Bonjour archer9,
Merci pour ta réponse toujours limpide et tes conseils.
Comme convenu, je te joins le rapport UsbFix:
############################## | UsbFix V6.040 |
User : Philippe (Administrateurs) # DOBEDO
Update on 10/10/2009 by Chiquitine29, C_XX & Chimay8
Start at: 09:52:27 | 11/10/2009
Website : http://pagesperso-orange.fr/NosTools/index.html
AMD Turion(tm) X2 Ultra Dual-Core Mobile ZM-82
Microsoft® Windows Vista™ Édition Familiale Premium (6.0.6002 32-bit) # Service Pack 2
Internet Explorer 8.0.6001.18813
Windows Firewall Status : Enabled
C:\ -> Disque fixe local # 288,86 Go (52,13 Go free) # NTFS
D:\ -> Disque fixe local # 9,23 Go (1,17 Go free) [HP_RECOVERY] # NTFS
E:\ -> Disque CD-ROM
F:\ -> Disque fixe local # 52,95 Go (4,1 Go free) [Philippe 1] # NTFS
G:\ -> Disque CD-ROM
H:\ -> Disque fixe local # 931,51 Go (557,82 Go free) [WD 2] # NTFS
I:\ -> Disque amovible # 7,47 Go (42,84 Mo free) [USB SONY 8] # FAT32
J:\ -> Disque amovible # 3,77 Go (2,24 Go free) # NTFS
K:\ -> Disque fixe local # 2,93 Go (2,89 Go free) [PQSERVICE] # NTFS
L:\ -> Disque fixe local # 931,51 Go (35,71 Go free) [WD 1] # NTFS
M:\ -> Disque amovible # 7,53 Go (4,09 Go free) # NTFS
############################## | Processus actifs |
C:\Windows\System32\smss.exe
C:\Windows\system32\csrss.exe
C:\Windows\system32\csrss.exe
C:\Windows\system32\wininit.exe
C:\Windows\system32\services.exe
C:\Windows\system32\lsass.exe
C:\Windows\system32\lsm.exe
C:\Windows\system32\svchost.exe
C:\Windows\system32\svchost.exe
C:\Windows\System32\svchost.exe
C:\Windows\system32\Ati2evxx.exe
C:\Windows\System32\svchost.exe
C:\Windows\System32\svchost.exe
C:\Windows\system32\svchost.exe
C:\Windows\System32\DriverStore\FileRepository\stwrt.inf_a7e996cd\STacSV.exe
C:\Windows\system32\winlogon.exe
C:\Windows\system32\svchost.exe
C:\Windows\system32\SLsvc.exe
C:\Windows\system32\svchost.exe
C:\Windows\system32\LogonUI.exe
C:\Windows\system32\Hpservice.exe
C:\Windows\system32\svchost.exe
C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
C:\Windows\system32\Ati2evxx.exe
C:\Program Files\Alwil Software\Avast4\ashServ.exe
C:\Windows\system32\WLANExt.exe
C:\Windows\System32\spoolsv.exe
C:\Windows\system32\svchost.exe
C:\Program Files\Alwil Software\Avast4\setup\avast.setup
C:\Windows\system32\Dwm.exe
C:\Windows\system32\taskeng.exe
C:\Windows\Explorer.EXE
C:\Program Files\IObit\Advanced SystemCare 3\AWC.exe
C:\Windows\system32\runonce.exe
C:\Program Files\Adobe\Photoshop Elements 6.0\PhotoshopElementsFileAgent.exe
C:\Windows\System32\DriverStore\FileRepository\stwrt.inf_a7e996cd\aestsrv.exe
C:\Windows\system32\taskeng.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\Program Files\Easy-Hide-IP\services\EasyHideIp.exe
C:\Windows\system32\conime.exe
C:\Program Files\Easy-Hide-IP\services\EasyHideIP-Server2\Easy-Hide-IPS2.exe
C:\Program Files\Common Files\Nero\Nero BackItUp 4\NBService.exe
C:\Program Files\Easy-Hide-IP\services\EasyHideIP-Server2\EasyHideIP-Server2.exe
C:\Program Files\Raxco\PerfectDisk10\PDAgent.exe
C:\Windows\system32\svchost.exe
C:\Program Files\Easy-Hide-IP\services\EasyHideIP-Server1\EasyHideIP-Server1.exe
C:\Program Files\HP\QuickPlay\Kernel\TV\QPCapSvc.exe
C:\Program Files\HP\QuickPlay\Kernel\TV\QPSched.exe
C:\Windows\SMINST\BLService.exe
C:\Program Files\CyberLink\Shared Files\RichVideo.exe
C:\Windows\system32\svchost.exe
C:\Program Files\Western Digital\WD Drive Manager\WDBtnMgrSvc.exe
C:\Windows\System32\svchost.exe
C:\Windows\system32\SearchIndexer.exe
