SLOW notebook, possible virus
Solved/Closed
bcn101
Posts
113
Registration date
Friday November 9, 2012
Status
Member
Last seen
July 28, 2014
-
Aug 20, 2013 at 05:55 PM
bcn101 Posts 113 Registration date Friday November 9, 2012 Status Member Last seen July 28, 2014 - Aug 29, 2013 at 04:27 PM
bcn101 Posts 113 Registration date Friday November 9, 2012 Status Member Last seen July 28, 2014 - Aug 29, 2013 at 04:27 PM
Related:
- SLOW notebook, possible virus
- Goose virus - Download - Other
- Ntuser.dat virus - Guide
- Can jpg have virus - Guide
- Smart notebook download - Download - Organisation and teamwork
- Notebook fancontrol - Download - Cleaning and optimization
7 responses
bcn101
Posts
113
Registration date
Friday November 9, 2012
Status
Member
Last seen
July 28, 2014
Aug 21, 2013 at 04:41 PM
Aug 21, 2013 at 04:41 PM
HELPPPPP PLEASEEEEE !!!!
Ambucias
Posts
47310
Registration date
Monday February 1, 2010
Status
Moderator
Last seen
February 15, 2023
11,162
Aug 22, 2013 at 06:31 AM
Aug 22, 2013 at 06:31 AM
Ola !
Sorry for the late response. Do you still need help ?
Sorry for the late response. Do you still need help ?
bcn101
Posts
113
Registration date
Friday November 9, 2012
Status
Member
Last seen
July 28, 2014
Aug 27, 2013 at 04:12 PM
Aug 27, 2013 at 04:12 PM
yes ambucias.... you're always my savior and you know that...helpppppppp
i really have prob with the vids, even in skype... it freezes the screen and a very annoying buzz follows ;/
i really have prob with the vids, even in skype... it freezes the screen and a very annoying buzz follows ;/
Ambucias
Posts
47310
Registration date
Monday February 1, 2010
Status
Moderator
Last seen
February 15, 2023
11,162
Aug 27, 2013 at 04:25 PM
Aug 27, 2013 at 04:25 PM
Hold on for analysis
bcn101
Posts
113
Registration date
Friday November 9, 2012
Status
Member
Last seen
July 28, 2014
Aug 27, 2013 at 04:31 PM
Aug 27, 2013 at 04:31 PM
thanks ambu :)
Ambucias
Posts
47310
Registration date
Monday February 1, 2010
Status
Moderator
Last seen
February 15, 2023
11,162
Aug 27, 2013 at 04:43 PM
Aug 27, 2013 at 04:43 PM
No wonder it's slow but this time we will have this clean in a jiffy.
1. You have a programme called "My PC Backup" please remove it. Every time you do something it takes your ressources to saveguard.
2. You have another application called OfferBox, it has a proxy override feature.
Launch ZHP fix and copy the following files:
R5 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = <local>;*.offerbox.com =>PUP.OfferBox
O43 - CFD: 4/1/2013 - 4:25:08 PM - [0.015] ----D C:\Program Files\MyPC Backup =>PUP.MyPCBackup
C:\Program Files\MyPC Backup =>PUP.MyPCBackup^
Click on the clipboard button the on the GO button.
Close ZHP Fix
Restart your system and then everything should work normally
1. You have a programme called "My PC Backup" please remove it. Every time you do something it takes your ressources to saveguard.
2. You have another application called OfferBox, it has a proxy override feature.
Launch ZHP fix and copy the following files:
R5 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = <local>;*.offerbox.com =>PUP.OfferBox
O43 - CFD: 4/1/2013 - 4:25:08 PM - [0.015] ----D C:\Program Files\MyPC Backup =>PUP.MyPCBackup
C:\Program Files\MyPC Backup =>PUP.MyPCBackup^
Click on the clipboard button the on the GO button.
Close ZHP Fix
Restart your system and then everything should work normally
bcn101
Posts
113
Registration date
Friday November 9, 2012
Status
Member
Last seen
July 28, 2014
Aug 27, 2013 at 05:04 PM
Aug 27, 2013 at 05:04 PM
hi, should i restart my computer? anything that i should do next?
