Merci d avance, je vous envoie les rapports
Rapport Scan
############################## | UsbFix V 7.145 | [Recherche]
Utilisateur: ALICE (Administrateur) # ALICE-HP
Mis à jour le 17/10/2013 par El Desaparecido - Team SosVirus
Lancé à 16:25:41 | 11/11/2013
Site Web:
https://www.usbfix.net/
Forum :
https://www.sosvirus.net/
Upload Malware:
https://www.sosvirus.net/upload_malware.php
Contact:
https://www.usbfix.net/contact/
PC: Hewlett-Packard (338D)
CPU: Intel(R) Atom(TM) CPU N2600 @ 1.60GHz
RAM -> [Total : 1012 | Free : 181]
Bios: Hewlett-Packard
Boot: Normal boot
OS: Microsoft Windows 7 à‰dition Starter (6.1.7601 32-Bit) # Service Pack 1
WB: Windows Internet Explorer 10.0.9200.16721
SC: Security Center Service [Enabled]
WU: Windows Update Service [Enabled]
AV: Kaspersky Anti-Virus [(!) Disabled | (!) Outdated]
FW: Windows FireWall Service [Enabled]
C:\ (%systemdrive%) -> Disque fixe # 181 Go (89 Go libre(s) - 49%) [] # NTFS
D:\ -> Disque fixe # 19 Go (2 Go libre(s) - 11%) [Recovery] # NTFS
E:\ -> Disque amovible # 7 Go (7 Go libre(s) - 99%) [] # FAT32
################## | Processus Actif |
C:\Windows\system32\csrss.exe (ID 528 |ParentID 496)
C:\Windows\system32\wininit.exe (ID 588 |ParentID 496)
C:\Windows\system32\csrss.exe (ID 596 |ParentID 580)
C:\Windows\system32\services.exe (ID 664 |ParentID 588)
C:\Windows\system32\winlogon.exe (ID 688 |ParentID 580)
C:\Windows\system32\lsass.exe (ID 716 |ParentID 588)
C:\Windows\system32\lsm.exe (ID 724 |ParentID 588)
C:\Windows\system32\svchost.exe (ID 832 |ParentID 664)
C:\Windows\system32\svchost.exe (ID 936 |ParentID 664)
C:\Windows\System32\svchost.exe (ID 1028 |ParentID 664)
C:\Windows\System32\svchost.exe (ID 1076 |ParentID 664)
C:\Windows\system32\svchost.exe (ID 1104 |ParentID 664)
C:\Windows\system32\svchost.exe (ID 1132 |ParentID 664)
C:\Program Files\IDT\WDM\STacSV.exe (ID 1184 |ParentID 664)
C:\Windows\system32\svchost.exe (ID 1496 |ParentID 664)
C:\Windows\system32\WLANExt.exe (ID 1644 |ParentID 1076)
C:\Windows\system32\conhost.exe (ID 1652 |ParentID 528)
C:\Windows\system32\taskeng.exe (ID 1820 |ParentID 1132)
C:\Windows\System32\spoolsv.exe (ID 1840 |ParentID 664)
C:\Windows\system32\svchost.exe (ID 1892 |ParentID 664)
C:\Program Files\Common Files\Adobe\ARM\1.0\armsvc.exe (ID 128 |ParentID 664)
C:\Program Files\IDT\WDM\aestsrv.exe (ID 428 |ParentID 664)
C:\Program Files\Bluetooth Suite\adminservice.exe (ID 536 |ParentID 664)
C:\Windows\system32\svchost.exe (ID 1128 |ParentID 664)
C:\Program Files\Hewlett-Packard\HP Client Services\HPClientServices.exe (ID 1416 |ParentID 664)
C:\Program Files\Hewlett-Packard\HP Quick Launch\HPWMISVC.exe (ID 1472 |ParentID 664)
C:\Program Files\InternetEverywhere\InternetEverywhere_Service.exe (ID 1800 |ParentID 664)
