############################## | UsbFix V 7.081 | [Research] User: Danusia (Administrator) # JA Updated 05/02/2012 by El Desaparecido Started at 16:17:25 | 21/02/2012 Website: http://eldesaparecido.com Suspicious file ? : http://eldesaparecido.com/upload.html Contact: contact@eldesaparecido.com PC: INTEL_ (D915PGN_) (X86-based PC) # Desktop Computer CPU: Intel(R) Pentium(R) 4 CPU 2.66GHz (2666) RAM -> [ Total : 510 | Free : 212 ] BIOS: BIOS Date: 09/26/06 10:10:49 Ver: 08.00.10 BOOT: Normal boot OS: Microsoft Windows XP Professional (5.1.2600 32-Bit) # Dodatek Service Pack 3 WB: Windows Internet Explorer 8.0.6001.18702 SC: Security Center Service [ Enabled ] WU: Windows Update Service [ Enabled ] FW: Windows FireWall Service [ Enabled ] C:\ (%systemdrive%) -> Fixed drive # 20 Gb (9 Mb free - 49%) [] # NTFS D:\ -> Fixed drive # 20 Gb (4 Mb free - 21%) [DANE] # NTFS E:\ -> Fixed drive # 35 Gb (14 Mb free - 39%) [MAGAZYN] # NTFS F:\ -> CD-ROM G:\ -> CD-ROM H:\ -> Fixed drive # 932 Gb (240 Mb free - 26%) [Volume] # NTFS ################## | Active Processes | C:\WINDOWS\System32\smss.exe (496) C:\WINDOWS\system32\winlogon.exe (1408) C:\WINDOWS\system32\services.exe (1452) C:\WINDOWS\system32\lsass.exe (1464) C:\WINDOWS\system32\Ati2evxx.exe (1612) C:\WINDOWS\system32\svchost.exe (1624) C:\WINDOWS\System32\svchost.exe (1996) C:\WINDOWS\system32\Ati2evxx.exe (772) C:\WINDOWS\Explorer.EXE (860) C:\WINDOWS\system32\spoolsv.exe (980) C:\WINDOWS\system32\acs.exe (1080) C:\Program Files\ESET\ESET Smart Security\ekrn.exe (1208) C:\WINDOWS\System32\svchost.exe (1300) C:\Program Files\Java\jre6\bin\jqs.exe (1328) C:\WINDOWS\system32\svchost.exe (1684) C:\Program Files\NETGEAR\WNA1100\WifiSvc.exe (1760) C:\WINDOWS\SOUNDMAN.EXE (1096) C:\WINDOWS\ALCWZRD.EXE (1196) C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe (1204) C:\WINDOWS\tsnp325.exe (1564) C:\WINDOWS\vsnp325.exe (1668) C:\Program Files\ESET\ESET Smart Security\egui.exe (604) C:\Program Files\HP\hpcoretech\hpcmpmgr.exe (2076) C:\WINDOWS\system32\spool\drivers\w32x86\3\hpztsb10.exe (2084) C:\Program Files\Hewlett-Packard\HP Software Update\HPWuSchd2.exe (2096) C:\Program Files\Common Files\Java\Java Update\jusched.exe (2156) C:\WINDOWS\system32\ctfmon.exe (2180) C:\Program Files\Common Files\Ahead\Lib\NMBgMonitor.exe (2228) C:\Program Files\DAEMON Tools Lite\DTLite.exe (2236) C:\Program Files\Windows Media Player\WMPNSCFG.exe (2324) C:\Program Files\NETGEAR\WNA1100\WNA1100.exe (2572) C:\Program Files\Common Files\Ahead\Lib\NMIndexingService.exe (716) C:\WINDOWS\system32\wbem\wmiapsrv.exe (2668) C:\Program Files\Common Files\Ahead\Lib\NMIndexStoreSvr.exe (2692) C:\Program Files\Mozilla Firefox\firefox.exe (2980) C:\Program Files\Mozilla Firefox\plugin-container.exe (4052) C:\UsbFix\Go.exe (8284) ################## | Files # Infected Folders | Found ! H:\Menu.exe Found ! H:\MUZYKA ################## | Registry | ################## | Mountpoints2 | ################## | Vaccin | (!) This computer is not vaccinated! ################## | E.O.F |