- jeu. 3 avr. 2014 23:33
#117741
############################## | UsbFix V 7.169 | [Recherche]
Utilisateur: amine (Administrateur) # AMINE-PC
Mis à jour le 31/03/2014 par El Desaparecido - Team SosVirus
Lancé à 21:45:27 | 03/04/2014
Site Web : http://www.usbfix.net/
Changelog : http://www.usbfix.net/maj/
Support : http://www.sosvirus.net/forum-virus-securite.html
Upload Malware : http://www.sosvirus.net/upload_malware.php
Contact : http://www.usbfix.net/contact/
PC: Intel Corp. (Base Board Product Name)
CPU: Intel(R) Core(TM) i5-2410M CPU @ 2.30GHz
RAM - [Total : 4078 Mo| Free : 2432 Mo]
Bios: INSYDE
Boot: Normal boot
OS: Microsoft Windows 7 Edition Intégrale (6.1.7601 64-Bit) Service Pack 1
WB: Windows Internet Explorer : 8.0.7601.17514
WB: Mozilla Firefox : 26.0
SC: Security Center [Enabled]
WU: Windows Update [Enabled]
AV: avast! Antivirus [Enabled | Updated]
AS: avast! Antivirus [Enabled | Updated]
AS: Windows Defender [Enabled | (!) Outdated]
FW: Windows FireWall [Enabled]
C:\ (%systemdrive%) - Disque fixe # 349 Go (40 Go libre(s) - 11%) [] # NTFS
D:\ - Disque fixe # 350 Go (6 Go libre(s) - 2%) [Data] # NTFS
E:\ - CD-ROM
F:\ - CD-ROM
G:\ - CD-ROM
H:\ - Disque fixe # 931 Go (24 Go libre(s) - 3%) [AMINE] # FAT32
I:\ - Disque amovible # 974 Mo (973 Mo libre(s) - 100%) [] # FAT
################## | Processus Actif |
C:\Windows\system32\csrss.exe (ID: 456 |ParentID: 448)
C:\Windows\system32\wininit.exe (ID: 532 |ParentID: 448)
C:\Windows\system32\csrss.exe (ID: 556 |ParentID: 544)
C:\Windows\system32\services.exe (ID: 600 |ParentID: 532)
C:\Windows\system32\lsass.exe (ID: 620 |ParentID: 532)
C:\Windows\system32\lsm.exe (ID: 628 |ParentID: 532)
C:\Windows\system32\winlogon.exe (ID: 680 |ParentID: 544)
C:\Windows\system32\svchost.exe (ID: 772 |ParentID: 600)
C:\Windows\system32\nvvsvc.exe (ID: 844 |ParentID: 600)
C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe (ID: 868 |ParentID: 600)
C:\Windows\system32\svchost.exe (ID: 912 |ParentID: 600)
C:\Windows\System32\svchost.exe (ID: 1008 |ParentID: 600)
C:\Windows\System32\svchost.exe (ID: 316 |ParentID: 600)
C:\Windows\system32\svchost.exe (ID: 468 |ParentID: 600)
C:\Windows\system32\svchost.exe (ID: 1096 |ParentID: 600)
C:\Windows\system32\svchost.exe (ID: 1188 |ParentID: 600)
C:\Program Files\Alwil Software\Avast5\AvastSvc.exe (ID: 1332 |ParentID: 600)
C:\Windows\system32\WLANExt.exe (ID: 1340 |ParentID: 316)
C:\Windows\system32\conhost.exe (ID: 1348 |ParentID: 456)
C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe (ID: 1392 |ParentID: 844)
C:\Windows\system32\nvvsvc.exe (ID: 1400 |ParentID: 844)
C:\Windows\system32\Dwm.exe (ID: 1960 |ParentID: 316)
C:\Windows\System32\spoolsv.exe (ID: 1212 |ParentID: 600)
C:\Windows\system32\svchost.exe (ID: 1648 |ParentID: 600)
C:\Program Files (x86)\AskPartnerNetwork\Toolbar\apnmcp.exe (ID: 2012 |ParentID: 600)
C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe (ID: 2068 |ParentID: 600)
C:\Program Files\Bonjour\mDNSResponder.exe (ID: 2092 |ParentID: 600)
C:\Windows\system32\CxAudMsg64.exe (ID: 2140 |ParentID: 600)
C:\Program Files (x86)\NVIDIA Corporation\NetService\NvNetworkService.exe (ID: 2208 |ParentID: 600)
C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe (ID: 2392 |ParentID: 600)
C:\Windows\system32\svchost.exe (ID: 2488 |ParentID: 600)
