- dim. 3 nov. 2013 18:38
#14244
TADAA!
- Code: Tout sélectionner
############################## | UsbFix V 7.148 | [Deletion]
User: Audrey (Administrator) # AUDREY-HP
Updated 01/11/2013 by El Desaparecido - Team SosVirus
Started at 17:28:11 | 03/11/2013
Website: https://www.usbfix.net/
Forum : https://www.sosvirus.net/
Upload Malware: https://www.sosvirus.net/upload_malware.php
Contact: https://www.usbfix.net/contact/
PC: Hewlett-Packard (1611)
CPU: AMD E-350 Processor
RAM -> [Total : 3578 | Free : 2131]
Bios: Hewlett-Packard
Boot: Fail-safe with network boot
OS: Microsoft Windows 7 Home Premium (6.1.7601 32-Bit) Service Pack 1
WB: Windows Internet Explorer : 10.0.9200.16721
SC: Security Center Service [Enabled]
WU: Windows Update Service [Enabled]
AV: BitDefender Antivirus [(!) Disabled | (!) Outdated]
AS: Windows Defender : 6.1.7600.16385 (win7_rtm.090713-1255)
AS: Malwarebytes' Anti-Malware : 1.75.0001
FW: Windows FireWall Service [Enabled]
C:\ (%systemdrive%) -> Fixed drive # 447 Gb (208 Mb free - 47%) [] # NTFS
D:\ -> Fixed drive # 15 Gb (2 Mb free - 10%) [RECOVERY] # NTFS
E:\ -> Fixed drive # 4 Gb (1 Mb free - 28%) [HP_TOOLS] # FAT32
F:\ -> Removable drive # 2 Gb (2 Mb free - 97%) [] # FAT
################## | Reference of comparison MD5 |
Md5 : b7019418d79d26cef0d0ea8c04a39337 -> C:\Users\Public\8i7asystemmD.vbe
Md5 : b7019418d79d26cef0d0ea8c04a39337 -> C:\Users\Public\97asystemD.VBE
Md5 : b7019418d79d26cef0d0ea8c04a39337 -> C:\Users\Public\9eimmD.vbe
Md5 : b7019418d79d26cef0d0ea8c04a39337 -> C:\Users\Public\9emmD.vbe
Md5 : b7019418d79d26cef0d0ea8c04a39337 -> C:\Users\Public\9stemD.VBE
Md5 : b7019418d79d26cef0d0ea8c04a39337 -> C:\Users\Public\9stiemD.VBE
Md5 : b7019418d79d26cef0d0ea8c04a39337 -> C:\Users\Public\sysfftem7.VBE
Md5 : b7019418d79d26cef0d0ea8c04a39337 -> C:\Users\Public\systefm34.vbe
Md5 : aed4faf279abf7d7605e81707be3ce64 -> C:\Users\Audrey\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\iTunesHelper.vbe
Md5 : bcdef9a6d179f4c587f9b742de82eef0 -> C:\Users\Audrey\AppData\Local\Temp\flashmemory.vbe
Md5 : bcdef9a6d179f4c587f9b742de82eef0 -> C:\Users\Audrey\AppData\Local\Temp\iTunesHelper.vbe
Md5 : c9b8fa51c889f97dc5c4deb274b1fbf2 -> C:\Users\Audrey\AppData\Local\Temp\Nj99.vbs
Md5 : DENIED -> F:\iTunesHelper.vbe
################## | Stopped processes |
Stopped! C:\Windows\Explorer.EXE (ID: 1416 |ParentID: 1408)
Stopped! C:\Windows\system32\ctfmon.exe (ID: 1488 |ParentID: 1416)
Stopped! C:\Windows\system32\DllHost.exe (ID: 1724 |ParentID: 624)
Stopped! C:\Users\Audrey\AppData\Local\Google\Chrome\Application\chrome.exe (ID: 348 |ParentID: 1416)
Stopped! C:\Users\Audrey\AppData\Local\Google\Chrome\Application\chrome.exe (ID: 1632 |ParentID: 348)
Stopped! C:\Users\Audrey\AppData\Local\Google\Chrome\Application\chrome.exe (ID: 1892 |ParentID: 348)
Stopped! C:\Windows\System32\wscript.exe (ID: 2056 |ParentID: 3236)
