Sie sind auf Seite 1von 3

############################## | UsbFix V 7.

155 | [Recherche]

Utilisateur: Admin (Administrateur) # TOUSHIBA-PC


Mis jour le 16/12/2013 par El Desaparecido - Team SosVirus
Lanc 16:45:53 | 27/10/2017

Site Web : http://www.usbfix.net


Forum : http://www.sosvirus.net/
Upload Malware : http://www.sosvirus.net/upload_malware.php
Contact : http://www.usbfix.net/contact/

PC: Intel (PT10F)


CPU: Intel(R) Celeron(R) CPU 1005M @ 1.90GHz
RAM -> [Total : 3971 | Free : 1447]
Bios: Insyde Corp.
Boot: Normal boot

OS: Microsoft Windows7 dition Intgrale (5.1.2600 64-Bit) Service Pack 2


WB: Windows Internet Explorer : 8.0.7601.17514
WB: Google Chrome : 61.0.3163.100
WB: Mozilla Firefox : 56.0

SC: Security Center Service [Enabled]


WU: Windows Update Service [Enabled]
AS: Windows Defender [Enabled | (!) Outdated]
AS: Windows Defender : 6.1.7600.16385 (win7_rtm.090713-1255)
FW: Windows FireWall Service [Enabled]

C:\ (%systemdrive%) -> Disque fixe # 111 Go (44 Go libre(s) - 39%) [Win7_64] # NTFS
D:\ -> Disque fixe # 355 Go (100 Go libre(s) - 28%) [] # NTFS
E:\ -> CD-ROM
G:\ -> Disque amovible # 2 Go (2 Go libre(s) - 100%) [] # FAT
H:\ -> CD-ROM

################## | Processus Actif |

C:\Windows\system32\csrss.exe (ID: 456 |ParentID: 448)


