crapo131313 Messages postés 1 Date d'inscription dimanche 10 novembre 2013 Statut Membre Dernière intervention 10 novembre 2013 - 10 nov. 2013 à 04:45
lilidurhone Messages postés 43343 Date d'inscription lundi 25 avril 2011 Statut Contributeur sécurité Dernière intervention 19 juillet 2024 - 10 nov. 2013 à 09:21

Voila mon rapport USBFIX.
Sur mon DD mes fichiers sont invisibles après avoir été transformes en raccourcis.
Quelle est la suite des événements?
Merci a ceux qui peuvent m'aider.

El Crapo

############################## | UsbFix V 7.150 | [Research]

User: Steph (Administrator) # STEF
Updated 08/11/2013 by El Desaparecido - Team SosVirus
Started at 17:27:00 | 09/11/2013

Website : http://www.en.usbfix.net
Forum : https://www.sosvirus.net/
Upload Malware : http://www.sosvirus.net/upload_malware.php
Contact : http://www.en.usbfix.net/contact/

PC: Hewlett-Packard (30A8)
CPU: Intel(R) Celeron(R) M CPU 410 @ 1.46GHz
RAM -> [Total : 2038 | Free : 769]
Bios: Hewlett-Packard
Boot: Normal boot

OS: Microsoft Windows XP Home Edition (5.1.2600 32-Bit) Service Pack 3
WB: Windows Internet Explorer : 8.0.6001.18702
WB: Google Chrome : 30.0.1599.101
WB: Mozilla Firefox : 24.0

SC: Security Center Service [Enabled]
WU: Windows Update Service [Enabled]
FW: Windows FireWall Service [Enabled]

C:\ (%systemdrive%) -> Fixed drive # 48 Gb (4 Mb free - 9%) [] # NTFS
D:\ -> Fixed drive # 8 Gb (1 Mb free - 14%) [PRESARIO_RP] # FAT32
F:\ -> Fixed drive # 931 Gb (350 Mb free - 38%) [DD] # FAT32

################## | Active Processes |

C:\WINDOWS\System32\smss.exe (ID: 548 |ParentID: 4)
C:\WINDOWS\system32\winlogon.exe (ID: 648 |ParentID: 548)
C:\WINDOWS\system32\services.exe (ID: 692 |ParentID: 648)
C:\WINDOWS\system32\lsass.exe (ID: 704 |ParentID: 648)
C:\WINDOWS\system32\svchost.exe (ID: 856 |ParentID: 692)
C:\WINDOWS\System32\svchost.exe (ID: 976 |ParentID: 692)
C:\WINDOWS\Explorer.EXE (ID: 1396 |ParentID: 1292)
C:\WINDOWS\system32\spoolsv.exe (ID: 1532 |ParentID: 692)
C:\Program Files\Avira\AntiVir Desktop\sched.exe (ID: 1600 |ParentID: 692)
C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe (ID: 1760 |ParentID: 1396)
C:\Program Files\hpq\HP Wireless Assistant\HP Wireless Assistant.exe (ID: 1776 |ParentID: 1396)
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe (ID: 1844 |ParentID: 1396)
C:\Program Files\HP\QuickPlay\QPService.exe (ID: 1924 |ParentID: 1396)
C:\Program Files\Hp\HP Software Update\HPWuSchd2.exe (ID: 1964 |ParentID: 1396)
C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe (ID: 2036 |ParentID: 1396)
C:\Program Files\Hewlett-Packard\HP Quick Launch Buttons\QlbCtrl.exe (ID: 2044 |ParentID: 1396)
C:\WINDOWS\V0470Mon.exe (ID: 204 |ParentID: 1396)
C:\WINDOWS\system32\hkcmd.exe (ID: 244 |ParentID: 1396)
C:\WINDOWS\system32\igfxpers.exe (ID: 304 |ParentID: 1396)
C:\Program Files\AVG Secure Search\vprot.exe (ID: 312 |ParentID: 1396)
C:\Program Files\TuneUp Utilities 2008\OneClick.exe (ID: 432 |ParentID: 2004)
C:\Program Files\Avira\AntiVir Desktop\avgnt.exe (ID: 436 |ParentID: 1396)
C:\Program Files\Avira\AntiVir Desktop\avguard.exe (ID: 668 |ParentID: 692)
C:\Program Files\AskPartnerNetwork\Toolbar\Updater\TBNotifier.exe (ID: 876 |ParentID: 1396)
C:\WINDOWS\system32\ctfmon.exe (ID: 1012 |ParentID: 1396)
C:\Program Files\AskPartnerNetwork\Toolbar\apnmcp.exe (ID: 1220 |ParentID: 692)
C:\Program Files\Skype\Phone\Skype.exe (ID: 1336 |ParentID: 1396)
C:\Program Files\Bonjour\mDNSResponder.exe (ID: 1612 |ParentID: 692)
C:\Documents and Settings\Steph\Application Data\Dropbox\bin\Dropbox.exe (ID: 1624 |ParentID: 1396)
C:\Program Files\Common Files\LightScribe\LSSrvc.exe (ID: 608 |ParentID: 692)
C:\WINDOWS\system32\svchost.exe (ID: 1816 |ParentID: 692)
C:\Program Files\Common Files\AVG Secure Search\vToolbarUpdater\17.0.12\ToolbarUpdater.exe (ID: 2072 |ParentID: 692)
C:\Program Files\Hewlett-Packard\Shared\hpqwmiex.exe (ID: 2172 |ParentID: 692)
C:\Program Files\TuneUp Utilities 2008\RegistryCleaner.exe (ID: 2304 |ParentID: 432)
C:\Program Files\Common Files\AVG Secure Search\vToolbarUpdater\17.0.12\loggingserver.exe (ID: 2368 |ParentID: 2072)
C:\Program Files\Mozilla Firefox\firefox.exe (ID: 3308 |ParentID: 1396)
C:\Program Files\Avira\AntiVir Desktop\avshadow.exe (ID: 3924 |ParentID: 668)
C:\Program Files\Avira\AntiVir Desktop\AVWEBGRD.EXE (ID: 4084 |ParentID: 692)
C:\WINDOWS\System32\TuneUpDefragService.exe (ID: 3604 |ParentID: 692)
C:\Program Files\Mozilla Firefox\plugin-container.exe (ID: 492 |ParentID: 3308)
C:\WINDOWS\system32\wscntfy.exe (ID: 1440 |ParentID: 976)
C:\UsbFix\Go.exe (ID: 3652 |ParentID: 3444)
C:\WINDOWS\system32\wuauclt.exe (ID: 788 |ParentID: 976)

