Documenti di Didattica
Documenti di Professioni
Documenti di Cultura
165 | [Research]
User: ash (Administrator) # ASH-PC
Updated 20/02/2014 by El Desaparecido - Team SosVirus
Started at 09:17:09 | 21/03/2014
Website : http://www.en.usbfix.net/
Changelog : http://www.en.usbfix.net/changelog/
Support : http://www.sosvirus.net/
Upload Malware : http://www.sosvirus.net/upload_malware.php
Contact : http://www.en.usbfix.net/contact/
PC: SAMSUNG ELECTRONICS CO., LTD. (RV420/RV520/RV720/E3530/S3530)
CPU: Intel(R) Core(TM) i3-2310M CPU @ 2.10GHz
RAM -> [Total : 4011 Mo| Free : 2080 Mo]
Bios: Phoenix Technologies Ltd.
Boot: Normal boot
OS: Microsoft Windows 7 Home Premium (6.1.7601 64-Bit) Service Pack 1
WB: Windows Internet Explorer : 9.0.8112.16421
WB: Google Chrome : 33.0.1750.154
SC:
WU:
AV:
AV:
AV:
AS:
AS:
AS:
AS:
FW:
FW:
AS:
C:\
D:\
E:\
F:\
G:\
rentID: 2488)
C:\windows\splwow64.exe (ID: 6488 |ParentID: 3448)
C:\Program Files (x86)\CyberLink\Power2Go\CLMLSvc.exe (ID: 3524 |ParentID: 1892)
C:\windows\System32\svchost.exe (ID: 7424 |ParentID: 940)
C:\Program Files (x86)\CyberLink\Media+Player10\Media+Player10Serv.exe (ID: 7492
|ParentID: 1892)
C:\windows\system32\hkcmd.exe (ID: 7580 |ParentID: 1892)
C:\windows\system32\igfxtray.exe (ID: 8004 |ParentID: 1892)
C:\windows\system32\DllHost.exe (ID: 6764 |ParentID: 1072)
C:\Program Files\Common Files\Intel\WirelessCommon\iFrmewrk.exe (ID: 3832 |Paren
tID: 1892)
C:\Program Files (x86)\Samsung\Samsung Update Plus\SUPBackground.exe (ID: 5424 |
ParentID: 2488)
C:\Program Files\Intel\WiMAX\Bin\WiMAXCU.exe (ID: 6472 |ParentID: 1892)
C:\windows\system32\igfxpers.exe (ID: 7576 |ParentID: 1892)
C:\Program Files (x86)\SAMSUNG\EasySpeedUpManager\EasySpeedUpManager.exe (ID: 65
60 |ParentID: 2488)
C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe (
ID: 2152 |ParentID: 940)
C:\Program Files (x86)\Symantec\Norton Online Backup\NOBuAgent.exe (ID: 1812 |Pa
rentID: 940)
C:\windows\system32\wbem\unsecapp.exe (ID: 6348 |ParentID: 1072)
C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe (
ID: 7288 |ParentID: 940)
C:\Program Files (x86)\Microsoft Office\Office14\EXCEL.EXE (ID: 6624 |ParentID:
992)
C:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\
OSPPSVC.EXE (ID: 5952 |ParentID: 940)
################## | Regedit Run |
04 - HKCU\..\Run : [EPSON Stylus T10 Series] C:\windows\system32\spool\DRIVERS\x
64\3\E_IATIEBS.EXE /FU "C:\windows\TEMP\E_SC2D3.tmp" /EF "HKCU"
04 - HKCU\..\Run : [Messenger (Yahoo!)] "C:\PROGRA~2\Yahoo!\Messenger\YahooMesse
nger.exe" -quiet
04 - HKCU\..\Run : [EPSON L100 Series] C:\windows\system32\spool\DRIVERS\x64\3\E
_IATIGTP.EXE /FU "C:\windows\TEMP\E_S2941.tmp" /EF "HKCU"
04 - HKCU\..\Run : [MobileDocuments] C:\Program Files (x86)\Common Files\Apple\I
nternet Services\ubd.exe
04 - HKCU\..\Run : [iCloudServices] C:\Program Files (x86)\Common Files\Apple\In
ternet Services\iCloudServices.exe
04 - HKCU\..\Run : [ApplePhotoStreams] C:\Program Files (x86)\Common Files\Apple
\Internet Services\ApplePhotoStreams.exe
04 - HKCU\..\Run : [Facebook Update] "C:\Users\ash\AppData\Local\Facebook\Update
\FacebookUpdate.exe" /c /nocrashserver
04 - HKCU\..\Run : [GoogleDriveSync] "C:\Program Files (x86)\Google\Drive\google
drivesync.exe" /autostart
04 - HKCU\..\Run : [Skype] "C:\Program Files (x86)\Skype\Phone\Skype.exe" /minim
ized /regrun
04 - HKCU\..\Run : [EPLTarget\P0000000000000004] C:\windows\system32\spool\DRIVE
RS\x64\3\E_YATII2E.EXE /EPT "EPLTarget\P0000000000000004" /M "L210 Series"
04 - HKCU\..\Run : [AdobeBridge]
04 - HKCU\..\Run : [uTorrent] "C:\Users\ash\AppData\Roaming\uTorrent\uTorrent.ex
e" /MINIMIZED
04 - HKCU\..\Run : [EPLTarget\P0000000000000002] C:\windows\system32\spool\DRIVE
RS\x64\3\E_YATII2E.EXE /EPT "EPLTarget\P0000000000000002" /M "L210 Series" /EF "
HKCU"
04 - HKLM\..\Run : [AVG_TRAY] "C:\Program Files (x86)\AVG\AVG2012\avgtray.exe"
04 - HKLM\..\Run : [TkBellExe] "C:\Program Files (x86)\Real\RealPlayer\update\re
alsched.exe" -osboot