ça a enfin marché, merci pour votre patience.
voici le scan
############################## | UsbFix V 7.159 | [Suppression]
Utilisateur: Laura (Administrateur) # LAURA
Mis à jour le 06/01/2014 par El Desaparecido - Team SosVirus
Lancé à 19:11:56 | 06/01/2014
Site Web : http://www.usbfix.net" onclick="window.open(this.href);return false;
Changelog : http://www.usbfix.net/maj/" onclick="window.open(this.href);return false;
Support : http://www.sosvirus.net/" onclick="window.open(this.href);return false;
Upload Malware : http://www.sosvirus.net/upload_malware.php" onclick="window.open(this.href);return false;
Contact : http://www.usbfix.net/contact/" onclick="window.open(this.href);return false;
PC: SAMSUNG ELECTRONICS CO., LTD. (NP270E5E-X06FR)
CPU: Intel(R) Core(TM) i5-3230M CPU @ 2.60GHz
RAM -> [Total : 3798 Mo| Free : 2113 Mo]
Bios: Phoenix Technologies Ltd.
Boot: Normal boot
OS: Microsoft Windows 8 (6.2.9200 64-Bit)
WB: Windows Internet Explorer : 10.0.9200.16750
WB: Google Chrome : 31.0.1650.63
SC: Security Center Service [Enabled]
WU: Windows Update Service [(!) Disabled]
AV: Windows Defender [(!) Disabled | Updated]
AS: Windows Defender : 4.3.0215.0
FW: Windows FireWall Service [Enabled]
C:\ (%systemdrive%) -> Disque fixe # 673 Go (225 Go libre(s) - 33%) [] # NTFS
D:\ -> CD-ROM
E:\ -> Disque amovible # 4 Go (4 Go libre(s) - 98%) [USB DISK] # FAT32
F:\ -> Disque amovible # 2 Go (563 Mo libre(s) - 30%) [BSIX] # FAT
G:\ -> Disque amovible # 15 Go (14 Go libre(s) - 100%) [LAURA] # FAT32
################## | Processus Stoppés |
Stoppé! C:\windows\system32\nvvsvc.exe (ID: 972 |ParentID: 796)
Stoppé! C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe (ID: 1196 |ParentID: 972)
Stoppé! C:\windows\system32\nvvsvc.exe (ID: 1204 |ParentID: 972)
Stoppé! C:\windows\System32\spoolsv.exe (ID: 1724 |ParentID: 796)
Stoppé! C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe (ID: 1924 |ParentID: 796)
Stoppé! C:\Program Files (x86)\AskPartnerNetwork\Toolbar\apnmcp.exe (ID: 1944 |ParentID: 796)
Stoppé! C:\Program Files (x86)\Bluetooth Suite\adminservice.exe (ID: 1968 |ParentID: 796)
Stoppé! C:\Program Files (x86)\Samsung\Settings\CmdServer\EasyLauncher.exe (ID: 1228 |ParentID: 796)
Stoppé! C:\windows\system32\dashost.exe (ID: 1292 |ParentID: 1136)
Stoppé! C:\Program Files\Intel\iCLS Client\HeciServer.exe (ID: 1116 |ParentID: 796)
Stoppé! C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe (ID: 1276 |ParentID: 796)
Stoppé! C:\Program Files (x86)\Norton Internet Security\Engine\21.1.0.18\NIS.exe (ID: 1780 |ParentID: 796)
Stoppé! C:\Program Files\Microsoft Office 15\ClientX64\integratedoffice.exe (ID: 1904 |ParentID: 796)
Stoppé! C:\Users\Laura\AppData\Local\ValueApps\ValueApps.exe (ID: 2176 |ParentID: 796)
Stoppé! C:\Program Files (x86)\Wajam\Updater\WajamUpdaterV2.exe (ID: 2224 |ParentID: 796)
