C'est fait. J'ai mis tous les périphériques de données que j'avais sous la main. Néanmoins, il m'en reste quelques-uns non testés qui se trouvent à mon boulot. Les clés usb, j'en ai également un certain nombre.
Mais j'ai mis celles que j'ai utilisées récemment.
############################## | UsbFix V6.055 |
User : Anne-Laure (Administrateurs) # PC-DE-ANNE-LAUR
Update on 18/11/2009 by Chiquitine29, C_XX & Chimay8
Start at: 19:44:50 | 20/11/2009
Website :
http://pagesperso-orange.fr/NosTools/index.html
Contact : FindyKill.Contact@gmail.com
Intel(R) Pentium(R) Dual CPU T2310 @ 1.46GHz
Microsoft® Windows Vista™ Édition Familiale Premium (6.0.6001 32-bit) # Service Pack 1
Internet Explorer 8.0.6001.18828
Windows Firewall Status : Enabled
AV : avast! antivirus 4.8.1351 [VPS 090830-0] 4.8.1351 [ Enabled | Updated ]
AV : Norton Internet Security 2007 [ Enabled | Updated ]
FW : Norton Internet Security[ Enabled ]2007
C:\ -> Disque fixe local # 141,59 Go (13,89 Go free) # NTFS
D:\ -> Disque fixe local # 7,46 Go (2,31 Go free) [HP_RECOVERY] # NTFS
E:\ -> Disque CD-ROM
F:\ -> Disque amovible # 989,22 Mo (585,86 Mo free) # FAT
H:\ -> Disque fixe local # 149,05 Go (17,25 Go free) [DDIomega] # NTFS
############################## | Processus actifs |
C:\Windows\System32\smss.exe 476
C:\Windows\system32\csrss.exe 612
C:\Windows\system32\wininit.exe 664
C:\Windows\system32\services.exe 712
C:\Windows\system32\lsass.exe 724
C:\Windows\system32\lsm.exe 732
C:\Windows\system32\svchost.exe 876
C:\Windows\system32\svchost.exe 952
C:\Windows\System32\svchost.exe 988
C:\Windows\System32\svchost.exe 1072
C:\Windows\System32\svchost.exe 1108
C:\Windows\system32\svchost.exe 1128
C:\Windows\system32\svchost.exe 1228
C:\Windows\system32\SLsvc.exe 1244
C:\Windows\system32\svchost.exe 1328
C:\Windows\system32\svchost.exe 1484
C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe 1684
C:\Program Files\Alwil Software\Avast4\ashServ.exe 1696
C:\Windows\System32\spoolsv.exe 1972
C:\Windows\system32\svchost.exe 2000
C:\Windows\system32\taskeng.exe 2200
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe 2292
C:\Program Files\Bonjour\mDNSResponder.exe 2304
C:\Program Files\HP\QuickPlay\Kernel\TV\CLCapSvc.exe 2316
C:\Program Files\Intel\Intel Matrix Storage Manager\IAANTMon.exe 2436
C:\Program Files\Common Files\LightScribe\LSSrvc.exe 2536
C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc.exe 2584
C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe 2636
C:\Windows\system32\svchost.exe 2704
C:\Windows\system32\svchost.exe 2740
C:\Windows\System32\svchost.exe 2772
C:\Windows\system32\SearchIndexer.exe 2816
C:\Program Files\Hewlett-Packard\Shared\hpqwmiex.exe 2912
C:\Windows\system32\SearchProtocolHost.exe 3700
C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe 2144
C:\Windows\system32\csrss.exe 2192
C:\Program Files\Alwil Software\Avast4\ashWebSv.exe 2232
C:\Windows\system32\winlogon.exe 1096
C:\Windows\system32\Dwm.exe 3392
C:\Windows\Explorer.EXE 3244
C:\Windows\system32\taskeng.exe 3040
C:\Program Files\Windows Defender\MSASCui.exe 3556
C:\Program Files\Motorola\SMSERIAL\sm56hlpr.exe 3344
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe 3328
C:\Windows\RtHDVCpl.exe 580
C:\Program Files\Intel\Intel Matrix Storage Manager\IAAnotif.exe 2176
C:\Program Files\Hewlett-Packard\HP Quick Launch Buttons\QLBCTRL.exe 3948
C:\Program Files\Hewlett-Packard\HP Wireless Assistant\HPWAMain.exe 1504
C:\Program Files\Hewlett-Packard\HP Wireless Assistant\WiFiMsg.exe 3976
C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc.exe 3964
C:\Program Files\Alwil Software\Avast4\ashDisp.exe 1716
C:\Windows\system32\wbem\wmiprvse.exe 1284
C:\Windows\System32\rundll32.exe 3868
