############################## | UsbFix V 7.162 | [Recherche]
Utilisateur: pedro (Administrateur) # PEDRO-PC
Mis à jour le 27/01/2014 par El Desaparecido - Team SosVirus
Lancé à 13:52:16 | 31/01/2014
Site Web :
http://www.usbfix.net
Changelog :
http://www.usbfix.net/maj/
Support :
http://www.sosvirus.net/
Upload Malware :
http://www.sosvirus.net/upload_malware.php
Contact :
http://www.usbfix.net/contact/
PC: ASUSTeK Computer INC. (P5Q Premium)
CPU: Intel(R) Core(TM)2 Quad CPU Q8300 @ 2.50GHz
RAM - [Total : 3327 Mo| Free : 1906 Mo]
Bios: American Megatrends Inc.
Boot: Normal boot
OS: Microsoft Windows 7 Édition Intégrale (6.1.7601 32-Bit) Service Pack 1
WB: Windows Internet Explorer : 11.0.9600.16476
WB: Google Chrome : 32.0.1700.102
SC: Security Center [Enabled]
WU: Windows Update [Enabled]
AV: Microsoft Security Essentials [(!) Disabled | Updated]
AS: Windows Defender [(!) Disabled | Updated]
AS: Microsoft Security Essentials [(!) Disabled | Updated]
FW: Windows FireWall [(!) Disabled]
AS: Malwarebytes' Anti-Malware : 1.75.0001
C:\ (%systemdrive%) - Disque fixe # 68 Go (27 Go libre(s) - 39%) [] # NTFS
D:\ - Disque fixe # 100 Mo (86 Mo libre(s) - 86%) [Réservé au système] # NTFS
E:\ - Disque fixe # 156 Go (146 Go libre(s) - 94%) [disque local] # NTFS
F:\ - Disque fixe # 195 Go (127 Go libre(s) - 65%) [] # NTFS
G:\ - Disque fixe # 202 Go (199 Go libre(s) - 99%) [] # NTFS
H:\ - CD-ROM
I:\ - CD-ROM
J:\ - Disque amovible # 7 Go (24 Mo libre(s) - 0%) [] # FAT32
K:\ - Disque amovible # 15 Go (6 Go libre(s) - 39%) [KINGSTON] # FAT32
L:\ - Disque amovible # 15 Go (15 Go libre(s) - 99%) [KINGSTON] # NTFS
M:\ - Disque fixe # 931 Go (722 Go libre(s) - 78%) [HD-PCT1TU3/BB-EU] # NTFS
################## | Processus Actif |
C:\Windows\system32\csrss.exe (ID: 452 |ParentID: 376)
C:\Windows\system32\wininit.exe (ID: 524 |ParentID: 376)
C:\Windows\system32\csrss.exe (ID: 532 |ParentID: 516)
C:\Windows\system32\services.exe (ID: 572 |ParentID: 524)
C:\Windows\system32\lsass.exe (ID: 600 |ParentID: 524)
C:\Windows\system32\lsm.exe (ID: 616 |ParentID: 524)
C:\Windows\system32\winlogon.exe (ID: 636 |ParentID: 516)
C:\Windows\system32\svchost.exe (ID: 748 |ParentID: 572)
C:\Windows\system32\nvvsvc.exe (ID: 824 |ParentID: 572)
C:\Program Files\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe (ID: 848 |ParentID: 572)
C:\Windows\system32\svchost.exe (ID: 892 |ParentID: 572)
C:\Program Files\Microsoft Security Client\MsMpEng.exe (ID: 956 |ParentID: 572)
C:\Windows\System32\svchost.exe (ID: 1028 |ParentID: 572)
C:\Windows\System32\svchost.exe (ID: 1068 |ParentID: 572)
C:\Windows\system32\svchost.exe (ID: 1108 |ParentID: 572)
C:\Windows\system32\svchost.exe (ID: 1132 |ParentID: 572)
C:\Windows\system32\svchost.exe (ID: 1268 |ParentID: 572)
C:\Windows\Explorer.EXE (ID: 1568 |ParentID: 1556)
C:\Windows\system32\Dwm.exe (ID: 1612 |ParentID: 1068)
C:\Windows\system32\svchost.exe (ID: 1640 |ParentID: 572)
C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe (ID: 1652 |ParentID: 824)
C:\Windows\system32\nvvsvc.exe (ID: 1664 |ParentID: 824)
C:\Windows\System32\spoolsv.exe (ID: 1908 |ParentID: 572)
C:\Windows\system32\svchost.exe (ID: 1944 |ParentID: 572)
C:\Windows\system32\taskhost.exe (ID: 2004 |ParentID: 572)
