Infection clé USB ... et plus si affinités ? - Page 2

Précédent
  • 1
  • 2
  1. billmaxime Messages postés 50526 Date d'inscription   Statut Contributeur Dernière intervention   6 152
     
    re kulka

    essaye ceci (mkv) de iel desaparecido

    http://general-changelog-team.fr/fr/downloads/viewdownload/15-outils-de-el-desaparecido/20-mkv

    attention avast me le bloque, donc tu devras peut être désactiver ton AV

    @+
    0
  2. billmaxime Messages postés 50526 Date d'inscription   Statut Contributeur Dernière intervention   6 152
     
    re

    usbfix refonctionne, tu peux le télécharger et l'exécuter (en mode suppression)

    le lien http://general-changelog-team.fr/fr/downloads/viewdownload/15-outils-de-el-desaparecido/79-usbfix

    ps:poste le rapport

    @+
    0
  3. Kulka Messages postés 17 Statut Membre
     
    Bonjour,

    Nouveau problème le bureau semble infecté à son tour !

    OS: Microsoft Windows 7 Édition Familiale Premium (6.1.7601 64-Bit) # Service Pack 1
    WB: Windows Internet Explorer 10.0.9200.16540

    SC: Security Center Service [Enabled]
    WU: Windows Update Service [Enabled]
    AV: avast! Antivirus [Enabled | Updated]
    FW: Windows FireWall Service [Enabled]

    C:\ (%systemdrive%) -> Disque fixe # 454 Go (377 Go libre(s) - 83%) [Acer] # NTFS
    D:\ -> Disque fixe # 466 Go (432 Go libre(s) - 93%) [DATA] # NTFS
    E:\ -> CD-ROM
    F:\ -> Disque amovible # 7 Go (5 Go libre(s) - 73%) [BEN] # FAT32

