Merci beaucoup de ton attention le scan a été effectué voila le rapport:
############################## | UsbFix V 7.174 | [Nettoyage]
Utilisateur: Arnaud (Administrateur) # ARNAUD-PC
Mis à jour le 10/07/2014 par El Desaparecido - SosVirus
Lancé à 02:07:54 | 11/07/2014
Site Web :
http://www.usbfix.net/
Changelog :
http://www.usbfix.net/maj/
Assistance :
http://www.sosvirus.net/forum-virus-securite.html
Upload Malware :
http://www.sosvirus.net/upload_malware.php
Contact :
http://www.usbfix.net/contact/
################## | System information |
MB: Gigabyte Technology Co., Ltd. (H77-DS3H)
CPU: Intel(R) Pentium(R) CPU G2120 @ 3.10GHz
GC: NVIDIA GeForce GT 620
RAM - [Total : 12249 Mo | Free : 8942 Mo]
Bios: American Megatrends Inc.
Boot: Normal boot
OS: Microsoft™ Windows 7 Ultimate (6.1.7601 64-Bit) Service Pack 1
WB: Internet Explorer : 11.00.9600.16428
WB: Google Chrome : 31.0.1650.63
WB: Mozilla Firefox : 30.0
################## | Security Information |
AV: Microsoft Security Essentials [
(!) Désactivé |A jour]
AS: Windows Defender [
(!) Désactivé |A jour]
AS: Microsoft Security Essentials [
(!) Désactivé |A jour]
AS: Malwarebytes Anti-Malware : 1.75.0001
FW: Windows Firewall [Actif]
SC: Security Center [Actif]
WU: Windows Update [Actif]
################## | Disk Information |
C:\ (%SystemDrive%) - Disque fixe # 931 Go (144 Go libre(s) - 15%) [] # NTFS
E:\ - Disque amovible # 8 Go (3 Go libre(s) - 34%) [] # FAT32
################## | Processus Stoppés |
C:\Windows\System32\nvvsvc.exe (ID: 904|ParentID: 688)
C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe (ID: 932|ParentID: 688)
C:\Windows\System32\wisptis.exe (ID: 1384|ParentID: 1080|Système)
C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe (ID: 1408|ParentID: 904|Système)
C:\Windows\System32\nvvsvc.exe (ID: 1416|ParentID: 904|Système)
C:\ProgramData\IePluginServices\PluginService.exe (ID: 1740|ParentID: 688|Système)
C:\Windows\System32\spoolsv.exe (ID: 1948|ParentID: 688|Système)
C:\Windows\System32\wisptis.exe (ID: 2032|ParentID: 1080|Arnaud)
C:\Windows\System32\taskhost.exe (ID: 1220|ParentID: 688|Arnaud)
C:\Program Files\Common Files\Microsoft Shared\ink\TabTip.exe (ID: 1372|ParentID: 1080|Arnaud)
C:\Windows\explorer.exe (ID: 1508|ParentID: 1596|Arnaud)
C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe (ID: 2408|ParentID: 688|Système)
C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe (ID: 2444|ParentID: 688|Système)
C:\Program Files\Bonjour\mDNSResponder.exe (ID: 2608|ParentID: 688|Système)
C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe (ID: 2732|ParentID: 1508|Arnaud)
C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvBackend.exe (ID: 2752|ParentID: 1508|Arnaud)
C:\Program Files\Microsoft Security Client\msseces.exe (ID: 2764|ParentID: 1508|Arnaud)
C:\Program Files\NVIDIA Corporation\Display\nvtray.exe (ID: 2156|ParentID: 1408|Arnaud)
C:\Program Files\Intel\iCLS Client\HeciServer.exe (ID: 2964|ParentID: 688|Système)
