############################## | UsbFix 7.060 | [Recherche]
Utilisateur: Sarah (Administrateur) # PC-DE-SARAH
Mis à jour le 22/09/2011 par El Desaparecido
Lancé à 10:35:54 | 24/09/2011
Site Web:
http://eldesaparecido.comFichier suspect ? :
http://eldesaparecido.com/support.phpContact:
contact@eldesaparecido.comPC: HP-Pavilion (GX598AA-ABF a6221.fr) (X86-based PC) # Desktop Computer
CPU: Intel(R) Core(TM)2 Duo CPU E4400 @ 2.00GHz (2000)
RAM -> [ Total : 3070 | Free : 1676 ]
BIOS: Phoenix - AwardBIOS v6.00PG
BOOT: Normal boot
OS: Microsoft® Windows Vista™ Édition Familiale Premium (6.0.6002 32-Bit) # Service Pack 2
WB: Windows Internet Explorer 9.0.8112.16421
SC: Security Center Service [ Enabled ]
WU: Windows Update Service [ Enabled ]
FW: Windows FireWall Service [ Enabled ]
C:\ (%systemdrive%) -> Disque fixe # 328 Go (64 Go libre(s) - 20%) [HP] # NTFS
D:\ -> Disque fixe # 7 Go (1009 Mo libre(s) - 13%) [FACTORY_IMAGE] # NTFS
E:\ -> CD-ROM
F:\ -> CD-ROM
K:\ -> Disque fixe # 297 Go (225 Go libre(s) - 76%) [My Passport] # NTFS
L:\ -> Disque amovible # 2 Go (1 Go libre(s) - 63%) [] # FAT
################## | Processus Actif |
C:\Windows\system32\csrss.exe (632)
C:\Windows\system32\wininit.exe (684)
C:\Windows\system32\csrss.exe (696)
C:\Windows\system32\services.exe (736)
C:\Windows\system32\lsass.exe (748)
C:\Windows\system32\lsm.exe (756)
C:\Windows\system32\winlogon.exe (840)
C:\Windows\system32\svchost.exe (948)
C:\Windows\system32\svchost.exe (1020)
C:\Windows\System32\svchost.exe (1060)
C:\Windows\system32\Ati2evxx.exe (1144)
C:\Windows\System32\svchost.exe (1176)
C:\Windows\System32\svchost.exe (1228)
C:\Windows\system32\svchost.exe (1252)
C:\Windows\system32\svchost.exe (1368)
C:\Windows\system32\SLsvc.exe (1388)
C:\Windows\system32\svchost.exe (1428)
C:\Windows\system32\Ati2evxx.exe (1560)
C:\Program Files\AVAST Software\Avast\AvastSvc.exe (1716)
C:\Windows\System32\spoolsv.exe (428)
C:\Windows\system32\svchost.exe (588)
C:\Program Files\Common Files\Adobe\ARM\1.0\armsvc.exe (1796)
C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe (1712)
C:\Windows\system32\svchost.exe (624)
C:\Windows\system32\taskeng.exe (1808)
C:\Program Files\Common Files\Intel\IntelDH\NMS\AdpPlugins\DQLWinService.exe (2088)
C:\Windows\system32\svchost.exe (2108)
c:\Program Files\Common Files\LightScribe\LSSrvc.exe (2176)
C:\Windows\System32\svchost.exe (2220)
C:\Windows\System32\svchost.exe (2264)
C:\Windows\system32\svchost.exe (2280)
C:\Windows\system32\svchost.exe (2300)
C:\Windows\System32\svchost.exe (2328)
C:\Windows\system32\SearchIndexer.exe (2356)
C:\Windows\system32\WUDFHost.exe (2696)
C:\Windows\system32\svchost.exe (4060)
c:\Program Files\Hewlett-Packard\HP Health Check\hphc_service.exe (2448)
C:\Windows\system32\Dwm.exe (2776)
C:\Windows\system32\taskeng.exe (3328)
C:\hp\support\hpsysdrv.exe (3688)
C:\Program Files\Hewlett-Packard\On-Screen OSD Indicator\OSD.exe (3644)
C:\WINDOWS\RtHDVCpl.exe (3536)
c:\Program Files\ATI Technologies\ATI.ACE\Core-Static\MOM.EXE (2344)
C:\Program Files\HP\HP Software Update\hpwuSchd2.exe (2296)
C:\Program Files\AVAST Software\Avast\AvastUI.exe (2772)
C:\Program Files\iTunes\iTunesHelper.exe (3348)
C:\Program Files\Common Files\Java\Java Update\jusched.exe (3464)
C:\Program Files\Hewlett-Packard\HP Advisor\HPAdvisor.exe (3488)
