############################## | UsbFix V 7.168 | [Recherche]
Utilisateur: abenali (Administrateur) # BENALI
Mis à jour le 28/03/2014 par El Desaparecido - Team SosVirus
Lancé à 21:32:56 | 07/07/2014
Site Web :
http://www.usbfix.net/
Changelog :
http://www.usbfix.net/maj/
Support :
http://www.sosvirus.net/forum-virus-securite.html
Upload Malware :
http://www.sosvirus.net/upload_malware.php
Contact :
http://www.usbfix.net/contact/
PC: Hewlett-Packard (1619)
CPU: Intel(R) Core(TM) i5-2520M CPU @ 2.50GHz
RAM - [Total : 4030 Mo| Free : 1216 Mo]
Bios: Hewlett-Packard
Boot: Normal boot
OS: Microsoft Windows 7 Professionnel (6.1.7601 64-Bit) Service Pack 1
WB: Windows Internet Explorer : 11.0.9600.17126
WB: Google Chrome : 32.0.1700.72
WB: Mozilla Firefox : 30.0
SC: Security Center [Enabled]
WU: Windows Update [Enabled]
AV: Trend Micro OfficeScan Antivirus [Enabled | Updated]
AS: Trend Micro OfficeScan Anti-spyware [Enabled | Updated]
AS: Windows Defender [Enabled | Updated]
FW: Trend Micro Personal Firewall [Enabled]
FW: Windows FireWall [Enabled]
C:\ (%systemdrive%) - Disque fixe # 278 Go (166 Go libre(s) - 60%) [] # NTFS
D:\ - Disque amovible # 8 Go (7 Go libre(s) - 97%) [PRODIGE] # FAT32
E:\ - Disque fixe # 15 Go (2 Go libre(s) - 15%) [HP_RECOVERY] # NTFS
F:\ - Disque fixe # 5 Go (2 Go libre(s) - 43%) [HP_TOOLS] # FAT32
G:\ - CD-ROM
################## | Processus Actif |
C:\windows\system32\csrss.exe (ID: 540 |ParentID: 528)
C:\windows\system32\csrss.exe (ID: 632 |ParentID: 624)
C:\windows\system32\wininit.exe (ID: 640 |ParentID: 528)
C:\windows\system32\winlogon.exe (ID: 688 |ParentID: 624)
C:\windows\system32\services.exe (ID: 736 |ParentID: 640)
C:\windows\system32\lsass.exe (ID: 744 |ParentID: 640)
C:\windows\system32\lsm.exe (ID: 752 |ParentID: 640)
C:\windows\system32\svchost.exe (ID: 848 |ParentID: 736)
C:\Program Files (x86)\Hewlett-Packard\File Sanitizer\HPFSService.exe (ID: 940 |ParentID: 736)
C:\windows\system32\svchost.exe (ID: 992 |ParentID: 736)
C:\windows\System32\svchost.exe (ID: 552 |ParentID: 736)
C:\windows\System32\svchost.exe (ID: 508 |ParentID: 736)
C:\windows\system32\svchost.exe (ID: 624 |ParentID: 736)
C:\windows\system32\svchost.exe (ID: 808 |ParentID: 736)
C:\Program Files\IDT\WDM\STacSV64.exe (ID: 1048 |ParentID: 736)
C:\windows\system32\svchost.exe (ID: 1280 |ParentID: 736)
C:\windows\system32\Hpservice.exe (ID: 1392 |ParentID: 736)
C:\windows\system32\vcsFPService.exe (ID: 1472 |ParentID: 736)
C:\windows\system32\svchost.exe (ID: 1528 |ParentID: 736)
C:\windows\System32\spoolsv.exe (ID: 1740 |ParentID: 736)
C:\windows\system32\taskeng.exe (ID: 1764 |ParentID: 808)
c:\Program Files\Hewlett-Packard\HP ProtectTools Security Manager\Bin\DpHostW.exe (ID: 1800 |ParentID: 736)
C:\windows\system32\svchost.exe (ID: 1940 |ParentID: 736)
C:\Program Files\IDT\WDM\AESTSr64.exe (ID: 1212 |ParentID: 736)
C:\Program Files\LSI SoftModem\agr64svc.exe (ID: 1240 |ParentID: 736)
