Répondre à : worm sur disque dur 2016-09-08T13:35:55+00:00
Photo du profil de Antoine83Antoine83
Participant
Post count: 49

Rapport d’OTL :
All processes killed
========== OTL ==========
Registry value HKEY_USERSS-1-5-21-1455361060-3865099847-914009229-1000SoftwareMicrosoftWindowsCurrentVersionRun\41a deleted successfully.
Registry value HKEY_LOCAL_MACHINESOFTWAREMicrosoftWindows NTCurrentVersionWindows\AppInit_Dlls:c:progra~2bitguard271832~1.68{c16c1~1bitguard.dll deleted successfully.
========== FILES ==========
C:56d5f folder moved successfully.
F:575 folder moved successfully.
F:72727 folder moved successfully.
G:575 folder moved successfully.
G:72727 folder moved successfully.
========== COMMANDS ==========

[EMPTYTEMP]

User: All Users

User: ASUS
->Temp folder emptied: 7714240 bytes
->Temporary Internet Files folder emptied: 3288479 bytes
->FireFox cache emptied: 29999782 bytes
->Google Chrome cache emptied: 8056712 bytes
->Apple Safari cache emptied: 0 bytes
->Flash cache emptied: 763 bytes

User: Default
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 0 bytes
->Google Chrome cache emptied: 0 bytes

User: Default User

User: Public

%systemdrive% .tmp files removed: 0 bytes
%systemroot% .tmp files removed: 0 bytes
%systemroot%System32 .tmp files removed: 0 bytes
%systemroot%System32drivers .tmp files removed: 0 bytes
Windows Temp folder emptied: 28640674 bytes
RecycleBin emptied: 0 bytes

Total Files Cleaned = 74,00 mb

[EMPTYFLASH]

User: All Users

User: ASUS
->Flash cache emptied: 0 bytes

User: Default

User: Default User

User: Public

Total Flash Files Cleaned = 0,00 mb

OTL by OldTimer – Version 3.2.69.0 log created on 04232014_160919

FilesFolders moved on Reboot…
C:UsersASUSAppDataLocalTempStarSheaStaff contact list 10.03.14 – Copie.xlsx moved successfully.
FileFolder C:UsersASUSAppDataLocalTemp~$StarSheaStaff contact list 10.03.14 – Copie.xlsx not found!
C:UsersASUSAppDataLocalTemp~DFA374.tmp moved successfully.
FileFolder C:UsersASUSAppDataLocalMicrosoftWindowsTemporary Internet FilesContent.MSOmso10D4.tmp not found!
FileFolder C:UsersASUSAppDataLocalMicrosoftWindowsTemporary Internet FilesContent.MSOmso10D5.tmp not found!
FileFolder C:UsersASUSAppDataLocalMicrosoftWindowsTemporary Internet FilesContent.MSOmso22FE.tmp not found!
FileFolder C:UsersASUSAppDataLocalMicrosoftWindowsTemporary Internet FilesContent.MSOmso260B.tmp not found!
FileFolder C:UsersASUSAppDataLocalMicrosoftWindowsTemporary Internet FilesContent.MSOmso26D7.tmp not found!
FileFolder C:UsersASUSAppDataLocalMicrosoftWindowsTemporary Internet FilesContent.MSOmso2755.tmp not found!
FileFolder C:UsersASUSAppDataLocalMicrosoftWindowsTemporary Internet FilesContent.MSOmso2766.tmp not found!
FileFolder C:UsersASUSAppDataLocalMicrosoftWindowsTemporary Internet FilesContent.MSOmso2767.tmp not found!
FileFolder C:UsersASUSAppDataLocalMicrosoftWindowsTemporary Internet FilesContent.MSOmso2777.tmp not found!
File move failed. C:Windowstemp_avast_AvastLock.txt scheduled to be moved on reboot.
File move failed. C:Windowstemp_avast_Webshlock.txt scheduled to be moved on reboot.

