Scan Malwarebytes, Fichiers infectés

Chamsy Messages postés 23 Statut Membre -  
 gen-hackman -
Bonjour,

J'ai éffectué un scan avec malwarebytes-anti-malware, et il m'a détecté des infections. Pourriez vous m'aider a interpreter ce scan et me dire les bonnes démarches. Je n'ai pas supprimé ce qu'il a trouvé par peur d'effacer des choses importantes.
Voici les resultats du scan:

Malwarebytes' Anti-Malware 1.50.1.1100
www.malwarebytes.org

Version de la base de données: 5363

Windows 5.1.2600 Service Pack 3
Internet Explorer 8.0.6001.18702

15/04/2011 00:28:12
mbam-log-2011-04-15 (00-27-59).txt

Type d'examen: Examen complet (C:\|)
Elément(s) analysé(s): 229514
Temps écoulé: 47 minute(s), 21 seconde(s)

Processus mémoire infecté(s): 0
Module(s) mémoire infecté(s): 0
Clé(s) du Registre infectée(s): 4
Valeur(s) du Registre infectée(s): 3
Elément(s) de données du Registre infecté(s): 8
Dossier(s) infecté(s): 0
Fichier(s) infecté(s): 3

Processus mémoire infecté(s):
(Aucun élément nuisible détecté)

Module(s) mémoire infecté(s):
(Aucun élément nuisible détecté)

Clé(s) du Registre infectée(s):
HKEY_CLASSES_ROOT\CLSID\{B922D405-6D13-4A2B-AE89-08A030DA4402} (Adware.WidgiToolbar) -> No action taken.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{B922D405-6D13-4A2B-AE89-08A030DA4402} (Adware.WidgiToolbar) -> No action taken.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Settings\{B922D405-6D13-4A2B-AE89-08A030DA4402} (Adware.WidgiToolbar) -> No action taken.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{B922D405-6D13-4A2B-AE89-08A030DA4402} (Adware.WidgiToolbar) -> No action taken.

Valeur(s) du Registre infectée(s):
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\URLSearchHooks\{B922D405-6D13-4A2B-AE89-08A030DA4402} (Adware.WidgiToolbar) -> Value: {B922D405-6D13-4A2B-AE89-08A030DA4402} -> No action taken.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar\{B922D405-6D13-4A2B-AE89-08A030DA4402} (Adware.WidgiToolbar) -> Value: {B922D405-6D13-4A2B-AE89-08A030DA4402} -> No action taken.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\SharedDLLs\C:\PROGRAM FILES\FICHIERS COMMUNS\SPIGOT\WTXPCOM\COMPONENTS\WIDGITOOLBARFF.DLL (Adware.WidgiToolbar) -> Value: WIDGITOOLBARFF.DLL -> No action taken.

Elément(s) de données du Registre infecté(s):
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\Main\Search Page (Hijack.SearchPage) -> Bad: (http://www.cherche.us) Good: (http://www.google.com) -> No action taken.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\Main\Default_Page_URL (Hijack.StartPage) -> Bad: (http://www.cherche.us) Good: (http://www.google.com) -> No action taken.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\Main\Start Page_bak (Hijack.StartPage) -> Bad: (http://www.cherche.us) Good: (http://www.google.com) -> No action taken.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\Main\Search Bar (Hijack.SearchPage) -> Bad: (http://www.cherche.us) Good: (http://www.google.com) -> No action taken.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\Main\Default_Search_URL (Hijack.SearchPage) -> Bad: (http://ww12.cherche.us Good: (http://www.google.com) -> No action taken.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\SearchURL\SearchAssistant (Hijack.SearchPage) -> Bad: (http://www.cherche.us) Good: (https://www.google.com/?gws_rd=ssl -> No action taken.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Security Center\FirewallDisableNotify (PUM.Disabled.SecurityCenter) -> Bad: (1) Good: (0) -> No action taken.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\FirewallDisableNotify (PUM.Disabled.SecurityCenter) -> Bad: (1) Good: (0) -> No action taken.

Dossier(s) infecté(s):
(Aucun élément nuisible détecté)

Fichier(s) infecté(s):
c:\program files\pdfforge toolbar\IE\4.3\pdfforgetoolbarie.dll (Adware.WidgiToolbar) -> No action taken.
c:\program files\fichiers communs\Spigot\wtxpcom\components\widgitoolbarff.dll (Adware.WidgiToolbar) -> No action taken.
c:\program files\pdfforge toolbar\widgihelper.exe (Adware.WidgiToolbar) -> No action taken.

Help me please !

60 réponses

  • 1
  • 2
  • 3
Résumé de la discussion

Un balayage Malwarebytes a détecté des éléments nuisibles, principalement des clés et des valeurs de registre liées à Adware.WidgiToolbar et un redirect de page, indiquant une compromission du navigateur.
Parmi les résultats, 3 fichiers et plusieurs clés de registre signalés infectés, dont des DLL et des entrées de démarrage, et un hijack de page d’accueil a été noté.
Les échanges suggèrent un nettoyage via Ad-Remover, qui a supprimé des clés et fichiers indésirables et réinitialisé les entrées liées à WidgiToolbar, suivi d’instructions pour un scan supplémentaire avec OTL.
En cas de persistance des symptômes après nettoyage, la discussion évoque une réparation du démarrage avec CD Windows (boot.ini et MBR) et des commandes en invite pour rétablir le système.

Généré automatiquement par IA
sur la base des meilleures réponses
  1. gen-hackman
     
    salut mbam n'est pas à jour peu importe

    ▶ Télécharge ici : Ad-remover sur ton bureau :

    ▶ Déconnecte toi et ferme toutes applications en cours !

    si tu as XP => double clique
    si tu as Vista ou windows 7 => clic droit "executer en tant que...."


    ▶ sur "Ad-R.exe" pour lancer l'installation et laisse les paramètres d'installation par défaut .

    ▶ clique le raccourci Ad-remover qui est sur ton bureau pour lancer l'outil .

    ▶ Au menu principal choisis "option Nettoyer" et tape sur [entrée] .

    ▶ Laisse travailler l'outil et ne touche à rien ...

    ▶ Poste le rapport qui apparait à la fin , sur le forum ...

    ( Le rapport est sauvegardé aussi sous C:\Ad-report.log )
    ( CTRL+A Pour tout sélectionner , CTRL+C pour copier et CTRL+V pour coller )

    0
  2. Chamsy Messages postés 23 Statut Membre
     
    Voici ce que cela donne :

    ======= RAPPORT D'AD-REMOVER 2.0.0.2,G | UNIQUEMENT XP/VISTA/7 =======

    Mis à jour par TeamXscript le 12/04/11
    Contact: AdRemover[DOT]contact[AT]gmail[DOT]com
    Site web: http://www.teamxscript.org

    C:\Program Files\Ad-Remover\main.exe (CLEAN [1]) -> Lancé à 01:02:32 le 15/04/2011, Mode normal

    Microsoft Windows XP Professionnel Service Pack 3 (X86)
    utilisateur@PC01 ( )

    ============== ACTION(S) ==============

    Service: "Application Updater" Stoppé et supprimé

    Fichier supprimé: C:\Program Files\Mozilla FireFox\extensions\pdfforge@mybrowserbar.com
    Fichier supprimé: C:\Documents and Settings\utilisateur\Application Data\Mozilla\FireFox\Profiles\q2cg1aoh.default\searchplugins\cherche.xml
    Fichier supprimé: C:\Documents and Settings\utilisateur\scriptjava.html
    Fichier supprimé: C:\Documents and Settings\utilisateur\tmp1.7
    Dossier supprimé: C:\Program Files\Application Updater
    Dossier supprimé: C:\Documents and Settings\utilisateur\Application Data\pdfforge
    Dossier supprimé: C:\Program Files\pdfforge Toolbar
    Dossier supprimé: C:\Documents and Settings\utilisateur\Application Data\Search Settings
    Dossier supprimé: C:\Program Files\Fichiers communs\Spigot

    (!) -- Fichiers temporaires supprimés.