C:\Program Files\WIDCOMM\Bluetooth Software\btwdins.exe (ID: 1384 |ParentID: 736)
c:\Program Files\Hewlett-Packard\HP DayStarter\32-bit\HPDayStarterService.exe (ID: 1424 |ParentID: 736)
C:\Program Files (x86)\Hewlett-Packard\Shared\HPDrvMntSvc.exe (ID: 1904 |ParentID: 736)
C:\Program Files (x86)\Hewlett-Packard\HP Hotkey Support\HpHotkeyMonitor.exe (ID: 1420 |ParentID: 736)
C:\windows\system32\taskhost.exe (ID: 2056 |ParentID: 736)
C:\Program Files (x86)\Google\Update\GoogleUpdate.exe (ID: 2144 |ParentID: 1764)
c:\Program Files (x86)\Hewlett-Packard\HP ProtectTools Security Manager\Bin\DPAgent.exe (ID: 2164 |ParentID: 688)
C:\windows\system32\Dwm.exe (ID: 2188 |ParentID: 508)
c:\Program Files (x86)\Hewlett-Packard\Embedded Security Software\ifxspmgt.exe (ID: 2260 |ParentID: 736)
C:\windows\Explorer.EXE (ID: 2268 |ParentID: 2104)
c:\support\couponsupport.exe (ID: 2472 |ParentID: 1764)
c:\Program Files (x86)\Hewlett-Packard\Embedded Security Software\ifxtcs.exe (ID: 2544 |ParentID: 736)
C:\Program Files (x86)\Intel\Services\IPT\jhi_service.exe (ID: 2616 |ParentID: 736)
C:\windows\system32\taskeng.exe (ID: 2696 |ParentID: 808)
C:\Program Files (x86)\Common Files\LightScribe\LSSrvc.exe (ID: 2724 |ParentID: 736)
C:\Program Files (x86)\LogMeIn\x64\LMIGuardianSvc.exe (ID: 2940 |ParentID: 736)
C:\windows\system32\taskeng.exe (ID: 3012 |ParentID: 808)
C:\Program Files (x86)\LogMeIn\x64\RaMaint.exe (ID: 1756 |ParentID: 736)
C:\Program Files\Hewlett-Packard\Drive Encryption\EEAgent\MfeEpeHost.exe (ID: 2216 |ParentID: 736)
C:\Program Files (x86)\Trend Micro\OfficeScan Client\ntrtscan.exe (ID: 2252 |ParentID: 736)
C:\Program Files (x86)\PDF Complete\pdfsvc.exe (ID: 3044 |ParentID: 736)
C:\Program Files (x86)\Common Files\Portrait Displays\Drivers\pdisrvc.exe (ID: 3064 |ParentID: 736)
c:\Program Files (x86)\Hewlett-Packard\Embedded Security Software\IfxPsdSv.exe (ID: 1924 |ParentID: 736)
C:\Program Files (x86)\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe (ID: 3112 |ParentID: 736)
C:\Program Files (x86)\Stonesoft\StoneGate IPsec VPN\bin\sgvpn.exe (ID: 3200 |ParentID: 736)
C:\Program Files\Common Files\ShopperPro\spbiu.exe (ID: 3248 |ParentID: 736)
C:\windows\system32\svchost.exe (ID: 3276 |ParentID: 736)
C:\Program Files (x86)\Stonesoft\StoneGate IPsec VPN\bin\sgpm.exe (ID: 3336 |ParentID: 3200)
C:\windows\system32\conhost.exe (ID: 3416 |ParentID: 540)
C:\windows\SysWow64\ArcVCapRender\uArcCapture.exe (ID: 3512 |ParentID: 736)
C:\Program Files (x86)\focusbase\updatefocusbase.exe (ID: 3628 |ParentID: 736)
c:\Program Files\Hewlett-Packard\HP ProtectTools Security Manager\Bin\DPAgent.exe (ID: 3680 |ParentID: 2164)
C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE (ID: 3876 |ParentID: 736)
C:\Program Files (x86)\LogMeIn\x64\LogMeIn.exe (ID: 3996 |ParentID: 736)
C:\Program Files (x86)\Trend Micro\OfficeScan Client\tmlisten.exe (ID: 3408 |ParentID: 736)
