Can't remove shortcut virus [Solved/Closed]

Al_Bo 3 Posts Monday November 11, 2013Registration date November 12, 2013 Last seen - Nov 11, 2013 at 04:28 PM - Latest reply: Ambucias 53195 Posts Monday February 1, 2010Registration dateModeratorStatus July 16, 2018 Last seen
- May 20, 2014 at 07:56 AM
Hi,

I have a shortcut virus on my flash drive.
I hev tried to follow http://ccm.net/forum/affich-488562-shortcut-virus-on-flash-drive
But the problem always comes back immediately after running "attrib -r ...".
I have also tried to completely wipe the dirve according to http://www.neowin.net/forum/topic/808732-i-want-to-erase-my-usb-flash-drive-completely/ using DISKPART. Again, the problem returns immediately after a new folder or file has been adden to the drive.

What can I do?


Thanks,

Al_Bo
See more 

7 replies

Best answer
Al_Bo 3 Posts Monday November 11, 2013Registration date November 12, 2013 Last seen - Nov 12, 2013 at 08:52 AM
3
Thank you
Hi,

Running in safe mode worked, the problem seems fixed. Thanks!


The log is

############################## | UsbFix V 7.150 | [Deletion]


User: Alex (Administrator) # ALEX-LAPTOP
Updated 08/11/2013 by El Desaparecido - Team SosVirus
Started at 14:30:33 | 12/11/2013

Website : http://www.en.usbfix.net
Forum : http://www.sosvirus.net/
Upload Malware : http://www.sosvirus.net/upload_malware.php
Contact : http://www.en.usbfix.net/contact/

PC: Sony Corporation (VAIO)
CPU: Intel(R) Core(TM) i3-2370M CPU @ 2.40GHz
RAM -> [Total : 4066 | Free : 2917]
Bios: Insyde Corp.
Boot: Fail-safe boot

OS: Microsoft Windows 7 Home Premium (6.1.7601 64-Bit) Service Pack 1
WB: Windows Internet Explorer : 10.0.9200.16721

SC: Security Center Service [Enabled]
WU: Windows Update Service [Enabled]
AS: Windows Defender [Enabled | Updated]
AS: Windows Defender : 6.1.7600.16385 (win7_rtm.090713-1255)
AS: Malwarebytes' Anti-Malware : 1.75.0001
FW: Windows FireWall Service [(!) Disabled]

C:\ (%systemdrive%) -> Fixed drive # 577 Gb (272 Mb free - 47%) [] # NTFS
D:\ -> CD-ROM
H:\ -> Removable drive # 15 Gb (15 Mb free - 100%) [] # FAT32

################## | Stopped processes |

Stopped! C:\Windows\Explorer.EXE (ID: 1032 |ParentID: 492)
Stopped! C:\Windows\system32\ctfmon.exe (ID: 1076 |ParentID: 1032)
Stopped! C:\Windows\system32\DllHost.exe (ID: 1332 |ParentID: 708)

