Répondre à : Ma clé usb et autres périphériques sont infectés (raccourci..) 2016-09-08T13:25:14+00:00
cecile
Participant
Nombre d'articles : 51

Ca y est, voici le rapport:

############################## | UsbFix V 7.154 | [Suppression]

Utilisateur: cecile (Administrateur) # CECILE-PC
Mis à jour le 13/12/2013 par El Desaparecido – Team SosVirus
Lancé à 21:48:11 | 14/12/2013

Site Web : http://www.usbfix.net” onclick=”window.open(this.href);return false;
Forum : https://www.sosvirus.net/” onclick=”window.open(this.href);return false;
Upload Malware : upload_malware.php
Contact : http://www.usbfix.net/contact/” onclick=”window.open(this.href);return false;

PC: ASUSTeK Computer Inc. (K50IN )
CPU: Pentium(R) Dual-Core CPU T4300 @ 2.10GHz
RAM -> [Total : 4095 | Free : 3141]
Bios: American Megatrends Inc.
Boot: Fail-safe with network boot

OS: Microsoft Windows 7 Édition Familiale Premium (6.1.7600 64-Bit)
WB: Windows Internet Explorer : 8.0.7600.16385

SC: Security Center Service [(!) Disabled]
WU: Windows Update Service [Enabled]
AV: Microsoft Security Essentials [Enabled | Updated]
AS: Windows Defender : 6.1.7600.16385 (win7_rtm.090713-1255)
AS: Malwarebytes’ Anti-Malware : 1.75.0001
FW: Windows FireWall Service [Enabled]

C: (%systemdrive%) -> Disque fixe # 149 Go (35 Go libre(s) – 23%) [OS] # NTFS
D: -> Disque fixe # 134 Go (21 Go libre(s) – 15%) [DATA] # NTFS
E: -> CD-ROM
F: -> Disque amovible # 4 Go (0 Mo libre(s) – 0%) [] # FAT32
H: -> Disque amovible # 7 Go (3 Mo libre(s) – 0%) [] # FAT32

################## | Processus Stoppés |

Stoppé! c:Program FilesMicrosoft Security ClientMsMpEng.exe (ID: 1848 |ParentID: 392)
Stoppé! C:WindowsExplorer.exe (ID: 1184 |ParentID: 1132)
Stoppé! C:Windowssystem32ctfmon.exe (ID: 204 |ParentID: 1184)
Stoppé! C:UserscecileAppDataLocalGoogleChromeApplicationchrome.exe (ID: 1652 |ParentID: 2024)
Stoppé! C:UserscecileAppDataLocalGoogleChromeApplicationchrome.exe (ID: 380 |ParentID: 1652)
Stoppé! C:UserscecileAppDataLocalGoogleChromeApplicationchrome.exe (ID: 1244 |ParentID: 1652)

