le rapport:
############################## [ UsbFix V3.025 | Cleaning ]
# User : Lobna (Administrateurs) # CHEF-10A8A34
# Update on 22/05/09 by Chiquitine29, C_XX & Chimay8
# WebSite :
http://pagesperso-orange.fr/NosTools/usbfix.html
# Start at: 14:18:18 | 24/05/2009
# Intel(R) Pentium(R) 4 CPU 2.66GHz
# Microsoft Windows XP Professionnel (5.1.2600 32-bit) # Service Pack 2
# Internet Explorer 6.0.2900.2180
# Windows Firewall Status : Enabled
# AV : AntiVir Desktop 9.0.1.26 [ Enabled | Updated ]
# A:\ # Lecteur de disquettes 3 ½ pouces
# C:\ # Disque fixe local # 48,83 Go (37,77 Go free) # NTFS
# D:\ # Disque fixe local # 23,3 Go (10,35 Go free) # NTFS
# E:\ # Disque CD-ROM
# F:\ # Disque CD-ROM
############################## [ Processus actifs ]
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\csrss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\logonui.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Avira\AntiVir Desktop\sched.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\userinit.exe
C:\WINDOWS\system32\WgaTray.exe
C:\Program Files\Google\Update\GoogleUpdate.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Google\Update\GoogleUpdate.exe
C:\Program Files\Avira\AntiVir Desktop\avguard.exe
C:\Program Files\Google\Update\GoogleUpdate.exe
C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
C:\Program Files\Google\Update\GoogleUpdate.exe
C:\Program Files\Canon\IJPLM\IJPLMSVC.EXE
C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe
C:\WINDOWS\System32\PAStiSvc.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\wbem\wmiprvse.exe
################## [ Fichiers # Dossiers infectieux ]
Deleted ! C:\WINDOWS\inf\smss.exe
Deleted ! C:\WINDOWS\system32\win.exe
Deleted ! C:\WINDOWS\system32\winjpg.jpg
Deleted ! "C:\Documents and Settings\Lobna\Application Data\tazebama"
Deleted ! "C:\WINDOWS\system32\Sexy Girls.scr"
Deleted ! "C:\Documents and Settings\Lobna\Application Data\svchost.exe"
Deleted ! "C:\Documents and Settings\Lobna\Application Data\lsass.exe"
Deleted ! "C:\Documents and Settings\Lobna\Application Data\smss.exe"
Deleted ! "C:\Documents and Settings\tazebama.dll"
Deleted ! C:\DOCUME~1\Lobna\LOCALS~1\Temp\{3722D541-7C01-4DB1-94C7-6EEB7F44663B}\goopdateres_ms.dll
Deleted ! C:\DOCUME~1\Lobna\LOCALS~1\Temp\{FD6A78A6-939D-43E3-8E83-A95E973EA2F0}\goopdateres_ms.dll
Deleted ! C:\winfile.jpg
Deleted ! C:\autorun.inf
Deleted ! D:\winfile.jpg
Deleted ! D:\autorun.inf
################## [ Registre # Clés Run infectieuses ]
Deleted ! HKLM\Software\Microsoft\Windows\CurrentVersion\Run "CTFMON"
Deleted ! HKLM\Software\Microsoft\Windows\CurrentVersion\Run "FrameWorkService"
Deleted ! HKLM\Software\Microsoft\Windows\CurrentVersion\Run "regdiit"
Deleted ! HKLM\Software\Microsoft\Windows\CurrentVersion\Run "smsm"
Deleted ! HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Run "FrameWorkService"
Deleted ! HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\msconfig.exe
Deleted ! HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\procexp.exe
Deleted ! HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\regedit.exe
Deleted ! HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\taskmgr.exe
Deleted ! HKLM\software\microsoft\windows nt\currentversion\image file execution options\drwtsn32.exe
Deleted ! HKLM\software\microsoft\windows nt\currentversion\image file execution options\rstrui.exe
Deleted ! HKLM\software\microsoft\windows nt\currentversion\image file execution options\dwwin.exe
