Opinión sobre escaneo USBFIX
Resuelto
machpro57
Mensajes publicados
5
Estado
Miembro
-
Malekal_morte- Mensajes publicados 178136 Fecha de registro Estado Moderador, Colaborador de seguridad Última intervención -
Malekal_morte- Mensajes publicados 178136 Fecha de registro Estado Moderador, Colaborador de seguridad Última intervención -
Hola,
Habiendo descubierto, en mi unidad USB, un archivo oculto "Autorun.inf", y no habiendo podido eliminarlo con los consejos de su sitio, instalé USBFIX.EXE, ejecuté una búsqueda y obtuve el siguiente resultado que me gustaría someter a su opinión.
Gracias por su ayuda.
############################## | UsbFix V 7.150 | [Búsqueda]
Usuario: Guy (Administrador) # GUY-HP
Actualizado el 08/11/2013 por El Desaparecido - Team SosVirus
Ejecutado a las 09:59:29 | 10/11/2013
Sitio Web : https://www.usbfix.net/
Foro : https://www.sosvirus.net/
Subir Malware : http://www.sosvirus.net/upload_malware.php
Contacto : https://www.usb-antivirus.com/fr/contact/
PC: Hewlett-Packard (1656)
CPU: Intel(R) Core(TM) i7-2670QM CPU @ 2.20GHz
RAM -> [Total : 6092 | Libre : 3897]
Bios: Hewlett-Packard
Boot: Normal boot
SO: Microsoft Windows 7 Edición Starter Premium (6.1.7601 64-Bit) Service Pack 1
WB: Windows Internet Explorer : 10.0.9200.16721
WB: Mozilla Firefox : 25.0
SC: Security Center Service [Enabled]
WU: Windows Update Service [Enabled]
AV: Trend Micro Titanium Internet Security 2012 [(!) Disabled | Updated]
AS: Windows Defender : 6.1.7600.16385 (win7_rtm.090713-1255)
FW: Windows Firewall Service [Enabled]
C:\ (%systemdrive%) -> Disco fijo # 916 Go (804 Go libres - 88%) [] # NTFS
D:\ -> Disco fijo # 15 Go (2 Go libres - 11%) [RECOVERY] # NTFS
E:\ -> CD-ROM
F:\ -> Disco fijo # 99 Mo (84 Mo libres - 86%) [HP_TOOLS] # FAT32
G:\ -> Disco extraíble # 2 Go (2 Go libres - 99%) [] # FAT
################## | Proceso Activo |
C:\Windows\system32\csrss.exe (ID: 684 |ParentID: 676)
C:\Windows\system32\wininit.exe (ID: 756 |ParentID: 676)
C:\Windows\system32\csrss.exe (ID: 784 |ParentID: 768)
C:\Windows\system32\services.exe (ID: 824 |ParentID: 756)
C:\Windows\system32\lsass.exe (ID: 840 |ParentID: 756)
C:\Windows\system32\lsm.exe (ID: 848 |ParentID: 756)
C:\Windows\system32\svchost.exe (ID: 960 |ParentID: 824)
C:\Windows\system32\winlogon.exe (ID: 148 |ParentID: 768)
C:\Program Files (x86)\HP SimplePass 2011\TrueSuiteService.exe (ID: 520 |ParentID: 824)
C:\Windows\system32\svchost.exe (ID: 904 |ParentID: 824)
C:\Windows\system32\atiesrxx.exe (ID: 1068 |ParentID: 824)
C:\Windows\System32\svchost.exe (ID: 1100 |ParentID: 824)
C:\Windows\System32\svchost.exe (ID: 1132 |ParentID: 824)
C:\Windows\system32\svchost.exe (ID: 1160 |ParentID: 824)
C:\Windows\system32\svchost.exe (ID: 1184 |ParentID: 824)
C:\Program Files\IDT\WDM\STacSV64.exe (ID: 1212 |ParentID: 824)
C:\Windows\system32\Hpservice.exe (ID: 1620 |ParentID: 824)
C:\Windows\System32\WUDFHost.exe (ID: 1668 |ParentID: 1132)
C:\Windows\system32\atieclxx.exe (ID: 1740 |ParentID: 1068)
C:\Windows\system32\svchost.exe (ID: 1848 |ParentID: 824)
C:\Windows\system32\WLANExt.exe (ID: 1936 |ParentID: 1132)
C:\Windows\system32\conhost.exe (ID: 1944 |ParentID: 684)
C:\Windows\System32\spoolsv.exe (ID: 2020 |ParentID: 824)
C:\Windows\system32\svchost.exe (ID: 1440 |ParentID: 824)
C:\Windows\system32\svchost.exe (ID: 1456 |ParentID: 824)
C:\Program Files\Trend Micro\UniClient\UiFrmWrk\uiWatchDog.exe (ID: 2148 |ParentID: 2112)
C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe (ID: 2156 |ParentID: 824)
C:\Program Files\IDT\WDM\AESTSr64.exe (ID: 2192 |ParentID: 824)
C:\Program Files\Intel\BluetoothHS\BTHSAmpPalService.exe (ID: 2224 |ParentID: 824)
C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe (ID: 2260 |ParentID: 824)
C:\Program Files (x86)\Intel\Bluetooth\devmonsrv.exe (ID: 2372 |ParentID: 824)
C:\Program Files\Bonjour\mDNSResponder.exe (ID: 2408 |ParentID: 824)
C:\Windows\system32\svchost.exe (ID: 2428 |ParentID: 824)
C:\Program Files\Intel\BluetoothHS\BTHSSecurityMgr.exe (ID: 2464 |ParentID: 824)
