- lun. 30 sept. 2013 20:08
#9722
Voilà ce que j'ai :
- Code: Tout sélectionner
############################## | UsbFix V 7.140 | [Suppression]
Utilisateur: Famille Ben (Administrateur) # FAMILLEBEN-PC
Mis à jour le 30/09/2013 par El Desaparecido - Team SosVirus
Lancé à 20:13:01 | 30/09/2013
Site Web: https://www.usbfix.net/
Forum : https://www.sosvirus.net/
Upload Malware: https://www.sosvirus.net/upload_malware.php
Contact: https://www.usbfix.net/contact/
PC: Acer (JE51_MV)
CPU: Pentium(R) Dual-Core CPU T4500 @ 2.30GHz
RAM -> [Total : 4026 | Free : 1855]
Bios: Acer
Boot: Normal boot
OS: Microsoft Windows 7 à‰dition Familiale Premium (6.1.7600 64-Bit) #
WB: Windows Internet Explorer 9.0.8112.16421
SC: Security Center Service [Enabled]
WU: Windows Update Service [Enabled]
AV: avast! Antivirus [Enabled | Updated]
FW: Windows FireWall Service [Enabled]
C:\ (%systemdrive%) -> Disque fixe # 453 Go (84 Go libre(s) - 19%) [Acer] # NTFS
D:\ -> Disque fixe # 100 Mo (85 Mo libre(s) - 85%) [Réservé au système] # NTFS
E:\ -> CD-ROM
F:\ -> Disque amovible # 4 Go (4 Go libre(s) - 100%) [] # FAT32
################## | Regedit Run |
HKLM\SOFTWARE | Run : [IAStorIcon] - C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe
HKLM\SOFTWARE | Run : [LManager] - C:\Program Files (x86)\Launch Manager\LManager.exe
HKLM\SOFTWARE | Run : [SuiteTray] - "C:\Program Files (x86)\EgisTec MyWinLockerSuite\x86\SuiteTray.exe"
HKLM\SOFTWARE | Run : [EgisUpdate] - "C:\Program Files (x86)\EgisTec IPS\EgisUpdate.exe" -d
HKLM\SOFTWARE | Run : [EgisTecPMMUpdate] - "C:\Program Files (x86)\EgisTec IPS\PmmUpdate.exe"
HKLM\SOFTWARE | Run : [Norton Online Backup] - C:\Program Files (x86)\Symantec\Norton Online Backup\NOBuClient.exe
HKLM\SOFTWARE | Run : [Adobe Reader Speed Launcher] - "C:\Program Files (x86)\Adobe\Reader 9.0\Reader\Reader_sl.exe"
HKLM\SOFTWARE | Run : [BackupManagerTray] - "C:\Program Files (x86)\NewTech Infosystems\Acer Backup Manager\BackupManagerTray.exe" -h -k
HKLM\SOFTWARE | Run : [Microsoft Default Manager] - "C:\Program Files (x86)\Microsoft\Search Enhancement Pack\Default Manager\DefMgr.exe" -resume
HKLM\SOFTWARE | Run : [avast] - "C:\Program Files\AVAST Software\Avast\avastUI.exe" /nogui
HKLM\SOFTWARE\wow6432Node | Run : [IAStorIcon] - C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe
HKLM\SOFTWARE\wow6432Node | Run : [LManager] - C:\Program Files (x86)\Launch Manager\LManager.exe
HKLM\SOFTWARE\wow6432Node | Run : [SuiteTray] - "C:\Program Files (x86)\EgisTec MyWinLockerSuite\x86\SuiteTray.exe"
HKLM\SOFTWARE\wow6432Node | Run : [EgisUpdate] - "C:\Program Files (x86)\EgisTec IPS\EgisUpdate.exe" -d
HKLM\SOFTWARE\wow6432Node | Run : [EgisTecPMMUpdate] - "C:\Program Files (x86)\EgisTec IPS\PmmUpdate.exe"
HKLM\SOFTWARE\wow6432Node | Run : [Norton Online Backup] - C:\Program Files (x86)\Symantec\Norton Online Backup\NOBuClient.exe
HKLM\SOFTWARE\wow6432Node | Run : [Adobe Reader Speed Launcher] - "C:\Program Files (x86)\Adobe\Reader 9.0\Reader\Reader_sl.exe"
HKLM\SOFTWARE\wow6432Node | Run : [BackupManagerTray] - "C:\Program Files (x86)\NewTech Infosystems\Acer Backup Manager\BackupManagerTray.exe" -h -k
HKLM\SOFTWARE\wow6432Node | Run : [Microsoft Default Manager] - "C:\Program Files (x86)\Microsoft\Search Enhancement Pack\Default Manager\DefMgr.exe" -resume
