- dim. 3 nov. 2013 22:30
#14307
############################## | UsbFix V 7.149 | [Recherche]
Utilisateur: gweny (Administrateur) # GIACK
Mis à jour le 03/11/2013 par El Desaparecido - Team SosVirus
Lancé à 22:20:20 | 03/11/2013
Site Web: https://www.usbfix.net/
Forum : https://www.sosvirus.net/
Upload Malware: https://www.sosvirus.net/upload_malware.php
Contact: https://www.usbfix.net/contact/
PC: Packard Bell (EasyNote TK85)
CPU: Intel(R) Core(TM) i5 CPU M 480 @ 2.67GHz
RAM -> [Total : 3767 | Free : 1249]
Bios: Packard Bell
Boot: Normal boot
OS: Microsoft Windows 7 à‰dition Familiale Premium (6.1.7601 64-Bit) Service Pack 1
WB: Windows Internet Explorer : 10.0.9200.16721
WB: Google Chrome : 30.0.1599.101
WB: Mozilla Firefox : 22.0
SC: Security Center Service [Enabled]
WU: Windows Update Service [Enabled]
AV: Norton AntiVirus [(!) Disabled | Updated]
AS: Windows Defender : 6.1.7600.16385 (win7_rtm.090713-1255)
FW: Windows FireWall Service [Enabled]
C:\ (%systemdrive%) -> Disque fixe # 446 Go (179 Go libre(s) - 40%) [Packard Bell] # NTFS
D:\ -> CD-ROM
E:\ -> Disque amovible # 7 Go (1 Go libre(s) - 16%) [] # FAT32
################## | Référence de comparaison MD5 |
Md5 : DENIED -> C:\Users\gweny\AppData\Local\Temp\iTunesHelper.vbe
Md5 : 67eb1322395d41dddc9045b4eef2309d -> C:\Users\gweny\AppData\Local\Temp\Lanceur.vbs
Md5 : 885e9eb42889ca547f4e3515dcde5d3d -> C:\Users\gweny\AppData\Local\Temp\7za.exe
Md5 : 32bef3bb4b558ade6cf41113628fc86d -> E:\iTunesHelper.vbe
################## | Processus Actif |
C:\Windows\system32\csrss.exe (ID: 460 |ParentID: 452)
C:\Windows\system32\wininit.exe (ID: 584 |ParentID: 452)
C:\Windows\system32\csrss.exe (ID: 608 |ParentID: 596)
C:\Windows\system32\services.exe (ID: 652 |ParentID: 584)
C:\Windows\system32\lsass.exe (ID: 668 |ParentID: 584)
C:\Windows\system32\lsm.exe (ID: 680 |ParentID: 584)
C:\Windows\system32\winlogon.exe (ID: 732 |ParentID: 596)
C:\Windows\system32\svchost.exe (ID: 816 |ParentID: 652)
C:\Windows\system32\svchost.exe (ID: 892 |ParentID: 652)
C:\Windows\System32\svchost.exe (ID: 988 |ParentID: 652)
C:\Windows\System32\svchost.exe (ID: 128 |ParentID: 652)
C:\Windows\system32\svchost.exe (ID: 432 |ParentID: 652)
C:\Windows\system32\svchost.exe (ID: 480 |ParentID: 652)
C:\Windows\system32\svchost.exe (ID: 1072 |ParentID: 652)
C:\Windows\system32\WLANExt.exe (ID: 1228 |ParentID: 128)
C:\Windows\system32\conhost.exe (ID: 1240 |ParentID: 460)
C:\Windows\System32\spoolsv.exe (ID: 1340 |ParentID: 652)
C:\Windows\system32\svchost.exe (ID: 1384 |ParentID: 652)
c:\Program Files (x86)\Adobe\Elements 9 Organizer\PhotoshopElementsFileAgent.exe (ID: 1508 |ParentID: 652)
C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe (ID: 1596 |ParentID: 652)
C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe (ID: 1676 |ParentID: 652)
C:\Program Files\Bonjour\mDNSResponder.exe (ID: 1772 |ParentID: 652)
C:\Program Files (x86)\Launch Manager\dsiwmis.exe (ID: 1804 |ParentID: 652)
C:\Program Files\Packard Bell\Packard Bell Power Management\ePowerSvc.exe (ID: 1848 |ParentID: 652)
C:\ProgramData\EPSON\EPW!3 SSRP\E_S40RPB.EXE (ID: 1872 |ParentID: 652)
C:\Program Files (x86)\Packard Bell\Registration\GREGsvc.exe (ID: 1900 |ParentID: 652)
C:\Program Files\Packard Bell\Packard Bell Updater\UpdaterService.exe (ID: 1932 |ParentID: 652)
C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe (ID: 1980 |ParentID: 652)
