bonjour bonjour!!
voici le rapport:
############################## | UsbFix V 7.176 | [Recherche]
Utilisateur: colinebio (Administrateur) # BLACKPEARL
Mis à jour le 18/07/2014 par El Desaparecido - SosVirus
Lancé à 09:14:19 | 26/07/2014
Site Web :
http://www.usbfix.net/
Changelog :
http://www.usbfix.net/maj/
Assistance :
http://www.sosvirus.net/
Upload Malware :
http://www.sosvirus.net/upload_malware.php
Contact :
http://www.usbfix.net/contact/
################## | System information |
CPU: Intel(R) Core(TM)2 CPU T5500 @ 1.66GHz
RAM - [Total : 1022 Mo | Free : 296 Mo]
Boot: Normal boot
OS: Microsoft Windows XP (5.1.2600 32-Bit) Service Pack 3
WB: Internet Explorer : 6.00.2900.5512
WB: Mozilla Firefox : 31.0
################## | Security Information |
FW: Windows Firewall [Actif]
SC: Security Center [Actif]
WU: Windows Update [Actif]
################## | Disk Information |
C:\ (%SystemDrive%) - Disque fixe # 93 Go (59 Go libre(s) - 64%) [] # NTFS
D:\ - Disque fixe # 279 Go (21 Go libre(s) - 8%) [KG-DO300GB] # FAT32
E:\ - Disque amovible # 250 Mo (248 Mo libre(s) - 99%) [] # FAT
G:\ - Disque amovible # 7 Go (388 Mo libre(s) - 5%) [PERRIERCL] # NTFS
H:\ - Disque amovible # 7 Go (6 Go libre(s) - 78%) [] # FAT32
################## | Processus Actif |
C:\WINDOWS\system32\smss.exe (ID: 748|ParentID: 4|SYSTEM)
C:\WINDOWS\system32\winlogon.exe (ID: 828|ParentID: 748|SYSTEM)
C:\WINDOWS\system32\services.exe (ID: 872|ParentID: 828|SYSTEM)
C:\WINDOWS\system32\lsass.exe (ID: 884|ParentID: 828|SYSTEM)
C:\WINDOWS\system32\svchost.exe (ID: 1096|ParentID: 872|SYSTEM)
C:\WINDOWS\system32\svchost.exe (ID: 1200|ParentID: 872|SYSTEM)
C:\Program Files\Intel\Wireless\Bin\EvtEng.exe (ID: 1256|ParentID: 872|SYSTEM)
C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe (ID: 1344|ParentID: 872|SYSTEM)
C:\WINDOWS\system32\spoolsv.exe (ID: 1792|ParentID: 872|SYSTEM)
C:\Program Files\Toshiba\ConfigFree\CFSvcs.exe (ID: 1900|ParentID: 872|SYSTEM)
C:\WINDOWS\ehome\ehrecvr.exe (ID: 1936|ParentID: 872|SYSTEM)
C:\WINDOWS\ehome\ehSched.exe (ID: 1952|ParentID: 872|SYSTEM)
C:\Program Files\Java\jre7\bin\jqs.exe (ID: 2024|ParentID: 872|SYSTEM)
C:\WINDOWS\system32\nvsvc32.exe (ID: 232|ParentID: 872|SYSTEM)
C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe (ID: 296|ParentID: 872|SYSTEM)
C:\WINDOWS\system32\svchost.exe (ID: 608|ParentID: 872|SYSTEM)
C:\Program Files\Toshiba\TOSHIBA Applet\TAPPSRV.exe (ID: 632|ParentID: 872|SYSTEM)
C:\Program Files\Fichiers communs\Ulead Systems\DVD\ULCDRSvr.exe (ID: 652|ParentID: 872|SYSTEM)
C:\PROGRA~1\COMMON~1\X10\Common\X10nets.exe (ID: 692|ParentID: 872|SYSTEM)
C:\WINDOWS\system32\msiexec.exe (ID: 1724|ParentID: 872|SYSTEM)
C:\WINDOWS\explorer.exe (ID: 2864|ParentID: 2728|colinebio)
C:\WINDOWS\ehome\ehtray.exe (ID: 3104|ParentID: 2864|colinebio)
C:\WINDOWS\ehome\ehmsas.exe (ID: 3164|ParentID: 1096|colinebio)
C:\WINDOWS\system32\rundll32.exe (ID: 3188|ParentID: 2864|colinebio)
C:\WINDOWS\system32\rundll32.exe (ID: 3196|ParentID: 3180|colinebio)
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe (ID: 3204|ParentID: 2864|colinebio)
C:\WINDOWS\RTHDCPL.exe (ID: 3224|ParentID: 2864|colinebio)
C:\Program Files\Synaptics\SynTP\Toshiba.exe (ID: 3232|ParentID: 3204|colinebio)
C:\WINDOWS\agrsmmsg.exe (ID: 3272|ParentID: 2864|colinebio)
C:\Program Files\Toshiba\TOSHIBA Applet\THotkey.exe (ID: 3300|ParentID: 2864|colinebio)
C:\WINDOWS\system32\TPSMain.exe (ID: 3308|ParentID: 2864|colinebio)
C:\Program Files\Toshiba\ConfigFree\NDSTray.exe (ID: 3464|ParentID: 2864|colinebio)
C:\Program Files\Toshiba\Tvs\TvsTray.exe (ID: 3480|ParentID: 2864|colinebio)
C:\Program Files\Toshiba\Utilitaire de zoom TOSHIBA\SmoothView.exe (ID: 3492|ParentID: 2864|colinebio)
C:\WINDOWS\system32\TPSBattM.exe (ID: 3504|ParentID: 3308|colinebio)
C:\Program Files\Toshiba\Commandes TOSHIBA\TFncKy.exe (ID: 3536|ParentID: 2864|colinebio)
