- dim. 19 mai 2013 23:51
#3998
Re Bonsoir!
Voilà tous les scans pour le second PC!
1er rapport:
############################## | UsbFix V 7.126 | [Recherche]
Utilisateur: Anne (Administrateur) # ANNE-VAIO
Mis à jour le 13/05/2013 par El Desaparecido
Lancé à 23:00:58 | 19/05/2013
Site Web: https://sosvirus.org/
Upload Malware: https://upload.sosvirus.org/
Contact: contact@sosvirus.org
PC: Sony Corporation (VPCSB3V9E) (x64-based PC)
CPU: Intel(R) Core(TM) i5-2430M CPU @ 2.40GHz (2401)
RAM -> [Total : 6060 | Free : 4023]
BIOS: InsydeH2O Version HuronRiver.3.60.48.2043R2080H4
BOOT: Normal boot
OS: Microsoft Windows 7 Professionnel (6.1.7601 64-Bit) # Service Pack 1
WB: Windows Internet Explorer 10.0.9200.16576
SC: Security Center Service [Enabled]
WU: Windows Update Service [Enabled]
AV: avast! Antivirus [(!) Disabled | Updated]
FW: Windows FireWall Service [Enabled]
C:\ (%systemdrive%) -> Disque fixe # 449 Go (277 Go libre(s) - 62%) [] # NTFS
D:\ -> CD-ROM
F:\ -> Disque fixe # 931 Go (520 Go libre(s) - 56%) [My Book] # NTFS
G:\ -> CD-ROM
################## | Processus Actif |
C:\Windows\system32\csrss.exe (556)
C:\Windows\system32\wininit.exe (692)
C:\Windows\system32\csrss.exe (720)
C:\Windows\system32\services.exe (748)
C:\Windows\system32\lsass.exe (764)
C:\Windows\system32\lsm.exe (772)
C:\Windows\system32\svchost.exe (880)
C:\Windows\system32\winlogon.exe (940)
C:\Program Files\TrueSuite\TrueSuite.Service.exe (1004)
C:\Windows\system32\svchost.exe (376)
C:\Windows\system32\atiesrxx.exe (596)
C:\Windows\System32\svchost.exe (704)
C:\Windows\System32\svchost.exe (1036)
C:\Windows\system32\svchost.exe (1064)
C:\Windows\system32\svchost.exe (1092)
C:\Windows\system32\svchost.exe (1408)
C:\Windows\system32\atieclxx.exe (1480)
C:\Windows\system32\WLANExt.exe (1532)
C:\Windows\system32\conhost.exe (1572)
C:\Windows\system32\svchost.exe (1708)
C:\Program Files\AVAST Software\Avast\AvastSvc.exe (1748)
C:\Windows\System32\spoolsv.exe (1880)
C:\Windows\system32\svchost.exe (1952)
C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe (2072)
C:\Windows\SysWOW64\svchost.exe (2096)
C:\Program Files\Intel\BluetoothHS\BTHSAmpPalService.exe (2116)
C:\Program Files (x86)\Autodesk\Content Service\Connect.Service.ContentService.exe (2144)
C:\Program Files (x86)\Intel\Bluetooth\devmonsrv.exe (2372)
C:\Program Files\Bonjour\mDNSResponder.exe (2396)
C:\Windows\system32\svchost.exe (2432)
C:\Program Files\Intel\BluetoothHS\BTHSSecurityMgr.exe (2472)
C:\Program Files\Intel\WiFi\bin\EvtEng.exe (2544)
C:\Windows\system32\svchost.exe (2568)
C:\Program Files (x86)\Huawei\Gobi\GobiQDLService\GobiQDLService.exe (2648)
C:\Program Files\Common Files\Intel\WirelessCommon\RegSrvc.exe (2748)
C:\Program Files (x86)\Microsoft\BingBar\SeaPort.EXE (2776)
C:\Program Files (x86)\Microsoft Application Virtualization Client\sftvsa.exe (2132)
C:\Windows\system32\svchost.exe (2672)
C:\Program Files (x86)\Sony\VAIO Control Center\VESMgr.exe (3140)
C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE (3168)
C:\Program Files (x86)\Sony\VAIO Control Center\VESMgrSub.exe (3216)
C:\Program Files (x86)\Sony\VAIO Control Center\VESMgrSub.exe (3244)
C:\Windows\SysWOW64\DllHost.exe (3332)
C:\Windows\SysWOW64\DllHost.exe (3376)
C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe (3480)
C:\Windows\system32\wbem\wmiprvse.exe (3556)
C:\Windows\system32\wbem\unsecapp.exe (3592)
C:\Program Files (x86)\OneClickInternet\WTGService.exe (3740)
C:\Program Files (x86)\Intel\Bluetooth\obexsrv.exe (3764)
C:\Program Files (x86)\Microsoft Application Virtualization Client\sftlist.exe (3872)
C:\Program Files (x86)\Common Files\Microsoft Shared\Virtualization Handler\CVHSVC.EXE (4040)
