Voici le rapport usbfix, la suite arrive
############################## [ UsbFix V3.025 | Cleaning ]
# User : Momo (Utilisateurs) # KOSVOCORE
# Update on 22/05/09 by Chiquitine29, C_XX & Chimay8
# WebSite :
http://pagesperso-orange.fr/NosTools/usbfix.html
# Start at: 20:28:47 | 26/05/2009
# Mobile AMD Sempron(tm) Processor 3100+
# Microsoft Windows XP Professionnel (5.1.2600 32-bit) # Service Pack 2
# Internet Explorer 7.0.5730.13
# Windows Firewall Status : Enabled
# AV : Avira AntiVir PersonalEdition Classic 8.0.1.30 [ Enabled | Updated ]
# FW : Sunbelt Personal Firewall[ Enabled ]4.6.1861 T
# C:\ # Disque fixe local # 55,88 Go (25,77 Go free) [systeme] # NTFS
# D:\ # Disque CD-ROM
# E:\ # Disque amovible # 3,72 Go (357,42 Mo free) # FAT32
# F:\ # Disque fixe local # 29,3 Go (27,84 Go free) [reception] # NTFS
# G:\ # Disque fixe local # 203,58 Go (12,42 Go free) [Data] # NTFS
# H:\ # Disque amovible # 976,12 Mo (503,08 Mo free) # FAT
############################## [ Processus actifs ]
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\csrss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Avira\AntiVir PersonalEdition Classic\sched.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Avira\AntiVir PersonalEdition Classic\avguard.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\WINDOWS\system32\oodag.exe
C:\Program Files\Sunbelt Software\Personal Firewall\SbPFLnch.exe
C:\Program Files\Sunbelt Software\Personal Firewall\SbPFSvc.exe
C:\WINDOWS\system32\wbem\wmiapsrv.exe
C:\WINDOWS\system32\wbem\wmiprvse.exe
C:\Program Files\Sunbelt Software\Personal Firewall\SbPFCl.exe
C:\WINDOWS\system32\wbem\wmiprvse.exe
C:\WINDOWS\System32\alg.exe
################## [ Fichiers # Dossiers infectieux ]
(!) Not Deleted ! C:\copy.exe
(!) Not Deleted ! C:\RavMon.exe
E:\autorun.inf # -> fichier appelé : "E:\2u.com" ( absent ! )
Deleted ! E:\6fnlpetp.exe
Deleted ! E:\autorun.inf
(!) Not Deleted ! F:\copy.exe
(!) Not Deleted ! F:\RavMon.exe
(!) Not Deleted ! G:\copy.exe
(!) Not Deleted ! G:\RavMon.exe
(!) Not Deleted ! H:\copy.exe
(!) Not Deleted ! H:\RavMon.exe
################## [ Registre # Clés Run infectieuses ]
Deleted ! HKLM\SYSTEM\CurrentControlSet\Services\sysdrv32
Deleted ! HKLM\SYSTEM\ControlSet003\Services\sysdrv32
# HKLM\software\microsoft\security center\\ "UpdatesDisableNotify"
# -> ( Value = 0x1 | Good = 0x0 Bad = 0x1 ) # -> Reset sucessfully !
################## [ Registre # Mountpoints2 ]
Deleted ! HKCU\...\Explorer\MountPoints2\{db4901c0-bf1b-11dd-a5f6-0013d3f00919}\Shell\AutoRun\Command
################## [ Listing des fichiers présent ]
[30/11/2008 21:44|--a------|0] - C:\AUTOEXEC.BAT
[30/11/2008 21:39|---hs----|212] - C:\boot.ini
[28/08/2001 16:00|-rahs----|4952] - C:\Bootfont.bin
[30/11/2008 21:44|--a------|0] - C:\CONFIG.SYS
[26/12/2008 22:49|--a------|172] - C:\curr_ver.tmp
[30/11/2008 21:44|-rahs----|0] - C:\IO.SYS
[30/11/2008 21:44|-rahs----|0] - C:\MSDOS.SYS
[04/08/2004 00:38|-rahs----|47564] - C:\NTDETECT.COM
[04/08/2004 00:59|-rahs----|251712] - C:\ntldr
[29/02/2004 17:44|--a------|52576] - C:\orange.bmp
[?|?|?] - C:\pagefile.sys
[26/05/2009 20:32|--a------|3455] - C:\UsbFix.txt
[29/12/2008 15:41|--a------|122880] - C:\VaccinUSB.exe
[29/12/2008 15:51|--a------|6251] - C:\VaccinUSB.txt
[09/06/2008 16:34|--ah-----|4096] - E:\._.Trashes
[22/01/2009 15:47|--ah-----|15364] - E:\.DS_Store
[19/01/2009 11:29|--ah-----|53619] - E:\._P1030832.JPG
[19/01/2009 11:29|--ah-----|53384] - E:\._P1030823.JPG
[19/01/2009 11:29|--ah-----|53622] - E:\._P1030817.JPG
[19/01/2009 11:29|--ah-----|53684] - E:\._P1030811.JPG
[19/01/2009 11:29|--ah-----|53586] - E:\._P1030812.JPG
[19/01/2009 11:29|--ah-----|53734] - E:\._P1030818.JPG
