Supprimer le virus RECYCLER.exe
Fermé
Bonjour,
s'il vous plais j'ai un probleme avec le virus RECYCLER.exe.
quand j'ai envoyée un docier de mon pc à mon flache disque qui'il été vide avans g trouver un docier qui s'appel RECYCLER.exe,il ma dit que c'est un virus, j'ai analisé mon flache mais l'antivirus n'a detecté aucune virus c'est bizar.et puisque j'ai copiée le docier de mon pc c'est à dire que ce virus et dedans mais quand j'ai fais un scane complet j'ai rien trouvée.
il ma dit qu'il faut afficher les doccier cachés en utilisant panneau de configuration -->option des docier -->afficher les dociers cachés mais les docier reste cachée et quand je revien au option des docier je trouve l'option afficher les dociers cachés desactivé je ne sais pas pourquoi se probleme et j'arrive pas a le resoudre
s'il vous plais aidez moi pour detruir ce virus et si vous avez d'autre idée dite moi plais.
merci d'avance.
s'il vous plais j'ai un probleme avec le virus RECYCLER.exe.
quand j'ai envoyée un docier de mon pc à mon flache disque qui'il été vide avans g trouver un docier qui s'appel RECYCLER.exe,il ma dit que c'est un virus, j'ai analisé mon flache mais l'antivirus n'a detecté aucune virus c'est bizar.et puisque j'ai copiée le docier de mon pc c'est à dire que ce virus et dedans mais quand j'ai fais un scane complet j'ai rien trouvée.
il ma dit qu'il faut afficher les doccier cachés en utilisant panneau de configuration -->option des docier -->afficher les dociers cachés mais les docier reste cachée et quand je revien au option des docier je trouve l'option afficher les dociers cachés desactivé je ne sais pas pourquoi se probleme et j'arrive pas a le resoudre
s'il vous plais aidez moi pour detruir ce virus et si vous avez d'autre idée dite moi plais.
merci d'avance.
Configuration: Windows XP Internet Explorer 7.0
26 réponses
-
Contributeur sécuritéslt
pas de panique
C_XX & Chiquitine29 ont crée ce qu'il te faut !
Télécharge et install UsbFix de C_XX & Chiquitine29
Branche tes sources de données externes à ton PC, (clé USB, disque dur externe, etc...) susceptible d'avoir été infectées sans les ouvrir
# Double clic sur le raccourci UsbFix présent sur ton bureau .
# Choisis l'option 1 ( Recherche )
# Laisse travailler l'outil.
# Ensuite post le rapport UsbFix.txt qui apparaitra.
# Note : Le rapport UsbFix.txt est sauvegardé a la racine du disque. ( C:\UsbFix.txt )
( CTRL+A Pour tout selectionner , CTRL+C pour copier et CTRL+V pour coller )
# Note : "Process.exe", une composante de l'outil, est détecté par certains antivirus (AntiVir, Dr.Web, Kaspersky Anti-Virus) comme étant un RiskTool.
Il ne s'agit pas d'un virus, mais d'un utilitaire destiné à mettre fin à des processus.
Mis entre de mauvaises mains, cet utilitaire pourrait arrêter des logiciels de sécurité (Antivirus, Firewall...) d'où l'alerte émise par ces antivirus.-
-
-
-
bonsoir, j'ai le même problème et voici mon rapport:
############################## | UsbFix V 7.109 | [Suppression]
Utilisateur: michel bernard (Administrateur) # YOUR-409757439B
Mis à jour le 22/02/2013 par El Desaparecido
Lancé à 11:41:55 | 25/02/2013
Site Web: https://www.sosvirus.net/
Contact: contact@sosvirus.org
PC: TOSHIBA (TOSHIBA NB200) (X86-based PC)