C:\Program Files (x86)\Symantec\Norton Online Backup\NOBuAgent.exe (ID: 2032 |ParentID: 652)
C:\Program Files (x86)\NewTech Infosystems\Packard Bell MyBackup\IScheduleSvc.exe (ID: 1532 |ParentID: 652)
C:\Program Files (x86)\Microsoft Application Virtualization Client\sftvsa.exe (ID: 2156 |ParentID: 652)
C:\ProgramData\Skype\Toolbars\Skype C2C Service\c2c_service.exe (ID: 2196 |ParentID: 652)
C:\Windows\system32\svchost.exe (ID: 2284 |ParentID: 652)
C:\Program Files\IB Updater\ExtensionUpdaterService.exe (ID: 2348 |ParentID: 652)
C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE (ID: 2400 |ParentID: 652)
C:\Program Files (x86)\Microsoft Application Virtualization Client\sftlist.exe (ID: 2456 |ParentID: 652)
C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe (ID: 2528 |ParentID: 2400)
C:\Windows\system32\taskhost.exe (ID: 2648 |ParentID: 652)
C:\Windows\system32\Dwm.exe (ID: 2760 |ParentID: 128)
C:\Windows\Explorer.EXE (ID: 2780 |ParentID: 2704)
C:\Program Files (x86)\Common Files\Microsoft Shared\Virtualization Handler\CVHSVC.EXE (ID: 2720 |ParentID: 652)
C:\Windows\system32\SearchIndexer.exe (ID: 3208 |ParentID: 652)
C:\Windows\system32\svchost.exe (ID: 3312 |ParentID: 652)
C:\Windows\system32\svchost.exe (ID: 3468 |ParentID: 652)
C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe (ID: 3572 |ParentID: 2780)
C:\Program Files\Elantech\ETDCtrl.exe (ID: 3556 |ParentID: 2780)
C:\Program Files\Packard Bell\Packard Bell Power Management\ePowerTray.exe (ID: 3724 |ParentID: 2780)
C:\Windows\System32\igfxtray.exe (ID: 3820 |ParentID: 2780)
C:\Windows\System32\hkcmd.exe (ID: 3880 |ParentID: 2780)
C:\Windows\system32\igfxsrvc.exe (ID: 3884 |ParentID: 816)
C:\Windows\system32\wbem\wmiprvse.exe (ID: 3748 |ParentID: 816)
C:\Windows\System32\igfxpers.exe (ID: 3644 |ParentID: 2780)
C:\Windows\System32\spool\drivers\x64\3\E_IATICEE.EXE (ID: 4072 |ParentID: 2780)
C:\Users\gweny\AppData\Roaming\Spotify\Data\SpotifyWebHelper.exe (ID: 3300 |ParentID: 2780)
C:\Windows\System32\wscript.exe (ID: 3764 |ParentID: 2780)
C:\Program Files\Elantech\ETDCtrlHelper.exe (ID: 3936 |ParentID: 3556)
C:\Windows\system32\igfxext.exe (ID: 4108 |ParentID: 816)
C:\Windows\system32\wbem\unsecapp.exe (ID: 4244 |ParentID: 816)
C:\Windows\system32\wbem\wmiprvse.exe (ID: 4352 |ParentID: 816)
C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe (ID: 4444 |ParentID: 4396)
C:\Program Files\Packard Bell\Packard Bell Power Management\ePowerEvent.exe (ID: 4552 |ParentID: 1848)
C:\Program Files (x86)\NewTech Infosystems\Packard Bell MyBackup\BackupManagerTray.exe (ID: 4704 |ParentID: 4396)
C:\Program Files (x86)\Launch Manager\LManager.exe (ID: 4780 |ParentID: 4396)
C:\Program Files (x86)\iMesh Applications\MediaBar\Datamngr\datamngrUI.exe (ID: 4788 |ParentID: 4396)
C:\Program Files (x86)\Citrix\ICA Client\concentr.exe (ID: 4816 |ParentID: 4396)
C:\Program Files (x86)\Real\RealPlayer\Update\realsched.exe (ID: 4868 |ParentID: 4396)
C:\Program Files (x86)\iTunes\iTunesHelper.exe (ID: 4920 |ParentID: 4396)
C:\Program Files (x86)\Citrix\ICA Client\wfcrun32.exe (ID: 4976 |ParentID: 816)
C:\Program Files (x86)\Launch Manager\MMDx64Fx.exe (ID: 4936 |ParentID: 4780)
C:\Program Files (x86)\Launch Manager\LMworker.exe (ID: 4424 |ParentID: 1804)
C:\Program Files\iPod\bin\iPodService.exe (ID: 1260 |ParentID: 652)
C:\Program Files\Windows Media Player\wmpnetwk.exe (ID: 5888 |ParentID: 652)
