USBFix:
############################## | UsbFix V6.053 |
############################## | Processus actifs |
C:\WINDOWS\System32\smss.exe 456
C:\WINDOWS\system32\csrss.exe 520
C:\WINDOWS\system32\winlogon.exe 552
C:\WINDOWS\system32\services.exe 596
C:\WINDOWS\system32\lsass.exe 608
C:\WINDOWS\system32\svchost.exe 792
C:\WINDOWS\system32\svchost.exe 844
C:\WINDOWS\System32\svchost.exe 880
C:\WINDOWS\system32\svchost.exe 944
C:\WINDOWS\system32\logonui.exe 976
C:\WINDOWS\system32\spoolsv.exe 1124
C:\WINDOWS\Explorer.EXE 1320
C:\Program Files\Java\jre6\bin\jqs.exe 1380
C:\Program Files\Malwarebytes' Anti-Malware\mbamservice.exe 1484
C:\WINDOWS\system32\svchost.exe 1552
C:\WINDOWS\System32\alg.exe 1888
C:\WINDOWS\system32\wscntfy.exe 1948
################## | Fichiers # Dossiers infectieux |
Supprimé ! C:\DOCUME~1\Moussa\LOCALS~1\Temp\107.exe
Supprimé ! C:\DOCUME~1\Moussa\LOCALS~1\Temp\183.exe
Supprimé ! C:\Recycler\S-1-5-21-0243556031-888888379-781863308-1455\fresdg.exe
Supprimé ! C:\Recycler\S-1-5-21-0243556031-888888379-781863308-1455\Desktop.ini
Supprimé ! C:\Recycler\S-1-5-21-0243556031-888888379-781863308-1455
Supprimé ! C:\Recycler\S-1-5-21-0243936033-3052116371-381863308-1811\vsbntlo.exe
Supprimé ! C:\Recycler\S-1-5-21-0243936033-3052116371-381863308-1811\Desktop.ini
Supprimé ! C:\Recycler\S-1-5-21-0243936033-3052116371-381863308-1811
Supprimé ! C:\Recycler\S-1-5-21-0243936033-3052116371-381863308-1859\ls888.exe
Supprimé ! C:\Recycler\S-1-5-21-0243936033-3052116371-381863308-1859\Desktop.ini
Supprimé ! C:\Recycler\S-1-5-21-0243936033-3052116371-381863308-1859
Supprimé ! C:\Recycler\S-1-5-21-1191667783-2647786256-508639984-6251\wnzip32.exe
Supprimé ! C:\Recycler\S-1-5-21-1191667783-2647786256-508639984-6251\Desktop.ini
Supprimé ! C:\Recycler\S-1-5-21-1191667783-2647786256-508639984-6251
G:\autorun.inf -> fichier appelé : "G:\RECYCLING\autorun.exe" ( Présent ! )
Supprimé ! G:\RECYCLING\autorun.exe
Supprimé ! G:\autorun.inf
Supprimé ! G:\nlhgul.pif
################## | Mabezat |
Supprimé ! C:\DOCUME~1\Moussa\APPLIC~1\tazebama
Supprimé ! D:\Famille\My Folda\Babes\Saves\RecycleBinProtect.exe
Supprimé ! G:\FOUND.000\WinrRarSerialInstall.exe
Supprimé ! C:\Documents and Settings\Moussa\Bureau\Avvies\Croquis\Others'\Others'\imp_data.rar
Supprimé ! D:\Downloads\15000 Useful English Phrases [GeneGeter.com]\MyDocuments.rar
Supprimé ! D:\Downloads\A Brief History of the Internet Ebook\documents_backup.rar
Supprimé ! D:\Downloads\A Positive Attitude Ebook\imp_data.rar
Supprimé ! D:\Downloads\Absolute Beginner's Guide to Personal Firewalls~tqw~_darksiderg\source.rar
Supprimé ! D:\Downloads\Animal Anatomy for artists\passwords.rar
Supprimé ! D:\Downloads\ArabLionz.com.Cr.TE.Pc.By.aly\serials.rar
Supprimé ! D:\Downloads\Windows XP Hidden Appz\MyDocuments.rar
Supprimé ! D:\Downloads\Windows XP Hidden Appz\Windows XP Hidden Appz\documents_backup.rar
Supprimé ! D:\Downloads\Windows.Genuine.Advantage.Validation.v1.7.69.2.CRACKED-ETH0\backup.rar
Supprimé ! D:\Downloads\World of Darkness\documents_backup.rar
Supprimé ! D:\Downloads\World of Darkness -- Silent Hill -- Fan Supplement\imp_data.rar
