Voilà le rapport:
############################## | UsbFix V 7.145 | [Suppression]
Utilisateur: amedrine (Administrateur) # AMEDRINE-PC
Mis à jour le 17/10/2013 par El Desaparecido - Team SosVirus
Lancé à 17:28:25 | 22/10/2013
Site Web:
https://www.usbfix.net/
Forum :
https://www.sosvirus.net/
Upload Malware:
https://www.sosvirus.net/upload_malware.php
Contact:
https://www.usbfix.net/contact/
PC: ASUSTeK Computer INC. (P8P67 PRO)
CPU: Intel(R) Core(TM) i7-2600 CPU @ 3.40GHz
RAM -> [Total : 4076 | Free : 2040]
Bios: American Megatrends Inc.
Boot: Normal boot
OS: Microsoft Windows 7 à‰dition Familiale Premium (6.1.7601 64-Bit) # Service Pack 1
WB: Windows Internet Explorer 10.0.9200.16721
SC: Security Center Service [Enabled]
WU: Windows Update Service [Enabled]
AV: G Data TotalCare 2012 [Enabled | Updated]
FW: Windows FireWall Service [Enabled]
C:\ (%systemdrive%) -> Disque fixe # 100 Go (54 Go libre(s) - 53%) [] # NTFS
D:\ -> CD-ROM
E:\ -> Disque fixe # 415 Go (301 Go libre(s) - 73%) [Données] # NTFS
################## | Regedit Run |
HKLM\SOFTWARE | Run : [NUSB3MON] - "C:\Program Files (x86)\Renesas Electronics\USB 3.0 Host Controller Driver\Application\nusb3mon.exe"
HKLM\SOFTWARE | Run : [IAStorIcon] - C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe
HKLM\SOFTWARE | Run : [JMB36X IDE Setup] - C:\Windows\RaidTool\xInsIDE.exe
HKLM\SOFTWARE | Run : [ASUS ShellProcess Execute] - C:\Program Files (x86)\ASUS\AI Suite II\ASUS Mobilink\Simulator\AsShellProcess.exe
HKLM\SOFTWARE | Run : [G Data AntiVirus Tray Application] - C:\Program Files (x86)\G Data\TotalCare\AVKTray\AVKTray.exe
HKLM\SOFTWARE | Run : [GDFirewallTray] - C:\Program Files (x86)\G Data\TotalCare\Firewall\GDFirewallTray.exe
HKLM\SOFTWARE | Run : [Adobe ARM] - "C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
HKLM\SOFTWARE | Run : [SunJavaUpdateSched] - "C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe"
HKLM\SOFTWARE | Run : [] -
HKLM\SOFTWARE | Run : [Acrobat Assistant 8.0] - "C:\Program Files (x86)\Adobe\Acrobat 11.0\Acrobat\Acrotray.exe"
HKLM\SOFTWARE | Run : [NPSStartup] -
HKLM\SOFTWARE\wow6432Node | Run : [NUSB3MON] - "C:\Program Files (x86)\Renesas Electronics\USB 3.0 Host Controller Driver\Application\nusb3mon.exe"
HKLM\SOFTWARE\wow6432Node | Run : [IAStorIcon] - C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe
HKLM\SOFTWARE\wow6432Node | Run : [JMB36X IDE Setup] - C:\Windows\RaidTool\xInsIDE.exe
HKLM\SOFTWARE\wow6432Node | Run : [ASUS ShellProcess Execute] - C:\Program Files (x86)\ASUS\AI Suite II\ASUS Mobilink\Simulator\AsShellProcess.exe
HKLM\SOFTWARE\wow6432Node | Run : [G Data AntiVirus Tray Application] - C:\Program Files (x86)\G Data\TotalCare\AVKTray\AVKTray.exe
HKLM\SOFTWARE\wow6432Node | Run : [GDFirewallTray] - C:\Program Files (x86)\G Data\TotalCare\Firewall\GDFirewallTray.exe
HKLM\SOFTWARE\wow6432Node | Run : [Adobe ARM] - "C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
HKLM\SOFTWARE\wow6432Node | Run : [SunJavaUpdateSched] - "C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe"
HKLM\SOFTWARE\wow6432Node | Run : [] -
HKLM\SOFTWARE\wow6432Node | Run : [Acrobat Assistant 8.0] - "C:\Program Files (x86)\Adobe\Acrobat 11.0\Acrobat\Acrotray.exe"
HKLM\SOFTWARE\wow6432Node | Run : [NPSStartup] -
HKLM\SOFTWARE | RunOnce : [] -
