voici le rapport de suppression, comment mon pc à galéré, j'ai cru que j'allais le perdre!!!
############################## | UsbFix V8 bêta V 8.000 | [Suppression]
Utilisateur: jojo (Administrateur) # PC-DE-JOJO
Mis à jour le 12/09/2013 par El Desaparecido g3n-h@ckm@n
Lancé à 23:38:05 | 02/10/2013
Site Web:
http://sosvirus.net/
Upload Malware:
http://sosvirus.net/viewtopic.php?f=6t=489
Contact:
eldesaparecido@sosvirus.net
PC: Sony Corporation (VGN-SZ5XWN_C) (X86-based PC)
CPU: Intel(R) Core(TM)2 CPU T7200 @ 2.00GHz (2000)
RAM - [Total : 2037 | Free : 1016]
BIOS: Ver 1.00PARTTBL
BOOT: Normal boot
OS: Microsoft® Windows Vista™ Professionnel (6.0.6000 32-Bit) #
WB: Windows Internet Explorer 7.0.6000.16982
SC: Security Center Service [Enabled]
WU: Windows Update Service [Enabled]
FW: Windows FireWall Service [Enabled]
C:\ (%systemdrive%) - Disque fixe # 140 Go (46 Go libre(s) - 33%) [] # NTFS
E:\ - CD-ROM
G:\ - Disque fixe # 745 Go (285 Go libre(s) - 38%) [LaCie] # NTFS
H:\ - Disque fixe # 186 Go (186 Go libre(s) - 100%) [LACIE SHARE] # FAT32
############### | Drives
c:\ - Fixed # 143 GO ( Free : 47 Go) [] # NTFS
e:\ - CDROM # 0 GO ( Free : 0 Go) [327EN] # CDFS
g:\ - Fixed # 763 GO ( Free : 292 Go) [LaCie] # NTFS
h:\ - Fixed # 191 GO ( Free : 190 Go) [LACIE SHARE] # FAT32
################## | Comparaison MD5 |
################## | El Desaparecido Section |
HKLM\software | Run|[Windows Defender] : %ProgramFiles%\Windows Defender\MSASCui.exe -hide
HKLM\software | Run|[Apoint] : C:\Program Files\Apoint\Apoint.exe
HKLM\software | Run|[DRCU] : "C:\Program Files\Sony\DRCU\DRCU.exe"
HKLM\software | Run|[VAIOCameraUtility] : "C:\Program Files\Sony\VAIO Camera Utility\VCUServe.exe"
HKLM\software | Run|[ISBMgr.exe] : "C:\Program Files\Sony\ISB Utility\ISBMgr.exe"
HKLM\software | Run|[VAIODetection] : C:\Program Files\Sony\WiseWan\NovatelDetection\VAIODetection.exe
HKLM\software | Run|[IgfxTray] : C:\Windows\system32\igfxtray.exe
HKLM\software | Run|[HotKeysCmds] : C:\Windows\system32\hkcmd.exe
HKLM\software | Run|[Persistence] : C:\Windows\system32\igfxpers.exe
HKLM\software | Run|[MSConfig] : "C:\Windows\system32\msconfig.exe" /auto
HKLM\software | Run|[NvCplDaemon] : RUNDLL32.EXE C:\Windows\system32\NvCpl.dll,NvStartup
HKLM\software | Run|[NvMediaCenter] : RUNDLL32.EXE C:\Windows\system32\NvMcTray.dll,NvTaskbarInit
HKLM\software | Run|[avast] : "C:\Program Files\Alwil Software\Avast5\avastUI.exe" /nogui
HKLM\software | Run|[APSDaemon] : "C:\Program Files\Common Files\Apple\Apple Application Support\APSDaemon.exe"
HKLM\software | Run|[QuickTime Task] : "C:\Program Files\QuickTime\QTTask.exe" -atboottime
HKLM\software | Run|[SunJavaUpdateSched] : "C:\Program Files\Common Files\Java\Java Update\jusched.exe"
HKU\S-1-5-19\software | Run|[Sidebar] : %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem
HKU\S-1-5-20\software | Run|[Sidebar] : %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem
HKU\S-1-5-21-3113836193-271341877-650403806-1004\software | Run|[Sidebar] : C:\Program Files\Windows Sidebar\sidebar.exe /autoRun
HKU\S-1-5-21-3113836193-271341877-650403806-1004\software | Run|[] :
HKU\S-1-5-21-3113836193-271341877-650403806-1004\software | Run|[WMPNSCFG] : C:\Program Files\Windows Media Player\WMPNSCFG.exe