C:\Windows\system32\svchost.exe (4248)
C:\Windows\system32\Dwm.exe (4928)
C:\Windows\system32\taskhost.exe (4936)
C:\Windows\Explorer.EXE (5000)
C:\Windows\system32\taskeng.exe (4408)
C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe (552)
C:\Program Files\Common Files\Intel\WirelessCommon\iFrmewrk.exe (1624)
C:\Windows\System32\rundll32.exe (800)
C:\Program Files\Apoint\Apoint.exe (3284)
C:\Program Files\TrueSuite\TrueSuite.ClientAppLogonExe.exe (3436)
C:\Program Files\TrueSuite\x86\TrueSuite.ClientAppLogonExe.exe (1740)
C:\Windows\System32\hkcmd.exe (2976)
C:\Windows\system32\wbem\unsecapp.exe (2920)
C:\Program Files\Apoint\ApMsgFwd.exe (4348)
C:\Windows\System32\igfxpers.exe (4896)
C:\Program Files\HP\HP Photosmart 6510 series\Bin\ScanToPCActivationApp.exe (2084)
C:\Program Files (x86)\Common Files\Apple\Internet Services\iCloudServices.exe (4644)
C:\Program Files (x86)\Common Files\Apple\Internet Services\ApplePhotoStreams.exe (4648)
C:\Windows\System32\StikyNot.exe (3020)
C:\Windows\System32\WScript.exe (3512)
C:\Windows\system32\RunDll32.exe (2480)
C:\Program Files (x86)\Intel\Bluetooth\mediasrv.exe (1160)
C:\Windows\system32\wbem\wmiprvse.exe (1908)
C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe (3120)
C:\Program Files\TrueSuite\TrueSuite.TouchControl.exe (3184)
C:\Program Files\HP\HP Photosmart 6510 series\bin\HPNetworkCommunicator.exe (4620)
C:\Windows\system32\SearchIndexer.exe (5124)
C:\Program Files (x86)\Sony\ISB Utility\ISBMgr.exe (5208)
C:\Program Files\Apoint\Apntex.exe (5240)
C:\Windows\system32\conhost.exe (5268)
C:\Program Files (x86)\Adobe\Acrobat 10.0\Acrobat\acrotray.exe (5312)
C:\Program Files\AVAST Software\Avast\AvastUI.exe (5372)
C:\Program Files (x86)\HP\HP Software Update\hpwuschd2.exe (5392)
C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe (5452)
C:\Program Files\Apoint\Apvfb.exe (5536)
C:\Program Files\Windows Media Player\wmpnetwk.exe (5724)
C:\Program Files\HP\HP Photosmart 6510 series\Bin\HPNetworkCommunicator.exe (6044)
C:\Program Files (x86)\Intel\Bluetooth\BTPlayerCtrl.exe (4552)
C:\Program Files\Sony\VAIO Smart Network\VSNService.exe (4556)
C:\Program Files\Sony\VAIO Smart Network\VSNClient.exe (4000)
C:\Windows\system32\DllHost.exe (4916)
c:\Program Files (x86)\Adobe\Elements 9 Organizer\PhotoshopElementsFileAgent.exe (6384)
C:\Windows\System32\svchost.exe (6536)
C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe (6852)
C:\Program Files (x86)\Realtek\Realtek PCIE Card Reader\RIconMan.exe (7068)
C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe (7100)
C:\Program Files\Sony\VAIO Power Management\SPMgr.exe (7132)
C:\Program Files\Sony\VAIO Care\VCPerfService.exe (7148)
C:\Windows\system32\DllHost.exe (5104)
C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\MOM.exe (6444)
C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CCC.exe (4300)
C:\Program Files\Sony\VAIO Care\listener.exe (3712)
C:\Program Files\Sony\VAIO Power Management\SPMService.exe (8132)
C:\Windows\Microsoft.Net\Framework64\v3.0\WPF\PresentationFontCache.exe (8164)
C:\Windows\System32\svchost.exe (5812)
C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe (1684)
C:\Program Files\Sony\VAIO Care\VCSystemTray.exe (6612)
C:\Program Files\Sony\VAIO Care\VCService.exe (8128)
C:\Program Files\Sony\VAIO Care\VCAgent.exe (4752)
C:\Windows\System32\vds.exe (6116)
C:\Program Files\Sony\VAIO Update Common\VUAgent.exe (3148)
C:\Program Files\Sony\VAIO Care\VCAdmin.exe (5504)
C:\Program Files\Sony\VAIO Care\VCSystemTray.exe (5612)
C:\Program Files\Sony\VAIO Care\VCSystemTray.exe (8568)
C:\Windows\SysWOW64\cmd.exe (18752)
C:\Users\Anne\AppData\Local\Akamai\netsession_win.exe (18636)
