############################## | UsbFix V 7.163 | [Suppression] Utilisateur: YASSEM (Administrateur) # SHIELD Mis à jour le 02/02/2014 par El Desaparecido - Team SosVirus Lancé à 11:44:21 | 07/02/2014 Site Web : http://www.usbfix.net Changelog : http://www.usbfix.net/maj/ Support : http://www.sosvirus.net/ Upload Malware : http://www.sosvirus.net/upload_malware.php Contact : http://www.usbfix.net/contact/ PC: Sony Corporation (VAIO) CPU: Intel(R) Core(TM)2 CPU T5300 @ 1.73GHz RAM -> [Total : 2038 Mo| Free : 1498 Mo] Bios: Phoenix Technologies LTD Boot: Normal boot OS: Microsoft Windows XP Professionnel (5.1.2600 32-Bit) Service Pack 3 WB: Windows Internet Explorer : 6.0.2900.5512 WB: Google Chrome : 32.0.1700.102 WB: Mozilla Firefox : 1.8.1: 2006101023 SC: Security Center [Enabled] WU: Windows Update [Enabled] FW: Windows FireWall [Enabled] C:\ (%systemdrive%) -> Disque fixe # 39 Go (14 Go libre(s) - 37%) [] # NTFS D:\ -> Disque fixe # 73 Go (19 Go libre(s) - 26%) [] # NTFS E:\ -> CD-ROM G:\ -> Disque amovible # 7 Go (7 Go libre(s) - 100%) [TOSHIBA] # FAT32 H:\ -> Disque amovible # 960 Mo (208 Mo libre(s) - 22%) [YVES] # FAT ################## | Processus Actif | C:\WINDOWS\System32\smss.exe (ID: 740 |ParentID: 4) C:\PROGRA~1\AVG\AVG2014\avgrsx.exe (ID: 776 |ParentID: 764) C:\Program Files\AVG\AVG2014\avgcsrvx.exe (ID: 812 |ParentID: 776) C:\WINDOWS\system32\winlogon.exe (ID: 1028 |ParentID: 740) C:\WINDOWS\system32\services.exe (ID: 1072 |ParentID: 1028) C:\WINDOWS\system32\lsass.exe (ID: 1084 |ParentID: 1028) C:\WINDOWS\system32\svchost.exe (ID: 1244 |ParentID: 1072) C:\WINDOWS\System32\svchost.exe (ID: 1344 |ParentID: 1072) C:\WINDOWS\system32\svchost.exe (ID: 1396 |ParentID: 1072) C:\WINDOWS\system32\spoolsv.exe (ID: 1776 |ParentID: 1072) C:\WINDOWS\Explorer.EXE (ID: 176 |ParentID: 2008) C:\Program Files\AVG\AVG2014\avgidsagent.exe (ID: 440 |ParentID: 1072) C:\Program Files\AVG\AVG2014\avgwdsvc.exe (ID: 456 |ParentID: 1072) C:\WINDOWS\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe (ID: 480 |ParentID: 1072) C:\Program Files\NCH Software\Fling\fling.exe (ID: 828 |ParentID: 1072) C:\Program Files\Freemake\CaptureLib\CaptureLibService.exe (ID: 1000 |ParentID: 1072) C:\Program Files\Google\Update\GoogleUpdate.exe (ID: 1568 |ParentID: 1072) C:\WINDOWS\system32\wuauclt.exe (ID: 1652 |ParentID: 1344) C:\Program Files\AVG\AVG2014\avgnsx.exe (ID: 2152 |ParentID: 456) C:\Program Files\AVG\AVG2014\avgemcx.exe (ID: 2164 |ParentID: 456) ################## | Regedit Run | 04 - HKCU\..\Run : [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe 04 - HKCU\..\Run : [SuperCopier2.exe] C:\Program Files\SuperCopier2\SuperCopier2.exe 04 - HKCU\..