- ven. 22 nov. 2013 00:02
#18376
Voici le résultat d'analyse, je ne sais pas si je suis infecté ou pas, que dois-je faire?
Merci d'avance!
############################## | UsbFix V 7.152 | [Recherche]
Utilisateur: Jean-Baptiste (Administrateur) # PC-JB
Mis à jour le 20/11/2013 par El Desaparecido - Team SosVirus
Lancé à 23:51:06 | 21/11/2013
Site Web : http://www.usbfix.net" onclick="window.open(this.href);return false;
Forum : http://www.sosvirus.net/" onclick="window.open(this.href);return false;
Upload Malware : http://www.sosvirus.net/upload_malware.php" onclick="window.open(this.href);return false;
Contact : http://www.usbfix.net/contact/" onclick="window.open(this.href);return false;
PC: Wistron (303C)
CPU: AMD Sempron(tm) SI-42
RAM -> [Total : 2814 | Free : 1434]
Bios: Hewlett-Packard
Boot: Normal boot
OS: Microsoft Windows 7 à‰dition Intégrale (6.1.7601 32-Bit) Service Pack 1
WB: Windows Internet Explorer : 10.0.9200.16721
SC: Security Center Service [Enabled]
WU: Windows Update Service [Enabled]
AV: avast! Antivirus [(!) Disabled | Updated]
AS: Windows Defender : 6.1.7600.16385 (win7_rtm.090713-1255)
FW: Windows FireWall Service [Enabled]
C:\ (%systemdrive%) -> Disque fixe # 139 Go (87 Go libre(s) - 63%) [] # NTFS
D:\ -> Disque fixe # 10 Go (2 Go libre(s) - 17%) [RECOVERY] # NTFS
E:\ -> CD-ROM
F:\ -> Disque amovible # 4 Go (4 Go libre(s) - 99%) [0478 348710] # FAT32
G:\ -> Disque amovible # 7 Go (7 Go libre(s) - 100%) [0478 348710] # FAT32
################## | Processus Actif |
C:\Windows\system32\csrss.exe (ID: 428 |ParentID: 360)
C:\Windows\system32\wininit.exe (ID: 484 |ParentID: 360)
C:\Windows\system32\csrss.exe (ID: 492 |ParentID: 476)
C:\Windows\system32\services.exe (ID: 540 |ParentID: 484)
C:\Windows\system32\lsass.exe (ID: 556 |ParentID: 484)
C:\Windows\system32\lsm.exe (ID: 564 |ParentID: 484)
C:\Windows\system32\svchost.exe (ID: 652 |ParentID: 540)
C:\Windows\system32\nvvsvc.exe (ID: 720 |ParentID: 540)
C:\Windows\system32\svchost.exe (ID: 748 |ParentID: 540)
C:\Windows\System32\svchost.exe (ID: 796 |ParentID: 540)
C:\Windows\System32\svchost.exe (ID: 852 |ParentID: 540)
C:\Windows\system32\svchost.exe (ID: 892 |ParentID: 540)
C:\Windows\system32\winlogon.exe (ID: 916 |ParentID: 476)
C:\Windows\system32\svchost.exe (ID: 980 |ParentID: 540)
C:\Windows\system32\svchost.exe (ID: 1144 |ParentID: 540)
C:\Windows\system32\svchost.exe (ID: 1364 |ParentID: 540)
C:\Program Files\Alwil Software\Avast5\AvastSvc.exe (ID: 1436 |ParentID: 540)
C:\Windows\System32\spoolsv.exe (ID: 1568 |ParentID: 540)
C:\Windows\system32\svchost.exe (ID: 1608 |ParentID: 540)
C:\Program Files\Common Files\Adobe\ARM\1.0\armsvc.exe (ID: 1676 |ParentID: 540)
C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe (ID: 1708 |ParentID: 540)
C:\Program Files\Bonjour\mDNSResponder.exe (ID: 1740 |ParentID: 540)
C:\Windows\system32\svchost.exe (ID: 1776 |ParentID: 540)
C:\Windows\system32\svchost.exe (ID: 1824 |ParentID: 540)
C:\Windows\system32\svchost.exe (ID: 1844 |ParentID: 540)
C:\Program Files\Common Files\LightScribe\LSSrvc.exe (ID: 1868 |ParentID: 540)
