Bonjour,
Voilà le rapport d'USBFix :
############################## | UsbFix V 7.078 | [Suppression]
Utilisateur: patte (Administrateur) # PC-DE-PATTE
Mis à jour le 06/01/2012 par El Desaparecido
Lancé à 08:10:12 | 20/01/2012
Site Web:
http://eldesaparecido.com
Fichier suspect ? :
http://eldesaparecido.com/upload.html
Contact: contact@eldesaparecido.com
PC: Hewlett-Packard (HP Pavilion dv6000 (GH906EA#ABF) ) (X86-based PC) # Notebook
CPU: Genuine Intel(R) CPU T2130 @ 1.86GHz (1867)
RAM -> [ Total : 2037 | Free : 1107 ]
BIOS: Ver 1.00PARTTBLv
BOOT: Normal boot
OS: Microsoft® Windows Vista(TM) Édition Familiale Premium (6.0.6000 32-Bit) #
WB: Windows Internet Explorer 7.0.6000.17037
SC: Security Center Service [ Enabled ]
WU: Windows Update Service [ Enabled ]
FW: Windows FireWall Service [ Enabled ]
C:\ (%systemdrive%) -> Disque fixe # 142 Go (61 Go libre(s) - 43%) [] # NTFS
D:\ -> Disque fixe # 7 Go (2 Go libre(s) - 30%) [HP_RECOVERY] # NTFS
E:\ -> CD-ROM
F:\ -> CD-ROM
################## | Processus Actif |
C:\Windows\system32\csrss.exe (580)
C:\Windows\system32\wininit.exe (620)
C:\Windows\system32\csrss.exe (632)
C:\Windows\system32\services.exe (664)
C:\Windows\system32\lsass.exe (676)
C:\Windows\system32\lsm.exe (684)
C:\Windows\system32\winlogon.exe (756)
C:\Windows\system32\svchost.exe (872)
C:\Windows\system32\svchost.exe (940)
C:\Windows\System32\svchost.exe (996)
C:\Windows\System32\svchost.exe (1064)
C:\Windows\System32\svchost.exe (1100)
C:\Windows\system32\svchost.exe (1112)
C:\Windows\system32\SLsvc.exe (1272)
C:\Windows\system32\svchost.exe (1312)
C:\Windows\system32\svchost.exe (1516)
C:\Program Files\Alwil Software\Avast5\AvastSvc.exe (1628)
C:\Windows\System32\spoolsv.exe (1952)
C:\Windows\system32\svchost.exe (1976)
C:\Windows\system32\Dwm.exe (1500)
C:\Windows\system32\taskeng.exe (1440)
C:\Windows\Explorer.EXE (732)
C:\Program Files\HP\QuickPlay\Kernel\TV\CLCapSvc.exe (936)
C:\Windows\system32\svchost.exe (1292)
C:\Program Files\Common Files\LightScribe\LSSrvc.exe (1020)
C:\Windows\System32\svchost.exe (2140)
C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe (2192)
C:\Program Files\Sony\PMB\PMBDeviceInfoProvider.exe (2260)
C:\Windows\System32\svchost.exe (2288)
C:\Windows\system32\svchost.exe (2300)
C:\Windows\system32\svchost.exe (2320)
C:\Windows\System32\svchost.exe (2348)
C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE (2364)
C:\Windows\system32\SearchIndexer.exe (2432)
C:\Windows\system32\DRIVERS\xaudio.exe (2532)
C:\Program Files\HP\QuickPlay\Kernel\TV\CLSched.exe (2696)
C:\Windows\system32\igfxsrvc.exe (2988)
C:\Program Files\Windows Defender\MSASCui.exe (2996)
C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe (3072)
C:\Windows\System32\hkcmd.exe (3096)
C:\Windows\System32\igfxpers.exe (3148)
C:\Program Files\Hp\HP Software Update\hpwuschd2.exe (3212)
C:\Program Files\Hp\QuickPlay\QPService.exe (3228)
C:\Program Files\Hewlett-Packard\HP Health Check\HPHC_Scheduler.exe (3268)
C:\Program Files\Hewlett-Packard\HP Wireless Assistant\HPWAMain.exe (3308)
C:\Program Files\Hewlett-Packard\HP Wireless Assistant\WiFiMsg.exe (3364)
C:\Program Files\Java\jre6\bin\jusched.exe (3424)
C:\Program Files\Adobe\Reader 8.0\Reader\reader_sl.exe (3468)
C:\Program Files\Sony\PMB\PMBVolumeWatcher.exe (3528)
C:\Program Files\Alwil Software\Avast5\AvastUI.exe (3536)
C:\Program Files\Windows Sidebar\sidebar.exe (3624)
C:\Windows\ehome\ehtray.exe (3648)
C:\Windows\System32\p2phost.exe (3772)
C:\Windows\ehome\ehmsas.exe (3844)
C:\Program Files\DAEMON Tools Lite\daemon.exe (3908)
C:\Program Files\Windows Media Player\wmpnscfg.exe (3932)
