############################## | UsbFix V6.008 |
# User : Demonn (Utilisateurs) # XP-DEMONN
# Update on 17/07/09 by Chiquitine29 & C_XX
# Start at: 19:59:37 | 20/07/2009
# Website :
http://pagesperso-orange.fr/NosTools/index.html
# Intel(R) Pentium(R) 4 CPU 3.00GHz
# Microsoft Windows XP Professionnel (5.1.2600 32-bit) # Service Pack 3
# Internet Explorer 6.0.2900.5512
# Windows Firewall Status : Enabled
# AV : avast! antivirus 4.8.1335 [VPS 090719-1] 4.8.1335 [ Enabled | Updated ]
# C:\ # Disque fixe local # 48,83 Go (38,3 Go free) # NTFS
# D:\ # Disque fixe local # 100,21 Go (90,4 Go free) # NTFS
# E:\ # Disque CD-ROM
############################## | Processus actifs |
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\csrss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
C:\Program Files\Alwil Software\Avast4\ashServ.exe
C:\WINDOWS\system32\logonui.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\wdfmgr.exe
C:\Program Files\Alwil Software\Avast4\setup\avast.setup
C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
C:\WINDOWS\system32\wscntfy.exe
C:\WINDOWS\system32\wbem\wmiprvse.exe
C:\WINDOWS\System32\alg.exe
################## | Fichiers # Dossiers infectieux |
################## | C:\Documents and Settings\Demonn\Temporary Internet Files |
################## | All Drives ... |
################## | Registre # Clés Run infectieuses |
# HKLM\software\microsoft\security center "AntiVirusOverride" # -> Reset sucessfully !
################## | Registre # Mountpoints2 |
Supprimé ! HKCU\...\Explorer\MountPoints2\{ab248126-5382-11de-bb77-00138ff9b8e1}\Shell\AutoRun\Command
################## | Listing des fichiers présent |
[06/05/2009 12:57|--a------|0] - C:\AUTOEXEC.BAT
[16/07/2009 09:49|--a------|0] - C:\bcrypt.html
[06/05/2009 12:51|---hs----|212] - C:\boot.ini
[24/08/2001 17:00|-rahs----|4952] - C:\Bootfont.bin
[06/05/2009 12:57|--a------|0] - C:\CONFIG.SYS
[06/05/2009 12:57|-rahs----|0] - C:\IO.SYS
[06/05/2009 12:57|-rahs----|0] - C:\MSDOS.SYS
[04/08/2004 02:38|-rahs----|47564] - C:\NTDETECT.COM
[06/05/2009 14:28|-rahs----|252240] - C:\ntldr
[?|?|?] - C:\pagefile.sys
[20/07/2009 20:00|--a------|2557] - C:\UsbFix.txt
[12/11/2004 03:38|--a------|23622] - C:\XP.ini
[28/05/2009 17:19|--a------|7539030] - D:\- L'orchestre National De Barbes - Warda - Harramt Ahibbak.mp3
################## | Vaccination |
# C:\autorun.inf ( # Not infected ) -> Folder created by UsbFix.
# D:\autorun.inf ( # Not infected ) -> Folder created by UsbFix.
################## | Etat / Services / Informations |
# Mode sans echec : OK
# Affichage des fichiers cachés : OK
# Ndisuio -> Start = 3 ( Good = 3 | Bad = 4 )
# EapHost -> Start = 2 ( Good = 2 | Bad = 4 )
# Ip6Fw -> Start = 2 ( Good = 2 | Bad = 4 )
# SharedAccess -> Start = 2 ( Good = 2 | Bad = 4 )
# wuauserv -> Start = 2 ( Good = 2 | Bad = 4 )
# wscsvc -> Start = 2 ( Good = 2 | Bad = 4 )
################## | Cracks / Keygens / Serials |
################## | ! Fin du rapport # UsbFix V6.008 ! |