# HKLM\software\microsoft\security center\\ "AntiVirusOverride"
# -> ( Value = 0x1 | Good = 0x0 Bad = 0x1 ) # -> Reset sucessfully !
################## [ Registre # Mountpoints2 ]
Deleted ! HKCU\...\Explorer\MountPoints2\{714074f3-35a1-11de-bf56-000d604755eb}\Shell\AutoRun\Command
Deleted ! HKCU\...\Explorer\MountPoints2\{e9a8a7b8-370f-11de-bf5f-000d604755eb}\Shell\AutoRun\Command
################## [ Listing des fichiers présent ]
[26/04/2009 13:34|--a------|0] - C:\AUTOEXEC.BAT
[26/04/2009 13:28|---hs----|212] - C:\boot.ini
[28/08/2001 11:00|-rahs----|4952] - C:\Bootfont.bin
[26/04/2009 13:34|--a------|0] - C:\CONFIG.SYS
[26/04/2009 13:34|-rahs----|0] - C:\IO.SYS
[26/04/2009 13:34|-rahs----|0] - C:\MSDOS.SYS
[03/08/2004 23:38|-rahs----|47564] - C:\NTDETECT.COM
[03/08/2004 23:59|-rahs----|251712] - C:\ntldr
[?|?|?] - C:\pagefile.sys
[26/04/2009 17:05|--ah-----|268] - C:\sqmdata00.sqm
[27/04/2009 07:44|--ah-----|268] - C:\sqmdata01.sqm
[26/04/2009 17:05|--ah-----|244] - C:\sqmnoopt00.sqm
[27/04/2009 07:44|--ah-----|244] - C:\sqmnoopt01.sqm
[17/05/2009 18:18|--a------|304160] - C:\StiImg.dat
[24/05/2009 14:19|--a------|5141] - C:\UsbFix.txt
[12/05/2009 10:44|--a------|128141] - D:\0015051eiJJ.jpg
[24/05/2009 11:10|--a------|5238224] - D:\09 - We Can Go Anywhere.mp3
[22/05/2009 16:55|--a------|19968] - D:\1EBC.doc
[24/05/2009 10:21|--a------|31958] - D:\2365178157_small_1.jpg
[01/05/2009 11:17|--a------|76288] - D:\Advantages of internet.doc
[04/05/2009 19:44|--a------|62976] - D:\Advantages of internet00.doc
[24/05/2009 12:32|---hs----|2342] - D:\AlbumArtSmall.jpg
[24/05/2009 12:32|---hs----|9471] - D:\AlbumArt_{973AE02F-E330-448F-A0DD-883EFF75D5C9}_Large.jpg
[24/05/2009 12:32|---hs----|2342] - D:\AlbumArt_{973AE02F-E330-448F-A0DD-883EFF75D5C9}_Small.jpg
[22/05/2009 19:14|--a------|348160] - D:\Astronomie.doc
[24/05/2009 11:11|--a------|8196302] - D:\blow your mind-jesse mac.mp3
[24/05/2009 12:32|---hs----|301] - D:\desktop.ini
[10/05/2009 11:17|--a------|24576] - D:\Exercice.doc
[24/05/2009 12:32|---hs----|9471] - D:\Folder.jpg
[21/05/2009 22:13|--a------|21504] - D:\I never forget that day.doc
[04/05/2009 20:36|--a------|61440] - D:\Internet having a vital role in today.doc
[24/05/2009 12:42|--a------|3757579] - D:\Jesse McCartney - Just So You Know.mp3
[24/05/2009 10:54|--a------|3785003] - D:\Jesse Mccartney-Beautiful Soul.mp3
[24/05/2009 10:43|--a------|2695191] - D:\Jesse_McCartney_How_Do_You_Sleep.mp3
[24/05/2009 08:41|--a------|3276794] - D:\Kat DeLuna - In The End.mp3
[01/05/2009 13:46|--a------|36864] - D:\La pression atmosph‚rique.doc
[12/05/2009 22:45|--a------|41472] - D:\LamŠsi est partie.doc
[04/05/2009 21:28|--a------|64000] - D:\loulouloulou.doc
[?|?|?] - D:\music - Gd - Gd - 01.She's No You.mp3
[19/05/2009 12:06|--a------|19968] - D:\r‚cup.doc
[23/05/2009 15:29|--a------|20992] - D:\SHAYNE WARD LYRICS.doc
[01/05/2009 13:34|--a------|355328] - D:\SystŠme solaire.doc
[04/05/2009 19:33|--a------|58368] - D:\The Advantages.doc
[24/05/2009 08:21|--ahs----|6656] - D:\Thumbs.db
[22/05/2009 16:55|--a------|19968] - D:\???????.doc
[22/05/2009 16:55|--a------|19968] - D:\?????.doc
[17/05/2009 18:06|--a------|45568] - D:\????? ??????? ?? ?????? ?????????.doc
[18/05/2009 18:35|--a------|3397632] - D:\????? ???--???? ?????.mp3
[22/05/2009 16:55|--a------|19968] - D:\????.doc
################## [ Vaccination ]
# C:\autorun.inf ( # Not infected ) -> Folder created by UsbFix.
# D:\autorun.inf ( # Not infected ) -> Folder created by UsbFix.
################## [ Informations # Fichier Suspect ]
################## [ Cracks # Keygens # Serials ]
# -> Nothing found !
################## [ ! Fin du rapport # UsbFix V3.025 ! ]
(.-~= Hacked by X4X =~-. ne s'affiche pas)