Encore une infection!

Résolu
Bonjour à tous les dieux de la désinfect du site,

Une fois de plus je m'en remet à votre grande expertise et bonté pour m'aider dans la désinfection de cette machine.

voici un zhpdiag

https://www.cjoint.com/?BBkpOHst1Ai

bonne journée à vous.merci

89 réponses

Résumé de la discussion

La discussion porte sur la désinfection d'une machine sous Windows Vista confrontée à un rootkit TDSS et à des éléments de persistance après une infection, avec l'utilisation de TDSSKiller et de ComboFix. Des outils dédiés ont été employés, dont TDSSKiller pour débusquer le rootkit TDSS et ComboFix pour nettoyer les infections détectées, avec des rapports détaillés listant les fichiers et les processus modifiés. En pratique, le journal des analyses rapporte des suppressions et remplacements de fichiers, des éléments de démarrage modifiés et des pilotes infectés restaurés, avec des détails techniques. En dernier lieu, les journaux indiquent que des éléments critiques du système ont été restaurés ou supprimés, et que des outils spécialisés nécessitent parfois redémarrages pour stabiliser la machine.

Bobot (l’IA à votre service)
  1. salut quelle horreur !!!!

    j'ai jamais vu un pc aussi infecté

    telecharge et enregistre ceci sur ton bureau :

    Pre_Scan

    Avertissement: tous les processus non-vitaux de windows seront coupés --> pas de panique.

    une fois telechargé lance-le , laisse faire le scan jusqu'à l'apparition du rapport sur le bureau.

    si 'outil est bloqué par l'infection utilise cette version : Version .pif

    ou encore cette version renommée : Winlogon.exe

    si l'outil detecte un proxy et que tu n'en as pas installé clique sur "supprimer le proxy"

    Il se peut qu'une multitude de fenêtres noires clignotent , laisse-le travailler

    Si l'outil ouvre une fenetre "Lecteurs virtuels" , fais exactement ce qui est indiqué dans cettte fenetre

    Poste Pre_Scan_la_date_et_l'heure.txt qui apparaitra sur le bureau en fin de scan après redemarrage

    ▶▶▶ NE LE POSTE PAS SUR LE FORUM (il est trop long)

    heberge le rapport sur http://pjjoint.malekal.com et donne le lien obtenu
    ¤¤¤¤¤¤¤¤¤¤_g3n-h@ckm@n_Developpement_¤¤¤¤¤¤¤¤¤¤
    ¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤
    _Pre_Scan_¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤
    0
    1. j'ai lancé et ça met beaucoup de temps; j'ai arreté, en me disant qu'il ya anormalité quelque part. est ce le cas?
      0
      1. chez moi le scan dure 4 mn sur tous les OS...

        à quel endroit bloquait-til ?
        0
        1. il a fait tout le registre, et puis il bloque à suppression T*** j'ai oublié le mot.
          0
          1. enfin, il a avancé jusqu'à environ 20% et puis il avançait plus.
            0
        2. pas etonnant remarque avec tout ce qu il y a la dedans...il a du etre corrompu


          /!\ ATTENTION SUIVRE A LA LETTRE CES INDICATIONS/!\

          __________________________________________________________
          >Ce logiciel n'est à utiliser que prescrit par un helper qualifié et formé à l'outil.<
          >>>>>>>Ne pas utiliser en dehors de ce cas de figure : dangereux!<<<<<<<<
          =====================================================


          ▶ Surtout , pense à l'enregistrement à renommer Combofix en "ton prenom.exe" avant qu'il soit enregistré sur ton disque dur

          Telecharge ici : Combofix

          Avant d'utiliser ComboFix :

          Si tu utilises AVG, IL FAUT IMPERATIVEMENT LE DESINSTALLER avant d'utiliser Combofix car il peut causer des dégâts en interaction avec l'outil pouvant mener à la réinstallation totale du système.
          La simple désactivation du résident n'est pas suffisante.
          Télécharge le désinstalleur d'AVG sur ce lien : https://www.avg.com/fr-fr/avg-remover
          Choisis la version adéquate (32 ou 64 bits)/!\

          Les logiciels d'émulation de CD comme Daemon Tools peuvent gêner les outils de désinfection. Utilise Defogger pour les désactiver temporairement :

          ▶ Télécharge Defogger (de jpshortstuff) sur ton Bureau

          ▶ Lance le

          Une fenêtre apparait : clique sur "Disable"

          ▶ Fais redémarrer l'ordinateur si l'outil te le demande

          Note : Quand nous aurons terminé la désinfection, tu pourras réactiver ces logiciels en relançant Defogger et en cliquant sur "Re-enable"

          _________________________________________________________
          >> referme les fenêtres de tous les programmes en cours.
          >> Désactive provisoirement et seulement le temps de l'utilisation de ComboFix,
          >>la protection en temps réel de ton Antivirus et de tes Antispywares,
          >>qui peuvent gêner fortement la procédure de recherche et de nettoyage de l'outil.

          °°°°°°°°°°°°°°°°°°°°°°°°°°°°°°°°°°°°°°°°°°°°°°°°°°°°°°°°°°°°°°°°°°°°°°°°°°°


          si tu as XP => double clique
          si tu as Vista ou windows 7 => clic droit "executer en tant que...."


          sur combofix renommé

          ¤¤¤¤¤¤¤¤¤¤ LAISSE-LE INSTALLER LA CONSOLE DE RECUPERATION S'IL TE LE DEMANDE ¤¤¤¤¤¤¤¤¤¤

          ▶ !!!!!NE TOUCHE A RIEN PENDANT LE TRAVAIL DE COMBOFIX (SOURIS/CLAVIER.....)!!!!!

          ▶ n'oublie pas de reactiver la garde de ton Antivirus et de tes Antispywares, avant de te reconnecter à internet.

          ▶▶ Reviens sur le forum, et copie et colle la totalité du contenu de C:\Combofix.txt dans ton prochain message.

          0
          1. j'ai telecargé et il me fait une erreur au lancement quelque chose nsis.error.

            je retelecharge sur une autre machine avant d'importer sur celle ci pour voir
            0
            1. grave!!

              dès que je branche la clé qui contient combofix, les virus le supprime tout de suite
              0
              1. Ce que j'ai fait :
                j'ai renommé en un fichier sans extension (les virus l'ont pas vu venir)
                je lai copié sur le bureau
                renommé en .exe
                et executé!!

                il s'est lancé, j'attends
                0
                1. ne remets pas ta clé dans l autre pc apres celui-ci car tu vas infecter l autre pc
                  0
                  1. ouuuchh!! je l'ai fait.

