Security-X
Forum Security-X => Hardware => Discussion démarrée par: Sweet-Angel le septembre 25, 2014, 21:29:22
-
Bonsoir, :AAC
J'ai sous la main une clé usb , infectée : (https://forum.security-x.fr/proxy.php?request=http%3A%2F%2Fimg15.hostingpics.net%2Fpics%2F776826Sanstitre.png&hash=9cf5bcf502ff3a83506895faebcc33d8d5257fc2) (http://www.hostingpics.net)
même si je l'ai mis en quarantaine, je n'arrive toujours pas à voir le contenu ( important ) de cette clé ( quand je clique c'est : dossier vide) alors qu'on voit bien qu'il est rempli à moitié !
Avez-vous une idée svp :AAF
Merci
P.S : Suis-je aveugle ou l'option ''héberger une image'' n'existe pas ici ?? (o)
Merci encore
-
Bonjour,
Pour vérifier cette clé et à y être les autres supports amovibles qui ont été connectés sur ce PC :
---------------------------------------------------------------------------------------------
USBFix - Recherche :
- Télécharge UsbFix (http://www.usbfix.net/?wpdmdl=497) de El Desaparecido et enregistre-le sur ton Bureau
- /!\ Important -> Branche tous les périphériques externes (clés, disques durs externes, lecteurs MP3/MP4, smartphone, carte SD, ....)
- Double-clique sur UsbFix sur ton Bureau
/!\ Sous Vista, Windows 7 et 8, il faut lancer le fichier par clic-droit -> Exécuter en tant qu'administrateur
- Clique sur l'option Recherche, valide par OK les différents messages d'informations
- La recherche se lance, patiente le temps de l'analyse
- Le rapport UsbFix.txt s'affiche. Poste ce rapport dans ta prochaine réponse
Le rapport se trouve sous C:\UsbFix.txt
Si le Bureau ne réapparait pas, presse Ctrl+Alt+Suppr, Onglet "Fichier", "Nouvelle tâche", tape explorer.exe et valide
/!\UsbFix est détecté par certains antivirus comme étant une infection, c'est un faux positif, désactive temporairement ton antivirus.
Tutoriel d'utilisation USBFix en images (http://forum.security-x.fr/tutoriels-317/tutoriel-usbfix-11888/)
---------------------------------------------------------------------------------------------
Est attendu le rapport USBFix-Recherche
Pour peux héberger une image sur http://up.security-x.fr/ (sur le bandeau en haut Accueil, Aide, Rechercher, Team, Upload, .......)
@+
-
:AAC Chantal ,
Désolée du retard, mais la personne étant pressée, a décidé de formater la clé et de tout recommencer ! tant pis donc ! :AAG
Mais quand j'aurai son pc sous la main, je reviendrai vers vous :AAN
Merci encore
-
Bonjour Sweet-Angel :D
Tant pis pour la clé alors, mais il faudra quand même vérifier le système sur lequel a été connectée cette clé, ainsi que tous les autres supports amovibles.
@+
-
Cc Chantal ,
Arf, c'est sur mon PC :( ! même si j'ai scanné avant et j'ai exploré pour voir le contenu ! Si tu juges nécessaire de vérifier mon PC , je suis tout ouïe :)
Merci beacoup :AAN
-
Re,
Ce sera vite vu, il te suffit de lancer l'outil demandé ici -> http://forum.security-x.fr/hardware/usb-defectueuse/msg123201/#msg123201
et poster le rapport de Recherche.
@+
-
:AAC Désolée du retard.
Voilà le rapport
[b]############################## | UsbFix V 7.182 | [Recherche][/b]
Utilisateur: Faty (Administrateur) # FATY-VAIO
Mis à jour le 14/09/2014 par El Desaparecido - SosVirus
Lancé à 00:30:28 | 29/09/2014
Site Web : [url=http://www.usbfix.net/]http://www.usbfix.net/[/url]
Changelog : [url=http://www.usbfix.net/maj/]http://www.usbfix.net/maj/[/url]
Assistance : [url=http://www.sosvirus.net/forum-virus-securite.html]http://www.sosvirus.net/forum-virus-securite.html[/url]
Upload Malware : [url=http://www.sosvirus.net/upload_malware.php]http://www.sosvirus.net/upload_malware.php[/url]
Détection en Live : [url=http://comment-supprimer.fr/]http://comment-supprimer.fr/[/url]
Contact : [url=http://www.usbfix.net/contact/]http://www.usbfix.net/contact/[/url]
[b]################## | System information |[/b]
MB: Sony Corporation (VAIO)
CPU: Pentium(R) Dual-Core CPU T4300 @ 2.10GHz
GC: ATI Mobility Radeon HD 4570
RAM -> [Total : 4063 Mo | Free : 1585 Mo]
Bios: American Megatrends Inc.