PendingFileRenameOperations files…

Registry entries deleted on Reboot…

et de UsbFix

############################## | UsbFix V 7.169 | [Suppression]

Utilisateur: ASUS (Administrateur) # PC-ASUS
Mis à jour le 31/03/2014 par El Desaparecido – Team SosVirus
Lancé à 16:51:13 | 23/04/2014

Site Web : http://www.usbfix.net/” onclick=”window.open(this.href);return false;
Changelog : http://www.usbfix.net/maj/” onclick=”window.open(this.href);return false;
Support : forum-virus-securite.html
Upload Malware : upload_malware.php
Contact : http://www.usbfix.net/contact/” onclick=”window.open(this.href);return false;

PC: ASUSTeK Computer Inc. (F5N )
CPU: AMD Athlon(tm) 64 X2 Dual-Core Processor TK-57
RAM -> [Total : 1919 Mo| Free : 777 Mo]
Bios: American Megatrends Inc.
Boot: Normal boot

OS: Microsoft® Windows Vista™ Édition Familiale Premium (6.0.6000 32-Bit)
WB: Windows Internet Explorer : 7.0.6000.16982
WB: Google Chrome : 30.0.1599.101
WB: Mozilla Firefox : 24.0
WB: Safari : 534.57.2

SC: Security Center [Enabled]
WU: Windows Update [Enabled]

FW: Windows FireWall [Enabled]

C: (%systemdrive%) -> Disque fixe # 116 Go (56 Go libre(s) – 48%) [VistaOS] # NTFS
D: -> Disque fixe # 109 Go (13 Go libre(s) – 12%) [DATA] # NTFS
E: -> CD-ROM
F: -> Disque fixe # 273 Go (157 Go libre(s) – 58%) [] # NTFS
G: -> Disque fixe # 182 Go (182 Go libre(s) – 100%) [] # NTFS

