Fichier en raccouris
dnph2010
Messages postés
10
Date d'inscription
Statut
Membre
Dernière intervention
-
2011N2 Messages postés 13352 Date d'inscription Statut Contributeur sécurité Dernière intervention -
2011N2 Messages postés 13352 Date d'inscription Statut Contributeur sécurité Dernière intervention -
bonjour!
j'ai un virus qui transforme mes fichier en raccourci. après le scan avec usbfix voici le rapport. Pouviez me venir en aide pour la suite?Merci d'avance.
############################## | UsbFix V 7.133 | [Research]
User: EKANZA-PC (Administrator) # EKANZA
Updated 27/08/2013 by El Desaparecido
Started at 10:40:38 | 27/08/2013
Website: https://www.sosvirus.net/
Upload Malware: http://sosvirus.net/viewtopic.php?f=6&t=489
Contact: eldesaparecido@sosvirus.net
PC: Hewlett-Packard (HP Compaq 6735s) (X86-based PC)
CPU: AMD Sempron(tm) SI-42 (2100)
RAM -> [Total : 1789 | Free : 524]
BIOS: Default System BIOS
BOOT: Normal boot
OS: Microsoft Windows 8 Professionnel (6.2.9200 32-Bit) #
WB: Windows Internet Explorer 10.0.9200.16540
SC: Security Center Service [Enabled]
WU: Windows Update Service [(!) Disabled]
AV: Windows Defender [Enabled | (!) Outdated]
FW: Windows FireWall Service [Enabled]
C:\ (%systemdrive%) -> Fixed drive # 59 Gb (6 Mb free - 10%) [] # NTFS
D:\ -> Fixed drive # 51 Gb (2 Mb free - 3%) [Disque local ] # NTFS
E:\ -> Fixed drive # 39 Gb (775 Mb free - 2%) [] # NTFS
F:\ -> CD-ROM
G:\ -> CD-ROM
H:\ -> Removable drive # 4 Gb (4 Mb free - 100%) [AMARA II] # FAT32
################## | Active Processes |
C:\WINDOWS\system32\csrss.exe (468)
C:\WINDOWS\system32\wininit.exe (588)
C:\WINDOWS\system32\services.exe (656)
C:\WINDOWS\system32\lsass.exe (664)
C:\WINDOWS\system32\svchost.exe (772)
C:\WINDOWS\system32\svchost.exe (812)
C:\WINDOWS\System32\svchost.exe (872)
C:\WINDOWS\system32\svchost.exe (1036)
C:\WINDOWS\system32\svchost.exe (1068)
C:\WINDOWS\System32\svchost.exe (1140)
C:\WINDOWS\system32\Hpservice.exe (1216)
C:\WINDOWS\system32\svchost.exe (1256)
C:\WINDOWS\System32\spoolsv.exe (1452)
C:\WINDOWS\system32\svchost.exe (1480)
C:\Program Files\Bonjour\mDNSResponder.exe (1636)
C:\Program Files\InternetEverywhere\InternetEverywhere_Service.exe (1680)
C:\WINDOWS\system32\dashost.exe (1704)
C:\WINDOWS\system32\rpcnet.exe (1748)
C:\WINDOWS\system32\svchost.exe (1832)
C:\Program Files\Common Files\AVG Secure Search\vToolbarUpdater\15.5.0\ToolbarUpdater.exe (1936)
c:\wamp5\apache2\bin\httpd.exe (1964)
c:\wamp5\mysql\bin\mysqld-nt.exe (1996)
C:\Program Files\Windows Defender\MsMpEng.exe (2016)
C:\Program Files\Common Files\AVG Secure Search\vToolbarUpdater\15.5.0\loggingserver.exe (884)
C:\WINDOWS\system32\conhost.exe (1080)
C:\wamp5\apache2\bin\httpd.exe (2256)
C:\WINDOWS\system32\svchost.exe (3692)
C:\Windows\System32\WUDFHost.exe (3848)
C:\WINDOWS\system32\SearchIndexer.exe (4348)
C:\Program Files\Hewlett-Packard\Shared\hpqwmiex.exe (4688)
C:\WINDOWS\system32\wbem\wmiprvse.exe (4652)
C:\Program Files\Hewlett-Packard\HP Quick Launch Buttons\Com4QLBEx.exe (4200)
C:\WINDOWS\system32\csrss.exe (3540)
C:\WINDOWS\System32\WinLogon.exe (1660)
C:\WINDOWS\System32\dwm.exe (3372)
C:\WINDOWS\system32\taskhostex.exe (5848)
C:\WINDOWS\Explorer.EXE (3972)
C:\Program Files\WindowsApps\microsoft.windowscommunicationsapps_16.4.4206.722_x86__8wekyb3d8bbwe\LiveComm.exe (5328)
C:\Windows\System32\RuntimeBroker.exe (2088)
C:\Program Files\AVG Secure Search\vprot.exe (3920)
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe (4904)
C:\Program Files\Hewlett-Packard\HP Quick Launch Buttons\QLBCtrl.exe (596)
C:\Program Files\Synaptics\SynTP\SynTPHelper.exe (4740)
C:\Program Files\Hewlett-Packard\HP Quick Launch Buttons\VolCtrl.exe (5708)
C:\Program Files\Nitro PDF\Professional\NitroPDFPrinterMonitor.exe (412)
C:\Program Files\Common Files\Java\Java Update\jusched.exe (3584)
C:\Program Files\SuperCopier2\SuperCopier2.exe (5544)
C:\Program Files\Skype\Phone\Skype.exe (4464)
C:\Users\EKANZA-PC\AppData\Local\Microsoft\SkyDrive\SkyDrive.exe (3472)
C:\Program Files\Microsoft Office\Office14\MSOSYNC.EXE (4520)
C:\Users\EKANZA-PC\IMG 257654.bmp.scr (5492)
C:\Program Files\Larousse\Petit Larousse 2010\bin\Hyperappel.exe (6068)
C:\Program Files\InternetEverywhere\InternetEverywhere_Launcher.exe (1392)
C:\Users\EKANZA-PC\AppData\Roaming\Dropbox\bin\Dropbox.exe (5816)
C:\Program Files\Micro Application\38 Dictionnaires et Recueils de Correspondance\MediaDico38.exe (3444)
C:\Program Files\Micro Application\38 Dictionnaires et Recueils de Correspondance\RAC38.exe (1172)
C:\wamp5\wampmanager.exe (5240)
C:\Program Files\Microsoft Office\Office14\OUTLOOK.EXE (4392)
C:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPSVC.EXE (6076)
C:\Program Files\Google\Chrome\Application\chrome.exe (4648)
C:\Program Files\Google\Chrome\Application\chrome.exe (3992)
C:\Program Files\Google\Chrome\Application\chrome.exe (912)
C:\Program Files\Google\Chrome\Application\chrome.exe (740)
C:\Program Files\Common Files\Adobe\OOBE\PDApp\UWA\AAM Updates Notifier.exe (1720)
C:\Program Files\Google\Chrome\Application\chrome.exe (6256)
C:\Program Files\Google\Chrome\Application\chrome.exe (6348)
C:\Program Files\Google\Chrome\Application\chrome.exe (2268)
C:\WINDOWS\system32\wbem\wmiprvse.exe (1948)
C:\Program Files\Google\Chrome\Application\chrome.exe (7512)
C:\Users\EKANZA~1\AppData\Local\Temp\tmp2013101700\setup.exe (7312)
C:\WINDOWS\system32\NOTEPAD.EXE (4284)
C:\WINDOWS\system32\SearchProtocolHost.exe (7980)
C:\UsbFix\Go.exe (6428)
C:\WINDOWS\system32\SearchFilterHost.exe (6304)
################## | El Desaparecido Section |
HKLM\SOFTWARE | Run : [vProt] - "C:\Program Files\AVG Secure Search\vprot.exe"
HKLM\SOFTWARE | Run : [Adobe ARM] - "C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
HKLM\SOFTWARE | Run : [SynTPEnh] - %ProgramFiles%\Synaptics\SynTP\SynTPEnh.exe
HKLM\SOFTWARE | Run : [QlbCtrl.exe] - C:\Program Files\Hewlett-Packard\HP Quick Launch Buttons\QlbCtrl.exe /Start
HKLM\SOFTWARE | Run : [Nitro PDF Printer Monitor] - "C:\Program Files\Nitro PDF\Professional\NitroPDFPrinterMonitor.exe"
HKLM\SOFTWARE | Run : [SunJavaUpdateSched] - "C:\Program Files\Common Files\Java\Java Update\jusched.exe"
HKLM\SOFTWARE | Run : [AdobeAAMUpdater-1.0] - "C:\Program Files\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe"
HKLM\SOFTWARE | Run : [AdobeCS5ServiceManager] - "C:\Program Files\Common Files\Adobe\CS5ServiceManager\CS5ServiceManager.exe" -launchedbylogin
HKLM\SOFTWARE | RunOnce : [] -
HKU\S-1-5-21-178000282-2722677192-2624188697-1001\SOFTWARE | Run : [SuperCopier2.exe] - C:\Program Files\SuperCopier2\SuperCopier2.exe
HKU\S-1-5-21-178000282-2722677192-2624188697-1001\SOFTWARE | Run : [MediaDICO38] - C:\Program Files\Micro Application\38 Dictionnaires et Recueils de Correspondance\LanceMediaDICO38.exe Lancement
HKU\S-1-5-21-178000282-2722677192-2624188697-1001\SOFTWARE | Run : [Skype] - "C:\Program Files\Skype\Phone\Skype.exe" /minimized /regrun
HKU\S-1-5-21-178000282-2722677192-2624188697-1001\SOFTWARE | Run : [SkyDrive] - "C:\Users\EKANZA-PC\AppData\Local\Microsoft\SkyDrive\SkyDrive.exe" /background
HKU\S-1-5-21-178000282-2722677192-2624188697-1001\SOFTWARE | Run : [OfficeSyncProcess] - "C:\Program Files\Microsoft Office\Office14\MSOSYNC.EXE"
HKU\S-1-5-21-178000282-2722677192-2624188697-1001\SOFTWARE | Run : [help.vbs] - "C:\Users\EKANZA~1\AppData\Local\Temp\help.vbs"
HKU\S-1-5-21-178000282-2722677192-2624188697-1001\SOFTWARE | Run : [IMG 257654.bmp] - "C:\Users\EKANZA-PC\IMG 257654.bmp.scr"
################## | Files # Infected Folders |
Found ! H:\DISCOURS DE MONSIEUR EDI A L.LNK
Found ! H:\DSCF2159.LNK
Found ! H:\DSCF2166.LNK
Found ! H:\ELECTION REGIONALE.LNK
Found ! H:\ENSEIGNE_ONG_ACTE_1.LNK
Found ! H:\ENSEIGNE_ONG_ACTE_2.LNK
Found ! H:\ENSEIGNE_ONG_ACTES 4m.LNK
Found ! H:\esquiss_en_cours-1 arcom.LNK
Found ! H:\esquiss_suite-1.LNK
Found ! H:\FACTURE PAYEE POUR UNE PARUTION DANS ARCOMCentre de Santé Nimatoullah.LNK
Found ! H:\form_personnel_elections_regionales.LNK
Found ! H:\Index des nom1.LNK
Found ! H:\Index des noms et concepts (Enregistré automatiquement).LNK
Found ! H:\PENDA.LNK
Found ! H:\TRAORE.lnk
Found ! H:\languette.LNK
Found ! H:\LCD N° 661-1.LNK
Found ! H:\Liste de personnes pressenties pour le conseil régionale après enquêtes.LNK
Found ! H:\Liste de quelques militants du Fpi proposée par Salifou Amara.LNK
Found ! H:\LISTE DES REALISATIONS-1.LNK
Found ! H:\LISTE DU MATERIEL DES TRAVAUX PUBLICS.LNK
Found ! H:\LISTE EDI RÉNÉ UNION RETROUVEE POUR LE DEVELOPPEMENT ET LA PROSPERITÉ.LNK