################## | Regedit Run |

04 - HKLM\SOFTWARE | Run : [StartCCC] - "C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" MSRun
04 - HKLM\SOFTWARE | Run : [IAStorIcon] - C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe
04 - HKLM\SOFTWARE | Run : [USB3MON] - "C:\Program Files (x86)\Intel\Intel(R) USB 3.0 eXtensible Host Controller Driver\Application\iusb3mon.exe"
04 - HKLM\SOFTWARE | Run : [ISBMgr.exe] - "C:\Program Files (x86)\Sony\ISB Utility\ISBMgr.exe"
04 - HKLM\SOFTWARE | Run : [APSDaemon] - "C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe"
04 - HKLM\SOFTWARE | Run : [BrMfcWnd] - C:\Program Files (x86)\Brother\Brmfcmon\BrMfcWnd.exe /AUTORUN
04 - HKLM\SOFTWARE | Run : [ControlCenter3] - C:\Program Files (x86)\Brother\ControlCenter3\brctrcen.exe /autorun
04 - HKLM\SOFTWARE | Run : [Reader Library Launcher] - C:\Program Files (x86)\Sony\Reader\Data\bin\launcher\Reader Library Launcher.exe
04 - HKLM\SOFTWARE | Run : [Adobe Acrobat Speed Launcher] - "C:\Program Files (x86)\Adobe\Acrobat 9.0\Acrobat\Acrobat_sl.exe"
04 - HKLM\SOFTWARE | Run : [] -
04 - HKLM\SOFTWARE | Run : [Acrobat Assistant 8.0] - "C:\Program Files (x86)\Adobe\Acrobat 9.0\Acrobat\Acrotray.exe"
04 - HKLM\SOFTWARE | Run : [iTunesHelper] - "C:\Program Files (x86)\iTunes\iTunesHelper.exe"
04 - HKLM\SOFTWARE\wow6432Node | Run : [StartCCC] - "C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" MSRun
04 - HKLM\SOFTWARE\wow6432Node | Run : [IAStorIcon] - C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe
04 - HKLM\SOFTWARE\wow6432Node | Run : [USB3MON] - "C:\Program Files (x86)\Intel\Intel(R) USB 3.0 eXtensible Host Controller Driver\Application\iusb3mon.exe"
04 - HKLM\SOFTWARE\wow6432Node | Run : [ISBMgr.exe] - "C:\Program Files (x86)\Sony\ISB Utility\ISBMgr.exe"
04 - HKLM\SOFTWARE\wow6432Node | Run : [APSDaemon] - "C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe"
04 - HKLM\SOFTWARE\wow6432Node | Run : [BrMfcWnd] - C:\Program Files (x86)\Brother\Brmfcmon\BrMfcWnd.exe /AUTORUN
04 - HKLM\SOFTWARE\wow6432Node | Run : [ControlCenter3] - C:\Program Files (x86)\Brother\ControlCenter3\brctrcen.exe /autorun
04 - HKLM\SOFTWARE\wow6432Node | Run : [Reader Library Launcher] - C:\Program Files (x86)\Sony\Reader\Data\bin\launcher\Reader Library Launcher.exe
04 - HKLM\SOFTWARE\wow6432Node | Run : [Adobe Acrobat Speed Launcher] - "C:\Program Files (x86)\Adobe\Acrobat 9.0\Acrobat\Acrobat_sl.exe"
04 - HKLM\SOFTWARE\wow6432Node | Run : [] -
04 - HKLM\SOFTWARE\wow6432Node | Run : [Acrobat Assistant 8.0] - "C:\Program Files (x86)\Adobe\Acrobat 9.0\Acrobat\Acrotray.exe"
04 - HKLM\SOFTWARE\wow6432Node | Run : [iTunesHelper] - "C:\Program Files (x86)\iTunes\iTunesHelper.exe"
04 - HKLM\SOFTWARE | RunOnce : [] -
04 - HKLM\SOFTWARE\wow6432Node | RunOnce : [] -
04 - HKU\S-1-5-19\SOFTWARE | Run : [Sidebar] - %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun
04 - HKU\S-1-5-20\SOFTWARE | Run : [Sidebar] - %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun
04 - HKU\S-1-5-21-3503229905-3959933055-1343893597-1000\SOFTWARE | Run : [Google Update] - "C:\Users\Alex\AppData\Local\Google\Update\GoogleUpdate.exe" /c
04 - HKU\S-1-5-21-3503229905-3959933055-1343893597-1000\SOFTWARE | Run : [SkyDrive] - "C:\Users\Alex\AppData\Local\Microsoft\SkyDrive\SkyDrive.exe" /background
04 - HKU\S-1-5-21-3503229905-3959933055-1343893597-1000\SOFTWARE | Run : [RGSC] - C:\Program Files (x86)\Rockstar Games\Rockstar Games Social Club\RGSCLauncher.exe /silent
04 - HKU\S-1-5-21-3503229905-3959933055-1343893597-1000\SOFTWARE | Run : [iTunesHelper] - wscript.exe //B "C:\Users\Alex\AppData\Local\Temp\iTunesHelper.vbe"
04 - HKU\S-1-5-19\SOFTWARE | RunOnce : [mctadmin] - C:\Windows\System32\mctadmin.exe
04 - HKU\S-1-5-20\SOFTWARE | RunOnce : [mctadmin] - C:\Windows\System32\mctadmin.exe

