Bonjour,
je vous remercie pour votre aide !!
Voici le rapport de UsbFix :
############################## | UsbFix V 7.145 | [Suppression]
Utilisateur: Hélène (Administrateur) # Hà‰LàˆNE-TOSH
Mis à jour le 17/10/2013 par El Desaparecido - Team SosVirus
Lancé à 12:08:19 | 27/10/2013
Site Web:
https://www.usbfix.net/
Forum :
https://www.sosvirus.net/
Upload Malware:
https://www.sosvirus.net/upload_malware.php
Contact:
https://www.usbfix.net/contact/
PC: TOSHIBA (KSWAA)
CPU: Pentium(R) Dual-Core CPU T4300 @ 2.10GHz
RAM -> [Total : 3933 | Free : 2089]
Bios: TOSHIBA
Boot: Normal boot
OS: Microsoft Windows 7 à‰dition Familiale Premium (6.1.7601 64-Bit) # Service Pack 1
WB: Windows Internet Explorer 10.0.9200.16686
SC: Security Center Service [Enabled]
WU: Windows Update Service [Enabled]
AV: avast! Antivirus [(!) Disabled | Updated]
FW: Windows FireWall Service [Enabled]
C:\ (%systemdrive%) -> Disque fixe # 233 Go (1 Go libre(s) - 0%) [WINDOWS] # NTFS
D:\ -> Disque fixe # 232 Go (8 Go libre(s) - 3%) [Data] # NTFS
E:\ -> CD-ROM
F:\ -> Disque amovible # 4 Go (4 Go libre(s) - 100%) [Hà‰LàˆNE] # FAT32
################## | Regedit Run |
HKLM\SOFTWARE | Run : [SVPWUTIL] - C:\Program Files (x86)\TOSHIBA\Utilities\SVPWUTIL.exe SVPwUTIL
HKLM\SOFTWARE | Run : [HWSetup] - "C:\Program Files\TOSHIBA\Utilities\HWSetup.exe" hwSetUP
HKLM\SOFTWARE | Run : [KeNotify] - C:\Program Files (x86)\TOSHIBA\Utilities\KeNotify.exe
HKLM\SOFTWARE | Run : [TWebCamera] - "%ProgramFiles%\TOSHIBA\TOSHIBA Web Camera Application\TWebCamera.exe" autorun
HKLM\SOFTWARE | Run : [SSDMonitor] - C:\Program Files (x86)\Common Files\PC Tools\sMonitor\SSDMonitor.exe
HKLM\SOFTWARE | Run : [avast5] - "C:\Program Files\Alwil Software\Avast5\avastUI.exe" /nogui
HKLM\SOFTWARE | Run : [ORAHSSSessionManager] - "C:\Program Files (x86)\Orange\Connexion Internet Orange\SessionManager\SessionManager.exe"
HKLM\SOFTWARE | Run : [GrooveMonitor] - "C:\Program Files (x86)\Microsoft Office\Office12\GrooveMonitor.exe"
HKLM\SOFTWARE | Run : [QuickTime Task] - "C:\Program Files (x86)\QuickTime\QTTask.exe" -atboottime
HKLM\SOFTWARE | Run : [iTunesHelper] - "C:\Program Files (x86)\iTunes\iTunesHelper.exe"
HKLM\SOFTWARE | Run : [Adobe Reader Speed Launcher] - "C:\Program Files (x86)\Adobe\Reader 9.0\Reader\Reader_sl.exe"
HKLM\SOFTWARE | Run : [Adobe ARM] - "C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
HKLM\SOFTWARE\wow6432Node | Run : [SVPWUTIL] - C:\Program Files (x86)\TOSHIBA\Utilities\SVPWUTIL.exe SVPwUTIL
HKLM\SOFTWARE\wow6432Node | Run : [HWSetup] - "C:\Program Files\TOSHIBA\Utilities\HWSetup.exe" hwSetUP
HKLM\SOFTWARE\wow6432Node | Run : [KeNotify] - C:\Program Files (x86)\TOSHIBA\Utilities\KeNotify.exe
HKLM\SOFTWARE\wow6432Node | Run : [TWebCamera] - "%ProgramFiles%\TOSHIBA\TOSHIBA Web Camera Application\TWebCamera.exe" autorun
HKLM\SOFTWARE\wow6432Node | Run : [SSDMonitor] - C:\Program Files (x86)\Common Files\PC Tools\sMonitor\SSDMonitor.exe
