salut
merci pour l'aide
je ne retrouve pas le fichier de la recherche
je vous met le fichier de la suppression
############################## | UsbFix V 7.145 | [Suppression]
Utilisateur: Lindsay (Administrateur) # LINDSAY
Mis à jour le 17/10/2013 par El Desaparecido - Team SosVirus
Lancé à 20:59:31 | 20/10/2013
Site Web:
https://www.usbfix.net/
Forum :
https://www.sosvirus.net/
Upload Malware:
https://www.sosvirus.net/upload_malware.php
Contact:
https://www.usbfix.net/contact/
PC: AMD (PLCBX8)
CPU: AMD E1-1200 APU with Radeon(tm) HD Graphics
RAM -> [Total : 5731 | Free : 3536]
Bios: Insyde Corp.
Boot: Normal boot
OS: Microsoft Windows 8 (6.2.9200 64-Bit) #
WB: Windows Internet Explorer 10.0.9200.16721
SC: Security Center Service [Enabled]
WU: Windows Update Service [(!) Disabled]
AV: McAfee Anti-Virus et Anti-Spyware [Enabled | Updated]
FW: Windows FireWall Service [Enabled]
C:\ (%systemdrive%) -> Disque fixe # 288 Go (236 Go libre(s) - 82%) [TI30993600A] # NTFS
D:\ -> CD-ROM
E:\ -> Disque fixe # 168 Go (168 Go libre(s) - 100%) [] # NTFS
F:\ -> Disque amovible # 8 Go (7 Go libre(s) - 99%) [TRANSCEND] # FAT32
################## | Regedit Run |
HKLM\SOFTWARE | Run : [Intel AppUp(SM) center] - "C:\Program Files (x86)\Intel\IntelAppStore\bin\ismagent.exe" --domain-id F0399437-FD0C-4A48-B101-F0314A6172E4
HKLM\SOFTWARE | Run : [ToshibaDynamicIconUtility] - "C:\Program Files\TOSHIBA\TOSHIBA Places Icon Utility\TosDIMonitor.exe"
HKLM\SOFTWARE | Run : [StartCCC] - "C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" MSRun
HKLM\SOFTWARE | Run : [TPUReg(x86)] - "C:\Program Files\TOSHIBA\Password Utility\TosPU.exe" /Retimes
HKLM\SOFTWARE | Run : [TPUReg] - "C:\Program Files (x86)\TOSHIBA\Password Utility\TosPU.exe" /Retimes
HKLM\SOFTWARE | Run : [SunJavaUpdateSched] - "C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe"
HKLM\SOFTWARE | Run : [Adobe ARM] - "C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
HKLM\SOFTWARE | Run : [mcpltui_exe] - "C:\Program Files\McAfee.com\Agent\mcagent.exe" /runkey
HKLM\SOFTWARE\wow6432Node | Run : [Intel AppUp(SM) center] - "C:\Program Files (x86)\Intel\IntelAppStore\bin\ismagent.exe" --domain-id F0399437-FD0C-4A48-B101-F0314A6172E4
HKLM\SOFTWARE\wow6432Node | Run : [ToshibaDynamicIconUtility] - "C:\Program Files\TOSHIBA\TOSHIBA Places Icon Utility\TosDIMonitor.exe"
HKLM\SOFTWARE\wow6432Node | Run : [StartCCC] - "C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" MSRun
HKLM\SOFTWARE\wow6432Node | Run : [TPUReg(x86)] - "C:\Program Files\TOSHIBA\Password Utility\TosPU.exe" /Retimes
HKLM\SOFTWARE\wow6432Node | Run : [TPUReg] - "C:\Program Files (x86)\TOSHIBA\Password Utility\TosPU.exe" /Retimes
HKLM\SOFTWARE\wow6432Node | Run : [SunJavaUpdateSched] - "C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe"
HKLM\SOFTWARE\wow6432Node | Run : [Adobe ARM] - "C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
HKLM\SOFTWARE\wow6432Node | Run : [mcpltui_exe] - "C:\Program Files\McAfee.com\Agent\mcagent.exe" /runkey
HKLM\SOFTWARE | RunOnce : [] -
HKLM\SOFTWARE\wow6432Node | RunOnce : [] -
HKU\S-1-5-21-2333576209-3530835589-3710937388-1001\SOFTWARE | Run : [Intel(R)TCP] - C:\Users\Public\Intel(R)TCP.exe
HKU\S-1-5-21-2333576209-3530835589-3710937388-1001\SOFTWARE | Run : [iTunesHelper] - wscript.exe //B "C:\Users\Lindsay\AppData\Local\Temp\iTunesHelper.vbe"
HKU\S-1-5-21-2333576209-3530835589-3710937388-1001\SOFTWARE | Run : [RESTART_STICKY_NOTES] - C:\Windows\System32\StikyNot.exe
