Rem-VBSworm v8.0 =========== - General info: Running under: Jean Marie CARRIBON on profile: C:\Users\Jean Marie CARRIBON Computer name: DESKTOP-NA2IIKJ Operating System: Microsoft Windows 10 Famille Boot Mode: Normal boot Antivirus software installed: Windows Defender COMODO Antivirus Executed on: 29/03/2022 @ 10:52:14,34 =========== - Drive info: Listing currently attached drives: Caption Description VolumeName C: Disque mont‚ local WINDOWS 10 FAMILLE 64 BITS D: Disque amovible E: Disque CD-ROM WebPlus X7 F: Disque amovible Physical drives information: C: \Device\HarddiskVolume4 NTFS E: \Device\CdRom0 CDFS F: \Device\HarddiskVolume38 FAT =========== - Disinfection info: Op‚ration r‚ussieÿ: le processus avec PID 11048 a ‚t‚ termin‚. Op‚ration r‚ussieÿ: le processus avec PID 2136 a ‚t‚ termin‚. Op‚ration r‚ussieÿ: le processus avec PID 7208 a ‚t‚ termin‚. Op‚ration r‚ussieÿ: le processus avec PID 5796 a ‚t‚ termin‚. Op‚ration r‚ussieÿ: le processus avec PID 8892 a ‚t‚ termin‚. Op‚ration r‚ussieÿ: le processus avec PID 4948 a ‚t‚ termin‚. Op‚ration r‚ussieÿ: le processus avec PID 8620 a ‚t‚ termin‚. Op‚ration r‚ussieÿ: le processus avec PID 1232 a ‚t‚ termin‚. Op‚ration r‚ussieÿ: le processus avec PID 8508 a ‚t‚ termin‚. Op‚ration r‚ussieÿ: le processus avec PID 9828 a ‚t‚ termin‚. Op‚ration r‚ussieÿ: le processus avec PID 10272 a ‚t‚ termin‚. Op‚ration r‚ussieÿ: le processus avec PID 10600 a ‚t‚ termin‚. Op‚ration r‚ussieÿ: le processus avec PID 11708 a ‚t‚ termin‚. Op‚ration r‚ussieÿ: le processus avec PID 11728 a ‚t‚ termin‚. Op‚ration r‚ussieÿ: le processus avec PID 10432 a ‚t‚ termin‚. Op‚ration r‚ussieÿ: le processus avec PID 4348 a ‚t‚ termin‚. Op‚ration r‚ussieÿ: le processus avec PID 10156 a ‚t‚ termin‚. Op‚ration r‚ussieÿ: le processus avec PID 8896 a ‚t‚ termin‚. Op‚ration r‚ussieÿ: le processus avec PID 10352 a ‚t‚ termin‚. Op‚ration r‚ussieÿ: le processus avec PID 10876 a ‚t‚ termin‚. Op‚ration r‚ussieÿ: le processus avec PID 11612 a ‚t‚ termin‚. Op‚ration r‚ussieÿ: le processus avec PID 7164 a ‚t‚ termin‚. Op‚ration r‚ussieÿ: le processus avec PID 5572 a ‚t‚ termin‚. Op‚ration r‚ussieÿ: le processus avec PID 11740 a ‚t‚ termin‚. Op‚ration r‚ussieÿ: le processus avec PID 9904 a ‚t‚ termin‚. Op‚ration r‚ussieÿ: le processus avec PID 10884 a ‚t‚ termin‚. Op‚ration r‚ussieÿ: le processus avec PID 9288 a ‚t‚ termin‚. Informationÿ: aucune tƒche en service ne correspond aux critŠres sp‚cifi‚s. =========== - Shortcut info: Shortcut: "C:\ProgramData\Microsoft\Windows\Start Menu\Programs\StartUp\D‚marrage du CCM.lnk" ---------------------------------------------------------------- Shortcut: "C:\ProgramData\Microsoft\Windows\Start Menu\Programs\StartUp\V3S Reconnexion.lnk" ---------------------------------------------------------------- =========== - Scheduled