################## | Processus Actif |

C:Windowssystem32csrss.exe (ID: 552 |ParentID: 540)
C:Windowssystem32wininit.exe (ID: 604 |ParentID: 540)
C:Windowssystem32csrss.exe (ID: 616 |ParentID: 596)
C:Windowssystem32services.exe (ID: 652 |ParentID: 604)
C:Windowssystem32lsass.exe (ID: 668 |ParentID: 604)
C:Windowssystem32lsm.exe (ID: 676 |ParentID: 604)
C:Windowssystem32winlogon.exe (ID: 748 |ParentID: 596)
C:Windowssystem32svchost.exe (ID: 860 |ParentID: 652)
C:Windowssystem32svchost.exe (ID: 944 |ParentID: 652)
C:WindowsSystem32svchost.exe (ID: 976 |ParentID: 652)
C:WindowsSystem32svchost.exe (ID: 1128 |ParentID: 652)
C:WindowsSystem32svchost.exe (ID: 1168 |ParentID: 652)
C:Windowssystem32svchost.exe (ID: 1180 |ParentID: 652)
C:Windowssystem32AUDIODG.EXE (ID: 1272 |ParentID: 1128)
C:Windowssystem32SLsvc.exe (ID: 1316 |ParentID: 652)
C:Windowssystem32svchost.exe (ID: 1352 |ParentID: 652)
C:Windowssystem32svchost.exe (ID: 1536 |ParentID: 652)
C:Program FilesCommon FilesSymantec SharedccSvcHst.exe (ID: 1656 |ParentID: 652)
C:Program FilesCommon FilesSymantec SharedAppCoreAppSvc32.exe (ID: 1776 |ParentID: 652)
C:Windowssystem32Dwm.exe (ID: 1812 |ParentID: 1168)
C:WindowsExplorer.EXE (ID: 1828 |ParentID: 1792)
C:Program FilesATK HotkeyASLDRSrv.exe (ID: 1868 |ParentID: 652)
C:Program FilesATKGFNEXGFNEXSrv.exe (ID: 1892 |ParentID: 652)
C:Program FilesAVAST SoftwareAvastAvastSvc.exe (ID: 1928 |ParentID: 652)
C:Program FilesWinZipperwinzipersvc.exe (ID: 2004 |ParentID: 652)
C:ProgramDataWPMwprotectmanager.exe (ID: 244 |ParentID: 652)
C:Windowssystem32taskeng.exe (ID: 624 |ParentID: 1180)
C:WindowsSystem32spoolsv.exe (ID: 644 |ParentID: 652)
C:Windowssystem32svchost.exe (ID: 868 |ParentID: 652)
C:Windowssystem32taskeng.exe (ID: 1388 |ParentID: 1180)
C:Program FilesDuuquUpdateDuuquUpdate.exe (ID: 1408 |ParentID: 624)
C:Program FilesGoogleUpdateGoogleUpdate.exe (ID: 1544 |ParentID: 624)
C:Program FilesCommon FilesABBYYFineReaderSprint9.00LicensingNetworkLicenseServer.exe (ID: 2192 |ParentID: 652)
C:Program FilesATK HotkeyHcontrol.exe (ID: 2376 |ParentID: 1868)
C:Program FilesATKOSD2ATKOSD2.exe (ID: 2384 |ParentID: 1868)
C:Program FilesWireless Console 2wcourier.exe (ID: 2392 |ParentID: 1868)
C:Program FilesP4GBatteryLife.exe (ID: 2408 |ParentID: 1868)
C:Program FilesCommon FilesAdobeARM1.0armsvc.exe (ID: 2420 |ParentID: 652)
C:Program FilesCommon FilesAppleMobile Device SupportAppleMobileDeviceService.exe (ID: 2456 |ParentID: 652)
C:Program FilesBonjourmDNSResponder.exe (ID: 2616 |ParentID: 652)
C:Windowssystem32svchost.exe (ID: 2652 |ParentID: 652)
C:Program FilesATK HotkeyATKOSD.exe (ID: 3116 |ParentID: 2376)
C:ProgramDataDatacardServiceHWDeviceService.exe (ID: 3124 |ParentID: 652)