C:\Windows\system32\TODDSrv.exe (ID: 2516 |ParentID: 600)
C:\Program Files (x86)\Common Files\Ulead Systems\DVD\ULCDRSvr.exe (ID: 2560 |ParentID: 600)
C:\Windows\system32\rundll32.exe (ID: 2608 |ParentID: 2592)
C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe (ID: 1948 |ParentID: 2392)
C:\Windows\system32\conhost.exe (ID: 2800 |ParentID: 556)
C:\Windows\System32\rundll32.exe (ID: 1816 |ParentID: 772)
C:\Windows\explorer.exe (ID: 3424 |ParentID: 2264)
C:\Windows\system32\SearchIndexer.exe (ID: 3756 |ParentID: 600)
C:\Windows\system32\svchost.exe (ID: 3180 |ParentID: 600)
C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe (ID: 1284 |ParentID: 600)
C:\Windows\System32\svchost.exe (ID: 2700 |ParentID: 600)
C:\Program Files\Windows Media Player\wmpnetwk.exe (ID: 1900 |ParentID: 600)
C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe (ID: 3656 |ParentID: 600)
C:\Windows\system32\svchost.exe (ID: 2196 |ParentID: 600)
C:\Program Files (x86)\Common Files\Apple\Internet Services\ApplePhotoStreams.exe (ID: 3996 |ParentID: 772)
C:\Windows\system32\WUDFHost.exe (ID: 1676 |ParentID: 316)
C:\Program Files (x86)\HSPA USB Modem\HSPA USB Modem.exe (ID: 3724 |ParentID: 3424)
C:\Program Files (x86)\HSPA USB Modem\HSPALauncher.exe (ID: 1996 |ParentID: 3724)
C:\Windows\system32\wbem\wmiprvse.exe (ID: 3968 |ParentID: 772)
C:\Program Files (x86)\Internet Download Manager\IDMan.exe (ID: 1300 |ParentID: 772)
C:\Program Files (x86)\Internet Download Manager\IEMonitor.exe (ID: 3504 |ParentID: 1300)
C:\Windows\explorer.exe (ID: 4304 |ParentID: 772)
C:\Program Files (x86)\Mozilla Firefox\firefox.exe (ID: 4920 |ParentID: 3424)
C:\Windows\system32\SearchProtocolHost.exe (ID: 3700 |ParentID: 3756)
C:\Windows\system32\SearchFilterHost.exe (ID: 4832 |ParentID: 3756)
C:\Windows\explorer.exe (ID: 2844 |ParentID: 772)
C:\Windows\system32\wbem\wmiprvse.exe (ID: 5116 |ParentID: 772)
################## | Regedit Run |
F2 - HKLM\..\Winlogon : [Shell] explorer.exe
F2 - [x64] HKLM\..\Winlogon : [Shell] explorer.exe
F2 - HKLM\..\Winlogon : [Userinit] userinit.exe
F2 - [x64] HKLM\..\Winlogon : [Userinit] C:\Windows\system32\userinit.exe,
04 - HKCU\..\Run : [IDMan] C:\Program Files (x86)\Internet Download Manager\IDMan.exe /onboot
04 - HKCU\..\Run : [DAEMON Tools Lite] "C:\Program Files (x86)\DAEMON Tools Lite\DTLite.exe" -autorun
04 - HKCU\..\Run : [LaunchList] C:\Program Files (x86)\Pinnacle\Studio 11\LaunchList2.exe
04 - HKCU\..\Run : [MediaDico] C:\Program Files (x86)\Micro Application\12 DICOS Indispensables\LanceMediaDICO12.exe Lancement
04 - HKLM\..\Run : [Adobe Reader Speed Launcher] "C:\Program Files (x86)\Adobe\Reader 9.0\Reader\Reader_sl.exe"
04 - HKLM\..\Run : [TWebCamera] "C:\Program Files (x86)\TOSHIBA\TOSHIBA Web Camera Application\TWebCamera.exe" autorun
04 - HKLM\..\Run : [ApnTBMon] "C:\Program Files (x86)\AskPartnerNetwork\Toolbar\Updater\TBNotifier.exe"
04 - HKLM\..\Run : [APSDaemon] "C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe"
04 - HKLM\..\Run : [iTunesHelper] "C:\Program Files (x86)\iTunes\iTunesHelper.exe"
04 - HKLM\..\Run : [HSPALauncher] C:\PROGRA~2\HSPAUS~1\HSPALA~1.EXE
04 - HKLM\..\Run : [UVS10 Preload] C:\Program Files (x86)\Ulead Systems\Ulead VideoStudio SE DVD\uvPL.exe
04 - HKLM\..\Run : [GrooveMonitor] "C:\Program Files (x86)\Microsoft Office\Office12\GrooveMonitor.exe"