HKLM\SOFTWARE\wow6432Node | RunOnce : [] -
HKU\S-1-5-19\SOFTWARE | Run : [Sidebar] - %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun
HKU\S-1-5-20\SOFTWARE | Run : [Sidebar] - %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun
HKU\S-1-5-21-289441953-525629660-1903516566-1000\SOFTWARE | Run : [SpybotSD TeaTimer] - C:\Program Files (x86)\Spybot - Search & Destroy\TeaTimer.exe
HKU\S-1-5-21-289441953-525629660-1903516566-1000\SOFTWARE | Run : [Connexion SFR 9props.exe] - "C:\Program Files (x86)\Neuf\Kit\9props.exe" /trayicon
HKU\S-1-5-21-289441953-525629660-1903516566-1000\SOFTWARE | Run : [Skype] - "C:\Program Files (x86)\Skype\Phone\Skype.exe" /minimized /regrun
HKU\S-1-5-21-289441953-525629660-1903516566-1000\SOFTWARE | Run : [AutoStartNPSAgent] - C:\Program Files (x86)\Samsung\Samsung New PC Studio\NPSAgent.exe
HKU\S-1-5-19\SOFTWARE | RunOnce : [mctadmin] - C:\Windows\System32\mctadmin.exe
HKU\S-1-5-20\SOFTWARE | RunOnce : [mctadmin] - C:\Windows\System32\mctadmin.exe
################## | Processus Stoppés |
Stoppé! C:\Windows\system32\nvvsvc.exe (ID 896 |ParentID 708)
Stoppé! C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe (ID 920 |ParentID 708)
Stoppé! C:\Program Files (x86)\Common Files\G Data\GDScan\GDScan.exe (ID 348 |ParentID 708)
Stoppé! C:\Program Files (x86)\G Data\TotalCare\AVK\AVKWCtlX64.exe (ID 532 |ParentID 708)
Stoppé! C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe (ID 1396 |ParentID 896)
Stoppé! C:\Windows\system32\nvvsvc.exe (ID 1404 |ParentID 896)
Stoppé! C:\Windows\System32\spoolsv.exe (ID 1704 |ParentID 708)
Stoppé! C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe (ID 1884 |ParentID 708)
Stoppé! C:\Program Files (x86)\ASUS\AXSP\1.00.12\atkexComSvc.exe (ID 1916 |ParentID 708)
Stoppé! C:\Program Files (x86)\ASUS\AAHM\1.00.09\aaHMSvc.exe (ID 1964 |ParentID 708)
Stoppé! C:\Program Files (x86)\ASUS\AsSysCtrlService\1.00.10\AsSysCtrlService.exe (ID 2000 |ParentID 708)
Stoppé! C:\Program Files (x86)\Bluetooth Suite\adminservice.exe (ID 2024 |ParentID 708)
Stoppé! C:\Windows\system32\taskhost.exe (ID 1592 |ParentID 708)
Stoppé! C:\Windows\system32\taskeng.exe (ID 1556 |ParentID 1108)
Stoppé! C:\Program Files (x86)\Common Files\G Data\AVKProxy\AVKProxy.exe (ID 1512 |ParentID 708)
Stoppé! C:\Windows\system32\taskeng.exe (ID 1140 |ParentID 1108)
Stoppé! C:\Program Files\Microsoft Mouse and Keyboard Center\ipoint.exe (ID 2076 |ParentID 1556)
Stoppé! C:\Windows\system32\taskeng.exe (ID 2088 |ParentID 1108)
Stoppé! C:\Program Files (x86)\G Data\TotalCare\AVK\AVKService.exe (ID 2144 |ParentID 708)
Stoppé! C:\Windows\system32\IProsetMonitor.exe (ID 2232 |ParentID 708)
Stoppé! C:\Program Files (x86)\Google\Update\GoogleUpdate.exe (ID 2240 |ParentID 1140)
Stoppé! C:\Windows\Explorer.EXE (ID 2252 |ParentID 1228)
Stoppé! C:\Program Files (x86)\ASUS\AI Suite II\DIGI+ VRM\VRMHelp.exe (ID 2316 |ParentID 2088)
Stoppé! C:\Program Files\Microsoft Mouse and Keyboard Center\itype.exe (ID 2332 |ParentID 1556)
Stoppé! C:\Program Files (x86)\ASUS\AI Suite II\AsRoutineController.exe (ID 2340 |ParentID 2088)
Stoppé! C:\Program Files (x86)\Common Files\Protexis\License Service\PSIService.exe (ID 2440 |ParentID 708)
Stoppé! C:\Program Files (x86)\SFR\Gestionnaire de Connexion\SFR.DashBoard.Service.exe (ID 2500 |ParentID 708)