Supprimé ! D:\Famille\chuck file\passwords.rar
Supprimé ! D:\Famille\chuck file\naruto\Naruto Tome 2\Naruto Tome 2\source.rar
Supprimé ! D:\Famille\chuck file\naruto\Naruto Tome 3\MyDocuments.rar
Supprimé ! D:\Famille\chuck file\naruto\Naruto Tome 3\Naruto Tome 3\windows_secrets.rar
Supprimé ! D:\Famille\chuck file\naruto\Naruto Tome 4\backup.rar
Supprimé ! D:\Famille\chuck file\naruto\Naruto Tome 4\Naruto Tome 4\passwords.rar
Supprimé ! D:\Famille\chuck file\naruto\Naruto Tome 5\documents_backup.rar
Supprimé ! D:\Famille\chuck file\naruto\Naruto Tome 5\Naruto Tome 5\serials.rar
Supprimé ! D:\Famille\chuck file\naruto\Naruto_tome1\imp_data.rar
Supprimé ! D:\Famille\chuck file\naruto\Naruto_tome1\Naruto Tome 1\office_crack.rar
Supprimé ! D:\Famille\chuck file\naruto\Naruto_tome1\Naruto Tome 1\Naruto Chapitre 001\windows.rar
Supprimé ! D:\Famille\Doccies\serials.rar
Supprimé ! D:\Famille\Docs\office_crack.rar
Supprimé ! D:\Famille\My Folda\windows.rar
Supprimé ! D:\Famille\My Folda\02.04.2009 - chri3a\backup.rar
Supprimé ! D:\Famille\My Folda\02.04.2009 - chri3a\Cabinet allez\imp_data.rar
Supprimé ! D:\Famille\My Folda\02.04.2009 - chri3a\Houma\source.rar
Supprimé ! D:\Famille\My Folda\02.04.2009 - chri3a\Me\windows_secrets.rar
Supprimé ! D:\Famille\My Folda\Avvies\Croquis\Others'\imp_data.rar
Supprimé ! D:\Famille\My Folda\Babes\Baby Jane\source.rar
Supprimé ! D:\Famille\My Folda\Babes\Baby Jane\Xtina\serials.rar
Supprimé ! D:\Famille\My Folda\Babes\FHM - The Ultimate Sex Positions Images\Classic Doggie\windows.rar
Supprimé ! D:\Famille\My Folda\Babes\Wowy\passwords.rar
Supprimé ! D:\Famille\My Folda\Fo' Peffy\Metantai Conan\Tome 01\MyDocuments.rar
Supprimé ! D:\Famille\My Folda\W\MyDocuments.rar
Supprimé ! D:\Program Files\Adobe\Adobe Photoshop CS2\Activation\da_DK\windows.rar
Supprimé ! D:\Program Files\Adobe\Adobe Photoshop CS2\Aide\MyDocuments.rar
Supprimé ! D:\Program Files\Adobe\Adobe Photoshop CS2\Exemples\backup.rar
Supprimé ! D:\Program Files\Adobe\Adobe Photoshop CS2\Guide des scripts\documents_backup.rar
Supprimé ! D:\Program Files\Adobe\Adobe Photoshop CS2\Helpers\imp_data.rar
Supprimé ! D:\Program Files\Adobe\Adobe Photoshop CS2\Legal\source.rar
Supprimé ! D:\Program Files\Adobe\Adobe Photoshop CS2\Legal\es_es\MyDocuments.rar
Supprimé ! D:\Program Files\Adobe\Adobe Photoshop CS2\Legal\fi_fi\backup.rar
Supprimé ! D:\Program Files\Adobe\Adobe Photoshop CS2\Legal\fr_fr\documents_backup.rar
Supprimé ! D:\Program Files\Adobe\Adobe Photoshop CS2\Legal\it_it\imp_data.rar
Supprimé ! D:\Program Files\Adobe\Adobe Photoshop CS2\Legal\ja_jp\source.rar
Supprimé ! D:\Program Files\Adobe\Adobe Photoshop CS2\Legal\ko_kr\windows_secrets.rar
Supprimé ! D:\Program Files\Adobe\Adobe Photoshop CS2\Legal\nl_nl\passwords.rar
Supprimé ! D:\Program Files\Adobe\Adobe Photoshop CS2\Legal\no_no\serials.rar
Supprimé ! D:\Program Files\Adobe\Adobe Photoshop CS2\Legal\pt_br\office_crack.rar
Supprimé ! D:\Program Files\Adobe\Adobe Photoshop CS2\Legal\sv_se\windows.rar
Supprimé ! D:\Program Files\Adobe\Adobe Photoshop CS2\Modules externes\windows_secrets.rar