C:\Program Files\Microsoft Application Virtualization Client\sftvsa.exe (ID 2380 |ParentID 664)
C:\ProgramData\Skype\Toolbars\Skype C2C Service\c2c_service.exe (ID 2496 |ParentID 664)
C:\Windows\system32\svchost.exe (ID 2572 |ParentID 664)
C:\Program Files\EazelBar\ToolbarUpdaterService.exe (ID 2616 |ParentID 664)
C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE (ID 2720 |ParentID 664)
C:\Program Files\Yahoo!\SoftwareUpdate\YahooAUService.exe (ID 2780 |ParentID 664)
C:\Program Files\Bluetooth Suite\Ath_CoexAgent.exe (ID 2836 |ParentID 664)
C:\Program Files\Hewlett-Packard\HP Auto\HPAuto.exe (ID 2864 |ParentID 664)
C:\Program Files\Microsoft Application Virtualization Client\sftlist.exe (ID 2924 |ParentID 664)
C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe (ID 2992 |ParentID 2720)
C:\Program Files\Common Files\Microsoft Shared\Virtualization Handler\CVHSVC.EXE (ID 3224 |ParentID 664)
C:\Windows\system32\taskhost.exe (ID 3396 |ParentID 664)
C:\Windows\system32\SearchIndexer.exe (ID 3536 |ParentID 664)
C:\Windows\system32\Dwm.exe (ID 3556 |ParentID 1076)
C:\Windows\Explorer.EXE (ID 3596 |ParentID 3480)
C:\Windows\system32\svchost.exe (ID 3760 |ParentID 664)
C:\Windows\system32\svchost.exe (ID 3804 |ParentID 664)
c:\programdata\summersoft\optimizerpro\OptimizerPro.exe (ID 3884 |ParentID 1820)
C:\Users\ALICE\AppData\Roaming\uTorrent\uTorrent.exe (ID 2376 |ParentID 3596)
C:\Program Files\Optimizer Pro\OptProReminder.exe (ID 4248 |ParentID 860)
C:\Windows\System32\svchost.exe (ID 4972 |ParentID 664)
C:\Windows\system32\taskeng.exe (ID 5252 |ParentID 1132)
C:\Program Files\CyberLink\YouCam\YCMMirage.exe (ID 5348 |ParentID 5252)
C:\Program Files\Windows Media Player\wmpnetwk.exe (ID 5356 |ParentID 664)
C:\Windows\system32\DllHost.exe (ID 5740 |ParentID 832)
C:\Users\ALICE\AppData\Local\Google\Chrome\Application\chrome.exe (ID 5872 |ParentID 3596)
C:\Users\ALICE\AppData\Local\Google\Chrome\Application\chrome.exe (ID 4176 |ParentID 5872)
C:\Program Files\Hewlett-Packard\HP Support Framework\hpsa_service.exe (ID 5720 |ParentID 664)
C:\Users\ALICE\AppData\Local\Google\Chrome\Application\chrome.exe (ID 1900 |ParentID 5872)
C:\Program Files\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe (ID 5892 |ParentID 664)
C:\Windows\System32\svchost.exe (ID 5812 |ParentID 664)
C:\Users\ALICE\AppData\Local\Google\Chrome\Application\chrome.exe (ID 3428 |ParentID 5872)
C:\Windows\system32\wuauclt.exe (ID 1460 |ParentID 1132)
C:\Windows\system32\taskhost.exe (ID 4652 |ParentID 664)
C:\Program Files\Microsoft\BingBar\7.2.241.0\SeaPort.exe (ID 3104 |ParentID 664)
C:\Users\ALICE\AppData\Local\Google\Chrome\Application\chrome.exe (ID 3712 |ParentID 5872)