Stoppé! C:\Program Files (x86)\Bluetooth Suite\Ath_CoexAgent.exe (ID: 2412 |ParentID: 796)
Stoppé! C:\windows\system32\SearchIndexer.exe (ID: 3560 |ParentID: 796)
Stoppé! C:\Program Files (x86)\Samsung\Settings\CmdServer\EasySettingsCmdServer.exe (ID: 3904 |ParentID: 1228)
Stoppé! C:\Program Files\Synaptics\SynTP\SynTPEnh.exe (ID: 3988 |ParentID: 796)
Stoppé! C:\windows\system32\taskhostex.exe (ID: 3996 |ParentID: 796)
Stoppé! C:\Program Files (x86)\Samsung\Settings\sSettings.exe (ID: 4168 |ParentID: 796)
Stoppé! C:\Program Files\NVIDIA Corporation\Display\nvtray.exe (ID: 4644 |ParentID: 1196)
Stoppé! C:\Program Files (x86)\Norton Internet Security\Engine\21.1.0.18\NIS.exe (ID: 4896 |ParentID: 1780)
Stoppé! C:\Program Files\Samsung\S Agent\CommonAgent.exe (ID: 4572 |ParentID: 796)
Stoppé! C:\windows\system32\igfxext.exe (ID: 4536 |ParentID: 932)
Stoppé! C:\Program Files\WindowsApps\microsoft.windowscommunicationsapps_17.0.1119.516_x64__8wekyb3d8bbwe\LiveComm.exe (ID: 348 |ParentID: 932)
Stoppé! C:\Program Files (x86)\Adobe\Elements 11 Organizer\PhotoshopElementsFileAgent.exe (ID: 3540 |ParentID: 796)
Stoppé! C:\Windows\System32\RuntimeBroker.exe (ID: 1812 |ParentID: 932)
Stoppé! C:\Program Files (x86)\Bluetooth Suite\BtvStack.exe (ID: 2164 |ParentID: 4036)
Stoppé! C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe (ID: 576 |ParentID: 4036)
Stoppé! C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe (ID: 3520 |ParentID: 4036)
Stoppé! C:\Windows\System32\hkcmd.exe (ID: 1644 |ParentID: 4036)
Stoppé! C:\Windows\System32\igfxpers.exe (ID: 5280 |ParentID: 4036)
Stoppé! C:\Program Files (x86)\Intel\Intel(R) Integrated Clock Controller Service\ICCProxy.exe (ID: 5316 |ParentID: 796)
Stoppé! C:\Windows\System32\wscript.exe (ID: 5344 |ParentID: 4036)
Stoppé! C:\ProgramData\Updater\updater.exe (ID: 5360 |ParentID: 4036)
Stoppé! C:\windows\system32\RunDll32.exe (ID: 5380 |ParentID: 4036)
Stoppé! C:\Program Files (x86)\CyberLink\PowerDVD10\PDVD10Serv.exe (ID: 5452 |ParentID: 5368)
Stoppé! C:\Program Files\Microsoft Office 15\root\office15\ONENOTEM.EXE (ID: 5460 |ParentID: 4036)
Stoppé! C:\Program Files (x86)\CyberLink\Power2Go8\CLMLSvc_P2G8.exe (ID: 5508 |ParentID: 5368)
Stoppé! C:\ProgramData\RHelpers\ChromeHelper\ChromeHelper.exe (ID: 5624 |ParentID: 5360)
Stoppé! C:\ProgramData\RHelpers\FireFoxHelper\FireFoxHelper.exe (ID: 5656 |ParentID: 5360)
Stoppé! C:\ProgramData\RHelpers\IEHelper\IeHelper.exe (ID: 5720 |ParentID: 5656)
Stoppé! C:\Program Files (x86)\Samsung\Kies\KiesTrayAgent.exe (ID: 5820 |ParentID: 5368)
Stoppé! C:\Program Files (x86)\HP\HP Software Update\hpwuschd2.exe (ID: 5852 |ParentID: 5368)
Stoppé! C:\Program Files (x86)\AskPartnerNetwork\Toolbar\Updater\TBNotifier.exe (ID: 6120 |ParentID: 5368)
Stoppé! C:\Program Files (x86)\Mobogenie\DaemonProcess.exe (ID: 6128 |ParentID: 5368)