Found ! H:\Liste probable de conseillers ou personnes ressources présentées par Amara.LNK
Found ! H:\LOGO DEUX EDI RENE.LNK
Found ! H:\Messe d'action de grâce de l'Eglise Catholique de Rubino.LNK
Found ! H:\N 3 nv introduction de technique et politique chez herbert marcuse prof bah.LNK
Found ! H:\N 3 nv introduction de technique et politique chez herbert marcuse-1 (thèse definitive) 1.pdf.LNK
Found ! H:\Page de garde Rapport.LNK
Found ! H:\PAGINATION THESE.LNK
Found ! H:\PC_BOOSTER.LNK
Found ! H:\Photo Beach.LNK
Found ! H:\photo Dossa Charlotte Bassam.LNK
Found ! H:\photo kodjo Kouassi Frederic Bassam.LNK
Found ! H:\photo Nina.LNK
Found ! H:\photo Touakesseu Mélanie bassam.LNK
Found ! H:\POINTS DU DISCOURS EDI RENE A GRAND MORIE.LNK
Found ! H:\pre rapport professeur Bah.LNK
Found ! H:\Préinscription universitaire Année scolaire 2012-2013.LNK
Found ! H:\Présentation de la thèse « Technique et politique chez Herbert Marcuse ».LNK
Found ! H:\Présentation sommaire du candidat EDI RENÉ.LNK
Found ! H:\projets réalisés 2001-2012 (version 1).LNK
Found ! H:\Quelques précisions à la suite du pré.LNK
Found ! H:\Rapport final (définitif).LNK
Found ! H:\Regionale Agneby taabo.LNK
Found ! H:\REGROUPEMENT DES VILLAGES PAR LIGNE.LNK
Found ! H:\REMERCIEMENTS thèse.LNK
Found ! H:\REPARTITIONS DE 1000 CALENDRIERS BANCAIRES.LNK
Found ! H:\RESUME DE LA THESE.LNK
Found ! H:\Service communication et animation.LNK
Found ! H:\UsbFix.LNK
Found ! H:\ShortcutVirusRemover.LNK
Found ! H:\Nouveau dossier.lnk
Found ! H:\Signature Amara.LNK
Found ! H:\Slogan Campagne Edi René pour affiches et tee shirt.LNK
Found ! H:\SOUTENANCE DE THESE DE DOCTORAT.LNK
Found ! H:\SPOT EDI RENE 1.LNK
Found ! H:\STRUCTURATION DU DISCOURS DE M. EDI RENE A SIKENSI.LNK
Found ! H:\STRUCTURATION DU DISCOURS DU DRC A SIKENSI.LNK
Found ! H:\Supports et communication conseil régional Agneby.LNK
Found ! H:\Tableau stratégie EDI RENE.LNK
Found ! H:\tarifs comdev.LNK
Found ! H:\Thèse Amara Salifou.LNK
Found ! H:\Thèse Amara Salifou 1.LNK
Found ! H:\T-shirts-1 Casquettes campagne.LNK
Found ! H:\.LNK
Found ! H:\._.LNK
Found ! H:\~WRL0910.LNK
Found ! H:\Agboville.LNK
Found ! H:\Agboville grand morié.LNK
Found ! H:\ARCOM.LNK
Found ! H:\ARCOM journal definitif corrigé.LNK
Found ! H:\ARCOM n°002_Mise en page 1.LNK
Found ! H:\arcom_journal_specimen.LNK
Found ! H:\ARCOM_Mise en page derniere monture.LNK
Found ! H:\ARGUMENTAIRE POUR ARCOM.LNK
Found ! H:\AU COMITE ROYAL DU FESTIVAL CLIMBIE BEACH D'ASSINIE-MAFIA (FECBA).LNK
Found ! H:\Autorun.LNK
Found ! H:\BAH.LNK
Found ! H:\Communication Chefs de terre et Manifestation jeunes Rubino.LNK
Found ! H:\config.LNK
Found ! H:\Copie de Conseil Régional-liste de synthèse provisoire-version ldc1-1.LNK
Found ! H:\Copie de RESUME DE LA THESE.LNK
Found ! H:\courrier à monsieur Kipré Digbeu.LNK
Found ! H:\CREA BOUAKE OK.LNK
Found ! H:\cvisit_amara arcom.LNK
Found ! H:\Dao.LNK
Found ! H:\DEMANDE DE SPONSORING.LNK
Found ! H:\des femmes leaders LMP choisissent Edi René.LNK
Found ! H:\Développement de proximité à Agboville.LNK
Found ! H:\Diby Cléophas Lolo.LNK
Found ! H:\DISCOURS DE M. EDI RENE A L'EGLISE CATHOLIQUE DE RUBINO.LNK
Found ! H:\DISCOURS DE MONSIEUR EDI A KODIMASSO.LNK
Found ! C:\Users\EKANZA-PC\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\IMG 257654.bmp.scr
Found ! C:\Users\EKANZA-PC\IMG 257654.bmp.scr
Found ! H:\IMG 257654.bmp.scr
################## | Registry |
Found ! HKCU\Software\Microsoft\Windows\CurrentVersion\Run|help.vbs
################## | Mountpoints2 |
HKCU\.\.\.\.\Explorer\MountPoints2\{05b12f66-b8ef-11e2-afe1-00247e30c1c0}
Shell\AutoRun\Command = "J:\Setup.exe"
HKCU\.\.\.\.\Explorer\MountPoints2\{16fbe5b7-a542-11e2-afb8-00247e30c1c0}
Shell\AutoRun\Command = "I:\Setup.exe"
HKCU\.\.\.\.\Explorer\MountPoints2\{3b0f15be-955c-11e2-af9c-002481413300}
Shell\AutoRun\Command = "I:\.\Setup.exe" AUTORUN=1
HKCU\.\.\.\.\Explorer\MountPoints2\{954416f2-bbc6-11e2-afe4-404d8e4ad39e}
Shell\AutoRun\Command = "G:\.\Setup.exe" AUTORUN=1
HKCU\.\.\.\.\Explorer\MountPoints2\{95441706-bbc6-11e2-afe4-404d8e4ad39e}
Shell\AutoRun\Command = "G:\.\Setup.exe" AUTORUN=1
HKCU\.\.\.\.\Explorer\MountPoints2\{9544171a-bbc6-11e2-afe4-404d8e4ad39e}
Shell\AutoRun\Command = "G:\.\Setup.exe" AUTORUN=1
HKCU\.\.\.\.\Explorer\MountPoints2\{f5e7e832-95ee-11e2-afa0-002481413300}
Shell\AutoRun\Command = "H:\.\Setup.exe" AUTORUN=1
################## | Vaccin |
(!) This computer is not vaccinated!
################## | E.O.F | https://www.sosvirus.net/ |
j'ai un virus qui transforme mes fichier en raccourci. après le scan avec usbfix voici le rapport. Pouviez me venir en aide pour la suite?Merci d'avance.
############################## | UsbFix V 7.133 | [Research]
User: EKANZA-PC (Administrator) # EKANZA
Updated 27/08/2013 by El Desaparecido
Started at 10:40:38 | 27/08/2013
Website: https://www.sosvirus.net/
Upload Malware: http://sosvirus.net/viewtopic.php?f=6&t=489
Contact: eldesaparecido@sosvirus.net
PC: Hewlett-Packard (HP Compaq 6735s) (X86-based PC)
CPU: AMD Sempron(tm) SI-42 (2100)
RAM -> [Total : 1789 | Free : 524]
BIOS: Default System BIOS
BOOT: Normal boot
OS: Microsoft Windows 8 Professionnel (6.2.9200 32-Bit) #
WB: Windows Internet Explorer 10.0.9200.16540
SC: Security Center Service [Enabled]
WU: Windows Update Service [(!) Disabled]
AV: Windows Defender [Enabled | (!) Outdated]
FW: Windows FireWall Service [Enabled]
C:\ (%systemdrive%) -> Fixed drive # 59 Gb (6 Mb free - 10%) [] # NTFS
D:\ -> Fixed drive # 51 Gb (2 Mb free - 3%) [Disque local ] # NTFS
E:\ -> Fixed drive # 39 Gb (775 Mb free - 2%) [] # NTFS
F:\ -> CD-ROM
G:\ -> CD-ROM
H:\ -> Removable drive # 4 Gb (4 Mb free - 100%) [AMARA II] # FAT32
################## | Active Processes |
C:\WINDOWS\system32\csrss.exe (468)
C:\WINDOWS\system32\wininit.exe (588)
C:\WINDOWS\system32\services.exe (656)
C:\WINDOWS\system32\lsass.exe (664)
C:\WINDOWS\system32\svchost.exe (772)
C:\WINDOWS\system32\svchost.exe (812)
C:\WINDOWS\System32\svchost.exe (872)
C:\WINDOWS\system32\svchost.exe (1036)
C:\WINDOWS\system32\svchost.exe (1068)
C:\WINDOWS\System32\svchost.exe (1140)
C:\WINDOWS\system32\Hpservice.exe (1216)
C:\WINDOWS\system32\svchost.exe (1256)
C:\WINDOWS\System32\spoolsv.exe (1452)
C:\WINDOWS\system32\svchost.exe (1480)
C:\Program Files\Bonjour\mDNSResponder.exe (1636)
C:\Program Files\InternetEverywhere\InternetEverywhere_Service.exe (1680)
C:\WINDOWS\system32\dashost.exe (1704)
C:\WINDOWS\system32\rpcnet.exe (1748)
C:\WINDOWS\system32\svchost.exe (1832)
C:\Program Files\Common Files\AVG Secure Search\vToolbarUpdater\15.5.0\ToolbarUpdater.exe (1936)
c:\wamp5\apache2\bin\httpd.exe (1964)
c:\wamp5\mysql\bin\mysqld-nt.exe (1996)
C:\Program Files\Windows Defender\MsMpEng.exe (2016)
C:\Program Files\Common Files\AVG Secure Search\vToolbarUpdater\15.5.0\loggingserver.exe (884)
C:\WINDOWS\system32\conhost.exe (1080)
C:\wamp5\apache2\bin\httpd.exe (2256)
C:\WINDOWS\system32\svchost.exe (3692)
C:\Windows\System32\WUDFHost.exe (3848)
C:\WINDOWS\system32\SearchIndexer.exe (4348)
C:\Program Files\Hewlett-Packard\Shared\hpqwmiex.exe (4688)
C:\WINDOWS\system32\wbem\wmiprvse.exe (4652)
C:\Program Files\Hewlett-Packard\HP Quick Launch Buttons\Com4QLBEx.exe (4200)
C:\WINDOWS\system32\csrss.exe (3540)
C:\WINDOWS\System32\WinLogon.exe (1660)
C:\WINDOWS\System32\dwm.exe (3372)
C:\WINDOWS\system32\taskhostex.exe (5848)
C:\WINDOWS\Explorer.EXE (3972)
C:\Program Files\WindowsApps\microsoft.windowscommunicationsapps_16.4.4206.722_x86__8wekyb3d8bbwe\LiveComm.exe (5328)
C:\Windows\System32\RuntimeBroker.exe (2088)
C:\Program Files\AVG Secure Search\vprot.exe (3920)
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe (4904)
C:\Program Files\Hewlett-Packard\HP Quick Launch Buttons\QLBCtrl.exe (596)
C:\Program Files\Synaptics\SynTP\SynTPHelper.exe (4740)
C:\Program Files\Hewlett-Packard\HP Quick Launch Buttons\VolCtrl.exe (5708)
C:\Program Files\Nitro PDF\Professional\NitroPDFPrinterMonitor.exe (412)
C:\Program Files\Common Files\Java\Java Update\jusched.exe (3584)
C:\Program Files\SuperCopier2\SuperCopier2.exe (5544)
C:\Program Files\Skype\Phone\Skype.exe (4464)
C:\Users\EKANZA-PC\AppData\Local\Microsoft\SkyDrive\SkyDrive.exe (3472)
C:\Program Files\Microsoft Office\Office14\MSOSYNC.EXE (4520)
C:\Users\EKANZA-PC\IMG 257654.bmp.scr (5492)
C:\Program Files\Larousse\Petit Larousse 2010\bin\Hyperappel.exe (6068)
C:\Program Files\InternetEverywhere\InternetEverywhere_Launcher.exe (1392)
C:\Users\EKANZA-PC\AppData\Roaming\Dropbox\bin\Dropbox.exe (5816)
C:\Program Files\Micro Application\38 Dictionnaires et Recueils de Correspondance\MediaDico38.exe (3444)