\Run : [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background 04 - HKCU\..\Run : [TBHostSupport] "C:\WINDOWS\system32\Rundll32.exe" "C:\Documents and Settings\YASSEM\Local Settings\Application Data\TBHostSupport\TBHostSupport.dll",DLLRunTBHostSupportPlugin 04 - HKCU\..\Run : [LiveSupport] "C:\Program Files\LiveSupport\LiveSupport.exe" /noshow /log 04 - HKCU\..\Run : [iLivid] "C:\Documents and Settings\YASSEM\Local Settings\Application Data\iLivid\iLivid.exe" -autorun 04 - HKCU\..\Run : [AVG-Secure-Search-Update_0214c] C:\Documents and Settings\YASSEM\Application Data\AVG 0214c Campaign\AVG-Secure-Search-Update-0214c.exe /PROMPT /mid=83ef938c632647d3b6aed15038c84540-fe15dc9c2ecd4f8b8aedfc32e01bbd11e392d4ab /CMPID=0214c 04 - HKCU\..\Run : [APISupport] "C:\WINDOWS\system32\Rundll32.exe" "C:\Documents and Settings\YASSEM\Local Settings\Application Data\Conduit\APISupport\APISupport.dll",DLLRunAPISupport 04 - HKCU\..\Run : [hCbnTNLj] wscript.exe //B "C:\DOCUME~1\YASSEM\LOCALS~1\Temp\hCbnTNLj.vbs" 04 - HKLM\..\Run : [PWRISOVM.EXE] C:\Program Files\PowerISO\PWRISOVM.EXE 04 - HKLM\..\Run : [IgfxTray] C:\WINDOWS\system32\igfxtray.exe 04 - HKLM\..\Run : [HotKeysCmds] C:\WINDOWS\system32\hkcmd.exe 04 - HKLM\..\Run : [Persistence] C:\WINDOWS\system32\igfxpers.exe 04 - HKLM\..\Run : [MySight 2006 BS Check&Random] C:\Program Files\MySight 2006\quickbs.exe 04 - HKLM\..\Run : [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime 04 - HKLM\..\Run : [AVG_UI] "C:\Program Files\AVG\AVG2014\avgui.exe" /TRAYONLY 04 - HKLM\..\Run : [DrvIcon] C:\Program Files\Vista Drive Icon\DrvIcon.exe 04 - HKLM\..\Run : [Fling] "C:\Program Files\NCH Software\Fling\fling.exe" -logon 04 - HKLM\..\Run : [Adobe ARM] "C:\Program Files\Fichiers communs\Adobe\ARM\1.0\AdobeARM.exe" 04 - HKLM\..\Run : [hCbnTNLj] wscript.exe //B "C:\DOCUME~1\YASSEM\LOCALS~1\Temp\hCbnTNLj.vbs" 04 - HKLM\Software\Microsoft\Windows NT\CurrentVersion\Terminal Server\Install\..\Run : [] 04 - HKLM\Software\Microsoft\Windows NT\CurrentVersion\Terminal Server\Install\..\RunOnce : [] 04 - HKU\S-1-5-19\..\Run : [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE 04 - HKU\S-1-5-20\..\Run : [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE 04 - HKU\S-1-5-21-1060284298-776561741-1417001333-1003\..\Run : [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe 04 - HKU\S-1-5-21-1060284298-776561741-1417001333-1003\..\Run : [SuperCopier2.exe] C:\Program Files\SuperCopier2\SuperCopier2.exe 04 - HKU\S-1-5-21-1060284298-776561741-1417001333-1003\..\Run : [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background 04 - HKU\S-1-5-21-1060284298-776561741-1417001333-1003\..