################## | Processus Stoppés |
Stoppé! C:\windows\system32\atiesrxx.exe (ID 1012 |ParentID 800)
Stoppé! C:\windows\system32\WLANExt.exe (ID 1328 |ParentID 1104)
Stoppé! C:\Program Files (x86)\TOSHIBA\Password Utility\GFNEXSrv.exe (ID 1336 |ParentID 800)
Stoppé! C:\windows\System32\spoolsv.exe (ID 1616 |ParentID 800)
Stoppé! C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe (ID 1852 |ParentID 800)
Stoppé! C:\windows\system32\dashost.exe (ID 1916 |ParentID 1104)
Stoppé! c:\PROGRA~2\mcafee\SITEAD~1\mcsacore.exe (ID 1948 |ParentID 800)
Stoppé! C:\Program Files\McAfee\MSC\McAPExe.exe (ID 1984 |ParentID 800)
Stoppé! C:\Program Files\McAfee\AppStats\MfeASUM.exe (ID 2004 |ParentID 800)
Stoppé! C:\windows\system32\mfevtps.exe (ID 2036 |ParentID 800)
Stoppé! C:\Windows\system32\TODDSrv.exe (ID 1660 |ParentID 800)
Stoppé! C:\Program Files\Common Files\McAfee\AMCore\mcshield.exe (ID 2112 |ParentID 800)
Stoppé! C:\Program Files\Common Files\McAfee\SystemCore\mfefire.exe (ID 2212 |ParentID 800)
Stoppé! C:\Program Files\TOSHIBA\Teco\TecoService.exe (ID 2332 |ParentID 800)
Stoppé! C:\Program Files\Common Files\McAfee\Platform\McSvcHost\McSvHost.exe (ID 2940 |ParentID 800)
Stoppé! C:\windows\system32\SearchIndexer.exe (ID 3908 |ParentID 800)
Stoppé! C:\Program Files (x86)\McAfee Online Backup\MOBKbackup.exe (ID 2608 |ParentID 800)
Stoppé! C:\Program Files (x86)\Nero\Update\NASvc.exe (ID 4912 |ParentID 800)
Stoppé! C:\Program Files\TOSHIBA\TPHM\TPCHSrv.exe (ID 4044 |ParentID 800)
Stoppé! C:\Program Files\TOSHIBA\TOSHIBA Service Station\TMachInfo.exe (ID 4628 |ParentID 800)
Stoppé! C:\windows\Microsoft.Net\Framework64\v3.0\WPF\PresentationFontCache.exe (ID 2152 |ParentID 800)
Stoppé! C:\windows\system32\atieclxx.exe (ID 3336 |ParentID 1012)
Stoppé! C:\windows\system32\rundll32.exe (ID 4480 |ParentID 1948)
Stoppé! C:\windows\system32\rundll32.exe (ID 2148 |ParentID 1948)
Stoppé! C:\windows\SysWOW64\rundll32.exe (ID 5036 |ParentID 4480)
Stoppé! C:\Program Files\Synaptics\SynTP\SynTPEnh.exe (ID 4272 |ParentID 800)
Stoppé! C:\windows\system32\taskhostex.exe (ID 4856 |ParentID 800)
Stoppé! C:\Program Files\Common Files\McAfee\Platform\mcuicnt.exe (ID 5168 |ParentID 5452)
Stoppé! C:\windows\Explorer.EXE (ID 5600 |ParentID 1672)
Stoppé! C:\Program Files\WindowsApps\microsoft.windowscommunicationsapps_17.0.1114.318_x64__8wekyb3d8bbwe\LiveComm.exe (ID 4460 |ParentID 904)
Stoppé! C:\Windows\System32\RuntimeBroker.exe (ID 5780 |ParentID 904)
Stoppé! C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe (ID 4464 |ParentID 5600)
Stoppé! C:\PROGRAM FILES\SYNAPTICS\SYNTP\SYNTPHELPER.EXE (ID 3600 |ParentID 4604)
Stoppé! C:\Program Files\TOSHIBA\Hotkey\TCrdMain_Win8.exe (ID 2488 |ParentID 5600)
Stoppé! C:\Program Files\TOSHIBA\Teco\TecoResident.exe (ID 4508 |ParentID 5600)
Stoppé! C:\Program Files\TOSHIBA\TPHM\TPCHWMsg.exe (ID 328 |ParentID 4148)
Stoppé! C:\Windows\System32\wscript.exe (ID 5864 |ParentID 5600)
Stoppé! C:\windows\SysWOW64\explorer.exe (ID 6140 |ParentID 3460)
Stoppé! C:\Users\Public\Intel(R)TCP.exe (ID 5800 |ParentID 3460)
Stoppé! C:\Windows\System32\StikyNot.exe (ID 3340 |ParentID 5600)
Stoppé! C:\Users\Public\Intel(R)TCP.exe (ID 5872 |ParentID 3104)
Stoppé! C:\Program Files\McAfee Security Scan\3.8.130\SSScheduler.exe (ID 1672 |ParentID 5600)
Stoppé! C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe (ID 2960 |ParentID 3688)
Stoppé! C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe (ID 3324 |ParentID 3688)