bcn101
Posts
113
Registration date
Friday November 9, 2012
Status
Member
Last seen
July 28, 2014
Aug 27, 2013 at 05:32 PM
Aug 27, 2013 at 05:32 PM
ambu..... still it lags and gives me the annoying buzz for videos :/
Ambucias
Posts
47310
Registration date
Monday February 1, 2010
Status
Moderator
Last seen
February 15, 2023
11,162
Aug 28, 2013 at 06:30 AM
Aug 28, 2013 at 06:30 AM
Launch ZHP Fix again, copy the following lines, paste with clipboard button and click on go. (They are useless toolbars)
O3 - Toolbar: avast! Online Security - [HKLM]{8E5E2654-AD2D-48bf-AC2D-D17F00898D06} . (.AVAST Software - IE Webrep plugin.) -- C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll =>Toolbar.Avast
O3 - Toolbar: Google Toolbar - [HKLM]{2318C2B1-4965-11d4-9B18-009027A5CD4F} . (.Google Inc. - Google Toolbar.) -- C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll =>Toolbar.Google
O3 - Toolbar\WebBrowser: (no name) - [HKCU]{2318C2B1-4965-11D4-9B18-009027A5CD4F} Orphan key => Toolbar.Google
O43 - CFD: 4/10/2013 - 1:47:46 PM - [6.006] ----D C:\Program Files\Yahoo! =>Toolbar.Yahoo
O43 - CFD: 4/10/2013 - 1:47:44 PM - [0.002] ----D C:\ProgramData\Yahoo! =>Toolbar.Yahoo
O43 - CFD: 4/6/2013 - 11:33:38 PM - [0.090] ----D C:\Users\Usuario\AppData\Roaming\Yahoo! =>Toolbar.Yahoo
[MD5.D24949E5C6EC59F7F8664A657066994D] [WIS][8/14/2009] (.Google Inc. - Google Toolbar for Internet Explorer.) -- C:\Windows\Installer\1dd6c4.msi [28160] =>Toolbar.Google
[HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{8E5E2654-AD2D-48bf-AC2D-D17F00898D06}] =>Toolbar.Avast
[HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{8E5E2654-AD2D-48bf-AC2D-D17F00898D06}] =>Toolbar.Avast
[HKLM\Software\Classes\CLSID\{8E5E2654-AD2D-48bf-AC2D-D17F00898D06}] =>Toolbar.Avast
[HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{8E5E2654-AD2D-48bf-AC2D-D17F00898D06}] =>Toolbar.Avast
[HKLM\Software\Microsoft\Internet Explorer\Toolbar]:{8E5E2654-AD2D-48bf-AC2D-D17F00898D06} =>Toolbar.Avast^
C:\Program Files\Yahoo! =>Toolbar.Yahoo^
C:\ProgramData\Yahoo! =>Toolbar.Yahoo^
C:\Users\Usuario\AppData\Roaming\Yahoo! =>Toolbar.Yahoo^
C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll =>Toolbar.Avast^
C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll =>Toolbar.Google^
:\Windows\Installer\1dd6c4.msi =>Toolbar.Google^
Next, there is a possible usb virus
Here is a tool to remove the virus and vaccinate your USB against further viruses.
Download UsbFix (created by El Desaparecido) on your desktop.
http://ccm.net/download/download-24089-usbfix
If your antivirus gives an alert, ignore it and temporarily deactivate the antivirus.
Plug in your usb devices (Flash drive, pen drive. External HD etc...) don't open them.
Double click sur UsbFix.exe.
Click on deletion
.
Let the tool work.
At the end of the scan a report will show which you can copy and paste here..
The report is save at the root ( C:\UsbFix.txt ).
O3 - Toolbar: avast! Online Security - [HKLM]{8E5E2654-AD2D-48bf-AC2D-D17F00898D06} . (.AVAST Software - IE Webrep plugin.) -- C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll =>Toolbar.Avast
O3 - Toolbar: Google Toolbar - [HKLM]{2318C2B1-4965-11d4-9B18-009027A5CD4F} . (.Google Inc. - Google Toolbar.) -- C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll =>Toolbar.Google
O3 - Toolbar\WebBrowser: (no name) - [HKCU]{2318C2B1-4965-11D4-9B18-009027A5CD4F} Orphan key => Toolbar.Google
O43 - CFD: 4/10/2013 - 1:47:46 PM - [6.006] ----D C:\Program Files\Yahoo! =>Toolbar.Yahoo
O43 - CFD: 4/10/2013 - 1:47:44 PM - [0.002] ----D C:\ProgramData\Yahoo! =>Toolbar.Yahoo
O43 - CFD: 4/6/2013 - 11:33:38 PM - [0.090] ----D C:\Users\Usuario\AppData\Roaming\Yahoo! =>Toolbar.Yahoo
[MD5.D24949E5C6EC59F7F8664A657066994D] [WIS][8/14/2009] (.Google Inc. - Google Toolbar for Internet Explorer.) -- C:\Windows\Installer\1dd6c4.msi [28160] =>Toolbar.Google
[HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{8E5E2654-AD2D-48bf-AC2D-D17F00898D06}] =>Toolbar.Avast
[HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{8E5E2654-AD2D-48bf-AC2D-D17F00898D06}] =>Toolbar.Avast
[HKLM\Software\Classes\CLSID\{8E5E2654-AD2D-48bf-AC2D-D17F00898D06}] =>Toolbar.Avast
[HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{8E5E2654-AD2D-48bf-AC2D-D17F00898D06}] =>Toolbar.Avast
[HKLM\Software\Microsoft\Internet Explorer\Toolbar]:{8E5E2654-AD2D-48bf-AC2D-D17F00898D06} =>Toolbar.Avast^
C:\Program Files\Yahoo! =>Toolbar.Yahoo^
C:\ProgramData\Yahoo! =>Toolbar.Yahoo^
C:\Users\Usuario\AppData\Roaming\Yahoo! =>Toolbar.Yahoo^
C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll =>Toolbar.Avast^
C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll =>Toolbar.Google^
:\Windows\Installer\1dd6c4.msi =>Toolbar.Google^
Next, there is a possible usb virus
Here is a tool to remove the virus and vaccinate your USB against further viruses.
