Voila le rapport de USB FIX : j'ai du me mettre en mode sans échec pour le faire.
############################## | UsbFix V 7.160 | [Suppression]
Utilisateur: Samy (Administrateur) # PCSAMY
Mis à jour le 11/01/2014 par El Desaparecido - Team SosVirus
Lancé à 18:12:03 | 11/01/2014
Site Web :
https://www.usbfix.net
Changelog :
https://www.usbfix.net/maj/
Support :
https://www.sosvirus.net/
Upload Malware :
https://www.sosvirus.net/upload_malware.php
Contact :
https://www.usbfix.net/contact/
PC: SAMSUNG ELECTRONICS CO., LTD. (530U3BI/530U4BI/530U4BH)
CPU: Intel(R) Core(TM) i5-2467M CPU @ 1.60GHz
RAM -> [Total : 3990 Mo| Free : 2898 Mo]
Bios: Phoenix Technologies Ltd.
Boot: Fail-safe with network boot
OS: Microsoft Windows 7 à‰dition Familiale Premium (6.1.7601 64-Bit) Service Pack 1
WB: Windows Internet Explorer : 11.0.9600.16476
WB: Google Chrome : 31.0.1650.63
SC: Security Center Service [Enabled]
WU: Windows Update Service [Enabled]
AV: Trend Micro Titanium Internet Security [(!) Disabled | Updated]
AS: Windows Defender : 6.1.7600.16385 (win7_rtm.090713-1255)
AS: Malwarebytes' Anti-Malware : 1.75.0001
FW: Windows FireWall Service [Enabled]
C:\ (%systemdrive%) -> Disque fixe # 444 Go (305 Go libre(s) - 69%) [] # NTFS
D:\ -> Disque amovible # 963 Mo (264 Mo libre(s) - 27%) [SAMY] # FAT32
################## | Processus Stoppés |
Stoppé! C:\windows\Explorer.EXE (ID: 1360 |ParentID: 1352)
Stoppé! C:\windows\system32\ctfmon.exe (ID: 1448 |ParentID: 1360)
Stoppé! C:\windows\system32\DllHost.exe (ID: 1836 |ParentID: 732)
################## | Regedit Run |
04 - HKLM\..\Run : [Norton Online Backup] C:\Program Files (x86)\Symantec\Norton Online Backup\NOBuClient.exe
04 - HKLM\..\Run : [Adobe ARM] "C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
04 - HKLM\..\Run : [APSDaemon] "C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe"
04 - HKLM\..\Run : [iTunesHelper] "C:\Program Files (x86)\iTunes\iTunesHelper.exe"
04 - HKLM\..\Run : [KiesTrayAgent] C:\Program Files (x86)\Samsung\Kies\KiesTrayAgent.exe
04 - HKLM\..\Run : [SunJavaUpdateSched] "C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe"
04 - HKLM\..\Run : [mobilegeni daemon] C:\Program Files (x86)\Mobogenie\DaemonProcess.exe
04 - HKLM\..\Run : [USB Security] C:\Program Files (x86)\USB Disk Security\USBGuard.exe
04 - HKLM\..\RunOnce : []
04 - HKLM64\..\Run : [IgfxTray] C:\windows\system32\igfxtray.exe
04 - HKLM64\..\Run : [HotKeysCmds] C:\windows\system32\hkcmd.exe
04 - HKLM64\..\Run : [Persistence] C:\windows\system32\igfxpers.exe
04 - HKLM64\..\Run : [RtHDVCpl] C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe -s
04 - HKLM64\..\Run : [IntelPAN] "C:\Program Files\Common Files\Intel\WirelessCommon\iFrmewrk.exe" /tf Intel PAN Tray
04 - HKLM64\..\Run : [FreeFallProtection] C:\Program Files (x86)\STMicroelectronics\Accelerometer\FF_Protection.exe
04 - HKLM64\..\Run : [ETDCtrl] %ProgramFiles%\Elantech\ETDCtrl.exe
04 - HKLM64\..\Run : [BTMTrayAgent] rundll32.exe "C:\Program Files (x86)\Intel\Bluetooth\btmshell.dll",TrayApp
