Oups effectivement je viens de remarquer que le rapport était incomplet, bon je te le poste de nouveau, ceci dit, impossible de vacciner, il me dit erreur durant la vaccination, donc je vais aller me jeter dans les bras de Morphée et remettre ça demain, parce que je ne ne comprend rien. merci pour ton aide et ta patience et bonne fin de soirée.
############################## | UsbFix V 7.144 | [Recherche]
Utilisateur: Pierre (Administrateur) # BASTOS
Mis à jour le 08/10/2013 par El Desaparecido - Team SosVirus
Lancé à 23:29:49 | 13/10/2013
Site Web:
http://www.usbfix.net/
Forum :
http://www.sosvirus.net/
Upload Malware:
http://www.sosvirus.net/upload_malware.php
Contact:
http://www.usbfix.net/contact/
PC: Packard Bell (Veriton M275 )
CPU: Pentium(R) Dual-Core CPU E5500 @ 2.80GHz
RAM - [Total : 4095 | Free : 2381]
Bios: American Megatrends Inc.
Boot: Normal boot
OS: Microsoft Windows 7 Édition Familiale Premium (6.1.7601 64-Bit) # Service Pack 1
WB: Windows Internet Explorer 10.0.9200.16721
SC: Security Center Service [Enabled]
WU: Windows Update Service [Enabled]
AV: avast! Antivirus [Enabled | Updated]
FW: Windows FireWall Service [Enabled]
C:\ (%systemdrive%) - Disque fixe # 455 Go (165 Go libre(s) - 36%) [Packard Bell] # NTFS
D:\ - Disque fixe # 455 Go (420 Go libre(s) - 92%) [DATA] # NTFS
E:\ - CD-ROM
################## | Processus Actif |
C:\Windows\system32\csrss.exe (ID 428 |ParentID 420)
C:\Windows\system32\wininit.exe (ID 488 |ParentID 420)
C:\Windows\system32\csrss.exe (ID 504 |ParentID 480)
C:\Windows\system32\services.exe (ID 552 |ParentID 488)
C:\Windows\system32\winlogon.exe (ID 576 |ParentID 480)
C:\Windows\system32\lsass.exe (ID 604 |ParentID 488)
C:\Windows\system32\lsm.exe (ID 612 |ParentID 488)
C:\Windows\system32\svchost.exe (ID 712 |ParentID 552)
C:\Windows\system32\nvvsvc.exe (ID 792 |ParentID 552)
C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe (ID 816 |ParentID 552)
C:\Windows\system32\svchost.exe (ID 848 |ParentID 552)
C:\Windows\System32\svchost.exe (ID 940 |ParentID 552)
C:\Windows\System32\svchost.exe (ID 996 |ParentID 552)
C:\Windows\system32\svchost.exe (ID 108 |ParentID 552)
C:\Windows\system32\svchost.exe (ID 328 |ParentID 552)
C:\Program Files (x86)\Common Files\logishrd\LVMVFM\UMVPFSrv.exe (ID 484 |ParentID 552)
C:\Windows\system32\svchost.exe (ID 1120 |ParentID 552)
C:\Program Files\Alwil Software\Avast5\AvastSvc.exe (ID 1184 |ParentID 552)
C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe (ID 1240 |ParentID 792)
C:\Windows\system32\nvvsvc.exe (ID 1248 |ParentID 792)
C:\Windows\System32\spoolsv.exe (ID 1528 |ParentID 552)
C:\Windows\system32\taskhost.exe (ID 1536 |ParentID 552)
C:\Windows\system32\Dwm.exe (ID 1584 |ParentID 996)
C:\Windows\system32\svchost.exe (ID 1636 |ParentID 552)
C:\Windows\Explorer.EXE (ID 1644 |ParentID 1552)
c:\Program Files (x86)\Adobe\Elements Organizer 8.0\PhotoshopElementsFileAgent.exe (ID 1904 |ParentID 552)
C:\Windows\system32\taskeng.exe (ID 1916 |ParentID 328)
C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe (ID 664 |ParentID 552)
C:\Windows\system32\taskeng.exe (ID 1080 |ParentID 328)
C:\Program Files\Windows Sidebar\sidebar.exe (ID 2060 |ParentID 1644)
C:\Program Files (x86)\Logitech\Vid HD\Vid.exe (ID 2204 |ParentID 1644)