C:Program FilesCommon FilesLightScribeLSSrvc.exe (ID: 3144 |ParentID: 652)
C:ProgramDataDatacardServiceDCSHelper.exe (ID: 3204 |ParentID: 3124)
C:Program FilesATK HotkeyKBFiltr.exe (ID: 3212 |ParentID: 2376)
C:ProgramDataMTN Pocket InternetOnlineUpdateouc.exe (ID: 3244 |ParentID: 3196)
C:Windowssystem32svchost.exe (ID: 3264 |ParentID: 652)
C:ProgramDataSkypeToolbarsSkype C2C Servicec2c_service.exe (ID: 3356 |ParentID: 652)
C:Program FilesASUSNB ProbeSPMspmgr.exe (ID: 3460 |ParentID: 652)
C:Windowssystem32svchost.exe (ID: 3472 |ParentID: 652)
C:WindowsSystem32StkCSrv.exe (ID: 3552 |ParentID: 652)
C:WindowsSystem32svchost.exe (ID: 3588 |ParentID: 652)
C:Windowssystem32SearchIndexer.exe (ID: 3620 |ParentID: 652)
C:Program FilesWindows DefenderMSASCui.exe (ID: 1676 |ParentID: 1828)
C:Windowssystem32wbemwmiprvse.exe (ID: 1108 |ParentID: 860)
C:WindowsSystem32rundll32.exe (ID: 3256 |ParentID: 1828)
C:WindowsRtHDVCpl.exe (ID: 1720 |ParentID: 1828)
C:WindowsSystem32rundll32.exe (ID: 1904 |ParentID: 1704)
C:Windowssystem32wbemunsecapp.exe (ID: 2548 |ParentID: 860)
C:Program FilesMotorolaSMSERIALsm56hlpr.exe (ID: 1092 |ParentID: 1828)
C:Program FilesASUSATK MediaDMedia.exe (ID: 2212 |ParentID: 1828)
C:Program FilesSynapticsSynTPSynTPEnh.exe (ID: 2444 |ParentID: 1828)
C:WindowsASScrPro.exe (ID: 4104 |ParentID: 1828)
C:Program FilesPowerForPhonePowerForPhone.exe (ID: 4132 |ParentID: 1828)
C:Program FilesCommon FilesSymantec SharedccApp.exe (ID: 4212 |ParentID: 1828)
C:Program FilesEpson SoftwareEvent ManagerEEventManager.exe (ID: 4296 |ParentID: 1828)
C:Program FilesCommon FilesAdobeARM1.0AdobeARM.exe (ID: 4308 |ParentID: 1828)
C:Program FilesiTunesiTunesHelper.exe (ID: 4328 |ParentID: 1828)
C:Program FilesFrameFoxExtensionsInternetExplorerframefox.exe (ID: 4412 |ParentID: 1828)
C:Program FilesAVAST SoftwareAvastAvastUI.exe (ID: 4424 |ParentID: 1828)
C:Program FilesMicrosoft OfficeOffice12GrooveMonitor.exe (ID: 4436 |ParentID: 1828)
C:Program FilesCommon FilesLightScribeLightScribeControlPanel.exe (ID: 4456 |ParentID: 1828)
C:Windowsehomeehtray.exe (ID: 4532 |ParentID: 1828)
C:Program FilesSkypePhoneSkype.exe (ID: 4540 |ParentID: 1828)
C:UsersASUSAppDataRoamingDropboxbinDropbox.exe (ID: 4612 |ParentID: 1828)
C:Windowsehomeehmsas.exe (ID: 4628 |ParentID: 860)
C:Program FilesiPodbiniPodService.exe (ID: 4736 |ParentID: 652)
C:Program FilesMozilla Firefoxfirefox.exe (ID: 5088 |ParentID: 1828)
C:Windowssystem32SearchProtocolHost.exe (ID: 5596 |ParentID: 3620)
C:Windowssystem32wbemwmiprvse.exe (ID: 5716 |ParentID: 860)
C:Windowssystem32NOTEPAD.EXE (ID: 4848 |ParentID: 1828)
C:Windowssystem32SearchFilterHost.exe (ID: 5720 |ParentID: 3620)
C:WindowsservicingTrustedInstaller.exe (ID: 5820 |ParentID: 652)

