cjoint

Publicité


Publicité

Format du document : text/plain

Prévisualisation

[b]############################## | UsbFix V 7.177 | [Nettoyage][/b]

Utilisateur: Momo (Administrateur) # MOMO
Mis � jour le 29/07/2014 par El Desaparecido - SosVirus
Lanc� � 15:15:59 | 02/08/2014

Site Web : [url=http://www.usbfix.net/]http://www.usbfix.net/[/url]
Changelog : [url=http://www.usbfix.net/maj/]http://www.usbfix.net/maj/[/url]
Assistance : [url=http://www.sosvirus.net/forum-virus-securite.html]http://www.sosvirus.net/forum-virus-securite.html[/url]
Upload Malware : [url=http://www.sosvirus.net/upload_malware.php]http://www.sosvirus.net/upload_malware.php[/url]
Contact : [url=http://www.usbfix.net/contact/]http://www.usbfix.net/contact/[/url]

[b]################## | System information |[/b]

MB: Acer (EA50_CX)
CPU: Intel(R) Pentium(R) CPU 2117U @ 1.80GHz
RAM -> [Total : 8007 Mo | Free : 6646 Mo]
Bios: Insyde Corp.
Boot: Normal boot

OS: Microsoft� Windows 8.1 (6.3.9600 64-Bit)
WB: Internet Explorer : 11.00.9600.16384
WB: Google Chrome : 36.0.1985.125

[b]################## | Security Information |[/b]

AV: Windows Defender [[b](!) D�sactiv�[/b] |A jour]
AV: avast! Antivirus [Actif |A jour]
AS: Windows Defender [[b](!) D�sactiv�[/b] |A jour]
AS: avast! Antivirus [Actif |A jour]
AS: Malwarebytes Anti-Malware : 2.0.2.1012
FW: Windows Firewall [Actif]
SC: Security Center [Actif]
WU: Windows Update [Actif]

[b]################## | Disk Information |[/b]

C:\ (%SystemDrive%) -> Disque fixe # 913 Go (663 Go libre(s) - 73%) [Acer] # NTFS
E:\ -> Disque amovible # 4 Go (46 Mo libre(s) - 1%) [] # FAT32
F:\ -> Disque amovible # 4 Go (1 Go libre(s) - 31%) [MOMO USB] # FAT32
G:\ -> Disque amovible # 4 Go (708 Mo libre(s) - 19%) [ANGRY BIRD] # FAT32

[b]################## | Autorun |[/b]

F:\TPE.lnk -> F:\flashmemory.vbe - (SHA1: 0C9432A8F23136E7E4291CA3E987FB80CBDD72EA)
F:\ANGRY BIRD.lnk -> F:\flashmemory.vbe - (SHA1: 0C9432A8F23136E7E4291CA3E987FB80CBDD72EA)
G:\TPE.lnk -> G:\flashmemory.vbe - (SHA1: 0C9432A8F23136E7E4291CA3E987FB80CBDD72EA)
G:\synth�se MOMO.lnk -> G:\flashmemory.vbe - (SHA1: 0C9432A8F23136E7E4291CA3E987FB80CBDD72EA)
G:\SYNTHESE DAOUDA.lnk -> G:\flashmemory.vbe - (SHA1: 0C9432A8F23136E7E4291CA3E987FB80CBDD72EA)
G:\synthese erwan.lnk -> G:\flashmemory.vbe - (SHA1: 0C9432A8F23136E7E4291CA3E987FB80CBDD72EA)
G:\SECURITY.lnk -> G:\flashmemory.vbe - (SHA1: 0C9432A8F23136E7E4291CA3E987FB80CBDD72EA)
G:\.lnk -> G:\flashmemory.vbe - (SHA1: 0C9432A8F23136E7E4291CA3E987FB80CBDD72EA)

[b]################## | Recherche g�n�rique |[/b]

Supprim�! E:\DCIM.exe
Supprim�! E:\explorer.exe
Supprim�! E:\SysAnti.exe
Supprim�! F:\flashmemory.vbe
Supprim�! G:\flashmemory.vbe
Supprim�! F:\TPE.lnk
Supprim�! F:\ANGRY BIRD.lnk
Supprim�! G:\TPE.lnk
Supprim�! G:\synth�se MOMO.lnk
Supprim�! G:\SYNTHESE DAOUDA.lnk
Supprim�! G:\synthese erwan.lnk
Supprim�! G:\SECURITY.lnk
Supprim�! G:\.lnk
Supprim�! E:\Autorun.inf
Supprim�! F:\ANGRY BIRD\flashmemory.vbe

(!) Fichiers temporaires supprim�s. (22.5803823471069 MB)

[b]################## | Registre |[/b]