C:\Program Files\Bonjour\mDNSResponder.exe (ID 2212 |ParentID 552)
C:\Windows\system32\svchost.exe (ID 2244 |ParentID 552)
C:\Program Files (x86)\Packard Bell\Registration\GregHSRW.exe (ID 2308 |ParentID 552)
C:\Program Files\Common Files\Logishrd\LVMVFM\LVPrcSrv.exe (ID 2372 |ParentID 552)
C:\Program Files (x86)\Sony\Sony PC Companion\PCCompanion.exe (ID 2420 |ParentID 1644)
C:\Program Files (x86)\Sony\Sony PC Companion\PCCompanionInfo.exe (ID 2496 |ParentID 2420)
C:\Program Files (x86)\Common Files\Logishrd\LVMVFM\LVPrS64H.exe (ID 2564 |ParentID 712)
C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamscheduler.exe (ID 2604 |ParentID 552)
C:\Program Files (x86)\Microsoft Office\Office12\ONENOTEM.EXE (ID 2748 |ParentID 1644)
C:\Program Files (x86)\Packard Bell\Hotkey Utility\HotkeyUtility.exe (ID 2772 |ParentID 2708)
C:\Program Files\Alwil Software\Avast5\AvastUI.exe (ID 2820 |ParentID 2708)
C:\Program Files (x86)\Logitech\LWS\Webcam Software\LWS.exe (ID 2884 |ParentID 2708)
C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe (ID 2124 |ParentID 2708)
C:\Program Files (x86)\iTunes\iTunesHelper.exe (ID 2168 |ParentID 2708)
C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe (ID 2144 |ParentID 552)
C:\Windows\System32\svchost.exe (ID 2188 |ParentID 552)
C:\Windows\System32\svchost.exe (ID 2160 |ParentID 552)
C:\Windows\system32\svchost.exe (ID 2580 |ParentID 552)
C:\Program Files\NVIDIA Corporation\Display\nvtray.exe (ID 1204 |ParentID 1240)
C:\Program Files\Packard Bell\Packard Bell Updater\UpdaterService.exe (ID 956 |ParentID 552)
C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamgui.exe (ID 2940 |ParentID 2144)
C:\Program Files (x86)\Logitech\LWS\Webcam Software\CameraHelperShell.exe (ID 2948 |ParentID 2884)
C:\Program Files (x86)\Common Files\Logishrd\LQCVFX\COCIManager.exe (ID 2720 |ParentID 712)
C:\Program Files\iPod\bin\iPodService.exe (ID 3428 |ParentID 552)
C:\Windows\system32\SearchIndexer.exe (ID 3844 |ParentID 552)
C:\Program Files (x86)\Packard Bell\Hotkey Utility\HotkeyUI.exe (ID 3364 |ParentID 2772)
C:\Windows\System32\WUDFHost.exe (ID 4052 |ParentID 996)
C:\Windows\System32\svchost.exe (ID 2304 |ParentID 552)
C:\Program Files\Windows Media Player\wmpnetwk.exe (ID 1524 |ParentID 552)
C:\Windows\system32\wbem\wmiprvse.exe (ID 2040 |ParentID 712)
C:\Users\Pierre\AppData\Local\Google\Chrome\Application\chrome.exe (ID 1264 |ParentID 1644)
C:\Users\Pierre\AppData\Local\Google\Chrome\Application\chrome.exe (ID 2872 |ParentID 1264)
C:\Users\Pierre\AppData\Local\Google\Chrome\Application\chrome.exe (ID 3460 |ParentID 1264)
C:\Users\Pierre\AppData\Local\Google\Chrome\Application\chrome.exe (ID 4208 |ParentID 1264)
C:\Users\Pierre\AppData\Local\Google\Chrome\Application\chrome.exe (ID 4828 |ParentID 1264)
C:\Windows\system32\taskhost.exe (ID 5068 |ParentID 552)
C:\UsbFix\Go.exe (ID 4368 |ParentID 4748)
C:\Windows\system32\wbem\wmiprvse.exe (ID 4760 |ParentID 712)
################## | Regedit Run |
HKLM\SOFTWARE | Run : [Hotkey Utility] - C:\Program Files (x86)\Packard Bell\Hotkey Utility\HotkeyUtility.exe
HKLM\SOFTWARE | Run : [NortonOnlineBackupReminder] - "C:\Program Files (x86)\Symantec\Norton Online Backup\Activation\NobuActivation.exe" UNATTENDED
HKLM\SOFTWARE | Run : [avast5] - "C:\Program Files\Alwil Software\Avast5\avastUI.exe" /nogui