                    Mais il y a AVG, ça infecte tout de meme?
                    0
                    1. avg ne vaut rien...

                      je pense que tu vas etre mal....

                      que dit combofix ?
                      0
                      1. La machine est restée au bureau. là je suis déjà retourné à la maison. je continue avec combofix le matin, mais déjà il arretait pas de signaler la présence d'un rootkit, puis la machine a redemarré. j'ai pas vu de rapport.

                        ça m'intrigue énormément quand tu me dis qu'AVG ne vaut rien, ça veut dire que cet ordi sur lequel j'ai fais l'échange de clé est infecté!

                        déjà je dois procéder à sa désinfection?

                        Que me conseille tu de bon à la place d'AVG ( je le trouve trop lourd déjà avec ses mises à jours qui me bouffent tout l'espace)
                        0
                        1. fais deja ca sur tes deux pc

                          ▶ Téléchargez UsbFix (créé par El Desaparecido) sur votre Bureau.

                          ▶ Si votre antivirus affiche une alerte, ignorez-la et désactivez l'antivirus temporairement.
                          Branchez toutes vos sources de données externes à votre PC (clé USB, disque dur externe, etc...) sans les ouvrir.
                          ▶ Double cliquez sur UsbFix.exe.

                          ▶ Cliquez sur Suppression.
                          ▶ Laissez travailler l'outil.

                          ▶ À la fin du scan, un rapport va s'afficher, postez-le dans votre prochaine réponse sur le forum.

                          ▶ Le rapport est aussi sauvegardé à la racine du disque système ( C:\UsbFix.txt ).
                          Tutoriel vidéo

                          0
                          1. BOnjour genhackman,

                            J'ai passé usbfix sur cette machine (celle de la maison) dont voici le log en dessous. je continue avec la machine du bureau tout à l'heure quand j'y retourne.

                            Est ce que tu penses qu'avec teamviewer je peut faire la désinfection à distance?

                            QU'en est il pour AVG? que me coneilles tu à la place?

                            PS: usbfix a mis beaucoup de temps pour s'exécuter, AVG signalait comme dangeureux. j'ai pas pu arrêter avg avant.

                            ############################## | UsbFix V 7.081 | [Suppression]

                            Utilisateur: KAMMI (Administrateur) # MASTEL
                            Mis à jour le 05/02/2012 par El Desaparecido
                            Lancé à 00:03:35 | 10/01/2006

                            Site Web: https://www.sosvirus.net/
                            Fichier suspect ? : http://eldesaparecido.com/upload.html
                            Contact: contact@eldesaparecido.com

                            PC: Acer (TravelMate 4320 ) (X86-based PC) # Notebook
                            CPU: Processeur Intel Pentium II (1729)
                            RAM -> [ Total : 1014 | Free : 418 ]
                            BIOS: Ver 1.00PARTTBL
                            BOOT: Normal boot

                            OS: Microsoft Windows XP Professionnel (5.1.2600 32-Bit) # Service Pack 3
                            WB: Windows Internet Explorer 6.0.2900.5512

                            SC: Security Center Service [ Enabled ]
                            WU: Windows Update Service [ Enabled ]
                            FW: Windows FireWall Service [ Enabled ]

                            C:\ (%systemdrive%) -> Disque fixe # 34 Go (3 Go libre(s) - 8%) [] # NTFS
                            D:\ -> CD-ROM
                            E:\ -> Disque fixe # 35 Go (668 Mo libre(s) - 2%) [ACERDATA] # FAT32
                            F:\ -> CD-ROM
                            G:\ -> Disque fixe # 59 Go (23 Go libre(s) - 40%) [DISK THIERR] # FAT32
                            H:\ -> Disque fixe # 932 Go (444 Go libre(s) - 48%) [FreeAgent GoFlex Drive] # NTFS
                            I:\ -> Disque fixe # 40 Go (11 Go libre(s) - 27%) [DATA2] # NTFS
                            K:\ -> Disque fixe # 50 Go (5 Go libre(s) - 9%) [DATA3] # NTFS

                            ################## | Processus Actif |

                            C:\WINDOWS\System32\smss.exe (876)
                            C:\PROGRA~1\AVG\AVG2012\avgrsx.exe (932)
                            C:\Program Files\AVG\AVG2012\avgcsrvx.exe (964)
                            C:\WINDOWS\system32\csrss.exe (1200)
                            C:\WINDOWS\system32\winlogon.exe (1232)
                            C:\WINDOWS\system32\services.exe (1284)
                            C:\WINDOWS\system32\lsass.exe (1296)
                            C:\WINDOWS\system32\svchost.exe (1460)
                            C:\WINDOWS\system32\svchost.exe (1536)
                            C:\WINDOWS\System32\svchost.exe (1680)
                            C:\WINDOWS\system32\svchost.exe (1716)
                            C:\WINDOWS\system32\svchost.exe (1928)
                            C:\WINDOWS\system32\svchost.exe (156)
                            C:\WINDOWS\system32\spoolsv.exe (632)
                            C:\WINDOWS\Explorer.EXE (1208)
                            C:\WINDOWS\system32\svchost.exe (1904)
                            C:\WINDOWS\system32\agrsmsvc.exe (1936)
                            C:\Program Files\Fichiers communs\Apple\Mobile Device Support\AppleMobileDeviceService.exe (1956)
                            C:\Program Files\AVG\AVG2012\avgwdsvc.exe (1976)
                            C:\Program Files\Bonjour\mDNSResponder.exe (2012)
                            C:\WINDOWS\RTHDCPL.EXE (224)
                            C:\WINDOWS\system32\igfxtray.exe (756)
                            C:\WINDOWS\system32\hkcmd.exe (808)
                            C:\Program Files\Java\jre6\bin\jqs.exe (816)
                            C:\WINDOWS\system32\igfxpers.exe (848)
                            C:\Program Files\Java\jre6\bin\jusched.exe (892)
                            C:\WINDOWS\system32\igfxsrvc.exe (1768)
                            C:\Program Files\Malwarebytes' Anti-Malware\mbamservice.exe (1364)
                            C:\Program Files\iTunes\iTunesHelper.exe (1968)
                            C:\Program Files\Synaptics\SynTP\SynTPEnh.exe (452)
                            C:\Program Files\USB Disk Security\USBGuard.exe (1340)
                            C:\Program Files\AVG\AVG2012\avgtray.exe (916)
                            C:\WINDOWS\system32\svchost.exe (708)
                            C:\Program Files\AVG Secure Search\vprot.exe (1484)
                            C:\Program Files\AVG\AVG2012\avgnsx.exe (1760)
                            C:\Program Files\NEC Electronics\USB 3.0 Host Controller Driver\Application\nusb3mon.exe (2220)
                            C:\Program Files\AVG Secure Search\ROC_roc_dec12.exe (2524)
                            C:\Program Files\TeamViewer\Version7\TeamViewer_Service.exe (2588)
                            C:\Program Files\Fichiers communs\AVG Secure Search\vToolbarUpdater\10.0.6\ToolbarUpdater.exe (2716)
                            C:\WINDOWS\system32\ctfmon.exe (2720)
                            C:\Program Files\SuperCopier2\SuperCopier2.exe (2948)
                            C:\Program Files\AVG\AVG2012\AVGIDSAgent.exe (2960)
                            C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe (3004)
                            C:\WINDOWS\system32\wuauclt.exe (3176)
                            C:\Program Files\Internet Download Manager\IDMan.exe (3184)
                            C:\Documents and Settings\KAMMI\Local Settings\Application Data\Google\Update\GoogleUpdate.exe (3496)
                            C:\Program Files\Fichiers communs\Ahead\lib\NMBgMonitor.exe (3812)
                            C:\Program Files\Messenger\msmsgs.exe (3916)
                            C:\Program Files\Micro Application\38 Dictionnaires et Recueils de Correspondance\MediaDICO38.EXE (4048)
                            C:\WINDOWS\system32\wscntfy.exe (272)
                            C:\Program Files\Nokia\Nokia Suite\NokiaSuite.exe (844)
                            C:\Program Files\Micro Application\38 Dictionnaires et Recueils de Correspondance\Rac38.EXE (2276)
                            C:\Program Files\A Note\A Note.exe (2576)
                            C:\WINDOWS\System32\alg.exe (2864)
                            C:\Program Files\TeamViewer\Version7\TeamViewer.exe (3168)
                            C:\WINDOWS\system32\wbem\wmiprvse.exe (4068)
                            C:\Program Files\iPod\bin\iPodService.exe (2068)
                            C:\DOCUME~1\KAMMI\LOCALS~1\Temp\RtkBtMnt.exe (3120)
                            C:\WINDOWS\system32\wbem\wmiapsrv.exe (2272)
                            C:\WINDOWS\system32\wbem\wmiprvse.exe (1436)
                            C:\Program Files\Internet Download Manager\IEMonitor.exe (1132)
                            C:\UsbFix\Go.exe (3700)
                            C:\Program Files\TeamViewer\Version7\tv_w32.exe (2996)
                            C:\Program Files\Fichiers communs\AVG Secure Search\ScriptHelperInstaller\10.0.6\ScriptHelper.exe (1700)