################## | Generic Research |

Deleted ! C:\Users\Alex\AppData\Local\Temp\iTunesHelper.vbe
Deleted ! C:\Users\Alex\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\iTunesHelper.vbe
Deleted ! H:\iTunesHelper.vbe
Deleted ! H:\map.lnk

(!) Temporary files deleted.

################## | Reference of comparison MD5 |

Md5 : 32BEF3BB4B558ADE6CF41113628FC86D -> C:\Users\Alex\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\iTunesHelper.vbe
Md5 : 32BEF3BB4B558ADE6CF41113628FC86D -> C:\Users\Alex\AppData\Local\Temp\iTunesHelper.vbe
Md5 : B3FDF6E7B0AECD48CA7E4921773FB606 -> C:\Users\Alex\AppData\Local\Temp\7z920.exe
Md5 : 2AE9B37AC30676121F0029989DEC79DD -> H:\iTunesHelper.vbe
Md5 : 32BEF3BB4B558ADE6CF41113628FC86D -> C:\Users\Alex\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\iTunesHelper.vbe
Md5 : 32BEF3BB4B558ADE6CF41113628FC86D -> C:\Users\Alex\AppData\Local\Temp\iTunesHelper.vbe
Md5 : B3FDF6E7B0AECD48CA7E4921773FB606 -> C:\Users\Alex\AppData\Local\Temp\7z920.exe
Md5 : 32BEF3BB4B558ADE6CF41113628FC86D -> H:\iTunesHelper.vbe
Md5 : 32BEF3BB4B558ADE6CF41113628FC86D -> C:\Users\Alex\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\iTunesHelper.vbe
Md5 : 32BEF3BB4B558ADE6CF41113628FC86D -> C:\Users\Alex\AppData\Local\Temp\iTunesHelper.vbe
Md5 : 8EF632D044C361C08122A50A38797B35 -> H:\iTunesHelper.vbe
Md5 : 32BEF3BB4B558ADE6CF41113628FC86D -> C:\Users\Alex\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\iTunesHelper.vbe
Md5 : 32BEF3BB4B558ADE6CF41113628FC86D -> C:\Users\Alex\AppData\Local\Temp\iTunesHelper.vbe
Md5 : 32BEF3BB4B558ADE6CF41113628FC86D -> H:\iTunesHelper.vbe

################## | Comparison MD5 |


################## | Registry |

Deleted ! HKU\S-1-5-21-3503229905-3959933055-1343893597-1000\Software\Microsoft\Windows\CurrentVersion\Run|iTunesHelper
Deleted ! HKLM\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Run|iTunesHelper
Deleted ! HKU\S-1-5-21-3503229905-3959933055-1343893597-1000\Software\.\.\.\.\Mountpoints2\G