C:\Windows\system32\wininit.exe (ID: 536 |ParentID: 448)
C:\Windows\system32\csrss.exe (ID: 556 |ParentID: 528)
C:\Windows\system32\services.exe (ID: 604 |ParentID: 536)
C:\Windows\system32\lsass.exe (ID: 616 |ParentID: 536)
C:\Windows\system32\lsm.exe (ID: 624 |ParentID: 536)
C:\Windows\system32\winlogon.exe (ID: 684 |ParentID: 528)
C:\Windows\system32\svchost.exe (ID: 780 |ParentID: 604)
C:\Windows\system32\svchost.exe (ID: 884 |ParentID: 604)
C:\Windows\System32\svchost.exe (ID: 976 |ParentID: 604)
C:\Windows\System32\svchost.exe (ID: 1008 |ParentID: 604)
C:\Windows\system32\svchost.exe (ID: 300 |ParentID: 604)
C:\Windows\system32\svchost.exe (ID: 1072 |ParentID: 604)
C:\Windows\system32\igfxCUIService.exe (ID: 1124 |ParentID: 604)
C:\Windows\system32\svchost.exe (ID: 1260 |ParentID: 604)
C:\Windows\System32\spoolsv.exe (ID: 1396 |ParentID: 604)
C:\Windows\system32\svchost.exe (ID: 1448 |ParentID: 604)
C:\Program Files (x86)\Freemake\CaptureLib\CaptureLibService.exe (ID: 1748 |
ParentID: 604)
C:\Windows\system32\svchost.exe (ID: 1876 |ParentID: 604)
C:\Program Files\Common Files\Microsoft
Shared\OfficeSoftwareProtectionPlatform\OSPPSVC.EXE (ID: 1708 |ParentID: 604)
C:\Windows\system32\svchost.exe (ID: 1728 |ParentID: 604)
C:\Windows\system32\WUDFHost.exe (ID: 2196 |ParentID: 1008)
C:\Windows\system32\svchost.exe (ID: 2268 |ParentID: 604)
C:\Windows\system32\wbem\wmiprvse.exe (ID: 2512 |ParentID: 780)
C:\Windows\system32\taskhost.exe (ID: 2896 |ParentID: 604)
C:\Windows\system32\Dwm.exe (ID: 2972 |ParentID: 1008)
C:\Windows\Explorer.EXE (ID: 2988 |ParentID: 2956)
C:\Windows\Microsoft.Net\Framework64\v3.0\WPF\PresentationFontCache.exe (ID: 3008 |
ParentID: 604)
C:\Windows\system32\igfxEM.exe (ID: 1592 |ParentID: 2568)
C:\Windows\system32\igfxHK.exe (ID: 1568 |ParentID: 2568)
C:\Program Files (x86)\Internet Download Manager\IDMan.exe (ID: 2884 |ParentID:
2988)
C:\Program Files (x86)\SuperCopier2\SuperCopier2.exe (ID: 3000 |ParentID: 2988)
C:\Users\Admin\AppData\Local\FluxSoftware\Flux\flux.exe (ID: 2912 |ParentID: 2988)
C:\Program Files (x86)\USB Disk Security\USBGuard.exe (ID: 3124 |ParentID: 2616)
C:\Program Files (x86)\Real\RealPlayer\Update\realsched.exe (ID: 3132 |ParentID:
2616)
C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe (ID: 3144 |
ParentID: 2616)
C:\Program Files (x86)\USB Disk Security\USBGuard.exe (ID: 3152 |ParentID: 3124)
C:\Program Files (x86)\Elaborate Bytes\VirtualCloneDrive\VCDDaemon.exe (ID: 3164 |
ParentID: 2616)
C:\Program Files (x86)\Common Files\Freemake
Shared\ProductUpdater\ProductUpdater.exe (ID: 3184 |ParentID: 2616)
C:\Windows\system32\WUDFHost.exe (ID: 3276 |ParentID: 1008)
C:\Program Files (x86)\Google\Update\1.3.33.5\GoogleCrashHandler.exe (ID: 3368 |
ParentID: 2944)
C:\Program Files (x86)\Internet Download Manager\IEMonitor.exe (ID: 3604 |ParentID:
2884)
C:\Program Files (x86)\Google\Update\1.3.33.5\GoogleCrashHandler64.exe (ID: 3648 |
ParentID: 2944)
C:\Windows\system32\svchost.exe (ID: 3772 |ParentID: 604)
C:\Windows\system32\SearchIndexer.exe (ID: 4024 |ParentID: 604)
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (ID: 3704 |ParentID:
2988)
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (ID: 3712 |ParentID:
3704)
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (ID: 760 |ParentID:
3704)
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (ID: 600 |ParentID:
3704)
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (ID: 3868 |ParentID:
3704)
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (ID: 3844 |ParentID:
3704)
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (ID: 4108 |ParentID:
3704)
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (ID: 4184 |ParentID:
3704)
C:\Windows\System32\svchost.exe (ID: 4716 |ParentID: 604)
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (ID: 2184 |ParentID:
3704)
C:\Program Files (x86)\Common Files\Java\Java Update\jucheck.exe (ID: 4304 |
ParentID: 3144)
C:\Windows\explorer.exe (ID: 2412 |ParentID: 780)
C:\Windows\explorer.exe (ID: 496 |ParentID: 780)
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (ID: 2780 |ParentID:
3704)
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (ID: 1040 |ParentID:
3704)
C:\Windows\system32\taskmgr.exe (ID: 1184 |ParentID: 684)
C:\Windows\system32\SearchProtocolHost.exe (ID: 3476 |ParentID: 4024)
C:\Windows\system32\SearchFilterHost.exe (ID: 3992 |ParentID: 4024)
C:\Program Files (x86)\WinRAR\WinRAR.exe (ID: 5032 |ParentID: 3704)
C:\UsbFix\Go.exe (ID: 1872 |ParentID: 3620)
c:\program files\windows defender\MpCmdRun.exe (ID: 4804 |ParentID: 4244)

