et voila le rapport
############################## | UsbFix V 7.146 | [Suppression]
Utilisateur: philippe (Administrateur) # JULIEN
Mis à jour le 28/10/2013 par El Desaparecido - Team SosVirus
Lancé à 21:06:35 | 29/10/2013
Site Web: http://www.usbfix.net/
Forum : http://www.sosvirus.net/
Upload Malware: http://www.sosvirus.net/upload_malware.php
Contact: http://www.usbfix.net/contact/
PC: Gigabyte Technology Co., Ltd. (M61PME-S2P)
CPU: AMD Processor model unknown
RAM -> [Total : 2047 | Free : 1464]
Bios: Award Software International, Inc.
Boot: Normal boot
OS: Microsoft Windows XP Professionnel (5.1.2600 32-Bit) Service Pack 3
WB: Windows Internet Explorer : 8.0.6001.18702
SC: Security Center Service [Enabled]
WU: Windows Update Service [Enabled]
AS: Malwarebytes' Anti-Malware : 1.75.0001
FW: Windows FireWall Service [Enabled]
C:\ (%systemdrive%) -> Disque fixe # 128 Go (14 Go libre(s) - 11%) [] # NTFS
D:\ -> CD-ROM
E:\ -> CD-ROM
F:\ -> Disque amovible # 7 Go (800 Mo libre(s) - 11%) [JULIEN] # FAT32
################## | Processus Stoppés |
Stoppé! C:\WINDOWS\system32\Ati2evxx.exe (ID: 1188 |ParentID: 1012)
Stoppé! C:\Documents and Settings\All Users\Application Data\eSafe\eGdpSvc.exe (ID: 1624 |ParentID: 1012)
Stoppé! C:\WINDOWS\system32\Ati2evxx.exe (ID: 1928 |ParentID: 968)
Stoppé! C:\WINDOWS\Explorer.EXE (ID: 304 |ParentID: 280)
Stoppé! C:\WINDOWS\system32\spoolsv.exe (ID: 916 |ParentID: 1012)
Stoppé! C:\Program Files\Fichiers communs\ABBYY\FineReaderSprint\9.00\Licensing\NetworkLicenseServer.exe (ID: 364 |ParentID: 1012)
Stoppé! C:\Program Files\Fichiers communs\Apple\Mobile Device Support\AppleMobileDeviceService.exe (ID: 380 |ParentID: 1012)
Stoppé! C:\Program Files\Bonjour\mDNSResponder.exe (ID: 516 |ParentID: 1012)
Stoppé! C:\Program Files\Java\jre6\bin\jqs.exe (ID: 608 |ParentID: 1012)
Stoppé! C:\WINDOWS\system32\PnkBstrA.exe (ID: 1276 |ParentID: 1012)
Stoppé! C:\WINDOWS\system32\PnkBstrB.exe (ID: 1332 |ParentID: 1012)
Stoppé! C:\Documents and Settings\All Users\Application Data\Skype\Toolbars\Skype C2C Service\c2c_service.exe (ID: 1372 |ParentID: 1012)
Stoppé! C:\WINDOWS\System32\wbem\wmiapsrv.exe (ID: 2216 |ParentID: 1012)
Stoppé! C:\WINDOWS\system32\wscntfy.exe (ID: 2360 |ParentID: 1428)
Stoppé! C:\WINDOWS\RTHDCPL.EXE (ID: 3148 |ParentID: 304)
Stoppé! c:\Program Files\ATI Technologies\ATI.ACE\Core-Static\MOM.exe (ID: 3232 |ParentID: 3024)
Stoppé! C:\Program Files\DAEMON Tools\daemon.exe (ID: 3244 |ParentID: 304)
Stoppé! C:\Program Files\Fichiers communs\Java\Java Update\jusched.exe (ID: 3336 |ParentID: 304)
Stoppé! C:\Program Files\Fichiers communs\Adobe\ARM\1.0\AdobeARM.exe (ID: 3372 |ParentID: 304)
Stoppé! C:\Program Files\iTunes\iTunesHelper.exe (ID: 3432 |ParentID: 304)