CPU: Intel(R) Atom(TM) CPU N280 @ 1.66GHz (1662)
RAM -> [Total : 1014 | Free : 260]
BIOS: Ver 1.00PARTTBL4
BOOT: Normal boot
OS: Microsoft Windows XP Édition familiale (5.1.2600 32-Bit) # Service Pack 3
WB: Windows Internet Explorer 7.0.5730.13
SC: Security Center Service [Enabled]
WU: Windows Update Service [Enabled]
FW: Windows FireWall Service [Enabled]
C:\ (%systemdrive%) -> Disque fixe # 75 Go (39 Go libre(s) - 53%) [XP] # NTFS
D:\ -> Disque fixe # 73 Go (69 Go libre(s) - 94%) [Data] # NTFS
E:\ -> Disque fixe # 298 Go (9 Go libre(s) - 3%) [SAMSUNG] # NTFS
F:\ -> Disque amovible # 4 Go (2 Go libre(s) - 47%) [] # FAT32
G:\ -> Disque amovible # 8 Go (4 Go libre(s) - 55%) [] # FAT32
################## | Processus Stoppés |
Stoppé! C:\WINDOWS\system32\spoolsv.exe (1860)
Stoppé! C:\WINDOWS\Explorer.EXE (1868)
Stoppé! C:\WINDOWS\system32\acs.exe (1916)
Stoppé! C:\Program Files\TOSHIBA\ConfigFree\CFSvcs.exe (432)
Stoppé! C:\WINDOWS\system32\ThpSrv.exe (728)
Stoppé! C:\WINDOWS\system32\TODDSrv.exe (792)
Stoppé! c:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosBtSrv.exe (856)
Stoppé! C:\WINDOWS\system32\SearchIndexer.exe (1416)
Stoppé! C:\WINDOWS\system32\igfxtray.exe (260)
Stoppé! C:\WINDOWS\system32\igfxsrvc.exe (1248)
Stoppé! C:\WINDOWS\system32\hkcmd.exe (580)
Stoppé! C:\WINDOWS\system32\igfxpers.exe (636)
Stoppé! C:\WINDOWS\RTHDCPL.EXE (724)
Stoppé! C:\Program Files\TOSHIBA\ConfigFree\NDSTray.exe (516)
Stoppé! C:\Program Files\TOSHIBA\E-KEY\CeEKey.exe (532)
Stoppé! C:\WINDOWS\system32\TDispVol.exe (872)
Stoppé! C:\Program Files\TOSHIBA\Utilitaire de zoom TOSHIBA\SmoothView.exe (1344)
Stoppé! C:\WINDOWS\system32\ZoomingHook.exe (1396)
Stoppé! C:\Program Files\TOSHIBA\TouchPad\TPTray.exe (1884)
Stoppé! C:\WINDOWS\system32\thpsrv.exe (1644)
Stoppé! C:\Program Files\Atheros\ACU.exe (1704)
Stoppé! C:\Program Files\Apoint2K\Apoint.exe (1820)
Stoppé! C:\Program Files\Camera Assistant Software for Toshiba\traybar.exe (1996)
Stoppé! C:\Program Files\AVG Secure Search\vprot.exe (2068)
Stoppé! C:\WINDOWS\system32\TPSBattM.exe (2132)
Stoppé! C:\WINDOWS\system32\ctfmon.exe (2144)
Stoppé! C:\Program Files\TOSHIBA\Toshiba Online Product Information\topi.exe (2168)
Stoppé! C:\Program Files\Messenger\msmsgs.exe (2208)
Stoppé! C:\Program Files\Microsoft ActiveSync\wcescomm.exe (2232)
Stoppé! C:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosBtMng.exe (2288)
Stoppé! C:\Program Files\McAfee Security Scan\3.0.318\SSScheduler.exe (2312)
Stoppé! C:\PROGRA~1\MICROS~4\rapimgr.exe (2332)
Stoppé! C:\Program Files\Windows Desktop Search\WindowsSearch.exe (2340)
Stoppé! c:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosA2dp.exe (3560)
Stoppé! c:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosBtHid.exe (3752)
Stoppé! c:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosBtHsp.exe (2916)
Stoppé! C:\Program Files\Apoint2K\Apntex.exe (3712)
Stoppé! C:\WINDOWS\system32\wuauclt.exe (1744)
Stoppé! C:\Program Files\Mozilla Firefox\firefox.exe (1684)
################## | Éléments infectieux |
Supprimé! C:\DOCUME~1\MICHEL~1\LOCALS~1\Temp\DataCard_Setup.exe
Supprimé! C:\DOCUME~1\MICHEL~1\LOCALS~1\Temp\ose00000.exe
Supprimé! D:\setupSNK.exe
Supprimé! D:\AUTORUN.INF
(!) Fichiers temporaires supprimés.