C:\Windows\system32\PnkBstrA.exe (ID: 1916 |ParentID: 540)
C:\Program Files\SMINST\BLService.exe (ID: 1956 |ParentID: 540)
C:\Windows\system32\svchost.exe (ID: 1284 |ParentID: 540)
C:\Program Files\Spybot - Search & Destroy\SDWinSec.exe (ID: 2028 |ParentID: 540)
C:\Windows\system32\nvvsvc.exe (ID: 2256 |ParentID: 720)
C:\Windows\system32\taskhost.exe (ID: 1860 |ParentID: 540)
C:\Windows\system32\Dwm.exe (ID: 2916 |ParentID: 852)
C:\Windows\Explorer.EXE (ID: 2784 |ParentID: 188)
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe (ID: 2320 |ParentID: 2784)
C:\Program Files\Hewlett-Packard\HP Wireless Assistant\HPWAMain.exe (ID: 3400 |ParentID: 2784)
C:\Program Files\Hewlett-Packard\HP Quick Launch Buttons\QLBCTRL.exe (ID: 3644 |ParentID: 2784)
C:\Program Files\Hewlett-Packard\Shared\hpqwmiex.exe (ID: 3872 |ParentID: 540)
C:\Windows\PLFSetL.exe (ID: 3616 |ParentID: 2784)
C:\Windows\snuvcdsm.exe (ID: 3816 |ParentID: 2784)
C:\Program Files\Alwil Software\Avast5\AvastUI.exe (ID: 3660 |ParentID: 2784)
C:\Windows\system32\wbem\wmiprvse.exe (ID: 3928 |ParentID: 652)
C:\Program Files\Synaptics\SynTP\SynTPHelper.exe (ID: 3828 |ParentID: 2320)
C:\Program Files\iTunes\iTunesHelper.exe (ID: 3316 |ParentID: 2784)
C:\Windows\system32\SearchIndexer.exe (ID: 4036 |ParentID: 540)
C:\Program Files\Common Files\Java\Java Update\jusched.exe (ID: 3900 |ParentID: 2784)
C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe (ID: 2220 |ParentID: 2784)
C:\Users\Jean-Baptiste\AppData\Roaming\cacaoweb\cacaoweb.exe (ID: 2840 |ParentID: 2784)
C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe (ID: 2152 |ParentID: 2784)
C:\Program Files\Windows Media Player\wmpnetwk.exe (ID: 964 |ParentID: 540)
C:\Program Files\Hewlett-Packard\HP Quick Launch Buttons\Com4QLBEx.exe (ID: 3588 |ParentID: 540)
C:\Program Files\Hewlett-Packard\Shared\HpqToaster.exe (ID: 1044 |ParentID: 652)
C:\Users\Jean-Baptiste\AppData\Roaming\Dropbox\bin\Dropbox.exe (ID: 4056 |ParentID: 2784)
C:\Program Files\iPod\bin\iPodService.exe (ID: 3764 |ParentID: 540)
c:\Program Files\Hewlett-Packard\HP Health Check\hphc_service.exe (ID: 3144 |ParentID: 540)
C:\Windows\System32\svchost.exe (ID: 1664 |ParentID: 540)
C:\Program Files\HP\Digital Imaging\bin\hpqSTE08.exe (ID: 4176 |ParentID: 2152)
C:\Program Files\HP\Digital Imaging\bin\hpqbam08.exe (ID: 4248 |ParentID: 652)
C:\Program Files\HP\Digital Imaging\bin\hpqgpc01.exe (ID: 4384 |ParentID: 652)
C:\Windows\system32\svchost.exe (ID: 2376 |ParentID: 540)
C:\Program Files\Common Files\Java\Java Update\jucheck.exe (ID: 3036 |ParentID: 3900)
C:\Windows\system32\taskhost.exe (ID: 5320 |ParentID: 540)
C:\Program Files\Internet Explorer\iexplore.exe (ID: 4400 |ParentID: 2784)
C:\Program Files\Internet Explorer\iexplore.exe (ID: 4516 |ParentID: 4400)
C:\Program Files\Google\Google Toolbar\GoogleToolbarUser_32.exe (ID: 2188 |ParentID: 4400)
C:\Windows\System32\WUDFHost.exe (ID: 5416 |ParentID: 852)
C:\Users\Jean-Baptiste\AppData\Local\Google\Chrome\Application\chrome.exe (ID: 5668 |ParentID: 2784)
C:\Users\Jean-Baptiste\AppData\Local\Google\Chrome\Application\chrome.exe (ID: 4700 |ParentID: 5668)
