Alors là j'ai mis à jour l'ordi, et suivi le tutoriel d'USBfix. Je n'ai pas encore vacciné.
Voici le rapport:
############################## | UsbFix V 7.145 | [Recherche]
Utilisateur: Anne-Sophie (Administrateur) # ASOLEZAC
Mis à jour le 17/10/2013 par El Desaparecido - Team SosVirus
Lancé à 21:18:25 | 21/10/2013
Site Web:
http://www.usbfix.net/
Forum :
http://www.sosvirus.net/
Upload Malware:
http://www.sosvirus.net/upload_malware.php
Contact:
http://www.usbfix.net/contact/
PC: Intel (PLCSF8)
CPU: Intel(R) Core(TM) i7-3630QM CPU @ 2.40GHz
RAM - [Total : 6095 | Free : 3972]
Bios: Insyde Corp.
Boot: Normal boot
OS: Microsoft Windows 8 (6.2.9200 64-Bit) #
WB: Windows Internet Explorer 10.0.9200.16721
SC: Security Center Service [Enabled]
WU: Windows Update Service [(!) Disabled]
AV: Windows Defender [(!) Disabled | Updated]
FW: Windows FireWall Service [Enabled]
C:\ (%systemdrive%) - Disque fixe # 919 Go (789 Go libre(s) - 86%) [TI31085000A] # NTFS
D:\ - CD-ROM
E:\ - Disque fixe # 466 Go (262 Go libre(s) - 56%) [TOSHIBA EXT] # NTFS
F:\ - Disque amovible # 4 Go (1 Go libre(s) - 28%) [USB DISK] # FAT32
################## | Processus Actif |
C:\windows\system32\csrss.exe (ID 676 |ParentID 664)
C:\windows\system32\wininit.exe (ID 760 |ParentID 664)
C:\windows\system32\csrss.exe (ID 776 |ParentID 768)
C:\windows\system32\winlogon.exe (ID 828 |ParentID 768)
C:\windows\system32\services.exe (ID 852 |ParentID 760)
C:\windows\system32\lsass.exe (ID 860 |ParentID 760)
C:\windows\system32\svchost.exe (ID 980 |ParentID 852)
C:\windows\system32\svchost.exe (ID 332 |ParentID 852)
C:\windows\system32\atiesrxx.exe (ID 408 |ParentID 852)
C:\windows\System32\svchost.exe (ID 480 |ParentID 852)
C:\windows\system32\svchost.exe (ID 696 |ParentID 852)
C:\windows\system32\svchost.exe (ID 496 |ParentID 852)
C:\windows\system32\dwm.exe (ID 1048 |ParentID 828)
C:\windows\System32\svchost.exe (ID 1060 |ParentID 852)
C:\windows\system32\atieclxx.exe (ID 1140 |ParentID 408)
C:\Program Files\Realtek\Audio\HDA\RtkAudioService64.exe (ID 1216 |ParentID 852)
C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe (ID 1280 |ParentID 1216)
C:\windows\system32\svchost.exe (ID 1388 |ParentID 852)
C:\Program Files\AVAST Software\Avast\AvastSvc.exe (ID 1468 |ParentID 852)
C:\Program Files (x86)\TOSHIBA\Password Utility\GFNEXSrv.exe (ID 1556 |ParentID 852)
C:\windows\System32\spoolsv.exe (ID 1752 |ParentID 852)
C:\windows\system32\svchost.exe (ID 1804 |ParentID 852)
C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe (ID 1908 |ParentID 852)
C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe (ID 1928 |ParentID 852)
C:\Program Files\Bonjour\mDNSResponder.exe (ID 1960 |ParentID 852)
C:\Program Files\Siber Systems\GoodSync\Gs-Server.exe (ID 2004 |ParentID 852)
C:\windows\system32\dashost.exe (ID 2024 |ParentID 1060)
C:\Program Files\Intel\iCLS Client\HeciServer.exe (ID 1360 |ParentID 852)