################## | Regedit Run |

04 - HKLM\SOFTWARE | Run : [Adobe Reader Speed Launcher] - "C:\Program Files


(x86)\Adobe\Reader 8.0\Reader\Reader_sl.exe"
04 - HKLM\SOFTWARE | Run : [USB Security] - C:\Program Files (x86)\USB Disk
Security\USBGuard.exe
04 - HKLM\SOFTWARE | Run : [TkBellExe] - "C:\Program Files
(x86)\Real\RealPlayer\update\realsched.exe" -osboot
04 - HKLM\SOFTWARE | Run : [SunJavaUpdateSched] - "C:\Program Files (x86)\Common
Files\Java\Java Update\jusched.exe"
04 - HKLM\SOFTWARE | Run : [VirtualCloneDrive] - "C:\Program Files (x86)\Elaborate
Bytes\VirtualCloneDrive\VCDDaemon.exe" /s
04 - HKLM\SOFTWARE | Run : [ProductUpdater] - C:\Program Files (x86)\Common
Files\Freemake Shared\ProductUpdater\ProductUpdater.exe
04 - HKLM\SOFTWARE\wow6432Node | Run : [Adobe Reader Speed Launcher] - "C:\Program
Files (x86)\Adobe\Reader 8.0\Reader\Reader_sl.exe"
04 - HKLM\SOFTWARE\wow6432Node | Run : [USB Security] - C:\Program Files (x86)\USB
Disk Security\USBGuard.exe
04 - HKLM\SOFTWARE\wow6432Node | Run : [TkBellExe] - "C:\Program Files
(x86)\Real\RealPlayer\update\realsched.exe" -osboot
04 - HKLM\SOFTWARE\wow6432Node | Run : [SunJavaUpdateSched] - "C:\Program Files
(x86)\Common Files\Java\Java Update\jusched.exe"
04 - HKLM\SOFTWARE\wow6432Node | Run : [VirtualCloneDrive] - "C:\Program Files
(x86)\Elaborate Bytes\VirtualCloneDrive\VCDDaemon.exe" /s
04 - HKLM\SOFTWARE\wow6432Node | Run : [ProductUpdater] - C:\Program Files
(x86)\Common Files\Freemake Shared\ProductUpdater\ProductUpdater.exe
04 - HKLM\SOFTWARE | RunOnce : [] -
04 - HKLM\SOFTWARE\wow6432Node | RunOnce : [] -
04 - HKU\S-1-5-19\SOFTWARE | Run : [Sidebar] - %ProgramFiles%\Windows
Sidebar\Sidebar.exe /autoRun
04 - HKU\S-1-5-20\SOFTWARE | Run : [Sidebar] - %ProgramFiles%\Windows
Sidebar\Sidebar.exe /autoRun
04 - HKU\S-1-5-21-1120469185-1882872183-1501346414-1000\SOFTWARE | Run :
[ultracopier] - "C:\Program Files (x86)\Supercopier\supercopier.exe"
04 - HKU\S-1-5-21-1120469185-1882872183-1501346414-1000\SOFTWARE | Run : [IDMan] -
C:\Program Files (x86)\Internet Download Manager\IDMan.exe /onboot
04 - HKU\S-1-5-21-1120469185-1882872183-1501346414-1000\SOFTWARE | Run :
[SuperCopier2.exe] - C:\Program Files (x86)\SuperCopier2\SuperCopier2.exe
04 - HKU\S-1-5-21-1120469185-1882872183-1501346414-1000\SOFTWARE | Run :
[SysinfY2X] - C:\WINDOWS\system32\cmd.exe /c start wscript /e:VBScript.Encode
%temp%\SysinfY2X.db
04 - HKU\S-1-5-21-1120469185-1882872183-1501346414-1000\SOFTWARE | Run : [f.lux] -
"C:\Users\Admin\AppData\Local\FluxSoftware\Flux\flux.exe" /noshow
04 - HKU\S-1-5-19\SOFTWARE | RunOnce : [mctadmin] -
C:\Windows\System32\mctadmin.exe
04 - HKU\S-1-5-20\SOFTWARE | RunOnce : [mctadmin] -
C:\Windows\System32\mctadmin.exe

################## | Recherche gnrique |

Das könnte Ihnen auch gefallen