HKLM\SOFTWARE\wow6432Node | Run : [avast5] - "C:\Program Files\Alwil Software\Avast5\avastUI.exe" /nogui
HKLM\SOFTWARE\wow6432Node | Run : [ORAHSSSessionManager] - "C:\Program Files (x86)\Orange\Connexion Internet Orange\SessionManager\SessionManager.exe"
HKLM\SOFTWARE\wow6432Node | Run : [GrooveMonitor] - "C:\Program Files (x86)\Microsoft Office\Office12\GrooveMonitor.exe"
HKLM\SOFTWARE\wow6432Node | Run : [QuickTime Task] - "C:\Program Files (x86)\QuickTime\QTTask.exe" -atboottime
HKLM\SOFTWARE\wow6432Node | Run : [iTunesHelper] - "C:\Program Files (x86)\iTunes\iTunesHelper.exe"
HKLM\SOFTWARE\wow6432Node | Run : [Adobe Reader Speed Launcher] - "C:\Program Files (x86)\Adobe\Reader 9.0\Reader\Reader_sl.exe"
HKLM\SOFTWARE\wow6432Node | Run : [Adobe ARM] - "C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
HKLM\SOFTWARE | RunOnce : [] -
HKLM\SOFTWARE\wow6432Node | RunOnce : [] -
HKU\S-1-5-19\SOFTWARE | Run : [Sidebar] - %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun
HKU\S-1-5-20\SOFTWARE | Run : [Sidebar] - %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun
HKU\S-1-5-21-3942088474-775173721-4025348067-1000\SOFTWARE | Run : [RegistryMechanic] - C:\Program Files (x86)\Registry Mechanic\RMTray.exe /H
HKU\S-1-5-21-3942088474-775173721-4025348067-1000\SOFTWARE | Run : [Sidebar] - C:\Program Files\Windows Sidebar\sidebar.exe /autoRun
HKU\S-1-5-21-3942088474-775173721-4025348067-1000\SOFTWARE | Run : [OrangeInside] - C:\Users\Hélène\AppData\Roaming\Orange\OrangeInside\one\OrangeInside.exe
HKU\S-1-5-21-3942088474-775173721-4025348067-1000\SOFTWARE | Run : [Facebook Update] - "C:\Users\Hélène\AppData\Local\Facebook\Update\FacebookUpdate.exe" /c /nocrashserver
HKU\S-1-5-21-3942088474-775173721-4025348067-1000\SOFTWARE | Run : [swg] - "C:\Program Files (x86)\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe"
HKU\S-1-5-21-3942088474-775173721-4025348067-1000\SOFTWARE | Run : [cacaoweb] - "C:\Users\Hélène\AppData\Roaming\cacaoweb\cacaoweb.exe" -noplayer
HKU\S-1-5-21-3942088474-775173721-4025348067-1000\SOFTWARE | Run : [Intel(R)Service] - wscript.exe //B "C:\Users\HLNE~1\AppData\Local\Temp\Intel(R)Service.vbs"
HKU\S-1-5-18\SOFTWARE | Run : [TOSHIBA Online Product Information] - C:\Program Files (x86)\TOSHIBA\Toshiba Online Product Information\topi.exe
HKU\S-1-5-19\SOFTWARE | RunOnce : [mctadmin] - C:\Windows\System32\mctadmin.exe
HKU\S-1-5-20\SOFTWARE | RunOnce : [mctadmin] - C:\Windows\System32\mctadmin.exe
################## | Processus Stoppés |
Stoppé! C:\Program Files\Alwil Software\Avast5\AvastSvc.exe (ID 1216 |ParentID 604)
Stoppé! C:\Windows\System32\spoolsv.exe (ID 1412 |ParentID 604)
Stoppé! C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe (ID 1540 |ParentID 604)
Stoppé! C:\Program Files (x86)\Bonjour\mDNSResponder.exe (ID 1956 |ParentID 604)
Stoppé! C:\Windows\SysWOW64\schtasks.exe (ID 1964 |ParentID 1920)
Stoppé! C:\Windows\system32\conhost.exe (ID 1976 |ParentID 492)
Stoppé! C:\PROGRA~2\COMMON~1\France Telecom\Shared Modules\FTRTSVC\0\FTRTSVC.exe (ID 1124 |ParentID 604)