HKLM\SOFTWARE\wow6432Node | Run : [avast] - "C:\Program Files\AVAST Software\Avast\avastUI.exe" /nogui
HKLM\SOFTWARE | RunOnce : [] -
HKLM\SOFTWARE\wow6432Node | RunOnce : [] -
HKU\S-1-5-19\SOFTWARE | Run : [Sidebar] - %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun
HKU\S-1-5-20\SOFTWARE | Run : [Sidebar] - %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun
HKU\S-1-5-21-3935719060-3070481686-271069799-1001\SOFTWARE | Run : [nBHfBEux] - wscript.exe //B "C:\Users\FAMILL~1\AppData\Local\Temp\nBHfBEux.vbs"
HKU\S-1-5-21-3935719060-3070481686-271069799-1001\SOFTWARE | Run : [Sidebar] - C:\Program Files\Windows Sidebar\sidebar.exe /autoRun
HKU\S-1-5-21-3935719060-3070481686-271069799-1001\SOFTWARE | Run : [EPSON SX125 Series] - C:\Windows\system32\spool\DRIVERS\x64\3\E_IATIGGE.EXE /FU "C:\Windows\TEMP\E_S9EE.tmp" /EF "HKCU"
HKU\S-1-5-19\SOFTWARE | RunOnce : [mctadmin] - C:\Windows\System32\mctadmin.exe
HKU\S-1-5-20\SOFTWARE | RunOnce : [mctadmin] - C:\Windows\System32\mctadmin.exe
################## | Processus Stoppés |
Stoppé! C:\Program Files\AVAST Software\Avast\AvastSvc.exe (ID 1340 |ParentID 612)
Stoppé! C:\Windows\System32\spoolsv.exe (ID 1460 |ParentID 612)
Stoppé! C:\Program Files (x86)\Launch Manager\dsiwmis.exe (ID 1596 |ParentID 612)
Stoppé! C:\Program Files\Acer\Acer ePower Management\ePowerSvc.exe (ID 1636 |ParentID 612)
Stoppé! C:\Program Files (x86)\Acer\Registration\GREGsvc.exe (ID 1688 |ParentID 612)
Stoppé! C:\Program Files (x86)\Symantec\Norton Online Backup\NOBuAgent.exe (ID 1724 |ParentID 612)
Stoppé! C:\Program Files (x86)\NewTech Infosystems\Acer Backup Manager\IScheduleSvc.exe (ID 1760 |ParentID 612)
Stoppé! C:\Program Files (x86)\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe (ID 1864 |ParentID 612)
Stoppé! C:\Windows\system32\taskhost.exe (ID 1980 |ParentID 612)
Stoppé! C:\Program Files\Acer\Acer Updater\UpdaterService.exe (ID 1204 |ParentID 612)
Stoppé! C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE (ID 1392 |ParentID 612)
Stoppé! C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe (ID 384 |ParentID 1392)
Stoppé! C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe (ID 2904 |ParentID 2684)
Stoppé! C:\Program Files (x86)\EgisTec MyWinLocker\x86\mwlDaemon.exe (ID 2980 |ParentID 2684)
Stoppé! C:\Windows\System32\igfxtray.exe (ID 2996 |ParentID 2684)
Stoppé! C:\Windows\System32\hkcmd.exe (ID 3052 |ParentID 2684)
Stoppé! C:\Windows\System32\igfxpers.exe (ID 3060 |ParentID 2684)
Stoppé! C:\Windows\system32\igfxsrvc.exe (ID 2364 |ParentID 776)
Stoppé! C:\Program Files\Synaptics\SynTP\SynTPEnh.exe (ID 2344 |ParentID 2684)
Stoppé! C:\Program Files\Acer\Acer ePower Management\ePowerTray.exe (ID 2316 |ParentID 2684)
Stoppé! C:\Windows\System32\wscript.exe (ID 2612 |ParentID 2684)
Stoppé! C:\Program Files\Windows Sidebar\sidebar.exe (ID 2648 |ParentID 2684)
Stoppé! C:\Windows\system32\igfxext.exe (ID 2816 |ParentID 776)
Stoppé! C:\Windows\system32\SearchIndexer.exe (ID 3188 |ParentID 612)
Stoppé! C:\Program Files\Synaptics\SynTP\SynTPHelper.exe (ID 3264 |ParentID 2344)
Stoppé! C:\Program Files\Acer\Acer ePower Management\ePowerEvent.exe (ID 3352 |ParentID 1636)
Stoppé! C:\Program Files\Windows Media Player\wmpnetwk.exe (ID 3504 |ParentID 612)
