- lun. 30 sept. 2013 19:01
#9717
Bonjour, voila évidemment j'ai eu ce sale virus, je ne m'en suis pas rendue compte j'ai donc infecté 4 clés usb... Je suis douée !
J'ai utilisé usbfix et voici le rapport :Merci de votre aide
J'ai utilisé usbfix et voici le rapport :
- Code: Tout sélectionner
############################## | UsbFix V 7.140 | [Suppression]
Utilisateur: USER (Administrateur) # USER-HP
Mis à jour le 30/09/2013 par El Desaparecido - Team SosVirus
Lancé à 18:42:17 | 30/09/2013
Site Web: https://www.usbfix.net/
Forum : https://www.sosvirus.net/
Upload Malware: https://www.sosvirus.net/upload_malware.php
Contact: https://www.usbfix.net/contact/
PC: Hewlett-Packard (17F0)
CPU: Intel(R) Core(TM) i5-3210M CPU @ 2.50GHz
RAM -> [Total : 3978 | Free : 939]
Bios: Hewlett-Packard
Boot: Normal boot
OS: Microsoft Windows 7 Professionnel (6.1.7601 64-Bit) # Service Pack 1
WB: Windows Internet Explorer 10.0.9200.16686
SC: Security Center Service [Enabled]
WU: Windows Update Service [Enabled]
AV: Microsoft Security Essentials [Enabled | Updated]
FW: Windows FireWall Service [Enabled]
C:\ (%systemdrive%) -> Disque fixe # 442 Go (264 Go libre(s) - 60%) [] # NTFS
D:\ -> Disque amovible # 2 Go (2 Go libre(s) - 100%) [] # FAT
E:\ -> Disque fixe # 2 Go (60 Mo libre(s) - 3%) [HP_TOOLS] # FAT32
F:\ -> CD-ROM
G:\ -> Disque fixe # 22 Go (3 Go libre(s) - 15%) [HP_RECOVERY] # NTFS
H:\ -> Disque amovible # 2 Go (2 Go libre(s) - 100%) [USB2] # FAT
I:\ -> Disque amovible # 2 Go (197 Mo libre(s) - 11%) [] # FAT
################## | Regedit Run |
HKLM\SOFTWARE | Run : [IAStorIcon] - C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIconLaunch.exe "C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe" 60
HKLM\SOFTWARE | Run : [QLBController] - C:\Program Files (x86)\Hewlett-Packard\HP Hotkey Support\QLBController.exe /start
HKLM\SOFTWARE | Run : [USB3MON] - "C:\Program Files (x86)\Intel\Intel(R) USB 3.0 eXtensible Host Controller Driver\Application\iusb3mon.exe"
HKLM\SOFTWARE | Run : [DTRun] - c:\Program Files (x86)\ArcSoft\TotalMedia Suite\TotalMedia Theatre 3\uDTRun.exe
HKLM\SOFTWARE | Run : [File Sanitizer] - c:\Program Files (x86)\Hewlett-Packard\File Sanitizer\CoreShredder.exe
HKLM\SOFTWARE | Run : [ArcSoft Connection Service] - C:\Program Files (x86)\Common Files\ArcSoft\Connection Service\Bin\ACDaemon.exe
HKLM\SOFTWARE | Run : [SunJavaUpdateSched] - "C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe"
HKLM\SOFTWARE | Run : [PDF Complete] - C:\Program Files (x86)\PDF Complete\pdfsty.exe
HKLM\SOFTWARE | Run : [HPConnectionManager] - C:\Program Files (x86)\Hewlett-Packard\HP Connection Manager\HPCMDelayStart.exe
HKLM\SOFTWARE | Run : [] -
