- mer. 20 nov. 2013 10:46
#17870
Bonjour tout le monde,
Enfin, je trouve un forum qui a l'air correct!
J'ai un soucis avec mes 2 clés usb...(à cause des pc de l'école grrr) Toutes les 2 ne me mettent plus que des fichiers en raccourcis...et certains fichiers ont eu du mal à partir, j'ai fait un formatage des clés..
Une des deux a un virus qui s'appelle Sergelelama..
J'ai cherché une solution sur d'autres forum et j'ai téléchargé usbfix...J'ai fait la recherche et la suppression.Je vois que beaucoup ont collé ce rapport donc le voici:
############################## | UsbFix V 7.150 | [Suppression]
Utilisateur: valou08 (Administrateur) # VAIO
Mis à jour le 08/11/2013 par El Desaparecido - Team SosVirus
Lancé à 10:15:19 | 20/11/2013
Site Web : https://www.usbfix.net
Forum : https://www.sosvirus.net/
Upload Malware : https://www.sosvirus.net/upload_malware.php
Contact : https://www.usbfix.net/contact/
PC: Sony Corporation (VAIO)
CPU: Intel(R) Pentium(R) CPU B980 @ 2.40GHz
RAM -> [Total : 4043 | Free : 2580]
Bios: Insyde Corp.
Boot: Normal boot
OS: Microsoft Windows 8 (6.2.9200 64-Bit)
WB: Windows Internet Explorer : 10.0.9200.16721
WB: Google Chrome : 31.0.1650.57
WB: Mozilla Firefox : 25.0.1
SC: Security Center Service [(!) Disabled]
WU: Windows Update Service [(!) Disabled]
AV: Protection antivirus et antispyware McAfee [(!) Disabled | Updated]
AS: Windows Defender : 4.3.0215.0
FW: Windows FireWall Service [(!) Disabled]
C:\ (%systemdrive%) -> Disque fixe # 434 Go (245 Go libre(s) - 56%) [] # NTFS
D:\ -> CD-ROM
E:\ -> Disque amovible # 15 Go (13 Go libre(s) - 90%) [INTENSO] # FAT32
F:\ -> CD-ROM
G:\ -> Disque amovible # 983 Mo (912 Mo libre(s) - 93%) [HYBRID] # FAT
################## | Processus Stoppés |
Stoppé! C:\Program Files\AVAST Software\Avast\AvastSvc.exe (ID: 1376 |ParentID: 928)
Stoppé! C:\Program Files\AVAST Software\Avast\AvastUI.exe (ID: 5080 |ParentID: 3044)
Stoppé! C:\Program Files\Intel\iCLS Client\HeciServer.exe (ID: 5908 |ParentID: 928)
Stoppé! C:\Windows\explorer.exe (ID: 6172 |ParentID: 5444)
Stoppé! C:\Windows\System32\WUDFHost.exe (ID: 908 |ParentID: 1064)
Stoppé! C:\Windows\system32\DllHost.exe (ID: 6408 |ParentID: 280)
Stoppé! C:\Program Files (x86)\Sony\VAIO Control Center\VESMgr.exe (ID: 4812 |ParentID: 928)
Stoppé! C:\Windows\system32\SearchIndexer.exe (ID: 1752 |ParentID: 928)
Stoppé! C:\Program Files (x86)\Sony\VAIO Control Center\VESMgrSub.exe (ID: 3820 |ParentID: 4812)
Stoppé! C:\Program Files (x86)\Sony\VAIO Control Center\VESMgrSub.exe (ID: 4668 |ParentID: 4812)
Stoppé! C:\Windows\SysWOW64\DllHost.exe (ID: 4228 |ParentID: 280)
Stoppé! C:\Windows\System32\spoolsv.exe (ID: 4556 |ParentID: 928)
Stoppé! C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe (ID: 5216 |ParentID: 928)
Stoppé! C:\Program Files\Windows Media Player\wmpnetwk.exe (ID: 6332 |ParentID: 928)
Stoppé! C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe (ID: 3568 |ParentID: 928)