Download UsbFix (created by El Desaparecido) on your desktop.
http://ccm.net/download/download-24089-usbfix
If your antivirus gives an alert, ignore it and temporarily deactivate the antivirus.
Plug in your usb devices (Flash drive, pen drive. External HD etc...) don't open them.
Double click sur UsbFix.exe.
Click on deletion
.
Let the tool work.
At the end of the scan a report will show which you can copy and paste here..
The report is save at the root ( C:\UsbFix.txt ).
Didn't find the answer you are looking for?
Ask a question
bcn101
Posts
113
Registration date
Friday November 9, 2012
Status
Member
Last seen
July 28, 2014
Aug 29, 2013 at 02:39 PM
Aug 29, 2013 at 02:39 PM
hi ambu,
below is the log.... i dont have any usb...
############################## | UsbFix V 7.133 | [Supresión]
Usuario: Usuario (Administrador) # USUARIO-PC
Actualizado el 27/08/2013 por El Desaparecido
Comenzó a 20:22:24 | 29/08/2013
Sitio web: https://www.sosvirus.net/
Upload Malware: http://sosvirus.net/viewtopic.php?f=6&t=489
Contacto: eldesaparecido@sosvirus.net
PC: Acer (Aspire one ) (X86-based PC)
CPU: Intel(R) Atom(TM) CPU N270 @ 1.60GHz (1600)
RAM -> [Total : 1014 | Free : 240]
BIOS: InsydeH2O Version V1.22
BOOT: Normal boot
OS: Microsoft Windows 7 Starter (6.1.7601 32-Bit) # Service Pack 1
WB: Windows Internet Explorer 10.0.9200.16660
SC: Security Center Service [Enabled]
WU: Windows Update Service [Enabled]
AV: avast! Antivirus [Enabled | Updated]
FW: Windows FireWall Service [Enabled]
C:\ (%systemdrive%) -> Disco fijo # 133 Gb (97 Mb libre(s) - 73%) [Acer] # NTFS
D:\ -> Disco fijo # 4 Gb (3 Mb libre(s) - 68%) [] # FAT32
################## | El Desaparecido Section |
HKLM\SOFTWARE | Run : [IAAnotif] - C:\Program Files\Intel\Intel Matrix Storage Manager\iaanotif.exe
HKLM\SOFTWARE | Run : [LManager] - C:\Program Files\Launch Manager\LManager.exe
HKLM\SOFTWARE | Run : [RtHDVCpl] - C:\Program Files\Realtek\Audio\HDA\RtHDVCpl.exe
HKLM\SOFTWARE | Run : [Acer ePower Management] - C:\Program Files\Acer\Acer ePower Management\ePowerTray.exe
HKLM\SOFTWARE | Run : [EgisTecLiveUpdate] - "C:\Program Files\EgisTec Egis Software Update\EgisUpdate.exe"
HKLM\SOFTWARE | Run : [mwlDaemon] - C:\Program Files\EgisTec\MyWinLocker 3\x86\mwlDaemon.exe
HKLM\SOFTWARE | Run : [Adobe Reader Speed Launcher] - "C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe"
HKLM\SOFTWARE | Run : [SynTPEnh] - %ProgramFiles%\Synaptics\SynTP\SynTPEnh.exe
HKLM\SOFTWARE | Run : [iSyncData] - C:\Program Files\Acer\Android Manager\iSync.exe
HKLM\SOFTWARE | Run : [AndroidManager] - C:\Program Files\Acer\Android Manager\AML.exe
HKLM\SOFTWARE | Run : [iPatchData] - C:\Program Files\Acer\Updater\iUpdate.exe
HKLM\SOFTWARE | Run : [IgfxTray] - C:\Windows\system32\igfxtray.exe
HKLM\SOFTWARE | Run : [HotKeysCmds] - C:\Windows\system32\hkcmd.exe
HKLM\SOFTWARE | Run : [Persistence] - C:\Windows\system32\igfxpers.exe
HKLM\SOFTWARE | Run : [KiesTrayAgent] - C:\Program Files\Samsung\Kies\KiesTrayAgent.exe
HKLM\SOFTWARE | Run : [avast] - "C:\Program Files\AVAST Software\Avast\avastUI.exe" /nogui
HKLM\SOFTWARE | Run : [SunJavaUpdateSched] - "C:\Program Files\Common Files\Java\Java Update\jusched.exe"
