############################## | UsbFix V 7.134 | [Deletion]
User: robert (Administrator) # ROBERT-PC
Updated 06/09/2013 by El Desaparecido
Started at 10:19:24 | 29/12/2013
Website:
http://www.sosvirus.net/
Upload Malware:
http://www.sosvirus.net/upload_malware.php
Contact:
eldesaparecido@sosvirus.net
PC: ASUSTeK COMPUTER INC. (X101CH) (X86-based PC)
CPU: Intel(R) Atom(TM) CPU N2600 @ 1.60GHz (1600)
RAM -> [Total : 1012 | Free : 274]
BIOS: BIOS Date: 07/30/12 09:20:47 Ver: 04.06.05
BOOT: Normal boot
OS: Microsoft Windows 7 Starter (6.1.7601 32-Bit) # Service Pack 1
WB: Windows Internet Explorer 10.0.9200.16660
SC: Security Center Service [Enabled]
WU: Windows Update Service [Enabled]
AS: Windows Defender [Enabled | (!) Outdated]
FW: Windows FireWall Service [Enabled]
C:\ (%systemdrive%) -> Fixed drive # 298 Gb (218 Mb free - 73%) [Windows] # NTFS
D:\ -> Removable drive # 7 Gb (2 Mb free - 29%) [] # FAT32
################## | El Desaparecido Section |
HKLM\SOFTWARE | Run : [GfxServiceInstall] - C:\Windows\system32\GfxCUIServiceInstall.vbs
HKLM\SOFTWARE | Run : [IgfxTray] - C:\Windows\system32\igfxtray.exe
HKLM\SOFTWARE | Run : [HotKeysCmds] - C:\Windows\system32\hkcmd.exe
HKLM\SOFTWARE | Run : [Persistence] - C:\Windows\system32\igfxpers.exe
HKLM\SOFTWARE | Run : [RTHDVCPL] - C:\Program Files\Realtek\Audio\HDA\RtHDVCpl.exe -s
HKLM\SOFTWARE | Run : [SynTPEnh] - %ProgramFiles%\Synaptics\SynTP\SynTPEnh.exe
HKLM\SOFTWARE | Run : [HotkeyMon] - AsusSender.exe C:\Program Files\ASUS\HotkeyService\HotKeyMon.exe
HKLM\SOFTWARE | Run : [HotkeyService] - AsusSender.exe C:\Program Files\ASUS\HotkeyService\HotkeyService.exe
HKLM\SOFTWARE | Run : [CapsHook] - AsusSender.exe C:\Program Files\ASUS\CapsHook\CapsHook.exe
HKLM\SOFTWARE | Run : [SuperHybridEngine] - AsusSender.exe C:\Program Files\ASUS\SHE\SuperHybridEngine.exe
HKLM\SOFTWARE | Run : [LiveUpdate] - AsusSender.exe C:\Program Files\Asus\LiveUpdate\LiveUpdate.exe auto
HKLM\SOFTWARE | Run : [SynAsusAcpi] - %ProgramFiles%\Synaptics\SynTP\SynAsusAcpi.exe
HKLM\SOFTWARE | Run : [Adobe ARM] - "C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
HKLM\SOFTWARE | Run : [NtVdmSrv] - C:\Windows\inf\ntvdm.vbe
HKLM\SOFTWARE | RunOnce : [] -
HKU\S-1-5-19\SOFTWARE | Run : [Sidebar] - %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun
HKU\S-1-5-20\SOFTWARE | Run : [Sidebar] - %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun
HKU\S-1-5-21-2614108188-4201486478-1772553301-1000\SOFTWARE | Run : [rqcqyuxmeb] - wscript.exe //B "C:\Users\robert\AppData\Local\Temp\rqcqyuxmeb.vbs"
HKU\S-1-5-19\SOFTWARE | RunOnce : [mctadmin] - C:\Windows\System32\mctadmin.exe
HKU\S-1-5-20\SOFTWARE | RunOnce : [mctadmin] - C:\Windows\System32\mctadmin.exe
################## | Stopped processes |
Stopped! C:\Windows\system32\WLANExt.exe (1332)
Stopped! C:\Windows\System32\spoolsv.exe (1436)
Stopped! C:\Windows\system32\taskhost.exe (1620)
Stopped! C:\Program Files\Common Files\Adobe\ARM\1.0\armsvc.exe (1632)
Stopped! C:\Windows\system32\AsusService.exe (1680)
Stopped! C:\Windows\System32\igfxtray.exe (2200)
Stopped! C:\Windows\System32\hkcmd.exe (2220)
Stopped! C:\Windows\System32\igfxpers.exe (2260)
Stopped! C:\Windows\system32\igfxsrvc.exe (2288)
Stopped! C:\Program Files\Realtek\Audio\HDA\RtHDVCpl.exe (2300)
Stopped! C:\Program Files\Synaptics\SynTP\SynTPEnh.exe (2328)
Stopped! C:\Program Files\ASUS\HotkeyService\HotKeyMon.exe (2392)
Stopped! C:\Windows\system32\WUDFHost.exe (2400)
Stopped! C:\Program Files\ASUS\HotkeyService\HotkeyService.exe (2412)
Stopped! C:\Program Files\ASUS\CapsHook\CapsHook.exe (2512)