C:\Users\Jean-Baptiste\AppData\Local\Google\Chrome\Application\chrome.exe (ID: 6052 |ParentID: 5668)
C:\Users\Jean-Baptiste\AppData\Local\Google\Chrome\Application\chrome.exe (ID: 5148 |ParentID: 5668)
C:\Users\Jean-Baptiste\AppData\Local\Google\Chrome\Application\chrome.exe (ID: 4656 |ParentID: 5668)
C:\Users\Jean-Baptiste\AppData\Local\Google\Chrome\Application\chrome.exe (ID: 1248 |ParentID: 5668)
C:\Windows\system32\ctfmon.exe (ID: 4556 |ParentID: 3660)
C:\Windows\system32\SearchProtocolHost.exe (ID: 4616 |ParentID: 4036)
C:\Windows\system32\SearchFilterHost.exe (ID: 4452 |ParentID: 4036)
C:\UsbFix\Go.exe (ID: 6080 |ParentID: 2928)
C:\Windows\system32\wbem\wmiprvse.exe (ID: 5756 |ParentID: 652)
################## | Regedit Run |
04 - HKLM\SOFTWARE | Run : [SynTPEnh] - C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
04 - HKLM\SOFTWARE | Run : [HP Health Check Scheduler] - c:\Program Files\Hewlett-Packard\HP Health Check\HPHC_Scheduler.exe
04 - HKLM\SOFTWARE | Run : [hpqSRMon] - C:\Program Files\HP\Digital Imaging\bin\hpqSRMon.exe
04 - HKLM\SOFTWARE | Run : [hpWirelessAssistant] - C:\Program Files\Hewlett-Packard\HP Wireless Assistant\HPWAMain.exe
04 - HKLM\SOFTWARE | Run : [NvCplDaemon] - RUNDLL32.EXE C:\Windows\system32\NvCpl.dll,NvStartup
04 - HKLM\SOFTWARE | Run : [QlbCtrl.exe] - C:\Program Files\Hewlett-Packard\HP Quick Launch Buttons\QlbCtrl.exe /Start
04 - HKLM\SOFTWARE | Run : [UpdateP2GoShortCut] - "C:\Program Files\CyberLink\Power2Go\MUITransfer\MUIStartMenu.exe" "C:\Program Files\CyberLink\Power2Go" UpdateWithCreateOnce "SOFTWARE\CyberLink\Power2Go\6.0"
04 - HKLM\SOFTWARE | Run : [UpdatePSTShortCut] - "C:\Program Files\CyberLink\DVD Suite\MUITransfer\MUIStartMenu.exe" "C:\Program Files\CyberLink\DVD Suite" UpdateWithCreateOnce "Software\CyberLink\PowerStarter"
04 - HKLM\SOFTWARE | Run : [PLFSetL] - C:\Windows\PLFSetL.exe
04 - HKLM\SOFTWARE | Run : [SNUVCDSM] - C:\Windows\snuvcdsm.exe
04 - HKLM\SOFTWARE | Run : [avast5] - "C:\Program Files\Alwil Software\Avast5\avastUI.exe" /nogui
04 - HKLM\SOFTWARE | Run : [QuickTime Task] - "C:\Program Files\QuickTime\QTTask.exe" -atboottime
04 - HKLM\SOFTWARE | Run : [iTunesHelper] - "C:\Program Files\iTunes\iTunesHelper.exe"
04 - HKLM\SOFTWARE | Run : [Adobe ARM] - "C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
04 - HKLM\SOFTWARE | Run : [SunJavaUpdateSched] - "C:\Program Files\Common Files\Java\Java Update\jusched.exe"
04 - HKLM\SOFTWARE | RunOnce : [] -
04 - HKU\S-1-5-19\SOFTWARE | Run : [Sidebar] - %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun
04 - HKU\S-1-5-20\SOFTWARE | Run : [Sidebar] - %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun
04 - HKU\S-1-5-21-222430623-1189483096-3784063953-1000\SOFTWARE | Run : [SpybotSD TeaTimer] - C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
04 - HKU\S-1-5-21-222430623-1189483096-3784063953-1000\SOFTWARE | Run : [Jean-Baptiste] - C:\Users\Jean-Baptiste\Jean-Baptiste.exe
04 - HKU\S-1-5-21-222430623-1189483096-3784063953-1000\SOFTWARE | Run : [WMPNSCFG] - C:\Program Files\Windows Media Player\WMPNSCFG.exe
