[b]############################## | UsbFix V 7.184 | [Recherche][/b] Utilisateur: Angele OUIYA (Administrateur) # ANGELEOUIYA-PC Mis à jour le 20/10/2014 par El Desaparecido - SosVirus Lancé à 18:07:02 | 18/04/2017 Site Web : [url=http://www.usbfix.net/]http://www.usbfix.net/[/url] Changelog : [url=http://www.usbfix.net/maj/]http://www.usbfix.net/maj/[/url] Assistance : [url=http://www.sosvirus.net/forum-virus-securite.html]http://www.sosvirus.net/forum-virus-securite.html[/url] Upload Malware : [url=http://www.sosvirus.net/upload_malware.php]http://www.sosvirus.net/upload_malware.php[/url] Détection en Live : [url=http://comment-supprimer.fr/]http://comment-supprimer.fr/[/url] Contact : [url=http://www.usbfix.net/contact/]http://www.usbfix.net/contact/[/url] [b]################## | System information |[/b] MB: Quanta (3627) CPU: Intel(R) Core(TM)2 Duo CPU T6600 @ 2.20GHz GC: Mobile Intel(R) 4 Series Express Chipset Family RAM -> [Total : 3999 Mo | Free : 1360 Mo] Bios: Hewlett-Packard Boot: Normal boot OS: Microsoft™ Windows 7 Home Premium (6.1.7601 64-Bit) Service Pack 1 WB: Internet Explorer : 11.00.9600.16428 WB: Google Chrome : 57.0.2987.133 [b]################## | Security Information |[/b] AV: avast! Antivirus [[b](!) Désactivé[/b] |[b](!) Non à jour[/b]] AS: Windows Defender [Actif |[b](!) Non à jour[/b]] AS: avast! Antivirus [[b](!) Désactivé[/b] |[b](!) Non à jour[/b]] FW: avast! Antivirus [[b](!) Désactivé[/b]] FW: Windows Firewall [Actif] SC: Security Center [Actif] WU: Windows Update [Actif] [b]################## | Disk Information |[/b] C:\ (%SystemDrive%) -> Disque fixe # 243 Go (147 Go libre(s) - 61%) [OS7] # NTFS D:\ -> Disque fixe # 13 Go (2 Go libre(s) - 17%) [RECOVERY] # NTFS F:\ -> Disque fixe # 10 Go (6 Go libre(s) - 60%) [Pas Toucher] # NTFS G:\ -> Disque fixe # 199 Go (33 Go libre(s) - 16%) [Données 1] # NTFS H:\ -> Disque amovible # 7 Go (7 Go libre(s) - 100%) [] # FAT32 I:\ -> Disque amovible # 121 Mo (7 Mo libre(s) - 6%) [ANGÈLE] # FAT32 [b]################## | Regedit Run |[/b] F2 - HKLM\..\Winlogon : [Shell] explorer.exe F2 - [x64] HKLM\..\Winlogon : [Shell] explorer.exe F2 - HKLM\..\Winlogon : [Userinit] userinit.exe F2 - [x64] HKLM\..\Winlogon : [Userinit] C:\Windows\system32\userinit.exe, 04 - HKCU\..\Run : [LightScribe Control Panel] C:\Program Files (x86)\Common Files\LightScribe\LightScribeControlPanel.exe -hidden 04 - HKCU\..\Run : [Messenger (Yahoo!)] "C:\PROGRA~2\Yahoo!\MESSEN~1\YahooMessenger.exe" -quiet 04 - HKCU\..\Run : [Gestionnaire Antidote.exe] C:\Program Files (x86)\Druide\Antidote\Gestionnaire Antidote.exe 04 - HKCU\..\Run : [swg] "C:\Program Files (x86)\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" 04 - HKCU\..\Run : [EPSON Stylus CX4400 Series] C:\Windows\system32\spool\DRIVERS\x64\3\E_IATICAA.EXE /FU "C:\Users\ANGELE~1\AppData\Local\Temp\E_SED0C.tmp" /EF "HKCU" 04 - HKCU\..