C:\Windows\System32\svchost.exe (ID: 6028 |ParentID: 652)
C:\Windows\system32\DllHost.exe (ID: 3352 |ParentID: 816)
C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe (ID: 6100 |ParentID: 652)
C:\Program Files (x86)\Nero\Update\NASvc.exe (ID: 2100 |ParentID: 652)
C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe (ID: 4288 |ParentID: 652)
C:\Program Files (x86)\Norton Identity Safe\Engine\2014.6.0.27\NST.exe (ID: 6092 |ParentID: 652)
C:\Program Files (x86)\Norton Identity Safe\Engine\2014.6.0.27\NST.exe (ID: 4672 |ParentID: 6092)
C:\Windows\Microsoft.Net\Framework64\v3.0\WPF\PresentationFontCache.exe (ID: 2252 |ParentID: 652)
C:\Program Files (x86)\Norton AntiVirus\Engine\21.1.0.18\NAV.exe (ID: 4260 |ParentID: 652)
C:\Program Files (x86)\Norton AntiVirus\Engine\21.1.0.18\NAV.exe (ID: 3564 |ParentID: 4260)
C:\Windows\system32\taskhost.exe (ID: 5952 |ParentID: 652)
C:\Users\gweny\AppData\Roaming\Juniper Networks\Setup Client\JuniperSetupClient.exe (ID: 7160 |ParentID: 7768)
C:\Program Files\Internet Explorer\IEXPLORE.EXE (ID: 5336 |ParentID: 6588)
C:\Program Files (x86)\Internet Explorer\IEXPLORE.EXE (ID: 5788 |ParentID: 5336)
C:\Windows\system32\Macromed\Flash\FlashUtil64_11_9_900_117_ActiveX.exe (ID: 7652 |ParentID: 816)
C:\Program Files (x86)\Internet Explorer\IEXPLORE.EXE (ID: 6648 |ParentID: 5336)
C:\UsbFix\Go.exe (ID: 6260 |ParentID: 4764)
C:\Windows\System32\WUDFHost.exe (ID: 7064 |ParentID: 128)
C:\Windows\system32\taskeng.exe (ID: 6264 |ParentID: 480)
\\?\C:\Windows\system32\wbem\WMIADAP.EXE (ID: 6628 |ParentID: 480)
################## | Regedit Run |
04 - HKLM\SOFTWARE | Run : [IAStorIcon] - C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe
04 - HKLM\SOFTWARE | Run : [BackupManagerTray] - "C:\Program Files (x86)\NewTech Infosystems\Packard Bell MyBackup\BackupManagerTray.exe" -h -k
04 - HKLM\SOFTWARE | Run : [Norton Online Backup] - C:\Program Files (x86)\Symantec\Norton Online Backup\NOBuClient.exe
04 - HKLM\SOFTWARE | Run : [LManager] - C:\Program Files (x86)\Launch Manager\LManager.exe
04 - HKLM\SOFTWARE | Run : [DATAMNGR] - C:\PROGRA~2\IMESHA~1\MediaBar\Datamngr\DATAMN~1.EXE
04 - HKLM\SOFTWARE | Run : [ConnectionCenter] - "C:\Program Files (x86)\Citrix\ICA Client\concentr.exe" /startup
04 - HKLM\SOFTWARE | Run : [Adobe ARM] - "C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
04 - HKLM\SOFTWARE | Run : [TkBellExe] - "C:\Program Files (x86)\Real\RealPlayer\Update\realsched.exe" -osboot
04 - HKLM\SOFTWARE | Run : [APSDaemon] - "C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe"
04 - HKLM\SOFTWARE | Run : [iTunesHelper] - "C:\Program Files (x86)\iTunes\iTunesHelper.exe"
04 - HKLM\SOFTWARE\wow6432Node | Run : [IAStorIcon] - C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe
04 - HKLM\SOFTWARE\wow6432Node | Run : [BackupManagerTray] - "C:\Program Files (x86)\NewTech Infosystems\Packard Bell MyBackup\BackupManagerTray.exe" -h -k
04 - HKLM\SOFTWARE\wow6432Node | Run : [Norton Online Backup] - C:\Program Files (x86)\Symantec\Norton Online Backup\NOBuClient.exe
04 - HKLM\SOFTWARE\wow6432Node | Run : [LManager] - C:\Program Files (x86)\Launch Manager\LManager.exe
04 - HKLM\SOFTWARE\wow6432Node | Run : [DATAMNGR] - C:\PROGRA~2\IMESHA~1\MediaBar\Datamngr\DATAMN~1.EXE
04 - HKLM\SOFTWARE\wow6432Node | Run : [ConnectionCenter] - "C:\Program Files (x86)\Citrix\ICA Client\concentr.exe" /startup
