Voila le rapport,
############################## | UsbFix V 7.165 | [Suppression]
Utilisateur: Jean (Administrateur) # PC-DE-JEAN
Mis à jour le 20/02/2014 par El Desaparecido - Team SosVirus
Lancé à 18:24:15 | 21/02/2014
Site Web :
http://www.usbfix.net/
Changelog :
http://www.usbfix.net/maj/
Support :
http://www.sosvirus.net/
Upload Malware :
http://www.sosvirus.net/upload_malware.php
Contact :
http://www.usbfix.net/contact/
PC: PEGATRON CORPORATION (2A72h)
CPU: AMD Athlon(tm) Dual Core Processor 5000B
RAM - [Total : 1918 Mo| Free : 1122 Mo]
Bios: Phoenix Technologies, LTD
Boot: Normal boot
OS: Microsoft® Windows Vista™ Édition Familiale Basique (6.0.6002 32-Bit) Service Pack 2
WB: Windows Internet Explorer : 9.0.8112.16421
SC: Security Center [Enabled]
WU: Windows Update [Enabled]
AV: Microsoft Security Essentials [(!) Disabled | Updated]
AS: Windows Defender [(!) Disabled | (!) Outdated]
AS: Microsoft Security Essentials [(!) Disabled | Updated]
FW: Windows FireWall [(!) Disabled]
AS: Malwarebytes' Anti-Malware : 1.75.0001
C:\ (%systemdrive%) - Disque fixe # 282 Go (52 Go libre(s) - 18%) [] # NTFS
D:\ - Disque fixe # 14 Go (6 Go libre(s) - 42%) [HP_RECOVERY] # NTFS
E:\ - Disque fixe # 2 Go (2 Go libre(s) - 89%) [OS_TOOLS] # NTFS
F:\ - CD-ROM
G:\ - Disque fixe # 931 Go (547 Go libre(s) - 59%) [VERBATIM HD] # FAT32
################## | Processus Actif |
C:\Windows\system32\csrss.exe (ID: 560 |ParentID: 548)
C:\Windows\system32\wininit.exe (ID: 624 |ParentID: 548)
C:\Windows\system32\csrss.exe (ID: 632 |ParentID: 616)
C:\Windows\system32\services.exe (ID: 668 |ParentID: 624)
C:\Windows\system32\lsass.exe (ID: 684 |ParentID: 624)
C:\Windows\system32\lsm.exe (ID: 692 |ParentID: 624)
C:\Windows\system32\winlogon.exe (ID: 764 |ParentID: 616)
C:\Windows\system32\svchost.exe (ID: 864 |ParentID: 668)
C:\Windows\system32\svchost.exe (ID: 936 |ParentID: 668)
c:\Program Files\Microsoft Security Client\MsMpEng.exe (ID: 1004 |ParentID: 668)
C:\Windows\System32\svchost.exe (ID: 1172 |ParentID: 668)
C:\Windows\System32\svchost.exe (ID: 1212 |ParentID: 668)
C:\Windows\system32\svchost.exe (ID: 1228 |ParentID: 668)
C:\Windows\system32\svchost.exe (ID: 1324 |ParentID: 668)
C:\Windows\system32\SLsvc.exe (ID: 1348 |ParentID: 668)
C:\Windows\system32\svchost.exe (ID: 1372 |ParentID: 668)
C:\Windows\system32\svchost.exe (ID: 1608 |ParentID: 668)
C:\Windows\System32\spoolsv.exe (ID: 1776 |ParentID: 668)
C:\Windows\system32\taskeng.exe (ID: 1784 |ParentID: 1228)
C:\Windows\system32\svchost.exe (ID: 1816 |ParentID: 668)
C:\Windows\system32\Dwm.exe (ID: 552 |ParentID: 1212)
C:\Windows\system32\taskeng.exe (ID: 856 |ParentID: 1228)
C:\Windows\Explorer.EXE (ID: 1488 |ParentID: 568)
C:\Windows\system32\runonce.exe (ID: 1824 |ParentID: 1488)
C:\Program Files\Common Files\EPSON\EBAPI\eEBSVC.exe (ID: 2004 |ParentID: 668)
C:\Program Files\Common Files\Adobe\ARM\1.0\armsvc.exe (ID: 1088 |ParentID: 668)
C:\Program Files\Common Files\InterVideo\RegMgr\iviRegMgr.exe (ID: 924 |ParentID: 668)
C:\Program Files\ma-config.com\MaConfigAgent.exe (ID: 2092 |ParentID: 668)
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE (ID: 2168 |ParentID: 668)
