[b]############################## | UsbFix V 7.183 | [Recherche][/b] Utilisateur: catherinepomper (Administrateur) # PCPORTABLE Mis à jour le 30/09/2014 par El Desaparecido - SosVirus Lancé à 10:53:41 | 17/10/2014 Site Web : [url=http://www.usbfix.net/]http://www.usbfix.net/[/url] Changelog : [url=http://www.usbfix.net/maj/]http://www.usbfix.net/maj/[/url] Assistance : [url=http://www.sosvirus.net/forum-virus-securite.html]http://www.sosvirus.net/forum-virus-securite.html[/url] Upload Malware : [url=http://www.sosvirus.net/upload_malware.php]http://www.sosvirus.net/upload_malware.php[/url] Détection en Live : [url=http://comment-supprimer.fr/]http://comment-supprimer.fr/[/url] Contact : [url=http://www.usbfix.net/contact/]http://www.usbfix.net/contact/[/url] [b]################## | System information |[/b] MB: LENOVO (MoutCook) CPU: Intel(R) Core(TM) i3 CPU M 380 @ 2.53GHz RAM -> [Total : 3829 Mo | Free : 1608 Mo] Bios: LENOVO Boot: Normal boot OS: Microsoft™ Windows 7 Home Premium (6.1.7601 64-Bit) Service Pack 1 WB: Internet Explorer : 11.00.9600.16428 WB: Mozilla Firefox : 33.0 [b]################## | Security Information |[/b] AV: avast! Antivirus [[b](!) Désactivé[/b] |[b](!) Non à jour[/b]] AS: Windows Defender [Actif |A jour] AS: avast! Antivirus [[b](!) Désactivé[/b] |[b](!) Non à jour[/b]] AS: Malwarebytes Anti-Malware : 2.0.3.1025 FW: Windows Firewall [Actif] SC: Security Center [Actif] WU: Windows Update [Actif] [b]################## | Disk Information |[/b] C:\ (%SystemDrive%) -> Disque fixe # 254 Go (65 Go libre(s) - 26%) [] # NTFS D:\ -> Disque fixe # 29 Go (15 Go libre(s) - 51%) [LENOVO] # NTFS [b]################## | Regedit Run |[/b] F2 - HKLM\..\Winlogon : [Shell] explorer.exe F2 - [x64] HKLM\..\Winlogon : [Shell] explorer.exe F2 - HKLM\..\Winlogon : [Userinit] userinit.exe, F2 - [x64] HKLM\..\Winlogon : [Userinit] C:\Windows\system32\userinit.exe, 04 - HKCU\..\Run : [iCloudServices] C:\Program Files (x86)\Common Files\Apple\Internet Services\iCloudServices.exe 04 - HKCU\..\Run : [FileHippo.com] "C:\Program Files (x86)\FileHippo.com\FileHippo.AppManager.exe" /background 04 - HKCU\..\RunOnce : [Uninstall C:\Users\catherinepomper\AppData\Local\Microsoft\SkyDrive\16.4.6013.0910\amd64] C:\windows\system32\cmd.exe /q /c rmdir /s /q "C:\Users\catherinepomper\AppData\Local\Microsoft\SkyDrive\16.4.6013.0910\amd64" 04 - HKCU\..\RunOnce : [Uninstall C:\Users\catherinepomper\AppData\Local\Microsoft\SkyDrive\16.4.6013.0910] C:\windows\system32\cmd.exe /q /c rmdir /s /q "C:\Users\catherinepomper\AppData\Local\Microsoft\SkyDrive\16.4.6013.0910" 04 - HKCU\..\RunOnce : [Uninstall C:\Users\catherinepomper\AppData\Local\Microsoft\SkyDrive\17.0.4024.1220\amd64] C:\windows\system32\cmd.exe /q /c rmdir /s /q "C:\Users\catherinepomper\AppData\Local\Microsoft\SkyDrive\17.0.4024.1220\amd64" 04 - HKCU\..