Voici le rapport :
############################## | UsbFix V 7.170 | [Nettoyage]
Utilisateur: Jeux (Administrateur) # WIN-QH5JL4FD08P
Mis à jour le 13/05/2014 par El Desaparecido - SosVirus
Lancé à 13:54:55 | 15/05/2014
Site Web :
http://www.usbfix.net/
Changelog :
http://www.usbfix.net/maj/
Assistance :
http://www.sosvirus.net/forum-virus-securite.html
Upload Malware :
http://www.sosvirus.net/upload_malware.php
Contact :
http://www.usbfix.net/contact/
PC: TOSHIBA (Portable PC)
CPU: Intel(R) Celeron(R) CPU 900 @ 2.20GHz
RAM - [Total : 1916 Mo| Free : 772 Mo]
Bios: INSYDE
Boot: Normal boot
OS: Microsoft Windows 7 Professionnel (6.1.7601 64-Bit) Service Pack 1
WB: Windows Internet Explorer : 11.0.9600.17105
WB: Mozilla Firefox : 29.0.1
SC: Security Center [Enabled]
WU: Windows Update [Enabled]
AV: Microsoft Security Essentials [(!) Disabled | Updated]
AS: Windows Defender [(!) Disabled | (!) Outdated]
AS: Microsoft Security Essentials [(!) Disabled | Updated]
FW: Windows FireWall [Enabled]
C:\ (%SystemDrive%) - Disque fixe # 116 Go (18 Go libre(s) - 16%) [WINDOWS] # NTFS
D:\ - Disque fixe # 116 Go (80 Go libre(s) - 69%) [Data] # NTFS
E:\ - CD-ROM
F:\ - CD-ROM
G:\ - CD-ROM
H:\ - CD-ROM
I:\ - CD-ROM
J:\ - Disque amovible # 7 Go (7 Go libre(s) - 95%) [] # FAT32
################## | Processus Stoppés |
C:\Windows\System32\spoolsv.exe (ID: 1416|ParentID: 560|Système)
C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe (ID: 1552|ParentID: 560|Système)
C:\Program Files\Common Files\Native Instruments\Hardware\NIHardwareService.exe (ID: 1644|ParentID: 560|Système)
C:\Program Files (x86)\Microsoft Application Virtualization Client\sftvsa.exe (ID: 1864|ParentID: 560|Système)
C:\Windows\System32\TODDSrv.exe (ID: 2012|ParentID: 560|Système)
C:\Program Files\TOSHIBA\Power Saver\TosCoSrv.exe (ID: 2040|ParentID: 560|Système)
C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE (ID: 1632|ParentID: 560|Système)
C:\Program Files (x86)\Microsoft Application Virtualization Client\sftlist.exe (ID: 1988|ParentID: 560|Système)
C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVCM.EXE (ID: 2068|ParentID: 1632|Système)
C:\Program Files (x86)\Common Files\microsoft shared\Virtualization Handler\CVHSVC.EXE (ID: 2308|ParentID: 560|Système)
C:\Windows\System32\alg.exe (ID: 2388|ParentID: 560|SERVICE LOCAL)
C:\Windows\System32\taskhost.exe (ID: 2888|ParentID: 560|Jeux)
C:\Windows\explorer.exe (ID: 2972|ParentID: 2932|Jeux)
C:\Program Files\CONEXANT\cAudioFilterAgent\cAudioFilterAgent64.exe (ID: 2620|ParentID: 2972|Jeux)
C:\Program Files\TOSHIBA\Power Saver\TPwrMain.exe (ID: 2812|ParentID: 2972|Jeux)
C:\Program Files\TOSHIBA\SmoothView\SmoothView.exe (ID: 2820|ParentID: 2972|Jeux)
C:\Program Files\TOSHIBA\FlashCards\TCrdMain.exe (ID: 2804|ParentID: 2972|Jeux)
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe (ID: 2916|ParentID: 2972|Jeux)
C:\Program Files\Synaptics\SynTP\SynTPHelper.exe (ID: 2468|ParentID: 2916|Jeux)
C:\Program Files\TOSHIBA\BulletinBoard\TosNcCore.exe (ID: 3076|ParentID: 2972|Jeux)
C:\Program Files\TOSHIBA\ReelTime\TosReelTimeMonitor.exe (ID: 3096|ParentID: 2972|Jeux)
C:\Program Files\Microsoft Security Client\msseces.exe (ID: 3136|ParentID: 2972|Jeux)
C:\Windows\System32\igfxtray.exe (ID: 3148|ParentID: 2972|Jeux)
C:\Windows\System32\hkcmd.exe (ID: 3184|ParentID: 2972|Jeux)
C:\Windows\System32\igfxpers.exe (ID: 3196|ParentID: 2972|Jeux)
C:\Program Files (x86)\RocketDock\RocketDock.exe (ID: 3216|ParentID: 2972|Jeux)
C:\Windows\System32\igfxsrvc.exe (ID: 3312|ParentID: 716|Jeux)
C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe (ID: 3464|ParentID: 3260|Jeux)
C:\Windows\System32\igfxext.exe (ID: 3656|ParentID: 716|Jeux)
C:\Windows\System32\SearchIndexer.exe (ID: 3696|ParentID: 560|Système)
C:\Program Files\TOSHIBA\TOSHIBA HDD SSD Alert\TosSmartSrv.exe (ID: 1656|ParentID: 560|Système)
C:\Program Files\TOSHIBA\TOSHIBA HDD SSD Alert\TosSENotify.exe (ID: 2204|ParentID: 3000|Jeux)
C:\Windows\System32\wuauclt.exe (ID: 1120|ParentID: 432|Jeux)
C:\Windows\System32\WUDFHost.exe (ID: 3500|ParentID: 100|SERVICE LOCAL)
################## | Autorun |
################## | Recherche générique |
Supprimé! J:\syncguid.dat
Supprimé! J:\Recycler\S-5-3-42-2819952290-8240758988-879315005-3665
(!) Fichiers temporaires supprimés.
