Problème DDE
alexisvirus
Messages postés
11
Statut
Membre
-
Utilisateur anonyme -
Utilisateur anonyme -
Bonjour,
j'ai un problème avec mon disque dur externe tous mes dossiers ont disparus il ne reste que des raccourcis ne menant à rien. Voici le log USBFIX :
############################## | UsbFix V 7.102 | [Research]
User: alexis (Administrator) # ALEXIS-PC
Updated 20/12/2012 by El Desaparecido
Started at 16:30:04 | 29/01/2013
Website: https://www.sosvirus.net/
Contact: contact@eldesaparecido.com
PC: Gigabyte Technology Co., Ltd. (G31M-ES2L) (X86-based PC
CPU: Pentium(R) Dual-Core CPU E5200 @ 2.50GHz (3166)
RAM -> [Total : 2046 | Free : 587]
BIOS: Award Modular BIOS v6.00PG
BOOT: Normal boot
OS: Microsoft Windows 7 Édition Intégrale (6.1.7601 32-Bit) # Service Pack 1
WB: Windows Internet Explorer 9.0.8112.16421
SC: Security Center Service [Enabled]
WU: Windows Update Service [Enabled]
AV: Microsoft Security Essentials [(!) Disabled | Updated]
FW: Windows FireWall Service [Enabled]
B:\ -> Fixed drive # 466 Gb (69 Mb free - 15%) [Elements] # NTFS
C:\ (%systemdrive%) -> Fixed drive # 233 Gb (158 Mb free - 68%) [] # NTFS
D:\ -> Fixed drive # 93 Gb (46 Mb free - 50%) [] # NTFS
E:\ -> CD-ROM
F:\ -> CD-ROM
G:\ -> Removable drive # 7 Gb (202 Mb free - 3%) [GROUSSIN YV] # NTFS
################## | Active Processes |
C:\Windows\system32\csrss.exe (420)
C:\Windows\system32\wininit.exe (500)
C:\Windows\system32\csrss.exe (512)
C:\Windows\system32\services.exe (552)
C:\Windows\system32\lsass.exe (568)
C:\Windows\system32\lsm.exe (576)
C:\Windows\system32\svchost.exe (684)
C:\Windows\system32\winlogon.exe (760)
C:\Windows\system32\svchost.exe (808)
c:\Program Files\Microsoft Security Client\MsMpEng.exe (856)
C:\Windows\system32\atiesrxx.exe (996)
C:\Windows\System32\svchost.exe (1040)
C:\Windows\System32\svchost.exe (1080)
C:\Windows\system32\svchost.exe (1124)
C:\Windows\system32\svchost.exe (1220)
C:\Windows\system32\svchost.exe (1296)
C:\Windows\system32\atieclxx.exe (1372)
C:\Windows\system32\svchost.exe (1456)
C:\Windows\System32\spoolsv.exe (1620)
C:\Windows\system32\svchost.exe (1672)
C:\Windows\system32\taskhost.exe (1864)
C:\Windows\system32\svchost.exe (2036)
C:\Windows\system32\svchost.exe (364)
C:\Windows\System32\svchost.exe (428)
C:\Windows\System32\svchost.exe (544)
C:\Windows\system32\svchost.exe (1120)
C:\Windows\Explorer.EXE (1944)
C:\Windows\system32\Dwm.exe (2192)
C:\Program Files\TuneUp Utilities 2012\TuneUpUtilitiesService32.exe (2204)
C:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPSVC.EXE (2596)
C:\Windows\system32\svchost.exe (2636)
C:\Windows\system32\svchost.exe (2904)
C:\Program Files\TuneUp Utilities 2012\TuneUpUtilitiesApp32.exe (3320)
C:\Windows\System32\WUDFHost.exe (3560)
C:\Program Files\Microsoft Security Client\msseces.exe (3736)
C:\Program Files\Skype\Phone\Skype.exe (3792)
C:\Program Files\Samsung\Kies\External\FirmwareUpdate\KiesPDLR.exe (3864)
C:\Program Files\Ultracopier\ultracopier.exe (3920)
C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe (3928)
C:\Program Files\LOLReplay\LOLRecorder.exe (3960)
C:\Windows\System32\svchost.exe (2736)
C:\Program Files\DAEMON Tools Pro\DTShellHlp.exe (3164)
C:\Program Files\Windows Media Player\wmpnetwk.exe (2968)
C:\Program Files\Nero\Update\NASvc.exe (4408)
C:\Program Files\uTorrent\uTorrent.exe (6000)
C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\MOM.exe (5544)
C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CCC.exe (2856)
C:\Windows\Microsoft.Net\Framework\v3.0\WPF\PresentationFontCache.exe (1188)
C:\Program Files\Google\Chrome\Application\chrome.exe (2376)
C:\Program Files\Google\Chrome\Application\chrome.exe (5532)
C:\Program Files\Google\Chrome\Application\chrome.exe (4784)
C:\Program Files\Google\Chrome\Application\chrome.exe (2216)
C:\Program Files\Google\Chrome\Application\chrome.exe (3288)
C:\Program Files\Google\Chrome\Application\chrome.exe (3448)
C:\Program Files\Google\Chrome\Application\chrome.exe (2620)
C:\Program Files\Google\Chrome\Application\chrome.exe (4476)
C:\Program Files\Google\Chrome\Application\chrome.exe (5424)
C:\Windows\servicing\TrustedInstaller.exe (5912)
C:\Windows\system32\taskhost.exe (4584)
C:\Program Files\Google\Chrome\Application\chrome.exe (2320)
C:\Program Files\Google\Chrome\Application\chrome.exe (984)
C:\Program Files\Internet Explorer\IELowutil.exe (2488)
C:\UsbFix\Go.exe (5352)
C:\Windows\system32\wbem\wmiprvse.exe (4708)
################## | Files # Infected Folders |
################## | Registry |
Found ! HKLM\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\excel.exe
Found ! HKLM\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\infopath.exe
Found ! HKLM\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\mcdetection.exe
Found ! HKLM\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\mcsettings.exe