C:\Program Files (x86)\Cobian Backup 11\cbVSCService11.exe (ID: 2508 |ParentID: 824)
C:\Program Files\Intel\WiFi\bin\EvtEng.exe (ID: 2628 |ParentID: 824)
C:\Windows\SysWOW64\ezSharedSvcHost.exe (ID: 2672 |ParentID: 824)
C:\Windows\system32\svchost.exe (ID: 2784 |ParentID: 824)
C:\Program Files\Hewlett-Packard\HP Client Services\HPClientServices.exe (ID: 2808 |ParentID: 824)
C:\Windows\SysWOW64\HP\HP Quick Launch\HPWMISVC.exe (ID: 2872 |ParentID: 824)
C:\Program Files (x86)\Realtek\Realtek PCIE Card Reader\RIconMan.exe (ID: 2920 |ParentID: 824)
C:\Program Files\Common Files\Intel\WirelessCommon\RegSrvc.exe (ID: 2996 |ParentID: 824)
C:\Windows\system32\svchost.exe (ID: 3020 |ParentID: 824)
C:\Program Files (x86)\TeamViewer\Version7\TeamViewer_Service.exe (ID: 2064 |ParentID: 824)
C:\Program Files (x86)\TomTom HOME 2\TomTomHOMEService.exe (ID: 1228 |ParentID: 824)
C:\Program Files (x86)\Western Digital\WD Drive Manager\WDDriveService.exe (ID: 1536 |ParentID: 824)
C:\Program Files (x86)\Western Digital\WD SmartWare\WDRulesEngine.exe (ID: 1524 |ParentID: 824)
C:\Windows\system32\taskeng.exe (ID: 3152 |ParentID: 1184)
C:\Windows\system32\taskhost.exe (ID: 3232 |ParentID: 824)
C:\Windows\system32\Dwm.exe (ID: 3292 |ParentID: 1132)
C:\Windows\Explorer.EXE (ID: 3332 |ParentID: 3244)
C:\Program Files (x86)\PenWes\penwes.exe (ID: 3436 |ParentID: 3152)
C:\Program Files (x86)\HP SimplePass 2011\TouchControl.exe (ID: 3444 |ParentID: 520)
C:\Program Files (x86)\HP SimplePass 2011\BioMonitor.exe (ID: 3484 |ParentID: 960)
C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE (ID: 3628 |ParentID: 824)
C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe (ID: 4292 |ParentID: 824)
C:\Program Files (x86)\Hewlett-Packard\HP Connection Manager\hpConnectionManager.exe (ID: 4464 |ParentID: 4736)
C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe (ID: 6308 |ParentID: 824)
C:\Windows\system32\sppsvc.exe (ID: 6492 |ParentID: 824)
C:\Windows\System32\svchost.exe (ID: 6372 |ParentID: 824)
C:\Program Files (x86)\Hewlett-Packard\HP Connection Manager\hpCMSrv.exe (ID: 7632 |ParentID: 824)
C:\Program Files (x86)\Mozilla Firefox\plugin-container.exe (ID: 8104 |ParentID: 5224)
C:\Windows\Microsoft.Net\Framework64\v3.0\WPF\PresentationFontCache.exe (ID: 7292 |ParentID: 824)
C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerPlugin_11_9_900_117.exe (ID: 5308 |ParentID: 8104)
C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerPlugin_11_9_900_117.exe (ID: 4620 |ParentID: 5308)
C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe (ID: 4760 |ParentID: 4548)
C:\Program Files (x86)\Renesas Electronics\USB 3.0 Host Controller Driver\Application\nusb3mon.exe (ID: 4784 |ParentID: 4548)
C:\Windows\system32\RunDll32.exe (ID: 1276 |ParentID: 3332)
C:\PROGRAM FILES\SYNAPTICS\SYNTP\SYNTPHELPER.EXE (ID: 4936 |ParentID: 4824)
C:\Program Files (x86)\Intel\Bluetooth mediasrv.exe (ID: 5060 |ParentID: 824)
C:\Program Files\Common Files\Intel\WirelessCommon\iFrmewrk.exe (ID: 4364 |ParentID: 3332)
C:\Program Files\IDT\WDM\sttray64.exe (ID: 4480 |ParentID: 3332)
C:\Program Files\HP\HP Photosmart 6510 series\Bin\ScanToPCActivationApp.exe (ID: 4520 |ParentID: 3332)
C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe (ID: 4760 |ParentID: 4548)
C:\Program Files (x86)\Renesas Electronics\USB 3.0 Host Controller Driver\Application\nusb3mon.exe (ID: 4784 |ParentID: 4548)
C:\Windows\system32\RunDll32.exe (ID: 1276 |ParentID: 3332)
C:\PROGRAM FILES\SYNAPTICS\SYNTP\SYNTPHELPER.EXE (ID: 4936 |ParentID: 4824)
C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe (ID: 4760 |ParentID: 4548)
C:\Program Files (x86)\Renesas Electronics\USB 3.0 Host Controller Driver\Application\nusb3mon.exe (ID: 4784 |ParentID: 4548)
C:\ Windows\System32\taskeng.exe (ID: 3152 |ParentID: 1184)
C:\Windows\system32\taskhost.exe (ID: 3232 |ParentID: 824)
C:\Windows\system32\Dwm.exe (ID: 3292 |ParentID: 1132)
C:\Windows\Explorer.EXE (ID: 3332 |ParentID: 3244)
C:\Program Files (x86)\PenWes\penwes.exe (ID: 3436 |ParentID: 3152)