Stoppé! C:\Program Files (x86)\Realtek\Realtek PCIE Card Reader\RIconMan.exe (ID: 3724 |ParentID: 928)
Stoppé! C:\Windows\System32\vds.exe (ID: 4988 |ParentID: 928)
Stoppé! C:\Windows\system32\dashost.exe (ID: 2156 |ParentID: 1064)
Stoppé! C:\Program Files (x86)\Mozilla Firefox\firefox.exe (ID: 2880 |ParentID: 6172)
Stoppé! C:\Program Files (x86)\Mozilla Firefox\plugin-container.exe (ID: 828 |ParentID: 2880)
Stoppé! C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerPlugin_11_9_900_117.exe (ID: 1656 |ParentID: 828)
Stoppé! C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerPlugin_11_9_900_117.exe (ID: 4828 |ParentID: 1656)
Stoppé! C:\Program Files\Internet Explorer\iexplore.exe (ID: 6432 |ParentID: 6804)
Stoppé! C:\Program Files (x86)\Internet Explorer\IEXPLORE.EXE (ID: 2392 |ParentID: 6432)
Stoppé! C:\Windows\system32\SearchProtocolHost.exe (ID: 4028 |ParentID: 1752)
Stoppé! C:\Windows\system32\SearchFilterHost.exe (ID: 2192 |ParentID: 1752)
################## | Regedit Run |
04 - HKLM\SOFTWARE | Run : [StartCCC] - "C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" MSRun
04 - HKLM\SOFTWARE | Run : [ISBMgr.exe] - "C:\Program Files (x86)\Sony\ISB Utility\ISBMgr.exe"
04 - HKLM\SOFTWARE | Run : [PMBVolumeWatcher] - C:\Program Files (x86)\Sony\PlayMemories Home\PMBVolumeWatcher.exe
04 - HKLM\SOFTWARE | Run : [Adobe Reader Speed Launcher] - "c:\Program Files (x86)\Adobe\Reader 10.0\Reader\Reader_sl.exe"
04 - HKLM\SOFTWARE | Run : [Adobe ARM] - "c:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
04 - HKLM\SOFTWARE | Run : [Intel AppUp(SM) center] - "C:\Program Files (x86)\Intel\IntelAppStore\bin\ismagent.exe" --domain-id F0399437-FD0C-4A48-B101-F0314A6172E4
04 - HKLM\SOFTWARE | Run : [GrooveMonitor] - "C:\Program Files (x86)\Microsoft Office\Office12\GrooveMonitor.exe"
04 - HKLM\SOFTWARE | Run : [HP Software Update] - C:\Program Files (x86)\HP\HP Software Update\HPWuSchd2.exe
04 - HKLM\SOFTWARE | Run : [APSDaemon] - "C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe"
04 - HKLM\SOFTWARE | Run : [beid] - "C:\Program Files (x86)\Belgium Identity Card\beid35gui.exe" /startup
04 - HKLM\SOFTWARE | Run : [QuickTime Task] - "C:\Program Files (x86)\QuickTime\QTTask.exe" -atboottime
04 - HKLM\SOFTWARE | Run : [iTunesHelper] - "C:\Program Files (x86)\iTunes\iTunesHelper.exe"
04 - HKLM\SOFTWARE | Run : [AvastUI.exe] - "C:\Program Files\AVAST Software\Avast\AvastUI.exe" /nogui
04 - HKLM\SOFTWARE\wow6432Node | Run : [StartCCC] - "C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" MSRun
04 - HKLM\SOFTWARE\wow6432Node | Run : [ISBMgr.exe] - "C:\Program Files (x86)\Sony\ISB Utility\ISBMgr.exe"
04 - HKLM\SOFTWARE\wow6432Node | Run : [PMBVolumeWatcher] - C:\Program Files (x86)\Sony\PlayMemories Home\PMBVolumeWatcher.exe
04 - HKLM\SOFTWARE\wow6432Node | Run : [Adobe Reader Speed Launcher] - "c:\Program Files (x86)\Adobe\Reader 10.0\Reader\Reader_sl.exe"