C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
C:\Program Files\Raxco\PerfectDisk10\PDEngine.exe
C:\Windows\System32\vds.exe
C:\Windows\system32\wbem\wmiprvse.exe
C:\Program Files\Raxco\PerfectDisk10\PDAgentS1.exe
C:\Windows\system32\AmplusnetPrivacyTools.exe
C:\Windows\system32\wbem\wmiprvse.exe
C:\Windows\system32\WerCon.exe
################## | Fichiers # Dossiers infectieux |
Supprimé ! C:\autorun.inf
Supprimé ! D:\autorun.inf
Supprimé ! D:\desktop.ini
Supprimé ! D:\resycled
Supprimé ! F:\autorun.inf
Supprimé ! I:\autorun.inf
Supprimé ! I:\resycled
Supprimé ! L:\autorun.inf
Supprimé ! L:\resycled
################## | Registre # Clés Run infectieuses |
################## | Registre # Mountpoints2 |
Supprimé ! HKCU\...\Explorer\MountPoints2\{f3520521-64af-11de-b7f7-00238b02877f}\Shell\AutoRun\Command
################## | Listing des fichiers présent |
[09/10/2009 08:56|--a------|14969] C:\Ad-Report-CLEAN[1].log
[09/10/2009 18:17|--a------|11939] C:\Ad-Report-CLEAN[2].log
[11/04/2009 08:36|-rahs----|333257] C:\bootmgr
[18/09/2006 23:43|--a------|10] C:\config.sys
[?|?|?] C:\hiberfil.sys
[27/02/2009 19:21|-rahs----|0] C:\IO.SYS
[03/11/2008 14:45|--ah-----|373] C:\IPH.PH
[27/02/2009 19:21|-rahs----|0] C:\MSDOS.SYS
[?|?|?] C:\pagefile.sys
[09/10/2009 18:23|--a------|1908] C:\rapport.txt
[05/07/2009 21:37|--a------|398] C:\Sys_LogWin.log
[09/10/2009 18:21|--a------|21608] C:\TB.txt
[11/10/2009 10:04|--a------|5080] C:\UsbFix.txt
[03/11/2008 14:42|---hs----|13] D:\BLOCK.RIN
[04/10/2006 00:02|---hs----|438328] D:\bootmgr
[03/11/2008 16:45|--ahs----|22] D:\HPCD.sys
[11/10/2009 10:03|--a------|46] D:\MASTER.LOG
[16/09/2002 15:37|---hs----|181898] D:\protect.chinese hong kong
[16/09/2002 15:37|---hs----|181916] D:\protect.chinese simplified
[16/09/2002 15:37|---hs----|181898] D:\protect.chinese traditional
[27/04/2006 17:19|---hs----|181865] D:\protect.czech
[03/11/2005 16:21|---hs----|181726] D:\protect.danish
[10/09/2002 14:56|---hs----|181605] D:\protect.dutch
[10/09/2002 14:50|---hs----|181651] D:\protect.ed
[22/11/2004 16:28|---hs----|181648] D:\protect.english
[03/11/2005 16:20|---hs----|181673] D:\protect.finnish
[03/11/2005 16:19|---hs----|181736] D:\protect.french
[03/11/2005 16:18|---hs----|181669] D:\protect.german
[23/11/2005 16:56|---hs----|182689] D:\protect.greek
[23/01/2006 10:18|---hs----|182605] D:\protect.hebrew
[28/08/2007 15:58|---hs----|181696] D:\protect.hungarian
[03/11/2005 16:17|---hs----|181554] D:\protect.italian
[19/06/2007 16:22|---hs----|182351] D:\protect.japanese
[24/11/2005 12:24|---hs----|218295] D:\protect.korean
[03/11/2005 16:15|---hs----|181578] D:\protect.norwegian
[25/04/2006 15:44|---hs----|181789] D:\protect.polish
[03/11/2005 16:13|---hs----|181624] D:\protect.portuguese
[27/10/2005 20:24|---hs----|181882] D:\protect.portuguese brazilian
[28/06/2004 09:52|---hs----|211936] D:\protect.russian
[03/11/2005 16:11|---hs----|181586] D:\protect.spanish
[10/09/2002 15:15|---hs----|181602] D:\protect.swedish
[12/08/2003 11:37|---hs----|181783] D:\protect.turkish
[03/11/2008 15:35|-r-hs----|26] D:\RCBoot.sys
[28/03/2009 21:55|--ah-----|4096] I:\._.Trashes
[11/09/2009 19:25|--ah-----|15364] I:\.DS_Store
[02/10/2009 19:13|--a------|982546] I:\USB Disk Security + Serial.rar
[05/10/2009 17:50|--a------|2186743598] I:\La Chute.avi
[02/10/2009 11:19|--a------|14938480] I:\IE8-WindowsVista-x86-FRA.exe
[02/10/2009 19:01|--a------|14320658] I:\Serial Box [10.2009] [MAC] + iSerial Reader [v2.0.7] + SerialSeeker [v1.3.1 (A4)] [MAC] [Universal] [CodeTempest].zip
