Vous pensez être infecté, des pubs s'affichent quand vous naviguez sur internet ?
Perte de données, ralentissement système, virus USB ?
Réparez votre ordinateur gratuitement sur notre assistance en ligne.
  • Avatar du membre
  • Avatar du membre
Avatar du membre
par Evasion60
#12270
:hello: Le bon usage sur tous les forums est de dire Bonsoir !
Nous ne sommes pas des Robots, mais des Humains :hein:

Donc, bonsoir

Je vais te prendre en charge

Téléchargez UsbFix et enregistrez-le sur votre bureau
Lien page de téléchargement: https://www.sosvirus.net/tools/UsbFix.exe

Une fois téléchargé sur votre bureau, double-cliquez sur son icone
Image

Puis cliquez sur Exécuter pour lancer l'installation qui se fera automatiquement
Image

Recherche des infections
Clique sur le bouton " Recherche "

Image

Laisse travailler l'outil
à€ la fin du scan, un rapport va s'afficher, poste-le dans ta prochaine réponse sur le forum
Le rapport est aussi sauvegardé à la racine du disque système => C:\UsbFix [Scan X].txt
Tutoriel en images => https://www.sosvirus.net/viewtopic.php?f=204&t=3


Suppression des infections
/!\Si blocage, désactiver temporairement l'antivirus
ou
Redémarre en mode sans échec avec prise en charge du réseau

Clique sur le bouton " Suppression "
Image

Veuillez faire un copié/collé de ce rapport sur le forum o๠vous demandez de l'aide
Rappel => Ctrl A pour sélectionner tout, Ctrl C pour copier puis Ctrl V pour coller le rapport sur le forum
Le rapport est aussi sauvegardé à la racine du disque système => C:\UsbFix [Clean X].txt


Reviens dans ta réponse avec les deux rapports

;)
Avatar du membre
par steeven
#12272
désoler novice dans les forums, bonsoir et merci de me prendre en charge
voici le rapport :
############################## | UsbFix V 7.145 | [Recherche]

Utilisateur: steeven (Administrateur) # STEEVEN
Mis à jour le 17/10/2013 par El Desaparecido - Team SosVirus
Lancé à 21:17:52 | 20/10/2013

Site Web:
Forum : https://www.sosvirus.net/
Upload Malware: https://www.sosvirus.net/upload_malware.php
Contact:

PC: ASUSTeK COMPUTER INC. (CM6330_CM6630_CM6730_CM6830)
CPU: Intel(R) Core(TM) i5-3330 CPU @ 3.00GHz
RAM -> [Total : 8146 | Free : 5086]
Bios: American Megatrends Inc.
Boot: Normal boot

OS: Microsoft Windows 8 (6.2.9200 64-Bit) #
WB: Windows Internet Explorer 10.0.9200.16721

SC: Security Center Service [Enabled]
WU: Windows Update Service [Enabled]
AV: Windows Defender [(!) Disabled | Updated]
FW: Windows FireWall Service [Enabled]

C:\ (%systemdrive%) -> Disque fixe # 150 Go (82 Go libre(s) - 55%) [Windows] # NTFS
D:\ -> Disque fixe # 766 Go (628 Go libre(s) - 82%) [Data] # NTFS
E:\ -> CD-ROM
F:\ -> Disque amovible # 7 Go (7 Go libre(s) - 98%) [] # FAT32
G:\ -> Disque fixe # 1397 Go (1010 Go libre(s) - 72%) [STOREX] # FAT32