04 - HKLM\SOFTWARE\wow6432Node | Run : [Adobe ARM] - "c:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
04 - HKLM\SOFTWARE\wow6432Node | Run : [Intel AppUp(SM) center] - "C:\Program Files (x86)\Intel\IntelAppStore\bin\ismagent.exe" --domain-id F0399437-FD0C-4A48-B101-F0314A6172E4
04 - HKLM\SOFTWARE\wow6432Node | Run : [GrooveMonitor] - "C:\Program Files (x86)\Microsoft Office\Office12\GrooveMonitor.exe"
04 - HKLM\SOFTWARE\wow6432Node | Run : [HP Software Update] - C:\Program Files (x86)\HP\HP Software Update\HPWuSchd2.exe
04 - HKLM\SOFTWARE\wow6432Node | Run : [APSDaemon] - "C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe"
04 - HKLM\SOFTWARE\wow6432Node | Run : [beid] - "C:\Program Files (x86)\Belgium Identity Card\beid35gui.exe" /startup
04 - HKLM\SOFTWARE\wow6432Node | Run : [QuickTime Task] - "C:\Program Files (x86)\QuickTime\QTTask.exe" -atboottime
04 - HKLM\SOFTWARE\wow6432Node | Run : [iTunesHelper] - "C:\Program Files (x86)\iTunes\iTunesHelper.exe"
04 - HKLM\SOFTWARE\wow6432Node | Run : [AvastUI.exe] - "C:\Program Files\AVAST Software\Avast\AvastUI.exe" /nogui
04 - HKLM\SOFTWARE | RunOnce : [] -
04 - HKLM\SOFTWARE\wow6432Node | RunOnce : [] -
04 - HKU\S-1-5-21-3336193131-428724718-2682413929-1001\SOFTWARE | Run : [Skype] - "C:\Program Files (x86)\Skype\Phone\Skype.exe" /minimized /regrun
04 - HKU\S-1-5-21-3336193131-428724718-2682413929-1001\SOFTWARE | Run : [A7KGEquN] - wscript.exe //B "C:\Users\valou08\AppData\Local\Temp\A7KGEquN.vbs"
04 - HKU\S-1-5-21-3336193131-428724718-2682413929-1001\SOFTWARE | Run : [SergeLeLama] - wscript.exe //B "C:\Users\valou08\AppData\Local\Temp\SergeLeLama.vbs"
04 - HKU\S-1-5-21-3336193131-428724718-2682413929-1001\SOFTWARE | Run : [DownBook] - "C:\Users\valou08\AppData\Local\DownBook\DownBook.exe" f2907eca64d68105e9316a76d526706b 12
04 - HKU\S-1-5-21-3336193131-428724718-2682413929-1001\SOFTWARE | Run : [Google Update] -
04 - HKU\S-1-5-21-3336193131-428724718-2682413929-1001\SOFTWARE | Run : [sqlserver7] - C:\Users\Public\sqlsrvr.exe
################## | Recherche générique |
Supprimé! C:\Users\valou08\AppData\Roaming\SergeLeLama.vbs
Supprimé! C:\Users\valou08\AppData\Roaming\86B40CD0\ak.tmp
Supprimé! C:\Users\valou08\AppData\Roaming\86B40CD0
Supprimé! C:\Users\valou08\AppData\Local\Temp\SergeLeLama.vbs
Supprimé! C:\Users\valou08\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\SergeLeLama.vbs
Supprimé! E:\SergeLeLama.vbs
Supprimé! G:\SergeLeLama.vbs
Supprimé! E:\Supernatural.lnk
Supprimé! G:\motivation-arbsa.lnk
Supprimé! C:\Users\valou08\AppData\Local\Temp\valou087
Supprimé! C:\Users\valou08\AppData\Local\Temp\valou088
Supprimé! C:\Users\valou08\AppData\Local\Temp\201.pif
Supprimé! C:\Users\valou08\AppData\Local\Temp\204.pif
Supprimé! C:\Users\valou08\AppData\Local\Temp\41fsd.hta
Supprimé! C:\Users\valou08\AppData\Local\Temp\B2Y.hta
Supprimé! C:\Users\valou08\AppData\Local\Temp\25535-667776-mozilla-firefox.exe
Non supprimé ! F:\autorun.inf
(!) Fichiers temporaires supprimés.