################## | Listing |

[07/09/2012 - 11:17:27 | SHD ] C:\$Recycle.Bin
[23/08/2013 - 14:49:35 | N | 1024] C:\.rnd
[12/05/2012 - 12:00:36 | D ] C:\Documentation
[14/07/2009 - 06:08:56 | SHD ] C:\Documents and Settings
[12/11/2013 - 14:29:28 | ASH | 3197915136] C:\hiberfil.sys
[12/05/2012 - 11:27:26 | D ] C:\Intel
[08/10/2012 - 13:17:30 | RHD ] C:\MSOCache
[12/11/2013 - 14:29:28 | ASH | 4263886848] C:\pagefile.sys
[14/07/2009 - 04:20:08 | D ] C:\PerfLogs
[11/11/2013 - 14:55:46 | D ] C:\Program Files
[11/11/2013 - 20:23:39 | D ] C:\Program Files (x86)
[11/11/2013 - 15:09:37 | HD ] C:\ProgramData
[03/05/2013 - 18:54:44 | D ] C:\Python33
[12/05/2012 - 11:30:55 | N | 2197] C:\RHDSetup.log
[25/08/2013 - 14:29:54 | D ] C:\SkyDriveTemp
[12/11/2013 - 14:12:16 | SHD ] C:\System Volume Information
[11/11/2013 - 23:34:02 | D ] C:\temp
[12/11/2013 - 14:44:45 | D ] C:\UsbFix
[12/11/2013 - 14:45:11 | A | 8631] C:\UsbFix [Clean 3] ALEX-LAPTOP.txt
[07/09/2012 - 11:15:07 | RD ] C:\Users
[12/05/2012 - 12:29:23 | D ] C:\VAIO Sample Contents
[07/09/2012 - 15:10:44 | D ] C:\watcom-1.3
[12/11/2013 - 14:29:28 | D ] C:\Windows
[11/11/2013 - 22:20:14 | D ] H:\map

################## | Vaccin |

H:\Autorun.inf -> Vaccine created by UsbFix (El Desaparecido)

################## | E.O.F | http://www.usbfix.net - http://www.sosvirus.net |

Thank you, Al_Bo 3

Something to say? Add comment

CCM has helped 1702 users this month

Ambucias 53195 Posts Monday February 1, 2010Registration dateModeratorStatus July 16, 2018 Last seen - Nov 11, 2013 at 04:31 PM
1
Thank you
Greetings Al_Bo

Very simple !

This type issue could be caused by a USB virus. It will spread to all of your USB memory devices and hard disk.

Here is a tool to remove the virus and vaccinate your USB against further viruses.


Download UsbFix (created by El Desaparecido) on your desktop.

http://ccm.net/download/download-24089-usbfix

If your antivirus gives an alert, ignore it and temporarily deactivate the antivirus.
Plug in your usb devices (Flash drive, pen drive. External HD etc...) don't open them.
Double click sur UsbFix.exe.

Click on deletion
.
Let the tool work.

Ambucias
Moderator/virus security contributor

At the end of the scan a report will show which you can copy and paste here..

The report is save at the root ( C:\UsbFix.txt ).

You can also vaccinate against any virus.
Al_Bo 3 Posts Monday November 11, 2013Registration date November 12, 2013 Last seen - Nov 12, 2013 at 03:30 AM
0
Thank you
Thanks for the reply,

USBFix invariably freezes at 26%, forcing me to reboot my computer.

This is the log file

############################## | UsbFix V 7.150 | [Deletion]


User: Alex (Administrator) # ALEX-LAPTOP
Updated 08/11/2013 by El Desaparecido - Team SosVirus
Started at 23:41:01 | 11/11/2013

Website : http://www.en.usbfix.net
Forum : http://www.sosvirus.net/
Upload Malware : http://www.sosvirus.net/upload_malware.php
Contact : http://www.en.usbfix.net/contact/

PC: Sony Corporation (VAIO)
CPU: Intel(R) Core(TM) i3-2370M CPU @ 2.40GHz
RAM -> [Total : 4066 | Free : 1757]
Bios: Insyde Corp.
Boot: Normal boot

OS: Microsoft Windows 7 Home Premium (6.1.7601 64-Bit) Service Pack 1
WB: Windows Internet Explorer : 10.0.9200.16721

