Voilà le rapport de suppression:
############################## | UsbFix V 7.161 | [Suppression]
Utilisateur: STEPHANE (Administrateur) # STEPHANEPETRY
Mis à jour le 15/01/2014 par El Desaparecido - Team SosVirus
Lancé à 21:36:10 | 16/01/2014
Site Web :
http://www.usbfix.net
Changelog :
http://www.usbfix.net/maj/
Support :
http://www.sosvirus.net/
Upload Malware :
http://www.sosvirus.net/upload_malware.php
Contact :
http://www.usbfix.net/contact/
PC: ASUSTeK Computer INC. (P5Q SE PLUS)
CPU: Processeur Intel Pentium III Xeon
RAM - [Total : 2047 Mo| Free : 1262 Mo]
Bios: American Megatrends Inc.
Boot: Normal boot
OS: Microsoft Windows XP Professionnel (5.1.2600 32-Bit) Service Pack 3
WB: Windows Internet Explorer : 8.0.6001.18702
SC: Security Center Service [Enabled]
WU: Windows Update Service [Enabled]
AS: Malwarebytes' Anti-Malware : 1.75.0001
FW: Windows FireWall Service [Enabled]
C:\ (%systemdrive%) - Disque fixe # 176 Go (41 Go libre(s) - 23%) [] # NTFS
D:\ - Disque fixe # 98 Go (63 Go libre(s) - 65%) [DONNEES] # NTFS
E:\ - CD-ROM
S:\ - Disque fixe # 25 Go (21 Go libre(s) - 84%) [SAUVEGARDE] # NTFS
################## | Processus Stoppés |
Stoppé! C:\Program Files\AVAST Software\Avast\AvastSvc.exe (ID: 1524 |ParentID: 928)
Stoppé! C:\WINDOWS\system32\spoolsv.exe (ID: 1740 |ParentID: 928)
Stoppé! C:\Program Files\Fichiers communs\Apple\Mobile Device Support\AppleMobileDeviceService.exe (ID: 1812 |ParentID: 928)
Stoppé! C:\ASUS.SYS\config\DVMExportService.exe (ID: 2036 |ParentID: 928)
Stoppé! C:\Program Files\Seagate\SeagateManager\Sync\FreeAgentService.exe (ID: 184 |ParentID: 928)
Stoppé! C:\Documents and Settings\All Users\Application Data\Freemake\FreemakeUtilsService\FreemakeUtilsService.exe (ID: 236 |ParentID: 928)
Stoppé! C:\WINDOWS\Explorer.EXE (ID: 564 |ParentID: 480)
Stoppé! C:\Program Files\Canon\IJPLM\IJPLMSVC.EXE (ID: 820 |ParentID: 928)
Stoppé! C:\Program Files\Java\jre7\bin\jqs.exe (ID: 860 |ParentID: 928)
Stoppé! C:\Program Files\Fichiers communs\LightScribe\LSSrvc.exe (ID: 1080 |ParentID: 928)
Stoppé! C:\Program Files\ma-config.com\MaConfigAgent.exe (ID: 1228 |ParentID: 928)
Stoppé! C:\Program Files\M-Audio\Audiophile USB\MAUSBAPInst.exe (ID: 1244 |ParentID: 928)
Stoppé! C:\Program Files\Malwarebytes' Anti-Malware\mbamscheduler.exe (ID: 1660 |ParentID: 928)
Stoppé! C:\Program Files\Nero\Update\NASvc.exe (ID: 432 |ParentID: 928)
Stoppé! C:\WINDOWS\system32\nvsvc32.exe (ID: 632 |ParentID: 928)
Stoppé! C:\Program Files\Fichiers communs\Ulead Systems\DVD\ULCDRSvr.exe (ID: 2336 |ParentID: 928)
Stoppé! C:\WINDOWS\system32\SearchIndexer.exe (ID: 2396 |ParentID: 928)
Stoppé! C:\Program Files\Windows Media Player\WMPNetwk.exe (ID: 2716 |ParentID: 928)
Stoppé! C:\WINDOWS\explorer.exe (ID: 3704 |ParentID: 3676)
Stoppé! C:\WINDOWS\system32\wbem\wmiapsrv.exe (ID: 3540 |ParentID: 928)
Stoppé! C:\WINDOWS\System32\alg.exe (ID: 188 |ParentID: 928)
Stoppé! C:\Users\Public\conhost.exe (ID: 828 |ParentID: 564)