C:\Program Files\Micro Application\38 Dictionnaires et Recueils de Correspondance\RAC38.exe (1172)
C:\wamp5\wampmanager.exe (5240)
C:\Program Files\Microsoft Office\Office14\OUTLOOK.EXE (4392)
C:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPSVC.EXE (6076)
C:\Program Files\Google\Chrome\Application\chrome.exe (4648)
C:\Program Files\Google\Chrome\Application\chrome.exe (3992)
C:\Program Files\Google\Chrome\Application\chrome.exe (912)
C:\Program Files\Google\Chrome\Application\chrome.exe (740)
C:\Program Files\Common Files\Adobe\OOBE\PDApp\UWA\AAM Updates Notifier.exe (1720)
C:\Program Files\Google\Chrome\Application\chrome.exe (6256)
C:\Program Files\Google\Chrome\Application\chrome.exe (6348)
C:\Program Files\Google\Chrome\Application\chrome.exe (2268)
C:\WINDOWS\system32\wbem\wmiprvse.exe (1948)
C:\Program Files\Google\Chrome\Application\chrome.exe (7512)
C:\Users\EKANZA~1\AppData\Local\Temp\tmp2013101700\setup.exe (7312)
C:\WINDOWS\system32\NOTEPAD.EXE (4284)
C:\WINDOWS\system32\SearchProtocolHost.exe (7980)
C:\UsbFix\Go.exe (6428)
C:\WINDOWS\system32\SearchFilterHost.exe (6304)
################## | El Desaparecido Section |
HKLM\SOFTWARE | Run : [vProt] - "C:\Program Files\AVG Secure Search\vprot.exe"
HKLM\SOFTWARE | Run : [Adobe ARM] - "C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
HKLM\SOFTWARE | Run : [SynTPEnh] - %ProgramFiles%\Synaptics\SynTP\SynTPEnh.exe
HKLM\SOFTWARE | Run : [QlbCtrl.exe] - C:\Program Files\Hewlett-Packard\HP Quick Launch Buttons\QlbCtrl.exe /Start
HKLM\SOFTWARE | Run : [Nitro PDF Printer Monitor] - "C:\Program Files\Nitro PDF\Professional\NitroPDFPrinterMonitor.exe"
HKLM\SOFTWARE | Run : [SunJavaUpdateSched] - "C:\Program Files\Common Files\Java\Java Update\jusched.exe"
HKLM\SOFTWARE | Run : [AdobeAAMUpdater-1.0] - "C:\Program Files\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe"
HKLM\SOFTWARE | Run : [AdobeCS5ServiceManager] - "C:\Program Files\Common Files\Adobe\CS5ServiceManager\CS5ServiceManager.exe" -launchedbylogin
HKLM\SOFTWARE | RunOnce : [] -
HKU\S-1-5-21-178000282-2722677192-2624188697-1001\SOFTWARE | Run : [SuperCopier2.exe] - C:\Program Files\SuperCopier2\SuperCopier2.exe
HKU\S-1-5-21-178000282-2722677192-2624188697-1001\SOFTWARE | Run : [MediaDICO38] - C:\Program Files\Micro Application\38 Dictionnaires et Recueils de Correspondance\LanceMediaDICO38.exe Lancement
HKU\S-1-5-21-178000282-2722677192-2624188697-1001\SOFTWARE | Run : [Skype] - "C:\Program Files\Skype\Phone\Skype.exe" /minimized /regrun
HKU\S-1-5-21-178000282-2722677192-2624188697-1001\SOFTWARE | Run : [SkyDrive] - "C:\Users\EKANZA-PC\AppData\Local\Microsoft\SkyDrive\SkyDrive.exe" /background
HKU\S-1-5-21-178000282-2722677192-2624188697-1001\SOFTWARE | Run : [OfficeSyncProcess] - "C:\Program Files\Microsoft Office\Office14\MSOSYNC.EXE"
HKU\S-1-5-21-178000282-2722677192-2624188697-1001\SOFTWARE | Run : [help.vbs] - "C:\Users\EKANZA~1\AppData\Local\Temp\help.vbs"
HKU\S-1-5-21-178000282-2722677192-2624188697-1001\SOFTWARE | Run : [IMG 257654.bmp] - "C:\Users\EKANZA-PC\IMG 257654.bmp.scr"
################## | Files # Infected Folders |
Found ! H:\DISCOURS DE MONSIEUR EDI A L.LNK
Found ! H:\DSCF2159.LNK
Found ! H:\DSCF2166.LNK
Found ! H:\ELECTION REGIONALE.LNK
Found ! H:\ENSEIGNE_ONG_ACTE_1.LNK
Found ! H:\ENSEIGNE_ONG_ACTE_2.LNK
Found ! H:\ENSEIGNE_ONG_ACTES 4m.LNK
Found ! H:\esquiss_en_cours-1 arcom.LNK
Found ! H:\esquiss_suite-1.LNK
Found ! H:\FACTURE PAYEE POUR UNE PARUTION DANS ARCOMCentre de Santé Nimatoullah.LNK
Found ! H:\form_personnel_elections_regionales.LNK
Found ! H:\Index des nom1.LNK
Found ! H:\Index des noms et concepts (Enregistré automatiquement).LNK
Found ! H:\PENDA.LNK
Found ! H:\TRAORE.lnk
Found ! H:\languette.LNK
Found ! H:\LCD N° 661-1.LNK
Found ! H:\Liste de personnes pressenties pour le conseil régionale après enquêtes.LNK
Found ! H:\Liste de quelques militants du Fpi proposée par Salifou Amara.LNK
Found ! H:\LISTE DES REALISATIONS-1.LNK
Found ! H:\LISTE DU MATERIEL DES TRAVAUX PUBLICS.LNK
Found ! H:\LISTE EDI RÉNÉ UNION RETROUVEE POUR LE DEVELOPPEMENT ET LA PROSPERITÉ.LNK
Found ! H:\Liste probable de conseillers ou personnes ressources présentées par Amara.LNK
Found ! H:\LOGO DEUX EDI RENE.LNK
Found ! H:\Messe d'action de grâce de l'Eglise Catholique de Rubino.LNK
Found ! H:\N 3 nv introduction de technique et politique chez herbert marcuse prof bah.LNK
Found ! H:\N 3 nv introduction de technique et politique chez herbert marcuse-1 (thèse definitive) 1.pdf.LNK
Found ! H:\Page de garde Rapport.LNK
Found ! H:\PAGINATION THESE.LNK
Found ! H:\PC_BOOSTER.LNK
Found ! H:\Photo Beach.LNK
Found ! H:\photo Dossa Charlotte Bassam.LNK
Found ! H:\photo kodjo Kouassi Frederic Bassam.LNK
Found ! H:\photo Nina.LNK
Found ! H:\photo Touakesseu Mélanie bassam.LNK
Found ! H:\POINTS DU DISCOURS EDI RENE A GRAND MORIE.LNK
Found ! H:\pre rapport professeur Bah.LNK
Found ! H:\Préinscription universitaire Année scolaire 2012-2013.LNK
Found ! H:\Présentation de la thèse « Technique et politique chez Herbert Marcuse ».LNK
Found ! H:\Présentation sommaire du candidat EDI RENÉ.LNK
Found ! H:\projets réalisés 2001-2012 (version 1).LNK
Found ! H:\Quelques précisions à la suite du pré.LNK
Found ! H:\Rapport final (définitif).LNK
Found ! H:\Regionale Agneby taabo.LNK
Found ! H:\REGROUPEMENT DES VILLAGES PAR LIGNE.LNK
Found ! H:\REMERCIEMENTS thèse.LNK
Found ! H:\REPARTITIONS DE 1000 CALENDRIERS BANCAIRES.LNK
Found ! H:\RESUME DE LA THESE.LNK
Found ! H:\Service communication et animation.LNK
Found ! H:\UsbFix.LNK
Found ! H:\ShortcutVirusRemover.LNK
Found ! H:\Nouveau dossier.lnk
Found ! H:\Signature Amara.LNK
Found ! H:\Slogan Campagne Edi René pour affiches et tee shirt.LNK
Found ! H:\SOUTENANCE DE THESE DE DOCTORAT.LNK
Found ! H:\SPOT EDI RENE 1.LNK
Found ! H:\STRUCTURATION DU DISCOURS DE M. EDI RENE A SIKENSI.LNK
Found ! H:\STRUCTURATION DU DISCOURS DU DRC A SIKENSI.LNK
Found ! H:\Supports et communication conseil régional Agneby.LNK
Found ! H:\Tableau stratégie EDI RENE.LNK
Found ! H:\tarifs comdev.LNK
Found ! H:\Thèse Amara Salifou.LNK
Found ! H:\Thèse Amara Salifou 1.LNK
Found ! H:\T-shirts-1 Casquettes campagne.LNK
Found ! H:\.LNK
Found ! H:\._.LNK
Found ! H:\~WRL0910.LNK
Found ! H:\Agboville.LNK
Found ! H:\Agboville grand morié.LNK
Found ! H:\ARCOM.LNK
Found ! H:\ARCOM journal definitif corrigé.LNK
Found ! H:\ARCOM n°002_Mise en page 1.LNK
Found ! H:\arcom_journal_specimen.LNK
Found ! H:\ARCOM_Mise en page derniere monture.LNK
Found ! H:\ARGUMENTAIRE POUR ARCOM.LNK
Found ! H:\AU COMITE ROYAL DU FESTIVAL CLIMBIE BEACH D'ASSINIE-MAFIA (FECBA).LNK
Found ! H:\Autorun.LNK
Found ! H:\BAH.LNK
Found ! H:\Communication Chefs de terre et Manifestation jeunes Rubino.LNK
Found ! H:\config.LNK
Found ! H:\Copie de Conseil Régional-liste de synthèse provisoire-version ldc1-1.LNK
Found ! H:\Copie de RESUME DE LA THESE.LNK
Found ! H:\courrier à monsieur Kipré Digbeu.LNK
Found ! H:\CREA BOUAKE OK.LNK
Found ! H:\cvisit_amara arcom.LNK
Found ! H:\Dao.LNK
Found ! H:\DEMANDE DE SPONSORING.LNK
Found ! H:\des femmes leaders LMP choisissent Edi René.LNK
Found ! H:\Développement de proximité à Agboville.LNK
Found ! H:\Diby Cléophas Lolo.LNK
Found ! H:\DISCOURS DE M. EDI RENE A L'EGLISE CATHOLIQUE DE RUBINO.LNK
Found ! H:\DISCOURS DE MONSIEUR EDI A KODIMASSO.LNK
Found ! C:\Users\EKANZA-PC\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\IMG 257654.bmp.scr
Found ! C:\Users\EKANZA-PC\IMG 257654.bmp.scr
Found ! H:\IMG 257654.bmp.scr
################## | Registry |
Found ! HKCU\Software\Microsoft\Windows\CurrentVersion\Run|help.vbs
################## | Mountpoints2 |
HKCU\.\.\.\.\Explorer\MountPoints2\{05b12f66-b8ef-11e2-afe1-00247e30c1c0}
Shell\AutoRun\Command = "J:\Setup.exe"
HKCU\.\.\.\.\Explorer\MountPoints2\{16fbe5b7-a542-11e2-afb8-00247e30c1c0}
Shell\AutoRun\Command = "I:\Setup.exe"
HKCU\.\.\.\.\Explorer\MountPoints2\{3b0f15be-955c-11e2-af9c-002481413300}
Shell\AutoRun\Command = "I:\.\Setup.exe" AUTORUN=1
HKCU\.\.\.\.\Explorer\MountPoints2\{954416f2-bbc6-11e2-afe4-404d8e4ad39e}
Shell\AutoRun\Command = "G:\.\Setup.exe" AUTORUN=1
HKCU\.\.\.\.\Explorer\MountPoints2\{95441706-bbc6-11e2-afe4-404d8e4ad39e}
Shell\AutoRun\Command = "G:\.\Setup.exe" AUTORUN=1
HKCU\.\.\.\.\Explorer\MountPoints2\{9544171a-bbc6-11e2-afe4-404d8e4ad39e}
Shell\AutoRun\Command = "G:\.\Setup.exe" AUTORUN=1
HKCU\.\.\.\.\Explorer\MountPoints2\{f5e7e832-95ee-11e2-afa0-002481413300}
Shell\AutoRun\Command = "H:\.\Setup.exe" AUTORUN=1
################## | Vaccin |
(!) This computer is not vaccinated!