Stoppé! C:\Program Files (x86)\Common Files\PC Tools\sMonitor\StartManSvc.exe (ID 2020 |ParentID 604)
Stoppé! C:\ProgramData\Skype\Toolbars\Skype C2C Service\c2c_service.exe (ID 1880 |ParentID 604)
Stoppé! C:\Program Files (x86)\Toshiba TEMPRO\TemproSvc.exe (ID 2096 |ParentID 604)
Stoppé! C:\Windows\system32\TODDSrv.exe (ID 2188 |ParentID 604)
Stoppé! C:\Program Files\TOSHIBA\Power Saver\TosCoSrv.exe (ID 2220 |ParentID 604)
Stoppé! C:\Program Files\TOSHIBA\TECO\TecoService.exe (ID 2300 |ParentID 604)
Stoppé! C:\Windows\system32\msiexec.exe (ID 2980 |ParentID 604)
Stoppé! C:\Windows\system32\taskhost.exe (ID 2732 |ParentID 604)
Stoppé! C:\Windows\Explorer.EXE (ID 2092 |ParentID 1896)
Stoppé! C:\Program Files (x86)\Toshiba TEMPRO\TemproTray.exe (ID 3388 |ParentID 2092)
Stoppé! C:\Program Files\TOSHIBA\BulletinBoard\TosNcCore.exe (ID 3432 |ParentID 2092)
Stoppé! C:\Program Files\TOSHIBA\ReelTime\TosReelTimeMonitor.exe (ID 3568 |ParentID 2092)
Stoppé! C:\Windows\System32\igfxtray.exe (ID 3580 |ParentID 2092)
Stoppé! C:\Windows\System32\hkcmd.exe (ID 3588 |ParentID 2092)
Stoppé! C:\Windows\System32\igfxpers.exe (ID 3596 |ParentID 2092)
Stoppé! C:\Windows\system32\igfxsrvc.exe (ID 3628 |ParentID 736)
Stoppé! C:\Program Files\TOSHIBA\SmoothView\SmoothView.exe (ID 3656 |ParentID 2092)
Stoppé! C:\Windows\system32\SearchIndexer.exe (ID 3764 |ParentID 604)
Stoppé! C:\Program Files\TOSHIBA\Power Saver\TPwrMain.exe (ID 4020 |ParentID 2092)
Stoppé! C:\Program Files (x86)\TOSHIBA\ConfigFree\CFIWmxSvcs64.exe (ID 4068 |ParentID 604)
Stoppé! C:\Program Files\TOSHIBA\FlashCards\TCrdMain.exe (ID 3444 |ParentID 2092)
Stoppé! C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe (ID 1932 |ParentID 2092)
Stoppé! C:\Program Files\Synaptics\SynTP\SynTPEnh.exe (ID 3372 |ParentID 2092)
Stoppé! C:\Program Files\TOSHIBA\TECO\TEco.exe (ID 3972 |ParentID 2092)
Stoppé! C:\Program Files\TOSHIBA\Registration\ToshibaReminder.exe (ID 3556 |ParentID 2092)
Stoppé! C:\Program Files\Windows Sidebar\sidebar.exe (ID 3468 |ParentID 2092)
Stoppé! C:\Program Files (x86)\TOSHIBA\ConfigFree\CFProcSRVC.exe (ID 4476 |ParentID 604)
Stoppé! C:\Users\Hélène\AppData\Roaming\cacaoweb\cacaoweb.exe (ID 4560 |ParentID 2092)
Stoppé! C:\Windows\system32\igfxext.exe (ID 4632 |ParentID 736)
Stoppé! C:\Program Files (x86)\TOSHIBA\ConfigFree\CFSvcs.exe (ID 5000 |ParentID 604)
Stoppé! C:\Program Files\Synaptics\SynTP\SynTPHelper.exe (ID 236 |ParentID 3372)
Stoppé! C:\Program Files (x86)\TOSHIBA\Utilities\KeNotify.exe (ID 1920 |ParentID 4592)
Stoppé! C:\ProgramData\BitGuard\2.6.1694.246\{c16c1ccb-7046-4e5c-a2f3-533ad2fec8e8}\BitGuard.exe (ID 2920 |ParentID 604)
Stoppé! C:\Program Files (x86)\Common Files\PC Tools\sMonitor\SSDMonitor.exe (ID 4672 |ParentID 4592)
Stoppé! C:\Program Files\Alwil Software\Avast5\AvastUI.exe (ID 3220 |ParentID 4592)
Stoppé! C:\Program Files (x86)\iTunes\iTunesHelper.exe (ID 4764 |ParentID 4592)
Stoppé! C:\Windows\SysWOW64\schtasks.exe (ID 3856 |ParentID 4948)