                            ################## | Processus Stoppés |

                            Stoppé! C:\PROGRA~1\AVG\AVG2012\avgrsx.exe (932)
                            Stoppé! C:\Program Files\AVG\AVG2012\avgcsrvx.exe (964)
                            Stoppé! C:\WINDOWS\system32\spoolsv.exe (632)
                            Stoppé! C:\WINDOWS\Explorer.EXE (1208)
                            Stoppé! C:\WINDOWS\system32\agrsmsvc.exe (1936)
                            Stoppé! C:\Program Files\Fichiers communs\Apple\Mobile Device Support\AppleMobileDeviceService.exe (1956)
                            Stoppé! C:\Program Files\AVG\AVG2012\avgwdsvc.exe (1976)
                            Stoppé! C:\Program Files\Bonjour\mDNSResponder.exe (2012)
                            Stoppé! C:\WINDOWS\RTHDCPL.EXE (224)
                            Stoppé! C:\WINDOWS\system32\igfxtray.exe (756)
                            Stoppé! C:\WINDOWS\system32\hkcmd.exe (808)
                            Stoppé! C:\Program Files\Java\jre6\bin\jqs.exe (816)
                            Stoppé! C:\WINDOWS\system32\igfxpers.exe (848)
                            Stoppé! C:\Program Files\Java\jre6\bin\jusched.exe (892)
                            Stoppé! C:\WINDOWS\system32\igfxsrvc.exe (1768)
                            Stoppé! C:\Program Files\Malwarebytes' Anti-Malware\mbamservice.exe (1364)
                            Stoppé! C:\Program Files\iTunes\iTunesHelper.exe (1968)
                            Stoppé! C:\Program Files\Synaptics\SynTP\SynTPEnh.exe (452)
                            Stoppé! C:\Program Files\USB Disk Security\USBGuard.exe (1340)
                            Stoppé! C:\Program Files\AVG\AVG2012\avgtray.exe (916)
                            Stoppé! C:\Program Files\AVG Secure Search\vprot.exe (1484)
                            Stoppé! C:\Program Files\AVG\AVG2012\avgnsx.exe (1760)
                            Stoppé! C:\Program Files\NEC Electronics\USB 3.0 Host Controller Driver\Application\nusb3mon.exe (2220)
                            Stoppé! C:\Program Files\AVG Secure Search\ROC_roc_dec12.exe (2524)
                            Stoppé! C:\Program Files\TeamViewer\Version7\TeamViewer_Service.exe (2588)
                            Stoppé! C:\Program Files\Fichiers communs\AVG Secure Search\vToolbarUpdater\10.0.6\ToolbarUpdater.exe (2716)
                            Stoppé! C:\WINDOWS\system32\ctfmon.exe (2720)
                            Stoppé! C:\Program Files\SuperCopier2\SuperCopier2.exe (2948)
                            Stoppé! C:\Program Files\AVG\AVG2012\AVGIDSAgent.exe (2960)
                            Stoppé! C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe (3004)
                            Stoppé! C:\WINDOWS\system32\wuauclt.exe (3176)
                            Stoppé! C:\Program Files\Internet Download Manager\IDMan.exe (3184)
                            Stoppé! C:\Documents and Settings\KAMMI\Local Settings\Application Data\Google\Update\GoogleUpdate.exe (3496)
                            Stoppé! C:\Program Files\Fichiers communs\Ahead\lib\NMBgMonitor.exe (3812)
                            Stoppé! C:\Program Files\Messenger\msmsgs.exe (3916)
                            Stoppé! C:\Program Files\Micro Application\38 Dictionnaires et Recueils de Correspondance\MediaDICO38.EXE (4048)
                            Stoppé! C:\WINDOWS\system32\wscntfy.exe (272)
                            Stoppé! C:\Program Files\Nokia\Nokia Suite\NokiaSuite.exe (844)
                            Stoppé! C:\Program Files\Micro Application\38 Dictionnaires et Recueils de Correspondance\Rac38.EXE (2276)
                            Stoppé! C:\Program Files\A Note\A Note.exe (2576)
                            Stoppé! C:\WINDOWS\System32\alg.exe (2864)
                            Stoppé! C:\Program Files\TeamViewer\Version7\TeamViewer.exe (3168)
                            Stoppé! C:\Program Files\iPod\bin\iPodService.exe (2068)
                            Stoppé! C:\DOCUME~1\KAMMI\LOCALS~1\Temp\RtkBtMnt.exe (3120)
                            Stoppé! C:\WINDOWS\system32\wbem\wmiapsrv.exe (2272)
                            Stoppé! C:\Program Files\Internet Download Manager\IEMonitor.exe (1132)
                            Stoppé! C:\Program Files\TeamViewer\Version7\tv_w32.exe (2996)
                            Stoppé! C:\Program Files\Fichiers communs\AVG Secure Search\ScriptHelperInstaller\10.0.6\ScriptHelper.exe (1700)
                            Stoppé! C:\Program Files\PC Connectivity Solution\ServiceLayer.exe (1244)
                            Stoppé! C:\Program Files\PC Connectivity Solution\Transports\NclUSBSrv.exe (3568)