HKLM\SOFTWARE | RunOnce : [] -
HKU\S-1-5-19\SOFTWARE | Run : [Sidebar] - %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun
HKU\S-1-5-20\SOFTWARE | Run : [Sidebar] - %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun
HKU\S-1-5-21-3095367477-2772566876-4048981669-1000\SOFTWARE | Run : [swg] - "C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe"
HKU\S-1-5-21-3095367477-2772566876-4048981669-1000\SOFTWARE | Run : [msnmsgr] - "C:\Program Files\Windows Live\Messenger\msnmsgr.exe" /background
HKU\S-1-5-21-3095367477-2772566876-4048981669-1000\SOFTWARE | Run : [KiesPreload] - C:\Program Files\Samsung\Kies\Kies.exe /preload
HKU\S-1-5-21-3095367477-2772566876-4048981669-1000\SOFTWARE | Run : [KiesAirMessage] - C:\Program Files\Samsung\Kies\KiesAirMessage.exe -startup
HKU\S-1-5-21-3095367477-2772566876-4048981669-1000\SOFTWARE | Run : [] - C:\Program Files\Samsung\Kies\External\FirmwareUpdate\KiesPDLR.exe
HKU\S-1-5-21-3095367477-2772566876-4048981669-1000\SOFTWARE | Run : [Skype] - "C:\Program Files\Skype\Phone\Skype.exe" /minimized /regrun
HKU\S-1-5-19\SOFTWARE | RunOnce : [mctadmin] - C:\Windows\System32\mctadmin.exe
HKU\S-1-5-20\SOFTWARE | RunOnce : [mctadmin] - C:\Windows\System32\mctadmin.exe
HKU\S-1-5-18\SOFTWARE | RunOnce : [SPReview] - "C:\Windows\System32\SPReview\SPReview.exe" /sp:1 /errorfwlink:"https://support.microsoft.com/en-us/windows/install-windows-7-service-pack-1-sp1-b3da2c0f-cdb6-0572-8596-bab972897f61" /build:7601
################## | Procesos Parados |
Parado! C:\Program Files\AVAST Software\Avast\AvastSvc.exe (1428)
Parado! C:\Windows\Explorer.EXE (1508)
Parado! C:\Windows\System32\spoolsv.exe (1672)
Parado! C:\Windows\system32\taskhost.exe (1692)
Parado! C:\Program Files\Intel\Intel Matrix Storage Manager\IAAnotif.exe (1728)
Parado! C:\Program Files\Acer\Acer ePower Management\ePowerSvc.exe (448)
Parado! C:\Program Files\Acer\Registration\GregHSRW.exe (484)
Parado! C:\Program Files\EgisTec\MyWinLocker 3\x86\MWLService.exe (872)
Parado! C:\Program Files\Acer\Acer VCM\RS_Service.exe (1328)
Parado! C:\Program Files\Acer\Acer Updater\UpdaterService.exe (1112)
Parado! C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE (1992)
Parado! C:\Program Files\Google\Chrome\Application\chrome.exe (1100)
Parado! C:\Program Files\Intel\Intel Matrix Storage Manager\IAANTMon.exe (1136)
Parado! C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe (2192)
Parado! C:\Windows\system32\SearchIndexer.exe (2352)
Parado! C:\Program Files\Google\Chrome\Application\chrome.exe (2716)
Parado! C:\Program Files\Launch Manager\LManager.exe (2976)
Parado! C:\Program Files\Realtek\Audio\HDA\RtHDVCpl.exe (2988)
Parado! C:\Program Files\Acer\Acer ePower Management\ePowerTray.exe (3008)
Parado! C:\Program Files\EgisTec Egis Software Update\EgisUpdate.exe (3028)
Parado! C:\Program Files\EgisTec\MyWinLocker 3\x86\mwlDaemon.exe (3040)
Parado! C:\Program Files\Synaptics\SynTP\SynTPEnh.exe (3056)
Parado! C:\Program Files\Acer\Android Manager\iSync.exe (3064)
Parado! C:\Program Files\Acer\Updater\iUpdate.exe (3084)
Parado! C:\Windows\System32\igfxtray.exe (3124)
Parado! C:\Windows\System32\hkcmd.exe (3224)