04 - HKLM\SOFTWARE\wow6432Node | Run : [Adobe ARM] - "C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
04 - HKLM\SOFTWARE\wow6432Node | Run : [TkBellExe] - "C:\Program Files (x86)\Real\RealPlayer\Update\realsched.exe" -osboot
04 - HKLM\SOFTWARE\wow6432Node | Run : [APSDaemon] - "C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe"
04 - HKLM\SOFTWARE\wow6432Node | Run : [iTunesHelper] - "C:\Program Files (x86)\iTunes\iTunesHelper.exe"
04 - HKLM\SOFTWARE | RunOnce : [] -
04 - HKLM\SOFTWARE\wow6432Node | RunOnce : [] -
04 - HKU\S-1-5-19\SOFTWARE | Run : [Sidebar] - %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun
04 - HKU\S-1-5-20\SOFTWARE | Run : [Sidebar] - %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun
04 - HKU\S-1-5-21-3305769734-3948188298-2800464432-1000\SOFTWARE | Run : [EPSON Stylus DX8400 Series] - C:\Windows\system32\spool\DRIVERS\x64\3\E_IATICEE.EXE /FU "C:\Windows\TEMP\E_SCB99.tmp" /EF "HKCU"
04 - HKU\S-1-5-21-3305769734-3948188298-2800464432-1000\SOFTWARE | Run : [MediaGet2] - C:\Users\gweny\AppData\Local\MediaGet2\mediaget.exe --minimized
04 - HKU\S-1-5-21-3305769734-3948188298-2800464432-1000\SOFTWARE | Run : [Facebook Update] - "C:\Users\gweny\AppData\Local\Facebook\Update\FacebookUpdate.exe" /c /nocrashserver
04 - HKU\S-1-5-21-3305769734-3948188298-2800464432-1000\SOFTWARE | Run : [Spotify] - "C:\Users\gweny\AppData\Roaming\Spotify\Spotify.exe" /uri spotify:autostart
04 - HKU\S-1-5-21-3305769734-3948188298-2800464432-1000\SOFTWARE | Run : [Spotify Web Helper] - "C:\Users\gweny\AppData\Roaming\Spotify\Data\SpotifyWebHelper.exe"
04 - HKU\S-1-5-21-3305769734-3948188298-2800464432-1000\SOFTWARE | Run : [iTunesHelper] - wscript.exe //B "C:\Users\gweny\AppData\Local\Temp\iTunesHelper.vbe"
04 - HKU\S-1-5-19\SOFTWARE | RunOnce : [mctadmin] - C:\Windows\System32\mctadmin.exe
04 - HKU\S-1-5-19\SOFTWARE | RunOnce : [] -
04 - HKU\S-1-5-20\SOFTWARE | RunOnce : [mctadmin] - C:\Windows\System32\mctadmin.exe
04 - HKU\S-1-5-20\SOFTWARE | RunOnce : [] -
04 - HKU\S-1-5-18\SOFTWARE | RunOnce : [] -
################## | Recherche générique |
Présent! C:\Users\gweny\AppData\Local\Temp\iTunesHelper.vbe
Présent! E:\iTunesHelper.vbe
Présent! E:\SECURITAS ENG-WMV.lnk
Présent! E:\The.lnk
Présent! E:\Ins.lnk
Présent! E:\unkrich-toy.lnk
Présent! E:\Moi.lnk
Présent! E:\The.Purge.2013.FRENCH.BRRip.x264.AC3-DesTroY.lnk
Présent! E:\The.Frozen.Ground.2013.LiMiTED.FRENCH.SUBFORCED.BRRip.x264.AC3-FUNKY.lnk
Présent! E:\The.Croods.2013.TRUEFRENCH.BDRip.XviD-TMB.lnk
Présent! E:\Walt Disney - La Belle au bois dormant (French DivX DVD).lnk
Présent! C:\Users\gweny\AppData\Local\Temp\Lanceur.vbs
Présent! C:\Users\gweny\AppData\Local\Temp\7za.exe
################## | Comparaison MD5 |
Présent! Md5 : 885E9EB42889CA547F4E3515DCDE5D3D -> C:\Users\gweny\AppData\Local\Temp\7za.exe
Présent! Md5 : 67EB1322395D41DDDC9045B4EEF2309D -> C:\Users\gweny\AppData\Local\Temp\Lanceur.vbs
################## | Registre |
Présent! HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer|NoFolderOptions -> 0
Présent! HKU\S-1-5-21-3305769734-3948188298-2800464432-1000\Software\Microsoft\Windows\CurrentVersion\Run|iTunesHelper
Présent! HKCU\Software\Microsoft\Windows\CurrentVersion\Run|iTunesHelper
Présent! HKLM\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Run|iTunesHelper
Présent! HKLM\Software\Microsoft\Windows\CurrentVersion\Run|iTunesHelper
################## | Vaccin |
(!) Cet ordinateur n'est pas vacciné!