C:\windows\system32\wbem\unsecapp.exe (ID: 3068 |ParentID: 848)
C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe (ID: 3728 |ParentID: 3876)
C:\windows\system32\wbem\wmiprvse.exe (ID: 572 |ParentID: 848)
C:\windows\system32\wbem\wmiprvse.exe (ID: 4112 |ParentID: 848)
C:\Program Files (x86)\LogMeIn\x64\LogMeInSystray.exe (ID: 4324 |ParentID: 2268)
C:\windows\System32\alg.exe (ID: 4452 |ParentID: 736)
C:\windows\system32\SearchIndexer.exe (ID: 4508 |ParentID: 736)
C:\Program Files (x86)\Hewlett-Packard\Shared\hpqWmiEx.exe (ID: 4812 |ParentID: 736)
C:\windows\System32\svchost.exe (ID: 4992 |ParentID: 736)
C:\windows\system32\svchost.exe (ID: 5020 |ParentID: 736)
C:\windows\system32\svchost.exe (ID: 5056 |ParentID: 736)
C:\windows\servicing\TrustedInstaller.exe (ID: 5088 |ParentID: 736)
C:\Program Files (x86)\Trend Micro\OfficeScan Client\TmPfw.exe (ID: 4932 |ParentID: 736)
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe (ID: 1232 |ParentID: 2268)
C:\Windows\System32\igfxtray.exe (ID: 5132 |ParentID: 2268)
C:\Windows\System32\hkcmd.exe (ID: 5144 |ParentID: 2268)
C:\Windows\System32\igfxpers.exe (ID: 5156 |ParentID: 2268)
C:\Program Files\IDT\WDM\sttray64.exe (ID: 5176 |ParentID: 2268)
C:\Program Files\Hewlett-Packard\Drive Encryption\EpePcMonitor.exe (ID: 5220 |ParentID: 2268)
C:\windows\sysWOW64\wbem\wmiprvse.exe (ID: 5544 |ParentID: 848)
C:\Program Files\Synaptics\SynTP\SynTPHelper.exe (ID: 5736 |ParentID: 1232)
C:\Program Files (x86)\Trend Micro\OfficeScan Client\CNTAoSMgr.exe (ID: 6044 |ParentID: 3408)
C:\windows\system32\conhost.exe (ID: 6056 |ParentID: 540)
C:\Program Files (x86)\Trend Micro\OfficeScan Client\TmProxy.exe (ID: 5556 |ParentID: 736)
C:\Program Files (x86)\Common Files\LightScribe\LightScribeControlPanel.exe (ID: 1116 |ParentID: 2268)
C:\Windows\System32\wscript.exe (ID: 2468 |ParentID: 2268)
C:\Program Files (x86)\ShopperPro\JSDriver\1.37.1.189\jsdrv.exe (ID: 5664 |ParentID: 2268)
C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe (ID: 5756 |ParentID: 2268)
C:\Program Files (x86)\Roxio\Roxio Burn\RoxioBurnLauncher.exe (ID: 5432 |ParentID: 5680)
C:\Program Files\McAfee Security Scan\3.8.150\SSScheduler.exe (ID: 1868 |ParentID: 2268)
C:\Program Files\Windows Media Player\wmpnetwk.exe (ID: 4016 |ParentID: 736)
C:\Program Files (x86)\Hewlett-Packard\HP HotKey Support\QLBController.exe (ID: 5620 |ParentID: 5680)
C:\Program Files (x86)\Hewlett-Packard\File Sanitizer\coreshredder.exe (ID: 5632 |ParentID: 5680)
C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe (ID: 5644 |ParentID: 5680)
C:\Program Files (x86)\Hewlett-Packard\HP QuickWeb\hpqwutils.exe (ID: 5732 |ParentID: 5680)
C:\Program Files (x86)\Trend Micro\OfficeScan Client\PccNTMon.exe (ID: 6416 |ParentID: 5680)
C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe (ID: 6536 |ParentID: 5680)
C:\Program Files (x86)\Stonesoft\StoneGate IPsec VPN\bin\sggui.exe (ID: 6556 |ParentID: 5680)