################## | Regedit Run |

04 - HKLM\SOFTWARE | Run : [SunJavaUpdateSched] - "C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe"
04 - HKLM\SOFTWARE | Run : [hpWirelessAssistant] - C:\Program Files\hpq\HP Wireless Assistant\HP Wireless Assistant.exe
04 - HKLM\SOFTWARE | Run : [High Definition Audio Property Page Shortcut] - CHDAudPropShortcut.exe
04 - HKLM\SOFTWARE | Run : [SynTPEnh] - C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
04 - HKLM\SOFTWARE | Run : [QPService] - "C:\Program Files\HP\QuickPlay\QPService.exe"
04 - HKLM\SOFTWARE | Run : [HP Software Update] - C:\Program Files\Hp\HP Software Update\HPWuSchd2.exe
04 - HKLM\SOFTWARE | Run : [ISUSPM Startup] - "C:\Program Files\Common Files\InstallShield\UpdateService\isuspm.exe" -startup
04 - HKLM\SOFTWARE | Run : [ISUSScheduler] - "C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe" -start
04 - HKLM\SOFTWARE | Run : [QlbCtrl] - %ProgramFiles%\Hewlett-Packard\HP Quick Launch Buttons\QlbCtrl.exe /Start
04 - HKLM\SOFTWARE | Run : [Cpqset] - C:\Program Files\HPQ\Default Settings\cpqset.exe
04 - HKLM\SOFTWARE | Run : [RecGuard] - C:\Windows\SMINST\RecGuard.exe
04 - HKLM\SOFTWARE | Run : [V0470Mon.exe] - C:\WINDOWS\V0470Mon.exe
04 - HKLM\SOFTWARE | Run : [IgfxTray] - C:\WINDOWS\system32\igfxtray.exe
04 - HKLM\SOFTWARE | Run : [HotKeysCmds] - C:\WINDOWS\system32\hkcmd.exe
04 - HKLM\SOFTWARE | Run : [Persistence] - C:\WINDOWS\system32\igfxpers.exe
04 - HKLM\SOFTWARE | Run : [vProt] - "C:\Program Files\AVG Secure Search\vprot.exe"
04 - HKLM\SOFTWARE | Run : [ROC_roc_ssl_v12] - "C:\Program Files\AVG Secure Search\ROC_roc_ssl_v12.exe" / /PROMPT /CMPID=roc_ssl_v12
04 - HKLM\SOFTWARE | Run : [avgnt] - "C:\Program Files\Avira\AntiVir Desktop\avgnt.exe" /min
04 - HKLM\SOFTWARE | Run : [ApnTBMon] - "C:\Program Files\AskPartnerNetwork\Toolbar\Updater\TBNotifier.exe"
04 - HKLM\SOFTWARE | RunOnce : [] -
04 - HKU\S-1-5-21-3224148252-3367876100-3992345983-1006\SOFTWARE | Run : [ctfmon.exe] - C:\WINDOWS\system32\ctfmon.exe
04 - HKU\S-1-5-21-3224148252-3367876100-3992345983-1006\SOFTWARE | Run : [Facebook Update] - "C:\Documents and Settings\Steph\Local Settings\Application Data\Facebook\Update\FacebookUpdate.exe" /c /nocrashserver
04 - HKU\S-1-5-21-3224148252-3367876100-3992345983-1006\SOFTWARE | Run : [swg] - "C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe"
04 - HKU\S-1-5-21-3224148252-3367876100-3992345983-1006\SOFTWARE | Run : [Skype] - "C:\Program Files\Skype\Phone\Skype.exe" /minimized /regrun
04 - HKU\S-1-5-18\SOFTWARE | Run : [DWQueuedReporting] - "C:\PROGRA~1\COMMON~1\MICROS~1\DW\dwtrig20.exe" -t

################## | Generic Research |

Found ! C:\Documents and Settings\Steph\Application Data\Zyngnf.exe
Found ! D:\setupSNK.exe
Found ! C:\WINDOWS\pskt.ini
Found ! D:\Autorun.inf
Found ! D:\desktop.ini

################## | Registry |

################## | Vaccin |

(!) This computer is not vaccinated!

################## | E.O.F | https://www.usbfix.net/ - https://www.sosvirus.net/ |

lilidurhone Messages postés 43343 Date d'inscription lundi 25 avril 2011 Statut Contributeur sécurité Dernière intervention 19 juillet 2024 3 807
10 nov. 2013 à 09:21
Tu peux passer à la suppression