                            ################## | Éléments infectieux |

                            Supprimé! C:\Recycler\S-1-5-21-436374069-1532298954-839522115-1003
                            Supprimé! G:\Recycler\S-5-3-42-2819952290-8240758988-879315005-3665\jwgkvsq.vmx
                            Supprimé! G:\Recycler\S-5-3-42-2819952290-8240758988-879315005-3665
                            Supprimé! H:\$RECYCLE.BIN\S-1-5-21-441455308-3259083724-4074586437-1000
                            Supprimé! H:\$RECYCLE.BIN\S-1-5-21-903822699-2371328969-740899043-1000
                            Supprimé! H:\Recycler\S-1-5-21-1202660629-1454471165-725345543-1003
                            Supprimé! H:\Recycler\S-1-5-21-436374069-1532298954-839522115-1003
                            Supprimé! I:\Recycler\S-1-5-21-436374069-1532298954-839522115-1003
                            Supprimé! K:\$RECYCLE.BIN\S-1-5-21-1209201674-4029264647-1254799989-1003
                            Supprimé! K:\$RECYCLE.BIN\S-1-5-21-1209207280-2693176973-192453593-1000
                            Supprimé! K:\$RECYCLE.BIN\S-1-5-21-1935032933-800376547-710726222-1000
                            Supprimé! K:\$RECYCLE.BIN\S-1-5-21-2446727837-2109171694-2412804598-1000
                            Supprimé! K:\$RECYCLE.BIN\S-1-5-21-2845897591-4242094509-1808894660-1000
                            Supprimé! K:\$RECYCLE.BIN\S-1-5-21-3610086551-1814595220-2476699251-1000
                            Supprimé! K:\$RECYCLE.BIN\S-1-5-21-759196459-2095686694-3291775682-1000
                            Supprimé! K:\Recycler\S-1-5-21-1060284298-1500820517-682003330-1003
                            Supprimé! K:\Recycler\S-1-5-21-1202660629-1454471165-725345543-1003
                            Supprimé! K:\Recycler\S-1-5-21-3814263335-1044751954-3476302778-1009
                            Supprimé! K:\Recycler\S-1-5-21-436374069-1532298954-839522115-1003
                            Non supprimé ! K:\Recycler\S-5-3-42-2819952290-8240758988-879315005-3665\jwgkvsq.vmx
                            Non supprimé ! K:\Recycler\S-5-3-42-2819952290-8240758988-879315005-3665

                            (!) Fichiers temporaires supprimés.

                            ################## | Registre |

                            ################## | Mountpoints2 |

                            Supprimé! HKCU\.\.\.\.\Explorer\MountPoints2\G
                            Supprimé! HKCU\.\.\.\.\Explorer\MountPoints2\{95f97cfc-2cf3-11e1-8637-001e4c0a95b0}

