Rapport 2 :
############################## | UsbFix V 7.145 | [Suppression]
Utilisateur: KOFFI (Administrateur) # KOFFI-PC
Mis à jour le 17/10/2013 par El Desaparecido - Team SosVirus
Lancé à 14:23:44 | 29/10/2013
Site Web:
https://www.usbfix.net/
Forum :
https://www.sosvirus.net/
Upload Malware:
https://www.sosvirus.net/upload_malware.php
Contact:
https://www.usbfix.net/contact/
PC: ASUSTeK Computer Inc. (N73SV)
CPU: Intel(R) Core(TM) i7-2630QM CPU @ 2.00GHz
RAM -> [Total : 6055 | Free : 4092]
Bios: American Megatrends Inc.
Boot: Normal boot
OS: Microsoft Windows 7 à‰dition Familiale Premium (6.1.7601 64-Bit) # Service Pack 1
WB: Windows Internet Explorer 10.0.9200.16721
SC: Security Center Service [Enabled]
WU: Windows Update Service [Enabled]
AV: BitDefender Antivirus [Enabled | Updated]
FW: Windows FireWall Service [Enabled]
C:\ (%systemdrive%) -> Disque fixe # 200 Go (60 Go libre(s) - 30%) [OS] # NTFS
D:\ -> Disque fixe # 466 Go (158 Go libre(s) - 34%) [DATA2] # NTFS
E:\ -> Disque fixe # 241 Go (51 Go libre(s) - 21%) [Data] # NTFS
F:\ -> CD-ROM
G:\ -> CD-ROM
H:\ -> Disque fixe # 1863 Go (1863 Go libre(s) - 100%) [My Passport] # NTFS
I:\ -> Disque amovible # 2 Go (0 Mo libre(s) - 0%) [T98] # FAT32
J:\ -> Disque amovible # 4 Go (68 Mo libre(s) - 2%) [] # FAT32
################## | Regedit Run |
HKLM\SOFTWARE | Run : [UpdateLBPShortCut] - "C:\Program Files (x86)\CyberLink\LabelPrint\MUITransfer\MUIStartMenu.exe" "C:\Program Files (x86)\CyberLink\LabelPrint" UpdateWithCreateOnce "Software\CyberLink\LabelPrint\2.5"
HKLM\SOFTWARE | Run : [UpdateP2GoShortCut] - "C:\Program Files (x86)\CyberLink\Power2Go\MUITransfer\MUIStartMenu.exe" "C:\Program Files (x86)\CyberLink\Power2Go" UpdateWithCreateOnce "SOFTWARE\CyberLink\Power2Go\6.0"
HKLM\SOFTWARE | Run : [Nuance PDF Reader-reminder] - "C:\Program Files (x86)\Nuance\PDF Reader\Ereg\Ereg.exe" -r "C:\ProgramData\Nuance\PDF Reader\Ereg\Ereg.ini"
HKLM\SOFTWARE | Run : [ATKMEDIA] - C:\Program Files (x86)\ASUS\ATK Package\ATK Media\DMedia.exe
HKLM\SOFTWARE | Run : [HControlUser] - C:\Program Files (x86)\ASUS\ATK Package\ATK Hotkey\HControlUser.exe
HKLM\SOFTWARE | Run : [SonicMasterTray] - C:\Program Files (x86)\ASUS\SonicMaster\SonicMasterTray.exe
HKLM\SOFTWARE | Run : [Wireless Console 3] - C:\Program Files (x86)\ASUS\Wireless Console 3\wcourier.exe
HKLM\SOFTWARE | Run : [VAWinAgent] - C:\ExpressGateUtil\VAWinAgent.exe
HKLM\SOFTWARE | Run : [RemoteControl10] - "C:\Program Files (x86)\Cyberlink\PowerDVD10\PDVD10Serv.exe"
HKLM\SOFTWARE | Run : [BDRegion] - C:\Program Files (x86)\Cyberlink\Shared files\brs.exe
HKLM\SOFTWARE | Run : [UpdatePSTShortCut] - "C:\Program Files (x86)\Cyberlink\DVD Suite\MUITransfer\MUIStartMenu.exe" "C:\Program Files (x86)\Cyberlink\DVD Suite" UpdateWithCreateOnce "Software\CyberLink\PowerStarter"
HKLM\SOFTWARE | Run : [PWRISOVM.EXE] - C:\Program Files (x86)\PowerISO\PWRISOVM.EXE
HKLM\SOFTWARE | Run : [YSearchProtection] - "C:\Program Files (x86)\Yahoo!\Search Protection\SearchProtection.exe"