Stoppé! C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe (ID 2860 |ParentID 2252)
Stoppé! C:\Program Files (x86)\Bluetooth Suite\BtvStack.exe (ID 2868 |ParentID 2252)
Stoppé! C:\Program Files (x86)\Bluetooth Suite\AthBtTray.exe (ID 2876 |ParentID 2252)
Stoppé! C:\Windows\WindowsMobile\wmdc.exe (ID 2884 |ParentID 2252)
Stoppé! C:\Program Files (x86)\Neuf\Kit\9props.exe (ID 3032 |ParentID 2252)
Stoppé! C:\Program Files (x86)\Skype\Phone\Skype.exe (ID 2680 |ParentID 2252)
Stoppé! C:\Program Files (x86)\Samsung\Samsung New PC Studio\NPSAgent.exe (ID 2640 |ParentID 2252)
Stoppé! C:\Program Files\NVIDIA Corporation\Display\nvtray.exe (ID 2628 |ParentID 1396)
Stoppé! C:\Program Files (x86)\Microsoft Office\Office12\ONENOTEM.EXE (ID 528 |ParentID 2252)
Stoppé! C:\Program Files (x86)\Renesas Electronics\USB 3.0 Host Controller Driver\Application\nusb3mon.exe (ID 3088 |ParentID 1856)
Stoppé! C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe (ID 3144 |ParentID 1856)
Stoppé! C:\Program Files (x86)\ASUS\AI Suite II\ASUS Mobilink\Simulator\AsShellProcess.exe (ID 3168 |ParentID 1856)
Stoppé! C:\Program Files (x86)\G Data\TotalCare\AVKTray\AVKTray.exe (ID 3188 |ParentID 1856)
Stoppé! C:\Program Files (x86)\G Data\TotalCare\Firewall\GDFirewallTray.exe (ID 3204 |ParentID 1856)
Stoppé! C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe (ID 3288 |ParentID 1856)
Stoppé! C:\Program Files (x86)\Adobe\Acrobat 11.0\Acrobat\acrotray.exe (ID 3312 |ParentID 1856)
Stoppé! C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE (ID 3616 |ParentID 708)
Stoppé! C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe (ID 3720 |ParentID 3616)
Stoppé! C:\Program Files (x86)\Spybot - Search & Destroy\SDWinSec.exe (ID 3728 |ParentID 708)
Stoppé! C:\Windows\system32\SearchIndexer.exe (ID 4068 |ParentID 708)
Stoppé! C:\Program Files (x86)\G Data\TotalCare\Firewall\GDFwSvcx64.exe (ID 4148 |ParentID 708)
Stoppé! C:\Program Files (x86)\ASUS\AI Suite II\ASUS Mobilink\iPhone Simulator\pnSvc.exe (ID 4508 |ParentID 2396)
Stoppé! C:\Program Files (x86)\ASUS\AI Suite II\ASUS Mobilink\Simulator\EC Simulator.exe (ID 4932 |ParentID 2396)
Stoppé! C:\Program Files (x86)\Common Files\G Data\AVKProxy\AvkBap64.exe (ID 4864 |ParentID 828)
Stoppé! C:\Program Files (x86)\ASUS\AI Suite II\TurboV EVO\TurboVHelp.exe (ID 5900 |ParentID 2340)
Stoppé! C:\Program Files (x86)\ASUS\AI Suite II\EPU\EPUHelp.exe (ID 6068 |ParentID 2340)
Stoppé! C:\Program Files (x86)\ASUS\AI Suite II\AI Suite II.exe (ID 2532 |ParentID 2340)
Stoppé! C:\Program Files (x86)\ASUS\AI Suite II\Sensor\AlertHelper\AlertHelper.exe (ID 4244 |ParentID 2532)
Stoppé! C:\Program Files\Internet Explorer\IEXPLORE.EXE (ID 6020 |ParentID 5280)
Stoppé! C:\Windows\system32\wuauclt.exe (ID 2044 |ParentID 1108)
Stoppé! C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbarUser_32.exe (ID 5644 |ParentID 6020)
Stoppé! C:\Windows\system32\Macromed\Flash\FlashUtil64_11_9_900_117_ActiveX.exe (ID 5956 |ParentID 828)
Stoppé! C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbam.exe (ID 3344 |ParentID 2252)
Stoppé! C:\Program Files (x86)\G Data\TotalCare\GUI\GDSC.exe (ID 7424 |ParentID 3188)
################## | à‰léments infectieux |
(!) Fichiers temporaires supprimés.
