UsbFix V 7.129 | [Suppression]
Utilisateur: ANNA (Administrateur) # ANNABEL
Mis à jour le 24/06/2013 par El Desaparecido
Lancé à 17:09:10 | 15/08/2013
Site Web: http://sosvirus.net/
Upload Malware: http://www.sosvirus.net/upload-malware-pour-analyse-t489.html
Contact: ***@***
PC: System manufacturer (P5Q SE) (X86-based PC)
CPU: Intel(R) Core(TM)2 CPU 6320 @ 1.86GHz (1862)
RAM -> [Total : 2047 | Free : 1106]
BIOS: BIOS Date: 03/20/09 13:51:43 Ver: 08.00.14
BOOT: Normal boot
OS: Microsoft Windows XP Professionnel (5.1.2600 32-Bit) # Service Pack 3
WB: Windows Internet Explorer 8.0.6001.18702
SC: Security Center Service [Enabled]
WU: Windows Update Service [Enabled]
FW: Windows FireWall Service [Enabled]
C:\ (%systemdrive%) -> Disque fixe # 233 Go (50 Go libre(s) - 22%) [] # NTFS
D:\ -> Disque fixe # 466 Go (299 Go libre(s) - 64%) [] # NTFS
E:\ -> CD-ROM
F:\ -> CD-ROM
M:\ -> CD-ROM
################## | El Desaparecido Section |
HKLM\SOFTWARE | Run : [GrooveMonitor] - "C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe"
HKLM\SOFTWARE | Run : [Ai Nap] - "C:\Program Files\ASUS\AI Suite\AiNap\AiNap.exe"
HKLM\SOFTWARE | Run : [QFan Help] - "C:\Program Files\ASUS\AI Suite\QFan3\QFanHelp.exe"
HKLM\SOFTWARE | Run : [Cpu Level Up help] - C:\Program Files\ASUS\AI Suite\CpuLevelUpHelp.exe
HKLM\SOFTWARE | Run : [ASUS Update Checker] - C:\Program Files\ASUS\ASUSUpdate\UpdateChecker\UpdateChecker.exe
HKLM\SOFTWARE | Run : [VirtualCloneDrive] - "C:\Program Files\Elaborate Bytes\VirtualCloneDrive\VCDDaemon.exe" /s
HKLM\SOFTWARE | Run : [FUFAXRCV] - "C:\Program Files\Epson Software\FAX Utility\FUFAXRCV.exe"
HKLM\SOFTWARE | Run : [FUFAXSTM] - "C:\Program Files\Epson Software\FAX Utility\FUFAXSTM.exe"
HKLM\SOFTWARE | Run : [NWEReboot] -
HKLM\SOFTWARE | Run : [NeroFilterCheck] - C:\Program Files\Fichiers communs\Ahead\Lib\NeroCheck.exe
HKLM\SOFTWARE | Run : [Ulead AutoDetector] - C:\Program Files\Ulead Systems\Ulead Photo Explorer 8.0 SE Basic\Monitor.exe
HKLM\SOFTWARE | Run : [QuickTime Task] - "C:\Program Files\QuickTime\qttask.exe" -atboottime
HKLM\SOFTWARE | Run : [StartCCC] - "C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" MSRun
HKLM\SOFTWARE | Run : [RTHDCPL] - RTHDCPL.EXE
HKLM\SOFTWARE | Run : [Alcmtr] - ALCMTR.EXE
HKLM\SOFTWARE | Run : [NBAgent] - "C:\Program Files\Nero\Nero 10\Nero BackItUp\NBAgent.exe" /WinStart
HKLM\SOFTWARE | Run : [TrayServer] - C:\Program Files\MAGIX\Video_deluxe_16_Premium\TrayServer.exe
HKLM\SOFTWARE | Run : [USB2Check] - RUNDLL32.EXE "C:\WINDOWS\system32\PCLECoInst.dll",CheckUSBController
HKLM\SOFTWARE | Run : [USBToolTip] - "C:\Program Files\Pinnacle\Shared Files\Programs\USBTip\USBTip.exe"
HKLM\SOFTWARE | Run : [AdobeAAMUpdater-1.0] - "C:\Program Files\Fichiers communs\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe"