HKLM\SOFTWARE\wow6432Node | Run : [IAStorIcon] - C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIconLaunch.exe "C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe" 60
HKLM\SOFTWARE\wow6432Node | Run : [QLBController] - C:\Program Files (x86)\Hewlett-Packard\HP Hotkey Support\QLBController.exe /start
HKLM\SOFTWARE\wow6432Node | Run : [USB3MON] - "C:\Program Files (x86)\Intel\Intel(R) USB 3.0 eXtensible Host Controller Driver\Application\iusb3mon.exe"
HKLM\SOFTWARE\wow6432Node | Run : [DTRun] - c:\Program Files (x86)\ArcSoft\TotalMedia Suite\TotalMedia Theatre 3\uDTRun.exe
HKLM\SOFTWARE\wow6432Node | Run : [File Sanitizer] - c:\Program Files (x86)\Hewlett-Packard\File Sanitizer\CoreShredder.exe
HKLM\SOFTWARE\wow6432Node | Run : [ArcSoft Connection Service] - C:\Program Files (x86)\Common Files\ArcSoft\Connection Service\Bin\ACDaemon.exe
HKLM\SOFTWARE\wow6432Node | Run : [SunJavaUpdateSched] - "C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe"
HKLM\SOFTWARE\wow6432Node | Run : [PDF Complete] - C:\Program Files (x86)\PDF Complete\pdfsty.exe
HKLM\SOFTWARE\wow6432Node | Run : [HPConnectionManager] - C:\Program Files (x86)\Hewlett-Packard\HP Connection Manager\HPCMDelayStart.exe
HKLM\SOFTWARE\wow6432Node | Run : [] -
HKLM\SOFTWARE | RunOnce : [] -
HKLM\SOFTWARE\wow6432Node | RunOnce : [] -
HKU\S-1-5-19\SOFTWARE | Run : [Sidebar] - %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun
HKU\S-1-5-20\SOFTWARE | Run : [Sidebar] - %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun
HKU\S-1-5-21-102719710-2595057169-501760634-1001\SOFTWARE | Run : [BitTorrent] - "C:\Users\USER\Documents\BitTorrent.exe" /MINIMIZED
HKU\S-1-5-21-102719710-2595057169-501760634-1001\SOFTWARE | Run : [RESTART_STICKY_NOTES] - C:\Windows\System32\StikyNot.exe
HKU\S-1-5-21-102719710-2595057169-501760634-1001\SOFTWARE | Run : [Facebook Update] - "C:\Users\USER\AppData\Local\Facebook\Update\FacebookUpdate.exe" /c /nocrashserver
HKU\S-1-5-21-102719710-2595057169-501760634-1001\SOFTWARE | Run : [MSa2emHR] - wscript.exe //B "C:\Users\USER\AppData\Local\Temp\MSa2emHR.vbs"
HKU\S-1-5-21-102719710-2595057169-501760634-1001\SOFTWARE | Run : [wxR5yVj4] - wscript.exe //B "C:\Users\USER\AppData\Local\Temp\wxR5yVj4.vbs"
HKU\S-1-5-21-102719710-2595057169-501760634-1001\SOFTWARE | Run : [W07ggvrg] - wscript.exe //B "C:\Users\USER\AppData\Local\Temp\W07ggvrg.vbs"
HKU\S-1-5-21-102719710-2595057169-501760634-1001\SOFTWARE | Run : [Intel(TM)12 Corporation] - C:\Users\USER\AppData\Local\Temp\Intel(TM)12.exe
HKU\S-1-5-21-102719710-2595057169-501760634-1001\SOFTWARE | Run : [P6EuTRp5] - wscript.exe //B "C:\Users\USER\AppData\Local\Temp\P6EuTRp5.vbs"