C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe (ID 2016 |ParentID 852)
C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamscheduler.exe (ID 2080 |ParentID 852)
C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe (ID 2100 |ParentID 852)
C:\Program Files\Microsoft Office 15\ClientX64\integratedoffice.exe (ID 2260 |ParentID 852)
C:\Program Files (x86)\Sony\PMB\PMBDeviceInfoProvider.exe (ID 2312 |ParentID 852)
c:\Program Files (x86)\Common Files\Protexis\License Service\PsiService_2.exe (ID 2768 |ParentID 852)
C:\windows\system32\svchost.exe (ID 2852 |ParentID 852)
C:\Windows\system32\TODDSrv.exe (ID 2904 |ParentID 852)
C:\Program Files\TOSHIBA\Teco\TecoService.exe (ID 2124 |ParentID 852)
C:\windows\system32\svchost.exe (ID 692 |ParentID 852)
C:\windows\system32\wbem\wmiprvse.exe (ID 3252 |ParentID 980)
C:\windows\system32\wbem\unsecapp.exe (ID 3424 |ParentID 980)
C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\FWService\IntelMeFWService.exe (ID 3436 |ParentID 852)
C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe (ID 1900 |ParentID 852)
C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe (ID 3004 |ParentID 852)
C:\windows\system32\wbem\wmiprvse.exe (ID 500 |ParentID 980)
C:\windows\system32\taskhostex.exe (ID 4492 |ParentID 852)
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe (ID 4648 |ParentID 852)
C:\windows\Explorer.EXE (ID 5052 |ParentID 4640)
C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamgui.exe (ID 4244 |ParentID 2100)
C:\PROGRAM FILES\SYNAPTICS\SYNTP\SYNTPHELPER.EXE (ID 4284 |ParentID 4868)
C:\Program Files\WindowsApps\microsoft.windowscommunicationsapps_17.0.1119.516_x64__8wekyb3d8bbwe\LiveComm.exe (ID 4452 |ParentID 980)
C:\Windows\System32\RuntimeBroker.exe (ID 4568 |ParentID 980)
C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe (ID 3456 |ParentID 5052)
C:\Program Files\TOSHIBA\Hotkey\TCrdMain_Win8.exe (ID 2148 |ParentID 5052)
C:\Program Files (x86)\TOSHIBA\System Setting\TSleepSrv.exe (ID 4920 |ParentID 5052)
C:\Program Files\TOSHIBA\Teco\TecoResident.exe (ID 4420 |ParentID 5052)
C:\Program Files\SRS Labs\SRS Control Panel\SRSPanel_64.exe (ID 4212 |ParentID 5052)
C:\Program Files\HP\HP Photosmart 5520 series\Bin\ScanToPCActivationApp.exe (ID 4604 |ParentID 5052)
C:\Users\Anne-Sophie\AppData\Local\Microsoft\SkyDrive\SkyDrive.exe (ID 4864 |ParentID 5052)
C:\Program Files (x86)\Common Files\Apple\Internet Services\iCloudServices.exe (ID 4692 |ParentID 5052)
C:\Program Files (x86)\Common Files\Apple\Internet Services\ApplePhotoStreams.exe (ID 5128 |ParentID 5052)
C:\Program Files (x86)\Common Files\Apple\Internet Services\APSDaemon.exe (ID 5716 |ParentID 980)
C:\Program Files (x86)\FileHippo.com\UpdateChecker.exe (ID 5352 |ParentID 5052)
C:\windows\system32\RunDll32.exe (ID 5672 |ParentID 5052)
C:\Program Files\HP\HP Photosmart 5520 series\Bin\HPNetworkCommunicatorCom.exe (ID 5168 |ParentID 980)