HKLM\SOFTWARE | Run : [Adobe ARM] - "C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
HKLM\SOFTWARE | Run : [LWS] - C:\Program Files (x86)\Logitech\LWS\Webcam Software\LWS.exe -hide
HKLM\SOFTWARE | Run : [APSDaemon] - "C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe"
HKLM\SOFTWARE | Run : [] -
HKLM\SOFTWARE | Run : [SunJavaUpdateSched] - "C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe"
HKLM\SOFTWARE | Run : [iTunesHelper] - "C:\Program Files (x86)\iTunes\iTunesHelper.exe"
HKLM\SOFTWARE\wow6432Node | Run : [Hotkey Utility] - C:\Program Files (x86)\Packard Bell\Hotkey Utility\HotkeyUtility.exe
HKLM\SOFTWARE\wow6432Node | Run : [NortonOnlineBackupReminder] - "C:\Program Files (x86)\Symantec\Norton Online Backup\Activation\NobuActivation.exe" UNATTENDED
HKLM\SOFTWARE\wow6432Node | Run : [avast5] - "C:\Program Files\Alwil Software\Avast5\avastUI.exe" /nogui
HKLM\SOFTWARE\wow6432Node | Run : [Adobe ARM] - "C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
HKLM\SOFTWARE\wow6432Node | Run : [LWS] - C:\Program Files (x86)\Logitech\LWS\Webcam Software\LWS.exe -hide
HKLM\SOFTWARE\wow6432Node | Run : [APSDaemon] - "C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe"
HKLM\SOFTWARE\wow6432Node | Run : [] -
HKLM\SOFTWARE\wow6432Node | Run : [SunJavaUpdateSched] - "C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe"
HKLM\SOFTWARE\wow6432Node | Run : [iTunesHelper] - "C:\Program Files (x86)\iTunes\iTunesHelper.exe"
HKLM\SOFTWARE | RunOnce : [] -
HKLM\SOFTWARE\wow6432Node | RunOnce : [] -
HKU\S-1-5-19\SOFTWARE | Run : [Sidebar] - %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun
HKU\S-1-5-20\SOFTWARE | Run : [Sidebar] - %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun
HKU\S-1-5-21-2097648666-163629840-2645427609-1001\SOFTWARE | Run : [Sidebar] - C:\Program Files\Windows Sidebar\sidebar.exe /autoRun
HKU\S-1-5-21-2097648666-163629840-2645427609-1001\SOFTWARE | Run : [Google Update] - "C:\Users\Pierre\AppData\Local\Google\Update\GoogleUpdate.exe" /c
HKU\S-1-5-21-2097648666-163629840-2645427609-1001\SOFTWARE | Run : [Logitech Vid] - "C:\Program Files (x86)\Logitech\Vid HD\Vid.exe" -bootmode
HKU\S-1-5-21-2097648666-163629840-2645427609-1001\SOFTWARE | Run : [Sony PC Companion] - "C:\Program Files (x86)\Sony\Sony PC Companion\PCCompanion.exe" /Background
HKU\S-1-5-21-2097648666-163629840-2645427609-1001\SOFTWARE | Run : [Facebook Update] - "C:\Users\Pierre\AppData\Local\Facebook\Update\FacebookUpdate.exe" /c /nocrashserver
HKU\S-1-5-19\SOFTWARE | RunOnce : [mctadmin] - C:\Windows\System32\mctadmin.exe
HKU\S-1-5-20\SOFTWARE | RunOnce : [mctadmin] - C:\Windows\System32\mctadmin.exe
################## | Éléments infectieux |
################## | Registre |
Présent! HKU\S-1-5-21-2097648666-163629840-2645427609-1001\Software\Microsoft\Windows\CurrentVersion\Policies\System|DisableTaskMgr
Présent! HKCU\Software\Microsoft\Windows\CurrentVersion\Policies\System|DisableTaskMgr
HKCU\.\.\.\.\Explorer\MountPoints2\{29967f87-b26f-11e1-82d5-90fba6893745}
Shell\AutoRun\Command = F:\LaunchU3.exe -a
################## | Vaccin |
C:\Autorun.inf - Vaccin créé par UsbFix (El Desaparecido)
D:\Autorun.inf - Vaccin créé par UsbFix (El Desaparecido)
################## | E.O.F |
http://www.usbfix.net -
http://www.sosvirus.net |