Found ! HKLM\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\msaccess.exe
Found ! HKLM\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\mspub.exe
Found ! HKLM\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\onenote.exe
Found ! HKLM\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\outlook.exe
Found ! HKLM\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\Winword.exe
################## | Mountpoints2 |
HKCU\.\.\.\.\Explorer\MountPoints2\{20411f1c-46e0-11e2-917f-00241d32b1bb}
Shell\AutoRun\Command = F:\setup.exe
################## | Vaccin |
B:\Autorun.inf -> Vaccine created by UsbFix (El Desaparecido)
C:\Autorun.inf -> Vaccine created by UsbFix (El Desaparecido)
D:\Autorun.inf -> Vaccine created by UsbFix (El Desaparecido)
G:\Autorun.inf -> Vaccine created by UsbFix (El Desaparecido)
################## | E.O.F |
j'ai un problème avec mon disque dur externe tous mes dossiers ont disparus il ne reste que des raccourcis ne menant à rien. Voici le log USBFIX :
############################## | UsbFix V 7.102 | [Research]
User: alexis (Administrator) # ALEXIS-PC
Updated 20/12/2012 by El Desaparecido
Started at 16:30:04 | 29/01/2013
Website: https://www.sosvirus.net/
Contact: contact@eldesaparecido.com
PC: Gigabyte Technology Co., Ltd. (G31M-ES2L) (X86-based PC
CPU: Pentium(R) Dual-Core CPU E5200 @ 2.50GHz (3166)
RAM -> [Total : 2046 | Free : 587]
BIOS: Award Modular BIOS v6.00PG
BOOT: Normal boot
OS: Microsoft Windows 7 Édition Intégrale (6.1.7601 32-Bit) # Service Pack 1
WB: Windows Internet Explorer 9.0.8112.16421
SC: Security Center Service [Enabled]
WU: Windows Update Service [Enabled]
AV: Microsoft Security Essentials [(!) Disabled | Updated]
FW: Windows FireWall Service [Enabled]
B:\ -> Fixed drive # 466 Gb (69 Mb free - 15%) [Elements] # NTFS
C:\ (%systemdrive%) -> Fixed drive # 233 Gb (158 Mb free - 68%) [] # NTFS
D:\ -> Fixed drive # 93 Gb (46 Mb free - 50%) [] # NTFS
E:\ -> CD-ROM
F:\ -> CD-ROM
G:\ -> Removable drive # 7 Gb (202 Mb free - 3%) [GROUSSIN YV] # NTFS
################## | Active Processes |
C:\Windows\system32\csrss.exe (420)
C:\Windows\system32\wininit.exe (500)
C:\Windows\system32\csrss.exe (512)
C:\Windows\system32\services.exe (552)
C:\Windows\system32\lsass.exe (568)
C:\Windows\system32\lsm.exe (576)
C:\Windows\system32\svchost.exe (684)
C:\Windows\system32\winlogon.exe (760)
C:\Windows\system32\svchost.exe (808)
c:\Program Files\Microsoft Security Client\MsMpEng.exe (856)
C:\Windows\system32\atiesrxx.exe (996)
C:\Windows\System32\svchost.exe (1040)
C:\Windows\System32\svchost.exe (1080)
C:\Windows\system32\svchost.exe (1124)
C:\Windows\system32\svchost.exe (1220)
C:\Windows\system32\svchost.exe (1296)
C:\Windows\system32\atieclxx.exe (1372)
C:\Windows\system32\svchost.exe (1456)
C:\Windows\System32\spoolsv.exe (1620)
C:\Windows\system32\svchost.exe (1672)
C:\Windows\system32\taskhost.exe (1864)
C:\Windows\system32\svchost.exe (2036)
C:\Windows\system32\svchost.exe (364)
C:\Windows\System32\svchost.exe (428)
C:\Windows\System32\svchost.exe (544)
C:\Windows\system32\svchost.exe (1120)
C:\Windows\Explorer.EXE (1944)
C:\Windows\system32\Dwm.exe (2192)
C:\Program Files\TuneUp Utilities 2012\TuneUpUtilitiesService32.exe (2204)
C:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPSVC.EXE (2596)
C:\Windows\system32\svchost.exe (2636)
C:\Windows\system32\svchost.exe (2904)
C:\Program Files\TuneUp Utilities 2012\TuneUpUtilitiesApp32.exe (3320)
C:\Windows\System32\WUDFHost.exe (3560)
C:\Program Files\Microsoft Security Client\msseces.exe (3736)
C:\Program Files\Skype\Phone\Skype.exe (3792)
C:\Program Files\Samsung\Kies\External\FirmwareUpdate\KiesPDLR.exe (3864)
C:\Program Files\Ultracopier\ultracopier.exe (3920)
C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe (3928)
C:\Program Files\LOLReplay\LOLRecorder.exe (3960)
C:\Windows\System32\svchost.exe (2736)
C:\Program Files\DAEMON Tools Pro\DTShellHlp.exe (3164)
C:\Program Files\Windows Media Player\wmpnetwk.exe (2968)
C:\Program Files\Nero\Update\NASvc.exe (4408)
C:\Program Files\uTorrent\uTorrent.exe (6000)
C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\MOM.exe (5544)
C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CCC.exe (2856)
C:\Windows\Microsoft.Net\Framework\v3.0\WPF\PresentationFontCache.exe (1188)
C:\Program Files\Google\Chrome\Application\chrome.exe (2376)
C:\Program Files\Google\Chrome\Application\chrome.exe (5532)
C:\Program Files\Google\Chrome\Application\chrome.exe (4784)
C:\Program Files\Google\Chrome\Application\chrome.exe (2216)
C:\Program Files\Google\Chrome\Application\chrome.exe (3288)
C:\Program Files\Google\Chrome\Application\chrome.exe (3448)
C:\Program Files\Google\Chrome\Application\chrome.exe (2620)
C:\Program Files\Google\Chrome\Application\chrome.exe (4476)