HKLM\SOFTWARE | Run : [ACU] - "C:\Program Files\OLITEC\ACU.exe" -nogui
HKLM\SOFTWARE | Run : [Adobe ARM] - "C:\Program Files\Fichiers communs\Adobe\ARM\1.0\AdobeARM.exe"
HKLM\SOFTWARE | Run : [SunJavaUpdateSched] - "C:\Program Files\Fichiers communs\Java\Java Update\jusched.exe"
HKLM\SOFTWARE | Run : [KiesTrayAgent] - C:\Program Files\Samsung\Kies\KiesTrayAgent.exe
HKLM\SOFTWARE | RunOnce : [] -
HKU\S-1-5-19\SOFTWARE | Run : [CTFMON.EXE] - C:\WINDOWS\System32\CTFMON.EXE
HKU\S-1-5-20\SOFTWARE | Run : [CTFMON.EXE] - C:\WINDOWS\System32\CTFMON.EXE
HKU\S-1-5-21-1960408961-492894223-839522115-1003\SOFTWARE | Run : [CTFMON.EXE] - C:\WINDOWS\system32\ctfmon.exe
HKU\S-1-5-21-1960408961-492894223-839522115-1003\SOFTWARE | Run : [BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] - "C:\Program Files\Fichiers communs\Ahead\Lib\NMBgMonitor.exe"
HKU\S-1-5-21-1960408961-492894223-839522115-1003\SOFTWARE | Run : [TomTomHOME.exe] - "C:\Program Files\TomTom HOME 2\TomTomHOMERunner.exe"
HKU\S-1-5-21-1960408961-492894223-839522115-1003\SOFTWARE | Run : [EPSON BX305 Plus Series] - C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_FATIHRE.EXE /FU "C:\DOCUME~1\ANNA\LOCALS~1\Temp\E_S77.tmp" /EF "HKCU"
HKU\S-1-5-21-1960408961-492894223-839522115-1003\SOFTWARE | Run : [KiesPreload] - C:\Program Files\Samsung\Kies\Kies.exe /preload
HKU\S-1-5-21-1960408961-492894223-839522115-1003\SOFTWARE | Run : [KiesAirMessage] - C:\Program Files\Samsung\Kies\KiesAirMessage.exe -startup
HKU\S-1-5-21-1960408961-492894223-839522115-1003\SOFTWARE | Run : [] - C:\Program Files\Samsung\Kies\External\FirmwareUpdate\KiesPDLR.exe
HKU\S-1-5-18\SOFTWARE | Run : [CTFMON.EXE] - C:\WINDOWS\System32\CTFMON.EXE
################## | Processus Stoppés |
Stoppé! C:\WINDOWS\system32\Ati2evxx.exe (1040)
Stoppé! C:\WINDOWS\system32\Ati2evxx.exe (1560)
Stoppé! C:\WINDOWS\system32\spoolsv.exe (1636)
Stoppé! C:\WINDOWS\system32\acs.exe (1760)
Stoppé! C:\Program Files\Adobe\Elements 10 Organizer\PhotoshopElementsFileAgent.exe (1168)
Stoppé! C:\Program Files\Fichiers communs\MAGIX Services\Database\bin\FABS.exe (1256)
Stoppé! C:\Program Files\Java\jre7\bin\jqs.exe (1300)
Stoppé! C:\Program Files\ma-config.com\MaConfigAgent.exe (1308)
Stoppé! C:\Program Files\Nero\Update\NASvc.exe (1612)
Stoppé! C:\Program Files\TomTom HOME 2\TomTomHOMEService.exe (1792)
Stoppé! C:\Program Files\Fichiers communs\Ulead Systems\DVD\ULCDRSvr.exe (260)
Stoppé! C:\Program Files\MAGIX\PC_Check_Tuning_2010\MxTray.exe (1752)
Stoppé! C:\WINDOWS\Explorer.EXE (1996)
Stoppé! C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe (2192)
Stoppé! C:\Program Files\ASUS\AI Suite\AiNap\AiNap.exe (2208)