SC: Security Center Service [Enabled]
WU: Windows Update Service [Enabled]
AS: Windows Defender [Enabled | Updated]
AS: Windows Defender : 6.1.7600.16385 (win7_rtm.090713-1255)
AS: Malwarebytes' Anti-Malware : 1.75.0001
FW: Windows FireWall Service [Enabled]

C:\ (%systemdrive%) -> Fixed drive # 577 Gb (272 Mb free - 47%) [] # NTFS
D:\ -> CD-ROM
E:\ -> CD-ROM
F:\ -> CD-ROM
H:\ -> Removable drive # 15 Gb (15 Mb free - 100%) [] # FAT32

################## | Stopped processes |

Stopped! C:\Windows\system32\atiesrxx.exe (ID: 980 |ParentID: 836)
Stopped! C:\Program Files\Tablet\Wacom\WTabletServicePro.exe (ID: 1364 |ParentID: 836)
Stopped! C:\Windows\system32\atieclxx.exe (ID: 1384 |ParentID: 980)
Stopped! C:\Windows\system32\WLANExt.exe (ID: 1628 |ParentID: 1124)
Stopped! C:\Windows\System32\spoolsv.exe (ID: 1736 |ParentID: 836)
Stopped! C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe (ID: 1912 |ParentID: 836)
Stopped! C:\Program Files (x86)\Bluetooth Suite\adminservice.exe (ID: 1956 |ParentID: 836)
Stopped! C:\Program Files\Bonjour\mDNSResponder.exe (ID: 1996 |ParentID: 836)
Stopped! c:\Program Files\Intel\iCLS Client\HeciServer.exe (ID: 2028 |ParentID: 836)
Stopped! C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\FWService\IntelMeFWService.exe (ID: 1340 |ParentID: 836)
Stopped! C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe (ID: 1492 |ParentID: 836)
Stopped! C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamscheduler.exe (ID: 1744 |ParentID: 836)
Stopped! C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe (ID: 1644 |ParentID: 836)
Stopped! C:\Program Files (x86)\Sony\VAIO Control Center\VESMgr.exe (ID: 2296 |ParentID: 836)
Stopped! C:\Program Files (x86)\Sony\VAIO Control Center\VESMgrSub.exe (ID: 2340 |ParentID: 2296)
Stopped! C:\Windows\system32\taskeng.exe (ID: 2380 |ParentID: 1184)
Stopped! C:\Windows\system32\taskeng.exe (ID: 2428 |ParentID: 1184)
Stopped! C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE (ID: 2548 |ParentID: 836)
Stopped! C:\Program Files (x86)\Bluetooth Suite\Ath_CoexAgent.exe (ID: 2572 |ParentID: 836)
Stopped! C:\Windows\System32\WUDFHost.exe (ID: 2984 |ParentID: 1124)
Stopped! C:\Program Files (x86)\Sony\VAIO Control Center\VESMgrSub.exe (ID: 3036 |ParentID: 2296)
Stopped! C:\Windows\servicing\TrustedInstaller.exe (ID: 1764 |ParentID: 836)
Stopped! C:\Windows\SysWOW64\DllHost.exe (ID: 2512 |ParentID: 964)
Stopped! C:\Windows\SysWOW64\DllHost.exe (ID: 3088 |ParentID: 964)
Stopped! C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamgui.exe (ID: 3332 |ParentID: 1644)
Stopped! C:\Windows\Explorer.EXE (ID: 3396 |ParentID: 3356)
Stopped! C:\Windows\system32\taskhost.exe (ID: 3424 |ParentID: 836)
Stopped! C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe (ID: 3740 |ParentID: 3396)
Stopped! C:\Program Files\Tablet\Wacom\Wacom_TabletUser.exe (ID: 3768 |ParentID: 1364)
Stopped! C:\Program Files (x86)\Bluetooth Suite\BtvStack.exe (ID: 3788 |ParentID: 3396)
Stopped! C:\Program Files\Tablet\Wacom\WacomHost.exe (ID: 3796 |ParentID: 1364)
Stopped! C:\Program Files (x86)\Bluetooth Suite\AthBtTray.exe (ID: 3840 |ParentID: 3396)
Stopped! C:\Program Files\Synaptics\SynTP\SynTPEnh.exe (ID: 3900 |ParentID: 3396)
Stopped! C:\Users\Alex\AppData\Local\Microsoft\SkyDrive\SkyDrive.exe (ID: 3996 |ParentID: 3396)
Stopped! C:\Windows\System32\wscript.exe (ID: 3232 |ParentID: 3396)
Stopped! C:\Windows\system32\taskeng.exe (ID: 3468 |ParentID: 1184)
