- lun. 18 nov. 2013 18:05
#17588
Bonjour,
Mon disque dur externe sur le Drive F: m'est devenu inaccessible car les fichiers ont été transformés en raccourcis.
En revanche les dossiers qui sont dessus existent toujours bien.
Je suis preneur de votre aide.
DC
Ci-dessous le rapport SOSvirus :
############################## | UsbFix V 7.150 | [Research]
User: berber (Administrator) # BERBER1
Updated 08/11/2013 by El Desaparecido - Team SosVirus
Started at 16:52:34 | 18/11/2013
Website : https://www.en.usbfix.net
Forum : https://www.sosvirus.net/
Upload Malware : https://www.sosvirus.net/upload_malware.php
Contact : https://www.en.usbfix.net/contact/
PC: Hewlett-Packard (161D)
CPU: Intel(R) Core(TM) i5-2520M CPU @ 2.50GHz
RAM -> [Total : 4030 | Free : 1061]
Bios: Hewlett-Packard
Boot: Normal boot
OS: Microsoft Windows 7 Enterprise (6.1.7601 64-Bit) Service Pack 1
WB: Windows Internet Explorer : 10.0.9200.16721
WB: Google Chrome : 31.0.1650.57
SC: Security Center Service [(!) Disabled]
WU: Windows Update Service [(!) Disabled]
AV: McAfee VirusScan Enterprise [Enabled | Updated]
AS: Windows Defender : 6.1.7600.16385 (win7_rtm.090713-1255)
FW: Windows FireWall Service [(!) Disabled]
C:\ (%systemdrive%) -> Fixed drive # 466 Gb (370 Mb free - 80%) [PC COE] # NTFS
D:\ -> CD-ROM
F:\ -> Fixed drive # 465 Gb (394 Mb free - 85%) [Local Disk] # NTFS
################## | Active Processes |
C:\Windows\system32\csrss.exe (ID: 504 |ParentID: 436)
C:\Windows\system32\wininit.exe (ID: 556 |ParentID: 436)
C:\Windows\system32\csrss.exe (ID: 580 |ParentID: 564)
C:\Windows\system32\services.exe (ID: 620 |ParentID: 556)
C:\Windows\system32\lsass.exe (ID: 636 |ParentID: 556)
C:\Windows\system32\lsm.exe (ID: 644 |ParentID: 556)
C:\Windows\system32\winlogon.exe (ID: 708 |ParentID: 564)
C:\Windows\system32\svchost.exe (ID: 792 |ParentID: 620)
C:\Windows\system32\svchost.exe (ID: 880 |ParentID: 620)
C:\Windows\System32\svchost.exe (ID: 944 |ParentID: 620)
C:\Windows\System32\svchost.exe (ID: 1012 |ParentID: 620)
C:\Windows\system32\svchost.exe (ID: 396 |ParentID: 620)
C:\Windows\system32\svchost.exe (ID: 516 |ParentID: 620)
C:\Program Files\IDT\WDM\STacSV64.exe (ID: 612 |ParentID: 620)
C:\Windows\system32\Hpservice.exe (ID: 1328 |ParentID: 620)
C:\Windows\system32\WUDFHost.exe (ID: 1432 |ParentID: 1012)
C:\Windows\system32\vcsFPService.exe (ID: 1472 |ParentID: 620)
C:\Windows\system32\svchost.exe (ID: 1520 |ParentID: 620)
C:\Windows\System32\spoolsv.exe (ID: 1648 |ParentID: 620)
C:\Program Files\Common Files\ActivIdentity\ac.sharedstore.exe (ID: 1696 |ParentID: 620)
C:\Windows\system32\svchost.exe (ID: 1736 |ParentID: 620)
C:\Program Files\ActivIdentity\ActivClient\acevents.exe (ID: 1800 |ParentID: 1696)
C:\Windows\system32\svchost.exe (ID: 1820 |ParentID: 620)
C:\Program Files (x86)\McAfee\Endpoint Encryption for PC\SbClientManager.exe (ID: 1912 |ParentID: 620)
C:\Program Files (x86)\Common Files\ArcSoft\Connection Service\Bin\ACService.exe (ID: 1948 |ParentID: 620)
C:\Program Files\IDT\WDM\AESTSr64.exe (ID: 1972 |ParentID: 620)
C:\Program Files\LSI SoftModem\agr64svc.exe (ID: 2000 |ParentID: 620)
C:\Program Files\WIDCOMM\Bluetooth Software\btwdins.exe (ID: 2020 |ParentID: 620)
C:\Program Files (x86)\McAfee\Host Intrusion Prevention\FireSvc.exe (ID: 1212 |ParentID: 620)
C:\Program Files\Microsoft Forefront Identity Manager\2010\Password Reset Client Service\PwdMgmtProxy.exe (ID: 1376 |ParentID: 620)
C:\Program Files (x86)\McAfee\Host Intrusion Prevention\HIPSCore\x64\HIPSvc.exe (ID: 2052 |ParentID: 620)
C:\Program Files (x86)\Hewlett-Packard\Shared\HPDrvMntSvc.exe (ID: 2084 |ParentID: 620)
C:\Program Files (x86)\Hewlett-Packard\HP Hotkey Support\HpHotkeyMonitor.exe (ID: 2116 |ParentID: 620)
C:\ProgramData\IBUpdaterService\ibsvc.exe (ID: 2148 |ParentID: 620)
c:\Program Files (x86)\Common Files\LightScribe\LSSrvc.exe (ID: 2296 |ParentID: 620)
C:\Program Files (x86)\McAfee\SiteAdvisor Enterprise\McSACore.exe (ID: 2332 |ParentID: 620)
C:\Program Files (x86)\McAfee\VirusScan Enterprise\x64\EngineServer.exe (ID: 2456 |ParentID: 620)
C:\Program Files (x86)\McAfee\Common Framework\FrameworkService.exe (ID: 2500 |ParentID: 620)
C:\Program Files (x86)\McAfee\VirusScan Enterprise\VsTskMgr.exe (ID: 2040 |ParentID: 620)
C:\Windows\system32\mfevtps.exe (ID: 2420 |ParentID: 620)
C:\Windows\System32\svchost.exe (ID: 2560 |ParentID: 620)
C:\Program Files (x86)\Common Files\Portrait Displays\Drivers\pdisrvc.exe (ID: 2792 |ParentID: 620)
C:\Windows\System32\svchost.exe (ID: 2788 |ParentID: 620)
C:\Windows\system32\svchost.exe (ID: 2912 |ParentID: 620)
C:\Program Files (x86)\Hewlett-Packard\PC COE 3\OV CMS\radexecd.exe (ID: 2572 |ParentID: 620)
