Bonsoir,
Voici le rapport d'USBFix:
############################## | UsbFix V 7.171 | [Nettoyage]
Utilisateur: rm (Administrateur) # RM-PC
Mis à jour le 09/06/2014 par El Desaparecido - SosVirus
Lancé à 17:45:26 | 15/06/2014
Site Web :
http://www.usbfix.net/
Changelog :
http://www.usbfix.net/maj/
Assistance :
http://www.sosvirus.net/forum-virus-securite.html
Upload Malware :
http://www.sosvirus.net/upload_malware.php
Contact :
http://www.usbfix.net/contact/
PC: PEGATRON CORPORATION (EVANS)
CPU: Pentium(R) Dual-Core CPU E5300 @ 2.60GHz
RAM - [Total : 4095 Mo| Free : 2215 Mo]
Bios: American Megatrends Inc.
Boot: Normal boot
OS: Microsoft Windows 7 Édition Familiale Premium (6.1.7601 64-Bit) Service Pack 1
WB: Windows Internet Explorer : 11.0.9600.17126
SC: Security Center [Enabled]
WU: Windows Update [Enabled]
AV: Microsoft Security Essentials [Enabled | Updated]
AS: Windows Defender [(!) Disabled | Updated]
AS: Microsoft Security Essentials [Enabled | Updated]
FW: Windows FireWall [(!) Disabled]
C:\ (%SystemDrive%) - Disque fixe # 452 Go (377 Go libre(s) - 83%) [HP] # NTFS
D:\ - Disque fixe # 14 Go (14 Go libre(s) - 99%) [FACTORY_IMAGE] # NTFS
E:\ - CD-ROM
F:\ - Disque amovible # 2 Go (472 Mo libre(s) - 24%) [z-PEN] # FAT
K:\ - Disque amovible # 4 Go (3 Go libre(s) - 90%) [] # FAT32
################## | Processus Stoppés |
C:\Windows\System32\nvvsvc.exe (ID: 764|ParentID: 508)
C:\Program Files\Tablet\Pen\Pen_TouchService.exe (ID: 1096|ParentID: 508|Système)
C:\Windows\System32\nvvsvc.exe (ID: 1184|ParentID: 764|Système)
C:\Windows\System32\wisptis.exe (ID: 1216|ParentID: 1020|Système)
C:\Windows\System32\spoolsv.exe (ID: 1460|ParentID: 508|Système)
C:\Program Files (x86)\Adobe\Elements Organizer 8.0\PhotoshopElementsFileAgent.exe (ID: 1588|ParentID: 508|Système)
C:\Windows\System32\taskhost.exe (ID: 1636|ParentID: 508|rm)
C:\Windows\System32\wisptis.exe (ID: 1660|ParentID: 1020|rm)
C:\Program Files\Common Files\Microsoft Shared\ink\TabTip.exe (ID: 1668|ParentID: 1020|rm)
C:\Program Files\Tablet\Pen\Pen_TouchUser.exe (ID: 1736|ParentID: 1096|rm)
C:\Windows\explorer.exe (ID: 1916|ParentID: 1812|rm)
C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe (ID: 1120|ParentID: 508|Système)
C:\Windows\System32\taskeng.exe (ID: 644|ParentID: 372|rm)
C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe (ID: 1836|ParentID: 508|Système)
C:\Program Files\Bonjour\mDNSResponder.exe (ID: 2168|ParentID: 508|Système)
C:\Program Files (x86)\Common Files\LightScribe\LSSrvc.exe (ID: 2256|ParentID: 508|Système)
C:\Windows\SysWOW64\PSIService.exe (ID: 2364|ParentID: 508|Système)
C:\Program Files\Tablet\Pen\Pen_Tablet.exe (ID: 2452|ParentID: 508|Système)