Parado! C:\Windows\System32\igfxpers.exe (3248)
Parado! C:\Program Files\Samsung\Kies\KiesTrayAgent.exe (3284)
Parado! C:\Program Files\AVAST Software\Avast\AvastUI.exe (3312)
Parado! C:\Program Files\Common Files\Java\Java Update\jusched.exe (3328)
Parado! C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe (3344)
Parado! C:\Program Files\Windows Live\Messenger\msnmsgr.exe (3372)
Parado! C:\Program Files\Samsung\Kies\Kies.exe (3408)
Parado! C:\Program Files\Skype\Phone\Skype.exe (3456)
Parado! C:\Program Files\Acer\Acer VCM\AcerVCM.exe (3480)
Parado! C:\Windows\system32\igfxsrvc.exe (3656)
Parado! C:\Windows\system32\igfxext.exe (3692)
Parado! C:\Program Files\Synaptics\SynTP\SynTPHelper.exe (4044)
Parado! C:\Program Files\Acer\Acer ePower Management\ePowerEvent.exe (4876)
Parado! C:\Windows\system32\taskeng.exe (3048)
Parado! C:\Windows\system32\taskeng.exe (3188)
################## | Archivos # Carpetas infectadas |
Suprimido ! C:\ProgramData\FullRemove.exe
Suprimido ! C:\Program Files\GUM76FB.tmp
Suprimido ! C:\Program Files\GUT774A.tmp
Suprimido ! C:\Windows\system32\update.exe
(!) Archivos temporales suprimido.
################## | Registro |
################## | Mountpoints2 |
Suprimido ! HKCU\.\.\.\.\Explorer\MountPoints2\{0cdd4124-ba79-11e2-b9c0-806e6f6e6963}
################## | Listing |
[16/03/2013 - 13:18:23 | SHD ] C:\$Recycle.Bin
[11/04/2013 - 23:53:10 | N | 6155] C:\AdwCleaner[S1].txt
[12/08/2013 - 22:54:23 | N | 2574] C:\AdwCleaner[S2].txt
[16/03/2013 - 13:15:11 | D ] C:\Archivos de programa
[10/06/2009 - 23:42:20 | N | 24] C:\autoexec.bat
[16/03/2013 - 13:19:38 | D ] C:\book
[14/08/2009 - 11:25:33 | N | 8192] C:\BOOTSECT.BAK
[15/08/2013 - 03:53:04 | D ] C:\Config.Msi
[10/06/2009 - 23:42:20 | N | 10] C:\config.sys
[14/07/2009 - 06:53:55 | SHD ] C:\Documents and Settings
[29/08/2013 - 20:05:18 | ASH | 797396992] C:\hiberfil.sys
[14/08/2009 - 10:34:55 | D ] C:\Intel
[14/08/2009 - 10:54:35 | RHD ] C:\MSOCache
[17/04/2013 - 11:36:20 | D ] C:\OEM
[29/08/2013 - 20:05:17 | ASH | 1073741824] C:\pagefile.sys
[14/07/2009 - 04:37:05 | D ] C:\PerfLogs
[20/08/2013 - 23:47:35 | N | 512] C:\PhysicalDisk0_MBR.bin
[29/08/2013 - 20:26:47 | D ] C:\Program Files
[29/08/2013 - 20:26:41 | HD ] C:\ProgramData
[16/03/2013 - 13:15:11 | SHD ] C:\Recovery
[14/08/2009 - 10:44:36 | N | 1937] C:\RHDSetup.log
[24/08/2013 - 13:54:50 | SHD ] C:\System Volume Information
[29/08/2013 - 20:26:49 | D ] C:\UsbFix
[29/08/2013 - 20:27:45 | A | 8223] C:\UsbFix [Clean 1] USUARIO-PC.txt
[16/03/2013 - 13:15:27 | D ] C:\Users
[24/08/2013 - 23:43:41 | D ] C:\Windows
[28/08/2013 - 23:33:12 | D ] C:\ZHP
[15/04/2013 - 23:10:50 | N | 201327275] D:\var.img
[15/04/2013 - 23:11:02 | N | 138412983] D:\q2l.img
[15/04/2013 - 23:10:50 | N | 1048576000] D:\firefox.img
[15/04/2013 - 23:10:50 | D ] D:\Downloads
[15/04/2013 - 23:12:04 | D ] D:\picture
[15/04/2013 - 23:11:02 | D ] D:\android
[16/03/2013 - 13:18:08 | SHD ] D:\$RECYCLE.BIN
################## | Vaccin |
C:\Autorun.inf -> Vacuna creada por UsbFix (El Desaparecido)
D:\Autorun.inf -> Vacuna creada por UsbFix (El Desaparecido)
################## | E.O.F | https://www.sosvirus.net/ |
below is the log.... i dont have any usb...
