- ven. 4 oct. 2013 10:52
#10214
Salut à tous,
voilà j'ai le même virus dont tous le monde parle sur internet.... j'ai installé mon usb fix, dont voici le rapport, quelqu'un pourrait m'aider?
voilà j'ai le même virus dont tous le monde parle sur internet.... j'ai installé mon usb fix, dont voici le rapport, quelqu'un pourrait m'aider?
- Code: Tout sélectionner
############################## | UsbFix V 7.139 | [Recherche]
Utilisateur: Alhan (Administrateur) # ALHAN-PC
Mis à jour le 29/09/2013 par El Desaparecido - Team SosVirus
Lancé à 10:50:53 | 04/10/2013
Site Web: https://www.usbfix.net/
Forum : https://www.sosvirus.net/
Upload Malware: https://www.sosvirus.net/upload_malware.php
Contact: https://www.usbfix.net/contact/
PC: ASUSTeK Computer Inc. (N71Jq)
CPU: Intel(R) Core(TM) i7 CPU Q 720 @ 1.60GHz
RAM -> [Total : 4021 | Free : 1982]
Bios: American Megatrends Inc.
Boot: Normal boot
OS: Microsoft Windows 7 à‰dition Familiale Premium (6.1.7600 64-Bit) #
WB: Windows Internet Explorer 8.0.7600.16385
SC: Security Center Service [Enabled]
WU: Windows Update Service [Enabled]
AV: Avira Desktop [Enabled | Updated]
FW: Windows FireWall Service [Enabled]
C:\ (%systemdrive%) -> Disque fixe # 681 Go (141 Go libre(s) - 21%) [OS] # NTFS
D:\ -> Disque fixe # 298 Go (8 Go libre(s) - 3%) [] # NTFS
E:\ -> CD-ROM
F:\ -> Disque fixe # 298 Go (70 Go libre(s) - 23%) [] # NTFS
G:\ -> Disque amovible # 7 Go (7 Go libre(s) - 100%) [STORE N GO] # FAT32
################## | Processus Actif |
C:\Windows\system32\csrss.exe (ID 472 |ParentID 460)
C:\Windows\system32\wininit.exe (ID 536 |ParentID 460)
C:\Windows\system32\csrss.exe (ID 556 |ParentID 544)
C:\Windows\system32\services.exe (ID 592 |ParentID 536)
C:\Windows\system32\lsass.exe (ID 620 |ParentID 536)
C:\Windows\system32\lsm.exe (ID 628 |ParentID 536)
C:\Windows\system32\svchost.exe (ID 724 |ParentID 592)
C:\Windows\system32\winlogon.exe (ID 792 |ParentID 544)
C:\Windows\system32\svchost.exe (ID 852 |ParentID 592)
C:\Windows\system32\atiesrxx.exe (ID 912 |ParentID 592)
C:\Windows\System32\svchost.exe (ID 972 |ParentID 592)
C:\Windows\System32\svchost.exe (ID 1012 |ParentID 592)
C:\Windows\system32\svchost.exe (ID 144 |ParentID 592)
C:\Windows\system32\svchost.exe (ID 164 |ParentID 592)
C:\Windows\system32\svchost.exe (ID 1104 |ParentID 592)
C:\Windows\system32\atieclxx.exe (ID 1264 |ParentID 912)
C:\Windows\system32\FBAgent.exe (ID 1368 |ParentID 592)
C:\Program Files (x86)\ASUS\ATK Hotkey\ASLDRSrv.exe (ID 1392 |ParentID 592)
C:\Program Files\ATKGFNEX\GFNEXSrv.exe (ID 1432 |ParentID 592)
C:\Windows\System32\spoolsv.exe (ID 1528 |ParentID 592)
C:\Program Files (x86)\Avira\AntiVir Desktop\sched.exe (ID 1592 |ParentID 592)
C:\Windows\system32\svchost.exe (ID 1624 |ParentID 592)
C:\Program Files (x86)\Avira\AntiVir Desktop\avguard.exe (ID 1728 |ParentID 592)
C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe (ID 1764 |ParentID 592)
C:\Program Files\Bonjour\mDNSResponder.exe (ID 1936 |ParentID 592)
C:\Windows\system32\svchost.exe (ID 1984 |ParentID 592)
C:\Windows\SysWOW64\svchost.exe (ID 2012 |ParentID 592)
C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe (ID 2040 |ParentID 592)