C:\Program Files\HP\HP Software Update\hpwuSchd2.exe 1652
C:\Program Files\Java\jre6\bin\jusched.exe 1212
C:\Program Files\iTunes\iTunesHelper.exe 1032
C:\Program Files\Windows Sidebar\sidebar.exe 4052
C:\Program Files\Windows Live\Messenger\msnmsgr.exe 3824
C:\Program Files\Windows Media Player\wmpnscfg.exe 3180
C:\Windows\System32\rundll32.exe 3676
C:\Windows\system32\wbem\unsecapp.exe 3808
C:\Program Files\Windows Media Player\wmpnetwk.exe 1476
C:\Program Files\Hewlett-Packard\Shared\HpqToaster.exe 2040
C:\Program Files\Mozilla Firefox\firefox.exe 4044
C:\Program Files\iPod\bin\iPodService.exe 2268
C:\Program Files\Hewlett-Packard\HP Health Check\hphc_service.exe 4336
C:\Windows\system32\wuauclt.exe 5624
C:\Program Files\Malwarebytes' Anti-Malware\mbam.exe 5264
C:\Windows\system32\conime.exe 4480
C:\Windows\system32\SearchFilterHost.exe 5852
C:\Windows\system32\WUDFHost.exe 3952
\\?\C:\Windows\system32\wbem\WMIADAP.EXE 5512
C:\Windows\system32\wbem\wmiprvse.exe 4844
################## | Fichiers # Dossiers infectieux |
################## | Registre # Clés infectieuses |
################## | Registre # Mountpoints2 |
HKCU\..\..\Explorer\MountPoints2\G
shell\AutoRun\command =G:\LaunchU3.exe -a
HKCU\..\..\Explorer\MountPoints2\{17668fff-d353-11dc-abe2-001b2495af88}
shell\Auto\command =UFO.exe
shell\AutoRun\command =C:\Windows\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL UFO.exe
HKCU\..\..\Explorer\MountPoints2\{17669004-d353-11dc-abe2-001b2495af88}
shell\AutoRun\command =G:\LaunchU3.exe -a
HKCU\..\..\Explorer\MountPoints2\{1ae97c4e-51c9-11dd-9ea7-001b2495af88}
shell\Auto\command =UFO.exe
shell\AutoRun\command =C:\Windows\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL UFO.exe
HKCU\..\..\Explorer\MountPoints2\{1ae97c6e-51c9-11dd-9ea7-001b2495af88}
shell\AutoRun\command =xp19.com
shell\explore\Command =xp19.com
shell\open\Command =xp19.com
HKCU\..\..\Explorer\MountPoints2\{2d12b24d-99d8-11dc-b702-001b2495af88}
shell\AutoRun\command =F:\LaunchU3.exe -a
HKCU\..\..\Explorer\MountPoints2\{32e9192b-93a0-11dc-ba54-001b2495af88}
shell\AutoRun\command =F:\LaunchU3.exe -a
HKCU\..\..\Explorer\MountPoints2\{8077ea10-bec0-11dc-8134-99a5fa5e2aa7}
shell\Auto\command =F:\UFO.exe
shell\AutoRun\command =C:\Windows\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL F:\UFO.exe
HKCU\..\..\Explorer\MountPoints2\{8077ea13-bec0-11dc-8134-99a5fa5e2aa7}
shell\AutoRun\command =G:\LaunchU3.exe -a
HKCU\..\..\Explorer\MountPoints2\{9e2870f0-ba36-11de-8246-001b2495af88}
shell\AutoRun\command =G:\egu2009win.exe
HKCU\..\..\Explorer\MountPoints2\{a1496738-0a12-11dd-b0d0-001b2495af88}
shell\Auto\command =UFO.exe
shell\AutoRun\command =C:\Windows\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL UFO.exe
HKCU\..\..\Explorer\MountPoints2\{b92dd635-c01e-11dc-87b7-001b2495af88}
shell\Auto\command =F:\UFO.exe
shell\AutoRun\command =C:\Windows\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL F:\UFO.exe
HKCU\..\..\Explorer\MountPoints2\{d28db6c4-cf22-11dc-ac30-001b2495af88}
shell\AutoRun\command =F:\qd.cmd
shell\explore\Command =F:\qd.cmd
shell\open\Command =F:\qd.cmd
HKCU\..\..\Explorer\MountPoints2\{d28db6ea-cf22-11dc-ac30-89682af5a9ea}
shell\AutoRun\command =F:\awda2.exe
shell\explore\Command =F:\awda2.exe
shell\open\Command =F:\awda2.exe
HKCU\..\..\Explorer\MountPoints2\{ff66dde1-b95d-11dc-a6e6-001b2495af88}
shell\Auto\command =F:\UFO.exe
shell\AutoRun\command =C:\Windows\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL F:\UFO.exe
################## | Cracks / Keygens / Serials |
"C:\Program Files\Motorola\SMSERIAL\sm56hlpr.exe"
09/10/2006 21:43 |Size 729088 |Crc32 442f9639 |Md5 04870a30820f902aab828317c3b5e897
################## | ! Fin du rapport # UsbFix V6.055 ! |