Supprimé ! D:\Program Files\Adobe\Adobe Photoshop CS2\Modules externes\Adobe Photoshop Only\Extensions\Grands carreaux\passwords.rar
Supprimé ! D:\Program Files\Adobe\Adobe Photoshop CS2\Modules externes\Adobe Photoshop Only\Importation-Exportation\windows_secrets.rar
Supprimé ! D:\Program Files\Adobe\Adobe Photoshop CS2\ParamŠtres d'Adobe Photoshop CS2\passwords.rar
Supprimé ! D:\Program Files\Adobe\Adobe Photoshop CS2\ParamŠtres pr‚d‚finis\serials.rar
Supprimé ! D:\Program Files\Adobe\Adobe Photoshop CS2\ParamŠtres pr‚d‚finis\Bichromie\3 encres\windows_secrets.rar
Supprimé ! D:\Program Files\Adobe\Adobe Photoshop CS2\ParamŠtres pr‚d‚finis\Bichromie\3 encres\Gris\office_crack.rar
Supprimé ! D:\Program Files\Adobe\Adobe Photoshop CS2\ParamŠtres pr‚d‚finis\Bichromie\3 encres\PANTONE(R)\windows.rar
Supprimé ! D:\Program Files\Adobe\Adobe Photoshop CS2\ParamŠtres pr‚d‚finis\Bichromie\4 encres\passwords.rar
Supprimé ! D:\Program Files\Adobe\Adobe Photoshop CS2\ParamŠtres pr‚d‚finis\Bichromie\Bichromie\serials.rar
Supprimé ! D:\Program Files\Adobe\Adobe Photoshop CS2\ParamŠtres pr‚d‚finis\Galerie Web Photo\Bordure pointill‚e - Blanc-noir\serials.rar
Supprimé ! D:\Program Files\Adobe\Adobe Photoshop CS2\ParamŠtres pr‚d‚finis\Galerie Web Photo\Cadre centr‚ 1 - Infos seules\windows.rar
Supprimé ! D:\Program Files\Adobe\Adobe Photoshop CS2\ParamŠtres pr‚d‚finis\Scripts\MyDocuments.rar
Supprimé ! D:\Program Files\Adobe\Adobe Photoshop CS2\ParamŠtres pr‚d‚finis\Scripts Photoshop\backup.rar
Supprimé ! D:\Program Files\Adobe\Adobe Photoshop CS2\ParamŠtres pr‚d‚finis\Styles\documents_backup.rar
Supprimé ! D:\Program Files\Adobe\Adobe Photoshop CS2\ParamŠtres pr‚d‚finis\Textures\imp_data.rar
Supprimé ! D:\Program Files\Adobe\Adobe Photoshop CS2\ParamŠtres pr‚d‚finis\ZoomView\source.rar
Supprimé ! D:\Program Files\Adobe\Adobe Photoshop CS2\Required\office_crack.rar
Supprimé ! D:\Program Files\AutoHotkey\Extras\Editors\EmEditor\MyDocuments.rar
Supprimé ! D:\Program Files\AutoHotkey\Extras\Editors\jEdit\backup.rar
Supprimé ! D:\Program Files\AutoHotkey\Extras\Editors\MED\documents_backup.rar
Supprimé ! D:\Program Files\AutoHotkey\Extras\Editors\Notepad++\imp_data.rar
Supprimé ! D:\Program Files\AutoHotkey\Extras\Editors\PSPad\source.rar
Supprimé ! D:\Program Files\AutoHotkey\Extras\Editors\SciTE\windows_secrets.rar
Supprimé ! D:\Program Files\AutoHotkey\Extras\Editors\Syntax\passwords.rar
Supprimé ! D:\Program Files\AutoHotkey\Extras\Editors\TextPad\serials.rar
Supprimé ! D:\Program Files\AutoHotkey\Extras\Editors\UltraEdit\office_crack.rar
Supprimé ! D:\Program Files\AutoHotkey\Extras\Editors\Vim\windows.rar
Supprimé ! D:\Program Files\EasyPHP 3.0\mysql\data\mysql\MyDocuments.rar
Supprimé ! D:\Program Files\EasyPHP 3.0\mysql\share\charsets\backup.rar
Supprimé ! D:\Program Files\EasyPHP 3.0\mysql\share\czech\documents_backup.rar
Supprimé ! D:\Program Files\EasyPHP 3.0\mysql\share\danish\imp_data.rar
Supprimé ! D:\Program Files\EasyPHP 3.0\mysql\share\dutch\source.rar
Supprimé ! D:\Program Files\EasyPHP 3.0\mysql\share\english\windows_secrets.rar