c:\Program Files (x86)\Hewlett-Packard\Embedded Security Software\PSDrt.exe (ID: 6884 |ParentID: 1852)
C:\windows\SysWOW64\RunDll32.exe (ID: 6424 |ParentID: 5756)
C:\Program Files (x86)\Stonesoft\StoneGate IPsec VPN\bin\sgcrypto.exe (ID: 1708 |ParentID: 6556)
C:\Program Files\WIDCOMM\Bluetooth Software\BtStackServer.exe (ID: 6624 |ParentID: 848)
C:\windows\System32\svchost.exe (ID: 6872 |ParentID: 736)
C:\Program Files\WIDCOMM\Bluetooth Software\BluetoothHeadsetProxy.exe (ID: 6948 |ParentID: 6624)
C:\Program Files (x86)\Roxio\Roxio Burn\Roxio Burn.exe (ID: 6328 |ParentID: 5432)
C:\windows\system32\wuauclt.exe (ID: 7732 |ParentID: 808)
C:\Program Files (x86)\DistributedData\DataClient.exe (ID: 6708 |ParentID: 5680)
C:\Program Files (x86)\Hewlett-Packard\HP Health Check\hphc_service.exe (ID: 6764 |ParentID: 736)
C:\Users\abenali\AppData\Local\Temp\TCB_01923\IndexingService.exe (ID: 7752 |ParentID: 6708)
C:\windows\system32\conhost.exe (ID: 7912 |ParentID: 632)
C:\Program Files\Hewlett-Packard\HP Power Assistant\HPPA_Service.exe (ID: 7864 |ParentID: 736)
C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe (ID: 8000 |ParentID: 736)
C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe (ID: 6336 |ParentID: 736)
C:\Program Files\Hewlett-Packard\HP Power Assistant\HPPA_Main.exe (ID: 4536 |ParentID: 4408)
C:\windows\system32\sppsvc.exe (ID: 3480 |ParentID: 736)
C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe (ID: 7360 |ParentID: 736)
C:\Program Files (x86)\Hewlett-Packard\HP Connection Manager\hpConnectionManager.exe (ID: 4408 |ParentID: 5712)
c:\Program Files (x86)\Hewlett-Packard\HP Connection Manager\hpCMSrv.exe (ID: 5196 |ParentID: 736)
C:\Program Files (x86)\Common Files\Portrait Displays\Drivers\SDKCOMServer.exe (ID: 3852 |ParentID: 848)
C:\Program Files (x86)\Hewlett-Packard\Shared\hpCaslNotification.exe (ID: 7728 |ParentID: 4408)
C:\windows\Microsoft.Net\Framework64\v3.0\WPF\PresentationFontCache.exe (ID: 2756 |ParentID: 736)
C:\Program Files (x86)\Microsoft Office\Office14\OUTLOOK.EXE (ID: 6680 |ParentID: 2268)
C:\Program Files (x86)\Common Files\Portrait Displays\Drivers\pdiSdkHelperx64.exe (ID: 7784 |ParentID: 3852)
C:\windows\system32\igfxext.exe (ID: 4728 |ParentID: 848)
C:\windows\system32\igfxsrvc.exe (ID: 6156 |ParentID: 848)
C:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPSVC.EXE (ID: 8164 |ParentID: 736)
C:\Program Files (x86)\Mozilla Firefox\firefox.exe (ID: 1080 |ParentID: 6680)
C:\Program Files (x86)\Mozilla Firefox\plugin-container.exe (ID: 8456 |ParentID: 1080)
C:\windows\SysWOW64\Macromed\Flash\FlashPlayerPlugin_14_0_0_125.exe (ID: 8584 |ParentID: 8456)
C:\windows\SysWOW64\Macromed\Flash\FlashPlayerPlugin_14_0_0_125.exe (ID: 8604 |ParentID: 8584)
C:\windows\System32\WUDFHost.exe (ID: 3688 |ParentID: 508)
C:\windows\system32\SearchProtocolHost.exe (ID: 8156 |ParentID: 4508)
C:\windows\system32\SearchFilterHost.exe (ID: 4612 |ParentID: 4508)