C:\Program Files (x86)\Intel\IntelAppStore\bin\ismagent.exe (ID 5436 |ParentID 5612)
C:\Users\Anne-Sophie\AppData\Roaming\Dropbox\bin\Dropbox.exe (ID 6048 |ParentID 5052)
C:\Program Files\Microsoft Office 15\root\office15\onenotem.exe (ID 6044 |ParentID 5052)
C:\Program Files (x86)\HP\HP Software Update\hpwuschd2.exe (ID 5256 |ParentID 5612)
C:\Program Files (x86)\Sony\PMB\PMBVolumeWatcher.exe (ID 4336 |ParentID 5612)
C:\Program Files\Microsoft Office 15\Root\VFS\ProgramFilesCommonX86\Microsoft Shared\OFFICE15\CSISYNCCLIENT.EXE (ID 6256 |ParentID 6200)
C:\Program Files (x86)\iTunes\iTunesHelper.exe (ID 6760 |ParentID 5612)
C:\Program Files\AVAST Software\Avast\AvastUI.exe (ID 7152 |ParentID 5612)
C:\Program Files\iPod\bin\iPodService.exe (ID 6180 |ParentID 852)
C:\Program Files (x86)\Mozilla Firefox\firefox.exe (ID 672 |ParentID 5052)
C:\Program Files\TOSHIBA\TPHM\TPCHSrv.exe (ID 2036 |ParentID 852)
C:\Program Files\TOSHIBA\TPHM\TPCHWMsg.exe (ID 4580 |ParentID 4888)
C:\Program Files\TOSHIBA\Toshiba Service Station\ToshibaServiceStation.exe (ID 6396 |ParentID 852)
C:\Program Files\TOSHIBA\TOSHIBA Service Station\TMachInfo.exe (ID 6160 |ParentID 852)
C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\MOM.exe (ID 5740 |ParentID 5344)
C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CCC.exe (ID 3892 |ParentID 5740)
C:\Program Files\Microsoft Office 15\ClientX64\integratedoffice.exe (ID 7060 |ParentID 5052)
C:\windows\system32\SearchIndexer.exe (ID 2356 |ParentID 852)
C:\UsbFix\Go.exe (ID 8996 |ParentID 1564)
C:\Windows\System32\WUDFHost.exe (ID 8908 |ParentID 1060)
################## | Regedit Run |
HKLM\SOFTWARE | Run : [Intel AppUp(R) center] - "C:\Program Files (x86)\Intel\IntelAppStore\bin\ismagent.exe" --domain-id F0399437-FD0C-4A48-B101-F0314A6172E4
HKLM\SOFTWARE | Run : [StartCCC] - "C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" MSRun
HKLM\SOFTWARE | Run : [TPUReg] - "C:\Program Files (x86)\TOSHIBA\Password Utility\TosPU.exe" /Retimes
HKLM\SOFTWARE | Run : [APSDaemon] - "C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe"
HKLM\SOFTWARE | Run : [HP Software Update] - C:\Program Files (x86)\Hp\HP Software Update\HPWuSchd2.exe
HKLM\SOFTWARE | Run : [] -
HKLM\SOFTWARE | Run : [Adobe ARM] - "C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
HKLM\SOFTWARE | Run : [PMBVolumeWatcher] - C:\Program Files (x86)\Sony\PMB\PMBVolumeWatcher.exe
HKLM\SOFTWARE | Run : [iTunesHelper] - "C:\Program Files (x86)\iTunes\iTunesHelper.exe"
HKLM\SOFTWARE | Run : [AvastUI.exe] - "C:\Program Files\AVAST Software\Avast\AvastUI.exe" /nogui
HKLM\SOFTWARE\wow6432Node | Run : [Intel AppUp(R) center] - "C:\Program Files (x86)\Intel\IntelAppStore\bin\ismagent.exe" --domain-id F0399437-FD0C-4A48-B101-F0314A6172E4
HKLM\SOFTWARE\wow6432Node | Run : [StartCCC] - "C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" MSRun
