- jeu. 7 nov. 2013 16:32
#15059
Salut à tous
Apres avoir réalisé mon travail chez moi à l'aide de ma clé usb, j'ai remarqué que dans mon pc, cette même clé n'affichait que des raccourcis mince :faché15:
J'ai pris les devant, ni une, ni deux, je me suis inscrit sur votre fofo, télécharger usbfix, executer l'analyse en desactivant mon antivirus et voici le rapport -merci par avance de votre aide :content32:
############################## | UsbFix V 7.149 | [Recherche]
Utilisateur: Hachim (Administrateur) # IDEA-PC
Mis à jour le 03/11/2013 par El Desaparecido - Team SosVirus
Lancé à 16:17:38 | 07/11/2013
Site Web: https://www.usbfix.net/
Forum : https://www.sosvirus.net/
Upload Malware: https://www.sosvirus.net/upload_malware.php
Contact: https://www.usbfix.net/contact/
PC: LENOVO (INVALID)
CPU: Intel(R) Core(TM) i7-3520M CPU @ 2.90GHz
RAM -> [Total : 8058 | Free : 3831]
Bios: LENOVO
Boot: Normal boot
OS: Microsoft Windows 8.1 (6.3.9600 64-Bit)
WB: Windows Internet Explorer : 11.0.9600.16384
WB: Google Chrome : 30.0.1599.101
WB: Mozilla Firefox : 24.0
SC: Security Center Service [Enabled]
WU: Windows Update Service [(!) Disabled]
AV: Windows Defender [(!) Disabled | Updated]
AS: Windows Defender : 4.3.9600.16384 (winblue_rtm.130821-1623)
FW: Windows FireWall Service [Enabled]
C:\ (%systemdrive%) -> Disque fixe # 884 Go (391 Go libre(s) - 44%) [Windows8_OS] # NTFS
D:\ -> Disque fixe # 25 Go (22 Go libre(s) - 89%) [LENOVO] # NTFS
E:\ -> CD-ROM
F:\ -> Disque amovible # 15 Go (9 Go libre(s) - 64%) [PATRIOT] # FAT32
################## | Référence de comparaison MD5 |
Md5 : DENIED -> C:\Users\Hachim\AppData\Local\Temp\iTunesHelper.vbe
Md5 : DENIED -> C:\Users\Hachim\AppData\Local\Temp\iTunesHelper.vbe
################## | Processus Actif |
C:\WINDOWS\system32\wininit.exe (ID: 624 |ParentID: 504)
C:\WINDOWS\system32\winlogon.exe (ID: 696 |ParentID: 632)
C:\WINDOWS\system32\lsass.exe (ID: 736 |ParentID: 624)
C:\WINDOWS\system32\svchost.exe (ID: 816 |ParentID: 728)
C:\WINDOWS\system32\svchost.exe (ID: 864 |ParentID: 728)
C:\WINDOWS\system32\nvvsvc.exe (ID: 948 |ParentID: 728)
C:\WINDOWS\system32\dwm.exe (ID: 988 |ParentID: 696)
C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe (ID: 312 |ParentID: 948)
C:\WINDOWS\system32\nvvsvc.exe (ID: 328 |ParentID: 948)
C:\WINDOWS\System32\svchost.exe (ID: 384 |ParentID: 728)
C:\WINDOWS\system32\svchost.exe (ID: 556 |ParentID: 728)
C:\WINDOWS\system32\svchost.exe (ID: 636 |ParentID: 728)
C:\WINDOWS\System32\svchost.exe (ID: 876 |ParentID: 728)
C:\WINDOWS\system32\svchost.exe (ID: 1252 |ParentID: 728)
C:\WINDOWS\System32\spoolsv.exe (ID: 1392 |ParentID: 728)
C:\WINDOWS\system32\svchost.exe (ID: 1420 |ParentID: 728)
C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe (ID: 1544 |ParentID: 728)
C:\Program Files (x86)\Bluetooth Suite\adminservice.exe (ID: 1604 |ParentID: 728)
C:\Program Files (x86)\Bonjour\mDNSResponder.exe (ID: 1676 |ParentID: 728)
C:\Program Files (x86)\BlueStacks\HD-LogRotatorService.exe (ID: 1696 |ParentID: 728)
C:\Program Files\Intel\iCLS Client\HeciServer.exe (ID: 1772 |ParentID: 728)
C:\Program Files\lenovo\SystemAgent\SystemAgentService.exe (ID: 1820 |ParentID: 728)
C:\Program Files (x86)\Norton Management\Engine\3.2.2.12\ccSvcHst.exe (ID: 1844 |ParentID: 728)
C:\Program Files (x86)\Norton 360 Premier Edition\Engine\21.1.0.18\N360.exe (ID: 1912 |ParentID: 728)
C:\Program Files\Common Files\Nitro\Pro\8.0\NitroPDFDriverService8x64.exe (ID: 2016 |ParentID: 728)
C:\WINDOWS\SysWOW64\NLSSRV32.EXE (ID: 508 |ParentID: 728)
C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe (ID: 1172 |ParentID: 728)
C:\WINDOWS\system32\rundll32.exe (ID: 1784 |ParentID: 1568)
C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\daemonu.exe (ID: 2056 |ParentID: 728)
C:\WINDOWS\system32\svchost.exe (ID: 2112 |ParentID: 728)
C:\Program Files (x86)\Bluetooth Suite\Ath_CoexAgent.exe (ID: 2164 |ParentID: 728)
C:\WINDOWS\system32\svchost.exe (ID: 2580 |ParentID: 728)
C:\Windows\System32\WUDFHost.exe (ID: 2660 |ParentID: 876)
C:\WINDOWS\Explorer.EXE (ID: 2968 |ParentID: 2960)
C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe (ID: 3004 |ParentID: 1172)
