############################## | UsbFix V 7.118 | [Deletion]
User: pc (Administrator) # VALACH
Updated 24/03/2013 by El Desaparecido
Started at 13:00:50 | 26/03/2013
Website:
http://sosvirus.org/
Upload Malware:
http://upload.sosvirus.org/
Contact:
contact@sosvirus.org
PC: Gigabyte Technology Co., Ltd. (To be filled by O.E.M.) (x64-based PC)
CPU: Intel(R) Core(TM) i5-3550 CPU @ 3.30GHz (3701)
RAM -> [Total : 8138 | Free : 5208]
BIOS: BIOS Date: 02/15/12 18:07:41 Ver: 04.06.05
BOOT: Normal boot
OS: Microsoft Windows 7 Ultimate (6.1.7601 64-Bit) # Service Pack 1
WB: Windows Internet Explorer 9.0.8112.16421
SC: Security Center Service [Enabled]
WU: Windows Update Service [Enabled]
AV: Emsisoft Anti-Malware [(!) Disabled | Updated]
FW: Windows FireWall Service [Enabled]
C:\ (%systemdrive%) -> Fixed drive # 931 Gb (281 Mb free - 30%) [WD Caviar Black 1 TB] # NTFS
D:\ -> CD-ROM
E:\ -> CD-ROM
G:\ -> Removable drive # 4 Gb (4 Mb free - 100%) [] # FAT32
################## | El Desaparecido Section |
HKLM\SOFTWARE | Run : [IMSS] - "C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IMSS\PIconStartup.exe"
HKLM\SOFTWARE | Run : [USB3MON] - "C:\Program Files (x86)\Intel\Intel(R) USB 3.0 eXtensible Host Controller Driver\Application\iusb3mon.exe"
HKLM\SOFTWARE | Run : [StartCCC] - "C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" MSRun
HKLM\SOFTWARE | Run : [STCAgent] - "C:\Program Files (x86)\Splashtop\Splashtop Connect IE\STCAgent.exe"
HKLM\SOFTWARE | Run : [ZyngaGamesAgent] - "C:\Program Files (x86)\Splashtop\Splashtop Connect\ZyngaGamesAgent.exe"
HKLM\SOFTWARE | Run : [emsisoft anti-malware] - "C:\Program Files (x86)\Emsisoft Anti-Malware\a2guard.exe" /d=60
HKLM\SOFTWARE\wow6432Node | Run : [IMSS] - "C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IMSS\PIconStartup.exe"
HKLM\SOFTWARE\wow6432Node | Run : [USB3MON] - "C:\Program Files (x86)\Intel\Intel(R) USB 3.0 eXtensible Host Controller Driver\Application\iusb3mon.exe"
HKLM\SOFTWARE\wow6432Node | Run : [StartCCC] - "C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" MSRun
HKLM\SOFTWARE\wow6432Node | Run : [STCAgent] - "C:\Program Files (x86)\Splashtop\Splashtop Connect IE\STCAgent.exe"
HKLM\SOFTWARE\wow6432Node | Run : [ZyngaGamesAgent] - "C:\Program Files (x86)\Splashtop\Splashtop Connect\ZyngaGamesAgent.exe"
HKLM\SOFTWARE\wow6432Node | Run : [emsisoft anti-malware] - "C:\Program Files (x86)\Emsisoft Anti-Malware\a2guard.exe" /d=60
HKLM\SOFTWARE | RunOnce : [] -
HKLM\SOFTWARE\wow6432Node | RunOnce : [] -
HKU\S-1-5-19\SOFTWARE | Run : [Sidebar] - %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun
HKU\S-1-5-20\SOFTWARE | Run : [Sidebar] - %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun
HKU\S-1-5-21-774546196-2300074726-1560002794-1000\SOFTWARE | Run : [Sidebar] - C:\Program Files\Windows Sidebar\sidebar.exe /autoRun
HKU\S-1-5-21-774546196-2300074726-1560002794-1000\SOFTWARE | Run : [IDMan] - C:\Users\pc\Desktop\MIX\Internet Download Manager v6.11 Build 5-li0nh3art\crack\IDMan.exe /onboot
HKU\S-1-5-21-774546196-2300074726-1560002794-1000\SOFTWARE | Run : [Skype] - "C:\Program Files (x86)\Skype\Phone\Skype.exe" /minimized /regrun
HKU\S-1-5-21-774546196-2300074726-1560002794-1000\SOFTWARE | Run : [HydraVisionDesktopManager] - "C:\Program Files (x86)\ATI Technologies\HydraVision\HydraDM.exe"
HKU\S-1-5-19\SOFTWARE | RunOnce : [mctadmin] - C:\Windows\System32\mctadmin.exe
HKU\S-1-5-20\SOFTWARE | RunOnce : [mctadmin] - C:\Windows\System32\mctadmin.exe
################## | Stopped processes |
Stopped! C:\Program Files\Bitdefender\Antivirus Free Edition\gzserv.exe (948)
Stopped! C:\Program Files (x86)\Emsisoft Anti-Malware\a2service.exe (976)
Stopped! c:\Program Files\Microsoft Security Client\MsMpEng.exe (1168)
Stopped! C:\Windows\system32\atiesrxx.exe (1276)
Stopped! C:\Windows\system32\atieclxx.exe (1544)
Stopped! C:\Windows\system32\taskeng.exe (1440)
Stopped! C:\Windows\system32\taskhost.exe (1824)
Stopped! C:\Windows\System32\spoolsv.exe (1920)
Stopped! C:\Program Files\Bitdefender\Antivirus Free Edition\gziface.exe (2328)
Stopped! C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe (2364)
Stopped! C:\Program Files\Intel\iCLS Client\HeciServer.exe (2500)