    -- Fichier ouvert: C:\Documents and Settings\utilisateur\Application Data\Mozilla\FireFox\Profiles\q2cg1aoh.default\Prefs.js --
    Ligne supprimée: user_pref("keyword.URL", "hxxp://www.cherche.us/Result.php?cx=partner-pub-0420647136319153%3A5n6ugpj...
    -- Fichier Fermé --

    Clé supprimée: HKLM\Software\Classes\CLSID\{B922D405-6D13-4A2B-AE89-08A030DA4402}
    Clé supprimée: HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{B922D405-6D13-4A2B-AE89-08A030DA4402}
    Clé supprimée: HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{B922D405-6D13-4A2B-AE89-08A030DA4402}
    Clé supprimée: HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{B922D405-6D13-4A2B-AE89-08A030DA4402}
    Clé supprimée: HKLM\Software\Classes\CLSID\{E49F0B41-3322-11D4-AEFE-00C04F61025C}
    Clé supprimée: HKLM\Software\Application Updater
    Clé supprimée: HKLM\Software\pdfforge
    Clé supprimée: HKLM\Software\Search Settings
    Clé supprimée: HKCU\Software\pdfforge
    Clé supprimée: HKCU\Software\Search Settings
    Clé supprimée: HKCU\Software\AppDataLow\Software\pdfforge
    Clé supprimée: HKCU\Software\AppDataLow\Software\Search Settings
    Clé supprimée: HKLM\Software\Classes\Installer\Products\7A931B0A5D8E8E947AFB2124E1562280
    Clé supprimée: HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\Userdata\S-1-5-18\Products\7A931B0A5D8E8E947AFB2124E1562280
    Clé supprimée: HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{557C21FE-7274-410D-853E-9ED4471BF193}
    Clé supprimée: HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{E312764E-7706-43F1-8DAB-FCDD2B1E416D}

    Valeur supprimée: HKLM\Software\Microsoft\Windows\CurrentVersion\Run|binternet
    Valeur supprimée: HKLM\Software\Microsoft\Windows\CurrentVersion\Run|SearchSettings
    Valeur supprimée: HKLM\Software\Microsoft\Internet Explorer\Toolbar|{B922D405-6D13-4A2B-AE89-08A030DA4402}

    ============== SCAN ADDITIONNEL ==============

    **** Mozilla Firefox Version [4.0 (fr)] ****

    Searchplugins\bing.xml ( hxxp://www.bing.com/search)
    Components\browsercomps.dll (Mozilla Foundation)
    Extensions\{AB2CE124-6272-4b12-94A9-7303C7397BD1} (Skype extension )

    -- C:\Documents and Settings\utilisateur\Application Data\Mozilla\FireFox\Profiles\q2cg1aoh.default --
    Extensions\{2f17f610-5e97-4fed-828f-9940b7b577a4} (TV-Fox)
    Extensions\{9669CC8F-B388-42FE-86F4-CB5E7F5A8BDC}(2) (MR Tech Toolkit)
    Prefs.js - browser.download.lastDir, C:\\Documents and Settings\\utilisateur\\Mes documents\\ECE\\Administration\\Uniformation\\Cat...
    Prefs.js - browser.startup.homepage, hxxp://www.apbif.org/
    Prefs.js - browser.startup.homepage_override.buildID, 20110318052756
    Prefs.js - browser.startup.homepage_override.mstone, rv:2.0

    ========================================

    **** Internet Explorer Version [8.0.6001.18702] ****

    HKCU_Main|Default_Page_URL - hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&pver=6&ar=msnhome
    HKCU_Main|Default_Search_URL - hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
    HKCU_Main|Search bar - hxxp://go.microsoft.com/fwlink/?linkid=54896
    HKCU_Main|Start Page - hxxp://fr.msn.com/
    HKLM_Main|Default_Page_URL - hxxp://go.microsoft.com/fwlink/?LinkId=54896
    HKLM_Main|Default_Search_URL - hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
    HKLM_Main|Search bar - hxxp://search.msn.com/spbasic.htm
    HKLM_Main|Search Page - hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
    HKLM_Main|Start Page - hxxp://fr.msn.com/
    HKCU_URLSearchHooks|{B922D405-6D13-4A2B-AE89-08A030DA4402} (x)
    HKLM_Extensions\{4EAFEF58-EEFA-4116-983D-03B49BCBFFFE} - "PalTalk" (C:\Program Files\Paltalk Messenger\Paltalk.exe,476)
    HKLM_Extensions\{85d1f590-48f4-11d9-9669-0800200c9a66} - "?" (?)
    HKLM_Extensions\{e2e2dd38-d088-4134-82b7-f2ba38496583} - "?" (?)
    BHO\{5C255C8A-E604-49b4-9D64-90988571CECB} (?)

    ========================================

    C:\Program Files\Ad-Remover\Quarantine: 74 Fichier(s)
    C:\Program Files\Ad-Remover\Backup: 14 Fichier(s)

    C:\Ad-Report-CLEAN[1].txt - 15/04/2011 01:02:38 (1515 Octet(s))

    Fin à: 01:03:45, 15/04/2011

    ============== E.O.F ==============
    0
  3. gen-hackman
     
    Télécharge ici :OTL

    enregistre le sur ton Bureau.

    si tu as XP => double clique
    si tu as Vista ou windows 7 => clic droit "executer en tant que...."


    sur OTL.exe pour le lancer.

    => Configuration

    ▶Clic sur Analyse.

    A la fin du scan, le Bloc-Notes va s'ouvrir avec le rapport (OTL.txt).

    Ce fichier est sur ton Bureau (en général C:\Documents and settings\le_nom_de_ta_session\OTL.txt)

    ▶▶▶ NE LE POSTE PAS SUR LE FORUM (il est trop long)

    Pour me le transmettre clique sur ce lien : http://www.cijoint.fr/

    ▶ Clique sur Parcourir et cherche le fichier ci-dessus.

    ▶ Clique sur Ouvrir.

    ▶ Clique sur "Cliquez ici pour déposer le fichier".

    juste au niveau du bouton , en fin de chargement du fichier , Un lien de cette forme apparaitra :

    http://www.cijoint.fr/cjlink.php?file=cjge368/cijSKAP5fU.txt

    ▶ Copie ce lien dans ta réponse.

