- dim. 20 oct. 2013 17:05
#12141
Voici le rapport UsbFix établi suite au scan de mon PC et d'une clef USB.
Pouvez-vous m'indiquer la marche à suivre.
Merci d'avance.
Pouvez-vous m'indiquer la marche à suivre.
Merci d'avance.
- Code: Tout sélectionner
############################## | UsbFix V 7.145 | [Recherche]
Utilisateur: User (Administrateur) # USER-PC
Mis à jour le 17/10/2013 par El Desaparecido - Team SosVirus
Lancé à 16:46:52 | 20/10/2013
Site Web: https://www.usbfix.net/
Forum : https://www.sosvirus.net/
Upload Malware: https://www.sosvirus.net/upload_malware.php
Contact: https://www.usbfix.net/contact/
PC: ASUSTeK Computer Inc. (K54C)
CPU: Intel(R) Core(TM) i3-2350M CPU @ 2.30GHz
RAM -> [Total : 4000 | Free : 2214]
Bios: American Megatrends Inc.
Boot: Normal boot
OS: Microsoft Windows 7 à‰dition Familiale Premium (6.1.7601 64-Bit) # Service Pack 1
WB: Windows Internet Explorer 10.0.9200.16721
SC: Security Center Service [Enabled]
WU: Windows Update Service [Enabled]
AV: Bitdefender Antivirus [Enabled | Updated]
FW: Windows FireWall Service [Enabled]
C:\ (%systemdrive%) -> Disque fixe # 186 Go (108 Go libre(s) - 58%) [OS] # NTFS
D:\ -> Disque fixe # 254 Go (210 Go libre(s) - 82%) [DATA] # NTFS
E:\ -> CD-ROM
F:\ -> Disque amovible # 958 Mo (932 Mo libre(s) - 97%) [] # FAT32
################## | Processus Actif |
C:\Windows\system32\csrss.exe (ID 600 |ParentID 488)
C:\Windows\system32\wininit.exe (ID 672 |ParentID 488)
C:\Windows\system32\csrss.exe (ID 696 |ParentID 680)
C:\Windows\system32\services.exe (ID 728 |ParentID 672)
C:\Windows\system32\lsass.exe (ID 756 |ParentID 672)
C:\Windows\system32\lsm.exe (ID 764 |ParentID 672)
C:\Windows\system32\winlogon.exe (ID 824 |ParentID 680)
C:\Windows\system32\svchost.exe (ID 912 |ParentID 728)
C:\Program Files\Bitdefender\Bitdefender 2012\vsserv.exe (ID 968 |ParentID 728)
C:\Windows\system32\svchost.exe (ID 1076 |ParentID 728)
C:\Windows\System32\svchost.exe (ID 1184 |ParentID 728)
C:\Windows\System32\svchost.exe (ID 1236 |ParentID 728)
C:\Windows\system32\svchost.exe (ID 1264 |ParentID 728)
C:\Windows\system32\svchost.exe (ID 1296 |ParentID 728)
C:\Windows\system32\svchost.exe (ID 1412 |ParentID 728)
C:\Windows\system32\svchost.exe (ID 1512 |ParentID 728)
C:\Windows\system32\FBAgent.exe (ID 1632 |ParentID 728)
C:\Windows\system32\WLANExt.exe (ID 1640 |ParentID 1236)
C:\Windows\system32\conhost.exe (ID 1648 |ParentID 600)
C:\Program Files (x86)\ASUS\ATK Package\ATK Hotkey\ASLDRSrv.exe (ID 1704 |ParentID 728)
C:\Program Files (x86)\ASUS\ATK Package\ATKGFNEX\GFNEXSrv.exe (ID 1764 |ParentID 728)
C:\Windows\System32\spoolsv.exe (ID 1896 |ParentID 728)
C:\Windows\system32\svchost.exe (ID 1940 |ParentID 728)
C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe (ID 1964 |ParentID 728)
C:\Windows\system32\taskhost.exe (ID 2196 |ParentID 728)
C:\Program Files\Bitdefender\Bitdefender 2012\bdagent.exe (ID 2228 |ParentID 2212)
C:\Windows\system32\Dwm.exe (ID 2304 |ParentID 1236)
C:\Windows\Explorer.EXE (ID 2360 |ParentID 2272)