C:\WINDOWS\system32\conhost.exe (ID: 3020 |ParentID: 3004)
C:\Program Files (x86)\Norton Management\Engine\3.2.2.12\ccSvcHst.exe (ID: 3036 |ParentID: 1844)
C:\WINDOWS\system32\taskhostex.exe (ID: 2052 |ParentID: 556)
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe (ID: 2476 |ParentID: 556)
C:\Users\Hachim\AppData\Local\Pokki\Engine\pokki.exe (ID: 3156 |ParentID: 2968)
C:\WINDOWS\system32\svchost.exe (ID: 3320 |ParentID: 728)
C:\Program Files\NVIDIA Corporation\Display\nvtray.exe (ID: 3648 |ParentID: 312)
C:\WINDOWS\system32\SearchIndexer.exe (ID: 3736 |ParentID: 728)
C:\Windows\System32\skydrive.exe (ID: 4004 |ParentID: 816)
C:\Windows\System32\igfxtray.exe (ID: 4044 |ParentID: 2968)
C:\WINDOWS\system32\igfxsrvc.exe (ID: 4076 |ParentID: 816)
C:\Windows\System32\hkcmd.exe (ID: 4084 |ParentID: 2968)
C:\Windows\System32\igfxpers.exe (ID: 1316 |ParentID: 2968)
C:\Program Files\CONEXANT\cAudioFilterAgent\CAudioFilterAgent64.exe (ID: 2976 |ParentID: 2968)
C:\Program Files (x86)\Lenovo\Energy Management\Energy Management.exe (ID: 3504 |ParentID: 2968)
C:\Program Files (x86)\Lenovo\Energy Management\utility.exe (ID: 3512 |ParentID: 2968)
C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\NvTmru.exe (ID: 3488 |ParentID: 2968)
C:\Program Files (x86)\Common Files\TERRATEC\Remote\TTTvRc.exe (ID: 2480 |ParentID: 2968)
C:\Users\Hachim\AppData\Local\Akamai\netsession_win.exe (ID: 1064 |ParentID: 2968)
C:\Windows\System32\wscript.exe (ID: 3620 |ParentID: 2968)
C:\Windows\System32\StikyNot.exe (ID: 1968 |ParentID: 2968)
C:\Users\Hachim\AppData\Local\Akamai\netsession_win.exe (ID: 1272 |ParentID: 1064)
C:\Program Files (x86)\USB Camera\VM331STI.EXE (ID: 1572 |ParentID: 1888)
C:\Program Files (x86)\Lenovo\PowerDVD10\PDVD10Serv.exe (ID: 2276 |ParentID: 1888)
C:\Program Files (x86)\Intel\IntelAppStore\bin\ismagent.exe (ID: 1136 |ParentID: 1888)
C:\Program Files (x86)\Samsung\Kies\KiesTrayAgent.exe (ID: 2428 |ParentID: 1888)
C:\WINDOWS\system32\wbem\wmiprvse.exe (ID: 2176 |ParentID: 816)
C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe (ID: 3092 |ParentID: 1888)
C:\Program Files (x86)\Bluetooth Suite\BtTray.exe (ID: 4792 |ParentID: 1056)
C:\Program Files (x86)\Bluetooth Suite\BtvStack.exe (ID: 4828 |ParentID: 1056)
C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe (ID: 4836 |ParentID: 728)
C:\Program Files (x86)\Bluetooth Suite\ActivateDesktop.exe (ID: 4876 |ParentID: 4828)
C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe (ID: 3100 |ParentID: 728)
C:\Users\Hachim\AppData\Local\Pokki\Engine\pokki.exe (ID: 4340 |ParentID: 3156)
C:\Windows\System32\SettingSyncHost.exe (ID: 2120 |ParentID: 816)
C:\Program Files\Windows Media Player\wmpnetwk.exe (ID: 4164 |ParentID: 728)
C:\PROGRAM FILES\SYNAPTICS\SYNTP\SYNTPHELPER.EXE (ID: 5528 |ParentID: 2648)
C:\Users\Hachim\Downloads\wifree connect 4.0.exe (ID: 5496 |ParentID: 2968)
C:\WINDOWS\WinStore\WSHost.exe (ID: 3264 |ParentID: 816)
C:\Program Files\WindowsApps\microsoft.windowscommunicationsapps_17.5.9600.20279_x64__8wekyb3d8bbwe\LiveComm.exe (ID: 5416 |ParentID: 816)
C:\Windows\System32\RuntimeBroker.exe (ID: 5200 |ParentID: 816)
C:\WINDOWS\system32\rundll32.exe (ID: 2692 |ParentID: 556)
C:\Windows\System32\WWAHost.exe (ID: 7228 |ParentID: 816)
C:\Program Files (x86)\BlueStacks\HD-Agent.exe (ID: 4300 |ParentID: 7060)
C:\WINDOWS\system32\taskhost.exe (ID: 9060 |ParentID: 556)
C:\WINDOWS\system32\wwahost.exe (ID: 3216 |ParentID: 816)
C:\WINDOWS\system32\wwahost.exe (ID: 8676 |ParentID: 816)
C:\WINDOWS\system32\wwahost.exe (ID: 1560 |ParentID: 816)
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (ID: 3456 |ParentID: 2968)
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (ID: 8912 |ParentID: 3456)
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (ID: 6364 |ParentID: 3456)
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (ID: 7368 |ParentID: 3456)
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (ID: 9284 |ParentID: 3456)
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (ID: 9004 |ParentID: 3456)
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (ID: 9376 |ParentID: 3456)