################## | Processus Actif |

C:\WINDOWS\system32\csrss.exe (ID 472 |ParentID 460)
C:\WINDOWS\system32\wininit.exe (ID 544 |ParentID 460)
C:\WINDOWS\system32\services.exe (ID 608 |ParentID 544)
C:\WINDOWS\system32\lsass.exe (ID 648 |ParentID 544)
C:\WINDOWS\system32\svchost.exe (ID 772 |ParentID 608)
C:\WINDOWS\system32\nvvsvc.exe (ID 808 |ParentID 608)
C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe (ID 836 |ParentID 608)
C:\WINDOWS\system32\svchost.exe (ID 872 |ParentID 608)
C:\WINDOWS\System32\svchost.exe (ID 932 |ParentID 608)
C:\WINDOWS\system32\svchost.exe (ID 996 |ParentID 608)
C:\WINDOWS\system32\svchost.exe (ID 436 |ParentID 608)
C:\WINDOWS\System32\svchost.exe (ID 704 |ParentID 608)
C:\WINDOWS\system32\svchost.exe (ID 1156 |ParentID 608)
C:\WINDOWS\System32\spoolsv.exe (ID 1400 |ParentID 608)
C:\WINDOWS\system32\svchost.exe (ID 1432 |ParentID 608)
C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe (ID 1628 |ParentID 608)
C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe (ID 1812 |ParentID 608)
C:\Program Files (x86)\ASUS\AXSP\1.00.19\atkexComSvc.exe (ID 1872 |ParentID 608)
C:\Program Files (x86)\ASUS\AAHM\1.00.20\aaHMSvc.exe (ID 1948 |ParentID 608)
C:\Program Files (x86)\ASUS\AsSysCtrlService\1.00.13\AsSysCtrlService.exe (ID 1984 |ParentID 608)
C:\Program Files\Bonjour\mDNSResponder.exe (ID 2040 |ParentID 608)
C:\Program Files\Intel\iCLS Client\HeciServer.exe (ID 1516 |ParentID 608)
C:\WINDOWS\system32\dashost.exe (ID 1544 |ParentID 704)
C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe (ID 1640 |ParentID 608)
C:\Program Files\Microsoft Office 15\ClientX64\integratedoffice.exe (ID 1832 |ParentID 608)
C:\WINDOWS\system32\svchost.exe (ID 2092 |ParentID 608)
C:\Program Files\Windows Defender\MsMpEng.exe (ID 2132 |ParentID 608)
C:\PROGRA~2\SearchProtect\Main\bin\CltMngSvc.exe (ID 2460 |ParentID 608)
C:\Program Files (x86)\Spybot - Search & Destroy\SDWinSec.exe (ID 2628 |ParentID 608)
C:\WINDOWS\system32\svchost.exe (ID 3040 |ParentID 608)
C:\Windows\System32\WUDFHost.exe (ID 4228 |ParentID 704)
C:\WINDOWS\system32\SearchIndexer.exe (ID 2368 |ParentID 608)
C:\Program Files\iPod\bin\iPodService.exe (ID 4288 |ParentID 608)
C:\WINDOWS\system32\svchost.exe (ID 5568 |ParentID 608)
C:\Program Files (x86)\Common Files\MAGIX Services\Database\bin\FABS.exe (ID 3828 |ParentID 608)
C:\WINDOWS\System32\svchost.exe (ID 5196 |ParentID 608)
C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe (ID 3092 |ParentID 608)
C:\Program Files (x86)\Nero\Update\NASvc.exe (ID 4316 |ParentID 608)
C:\WINDOWS\system32\taskhost.exe (ID 6896 |ParentID 608)
C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe (ID 5852 |ParentID 608)
C:\Program Files\Windows Media Player\wmpnetwk.exe (ID 7164 |ParentID 608)
C:\Program Files (x86)\Microsoft\BingBar\7.2.241.0\SeaPort.exe (ID 7280 |ParentID 608)
C:\WINDOWS\system32\csrss.exe (ID 6260 |ParentID 7340)
C:\WINDOWS\system32\winlogon.exe (ID 4280 |ParentID 7340)
C:\WINDOWS\system32\dwm.exe (ID 11132 |ParentID 4280)
C:\WINDOWS\system32\taskhostex.exe (ID 5004 |ParentID 608)
C:\WINDOWS\Explorer.EXE (ID 1220 |ParentID 6524)
C:\Program Files\WindowsApps\microsoft.windowscommunicationsapps_17.0.1119.516_x64__8wekyb3d8bbwe\LiveComm.exe (ID 10400 |ParentID 772)
C:\Windows\System32\RuntimeBroker.exe (ID 6904 |ParentID 772)
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (ID 9092 |ParentID 8708)
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (ID 1236 |ParentID 9092)
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (ID 5732 |ParentID 9092)
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (ID 10628 |ParentID 9092)
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (ID 9816 |ParentID 9092)
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (ID 8404 |ParentID 9092)
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (ID 10788 |ParentID 9092)
C:\Program Files (x86)\Common Files\Apple\Internet Services\ApplePhotoStreams.exe (ID 2740 |ParentID 772)
C:\Program Files (x86)\Common Files\Apple\Internet Services\APSDaemon.exe (ID 1932 |ParentID 772)
C:\Program Files (x86)\Windows Media Player\wmplayer.exe (ID 9748 |ParentID 772)
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (ID 10592 |ParentID 9092)
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (ID 9616 |ParentID 9092)
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (ID 9304 |ParentID 9092)
C:\WINDOWS\system32\wbem\wmiprvse.exe (ID 600 |ParentID 772)
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (ID 10248 |ParentID 9092)
C:\UsbFix\Go.exe (ID 7452 |ParentID 5588)
C:\WINDOWS\System32\svchost.exe (ID 6244 |ParentID 608)