C:\Program Files (x86)\LogMeIn Hamachi\LMIGuardianSvc.exe (ID: 1204|ParentID: 688|Système)
C:\Program Files\ma-config.com\MaConfigAgent.exe (ID: 368|ParentID: 688|Système)
C:\Program Files\Microsoft LifeCam\MSCamS64.exe (ID: 352|ParentID: 688|Système)
C:\Program Files (x86)\NVIDIA Corporation\NetService\NvNetworkService.exe (ID: 2984|ParentID: 688|Système)
C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe (ID: 2560|ParentID: 688|Système)
C:\Program Files (x86)\SplitCam\SplitCamService.exe (ID: 3080|ParentID: 688|Système)
C:\Genius\ioTablet\TabletService.exe (ID: 3128|ParentID: 688|Système)
C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE (ID: 3168|ParentID: 688|Système)
C:\Program Files (x86)\LogMeIn Hamachi\hamachi-2.exe (ID: 3220|ParentID: 688|Système)
C:\Program Files (x86)\LogMeIn Hamachi\hamachi-2-ui.exe (ID: 3712|ParentID: 3220|Arnaud)
C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe (ID: 3772|ParentID: 2560|SERVICE RÉSEAU)
C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe (ID: 3780|ParentID: 2560|Système)
C:\Windows\System32\SearchIndexer.exe (ID: 3852|ParentID: 688|Système)
C:\Genius\ioTablet\gTabletTask.exe (ID: 3860|ParentID: 3128|Système)
C:\Program Files\Windows Media Player\wmpnetwk.exe (ID: 4752|ParentID: 688|SERVICE RÉSEAU)
C:\Program Files\Logitech Gaming Software\LCore.exe (ID: 4772|ParentID: 1508|Arnaud)
C:\Windows\PixArt\Pac207\Monitor.exe (ID: 4456|ParentID: 1508|Arnaud)
C:\Users\Arnaud\AppData\Local\Akamai\netsession_win.exe (ID: 5124|ParentID: 1508|Arnaud)
C:\Program Files\Windows Sidebar\sidebar.exe (ID: 5148|ParentID: 1508|Arnaud)
C:\Users\Arnaud\AppData\Local\Akamai\netsession_win.exe (ID: 5224|ParentID: 5124|Arnaud)
C:\Users\Arnaud\AppData\Roaming\Spotify\Data\SpotifyWebHelper.exe (ID: 5304|ParentID: 1508|Arnaud)
C:\Users\Arnaud\AppData\Roaming\Xpeyo\ltc.exe (ID: 5512|ParentID: 1508|Arnaud)
C:\Program Files (x86)\Java\jre7\bin\javaw.exe (ID: 5528|ParentID: 1508|Arnaud)
C:\Program Files\Common Files\Microsoft Shared\ink\InputPersonalization.exe (ID: 5732|ParentID: 1508|Arnaud)
C:\Program Files (x86)\Intel\Intel(R) USB 3.0 eXtensible Host Controller Driver\Application\iusb3mon.exe (ID: 5996|ParentID: 5648|Arnaud)
C:\Genius\ioTablet\gTabTaskBar.exe (ID: 6056|ParentID: 5648|Arnaud)
C:\Program Files (x86)\iTunes\iTunesHelper.exe (ID: 6072|ParentID: 5648|Arnaud)
C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe (ID: 6080|ParentID: 5648|Arnaud)
C:\Genius\ioTablet\gIoTabletFunMgm.exe (ID: 5700|ParentID: 6056|Arnaud)
C:\Program Files\iPod\bin\iPodService.exe (ID: 4808|ParentID: 688|Système)
C:\Users\Arnaud\AppData\Roaming\Xpeyo\taskhost.exe (ID: 248|ParentID: 5512|Arnaud)
C:\Windows\System32\conhost.exe (ID: 2744|ParentID: 588|Arnaud)
C:\Program Files\Logitech Gaming Software\Applets\LCDClock.exe (ID: 5668|ParentID: 4772|Arnaud)
C:\Program Files\Logitech Gaming Software\Applets\LCDRSS.exe (ID: 6148|ParentID: 4772|Arnaud)