\Run : [SuperCopier2.exe] C:\Program Files (x86)\SuperCopier2\SuperCopier2.exe 04 - HKCU\..\Run : [Search Protection] C:\Program Files (x86)\Yahoo!\Search Protection\SearchProtection.exe 04 - HKCU\..\Run : [PhotoJoy] C:\Program Files (x86)\PhotoJoy\bin\PhotoJoy.exe /c 04 - HKCU\..\Run : [msnmsgr] "C:\Program Files (x86)\Windows Live\Messenger\msnmsgr.exe" /background 04 - HKCU\..\Run : [KiesHelper] C:\Program Files (x86)\Samsung\Kies\KiesHelper.exe /s 04 - HKCU\..\Run : [KiesTrayAgent] C:\Program Files (x86)\Samsung\Kies\KiesTrayAgent.exe 04 - HKCU\..\Run : [KiesPDLR] C:\Program Files (x86)\Samsung\Kies\External\FirmwareUpdate\KiesPDLR.exe 04 - HKCU\..\Run : [SDP] C:\Program Files (x86)\FilesFrog Update Checker\update_checker.exe /auto 04 - HKCU\..\Run : [feielo] C:\Users\Angele OUIYA\feielo.exe /H 04 - HKCU\..\Run : [Advanced Woman Calendar] "C:\Program Files (x86)\Advanced Woman Calendar\WomanCalendar.exe" -m 04 - HKCU\..\Run : [IDMan] C:\Program Files (x86)\Internet Download Manager\IDMan.exe /onboot 04 - HKCU\..\Run : [Skype] "C:\Program Files (x86)\Skype\Phone\Skype.exe" /minimized /regrun 04 - HKCU\..\Run : [updat] wscript.exe //B "C:\Users\ANGELE~1\AppData\Local\Temp\updat.vbs" 04 - HKCU\..\Run : [{E4F9986F-B279-4A88-8BA9-18D76F2CF6B9}] C:\Windows\system32\WindowsPowerShell\v1.0\powershell.exe -noprofile -windowstyle hidden -executionpolicy bypass iex ([Text.Encoding]::ASCII.GetString([Convert]::FromBase64String((gp 'HKCU:\Software\Classes\eRclLYcr').UDKIAXPSU))); 04 - HKLM\..\Run : [HPCam_Menu] "c:\Program Files (x86)\Hewlett-Packard\Media\Webcam\MUITransfer\MUIStartMenu.exe" "c:\Program Files (x86)\Hewlett-Packard\Media\Webcam" UpdateWithCreateOnce "Software\Hewlett-Packard\Media\Webcam" 04 - HKLM\..\Run : [QlbCtrl.exe] C:\Program Files (x86)\Hewlett-Packard\HP Quick Launch Buttons\QlbCtrl.exe /Start 04 - HKLM\..\Run : [UpdatePRCShortCut] "C:\Program Files (x86)\Hewlett-Packard\Recovery\MUITransfer\MUIStartMenu.exe" "C:\Program Files (x86)\Hewlett-Packard\Recovery" UpdateWithCreateOnce "Software\CyberLink\PowerRecover" 04 - HKLM\..\Run : [WirelessAssistant] C:\Program Files (x86)\Hewlett-Packard\HP Wireless Assistant\HPWAMain.exe 04 - HKLM\..\Run : [QuickTime Task] "C:\Program Files (x86)\QuickTime\qttask.exe" -atboottime 04 - HKLM\..\Run : [GrooveMonitor] "C:\Program Files (x86)\Microsoft Office\Office12\GrooveMonitor.exe" 04 - HKLM\..\Run : [NBKeyScan] "C:\Program Files (x86)\Nero\Nero BackItUp 4\NBKeyScan.exe" 04 - HKLM\..\Run : [YSearchProtection] "C:\Program Files (x86)\Yahoo!\Search Protection\SearchProtection.exe" 04 - HKLM\..\Run : [ApnUpdater] "C:\Program Files (x86)\Ask.com\Updater\Updater.exe" 04 - HKLM\..\Run : [facemoods] "C:\Program Files (x86)\facemoods.com\facemoods\1.4.17.11\facemoodssrv.exe" /md I 04 - HKLM\..\Run : [DATAMNGR] C:\PROGRA~2\SEARCH~1\Datamngr\DATAMN~1.EXE 04 - HKLM\..