    ▶▶ Tu feras la meme chose avec le "Extra.txt" qui logiquement sera aussi sur ton bureau.
    0
  4. Chamsy Messages postés 23 Statut Membre
     
    Voici le premier lien :

    http://www.cijoint.fr/cjlink.php?file=cj201104/cijty0DWLc.txt

    Voici le second :

    http://www.cijoint.fr/cjlink.php?file=cj201104/cijHAMzXLM.txt

    J'aimerai bien savoir faire tout cela !

    Merci pour tout
    0
  5. Vous n’avez pas trouvé la réponse que vous recherchez ?

    Posez votre question
  6. gen-hackman
     
    DESACTIVE TON ANTIVIRUS ET TON PAREFEU SI PRESENTS !!!!! (car l'outil est detecté a tort comme infection contenant un module qui sert à arrêter des processus , et un autre servant à prendre des droits dans le registre pour effectuer des suppressions)

    ▶ Télécharge ici :List_Kill'em

    et enregistre le sur ton bureau et lance l'installation

    Laisse coché :

    ♦ Executer List_Kill'em

    une fois terminée , clic sur "terminer"

    choisis l'option Search

    ▶ laisse travailler l'outil

    Attention : il se peut que l'outil bloque anormalement longtemps arrivé à 95%, relance-le avec le raccourci sur le bureau sans l'arreter , puis clique sur le tout petit "X" en bas de la fenetre d'accueil du programme, ca le debloquera pour finir son scan

    ▶ Poste les rapports qui apparaitront sur ton bureau : List'em.txt et More.txt

    ▶▶▶ NE LES POSTE PAS SUR LE FORUM

    Pour me le transmettre clique sur ce lien : http://www.cijoint.fr/

    ▶ Clique sur Parcourir et selectionne , un par un , les fichiers concernés apparus sur ton bureau

    ▶ Clique sur Ouvrir.

    ▶ Clique sur "Cliquez ici pour déposer le fichier".

    Un lien de cette forme :

    http://www.cijoint.fr/cjlink.php?file=265368/cijSKAP5fU.txt

    est ajouté dans la page.

    ▶ Copie ces liens dans ta réponse.
    0
  7. Chamsy Messages postés 23 Statut Membre
     
    List'em :

    http://www.cijoint.fr/cjlink.php?file=cj201104/cijSEowiY0.txt

    More :

    http://www.cijoint.fr/cjlink.php?file=cj201104/cijiHWx728.txt
    0
  8. gen-hackman
     
    toujours protections desactivées :

    ATTENTION !! ce script est réservé uniquement à cette machine , ne pas reproduire !!!!!

    ▶ Relance List&Kill'em,avec le raccourci sur ton bureau.

    mais cette fois-ci :

    ▶ choisis l'option Tools puis Script

    une fenêtre noire va s'ouvrir brievement , et List_Kill'em va se fermer

    un nouveau document texte s'ouvre , copie/colle ce en gras si dessous :


    REM:"HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run" /v "Adobe Reader Speed Launcher"
    REM:"HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run" /v "NPSStartup"
    REM:"HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run" /v ""
    ADD:"HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings" /v "ProxyOverride" /t REG_DWORD /d *.local
    REM:HKCU\Software\BB692CD5ACA2C93120313F03D91D3E77

    ▶ enregistre le document texte avec l'onglet fichier (enregistrer) de ce dernier , puis ferme-le

    laisse travailler l'outil

    poste le resultat

    ▶ Ferme List_Kill'em

    Note : le rapport est sur ton bureau : Script_(4 chiffres).txt
    0
  9. Chamsy Messages postés 23 Statut Membre
     
    Voici le résultat :

    http://www.cijoint.fr/cjlink.php?file=cj201104/cijGTg91Y8.txt
    0
  10. gen-hackman
     
    ▶ Relance List_Kill'em,avec le raccourci sur ton bureau.

    mais cette fois-ci :

    ▶ choisis l'Option Suppression

    ▶▶▶ Ne clique qu'une seule fois sur le bouton !!

    laisse travailler l'outil.

    en fin de scan la fenetre se ferme , et tu as un rapport du nom de Kill'em.txt sur ton bureau ,

    ▶ colle le contenu dans ta reponse
    0
  11. Chamsy Messages postés 23 Statut Membre
     
    Voici le contenu :

    ¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤ Kill'em by g3n-h@ckm@n 2.1.3.9 ¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤

    Mis à jour le 14/04/2011 | 23.30 par g3n-h@ckm@n
    Utilisateur : utilisateur (Administrateurs)
    Ordinateur : PC01

    Système d'exploitation : Microsoft Windows XP (32 bits)

    c:\ -> [Fixed] | [] | Total : 76230 Mo | Free : 46630 Mo -> NTFS
    d:\ -> [CDROM] | [] | Total : 0 Mo | Free : 0 Mo ->

    Scan : 02:02:50 | 15/04/2011

    ¤¤¤¤¤¤¤¤¤¤ Hosts ¤¤¤¤¤¤¤¤¤¤

    127.0.0.1 localhost

    ¤¤¤¤¤¤¤¤¤¤ Supression Fichiers | Dossiers ¤¤¤¤¤¤¤¤¤¤

    Mise en quarantaine : C:\Documents and Settings\All Users\Application Data\Temp\{5DB1DF0C-AABC-4362-8A6D-CEFDFB036E41}
    Mise en quarantaine : C:\Documents and Settings\All Users\Application Data\Temp
    Erreur de suppression : C:\Documents and Settings\All Users\Application Data\Temp
    Mise en quarantaine : C:\Documents and Settings\utilisateur\Menu Démarrer\Programmes\Démarrage\binternet.lnk
    Mise en quarantaine : C:\WINDOWS\Temp\PR65.tmp
    Mise en quarantaine : C:\WINDOWS\Temp\~GLF3248.TMP
    Mise en quarantaine : C:\WINDOWS\Temp\~GLG3248.TMP
    Mise en quarantaine : C:\WINDOWS\Temp\setup.exe
    Mise en quarantaine : C:\WINDOWS\Temp\~GL_302C.EXE

    ¤¤¤¤¤¤¤¤¤¤ Suppression Clés ¤¤¤¤¤¤¤¤¤¤

    ¤¤¤¤¤¤¤¤¤¤¤ Services néfastes ¤¤¤¤¤¤¤¤¤¤

    ¤¤¤¤¤¤¤¤¤¤ Suppression Valeurs ¤¤¤¤¤¤¤¤¤¤

    ¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤

    [HKLM\..\..\Security Center] | FirstRunDisabled = 1
    [HKLM\..\..\Security Center] | AntiVirusDisableNotify = 0
    [HKLM\..\..\Security Center] | UpdatesDisableNotify = 0
    [HKLM\..\..\Security Center] | AntiVirusOverride = 0
    [HKLM\..\..\Security Center] | FirewallOverride = 0
    [HKLM\..\..\Security Center] | FirewallDisableNotify = 1

    Fin : 02:09:13

    ¤¤¤¤¤¤¤¤¤¤¤¤¤( EOF )¤¤¤¤¤¤¤¤¤¤¤¤

    Est-ce normal qu'à la fin le nettoyage de disque s'active ?
    0
  12. gen-hackman
     
    oui justement je me demandais s'il etait bien fonctionnel sur tous les pc :)

    merci de la confirmation :)

    mets malwarebytes à jour et scan complet puis poste le rapport :)
    0
  13. Chamsy Messages postés 23 Statut Membre
     
    Puis-je brancher aussi mon disque dur externe pour vérification ou non ?