Supprimé ! D:\Program Files\EasyPHP 3.0\mysql\share\estonian\passwords.rar
Supprimé ! D:\Program Files\EasyPHP 3.0\mysql\share\french\serials.rar
Supprimé ! D:\Program Files\EasyPHP 3.0\mysql\share\german\office_crack.rar
Supprimé ! D:\Program Files\EasyPHP 3.0\mysql\share\greek\windows.rar
Supprimé ! D:\Program Files\EasyPHP 3.0\phpmyadmin\js\mooRainbow\images\MyDocuments.rar
Supprimé ! D:\Program Files\EasyPHP 3.0\phpmyadmin\libraries\auth\backup.rar
Supprimé ! D:\Program Files\EasyPHP 3.0\phpmyadmin\libraries\auth\swekey\windows.rar
Supprimé ! D:\Program Files\EasyPHP 3.0\phpmyadmin\libraries\dbg\documents_backup.rar
Supprimé ! D:\Program Files\EasyPHP 3.0\phpmyadmin\libraries\dbi\imp_data.rar
Supprimé ! D:\Program Files\EasyPHP 3.0\phpmyadmin\libraries\engines\source.rar
Supprimé ! D:\Program Files\EasyPHP 3.0\phpmyadmin\libraries\export\windows_secrets.rar
Supprimé ! D:\Program Files\EasyPHP 3.0\phpmyadmin\libraries\import\passwords.rar
Supprimé ! D:\Program Files\EasyPHP 3.0\phpmyadmin\libraries\tcpdf\serials.rar
Supprimé ! D:\Program Files\EasyPHP 3.0\phpmyadmin\libraries\transformations\office_crack.rar
Supprimé ! D:\Program Files\EasyPHP 3.0\sqlitemanager\spaw\lib\lang\dk\MyDocuments.rar
Supprimé ! D:\Program Files\EasyPHP 3.0\sqlitemanager\spaw\lib\lang\en\backup.rar
Supprimé ! D:\Program Files\EasyPHP 3.0\sqlitemanager\spaw\lib\lang\es\documents_backup.rar
Supprimé ! D:\Program Files\EasyPHP 3.0\sqlitemanager\spaw\lib\lang\et\imp_data.rar
Supprimé ! D:\Program Files\EasyPHP 3.0\sqlitemanager\spaw\lib\lang\fi\source.rar
Supprimé ! D:\Program Files\EasyPHP 3.0\sqlitemanager\spaw\lib\lang\fr\windows_secrets.rar
Supprimé ! D:\Program Files\EasyPHP 3.0\sqlitemanager\spaw\lib\lang\gr\passwords.rar
Supprimé ! D:\Program Files\EasyPHP 3.0\sqlitemanager\spaw\lib\lang\gz\serials.rar
Supprimé ! D:\Program Files\EasyPHP 3.0\sqlitemanager\spaw\lib\lang\he\office_crack.rar
Supprimé ! D:\Program Files\EasyPHP 3.0\sqlitemanager\spaw\lib\lang\hr\windows.rar
Supprimé ! D:\Program Files\EasyPHP 3.0\sqlitemanager\theme\default\MyDocuments.rar
Supprimé ! D:\Program Files\EasyPHP 3.0\sqlitemanager\theme\default\menu\source.rar
Supprimé ! D:\Program Files\EasyPHP 3.0\sqlitemanager\theme\default\pics\windows_secrets.rar
Supprimé ! D:\Program Files\EasyPHP 3.0\sqlitemanager\theme\green\backup.rar
Supprimé ! D:\Program Files\EasyPHP 3.0\sqlitemanager\theme\green\menu\passwords.rar
Supprimé ! D:\Program Files\EasyPHP 3.0\sqlitemanager\theme\green\pics\serials.rar
Supprimé ! D:\Program Files\EasyPHP 3.0\sqlitemanager\theme\jall\documents_backup.rar
Supprimé ! D:\Program Files\EasyPHP 3.0\sqlitemanager\theme\PMA\imp_data.rar
Supprimé ! D:\Program Files\Internet Download Manager\Languages\office_crack.rar
Supprimé ! D:\Program Files\Internet Download Manager\Toolbar\windows.rar
Supprimé ! G:\Books\How to Build Muscle without Weights [hotcyzone]\MyDocuments.rar
Supprimé ! G:\Books\Burn the Fat, Feed the Muscle - Tom Venuto\backup.rar
Supprimé ! G:\How to Build Muscle without Weights [hotcyzone]\MyDocuments.rar
################## | Registre # Clés Run infectieuses |