C:\Program Files\Google\Chrome\Application\chrome.exe (5424)
C:\Windows\servicing\TrustedInstaller.exe (5912)
C:\Windows\system32\taskhost.exe (4584)
C:\Program Files\Google\Chrome\Application\chrome.exe (2320)
C:\Program Files\Google\Chrome\Application\chrome.exe (984)
C:\Program Files\Internet Explorer\IELowutil.exe (2488)
C:\UsbFix\Go.exe (5352)
C:\Windows\system32\wbem\wmiprvse.exe (4708)
################## | Files # Infected Folders |
################## | Registry |
Found ! HKLM\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\excel.exe
Found ! HKLM\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\infopath.exe
Found ! HKLM\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\mcdetection.exe
Found ! HKLM\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\mcsettings.exe
Found ! HKLM\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\msaccess.exe
Found ! HKLM\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\mspub.exe
Found ! HKLM\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\onenote.exe
Found ! HKLM\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\outlook.exe
Found ! HKLM\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\Winword.exe
################## | Mountpoints2 |
HKCU\.\.\.\.\Explorer\MountPoints2\{20411f1c-46e0-11e2-917f-00241d32b1bb}
Shell\AutoRun\Command = F:\setup.exe
################## | Vaccin |
B:\Autorun.inf -> Vaccine created by UsbFix (El Desaparecido)
C:\Autorun.inf -> Vaccine created by UsbFix (El Desaparecido)
D:\Autorun.inf -> Vaccine created by UsbFix (El Desaparecido)
G:\Autorun.inf -> Vaccine created by UsbFix (El Desaparecido)
################## | E.O.F |
A voir également:
- Problème DDE
- Salaire dde - Guide
- Image dde - Guide
- Que veut dire dde ✓ - Forum Disque dur / SSD
- Impossible de formater DDE ✓ - Forum MacOS
- DDE et secteurs instables ✓ - Forum Disque dur / SSD
13 réponses
############################## | UsbFix V 7.102 | [Deletion]
User: alexis (Administrator) # ALEXIS-PC
Updated 20/12/2012 by El Desaparecido
Started at 16:46:53 | 29/01/2013
Website: https://www.sosvirus.net/
Contact: contact@eldesaparecido.com
PC: Gigabyte Technology Co., Ltd. (G31M-ES2L) (X86-based PC
CPU: Pentium(R) Dual-Core CPU E5200 @ 2.50GHz (3166)
RAM -> [Total : 2046 | Free : 506]
BIOS: Award Modular BIOS v6.00PG
BOOT: Normal boot
OS: Microsoft Windows 7 Édition Intégrale (6.1.7601 32-Bit) # Service Pack 1
WB: Windows Internet Explorer 9.0.8112.16421
SC: Security Center Service [Enabled]
WU: Windows Update Service [Enabled]
AV: Microsoft Security Essentials [(!) Disabled | Updated]
FW: Windows FireWall Service [Enabled]
B:\ -> Fixed drive # 466 Gb (69 Mb free - 15%) [Elements] # NTFS
C:\ (%systemdrive%) -> Fixed drive # 233 Gb (156 Mb free - 67%) [] # NTFS
D:\ -> Fixed drive # 93 Gb (46 Mb free - 50%) [] # NTFS
E:\ -> CD-ROM
F:\ -> CD-ROM
G:\ -> Removable drive # 7 Gb (202 Mb free - 3%) [GROUSSIN YV] # NTFS
################## | Active Processes |
C:\Windows\system32\csrss.exe (420)
C:\Windows\system32\wininit.exe (500)
C:\Windows\system32\csrss.exe (512)
C:\Windows\system32\services.exe (552)
C:\Windows\system32\lsass.exe (568)
C:\Windows\system32\lsm.exe (576)
C:\Windows\system32\svchost.exe (684)
C:\Windows\system32\winlogon.exe (760)
C:\Windows\system32\svchost.exe (808)
c:\Program Files\Microsoft Security Client\MsMpEng.exe (856)
C:\Windows\system32\atiesrxx.exe (996)
C:\Windows\System32\svchost.exe (1040)
C:\Windows\System32\svchost.exe (1080)
C:\Windows\system32\svchost.exe (1124)
C:\Windows\system32\svchost.exe (1220)
C:\Windows\system32\svchost.exe (1296)
C:\Windows\system32\atieclxx.exe (1372)
C:\Windows\system32\svchost.exe (1456)
C:\Windows\System32\spoolsv.exe (1620)
C:\Windows\system32\svchost.exe (1672)
C:\Windows\system32\taskhost.exe (1864)
C:\Windows\system32\svchost.exe (2036)
C:\Windows\system32\svchost.exe (364)
C:\Windows\System32\svchost.exe (428)
C:\Windows\System32\svchost.exe (544)
C:\Windows\system32\svchost.exe (1120)
C:\Windows\Explorer.EXE (1944)
C:\Windows\system32\Dwm.exe (2192)
C:\Program Files\TuneUp Utilities 2012\TuneUpUtilitiesService32.exe (2204)
C:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPSVC.EXE (2596)
C:\Windows\system32\svchost.exe (2636)
C:\Windows\system32\svchost.exe (2904)
C:\Program Files\TuneUp Utilities 2012\TuneUpUtilitiesApp32.exe (3320)
C:\Windows\System32\WUDFHost.exe (3560)
C:\Program Files\Microsoft Security Client\msseces.exe (3736)
C:\Program Files\Skype\Phone\Skype.exe (3792)
C:\Program Files\Samsung\Kies\External\FirmwareUpdate\KiesPDLR.exe (3864)
C:\Program Files\Ultracopier\ultracopier.exe (3920)
C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe (3928)
C:\Program Files\LOLReplay\LOLRecorder.exe (3960)
C:\Windows\System32\svchost.exe (2736)
C:\Program Files\DAEMON Tools Pro\DTShellHlp.exe (3164)