C:\Program Files\ma-config.com\MaConfigAgent.exe (ID 1644 |ParentID 592)
C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamscheduler.exe (ID 432 |ParentID 592)
C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe (ID 2056 |ParentID 592)
C:\Program Files (x86)\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe (ID 2204 |ParentID 592)
C:\Windows\system32\svchost.exe (ID 2308 |ParentID 592)
C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE (ID 2384 |ParentID 592)
C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe (ID 2724 |ParentID 2384)
C:\Program Files (x86)\Avira\AntiVir Desktop\avshadow.exe (ID 3048 |ParentID 1728)
C:\Windows\system32\svchost.exe (ID 3588 |ParentID 592)
C:\Windows\system32\svchost.exe (ID 3712 |ParentID 592)
C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamgui.exe (ID 3676 |ParentID 2056)
C:\Windows\system32\Dwm.exe (ID 1828 |ParentID 1012)
C:\Windows\system32\taskhost.exe (ID 2524 |ParentID 592)
C:\Windows\Explorer.EXE (ID 3868 |ParentID 3768)
C:\Program Files (x86)\ASUS\ATK Hotkey\HControl.exe (ID 3616 |ParentID 1392)
C:\Windows\system32\taskeng.exe (ID 1584 |ParentID 144)
C:\Windows\system32\wbem\wmiprvse.exe (ID 3512 |ParentID 724)
C:\Program Files (x86)\ASUS\ASUS Live Update\ALU.exe (ID 3692 |ParentID 1584)
C:\Program Files (x86)\ASUS\Splendid\ACMON.exe (ID 1044 |ParentID 1584)
C:\Program Files (x86)\ASUS\SmartLogon\sensorsrv.exe (ID 2808 |ParentID 1584)
C:\Program Files\P4G\BatteryLife.exe (ID 3816 |ParentID 1584)
C:\Program Files (x86)\ASUS\ControlDeck\ControlDeckStartUp.exe (ID 3420 |ParentID 1584)
C:\Program Files (x86)\ASUS\ATK Hotkey\ATKOSD.exe (ID 3976 |ParentID 3616)
C:\Windows\SysWOW64\ACEngSvr.exe (ID 3268 |ParentID 724)
C:\Program Files (x86)\ASUS\ATK Hotkey\WDC.exe (ID 3436 |ParentID 3616)
C:\Program Files\Elantech\ETDCtrl.exe (ID 452 |ParentID 3868)
C:\Program Files (x86)\ASUS\ASUS WebStorage\SERVICE\AsusWSService.exe (ID 3404 |ParentID 3868)
C:\Program Files (x86)\AmIcoSingLun\AmIcoSinglun64.exe (ID 3972 |ParentID 3868)
C:\Windows\System32\wscript.exe (ID 3960 |ParentID 3868)
C:\Program Files (x86)\HP\Digital Imaging\bin\hpqtra08.exe (ID 4012 |ParentID 3868)
C:\Program Files\SRS Labs\SRS Premium Sound Control Panel\SRSPremiumPanel_64.exe (ID 3480 |ParentID 3868)
C:\Windows\system32\wbem\wmiprvse.exe (ID 3652 |ParentID 724)
C:\Program Files (x86)\ASUS\ATK Hotkey\HControlUser.exe (ID 4000 |ParentID 3096)
C:\Program Files (x86)\ASUS\ATK Media\DMedia.exe (ID 2444 |ParentID 3096)
C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\MOM.exe (ID 2336 |ParentID 1188)
C:\Program Files (x86)\ASUS\ATKOSD2\ATKOSD2.exe (ID 3628 |ParentID 3096)
C:\Program Files (x86)\NEC Electronics\USB 3.0 Host Controller Driver\Application\nusb3mon.exe (ID 3640 |ParentID 3096)
C:\Program Files (x86)\Avira\AntiVir Desktop\avgnt.exe (ID 3856 |ParentID 3096)
C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe (ID 3768 |ParentID 3096)
C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe (ID 1572 |ParentID 3096)
C:\Program Files (x86)\HP\HP Software Update\hpwuSchd2.exe (ID 2980 |ParentID 3096)
C:\Program Files (x86)\iTunes\iTunesHelper.exe (ID 560 |ParentID 3096)
