############################## | UsbFix 7.038 | [Suppression]
Utilisateur: CELINE (Administrateur) # PC-DE-CELINE [TOSHIBA Satellite Pro L300]
Mis à jour le 14/01/2011 par El Desaparecido / C_XX
Lancé à 19:41:07 | 19/01/2011
Site Web:
http://www.teamxscript.org
Contact:
eldesaparecido@teamxscript.org
CPU: Intel(R) Pentium(R) Dual CPU T3200 @ 2.00GHz
CPU 2: Intel(R) Pentium(R) Dual CPU T3200 @ 2.00GHz
Microsoft® Windows Vista™ Édition Familiale Premium (6.0.6002 32-Bit) # Service Pack 2
Internet Explorer 8.0.6001.18999
Pare-feu Windows: Activé
RAM -> 1915 Mo
C:\ (%systemdrive%) -> Disque fixe # 56 Go (9 Go libre(s) - 15%) [Vista] # NTFS
D:\ -> CD-ROM
E:\ -> Disque fixe # 55 Go (21 Go libre(s) - 38%) [Data] # NTFS
F:\ -> CD-ROM
G:\ -> Disque amovible # 7 Go (2 Go libre(s) - 23%) [Cruzer] # FAT32
################## | Éléments infectieux |
Supprimé! C:\Windows\system32\arking.exe
Supprimé! C:\Windows\system32\arking0.dll
Supprimé! C:\Windows\system32\arking1.dll
Supprimé! C:\Windows\system32\mgking0.dll
Supprimé! C:\Windows\pagefile.sys.vbs
Supprimé! C:\$RECYCLE.BIN\S-1-5-21-2332586857-578166098-4569380-1044
Supprimé! E:\$RECYCLE.BIN\S-1-5-21-184214427-284726437-1303234803-1000
Supprimé! E:\$RECYCLE.BIN\S-1-5-21-2332586857-578166098-4569380-1037
Supprimé! E:\$RECYCLE.BIN\S-1-5-21-2332586857-578166098-4569380-1038
Supprimé! E:\$RECYCLE.BIN\S-1-5-21-2332586857-578166098-4569380-1039
Supprimé! E:\$RECYCLE.BIN\S-1-5-21-2332586857-578166098-4569380-1040
Supprimé! E:\$RECYCLE.BIN\S-1-5-21-2332586857-578166098-4569380-1041
Supprimé! E:\$RECYCLE.BIN\S-1-5-21-2332586857-578166098-4569380-1042
Supprimé! E:\$RECYCLE.BIN\S-1-5-21-2332586857-578166098-4569380-1044
Supprimé! E:\$RECYCLE.BIN\S-1-5-21-2332586857-578166098-4569380-500
Supprimé! E:\$RECYCLE.BIN\S-1-5-21-836581112-2635297850-3627004266-1000
Supprimé! E:\$RECYCLE.BIN\S-1-5-21-836581112-2635297850-3627004266-1001
Supprimé! E:\$RECYCLE.BIN\S-1-5-21-836581112-2635297850-3627004266-1002
Supprimé! E:\$RECYCLE.BIN\S-1-5-21-836581112-2635297850-3627004266-1003
Supprimé! E:\$RECYCLE.BIN\S-1-5-21-836581112-2635297850-3627004266-1004
Supprimé! E:\$RECYCLE.BIN\S-1-5-21-836581112-2635297850-3627004266-1005
Supprimé! E:\$RECYCLE.BIN\S-1-5-21-836581112-2635297850-3627004266-1006
Supprimé! E:\$RECYCLE.BIN\S-1-5-21-836581112-2635297850-3627004266-1007
Supprimé! E:\$RECYCLE.BIN\S-1-5-21-836581112-2635297850-3627004266-1008
Supprimé! E:\$RECYCLE.BIN\S-1-5-21-836581112-2635297850-3627004266-1009
Supprimé! E:\$RECYCLE.BIN\S-1-5-21-836581112-2635297850-3627004266-1010
Supprimé! E:\$RECYCLE.BIN\S-1-5-21-836581112-2635297850-3627004266-1011
Supprimé! E:\$RECYCLE.BIN\S-1-5-21-836581112-2635297850-3627004266-1012
Supprimé! E:\$RECYCLE.BIN\S-1-5-21-836581112-2635297850-3627004266-1013
Supprimé! E:\$RECYCLE.BIN\S-1-5-21-836581112-2635297850-3627004266-1014