################## | Regedit Run |

04 – HKLMSOFTWARE | Run : [NPSStartup] –
04 – HKLMSOFTWARE | Run : [ArcSoft Connection Service] – C:Program Files (x86)Common FilesArcSoftConnection ServiceBinACDaemon.exe
04 – HKLMSOFTWARE | Run : [EEventManager] – “C:Program Files (x86)Epson SoftwareEvent ManagerEEventManager.exe”
04 – HKLMSOFTWARE | Run : [HP Software Update] – C:Program Files (x86)HpHP Software UpdateHPWuSchd2.exe
04 – HKLMSOFTWARE | Run : [Adobe ARM] – “C:Program Files (x86)Common FilesAdobeARM1.0AdobeARM.exe”
04 – HKLMSOFTWARE | Run : [APSDaemon] – “C:Program Files (x86)Common FilesAppleApple Application SupportAPSDaemon.exe”
04 – HKLMSOFTWARE | Run : [QuickTime Task] – “C:Program Files (x86)QuickTimeQTTask.exe” -atboottime
04 – HKLMSOFTWARE | Run : [AdobeCS6ServiceManager] – “C:Program Files (x86)Common FilesAdobeCS6ServiceManagerCS6ServiceManager.exe” -launchedbylogin
04 – HKLMSOFTWARE | Run : [SunJavaUpdateSched] – “C:Program Files (x86)Common FilesJavaJava Updatejusched.exe”
04 – HKLMSOFTWAREwow6432Node | Run : [NPSStartup] –
04 – HKLMSOFTWAREwow6432Node | Run : [ArcSoft Connection Service] – C:Program Files (x86)Common FilesArcSoftConnection ServiceBinACDaemon.exe
04 – HKLMSOFTWAREwow6432Node | Run : [EEventManager] – “C:Program Files (x86)Epson SoftwareEvent ManagerEEventManager.exe”
04 – HKLMSOFTWAREwow6432Node | Run : [HP Software Update] – C:Program Files (x86)HpHP Software UpdateHPWuSchd2.exe
04 – HKLMSOFTWAREwow6432Node | Run : [Adobe ARM] – “C:Program Files (x86)Common FilesAdobeARM1.0AdobeARM.exe”
04 – HKLMSOFTWAREwow6432Node | Run : [APSDaemon] – “C:Program Files (x86)Common FilesAppleApple Application SupportAPSDaemon.exe”
04 – HKLMSOFTWAREwow6432Node | Run : [QuickTime Task] – “C:Program Files (x86)QuickTimeQTTask.exe” -atboottime
04 – HKLMSOFTWAREwow6432Node | Run : [AdobeCS6ServiceManager] – “C:Program Files (x86)Common FilesAdobeCS6ServiceManagerCS6ServiceManager.exe” -launchedbylogin
04 – HKLMSOFTWAREwow6432Node | Run : [SunJavaUpdateSched] – “C:Program Files (x86)Common FilesJavaJava Updatejusched.exe”
04 – HKLMSOFTWARE | RunOnce : [] –
04 – HKLMSOFTWAREwow6432Node | RunOnce : [] –
04 – HKUS-1-5-19SOFTWARE | Run : [Sidebar] – %ProgramFiles%Windows SidebarSidebar.exe /autoRun
04 – HKUS-1-5-20SOFTWARE | Run : [Sidebar] – %ProgramFiles%Windows SidebarSidebar.exe /autoRun
04 – HKUS-1-5-21-693478475-1187222661-1201366418-1000SOFTWARE | Run : [Google Update] – “C:UserscecileAppDataLocalGoogleUpdateGoogleUpdate.exe” /c
04 – HKUS-1-5-21-693478475-1187222661-1201366418-1000SOFTWARE | Run : [AdobeBridge] –
04 – HKUS-1-5-21-693478475-1187222661-1201366418-1000SOFTWARE | Run : [Intel(R)TCP] – C:UserscecileAppDataRoamingPublicIntel(R)TCP.exe
04 – HKUS-1-5-21-693478475-1187222661-1201366418-1000SOFTWARE | Run : [BTGBJNru] – wscript.exe //B “C:UserscecileAppDataLocalTempBTGBJNru.vbs”
04 – HKUS-1-5-21-693478475-1187222661-1201366418-1000SOFTWARE | Run : [8jusched] – C:UserscecileAppDataRoamingPublicjusched.exe
04 – HKUS-1-5-21-693478475-1187222661-1201366418-1000SOFTWARE | Run : [iTunesHelper] – wscript.exe //B “C:UserscecileAppDataLocalTempiTunesHelper.vbe”
04 – HKUS-1-5-21-693478475-1187222661-1201366418-1000SOFTWARE | Run : [sqlsern] – C:UsersPublicOpenCandy.exe
04 – HKUS-1-5-21-693478475-1187222661-1201366418-1000SOFTWARE | Run : [ISG] – C:UserscecileAppDataRoamingPublicwuauclt.exe
04 – HKUS-1-5-21-693478475-1187222661-1201366418-1000SOFTWARE | Run : [APS] – C:UsersPublicconhost.exe
04 – HKUS-1-5-19SOFTWARE | RunOnce : [mctadmin] – C:WindowsSystem32mctadmin.exe
04 – HKUS-1-5-20SOFTWARE | RunOnce : [mctadmin] – C:WindowsSystem32mctadmin.exe