\Run : [VDownloader] C:\Program Files (x86)\VDownloader\VDownloader.exe /silent 04 - HKLM\..\Run : [Sweetpacks Communicator] C:\Program Files (x86)\SweetIM\Communicator\SweetPacksUpdateManager.exe 04 - HKLM\..\Run : [Adobe ARM] "C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe" 04 - HKLM\..\Run : [AvastUI.exe] "C:\Program Files\AVAST Software\Avast\AvastUI.exe" /nogui 04 - HKLM\..\Run : [SunJavaUpdateSched] "C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe" 04 - HKLM\..\Run : [HPUsageTrackingLEDM] "C:\Program Files (x86)\HP\HP UT LEDM\bin\hppusg.exe" "C:\Program Files (x86)\HP\HP UT LEDM\" 04 - HKLM\..\Run : [{2EB25CE5-0F84-4B65-AFB4-4360BECDEDC1}] "C:\Program Files (x86)\Airtel Internet\UUShell.exe" /CallBySystem 04 - HKLM\..\Run : [CancelAutoPlay] "C:\Program Files (x86)\Airtel Internet\CancelAutoPlay.exe" run 04 - HKLM\..\Run : [HP Software Update] C:\Program Files (x86)\Hp\HP Software Update\HPWuSchd2.exe 04 - HKLM\..\Policies\Explorer\run : [1811855875] C:\ProgramData\mscne.exe 04 - [x64] HKLM\..\Run : [SynTPEnh] %ProgramFiles%\Synaptics\SynTP\SynTPEnh.exe 04 - [x64] HKLM\..\Run : [SmartMenu] C:\Program Files\Hewlett-Packard\HP MediaSmart\SmartMenu.exe /background 04 - [x64] HKLM\..\Run : [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe" 04 - [x64] HKLM\..\Run : [IgfxTray] C:\Windows\system32\igfxtray.exe 04 - [x64] HKLM\..\Run : [HotKeysCmds] C:\Windows\system32\hkcmd.exe 04 - [x64] HKLM\..\Run : [Persistence] C:\Windows\system32\igfxpers.exe 04 - [x64] HKLM\..\Run : [SysTrayApp] C:\Program Files\IDT\WDM\sttray64.exe 04 - [x64] HKLM\..\Run : [VDownloader] C:\Program Files\VDownloader\VDownloader.exe /silent 04 - [x64] HKLM\..\Policies\Explorer\run : [1811855875] C:\ProgramData\mscne.exe 04 - HKU\S-1-5-19\..\Run : [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun 04 - HKU\S-1-5-20\..\Run : [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun 04 - HKU\S-1-5-21-2110722252-3502127745-55028577-1001\..\Run : [LightScribe Control Panel] C:\Program Files (x86)\Common Files\LightScribe\LightScribeControlPanel.exe -hidden 04 - HKU\S-1-5-21-2110722252-3502127745-55028577-1001\..\Run : [Messenger (Yahoo!)] "C:\PROGRA~2\Yahoo!\MESSEN~1\YahooMessenger.exe" -quiet 04 - HKU\S-1-5-21-2110722252-3502127745-55028577-1001\..\Run : [Gestionnaire Antidote.exe] C:\Program Files (x86)\Druide\Antidote\Gestionnaire Antidote.exe 04 - HKU\S-1-5-21-2110722252-3502127745-55028577-1001\..\Run : [swg] "C:\Program Files (x86)\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" 04 - HKU\S-1-5-21-2110722252-3502127745-55028577-1001\..\Run : [EPSON Stylus CX4400 Series] C:\Windows\system32\spool\DRIVERS\x64\3\E_IATICAA.EXE /FU "C:\Users\ANGELE~1\AppData\Local\Temp\E_SED0C.tmp" /EF "HKCU" 04 - HKU\S-1-5-21-2110722252-3502127745-55028577-1001\..\Run : [SuperCopier2.exe] C:\Program Files (x86)\SuperCopier2\SuperCopier2.exe 04 - HKU\S-1-5-21-2110722252-3502127745-55028577-1001\..