################## | Regedit Run |

HKLM\SOFTWARE | Run : [Adobe ARM] - "C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
HKLM\SOFTWARE | Run : [ASUS AiChargerPlus Execute] - C:\Program Files (x86)\InstallShield Installation Information\{E6931688-DA2B-4E16-8539-3D323D69C677}\AiChargerPlus.exe
HKLM\SOFTWARE | Run : [ASUS Easy Update] - C:\Program Files (x86)\ASUS\ASUS Easy Update\ALU.exe
HKLM\SOFTWARE | Run : [RemoteControl10] - "C:\Program Files (x86)\CyberLink\PowerDVD10\PDVD10Serv.exe"
HKLM\SOFTWARE | Run : [BDRegion] - C:\Program Files (x86)\Cyberlink\Shared files\brs.exe
HKLM\SOFTWARE | Run : [APSDaemon] - "C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe"
HKLM\SOFTWARE | Run : [CanonSolutionMenuEx] - C:\Program Files (x86)\Canon\Solution Menu EX\CNSEMAIN.EXE /logon
HKLM\SOFTWARE | Run : [IJNetworkScanUtility] - C:\Program Files (x86)\Canon\Canon IJ Network Scan Utility\CNMNSUT.exe
HKLM\SOFTWARE | Run : [QuickTime Task] - "C:\Program Files (x86)\QuickTime\QTTask.exe" -atboottime
HKLM\SOFTWARE | Run : [iTunesHelper] - "C:\Program Files (x86)\iTunes\iTunesHelper.exe"
HKLM\SOFTWARE\wow6432Node | Run : [Adobe ARM] - "C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
HKLM\SOFTWARE\wow6432Node | Run : [ASUS AiChargerPlus Execute] - C:\Program Files (x86)\InstallShield Installation Information\{E6931688-DA2B-4E16-8539-3D323D69C677}\AiChargerPlus.exe
HKLM\SOFTWARE\wow6432Node | Run : [ASUS Easy Update] - C:\Program Files (x86)\ASUS\ASUS Easy Update\ALU.exe
HKLM\SOFTWARE\wow6432Node | Run : [RemoteControl10] - "C:\Program Files (x86)\CyberLink\PowerDVD10\PDVD10Serv.exe"
HKLM\SOFTWARE\wow6432Node | Run : [BDRegion] - C:\Program Files (x86)\Cyberlink\Shared files\brs.exe
HKLM\SOFTWARE\wow6432Node | Run : [APSDaemon] - "C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe"
HKLM\SOFTWARE\wow6432Node | Run : [CanonSolutionMenuEx] - C:\Program Files (x86)\Canon\Solution Menu EX\CNSEMAIN.EXE /logon
HKLM\SOFTWARE\wow6432Node | Run : [IJNetworkScanUtility] - C:\Program Files (x86)\Canon\Canon IJ Network Scan Utility\CNMNSUT.exe
HKLM\SOFTWARE\wow6432Node | Run : [QuickTime Task] - "C:\Program Files (x86)\QuickTime\QTTask.exe" -atboottime
HKLM\SOFTWARE\wow6432Node | Run : [iTunesHelper] - "C:\Program Files (x86)\iTunes\iTunesHelper.exe"
HKLM\SOFTWARE | RunOnce : [] -
HKLM\SOFTWARE\wow6432Node | RunOnce : [] -
HKU\S-1-5-21-676899527-2510676052-1929784452-1001\SOFTWARE | Run : [SpybotSD TeaTimer] - C:\Program Files (x86)\Spybot - Search & Destroy\TeaTimer.exe
HKU\S-1-5-21-676899527-2510676052-1929784452-1001\SOFTWARE | Run : [CCleaner] - "C:\Program Files\CCleaner\CCleaner64.exe" /AUTO
HKU\S-1-5-21-676899527-2510676052-1929784452-1001\SOFTWARE | Run : [uTorrent] - "C:\Users\steeven\AppData\Roaming\uTorrent\uTorrent.exe" /MINIMIZED
HKU\S-1-5-21-676899527-2510676052-1929784452-1001\SOFTWARE | Run : [iCloudServices] - C:\Program Files (x86)\Common Files\Apple\Internet Services\iCloudServices.exe
HKU\S-1-5-21-676899527-2510676052-1929784452-1001\SOFTWARE | Run : [ApplePhotoStreams] - C:\Program Files (x86)\Common Files\Apple\Internet Services\ApplePhotoStreams.exe
HKU\S-1-5-21-676899527-2510676052-1929784452-1001\SOFTWARE | RunOnce : [Uninstall C:\Users\steeven\AppData\Local\Microsoft\SkyDrive\16.4.6010.0727\amd64] - C:\WINDOWS\system32\cmd.exe /q /c rmdir /s /q "C:\Users\steeven\AppData\Local\Microsoft\SkyDrive\16.4.6010.0727\amd64"

################## | à‰léments infectieux |

Présent! G:\StorexProteKSBS_4_0_328_1.exe

################## | Registre |



################## | Vaccin |

(!) Cet ordinateur n'est pas vacciné!

################## | E.O.F | - https://www.sosvirus.net |
Avatar du membre
par Evasion60
#12274
:hello: Re

Relance USBFix en mode Suppression, comme demandé plus haut !
Poste son rapport / STP
... impossible d'analyser mon disc dur et le reparer ...
Quand tu écris ci dessus, c'est de quel disque dur dont tu parles ?
Celui externe USB, ou un disque dur interne, et lequel ?


;)
Avatar du membre
par steeven
#12275
et voila le deuxieme rapport merci :
############################## | UsbFix V 7.145 | [Suppression]

Utilisateur: steeven (Administrateur) # STEEVEN
Mis à jour le 17/10/2013 par El Desaparecido - Team SosVirus
Lancé à 23:16:19 | 20/10/2013

Site Web:
Forum : https://www.sosvirus.net/
Upload Malware: https://www.sosvirus.net/upload_malware.php
Contact:

PC: ASUSTeK COMPUTER INC. (CM6330_CM6630_CM6730_CM6830)
CPU: Intel(R) Core(TM) i5-3330 CPU @ 3.00GHz
RAM -> [Total : 8146 | Free : 4644]
Bios: American Megatrends Inc.
Boot: Normal boot

OS: Microsoft Windows 8 (6.2.9200 64-Bit) #
WB: Windows Internet Explorer 10.0.9200.16721

SC: Security Center Service [Enabled]
WU: Windows Update Service [Enabled]
AV: Windows Defender [(!) Disabled | Updated]
FW: Windows FireWall Service [Enabled]

C:\ (%systemdrive%) -> Disque fixe # 150 Go (82 Go libre(s) - 55%) [Windows] # NTFS
D:\ -> Disque fixe # 766 Go (628 Go libre(s) - 82%) [Data] # NTFS
E:\ -> CD-ROM
F:\ -> Disque amovible # 7 Go (7 Go libre(s) - 98%) [] # FAT32
G:\ -> Disque fixe # 1397 Go (1010 Go libre(s) - 72%) [STOREX] # FAT32