Boot: Normal boot
OS: Microsoft™ Windows 7 Home Premium (6.1.7601 64-Bit) Service Pack 1
WB: Internet Explorer : 11.00.9600.16428
WB: Google Chrome : 37.0.2062.124
WB: Mozilla Firefox : 32.0.3
[b]################## | Security Information |[/b]
AV: avast! Antivirus [Actif |A jour]
AS: Windows Defender [Actif |A jour]
AS: avast! Antivirus [Actif |A jour]
FW: Windows Firewall [Actif]
SC: Security Center [Actif]
WU: Windows Update [Actif]
[b]################## | Disk Information |[/b]
C:\ (%SystemDrive%) -> Disque fixe # 142 Go (17 Go libre(s) - 12%) [] # NTFS
D:\ -> Disque fixe # 146 Go (14 Go libre(s) - 10%) [Disque local] # NTFS
[b]################## | Regedit Run |[/b]
F2 - HKLM\..\Winlogon : [Shell] explorer.exe
F2 - [x64] HKLM\..\Winlogon : [Shell] explorer.exe
F2 - HKLM\..\Winlogon : [Userinit] userinit.exe
F2 - [x64] HKLM\..\Winlogon : [Userinit] C:\Windows\system32\userinit.exe,
04 - HKCU\..\Run : [Sidebar] C:\Program Files\Windows Sidebar\sidebar.exe /autoRun
04 - HKCU\..\Run : [RESTART_STICKY_NOTES] C:\Windows\System32\StikyNot.exe
04 - HKCU\..\Run : [IDMan] C:\Program Files (x86)\Internet Download Manager\IDMan.exe /onboot
04 - HKCU\..\Run : [NokiaSuite.exe] C:\Program Files (x86)\Nokia\Nokia Suite\NokiaSuite.exe -tray
04 - HKCU\..\Run : [ultracopier] "C:\Program Files (x86)\Supercopier\supercopier.exe"
04 - HKCU\..\Run : [CCleaner Monitoring] "C:\Program Files\CCleaner\CCleaner64.exe" /MONITOR
04 - HKLM\..\Run : [SunJavaUpdateSched] "C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe"
04 - HKLM\..\Run : [AvastUI.exe] "C:\Program Files\AVAST Software\Avast\AvastUI.exe" /nogui
04 - [x64] HKLM\..\Run : [RtHDVCpl] C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe
04 - [x64] HKLM\..\Run : [fssui] "C:\Program Files (x86)\Windows Live\Family Safety\fsui.exe" -autorun
04 - [x64] HKLM\..\Run : [Apoint] %ProgramFiles%\Apoint\Apoint.exe
04 - HKU\S-1-5-19\..\Run : [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun
04 - HKU\S-1-5-20\..\Run : [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun
04 - HKU\S-1-5-21-2476284646-1060634535-2591071901-1000\..\Run : [Sidebar] C:\Program Files\Windows Sidebar\sidebar.exe /autoRun
04 - HKU\S-1-5-21-2476284646-1060634535-2591071901-1000\..\Run : [RESTART_STICKY_NOTES] C:\Windows\System32\StikyNot.exe
04 - HKU\S-1-5-21-2476284646-1060634535-2591071901-1000\..\Run : [IDMan] C:\Program Files (x86)\Internet Download Manager\IDMan.exe /onboot
04 - HKU\S-1-5-21-2476284646-1060634535-2591071901-1000\..\Run : [NokiaSuite.exe] C:\Program Files (x86)\Nokia\Nokia Suite\NokiaSuite.exe -tray
04 - HKU\S-1-5-21-2476284646-1060634535-2591071901-1000\..\Run : [ultracopier] "C:\Program Files (x86)\Supercopier\supercopier.exe"
04 - HKU\S-1-5-21-2476284646-1060634535-2591071901-1000\..\Run : [CCleaner Monitoring] "C:\Program Files\CCleaner\CCleaner64.exe" /MONITOR
04 - HKU\S-1-5-19\..\RunOnce : [mctadmin] C:\Windows\System32\mctadmin.exe
04 - HKU\S-1-5-20\..\RunOnce : [mctadmin] C:\Windows\System32\mctadmin.exe
[b]################## | Recherche générique |[/b]
[b]################## | Registre |[/b]
[b]################## | UsbFix - Information |[/b]
Info : [url=https://www.youtube.com/watch?v=vUZYYASd7FE]Comment supprimer l'infection des raccourcis sur USB ? (Video)[/url]
Info : [url=http://www.en.usbfix.net/2014/03/remove-shortcut-virus-usb/]L'infection des raccourcis USB, c'est quoi ?[/url]
[b]################## | Hijack |[/b]
[b]################## | E.O.F | [url=http://www.sosvirus.net/]http://www.sosvirus.net/[/url] | [url=http://www.usbfix.net/]http://www.usbfix.net/[/url] |[/b]
Merci :AAN
-
Bonjour,
Pas d'inquiétude à avoir, ton système n'a pas été infecté par cette clé :D
-
:BAN :BAN :BAN tant mieux alors !
Merci encore Chantal :AAN :AAF