C:\Program Files (x86)\HP SimplePass 2011\TouchControl.exe (ID: 3444 |ParentID: 520)
C:\Program Files (x86)\HP SimplePass 2011\BioMonitor.exe (ID: 3484 |ParentID: 960)
C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE (ID: 3628 |ParentID: 824)
C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe (ID: 4292 |ParentID: 824)
C:\Program Files (x86)\Hewlett-Packard\HP Connection Manager\hpConnectionManager.exe (ID: 4464 |ParentID: 4736)
C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe (ID: 6308 |ParentID: 824)
C:\Windows\system32\sppsvc.exe (ID: 6492 |ParentID: 824)
C:\Windows\System32\svchost.exe (ID: 6372 |ParentID: 824)
C:\Program Files (x86)\Hewlett-Packard\HP Connection Manager\hpCMSrv.exe (ID: 7632 |ParentID: 824)
C:\Program Files (x86)\Mozilla Firefox\plugin-container.exe (ID: 8104 |ParentID: 5224)
C:\Windows\Microsoft.Net\Framework64\v3.0\WPF\PresentationFontCache.exe (ID: 7292 |ParentID: 824)
C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerPlugin_11_9_900_117.exe (ID: 5308 |ParentID: 8104)
C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerPlugin_11_9_900_117.exe (ID: 4620 |ParentID: 5308)
C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe (ID: 4760 |ParentID: 4548)
C:\Program Files (x86)\Renesas Electronics\USB 3.0 Host Controller Driver\Application\nusb3mon.exe (ID: 4784 |ParentID: 4548)
C:\Windows\system32\RunDll32.exe (ID: 1276 |ParentID: 3332)
C:\PROGRAM FILES\SYNAPTICS\SYNTP\SYNTPHELPER.EXE (ID: 4936 |ParentID: 4824)
C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe (ID: 4760 |ParentID: 4548)
C:\Program Files (x86)\Renesas Electronics\USB 3.0 Host Controller Driver\Application\nusb3mon.exe (ID: 4784 |ParentID: 4548)
C:\Windows\system32\wbem\wmiprvse.exe (ID: 8008 |ParentID: 960)
C:\Program Files\HP\HP Photosmart 6510 series\bin\HPNetworkCommunicator.exe (ID: 4840 |ParentID: 1276)
C:\Program Files\HP\HP Photosmart 6510 series\Bin\HPNetworkCommunicator.exe (ID: 5572 |ParentID: 4520)
################## | Registre |
################## | Vaccinación |
(!) ¡Este ordenador no está vacunado!
################## | E.O.F | https://www.usbfix.net/ - https://www.sosvirus.net/ |
Habiendo descubierto, en mi unidad USB, un archivo oculto "Autorun.inf", y no habiendo podido eliminarlo con los consejos de su sitio, instalé USBFIX.EXE, ejecuté una búsqueda y obtuve el siguiente resultado que me gustaría someter a su opinión.
Gracias por su ayuda.
############################## | UsbFix V 7.150 | [Búsqueda]
Usuario: Guy (Administrador) # GUY-HP
Actualizado el 08/11/2013 por El Desaparecido - Team SosVirus
Ejecutado a las 09:59:29 | 10/11/2013
Sitio Web : https://www.usbfix.net/
Foro : https://www.sosvirus.net/
Subir Malware : http://www.sosvirus.net/upload_malware.php
Contacto : https://www.usb-antivirus.com/fr/contact/
PC: Hewlett-Packard (1656)
CPU: Intel(R) Core(TM) i7-2670QM CPU @ 2.20GHz
RAM -> [Total : 6092 | Libre : 3897]
Bios: Hewlett-Packard
Boot: Normal boot
SO: Microsoft Windows 7 Edición Starter Premium (6.1.7601 64-Bit) Service Pack 1
WB: Windows Internet Explorer : 10.0.9200.16721
WB: Mozilla Firefox : 25.0
SC: Security Center Service [Enabled]
WU: Windows Update Service [Enabled]
AV: Trend Micro Titanium Internet Security 2012 [(!) Disabled | Updated]
AS: Windows Defender : 6.1.7600.16385 (win7_rtm.090713-1255)
FW: Windows Firewall Service [Enabled]
C:\ (%systemdrive%) -> Disco fijo # 916 Go (804 Go libres - 88%) [] # NTFS
D:\ -> Disco fijo # 15 Go (2 Go libres - 11%) [RECOVERY] # NTFS
E:\ -> CD-ROM
F:\ -> Disco fijo # 99 Mo (84 Mo libres - 86%) [HP_TOOLS] # FAT32
G:\ -> Disco extraíble # 2 Go (2 Go libres - 99%) [] # FAT
################## | Proceso Activo |
C:\Windows\system32\csrss.exe (ID: 684 |ParentID: 676)
C:\Windows\system32\wininit.exe (ID: 756 |ParentID: 676)
C:\Windows\system32\csrss.exe (ID: 784 |ParentID: 768)
C:\Windows\system32\services.exe (ID: 824 |ParentID: 756)
C:\Windows\system32\lsass.exe (ID: 840 |ParentID: 756)
C:\Windows\system32\lsm.exe (ID: 848 |ParentID: 756)