################## | Regedit Run |

HKLM\SOFTWARE | Run : [Adobe ARM] - "C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
HKLM\SOFTWARE | Run : [ASUS AiChargerPlus Execute] - C:\Program Files (x86)\InstallShield Installation Information\{E6931688-DA2B-4E16-8539-3D323D69C677}\AiChargerPlus.exe
HKLM\SOFTWARE | Run : [ASUS Easy Update] - C:\Program Files (x86)\ASUS\ASUS Easy Update\ALU.exe
HKLM\SOFTWARE | Run : [RemoteControl10] - "C:\Program Files (x86)\CyberLink\PowerDVD10\PDVD10Serv.exe"
HKLM\SOFTWARE | Run : [BDRegion] - C:\Program Files (x86)\Cyberlink\Shared files\brs.exe
HKLM\SOFTWARE | Run : [APSDaemon] - "C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe"
HKLM\SOFTWARE | Run : [CanonSolutionMenuEx] - C:\Program Files (x86)\Canon\Solution Menu EX\CNSEMAIN.EXE /logon
HKLM\SOFTWARE | Run : [IJNetworkScanUtility] - C:\Program Files (x86)\Canon\Canon IJ Network Scan Utility\CNMNSUT.exe
HKLM\SOFTWARE | Run : [QuickTime Task] - "C:\Program Files (x86)\QuickTime\QTTask.exe" -atboottime
HKLM\SOFTWARE | Run : [iTunesHelper] - "C:\Program Files (x86)\iTunes\iTunesHelper.exe"
HKLM\SOFTWARE\wow6432Node | Run : [Adobe ARM] - "C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
HKLM\SOFTWARE\wow6432Node | Run : [ASUS AiChargerPlus Execute] - C:\Program Files (x86)\InstallShield Installation Information\{E6931688-DA2B-4E16-8539-3D323D69C677}\AiChargerPlus.exe
HKLM\SOFTWARE\wow6432Node | Run : [ASUS Easy Update] - C:\Program Files (x86)\ASUS\ASUS Easy Update\ALU.exe
HKLM\SOFTWARE\wow6432Node | Run : [RemoteControl10] - "C:\Program Files (x86)\CyberLink\PowerDVD10\PDVD10Serv.exe"
HKLM\SOFTWARE\wow6432Node | Run : [BDRegion] - C:\Program Files (x86)\Cyberlink\Shared files\brs.exe
HKLM\SOFTWARE\wow6432Node | Run : [APSDaemon] - "C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe"
HKLM\SOFTWARE\wow6432Node | Run : [CanonSolutionMenuEx] - C:\Program Files (x86)\Canon\Solution Menu EX\CNSEMAIN.EXE /logon
HKLM\SOFTWARE\wow6432Node | Run : [IJNetworkScanUtility] - C:\Program Files (x86)\Canon\Canon IJ Network Scan Utility\CNMNSUT.exe
HKLM\SOFTWARE\wow6432Node | Run : [QuickTime Task] - "C:\Program Files (x86)\QuickTime\QTTask.exe" -atboottime
HKLM\SOFTWARE\wow6432Node | Run : [iTunesHelper] - "C:\Program Files (x86)\iTunes\iTunesHelper.exe"
HKLM\SOFTWARE | RunOnce : [] -
HKLM\SOFTWARE\wow6432Node | RunOnce : [] -
HKU\S-1-5-21-676899527-2510676052-1929784452-1001\SOFTWARE | Run : [SpybotSD TeaTimer] - C:\Program Files (x86)\Spybot - Search & Destroy\TeaTimer.exe
HKU\S-1-5-21-676899527-2510676052-1929784452-1001\SOFTWARE | Run : [CCleaner] - "C:\Program Files\CCleaner\CCleaner64.exe" /AUTO
HKU\S-1-5-21-676899527-2510676052-1929784452-1001\SOFTWARE | Run : [uTorrent] - "C:\Users\steeven\AppData\Roaming\uTorrent\uTorrent.exe" /MINIMIZED
HKU\S-1-5-21-676899527-2510676052-1929784452-1001\SOFTWARE | Run : [iCloudServices] - C:\Program Files (x86)\Common Files\Apple\Internet Services\iCloudServices.exe
HKU\S-1-5-21-676899527-2510676052-1929784452-1001\SOFTWARE | Run : [ApplePhotoStreams] - C:\Program Files (x86)\Common Files\Apple\Internet Services\ApplePhotoStreams.exe
HKU\S-1-5-21-676899527-2510676052-1929784452-1001\SOFTWARE | RunOnce : [Uninstall C:\Users\steeven\AppData\Local\Microsoft\SkyDrive\16.4.6010.0727\amd64] - C:\WINDOWS\system32\cmd.exe /q /c rmdir /s /q "C:\Users\steeven\AppData\Local\Microsoft\SkyDrive\16.4.6010.0727\amd64"