C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe (ID 7904 |ParentID 7864)
C:\Program Files\Common Files\microsoft shared\Virtualization Handler\CVH.EXE (ID 6656 |ParentID 3596)
C:\Program Files\Common Files\microsoft shared\virtualization handler\OfficeVirt.exe (ID 6224 |ParentID 6656)
C:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPSVC.EXE (ID 6216 |ParentID 664)
C:\Windows\system32\igfxsrvc.exe (ID 5824 |ParentID 832)
C:\Program Files\Internet Explorer\iexplore.exe (ID 5692 |ParentID 3596)
C:\Program Files\Internet Explorer\iexplore.exe (ID 3732 |ParentID 5692)
C:\Program Files\Internet Explorer\iexplore.exe (ID 6332 |ParentID 3596)
C:\Program Files\Internet Explorer\iexplore.exe (ID 6908 |ParentID 6332)
C:\Windows\system32\Macromed\Flash\FlashUtil32_11_2_202_235_ActiveX.exe (ID 7540 |ParentID 832)
C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 2012\klwtblfs.exe (ID 5100 |ParentID 832)
C:\Program Files\Yahoo!\Companion\Installs\cpn1\ytbb.exe (ID 7348 |ParentID 832)
C:\Windows\system32\wbem\wmiprvse.exe (ID 4236 |ParentID 832)
C:\Windows\System32\WUDFHost.exe (ID 1864 |ParentID 1076)
C:\UsbFix\Go.exe (ID 2204 |ParentID 4240)
################## | Regedit Run |
HKLM\SOFTWARE | Run : [AVP] - "C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 2012\avp.exe"
HKLM\SOFTWARE | RunOnce : [] -
HKU\S-1-5-19\SOFTWARE | Run : [Sidebar] - %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun
HKU\S-1-5-20\SOFTWARE | Run : [Sidebar] - %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun
HKU\S-1-5-21-4258096444-3120789726-3743063335-1000\SOFTWARE | Run : [Google Update] - "C:\Users\ALICE\AppData\Local\Google\Update\GoogleUpdate.exe" /c
HKU\S-1-5-21-4258096444-3120789726-3743063335-1000\SOFTWARE | Run : [uTorrent] - "C:\Users\ALICE\AppData\Roaming\uTorrent\uTorrent.exe" /MINIMIZED
HKU\S-1-5-21-4258096444-3120789726-3743063335-1000\SOFTWARE | Run : [Optimizer Pro] - C:\Program Files\Optimizer Pro\OptProLauncher.exe
HKU\S-1-5-21-4258096444-3120789726-3743063335-1000\SOFTWARE | Run : [se] - C:\Users\user\AppData\Roaming\SkypEmoticons\SE.exe /minimized
HKU\S-1-5-19\SOFTWARE | RunOnce : [mctadmin] - C:\Windows\System32\mctadmin.exe
HKU\S-1-5-20\SOFTWARE | RunOnce : [mctadmin] - C:\Windows\System32\mctadmin.exe
################## | à‰léments infectieux |
Présent! E:\mseinstall.lnk
Présent! E:\Logiciels de départ.lnk
Présent! E:\Cartes de visite.lnk
Présent! E:\Autorun.inf.lnk
Présent! E:\Microsoft Security Essential Win7 10JAN2013.lnk
Présent! C:\Users\Public\e-book-Les 2 Clés universelles pour réussir en affaires.pdf
Présent! C:\Users\ALICE\AppData\Local\Temp\crt1B12.tmp.exe
Présent! C:\Users\ALICE\AppData\Local\Temp\utt7546.tmp.exe
Présent! C:\Users\ALICE\AppData\Local\Temp\424bInstaller.exe