################## | Registre |
################## | Mountpoints2 |
Supprimé! HKCU\.\.\.\.\Explorer\MountPoints2\{03b4c672-2219-11e1-8e7d-002308a5455f}
Supprimé! HKCU\.\.\.\.\Explorer\MountPoints2\{0fb37812-14cf-11e1-8e67-002308a5455f}
Supprimé! HKCU\.\.\.\.\Explorer\MountPoints2\{35e283db-254f-11de-8ca7-00235a07d42c}
Supprimé! HKCU\.\.\.\.\Explorer\MountPoints2\{6ea21dd2-f9d9-11de-8db2-00235afc9474}
Supprimé! HKCU\.\.\.\.\Explorer\MountPoints2\{7f4ce2a8-255d-11de-96e5-00235a07d42c}
Supprimé! HKCU\.\.\.\.\Explorer\MountPoints2\{a7fb5a43-17ed-11e1-8e71-002308a5455f}
Supprimé! HKCU\.\.\.\.\Explorer\MountPoints2\{aaccac64-2f49-11df-8dba-002258fb4a8c}
################## | Listing |
[24/08/2010 - 17:06:49 | D ] C:\$AVG
[15/03/2010 - 00:42:46 | N | 34802] C:\ASLog.txt
[09/04/2009 - 05:13:23 | N | 0] C:\AUTOEXEC.BAT
[31/12/2009 - 17:16:36 | N | 233] C:\boot.ini
[14/04/2008 - 13:00:00 | N | 4952] C:\Bootfont.bin
[25/02/2013 - 06:11:56 | D ] C:\Config.Msi
[09/04/2009 - 05:13:23 | N | 0] C:\CONFIG.SYS
[31/12/2009 - 17:17:21 | D ] C:\Documents and Settings
[25/02/2013 - 06:08:00 | ASH | 1063702528] C:\hiberfil.sys
[09/04/2009 - 05:38:03 | D ] C:\I386
[31/12/2009 - 17:18:06 | D ] C:\Intel
[09/04/2009 - 05:13:23 | N | 0] C:\IO.SYS
[23/01/2013 - 11:41:19 | D ] C:\kleaner.tmp
[09/04/2009 - 05:13:23 | N | 0] C:\MSDOS.SYS
[02/11/2011 - 20:59:07 | RHD ] C:\MSOCache
[14/04/2008 - 13:00:00 | N | 47564] C:\NTDETECT.COM
[14/04/2008 - 13:00:00 | N | 252240] C:\ntldr
[25/02/2013 - 06:07:59 | ASH | 1598029824] C:\pagefile.sys
[25/02/2013 - 11:17:40 | D ] C:\Program Files
[13/03/2010 - 20:00:51 | SHD ] C:\RECYCLER
[09/04/2009 - 06:11:42 | N | 1832] C:\RHDSetup.log
[09/04/2009 - 05:38:10 | D ] C:\SUPPORT
[08/04/2009 - 17:57:49 | N | 176] C:\SWSTAMP.TXT
[25/01/2013 - 07:05:33 | SHD ] C:\System Volume Information
[10/04/2009 - 00:53:01 | D ] C:\Toshiba
[25/02/2013 - 11:44:31 | D ] C:\UsbFix
[25/02/2013 - 11:45:11 | A | 5610] C:\UsbFix [Clean 1] YOUR-409757439B.txt
[06/06/2010 - 16:22:28 | D ] C:\VALUEADD
[25/02/2013 - 06:10:44 | D ] C:\WINDOWS
[16/05/2012 - 08:58:38 | D ] D:\0db2b9e0c081ab041e8d0acead0e
[17/05/2012 - 10:39:20 | D ] D:\1143c195d0e1151fc9fb
[04/01/2010 - 00:04:09 | D ] D:\12bb6241e6a29abcc68954
[17/05/2012 - 01:46:14 | D ] D:\3f3424430d474e6734d9cfa7aaf1b790
[03/01/2010 - 20:07:26 | D ] D:\597c43a6ec0ca845ffab
[03/01/2010 - 22:25:40 | D ] D:\7c6680354387b167cad4a4550f
[18/05/2012 - 14:58:24 | D ] D:\84a3bdb6e92ab652b2041e8e6a
[03/01/2010 - 22:25:33 | D ] D:\945b1a8bc35789d42b3e7f7481
[03/01/2010 - 20:07:32 | D ] D:\c19856bcd2ea7e3afc5c
[22/05/2012 - 14:49:59 | D ] D:\ec8112c4e2a16e562951a22f49
[22/05/2012 - 13:42:32 | D ] D:\ef89866d4a37491dfacf04b54a01db9a
[01/01/2010 - 03:11:40 | D ] D:\HDDRecovery
[20/04/2009 - 18:49:48 | N | 11] D:\R10806FR.tag
[09/10/2011 - 19:39:18 | SHD ] D:\RECYCLER
[29/02/2012 - 07:05:13 | D ] D:\SMRTNTKY
[24/01/2013 - 07:55:08 | SHD ] D:\System Volume Information
################## | Vaccin |
C:\Autorun.inf -> Vaccin créé par UsbFix (El Desaparecido)
D:\Autorun.inf -> Vaccin créé par UsbFix (El Desaparecido)
################## | E.O.F | https://www.sosvirus.net/ |
Pouvez vous m'aider ?