Stoppé! C:\Program Files\ASUS\EPU-4 Engine\FourEngine.exe (ID: 4024 |ParentID: 564)
Stoppé! C:\WINDOWS\system32\RunDLL32.exe (ID: 4012 |ParentID: 564)
Stoppé! C:\Program Files\NVIDIA Corporation\NVIDIA Update Core\nvtmru.exe (ID: 1276 |ParentID: 564)
Stoppé! C:\Program Files\AVAST Software\Avast\AvastUI.exe (ID: 3488 |ParentID: 564)
Stoppé! C:\Users\Public\conhost.exe (ID: 3248 |ParentID: 564)
Stoppé! C:\WINDOWS\system32\DeltTray.exe (ID: 3628 |ParentID: 564)
Stoppé! C:\Users\Public\conhost.exe (ID: 3636 |ParentID: 564)
Stoppé! C:\WINDOWS\system32\CTFMON.EXE (ID: 3652 |ParentID: 564)
Stoppé! C:\Users\Public\conhost.exe (ID: 3848 |ParentID: 564)
Stoppé! C:\PROGRA~1\MI3AA1~1\wcescomm.exe (ID: 3888 |ParentID: 564)
Stoppé! C:\PROGRA~1\MI3AA1~1\rapimgr.exe (ID: 3676 |ParentID: 1128)
Stoppé! C:\Program Files\Hercules\WiFi Station\WifiStation.exe (ID: 3064 |ParentID: 564)
Stoppé! C:\Documents and Settings\STEPHANE.STEPHANE\Menu Démarrer\Programmes\Démarrage\conhost.exe (ID: 1952 |ParentID: 564)
Stoppé! C:\Program Files\Fichiers communs\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPSVC.EXE (ID: 2076 |ParentID: 928)
Stoppé! C:\WINDOWS\system32\SearchProtocolHost.exe (ID: 5252 |ParentID: 2396)
Stoppé! C:\WINDOWS\system32\SearchFilterHost.exe (ID: 6104 |ParentID: 2396)
################## | Regedit Run |
04 - HKLM\..\Run : [Six Engine] "C:\Program Files\ASUS\EPU-4 Engine\FourEngine.exe" -b
04 - HKLM\..\Run : [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
04 - HKLM\..\Run : [NvMediaCenter] RunDLL32.exe NvMCTray.dll,NvTaskbarInit -login
04 - HKLM\..\Run : [Nvtmru] "C:\Program Files\NVIDIA Corporation\NVIDIA Update Core\nvtmru.exe"
04 - HKLM\..\Run : [UVS10 Preload] C:\Program Files\Ulead Systems\Ulead VideoStudio SE DVD\uvPL.exe
04 - HKLM\..\Run : [AvastUI.exe] "C:\Program Files\AVAST Software\Avast\AvastUI.exe" /nogui
04 - HKLM\..\Run : [nwiz] C:\Program Files\NVIDIA Corporation\nview\nwiz.exe /installquiet
04 - HKLM\..\Run : [RZN] C:\Users\Public\conhost.exe
04 - HKLM\..\Run : [SSBkgdUpdate] "C:\Program Files\Fichiers communs\Scansoft Shared\SSBkgdUpdate\SSBkgdupdate.exe" -Embedding -boot
04 - HKLM\..\Run : [DeltTray] DeltTray.exe
04 - HKLM\..\RunOnce : []
04 - HKLM\..\Policies\Explorer\run : [DOJ] C:\Users\Public\conhost.exe
04 - HKLM\Software\Microsoft\Windows NT\CurrentVersion\Terminal Server\Install\..\RunOnce : []
04 - HKU\S-1-5-21-436374069-57989841-839522115-1003\..\Run : [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
04 - HKU\S-1-5-21-436374069-57989841-839522115-1003\..\Run : [Google Update] "C:\Documents and Settings\STEPHANE\Local Settings\Application Data\Google\Update\GoogleUpdate.exe" /c
04 - HKU\S-1-5-21-436374069-57989841-839522115-1003\..\Run : [APS] C:\Users\Public\conhost.exe
04 - HKU\S-1-5-21-436374069-57989841-839522115-1003\..\Run : [H/PC Connection Agent] "C:\PROGRA~1\MI3AA1~1\wcescomm.exe"
04 - HKU\S-1-5-21-436374069-57989841-839522115-1003\..\Policies\Explorer\run : [DOJ] C:\Users\Public\conhost.exe