Stopped! C:\Program Files (x86)\OpenOffice.org 3\program\soffice.exe (ID: 3352 |ParentID: 2256)
Stopped! C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe (ID: 3872 |ParentID: 2184)
Stopped! C:\Program Files\Tablet\Wacom\Wacom_Tablet.exe (ID: 3068 |ParentID: 3796)
Stopped! C:\Program Files (x86)\Intel\Intel(R) USB 3.0 eXtensible Host Controller Driver\Application\iusb3mon.exe (ID: 2472 |ParentID: 2184)
Stopped! C:\Program Files (x86)\Sony\ISB Utility\ISBMgr.exe (ID: 3228 |ParentID: 2184)
Stopped! C:\Program Files\Tablet\Wacom\Wacom_TouchUser.exe (ID: 3824 |ParentID: 1364)
Stopped! C:\Program Files (x86)\Brother\Brmfcmon\BrMfcWnd.exe (ID: 3656 |ParentID: 2184)
Stopped! C:\Program Files (x86)\OpenOffice.org 3\program\soffice.bin (ID: 3892 |ParentID: 3352)
Stopped! C:\Windows\system32\DllHost.exe (ID: 3252 |ParentID: 964)
Stopped! C:\Program Files (x86)\Sony\Reader\Data\bin\launcher\Reader Library Launcher.exe (ID: 3640 |ParentID: 2184)
Stopped! C:\Program Files (x86)\Adobe\Acrobat 9.0\Acrobat\acrobat_sl.exe (ID: 3200 |ParentID: 2184)
Stopped! C:\Program Files (x86)\Adobe\Acrobat 9.0\Acrobat\acrotray.exe (ID: 3552 |ParentID: 2184)
Stopped! C:\Program Files (x86)\iTunes\iTunesHelper.exe (ID: 3816 |ParentID: 2184)
Stopped! C:\Windows\system32\SearchIndexer.exe (ID: 1040 |ParentID: 836)
Stopped! C:\Program Files (x86)\Brother\ControlCenter3\brccMCtl.exe (ID: 3804 |ParentID: 4016)
Stopped! C:\Program Files\iPod\bin\iPodService.exe (ID: 5072 |ParentID: 836)
Stopped! C:\Windows\system32\SearchProtocolHost.exe (ID: 4232 |ParentID: 1040)
Stopped! C:\Program Files (x86)\Brother\Brmfcmon\BrMfcmon.exe (ID: 4920 |ParentID: 3656)
Stopped! C:\Program Files\Windows Media Player\wmpnetwk.exe (ID: 4280 |ParentID: 836)
Stopped! C:\PROGRAM FILES\SYNAPTICS\SYNTP\SYNTPHELPER.EXE (ID: 4268 |ParentID: 3952)
Stopped! C:\Program Files\Sony\VAIO Smart Network\VSNService.exe (ID: 4500 |ParentID: 836)
Stopped! C:\Program Files\Sony\VAIO Smart Network\VSNClient.exe (ID: 4372 |ParentID: 4500)
Stopped! C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\MOM.exe (ID: 5512 |ParentID: 3220)
Stopped! C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CCC.exe (ID: 5528 |ParentID: 5512)
Stopped! C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe (ID: 2160 |ParentID: 836)
Stopped! C:\Program Files (x86)\Realtek\Realtek PCIE Card Reader\RIconMan.exe (ID: 5892 |ParentID: 836)
Stopped! C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe (ID: 2224 |ParentID: 836)
Stopped! C:\Program Files\Sony\VAIO Care\VCPerfService.exe (ID: 2596 |ParentID: 836)
Stopped! C:\Program Files\Sony\VAIO Care\listener.exe (ID: 3608 |ParentID: 2596)
Stopped! C:\Windows\Microsoft.Net\Framework64\v3.0\WPF\PresentationFontCache.exe (ID: 3784 |ParentID: 836)
Stopped! C:\Windows\system32\sppsvc.exe (ID: 2184 |ParentID: 836)
Stopped! C:\Program Files (x86)\ArcSoft\Magic-i Visual Effects 2\uCamMonitor.exe (ID: 1344 |ParentID: 836)
Stopped! C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe (ID: 2212 |ParentID: 836)
Stopped! C:\Program Files\Sony\VAIO Care\VCSystemTray.exe (ID: 5492 |ParentID: 3468)
Stopped! C:\Program Files\Sony\VAIO Care\VCService.exe (ID: 2176 |ParentID: 836)
Stopped! C:\Program Files\Sony\VAIO Care\VCAgent.exe (ID: 4300 |ParentID: 2176)
Stopped! C:\Windows\System32\vds.exe (ID: 6040 |ParentID: 836)
Stopped! C:\Program Files\Sony\VAIO Update Common\VUAgent.exe (ID: 2084 |ParentID: 836)
Stopped! C:\Program Files\Sony\VAIO Care\VCAdmin.exe (ID: 5364 |ParentID: 2176)