Stoppé! C:\ProgramData\BitGuard\2.6.1694.246\{c16c1ccb-7046-4e5c-a2f3-533ad2fec8e8}\BitGuard.exe (ID 4528 |ParentID 2920)
Stoppé! C:\Program Files (x86)\Orange\Connexion Internet Orange\Launcher\Launcher.exe (ID 5072 |ParentID 256)
Stoppé! C:\Windows\system32\conhost.exe (ID 3464 |ParentID 560)
Stoppé! C:\PROGRA~2\COMMON~1\France Telecom\Shared Modules\AlertModule\0\AlertModule.exe (ID 5248 |ParentID 736)
Stoppé! C:\Program Files\iPod\bin\iPodService.exe (ID 5444 |ParentID 604)
Stoppé! C:\Program Files (x86)\Orange\Connexion Internet Orange\systray\systrayapp.exe (ID 5656 |ParentID 5072)
Stoppé! C:\Program Files (x86)\Orange\Connexion Internet Orange\connectivity\connectivitymanager.exe (ID 5692 |ParentID 5072)
Stoppé! C:\Program Files (x86)\Orange\Connexion Internet Orange\connectivity\CoreCom\CoreCom.exe (ID 5788 |ParentID 5692)
Stoppé! C:\Program Files (x86)\Orange\Connexion Internet Orange\connectivity\CoreCom\OraConfigRecover.exe (ID 6016 |ParentID 5788)
Stoppé! C:\Program Files\TOSHIBA\TOSHIBA HDD SSD Alert\TosSmartSrv.exe (ID 5564 |ParentID 604)
Stoppé! C:\Program Files\TOSHIBA\TOSHIBA HDD SSD Alert\TosSENotify.exe (ID 5408 |ParentID 3308)
Stoppé! C:\Program Files\TOSHIBA\TPHM\TPCHSrv.exe (ID 4948 |ParentID 604)
Stoppé! C:\Program Files\TOSHIBA\TPHM\TPCHWMsg.exe (ID 5320 |ParentID 1480)
Stoppé! C:\Windows\system32\rundll32.exe (ID 5684 |ParentID 488)
Stoppé! C:\Windows\system32\vssvc.exe (ID 2428 |ParentID 604)
Stoppé! C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe (ID 5504 |ParentID 1400)
Stoppé! C:\Windows\System32\wscript.exe (ID 3352 |ParentID 6864)
Stoppé! C:\Windows\system32\taskhost.exe (ID 4604 |ParentID 604)
Stoppé! C:\Windows\system32\wuauclt.exe (ID 3540 |ParentID 484)
Stoppé! C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (ID 3164 |ParentID 2092)
Stoppé! C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (ID 7876 |ParentID 3164)
Stoppé! C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (ID 7328 |ParentID 3164)
Stoppé! C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (ID 3348 |ParentID 3164)
Stoppé! C:\Program Files (x86)\Internet Explorer\IELowutil.exe (ID 6836 |ParentID 3784)
Stoppé! C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (ID 7252 |ParentID 3164)
Stoppé! C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (ID 5948 |ParentID 3164)
Stoppé! C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (ID 3324 |ParentID 3164)
Stoppé! C:\Windows\system32\taskeng.exe (ID 7140 |ParentID 484)
Stoppé! C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (ID 6656 |ParentID 3164)
Stoppé! C:\Windows\System32\WUDFHost.exe (ID 5008 |ParentID 1016)
Stoppé! C:\Windows\system32\taskhost.exe (ID 6876 |ParentID 604)
################## | à‰léments infectieux |
Supprimé! F:\Intel(R)Service.vbs
Supprimé! C:\Users\HLNE~1\AppData\Local\Temp\Intel(R)Service.vbs
Supprimé! C:\Users\Hélène\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Intel(R)Service.vbs
(!) Fichiers temporaires supprimés.