################## | Processus Stoppés |

Stoppé! C:\WINDOWS\system32\nvvsvc.exe (ID 808 |ParentID 608)
Stoppé! C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe (ID 836 |ParentID 608)
Stoppé! C:\WINDOWS\System32\spoolsv.exe (ID 1400 |ParentID 608)
Stoppé! C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe (ID 1628 |ParentID 608)
Stoppé! C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe (ID 1812 |ParentID 608)
Stoppé! C:\Program Files (x86)\ASUS\AXSP\1.00.19\atkexComSvc.exe (ID 1872 |ParentID 608)
Stoppé! C:\Program Files (x86)\ASUS\AAHM\1.00.20\aaHMSvc.exe (ID 1948 |ParentID 608)
Stoppé! C:\Program Files (x86)\ASUS\AsSysCtrlService\1.00.13\AsSysCtrlService.exe (ID 1984 |ParentID 608)
Stoppé! C:\Program Files\Bonjour\mDNSResponder.exe (ID 2040 |ParentID 608)
Stoppé! C:\Program Files\Intel\iCLS Client\HeciServer.exe (ID 1516 |ParentID 608)
Stoppé! C:\WINDOWS\system32\dashost.exe (ID 1544 |ParentID 704)
Stoppé! C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe (ID 1640 |ParentID 608)
Stoppé! C:\Program Files\Microsoft Office 15\ClientX64\integratedoffice.exe (ID 1832 |ParentID 608)
Stoppé! C:\Program Files\Windows Defender\MsMpEng.exe (ID 2132 |ParentID 608)
Stoppé! C:\PROGRA~2\SearchProtect\Main\bin\CltMngSvc.exe (ID 2460 |ParentID 608)
Stoppé! C:\Program Files (x86)\Spybot - Search & Destroy\SDWinSec.exe (ID 2628 |ParentID 608)
Stoppé! C:\Windows\System32\WUDFHost.exe (ID 4228 |ParentID 704)
Stoppé! C:\WINDOWS\system32\SearchIndexer.exe (ID 2368 |ParentID 608)
Stoppé! C:\Program Files\iPod\bin\iPodService.exe (ID 4288 |ParentID 608)
Stoppé! C:\Program Files (x86)\Common Files\MAGIX Services\Database\bin\FABS.exe (ID 3828 |ParentID 608)
Stoppé! C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe (ID 3092 |ParentID 608)
Stoppé! C:\Program Files (x86)\Nero\Update\NASvc.exe (ID 4316 |ParentID 608)
Stoppé! C:\WINDOWS\system32\taskhost.exe (ID 6896 |ParentID 608)
Stoppé! C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe (ID 5852 |ParentID 608)
Stoppé! C:\Program Files\Windows Media Player\wmpnetwk.exe (ID 7164 |ParentID 608)
Stoppé! C:\Program Files (x86)\Microsoft\BingBar\7.2.241.0\SeaPort.exe (ID 7280 |ParentID 608)
Stoppé! C:\WINDOWS\system32\taskhostex.exe (ID 5004 |ParentID 608)
Stoppé! C:\WINDOWS\Explorer.EXE (ID 1220 |ParentID 6524)
Stoppé! C:\Program Files\WindowsApps\microsoft.windowscommunicationsapps_17.0.1119.516_x64__8wekyb3d8bbwe\LiveComm.exe (ID 10400 |ParentID 772)
Stoppé! C:\Windows\System32\RuntimeBroker.exe (ID 6904 |ParentID 772)
Stoppé! C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (ID 9092 |ParentID 8708)
Stoppé! C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (ID 1236 |ParentID 9092)
Stoppé! C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (ID 5732 |ParentID 9092)
Stoppé! C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (ID 10628 |ParentID 9092)
Stoppé! C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (ID 9816 |ParentID 9092)
Stoppé! C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (ID 8404 |ParentID 9092)
Stoppé! C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (ID 10788 |ParentID 9092)
Stoppé! C:\Program Files (x86)\Common Files\Apple\Internet Services\ApplePhotoStreams.exe (ID 2740 |ParentID 772)
Stoppé! C:\Program Files (x86)\Common Files\Apple\Internet Services\APSDaemon.exe (ID 1932 |ParentID 772)
Stoppé! C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (ID 10592 |ParentID 9092)
Stoppé! C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (ID 10248 |ParentID 9092)
Stoppé! C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (ID 5268 |ParentID 9092)
Stoppé! C:\Program Files (x86)\Windows Media Player\wmplayer.exe (ID 8536 |ParentID 772)
Stoppé! C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (ID 7916 |ParentID 9092)

################## | à‰léments infectieux |

Supprimé! G:\StorexProteKSBS_4_0_328_1.exe

(!) Fichiers temporaires supprimés.

################## | Registre |


################## | Listing |

[03/09/2013 - 03:40:12 | SHD ] C:\$Recycle.Bin
[03/09/2012 - 12:26:16 | SHD ] C:\Boot
[26/07/2012 - 05:44:30 | RASH | 398156] C:\bootmgr
[02/06/2012 - 16:30:55 | N | 1] C:\BOOTNXT
[26/07/2012 - 09:22:08 | SHD ] C:\Documents and Settings
[20/10/2013 - 15:31:44 | ASH | 6833057792] C:\hiberfil.sys
[03/09/2012 - 12:35:34 | D ] C:\Intel
[20/10/2013 - 15:31:44 | ASH | 8589934592] C:\pagefile.sys
[26/07/2012 - 09:33:46 | D ] C:\PerfLogs
[16/10/2013 - 01:47:28 | D ] C:\Program Files
[16/10/2013 - 01:47:28 | D ] C:\Program Files (x86)
[16/10/2013 - 01:47:28 | HD ] C:\ProgramData
[24/08/2013 - 10:25:28 | N | 0] C:\Recovery.txt
[03/09/2012 - 12:40:30 | N | 2235] C:\RHDSetup.log
[03/09/2012 - 12:14:29 | D ] C:\sources
[20/10/2013 - 15:31:44 | ASH | 268435456] C:\swapfile.sys
[17/10/2013 - 21:05:35 | SHD ] C:\System Volume Information
[05/10/2012 - 12:00:31 | D ] C:\temp
[20/10/2013 - 23:16:48 | D ] C:\UsbFix
[20/10/2013 - 23:17:37 | A | 9827] C:\UsbFix [Clean 3] STEEVEN.txt
[20/10/2013 - 21:19:20 | N | 9836] C:\UsbFix [Scan 2] STEEVEN.txt
[24/08/2013 - 02:22:54 | RD ] C:\Users
[20/10/2013 - 20:09:35 | D ] C:\Windows
[24/08/2013 - 02:27:18 | SHD ] D:\$RECYCLE.BIN
[20/10/2013 - 19:41:35 | D ] D:\Films
[01/10/2013 - 02:38:27 | D ] D:\Logiciels
[26/09/2013 - 19:55:38 | D ] D:\Nouveau dossier
[24/08/2013 - 12:19:36 | SHD ] D:\System Volume Information
[27/08/2013 - 21:18:56 | D ] F:\Dossier
[16/07/2013 - 11:18:14 | N | 41771] F:\pduc-005-darty.docx
[03/10/2013 - 11:46:46 | N | 732298] F:\Donnee sur La ville du chesnay.pdf
[03/10/2013 - 12:55:32 | N | 1147362] F:\Sans titre.png
[15/08/2012 - 02:16:20 | N | 16409960] F:\spybotsd162.exe
[24/08/2013 - 21:28:38 | N | 4429440] F:\ccsetup404.exe
[24/08/2013 - 21:42:54 | N | 55454464] F:\SpybotSD2.exe
[11/05/2011 - 16:50:20 | SHD ] G:\System Volume Information
[03/01/2012 - 16:05:46 | D ] G:\FOUND.000
[08/08/2012 - 09:37:10 | D ] G:\FOUND.001
[25/07/2013 - 23:29:16 | D ] G:\FOUND.002
[13/10/2013 - 19:44:04 | D ] G:\FOUND.003
[20/10/2013 - 20:45:02 | D ] G:\FOUND.004
[11/05/2011 - 16:46:36 | D ] G:\Films
[20/05/2011 - 19:53:34 | SHD ] G:\$RECYCLE.BIN
[21/12/2011 - 18:50:50 | D ] G:\Documents
[12/08/2012 - 02:22:22 | D ] G:\Music
[29/12/2011 - 17:45:02 | D ] G:\Kelvin
[16/08/2012 - 21:48:50 | D ] G:\Maman
[10/12/2011 - 03:27:24 | D ] G:\Logiciels
[17/08/2012 - 00:37:38 | D ] G:\Pictures
[17/08/2012 - 01:06:16 | D ] G:\Videos
[06/04/2013 - 23:06:26 | D ] G:\Recycled