################## | Recherche générique |
Supprimé! C:\Documents and Settings\STEPHANE.STEPHANE\Application Data\STEPHANEv3.4.2.2.vbs
Supprimé! C:\Documents and Settings\STEPHANE.STEPHANE\Menu Démarrer\Programmes\Démarrage\conhost.exe
Supprimé! C:\Documents and Settings\STEPHANE.STEPHANE\Application Data\00041219\15-01-2014
Supprimé! C:\Documents and Settings\STEPHANE.STEPHANE\Application Data\00041219\16-01-2014
Supprimé! C:\Documents and Settings\STEPHANE.STEPHANE\Application Data\00041219\ak.tmp
Supprimé! C:\Documents and Settings\STEPHANE.STEPHANE\Application Data\00041219
Supprimé! C:\DOCUME~1\STEPHA~1.ST~\LOCALS~1\Temp\STEPHANE7
Supprimé! C:\DOCUME~1\STEPHA~1.ST~\LOCALS~1\Temp\STEPHANE8
Supprimé! C:\Documents and Settings\STEPHANE.STEPHANE\Application Data\STEPHANE-wchelper.dll
Supprimé! C:\System Volume Information\_restore{4FCC4763-D456-41E6-8F1C-E47DEE86B237}\RP17\A0030493.vbs
Supprimé! C:\System Volume Information\_restore{4FCC4763-D456-41E6-8F1C-E47DEE86B237}\RP18\A0030537.vbs
Supprimé! C:\System Volume Information\_restore{4FCC4763-D456-41E6-8F1C-E47DEE86B237}\RP19\A0030591.vbs
Supprimé! C:\System Volume Information\_restore{4FCC4763-D456-41E6-8F1C-E47DEE86B237}\RP19\A0030629.vbs
Supprimé! C:\System Volume Information\_restore{4FCC4763-D456-41E6-8F1C-E47DEE86B237}\RP19\A0030632.vbs
Supprimé! C:\System Volume Information\_restore{4FCC4763-D456-41E6-8F1C-E47DEE86B237}\RP21\A0032295.vbs
(!) Fichiers temporaires supprimés.
################## | Registre |
Supprimé! HKLM\SOFTWARE\Microsoft\Active Setup\Installed Components\{LD5BC301-7F16-1V42-F3VP-8K4PC23067A5}
Supprimé! HKCU\SOFTWARE\Microsoft\Active Setup\Installed Components\{LD5BC301-7F16-1V42-F3VP-8K4PC23067A5}
Supprimé! HKCU\Software\Holaa
Supprimé! HKU\S-1-5-21-436374069-57989841-839522115-1003\Software\Microsoft\Windows\CurrentVersion\Run|APS
Supprimé! HKU\S-1-5-21-436374069-57989841-839522115-1003\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\Run|DOJ
Supprimé! HKLM\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\Run|DOJ
Supprimé! HKLM\Software\Microsoft\Windows\CurrentVersion\Run|RZN
################## | UsbFix - Information |
UsbFix a détecté sur votre ordinateur, une infection qui dispose d'une fonction de Keylogger.
Après désinfection par UsbFix, veuillez modifier tous vos mots de passe.
Si vous avez effectué des achats sur internet,
veuillez contacter votre banque afin d'envisager une opposition sur votre carte bancaire.
Info :
http://www.sosvirus.net/infection-dinih ... t4852.html
################## | Listing |
[16/01/2014 - 12:44:13 | D] - C:\AdwCleaner
[25/05/2010 - 22:46:46 | D] - C:\ASUS.000
[04/12/2009 - 22:44:46 | D] - C:\ASUS.SYS
[08/01/2014 - 21:23:16 | D] - C:\AVAST Software
[15/01/2014 - 19:43:20 | RASH | 0 Ko] - C:\boot.ini
[05/08/2004 - 13:00:00 | | 5 Ko] - C:\Bootfont.bin
[21/06/2011 - 14:47:58 | D] - C:\Brother
[13/01/2013 - 18:59:40 | D] - C:\Clarity
[06/08/2010 - 23:38:28 | D] - C:\cmdcons
[08/01/2014 - 18:04:05 | | 27 Ko | 53925A7DA3D0899799DD20D5723D5A53] - C:\ComboFix.txt
