bonjour Gabriel
çà y est j'ai fait usbfix
voici le rapport
############################## | UsbFix V 7.144 | [Recherche]
Utilisateur: Cosette (Administrateur) # COSETTE-PC
Mis à jour le 08/10/2013 par El Desaparecido - Team SosVirus
Lancé à 11:43:10 | 16/10/2013
Site Web:
http://www.usbfix.net/
Forum :
http://www.sosvirus.net/
Upload Malware:
http://www.sosvirus.net/upload_malware.php
Contact:
http://www.usbfix.net/contact/
PC: ASUSTeK Computer INC. (1015BXO)
CPU: AMD C-60 APU with Radeon(tm) HD Graphics
RAM - [Total : 750 | Free : 86]
Bios: American Megatrends Inc.
Boot: Normal boot
OS: Microsoft Windows 7 Édition Starter (6.1.7601 32-Bit) # Service Pack 1
WB: Windows Internet Explorer 10.0.9200.16721
SC: Security Center Service [Enabled]
WU: Windows Update Service [Enabled]
AV: Trend Micro Titanium [(!) Disabled | Updated]
FW: Windows FireWall Service [Enabled]
C:\ (%systemdrive%) - Disque fixe # 100 Go (72 Go libre(s) - 72%) [] # NTFS
D:\ - Disque fixe # 183 Go (183 Go libre(s) - 100%) [] # NTFS
################## | Processus Actif |
C:\windows\system32\csrss.exe (ID 444 |ParentID 392)
C:\windows\system32\wininit.exe (ID 516 |ParentID 392)
C:\windows\system32\csrss.exe (ID 524 |ParentID 508)
C:\windows\system32\services.exe (ID 572 |ParentID 516)
C:\windows\system32\lsass.exe (ID 588 |ParentID 516)
C:\windows\system32\lsm.exe (ID 596 |ParentID 516)
C:\windows\system32\winlogon.exe (ID 632 |ParentID 508)
C:\windows\system32\svchost.exe (ID 736 |ParentID 572)
C:\windows\system32\svchost.exe (ID 816 |ParentID 572)
C:\windows\system32\atiesrxx.exe (ID 864 |ParentID 572)
C:\windows\System32\svchost.exe (ID 936 |ParentID 572)
C:\windows\System32\svchost.exe (ID 988 |ParentID 572)
C:\windows\system32\svchost.exe (ID 1016 |ParentID 572)
C:\windows\system32\svchost.exe (ID 1060 |ParentID 572)
C:\windows\system32\atieclxx.exe (ID 1220 |ParentID 864)
C:\windows\system32\svchost.exe (ID 1304 |ParentID 572)
C:\windows\system32\WLANExt.exe (ID 1468 |ParentID 988)
C:\windows\system32\conhost.exe (ID 1480 |ParentID 444)
C:\windows\System32\spoolsv.exe (ID 1560 |ParentID 572)
C:\windows\system32\svchost.exe (ID 1588 |ParentID 572)
C:\Program Files\ATI Technologies\ATI.ACE\Fuel\Fuel.Service.exe (ID 1672 |ParentID 572)
C:\Program Files\Common Files\InstantOn\InsOnSrv.exe (ID 1696 |ParentID 572)
C:\windows\system32\AsusService.exe (ID 1724 |ParentID 572)
C:\Program Files\Malwarebytes' Anti-Malware\mbamscheduler.exe (ID 1840 |ParentID 572)
C:\Program Files\Malwarebytes' Anti-Malware\mbamservice.exe (ID 1884 |ParentID 572)
C:\windows\system32\svchost.exe (ID 1916 |ParentID 572)
C:\Program Files\Trend Micro\Titanium\TiMiniService.exe (ID 1944 |ParentID 572)
C:\Program Files\Trend Micro\Titanium\TiResumeSrv.exe (ID 2024 |ParentID 1944)
C:\ExpressGateUtil\VAWinService.exe (ID 2032 |ParentID 572)
C:\windows\system32\conhost.exe (ID 2040 |ParentID 444)
C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE (ID 12 |ParentID 572)
C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe (ID 1240 |ParentID 12)
C:\windows\system32\svchost.exe (ID 2076 |ParentID 572)
C:\windows\system32\wbem\wmiprvse.exe (ID 2172 |ParentID 736)
C:\windows\system32\taskhost.exe (ID 2976 |ParentID 572)
C:\Program Files\Common Files\InstantOn\InsOnWMI.exe (ID 3012 |ParentID 1696)
C:\Program Files\Malwarebytes' Anti-Malware\mbamgui.exe (ID 3032 |ParentID 1884)
C:\windows\system32\Dwm.exe (ID 3360 |ParentID 988)
C:\windows\Explorer.EXE (ID 3440 |ParentID 3180)
C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\MOM.exe (ID 2520 |ParentID 2268)
C:\Program Files\ASUS\HotkeyService\HotKeyMon.exe (ID 2580 |ParentID 1724)
C:\Program Files\ASUS\HotkeyService\HotkeyService.exe (ID 2640 |ParentID 1724)
C:\Program Files\Asus\Eee Docking\Eee Docking.exe (ID 2652 |ParentID 3440)