################## | Regedit Run |

04 - HKLM\SOFTWARE | Run : [StartCCC] - "C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" MSRun
04 - HKLM\SOFTWARE | Run : [IAStorIcon] - C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe
04 - HKLM\SOFTWARE | Run : [USB3MON] - "C:\Program Files (x86)\Intel\Intel(R) USB 3.0 eXtensible Host Controller Driver\Application\iusb3mon.exe"
04 - HKLM\SOFTWARE | Run : [ISBMgr.exe] - "C:\Program Files (x86)\Sony\ISB Utility\ISBMgr.exe"
04 - HKLM\SOFTWARE | Run : [APSDaemon] - "C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe"
04 - HKLM\SOFTWARE | Run : [BrMfcWnd] - C:\Program Files (x86)\Brother\Brmfcmon\BrMfcWnd.exe /AUTORUN
04 - HKLM\SOFTWARE | Run : [ControlCenter3] - C:\Program Files (x86)\Brother\ControlCenter3\brctrcen.exe /autorun
04 - HKLM\SOFTWARE | Run : [Reader Library Launcher] - C:\Program Files (x86)\Sony\Reader\Data\bin\launcher\Reader Library Launcher.exe
04 - HKLM\SOFTWARE | Run : [Adobe Acrobat Speed Launcher] - "C:\Program Files (x86)\Adobe\Acrobat 9.0\Acrobat\Acrobat_sl.exe"
04 - HKLM\SOFTWARE | Run : [] -
04 - HKLM\SOFTWARE | Run : [Acrobat Assistant 8.0] - "C:\Program Files (x86)\Adobe\Acrobat 9.0\Acrobat\Acrotray.exe"
04 - HKLM\SOFTWARE | Run : [iTunesHelper] - "C:\Program Files (x86)\iTunes\iTunesHelper.exe"
04 - HKLM\SOFTWARE\wow6432Node | Run : [StartCCC] - "C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" MSRun
04 - HKLM\SOFTWARE\wow6432Node | Run : [IAStorIcon] - C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe
04 - HKLM\SOFTWARE\wow6432Node | Run : [USB3MON] - "C:\Program Files (x86)\Intel\Intel(R) USB 3.0 eXtensible Host Controller Driver\Application\iusb3mon.exe"
04 - HKLM\SOFTWARE\wow6432Node | Run : [ISBMgr.exe] - "C:\Program Files (x86)\Sony\ISB Utility\ISBMgr.exe"
04 - HKLM\SOFTWARE\wow6432Node | Run : [APSDaemon] - "C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe"
04 - HKLM\SOFTWARE\wow6432Node | Run : [BrMfcWnd] - C:\Program Files (x86)\Brother\Brmfcmon\BrMfcWnd.exe /AUTORUN
04 - HKLM\SOFTWARE\wow6432Node | Run : [ControlCenter3] - C:\Program Files (x86)\Brother\ControlCenter3\brctrcen.exe /autorun
