############################## | UsbFix V6.045 |
User : Administrateur (Administrateurs) # RECAMIENS
Update on 24/10/2009 by Chiquitine29, C_XX & Chimay8
Start at: 21:07:07 | 24/10/2009
Website :
http://pagesperso-orange.fr/NosTools/index.html
Contact : FindyKill.Contact@gmail.com
Intel(R) Pentium(R) D CPU 3.00GHz
Microsoft Windows XP Professionnel (5.1.2600 32-bit) # Service Pack 2
Internet Explorer 6.0.2900.2180
Windows Firewall Status : Enabled
AV : AntiVir Desktop 9.0.1.26 [ (!) Disabled | (!) Outdated ]
C:\ -> Disque fixe local # 66,51 Go (42,25 Go free) # NTFS
D:\ -> Disque fixe local # 8,01 Go (6,27 Go free) [HP_RECOVERY] # NTFS
E:\ -> Disque CD-ROM
F:\ -> Disque amovible
G:\ -> Disque amovible # 3,76 Go (2,57 Go free) [CLEF_2_JS] # FAT32
H:\ -> Disque amovible
I:\ -> Disque amovible
J:\ -> Disque amovible
K:\ -> Disque amovible # 3,84 Go (3,51 Go free) [STORE N GO] # FAT32
L:\ -> Disque amovible # 7,82 Go (7,74 Go free) # FAT32
############################## | Processus actifs |
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\csrss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\logonui.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Avira\AntiVir Desktop\sched.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Avira\AntiVir Desktop\avguard.exe
C:\Program Files\Fichiers communs\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\Program Files\Fichiers communs\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\WINDOWS\system32\svchost.exe
C:\Program Files\UltraVNC\WinVNC.exe
C:\WINDOWS\system32\wbem\wmiprvse.exe
C:\WINDOWS\System32\alg.exe
################## | Fichiers # Dossiers infectieux |
Supprimé ! C:\Documents and Settings\Administrateur\RavMonLog
Supprimé ! D:\autorun.inf
Supprimé ! G:\RavMonLog
Supprimé ! K:\adober.exe
Supprimé ! K:\Recycler\S-5-3-42-2819952290-8240758988-879315005-3665\jwgkvsq.vmx
Supprimé ! K:\Recycler\S-5-3-42-2819952290-8240758988-879315005-3665
Supprimé ! L:\adober.exe
Supprimé ! L:\Recycler\S-5-3-42-2819952290-8240758988-879315005-3665\jwgkvsq.vmx
Supprimé ! L:\Recycler\S-5-3-42-2819952290-8240758988-879315005-3665
################## | Registre # Clés Run infectieuses |
################## | Registre # Mountpoints2 |
Supprimé ! HKCU\...\Explorer\MountPoints2\D\Shell\AutoRun\Command
Supprimé ! HKCU\...\Explorer\MountPoints2\{16aca3e5-d23d-11db-a710-0019bb587234}\Shell\Auto\Command
Supprimé ! HKCU\...\Explorer\MountPoints2\{1bdb9d49-c8a8-11db-a708-0019bb587234}\Shell\Auto\Command
Supprimé ! HKCU\...\Explorer\MountPoints2\{5a74c780-c816-11db-a707-0019bb587234}\Shell\Auto\Command
Supprimé ! HKCU\...\Explorer\MountPoints2\{6359ea64-7717-11dc-a7b2-0019bb587234}\Shell\Auto\Command
Supprimé ! HKCU\...\Explorer\MountPoints2\{927b280e-8b76-11dc-a7d8-0019bb587234}\Shell\Auto\Command
Supprimé ! HKCU\...\Explorer\MountPoints2\{b0c9d66a-7e45-11dd-a8b5-0019bb587234}\Shell\Auto\Command
Supprimé ! HKCU\...\Explorer\MountPoints2\{b28b199a-21ef-11dd-a85a-0019bb587234}\Shell\AutoRun\Command
Supprimé ! HKCU\...\Explorer\MountPoints2\{dcd3549d-8924-11dc-a7cf-0019bb587234}\Shell\Auto\Command