C:\Program Files\Common Files\Adobe\ARM\1.0\armsvc.exe (ID: 520 |ParentID: 572)
C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe (ID: 360 |ParentID: 572)
C:\Program Files\Bonjour\mDNSResponder.exe (ID: 876 |ParentID: 572)
C:\Windows\system32\taskeng.exe (ID: 1304 |ParentID: 1132)
C:\Users\pedro\AppData\Roaming\Orange\OrangeInside\one\OrangeInside.exe (ID: 1696 |ParentID: 1304)
C:\Users\pedro\AppData\Local\CrossLoop\CrossLoopService.exe (ID: 1976 |ParentID: 572)
C:\Program Files\Orange\Assistance Livebox\dedicarz\DedicarzService.exe (ID: 2064 |ParentID: 572)
C:\Windows\system32\taskeng.exe (ID: 2076 |ParentID: 1132)
C:\Program Files\Microsoft Mouse and Keyboard Center\itype.exe (ID: 2112 |ParentID: 2076)
C:\Program Files\Orange\Orange Installer\OrangeInstaller.exe (ID: 2160 |ParentID: 1304)
C:\Program Files\Microsoft Mouse and Keyboard Center\ipoint.exe (ID: 2212 |ParentID: 2076)
C:\Program Files\Google\Update\1.3.22.3\GoogleCrashHandler.exe (ID: 2220 |ParentID: 1228)
C:\Windows\system32\svchost.exe (ID: 2328 |ParentID: 572)
C:\Program Files\Malwarebytes' Anti-Malware\mbamscheduler.exe (ID: 2364 |ParentID: 572)
C:\Program Files\Malwarebytes' Anti-Malware\mbamservice.exe (ID: 2536 |ParentID: 572)
C:\Program Files\NVIDIA Corporation\NetService\NvNetworkService.exe (ID: 2560 |ParentID: 572)
C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe (ID: 2608 |ParentID: 572)
C:\Program Files\Malwarebytes' Anti-Malware\mbamgui.exe (ID: 2640 |ParentID: 2536)
C:\Windows\system32\rundll32.exe (ID: 2740 |ParentID: 2724)
C:\Windows\system32\svchost.exe (ID: 2752 |ParentID: 572)
C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE (ID: 2792 |ParentID: 572)
C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe (ID: 2948 |ParentID: 2792)
C:\Program Files\Microsoft Security Client\msseces.exe (ID: 3104 |ParentID: 1568)
C:\Program Files\NVIDIA Corporation\NVIDIA Update Core\NvTmru.exe (ID: 3120 |ParentID: 1568)
C:\Program Files\Renesas Electronics\USB 3.0 Host Controller Driver\Application\nusb3mon.exe (ID: 3160 |ParentID: 1568)
C:\Program Files\Canon\MyPrinter\BJMYPRT.EXE (ID: 3288 |ParentID: 1568)
C:\Program Files\Canon\Solution Menu EX\CNSEMAIN.EXE (ID: 3332 |ParentID: 1568)
C:\Program Files\Canon\Canon IJ Network Scan Utility\CNMNSUT.exe (ID: 3344 |ParentID: 1568)
C:\Program Files\Logitech\LWS\Webcam Software\LWS.exe (ID: 3376 |ParentID: 1568)
C:\Program Files\Common Files\Java\Java Update\jusched.exe (ID: 3384 |ParentID: 1568)
C:\Program Files\Nero\Nero 10\Nero BackItUp\NBAgent.exe (ID: 3412 |ParentID: 1568)
C:\Program Files\Logitech\LWS\Webcam Software\CameraHelperShell.exe (ID: 3544 |ParentID: 3376)
C:\Program Files\NVIDIA Corporation\Update Core\NvBackend.exe (ID: 3880 |ParentID: 1568)
C:\Windows\system32\SearchIndexer.exe (ID: 3976 |ParentID: 572)
C:\Program Files\Ad Muncher\AdMunch.exe (ID: 3268 |ParentID: 1568)
C:\Program Files\Logitech\SetPointP\SetPoint.exe (ID: 3768 |ParentID: 1568)
C:\Program Files\iTunes\iTunesHelper.exe (ID: 4004 |ParentID: 1568)
C:\Program Files\IncrediMail\Bin\IncMail.exe (ID: 3460 |ParentID: 1568)
C:\Program Files\Windows Sidebar\sidebar.exe (ID: 3464 |ParentID: 1568)
C:\Program Files\Common Files\Apple\Internet Services\iCloudServices.exe (ID: 1964 |ParentID: 1568)