C:\Program Files (x86)\TomTom HOME 2\TomTomHOMEService.exe (ID: 2476|ParentID: 508|Système)
C:\Program Files\Tablet\Pen\Pen_TabletUser.exe (ID: 2680|ParentID: 2452|rm)
C:\Program Files\Hewlett-Packard\HP MediaSmart\SmartMenu.exe (ID: 2836|ParentID: 1916|rm)
C:\Program Files\Microsoft Security Client\msseces.exe (ID: 2848|ParentID: 1916|rm)
C:\Program Files (x86)\Samsung\Kies\External\FirmwareUpdate\KiesPDLR.exe (ID: 2924|ParentID: 1916|rm)
C:\Program Files\Tablet\Pen\Pen_Tablet.exe (ID: 2932|ParentID: 2452|Système)
C:\Program Files (x86)\Samsung\Kies\Kies.exe (ID: 2968|ParentID: 1916|rm)
C:\Program Files (x86)\TomTom HOME 2\TomTomHOMERunner.exe (ID: 2984|ParentID: 1916|rm)
C:\Program Files (x86)\OpenOffice.org 3\program\soffice.exe (ID: 3028|ParentID: 3008|rm)
C:\Program Files (x86)\OpenOffice.org 3\program\soffice.bin (ID: 3044|ParentID: 3028|rm)
C:\Program Files (x86)\Hewlett-Packard\HP Odometer\hpsysdrv.exe (ID: 2320|ParentID: 3000|rm)
C:\Program Files (x86)\hp\HP Software Update\hpwuschd2.exe (ID: 2336|ParentID: 3000|rm)
C:\Program Files (x86)\Bamboo Dock\BambooCore.exe (ID: 2776|ParentID: 3000|rm)
C:\ProgramData\Easybits Magic Desktop for HP\mdhpSUN.exe (ID: 2532|ParentID: 3000|rm)
C:\Program Files (x86)\Samsung\Kies\KiesTrayAgent.exe (ID: 2544|ParentID: 3000|rm)
C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe (ID: 2304|ParentID: 3000|rm)
C:\Windows\System32\SearchIndexer.exe (ID: 3420|ParentID: 508|Système)
C:\Windows\System32\WUDFHost.exe (ID: 3500|ParentID: 1020|SERVICE LOCAL)
C:\Program Files (x86)\Hewlett-Packard\Media\DVD\DVDAgent.exe (ID: 3604|ParentID: 644|rm)
C:\Program Files (x86)\Hewlett-Packard\TouchSmart\Media\Kernel\CLML\CLMLSvc.exe (ID: 3612|ParentID: 644|rm)
C:\Program Files\Windows Media Player\wmpnetwk.exe (ID: 4160|ParentID: 508|SERVICE RÉSEAU)
C:\Program Files (x86)\Mozilla Thunderbird\thunderbird.exe (ID: 4664|ParentID: 1916|rm)
C:\Program Files\Internet Explorer\iexplore.exe (ID: 4944|ParentID: 4664|rm)
C:\Program Files (x86)\Internet Explorer\iexplore.exe (ID: 4992|ParentID: 4944|rm)
C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\HPSA_Service.exe (ID: 4636|ParentID: 508|Système)
C:\Windows\System32\sppsvc.exe (ID: 4200|ParentID: 508|SERVICE RÉSEAU)
C:\Program Files\Common Files\Microsoft Shared\ink\InputPersonalization.exe (ID: 4880|ParentID: 508|rm)
C:\Windows\System32\wuauclt.exe (ID: 3464|ParentID: 372|rm)
C:\Windows\System32\taskhost.exe (ID: 3060|ParentID: 508|SERVICE LOCAL)
C:\Windows\System32\SearchProtocolHost.exe (ID: 3004|ParentID: 3420|Système)
################## | Autorun |
################## | Recherche générique |
(!) Fichiers temporaires supprimés.