Présent! D:\desktop.ini
Présent! E:\xGyreppr.vbs
################## | Registre |
HKCU\.\.\.\.\Explorer\MountPoints2\E
Shell\AutoRun\Command = E:\.\Setup.exe AUTORUN=1
HKCU\.\.\.\.\Explorer\MountPoints2\F
Shell\AutoRun\Command = F:\LaunchU3.exe
HKCU\.\.\.\.\Explorer\MountPoints2\{c482e3e0-3a59-11e2-bda1-446d57bc47df}
Shell\AutoRun\Command = E:\.\Setup.exe AUTORUN=1
HKCU\.\.\.\.\Explorer\MountPoints2\{d6a9d5cd-5b62-11e2-b679-446d57bc47df}
Shell\AutoRun\Command = E:\.\Setup.exe AUTORUN=1
HKCU\.\.\.\.\Explorer\MountPoints2\{e47eedaf-0f94-11e2-a44a-446d57bc47df}
Shell\AutoRun\Command = F:\LaunchU3.exe
################## | Vaccin |
E:\Autorun.inf -> Vaccin créé par UsbFix (El Desaparecido)
################## | E.O.F |
https://www.usbfix.net -
https://www.sosvirus.net |
Rapport Clean
############################## | UsbFix V 7.145 | [Suppression]
Utilisateur: ALICE (Administrateur) # ALICE-HP
Mis à jour le 17/10/2013 par El Desaparecido - Team SosVirus
Lancé à 16:43:38 | 11/11/2013
Site Web:
https://www.usbfix.net/
Forum :
https://www.sosvirus.net/
Upload Malware:
https://www.sosvirus.net/upload_malware.php
Contact:
https://www.usbfix.net/contact/
PC: Hewlett-Packard (338D)
CPU: Intel(R) Atom(TM) CPU N2600 @ 1.60GHz
RAM -> [Total : 1012 | Free : 106]
Bios: Hewlett-Packard
Boot: Normal boot
OS: Microsoft Windows 7 à‰dition Starter (6.1.7601 32-Bit) # Service Pack 1
WB: Windows Internet Explorer 10.0.9200.16721
SC: Security Center Service [Enabled]
WU: Windows Update Service [Enabled]
AV: Kaspersky Anti-Virus [(!) Disabled | (!) Outdated]
FW: Windows FireWall Service [Enabled]
C:\ (%systemdrive%) -> Disque fixe # 181 Go (89 Go libre(s) - 49%) [] # NTFS
D:\ -> Disque fixe # 19 Go (2 Go libre(s) - 11%) [Recovery] # NTFS
E:\ -> Disque amovible # 7 Go (7 Go libre(s) - 99%) [] # FAT32
################## | Regedit Run |
HKLM\SOFTWARE | Run : [AVP] - "C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 2012\avp.exe"
HKLM\SOFTWARE | RunOnce : [] -
HKU\S-1-5-19\SOFTWARE | Run : [Sidebar] - %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun
HKU\S-1-5-20\SOFTWARE | Run : [Sidebar] - %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun
HKU\S-1-5-21-4258096444-3120789726-3743063335-1000\SOFTWARE | Run : [Google Update] - "C:\Users\ALICE\AppData\Local\Google\Update\GoogleUpdate.exe" /c
HKU\S-1-5-21-4258096444-3120789726-3743063335-1000\SOFTWARE | Run : [uTorrent] - "C:\Users\ALICE\AppData\Roaming\uTorrent\uTorrent.exe" /MINIMIZED
HKU\S-1-5-21-4258096444-3120789726-3743063335-1000\SOFTWARE | Run : [Optimizer Pro] - C:\Program Files\Optimizer Pro\OptProLauncher.exe
HKU\S-1-5-21-4258096444-3120789726-3743063335-1000\SOFTWARE | Run : [se] - C:\Users\user\AppData\Roaming\SkypEmoticons\SE.exe /minimized