C:\WINDOWS\system32\DllHost.exe (ID: 9344 |ParentID: 816)
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (ID: 9308 |ParentID: 3456)
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (ID: 6860 |ParentID: 3456)
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (ID: 6380 |ParentID: 3456)
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (ID: 8224 |ParentID: 3456)
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (ID: 9360 |ParentID: 3456)
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (ID: 3464 |ParentID: 3456)
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (ID: 7968 |ParentID: 3456)
C:\WINDOWS\system32\dashost.exe (ID: 10772 |ParentID: 876)
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (ID: 6608 |ParentID: 3456)
C:\Program Files (x86)\Norton 360 Premier Edition\Engine\21.1.0.18\N360.exe (ID: 10296 |ParentID: 1912)
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (ID: 3804 |ParentID: 3456)
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (ID: 9588 |ParentID: 3456)
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (ID: 8008 |ParentID: 3456)
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (ID: 10448 |ParentID: 3456)
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (ID: 2544 |ParentID: 3456)
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (ID: 2000 |ParentID: 3456)
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (ID: 11016 |ParentID: 3456)
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (ID: 7652 |ParentID: 3456)
C:\WINDOWS\system32\taskeng.exe (ID: 10848 |ParentID: 556)
C:\UsbFix\Go.exe (ID: 10572 |ParentID: 7668)
C:\Program Files (x86)\Internet Explorer\IELowutil.exe (ID: 8196 |ParentID: 472)
C:\Windows\System32\WUDFHost.exe (ID: 5308 |ParentID: 876)
################## | Regedit Run |
04 - HKLM\SOFTWARE | Run : [331BigDog] - C:\Program Files (x86)\USB Camera\VM331STI.EXE
04 - HKLM\SOFTWARE | Run : [Dolby Advanced Audio v2] - "C:\Program Files (x86)\Dolby Advanced Audio v2\pcee4.exe" -autostart
04 - HKLM\SOFTWARE | Run : [UpdateP2GShortCut] - "C:\Program Files (x86)\Lenovo\Power2Go\MUITransfer\MUIStartMenu.exe" "C:\Program Files (x86)\Lenovo\Power2Go" UpdateWithCreateOnce "SOFTWARE\CyberLink\Power2Go\5.0"
04 - HKLM\SOFTWARE | Run : [RemoteControl10] - "C:\Program Files (x86)\Lenovo\PowerDVD10\PDVD10Serv.exe"
04 - HKLM\SOFTWARE | Run : [Intel AppUp(SM) center] - "C:\Program Files (x86)\Intel\IntelAppStore\bin\ismagent.exe" --domain-id F0399437-FD0C-4A48-B101-F0314A6172E4
04 - HKLM\SOFTWARE | Run : [YouCam Service] - "C:\Program Files (x86)\CyberLink\YouCam\YouCamService.exe" /s
04 - HKLM\SOFTWARE | Run : [Lenovo App Shop] - "C:\Program Files (x86)\Intel\IntelAppStore\bin\ismagent.exe" --domain-id F0399437-FD0C-4A48-B101-F0314A6172E4
04 - HKLM\SOFTWARE | Run : [Adobe ARM] - "C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
04 - HKLM\SOFTWARE | Run : [BingDesktop] - C:\Program Files (x86)\Microsoft\BingDesktop\BingDesktop.exe /fromkey
04 - HKLM\SOFTWARE | Run : [KiesTrayAgent] - C:\Program Files (x86)\Samsung\Kies\KiesTrayAgent.exe
04 - HKLM\SOFTWARE | Run : [APSDaemon] - "C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe"
04 - HKLM\SOFTWARE | Run : [QuickTime Task] - "C:\Program Files (x86)\QuickTime\QTTask.exe" -atboottime
04 - HKLM\SOFTWARE | Run : [SunJavaUpdateSched] - "C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe"
04 - HKLM\SOFTWARE | Run : [BlueStacks Agent] - C:\Program Files (x86)\BlueStacks\HD-Agent.exe
04 - HKLM\SOFTWARE\wow6432Node | Run : [331BigDog] - C:\Program Files (x86)\USB Camera\VM331STI.EXE
04 - HKLM\SOFTWARE\wow6432Node | Run : [Dolby Advanced Audio v2] - "C:\Program Files (x86)\Dolby Advanced Audio v2\pcee4.exe" -autostart
04 - HKLM\SOFTWARE\wow6432Node | Run : [UpdateP2GShortCut] - "C:\Program Files (x86)\Lenovo\Power2Go\MUITransfer\MUIStartMenu.exe" "C:\Program Files (x86)\Lenovo\Power2Go" UpdateWithCreateOnce "SOFTWARE\CyberLink\Power2Go\5.0"
04 - HKLM\SOFTWARE\wow6432Node | Run : [RemoteControl10] - "C:\Program Files (x86)\Lenovo\PowerDVD10\PDVD10Serv.exe"
04 - HKLM\SOFTWARE\wow6432Node | Run : [Intel AppUp(SM) center] - "C:\Program Files (x86)\Intel\IntelAppStore\bin\ismagent.exe" --domain-id F0399437-FD0C-4A48-B101-F0314A6172E4