################## | Registre |
################## | Regedit Run |
F2 - HKLM\..\Winlogon : [Shell] explorer.exe
F2 - [x64] HKLM\..\Winlogon : [Shell] explorer.exe
F2 - HKLM\..\Winlogon : [Userinit] userinit.exe,
F2 - [x64] HKLM\..\Winlogon : [Userinit] C:\Windows\system32\userinit.exe,
04 - HKCU\..\Run : [BambooScribe.exe] "C:\Program Files (x86)\Vision Objects\Bamboo Scribe\BambooScribe.exe" /i
04 - HKCU\..\Run : [KiesPDLR] C:\Program Files (x86)\Samsung\Kies\External\FirmwareUpdate\KiesPDLR.exe
04 - HKCU\..\Run : [KiesPreload] C:\Program Files (x86)\Samsung\Kies\Kies.exe /preload
04 - HKCU\..\Run : [TomTomHOME.exe] "C:\Program Files (x86)\TomTom HOME 2\TomTomHOMERunner.exe"
04 - HKCU\..\Run : [CCleaner] "C:\Program Files\CCleaner\CCleaner64.exe" /AUTO
04 - HKLM\..\Run : [hpsysdrv] c:\program files (x86)\hewlett-packard\HP odometer\hpsysdrv.exe
04 - HKLM\..\Run : [HP Software Update] c:\Program Files (x86)\HP\HP Software Update\HPWuSchd2.exe
04 - HKLM\..\Run : [Easybits Recovery] C:\Program Files (x86)\EasyBits For Kids\ezRecover.exe
04 - HKLM\..\Run : [UpdatePRCShortCut] "C:\Program Files (x86)\Hewlett-Packard\Recovery\MUITransfer\MUIStartMenu.exe" "C:\Program Files (x86)\Hewlett-Packard\Recovery" UpdateWithCreateOnce "Software\CyberLink\PowerRecover"
04 - HKLM\..\Run : [BambooCore] C:\Program Files (x86)\Bamboo Dock\BambooCore.exe
04 - HKLM\..\Run : [BambooScribeAutoStart.vbe] "C:\Program Files (x86)\Vision Objects\Bamboo Scribe\BambooScribeAutoStart.vbe"
04 - HKLM\..\Run : [Samsung PanelMgr] C:\Windows\Samsung\PanelMgr\SSMMgr.exe /autorun
04 - HKLM\..\Run : [APSDaemon] "C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe"
04 - HKLM\..\Run : [Adobe ARM] "C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
04 - HKLM\..\Run : [Magic Desktop for HP notification] "C:\ProgramData\Easybits Magic Desktop for HP\mdhpSUN.exe"
04 - HKLM\..\Run : [KiesTrayAgent] C:\Program Files (x86)\Samsung\Kies\KiesTrayAgent.exe
04 - HKLM\..\Run : [SunJavaUpdateSched] "C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe"
04 - [x64] HKLM\..\Run : [NvCplDaemon] RUNDLL32.EXE C:\Windows\system32\NvCpl.dll,NvStartup
04 - [x64] HKLM\..\Run : [SmartMenu] C:\Program Files\Hewlett-Packard\HP MediaSmart\SmartMenu.exe /background
04 - [x64] HKLM\..\Run : [MSC] "c:\Program Files\Microsoft Security Client\msseces.exe" -hide -runkey
04 - [x64] HKLM\..\RunOnce : [NCPluginUpdater] "C:\Program Files (x86)\Hewlett-Packard\HP Health Check\ActiveCheck\product_line\NCPluginUpdater.exe" Update
04 - HKU\S-1-5-19\..\Run : [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun
04 - HKU\S-1-5-20\..\Run : [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun
04 - HKU\S-1-5-21-3665027634-1497555908-1381305757-1000\..\Run : [BambooScribe.exe] "C:\Program Files (x86)\Vision Objects\Bamboo Scribe\BambooScribe.exe" /i
04 - HKU\S-1-5-21-3665027634-1497555908-1381305757-1000\..\Run : [KiesPDLR] C:\Program Files (x86)\Samsung\Kies\External\FirmwareUpdate\KiesPDLR.exe