    Je crois qu'il y en a pour un bout de temps, pourrais-je te le poster demain matin le rapport si tu es OK ?
    0
  14. gen-hackman
     
    alors avant malwarebytes :

    ▶ Télécharge ici : USBFIX sur ton bureau

    branche tous tes periphériques sans les ouvrir

    /!\ Désactive provisoirement et seulement le temps de l'utilisation d'USBFIX, la protection en temps réel de ton Antivirus et de tes Antispywares, qui peuvent gêner fortement la procédure de recherche et de nettoyage de l'outil.

    si tu as XP => double clique
    si tu as Vista ou windows 7 => clic droit "executer en tant que...."


    sur l'icône Usbfix située sur ton Bureau.
    Sur la page, clique sur le bouton :

    ▶ choisi l option Suppression

    ▶ UsbFix scannera ton pc , laisse travailler l outil.

    ▶ Ensuite post le rapport UsbFix.txt qui apparaitra avec le bureau .

    ▶ Note : Le rapport UsbFix.txt est sauvegardé a la racine du disque.( C:\UsbFix.txt )

    ( CTRL+A Pour tout selectionner , CTRL+C pour copier et CTRL+V pour coller )

    0
  15. Chamsy Messages postés 23 Statut Membre
     
    ############################## | UsbFix 7.043 | [Suppression]

    Utilisateur: utilisateur (Administrateur) # PC01 [ ]
    Mis à jour le 12/04/2011 par TeamXscript
    Lancé à 02:37:50 | 15/04/2011
    Site Web: http://www.teamxscript.org
    Submit your sample: http://www.teamxscript.org/Upload.php
    Contact: TeamXscript.ElDesaparecido@gmail.com

    CPU: Intel(R) Pentium(R) D CPU 2.80GHz
    CPU 2: Intel(R) Pentium(R) D CPU 2.80GHz
    Microsoft Windows XP Professionnel (5.1.2600 32-Bit) # Service Pack 3
    Internet Explorer 8.0.6001.18702

    Antivirus: AntiVir Desktop 10.0.1.52 [(!) Disabled | (!) Outdated]
    RAM -> 2038 Mo
    C:\ (%systemdrive%) -> Disque fixe # 74 Go (46 Go libre(s) - 61%) [] # NTFS
    D:\ -> CD-ROM
    F:\ -> Disque fixe # 466 Go (234 Go libre(s) - 50%) [My Book] # FAT32

    ################## | Éléments infectieux |

    Supprimé! C:\Recycler\S-1-5-21-1482476501-1604221776-1417001333-1003
    Supprimé! C:\Recycler\S-1-5-21-321696159-428212251-2569933376-1003
    Supprimé! C:\Recycler\S-1-5-21-5024690470-6111750144-909111224-1992
    Supprimé! C:\Recycler\S-1-5-21-8441444613-2845449365-996543396-7742
    Supprimé! C:\Recycler\S-1-5-21-8746733103-3098886034-343742420-4521
    Supprimé! C:\msvcr71.dll
    Supprimé! F:\autorun.inf

    ################## | Registre |

    Supprimé! HKLM\software\microsoft\windows nt\currentversion\winlogon|Taskman

    ################## | Mountpoints2 |

    Supprimé! HKCU\.\.\.\.\Explorer\MountPoints2\{083bfd26-fdbb-11dd-be4a-806d6172696f}