                            ################## | Listing |

                            [07/11/2011 - 00:13:19 | D ] C:\$AVG
                            [31/10/2011 - 23:00:40 | D ] C:\acer travelmate 4320
                            [31/10/2011 - 21:29:35 | N | 0] C:\AUTOEXEC.BAT
                            [09/11/2011 - 22:12:28 | D ] C:\Classical Music Top 100
                            [16/01/2012 - 01:48:05 | N | 29872] C:\comité exécutif camimun.jpg
                            [31/10/2011 - 21:29:35 | N | 0] C:\CONFIG.SYS
                            [12/01/2012 - 02:31:22 | D ] C:\CPCGLOBE
                            [26/01/2012 - 06:40:41 | N | 1969] C:\DelFix[S1].txt
                            [31/10/2011 - 23:41:17 | D ] C:\DHO
                            [31/10/2011 - 23:09:17 | D ] C:\Documents and Settings
                            [01/01/2012 - 05:12:21 | N | 157774] C:\DSCN1024.JPG
                            [31/10/2011 - 22:49:52 | D ] C:\Intel
                            [31/10/2011 - 21:29:35 | N | 0] C:\IO.SYS
                            [10/01/2006 - 00:10:37 | N | 1483] C:\LISTING.TXT
                            [01/11/2011 - 21:16:45 | N | 13582] C:\Login et Mot de Passe.docx
                            [07/02/2012 - 07:27:55 | D ] C:\Lyrics
                            [25/01/2012 - 13:24:02 | D ] C:\messanga
                            [31/10/2011 - 21:29:35 | N | 0] C:\MSDOS.SYS
                            [31/10/2011 - 23:23:09 | RHD ] C:\MSOCache
                            [23/01/2012 - 18:27:00 | N | 227696] C:\PA280154.JPG
                            [10/01/2006 - 00:01:02 | ASH | 1598029824] C:\pagefile.sys
                            [01/11/2011 - 20:50:16 | D ] C:\photos
                            [10/01/2006 - 00:14:07 | N | 1241] C:\PL_A001.$$$
                            [23/01/2012 - 18:28:29 | N | 6899] C:\portrait kammi.JPG
                            [08/02/2012 - 00:17:08 | N | 14286] C:\poste à pourvoir camimun (Copie de Thierry KAMMI en conflit 2012-01-13).xlsx
                            [09/02/2012 - 00:08:46 | D ] C:\Program Files
                            [10/01/2006 - 00:20:47 | SHD ] C:\RECYCLER
                            [07/09/2011 - 03:10:45 | N | 2774272] C:\rmparite.exe
                            [31/10/2011 - 23:33:11 | D ] C:\swsetup
                            [31/10/2011 - 22:09:26 | SHD ] C:\System Volume Information
                            [16/01/2012 - 01:48:23 | N | 24171] C:\séance travail.jpg
                            [25/01/2012 - 01:32:32 | ASH | 49152] C:\Thumbs.db
                            [10/12/2011 - 21:45:50 | D ] C:\TMP
                            [10/01/2006 - 00:20:50 | D ] C:\UsbFix
                            [10/01/2006 - 00:20:50 | A | 9610] C:\UsbFix.txt
                            [06/02/2012 - 20:43:26 | D ] C:\WINDOWS
                            [04/10/2010 - 17:03:08 | D ] E:\topho
                            [22/10/2008 - 17:32:44 | SHD ] E:\System Volume Information
                            [09/03/2010 - 15:45:44 | N | 10090635] E:\TC.rar
                            [21/01/2006 - 01:00:18 | RASHD ] E:\Autorun.inf
                            [10/01/2006 - 00:47:52 | D ] E:\$AVG
                            [21/11/2008 - 09:57:16 | N | 69632] E:\LE MODÈLE ACTANTIEL.doc
                            [04/10/2010 - 17:04:16 | D ] E:\JEUX
                            [10/01/2006 - 01:06:40 | D ] E:\tumba la madiba volume 1
                            [23/04/2011 - 00:38:42 | D ] E:\Pièces
                            [01/11/2011 - 00:29:48 | N | 252240] E:\ntldr
                            [03/08/2004 - 21:38:34 | N | 47564] E:\NTDETECT.COM
                            [31/10/2011 - 21:10:20 | N | 211] E:\boot.ini
                            [04/06/2009 - 04:47:22 | D ] E:\Xilisoft
                            [10/02/2009 - 09:37:52 | D ] E:\500 National Geographic Wallpapers
                            [28/07/2011 - 01:51:24 | D ] E:\Mes sélections
                            [18/09/2011 - 12:48:04 | D ] E:\bord ezanga kombo
                            [28/09/2001 - 12:00:00 | N | 4952] E:\Bootfont.bin
                            [08/11/2011 - 16:25:42 | SHD ] E:\Recycled
                            [26/06/2008 - 17:48:44 | D ] E:\Jean de La Fontaine - Fables (Compilation)
                            [23/11/2008 - 14:44:14 | D ] E:\vIDEO
                            [19/09/2011 - 08:09:30 | D ] E:\MUSIQUE
                            [01/02/2009 - 18:43:06 | D ] E:\culture NTIC
                            [27/09/2010 - 22:47:02 | ASH | 52224] E:\Thumbs.db
                            [12/06/2007 - 18:42:58 | D ] E:\TC
                            [19/04/2000 - 11:57:10 | R | 79509064] F:\ABSTRACT.DAT
                            [09/05/2000 - 23:45:32 | R | 25102340] F:\ALLTEXTS.DAT
                            [11/05/2000 - 11:14:43 | RD ] F:\BACKGRND
                            [11/05/2000 - 11:14:45 | RD ] F:\CABIKEY
                            [13/04/2000 - 20:45:16 | R | 17408] F:\COUNTRY.CDX
                            [10/05/2000 - 16:54:08 | R | 178955] F:\COUNTRY.DBF
                            [10/05/2000 - 16:07:16 | R | 4399267] F:\COVER.DAT
                            [29/03/2000 - 09:20:12 | R | 10] F:\CPC_3_00.ID
                            [10/05/2000 - 11:05:02 | R | 2443573] F:\CPC_TOUR.DMR
                            [04/05/2000 - 16:46:46 | R | 248731] F:\CTRY_DAT.DAT
                            [09/05/2000 - 23:43:28 | R | 912086] F:\CTRY_OCC.DAT
                            [11/05/2000 - 11:14:54 | RD ] F:\DIPTKEY
                            [11/05/2000 - 11:15:42 | R | 5] F:\DISK1.ID
                            [03/03/2000 - 16:57:52 | R | 13312] F:\FAO_CONS.CDX
                            [03/03/2000 - 16:57:50 | R | 235142] F:\FAO_CONS.DBF
                            [10/05/2000 - 12:26:44 | R | 15872] F:\FAO_LAND.CDX
                            [10/05/2000 - 12:26:44 | R | 368147] F:\FAO_LAND.DBF
                            [10/05/2000 - 12:26:28 | R | 1204224] F:\FAO_PROD.CDX
                            [10/05/2000 - 12:26:28 | R | 6033561] F:\FAO_PROD.DBF
                            [04/05/2000 - 16:10:18 | R | 10240] F:\FAO_TRAD.CDX
                            [04/05/2000 - 16:10:18 | R | 311101] F:\FAO_TRAD.DBF
                            [11/05/2000 - 11:14:43 | RD ] F:\FRUITKEY
                            [10/05/2000 - 17:13:28 | R | 10816089] F:\GEOGDIST.DAT
                            [09/05/2000 - 23:40:44 | R | 9937841] F:\GEOGTEXT.DAT
                            [10/05/2000 - 09:36:42 | R | 31744] F:\GLOSSARY.CDX
                            [10/05/2000 - 09:41:12 | R | 105839] F:\GLOSSARY.DBF
                            [10/05/2000 - 09:41:08 | R | 3082255] F:\GLOSSARY.FPT
                            [10/05/2000 - 09:36:49 | R | 461312] F:\GLOSTERM.CDX
                            [10/05/2000 - 09:36:25 | R | 567479] F:\GLOSTERM.DBF
                            [04/05/2000 - 17:41:30 | R | 1613005] F:\HOSTLIST.DAT
                            [04/05/2000 - 17:42:08 | R | 2074123] F:\HOSTPEST.DAT
                            [04/05/2000 - 17:40:58 | R | 3668574] F:\HOSTS.DAT
                            [11/05/2000 - 11:14:12 | RD ] F:\IMAGES
                            [09/05/2000 - 21:01:34 | R | 123904] F:\INFO.CDX
                            [10/05/2000 - 16:55:39 | R | 5270676] F:\INFO.DBF
                            [09/05/2000 - 11:54:36 | R | 5632] F:\LB_FLDS.CDX
                            [09/05/2000 - 11:54:12 | R | 24197] F:\LB_FLDS.DBF
                            [09/05/2000 - 10:34:19 | R | 116678] F:\LOGO.BMP
                            [11/05/2000 - 11:14:11 | RD ] F:\MAPS
                            [10/05/2000 - 13:01:48 | R | 12443648] F:\NAMES.CDX
                            [09/05/2000 - 23:38:40 | R | 7061396] F:\NAMES.DAT
                            [10/05/2000 - 13:01:48 | R | 8291277] F:\NAMES.DBF
                            [11/05/2000 - 11:14:10 | RD ] F:\NEMAKEY