Stoppé! C:\PROGRAM FILES\SYNAPTICS\SYNTP\SYNTPHELPER.EXE (ID: 3784 |ParentID: 5264)
Stoppé! C:\Program Files\Internet Explorer\iexplore.exe (ID: 5052 |ParentID: 4036)
Stoppé! C:\Program Files (x86)\Internet Explorer\IEXPLORE.EXE (ID: 5884 |ParentID: 5052)
Stoppé! C:\Windows\System32\Macromed\Flash\FlashUtil_ActiveX.exe (ID: 6532 |ParentID: 932)
Stoppé! C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\FWService\IntelMeFWService.exe (ID: 6884 |ParentID: 796)
Stoppé! C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe (ID: 6996 |ParentID: 796)
Stoppé! C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\daemonu.exe (ID: 7012 |ParentID: 796)
Stoppé! C:\ProgramData\Samsung\SW Update Service\SWMAgent.exe (ID: 3200 |ParentID: 796)
Stoppé! C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe (ID: 7060 |ParentID: 796)
Stoppé! C:\Program Files\Windows Media Player\wmpnetwk.exe (ID: 3028 |ParentID: 796)
Stoppé! C:\Program Files\Samsung\Support Center\GuaranaAgent.exe (ID: 7160 |ParentID: 4572)
Stoppé! C:\windows\system32\wwahost.exe (ID: 6800 |ParentID: 932)
Stoppé! C:\Program Files (x86)\Intel\Intel(R) ME FW Recovery Agent\bin\ismagent.exe (ID: 1852 |ParentID: 1704)
Stoppé! C:\Program Files (x86)\Intel\Intel(R) ME FW Recovery Agent\bin\updateui.exe (ID: 2440 |ParentID: 1852)
Stoppé! C:\Windows\System32\WUDFHost.exe (ID: 208 |ParentID: 1136)
Stoppé! C:\windows\ImmersiveControlPanel\SystemSettings.exe (ID: 1656 |ParentID: 932)
################## | Regedit Run |
04 - HKLM\..\Run : [RemoteControl10] "C:\Program Files (x86)\CyberLink\PowerDVD10\PDVD10Serv.exe"
04 - HKLM\..\Run : [CLMLServer_For_P2G8] "C:\Program Files (x86)\CyberLink\Power2Go8\CLMLSvc_P2G8.exe"
04 - HKLM\..\Run : [CLVirtualDrive] "C:\Program Files (x86)\CyberLink\Power2Go8\VirtualDrive.exe" /R
04 - HKLM\..\Run : [Adobe Reader Speed Launcher] "C:\Program Files (x86)\Adobe\Reader 10.0\Reader\Reader_sl.exe"
04 - HKLM\..\Run : [Adobe ARM] "C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
04 - HKLM\..\Run : [KiesTrayAgent] C:\Program Files (x86)\Samsung\Kies\KiesTrayAgent.exe
04 - HKLM\..\Run : [HP Software Update] C:\Program Files (x86)\Hp\HP Software Update\HPWuSchd2.exe
04 - HKLM\..\Run : []
04 - HKLM\..\Run : [ApnTBMon] "C:\Program Files (x86)\AskPartnerNetwork\Toolbar\Updater\TBNotifier.exe"
04 - HKLM\..\Run : [mobilegeni daemon] C:\Program Files (x86)\Mobogenie\DaemonProcess.exe
04 - HKLM\..\Run : [Updater] C:\ProgramData\Updater\Updater.exe
04 - HKLM\..\RunOnce : []
04 - HKLM\..\Policies\Explorer\run : [BtvStack] "C:\Program Files (x86)\Bluetooth Suite\BtvStack.exe"
04 - HKLM64\..\Run : [RtHDVCpl] C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe -s
04 - HKLM64\..\Run : [RtHDVBg] C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe /S3HpProtect