C:\Users\Anne\AppData\Local\Akamai\netsession_win.exe (19056)
C:\Program Files\Sony\VAIO Care\VCSystemTray.exe (16092)
C:\Program Files\Sony\VAIO Care\VCSystemTray.exe (18628)
C:\Program Files\Sony\VAIO Care\VCSystemTray.exe (15140)
C:\UsbFix\Go.exe (10896)
C:\Windows\SysWOW64\ctfmon.exe (9392)
C:\Windows\system32\igfxsrvc.exe (8496)
C:\Windows\system32\taskeng.exe (8352)
################## | El Desaparecido Section |
HKLM\SOFTWARE | Run : [IAStorIcon] - C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe
HKLM\SOFTWARE | Run : [ISBMgr.exe] - "C:\Program Files (x86)\Sony\ISB Utility\ISBMgr.exe"
HKLM\SOFTWARE | Run : [Adobe Acrobat Speed Launcher] - "C:\Program Files (x86)\Adobe\Acrobat 10.0\Acrobat\Acrobat_sl.exe"
HKLM\SOFTWARE | Run : [Acrobat Assistant 8.0] - "C:\Program Files (x86)\Adobe\Acrobat 10.0\Acrobat\Acrotray.exe"
HKLM\SOFTWARE | Run : [avast] - "C:\Program Files\AVAST Software\Avast\avastUI.exe" /nogui
HKLM\SOFTWARE | Run : [HP Software Update] - C:\Program Files (x86)\Hp\HP Software Update\HPWuSchd2.exe
HKLM\SOFTWARE | Run : [] -
HKLM\SOFTWARE | Run : [StartCCC] - "C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" MSRun
HKLM\SOFTWARE | Run : [APSDaemon] - "C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe"
HKLM\SOFTWARE | Run : [QuickTime Task] - "C:\Program Files (x86)\QuickTime\QTTask.exe" -atboottime
HKLM\SOFTWARE | Run : [SwitchBoard] - C:\Program Files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe
HKLM\SOFTWARE | Run : [AdobeCS6ServiceManager] - "C:\Program Files (x86)\Common Files\Adobe\CS6ServiceManager\CS6ServiceManager.exe" -launchedbylogin
HKLM\SOFTWARE\wow6432Node | Run : [IAStorIcon] - C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe
HKLM\SOFTWARE\wow6432Node | Run : [ISBMgr.exe] - "C:\Program Files (x86)\Sony\ISB Utility\ISBMgr.exe"
HKLM\SOFTWARE\wow6432Node | Run : [Adobe Acrobat Speed Launcher] - "C:\Program Files (x86)\Adobe\Acrobat 10.0\Acrobat\Acrobat_sl.exe"
HKLM\SOFTWARE\wow6432Node | Run : [Acrobat Assistant 8.0] - "C:\Program Files (x86)\Adobe\Acrobat 10.0\Acrobat\Acrotray.exe"
HKLM\SOFTWARE\wow6432Node | Run : [avast] - "C:\Program Files\AVAST Software\Avast\avastUI.exe" /nogui
HKLM\SOFTWARE\wow6432Node | Run : [HP Software Update] - C:\Program Files (x86)\Hp\HP Software Update\HPWuSchd2.exe
HKLM\SOFTWARE\wow6432Node | Run : [] -
HKLM\SOFTWARE\wow6432Node | Run : [StartCCC] - "C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" MSRun
HKLM\SOFTWARE\wow6432Node | Run : [APSDaemon] - "C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe"
HKLM\SOFTWARE\wow6432Node | Run : [QuickTime Task] - "C:\Program Files (x86)\QuickTime\QTTask.exe" -atboottime
HKLM\SOFTWARE\wow6432Node | Run : [SwitchBoard] - C:\Program Files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe
HKLM\SOFTWARE\wow6432Node | Run : [AdobeCS6ServiceManager] - "C:\Program Files (x86)\Common Files\Adobe\CS6ServiceManager\CS6ServiceManager.exe" -launchedbylogin
HKLM\SOFTWARE | RunOnce : [] -
HKLM\SOFTWARE\wow6432Node | RunOnce : [] -
HKU\S-1-5-19\SOFTWARE | Run : [Sidebar] - %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun
HKU\S-1-5-20\SOFTWARE | Run : [Sidebar] - %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun
HKU\S-1-5-21-1629100858-3325427812-1078406721-1001\SOFTWARE | Run : [Akamai NetSession Interface] - "C:\Users\Anne\AppData\Local\Akamai\netsession_win.exe"
HKU\S-1-5-21-1629100858-3325427812-1078406721-1001\SOFTWARE | Run : [HP Photosmart 6510 series (NET)] - "C:\Program Files\HP\HP Photosmart 6510 series\Bin\ScanToPCActivationApp.exe" -deviceID "CN1CN4328205QB:NW" -scfn "HP Photosmart 6510 series (NET)" -AutoStart 1
