Bonjour!
Voici le
rapport de Doctor CureIt.
Je passe USBFix
Edit: Est-ce normal qu'après avoir fait suppression puis vaccination, je n'aie pas le fichier autorun.inf sur mes différents supports usb? :hein:
Rapport d'USBFix:
############################## | UsbFix V 7.133 | [Suppression]
Utilisateur: aa (Administrateur) # JASMIN
Mis à jour le 27/08/2013 par El Desaparecido
Lancé à 12:52:56 | 04/09/2013
Site Web:
https://www.sosvirus.net/
Upload Malware:
https://www.sosvirus.net/depannages-informatique/viewtopic.php?f=6&t=489
Contact:
eldesaparecido@sosvirus.net
PC: TOSHIBA (Satellite L300) (X86-based PC)
CPU: Intel(R) Pentium(R) Dual CPU T2370 @ 1.73GHz (1729)
RAM -> [Total : 2037 | Free : 1614]
BIOS: Default System BIOS
BOOT: Fail-safe boot
OS: Microsoft® Windows Vistaâ„¢ à‰dition Familiale Premium (6.0.6002 32-Bit) # Service Pack 2
WB: Windows Internet Explorer 9.0.8112.16421
SC: Security Center Service [Enabled]
WU: Windows Update Service [Enabled]
AV: avast! Antivirus [Enabled | Updated]
FW: Windows FireWall Service [(!) Disabled]
C:\ (%systemdrive%) -> Disque fixe # 56 Go (5 Go libre(s) - 9%) [Vista] # NTFS
D:\ -> Disque fixe # 55 Go (49 Go libre(s) - 89%) [Data] # NTFS
E:\ -> CD-ROM
F:\ -> Disque fixe # 298 Go (181 Go libre(s) - 61%) [MON DISQUE] # FAT32
G:\ -> Disque amovible # 2 Go (63 Mo libre(s) - 3%) [MINI JUNIOR] # FAT32
Z:\ -> Disque amovible # 7 Go (6 Go libre(s) - 80%) [MY ZEN] # FAT32
################## | El Desaparecido Section |
HKLM\SOFTWARE | Run : [Windows Defender] - %ProgramFiles%\Windows Defender\MSASCui.exe -hide
HKLM\SOFTWARE | Run : [IgfxTray] - C:\Windows\system32\igfxtray.exe
HKLM\SOFTWARE | Run : [HotKeysCmds] - C:\Windows\system32\hkcmd.exe
HKLM\SOFTWARE | Run : [Persistence] - C:\Windows\system32\igfxpers.exe
HKLM\SOFTWARE | Run : [RtHDVCpl] - RtHDVCpl.exe
HKLM\SOFTWARE | Run : [SynTPEnh] - C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
HKLM\SOFTWARE | Run : [NDSTray.exe] - NDSTray.exe
HKLM\SOFTWARE | Run : [topi] - C:\Program Files\TOSHIBA\Toshiba Online Product Information\topi.exe -startup
HKLM\SOFTWARE | Run : [Google Desktop Search] - "C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe" /startup
HKLM\SOFTWARE | Run : [Camera Assistant Software] - "C:\Program Files\Camera Assistant Software for Toshiba\traybar.exe" /start
HKLM\SOFTWARE | Run : [TPwrMain] - %ProgramFiles%\TOSHIBA\Power Saver\TPwrMain.EXE
HKLM\SOFTWARE | Run : [SmoothView] - %ProgramFiles%\Toshiba\SmoothView\SmoothView.exe
HKLM\SOFTWARE | Run : [00TCrdMain] - %ProgramFiles%\TOSHIBA\FlashCards\TCrdMain.exe
HKLM\SOFTWARE | Run : [QuickTime Task] - "C:\Program Files\QuickTime\QTTask.exe" -atboottime
HKLM\SOFTWARE | Run : [PlusService] - C:\Program Files\Yuna Software\Messenger Plus!\PlusService.exe
HKLM\SOFTWARE | Run : [avast] - "C:\Program Files\Alwil Software\Avast5\avastUI.exe" /nogui
HKLM\SOFTWARE | Run : [Adobe ARM] - "C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
HKLM\SOFTWARE | Run : [SunJavaUpdateSched] - "C:\Program Files\Java\jre7\bin\jusched.exe"
HKLM\SOFTWARE | Run : [Skytel] - Skytel.exe
HKLM\SOFTWARE | RunOnce : [] -
HKU\S-1-5-19\SOFTWARE | Run : [Sidebar] - %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem
HKU\S-1-5-19\SOFTWARE | Run : [WindowsWelcomeCenter] - rundll32.exe oobefldr.dll,ShowWelcomeCenter
HKU\S-1-5-20\SOFTWARE | Run : [Sidebar] - %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem
HKU\S-1-5-20\SOFTWARE | Run : [WindowsWelcomeCenter] - rundll32.exe oobefldr.dll,ShowWelcomeCenter
HKU\S-1-5-21-1415226798-1588212495-2367356855-1000\SOFTWARE | Run : [TOSCDSPD] - C:\Program Files\TOSHIBA\TOSCDSPD\TOSCDSPD.exe
HKU\S-1-5-21-1415226798-1588212495-2367356855-1000\SOFTWARE | Run : [swg] - "C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe"
HKU\S-1-5-21-1415226798-1588212495-2367356855-1000\SOFTWARE | Run : [ehTray.exe] - C:\Windows\ehome\ehTray.exe
HKU\S-1-5-18\SOFTWARE | Run : [Picasa Media Detector] - C:\Program Files\Picasa2\PicasaMediaDetector.exe
HKU\S-1-5-18\SOFTWARE | Run : [msnmsgr] - "C:\Program Files\Windows Live\Messenger\msnmsgr.exe" /background
################## | Processus Stoppés |
Stoppé! C:\Windows\Explorer.EXE (1072)
################## | à‰léments infectieux |
(!) Fichiers temporaires supprimés.