Stoppé! C:\Program Files\Elaborate Bytes\VirtualCloneDrive\VCDDaemon.exe (2280)
Stoppé! C:\Program Files\Epson Software\FAX Utility\FUFAXRCV.exe (2320)
Stoppé! C:\Program Files\Epson Software\FAX Utility\FUFAXSTM.exe (2332)
Stoppé! C:\Program Files\Ulead Systems\Ulead Photo Explorer 8.0 SE Basic\Monitor.exe (2348)
Stoppé! C:\Program Files\QuickTime\qttask.exe (2356)
Stoppé! C:\WINDOWS\RTHDCPL.EXE (2372)
Stoppé! C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\MOM.exe (2384)
Stoppé! C:\Program Files\Nero\Nero 10\Nero BackItUp\NBAgent.exe (2408)
Stoppé! C:\Program Files\Pinnacle\Shared Files\Programs\USBTip\USBTip.exe (2460)
Stoppé! C:\Program Files\OLITEC\ACU.exe (2480)
Stoppé! C:\Program Files\Fichiers communs\Java\Java Update\jusched.exe (2500)
Stoppé! C:\Program Files\Samsung\Kies\KiesTrayAgent.exe (2516)
Stoppé! C:\WINDOWS\system32\ctfmon.exe (2528)
Stoppé! C:\Program Files\Fichiers communs\Ahead\Lib\NMBgMonitor.exe (2536)
Stoppé! C:\Program Files\TomTom HOME 2\TomTomHOMERunner.exe (2552)
Stoppé! C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_FATIHRE.EXE (2576)
Stoppé! C:\Program Files\Samsung\Kies\Kies.exe (2584)
Stoppé! C:\Program Files\Samsung\Kies\KiesAirMessage.exe (2612)
Stoppé! C:\Program Files\Samsung\Kies\External\FirmwareUpdate\KiesPDLR.exe (2640)
Stoppé! C:\Program Files\Ulead Systems\Ulead Photo Express 4.0 SE\CalCheck.exe (2812)
Stoppé! C:\Program Files\Micro Application\LauncherMA.exe (2872)
Stoppé! C:\Program Files\Microsoft Office\Office12\ONENOTEM.EXE (2884)
Stoppé! C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\ccc.exe (3388)
Stoppé! C:\WINDOWS\system32\wuauclt.exe (3684)
Stoppé! C:\WINDOWS\System32\wbem\wmiapsrv.exe (3860)
Stoppé! C:\WINDOWS\system32\wscntfy.exe (4088)
Stoppé! C:\Program Files\Mozilla Firefox\firefox.exe (3756)
Stoppé! C:\Program Files\Mozilla Firefox\plugin-container.exe (1052)
################## | Éléments infectieux |
Supprimé! D:\Thumbs.db
(!) Fichiers temporaires supprimés.
################## | Registre |
################## | Mountpoints2 |
Supprimé! HKCU\.\.\.\.\Explorer\MountPoints2\{91d7fd29-6afe-11e2-8145-806d6172696f}
################## | Listing |
[31/01/2013 - 01:22:45 | N | 898744] C:\adorage-protocol.txt
[15/02/2013 - 19:30:25 | N | 14329] C:\AdwCleaner[R1].txt
[15/02/2013 - 19:42:49 | N | 1643] C:\AdwCleaner[R2].txt
[11/03/2013 - 23:34:42 | N | 3606] C:\AdwCleaner[R3].txt
[11/03/2013 - 23:41:45 | N | 1315] C:\AdwCleaner[R4].txt
[10/05/2013 - 15:57:52 | N | 2329] C:\AdwCleaner[R5].txt
[10/05/2013 - 15:58:41 | N | 2389] C:\AdwCleaner[R6].txt
[15/02/2013 - 19:31:44 | N | 14477] C:\AdwCleaner[S1].txt
[15/02/2013 - 19:43:29 | N | 1556] C:\AdwCleaner[S2].txt
[11/03/2013 - 23:35:04 | N | 3704] C:\AdwCleaner[S3].txt
[15/08/2013 - 13:55:50 | N | 395] C:\AdwCleaner[S4].txt