################## | Vaccin |

C:\Autorun.inf -> Vaccin créé par UsbFix (El Desaparecido)
D:\Autorun.inf -> Vaccin créé par UsbFix (El Desaparecido)
F:\Autorun.inf -> Vaccin créé par UsbFix (El Desaparecido)
G:\Autorun.inf -> Vaccin créé par UsbFix (El Desaparecido)

################## | E.O.F | - https://www.sosvirus.net |
Avatar du membre
par Evasion60
#12276
:hello: Re

Peux-tu répondre à ma question ?
Merci !
Avatar du membre
par steeven
#12279
re
je parle du disc dur externe ( storex )
donc j'ai relancer suprimer sur usbfix et voila le rapport :)
############################## | UsbFix V 7.145 | [Suppression]

Utilisateur: steeven (Administrateur) # STEEVEN
Mis à jour le 17/10/2013 par El Desaparecido - Team SosVirus
Lancé à 23:29:27 | 20/10/2013

Site Web:
Forum : https://www.sosvirus.net/
Upload Malware: https://www.sosvirus.net/upload_malware.php
Contact:

PC: ASUSTeK COMPUTER INC. (CM6330_CM6630_CM6730_CM6830)
CPU: Intel(R) Core(TM) i5-3330 CPU @ 3.00GHz
RAM -> [Total : 8146 | Free : 5225]
Bios: American Megatrends Inc.
Boot: Normal boot

OS: Microsoft Windows 8 (6.2.9200 64-Bit) #
WB: Windows Internet Explorer 10.0.9200.16721

SC: Security Center Service [Enabled]
WU: Windows Update Service [Enabled]
AV: Windows Defender [(!) Disabled | Updated]
FW: Windows FireWall Service [Enabled]

C:\ (%systemdrive%) -> Disque fixe # 150 Go (82 Go libre(s) - 55%) [Windows] # NTFS
D:\ -> Disque fixe # 766 Go (628 Go libre(s) - 82%) [Data] # NTFS
E:\ -> CD-ROM
F:\ -> Disque amovible # 7 Go (7 Go libre(s) - 98%) [] # FAT32
G:\ -> Disque fixe # 1397 Go (1010 Go libre(s) - 72%) [STOREX] # FAT32