C:\Program Files\PC Tools Security\SpamMonitor\PCTools Email Toolbars\WLMailApiAgent.exe (3972)
C:\Program Files\Windows Media Player\wmpnetwk.exe (4064)
C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpqtra08.exe (4088)
C:\Users\patte\AppData\Roaming\Dropbox\bin\Dropbox.exe (2336)
C:\Windows\system32\wbem\unsecapp.exe (2604)
C:\Windows\system32\wbem\wmiprvse.exe (3120)
C:\Windows\system32\SearchProtocolHost.exe (3644)
C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpqSTE08.exe (3320)
C:\Windows\system32\SearchFilterHost.exe (3700)
C:\Program Files\Hewlett-Packard\HP Health Check\hphc_service.exe (3408)
C:\UsbFix\Go.exe (3500)
C:\Program Files\Malwarebytes' Anti-Malware\mbamservice.exe (3144)
C:\Windows\system32\wbem\wmiprvse.exe (2888)
################## | Processus Stoppés |
Stoppé! C:\Windows\system32\SLsvc.exe (1272)
Stoppé! C:\Program Files\Alwil Software\Avast5\AvastSvc.exe (1628)
Stoppé! C:\Windows\System32\spoolsv.exe (1952)
Stoppé! C:\Windows\system32\taskeng.exe (1440)
Stoppé! C:\Program Files\HP\QuickPlay\Kernel\TV\CLCapSvc.exe (936)
Stoppé! C:\Program Files\Common Files\LightScribe\LSSrvc.exe (1020)
Stoppé! C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe (2192)
Stoppé! C:\Program Files\Sony\PMB\PMBDeviceInfoProvider.exe (2260)
Stoppé! C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE (2364)
Stoppé! C:\Windows\system32\SearchIndexer.exe (2432)
Stoppé! C:\Windows\system32\DRIVERS\xaudio.exe (2532)
Stoppé! C:\Program Files\HP\QuickPlay\Kernel\TV\CLSched.exe (2696)
Stoppé! C:\Windows\system32\igfxsrvc.exe (2988)
Stoppé! C:\Program Files\Windows Defender\MSASCui.exe (2996)
Stoppé! C:\Windows\System32\hkcmd.exe (3096)
Stoppé! C:\Windows\System32\igfxpers.exe (3148)
Stoppé! C:\Program Files\Hp\HP Software Update\hpwuschd2.exe (3212)
Stoppé! C:\Program Files\Hp\QuickPlay\QPService.exe (3228)
Stoppé! C:\Program Files\Hewlett-Packard\HP Health Check\HPHC_Scheduler.exe (3268)
Stoppé! C:\Program Files\Hewlett-Packard\HP Wireless Assistant\HPWAMain.exe (3308)
Stoppé! C:\Program Files\Hewlett-Packard\HP Wireless Assistant\WiFiMsg.exe (3364)
Stoppé! C:\Program Files\Java\jre6\bin\jusched.exe (3424)
Stoppé! C:\Program Files\Adobe\Reader 8.0\Reader\reader_sl.exe (3468)
Stoppé! C:\Program Files\Sony\PMB\PMBVolumeWatcher.exe (3528)
Stoppé! C:\Program Files\Alwil Software\Avast5\AvastUI.exe (3536)
Stoppé! C:\Program Files\Windows Sidebar\sidebar.exe (3624)
Stoppé! C:\Windows\ehome\ehtray.exe (3648)
Stoppé! C:\Windows\System32\p2phost.exe (3772)
Stoppé! C:\Windows\ehome\ehmsas.exe (3844)
Stoppé! C:\Program Files\DAEMON Tools Lite\daemon.exe (3908)
Stoppé! C:\Program Files\Windows Media Player\wmpnscfg.exe (3932)
Stoppé! C:\Program Files\PC Tools Security\SpamMonitor\PCTools Email Toolbars\WLMailApiAgent.exe (3972)
Stoppé! C:\Program Files\Windows Media Player\wmpnetwk.exe (4064)
Stoppé! C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpqtra08.exe (4088)
Stoppé! C:\Users\patte\AppData\Roaming\Dropbox\bin\Dropbox.exe (2336)
Stoppé! C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpqSTE08.exe (3320)
Stoppé! C:\Program Files\Hewlett-Packard\HP Health Check\hphc_service.exe (3408)
Stoppé! C:\Program Files\Malwarebytes' Anti-Malware\mbamservice.exe (3144)
################## | Éléments infectieux |
Supprimé! C:\$RECYCLE.BIN\S-1-5-20
Supprimé! C:\$RECYCLE.BIN\S-1-5-21-413226321-3452886260-426709285-500
Supprimé! C:\$RECYCLE.BIN\S-1-5-21-834615786-450031599-1885179410-1000
Supprimé! C:\$RECYCLE.BIN\S-1-5-21-834615786-450031599-1885179410-500
Supprimé! D:\$RECYCLE.BIN\S-1-5-21-834615786-450031599-1885179410-1000
(!) Fichiers temporaires supprimés.