C:\Program Files (x86)\Hewlett-Packard\PC COE 3\OV CMS\radsched.exe (ID: 2980 |ParentID: 620)
C:\Program Files (x86)\Hewlett-Packard\PC COE 3\OV CMS\Radstgms.exe (ID: 2672 |ParentID: 620)
C:\PROGRA~2\HEWLET~1\PCCOE3~1\OVCMS~1\radalert.exe (ID: 3000 |ParentID: 2572)
C:\Windows\system32\svchost.exe (ID: 2264 |ParentID: 620)
C:\Program Files (x86)\Products\Time Service\svctimehpc.exe (ID: 2644 |ParentID: 620)
C:\Program Files (x86)\ArcSoft\HP Webcam Software Suite\Magic-i Visual Effects 2\uCamMonitor.exe (ID: 3104 |ParentID: 620)
C:\Program Files (x86)\Yahoo!\SoftwareUpdate\YahooAUService.exe (ID: 3252 |ParentID: 620)
C:\Program Files (x86)\McAfee\Common Framework\naPrdMgr.exe (ID: 3304 |ParentID: 792)
C:\Program Files (x86)\Yontoo\Y2Desktop.Updater.exe (ID: 3392 |ParentID: 620)
C:\Program Files (x86)\McAfee\VirusScan Enterprise\x64\McShield.exe (ID: 3488 |ParentID: 620)
C:\Program Files (x86)\McAfee\VirusScan Enterprise\x64\mfeann.exe (ID: 3540 |ParentID: 3488)
C:\Windows\system32\conhost.exe (ID: 3548 |ParentID: 504)
C:\Windows\system32\wbem\unsecapp.exe (ID: 3912 |ParentID: 792)
C:\Windows\system32\wbem\unsecapp.exe (ID: 3944 |ParentID: 792)
C:\Windows\system32\wbem\wmiprvse.exe (ID: 4028 |ParentID: 792)
C:\Program Files (x86)\Hewlett-Packard\Shared\hpqWmiEx.exe (ID: 4304 |ParentID: 620)
C:\Windows\system32\svchost.exe (ID: 4528 |ParentID: 620)
C:\Windows\system32\Dwm.exe (ID: 4876 |ParentID: 1012)
C:\Windows\Explorer.EXE (ID: 4896 |ParentID: 2740)
C:\Program Files\ActivIdentity\ActivClient\acevents.exe (ID: 4660 |ParentID: 4896)
C:\Program Files\ActivIdentity\ActivClient\accrdsub.exe (ID: 4604 |ParentID: 4896)
C:\Program Files\RA2HP\HPRAService.exe (ID: 1064 |ParentID: 4896)
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe (ID: 972 |ParentID: 4896)
C:\Windows\System32\igfxtray.exe (ID: 5020 |ParentID: 4896)
C:\Windows\System32\hkcmd.exe (ID: 4916 |ParentID: 4896)
C:\Windows\System32\igfxpers.exe (ID: 680 |ParentID: 4896)
C:\Program Files\IDT\WDM\sttray64.exe (ID: 164 |ParentID: 4896)
C:\Program Files\Synaptics\SynTP\SynTPHelper.exe (ID: 1156 |ParentID: 972)
C:\Program Files (x86)\Common Files\LightScribe\LightScribeControlPanel.exe (ID: 5248 |ParentID: 4896)
C:\Windows\system32\SearchIndexer.exe (ID: 5272 |ParentID: 620)
C:\Windows\system32\DllHost.exe (ID: 5672 |ParentID: 792)
C:\Users\berber\AppData\Roaming\Yontoo\YontooDesktop.exe (ID: 5812 |ParentID: 3392)
C:\Program Files\ActivIdentity\ActivClient\acsagent.exe (ID: 5820 |ParentID: 4896)
C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe (ID: 5900 |ParentID: 4896)
C:\Program Files (x86)\HP Button Manager\BM.exe (ID: 5944 |ParentID: 4896)
C:\ProgramData\U3\U3Launcher\LaunchU3.exe (ID: 5980 |ParentID: 4896)
C:\Program Files (x86)\Microsoft Office\Office12\ONENOTEM.EXE (ID: 6064 |ParentID: 4896)
C:\Program Files (x86)\Hewlett-Packard\PC COE\COEMsgDisplay.exe (ID: 6080 |ParentID: 5652)
C:\Windows\SysWOW64\WerFault.exe (ID: 6096 |ParentID: 5664)
C:\Program Files (x86)\McAfee\Host Intrusion Prevention\FireTray.exe (ID: 5164 |ParentID: 5652)
C:\Program Files (x86)\Hewlett-Packard\PC COE\ida.exe (ID: 5512 |ParentID: 5652)
C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe (ID: 5544 |ParentID: 5652)
C:\Program Files (x86)\Hewlett-Packard\HP HotKey Support\QLBController.exe (ID: 3420 |ParentID: 5652)
C:\Program Files (x86)\SafeBoot Tray Manager\SbTrayManager.exe (ID: 5124 |ParentID: 5652)
C:\Program Files (x86)\McAfee\Endpoint Encryption for PC\SbTokWatch.exe (ID: 5160 |ParentID: 5652)
C:\Program Files (x86)\Hewlett-Packard\GetITIcon\GetITShell.exe (ID: 5960 |ParentID: 5652)
C:\Program Files (x86)\Google\Google Desktop Search\GoogleDesktop.exe (ID: 820 |ParentID: 5652)
C:\Program Files (x86)\Common Files\ArcSoft\Connection Service\Bin\ACDaemon.exe (ID: 5404 |ParentID: 5652)
C:\Program Files (x86)\McAfee\Common Framework\UdaterUI.exe (ID: 4448 |ParentID: 5652)
C:\Program Files (x86)\Microsoft Office\Office12\OUTLOOK.EXE (ID: 5364 |ParentID: 4896)
C:\Program Files (x86)\Adobe\Acrobat 9.0\Acrobat\acrotray.exe (ID: 3616 |ParentID: 5652)
C:\Program Files (x86)\Common Files\ArcSoft\Connection Service\Bin\ArcCon.ac (ID: 5652 |ParentID: 5404)
C:\Windows\system32\wbem\wmiprvse.exe (ID: 6176 |ParentID: 792)
C:\Program Files (x86)\McAfee\Common Framework\McTray.exe (ID: 6608 |ParentID: 4448)
C:\Windows\SysWOW64\RunDll32.exe (ID: 6664 |ParentID: 5900)
C:\Program Files\WIDCOMM\Bluetooth Software\BtStackServer.exe (ID: 6828 |ParentID: 792)
C:\Program Files\WIDCOMM\Bluetooth Software\BluetoothHeadsetProxy.exe (ID: 7004 |ParentID: 6828)