C:\Windows\system32\svchost.exe (ID: 960 |ParentID: 824)
C:\Windows\system32\winlogon.exe (ID: 148 |ParentID: 768)
C:\Program Files (x86)\HP SimplePass 2011\TrueSuiteService.exe (ID: 520 |ParentID: 824)
C:\Windows\system32\svchost.exe (ID: 904 |ParentID: 824)
C:\Windows\system32\atiesrxx.exe (ID: 1068 |ParentID: 824)
C:\Windows\System32\svchost.exe (ID: 1100 |ParentID: 824)
C:\Windows\System32\svchost.exe (ID: 1132 |ParentID: 824)
C:\Windows\system32\svchost.exe (ID: 1160 |ParentID: 824)
C:\Windows\system32\svchost.exe (ID: 1184 |ParentID: 824)
C:\Program Files\IDT\WDM\STacSV64.exe (ID: 1212 |ParentID: 824)
C:\Windows\system32\Hpservice.exe (ID: 1620 |ParentID: 824)
C:\Windows\System32\WUDFHost.exe (ID: 1668 |ParentID: 1132)
C:\Windows\system32\atieclxx.exe (ID: 1740 |ParentID: 1068)
C:\Windows\system32\svchost.exe (ID: 1848 |ParentID: 824)
C:\Windows\system32\WLANExt.exe (ID: 1936 |ParentID: 1132)
C:\Windows\system32\conhost.exe (ID: 1944 |ParentID: 684)
C:\Windows\System32\spoolsv.exe (ID: 2020 |ParentID: 824)
C:\Windows\system32\svchost.exe (ID: 1440 |ParentID: 824)
C:\Windows\system32\svchost.exe (ID: 1456 |ParentID: 824)
C:\Program Files\Trend Micro\UniClient\UiFrmWrk\uiWatchDog.exe (ID: 2148 |ParentID: 2112)
C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe (ID: 2156 |ParentID: 824)
C:\Program Files\IDT\WDM\AESTSr64.exe (ID: 2192 |ParentID: 824)
C:\Program Files\Intel\BluetoothHS\BTHSAmpPalService.exe (ID: 2224 |ParentID: 824)
C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe (ID: 2260 |ParentID: 824)
C:\Program Files (x86)\Intel\Bluetooth\devmonsrv.exe (ID: 2372 |ParentID: 824)
C:\Program Files\Bonjour\mDNSResponder.exe (ID: 2408 |ParentID: 824)
C:\Windows\system32\svchost.exe (ID: 2428 |ParentID: 824)
C:\Program Files\Intel\BluetoothHS\BTHSSecurityMgr.exe (ID: 2464 |ParentID: 824)
C:\Program Files (x86)\Cobian Backup 11\cbVSCService11.exe (ID: 2508 |ParentID: 824)
C:\Program Files\Intel\WiFi\bin\EvtEng.exe (ID: 2628 |ParentID: 824)
C:\Windows\SysWOW64\ezSharedSvcHost.exe (ID: 2672 |ParentID: 824)
C:\Windows\system32\svchost.exe (ID: 2784 |ParentID: 824)
C:\Program Files\Hewlett-Packard\HP Client Services\HPClientServices.exe (ID: 2808 |ParentID: 824)
C:\Windows\SysWOW64\HP\HP Quick Launch\HPWMISVC.exe (ID: 2872 |ParentID: 824)
C:\Program Files (x86)\Realtek\Realtek PCIE Card Reader\RIconMan.exe (ID: 2920 |ParentID: 824)
C:\Program Files\Common Files\Intel\WirelessCommon\RegSrvc.exe (ID: 2996 |ParentID: 824)
C:\Windows\system32\svchost.exe (ID: 3020 |ParentID: 824)
C:\Program Files (x86)\TeamViewer\Version7\TeamViewer_Service.exe (ID: 2064 |ParentID: 824)
C:\Program Files (x86)\TomTom HOME 2\TomTomHOMEService.exe (ID: 1228 |ParentID: 824)
C:\Program Files (x86)\Western Digital\WD Drive Manager\WDDriveService.exe (ID: 1536 |ParentID: 824)
C:\Program Files (x86)\Western Digital\WD SmartWare\WDRulesEngine.exe (ID: 1524 |ParentID: 824)
C:\Windows\system32\taskeng.exe (ID: 3152 |ParentID: 1184)
C:\Windows\system32\taskhost.exe (ID: 3232 |ParentID: 824)
C:\Windows\system32\Dwm.exe (ID: 3292 |ParentID: 1132)
C:\Windows\Explorer.EXE (ID: 3332 |ParentID: 3244)
C:\Program Files (x86)\PenWes\penwes.exe (ID: 3436 |ParentID: 3152)
C:\Program Files (x86)\HP SimplePass 2011\TouchControl.exe (ID: 3444 |ParentID: 520)
C:\Program Files (x86)\HP SimplePass 2011\BioMonitor.exe (ID: 3484 |ParentID: 960)
C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE (ID: 3628 |ParentID: 824)
C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe (ID: 4292 |ParentID: 824)
C:\Program Files (x86)\Hewlett-Packard\HP Connection Manager\hpConnectionManager.exe (ID: 4464 |ParentID: 4736)
C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe (ID: 6308 |ParentID: 824)
C:\Windows\system32\sppsvc.exe (ID: 6492 |ParentID: 824)
C:\Windows\System32\svchost.exe (ID: 6372 |ParentID: 824)
C:\Program Files (x86)\Hewlett-Packard\HP Connection Manager\hpCMSrv.exe (ID: 7632 |ParentID: 824)
C:\Program Files (x86)\Mozilla Firefox\plugin-container.exe (ID: 8104 |ParentID: 5224)