################## | E.O.F | https://www.usbfix.net - https://www.sosvirus.net |
Utilisateur: gweny (Administrateur) # GIACK
Mis à jour le 03/11/2013 par El Desaparecido - Team SosVirus
Lancé à 22:20:20 | 03/11/2013
Site Web: https://www.usbfix.net/
Forum : https://www.sosvirus.net/
Upload Malware: https://www.sosvirus.net/upload_malware.php
Contact: https://www.usbfix.net/contact/
PC: Packard Bell (EasyNote TK85)
CPU: Intel(R) Core(TM) i5 CPU M 480 @ 2.67GHz
RAM -> [Total : 3767 | Free : 1249]
Bios: Packard Bell
Boot: Normal boot
OS: Microsoft Windows 7 à‰dition Familiale Premium (6.1.7601 64-Bit) Service Pack 1
WB: Windows Internet Explorer : 10.0.9200.16721
WB: Google Chrome : 30.0.1599.101
WB: Mozilla Firefox : 22.0
SC: Security Center Service [Enabled]
WU: Windows Update Service [Enabled]
AV: Norton AntiVirus [(!) Disabled | Updated]
AS: Windows Defender : 6.1.7600.16385 (win7_rtm.090713-1255)
FW: Windows FireWall Service [Enabled]
C:\ (%systemdrive%) -> Disque fixe # 446 Go (179 Go libre(s) - 40%) [Packard Bell] # NTFS
D:\ -> CD-ROM
E:\ -> Disque amovible # 7 Go (1 Go libre(s) - 16%) [] # FAT32
################## | Référence de comparaison MD5 |
Md5 : DENIED -> C:\Users\gweny\AppData\Local\Temp\iTunesHelper.vbe
Md5 : 67eb1322395d41dddc9045b4eef2309d -> C:\Users\gweny\AppData\Local\Temp\Lanceur.vbs
Md5 : 885e9eb42889ca547f4e3515dcde5d3d -> C:\Users\gweny\AppData\Local\Temp\7za.exe
Md5 : 32bef3bb4b558ade6cf41113628fc86d -> E:\iTunesHelper.vbe
################## | Processus Actif |
C:\Windows\system32\csrss.exe (ID: 460 |ParentID: 452)
C:\Windows\system32\wininit.exe (ID: 584 |ParentID: 452)
C:\Windows\system32\csrss.exe (ID: 608 |ParentID: 596)
C:\Windows\system32\services.exe (ID: 652 |ParentID: 584)
C:\Windows\system32\lsass.exe (ID: 668 |ParentID: 584)
C:\Windows\system32\lsm.exe (ID: 680 |ParentID: 584)
C:\Windows\system32\winlogon.exe (ID: 732 |ParentID: 596)
C:\Windows\system32\svchost.exe (ID: 816 |ParentID: 652)
C:\Windows\system32\svchost.exe (ID: 892 |ParentID: 652)
C:\Windows\System32\svchost.exe (ID: 988 |ParentID: 652)
C:\Windows\System32\svchost.exe (ID: 128 |ParentID: 652)
C:\Windows\system32\svchost.exe (ID: 432 |ParentID: 652)
C:\Windows\system32\svchost.exe (ID: 480 |ParentID: 652)
C:\Windows\system32\svchost.exe (ID: 1072 |ParentID: 652)
C:\Windows\system32\WLANExt.exe (ID: 1228 |ParentID: 128)
C:\Windows\system32\conhost.exe (ID: 1240 |ParentID: 460)
C:\Windows\System32\spoolsv.exe (ID: 1340 |ParentID: 652)
C:\Windows\system32\svchost.exe (ID: 1384 |ParentID: 652)
c:\Program Files (x86)\Adobe\Elements 9 Organizer\PhotoshopElementsFileAgent.exe (ID: 1508 |ParentID: 652)
C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe (ID: 1596 |ParentID: 652)
C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe (ID: 1676 |ParentID: 652)
C:\Program Files\Bonjour\mDNSResponder.exe (ID: 1772 |ParentID: 652)
C:\Program Files (x86)\Launch Manager\dsiwmis.exe (ID: 1804 |ParentID: 652)
C:\Program Files\Packard Bell\Packard Bell Power Management\ePowerSvc.exe (ID: 1848 |ParentID: 652)
C:\ProgramData\EPSON\EPW!3 SSRP\E_S40RPB.EXE (ID: 1872 |ParentID: 652)
C:\Program Files (x86)\Packard Bell\Registration\GREGsvc.exe (ID: 1900 |ParentID: 652)
C:\Program Files\Packard Bell\Packard Bell Updater\UpdaterService.exe (ID: 1932 |ParentID: 652)
C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe (ID: 1980 |ParentID: 652)