    ################## | Processus Actif |

    C:\Windows\system32\csrss.exe (516)
    C:\Windows\system32\wininit.exe (604)
    C:\Windows\system32\csrss.exe (632)
    C:\Windows\system32\services.exe (664)
    C:\Windows\system32\lsass.exe (692)
    C:\Windows\system32\lsm.exe (700)
    C:\Windows\system32\svchost.exe (808)
    C:\Windows\system32\winlogon.exe (876)
    C:\Windows\system32\svchost.exe (952)
    C:\Windows\system32\atiesrxx.exe (1012)
    C:\Windows\System32\svchost.exe (424)
    C:\Windows\System32\svchost.exe (500)
    C:\Windows\system32\svchost.exe (1040)
    C:\Windows\system32\svchost.exe (1064)
    C:\Windows\system32\svchost.exe (1140)
    C:\Windows\system32\svchost.exe (1224)
    C:\Program Files\AVAST Software\Avast\AvastSvc.exe (1304)
    C:\Windows\system32\WLANExt.exe (1312)
    C:\Windows\system32\conhost.exe (1320)
    C:\Windows\system32\atieclxx.exe (1360)
    C:\Windows\System32\spoolsv.exe (1596)
    C:\Windows\system32\svchost.exe (1624)
    C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe (1780)
    C:\Program Files (x86)\Launch Manager\dsiwmis.exe (1832)
    C:\Program Files\Acer\Acer PowerSmart Manager\ePowerSvc.exe (1960)
    C:\ProgramData\EPSON\EPW!3 SSRP\E_S40STB.EXE (1104)
    C:\ProgramData\EPSON\EPW!3 SSRP\E_S40RPB.EXE (1212)
    C:\Program Files (x86)\Acer\Registration\GREGsvc.exe (1488)
    C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe (1764)
    C:\Program Files (x86)\NewTech Infosystems\Acer Backup Manager\IScheduleSvc.exe (2060)
    C:\Program Files (x86)\NewTech Infosystems\NTI Backup Now 5\SchedulerSvc.exe (2104)
    C:\Program Files (x86)\Cyberlink\Shared files\RichVideo.exe (2144)
    C:\Windows\system32\svchost.exe (2180)
    C:\Program Files\Acer\Acer Updater\UpdaterService.exe (2348)
    C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE (2384)
    C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe (2412)
    C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe (2460)
    C:\Windows\system32\svchost.exe (3028)
    C:\Windows\system32\svchost.exe (2860)
    C:\Windows\System32\WUDFHost.exe (3152)
    C:\Windows\system32\taskhost.exe (3528)
    C:\Windows\system32\Dwm.exe (3676)
    C:\Windows\Explorer.EXE (3712)
    C:\Program Files (x86)\AmIcoSingLun\AmIcoSinglun64.exe (3960)
    C:\Program Files (x86)\EgisTec MyWinLocker\x86\mwlDaemon.exe (3976)
    C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe (3996)
    C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe (4036)
    C:\Windows\System32\igfxpers.exe (4072)
    C:\Windows\system32\igfxsrvc.exe (3268)
    C:\Program Files\Synaptics\SynTP\SynTPEnh.exe (2948)
    C:\Windows\PLFSetI.exe (3440)
    C:\Program Files (x86)\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe (1376)
    C:\Users\Proprietaire\Desktop\StikyNot.exe (2468)
    C:\Program Files (x86)\Sony\Sony PC Companion\PCCompanion.exe (1972)
    C:\Program Files\Windows Sidebar\sidebar.exe (3608)
    C:\Windows\system32\SearchIndexer.exe (1032)
    C:\Program Files\Synaptics\SynTP\SynTPHelper.exe (4060)
    C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe (3540)
    C:\Program Files (x86)\Launch Manager\LManager.exe (2788)
    C:\Program Files (x86)\EgisTec IPS\PmmUpdate.exe (3396)
    C:\Program Files (x86)\Sony\Sony PC Companion\PCCompanionInfo.exe (3460)
    C:\Program Files (x86)\Launch Manager\MMDx64Fx.exe (2668)
    C:\Program Files (x86)\NewTech Infosystems\Acer Backup Manager\BackupManagerTray.exe (3936)
    C:\Program Files\Windows Media Player\wmpnetwk.exe (4120)
    C:\Program Files (x86)\Launch Manager\LMworker.exe (4192)
    C:\Program Files (x86)\Acer Arcade Deluxe\Arcade Movie\ArcadeMovieService.exe (4204)
    C:\Program Files (x86)\Epson Software\Event Manager\EEventManager.exe (4320)
    C:\Program Files (x86)\BOINC\boincmgr.exe (4432)
    C:\Program Files (x86)\BOINC\boinctray.exe (4440)
    C:\Windows\system32\wbem\unsecapp.exe (4452)
    C:\Program Files (x86)\EgisTec IPS\EgisUpdate.exe (4464)
    C:\Program Files\AVAST Software\Avast\AvastUI.exe (4492)
    C:\Users\Proprietaire\AppData\Roaming\Dropbox\bin\Dropbox.exe (4504)
    C:\Windows\system32\wbem\wmiprvse.exe (4692)
    C:\Program Files (x86)\BOINC\boinc.exe (4728)
    C:\Windows\system32\conhost.exe (4736)
    C:\Program Files (x86)\OpenOffice.org 3\program\soffice.exe (4808)
    C:\Program Files (x86)\OpenOffice.org 3\program\soffice.bin (4880)
    C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\MOM.exe (4236)
    C:\Program Files\Acer\Acer PowerSmart Manager\ePowerTray.exe (4980)
    C:\Program Files\Acer\Acer PowerSmart Manager\ePowerEvent.exe (3376)
    C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CCC.exe (5020)
    C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe (912)
    C:\Windows\System32\svchost.exe (3292)
    C:\Program Files (x86)\Mozilla Firefox\firefox.exe (732)
    C:\Windows\system32\svchost.exe (4524)
    C:\Windows\system32\igfxext.exe (3336)
    C:\Windows\system32\taskeng.exe (4240)
    C:\Program Files (x86)\Mozilla Firefox\plugin-container.exe (1152)
    C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerPlugin_11_7_700_169.exe (3000)
    C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerPlugin_11_7_700_169.exe (384)
    C:\Windows\system32\SearchProtocolHost.exe (5716)
    C:\Windows\system32\SearchFilterHost.exe (5160)
    C:\UsbFix\Go.exe (5656)
    C:\Windows\system32\wbem\wmiprvse.exe (2280)