C:\Program Files\Hewlett-Packard\HP Power Assistant\HPPA_Service.exe (ID: 6912 |ParentID: 620)
C:\Program Files\Hewlett-Packard\HP Wireless Assistant\HPWA_Service.exe (ID: 3928 |ParentID: 620)
C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe (ID: 7184 |ParentID: 620)
C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe (ID: 7352 |ParentID: 620)
C:\Windows\system32\sppsvc.exe (ID: 7504 |ParentID: 620)
C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe (ID: 7692 |ParentID: 620)
C:\Program Files\Hewlett-Packard\HP Wireless Assistant\HPWA_Main.exe (ID: 7012 |ParentID: 5220)
C:\Program Files\Hewlett-Packard\HP Power Assistant\HPPA_Main.exe (ID: 8100 |ParentID: 1964)
C:\Program Files (x86)\Common Files\Portrait Displays\Drivers\SDKCOMServer.exe (ID: 1344 |ParentID: 792)
C:\Program Files (x86)\Hewlett-Packard\Shared\hpCaslNotification.exe (ID: 1964 |ParentID: 7012)
C:\Program Files (x86)\Common Files\Portrait Displays\Drivers\pdiSdkHelperx64.exe (ID: 7044 |ParentID: 1344)
C:\Windows\Microsoft.Net\Framework64\v3.0\WPF\PresentationFontCache.exe (ID: 4788 |ParentID: 620)
C:\Windows\system32\igfxext.exe (ID: 5224 |ParentID: 792)
C:\Windows\system32\igfxsrvc.exe (ID: 6856 |ParentID: 792)
C:\Program Files (x86)\Adobe\Acrobat 9.0\Acrobat\Acrobat.exe (ID: 7280 |ParentID: 5364)
C:\Program Files (x86)\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe (ID: 6908 |ParentID: 620)
C:\Program Files\Internet Explorer\IEXPLORE.EXE (ID: 9008 |ParentID: 8360)
C:\Program Files (x86)\Internet Explorer\IEXPLORE.EXE (ID: 7344 |ParentID: 9008)
C:\Program Files (x86)\TeamViewer\Version8\TeamViewer_Service.exe (ID: 8484 |ParentID: 620)
C:\Program Files (x86)\TeamViewer\Version8\TeamViewer.exe (ID: 9000 |ParentID: 8484)
C:\Program Files (x86)\TeamViewer\Version8\tv_w32.exe (ID: 6784 |ParentID: 8484)
C:\Program Files (x86)\TeamViewer\Version8\tv_x64.exe (ID: 8520 |ParentID: 8484)
C:\Program Files (x86)\Microsoft Office\Office12\WINWORD.EXE (ID: 8876 |ParentID: 4896)
C:\Windows\splwow64.exe (ID: 7036 |ParentID: 8876)
C:\Windows\system32\cmd.exe (ID: 8384 |ParentID: 4896)
C:\Windows\system32\conhost.exe (ID: 5472 |ParentID: 580)
C:\Program Files (x86)\Internet Explorer\IEXPLORE.EXE (ID: 10100 |ParentID: 9008)
C:\Program Files (x86)\McAfee\VirusScan Enterprise\x64\SCAN64.EXE (ID: 7616 |ParentID: 3304)
C:\UsbFix\Go.exe (ID: 10712 |ParentID: 10556)
################## | Regedit Run |
04 - HKLM\SOFTWARE | Run : [COEMsgDisplay] - c:\Program Files (x86)\Hewlett-Packard\PC COE\COEMsgDisplay.exe
04 - HKLM\SOFTWARE | Run : [ShStatEXE] - "C:\Program Files (x86)\McAfee\VirusScan Enterprise\SHSTAT.EXE" /STANDALONE
04 - HKLM\SOFTWARE | Run : [McAfee Host Intrusion Prevention Tray] - "C:\Program Files (x86)\McAfee\Host Intrusion Prevention\FireTray.exe"
04 - HKLM\SOFTWARE | Run : [Adobe Reader Speed Launcher] - "C:\Program Files (x86)\Adobe\Reader 9.0\Reader\Reader_sl.exe"
04 - HKLM\SOFTWARE | Run : [Adobe ARM] - "C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
04 - HKLM\SOFTWARE | Run : [IDA] - C:\Program Files (x86)\Hewlett-Packard\PC COE\IDA.EXE
04 - HKLM\SOFTWARE | Run : [IAStorIcon] - C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe
04 - HKLM\SOFTWARE | Run : [QLBController] - C:\Program Files (x86)\Hewlett-Packard\HP HotKey Support\QLBController.exe /start
04 - HKLM\SOFTWARE | Run : [eepc_SmartClient] - C:\Program Files (x86)\SmartClient\Smart.exe
04 - HKLM\SOFTWARE | Run : [SafeBootTrayManager] - "C:\Program Files (x86)\SafeBoot Tray Manager\SbTrayManager.exe"
04 - HKLM\SOFTWARE | Run : [SafeBootTokenWatcher] - "C:\Program Files (x86)\McAfee\Endpoint Encryption for PC\SbTokWatch.exe"
04 - HKLM\SOFTWARE | Run : [GetITIcon] - C:\Program Files (x86)\Hewlett-Packard\GetITIcon\GetITShell.exe
04 - HKLM\SOFTWARE | Run : [Communicator] - "C:\Program Files (x86)\Microsoft Lync\communicator.exe" /fromrunkey
04 - HKLM\SOFTWARE | Run : [Google Desktop Search] - "C:\Program Files (x86)\Google\Google Desktop Search\GoogleDesktop.exe" /startup
04 - HKLM\SOFTWARE | Run : [ArcSoft Connection Service] - C:\Program Files (x86)\Common Files\ArcSoft\Connection Service\Bin\ACDaemon.exe
04 - HKLM\SOFTWARE | Run : [McAfeeUpdaterUI] - "C:\Program Files (x86)\McAfee\Common Framework\udaterui.exe" /StartedFromRunKey
04 - HKLM\SOFTWARE | Run : [Adobe Acrobat Speed Launcher] - "C:\Program Files (x86)\Adobe\Acrobat 9.0\Acrobat\Acrobat_sl.exe"
04 - HKLM\SOFTWARE | Run : [] -
04 - HKLM\SOFTWARE | Run : [Acrobat Assistant 8.0] - "C:\Program Files (x86)\Adobe\Acrobat 9.0\Acrobat\Acrotray.exe"
04 - HKLM\SOFTWARE\wow6432Node | Run : [COEMsgDisplay] - c:\Program Files (x86)\Hewlett-Packard\PC COE\COEMsgDisplay.exe