HKU\S-1-5-21-3113836193-271341877-650403806-1004\software | Run|[Skype] : "C:\Program Files\Skype\Phone\Skype.exe" /minimized /regrun
##### | Scan zones sensibles |
C:\Users\jojo\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
C:\Users\jojo\ntuser.ini
#################### | Processus Stoppés |
C:\Windows\system32\SLsvc.exe (1468)
C:\Windows\System32\spoolsv.exe (2040)
C:\Windows\Explorer.EXE (1736)
C:\Windows\system32\taskeng.exe (1984)
C:\Program Files\Google\Update\GoogleUpdate.exe (2068)
C:\Windows\system32\taskeng.exe (2076)
C:\Program Files\Windows Defender\MSASCui.exe (2696)
C:\Program Files\Apoint\Apoint.exe (2940)
C:\Program Files\Sony\VAIO Camera Utility\VCUServe.exe (2996)
C:\Program Files\Sony\ISB Utility\ISBMgr.exe (3012)
C:\Program Files\Sony\WiseWan\NovatelDetection\VAIODetection.exe (3048)
C:\Windows\System32\hkcmd.exe (3064)
C:\Windows\System32\igfxpers.exe (3072)
C:\Windows\system32\igfxsrvc.exe (3088)
C:\Program Files\Common Files\Java\Java Update\jusched.exe (3204)
C:\Program Files\Windows Sidebar\sidebar.exe (3212)
C:\Program Files\Windows Media Player\wmpnscfg.exe (3220)
C:\Program Files\Skype\Phone\Skype.exe (3308)
C:\Program Files\Malwarebytes' Anti-Malware\mbamscheduler.exe (3508)
C:\PROGRA~1\PANASO~1\LocalCom\lmsrvnt.exe (3620)
C:\Program Files\Malwarebytes' Anti-Malware\mbamgui.exe (3652)
C:\PROGRA~1\PANASO~1\TRAPMO~1\Trapmnnt.exe (3664)
C:\ProgramData\Skype\Toolbars\Skype C2C Service\c2c_service.exe (3776)
C:\Program Files\Microsoft SQL Server\90\Shared\sqlbrowser.exe (3836)
C:\Program Files\Microsoft SQL Server\90\Shared\sqlwriter.exe (3872)
C:\Program Files\SigmaTel\C-Major Audio\WDM\STacSV.exe (3896)
C:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosBtSrv.exe (3980)
C:\Program Files\Sony\VAIO Event Service\VESMgr.exe (2148)
C:\Program Files\Common Files\Sony Shared\VAIO Content Folder Watcher\VCFw.exe (2948)
C:\Program Files\Sony\VAIO Event Service\VESMgrSub.exe (3892)
C:\Program Files\Common Files\Sony Shared\VAIO Entertainment Platform\VzCdb\VzCdbSvc.exe (1304)
C:\Windows\system32\SearchIndexer.exe (3116)
C:\Windows\system32\WUDFHost.exe (2284)
C:\Windows\system32\DRIVERS\xaudio.exe (1456)
C:\Windows\system32\taskeng.exe (3392)
C:\Windows\system32\igfxext.exe (4512)
C:\Windows\system32\igfxsrvc.exe (4760)
C:\Program Files\Sony\Wireless Switch Setting Utility\Switcher.exe (5372)
C:\Program Files\Sony\VAIO Power Management\SPMgr.exe (5620)
C:\Program Files\Common Files\Sony Shared\VAIO Entertainment Platform\VCSW\VCSW.exe (4336)
C:\Program Files\Apoint\ApMsgFwd.exe (4368)
C:\Program Files\Sony\VAIO Update 5\VAIOUpdt.exe (4568)
C:\Program Files\Apoint\Apntex.exe (2980)
C:\Windows\system32\conime.exe (692)
C:\Program Files\Google\Chrome\Application\chrome.exe (4556)
C:\Program Files\Google\Chrome\Application\chrome.exe (4456)
C:\Program Files\Google\Chrome\Application\chrome.exe (6124)
C:\Program Files\Google\Chrome\Application\chrome.exe (5120)
C:\Program Files\Google\Chrome\Application\chrome.exe (1992)
C:\Program Files\Google\Chrome\Application\chrome.exe (4716)
C:\Program Files\Google\Chrome\Application\chrome.exe (4436)
C:\Windows\System32\mobsync.exe (5936)
################## | Éléments infectieux |
(!) Fichiers temporaires supprimés.