################## | Recherche générique |

Supprimé! D:ImageReady.exe
Supprimé! H:SURVIVAL.vbe
Supprimé! H:iTunesHelper.vbe
Supprimé! C:UserscecileAppDataRoamingDC3E7919ak.tmp
Supprimé! C:UserscecileAppDataRoamingDC3E791912-10-2013
Supprimé! C:UserscecileAppDataRoamingDC3E791913-10-2013
Supprimé! C:UserscecileAppDataRoamingDC3E791914-10-2013
Supprimé! C:UserscecileAppDataRoamingDC3E791916-10-2013
Supprimé! C:UserscecileAppDataRoamingDC3E791917-10-2013
Supprimé! C:UserscecileAppDataRoamingDC3E791918-10-2013
Supprimé! C:UserscecileAppDataRoamingDC3E791919-10-2013
Supprimé! C:UserscecileAppDataRoamingDC3E791920-10-2013
Supprimé! C:UserscecileAppDataRoamingDC3E791922-10-2013
Supprimé! C:UserscecileAppDataRoamingDC3E791923-10-2013
Supprimé! C:UserscecileAppDataRoamingDC3E791924-10-2013
Supprimé! C:UserscecileAppDataRoamingDC3E791925-10-2013
Supprimé! C:UserscecileAppDataRoamingDC3E791926-10-2013
Supprimé! C:UserscecileAppDataRoamingDC3E791928-10-2013
Supprimé! C:UserscecileAppDataRoamingDC3E791929-10-2013
Supprimé! C:UserscecileAppDataRoamingDC3E791930-10-2013
Supprimé! C:UserscecileAppDataRoamingDC3E791931-10-2013
Supprimé! C:UserscecileAppDataRoamingDC3E79191-11-2013
Supprimé! C:UserscecileAppDataRoamingDC3E79192-11-2013
Supprimé! C:UserscecileAppDataRoamingDC3E79193-11-2013
Supprimé! C:UserscecileAppDataRoamingDC3E79194-11-2013
Supprimé! C:UserscecileAppDataRoamingDC3E79198-11-2013
Supprimé! C:UserscecileAppDataRoamingDC3E791910-11-2013
Supprimé! C:UserscecileAppDataRoamingDC3E791911-11-2013
Supprimé! C:UserscecileAppDataRoamingDC3E791912-11-2013
Supprimé! C:UserscecileAppDataRoamingDC3E791919-11-2013
Supprimé! C:UserscecileAppDataRoamingDC3E791920-11-2013
Supprimé! C:UserscecileAppDataRoamingDC3E791921-11-2013
Supprimé! C:UserscecileAppDataRoamingDC3E791922-11-2013
Supprimé! C:UserscecileAppDataRoamingDC3E791923-11-2013
Supprimé! C:UserscecileAppDataRoamingDC3E791924-11-2013
Supprimé! C:UserscecileAppDataRoamingDC3E791925-11-2013
Supprimé! C:UserscecileAppDataRoamingDC3E791926-11-2013
Supprimé! C:UserscecileAppDataRoamingDC3E791927-11-2013
Supprimé! C:UserscecileAppDataRoamingDC3E791928-11-2013
Supprimé! C:UserscecileAppDataRoamingDC3E791929-11-2013
Supprimé! C:UserscecileAppDataRoamingDC3E79196-12-2013
Supprimé! C:UserscecileAppDataRoamingDC3E79197-12-2013
Supprimé! C:UserscecileAppDataRoamingDC3E79198-12-2013
Supprimé! C:UserscecileAppDataRoamingDC3E79199-12-2013
Supprimé! C:UserscecileAppDataRoamingDC3E791910-12-2013
Supprimé! C:UserscecileAppDataRoamingDC3E791911-12-2013
Supprimé! C:UserscecileAppDataRoamingDC3E791912-12-2013
Supprimé! C:UserscecileAppDataRoamingDC3E791913-12-2013
Supprimé! C:UserscecileAppDataRoamingDC3E791914-12-2013
Supprimé! C:UserscecileAppDataRoamingDC3E7919
Supprimé! C:UserscecileAppDataLocalTempcecile8
Supprimé! C:UserscecileAppDataRoamingMicrosoftWindowsStart MenuProgramsStartupIntel(R)TCP.exe
Supprimé! C:UserscecileAppDataRoamingMicrosoftWindowsStart MenuProgramsStartupOpenCandy.exe
Supprimé! C:UsersPublicOpenCandy.exe
Supprimé! C:UserscecileAppDataRoamingMicrosoftWindowsStart MenuProgramsStartupconhost.exe
Supprimé! C:UsersPublicconhost.exe
Supprimé! F:perso cecile.lnk
Supprimé! C:UsersPublic4z1z.VBE
Supprimé! C:UsersPublic4zz.VBE
Supprimé! C:UsersPublic7z1z.VBE
Supprimé! C:UsersPublic7zz.VBE
Supprimé! C:UsersPubliciAStorIcon.exe
Supprimé! C:UsersPublicIntel(TM)SD.exe
Supprimé! C:UserscecileAppDataRoamingcecile-wchelper.dll
Supprimé! C:UserscecileAppDataRoamingPublic
Supprimé! C:UserscecileAppDataRoamingMicrosoftWindowsStart MenuProgramsStartup5z1z.lnk
Supprimé! C:UserscecileAppDataRoamingMicrosoftWindowsStart MenuProgramsStartup5zz.lnk
Supprimé! C:UserscecileAppDataRoamingMicrosoftWindowsStart MenuProgramsStartupjusched.exe
Supprimé! C:UserscecileAppDataRoamingMicrosoftWindowsStart MenuProgramsStartupwuauclt.exe
Supprimé! C:UserscecileAppDataLocalTempB9Y.hta
Supprimé! C:UserscecileAppDataLocalTemp%C2%9D.pif
Supprimé! C:UserscecileAppDataLocalTemp702.pif
Supprimé! C:UserscecileAppDataLocalTemp703.pif
Supprimé! C:UserscecileAppDataLocalTempetilqs_7OoXdBUc14ideje.pif

