cjoint

Publicité


Publicité

Commentaire : UsbFix Scan 1 ABDUSSALAM-PC.txt

Format du document : text/plain

Prévisualisation

[b]############################## | UsbFix V 8.154 | [Research][/b]

User: Abdussalam (Administrator) # ABDUSSALAM-PC
Updated 24/11/2015 by SosVirus
Started at 13:44:23 | 29/12/2015

Website : [url=http://www.en.usbfix.net/]http://www.en.usbfix.net/[/url]
Tutorial : [url=http://www.pt.usbfix.net/2014/03/tutorial-do-usbfix-scan/]http://www.pt.usbfix.net/2014/03/tutorial-do-usbfix-scan/[/url]
Support : [url=http://www.sos-virus.net/]http://www.sos-virus.net/[/url]
Live detection : [url=http://how-to-remove.us/]http://how-to-remove.us/[/url]
Contact : [url=http://www.en.usbfix.net/contact/]http://www.en.usbfix.net/contact/[/url]

[b]################## | System information |[/b]

MB: Type2 - Board Vendor Name1 (Type2 - Board Product Name1)
CPU: Intel(R) Core(TM) i5-3230M CPU @ 2.60GHz
RAM -> [Total : 3988 Mo | Free : 2034 Mo]
Bios: Insyde Corp.
Boot: Normal boot

OS: Microsoft™ Windows 7 Ultimate (6.1.7601 64-Bit) Service Pack 1
WB: Internet Explorer : 11.00.9600.16428
WB: Google Chrome : 30.0.1573.2
WB: Mozilla Firefox : 38.0.5
WB: Opera : 34.0.2036.25

[b]################## | Security Information |[/b]

AV: McAfee VirusScan Enterprise [Enabled |Updated]
AS: Windows Defender [[b](!) Disabled[/b] |Updated]
FW: Windows Firewall [Enabled]
SC: Security Center [Enabled]
WU: Windows Update [Enabled]

[b]################## | Disk Information |[/b]

C:\ (%SystemDrive%) -> Fixed disk # 98 Gb (9 Gb free - 9%) [] # NTFS
D:\ -> Fixed disk # 195 Gb (31 Gb free - 16%) [Downloading] # NTFS
E:\ -> Fixed disk # 98 Gb (17 Gb free - 17%) [Entertainment] # NTFS
G:\ -> Removable disk # 15 Gb (2 Gb free - 12%) [BEN ALLA] # FAT32
H:\ -> Fixed disk # 75 Gb (21 Gb free - 28%) [Spé] # NTFS
I:\ -> CD-ROM # 668 Mb (0 Mb free - 0%) [OALD8] # CDFS

[b]################## | Startup |[/b]