C:\WINDOWS\ehome\ehtray.exe (3192)
C:\Program Files\Windows Sidebar\sidebar.exe (3216)
C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe (1436)
C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe (1052)
C:\Windows\ehome\ehmsas.exe (3020)
C:\Program Files\HP\Digital Imaging\bin\hpqSTE08.exe (3924)
C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CCC.exe (3244)
C:\Program Files\iPod\bin\iPodService.exe (2480)
C:\Windows\system32\wuauclt.exe (4140)
C:\Windows\Microsoft.Net\Framework\v3.0\WPF\PresentationFontCache.exe (4660)
C:\Windows\system32\conime.exe (4984)
C:\Windows\system32\Macromed\Flash\FlashUtil10w_ActiveX.exe (4976)
C:\Windows\Explorer.exe (4848)
C:\Program Files\Internet Explorer\iexplore.exe (4956)
C:\Program Files\Internet Explorer\iexplore.exe (5776)
C:\Windows\system32\wbem\wmiprvse.exe (3264)
C:\UsbFix\UsbFix.exe (5888)
################## | Éléments infectieux |
Présent! C:\Users\Sarah\install_flash_player.exe
Présent! C:\Users\Sarah\install_flash_player_ax.exe
Présent! F:\autorun.inf
################## | Registre |
Présent! HKLM\Software\Microsoft\Windows\CurrentVersion\Policies\System|DisableRegistryTools
Présent! HKLM\Software\Microsoft\Windows\CurrentVersion\Policies\explorer|NoDrives
Présent! HKCU\Software\Microsoft\Windows\CurrentVersion\Policies\explorer|NoDrives
################## | Mountpoints2 |
HKCU\.\.\.\.\Explorer\MountPoints2\{2475e6aa-1b85-11de-845c-001d60727471}
Shell\AutoRun\Command = F:\WD_Windows_Tools\Setup.exe
HKCU\.\.\.\.\Explorer\MountPoints2\{262570f8-17b7-11e0-95b7-001d60727471}
Shell\AutoRun\Command = L:\PMBP_Win.exe
HKCU\.\.\.\.\Explorer\MountPoints2\{439b6a01-c058-11e0-9c73-001d60727471}
Shell\AutoRun\Command = "F:\WD SmartWare.exe" autoplay=true
HKCU\.\.\.\.\Explorer\MountPoints2\{95eb7ce3-831d-11df-8988-001d60727471}
Shell\AutoRun\Command = "F:\WD SmartWare.exe" autoplay=true
################## | Listing |
[14/01/2008 - 18:33:53 | SHD ] C:\$Recycle.Bin
[01/12/2008 - 17:14:33 | A | 865] C:\A2Output2.xml
[01/12/2008 - 17:14:33 | A | 865] C:\A2Output6.xml
[18/09/2011 - 19:39:49 | A | 16968] C:\AdwCleaner[R1].txt
[20/09/2011 - 17:17:22 | A | 17013] C:\AdwCleaner[S1].txt
[01/09/2007 - 07:35:22 | A | 74] C:\autoexec.bat
[05/10/2009 - 16:16:46 | SHD ] C:\Boot
[11/04/2009 - 08:36:36 | RASH | 333257] C:\bootmgr
[01/09/2007 - 16:48:04 | RAS | 8192] C:\BOOTSECT.BAK
[20/07/2008 - 07:54:42 | A | 35664] C:\caavsetupLog.txt
[23/07/2008 - 17:54:01 | A | 19832] C:\caisslog.txt
[23/07/2008 - 07:46:33 | A | 16229] C:\CFScript.txt
[16/07/2009 - 21:06:39 | A | 1802] C:\cleannavi.txt
[12/02/2009 - 18:28:08 | D ] C:\ComboFix
[12/02/2009 - 18:28:03 | A | 211719] C:\ComboFix.txt
[18/09/2006 - 23:43:37 | A | 10] C:\config.sys
[14/01/2008 - 18:25:32 | SHD ] C:\Documents and Settings
[11/01/2010 - 13:39:16 | D ] C:\Games
[24/09/2011 - 05:48:17 | ASH | 3219611648] C:\hiberfil.sys
[09/12/2010 - 12:37:42 | HD ] C:\hp
[25/09/2008 - 14:05:27 | D ] C:\Intel
[24/09/2008 - 20:57:20 | RASH | 0] C:\IO.SYS
[22/07/2008 - 19:16:46 | A | 14966] C:\log - Copie.txt
[22/07/2008 - 19:16:46 | A | 14966] C:\log.txt
[05/11/2009 - 08:48:59 | A | 18039] C:\MP4debug.log
[24/09/2008 - 20:57:20 | RASH | 0] C:\MSDOS.SYS
[13/02/2008 - 11:33:32 | RHD ] C:\MSOCache
[24/09/2011 - 05:48:16 | ASH | 3533451264] C:\pagefile.sys