################## | Référence de comparaison MD5 |
Md5 : 304439A2E8278F31E4E42DD145C65B48 -> C:\Users\valou08\AppData\Roaming\SergeLeLama.vbs
Md5 : 304439A2E8278F31E4E42DD145C65B48 -> C:\Users\valou08\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\SergeLeLama.vbs
Md5 : 304439A2E8278F31E4E42DD145C65B48 -> C:\Users\valou08\AppData\Local\Temp\SergeLeLama.vbs
Md5 : 304439A2E8278F31E4E42DD145C65B48 -> E:\SergeLeLama.vbs
Md5 : 304439A2E8278F31E4E42DD145C65B48 -> G:\SergeLeLama.vbs
################## | Comparaison MD5 |
################## | Registre |
Supprimé! HKU\S-1-5-21-3336193131-428724718-2682413929-1001\Software\Microsoft\Windows\CurrentVersion\Run|SergeLeLama
Supprimé! HKU\S-1-5-21-3336193131-428724718-2682413929-1001\Software\.\.\.\.\Mountpoints2\{5dfb6e6d-3981-11e2-be73-083e8eba6662}
Supprimé! HKU\S-1-5-21-3336193131-428724718-2682413929-1001\Software\.\.\.\.\Mountpoints2\{ada2fe8e-b8df-11e2-be88-083e8eba6662}
################## | Listing |
[28/11/2012 - 18:47:22 | SHD ] C:\$Recycle.Bin
[17/11/2013 - 13:09:05 | D ] C:\AdwCleaner
[26/07/2012 - 04:44:30 | RASH | 398156] C:\bootmgr
[02/06/2012 - 15:30:55 | N | 1] C:\BOOTNXT
[23/03/2013 - 12:14:31 | D ] C:\Documentation
[26/07/2012 - 08:22:08 | SHD ] C:\Documents and Settings
[08/08/2013 - 11:13:21 | D ] C:\Downloads
[20/03/2013 - 12:44:39 | D ] C:\drivers
[22/09/2012 - 19:46:32 | N | 123580] C:\firecore.log
[17/01/2013 - 22:12:40 | D ] C:\found.000
[11/04/2013 - 20:21:09 | D ] C:\found.001
[09/05/2013 - 20:33:50 | D ] C:\found.002
[17/11/2013 - 18:20:26 | ASH | 3391741952] C:\hiberfil.sys
[22/09/2012 - 19:03:38 | D ] C:\Intel
[02/12/2012 - 11:16:03 | RHD ] C:\MSOCache
[17/11/2013 - 20:43:57 | ASH | 1811939328] C:\pagefile.sys
[26/07/2012 - 08:33:46 | D ] C:\PerfLogs
[17/11/2013 - 18:16:01 | D ] C:\Program Files
[17/11/2013 - 18:55:42 | D ] C:\Program Files (x86)
[20/11/2013 - 09:32:58 | HD ] C:\ProgramData
[22/09/2012 - 19:08:40 | N | 2227] C:\RHDSetup.log
[22/09/2012 - 18:58:48 | D ] C:\sources
[17/11/2013 - 20:43:58 | ASH | 268435456] C:\swapfile.sys
[17/11/2013 - 18:13:05 | SHD ] C:\System Volume Information
[17/10/2013 - 20:03:13 | D ] C:\Update
[20/11/2013 - 10:22:39 | D ] C:\UsbFix
[20/11/2013 - 10:22:51 | A | 10854] C:\UsbFix [Clean 2] VAIO.txt
[20/11/2013 - 09:20:34 | N | 14450] C:\UsbFix [Scan 1] VAIO.txt
[20/11/2013 - 09:49:28 | N | 10988] C:\UsbFix [Scan 2] VAIO.txt
[28/11/2012 - 18:42:55 | RD ] C:\Users
[17/11/2013 - 18:13:47 | D ] C:\Windows
[17/11/2013 - 10:11:50 | N | 365252624] E:\Supernatural.S08E15.FRENCH.DVDRIP.XviD-ArRoWs.zone-telechargement.com.avi
[16/11/2013 - 16:51:58 | N | 365039632] E:\Supernatural.S08E12.FRENCH.DVDRIP.XviD-ArRoWs.zone-telechargement.com.avi
[16/11/2013 - 18:25:46 | N | 365217808] E:\Supernatural.S08E13.FRENCH.DVDRIP.XviD-ArRoWs.zone-telechargement.com.avi
[16/11/2013 - 19:40:16 | N | 364875792] E:\Supernatural.S08E14.FRENCH.DVDRIP.XviD-ArRoWs.zone-telechargement.com.avi
[12/02/2007 - 20:53:42 | R | 277] F:\autorun.inf
[13/02/2007 - 02:33:37 | R | 1110016] F:\LaunchU3.exe
[13/02/2007 - 03:23:09 | R | 4558081] F:\LaunchPad.zip
[25/10/2012 - 08:11:34 | N | 30720] G:\motivation-arbsa.doc
################## | Vaccin |
E:\Autorun.inf -> Vaccin créé par UsbFix (El Desaparecido)
G:\Autorun.inf -> Vaccin créé par UsbFix (El Desaparecido)
################## | E.O.F | https://www.usbfix.net - https://www.sosvirus.net |
Pouvez-vous me dire ce qu'il y a lieu de faire? Mon pc est-il infecté? Pourrais-je encore utiliser mes clés usb?