C:\Program Files\Windows Media Player\wmpnetwk.exe (2968)
C:\Program Files\Nero\Update\NASvc.exe (4408)
C:\Program Files\uTorrent\uTorrent.exe (6000)
C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\MOM.exe (5544)
C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CCC.exe (2856)
C:\Windows\Microsoft.Net\Framework\v3.0\WPF\PresentationFontCache.exe (1188)
C:\Program Files\Google\Chrome\Application\chrome.exe (2376)
C:\Program Files\Google\Chrome\Application\chrome.exe (5532)
C:\Program Files\Google\Chrome\Application\chrome.exe (4784)
C:\Program Files\Google\Chrome\Application\chrome.exe (2216)
C:\Program Files\Google\Chrome\Application\chrome.exe (3288)
C:\Program Files\Google\Chrome\Application\chrome.exe (4476)
C:\Program Files\Google\Chrome\Application\chrome.exe (5424)
C:\Windows\system32\taskhost.exe (4584)
C:\Program Files\Google\Chrome\Application\chrome.exe (5584)
C:\Program Files\Google\Chrome\Application\chrome.exe (5492)
C:\Program Files\Google\Chrome\Application\chrome.exe (3476)
C:\UsbFix\Go.exe (5472)
C:\Windows\system32\wbem\wmiprvse.exe (3080)
C:\Windows\System32\svchost.exe (908)
################## | Stopped processes |
Stopped! c:\Program Files\Microsoft Security Client\MsMpEng.exe (856)
Stopped! C:\Windows\system32\atiesrxx.exe (996)
Stopped! C:\Windows\system32\atieclxx.exe (1372)
Stopped! C:\Windows\System32\spoolsv.exe (1620)
Stopped! C:\Windows\system32\taskhost.exe (1864)
Stopped! C:\Windows\Explorer.EXE (1944)
Stopped! C:\Program Files\TuneUp Utilities 2012\TuneUpUtilitiesService32.exe (2204)
Stopped! C:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPSVC.EXE (2596)
Stopped! C:\Program Files\TuneUp Utilities 2012\TuneUpUtilitiesApp32.exe (3320)
Stopped! C:\Windows\System32\WUDFHost.exe (3560)
Stopped! C:\Program Files\Microsoft Security Client\msseces.exe (3736)
Stopped! C:\Program Files\Skype\Phone\Skype.exe (3792)
Stopped! C:\Program Files\Samsung\Kies\External\FirmwareUpdate\KiesPDLR.exe (3864)
Stopped! C:\Program Files\Ultracopier\ultracopier.exe (3920)
Stopped! C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe (3928)
Stopped! C:\Program Files\LOLReplay\LOLRecorder.exe (3960)
Stopped! C:\Program Files\DAEMON Tools Pro\DTShellHlp.exe (3164)
Stopped! C:\Program Files\Windows Media Player\wmpnetwk.exe (2968)
Stopped! C:\Program Files\Nero\Update\NASvc.exe (4408)
Stopped! C:\Program Files\uTorrent\uTorrent.exe (6000)
Stopped! C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\MOM.exe (5544)
Stopped! C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CCC.exe (2856)
Stopped! C:\Windows\Microsoft.Net\Framework\v3.0\WPF\PresentationFontCache.exe (1188)
Stopped! C:\Program Files\Google\Chrome\Application\chrome.exe (2376)
Stopped! C:\Program Files\Google\Chrome\Application\chrome.exe (5532)
Stopped! C:\Program Files\Google\Chrome\Application\chrome.exe (4784)
Stopped! C:\Program Files\Google\Chrome\Application\chrome.exe (2216)
Stopped! C:\Program Files\Google\Chrome\Application\chrome.exe (3288)
Stopped! C:\Program Files\Google\Chrome\Application\chrome.exe (4476)
Stopped! C:\Windows\system32\taskhost.exe (4584)
Stopped! C:\Program Files\Google\Chrome\Application\chrome.exe (5584)
Stopped! C:\Program Files\Google\Chrome\Application\chrome.exe (5492)
################## | Files # Infected Folders |
Deleted ! B:\$RECYCLE.BIN\S-1-5-21-1333157739-3868082180-2813009589-1000
Deleted ! B:\$RECYCLE.BIN\S-1-5-21-205502895-4010391926-2562467215-1004
Deleted ! B:\$RECYCLE.BIN\S-1-5-21-2561262488-3556830587-2759304412-1000
Deleted ! B:\$RECYCLE.BIN\S-1-5-21-3101594506-4248310904-250478768-1000
Deleted ! B:\$RECYCLE.BIN\S-1-5-21-3473110589-3719869304-2675528683-1000
Deleted ! B:\$RECYCLE.BIN\S-1-5-21-819639659-4150350305-585420797-1001
Deleted ! B:\Recycler\S-1-5-21-1417001333-1085031214-1177238915-1003
Deleted ! C:\$RECYCLE.BIN\S-1-5-21-1439568560-716387363-1758077318-1000
Deleted ! D:\$RECYCLE.BIN\S-1-5-18
Deleted ! D:\$RECYCLE.BIN\S-1-5-20
Deleted ! D:\$RECYCLE.BIN\S-1-5-21-1439568560-716387363-1758077318-1000
Deleted ! D:\$RECYCLE.BIN\S-1-5-21-1634515302-719294652-2573437395-1000
Deleted ! D:\$RECYCLE.BIN\S-1-5-21-191828944-3400758757-2568333681-1001
Deleted ! D:\$RECYCLE.BIN\S-1-5-21-1959394873-3256452105-4141051870-1001
Deleted ! D:\$RECYCLE.BIN\S-1-5-21-2283374110-3856510542-2582306016-1000
Deleted ! D:\$RECYCLE.BIN\S-1-5-21-3262058040-3800136641-854213781-1001
Deleted ! D:\$RECYCLE.BIN\S-1-5-21-3818251717-863624816-859699605-1001
Deleted ! D:\$RECYCLE.BIN\S-1-5-21-4284322940-2377724288-2241919479-1000
Deleted ! D:\$RECYCLE.BIN\S-1-5-21-430048472-3075848688-2778352936-1000
Deleted ! D:\$RECYCLE.BIN\S-1-5-21-44465686-2617674497-2157599098-1000
Deleted ! D:\$RECYCLE.BIN\S-1-5-21-686295007-1848298241-3915102314-1000
Deleted ! D:\$RECYCLE.BIN\S-1-5-21-767982066-497360678-862842875-1000
(!) Temporary files deleted.