merci -
############################## | UsbFix V 7.152 | [Recherche]
Utilisateur: WINDOWS (Administrateur) # WINDOWS-PC
Mis à jour le 20/11/2013 par El Desaparecido - Team SosVirus
Lancé à 11:43:19 | 04/12/2013
Site Web : http://www.usbfix.net
Forum : http://www.sosvirus.net/
Upload Malware : http://www.sosvirus.net/upload_malware.php
Contact : http://www.usbfix.net/contact/
PC: Hewlett-Packard (308A)
CPU: Intel(R) Core(TM)2 Duo CPU T5870 @ 2.00GHz
RAM -> [Total : 3063 | Free : 1570]
Bios: Hewlett-Packard
Boot: Normal boot
OS: Microsoft Windows 7 Edition Intégrale (6.1.7600 32-Bit)
WB: Windows Internet Explorer : 9.0.8112.16421
WB: Mozilla Firefox : 15.0.1
SC: Security Center Service [Enabled]
WU: Windows Update Service [Enabled]
AV: avast! Antivirus [Enabled | Updated]
AS: Windows Defender : 6.1.7600.16385 (win7_rtm.090713-1255)
FW: Windows FireWall Service [Enabled]
C:\ (%systemdrive%) -> Disque fixe # 146 Go (72 Go libre(s) - 49%) [] # NTFS
D:\ -> Disque fixe # 152 Go (32 Go libre(s) - 21%) [] # NTFS
E:\ -> CD-ROM
G:\ -> Disque amovible # 7 Go (6 Go libre(s) - 80%) [USB TOSHIBA] # FAT32
################## | Processus Actif |
C:\Windows\system32\csrss.exe (ID: 404 |ParentID: 396)
C:\Windows\system32\wininit.exe (ID: 460 |ParentID: 396)
C:\Windows\system32\csrss.exe (ID: 468 |ParentID: 448)
C:\Windows\system32\services.exe (ID: 520 |ParentID: 460)
C:\Windows\system32\lsass.exe (ID: 536 |ParentID: 460)
C:\Windows\system32\lsm.exe (ID: 544 |ParentID: 460)
C:\Windows\system32\winlogon.exe (ID: 684 |ParentID: 448)
C:\Windows\system32\svchost.exe (ID: 708 |ParentID: 520)
C:\Windows\system32\svchost.exe (ID: 804 |ParentID: 520)
C:\Windows\System32\svchost.exe (ID: 860 |ParentID: 520)
C:\Windows\System32\svchost.exe (ID: 964 |ParentID: 520)
C:\Windows\system32\svchost.exe (ID: 1004 |ParentID: 520)
C:\Windows\system32\svchost.exe (ID: 1176 |ParentID: 520)
C:\Windows\system32\svchost.exe (ID: 1280 |ParentID: 520)
C:\Windows\system32\svchost.exe (ID: 1472 |ParentID: 520)
C:\Program Files\AVAST Software\Avast\AvastSvc.exe (ID: 1504 |ParentID: 520)
C:\Windows\System32\spoolsv.exe (ID: 1872 |ParentID: 520)
C:\Program Files\Common Files\DeviceHelper\DeviceManager.exe (ID: 2028 |ParentID: 520)
C:\Windows\system32\HPSIsvc.exe (ID: 368 |ParentID: 520)
C:\Windows\system32\taskhost.exe (ID: 452 |ParentID: 520)
C:\Windows\system32\Dwm.exe (ID: 1264 |ParentID: 964)
C:\Windows\Explorer.EXE (ID: 1536 |ParentID: 1092)
C:\Windows\system32\taskeng.exe (ID: 1376 |ParentID: 1004)
C:\Windows\system32\Rundll32.exe (ID: 1380 |ParentID: 1376)
C:\Program Files\Protected Search\ProtectedSearch.exe (ID: 2008 |ParentID: 1376)
C:\ProgramData\DatacardService\HWDeviceService.exe (ID: 1980 |ParentID: 520)
C:\ProgramData\DatacardService\DCSHelper.exe (ID: 2100 |ParentID: 1980)
C:\Program Files\Google\Update\1.3.21.165\GoogleCrashHandler.exe (ID: 2216 |ParentID: 1732)
C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe (ID: 2432 |ParentID: 1536)
C:\Windows\System32\hkcmd.exe (ID: 2580 |ParentID: 1536)
C:\Windows\System32\igfxpers.exe (ID: 2596 |ParentID: 1536)
C:\Windows\system32\igfxsrvc.exe (ID: 2640 |ParentID: 708)
C:\Program Files\Activ Software\ActivDriver\ActivControl2.exe (ID: 2716 |ParentID: 1536)
C:\Program Files\USB Disk Security\USBGuard.exe (ID: 2744 |ParentID: 1536)
C:\Program Files\AVAST Software\Avast\avastui.exe (ID: 2756 |ParentID: 1536)
C:\Program Files\Winamp\winampa.exe (ID: 2808 |ParentID: 1536)
