Aide à lire le rapport usbFix

tas -  
lilidurhone Messages postés 43355 Date d'inscription   Statut Contributeur sécurité Dernière intervention   -
Bonjour,




Svp, m'aider à lire ce rapport pour désinfecté mon flash. Merci
############################## | UsbFix V 7.164 | [Research]

User: ibtissem (Administrator) # IBTISSEM-PC
Updated05/02/2014 by El Desaparecido - Team SosVirus
Started at 17:57:00 | 16/02/2014

Website : http://www.en.usbfix.net/
Changelog : http://www.usbfix.net/maj/
Support : http://www.sosvirus.net/
Upload Malware : http://www.sosvirus.net/upload_malware.php
Contact : http://www.en.usbfix.net/contact/

PC: Hewlett-Packard (3659)
CPU: Intel(R) Core(TM) i3 CPU M 330 @ 2.13GHz
RAM -> [Total : 3063 Mo| Free : 1811 Mo]
Bios: Hewlett-Packard
Boot: Normal boot

OS: Microsoft Windows 7 Professional (6.1.7600 64-Bit)
WB: Windows Internet Explorer : 8.0.7600.16385
WB: Google Chrome : 31.0.1650.63
WB: Mozilla Firefox : 22.0

SC: Security Center [Enabled]
WU: Windows Update [Enabled]
AV: avast! Antivirus [Enabled | Updated]
AS: Windows Defender [Enabled | (!) Outdated]
AS: avast! Antivirus [Enabled | Updated]
FW: Windows FireWall [Enabled]

C:\ (%systemdrive%) -> Fixed drive # 128 Gb (96 Mb free - 75%) [] # NTFS
D:\ -> Fixed drive # 70 Gb (69 Mb free - 99%) [] # NTFS
E:\ -> Fixed drive # 100 Gb (100 Mb free - 100%) [] # NTFS
F:\ -> CD-ROM
G:\ -> Removable drive # 8 Gb (8 Mb free - 100%) [] # FAT32
H:\ -> CD-ROM

################## | Active Processes |

C:\Windows\system32\csrss.exe (ID: 408 |ParentID: 400)
C:\Windows\system32\wininit.exe (ID: 448 |ParentID: 400)
C:\Windows\system32\services.exe (ID: 504 |ParentID: 448)
C:\Windows\system32\lsass.exe (ID: 524 |ParentID: 448)
C:\Windows\system32\lsm.exe (ID: 532 |ParentID: 448)
C:\Windows\system32\svchost.exe (ID: 676 |ParentID: 504)
C:\Windows\system32\svchost.exe (ID: 772 |ParentID: 504)
C:\Windows\System32\svchost.exe (ID: 856 |ParentID: 504)
C:\Windows\System32\svchost.exe (ID: 908 |ParentID: 504)
C:\Windows\system32\svchost.exe (ID: 972 |ParentID: 504)
C:\Windows\system32\svchost.exe (ID: 460 |ParentID: 504)
C:\Windows\system32\svchost.exe (ID: 1040 |ParentID: 504)
C:\Windows\system32\WLANExt.exe (ID: 1212 |ParentID: 908)
C:\Windows\system32\conhost.exe (ID: 1220 |ParentID: 408)
C:\Windows\system32\svchost.exe (ID: 1296 |ParentID: 504)
C:\Program Files\AVAST Software\Avast\AvastSvc.exe (ID: 1324 |ParentID: 504)
C:\Windows\System32\spoolsv.exe (ID: 1444 |ParentID: 504)
C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe (ID: 1556 |ParentID: 504)
c:\Program Files\WIDCOMM\Bluetooth Software\btwdins.exe (ID: 1792 |ParentID: 504)
C:\ProgramData\Dim@net\OnlineUpdate\ouc.exe (ID: 1868 |ParentID: 1836)
C:\ProgramData\DatacardService\HWDeviceService64.exe (ID: 1896 |ParentID: 504)
C:\Program Files (x86)\RealNetworks\RealDownloader\rndlresolversvc.exe (ID: 1948 |ParentID: 504)
C:\Program Files (x86)\TeamViewer\Version8\TeamViewer_Service.exe (ID: 1140 |ParentID: 504)
C:\Windows\System32\svchost.exe (ID: 2300 |ParentID: 504)
C:\Windows\system32\svchost.exe (ID: 2320 |ParentID: 504)
C:\Windows\system32\svchost.exe (ID: 2352 |ParentID: 504)
C:\Windows\system32\taskeng.exe (ID: 2772 |ParentID: 972)
C:\Program Files (x86)\Google\Update\GoogleUpdate.exe (ID: 2856 |ParentID: 2772)
C:\ProgramData\BetterSoft\OptimizerPro\OptimizerPro.exe (ID: 2928 |ParentID: 2772)
C:\Windows\system32\SearchIndexer.exe (ID: 3204 |ParentID: 504)
C:\Windows\system32\csrss.exe (ID: 2684 |ParentID: 3420)
C:\Windows\system32\winlogon.exe (ID: 2272 |ParentID: 3420)
C:\Windows\system32\taskhost.exe (ID: 620 |ParentID: 504)
C:\Windows\system32\Dwm.exe (ID: 4084 |ParentID: 908)
C:\Windows\Explorer.EXE (ID: 2696 |ParentID: 1256)
C:\Users\ibtissem\AppData\Local\iLivid\iLivid.exe (ID: 3936 |ParentID: 2696)
C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe (ID: 3892 |ParentID: 2696)
C:\Program Files (x86)\Real\RealPlayer\Update\realsched.exe (ID: 380 |ParentID: 3648)
C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe (ID: 2536 |ParentID: 3648)
C:\Program Files\AVAST Software\Avast\AvastUI.exe (ID: 2848 |ParentID: 3648)
C:\Program Files (x86)\Evernote\Evernote\EvernoteClipper.exe (ID: 3752 |ParentID: 2696)
C:\Windows\system32\taskeng.exe (ID: 3900 |ParentID: 972)
C:\Users\ibtissem\AppData\Local\FilesFrog Update Checker\update_checker.exe (ID: 3856 |ParentID: 3900)
C:\Windows\system32\WUDFHost.exe (ID: 3396 |ParentID: 908)
C:\Program Files (x86)\Dim@net\***@*** (ID: 4032 |ParentID: 2696)
C:\ProgramData\DatacardService\DCSHelper.exe (ID: 2024 |ParentID: 1896)
C:\Windows\system32\wbem\wmiprvse.exe (ID: 1840 |ParentID: 676)
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (ID: 1892 |ParentID: 2696)
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (ID: 692 |ParentID: 1892)
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (ID: 1940 |ParentID: 1892)
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (ID: 3456 |ParentID: 1892)
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (ID: 3100 |ParentID: 1892)
C:\Windows\system32\SearchProtocolHost.exe (ID: 4564 |ParentID: 3204)
C:\Windows\system32\SearchFilterHost.exe (ID: 4584 |ParentID: 3204)
C:\Windows\system32\wbem\wmiprvse.exe (ID: 4364 |ParentID: 676)

