Voila
############################## [ UsbFix V3.031 ]
# User : LOTFI (Administrateurs) # LOLI
# Update on 13/06/09 by Chiquitine29
# Start at: 17:43:04 | 13/06/2009
# Website : http://pagesperso-orange.fr/NosTools/usbfix.html
# Intel(R) Pentium(R) 4 CPU 3.06GHz
# Microsoft Windows XP Professionnel (5.1.2600 32-bit) # Service Pack 2
# Internet Explorer 6.0.2900.2180
# Windows Firewall Status : Enabled
# AV : Kaspersky Anti-Virus 8.0.0.357 [ Enabled | Updated ]
# A:\ # Lecteur de disquettes 3 ½ pouces
# C:\ # Disque fixe local # 9,77 Go (3,31 Go free) # NTFS
# D:\ # Disque fixe local # 19,53 Go (5,36 Go free) # NTFS
# E:\ # Disque fixe local # 47,38 Go (12,04 Go free) [document loto] # NTFS
# F:\ # Disque CD-ROM # 600,16 Mo (0 Mo free) [X2PVOL_FR] # CDFS
# G:\ # Disque amovible # 986,34 Mo (986,3 Mo free) [SOUMIAAAAAA] # FAT32
# S:\ # Disque CD-ROM
############################## [ Processus actifs ]
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\csrss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\ctfmon.exe
E:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 2009\avp.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Fichiers communs\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\TUProgSt.exe
C:\Program Files\HHVcdV5Sys\VC5SecS.exe
C:\WINDOWS\system32\wbem\wmiprvse.exe
C:\WINDOWS\System32\alg.exe
################## [ Fichiers # Dossiers infectieux ]
Supprimé ! C:\WINDOWS\system32\winjpg.jpg
Supprimé ! C:\DOCUME~1\LOTFI\LOCALS~1\Temp\Uninstall.exe
(!) Non supprimé ! F:\Setup.exe
(!) Non supprimé ! F:\autorun.inf
################## [ Registre # Clés Run infectieuses ]
Supprimé ! HKLM\Software\Microsoft\Windows\CurrentVersion\Run "CTFMON"
Supprimé ! HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\msconfig.exe
Supprimé ! HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\procexp.exe
Supprimé ! HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\regedit.exe
Supprimé ! HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\taskmgr.exe
Supprimé ! HKLM\software\microsoft\windows nt\currentversion\image file execution options\drwtsn32.exe
Supprimé ! HKLM\software\microsoft\windows nt\currentversion\image file execution options\dwwinxp.exe
Supprimé ! HKLM\software\microsoft\windows nt\currentversion\image file execution options\rstrui.exe
# HKLM\software\microsoft\security center "AntiVirusOverride" # -> Reset sucessfully !
################## [ Registre # Mountpoints2 ]
Deleted ! HKCU\...\Explorer\MountPoints2\{bb4a3f95-5822-11de-b279-0011677854fb}\Shell\AutoRun\Command
################## [ Listing des fichiers présent ]
[31/05/2009 10:02|--a------|0] - C:\AUTOEXEC.BAT
[31/05/2009 09:57|---hs----|212] - C:\boot.ini
[07/09/2002 01:00|-rahs----|4952] - C:\Bootfont.bin
[31/05/2009 10:02|--a------|0] - C:\CONFIG.SYS
[31/05/2009 10:02|-rahs----|0] - C:\IO.SYS
[31/05/2009 10:02|-rahs----|0] - C:\MSDOS.SYS
[04/08/2004 03:38|-rahs----|47564] - C:\NTDETECT.COM
[04/08/2004 03:59|-rahs----|251712] - C:\ntldr
[?|?|?] - C:\pagefile.sys
[05/06/2009 09:04|--a------|0] - C:\ugm.log
[13/06/2009 17:45|--a------|3601] - C:\UsbFix.txt
[10/03/2009 20:01|--a------|593920] - D:\ideas.exe
[13/06/2009 16:10|--a------|9277168] - D:\MX_vs_ATV_Extreme_Limite_ by dramamanouti for www.tunisia-sat.com.rar
[07/03/2008 21:11|--a------|16777216] - D:\MX_vs_ATV_Extreme_Limite_.nds
[13/06/2009 16:43|--a------|8192] - D:\MX_vs_ATV_Extreme_Limite_.sav
[13/06/2009 15:31|--a------|65536] - D:\pokemonemeraude.sav
[13/06/2009 00:13|--a------|7027419] - D:\pokemonemeraude.zip
[13/06/2009 15:36|--a------|65536] - D:\pokemonsaphir.sav
[13/06/2009 00:14|--a------|4976854] - D:\pokemonsaphir.zip
[13/06/2009 00:20|--a------|947465] - D:\Pokemon_Cristal_Pokeblog_FR.rar
[13/06/2009 00:38|--a------|4946979] - D:\Pokemon_VF_Pokeblog_FR.rar
[13/06/2009 16:43|--a------|1397] - D:\Software.ini
[13/06/2009 17:13|--a------|2242] - D:\vba.ini
[13/06/2009 00:07|--a------|1757264] - D:\visualboyadvance.exe
[23/02/2009 17:37|--ah-----|1194908] - E:\lotfi.rar
[07/09/2002 01:00|-r-------|112] - F:\AUTORUN.INF
[18/07/2004 03:54|-r-------|37874] - F:\LISEZMOI.HTM
[04/08/2004 05:54|-r-------|2584576] - F:\SETUP.EXE
[18/07/2004 03:54|-r-------|105053] - F:\SETUPXP.HTM
[07/09/2002 01:00|-r-------|12530] - F:\SPNOTES.HTM
[07/09/2002 01:00|-r-------|10] - F:\WIN51
[07/09/2002 01:00|-r-------|10] - F:\WIN51IP
[07/09/2002 01:00|-r-------|2] - F:\WIN51IP.SP1
[04/08/2004 06:58|-r-------|2] - F:\WIN51IP.SP2
[09/05/2009 20:01|--a------|27136] - G:\????? ???? ??????.doc
################## [ Vaccination ]
# C:\autorun.inf ( # Not infected ) -> Folder created by UsbFix.
# D:\autorun.inf ( # Not infected ) -> Folder created by UsbFix.
# E:\autorun.inf ( # Not infected ) -> Folder created by UsbFix.
# G:\autorun.inf ( # Not infected ) -> Folder created by UsbFix.
################## [ ! Fin du rapport # UsbFix V3.031 ! ]