et voila le deuxieme rapport merci :
############################## | UsbFix V 7.145 | [Suppression]
Utilisateur: steeven (Administrateur) # STEEVEN
Mis à jour le 17/10/2013 par El Desaparecido - Team SosVirus
Lancé à 23:16:19 | 20/10/2013
Site Web:
https://www.usbfix.net/
Forum :
https://www.sosvirus.net/
Upload Malware:
https://www.sosvirus.net/upload_malware.php
Contact:
https://www.usbfix.net/contact/
PC: ASUSTeK COMPUTER INC. (CM6330_CM6630_CM6730_CM6830)
CPU: Intel(R) Core(TM) i5-3330 CPU @ 3.00GHz
RAM -> [Total : 8146 | Free : 4644]
Bios: American Megatrends Inc.
Boot: Normal boot
OS: Microsoft Windows 8 (6.2.9200 64-Bit) #
WB: Windows Internet Explorer 10.0.9200.16721
SC: Security Center Service [Enabled]
WU: Windows Update Service [Enabled]
AV: Windows Defender [(!) Disabled | Updated]
FW: Windows FireWall Service [Enabled]
C:\ (%systemdrive%) -> Disque fixe # 150 Go (82 Go libre(s) - 55%) [Windows] # NTFS
D:\ -> Disque fixe # 766 Go (628 Go libre(s) - 82%) [Data] # NTFS
E:\ -> CD-ROM
F:\ -> Disque amovible # 7 Go (7 Go libre(s) - 98%) [] # FAT32
G:\ -> Disque fixe # 1397 Go (1010 Go libre(s) - 72%) [STOREX] # FAT32
################## | Regedit Run |
HKLM\SOFTWARE | Run : [Adobe ARM] - "C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
HKLM\SOFTWARE | Run : [ASUS AiChargerPlus Execute] - C:\Program Files (x86)\InstallShield Installation Information\{E6931688-DA2B-4E16-8539-3D323D69C677}\AiChargerPlus.exe
HKLM\SOFTWARE | Run : [ASUS Easy Update] - C:\Program Files (x86)\ASUS\ASUS Easy Update\ALU.exe
HKLM\SOFTWARE | Run : [RemoteControl10] - "C:\Program Files (x86)\CyberLink\PowerDVD10\PDVD10Serv.exe"
HKLM\SOFTWARE | Run : [BDRegion] - C:\Program Files (x86)\Cyberlink\Shared files\brs.exe
HKLM\SOFTWARE | Run : [APSDaemon] - "C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe"
HKLM\SOFTWARE | Run : [CanonSolutionMenuEx] - C:\Program Files (x86)\Canon\Solution Menu EX\CNSEMAIN.EXE /logon
HKLM\SOFTWARE | Run : [IJNetworkScanUtility] - C:\Program Files (x86)\Canon\Canon IJ Network Scan Utility\CNMNSUT.exe
HKLM\SOFTWARE | Run : [QuickTime Task] - "C:\Program Files (x86)\QuickTime\QTTask.exe" -atboottime
HKLM\SOFTWARE | Run : [iTunesHelper] - "C:\Program Files (x86)\iTunes\iTunesHelper.exe"
HKLM\SOFTWARE\wow6432Node | Run : [Adobe ARM] - "C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
HKLM\SOFTWARE\wow6432Node | Run : [ASUS AiChargerPlus Execute] - C:\Program Files (x86)\InstallShield Installation Information\{E6931688-DA2B-4E16-8539-3D323D69C677}\AiChargerPlus.exe
HKLM\SOFTWARE\wow6432Node | Run : [ASUS Easy Update] - C:\Program Files (x86)\ASUS\ASUS Easy Update\ALU.exe
HKLM\SOFTWARE\wow6432Node | Run : [RemoteControl10] - "C:\Program Files (x86)\CyberLink\PowerDVD10\PDVD10Serv.exe"
HKLM\SOFTWARE\wow6432Node | Run : [BDRegion] - C:\Program Files (x86)\Cyberlink\Shared files\brs.exe