################## | E.O.F | https://www.sosvirus.net/ |
A voir également:
- Fichier en raccouris
- Fichier bin - Guide
- Fichier epub - Guide
- Fichier rar - Guide
- Comment réduire la taille d'un fichier - Guide
- Fichier .dat - Guide
3 réponses
voici lee rapport de la suppression:
############################## | UsbFix V 7.133 | [Deletion]
User: EKANZA-PC (Administrator) # EKANZA
Updated 27/08/2013 by El Desaparecido
Started at 12:48:54 | 27/08/2013
Website: https://www.sosvirus.net/
Upload Malware: http://sosvirus.net/viewtopic.php?f=6&t=489
Contact: eldesaparecido@sosvirus.net
PC: Hewlett-Packard (HP Compaq 6735s) (X86-based PC)
CPU: AMD Sempron(tm) SI-42 (2100)
RAM -> [Total : 1789 | Free : 900]
BIOS: Default System BIOS
BOOT: Normal boot
OS: Microsoft Windows 8 Professionnel (6.2.9200 32-Bit) #
WB: Windows Internet Explorer 10.0.9200.16540
SC: Security Center Service [Enabled]
WU: Windows Update Service [(!) Disabled]
AV: Windows Defender [Enabled | Updated]
FW: Windows FireWall Service [Enabled]
C:\ (%systemdrive%) -> Fixed drive # 59 Gb (7 Mb free - 12%) [] # NTFS
D:\ -> Fixed drive # 51 Gb (4 Mb free - 8%) [Disque local ] # NTFS
E:\ -> Fixed drive # 39 Gb (775 Mb free - 2%) [] # NTFS
F:\ -> CD-ROM
G:\ -> CD-ROM
H:\ -> Removable drive # 4 Gb (4 Mb free - 100%) [AMARA II] # FAT32
J:\ -> Removable drive # 4 Gb (2 Mb free - 52%) [] # FAT32
################## | El Desaparecido Section |
HKLM\SOFTWARE | Run : [vProt] - "C:\Program Files\AVG Secure Search\vprot.exe"
HKLM\SOFTWARE | Run : [Adobe ARM] - "C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
HKLM\SOFTWARE | Run : [SynTPEnh] - %ProgramFiles%\Synaptics\SynTP\SynTPEnh.exe
HKLM\SOFTWARE | Run : [QlbCtrl.exe] - C:\Program Files\Hewlett-Packard\HP Quick Launch Buttons\QlbCtrl.exe /Start
HKLM\SOFTWARE | Run : [Nitro PDF Printer Monitor] - "C:\Program Files\Nitro PDF\Professional\NitroPDFPrinterMonitor.exe"
HKLM\SOFTWARE | Run : [SunJavaUpdateSched] - "C:\Program Files\Common Files\Java\Java Update\jusched.exe"
HKLM\SOFTWARE | Run : [AdobeAAMUpdater-1.0] - "C:\Program Files\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe"
HKLM\SOFTWARE | Run : [AdobeCS5ServiceManager] - "C:\Program Files\Common Files\Adobe\CS5ServiceManager\CS5ServiceManager.exe" -launchedbylogin
HKLM\SOFTWARE | RunOnce : [] -
HKU\S-1-5-21-178000282-2722677192-2624188697-1001\SOFTWARE | Run : [SuperCopier2.exe] - C:\Program Files\SuperCopier2\SuperCopier2.exe
HKU\S-1-5-21-178000282-2722677192-2624188697-1001\SOFTWARE | Run : [MediaDICO38] - C:\Program Files\Micro Application\38 Dictionnaires et Recueils de Correspondance\LanceMediaDICO38.exe Lancement
HKU\S-1-5-21-178000282-2722677192-2624188697-1001\SOFTWARE | Run : [Skype] - "C:\Program Files\Skype\Phone\Skype.exe" /minimized /regrun
HKU\S-1-5-21-178000282-2722677192-2624188697-1001\SOFTWARE | Run : [SkyDrive] - "C:\Users\EKANZA-PC\AppData\Local\Microsoft\SkyDrive\SkyDrive.exe" /background
HKU\S-1-5-21-178000282-2722677192-2624188697-1001\SOFTWARE | Run : [OfficeSyncProcess] - "C:\Program Files\Microsoft Office\Office14\MSOSYNC.EXE"
HKU\S-1-5-21-178000282-2722677192-2624188697-1001\SOFTWARE | Run : [IMG 257654.bmp] - "C:\Users\EKANZA-PC\IMG 257654.bmp.scr"
################## | Stopped processes |
Stopped! C:\Program Files\Windows Defender\MsMpEng.exe (392)
Stopped! C:\Windows\System32\WUDFHost.exe (5356)
Stopped! C:\WINDOWS\System32\rundll32.exe (3828)
Stopped! C:\WINDOWS\System32\spoolsv.exe (4236)
Stopped! C:\WINDOWS\system32\SearchIndexer.exe (2488)
Stopped! C:\WINDOWS\system32\dashost.exe (2860)
Stopped! C:\WINDOWS\system32\DllHost.exe (3796)
Stopped! C:\WINDOWS\system32\msiexec.exe (5556)
Stopped! C:\WINDOWS\system32\SearchProtocolHost.exe (3488)
Stopped! C:\WINDOWS\system32\SearchFilterHost.exe (5220)
Stopped! C:\Program Files\Google\Chrome\Application\chrome.exe (5968)
Stopped! C:\Program Files\Google\Chrome\Application\chrome.exe (5656)
Stopped! C:\Program Files\Google\Chrome\Application\chrome.exe (4496)
################## | Files # Infected Folders |
Deleted ! J:\wrar362fr.exe
Deleted ! J:\._.LNK
Deleted ! J:\.LNK
Deleted ! J:\~WRL0910.LNK
Deleted ! J:\Agboville grand morié.LNK
Deleted ! J:\Agboville.LNK
Deleted ! J:\ARCOM journal definitif corrigé.LNK
Deleted ! J:\ARCOM n°002_Mise en page 1.LNK
Deleted ! J:\ARCOM.LNK
Deleted ! J:\arcom_journal_specimen.LNK
Deleted ! J:\ARCOM_Mise en page derniere monture.LNK
Deleted ! J:\ARGUMENTAIRE POUR ARCOM.LNK
Deleted ! J:\AU COMITE ROYAL DU FESTIVAL CLIMBIE BEACH D'ASSINIE-MAFIA (FECBA).LNK
Deleted ! J:\Autorun.LNK
Deleted ! J:\BAH.LNK
Deleted ! J:\Communication Chefs de terre et Manifestation jeunes Rubino.LNK
Deleted ! J:\config.LNK
Deleted ! J:\Copie de Conseil Régional-liste de synthèse provisoire-version ldc1-1.LNK
Deleted ! J:\Copie de RESUME DE LA THESE.LNK
Deleted ! J:\courrier à monsieur Kipré Digbeu.LNK
Deleted ! J:\CREA BOUAKE OK.LNK
Deleted ! J:\cvisit_amara arcom.LNK
Deleted ! J:\Dao.LNK
Deleted ! J:\DEMANDE DE SPONSORING.LNK
Deleted ! J:\des femmes leaders LMP choisissent Edi René.LNK
Deleted ! J:\Développement de proximité à Agboville.LNK
Deleted ! J:\Diby Cléophas Lolo.LNK
Deleted ! J:\DISCOURS DE M. EDI RENE A L'EGLISE CATHOLIQUE DE RUBINO.LNK
Deleted ! J:\DISCOURS DE MONSIEUR EDI A KODIMASSO.LNK
Deleted ! J:\DISCOURS DE MONSIEUR EDI A L.LNK
Deleted ! J:\DSCF2159.LNK
Deleted ! J:\DSCF2166.LNK
Deleted ! J:\ELECTION REGIONALE.LNK
Deleted ! J:\ENSEIGNE_ONG_ACTE_1.LNK
Deleted ! J:\ENSEIGNE_ONG_ACTE_2.LNK
Deleted ! J:\ENSEIGNE_ONG_ACTES 4m.LNK
Deleted ! J:\esquiss_en_cours-1 arcom.LNK
Deleted ! J:\esquiss_suite-1.LNK
Deleted ! J:\FACTURE PAYEE POUR UNE PARUTION DANS ARCOMCentre de Santé Nimatoullah.LNK
Deleted ! J:\form_personnel_elections_regionales.LNK
Deleted ! J:\Index des nom1.LNK
Deleted ! J:\Index des noms et concepts (Enregistré automatiquement).LNK
Deleted ! J:\languette.LNK
Deleted ! J:\LCD N° 661-1.LNK
Deleted ! J:\Liste de personnes pressenties pour le conseil régionale après enquêtes.LNK
Deleted ! J:\Liste de quelques militants du Fpi proposée par Salifou Amara.LNK
Deleted ! J:\LISTE DES REALISATIONS-1.LNK
Deleted ! J:\LISTE DU MATERIEL DES TRAVAUX PUBLICS.LNK
Deleted ! J:\LISTE EDI RÉNÉ UNION RETROUVEE POUR LE DEVELOPPEMENT ET LA PROSPERITÉ.LNK
Deleted ! J:\Liste probable de conseillers ou personnes ressources présentées par Amara.LNK
Deleted ! J:\LOGO DEUX EDI RENE.LNK
Deleted ! J:\Messe d'action de grâce de l'Eglise Catholique de Rubino.LNK
Deleted ! J:\N 3 nv introduction de technique et politique chez herbert marcuse prof bah.LNK
Deleted ! J:\N 3 nv introduction de technique et politique chez herbert marcuse-1 (thèse definitive) 1.pdf.LNK
Deleted ! J:\Nouveau dossier.lnk
Deleted ! J:\Page de garde Rapport.LNK
Deleted ! J:\PAGINATION THESE.LNK
Deleted ! J:\PC_BOOSTER.LNK
Deleted ! J:\PENDA.LNK
Deleted ! J:\Photo Beach.LNK
Deleted ! J:\photo Dossa Charlotte Bassam.LNK
Deleted ! J:\photo kodjo Kouassi Frederic Bassam.LNK