################## | Référence de comparaison MD5 |

Md5 : F0070AAFC90FE78EFACE902CB233D329 -> C:UsersPublic4z1z.VBE
Md5 : 4915B7758A2AF193B001A4B42CD42CB5 -> C:UsersPublic4zz.VBE
Md5 : F0070AAFC90FE78EFACE902CB233D329 -> C:UsersPublic7z1z.VBE
Md5 : 4915B7758A2AF193B001A4B42CD42CB5 -> C:UsersPublic7zz.VBE
Md5 : 40F4AAE74C6D4FADCDBFCC08AC7498FD -> C:UsersPublicIntel(TM)SD.exe
Md5 : E89028D8068170E606AA0996D457AAA3 -> C:UserscecileAppDataRoamingPublicjusched.exe
Md5 : 40F4AAE74C6D4FADCDBFCC08AC7498FD -> C:UserscecileAppDataRoamingMicrosoftWindowsStart MenuProgramsStartupIntel(R)TCP.exe
Md5 : 4DCDC65965510C215ED47D0BB75E26E6 -> C:UserscecileAppDataRoamingMicrosoftWindowsStart MenuProgramsStartupwuauclt.exe
Md5 : 61D6DB6F0BDC73E1F009847F1F9F432A -> D:ImageReady.exe
Md5 : 566A2952410520E6E384366F28F6871B -> H:SURVIVAL.vbe
Md5 : 2BCBCF86077A7E0F77BDB82F331F2957 -> H:iTunesHelper.vbe
Md5 : A409E23D76D5BD9E6E3027493DA121B8 -> C:UsersPublicOpenCandy.exe
Md5 : A409E23D76D5BD9E6E3027493DA121B8 -> C:UserscecileAppDataRoamingMicrosoftWindowsStart MenuProgramsStartupOpenCandy.exe
Md5 : F936FA87EC52A3373E254E1D559E8609 -> C:UsersPublicconhost.exe
Md5 : F936FA87EC52A3373E254E1D559E8609 -> C:UserscecileAppDataRoamingMicrosoftWindowsStart MenuProgramsStartupconhost.exe

################## | Comparaison MD5 |

-> Pas de valeur Md5 identique trouvée.