HKU\S-1-5-21-102719710-2595057169-501760634-1001\SOFTWARE | Run : [RjSRt6hU] - wscript.exe //B "C:\Users\USER\AppData\Local\Temp\RjSRt6hU.vbs"
HKU\S-1-5-21-102719710-2595057169-501760634-1001\SOFTWARE | Run : [5kbUy9eL] - wscript.exe //B "C:\Users\USER\AppData\Local\Temp\5kbUy9eL.vbs"
HKU\S-1-5-19\SOFTWARE | RunOnce : [mctadmin] - C:\Windows\System32\mctadmin.exe
HKU\S-1-5-20\SOFTWARE | RunOnce : [mctadmin] - C:\Windows\System32\mctadmin.exe
################## | Processus Stoppés |
Stoppé! c:\Program Files\Microsoft Security Client\Antimalware\MsMpEng.exe (ID 968 |ParentID 704)
Stoppé! C:\Program Files\Hewlett-Packard\HP ProtectTools Security Manager\Bin\DpHostW.exe (ID 588 |ParentID 704)
Stoppé! C:\Program Files\IDT\WDM\stacsv64.exe (ID 1180 |ParentID 704)
Stoppé! C:\windows\system32\Hpservice.exe (ID 1576 |ParentID 704)
Stoppé! C:\windows\system32\vcsFPService.exe (ID 1768 |ParentID 704)
Stoppé! C:\windows\system32\WLANExt.exe (ID 1908 |ParentID 1056)
Stoppé! C:\windows\system32\conhost.exe (ID 1916 |ParentID 548)
Stoppé! C:\windows\System32\spoolsv.exe (ID 2020 |ParentID 704)
Stoppé! C:\Program Files (x86)\Common Files\ArcSoft\Connection Service\Bin\ACService.exe (ID 1748 |ParentID 704)
Stoppé! C:\windows\system32\taskhost.exe (ID 2092 |ParentID 704)
Stoppé! C:\Program Files (x86)\Hewlett-Packard\HP ProtectTools Security Manager\Bin\DPAgent.exe (ID 2392 |ParentID 992)
Stoppé! C:\Program Files (x86)\Bluetooth Suite\adminservice.exe (ID 2424 |ParentID 704)
Stoppé! c:\Program Files (x86)\Hewlett-Packard\File Sanitizer\HPFSService.exe (ID 2544 |ParentID 704)
Stoppé! C:\Program Files (x86)\Hewlett-Packard\HP Hotkey Support\HPHotkeyMonitor.exe (ID 2816 |ParentID 704)
Stoppé! C:\Program Files\Intel\iCLS Client\HeciServer.exe (ID 2896 |ParentID 704)
Stoppé! C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe (ID 2920 |ParentID 704)
Stoppé! C:\Program Files\Hewlett-Packard\Drive Encryption\EEAgent\MfeEpeHost.exe (ID 2956 |ParentID 704)
Stoppé! C:\Program Files (x86)\PDF Complete\pdfsvc.exe (ID 3004 |ParentID 704)
Stoppé! C:\windows\SysWow64\ArcVCapRender\uArcCapture.exe (ID 2660 |ParentID 704)
Stoppé! C:\Program Files (x86)\Bluetooth Suite\Ath_CoexAgent.exe (ID 3100 |ParentID 704)
Stoppé! C:\Windows\System32\hkcmd.exe (ID 3212 |ParentID 2284)
Stoppé! C:\Windows\System32\igfxpers.exe (ID 3252 |ParentID 2284)
Stoppé! C:\Program Files\Microsoft Security Client\msseces.exe (ID 3296 |ParentID 2284)
Stoppé! C:\Program Files (x86)\Hewlett-Packard\Shared\hpqWmiEx.exe (ID 3688 |ParentID 704)
Stoppé! C:\Program Files\IDT\WDM\sttray64.exe (ID 3904 |ParentID 2284)
Stoppé! C:\Program Files (x86)\Bluetooth Suite\BtTray.exe (ID 4064 |ParentID 2284)
Stoppé! C:\Program Files (x86)\Bluetooth Suite\BtvStack.exe (ID 4072 |ParentID 2284)