HKLM\SOFTWARE\wow6432Node | Run : [APSDaemon] - "C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe"
HKLM\SOFTWARE\wow6432Node | Run : [CanonSolutionMenuEx] - C:\Program Files (x86)\Canon\Solution Menu EX\CNSEMAIN.EXE /logon
HKLM\SOFTWARE\wow6432Node | Run : [IJNetworkScanUtility] - C:\Program Files (x86)\Canon\Canon IJ Network Scan Utility\CNMNSUT.exe
HKLM\SOFTWARE\wow6432Node | Run : [QuickTime Task] - "C:\Program Files (x86)\QuickTime\QTTask.exe" -atboottime
HKLM\SOFTWARE\wow6432Node | Run : [iTunesHelper] - "C:\Program Files (x86)\iTunes\iTunesHelper.exe"
HKLM\SOFTWARE | RunOnce : [] -
HKLM\SOFTWARE\wow6432Node | RunOnce : [] -
HKU\S-1-5-21-676899527-2510676052-1929784452-1001\SOFTWARE | Run : [SpybotSD TeaTimer] - C:\Program Files (x86)\Spybot - Search & Destroy\TeaTimer.exe
HKU\S-1-5-21-676899527-2510676052-1929784452-1001\SOFTWARE | Run : [CCleaner] - "C:\Program Files\CCleaner\CCleaner64.exe" /AUTO
HKU\S-1-5-21-676899527-2510676052-1929784452-1001\SOFTWARE | Run : [uTorrent] - "C:\Users\steeven\AppData\Roaming\uTorrent\uTorrent.exe" /MINIMIZED
HKU\S-1-5-21-676899527-2510676052-1929784452-1001\SOFTWARE | Run : [iCloudServices] - C:\Program Files (x86)\Common Files\Apple\Internet Services\iCloudServices.exe
HKU\S-1-5-21-676899527-2510676052-1929784452-1001\SOFTWARE | Run : [ApplePhotoStreams] - C:\Program Files (x86)\Common Files\Apple\Internet Services\ApplePhotoStreams.exe
HKU\S-1-5-21-676899527-2510676052-1929784452-1001\SOFTWARE | RunOnce : [Uninstall C:\Users\steeven\AppData\Local\Microsoft\SkyDrive\16.4.6010.0727\amd64] - C:\WINDOWS\system32\cmd.exe /q /c rmdir /s /q "C:\Users\steeven\AppData\Local\Microsoft\SkyDrive\16.4.6010.0727\amd64"
################## | Processus Stoppés |
Stoppé! C:\WINDOWS\system32\nvvsvc.exe (ID 808 |ParentID 608)
Stoppé! C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe (ID 836 |ParentID 608)
Stoppé! C:\WINDOWS\System32\spoolsv.exe (ID 1400 |ParentID 608)
Stoppé! C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe (ID 1628 |ParentID 608)
Stoppé! C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe (ID 1812 |ParentID 608)
Stoppé! C:\Program Files (x86)\ASUS\AXSP\1.00.19\atkexComSvc.exe (ID 1872 |ParentID 608)
Stoppé! C:\Program Files (x86)\ASUS\AAHM\1.00.20\aaHMSvc.exe (ID 1948 |ParentID 608)
Stoppé! C:\Program Files (x86)\ASUS\AsSysCtrlService\1.00.13\AsSysCtrlService.exe (ID 1984 |ParentID 608)
Stoppé! C:\Program Files\Bonjour\mDNSResponder.exe (ID 2040 |ParentID 608)
Stoppé! C:\Program Files\Intel\iCLS Client\HeciServer.exe (ID 1516 |ParentID 608)
Stoppé! C:\WINDOWS\system32\dashost.exe (ID 1544 |ParentID 704)
Stoppé! C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe (ID 1640 |ParentID 608)
Stoppé! C:\Program Files\Microsoft Office 15\ClientX64\integratedoffice.exe (ID 1832 |ParentID 608)