C:\Windows\Microsoft.Net\Framework64\v3.0\WPF\PresentationFontCache.exe (ID: 7292 |ParentID: 824)
C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerPlugin_11_9_900_117.exe (ID: 5308 |ParentID: 8104)
C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerPlugin_11_9_900_117.exe (ID: 4620 |ParentID: 5308)
C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe (ID: 4760 |ParentID: 4548)
C:\Program Files (x86)\Renesas Electronics\USB 3.0 Host Controller Driver\Application\nusb3mon.exe (ID: 4784 |ParentID: 4548)
C:\Windows\system32\RunDll32.exe (ID: 1276 |ParentID: 3332)
C:\PROGRAM FILES\SYNAPTICS\SYNTP\SYNTPHELPER.EXE (ID: 4936 |ParentID: 4824)
C:\Program Files (x86)\Intel\Bluetooth mediasrv.exe (ID: 5060 |ParentID: 824)
C:\Program Files\Common Files\Intel\WirelessCommon\iFrmewrk.exe (ID: 4364 |ParentID: 3332)
C:\Program Files\IDT\WDM\sttray64.exe (ID: 4480 |ParentID: 3332)
C:\Program Files\HP\HP Photosmart 6510 series\Bin\ScanToPCActivationApp.exe (ID: 4520 |ParentID: 3332)
C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe (ID: 4760 |ParentID: 4548)
C:\Program Files (x86)\Renesas Electronics\USB 3.0 Host Controller Driver\Application\nusb3mon.exe (ID: 4784 |ParentID: 4548)
C:\Windows\system32\RunDll32.exe (ID: 1276 |ParentID: 3332)
C:\PROGRAM FILES\SYNAPTICS\SYNTP\SYNTPHELPER.EXE (ID: 4936 |ParentID: 4824)
C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe (ID: 4760 |ParentID: 4548)
C:\Program Files (x86)\Renesas Electronics\USB 3.0 Host Controller Driver\Application\nusb3mon.exe (ID: 4784 |ParentID: 4548)
C:\ Windows\System32\taskeng.exe (ID: 3152 |ParentID: 1184)
C:\Windows\system32\taskhost.exe (ID: 3232 |ParentID: 824)
C:\Windows\system32\Dwm.exe (ID: 3292 |ParentID: 1132)
C:\Windows\Explorer.EXE (ID: 3332 |ParentID: 3244)
C:\Program Files (x86)\PenWes\penwes.exe (ID: 3436 |ParentID: 3152)
C:\Program Files (x86)\HP SimplePass 2011\TouchControl.exe (ID: 3444 |ParentID: 520)
C:\Program Files (x86)\HP SimplePass 2011\BioMonitor.exe (ID: 3484 |ParentID: 960)
C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE (ID: 3628 |ParentID: 824)
C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe (ID: 4292 |ParentID: 824)
C:\Program Files (x86)\Hewlett-Packard\HP Connection Manager\hpConnectionManager.exe (ID: 4464 |ParentID: 4736)
C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe (ID: 6308 |ParentID: 824)
C:\Windows\system32\sppsvc.exe (ID: 6492 |ParentID: 824)
C:\Windows\System32\svchost.exe (ID: 6372 |ParentID: 824)
C:\Program Files (x86)\Hewlett-Packard\HP Connection Manager\hpCMSrv.exe (ID: 7632 |ParentID: 824)
C:\Program Files (x86)\Mozilla Firefox\plugin-container.exe (ID: 8104 |ParentID: 5224)
C:\Windows\Microsoft.Net\Framework64\v3.0\WPF\PresentationFontCache.exe (ID: 7292 |ParentID: 824)
C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerPlugin_11_9_900_117.exe (ID: 5308 |ParentID: 8104)
C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerPlugin_11_9_900_117.exe (ID: 4620 |ParentID: 5308)
C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe (ID: 4760 |ParentID: 4548)
C:\Program Files (x86)\Renesas Electronics\USB 3.0 Host Controller Driver\Application\nusb3mon.exe (ID: 4784 |ParentID: 4548)
C:\Windows\system32\RunDll32.exe (ID: 1276 |ParentID: 3332)
C:\PROGRAM FILES\SYNAPTICS\SYNTP\SYNTPHELPER.EXE (ID: 4936 |ParentID: 4824)
C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe (ID: 4760 |ParentID: 4548)
C:\Program Files (x86)\Renesas Electronics\USB 3.0 Host Controller Driver\Application\nusb3mon.exe (ID: 4784 |ParentID: 4548)
C:\Windows\system32\wbem\wmiprvse.exe (ID: 8008 |ParentID: 960)
C:\Program Files\HP\HP Photosmart 6510 series\bin\HPNetworkCommunicator.exe (ID: 4840 |ParentID: 1276)
C:\Program Files\HP\HP Photosmart 6510 series\Bin\HPNetworkCommunicator.exe (ID: 5572 |ParentID: 4520)
################## | Registre |
################## | Vaccinación |
(!) ¡Este ordenador no está vacunado!
################## | E.O.F | https://www.usbfix.net/ - https://www.sosvirus.net/ |
8 respuestas
-
Hola,
Haz la suppressión y da el informe.