################## | Registre |
Supprimé! HKU\S-1-5-21-904385973-1298194129-983972449-1004\Software\.\.\.\.\Mountpoints2\{200c0e52-f326-11df-a846-806e6f6e6963}
Supprimé! HKU\S-1-5-21-904385973-1298194129-983972449-1004\Software\.\.\.\.\Mountpoints2\{4dcd6075-5313-11e0-ab0a-00266c825305}
Supprimé! HKU\S-1-5-21-904385973-1298194129-983972449-1004\Software\.\.\.\.\Mountpoints2\{728ac511-994c-11e3-815d-00266c825305}
################## | Regedit Run |
F2 - HKLM\..\Winlogon : [Shell] explorer.exe
F2 - [x64] HKLM\..\Winlogon : [Shell] explorer.exe
F2 - HKLM\..\Winlogon : [Userinit] userinit.exe,
F2 - [x64] HKLM\..\Winlogon : [Userinit] C:\Windows\system32\userinit.exe,
04 - HKCU\..\Run : [RocketDock] "C:\Program Files (x86)\RocketDock\RocketDock.exe"
04 - HKLM\..\Run : [TWebCamera] "C:\Program Files (x86)\TOSHIBA\TOSHIBA Web Camera Application\TWebCamera.exe" autorun
04 - HKLM\..\Run : [Adobe ARM] "C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
04 - HKLM\..\Run : [SunJavaUpdateSched] "C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe"
04 - [x64] HKLM\..\Run : [cAudioFilterAgent] C:\Program Files\Conexant\cAudioFilterAgent\cAudioFilterAgent64.exe
04 - [x64] HKLM\..\Run : [SmartAudio] C:\Program Files\CONEXANT\SAII\SAIICpl.exe /t
04 - [x64] HKLM\..\Run : [TPwrMain] %ProgramFiles%\TOSHIBA\Power Saver\TPwrMain.EXE
04 - [x64] HKLM\..\Run : [SmoothView] %ProgramFiles%\Toshiba\SmoothView\SmoothView.exe
04 - [x64] HKLM\..\Run : [00TCrdMain] %ProgramFiles%\TOSHIBA\FlashCards\TCrdMain.exe
04 - [x64] HKLM\..\Run : [SynTPEnh] %ProgramFiles%\Synaptics\SynTP\SynTPEnh.exe
04 - [x64] HKLM\..\Run : [TosSENotify] C:\Program Files\TOSHIBA\TOSHIBA HDD SSD Alert\TosWaitSrv.exe
04 - [x64] HKLM\..\Run : [TosVolRegulator] C:\Program Files\TOSHIBA\TosVolRegulator\TosVolRegulator.exe
04 - [x64] HKLM\..\Run : [TosNC] %ProgramFiles%\Toshiba\BulletinBoard\TosNcCore.exe
04 - [x64] HKLM\..\Run : [TosReelTimeMonitor] %ProgramFiles%\TOSHIBA\ReelTime\TosReelTimeMonitor.exe
04 - [x64] HKLM\..\Run : [MSC] "C:\Program Files\Microsoft Security Client\msseces.exe" -hide -runkey
04 - [x64] HKLM\..\Run : [IgfxTray] C:\Windows\system32\igfxtray.exe
04 - [x64] HKLM\..\Run : [HotKeysCmds] C:\Windows\system32\hkcmd.exe
04 - [x64] HKLM\..\Run : [Persistence] C:\Windows\system32\igfxpers.exe
04 - HKU\S-1-5-19\..\Run : [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun
04 - HKU\S-1-5-20\..\Run : [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun
04 - HKU\S-1-5-21-904385973-1298194129-983972449-1004\..\Run : [RocketDock] "C:\Program Files (x86)\RocketDock\RocketDock.exe"
04 - HKU\S-1-5-19\..\RunOnce : [mctadmin] C:\Windows\System32\mctadmin.exe
04 - HKU\S-1-5-20\..\RunOnce : [mctadmin] C:\Windows\System32\mctadmin.exe
04 - HKU\S-1-5-18\..\RunOnce : [SPReview] "C:\Windows\System32\SPReview\SPReview.exe" /sp:1 /errorfwlink:"
http://go.microsoft.com/fwlink/?LinkID=122915" /build:7601