################## | Regedit Run |
HKLM\SOFTWARE | Run : [StartCCC] - "C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" MSRun
HKLM\SOFTWARE | Run : [SysTrayApp] - C:\Program Files\IDT\WDM\sttray.exe
HKLM\SOFTWARE | Run : [SynTPEnh] - %ProgramFiles%\Synaptics\SynTP\SynTPEnh.exe
HKLM\SOFTWARE | Run : [BTMTrayAgent] - rundll32.exe "C:\Program Files\Motorola\Bluetooth\btmshell.dll",TrayApp
HKLM\SOFTWARE | Run : [HPQuickWebProxy] - "C:\Program Files\Hewlett-Packard\HP QuickWeb\hpqwutils.exe"
HKLM\SOFTWARE | Run : [HPConnectionManager] - C:\Program Files\Hewlett-Packard\HP Connection Manager\HPCMDelayStart.exe
HKLM\SOFTWARE | Run : [] -
HKLM\SOFTWARE | Run : [HP Quick Launch] - C:\Program Files\Hewlett-Packard\HP Quick Launch\HPMSGSVC.exe
HKLM\SOFTWARE | Run : [Easybits Recovery] - C:\Program Files\EasyBits For Kids\ezRecover.exe
HKLM\SOFTWARE | Run : [HPOSD] - C:\Program Files\Hewlett-Packard\HP On Screen Display\HPOSD.exe
HKLM\SOFTWARE | Run : [APSDaemon] - "C:\Program Files\Common Files\Apple\Apple Application Support\APSDaemon.exe"
HKLM\SOFTWARE | Run : [Adobe ARM] - "C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
HKLM\SOFTWARE | Run : [iTunesHelper] - wscript.exe //B "C:\Users\Audrey\AppData\Local\Temp\iTunesHelper.vbe"
HKLM\SOFTWARE | Run : [Genie TimeLine Tray] - C:\Program Files\Genie-Soft\Genie Timeline\GSTimeLineAgent.exe -auto
HKLM\SOFTWARE | Run : [GrooveMonitor] - "C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe"
HKLM\SOFTWARE | Run : [SunJavaUpdateSched] - "C:\Program Files\Common Files\Java\Java Update\jusched.exe"
HKLM\SOFTWARE | Run : [AvastUI.exe] - "C:\Program Files\AVAST Software\Avast\AvastUI.exe" /nogui
HKLM\SOFTWARE | Run : [bdruninstaller] - "C:\Program Files\Common Files\Bitdefender\SetupInformation\downloader\setuplauncher.exe" /run:"C:\Program Files\Common Files\Bitdefender\SetupInformation\downloader\setupdownloader.exe" /args:"/after_restart"
HKLM\SOFTWARE | Run : [BitDefender Antiphishing Helper] - "C:\Program Files\BitDefender\BitDefender 2011\ieshow.exe"
HKLM\SOFTWARE | Run : [BDAgent] - "C:\Program Files\BitDefender\BitDefender 2011\bdagent.exe"
HKLM\SOFTWARE | RunOnce : [] -
HKU\S-1-5-19\SOFTWARE | Run : [Sidebar] - %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun
HKU\S-1-5-20\SOFTWARE | Run : [Sidebar] - %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun
HKU\S-1-5-21-1190468337-140412576-3729368624-1002\SOFTWARE | Run : [Google Update] - "C:\Users\Audrey\AppData\Local\Google\Update\GoogleUpdate.exe" /c
HKU\S-1-5-21-1190468337-140412576-3729368624-1002\SOFTWARE | Run : [Facebook Update] - "C:\Users\Audrey\AppData\Local\Facebook\Update\FacebookUpdate.exe" /c /nocrashserver
HKU\S-1-5-21-1190468337-140412576-3729368624-1002\SOFTWARE | Run : [LaCie Desktop Manager Startup] - "C:\Program Files\LaCie\Desktop Manager\LaCieDesktopManagerStatusItem.exe"