04 - HKLM\..\Run : [avast5] "C:\Program Files\Alwil Software\Avast5\avastUI.exe" /nogui
04 - HKLM\..\RunOnce : []
04 - [x64] HKLM\..\Run : [SmartAudio] C:\Program Files\CONEXANT\SAII\SACpl.exe /t
04 - [x64] HKLM\..\Run : [Nvtmru] "C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\nvtmru.exe"
04 - [x64] HKLM\..\Run : [ShadowPlay] C:\Windows\system32\rundll32.exe C:\Windows\system32\nvspcap64.dll,ShadowPlayOnSystemStart
04 - [x64] HKLM\..\Run : [NvBackend] "C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvBackend.exe"
04 - [x64] HKLM\..\Run : [CNAP2 Launcher] C:\Windows\system32\spool\DRIVERS\x64\3\CNAP2LAK.EXE
04 - HKU\S-1-5-19\..\Run : [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun
04 - HKU\S-1-5-20\..\Run : [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun
04 - HKU\S-1-5-21-732240150-1205699937-1413452075-1000\..\Run : [IDMan] C:\Program Files (x86)\Internet Download Manager\IDMan.exe /onboot
04 - HKU\S-1-5-21-732240150-1205699937-1413452075-1000\..\Run : [DAEMON Tools Lite] "C:\Program Files (x86)\DAEMON Tools Lite\DTLite.exe" -autorun
04 - HKU\S-1-5-21-732240150-1205699937-1413452075-1000\..\Run : [LaunchList] C:\Program Files (x86)\Pinnacle\Studio 11\LaunchList2.exe
04 - HKU\S-1-5-21-732240150-1205699937-1413452075-1000\..\Run : [MediaDico] C:\Program Files (x86)\Micro Application\12 DICOS Indispensables\LanceMediaDICO12.exe Lancement
04 - HKU\S-1-5-19\..\RunOnce : [mctadmin] C:\Windows\System32\mctadmin.exe
04 - HKU\S-1-5-20\..\RunOnce : [mctadmin] C:\Windows\System32\mctadmin.exe
################## | Recherche générique |
################## | Registre |
################## | E.O.F | http://www.usbfix.net/ - http://www.sosvirus.net |
Utilisateur: amine (Administrateur) # AMINE-PC
Mis à jour le 31/03/2014 par El Desaparecido - Team SosVirus
Lancé à 21:45:27 | 03/04/2014
Site Web : http://www.usbfix.net/
Changelog : http://www.usbfix.net/maj/
Support : http://www.sosvirus.net/forum-virus-securite.html
Upload Malware : http://www.sosvirus.net/upload_malware.php
Contact : http://www.usbfix.net/contact/
PC: Intel Corp. (Base Board Product Name)
CPU: Intel(R) Core(TM) i5-2410M CPU @ 2.30GHz
RAM - [Total : 4078 Mo| Free : 2432 Mo]
Bios: INSYDE
Boot: Normal boot
OS: Microsoft Windows 7 Edition Intégrale (6.1.7601 64-Bit) Service Pack 1
WB: Windows Internet Explorer : 8.0.7601.17514
WB: Mozilla Firefox : 26.0
SC: Security Center [Enabled]
WU: Windows Update [Enabled]
AV: avast! Antivirus [Enabled | Updated]
AS: avast! Antivirus [Enabled | Updated]
AS: Windows Defender [Enabled | (!) Outdated]
FW: Windows FireWall [Enabled]
C:\ (%systemdrive%) - Disque fixe # 349 Go (40 Go libre(s) - 11%) [] # NTFS
D:\ - Disque fixe # 350 Go (6 Go libre(s) - 2%) [Data] # NTFS
E:\ - CD-ROM
F:\ - CD-ROM
G:\ - CD-ROM
H:\ - Disque fixe # 931 Go (24 Go libre(s) - 3%) [AMINE] # FAT32
I:\ - Disque amovible # 974 Mo (973 Mo libre(s) - 100%) [] # FAT
################## | Processus Actif |
C:\Windows\system32\csrss.exe (ID: 456 |ParentID: 448)
C:\Windows\system32\wininit.exe (ID: 532 |ParentID: 448)
C:\Windows\system32\csrss.exe (ID: 556 |ParentID: 544)
C:\Windows\system32\services.exe (ID: 600 |ParentID: 532)
C:\Windows\system32\lsass.exe (ID: 620 |ParentID: 532)
C:\Windows\system32\lsm.exe (ID: 628 |ParentID: 532)
C:\Windows\system32\winlogon.exe (ID: 680 |ParentID: 544)