Supprimé ! [HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "12CFG214-K641-12SF-N85P"
Supprimé ! [HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "12CFG214-K641-24SF-N85P"
Supprimé ! [HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "Test321"
Supprimé ! [HKLM\Software\Microsoft\Windows\CurrentVersion\Run] "Microsoft Driver Setup"
Supprimé ! [HKLM\Software\Microsoft\Windows\CurrentVersion\Run] "wshost32"
Supprimé ! [HKLM\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\Run] "Microsoft Driver Setup"
Supprimé ! [HKLM\SYSTEM\CurrentControlSet\Services\AVPsys]
Supprimé ! [HKLM\SYSTEM\ControlSet001\Services\AVPsys]
Supprimé ! [HKLM\SYSTEM\ControlSet003\Services\AVPsys]
Supprimé ! [HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\taskmgr.exe]
################## | Registre # Mountpoints2 |
Supprimé ! HKCU\...\Explorer\MountPoints2\{0a3b59f0-7abc-11de-8f8c-00022ad8834f}\Shell\AutoRun\Command
Supprimé ! HKCU\...\Explorer\MountPoints2\{2a20a010-234b-11de-8e25-be946ad46225}\Shell\AutoRun\Command
Supprimé ! HKCU\...\Explorer\MountPoints2\{2a20a011-234b-11de-8e25-be946ad46225}\Shell\AutoRun\Command
Supprimé ! HKCU\...\Explorer\MountPoints2\{52e08da1-de2f-11dd-8d15-4d6564696130}\Shell\AutoRun\Command
Supprimé ! HKCU\...\Explorer\MountPoints2\{57bdebe5-38bf-11de-8e6d-00022ad8834f}\Shell\AutoRun\Command
Supprimé ! HKCU\...\Explorer\MountPoints2\{8cdb2740-d5a3-11dd-8cf5-4d6564696130}\Shell\AutoRun\Command
Supprimé ! HKCU\...\Explorer\MountPoints2\{a355e981-65ae-11de-8f18-00022ad8834f}\Shell\AutoRun\Command
Supprimé ! HKCU\...\Explorer\MountPoints2\{b39021f0-0b20-11de-8dc1-4d6564696130}\Shell\AutoRun\Command
Supprimé ! HKCU\...\Explorer\MountPoints2\{ccec5691-b5c8-11de-9084-00022ad8834f}\Shell\AutoRun\Command
Supprimé ! HKCU\...\Explorer\MountPoints2\{d9d1b4d0-9597-11de-8ff3-00022ad8834f}\Shell\AutoRun\Command
################## | Listing des fichiers présent |
[26/12/2008 11:53|--a------|0] C:\AUTOEXEC.BAT
[15/05/2009 09:42|---hs----|212] C:\boot.ini
[07/09/2002 01:00|-rahs----|4952] C:\Bootfont.bin
[26/12/2008 11:53|--a------|0] C:\CONFIG.SYS
[14/11/2009 10:09|--a------|3653] C:\FindyKill.txt
[?|?|?] C:\hiberfil.sys
[26/12/2008 11:53|-rahs----|0] C:\IO.SYS
[01/09/2009 14:31|--ah-----|307] C:\IPH.PH
[26/12/2008 11:53|-rahs----|0] C:\MSDOS.SYS
[04/08/2004 03:38|-rahs----|47564] C:\NTDETECT.COM
[04/08/2004 03:59|-rahs----|251712] C:\ntldr
[?|?|?] C:\pagefile.sys
[16/11/2009 15:10|--a------|15267] C:\UsbFix.txt
[?|?|?] D:\pagefile.sys
[20/02/2009 15:43|--ahs----|4096] D:\Thumbs.db
[14/11/2009 21:29|--a------|25600] G:\123456.doc
[09/11/2009 18:45|--a------|11630] G:\BOOTEX.LOG
[30/10/2009 00:22|--a------|29449] G:\tolphoto.jpg
[30/10/2009 00:57|--a------|20992] G:\Il ‚tait 5 heure du soir lorsque l.doc
[12/04/2009 15:33|--a------|1980624] G:\SDC15950.JPG
[11/10/2009 10:46|--a------|4890104] G:\Dicozip.exe
[14/08/2009 20:34|--a------|23] G:\key.txt
[09/10/2009 12:56|--a------|296] G:\WMPInfo.xml
[11/10/2009 12:36|--a------|6683956] G:\Pencil Sketching.pdf
[23/10/2009 00:58|--a------|18527244] G:\vlc-1.0.2-win32.exe
[05/10/2009 20:57|--a------|110] G:\keysss.txt