################## | Registre |

Supprimé! HKCUSoftwareÀ classé
Supprimé! HKUS-1-5-21-693478475-1187222661-1201366418-1000SoftwareMicrosoftWindowsCurrentVersionRun|8jusched
Supprimé! HKUS-1-5-21-693478475-1187222661-1201366418-1000SoftwareMicrosoftWindowsCurrentVersionRun|APS
Supprimé! HKUS-1-5-21-693478475-1187222661-1201366418-1000SoftwareMicrosoftWindowsCurrentVersionRun|Intel(R)TCP
Supprimé! HKUS-1-5-21-693478475-1187222661-1201366418-1000SoftwareMicrosoftWindowsCurrentVersionRun|ISG
Supprimé! HKUS-1-5-21-693478475-1187222661-1201366418-1000SoftwareMicrosoftWindowsCurrentVersionRun|iTunesHelper
Supprimé! HKUS-1-5-21-693478475-1187222661-1201366418-1000Software….Mountpoints2H
Supprimé! HKCU….ExplorerMountPoints2{040198da-fb15-11de-97a2-90e6ba67c8b6}

################## | UsbFix – Information |

UsbFix a détecté sur votre ordinateur, une infection qui dispose d’une fonction de Keylogger.
Après désinfection par UsbFix, veuillez modifier tous vos mots de passe.
Si vous avez effectué des achats sur internet,
veuillez contacter votre banque afin d’envisager une opposition sur votre carte bancaire.