C:\Program Files\WinZip Driver Updater\winzipdu.exe (ID: 2184 |ParentID: 856)
C:\Windows\system32\PnkBstrA.exe (ID: 2216 |ParentID: 668)
C:\Windows\system32\svchost.exe (ID: 2232 |ParentID: 668)
C:\Program Files\Common Files\Protexis\License Service\PsiService_2.exe (ID: 2248 |ParentID: 668)
C:\Windows\system32\svchost.exe (ID: 2444 |ParentID: 668)
C:\Program Files\TeamViewer\Version6\TeamViewer_Service.exe (ID: 2464 |ParentID: 668)
C:\Windows\system32\UTSCSI.EXE (ID: 2540 |ParentID: 668)
C:\Windows\System32\svchost.exe (ID: 2556 |ParentID: 668)
C:\Program Files\WinZip System Utilities Suite\WINZIPSSDefragSrv.exe (ID: 2588 |ParentID: 668)
C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE (ID: 2652 |ParentID: 668)
C:\Windows\system32\SearchIndexer.exe (ID: 2684 |ParentID: 668)
C:\Program Files\Spybot - Search Destroy\SDWinSec.exe (ID: 2800 |ParentID: 668)
C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe (ID: 2892 |ParentID: 2652)
C:\Windows\servicing\TrustedInstaller.exe (ID: 3200 |ParentID: 668)
C:\Windows\system32\SearchProtocolHost.exe (ID: 2924 |ParentID: 2684)
C:\Windows\system32\SearchFilterHost.exe (ID: 2176 |ParentID: 2684)
C:\Windows\system32\svchost.exe (ID: 3352 |ParentID: 668)
C:\Program Files\Windows Media Player\wmpnetwk.exe (ID: 3024 |ParentID: 668)
C:\Windows\system32\wbem\wmiprvse.exe (ID: 3400 |ParentID: 864)
################## | Regedit Run |
04 - HKCU\..\Run : [Sidebar] C:\Program Files\Windows Sidebar\sidebar.exe /autoRun
04 - HKCU\..\Run : []
04 - HKCU\..\Run : [WMPNSCFG] C:\Program Files\Windows Media Player\WMPNSCFG.exe
04 - HKCU\..\Run : [KCleaner] C:\Program Files\KC Softwares\KCleaner\KCleaner.exe /minimized
04 - HKCU\..\Run : [Google Update] "C:\Users\Jean\AppData\Local\Google\Update\GoogleUpdate.exe" /c
04 - HKLM\..\Run : [Windows Defender] %ProgramFiles%\Windows Defender\MSASCui.exe -hide
04 - HKLM\..\Run : [Adobe ARM] "C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
04 - HKLM\..\Run : [MSC] "c:\Program Files\Microsoft Security Client\msseces.exe" -hide -runkey
04 - HKU\S-1-5-19\..\Run : [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem
04 - HKU\S-1-5-19\..\Run : [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCenter
04 - HKU\S-1-5-20\..\Run : [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem
04 - HKU\S-1-5-20\..\Run : [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCenter
04 - HKU\S-1-5-21-1254181848-837224991-1217073606-1001\..\Run : [Sidebar] C:\Program Files\Windows Sidebar\sidebar.exe /autoRun
04 - HKU\S-1-5-21-1254181848-837224991-1217073606-1001\..\Run : []
04 - HKU\S-1-5-21-1254181848-837224991-1217073606-1001\..\Run : [WMPNSCFG] C:\Program Files\Windows Media Player\WMPNSCFG.exe
04 - HKU\S-1-5-21-1254181848-837224991-1217073606-1001\..\Run : [KCleaner] C:\Program Files\KC Softwares\KCleaner\KCleaner.exe /minimized
04 - HKU\S-1-5-21-1254181848-837224991-1217073606-1001\..\Run : [Google Update] "C:\Users\Jean\AppData\Local\Google\Update\GoogleUpdate.exe" /c
################## | Recherche générique |
Supprimé! G:\RECYCLER\S-1-5-21-1482476501-3352491937-682996330-1013\windows.exe
Supprimé! G:\RECYCLER\S-1-5-21-1482476501-3352491937-682996330-1013
(!) Fichiers temporaires supprimés.