Stoppé! C:\Program Files\Windows Defender\MsMpEng.exe (ID 2132 |ParentID 608)
Stoppé! C:\PROGRA~2\SearchProtect\Main\bin\CltMngSvc.exe (ID 2460 |ParentID 608)
Stoppé! C:\Program Files (x86)\Spybot - Search & Destroy\SDWinSec.exe (ID 2628 |ParentID 608)
Stoppé! C:\Windows\System32\WUDFHost.exe (ID 4228 |ParentID 704)
Stoppé! C:\WINDOWS\system32\SearchIndexer.exe (ID 2368 |ParentID 608)
Stoppé! C:\Program Files\iPod\bin\iPodService.exe (ID 4288 |ParentID 608)
Stoppé! C:\Program Files (x86)\Common Files\MAGIX Services\Database\bin\FABS.exe (ID 3828 |ParentID 608)
Stoppé! C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe (ID 3092 |ParentID 608)
Stoppé! C:\Program Files (x86)\Nero\Update\NASvc.exe (ID 4316 |ParentID 608)
Stoppé! C:\WINDOWS\system32\taskhost.exe (ID 6896 |ParentID 608)
Stoppé! C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe (ID 5852 |ParentID 608)
Stoppé! C:\Program Files\Windows Media Player\wmpnetwk.exe (ID 7164 |ParentID 608)
Stoppé! C:\Program Files (x86)\Microsoft\BingBar\7.2.241.0\SeaPort.exe (ID 7280 |ParentID 608)
Stoppé! C:\WINDOWS\system32\taskhostex.exe (ID 5004 |ParentID 608)
Stoppé! C:\WINDOWS\Explorer.EXE (ID 1220 |ParentID 6524)
Stoppé! C:\Program Files\WindowsApps\microsoft.windowscommunicationsapps_17.0.1119.516_x64__8wekyb3d8bbwe\LiveComm.exe (ID 10400 |ParentID 772)
Stoppé! C:\Windows\System32\RuntimeBroker.exe (ID 6904 |ParentID 772)
Stoppé! C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (ID 9092 |ParentID 8708)
Stoppé! C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (ID 1236 |ParentID 9092)
Stoppé! C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (ID 5732 |ParentID 9092)
Stoppé! C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (ID 10628 |ParentID 9092)
Stoppé! C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (ID 9816 |ParentID 9092)
Stoppé! C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (ID 8404 |ParentID 9092)
Stoppé! C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (ID 10788 |ParentID 9092)
Stoppé! C:\Program Files (x86)\Common Files\Apple\Internet Services\ApplePhotoStreams.exe (ID 2740 |ParentID 772)
Stoppé! C:\Program Files (x86)\Common Files\Apple\Internet Services\APSDaemon.exe (ID 1932 |ParentID 772)
Stoppé! C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (ID 10592 |ParentID 9092)
Stoppé! C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (ID 10248 |ParentID 9092)
Stoppé! C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (ID 5268 |ParentID 9092)
Stoppé! C:\Program Files (x86)\Windows Media Player\wmplayer.exe (ID 8536 |ParentID 772)
Stoppé! C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (ID 7916 |ParentID 9092)
################## | à‰léments infectieux |
Supprimé! G:\StorexProteKSBS_4_0_328_1.exe
(!) Fichiers temporaires supprimés.