Infos: infection-dinihou-vous-explique-son-fonctionnement-t4852.html

################## | Listing |

[14/12/2013 – 13:11:36 | N | 7 Ko] – C:UsbFix [Scan 1] CECILE-PC.txt
[14/12/2013 – 13:31:04 | N | 8 Ko] – C:UsbFix [Scan 2] CECILE-PC.txt
[14/12/2013 – 14:35:38 | N | 8 Ko] – C:UsbFix [Scan 3] CECILE-PC.txt
[14/12/2013 – 14:51:52 | N | 8 Ko] – C:UsbFix [Scan 4] CECILE-PC.txt
[14/12/2013 – 15:55:13 | N | 8 Ko] – C:UsbFix [Scan 5] CECILE-PC.txt
[14/12/2013 – 19:58:01 | N | 8 Ko] – C:UsbFix [Scan 6] CECILE-PC.txt
[14/12/2013 – 20:15:35 | N | 16 Ko] – C:UsbFix [Scan 7] CECILE-PC.txt
[14/12/2013 – 21:54:15 | A | 13 Ko] – C:UsbFix [Clean 2] CECILE-PC.txt
[14/12/2013 – 20:04:38 | ASH | 3145164 Ko] – C:hiberfil.sys
[14/12/2013 – 20:04:39 | ASH | 4193556 Ko] – C:pagefile.sys
[08/11/2009 – 14:14:24 | D] – C:asus.dat
[22/07/2009 – 10:02:29 | N | 1024 Ko] – C:K40IN.BIN
[03/01/2010 – 17:13:12 | N | 1 Ko] – C:os264931.bin
[12/06/2011 – 11:42:56 | SHD] – C:$Recycle.Bin
[29/07/2009 – 07:03:37 | N | 8 Ko] – C:BOOTSECT.BAK
[14/07/2009 – 02:38:58 | RASH | 375 Ko] – C:bootmgr
[14/07/2009 – 04:20:08 | D] – C:PerfLogs
[14/07/2009 – 06:08:56 | SHD] – C:Documents and Settings
[29/07/2009 – 07:03:34 | SHD] – C:Boot
[05/10/2009 – 08:49:59 | RHD] – C:MSOCache
[08/11/2009 – 14:01:19 | SHD] – C:Recovery
[08/05/2010 – 12:24:46 | D] – C:NVIDIA
[09/05/2013 – 02:25:23 | D] – C:Users
[26/08/2013 – 12:32:11 | D] – C:Downloads
[08/09/2013 – 18:05:19 | SHD] – C:System Volume Information
[07/10/2013 – 11:31:39 | D] – C:AdwCleaner
[16/10/2013 – 20:09:08 | D] – C:Program Files
[08/12/2013 – 15:52:32 | D] – C:Program Files (x86)
[12/12/2013 – 14:04:36 | HD] – C:ProgramData
[14/12/2013 – 15:39:36 | D] – C:FRST
[14/12/2013 – 20:04:38 | D] – C:Windows
[14/12/2013 – 21:54:02 | D] – C:UsbFix
[27/10/2003 – 08:18:02 | C | 21 Ko] – D:Photoshop CS LisezMoi.wri
[10/06/2011 – 22:32:20 | C | 0 Ko] – D:How to-A lire.txt.txt
[04/11/2003 – 04:23:32 | C | 147 Ko] – D:TypeLibrary.tlb
[27/10/2003 – 08:56:32 | C | 40 Ko] – D:Licence tierce.pdf
[17/04/2011 – 21:52:45 | C | 0 Ko] – D:OS (C) – Raccourci.lnk
[01/11/2013 – 11:55:40 | C | 0 Ko] – D:Disque amovible (G) – Raccourci.lnk
[14/12/2013 – 20:15:33 | RASHDC] – D:Autorun.inf
[04/11/2003 – 05:29:20 | C | 17536 Ko | CC1328B78787D46F1EF051BD391CB2B7] – D:Photoshop.exe
[10/06/2011 – 22:48:38 | C | 1476679 Ko | 28C87BF43C0EF74E181F0829FFE56A75] – D:Adobe Illustrator CS5.exe
[01/02/1999 – 23:00:00 | C | 260 Ko] – D:Msvcrt.dll
[03/12/1999 – 05:01:32 | C | 22 Ko] – D:Shfolder.dll
[28/08/2000 – 23:19:16 | C | 392 Ko] – D:MSVCP60.DLL
[03/06/2002 – 10:03:54 | C | 60 Ko] – D:Uninst.dll
[23/07/2003 – 11:17:06 | C | 240 Ko] – D:Asn.er.dll
[27/08/2003 – 10:05:22 | C | 160 Ko] – D:UID.mr.dll
[03/09/2003 – 23:49:18 | C | 516 Ko] – D:JP2KLib.dll
