Autant pour moi, Tea timer n'était pas désastivé...voilà qui est fait...sorry
############################## [ UsbFix V3.016 # Scan ]
# User : Michael (Administrateurs) # ORDINATEUR
# Update on 02/05/09 by Chiquitine29, C_XX & Chimay8
# WebSite :
http://pagesperso-orange.fr/NosTools/usbfix.html
# Start at: 18:33:59 | 05/05/2009
# AMD Athlon(tm) 64 X2 Dual Core Processor 5200+
# Microsoft Windows XP Édition familiale (5.1.2600 32-bit) # Service Pack 1
# Internet Explorer 6.0.2800.1106
# Windows Firewall Status : Not defined.
# A:\ # Lecteur de disquettes 3 ½ pouces
# C:\ # Disque fixe local # 19,53 Go (13,97 Go free) # NTFS
# D:\ # Disque fixe local # 29,29 Go (25,32 Go free) [lyla] # NTFS
# E:\ # Disque fixe local # 29,29 Go (27,2 Go free) # NTFS
# F:\ # Disque fixe local # 33,67 Go (33,47 Go free) # NTFS
# G:\ # Disque CD-ROM # 506,57 Mo (0 Mo free) [Kit Freebox 4.1] # CDFS
# H:\ # Disque fixe local # 298,02 Go (129,25 Go free) [LA CIE] # FAT32
############################## [ Processus actifs ]
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\csrss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\System32\nvsvc32.exe
C:\WINDOWS\system\VMwareService.exe
C:\WINDOWS\system32\csrsc.exe
C:\Program Files\Analog Devices\Core\smax4pnp.exe
C:\Program Files\Analog Devices\SoundMAX\Smax4.exe
C:\WINDOWS\System32\RUNDLL32.EXE
C:\WINDOWS\System32\ctfmon.exe
C:\Program Files\Logitech\SetPoint\SetPoint.exe
C:\Program Files\Fichiers communs\Logishrd\KHAL2\KHALMNPR.EXE
C:\Program Files\Mozilla Firefox\firefox.exe
C:\WINDOWS\System32\wscript.exe
C:\WINDOWS\System32\wbem\wmiprvse.exe
################## [ Registre # Startup ]
HKCU_Main: "Local Page"="C:\\WINDOWS\\system32\\blank.htm"
HKCU_Main: "Search Page"="
http://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch"
HKCU_Main: "Start Page"="
http://www.google.fr/"
HKLM_logon: "Userinit"="C:\\WINDOWS\\system32\\userinit.exe,"
HKLM_logon: "DefaultUserName"="Michael"
HKLM_logon: "AltDefaultUserName"="Michael"
HKLM_logon: "LegalNoticeCaption"=""
HKLM_logon: "LegalNoticeText"=""
HKLM_Run: JMB36X Configure=C:\WINDOWS\System32\JMRaidTool.exe boot
HKLM_Run: SoundMAXPnP=C:\Program Files\Analog Devices\Core\smax4pnp.exe
HKLM_Run: SoundMAX="C:\Program Files\Analog Devices\SoundMAX\Smax4.exe" /tray
HKLM_Run: ilasss=C:\WINDOWS\system\lsass.exe
HKLM_Run: Windows Explorer=C:\WINDOWS\System32\explorer.exe
HKLM_Run: Spooler SubSystem App=C:\WINDOWS\System32\spoolsvc.exe
HKLM_Run: PromoReg=C:\WINDOWS\System32\lcxrsk.exe
HKLM_Run: MS32DLL=C:\WINDOWS\.MS32DLL.dll.vbs
HKLM_Run: winboot=wscript.exe /E:vbs C:\WINDOWS\boot.ini
HKLM_Run: NvCplDaemon=RUNDLL32.EXE C:\WINDOWS\System32\NvCpl.dll,NvStartup
HKLM_Run: nwiz=nwiz.exe /install
HKLM_Run: NvMediaCenter=RUNDLL32.EXE C:\WINDOWS\System32\NvMcTray.dll,NvTaskbarInit
HKLM_Run: Kernel and Hardware Abstraction Layer=KHALMNPR.EXE
HKCU_Run: CTFMON.EXE=C:\WINDOWS\System32\ctfmon.exe
HKCU_Run: 32NFG94-H61-2SF-N1P-5M1ERH6L6=C:\RECYCLER\S-1-5-21-6360033823-7822489874-596852530-8001\winIgn.exe
HKCU_Run: 12CFG515-K641-55SF-N66P=C:\RECYCLER\S-1-5-21-0243636035-3055115376-381863306-1556\pqlmq.exe
HKCU_Run: 12CFG515-K641-55SF-N55P=C:\RECYCLER\S-1-5-21-0243336035-3055115375-381863305-1553\vslmq.exe
################## [ Informations ]
################## [ Fichiers # Dossiers infectieux ]
Found ! C:\WINDOWS\.MS32DLL.dll.vbs
Found ! C:\WINDOWS\boot.ini
Found ! C:\WINDOWS\system32\drivers\sysdrv32.sys
Found ! C:\.MS32DLL.dll.vbs
Found ! C:\autorun.inf
Found ! D:\.MS32DLL.dll.vbs
Found ! D:\autorun.inf
Found ! E:\.MS32DLL.dll.vbs
Found ! E:\autorun.inf
Found ! F:\.MS32DLL.dll.vbs
Found ! F:\autorun.inf
Found ! G:\autorun.inf
Found ! H:\.MS32DLL.dll.vbs
Found ! H:\autorun.inf
################## [ Registre # Clés Run infectieuses ]
Found ! HKLM\Software\Microsoft\Windows\CurrentVersion\Run "ms32dll"
Found ! HKLM\Software\Microsoft\Windows\CurrentVersion\Run "Spooler SubSystem App"
Found ! HKLM\Software\Microsoft\Windows\CurrentVersion\Run "Winboot"
################## [ Registre # Mountpoints2 ]
# -> Not Found !
################## [ ! Fin du rapport # UsbFix V3.016 ! ]