\Run : [TBHostSupport] "C:\WINDOWS\system32\Rundll32.exe" "C:\Documents and Settings\YASSEM\Local Settings\Application Data\TBHostSupport\TBHostSupport.dll",DLLRunTBHostSupportPlugin 04 - HKU\S-1-5-21-1060284298-776561741-1417001333-1003\..\Run : [LiveSupport] "C:\Program Files\LiveSupport\LiveSupport.exe" /noshow /log 04 - HKU\S-1-5-21-1060284298-776561741-1417001333-1003\..\Run : [iLivid] "C:\Documents and Settings\YASSEM\Local Settings\Application Data\iLivid\iLivid.exe" -autorun 04 - HKU\S-1-5-21-1060284298-776561741-1417001333-1003\..\Run : [AVG-Secure-Search-Update_0214c] C:\Documents and Settings\YASSEM\Application Data\AVG 0214c Campaign\AVG-Secure-Search-Update-0214c.exe /PROMPT /mid=83ef938c632647d3b6aed15038c84540-fe15dc9c2ecd4f8b8aedfc32e01bbd11e392d4ab /CMPID=0214c 04 - HKU\S-1-5-21-1060284298-776561741-1417001333-1003\..\Run : [APISupport] "C:\WINDOWS\system32\Rundll32.exe" "C:\Documents and Settings\YASSEM\Local Settings\Application Data\Conduit\APISupport\APISupport.dll",DLLRunAPISupport 04 - HKU\S-1-5-21-1060284298-776561741-1417001333-1003\..\Run : [hCbnTNLj] wscript.exe //B "C:\DOCUME~1\YASSEM\LOCALS~1\Temp\hCbnTNLj.vbs" 04 - HKU\S-1-5-18\..\Run : [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE ################## | Recherche générique | Supprimé! C:\Documents and Settings\YASSEM\Menu Démarrer\Programmes\Démarrage\hCbnTNLj.vbs Supprimé! G:\hCbnTNLj.vbs Supprimé! H:\hCbnTNLj.vbs Supprimé! C:\DOCUME~1\YASSEM\LOCALS~1\Temp\hCbnTNLj.vbs Supprimé! G:\59secretstemps.lnk Supprimé! G:\graphlog.lnk Supprimé! G:\DOCS.lnk Supprimé! G:\Autorun.inf.lnk Supprimé! H:\La.lnk Supprimé! H:\DOCS.lnk Supprimé! H:\CV.lnk Supprimé! H:\Autorun.inf.lnk (!) Fichiers temporaires supprimés. ################## | Registre | Supprimé! HKLM\SYSTEM\CurrentControlSet\Services\npf Réparé ! HKLM\Software\Microsoft\Windows\CurrentVersion\Policies\System|EnableLUA -> 1 Réparé ! HKLM\Software\Microsoft\Windows\CurrentVersion\Policies\System|ConsentPromptBehaviorAdmin -> 5 Supprimé! HKU\S-1-5-21-1060284298-776561741-1417001333-1003\Software\Microsoft\Windows\CurrentVersion\Run|hCbnTNLj Supprimé! HKLM\Software\Microsoft\Windows\CurrentVersion\Run|hCbnTNLj Supprimé! HKU\S-1-5-21-1060284298-776561741-1417001333-1003\Software\.\.\.\.\Mountpoints2\{4d3bf206-746b-11e3-9580-00197e2cacb3} Supprimé! HKU\S-1-5-21-1060284298-776561741-1417001333-1003\Software\.\.\.\.