voici le rapport après scan:
############################## | UsbFix V6.049 |
User : Raïssa (Administrateurs) # RAISSA-PC
Update on 06/11/2009 by Chiquitine29, C_XX & Chimay8
Start at: 15:14:53 | 07/11/2009
Website :
http://pagesperso-orange.fr/NosTools/index.html
Contact : FindyKill.Contact@gmail.com
Genuine Intel(R) CPU T2050 @ 1.60GHz
Microsoft Windows XP Professionnel (5.1.2600 32-bit) # Service Pack 2
Internet Explorer 6.0.2900.2180
Windows Firewall Status : Enabled
AV : Kaspersky Internet Security 7.0.1.325 [ Enabled | Updated ]
FW : Kaspersky Internet Security[ Enabled ]7.0.1.325
C:\ -> Disque fixe local # 46,41 Go (19,15 Go free) # NTFS
D:\ -> Disque fixe local # 46,75 Go (39,72 Go free) # NTFS
E:\ -> Disque CD-ROM
F:\ -> Disque amovible # 966,98 Mo (935,11 Mo free) [BEN J] # FAT32
G:\ -> Disque amovible # 244 Mo (210,45 Mo free) [SAVALET] # FAT32
H:\ -> Disque amovible # 241,48 Mo (153,11 Mo free) [HP327EXT] # FAT
############################## | Processus actifs |
C:\WINDOWS\System32\smss.exe 1436
C:\WINDOWS\system32\csrss.exe 1492
C:\WINDOWS\system32\winlogon.exe 1516
C:\WINDOWS\system32\services.exe 1572
C:\WINDOWS\system32\lsass.exe 1584
C:\WINDOWS\system32\svchost.exe 1776
C:\WINDOWS\system32\svchost.exe 1884
C:\WINDOWS\System32\svchost.exe 164
C:\Program Files\Intel\Wireless\Bin\EvtEng.exe 372
C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe 412
C:\WINDOWS\system32\svchost.exe 660
C:\WINDOWS\system32\svchost.exe 820
C:\WINDOWS\system32\spoolsv.exe 1288
C:\WINDOWS\Explorer.EXE 1116
C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 7.0\avp.exe 1176
C:\Program Files\TOSHIBA\ConfigFree\CFSvcs.exe 1336
C:\WINDOWS\system32\DVDRAMSV.exe 1464
C:\WINDOWS\eHome\ehRecvr.exe 1472
C:\WINDOWS\eHome\ehSched.exe 1736
C:\Program Files\Java\jre6\bin\jqs.exe 1992
C:\Program Files\CDBurnerXP\NMSAccessU.exe 236
C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe 332
C:\Program Files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe 456
C:\WINDOWS\system32\svchost.exe 688
C:\WINDOWS\system32\svchost.exe 716
C:\WINDOWS\system32\TODDSrv.exe 736
C:\PROGRA~1\COMMON~1\X10\Common\x10nets.exe 2212
C:\WINDOWS\system32\igfxtray.exe 2288
C:\WINDOWS\system32\igfxpers.exe 2308
C:\WINDOWS\RTHDCPL.EXE 2316
C:\Program Files\Yahoo!\SoftwareUpdate\YahooAUService.exe 2324
C:\Program Files\TOSHIBA\TouchPad\TPTray.exe 2388
C:\Program Files\TOSHIBA\Touch and Launch\PadExe.exe 2416
C:\WINDOWS\ehome\mcrdsvc.exe 2516
C:\Program Files\TOSHIBA\E-KEY\CeEKey.exe 2532
C:\Program Files\Apoint2K\Apoint.exe 2632
C:\WINDOWS\system32\ZoomingHook.exe 2732
C:\WINDOWS\system32\TCtrlIOHook.exe 2740
C:\WINDOWS\system32\TPSMain.exe 2748
C:\Program Files\TOSHIBA\Utilitaire de zoom TOSHIBA\SmoothView.exe 2756
C:\Program Files\TOSHIBA\Commandes TOSHIBA\TFncKy.exe 2776
C:\Program Files\TOSHIBA\Tvs\TvsTray.exe 2820
C:\Program Files\TOSHIBA\ConfigFree\NDSTray.exe 2844
C:\Program Files\TOSHIBA\TOSHIBA Direct Disc Writer\ddwmon.exe 2852
C:\Program Files\Intel\Wireless\bin\ZCfgSvc.exe 2884
C:\Program Files\Intel\Wireless\Bin\ifrmewrk.exe 2900
C:\WINDOWS\system32\TPSBattM.exe 2912
C:\Program Files\ltmoh\Ltmoh.exe 2928
C:\WINDOWS\AGRSMMSG.exe 2936
C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 7.0\avp.exe 2948
C:\Program Files\TOSHIBA\ConfigFree\CFSServ.exe 2976
C:\Program Files\Apoint2K\Apntex.exe 3032
C:\Program Files\HP\HP Software Update\HPWuSchd2.exe 3120
C:\Program Files\Java\jre6\bin\jusched.exe 3216
C:\WINDOWS\system32\ctfmon.exe 3260
C:\Program Files\TOSHIBA\TOSCDSPD\toscdspd.exe 3276
C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe 3460
C:\WINDOWS\system32\RAMASST.exe 3604
C:\Program Files\Microsoft Office\OFFICE11\ONENOTEM.EXE 3684
C:\Program Files\HP\Digital Imaging\bin\hpqimzone.exe 3976
C:\WINDOWS\system32\dllhost.exe 620