[19/01/2009 11:29|--ah-----|53533] - E:\._P1030824.JPG
[19/01/2009 11:29|--ah-----|53141] - E:\._P1030833.JPG
[19/01/2009 11:29|--ah-----|53789] - E:\._P1030813.JPG
[19/01/2009 11:29|--ah-----|53761] - E:\._P1030819.JPG
[19/01/2009 11:29|--ah-----|53381] - E:\._P1030828.JPG
[19/01/2009 11:29|--ah-----|52925] - E:\._P1030834.JPG
[19/01/2009 11:29|--ah-----|53813] - E:\._P1030814.JPG
[19/01/2009 11:29|--ah-----|53802] - E:\._P1030820.JPG
[19/01/2009 11:29|--ah-----|53793] - E:\._P1030829.JPG
[19/01/2009 11:29|--ah-----|53695] - E:\._P1030835.JPG
[19/01/2009 11:29|--ah-----|53897] - E:\._P1030821.JPG
[19/01/2009 11:29|--ah-----|53388] - E:\._P1030807.JPG
[19/01/2009 11:29|--ah-----|53197] - E:\._P1030808.JPG
[19/01/2009 11:29|--ah-----|53862] - E:\._P1030822.JPG
[19/01/2009 11:29|--ah-----|53782] - E:\._P1030809.JPG
[19/01/2009 11:29|--ah-----|53352] - E:\._P1030830.JPG
[19/01/2009 11:29|--ah-----|53787] - E:\._P1030810.JPG
[19/01/2009 11:30|--ah-----|53292] - E:\._P1030831.JPG
[19/01/2009 11:30|--ah-----|53875] - E:\._P1030815.JPG
[19/01/2009 11:30|--ah-----|53657] - E:\._P1030816.JPG
[19/01/2009 11:30|--ah-----|51799] - E:\._P1030621.JPG
[19/01/2009 11:30|--ah-----|82] - E:\._P1030763.JPG
[19/01/2009 11:31|--ah-----|82] - E:\._P1030764.JPG
[21/01/2009 16:46|--ah-----|82] - E:\._grav011.tif
[21/01/2009 16:46|--ah-----|82] - E:\._grav012.tif
[21/01/2009 16:47|--ah-----|82] - E:\._grav013.tif
[21/01/2009 16:47|--ah-----|82] - E:\._grav014.tif
[21/01/2009 16:47|--ah-----|82] - E:\._grav05.tif
[21/01/2009 16:47|--ah-----|82] - E:\._grav006.tif
[21/01/2009 16:47|--ah-----|82] - E:\._grav007.tif
[21/01/2009 16:47|--ah-----|82] - E:\._grav008.tif
[21/01/2009 16:47|--ah-----|82] - E:\._grav009.tif
[21/01/2009 16:47|--ah-----|82] - E:\._grav010.tif
[22/01/2009 15:11|--ah-----|82] - E:\._Nelly
[22/01/2009 15:01|--a------|44692888] - E:\book deb 2009 opt.pdf
[22/01/2009 15:09|--a------|1279509] - E:\couv book deb 2009 opt.pdf
[26/12/2008 22:27|-rahs----|595] - F:\autorun.inf NEUTRALISE (par Anti-autorun.inf NumAuto='108681360').txt
[29/12/2008 15:41|--a------|122880] - F:\VaccinUSB.exe
[29/12/2008 15:50|--a------|6251] - F:\VaccinUSB.txt
[26/12/2008 22:27|-rahs----|595] - G:\autorun.inf NEUTRALISE (par Anti-autorun.inf NumAuto='210725611').txt
[29/12/2008 15:41|--a------|122880] - G:\VaccinUSB.exe
[29/12/2008 15:46|--a------|6251] - G:\VaccinUSB.txt
[18/05/2009 13:36|--ah-----|4096] - H:\._.Trashes
[29/12/2008 14:41|--a------|122880] - H:\VaccinUSB.exe
[18/05/2009 16:00|--ah-----|12292] - H:\.DS_Store
[18/05/2009 14:24|--a------|853644] - H:\Page1.pdf
[18/05/2009 15:12|--a------|21504] - H:\texte concours.doc
[18/05/2009 15:14|--ah-----|82] - H:\._texte concours.doc
[18/05/2009 15:14|--ah-----|82] - H:\._Page1.pdf
[18/05/2009 14:24|--a------|466032] - H:\Page2.pdf
[18/05/2009 15:14|--ah-----|82] - H:\._Page2.pdf
[18/05/2009 14:25|--a------|727730] - H:\page3.pdf
[18/05/2009 15:14|--ah-----|82] - H:\._page3.pdf
[18/05/2009 15:37|--a------|38041] - H:\texte amidba.pdf
[18/05/2009 15:39|--ah-----|82] - H:\._texte amidba.pdf
[18/05/2009 15:35|--a------|2615891] - H:\amidba.pdf
[18/05/2009 15:39|--ah-----|82] - H:\._amidba.pdf
################## [ Vaccination ]
# C:\autorun.inf ( # Not infected ) -> Folder created by UsbFix.
# E:\autorun.inf ( # Not infected ) -> Folder created by UsbFix.
# F:\autorun.inf ( # Not infected ) -> Folder created by UsbFix.
# G:\autorun.inf ( # Not infected ) -> Folder created by UsbFix.
# H:\autorun.inf ( # Not infected ) -> Folder created by UsbFix.
################## [ Informations # Fichier Suspect ]
################## [ Cracks # Keygens # Serials ]
# -> Nothing found !
################## [ ! Fin du rapport # UsbFix V3.025 ! ]