C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CCC.exe (ID 4208 |ParentID 2336)
C:\Program Files\iPod\bin\iPodService.exe (ID 4908 |ParentID 592)
C:\Program Files\Windows Media Player\wmpnetwk.exe (ID 660 |ParentID 592)
C:\Program Files (x86)\HP\Digital Imaging\bin\hpqSTE08.exe (ID 4364 |ParentID 4012)
C:\Program Files (x86)\HP\Digital Imaging\bin\hpqbam08.exe (ID 4100 |ParentID 724)
C:\windows\Intel(TM)7z.exe (ID 4576 |ParentID 4556)
C:\Windows\AsScrPro.exe (ID 4712 |ParentID 1368)
C:\Program Files (x86)\HP\Digital Imaging\bin\hpqgpc01.exe (ID 4528 |ParentID 724)
C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe (ID 5080 |ParentID 1368)
C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe (ID 4168 |ParentID 592)
C:\Program Files (x86)\Common Files\Java\Java Update\jucheck.exe (ID 3820 |ParentID 3768)
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (ID 4876 |ParentID 3868)
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (ID 1452 |ParentID 4876)
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (ID 5948 |ParentID 4876)
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (ID 4532 |ParentID 4876)
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (ID 5740 |ParentID 4876)
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (ID 5648 |ParentID 4876)
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (ID 5340 |ParentID 4876)
C:\Windows\system32\WUDFHost.exe (ID 3536 |ParentID 1012)
C:\Windows\System32\svchost.exe (ID 1576 |ParentID 592)
C:\UsbFix\Go.exe (ID 4816 |ParentID 4236)
################## | Regedit Run |
HKLM\SOFTWARE | Run : [UpdatePSTShortCut] - "C:\Program Files (x86)\Cyberlink\DVD Suite\MUITransfer\MUIStartMenu.exe" "C:\Program Files (x86)\Cyberlink\DVD Suite" UpdateWithCreateOnce "Software\CyberLink\PowerStarter"
HKLM\SOFTWARE | Run : [StartCCC] - "C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" MSRun
HKLM\SOFTWARE | Run : [HControlUser] - C:\Program Files (x86)\ASUS\ATK Hotkey\HControlUser.exe
HKLM\SOFTWARE | Run : [ATKMEDIA] - C:\Program Files (x86)\ASUS\ATK Media\DMedia.exe
HKLM\SOFTWARE | Run : [ATKOSD2] - C:\Program Files (x86)\ASUS\ATKOSD2\ATKOSD2.exe
HKLM\SOFTWARE | Run : [NUSB3MON] - "C:\Program Files (x86)\NEC Electronics\USB 3.0 Host Controller Driver\Application\nusb3mon.exe"
HKLM\SOFTWARE | Run : [Setwallpaper] - c:\programdata\SetWallpaper.cmd
HKLM\SOFTWARE | Run : [avgnt] - "C:\Program Files (x86)\Avira\AntiVir Desktop\avgnt.exe" /min
HKLM\SOFTWARE | Run : [APSDaemon] - "C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe"
HKLM\SOFTWARE | Run : [SunJavaUpdateSched] - "C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe"
HKLM\SOFTWARE | Run : [Adobe ARM] - "C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
HKLM\SOFTWARE | Run : [Adobe Reader Speed Launcher] - "C:\Program Files (x86)\Adobe\Reader 9.0\Reader\Reader_sl.exe"
HKLM\SOFTWARE | Run : [HP Software Update] - C:\Program Files (x86)\HP\HP Software Update\HPWuSchd2.exe
HKLM\SOFTWARE | Run : [iTunesHelper] - "C:\Program Files (x86)\iTunes\iTunesHelper.exe"
HKLM\SOFTWARE | Run : [Intel(TM)7z] - "C:\windows\Intel(TM)7z.exe"
