USB FIX

tiphaine -  
 Utilisateur anonyme -
Bonjour,

J'ai un soucis avec mon disque dur externe qui contient toutes mes photos mes fichiers ce sont transformés en raccourci et donc je ne peux plus y accéder.
J'ai fait un rapport d'analyse avec USBFIX. Que dois-je faire après, j'ai peur qu'en mettant supprimer mes fichiers s'effacent.

Merci.

8 réponses

  1. Utilisateur anonyme
     
    bonjour,
    déjà pour commencer, copie et colle ton rapport de Usbfix ici :-)
    0
  2. tiphaine
     
    bonjour,

    Voici le rapport :

    CPU: AMD Athlon(tm) Dual Core Processor 4450B
    CPU 2: AMD Athlon(tm) Dual Core Processor 4450B
    Microsoft® Windows Vista(TM) Édition Familiale Basique (6.0.6001 32-Bit) # Service Pack 1
    Internet Explorer 7.0.6001.18000

    Pare-feu Windows: Désactivé /!\
    Antivirus: Total Protection 4.9.0.387 [Enabled | (!) Outdated]
    Firewall: Total Protection 4.0 [Enabled]
    RAM -> 2942 Mo
    C:\ (%systemdrive%) -> Disque fixe # 217 Go (156 Go libre(s) - 72%) [] # NTFS
    D:\ -> Disque fixe # 16 Go (10 Go libre(s) - 63%) [HP_RECOVERY] # NTFS
    E:\ -> Disque fixe # 298 Go (209 Go libre(s) - 70%) [HITACHI] # FAT32
    F:\ -> CD-ROM

    ################## | Éléments infectieux |

    Présent! C:\Users\lili\veamua.exe
    Présent! E:\Autorun.inf
    Présent! E:\$RECYCLE.BIN.lnk
    Présent! E:\Documents.lnk
    Présent! E:\Music.lnk
    Présent! E:\Pictures.lnk
    Présent! E:\Recycled.lnk
    Présent! E:\System Volume Information.lnk
    Présent! E:\Video.lnk

    ################## | Registre |

    Présent! HKCU\Software\Microsoft\Windows\CurrentVersion\Run|veamua

    ################## | Mountpoints2 |

    HKCU\.\.\.\.\Explorer\MountPoints2\{28e321ea-e000-11df-81e8-002264bc937c}
    Shell\AutoRun\Command = C:\Windows\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL G:\vEaMua.EXe

    ################## | Vaccin |

    C:\autorun.inf -> Dossier créé par Flash_Disinfector (sUBs)
    D:\autorun.inf -> Dossier créé par Flash_Disinfector (sUBs)

    ################## | E.O.F |
    0
  3. Utilisateur anonyme
     
    relance usbfix, choisis l'option 2 et poste son rapport

    0
  4. tiphaine
     
    L'option 2 est supprimer ou listing ?
    0
  5. Vous n’avez pas trouvé la réponse que vous recherchez ?

    Posez votre question
  6. tiphaine
     
    Pare-feu Windows: Désactivé /!\
    Antivirus: Total Protection 4.9.0.387 [Enabled | (!) Outdated]
    Firewall: Total Protection 4.0 [Enabled]
    RAM -> 2942 Mo
    C:\ (%systemdrive%) -> Disque fixe # 217 Go (156 Go libre(s) - 72%) [] # NTFS
    D:\ -> Disque fixe # 16 Go (10 Go libre(s) - 63%) [HP_RECOVERY] # NTFS
    E:\ -> Disque fixe # 298 Go (209 Go libre(s) - 70%) [HITACHI] # FAT32
    F:\ -> CD-ROM

    ################## | Éléments infectieux |

    Supprimé! C:\Users\lili\veamua.exe
    Supprimé! E:\veamua.exe
    Supprimé! E:\veamuax.exe
    Supprimé! C:\$RECYCLE.BIN\S-1-5-21-630941651-3320730440-3663294316-1001
    Supprimé! D:\$RECYCLE.BIN\S-1-5-21-630941651-3320730440-3663294316-1001
    Supprimé! E:\$RECYCLE.BIN.lnk
    Supprimé! E:\Documents.lnk
    Supprimé! E:\Music.lnk
    Supprimé! E:\Pictures.lnk
    Supprimé! E:\Recycled.lnk
    Supprimé! E:\System Volume Information.lnk
    Supprimé! E:\Video.lnk

    ################## | Registre |

    Supprimé! HKCU\Software\Microsoft\Windows\CurrentVersion\Run|veamua

    ################## | Mountpoints2 |

    Supprimé! HKCU\.\.\.\.\Explorer\MountPoints2\{28e321ea-e000-11df-81e8-002264bc937c}