C:\Program Files\ASUS\SHE\SuperHybridEngine.exe (ID 2692 |ParentID 1724)
C:\Program Files\Asus\LiveUpdate\LiveUpdate.exe (ID 2764 |ParentID 1724)
C:\Program Files\ASUS\CapsHook\CapsHook.exe (ID 2852 |ParentID 1724)
C:\Program Files\Realtek\Audio\HDA\RtHDVCpl.exe (ID 3436 |ParentID 3440)
C:\Program Files\Elantech\ETDCtrl.exe (ID 3656 |ParentID 3440)
C:\ExpressGateUtil\VAWinAgent.exe (ID 3708 |ParentID 3440)
C:\windows\system32\SearchIndexer.exe (ID 3872 |ParentID 572)
C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CCC.exe (ID 3828 |ParentID 2520)
C:\Program Files\Elantech\ETDCtrlHelper.exe (ID 2484 |ParentID 3656)
C:\Program Files\Internet Explorer\iexplore.exe (ID 3228 |ParentID 3440)
C:\Program Files\Internet Explorer\iexplore.exe (ID 3448 |ParentID 3228)
C:\windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe (ID 2860 |ParentID 572)
C:\windows\system32\svchost.exe (ID 3692 |ParentID 572)
C:\windows\Microsoft.Net\Framework\v3.0\WPF\PresentationFontCache.exe (ID 3672 |ParentID 572)
C:\Program Files\Internet Explorer\iexplore.exe (ID 1764 |ParentID 3228)
C:\Program Files\Microsoft\BingBar\7.1.391.0\SeaPort.exe (ID 1792 |ParentID 572)
C:\windows\system32\wbem\wmiprvse.exe (ID 5944 |ParentID 736)
C:\UsbFix\Go.exe (ID 5028 |ParentID 1848)
C:\UsbFix\Go.exe (ID 5268 |ParentID 4848)
C:\UsbFix\Go.exe (ID 5848 |ParentID 2536)
################## | Regedit Run |
HKLM\SOFTWARE | Run : [StartCCC] - "C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" MSRun
HKLM\SOFTWARE | Run : [HotkeyMon] - AsusSender.exe C:\Program Files\ASUS\HotkeyService\HotKeyMon.exe
HKLM\SOFTWARE | Run : [HotkeyService] - AsusSender.exe C:\Program Files\ASUS\HotkeyService\HotkeyService.exe
HKLM\SOFTWARE | Run : [SuperHybridEngine] - AsusSender.exe C:\Program Files\ASUS\SHE\SuperHybridEngine.exe
HKLM\SOFTWARE | Run : [LiveUpdate] - AsusSender.exe C:\Program Files\Asus\LiveUpdate\LiveUpdate.exe auto
HKLM\SOFTWARE | Run : [CapsHook] - AsusSender.exe C:\Program Files\ASUS\CapsHook\CapsHook.exe
HKLM\SOFTWARE | Run : [Eee Docking] - C:\Program Files\ASUS\Eee Docking\Eee Docking.exe autorun
HKLM\SOFTWARE | Run : [VizorHtmlDialog.exe] - "C:\Program Files\Trend Micro\Titanium\UIFramework\VizorHtmlDialog.exe" "DEF" "EULA" "C:\Program Files\Trend Micro\Titanium\UI\Installer.cmpt\resources\preinstall_01_welcome_trial.html" "DEF" "DEF" "DEF"
HKLM\SOFTWARE | Run : [Trend Micro Client Framework] - "C:\Program Files\Trend Micro\UniClient\UiFrmWrk\UIWatchDog.exe"
HKLM\SOFTWARE | Run : [Trend Micro Titanium] - C:\Program Files\Trend Micro\Titanium\VizorShortCut.exe -ReFlush "none" "none"
HKLM\SOFTWARE | Run : [RtHDVCpl] - C:\Program Files\Realtek\Audio\HDA\RtHDVCpl.exe -s
HKLM\SOFTWARE | Run : [ETDWare] - %ProgramFiles%\Elantech\ETDCtrl.exe
HKLM\SOFTWARE | Run : [VAWinAgent] - C:\ExpressGateUtil\VAWinAgent.exe
HKLM\SOFTWARE | Run : [ASUSPRP] - C:\Program Files\ASUS\APRP\APRP.EXE
HKLM\SOFTWARE | Run : [ASUSWebStorage] - C:\Program Files\ASUS\ASUS WebStorage\3.0.108.222\AsusWSPanel.exe /S
HKLM\SOFTWARE | Run : [Adobe ARM] - "C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
HKLM\SOFTWARE | RunOnce : [] -
HKU\S-1-5-19\SOFTWARE | Run : [Sidebar] - %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun
HKU\S-1-5-20\SOFTWARE | Run : [Sidebar] - %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun
HKU\S-1-5-19\SOFTWARE | RunOnce : [mctadmin] - C:\Windows\System32\mctadmin.exe
HKU\S-1-5-20\SOFTWARE | RunOnce : [mctadmin] - C:\Windows\System32\mctadmin.exe
################## | Éléments infectieux |
################## | Registre |
################## | Vaccin |
C:\Autorun.inf - Vaccin créé par UsbFix (El Desaparecido)
D:\Autorun.inf - Vaccin créé par UsbFix (El Desaparecido)
################## | E.O.F |
http://www.usbfix.net -
http://www.sosvirus.net |