04 - HKLM\SOFTWARE\wow6432Node | Run : [ShStatEXE] - "C:\Program Files (x86)\McAfee\VirusScan Enterprise\SHSTAT.EXE" /STANDALONE
04 - HKLM\SOFTWARE\wow6432Node | Run : [McAfee Host Intrusion Prevention Tray] - "C:\Program Files (x86)\McAfee\Host Intrusion Prevention\FireTray.exe"
04 - HKLM\SOFTWARE\wow6432Node | Run : [Adobe Reader Speed Launcher] - "C:\Program Files (x86)\Adobe\Reader 9.0\Reader\Reader_sl.exe"
04 - HKLM\SOFTWARE\wow6432Node | Run : [Adobe ARM] - "C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
04 - HKLM\SOFTWARE\wow6432Node | Run : [IDA] - C:\Program Files (x86)\Hewlett-Packard\PC COE\IDA.EXE
04 - HKLM\SOFTWARE\wow6432Node | Run : [IAStorIcon] - C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe
04 - HKLM\SOFTWARE\wow6432Node | Run : [QLBController] - C:\Program Files (x86)\Hewlett-Packard\HP HotKey Support\QLBController.exe /start
04 - HKLM\SOFTWARE\wow6432Node | Run : [eepc_SmartClient] - C:\Program Files (x86)\SmartClient\Smart.exe
04 - HKLM\SOFTWARE\wow6432Node | Run : [SafeBootTrayManager] - "C:\Program Files (x86)\SafeBoot Tray Manager\SbTrayManager.exe"
04 - HKLM\SOFTWARE\wow6432Node | Run : [SafeBootTokenWatcher] - "C:\Program Files (x86)\McAfee\Endpoint Encryption for PC\SbTokWatch.exe"
04 - HKLM\SOFTWARE\wow6432Node | Run : [GetITIcon] - C:\Program Files (x86)\Hewlett-Packard\GetITIcon\GetITShell.exe
04 - HKLM\SOFTWARE\wow6432Node | Run : [Communicator] - "C:\Program Files (x86)\Microsoft Lync\communicator.exe" /fromrunkey
04 - HKLM\SOFTWARE\wow6432Node | Run : [Google Desktop Search] - "C:\Program Files (x86)\Google\Google Desktop Search\GoogleDesktop.exe" /startup
04 - HKLM\SOFTWARE\wow6432Node | Run : [ArcSoft Connection Service] - C:\Program Files (x86)\Common Files\ArcSoft\Connection Service\Bin\ACDaemon.exe
04 - HKLM\SOFTWARE\wow6432Node | Run : [McAfeeUpdaterUI] - "C:\Program Files (x86)\McAfee\Common Framework\udaterui.exe" /StartedFromRunKey
04 - HKLM\SOFTWARE\wow6432Node | Run : [Adobe Acrobat Speed Launcher] - "C:\Program Files (x86)\Adobe\Acrobat 9.0\Acrobat\Acrobat_sl.exe"
04 - HKLM\SOFTWARE\wow6432Node | Run : [] -
04 - HKLM\SOFTWARE\wow6432Node | Run : [Acrobat Assistant 8.0] - "C:\Program Files (x86)\Adobe\Acrobat 9.0\Acrobat\Acrotray.exe"
04 - HKLM\SOFTWARE | RunOnce : [] -
04 - HKLM\SOFTWARE\wow6432Node | RunOnce : [] -
04 - HKU\S-1-5-19\SOFTWARE | Run : [Sidebar] - %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun
04 - HKU\S-1-5-20\SOFTWARE | Run : [Sidebar] - %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun
04 - HKU\S-1-5-21-1957994488-842925246-40105171-559050\SOFTWARE | Run : [LightScribe Control Panel] - C:\Program Files (x86)\Common Files\LightScribe\LightScribeControlPanel.exe -hidden
04 - HKU\S-1-5-21-1957994488-842925246-40105171-559050\SOFTWARE | Run : [Yontoo Desktop] - "C:\Users\berber\AppData\Roaming\Yontoo\YontooDesktop.exe"
04 - HKU\S-1-5-21-1957994488-842925246-40105171-559050\SOFTWARE | Run : [Uftiux] - C:\Users\berber\AppData\Roaming\Fiqya\querq.exe
04 - HKU\S-1-5-21-1957994488-842925246-40105171-559050\SOFTWARE | Run : [Screen Saver Pro 3.1] - C:\Users\berber\AppData\Roaming\ScreenSaverPro.scr
04 - HKU\S-1-5-21-1957994488-842925246-40105171-559050\SOFTWARE | Run : [hbweaaa] - C:\RECYCLER\S-1-5-21-0243556031-888888379-781863308-5135689\hbweaaa.exe
04 - HKU\S-1-5-21-1957994488-842925246-40105171-559050\SOFTWARE | Run : [ActiveUpdate] - \Windows\Explorer.exe
04 - HKU\S-1-5-21-1957994488-842925246-40105171-559050\SOFTWARE | Run : [Xfogod] - C:\Users\berber\AppData\Roaming\Microsoft\Xfogod.exe
04 - HKU\S-1-5-19\SOFTWARE | RunOnce : [mctadmin] - C:\Windows\System32\mctadmin.exe
04 - HKU\S-1-5-20\SOFTWARE | RunOnce : [mctadmin] - C:\Windows\System32\mctadmin.exe
################## | Generic Research |
Found ! F:\$RECYCLE.BIN.lnk
Found ! F:\92b598d5c25eaab268d0b4.lnk
Found ! F:\System Volume Information.lnk
Found ! F:\TBE.lnk
Found ! C:\Users\berber\AppData\Roaming\temp.bin
Found ! C:\Recycler\S-1-5-21-0243556031-888888379-781863308-5135689
################## | Reference of comparison MD5 |
Md5 : 8FC4380C035CCB452FFFD4802A13EB2B -> C:\Users\berber\AppData\Roaming\temp.bin
################## | Comparison MD5 |
################## | Registry |
Found ! HKLM\Software\Microsoft\Windows\CurrentVersion\Policies\System|EnableLUA -> 0
Found ! HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced|Start_ShowMyGames -> 0
Found ! HKU\S-1-5-21-1957994488-842925246-40105171-559050\Software\Microsoft\Windows\CurrentVersion\Run|Screen Saver Pro 3.1
Found ! HKCU\Software\Microsoft\Windows\CurrentVersion\Run|Screen Saver Pro 3.1
################## | Vaccin |
(!) This computer is not vaccinated!