Stoppé! C:\windows\SysWOW64\explorer.exe (ID 2460 |ParentID 1864)
Stoppé! C:\windows\SysWOW64\explorer.exe (ID 4088 |ParentID 5908)
Stoppé! C:\Users\Public\Intel(R)Pl5.exe (ID 2820 |ParentID 1864)
Stoppé! C:\Program Files\TOSHIBA\Toshiba Service Station\ToshibaServiceStation.exe (ID 7032 |ParentID 800)
Stoppé! C:\PROGRA~1\COMMON~1\McAfee\Platform\MSM\McSmtFwk.exe (ID 6396 |ParentID 6484)
Stoppé! C:\PROGRA~1\COMMON~1\McAfee\Platform\McUICnt.exe (ID 3460 |ParentID 6484)
Stoppé! c:\PROGRA~1\mcafee.com\agent\McUpdate.exe (ID 7088 |ParentID 2940)
Stoppé! c:\PROGRA~1\mcafee\msc\mcupdmgr.exe (ID 1424 |ParentID 904)
Stoppé! c:\PROGRA~1\mcafee\mqs\qcshm.exe (ID 5484 |ParentID 904)
Stoppé! C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\MOM.exe (ID 6248 |ParentID 4492)
Stoppé! C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CCC.exe (ID 528 |ParentID 6248)
Stoppé! C:\Program Files\Common Files\McAfee\Platform\Core\mchost.exe (ID 5880 |ParentID 2940)
Stoppé! C:\Program Files\McAfee\VirusScan\mcods.exe (ID 5380 |ParentID 800)
Stoppé! C:\Program Files (x86)\Mozilla Firefox\firefox.exe (ID 3736 |ParentID 5600)
Stoppé! C:\Program Files (x86)\Mozilla Firefox\plugin-container.exe (ID 7580 |ParentID 3736)
Stoppé! C:\Program Files (x86)\Mozilla Firefox\plugin-container.exe (ID 8092 |ParentID 3736)
Stoppé! C:\windows\SysWOW64\Macromed\Flash\FlashPlayerPlugin_11_9_900_117.exe (ID 5596 |ParentID 8092)
Stoppé! C:\windows\SysWOW64\Macromed\Flash\FlashPlayerPlugin_11_9_900_117.exe (ID 1216 |ParentID 5596)
Stoppé! c:\PROGRA~2\mcafee\SITEAD~1\saui.exe (ID 5904 |ParentID 904)
Stoppé! C:\Windows\System32\WUDFHost.exe (ID 5656 |ParentID 1104)
Stoppé! C:\windows\SysWOW64\NOTEPAD.EXE (ID 5912 |ParentID 1668)
################## | à‰léments infectieux |
Supprimé! F:\iTunesHelper.vbe
Supprimé! C:\Users\Lindsay\AppData\Local\Temp\iTunesHelper.vbe
Supprimé! C:\Users\Lindsay\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Intel(R)TCP.exe
Supprimé! C:\Users\Lindsay\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\iTunesHelper.vbe
Supprimé! C:\Users\Lindsay\AppData\Roaming\0C388F8C\ak.tmp
Supprimé! C:\Users\Lindsay\AppData\Roaming\0C388F8C
Supprimé! C:\Users\Public\4zz.VBE
Supprimé! C:\Users\Public\4zzz.VBE
Supprimé! C:\Users\Public\7zz.VBE
Supprimé! C:\Users\Public\7zzz.VBE
Supprimé! C:\Users\Public\9eizmmD.vbe
Supprimé! C:\Users\Public\9stziemD.VBE
Supprimé! C:\Users\Public\Intel(R)Pl5.exe
Supprimé! C:\Users\Public\Intel(R)TCP.exe
Supprimé! C:\Users\Public\Intel(TM)SD.exe
Supprimé! C:\Users\Lindsay\AppData\Roaming\Lindsay-wchelper.dll
Supprimé! C:\Users\Lindsay\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\iz710bclD.lnk
Supprimé! C:\Users\Lindsay\AppData\Local\Temp\Lindsay8
Supprimé! C:\Users\Lindsay\AppData\Local\Temp\jusched.pif
Supprimé! C:\Users\Lindsay\AppData\Local\Temp\Musiques.pif
Supprimé! C:\Users\Lindsay\AppData\Local\Temp\Skype.pif
Supprimé! C:\Users\Lindsay\AppData\Local\Temp\A7KGEquN.vbs
Supprimé! C:\Users\Lindsay\AppData\Local\Temp\09a.hta
Supprimé! C:\Users\Lindsay\AppData\Local\Temp\452CG4.hta
Supprimé! C:\Users\Lindsay\AppData\Local\Temp\ddvG4.hta
Supprimé! C:\Users\Lindsay\AppData\Local\Temp\dggg.hta
Supprimé! C:\Users\Lindsay\AppData\Local\Temp\s15g.hta
Supprimé! C:\Users\Lindsay\AppData\Local\Temp\vf01.hta
Supprimé! C:\Users\Lindsay\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\2NF8D2CM\Skype[1].pif
(!) Fichiers temporaires supprimés.