################## | Registry |
Deleted ! HKLM\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\excel.exe
Deleted ! HKLM\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\infopath.exe
Deleted ! HKLM\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\mcdetection.exe
Deleted ! HKLM\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\mcsettings.exe
Deleted ! HKLM\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\msaccess.exe
Deleted ! HKLM\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\mspub.exe
Deleted ! HKLM\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\onenote.exe
Deleted ! HKLM\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\outlook.exe
Deleted ! HKLM\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\Winword.exe
################## | Mountpoints2 |
Deleted ! HKCU\.\.\.\.\Explorer\MountPoints2\{20411f1c-46e0-11e2-917f-00241d32b1bb}
################## | Listing |
[29/01/2013 - 16:48:02 | SHD ] B:\$RECYCLE.BIN
[15/08/2012 - 16:51:47 | D ] B:\.fseventsd
[15/08/2012 - 16:43:10 | SHD ] B:\.Trashes
[30/03/2010 - 02:45:31 | D ] B:\autorun
[29/01/2013 - 16:13:51 | RASHD ] B:\Autorun.inf
[15/08/2012 - 16:41:25 | D ] B:\EMILIEN MUSIC
[08/01/2013 - 14:34:34 | D ] B:\Ma musique
[03/02/2011 - 19:35:51 | D ] B:\Mes documents 01032010
[11/10/2012 - 21:31:19 | D ] B:\Mes images
[05/01/2013 - 02:34:21 | D ] B:\Mes vidéos
[05/01/2013 - 02:40:34 | D ] B:\NEW SON
[06/02/2011 - 16:12:16 | SHD ] B:\RECYCLER
[05/11/2012 - 00:39:36 | D ] B:\Resume
[11/10/2012 - 22:50:05 | SHD ] B:\System Volume Information
[22/11/2012 - 23:55:21 | N | 34955] B:\Waiter 3.docx
[29/01/2013 - 16:48:02 | SHD ] C:\$Recycle.Bin
[15/12/2012 - 23:26:31 | D ] C:\AMD
[10/06/2009 - 22:42:20 | N | 24] C:\autoexec.bat
[29/01/2013 - 16:13:40 | RASHD ] C:\Autorun.inf
[28/01/2013 - 23:10:05 | D ] C:\Config.Msi
[10/06/2009 - 22:42:20 | N | 10] C:\config.sys
[14/07/2009 - 05:53:55 | SHD ] C:\Documents and Settings
[15/12/2012 - 21:54:13 | D ] C:\found.000
[16/12/2012 - 00:11:32 | D ] C:\Intel
[15/12/2012 - 19:20:40 | RHD ] C:\MSOCache
[29/01/2013 - 15:37:14 | ASH | 2145902592] C:\pagefile.sys
[14/07/2009 - 03:37:05 | D ] C:\PerfLogs
[29/01/2013 - 15:49:34 | D ] C:\Program Files
[29/01/2013 - 15:49:08 | HD ] C:\ProgramData
[15/12/2012 - 18:49:25 | SHD ] C:\Recovery
[15/12/2012 - 19:58:40 | D ] C:\Riot Games
[16/12/2012 - 14:43:33 | D ] C:\Stinger Mouse Driver
[29/01/2013 - 16:19:29 | SHD ] C:\System Volume Information
[29/01/2013 - 16:48:02 | D ] C:\UsbFix
[29/01/2013 - 16:47:01 | A | 10747] C:\UsbFix.txt
[15/12/2012 - 18:51:02 | D ] C:\Users
[29/01/2013 - 16:19:39 | D ] C:\Windows
[29/01/2013 - 16:48:02 | SHD ] D:\$RECYCLE.BIN
[29/01/2013 - 16:13:42 | RASHD ] D:\Autorun.inf
[16/12/2012 - 03:42:11 | SHD ] D:\Boot
[20/11/2010 - 22:29:06 | RASH | 383786] D:\bootmgr
[16/12/2012 - 03:42:13 | N | 8192] D:\BOOTSECT.BAK
[15/12/2012 - 12:40:11 | D ] D:\Documents
[13/12/2012 - 18:37:11 | D ] D:\Images
[15/12/2012 - 19:18:27 | D ] D:\Logiciels
[20/01/2013 - 13:17:58 | D ] D:\Musique
[15/12/2012 - 14:36:11 | N | 3218079744] D:\pagefile.sys
[19/01/2013 - 21:51:06 | D ] D:\SD
[20/03/2012 - 20:33:59 | D ] D:\Skins
[16/10/2010 - 12:46:05 | SHD ] D:\System Volume Information
[29/01/2013 - 15:49:54 | D ] D:\Vidéos
[05/07/2011 - 12:41:49 | N | 3] D:\win7ldr
[18/01/2013 - 11:17:12 | | 435260] D:\ZPUTI
[29/01/2013 - 16:13:43 | RASHD ] G:\Autorun.inf
[29/01/2013 - 15:38:30 | N | 7686062080] G:\ReadyBoost.sfcache
################## | Vaccin |
B:\Autorun.inf -> Vaccine created by UsbFix (El Desaparecido)
C:\Autorun.inf -> Vaccine created by UsbFix (El Desaparecido)
D:\Autorun.inf -> Vaccine created by UsbFix (El Desaparecido)
G:\Autorun.inf -> Vaccine created by UsbFix (El Desaparecido)
Je peux vérifier si le problème est résolu?