C:\Program Files (x86)\Symantec\Norton Online Backup\NOBuAgent.exe (ID: 2032 |ParentID: 652)
C:\Program Files (x86)\NewTech Infosystems\Packard Bell MyBackup\IScheduleSvc.exe (ID: 1532 |ParentID: 652)
C:\Program Files (x86)\Microsoft Application Virtualization Client\sftvsa.exe (ID: 2156 |ParentID: 652)
C:\ProgramData\Skype\Toolbars\Skype C2C Service\c2c_service.exe (ID: 2196 |ParentID: 652)
C:\Windows\system32\svchost.exe (ID: 2284 |ParentID: 652)
C:\Program Files\IB Updater\ExtensionUpdaterService.exe (ID: 2348 |ParentID: 652)
C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE (ID: 2400 |ParentID: 652)
C:\Program Files (x86)\Microsoft Application Virtualization Client\sftlist.exe (ID: 2456 |ParentID: 652)
C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe (ID: 2528 |ParentID: 2400)
C:\Windows\system32\taskhost.exe (ID: 2648 |ParentID: 652)
C:\Windows\system32\Dwm.exe (ID: 2760 |ParentID: 128)
C:\Windows\Explorer.EXE (ID: 2780 |ParentID: 2704)
C:\Program Files (x86)\Common Files\Microsoft Shared\Virtualization Handler\CVHSVC.EXE (ID: 2720 |ParentID: 652)
C:\Windows\system32\SearchIndexer.exe (ID: 3208 |ParentID: 652)
C:\Windows\system32\svchost.exe (ID: 3312 |ParentID: 652)
C:\Windows\system32\svchost.exe (ID: 3468 |ParentID: 652)
C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe (ID: 3572 |ParentID: 2780)
C:\Program Files\Elantech\ETDCtrl.exe (ID: 3556 |ParentID: 2780)
C:\Program Files\Packard Bell\Packard Bell Power Management\ePowerTray.exe (ID: 3724 |ParentID: 2780)
C:\Windows\System32\igfxtray.exe (ID: 3820 |ParentID: 2780)
C:\Windows\System32\hkcmd.exe (ID: 3880 |ParentID: 2780)
C:\Windows\system32\igfxsrvc.exe (ID: 3884 |ParentID: 816)
C:\Windows\system32\wbem\wmiprvse.exe (ID: 3748 |ParentID: 816)
C:\Windows\System32\igfxpers.exe (ID: 3644 |ParentID: 2780)
C:\Windows\System32\spool\drivers\x64\3\E_IATICEE.EXE (ID: 4072 |ParentID: 2780)
C:\Users\gweny\AppData\Roaming\Spotify\Data\SpotifyWebHelper.exe (ID: 3300 |ParentID: 2780)
C:\Windows\System32\wscript.exe (ID: 3764 |ParentID: 2780)
C:\Program Files\Elantech\ETDCtrlHelper.exe (ID: 3936 |ParentID: 3556)
C:\Windows\system32\igfxext.exe (ID: 4108 |ParentID: 816)
C:\Windows\system32\wbem\unsecapp.exe (ID: 4244 |ParentID: 816)
C:\Windows\system32\wbem\wmiprvse.exe (ID: 4352 |ParentID: 816)
C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe (ID: 4444 |ParentID: 4396)
C:\Program Files\Packard Bell\Packard Bell Power Management\ePowerEvent.exe (ID: 4552 |ParentID: 1848)
C:\Program Files (x86)\NewTech Infosystems\Packard Bell MyBackup\BackupManagerTray.exe (ID: 4704 |ParentID: 4396)
C:\Program Files (x86)\Launch Manager\LManager.exe (ID: 4780 |ParentID: 4396)
C:\Program Files (x86)\iMesh Applications\MediaBar\Datamngr\datamngrUI.exe (ID: 4788 |ParentID: 4396)
C:\Program Files (x86)\Citrix\ICA Client\concentr.exe (ID: 4816 |ParentID: 4396)
C:\Program Files (x86)\Real\RealPlayer\Update\realsched.exe (ID: 4868 |ParentID: 4396)
C:\Program Files (x86)\iTunes\iTunesHelper.exe (ID: 4920 |ParentID: 4396)
C:\Program Files (x86)\Citrix\ICA Client\wfcrun32.exe (ID: 4976 |ParentID: 816)
C:\Program Files (x86)\Launch Manager\MMDx64Fx.exe (ID: 4936 |ParentID: 4780)
C:\Program Files (x86)\Launch Manager\LMworker.exe (ID: 4424 |ParentID: 1804)
C:\Program Files\iPod\bin\iPodService.exe (ID: 1260 |ParentID: 652)
C:\Program Files\Windows Media Player\wmpnetwk.exe (ID: 5888 |ParentID: 652)
C:\Windows\System32\svchost.exe (ID: 6028 |ParentID: 652)