F2 - HKLM\..\Winlogon : [Shell] explorer.exe
F2 - [x64] HKLM\..\Winlogon : [Shell] explorer.exe
F2 - HKLM\..\Winlogon : [Userinit] userinit.exe
F2 - [x64] HKLM\..\Winlogon : [Userinit] C:\Windows\system32\userinit.exe,
04 - HKCU\..\Run : [DAEMON Tools Pro Agent] "C:\Program Files (x86)\DAEMON Tools Pro\DTAgent.exe" -autorun
04 - HKCU\..\Run : [Le Petit Robert V3 Hyperappel] C:\Program Files\Le Robert\Le Petit Robert 2010\RobertHA.exe
04 - HKCU\..\Run : [Skype] "C:\Program Files (x86)\Skype\Phone\Skype.exe" /minimized /regrun
04 - HKCU\..\Run : [YTDownloader] "C:\Program Files (x86)\YTDownloader\YTDownloader.exe" /boot
04 - HKCU\..\Run : [RESTART_STICKY_NOTES] C:\Windows\System32\StikyNot.exe
04 - HKCU\..\Run : [4c9b62d819bccb0b01cc8c566c166126] "C:\Users\Abdussalam\AppData\Local\Temp\jlaw.exe" ..
04 - HKCU\..\Run : [winlogon] "C:\Users\ABDUSS~1\AppData\Local\Temp\winlogon.bat"
04 - HKLM\..\Run : [IME14 CHT Setup] C:\PROGRA~2\COMMON~1\MICROS~1\IME14\SHARED\IMEKLMG.EXE /SetPreload /CHT /Log
04 - HKLM\..\Run : [IME14 JPN Setup] C:\PROGRA~2\COMMON~1\MICROS~1\IME14\SHARED\IMEKLMG.EXE /SetPreload /JPN /Log
04 - HKLM\..\Run : [IME14 KOR Setup] C:\PROGRA~2\COMMON~1\MICROS~1\IME14\SHARED\IMEKLMG.EXE /SetPreload /KOR /Log
04 - HKLM\..\Run : [IME14 CHS Setup] C:\PROGRA~2\COMMON~1\MICROS~1\IME14\SHARED\IMEKLMG.EXE /SetPreload /CHS /Log
04 - HKLM\..\Run : [CanonSolutionMenuEx] C:\Program Files (x86)\Canon\Solution Menu EX\CNSEMAIN.EXE /logon
04 - HKLM\..\Run : [YTDownloader] "C:\Program Files (x86)\YTDownloader\YTDownloader.exe" /boot
04 - HKLM\..\Run : [TrayServer] C:\Program Files (x86)\MAGIX\Video_deluxe_17_Premium_Version_a_telecharger\TrayServer_fr.exe
04 - HKLM\..\Run : [SunJavaUpdateSched] "C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe"
04 - HKLM\..\Run : [HP Software Update] C:\Program Files (x86)\HP\HP Software Update\HPWuSchd2.exe
04 - HKLM\..\Run : [setup.exe -start] C:\Users\ABDUSS~1\AppData\Local\Temp\setup.exe -start
04 - HKLM\..\Run : [4c9b62d819bccb0b01cc8c566c166126] "C:\Users\Abdussalam\AppData\Local\Temp\jlaw.exe" ..
04 - HKLM\..\Run : [McAfeeUpdaterUI] "C:\Program Files (x86)\McAfee\Common Framework\udaterui.exe" /StartedFromRunKey
04 - HKLM\..\Run : [ShStatEXE] "C:\Program Files (x86)\McAfee\VirusScan Enterprise\SHSTAT.EXE" /STANDALONE
04 - [x64] HKLM\..\Run : [IgfxTray] C:\Windows\system32\igfxtray.exe
04 - [x64] HKLM\..\Run : [HotKeysCmds] C:\Windows\system32\hkcmd.exe
04 - [x64] HKLM\..\Run : [Persistence] C:\Windows\system32\igfxpers.exe
04 - [x64] HKLM\..\Run : [SynTPEnh] %ProgramFiles%\Synaptics\SynTP\SynTPEnh.exe
04 - [x64] HKLM\..\Run : [RtHDVCpl] C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe -s
04 - [x64] HKLM\..\Run : [BCSSync] "C:\Program Files\Microsoft Office\Office14\BCSSync.exe" /DelayServices
04 - [x64] HKLM\..\Run : [IME14 CHT Setup] C:\PROGRA~1\COMMON~1\MICROS~1\IME14\SHARED\IMEKLMG.EXE /SetPreload /CHT /Log