04 - HKLM64\..\Run : [BCSSync] "C:\Program Files\Microsoft Office\Office14\BCSSync.exe" /DelayServices
04 - HKLM64\..\Run : [Trend Micro Titanium] "C:\Program Files\Trend Micro\Titanium\UIFramework\uiWinMgr.exe" -set Silent "1" SplashURL ""
04 - HKLM64\..\Run : [Trend Micro Client Framework] "C:\Program Files\Trend Micro\UniClient\UiFrmWrk\UIWatchDog.exe"
04 - HKU\S-1-5-19\..\Run : [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun
04 - HKU\S-1-5-20\..\Run : [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun
04 - HKU\S-1-5-21-454197360-789761907-2218566396-1000\..\Run : [uTorrent] "C:\Program Files (x86)\uTorrent\uTorrent.exe" /MINIMIZED
04 - HKU\S-1-5-21-454197360-789761907-2218566396-1000\..\Run : [Facebook Update] "C:\Users\Samy\AppData\Local\Facebook\Update\FacebookUpdate.exe" /c /nocrashserver
04 - HKU\S-1-5-21-454197360-789761907-2218566396-1000\..\Run : [OfficeSyncProcess] "C:\Program Files\Microsoft Office\Office14\MSOSYNC.EXE"
04 - HKU\S-1-5-21-454197360-789761907-2218566396-1000\..\Run : [KiesPreload] C:\Program Files (x86)\Samsung\Kies\Kies.exe /preload
04 - HKU\S-1-5-21-454197360-789761907-2218566396-1000\..\Run : [KiesAirMessage] C:\Program Files (x86)\Samsung\Kies\KiesAirMessage.exe -startup
04 - HKU\S-1-5-21-454197360-789761907-2218566396-1000\..\Run : [] C:\Program Files (x86)\Samsung\Kies\External\FirmwareUpdate\KiesPDLR.exe Run
04 - HKU\S-1-5-21-454197360-789761907-2218566396-1000\..\Run : [iTunesHelper] wscript.exe //B "C:\Users\Samy\AppData\Local\Temp\iTunesHelper.vbe"
04 - HKU\S-1-5-21-454197360-789761907-2218566396-1000\..\Run : [cacaoweb] "C:\Users\Samy\AppData\Roaming\cacaoweb\cacaoweb.exe" -noplayer
04 - HKU\S-1-5-19\..\RunOnce : [mctadmin] C:\Windows\System32\mctadmin.exe
04 - HKU\S-1-5-20\..\RunOnce : [mctadmin] C:\Windows\System32\mctadmin.exe
################## | Recherche générique |
(!) Fichiers temporaires supprimés.
################## | Registre |
Supprimé! HKU\S-1-5-21-454197360-789761907-2218566396-1000\Software\.\.\.\.\Mountpoints2\{8a98d9e0-7dce-11e2-8d02-88532ebf4f59}
Supprimé! HKU\S-1-5-21-454197360-789761907-2218566396-1000\Software\.\.\.\.\Mountpoints2\{b69383fb-95ff-11e2-b48e-88532ebf4f59}
################## | Listing |
[28/09/2012 - 23:56:19 | SHD] - C:\$Recycle.Bin
[01/10/2012 - 20:27:24 | D] - C:\37d87a0bcb264c7dcda50f04f5005bc7
[10/07/2013 - 00:04:27 | D] - C:\73a7620d686470b28afc845c
[11/01/2014 - 14:18:46 | D] - C:\AdwCleaner
[21/12/2013 - 19:54:01 | D] - C:\Config.Msi
[01/10/2012 - 06:20:23 | D] - C:\db673455d27370a665446ac7
[14/07/2009 - 06:08:56 | SHD] - C:\Documents and Settings
[07/11/2007 - 08:00:40 | N | 17 Ko | 9147A93F43D8E58218EBCB15FDA888C9] - C:\eula.1028.txt
[07/11/2007 - 08:00:40 | N | 17 Ko | 9147A93F43D8E58218EBCB15FDA888C9] - C:\eula.1031.txt
[07/11/2007 - 08:00:40 | N | 10 Ko | 99C22D4A31F4EAD4351B71D6F4E5F6A1] - C:\eula.1033.txt
[07/11/2007 - 08:00:40 | N | 17 Ko | 9147A93F43D8E58218EBCB15FDA888C9] - C:\eula.1036.txt
[07/11/2007 - 08:00:40 | N | 17 Ko | 9147A93F43D8E58218EBCB15FDA888C9] - C:\eula.1040.txt