C:\Windows\system32\svchost.exe (ID: 772 |ParentID: 600)
C:\Windows\system32\nvvsvc.exe (ID: 844 |ParentID: 600)
C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe (ID: 868 |ParentID: 600)
C:\Windows\system32\svchost.exe (ID: 912 |ParentID: 600)
C:\Windows\System32\svchost.exe (ID: 1008 |ParentID: 600)
C:\Windows\System32\svchost.exe (ID: 316 |ParentID: 600)
C:\Windows\system32\svchost.exe (ID: 468 |ParentID: 600)
C:\Windows\system32\svchost.exe (ID: 1096 |ParentID: 600)
C:\Windows\system32\svchost.exe (ID: 1188 |ParentID: 600)
C:\Program Files\Alwil Software\Avast5\AvastSvc.exe (ID: 1332 |ParentID: 600)
C:\Windows\system32\WLANExt.exe (ID: 1340 |ParentID: 316)
C:\Windows\system32\conhost.exe (ID: 1348 |ParentID: 456)
C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe (ID: 1392 |ParentID: 844)
C:\Windows\system32\nvvsvc.exe (ID: 1400 |ParentID: 844)
C:\Windows\system32\Dwm.exe (ID: 1960 |ParentID: 316)
C:\Windows\System32\spoolsv.exe (ID: 1212 |ParentID: 600)
C:\Windows\system32\svchost.exe (ID: 1648 |ParentID: 600)
C:\Program Files (x86)\AskPartnerNetwork\Toolbar\apnmcp.exe (ID: 2012 |ParentID: 600)
C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe (ID: 2068 |ParentID: 600)
C:\Program Files\Bonjour\mDNSResponder.exe (ID: 2092 |ParentID: 600)
C:\Windows\system32\CxAudMsg64.exe (ID: 2140 |ParentID: 600)
C:\Program Files (x86)\NVIDIA Corporation\NetService\NvNetworkService.exe (ID: 2208 |ParentID: 600)
C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe (ID: 2392 |ParentID: 600)
C:\Windows\system32\svchost.exe (ID: 2488 |ParentID: 600)
C:\Windows\system32\TODDSrv.exe (ID: 2516 |ParentID: 600)
C:\Program Files (x86)\Common Files\Ulead Systems\DVD\ULCDRSvr.exe (ID: 2560 |ParentID: 600)
C:\Windows\system32\rundll32.exe (ID: 2608 |ParentID: 2592)
C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe (ID: 1948 |ParentID: 2392)
C:\Windows\system32\conhost.exe (ID: 2800 |ParentID: 556)
C:\Windows\System32\rundll32.exe (ID: 1816 |ParentID: 772)
C:\Windows\explorer.exe (ID: 3424 |ParentID: 2264)
C:\Windows\system32\SearchIndexer.exe (ID: 3756 |ParentID: 600)
C:\Windows\system32\svchost.exe (ID: 3180 |ParentID: 600)
C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe (ID: 1284 |ParentID: 600)
C:\Windows\System32\svchost.exe (ID: 2700 |ParentID: 600)
C:\Program Files\Windows Media Player\wmpnetwk.exe (ID: 1900 |ParentID: 600)
C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe (ID: 3656 |ParentID: 600)
C:\Windows\system32\svchost.exe (ID: 2196 |ParentID: 600)
C:\Program Files (x86)\Common Files\Apple\Internet Services\ApplePhotoStreams.exe (ID: 3996 |ParentID: 772)
C:\Windows\system32\WUDFHost.exe (ID: 1676 |ParentID: 316)
C:\Program Files (x86)\HSPA USB Modem\HSPA USB Modem.exe (ID: 3724 |ParentID: 3424)
C:\Program Files (x86)\HSPA USB Modem\HSPALauncher.exe (ID: 1996 |ParentID: 3724)
C:\Windows\system32\wbem\wmiprvse.exe (ID: 3968 |ParentID: 772)
C:\Program Files (x86)\Internet Download Manager\IDMan.exe (ID: 1300 |ParentID: 772)
C:\Program Files (x86)\Internet Download Manager\IEMonitor.exe (ID: 3504 |ParentID: 1300)
C:\Windows\explorer.exe (ID: 4304 |ParentID: 772)
C:\Program Files (x86)\Mozilla Firefox\firefox.exe (ID: 4920 |ParentID: 3424)
C:\Windows\system32\SearchProtocolHost.exe (ID: 3700 |ParentID: 3756)