04 - HKLM\SOFTWARE\wow6432Node | Run : [Reader Library Launcher] - C:\Program Files (x86)\Sony\Reader\Data\bin\launcher\Reader Library Launcher.exe
04 - HKLM\SOFTWARE\wow6432Node | Run : [Adobe Acrobat Speed Launcher] - "C:\Program Files (x86)\Adobe\Acrobat 9.0\Acrobat\Acrobat_sl.exe"
04 - HKLM\SOFTWARE\wow6432Node | Run : [] -
04 - HKLM\SOFTWARE\wow6432Node | Run : [Acrobat Assistant 8.0] - "C:\Program Files (x86)\Adobe\Acrobat 9.0\Acrobat\Acrotray.exe"
04 - HKLM\SOFTWARE\wow6432Node | Run : [iTunesHelper] - "C:\Program Files (x86)\iTunes\iTunesHelper.exe"
04 - HKLM\SOFTWARE | RunOnce : [] -
04 - HKLM\SOFTWARE\wow6432Node | RunOnce : [] -
04 - HKU\S-1-5-19\SOFTWARE | Run : [Sidebar] - %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun
04 - HKU\S-1-5-20\SOFTWARE | Run : [Sidebar] - %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun
04 - HKU\S-1-5-21-3503229905-3959933055-1343893597-1000\SOFTWARE | Run : [Google Update] - "C:\Users\Alex\AppData\Local\Google\Update\GoogleUpdate.exe" /c
04 - HKU\S-1-5-21-3503229905-3959933055-1343893597-1000\SOFTWARE | Run : [SkyDrive] - "C:\Users\Alex\AppData\Local\Microsoft\SkyDrive\SkyDrive.exe" /background
04 - HKU\S-1-5-21-3503229905-3959933055-1343893597-1000\SOFTWARE | Run : [RGSC] - C:\Program Files (x86)\Rockstar Games\Rockstar Games Social Club\RGSCLauncher.exe /silent
04 - HKU\S-1-5-21-3503229905-3959933055-1343893597-1000\SOFTWARE | Run : [iTunesHelper] - wscript.exe //B "C:\Users\Alex\AppData\Local\Temp\iTunesHelper.vbe"
04 - HKU\S-1-5-19\SOFTWARE | RunOnce : [mctadmin] - C:\Windows\System32\mctadmin.exe
04 - HKU\S-1-5-20\SOFTWARE | RunOnce : [mctadmin] - C:\Windows\System32\mctadmin.exe

################## | Generic Research |
Ambucias 53195 Posts Monday February 1, 2010Registration dateModeratorStatus July 16, 2018 Last seen - May 20, 2014 at 07:56 AM
You are totally welcome
Ambucias 53195 Posts Monday February 1, 2010Registration dateModeratorStatus July 16, 2018 Last seen - Nov 12, 2013 at 06:02 AM
0
Thank you
Try usbfix again but in safe mode
Ambucias 53195 Posts Monday February 1, 2010Registration dateModeratorStatus July 16, 2018 Last seen - Nov 12, 2013 at 04:22 PM
0
Thank you
You are totally welcome,

We eliminated the famous vbe virus.

Take care