################## | Réparations registre |
Réparé ! HKLM\Software\Microsoft\Internet Explorer\ABOUTURLS|[Tabs] :
http://www.google.com - res://ieframe.dll/tabswelcome.htm
Réparé ! HKLM\Software\Microsoft\Internet Explorer\Main|[Default_search_url] :
http://go.microsoft.com/fwlink/?LinkId=54896 -
http://www.microsoft.com/isapi/redir.dl ... r=iesearch
Réparé ! HKLM\Software\Microsoft\Internet Explorer\Main|[Default_page_url] :
http://www.google.com -
http://www.microsoft.com/isapi/redir.dl ... ar=msnhome
Réparé ! HKLM\Software\Microsoft\Internet Explorer\Main|[Search bar] : -
http://search.msn.com/spbasic.htm
Réparé ! HKLM\Software\Microsoft\Internet Explorer\Main|[Start page] :
http://www.google.com -
http://fr.msn.com/
Réparé ! HKCU\Software\Microsoft\Internet Explorer\Main|[Default_search_url] : -
http://www.microsoft.com/isapi/redir.dl ... r=iesearch
Réparé ! HKCU\Software\Microsoft\Internet Explorer\Main|[Default_page_url] :
http://www.google.com -
http://www.microsoft.com/isapi/redir.dl ... ar=msnhome
Réparé ! HKCU\Software\Microsoft\Internet Explorer\Main|[Search bar] :
http://www.bing.com -
http://go.microsoft.com/fwlink/?linkid=54896
Réparé ! HKCU\Software\Microsoft\Internet Explorer\Main|[Start page] :
http://www.google.com/ -
http://fr.msn.com/
Réparé ! HKCU\Software\Microsoft\Internet Explorer\Main|[Window Title] : - Windows Internet Explorer
Réparé ! HKCU\Software\Microsoft\Internet Explorer\SearchScopes\${searchCLSID}|[] : - Live Search
Réparé ! HKCU\Software\Microsoft\Internet Explorer\SearchScopes\${searchCLSID}|[DisplayName] : - @ieframe.dll,-12512
Réparé ! HKCU\Software\Microsoft\Internet Explorer\SearchScopes\${searchCLSID}|[URL] : -
http://search.live.com/results.aspx?q={ ... rer:source?}
Réparé ! HKLM\System\ControlSet002\Control\SafeBoot|[AlternateShell] : - cmd.exe
################## | Winlogon User |
################## | Winlogon Machine |
################## | Registre |
Supprimé! HKLM\Software\Microsoft\Windows\CurrentVersion\Run|MSConfig
################## | Mountpoints2 |
Supprimé! HKU\S-1-5-21-3113836193-271341877-650403806-1004\Software\Microsoft\Windows\CurrentVersion\Explorer\Mountpoints2\G | AutoRun\command : G:\Autorun.exe
Supprimé! HKU\S-1-5-21-3113836193-271341877-650403806-1004\Software\Microsoft\Windows\CurrentVersion\Explorer\Mountpoints2\{e75c59ca-43b8-11e2-a520-0013a9fc61d7} | AutoRun\command : I:\PMBP_Win.exe
Supprimé! HKU\S-1-5-21-3113836193-271341877-650403806-1004\Software\Microsoft\Windows\CurrentVersion\Explorer\Mountpoints2\{f4a89aa5-087b-11e0-9d25-0013a9fc61d7} | AutoRun\command : G:\Startme.exe
################## | Listing |
[01/10/2013 21:42:58 | A | 2 Ko] - C:\DelFix.txt
[02/10/2013 21:15:42 | A | 9 Ko] - C:\UsbFix [Scan 1] PC-DE-JOJO.txt