    ################## | Listing |

    [11/11/2010 - 19:28:24 | SHD ] C:\$RECYCLE.BIN
    [18/09/2006 - 22:43:36 | N | 24] C:\autoexec.bat
    [11/11/2010 - 15:07:17 | AD ] C:\autorun.inf
    [15/03/2008 - 00:50:14 | D ] C:\boot
    [21/01/2008 - 03:34:29 | RASH | 333203] C:\bootmgr
    [15/03/2008 - 00:50:16 | N | 8192] C:\BOOTSECT.BAK
    [11/11/2010 - 19:21:36 | D ] C:\Config.Msi
    [18/09/2006 - 22:43:37 | N | 10] C:\config.sys
    [18/09/2010 - 18:59:03 | SHD ] C:\Documents and Settings
    [24/01/2009 - 08:32:31 | D ] C:\fslrdr
    [11/11/2010 - 19:15:43 | ASH | 3085426688] C:\hiberfil.sys
    [24/01/2009 - 08:39:13 | D ] C:\hp
    [16/05/2010 - 10:11:53 | N | 32] C:\HPCD.SYS
    [24/01/2009 - 08:26:34 | RHD ] C:\MSOCache
    [11/11/2010 - 19:15:42 | ASH | 3399237632] C:\pagefile.sys
    [21/01/2008 - 03:43:50 | D ] C:\PerfLogs
    [11/11/2010 - 19:20:37 | D ] C:\Program Files
    [11/11/2010 - 19:20:37 | HD ] C:\ProgramData
    [18/09/2010 - 19:13:20 | D ] C:\SWSetup
    [11/11/2010 - 19:20:34 | SHD ] C:\System Volume Information
    [18/09/2010 - 19:13:05 | D ] C:\system.sav
    [11/11/2010 - 19:28:24 | D ] C:\UsbFix
    [11/11/2010 - 19:26:21 | A | 2764] C:\UsbFix.txt
    [18/09/2010 - 19:12:06 | D ] C:\Users
    [11/11/2010 - 19:20:50 | D ] C:\windows
    [11/11/2010 - 19:28:24 | SHD ] D:\$RECYCLE.BIN
    [11/11/2010 - 15:07:18 | AD ] D:\autorun.inf
    [19/09/2010 - 04:53:56 | D ] D:\BOOT
    [30/08/2006 - 10:38:02 | SH | 435752] D:\bootmgr
    [04/06/2008 - 16:24:14 | SH | 7387] D:\Desktop.ini
    [16/05/2010 - 10:10:32 | N | 24] D:\DRECOVERY
    [16/05/2010 - 10:11:53 | N | 32] D:\HPCD.sys
    [16/05/2010 - 10:10:32 | N | 28] D:\HP_RECOVERY
    [18/09/2010 - 19:13:15 | N | 1256] D:\Master.log
    [24/01/2009 - 08:38:01 | N | 561960] D:\MASTER.LOG.COPY
    [16/05/2010 - 10:10:32 | N | 14] D:\NTFS
    [19/09/2010 - 04:53:56 | D ] D:\preload
    [24/01/2009 - 08:37:49 | N | 182323] D:\protect.arabic
    [24/01/2009 - 08:37:49 | N | 181572] D:\protect.basque
    [24/01/2009 - 08:37:49 | N | 182298] D:\protect.bulgarian
    [24/01/2009 - 08:37:49 | N | 181572] D:\protect.catalan
    [24/01/2009 - 08:37:49 | N | 181898] D:\protect.chinese hong kong
    [24/01/2009 - 08:37:49 | N | 181916] D:\protect.chinese simplified
    [24/01/2009 - 08:37:49 | N | 181898] D:\protect.chinese traditional
    [24/01/2009 - 08:37:49 | N | 181936] D:\protect.croatian
    [24/01/2009 - 08:37:50 | N | 181735] D:\protect.czech
    [24/01/2009 - 08:37:50 | N | 181680] D:\protect.danish
    [24/01/2009 - 08:37:50 | N | 181605] D:\protect.dutch
    [24/01/2009 - 08:37:50 | N | 181648] D:\protect.ed
    [24/01/2009 - 08:37:50 | N | 181648] D:\protect.english
    [24/01/2009 - 08:37:50 | N | 183351] D:\protect.estonian
    [24/01/2009 - 08:37:50 | N | 181648] D:\protect.finnish
    [24/01/2009 - 08:37:50 | N | 181616] D:\protect.french
    [24/01/2009 - 08:37:50 | N | 181572] D:\protect.galician
    [24/01/2009 - 08:37:50 | N | 181650] D:\protect.german
    [24/01/2009 - 08:37:50 | N | 182717] D:\protect.greek
    [24/01/2009 - 08:37:50 | N | 182626] D:\protect.hebrew
    [24/01/2009 - 08:37:50 | N | 181696] D:\protect.hungarian
    [24/01/2009 - 08:37:50 | N | 181535] D:\protect.italian
    [24/01/2009 - 08:37:50 | N | 182351] D:\protect.japanese
    [24/01/2009 - 08:37:50 | N | 182043] D:\protect.korean