################## | C:\ %SystemDrive% - Disque Fixe (NTFS) |
[28/07/2010 - 11:31:03 | N | 0 Ko] - C:\SWSTAMP.TXT
[08/10/2010 - 10:19:17 | N | 0 Ko] - C:\Version.txt
[02/05/2014 - 21:07:30 | N | 81 Ko] - C:\Shortcut_Module_02_05_2014_21_07_30.txt
[15/05/2014 - 12:57:35 | ASH | 1471468 Ko] - C:\hiberfil.sys
[15/05/2014 - 12:57:41 | ASH | 1961960 Ko] - C:\pagefile.sys
[20/03/2011 - 20:02:50 | N | 8 Ko] - C:\wubildr.mbr
[13/08/2012 - 02:20:14 | N | 8 Ko] - C:\GDIPFONTCACHEV1.DAT
[13/06/2013 - 21:32:23 | SHD] - C:\$RECYCLE.BIN
[02/05/2014 - 15:56:59 | N | 1 Ko] - C:\PhysicalDisk0_MBR.bin
[19/10/2013 - 23:08:03 | D] - C:\found.002
[09/10/2011 - 11:08:15 | D] - C:\found.001
[19/10/2013 - 23:08:03 | D] - C:\found.000
[14/07/2009 - 05:20:08 | D] - C:\PerfLogs
[14/07/2009 - 07:08:56 | SHD] - C:\Documents and Settings
[28/07/2010 - 10:58:44 | D] - C:\Toshiba
[02/10/2010 - 11:43:02 | D] - C:\CRMP
[20/03/2011 - 20:02:50 | N | 114 Ko] - C:\wubildr
[09/07/2013 - 12:44:44 | D] - C:\Riot Games
[22/01/2014 - 15:17:50 | D] - C:\Intel
[08/03/2014 - 00:21:41 | D] - C:\Users
[27/03/2014 - 04:01:14 | D] - C:\Windows
[01/05/2014 - 18:32:59 | D] - C:\Program Files
[02/05/2014 - 21:06:59 | D] - C:\Shortcut_Module
[06/05/2014 - 14:52:08 | D] - C:\AdwCleaner
[07/05/2014 - 16:44:03 | HD] - C:\ProgramData
[10/05/2014 - 19:30:41 | D] - C:\Program Files (x86)
[13/05/2014 - 11:20:48 | SHD] - C:\System Volume Information
[15/05/2014 - 13:52:29 | D] - C:\UsbFix
################## | D:\ - Disque Fixe (NTFS) |
[26/10/2013 - 00:33:28 | D] - D:\msdownld.tmp
[13/08/2012 - 02:19:32 | SHD] - D:\$RECYCLE.BIN
[18/11/2010 - 17:12:18 | SHD] - D:\System Volume Information
[20/03/2011 - 20:01:53 | D] - D:\ubuntu
[27/06/2011 - 03:02:09 | D] - D:\707c50c7aaaffd9a31
[19/09/2011 - 23:55:51 | D] - D:\6c44696615db1b2f07c74aa22e
[27/05/2012 - 03:01:22 | D] - D:\fbf7f744c8153b77d6b8ba43
[29/05/2012 - 19:00:53 | D] - D:\4fe79babbc8ba34d7010087fe78302f4
[30/06/2013 - 00:16:53 | D] - D:\0b18b5688c3bb31d8775c6eb
[11/07/2013 - 03:36:19 | D] - D:\0231b643d6587ae563adad
[02/10/2013 - 13:06:02 | D] - D:\Photofiltre
[04/10/2013 - 13:33:20 | D] - D:\VLC
[30/04/2014 - 22:40:48 | D] - D:\Program Files (x86)
[30/04/2014 - 23:01:30 | D] - D:\Films
[30/04/2014 - 23:04:23 | D] - D:\Musiques
[02/05/2014 - 19:24:50 | D] - D:\Steam
[13/05/2014 - 18:02:54 | D] - D:\CHATONNE
################## | J:\ - Disque USB (FAT32) |
[02/02/2013 - 13:40:02 | N | 0 Ko] - J:\_disk_id.pod
[05/05/2013 - 20:04:30 | D] - J:\FOUND.000
[02/02/2012 - 13:33:38 | D] - J:\PRIVATE
[16/05/2012 - 21:11:58 | D] - J:\MISC
[16/05/2012 - 21:11:58 | D] - J:\DCIM
[17/03/2013 - 17:58:22 | RSHD] - J:\RECYCLER
################## | Vaccin |
D:\Autorun.inf - Vaccin créé par UsbFix (El Desaparecido)
J:\Autorun.inf - Vaccin créé par UsbFix (El Desaparecido)
################## | E.O.F | http://www.sosvirus.net/ | http://www.usbfix.net/ |