C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe (ID 2564 |ParentID 728)
C:\Windows\system32\taskeng.exe (ID 2572 |ParentID 1296)
C:\Windows\system32\taskeng.exe (ID 2620 |ParentID 1296)
C:\Program Files (x86)\ASUS\Splendid\ACMON.exe (ID 2628 |ParentID 2572)
C:\Program Files (x86)\ASUS\FaceLogon\sensorsrv.exe (ID 2644 |ParentID 2572)
C:\Program Files\ASUS\P4G\BatteryLife.exe (ID 2700 |ParentID 2572)
C:\Program Files (x86)\ASUS\ATK Package\ATKOSD2\ATKOSD2.exe (ID 2712 |ParentID 2620)
C:\Windows\SysWOW64\ACEngSvr.exe (ID 2844 |ParentID 912)
C:\Program Files (x86)\ASUS\ATK Package\ATK Hotkey\HControl.exe (ID 2872 |ParentID 1704)
C:\Windows\System32\igfxtray.exe (ID 2944 |ParentID 2360)
C:\Program Files (x86)\ASUS\InstantOn for NB\InsOnSrv.exe (ID 2968 |ParentID 728)
C:\Program Files\Bonjour\mDNSResponder.exe (ID 3016 |ParentID 728)
C:\Windows\system32\svchost.exe (ID 3048 |ParentID 728)
C:\Program Files (x86)\PDF Architect\HelperService.exe (ID 2080 |ParentID 728)
C:\Windows\System32\hkcmd.exe (ID 116 |ParentID 2360)
C:\Windows\System32\igfxpers.exe (ID 2680 |ParentID 2360)
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe (ID 2140 |ParentID 2360)
C:\Program Files (x86)\PDF Architect\ConversionService.exe (ID 2128 |ParentID 728)
C:\Program Files (x86)\AmIcoSingLun\AmIcoSinglun64.exe (ID 3088 |ParentID 2360)
C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe (ID 3228 |ParentID 2360)
C:\Program Files (x86)\Skype\Phone\Skype.exe (ID 3304 |ParentID 2360)
C:\Program Files (x86)\Microsoft Office\Office14\MSOSYNC.EXE (ID 3332 |ParentID 2360)
C:\Program Files\Windows Sidebar\sidebar.exe (ID 3364 |ParentID 2360)
C:\Windows\System32\wscript.exe (ID 3392 |ParentID 2360)
C:\Windows\system32\svchost.exe (ID 3608 |ParentID 728)
C:\Program Files\Bitdefender\Bitdefender 2012\updatesrv.exe (ID 3648 |ParentID 728)
C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE (ID 3712 |ParentID 728)
C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe (ID 3940 |ParentID 3712)
C:\Windows\system32\svchost.exe (ID 2044 |ParentID 728)
C:\Program Files (x86)\Microsoft Office\Office14\ONENOTEM.EXE (ID 3580 |ParentID 2360)
C:\Windows\system32\SearchIndexer.exe (ID 4240 |ParentID 728)
C:\Program Files\Synaptics\SynTP\SynTPHelper.exe (ID 4456 |ParentID 2140)
C:\Windows\AsScrPro.exe (ID 4592 |ParentID 1632)
C:\Program Files (x86)\CyberLink\Power2Go\CLMLSvc.exe (ID 4720 |ParentID 1632)
C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe (ID 4884 |ParentID 1632)
C:\Windows\system32\wbem\wmiprvse.exe (ID 4976 |ParentID 912)
C:\Windows\system32\wbem\wmiprvse.exe (ID 4984 |ParentID 912)
C:\Program Files (x86)\ASUS\Sonic Focus\SonicFocusTray.exe (ID 5096 |ParentID 3400)
C:\Program Files (x86)\ASUS\ATK Package\ATK Media\DMedia.exe (ID 3468 |ParentID 3400)
C:\Program Files (x86)\ASUS\ATK Package\ATK Hotkey\HControlUser.exe (ID 4104 |ParentID 3400)
C:\Program Files (x86)\ASUS\Wireless Console 3\wcourier.exe (ID 3108 |ParentID 3400)
C:\Program Files (x86)\iTunes\iTunesHelper.exe (ID 3800 |ParentID 3400)