\Mountpoints2\{bc389a3d-4fc9-11e3-954b-00197e2cacb3} ################## | Listing | [04/10/2013 - 18:49:23 | D] - C:\$AVG [11/11/2013 - 23:15:44 | D] - C:\Anm [26/09/2013 - 15:54:12 | A | 0 Ko] - C:\AUTOEXEC.BAT [26/10/2013 - 02:15:55 | A | 0 Ko] - C:\boot.ini [26/09/2013 - 15:48:04 | N | 0 Ko] - C:\boot.ini.back [26/09/2013 - 15:48:04 | N | 0 Ko] - C:\boot.uni [28/08/2001 - 13:00:00 | N | 5 Ko] - C:\Bootfont.bin [26/09/2013 - 15:54:12 | N | 0 Ko] - C:\CONFIG.SYS [19/11/2013 - 16:31:05 | D] - C:\Documents and Settings [04/10/2013 - 18:36:05 | N | 0 Ko] - C:\END [25/10/2013 - 15:07:47 | D] - C:\GESTION_BOURSES2013 [26/09/2013 - 15:54:12 | RASH | 0 Ko] - C:\IO.SYS [26/09/2013 - 15:54:12 | RASH | 0 Ko] - C:\MSDOS.SYS [26/09/2013 - 16:12:51 | RHD] - C:\MSOCache [03/02/2014 - 00:00:02 | N | 0 Ko] - C:\Nouveau dossier.lnk [13/04/2008 - 08:43:04 | N | 46 Ko | B2DE3452DE03674C6CEC68B8C8CE7C78] - C:\NTDETECT.COM [13/04/2008 - 10:31:52 | RASH | 246 Ko] - C:\ntldr [04/01/2014 - 23:34:26 | N | 0 Ko] - C:\open.ini [07/02/2014 - 11:43:11 | ASH | 2095104 Ko] - C:\pagefile.sys [04/01/2014 - 21:27:56 | D] - C:\Program Files [26/09/2013 - 16:03:08 | SHD] - C:\RECYCLER [17/11/2013 - 23:19:07 | D] - C:\SmartSound Software [26/09/2013 - 15:57:52 | SHD] - C:\System Volume Information [27/09/2013 - 10:15:06 | D] - C:\transparency [07/02/2014 - 11:40:58 | D] - C:\UsbFix [06/02/2014 - 14:48:03 | N | 23 Ko | ED3EB724D9624BEFF7A9977C28FFE5CC] - C:\UsbFix [Clean 2] SHIELD.txt [07/02/2014 - 11:30:59 | N | 20 Ko | A634BCA3642F24ADB6BC2F041C195036] - C:\UsbFix [Clean 4] SHIELD.txt [07/02/2014 - 11:54:21 | A | 9 Ko | DC87D16571A4C0134FA8804AF638F6AA] - C:\UsbFix [Clean 6] SHIELD.txt [06/02/2014 - 11:11:59 | N | 13 Ko | 130EB5814E758A36B53E57D79BA90FD6] - C:\UsbFix [Scan 1] SHIELD.txt [07/02/2014 - 11:39:30 | N | 11 Ko | BA8B34F1AC824DEC23DF2F690FBA02C7] - C:\UsbFix [Scan 2] SHIELD.txt [07/02/2014 - 11:51:36 | D] - C:\WINDOWS [30/09/2013 - 09:56:49 | D] - C:\[Smad-Cage] [11/12/2013 - 18:32:30 | D] - D:\$AVG [27/11/2013 - 12:11:37 | D] - D:\affaire [27/11/2013 - 12:11:40 | D] - D:\appliquée [27/11/2013 - 13:31:02 | D] - D:\BIBLE-CORAN [25/10/2013 - 23:34:13 | N | 5263651 Ko] - D:\bilan vrai.avi [08/08/2010 - 10:44:58 | N | 711914 Ko] - D:\Blood.and.Chocolate.LiMiTED.FRENCH.DVDRiP.XviD-iD-AceBot-CasualFirm.[emule-island.com].avi [27/11/2013 - 12:11:44 | D] - D:\bluetooth [27/11/2013 - 12:11:46 | D] - D:\carte de mariage [17/01/2014 - 00:04:23 | D] - D:\CHRETIEN [02/09/2013 - 19:09:36 | D] - D:\cle [27/04/2013 - 16:33:03 | N | 39 Ko] - D:\CONCOURS LISTES COMPETITEURS.odt [27/04/2013 - 16:33:18 | N | 56 Ko] - D:\CONCOURS LISTES COMPETITEURS.pdf [27/04/2013 - 16:01:18 | N | 41 Ko] - D:\CONCOURS POEMES.odt [27/04/2013 - 16:27:01 | N | 59 Ko] - D:\CONCOURS POEMES.pdf [27/04/2013 - 14:39:32 | N | 17 Ko] - D:\CONCOURS PREDICATION .odt [27/04/2013 - 16:25:20 | N | 45 Ko] - D:\CONCOURS PREDICATION V.odt [27/04/2013 - 16:26:47 | N | 84 Ko] - D:\CONCOURS PREDICATION V.pdf [27/11/2013 - 12:11:50 | D] - D:\cours de droit [27/11/2013 - 12:11:50 | D] - D:\cours droit civil [27/11/2013 - 12:11:51 | D] - D:\cours droit entre [04/02/2014 - 23:34:24 | D] - D:\cours psycho [29/01/2014 - 01:57:52 | D] - D:\cours veritables d'anglais intensif [27/04/2013 - 16:33:59 | D] - D:\CPI [27/11/2013 - 12:11:52 | D] - D:\CV [21/11/2013 - 11:38:06 | N | 37 Ko] - D:\CV VALENTINE KONAN.docx [27/11/2013 - 12:11:53 | D] - D:\DEVOIRS FRANCAIS [09/09/2009 - 23:52:36 | D] - D:\diplomes [27/11/2013 - 12:11:53 | D] - D:\DOCS CREL [27/11/2013 - 12:11:54 | D] - D:\DOCS PERSO IMPORTANTS [28/04/2013 - 19:46:48 | D] - D:\DOCS SERGES DEF [27/11/2013 - 12:11:55 | D] - D:\DOCS YVES [27/11/2013 - 12:11:56 | D] - D:\download [11/12/2013 - 11:16:08 | D] - D:\ea624e915dc851cf3f4b76 [27/11/2013 - 12:11:56 | D] - D:\emploi [18/12/2013 - 08:39:16 | D] - D:\ENA [28/09/2013 - 20:04:53 | D] - D:\ENA2 [27/11/2013 - 13:25:33 | D] - D:\EVALUATION DROIT [27/11/2013 - 13:25:37 | D] - D:\EVALUATION PSYCHO [27/11/2013 - 13:25:38 | D] - D:\Extraits [29/01/2013 - 10:33:39 | N | 12 Ko] - D:\fiche de suivi cours a domicile.odt [29/01/2013 - 10:33:47 | N | 40 Ko] - D:\fiche de suivi cours a domicile.pdf [31/01/2014 - 11:35:07 | D] - D:\film [26/11/2013 - 00:04:15 | D] - D:\film jep [04/01/2014 - 23:34:13 | D] - D:\Formation.Excel.20071 [29/04/2013 - 12:48:50 | D] - D:\GESTBOURSE 2013 [04/01/2014 - 16:09:36 | D] - D:\GRANDS AUTEURS FRANCAIS [04/12/2013 - 17:52:39 | N | 1 Ko] - D:\gravure.ebp [08/04/2006 - 00:52:20 | N | 712274 Ko] - D:\Hitch, Expert En Séduction.avi [27/11/2013 - 13:25:32 | D] - D:\IGNAME [04/02/2014 - 19:07:00 | N | 40 Ko] - D:\image.jpeg [04/02/2014 - 19:07:00 | N | 103 Ko] - D:\image.png [27/11/2013 - 13:25:35 | D] - D:\impression [25/12/2013 - 20:10:19 | D] - D:\JAC [06/02/2014 - 00:34:03 | D] - D:\jeux [23/10/2013 - 22:43:53 | N | 43 Ko] - D:\KOUAKOU AYA HONORINE.docx [01/07/2013 - 11:25:16 | N | 764032 Ko] - D:\La.Chute.de.la Maison.Blanche.2013.FRENCH.DVDRip.MD.www.zone-telechargement.com.avi [27/11/2013 - 13:25:37 | D] - D:\langue grammaire transf [29/01/2014 - 02:01:13 | D] - D:\logicielll [30/01/2014 - 22:08:18 | D] - D:\mariage groupé [29/12/2013 - 23:59:03 | D] - D:\mariage pasteur [02/12/2013 - 10:08:16 | N | 62 Ko] - D:\mariage suzane.xphd [27/11/2013 - 13:25:38 | D] - D:\morenga [19/11/2013 - 18:53:19 | N | 7058209 Ko] - D:\movie 3.avi [08/07/2007 - 10:18:20 | N | 716422 Ko] - D:\Naked Weapon.avi [27/11/2013 - 13:25:38 | D] - D:\natacha [05/12/2013 - 14:06:54 | D] - D:\Need~ [05/02/2014 - 02:24:51 | D] - D:\NewDir [19/06/2013 - 15:00:06 | N | 9710 Ko] - D:\Office_2007_Reussir_Entreprise.pdf [07/07/2012 - 20:19:28 | D] - D:\offre emploi [27/11/2013 - 13:20:00 | D] - D:\OUVRAGES SPECIALISES [24/12/2008 - 15:54:04 | N | 717132 Ko] - D:\Papa J'ai Une Maman Pour Toi - comedie.avi [09/03/2013 - 00:04:55 | N | 192 Ko] - D:\PERCEPTION CARRE.png [27/11/2013 - 12:19:48 | D] - D:\photos claude [05/02/2014 - 20:45:53 | D] - D:\Pièces jointes_201425 [05/02/2014 - 18:10:56 | N | 1243 Ko] - D:\Pièces jointes_201425 (1).zip [05/02/2014 - 18:08:37 | N | 2170 Ko] - D:\Pièces jointes_201425.zip [27/11/2013 - 13:25:40 | D] - D:\PROJET SHIELD [19/06/2013 - 17:23:30 | D] - D:\PROPOSITION AFFAIRES [26/09/2013 - 16:03:08 | SHD] - D:\RECYCLER [27/11/2013 - 13:25:40 | D] - D:\RHCOM [25/02/2012 - 06:49:26 | N | 716244 Ko] - D:\Samurai.Ayothaya.2010.FRENCH.DVDRip.XviD-Watin.avi [08/01/2014 - 15:07:33 | D] - D:\SHIELD [27/11/2013 - 13:25:46 | D] - D:\socio [27/11/2013 - 13:25:46 | D] - D:\SUJETS DE PRIERE [26/09/2013 - 16:22:56 | SHD] - D:\System Volume Information [24/11/2012 - 10:13:37 | D] - D:\tantie louise [08/03/2013 - 14:40:50 | N | 84 Ko] - D:\test.odt [11/04/2004 - 04:14:58 | N | 612718 Ko] - D:\The confession.VOB [05/03/2012 - 08:48:08 | N | 717454 Ko] - D:\The.Adventures.Of.Tintin.2011.FRENCH.DVDRip.XviD-AYMO_ns.avi [11/11/2013 - 16:59:08 | N | 11 Ko] - D:\THEME DE MEMOIRE LES RELATIONS ENTRE LES ETATS AFRICAINS ET LA CPI.docx [22/03/2013 - 17:54:14 | N | 14 Ko] - D:\THEME DE MEMOIRE LES RELATIONS ENTRE LES ETATS AFRICAINS ET LA CPI.odt [15/04/2013 - 19:34:17 | N | 52 Ko] - D:\THEME%20DE%20MEMOIRE%20LES%20RELATIONS%20ENTRE%20LES%20ETATS%20AFRICAINS%20ET%20LA%20CPI.doc_1.odt [27/11/2013 - 13:25:56 | ASH | 51 Ko] - D:\Thumbs.db [11/06/2012 - 11:03:33 | N | 0 Ko | D2D78D993857028F80A115D8CBD02219] - D:\TileRacer_420-sfs4.sfs-md5.txt [11/12/2013 - 18:35:50 | D] - D:\UnderCoverXP [27/11/2013 - 13:25:47 | D] - D:\VIDEO MARIAGE [28/09/2013 - 13:39:56 | N | 25166 Ko | 69474BFF35EF9AEA2A567A930334F1B9] - D:\wmp11-windowsxp-x86-FR-FR.exe [28/09/2013 - 21:33:33 | D] - D:\Zuma's Revenge! [12/12/2009 - 15:49:26 | N | 192 Ko] - G:\59secretstemps.pdf [12/12/2009 - 15:49:44 | N | 493 Ko] - G:\graphlog.zip [05/02/2014 - 02:24:52 | D] - G:\DOCS [05/02/2014 - 02:24:52 | D] - H:\DOCS [27/11/2013 - 12:11:54 | D] - H:\CV [01/07/2013 - 11:25:16 | N | 764032 Ko] - H:\La.Chute.de.la Maison.Blanche.2013.FRENCH.DVDRip.MD.www.zone-telechargement.com.avi ################## | Vaccin | D:\Autorun.inf -> Vaccin créé par UsbFix (El Desaparecido) G:\Autorun.inf -> Vaccin créé par UsbFix (El Desaparecido) H:\Autorun.inf -> Vaccin créé par UsbFix (El Desaparecido) ################## | E.O.F | http://www.usbfix.net - http://www.sosvirus.net |