################## | Registre |
################## | Mountpoints2 |
################## | Listing |
[29/07/2009 - 16:51:28 | SHD ] C:\$RECYCLE.BIN
[13/05/2013 - 23:09:07 | D ] C:\22ba4e4239e907cf1fdc9c
[18/09/2006 - 23:43:36 | N | 24] C:\autoexec.bat
[31/05/2013 - 16:12:40 | RASHD ] C:\Autorun.inf
[01/06/2013 - 18:15:34 | SHD ] C:\Boot
[11/04/2009 - 08:36:36 | RASH | 333257] C:\bootmgr
[25/02/2008 - 11:45:00 | N | 8192] C:\BOOTSECT.BAK
[18/09/2006 - 23:43:37 | N | 10] C:\config.sys
[02/11/2006 - 15:02:03 | SHD ] C:\Documents and Settings
[16/11/2012 - 19:55:16 | N | 5842] C:\Formulaire_Enregistrement_Finale_2010.htm
[16/11/2012 - 20:42:27 | N | 5842] C:\Formulaire_Enregistrement_Finale_2011.htm
[17/04/2012 - 11:05:31 | D ] C:\found.000
[25/02/2008 - 12:15:16 | D ] C:\Intel
[08/12/2008 - 20:37:41 | N | 0] C:\IO.SYS
[08/12/2008 - 20:37:41 | N | 0] C:\MSDOS.SYS
[25/05/2012 - 18:05:58 | RHD ] C:\MSOCache
[04/09/2013 - 12:51:23 | ASH | 2450751488] C:\pagefile.sys
[21/01/2008 - 04:32:31 | D ] C:\PerfLogs
[17/08/2013 - 22:12:37 | N | 512] C:\PhysicalDisk0_MBR.bin
[03/09/2013 - 22:29:03 | D ] C:\Program Files
[23/05/2013 - 00:37:02 | HD ] C:\ProgramData
[16/11/2012 - 19:59:03 | D ] C:\PSFONTS
[25/02/2008 - 12:27:51 | N | 651] C:\RHDSetup.log
[26/02/2008 - 11:10:57 | N | 123] C:\SWSTAMP.TXT
[03/09/2013 - 22:28:22 | SHD ] C:\System Volume Information
[22/08/2008 - 14:30:05 | D ] C:\Toshiba
[04/09/2013 - 12:57:53 | D ] C:\UsbFix
[04/09/2013 - 12:58:18 | A | 5597] C:\UsbFix [Clean 4] JASMIN.txt
[22/08/2008 - 14:09:41 | D ] C:\Users
[03/09/2013 - 18:29:15 | D ] C:\Windows
[26/02/2008 - 10:39:00 | D ] C:\Works
[18/08/2013 - 13:56:17 | D ] C:\ZHP
[03/09/2013 - 14:01:21 | D ] C:\_OTL
[26/02/2008 - 10:18:04 | T | 23120] C:\_wdsuef.dmp
[29/06/2008 - 13:33:46 | SHD ] D:\$RECYCLE.BIN
[02/11/2012 - 09:27:17 | D ] D:\1d3815490040317e1a9ca886d63e
[22/02/2013 - 21:00:42 | D ] D:\1ed18abe2d59b9f3b992cdc1ce83ba
[31/05/2013 - 16:12:40 | RASHD ] D:\Autorun.inf
[29/06/2008 - 19:00:16 | D ] D:\HDDRecovery
[03/12/2008 - 19:25:18 | D ] D:\Mulet
[30/12/2008 - 18:44:47 | D ] D:\Partage
[28/03/2008 - 07:36:35 | N | 11] D:\R08511FR.tag
[07/12/2008 - 16:34:45 | D ] D:\software
[03/09/2013 - 22:28:06 | SHD ] D:\System Volume Information
[15/06/2009 - 11:18:10 | D ] D:\temp
[12/06/2010 - 21:42:38 | D ] F:\Recycled