C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe (ID 3772 |ParentID 3400)
C:\Program Files\Windows Media Player\wmpnetwk.exe (ID 2020 |ParentID 728)
C:\Program Files\iPod\bin\iPodService.exe (ID 5396 |ParentID 728)
C:\Program Files (x86)\ASUS\InstantOn for NB\InsOnWMI.exe (ID 5736 |ParentID 2968)
C:\Program Files (x86)\ASUS\ATK Package\ATK Hotkey\ATKOSD.exe (ID 5964 |ParentID 2872)
C:\Program Files (x86)\ASUS\ATK Package\ATK Hotkey\KBFiltr.exe (ID 5516 |ParentID 2872)
C:\Program Files (x86)\ASUS\ATK Package\ATK Hotkey\WDC.exe (ID 5212 |ParentID 2872)
C:\Windows\System32\svchost.exe (ID 6556 |ParentID 728)
C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe (ID 6876 |ParentID 728)
C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe (ID 2608 |ParentID 728)
C:\Windows\system32\DllHost.exe (ID 1424 |ParentID 912)
C:\Windows\System32\WUDFHost.exe (ID 7004 |ParentID 1236)
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (ID 6984 |ParentID 3132)
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (ID 3756 |ParentID 6984)
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (ID 4968 |ParentID 6984)
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (ID 5024 |ParentID 6984)
C:\UsbFix\Go.exe (ID 8380 |ParentID 8352)
################## | Regedit Run |
HKLM\SOFTWARE | Run : [Nuance PDF Reader-reminder] - "C:\Program Files (x86)\Nuance\PDF Reader\Ereg\Ereg.exe" -r "C:\ProgramData\Nuance\PDF Reader\Ereg\Ereg.ini"
HKLM\SOFTWARE | Run : [ASUSWebStorage] - C:\Program Files (x86)\ASUS\ASUS WebStorage\3.0.108.222\AsusWSPanel.exe /S
HKLM\SOFTWARE | Run : [SonicMasterTray] - C:\Program Files (x86)\ASUS\Sonic Focus\SonicFocusTray.exe
HKLM\SOFTWARE | Run : [ATKOSD2] - C:\Program Files (x86)\ASUS\ATK Package\ATKOSD2\ATKOSD2.exe
HKLM\SOFTWARE | Run : [ATKMEDIA] - C:\Program Files (x86)\ASUS\ATK Package\ATK Media\DMedia.exe
HKLM\SOFTWARE | Run : [HControlUser] - C:\Program Files (x86)\ASUS\ATK Package\ATK Hotkey\HControlUser.exe
HKLM\SOFTWARE | Run : [Wireless Console 3] - C:\Program Files (x86)\ASUS\Wireless Console 3\wcourier.exe
HKLM\SOFTWARE | Run : [Adobe ARM] - "C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
HKLM\SOFTWARE | Run : [BCSSync] - "C:\Program Files (x86)\Microsoft Office\Office14\BCSSync.exe" /DelayServices
HKLM\SOFTWARE | Run : [APSDaemon] - "C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe"
HKLM\SOFTWARE | Run : [iTunesHelper] - "C:\Program Files (x86)\iTunes\iTunesHelper.exe"
HKLM\SOFTWARE | Run : [SunJavaUpdateSched] - "C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe"
HKLM\SOFTWARE\wow6432Node | Run : [Nuance PDF Reader-reminder] - "C:\Program Files (x86)\Nuance\PDF Reader\Ereg\Ereg.exe" -r "C:\ProgramData\Nuance\PDF Reader\Ereg\Ereg.ini"
HKLM\SOFTWARE\wow6432Node | Run : [ASUSWebStorage] - C:\Program Files (x86)\ASUS\ASUS WebStorage\3.0.108.222\AsusWSPanel.exe /S
HKLM\SOFTWARE\wow6432Node | Run : [SonicMasterTray] - C:\Program Files (x86)\ASUS\Sonic Focus\SonicFocusTray.exe