HKU\S-1-5-19\SOFTWARE | RunOnce : [mctadmin] - C:\Windows\System32\mctadmin.exe
HKU\S-1-5-20\SOFTWARE | RunOnce : [mctadmin] - C:\Windows\System32\mctadmin.exe
################## | Processus Stoppés |
Stoppé! C:\Program Files\IDT\WDM\STacSV.exe (ID 1184 |ParentID 664)
Stoppé! C:\Windows\system32\WLANExt.exe (ID 1644 |ParentID 1076)
Stoppé! C:\Windows\system32\conhost.exe (ID 1652 |ParentID 528)
Stoppé! C:\Windows\system32\taskeng.exe (ID 1820 |ParentID 1132)
Stoppé! C:\Windows\System32\spoolsv.exe (ID 1840 |ParentID 664)
Stoppé! C:\Program Files\Common Files\Adobe\ARM\1.0\armsvc.exe (ID 128 |ParentID 664)
Stoppé! C:\Program Files\IDT\WDM\aestsrv.exe (ID 428 |ParentID 664)
Stoppé! C:\Program Files\Bluetooth Suite\adminservice.exe (ID 536 |ParentID 664)
Stoppé! C:\Program Files\Hewlett-Packard\HP Client Services\HPClientServices.exe (ID 1416 |ParentID 664)
Stoppé! C:\Program Files\Hewlett-Packard\HP Quick Launch\HPWMISVC.exe (ID 1472 |ParentID 664)
Stoppé! C:\Program Files\InternetEverywhere\InternetEverywhere_Service.exe (ID 1800 |ParentID 664)
Stoppé! C:\Program Files\Microsoft Application Virtualization Client\sftvsa.exe (ID 2380 |ParentID 664)
Stoppé! C:\ProgramData\Skype\Toolbars\Skype C2C Service\c2c_service.exe (ID 2496 |ParentID 664)
Stoppé! C:\Program Files\EazelBar\ToolbarUpdaterService.exe (ID 2616 |ParentID 664)
Stoppé! C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE (ID 2720 |ParentID 664)
Stoppé! C:\Program Files\Yahoo!\SoftwareUpdate\YahooAUService.exe (ID 2780 |ParentID 664)
Stoppé! C:\Program Files\Bluetooth Suite\Ath_CoexAgent.exe (ID 2836 |ParentID 664)
Stoppé! C:\Program Files\Hewlett-Packard\HP Auto\HPAuto.exe (ID 2864 |ParentID 664)
Stoppé! C:\Program Files\Microsoft Application Virtualization Client\sftlist.exe (ID 2924 |ParentID 664)
Stoppé! C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe (ID 2992 |ParentID 2720)
Stoppé! C:\Program Files\Common Files\Microsoft Shared\Virtualization Handler\CVHSVC.EXE (ID 3224 |ParentID 664)
Stoppé! C:\Windows\system32\taskhost.exe (ID 3396 |ParentID 664)
Stoppé! C:\Windows\system32\SearchIndexer.exe (ID 3536 |ParentID 664)
Stoppé! C:\Windows\Explorer.EXE (ID 3596 |ParentID 3480)
Stoppé! c:\programdata\summersoft\optimizerpro\OptimizerPro.exe (ID 3884 |ParentID 1820)
Stoppé! C:\Users\ALICE\AppData\Roaming\uTorrent\uTorrent.exe (ID 2376 |ParentID 3596)
Stoppé! C:\Program Files\Optimizer Pro\OptProReminder.exe (ID 4248 |ParentID 860)
Stoppé! C:\Windows\system32\taskeng.exe (ID 5252 |ParentID 1132)
Stoppé! C:\Program Files\CyberLink\YouCam\YCMMirage.exe (ID 5348 |ParentID 5252)
Stoppé! C:\Program Files\Windows Media Player\wmpnetwk.exe (ID 5356 |ParentID 664)