################## | Registre |
Réparé ! HKLM\Software\Microsoft\Windows\CurrentVersion\Policies\System|EnableLUA - 1
Réparé ! HKLM\Software\Microsoft\Windows\CurrentVersion\Policies\System|ConsentPromptBehaviorAdmin - 5
Supprimé! HKU\S-1-5-21-1254181848-837224991-1217073606-1001\Software\.\.\.\.\Mountpoints2\{117820e0-cc57-11de-b47c-00237dc8eead}
Supprimé! HKU\S-1-5-21-1254181848-837224991-1217073606-1001\Software\.\.\.\.\Mountpoints2\{1eda04f3-f480-11df-be67-00237dc8eead}
Supprimé! HKU\S-1-5-21-1254181848-837224991-1217073606-1001\Software\.\.\.\.\Mountpoints2\{645e4203-87d5-11e1-92b6-00237dc8eead}
Supprimé! HKU\S-1-5-21-1254181848-837224991-1217073606-1001\Software\.\.\.\.\Mountpoints2\{fc6b9648-7728-11de-93cb-806e6f6e6963}
################## | Listing |
[07/09/2012 - 09:36:43 | SHD] - C:\$RECYCLE.BIN
[13/04/2012 - 00:01:23 | D] - C:\3fc60912009a8b03421cd123298e1bf8
[12/02/2014 - 12:59:45 | D] - C:\AdwCleaner
[22/10/2009 - 17:20:32 | SHD] - C:\boot
[11/04/2009 - 07:36:36 | RASH | 325 Ko] - C:\bootmgr
[15/03/2008 - 00:50:16 | RAS | 8 Ko] - C:\BOOTSECT.BAK
[02/11/2006 - 13:59:44 | SHD] - C:\Documents and Settings
[12/10/2009 - 14:04:13 | D] - C:\drivers
[05/02/2014 - 21:05:05 | D] - C:\FFOutput
[03/11/2009 - 12:24:05 | D] - C:\found.000
[14/06/2011 - 09:49:51 | D] - C:\found.001
[02/12/2011 - 17:57:02 | D] - C:\found.002
[19/04/2012 - 06:20:11 | D] - C:\found.003
[06/07/2012 - 09:01:23 | D] - C:\found.004
[31/08/2012 - 14:01:04 | D] - C:\found.005
[08/12/2012 - 13:42:51 | D] - C:\found.006
[23/07/2009 - 02:51:32 | D] - C:\fslrdr
[21/02/2014 - 18:20:34 | ASH | 1964536 Ko] - C:\hiberfil.sys
[23/07/2009 - 02:57:54 | D] - C:\hp
[05/04/2010 - 22:47:09 | RASH | 0 Ko] - C:\IO.SYS
[05/04/2010 - 22:47:09 | RASH | 0 Ko] - C:\MSDOS.SYS
[11/10/2009 - 13:29:15 | RHD] - C:\MSOCache
[22/05/2011 - 15:36:59 | D] - C:\OUT_MEDIA_FILES
[21/02/2014 - 18:20:32 | ASH | 2270992 Ko] - C:\pagefile.sys
[21/01/2008 - 03:43:50 | D] - C:\PerfLogs
[13/02/2014 - 16:19:08 | D] - C:\Program Files
[19/02/2014 - 09:36:09 | HD] - C:\ProgramData
[16/02/2014 - 13:51:25 | D] - C:\Shortcut_Module
[12/02/2014 - 19:55:54 | N | 4 Ko | 671B071DBB82930652C5EDD730E6A3A5] - C:\Shortcut_Module_12_02_2014_19_55_54.txt
[16/02/2014 - 14:24:46 | N | 15 Ko | 3101DA37BBCD92E2F66144C7B172A333] - C:\Shortcut_Module_16_02_2014_14_24_46.txt
[11/10/2009 - 08:39:12 | D] - C:\SWSetup
[23/07/2009 - 02:57:08 | D] - C:\System Recovery
[21/02/2014 - 14:45:11 | SHD] - C:\System Volume Information
[11/10/2009 - 14:28:11 | D] - C:\system.sav
[19/03/2010 - 12:05:15 | D] - C:\temp
[21/02/2014 - 18:17:58 | D] - C:\UsbFix
[21/02/2014 - 18:24:53 | A | 9 Ko | D90314A0D94E03E81B86AD74191F7788] - C:\UsbFix [Clean 3] PC-DE-JEAN.txt