C:\Windows\system32\DllHost.exe (ID: 3352 |ParentID: 816)
C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe (ID: 6100 |ParentID: 652)
C:\Program Files (x86)\Nero\Update\NASvc.exe (ID: 2100 |ParentID: 652)
C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe (ID: 4288 |ParentID: 652)
C:\Program Files (x86)\Norton Identity Safe\Engine\2014.6.0.27\NST.exe (ID: 6092 |ParentID: 652)
C:\Program Files (x86)\Norton Identity Safe\Engine\2014.6.0.27\NST.exe (ID: 4672 |ParentID: 6092)
C:\Windows\Microsoft.Net\Framework64\v3.0\WPF\PresentationFontCache.exe (ID: 2252 |ParentID: 652)
C:\Program Files (x86)\Norton AntiVirus\Engine\21.1.0.18\NAV.exe (ID: 4260 |ParentID: 652)
C:\Program Files (x86)\Norton AntiVirus\Engine\21.1.0.18\NAV.exe (ID: 3564 |ParentID: 4260)
C:\Windows\system32\taskhost.exe (ID: 5952 |ParentID: 652)
C:\Users\gweny\AppData\Roaming\Juniper Networks\Setup Client\JuniperSetupClient.exe (ID: 7160 |ParentID: 7768)
C:\Program Files\Internet Explorer\IEXPLORE.EXE (ID: 5336 |ParentID: 6588)
C:\Program Files (x86)\Internet Explorer\IEXPLORE.EXE (ID: 5788 |ParentID: 5336)
C:\Windows\system32\Macromed\Flash\FlashUtil64_11_9_900_117_ActiveX.exe (ID: 7652 |ParentID: 816)
C:\Program Files (x86)\Internet Explorer\IEXPLORE.EXE (ID: 6648 |ParentID: 5336)
C:\UsbFix\Go.exe (ID: 6260 |ParentID: 4764)
C:\Windows\System32\WUDFHost.exe (ID: 7064 |ParentID: 128)
C:\Windows\system32\taskeng.exe (ID: 6264 |ParentID: 480)
\\?\C:\Windows\system32\wbem\WMIADAP.EXE (ID: 6628 |ParentID: 480)
################## | Regedit Run |
04 - HKLM\SOFTWARE | Run : [IAStorIcon] - C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe
04 - HKLM\SOFTWARE | Run : [BackupManagerTray] - "C:\Program Files (x86)\NewTech Infosystems\Packard Bell MyBackup\BackupManagerTray.exe" -h -k
04 - HKLM\SOFTWARE | Run : [Norton Online Backup] - C:\Program Files (x86)\Symantec\Norton Online Backup\NOBuClient.exe
04 - HKLM\SOFTWARE | Run : [LManager] - C:\Program Files (x86)\Launch Manager\LManager.exe
04 - HKLM\SOFTWARE | Run : [DATAMNGR] - C:\PROGRA~2\IMESHA~1\MediaBar\Datamngr\DATAMN~1.EXE
04 - HKLM\SOFTWARE | Run : [ConnectionCenter] - "C:\Program Files (x86)\Citrix\ICA Client\concentr.exe" /startup
04 - HKLM\SOFTWARE | Run : [Adobe ARM] - "C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
04 - HKLM\SOFTWARE | Run : [TkBellExe] - "C:\Program Files (x86)\Real\RealPlayer\Update\realsched.exe" -osboot
04 - HKLM\SOFTWARE | Run : [APSDaemon] - "C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe"
04 - HKLM\SOFTWARE | Run : [iTunesHelper] - "C:\Program Files (x86)\iTunes\iTunesHelper.exe"
04 - HKLM\SOFTWARE\wow6432Node | Run : [IAStorIcon] - C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe
04 - HKLM\SOFTWARE\wow6432Node | Run : [BackupManagerTray] - "C:\Program Files (x86)\NewTech Infosystems\Packard Bell MyBackup\BackupManagerTray.exe" -h -k
04 - HKLM\SOFTWARE\wow6432Node | Run : [Norton Online Backup] - C:\Program Files (x86)\Symantec\Norton Online Backup\NOBuClient.exe
04 - HKLM\SOFTWARE\wow6432Node | Run : [LManager] - C:\Program Files (x86)\Launch Manager\LManager.exe
04 - HKLM\SOFTWARE\wow6432Node | Run : [DATAMNGR] - C:\PROGRA~2\IMESHA~1\MediaBar\Datamngr\DATAMN~1.EXE
04 - HKLM\SOFTWARE\wow6432Node | Run : [ConnectionCenter] - "C:\Program Files (x86)\Citrix\ICA Client\concentr.exe" /startup
04 - HKLM\SOFTWARE\wow6432Node | Run : [Adobe ARM] - "C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