################## | Regedit Run |

HKLM\SOFTWARE | Run : [Adobe ARM] - "C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
HKLM\SOFTWARE | Run : [ASUS AiChargerPlus Execute] - C:\Program Files (x86)\InstallShield Installation Information\{E6931688-DA2B-4E16-8539-3D323D69C677}\AiChargerPlus.exe
HKLM\SOFTWARE | Run : [ASUS Easy Update] - C:\Program Files (x86)\ASUS\ASUS Easy Update\ALU.exe
HKLM\SOFTWARE | Run : [RemoteControl10] - "C:\Program Files (x86)\CyberLink\PowerDVD10\PDVD10Serv.exe"
HKLM\SOFTWARE | Run : [BDRegion] - C:\Program Files (x86)\Cyberlink\Shared files\brs.exe
HKLM\SOFTWARE | Run : [APSDaemon] - "C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe"
HKLM\SOFTWARE | Run : [CanonSolutionMenuEx] - C:\Program Files (x86)\Canon\Solution Menu EX\CNSEMAIN.EXE /logon
HKLM\SOFTWARE | Run : [IJNetworkScanUtility] - C:\Program Files (x86)\Canon\Canon IJ Network Scan Utility\CNMNSUT.exe
HKLM\SOFTWARE | Run : [QuickTime Task] - "C:\Program Files (x86)\QuickTime\QTTask.exe" -atboottime
HKLM\SOFTWARE | Run : [iTunesHelper] - "C:\Program Files (x86)\iTunes\iTunesHelper.exe"
HKLM\SOFTWARE\wow6432Node | Run : [Adobe ARM] - "C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
HKLM\SOFTWARE\wow6432Node | Run : [ASUS AiChargerPlus Execute] - C:\Program Files (x86)\InstallShield Installation Information\{E6931688-DA2B-4E16-8539-3D323D69C677}\AiChargerPlus.exe
HKLM\SOFTWARE\wow6432Node | Run : [ASUS Easy Update] - C:\Program Files (x86)\ASUS\ASUS Easy Update\ALU.exe
HKLM\SOFTWARE\wow6432Node | Run : [RemoteControl10] - "C:\Program Files (x86)\CyberLink\PowerDVD10\PDVD10Serv.exe"
HKLM\SOFTWARE\wow6432Node | Run : [BDRegion] - C:\Program Files (x86)\Cyberlink\Shared files\brs.exe
HKLM\SOFTWARE\wow6432Node | Run : [APSDaemon] - "C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe"
HKLM\SOFTWARE\wow6432Node | Run : [CanonSolutionMenuEx] - C:\Program Files (x86)\Canon\Solution Menu EX\CNSEMAIN.EXE /logon
HKLM\SOFTWARE\wow6432Node | Run : [IJNetworkScanUtility] - C:\Program Files (x86)\Canon\Canon IJ Network Scan Utility\CNMNSUT.exe
HKLM\SOFTWARE\wow6432Node | Run : [QuickTime Task] - "C:\Program Files (x86)\QuickTime\QTTask.exe" -atboottime
HKLM\SOFTWARE\wow6432Node | Run : [iTunesHelper] - "C:\Program Files (x86)\iTunes\iTunesHelper.exe"
HKLM\SOFTWARE | RunOnce : [] -
HKLM\SOFTWARE\wow6432Node | RunOnce : [] -
HKU\S-1-5-21-676899527-2510676052-1929784452-1001\SOFTWARE | Run : [SpybotSD TeaTimer] - C:\Program Files (x86)\Spybot - Search & Destroy\TeaTimer.exe
HKU\S-1-5-21-676899527-2510676052-1929784452-1001\SOFTWARE | Run : [CCleaner] - "C:\Program Files\CCleaner\CCleaner64.exe" /AUTO
HKU\S-1-5-21-676899527-2510676052-1929784452-1001\SOFTWARE | Run : [uTorrent] - "C:\Users\steeven\AppData\Roaming\uTorrent\uTorrent.exe" /MINIMIZED
HKU\S-1-5-21-676899527-2510676052-1929784452-1001\SOFTWARE | Run : [iCloudServices] - C:\Program Files (x86)\Common Files\Apple\Internet Services\iCloudServices.exe
HKU\S-1-5-21-676899527-2510676052-1929784452-1001\SOFTWARE | Run : [ApplePhotoStreams] - C:\Program Files (x86)\Common Files\Apple\Internet Services\ApplePhotoStreams.exe
HKU\S-1-5-21-676899527-2510676052-1929784452-1001\SOFTWARE | RunOnce : [Uninstall C:\Users\steeven\AppData\Local\Microsoft\SkyDrive\16.4.6010.0727\amd64] - C:\WINDOWS\system32\cmd.exe /q /c rmdir /s /q "C:\Users\steeven\AppData\Local\Microsoft\SkyDrive\16.4.6010.0727\amd64"

################## | Processus Stoppés |

Stoppé! C:\Program Files\Windows Defender\MsMpEng.exe (ID 2132 |ParentID 608)
Stoppé! C:\Program Files\Intel\iCLS Client\HeciServer.exe (ID 6032 |ParentID 608)
Stoppé! C:\Program Files\Microsoft Office 15\ClientX64\integratedoffice.exe (ID 6928 |ParentID 608)
Stoppé! C:\WINDOWS\explorer.exe (ID 6624 |ParentID 4280)
Stoppé! C:\Windows\System32\WUDFHost.exe (ID 212 |ParentID 704)
Stoppé! C:\WINDOWS\system32\DllHost.exe (ID 5668 |ParentID 772)
Stoppé! C:\WINDOWS\System32\spoolsv.exe (ID 1376 |ParentID 608)
Stoppé! C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe (ID 7068 |ParentID 608)
Stoppé! C:\WINDOWS\system32\SearchIndexer.exe (ID 9408 |ParentID 608)
Stoppé! C:\Program Files\WindowsApps\microsoft.windowscommunicationsapps_17.0.1119.516_x64__8wekyb3d8bbwe\LiveComm.exe (ID 8908 |ParentID 772)
Stoppé! C:\Windows\System32\RuntimeBroker.exe (ID 8112 |ParentID 772)
Stoppé! C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe (ID 5900 |ParentID 608)
Stoppé! C:\WINDOWS\SysWOW64\NOTEPAD.EXE (ID 8812 |ParentID 6820)
Stoppé! C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (ID 7672 |ParentID 4552)
Stoppé! C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (ID 5692 |ParentID 7672)
Stoppé! C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (ID 7112 |ParentID 7672)
Stoppé! C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (ID 6824 |ParentID 7672)
Stoppé! C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (ID 7868 |ParentID 7672)
Stoppé! C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (ID 10332 |ParentID 7672)
Stoppé! C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (ID 10532 |ParentID 7672)
Stoppé! C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (ID 8548 |ParentID 7672)
Stoppé! C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (ID 4604 |ParentID 7672)
Stoppé! C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (ID 6192 |ParentID 7672)
Stoppé! C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (ID 5264 |ParentID 7672)
Stoppé! C:\WINDOWS\system32\dashost.exe (ID 6864 |ParentID 704)
Stoppé! C:\Program Files (x86)\Windows Media Player\wmplayer.exe (ID 5088 |ParentID 772)

################## | à‰léments infectieux |


(!) Fichiers temporaires supprimés.