################## | Registre |
################## | Listing |
[03/09/2013 - 03:40:12 | SHD ] C:\$Recycle.Bin
[03/09/2012 - 12:26:16 | SHD ] C:\Boot
[26/07/2012 - 05:44:30 | RASH | 398156] C:\bootmgr
[02/06/2012 - 16:30:55 | N | 1] C:\BOOTNXT
[26/07/2012 - 09:22:08 | SHD ] C:\Documents and Settings
[20/10/2013 - 15:31:44 | ASH | 6833057792] C:\hiberfil.sys
[03/09/2012 - 12:35:34 | D ] C:\Intel
[20/10/2013 - 15:31:44 | ASH | 8589934592] C:\pagefile.sys
[26/07/2012 - 09:33:46 | D ] C:\PerfLogs
[16/10/2013 - 01:47:28 | D ] C:\Program Files
[16/10/2013 - 01:47:28 | D ] C:\Program Files (x86)
[16/10/2013 - 01:47:28 | HD ] C:\ProgramData
[24/08/2013 - 10:25:28 | N | 0] C:\Recovery.txt
[03/09/2012 - 12:40:30 | N | 2235] C:\RHDSetup.log
[03/09/2012 - 12:14:29 | D ] C:\sources
[20/10/2013 - 15:31:44 | ASH | 268435456] C:\swapfile.sys
[17/10/2013 - 21:05:35 | SHD ] C:\System Volume Information
[05/10/2012 - 12:00:31 | D ] C:\temp
[20/10/2013 - 23:16:48 | D ] C:\UsbFix
[20/10/2013 - 23:17:37 | A | 9827] C:\UsbFix [Clean 3] STEEVEN.txt
[20/10/2013 - 21:19:20 | N | 9836] C:\UsbFix [Scan 2] STEEVEN.txt
[24/08/2013 - 02:22:54 | RD ] C:\Users
[20/10/2013 - 20:09:35 | D ] C:\Windows
[24/08/2013 - 02:27:18 | SHD ] D:\$RECYCLE.BIN
[20/10/2013 - 19:41:35 | D ] D:\Films
[01/10/2013 - 02:38:27 | D ] D:\Logiciels
[26/09/2013 - 19:55:38 | D ] D:\Nouveau dossier
[24/08/2013 - 12:19:36 | SHD ] D:\System Volume Information
[27/08/2013 - 21:18:56 | D ] F:\Dossier
[16/07/2013 - 11:18:14 | N | 41771] F:\pduc-005-darty.docx
[03/10/2013 - 11:46:46 | N | 732298] F:\Donnee sur La ville du chesnay.pdf
[03/10/2013 - 12:55:32 | N | 1147362] F:\Sans titre.png
[15/08/2012 - 02:16:20 | N | 16409960] F:\spybotsd162.exe
[24/08/2013 - 21:28:38 | N | 4429440] F:\ccsetup404.exe
[24/08/2013 - 21:42:54 | N | 55454464] F:\SpybotSD2.exe
[11/05/2011 - 16:50:20 | SHD ] G:\System Volume Information
[03/01/2012 - 16:05:46 | D ] G:\FOUND.000
[08/08/2012 - 09:37:10 | D ] G:\FOUND.001
[25/07/2013 - 23:29:16 | D ] G:\FOUND.002
[13/10/2013 - 19:44:04 | D ] G:\FOUND.003
[20/10/2013 - 20:45:02 | D ] G:\FOUND.004
[11/05/2011 - 16:46:36 | D ] G:\Films
[20/05/2011 - 19:53:34 | SHD ] G:\$RECYCLE.BIN
[21/12/2011 - 18:50:50 | D ] G:\Documents
[12/08/2012 - 02:22:22 | D ] G:\Music
[29/12/2011 - 17:45:02 | D ] G:\Kelvin
[16/08/2012 - 21:48:50 | D ] G:\Maman
[10/12/2011 - 03:27:24 | D ] G:\Logiciels
[17/08/2012 - 00:37:38 | D ] G:\Pictures
[17/08/2012 - 01:06:16 | D ] G:\Videos
[06/04/2013 - 23:06:26 | D ] G:\Recycled
################## | Vaccin |
C:\Autorun.inf -> Vaccin créé par UsbFix (El Desaparecido)
D:\Autorun.inf -> Vaccin créé par UsbFix (El Desaparecido)
F:\Autorun.inf -> Vaccin créé par UsbFix (El Desaparecido)
G:\Autorun.inf -> Vaccin créé par UsbFix (El Desaparecido)
################## | E.O.F |
https://www.usbfix.net -
https://www.sosvirus.net |