################## | Recherche générique |

(!) Fichiers temporaires supprimés.

################## | Registre |

################## | Regedit Run |

F2 – HKLM..Winlogon : [Shell] explorer.exe
F2 – [x64] HKLM..Winlogon : [Shell] explorer.exe
F2 – HKLM..Winlogon : [Userinit] C:Windowssystem32userinit.exe,
F2 – [x64] HKLM..Winlogon : [Userinit] C:Windowssystem32userinit.exe,
04 – HKCU..Run : [LightScribe Control Panel] C:Program FilesCommon FilesLightScribeLightScribeControlPanel.exe -hidden
04 – HKCU..Run : [EPSON SX130 Series] C:Windowssystem32spoolDRIVERSW32X863E_FATIHJE.EXE /FU “C:WindowsTEMPE_SD820.tmp” /EF “HKCU”
04 – HKCU..Run : [ehTray.exe] C:WindowsehomeehTray.exe
04 – HKCU..Run : [Skype] “C:Program FilesSkypePhoneSkype.exe” /minimized /regrun
04 – HKCU..Run : [Bubble Dock] “C:UsersASUSAppDataRoamingNosibayBubble DockLBubble Dock.exe” /winstartup
04 – HKLM..Run : [Windows Defender] %ProgramFiles%Windows DefenderMSASCui.exe -hide
04 – HKLM..Run : [NvSvc] RUNDLL32.EXE C:Windowssystem32nvsvc.dll,nvsvcStart
04 – HKLM..Run : [NvCplDaemon] RUNDLL32.EXE C:Windowssystem32NvCpl.dll,NvStartup
04 – HKLM..Run : [NvMediaCenter] RUNDLL32.EXE C:Windowssystem32NvMcTray.dll,NvTaskbarInit
04 – HKLM..Run : [RtHDVCpl] RtHDVCpl.exe
04 – HKLM..Run : [Skytel] Skytel.exe
04 – HKLM..Run : [SMSERIAL] C:Program FilesMotorolaSMSERIALsm56hlpr.exe
04 – HKLM..Run : [ATKMEDIA] C:Program FilesASUSATK MediaDMEDIA.EXE
04 – HKLM..Run : [SynTPEnh] C:Program FilesSynapticsSynTPSynTPEnh.exe
04 – HKLM..Run : [ASUS Camera ScreenSaver] C:WindowsASScrProlog.exe
04 – HKLM..Run : [ASUS Screen Saver Protector] C:WindowsASScrPro.exe
04 – HKLM..Run : [PowerForPhone] C:Program FilesPowerForPhonePowerForPhone.exe
04 – HKLM..Run : [NeroFilterCheck] C:Program FilesCommon FilesAheadLibNeroCheck.exe
04 – HKLM..Run : [ccApp] “C:Program FilesCommon FilesSymantec SharedccApp.exe”
04 – HKLM..Run : [EEventManager] “C:Program FilesEpson SoftwareEvent ManagerEEventManager.exe”
04 – HKLM..Run : [Adobe ARM] “C:Program FilesCommon FilesAdobeARM1.0AdobeARM.exe”
04 – HKLM..Run : [APSDaemon] “C:Program FilesCommon FilesAppleApple Application SupportAPSDaemon.exe”
04 – HKLM..Run : [iTunesHelper] “C:Program FilesiTunesiTunesHelper.exe”
04 – HKLM..Run : [FrameFox Extensions] C:Program FilesFrameFoxExtensionsInternetExplorerframefox.exe
04 – HKLM..Run : [AvastUI.exe] “C:Program FilesAVAST SoftwareAvastAvastUI.exe” /nogui
04 – HKLM..Run : [GrooveMonitor] “C:Program FilesMicrosoft OfficeOffice12GrooveMonitor.exe”
04 – HKUS-1-5-19..Run : [Sidebar] %ProgramFiles%Windows SidebarSidebar.exe /detectMem
04 – HKUS-1-5-19..Run : [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCenter
04 – HKUS-1-5-20..Run : [Sidebar] %ProgramFiles%Windows SidebarSidebar.exe /detectMem
04 – HKUS-1-5-20..Run : [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCenter
04 – HKUS-1-5-21-1455361060-3865099847-914009229-1000..Run : [LightScribe Control Panel] C:Program FilesCommon FilesLightScribeLightScribeControlPanel.exe -hidden
04 – HKUS-1-5-21-1455361060-3865099847-914009229-1000..Run : [EPSON SX130 Series] C:Windowssystem32spoolDRIVERSW32X863E_FATIHJE.EXE /FU “C:WindowsTEMPE_SD820.tmp” /EF “HKCU”
04 – HKUS-1-5-21-1455361060-3865099847-914009229-1000..Run : [ehTray.exe] C:WindowsehomeehTray.exe
04 – HKUS-1-5-21-1455361060-3865099847-914009229-1000..Run : [Skype] “C:Program FilesSkypePhoneSkype.exe” /minimized /regrun
04 – HKUS-1-5-21-1455361060-3865099847-914009229-1000..Run : [Bubble Dock] “C:UsersASUSAppDataRoamingNosibayBubble DockLBubble Dock.exe” /winstartup