tasks info: Commentaire: Collecteur d'informations r‚seau =========== - USB drive info: f: selected USB Device ID: USBSTOR\DISK&VEN_SPECIFIC&PROD_STORAGE_DEVICE&REV_0009\72541178&0 SCSI\DISK&VEN_&PROD_ST1000DM003-1SB1\4&91D23C5&0&000000 USBSTOR\DISK&VEN_SMI&PROD_USB_DISK&REV_1100\CCYYMMDDHHMMSS54FQ2A&0 Fichier supprim‚ - f:\SDI_R2102\SDI_auto.bat Fichier supprim‚ - f:\Autorun.inf\lpt1.UsbFix WARNING... Possible Andromeda/Gamarue infection... Listing root contents of f: Le volume dans le lecteur F n'a pas de nom. Le num‚ro de s‚rie du volume est A084-9267 R‚pertoire de F:\ 01/01/1980 01:00 3ÿ571ÿ564ÿ146 part z sigma++sfce part 40, cab‚cous au chocolat, les folies uefm de lolly's et cewb‚link u v5, et meeting a‚rien.mp4 13/02/2018 16:54 161ÿ545ÿ189 Ultra semi-widen en keepvid mudar imudar wonderdar.mp4 19/02/2018 12:58 217ÿ970ÿ052 ScreenRecord_20180218_133836.mp4 20/02/2018 16:11 89ÿ128ÿ960 ScreenRecord_20180216_142623.mp4 20/03/2018 20:56 699ÿ844ÿ228 efm hors lfs hyper & tuto instal makeupdirector portable.mp4 23/03/2018 08:19 16ÿ908ÿ288 kc_rename.A?~afpaawt b16 part z tera +ž sfce part 16 acte 1.mp4 26/03/2018 09:03 444ÿ792ÿ832 tuto copie replay zinstall 8 octobre 2k17-26 mars 2k18.avi 29/05/2018 17:04 39ÿ373ÿ287 webinar sirop pomme-caramel.mp4 07/08/2018 19:12 202ÿ293ÿ090 WIN_20180807_19_11_20_Pro.mp4 11/09/2018 13:48 2ÿ625ÿ660ÿ643 +x6rem lite ‚dition makeupdirecdar finalis en dior - marly-puget in e36-barrow 1.wmv 25/12/2018 07:05 82ÿ608ÿ634 IMG_0013~video.mov 27/12/2018 04:36 434ÿ050ÿ211 IMG_0006~video.mov 27/12/2018 04:36 434ÿ050ÿ211 imudar finalis 2019.mov 27/12/2018 06:23 238ÿ568ÿ884 IMG_0014~video.mov 27/12/2018 07:31 328ÿ062ÿ521 IMG_0012~video.mov 31/01/2019 16:15 317ÿ392ÿ274 3…5 rem scŠne 5- ice tea hibiscus … carrefour St alvŠre.mp4 02/02/2019 02:30 1ÿ776ÿ888ÿ304 3…4 rem folie ice-tea hibiscus scŠne 1 version finale propri‚t‚.mp4 02/02/2019 08:07 99ÿ592ÿ203 3…5 rem scŠne 14 - ice tea hibiscus chez Champion souvenir muscade-moulue 2005.mp4 15/02/2019 19:09 165ÿ737ÿ143 3a5rem scŠne 38 - widen 4 avec gedimat et grillis.mp4 15/02/2019 19:14 169ÿ137ÿ450 3a5rem scŠne 39.mp4 15/02/2019 19:28 32ÿ271ÿ188 3a5rem scŠne 40.mp4 15/02/2019 20:29 507ÿ097ÿ396 3a5rem scŠne 41.mp4 06/04/2021 08:48 5ÿ321ÿ112 quickdiag_V5_29.10.19.1.exe 06/04/2021 09:05 522ÿ240 OTM.exe 06/04/2021 09:20 4ÿ541ÿ680 QuickDiag.exe 06/04/2021 12:12 5ÿ712ÿ000 cav_installer_138430010_1a.exe 06/04/2021 12:14 19ÿ756ÿ184 css_installer.exe 06/04/2021 12:29 30ÿ996ÿ392 pdf-bates.exe 06/04/2021 12:35 56ÿ510ÿ344 Non confirm‚ 872264.crdownload 06/04/2021 12:35 61ÿ473ÿ376 Wireshark-win64-3.4.4.exe 06/04/2021 13:06 28ÿ582ÿ504 PrivaZer_free.exe 06/04/2021 13:08 72ÿ108ÿ796 Nuii ice cream review.mp4 06/04/2021 13:10 62ÿ691ÿ512 audio-video-to-exe_2-0-2-0_fr_193866.zip 