Deleted ! J:\photo Nina.LNK
Deleted ! J:\photo Touakesseu Mélanie bassam.LNK
Deleted ! J:\POINTS DU DISCOURS EDI RENE A GRAND MORIE.LNK
Deleted ! J:\pre rapport professeur Bah.LNK
Deleted ! J:\Préinscription universitaire Année scolaire 2012-2013.LNK
Deleted ! J:\Présentation de la thèse « Technique et politique chez Herbert Marcuse ».LNK
Deleted ! J:\Présentation sommaire du candidat EDI RENÉ.LNK
Deleted ! J:\projets réalisés 2001-2012 (version 1).LNK
Deleted ! J:\Quelques précisions à la suite du pré.LNK
Deleted ! J:\Rapport final (définitif).LNK
Deleted ! J:\Regionale Agneby taabo.LNK
Deleted ! J:\REGROUPEMENT DES VILLAGES PAR LIGNE.LNK
Deleted ! J:\REMERCIEMENTS thèse.LNK
Deleted ! J:\REPARTITIONS DE 1000 CALENDRIERS BANCAIRES.LNK
Deleted ! J:\RESUME DE LA THESE.LNK
Deleted ! J:\Service communication et animation.LNK
Deleted ! J:\Signature Amara.LNK
Deleted ! J:\Slogan Campagne Edi René pour affiches et tee shirt.LNK
Deleted ! J:\SOUTENANCE DE THESE DE DOCTORAT.LNK
Deleted ! J:\SPOT EDI RENE 1.LNK
Deleted ! J:\STRUCTURATION DU DISCOURS DE M. EDI RENE A SIKENSI.LNK
Deleted ! J:\STRUCTURATION DU DISCOURS DU DRC A SIKENSI.LNK
Deleted ! J:\Supports et communication conseil régional Agneby.LNK
Deleted ! J:\Tableau stratégie EDI RENE.LNK
Deleted ! J:\tarifs comdev.LNK
Deleted ! J:\Thèse Amara Salifou 1.LNK
Deleted ! J:\Thèse Amara Salifou.LNK
Deleted ! J:\TRAORE.lnk
Deleted ! J:\T-shirts-1 Casquettes campagne.LNK
(!) Temporary files deleted.
################## | Registry |
################## | Mountpoints2 |
################## | Listing |
[10/04/2013 - 13:09:22 | SHD ] C:\$Recycle.Bin
[10/06/2009 - 21:42:20 | N | 24] C:\autoexec.bat
[27/08/2013 - 12:45:10 | RASHD ] C:\Autorun.inf
[20/02/2013 - 21:26:12 | D ] C:\avast! sandbox
[14/04/2013 - 20:35:27 | D ] C:\Beceem Diagnostic Control Panel 3.5.0
[02/06/2012 - 14:30:55 | N | 1] C:\BOOTNXT
[13/07/2013 - 07:03:16 | D ] C:\Config.Msi
[10/06/2009 - 21:42:20 | N | 10] C:\config.sys
[26/07/2012 - 06:04:44 | SHD ] C:\Documents and Settings
[26/07/2013 - 11:51:55 | D ] C:\Dossier partagé
[09/04/2013 - 18:49:57 | D ] C:\FFOutput
[27/08/2013 - 12:26:54 | ASH | 1500606464] C:\hiberfil.sys
[17/02/2013 - 23:10:34 | RHD ] C:\MSOCache
[27/08/2013 - 12:26:58 | ASH | 1879048192] C:\pagefile.sys
[26/07/2012 - 06:29:57 | D ] C:\PerfLogs
[19/08/2013 - 16:05:29 | D ] C:\Program Files
[18/07/2013 - 16:39:20 | HD ] C:\ProgramData
[25/03/2013 - 14:59:26 | SHD ] C:\Recovery
[09/04/2013 - 18:36:28 | D ] C:\sources
[27/08/2013 - 12:27:02 | ASH | 268435456] C:\swapfile.sys
[26/08/2013 - 12:59:16 | SHD ] C:\System Volume Information
[27/08/2013 - 11:56:33 | N | 22] C:\Upload_UsbFix.zip
[27/08/2013 - 12:50:25 | D ] C:\UsbFix
[27/08/2013 - 12:45:10 | N | 13843] C:\UsbFix [Clean 1] EKANZA.txt
[27/08/2013 - 12:50:49 | A | 9630] C:\UsbFix [Clean 2] EKANZA.txt
[25/03/2013 - 15:06:48 | D ] C:\Users
[22/05/2013 - 11:29:35 | D ] C:\wamp
[23/05/2013 - 10:54:33 | D ] C:\wamp4
[05/06/2013 - 10:07:50 | D ] C:\wamp5
[27/08/2013 - 12:27:04 | D ] C:\Windows
[25/03/2013 - 15:11:41 | SHD ] D:\$RECYCLE.BIN
[27/08/2013 - 12:45:10 | RASHD ] D:\Autorun.inf
[24/07/2011 - 14:26:16 | D ] D:\C-extra musica
[21/08/2013 - 09:32:50 | D ] D:\cv
[18/04/2013 - 23:05:13 | D ] D:\DJ_news
[09/11/2012 - 04:29:48 | D ] D:\ECOLE PREPARATOIRE 2009 2012
[14/07/2013 - 15:56:53 | D ] D:\Enseignement Texte
[11/08/2013 - 20:50:35 | D ] D:\ESI
[04/06/2012 - 01:01:09 | D ] D:\EXCLUSIF RELIGION
[09/08/2013 - 23:25:09 | D ] D:\films
[17/03/2013 - 20:59:59 | D ] D:\Guy Christ Israel 2
[14/11/2011 - 10:54:46 | D ] D:\GUY ISRAEL
[02/09/2011 - 07:56:40 | D ] D:\Guy Roger New
[01/05/2012 - 10:26:55 | D ] D:\Icone(ico)
[14/07/2013 - 16:27:50 | D ] D:\images Réligieuses
[26/06/2013 - 14:32:45 | D ] D:\image_INP
[27/08/2013 - 10:29:10 | D ] D:\logiciels
[11/08/2013 - 20:58:34 | D ] D:\MA CLASSE
[01/03/2012 - 10:42:07 | N | 310] D:\mul.sql
[23/06/2013 - 20:45:41 | D ] D:\Nestor_David
[25/08/2013 - 11:00:56 | D ] D:\New folder
[23/08/2013 - 16:03:46 | D ] D:\Nouveau dossier
[23/09/2012 - 20:01:03 | D ] D:\P.SQUARE-DANGER(2010)
[31/12/2011 - 13:02:06 | N | 15360] D:\photothumb.db
[07/01/2013 - 20:44:12 | D ] D:\PROG C
[29/02/2012 - 22:20:32 | D ] D:\prog vb
[14/07/2013 - 16:08:35 | D ] D:\Projet
[23/06/2013 - 20:54:22 | D ] D:\psquare
[14/07/2013 - 16:20:38 | D ] D:\rire
[14/07/2013 - 15:57:20 | D ] D:\ROSAIRE
[29/06/2013 - 13:09:21 | D ] D:\selection religion
[25/08/2013 - 10:58:39 | D ] D:\selectiondj
[14/07/2013 - 15:57:45 | D ] D:\sons ivoire
[14/08/2012 - 21:29:39 | SHD ] D:\System Volume Information
[14/06/2011 - 15:15:42 | D ] D:\tppascal
[12/07/2013 - 10:13:55 | D ] D:\transporteur
[10/11/2011 - 17:05:29 | D ] D:\wall paper 7
[22/05/2013 - 13:46:22 | D ] D:\www
[20/08/2012 - 17:46:15 | D ] D:\Zouglou
[14/02/2011 - 02:16:25 | N | 162] D:\~$eriode.docx
[25/03/2013 - 15:11:42 | SHD ] E:\$RECYCLE.BIN
[18/12/2011 - 00:11:44 | N | 37394679] E:\351765-debuter-sur-adobe-photoshop_2.pdf
[27/08/2013 - 12:45:10 | RASHD ] E:\Autorun.inf
[14/12/2011 - 08:40:43 | D ] E:\C#
[10/04/2010 - 18:53:56 | N | 16884297] E:\C# et .NET Version 2 - Edition Eyrolles.pdf
[28/01/2012 - 07:02:48 | N | 35406929] E:\C# et .Net - Versions 1 à 4.pdf
[03/01/2013 - 14:12:33 | N | 694522] E:\codeigniter.pdf
[17/01/2011 - 07:07:16 | N | 5775510] E:\contacts_entreprise.pdf
[06/02/2011 - 09:32:36 | D ] E:\Cour Photoshop
[05/06/2012 - 22:44:36 | D ] E:\COURS
[19/02/2012 - 10:09:15 | D ] E:\Cours CS5
[14/12/2011 - 08:40:46 | D ] E:\cours de VB8
[28/07/2012 - 22:48:36 | N | 18353467] E:\cours-c.pdf
[11/05/2005 - 16:44:42 | N | 738883] E:\COURS_matlab.pdf
[14/12/2011 - 08:41:10 | D ] E:\CRACKING
[17/02/2011 - 23:39:40 | N | 99445] E:\CRACKME.alf
[17/02/2011 - 23:39:40 | N | 21168] E:\CRACKME.wpj
[26/06/2011 - 18:48:15 | D ] E:\CrDoc
[05/11/2012 - 23:50:19 | D ] E:\CS6
[19/12/2011 - 01:02:32 | N | 4884331] E:\CurIA_06-12-2012ok.docx
[27/01/2011 - 09:47:58 | N | 128747] E:\DM_Info11.pdf
[06/02/2011 - 09:32:50 | D ] E:\DOCS INFO
[18/06/2011 - 18:22:08 | D ] E:\Dut2010_2011
[24/07/2011 - 16:56:39 | D ] E:\EKANZA
[07/07/2012 - 11:33:04 | D ] E:\Etudiant
[02/03/2011 - 06:28:54 | N | 39492] E:\EXPOSE SUR NTFS.pdf
[04/06/2011 - 19:38:26 | N | 9504254] E:\EXPOSE.docx
[14/12/2011 - 08:41:13 | D ] E:\Gne
[16/05/2013 - 18:00:38 | D ] E:\html
[21/01/2013 - 21:36:26 | D ] E:\informatiques
[16/05/2013 - 18:10:14 | D ] E:\Java
[25/02/2011 - 13:05:16 | D ] E:\LANGAGE
[08/02/2013 - 06:09:27 | D ] E:\lecon 3
[13/06/2010 - 20:14:30 | N | 53720] E:\Les raccourcis basiques.docx
[19/02/2011 - 16:19:34 | N | 579167] E:\Les_commandes_fondamentales_de_Linux.pdf
[07/02/2011 - 21:52:48 | N | 271637] E:\logiciels info3.pdf
[12/03/2012 - 22:59:41 | D ] E:\Maintenance Des Ordinateurs
[16/12/2009 - 11:07:42 | N | 6332622] E:\Mathematiques resumés de cours.pdf
[09/10/2012 - 17:13:34 | D ] E:\Memoire DUT INFO
[21/10/2012 - 11:34:31 | D ] E:\MEMOIRES
[01/03/2012 - 16:07:46 | D ] E:\mes doc