[02/10/2013 23:38:05 | A | 9 Ko] - C:\UsbFix [Clean 1] PC-DE-JOJO.txt
[02/11/2006 08:25:08 | A | 0 Ko] - C:\config.sys
[12/03/2007 15:33:00 | RASH | 0 Ko] - C:\MSDOS.SYS
[12/03/2007 15:33:00 | RASH | 0 Ko] - C:\IO.SYS
[15/09/2010 06:11:42 | ASH | 2393536 Ko] - C:\pagefile.sys
[15/09/2010 10:17:12 | A | 379 Ko] - C:\vcredist_x86.log
[16/12/2010 01:05:43 | A | 1 Ko] - C:\debug.log
[23/10/2011 17:26:14 | A | 0 Ko] - C:\prefs.js
[04/12/2012 22:15:32 | A | 0 Ko] - C:\user.js
[02/11/2006 13:17:19 | SHD | 1 Ko] - C:\$Recycle.Bin
[02/11/2006 12:23:09 | A | 0 Ko] - C:\autoexec.bat
[10/03/2007 01:30:28 | RAS | 8 Ko] - C:\BOOTSECT.BAK
[10/03/2007 01:30:27 | RASH | 429 Ko] - C:\bootmgr
[02/11/2006 15:02:24 | SHD | 0 Ko] - C:\Documents and Settings
[10/03/2007 01:30:26 | SHD | 13868 Ko] - C:\Boot
[10/03/2007 01:29:26 | D | 120405 Ko] - C:\Drivers
[12/03/2007 15:11:55 | D | 27830 Ko] - C:\Documentation
[02/11/2006 13:18:33 | RD | 73110809 Ko] - C:\Users
[15/09/2010 10:23:20 | D | 98934 Ko] - C:\Infineon
[15/09/2010 11:28:43 | RHD | 8217 Ko] - C:\MSOCache
[19/09/2010 12:36:03 | D | 180 Ko] - C:\Intel
[04/10/2010 10:17:09 | D | 0 Ko] - C:\VAIO Entertainment
[04/10/2010 09:43:17 | D | 120269 Ko] - C:\Update
[14/12/2012 00:13:08 | D | 3953 Ko] - C:\SiLabs
[13/03/2013 15:30:28 | D | 4480 Ko] - C:\3c615af712f4f76cb8bcfd908f
[25/09/2013 21:00:09 | D | 4043 Ko] - C:\AdwCleaner
[02/11/2006 13:18:33 | HD | 1978798 Ko] - C:\ProgramData
[02/11/2006 13:18:33 | RD | 6870377 Ko] - C:\Program Files
[15/09/2010 06:11:42 | SHD | 0 Ko] - C:\System Volume Information
[30/09/2013 10:14:11 | D | 3563 Ko] - C:\UsbFix
[02/11/2006 13:18:34 | D | 14274476 Ko] - C:\Windows
[28/12/2011 06:14:38 | R | 44 Ko] - E:\Digimoto+v4[1].03.zip
[28/12/2011 06:25:04 | R | 4084 Ko] - E:\OBD-DIAGV1.01.00.zip
[28/12/2011 06:39:52 | R | 27601 Ko] - E:\BlueSoleil_2.3_standard_Release_060728.zip
[07/06/2012 04:56:52 | R | 0 Ko] - E:\software instruction.txt
[04/11/2011 17:32:54 | R | 187 Ko] - E:\ScanMaster.rar
[28/12/2011 06:10:52 | R | 27676 Ko] - E:\digimoto403fw.rar
[28/12/2011 06:14:38 | R | 203 Ko] - E:\prscnkg.rar
[28/12/2011 06:30:00 | R | 14273 Ko] - E:\PALMERPEPCMSCANV2.4.8.rar
[28/12/2011 06:30:20 | R | 1054 Ko] - E:\ProScan_Setup_4-0a.rar
[28/12/2011 06:30:44 | R | 1047 Ko] - E:\ProScanUsersManual.pdf
[28/12/2011 06:23:42 | R | 22960 Ko] - E:\microsfot_framework20chs.exe
[28/12/2011 06:40:20 | R | 1408 Ko] - E:\BlueSoleil.exe
[09/08/2012 14:12:42 | R | 7856 Ko] - E:\ELM327 Microsoft Word ??.doc
[30/07/2010 08:30:00 | D | 16795 Ko] - E:\ScanMaster-ELM v2.1
[16/06/2012 04:50:06 | D | 1560 Ko] - E:\CDM 2.02.04 WHQL Certified
[23/05/2009 11:31:20 | D | 1965 Ko] - E:\USB Driver
[16/06/2012 04:49:22 | D | 1870 Ko] - E:\windows vista usb drive