HKLM\SOFTWARE\wow6432Node | Run : [ATKOSD2] - C:\Program Files (x86)\ASUS\ATK Package\ATKOSD2\ATKOSD2.exe
HKLM\SOFTWARE\wow6432Node | Run : [ATKMEDIA] - C:\Program Files (x86)\ASUS\ATK Package\ATK Media\DMedia.exe
HKLM\SOFTWARE\wow6432Node | Run : [HControlUser] - C:\Program Files (x86)\ASUS\ATK Package\ATK Hotkey\HControlUser.exe
HKLM\SOFTWARE\wow6432Node | Run : [Wireless Console 3] - C:\Program Files (x86)\ASUS\Wireless Console 3\wcourier.exe
HKLM\SOFTWARE\wow6432Node | Run : [Adobe ARM] - "C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
HKLM\SOFTWARE\wow6432Node | Run : [BCSSync] - "C:\Program Files (x86)\Microsoft Office\Office14\BCSSync.exe" /DelayServices
HKLM\SOFTWARE\wow6432Node | Run : [APSDaemon] - "C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe"
HKLM\SOFTWARE\wow6432Node | Run : [iTunesHelper] - "C:\Program Files (x86)\iTunes\iTunesHelper.exe"
HKLM\SOFTWARE\wow6432Node | Run : [SunJavaUpdateSched] - "C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe"
HKLM\SOFTWARE | RunOnce : [] -
HKLM\SOFTWARE\wow6432Node | RunOnce : [] -
HKU\S-1-5-19\SOFTWARE | Run : [Sidebar] - %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun
HKU\S-1-5-20\SOFTWARE | Run : [Sidebar] - %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun
HKU\S-1-5-21-1747940908-1875828394-673419322-1000\SOFTWARE | Run : [Skype] - "C:\Program Files (x86)\Skype\Phone\Skype.exe" /minimized /regrun
HKU\S-1-5-21-1747940908-1875828394-673419322-1000\SOFTWARE | Run : [OfficeSyncProcess] - "C:\Program Files (x86)\Microsoft Office\Office14\MSOSYNC.EXE"
HKU\S-1-5-21-1747940908-1875828394-673419322-1000\SOFTWARE | Run : [Sidebar] - C:\Program Files\Windows Sidebar\sidebar.exe /autoRun
HKU\S-1-5-21-1747940908-1875828394-673419322-1000\SOFTWARE | Run : [dxrpdiag] - wscript.exe //B "C:\Users\User\AppData\Local\Temp\dxrpdiag.vbs"
HKU\S-1-5-19\SOFTWARE | RunOnce : [mctadmin] - C:\Windows\System32\mctadmin.exe
HKU\S-1-5-20\SOFTWARE | RunOnce : [mctadmin] - C:\Windows\System32\mctadmin.exe
################## | à‰léments infectieux |
Présent! F:\dxrpdiag.vbs
Présent! C:\Users\User\AppData\Local\Temp\dxrpdiag.vbs
Présent! C:\Users\User\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\dxrpdiag.vbs
Présent! F:\Autre.lnk
Présent! F:\Hygiène.lnk
Présent! F:\Chimie générale.lnk
################## | Registre |
Présent! HKU\S-1-5-21-1747940908-1875828394-673419322-1000\Software\Microsoft\Windows\CurrentVersion\Run|dxrpdiag
Présent! HKCU\Software\Microsoft\Windows\CurrentVersion\Run|dxrpdiag
Présent! HKU\S-1-5-21-1747940908-1875828394-673419322-1000\Software\Microsoft\Windows\CurrentVersion\Run|dxrpdiag
Présent! HKCU\Software\Microsoft\Windows\CurrentVersion\Run|dxrpdiag
Présent! HKU\S-1-5-21-1747940908-1875828394-673419322-1000\Software\Microsoft\Windows\CurrentVersion\Run|dxrpdiag
Présent! HKCU\Software\Microsoft\Windows\CurrentVersion\Run|dxrpdiag
################## | Vaccin |
(!) Cet ordinateur n'est pas vacciné!
################## | E.O.F | https://www.usbfix.net - https://www.sosvirus.net |