HKU\S-1-5-21-1629100858-3325427812-1078406721-1001\SOFTWARE | Run : [iCloudServices] - C:\Program Files (x86)\Common Files\Apple\Internet Services\iCloudServices.exe
HKU\S-1-5-21-1629100858-3325427812-1078406721-1001\SOFTWARE | Run : [ApplePhotoStreams] - C:\Program Files (x86)\Common Files\Apple\Internet Services\ApplePhotoStreams.exe
HKU\S-1-5-21-1629100858-3325427812-1078406721-1001\SOFTWARE | Run : [AdobeBridge] -
HKU\S-1-5-21-1629100858-3325427812-1078406721-1001\SOFTWARE | Run : [RESTART_STICKY_NOTES] - C:\Windows\System32\StikyNot.exe
HKU\S-1-5-21-1629100858-3325427812-1078406721-1001\SOFTWARE | Run : [Facebook.vbs] - "C:\Users\Anne\AppData\Local\Temp\Facebook.vbs"
HKU\S-1-5-19\SOFTWARE | RunOnce : [mctadmin] - C:\Windows\System32\mctadmin.exe
HKU\S-1-5-20\SOFTWARE | RunOnce : [mctadmin] - C:\Windows\System32\mctadmin.exe
################## | à‰léments infectieux |
Présent! C:\Users\Anne\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Facebook.vbs
Présent! C:\Users\Anne\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\FlashPlayerPlug.lnk
Présent! C:\Users\Anne\AppData\Local\Temp\Facebook.vbs
Présent! D:\autorun.inf
Présent! F:\autorun.inf
################## | Registre |
Présent! HKCU|njq8
Présent! HKCU\Software\Microsoft\Windows\CurrentVersion\Run|Facebook.vbs
################## | Mountpoints2 |
HKCU\.\.\.\.\Explorer\MountPoints2\{ff50cb17-c165-11e1-a8f4-88532e57fbf6}
Shell\AutoRun\Command = "D:\WD SmartWare.exe" autoplay=true
################## | Vaccin |
(!) Cet ordinateur n'est pas vacciné!
################## | E.O.F | https://sosvirus.org |
Deuxième rapport:
# AdwCleaner v2.301 - Rapport créé le 19/05/2013 à 23:26:33
# Mis à jour le 16/05/2013 par Xplode
# Système d'exploitation : Windows 7 Professional Service Pack 1 (64 bits)
# Nom d'utilisateur : Anne - ANNE-VAIO
# Mode de démarrage : Normal
# Exécuté depuis : C:\Users\Anne\Desktop\adwcleaner.exe
# Option [Suppression]
***** [Services] *****
***** [Fichiers / Dossiers] *****
***** [Registre] *****
Clé Supprimée : HKLM\Software\DeviceVM
***** [Navigateurs] *****
-\\ Internet Explorer v10.0.9200.16576
[OK] Le registre ne contient aucune entrée illégitime.
-\\ Mozilla Firefox v20.0.1 (fr)
Fichier : C:\Users\Anne\AppData\Roaming\Mozilla\Firefox\Profiles\jqk4dqcz.default\prefs.js
[OK] Le fichier ne contient aucune entrée illégitime.
-\\ Google Chrome v26.0.1410.64
Fichier : C:\Users\Anne\AppData\Local\Google\Chrome\User Data\Default\Preferences
[OK] Le fichier ne contient aucune entrée illégitime.
*************************
AdwCleaner[S1].txt - [988 octets] - [19/05/2013 23:26:33]
########## EOF - C:\AdwCleaner[S1].txt - [1047 octets] ##########
3e rapport:
# AdwCleaner v2.301 - Rapport créé le 19/05/2013 à 23:26:33
# Mis à jour le 16/05/2013 par Xplode
# Système d'exploitation : Windows 7 Professional Service Pack 1 (64 bits)
# Nom d'utilisateur : Anne - ANNE-VAIO
# Mode de démarrage : Normal
# Exécuté depuis : C:\Users\Anne\Desktop\adwcleaner.exe
# Option [Suppression]
***** [Services] *****
***** [Fichiers / Dossiers] *****
***** [Registre] *****
Clé Supprimée : HKLM\Software\DeviceVM
***** [Navigateurs] *****
-\\ Internet Explorer v10.0.9200.16576
[OK] Le registre ne contient aucune entrée illégitime.
-\\ Mozilla Firefox v20.0.1 (fr)
Fichier : C:\Users\Anne\AppData\Roaming\Mozilla\Firefox\Profiles\jqk4dqcz.default\prefs.js
[OK] Le fichier ne contient aucune entrée illégitime.
-\\ Google Chrome v26.0.1410.64
Fichier : C:\Users\Anne\AppData\Local\Google\Chrome\User Data\Default\Preferences
[OK] Le fichier ne contient aucune entrée illégitime.
*************************
AdwCleaner[S1].txt - [988 octets] - [19/05/2013 23:26:33]
########## EOF - C:\AdwCleaner[S1].txt - [1047 octets] ##########
Merci encore!