Stoppé! C:\Windows\system32\DllHost.exe (ID 5740 |ParentID 832)
Stoppé! C:\Users\ALICE\AppData\Local\Google\Chrome\Application\chrome.exe (ID 5872 |ParentID 3596)
Stoppé! C:\Users\ALICE\AppData\Local\Google\Chrome\Application\chrome.exe (ID 4176 |ParentID 5872)
Stoppé! C:\Program Files\Hewlett-Packard\HP Support Framework\hpsa_service.exe (ID 5720 |ParentID 664)
Stoppé! C:\Users\ALICE\AppData\Local\Google\Chrome\Application\chrome.exe (ID 1900 |ParentID 5872)
Stoppé! C:\Program Files\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe (ID 5892 |ParentID 664)
Stoppé! C:\Users\ALICE\AppData\Local\Google\Chrome\Application\chrome.exe (ID 3428 |ParentID 5872)
Stoppé! C:\Windows\system32\wuauclt.exe (ID 1460 |ParentID 1132)
Stoppé! C:\Windows\system32\taskhost.exe (ID 4652 |ParentID 664)
Stoppé! C:\Program Files\Microsoft\BingBar\7.2.241.0\SeaPort.exe (ID 3104 |ParentID 664)
Stoppé! C:\Users\ALICE\AppData\Local\Google\Chrome\Application\chrome.exe (ID 3712 |ParentID 5872)
Stoppé! C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe (ID 7904 |ParentID 7864)
Stoppé! C:\Program Files\Common Files\microsoft shared\Virtualization Handler\CVH.EXE (ID 6656 |ParentID 3596)
Stoppé! C:\Program Files\Common Files\microsoft shared\virtualization handler\OfficeVirt.exe (ID 6224 |ParentID 6656)
Stoppé! C:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPSVC.EXE (ID 6216 |ParentID 664)
Stoppé! C:\Windows\system32\igfxsrvc.exe (ID 5824 |ParentID 832)
Stoppé! C:\Program Files\Internet Explorer\iexplore.exe (ID 5692 |ParentID 3596)
Stoppé! C:\Program Files\Internet Explorer\iexplore.exe (ID 3732 |ParentID 5692)
Stoppé! C:\Program Files\Internet Explorer\iexplore.exe (ID 6332 |ParentID 3596)
Stoppé! C:\Program Files\Internet Explorer\iexplore.exe (ID 6908 |ParentID 6332)
Stoppé! C:\Windows\system32\Macromed\Flash\FlashUtil32_11_2_202_235_ActiveX.exe (ID 7540 |ParentID 832)
Stoppé! C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 2012\klwtblfs.exe (ID 5100 |ParentID 832)
Stoppé! C:\Program Files\Yahoo!\Companion\Installs\cpn1\ytbb.exe (ID 7348 |ParentID 832)
Stoppé! C:\Windows\System32\WUDFHost.exe (ID 1864 |ParentID 1076)
################## | à‰léments infectieux |
Supprimé! E:\mseinstall.lnk
Supprimé! E:\Logiciels de départ.lnk
Supprimé! E:\Cartes de visite.lnk
Supprimé! E:\Autorun.inf.lnk
Supprimé! E:\Microsoft Security Essential Win7 10JAN2013.lnk
Supprimé! C:\Users\Public\e-book-Les 2 Clés universelles pour réussir en affaires.pdf
Supprimé! C:\Users\ALICE\AppData\Local\Temp\crt1B12.tmp.exe
Supprimé! C:\Users\ALICE\AppData\Local\Temp\utt7546.tmp.exe
Supprimé! C:\Users\ALICE\AppData\Local\Temp\424bInstaller.exe
Supprimé! D:\desktop.ini
Supprimé! E:\xGyreppr.vbs
(!) Fichiers temporaires supprimés.