User: alexis (Administrator) # ALEXIS-PC
Updated 20/12/2012 by El Desaparecido
Started at 16:46:53 | 29/01/2013
Website: https://www.sosvirus.net/
Contact: contact@eldesaparecido.com
PC: Gigabyte Technology Co., Ltd. (G31M-ES2L) (X86-based PC
CPU: Pentium(R) Dual-Core CPU E5200 @ 2.50GHz (3166)
RAM -> [Total : 2046 | Free : 506]
BIOS: Award Modular BIOS v6.00PG
BOOT: Normal boot
OS: Microsoft Windows 7 Édition Intégrale (6.1.7601 32-Bit) # Service Pack 1
WB: Windows Internet Explorer 9.0.8112.16421
SC: Security Center Service [Enabled]
WU: Windows Update Service [Enabled]
AV: Microsoft Security Essentials [(!) Disabled | Updated]
FW: Windows FireWall Service [Enabled]
B:\ -> Fixed drive # 466 Gb (69 Mb free - 15%) [Elements] # NTFS
C:\ (%systemdrive%) -> Fixed drive # 233 Gb (156 Mb free - 67%) [] # NTFS
D:\ -> Fixed drive # 93 Gb (46 Mb free - 50%) [] # NTFS
E:\ -> CD-ROM
F:\ -> CD-ROM
G:\ -> Removable drive # 7 Gb (202 Mb free - 3%) [GROUSSIN YV] # NTFS
################## | Active Processes |
C:\Windows\system32\csrss.exe (420)
C:\Windows\system32\wininit.exe (500)
C:\Windows\system32\csrss.exe (512)
C:\Windows\system32\services.exe (552)
C:\Windows\system32\lsass.exe (568)
C:\Windows\system32\lsm.exe (576)
C:\Windows\system32\svchost.exe (684)
C:\Windows\system32\winlogon.exe (760)
C:\Windows\system32\svchost.exe (808)
c:\Program Files\Microsoft Security Client\MsMpEng.exe (856)
C:\Windows\system32\atiesrxx.exe (996)
C:\Windows\System32\svchost.exe (1040)
C:\Windows\System32\svchost.exe (1080)
C:\Windows\system32\svchost.exe (1124)
C:\Windows\system32\svchost.exe (1220)
C:\Windows\system32\svchost.exe (1296)
C:\Windows\system32\atieclxx.exe (1372)
C:\Windows\system32\svchost.exe (1456)
C:\Windows\System32\spoolsv.exe (1620)
C:\Windows\system32\svchost.exe (1672)
C:\Windows\system32\taskhost.exe (1864)
C:\Windows\system32\svchost.exe (2036)
C:\Windows\system32\svchost.exe (364)
C:\Windows\System32\svchost.exe (428)
C:\Windows\System32\svchost.exe (544)
C:\Windows\system32\svchost.exe (1120)
C:\Windows\Explorer.EXE (1944)
C:\Windows\system32\Dwm.exe (2192)
C:\Program Files\TuneUp Utilities 2012\TuneUpUtilitiesService32.exe (2204)
C:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPSVC.EXE (2596)
C:\Windows\system32\svchost.exe (2636)
C:\Windows\system32\svchost.exe (2904)
C:\Program Files\TuneUp Utilities 2012\TuneUpUtilitiesApp32.exe (3320)
C:\Windows\System32\WUDFHost.exe (3560)
C:\Program Files\Microsoft Security Client\msseces.exe (3736)
C:\Program Files\Skype\Phone\Skype.exe (3792)
C:\Program Files\Samsung\Kies\External\FirmwareUpdate\KiesPDLR.exe (3864)
C:\Program Files\Ultracopier\ultracopier.exe (3920)
C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe (3928)
C:\Program Files\LOLReplay\LOLRecorder.exe (3960)
C:\Windows\System32\svchost.exe (2736)
C:\Program Files\DAEMON Tools Pro\DTShellHlp.exe (3164)
C:\Program Files\Windows Media Player\wmpnetwk.exe (2968)
C:\Program Files\Nero\Update\NASvc.exe (4408)
C:\Program Files\uTorrent\uTorrent.exe (6000)
C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\MOM.exe (5544)
C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CCC.exe (2856)
C:\Windows\Microsoft.Net\Framework\v3.0\WPF\PresentationFontCache.exe (1188)
C:\Program Files\Google\Chrome\Application\chrome.exe (2376)
C:\Program Files\Google\Chrome\Application\chrome.exe (5532)
C:\Program Files\Google\Chrome\Application\chrome.exe (4784)
C:\Program Files\Google\Chrome\Application\chrome.exe (2216)
C:\Program Files\Google\Chrome\Application\chrome.exe (3288)
C:\Program Files\Google\Chrome\Application\chrome.exe (4476)
C:\Program Files\Google\Chrome\Application\chrome.exe (5424)
C:\Windows\system32\taskhost.exe (4584)
C:\Program Files\Google\Chrome\Application\chrome.exe (5584)
C:\Program Files\Google\Chrome\Application\chrome.exe (5492)