C:\Windows\system32\svchost.exe (ID: 4024 |ParentID: 572)
C:\Program Files\Common Files\Apple\Internet Services\AppleIEDAV.exe (ID: 1380 |ParentID: 1568)
C:\Program Files\NVIDIA Corporation\Display\nvtray.exe (ID: 4012 |ParentID: 1652)
C:\Program Files\Common Files\Apple\Internet Services\ApplePhotoStreams.exe (ID: 3616 |ParentID: 1568)
C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe (ID: 5512 |ParentID: 2608)
C:\Windows\system32\conhost.exe (ID: 5880 |ParentID: 532)
C:\Program Files\iPod\bin\iPodService.exe (ID: 5892 |ParentID: 572)
C:\Windows\System32\svchost.exe (ID: 4088 |ParentID: 572)
C:\Program Files\Common Files\Apple\Internet Services\APSDaemon.exe (ID: 4836 |ParentID: 748)
C:\Program Files\Common Files\LogiShrd\KHAL3\KHALMNPR.EXE (ID: 3872 |ParentID: 3768)
C:\Program Files\IncrediMail\Bin\ImApp.exe (ID: 2416 |ParentID: 748)
C:\Program Files\Windows Media Player\wmpnetwk.exe (ID: 5180 |ParentID: 572)
C:\Windows\system32\DllHost.exe (ID: 4976 |ParentID: 748)
C:\Program Files\Google\Chrome\Application\chrome.exe (ID: 4560 |ParentID: 1568)
C:\Program Files\Google\Chrome\Application\chrome.exe (ID: 6296 |ParentID: 4560)
C:\Program Files\Google\Chrome\Application\chrome.exe (ID: 7984 |ParentID: 4560)
C:\Program Files\Google\Chrome\Application\chrome.exe (ID: 6728 |ParentID: 4560)
C:\Program Files\Google\Chrome\Application\chrome.exe (ID: 6996 |ParentID: 4560)
C:\Program Files\Diskeeper Corporation\Diskeeper\DkService.exe (ID: 8120 |ParentID: 572)
C:\Program Files\Nero\Update\NASvc.exe (ID: 6988 |ParentID: 572)
C:\Program Files\Logitech\SetPointP\LogiAppBroker.exe (ID: 6660 |ParentID: 3768)
C:\Windows\system32\svchost.exe (ID: 6212 |ParentID: 572)
C:\Windows\system32\taskeng.exe (ID: 2356 |ParentID: 1132)
C:\Windows\System32\WUDFHost.exe (ID: 5772 |ParentID: 1068)
C:\Windows\system32\wbem\wmiprvse.exe (ID: 4704 |ParentID: 748)
C:\Windows\system32\wbem\wmiprvse.exe (ID: 4148 |ParentID: 748)
C:\Windows\System32\svchost.exe (ID: 764 |ParentID: 572)
################## | Regedit Run |
04 - HKCU\..\Run : [IncrediMail] C:\Program Files\IncrediMail\bin\IncMail.exe /c
04 - HKCU\..\Run : [Sidebar] C:\Program Files\Windows Sidebar\sidebar.exe /autoRun
04 - HKCU\..\Run : [iCloudServices] C:\Program Files\Common Files\Apple\Internet Services\iCloudServices.exe
04 - HKCU\..\Run : [Orange Installer] "C:\Program Files\Orange\Orange Installer\OrangeInstaller.exe"
04 - HKCU\..\Run : [AppleIEDAV] C:\Program Files\Common Files\Apple\Internet Services\AppleIEDAV.exe
04 - HKCU\..\Run : [ApplePhotoStreams] C:\Program Files\Common Files\Apple\Internet Services\ApplePhotoStreams.exe
04 - HKCU\..\Run : [OrangeInside] C:\Users\pedro\AppData\Roaming\Orange\OrangeInside\one\OrangeInside.exe
04 - HKCU\..\Run : [FileHippo.com] "C:\Program Files\FileHippo.com\UpdateChecker.exe" /background
04 - HKLM\..\Run : [MSC] "C:\Program Files\Microsoft Security Client\msseces.exe" -hide -runkey
04 - HKLM\..\Run : [TaskTray]
04 - HKLM\..\Run : [Nvtmru] "C:\Program Files\NVIDIA Corporation\NVIDIA Update Core\nvtmru.exe"
04 - HKLM\..\Run : [NUSB3MON] "C:\Program Files\Renesas Electronics\USB 3.0 Host Controller Driver\Application\nusb3mon.exe"