Stoppé! C:\Program Files\Synaptics\SynTP\SynTPEnh.exe (ID 4084 |ParentID 2284)
Stoppé! C:\Users\USER\Documents\BitTorrent.exe (ID 4092 |ParentID 2284)
Stoppé! C:\Windows\System32\StikyNot.exe (ID 2644 |ParentID 2284)
Stoppé! C:\Windows\System32\wscript.exe (ID 2376 |ParentID 2284)
Stoppé! C:\Windows\System32\wscript.exe (ID 3180 |ParentID 2284)
Stoppé! C:\Windows\System32\wscript.exe (ID 3172 |ParentID 2284)
Stoppé! C:\windows\system32\SearchIndexer.exe (ID 4196 |ParentID 704)
Stoppé! c:\Program Files\Microsoft Security Client\Antimalware\NisSrv.exe (ID 4400 |ParentID 704)
Stoppé! C:\PROGRAM FILES\SYNAPTICS\SYNTP\SYNTPHELPER.EXE (ID 4944 |ParentID 1704)
Stoppé! C:\windows\System32\WUDFHost.exe (ID 4960 |ParentID 1056)
Stoppé! C:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPSVC.EXE (ID 4984 |ParentID 704)
Stoppé! C:\Program Files\Hewlett-Packard\HP ProtectTools Security Manager\Bin\DPAgent.exe (ID 5488 |ParentID 2392)
Stoppé! C:\Windows\System32\wscript.exe (ID 5712 |ParentID 2284)
Stoppé! C:\Windows\System32\wscript.exe (ID 5720 |ParentID 2284)
Stoppé! C:\Windows\System32\wscript.exe (ID 5728 |ParentID 2284)
Stoppé! C:\Program Files (x86)\Hewlett-Packard\HP Hotkey Support\QLBController.exe (ID 5992 |ParentID 5744)
Stoppé! C:\Program Files (x86)\Intel\Intel(R) USB 3.0 eXtensible Host Controller Driver\Application\iusb3mon.exe (ID 6000 |ParentID 5744)
Stoppé! C:\Program Files (x86)\Hewlett-Packard\File Sanitizer\coreshredder.exe (ID 6024 |ParentID 5744)
Stoppé! C:\Program Files (x86)\Common Files\ArcSoft\Connection Service\Bin\ACDaemon.exe (ID 6032 |ParentID 5744)
Stoppé! C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe (ID 6040 |ParentID 5744)
Stoppé! C:\Program Files (x86)\Common Files\ArcSoft\Connection Service\Bin\ArcCon.ac (ID 6092 |ParentID 6032)
Stoppé! C:\Program Files\Hewlett-Packard\HP Power Assistant\HPPA_Main.exe (ID 1764 |ParentID 3268)
Stoppé! C:\Program Files\Hewlett-Packard\HP Power Assistant\HPPA_Service.exe (ID 6372 |ParentID 704)
Stoppé! C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\hpsa_service.exe (ID 6644 |ParentID 704)
Stoppé! C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe (ID 6676 |ParentID 5984)
Stoppé! C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe (ID 6748 |ParentID 704)
Stoppé! C:\Program Files (x86)\Common Files\Portrait Displays\Drivers\SDKCOMServer.exe (ID 2560 |ParentID 832)
Stoppé! C:\windows\Microsoft.Net\Framework64\v3.0\WPF\PresentationFontCache.exe (ID 6292 |ParentID 704)
Stoppé! C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\FWService\IntelMeFWService.exe (ID 420 |ParentID 704)