[14/06/2013 - 14:13:40 | D ] F:\Mes Images - Photos - Videos
[16/06/2010 - 10:35:52 | D ] F:\~~~~
[12/06/2010 - 22:15:52 | D ] F:\Le donjon de Naheulbeuk
[14/06/2013 - 14:13:16 | D ] F:\Ma musique
[12/06/2010 - 22:17:04 | D ] F:\Docs
[12/06/2010 - 23:10:38 | D ] F:\Xiu-Ning
[12/06/2010 - 22:06:46 | D ] F:\Jeux
[12/06/2010 - 23:19:36 | D ] F:\Toons
[31/08/2011 - 12:56:42 | D ] F:\Logiciels
[04/09/2011 - 23:20:44 | SHD ] F:\System Volume Information
[25/12/2011 - 17:07:30 | SHD ] F:\$RECYCLE.BIN
[22/07/2012 - 16:23:18 | N | 344064] F:\ehthumbs_vista.db
[10/08/2012 - 11:34:10 | D ] F:\Films des gens
[06/05/2012 - 19:12:54 | D ] F:\Ricet_Barrier_Tel_quel
[26/05/2013 - 13:18:34 | RASHD ] F:\Autorun.inf
[14/05/2013 - 14:38:14 | D ] G:\Swanouche
[14/05/2013 - 14:41:50 | D ] G:\Temporaire
[20/05/2013 - 11:12:34 | RASD ] G:\Autorun.inf
[05/08/2013 - 17:36:06 | D ] G:\Extraits convers
[16/05/2011 - 11:21:12 | N | 1776] Z:\SETSTOR.DAT
[04/09/2013 - 12:51:14 | N | 26] Z:\SYSINFO.DAT
[16/05/2011 - 11:21:12 | N | 4194304] Z:\STDBSTR.DAT
[16/05/2011 - 11:21:12 | N | 2536] Z:\STDBSTR.IDX
[16/05/2011 - 11:21:12 | N | 4194304] Z:\STDBDATA.DAT
[16/05/2011 - 11:21:12 | N | 296] Z:\STDBDATA.IDX
[16/05/2011 - 11:21:14 | D ] Z:\Recorded
[16/05/2011 - 11:21:14 | D ] Z:\Music
[16/05/2011 - 11:21:14 | D ] Z:\Pictures
[16/05/2011 - 11:21:14 | D ] Z:\Video
[16/05/2011 - 11:21:14 | D ] Z:\My Organizer
[16/05/2011 - 11:21:14 | D ] Z:\Playlist
[16/05/2011 - 11:21:14 | N | 660000] Z:\RAMLIST.DAT
[16/05/2011 - 11:21:14 | N | 32766] Z:\CMI_INDEX_TITLE.IDX
[16/05/2011 - 11:21:14 | N | 32766] Z:\CMI_INDEX_ARTIST.IDX
[16/05/2011 - 11:21:14 | N | 32766] Z:\CMI_INDEX_ALBUM.IDX
[16/05/2011 - 11:21:16 | N | 32766] Z:\CMI_INDEX_GENRE.IDX
[16/05/2011 - 11:21:18 | N | 200040] Z:\playqueue.dat
[16/05/2011 - 11:21:18 | N | 0] Z:\thumblnail.dat
[16/05/2011 - 11:21:18 | N | 15590] Z:\CDARTTHN.DAT
[06/06/2013 - 14:34:48 | N | 296] Z:\WMPInfo.xml
################## | Vaccin |
C:\Autorun.inf -> Vaccin créé par UsbFix (El Desaparecido)
D:\Autorun.inf -> Vaccin créé par UsbFix (El Desaparecido)
F:\Autorun.inf -> Vaccin créé par UsbFix (El Desaparecido)
G:\Autorun.inf -> Vaccin créé par UsbFix (El Desaparecido)
Z:\Autorun.inf -> Vaccin créé par UsbFix (El Desaparecido)
################## | E.O.F |
https://www.sosvirus.net |