Enfin, je trouve un forum qui a l'air correct!
J'ai un soucis avec mes 2 clés usb...(à cause des pc de l'école grrr) Toutes les 2 ne me mettent plus que des fichiers en raccourcis...et certains fichiers ont eu du mal à partir, j'ai fait un formatage des clés..
Une des deux a un virus qui s'appelle Sergelelama..
J'ai cherché une solution sur d'autres forum et j'ai téléchargé usbfix...J'ai fait la recherche et la suppression.Je vois que beaucoup ont collé ce rapport donc le voici:
############################## | UsbFix V 7.150 | [Suppression]
Utilisateur: valou08 (Administrateur) # VAIO
Mis à jour le 08/11/2013 par El Desaparecido - Team SosVirus
Lancé à 10:15:19 | 20/11/2013
Site Web : https://www.usbfix.net
Forum : https://www.sosvirus.net/
Upload Malware : https://www.sosvirus.net/upload_malware.php
Contact : https://www.usbfix.net/contact/
PC: Sony Corporation (VAIO)
CPU: Intel(R) Pentium(R) CPU B980 @ 2.40GHz
RAM -> [Total : 4043 | Free : 2580]
Bios: Insyde Corp.
Boot: Normal boot
OS: Microsoft Windows 8 (6.2.9200 64-Bit)
WB: Windows Internet Explorer : 10.0.9200.16721
WB: Google Chrome : 31.0.1650.57
WB: Mozilla Firefox : 25.0.1
SC: Security Center Service [(!) Disabled]
WU: Windows Update Service [(!) Disabled]
AV: Protection antivirus et antispyware McAfee [(!) Disabled | Updated]
AS: Windows Defender : 4.3.0215.0
FW: Windows FireWall Service [(!) Disabled]
C:\ (%systemdrive%) -> Disque fixe # 434 Go (245 Go libre(s) - 56%) [] # NTFS
D:\ -> CD-ROM
E:\ -> Disque amovible # 15 Go (13 Go libre(s) - 90%) [INTENSO] # FAT32
F:\ -> CD-ROM
G:\ -> Disque amovible # 983 Mo (912 Mo libre(s) - 93%) [HYBRID] # FAT
################## | Processus Stoppés |
Stoppé! C:\Program Files\AVAST Software\Avast\AvastSvc.exe (ID: 1376 |ParentID: 928)
Stoppé! C:\Program Files\AVAST Software\Avast\AvastUI.exe (ID: 5080 |ParentID: 3044)
Stoppé! C:\Program Files\Intel\iCLS Client\HeciServer.exe (ID: 5908 |ParentID: 928)
Stoppé! C:\Windows\explorer.exe (ID: 6172 |ParentID: 5444)
Stoppé! C:\Windows\System32\WUDFHost.exe (ID: 908 |ParentID: 1064)
Stoppé! C:\Windows\system32\DllHost.exe (ID: 6408 |ParentID: 280)
Stoppé! C:\Program Files (x86)\Sony\VAIO Control Center\VESMgr.exe (ID: 4812 |ParentID: 928)
Stoppé! C:\Windows\system32\SearchIndexer.exe (ID: 1752 |ParentID: 928)
Stoppé! C:\Program Files (x86)\Sony\VAIO Control Center\VESMgrSub.exe (ID: 3820 |ParentID: 4812)
Stoppé! C:\Program Files (x86)\Sony\VAIO Control Center\VESMgrSub.exe (ID: 4668 |ParentID: 4812)
Stoppé! C:\Windows\SysWOW64\DllHost.exe (ID: 4228 |ParentID: 280)
Stoppé! C:\Windows\System32\spoolsv.exe (ID: 4556 |ParentID: 928)
Stoppé! C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe (ID: 5216 |ParentID: 928)
Stoppé! C:\Program Files\Windows Media Player\wmpnetwk.exe (ID: 6332 |ParentID: 928)
Stoppé! C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe (ID: 3568 |ParentID: 928)