    ################## | Listing |

    [15/04/2011 - 01:03:46 | N | 5367] C:\Ad-Report-CLEAN[1].txt
    [11/06/2008 - 12:44:04 | N | 6480] C:\ANYCALLMUSIC.adf
    [07/04/2009 - 10:23:44 | N | 53248] C:\Anycall_Land.dll
    [24/10/2010 - 17:16:24 | D ] C:\Audacity
    [18/02/2009 - 14:13:39 | N | 0] C:\AUTOEXEC.BAT
    [07/04/2009 - 10:45:04 | N | 77824] C:\BackupRestoreWM.dll
    [07/04/2009 - 10:45:04 | N | 33280] C:\BackupSYM.dll
    [14/09/2009 - 19:28:56 | N | 212] C:\boot.ini
    [14/04/2008 - 14:00:00 | N | 4952] C:\Bootfont.bin
    [04/08/2008 - 01:48:44 | N | 22824] C:\ceutil.dll
    [16/04/2009 - 10:38:48 | N | 32256] C:\Common.dll
    [18/02/2009 - 14:13:39 | N | 0] C:\CONFIG.SYS
    [07/04/2009 - 10:40:44 | N | 248239] C:\connect_ani.dat
    [07/04/2009 - 10:40:44 | N | 252890] C:\Connect_ATT.dat
    [07/04/2009 - 10:43:10 | N | 36864] C:\ConvLunar.dll
    [18/02/2009 - 15:04:28 | D ] C:\DELL
    [07/04/2009 - 10:44:22 | N | 16384] C:\dmstpb.dll
    [18/02/2009 - 14:21:29 | D ] C:\Documents and Settings
    [31/07/2008 - 12:14:14 | N | 54346] C:\DRM Adaptor.ndf
    [07/04/2009 - 10:23:44 | N | 237568] C:\drmcm.dll
    [16/04/2009 - 10:38:12 | N | 12288] C:\Dump.dll
    [16/04/2009 - 10:39:48 | N | 233472] C:\EmailAdaptor.dll
    [07/04/2009 - 10:23:40 | N | 3810128] C:\energetic&soothing.classifier
    [01/07/2009 - 22:08:07 | D ] C:\Exifer
    [01/07/2009 - 21:56:50 | N | 30] C:\Exiferupdate.ini
    [07/04/2009 - 10:23:40 | N | 476160] C:\EzNpsSharedLib.dll
    [07/04/2009 - 10:23:40 | N | 3821846] C:\fast&slow.classifier
    [07/04/2009 - 10:54:42 | N | 90112] C:\flashdll.dll
    [07/04/2009 - 10:39:44 | N | 319808] C:\FsAdmin64.exe
    [07/04/2009 - 10:39:44 | N | 204800] C:\FsDeviceLib64.dll
    [07/04/2009 - 10:39:44 | N | 24064] C:\FsExService64.exe
    [07/04/2009 - 10:39:44 | N | 226832] C:\FsUsbExAdmin.exe
    [07/04/2009 - 10:39:44 | N | 110592] C:\FsUsbExDevice.Dll
    [07/04/2009 - 10:39:44 | N | 147456] C:\FsUsbExDeviceLib.dll
    [07/04/2009 - 10:39:44 | N | 36608] C:\FsUsbExDisk.sys
    [07/04/2009 - 10:39:44 | N | 233472] C:\FsUsbExService.exe
    [10/04/2009 - 15:03:16 | N | 7045120] C:\FunCodecFilter.ax
    [07/04/2009 - 10:23:40 | N | 249856] C:\fun_id3tag.dll
    [07/04/2009 - 10:55:02 | N | 102400] C:\FUSCrypt.dll
    [18/03/2009 - 03:06:40 | N | 114688] C:\FUSCryptForLimo.dll
    [05/08/2004 - 22:00:00 | N | 1712128] C:\GdiPlus.dll
    [31/12/2009 - 23:41:27 | D ] C:\Help
    [07/04/2009 - 11:10:42 | N | 176128] C:\HSPIO.dll
    [31/12/2009 - 23:41:27 | D ] C:\Image
    [07/04/2009 - 10:45:06 | N | 27648] C:\InstallSYM.dll
    [07/04/2009 - 10:45:06 | N | 86016] C:\InstAppWM.dll
    [18/02/2009 - 14:13:39 | N | 0] C:\IO.SYS
    [11/12/2009 - 16:32:06 | D ] C:\Joomla
    [07/04/2009 - 10:44:22 | N | 482816] C:\JSRHandler.dll
    [18/02/2009 - 15:13:49 | D ] C:\KAV
    [15/04/2011 - 01:35:48 | D ] C:\Kill'em
    [25/08/2008 - 19:21:22 | N | 162816] C:\KMPWebModule.dll
    [07/04/2009 - 10:23:40 | N | 221281] C:\KRCaptionDll.dll
    [07/04/2009 - 10:23:46 | N | 540672] C:\KTFDRM20.dll
    [07/04/2009 - 10:23:46 | N | 659456] C:\KTFDRM_UCC.dll
    [07/04/2009 - 10:23:40 | N | 22368] C:\Lfani15u.dll
    [07/04/2009 - 10:23:40 | N | 30048] C:\Lfbmp15u.dll
    [07/04/2009 - 10:23:40 | N | 390496] C:\Lfcmp15u.dll
    [07/04/2009 - 10:23:42 | N | 423264] C:\Lfcmw15u.dll
    [07/04/2009 - 10:23:40 | N | 54624] C:\Lfdrw15u.dll
    [07/04/2009 - 10:23:42 | N | 99680] C:\Lffax15u.dll
    [07/04/2009 - 10:23:42 | N | 18272] C:\Lffit15u.dll
    [07/04/2009 - 10:23:42 | N | 34656] C:\Lfgif15u.dll
    [07/04/2009 - 10:23:42 | N | 17248] C:\Lfimg15u.dll
    [07/04/2009 - 10:23:42 | N | 17248] C:\Lfitg15u.dll
    [07/04/2009 - 10:23:42 | N | 67936] C:\Lfjbg15u.dll
    [07/04/2009 - 10:23:42 | N | 128352] C:\Lfpng15u.dll
    [07/04/2009 - 10:23:42 | N | 14176] C:\Lfraw15u.dll
    [07/04/2009 - 10:23:42 | N | 20320] C:\Lftga15u.dll
    [07/04/2009 - 10:23:42 | N | 152928] C:\Lftif15u.dll
    [07/04/2009 - 10:23:42 | N | 15712] C:\Lfwmp15u.dll
    [07/04/2009 - 10:54:32 | N | 503808] C:\libpin3_dll.dll
    [07/04/2009 - 10:23:42 | N | 267616] C:\Ltdis15u.dll
    [07/04/2009 - 10:23:42 | N | 259424] C:\Ltefx15u.dll
    [07/04/2009 - 10:23:42 | N | 185696] C:\Ltfil15u.dll
    [07/04/2009 - 10:23:42 | N | 214368] C:\Ltimgclr15u.dll
    [07/04/2009 - 10:23:42 | N | 353632] C:\Ltimgcor15u.dll
    [07/04/2009 - 10:23:42 | N | 214368] C:\Ltimgefx15u.dll
    [07/04/2009 - 10:23:42 | N | 447840] C:\Ltimgsfx15u.dll
    [07/04/2009 - 10:23:42 | N | 128352] C:\Ltimgutl15u.dll
    [07/04/2009 - 10:23:42 | N | 488800] C:\Ltkrn15u.dll
    [07/04/2009 - 10:23:42 | N | 107872] C:\Ltpnt15u.dll
    [07/04/2009 - 10:23:42 | N | 2241888] C:\Ltwvc15u.dll
    [07/04/2009 - 10:23:42 | N | 1097728] C:\M5_EmuHw.dll
    [07/04/2009 - 10:23:42 | N | 507904] C:\M5_EmuMapi30.dll
    [07/04/2009 - 10:23:42 | N | 1998848] C:\M5_EmuSmw5.dll
    [18/03/2009 - 03:07:50 | N | 1560720] C:\MacOSX.msstyles
    [07/04/2009 - 10:23:46 | N | 315392] C:\MACSSDK.dll
    [07/04/2009 - 10:23:44 | N | 40960] C:\MAMACExtract.dll
    [07/04/2009 - 10:23:46 | N | 1241088] C:\MediaInfo.dll
    [09/04/2009 - 11:07:30 | N | 167936] C:\MedicDll.dll
    [14/04/2008 - 12:26:46 | N | 1028096] C:\mfc42.dll
    [03/04/2007 - 13:14:48 | N | 981760] C:\mfc42u.dll
    [07/04/2009 - 10:23:42 | N | 159744] C:\Mirage.dll
    [07/04/2009 - 10:55:04 | N | 23384] C:\MMSProfile.ppz
    [07/04/2009 - 10:23:42 | N | 294912] C:\MMTCM3EncoderDLL.dll
    [16/04/2009 - 10:39:10 | N | 327680] C:\MObexDll.dll
    [31/12/2009 - 23:41:52 | D ] C:\ModelExtension
    [07/04/2009 - 11:10:24 | N | 184320] C:\Modem.dll
    [18/02/2009 - 14:13:39 | N | 0] C:\MSDOS.SYS
    [18/02/2009 - 15:10:12 | RHD ] C:\MSOCache
    [07/04/2009 - 11:10:18 | N | 499712] C:\msvcp71.dll
    [14/04/2008 - 12:26:50 | N | 343040] C:\msvcrt.dll
    [07/04/2009 - 10:23:46 | N | 28672] C:\MTDES.dll
    [07/04/2009 - 10:23:44 | N | 692224] C:\NeoCertDll.dll
    [16/04/2009 - 17:09:28 | N | 1863680] C:\NewPCStudio.exe
    [16/04/2009 - 10:43:28 | N | 925696] C:\NLANG_Scheduler.dll
    [07/04/2009 - 10:40:26 | N | 4960256] C:\NPS.dat
    [08/07/2008 - 15:20:56 | N | 569344] C:\npsadec.dll
    [08/07/2008 - 15:22:22 | N | 139264] C:\npsaef.dll
    [16/04/2009 - 10:41:18 | N | 102400] C:\NPSAgent.exe