HKLM\SOFTWARE | Run : [BitDefender Antiphishing Helper] - "C:\Program Files\BitDefender\BitDefender 2011\Antispam32\ieshow.exe"
HKLM\SOFTWARE | Run : [APSDaemon] - "C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe"
HKLM\SOFTWARE | Run : [iTunesHelper] - "C:\Program Files (x86)\iTunes\iTunesHelper.exe"
HKLM\SOFTWARE | Run : [ApnTBMon] - "C:\Program Files (x86)\AskPartnerNetwork\Toolbar\Updater\TBNotifier.exe"
HKLM\SOFTWARE | Run : [RIMBBLaunchAgent.exe] - C:\Program Files (x86)\Common Files\Research In Motion\USB Drivers\RIMBBLaunchAgent.exe
HKLM\SOFTWARE\wow6432Node | Run : [UpdateLBPShortCut] - "C:\Program Files (x86)\CyberLink\LabelPrint\MUITransfer\MUIStartMenu.exe" "C:\Program Files (x86)\CyberLink\LabelPrint" UpdateWithCreateOnce "Software\CyberLink\LabelPrint\2.5"
HKLM\SOFTWARE\wow6432Node | Run : [UpdateP2GoShortCut] - "C:\Program Files (x86)\CyberLink\Power2Go\MUITransfer\MUIStartMenu.exe" "C:\Program Files (x86)\CyberLink\Power2Go" UpdateWithCreateOnce "SOFTWARE\CyberLink\Power2Go\6.0"
HKLM\SOFTWARE\wow6432Node | Run : [Nuance PDF Reader-reminder] - "C:\Program Files (x86)\Nuance\PDF Reader\Ereg\Ereg.exe" -r "C:\ProgramData\Nuance\PDF Reader\Ereg\Ereg.ini"
HKLM\SOFTWARE\wow6432Node | Run : [ATKMEDIA] - C:\Program Files (x86)\ASUS\ATK Package\ATK Media\DMedia.exe
HKLM\SOFTWARE\wow6432Node | Run : [HControlUser] - C:\Program Files (x86)\ASUS\ATK Package\ATK Hotkey\HControlUser.exe
HKLM\SOFTWARE\wow6432Node | Run : [SonicMasterTray] - C:\Program Files (x86)\ASUS\SonicMaster\SonicMasterTray.exe
HKLM\SOFTWARE\wow6432Node | Run : [Wireless Console 3] - C:\Program Files (x86)\ASUS\Wireless Console 3\wcourier.exe
HKLM\SOFTWARE\wow6432Node | Run : [VAWinAgent] - C:\ExpressGateUtil\VAWinAgent.exe
HKLM\SOFTWARE\wow6432Node | Run : [RemoteControl10] - "C:\Program Files (x86)\Cyberlink\PowerDVD10\PDVD10Serv.exe"
HKLM\SOFTWARE\wow6432Node | Run : [BDRegion] - C:\Program Files (x86)\Cyberlink\Shared files\brs.exe
HKLM\SOFTWARE\wow6432Node | Run : [UpdatePSTShortCut] - "C:\Program Files (x86)\Cyberlink\DVD Suite\MUITransfer\MUIStartMenu.exe" "C:\Program Files (x86)\Cyberlink\DVD Suite" UpdateWithCreateOnce "Software\CyberLink\PowerStarter"
HKLM\SOFTWARE\wow6432Node | Run : [PWRISOVM.EXE] - C:\Program Files (x86)\PowerISO\PWRISOVM.EXE
HKLM\SOFTWARE\wow6432Node | Run : [YSearchProtection] - "C:\Program Files (x86)\Yahoo!\Search Protection\SearchProtection.exe"
HKLM\SOFTWARE\wow6432Node | Run : [BitDefender Antiphishing Helper] - "C:\Program Files\BitDefender\BitDefender 2011\Antispam32\ieshow.exe"
HKLM\SOFTWARE\wow6432Node | Run : [APSDaemon] - "C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe"
HKLM\SOFTWARE\wow6432Node | Run : [iTunesHelper] - "C:\Program Files (x86)\iTunes\iTunesHelper.exe"
HKLM\SOFTWARE\wow6432Node | Run : [ApnTBMon] - "C:\Program Files (x86)\AskPartnerNetwork\Toolbar\Updater\TBNotifier.exe"
HKLM\SOFTWARE\wow6432Node | Run : [RIMBBLaunchAgent.exe] - C:\Program Files (x86)\Common Files\Research In Motion\USB Drivers\RIMBBLaunchAgent.exe