Supprimé ! HKCU\...\Explorer\MountPoints2\{ec5fbeba-07da-11de-a941-0019bb587234}\Shell\Auto\Command
Supprimé ! HKCU\...\Explorer\MountPoints2\{efcb89e6-3ad4-11dc-a774-0019bb587234}\Shell\AutoRun\Command
Supprimé ! HKCU\...\Explorer\MountPoints2\{efcb89e7-3ad4-11dc-a774-0019bb587234}\Shell\Auto\Command
Supprimé ! HKCU\...\Explorer\MountPoints2\{fecdc0a8-6d4d-11de-a99f-0019bb587234}\Shell\AutoRun\Command
################## | Listing des fichiers présent |
[15/07/2002 12:19|--a------|82] C:\Blacksoft.url
[16/10/2009 21:11|-rahs----|212] C:\boot.ini
[02/03/2006 04:00|-rahs----|4952] C:\Bootfont.bin
[02/10/2007 09:26|--a------|74] C:\CMLoader.log
[26/01/2003 11:39|--a------|32768] C:\control.dll
[26/01/2003 11:40|--a------|20480] C:\Express.exe
[26/01/2003 11:39|--a------|86016] C:\FileDlg.ocx
[01/01/2003 20:34|--a------|16764] C:\help.chm
[?|?|?] C:\hiberfil.sys
[26/01/2003 11:40|--a------|98304] C:\ichaos.dll
[26/01/2003 11:38|--a------|36864] C:\init.dll
[23/04/2008 16:59|-rahs----|0] C:\IO.SYS
[22/02/2003 12:26|--a------|28672] C:\language.dll
[22/02/2003 11:40|--a------|12] C:\mkf.dat
[23/04/2008 16:59|-rahs----|0] C:\MSDOS.SYS
[02/03/2006 04:00|--ahs----|47564] C:\ntdetect.com
[02/03/2006 04:00|--ahs----|251712] C:\ntldr
[?|?|?] C:\pagefile.sys
[24/10/2009 21:09|--a------|4780] C:\UsbFix.txt
[26/01/2003 11:38|--a------|225280] C:\utilites.dll
[17/06/2008 00:04|--a------|96449884] D:\2358_MissKetty06[1].mp3
[01/07/2005 16:16|--ahs----|102] D:\Desktop.ini
[22/11/2004 20:28|--ahs----|8130] D:\Folder.htt
[03/11/2005 12:29|--ahs----|0] D:\HP_RECOVERY
[30/11/2004 16:01|--ahs----|73728] D:\Info.exe
[13/02/2007 13:59|--ahs----|1202] D:\MASTER.LOG
[29/08/2002 08:00|--ahs----|47580] D:\NTDETECT.COM
[12/05/2006 17:07|--ahs----|0] D:\NTFS
[29/08/2002 08:00|--ahs----|245920] D:\NTLDR
[10/09/2002 14:58|--ahs----|181616] D:\protect.ed
[29/08/2002 08:00|--ahs----|245920] D:\STLDR
[08/02/2002 20:44|--ahs----|88038] D:\Warning.bmp
[25/03/2005 17:00|--ahs----|10] D:\WIN51
[22/01/2001 22:00|--ahs----|11] D:\WIN51.B2
[25/07/2001 22:00|--ahs----|11] D:\WIN51.RC1
[26/07/2001 03:47|--ahs----|11] D:\WIN51.RC2
[25/03/2005 17:00|--ahs----|10] D:\WIN51IA
[25/03/2005 17:00|--ahs----|10] D:\WIN51IA.SP1
[18/08/2001 22:00|--ahs----|10] D:\WIN51IC
[20/03/2001 22:00|--ahs----|11] D:\WIN51IC.B2
[25/07/2001 22:00|--ahs----|11] D:\WIN51IC.RC1
[25/07/2001 22:00|--ahs----|11] D:\WIN51IC.RC2
[17/08/2001 22:00|--ahs----|10] D:\WIN51IP
[22/01/2001 22:00|--ahs----|11] D:\WIN51IP.B2
[26/07/2001 03:47|--ahs----|11] D:\WIN51IP.RC2
[17/08/2001 22:00|--ahs----|10] D:\WIN51IP.SP1
[17/08/2001 22:00|--ahs----|10] D:\WIN51IP2
[25/03/2005 17:00|--ahs----|167] D:\WINBOM.INI
[12/05/2006 17:07|--ahs----|0] D:\XGA
[24/10/2009 20:43|--a------|817760] G:\UsbFix.exe
[24/12/2008 21:24|--ah-----|512] G:\NIKON001.DSC
[03/05/2009 15:37|---hs----|348160] G:\msvcr71.dll
[05/05/2009 16:54|--a------|207] G:\Toute l'information des terminaux mobiles.url
[05/05/2009 16:57|--a------|139539] G:\Radar_Fr.zip
[09/05/2009 17:45|--a------|194] G:\[HTC Touch HD] Astuces + logiciels en tout genre pour votre HD.url