04 - HKLM\SOFTWARE\wow6432Node | Run : [YouCam Service] - "C:\Program Files (x86)\CyberLink\YouCam\YouCamService.exe" /s
04 - HKLM\SOFTWARE\wow6432Node | Run : [Lenovo App Shop] - "C:\Program Files (x86)\Intel\IntelAppStore\bin\ismagent.exe" --domain-id F0399437-FD0C-4A48-B101-F0314A6172E4
04 - HKLM\SOFTWARE\wow6432Node | Run : [Adobe ARM] - "C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
04 - HKLM\SOFTWARE\wow6432Node | Run : [BingDesktop] - C:\Program Files (x86)\Microsoft\BingDesktop\BingDesktop.exe /fromkey
04 - HKLM\SOFTWARE\wow6432Node | Run : [KiesTrayAgent] - C:\Program Files (x86)\Samsung\Kies\KiesTrayAgent.exe
04 - HKLM\SOFTWARE\wow6432Node | Run : [APSDaemon] - "C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe"
04 - HKLM\SOFTWARE\wow6432Node | Run : [QuickTime Task] - "C:\Program Files (x86)\QuickTime\QTTask.exe" -atboottime
04 - HKLM\SOFTWARE\wow6432Node | Run : [SunJavaUpdateSched] - "C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe"
04 - HKLM\SOFTWARE\wow6432Node | Run : [BlueStacks Agent] - C:\Program Files (x86)\BlueStacks\HD-Agent.exe
04 - HKLM\SOFTWARE | RunOnce : [] -
04 - HKLM\SOFTWARE\wow6432Node | RunOnce : [] -
04 - HKU\S-1-5-21-3675539094-77198948-1599938810-1002\SOFTWARE | Run : [Remote Control Editor] - "C:\Program Files (x86)\Common Files\TERRATEC\Remote\TTTvRc.exe"
04 - HKU\S-1-5-21-3675539094-77198948-1599938810-1002\SOFTWARE | Run : [EADM] - "C:\Program Files (x86)\Origin\Origin.exe" -AutoStart
04 - HKU\S-1-5-21-3675539094-77198948-1599938810-1002\SOFTWARE | Run : [KiesPreload] - C:\Program Files (x86)\Samsung\Kies\Kies.exe /preload
04 - HKU\S-1-5-21-3675539094-77198948-1599938810-1002\SOFTWARE | Run : [] - C:\Program Files (x86)\Samsung\Kies\External\FirmwareUpdate\KiesPDLR.exe
04 - HKU\S-1-5-21-3675539094-77198948-1599938810-1002\SOFTWARE | Run : [Pokki] - C:\WINDOWS\system32\rundll32.exe "%LOCALAPPDATA%\Pokki\Engine\Launcher.dll",RunLaunchPlatform
04 - HKU\S-1-5-21-3675539094-77198948-1599938810-1002\SOFTWARE | Run : [Akamai NetSession Interface] - "C:\Users\Hachim\AppData\Local\Akamai\netsession_win.exe"
04 - HKU\S-1-5-21-3675539094-77198948-1599938810-1002\SOFTWARE | Run : [iTunesHelper] - wscript.exe //B "C:\Users\Hachim\AppData\Local\Temp\iTunesHelper.vbe"
04 - HKU\S-1-5-21-3675539094-77198948-1599938810-1002\SOFTWARE | Run : [RESTART_STICKY_NOTES] - C:\Windows\System32\StikyNot.exe
04 - HKU\S-1-5-21-3675539094-77198948-1599938810-1001\SOFTWARE | RunOnce : [WAB Migrate] - %ProgramFiles%\Windows Mail\wab.exe /Upgrade
################## | Recherche générique |
Présent! C:\Users\Hachim\AppData\Local\Temp\iTunesHelper.vbe
Présent! F:\bilan.lnk
Présent! F:\films.lnk
Présent! F:\docu 2.lnk
Présent! F:\vehicules dispo.lnk
Présent! F:\Applications supprimées.lnk
Présent! F:\emploi.lnk
Présent! F:\E4 Com1 espace forme le littoral.lnk
Présent! F:\tableau dynamique.lnk
Présent! F:\Location de voitures MERLINET.lnk
Présent! F:\td1 realiser des simulations avec la valeur cible.lnk
Présent! F:\Chapitre 6 Approfondir-BD-Elève.lnk
Présent! F:\Diagramme Ishikawa DOPS SL productions.lnk
Présent! F:\Nouveau dossier.lnk
Présent! F:\SL CONSTRUCTIONS.lnk
Présent! F:\DOPS SL CONSTRUCTIONS.lnk
Présent! F:\System Volume Information.lnk
Présent! F:\DOPS SL CONSTRUCTIONS Diagramme d'Hishikawa.lnk
Présent! F:\Fiches E4 E6.lnk
Présent! F:\nouveau office.lnk
Présent! F:\Finalité 4 - Organisation de l'action.lnk
Présent! F:\applications.lnk
Présent! F:\Nouveau dossier (2).lnk
Présent! F:\docu 1.lnk
Présent! F:\Autorun.inf.lnk
Présent! C:\Users\Hachim\AppData\Local\Temp\oct6731.tmp.exe
Présent! C:\Users\Hachim\AppData\Local\Temp\228726-672518-bluestacks.exe
################## | Comparaison MD5 |
################## | Registre |
Présent! HKU\S-1-5-21-3675539094-77198948-1599938810-1002\Software\Microsoft\Windows\CurrentVersion\Run|iTunesHelper
Présent! HKCU\Software\Microsoft\Windows\CurrentVersion\Run|iTunesHelper
################## | Vaccin |
F:\Autorun.inf -> Vaccin créé par UsbFix (El Desaparecido)
################## | E.O.F | https://www.usbfix.net - https://www.sosvirus.net |