Stoppé! C:\WINDOWS\system32\ctfmon.exe (ID: 3440 |ParentID: 304)
Stoppé! C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_FATIHJE.EXE (ID: 3648 |ParentID: 304)
Stoppé! C:\Program Files\Hercules\WiFi Station\WifiStation.exe (ID: 3708 |ParentID: 304)
Stoppé! C:\Program Files\OpenOffice.org 3\program\soffice.exe (ID: 3848 |ParentID: 3776)
Stoppé! C:\Program Files\iPod\bin\iPodService.exe (ID: 3912 |ParentID: 1012)
Stoppé! C:\Program Files\OpenOffice.org 3\program\soffice.bin (ID: 3940 |ParentID: 3848)
Stoppé! c:\Program Files\ATI Technologies\ATI.ACE\Core-Static\ccc.exe (ID: 556 |ParentID: 3232)
################## | Regedit Run |
HKLM\SOFTWARE | Run : [GEST] -
HKLM\SOFTWARE | Run : [ATICustomerCare] - "C:\Program Files\ATI\ATICustomerCare\ATICustomerCare.exe"
HKLM\SOFTWARE | Run : [StartCCC] - "c:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" MSRun
HKLM\SOFTWARE | Run : [RTHDCPL] - RTHDCPL.EXE
HKLM\SOFTWARE | Run : [Alcmtr] - ALCMTR.EXE
HKLM\SOFTWARE | Run : [DAEMON Tools] - "C:\Program Files\DAEMON Tools\daemon.exe" -lang 1033
HKLM\SOFTWARE | Run : [SunJavaUpdateSched] - "C:\Program Files\Fichiers communs\Java\Java Update\jusched.exe"
HKLM\SOFTWARE | Run : [QuickTime Task] - "C:\Program Files\QuickTime\qttask.exe" -atboottime
HKLM\SOFTWARE | Run : [Adobe ARM] - "C:\Program Files\Fichiers communs\Adobe\ARM\1.0\AdobeARM.exe"
HKLM\SOFTWARE | Run : [APSDaemon] - "C:\Program Files\Fichiers communs\Apple\Apple Application Support\APSDaemon.exe"
HKLM\SOFTWARE | Run : [iTunesHelper] - "C:\Program Files\iTunes\iTunesHelper.exe"
HKLM\SOFTWARE | RunOnce : [] -
HKU\S-1-5-19\SOFTWARE | Run : [CTFMON.EXE] - C:\WINDOWS\System32\CTFMON.EXE
HKU\S-1-5-20\SOFTWARE | Run : [CTFMON.EXE] - C:\WINDOWS\System32\CTFMON.EXE
HKU\S-1-5-21-1960408961-1220945662-839522115-1003\SOFTWARE | Run : [CTFMON.EXE] - C:\WINDOWS\system32\ctfmon.exe
HKU\S-1-5-21-1960408961-1220945662-839522115-1003\SOFTWARE | Run : [Google Update] - "C:\Documents and Settings\philippe\Local Settings\Application Data\Google\Update\GoogleUpdate.exe" /c
HKU\S-1-5-21-1960408961-1220945662-839522115-1003\SOFTWARE | Run : [Steam] - "C:\Program Files\steam2\Steam.exe" -silent
HKU\S-1-5-21-1960408961-1220945662-839522115-1003\SOFTWARE | Run : [uTorrent] - "C:\Program Files\uTorrent\uTorrent.exe" /MINIMIZED
HKU\S-1-5-21-1960408961-1220945662-839522115-1003\SOFTWARE | Run : [EPSON SX130 Series] - C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_FATIHJE.EXE /FU "C:\WINDOWS\TEMP\E_S2108.tmp" /EF "HKCU"
HKU\S-1-5-18\SOFTWARE | Run : [CTFMON.EXE] - C:\WINDOWS\System32\CTFMON.EXE
################## | Recherche générique |
Supprimé! C:\DOCUME~1\philippe\LOCALS~1\Temp\ubi15B8.tmp.exe
Supprimé! F:\MSN\D\Mic.exe
Supprimé! C:\MSN
Supprimé! F:\autorun.inf
Supprimé! F:\MSN
(!) Fichiers temporaires supprimés.