################## | Registre |
Supprimé! HKU\S-1-5-21-2333576209-3530835589-3710937388-1001\Software\Microsoft\Windows\CurrentVersion\Run|iTunesHelper
Supprimé! HKU\S-1-5-21-2333576209-3530835589-3710937388-1001\Software\Microsoft\Windows\CurrentVersion\Run|Intel(R)TCP
Supprimé! HKLM\Software\Microsoft\Windows\CurrentVersion\Policies\System|DisableRegistryTools
Supprimé! HKLM\Software\Microsoft\Windows\CurrentVersion\Policies\System|DisableTaskMgr
################## | Listing |
[26/03/2013 - 17:31:54 | SHD ] C:\$RECYCLE.BIN
[12/10/2013 - 19:59:04 | D ] C:\204aec25a917df7819
[17/09/2013 - 12:43:08 | D ] C:\927bd58d0f94af1ab7db5a
[13/07/2013 - 19:02:03 | D ] C:\ab60068568bbf07e6633a7ea
[18/08/2013 - 19:51:59 | D ] C:\b69b777beff55aff2df3977c634dc8
[28/06/2013 - 18:36:29 | D ] C:\bcb2de7f3897140a3402190791
[26/07/2012 - 05:44:30 | RASH | 398156] C:\bootmgr
[02/06/2012 - 16:30:55 | N | 1] C:\BOOTNXT
[20/10/2013 - 18:44:28 | SHD ] C:\Config.Msi
[26/07/2012 - 09:22:08 | SHD ] C:\Documents and Settings
[20/10/2013 - 11:04:55 | ASH | 4807725056] C:\hiberfil.sys
[10/05/2013 - 10:32:27 | D ] C:\HP_ePrint_Mobile
[03/04/2013 - 22:16:35 | RHD ] C:\MSOCache
[20/10/2013 - 11:04:56 | ASH | 939524096] C:\pagefile.sys
[26/07/2012 - 09:33:46 | D ] C:\PerfLogs
[20/10/2013 - 18:44:25 | D ] C:\Program Files
[20/10/2013 - 18:44:25 | D ] C:\Program Files (x86)
[17/07/2013 - 14:26:50 | HD ] C:\ProgramData
[31/03/2013 - 23:36:26 | D ] C:\sources
[20/10/2013 - 11:04:56 | ASH | 268435456] C:\swapfile.sys
[20/10/2013 - 18:43:25 | SHD ] C:\System Volume Information
[12/09/2012 - 21:02:08 | D ] C:\Toshiba
[20/10/2013 - 21:15:07 | D ] C:\UsbFix
[20/10/2013 - 21:20:19 | A | 12270] C:\UsbFix [Clean 1] LINDSAY.txt
[20/10/2013 - 20:51:31 | N | 12646] C:\UsbFix [Scan 1] LINDSAY.txt
[26/03/2013 - 17:37:49 | RD ] C:\Users
[25/07/2013 - 07:07:37 | D ] C:\Windows
[28/12/1998 - 09:29:03 | RAD ] D:\AUDIO_TS
[28/12/1998 - 09:29:03 | RAD ] D:\VIDEO_TS
[26/03/2013 - 17:31:54 | SHD ] E:\$RECYCLE.BIN
[26/03/2013 - 03:27:48 | D ] E:\Nouveau dossier
[28/03/2013 - 10:57:04 | SHD ] E:\System Volume Information
################## | Vaccin |
C:\Autorun.inf -> Vaccin créé par UsbFix (El Desaparecido)
E:\Autorun.inf -> Vaccin créé par UsbFix (El Desaparecido)
F:\Autorun.inf -> Vaccin créé par UsbFix (El Desaparecido)
################## | E.O.F |
https://www.usbfix.net -
https://www.sosvirus.net |