HKU\S-1-5-21-1190468337-140412576-3729368624-1002\SOFTWARE | Run : [MSa2emHR] - wscript.exe //B "C:\Users\Audrey\AppData\Local\Temp\MSa2emHR.vbs"
HKU\S-1-5-21-1190468337-140412576-3729368624-1002\SOFTWARE | Run : [qAuPnVQM] - wscript.exe //B "C:\Users\Audrey\AppData\Local\Temp\qAuPnVQM.vbs"
HKU\S-1-5-21-1190468337-140412576-3729368624-1002\SOFTWARE | Run : [LU86st0c] - wscript.exe //B "C:\Users\Audrey\AppData\Local\Temp\LU86st0c.vbs"
HKU\S-1-5-21-1190468337-140412576-3729368624-1002\SOFTWARE | Run : [G9zxsaPJ] - wscript.exe //B "C:\Users\Audrey\AppData\Local\Temp\G9zxsaPJ.vbs"
HKU\S-1-5-21-1190468337-140412576-3729368624-1002\SOFTWARE | Run : [iTunesHelper] - wscript.exe //B "C:\Users\Audrey\AppData\Local\Temp\iTunesHelper.vbe"
HKU\S-1-5-19\SOFTWARE | RunOnce : [mctadmin] - C:\Windows\System32\mctadmin.exe
HKU\S-1-5-20\SOFTWARE | RunOnce : [mctadmin] - C:\Windows\System32\mctadmin.exe
################## | Generic Research |
Deleted ! F:\iTunesHelper.vbe
Deleted ! C:\Users\Audrey\AppData\Local\Temp\iTunesHelper.vbe
Deleted ! C:\Users\Audrey\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\iTunesHelper.vbe
Deleted ! F:\Autorun.inf.lnk
Deleted ! F:\BitDefender.lnk
Deleted ! F:\Usbfix.lnk
Deleted ! C:\Users\Public\8i7asystemmD.vbe
Deleted ! C:\Users\Public\97asystemD.VBE
Deleted ! C:\Users\Public\9eimmD.vbe
Deleted ! C:\Users\Public\9emmD.vbe
Deleted ! C:\Users\Public\9stemD.VBE
Deleted ! C:\Users\Public\9stiemD.VBE
Deleted ! C:\Users\Public\sysfftem7.VBE
Deleted ! C:\Users\Public\systefm34.vbe
Deleted ! C:\Users\Public\9iaD12_Loading.zip
Deleted ! C:\Users\Public\D7_Loading.zip
Deleted ! C:\Users\Audrey\AppData\Local\Temp\Intel(R)s7.exe.tmp
Deleted ! C:\Users\Audrey\AppData\Local\Temp\Musiques.pif
Deleted ! C:\Users\Audrey\AppData\Local\Temp\utt19CA.tmp.exe
Deleted ! C:\Users\Audrey\AppData\Local\Temp\uttA558.tmp.exe
Deleted ! C:\Users\Audrey\AppData\Local\Temp\uttEDD3.tmp.exe
Deleted ! C:\Users\Audrey\AppData\Local\Temp\flashmemory.vbe
Deleted ! C:\Users\Audrey\AppData\Local\Temp\Nj99.vbs
Deleted ! C:\Users\Audrey\AppData\Local\Temp\1477.hta
Deleted ! C:\Users\Audrey\AppData\Local\Temp\7777i.hta
Deleted ! C:\Users\Audrey\AppData\Local\Temp\77u.hta
Deleted ! C:\Users\Audrey\AppData\Local\Temp\97.hta
Deleted ! C:\Users\Audrey\AppData\Local\Temp\DC7.hta
Deleted ! C:\Users\Audrey\AppData\Local\Temp\dcyyt.hta
Deleted ! C:\Users\Audrey\AppData\Local\Temp\ddddddddddd.hta
Deleted ! C:\Users\Audrey\AppData\Local\Temp\HY.hta
Deleted ! C:\Users\Audrey\AppData\Local\Temp\iiiii9.hta
Deleted ! C:\Users\Audrey\AppData\Local\Temp\iiiiiiiiiiiiz7.hta
Deleted ! C:\Users\Audrey\AppData\Local\Temp\sssssssssi.hta
Deleted ! C:\Users\Audrey\AppData\Local\Temp\zzzz7.hta
Deleted ! C:\Users\Audrey\AppData\Local\Temp\zzzzzzzzzzzz5.hta
Deleted ! D:\desktop.ini
(!) Temporary files deleted.