################## | Registre |
Supprimé! HKCU\.\.\.\.\Explorer\MountPoints2\E
Supprimé! HKCU\.\.\.\.\Explorer\MountPoints2\{c482e3e0-3a59-11e2-bda1-446d57bc47df}
Supprimé! HKCU\.\.\.\.\Explorer\MountPoints2\{d6a9d5cd-5b62-11e2-b679-446d57bc47df}
Supprimé! HKCU\.\.\.\.\Explorer\MountPoints2\{e47eedaf-0f94-11e2-a44a-446d57bc47df}
################## | Listing |
[02/10/2012 - 15:49:04 | SHD ] C:\$Recycle.Bin
[11/10/2013 - 21:54:36 | D ] C:\54fe9af93902b1f85da6ef816a
[04/10/2012 - 12:49:51 | D ] C:\6782dee86a706c66d4b5f4adb4d977d8
[10/06/2009 - 22:42:20 | N | 24] C:\autoexec.bat
[19/01/2012 - 23:19:44 | SHD ] C:\boot
[20/11/2010 - 22:29:06 | RASH | 383786] C:\bootmgr
[12/10/2013 - 03:30:16 | D ] C:\Config.Msi
[10/06/2009 - 22:42:20 | N | 10] C:\config.sys
[14/07/2009 - 05:53:55 | SHD ] C:\Documents and Settings
[02/10/2012 - 15:18:56 | D ] C:\Dokumente und Einstellungen
[22/06/2013 - 03:56:02 | D ] C:\E
[10/11/2013 - 08:36:12 | ASH | 796102656] C:\hiberfil.sys
[01/05/2012 - 02:13:42 | D ] C:\HP
[01/05/2012 - 01:51:01 | D ] C:\Intel
[03/10/2012 - 14:58:54 | RHD ] C:\MSOCache
[10/11/2013 - 10:17:00 | ASH | 1550958592] C:\pagefile.sys
[14/07/2009 - 03:37:05 | D ] C:\PerfLogs
[13/10/2013 - 17:48:02 | D ] C:\Program Files
[13/10/2013 - 08:01:41 | HD ] C:\ProgramData
[02/10/2012 - 15:18:56 | D ] C:\Programme
[02/10/2012 - 15:21:08 | SHD ] C:\Recovery
[21/06/2013 - 10:54:17 | D ] C:\SWSetup
[07/11/2013 - 03:00:50 | SHD ] C:\System Volume Information
[02/10/2012 - 15:21:16 | D ] C:\SYSTEM.SAV
[11/11/2013 - 16:51:18 | D ] C:\UsbFix
[11/11/2013 - 16:56:44 | A | 9152] C:\UsbFix [Clean 1] ALICE-HP.txt
[11/11/2013 - 16:36:55 | N | 9156] C:\UsbFix [Scan 2] ALICE-HP.txt
[02/10/2012 - 15:19:08 | RD ] C:\Users
[28/09/2013 - 03:06:27 | D ] C:\Windows
[02/10/2012 - 15:49:04 | SHD ] D:\$RECYCLE.BIN
[02/10/2012 - 15:48:51 | RASHD ] D:\boot
[14/07/2009 - 19:39:00 | RASH | 383562] D:\bootmgr
[02/10/2012 - 15:48:52 | D ] D:\FactoryUpdate
[02/10/2012 - 15:48:51 | D ] D:\hp
[04/10/2012 - 15:33:45 | N | 20] D:\HPSF_Rep.txt
[02/10/2012 - 15:30:31 | N | 8] D:\HP_WSD.dat
[02/10/2012 - 15:48:51 | RSHD ] D:\preload
[02/10/2012 - 15:48:51 | RSD ] D:\recovery
[02/10/2012 - 15:48:51 | D ] D:\RM_Reserve
[05/12/2012 - 11:08:40 | SHD ] D:\System Volume Information
[21/10/2013 - 17:02:50 | D ] E:\Logiciels de départ
[22/10/2013 - 15:26:52 | D ] E:\Cartes de visite
[29/10/2013 - 15:21:42 | SHD ] E:\Autorun.inf
[10/01/2013 - 10:10:18 | D ] E:\Microsoft Security Essential Win7 10JAN2013
[08/11/2013 - 14:40:52 | N | 13834936] E:\mseinstall.exe
################## | Vaccin |
C:\Autorun.inf -> Vaccin créé par UsbFix (El Desaparecido)
D:\Autorun.inf -> Vaccin créé par UsbFix (El Desaparecido)
E:\Autorun.inf -> Vaccin créé par UsbFix (El Desaparecido)
################## | E.O.F |
https://www.usbfix.net -
https://www.sosvirus.net |