Supprimé! E:\$RECYCLE.BIN\S-1-5-21-836581112-2635297850-3627004266-1015
Supprimé! E:\$RECYCLE.BIN\S-1-5-21-836581112-2635297850-3627004266-1016
Supprimé! E:\$RECYCLE.BIN\S-1-5-21-836581112-2635297850-3627004266-1017
Supprimé! E:\$RECYCLE.BIN\S-1-5-21-836581112-2635297850-3627004266-1018
Supprimé! E:\$RECYCLE.BIN\S-1-5-21-836581112-2635297850-3627004266-1019
Supprimé! E:\$RECYCLE.BIN\S-1-5-21-836581112-2635297850-3627004266-1020
Supprimé! E:\$RECYCLE.BIN\S-1-5-21-836581112-2635297850-3627004266-1021
Supprimé! E:\$RECYCLE.BIN\S-1-5-21-836581112-2635297850-3627004266-1022
Supprimé! E:\$RECYCLE.BIN\S-1-5-21-836581112-2635297850-3627004266-1023
Supprimé! E:\$RECYCLE.BIN\S-1-5-21-836581112-2635297850-3627004266-1024
Supprimé! E:\$RECYCLE.BIN\S-1-5-21-836581112-2635297850-3627004266-1025
Supprimé! E:\$RECYCLE.BIN\S-1-5-21-836581112-2635297850-3627004266-1026
Supprimé! E:\$RECYCLE.BIN\S-1-5-21-836581112-2635297850-3627004266-1027
Supprimé! E:\$RECYCLE.BIN\S-1-5-21-836581112-2635297850-3627004266-1028
Supprimé! E:\$RECYCLE.BIN\S-1-5-21-836581112-2635297850-3627004266-1029
Supprimé! E:\$RECYCLE.BIN\S-1-5-21-836581112-2635297850-3627004266-1030
Supprimé! E:\$RECYCLE.BIN\S-1-5-21-836581112-2635297850-3627004266-1031
Supprimé! E:\$RECYCLE.BIN\S-1-5-21-836581112-2635297850-3627004266-1032
Supprimé! E:\$RECYCLE.BIN\S-1-5-21-836581112-2635297850-3627004266-1033
Supprimé! E:\$RECYCLE.BIN\S-1-5-21-836581112-2635297850-3627004266-1034
Supprimé! E:\$RECYCLE.BIN\S-1-5-21-836581112-2635297850-3627004266-1035
Supprimé! E:\$RECYCLE.BIN\S-1-5-21-836581112-2635297850-3627004266-1036
Supprimé! E:\$RECYCLE.BIN\S-1-5-21-836581112-2635297850-3627004266-500
Supprimé! C:\affi8l.exe
Supprimé! C:\autorun.inf
Supprimé! C:\pagefile.sys.vbs
Supprimé! C:\ysyjq1bs.exe
Supprimé! E:\affi8l.exe
Supprimé! E:\autorun.inf
Supprimé! E:\pagefile.sys.vbs
Supprimé! E:\ysyjq1bs.exe
Non supprimé ! F:\autorun.inf
Supprimé! G:\a.exe
Supprimé! G:\autorun.inf
Supprimé! G:\pagefile.sys.vbs
################## | Registre |
Supprimé! HKLM\Software\Classes\CLSID\MADOWN
Supprimé! HKCU\Software\Microsoft\Windows\CurrentVersion\Run|api32
Supprimé! HKCU\Software\Microsoft\Windows\CurrentVersion\Run|cdoosoft
Supprimé! HKCU\Software\Microsoft\Windows\CurrentVersion\Run|King_ar
Supprimé! HKLM\Software\Microsoft\Windows\CurrentVersion\Run|MSRegInfo
################## | Mountpoints2 |
Supprimé! HKCU\.\.\.\.\Explorer\MountPoints2\F
Supprimé! HKCU\.\.\.\.\Explorer\MountPoints2\{055dd85d-61c1-11de-84f1-001e33972d26}
Supprimé! HKCU\.\.\.\.\Explorer\MountPoints2\{0c6832b6-5c9f-11de-a841-001e33972d26}
Supprimé! HKCU\.\.\.\.\Explorer\MountPoints2\{10d8393c-ecc8-11df-912e-001583166ded}
Supprimé! HKCU\.\.\.\.\Explorer\MountPoints2\{1d4ad98b-2b72-11de-a535-00225f64e7a4}
Supprimé! HKCU\.\.\.\.\Explorer\MountPoints2\{28d1eec0-b41c-11de-8513-001e33972d26}