C:\Windows\system32\SearchFilterHost.exe (ID: 4832 |ParentID: 3756)
C:\Windows\explorer.exe (ID: 2844 |ParentID: 772)
C:\Windows\system32\wbem\wmiprvse.exe (ID: 5116 |ParentID: 772)
################## | Regedit Run |
F2 - HKLM\..\Winlogon : [Shell] explorer.exe
F2 - [x64] HKLM\..\Winlogon : [Shell] explorer.exe
F2 - HKLM\..\Winlogon : [Userinit] userinit.exe
F2 - [x64] HKLM\..\Winlogon : [Userinit] C:\Windows\system32\userinit.exe,
04 - HKCU\..\Run : [IDMan] C:\Program Files (x86)\Internet Download Manager\IDMan.exe /onboot
04 - HKCU\..\Run : [DAEMON Tools Lite] "C:\Program Files (x86)\DAEMON Tools Lite\DTLite.exe" -autorun
04 - HKCU\..\Run : [LaunchList] C:\Program Files (x86)\Pinnacle\Studio 11\LaunchList2.exe
04 - HKCU\..\Run : [MediaDico] C:\Program Files (x86)\Micro Application\12 DICOS Indispensables\LanceMediaDICO12.exe Lancement
04 - HKLM\..\Run : [Adobe Reader Speed Launcher] "C:\Program Files (x86)\Adobe\Reader 9.0\Reader\Reader_sl.exe"
04 - HKLM\..\Run : [TWebCamera] "C:\Program Files (x86)\TOSHIBA\TOSHIBA Web Camera Application\TWebCamera.exe" autorun
04 - HKLM\..\Run : [ApnTBMon] "C:\Program Files (x86)\AskPartnerNetwork\Toolbar\Updater\TBNotifier.exe"
04 - HKLM\..\Run : [APSDaemon] "C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe"
04 - HKLM\..\Run : [iTunesHelper] "C:\Program Files (x86)\iTunes\iTunesHelper.exe"
04 - HKLM\..\Run : [HSPALauncher] C:\PROGRA~2\HSPAUS~1\HSPALA~1.EXE
04 - HKLM\..\Run : [UVS10 Preload] C:\Program Files (x86)\Ulead Systems\Ulead VideoStudio SE DVD\uvPL.exe
04 - HKLM\..\Run : [GrooveMonitor] "C:\Program Files (x86)\Microsoft Office\Office12\GrooveMonitor.exe"
04 - HKLM\..\Run : [avast5] "C:\Program Files\Alwil Software\Avast5\avastUI.exe" /nogui
04 - HKLM\..\RunOnce : []
04 - [x64] HKLM\..\Run : [SmartAudio] C:\Program Files\CONEXANT\SAII\SACpl.exe /t
04 - [x64] HKLM\..\Run : [Nvtmru] "C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\nvtmru.exe"
04 - [x64] HKLM\..\Run : [ShadowPlay] C:\Windows\system32\rundll32.exe C:\Windows\system32\nvspcap64.dll,ShadowPlayOnSystemStart
04 - [x64] HKLM\..\Run : [NvBackend] "C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvBackend.exe"
04 - [x64] HKLM\..\Run : [CNAP2 Launcher] C:\Windows\system32\spool\DRIVERS\x64\3\CNAP2LAK.EXE
04 - HKU\S-1-5-19\..\Run : [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun
04 - HKU\S-1-5-20\..\Run : [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun
04 - HKU\S-1-5-21-732240150-1205699937-1413452075-1000\..\Run : [IDMan] C:\Program Files (x86)\Internet Download Manager\IDMan.exe /onboot
04 - HKU\S-1-5-21-732240150-1205699937-1413452075-1000\..\Run : [DAEMON Tools Lite] "C:\Program Files (x86)\DAEMON Tools Lite\DTLite.exe" -autorun
04 - HKU\S-1-5-21-732240150-1205699937-1413452075-1000\..\Run : [LaunchList] C:\Program Files (x86)\Pinnacle\Studio 11\LaunchList2.exe
04 - HKU\S-1-5-21-732240150-1205699937-1413452075-1000\..\Run : [MediaDico] C:\Program Files (x86)\Micro Application\12 DICOS Indispensables\LanceMediaDICO12.exe Lancement
04 - HKU\S-1-5-19\..\RunOnce : [mctadmin] C:\Windows\System32\mctadmin.exe
04 - HKU\S-1-5-20\..\RunOnce : [mctadmin] C:\Windows\System32\mctadmin.exe
################## | Recherche générique |
################## | Registre |
################## | E.O.F | http://www.usbfix.net/ - http://www.sosvirus.net |