################## | Regedit Run |

04 - HKCU\..\Run : [Software updater] "C:\Users\ibtissem\AppData\Roaming\FreeSoftwareUpdater\updater.exe" -h http://neoupdater.com/
04 - HKCU\..\Run : [GoogleChromeAutoLaunch_090392DFC9C95FF1D42AC679514E27B4] "C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" --no-startup-window
04 - HKCU\..\Run : [iLivid] "C:\Users\ibtissem\AppData\Local\iLivid\iLivid.exe" -autorun
04 - HKLM\..\Run : [Adobe ARM] "C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
04 - HKLM\..\Run : [TkBellExe] "c:\program files (x86)\real\realplayer\Update\realsched.exe" -osboot
04 - HKLM\..\Run : [SunJavaUpdateSched] "C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe"
04 - HKLM\..\Run : [AvastUI.exe] "C:\Program Files\AVAST Software\Avast\AvastUI.exe" /nogui
04 - HKLM\..\RunOnce : []
04 - HKU\S-1-5-19\..\Run : [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun
04 - HKU\S-1-5-20\..\Run : [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun
04 - HKU\S-1-5-21-2281527450-914519173-1825432989-1000\..\Run : [Software updater] "C:\Users\ibtissem\AppData\Roaming\FreeSoftwareUpdater\updater.exe" -h http://neoupdater.com/
04 - HKU\S-1-5-21-2281527450-914519173-1825432989-1000\..\Run : [GoogleChromeAutoLaunch_090392DFC9C95FF1D42AC679514E27B4] "C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" --no-startup-window
04 - HKU\S-1-5-21-2281527450-914519173-1825432989-1000\..\Run : [iLivid] "C:\Users\ibtissem\AppData\Local\iLivid\iLivid.exe" -autorun
04 - HKU\S-1-5-19\..\RunOnce : [mctadmin] C:\Windows\System32\mctadmin.exe
04 - HKU\S-1-5-20\..\RunOnce : [mctadmin] C:\Windows\System32\mctadmin.exe

################## | Generic Research |

Found ! G:\photo 2013 45151545124.jpg______________.vbs.lnk
Found ! G:\RECYCLER.lnk
Found ! G:\WinUsbDriver.lnk
Found ! G:\autorun.lnk
Found ! G:\nscgxohhbe.lnk
Found ! G:\WinUsbDriver.vbs.lnk
Found ! G:\nscgxohhbe..vbs.lnk
Found ! G:\photo 2013 45151545124.lnk
Found ! G:\autorun.inf.lnk
Found ! G:\config.lnk
Found ! G:\violletta.lnk
Found ! G:\64749467img0023a-jpg.lnk
Found ! G:\50286_230185933329_3234055_n.lnk
Found ! G:\images.lnk
Found ! G:\lycee_bizerte.lnk
Found ! G:\config.dat.lnk
Found ! G:\téléchargement (20).jpg.lnk
Found ! G:\violletta.docx.lnk
Found ! G:\64749467img0023a-jpg.jpg.lnk
Found ! G:\50286_230185933329_3234055_n.jpg.lnk
Found ! G:\images.jpg.lnk
Found ! G:\lycee_bizerte.jpg.lnk
Found ! G:\winlog.vbs.lnk
Found ! G:\help.lnk
Found ! G:\winlog.lnk

################## | Registry |

Found ! HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced|Start_ShowMyGames -> 0

################## | Vaccin |

G:\Autorun.inf -> Vaccine created by UsbFix (El Desaparecido)

################## | E.O.F | http://www.en.usbfix.net/ - http://www.sosvirus.net |
A voir également:

1 réponse

Utilisateur anonyme
 
bonjour,

je parie que tes fichiers se sont transformés en raccourci !

de plus, tu as quelques adwares et pup sur ton pc !



1
lilidurhone Messages postés 43355 Date d'inscription   Statut Contributeur sécurité Dernière intervention   3 807
 
Hello

Et je rajouterai Windows pas à jour
0