[b]################## | Regedit Run |[/b]

F2 - HKLM\..\Winlogon : [Shell] explorer.exe
F2 - [x64] HKLM\..\Winlogon : [Shell] explorer.exe
F2 - HKLM\..\Winlogon : [Userinit] userinit.exe,
F2 - [x64] HKLM\..\Winlogon : [Userinit] C:\Windows\system32\userinit.exe,
04 - HKCU\..\Run : [EPSON Stylus SX400] C:\Windows\system32\spool\DRIVERS\x64\3\E_IATIEGE.EXE /FU "C:\Windows\TEMP\E_S63CD.tmp" /EF "HKCU"
04 - HKCU\..\Run : [Spotify Web Helper] "C:\Users\Mohamed\AppData\Roaming\Spotify\Data\SpotifyWebHelper.exe"
04 - HKCU\..\Run : [Skype] "C:\Program Files (x86)\Skype\Phone\Skype.exe" /minimized /regrun
04 - HKLM\..\Run : [AvastUI.exe] "C:\Program Files\AVAST Software\Avast\AvastUI.exe" /nogui
04 - HKLM\..\Run : [SunJavaUpdateSched] "C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe"
04 - HKLM\..\Run : [Adobe ARM] "C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
04 - HKLM\..\Run : [LogMeIn Hamachi Ui] "C:\Program Files (x86)\LogMeIn Hamachi\hamachi-2-ui.exe" --auto-start
04 - HKLM\..\Policies\Explorer\run : [BtvStack] "C:\Program Files (x86)\Qualcomm Atheros\Bluetooth Suite\BtvStack.exe"
04 - [x64] HKLM\..\Run : [IgfxTray] "C:\WINDOWS\system32\igfxtray.exe"
04 - [x64] HKLM\..\Run : [HotKeysCmds] "C:\WINDOWS\system32\hkcmd.exe"
04 - [x64] HKLM\..\Run : [Persistence] "C:\WINDOWS\system32\igfxpers.exe"
04 - [x64] HKLM\..\Run : [ETDCtrl] %ProgramFiles%\Elantech\ETDCtrl.exe
04 - [x64] HKLM\..\Run : [RTHDVCPL] "C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe" -s
04 - [x64] HKLM\..\Policies\Explorer\run : [BtvStack] "C:\Program Files (x86)\Qualcomm Atheros\Bluetooth Suite\BtvStack.exe"
04 - HKU\S-1-5-21-1555415473-1022194430-1092887353-1001\..\Run : [EPSON Stylus SX400] C:\Windows\system32\spool\DRIVERS\x64\3\E_IATIEGE.EXE /FU "C:\Windows\TEMP\E_S63CD.tmp" /EF "HKCU"
04 - HKU\S-1-5-21-1555415473-1022194430-1092887353-1001\..\Run : [Spotify Web Helper] "C:\Users\Mohamed\AppData\Roaming\Spotify\Data\SpotifyWebHelper.exe"
04 - HKU\S-1-5-21-1555415473-1022194430-1092887353-1001\..\Run : [Skype] "C:\Program Files (x86)\Skype\Phone\Skype.exe" /minimized /regrun

[b]################## | UsbFix - Information |[/b]

Info : [url=https://www.youtube.com/watch?v=vUZYYASd7FE]Comment supprimer l'infection des raccourcis sur USB ? (Video)[/url]
Info : [url=http://www.en.usbfix.net/2014/03/remove-shortcut-virus-usb/]L'infection des raccourcis USB, c'est quoi ?[/url]

[b]################## | Hijack |[/b]

Restaur�! [D] E:\DCIM
Restaur�! [D] F:\ANGRY BIRD
Restaur�! [N] F:\TPE.odt
Restaur�! [N] G:\synth�se MOMO.odt
Restaur�! [D] G:\SECURITY
Restaur�! [N] G:\synthese erwan.doc
Restaur�! [N] G:\.~lock.dissert.odt#

[b]################## | C:\ %SystemDrive% - Disque Fixe (NTFS) |[/b]