[06/10/2009 14:39|--a------|735555584] I:\Coco.Avant.Chanel.REPACK.1CD.FRENCH.DVDRip.XviD-GKS.avi
[09/10/2008 16:11|---hs----|2070] I:\AlbumArt_{4CBEE38B-3091-438D-8D63-A1C181B2E3CB}_Small.jpg
[09/10/2008 16:12|---hs----|8049] I:\AlbumArt_{4CBEE38B-3091-438D-8D63-A1C181B2E3CB}_Large.jpg
[09/10/2008 16:12|---hs----|2730] I:\AlbumArt_{BC94D9E4-92C5-4C60-B772-0B2DAB5D8CAA}_Small.jpg
[09/10/2008 16:14|---hs----|11380] I:\AlbumArt_{BC94D9E4-92C5-4C60-B772-0B2DAB5D8CAA}_Large.jpg
[09/10/2008 16:50|---hs----|3529] I:\AlbumArt_{469D093C-9EA2-427D-87C6-6FC427303D26}_Small.jpg
[09/10/2008 16:52|---hs----|15396] I:\AlbumArt_{469D093C-9EA2-427D-87C6-6FC427303D26}_Large.jpg
[09/10/2008 17:08|---hs----|2509] I:\AlbumArt_{67AFC532-030A-468D-B774-61680B339911}_Small.jpg
[09/10/2008 17:19|---hs----|10755] I:\AlbumArt_{67AFC532-030A-468D-B774-61680B339911}_Large.jpg
[22/07/2009 09:24|--a------|20862] J:\224px-Pongo_pygmaeus_%28orangutang%29.jpg
[07/01/2009 10:47|--a------|29506] J:\AA_CH_SIGN_BNP.pdf
[08/10/2009 20:44|--a------|1156764] J:\AD-R.exe
[05/01/2009 11:09|--a------|1860842] J:\Des Hommes en Fuite.pdf
[16/12/2008 17:09|--a------|2087921] J:\fdminst-lite.exe
[16/12/2008 16:41|--a------|5871877] J:\fdminst.exe
[22/07/2009 09:39|--a------|2451456] J:\grippe A et vaccin (Bickel).pps
[08/10/2009 20:48|--a------|4045528] J:\mbam-setup.exe
[05/01/2009 21:49|--a------|712844] J:\MD5Checksum.exe
[04/01/2009 20:53|--a------|29769] J:\MediaCoder-0.6.2.4230.exe
[22/07/2009 09:38|--a------|884561] J:\MiniCV-ADESuresnes.pdf
[22/07/2009 09:41|--a------|19456] J:\permission_sortie_femme.doc
[22/07/2009 09:41|--a------|35376] J:\permission_sortie_mari.doc
[22/07/2009 09:37|--a------|182302] J:\Playmobil.pdf
[16/12/2008 17:40|--a------|6696486] J:\Setup_FreeConverter.exe
[08/10/2009 20:45|--a------|1872472] J:\SmitfraudFix.exe
[08/10/2009 20:44|--a------|343020] J:\ToolBarSD.exe
[25/01/2009 15:06|--a------|733939712] J:\Truands.avi
[30/11/2008 17:11|--a------|579814] J:\Un Clown Lyrique janvier 2008.mht
[22/07/2009 09:36|--a------|590766] J:\untitled 1.bmp
[22/07/2009 09:36|--a------|411454] J:\untitled 1bis.bmp
[22/07/2009 09:35|--a------|709174] J:\untitled.bmp
[06/01/2009 17:47|--a------|22107298] J:\videoconvertersetup.exe
[24/12/2008 00:11|-ra------|528] L:\MediaID.bin
################## | Vaccination |
# C:\autorun.inf -> Folder created by UsbFix.
# D:\autorun.inf -> Folder created by UsbFix.
# F:\autorun.inf -> Folder created by UsbFix.
# H:\autorun.inf -> Folder created by UsbFix.
# I:\autorun.inf -> Folder created by UsbFix.
# J:\autorun.inf -> Folder created by UsbFix.
# K:\autorun.inf -> Folder created by UsbFix.
# L:\autorun.inf -> Folder created by UsbFix.
# M:\autorun.inf -> Folder created by UsbFix.
############################## | UsbFix V6.040 |
User : Philippe (Administrateurs) # DOBEDO
Update on 10/10/2009 by Chiquitine29, C_XX & Chimay8
Start at: 09:52:27 | 11/10/2009
Website : http://pagesperso-orange.fr/NosTools/index.html
AMD Turion(tm) X2 Ultra Dual-Core Mobile ZM-82
Microsoft® Windows Vista™ Édition Familiale Premium (6.0.6002 32-bit) # Service Pack 2
Internet Explorer 8.0.6001.18813
Windows Firewall Status : Enabled
C:\ -> Disque fixe local # 288,86 Go (52,13 Go free) # NTFS
D:\ -> Disque fixe local # 9,23 Go (1,17 Go free) [HP_RECOVERY] # NTFS
E:\ -> Disque CD-ROM
F:\ -> Disque fixe local # 52,95 Go (4,1 Go free) [Philippe 1] # NTFS
G:\ -> Disque CD-ROM
H:\ -> Disque fixe local # 931,51 Go (557,82 Go free) [WD 2] # NTFS