C:\WINDOWS\system32\DLA\DLACTRLW.EXE (ID: 3552|ParentID: 2864|colinebio)
C:\Program Files\Intel\Wireless\Bin\ZCfgSvc.exe (ID: 3560|ParentID: 2864|colinebio)
C:\Program Files\Intel\Wireless\Bin\iFrmewrk.exe (ID: 3628|ParentID: 2864|colinebio)
C:\Program Files\DAEMON Tools\daemon.exe (ID: 3660|ParentID: 2864|colinebio)
C:\Program Files\Fichiers communs\Java\Java Update\jusched.exe (ID: 3760|ParentID: 2864|colinebio)
C:\WINDOWS\system32\ctfmon.exe (ID: 3868|ParentID: 2864|colinebio)
C:\Program Files\Toshiba\TOSCDSPD\TOSCDSPD.exe (ID: 3888|ParentID: 2864|colinebio)
C:\Program Files\Intel\Wireless\Bin\Dot1XCfg.exe (ID: 2768|ParentID: 1096|colinebio)
C:\Program Files\Mozilla Firefox\firefox.exe (ID: 3088|ParentID: 2864|colinebio)
C:\WINDOWS\system32\wuauclt.exe (ID: 2548|ParentID: 1200|colinebio)
C:\Program Files\Fichiers communs\Java\Java Update\jucheck.exe (ID: 2472|ParentID: 3760|colinebio)
C:\UsbFix\UsbFix.exe (ID: 3212|ParentID: 2376|colinebio)
################## | Autorun |
################## | Regedit Run |
F2 - HKLM\..\Winlogon : [Shell] Explorer.exe
F2 - HKLM\..\Winlogon : [Userinit] C:\WINDOWS\system32\userinit.exe,
F3 - HKCU\..\Winlogon : [Shell] Explorer.exe
04 - HKCU\..\Run : [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
04 - HKCU\..\Run : [TOSCDSPD] C:\Program Files\TOSHIBA\TOSCDSPD\toscdspd.exe
04 - HKLM\..\Run : [ehTray] C:\WINDOWS\ehome\ehtray.exe
04 - HKLM\..\Run : [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
04 - HKLM\..\Run : [nwiz] nwiz.exe /installquiet /keeploaded /nodetect
04 - HKLM\..\Run : [NVRotateSysTray] rundll32.exe C:\WINDOWS\system32\nvsysrot.dll,Enable
04 - HKLM\..\Run : [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
04 - HKLM\..\Run : [RTHDCPL] RTHDCPL.EXE
04 - HKLM\..\Run : [Alcmtr] ALCMTR.EXE
04 - HKLM\..\Run : [AGRSMMSG] AGRSMMSG.exe
04 - HKLM\..\Run : [THotkey] C:\Program Files\Toshiba\Toshiba Applet\thotkey.exe
04 - HKLM\..\Run : [TPSMain] TPSMain.exe
04 - HKLM\..\Run : [NDSTray.exe] NDSTray.exe
04 - HKLM\..\Run : [Tvs] C:\Program Files\TOSHIBA\Tvs\TvsTray.exe
04 - HKLM\..\Run : [SmoothView] C:\Program Files\TOSHIBA\Utilitaire de zoom TOSHIBA\SmoothView.exe
04 - HKLM\..\Run : [TFncKy] TFncKy.exe
04 - HKLM\..\Run : [DLA] C:\WINDOWS\System32\DLA\DLACTRLW.EXE
04 - HKLM\..\Run : [IntelZeroConfig] "C:\Program Files\Intel\Wireless\bin\ZCfgSvc.exe"
04 - HKLM\..\Run : [IntelWireless] "C:\Program Files\Intel\Wireless\Bin\ifrmewrk.exe" /tf Intel PROSet/Wireless
04 - HKLM\..\Run : [DAEMON Tools] "C:\Program Files\DAEMON Tools\daemon.exe" -lang 1033
04 - HKLM\..\Run : [CFSServ.exe] CFSServ.exe -NoClient
04 - HKLM\..\Run : [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
04 - HKLM\..\Run : [Ulead Quick-Drop] "C:\Program Files\Ulead Systems\Ulead DVD MovieFactory 5\Ulead DVD MovieFactory 5\Quick-Drop.exe" WINDOWCALL
04 - HKLM\..\Run : [SunJavaUpdateSched] "C:\Program Files\Fichiers communs\Java\Java Update\jusched.exe"
04 - HKU\S-1-5-19\..\Run : [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE
04 - HKU\S-1-5-20\..\Run : [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE
04 - HKU\S-1-5-21-3329346852-2869397574-2443377332-1005\..\Run : [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
04 - HKU\S-1-5-21-3329346852-2869397574-2443377332-1005\..\Run : [TOSCDSPD] C:\Program Files\TOSHIBA\TOSCDSPD\toscdspd.exe
04 - HKU\S-1-5-18\..\Run : [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE
################## | Recherche générique |
Présent! C:\RECYCLER\S-1-5-21-4371220185-5097117163-079012875-6601\Desktop.ini
Présent! C:\RECYCLER\S-1-5-21-4371220185-5097117163-079012875-6601\djwi2kcew.exe
Présent! C:\RECYCLER\S-1-5-21-4371220185-5097117163-079012875-6601
Présent! D:\t.com
################## | Registre |
################## | E.O.F | http://www.sosvirus.net/ | http://www.usbfix.net/ |
A+
Co