Supprimé! HKCU\.\.\.\.\Explorer\MountPoints2\{29b2c621-2731-11de-b0a2-00225f64e7a4}
Supprimé! HKCU\.\.\.\.\Explorer\MountPoints2\{2e1ef3e8-080f-11df-9604-001583166ded}
Supprimé! HKCU\.\.\.\.\Explorer\MountPoints2\{3a9b63fa-2b1f-11de-9a68-00225f64e7a4}
Supprimé! HKCU\.\.\.\.\Explorer\MountPoints2\{3bcf2488-c954-11de-937f-001583166ded}
Supprimé! HKCU\.\.\.\.\Explorer\MountPoints2\{51b3baae-e95e-11de-807c-001583166ded}
Supprimé! HKCU\.\.\.\.\Explorer\MountPoints2\{5a682e04-7c42-11de-9654-00225f64e7a4}
Supprimé! HKCU\.\.\.\.\Explorer\MountPoints2\{66c99f3a-5fc9-11de-a181-00225f64e7a4}
Supprimé! HKCU\.\.\.\.\Explorer\MountPoints2\{6ca2cfa2-3825-11de-97b5-00225f64e7a4}
Supprimé! HKCU\.\.\.\.\Explorer\MountPoints2\{72cdb0b9-2599-11de-88b8-008098e5af7b}
Supprimé! HKCU\.\.\.\.\Explorer\MountPoints2\{7e43ddbe-5a47-11de-9579-001e33972d26}
Supprimé! HKCU\.\.\.\.\Explorer\MountPoints2\{846cec37-24e9-11de-9c01-008098e5af7b}
Supprimé! HKCU\.\.\.\.\Explorer\MountPoints2\{846cec48-24e9-11de-9c01-001e33972d26}
Supprimé! HKCU\.\.\.\.\Explorer\MountPoints2\{8c9652a2-e627-11de-8d5a-001583166ded}
Supprimé! HKCU\.\.\.\.\Explorer\MountPoints2\{8f7334ba-9e1f-11de-bd6d-00225f64e7a4}
Supprimé! HKCU\.\.\.\.\Explorer\MountPoints2\{936605e4-d451-11df-90d0-001583166ded}
Supprimé! HKCU\.\.\.\.\Explorer\MountPoints2\{a395840d-f092-11df-9dce-001583166ded}
Supprimé! HKCU\.\.\.\.\Explorer\MountPoints2\{a6d33b87-122f-11df-acd6-001583166ded}
Supprimé! HKCU\.\.\.\.\Explorer\MountPoints2\{ba433303-3d72-11df-a055-001583166ded}
Supprimé! HKCU\.\.\.\.\Explorer\MountPoints2\{c4f1b329-1d53-11e0-a9c4-001583166ded}
Supprimé! HKCU\.\.\.\.\Explorer\MountPoints2\{c78348d8-2a63-11de-84b0-001e33972d26}
Supprimé! HKCU\.\.\.\.\Explorer\MountPoints2\{ccd13602-2769-11df-81ea-001583166ded}
Supprimé! HKCU\.\.\.\.\Explorer\MountPoints2\{ccd1364b-2769-11df-81ea-001583166ded}
Supprimé! HKCU\.\.\.\.\Explorer\MountPoints2\{d74989ef-abff-11de-8213-001e33972d26}
Supprimé! HKCU\.\.\.\.\Explorer\MountPoints2\{debd8074-c2eb-11df-8d82-001583166ded}
Supprimé! HKCU\.\.\.\.\Explorer\MountPoints2\{e4ce7bf8-6c84-11df-8328-001583166ded}
Supprimé! HKCU\.\.\.\.\Explorer\MountPoints2\{e84043b2-2343-11de-a22a-00225f64e7a4}
Supprimé! HKCU\.\.\.\.\Explorer\MountPoints2\{f98a51fa-081d-11e0-9a11-001583166ded}
Supprimé! HKCU\.\.\.\.\Explorer\MountPoints2\{fc47d99e-0f0b-11df-a96c-001583166ded}
Supprimé! HKCU\.\.\.\.\Explorer\MountPoints2\{ff2e52b7-0982-11df-a463-001583166ded}
################## | Listing |
[19/01/2011 - 19:45:05 | SHD ] C:\$RECYCLE.BIN
[18/09/2006 - 22:43:36 | N | 24] C:\autoexec.bat
[04/03/2009 - 19:22:24 | D ] C:\Boonty
[05/07/2009 - 00:21:02 | D ] C:\Boot
[11/04/2009 - 07:36:36 | RASH | 333257] C:\bootmgr
[03/12/2008 - 09:47:31 | N | 8192] C:\BOOTSECT.BAK
[17/01/2011 - 17:41:13 | D ] C:\Config.Msi