--
Como el ángel que eres, te ríes creando una ligereza en mi pecho,
Tus ojos me atraviesan,
(Tu respuesta siempre es 'quizás')
Entonces me levanté y me fui -
Aquí está:
############################## | UsbFix V 7.150 | [Eliminación]
Usuario: Guy (Administrador) # GUY-HP
Actualizado el 08/11/2013 por El Desaparecido - Team SosVirus
Lanzado a las 10:54:13 | 10/11/2013
Sitio Web : https://www.usbfix.net/
Foro : https://www.sosvirus.net/
Subir Malware : http://www.sosvirus.net/upload_malware.php
Contacto : https://www.usb-antivirus.com/fr/contact/
PC: Hewlett-Packard (1656)
CPU: Intel(R) Core(TM) i7-2670QM CPU @ 2.20GHz
RAM -> [Total: 6092 | Libre: 4336]
Bios: Hewlett-Packard
Boot: Inicio normal
SO: Microsoft Windows 7 Home Premium Edition (6.1.7601 64-Bit) Service Pack 1
WB: Windows Internet Explorer : 10.0.9200.16721
WB: Mozilla Firefox : 25.0
SC: Security Center Service [Enabled]
WU: Windows Update Service [Enabled]
AV: Trend Micro Titanium Internet Security 2012 [(!) Disabled | Updated]
AS: Windows Defender : 6.1.7600.16385 (win7_rtm.090713-1255)
FW: Windows Firewall Service [Enabled]
C:\ (%systemdrive%) -> Disco fijo # 916 Go (804 Go libres - 88%) [] # NTFS
D:\ -> Disco fijo # 15 Go (2 Go libres - 11%) [RECOVERY] # NTFS
E:\ -> CD-ROM
F:\ -> Disco fijo # 99 Mo (84 Mo libres - 86%) [HP_TOOLS] # FAT32
G:\ -> Disco extraíble # 2 Go (2 Go libres - 99%) [] # FAT
################## | Proceso Detenido |
Detenido! C:\Windows\explorer.exe (ID: 5460 |ParentID: 148)
Detenido! C:\Program Files (x86)\Western Digital\WD SmartWare\WDRulesEngine.exe (ID: 4156 |ParentID: 824)
Detenido! C:\Windows\System32\rundll32.exe (ID: 3604 |ParentID: 960)
Detenido! C:\Program Files (x86)\Western Digital\WD Drive Manager\WDDriveService.exe (ID: 3504 |ParentID: 824)
Detenido! C:\Program Files (x86)\Western Digital\WD SmartWare\WDBackupEngine.exe (ID: 6176 |ParentID: 824)
Detenido! C:\Windows\System32\WUDFHost.exe (ID: 3940 |ParentID: 1132)
Detenido! C:\Windows\Microsoft.Net\Framework64\v3.0\WPF\PresentationFontCache.exe (ID: 8184 |ParentID: 824)
Detenido! C:\Windows\system32\DllHost.exe (ID: 5360 |ParentID: 960)
Detenido! C:\Program Files (x86)\TeamViewer\Version7\TeamViewer_Service.exe (ID: 1216 |ParentID: 824)
Detenido! C:\Program Files\Intel\BluetoothHS\BTHSSecurityMgr.exe (ID: 1984 |ParentID: 824)
Detenido! C:\Windows\system32\SearchIndexer.exe (ID: 3112 |ParentID: 824)
Detenido! C:\Windows\System32\WLIDSVC.EXE (ID: 2156 |ParentID: 824)
Detenido! C:\Windows\System32\WLIDSvcM.exe (ID: 2320 |ParentID: 2156)
Detenido! C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe (ID: 2712 |ParentID: 824)
Detenido! C:\Program Files\Windows Media Player\wmpnetwk.exe (ID: 2500 |ParentID: 824)
Detenido! C:\Windows\System32\spoolsv.exe (ID: 2900 |ParentID: 824)
Detenido! C:\Program Files\Intel\BluetoothHS\BTHSAmpPalService.exe (ID: 2808 |ParentID: 824)
Detenido! C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe (ID: 2876 |ParentID: 824)
Detenido! C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\hpsa_service.exe (ID: 7140 |ParentID: 824)
Detenido! C:\Windows\system32\vssvc.exe (ID: 1988 |ParentID: 824)
Detenido! C:\Program Files\Trend Micro\UniClient\UiFrmWrk\uiWatchDog.exe (ID: 3440 |ParentID: 3136)
Detenido! C:\Program Files (x86)\Internet Explorer\IELowutil.exe (ID: 3592 |ParentID: 6676)
Detenido! C:\Windows\System32\WUDFHost.exe (ID: 7712 |ParentID: 1132)
Detenido! C:\Windows\system32\SearchProtocolHost.exe (ID: 5700 |ParentID: 3112)
Detenido! C:\Windows\system32\SearchFilterHost.exe (ID: 4536 |ParentID: 3112)
################## | Regedit Run |
04 - HKLM\SOFTWARE | Run : [IAStorIcon] - C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe
04 - HKLM\SOFTWARE | Run : [StartCCC] - "C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" MSRun
04 - HKLM\SOFTWARE | Run : [NUSB3MON] - "C:\Program Files (x86)\Renesas Electronics\USB 3.0 Host Controller Driver\Application\nusb3mon.exe"