C:\Program Files\Activ Software\ActivDriver\activmgr.exe (ID: 2816 |ParentID: 2716)
C:\Program Files\LG Electronics\LG EV-DO Rev.A USB Modem\Modem Software\REVAService.exe (ID: 2848 |ParentID: 1536)
C:\Program Files\Skype\Phone\Skype.exe (ID: 2860 |ParentID: 1536)
C:\Users\WINDOWS\AppData\Roaming\SkypEmoticons\SE.exe (ID: 2940 |ParentID: 1536)
C:\Users\WINDOWS\AppData\Local\iLivid\iLivid.exe (ID: 2960 |ParentID: 1536)
C:\Program Files\Internet Download Manager\IDMan.exe (ID: 3048 |ParentID: 1536)
C:\Users\WINDOWS\AppData\Local\CatalinaGroup\Update\1.3.25.204\CatalinaCrashHandler.exe (ID: 3068 |ParentID: 2972)
C:\Program Files\RioStudio\Server\Server.exe (ID: 3244 |ParentID: 1536)
C:\Program Files\Nitro PDF\Reader 2\NitroPDFReaderDriverService2.exe (ID: 3436 |ParentID: 520)
C:\Program Files\Photodex\ProShowGold\ScsiAccess.exe (ID: 3572 |ParentID: 520)
C:\ProgramData\Skype\Toolbars\Skype C2C Service\c2c_service.exe (ID: 3652 |ParentID: 520)
C:\Windows\system32\svchost.exe (ID: 4000 |ParentID: 520)
C:\Program Files\LemurLeap\updateLemurLeap.exe (ID: 4088 |ParentID: 520)
C:\Program Files\LemurLeap\bin\utilLemurLeap.exe (ID: 352 |ParentID: 520)
C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE (ID: 2368 |ParentID: 520)
C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe (ID: 2564 |ParentID: 2368)
C:\Windows\system32\SearchIndexer.exe (ID: 2888 |ParentID: 520)
C:\Windows\system32\svchost.exe (ID: 3452 |ParentID: 520)
C:\Windows\system32\svchost.exe (ID: 3156 |ParentID: 520)
C:\Windows\system32\svchost.exe (ID: 3904 |ParentID: 520)
C:\Program Files\Windows Media Player\wmpnetwk.exe (ID: 4312 |ParentID: 520)
C:\Users\WINDOWS\AppData\Local\Google\Chrome\Application\chrome.exe (ID: 4768 |ParentID: 1536)
C:\Users\WINDOWS\AppData\Local\Google\Chrome\Application\chrome.exe (ID: 4924 |ParentID: 4768)
C:\Users\WINDOWS\AppData\Local\Google\Chrome\Application\chrome.exe (ID: 5244 |ParentID: 4768)
C:\Users\WINDOWS\AppData\Local\Google\Chrome\Application\chrome.exe (ID: 5532 |ParentID: 4768)
C:\Windows\System32\svchost.exe (ID: 6080 |ParentID: 520)
C:\Windows\system32\wuauclt.exe (ID: 1884 |ParentID: 1004)
C:\Users\WINDOWS\AppData\Local\Google\Chrome\Application\chrome.exe (ID: 6072 |ParentID: 4768)
C:\Windows\system32\cmd.exe (ID: 648 |ParentID: 1536)
C:\Windows\system32\conhost.exe (ID: 5008 |ParentID: 468)
C:\Users\WINDOWS\AppData\Local\Google\Chrome\Application\chrome.exe (ID: 928 |ParentID: 4768)
C:\Users\WINDOWS\AppData\Local\Google\Chrome\Application\chrome.exe (ID: 1888 |ParentID: 4768)
C:\UsbFix\Go.exe (ID: 4600 |ParentID: 1540)
C:\Windows\System32\WUDFHost.exe (ID: 3424 |ParentID: 964)
\\?\C:\Windows\system32\wbem\WMIADAP.EXE (ID: 896 |ParentID: 1004)
C:\Windows\system32\wbem\wmiprvse.exe (ID: 2900 |ParentID: 708)
C:\Windows\system32\wbem\wmiprvse.exe (ID: 168 |ParentID: 708)
################## | Regedit Run |
04 - HKLM\SOFTWARE | Run : [GrooveMonitor] - "C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe"
04 - HKLM\SOFTWARE | Run : [NeroCheck] - C:\Windows\system32\NeroCheck.exe
04 - HKLM\SOFTWARE | Run : [TkBellExe] - "C:\Program Files\Real\RealPlayer\update\realsched.exe" -osboot
04 - HKLM\SOFTWARE | Run : [IgfxTray] - C:\Windows\system32\igfxtray.exe
04 - HKLM\SOFTWARE | Run : [HotKeysCmds] - C:\Windows\system32\hkcmd.exe
04 - HKLM\SOFTWARE | Run : [Persistence] - C:\Windows\system32\igfxpers.exe
04 - HKLM\SOFTWARE | Run : [ActivControl] - C:\Program Files\Activ Software\ActivDriver\ActivControl2.exe