04 - HKU\S-1-5-21-3665027634-1497555908-1381305757-1000\..\Run : [KiesPreload] C:\Program Files (x86)\Samsung\Kies\Kies.exe /preload
04 - HKU\S-1-5-21-3665027634-1497555908-1381305757-1000\..\Run : [TomTomHOME.exe] "C:\Program Files (x86)\TomTom HOME 2\TomTomHOMERunner.exe"
04 - HKU\S-1-5-21-3665027634-1497555908-1381305757-1000\..\Run : [CCleaner] "C:\Program Files\CCleaner\CCleaner64.exe" /AUTO
04 - HKU\S-1-5-19\..\RunOnce : [mctadmin] C:\Windows\System32\mctadmin.exe
04 - HKU\S-1-5-20\..\RunOnce : [mctadmin] C:\Windows\System32\mctadmin.exe
################## | C:\ %SystemDrive% - Disque Fixe (NTFS) |
[07/11/2007 - 08:00:40 | N | 17 Ko] - C:\eula.1031.txt
[07/11/2007 - 08:00:40 | N | 17 Ko] - C:\eula.2052.txt
[07/11/2007 - 08:00:40 | N | 17 Ko] - C:\eula.1042.txt
[07/11/2007 - 08:00:40 | N | 0 Ko] - C:\eula.1041.txt
[07/11/2007 - 08:00:40 | N | 17 Ko] - C:\eula.1040.txt
[07/11/2007 - 08:00:40 | N | 17 Ko] - C:\eula.1036.txt
[07/11/2007 - 08:00:40 | N | 17 Ko] - C:\eula.1028.txt
[07/11/2007 - 08:00:40 | N | 17 Ko] - C:\eula.3082.txt
[07/11/2007 - 08:00:40 | N | 10 Ko] - C:\eula.1033.txt
[13/09/2010 - 09:04:02 | N | 1 Ko] - C:\FINIS_IT.TXT
[09/06/2014 - 16:53:00 | N | 4 Ko] - C:\DelFix.txt
[12/06/2014 - 16:15:18 | N | 99 Ko] - C:\Shortcut_Module_12_06_2014_16_15_18.txt
[12/06/2014 - 19:47:24 | N | 38 Ko] - C:\Shortcut_Module_12_06_2014_19_47_24.txt
[12/06/2014 - 21:23:14 | N | 35 Ko] - C:\Shortcut_Module_12_06_2014_21_23_14.txt
[15/06/2014 - 13:30:36 | N | 126 Ko] - C:\Shortcut_Module_15_06_2014_13_30_36.txt
[15/06/2014 - 17:38:25 | ASH | 3145144 Ko] - C:\hiberfil.sys
[15/06/2014 - 17:38:25 | ASH | 4193528 Ko] - C:\pagefile.sys
[11/01/2011 - 17:55:37 | D] - C:\SYSTEM.SAV
[07/11/2007 - 08:53:12 | N | 237 Ko] - C:\VC_RED.MSI
[12/06/2014 - 21:23:46 | D] - C:\Config.Msi
[07/11/2007 - 08:00:40 | N | 1 Ko] - C:\globdata.ini
[07/11/2007 - 08:00:40 | N | 1 Ko] - C:\install.ini
[29/11/2011 - 10:57:02 | N | 20 Ko] - C:\ffastun0.ffx
[29/11/2011 - 10:57:02 | N | 16 Ko] - C:\ffastun.ffo
[29/11/2011 - 10:57:02 | N | 24 Ko] - C:\ffastun.ffl
[29/11/2011 - 10:57:02 | N | 4 Ko] - C:\ffastun.ffa
[07/11/2007 - 08:44:20 | N | 835 Ko |
VirusTotal - (0/53)] - C:\install.exe
[01/12/2006 - 23:37:14 | N | 884 Ko |
VirusTotal - (0/54)] - C:\msdia80.dll
[07/11/2007 - 08:44:20 | N | 94 Ko |
VirusTotal - (0/52)] - C:\install.res.1036.dll
[07/11/2007 - 08:44:20 | N | 92 Ko |
VirusTotal - (0/52)] - C:\install.res.1040.dll
[07/11/2007 - 08:44:20 | N | 79 Ko |
VirusTotal - (0/53)] - C:\install.res.1041.dll
[07/11/2007 - 08:44:20 | N | 77 Ko |
VirusTotal - (0/52)] - C:\install.res.1042.dll
[07/11/2007 - 08:44:20 | N | 73 Ko |
VirusTotal - (0/48)] - C:\install.res.2052.dll
[07/11/2007 - 08:44:20 | N | 93 Ko |
VirusTotal - (0/52)] - C:\install.res.3082.dll
[07/11/2007 - 08:44:20 | N | 93 Ko |
VirusTotal - (0/47)] - C:\install.res.1031.dll
[07/11/2007 - 08:44:20 | N | 74 Ko |