Voilà tous les scans pour le second PC!
1er rapport:
############################## | UsbFix V 7.126 | [Recherche]
Utilisateur: Anne (Administrateur) # ANNE-VAIO
Mis à jour le 13/05/2013 par El Desaparecido
Lancé à 23:00:58 | 19/05/2013
Site Web: https://sosvirus.org/
Upload Malware: https://upload.sosvirus.org/
Contact: contact@sosvirus.org
PC: Sony Corporation (VPCSB3V9E) (x64-based PC)
CPU: Intel(R) Core(TM) i5-2430M CPU @ 2.40GHz (2401)
RAM -> [Total : 6060 | Free : 4023]
BIOS: InsydeH2O Version HuronRiver.3.60.48.2043R2080H4
BOOT: Normal boot
OS: Microsoft Windows 7 Professionnel (6.1.7601 64-Bit) # Service Pack 1
WB: Windows Internet Explorer 10.0.9200.16576
SC: Security Center Service [Enabled]
WU: Windows Update Service [Enabled]
AV: avast! Antivirus [(!) Disabled | Updated]
FW: Windows FireWall Service [Enabled]
C:\ (%systemdrive%) -> Disque fixe # 449 Go (277 Go libre(s) - 62%) [] # NTFS
D:\ -> CD-ROM
F:\ -> Disque fixe # 931 Go (520 Go libre(s) - 56%) [My Book] # NTFS
G:\ -> CD-ROM
################## | Processus Actif |
C:\Windows\system32\csrss.exe (556)
C:\Windows\system32\wininit.exe (692)
C:\Windows\system32\csrss.exe (720)
C:\Windows\system32\services.exe (748)
C:\Windows\system32\lsass.exe (764)
C:\Windows\system32\lsm.exe (772)
C:\Windows\system32\svchost.exe (880)
C:\Windows\system32\winlogon.exe (940)
C:\Program Files\TrueSuite\TrueSuite.Service.exe (1004)
C:\Windows\system32\svchost.exe (376)
C:\Windows\system32\atiesrxx.exe (596)
C:\Windows\System32\svchost.exe (704)
C:\Windows\System32\svchost.exe (1036)
C:\Windows\system32\svchost.exe (1064)
C:\Windows\system32\svchost.exe (1092)
C:\Windows\system32\svchost.exe (1408)
C:\Windows\system32\atieclxx.exe (1480)
C:\Windows\system32\WLANExt.exe (1532)
C:\Windows\system32\conhost.exe (1572)
C:\Windows\system32\svchost.exe (1708)
C:\Program Files\AVAST Software\Avast\AvastSvc.exe (1748)
C:\Windows\System32\spoolsv.exe (1880)
C:\Windows\system32\svchost.exe (1952)
C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe (2072)
C:\Windows\SysWOW64\svchost.exe (2096)
C:\Program Files\Intel\BluetoothHS\BTHSAmpPalService.exe (2116)
C:\Program Files (x86)\Autodesk\Content Service\Connect.Service.ContentService.exe (2144)
C:\Program Files (x86)\Intel\Bluetooth\devmonsrv.exe (2372)
C:\Program Files\Bonjour\mDNSResponder.exe (2396)
C:\Windows\system32\svchost.exe (2432)
C:\Program Files\Intel\BluetoothHS\BTHSSecurityMgr.exe (2472)
C:\Program Files\Intel\WiFi\bin\EvtEng.exe (2544)
C:\Windows\system32\svchost.exe (2568)
C:\Program Files (x86)\Huawei\Gobi\GobiQDLService\GobiQDLService.exe (2648)
C:\Program Files\Common Files\Intel\WirelessCommon\RegSrvc.exe (2748)
C:\Program Files (x86)\Microsoft\BingBar\SeaPort.EXE (2776)
C:\Program Files (x86)\Microsoft Application Virtualization Client\sftvsa.exe (2132)
C:\Windows\system32\svchost.exe (2672)
C:\Program Files (x86)\Sony\VAIO Control Center\VESMgr.exe (3140)
C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE (3168)
C:\Program Files (x86)\Sony\VAIO Control Center\VESMgrSub.exe (3216)
C:\Program Files (x86)\Sony\VAIO Control Center\VESMgrSub.exe (3244)
C:\Windows\SysWOW64\DllHost.exe (3332)
C:\Windows\SysWOW64\DllHost.exe (3376)
C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe (3480)
C:\Windows\system32\wbem\wmiprvse.exe (3556)
C:\Windows\system32\wbem\unsecapp.exe (3592)
C:\Program Files (x86)\OneClickInternet\WTGService.exe (3740)
C:\Program Files (x86)\Intel\Bluetooth\obexsrv.exe (3764)
C:\Program Files (x86)\Microsoft Application Virtualization Client\sftlist.exe (3872)
C:\Program Files (x86)\Common Files\Microsoft Shared\Virtualization Handler\CVHSVC.EXE (4040)
C:\Windows\system32\svchost.exe (4248)