04 - HKLM\SOFTWARE | Run : [HPConnectionManager] - C:\Program Files (x86)\Hewlett-Packard\HP Connection Manager\HPCMDelayStart.exe
04 - HKLM\SOFTWARE | Run : [Easybits Recovery] - C:\Program Files (x86)\EasyBits For Kids\ezRecover.exe
04 - HKLM\SOFTWARE | Run : [APSDaemon] - "C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe"
04 - HKLM\SOFTWARE | Run : [HPOSD] - C:\Program Files (x86)\Hewlett-Packard\HP On Screen Display\HPOSD.exe
04 - HKLM\SOFTWARE | Run : [WD Quick View] - C:\Program Files (x86)\Western Digital\WD Quick View\WDDMStatus.exe
04 - HKLM\SOFTWARE | Run : [Adobe ARM] - "C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
04 - HKLM\SOFTWARE | Run : [HP Quick Launch] - C:\Program Files (x86)\Hewlett-Packard\HP Quick Launch\HPMSGSVC.exe
04 - HKLM\SOFTWARE | Run : [HP Software Update] - C:\Program Files (x86)\Hp\HP Software Update\HPWuSchd2.exe
04 - HKLM\SOFTWARE | Run : [] -
04 - HKLM\SOFTWARE | Run : [QuickTime Task] - "C:\Program Files (x86)\QuickTime\QTTask.exe" -atboottime
04 - HKLM\SOFTWARE | Run : [iTunesHelper] - "C:\Program Files (x86)\iTunes\iTunesHelper.exe"
04 - HKLM\SOFTWARE | Run : [SunJavaUpdateSched] - "C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe"
04 - HKLM\SOFTWARE\wow6432Node | Run : [IAStorIcon] - C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe
04 - HKLM\SOFTWARE\wow6432Node | Run : [StartCCC] - "C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" MSRun
04 - HKLM\SOFTWARE\wow6432Node | Run : [NUSB3MON] - "C:\Program Files (x86)\Renesas Electronics\USB 3.0 Host Controller Driver\Application\nusb3mon.exe"
04 - HKLM\SOFTWARE\wow6432Node | Run : [HPConnectionManager] - C:\Program Files (x86)\Hewlett-Packard\HP Connection Manager\HPCMDelayStart.exe
04 - HKLM\SOFTWARE\wow6432Node | Run : [Easybits Recovery] - C:\Program Files (x86)\EasyBits For Kids\ezRecover.exe
04 - HKLM\SOFTWARE\wow6432Node | Run : [APSDaemon] - "C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe"
04 - HKLM\SOFTWARE\wow6432Node | Run : [HPOSD] - C:\Program Files (x86)\Hewlett-Packard\HP On Screen Display\HPOSD.exe
04 - HKLM\SOFTWARE\wow6432Node | Run : [WD Quick View] - C:\Program Files (x86)\Western Digital\WD Quick View\WDDMStatus.exe
04 - HKLM\SOFTWARE\wow6432Node | Run : [Adobe ARM] - "C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
04 - HKLM\SOFTWARE\wow6432Node | Run : [HP Quick Launch] - C:\Program Files (x86)\Hewlett-Packard\HP Quick Launch\HPMSGSVC.exe
04 - HKLM\SOFTWARE\wow6432Node | Run : [HP Software Update] - C:\Program Files (x86)\Hp\HP Software Update\HPWuSchd2.exe
04 - HKLM\SOFTWARE\wow6432Node | Run : [] -
04 - HKLM\SOFTWARE\wow6432Node | Run : [QuickTime Task] - "C:\Program Files (x86)\QuickTime\QTTask.exe" -atboottime
04 - HKLM\SOFTWARE\wow6432Node | Run : [iTunesHelper] - "C:\Program Files (x86)\iTunes\iTunesHelper.exe"
04 - HKLM\SOFTWARE\wow6432Node | Run : [SunJavaUpdateSched] - "C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe"
04 - HKLM\SOFTWARE | RunOnce : [] -
04 - HKLM\SOFTWARE\wow6432Node | RunOnce : [] -
04 - HKU\S-1-5-19\SOFTWARE | Run : [Sidebar] - %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun
04 - HKU\S-1-5-20\SOFTWARE | Run : [Sidebar] - %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun
04 - HKU\S-1-5-21-355231263-17124843-4200711193-1001\SOFTWARE | Run : [HP Photosmart 6510 series (NET)] - "C:\Program Files\HP\HP Photosmart 6510 series\Bin\ScanToPCActivationApp.exe" -deviceID "CN195421S205QB:NW" -scfn "HP Photosmart 6510 series (NET)" -AutoStart 1
04 - HKU\S-1-5-19\SOFTWARE | RunOnce : [mctadmin] - C:\Windows\System32\mctadmin.exe
04 - HKU\S-1-5-20\SOFTWARE | RunOnce : [mctadmin] - C:\Windows\System32\mctadmin.exe
################## | Recherche générique |
Supprimé! C:\Users\Guy\AppData\Local\Temp\Drives.vbs
D.E.S. ¿Supprimido! D:\desktop.ini
No eliminado ! G:\AUTORUN.INF
(!) Fichiers temporaires supprimés.