[11/10/2009 - 13:55:47 | D] - C:\Users
[19/02/2014 - 09:34:51 | D] - C:\windows
[11/10/2009 - 14:28:58 | SHD] - D:\$RECYCLE.BIN
[23/07/2009 - 02:57:23 | RSHD] - D:\boot
[23/07/2009 - 02:56:17 | SH | 426 Ko] - D:\bootmgr
[23/07/2009 - 02:56:17 | SH | 7 Ko] - D:\Desktop.ini
[23/07/2009 - 02:57:08 | D] - D:\EFI
[23/07/2009 - 02:56:18 | N | 8 Ko] - D:\Folder.htt
[03/11/2005 - 11:29:50 | N | 0 Ko] - D:\HP_RECOVERY
[23/07/2009 - 02:56:18 | N | 77 Ko | EDA83A93E1B27CA36E88E1C6B9FA6C95] - D:\Info.exe
[23/07/2009 - 03:16:01 | D] - D:\ISOS
[11/10/2009 - 14:28:32 | N | 1 Ko] - D:\MASTER.LOG
[23/07/2009 - 02:56:18 | N | 0 Ko] - D:\NTFS
[23/07/2009 - 02:57:08 | RSHD] - D:\PRELOAD
[23/07/2009 - 03:07:36 | D] - D:\Program Files
[23/07/2009 - 02:57:08 | RSHD] - D:\ProgramData
[23/07/2009 - 02:56:21 | SH | 178 Ko] - D:\protect.arabic
[23/07/2009 - 02:56:21 | N | 177 Ko] - D:\protect.basque
[23/07/2009 - 02:56:21 | SH | 178 Ko] - D:\protect.bulgarian
[23/07/2009 - 02:56:21 | SH | 177 Ko] - D:\protect.catalan
[23/07/2009 - 02:56:21 | SH | 178 Ko] - D:\protect.chinese hong kong
[23/07/2009 - 02:56:21 | SH | 178 Ko] - D:\protect.chinese simplified
[23/07/2009 - 02:56:21 | SH | 178 Ko] - D:\protect.chinese traditional
[23/07/2009 - 02:56:21 | N | 178 Ko] - D:\protect.croatian
[23/07/2009 - 02:56:21 | SH | 177 Ko] - D:\protect.czech
[23/07/2009 - 02:56:21 | SH | 177 Ko] - D:\protect.danish
[23/07/2009 - 02:56:21 | SH | 177 Ko] - D:\protect.dutch
[23/07/2009 - 02:56:21 | SH | 177 Ko] - D:\protect.ed
[23/07/2009 - 02:56:21 | SH | 177 Ko] - D:\protect.english
[23/07/2009 - 02:56:21 | N | 179 Ko] - D:\protect.estonian
[23/07/2009 - 02:56:21 | SH | 177 Ko] - D:\protect.finnish
[23/07/2009 - 02:56:21 | SH | 177 Ko] - D:\protect.french
[23/07/2009 - 02:56:21 | N | 177 Ko] - D:\protect.galician
[23/07/2009 - 02:56:21 | SH | 177 Ko] - D:\protect.german
[23/07/2009 - 02:56:21 | SH | 178 Ko] - D:\protect.greek
[23/07/2009 - 02:56:21 | SH | 178 Ko] - D:\protect.hebrew
[23/07/2009 - 02:56:21 | N | 177 Ko] - D:\protect.hungarian
[23/07/2009 - 02:56:21 | SH | 177 Ko] - D:\protect.italian
[23/07/2009 - 02:56:21 | SH | 178 Ko] - D:\protect.japanese
[23/07/2009 - 02:56:21 | SH | 178 Ko] - D:\protect.korean
[23/07/2009 - 02:56:21 | N | 178 Ko] - D:\protect.latvian
[23/07/2009 - 02:56:21 | N | 178 Ko] - D:\protect.lithuanian
[23/07/2009 - 02:56:21 | SH | 177 Ko] - D:\protect.norwegian
[23/07/2009 - 02:56:22 | SH | 177 Ko] - D:\protect.polish
[23/07/2009 - 02:56:22 | SH | 177 Ko] - D:\protect.portuguese
[23/07/2009 - 02:56:22 | SH | 178 Ko] - D:\protect.portuguese brazilian
[23/07/2009 - 02:56:22 | SH | 178 Ko] - D:\protect.romanian