04 - HKLM64\..\Run : [AdobeAAMUpdater-1.0] "C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe"
04 - HKLM64\..\Run : [Bitcasa] C:\Program Files\Bitcasa\Bitcasa.exe /startup
04 - HKLM64\..\Run : [IgfxTray] C:\windows\system32\igfxtray.exe
04 - HKLM64\..\Run : [HotKeysCmds] C:\windows\system32\hkcmd.exe
04 - HKLM64\..\Run : [Persistence] C:\windows\system32\igfxpers.exe
04 - HKLM64\..\Policies\Explorer\run : [BtvStack] "C:\Program Files (x86)\Bluetooth Suite\BtvStack.exe"
04 - HKU\S-1-5-21-2710196674-1561009495-2148570843-1002\..\Run : [iTunesHelper] wscript.exe //B "C:\Users\Laura\AppData\Local\Temp\iTunesHelper.vbe"
04 - HKU\S-1-5-21-2710196674-1561009495-2148570843-1002\..\Run : [Updater] C:\ProgramData\Updater\updater.exe
04 - HKU\S-1-5-21-2710196674-1561009495-2148570843-1002\..\RunOnce : [Uninstall C:\Users\Laura\AppData\Local\Microsoft\SkyDrive\16.4.6013.0910_1\amd64] C:\windows\system32\cmd.exe /q /c rmdir /s /q "C:\Users\Laura\AppData\Local\Microsoft\SkyDrive\16.4.6013.0910_1\amd64"
################## | Recherche générique |
Supprimé! C:\Users\Laura\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\iTunesHelper.vbe
Supprimé! C:\Users\Laura\AppData\Local\Temp\iTunesHelper.vbe
Supprimé! E:\iTunesHelper.vbe
Supprimé! F:\iTunesHelper.vbe
Supprimé! G:\iTunesHelper.vbe
Supprimé! E:\2003-2006, 2004-2007, 2005-2008.lnk
Supprimé! F:\Radiobiologie 2011.lnk
Supprimé! F:\RELATION COMMUNICATION.lnk
Supprimé! F:\SEMIOPATHOLOGIE.lnk
Supprimé! F:\PHYSIOLOGIE_PHARMACOLOGIE.lnk
Supprimé! F:\SOINS-HYGIENE.lnk
Supprimé! F:\RADIOBIOLOGIE.lnk
Supprimé! F:\METHODOLOGIE ERGONOMIE.lnk
Supprimé! F:\IMAGERIE MEDICALE.lnk
Supprimé! F:\PHYSIQUE_TECHNOLOGIE_RADIOPROTECTION.lnk
Supprimé! F:\Syst?me lymphatique_h?matologie.lnk
Supprimé! F:\Appareil respiratoire.lnk
Supprimé! F:\G?n?ralit?s en Radioth?rapie.lnk
Supprimé! F:\Physique Technologie.lnk
Supprimé! F:\Radiopharmacie 2011 bis.lnk
Supprimé! F:\cours IFMEM 2.lnk
Supprimé! F:\Révisions.lnk
Supprimé! F:\Travail de recherche immuno 2011.lnk
Supprimé! F:\CARDIOLOGIE IFMEM.lnk
Supprimé! F:\Magnétisme.lnk
Supprimé! F:\Neurophysiologie généralités.lnk
Supprimé! F:\Annales d'IRM.lnk
Supprimé! F:\Radiothérapie TG2 (2).lnk
Supprimé! F:\radio t.lnk
Supprimé! F:\CORRIGE RELATION DU 30 MARS 2011.lnk
Supprimé! F:\Anatomie digestive complet.lnk
Supprimé! F:\.Trashes.lnk
Supprimé! F:\.Spotlight-V100.lnk
Supprimé! F:\Système lymphatique_hématologie.lnk
Supprimé! F:\Généralités en Radiothérapie.lnk
Supprimé! F:\IRM.lnk
Supprimé! F:\organisation.lnk
Supprimé! F:\Physiologie_Pharmacologie 2°A.lnk
Supprimé! F:\neuro.lnk
Supprimé! F:\Imagerie médicale 2°A.lnk
Supprimé! F:\Sémiopathologie 2°A.lnk
Supprimé! F:\Radiothérapie 2°A.lnk
Supprimé! F:\Gestes et soins d'urgence 2°A.lnk
Supprimé! F:\Physique_Technologie 2°A.lnk
Supprimé! F:\Anatomie 2011.lnk
Supprimé! F:\EFSN.lnk
(!) Fichiers temporaires supprimés.