[16/06/2012 04:49:26 | D | 4908 Ko] - E:\wOBDCRAZY
[16/06/2012 04:49:28 | D | 964 Ko] - E:\scantool_net113win
[16/06/2012 04:49:52 | D | 5174 Ko] - E:\OBD2Spy
[16/06/2012 04:49:54 | D | 3122 Ko] - E:\EasyOBDII
[16/06/2012 04:50:00 | D | 11864 Ko] - E:\CP2102 usb driver
[28/09/2012 06:02:40 | D | 2686 Ko] - E:\obdsm0352
[13/01/2013 01:37:42 | AH | 4 Ko] - G:\._.Trashes
[13/01/2013 01:37:42 | AHD | 2344539 Ko] - G:\.Trashes
[26/05/2013 09:54:04 | A | 3371 Ko] - G:\Mandibule et ATM.pdf
[25/12/2012 16:19:08 | RAH | 4 Ko] - G:\._autorun.inf
[25/12/2012 16:19:08 | RAH | 0 Ko] - G:\autorun.inf
[25/12/2012 16:19:07 | AH | 53 Ko] - G:\.VolumeIcon.ico
[25/12/2012 16:19:07 | AH | 40 Ko] - G:\.VolumeIcon.icns
[13/01/2013 01:39:09 | AH | 12 Ko] - G:\.DS_Store
[25/12/2012 17:40:18 | SHD | 690965 Ko] - G:\$RECYCLE.BIN
[25/12/2012 16:19:08 | RAH | 4 Ko] - G:\._
[15/11/2011 00:16:50 | AD | 468928 Ko] - G:\revision Dorsales Pierre BONCHE
[13/04/2012 19:19:36 | AD | 2490484 Ko] - G:\REVISION VISCERAL PINGLAUT
[15/04/2012 06:56:26 | AD | 767146 Ko] - G:\SEMINAIRE AVRIL 2012
[13/04/2012 19:19:36 | AD | 2490484 Ko] - G:\révision viscéral Pinglaut
[15/11/2011 00:07:57 | AD | 1476272 Ko] - G:\revision K Pierre BONCHE
[21/01/2012 17:47:50 | AD | 152062547 Ko] - G:\CSOF 2
[11/05/2012 11:04:54 | AD | 2656059 Ko] - G:\Révisions viscéral Pinglaut 2
[14/04/2012 21:00:32 | AD | 192518896 Ko] - G:\CSOF
[30/08/2011 14:38:28 | AD | 18067175 Ko] - G:\Cours
[14/10/2012 11:30:52 | AD | 12078394 Ko] - G:\seminaire octobre 2012
[15/11/2011 00:28:16 | AD | 704519 Ko] - G:\Tripode WEBSTER
[25/12/2012 16:36:36 | SHD | 13 Ko] - G:\RECYCLER
[14/04/2013 01:52:22 | D | 67571370 Ko] - G:\5A CSO
[14/04/2013 02:38:08 | D | 5895258 Ko] - G:\5A-Séminaire 7
[14/04/2013 02:42:08 | D | 8721400 Ko] - G:\5A-Séminaire 8
[24/05/2013 16:12:50 | D | 10551405 Ko] - G:\5A- Séminaire 9
[25/12/2012 16:19:01 | SHD | 0 Ko] - G:\System Volume Information
[13/01/2013 00:37:43 | AH | 4 Ko] - H:\._.Trashes
[13/01/2013 00:37:43 | HD | 0 Ko] - H:\.Trashes
[13/01/2013 00:37:43 | HD | 1438 Ko] - H:\.Spotlight-V100
[25/12/2012 15:19:08 | RAH | 0 Ko] - H:\autorun.inf
[25/12/2012 15:19:08 | RAH | 4 Ko] - H:\._autorun.inf
[25/12/2012 15:19:08 | AH | 53 Ko] - H:\.VolumeIcon.ico
[25/12/2012 15:19:08 | AH | 40 Ko] - H:\.VolumeIcon.icns
[25/12/2012 16:40:26 | SHD | 0 Ko] - H:\$RECYCLE.BIN
[25/12/2012 15:19:08 | RAH | 4 Ko] - H:\._
[25/12/2012 15:19:09 | D | 529643 Ko] - H:\LaCie Setup
[25/12/2012 15:19:08 | SHD | 7 Ko] - H:\System Volume Information
################## | Vaccin |
C:\Autorun.inf - Vaccin créé par UsbFix (El Desaparecido)
G:\Autorun.inf - Vaccin créé par UsbFix (El Desaparecido)
H:\Autorun.inf - Vaccin créé par UsbFix (El Desaparecido)
################## | E.O.F |
http://sosvirus.net |