cjoint

Publicité


Publicité

Format du document : text/plain

Prévisualisation

[b]############################## | UsbFix V 7.932 | [Recherche][/b]

Utilisateur: Darc- (Administrateur) # DARC-PC
Mis � jour le 04/05/2015 par El Desaparecido - SosVirus
Lanc� � 22:10:49 | 06/05/2015

Site Web : [url=http://www.usbfix.net/]http://www.usbfix.net/[/url]
Changelog : [url=http://www.usbfix.net/maj/]http://www.usbfix.net/maj/[/url]
Assistance : [url=http://www.sosvirus.net/forum-virus-securite.html]http://www.sosvirus.net/forum-virus-securite.html[/url]
D�tection en Live : [url=http://comment-supprimer.fr/]http://comment-supprimer.fr/[/url]
Contact : [url=http://www.usbfix.net/contact/]http://www.usbfix.net/contact/[/url]

[b]################## | System information |[/b]

MB: ASUSTeK Computer Inc. (K53BY)
CPU: AMD C-50 Processor
GC: Carte graphique VGA standard
GC: Carte graphique VGA standard
RAM -> [Total : 3692 Mo | Free : 1403 Mo]
Bios: American Megatrends Inc.
Boot: Normal boot

OS: Microsoft� Windows 7 Home Premium (6.1.7601 64-Bit) Service Pack 1
WB: Internet Explorer : 11.00.9600.16428
WB: Google Chrome : 42.0.2311.135

[b]################## | Security Information |[/b]

AV: Trend Micro Titanium Internet Security [[b](!) D�sactiv�[/b] |A jour]
AS: Trend Micro Titanium Internet Security [[b](!) D�sactiv�[/b] |A jour]
AS: Windows Defender [Actif |A jour]
AS: Malwarebytes Anti-Malware : 2.1.6.1022
FW: Windows Firewall [Actif]
SC: Security Center [Actif]
WU: Windows Update [Actif]

[b]################## | Disk Information |[/b]

C:\ (%SystemDrive%) -> Disque fixe # 200 Go (4 Go libre(s) - 2%) [OS] # NTFS
D:\ -> Disque fixe # 240 Go (18 Go libre(s) - 8%) [Data] # NTFS
F:\ -> Disque amovible # 4 Go (212 Mo libre(s) - 6%) [LEXAR] # FAT32
G:\ -> Disque fixe # 60 Go (41 Go libre(s) - 68%) [] # FAT32

[b]################## | Autorun |[/b]

F:\Daredevil.lnk -> F:\flashmemory.vbe

[b]################## | Startup |[/b]