I:\ -> Disque amovible # 7,47 Go (42,84 Mo free) [USB SONY 8] # FAT32
J:\ -> Disque amovible # 3,77 Go (2,24 Go free) # NTFS
K:\ -> Disque fixe local # 2,93 Go (2,89 Go free) [PQSERVICE] # NTFS
L:\ -> Disque fixe local # 931,51 Go (35,71 Go free) [WD 1] # NTFS
M:\ -> Disque amovible # 7,53 Go (4,09 Go free) # NTFS
############################## | Processus actifs |
C:\Windows\System32\smss.exe
C:\Windows\system32\csrss.exe
C:\Windows\system32\csrss.exe
C:\Windows\system32\wininit.exe
C:\Windows\system32\services.exe
C:\Windows\system32\lsass.exe
C:\Windows\system32\lsm.exe
C:\Windows\system32\svchost.exe
C:\Windows\system32\svchost.exe
C:\Windows\System32\svchost.exe
C:\Windows\system32\Ati2evxx.exe
C:\Windows\System32\svchost.exe
C:\Windows\System32\svchost.exe
C:\Windows\system32\svchost.exe
C:\Windows\System32\DriverStore\FileRepository\stwrt.inf_a7e996cd\STacSV.exe
C:\Windows\system32\winlogon.exe
C:\Windows\system32\svchost.exe
C:\Windows\system32\SLsvc.exe
C:\Windows\system32\svchost.exe
C:\Windows\system32\LogonUI.exe
C:\Windows\system32\Hpservice.exe
C:\Windows\system32\svchost.exe
C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
C:\Windows\system32\Ati2evxx.exe
C:\Program Files\Alwil Software\Avast4\ashServ.exe
C:\Windows\system32\WLANExt.exe
C:\Windows\System32\spoolsv.exe
C:\Windows\system32\svchost.exe
C:\Program Files\Alwil Software\Avast4\setup\avast.setup
C:\Windows\system32\Dwm.exe
C:\Windows\system32\taskeng.exe
C:\Windows\Explorer.EXE
C:\Program Files\IObit\Advanced SystemCare 3\AWC.exe
C:\Windows\system32\runonce.exe
C:\Program Files\Adobe\Photoshop Elements 6.0\PhotoshopElementsFileAgent.exe
C:\Windows\System32\DriverStore\FileRepository\stwrt.inf_a7e996cd\aestsrv.exe
C:\Windows\system32\taskeng.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\Program Files\Easy-Hide-IP\services\EasyHideIp.exe
C:\Windows\system32\conime.exe
C:\Program Files\Easy-Hide-IP\services\EasyHideIP-Server2\Easy-Hide-IPS2.exe
C:\Program Files\Common Files\Nero\Nero BackItUp 4\NBService.exe
C:\Program Files\Easy-Hide-IP\services\EasyHideIP-Server2\EasyHideIP-Server2.exe
C:\Program Files\Raxco\PerfectDisk10\PDAgent.exe
C:\Windows\system32\svchost.exe
C:\Program Files\Easy-Hide-IP\services\EasyHideIP-Server1\EasyHideIP-Server1.exe
C:\Program Files\HP\QuickPlay\Kernel\TV\QPCapSvc.exe
C:\Program Files\HP\QuickPlay\Kernel\TV\QPSched.exe
C:\Windows\SMINST\BLService.exe
C:\Program Files\CyberLink\Shared Files\RichVideo.exe
C:\Windows\system32\svchost.exe
C:\Program Files\Western Digital\WD Drive Manager\WDBtnMgrSvc.exe
C:\Windows\System32\svchost.exe
C:\Windows\system32\SearchIndexer.exe
C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
C:\Program Files\Raxco\PerfectDisk10\PDEngine.exe
C:\Windows\System32\vds.exe
C:\Windows\system32\wbem\wmiprvse.exe
C:\Program Files\Raxco\PerfectDisk10\PDAgentS1.exe
C:\Windows\system32\AmplusnetPrivacyTools.exe
C:\Windows\system32\wbem\wmiprvse.exe
C:\Windows\system32\WerCon.exe
################## | Fichiers # Dossiers infectieux |
Supprimé ! C:\autorun.inf
Supprimé ! D:\autorun.inf
Supprimé ! D:\desktop.ini
Supprimé ! D:\resycled
Supprimé ! F:\autorun.inf
Supprimé ! I:\autorun.inf
Supprimé ! I:\resycled
Supprimé ! L:\autorun.inf
Supprimé ! L:\resycled
################## | Registre # Clés Run infectieuses |
################## | Registre # Mountpoints2 |
Supprimé ! HKCU\...\Explorer\MountPoints2\{f3520521-64af-11de-b7f7-00238b02877f}\Shell\AutoRun\Command
################## | Listing des fichiers présent |