[15/08/2013 - 16:43:00 | N | 4427] C:\AdwCleaner[S5].txt
[15/08/2013 - 17:00:08 | N | 1861] C:\AdwCleaner[S6].txt
[30/01/2013 - 19:45:57 | D ] C:\AMD
[30/01/2013 - 19:30:58 | D ] C:\ATI
[31/01/2013 - 00:15:23 | N | 95] C:\AUTOEXEC.BAT
[30/01/2013 - 18:29:32 | N | 212] C:\boot.ini
[28/08/2001 - 14:00:00 | N | 4952] C:\Bootfont.bin
[30/01/2013 - 18:18:43 | N | 0] C:\CONFIG.SYS
[17/02/2013 - 16:44:42 | N | 0] C:\DBS.TXT
[30/01/2013 - 18:40:04 | D ] C:\dell
[06/08/2013 - 23:28:44 | D ] C:\Documents and Settings
[30/01/2013 - 18:40:08 | D ] C:\Intel
[30/01/2013 - 18:18:43 | N | 0] C:\IO.SYS
[18/03/2013 - 22:27:55 | N | 477] C:\LOG46.log
[18/03/2013 - 22:27:55 | N | 0] C:\LOG46.tmp
[30/01/2013 - 18:18:43 | N | 0] C:\MSDOS.SYS
[30/01/2013 - 18:35:35 | RHD ] C:\MSOCache
[30/01/2013 - 18:26:08 | N | 47564] C:\NTDETECT.COM
[30/01/2013 - 18:26:08 | N | 252240] C:\ntldr
[31/01/2013 - 07:25:36 | D ] C:\OEMSettings
[15/08/2013 - 17:01:21 | ASH | 2145386496] C:\pagefile.sys
[15/08/2013 - 13:14:22 | N | 512] C:\PhysicalDisk0_MBR.bin
[15/08/2013 - 16:49:23 | D ] C:\Program Files
[30/01/2013 - 21:10:16 | SHD ] C:\RECYCLER
[31/01/2013 - 07:24:41 | D ] C:\setup-pcipccard80211sgv2
[30/01/2013 - 19:57:38 | D ] C:\SmartSound Software
[30/01/2013 - 18:31:49 | SHD ] C:\System Volume Information
[31/01/2013 - 07:24:47 | D ] C:\temp
[15/08/2013 - 17:19:14 | D ] C:\UsbFix
[15/08/2013 - 16:54:09 | N | 4621] C:\UsbFix [Clean 1] ANNABEL.txt
[15/08/2013 - 17:19:36 | A | 9956] C:\UsbFix [Clean 3] ANNABEL.txt
[15/08/2013 - 12:54:41 | D ] C:\WINDOWS
[15/08/2013 - 13:10:31 | D ] C:\ZHP
[29/03/2013 - 21:38:47 | N | 7797660] D:\.H0
[26/07/2013 - 21:04:22 | N | 45347] D:\2013-07-26.JPG
[02/08/2013 - 20:33:37 | N | 181534233] D:\Aides-moi Seigneur .mp4
[17/03/2013 - 16:00:54 | N | 8704] D:\Aimé.VSP
[17/02/2013 - 05:07:04 | N | 917118881] D:\Albert (119).MOV
[12/07/2013 - 14:28:12 | N | 2020530176] D:\Album Dallya.mpg
[12/07/2013 - 14:28:12 | N | 3035] D:\Album Dallya.upd
[12/07/2013 - 12:53:16 | N | 1064960] D:\Album Dallya.VSP
[28/07/2013 - 22:32:38 | N | 3896] D:\Album Dallya_mpg.AVD
[29/07/2013 - 06:33:25 | N | 2268] D:\Album Dallya_mpg.HDP
[21/10/2012 - 21:07:55 | N | 641118208] D:\Album Guy 1.mpg
[25/10/2012 - 17:21:07 | N | 254990336] D:\Album guy 2.mpg
[20/07/2013 - 21:21:33 | N | 675489792] D:\Album Hélène 50 ans.mpg
[20/07/2013 - 20:49:23 | N | 294912] D:\Album Hélène 50 ans.VSP
[24/05/2013 - 23:09:33 | N | 99328000] D:\Anna.mpg
[03/07/2013 - 22:40:06 | N | 2325317632] D:\BONDO.mpg
[20/07/2013 - 19:31:41 | D ] D:\Clé Abel musiques
[08/07/2013 - 05:05:56 | N | 302139392] D:\Cortège Dallya ok.mpg
[08/07/2013 - 04:56:05 | N | 310935552] D:\Cortège Dallya.mpg
[07/07/2013 - 13:57:39 | N | 8010567680] D:\DALLYA.mpg