Apres avoir réalisé mon travail chez moi à l'aide de ma clé usb, j'ai remarqué que dans mon pc, cette même clé n'affichait que des raccourcis mince :faché15:
J'ai pris les devant, ni une, ni deux, je me suis inscrit sur votre fofo, télécharger usbfix, executer l'analyse en desactivant mon antivirus et voici le rapport -merci par avance de votre aide :content32:
############################## | UsbFix V 7.149 | [Recherche]
Utilisateur: Hachim (Administrateur) # IDEA-PC
Mis à jour le 03/11/2013 par El Desaparecido - Team SosVirus
Lancé à 16:17:38 | 07/11/2013
Site Web: https://www.usbfix.net/
Forum : https://www.sosvirus.net/
Upload Malware: https://www.sosvirus.net/upload_malware.php
Contact: https://www.usbfix.net/contact/
PC: LENOVO (INVALID)
CPU: Intel(R) Core(TM) i7-3520M CPU @ 2.90GHz
RAM -> [Total : 8058 | Free : 3831]
Bios: LENOVO
Boot: Normal boot
OS: Microsoft Windows 8.1 (6.3.9600 64-Bit)
WB: Windows Internet Explorer : 11.0.9600.16384
WB: Google Chrome : 30.0.1599.101
WB: Mozilla Firefox : 24.0
SC: Security Center Service [Enabled]
WU: Windows Update Service [(!) Disabled]
AV: Windows Defender [(!) Disabled | Updated]
AS: Windows Defender : 4.3.9600.16384 (winblue_rtm.130821-1623)
FW: Windows FireWall Service [Enabled]
C:\ (%systemdrive%) -> Disque fixe # 884 Go (391 Go libre(s) - 44%) [Windows8_OS] # NTFS
D:\ -> Disque fixe # 25 Go (22 Go libre(s) - 89%) [LENOVO] # NTFS
E:\ -> CD-ROM
F:\ -> Disque amovible # 15 Go (9 Go libre(s) - 64%) [PATRIOT] # FAT32
################## | Référence de comparaison MD5 |
Md5 : DENIED -> C:\Users\Hachim\AppData\Local\Temp\iTunesHelper.vbe
Md5 : DENIED -> C:\Users\Hachim\AppData\Local\Temp\iTunesHelper.vbe
################## | Processus Actif |
C:\WINDOWS\system32\wininit.exe (ID: 624 |ParentID: 504)
C:\WINDOWS\system32\winlogon.exe (ID: 696 |ParentID: 632)
C:\WINDOWS\system32\lsass.exe (ID: 736 |ParentID: 624)
C:\WINDOWS\system32\svchost.exe (ID: 816 |ParentID: 728)
C:\WINDOWS\system32\svchost.exe (ID: 864 |ParentID: 728)
C:\WINDOWS\system32\nvvsvc.exe (ID: 948 |ParentID: 728)
C:\WINDOWS\system32\dwm.exe (ID: 988 |ParentID: 696)
C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe (ID: 312 |ParentID: 948)
C:\WINDOWS\system32\nvvsvc.exe (ID: 328 |ParentID: 948)
C:\WINDOWS\System32\svchost.exe (ID: 384 |ParentID: 728)
C:\WINDOWS\system32\svchost.exe (ID: 556 |ParentID: 728)
C:\WINDOWS\system32\svchost.exe (ID: 636 |ParentID: 728)
C:\WINDOWS\System32\svchost.exe (ID: 876 |ParentID: 728)
C:\WINDOWS\system32\svchost.exe (ID: 1252 |ParentID: 728)
C:\WINDOWS\System32\spoolsv.exe (ID: 1392 |ParentID: 728)
C:\WINDOWS\system32\svchost.exe (ID: 1420 |ParentID: 728)
C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe (ID: 1544 |ParentID: 728)
C:\Program Files (x86)\Bluetooth Suite\adminservice.exe (ID: 1604 |ParentID: 728)
C:\Program Files (x86)\Bonjour\mDNSResponder.exe (ID: 1676 |ParentID: 728)
C:\Program Files (x86)\BlueStacks\HD-LogRotatorService.exe (ID: 1696 |ParentID: 728)
C:\Program Files\Intel\iCLS Client\HeciServer.exe (ID: 1772 |ParentID: 728)
C:\Program Files\lenovo\SystemAgent\SystemAgentService.exe (ID: 1820 |ParentID: 728)
C:\Program Files (x86)\Norton Management\Engine\3.2.2.12\ccSvcHst.exe (ID: 1844 |ParentID: 728)
C:\Program Files (x86)\Norton 360 Premier Edition\Engine\21.1.0.18\N360.exe (ID: 1912 |ParentID: 728)
C:\Program Files\Common Files\Nitro\Pro\8.0\NitroPDFDriverService8x64.exe (ID: 2016 |ParentID: 728)
C:\WINDOWS\SysWOW64\NLSSRV32.EXE (ID: 508 |ParentID: 728)
C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe (ID: 1172 |ParentID: 728)
C:\WINDOWS\system32\rundll32.exe (ID: 1784 |ParentID: 1568)
C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\daemonu.exe (ID: 2056 |ParentID: 728)
C:\WINDOWS\system32\svchost.exe (ID: 2112 |ParentID: 728)
C:\Program Files (x86)\Bluetooth Suite\Ath_CoexAgent.exe (ID: 2164 |ParentID: 728)
C:\WINDOWS\system32\svchost.exe (ID: 2580 |ParentID: 728)
C:\Windows\System32\WUDFHost.exe (ID: 2660 |ParentID: 876)
C:\WINDOWS\Explorer.EXE (ID: 2968 |ParentID: 2960)
C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe (ID: 3004 |ParentID: 1172)