                            [04/05/2000 - 17:43:04 | R | 1916906] F:\NEN.DAT
                            [04/05/2000 - 17:42:36 | R | 675004] F:\NENHOSTS.DAT
                            [04/05/2000 - 17:43:22 | R | 824623] F:\NENLIST.DAT
                            [08/05/2000 - 16:01:07 | R | 33280] F:\PICTURES.CDX
                            [10/05/2000 - 14:58:41 | R | 759674] F:\PICTURES.DBF
                            [10/05/2000 - 14:58:41 | R | 595008] F:\PICTURES.FPT
                            [01/12/1995 - 13:58:04 | R | 169360] F:\PLAYER.EXE
                            [09/05/2000 - 20:40:04 | R | 1900544] F:\REFCODE.CDX
                            [09/05/2000 - 20:40:04 | R | 7408040] F:\REFCODE.DBF
                            [17/04/2000 - 17:17:39 | R | 15432796] F:\REFERENC.DAT
                            [10/05/2000 - 17:54:48 | R | 6656] F:\REGIONS.CDX
                            [10/05/2000 - 17:54:48 | R | 6091] F:\REGIONS.DBF
                            [23/03/1999 - 10:12:24 | R | 45312] F:\SETUP.EXE
                            [11/05/2000 - 11:11:06 | R | 75] F:\SETUP.INI
                            [08/04/1999 - 12:26:40 | R | 81342] F:\SETUP.INS
                            [11/05/2000 - 11:07:58 | R | 581] F:\SETUP.ISS
                            [11/05/2000 - 11:15:08 | R | 1465] F:\SETUP.PKG
                            [11/05/2000 - 11:14:10 | RD ] F:\SUPPORT
                            [10/06/1999 - 13:14:16 | R | 16384] F:\SYMPTOMS.CDX
                            [10/06/1999 - 13:14:14 | R | 123611] F:\SYMPTOMS.DBF
                            [09/06/1999 - 11:02:05 | R | 4000] F:\SYMPTOMS.TXT
                            [11/05/2000 - 11:14:10 | RD ] F:\TAXAKEY
                            [09/05/2000 - 21:00:14 | R | 111616] F:\TAXPOS.CDX
                            [09/05/2000 - 21:00:14 | R | 128473] F:\TAXPOS.DBF
                            [09/05/2000 - 20:52:12 | R | 10411008] F:\TERMS.CDX
                            [19/04/2000 - 16:10:42 | R | 19577965] F:\TERMS.DAT
                            [09/05/2000 - 20:52:12 | R | 14001528] F:\TERMS.DBF
                            [11/05/2000 - 11:14:09 | RD ] F:\WEEDKEY
                            [23/03/1999 - 10:12:22 | R | 283522] F:\_INST16.EX_
                            [23/03/1999 - 10:12:22 | R | 8192] F:\_ISDEL.EXE
                            [11/05/2000 - 11:12:41 | R | 14313665] F:\_SETUP.1
                            [23/03/1999 - 10:12:34 | R | 6128] F:\_SETUP.DLL
                            [11/05/2000 - 11:08:03 | R | 207452] F:\_SETUP.LIB
                            [13/11/2010 - 12:55:26 | D ] G:\FOUND.000
                            [17/10/2011 - 17:26:16 | D ] G:\mastel
                            [19/01/2012 - 00:52:00 | SHD ] G:\Recycled
                            [26/02/2009 - 22:44:02 | D ] G:\System Volume Information
                            [30/11/2010 - 14:37:30 | D ] G:\Lady Ponce-Bombe A
                            [04/10/2010 - 17:04:16 | D ] G:\JEUX
                            [09/05/2010 - 16:10:20 | D ] G:\Images gravure
                            [31/07/2011 - 23:49:18 | D ] G:\DHO
                            [11/04/2011 - 16:35:08 | D ] G:\Helvetica
                            [21/01/2006 - 01:00:18 | ASHD ] G:\Autorun.inf
                            [30/03/2010 - 16:10:08 | D ] G:\mes doc C
                            [27/04/2010 - 13:37:28 | D ] G:\$AVG
                            [13/02/2011 - 00:19:34 | N | 26624] G:\AWA SAI.doc
                            [04/04/2011 - 08:30:54 | D ] G:\zoropoto
                            [17/06/2010 - 01:02:40 | N | 3377718] G:\culture-generale-sujets-possibles-et-plans-types1.pdf
                            [24/04/2011 - 19:10:32 | D ] G:\Classical Music Top 100
                            [20/09/2010 - 16:49:22 | N | 103424] G:\CR_Passation de service.xls
                            [12/10/2010 - 08:04:34 | N | 55296] G:\CR reunion DRH-Superviseurs ID.xls
                            [21/05/2011 - 16:08:56 | D ] G:\Lyrics
                            [08/09/2011 - 09:14:34 | N | 66701] G:\msg.csv
                            [07/06/2011 - 12:47:02 | RSHD ] G:\RECYCLER
                            [26/11/2011 - 15:05:52 | D ] G:\Grey's anatomy
                            [20/06/2011 - 01:36:30 | N | 4314] G:\IELTS.mds
                            [02/03/2011 - 20:05:34 | N | 162] G:\~$WA SAI.doc
                            [10/05/2011 - 14:25:04 | N | 34304] G:\APPEL A PARTICIPATION.doc
                            [20/06/2011 - 01:36:30 | N | 63242240] G:\IELTS.mdf
                            [24/09/2007 - 23:29:18 | N | 9648128] G:\partlogic-0.69.iso
                            [12/04/2011 - 08:40:10 | D ] G:\US Top 40- Single Charts (26 March 2011)- Mp3ViLLe
                            [31/01/2011 - 11:31:24 | N | 170496] G:\JENUC projet de formation.doc
                            [10/05/2011 - 14:30:46 | N | 162] G:\~$PEL A PARTICIPATION.doc
                            [25/05/2011 - 15:38:28 | D ] G:\Tumba la madiba
                            [24/07/2011 - 20:12:46 | D ] G:\DREAMWEAVER
                            [04/05/2011 - 16:19:28 | D ] G:\diplomes scannés
                            [24/07/2011 - 20:44:50 | D ] G:\program files
                            [10/05/2011 - 16:04:38 | N | 44544] G:\demande communique TV.doc
                            [23/05/2011 - 13:01:28 | D ] G:\console recuperation
                            [10/05/2011 - 16:04:22 | N | 33280] G:\communiqué TV.doc
                            [23/04/2011 - 11:23:40 | D ] G:\Hacking Exposed Web Applications
                            [27/07/2011 - 06:44:20 | D ] G:\Logo UNYA
                            [30/03/2010 - 21:58:54 | D ] G:\YMulti Messenger v8(2)
                            [02/03/2009 - 13:01:38 | D ] G:\SOFTWARES
                            [30/05/2011 - 16:17:26 | ASH | 30208] G:\Thumbs.db
                            [24/05/2011 - 15:12:16 | D ] G:\photos workshop
                            [10/05/2011 - 15:30:36 | N | 33792] G:\communiqué Radio.doc
                            [26/05/2011 - 19:10:52 | N | 14219033] G:\Les Photos.docx
                            [10/05/2011 - 15:34:56 | N | 46080] G:\demande communique radio.doc
                            [05/06/2011 - 10:19:30 | D ] G:\anniversaire baby
                            [25/04/2011 - 15:49:12 | D ] G:\Syngress.Publishing.Firewall.Policies.and.VPN.Configurations.Sep.2006.eBook-BBL
                            [29/03/2011 - 22:12:24 | D ] G:\PHOTO OCM Identification Mars 2011
                            [27/03/2007 - 11:17:14 | N | 228106240] G:\Ms Office Project Professional 2007 rus.iso
                            [06/09/2011 - 23:37:48 | N | 14273] G:\Monsieur le Président de la République Populaire de Chine.docx
                            [03/10/2011 - 17:34:26 | D ] G:\Frontiere s
                            [10/01/2006 - 02:04:46 | D ] G:\acer travelmate 4320
                            [27/07/2011 - 05:21:06 | D ] G:\photos atelier 18 19 MAI 2011 UNFPA
                            [30/10/2011 - 10:16:20 | N | 14816] G:\IRIC le faux jeu de JEP.docx
                            [07/09/2011 - 10:11:42 | N | 23644789] G:\Avril Lavigne - He Wasn't.mp4
                            [08/09/2011 - 08:55:04 | D ] G:\music mes documents
                            [26/05/2011 - 19:01:32 | D ] G:\Afrique Renouveau L'Afrique au miroir de sa jeunesse_files
                            [26/05/2011 - 19:01:32 | N | 20491] G:\Afrique Renouveau L'Afrique au miroir de sa jeunesse.htm
                            [07/09/2011 - 10:13:14 | N | 24205317] G:\Avril Lavigne - I'm With You.mp4
                            [16/07/2011 - 07:22:16 | D ] G:\Billboard Hot 100 06-25-2011
                            [27/08/2011 - 23:55:38 | N | 15728] G:\demande ordinateur.docx
                            [17/05/2011 - 00:49:44 | N | 220546] G:\LOGO FINAL DE CHEZ FINAL AVEC MAIN ROUGE ENROULE.png