[07/07/2013 - 15:41:55 | N | 3724843008] D:\DALLYA1.mpg
[18/04/2013 - 20:48:47 | N | 1528064000] D:\Dimitry.mpg
[23/05/2013 - 19:29:52 | N | 1563883520] D:\EXAUCE LUWA.mpg
[03/07/2013 - 19:26:09 | N | 3896] D:\EXAUCE LUWA_mpg.AVD
[09/08/2013 - 12:01:03 | N | 79430015488] D:\Fichier Dallya ok.AVI
[09/08/2013 - 05:27:30 | N | 16374679552] D:\Fichier Dallya ok.mpg
[12/08/2012 - 20:20:37 | N | 3631532032] D:\GUY 1.mpg
[19/07/2013 - 21:16:19 | N | 3896] D:\GUY 1_mpg.AVD
[19/07/2013 - 21:25:56 | N | 2268] D:\GUY 1_mpg.HDP
[15/08/2012 - 00:40:27 | N | 6998452224] D:\GUY 2.mpg
[28/07/2013 - 17:44:19 | N | 123285504] D:\Géné fin Dallya.mpg
[28/07/2013 - 17:37:54 | N | 130560] D:\Géné fin Dallya.VSP
[24/07/2013 - 17:17:12 | N | 140904448] D:\Géné fin Hélène 50 nas.mpg
[24/07/2013 - 17:10:48 | N | 383488] D:\Géné fin Hélène 50 nas.VSP
[19/07/2013 - 22:46:28 | N | 367104] D:\Géné fin Kankolongo.VSP
[21/07/2013 - 01:23:22 | N | 4337242112] D:\Hélène 50 ans.mpg
[26/07/2013 - 21:18:46 | N | 3896] D:\Hélène 50 ans_mpg.AVD
[26/07/2013 - 23:44:29 | N | 2268] D:\Hélène 50 ans_mpg.HDP
[25/07/2013 - 19:15:38 | N | 101007620] D:\Hélène Facebook.mp4
[18/07/2013 - 20:54:46 | N | 41512] D:\Kankolongo.JPG
[18/07/2013 - 21:05:59 | N | 45106] D:\Kankolongo.JPG 2.JPG
[31/07/2013 - 14:56:15 | N | 7238483968] D:\Mariage Nsimba.mpg
[31/07/2013 - 16:25:03 | N | 3224788992] D:\Mariage Nsimba1.mpg
[15/08/2013 - 13:18:39 | N | 3896] D:\Mariage Nsimba1_mpg.AVD
[15/08/2013 - 17:16:11 | N | 2268] D:\Mariage Nsimba1_mpg.HDP
[15/08/2013 - 13:18:38 | N | 3896] D:\Mariage Nsimba_mpg.AVD
[15/08/2013 - 17:16:11 | N | 2268] D:\Mariage Nsimba_mpg.HDP
[09/08/2013 - 18:47:34 | N | 301316096] D:\Nsimba cortege.mpg
[15/08/2013 - 13:25:38 | N | 3896] D:\Nsimba cortege_mpg.AVD
[15/08/2013 - 17:16:12 | N | 2268] D:\Nsimba cortege_mpg.HDP
[28/07/2013 - 21:29:30 | D ] D:\oncle
[01/02/2013 - 16:55:39 | SHD ] D:\RECYCLER
[12/07/2013 - 12:55:35 | D ] D:\RUFFIN_LITHY
[26/05/2013 - 13:30:48 | SHD ] D:\System Volume Information
[28/07/2013 - 17:15:59 | N | 71827456] D:\Vidéo d'intro Dallya dvd 1.mpg
[28/07/2013 - 22:48:50 | N | 3896] D:\Vidéo d'intro Dallya dvd 1_mpg.AVD
[28/07/2013 - 23:59:38 | N | 2268] D:\Vidéo d'intro Dallya dvd 1_mpg.HDP
[26/07/2013 - 21:24:56 | N | 52768768] D:\Vidéo d'intro Hélène 50 ans.mpg
[26/07/2013 - 23:04:18 | N | 2268] D:\Vidéo d'intro Hélène 50 ans_mpg.HDP
[25/07/2013 - 18:53:00 | N | 146180096] D:\Vidéo debut Hélène 50 ans.mpg
[14/03/2013 - 23:24:54 | D ] D:\Vidéos Abel
################## | Vaccin |
C:\Autorun.inf -> Vaccin créé par UsbFix (El Desaparecido)
D:\Autorun.inf -> Vaccin créé par UsbFix (El Desaparecido)
################## | E.O.F | http://sosvirus.net |
Je veux voir cela et je te tiens au courant.