C:\Program Files\Logitech Gaming Software\Applets\LCDPOP3.exe (ID: 6172|ParentID: 4772|Arnaud)
C:\Program Files\Logitech Gaming Software\Applets\LCDMovieViewer.exe (ID: 6252|ParentID: 4772|Arnaud)
C:\Program Files\Logitech Gaming Software\Applets\LCDPictureViewer.exe (ID: 6264|ParentID: 4772|Arnaud)
C:\Program Files\Logitech Gaming Software\Applets\LCDYT.exe (ID: 6272|ParentID: 4772|Arnaud)
C:\Program Files\Logitech Gaming Software\Applets\LCDCountdown.exe (ID: 6284|ParentID: 4772|Arnaud)
C:\Program Files\Logitech Gaming Software\Applets\LCDMedia.exe (ID: 6292|ParentID: 4772|Arnaud)
C:\Program Files\Logitech Gaming Software\Applets\LCDWebCam.exe (ID: 6304|ParentID: 4772|Arnaud)
C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\Jhi_service.exe (ID: 4864|ParentID: 688|Système)
C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe (ID: 4376|ParentID: 688|Système)
C:\Program Files (x86)\Skype\Phone\Skype.exe (ID: 7108|ParentID: 1508|Arnaud)
C:\Program Files (x86)\mozilla firefox\firefox.exe (ID: 6972|ParentID: 1508|Arnaud)
C:\Program Files (x86)\mozilla firefox\plugin-container.exe (ID: 6784|ParentID: 6972|Arnaud)
C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerPlugin_14_0_0_145.exe (ID: 6964|ParentID: 6784|Arnaud)
C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerPlugin_14_0_0_145.exe (ID: 6920|ParentID: 6964|Arnaud)
C:\Program Files (x86)\Steam\Steam.exe (ID: 3484|ParentID: 1508|Arnaud)
C:\Program Files (x86)\Common Files\Steam\SteamService.exe (ID: 5628|ParentID: 688|Système)
C:\Windows\System32\WUDFHost.exe (ID: 2904|ParentID: 1080|SERVICE LOCAL)
C:\Windows\System32\wermgr.exe (ID: 6500|ParentID: 532|Système)
################## | Autorun |
################## | Recherche générique |
Supprimé! C:\Users\Arnaud\AppData\Roaming\Xpeyo\ltc.exe
Supprimé! C:\Users\Arnaud\AppData\Roaming\Xpeyo\taskhost.exe
Supprimé! C:\Users\Arnaud\AppData\Roaming\dclogs\2014-05-12-2.dc
Supprimé! C:\Users\Arnaud\AppData\Roaming\dclogs\2014-05-13-3.dc
Supprimé! C:\Users\Arnaud\AppData\Roaming\dclogs\2014-05-14-4.dc
Supprimé! C:\Users\Arnaud\AppData\Roaming\dclogs\2014-05-15-5.dc
Supprimé! C:\Users\Arnaud\AppData\Roaming\dclogs\2014-05-16-6.dc
Supprimé! C:\Users\Arnaud\AppData\Roaming\dclogs\2014-05-17-7.dc
Supprimé! C:\Users\Arnaud\AppData\Roaming\dclogs\2014-05-18-1.dc
Supprimé! C:\Users\Arnaud\AppData\Roaming\dclogs\2014-05-19-2.dc
Supprimé! C:\Users\Arnaud\AppData\Roaming\dclogs\2014-05-20-3.dc
Supprimé! C:\Users\Arnaud\AppData\Roaming\dclogs\2014-05-21-4.dc
Supprimé! C:\Users\Arnaud\AppData\Roaming\dclogs\2014-05-22-5.dc
Supprimé! C:\Users\Arnaud\AppData\Roaming\dclogs\2014-05-23-6.dc
Supprimé! C:\Users\Arnaud\AppData\Roaming\dclogs\2014-05-25-1.dc
Supprimé! C:\Users\Arnaud\AppData\Roaming\dclogs\2014-05-26-2.dc
Supprimé! C:\Users\Arnaud\AppData\Roaming\dclogs
Supprimé! C:\Users\Arnaud\AppData\Local\Temp\1303449684.exe
Supprimé! C:\Users\Arnaud\AppData\Local\Temp\590713053.exe
(!) Fichiers temporaires supprimés.