04 - HKLM\SOFTWARE | Run : [USB Security] - C:\Program Files\USB Disk Security\USBGuard.exe
04 - HKLM\SOFTWARE | Run : [AvastUI.exe] - "C:\Program Files\AVAST Software\Avast\AvastUI.exe" /nogui
04 - HKLM\SOFTWARE | Run : [WinampAgent] - "C:\Program Files\Winamp\winampa.exe"
04 - HKLM\SOFTWARE | Run : [20131121] - C:\Program Files\AVAST Software\Avast\setup\emupdate\25d669ff-fa6b-4e77-95be-072b15d2b673.exe /check
04 - HKLM\SOFTWARE | RunOnce : [] -
04 - HKU\S-1-5-19\SOFTWARE | Run : [Sidebar] - %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun
04 - HKU\S-1-5-20\SOFTWARE | Run : [Sidebar] - %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun
04 - HKU\S-1-5-21-363042910-2385499109-2152790226-1000\SOFTWARE | Run : [uTorrent] - "C:\Program Files\uTorrent\uTorrent.exe" /MINIMIZED
04 - HKU\S-1-5-21-363042910-2385499109-2152790226-1000\SOFTWARE | Run : [REVAService] - C:\Program Files\LG Electronics\LG EV-DO Rev.A USB Modem\Modem Software\REVAService.exe
04 - HKU\S-1-5-21-363042910-2385499109-2152790226-1000\SOFTWARE | Run : [Media Finder] - "C:\Program Files\Media Finder\Media Finder.exe" /opentotray
04 - HKU\S-1-5-21-363042910-2385499109-2152790226-1000\SOFTWARE | Run : [Skype] - "C:\Program Files\Skype\Phone\Skype.exe" /minimized /regrun
04 - HKU\S-1-5-21-363042910-2385499109-2152790226-1000\SOFTWARE | Run : [Facebook Update] - "C:\Users\WINDOWS\AppData\Local\Facebook\Update\FacebookUpdate.exe" /c /nocrashserver
04 - HKU\S-1-5-21-363042910-2385499109-2152790226-1000\SOFTWARE | Run : [Serviecs.vbs] - "C:\Users\WINDOWS\AppData\Local\Temp\Serviecs.vbs"
04 - HKU\S-1-5-21-363042910-2385499109-2152790226-1000\SOFTWARE | Run : [Viber] - "C:\Users\WINDOWS\AppData\Local\Viber\Viber.exe" StartMinimized
04 - HKU\S-1-5-21-363042910-2385499109-2152790226-1000\SOFTWARE | Run : [se] - "C:\Users\WINDOWS\AppData\Roaming\SkypEmoticons\SE.exe" /minimized
04 - HKU\S-1-5-21-363042910-2385499109-2152790226-1000\SOFTWARE | Run : [iLivid] - "C:\Users\WINDOWS\AppData\Local\iLivid\iLivid.exe" -autorun
04 - HKU\S-1-5-21-363042910-2385499109-2152790226-1000\SOFTWARE | Run : [CatalinaGroup Update] - "C:\Users\WINDOWS\AppData\Local\CatalinaGroup\Update\CatalinaUpdate.exe" /c
04 - HKU\S-1-5-21-363042910-2385499109-2152790226-1000\SOFTWARE | Run : [BackgroundContainer] - "C:\Windows\system32\Rundll32.exe" "C:\Users\WINDOWS\AppData\Local\Conduit\BackgroundContainer\BackgroundContainer.dll",DllRun
04 - HKU\S-1-5-21-363042910-2385499109-2152790226-1000\SOFTWARE | Run : [IDMan] - C:\Program Files\Internet Download Manager\IDMan.exe /onboot
04 - HKU\S-1-5-19\SOFTWARE | RunOnce : [mctadmin] - C:\Windows\System32\mctadmin.exe
04 - HKU\S-1-5-20\SOFTWARE | RunOnce : [mctadmin] - C:\Windows\System32\mctadmin.exe
04 - HKU\S-1-5-18\SOFTWARE | RunOnce : [SPReview] - "C:\Windows\System32\SPReview\SPReview.exe" /sp:1 /errorfwlink:"http://go.microsoft.com/fwlink/?LinkID=122915" /build:7601
################## | Recherche générique |
Présent! D:\Horloge à installer...exe
Présent! D:\zPharaoh.exe
Présent! G:\oomra 2013-1434.exe
Présent! G:\svt.exe
Présent! G:\les élève en europe.exe
Présent! G:\RECYCLER.exe
Présent! G:\oomra 2013-1434 .exe
Présent! G:\SVT .exe
Présent! G:\les élève en europe .exe
Présent! G:\RECYCLER .exe
Présent! C:\Users\WINDOWS\AppData\Local\NERDF87.tmp
Présent! C:\Users\WINDOWS\AppData\Roaming\Microsoft\SYSTEM\cste
Présent! C:\Users\WINDOWS\AppData\Local\Temp\APNSetup.exe.tmp
