voici ce que donne usbfix
############################## | UsbFix V 7.065 | [Recherche]
Utilisateur: bylf (Administrateur) # BYLF-PC
Mis à jour le 03/11/2011 par El Desaparecido
Lancé à 20:56:37 | 10/11/2011
Site Web:
http://eldesaparecido.com" onclick="window.open(this.href);return false;
Fichier suspect ? :
http://eldesaparecido.com/support.php" onclick="window.open(this.href);return false;
Contact:
contact@eldesaparecido.com
PC: System manufacturer (System Product Name) (x64-based PC) # Desktop Computer
CPU: Intel(R) Core(TM) i7 CPU 920 @ 2.67GHz (2668)
RAM -> [ Total : 6134 | Free : 4511 ]
BIOS: BIOS Date: 12/30/09 19:52:33 Ver: 08.00.15
BOOT: Normal boot
OS: Microsoft Windows 7 Édition Intégrale (6.1.7601 64-Bit) # Service Pack 1
WB: Windows Internet Explorer 9.0.8112.16421
SC: Security Center Service [ Enabled ]
WU: Windows Update Service [ Enabled ]
AV: Lavasoft Ad-Watch Live! Antivirus [ Enabled | Updated ]
FW: Windows FireWall Service [ Enabled ]
C:\ (%systemdrive%) -> Disque fixe # 149 Go (111 Go libre(s) - 75%) [] # NTFS
D:\ -> CD-ROM
E:\ -> Disque fixe # 1397 Go (173 Go libre(s) - 12%) [J¦Ãj+´Ó|GX] # FAT32
F:\ -> CD-ROM
################## | Processus Actif |
C:\Windows\system32\csrss.exe (540)
C:\Windows\system32\wininit.exe (604)
C:\Windows\system32\csrss.exe (628)
C:\Windows\system32\services.exe (664)
C:\Windows\system32\lsass.exe (672)
C:\Windows\system32\lsm.exe (684)
C:\Windows\system32\winlogon.exe (812)
C:\Windows\system32\svchost.exe (844)
C:\Windows\system32\svchost.exe (924)
C:\Windows\system32\atiesrxx.exe (988)
C:\Windows\System32\svchost.exe (152)
C:\Windows\System32\svchost.exe (372)
C:\Windows\system32\svchost.exe (548)
C:\Windows\system32\svchost.exe (1092)
C:\Windows\system32\svchost.exe (1204)
C:\Windows\system32\atieclxx.exe (1260)
C:\Program Files (x86)\Lavasoft\Ad-Aware\AAWService.exe (1384)
C:\Windows\System32\spoolsv.exe (1524)
C:\Windows\system32\svchost.exe (1552)
C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe (1660)
C:\Program Files (x86)\Common Files\MAGIX Services\Database\bin\FABS.exe (1732)
C:\Program Files (x86)\Common Files\LightScribe\LSSrvc.exe (1768)
C:\Program Files\Common Files\McAfee\McSvcHost\McSvHost.exe (1800)
C:\Windows\system32\mfevtps.exe (1824)
C:\Program Files (x86)\Soda PDF 3D Reader\ConversionService.exe (1920)
C:\Windows\system32\rundll32.exe (1952)
C:\Windows\SysWOW64\rundll32.exe (1968)
C:\Windows\system32\svchost.exe (1996)
C:\Windows\system32\svchost.exe (2020)
C:\Program Files\Common Files\McAfee\SystemCore\mcshield.exe (1328)
C:\Program Files\Common Files\McAfee\SystemCore\mfefire.exe (1856)
C:\Program Files (x86)\Canon\CAL\CALMAIN.exe (1416)
C:\Program Files (x86)\Spybot - Search & Destroy\SDWinSec.exe (1400)
C:\Windows\system32\wbem\unsecapp.exe (2440)
C:\Windows\system32\wbem\wmiprvse.exe (2680)
C:\Windows\system32\svchost.exe (3068)
C:\Windows\system32\taskhost.exe (3364)
C:\Windows\system32\Dwm.exe (3524)
C:\Windows\Explorer.EXE (3580)
C:\Program Files (x86)\ATI Technologies\HydraVision\HydraMD.exe (3832)
C:\Program Files (x86)\ATI Technologies\HydraVision\HydraDM.exe (3848)
C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\MOM.exe (3996)
C:\Program Files (x86)\ATI Technologies\HydraVision\HydraDM64.exe (4020)
C:\Program Files (x86)\ATI Technologies\HydraVision\HydraMD64.exe (4032)
C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CCC.exe (3264)
C:\Windows\system32\SearchIndexer.exe (3572)
C:\Program Files\Windows Media Player\wmpnetwk.exe (3804)