############################## | UsbFix V 7.133 | [Supresión]
Usuario: Usuario (Administrador) # USUARIO-PC
Actualizado el 27/08/2013 por El Desaparecido
Comenzó a 20:22:24 | 29/08/2013
Sitio web: https://www.sosvirus.net/
Upload Malware: http://sosvirus.net/viewtopic.php?f=6&t=489
Contacto: eldesaparecido@sosvirus.net
PC: Acer (Aspire one ) (X86-based PC)
CPU: Intel(R) Atom(TM) CPU N270 @ 1.60GHz (1600)
RAM -> [Total : 1014 | Free : 240]
BIOS: InsydeH2O Version V1.22
BOOT: Normal boot
OS: Microsoft Windows 7 Starter (6.1.7601 32-Bit) # Service Pack 1
WB: Windows Internet Explorer 10.0.9200.16660
SC: Security Center Service [Enabled]
WU: Windows Update Service [Enabled]
AV: avast! Antivirus [Enabled | Updated]
FW: Windows FireWall Service [Enabled]
C:\ (%systemdrive%) -> Disco fijo # 133 Gb (97 Mb libre(s) - 73%) [Acer] # NTFS
D:\ -> Disco fijo # 4 Gb (3 Mb libre(s) - 68%) [] # FAT32
################## | El Desaparecido Section |
HKLM\SOFTWARE | Run : [IAAnotif] - C:\Program Files\Intel\Intel Matrix Storage Manager\iaanotif.exe
HKLM\SOFTWARE | Run : [LManager] - C:\Program Files\Launch Manager\LManager.exe
HKLM\SOFTWARE | Run : [RtHDVCpl] - C:\Program Files\Realtek\Audio\HDA\RtHDVCpl.exe
HKLM\SOFTWARE | Run : [Acer ePower Management] - C:\Program Files\Acer\Acer ePower Management\ePowerTray.exe
HKLM\SOFTWARE | Run : [EgisTecLiveUpdate] - "C:\Program Files\EgisTec Egis Software Update\EgisUpdate.exe"
HKLM\SOFTWARE | Run : [mwlDaemon] - C:\Program Files\EgisTec\MyWinLocker 3\x86\mwlDaemon.exe
HKLM\SOFTWARE | Run : [Adobe Reader Speed Launcher] - "C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe"
HKLM\SOFTWARE | Run : [SynTPEnh] - %ProgramFiles%\Synaptics\SynTP\SynTPEnh.exe
HKLM\SOFTWARE | Run : [iSyncData] - C:\Program Files\Acer\Android Manager\iSync.exe
HKLM\SOFTWARE | Run : [AndroidManager] - C:\Program Files\Acer\Android Manager\AML.exe
HKLM\SOFTWARE | Run : [iPatchData] - C:\Program Files\Acer\Updater\iUpdate.exe
HKLM\SOFTWARE | Run : [IgfxTray] - C:\Windows\system32\igfxtray.exe
HKLM\SOFTWARE | Run : [HotKeysCmds] - C:\Windows\system32\hkcmd.exe
HKLM\SOFTWARE | Run : [Persistence] - C:\Windows\system32\igfxpers.exe
HKLM\SOFTWARE | Run : [KiesTrayAgent] - C:\Program Files\Samsung\Kies\KiesTrayAgent.exe
HKLM\SOFTWARE | Run : [avast] - "C:\Program Files\AVAST Software\Avast\avastUI.exe" /nogui
HKLM\SOFTWARE | Run : [SunJavaUpdateSched] - "C:\Program Files\Common Files\Java\Java Update\jusched.exe"
HKLM\SOFTWARE | RunOnce : [] -
HKU\S-1-5-19\SOFTWARE | Run : [Sidebar] - %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun
HKU\S-1-5-20\SOFTWARE | Run : [Sidebar] - %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun
HKU\S-1-5-21-3095367477-2772566876-4048981669-1000\SOFTWARE | Run : [swg] - "C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe"
HKU\S-1-5-21-3095367477-2772566876-4048981669-1000\SOFTWARE | Run : [msnmsgr] - "C:\Program Files\Windows Live\Messenger\msnmsgr.exe" /background
HKU\S-1-5-21-3095367477-2772566876-4048981669-1000\SOFTWARE | Run : [KiesPreload] - C:\Program Files\Samsung\Kies\Kies.exe /preload
HKU\S-1-5-21-3095367477-2772566876-4048981669-1000\SOFTWARE | Run : [KiesAirMessage] - C:\Program Files\Samsung\Kies\KiesAirMessage.exe -startup
HKU\S-1-5-21-3095367477-2772566876-4048981669-1000\SOFTWARE | Run : [] - C:\Program Files\Samsung\Kies\External\FirmwareUpdate\KiesPDLR.exe