Stopped! C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe (2544)
Stopped! C:\Program Files (x86)\Splashtop\Splashtop Connect\BackService.exe (2676)
Stopped! C:\Program Files (x86)\Splashtop\Splashtop Software Updater\SSUService.exe (2748)
Stopped! c:\Program Files\Microsoft Security Client\NisSrv.exe (2432)
Stopped! C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe (3264)
Stopped! C:\Program Files\Microsoft Security Client\msseces.exe (3272)
Stopped! C:\Program Files\Windows Sidebar\sidebar.exe (3300)
Stopped! C:\Users\pc\Desktop\MIX\Internet Download Manager v6.11 Build 5-li0nh3art\crack\IDMan.exe (3396)
Stopped! C:\Program Files (x86)\Skype\Phone\Skype.exe (3476)
Stopped! C:\Program Files (x86)\ATI Technologies\HydraVision\HydraDM.exe (3488)
Stopped! C:\Windows\System32\WUDFHost.exe (3560)
Stopped! C:\Windows\system32\SearchIndexer.exe (3580)
Stopped! C:\Program Files (x86)\Intel\Intel(R) USB 3.0 eXtensible Host Controller Driver\Application\iusb3mon.exe (3752)
Stopped! C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe (3760)
Stopped! C:\Program Files (x86)\Splashtop\Splashtop Connect\ZyngaGamesAgent.exe (3796)
Stopped! C:\Program Files (x86)\ATI Technologies\HydraVision\HydraDM64.exe (4076)
Stopped! C:\Program Files\Windows Media Player\wmpnetwk.exe (4700)
Stopped! C:\Program Files (x86)\Internet Explorer\IELowutil.exe (4680)
Stopped! C:\Program Files (x86)\Mozilla Firefox\firefox.exe (3516)
Stopped! C:\Program Files (x86)\Mozilla Firefox\plugin-container.exe (3908)
Stopped! C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerPlugin_11_6_602_180.exe (2540)
Stopped! C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe (4904)
Stopped! C:\Windows\system32\sppsvc.exe (4940)
Stopped! C:\Program Files (x86)\Intel\Extreme Tuning Utility\XtuService.exe (2724)
Stopped! C:\Program Files (x86)\Intel\Intel(R) Integrated Clock Controller Service\ICCProxy.exe (4892)
Stopped! C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe (1608)
Stopped! C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IMSS\PrivacyIconClient.exe (3632)
Stopped! C:\Windows\servicing\TrustedInstaller.exe (3728)
Stopped! C:\Windows\system32\taskhost.exe (4380)
Stopped! C:\Windows\system32\SearchProtocolHost.exe (3856)
################## | Files # Infected Folders |
Deleted ! G:\Removable Disk (4GB).lnk
Deleted ! G:\autorun.inf
(!) Temporary files deleted.
################## | Registry |
################## | Mountpoints2 |
################## | Listing |
[17/05/2012 - 20:42:27 | SHD ] C:\$Recycle.Bin
[26/03/2013 - 10:40:56 | RASHD ] C:\Autorun.inf
[25/03/2013 - 23:00:11 | D ] C:\Config.Msi
[05/11/2012 - 01:04:04 | D ] C:\Counter-Strike 1.6
[14/07/2009 - 06:08:56 | SHD ] C:\Documents and Settings
[01/03/2013 - 01:37:05 | D ] C:\fe97a3fd6027ba430357f7bc3390d1
[26/03/2013 - 12:56:00 | ASH | 6400323584] C:\hiberfil.sys
[17/05/2012 - 21:30:17 | D ] C:\Intel
[19/05/2012 - 00:52:43 | RHD ] C:\MSOCache
[26/03/2013 - 12:56:03 | ASH | 8533766144] C:\pagefile.sys
[14/07/2009 - 04:20:08 | D ] C:\PerfLogs
[26/03/2013 - 00:24:21 | D ] C:\Program Files
[26/03/2013 - 00:43:42 | D ] C:\Program Files (x86)
[26/03/2013 - 00:26:56 | HD ] C:\ProgramData
[17/05/2012 - 20:42:16 | SHD ] C:\Recovery
[26/03/2013 - 10:03:08 | SHD ] C:\System Volume Information
[25/03/2013 - 18:14:00 | D ] C:\Temp
[25/11/2012 - 20:43:40 | D ] C:\uninstall
[26/03/2013 - 13:02:55 | D ] C:\UsbFix
[26/03/2013 - 10:41:38 | N | 8797] C:\UsbFix [Clean 1] VALACH.txt
[26/03/2013 - 13:03:01 | A | 7997] C:\UsbFix [Clean 2] VALACH.txt
[26/03/2013 - 10:35:52 | N | 8112] C:\UsbFix [Scan 1] VALACH.txt
[17/05/2012 - 20:42:20 | D ] C:\Users
[19/05/2012 - 00:56:16 | D ] C:\VLAO
[25/03/2013 - 23:19:47 | D ] C:\Windows
[30/05/2012 - 21:16:44 | D ] C:\ZALOHA-184GB
[26/03/2013 - 11:18:20 | D ] G:\
[26/03/2013 - 11:18:22 | N | 2517] G:\~$WDNCFZK.FAT
[26/03/2013 - 11:18:22 | RASH | 3274] G:\desktop.ini
[26/03/2013 - 11:18:22 | RASH | 2517] G:\Thumbs.db
################## | Vaccin |
C:\Autorun.inf -> Vaccine created by UsbFix (El Desaparecido)
G:\Autorun.inf -> Vaccine created by UsbFix (El Desaparecido)
################## | E.O.F |
http://sosvirus.org |