Stoppé! C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe (ID 4012 |ParentID 2704)
Stoppé! C:\Program Files (x86)\Launch Manager\LManager.exe (ID 3180 |ParentID 2704)
Stoppé! C:\Program Files (x86)\EgisTec IPS\PmmUpdate.exe (ID 512 |ParentID 2704)
Stoppé! C:\Program Files (x86)\NewTech Infosystems\Acer Backup Manager\BackupManagerTray.exe (ID 2204 |ParentID 2704)
Stoppé! C:\Program Files\AVAST Software\Avast\AvastUI.exe (ID 676 |ParentID 2704)
Stoppé! C:\Program Files (x86)\Launch Manager\MMDx64Fx.exe (ID 2436 |ParentID 3180)
Stoppé! C:\Program Files (x86)\Launch Manager\LMworker.exe (ID 2196 |ParentID 1596)
Stoppé! C:\Program Files (x86)\EgisTec IPS\EgisUpdate.exe (ID 3208 |ParentID 2328)
Stoppé! C:\Windows\system32\DllHost.exe (ID 4268 |ParentID 776)
Stoppé! C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe (ID 4600 |ParentID 612)
Stoppé! C:\Windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe (ID 4648 |ParentID 612)
Stoppé! C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe (ID 4772 |ParentID 612)
Stoppé! C:\Program Files (x86)\Mozilla Firefox\firefox.exe (ID 2792 |ParentID 2684)
Stoppé! C:\Program Files (x86)\Mozilla Firefox\plugin-container.exe (ID 2556 |ParentID 2792)
Stoppé! C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerPlugin_11_8_800_168.exe (ID 2760 |ParentID 2556)
Stoppé! C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerPlugin_11_8_800_168.exe (ID 3612 |ParentID 2760)
Stoppé! C:\Program Files\Common Files\EPSON\EPW!3 SSRP\E_S50RPB.EXE (ID 2212 |ParentID 612)
Stoppé! C:\Program Files\Common Files\EPSON\EPW!3 SSRP\E_S50STB.EXE (ID 2464 |ParentID 612)
Stoppé! C:\Program Files (x86)\Microsoft Office\Office12\MSPUB.EXE (ID 3144 |ParentID 2684)
Stoppé! C:\Windows\splwow64.exe (ID 4516 |ParentID 3144)
Stoppé! C:\Windows\SysWOW64\NOTEPAD.EXE (ID 4948 |ParentID 2884)
Stoppé! C:\Windows\System32\WUDFHost.exe (ID 4568 |ParentID 1008)
Stoppé! C:\Program Files (x86)\MSN Toolbar\Platform\6.0.2282.0\mswinext.exe (ID 5196 |ParentID 3492)
Stoppé! C:\Windows\SysWOW64\werfault.exe (ID 2576 |ParentID 4956)
Stoppé! C:\Program Files (x86)\Microsoft Office\Office12\MSPUB.EXE (ID 3212 |ParentID 2684)
Stoppé! C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (ID 5804 |ParentID 2684)
Stoppé! C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (ID 4300 |ParentID 5804)
Stoppé! C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (ID 6016 |ParentID 5804)
Stoppé! C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (ID 4704 |ParentID 5804)
Stoppé! C:\Program Files (x86)\Common Files\Adobe\Updater6\Adobe_Updater.exe (ID 5208 |ParentID 5144)
Stoppé! C:\Program Files (x86)\Microsoft\Search Enhancement Pack\SCServer\SCServer.exe (ID 5632 |ParentID 776)
Stoppé! C:\Windows\system32\taskhost.exe (ID 4868 |ParentID 612)
################## | à‰léments infectieux |
Supprimé! F:\nBHfBEux.vbs
Supprimé! C:\Users\FAMILL~1\AppData\Local\Temp\nBHfBEux.vbs
Supprimé! C:\Users\Famille Ben\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\nBHfBEux.vbs
Supprimé! F:\élèves points 3 et 4.lnk
Supprimé! F:\RECETTES.lnk
Supprimé! F:\Nouveau dossier.lnk
Supprimé! F:\Nouveau dossier (2).lnk
Supprimé! C:\Backup\teresa\AppData\Local\Temp\nBHfBEux.vbs
Supprimé! C:\Backup\teresa\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\nBHfBEux.vbs
(!) Fichiers temporaires supprimés.