################## | Registre |
Supprimé! HKU\S-1-5-21-3942088474-775173721-4025348067-1000\Software\Microsoft\Windows\CurrentVersion\Run|Intel(R)Service
################## | Listing |
[19/12/2009 - 20:27:15 | SHD ] C:\$RECYCLE.BIN
[04/09/2009 - 14:49:05 | D ] C:\1033
[16/11/2012 - 01:55:49 | D ] C:\204ebae9efa537a695
[22/03/2013 - 11:39:50 | D ] C:\BioEdit
[14/07/2009 - 06:08:56 | SHD ] C:\Documents and Settings
[14/10/2013 - 09:19:48 | ASH | 3092938752] C:\hiberfil.sys
[04/10/2009 - 08:14:15 | D ] C:\Intel
[04/09/2009 - 14:49:13 | RHD ] C:\MSOCache
[14/10/2013 - 09:19:52 | ASH | 4123918336] C:\pagefile.sys
[14/07/2009 - 04:20:08 | D ] C:\PerfLogs
[01/05/2013 - 19:37:36 | D ] C:\Program Files
[17/10/2013 - 13:51:55 | D ] C:\Program Files (x86)
[15/09/2013 - 09:32:33 | HD ] C:\ProgramData
[04/10/2009 - 08:23:26 | N | 2942] C:\RHDSetup.log
[20/12/2009 - 15:21:31 | N | 159] C:\Setup.log
[04/09/2009 - 15:18:06 | N | 70] C:\SWSTAMP.TXT
[22/10/2013 - 18:12:39 | SHD ] C:\System Volume Information
[19/12/2009 - 20:27:08 | D ] C:\Toshiba
[27/10/2013 - 12:15:12 | D ] C:\UsbFix
[27/10/2013 - 12:18:02 | A | 13286] C:\UsbFix [Clean 1] Hà‰LàˆNE-TOSH.txt
[26/10/2013 - 12:35:15 | N | 13618] C:\UsbFix [Scan 2] Hà‰LàˆNE-TOSH.txt
[02/09/2013 - 16:25:31 | RD ] C:\Users
[03/09/2013 - 19:37:38 | D ] C:\Windows
[04/09/2009 - 14:47:52 | D ] C:\Works
[19/12/2009 - 20:27:15 | SHD ] D:\$RECYCLE.BIN
[16/08/2013 - 16:55:18 | D ] D:\111f0f44f0c3b47e7ca2
[19/01/2013 - 15:46:27 | D ] D:\FILMS
[20/12/2009 - 05:22:36 | D ] D:\HDDRecovery
[11/09/2009 - 17:43:21 | N | 11] D:\R11461FR.tag
[04/10/2009 - 08:11:39 | SHD ] D:\System Volume Information
################## | Vaccin |
C:\Autorun.inf -> Vaccin créé par UsbFix (El Desaparecido)
D:\Autorun.inf -> Vaccin créé par UsbFix (El Desaparecido)
F:\Autorun.inf -> Vaccin créé par UsbFix (El Desaparecido)
################## | E.O.F |
https://www.usbfix.net -
https://www.sosvirus.net |