06/04/2021 15:21 1ÿ504ÿ480 reiboot-for-android.exe 06/04/2021 15:54 Tenorshare.ReiBoot.for.Android.Pro.2.1.1.5 06/04/2021 15:56 5ÿ138ÿ388 Tenorshare.ReiBoot.for.Android.Pro.2.1.4.6.rar-AHlobGA8dwAAvhwCAEZSFwAMAJ4yRb8A.zip 06/04/2021 16:09 1ÿ802ÿ704 iExplore.exe 06/04/2021 16:15 1ÿ056ÿ496 drfone_repair_setup_full3371.exe 06/04/2021 16:57 2ÿ911ÿ160 imyfone-fixppo-for-android_setup.exe 06/04/2021 17:03 713ÿ064ÿ203 G350XXUAPG1_G350OXAAPG1_XEF.zip 06/04/2021 17:04 G350XXUAPG1_G350OXAAPG1_XEF 06/04/2021 17:07 9ÿ658ÿ664 DriverPack-17-Online.exe 06/04/2021 17:08 5ÿ383ÿ074 SDI_R2102.zip 20/04/2021 10:57 4ÿ158ÿ117 01-Babel.mp3 20/04/2021 10:57 4ÿ235ÿ436 02-Vivre.mp3 20/04/2021 10:58 5ÿ054ÿ741 03-I Don't Know.mp3 20/04/2021 10:58 3ÿ503ÿ539 04-Mishaela.mp3 20/04/2021 10:59 5ÿ185ÿ199 05-Child Of Man.mp3 20/04/2021 10:59 5ÿ340ÿ440 06-He.mp3 20/04/2021 11:00 5ÿ401ÿ203 07-Pines.mp3 20/04/2021 11:01 4ÿ849ÿ904 08-Nocturno.mp3 20/04/2021 11:01 3ÿ509ÿ709 09-Yuma.mp3 20/04/2021 11:02 4ÿ910ÿ909 10-Uri.mp3 20/04/2021 11:02 5ÿ191ÿ185 11-Mark Of Cain.mp3 20/04/2021 11:03 4ÿ777ÿ957 12-U.N.I.mp3 20/04/2021 11:03 4ÿ457ÿ930 13-Manhattan Tel Aviv.mp3 20/04/2021 11:04 5ÿ608ÿ228 14-Im Ein At.mp3 20/04/2021 11:04 4ÿ207ÿ379 15-Savior.mp3 20/04/2021 11:05 4ÿ657ÿ480 16-Ave Maria.mp3 20/04/2021 11:05 5ÿ411ÿ574 17-I Don't Know (En Duo Avec Florent Pagny).mp3 20/04/2021 11:34 107ÿ643ÿ499 20210420_111734.MP4 20/04/2021 11:59 36ÿ522ÿ456 20210420_114223.MP4 20/04/2021 14:12 138ÿ942 UsbFix-Report-02.txt 20/04/2021 20:42 352ÿ580ÿ571 lfsu_100%s_gpt finali fin de matin‚e du 5 au 6 avril 2018 (point com declin 4, 3 & +x4).mp4 21/04/2021 07:37 416ÿ176 Rem-VBS.log 21/04/2021 12:02 LOST.DIR 21/04/2021 12:02 DCIM 21/04/2021 12:02 Podcasts 21/04/2021 12:02 Music 21/04/2021 12:02 Ringtones 21/04/2021 12:02 Alarms 21/04/2021 12:02 Notifications 21/04/2021 12:02 Pictures 21/04/2021 12:02 Movies 21/04/2021 12:02 Download 21/04/2021 12:02 HuaweiSystem 21/04/2021 12:02 Sounds 21/04/2021 12:02 Huawei 25/05/2021 13:32 SDI_R2102 27/05/2021 12:43 32ÿ949 plus longue cl‚ usb du monde comodo ad-aware cyberlink.wpp 27/05/2021 12:43 11ÿ723ÿ700 Ashampoo_Snap_jeudi 27 mai 2021_12h33m21s_001_.wmv 01/06/2021 09:00 autorun.inf 09/06/2021 07:50 Android 29/03/2022 10:07 14ÿ716 UsbFix-Report-01 adaware cyberlink cri de aaliyah.txt 66 fichier(s) 14ÿ332ÿ806ÿ382 octets 19 R‚p(s) 140ÿ632ÿ064 octets libres USB drive disinfected and files unhidden ===================================================== Scan finished at: 11:07:39,62 Send this log only if requested by a helper. ===================================================== Made by @bartblaze Tool to delete VBS autorun worm and unhide files Quarantine folder on: C:\Rem-VBSqt Info: https://bartblaze.blogspot.com/2014/02/remediate-vbs-malware.html