[15/01/2014 - 22:18:32 | D] - C:\Config.Msi
[09/01/2014 - 17:30:00 | | 1 Ko | 95C83DF14F462AFC39CA8E68BA8BA55A] - C:\DelFix.txt
[15/01/2014 - 21:57:59 | D] - C:\Documents and Settings
[05/12/2009 - 10:42:47 | D] - C:\dvmexp
[16/01/2014 - 12:55:28 | N | 0 Ko] - C:\dvmexp.idx
[24/11/2010 - 18:23:45 | D] - C:\extensions
[19/03/2010 - 20:56:28 | D] - C:\found.000
[29/11/2009 - 21:59:16 | D] - C:\Intel
[29/11/2009 - 21:53:58 | | 0 Ko] - C:\IO.SYS
[08/01/2014 - 21:23:16 | D] - C:\Logs
[29/11/2009 - 21:53:58 | | 0 Ko] - C:\MSDOS.SYS
[29/11/2009 - 22:26:54 | RD] - C:\MSOCache
[01/07/2013 - 18:17:07 | D] - C:\MyWorks
[05/08/2004 - 13:00:00 | N | 46 Ko | B2DE3452DE03674C6CEC68B8C8CE7C78] - C:\NTDETECT.COM
[30/11/2009 - 00:37:52 | RASH | 246 Ko] - C:\ntldr
[16/01/2014 - 12:45:07 | ASH | 2095104 Ko] - C:\pagefile.sys
[09/01/2014 - 23:59:34 | | 1 Ko] - C:\PhysicalDisk0_MBR.bin
[11/01/2014 - 11:02:47 | D] - C:\Program Files
[04/12/2009 - 23:14:27 | D] - C:\PSFONTS
[08/01/2014 - 21:23:31 | D] - C:\Qoobox
[08/01/2014 - 22:40:52 | SHD] - C:\RECYCLER
[05/01/2014 - 18:12:44 | D] - C:\RegBackup
[11/01/2014 - 20:20:07 | | 8 Ko | 8530B43AC4D478B62ABAF6F7E3BBC31B] - C:\SeafLog.txt
[02/02/2011 - 17:27:43 | D] - C:\Spybot - Search Destroy
[05/01/2014 - 15:56:31 | SHD] - C:\System Volume Information
[05/01/2014 - 15:27:19 | D] - C:\temp
[16/01/2014 - 21:36:12 | D] - C:\UsbFix
[16/01/2014 - 21:40:29 | A | 10 Ko | A05AED910D88D0C91BC957C66A0550EE] - C:\UsbFix [Clean 1] STEPHANEPETRY.txt
[15/01/2014 - 18:16:30 | | 7 Ko | 3C9859257759C2886BB60EB035849EE4] - C:\UsbFix [Scan 1] STEPHANEPETRY.txt
[30/12/2013 - 13:03:59 | D] - C:\Users
[16/01/2014 - 12:45:15 | D] - C:\WINDOWS
[11/01/2014 - 19:37:14 | D] - C:\_OTM
[29/11/2009 - 22:44:07 | DC] - D:\ABLETON LIVE6
[27/12/2013 - 19:36:55 | DC] - D:\FILMS
[28/12/2013 - 11:00:00 | DC] - D:\Livres-Ero.-M1-cinéma
[28/12/2013 - 11:00:47 | DC] - D:\M1-Cinéma-Amandine
[20/12/2010 - 21:28:18 | DC] - D:\Maman
[06/08/2010 - 22:06:44 | DC] - D:\MASTER
[13/01/2014 - 23:51:14 | DC] - D:\MUSE
[21/09/2013 - 16:50:29 | SHDC] - D:\RECYCLER
[13/04/2008 - 19:34:30 | C | 28 Ko | 3680B9069C435DD7EE9DBEC2214F8E97] - D:\setupSNK.exe
[24/12/2009 - 12:34:35 | DC] - D:\SMRTNTKY
[13/10/2013 - 22:40:04 | DC] - D:\Stef
[14/02/2013 - 16:30:06 | SHD] - D:\System Volume Information
[30/11/2009 - 01:15:08 | C | 5643187 Ko] - S:\BackupSYSTEME291109.bkf
[29/11/2009 - 22:40:47 | C | 0 Ko | FD737EB78301BBF3689C6967D5C6D8CA] - S:\CLE AVAST ANTIVIRUS.txt
[30/11/2009 - 17:06:49 | C | 0 Ko | 4A88E510D9D5B18213A21859406CA7B7] - S:\LICENCE XP PRO.txt
[21/09/2013 - 16:50:29 | SHDC] - S:\RECYCLER
[14/02/2013 - 16:30:06 | SHD] - S:\System Volume Information
[01/12/2009 - 17:38:42 | C | 2 Ko] - S:\WinfoKeys_01_12_2009.html
################## | Vaccin |
D:\Autorun.inf - Vaccin créé par UsbFix (El Desaparecido)
S:\Autorun.inf - Vaccin créé par UsbFix (El Desaparecido)
################## | E.O.F |
http://www.usbfix.net -
http://www.sosvirus.net |