    ################## | El Desaparecido Section |

    HKLM\SOFTWARE | Run : [IAStorIcon] - C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe
    HKLM\SOFTWARE | Run : [LManager] - C:\Program Files (x86)\Launch Manager\LManager.exe
    HKLM\SOFTWARE | Run : [SuiteTray] - "C:\Program Files (x86)\EgisTec MyWinLockerSuite\x86\SuiteTray.exe"
    HKLM\SOFTWARE | Run : [EgisUpdate] - "C:\Program Files (x86)\EgisTec IPS\EgisUpdate.exe" -d
    HKLM\SOFTWARE | Run : [EgisTecPMMUpdate] - "C:\Program Files (x86)\EgisTec IPS\PmmUpdate.exe"
    HKLM\SOFTWARE | Run : [BackupManagerTray] - "C:\Program Files (x86)\NewTech Infosystems\Acer Backup Manager\BackupManagerTray.exe" -h -k
    HKLM\SOFTWARE | Run : [StartCCC] - "C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" MSRun
    HKLM\SOFTWARE | Run : [MDS_Menu] - "C:\Program Files (x86)\Acer Arcade Deluxe\MediaShow Espresso\MUITransfer\MUIStartMenu.exe" "C:\Program Files (x86)\Acer Arcade Deluxe\MediaShow Espresso" UpdateWithCreateOnce "Software\CyberLink\MediaShow Espresso\5.6"
    HKLM\SOFTWARE | Run : [ArcadeMovieService] - "C:\Program Files (x86)\Acer Arcade Deluxe\Arcade Movie\ArcadeMovieService.exe"
    HKLM\SOFTWARE | Run : [Adobe ARM] - "C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
    HKLM\SOFTWARE | Run : [EEventManager] - C:\PROGRA~2\EPSONS~1\EVENTM~1\EEventManager.exe
    HKLM\SOFTWARE | Run : [boincmgr] - "C:\Program Files (x86)\BOINC\boincmgr.exe" /a /s
    HKLM\SOFTWARE | Run : [boinctray] - "C:\Program Files (x86)\BOINC\boinctray.exe"
    HKLM\SOFTWARE | Run : [SunJavaUpdateSched] - "C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe"
    HKLM\SOFTWARE | Run : [avast] - "C:\Program Files\AVAST Software\Avast\avastUI.exe" /nogui
    HKLM\SOFTWARE\wow6432Node | Run : [IAStorIcon] - C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe
    HKLM\SOFTWARE\wow6432Node | Run : [LManager] - C:\Program Files (x86)\Launch Manager\LManager.exe
    HKLM\SOFTWARE\wow6432Node | Run : [SuiteTray] - "C:\Program Files (x86)\EgisTec MyWinLockerSuite\x86\SuiteTray.exe"
    HKLM\SOFTWARE\wow6432Node | Run : [EgisUpdate] - "C:\Program Files (x86)\EgisTec IPS\EgisUpdate.exe" -d
    HKLM\SOFTWARE\wow6432Node | Run : [EgisTecPMMUpdate] - "C:\Program Files (x86)\EgisTec IPS\PmmUpdate.exe"
    HKLM\SOFTWARE\wow6432Node | Run : [BackupManagerTray] - "C:\Program Files (x86)\NewTech Infosystems\Acer Backup Manager\BackupManagerTray.exe" -h -k
    HKLM\SOFTWARE\wow6432Node | Run : [StartCCC] - "C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" MSRun
    HKLM\SOFTWARE\wow6432Node | Run : [MDS_Menu] - "C:\Program Files (x86)\Acer Arcade Deluxe\MediaShow Espresso\MUITransfer\MUIStartMenu.exe" "C:\Program Files (x86)\Acer Arcade Deluxe\MediaShow Espresso" UpdateWithCreateOnce "Software\CyberLink\MediaShow Espresso\5.6"