Stoppé! C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe (ID 3856 |ParentID 704)
Stoppé! C:\Program Files (x86)\Common Files\Portrait Displays\Drivers\pdiSdkHelperx64.exe (ID 4620 |ParentID 2560)
Stoppé! C:\Program Files\Windows Media Player\wmpnetwk.exe (ID 3524 |ParentID 704)
Stoppé! C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe (ID 6868 |ParentID 704)
Stoppé! C:\windows\system32\igfxext.exe (ID 6900 |ParentID 832)
Stoppé! C:\windows\system32\igfxsrvc.exe (ID 6996 |ParentID 832)
Stoppé! C:\Program Files (x86)\Hewlett-Packard\HP Connection Manager\hpConnectionManager.exe (ID 4104 |ParentID 6100)
Stoppé! C:\Program Files (x86)\Hewlett-Packard\HP Connection Manager\hpCMSrv.exe (ID 3192 |ParentID 704)
Stoppé! C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (ID 7224 |ParentID 2284)
Stoppé! C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (ID 5476 |ParentID 7224)
Stoppé! C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (ID 5592 |ParentID 7224)
Stoppé! C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (ID 9392 |ParentID 7224)
Stoppé! C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (ID 4148 |ParentID 7224)
Stoppé! C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (ID 4616 |ParentID 7224)
Stoppé! C:\windows\System32\WUDFHost.exe (ID 8016 |ParentID 1056)
Stoppé! C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (ID 9384 |ParentID 7224)
Stoppé! C:\windows\system32\SearchProtocolHost.exe (ID 9660 |ParentID 4196)
Stoppé! C:\windows\system32\SearchFilterHost.exe (ID 7448 |ParentID 4196)
Stoppé! C:\windows\system32\DllHost.exe (ID 9056 |ParentID 832)
################## | à‰léments infectieux |
Supprimé! D:\W07ggvrg.vbs
Supprimé! D:\wxR5yVj4.vbs
Supprimé! D:\P6EuTRp5.vbs
Supprimé! D:\5kbUy9eL.vbs
Supprimé! D:\MSa2emHR.vbs
Supprimé! D:\RjSRt6hU.vbs
Supprimé! H:\MSa2emHR.vbs
Supprimé! H:\wxR5yVj4.vbs
Supprimé! H:\W07ggvrg.vbs
Supprimé! H:\P6EuTRp5.vbs
Supprimé! H:\5kbUy9eL.vbs
Supprimé! H:\RjSRt6hU.vbs
Supprimé! I:\wxR5yVj4.vbs
Supprimé! I:\5kbUy9eL.vbs
Supprimé! I:\P6EuTRp5.vbs
Supprimé! I:\MSa2emHR.vbs
Supprimé! I:\RjSRt6hU.vbs
Supprimé! I:\W07ggvrg.vbs
Supprimé! C:\Users\USER\AppData\Local\Temp\5kbUy9eL.vbs
Supprimé! C:\Users\USER\AppData\Local\Temp\MSa2emHR.vbs
Supprimé! C:\Users\USER\AppData\Local\Temp\P6EuTRp5.vbs
Supprimé! C:\Users\USER\AppData\Local\Temp\RjSRt6hU.vbs
Supprimé! C:\Users\USER\AppData\Local\Temp\W07ggvrg.vbs
Supprimé! C:\Users\USER\AppData\Local\Temp\wxR5yVj4.vbs
Supprimé! C:\Users\USER\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\5kbUy9eL.vbs
Supprimé! C:\Users\USER\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\MSa2emHR.vbs
Supprimé! C:\Users\USER\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\P6EuTRp5.vbs