[18/09/2003 – 16:01:58 | C | 556 Ko] – D:ACE.dll
[18/09/2003 – 16:01:58 | C | 174 Ko] – D:ARE.dll
[18/09/2003 – 16:01:58 | C | 148 Ko] – D:Bib.dll
[18/09/2003 – 16:01:58 | C | 1501 Ko] – D:AGM.dll
[18/09/2003 – 16:01:58 | C | 3404 Ko] – D:MPS.dll
[18/09/2003 – 16:01:58 | C | 1592 Ko] – D:CoolType.dll
[18/09/2003 – 16:01:58 | C | 212 Ko] – D:BIBUtils.dll
[18/09/2003 – 16:03:56 | C | 4188 Ko] – D:PDFL60.dll
[18/09/2003 – 16:06:40 | C | 304 Ko] – D:AXEParser.dll
[25/09/2003 – 13:33:00 | C | 1317 Ko] – D:AWSSCL.dll
[14/10/2003 – 07:24:10 | C | 267 Ko] – D:Adobelmsvc Installer.dll
[22/10/2003 – 13:01:50 | C | 384 Ko] – D:ExtendScript.dll
[22/10/2003 – 13:01:50 | C | 268 Ko] – D:ScCore.dll
[22/10/2003 – 13:01:50 | C | 56 Ko] – D:ExtendScriptIDE.dll
[22/10/2003 – 14:37:24 | C | 1036 Ko] – D:almuirsc.dll
[30/10/2003 – 17:34:44 | C | 228 Ko] – D:AWSCommonSymbols.dll
[30/10/2003 – 17:34:44 | C | 1416 Ko] – D:AWSCommonUI.dll
[30/10/2003 – 17:34:48 | C | 2536 Ko] – D:ARM.dll
[30/10/2003 – 17:34:50 | C | 804 Ko] – D:FileInfo.dll
[30/10/2003 – 17:34:52 | C | 484 Ko] – D:WebAccessUtils.dll
[04/11/2003 – 02:22:54 | C | 56 Ko] – D:Plugin.dll
[04/11/2003 – 04:22:18 | C | 1784 Ko] – D:PSViews.dll
[04/11/2003 – 04:22:36 | C | 2168 Ko] – D:PSArt.dll
[08/11/2003 – 06:25:34 | C | 684 Ko] – D:ImageReadyRes.dll
[08/11/2003 – 06:35:12 | C | 1164 Ko] – D:Photoshop.dll
[01/01/2004 – 15:14:46 | C | 400 Ko] – D:AdobeLM.dll
[01/01/2004 – 15:14:46 | C | 80 Ko] – D:Tw10122.dat
[12/06/2011 – 11:42:56 | SHDC] – D:$RECYCLE.BIN
[05/10/2009 – 08:38:27 | SHDC] – D:System Volume Information
[29/01/2011 – 18:00:07 | DC] – D:Adobe Illustrator CS5
[21/06/2011 – 14:54:31 | DC] – D:Adobe Photoshop
[21/06/2011 – 15:19:39 | DC] – D:Modules externes
[21/06/2011 – 15:19:48 | DC] – D:Paramètres prédéfinis
[21/06/2011 – 15:20:05 | DC] – D:Required
[21/06/2011 – 15:20:26 | DC] – D:Juridique
[21/06/2011 – 15:20:26 | DC] – D:Activation
[20/03/2012 – 18:33:56 | DC] – D:1aa4e02f49d0fb331dbccb
[02/11/2012 – 22:57:55 | DC] – D:photos
[09/05/2013 – 02:25:23 | DC] – D:Users
[27/05/2013 – 21:46:19 | DC] – D:cours
[07/08/2013 – 15:15:30 | DC] – D:fOTOS
[26/08/2013 – 19:03:40 | DC] – D:Program Files (x86)
[28/12/2010 – 16:52:50 | D] – F:perso cecile
[29/09/2011 – 16:37:06 | SHD] – H:.Trashes
[29/09/2011 – 16:37:06 | SH | 4 Ko] – H:._.Trashes
[26/09/2013 – 17:59:54 | SH | 4 Ko] – H:._.TemporaryItems
[26/09/2013 – 17:59:54 | SHD] – H:.TemporaryItems
[29/09/2011 – 16:37:08 | SHD] – H:.Spotlight-V100
[25/11/2013 – 07:47:18 | N | 1680384 Ko] – H:ReadyBoost.sfcache
[15/08/2013 – 15:58:12 | N | 6252 Ko] – H:rapport renaulttrucks 2.pdf
[27/08/2013 – 13:16:40 | N | 112836 Ko] – H:rapport renaulttrucks.pdf
[26/09/2013 – 18:04:34 | N | 4 Ko] – H:._affiche.pdf