[18/09/2006 - 22:43:37 | N | 10] C:\config.sys
[02/11/2006 - 14:02:03 | SHD ] C:\Documents and Settings
[16/01/2011 - 12:54:14 | D ] C:\Hama
[03/12/2008 - 10:59:06 | D ] C:\Intel
[09/12/2008 - 18:27:22 | N | 0] C:\IO.SYS
[09/12/2008 - 18:27:22 | N | 0] C:\MSDOS.SYS
[23/05/2009 - 17:41:47 | D ] C:\Netgear
[19/01/2011 - 16:55:58 | ASH | 4293918720] C:\pagefile.sys
[14/11/2010 - 17:45:10 | N | 58812] C:\pastedpic_11142010_174510.png
[21/01/2008 - 03:32:31 | D ] C:\PerfLogs
[20/02/2009 - 18:16:15 | D ] C:\pr
[19/01/2011 - 17:01:09 | D ] C:\Program Files
[29/12/2010 - 23:27:28 | HD ] C:\ProgramData
[08/12/2008 - 11:52:54 | N | 651] C:\RHDSetup.log
[03/12/2008 - 11:57:00 | N | 70] C:\SWSTAMP.TXT
[18/01/2011 - 18:53:13 | SHD ] C:\System Volume Information
[12/06/2009 - 17:28:00 | D ] C:\temp
[19/02/2009 - 18:10:58 | D ] C:\Toshiba
[19/01/2011 - 19:45:05 | D ] C:\UsbFix
[19/01/2011 - 19:41:15 | A | 9513] C:\UsbFix.txt
[30/10/2009 - 15:41:15 | D ] C:\Utilisateurs
[27/01/2009 - 12:53:22 | N | 11] C:\version.txt
[19/07/2009 - 21:31:50 | D ] C:\WIN32APP
[19/01/2011 - 19:45:00 | D ] C:\Windows
[19/01/2011 - 19:45:05 | SHD ] E:\$RECYCLE.BIN
[20/08/2009 - 22:24:18 | N | 19456] E:\aquarium3d.dgn
[26/04/2009 - 10:44:30 | D ] E:\clé
[19/06/2010 - 23:14:04 | D ] E:\divx
[13/10/2010 - 15:22:51 | D ] E:\Documents
[31/07/2010 - 14:39:59 | D ] E:\Guitar Pro 5
[01/08/2010 - 01:01:50 | D ] E:\Guitar-method-fr
[21/03/2010 - 01:05:11 | D ] E:\Larousse
[23/10/2009 - 14:28:45 | N | 208] E:\Lecteur CD - Raccourci.lnk
[30/07/2010 - 20:55:07 | D ] E:\libGP5
[24/06/2009 - 16:07:48 | D ] E:\Music
[20/08/2009 - 22:24:00 | N | 14848] E:\nouveau.dgn
[21/03/2010 - 01:11:15 | D ] E:\onisep
[18/01/2011 - 18:53:13 | SHD ] E:\System Volume Information
[29/12/2010 - 23:50:18 | D ] E:\video
[06/05/2008 - 13:26:23 | R | 309] F:\autorun.inf
[23/10/2007 - 08:45:39 | R | 1336632] F:\LaunchU3.exe
[06/05/2008 - 13:11:20 | R | 5600229] F:\LaunchPad.zip
[10/10/2010 - 17:53:16 | D ] G:\Documents
[10/11/2010 - 21:31:44 | D ] G:\video
[02/12/2010 - 11:40:42 | D ] G:\à imprimer
[11/12/2010 - 13:42:48 | N | 375459] G:\compte.ods
[06/01/2011 - 15:57:32 | D ] G:\téléchargements
[28/11/2010 - 18:01:06 | N | 24387773] G:\digestion.odt
[30/11/2008 - 10:10:52 | HD ] G:\System
[23/10/2007 - 09:45:40 | N | 1336632] G:\LaunchU3.exe
################## | Vaccin |
C:\Autorun.inf -> Dossier créé par UsbFix (El Desaparecido & C_XX)
E:\Autorun.inf -> Dossier créé par UsbFix (El Desaparecido & C_XX)
F:\Autorun.inf -> Dossier créé par Panda USB Vaccine
G:\Autorun.inf -> Dossier créé par UsbFix (El Desaparecido & C_XX)
################## | Upload |
Veuillez envoyer le fichier: C:\UsbFix_Upload_Me_PC-DE-CELINE.zip
http://www.teamxscript.org/Upload.php
Merci de votre contribution.
################## | E.O.F |