[09/10/2009 08:56|--a------|14969] C:\Ad-Report-CLEAN[1].log
[09/10/2009 18:17|--a------|11939] C:\Ad-Report-CLEAN[2].log
[11/04/2009 08:36|-rahs----|333257] C:\bootmgr
[18/09/2006 23:43|--a------|10] C:\config.sys
[?|?|?] C:\hiberfil.sys
[27/02/2009 19:21|-rahs----|0] C:\IO.SYS
[03/11/2008 14:45|--ah-----|373] C:\IPH.PH
[27/02/2009 19:21|-rahs----|0] C:\MSDOS.SYS
[?|?|?] C:\pagefile.sys
[09/10/2009 18:23|--a------|1908] C:\rapport.txt
[05/07/2009 21:37|--a------|398] C:\Sys_LogWin.log
[09/10/2009 18:21|--a------|21608] C:\TB.txt
[11/10/2009 10:04|--a------|5080] C:\UsbFix.txt
[03/11/2008 14:42|---hs----|13] D:\BLOCK.RIN
[04/10/2006 00:02|---hs----|438328] D:\bootmgr
[03/11/2008 16:45|--ahs----|22] D:\HPCD.sys
[11/10/2009 10:03|--a------|46] D:\MASTER.LOG
[16/09/2002 15:37|---hs----|181898] D:\protect.chinese hong kong
[16/09/2002 15:37|---hs----|181916] D:\protect.chinese simplified
[16/09/2002 15:37|---hs----|181898] D:\protect.chinese traditional
[27/04/2006 17:19|---hs----|181865] D:\protect.czech
[03/11/2005 16:21|---hs----|181726] D:\protect.danish
[10/09/2002 14:56|---hs----|181605] D:\protect.dutch
[10/09/2002 14:50|---hs----|181651] D:\protect.ed
[22/11/2004 16:28|---hs----|181648] D:\protect.english
[03/11/2005 16:20|---hs----|181673] D:\protect.finnish
[03/11/2005 16:19|---hs----|181736] D:\protect.french
[03/11/2005 16:18|---hs----|181669] D:\protect.german
[23/11/2005 16:56|---hs----|182689] D:\protect.greek
[23/01/2006 10:18|---hs----|182605] D:\protect.hebrew
[28/08/2007 15:58|---hs----|181696] D:\protect.hungarian
[03/11/2005 16:17|---hs----|181554] D:\protect.italian
[19/06/2007 16:22|---hs----|182351] D:\protect.japanese
[24/11/2005 12:24|---hs----|218295] D:\protect.korean
[03/11/2005 16:15|---hs----|181578] D:\protect.norwegian
[25/04/2006 15:44|---hs----|181789] D:\protect.polish
[03/11/2005 16:13|---hs----|181624] D:\protect.portuguese
[27/10/2005 20:24|---hs----|181882] D:\protect.portuguese brazilian
[28/06/2004 09:52|---hs----|211936] D:\protect.russian
[03/11/2005 16:11|---hs----|181586] D:\protect.spanish
[10/09/2002 15:15|---hs----|181602] D:\protect.swedish
[12/08/2003 11:37|---hs----|181783] D:\protect.turkish
[03/11/2008 15:35|-r-hs----|26] D:\RCBoot.sys
[28/03/2009 21:55|--ah-----|4096] I:\._.Trashes
[11/09/2009 19:25|--ah-----|15364] I:\.DS_Store
[02/10/2009 19:13|--a------|982546] I:\USB Disk Security + Serial.rar
[05/10/2009 17:50|--a------|2186743598] I:\La Chute.avi
[02/10/2009 11:19|--a------|14938480] I:\IE8-WindowsVista-x86-FRA.exe
[02/10/2009 19:01|--a------|14320658] I:\Serial Box [10.2009] [MAC] + iSerial Reader [v2.0.7] + SerialSeeker [v1.3.1 (A4)] [MAC] [Universal] [CodeTempest].zip
[06/10/2009 14:39|--a------|735555584] I:\Coco.Avant.Chanel.REPACK.1CD.FRENCH.DVDRip.XviD-GKS.avi
[09/10/2008 16:11|---hs----|2070] I:\AlbumArt_{4CBEE38B-3091-438D-8D63-A1C181B2E3CB}_Small.jpg
[09/10/2008 16:12|---hs----|8049] I:\AlbumArt_{4CBEE38B-3091-438D-8D63-A1C181B2E3CB}_Large.jpg
[09/10/2008 16:12|---hs----|2730] I:\AlbumArt_{BC94D9E4-92C5-4C60-B772-0B2DAB5D8CAA}_Small.jpg
[09/10/2008 16:14|---hs----|11380] I:\AlbumArt_{BC94D9E4-92C5-4C60-B772-0B2DAB5D8CAA}_Large.jpg
[09/10/2008 16:50|---hs----|3529] I:\AlbumArt_{469D093C-9EA2-427D-87C6-6FC427303D26}_Small.jpg
[09/10/2008 16:52|---hs----|15396] I:\AlbumArt_{469D093C-9EA2-427D-87C6-6FC427303D26}_Large.jpg
[09/10/2008 17:08|---hs----|2509] I:\AlbumArt_{67AFC532-030A-468D-B774-61680B339911}_Small.jpg
[09/10/2008 17:19|---hs----|10755] I:\AlbumArt_{67AFC532-030A-468D-B774-61680B339911}_Large.jpg