\Run : [Search Protection] C:\Program Files (x86)\Yahoo!\Search Protection\SearchProtection.exe 04 - HKU\S-1-5-21-2110722252-3502127745-55028577-1001\..\Run : [PhotoJoy] C:\Program Files (x86)\PhotoJoy\bin\PhotoJoy.exe /c 04 - HKU\S-1-5-21-2110722252-3502127745-55028577-1001\..\Run : [msnmsgr] "C:\Program Files (x86)\Windows Live\Messenger\msnmsgr.exe" /background 04 - HKU\S-1-5-21-2110722252-3502127745-55028577-1001\..\Run : [KiesHelper] C:\Program Files (x86)\Samsung\Kies\KiesHelper.exe /s 04 - HKU\S-1-5-21-2110722252-3502127745-55028577-1001\..\Run : [KiesTrayAgent] C:\Program Files (x86)\Samsung\Kies\KiesTrayAgent.exe 04 - HKU\S-1-5-21-2110722252-3502127745-55028577-1001\..\Run : [KiesPDLR] C:\Program Files (x86)\Samsung\Kies\External\FirmwareUpdate\KiesPDLR.exe 04 - HKU\S-1-5-21-2110722252-3502127745-55028577-1001\..\Run : [SDP] C:\Program Files (x86)\FilesFrog Update Checker\update_checker.exe /auto 04 - HKU\S-1-5-21-2110722252-3502127745-55028577-1001\..\Run : [feielo] C:\Users\Angele OUIYA\feielo.exe /H 04 - HKU\S-1-5-21-2110722252-3502127745-55028577-1001\..\Run : [Advanced Woman Calendar] "C:\Program Files (x86)\Advanced Woman Calendar\WomanCalendar.exe" -m 04 - HKU\S-1-5-21-2110722252-3502127745-55028577-1001\..\Run : [IDMan] C:\Program Files (x86)\Internet Download Manager\IDMan.exe /onboot 04 - HKU\S-1-5-21-2110722252-3502127745-55028577-1001\..\Run : [Skype] "C:\Program Files (x86)\Skype\Phone\Skype.exe" /minimized /regrun 04 - HKU\S-1-5-21-2110722252-3502127745-55028577-1001\..\Run : [updat] wscript.exe //B "C:\Users\ANGELE~1\AppData\Local\Temp\updat.vbs" 04 - HKU\S-1-5-21-2110722252-3502127745-55028577-1001\..\Run : [{E4F9986F-B279-4A88-8BA9-18D76F2CF6B9}] C:\Windows\system32\WindowsPowerShell\v1.0\powershell.exe -noprofile -windowstyle hidden -executionpolicy bypass iex ([Text.Encoding]::ASCII.GetString([Convert]::FromBase64String((gp 'HKCU:\Software\Classes\eRclLYcr').UDKIAXPSU))); 04 - HKU\S-1-5-18\..\Run : [Gestionnaire Antidote.exe] C:\Program Files (x86)\Druide\Antidote\Gestionnaire Antidote.exe 04 - HKU\S-1-5-19\..\RunOnce : [mctadmin] C:\Windows\System32\mctadmin.exe 04 - HKU\S-1-5-20\..\RunOnce : [mctadmin] C:\Windows\System32\mctadmin.exe [b]################## | Recherche générique |[/b] Présent! H:\Removable Drive (8GB).lnk Présent! I:\Skypee\AutoIt3.exe Présent! I:\Skypee [b]################## | Registre |[/b] [b]################## | UsbFix - Information |[/b] Info : [url=https://www.youtube.com/watch?v=vUZYYASd7FE]Comment supprimer l'infection des raccourcis sur USB ? (Video)[/url] Info : [url=http://www.en.usbfix.net/2014/03/remove-shortcut-virus-usb/]L'infection des raccourcis USB, c'est quoi ?[/url] [b]################## | Hijack |[/b] Hijacked! [SHD] H:\  [b]################## | E.O.F | [url=http://www.sosvirus.net/]http://www.sosvirus.net/[/url] | [url=http://www.usbfix.net/]http://www.usbfix.net/[/url] |[/b]