[09/11/2009 17:49|--a------|71680] G:\Emploi du Temps.doc
[08/10/2009 01:31|---h-----|34816] G:\~WRL0003.tmp
[23/09/2009 21:48|-rahs----|0] G:\Hi.doc .exe
[08/10/2009 01:31|---h-----|35328] G:\~WRL0005.tmp
[16/10/2009 00:23|--a------|1879207] G:\DSC05589.JPG
[12/04/2009 15:38|--a------|1985364] G:\SDC15951.JPG
[12/04/2009 15:38|--a------|1981342] G:\SDC15952.JPG
[31/10/2009 11:59|--a------|44640] G:\Lady-Gaga-performs-blood_l.jpg
[12/04/2009 15:38|--a------|1973904] G:\SDC15953.JPG
[12/04/2009 15:18|--a------|2002031] G:\SDC15947.JPG
[22/08/2009 18:33|--a------|31232] G:\Voici un petit condens‚ de tout ce que j.doc
[11/05/2009 14:01|---------|6394588] G:\chaba amel live.mp3
[23/08/2009 00:29|--a------|3346] G:\Document.rtf
[06/11/2009 18:25|--a------|2070864] G:\Cosplay 007.jpg
[05/10/2009 21:58|--a------|87] G:\conseil video.txt
[30/09/2009 10:57|--a------|495] G:\22.txt
[07/11/2009 21:05|--a------|12586] G:\www.AllSubs.org_1751-apocalypto-french-frana-ais-sous-titres-cd-fran_27361.zip
[19/10/2009 16:36|--a------|341402530] G:\Merlin.2x04.VOSTFR.Gillop.avi
[06/10/2009 23:22|--a------|321289] G:\50-conseils.pdf
[15/10/2009 21:35|--a------|36536] G:\19100436_jpg-r_760_x-f_jpg-q_x-20090505_111415.jpg
[21/12/2004 09:01|--a------|1896] G:\AUTOEXEC.NT
[23/09/2009 21:48|-rahs----|0] G:\Feeling inspired after reading Kalevala.doc .exe
[23/09/2009 23:17|-rahs----|0] G:\L.doc .exe
[11/10/2009 12:02|--a------|2425648] G:\microsoft-reader_microsoft_reader_v2.4.1_.exe_francais_36897.exe
[23/09/2009 21:48|-rahs----|0] G:\Everyone has a story to tell.doc .exe
[07/11/2009 10:07|--a------|18433] G:\Terra Media- The Best Medieval Chillout-2006 [yahaa.org].torrent
[25/09/2009 21:39|--a------|1808383] G:\Historiography in the Middle Ages (Brill).pdf
[25/09/2009 21:52|--a------|22930926] G:\An Encyclopedia of the Middle Ages.pdf
[11/10/2009 12:16|--a------|30935997] G:\Freehand Drawing Sketching.pdf
[15/10/2009 23:37|--a------|3816608] G:\MSReaderSetupFRA.exe
[25/09/2009 21:23|--a------|2700] G:\torrent2313 [mininova].torrent
[11/10/2009 12:07|--a------|13972994] G:\Master Lighting Guide for Portrait Photographers - C. Grey (2004) WW
[11/09/2009 00:39|--a------|30720] G:\what makes a good fantasy story.doc
[12/09/2009 15:11|--a------|2937104] G:\The Encyclopedia of Celtic Mythology and Folklore.pdf
[23/09/2009 23:19|-rahs----|0] G:\improving writing skills.doc .exe
[23/09/2009 23:19|-rahs----|0] G:\how to find a site to put stories on.doc .exe
[23/09/2009 23:19|-rahs----|0] G:\Getting Started in Fantasy Writing.doc .exe
[23/09/2009 23:19|-rahs----|0] G:\what makes a good fantasy story.doc .exe
[23/09/2009 23:19|-rahs----|0] G:\How tp write Fantasy.doc .exe
[23/09/2009 23:17|-rahs----|0] G:\1.doc .exe
[23/09/2009 23:17|-rahs----|0] G:\111.doc .exe
[23/09/2009 23:17|-rahs----|0] G:\11111.doc .exe
[23/09/2009 23:17|-rahs----|0] G:\CV.doc .exe
[23/09/2009 23:18|-rahs----|0] G:\CV2.doc .exe
[23/09/2009 23:18|-rahs----|0] G:\Bonjour.doc .exe
[23/09/2009 23:18|-rahs----|0] G:\http.doc .exe
[23/09/2009 23:18|-rahs----|0] G:\0123.doc .exe