[22/07/2009 09:24|--a------|20862] J:\224px-Pongo_pygmaeus_%28orangutang%29.jpg
[07/01/2009 10:47|--a------|29506] J:\AA_CH_SIGN_BNP.pdf
[08/10/2009 20:44|--a------|1156764] J:\AD-R.exe
[05/01/2009 11:09|--a------|1860842] J:\Des Hommes en Fuite.pdf
[16/12/2008 17:09|--a------|2087921] J:\fdminst-lite.exe
[16/12/2008 16:41|--a------|5871877] J:\fdminst.exe
[22/07/2009 09:39|--a------|2451456] J:\grippe A et vaccin (Bickel).pps
[08/10/2009 20:48|--a------|4045528] J:\mbam-setup.exe
[05/01/2009 21:49|--a------|712844] J:\MD5Checksum.exe
[04/01/2009 20:53|--a------|29769] J:\MediaCoder-0.6.2.4230.exe
[22/07/2009 09:38|--a------|884561] J:\MiniCV-ADESuresnes.pdf
[22/07/2009 09:41|--a------|19456] J:\permission_sortie_femme.doc
[22/07/2009 09:41|--a------|35376] J:\permission_sortie_mari.doc
[22/07/2009 09:37|--a------|182302] J:\Playmobil.pdf
[16/12/2008 17:40|--a------|6696486] J:\Setup_FreeConverter.exe
[08/10/2009 20:45|--a------|1872472] J:\SmitfraudFix.exe
[08/10/2009 20:44|--a------|343020] J:\ToolBarSD.exe
[25/01/2009 15:06|--a------|733939712] J:\Truands.avi
[30/11/2008 17:11|--a------|579814] J:\Un Clown Lyrique janvier 2008.mht
[22/07/2009 09:36|--a------|590766] J:\untitled 1.bmp
[22/07/2009 09:36|--a------|411454] J:\untitled 1bis.bmp
[22/07/2009 09:35|--a------|709174] J:\untitled.bmp
[06/01/2009 17:47|--a------|22107298] J:\videoconvertersetup.exe
[24/12/2008 00:11|-ra------|528] L:\MediaID.bin
################## | Vaccination |
# C:\autorun.inf -> Folder created by UsbFix.
# D:\autorun.inf -> Folder created by UsbFix.
# F:\autorun.inf -> Folder created by UsbFix.
# H:\autorun.inf -> Folder created by UsbFix.
# I:\autorun.inf -> Folder created by UsbFix.
# J:\autorun.inf -> Folder created by UsbFix.
# K:\autorun.inf -> Folder created by UsbFix.
# L:\autorun.inf -> Folder created by UsbFix.
# M:\autorun.inf -> Folder created by UsbFix.
############################## | UsbFix V6.040 |
User : Philippe (Administrateurs) # DOBEDO
Update on 10/10/2009 by Chiquitine29, C_XX & Chimay8
Start at: 09:52:27 | 11/10/2009
Website : http://pagesperso-orange.fr/NosTools/index.html
AMD Turion(tm) X2 Ultra Dual-Core Mobile ZM-82
Microsoft® Windows Vista™ Édition Familiale Premium (6.0.6002 32-bit) # Service Pack 2
Internet Explorer 8.0.6001.18813
Windows Firewall Status : Enabled
C:\ -> Disque fixe local # 288,86 Go (52,13 Go free) # NTFS
D:\ -> Disque fixe local # 9,23 Go (1,17 Go free) [HP_RECOVERY] # NTFS
E:\ -> Disque CD-ROM
F:\ -> Disque fixe local # 52,95 Go (4,1 Go free) [Philippe 1] # NTFS
G:\ -> Disque CD-ROM
H:\ -> Disque fixe local # 931,51 Go (557,82 Go free) [WD 2] # NTFS
I:\ -> Disque amovible # 7,47 Go (42,84 Mo free) [USB SONY 8] # FAT32
J:\ -> Disque amovible # 3,77 Go (2,24 Go free) # NTFS
K:\ -> Disque fixe local # 2,93 Go (2,89 Go free) [PQSERVICE] # NTFS
L:\ -> Disque fixe local # 931,51 Go (35,71 Go free) [WD 1] # NTFS
M:\ -> Disque amovible # 7,53 Go (4,09 Go free) # NTFS
############################## | Processus actifs |
C:\Windows\System32\smss.exe
C:\Windows\system32\csrss.exe
C:\Windows\system32\csrss.exe
C:\Windows\system32\wininit.exe
C:\Windows\system32\services.exe
C:\Windows\system32\lsass.exe
C:\Windows\system32\lsm.exe
C:\Windows\system32\svchost.exe
C:\Windows\system32\svchost.exe
C:\Windows\System32\svchost.exe
C:\Windows\system32\Ati2evxx.exe
C:\Windows\System32\svchost.exe
C:\Windows\System32\svchost.exe
C:\Windows\system32\svchost.exe
C:\Windows\System32\DriverStore\FileRepository\stwrt.inf_a7e996cd\STacSV.exe
C:\Windows\system32\winlogon.exe
C:\Windows\system32\svchost.exe
C:\Windows\system32\SLsvc.exe
C:\Windows\system32\svchost.exe
C:\Windows\system32\LogonUI.exe
C:\Windows\system32\Hpservice.exe
C:\Windows\system32\svchost.exe
C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
C:\Windows\system32\Ati2evxx.exe
C:\Program Files\Alwil Software\Avast4\ashServ.exe
C:\Windows\system32\WLANExt.exe
C:\Windows\System32\spoolsv.exe
