UsbFix
- Code: Tout sélectionner
############################## | UsbFix V 7.127 | [Suppression]
Utilisateur: lionel (Administrateur) # LIONEL-PC
Mis à jour le 05/06/2013 par El Desaparecido
Lancé à 22:07:39 | 14/06/2013
Site Web: https://sosvirus.org/
Upload Malware: https://upload.sosvirus.org/
Contact: contact@sosvirus.org
PC: Packard Bell (imedia S2870) (x64-based PC)
CPU: Intel(R) Core(TM) i3-2120 CPU @ 3.30GHz (3300)
RAM -> [Total : 4022 | Free : 2131]
BIOS: BIOS Date: 05/18/12 18:05:13 Ver: 04.06.05
BOOT: Normal boot
OS: Microsoft Windows 7 à‰dition Familiale Premium (6.1.7601 64-Bit) # Service Pack 1
WB: Windows Internet Explorer 10.0.9200.16614
SC: Security Center Service [Enabled]
WU: Windows Update Service [Enabled]
AV: avast! Antivirus [(!) Disabled | Updated]
FW: Windows FireWall Service [Enabled]
C:\ (%systemdrive%) -> Disque fixe # 456 Go (397 Go libre(s) - 87%) [Packard Bell] # NTFS
D:\ -> Disque fixe # 457 Go (457 Go libre(s) - 100%) [DATA] # NTFS
E:\ -> CD-ROM
G:\ -> Disque amovible # 962 Mo (700 Mo libre(s) - 73%) [PKBACK# 001] # FAT
################## | El Desaparecido Section |
HKLM\SOFTWARE | Run : [Adobe ARM] - "C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
HKLM\SOFTWARE | Run : [Hotkey Utility] - C:\Program Files (x86)\Packard Bell\Hotkey Utility\HotkeyUtility.exe
HKLM\SOFTWARE | Run : [avast] - "C:\Program Files\AVAST Software\Avast\avastUI.exe" /nogui
HKLM\SOFTWARE | Run : [HP Software Update] - C:\Program Files (x86)\Hp\HP Software Update\HPWuSchd2.exe
HKLM\SOFTWARE | Run : [] -
HKLM\SOFTWARE | Run : [BCSSync] - "C:\Program Files (x86)\Microsoft Office\Office14\BCSSync.exe" /DelayServices
HKLM\SOFTWARE | Run : [Sweetpacks Communicator] - C:\Program Files (x86)\SweetIM\Communicator\SweetPacksUpdateManager.exe
HKLM\SOFTWARE | Run : [APSDaemon] - "C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe"
HKLM\SOFTWARE | Run : [Wondershare Helper Compact.exe] - C:\Program Files (x86)\Common Files\Wondershare\Wondershare Helper Compact\WSHelper.exe
HKLM\SOFTWARE | Run : [BrowserPlugInHelper] - C:\Program Files (x86)\Wondershare\AllMyTube\BrowserPlugInHelper.exe
HKLM\SOFTWARE | Run : [iTunesHelper] - "C:\Program Files (x86)\iTunes\iTunesHelper.exe"
HKLM\SOFTWARE\wow6432Node | Run : [Adobe ARM] - "C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
HKLM\SOFTWARE\wow6432Node | Run : [Hotkey Utility] - C:\Program Files (x86)\Packard Bell\Hotkey Utility\HotkeyUtility.exe
HKLM\SOFTWARE\wow6432Node | Run : [avast] - "C:\Program Files\AVAST Software\Avast\avastUI.exe" /nogui
HKLM\SOFTWARE\wow6432Node | Run : [HP Software Update] - C:\Program Files (x86)\Hp\HP Software Update\HPWuSchd2.exe
HKLM\SOFTWARE\wow6432Node | Run : [] -
HKLM\SOFTWARE\wow6432Node | Run : [BCSSync] - "C:\Program Files (x86)\Microsoft Office\Office14\BCSSync.exe" /DelayServices
HKLM\SOFTWARE\wow6432Node | Run : [Sweetpacks Communicator] - C:\Program Files (x86)\SweetIM\Communicator\SweetPacksUpdateManager.exe
HKLM\SOFTWARE\wow6432Node | Run : [APSDaemon] - "C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe"
HKLM\SOFTWARE\wow6432Node | Run : [Wondershare Helper Compact.exe] - C:\Program Files (x86)\Common Files\Wondershare\Wondershare Helper Compact\WSHelper.exe
HKLM\SOFTWARE\wow6432Node | Run : [BrowserPlugInHelper] - C:\Program Files (x86)\Wondershare\AllMyTube\BrowserPlugInHelper.exe
HKLM\SOFTWARE\wow6432Node | Run : [iTunesHelper] - "C:\Program Files (x86)\iTunes\iTunesHelper.exe"
HKLM\SOFTWARE | RunOnce : [] -
HKLM\SOFTWARE\wow6432Node | RunOnce : [] -
HKU\S-1-5-19\SOFTWARE | Run : [Sidebar] - %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun
HKU\S-1-5-20\SOFTWARE | Run : [Sidebar] - %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun
HKU\S-1-5-19\SOFTWARE | RunOnce : [mctadmin] - C:\Windows\System32\mctadmin.exe
HKU\S-1-5-20\SOFTWARE | RunOnce : [mctadmin] - C:\Windows\System32\mctadmin.exe
################## | Processus Stoppés |
Stoppé! C:\Program Files\AVAST Software\Avast\AvastSvc.exe (1168)
Stoppé! C:\Windows\System32\spoolsv.exe (1404)
Stoppé! C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe (1528)
Stoppé! C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe (1568)
Stoppé! C:\Program Files\Bonjour\mDNSResponder.exe (1632)
Stoppé! C:\Program Files (x86)\Packard Bell\Registration\GREGsvc.exe (1724)
Stoppé! C:\Program Files\Intel\iCLS Client\HeciServer.exe (1764)
Stoppé! C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe (1816)
Stoppé! C:\Program Files\Packard Bell\Packard Bell Updater\UpdaterService.exe (1852)
Stoppé! C:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPSVC.EXE (2284)
Stoppé! C:\Windows\System32\WUDFHost.exe (2588)
Stoppé! C:\Windows\system32\taskhost.exe (1204)
Stoppé! C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamscheduler.exe (3480)
Stoppé! C:\Windows\System32\igfxtray.exe (3600)
Stoppé! C:\Windows\System32\hkcmd.exe (3612)
Stoppé! C:\Windows\System32\igfxpers.exe (3620)
Stoppé! C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe (3716)
Stoppé! C:\Windows\system32\RunDll32.exe (3732)
Stoppé! C:\Program Files (x86)\Packard Bell\Hotkey Utility\HotkeyUtility.exe (3984)
Stoppé! C:\Program Files\AVAST Software\Avast\AvastUI.exe (4000)
Stoppé! C:\Program Files (x86)\HP\HP Software Update\hpwuschd2.exe (4016)
Stoppé! C:\Program Files (x86)\SweetIM\Communicator\SweetPacksUpdateManager.exe (4052)
Stoppé! C:\Program Files (x86)\iTunes\iTunesHelper.exe (4068)
Stoppé! C:\Vega5\EpsiService.exe (4088)
Stoppé! C:\Windows\system32\SearchIndexer.exe (3292)
Stoppé! C:\Program Files\iPod\bin\iPodService.exe (3840)
Stoppé! C:\Program Files\Windows Media Player\wmpnetwk.exe (2836)
Stoppé! C:\Windows\system32\DllHost.exe (4624)
Stoppé! C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE (5012)
Stoppé! C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe (4312)
Stoppé! C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe (3684)
Stoppé! C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe (2996)
Stoppé! C:\Program Files (x86)\Nero\Update\NASvc.exe (4736)
Stoppé! C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe (2412)
Stoppé! C:\Program Files\Internet Explorer\iexplore.exe (2432)
Stoppé! C:\Program Files (x86)\Internet Explorer\IEXPLORE.EXE (4640)
Stoppé! C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbarUser_32.exe (1872)
Stoppé! C:\Windows\system32\Macromed\Flash\FlashUtil64_11_7_700_224_ActiveX.exe (3872)
Stoppé! C:\Program Files (x86)\Internet Explorer\IEXPLORE.EXE (2368)
Stoppé! C:\Windows\system32\SearchProtocolHost.exe (5292)
Stoppé! C:\Windows\system32\taskhost.exe (5808)
################## | à‰léments infectieux |
(!) Fichiers temporaires supprimés.
################## | Registre |
################## | Mountpoints2 |
################## | Listing |
[22/11/2012 - 15:18:21 | SHD ] C:\$Recycle.Bin
[14/06/2013 - 20:40:29 | N | 0] C:\autoexec.bat
[29/06/2012 - 11:38:00 | D ] C:\book
[29/03/2012 - 13:46:52 | N | 8192] C:\BOOTSECT.BAK
[14/06/2013 - 21:38:43 | D ] C:\Config.Msi
[14/07/2009 - 07:08:56 | SHD ] C:\Documents and Settings
[18/04/2013 - 16:24:12 | D ] C:\Epsilog
[14/06/2013 - 21:38:43 | ASH | 3163365376] C:\hiberfil.sys
[29/06/2012 - 11:33:07 | D ] C:\Intel