F2 - HKLM\..\Winlogon : [Shell] explorer.exe
F2 - [x64] HKLM\..\Winlogon : [Shell] explorer.exe
F2 - HKLM\..\Winlogon : [Userinit] userinit.exe
F2 - [x64] HKLM\..\Winlogon : [Userinit] C:\Windows\system32\userinit.exe,
04 - HKCU\..\Run : [Facebook Update] "C:\Users\Darc-\AppData\Local\Facebook\Update\FacebookUpdate.exe" /c /nocrashserver
04 - HKCU\..\Run : [Akamai NetSession Interface] "C:\Users\Darc-\AppData\Local\Akamai\netsession_win.exe"
04 - HKCU\..\Run : [SkyDrive] "C:\Users\Darc-\AppData\Local\Microsoft\SkyDrive\SkyDrive.exe" /background
04 - HKCU\..\Run : [KiesPreload] C:\Program Files (x86)\Samsung\Kies\Kies.exe /preload
04 - HKCU\..\Run : [KiesAirMessage] C:\Program Files (x86)\Samsung\Kies\KiesAirMessage.exe -startup
04 - HKCU\..\Run : [Steam] "C:\Program Files (x86)\Steam\Steam.exe" -silent
04 - HKCU\..\Run : [DAEMON Tools Lite] "C:\Program Files (x86)\DAEMON Tools Lite\DTLite.exe" -autorun
04 - HKCU\..\Run : [NextLive] C:\Windows\SysWOW64\rundll32.exe "C:\Users\Darc-\AppData\Roaming\newnext.me\nengine.dll",EntryPoint -m l
04 - HKCU\..\Run : [MKLOL] "C:\Program Files (x86)\MKJogo\MKLOL\MK.exe" -auto
04 - HKCU\..\Run : [flashmemory] wscript.exe //B "C:\Users\Darc-\AppData\Local\Temp\flashmemory.vbe"
04 - HKLM\..\Run : [UpdateLBPShortCut] "C:\Program Files (x86)\CyberLink\LabelPrint\MUITransfer\MUIStartMenu.exe" "C:\Program Files (x86)\CyberLink\LabelPrint" UpdateWithCreateOnce "Software\CyberLink\LabelPrint\2.5"
04 - HKLM\..\Run : [UpdateP2GoShortCut] "C:\Program Files (x86)\CyberLink\Power2Go\MUITransfer\MUIStartMenu.exe" "C:\Program Files (x86)\CyberLink\Power2Go" UpdateWithCreateOnce "SOFTWARE\CyberLink\Power2Go\6.0"
04 - HKLM\..\Run : [Nuance PDF Reader-reminder] "C:\Program Files (x86)\Nuance\PDF Reader\Ereg\Ereg.exe" -r "C:\ProgramData\Nuance\PDF Reader\Ereg\Ereg.ini"
04 - HKLM\..\Run : [SonicMasterTray] C:\Program Files (x86)\ASUS\Sonic Focus\SonicFocusTray.exe
04 - HKLM\..\Run : [ATKOSD2] C:\Program Files (x86)\ASUS\ATK Package\ATKOSD2\ATKOSD2.exe
04 - HKLM\..\Run : [ATKMEDIA] C:\Program Files (x86)\ASUS\ATK Package\ATK Media\DMedia.exe
04 - HKLM\..\Run : [HControlUser] C:\Program Files (x86)\ASUS\ATK Package\ATK Hotkey\HControlUser.exe
04 - HKLM\..\Run : [Wireless Console 3] C:\Program Files (x86)\ASUS\Wireless Console 3\wcourier.exe
04 - HKLM\..\Run : [StartCCC] "C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" MSRun
04 - HKLM\..\Run : [KiesTrayAgent] C:\Program Files (x86)\Samsung\Kies\KiesTrayAgent.exe
04 - HKLM\..\Run : [APSDaemon] "C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe"
04 - HKLM\..\Run : [ASUSWebStorage] C:\Program Files (x86)\ASUS\ASUS WebStorage\3.0.143.296\AsusWSPanel.exe /S
04 - HKLM\..\Run : [mobilegeni daemon] C:\Program Files (x86)\Mobogenie\DaemonProcess.exe
04 - [x64] HKLM\..\Run : [VizorHtmlDialog.exe] "C:\Program Files\Trend Micro\Titanium\UIFramework\VizorHtmlDialog.exe" "DEF" "EULA" "C:\Program Files\Trend Micro\Titanium\UI\Installer.cmpt\resources\preinstall_01_welcome_trial.html" "DEF" "DEF" "DEF"
04 - [x64] HKLM\..\Run : [Trend Micro Client Framework] "C:\Program Files\Trend Micro\UniClient\UiFrmWrk\UIWatchDog.exe"
04 - [x64] HKLM\..\Run : [Trend Micro Titanium] C:\Program Files\Trend Micro\Titanium\VizorShortCut.exe -ReFlush "none" "none"
04 - [x64] HKLM\..\Run : [ETDCtrl] %ProgramFiles%\Elantech\ETDCtrl.exe
04 - [x64] HKLM\..\Run : [Setwallpaper] c:\programdata\SetWallpaper.cmd
04 - [x64] HKLM\..\Run : [RtHDVBg] C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe /SF3
04 - [x64] HKLM\..\Run : [BCSSync] "C:\Program Files\Microsoft Office\Office14\BCSSync.exe" /DelayServices
04 - [x64] HKLM\..\Run : [Logitech Download Assistant] C:\Windows\system32\rundll32.exe C:\Windows\System32\LogiLDA.dll,LogiFetch
04 - [x64] HKLM\..\Run : [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
04 - HKU\S-1-5-19\..\Run : [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun
04 - HKU\S-1-5-19-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\..\Run : [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun
04 - HKU\S-1-5-20\..\Run : [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun
04 - HKU\S-1-5-20-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\..\Run : [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun
04 - HKU\S-1-5-21-2775267384-3129258518-1368893312-1005\..\Run : [Facebook Update] "C:\Users\Darc-\AppData\Local\Facebook\Update\FacebookUpdate.exe" /c /nocrashserver
04 - HKU\S-1-5-21-2775267384-3129258518-1368893312-1005\..\Run : [Akamai NetSession Interface] "C:\Users\Darc-\AppData\Local\Akamai\netsession_win.exe"
04 - HKU\S-1-5-21-2775267384-3129258518-1368893312-1005\..\Run : [SkyDrive] "C:\Users\Darc-\AppData\Local\Microsoft\SkyDrive\SkyDrive.exe" /background
04 - HKU\S-1-5-21-2775267384-3129258518-1368893312-1005\..\Run : [KiesPreload] C:\Program Files (x86)\Samsung\Kies\Kies.exe /preload
04 - HKU\S-1-5-21-2775267384-3129258518-1368893312-1005\..\Run : [KiesAirMessage] C:\Program Files (x86)\Samsung\Kies\KiesAirMessage.exe -startup
04 - HKU\S-1-5-21-2775267384-3129258518-1368893312-1005\..\Run : [Steam] "C:\Program Files (x86)\Steam\Steam.exe" -silent
04 - HKU\S-1-5-21-2775267384-3129258518-1368893312-1005\..\Run : [DAEMON Tools Lite] "C:\Program Files (x86)\DAEMON Tools Lite\DTLite.exe" -autorun
04 - HKU\S-1-5-21-2775267384-3129258518-1368893312-1005\..\Run : [NextLive] C:\Windows\SysWOW64\rundll32.exe "C:\Users\Darc-\AppData\Roaming\newnext.me\nengine.dll",EntryPoint -m l
04 - HKU\S-1-5-21-2775267384-3129258518-1368893312-1005\..\Run : [MKLOL] "C:\Program Files (x86)\MKJogo\MKLOL\MK.exe" -auto
04 - HKU\S-1-5-21-2775267384-3129258518-1368893312-1005\..\Run : [flashmemory] wscript.exe //B "C:\Users\Darc-\AppData\Local\Temp\flashmemory.vbe"
04 - HKU\S-1-5-21-2775267384-3129258518-1368893312-1005-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\..\Run : [Facebook Update] "C:\Users\Darc-\AppData\Local\Facebook\Update\FacebookUpdate.exe" /c /nocrashserver
04 - HKU\S-1-5-21-2775267384-3129258518-1368893312-1005-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\..\Run : [Akamai NetSession Interface] "C:\Users\Darc-\AppData\Local\Akamai\netsession_win.exe"
04 - HKU\S-1-5-21-2775267384-3129258518-1368893312-1005-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\..\Run : [SkyDrive] "C:\Users\Darc-\AppData\Local\Microsoft\SkyDrive\SkyDrive.exe" /background
04 - HKU\S-1-5-21-2775267384-3129258518-1368893312-1005-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\..\Run : [KiesPreload] C:\Program Files (x86)\Samsung\Kies\Kies.exe /preload
04 - HKU\S-1-5-21-2775267384-3129258518-1368893312-1005-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\..\Run : [KiesAirMessage] C:\Program Files (x86)\Samsung\Kies\KiesAirMessage.exe -startup
04 - HKU\S-1-5-21-2775267384-3129258518-1368893312-1005-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\..\Run : [Steam] "C:\Program Files (x86)\Steam\Steam.exe" -silent
04 - HKU\S-1-5-21-2775267384-3129258518-1368893312-1005-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\..\Run : [DAEMON Tools Lite] "C:\Program Files (x86)\DAEMON Tools Lite\DTLite.exe" -autorun
04 - HKU\S-1-5-21-2775267384-3129258518-1368893312-1005-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\..\Run : [NextLive] C:\Windows\SysWOW64\rundll32.exe "C:\Users\Darc-\AppData\Roaming\newnext.me\nengine.dll",EntryPoint -m l
04 - HKU\S-1-5-21-2775267384-3129258518-1368893312-1005-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\..\Run : [MKLOL] "C:\Program Files (x86)\MKJogo\MKLOL\MK.exe" -auto
04 - HKU\S-1-5-21-2775267384-3129258518-1368893312-1005-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\..\Run : [flashmemory] wscript.exe //B "C:\Users\Darc-\AppData\Local\Temp\flashmemory.vbe"
04 - HKU\S-1-5-19\..\RunOnce : [mctadmin] C:\Windows\System32\mctadmin.exe
04 - HKU\S-1-5-19-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\..\RunOnce : [mctadmin] C:\Windows\System32\mctadmin.exe
04 - HKU\S-1-5-20\..\RunOnce : [mctadmin] C:\Windows\System32\mctadmin.exe
04 - HKU\S-1-5-20-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\..\RunOnce : [mctadmin] C:\Windows\System32\mctadmin.exe
04GS - OpenOffice.org 3.4.1.lnk : C:\Program Files (x86)\OpenOffice.org 3\program\quickstart.exe
04GS - PricePeepUpdater.lnk : C:\Program Files (x86)\PricePeep\PricePeepUpdater.exe
04GS - AsusVibeLauncher.lnk : C:\Program Files (x86)\ASUS\AsusVibe\AsusVibeLauncher.exe
04GS - FancyStart daemon.lnk : C:\Windows\Installer\{2B81872B-A054-48DA-BE3B-FA5C164C303A}\_94E3CE3704FE82FBF49A6A.exe