04 - HKU\S-1-5-21-222430623-1189483096-3784063953-1000\SOFTWARE | Run : [TomTomHOME.exe] - "C:\Program Files\TomTom HOME 2\TomTomHOMERunner.exe"
04 - HKU\S-1-5-21-222430623-1189483096-3784063953-1000\SOFTWARE | Run : [RDReminder] -
04 - HKU\S-1-5-21-222430623-1189483096-3784063953-1000\SOFTWARE | Run : [Google Update] - "C:\Users\Jean-Baptiste\AppData\Local\Google\Update\GoogleUpdate.exe" /c
04 - HKU\S-1-5-21-222430623-1189483096-3784063953-1000\SOFTWARE | Run : [cacaoweb] - "C:\Users\Jean-Baptiste\AppData\Roaming\cacaoweb\cacaoweb.exe" -noplayer
04 - HKU\S-1-5-19\SOFTWARE | RunOnce : [mctadmin] - C:\Windows\System32\mctadmin.exe
04 - HKU\S-1-5-20\SOFTWARE | RunOnce : [mctadmin] - C:\Windows\System32\mctadmin.exe
04 - HKU\S-1-5-21-222430623-1189483096-3784063953-1000\SOFTWARE | RunOnce : [Application Restart #0] - C:\Users\Jean-Baptiste\AppData\Local\Google\Chrome\Application\chrome.exe --flag-switches-begin --flag-switches-end --restore-last-session --flag-switches-begin --flag-switches-end -- http://www.pewenvironment.org/uploadedF ... French.pdf" onclick="window.open(this.href);return false;
################## | Recherche générique |
Présent! D:\desktop.ini
################## | Registre |
Présent! HKU\S-1-5-21-222430623-1189483096-3784063953-1000\Software\Microsoft\Windows\CurrentVersion\Run|Jean-Baptiste
Présent! HKCU\Software\Microsoft\Windows\CurrentVersion\Run|Jean-Baptiste
################## | Vaccin |
(!) Cet ordinateur n'est pas vacciné!
################## | E.O.F | http://www.usbfix.net" onclick="window.open(this.href);return false; - http://www.sosvirus.net" onclick="window.open(this.href);return false; |
Merci d'avance!
############################## | UsbFix V 7.152 | [Recherche]
Utilisateur: Jean-Baptiste (Administrateur) # PC-JB
Mis à jour le 20/11/2013 par El Desaparecido - Team SosVirus
Lancé à 23:51:06 | 21/11/2013
Site Web : http://www.usbfix.net" onclick="window.open(this.href);return false;
Forum : http://www.sosvirus.net/" onclick="window.open(this.href);return false;
Upload Malware : http://www.sosvirus.net/upload_malware.php" onclick="window.open(this.href);return false;
Contact : http://www.usbfix.net/contact/" onclick="window.open(this.href);return false;
PC: Wistron (303C)
CPU: AMD Sempron(tm) SI-42
RAM -> [Total : 2814 | Free : 1434]
Bios: Hewlett-Packard
Boot: Normal boot
OS: Microsoft Windows 7 à‰dition Intégrale (6.1.7601 32-Bit) Service Pack 1
WB: Windows Internet Explorer : 10.0.9200.16721
SC: Security Center Service [Enabled]
WU: Windows Update Service [Enabled]
AV: avast! Antivirus [(!) Disabled | Updated]
AS: Windows Defender : 6.1.7600.16385 (win7_rtm.090713-1255)
FW: Windows FireWall Service [Enabled]
C:\ (%systemdrive%) -> Disque fixe # 139 Go (87 Go libre(s) - 63%) [] # NTFS
D:\ -> Disque fixe # 10 Go (2 Go libre(s) - 17%) [RECOVERY] # NTFS
E:\ -> CD-ROM
F:\ -> Disque amovible # 4 Go (4 Go libre(s) - 99%) [0478 348710] # FAT32
G:\ -> Disque amovible # 7 Go (7 Go libre(s) - 100%) [0478 348710] # FAT32
################## | Processus Actif |
C:\Windows\system32\csrss.exe (ID: 428 |ParentID: 360)
C:\Windows\system32\wininit.exe (ID: 484 |ParentID: 360)