################## | Registre |
################## | Listing |
[06/10/2011 - 12:47:39 | SHD ] C:\$Recycle.Bin
[22/10/2013 - 14:33:29 | D ] C:\AdwCleaner
[22/10/2013 - 14:22:28 | RASHD ] C:\Autorun.inf
[09/09/2012 - 15:09:07 | N | 26] C:\ChromeHPLog.txt
[14/07/2009 - 07:08:56 | SHD ] C:\Documents and Settings
[22/10/2013 - 16:25:19 | ASH | 3205754880] C:\hiberfil.sys
[27/01/2011 - 19:39:18 | D ] C:\Intel
[27/01/2011 - 20:35:23 | RHD ] C:\MSOCache
[27/01/2011 - 20:03:09 | D ] C:\NVIDIA
[22/10/2013 - 16:25:23 | ASH | 4274339840] C:\pagefile.sys
[17/03/2013 - 10:15:51 | D ] C:\PerfLogs
[22/10/2013 - 14:56:29 | N | 512] C:\PhysicalDisk0_MBR.bin
[26/07/2013 - 12:04:30 | D ] C:\Program Files
[22/10/2013 - 14:50:44 | D ] C:\Program Files (x86)
[22/10/2013 - 15:47:09 | HD ] C:\ProgramData
[28/02/2013 - 17:55:19 | D ] C:\PyGrenouille
[27/01/2011 - 19:48:04 | D ] C:\RaidTool
[27/01/2011 - 19:35:52 | SHD ] C:\Recovery
[22/10/2013 - 12:54:29 | D ] C:\rsit
[27/01/2011 - 19:59:15 | N | 90] C:\setup.log
[22/10/2013 - 12:44:36 | SHD ] C:\System Volume Information
[22/10/2013 - 17:30:42 | D ] C:\UsbFix
[22/10/2013 - 14:22:28 | N | 12764] C:\UsbFix [Clean 1] AMEDRINE-PC.txt
[22/10/2013 - 17:31:38 | A | 11338] C:\UsbFix [Clean 2] AMEDRINE-PC.txt
[22/10/2013 - 13:45:09 | N | 11514] C:\UsbFix [Scan 1] AMEDRINE-PC.txt
[26/01/2012 - 21:24:37 | N | 1492] C:\user.js
[06/07/2011 - 19:41:28 | RD ] C:\Users
[22/10/2013 - 12:05:10 | D ] C:\Windows
[22/10/2013 - 15:47:08 | D ] C:\_OTM
[09/02/2011 - 20:27:23 | SHD ] E:\$RECYCLE.BIN
[22/10/2013 - 14:22:28 | RASHD ] E:\Autorun.inf
[16/01/2008 - 13:48:06 | N | 1110] E:\globdata.ini
[16/01/2008 - 13:48:06 | N | 562688] E:\install.exe
[16/01/2008 - 13:48:14 | N | 843] E:\install.ini
[16/01/2008 - 13:52:54 | N | 97296] E:\install.res.1036.dll
[12/09/2013 - 07:42:12 | D ] E:\Ma musique
[19/10/2013 - 17:59:10 | D ] E:\Mes documents
[12/09/2013 - 07:42:12 | D ] E:\Mes images
[12/09/2013 - 07:42:12 | D ] E:\Mes videos
[06/07/2011 - 20:17:25 | SHD ] E:\System Volume Information
[16/01/2008 - 13:58:54 | N | 1442522] E:\VC_RED.cab
[16/01/2008 - 14:00:56 | N | 233984] E:\VC_RED.MSI
################## | Vaccin |
C:\Autorun.inf -> Vaccin créé par UsbFix (El Desaparecido)
E:\Autorun.inf -> Vaccin créé par UsbFix (El Desaparecido)
################## | E.O.F |
https://www.usbfix.net -
https://www.sosvirus.net |