Stopped! C:\Program Files\ASUS\SHE\SuperHybridEngine.exe (2536)
Stopped! C:\Program Files\Synaptics\SynTP\SynAsusAcpi.exe (2548)
Stopped! C:\Program Files\Asus\LiveUpdate\LiveUpdate.exe (2624)
Stopped! C:\Windows\System32\wscript.exe (2756)
Stopped! C:\Windows\Microsoft.Net\Framework\v3.0\WPF\PresentationFontCache.exe (3140)
Stopped! C:\Windows\system32\SearchIndexer.exe (3424)
Stopped! C:\Program Files\Windows Media Player\wmpnetwk.exe (3544)
Stopped! C:\Program Files\Synaptics\SynTP\SynTPHelper.exe (3820)
Stopped! C:\Users\robert\AppData\Local\Google\Chrome\Application\chrome.exe (2272)
Stopped! C:\Users\robert\AppData\Local\Google\Chrome\Application\chrome.exe (2368)
Stopped! C:\Users\robert\AppData\Local\Google\Chrome\Application\chrome.exe (3228)
Stopped! C:\Windows\system32\SearchProtocolHost.exe (2420)
Stopped! C:\Windows\system32\SearchFilterHost.exe (1408)
Stopped! C:\Windows\system32\DllHost.exe (3748)
################## | Files # Infected Folders |
Deleted ! D:\rqcqyuxmeb.vbs
Deleted ! C:\Users\robert\AppData\Local\Temp\rqcqyuxmeb.vbs
Deleted ! D:\.lnk
Deleted ! D:\Jackass 1 Cz (J).lnk
Deleted ! D:\Jackass 2.lnk
Deleted ! D:\JACKASS-3.lnk
Deleted ! D:\Jackass-3-CZ.lnk
Deleted ! D:\pstfsvapsu.lnk
Deleted ! D:\default-capability.lnk
Deleted ! D:\customized-capability.lnk
Deleted ! C:\Users\robert\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\rqcqyuxmeb.vbs
Deleted ! D:\pstfsvapsu.vbs
(!) Temporary files deleted.
################## | Registry |
Deleted ! HKCU\Software\Microsoft\Windows\CurrentVersion\Run|rqcqyuxmeb
################## | Mountpoints2 |
################## | Listing |
[07/09/2013 - 11:05:55 | SHD ] C:\$Recycle.Bin
[10/06/2009 - 22:42:20 | N | 24] C:\autoexec.bat
[10/06/2009 - 22:42:20 | N | 10] C:\config.sys
[04/01/2013 - 09:21:08 | N | 37] C:\DevMgr.bat
[14/07/2009 - 05:53:55 | SHD ] C:\Documents and Settings
[08/09/2013 - 13:02:34 | N | 332] C:\fftrlog.txt
[29/09/2013 - 12:16:08 | D ] C:\filmy
[29/12/2013 - 09:54:15 | ASH | 795824128] C:\hiberfil.sys
[08/09/2013 - 12:51:25 | D ] C:\hudba
[22/07/2013 - 15:55:11 | D ] C:\Intel
[29/12/2013 - 09:54:18 | ASH | 1073741824] C:\pagefile.sys
[14/07/2009 - 03:37:05 | D ] C:\PerfLogs
[03/11/2013 - 08:18:04 | D ] C:\Program Files
[08/09/2013 - 15:31:24 | HD ] C:\ProgramData
[08/09/2013 - 13:27:08 | D ] C:\programy
[07/09/2013 - 11:03:49 | SHD ] C:\Recovery
[22/07/2013 - 16:06:18 | N | 2035] C:\RHDSetup.log
[22/07/2013 - 16:56:59 | D ] C:\RPKTools
[22/07/2013 - 16:54:49 | N | 273] C:\siw_debug.txt
[29/12/2013 - 10:19:13 | D ] C:\stah
[22/10/2013 - 16:51:32 | SHD ] C:\System Volume Information
[04/01/2013 - 09:21:08 | D ] C:\Tools
[29/12/2013 - 10:21:46 | D ] C:\UsbFix
[29/12/2013 - 10:22:41 | A | 6454] C:\UsbFix [Clean 1] ROBERT-PC.txt
[07/09/2013 - 11:05:02 | D ] C:\Users
[08/09/2013 - 13:45:05 | D ] C:\Windows
[25/11/2013 - 20:06:34 | D ] D:\LOST.DIR
[25/11/2013 - 20:06:36 | N | 12743] D:\default-capability.xml
[25/11/2013 - 20:06:38 | N | 145] D:\customized-capability.xml
[24/05/2013 - 12:24:00 | N | 112] D:\.~lock.Ústecký Kraj.odp#
[06/10/2013 - 15:07:24 | D ] D:\manowar 2002
[18/12/2012 - 21:06:40 | N | 768788480] D:\Jackass 1 Cz (J).avi
[18/12/2012 - 21:06:40 | N | 737134592] D:\Jackass 2.avi
[18/12/2012 - 21:06:40 | N | 729323520] D:\JACKASS-3.5-(2012)-akční,-komedie-CZ-DABING.avi
[18/12/2012 - 21:06:40 | N | 725897216] D:\Jackass-3-CZ.avi
################## | Vaccin |
C:\Autorun.inf -> Vaccine created by UsbFix (El Desaparecido)
D:\Autorun.inf -> Vaccine created by UsbFix (El Desaparecido)
################## | E.O.F |
http://www.sosvirus.net |