C:\Program Files\Google\Chrome\Application\chrome.exe (3476)
C:\UsbFix\Go.exe (5472)
C:\Windows\system32\wbem\wmiprvse.exe (3080)
C:\Windows\System32\svchost.exe (908)
################## | Stopped processes |
Stopped! c:\Program Files\Microsoft Security Client\MsMpEng.exe (856)
Stopped! C:\Windows\system32\atiesrxx.exe (996)
Stopped! C:\Windows\system32\atieclxx.exe (1372)
Stopped! C:\Windows\System32\spoolsv.exe (1620)
Stopped! C:\Windows\system32\taskhost.exe (1864)
Stopped! C:\Windows\Explorer.EXE (1944)
Stopped! C:\Program Files\TuneUp Utilities 2012\TuneUpUtilitiesService32.exe (2204)
Stopped! C:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPSVC.EXE (2596)
Stopped! C:\Program Files\TuneUp Utilities 2012\TuneUpUtilitiesApp32.exe (3320)
Stopped! C:\Windows\System32\WUDFHost.exe (3560)
Stopped! C:\Program Files\Microsoft Security Client\msseces.exe (3736)
Stopped! C:\Program Files\Skype\Phone\Skype.exe (3792)
Stopped! C:\Program Files\Samsung\Kies\External\FirmwareUpdate\KiesPDLR.exe (3864)
Stopped! C:\Program Files\Ultracopier\ultracopier.exe (3920)
Stopped! C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe (3928)
Stopped! C:\Program Files\LOLReplay\LOLRecorder.exe (3960)
Stopped! C:\Program Files\DAEMON Tools Pro\DTShellHlp.exe (3164)
Stopped! C:\Program Files\Windows Media Player\wmpnetwk.exe (2968)
Stopped! C:\Program Files\Nero\Update\NASvc.exe (4408)
Stopped! C:\Program Files\uTorrent\uTorrent.exe (6000)
Stopped! C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\MOM.exe (5544)
Stopped! C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CCC.exe (2856)
Stopped! C:\Windows\Microsoft.Net\Framework\v3.0\WPF\PresentationFontCache.exe (1188)
Stopped! C:\Program Files\Google\Chrome\Application\chrome.exe (2376)
Stopped! C:\Program Files\Google\Chrome\Application\chrome.exe (5532)
Stopped! C:\Program Files\Google\Chrome\Application\chrome.exe (4784)
Stopped! C:\Program Files\Google\Chrome\Application\chrome.exe (2216)
Stopped! C:\Program Files\Google\Chrome\Application\chrome.exe (3288)
Stopped! C:\Program Files\Google\Chrome\Application\chrome.exe (4476)
Stopped! C:\Windows\system32\taskhost.exe (4584)
Stopped! C:\Program Files\Google\Chrome\Application\chrome.exe (5584)
Stopped! C:\Program Files\Google\Chrome\Application\chrome.exe (5492)
################## | Files # Infected Folders |
Deleted ! B:\$RECYCLE.BIN\S-1-5-21-1333157739-3868082180-2813009589-1000
Deleted ! B:\$RECYCLE.BIN\S-1-5-21-205502895-4010391926-2562467215-1004
Deleted ! B:\$RECYCLE.BIN\S-1-5-21-2561262488-3556830587-2759304412-1000
Deleted ! B:\$RECYCLE.BIN\S-1-5-21-3101594506-4248310904-250478768-1000
Deleted ! B:\$RECYCLE.BIN\S-1-5-21-3473110589-3719869304-2675528683-1000
Deleted ! B:\$RECYCLE.BIN\S-1-5-21-819639659-4150350305-585420797-1001
Deleted ! B:\Recycler\S-1-5-21-1417001333-1085031214-1177238915-1003
Deleted ! C:\$RECYCLE.BIN\S-1-5-21-1439568560-716387363-1758077318-1000
Deleted ! D:\$RECYCLE.BIN\S-1-5-18
Deleted ! D:\$RECYCLE.BIN\S-1-5-20
Deleted ! D:\$RECYCLE.BIN\S-1-5-21-1439568560-716387363-1758077318-1000
Deleted ! D:\$RECYCLE.BIN\S-1-5-21-1634515302-719294652-2573437395-1000
Deleted ! D:\$RECYCLE.BIN\S-1-5-21-191828944-3400758757-2568333681-1001
Deleted ! D:\$RECYCLE.BIN\S-1-5-21-1959394873-3256452105-4141051870-1001
Deleted ! D:\$RECYCLE.BIN\S-1-5-21-2283374110-3856510542-2582306016-1000
Deleted ! D:\$RECYCLE.BIN\S-1-5-21-3262058040-3800136641-854213781-1001
Deleted ! D:\$RECYCLE.BIN\S-1-5-21-3818251717-863624816-859699605-1001
Deleted ! D:\$RECYCLE.BIN\S-1-5-21-4284322940-2377724288-2241919479-1000
Deleted ! D:\$RECYCLE.BIN\S-1-5-21-430048472-3075848688-2778352936-1000
Deleted ! D:\$RECYCLE.BIN\S-1-5-21-44465686-2617674497-2157599098-1000
Deleted ! D:\$RECYCLE.BIN\S-1-5-21-686295007-1848298241-3915102314-1000
Deleted ! D:\$RECYCLE.BIN\S-1-5-21-767982066-497360678-862842875-1000
(!) Temporary files deleted.