HKLM\SOFTWARE | RunOnce : [] -
HKLM\SOFTWARE\wow6432Node | RunOnce : [] -
HKU\S-1-5-19\SOFTWARE | Run : [Sidebar] - %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun
HKU\S-1-5-20\SOFTWARE | Run : [Sidebar] - %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun
HKU\S-1-5-21-3150853622-2755031185-4004189574-1001\SOFTWARE | Run : [IDMan] - C:\Program Files (x86)\Internet Download Manager\IDMan.exe /onboot
HKU\S-1-5-21-3150853622-2755031185-4004189574-1001\SOFTWARE | Run : [Messenger (Yahoo!)] - "C:\PROGRA~2\Yahoo!\MESSEN~1\YahooMessenger.exe" -quiet
HKU\S-1-5-21-3150853622-2755031185-4004189574-1001\SOFTWARE | Run : [uTorrent] - "C:\Program Files (x86)\uTorrent\uTorrent.exe" /MINIMIZED
HKU\S-1-5-21-3150853622-2755031185-4004189574-1001\SOFTWARE | Run : [Search Protection] - C:\Program Files (x86)\Yahoo!\Search Protection\SearchProtection.exe
HKU\S-1-5-21-3150853622-2755031185-4004189574-1001\SOFTWARE | Run : [msnmsgr] - "C:\Program Files (x86)\Windows Live\Messenger\msnmsgr.exe" /background
HKU\S-1-5-21-3150853622-2755031185-4004189574-1001\SOFTWARE | Run : [Syncables] - C:\Program Files (x86)\syncables\syncables desktop\Syncables.exe
HKU\S-1-5-21-3150853622-2755031185-4004189574-1001\SOFTWARE | Run : [Facebook Update] - "C:\Users\KOFFI\AppData\Local\Facebook\Update\FacebookUpdate.exe" /c /nocrashserver
HKU\S-1-5-19\SOFTWARE | RunOnce : [mctadmin] - C:\Windows\System32\mctadmin.exe
HKU\S-1-5-20\SOFTWARE | RunOnce : [mctadmin] - C:\Windows\System32\mctadmin.exe
HKU\S-1-5-18\SOFTWARE | RunOnce : [SPReview] - "C:\Windows\System32\SPReview\SPReview.exe" /sp:1 /errorfwlink:"
https://go.microsoft.com/fwlink/?LinkID=122915" /build:7601
################## | Processus Stoppés |
Stoppé! C:\Program Files\BitDefender\BitDefender 2011\vsserv.exe (ID 1052 |ParentID 924)
Stoppé! C:\Program Files\BitDefender\BitDefender 2011\bdagent.exe (ID 2144 |ParentID 2112)
Stoppé! C:\Program Files\BitDefender\BitDefender 2011\pchooklaunch64.exe (ID 2528 |ParentID 2144)
Stoppé! C:\Program Files\BitDefender\BitDefender 2011\Antispam32\pchooklaunch32.exe (ID 2568 |ParentID 2144)
Stoppé! C:\Program Files\BitDefender\BitDefender 2011\updatesrv.exe (ID 4700 |ParentID 924)
Stoppé! C:\Windows\explorer.exe (ID 6876 |ParentID 844)
Stoppé! C:\Windows\system32\HPSIsvc.exe (ID 9528 |ParentID 924)
Stoppé! C:\Windows\System32\WUDFHost.exe (ID 9788 |ParentID 1164)
Stoppé! C:\Program Files\Intel\TurboBoost\TurboBoost.exe (ID 8872 |ParentID 924)
Stoppé! C:\Windows\system32\SearchIndexer.exe (ID 7520 |ParentID 924)
Stoppé! C:\Program Files\Windows Media Player\wmpnetwk.exe (ID 1180 |ParentID 924)
Stoppé! C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE (ID 2080 |ParentID 924)
Stoppé! C:\Windows\ehome\ehRecvr.exe (ID 2780 |ParentID 924)
Stoppé! C:\Windows\System32\spoolsv.exe (ID 7248 |ParentID 924)
Stoppé! C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe (ID 7840 |ParentID 924)
################## | à‰léments infectieux |
(!) Fichiers temporaires supprimés.