    [16/04/2009 - 17:01:18 | N | 94208] C:\NPSAlarm.exe
    [07/04/2009 - 10:55:04 | N | 287232] C:\NPSAndroidDownloader.dll
    [16/04/2009 - 10:44:02 | N | 2801664] C:\NPSApp.exe
    [01/08/2008 - 15:23:36 | N | 471040] C:\npsappactl.dll
    [16/04/2009 - 10:38:14 | N | 77824] C:\NPSArbiter.dll
    [08/07/2008 - 15:29:34 | N | 139264] C:\npsasrc.dll
    [09/09/2008 - 17:30:46 | N | 204800] C:\npsasvr.exe
    [08/07/2008 - 15:23:38 | N | 192512] C:\npsawms.dll
    [16/04/2009 - 17:00:34 | N | 192512] C:\NPSBackupAndRestore.exe
    [16/04/2009 - 10:39:08 | N | 53248] C:\NPSBinaryInfo_DU.dll
    [16/04/2009 - 10:38:30 | N | 86016] C:\NPSBinaryInfo_Limo.dll
    [16/04/2009 - 10:38:46 | N | 94208] C:\NPSBinaryInfo_Qualcomm.dll
    [16/04/2009 - 10:38:48 | N | 94208] C:\NPSBinaryInfo_Symbian.dll
    [16/04/2009 - 10:39:06 | N | 30208] C:\NPSBinaryInfo_WM.dll
    [16/04/2009 - 17:00:20 | N | 1404928] C:\NPSBinaryUpgrade.exe
    [25/11/2008 - 17:51:44 | N | 86016] C:\NPSBSCKoreaUMS.dll
    [25/11/2008 - 17:52:12 | N | 16384] C:\NPSBVCKoreaUMS.dll
    [08/02/2011 - 10:17:22 | N | 0] C:\NPSC.log
    [16/04/2009 - 10:38:18 | N | 155648] C:\NPSCBT.dll
    [16/04/2009 - 17:07:22 | N | 684032] C:\NPSCDBurner.exe
    [16/04/2009 - 17:06:54 | N | 831488] C:\NPSCDRipper.exe
    [16/04/2009 - 10:39:00 | N | 147456] C:\NPSCM.exe
    [16/04/2009 - 16:59:14 | N | 430080] C:\NPSCommon5.dll
    [16/04/2009 - 10:44:12 | N | 1163264] C:\NPSComnCtrl.dll
    [16/04/2009 - 10:39:16 | N | 73728] C:\NPSConnection.exe
    [16/04/2009 - 16:59:48 | N | 315392] C:\NPSConverter.dll
    [16/04/2009 - 17:02:20 | N | 1474560] C:\NPSConvey.dll
    [16/04/2009 - 10:38:12 | N | 57344] C:\NPSCore.dll
    [16/04/2009 - 17:01:30 | N | 790528] C:\NPSCustomCtrl.dll
    [16/04/2009 - 10:45:06 | N | 405504] C:\NPSCW.exe
    [07/04/2009 - 10:40:24 | N | 617472] C:\NPSDataHouse.exe
    [16/04/2009 - 10:38:18 | N | 90112] C:\NPSDBProxy.dll
    [16/04/2009 - 10:41:42 | N | 425984] C:\NPSDCAATCDMA.dll
    [16/04/2009 - 10:42:56 | N | 765952] C:\NPSDCAATOBEX.dll
    [16/04/2009 - 10:40:38 | N | 507904] C:\NPSDCACHINA2HSP.dll
    [16/04/2009 - 17:12:50 | N | 585728] C:\NPSDCACHINAHSP.dll
    [16/04/2009 - 10:40:46 | N | 626688] C:\NPSDCADU.dll
    [16/04/2009 - 10:41:02 | N | 528384] C:\NPSDCAGM.dll
    [16/04/2009 - 10:42:54 | N | 823296] C:\NPSDCAGMOBEX.dll
    [16/04/2009 - 10:43:52 | N | 344064] C:\NPSDCAHSP.dll
    [16/04/2009 - 10:41:16 | N | 503808] C:\NPSDCAKOREAHSP.dll
    [16/04/2009 - 10:53:28 | N | 839680] C:\NPSDCAMITSOBEX.dll
    [16/04/2009 - 10:43:56 | N | 913408] C:\NPSDCAOBEX.dll
    [16/04/2009 - 10:44:32 | N | 622592] C:\NPSDCASW.dll
    [16/04/2009 - 10:41:50 | N | 409600] C:\NPSDCASYM.dll
    [16/04/2009 - 16:59:48 | N | 630784] C:\NPSDCAWM.dll
    [16/04/2009 - 10:39:18 | N | 61440] C:\NPSDCM.dll
    [16/04/2009 - 17:05:56 | N | 221184] C:\NPSDDay.exe
    [16/04/2009 - 10:41:44 | N | 180224] C:\NPSDENG.exe
    [16/04/2009 - 10:39:12 | N | 765952] C:\NPSDeviceDRM3rd.dll
    [16/04/2009 - 17:04:42 | N | 663552] C:\NPSDeviceList.dll
    [16/04/2009 - 18:34:48 | N | 2191360] C:\NPSDexplorer.exe
    [16/04/2009 - 10:39:42 | N | 352256] C:\NPSDM.exe
    [16/04/2009 - 17:01:42 | N | 901120] C:\NPSDMPPlayer.exe
    [16/04/2009 - 10:39:30 | N | 1085440] C:\NPSDump.exe
    [07/04/2009 - 10:23:44 | N | 73728] C:\NPSEffectFilter.dll
    [16/04/2009 - 17:02:56 | N | 159744] C:\NPSEmailSync.exe
    [16/04/2009 - 10:44:42 | N | 1810432] C:\NPSFull.exe
    [16/04/2009 - 16:59:34 | N | 159744] C:\NPSFunction5.dll
    [25/11/2008 - 18:08:26 | N | 909312] C:\NPSFUSClientDU.exe
    [07/04/2009 - 10:54:40 | N | 2584394] C:\NPSGuide.dat
    [16/04/2009 - 10:43:12 | N | 61440] C:\NPSGuide.exe
    [16/04/2009 - 10:38:16 | N | 114688] C:\NPSHSPAgent.dll
    [16/04/2009 - 17:09:12 | N | 1335296] C:\NPSIFXBinaryUpgrade.exe
    [16/04/2009 - 17:07:40 | N | 299008] C:\NPSImageViewer.exe
    [07/04/2009 - 10:23:44 | N | 61440] C:\NPSImgFilter.ax
    [16/04/2009 - 17:04:12 | N | 135168] C:\NPSInstApp.exe
    [16/04/2009 - 17:06:12 | N | 241664] C:\NPSInternetConnector.exe
    [16/04/2009 - 17:04:58 | N | 2949120] C:\NPSLang.dll
    [16/04/2009 - 10:42:22 | N | 712704] C:\NPSLang_BackupAndRestore.dll
    [16/04/2009 - 10:38:40 | N | 532480] C:\NPSLang_DDay.dll
    [16/04/2009 - 10:38:46 | N | 622592] C:\NPSLang_EmailSync.dll
    [16/04/2009 - 10:41:54 | N | 253952] C:\NPSLang_InstApp.dll
    [16/04/2009 - 10:43:26 | N | 692224] C:\NPSLang_InternetConnector.dll
    [16/04/2009 - 10:39:00 | N | 475136] C:\NPSLang_Memo.dll
    [16/04/2009 - 10:41:56 | N | 626688] C:\NPSLang_MessageManager.dll
    [16/04/2009 - 10:52:40 | N | 1204224] C:\NPSLang_MyDiary.dll
    [16/04/2009 - 10:43:02 | N | 806912] C:\NPSLang_MyExplorer.dll
    [16/04/2009 - 10:39:00 | N | 1536000] C:\NPSLang_Phonebook.dll
    [16/04/2009 - 10:41:52 | N | 327680] C:\NPSLang_SMSSender.dll
    [16/04/2009 - 10:40:00 | N | 507904] C:\NPSLang_TimeTable.dll
    [16/04/2009 - 16:58:44 | N | 573440] C:\NPSLang_ToDo.dll
    [16/04/2009 - 10:40:02 | N | 331776] C:\NPSLang_VoiceMemo.dll
    [07/04/2009 - 10:55:04 | N | 285184] C:\NPSLinuxMitsDownloader.dll
    [10/04/2009 - 16:08:20 | N | 270848] C:\NPSLinuxMitsNpDownloader.dll
    [16/04/2009 - 10:46:32 | N | 1503232] C:\NPSMainChecker.exe
    [17/04/2009 - 10:22:20 | N | 7274496] C:\NPSMediaManager.exe
    [16/04/2009 - 17:08:24 | N | 180224] C:\NPSMemo.exe
    [16/04/2009 - 17:05:06 | N | 593920] C:\NPSMessageManager.exe
    [16/04/2009 - 17:00:34 | N | 1110016] C:\NPSMitsBinaryUpgrade.exe
    [16/04/2009 - 17:00:24 | N | 249856] C:\NPSMMSPlay.dll
    [16/04/2009 - 17:08:40 | N | 917504] C:\NPSMMSSender.exe
    [16/04/2009 - 10:38:16 | N | 61440] C:\NPSModelDB.dll
    [08/07/2008 - 15:24:20 | N | 131072] C:\npsmpgs.dll
    [16/04/2009 - 18:34:48 | N | 466944] C:\NPSMTPExplorer.exe
    [30/12/2008 - 02:41:12 | N | 94208] C:\NPSMusicManager.dll
    [16/04/2009 - 17:08:18 | N | 1114112] C:\NPSMusicPlayer.exe
    [16/04/2009 - 16:59:36 | N | 45568] C:\NPSMyComputer.dll
    [16/04/2009 - 17:09:36 | N | 434176] C:\NPSMyDiary.exe
    [16/04/2009 - 17:03:14 | N | 557056] C:\NPSMyExplorer.exe
    [16/04/2009 - 19:05:22 | N | 557056] C:\NPSNetworkProviderDB.dat
    [16/04/2009 - 17:06:34 | N | 1970176] C:\NPSNotifyClient.exe
    [16/04/2009 - 17:09:40 | N | 884736] C:\NPSPhonebook.exe
