Voici le rapport apres le 1er plantage ce matin
############################## | UsbFix V8 bêta V 7.133 | [Suppression]
Utilisateur: Cléa (Administrateur) # PC-HP-DV5000
Mis à jour le 23/08/2013 par El Desaparecido g3n-h@ckm@n
Lancé à 10:33:53 | 06/09/2013
Site Web:
http://sosvirus.net/
Upload Malware:
http://sosvirus.net/viewtopic.php?f=6t=489
Contact:
eldesaparecido@sosvirus.net
PC: Hewlett-Packard (HP Pavilion dv5000 (RG009EA#ABF) ) (X86-based PC)
CPU: Genuine Intel(R) CPU T2050 @ 1.60GHz (1596)
RAM - [Total : 510 | Free : 345]
BIOS: Ver 1.00PARTTBL
BOOT: Fail-safe with network boot
OS: Microsoft Windows XP Édition familiale (5.1.2600 32-Bit) # Service Pack 3
WB: Windows Internet Explorer 8.0.6001.18702
SC: Security Center Service [Enabled]
WU: Windows Update Service [Enabled]
FW: Windows FireWall Service [Enabled]
C:\ (%systemdrive%) - Disque fixe # 66 Go (13 Go libre(s) - 19%) [] # NTFS
D:\ - Disque fixe # 7 Go (1 Go libre(s) - 18%) [HP_RECOVERY] # FAT32
############### | Drives
c:\ - Fixed # 68 GO ( Free : 13 Go) [] # NTFS
d:\ - Fixed # 7 GO ( Free : 1 Go) [HP_RECOVERY] # FAT32
################## | El Desaparecido Section |
HKLM\software | Run|[hpWirelessAssistant] : C:\Program Files\hpq\HP Wireless Assistant\HP Wireless Assistant.exe
HKLM\software | Run|[NvCplDaemon] : RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
HKLM\software | Run|[NvMediaCenter] : RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
HKLM\software | Run|[nwiz] : nwiz.exe /installquiet /nodetect
HKLM\software | Run|[High Definition Audio Property Page Shortcut] : CHDAudPropShortcut.exe
HKLM\software | Run|[SynTPEnh] : C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
HKLM\software | Run|[QPService] : "C:\Program Files\HP\QuickPlay\QPService.exe"
HKLM\software | Run|[HP Software Update] : C:\Program Files\Hp\HP Software Update\HPWuSchd2.exe
HKLM\software | Run|[QlbCtrl] : %ProgramFiles%\Hewlett-Packard\HP Quick Launch Buttons\QlbCtrl.exe /Start
HKLM\software | Run|[Cpqset] : C:\Program Files\HPQ\Default Settings\cpqset.exe
HKLM\software | Run|[RecGuard] : C:\Windows\SMINST\RecGuard.exe
HKLM\software | Run|[HP Component Manager] : "C:\Program Files\HP\hpcoretech\hpcmpmgr.exe"
HKLM\software | Run|[HPDJ Taskbar Utility] : C:\WINDOWS\system32\spool\drivers\w32x86\3\hpztsb10.exe
HKLM\software | Run|[Adobe ARM] : "C:\Program Files\Fichiers communs\Adobe\ARM\1.0\AdobeARM.exe"
HKLM\software | Run|[SunJavaUpdateSched] : "C:\Program Files\Fichiers communs\Java\Java Update\jusched.exe"
HKU\S-1-5-21-1744838932-353309017-3117134509-1006\software | Run|[Skype] : "C:\Program Files\Skype\Phone\Skype.exe" /minimized /regrun
HKU\S-1-5-21-1744838932-353309017-3117134509-1006\software | Run|[ctfmon.exe] : C:\WINDOWS\system32\ctfmon.exe
HKU\S-1-5-18\software | Run|[CTFMON.EXE] : C:\WINDOWS\system32\CTFMON.EXE
##### | Scan zones sensibles |
C:\Documents and Settings\Cléa\Local Settings\Application Data\Bron.tok.A12.em.bin
C:\Documents and Settings\Cléa\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
C:\Documents and Settings\Cléa\ntuser.ini
################## | Processus Stoppés |
(1852) -- explorer.exe
(2016) -- wmiprvse.exe
################## | Éléments infectieux |
(!) Fichiers temporaires supprimés.
################## | Réparations registre |
Réparé ! HKLM\Software\Microsoft\Internet Explorer\Main|[Default_search_url] :
http://go.microsoft.com/fwlink/?LinkId=54896 -
http://www.microsoft.com/isapi/redir.dl ... r=iesearch
Réparé ! HKLM\Software\Microsoft\Internet Explorer\Main|[Default_page_url] :
http://go.microsoft.com/fwlink/?LinkId=69157 -
http://www.microsoft.com/isapi/redir.dl ... ar=msnhome
Réparé ! HKLM\Software\Microsoft\Internet Explorer\Main|[Start page] :
http://go.microsoft.com/fwlink/?LinkId=69157 -
http://fr.msn.com/
Réparé ! HKCU\Software\Microsoft\Internet Explorer\Main|[Default_page_url] : -
http://www.microsoft.com/isapi/redir.dl ... ar=msnhome
Réparé ! HKCU\Software\Microsoft\Internet Explorer\Main|[Search bar] : -
http://go.microsoft.com/fwlink/?linkid=54896
Réparé ! HKCU\Software\Microsoft\Internet Explorer\Main|[Search page] :
http://www.microsoft.com/isapi/redir.dl ... r=iesearch -
http://go.microsoft.com/fwlink/?LinkId=54896
Réparé ! HKCU\Software\Microsoft\Internet Explorer\Main|[Window Title] : - Windows Internet Explorer
Réparé ! HKCU\Software\Microsoft\Internet Explorer\SearchScopes\${searchCLSID}|[URL] :
http://search.live.com/results.aspx?q={ ... orm=IE8SRC -
http://search.live.com/results.aspx?q={ ... rer:source?}
Réparé ! HKLM\System\ControlSet002\Control\SafeBoot|[AlternateShell] : - cmd.exe
################## | Winlogon User |
################## | Winlogon Machine |
################## | Registre |
Supprimé! HKLM\Software\Microsoft\Windows\CurrentVersion\Policies\System|DisableRegistryTools
################## | Mountpoints2 |
################## | Comparaison MD5 |
B2DE3452DE03674C6CEC68B8C8CE7C78 : C:\ntdetect.com
B2DE3452DE03674C6CEC68B8C8CE7C78 : C:\cmdcons\NTDETECT.COM
095F5574535284431BAB15F3AD4D3767 : C:\Documents and Settings\Cléa\Mes documents\Downloads\UsbFix (2).exe