################## | Registry |
Deleted ! HKLM\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\excel.exe
Deleted ! HKLM\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\infopath.exe
Deleted ! HKLM\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\mcdetection.exe
Deleted ! HKLM\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\mcsettings.exe
Deleted ! HKLM\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\msaccess.exe
Deleted ! HKLM\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\mspub.exe
Deleted ! HKLM\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\onenote.exe
Deleted ! HKLM\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\outlook.exe
Deleted ! HKLM\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\Winword.exe
################## | Mountpoints2 |
Deleted ! HKCU\.\.\.\.\Explorer\MountPoints2\{20411f1c-46e0-11e2-917f-00241d32b1bb}
################## | Listing |
[29/01/2013 - 16:48:02 | SHD ] B:\$RECYCLE.BIN
[15/08/2012 - 16:51:47 | D ] B:\.fseventsd
[15/08/2012 - 16:43:10 | SHD ] B:\.Trashes
[30/03/2010 - 02:45:31 | D ] B:\autorun
[29/01/2013 - 16:13:51 | RASHD ] B:\Autorun.inf
[15/08/2012 - 16:41:25 | D ] B:\EMILIEN MUSIC
[08/01/2013 - 14:34:34 | D ] B:\Ma musique
[03/02/2011 - 19:35:51 | D ] B:\Mes documents 01032010
[11/10/2012 - 21:31:19 | D ] B:\Mes images
[05/01/2013 - 02:34:21 | D ] B:\Mes vidéos
[05/01/2013 - 02:40:34 | D ] B:\NEW SON
[06/02/2011 - 16:12:16 | SHD ] B:\RECYCLER
[05/11/2012 - 00:39:36 | D ] B:\Resume
[11/10/2012 - 22:50:05 | SHD ] B:\System Volume Information
[22/11/2012 - 23:55:21 | N | 34955] B:\Waiter 3.docx
[29/01/2013 - 16:48:02 | SHD ] C:\$Recycle.Bin
[15/12/2012 - 23:26:31 | D ] C:\AMD
[10/06/2009 - 22:42:20 | N | 24] C:\autoexec.bat
[29/01/2013 - 16:13:40 | RASHD ] C:\Autorun.inf
[28/01/2013 - 23:10:05 | D ] C:\Config.Msi
[10/06/2009 - 22:42:20 | N | 10] C:\config.sys
[14/07/2009 - 05:53:55 | SHD ] C:\Documents and Settings
[15/12/2012 - 21:54:13 | D ] C:\found.000
[16/12/2012 - 00:11:32 | D ] C:\Intel
[15/12/2012 - 19:20:40 | RHD ] C:\MSOCache
[29/01/2013 - 15:37:14 | ASH | 2145902592] C:\pagefile.sys
[14/07/2009 - 03:37:05 | D ] C:\PerfLogs
[29/01/2013 - 15:49:34 | D ] C:\Program Files
[29/01/2013 - 15:49:08 | HD ] C:\ProgramData
[15/12/2012 - 18:49:25 | SHD ] C:\Recovery
[15/12/2012 - 19:58:40 | D ] C:\Riot Games
[16/12/2012 - 14:43:33 | D ] C:\Stinger Mouse Driver
[29/01/2013 - 16:19:29 | SHD ] C:\System Volume Information
[29/01/2013 - 16:48:02 | D ] C:\UsbFix
[29/01/2013 - 16:47:01 | A | 10747] C:\UsbFix.txt
[15/12/2012 - 18:51:02 | D ] C:\Users
[29/01/2013 - 16:19:39 | D ] C:\Windows
[29/01/2013 - 16:48:02 | SHD ] D:\$RECYCLE.BIN
[29/01/2013 - 16:13:42 | RASHD ] D:\Autorun.inf
[16/12/2012 - 03:42:11 | SHD ] D:\Boot
[20/11/2010 - 22:29:06 | RASH | 383786] D:\bootmgr
[16/12/2012 - 03:42:13 | N | 8192] D:\BOOTSECT.BAK
[15/12/2012 - 12:40:11 | D ] D:\Documents
[13/12/2012 - 18:37:11 | D ] D:\Images
[15/12/2012 - 19:18:27 | D ] D:\Logiciels
[20/01/2013 - 13:17:58 | D ] D:\Musique
[15/12/2012 - 14:36:11 | N | 3218079744] D:\pagefile.sys
[19/01/2013 - 21:51:06 | D ] D:\SD
[20/03/2012 - 20:33:59 | D ] D:\Skins
[16/10/2010 - 12:46:05 | SHD ] D:\System Volume Information
[29/01/2013 - 15:49:54 | D ] D:\Vidéos
[05/07/2011 - 12:41:49 | N | 3] D:\win7ldr
[18/01/2013 - 11:17:12 | | 435260] D:\ZPUTI
[29/01/2013 - 16:13:43 | RASHD ] G:\Autorun.inf
[29/01/2013 - 15:38:30 | N | 7686062080] G:\ReadyBoost.sfcache
################## | Vaccin |
B:\Autorun.inf -> Vaccine created by UsbFix (El Desaparecido)
C:\Autorun.inf -> Vaccine created by UsbFix (El Desaparecido)
D:\Autorun.inf -> Vaccine created by UsbFix (El Desaparecido)
G:\Autorun.inf -> Vaccine created by UsbFix (El Desaparecido)
Je peux vérifier si le problème est résolu?
Vous n’avez pas trouvé la réponse que vous recherchez ?
Posez votre question
A la base il était en H mais j'ai essayé de changer la lettre et sur certaines personnes ça marchais^^ je le remets sur H et je remets un log, je pourrais delete direct?
EDIT:Après l'avoir remis en H c'est bon ca remarche!! merci =)
PS: comment savoir si on peut delete ou pas?
EDIT:Après l'avoir remis en H c'est bon ca remarche!! merci =)
PS: comment savoir si on peut delete ou pas?
bah si ca remarche je vois pas pourquoi tu veux delete une deuxieme fois
tu veux qu'on regarde plus profond dans le pc voir s'il y a pas un caca ?
tu veux qu'on regarde plus profond dans le pc voir s'il y a pas un caca ?
bah usbfix n'a jamais rien supprimé de légitime sauf peut etre un raccourci ou un .exe mais c'est pas mechant c'est à la racine des disques