04 - HKLM\..\Run : [CanonMyPrinter] C:\Program Files\Canon\MyPrinter\BJMyPrt.exe /logon
04 - HKLM\..\Run : [CanonSolutionMenuEx] C:\Program Files\Canon\Solution Menu EX\CNSEMAIN.EXE /logon
04 - HKLM\..\Run : [IJNetworkScanUtility] C:\Program Files\Canon\Canon IJ Network Scan Utility\CNMNSUT.exe
04 - HKLM\..\Run : [Adobe ARM] "C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
04 - HKLM\..\Run : [APSDaemon] "C:\Program Files\Common Files\Apple\Apple Application Support\APSDaemon.exe"
04 - HKLM\..\Run : [LWS] C:\Program Files\Logitech\LWS\Webcam Software\LWS.exe -hide
04 - HKLM\..\Run : [SunJavaUpdateSched] "C:\Program Files\Common Files\Java\Java Update\jusched.exe"
04 - HKLM\..\Run : [NBAgent] "C:\Program Files\Nero\Nero 10\Nero BackItUp\NBAgent.exe" /WinStart
04 - HKLM\..\Run : [ShadowPlay] C:\Windows\system32\rundll32.exe C:\Windows\system32\nvspcap.dll,ShadowPlayOnSystemStart
04 - HKLM\..\Run : [Logitech Download Assistant] C:\Windows\system32\rundll32.exe C:\Windows\System32\LogiLDA.dll,LogiFetch
04 - HKLM\..\Run : [NvBackend] "C:\Program Files\NVIDIA Corporation\Update Core\NvBackend.exe"
04 - HKLM\..\Run : [Ad Muncher] "C:\Program Files\Ad Muncher\AdMunch.exe" /bt
04 - HKLM\..\Run : [EvtMgr6] C:\Program Files\Logitech\SetPointP\SetPoint.exe /launchGaming
04 - HKLM\..\Run : [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
04 - HKLM\..\RunOnce : []
04 - HKU\S-1-5-19\..\Run : [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun
04 - HKU\S-1-5-20\..\Run : [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun
04 - HKU\S-1-5-21-2821299863-210336899-258489231-1001\..\Run : [IncrediMail] C:\Program Files\IncrediMail\bin\IncMail.exe /c
04 - HKU\S-1-5-21-2821299863-210336899-258489231-1001\..\Run : [Sidebar] C:\Program Files\Windows Sidebar\sidebar.exe /autoRun
04 - HKU\S-1-5-21-2821299863-210336899-258489231-1001\..\Run : [iCloudServices] C:\Program Files\Common Files\Apple\Internet Services\iCloudServices.exe
04 - HKU\S-1-5-21-2821299863-210336899-258489231-1001\..\Run : [Orange Installer] "C:\Program Files\Orange\Orange Installer\OrangeInstaller.exe"
04 - HKU\S-1-5-21-2821299863-210336899-258489231-1001\..\Run : [AppleIEDAV] C:\Program Files\Common Files\Apple\Internet Services\AppleIEDAV.exe
04 - HKU\S-1-5-21-2821299863-210336899-258489231-1001\..\Run : [ApplePhotoStreams] C:\Program Files\Common Files\Apple\Internet Services\ApplePhotoStreams.exe
04 - HKU\S-1-5-21-2821299863-210336899-258489231-1001\..\Run : [OrangeInside] C:\Users\pedro\AppData\Roaming\Orange\OrangeInside\one\OrangeInside.exe
04 - HKU\S-1-5-21-2821299863-210336899-258489231-1001\..\Run : [FileHippo.com] "C:\Program Files\FileHippo.com\UpdateChecker.exe" /background
04 - HKU\S-1-5-19\..\RunOnce : [mctadmin] C:\Windows\System32\mctadmin.exe
04 - HKU\S-1-5-20\..\RunOnce : [mctadmin] C:\Windows\System32\mctadmin.exe
04 - HKU\S-1-5-18\..\RunOnce : [SPReview] "C:\Windows\System32\SPReview\SPReview.exe" /sp:1 /errorfwlink:"
http://go.microsoft.com/fwlink/?LinkID=122915" /build:7601
################## | Recherche générique |
################## | Registre |
################## | Vaccin |
J:\Autorun.inf - Vaccin créé par UsbFix (El Desaparecido)
################## | E.O.F |
http://www.usbfix.net -
http://www.sosvirus.net |