################## | Regedit Run |
F2 - HKLM\..\Winlogon : [Shell] explorer.exe
F2 - [x64] HKLM\..\Winlogon : [Shell] explorer.exe
F2 - HKLM\..\Winlogon : [Userinit] userinit.exe
F2 - [x64] HKLM\..\Winlogon : [Userinit] C:\Windows\system32\userinit.exe,c:\Program Files (x86)\Hewlett-Packard\HP ProtectTools Security Manager\Bin\DPAgent.exe,
04 - HKCU\..\Run : [LightScribe Control Panel] C:\Program Files (x86)\Common Files\LightScribe\LightScribeControlPanel.exe -hidden
04 - HKCU\..\Run : [aljazeera-sport+2] wscript.exe //B "C:\Users\abenali\AppData\Local\Temp\aljazeera-sport+2.vbs"
04 - HKCU\..\Run : [SPDriver] C:\Program Files (x86)\ShopperPro\JSDriver\1.37.1.189\jsdrv.exe
04 - HKCU\..\Policies\Explorer\run : [1] C:\Program Files (x86)\Internet Explorer\iexplore.exe
04 - HKCU\..\Policies\Explorer\run : [2] C:\Program Files\Internet Explorer\iexplore.exe
04 - HKLM\..\Run : [Desktop Disc Tool] "C:\Program Files (x86)\Roxio\Roxio Burn\RoxioBurnLauncher.exe"
04 - HKLM\..\Run : [Microsoft Default Manager] "C:\Program Files (x86)\Microsoft\Search Enhancement Pack\Default Manager\DefMgr.exe" -resume
04 - HKLM\..\Run : [QLBController] C:\Program Files (x86)\Hewlett-Packard\HP HotKey Support\QLBController.exe /start
04 - HKLM\..\Run : [File Sanitizer] C:\Program Files (x86)\Hewlett-Packard\File Sanitizer\CoreShredder.exe
04 - HKLM\..\Run : [IAStorIcon] C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe
04 - HKLM\..\Run : [HPConnectionManager] c:\Program Files (x86)\Hewlett-Packard\HP Connection Manager\HPCMDelayStart.exe
04 - HKLM\..\Run : []
04 - HKLM\..\Run : [HPQuickWebProxy] "c:\Program Files (x86)\Hewlett-Packard\HP QuickWeb\hpqwutils.exe"
04 - HKLM\..\Run : [IFXSPMGT] "c:\Program Files (x86)\Hewlett-Packard\Embedded Security Software\ifxspmgt.exe" /NotifyLogon
04 - HKLM\..\Run : [OfficeScanNT Monitor] "C:\Program Files (x86)\Trend Micro\OfficeScan Client\pccntmon.exe" -HideWindow
04 - HKLM\..\Run : [Adobe Reader Speed Launcher] "C:\Program Files (x86)\Adobe\Reader 10.0\Reader\Reader_sl.exe"
04 - HKLM\..\Run : [Adobe ARM] "C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
04 - HKLM\..\Run : [StoneGate IPsec VPN GUI] C:\Program Files (x86)\Stonesoft\StoneGate IPsec VPN\bin\sggui.exe --logon
04 - HKLM\..\Run : [PDF Complete] C:\Program Files (x86)\PDF Complete\pdfsty.exe
04 - HKLM\..\Run : [mobilegeni daemon] C:\Program Files (x86)\Mobogenie\DaemonProcess.exe
04 - HKLM\..\Run : [fst_it_119]
04 - HKLM\..\Run : [SPDriver] C:\Program Files (x86)\ShopperPro\JSDriver\1.37.1.189\jsdrv.exe
04 - HKLM\..\Run : [CoreSystemDataClient] C:\Program Files (x86)\DistributedData\DataClient.exe
04 - HKLM\..\RunOnce : []
04 - [x64] HKLM\..\Run : [HPPowerAssistant] C:\Program Files\Hewlett-Packard\HP Power Assistant\DelayedAppStarter.exe 120 C:\Program Files\Hewlett-Packard\HP Power Assistant\HPPA_Main.exe /hidden
