
HKLM\SOFTWARE\wow6432Node | RunOnce : [] -
HKU\S-1-5-19\SOFTWARE | Run : [Sidebar] - %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun
HKU\S-1-5-20\SOFTWARE | Run : [Sidebar] - %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun
HKU\S-1-5-21-3761214776-854486660-3764415504-1000\SOFTWARE | Run : [Sidebar] - %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun
HKU\S-1-5-19\SOFTWARE | RunOnce : [mctadmin] - C:\Windows\System32\mctadmin.exe
HKU\S-1-5-19\SOFTWARE | RunOnce : [IsMyWinLockerReboot] - msiexec.exe /qn /x{voidguid}
HKU\S-1-5-20\SOFTWARE | RunOnce : [mctadmin] - C:\Windows\System32\mctadmin.exe
HKU\S-1-5-20\SOFTWARE | RunOnce : [IsMyWinLockerReboot] - msiexec.exe /qn /x{voidguid}
HKU\S-1-5-21-3761214776-854486660-3764415504-1000\SOFTWARE | RunOnce : [mctadmin] - C:\Windows\System32\mctadmin.exe
HKU\S-1-5-18\SOFTWARE | RunOnce : [IsMyWinLockerReboot] - msiexec.exe /qn /x{voidguid}
################## | Stopped processes |
Stopped! C:\Windows\system32\nvvsvc.exe (608)
Stopped! C:\Windows\system32\WLANExt.exe (1324)
Stopped! C:\Windows\system32\conhost.exe (1336)
Stopped! C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe (1544)
Stopped! C:\Windows\system32\nvvsvc.exe (1556)
Stopped! C:\Windows\System32\spoolsv.exe (1604)
Stopped! C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe (1848)
Stopped! C:\Program Files (x86)\Microsoft\BingBar\SeaPort.EXE (1888)
Stopped! C:\Program Files (x86)\Launch Manager\dsiwmis.exe (1932)
Stopped! C:\Program Files\Acer\Acer ePower Management\ePowerSvc.exe (2044)
Stopped! C:\Program Files (x86)\Acer\Registration\GREGsvc.exe (1340)
Stopped! C:\Program Files (x86)\Launch Manager\LMutilps32.exe (1724)
Stopped! C:\ProgramData\DatacardService\HWDeviceService64.exe (812)
Stopped! C:\Program Files\Intel\iCLS Client\HeciServer.exe (1392)
Stopped! C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe (2000)
Stopped! C:\Program Files\Acer\Acer Updater\UpdaterService.exe (1980)
Stopped! C:\Program Files\Common Files\McAfee\McSvcHost\McSvHost.exe (1988)
Stopped! C:\Windows\system32\mfevtps.exe (2076)
Stopped! C:\Program Files (x86)\Symantec\Norton Online Backup\NOBuAgent.exe (2096)
Stopped! C:\Program Files (x86)\NTI\Acer Backup Manager\IScheduleSvc.exe (2156)
Stopped! C:\Windows\system32\rundll32.exe (2192)
Stopped! C:\Windows\system32\rundll32.exe (2200)
Stopped! C:\Windows\SysWOW64\rundll32.exe (2240)
Stopped! C:\ProgramData\PLAY ONLINE\OnlineUpdate\ouc.exe (2264)
Stopped! C:\Program Files\Common Files\McAfee\SystemCore\mcshield.exe (2348)
Stopped! C:\Program Files\Common Files\McAfee\SystemCore\mfefire.exe (2400)
Stopped! C:\Windows\system32\taskhost.exe (3324)
Stopped! C:\Windows\System32\igfxtray.exe (3772)
Stopped! C:\Windows\System32\hkcmd.exe (3788)
Stopped! C:\Windows\system32\igfxsrvc.exe (3804)
Stopped! C:\Windows\System32\igfxpers.exe (3816)
Stopped! C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe (3892)
Stopped! C:\Program Files\Elantech\ETDCtrl.exe (3948)
Stopped! C:\Program Files\Acer\Acer ePower Management\ePowerTray.exe (3976)
Stopped! C:\ProgramData\DatacardService\DCSHelper.exe (4092)
Stopped! C:\Program Files (x86)\McAfee Security Scan\3.0.318\SSScheduler.exe (1672)
Stopped! C:\Program Files\mcafee.com\agent\mcagent.exe (3064)
Stopped! C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe (3188)
Stopped! C:\Program Files (x86)\NTI\Acer Backup Manager\BackupManagerTray.exe (2120)