C:\Windows\system32\svchost.exe
C:\Program Files\Alwil Software\Avast4\setup\avast.setup
C:\Windows\system32\Dwm.exe
C:\Windows\system32\taskeng.exe
C:\Windows\Explorer.EXE
C:\Program Files\IObit\Advanced SystemCare 3\AWC.exe
C:\Windows\system32\runonce.exe
C:\Program Files\Adobe\Photoshop Elements 6.0\PhotoshopElementsFileAgent.exe
C:\Windows\System32\DriverStore\FileRepository\stwrt.inf_a7e996cd\aestsrv.exe
C:\Windows\system32\taskeng.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\Program Files\Easy-Hide-IP\services\EasyHideIp.exe
C:\Windows\system32\conime.exe
C:\Program Files\Easy-Hide-IP\services\EasyHideIP-Server2\Easy-Hide-IPS2.exe
C:\Program Files\Common Files\Nero\Nero BackItUp 4\NBService.exe
C:\Program Files\Easy-Hide-IP\services\EasyHideIP-Server2\EasyHideIP-Server2.exe
C:\Program Files\Raxco\PerfectDisk10\PDAgent.exe
C:\Windows\system32\svchost.exe
C:\Program Files\Easy-Hide-IP\services\EasyHideIP-Server1\EasyHideIP-Server1.exe
C:\Program Files\HP\QuickPlay\Kernel\TV\QPCapSvc.exe
C:\Program Files\HP\QuickPlay\Kernel\TV\QPSched.exe
C:\Windows\SMINST\BLService.exe
C:\Program Files\CyberLink\Shared Files\RichVideo.exe
C:\Windows\system32\svchost.exe
C:\Program Files\Western Digital\WD Drive Manager\WDBtnMgrSvc.exe
C:\Windows\System32\svchost.exe
C:\Windows\system32\SearchIndexer.exe
C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
C:\Program Files\Raxco\PerfectDisk10\PDEngine.exe
C:\Windows\System32\vds.exe
C:\Windows\system32\wbem\wmiprvse.exe
C:\Program Files\Raxco\PerfectDisk10\PDAgentS1.exe
C:\Windows\system32\AmplusnetPrivacyTools.exe
C:\Windows\system32\wbem\wmiprvse.exe
C:\Windows\system32\WerCon.exe
################## | Fichiers # Dossiers infectieux |
Supprimé ! C:\autorun.inf
Supprimé ! D:\autorun.inf
Supprimé ! D:\desktop.ini
Supprimé ! D:\resycled
Supprimé ! F:\autorun.inf
Supprimé ! I:\autorun.inf
Supprimé ! I:\resycled
Supprimé ! L:\autorun.inf
Supprimé ! L:\resycled
################## | Registre # Clés Run infectieuses |
################## | Registre # Mountpoints2 |
Supprimé ! HKCU\...\Explorer\MountPoints2\{f3520521-64af-11de-b7f7-00238b02877f}\Shell\AutoRun\Command
################## | Listing des fichiers présent |
[09/10/2009 08:56|--a------|14969] C:\Ad-Report-CLEAN[1].log
[09/10/2009 18:17|--a------|11939] C:\Ad-Report-CLEAN[2].log
[11/04/2009 08:36|-rahs----|333257] C:\bootmgr
[18/09/2006 23:43|--a------|10] C:\config.sys
[?|?|?] C:\hiberfil.sys
[27/02/2009 19:21|-rahs----|0] C:\IO.SYS
[03/11/2008 14:45|--ah-----|373] C:\IPH.PH
[27/02/2009 19:21|-rahs----|0] C:\MSDOS.SYS
[?|?|?] C:\pagefile.sys
[09/10/2009 18:23|--a------|1908] C:\rapport.txt
[05/07/2009 21:37|--a------|398] C:\Sys_LogWin.log
[09/10/2009 18:21|--a------|21608] C:\TB.txt
[11/10/2009 10:04|--a------|5080] C:\UsbFix.txt
[03/11/2008 14:42|---hs----|13] D:\BLOCK.RIN
[04/10/2006 00:02|---hs----|438328] D:\bootmgr
[03/11/2008 16:45|--ahs----|22] D:\HPCD.sys
[11/10/2009 10:03|--a------|46] D:\MASTER.LOG
[16/09/2002 15:37|---hs----|181898] D:\protect.chinese hong kong
[16/09/2002 15:37|---hs----|181916] D:\protect.chinese simplified
[16/09/2002 15:37|---hs----|181898] D:\protect.chinese traditional
[27/04/2006 17:19|---hs----|181865] D:\protect.czech
[03/11/2005 16:21|---hs----|181726] D:\protect.danish
[10/09/2002 14:56|---hs----|181605] D:\protect.dutch
[10/09/2002 14:50|---hs----|181651] D:\protect.ed
[22/11/2004 16:28|---hs----|181648] D:\protect.english
[03/11/2005 16:20|---hs----|181673] D:\protect.finnish
[03/11/2005 16:19|---hs----|181736] D:\protect.french
[03/11/2005 16:18|---hs----|181669] D:\protect.german
[23/11/2005 16:56|---hs----|182689] D:\protect.greek
[23/01/2006 10:18|---hs----|182605] D:\protect.hebrew
[28/08/2007 15:58|---hs----|181696] D:\protect.hungarian
[03/11/2005 16:17|---hs----|181554] D:\protect.italian
[19/06/2007 16:22|---hs----|182351] D:\protect.japanese
[24/11/2005 12:24|---hs----|218295] D:\protect.korean