[26/03/2009 - 22:30:25 | D ] C:\PerfLogs
[22/09/2011 - 19:35:43 | A | 512] C:\PhysicalDisk0_MBR.bin
[02/03/2009 - 20:31:27 | A | 47542] C:\playground.log
[24/09/2011 - 10:30:56 | RD ] C:\Program Files
[24/09/2011 - 10:30:56 | HD ] C:\ProgramData
[12/02/2009 - 18:28:07 | D ] C:\QooBox
[18/01/2010 - 19:12:04 | A | 720] C:\resultat.txt
[17/01/2010 - 16:56:47 | D ] C:\rsit
[10/08/2009 - 16:11:22 | D ] C:\Rummy Royal
[24/09/2011 - 06:48:20 | SHD ] C:\System Volume Information
[24/09/2011 - 10:39:53 | D ] C:\UsbFix
[24/09/2011 - 10:37:00 | A | 7390] C:\UsbFix.txt
[14/01/2008 - 18:29:01 | RD ] C:\Users
[21/09/2011 - 05:19:41 | D ] C:\WINDOWS
[24/09/2011 - 10:31:00 | D ] C:\ZHP
[09/09/2011 - 16:12:12 | D ] C:\Zylom Games
[24/10/2009 - 09:50:41 | D ] C:\_OTM
[19/02/2009 - 17:57:27 | D ] C:\_OTMoveIt
[14/01/2008 - 18:33:53 | SHD ] D:\$RECYCLE.BIN
[04/10/2006 - 02:02:44 | SH | 438328] D:\boo.mgr
[14/01/2008 - 18:18:19 | SHD ] D:\boot
[02/11/2006 - 02:53:58 | SH | 438840] D:\bootmgr
[13/10/2006 - 17:00:52 | ASH | 1322] D:\Desktop.ini
[22/11/2009 - 09:04:59 | ASH | 24] D:\DRECOVERY
[14/01/2008 - 18:18:19 | SHD ] D:\hp
[01/09/2007 - 18:33:42 | SH | 111] D:\MASTER.LOG
[14/01/2008 - 18:29:59 | SHD ] D:\PC-Doctor 5 for Win PE
[14/01/2008 - 18:29:59 | SH | 429] D:\pcdr.ini
[22/11/2009 - 09:04:59 | SHD ] D:\PRELOAD
[10/09/2002 - 15:58:12 | ASH | 181616] D:\Protect.ed
[14/01/2008 - 18:18:19 | RD ] D:\RECOVERY
[01/09/2007 - 18:33:42 | SH | 44] D:\RESTORE.INI
[14/01/2008 - 18:18:19 | SHD ] D:\SOURCES
[22/09/2007 - 13:40:48 | SHD ] D:\System Volume Information
[11/05/2007 - 11:48:56 | SH | 35] D:\SystemRecovery.txt
[01/09/2007 - 18:33:43 | RSHD ] D:\Windows
[18/06/2009 - 23:12:18 | A | 88] F:\autorun.inf
[14/11/2009 - 02:33:06 | AD ] F:\Extras
[13/11/2009 - 21:25:22 | A | 3687200] F:\Unlock.exe
[13/11/2009 - 23:42:23 | AD ] F:\User Manuals
[14/11/2009 - 02:30:12 | A | 1456475] F:\Virtual CD Manager.exe
[14/11/2009 - 02:33:33 | AD ] F:\WD SmartWare
[13/11/2009 - 21:25:22 | A | 3280672] F:\WD SmartWare.exe
[18/06/2009 - 19:06:24 | A | 695] F:\What is this.html
[08/10/2010 - 15:24:46 | SHD ] K:\$RECYCLE.BIN
[15/08/2010 - 19:27:35 | D ] K:\Amis
[15/08/2010 - 19:30:10 | D ] K:\Animaux
[17/09/2011 - 11:45:36 | D ] K:\Famille
[05/09/2011 - 12:32:28 | A | 734265344] K:\Fast and Furious 5 .TRUEFRENCH.SUBFORCED.BDRiP.REPACK.1CD.XviD.AC3-QNU.By.Phoenix.[emule-island.ru].avi
[05/09/2011 - 12:52:46 | A | 733769728] K:\La.Croisiere.2011.FRENCH.DVDRIP.XVID-FwD.By.Cervolix.[emule-island.ru].avi
[16/08/2011 - 20:43:06 | A | 739309704] K:\Les femmes du 6eme étage étage.avi
[05/09/2011 - 13:11:44 | A | 780517210] K:\Pirates des Caraibes La Fontaine De Jouvence.avi
[14/07/2011 - 10:40:19 | SHD ] K:\RECYCLER
[17/09/2011 - 11:39:31 | D ] K:\Soirées - Sorties
[02/07/2011 - 09:47:54 | D ] K:\Sports
[22/10/2010 - 22:29:24 | SHD ] K:\System Volume Information
[17/09/2011 - 11:47:09 | D ] K:\Vacances-Week end
[08/10/2010 - 12:23:18 | A | 1876922] L:\P1090231.JPG
[21/09/2011 - 13:12:12 | A | 377968086] L:\Friday.Night.Lights.4x09.Les.Lumières.De.Carol.Park.FR.LD.DVDRip.XviD-JMT.[emule-island.ru].avi
[21/09/2011 - 11:10:30 | A | 370819054] L:\Friday.Night.Lights.4x10.Un.Bébé.Ou.Pas.FR.LD.DVDRip.XviD-JMT.[emule-island.ru].avi
################## | Vaccin |
(!) Cet ordinateur n'est pas vacciné!
################## | E.O.F |