04 - HKLM\SOFTWARE\wow6432Node | Run : [TkBellExe] - "C:\Program Files (x86)\Real\RealPlayer\Update\realsched.exe" -osboot
04 - HKLM\SOFTWARE\wow6432Node | Run : [APSDaemon] - "C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe"
04 - HKLM\SOFTWARE\wow6432Node | Run : [iTunesHelper] - "C:\Program Files (x86)\iTunes\iTunesHelper.exe"
04 - HKLM\SOFTWARE | RunOnce : [] -
04 - HKLM\SOFTWARE\wow6432Node | RunOnce : [] -
04 - HKU\S-1-5-19\SOFTWARE | Run : [Sidebar] - %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun
04 - HKU\S-1-5-20\SOFTWARE | Run : [Sidebar] - %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun
04 - HKU\S-1-5-21-3305769734-3948188298-2800464432-1000\SOFTWARE | Run : [EPSON Stylus DX8400 Series] - C:\Windows\system32\spool\DRIVERS\x64\3\E_IATICEE.EXE /FU "C:\Windows\TEMP\E_SCB99.tmp" /EF "HKCU"
04 - HKU\S-1-5-21-3305769734-3948188298-2800464432-1000\SOFTWARE | Run : [MediaGet2] - C:\Users\gweny\AppData\Local\MediaGet2\mediaget.exe --minimized
04 - HKU\S-1-5-21-3305769734-3948188298-2800464432-1000\SOFTWARE | Run : [Facebook Update] - "C:\Users\gweny\AppData\Local\Facebook\Update\FacebookUpdate.exe" /c /nocrashserver
04 - HKU\S-1-5-21-3305769734-3948188298-2800464432-1000\SOFTWARE | Run : [Spotify] - "C:\Users\gweny\AppData\Roaming\Spotify\Spotify.exe" /uri spotify:autostart
04 - HKU\S-1-5-21-3305769734-3948188298-2800464432-1000\SOFTWARE | Run : [Spotify Web Helper] - "C:\Users\gweny\AppData\Roaming\Spotify\Data\SpotifyWebHelper.exe"
04 - HKU\S-1-5-21-3305769734-3948188298-2800464432-1000\SOFTWARE | Run : [iTunesHelper] - wscript.exe //B "C:\Users\gweny\AppData\Local\Temp\iTunesHelper.vbe"
04 - HKU\S-1-5-19\SOFTWARE | RunOnce : [mctadmin] - C:\Windows\System32\mctadmin.exe
04 - HKU\S-1-5-19\SOFTWARE | RunOnce : [] -
04 - HKU\S-1-5-20\SOFTWARE | RunOnce : [mctadmin] - C:\Windows\System32\mctadmin.exe
04 - HKU\S-1-5-20\SOFTWARE | RunOnce : [] -
04 - HKU\S-1-5-18\SOFTWARE | RunOnce : [] -
################## | Recherche générique |
Présent! C:\Users\gweny\AppData\Local\Temp\iTunesHelper.vbe
Présent! E:\iTunesHelper.vbe
Présent! E:\SECURITAS ENG-WMV.lnk
Présent! E:\The.lnk
Présent! E:\Ins.lnk
Présent! E:\unkrich-toy.lnk
Présent! E:\Moi.lnk
Présent! E:\The.Purge.2013.FRENCH.BRRip.x264.AC3-DesTroY.lnk
Présent! E:\The.Frozen.Ground.2013.LiMiTED.FRENCH.SUBFORCED.BRRip.x264.AC3-FUNKY.lnk
Présent! E:\The.Croods.2013.TRUEFRENCH.BDRip.XviD-TMB.lnk
Présent! E:\Walt Disney - La Belle au bois dormant (French DivX DVD).lnk
Présent! C:\Users\gweny\AppData\Local\Temp\Lanceur.vbs
Présent! C:\Users\gweny\AppData\Local\Temp\7za.exe
################## | Comparaison MD5 |
Présent! Md5 : 885E9EB42889CA547F4E3515DCDE5D3D -> C:\Users\gweny\AppData\Local\Temp\7za.exe
Présent! Md5 : 67EB1322395D41DDDC9045B4EEF2309D -> C:\Users\gweny\AppData\Local\Temp\Lanceur.vbs
################## | Registre |
Présent! HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer|NoFolderOptions -> 0
Présent! HKU\S-1-5-21-3305769734-3948188298-2800464432-1000\Software\Microsoft\Windows\CurrentVersion\Run|iTunesHelper
Présent! HKCU\Software\Microsoft\Windows\CurrentVersion\Run|iTunesHelper
Présent! HKLM\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Run|iTunesHelper
Présent! HKLM\Software\Microsoft\Windows\CurrentVersion\Run|iTunesHelper
################## | Vaccin |
(!) Cet ordinateur n'est pas vacciné!
################## | E.O.F | https://www.usbfix.net - https://www.sosvirus.net |