[16/12/2009 - 12:55:46 | N | 5624911] E:\Methodes et exercices de Mathematiques PCSI-PTSI.pdf
[14/12/2011 - 08:41:47 | D ] E:\Nouveau dossier
[06/02/2012 - 22:37:41 | D ] E:\Nouveau dossier (2)
[28/04/2012 - 10:01:11 | D ] E:\Nouveau dossier (3)
[28/04/2012 - 09:36:00 | D ] E:\Nouveau dossier (4)
[08/02/2013 - 06:09:28 | D ] E:\OLLYDBG
[05/11/2012 - 15:43:44 | D ] E:\Philosophie
[18/06/2011 - 18:23:33 | D ] E:\Photoshop
[14/12/2011 - 08:49:24 | D ] E:\PROJET MICRO PRO
[02/11/2012 - 15:38:29 | N | 32448] E:\pronunciation_rules.pdf
[08/11/2012 - 14:26:33 | D ] E:\rapport
[07/11/2012 - 18:08:58 | D ] E:\rapport de stage EKS
[09/11/2012 - 01:14:03 | D ] E:\rapport_corrigé
[26/04/2012 - 15:51:10 | D ] E:\Reseaux
[11/01/2012 - 20:38:06 | D ] E:\serveur de messagerie
[11/02/2011 - 17:13:56 | N | 538] E:\sms32v50.INI
[14/12/2011 - 08:42:48 | D ] E:\SOFT_CRAKING
[26/04/2012 - 19:51:33 | D ] E:\sql server
[05/03/2012 - 10:14:37 | SHD ] E:\System Volume Information
[01/04/2012 - 15:04:12 | D ] E:\Tp-pascal
[14/12/2011 - 08:47:19 | D ] E:\Tp_Devoirs_LINUX
[12/12/2008 - 00:39:24 | N | 4390703] E:\Tutoriel sur les serveurs.pdf
[07/08/2012 - 14:55:20 | D ] E:\TUTO_NEW
[14/12/2011 - 08:47:26 | D ] E:\webmaster
[04/12/2012 - 20:43:17 | D ] E:\www
[30/05/2011 - 22:12:05 | D ] E:\www.siteduzero.com
[22/10/2012 - 11:24:38 | N | 162] E:\~$rIA_06-12-2012ok.docx
[15/01/2012 - 09:45:22 | N | 162] E:\~$s raccourcis basiques.docx
[27/08/2013 - 12:45:12 | RASHD ] H:\Autorun.inf
[27/08/2013 - 10:25:04 | N | 1144645] H:\UsbFix.exe
[27/08/2013 - 10:10:00 | N | 3343] H:\ShortcutVirusRemover.bat
[26/09/2012 - 11:25:34 | D ] J:\Audios
[26/09/2012 - 23:14:00 | D ] J:\Creation
[26/09/2012 - 11:25:38 | D ] J:\Ebook
[19/06/2013 - 23:21:24 | D ] J:\Enseignement Texte
[26/09/2012 - 11:25:36 | D ] J:\Images
[10/05/2013 - 16:53:50 | D ] J:\Nouveau dossier
[20/10/2012 - 21:37:26 | D ] J:\rapport
[23/08/2013 - 10:55:38 | N | 1696843] J:\formulaire.jpg
[23/08/2013 - 10:55:06 | N | 17207766] J:\formulaire.pdf
[13/08/2013 - 19:36:50 | D ] J:\OtoObiz
[19/07/2013 - 11:04:28 | D ] J:\public_html statistique- 30-05-2013
[07/06/2013 - 17:08:44 | D ] J:\public_html-04-08-2013
[10/10/2012 - 12:07:44 | D ] J:\rapport de stage EKS
[26/09/2012 - 11:25:38 | D ] J:\Received
[15/04/2013 - 08:03:36 | D ] J:\Restauration_Projec_last
[13/06/2013 - 10:05:34 | D ] J:\ROSAIRE
[29/06/2013 - 13:09:22 | D ] J:\selection religion
[06/11/2012 - 04:40:30 | D ] J:\tofs
[26/09/2012 - 11:25:36 | D ] J:\Videos
[07/05/2013 - 22:25:32 | N | 38235] J:\cv.rtf
[16/05/2013 - 14:16:52 | N | 311588] J:\CV_EKANZA_SERGE.pdf
[25/04/2013 - 10:30:02 | N | 385263] J:\CV-EKS.pdf
[19/04/2013 - 17:49:38 | N | 106711099] J:\Gloire à l'Agneau Les chantres.wmv
[18/05/2013 - 22:33:28 | N | 15014] J:\lettre de motivation.docx
[15/06/2012 - 15:58:24 | N | 2568952] J:\recuva_recuva_1.42.544_francais_31279.exe
[04/01/1980 - 06:19:16 | N | 401175] J:\Scan0002.jpg
[23/08/2013 - 10:42:22 | N | 617837] J:\2 028.jpg
[23/08/2013 - 10:48:08 | N | 445114] J:\2 029.jpg
[26/06/2013 - 14:30:32 | D ] J:\cv
################## | Vaccin |
C:\Autorun.inf -> Vaccine created by UsbFix (El Desaparecido)
D:\Autorun.inf -> Vaccine created by UsbFix (El Desaparecido)
E:\Autorun.inf -> Vaccine created by UsbFix (El Desaparecido)
H:\Autorun.inf -> Vaccine created by UsbFix (El Desaparecido)
J:\Autorun.inf -> Vaccine created by UsbFix (El Desaparecido)
############################## | UsbFix V 7.133 | [Deletion]
User: EKANZA-PC (Administrator) # EKANZA
Updated 27/08/2013 by El Desaparecido
Started at 12:48:54 | 27/08/2013
Website: https://www.sosvirus.net/
Upload Malware: http://sosvirus.net/viewtopic.php?f=6&t=489
Contact: eldesaparecido@sosvirus.net
PC: Hewlett-Packard (HP Compaq 6735s) (X86-based PC)
CPU: AMD Sempron(tm) SI-42 (2100)
RAM -> [Total : 1789 | Free : 900]
BIOS: Default System BIOS
BOOT: Normal boot
OS: Microsoft Windows 8 Professionnel (6.2.9200 32-Bit) #
WB: Windows Internet Explorer 10.0.9200.16540
SC: Security Center Service [Enabled]
WU: Windows Update Service [(!) Disabled]
AV: Windows Defender [Enabled | Updated]
FW: Windows FireWall Service [Enabled]
C:\ (%systemdrive%) -> Fixed drive # 59 Gb (7 Mb free - 12%) [] # NTFS
D:\ -> Fixed drive # 51 Gb (4 Mb free - 8%) [Disque local ] # NTFS
E:\ -> Fixed drive # 39 Gb (775 Mb free - 2%) [] # NTFS
F:\ -> CD-ROM
G:\ -> CD-ROM
H:\ -> Removable drive # 4 Gb (4 Mb free - 100%) [AMARA II] # FAT32
J:\ -> Removable drive # 4 Gb (2 Mb free - 52%) [] # FAT32
################## | El Desaparecido Section |
HKLM\SOFTWARE | Run : [vProt] - "C:\Program Files\AVG Secure Search\vprot.exe"
HKLM\SOFTWARE | Run : [Adobe ARM] - "C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
HKLM\SOFTWARE | Run : [SynTPEnh] - %ProgramFiles%\Synaptics\SynTP\SynTPEnh.exe
HKLM\SOFTWARE | Run : [QlbCtrl.exe] - C:\Program Files\Hewlett-Packard\HP Quick Launch Buttons\QlbCtrl.exe /Start
HKLM\SOFTWARE | Run : [Nitro PDF Printer Monitor] - "C:\Program Files\Nitro PDF\Professional\NitroPDFPrinterMonitor.exe"
HKLM\SOFTWARE | Run : [SunJavaUpdateSched] - "C:\Program Files\Common Files\Java\Java Update\jusched.exe"
HKLM\SOFTWARE | Run : [AdobeAAMUpdater-1.0] - "C:\Program Files\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe"
HKLM\SOFTWARE | Run : [AdobeCS5ServiceManager] - "C:\Program Files\Common Files\Adobe\CS5ServiceManager\CS5ServiceManager.exe" -launchedbylogin
HKLM\SOFTWARE | RunOnce : [] -
HKU\S-1-5-21-178000282-2722677192-2624188697-1001\SOFTWARE | Run : [SuperCopier2.exe] - C:\Program Files\SuperCopier2\SuperCopier2.exe
HKU\S-1-5-21-178000282-2722677192-2624188697-1001\SOFTWARE | Run : [MediaDICO38] - C:\Program Files\Micro Application\38 Dictionnaires et Recueils de Correspondance\LanceMediaDICO38.exe Lancement
HKU\S-1-5-21-178000282-2722677192-2624188697-1001\SOFTWARE | Run : [Skype] - "C:\Program Files\Skype\Phone\Skype.exe" /minimized /regrun
HKU\S-1-5-21-178000282-2722677192-2624188697-1001\SOFTWARE | Run : [SkyDrive] - "C:\Users\EKANZA-PC\AppData\Local\Microsoft\SkyDrive\SkyDrive.exe" /background
HKU\S-1-5-21-178000282-2722677192-2624188697-1001\SOFTWARE | Run : [OfficeSyncProcess] - "C:\Program Files\Microsoft Office\Office14\MSOSYNC.EXE"
HKU\S-1-5-21-178000282-2722677192-2624188697-1001\SOFTWARE | Run : [IMG 257654.bmp] - "C:\Users\EKANZA-PC\IMG 257654.bmp.scr"
################## | Stopped processes |
Stopped! C:\Program Files\Windows Defender\MsMpEng.exe (392)
Stopped! C:\Windows\System32\WUDFHost.exe (5356)
Stopped! C:\WINDOWS\System32\rundll32.exe (3828)
Stopped! C:\WINDOWS\System32\spoolsv.exe (4236)
Stopped! C:\WINDOWS\system32\SearchIndexer.exe (2488)
Stopped! C:\WINDOWS\system32\dashost.exe (2860)
Stopped! C:\WINDOWS\system32\DllHost.exe (3796)
Stopped! C:\WINDOWS\system32\msiexec.exe (5556)
Stopped! C:\WINDOWS\system32\SearchProtocolHost.exe (3488)
Stopped! C:\WINDOWS\system32\SearchFilterHost.exe (5220)
Stopped! C:\Program Files\Google\Chrome\Application\chrome.exe (5968)