################## | Listing |

[05/11/2012 – 20:21:28 | SHD] – C:$RECYCLE.BIN
[02/04/2008 – 22:29:08 | D] – C:ADOBE
[18/09/2006 – 21:43:36 | A | 0 Ko] – C:autoexec.bat
[18/04/2007 – 09:26:26 | SHD] – C:Boot
[02/11/2006 – 09:53:57 | RASH | 429 Ko] – C:bootmgr
[18/04/2007 – 09:26:27 | RAS | 8 Ko] – C:BOOTSECT.BAK
[04/04/2007 – 04:01:54 | N | 0 Ko | 78E5AC1AA5D0A50BB4B6B7354F923068] – C:CA13.txt
[22/04/2014 – 19:33:46 | D] – C:Config.Msi
[18/09/2006 – 21:43:37 | N | 0 Ko] – C:config.sys
[03/04/2008 – 00:29:04 | N | 19 Ko | F8FE4B3FDDB2A83D7F9B66202C498761] – C:devlist.txt
[02/11/2006 – 13:02:03 | SHD] – C:Documents and Settings
[21/08/2007 – 01:58:49 | N | 512 Ko] – C:F5N.ROM
[25/10/2007 – 01:09:13 | N | 0 Ko] – C:F5N_Vista.20
[03/04/2008 – 00:29:03 | N | 0 Ko] – C:Finish.log
[23/04/2014 – 16:45:34 | ASH | 1965336 Ko] – C:hiberfil.sys
[14/04/2014 – 11:49:20 | RHD] – C:MSOCache
[21/04/2014 – 12:40:47 | D] – C:musique (2)
[07/08/2007 – 21:43:02 | N | 0 Ko] – C:NERO.LOG
[05/11/2012 – 20:19:22 | D] – C:NIS
[17/05/2007 – 03:35:24 | N | 0 Ko | 440F3C847C02B75A30FE643F5A9E823D] – C:NIS2007_A.TXT
[15/03/2007 – 23:18:45 | N | 0 Ko | 9F9F657D665A4FDD8ADF0DAC16C4DF21] – C:OFFICE2007_A.TXT
[23/04/2014 – 16:45:31 | ASH | 2271904 Ko] – C:pagefile.sys
[02/04/2008 – 11:22:42 | N | 0 Ko | C4273828EA766A3346A74902E248A7D5] – C:Pass.txt
[22/01/2008 – 00:22:18 | N | 1 Ko] – C:Patch.LOG
[23/04/2014 – 11:44:35 | N | 1 Ko] – C:PhysicalMBR.bin
[02/04/2008 – 10:32:01 | D] – C:Preload
[22/04/2014 – 19:33:47 | D] – C:Program Files
[22/04/2014 – 09:10:48 | HD] – C:ProgramData
[23/05/2007 – 22:43:40 | N | 0 Ko | D418C03D6DB31B77DD48BF2A8DA9737A] – C:READER_A.TXT
[06/04/2007 – 11:38:05 | N | 0 Ko] – C:RECOVERY.DAT
[03/04/2008 – 00:02:52 | N | 0 Ko] – C:RHDSetup.log
[02/04/2008 – 22:16:17 | N | 0 Ko | E407677A3AF307821884DD7DF43C1257] – C:SumHidd.txt
[02/04/2008 – 22:15:23 | N | 0 Ko | 84BC5BEC99EBDCA0EE9C2B00C595B71D] – C:SumOS.txt
[23/04/2014 – 15:23:45 | SHD] – C:System Volume Information
[23/04/2014 – 16:38:01 | D] – C:UsbFix
[23/04/2014 – 09:35:40 | N | 16 Ko | 313AFD8234D4F8B84750DB6BFC37018B] – C:UsbFix [Clean 2] PC-ASUS.txt
[23/04/2014 – 13:14:49 | N | 13 Ko | A6326F7EB3CC603D2E556479E34D6100] – C:UsbFix [Clean 4] PC-ASUS.txt
[23/04/2014 – 16:35:56 | N | 15 Ko | 75B47DE3C8718B4C5288CF10BC949C18] – C:UsbFix [Clean 6] PC-ASUS.txt
[23/04/2014 – 16:51:59 | A | 13 Ko | 86172852E625F1148B3EE89954FED896] – C:UsbFix [Clean 8] PC-ASUS.txt
[23/04/2014 – 12:54:24 | N | 5 Ko | EA955E776D231EAD65DFBD68AEA1CFE5] – C:UsbFix [Listing 1] PC-ASUS.txt
[23/04/2014 – 08:57:49 | N | 12 Ko | 3FAB255D8E4B0DDA8A0B2B4554533144] – C:UsbFix [Scan 1] PC-ASUS.txt
[23/04/2014 – 09:08:01 | N | 12 Ko | 42A35018A5282BFB1968463FA21A15D3] – C:UsbFix [Scan 2] PC-ASUS.txt
[05/11/2012 – 20:14:29 | D] – C:Users
[06/12/2007 – 20:22:16 | N | 0 Ko | 8AE1554BEEE1A12B87B1BC2EEDD6B99C] – C:V54.TXT
[23/04/2014 – 09:54:35 | D] – C:Windows
[23/04/2014 – 12:30:15 | D] – C:_OTL
[23/04/2014 – 09:51:49 | D] – C:_OTM
[05/11/2012 – 20:21:28 | SHD] – D:$RECYCLE.BIN
[21/04/2014 – 12:26:29 | D] – D:Musique 1
[21/04/2014 – 11:03:36 | D] – D:Orange
[06/11/2012 – 05:07:25 | SHD] – D:System Volume Information
[21/04/2014 – 11:55:50 | D] – D:Séries (copie)
[22/04/2014 – 19:30:52 | SHD] – F:$RECYCLE.BIN
[23/04/2014 – 16:35:23 | HD] – F:.Trashes
[22/04/2014 – 20:10:34 | D] – F:Elise
[23/04/2014 – 13:38:17 | N | 4462 Ko] – F:How to Process … quality shea butter.pptx
[23/04/2014 – 13:23:05 | N | 7268 Ko] – F:How to Process … quality shea nuts.pptx
[22/04/2014 – 21:12:47 | SHD] – F:System Volume Information
[21/04/2014 – 16:50:44 | D] – F:Séries (copie)
[23/04/2014 – 09:34:39 | SHD] – G:$RECYCLE.BIN
[23/04/2014 – 16:35:23 | HD] – G:.Trashes
[23/04/2014 – 13:38:17 | N | 4462 Ko] – G:How to Process … quality shea butter.pptx
[23/04/2014 – 13:23:05 | N | 7268 Ko] – G:How to Process … quality shea nuts.pptx
[22/04/2014 – 21:12:47 | SHD] – G:System Volume Information

################## | Vaccin |

D:Autorun.inf -> Vaccin créé par UsbFix (El Desaparecido)
F:Autorun.inf -> Vaccin créé par UsbFix (El Desaparecido)
G:Autorun.inf -> Vaccin créé par UsbFix (El Desaparecido)

################## | E.O.F | http://www.usbfix.net/” onclick=”window.open(this.href);return false; – https://www.sosvirus.net” onclick=”window.open(this.href);return false; |