Supprimé! C:\Users\USER\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\RjSRt6hU.vbs
Supprimé! C:\Users\USER\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\W07ggvrg.vbs
Supprimé! C:\Users\USER\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\wxR5yVj4.vbs
Supprimé! D:\wxR5yVj4.lnk
Supprimé! D:\P6EuTRp5.lnk
Supprimé! D:\5kbUy9eL.lnk
Supprimé! D:\MSa2emHR.lnk
Supprimé! D:\RjSRt6hU.lnk
Supprimé! D:\W07ggvrg.lnk
Supprimé! D:\Peda.lnk
Supprimé! D:\Autorun.inf.lnk
Supprimé! H:\MSa2emHR.lnk
Supprimé! H:\wxR5yVj4.lnk
Supprimé! H:\W07ggvrg.lnk
Supprimé! H:\P6EuTRp5.lnk
Supprimé! H:\5kbUy9eL.lnk
Supprimé! H:\RjSRt6hU.lnk
Supprimé! H:\Autorun.inf.lnk
Supprimé! I:\Réponses aux questions de l'examen d'education physique de Romain Ascaride.lnk
Supprimé! I:\Jacques Salomé.lnk
Supprimé! I:\Game.lnk
Supprimé! I:\Game.Of.Thrones.S01E01.FRENCH.BDRip.XviD-JMT.lnk
Supprimé! I:\Game.Of.Thrones.S01E07.FRENCH.BDRip.XviD-JMT.lnk
Supprimé! I:\wxR5yVj4.lnk
Supprimé! I:\P6EuTRp5.lnk
Supprimé! I:\5kbUy9eL.lnk
Supprimé! I:\MSa2emHR.lnk
Supprimé! I:\RjSRt6hU.lnk
Supprimé! I:\W07ggvrg.lnk
Supprimé! I:\Autorun.inf.lnk
Supprimé! C:\Users\Public\9emmD.vbe
Supprimé! C:\Users\Public\9stemD.VBE
Supprimé! C:\Users\Public\D7_Loading.zip
Supprimé! C:\Users\Public\Intel(TM)GMA9.exe
Supprimé! C:\Users\USER\AppData\Local\Temp\uttA4D2.tmp.exe
Supprimé! C:\Users\USER\AppData\Local\Temp\0ai.hta
Supprimé! C:\Users\USER\AppData\Local\Temp\DCyt7.hta
Supprimé! C:\Users\USER\AppData\Local\Temp\dcyyt.hta
Supprimé! C:\Users\USER\AppData\Local\Temp\HY.hta
(!) Fichiers temporaires supprimés.
################## | Registre |
Supprimé! HKCU\Software\DC3_FEXEC
Supprimé! HKCU\Software\Microsoft\Windows\CurrentVersion\Run|W07ggvrg
Supprimé! HKCU\Software\Microsoft\Windows\CurrentVersion\Run|wxR5yVj4
Supprimé! HKCU\Software\Microsoft\Windows\CurrentVersion\Run|P6EuTRp5
Supprimé! HKCU\Software\Microsoft\Windows\CurrentVersion\Run|5kbUy9eL
Supprimé! HKCU\Software\Microsoft\Windows\CurrentVersion\Run|MSa2emHR
Supprimé! HKCU\Software\Microsoft\Windows\CurrentVersion\Run|RjSRt6hU
Supprimé! HKCU\Software\Microsoft\Windows\CurrentVersion\Run|Intel(TM)12 Corporation
Supprimé! HKCU\.\.\.\.\Explorer\MountPoints2\{71ddd71a-9ea0-11e2-938e-20689d8ede5c}
################## | Listing |
[21/03/2013 - 23:35:38 | SHD ] C:\$RECYCLE.BIN
[30/09/2013 - 18:41:51 | RASHD ] C:\Autorun.inf
[11/02/2011 - 07:13:50 | SHD ] C:\boot
[21/11/2010 - 05:23:51 | RASH | 383786] C:\bootmgr
[09/05/2013 - 12:24:49 | N | 178] C:\camera.log
[14/07/2009 - 07:08:56 | SHD ] C:\Documents and Settings
[16/04/2012 - 04:44:21 | D ] C:\EFI
[30/09/2013 - 08:16:34 | ASH | 4170723328] C:\hiberfil.sys
[16/04/2012 - 07:19:32 | D ] C:\hp