################## | Registre |
################## | Listing |
[25/06/2013 - 22:28:48 | SHD ] C:\$Recycle.Bin
[10/08/2011 - 14:26:56 | D ] C:\ASUS.DAT
[03/02/2011 - 14:19:12 | D ] C:\AsusVibeData
[29/10/2013 - 14:14:06 | RASHD ] C:\Autorun.inf
[28/10/2013 - 19:07:39 | N | 382438] C:\bdlog.txt
[06/05/2013 - 10:05:29 | SHD ] C:\Boot
[20/11/2010 - 04:40:08 | RASH | 383786] C:\bootmgr
[29/07/2009 - 06:03:37 | RASH | 8192] C:\BOOTSECT.BAK
[11/08/2011 - 05:07:11 | N | 16582] C:\devlist.txt
[14/07/2009 - 05:08:56 | SHD ] C:\Documents and Settings
[11/08/2011 - 04:45:52 | D ] C:\eSupport
[11/08/2011 - 04:58:43 | D ] C:\ExpressGateUtil
[10/08/2011 - 14:07:11 | N | 9] C:\Finish.log
[29/10/2013 - 11:24:56 | ASH | 4761669632] C:\hiberfil.sys
[11/08/2011 - 04:33:43 | D ] C:\Intel
[22/09/2013 - 01:01:54 | D ] C:\InternetEverywhere
[11/08/2011 - 04:41:26 | N | 29] C:\mini-agent.txt
[14/01/2013 - 14:09:27 | RHD ] C:\MSOCache
[14/04/2011 - 01:45:31 | N | 2621440] C:\N73SV.BIN
[20/04/2011 - 07:25:25 | N | 19] C:\N73SV_WIN7.60
[29/10/2013 - 11:25:03 | ASH | 6348894208] C:\pagefile.sys
[10/08/2011 - 15:08:04 | N | 233] C:\Pass.txt
[14/07/2009 - 03:20:08 | D ] C:\PerfLogs
[17/10/2013 - 16:49:48 | D ] C:\Program Files
[21/10/2013 - 14:30:27 | D ] C:\Program Files (x86)
[09/10/2013 - 11:01:43 | HD ] C:\ProgramData
[07/09/2011 - 05:28:39 | SHD ] C:\Recovery
[17/12/2010 - 01:50:23 | N | 5] C:\RECOVERY.DAT
[11/08/2011 - 04:37:49 | N | 2306] C:\RHDSetup.log
[11/08/2011 - 04:50:41 | N | 168] C:\setup.log
[11/08/2011 - 04:45:43 | N | 380] C:\setuplogfile.log
[29/10/2013 - 12:27:27 | SHD ] C:\System Volume Information
[29/10/2013 - 14:40:20 | D ] C:\UsbFix
[29/10/2013 - 14:14:09 | N | 20578] C:\UsbFix [Clean 2] KOFFI-PC.txt
[29/10/2013 - 14:44:12 | A | 11014] C:\UsbFix [Clean 3] KOFFI-PC.txt
[29/10/2013 - 14:08:32 | D ] C:\Users
[29/10/2013 - 14:08:32 | D ] C:\Windows
[07/09/2011 - 05:29:29 | SHD ] D:\$RECYCLE.BIN
[29/10/2013 - 14:14:06 | RASHD ] D:\Autorun.inf
[29/08/2013 - 11:09:42 | D ] D:\FFOutput
[29/10/2013 - 14:08:32 | D ] D:\Series
[11/08/2011 - 04:14:50 | SHD ] D:\System Volume Information