C:\Windows\system32\Dwm.exe (4928)
C:\Windows\system32\taskhost.exe (4936)
C:\Windows\Explorer.EXE (5000)
C:\Windows\system32\taskeng.exe (4408)
C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe (552)
C:\Program Files\Common Files\Intel\WirelessCommon\iFrmewrk.exe (1624)
C:\Windows\System32\rundll32.exe (800)
C:\Program Files\Apoint\Apoint.exe (3284)
C:\Program Files\TrueSuite\TrueSuite.ClientAppLogonExe.exe (3436)
C:\Program Files\TrueSuite\x86\TrueSuite.ClientAppLogonExe.exe (1740)
C:\Windows\System32\hkcmd.exe (2976)
C:\Windows\system32\wbem\unsecapp.exe (2920)
C:\Program Files\Apoint\ApMsgFwd.exe (4348)
C:\Windows\System32\igfxpers.exe (4896)
C:\Program Files\HP\HP Photosmart 6510 series\Bin\ScanToPCActivationApp.exe (2084)
C:\Program Files (x86)\Common Files\Apple\Internet Services\iCloudServices.exe (4644)
C:\Program Files (x86)\Common Files\Apple\Internet Services\ApplePhotoStreams.exe (4648)
C:\Windows\System32\StikyNot.exe (3020)
C:\Windows\System32\WScript.exe (3512)
C:\Windows\system32\RunDll32.exe (2480)
C:\Program Files (x86)\Intel\Bluetooth\mediasrv.exe (1160)
C:\Windows\system32\wbem\wmiprvse.exe (1908)
C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe (3120)
C:\Program Files\TrueSuite\TrueSuite.TouchControl.exe (3184)
C:\Program Files\HP\HP Photosmart 6510 series\bin\HPNetworkCommunicator.exe (4620)
C:\Windows\system32\SearchIndexer.exe (5124)
C:\Program Files (x86)\Sony\ISB Utility\ISBMgr.exe (5208)
C:\Program Files\Apoint\Apntex.exe (5240)
C:\Windows\system32\conhost.exe (5268)
C:\Program Files (x86)\Adobe\Acrobat 10.0\Acrobat\acrotray.exe (5312)
C:\Program Files\AVAST Software\Avast\AvastUI.exe (5372)
C:\Program Files (x86)\HP\HP Software Update\hpwuschd2.exe (5392)
C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe (5452)
C:\Program Files\Apoint\Apvfb.exe (5536)
C:\Program Files\Windows Media Player\wmpnetwk.exe (5724)
C:\Program Files\HP\HP Photosmart 6510 series\Bin\HPNetworkCommunicator.exe (6044)
C:\Program Files (x86)\Intel\Bluetooth\BTPlayerCtrl.exe (4552)
C:\Program Files\Sony\VAIO Smart Network\VSNService.exe (4556)
C:\Program Files\Sony\VAIO Smart Network\VSNClient.exe (4000)
C:\Windows\system32\DllHost.exe (4916)
c:\Program Files (x86)\Adobe\Elements 9 Organizer\PhotoshopElementsFileAgent.exe (6384)
C:\Windows\System32\svchost.exe (6536)
C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe (6852)
C:\Program Files (x86)\Realtek\Realtek PCIE Card Reader\RIconMan.exe (7068)
C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe (7100)
C:\Program Files\Sony\VAIO Power Management\SPMgr.exe (7132)
C:\Program Files\Sony\VAIO Care\VCPerfService.exe (7148)
C:\Windows\system32\DllHost.exe (5104)
C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\MOM.exe (6444)
C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CCC.exe (4300)
C:\Program Files\Sony\VAIO Care\listener.exe (3712)
C:\Program Files\Sony\VAIO Power Management\SPMService.exe (8132)
C:\Windows\Microsoft.Net\Framework64\v3.0\WPF\PresentationFontCache.exe (8164)
C:\Windows\System32\svchost.exe (5812)
C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe (1684)
C:\Program Files\Sony\VAIO Care\VCSystemTray.exe (6612)
C:\Program Files\Sony\VAIO Care\VCService.exe (8128)
C:\Program Files\Sony\VAIO Care\VCAgent.exe (4752)
C:\Windows\System32\vds.exe (6116)
C:\Program Files\Sony\VAIO Update Common\VUAgent.exe (3148)
C:\Program Files\Sony\VAIO Care\VCAdmin.exe (5504)
C:\Program Files\Sony\VAIO Care\VCSystemTray.exe (5612)
C:\Program Files\Sony\VAIO Care\VCSystemTray.exe (8568)
C:\Windows\SysWOW64\cmd.exe (18752)
C:\Users\Anne\AppData\Local\Akamai\netsession_win.exe (18636)