    [16/04/2009 - 10:33:36 | N | 480234] C:\NPSPhoneProfile.ppz
    [16/04/2009 - 10:43:56 | N | 73728] C:\NPSPwRecovery.exe
    [16/04/2009 - 17:00:34 | N | 1613824] C:\NPSQualcommBinaryUpgrade.exe
    [07/04/2009 - 10:44:22 | N | 153984] C:\NPSRapiServer.dll
    [16/04/2009 - 10:24:32 | N | 161152] C:\NPSRapiServer_k.dll
    [07/04/2009 - 10:44:22 | N | 138624] C:\NPSRapiServer_m.dll
    [16/04/2009 - 18:27:06 | N | 987136] C:\npssamsungmodeldb.dat
    [16/04/2009 - 17:07:30 | N | 675840] C:\NPSScheduler.exe
    [07/04/2009 - 10:44:22 | N | 34176] C:\NPSSendMessage.exe
    [16/04/2009 - 17:05:34 | N | 356352] C:\NPSSIMEditor.exe
    [16/04/2009 - 17:04:32 | N | 221184] C:\NPSSMSSender.exe
    [16/04/2009 - 17:03:14 | N | 712704] C:\NPSStageSync.exe
    [07/04/2009 - 10:23:44 | N | 65536] C:\NPSSubPicture.dll
    [16/04/2009 - 17:03:14 | N | 1363968] C:\NPSSymbianBinaryUpgrade.exe
    [16/04/2009 - 10:42:58 | N | 573440] C:\NPSSync.dll
    [16/04/2009 - 17:04:36 | N | 307200] C:\NPSTimeTable.exe
    [16/04/2009 - 17:07:54 | N | 270336] C:\NPSToDo.exe
    [16/04/2009 - 10:43:56 | N | 622592] C:\NPSToolboxAdd.exe
    [16/04/2009 - 17:06:06 | N | 880640] C:\NPSToWeb2.exe
    [16/04/2009 - 10:44:36 | N | 40960] C:\NPSToWebBtn.dll
    [16/04/2009 - 10:43:24 | N | 50176] C:\NPSUserWebFeedback.exe
    [08/07/2008 - 18:23:12 | N | 139264] C:\npsvae.dll
    [01/08/2008 - 13:25:02 | N | 839680] C:\npsvctl.dll
    [16/04/2009 - 17:01:52 | N | 741376] C:\NPSVideoConverter.exe
    [16/04/2009 - 17:07:20 | N | 655360] C:\NPSVideoPlayer.exe
    [16/04/2009 - 17:02:54 | N | 229376] C:\NPSVoiceMemo.exe
    [08/07/2008 - 19:15:30 | N | 143360] C:\npsvsrc.dll
    [09/09/2008 - 17:33:18 | N | 204800] C:\npsvsvr.exe
    [08/07/2008 - 18:19:26 | N | 167936] C:\npsvve.dll
    [08/07/2008 - 18:26:08 | N | 200704] C:\npsvwms.dll
    [16/04/2009 - 17:05:04 | N | 102400] C:\NPSWidgetContainer.exe
    [16/04/2009 - 17:04:36 | N | 675840] C:\NPSWizard.exe
    [16/04/2009 - 10:38:52 | N | 217088] C:\NPSWMBinaryEngine.dll
    [16/04/2009 - 17:00:28 | N | 2265088] C:\NPSWMBinaryUpgrade.exe
    [07/04/2009 - 10:23:44 | N | 667648] C:\NPS_MEDIA_USER_DB.dat
    [10/04/2007 - 11:40:46 | N | 74240] C:\nsldap32v11.dll
    [14/04/2008 - 14:00:00 | N | 47564] C:\NTDETECT.COM
    [14/04/2008 - 14:00:00 | N | 252240] C:\ntldr
    [16/04/2009 - 10:38:50 | N | 27136] C:\ObexInterface.dll
    [09/04/2009 - 19:58:38 | N | 274432] C:\Octans_HomeDL.dll
    [19/02/2009 - 10:34:24 | N | 266240] C:\Omnia_HomeDL_VISTA.dll
    [19/02/2009 - 10:34:24 | N | 266240] C:\Omnia_HomeDL_XP.dll
    [15/04/2011 - 01:04:38 | ASH | 2145386496] C:\pagefile.sys
    [07/04/2009 - 11:10:24 | N | 90112] C:\PC_Download_DLL_AP.dll
    [13/09/2009 - 16:46:12 | D ] C:\PDFCreator
    [06/10/2009 - 16:55:22 | D ] C:\PhotoFiltre
    [07/04/2009 - 10:23:44 | N | 94208] C:\proghelp.dll
    [15/04/2011 - 01:35:42 | D ] C:\Program Files
    [07/06/2010 - 15:19:10 | N | 9157] C:\qr.dat
    [04/08/2008 - 01:48:44 | N | 138024] C:\rapi.dll
    [15/04/2011 - 02:39:42 | SHD ] C:\RECYCLER
    [31/12/2009 - 23:41:53 | D ] C:\resources
    [07/04/2009 - 10:23:44 | N | 352256] C:\SamsungMediaServer.dll
    [07/04/2009 - 10:23:46 | N | 384512] C:\SAPEncoder.dll
    [07/04/2009 - 10:44:22 | N | 13880] C:\SetupNPSRapiServer.exe
    [07/04/2009 - 10:44:22 | N | 13880] C:\SetupNPSRapiServer_SGH-i900.exe
    [07/04/2009 - 10:23:44 | N | 2367488] C:\SMAFMMS5EMU.dll
    [16/04/2009 - 10:38:36 | N | 122880] C:\Smllib.dll
    [07/04/2009 - 10:23:46 | N | 383488] C:\SMPDecoder.dll
    [07/04/2009 - 10:23:46 | N | 434176] C:\SMPEncoder.dll
    [20/06/2010 - 02:49:15 | D ] C:\SolidWorks Data
    [07/04/2009 - 10:40:24 | N | 904332] C:\splash.dat
    [07/04/2009 - 10:23:44 | N | 624640] C:\StarBurn.dll
    [07/04/2009 - 10:23:44 | N | 131072] C:\Sub3.dll
    [16/04/2009 - 16:50:16 | N | 208896] C:\Symbian_Downloader_DLL.dll
    [16/04/2009 - 10:39:02 | N | 94208] C:\SyncEngine.dll
    [14/04/2011 - 22:26:59 | SHD ] C:\System Volume Information
    [07/04/2009 - 10:44:22 | N | 35840] C:\TCLAppointment.dll
    [07/04/2009 - 10:23:44 | N | 40960] C:\TCM2Decoder12.dll
    [07/04/2009 - 10:23:44 | N | 40960] C:\TCM2Decoder16.dll
    [07/04/2009 - 10:23:44 | N | 36864] C:\TCM2Decoder2.dll
    [07/04/2009 - 10:23:44 | N | 36864] C:\TCM2Decoder24.dll
    [07/04/2009 - 10:23:44 | N | 40960] C:\TCM2Decoder8.dll
    [07/04/2009 - 10:23:44 | N | 98304] C:\TCM2Encoder.dll
    [07/04/2009 - 10:23:44 | N | 229376] C:\TCMSEncoder.dll
    [07/04/2009 - 10:39:44 | N | 16392] C:\TFsExDisk.sys
    [10/03/2008 - 00:59:42 | ASH | 4096] C:\Thumbs.db
    [07/04/2009 - 10:23:44 | N | 36864] C:\tn30CSTK.dll
    [05/06/2008 - 01:08:56 | N | 5734400] C:\ToolkitPro1112vc80U.dll
    [16/04/2009 - 10:38:18 | N | 114688] C:\Type.dll
    [28/08/2005 - 21:51:42 | N | 766] C:\Uninstall.ico
    [31/12/2009 - 23:41:53 | D ] C:\USB Drivers
    [15/04/2011 - 02:41:56 | D ] C:\UsbFix
    [15/04/2011 - 02:42:08 | A | 1339] C:\UsbFix.txt
    [16/04/2009 - 10:38:32 | N | 102400] C:\vObject.dll
    [14/04/2011 - 23:35:58 | D ] C:\WINDOWS
    [07/04/2009 - 11:10:30 | N | 16384] C:\winusb.dll
    [01/03/2001 - 09:27:00 | N | 278800] C:\wmv8ds32.ax
    [28/04/2000 - 11:01:00 | N | 262416] C:\wmvds32.ax
    [07/04/2009 - 10:23:44 | N | 126976] C:\WnASPI32.dll
    [23/01/2010 - 00:59:08 | D ] C:\XPortail
    [07/04/2009 - 10:23:46 | N | 151552] C:\XSYNCClt.dll
    [28/07/2008 - 12:31:06 | D ] F:\wd_windows_tools
    [28/07/2008 - 12:32:14 | D ] F:\wd_mac_tools
    [28/07/2008 - 12:32:22 | D ] F:\autorun
    [31/03/2008 - 12:57:12 | N | 87] F:\Install.ini
    [01/04/2008 - 15:05:20 | N | 319488] F:\setup.exe
    [28/08/2008 - 18:28:46 | SHD ] F:\System Volume Information
    [28/08/2008 - 18:38:58 | D ] F:\Films
    [29/08/2008 - 21:10:30 | D ] F:\Campings
    [14/09/2008 - 21:37:36 | D ] F:\Technologie
    [17/09/2008 - 21:29:10 | D ] F:\Photos
    [18/09/2008 - 12:00:24 | SHD ] F:\Recycled
    [05/12/2008 - 23:57:52 | D ] F:\Soft
    [17/02/2009 - 18:54:58 | D ] F:\Da^wah 'ila l-Lah
    [22/10/2009 - 18:52:14 | D ] F:\Sauvegarde PC
    [16/04/2010 - 08:54:20 | D ] F:\1-TECHNOLOGIE
    [21/03/2010 - 15:50:06 | D ] F:\cours chaykh
    [15/08/2010 - 21:09:52 | D ] F:\0a161b8819e54857cd13f1
    [04/09/2010 - 16:07:06 | D ] F:\Disque ECE 04 09 2010
    [27/03/2011 - 15:08:36 | D ] F:\Disque ECE 27 03 2011