HKU\S-1-5-21-3095367477-2772566876-4048981669-1000\SOFTWARE | Run : [Skype] - "C:\Program Files\Skype\Phone\Skype.exe" /minimized /regrun
HKU\S-1-5-19\SOFTWARE | RunOnce : [mctadmin] - C:\Windows\System32\mctadmin.exe
HKU\S-1-5-20\SOFTWARE | RunOnce : [mctadmin] - C:\Windows\System32\mctadmin.exe
HKU\S-1-5-18\SOFTWARE | RunOnce : [SPReview] - "C:\Windows\System32\SPReview\SPReview.exe" /sp:1 /errorfwlink:"https://support.microsoft.com/en-us/windows/install-windows-7-service-pack-1-sp1-b3da2c0f-cdb6-0572-8596-bab972897f61" /build:7601
################## | Procesos Parados |
Parado! C:\Program Files\AVAST Software\Avast\AvastSvc.exe (1428)
Parado! C:\Windows\Explorer.EXE (1508)
Parado! C:\Windows\System32\spoolsv.exe (1672)
Parado! C:\Windows\system32\taskhost.exe (1692)
Parado! C:\Program Files\Intel\Intel Matrix Storage Manager\IAAnotif.exe (1728)
Parado! C:\Program Files\Acer\Acer ePower Management\ePowerSvc.exe (448)
Parado! C:\Program Files\Acer\Registration\GregHSRW.exe (484)
Parado! C:\Program Files\EgisTec\MyWinLocker 3\x86\MWLService.exe (872)
Parado! C:\Program Files\Acer\Acer VCM\RS_Service.exe (1328)
Parado! C:\Program Files\Acer\Acer Updater\UpdaterService.exe (1112)
Parado! C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE (1992)
Parado! C:\Program Files\Google\Chrome\Application\chrome.exe (1100)
Parado! C:\Program Files\Intel\Intel Matrix Storage Manager\IAANTMon.exe (1136)
Parado! C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe (2192)
Parado! C:\Windows\system32\SearchIndexer.exe (2352)
Parado! C:\Program Files\Google\Chrome\Application\chrome.exe (2716)
Parado! C:\Program Files\Launch Manager\LManager.exe (2976)
Parado! C:\Program Files\Realtek\Audio\HDA\RtHDVCpl.exe (2988)
Parado! C:\Program Files\Acer\Acer ePower Management\ePowerTray.exe (3008)
Parado! C:\Program Files\EgisTec Egis Software Update\EgisUpdate.exe (3028)
Parado! C:\Program Files\EgisTec\MyWinLocker 3\x86\mwlDaemon.exe (3040)
Parado! C:\Program Files\Synaptics\SynTP\SynTPEnh.exe (3056)
Parado! C:\Program Files\Acer\Android Manager\iSync.exe (3064)
Parado! C:\Program Files\Acer\Updater\iUpdate.exe (3084)
Parado! C:\Windows\System32\igfxtray.exe (3124)
Parado! C:\Windows\System32\hkcmd.exe (3224)
Parado! C:\Windows\System32\igfxpers.exe (3248)
Parado! C:\Program Files\Samsung\Kies\KiesTrayAgent.exe (3284)
Parado! C:\Program Files\AVAST Software\Avast\AvastUI.exe (3312)
Parado! C:\Program Files\Common Files\Java\Java Update\jusched.exe (3328)
Parado! C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe (3344)
Parado! C:\Program Files\Windows Live\Messenger\msnmsgr.exe (3372)
Parado! C:\Program Files\Samsung\Kies\Kies.exe (3408)
Parado! C:\Program Files\Skype\Phone\Skype.exe (3456)
Parado! C:\Program Files\Acer\Acer VCM\AcerVCM.exe (3480)
Parado! C:\Windows\system32\igfxsrvc.exe (3656)
Parado! C:\Windows\system32\igfxext.exe (3692)
Parado! C:\Program Files\Synaptics\SynTP\SynTPHelper.exe (4044)
Parado! C:\Program Files\Acer\Acer ePower Management\ePowerEvent.exe (4876)
Parado! C:\Windows\system32\taskeng.exe (3048)
Parado! C:\Windows\system32\taskeng.exe (3188)
################## | Archivos # Carpetas infectadas |
Suprimido ! C:\ProgramData\FullRemove.exe
Suprimido ! C:\Program Files\GUM76FB.tmp
Suprimido ! C:\Program Files\GUT774A.tmp
Suprimido ! C:\Windows\system32\update.exe
(!) Archivos temporales suprimido.