HKLM\SOFTWARE\wow6432Node | Run : [UpdatePSTShortCut] - "C:\Program Files (x86)\Cyberlink\DVD Suite\MUITransfer\MUIStartMenu.exe" "C:\Program Files (x86)\Cyberlink\DVD Suite" UpdateWithCreateOnce "Software\CyberLink\PowerStarter"
HKLM\SOFTWARE\wow6432Node | Run : [StartCCC] - "C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" MSRun
HKLM\SOFTWARE\wow6432Node | Run : [HControlUser] - C:\Program Files (x86)\ASUS\ATK Hotkey\HControlUser.exe
HKLM\SOFTWARE\wow6432Node | Run : [ATKMEDIA] - C:\Program Files (x86)\ASUS\ATK Media\DMedia.exe
HKLM\SOFTWARE\wow6432Node | Run : [ATKOSD2] - C:\Program Files (x86)\ASUS\ATKOSD2\ATKOSD2.exe
HKLM\SOFTWARE\wow6432Node | Run : [NUSB3MON] - "C:\Program Files (x86)\NEC Electronics\USB 3.0 Host Controller Driver\Application\nusb3mon.exe"
HKLM\SOFTWARE\wow6432Node | Run : [Setwallpaper] - c:\programdata\SetWallpaper.cmd
HKLM\SOFTWARE\wow6432Node | Run : [avgnt] - "C:\Program Files (x86)\Avira\AntiVir Desktop\avgnt.exe" /min
HKLM\SOFTWARE\wow6432Node | Run : [APSDaemon] - "C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe"
HKLM\SOFTWARE\wow6432Node | Run : [SunJavaUpdateSched] - "C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe"
HKLM\SOFTWARE\wow6432Node | Run : [Adobe ARM] - "C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
HKLM\SOFTWARE\wow6432Node | Run : [Adobe Reader Speed Launcher] - "C:\Program Files (x86)\Adobe\Reader 9.0\Reader\Reader_sl.exe"
HKLM\SOFTWARE\wow6432Node | Run : [HP Software Update] - C:\Program Files (x86)\HP\HP Software Update\HPWuSchd2.exe
HKLM\SOFTWARE\wow6432Node | Run : [iTunesHelper] - "C:\Program Files (x86)\iTunes\iTunesHelper.exe"
HKLM\SOFTWARE\wow6432Node | Run : [Intel(TM)7z] - "C:\windows\Intel(TM)7z.exe"
HKLM\SOFTWARE | RunOnce : [] -
HKLM\SOFTWARE\wow6432Node | RunOnce : [] -
HKU\S-1-5-21-2351134466-4085927225-1477360203-1000\SOFTWARE | Run : [Facebook Update] - "C:\Users\Alhan\AppData\Local\Facebook\Update\FacebookUpdate.exe" /c /nocrashserver
HKU\S-1-5-21-2351134466-4085927225-1477360203-1000\SOFTWARE | Run : [A7KGEquN] - wscript.exe //B "C:\Users\Alhan\AppData\Local\Temp\A7KGEquN.vbs"
################## | à‰léments infectieux |
Présent! G:\A7KGEquN.vbs
Présent! C:\Users\Alhan\AppData\Local\Temp\A7KGEquN.vbs
Présent! C:\Users\Alhan\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\A7KGEquN.vbs
Présent! G:\Autorun.inf.lnk
Présent! G:\P04-1708.lnk
Présent! C:\Users\Public\9eimmD.vbe
Présent! C:\Users\Public\9stiemD.VBE
Présent! C:\Users\Public\Intel(R)Graph.exe
Présent! C:\Users\Alhan\AppData\Local\Temp\iiiii9.hta
################## | Registre |
Présent! HKCU\Software\Microsoft\Windows\CurrentVersion\Run|A7KGEquN
Présent! HKCU\Software\Microsoft\Windows\CurrentVersion\Run|A7KGEquN
Présent! HKCU\Software\Microsoft\Windows\CurrentVersion\Run|A7KGEquN
Présent! HKLM\Software\Microsoft\Windows\CurrentVersion\Policies\System|DisableRegistryTools
################## | Vaccin |
C:\Autorun.inf -> Vaccin créé par UsbFix (El Desaparecido)
D:\Autorun.inf -> Vaccin créé par UsbFix (El Desaparecido)
F:\Autorun.inf -> Vaccin créé par UsbFix (El Desaparecido)
G:\Autorun.inf -> Vaccin créé par UsbFix (El Desaparecido)
################## | E.O.F | https://www.usbfix.net - https://www.sosvirus.net |