C:\Windows\system32\csrss.exe (ID: 492 |ParentID: 476)
C:\Windows\system32\services.exe (ID: 540 |ParentID: 484)
C:\Windows\system32\lsass.exe (ID: 556 |ParentID: 484)
C:\Windows\system32\lsm.exe (ID: 564 |ParentID: 484)
C:\Windows\system32\svchost.exe (ID: 652 |ParentID: 540)
C:\Windows\system32\nvvsvc.exe (ID: 720 |ParentID: 540)
C:\Windows\system32\svchost.exe (ID: 748 |ParentID: 540)
C:\Windows\System32\svchost.exe (ID: 796 |ParentID: 540)
C:\Windows\System32\svchost.exe (ID: 852 |ParentID: 540)
C:\Windows\system32\svchost.exe (ID: 892 |ParentID: 540)
C:\Windows\system32\winlogon.exe (ID: 916 |ParentID: 476)
C:\Windows\system32\svchost.exe (ID: 980 |ParentID: 540)
C:\Windows\system32\svchost.exe (ID: 1144 |ParentID: 540)
C:\Windows\system32\svchost.exe (ID: 1364 |ParentID: 540)
C:\Program Files\Alwil Software\Avast5\AvastSvc.exe (ID: 1436 |ParentID: 540)
C:\Windows\System32\spoolsv.exe (ID: 1568 |ParentID: 540)
C:\Windows\system32\svchost.exe (ID: 1608 |ParentID: 540)
C:\Program Files\Common Files\Adobe\ARM\1.0\armsvc.exe (ID: 1676 |ParentID: 540)
C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe (ID: 1708 |ParentID: 540)
C:\Program Files\Bonjour\mDNSResponder.exe (ID: 1740 |ParentID: 540)
C:\Windows\system32\svchost.exe (ID: 1776 |ParentID: 540)
C:\Windows\system32\svchost.exe (ID: 1824 |ParentID: 540)
C:\Windows\system32\svchost.exe (ID: 1844 |ParentID: 540)
C:\Program Files\Common Files\LightScribe\LSSrvc.exe (ID: 1868 |ParentID: 540)
C:\Windows\system32\PnkBstrA.exe (ID: 1916 |ParentID: 540)
C:\Program Files\SMINST\BLService.exe (ID: 1956 |ParentID: 540)
C:\Windows\system32\svchost.exe (ID: 1284 |ParentID: 540)
C:\Program Files\Spybot - Search & Destroy\SDWinSec.exe (ID: 2028 |ParentID: 540)
C:\Windows\system32\nvvsvc.exe (ID: 2256 |ParentID: 720)
C:\Windows\system32\taskhost.exe (ID: 1860 |ParentID: 540)
C:\Windows\system32\Dwm.exe (ID: 2916 |ParentID: 852)
C:\Windows\Explorer.EXE (ID: 2784 |ParentID: 188)
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe (ID: 2320 |ParentID: 2784)
C:\Program Files\Hewlett-Packard\HP Wireless Assistant\HPWAMain.exe (ID: 3400 |ParentID: 2784)
C:\Program Files\Hewlett-Packard\HP Quick Launch Buttons\QLBCTRL.exe (ID: 3644 |ParentID: 2784)
C:\Program Files\Hewlett-Packard\Shared\hpqwmiex.exe (ID: 3872 |ParentID: 540)
C:\Windows\PLFSetL.exe (ID: 3616 |ParentID: 2784)
C:\Windows\snuvcdsm.exe (ID: 3816 |ParentID: 2784)
C:\Program Files\Alwil Software\Avast5\AvastUI.exe (ID: 3660 |ParentID: 2784)
C:\Windows\system32\wbem\wmiprvse.exe (ID: 3928 |ParentID: 652)
C:\Program Files\Synaptics\SynTP\SynTPHelper.exe (ID: 3828 |ParentID: 2320)
C:\Program Files\iTunes\iTunesHelper.exe (ID: 3316 |ParentID: 2784)
C:\Windows\system32\SearchIndexer.exe (ID: 4036 |ParentID: 540)
C:\Program Files\Common Files\Java\Java Update\jusched.exe (ID: 3900 |ParentID: 2784)
C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe (ID: 2220 |ParentID: 2784)
C:\Users\Jean-Baptiste\AppData\Roaming\cacaoweb\cacaoweb.exe (ID: 2840 |ParentID: 2784)
C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe (ID: 2152 |ParentID: 2784)