                            [27/07/2011 - 05:24:12 | D ] G:\photos beaudelaire nouemechi squatter
                            [29/09/2011 - 19:29:22 | D ] G:\Avril Lavigne Complete discography [2002 - 2009]
                            [27/07/2011 - 05:29:06 | D ] G:\photos atelier jeunes et agriculture limbé 7-9 juillet 2011
                            [23/05/2011 - 04:31:02 | D ] G:\photos Kwedi marie laure
                            [07/09/2011 - 10:15:10 | N | 18101577] G:\Avril Lavigne - Knockin.mp4
                            [07/09/2011 - 10:16:44 | N | 33275867] G:\Avril Lavigne - Losing Grip(Zone).mp4
                            [26/08/2011 - 11:13:40 | N | 25487] G:\FICHE_INSCRIPTION_ENSP.docx
                            [14/08/2011 - 19:20:14 | N | 18156] G:\discours JIJ 2011 Jeunes du Burkina Faso.docx
                            [27/09/2011 - 18:54:58 | N | 10560] G:\pat & bros.xlsx
                            [07/09/2011 - 10:09:34 | N | 25330625] G:\Avril Lavigne -he wasn't.mp4
                            [03/10/2011 - 17:34:32 | D ] G:\Mystic.River.2003.DVDRip.XViD-BTSFilms
                            [26/11/2011 - 22:29:20 | N | 37865] G:\TDR projet information phytosanitaire (Enregistré automatiquement).docx
                            [18/10/2011 - 16:51:13 | D ] H:\$AVG
                            [10/01/2006 - 00:19:58 | D ] H:\$RECYCLE.BIN
                            [17/11/2010 - 22:29:41 | D ] H:\.hitachi-lifestudio
                            [04/01/2012 - 04:18:33 | N | 9517056] H:\016 Drake - Headlines.mp3
                            [02/11/2011 - 01:07:30 | D ] H:\BERNARD SECRETARIAT
                            [25/12/2011 - 03:39:43 | D ] H:\DATA (D)
                            [12/11/2011 - 13:17:15 | D ] H:\DATA 2
                            [19/11/2011 - 09:47:10 | N | 6213933] H:\DeepBurnerPro.exe
                            [10/02/2012 - 09:04:12 | D ] H:\dll
                            [24/12/2011 - 22:40:21 | D ] H:\films
                            [18/03/2010 - 08:49:00 | N | 65643] H:\GoFlex.ico
                            [29/01/2012 - 03:05:41 | D ] H:\gumne
                            [27/11/2011 - 21:45:45 | D ] H:\Harry Potter and the Deathly Hallows Part 2 (2011) DVDRip XviD-MAXSPEED
                            [30/08/2011 - 15:14:30 | D ] H:\Images gravure
                            [02/11/2011 - 01:01:10 | D ] H:\LOGICIELS
                            [03/09/2011 - 19:43:52 | D ] H:\Logo UNYA
                            [30/12/2011 - 11:39:41 | D ] H:\ma clé au 23 12 2011
                            [13/05/2010 - 02:49:08 | N | 35310222] H:\Mac Installer.dmg
                            [18/01/2012 - 22:58:50 | D ] H:\MUSIQUE
                            [09/05/2011 - 02:08:03 | D ] H:\Musique Video
                            [25/12/2011 - 04:14:20 | D ] H:\NEW DD
                            [24/01/2012 - 21:07:15 | N | 12420] H:\plan d'action INNOVTION IRIC.docx
                            [10/01/2006 - 00:20:49 | SHD ] H:\RECYCLER
                            [07/09/2011 - 03:10:46 | N | 2774272] H:\rmparite.exe
                            [13/08/2010 - 21:03:26 | D ] H:\Seagate
                            [16/01/2009 - 09:14:08 | N | 156312] H:\Setup.exe
                            [31/10/2011 - 23:21:53 | SHD ] H:\System Volume Information
                            [24/12/2010 - 06:35:40 | N | 82685] H:\Takers (2010).720p.srt
                            [19/10/2011 - 10:25:00 | D ] H:\TEST SECURITE ONU
                            [11/02/2012 - 00:29:05 | D ] H:\the vampire diaries s03
                            [31/10/2011 - 23:59:21 | D ] H:\The vampire diaries Season 2
                            [06/11/2011 - 12:21:06 | N | 366431054] H:\The.Vampire.Diaries.S03E07.HDTV.XviD-2HD.avi
                            [10/11/2011 - 06:26:12 | D ] H:\thierry bureau
                            [31/10/2011 - 23:59:32 | ASH | 31232] H:\Thumbs.db
                            [13/08/2010 - 21:03:14 | D ] H:\USB 3.0 PC Card Adapter
                            [16/11/2010 - 10:02:19 | D ] H:\user_Backup
                            [18/12/2011 - 11:09:53 | D ] I:\Adobe CS3
                            [16/01/2012 - 14:50:26 | N | 431716352] I:\Office Pro 07.iso
                            [03/01/2012 - 13:23:45 | D ] I:\Program Files
                            [10/01/2006 - 00:20:49 | SHD ] I:\RECYCLER
                            [18/12/2011 - 10:45:36 | SHD ] I:\System Volume Information
                            [26/05/2011 - 17:17:01 | D ] K:\$AVG
                            [10/01/2006 - 00:20:05 | HD ] K:\$RECYCLE.BIN
                            [02/12/2007 - 17:36:27 | N | 50176] K:\actionplan.doc
                            [13/03/2011 - 09:55:52 | N | 308229] K:\Additif_Examen_MASTEL_Semestre1_2010_2011.rar
                            [24/11/2011 - 02:56:52 | D ] K:\ancien RnB
                            [21/01/2006 - 01:00:16 | ASHD ] K:\Autorun.inf
                            [18/02/2011 - 15:05:18 | N | 154871128] K:\avg_free_x86_all_2011_1204a3402.exe
                            [29/07/2009 - 10:57:43 | N | 211456] K:\CandidatureForm_CoordinatingCommittee_KAMMI Thierry.doc
                            [10/05/2011 - 15:37:02 | D ] K:\cle
                            [12/09/2011 - 02:57:17 | D ] K:\DATA 1
                            [20/11/2011 - 12:38:07 | D ] K:\decale
                            [23/04/2011 - 01:25:35 | D ] K:\Documents de EBA
                            [12/11/2011 - 12:33:53 | D ] K:\Enya - The Very Best of Enya [mp3-vbr-2009]
                            [28/07/2011 - 14:51:02 | N | 993252] K:\Examen_MASTEL_Aout_2011.zip
                            [31/07/2011 - 13:47:50 | N | 324650] K:\Examen_MASTEL_Aout_2011_ajout.zip
                            [08/03/2011 - 11:21:26 | N | 1637409] K:\Examen_MASTEL_Semestre1_2010_2011.zip
                            [28/08/2011 - 02:05:08 | N | 366861340] K:\Fringe.S02E01.A.New.Day.in.the.Old.Town.HDTV.XviD-FQM.avi
                            [28/08/2011 - 16:18:00 | N | 366782930] K:\Fringe.S02E02.Night.of.Desirable.Objects.HDTV.XviD-FQM.avi
                            [28/08/2011 - 23:48:00 | N | 366575810] K:\Fringe.S02E03.PROPER.HDTV.XviD-2HD.avi
                            [29/08/2011 - 00:58:30 | N | 366503566] K:\Fringe.S02E04.HDTV.XviD-2HD.avi
                            [06/05/2011 - 20:35:17 | D ] K:\Internet Download Manager 5.19.1 Precracked
                            [18/10/2011 - 09:30:34 | D ] K:\MASTEL2010
                            [19/07/2011 - 06:02:55 | D ] K:\Musics religieuse
                            [24/05/2011 - 20:07:38 | D ] K:\PERMANENTLY ACTIVATE OFFICE 2010 PROFESSIONAL PLUS
                            [09/08/2009 - 11:54:44 | N | 32768] K:\permettez que la présente chronique réponde aux nombreux internautes qui.doc
                            [10/02/2010 - 01:53:18 | N | 4023943168] K:\PRJ_20091227.mdf
                            [10/02/2010 - 01:53:18 | N | 4397] K:\PRJ_20091227.mds
                            [10/01/2006 - 00:20:49 | SHD ] K:\RECYCLER
                            [20/02/2009 - 22:27:59 | D ] K:\resumé prime star ac
                            [11/11/2011 - 20:21:27 | RSHD ] K:\System Volume Information
                            [12/11/2011 - 12:33:53 | ASH | 33280] K:\Thumbs.db
                            [07/12/2008 - 17:07:44 | N | 92672] K:\Thèmes de mémoires GPC 11é promotion.doc
                            [15/12/2008 - 19:57:31 | N | 72704] K:\Titre des mémoires Département Administration générale.doc
                            [05/07/2011 - 03:38:27 | D ] K:\traductions diplomes francine
                            [28/02/2011 - 00:57:49 | D ] K:\Vocabulaire Anglais
                            [17/10/2011 - 15:54:30 | D ] K:\xampplite
                            [24/11/2011 - 03:10:01 | D ] K:\zik zik
                            [28/10/2010 - 00:39:37 | N | 162] K:\~$tionplan.doc