[29/01/2009 18:38|--a------|3968] G:\j0424748.wmf
[29/01/2009 18:38|--a------|7098] G:\j0432618.png
[29/01/2009 18:38|--a------|13052] G:\j0432666.png
[29/01/2009 18:38|--a------|12806] G:\j0432667.png
[29/01/2009 18:38|--a------|19960] G:\j0432676.png
[29/01/2009 18:38|--a------|19920] G:\j0432677.png
[29/01/2009 18:38|--a------|27878] G:\j0432678.png
[29/01/2009 18:38|--a------|28088] G:\j0432679.png
[11/09/2009 10:16|--a------|21504] G:\Cinema_REC.doc
[11/09/2009 10:30|--a------|63488] G:\SORTAIS_Jerome.doc
[25/08/2009 20:22|--a------|3921920] K:\P 09.xls
[25/08/2009 18:47|--a------|87040] K:\COMPTEUR annualisation.xls
[14/06/2009 22:03|--a------|3985408] K:\P 08.xls
[22/08/2009 15:55|--a------|419328] K:\P REC 08 09.xls
[02/02/2008 18:25|---hs----|348160] K:\msvcr71.dll
[12/03/2009 13:32|--a------|26624] K:\REC 2011.xls
[02/02/2008 18:36|---hs----|6144] K:\Thumbs.db
[16/10/2009 17:59|--a------|133120] K:\CONF REC2009.xls
[31/12/2008 20:37|--a------|222720] K:\CONF REC2008.xls
[23/09/2008 15:44|--a------|3609088] K:\P 07.xls
[27/12/2008 17:35|--a------|166400] K:\P REC 2008.xls
[17/05/2009 15:33|--a------|498176] K:\Cabine 2009.XLS
[23/12/2005 16:33|--a------|3234816] K:\P05.xls
[16/10/2009 18:00|--a------|1542656] K:\AMIENS feuille conf NOUVEAU PAIE NOV 06 marie-luce.xls
[20/02/2009 15:39|--a------|37376] K:\CDD 25 H.doc
[28/05/2009 18:08|--a------|2755072] K:\Perso3_2009 multiplexe.xls
[13/01/2009 19:49|--a------|23552] K:\Emargement Paye.xls
[19/05/2009 14:57|--a------|13645] K:\20042009_bbp.txt
[25/08/2005 21:40|--a------|1633280] K:\PLANNING HALL 2004.BACK-up.XLS
[02/09/2009 19:49|--a------|24064] K:\Stat CP 0.xls
[05/12/2004 18:40|--a------|3137536] K:\PLANNING HALL 2003.XLS
[22/10/2009 15:48|--a------|17408] K:\SSIAP 2009.xls
[23/10/2009 19:29|--a------|466944] L:\P REC 08 09.xls
[24/10/2009 20:50|--a------|4198400] L:\P 09.xls
[31/08/2009 17:31|--a------|95232] L:\COMMANDE MONNAIE&VERST LOOMIS.xls
[31/08/2009 17:32|--a------|36199424] L:\matrice nouveau CLOTURE.xls
[31/08/2009 17:27|--a------|45568] L:\SUIVI EXO.xls
[18/09/2009 17:17|--a------|23552] L:\Forfait REC 09.xls
[30/09/2009 21:45|--a------|313856] L:\P REC trois.xls
[20/10/2009 09:18|---hs----|348160] L:\msvcr71.dll
[24/10/2009 20:43|--a------|817760] L:\UsbFix.exe
[05/09/2009 21:44|--a------|36206592] L:\NEO CLOTURE.xls
[18/09/2009 15:56|--a------|23040] L:\Forfait REC 08.xls
[18/09/2009 16:01|--a------|16384] L:\CHQ NOEL 2009.xls
################## | Vaccination |
# C:\autorun.inf -> Folder created by UsbFix.
# D:\autorun.inf -> Folder created by UsbFix.
# G:\autorun.inf -> Folder created by UsbFix.
# K:\autorun.inf -> Folder created by UsbFix.
# L:\autorun.inf -> Folder created by UsbFix.
################## | Suspect |
http://www.virustotal.com |
################## | Cracks / Keygens / Serials |
################## | Upload |
Veuillez envoyer le fichier : C:\DOCUME~1\ADMINI~1\Bureau\UsbFix_Upload_Me_RECAMIENS.zip :
http://forum-aide-contre-virus.be/usbfix/choix_fichier.php
Merci pour votre contribution .
################## | ! Fin du rapport # UsbFix V6.045 ! |