Présent! C:\Users\WINDOWS\AppData\Local\Temp\APNSetup1.exe.tmp
Présent! C:\Users\WINDOWS\AppData\Local\Temp\ADMIN.vbe
Présent! C:\Users\WINDOWS\AppData\Local\Temp\CPBA.bat
Présent! C:\Windows\Tasks\Update23.job
Présent! G:\Recycler\S-8-7-51-6701716238-7502128570-118303462-0338\nFEEDunT.cpl
Présent! G:\Recycler\S-8-7-51-6701716238-7502128570-118303462-0338
Présent! G:\Recycler\S-8-7-51-6701716238-7502128570-118303462-0338\nmwPHrfY.cpl
Présent! G:\Recycler\S-8-7-51-6701716238-7502128570-118303462-0338\lGcZFiWd.cpl
Présent! G:\Recycler\S-8-7-51-6701716238-7502128570-118303462-0338\vviHIFIm.cpl
Présent! G:\Recycler\S-8-7-51-6701716238-7502128570-118303462-0338\UtLSJHms.cpl
Présent! G:\Recycler\S-8-7-51-6701716238-7502128570-118303462-0338\vBlArZIV.cpl
Présent! G:\Recycler\S-8-7-51-6701716238-7502128570-118303462-0338\nqqPuMoE.cpl
Présent! G:\Recycler\S-8-7-51-6701716238-7502128570-118303462-0338\MurNOhLa.cpl
Présent! G:\Recycler\S-8-7-51-6701716238-7502128570-118303462-0338\qIZlMFiB.cpl
Présent! G:\Recycler\S-8-7-51-6701716238-7502128570-118303462-0338\aNkjCrYu.cpl
Présent! G:\Recycler\S-8-7-51-6701716238-7502128570-118303462-0338\NYWmWKPu.cpl
Présent! G:\Recycler\S-8-7-51-6701716238-7502128570-118303462-0338\BcCVIVke.cpl
Présent! G:\Recycler\S-8-7-51-6701716238-7502128570-118303462-0338\DWmZlXqK.cpl
Présent! G:\Recycler\S-8-7-51-6701716238-7502128570-118303462-0338\digTBZrr.cpl
Présent! G:\Recycler\S-8-7-51-6701716238-7502128570-118303462-0338\dBycKTax.cpl
Présent! G:\Recycler\S-8-7-51-6701716238-7502128570-118303462-0338\LAkeEPXh.cpl
Présent! G:\Recycler\S-8-7-51-6701716238-7502128570-118303462-0338\gsBLcpZm.cpl
Présent! G:\Recycler\S-8-7-51-6701716238-7502128570-118303462-0338\XAitJLJi.cpl
Présent! G:\Recycler\S-8-7-51-6701716238-7502128570-118303462-0338\WlkGYCit.cpl
Présent! G:\Recycler\S-8-7-51-6701716238-7502128570-118303462-0338\SRrqcCxX.cpl
Présent! G:\Recycler\S-8-7-51-6701716238-7502128570-118303462-0338\QKGgLFoI.cpl
Présent! G:\Recycler\S-8-7-51-6701716238-7502128570-118303462-0338\JvLZpsOj.cpl
Présent! G:\Recycler\S-8-7-51-6701716238-7502128570-118303462-0338\sYoTFIWG.cpl
Présent! G:\Recycler\S-8-7-51-6701716238-7502128570-118303462-0338\mEsQjTxn.cpl
Présent! G:\Recycler\S-8-7-51-6701716238-7502128570-118303462-0338\LdIbbNfC.cpl
Présent! G:\Recycler\S-8-7-51-6701716238-7502128570-118303462-0338\RRUbxSxf.cpl
Présent! G:\Recycler\S-8-7-51-6701716238-7502128570-118303462-0338\OpNiWPxR.cpl
Présent! G:\Recycler\S-8-7-51-6701716238-7502128570-118303462-0338\pUCwGfwT.cpl
Présent! G:\Recycler\S-8-7-51-6701716238-7502128570-118303462-0338\bpMfTPuD.cpl
Présent! G:\Recycler\S-8-7-51-6701716238-7502128570-118303462-0338\ryUPQXTc.cpl
Présent! G:\Recycler\S-8-7-51-6701716238-7502128570-118303462-0338\BDJTSxOl.cpl
Présent! G:\Recycler\S-8-7-51-6701716238-7502128570-118303462-0338\LrLSqARf.cpl
Présent! G:\Recycler\S-8-7-51-6701716238-7502128570-118303462-0338\qvDbwrhI.cpl
Présent! G:\Recycler\S-8-7-51-6701716238-7502128570-118303462-0338\ylCjAEsO.cpl
Présent! G:\Recycler\S-8-7-51-6701716238-7502128570-118303462-0338\EqhboyxV.cpl
Présent! G:\Recycler\S-8-7-51-6701716238-7502128570-118303462-0338\fursHUGA.cpl
Présent! G:\Recycler\S-8-7-51-6701716238-7502128570-118303462-0338\mloZagmJ.cpl
Présent! G:\Recycler\S-8-7-51-6701716238-7502128570-118303462-0338\ubWaWHac.cpl
Présent! G:\Recycler\S-8-7-51-6701716238-7502128570-118303462-0338\PhcRiqmE.cpl