Stoppé! C:\Program Files (x86)\Realtek\Realtek PCIE Card Reader\RIconMan.exe (ID: 3724 |ParentID: 928)
Stoppé! C:\Windows\System32\vds.exe (ID: 4988 |ParentID: 928)
Stoppé! C:\Windows\system32\dashost.exe (ID: 2156 |ParentID: 1064)
Stoppé! C:\Program Files (x86)\Mozilla Firefox\firefox.exe (ID: 2880 |ParentID: 6172)
Stoppé! C:\Program Files (x86)\Mozilla Firefox\plugin-container.exe (ID: 828 |ParentID: 2880)
Stoppé! C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerPlugin_11_9_900_117.exe (ID: 1656 |ParentID: 828)
Stoppé! C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerPlugin_11_9_900_117.exe (ID: 4828 |ParentID: 1656)
Stoppé! C:\Program Files\Internet Explorer\iexplore.exe (ID: 6432 |ParentID: 6804)
Stoppé! C:\Program Files (x86)\Internet Explorer\IEXPLORE.EXE (ID: 2392 |ParentID: 6432)
Stoppé! C:\Windows\system32\SearchProtocolHost.exe (ID: 4028 |ParentID: 1752)
Stoppé! C:\Windows\system32\SearchFilterHost.exe (ID: 2192 |ParentID: 1752)
################## | Regedit Run |
04 - HKLM\SOFTWARE | Run : [StartCCC] - "C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" MSRun
04 - HKLM\SOFTWARE | Run : [ISBMgr.exe] - "C:\Program Files (x86)\Sony\ISB Utility\ISBMgr.exe"
04 - HKLM\SOFTWARE | Run : [PMBVolumeWatcher] - C:\Program Files (x86)\Sony\PlayMemories Home\PMBVolumeWatcher.exe
04 - HKLM\SOFTWARE | Run : [Adobe Reader Speed Launcher] - "c:\Program Files (x86)\Adobe\Reader 10.0\Reader\Reader_sl.exe"
04 - HKLM\SOFTWARE | Run : [Adobe ARM] - "c:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
04 - HKLM\SOFTWARE | Run : [Intel AppUp(SM) center] - "C:\Program Files (x86)\Intel\IntelAppStore\bin\ismagent.exe" --domain-id F0399437-FD0C-4A48-B101-F0314A6172E4
04 - HKLM\SOFTWARE | Run : [GrooveMonitor] - "C:\Program Files (x86)\Microsoft Office\Office12\GrooveMonitor.exe"
04 - HKLM\SOFTWARE | Run : [HP Software Update] - C:\Program Files (x86)\HP\HP Software Update\HPWuSchd2.exe
04 - HKLM\SOFTWARE | Run : [APSDaemon] - "C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe"
04 - HKLM\SOFTWARE | Run : [beid] - "C:\Program Files (x86)\Belgium Identity Card\beid35gui.exe" /startup
04 - HKLM\SOFTWARE | Run : [QuickTime Task] - "C:\Program Files (x86)\QuickTime\QTTask.exe" -atboottime
04 - HKLM\SOFTWARE | Run : [iTunesHelper] - "C:\Program Files (x86)\iTunes\iTunesHelper.exe"
04 - HKLM\SOFTWARE | Run : [AvastUI.exe] - "C:\Program Files\AVAST Software\Avast\AvastUI.exe" /nogui
04 - HKLM\SOFTWARE\wow6432Node | Run : [StartCCC] - "C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" MSRun
04 - HKLM\SOFTWARE\wow6432Node | Run : [ISBMgr.exe] - "C:\Program Files (x86)\Sony\ISB Utility\ISBMgr.exe"
04 - HKLM\SOFTWARE\wow6432Node | Run : [PMBVolumeWatcher] - C:\Program Files (x86)\Sony\PlayMemories Home\PMBVolumeWatcher.exe
04 - HKLM\SOFTWARE\wow6432Node | Run : [Adobe Reader Speed Launcher] - "c:\Program Files (x86)\Adobe\Reader 10.0\Reader\Reader_sl.exe"
04 - HKLM\SOFTWARE\wow6432Node | Run : [Adobe ARM] - "c:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