################## | Référence de comparación MD5 |
Md5 : AC8F18C5C595A5685FCEA46E61B6B5AF -> C:\Users\Guy\AppData\Local\Temp\Drives.vbs
################## | Comparaison MD5 |
################## | Registre |
Supprimé! HKU\S-1-5-21-355231263-17124843-4200711193-1001\Software\.\.\.\.\Mountpoints2\{1213b01d-9ead-11e1-8b62-ac72898c862d}
Supprimé! HKU\S-1-5-21-355231263-17124843-4200711193-1001\Software\.\.\.\.\Mountpoints2\{d3b9a0ca-6c65-11e1-98b2-ac72898c862d}
################## | Listing |
[23/01/2012 - 19:21:23 | SHD ] C:\$Recycle.Bin
[04/11/2012 - 16:10:39 | N | 2939] C:\AdwCleaner[R1].txt
[05/11/2012 - 18:06:18 | N | 2470] C:\AdwCleaner[R2].txt
[26/11/2012 - 21:57:00 | N | 1345] C:\AdwCleaner[R3].txt
[04/11/2012 - 16:13:24 | N | 2806] C:\AdwCleaner[S2].txt
[16/09/2013 - 06:41:34 | N | 0] C:\autoexec.bat
[22/06/2011 - 04:04:15 | SHD ] C:\boot
[21/11/2010 - 04:23:51 | RASH | 383786] C:\bootmgr
[14/10/2012 - 10:27:21 | N | 29542400] C:\CAPTURE.AVI
[20/10/2013 - 11:51:03 | SHD ] C:\Config.Msi
[14/07/2009 - 06:08:56 | SHD ] C:\Documents and Settings
[10/11/2013 - 09:51:37 | ASH | 4790833152] C:\hiberfil.sys
[09/09/2011 - 16:54:18 | D ] C:\HP
[22/01/2012 - 13:47:12 | D ] C:\HP_TOOLS_mountHPSF
[09/09/2011 - 16:33:31 | D ] C:\Intel
[15/03/2012 - 12:57:44 | D ] C:\MATS
[22/01/2012 - 17:50:59 | RHD ] C:\MSOCache
[10/11/2013 - 09:51:42 | ASH | 6387777536] C:\pagefile.sys
[14/07/2009 - 04:20:08 | D ] C:\PerfLogs
[05/10/2013 - 11:50:12 | D ] C:\Program Files
[09/11/2013 - 09:40:18 | D ] C:\Program Files (x86)
[19/10/2013 - 08:02:25 | HD ] C:\ProgramData
[21/01/2012 - 17:29:49 | SHD ] C:\Recovery
[16/09/2013 - 17:44:36 | D ] C:\sh4ldr
[28/05/2013 - 22:32:13 | D ] C:\SWSetup
[10/11/2013 - 10:53:48 | SHD ] C:\System Volume Information
[21/01/2012 - 17:29:55 | D ] C:\SYSTEM.SAV
[12/02/2012 - 17:13:00 | D ] C:\temp
[10/11/2013 - 10:57:04 | D ] C:\UsbFix
[10/11/2013 - 10:57:06 | A | 9949] C:\UsbFix [Clean 1] GUY-HP.txt
[10/11/2013 - 10:06:50 | N | 14801] C:\UsbFix [Scan 1] GUY-HP.txt
[21/01/2012 - 17:28:44 | RD ] C:\Users
[14/04/2012 - 11:42:05 | D ] C:\Western Digital
[14/10/2013 - 06:58:32 | D ] C:\Windows
[21/04/2012 - 13:30:20 | N | 11284] C:\WirelessDiagLog.csv
[18/04/2012 - 05:26:27 | D ] C:\_Exception1
[21/01/2012 - 17:33:10 | SHD ] D:\$RECYCLE.BIN
[21/01/2012 - 17:33:06 | RASHD ] D:\boot
[14/07/2009 - 19:39:00 | RASH | 383562] D:\bootmgr
[21/01/2012 - 17:33:06 | D ] D:\FactoryUpdate
[21/01/2012 - 17:33:06 | D ] D:\hp
[08/09/2012 - 10:54:31 | N | 8] D:\HP_WSD.dat
[21/01/2012 - 17:33:06 | RSHD ] D:\preload
[08/07/2013 - 16:06:09 | RSD ] D:\recovery
[10/02/2013 - 19:30:52 | N | 426] D:\RMCStatus.bin
[21/01/2012 - 17:33:06 | D ] D:\RM_Reserve
[21/07/2013 - 19:05:16 | SHD ] D:\System Volume Information
[09/09/2011 - 18:01:04 | SHD ] F:\$RECYCLE.BIN
[08/09/2012 - 11:54:32 | N | 8] F:\HP_WSD.dat
[29/05/2013 - 03:10:30 | D ] F:\Hewlett-Packard
[06/11/2013 - 16:18:02 | H | 16] G:\AUTORUN.INF
################## | Vaccinate |
(!) ¡Este ordenador no está vacunado!
################## | E.O.F | https://www.usbfix.net/ - https://www.sosvirus.net/ | -
voilà c'est nettoyé :)
--
Comme l'ange que tu es, tu ris en créant une légèreté dans ma poitrine,
Tes yeux me transpercent,
(Ta réponse est toujours 'peut-être')
C'est à ce moment-là que je me suis levé et suis parti -
Sin embargo, el archivo sigue presente en la memoria USB...
Gracias por su paciencia -
"Autorun.inf", el archivo, oculto en la llave "G:", que no estaba presente en esa llave antes de que me conectara en otro PC...
-
Hola,
Me permito una intrusión
[06/11/2013 - 16:18:02 | H | 16] G:\AUTORUN.INF
el archivo, oculto en la unidad "G:", que no estaba presente en esta unidad antes de que me conectara a otro PC...
El PC al que conectaste esta clave debía estar equipado con Panda UsbVaccine, por lo que el archivo autorun.inf es, por lo tanto, una vacuna y no un archivo infeccioso.
UsbFix no es capaz de indicar esta vacuna por el momento.
--
Desarrollador: UsbFix ## Webmaster: SosVirus
Como dijo Birdy -> People help the people -
-
:)
--
Comme l’ange que tu es, tu ris en créant une légèreté dans ma poitrine,
Tes yeux me traversent,
(Ta réponse est toujours 'peut-être')
C’est là que je me suis levé et suis parti