Présent! G:\Recycler\S-8-7-51-6701716238-7502128570-118303462-0338\JVxRfkAw.cpl
Présent! G:\Recycler\S-8-7-51-6701716238-7502128570-118303462-0338\kbLwOjoB.cpl
Présent! G:\Recycler\S-8-7-51-6701716238-7502128570-118303462-0338\fVPkeEVJ.cpl
Présent! G:\Recycler\S-8-7-51-6701716238-7502128570-118303462-0338\aTxsrpti.cpl
Présent! G:\Recycler\S-8-7-51-6701716238-7502128570-118303462-0338\YFaHYEir.cpl
Présent! G:\Recycler\S-8-7-51-6701716238-7502128570-118303462-0338\yyKbSxiX.cpl
Présent! G:\Recycler\S-8-7-51-6701716238-7502128570-118303462-0338\ZVTTXugD.cpl
Présent! G:\Recycler\S-8-7-51-6701716238-7502128570-118303462-0338\BQZXoEwp.cpl
Présent! G:\Recycler\S-8-7-51-6701716238-7502128570-118303462-0338\mnRYuByK.cpl
Présent! G:\Recycler\S-8-7-51-6701716238-7502128570-118303462-0338\LgkRUHnp.cpl
Présent! G:\Recycler\S-8-7-51-6701716238-7502128570-118303462-0338\WBcQReNm.cpl
Présent! G:\Recycler\S-8-7-51-6701716238-7502128570-118303462-0338\xvUpLUem.cpl
Présent! G:\Recycler\S-8-7-51-6701716238-7502128570-118303462-0338\XpEvtAeK.cpl
Présent! G:\Recycler\S-8-7-51-6701716238-7502128570-118303462-0338\BwZMvspi.cpl
Présent! G:\Recycler\S-8-7-51-6701716238-7502128570-118303462-0338\SbDVGaGq.cpl
Présent! G:\Recycler\S-8-7-51-6701716238-7502128570-118303462-0338\COBQBoId.cpl
Présent! G:\Recycler\S-8-7-51-6701716238-7502128570-118303462-0338\GiqMuvIp.cpl
Présent! G:\Recycler\S-8-7-51-6701716238-7502128570-118303462-0338\ZLYkBaAi.cpl
Présent! G:\Recycler\S-8-7-51-6701716238-7502128570-118303462-0338\pvpypoat.cpl
Présent! G:\Recycler\S-8-7-51-6701716238-7502128570-118303462-0338\amNZJajH.cpl
Présent! G:\Recycler\S-8-7-51-6701716238-7502128570-118303462-0338\qQtdCvwX.cpl
Présent! G:\Recycler\S-8-7-51-6701716238-7502128570-118303462-0338\KjxCHOol.cpl
################## | Référence de comparaison MD5 |
Md5 : E11A368AAA023AC803DFF823CC918920 -> C:\Users\WINDOWS\AppData\Local\Temp\ADMIN.vbe
Md5 : 6983856C4F46B13309C7CBDDFB5E0A01 -> G:\RECYCLER.exe
Md5 : C6B2F301DA7E51FE40E146E5E2A2E3F7 -> G:\RECYCLER .exe
Md5 : 6983856C4F46B13309C7CBDDFB5E0A01 -> G:\RECYCLER.exe
Md5 : C6B2F301DA7E51FE40E146E5E2A2E3F7 -> G:\RECYCLER .exe
Md5 : 6983856C4F46B13309C7CBDDFB5E0A01 -> G:\RECYCLER.exe
################## | Comparaison MD5 |
Présent! Md5 : E11A368AAA023AC803DFF823CC918920 -> C:\Users\WINDOWS\AppData\Local\Temp\ADMIN.vbe
Présent! Md5 : 6983856C4F46B13309C7CBDDFB5E0A01 -> G:\RECYCLER.exe
Présent! Md5 : C6B2F301DA7E51FE40E146E5E2A2E3F7 -> G:\oomra 2013-1434 .exe
Présent! Md5 : C6B2F301DA7E51FE40E146E5E2A2E3F7 -> G:\SVT .exe
Présent! Md5 : C6B2F301DA7E51FE40E146E5E2A2E3F7 -> G:\les élève en europe .exe
Présent! Md5 : C6B2F301DA7E51FE40E146E5E2A2E3F7 -> G:\RECYCLER .exe
################## | Registre |
Présent! HKLM\Software\Microsoft\Windows\CurrentVersion\Policies\System|EnableLUA -> 0
Présent! HKLM\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\bitguard.exe
Présent! HKLM\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\bprotect.exe
Présent! HKLM\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\browserdefender.exe
Présent! HKLM\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\browserprotect.exe
Présent! HKU\S-1-5-21-363042910-2385499109-2152790226-1000\Software\Microsoft\Windows\CurrentVersion\Run|Serviecs.vbs
Présent! HKCU\Software\Microsoft\Windows\CurrentVersion\Run|Serviecs.vbs
################## | Vaccin |
(!) Cet ordinateur n'est pas vacciné!
################## | E.O.F | http://www.usbfix.net - http://www.sosvirus.net |
-