04 - HKLM\SOFTWARE\wow6432Node | Run : [Intel AppUp(SM) center] - "C:\Program Files (x86)\Intel\IntelAppStore\bin\ismagent.exe" --domain-id F0399437-FD0C-4A48-B101-F0314A6172E4
04 - HKLM\SOFTWARE\wow6432Node | Run : [GrooveMonitor] - "C:\Program Files (x86)\Microsoft Office\Office12\GrooveMonitor.exe"
04 - HKLM\SOFTWARE\wow6432Node | Run : [HP Software Update] - C:\Program Files (x86)\HP\HP Software Update\HPWuSchd2.exe
04 - HKLM\SOFTWARE\wow6432Node | Run : [APSDaemon] - "C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe"
04 - HKLM\SOFTWARE\wow6432Node | Run : [beid] - "C:\Program Files (x86)\Belgium Identity Card\beid35gui.exe" /startup
04 - HKLM\SOFTWARE\wow6432Node | Run : [QuickTime Task] - "C:\Program Files (x86)\QuickTime\QTTask.exe" -atboottime
04 - HKLM\SOFTWARE\wow6432Node | Run : [iTunesHelper] - "C:\Program Files (x86)\iTunes\iTunesHelper.exe"
04 - HKLM\SOFTWARE\wow6432Node | Run : [AvastUI.exe] - "C:\Program Files\AVAST Software\Avast\AvastUI.exe" /nogui
04 - HKLM\SOFTWARE | RunOnce : [] -
04 - HKLM\SOFTWARE\wow6432Node | RunOnce : [] -
04 - HKU\S-1-5-21-3336193131-428724718-2682413929-1001\SOFTWARE | Run : [Skype] - "C:\Program Files (x86)\Skype\Phone\Skype.exe" /minimized /regrun
04 - HKU\S-1-5-21-3336193131-428724718-2682413929-1001\SOFTWARE | Run : [A7KGEquN] - wscript.exe //B "C:\Users\valou08\AppData\Local\Temp\A7KGEquN.vbs"
04 - HKU\S-1-5-21-3336193131-428724718-2682413929-1001\SOFTWARE | Run : [SergeLeLama] - wscript.exe //B "C:\Users\valou08\AppData\Local\Temp\SergeLeLama.vbs"
04 - HKU\S-1-5-21-3336193131-428724718-2682413929-1001\SOFTWARE | Run : [DownBook] - "C:\Users\valou08\AppData\Local\DownBook\DownBook.exe" f2907eca64d68105e9316a76d526706b 12
04 - HKU\S-1-5-21-3336193131-428724718-2682413929-1001\SOFTWARE | Run : [Google Update] -
04 - HKU\S-1-5-21-3336193131-428724718-2682413929-1001\SOFTWARE | Run : [sqlserver7] - C:\Users\Public\sqlsrvr.exe
################## | Recherche générique |
Supprimé! C:\Users\valou08\AppData\Roaming\SergeLeLama.vbs
Supprimé! C:\Users\valou08\AppData\Roaming\86B40CD0\ak.tmp
Supprimé! C:\Users\valou08\AppData\Roaming\86B40CD0
Supprimé! C:\Users\valou08\AppData\Local\Temp\SergeLeLama.vbs
Supprimé! C:\Users\valou08\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\SergeLeLama.vbs
Supprimé! E:\SergeLeLama.vbs
Supprimé! G:\SergeLeLama.vbs
Supprimé! E:\Supernatural.lnk
Supprimé! G:\motivation-arbsa.lnk
Supprimé! C:\Users\valou08\AppData\Local\Temp\valou087
Supprimé! C:\Users\valou08\AppData\Local\Temp\valou088
Supprimé! C:\Users\valou08\AppData\Local\Temp\201.pif
Supprimé! C:\Users\valou08\AppData\Local\Temp\204.pif
Supprimé! C:\Users\valou08\AppData\Local\Temp\41fsd.hta
Supprimé! C:\Users\valou08\AppData\Local\Temp\B2Y.hta
Supprimé! C:\Users\valou08\AppData\Local\Temp\25535-667776-mozilla-firefox.exe
Non supprimé ! F:\autorun.inf
(!) Fichiers temporaires supprimés.