[16/10/2013 – 16:02:56 | N | 1349 Ko] – H:carnet.pdf
[16/10/2013 – 21:02:54 | N | 320 Ko] – H:vue face.pdf
[16/10/2013 – 21:06:18 | N | 345 Ko] – H:profil.pdf
[16/10/2013 – 21:14:44 | N | 338 Ko] – H:dessus.pdf
[16/10/2013 – 21:15:54 | N | 73 Ko] – H:section.pdf
[25/10/2013 – 14:36:20 | N | 1362 Ko] – H:carnet (1).pdf
[26/11/2013 – 16:29:18 | N | 352 Ko] – H:cartels.pdf
[28/11/2013 – 11:18:14 | N | 2737 Ko] – H:Sondage couteau cécile.pdf
[15/12/2011 – 11:51:18 | N | 0 Ko] – H:.~lock.Cynisme.odt#
[10/07/2013 – 12:22:08 | N | 195 Ko] – H:numérisation0001.jpg
[26/09/2013 – 18:00:44 | N | 4 Ko] – H:._danone.jpg
[14/12/2013 – 20:15:36 | RASHD] – H:Autorun.inf
[12/12/2013 – 14:14:42 | N | 40 Ko] – H:tracé lame jet d’eau.dxf
[29/11/2013 – 11:32:28 | N | 21 Ko] – H:.DS_Store
[12/10/2013 – 15:18:58 | N | 13 Ko] – H:1 mois pour découvrir et intégrer une entreprise.docx
[02/10/2013 – 18:33:48 | N | 1752 Ko] – H:amtlib.dll
[21/03/2012 – 18:04:40 | SH | 433 Ko] – H:Thumbs.db
[16/10/2013 – 20:18:18 | N | 1218 Ko] – H:woody final r4.3dm
[24/10/2013 – 15:59:48 | N | 1632 Ko] – H:woody bébé final packr4.3dm
[07/11/2013 – 11:54:26 | N | 1902 Ko] – H:lampe baladeuse.3dm
[07/11/2013 – 12:00:26 | N | 1898 Ko] – H:lampe baladeuse (eclaté).3dm
[10/11/2013 – 17:59:32 | N | 231 Ko] – H:rhino section 2.3dm
[28/11/2013 – 11:38:50 | N | 3609 Ko] – H:couteau 2 r4.3dm
[28/11/2013 – 11:39:42 | N | 4080 Ko] – H:couteau fini r4.3dm
[28/11/2013 – 11:47:42 | N | 4033 Ko] – H:COUTEAU ETUI.3dm
[28/11/2013 – 14:24:36 | N | 3636 Ko] – H:couteau final .3dm
[28/11/2013 – 15:20:16 | N | 299 Ko] – H:boucher trou par surface section.3dm
[26/09/2013 – 15:59:30 | D] – H:26.09.13
[30/10/2013 – 11:03:28 | D] – H:FOUND.001
[12/02/2013 – 21:15:34 | D] – H:FOUND.000
[26/09/2013 – 17:33:54 | D] – H:2013-09 (sept.)
[22/12/2004 – 05:47:22 | SHD] – H:RECYCLER
[25/02/2013 – 15:33:36 | D] – H:autres
[27/02/2013 – 15:48:40 | D] – H:Book
[17/06/2013 – 11:22:30 | D] – H:stage
[21/09/2013 – 18:26:54 | D] – H:Lampe
[03/10/2013 – 07:40:22 | D] – H:Famille
[03/10/2013 – 07:40:48 | D] – H:Ruscha ed
[03/10/2013 – 07:41:54 | D] – H:affiche Marketing Florian
[07/10/2013 – 21:36:54 | D] – H:Points de vue(s)
[16/10/2013 – 11:28:14 | D] – H:lampe bébé
[29/10/2013 – 15:01:30 | D] – H:imprimer
[07/11/2013 – 12:04:24 | D] – H:BIZE KEVIN
[28/11/2013 – 15:34:36 | D] – H:Infographie

################## | Vaccin |

D:Autorun.inf -> Vaccin créé par UsbFix (El Desaparecido)
F:Autorun.inf -> Vaccin créé par UsbFix (El Desaparecido)
H:Autorun.inf -> Vaccin créé par UsbFix (El Desaparecido)

################## | E.O.F | http://www.usbfix.net” onclick=”window.open(this.href);return false; – https://www.sosvirus.net” onclick=”window.open(this.href);return false; |