################## | E.O.F | https://www.usbfix.net - https://www.sosvirus.net |
Mon disque dur externe sur le Drive F: m'est devenu inaccessible car les fichiers ont été transformés en raccourcis.
En revanche les dossiers qui sont dessus existent toujours bien.
Je suis preneur de votre aide.
DC
Ci-dessous le rapport SOSvirus :
############################## | UsbFix V 7.150 | [Research]
User: berber (Administrator) # BERBER1
Updated 08/11/2013 by El Desaparecido - Team SosVirus
Started at 16:52:34 | 18/11/2013
Website : https://www.en.usbfix.net
Forum : https://www.sosvirus.net/
Upload Malware : https://www.sosvirus.net/upload_malware.php
Contact : https://www.en.usbfix.net/contact/
PC: Hewlett-Packard (161D)
CPU: Intel(R) Core(TM) i5-2520M CPU @ 2.50GHz
RAM -> [Total : 4030 | Free : 1061]
Bios: Hewlett-Packard
Boot: Normal boot
OS: Microsoft Windows 7 Enterprise (6.1.7601 64-Bit) Service Pack 1
WB: Windows Internet Explorer : 10.0.9200.16721
WB: Google Chrome : 31.0.1650.57
SC: Security Center Service [(!) Disabled]
WU: Windows Update Service [(!) Disabled]
AV: McAfee VirusScan Enterprise [Enabled | Updated]
AS: Windows Defender : 6.1.7600.16385 (win7_rtm.090713-1255)
FW: Windows FireWall Service [(!) Disabled]
C:\ (%systemdrive%) -> Fixed drive # 466 Gb (370 Mb free - 80%) [PC COE] # NTFS
D:\ -> CD-ROM
F:\ -> Fixed drive # 465 Gb (394 Mb free - 85%) [Local Disk] # NTFS
################## | Active Processes |
C:\Windows\system32\csrss.exe (ID: 504 |ParentID: 436)
C:\Windows\system32\wininit.exe (ID: 556 |ParentID: 436)
C:\Windows\system32\csrss.exe (ID: 580 |ParentID: 564)
C:\Windows\system32\services.exe (ID: 620 |ParentID: 556)
C:\Windows\system32\lsass.exe (ID: 636 |ParentID: 556)
C:\Windows\system32\lsm.exe (ID: 644 |ParentID: 556)
C:\Windows\system32\winlogon.exe (ID: 708 |ParentID: 564)
C:\Windows\system32\svchost.exe (ID: 792 |ParentID: 620)
C:\Windows\system32\svchost.exe (ID: 880 |ParentID: 620)
C:\Windows\System32\svchost.exe (ID: 944 |ParentID: 620)
C:\Windows\System32\svchost.exe (ID: 1012 |ParentID: 620)
C:\Windows\system32\svchost.exe (ID: 396 |ParentID: 620)
C:\Windows\system32\svchost.exe (ID: 516 |ParentID: 620)
C:\Program Files\IDT\WDM\STacSV64.exe (ID: 612 |ParentID: 620)
C:\Windows\system32\Hpservice.exe (ID: 1328 |ParentID: 620)
C:\Windows\system32\WUDFHost.exe (ID: 1432 |ParentID: 1012)
C:\Windows\system32\vcsFPService.exe (ID: 1472 |ParentID: 620)
C:\Windows\system32\svchost.exe (ID: 1520 |ParentID: 620)
C:\Windows\System32\spoolsv.exe (ID: 1648 |ParentID: 620)
C:\Program Files\Common Files\ActivIdentity\ac.sharedstore.exe (ID: 1696 |ParentID: 620)
C:\Windows\system32\svchost.exe (ID: 1736 |ParentID: 620)
C:\Program Files\ActivIdentity\ActivClient\acevents.exe (ID: 1800 |ParentID: 1696)
C:\Windows\system32\svchost.exe (ID: 1820 |ParentID: 620)
C:\Program Files (x86)\McAfee\Endpoint Encryption for PC\SbClientManager.exe (ID: 1912 |ParentID: 620)
C:\Program Files (x86)\Common Files\ArcSoft\Connection Service\Bin\ACService.exe (ID: 1948 |ParentID: 620)
C:\Program Files\IDT\WDM\AESTSr64.exe (ID: 1972 |ParentID: 620)
C:\Program Files\LSI SoftModem\agr64svc.exe (ID: 2000 |ParentID: 620)
C:\Program Files\WIDCOMM\Bluetooth Software\btwdins.exe (ID: 2020 |ParentID: 620)
C:\Program Files (x86)\McAfee\Host Intrusion Prevention\FireSvc.exe (ID: 1212 |ParentID: 620)
C:\Program Files\Microsoft Forefront Identity Manager\2010\Password Reset Client Service\PwdMgmtProxy.exe (ID: 1376 |ParentID: 620)
C:\Program Files (x86)\McAfee\Host Intrusion Prevention\HIPSCore\x64\HIPSvc.exe (ID: 2052 |ParentID: 620)
C:\Program Files (x86)\Hewlett-Packard\Shared\HPDrvMntSvc.exe (ID: 2084 |ParentID: 620)
C:\Program Files (x86)\Hewlett-Packard\HP Hotkey Support\HpHotkeyMonitor.exe (ID: 2116 |ParentID: 620)
C:\ProgramData\IBUpdaterService\ibsvc.exe (ID: 2148 |ParentID: 620)
c:\Program Files (x86)\Common Files\LightScribe\LSSrvc.exe (ID: 2296 |ParentID: 620)
C:\Program Files (x86)\McAfee\SiteAdvisor Enterprise\McSACore.exe (ID: 2332 |ParentID: 620)
C:\Program Files (x86)\McAfee\VirusScan Enterprise\x64\EngineServer.exe (ID: 2456 |ParentID: 620)
C:\Program Files (x86)\McAfee\Common Framework\FrameworkService.exe (ID: 2500 |ParentID: 620)
C:\Program Files (x86)\McAfee\VirusScan Enterprise\VsTskMgr.exe (ID: 2040 |ParentID: 620)
C:\Windows\system32\mfevtps.exe (ID: 2420 |ParentID: 620)
C:\Windows\System32\svchost.exe (ID: 2560 |ParentID: 620)
C:\Program Files (x86)\Common Files\Portrait Displays\Drivers\pdisrvc.exe (ID: 2792 |ParentID: 620)
C:\Windows\System32\svchost.exe (ID: 2788 |ParentID: 620)
C:\Windows\system32\svchost.exe (ID: 2912 |ParentID: 620)