    HKLM\SOFTWARE\wow6432Node | Run : [ArcadeMovieService] - "C:\Program Files (x86)\Acer Arcade Deluxe\Arcade Movie\ArcadeMovieService.exe"
    HKLM\SOFTWARE\wow6432Node | Run : [Adobe ARM] - "C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
    HKLM\SOFTWARE\wow6432Node | Run : [EEventManager] - C:\PROGRA~2\EPSONS~1\EVENTM~1\EEventManager.exe
    HKLM\SOFTWARE\wow6432Node | Run : [boincmgr] - "C:\Program Files (x86)\BOINC\boincmgr.exe" /a /s
    HKLM\SOFTWARE\wow6432Node | Run : [boinctray] - "C:\Program Files (x86)\BOINC\boinctray.exe"
    HKLM\SOFTWARE\wow6432Node | Run : [SunJavaUpdateSched] - "C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe"
    HKLM\SOFTWARE\wow6432Node | Run : [avast] - "C:\Program Files\AVAST Software\Avast\avastUI.exe" /nogui
    HKLM\SOFTWARE | RunOnce : [] -
    HKLM\SOFTWARE\wow6432Node | RunOnce : [] -
    HKU\S-1-5-19\SOFTWARE | Run : [Sidebar] - %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun
    HKU\S-1-5-20\SOFTWARE | Run : [Sidebar] - %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun
    HKU\S-1-5-21-3191938311-3530252812-2698387358-1000\SOFTWARE | Run : [swg] - "C:\Program Files (x86)\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe"
    HKU\S-1-5-21-3191938311-3530252812-2698387358-1000\SOFTWARE | Run : [EPSON SX510W Series] - C:\Windows\system32\spool\DRIVERS\x64\3\E_IATIFIE.EXE /FU "C:\Windows\TEMP\E_S5521.tmp" /EF "HKCU"
    HKU\S-1-5-21-3191938311-3530252812-2698387358-1000\SOFTWARE | Run : [RESTART_STICKY_NOTES] - C:\Users\Proprietaire\Desktop\StikyNot.exe
    HKU\S-1-5-21-3191938311-3530252812-2698387358-1000\SOFTWARE | Run : [Sony PC Companion] - "C:\Program Files (x86)\Sony\Sony PC Companion\PCCompanion.exe" /Background
    HKU\S-1-5-21-3191938311-3530252812-2698387358-1000\SOFTWARE | Run : [Sidebar] - C:\Program Files\Windows Sidebar\sidebar.exe /autoRun
    HKU\S-1-5-19\SOFTWARE | RunOnce : [mctadmin] - C:\Windows\System32\mctadmin.exe
    HKU\S-1-5-20\SOFTWARE | RunOnce : [mctadmin] - C:\Windows\System32\mctadmin.exe

    ################## | Éléments infectieux |

    Présent! D:\desktop.ini

    ################## | Registre |

    ################## | Mountpoints2 |

    HKCU\.\.\.\.\Explorer\MountPoints2\{640604e4-fb57-11e1-8fe8-c80aa974ebae}
    Shell\AutoRun\Command = F:\SFR_Setup.exe

    ################## | Vaccin |

    (!) Cet ordinateur n'est pas vacciné!

    ################## | E.O.F | https://www.sosvirus.net/ |
    0
  4. Vous n’avez pas trouvé la réponse que vous recherchez ?

    Posez votre question
  5. billmaxime Messages postés 50526 Date d'inscription   Statut Contributeur Dernière intervention   6 152
     
    salut kulka

    effectivement, c'est propre maintenant

    tu as encore des soucis?

    @+
    0
Précédent
  • 1
  • 2