[23/09/2009 23:18|-rahs----|0] G:\Pour ‚crire un bon roman.doc .exe
[23/09/2009 23:18|-rahs----|0] G:\Comment ‚crire un roman fantastique.doc .exe
[23/09/2009 23:18|-rahs----|0] G:\QUELQUES MODESTES CONSEILS D.doc .exe
[23/09/2009 23:18|-rahs----|0] G:\Voici un petit condens‚ de tout ce que j.doc .exe
[23/09/2009 23:18|-rahs----|0] G:\Idi ouvrit les yeux.doc .exe
[23/09/2009 23:18|-rahs----|0] G:\how to1.doc .exe
[23/09/2009 23:18|-rahs----|0] G:\Create a world.doc .exe
[23/09/2009 23:18|-rahs----|0] G:\There are lots of poor.doc .exe
################## | Vaccination |
# C:\autorun.inf -> Dossier créé par UsbFix.
# D:\autorun.inf -> Dossier créé par UsbFix.
# G:\autorun.inf -> Dossier créé par UsbFix.
################## | Suspect |
http://www.virustotal.com |
################## | Cracks / Keygens / Serials |
"C:\Documents and Settings\Moussa\Mes documents\Pix\Cracked Winxmedia ipod mp4 converter 2007\winxmedia ipod mp4 converter\winxmedia_ipod_mp4_converter.exe"
16/12/2008 21:22 |Size 74752 |Crc32 d1a938a8 |Md5 07772196be2217de71f11b398bf74460
"C:\Documents and Settings\Moussa\Mes documents\Pix\Cracked Winxmedia ipod mp4 converter 2007\winxmedia ipod mp4 converter\Crack\NFOReader.exe"
16/12/2008 21:22 |Size 49152 |Crc32 45f39880 |Md5 f8cf96ce67284203c422c3c29c583980
"C:\Downloads\Malwarebytes Anti-Malware 1.41 + Serial [1337x] [Ahmed]\Setup\mbam-setup.exe"
12/11/2009 00:09 |Size 4045528 |Crc32 b8109dda |Md5 866e72c78e98ca4919cd16724a3bd4c1
"C:\Downloads\Tun3Up Ut1l1t13s duemilanove\crack\TuneUp.Utilities.2009.v8.x.x-Crack.exe"
15/11/2009 23:00 |Size 634368 |Crc32 f0fd7c12 |Md5 f35671d9c2bb44487fd87b27fbd16bd6
"D:\Downloads\Internet Download Manager v5.16.3\Crack\IDMan.exe"
23/09/2009 22:32 |Size 2794928 |Crc32 664bd09b |Md5 26cff7f60a18e8d2a1f0166587279263
"D:\Downloads\Internet Download Manager v5.16.3\Crack\IDMGrHlp.exe"
23/09/2009 22:32 |Size 284344 |Crc32 0e658634 |Md5 71599911cb97e9874e2546efec0541f5
"D:\Downloads\Internet Download Manager v5.16.3\Crack\Uninstall.exe"
23/09/2009 22:45 |Size 140208 |Crc32 cde96532 |Md5 7b1a9dc2688dbc7302053b51f046e36c
"D:\Downloads\Internet.Download.Manager.v5.15.WinAll.Incl.Keygen-CRD\idman515.exe"
25/09/2009 11:29 |Size 2775187 |Crc32 2933b77e |Md5 b5c83376dec4f14c4e7b17d910c2cdf7
"D:\Downloads\Windows.Genuine.Advantage.Validation.v1.7.69.2.CRACKED-ETH0\WgaTray.exe"
25/09/2009 11:31 |Size 332672 |Crc32 6922c227 |Md5 68a0615cc80b45d021e371bc8a7c0f45
"D:\Program Files\Adobe\Adobe Photoshop CS2\keygen.exe"
24/09/2009 12:26 |Size 190976 |Crc32 1dd02df6 |Md5 a39522a0b8874c42eef9326c8b687fdf
"D:\Downloads\Internet Download Manager v5.16.3\Crack.zip"
Contain : Crack\IDMan.exe
################## | ! Fin du rapport # UsbFix V6.053 ! |
RSIT:
Logfile of random's system information tool 1.06 (written by random/random)
Run by Moussa at 2009-11-16 15:37:37
Microsoft Windows XP Professionnel Service Pack 2
System drive C: has 4 GB (45%) free of 10 GB
Total RAM: 319 MB (32% free)
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 15:37:45, on 16/11/2009
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Unable to get Internet Explorer version!