C:\Users\Anne\AppData\Local\Akamai\netsession_win.exe (19056)
C:\Program Files\Sony\VAIO Care\VCSystemTray.exe (16092)
C:\Program Files\Sony\VAIO Care\VCSystemTray.exe (18628)
C:\Program Files\Sony\VAIO Care\VCSystemTray.exe (15140)
C:\UsbFix\Go.exe (10896)
C:\Windows\SysWOW64\ctfmon.exe (9392)
C:\Windows\system32\igfxsrvc.exe (8496)
C:\Windows\system32\taskeng.exe (8352)
################## | El Desaparecido Section |
HKLM\SOFTWARE | Run : [IAStorIcon] - C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe
HKLM\SOFTWARE | Run : [ISBMgr.exe] - "C:\Program Files (x86)\Sony\ISB Utility\ISBMgr.exe"
HKLM\SOFTWARE | Run : [Adobe Acrobat Speed Launcher] - "C:\Program Files (x86)\Adobe\Acrobat 10.0\Acrobat\Acrobat_sl.exe"
HKLM\SOFTWARE | Run : [Acrobat Assistant 8.0] - "C:\Program Files (x86)\Adobe\Acrobat 10.0\Acrobat\Acrotray.exe"
HKLM\SOFTWARE | Run : [avast] - "C:\Program Files\AVAST Software\Avast\avastUI.exe" /nogui
HKLM\SOFTWARE | Run : [HP Software Update] - C:\Program Files (x86)\Hp\HP Software Update\HPWuSchd2.exe
HKLM\SOFTWARE | Run : [] -
HKLM\SOFTWARE | Run : [StartCCC] - "C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" MSRun
HKLM\SOFTWARE | Run : [APSDaemon] - "C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe"
HKLM\SOFTWARE | Run : [QuickTime Task] - "C:\Program Files (x86)\QuickTime\QTTask.exe" -atboottime
HKLM\SOFTWARE | Run : [SwitchBoard] - C:\Program Files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe
HKLM\SOFTWARE | Run : [AdobeCS6ServiceManager] - "C:\Program Files (x86)\Common Files\Adobe\CS6ServiceManager\CS6ServiceManager.exe" -launchedbylogin
HKLM\SOFTWARE\wow6432Node | Run : [IAStorIcon] - C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe
HKLM\SOFTWARE\wow6432Node | Run : [ISBMgr.exe] - "C:\Program Files (x86)\Sony\ISB Utility\ISBMgr.exe"
HKLM\SOFTWARE\wow6432Node | Run : [Adobe Acrobat Speed Launcher] - "C:\Program Files (x86)\Adobe\Acrobat 10.0\Acrobat\Acrobat_sl.exe"
HKLM\SOFTWARE\wow6432Node | Run : [Acrobat Assistant 8.0] - "C:\Program Files (x86)\Adobe\Acrobat 10.0\Acrobat\Acrotray.exe"
HKLM\SOFTWARE\wow6432Node | Run : [avast] - "C:\Program Files\AVAST Software\Avast\avastUI.exe" /nogui
HKLM\SOFTWARE\wow6432Node | Run : [HP Software Update] - C:\Program Files (x86)\Hp\HP Software Update\HPWuSchd2.exe
HKLM\SOFTWARE\wow6432Node | Run : [] -
HKLM\SOFTWARE\wow6432Node | Run : [StartCCC] - "C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" MSRun
HKLM\SOFTWARE\wow6432Node | Run : [APSDaemon] - "C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe"
HKLM\SOFTWARE\wow6432Node | Run : [QuickTime Task] - "C:\Program Files (x86)\QuickTime\QTTask.exe" -atboottime
HKLM\SOFTWARE\wow6432Node | Run : [SwitchBoard] - C:\Program Files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe
HKLM\SOFTWARE\wow6432Node | Run : [AdobeCS6ServiceManager] - "C:\Program Files (x86)\Common Files\Adobe\CS6ServiceManager\CS6ServiceManager.exe" -launchedbylogin
HKLM\SOFTWARE | RunOnce : [] -
HKLM\SOFTWARE\wow6432Node | RunOnce : [] -
HKU\S-1-5-19\SOFTWARE | Run : [Sidebar] - %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun
HKU\S-1-5-20\SOFTWARE | Run : [Sidebar] - %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun
HKU\S-1-5-21-1629100858-3325427812-1078406721-1001\SOFTWARE | Run : [Akamai NetSession Interface] - "C:\Users\Anne\AppData\Local\Akamai\netsession_win.exe"
HKU\S-1-5-21-1629100858-3325427812-1078406721-1001\SOFTWARE | Run : [HP Photosmart 6510 series (NET)] - "C:\Program Files\HP\HP Photosmart 6510 series\Bin\ScanToPCActivationApp.exe" -deviceID "CN1CN4328205QB:NW" -scfn "HP Photosmart 6510 series (NET)" -AutoStart 1