[03/11/2005 16:15|---hs----|181578] D:\protect.norwegian
[25/04/2006 15:44|---hs----|181789] D:\protect.polish
[03/11/2005 16:13|---hs----|181624] D:\protect.portuguese
[27/10/2005 20:24|---hs----|181882] D:\protect.portuguese brazilian
[28/06/2004 09:52|---hs----|211936] D:\protect.russian
[03/11/2005 16:11|---hs----|181586] D:\protect.spanish
[10/09/2002 15:15|---hs----|181602] D:\protect.swedish
[12/08/2003 11:37|---hs----|181783] D:\protect.turkish
[03/11/2008 15:35|-r-hs----|26] D:\RCBoot.sys
[28/03/2009 21:55|--ah-----|4096] I:\._.Trashes
[11/09/2009 19:25|--ah-----|15364] I:\.DS_Store
[02/10/2009 19:13|--a------|982546] I:\USB Disk Security + Serial.rar
[05/10/2009 17:50|--a------|2186743598] I:\La Chute.avi
[02/10/2009 11:19|--a------|14938480] I:\IE8-WindowsVista-x86-FRA.exe
[02/10/2009 19:01|--a------|14320658] I:\Serial Box [10.2009] [MAC] + iSerial Reader [v2.0.7] + SerialSeeker [v1.3.1 (A4)] [MAC] [Universal] [CodeTempest].zip
[06/10/2009 14:39|--a------|735555584] I:\Coco.Avant.Chanel.REPACK.1CD.FRENCH.DVDRip.XviD-GKS.avi
[09/10/2008 16:11|---hs----|2070] I:\AlbumArt_{4CBEE38B-3091-438D-8D63-A1C181B2E3CB}_Small.jpg
[09/10/2008 16:12|---hs----|8049] I:\AlbumArt_{4CBEE38B-3091-438D-8D63-A1C181B2E3CB}_Large.jpg
[09/10/2008 16:12|---hs----|2730] I:\AlbumArt_{BC94D9E4-92C5-4C60-B772-0B2DAB5D8CAA}_Small.jpg
[09/10/2008 16:14|---hs----|11380] I:\AlbumArt_{BC94D9E4-92C5-4C60-B772-0B2DAB5D8CAA}_Large.jpg
[09/10/2008 16:50|---hs----|3529] I:\AlbumArt_{469D093C-9EA2-427D-87C6-6FC427303D26}_Small.jpg
[09/10/2008 16:52|---hs----|15396] I:\AlbumArt_{469D093C-9EA2-427D-87C6-6FC427303D26}_Large.jpg
[09/10/2008 17:08|---hs----|2509] I:\AlbumArt_{67AFC532-030A-468D-B774-61680B339911}_Small.jpg
[09/10/2008 17:19|---hs----|10755] I:\AlbumArt_{67AFC532-030A-468D-B774-61680B339911}_Large.jpg
[22/07/2009 09:24|--a------|20862] J:\224px-Pongo_pygmaeus_%28orangutang%29.jpg
[07/01/2009 10:47|--a------|29506] J:\AA_CH_SIGN_BNP.pdf
[08/10/2009 20:44|--a------|1156764] J:\AD-R.exe
[05/01/2009 11:09|--a------|1860842] J:\Des Hommes en Fuite.pdf
[16/12/2008 17:09|--a------|2087921] J:\fdminst-lite.exe
[16/12/2008 16:41|--a------|5871877] J:\fdminst.exe
[22/07/2009 09:39|--a------|2451456] J:\grippe A et vaccin (Bickel).pps
[08/10/2009 20:48|--a------|4045528] J:\mbam-setup.exe
[05/01/2009 21:49|--a------|712844] J:\MD5Checksum.exe
[04/01/2009 20:53|--a------|29769] J:\MediaCoder-0.6.2.4230.exe
[22/07/2009 09:38|--a------|884561] J:\MiniCV-ADESuresnes.pdf
[22/07/2009 09:41|--a------|19456] J:\permission_sortie_femme.doc
[22/07/2009 09:41|--a------|35376] J:\permission_sortie_mari.doc
[22/07/2009 09:37|--a------|182302] J:\Playmobil.pdf
[16/12/2008 17:40|--a------|6696486] J:\Setup_FreeConverter.exe
[08/10/2009 20:45|--a------|1872472] J:\SmitfraudFix.exe
[08/10/2009 20:44|--a------|343020] J:\ToolBarSD.exe
[25/01/2009 15:06|--a------|733939712] J:\Truands.avi
[30/11/2008 17:11|--a------|579814] J:\Un Clown Lyrique janvier 2008.mht
[22/07/2009 09:36|--a------|590766] J:\untitled 1.bmp
[22/07/2009 09:36|--a------|411454] J:\untitled 1bis.bmp
[22/07/2009 09:35|--a------|709174] J:\untitled.bmp
[06/01/2009 17:47|--a------|22107298] J:\videoconvertersetup.exe
[24/12/2008 00:11|-ra------|528] L:\MediaID.bin
################## | Vaccination |
# C:\autorun.inf -> Folder created by UsbFix.
# D:\autorun.inf -> Folder created by UsbFix.
# F:\autorun.inf -> Folder created by UsbFix.
# H:\autorun.inf -> Folder created by UsbFix.
# I:\autorun.inf -> Folder created by UsbFix.
# J:\autorun.inf -> Folder created by UsbFix.
# K:\autorun.inf -> Folder created by UsbFix.
# L:\autorun.inf -> Folder created by UsbFix.
# M:\autorun.inf -> Folder created by UsbFix.
Je fais les choses une après l'autre. Je reviens vers toi après hijakthis. Sinon, oui si il y a mieux qu'avast je suis preneur; le tout c'est de le désinstaller: ajout/supp prg suffit? J'attends ta réponse en te souhaitant un bon dimanche.
Dobedo