Boot mode: Normal
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\Program Files\Malwarebytes' Anti-Malware\mbamservice.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\wscntfy.exe
C:\WINDOWS\system32\wbem\wmiapsrv.exe
C:\WINDOWS\explorer.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Documents and Settings\Moussa\Bureau\RSIT.exe
C:\Program Files\trend micro\Moussa.exe
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar =
http://search.msn.fr/spbasic.htm
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page =
http://fr.msn.com/
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Windows Internet Explorer
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
R3 - URLSearchHook: (no name) - - (no file)
O2 - BHO: IDM Helper - {0055C089-8582-441B-A0BF-17B458C2A3A8} - D:\Downloads\Internet Download Manager v5.16.3\Crack\IDMIECC.dll
O2 - BHO: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre6\bin\ssv.dll
O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [NvMediaCenter] RunDLL32.exe NvMCTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [EPSON Stylus CX4900 Series English] C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_FATIBVP.EXE /FU "C:\WINDOWS\TEMP\E_SC1.tmp" /EF "HKLM"
O4 - HKLM\..\Run: [EPSON Stylus CX4900 Series] C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_FATIBVP.EXE /FU "C:\WINDOWS\TEMP\E_S13C.tmp" /EF "HKLM"
O4 - HKLM\..\Run: [Malwarebytes' Anti-Malware] "C:\Program Files\Malwarebytes' Anti-Malware\mbamgui.exe" /starttray
O4 - HKLM\..\Run: [Malwarebytes Anti-Malware (reboot)] "C:\Program Files\Malwarebytes' Anti-Malware\mbam.exe" /runcleanupscript
O4 - HKLM\..\Run: [Windows Update] C:\WINDOWS\system32\wuaucIt.exe
O4 - HKLM\..\Run: [] C:\WINDOWS\system32\.exe
O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\Windows Live\Messenger\MsnMsgr.Exe" /background
O4 - HKCU\..\Run: [uTorrent] "D:\Program Files\uTorrent\uTorrent.exe"
O4 - HKCU\..\Run: [DAEMON Tools Lite] "C:\Program Files\DAEMON Tools Lite\daemon.exe" -autorun
O4 - HKCU\..\Run: [IDMan] D:\Downloads\Internet Download Manager v5.16.3\Crack\IDMan.exe /onboot
O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVICE LOCAL')
O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVICE RÉSEAU')
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
O4 - Startup: Adobe Gamma.lnk = C:\Program Files\Fichiers communs\Adobe\Calibration\Adobe Gamma Loader.exe
O4 - Global Startup: DSLMON.lnk = ?
O8 - Extra context menu item: Télécharger avec IDM - D:\Downloads\Internet Download Manager v5.16.3\Crack\IEExt.htm
O8 - Extra context menu item: Télécharger le contenu de video FLV avec IDM - D:\Downloads\Internet Download Manager v5.16.3\Crack\IEGetVL.htm
O8 - Extra context menu item: Télécharger tous les liens avec IDM - D:\Downloads\Internet Download Manager v5.16.3\Crack\IEGetAll.htm
O9 - Extra button: (no name) - {85e1f530-48f4-11d9-9629-08ff2ffc9f67} - (no file)
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O17 - HKLM\System\CCS\Services\Tcpip\..\{451A9591-1BFD-4DED-B8A8-2CBD9CBC4738}: NameServer = 41.221.20.4 66.28.0.45
O23 - Service: Adobe LM Service - Adobe Systems - C:\Program Files\Fichiers communs\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Fichiers communs\InstallShield\Driver\1050\Intel 32\IDriverT.exe
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe
O23 - Service: MBAMService - Malwarebytes Corporation - C:\Program Files\Malwarebytes' Anti-Malware\mbamservice.exe