C:\Program Files\Windows Media Player\wmpnetwk.exe (ID: 964 |ParentID: 540)
C:\Program Files\Hewlett-Packard\HP Quick Launch Buttons\Com4QLBEx.exe (ID: 3588 |ParentID: 540)
C:\Program Files\Hewlett-Packard\Shared\HpqToaster.exe (ID: 1044 |ParentID: 652)
C:\Users\Jean-Baptiste\AppData\Roaming\Dropbox\bin\Dropbox.exe (ID: 4056 |ParentID: 2784)
C:\Program Files\iPod\bin\iPodService.exe (ID: 3764 |ParentID: 540)
c:\Program Files\Hewlett-Packard\HP Health Check\hphc_service.exe (ID: 3144 |ParentID: 540)
C:\Windows\System32\svchost.exe (ID: 1664 |ParentID: 540)
C:\Program Files\HP\Digital Imaging\bin\hpqSTE08.exe (ID: 4176 |ParentID: 2152)
C:\Program Files\HP\Digital Imaging\bin\hpqbam08.exe (ID: 4248 |ParentID: 652)
C:\Program Files\HP\Digital Imaging\bin\hpqgpc01.exe (ID: 4384 |ParentID: 652)
C:\Windows\system32\svchost.exe (ID: 2376 |ParentID: 540)
C:\Program Files\Common Files\Java\Java Update\jucheck.exe (ID: 3036 |ParentID: 3900)
C:\Windows\system32\taskhost.exe (ID: 5320 |ParentID: 540)
C:\Program Files\Internet Explorer\iexplore.exe (ID: 4400 |ParentID: 2784)
C:\Program Files\Internet Explorer\iexplore.exe (ID: 4516 |ParentID: 4400)
C:\Program Files\Google\Google Toolbar\GoogleToolbarUser_32.exe (ID: 2188 |ParentID: 4400)
C:\Windows\System32\WUDFHost.exe (ID: 5416 |ParentID: 852)
C:\Users\Jean-Baptiste\AppData\Local\Google\Chrome\Application\chrome.exe (ID: 5668 |ParentID: 2784)
C:\Users\Jean-Baptiste\AppData\Local\Google\Chrome\Application\chrome.exe (ID: 4700 |ParentID: 5668)
C:\Users\Jean-Baptiste\AppData\Local\Google\Chrome\Application\chrome.exe (ID: 6052 |ParentID: 5668)
C:\Users\Jean-Baptiste\AppData\Local\Google\Chrome\Application\chrome.exe (ID: 5148 |ParentID: 5668)
C:\Users\Jean-Baptiste\AppData\Local\Google\Chrome\Application\chrome.exe (ID: 4656 |ParentID: 5668)
C:\Users\Jean-Baptiste\AppData\Local\Google\Chrome\Application\chrome.exe (ID: 1248 |ParentID: 5668)
C:\Windows\system32\ctfmon.exe (ID: 4556 |ParentID: 3660)
C:\Windows\system32\SearchProtocolHost.exe (ID: 4616 |ParentID: 4036)
C:\Windows\system32\SearchFilterHost.exe (ID: 4452 |ParentID: 4036)
C:\UsbFix\Go.exe (ID: 6080 |ParentID: 2928)
C:\Windows\system32\wbem\wmiprvse.exe (ID: 5756 |ParentID: 652)
################## | Regedit Run |
04 - HKLM\SOFTWARE | Run : [SynTPEnh] - C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
04 - HKLM\SOFTWARE | Run : [HP Health Check Scheduler] - c:\Program Files\Hewlett-Packard\HP Health Check\HPHC_Scheduler.exe
04 - HKLM\SOFTWARE | Run : [hpqSRMon] - C:\Program Files\HP\Digital Imaging\bin\hpqSRMon.exe
04 - HKLM\SOFTWARE | Run : [hpWirelessAssistant] - C:\Program Files\Hewlett-Packard\HP Wireless Assistant\HPWAMain.exe
04 - HKLM\SOFTWARE | Run : [NvCplDaemon] - RUNDLL32.EXE C:\Windows\system32\NvCpl.dll,NvStartup
04 - HKLM\SOFTWARE | Run : [QlbCtrl.exe] - C:\Program Files\Hewlett-Packard\HP Quick Launch Buttons\QlbCtrl.exe /Start
04 - HKLM\SOFTWARE | Run : [UpdateP2GoShortCut] - "C:\Program Files\CyberLink\Power2Go\MUITransfer\MUIStartMenu.exe" "C:\Program Files\CyberLink\Power2Go" UpdateWithCreateOnce "SOFTWARE\CyberLink\Power2Go\6.0"