HKU\S-1-5-21-1629100858-3325427812-1078406721-1001\SOFTWARE | Run : [iCloudServices] - C:\Program Files (x86)\Common Files\Apple\Internet Services\iCloudServices.exe
HKU\S-1-5-21-1629100858-3325427812-1078406721-1001\SOFTWARE | Run : [ApplePhotoStreams] - C:\Program Files (x86)\Common Files\Apple\Internet Services\ApplePhotoStreams.exe
HKU\S-1-5-21-1629100858-3325427812-1078406721-1001\SOFTWARE | Run : [AdobeBridge] -
HKU\S-1-5-21-1629100858-3325427812-1078406721-1001\SOFTWARE | Run : [RESTART_STICKY_NOTES] - C:\Windows\System32\StikyNot.exe
HKU\S-1-5-21-1629100858-3325427812-1078406721-1001\SOFTWARE | Run : [Facebook.vbs] - "C:\Users\Anne\AppData\Local\Temp\Facebook.vbs"
HKU\S-1-5-19\SOFTWARE | RunOnce : [mctadmin] - C:\Windows\System32\mctadmin.exe
HKU\S-1-5-20\SOFTWARE | RunOnce : [mctadmin] - C:\Windows\System32\mctadmin.exe
################## | à‰léments infectieux |
Présent! C:\Users\Anne\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Facebook.vbs
Présent! C:\Users\Anne\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\FlashPlayerPlug.lnk
Présent! C:\Users\Anne\AppData\Local\Temp\Facebook.vbs
Présent! D:\autorun.inf
Présent! F:\autorun.inf
################## | Registre |
Présent! HKCU|njq8
Présent! HKCU\Software\Microsoft\Windows\CurrentVersion\Run|Facebook.vbs
################## | Mountpoints2 |
HKCU\.\.\.\.\Explorer\MountPoints2\{ff50cb17-c165-11e1-a8f4-88532e57fbf6}
Shell\AutoRun\Command = "D:\WD SmartWare.exe" autoplay=true
################## | Vaccin |
(!) Cet ordinateur n'est pas vacciné!
################## | E.O.F | https://sosvirus.org |
Deuxième rapport:
# AdwCleaner v2.301 - Rapport créé le 19/05/2013 à 23:26:33
# Mis à jour le 16/05/2013 par Xplode
# Système d'exploitation : Windows 7 Professional Service Pack 1 (64 bits)
# Nom d'utilisateur : Anne - ANNE-VAIO
# Mode de démarrage : Normal
# Exécuté depuis : C:\Users\Anne\Desktop\adwcleaner.exe
# Option [Suppression]
***** [Services] *****
***** [Fichiers / Dossiers] *****
***** [Registre] *****
Clé Supprimée : HKLM\Software\DeviceVM
***** [Navigateurs] *****
-\\ Internet Explorer v10.0.9200.16576
[OK] Le registre ne contient aucune entrée illégitime.
-\\ Mozilla Firefox v20.0.1 (fr)
Fichier : C:\Users\Anne\AppData\Roaming\Mozilla\Firefox\Profiles\jqk4dqcz.default\prefs.js
[OK] Le fichier ne contient aucune entrée illégitime.
-\\ Google Chrome v26.0.1410.64
Fichier : C:\Users\Anne\AppData\Local\Google\Chrome\User Data\Default\Preferences
[OK] Le fichier ne contient aucune entrée illégitime.
*************************
AdwCleaner[S1].txt - [988 octets] - [19/05/2013 23:26:33]
########## EOF - C:\AdwCleaner[S1].txt - [1047 octets] ##########
3e rapport:
# AdwCleaner v2.301 - Rapport créé le 19/05/2013 à 23:26:33
# Mis à jour le 16/05/2013 par Xplode
# Système d'exploitation : Windows 7 Professional Service Pack 1 (64 bits)
# Nom d'utilisateur : Anne - ANNE-VAIO
# Mode de démarrage : Normal
# Exécuté depuis : C:\Users\Anne\Desktop\adwcleaner.exe
# Option [Suppression]
***** [Services] *****
***** [Fichiers / Dossiers] *****
***** [Registre] *****
Clé Supprimée : HKLM\Software\DeviceVM
***** [Navigateurs] *****
-\\ Internet Explorer v10.0.9200.16576
[OK] Le registre ne contient aucune entrée illégitime.
-\\ Mozilla Firefox v20.0.1 (fr)
Fichier : C:\Users\Anne\AppData\Roaming\Mozilla\Firefox\Profiles\jqk4dqcz.default\prefs.js
[OK] Le fichier ne contient aucune entrée illégitime.
-\\ Google Chrome v26.0.1410.64
Fichier : C:\Users\Anne\AppData\Local\Google\Chrome\User Data\Default\Preferences
[OK] Le fichier ne contient aucune entrée illégitime.
*************************
AdwCleaner[S1].txt - [988 octets] - [19/05/2013 23:26:33]
########## EOF - C:\AdwCleaner[S1].txt - [1047 octets] ##########
Merci encore!