\RunOnce : [Uninstall C:\Users\catherinepomper\AppData\Local\Microsoft\SkyDrive\17.0.4024.1220] C:\windows\system32\cmd.exe /q /c rmdir /s /q "C:\Users\catherinepomper\AppData\Local\Microsoft\SkyDrive\17.0.4024.1220" 04 - HKLM\..\Run : [IAStorIcon] C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe 04 - HKLM\..\Run : [IMSS] "C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IMSS\PIconStartup.exe" 04 - HKLM\..\Run : [VitaKeyTSR] "C:\Program Files (x86)\EgisTec BioExcess\EgisTSR.exe" 04 - HKLM\..\Run : [UpdateP2GShortCut] "C:\Program Files (x86)\Lenovo\Power2Go\MUITransfer\MUIStartMenu.exe" "C:\Program Files (x86)\Lenovo\Power2Go" UpdateWithCreateOnce "SOFTWARE\CyberLink\Power2Go\5.0" 04 - HKLM\..\Run : [UCam_Menu] "C:\Program Files (x86)\Lenovo\YouCam\MUITransfer\MUIStartMenu.exe" "C:\Program Files (x86)\Lenovo\YouCam" UpdateWithCreateOnce "Software\CyberLink\YouCam\3.0" 04 - HKLM\..\Run : [YouCam Mirror Tray icon] "C:\Program Files (x86)\Lenovo\YouCam\YouCamTray.exe" /s 04 - HKLM\..\Run : [EgisTecPMMUpdate] "C:\Program Files (x86)\EgisTec IPS\PmmUpdate.exe" 04 - HKLM\..\Run : [EgisUpdate] "C:\Program Files (x86)\EgisTec IPS\EgisUpdate.exe" -d 04 - HKLM\..\Run : [PLTSR] "C:\Program Files (x86)\EgisTec Port Locker\EgisPLTSR.exe" 04 - HKLM\..\Run : [UpdatePRCShortCut] "C:\Program Files\Lenovo\OneKey App\OneKey Recovery\MUITransfer\MUIStartMenu.exe" "C:\Program Files\Lenovo\OneKey App\OneKey Recovery" UpdateWithCreateOnce "Software\Lenovo\OneKey App\OneKey Recovery" 04 - HKLM\..\Run : [APSDaemon] "C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe" 04 - HKLM\..\Run : [AvastUI.exe] "C:\Program Files\AVAST Software\Avast\AvastUI.exe" /nogui 04 - HKLM\..\Run : [Adobe ARM] "C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe" 04 - HKLM\..\Run : [CanonSolutionMenuEx] C:\Program Files (x86)\Canon\Solution Menu EX\CNSEMAIN.EXE /logon 04 - HKLM\..\Run : [IJNetworkScannerSelectorEX] C:\Program Files (x86)\Canon\IJ Network Scanner Selector EX\CNMNSST.exe /FORCE 04 - HKLM\..\Run : [QuickTime Task] "C:\Program Files (x86)\QuickTime\QTTask.exe" -atboottime 04 - HKLM\..\Run : [TkBellExe] "c:\program files (x86)\real\realplayer\Update\realsched.exe" -osboot 04 - HKLM\..\Run : [SunJavaUpdateSched] "C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe" 04 - HKLM\..\Run : [iTunesHelper] "C:\Program Files (x86)\iTunes\iTunesHelper.exe" 04 - [x64] HKLM\..\Run : [IgfxTray] C:\windows\system32\igfxtray.exe 04 - [x64] HKLM\..\Run : [HotKeysCmds] C:\windows\system32\hkcmd.exe 04 - [x64] HKLM\..\Run : [Persistence] C:\windows\system32\igfxpers.exe 04 - [x64] HKLM\..\Run : [RtHDVCpl] C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe -s 04 - [x64] HKLM\..\Run : [ETDWare] %ProgramFiles%\Elantech\ETDCtrl.exe 04 - [x64] HKLM\..