[02/08/2014 - 14:19:40 | ASH | 6559556 Ko] - C:\hiberfil.sys
[02/08/2014 - 14:19:43 | ASH | 8388608 Ko] - C:\pagefile.sys
[02/08/2014 - 14:19:45 | ASH | 262144 Ko] - C:\swapfile.sys
[07/07/2014 - 02:22:13 | SHD] - C:\$Recycle.Bin
[04/06/2013 - 06:23:11 | D] - C:\Intel
[18/06/2013 - 14:18:29 | N | 0 Ko] - C:\BOOTNXT
[22/08/2013 - 16:45:52 | SHD] - C:\Documents and Settings
[22/08/2013 - 17:22:35 | D] - C:\PerfLogs
[13/09/2013 - 07:51:04 | HD] - C:\sources
[16/01/2014 - 20:56:09 | D] - C:\OEM
[17/01/2014 - 00:53:11 | D] - C:\downloads
[21/04/2014 - 02:20:45 | SHD] - C:\Recovery
[24/04/2014 - 13:16:37 | RD] - C:\Program Files
[27/04/2014 - 00:25:43 | D] - C:\OverViewer
[27/04/2014 - 00:35:50 | D] - C:\World
[07/07/2014 - 02:21:03 | RD] - C:\Users
[01/08/2014 - 22:57:48 | SHD] - C:\System Volume Information
[02/08/2014 - 00:38:09 | D] - C:\_OTL
[02/08/2014 - 01:09:42 | D] - C:\AdwCleaner
[02/08/2014 - 01:25:53 | D] - C:\Windows
[02/08/2014 - 13:53:47 | RD] - C:\Program Files (x86)
[02/08/2014 - 13:53:47 | HD] - C:\ProgramData
[02/08/2014 - 13:56:57 | D] - C:\UsbFix

[b]################## | E:\ - Disque USB (FAT32) |[/b]

[01/01/2010 - 12:03:32 | D] - E:\DCIM
[12/02/2010 - 12:53:10 | D] - E:\DATABASE
[01/08/2014 - 22:13:20 | SHD] - E:\System Volume Information

[b]################## | F:\ - Disque USB (FAT32) |[/b]

[22/09/2013 - 00:47:56 | A | 166 Ko] - F:\2.skp
[22/09/2013 - 01:19:36 | A | 325 Ko] - F:\teste.skp
[28/01/2014 - 19:16:34 | N | 883 Ko] - F:\TPE.odt
[17/03/2014 - 22:23:38 | A | 398684 Ko] - F:\Harry_Potter_et_les_reliques_de_la_mort_2.mp4
[26/04/2014 - 23:22:20 | A | 330444 Ko] - F:\My_Super_Ex-Girlfriend_TRUEFRENCH_DVDrip_xvid-REDBULL.mp4
[30/04/2014 - 22:53:18 | A | 333245 Ko] - F:\Endiable.mp4
[04/05/2014 - 21:29:30 | A | 388108 Ko] - F:\Dumb___Dumber_Fr__Dvdrip.mp4
[09/05/2014 - 21:27:44 | A | 586849 Ko] - F:\Perp�te.mp4
[13/05/2014 - 23:53:26 | A | 468111 Ko] - F:\Welcome.Home.Roscoe.Jenkins.FRENCH.DVDRiP.XviD-MONK-318www..filmdoz.com.mp4
[28/01/2014 - 17:52:46 | D] - F:\ANGRY BIRD
[06/03/2014 - 21:28:10 | D] - F:\f
[02/04/2014 - 14:42:50 | D] - F:\PureCity SAVE 2 AVRIL
[24/04/2014 - 13:16:06 | SHD] - F:\System Volume Information

[b]################## | G:\ - Disque USB (FAT32) |[/b]

[10/03/2014 - 15:34:10 | N | 0 Ko] - G:\.~lock.dissert.odt#
[27/01/2014 - 01:00:00 | N | 24 Ko] - G:\synth�se MOMO.odt
[28/01/2014 - 19:16:34 | A | 883 Ko] - G:\TPE.odt
[10/03/2014 - 00:34:50 | A | 24 Ko] - G:\dissert.odt
[23/02/2014 - 13:39:20 | A | 2953737 Ko] - G:\Quantum Of Solace.flv
[28/01/2014 - 17:15:56 | N | 24 Ko] - G:\synthese erwan.doc
[28/01/2014 - 17:21:44 | D] - G:\SECURITY
[24/03/2014 - 21:47:12 | D] - G:\TPE
[07/04/2014 - 18:00:24 | D] - G:\bac francais
[02/08/2014 - 14:00:24 | SHD] - G:\System Volume Information

[b]################## | Vaccin |[/b]

C:\Autorun.inf -> Vaccin cr�� par UsbFix (El Desaparecido)
E:\Autorun.inf -> Vaccin cr�� par UsbFix (El Desaparecido)
F:\Autorun.inf -> Vaccin cr�� par UsbFix (El Desaparecido)
G:\Autorun.inf -> Vaccin cr�� par UsbFix (El Desaparecido)

[b]################## | E.O.F | [url=http://www.sosvirus.net/]http://www.sosvirus.net/[/url] | [url=http://www.usbfix.net/]http://www.usbfix.net/[/url] |[/b]

Publicité


Signaler le contenu de ce document

Publicité