################## | Registre |
Réparé ! HKLM\Software\Microsoft\Windows\CurrentVersion\Policies\System|ConsentPromptBehaviorAdmin -> 5
Supprimé! HKU\S-1-5-21-2710196674-1561009495-2148570843-1002\Software\Microsoft\Windows\CurrentVersion\Run|Updater
Supprimé! HKLM\Software\Microsoft\Windows\CurrentVersion\Run|Updater
Supprimé! HKU\S-1-5-21-2710196674-1561009495-2148570843-1002\Software\Microsoft\Windows\CurrentVersion\Run|iTunesHelper
Supprimé! HKU\S-1-5-21-2710196674-1561009495-2148570843-1002\Software\.\.\.\.\Mountpoints2\{66bd5c61-17e8-11e3-be85-1867b08da7d5}
################## | Listing |
[06/09/2013 - 18:42:23 | SHD] - C:\$Recycle.Bin
[26/07/2012 - 04:44:30 | RASH | 389 Ko] - C:\bootmgr
[02/06/2012 - 15:30:55 | N | 0 Ko] - C:\BOOTNXT
[06/01/2014 - 17:11:13 | D] - C:\Config.Msi
[26/07/2012 - 08:22:08 | SHD] - C:\Documents and Settings
[14/11/2013 - 00:06:11 | N | 0 Ko] - C:\end
[06/01/2014 - 17:08:50 | ASH | 3110932 Ko] - C:\hiberfil.sys
[17/05/2013 - 03:20:30 | D] - C:\Intel
[17/05/2013 - 03:52:13 | N | 0 Ko] - C:\kiessetup.log
[21/10/2013 - 09:39:10 | D] - C:\Laura
[06/01/2014 - 17:08:52 | ASH | 720896 Ko] - C:\pagefile.sys
[26/07/2012 - 08:33:46 | D] - C:\PerfLogs
[04/01/2014 - 13:16:10 | D] - C:\Program Files
[04/01/2014 - 13:16:09 | D] - C:\Program Files (x86)
[06/01/2014 - 17:13:09 | HD] - C:\ProgramData
[17/05/2013 - 01:33:39 | N | 2 Ko] - C:\RHDSetup.log
[17/05/2013 - 01:35:43 | N | 0 Ko] - C:\setup.log
[17/05/2013 - 04:44:40 | D] - C:\sources
[06/01/2014 - 17:08:53 | ASH | 262144 Ko] - C:\swapfile.sys
[06/01/2014 - 17:05:18 | SHD] - C:\System Volume Information
[06/01/2014 - 19:11:58 | D] - C:\UsbFix
[06/01/2014 - 19:16:19 | A | 13 Ko | D23CCB8BB7796F7FABE876680ED86337] - C:\UsbFix [Clean 1] LAURA.txt
[06/09/2013 - 18:39:50 | D] - C:\Users
[04/01/2014 - 13:10:25 | D] - C:\ValueApps
[06/01/2014 - 17:26:01 | D] - C:\Windows
[28/08/2013 - 18:05:44 | D] - E:\2003-2006, 2004-2007, 2005-2008
[27/10/2011 - 14:43:28 | SHD] - F:\.Trashes
[27/10/2011 - 14:43:28 | SHD] - F:\.Spotlight-V100
[02/04/2012 - 15:40:54 | N | 43028 Ko] - F:\Radiopharmacie 2011 bis.ppt
[02/09/2011 - 13:54:04 | N | 185 Ko] - F:\cours IFMEM 2.ppt
[03/04/2012 - 13:53:00 | N | 4 Ko] - F:\Révisions.pdf