[07/09/2011 - 05:29:29 | SHD ] E:\$RECYCLE.BIN
[29/10/2013 - 14:14:06 | RASHD ] E:\Autorun.inf
[29/10/2013 - 14:08:33 | D ] E:\SAUVEGARDE
[11/08/2011 - 04:14:52 | SHD ] E:\System Volume Information
[29/10/2013 - 14:23:57 | SHD ] H:\$RECYCLE.BIN
[17/06/2013 - 08:02:04 | N | 300507204] I:\Testing Video 01.avi
[02/01/2000 - 10:14:56 | D ] I:\LOST.DIR
[05/01/2000 - 03:03:44 | D ] I:\.android_secure
[02/01/2000 - 10:17:24 | D ] I:\Music
[02/01/2000 - 10:17:26 | D ] I:\Podcasts
[25/10/2013 - 16:28:30 | D ] I:\Ringtones
[02/01/2000 - 10:17:26 | D ] I:\Alarms
[02/01/2000 - 10:17:26 | D ] I:\Notifications
[02/01/2000 - 10:17:26 | D ] I:\Pictures
[02/01/2000 - 10:17:26 | D ] I:\Movies
[10/10/2013 - 05:56:10 | D ] I:\Download
[12/10/2013 - 20:05:44 | D ] I:\DCIM
[02/01/2000 - 10:22:38 | D ] I:\Android
[27/10/2013 - 11:13:52 | D ] I:\Recordings
[06/10/2013 - 19:49:28 | D ] I:\documents
[06/10/2013 - 19:49:34 | D ] I:\.dataviz
[08/10/2013 - 10:07:24 | D ] I:\.youversion
[08/10/2013 - 10:04:42 | D ] I:\aquery
[14/10/2013 - 20:51:24 | D ] I:\media
[22/10/2013 - 08:19:50 | D ] I:\WhatsApp
[29/10/2013 - 14:14:08 | RASHD ] I:\Autorun.inf
[18/12/2012 - 18:56:34 | D ] J:\Music
[01/10/2011 - 00:00:08 | D ] J:\Sounds
[01/10/2011 - 00:00:10 | D ] J:\Others
[08/10/2013 - 20:12:28 | N | 20] J:\mm_sec.dat
[18/06/2013 - 20:57:50 | D ] J:\blackberry
[18/06/2013 - 20:57:52 | D ] J:\tmp
[19/06/2013 - 13:07:08 | D ] J:\youversion
[13/05/2013 - 18:09:10 | N | 4178264] J:\d3dx9_41.dll
[23/06/2013 - 19:11:36 | N | 948067] J:\player.swf
[08/10/2013 - 15:46:42 | D ] J:\LOST.DIR
[13/10/2013 - 16:45:44 | D ] J:\Photos Léo
[29/10/2013 - 14:14:10 | RASHD ] J:\Autorun.inf
################## | Vaccin |
C:\Autorun.inf -> Vaccin créé par UsbFix (El Desaparecido)
D:\Autorun.inf -> Vaccin créé par UsbFix (El Desaparecido)
E:\Autorun.inf -> Vaccin créé par UsbFix (El Desaparecido)
H:\Autorun.inf -> Vaccin créé par UsbFix (El Desaparecido)
I:\Autorun.inf -> Vaccin créé par UsbFix (El Desaparecido)
J:\Autorun.inf -> Vaccin créé par UsbFix (El Desaparecido)
################## | E.O.F |
https://www.usbfix.net -
https://www.sosvirus.net |