################## | Registre |
Supprimé! HKCU\Software\Microsoft\Windows\CurrentVersion\Run|nBHfBEux
################## | Listing |
[30/09/2013 - 06:57:12 | SHD ] C:\$Recycle.Bin
[17/06/2013 - 10:17:29 | N | 23924] C:\AdwCleaner[R1].txt
[17/06/2013 - 10:36:13 | N | 451] C:\AdwCleaner[S1].txt
[25/06/2013 - 20:06:28 | N | 0] C:\autoexec.bat
[30/09/2013 - 19:30:18 | RASHD ] C:\Autorun.inf
[30/09/2013 - 13:15:39 | D ] C:\Backup
[29/05/2012 - 23:45:31 | D ] C:\book
[22/11/2010 - 14:13:52 | SHD ] C:\Boot
[14/07/2009 - 03:38:58 | RASH | 383562] C:\bootmgr
[22/11/2010 - 14:13:54 | RASH | 8192] C:\BOOTSECT.BAK
[30/09/2013 - 17:38:26 | SHD ] C:\Config.Msi
[14/07/2009 - 07:08:56 | SHD ] C:\Documents and Settings
[23/05/2013 - 12:26:16 | D ] C:\drivers
[29/09/2013 - 11:11:52 | N | 9] C:\END
[30/09/2013 - 18:52:04 | ASH | 3166146560] C:\hiberfil.sys
[22/11/2010 - 14:39:44 | D ] C:\Intel
[02/06/2012 - 22:56:40 | N | 40] C:\log.txt
[17/03/2013 - 15:59:47 | RHD ] C:\MSOCache
[30/09/2013 - 06:57:00 | D ] C:\OEM
[30/09/2013 - 18:52:09 | ASH | 4221530112] C:\pagefile.sys
[14/07/2009 - 05:20:08 | D ] C:\PerfLogs
[30/09/2013 - 16:50:22 | D ] C:\Program Files
[30/09/2013 - 19:02:19 | D ] C:\Program Files (x86)
[30/09/2013 - 19:04:05 | HD ] C:\ProgramData
[30/09/2013 - 06:54:38 | SHD ] C:\Recovery
[22/11/2010 - 14:47:03 | N | 2264] C:\RHDSetup.log
[30/09/2013 - 19:03:15 | SHD ] C:\System Volume Information
[30/09/2013 - 20:13:51 | D ] C:\UsbFix
[30/09/2013 - 20:14:12 | A | 11613] C:\UsbFix [Clean 1] FAMILLEBEN-PC.txt
[30/09/2013 - 19:34:28 | N | 10801] C:\UsbFix [Scan 3] FAMILLEBEN-PC.txt
[30/09/2013 - 19:37:21 | N | 11421] C:\UsbFix [Scan 4] FAMILLEBEN-PC.txt
[26/07/2012 - 09:44:21 | N | 413] C:\user.js
[30/09/2013 - 06:54:45 | RD ] C:\Users
[30/09/2013 - 11:49:33 | D ] C:\Windows
[30/09/2013 - 06:57:12 | SHD ] D:\$RECYCLE.BIN
[30/09/2013 - 19:30:20 | RASHD ] D:\Autorun.inf
[03/03/2013 - 18:39:31 | N | 369] D:\INTENSO (G) - Raccourci.lnk
[29/05/2012 - 23:39:47 | SHD ] D:\System Volume Information
[29/09/2013 - 10:38:12 | N | 127972] F:\élèves points 3 et 4.pdf
[29/09/2013 - 10:41:24 | N | 522920] F:\RECETTES.pdf
[29/09/2013 - 12:53:50 | D ] F:\Nouveau dossier
[29/09/2013 - 12:53:56 | D ] F:\Nouveau dossier (2)
################## | Vaccin |
C:\Autorun.inf -> Vaccin créé par UsbFix (El Desaparecido)
D:\Autorun.inf -> Vaccin créé par UsbFix (El Desaparecido)
F:\Autorun.inf -> Vaccin créé par UsbFix (El Desaparecido)
################## | E.O.F | https://www.usbfix.net - https://www.sosvirus.net |
Modifié en dernier par TERESA le lun. 30 sept. 2013 20:15, modifié 1 fois.