[06/12/2011 - 16:23:46 | N | 30 Ko] - F:\Travail de recherche immuno 2011.doc
[16/02/2011 - 15:43:36 | N | 2211 Ko] - F:\CARDIOLOGIE IFMEM.pdf
[11/05/2012 - 12:04:10 | D] - F:\PHYSIQUE_TECHNOLOGIE_RADIOPROTECTION
[11/05/2012 - 12:10:02 | D] - F:\Système lymphatique_hématologie
[11/05/2012 - 12:10:04 | D] - F:\Appareil respiratoire
[11/05/2012 - 12:10:30 | D] - F:\Généralités en Radiothérapie
[11/05/2012 - 12:10:52 | D] - F:\Physique Technologie
[02/01/2012 - 15:14:16 | N | 676 Ko] - F:\Magnétisme.pdf
[07/09/2012 - 11:24:46 | N | 777 Ko] - F:\Neurophysiologie généralités.pdf
[30/01/2013 - 13:00:32 | D] - F:\IRM
[24/02/2009 - 18:52:34 | N | 4644 Ko] - F:\Annales d'IRM.pdf
[11/04/2013 - 13:35:24 | D] - F:\organisation
[11/04/2013 - 13:36:52 | D] - F:\Physiologie_Pharmacologie 2°A
[11/04/2013 - 13:38:30 | D] - F:\neuro
[11/04/2013 - 13:38:44 | D] - F:\Imagerie médicale 2°A
[11/04/2013 - 13:40:14 | D] - F:\Sémiopathologie 2°A
[11/04/2013 - 13:40:40 | D] - F:\Radiothérapie 2°A
[11/04/2013 - 13:41:08 | D] - F:\Gestes et soins d'urgence 2°A
[11/04/2013 - 13:41:26 | D] - F:\Physique_Technologie 2°A
[11/04/2013 - 13:43:04 | D] - F:\Anatomie 2011
[11/04/2013 - 13:43:22 | D] - F:\Radiobiologie 2011
[11/04/2013 - 13:44:30 | D] - F:\RELATION COMMUNICATION
[11/04/2013 - 13:44:52 | D] - F:\SEMIOPATHOLOGIE
[11/04/2013 - 13:45:18 | D] - F:\PHYSIOLOGIE_PHARMACOLOGIE
[11/04/2013 - 13:45:42 | D] - F:\SOINS-HYGIENE
[11/04/2013 - 13:46:00 | D] - F:\RADIOBIOLOGIE
[11/04/2013 - 13:48:02 | D] - F:\METHODOLOGIE ERGONOMIE
[11/04/2013 - 13:49:04 | D] - F:\IMAGERIE MEDICALE
[12/04/2013 - 09:42:30 | N | 496 Ko] - F:\Radiothérapie TG2 (2).ppt
[12/04/2013 - 13:01:44 | N | 399 Ko] - F:\radio t.pdf
[12/04/2013 - 13:27:06 | N | 52 Ko] - F:\CORRIGE RELATION DU 30 MARS 2011.doc
[18/04/2013 - 12:09:20 | N | 884 Ko] - F:\Anatomie digestive complet.pdf
[24/05/2013 - 12:23:54 | D] - F:\EFSN
################## | Vaccin |
E:\Autorun.inf -> Vaccin créé par UsbFix (El Desaparecido)
F:\Autorun.inf -> Vaccin créé par UsbFix (El Desaparecido)
G:\Autorun.inf -> Vaccin créé par UsbFix (El Desaparecido)
################## | E.O.F | http://www.usbfix.net" onclick="window.open(this.href);return false; - http://www.sosvirus.net" onclick="window.open(this.href);return false; |