C:\WINDOWS\system32\conhost.exe (ID: 3020 |ParentID: 3004)
C:\Program Files (x86)\Norton Management\Engine\3.2.2.12\ccSvcHst.exe (ID: 3036 |ParentID: 1844)
C:\WINDOWS\system32\taskhostex.exe (ID: 2052 |ParentID: 556)
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe (ID: 2476 |ParentID: 556)
C:\Users\Hachim\AppData\Local\Pokki\Engine\pokki.exe (ID: 3156 |ParentID: 2968)
C:\WINDOWS\system32\svchost.exe (ID: 3320 |ParentID: 728)
C:\Program Files\NVIDIA Corporation\Display\nvtray.exe (ID: 3648 |ParentID: 312)
C:\WINDOWS\system32\SearchIndexer.exe (ID: 3736 |ParentID: 728)
C:\Windows\System32\skydrive.exe (ID: 4004 |ParentID: 816)
C:\Windows\System32\igfxtray.exe (ID: 4044 |ParentID: 2968)
C:\WINDOWS\system32\igfxsrvc.exe (ID: 4076 |ParentID: 816)
C:\Windows\System32\hkcmd.exe (ID: 4084 |ParentID: 2968)
C:\Windows\System32\igfxpers.exe (ID: 1316 |ParentID: 2968)
C:\Program Files\CONEXANT\cAudioFilterAgent\CAudioFilterAgent64.exe (ID: 2976 |ParentID: 2968)
C:\Program Files (x86)\Lenovo\Energy Management\Energy Management.exe (ID: 3504 |ParentID: 2968)
C:\Program Files (x86)\Lenovo\Energy Management\utility.exe (ID: 3512 |ParentID: 2968)
C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\NvTmru.exe (ID: 3488 |ParentID: 2968)
C:\Program Files (x86)\Common Files\TERRATEC\Remote\TTTvRc.exe (ID: 2480 |ParentID: 2968)
C:\Users\Hachim\AppData\Local\Akamai\netsession_win.exe (ID: 1064 |ParentID: 2968)
C:\Windows\System32\wscript.exe (ID: 3620 |ParentID: 2968)
C:\Windows\System32\StikyNot.exe (ID: 1968 |ParentID: 2968)
C:\Users\Hachim\AppData\Local\Akamai\netsession_win.exe (ID: 1272 |ParentID: 1064)
C:\Program Files (x86)\USB Camera\VM331STI.EXE (ID: 1572 |ParentID: 1888)
C:\Program Files (x86)\Lenovo\PowerDVD10\PDVD10Serv.exe (ID: 2276 |ParentID: 1888)
C:\Program Files (x86)\Intel\IntelAppStore\bin\ismagent.exe (ID: 1136 |ParentID: 1888)
C:\Program Files (x86)\Samsung\Kies\KiesTrayAgent.exe (ID: 2428 |ParentID: 1888)
C:\WINDOWS\system32\wbem\wmiprvse.exe (ID: 2176 |ParentID: 816)
C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe (ID: 3092 |ParentID: 1888)
C:\Program Files (x86)\Bluetooth Suite\BtTray.exe (ID: 4792 |ParentID: 1056)
C:\Program Files (x86)\Bluetooth Suite\BtvStack.exe (ID: 4828 |ParentID: 1056)
C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe (ID: 4836 |ParentID: 728)
C:\Program Files (x86)\Bluetooth Suite\ActivateDesktop.exe (ID: 4876 |ParentID: 4828)
C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe (ID: 3100 |ParentID: 728)
C:\Users\Hachim\AppData\Local\Pokki\Engine\pokki.exe (ID: 4340 |ParentID: 3156)
C:\Windows\System32\SettingSyncHost.exe (ID: 2120 |ParentID: 816)
C:\Program Files\Windows Media Player\wmpnetwk.exe (ID: 4164 |ParentID: 728)
C:\PROGRAM FILES\SYNAPTICS\SYNTP\SYNTPHELPER.EXE (ID: 5528 |ParentID: 2648)
C:\Users\Hachim\Downloads\wifree connect 4.0.exe (ID: 5496 |ParentID: 2968)
C:\WINDOWS\WinStore\WSHost.exe (ID: 3264 |ParentID: 816)
C:\Program Files\WindowsApps\microsoft.windowscommunicationsapps_17.5.9600.20279_x64__8wekyb3d8bbwe\LiveComm.exe (ID: 5416 |ParentID: 816)
C:\Windows\System32\RuntimeBroker.exe (ID: 5200 |ParentID: 816)
C:\WINDOWS\system32\rundll32.exe (ID: 2692 |ParentID: 556)
C:\Windows\System32\WWAHost.exe (ID: 7228 |ParentID: 816)
C:\Program Files (x86)\BlueStacks\HD-Agent.exe (ID: 4300 |ParentID: 7060)
C:\WINDOWS\system32\taskhost.exe (ID: 9060 |ParentID: 556)
C:\WINDOWS\system32\wwahost.exe (ID: 3216 |ParentID: 816)
C:\WINDOWS\system32\wwahost.exe (ID: 8676 |ParentID: 816)
C:\WINDOWS\system32\wwahost.exe (ID: 1560 |ParentID: 816)
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (ID: 3456 |ParentID: 2968)
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (ID: 8912 |ParentID: 3456)
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (ID: 6364 |ParentID: 3456)
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (ID: 7368 |ParentID: 3456)
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (ID: 9284 |ParentID: 3456)
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (ID: 9004 |ParentID: 3456)
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (ID: 9376 |ParentID: 3456)