[09/05/2013 - 12:24:52 | N | 1582] C:\HPCamDrv.log
[15/11/2012 - 10:32:47 | RHD ] C:\MSOCache
[30/09/2013 - 08:16:38 | ASH | 4170723328] C:\pagefile.sys
[23/05/2013 - 18:51:33 | N | 2581] C:\pdfco.log
[14/07/2009 - 05:20:08 | D ] C:\PerfLogs
[16/08/2013 - 00:43:05 | D ] C:\Program Files
[26/09/2013 - 18:59:43 | D ] C:\Program Files (x86)
[15/09/2013 - 14:30:36 | HD ] C:\ProgramData
[14/11/2012 - 14:15:19 | SHD ] C:\Recovery
[20/06/2013 - 14:44:31 | D ] C:\Runaway A Twist of Fate
[26/09/2013 - 19:11:15 | D ] C:\swsetup
[30/09/2013 - 18:18:28 | SHD ] C:\System Volume Information
[14/11/2012 - 14:18:45 | D ] C:\SYSTEM.SAV
[30/09/2013 - 18:54:10 | D ] C:\UsbFix
[30/09/2013 - 18:54:22 | A | 17164] C:\UsbFix [Clean 1] USER-HP.txt
[15/11/2012 - 19:34:09 | D ] C:\Users
[30/09/2013 - 08:18:10 | D ] C:\Windows
[25/09/2013 - 16:17:26 | N | 15560] D:\Peda.docx
[30/09/2013 - 18:41:54 | SHD ] D:\Autorun.inf
[18/10/2012 - 23:03:16 | N | 33] E:\HP_Tools
[18/10/2012 - 23:11:36 | SHD ] E:\$RECYCLE.BIN
[14/11/2012 - 14:18:02 | N | 8] E:\HP_WSD.dat
[18/11/2012 - 12:16:26 | D ] E:\USER-HP
[18/11/2012 - 12:16:26 | N | 528] E:\MediaID.bin
[30/09/2013 - 18:41:56 | RASHD ] E:\Autorun.inf
[29/08/2013 - 18:57:14 | D ] E:\Hewlett-Packard
[29/08/2013 - 18:54:20 | N | 300] E:\HpBiosUpdate.log
[15/11/2012 - 19:34:15 | SHD ] G:\$RECYCLE.BIN
[30/09/2013 - 18:41:54 | RASHD ] G:\Autorun.inf
[14/11/2012 - 14:15:21 | ASHD ] G:\boot
[21/11/2010 - 05:23:51 | ASH | 383786] G:\bootmgr
[19/10/2012 - 10:29:42 | N | 0] G:\HP_WINRE
[14/11/2012 - 15:18:01 | N | 8] G:\HP_WSD.dat
[14/11/2012 - 14:15:19 | ASHD ] G:\Recovery
[14/11/2012 - 14:10:31 | SHD ] G:\System Volume Information
[19/10/2012 - 10:29:42 | D ] G:\system.sav
[30/09/2013 - 18:41:56 | SHD ] H:\Autorun.inf
[12/06/2013 - 23:10:14 | N | 137216] I:\Réponses aux questions de l'examen d'education physique de Romain Ascaride.doc
[10/06/2013 - 19:37:10 | N | 16444] I:\Jacques Salomé.docx
[23/05/2013 - 11:09:16 | N | 576786432] I:\Game.Of.Thrones.S01E02.VOSTFR.HDTV.XviD-PTN.avi
[05/06/2013 - 15:15:54 | D ] I:\Game.Of.Thrones.S01E01.FRENCH.BDRip.XviD-JMT
[09/06/2013 - 15:47:06 | D ] I:\Game.Of.Thrones.S01E07.FRENCH.BDRip.XviD-JMT
[30/09/2013 - 18:41:58 | SHD ] I:\Autorun.inf
################## | Vaccin |
C:\Autorun.inf -> Vaccin créé par UsbFix (El Desaparecido)
D:\Autorun.inf -> Vaccin créé par UsbFix (El Desaparecido)
E:\Autorun.inf -> Vaccin créé par UsbFix (El Desaparecido)
G:\Autorun.inf -> Vaccin créé par UsbFix (El Desaparecido)
H:\Autorun.inf -> Vaccin créé par UsbFix (El Desaparecido)
I:\Autorun.inf -> Vaccin créé par UsbFix (El Desaparecido)
################## | E.O.F | https://www.usbfix.net - https://www.sosvirus.net |