\Run : [UpdatePRCShortCut] "C:\Program Files\Lenovo\OneKey App\OneKey Recovery\MUITransfer\MUIStartMenu.exe" "C:\Program Files\Lenovo\OneKey App\OneKey Recovery" UpdateWithCreateOnce "Software\Lenovo\OneKey App\OneKey Recovery" 04 - [x64] HKLM\..\Run : [EnergyUtility] C:\Program Files (x86)\Lenovo\Energy Management\utility.exe 04 - [x64] HKLM\..\Run : [Energy Management] C:\Program Files (x86)\Lenovo\Energy Management\Energy Management.exe 04 - [x64] HKLM\..\Run : [CanonMyPrinter] C:\Program Files\Canon\MyPrinter\BJMyPrt.exe /logon 04 - HKU\S-1-5-19\..\Run : [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun 04 - HKU\S-1-5-20\..\Run : [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun 04 - HKU\S-1-5-21-2564878898-3060027615-1487160507-1000\..\Run : [iCloudServices] C:\Program Files (x86)\Common Files\Apple\Internet Services\iCloudServices.exe 04 - HKU\S-1-5-21-2564878898-3060027615-1487160507-1000\..\Run : [FileHippo.com] "C:\Program Files (x86)\FileHippo.com\FileHippo.AppManager.exe" /background 04 - HKU\S-1-5-19\..\RunOnce : [mctadmin] C:\Windows\System32\mctadmin.exe 04 - HKU\S-1-5-20\..\RunOnce : [mctadmin] C:\Windows\System32\mctadmin.exe 04 - HKU\S-1-5-21-2564878898-3060027615-1487160507-1000\..\RunOnce : [Uninstall C:\Users\catherinepomper\AppData\Local\Microsoft\SkyDrive\16.4.6013.0910\amd64] C:\windows\system32\cmd.exe /q /c rmdir /s /q "C:\Users\catherinepomper\AppData\Local\Microsoft\SkyDrive\16.4.6013.0910\amd64" 04 - HKU\S-1-5-21-2564878898-3060027615-1487160507-1000\..\RunOnce : [Uninstall C:\Users\catherinepomper\AppData\Local\Microsoft\SkyDrive\16.4.6013.0910] C:\windows\system32\cmd.exe /q /c rmdir /s /q "C:\Users\catherinepomper\AppData\Local\Microsoft\SkyDrive\16.4.6013.0910" 04 - HKU\S-1-5-21-2564878898-3060027615-1487160507-1000\..\RunOnce : [Uninstall C:\Users\catherinepomper\AppData\Local\Microsoft\SkyDrive\17.0.4024.1220\amd64] C:\windows\system32\cmd.exe /q /c rmdir /s /q "C:\Users\catherinepomper\AppData\Local\Microsoft\SkyDrive\17.0.4024.1220\amd64" 04 - HKU\S-1-5-21-2564878898-3060027615-1487160507-1000\..\RunOnce : [Uninstall C:\Users\catherinepomper\AppData\Local\Microsoft\SkyDrive\17.0.4024.1220] C:\windows\system32\cmd.exe /q /c rmdir /s /q "C:\Users\catherinepomper\AppData\Local\Microsoft\SkyDrive\17.0.4024.1220" [b]################## | Recherche générique |[/b] [b]################## | Registre |[/b] [b]################## | UsbFix - Information |[/b] Info : [url=https://www.youtube.com/watch?v=vUZYYASd7FE]Comment supprimer l'infection des raccourcis sur USB ? (Video)[/url] Info : [url=http://www.en.usbfix.net/2014/03/remove-shortcut-virus-usb/]L'infection des raccourcis USB, c'est quoi ?[/url] [b]################## | Hijack |[/b] [b]################## | E.O.F | [url=http://www.sosvirus.net/]http://www.sosvirus.net/[/url] | [url=http://www.usbfix.net/]http://www.usbfix.net/[/url] |[/b]