04 - [x64] HKLM\..\Run : [SynTPEnh] %ProgramFiles%\Synaptics\SynTP\SynTPEnh.exe
04 - [x64] HKLM\..\Run : [IgfxTray] C:\windows\system32\igfxtray.exe
04 - [x64] HKLM\..\Run : [HotKeysCmds] C:\windows\system32\hkcmd.exe
04 - [x64] HKLM\..\Run : [Persistence] C:\windows\system32\igfxpers.exe
04 - [x64] HKLM\..\Run : [SysTrayApp] C:\Program Files\IDT\WDM\sttray64.exe
04 - [x64] HKLM\..\Run : [MfeEpePcMonitor] "C:\Program Files\Hewlett-Packard\Drive Encryption\EpePcMonitor.exe"
04 - [x64] HKLM\..\Run : [LogMeIn GUI] "C:\Program Files (x86)\LogMeIn\x64\LogMeInSystray.exe"
04 - HKU\S-1-5-19\..\Run : [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun
04 - HKU\S-1-5-20\..\Run : [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun
04 - HKU\S-1-5-21-485633963-1252553726-1178852362-7247\..\Run : [LightScribe Control Panel] C:\Program Files (x86)\Common Files\LightScribe\LightScribeControlPanel.exe -hidden
04 - HKU\S-1-5-21-485633963-1252553726-1178852362-7247\..\Run : [aljazeera-sport+2] wscript.exe //B "C:\Users\abenali\AppData\Local\Temp\aljazeera-sport+2.vbs"
04 - HKU\S-1-5-21-485633963-1252553726-1178852362-7247\..\Run : [SPDriver] C:\Program Files (x86)\ShopperPro\JSDriver\1.37.1.189\jsdrv.exe
04 - HKU\S-1-5-19\..\RunOnce : [mctadmin] C:\Windows\System32\mctadmin.exe
04 - HKU\S-1-5-20\..\RunOnce : [mctadmin] C:\Windows\System32\mctadmin.exe
04 - HKU\S-1-5-21-485633963-1252553726-1178852362-7247\..\Policies\Explorer\run : [1] C:\Program Files (x86)\Internet Explorer\iexplore.exe
04 - HKU\S-1-5-21-485633963-1252553726-1178852362-7247\..\Policies\Explorer\run : [2] C:\Program Files\Internet Explorer\iexplore.exe
################## | Recherche générique |
Présent! C:\Users\abenali\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\aljazeera-sport+2.vbs
Présent! D:\aljazeera-sport+2.vbs
Présent! C:\Users\abenali\AppData\Local\Temp\aljazeera-sport+2.vbs
Présent! D:\QUINCAILLERIE ACCESSOIRES POUR ARCHITECTURE MODERNE.lnk
Présent! D:\Autorun.inf.lnk
Présent! C:\Users\abenali\AppData\Roaming\newnext.me\cache\spark.bin
Présent! C:\Users\abenali\AppData\Roaming\newnext.me\nengine.cookie
Présent! C:\Users\abenali\AppData\Roaming\newnext.me\nengine.dll
Présent! C:\Users\abenali\AppData\Roaming\newnext.me
################## | Registre |
Présent! [x64] HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon|Userinit (C:\Windows\system32\userinit.exe,c:\Program Files (x86)\Hewlett-Packard\HP ProtectTools Security Manager\Bin\DPAgent.exe,)
Présent! HKU\S-1-5-21-485633963-1252553726-1178852362-7247\Software\Microsoft\Windows\CurrentVersion\Run|aljazeera-sport+2
Présent! HKCU\Software\Microsoft\Windows\CurrentVersion\Run|aljazeera-sport+2
Présent! HKU\S-1-5-21-485633963-1252553726-1178852362-7247\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\Run|1
Présent! HKCU\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\Run|1
################## | E.O.F |
http://www.usbfix.net/ -
http://www.sosvirus.net |