C:\WINDOWS\system32\wbem\wmiapsrv.exe 3900
C:\WINDOWS\System32\alg.exe 480
C:\Program Files\Internet Download Manager\IEMonitor.exe 2008
C:\PROGRA~1\Intel\Wireless\Bin\Dot1XCfg.exe 5432
c:\windows\ehome\ehtray.exe 2056
C:\WINDOWS\eHome\ehmsas.exe 1908
C:\WINDOWS\system32\wbem\wmiprvse.exe 2584
################## | Fichiers # Dossiers infectieux |
C:\WINDOWS\system32\winxp.exe
F:\autorun.inf
F:\autorun.inf -> fichier appelé : "F:\vlqvh.pif" ( Absent ! )
F:\Driver\Files
F:\JAJA
F:\SEVERINA
F:\irbegt.pif
F:\omnk.pif
F:\gdog.pif
F:\kggyg.pif
F:\vgbqc.pif
F:\lwudeu.pif
F:\cjxu.pif
F:\vdhod.pif
F:\mghju.pif
F:\nwavnu.pif
F:\pxsqn.pif
F:\chdlgx.pif
F:\fjne.pif
F:\pjeun.pif
F:\elmg.pif
F:\njopbr.pif
F:\sawys.pif
F:\lryjcy.pif
F:\gnmhq.pif
F:\gsms.pif
F:\cfrqur.pif
F:\eyktwu.pif
F:\Recycler\S-1-6-21-1254946310-2159485961-600003330-2501\shellopen.exe
F:\Recycler\S-1-6-21-1254946310-2159485961-600003330-2501\Desktop.ini
F:\Recycler\S-1-6-21-1254946310-2159485961-600003330-2501
G:\autorun.inf
G:\autorun.inf -> fichier appelé : "G:\name\\\\\\\\\\\\less.exe" ( Absent ! )
G:\JAJA
################## | Registre # Clés Run infectieuses |
[HKLM\Software\Microsoft\Windows\CurrentVersion\Run] "CTFMON"
[HKLM\Software\Microsoft\Windows\CurrentVersion\Run] "regdiit"
[HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\msconfig.exe]
[HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\procexp.exe]
[HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\regedit.exe]
[HKLM\software\microsoft\windows nt\currentversion\image file execution options\drwtsn32.exe]
[HKLM\software\microsoft\windows nt\currentversion\image file execution options\dwwinxp.exe]
[HKLM\software\microsoft\windows nt\currentversion\image file execution options\rstrui.exe]
################## | Registre # Mountpoints2 |
HKCU\..\..\Explorer\MountPoints2\{392799ed-b899-11de-a344-0016d48acb6c}
Shell\AutoRun\command =F:\LAUS///pobro.exe
Shell\explore\command =F:\LAUS//pobro.exe
Shell\open\command =F:\LAUS//pobro.exe
HKCU\..\..\Explorer\MountPoints2\{42ba595b-8571-11de-ab7a-0016d48acb6c}
Shell\AutoRun\command =C:\WINDOWS\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL Wscript.exe /e:vbs winfile.jpg
HKCU\..\..\Explorer\MountPoints2\{76c68f7c-baff-11de-a349-0016d48acb6c}
Shell\AutoRun\command =C:\WINDOWS\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL YEBOua_k.EXe
HKCU\..\..\Explorer\MountPoints2\{8138ceb6-8504-11de-ab76-0016d48acb6c}
shell\AUtOpLay\comMaNd =F:\vlqvh.pif
shell\AutoRun\command =F:\vlqvh.pif
shell\exPLOre\CoMmand =F:\vlqvh.pif
shell\Open\COmmaND =F:\vlqvh.pif
HKCU\..\..\Explorer\MountPoints2\{85b749cd-a369-11de-abca-0018debba2cc}
Shell\AutoRun\command =prhkwv.exe
Shell\explore\Command =prhkwv.exe
Shell\open\Command =prhkwv.exe
HKCU\..\..\Explorer\MountPoints2\{92f4c34b-a053-11de-abc9-0018debba2cc}
Shell\AutoRun\command =NEXT\FILES\NEXT.exe
Shell\open\command =NEXT\FILES\NEXT.exe
HKCU\..\..\Explorer\MountPoints2\{d597ddf9-958a-11de-abad-0016d48acb6c}
Shell\AutoRun\command =F:\Driver\Files\DT.exe
Shell\open\command =F:\Driver\Files\DT.exe
HKCU\..\..\Explorer\MountPoints2\{dc60c114-8737-11de-ab86-0016d48acb6c}
Shell\AutoRun\command =C:\WINDOWS\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL .\\\\name\\\\\\\\\\\\less.exe
Shell\explore\command =name\\\\\\\\\\\\less.exe
Shell\open\command =name\\\\\\\\\\\\less.exe
HKCU\..\..\Explorer\MountPoints2\{f46a8fb1-b703-11de-a342-0016d48acb6c}
Shell\AutoRun\command =Driver\Files\DT.exe
Shell\open\command =Driver\Files\DT.exe
################## | Suspect |
http://www.virustotal.com |
################## | Cracks / Keygens / Serials |
################## | ! Fin du rapport # UsbFix V6.049 ! |
que dois-je faire ensuite ? merci d'avance !!!
merci encore je patiente pour la suite !!!