################## | Registre |
Supprimé! HKCU\Software\DC3_FEXEC
Supprimé! HKU\S-1-5-21-2156171716-556064924-1487977086-1000\Software\Microsoft\Windows\CurrentVersion\Run|Default
################## | Regedit Run |
F2 - HKLM\..\Winlogon : [Shell] explorer.exe
F2 - [x64] HKLM\..\Winlogon : [Shell] explorer.exe
F2 - HKLM\..\Winlogon : [Userinit] userinit.exe,
F2 - [x64] HKLM\..\Winlogon : [Userinit] C:\Windows\system32\userinit.exe,
04 - HKCU\..\Run : [Akamai NetSession Interface] "C:\Users\Arnaud\AppData\Local\Akamai\netsession_win.exe"
04 - HKCU\..\Run : [Sidebar] C:\Program Files\Windows Sidebar\sidebar.exe /autoRun
04 - HKCU\..\Run : [DAEMON Tools Lite] "C:\Program Files (x86)\DAEMON Tools Lite\DTLite.exe" -autorun
04 - HKCU\..\Run : [Spotify Web Helper] "C:\Users\Arnaud\AppData\Roaming\Spotify\Data\SpotifyWebHelper.exe"
04 - HKCU\..\Run : [Spotify] "C:\Users\Arnaud\AppData\Roaming\Spotify\spotify.exe" /uri spotify:autostart
04 - HKCU\..\Run : [jawawv] "C:\Program Files (x86)\Java\jre7\bin\javaw.exe" -jar "C:\Users\Arnaud\AppData\Local\Temp\jawawv5708567619355446635.jar"
04 - HKLM\..\Run : [USB3MON] "C:\Program Files (x86)\Intel\Intel(R) USB 3.0 eXtensible Host Controller Driver\Application\iusb3mon.exe"
04 - HKLM\..\Run : [APSDaemon] "C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe"
04 - HKLM\..\Run : [LifeCam] "C:\Program Files (x86)\Microsoft LifeCam\LifeExp.exe"
04 - HKLM\..\Run : [Adobe ARM] "C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
04 - HKLM\..\Run : [ioTablet] "C:\Genius\ioTablet\gTabTaskBar.exe"
04 - HKLM\..\Run : [iTunesHelper] "C:\Program Files (x86)\iTunes\iTunesHelper.exe"
04 - HKLM\..\Run : [SunJavaUpdateSched] "C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe"
04 - HKLM\..\Run : [LogMeIn Hamachi Ui] "C:\Program Files (x86)\LogMeIn Hamachi\hamachi-2-ui.exe" --auto-start
04 - [x64] HKLM\..\Run : [RtHDVCpl] C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe -s
04 - [x64] HKLM\..\Run : [Nvtmru] "C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\nvtmru.exe"
04 - [x64] HKLM\..\Run : [ShadowPlay] C:\Windows\system32\rundll32.exe C:\Windows\system32\nvspcap64.dll,ShadowPlayOnSystemStart
04 - [x64] HKLM\..\Run : [NvBackend] "C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvBackend.exe"
04 - [x64] HKLM\..\Run : [MSC] "c:\Program Files\Microsoft Security Client\msseces.exe" -hide -runkey
04 - [x64] HKLM\..\Run : [LogMeIn GUI] "C:\Program Files (x86)\LogMeIn\x64\LogMeInSystray.exe"
04 - [x64] HKLM\..\Run : [Launch LCore] C:\Program Files\Logitech Gaming Software\LCore.exe /minimized
04 - [x64] HKLM\..\Run : [Monitor] C:\Windows\PixArt\PAC207\Monitor.exe
04 - [x64] HKLM\..\Run : [BCSSync] "C:\Program Files\Microsoft Office\Office14\BCSSync.exe" /DelayServices
04 - HKU\S-1-5-19\..\Run : [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun
04 - HKU\S-1-5-20\..\Run : [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun
04 - HKU\S-1-5-21-2156171716-556064924-1487977086-1000\..\Run : [Akamai NetSession Interface] "C:\Users\Arnaud\AppData\Local\Akamai\netsession_win.exe"
04 - HKU\S-1-5-21-2156171716-556064924-1487977086-1000\..\Run : [Sidebar] C:\Program Files\Windows Sidebar\sidebar.exe /autoRun