[08/11/2012 - 10:38:26 | RHD ] C:\MSOCache
[07/11/2012 - 18:25:55 | D ] C:\OEM
[14/06/2013 - 21:38:46 | ASH | 4217823232] C:\pagefile.sys
[14/07/2009 - 05:20:08 | D ] C:\PerfLogs
[14/06/2013 - 21:45:15 | D ] C:\Program Files
[14/06/2013 - 21:44:53 | D ] C:\Program Files (x86)
[11/06/2013 - 14:40:15 | HD ] C:\ProgramData
[07/11/2012 - 18:23:56 | SHD ] C:\Recovery
[07/11/2012 - 19:10:08 | D ] C:\sesam
[14/06/2013 - 21:24:41 | SHD ] C:\System Volume Information
[14/06/2013 - 22:08:01 | D ] C:\UsbFix
[14/06/2013 - 22:08:08 | A | 8083] C:\UsbFix [Clean 1] LIONEL-PC.txt
[14/06/2013 - 21:52:45 | N | 7895] C:\UsbFix [Scan 1] LIONEL-PC.txt
[07/11/2012 - 18:24:03 | D ] C:\Users
[14/06/2013 - 21:39:21 | D ] C:\Vega5
[14/06/2013 - 21:39:57 | D ] C:\Vega5maj
[14/06/2013 - 21:39:25 | D ] C:\Windows
[07/11/2012 - 18:25:59 | SHD ] D:\$RECYCLE.BIN
[07/11/2012 - 19:51:25 | SHD ] D:\System Volume Information
[06/09/2012 - 19:12:26 | D ] G:\Vega5
[25/07/2011 - 19:13:58 | N | 4096] G:\._P1060793.JPG
[25/07/2011 - 19:14:00 | N | 4096] G:\._P1060796.JPG
[22/11/2009 - 14:51:14 | N | 4096] G:\._.Trashes
[22/11/2009 - 14:51:14 | HD ] G:\.Trashes
[22/11/2009 - 14:51:16 | D ] G:\.Spotlight-V100
[25/07/2011 - 19:14:02 | N | 4096] G:\._P1060798.JPG
[25/07/2011 - 19:14:04 | N | 4096] G:\._P1060799.JPG
[25/07/2011 - 19:14:06 | N | 4096] G:\._P1060801.JPG
[25/07/2011 - 19:14:08 | N | 4096] G:\._P1060802.JPG
[25/07/2011 - 19:14:10 | N | 4096] G:\._P1060803.JPG
[23/09/2010 - 20:14:58 | D ] G:\.TemporaryItems
[23/09/2010 - 20:14:58 | N | 4096] G:\._.TemporaryItems
[25/07/2011 - 19:14:12 | N | 4096] G:\._P1060804.JPG
[25/07/2011 - 19:14:14 | N | 4096] G:\._P1060805.JPG
[25/07/2011 - 19:14:16 | N | 4096] G:\._P1060807.JPG
[25/07/2011 - 19:14:18 | N | 4096] G:\._P1060810.JPG
[25/07/2011 - 19:14:18 | N | 4096] G:\._P1060816.JPG
[25/07/2011 - 19:14:20 | N | 4096] G:\._P1060818.JPG
[25/07/2011 - 19:14:22 | N | 4096] G:\._P1060819.JPG
[25/07/2011 - 19:14:22 | N | 4096] G:\._P1060822.JPG
[25/07/2011 - 19:14:24 | N | 4096] G:\._P1060824.JPG
[25/07/2011 - 19:14:26 | N | 4096] G:\._P1060826.JPG
[25/07/2011 - 19:14:26 | N | 4096] G:\._P1060830.jpg
[25/07/2011 - 19:14:28 | N | 4096] G:\._P1060834.jpg
[25/07/2011 - 19:14:30 | N | 4096] G:\._P1060835.jpg
[25/07/2011 - 19:14:30 | N | 4096] G:\._P1060836.JPG
[25/07/2011 - 19:14:32 | N | 4096] G:\._P1060837.JPG
[25/07/2011 - 19:14:32 | N | 4096] G:\._P1060841.JPG
[25/07/2011 - 19:14:34 | N | 4096] G:\._P1060845.JPG
[25/07/2011 - 19:14:36 | N | 4096] G:\._P1060850.JPG
[25/07/2011 - 19:14:36 | N | 4096] G:\._P1060856.JPG
[25/07/2011 - 19:14:38 | N | 4096] G:\._P1060862.JPG
[25/07/2011 - 19:14:40 | N | 4096] G:\._P1060864.JPG
[25/07/2011 - 19:14:40 | N | 4096] G:\._P1060866.jpg
[25/07/2011 - 19:14:42 | N | 4096] G:\._P1060873.JPG
[25/07/2011 - 19:14:44 | N | 4096] G:\._P1060876.JPG
[25/07/2011 - 19:14:44 | N | 4096] G:\._P1060878.JPG
[25/07/2011 - 19:14:46 | N | 4096] G:\._P1060880.JPG
[25/07/2011 - 19:14:46 | N | 4096] G:\._P1060881.JPG
[25/07/2011 - 19:14:48 | N | 4096] G:\._P1060884.jpg
[25/07/2011 - 19:14:48 | N | 4096] G:\._P1060890.JPG
[25/07/2011 - 19:14:50 | N | 4096] G:\._P1060895.jpg
[25/07/2011 - 19:14:50 | N | 4096] G:\._P1060899.JPG
[25/07/2011 - 19:14:52 | N | 4096] G:\._P1060902.jpg
[25/07/2011 - 19:14:54 | N | 4096] G:\._P1060792.JPG
################## | Vaccin |
C:\Autorun.inf -> Vaccin créé par UsbFix (El Desaparecido)
D:\Autorun.inf -> Vaccin créé par UsbFix (El Desaparecido)
G:\Autorun.inf -> Vaccin créé par UsbFix (El Desaparecido)
################## | E.O.F | https://sosvirus.org |