[23/07/2009 - 02:56:22 | SH | 207 Ko] - D:\protect.russian
[23/07/2009 - 02:56:22 | SH | 178 Ko] - D:\protect.serbian latin
[23/07/2009 - 02:56:22 | SH | 178 Ko] - D:\protect.slovak
[23/07/2009 - 02:56:22 | N | 178 Ko] - D:\protect.slovenian
[23/07/2009 - 02:56:22 | SH | 177 Ko] - D:\protect.spanish
[23/07/2009 - 02:56:22 | SH | 177 Ko] - D:\protect.swedish
[23/07/2009 - 02:56:22 | N | 178 Ko] - D:\protect.thai
[23/07/2009 - 02:56:22 | SH | 178 Ko] - D:\protect.turkish
[23/07/2009 - 02:56:22 | N | 177 Ko] - D:\protect.ukranian
[23/07/2009 - 02:57:08 | RD] - D:\RECOVERY
[08/10/2008 - 13:49:42 | N | 0 Ko] - D:\renamewinpeshl.bat
[23/07/2009 - 02:57:16 | RSHD] - D:\sources
[23/07/2009 - 02:56:23 | N | 0 Ko] - D:\st_log.ini
[23/07/2009 - 02:57:08 | D] - D:\swsetup
[22/07/2009 - 23:48:04 | SHD] - D:\System Volume Information
[23/07/2009 - 02:57:08 | D] - D:\Users
[23/07/2009 - 03:06:20 | D] - D:\Windows
[06/06/2011 - 17:56:05 | N | 8 Ko] - D:\Winrelauncher.exe.LOG
[11/10/2009 - 14:28:58 | SHD] - E:\$RECYCLE.BIN
[03/01/2008 - 13:23:42 | N | 3096 Ko] - E:\boot.sdi
[23/07/2009 - 03:16:35 | N | 0 Ko] - E:\HP_WINRE
[23/07/2009 - 02:36:15 | SHD] - E:\System Volume Information
[11/10/2009 - 13:56:19 | N | 192820 Ko] - E:\WINRE.WIM
[05/02/2014 - 21:18:22 | HD] - G:\.Trashes
[06/02/2014 - 18:02:10 | HD] - G:\.fseventsd
[05/02/2014 - 21:18:24 | HD] - G:\.Spotlight-V100
[01/02/2014 - 15:57:20 | N | 92614 Ko] - G:\Studio D A1.pdf
[09/01/2014 - 16:26:40 | SHD] - G:\$RECYCLE.BIN
[09/01/2014 - 18:26:10 | D] - G:\Nouveau dossier
[20/08/2012 - 13:08:56 | D] - G:\Photo Steph
[01/02/2014 - 14:39:08 | RSHD] - G:\RECYCLER
[01/02/2014 - 14:39:10 | SHD] - G:\System Volume Information
[01/02/2014 - 14:42:32 | D] - G:\Olivier
[01/02/2014 - 14:50:58 | D] - G:\Recycled
[02/02/2014 - 14:51:26 | D] - G:\All
[02/02/2014 - 14:52:38 | D] - G:\Musiques
[02/02/2014 - 14:53:44 | D] - G:\Pictures
[03/08/2012 - 21:17:22 | D] - G:\Documents
[06/02/2014 - 17:57:02 | D] - G:\Logiciels Windows
[04/02/2014 - 20:05:58 | D] - G:\studio d(Allemand)
[14/11/2013 - 19:30:02 | D] - G:\Clé usb
[06/02/2014 - 22:22:06 | N | 94 Ko] - G:\Courrier révision loyer 2014.pdf
[07/02/2014 - 12:52:20 | N | 94 Ko] - G:\montage Jeanne c.jpg
[07/02/2014 - 12:54:36 | N | 313 Ko] - G:\JOUR 2 w leçon de récitation (23).JPG
[07/02/2014 - 19:37:00 | D] - G:\Cuisine
[06/02/2014 - 16:39:26 | D] - G:\Photo C3
[26/09/2012 - 19:08:08 | D] - G:\Thème 2010
################## | Vaccin |
D:\Autorun.inf - Vaccin créé par UsbFix (El Desaparecido)
E:\Autorun.inf - Vaccin créé par UsbFix (El Desaparecido)
G:\Autorun.inf - Vaccin créé par UsbFix (El Desaparecido)
################## | E.O.F |
http://www.usbfix.net/ -
http://www.sosvirus.net |