04 - HKLM\SOFTWARE | Run : [UpdatePSTShortCut] - "C:\Program Files\CyberLink\DVD Suite\MUITransfer\MUIStartMenu.exe" "C:\Program Files\CyberLink\DVD Suite" UpdateWithCreateOnce "Software\CyberLink\PowerStarter"
04 - HKLM\SOFTWARE | Run : [PLFSetL] - C:\Windows\PLFSetL.exe
04 - HKLM\SOFTWARE | Run : [SNUVCDSM] - C:\Windows\snuvcdsm.exe
04 - HKLM\SOFTWARE | Run : [avast5] - "C:\Program Files\Alwil Software\Avast5\avastUI.exe" /nogui
04 - HKLM\SOFTWARE | Run : [QuickTime Task] - "C:\Program Files\QuickTime\QTTask.exe" -atboottime
04 - HKLM\SOFTWARE | Run : [iTunesHelper] - "C:\Program Files\iTunes\iTunesHelper.exe"
04 - HKLM\SOFTWARE | Run : [Adobe ARM] - "C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
04 - HKLM\SOFTWARE | Run : [SunJavaUpdateSched] - "C:\Program Files\Common Files\Java\Java Update\jusched.exe"
04 - HKLM\SOFTWARE | RunOnce : [] -
04 - HKU\S-1-5-19\SOFTWARE | Run : [Sidebar] - %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun
04 - HKU\S-1-5-20\SOFTWARE | Run : [Sidebar] - %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun
04 - HKU\S-1-5-21-222430623-1189483096-3784063953-1000\SOFTWARE | Run : [SpybotSD TeaTimer] - C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
04 - HKU\S-1-5-21-222430623-1189483096-3784063953-1000\SOFTWARE | Run : [Jean-Baptiste] - C:\Users\Jean-Baptiste\Jean-Baptiste.exe
04 - HKU\S-1-5-21-222430623-1189483096-3784063953-1000\SOFTWARE | Run : [WMPNSCFG] - C:\Program Files\Windows Media Player\WMPNSCFG.exe
04 - HKU\S-1-5-21-222430623-1189483096-3784063953-1000\SOFTWARE | Run : [TomTomHOME.exe] - "C:\Program Files\TomTom HOME 2\TomTomHOMERunner.exe"
04 - HKU\S-1-5-21-222430623-1189483096-3784063953-1000\SOFTWARE | Run : [RDReminder] -
04 - HKU\S-1-5-21-222430623-1189483096-3784063953-1000\SOFTWARE | Run : [Google Update] - "C:\Users\Jean-Baptiste\AppData\Local\Google\Update\GoogleUpdate.exe" /c
04 - HKU\S-1-5-21-222430623-1189483096-3784063953-1000\SOFTWARE | Run : [cacaoweb] - "C:\Users\Jean-Baptiste\AppData\Roaming\cacaoweb\cacaoweb.exe" -noplayer
04 - HKU\S-1-5-19\SOFTWARE | RunOnce : [mctadmin] - C:\Windows\System32\mctadmin.exe
04 - HKU\S-1-5-20\SOFTWARE | RunOnce : [mctadmin] - C:\Windows\System32\mctadmin.exe
04 - HKU\S-1-5-21-222430623-1189483096-3784063953-1000\SOFTWARE | RunOnce : [Application Restart #0] - C:\Users\Jean-Baptiste\AppData\Local\Google\Chrome\Application\chrome.exe --flag-switches-begin --flag-switches-end --restore-last-session --flag-switches-begin --flag-switches-end -- http://www.pewenvironment.org/uploadedF ... French.pdf" onclick="window.open(this.href);return false;
################## | Recherche générique |
Présent! D:\desktop.ini
################## | Registre |
Présent! HKU\S-1-5-21-222430623-1189483096-3784063953-1000\Software\Microsoft\Windows\CurrentVersion\Run|Jean-Baptiste
Présent! HKCU\Software\Microsoft\Windows\CurrentVersion\Run|Jean-Baptiste
################## | Vaccin |
(!) Cet ordinateur n'est pas vacciné!
################## | E.O.F | http://www.usbfix.net" onclick="window.open(this.href);return false; - http://www.sosvirus.net" onclick="window.open(this.href);return false; |