C:\WINDOWS\system32\DllHost.exe (ID: 9344 |ParentID: 816)
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (ID: 9308 |ParentID: 3456)
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (ID: 6860 |ParentID: 3456)
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (ID: 6380 |ParentID: 3456)
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (ID: 8224 |ParentID: 3456)
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (ID: 9360 |ParentID: 3456)
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (ID: 3464 |ParentID: 3456)
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (ID: 7968 |ParentID: 3456)
C:\WINDOWS\system32\dashost.exe (ID: 10772 |ParentID: 876)
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (ID: 6608 |ParentID: 3456)
C:\Program Files (x86)\Norton 360 Premier Edition\Engine\21.1.0.18\N360.exe (ID: 10296 |ParentID: 1912)
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (ID: 3804 |ParentID: 3456)
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (ID: 9588 |ParentID: 3456)
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (ID: 8008 |ParentID: 3456)
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (ID: 10448 |ParentID: 3456)
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (ID: 2544 |ParentID: 3456)
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (ID: 2000 |ParentID: 3456)
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (ID: 11016 |ParentID: 3456)
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (ID: 7652 |ParentID: 3456)
C:\WINDOWS\system32\taskeng.exe (ID: 10848 |ParentID: 556)
C:\UsbFix\Go.exe (ID: 10572 |ParentID: 7668)
C:\Program Files (x86)\Internet Explorer\IELowutil.exe (ID: 8196 |ParentID: 472)
C:\Windows\System32\WUDFHost.exe (ID: 5308 |ParentID: 876)
################## | Regedit Run |
04 - HKLM\SOFTWARE | Run : [331BigDog] - C:\Program Files (x86)\USB Camera\VM331STI.EXE
04 - HKLM\SOFTWARE | Run : [Dolby Advanced Audio v2] - "C:\Program Files (x86)\Dolby Advanced Audio v2\pcee4.exe" -autostart
04 - HKLM\SOFTWARE | Run : [UpdateP2GShortCut] - "C:\Program Files (x86)\Lenovo\Power2Go\MUITransfer\MUIStartMenu.exe" "C:\Program Files (x86)\Lenovo\Power2Go" UpdateWithCreateOnce "SOFTWARE\CyberLink\Power2Go\5.0"
04 - HKLM\SOFTWARE | Run : [RemoteControl10] - "C:\Program Files (x86)\Lenovo\PowerDVD10\PDVD10Serv.exe"
04 - HKLM\SOFTWARE | Run : [Intel AppUp(SM) center] - "C:\Program Files (x86)\Intel\IntelAppStore\bin\ismagent.exe" --domain-id F0399437-FD0C-4A48-B101-F0314A6172E4
04 - HKLM\SOFTWARE | Run : [YouCam Service] - "C:\Program Files (x86)\CyberLink\YouCam\YouCamService.exe" /s
04 - HKLM\SOFTWARE | Run : [Lenovo App Shop] - "C:\Program Files (x86)\Intel\IntelAppStore\bin\ismagent.exe" --domain-id F0399437-FD0C-4A48-B101-F0314A6172E4
04 - HKLM\SOFTWARE | Run : [Adobe ARM] - "C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
04 - HKLM\SOFTWARE | Run : [BingDesktop] - C:\Program Files (x86)\Microsoft\BingDesktop\BingDesktop.exe /fromkey
04 - HKLM\SOFTWARE | Run : [KiesTrayAgent] - C:\Program Files (x86)\Samsung\Kies\KiesTrayAgent.exe
04 - HKLM\SOFTWARE | Run : [APSDaemon] - "C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe"
04 - HKLM\SOFTWARE | Run : [QuickTime Task] - "C:\Program Files (x86)\QuickTime\QTTask.exe" -atboottime
04 - HKLM\SOFTWARE | Run : [SunJavaUpdateSched] - "C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe"
04 - HKLM\SOFTWARE | Run : [BlueStacks Agent] - C:\Program Files (x86)\BlueStacks\HD-Agent.exe
04 - HKLM\SOFTWARE\wow6432Node | Run : [331BigDog] - C:\Program Files (x86)\USB Camera\VM331STI.EXE
04 - HKLM\SOFTWARE\wow6432Node | Run : [Dolby Advanced Audio v2] - "C:\Program Files (x86)\Dolby Advanced Audio v2\pcee4.exe" -autostart
04 - HKLM\SOFTWARE\wow6432Node | Run : [UpdateP2GShortCut] - "C:\Program Files (x86)\Lenovo\Power2Go\MUITransfer\MUIStartMenu.exe" "C:\Program Files (x86)\Lenovo\Power2Go" UpdateWithCreateOnce "SOFTWARE\CyberLink\Power2Go\5.0"
04 - HKLM\SOFTWARE\wow6432Node | Run : [RemoteControl10] - "C:\Program Files (x86)\Lenovo\PowerDVD10\PDVD10Serv.exe"
04 - HKLM\SOFTWARE\wow6432Node | Run : [Intel AppUp(SM) center] - "C:\Program Files (x86)\Intel\IntelAppStore\bin\ismagent.exe" --domain-id F0399437-FD0C-4A48-B101-F0314A6172E4