################## | Registro |
################## | Mountpoints2 |
Suprimido ! HKCU\.\.\.\.\Explorer\MountPoints2\{0cdd4124-ba79-11e2-b9c0-806e6f6e6963}
################## | Listing |
[16/03/2013 - 13:18:23 | SHD ] C:\$Recycle.Bin
[11/04/2013 - 23:53:10 | N | 6155] C:\AdwCleaner[S1].txt
[12/08/2013 - 22:54:23 | N | 2574] C:\AdwCleaner[S2].txt
[16/03/2013 - 13:15:11 | D ] C:\Archivos de programa
[10/06/2009 - 23:42:20 | N | 24] C:\autoexec.bat
[16/03/2013 - 13:19:38 | D ] C:\book
[14/08/2009 - 11:25:33 | N | 8192] C:\BOOTSECT.BAK
[15/08/2013 - 03:53:04 | D ] C:\Config.Msi
[10/06/2009 - 23:42:20 | N | 10] C:\config.sys
[14/07/2009 - 06:53:55 | SHD ] C:\Documents and Settings
[29/08/2013 - 20:05:18 | ASH | 797396992] C:\hiberfil.sys
[14/08/2009 - 10:34:55 | D ] C:\Intel
[14/08/2009 - 10:54:35 | RHD ] C:\MSOCache
[17/04/2013 - 11:36:20 | D ] C:\OEM
[29/08/2013 - 20:05:17 | ASH | 1073741824] C:\pagefile.sys
[14/07/2009 - 04:37:05 | D ] C:\PerfLogs
[20/08/2013 - 23:47:35 | N | 512] C:\PhysicalDisk0_MBR.bin
[29/08/2013 - 20:26:47 | D ] C:\Program Files
[29/08/2013 - 20:26:41 | HD ] C:\ProgramData
[16/03/2013 - 13:15:11 | SHD ] C:\Recovery
[14/08/2009 - 10:44:36 | N | 1937] C:\RHDSetup.log
[24/08/2013 - 13:54:50 | SHD ] C:\System Volume Information
[29/08/2013 - 20:26:49 | D ] C:\UsbFix
[29/08/2013 - 20:27:45 | A | 8223] C:\UsbFix [Clean 1] USUARIO-PC.txt
[16/03/2013 - 13:15:27 | D ] C:\Users
[24/08/2013 - 23:43:41 | D ] C:\Windows
[28/08/2013 - 23:33:12 | D ] C:\ZHP
[15/04/2013 - 23:10:50 | N | 201327275] D:\var.img
[15/04/2013 - 23:11:02 | N | 138412983] D:\q2l.img
[15/04/2013 - 23:10:50 | N | 1048576000] D:\firefox.img
[15/04/2013 - 23:10:50 | D ] D:\Downloads
[15/04/2013 - 23:12:04 | D ] D:\picture
[15/04/2013 - 23:11:02 | D ] D:\android
[16/03/2013 - 13:18:08 | SHD ] D:\$RECYCLE.BIN
################## | Vaccin |
C:\Autorun.inf -> Vacuna creada por UsbFix (El Desaparecido)
D:\Autorun.inf -> Vacuna creada por UsbFix (El Desaparecido)
################## | E.O.F | https://www.sosvirus.net/ |
Ambucias
Posts
47310
Registration date
Monday February 1, 2010
Status
Moderator
Last seen
February 15, 2023
11,162
Aug 29, 2013 at 04:15 PM
Aug 29, 2013 at 04:15 PM
Hi,
The problem should now be solved as USB Fix deleted the following virused files:
C:\ProgramData\FullRemove.exe
C:\Program Files\GUM76FB.tmp
C:\Program Files\GUT774A.tmp
C:\Windows\system32\update.exe
Suprimido ! HKCU\.\.\.\.\Explorer\MountPoints2\{0cdd4124-ba79-11e2-b9c0-806e6f6e6963}
The problem should now be solved as USB Fix deleted the following virused files:
C:\ProgramData\FullRemove.exe
C:\Program Files\GUM76FB.tmp
C:\Program Files\GUT774A.tmp
C:\Windows\system32\update.exe
Suprimido ! HKCU\.\.\.\.\Explorer\MountPoints2\{0cdd4124-ba79-11e2-b9c0-806e6f6e6963}
bcn101
Posts
113
Registration date
Friday November 9, 2012
Status
Member
Last seen
July 28, 2014
Aug 29, 2013 at 04:27 PM
Aug 29, 2013 at 04:27 PM
ok then.. thank you very much ambu :)