    ################## | Vaccin |

    C:\Autorun.inf -> Vaccin créé par UsbFix (TeamXscript)
    F:\Autorun.inf -> Vaccin créé par UsbFix (TeamXscript)

    ################## | Upload |

    Veuillez envoyer le fichier: C:\UsbFix_Upload_Me_PC01.zip
    http://www.teamxscript.org/Upload.php
    Merci de votre contribution.

    ################## | E.O.F |
    0
  16. gen-hackman
     
    c'est quoi tous ces fichiers dans c:\ ?
    0
  17. Chamsy Messages postés 23 Statut Membre
     
    J'étais en train de me dire la même chose. Je crois que c'est le logiciel livré avec mon téléphone portable qui a foutu le bazarre (Samsung New PC Studio). J'en ai pas besoin. Il faudrait que je le désinstalle si tu es ok.
    0
  18. gen-hackman
     
    tu peux

    fais gaffe à ce que tu vires :)
    0
  19. Chamsy Messages postés 23 Statut Membre
     
    C'est bon, c'est beaucoup plus beaucoup maintenant après avoir désinstaller tous les petits modules et avec un redémarrage :)

    Quelle est l'étape suivante ?
    0
  20. gen-hackman
     
    refais l option listing d'usbfix que je voie un peu
    0
  21. Chamsy
     
    Au secours ! Il s'est passé une catastrophe. Après t'avoir posté mon message précédent j'ai vu qu'il restait 2 applications samsung non désinstallés dans le panneau de config. Je les ai désinstallé puis redémarrer et là :
    Le PC affiche un écran tout noir avec écris en haut : NTDLR manque appuyer sur CTRL+ALT+SUPPR. Mais quand je le fais j'obtiens la même chose.

    J'ai du aller chercher un autre PC pour t'écrire. L'autre ne répond plus. Je suis un paniqué je t'avoue.
    0
  • 1
  • 2
  • 3