04 - [x64] HKLM\..\Run : [IME14 JPN Setup] C:\PROGRA~1\COMMON~1\MICROS~1\IME14\SHARED\IMEKLMG.EXE /SetPreload /JPN /Log
04 - [x64] HKLM\..\Run : [IME14 KOR Setup] C:\PROGRA~1\COMMON~1\MICROS~1\IME14\SHARED\IMEKLMG.EXE /SetPreload /KOR /Log
04 - [x64] HKLM\..\Run : [IME14 CHS Setup] C:\PROGRA~1\COMMON~1\MICROS~1\IME14\SHARED\IMEKLMG.EXE /SetPreload /CHS /Log
04 - [x64] HKLM\..\Run : [CanonMyPrinter] C:\Program Files\Canon\MyPrinter\BJMyPrt.exe /logon
04 - [x64] HKLM\..\Run : [bintin] C:\WINDOWS\system32\wscript.exe /e:VBScript.Encode D:\bin.doc
04 - [x64] HKLM\..\Run : [InstallerLauncher] "C:\Program Files\Common Files\Bitdefender\SetupInformation\{6F57816A-791A-4159-A75F-CFD0C7EA4FBF}\setuplauncher.exe" /run:"C:\Program Files\Common Files\Bitdefender\SetupInformation\{6F57816A-791A-4159-A75F-CFD0C7EA4FBF}\Installer.exe"
04 - [x64] HKLM\..\Run : [winlogon] "C:\Users\ABDUSS~1\AppData\Local\Temp\winlogon.bat"
04 - HKU\S-1-5-19\..\Run : [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun
04 - HKU\S-1-5-20\..\Run : [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun
04 - HKU\S-1-5-21-1841702979-3207138838-463625945-1000\..\Run : [DAEMON Tools Pro Agent] "C:\Program Files (x86)\DAEMON Tools Pro\DTAgent.exe" -autorun
04 - HKU\S-1-5-21-1841702979-3207138838-463625945-1000\..\Run : [Le Petit Robert V3 Hyperappel] C:\Program Files\Le Robert\Le Petit Robert 2010\RobertHA.exe
04 - HKU\S-1-5-21-1841702979-3207138838-463625945-1000\..\Run : [Skype] "C:\Program Files (x86)\Skype\Phone\Skype.exe" /minimized /regrun
04 - HKU\S-1-5-21-1841702979-3207138838-463625945-1000\..\Run : [YTDownloader] "C:\Program Files (x86)\YTDownloader\YTDownloader.exe" /boot
04 - HKU\S-1-5-21-1841702979-3207138838-463625945-1000\..\Run : [RESTART_STICKY_NOTES] C:\Windows\System32\StikyNot.exe
04 - HKU\S-1-5-21-1841702979-3207138838-463625945-1000\..\Run : [4c9b62d819bccb0b01cc8c566c166126] "C:\Users\Abdussalam\AppData\Local\Temp\jlaw.exe" ..
04 - HKU\S-1-5-21-1841702979-3207138838-463625945-1000\..\Run : [winlogon] "C:\Users\ABDUSS~1\AppData\Local\Temp\winlogon.bat"
04 - HKU\S-1-5-19\..\RunOnce : [mctadmin] C:\Windows\System32\mctadmin.exe
04 - HKU\S-1-5-20\..\RunOnce : [mctadmin] C:\Windows\System32\mctadmin.exe
04GS - Microsoft.Windows.7.Ultimate.SP1.x64.FRENCH.ISO.Integrated.January.2013 [FRENCH l MULTI].lnk : C:\ProgramData\{7b8d4422-5698-5230-7b8d-d44225691089}\Microsoft.Windows.7.Ultimate.SP1.x64.FRENCH.ISO.Integrated.January.2013 [FRENCH l MULTI].exe
04GS - Start.lnk : C:\Windows\system32\wscript.exe
04GS - Bluetooth Monitor.lnk : C:\Program Files (x86)\TOSHIBA\Bluetooth Monitor\BtMon2.exe
04GS - HP Digital Imaging Monitor.lnk : C:\Program Files (x86)\HP\Digital Imaging\bin\hpqtra08.exe
04GS - Hyperappel du Petit Larousse 2010.lnk : C:\Program Files (x86)\Larousse\Petit Larousse 2010\bin\Hyperappel.exe
04GS - Launcher.lnk : C:\Program Files (x86)\MeditelInternet\MeditelInternet_Launcher.exe