################## | Référence de comparaison MD5 |
Md5 : 304439A2E8278F31E4E42DD145C65B48 -> C:\Users\valou08\AppData\Roaming\SergeLeLama.vbs
Md5 : 304439A2E8278F31E4E42DD145C65B48 -> C:\Users\valou08\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\SergeLeLama.vbs
Md5 : 304439A2E8278F31E4E42DD145C65B48 -> C:\Users\valou08\AppData\Local\Temp\SergeLeLama.vbs
Md5 : 304439A2E8278F31E4E42DD145C65B48 -> E:\SergeLeLama.vbs
Md5 : 304439A2E8278F31E4E42DD145C65B48 -> G:\SergeLeLama.vbs
################## | Comparaison MD5 |
################## | Registre |
Supprimé! HKU\S-1-5-21-3336193131-428724718-2682413929-1001\Software\Microsoft\Windows\CurrentVersion\Run|SergeLeLama
Supprimé! HKU\S-1-5-21-3336193131-428724718-2682413929-1001\Software\.\.\.\.\Mountpoints2\{5dfb6e6d-3981-11e2-be73-083e8eba6662}
Supprimé! HKU\S-1-5-21-3336193131-428724718-2682413929-1001\Software\.\.\.\.\Mountpoints2\{ada2fe8e-b8df-11e2-be88-083e8eba6662}
################## | Listing |
[28/11/2012 - 18:47:22 | SHD ] C:\$Recycle.Bin
[17/11/2013 - 13:09:05 | D ] C:\AdwCleaner
[26/07/2012 - 04:44:30 | RASH | 398156] C:\bootmgr
[02/06/2012 - 15:30:55 | N | 1] C:\BOOTNXT
[23/03/2013 - 12:14:31 | D ] C:\Documentation
[26/07/2012 - 08:22:08 | SHD ] C:\Documents and Settings
[08/08/2013 - 11:13:21 | D ] C:\Downloads
[20/03/2013 - 12:44:39 | D ] C:\drivers
[22/09/2012 - 19:46:32 | N | 123580] C:\firecore.log
[17/01/2013 - 22:12:40 | D ] C:\found.000
[11/04/2013 - 20:21:09 | D ] C:\found.001
[09/05/2013 - 20:33:50 | D ] C:\found.002
[17/11/2013 - 18:20:26 | ASH | 3391741952] C:\hiberfil.sys
[22/09/2012 - 19:03:38 | D ] C:\Intel
[02/12/2012 - 11:16:03 | RHD ] C:\MSOCache
[17/11/2013 - 20:43:57 | ASH | 1811939328] C:\pagefile.sys
[26/07/2012 - 08:33:46 | D ] C:\PerfLogs
[17/11/2013 - 18:16:01 | D ] C:\Program Files
[17/11/2013 - 18:55:42 | D ] C:\Program Files (x86)
[20/11/2013 - 09:32:58 | HD ] C:\ProgramData
[22/09/2012 - 19:08:40 | N | 2227] C:\RHDSetup.log
[22/09/2012 - 18:58:48 | D ] C:\sources
[17/11/2013 - 20:43:58 | ASH | 268435456] C:\swapfile.sys
[17/11/2013 - 18:13:05 | SHD ] C:\System Volume Information
[17/10/2013 - 20:03:13 | D ] C:\Update
[20/11/2013 - 10:22:39 | D ] C:\UsbFix
[20/11/2013 - 10:22:51 | A | 10854] C:\UsbFix [Clean 2] VAIO.txt
[20/11/2013 - 09:20:34 | N | 14450] C:\UsbFix [Scan 1] VAIO.txt
[20/11/2013 - 09:49:28 | N | 10988] C:\UsbFix [Scan 2] VAIO.txt
[28/11/2012 - 18:42:55 | RD ] C:\Users
[17/11/2013 - 18:13:47 | D ] C:\Windows
[17/11/2013 - 10:11:50 | N | 365252624] E:\Supernatural.S08E15.FRENCH.DVDRIP.XviD-ArRoWs.zone-telechargement.com.avi
[16/11/2013 - 16:51:58 | N | 365039632] E:\Supernatural.S08E12.FRENCH.DVDRIP.XviD-ArRoWs.zone-telechargement.com.avi
[16/11/2013 - 18:25:46 | N | 365217808] E:\Supernatural.S08E13.FRENCH.DVDRIP.XviD-ArRoWs.zone-telechargement.com.avi
[16/11/2013 - 19:40:16 | N | 364875792] E:\Supernatural.S08E14.FRENCH.DVDRIP.XviD-ArRoWs.zone-telechargement.com.avi
[12/02/2007 - 20:53:42 | R | 277] F:\autorun.inf
[13/02/2007 - 02:33:37 | R | 1110016] F:\LaunchU3.exe
[13/02/2007 - 03:23:09 | R | 4558081] F:\LaunchPad.zip
[25/10/2012 - 08:11:34 | N | 30720] G:\motivation-arbsa.doc
################## | Vaccin |
E:\Autorun.inf -> Vaccin créé par UsbFix (El Desaparecido)
G:\Autorun.inf -> Vaccin créé par UsbFix (El Desaparecido)
################## | E.O.F | https://www.usbfix.net - https://www.sosvirus.net |
Pouvez-vous me dire ce qu'il y a lieu de faire? Mon pc est-il infecté? Pourrais-je encore utiliser mes clés usb?