C:\Windows\System32\svchost.exe (4164)
C:\Program Files (x86)\Lavasoft\Ad-Aware\AAWTray.exe (4896)
C:\Program Files (x86)\Mozilla Firefox\plugin-container.exe (6056)
C:\Program Files\McAfee.com\Agent\mcagent.exe (4928)
C:\Program Files\Common Files\McAfee\Core\mchost.exe (4956)
C:\Program Files (x86)\Mozilla Firefox\firefox.exe (3056)
C:\Program Files (x86)\Mozilla Firefox\plugin-container.exe (2480)
C:\Program Files (x86)\Mozilla Firefox\plugin-container.exe (5416)
C:\Windows\system32\taskeng.exe (4532)
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (1520)
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (4992)
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (3236)
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (5380)
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (3548)
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (2904)
C:\UsbFix\UsbFix.exe (1176)
C:\Windows\system32\wbem\wmiprvse.exe (328)
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (4520)
C:\Windows\SysWOW64\rundll32.exe (6100)
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (4740)
################## | Processus Stoppés |
Stoppé! C:\Windows\system32\atiesrxx.exe (988)
Stoppé! C:\Windows\system32\atieclxx.exe (1260)
Stoppé! C:\Program Files (x86)\Lavasoft\Ad-Aware\AAWService.exe (1384)
Stoppé! C:\Windows\System32\spoolsv.exe (1524)
Stoppé! C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe (1660)
Stoppé! C:\Program Files (x86)\Common Files\MAGIX Services\Database\bin\FABS.exe (1732)
Stoppé! C:\Program Files (x86)\Common Files\LightScribe\LSSrvc.exe (1768)
Stoppé! C:\Program Files\Common Files\McAfee\McSvcHost\McSvHost.exe (1800)
Stoppé! C:\Windows\system32\mfevtps.exe (1824)
Stoppé! C:\Program Files (x86)\Soda PDF 3D Reader\ConversionService.exe (1920)
Stoppé! C:\Windows\system32\rundll32.exe (1952)
Stoppé! C:\Windows\SysWOW64\rundll32.exe (1968)
Stoppé! C:\Program Files\Common Files\McAfee\SystemCore\mcshield.exe (1328)
Stoppé! C:\Program Files\Common Files\McAfee\SystemCore\mfefire.exe (1856)
Stoppé! C:\Program Files (x86)\Canon\CAL\CALMAIN.exe (1416)
Stoppé! C:\Program Files (x86)\Spybot - Search & Destroy\SDWinSec.exe (1400)
Stoppé! C:\Windows\system32\taskhost.exe (3364)
Stoppé! C:\Program Files (x86)\ATI Technologies\HydraVision\HydraMD.exe (3832)
Stoppé! C:\Program Files (x86)\ATI Technologies\HydraVision\HydraDM.exe (3848)
Stoppé! C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\MOM.exe (3996)
Stoppé! C:\Program Files (x86)\ATI Technologies\HydraVision\HydraDM64.exe (4020)
Stoppé! C:\Program Files (x86)\ATI Technologies\HydraVision\HydraMD64.exe (4032)
Stoppé! C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CCC.exe (3264)
Stoppé! C:\Windows\system32\SearchIndexer.exe (3572)
Stoppé! C:\Program Files\Windows Media Player\wmpnetwk.exe (3804)
Stoppé! C:\Program Files (x86)\Mozilla Firefox\plugin-container.exe (6056)
Stoppé! C:\Program Files\McAfee.com\Agent\mcagent.exe (4928)
Stoppé! C:\Program Files (x86)\Mozilla Firefox\firefox.exe (3056)
Stoppé! C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (1520)
Stoppé! C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (2904)
################## | Éléments infectieux |
Présent! C:\Users\bylf\AppData\Local\Temp\ytb.exe
################## | Registre |
################## | Mountpoints2 |
HKCU\.\.\.\.\Explorer\MountPoints2\{b615c913-b54e-11e0-89c7-90e6ba853d6d}
Shell\AutoRun\Command = E:\LaunchU3.exe
################## | Vaccin |
(!) Cet ordinateur n'est pas vacciné!
################## | E.O.F |