    [24/01/2009 - 08:37:50 | N | 182105] D:\protect.latvian
    [24/01/2009 - 08:37:50 | N | 181932] D:\protect.lithuanian
    [24/01/2009 - 08:37:50 | N | 181562] D:\protect.norwegian
    [24/01/2009 - 08:37:50 | N | 181741] D:\protect.polish
    [24/01/2009 - 08:37:50 | N | 181617] D:\protect.portuguese
    [24/01/2009 - 08:37:50 | N | 181866] D:\protect.portuguese brazilian
    [24/01/2009 - 08:37:50 | N | 182016] D:\protect.romanian
    [24/01/2009 - 08:37:50 | N | 211936] D:\protect.russian
    [24/01/2009 - 08:37:51 | N | 181959] D:\protect.serbian latin
    [24/01/2009 - 08:37:51 | N | 181954] D:\protect.slovak
    [24/01/2009 - 08:37:51 | N | 181936] D:\protect.slovenian
    [24/01/2009 - 08:37:51 | N | 181572] D:\protect.spanish
    [24/01/2009 - 08:37:51 | N | 181605] D:\protect.swedish
    [24/01/2009 - 08:37:51 | N | 182576] D:\protect.thai
    [24/01/2009 - 08:37:51 | N | 181829] D:\protect.turkish
    [24/01/2009 - 08:37:51 | N | 181648] D:\protect.ukranian
    [19/09/2010 - 04:53:57 | RD ] D:\RECOVERY
    [08/10/2008 - 14:49:42 | N | 373] D:\renamewinpeshl.bat
    [19/09/2010 - 04:53:56 | D ] D:\SOURCES
    [24/01/2009 - 08:37:54 | N | 42] D:\st_log.ini
    [19/09/2010 - 05:58:15 | SHD ] D:\System Volume Information
    [16/05/2010 - 19:29:08 | N | 8494] D:\Winrelauncher.exe.LOG
    [23/10/2009 - 15:21:58 | D ] E:\fscommand
    [23/10/2009 - 15:22:06 | D ] E:\Get_Started_for_Mac.app
    [12/03/2010 - 20:44:42 | D ] E:\ArcBackupDeviceInfo
    [12/03/2010 - 20:54:18 | D ] E:\For Sync
    [13/03/2010 - 10:52:54 | D ] E:\famille
    [25/02/2010 - 14:45:56 | D ] E:\film
    [15/03/2010 - 10:21:34 | SHD ] E:\$RECYCLE.BIN
    [27/03/2010 - 07:40:24 | D ] E:\FILM le 26.03.10
    [05/05/2010 - 21:21:56 | D ] E:\Tiphaine
    [25/08/2010 - 00:01:32 | D ] E:\Recycled
    [25/08/2010 - 00:01:32 | SHD ] E:\System Volume Information
    [11/11/2010 - 19:21:48 | N | 337] E:\fscommand.lnk
    [11/11/2010 - 19:21:48 | N | 365] E:\Get_Started_for_Mac.app.lnk
    [11/11/2010 - 19:21:48 | N | 357] E:\ArcBackupDeviceInfo.lnk
    [11/11/2010 - 19:21:48 | N | 335] E:\For Sync.lnk
    [11/11/2010 - 19:21:48 | N | 333] E:\famille.lnk
    [11/11/2010 - 19:21:48 | N | 327] E:\film.lnk
    [11/11/2010 - 19:21:48 | N | 351] E:\FILM le 26.03.10.lnk
    [11/11/2010 - 19:21:48 | N | 335] E:\Tiphaine.lnk
    [11/11/2010 - 19:21:48 | N | 339] E:\New Folder.lnk
    [11/11/2010 - 19:21:48 | N | 337] E:\Passwords.lnk

    ################## | Vaccin |

    C:\Autorun.inf -> Dossier créé par UsbFix (El Desaparecido & C_XX)
    D:\Autorun.inf -> Dossier créé par UsbFix (El Desaparecido & C_XX)
    E:\Autorun.inf -> Dossier créé par UsbFix (El Desaparecido & C_XX)
    0
  7. Utilisateur anonyme
     
    essaie d'accéder à ton DD externe pour visionner tes photos

    donne moi des nouvelles :-)

    0
  8. tiphaine
     
    Tout à l'air de bien fonctionner merci !! :-)
    0
  9. Utilisateur anonyme
     
    * pour supprimer les outils de désinfection
    :

    Télecharge Delfix sur ton bureau :
    http://sd-1.archive-host.com/membres/up/17959594961240255/DelFix.exe

    *Clique sur le bouton « Suppression » et poste son rapport sur ton prochain message
    **Pour le désinstaller, il suffit de le relancer et cliquer sur le bouton de désinstallation.

    as tu d'autres soucis ?

    0