Stopped! C:\Program Files\Google\Chrome\Application\chrome.exe (5656)
Stopped! C:\Program Files\Google\Chrome\Application\chrome.exe (4496)
################## | Files # Infected Folders |
Deleted ! J:\wrar362fr.exe
Deleted ! J:\._.LNK
Deleted ! J:\.LNK
Deleted ! J:\~WRL0910.LNK
Deleted ! J:\Agboville grand morié.LNK
Deleted ! J:\Agboville.LNK
Deleted ! J:\ARCOM journal definitif corrigé.LNK
Deleted ! J:\ARCOM n°002_Mise en page 1.LNK
Deleted ! J:\ARCOM.LNK
Deleted ! J:\arcom_journal_specimen.LNK
Deleted ! J:\ARCOM_Mise en page derniere monture.LNK
Deleted ! J:\ARGUMENTAIRE POUR ARCOM.LNK
Deleted ! J:\AU COMITE ROYAL DU FESTIVAL CLIMBIE BEACH D'ASSINIE-MAFIA (FECBA).LNK
Deleted ! J:\Autorun.LNK
Deleted ! J:\BAH.LNK
Deleted ! J:\Communication Chefs de terre et Manifestation jeunes Rubino.LNK
Deleted ! J:\config.LNK
Deleted ! J:\Copie de Conseil Régional-liste de synthèse provisoire-version ldc1-1.LNK
Deleted ! J:\Copie de RESUME DE LA THESE.LNK
Deleted ! J:\courrier à monsieur Kipré Digbeu.LNK
Deleted ! J:\CREA BOUAKE OK.LNK
Deleted ! J:\cvisit_amara arcom.LNK
Deleted ! J:\Dao.LNK
Deleted ! J:\DEMANDE DE SPONSORING.LNK
Deleted ! J:\des femmes leaders LMP choisissent Edi René.LNK
Deleted ! J:\Développement de proximité à Agboville.LNK
Deleted ! J:\Diby Cléophas Lolo.LNK
Deleted ! J:\DISCOURS DE M. EDI RENE A L'EGLISE CATHOLIQUE DE RUBINO.LNK
Deleted ! J:\DISCOURS DE MONSIEUR EDI A KODIMASSO.LNK
Deleted ! J:\DISCOURS DE MONSIEUR EDI A L.LNK
Deleted ! J:\DSCF2159.LNK
Deleted ! J:\DSCF2166.LNK
Deleted ! J:\ELECTION REGIONALE.LNK
Deleted ! J:\ENSEIGNE_ONG_ACTE_1.LNK
Deleted ! J:\ENSEIGNE_ONG_ACTE_2.LNK
Deleted ! J:\ENSEIGNE_ONG_ACTES 4m.LNK
Deleted ! J:\esquiss_en_cours-1 arcom.LNK
Deleted ! J:\esquiss_suite-1.LNK
Deleted ! J:\FACTURE PAYEE POUR UNE PARUTION DANS ARCOMCentre de Santé Nimatoullah.LNK
Deleted ! J:\form_personnel_elections_regionales.LNK
Deleted ! J:\Index des nom1.LNK
Deleted ! J:\Index des noms et concepts (Enregistré automatiquement).LNK
Deleted ! J:\languette.LNK
Deleted ! J:\LCD N° 661-1.LNK
Deleted ! J:\Liste de personnes pressenties pour le conseil régionale après enquêtes.LNK
Deleted ! J:\Liste de quelques militants du Fpi proposée par Salifou Amara.LNK
Deleted ! J:\LISTE DES REALISATIONS-1.LNK
Deleted ! J:\LISTE DU MATERIEL DES TRAVAUX PUBLICS.LNK
Deleted ! J:\LISTE EDI RÉNÉ UNION RETROUVEE POUR LE DEVELOPPEMENT ET LA PROSPERITÉ.LNK
Deleted ! J:\Liste probable de conseillers ou personnes ressources présentées par Amara.LNK
Deleted ! J:\LOGO DEUX EDI RENE.LNK
Deleted ! J:\Messe d'action de grâce de l'Eglise Catholique de Rubino.LNK
Deleted ! J:\N 3 nv introduction de technique et politique chez herbert marcuse prof bah.LNK
Deleted ! J:\N 3 nv introduction de technique et politique chez herbert marcuse-1 (thèse definitive) 1.pdf.LNK
Deleted ! J:\Nouveau dossier.lnk
Deleted ! J:\Page de garde Rapport.LNK
Deleted ! J:\PAGINATION THESE.LNK
Deleted ! J:\PC_BOOSTER.LNK
Deleted ! J:\PENDA.LNK
Deleted ! J:\Photo Beach.LNK
Deleted ! J:\photo Dossa Charlotte Bassam.LNK
Deleted ! J:\photo kodjo Kouassi Frederic Bassam.LNK
Deleted ! J:\photo Nina.LNK
Deleted ! J:\photo Touakesseu Mélanie bassam.LNK
Deleted ! J:\POINTS DU DISCOURS EDI RENE A GRAND MORIE.LNK
Deleted ! J:\pre rapport professeur Bah.LNK
Deleted ! J:\Préinscription universitaire Année scolaire 2012-2013.LNK
Deleted ! J:\Présentation de la thèse « Technique et politique chez Herbert Marcuse ».LNK
Deleted ! J:\Présentation sommaire du candidat EDI RENÉ.LNK
Deleted ! J:\projets réalisés 2001-2012 (version 1).LNK
Deleted ! J:\Quelques précisions à la suite du pré.LNK
Deleted ! J:\Rapport final (définitif).LNK
Deleted ! J:\Regionale Agneby taabo.LNK
Deleted ! J:\REGROUPEMENT DES VILLAGES PAR LIGNE.LNK
Deleted ! J:\REMERCIEMENTS thèse.LNK
Deleted ! J:\REPARTITIONS DE 1000 CALENDRIERS BANCAIRES.LNK
Deleted ! J:\RESUME DE LA THESE.LNK
Deleted ! J:\Service communication et animation.LNK
Deleted ! J:\Signature Amara.LNK
Deleted ! J:\Slogan Campagne Edi René pour affiches et tee shirt.LNK
Deleted ! J:\SOUTENANCE DE THESE DE DOCTORAT.LNK
Deleted ! J:\SPOT EDI RENE 1.LNK
Deleted ! J:\STRUCTURATION DU DISCOURS DE M. EDI RENE A SIKENSI.LNK
Deleted ! J:\STRUCTURATION DU DISCOURS DU DRC A SIKENSI.LNK
Deleted ! J:\Supports et communication conseil régional Agneby.LNK
Deleted ! J:\Tableau stratégie EDI RENE.LNK
Deleted ! J:\tarifs comdev.LNK
Deleted ! J:\Thèse Amara Salifou 1.LNK
Deleted ! J:\Thèse Amara Salifou.LNK
Deleted ! J:\TRAORE.lnk
Deleted ! J:\T-shirts-1 Casquettes campagne.LNK
(!) Temporary files deleted.
################## | Registry |
################## | Mountpoints2 |
################## | Listing |
[10/04/2013 - 13:09:22 | SHD ] C:\$Recycle.Bin
[10/06/2009 - 21:42:20 | N | 24] C:\autoexec.bat
[27/08/2013 - 12:45:10 | RASHD ] C:\Autorun.inf
[20/02/2013 - 21:26:12 | D ] C:\avast! sandbox
[14/04/2013 - 20:35:27 | D ] C:\Beceem Diagnostic Control Panel 3.5.0
[02/06/2012 - 14:30:55 | N | 1] C:\BOOTNXT
[13/07/2013 - 07:03:16 | D ] C:\Config.Msi
[10/06/2009 - 21:42:20 | N | 10] C:\config.sys
[26/07/2012 - 06:04:44 | SHD ] C:\Documents and Settings
[26/07/2013 - 11:51:55 | D ] C:\Dossier partagé
[09/04/2013 - 18:49:57 | D ] C:\FFOutput
[27/08/2013 - 12:26:54 | ASH | 1500606464] C:\hiberfil.sys
[17/02/2013 - 23:10:34 | RHD ] C:\MSOCache
[27/08/2013 - 12:26:58 | ASH | 1879048192] C:\pagefile.sys
[26/07/2012 - 06:29:57 | D ] C:\PerfLogs
[19/08/2013 - 16:05:29 | D ] C:\Program Files
[18/07/2013 - 16:39:20 | HD ] C:\ProgramData
[25/03/2013 - 14:59:26 | SHD ] C:\Recovery
[09/04/2013 - 18:36:28 | D ] C:\sources
[27/08/2013 - 12:27:02 | ASH | 268435456] C:\swapfile.sys
[26/08/2013 - 12:59:16 | SHD ] C:\System Volume Information
[27/08/2013 - 11:56:33 | N | 22] C:\Upload_UsbFix.zip
[27/08/2013 - 12:50:25 | D ] C:\UsbFix
[27/08/2013 - 12:45:10 | N | 13843] C:\UsbFix [Clean 1] EKANZA.txt
[27/08/2013 - 12:50:49 | A | 9630] C:\UsbFix [Clean 2] EKANZA.txt
[25/03/2013 - 15:06:48 | D ] C:\Users
[22/05/2013 - 11:29:35 | D ] C:\wamp
[23/05/2013 - 10:54:33 | D ] C:\wamp4
[05/06/2013 - 10:07:50 | D ] C:\wamp5
[27/08/2013 - 12:27:04 | D ] C:\Windows
[25/03/2013 - 15:11:41 | SHD ] D:\$RECYCLE.BIN
[27/08/2013 - 12:45:10 | RASHD ] D:\Autorun.inf
[24/07/2011 - 14:26:16 | D ] D:\C-extra musica
[21/08/2013 - 09:32:50 | D ] D:\cv
[18/04/2013 - 23:05:13 | D ] D:\DJ_news
[09/11/2012 - 04:29:48 | D ] D:\ECOLE PREPARATOIRE 2009 2012
[14/07/2013 - 15:56:53 | D ] D:\Enseignement Texte
[11/08/2013 - 20:50:35 | D ] D:\ESI
[04/06/2012 - 01:01:09 | D ] D:\EXCLUSIF RELIGION
[09/08/2013 - 23:25:09 | D ] D:\films
[17/03/2013 - 20:59:59 | D ] D:\Guy Christ Israel 2
[14/11/2011 - 10:54:46 | D ] D:\GUY ISRAEL
[02/09/2011 - 07:56:40 | D ] D:\Guy Roger New
[01/05/2012 - 10:26:55 | D ] D:\Icone(ico)
[14/07/2013 - 16:27:50 | D ] D:\images Réligieuses
[26/06/2013 - 14:32:45 | D ] D:\image_INP
[27/08/2013 - 10:29:10 | D ] D:\logiciels
[11/08/2013 - 20:58:34 | D ] D:\MA CLASSE