VirusTotal - (0/51)] - C:\install.res.1028.dll
[07/11/2007 - 08:44:20 | N | 88 Ko |
VirusTotal - (0/49)] - C:\install.res.1033.dll
[01/12/2011 - 11:40:03 | SHD] - C:\$Recycle.Bin
[14/07/2009 - 05:20:08 | D] - C:\PerfLogs
[14/07/2009 - 07:08:56 | SHD] - C:\Documents and Settings
[05/10/2010 - 18:39:36 | D] - C:\EPSON
[25/12/2011 - 11:21:21 | RHD] - C:\MSOCache
[04/02/2012 - 12:45:13 | D] - C:\Sans nom
[22/11/2012 - 18:40:22 | D] - C:\swsetup
[23/08/2013 - 15:26:48 | D] - C:\hp
[23/08/2013 - 15:26:57 | D] - C:\Errors
[13/11/2013 - 19:49:30 | D] - C:\Maps
[12/01/2014 - 20:53:07 | D] - C:\Winamax
[26/03/2014 - 12:17:25 | D] - C:\Poker
[10/04/2014 - 22:52:45 | D] - C:\___RM__photos
[06/05/2014 - 18:57:56 | D] - C:\Users
[11/05/2014 - 11:29:37 | D] - C:\_RM_courrier
[21/05/2014 - 11:31:29 | D] - C:\_______Mes_Toiles
[27/05/2014 - 12:13:26 | D] - C:\_RM_Humour
[07/06/2014 - 10:13:54 | D] - C:\Temp
[11/06/2014 - 11:10:15 | D] - C:\_RM_téléchargements
[11/06/2014 - 11:21:11 | D] - C:\_____GM
[11/06/2014 - 19:06:11 | D] - C:\_RM_z_autres
[11/06/2014 - 19:06:30 | D] - C:\_______Maïté
[11/06/2014 - 19:09:05 | D] - C:\______peinture
[11/06/2014 - 22:23:23 | D] - C:\______Aa_Word
[12/06/2014 - 09:39:32 | D] - C:\_______Poker
[12/06/2014 - 15:11:28 | D] - C:\_Informatique
[12/06/2014 - 20:33:16 | D] - C:\Program Files (x86)
[12/06/2014 - 20:34:43 | D] - C:\Program Files
[12/06/2014 - 20:34:43 | HD] - C:\ProgramData
[15/06/2014 - 08:52:55 | SHD] - C:\System Volume Information
[15/06/2014 - 13:30:30 | D] - C:\Shortcut_Module
[15/06/2014 - 13:55:56 | D] - C:\______Aa_excel
[15/06/2014 - 17:39:32 | D] - C:\Windows
[15/06/2014 - 17:45:05 | D] - C:\UsbFix
################## | D:\ - Disque Fixe (NTFS) |
[09/01/2014 - 19:21:04 | SHD] - D:\$RECYCLE.BIN
[09/06/2014 - 14:59:37 | SHD] - D:\System Volume Information
################## | F:\ - Disque USB (FAT) |
[22/02/2009 - 11:10:22 | N | 2 Ko] - F:\BOOTEX.LOG
[30/11/2009 - 14:19:10 | N | 0 Ko] - F:\.picasa.ini
[30/09/2009 - 10:18:26 | N | 2 Ko] - F:\baserm1.gpx
[19/01/2009 - 10:36:08 | D] - F:\jeux
[20/01/2009 - 15:58:32 | D] - F:\base_logiciels
[10/11/2009 - 18:30:02 | D] - F:\__immo
[10/11/2009 - 18:32:46 | D] - F:\1_VTT
[10/11/2009 - 18:33:42 | D] - F:\4_stats
[10/11/2009 - 18:33:52 | D] - F:\8_Autres
[10/11/2009 - 18:37:14 | D] - F:\z_Autres
[05/08/2012 - 22:51:54 | D] - F:\chateaux de la loire 2012
[19/11/2013 - 17:40:18 | D] - F:\_PHOTOS MAITE 19 11 2013
[18/01/2014 - 14:34:26 | D] - F:\___photos
################## | K:\ - Disque USB (FAT32) |
[01/03/2013 - 13:14:52 | D] - K:\___Photos maite
[02/09/2013 - 09:18:48 | D] - K:\divers dom
[17/11/2013 - 15:09:58 | D] - K:\_____informatique
################## | Vaccin |
D:\Autorun.inf - Vaccin créé par UsbFix (El Desaparecido)
F:\Autorun.inf - Vaccin créé par UsbFix (El Desaparecido)
K:\Autorun.inf - Vaccin créé par UsbFix (El Desaparecido)
################## | E.O.F | http://www.sosvirus.net/ | http://www.usbfix.net/ |
Merci pour la suite.