################## | Comparison MD5 |
################## | Registry |
Deleted ! HKU\S-1-5-21-1190468337-140412576-3729368624-1002\Software\Microsoft\Windows\CurrentVersion\Run|iTunesHelper
Deleted ! HKLM\Software\Microsoft\Windows\CurrentVersion\Run|iTunesHelper
################## | Listing |
[23/10/2011 - 15:00:29 | SHD ] C:\$Recycle.Bin
[02/11/2013 - 15:47:21 | D ] C:\AdwCleaner
[10/06/2009 - 22:42:20 | N | 24] C:\autoexec.bat
[01/11/2013 - 07:10:24 | D ] C:\Backup_2013-10-31 221024
[03/11/2013 - 03:21:15 | N | 5299] C:\bdlog.txt
[23/04/2011 - 03:54:33 | SHD ] C:\boot
[20/11/2010 - 22:29:06 | RASH | 383786] C:\bootmgr
[02/10/2013 - 20:53:53 | N | 3408] C:\bootsqm.dat
[02/11/2013 - 14:37:26 | SHD ] C:\Config.Msi
[10/06/2009 - 22:42:20 | N | 10] C:\config.sys
[14/07/2009 - 05:53:55 | SHD ] C:\Documents and Settings
[12/11/2011 - 15:44:40 | D ] C:\extensions
[03/11/2013 - 16:29:32 | ASH | 2813775872] C:\hiberfil.sys
[25/06/2011 - 20:25:54 | D ] C:\HP
[13/11/2011 - 17:24:45 | RHD ] C:\MSOCache
[03/11/2013 - 16:29:38 | ASH | 3751702528] C:\pagefile.sys
[14/07/2009 - 03:37:05 | D ] C:\PerfLogs
[02/11/2013 - 16:42:45 | N | 0] C:\PhysicalDisk0_MBR.bin
[02/11/2013 - 16:12:05 | D ] C:\Program Files
[02/11/2013 - 15:46:09 | HD ] C:\ProgramData
[23/10/2011 - 14:46:22 | SHD ] C:\Recovery
[01/11/2013 - 14:10:53 | D ] C:\rsit
[24/04/2012 - 12:04:08 | D ] C:\SphinxME
[27/11/2012 - 21:19:40 | D ] C:\SWSetup
[02/11/2013 - 11:30:08 | SHD ] C:\System Volume Information
[23/10/2011 - 14:46:28 | D ] C:\SYSTEM.SAV
[03/11/2013 - 17:36:59 | D ] C:\UsbFix
[03/11/2013 - 17:40:24 | A | 10294] C:\UsbFix [Clean 1] AUDREY-HP.txt
[03/11/2013 - 16:52:44 | N | 11000] C:\UsbFix [Scan 1] AUDREY-HP.txt
[23/10/2011 - 14:44:31 | RD ] C:\Users
[01/11/2013 - 18:59:33 | D ] C:\Windows
[01/11/2013 - 07:10:36 | D ] C:\_Exception1
[23/10/2011 - 15:00:29 | SHD ] D:\$RECYCLE.BIN
[23/10/2011 - 15:00:23 | RASHD ] D:\boot
[14/07/2009 - 19:39:00 | RASH | 383562] D:\bootmgr
[23/10/2011 - 15:00:23 | D ] D:\FactoryUpdate
[23/10/2011 - 15:00:23 | D ] D:\hp
[06/02/2012 - 21:17:17 | N | 19] D:\HPSF_Rep.txt
[05/11/2012 - 14:02:46 | N | 8] D:\HP_WSD.dat
[23/10/2011 - 15:00:23 | RSHD ] D:\preload
[17/01/2013 - 18:54:39 | RSD ] D:\recovery
[23/10/2011 - 15:00:23 | D ] D:\RM_Reserve
[30/12/2012 - 19:01:01 | SHD ] D:\System Volume Information
[05/11/2012 - 14:02:48 | N | 8] E:\HP_WSD.dat
[25/06/2011 - 21:07:50 | D ] E:\Hewlett-Packard
[25/06/2011 - 21:34:28 | SHD ] E:\$RECYCLE.BIN
[06/02/2012 - 21:17:18 | N | 19] E:\HPSF_Rep.txt
[01/11/2013 - 18:06:50 | SHD ] F:\Autorun.inf
[01/11/2013 - 18:07:54 | D ] F:\BitDefender
[01/11/2013 - 18:08:50 | D ] F:\Usbfix
################## | Vaccin |
F:\Autorun.inf -> Vaccine created by UsbFix (El Desaparecido)
################## | E.O.F | https://www.usbfix.net - https://www.sosvirus.net |