################## | Registre |


################## | Listing |

[03/09/2013 - 03:40:12 | SHD ] C:\$Recycle.Bin
[20/10/2013 - 23:17:37 | RASHD ] C:\Autorun.inf
[03/09/2012 - 12:26:16 | SHD ] C:\Boot
[26/07/2012 - 05:44:30 | RASH | 398156] C:\bootmgr
[02/06/2012 - 16:30:55 | N | 1] C:\BOOTNXT
[26/07/2012 - 09:22:08 | SHD ] C:\Documents and Settings
[20/10/2013 - 15:31:44 | ASH | 6833057792] C:\hiberfil.sys
[03/09/2012 - 12:35:34 | D ] C:\Intel
[20/10/2013 - 15:31:44 | ASH | 8589934592] C:\pagefile.sys
[26/07/2012 - 09:33:46 | D ] C:\PerfLogs
[16/10/2013 - 01:47:28 | D ] C:\Program Files
[16/10/2013 - 01:47:28 | D ] C:\Program Files (x86)
[16/10/2013 - 01:47:28 | HD ] C:\ProgramData
[24/08/2013 - 10:25:28 | N | 0] C:\Recovery.txt
[03/09/2012 - 12:40:30 | N | 2235] C:\RHDSetup.log
[03/09/2012 - 12:14:29 | D ] C:\sources
[20/10/2013 - 15:31:44 | ASH | 268435456] C:\swapfile.sys
[17/10/2013 - 21:05:35 | SHD ] C:\System Volume Information
[05/10/2012 - 12:00:31 | D ] C:\temp
[20/10/2013 - 23:29:44 | D ] C:\UsbFix
[20/10/2013 - 23:18:09 | N | 11770] C:\UsbFix [Clean 3] STEEVEN.txt
[20/10/2013 - 23:30:31 | A | 8210] C:\UsbFix [Clean 4] STEEVEN.txt
[20/10/2013 - 21:19:20 | N | 9836] C:\UsbFix [Scan 2] STEEVEN.txt
[24/08/2013 - 02:22:54 | RD ] C:\Users
[20/10/2013 - 20:09:35 | D ] C:\Windows
[24/08/2013 - 02:27:18 | SHD ] D:\$RECYCLE.BIN
[20/10/2013 - 23:17:37 | RASHD ] D:\Autorun.inf
[20/10/2013 - 19:41:35 | D ] D:\Films
[01/10/2013 - 02:38:27 | D ] D:\Logiciels
[26/09/2013 - 19:55:38 | D ] D:\Nouveau dossier
[24/08/2013 - 12:19:36 | SHD ] D:\System Volume Information
[27/08/2013 - 21:18:56 | D ] F:\Dossier
[16/07/2013 - 11:18:14 | N | 41771] F:\pduc-005-darty.docx
[03/10/2013 - 11:46:46 | N | 732298] F:\Donnee sur La ville du chesnay.pdf
[03/10/2013 - 12:55:32 | N | 1147362] F:\Sans titre.png
[15/08/2012 - 02:16:20 | N | 16409960] F:\spybotsd162.exe
[24/08/2013 - 21:28:38 | N | 4429440] F:\ccsetup404.exe
[24/08/2013 - 21:42:54 | N | 55454464] F:\SpybotSD2.exe
[20/10/2013 - 23:17:38 | RASHD ] F:\Autorun.inf
[11/05/2011 - 16:50:20 | SHD ] G:\System Volume Information
[03/01/2012 - 16:05:46 | D ] G:\FOUND.000
[08/08/2012 - 09:37:10 | D ] G:\FOUND.001
[25/07/2013 - 23:29:16 | D ] G:\FOUND.002
[13/10/2013 - 19:44:04 | D ] G:\FOUND.003
[20/10/2013 - 20:45:02 | D ] G:\FOUND.004
[11/05/2011 - 16:46:36 | D ] G:\Films
[20/05/2011 - 19:53:34 | SHD ] G:\$RECYCLE.BIN
[21/12/2011 - 18:50:50 | D ] G:\Documents
[12/08/2012 - 02:22:22 | D ] G:\Music
[29/12/2011 - 17:45:02 | D ] G:\Kelvin
[16/08/2012 - 21:48:50 | D ] G:\Maman
[10/12/2011 - 03:27:24 | D ] G:\Logiciels
[17/08/2012 - 00:37:38 | D ] G:\Pictures
[17/08/2012 - 01:06:16 | D ] G:\Videos
[06/04/2013 - 23:06:26 | D ] G:\Recycled
[20/10/2013 - 23:17:38 | RASHD ] G:\Autorun.inf

################## | Vaccin |

C:\Autorun.inf -> Vaccin créé par UsbFix (El Desaparecido)
D:\Autorun.inf -> Vaccin créé par UsbFix (El Desaparecido)
F:\Autorun.inf -> Vaccin créé par UsbFix (El Desaparecido)
G:\Autorun.inf -> Vaccin créé par UsbFix (El Desaparecido)

################## | E.O.F | - https://www.sosvirus.net |
Avatar du membre
par steeven
#12283
lorsque je fais " analyser et reparer " une barre de progression d'affiche et au bout de quelque seconde sa me fais " un probleme est survenue fermer la boite de dialogue et recomencer " et ensuite le disc dur ne s'affiche plus sur l'ordinateur...
Avatar du membre
par Evasion60
#12284
:hello: Re

Touche Windows du clavier + R
Dans la fenêtre qui s'ouvre tape diskmgmt.msc
Valide par OK

Dis moi si ton disque dur USB est bien en FAT32 et non en RAW !

;)

Coucou, ;) Brrr.... C'est ce qui me dépla[…]

Suspicion de virus crypto

Ok bonne route :)

Problème avec Adsfix

bonsoir ok , à te lire prochainement :)

suspicion de contamination

ok très bien, merci