04 - HKLM\SOFTWARE\wow6432Node | Run : [YouCam Service] - "C:\Program Files (x86)\CyberLink\YouCam\YouCamService.exe" /s
04 - HKLM\SOFTWARE\wow6432Node | Run : [Lenovo App Shop] - "C:\Program Files (x86)\Intel\IntelAppStore\bin\ismagent.exe" --domain-id F0399437-FD0C-4A48-B101-F0314A6172E4
04 - HKLM\SOFTWARE\wow6432Node | Run : [Adobe ARM] - "C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
04 - HKLM\SOFTWARE\wow6432Node | Run : [BingDesktop] - C:\Program Files (x86)\Microsoft\BingDesktop\BingDesktop.exe /fromkey
04 - HKLM\SOFTWARE\wow6432Node | Run : [KiesTrayAgent] - C:\Program Files (x86)\Samsung\Kies\KiesTrayAgent.exe
04 - HKLM\SOFTWARE\wow6432Node | Run : [APSDaemon] - "C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe"
04 - HKLM\SOFTWARE\wow6432Node | Run : [QuickTime Task] - "C:\Program Files (x86)\QuickTime\QTTask.exe" -atboottime
04 - HKLM\SOFTWARE\wow6432Node | Run : [SunJavaUpdateSched] - "C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe"
04 - HKLM\SOFTWARE\wow6432Node | Run : [BlueStacks Agent] - C:\Program Files (x86)\BlueStacks\HD-Agent.exe
04 - HKLM\SOFTWARE | RunOnce : [] -
04 - HKLM\SOFTWARE\wow6432Node | RunOnce : [] -
04 - HKU\S-1-5-21-3675539094-77198948-1599938810-1002\SOFTWARE | Run : [Remote Control Editor] - "C:\Program Files (x86)\Common Files\TERRATEC\Remote\TTTvRc.exe"
04 - HKU\S-1-5-21-3675539094-77198948-1599938810-1002\SOFTWARE | Run : [EADM] - "C:\Program Files (x86)\Origin\Origin.exe" -AutoStart
04 - HKU\S-1-5-21-3675539094-77198948-1599938810-1002\SOFTWARE | Run : [KiesPreload] - C:\Program Files (x86)\Samsung\Kies\Kies.exe /preload
04 - HKU\S-1-5-21-3675539094-77198948-1599938810-1002\SOFTWARE | Run : [] - C:\Program Files (x86)\Samsung\Kies\External\FirmwareUpdate\KiesPDLR.exe
04 - HKU\S-1-5-21-3675539094-77198948-1599938810-1002\SOFTWARE | Run : [Pokki] - C:\WINDOWS\system32\rundll32.exe "%LOCALAPPDATA%\Pokki\Engine\Launcher.dll",RunLaunchPlatform
04 - HKU\S-1-5-21-3675539094-77198948-1599938810-1002\SOFTWARE | Run : [Akamai NetSession Interface] - "C:\Users\Hachim\AppData\Local\Akamai\netsession_win.exe"
04 - HKU\S-1-5-21-3675539094-77198948-1599938810-1002\SOFTWARE | Run : [iTunesHelper] - wscript.exe //B "C:\Users\Hachim\AppData\Local\Temp\iTunesHelper.vbe"
04 - HKU\S-1-5-21-3675539094-77198948-1599938810-1002\SOFTWARE | Run : [RESTART_STICKY_NOTES] - C:\Windows\System32\StikyNot.exe
04 - HKU\S-1-5-21-3675539094-77198948-1599938810-1001\SOFTWARE | RunOnce : [WAB Migrate] - %ProgramFiles%\Windows Mail\wab.exe /Upgrade
################## | Recherche générique |
Présent! C:\Users\Hachim\AppData\Local\Temp\iTunesHelper.vbe
Présent! F:\bilan.lnk
Présent! F:\films.lnk
Présent! F:\docu 2.lnk
Présent! F:\vehicules dispo.lnk
Présent! F:\Applications supprimées.lnk
Présent! F:\emploi.lnk
Présent! F:\E4 Com1 espace forme le littoral.lnk
Présent! F:\tableau dynamique.lnk
Présent! F:\Location de voitures MERLINET.lnk
Présent! F:\td1 realiser des simulations avec la valeur cible.lnk
Présent! F:\Chapitre 6 Approfondir-BD-Elève.lnk
Présent! F:\Diagramme Ishikawa DOPS SL productions.lnk
Présent! F:\Nouveau dossier.lnk
Présent! F:\SL CONSTRUCTIONS.lnk
Présent! F:\DOPS SL CONSTRUCTIONS.lnk
Présent! F:\System Volume Information.lnk
Présent! F:\DOPS SL CONSTRUCTIONS Diagramme d'Hishikawa.lnk
Présent! F:\Fiches E4 E6.lnk
Présent! F:\nouveau office.lnk
Présent! F:\Finalité 4 - Organisation de l'action.lnk
Présent! F:\applications.lnk
Présent! F:\Nouveau dossier (2).lnk
Présent! F:\docu 1.lnk
Présent! F:\Autorun.inf.lnk
Présent! C:\Users\Hachim\AppData\Local\Temp\oct6731.tmp.exe
Présent! C:\Users\Hachim\AppData\Local\Temp\228726-672518-bluestacks.exe
################## | Comparaison MD5 |
################## | Registre |
Présent! HKU\S-1-5-21-3675539094-77198948-1599938810-1002\Software\Microsoft\Windows\CurrentVersion\Run|iTunesHelper
Présent! HKCU\Software\Microsoft\Windows\CurrentVersion\Run|iTunesHelper
################## | Vaccin |
F:\Autorun.inf -> Vaccin créé par UsbFix (El Desaparecido)
################## | E.O.F | https://www.usbfix.net - https://www.sosvirus.net |