################## | Registre |
Supprimé! HKCU\Software\Microsoft\Windows\CurrentVersion\Policies\System|DisableTaskMgr
Supprimé! HKCU\Software\Microsoft\Windows\CurrentVersion\Policies\explorer|NoClose
Supprimé! HKLM\Software\Microsoft\Windows\CurrentVersion\Run|MSConfig
################## | Mountpoints2 |
Supprimé! HKCU\.\.\.\.\Explorer\MountPoints2\{41067a11-52d2-11df-ab44-001b24518d96}
Supprimé! HKCU\.\.\.\.\Explorer\MountPoints2\{5e122ff6-5e11-11dc-a876-001b24518d96}
Supprimé! HKCU\.\.\.\.\Explorer\MountPoints2\{755fa1f1-c4a8-11de-a30e-001b24518d96}
Supprimé! HKCU\.\.\.\.\Explorer\MountPoints2\{7d3920a7-aef8-11dc-82ff-001b24518d96}
Supprimé! HKCU\.\.\.\.\Explorer\MountPoints2\{7f8336ea-1b74-11dd-9da5-001b24518d96}
Supprimé! HKCU\.\.\.\.\Explorer\MountPoints2\{a09f0467-13f4-11e0-ac94-001b24518d96}
Supprimé! HKCU\.\.\.\.\Explorer\MountPoints2\{a5d0a21c-037d-11df-b080-001b24518d96}
Supprimé! HKCU\.\.\.\.\Explorer\MountPoints2\{a5d0a235-037d-11df-b080-001b24518d96}
Supprimé! HKCU\.\.\.\.\Explorer\MountPoints2\{a5d0a27f-037d-11df-b080-001b24518d96}
Supprimé! HKCU\.\.\.\.\Explorer\MountPoints2\{bbbad2af-daa3-11de-9591-001b24518d96}
Supprimé! HKCU\.\.\.\.\Explorer\MountPoints2\{bd38465b-0233-11e1-949e-001b24518d96}
Supprimé! HKCU\.\.\.\.\Explorer\MountPoints2\{c9fc43ab-1536-11e1-a0de-001b24518d96}
Supprimé! HKCU\.\.\.\.\Explorer\MountPoints2\{e3973ec4-23e8-11e0-bbd7-001b24518d96}
Supprimé! HKCU\.\.\.\.\Explorer\MountPoints2\{e79a67cf-c4ab-11de-9cce-001b24518d96}
Supprimé! HKCU\.\.\.\.\Explorer\MountPoints2\{ead25746-72b0-11dd-9bdf-001b24518d96}
################## | Listing |
[20/01/2012 - 08:20:04 | SHD ] C:\$RECYCLE.BIN
[15/01/2012 - 23:12:28 | N | 27625] C:\AdwCleaner[R1].txt
[16/01/2012 - 00:49:47 | N | 1770] C:\AdwCleaner[R2].txt
[15/01/2012 - 23:13:52 | N | 27805] C:\AdwCleaner[S1].txt
[15/01/2012 - 23:17:32 | N | 753] C:\AdwCleaner[S2].txt
[15/01/2012 - 23:56:50 | N | 1186] C:\AdwCleaner[S3].txt
[16/01/2012 - 00:50:06 | N | 1377] C:\AdwCleaner[S4].txt
[18/01/2012 - 22:01:18 | N | 1475] C:\AdwCleaner[S5].txt
[21/04/2007 - 20:55:46 | N | 74] C:\autoexec.bat
[24/11/2005 - 15:25:22 | D ] C:\boot
[02/11/2006 - 04:53:57 | RASH | 438840] C:\bootmgr
[19/01/2012 - 19:10:45 | D ] C:\Config.Msi
[18/09/2006 - 16:43:37 | N | 10] C:\config.sys