Stopped! C:\Program Files (x86)\Launch Manager\LManager.exe (2708)
Stopped! C:\Program Files (x86)\Launch Manager\MMDx64Fx.exe (3596)
Stopped! C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe (3564)
Stopped! C:\Windows\system32\igfxext.exe (3724)
Stopped! C:\Program Files (x86)\Launch Manager\LMworker.exe (3364)
Stopped! C:\Program Files\Elantech\ETDCtrlHelper.exe (1484)
Stopped! C:\Program Files\NVIDIA Corporation\Display\nvtray.exe (1660)
Stopped! C:\Program Files\Acer\Acer ePower Management\ePowerEvent.exe (4108)
Stopped! C:\Windows\system32\SearchIndexer.exe (4216)
Stopped! C:\Windows\system32\taskeng.exe (4628)
Stopped! C:\Program Files (x86)\CyberLink\MediaEspresso\DeviceDetector\DeviceDetector.exe (4668)
Stopped! C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe (4100)
Stopped! C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe (4144)
Stopped! C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\daemonu.exe (5152)
Stopped! C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe (5816)
Stopped! C:\Windows\system32\wuauclt.exe (5752)
Stopped! C:\Program Files\EgisTec IPS\PMMUpdate.exe (4724)
Stopped! C:\Program Files\EgisTec IPS\EgisUpdate.exe (4472)
Stopped! C:\Program Files (x86)\Mozilla Firefox\firefox.exe (2104)
Stopped! C:\Program Files (x86)\Mozilla Firefox\plugin-container.exe (3304)
Stopped! C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerPlugin_11_7_700_224.exe (2168)
Stopped! C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerPlugin_11_7_700_224.exe (3920)
Stopped! c:\PROGRA~1\mcafee\VIRUSS~1\mcvsshld.exe (4804)
Stopped! C:\Windows\System32\WUDFHost.exe (2624)
################## | Files # Infected Folders |
Not deleted ! E:\autorun.inf
(!) Temporary files deleted.
################## | Registry |
Deleted ! HKLM\Software\Microsoft\Windows\CurrentVersion\Policies\System|DisableRegistryTools
Deleted ! HKLM\Software\Microsoft\Windows\CurrentVersion\Policies\System|DisableTaskMgr
################## | Mountpoints2 |
Deleted ! HKCU\.\.\.\.\Explorer\MountPoints2\E
Deleted ! HKCU\.\.\.\.\Explorer\MountPoints2\{20b9a7fc-12ec-11e2-a6b5-b888e34deccc}
################## | Listing |
[09/10/2012 - 14:17:30 | SHD ] C:\$Recycle.Bin
[09/10/2012 - 14:20:30 | D ] C:\book
[06/03/2012 - 13:26:17 | N | 8192] C:\BOOTSECT.BAK
[14/07/2009 - 07:08:56 | SHD ] C:\Documents and Settings
[25/07/2013 - 05:21:21 | ASH | 3092533248] C:\hiberfil.sys
[28/06/2012 - 23:59:11 | D ] C:\Intel
[09/10/2012 - 18:35:37 | N | 40] C:\log.txt
[09/10/2012 - 16:15:07 | D ] C:\MININT
[27/06/2013 - 07:19:20 | D ] C:\MSI
[10/10/2012 - 17:54:43 | RHD ] C:\MSOCache
[09/10/2012 - 14:20:34 | D ] C:\OEM
[25/07/2013 - 05:21:27 | ASH | 4123377664] C:\pagefile.sys
[14/07/2009 - 05:20:08 | D ] C:\PerfLogs
[07/07/2013 - 20:43:25 | D ] C:\Program Files
[25/07/2013 - 14:54:18 | D ] C:\Program Files (x86)
[04/07/2013 - 21:45:17 | HD ] C:\ProgramData
[09/10/2012 - 14:10:07 | SHD ] C:\Recovery
[25/07/2013 - 14:54:17 | SHD ] C:\System Volume Information
[31/12/2012 - 22:13:26 | D ] C:\totalcmd
[25/07/2013 - 15:16:32 | D ] C:\UsbFix
[25/07/2013 - 15:16:43 | A | 10056] C:\UsbFix [Clean 1] Administrator12.txt
[09/10/2012 - 14:11:40 | D ] C:\Users
[23/07/2013 - 12:58:21 | D ] C:\Windows
[25/07/2013 - 06:04:08 | D ] E:\
[25/07/2013 - 15:13:18 | N | 0] E:\autorun.inf
################## | Vaccin |
C:\Autorun.inf -> Vaccine created by UsbFix (El Desaparecido)
################## | E.O.F | http://sosvirus.net |
Bardzo Proszę o pomoc...