[01/03/2012 - 10:42:07 | N | 310] D:\mul.sql
[23/06/2013 - 20:45:41 | D ] D:\Nestor_David
[25/08/2013 - 11:00:56 | D ] D:\New folder
[23/08/2013 - 16:03:46 | D ] D:\Nouveau dossier
[23/09/2012 - 20:01:03 | D ] D:\P.SQUARE-DANGER(2010)
[31/12/2011 - 13:02:06 | N | 15360] D:\photothumb.db
[07/01/2013 - 20:44:12 | D ] D:\PROG C
[29/02/2012 - 22:20:32 | D ] D:\prog vb
[14/07/2013 - 16:08:35 | D ] D:\Projet
[23/06/2013 - 20:54:22 | D ] D:\psquare
[14/07/2013 - 16:20:38 | D ] D:\rire
[14/07/2013 - 15:57:20 | D ] D:\ROSAIRE
[29/06/2013 - 13:09:21 | D ] D:\selection religion
[25/08/2013 - 10:58:39 | D ] D:\selectiondj
[14/07/2013 - 15:57:45 | D ] D:\sons ivoire
[14/08/2012 - 21:29:39 | SHD ] D:\System Volume Information
[14/06/2011 - 15:15:42 | D ] D:\tppascal
[12/07/2013 - 10:13:55 | D ] D:\transporteur
[10/11/2011 - 17:05:29 | D ] D:\wall paper 7
[22/05/2013 - 13:46:22 | D ] D:\www
[20/08/2012 - 17:46:15 | D ] D:\Zouglou
[14/02/2011 - 02:16:25 | N | 162] D:\~$eriode.docx
[25/03/2013 - 15:11:42 | SHD ] E:\$RECYCLE.BIN
[18/12/2011 - 00:11:44 | N | 37394679] E:\351765-debuter-sur-adobe-photoshop_2.pdf
[27/08/2013 - 12:45:10 | RASHD ] E:\Autorun.inf
[14/12/2011 - 08:40:43 | D ] E:\C#
[10/04/2010 - 18:53:56 | N | 16884297] E:\C# et .NET Version 2 - Edition Eyrolles.pdf
[28/01/2012 - 07:02:48 | N | 35406929] E:\C# et .Net - Versions 1 à 4.pdf
[03/01/2013 - 14:12:33 | N | 694522] E:\codeigniter.pdf
[17/01/2011 - 07:07:16 | N | 5775510] E:\contacts_entreprise.pdf
[06/02/2011 - 09:32:36 | D ] E:\Cour Photoshop
[05/06/2012 - 22:44:36 | D ] E:\COURS
[19/02/2012 - 10:09:15 | D ] E:\Cours CS5
[14/12/2011 - 08:40:46 | D ] E:\cours de VB8
[28/07/2012 - 22:48:36 | N | 18353467] E:\cours-c.pdf
[11/05/2005 - 16:44:42 | N | 738883] E:\COURS_matlab.pdf
[14/12/2011 - 08:41:10 | D ] E:\CRACKING
[17/02/2011 - 23:39:40 | N | 99445] E:\CRACKME.alf
[17/02/2011 - 23:39:40 | N | 21168] E:\CRACKME.wpj
[26/06/2011 - 18:48:15 | D ] E:\CrDoc
[05/11/2012 - 23:50:19 | D ] E:\CS6
[19/12/2011 - 01:02:32 | N | 4884331] E:\CurIA_06-12-2012ok.docx
[27/01/2011 - 09:47:58 | N | 128747] E:\DM_Info11.pdf
[06/02/2011 - 09:32:50 | D ] E:\DOCS INFO
[18/06/2011 - 18:22:08 | D ] E:\Dut2010_2011
[24/07/2011 - 16:56:39 | D ] E:\EKANZA
[07/07/2012 - 11:33:04 | D ] E:\Etudiant
[02/03/2011 - 06:28:54 | N | 39492] E:\EXPOSE SUR NTFS.pdf
[04/06/2011 - 19:38:26 | N | 9504254] E:\EXPOSE.docx
[14/12/2011 - 08:41:13 | D ] E:\Gne
[16/05/2013 - 18:00:38 | D ] E:\html
[21/01/2013 - 21:36:26 | D ] E:\informatiques
[16/05/2013 - 18:10:14 | D ] E:\Java
[25/02/2011 - 13:05:16 | D ] E:\LANGAGE
[08/02/2013 - 06:09:27 | D ] E:\lecon 3
[13/06/2010 - 20:14:30 | N | 53720] E:\Les raccourcis basiques.docx
[19/02/2011 - 16:19:34 | N | 579167] E:\Les_commandes_fondamentales_de_Linux.pdf
[07/02/2011 - 21:52:48 | N | 271637] E:\logiciels info3.pdf
[12/03/2012 - 22:59:41 | D ] E:\Maintenance Des Ordinateurs
[16/12/2009 - 11:07:42 | N | 6332622] E:\Mathematiques resumés de cours.pdf
[09/10/2012 - 17:13:34 | D ] E:\Memoire DUT INFO
[21/10/2012 - 11:34:31 | D ] E:\MEMOIRES
[01/03/2012 - 16:07:46 | D ] E:\mes doc
[16/12/2009 - 12:55:46 | N | 5624911] E:\Methodes et exercices de Mathematiques PCSI-PTSI.pdf
[14/12/2011 - 08:41:47 | D ] E:\Nouveau dossier
[06/02/2012 - 22:37:41 | D ] E:\Nouveau dossier (2)
[28/04/2012 - 10:01:11 | D ] E:\Nouveau dossier (3)
[28/04/2012 - 09:36:00 | D ] E:\Nouveau dossier (4)
[08/02/2013 - 06:09:28 | D ] E:\OLLYDBG
[05/11/2012 - 15:43:44 | D ] E:\Philosophie
[18/06/2011 - 18:23:33 | D ] E:\Photoshop
[14/12/2011 - 08:49:24 | D ] E:\PROJET MICRO PRO
[02/11/2012 - 15:38:29 | N | 32448] E:\pronunciation_rules.pdf
[08/11/2012 - 14:26:33 | D ] E:\rapport
[07/11/2012 - 18:08:58 | D ] E:\rapport de stage EKS
[09/11/2012 - 01:14:03 | D ] E:\rapport_corrigé
[26/04/2012 - 15:51:10 | D ] E:\Reseaux
[11/01/2012 - 20:38:06 | D ] E:\serveur de messagerie
[11/02/2011 - 17:13:56 | N | 538] E:\sms32v50.INI
[14/12/2011 - 08:42:48 | D ] E:\SOFT_CRAKING
[26/04/2012 - 19:51:33 | D ] E:\sql server
[05/03/2012 - 10:14:37 | SHD ] E:\System Volume Information
[01/04/2012 - 15:04:12 | D ] E:\Tp-pascal
[14/12/2011 - 08:47:19 | D ] E:\Tp_Devoirs_LINUX
[12/12/2008 - 00:39:24 | N | 4390703] E:\Tutoriel sur les serveurs.pdf
[07/08/2012 - 14:55:20 | D ] E:\TUTO_NEW
[14/12/2011 - 08:47:26 | D ] E:\webmaster
[04/12/2012 - 20:43:17 | D ] E:\www
[30/05/2011 - 22:12:05 | D ] E:\www.siteduzero.com
[22/10/2012 - 11:24:38 | N | 162] E:\~$rIA_06-12-2012ok.docx
[15/01/2012 - 09:45:22 | N | 162] E:\~$s raccourcis basiques.docx
[27/08/2013 - 12:45:12 | RASHD ] H:\Autorun.inf
[27/08/2013 - 10:25:04 | N | 1144645] H:\UsbFix.exe
[27/08/2013 - 10:10:00 | N | 3343] H:\ShortcutVirusRemover.bat
[26/09/2012 - 11:25:34 | D ] J:\Audios
[26/09/2012 - 23:14:00 | D ] J:\Creation
[26/09/2012 - 11:25:38 | D ] J:\Ebook
[19/06/2013 - 23:21:24 | D ] J:\Enseignement Texte
[26/09/2012 - 11:25:36 | D ] J:\Images
[10/05/2013 - 16:53:50 | D ] J:\Nouveau dossier
[20/10/2012 - 21:37:26 | D ] J:\rapport
[23/08/2013 - 10:55:38 | N | 1696843] J:\formulaire.jpg
[23/08/2013 - 10:55:06 | N | 17207766] J:\formulaire.pdf
[13/08/2013 - 19:36:50 | D ] J:\OtoObiz
[19/07/2013 - 11:04:28 | D ] J:\public_html statistique- 30-05-2013
[07/06/2013 - 17:08:44 | D ] J:\public_html-04-08-2013
[10/10/2012 - 12:07:44 | D ] J:\rapport de stage EKS
[26/09/2012 - 11:25:38 | D ] J:\Received
[15/04/2013 - 08:03:36 | D ] J:\Restauration_Projec_last
[13/06/2013 - 10:05:34 | D ] J:\ROSAIRE
[29/06/2013 - 13:09:22 | D ] J:\selection religion
[06/11/2012 - 04:40:30 | D ] J:\tofs
[26/09/2012 - 11:25:36 | D ] J:\Videos
[07/05/2013 - 22:25:32 | N | 38235] J:\cv.rtf
[16/05/2013 - 14:16:52 | N | 311588] J:\CV_EKANZA_SERGE.pdf
[25/04/2013 - 10:30:02 | N | 385263] J:\CV-EKS.pdf
[19/04/2013 - 17:49:38 | N | 106711099] J:\Gloire à l'Agneau Les chantres.wmv
[18/05/2013 - 22:33:28 | N | 15014] J:\lettre de motivation.docx
[15/06/2012 - 15:58:24 | N | 2568952] J:\recuva_recuva_1.42.544_francais_31279.exe
[04/01/1980 - 06:19:16 | N | 401175] J:\Scan0002.jpg
[23/08/2013 - 10:42:22 | N | 617837] J:\2 028.jpg
[23/08/2013 - 10:48:08 | N | 445114] J:\2 029.jpg
[26/06/2013 - 14:30:32 | D ] J:\cv
################## | Vaccin |
C:\Autorun.inf -> Vaccine created by UsbFix (El Desaparecido)
D:\Autorun.inf -> Vaccine created by UsbFix (El Desaparecido)
E:\Autorun.inf -> Vaccine created by UsbFix (El Desaparecido)
H:\Autorun.inf -> Vaccine created by UsbFix (El Desaparecido)
J:\Autorun.inf -> Vaccine created by UsbFix (El Desaparecido)
Re,
Des améliorations ?
Fais un diagnostic de ton PC avec ZHPDiag comme ceci et poste moi le rapport précédemment hébergé sur cjoint : http://www.forum-entraide-informatique.com/support/zhpdiag-tutoriel-t4831.html
Gabriel.
Des améliorations ?
Fais un diagnostic de ton PC avec ZHPDiag comme ceci et poste moi le rapport précédemment hébergé sur cjoint : http://www.forum-entraide-informatique.com/support/zhpdiag-tutoriel-t4831.html
Gabriel.