C:\Program Files (x86)\Hewlett-Packard\PC COE 3\OV CMS\radexecd.exe (ID: 2572 |ParentID: 620)
C:\Program Files (x86)\Hewlett-Packard\PC COE 3\OV CMS\radsched.exe (ID: 2980 |ParentID: 620)
C:\Program Files (x86)\Hewlett-Packard\PC COE 3\OV CMS\Radstgms.exe (ID: 2672 |ParentID: 620)
C:\PROGRA~2\HEWLET~1\PCCOE3~1\OVCMS~1\radalert.exe (ID: 3000 |ParentID: 2572)
C:\Windows\system32\svchost.exe (ID: 2264 |ParentID: 620)
C:\Program Files (x86)\Products\Time Service\svctimehpc.exe (ID: 2644 |ParentID: 620)
C:\Program Files (x86)\ArcSoft\HP Webcam Software Suite\Magic-i Visual Effects 2\uCamMonitor.exe (ID: 3104 |ParentID: 620)
C:\Program Files (x86)\Yahoo!\SoftwareUpdate\YahooAUService.exe (ID: 3252 |ParentID: 620)
C:\Program Files (x86)\McAfee\Common Framework\naPrdMgr.exe (ID: 3304 |ParentID: 792)
C:\Program Files (x86)\Yontoo\Y2Desktop.Updater.exe (ID: 3392 |ParentID: 620)
C:\Program Files (x86)\McAfee\VirusScan Enterprise\x64\McShield.exe (ID: 3488 |ParentID: 620)
C:\Program Files (x86)\McAfee\VirusScan Enterprise\x64\mfeann.exe (ID: 3540 |ParentID: 3488)
C:\Windows\system32\conhost.exe (ID: 3548 |ParentID: 504)
C:\Windows\system32\wbem\unsecapp.exe (ID: 3912 |ParentID: 792)
C:\Windows\system32\wbem\unsecapp.exe (ID: 3944 |ParentID: 792)
C:\Windows\system32\wbem\wmiprvse.exe (ID: 4028 |ParentID: 792)
C:\Program Files (x86)\Hewlett-Packard\Shared\hpqWmiEx.exe (ID: 4304 |ParentID: 620)
C:\Windows\system32\svchost.exe (ID: 4528 |ParentID: 620)
C:\Windows\system32\Dwm.exe (ID: 4876 |ParentID: 1012)
C:\Windows\Explorer.EXE (ID: 4896 |ParentID: 2740)
C:\Program Files\ActivIdentity\ActivClient\acevents.exe (ID: 4660 |ParentID: 4896)
C:\Program Files\ActivIdentity\ActivClient\accrdsub.exe (ID: 4604 |ParentID: 4896)
C:\Program Files\RA2HP\HPRAService.exe (ID: 1064 |ParentID: 4896)
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe (ID: 972 |ParentID: 4896)
C:\Windows\System32\igfxtray.exe (ID: 5020 |ParentID: 4896)
C:\Windows\System32\hkcmd.exe (ID: 4916 |ParentID: 4896)
C:\Windows\System32\igfxpers.exe (ID: 680 |ParentID: 4896)
C:\Program Files\IDT\WDM\sttray64.exe (ID: 164 |ParentID: 4896)
C:\Program Files\Synaptics\SynTP\SynTPHelper.exe (ID: 1156 |ParentID: 972)
C:\Program Files (x86)\Common Files\LightScribe\LightScribeControlPanel.exe (ID: 5248 |ParentID: 4896)
C:\Windows\system32\SearchIndexer.exe (ID: 5272 |ParentID: 620)
C:\Windows\system32\DllHost.exe (ID: 5672 |ParentID: 792)
C:\Users\berber\AppData\Roaming\Yontoo\YontooDesktop.exe (ID: 5812 |ParentID: 3392)
C:\Program Files\ActivIdentity\ActivClient\acsagent.exe (ID: 5820 |ParentID: 4896)
C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe (ID: 5900 |ParentID: 4896)
C:\Program Files (x86)\HP Button Manager\BM.exe (ID: 5944 |ParentID: 4896)
C:\ProgramData\U3\U3Launcher\LaunchU3.exe (ID: 5980 |ParentID: 4896)
C:\Program Files (x86)\Microsoft Office\Office12\ONENOTEM.EXE (ID: 6064 |ParentID: 4896)
C:\Program Files (x86)\Hewlett-Packard\PC COE\COEMsgDisplay.exe (ID: 6080 |ParentID: 5652)
C:\Windows\SysWOW64\WerFault.exe (ID: 6096 |ParentID: 5664)
C:\Program Files (x86)\McAfee\Host Intrusion Prevention\FireTray.exe (ID: 5164 |ParentID: 5652)
C:\Program Files (x86)\Hewlett-Packard\PC COE\ida.exe (ID: 5512 |ParentID: 5652)
C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe (ID: 5544 |ParentID: 5652)
C:\Program Files (x86)\Hewlett-Packard\HP HotKey Support\QLBController.exe (ID: 3420 |ParentID: 5652)
C:\Program Files (x86)\SafeBoot Tray Manager\SbTrayManager.exe (ID: 5124 |ParentID: 5652)
C:\Program Files (x86)\McAfee\Endpoint Encryption for PC\SbTokWatch.exe (ID: 5160 |ParentID: 5652)
C:\Program Files (x86)\Hewlett-Packard\GetITIcon\GetITShell.exe (ID: 5960 |ParentID: 5652)
C:\Program Files (x86)\Google\Google Desktop Search\GoogleDesktop.exe (ID: 820 |ParentID: 5652)
C:\Program Files (x86)\Common Files\ArcSoft\Connection Service\Bin\ACDaemon.exe (ID: 5404 |ParentID: 5652)
C:\Program Files (x86)\McAfee\Common Framework\UdaterUI.exe (ID: 4448 |ParentID: 5652)
C:\Program Files (x86)\Microsoft Office\Office12\OUTLOOK.EXE (ID: 5364 |ParentID: 4896)
C:\Program Files (x86)\Adobe\Acrobat 9.0\Acrobat\acrotray.exe (ID: 3616 |ParentID: 5652)
C:\Program Files (x86)\Common Files\ArcSoft\Connection Service\Bin\ArcCon.ac (ID: 5652 |ParentID: 5404)
C:\Windows\system32\wbem\wmiprvse.exe (ID: 6176 |ParentID: 792)
C:\Program Files (x86)\McAfee\Common Framework\McTray.exe (ID: 6608 |ParentID: 4448)
C:\Windows\SysWOW64\RunDll32.exe (ID: 6664 |ParentID: 5900)
C:\Program Files\WIDCOMM\Bluetooth Software\BtStackServer.exe (ID: 6828 |ParentID: 792)
C:\Program Files\WIDCOMM\Bluetooth Software\BluetoothHeadsetProxy.exe (ID: 7004 |ParentID: 6828)