################## | Registre |
Supprimé! HKU\S-1-5-21-1960408961-1220945662-839522115-1003\Software\.\.\.\.\Mountpoints2\{012e6554-3755-11e3-b64d-00241da4a96b}
Supprimé! HKU\S-1-5-21-1960408961-1220945662-839522115-1003\Software\.\.\.\.\Mountpoints2\{39b0ed6a-0caa-11e2-b3bf-00241da4a96b}
Supprimé! HKU\S-1-5-21-1960408961-1220945662-839522115-1003\Software\.\.\.\.\Mountpoints2\{55279dbc-dc88-11e0-b145-00241da4a96b}
Supprimé! HKU\S-1-5-21-1960408961-1220945662-839522115-1003\Software\.\.\.\.\Mountpoints2\{6ac7bb5e-9b79-11e0-b0e6-00241da4a96b}
Supprimé! HKU\S-1-5-21-1960408961-1220945662-839522115-1003\Software\.\.\.\.\Mountpoints2\{7a1d83e5-af79-11df-aef2-00241da4a96b}
Supprimé! HKU\S-1-5-21-1960408961-1220945662-839522115-1003\Software\.\.\.\.\Mountpoints2\{90c6596e-8cf7-11e0-b0cf-00241da4a96b}
Supprimé! HKU\S-1-5-21-1960408961-1220945662-839522115-1003\Software\.\.\.\.\Mountpoints2\{b9198af4-657d-11e2-b473-00241da4a96b}
Supprimé! HKU\S-1-5-21-1960408961-1220945662-839522115-1003\Software\.\.\.\.\Mountpoints2\{c30b1006-207c-11e3-b614-00241da4a96b}
Supprimé! HKU\S-1-5-21-1960408961-1220945662-839522115-1003\Software\.\.\.\.\Mountpoints2\{cb3b21cc-bb73-11df-af19-00241da4a96b}
Supprimé! HKU\S-1-5-21-1960408961-1220945662-839522115-1003\Software\.\.\.\.\Mountpoints2\{d8af165f-1c0a-11e0-b009-00241da4a96b}
Supprimé! HKU\S-1-5-21-1960408961-1220945662-839522115-1003\Software\.\.\.\.\Mountpoints2\{e9c04838-b249-11e1-b315-00241da4a96b}
################## | Listing |
[08/05/2013 - 13:39:24 | D ] C:\Acrobat3
[29/10/2013 - 16:55:52 | D ] C:\AdwCleaner
[11/08/2010 - 18:06:17 | D ] C:\ATI
[11/08/2010 - 17:01:59 | N | 0] C:\AUTOEXEC.BAT
[29/10/2013 - 17:38:28 | D ] C:\Avenger
[16/09/2011 - 14:32:42 | N | 224] C:\boot.ini
[28/08/2001 - 13:00:00 | N | 4952] C:\Bootfont.bin
[29/10/2013 - 17:06:50 | SHD ] C:\Config.Msi
[11/08/2010 - 17:01:59 | N | 0] C:\CONFIG.SYS
[08/12/2010 - 09:35:14 | D ] C:\Documents and Settings
[05/08/2013 - 17:31:35 | D ] C:\Games
[01/03/2011 - 18:19:28 | D ] C:\gPotato.eu
[16/01/2011 - 12:51:30 | N | 20486220] C:\HDMI_R255.exe
[11/08/2010 - 17:01:59 | N | 0] C:\IO.SYS
[11/08/2010 - 17:01:59 | N | 0] C:\MSDOS.SYS
[11/08/2010 - 17:55:04 | N | 47564] C:\NTDETECT.COM
[29/10/2013 - 19:32:00 | N | 252240] C:\ntldr
[29/10/2013 - 20:11:16 | ASH | 2145386496] C:\pagefile.sys
[29/10/2013 - 18:16:36 | D ] C:\Program Files
[08/12/2010 - 09:35:15 | SHD ] C:\RECYCLER
[11/08/2010 - 18:01:25 | SHD ] C:\System Volume Information
[29/10/2013 - 21:11:07 | D ] C:\UsbFix
[29/10/2013 - 21:14:21 | A | 8179] C:\UsbFix [Clean 2] JULIEN.txt
[29/10/2013 - 20:43:02 | N | 6827] C:\UsbFix [Scan 1] JULIEN.txt
[29/10/2013 - 20:49:21 | N | 7145] C:\UsbFix [Scan 2] JULIEN.txt
[29/10/2013 - 20:13:20 | D ] C:\WINDOWS
[24/03/2013 - 22:33:06 | D ] F:\iPod_Control
[24/03/2013 - 14:33:10 | N | 0] F:\.metadata_never_index
################## | Vaccin |
F:\Autorun.inf -> Vaccin créé par UsbFix (El Desaparecido)
################## | E.O.F | http://www.usbfix.net - http://www.sosvirus.net |