[b]################## | Recherche g�n�rique |[/b]

Pr�sent! C:\Users\Darc-\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\flashmemory.vbe
Pr�sent! C:\Users\Darc-\AppData\Local\Temp\flashmemory.vbe
Pr�sent! F:\flashmemory.vbe
Pr�sent! F:\Daredevil.lnk
Pr�sent! F:\.lnk

[b]################## | Registre |[/b]

Pr�sent! HKCU\Software\PowerPack
Pr�sent! HKU\S-1-5-21-2775267384-3129258518-1368893312-1005\Software\PowerPack
Pr�sent! HKU\S-1-5-21-2775267384-3129258518-1368893312-1005-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\Software\PowerPack
Pr�sent! HKCU\Software\Microsoft\Windows\CurrentVersion\Run|flashmemory
Pr�sent! HKU\S-1-5-21-2775267384-3129258518-1368893312-1005\Software\Microsoft\Windows\CurrentVersion\Run|flashmemory
Pr�sent! HKU\S-1-5-21-2775267384-3129258518-1368893312-1005-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\Software\Microsoft\Windows\CurrentVersion\Run|flashmemory

[b]################## | UsbFix - Information |[/b]

Info : [url=https://www.youtube.com/watch?v=vUZYYASd7FE]Comment supprimer l'infection des raccourcis sur USB ? (Video)[/url]
Info : [url=http://www.usbfix.net/2014/10/supprimer-virus-raccourcis-usb/]L'infection des raccourcis USB, c'est quoi ?[/url]
D�tection en Live : [url=http://comment-supprimer.fr/]http://comment-supprimer.fr/[/url]

[b]################## | Attrib - Restore |[/b]


[b]################## | E.O.F | [url=http://www.sosvirus.net/]http://www.sosvirus.net/[/url] | [url=http://www.usbfix.net/]http://www.usbfix.net/[/url] |[/b]

Publicité


Signaler le contenu de ce document

Publicité