C:\Program Files\Hewlett-Packard\HP Power Assistant\HPPA_Service.exe (ID: 6912 |ParentID: 620)
C:\Program Files\Hewlett-Packard\HP Wireless Assistant\HPWA_Service.exe (ID: 3928 |ParentID: 620)
C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe (ID: 7184 |ParentID: 620)
C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe (ID: 7352 |ParentID: 620)
C:\Windows\system32\sppsvc.exe (ID: 7504 |ParentID: 620)
C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe (ID: 7692 |ParentID: 620)
C:\Program Files\Hewlett-Packard\HP Wireless Assistant\HPWA_Main.exe (ID: 7012 |ParentID: 5220)
C:\Program Files\Hewlett-Packard\HP Power Assistant\HPPA_Main.exe (ID: 8100 |ParentID: 1964)
C:\Program Files (x86)\Common Files\Portrait Displays\Drivers\SDKCOMServer.exe (ID: 1344 |ParentID: 792)
C:\Program Files (x86)\Hewlett-Packard\Shared\hpCaslNotification.exe (ID: 1964 |ParentID: 7012)
C:\Program Files (x86)\Common Files\Portrait Displays\Drivers\pdiSdkHelperx64.exe (ID: 7044 |ParentID: 1344)
C:\Windows\Microsoft.Net\Framework64\v3.0\WPF\PresentationFontCache.exe (ID: 4788 |ParentID: 620)
C:\Windows\system32\igfxext.exe (ID: 5224 |ParentID: 792)
C:\Windows\system32\igfxsrvc.exe (ID: 6856 |ParentID: 792)
C:\Program Files (x86)\Adobe\Acrobat 9.0\Acrobat\Acrobat.exe (ID: 7280 |ParentID: 5364)
C:\Program Files (x86)\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe (ID: 6908 |ParentID: 620)
C:\Program Files\Internet Explorer\IEXPLORE.EXE (ID: 9008 |ParentID: 8360)
C:\Program Files (x86)\Internet Explorer\IEXPLORE.EXE (ID: 7344 |ParentID: 9008)
C:\Program Files (x86)\TeamViewer\Version8\TeamViewer_Service.exe (ID: 8484 |ParentID: 620)
C:\Program Files (x86)\TeamViewer\Version8\TeamViewer.exe (ID: 9000 |ParentID: 8484)
C:\Program Files (x86)\TeamViewer\Version8\tv_w32.exe (ID: 6784 |ParentID: 8484)
C:\Program Files (x86)\TeamViewer\Version8\tv_x64.exe (ID: 8520 |ParentID: 8484)
C:\Program Files (x86)\Microsoft Office\Office12\WINWORD.EXE (ID: 8876 |ParentID: 4896)
C:\Windows\splwow64.exe (ID: 7036 |ParentID: 8876)
C:\Windows\system32\cmd.exe (ID: 8384 |ParentID: 4896)
C:\Windows\system32\conhost.exe (ID: 5472 |ParentID: 580)
C:\Program Files (x86)\Internet Explorer\IEXPLORE.EXE (ID: 10100 |ParentID: 9008)
C:\Program Files (x86)\McAfee\VirusScan Enterprise\x64\SCAN64.EXE (ID: 7616 |ParentID: 3304)
C:\UsbFix\Go.exe (ID: 10712 |ParentID: 10556)
################## | Regedit Run |
04 - HKLM\SOFTWARE | Run : [COEMsgDisplay] - c:\Program Files (x86)\Hewlett-Packard\PC COE\COEMsgDisplay.exe
04 - HKLM\SOFTWARE | Run : [ShStatEXE] - "C:\Program Files (x86)\McAfee\VirusScan Enterprise\SHSTAT.EXE" /STANDALONE
04 - HKLM\SOFTWARE | Run : [McAfee Host Intrusion Prevention Tray] - "C:\Program Files (x86)\McAfee\Host Intrusion Prevention\FireTray.exe"
04 - HKLM\SOFTWARE | Run : [Adobe Reader Speed Launcher] - "C:\Program Files (x86)\Adobe\Reader 9.0\Reader\Reader_sl.exe"
04 - HKLM\SOFTWARE | Run : [Adobe ARM] - "C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
04 - HKLM\SOFTWARE | Run : [IDA] - C:\Program Files (x86)\Hewlett-Packard\PC COE\IDA.EXE
04 - HKLM\SOFTWARE | Run : [IAStorIcon] - C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe
04 - HKLM\SOFTWARE | Run : [QLBController] - C:\Program Files (x86)\Hewlett-Packard\HP HotKey Support\QLBController.exe /start
04 - HKLM\SOFTWARE | Run : [eepc_SmartClient] - C:\Program Files (x86)\SmartClient\Smart.exe
04 - HKLM\SOFTWARE | Run : [SafeBootTrayManager] - "C:\Program Files (x86)\SafeBoot Tray Manager\SbTrayManager.exe"
04 - HKLM\SOFTWARE | Run : [SafeBootTokenWatcher] - "C:\Program Files (x86)\McAfee\Endpoint Encryption for PC\SbTokWatch.exe"
04 - HKLM\SOFTWARE | Run : [GetITIcon] - C:\Program Files (x86)\Hewlett-Packard\GetITIcon\GetITShell.exe
04 - HKLM\SOFTWARE | Run : [Communicator] - "C:\Program Files (x86)\Microsoft Lync\communicator.exe" /fromrunkey
04 - HKLM\SOFTWARE | Run : [Google Desktop Search] - "C:\Program Files (x86)\Google\Google Desktop Search\GoogleDesktop.exe" /startup
04 - HKLM\SOFTWARE | Run : [ArcSoft Connection Service] - C:\Program Files (x86)\Common Files\ArcSoft\Connection Service\Bin\ACDaemon.exe
04 - HKLM\SOFTWARE | Run : [McAfeeUpdaterUI] - "C:\Program Files (x86)\McAfee\Common Framework\udaterui.exe" /StartedFromRunKey
04 - HKLM\SOFTWARE | Run : [Adobe Acrobat Speed Launcher] - "C:\Program Files (x86)\Adobe\Acrobat 9.0\Acrobat\Acrobat_sl.exe"
04 - HKLM\SOFTWARE | Run : [] -
04 - HKLM\SOFTWARE | Run : [Acrobat Assistant 8.0] - "C:\Program Files (x86)\Adobe\Acrobat 9.0\Acrobat\Acrotray.exe"
04 - HKLM\SOFTWARE\wow6432Node | Run : [COEMsgDisplay] - c:\Program Files (x86)\Hewlett-Packard\PC COE\COEMsgDisplay.exe