[b]################## | Generic Research |[/b]

Found! G:\winlogon.vbs
Found! G:\test_write1.lnk
Found! G:\test_write2.lnk
Found! G:\l'application des NTIC dans le secteur public.lnk
Found! G:\~$l'application des NTIC dans le secteur public.lnk
Found! G:\Module.lnk
Found! G:\Demande_Inscription_Examen20150824.lnk
Found! G:\Formation et séminaire.lnk
Found! G:\document.lnk
Found! G:\Programme de première année de guitare.lnk
Found! G:\cables et conducteurs_eleve.lnk
Found! G:\conducteurs_cables_exercices_2.lnk
Found! G:\canalisations_prof.lnk
Found! G:\ALIDVRS2.lnk
Found! G:\.Trash-1000.lnk
Found! G:\Docummentaires-Astra.lnk
Found! G:\New folder.lnk
Found! G:\Theses of photovoltaic.lnk
Found! G:\$RECYCLEBIN.lnk
Found! G:\Nouveau dossier (14).lnk
Found! G:\ENS RABAT-formation 10000 cadres.lnk
Found! G:\Videos naima.lnk
Found! G:\ÉLECTROMÉCANIQUE DE SYSTEMES AUTOMATISES.lnk
Found! G:\FM_TSMFM_Ressources.lnk
Found! G:\ESA_CDS.lnk
Found! C:\Users\ABDUSS~1\AppData\Local\Temp\jlaw.exe
Found! C:\Users\ABDUSS~1\AppData\Local\Temp\jlaw.exe.tmp
Found! C:\Users\Abdussalam\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\4c9b62d819bccb0b01cc8c566c166126.exe
Found! C:\Users\Abdussalam\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Start.lnk
Found! C:\Users\ABDUSS~1\AppData\Local\Temp\winlogon.bat
Found! G:\$RECYCLEBIN\04
Found! G:\$RECYCLEBIN\06
Found! G:\$RECYCLEBIN\Skype.rar
Found! G:\$RECYCLEBIN\Adobe.rar
Found! G:\$RECYCLEBIN
Found! G:\Zain
Found! G:\winlogon.bat
Found! H:\Zain
Found! C:\Users\Abdussalam\AppData\Local\Temp\jlaw.exe
Found! C:\Users\Abdussalam\AppData\Local\Temp\winlogon.vbs
Found! [x64] HKLM\Software\winlogon
Found! HKLM\Software\Microsoft\Windows\CurrentVersion\Run|4c9b62d819bccb0b01cc8c566c166126
Found! HKCU\Software\Microsoft\Windows\CurrentVersion\Run|4c9b62d819bccb0b01cc8c566c166126
Found! HKU\S-1-5-21-1841702979-3207138838-463625945-1000\Software\Microsoft\Windows\CurrentVersion\Run|4c9b62d819bccb0b01cc8c566c166126
Found! [x64] HKLM\Software\Microsoft\Windows\CurrentVersion\Run|winlogon
Found! HKCU\Software\Microsoft\Windows\CurrentVersion\Run|winlogon
Found! HKU\S-1-5-21-1841702979-3207138838-463625945-1000\Software\Microsoft\Windows\CurrentVersion\Run|winlogon
Found! [x64] HKLM\Software\Microsoft\Windows\CurrentVersion\Run|bintin
Found! HKLM\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules|{876D6869-333D-4FFB-8FB0-DC7CBDBC8913}
Found! HKLM\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules|{4F0B187A-47BD-49F7-88A9-AD99501ABB99}
Found! HKLM\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules|{70505450-28BC-4683-9D32-BAA8811E6ED4}
Found! HKLM\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules|{0A35B8FC-EFD8-42E1-849B-838A8CECC817}
Found! HKLM\SYSTEM\ControlSet002\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules|{876D6869-333D-4FFB-8FB0-DC7CBDBC8913}
Found! HKLM\SYSTEM\ControlSet002\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules|{4F0B187A-47BD-49F7-88A9-AD99501ABB99}
Found! HKLM\SYSTEM\ControlSet002\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules|{70505450-28BC-4683-9D32-BAA8811E6ED4}
Found! HKLM\SYSTEM\ControlSet002\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules|{0A35B8FC-EFD8-42E1-849B-838A8CECC817}

[b]################## | UsbFix - Information |[/b]

UsbFix has detected on your computer, an infection which a Keylogger function.
After cleaning with UsbFix, please modify all your passwords.
If you made purchases on Internet,
please contact your bank to enviseager an opposition on your bank card.

Info : [url=https://www.youtube.com/watch?v=vUZYYASd7FE]How to remove shortcut virus on flash disk (Video)[/url]
Info : [url=http://www.en.usbfix.net/2014/03/remove-shortcut-virus-usb/]Shortcut virus on flash disk, What is it ?[/url]

[b]Analysed in 200.1 seconds[/b]

[b]################## | E.O.F | [url=http://www.sosvirus.net/]http://www.sosvirus.net/[/url] | [url=http://www.en.usbfix.net/]http://www.en.usbfix.net/[/url] |[/b]

Publicité


Signaler le contenu de ce document

Publicité