HKLM\SOFTWARE\wow6432Node | Run : [TPUReg] - "C:\Program Files (x86)\TOSHIBA\Password Utility\TosPU.exe" /Retimes
HKLM\SOFTWARE\wow6432Node | Run : [APSDaemon] - "C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe"
HKLM\SOFTWARE\wow6432Node | Run : [HP Software Update] - C:\Program Files (x86)\Hp\HP Software Update\HPWuSchd2.exe
HKLM\SOFTWARE\wow6432Node | Run : [] -
HKLM\SOFTWARE\wow6432Node | Run : [Adobe ARM] - "C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
HKLM\SOFTWARE\wow6432Node | Run : [PMBVolumeWatcher] - C:\Program Files (x86)\Sony\PMB\PMBVolumeWatcher.exe
HKLM\SOFTWARE\wow6432Node | Run : [iTunesHelper] - "C:\Program Files (x86)\iTunes\iTunesHelper.exe"
HKLM\SOFTWARE\wow6432Node | Run : [AvastUI.exe] - "C:\Program Files\AVAST Software\Avast\AvastUI.exe" /nogui
HKLM\SOFTWARE | RunOnce : [] -
HKLM\SOFTWARE\wow6432Node | RunOnce : [] -
HKU\S-1-5-21-685979562-3945554171-1838596097-1001\SOFTWARE | Run : [HP Photosmart 5520 series (NET)] - "C:\Program Files\HP\HP Photosmart 5520 series\Bin\ScanToPCActivationApp.exe" -deviceID "CN32K187VP0602:NW" -scfn "HP Photosmart 5520 series (NET)" -AutoStart 1
HKU\S-1-5-21-685979562-3945554171-1838596097-1001\SOFTWARE | Run : [SkyDrive] - "C:\Users\Anne-Sophie\AppData\Local\Microsoft\SkyDrive\SkyDrive.exe" /background
HKU\S-1-5-21-685979562-3945554171-1838596097-1001\SOFTWARE | Run : [iCloudServices] - C:\Program Files (x86)\Common Files\Apple\Internet Services\iCloudServices.exe
HKU\S-1-5-21-685979562-3945554171-1838596097-1001\SOFTWARE | Run : [ApplePhotoStreams] - C:\Program Files (x86)\Common Files\Apple\Internet Services\ApplePhotoStreams.exe
HKU\S-1-5-21-685979562-3945554171-1838596097-1001\SOFTWARE | Run : [FileHippo.com] - "C:\Program Files (x86)\FileHippo.com\UpdateChecker.exe" /background
HKU\S-1-5-21-685979562-3945554171-1838596097-1001\SOFTWARE | RunOnce : [Uninstall C:\Users\Anne-Sophie\AppData\Local\Microsoft\SkyDrive\16.4.6012.0828\amd64] - C:\windows\system32\cmd.exe /q /c rmdir /s /q "C:\Users\Anne-Sophie\AppData\Local\Microsoft\SkyDrive\16.4.6012.0828\amd64"
HKU\S-1-5-21-685979562-3945554171-1838596097-1001\SOFTWARE | RunOnce : [Uninstall C:\Users\Anne-Sophie\AppData\Local\Microsoft\SkyDrive\17.0.2006.0314\amd64] - C:\windows\system32\cmd.exe /q /c rmdir /s /q "C:\Users\Anne-Sophie\AppData\Local\Microsoft\SkyDrive\17.0.2006.0314\amd64"
HKU\S-1-5-21-685979562-3945554171-1838596097-1001\SOFTWARE | RunOnce : [Uninstall C:\Users\Anne-Sophie\AppData\Local\Microsoft\SkyDrive\17.0.2011.0627\amd64] - C:\windows\system32\cmd.exe /q /c rmdir /s /q "C:\Users\Anne-Sophie\AppData\Local\Microsoft\SkyDrive\17.0.2011.0627\amd64"
################## | Éléments infectieux |
################## | Registre |
################## | Vaccin |
(!) Cet ordinateur n'est pas vacciné!
################## | E.O.F |
http://www.usbfix.net -
http://www.sosvirus.net |