04 - HKLM\SOFTWARE\wow6432Node | Run : [ShStatEXE] - "C:\Program Files (x86)\McAfee\VirusScan Enterprise\SHSTAT.EXE" /STANDALONE
04 - HKLM\SOFTWARE\wow6432Node | Run : [McAfee Host Intrusion Prevention Tray] - "C:\Program Files (x86)\McAfee\Host Intrusion Prevention\FireTray.exe"
04 - HKLM\SOFTWARE\wow6432Node | Run : [Adobe Reader Speed Launcher] - "C:\Program Files (x86)\Adobe\Reader 9.0\Reader\Reader_sl.exe"
04 - HKLM\SOFTWARE\wow6432Node | Run : [Adobe ARM] - "C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
04 - HKLM\SOFTWARE\wow6432Node | Run : [IDA] - C:\Program Files (x86)\Hewlett-Packard\PC COE\IDA.EXE
04 - HKLM\SOFTWARE\wow6432Node | Run : [IAStorIcon] - C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe
04 - HKLM\SOFTWARE\wow6432Node | Run : [QLBController] - C:\Program Files (x86)\Hewlett-Packard\HP HotKey Support\QLBController.exe /start
04 - HKLM\SOFTWARE\wow6432Node | Run : [eepc_SmartClient] - C:\Program Files (x86)\SmartClient\Smart.exe
04 - HKLM\SOFTWARE\wow6432Node | Run : [SafeBootTrayManager] - "C:\Program Files (x86)\SafeBoot Tray Manager\SbTrayManager.exe"
04 - HKLM\SOFTWARE\wow6432Node | Run : [SafeBootTokenWatcher] - "C:\Program Files (x86)\McAfee\Endpoint Encryption for PC\SbTokWatch.exe"
04 - HKLM\SOFTWARE\wow6432Node | Run : [GetITIcon] - C:\Program Files (x86)\Hewlett-Packard\GetITIcon\GetITShell.exe
04 - HKLM\SOFTWARE\wow6432Node | Run : [Communicator] - "C:\Program Files (x86)\Microsoft Lync\communicator.exe" /fromrunkey
04 - HKLM\SOFTWARE\wow6432Node | Run : [Google Desktop Search] - "C:\Program Files (x86)\Google\Google Desktop Search\GoogleDesktop.exe" /startup
04 - HKLM\SOFTWARE\wow6432Node | Run : [ArcSoft Connection Service] - C:\Program Files (x86)\Common Files\ArcSoft\Connection Service\Bin\ACDaemon.exe
04 - HKLM\SOFTWARE\wow6432Node | Run : [McAfeeUpdaterUI] - "C:\Program Files (x86)\McAfee\Common Framework\udaterui.exe" /StartedFromRunKey
04 - HKLM\SOFTWARE\wow6432Node | Run : [Adobe Acrobat Speed Launcher] - "C:\Program Files (x86)\Adobe\Acrobat 9.0\Acrobat\Acrobat_sl.exe"
04 - HKLM\SOFTWARE\wow6432Node | Run : [] -
04 - HKLM\SOFTWARE\wow6432Node | Run : [Acrobat Assistant 8.0] - "C:\Program Files (x86)\Adobe\Acrobat 9.0\Acrobat\Acrotray.exe"
04 - HKLM\SOFTWARE | RunOnce : [] -
04 - HKLM\SOFTWARE\wow6432Node | RunOnce : [] -
04 - HKU\S-1-5-19\SOFTWARE | Run : [Sidebar] - %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun
04 - HKU\S-1-5-20\SOFTWARE | Run : [Sidebar] - %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun
04 - HKU\S-1-5-21-1957994488-842925246-40105171-559050\SOFTWARE | Run : [LightScribe Control Panel] - C:\Program Files (x86)\Common Files\LightScribe\LightScribeControlPanel.exe -hidden
04 - HKU\S-1-5-21-1957994488-842925246-40105171-559050\SOFTWARE | Run : [Yontoo Desktop] - "C:\Users\berber\AppData\Roaming\Yontoo\YontooDesktop.exe"
04 - HKU\S-1-5-21-1957994488-842925246-40105171-559050\SOFTWARE | Run : [Uftiux] - C:\Users\berber\AppData\Roaming\Fiqya\querq.exe
04 - HKU\S-1-5-21-1957994488-842925246-40105171-559050\SOFTWARE | Run : [Screen Saver Pro 3.1] - C:\Users\berber\AppData\Roaming\ScreenSaverPro.scr
04 - HKU\S-1-5-21-1957994488-842925246-40105171-559050\SOFTWARE | Run : [hbweaaa] - C:\RECYCLER\S-1-5-21-0243556031-888888379-781863308-5135689\hbweaaa.exe
04 - HKU\S-1-5-21-1957994488-842925246-40105171-559050\SOFTWARE | Run : [ActiveUpdate] - \Windows\Explorer.exe
04 - HKU\S-1-5-21-1957994488-842925246-40105171-559050\SOFTWARE | Run : [Xfogod] - C:\Users\berber\AppData\Roaming\Microsoft\Xfogod.exe
04 - HKU\S-1-5-19\SOFTWARE | RunOnce : [mctadmin] - C:\Windows\System32\mctadmin.exe
04 - HKU\S-1-5-20\SOFTWARE | RunOnce : [mctadmin] - C:\Windows\System32\mctadmin.exe
################## | Generic Research |
Found ! F:\$RECYCLE.BIN.lnk
Found ! F:\92b598d5c25eaab268d0b4.lnk
Found ! F:\System Volume Information.lnk
Found ! F:\TBE.lnk
Found ! C:\Users\berber\AppData\Roaming\temp.bin
Found ! C:\Recycler\S-1-5-21-0243556031-888888379-781863308-5135689
################## | Reference of comparison MD5 |
Md5 : 8FC4380C035CCB452FFFD4802A13EB2B -> C:\Users\berber\AppData\Roaming\temp.bin
################## | Comparison MD5 |
################## | Registry |
Found ! HKLM\Software\Microsoft\Windows\CurrentVersion\Policies\System|EnableLUA -> 0
Found ! HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced|Start_ShowMyGames -> 0
Found ! HKU\S-1-5-21-1957994488-842925246-40105171-559050\Software\Microsoft\Windows\CurrentVersion\Run|Screen Saver Pro 3.1
Found ! HKCU\Software\Microsoft\Windows\CurrentVersion\Run|Screen Saver Pro 3.1
################## | Vaccin |
(!) This computer is not vaccinated!
################## | E.O.F | https://www.usbfix.net - https://www.sosvirus.net |