[07/11/2007 - 08:00:40 | N | 0 Ko | 9B15A3A055CC6E67EA191A1B7885649A] - C:\eula.1041.txt
[07/11/2007 - 08:00:40 | N | 17 Ko | 9147A93F43D8E58218EBCB15FDA888C9] - C:\eula.1042.txt
[07/11/2007 - 08:00:40 | N | 17 Ko | 9147A93F43D8E58218EBCB15FDA888C9] - C:\eula.2052.txt
[07/11/2007 - 08:00:40 | N | 17 Ko | 9147A93F43D8E58218EBCB15FDA888C9] - C:\eula.3082.txt
[07/11/2007 - 08:00:40 | N | 1 Ko] - C:\globdata.ini
[28/09/2012 - 23:49:32 | ASH | 4086000 Ko] - C:\hiberfil.sys
[07/11/2007 - 08:44:20 | N | 835 Ko | E015A2D8890E2A96A93CA818F834C45B] - C:\install.exe
[07/11/2007 - 08:00:40 | N | 1 Ko] - C:\install.ini
[07/11/2007 - 08:44:20 | N | 74 Ko | 8F05FE39BDD336C8FA2A18EC3DFE418C] - C:\install.res.1028.dll
[07/11/2007 - 08:44:20 | N | 93 Ko | 7D9EBB7DCA62BA75361346CAF4EC196B] - C:\install.res.1031.dll
[07/11/2007 - 08:44:20 | N | 88 Ko | 43FB29E3A676D26FCBF0352207991523] - C:\install.res.1033.dll
[07/11/2007 - 08:44:20 | N | 94 Ko | 37C8A4717B40540816A3B92C470FD58F] - C:\install.res.1036.dll
[07/11/2007 - 08:44:20 | N | 92 Ko | 03576876C7E9A5B44EB7916492B5B0F6] - C:\install.res.1040.dll
[07/11/2007 - 08:44:20 | N | 79 Ko | A3946D3C9ED130AF89D1C1A9E63DEAA6] - C:\install.res.1041.dll
[07/11/2007 - 08:44:20 | N | 77 Ko | A5CFFE01D83AFECCD9590B4D696AA44E] - C:\install.res.1042.dll
[07/11/2007 - 08:44:20 | N | 73 Ko | 213BF3AD8A5F31C021BBE011D6460752] - C:\install.res.2052.dll
[07/11/2007 - 08:44:20 | N | 93 Ko | FACD045628070999B43EB7C13AB2E0FE] - C:\install.res.3082.dll
[27/12/2011 - 08:11:35 | D] - C:\Intel
[29/09/2012 - 00:40:34 | RHD] - C:\MSOCache
[11/01/2014 - 18:10:07 | ASH | 4086000 Ko] - C:\pagefile.sys
[14/07/2009 - 04:20:08 | D] - C:\PerfLogs
[09/01/2014 - 17:50:25 | D] - C:\Program Files
[11/01/2014 - 14:01:48 | D] - C:\Program Files (x86)
[11/01/2014 - 12:42:52 | HD] - C:\ProgramData
[28/09/2012 - 23:49:07 | SHD] - C:\Recovery
[27/12/2011 - 08:12:57 | N | 2 Ko] - C:\RHDSetup.log
[27/12/2011 - 09:27:50 | N | 0 Ko] - C:\setup.log
[11/01/2014 - 15:51:06 | SHD] - C:\System Volume Information
[20/12/2013 - 19:40:37 | D] - C:\temp
[20/12/2013 - 19:13:33 | D] - C:\TMRescueDisk
[11/01/2014 - 18:12:04 | D] - C:\UsbFix
[11/01/2014 - 18:07:35 | N | 11 Ko | B683777603C005FBEB7159E841F0AFDE] - C:\UsbFix [Clean 1] PCSAMY.txt
[11/01/2014 - 18:12:14 | A | 8 Ko | ED3D4B983CD3E0CB71918DADD611CC1E] - C:\UsbFix [Clean 2] PCSAMY.txt
[29/09/2012 - 17:52:47 | N | 0 Ko] - C:\user.js
[28/09/2012 - 23:49:41 | D] - C:\Users
[07/11/2007 - 08:00:40 | N | 6 Ko] - C:\vcredist.bmp
[07/11/2007 - 08:50:40 | N | 1883 Ko] - C:\VC_RED.cab
[07/11/2007 - 08:53:12 | N | 237 Ko] - C:\VC_RED.MSI
[11/01/2014 - 18:10:07 | D] - C:\Windows
[29/12/2013 - 19:18:29 | D] - C:\Wondershare_DrFone_Backup
[23/12/2009 - 12:41:34 | N | 716758 Ko] - D:\2012.avi
[11/01/2014 - 13:52:34 | RASHD] - D:\Autorun.inf
################## | Vaccin |
D:\Autorun.inf -> Vaccin créé par UsbFix (El Desaparecido)
################## | E.O.F |
https://www.usbfix.net -
https://www.sosvirus.net |