[17/04/2008 - 07:04:15 | N | 0] C:\conmgr.log
[02/11/2007 - 15:37:18 | N | 948] C:\debugInstaller.txt
[08/09/2007 - 08:09:33 | SHD ] C:\Documents and Settings
[05/11/2010 - 08:06:32 | D ] C:\extensions
[20/01/2012 - 08:06:33 | ASH | 2137055232] C:\hiberfil.sys
[21/04/2007 - 21:14:51 | D ] C:\HP
[13/10/2009 - 11:36:35 | N | 0] C:\IO.SYS
[13/10/2009 - 11:36:35 | N | 0] C:\MSDOS.SYS
[21/04/2007 - 20:27:25 | RHD ] C:\MSOCache
[20/01/2012 - 08:06:31 | ASH | 2450980864] C:\pagefile.sys
[19/01/2012 - 19:05:41 | D ] C:\Program Files
[15/01/2012 - 22:46:56 | HD ] C:\ProgramData
[08/01/2012 - 13:15:55 | D ] C:\rei
[21/04/2007 - 21:17:45 | N | 268] C:\sqmdata00.sqm
[21/04/2007 - 21:17:45 | N | 244] C:\sqmnoopt00.sqm
[08/09/2007 - 08:22:23 | D ] C:\SwSetup
[19/01/2012 - 19:06:13 | SHD ] C:\System Volume Information
[08/09/2007 - 08:22:23 | D ] C:\System.sav
[20/01/2012 - 08:20:04 | D ] C:\UsbFix
[20/01/2012 - 08:10:31 | A | 10707] C:\UsbFix.txt
[08/09/2007 - 08:14:01 | D ] C:\Users
[19/01/2012 - 19:05:36 | D ] C:\Windows
[19/01/2012 - 08:34:59 | D ] C:\ZHP
[20/01/2012 - 08:20:04 | SHD ] D:\$RECYCLE.BIN
[11/09/2005 - 10:18:54 | N | 340] D:\AUTOMODE
[08/09/2007 - 08:19:13 | N | 13] D:\BLOCK.RIN
[20/06/2007 - 04:45:17 | D ] D:\boot
[03/10/2006 - 18:02:44 | SH | 438328] D:\bootmgr
[03/11/2006 - 14:43:28 | SH | 117] D:\Desktop.ini
[10/09/2002 - 11:14:28 | N | 8134] D:\Folder.htt
[20/06/2007 - 04:45:17 | D ] D:\HP
[20/06/2007 - 03:05:14 | N | 698] D:\MASTER.LOG
[20/06/2007 - 04:45:17 | D ] D:\preload
[03/11/2005 - 10:19:52 | N | 181736] D:\protect.ed
[20/06/2007 - 04:45:17 | RD ] D:\RECOVERY
[20/06/2007 - 04:45:17 | D ] D:\SOURCES
[15/01/2012 - 22:38:18 | SHD ] D:\System Volume Information
[20/06/2007 - 04:45:18 | D ] D:\Tools
[20/06/2007 - 03:05:32 | N | 0] D:\USER
[20/06/2007 - 04:45:17 | D ] D:\WINDOWS
################## | Vaccin |
C:\Autorun.inf -> Vaccin créé par UsbFix (El Desaparecido)
D:\Autorun.inf -> Vaccin créé par UsbFix (El Desaparecido)
################## | Upload |
Veuillez envoyer le fichier: C:\UsbFix_Upload_Me_PC-DE-PATTE.zip
http://eldesaparecido.com/upload.html
Merci de votre contribution.
################## | E.O.F |
Et voilà le nouveau ZHP DIag :
http://pjjoint.malekal.com/files.php?id=ZHPDiag_20120120_e9p12j9z9x7
Merci !