04 - HKU\S-1-5-21-2156171716-556064924-1487977086-1000\..\Run : [DAEMON Tools Lite] "C:\Program Files (x86)\DAEMON Tools Lite\DTLite.exe" -autorun
04 - HKU\S-1-5-21-2156171716-556064924-1487977086-1000\..\Run : [Spotify Web Helper] "C:\Users\Arnaud\AppData\Roaming\Spotify\Data\SpotifyWebHelper.exe"
04 - HKU\S-1-5-21-2156171716-556064924-1487977086-1000\..\Run : [Spotify] "C:\Users\Arnaud\AppData\Roaming\Spotify\spotify.exe" /uri spotify:autostart
04 - HKU\S-1-5-21-2156171716-556064924-1487977086-1000\..\Run : [jawawv] "C:\Program Files (x86)\Java\jre7\bin\javaw.exe" -jar "C:\Users\Arnaud\AppData\Local\Temp\jawawv5708567619355446635.jar"
04 - HKU\S-1-5-19\..\RunOnce : [mctadmin] C:\Windows\System32\mctadmin.exe
04 - HKU\S-1-5-20\..\RunOnce : [mctadmin] C:\Windows\System32\mctadmin.exe
04 - HKU\S-1-5-18\..\RunOnce : [SPReview] "C:\Windows\System32\SPReview\SPReview.exe" /sp:1 /errorfwlink:"
http://go.microsoft.com/fwlink/?LinkID=122915" /build:7601
################## | C:\ %SystemDrive% - Disque Fixe (NTFS) |
[10/07/2014 - 12:33:47 | ASH | 9407388 Ko] - C:\hiberfil.sys
[10/07/2014 - 12:33:50 | ASH | 12543184 Ko] - C:\pagefile.sys
[03/01/2014 - 03:56:26 | N | 1 Ko] - C:\.rnd
[08/10/2013 - 17:21:42 | N | 3 Ko] - C:\RHDSetup.log
[08/10/2013 - 17:21:42 | N | 0 Ko] - C:\Install.log
[08/10/2013 - 17:23:47 | N | 0 Ko] - C:\csb.log
[13/03/2014 - 21:41:43 | N | 297 Ko] - C:\PA207.DAT
[26/12/2013 - 19:54:41 | SHD] - C:\$Recycle.Bin
[26/05/2014 - 17:18:02 | N | 1 Ko] - C:\PhysicalDisk0_MBR.bin
[14/07/2009 - 05:20:08 | D] - C:\PerfLogs
[14/07/2009 - 07:08:56 | SHD] - C:\Documents and Settings
[08/10/2013 - 17:14:00 | SHD] - C:\Recovery
[08/10/2013 - 17:20:11 | D] - C:\Intel
[09/12/2013 - 12:38:32 | D] - C:\World of Warcraft
[20/12/2013 - 21:01:05 | D] - C:\Riot Games
[05/01/2014 - 18:23:47 | N | 0 Ko] - C:\07D2F7CEAC4F
[05/01/2014 - 18:23:47 | N | 0 Ko] - C:\B14CF3A4CA9A
[10/01/2014 - 12:39:08 | D] - C:\wamp
[17/01/2014 - 01:08:14 | D] - C:\Données EuroSoft Software Development
[23/01/2014 - 23:01:58 | D] - C:\downloads
[18/02/2014 - 21:17:44 | D] - C:\NVIDIA
[20/03/2014 - 12:53:44 | D] - C:\Genius
[29/03/2014 - 11:05:48 | RHD] - C:\MSOCache
[06/04/2014 - 15:32:55 | D] - C:\OEMSettings
[25/04/2014 - 20:26:41 | D] - C:\FFOutput
[26/05/2014 - 18:51:20 | D] - C:\Fraps
[03/06/2014 - 11:50:29 | D] - C:\Games
[03/06/2014 - 18:13:42 | D] - C:\Program Files
[18/06/2014 - 20:23:39 | D] - C:\Users
[19/06/2014 - 09:36:50 | D] - C:\Windows
[07/07/2014 - 13:41:05 | HD] - C:\ProgramData
[07/07/2014 - 14:13:11 | D] - C:\Program Files (x86)
[10/07/2014 - 03:00:25 | SHD] - C:\System Volume Information
[11/07/2014 - 02:06:13 | D] - C:\UsbFix
################## | E:\ - Disque USB (FAT32) |
[19/06/2014 - 17:35:18 | N | 533785 Ko] - E:\[
www.OMGTORRENT.com] The.Walking.Dead.S04E11.FRENCH.LD.HDTV.x264-AUTHORiTY.mp4
[19/06/2014 - 17:40:12 | N | 383955 Ko] - E:\[
www.OMGTORRENT.com] The.Walking.Dead.S04E12.FRENCH.LD.HDTV.x264-AUTHORiTY.mp4
[01/06/2014 - 10:52:34 | D] - E:\Site AuCookieToutCuit
[20/06/2014 - 23:02:02 | D] - E:\saison 3 vostfr
[25/06/2014 - 22:51:34 | D] - E:\cours info
################## | Vaccin |
E:\Autorun.inf - Vaccin créé par UsbFix (El Desaparecido)
################## | E.O.F | http://www.sosvirus.net/ | http://www.usbfix.net/ |