                            ################## | Vaccin |

                            C:\Autorun.inf -> Vaccin créé par UsbFix (El Desaparecido)
                            E:\Autorun.inf -> Vaccin créé par UsbFix (El Desaparecido)
                            G:\Autorun.inf -> Vaccin créé par UsbFix (El Desaparecido)
                            H:\Autorun.inf -> Vaccin créé par UsbFix (El Desaparecido)
                            I:\Autorun.inf -> Vaccin créé par UsbFix (El Desaparecido)
                            K:\Autorun.inf -> Vaccin créé par UsbFix (El Desaparecido)

                            ################## | Upload |

                            Veuillez envoyer le fichier: C:\UsbFix_Upload_Me_MASTEL.zip
                            http://eldesaparecido.com/upload.html
                            Merci de votre contribution.

                            ################## | E.O.F |
                            0
                            1. ok à lire l'usnfix du bureau alors :)
                              0
                              1. bjr gen!!

                                jai lancé un usbfix qui a fait près de 3h avant de s'achever. c'est ce matin que je récupère le rapport sous c:\usbfix.txt. j'espère que c'est le bon, que voici.

                                PS: je me suis rendu compte ce matin que quelqu'un a branché une clé sur cette machine pour prendre un dossier. peu etre que sa clé était infectée? je sais pas

                                ############################## | UsbFix V 7.081 | [Suppression]

                                Utilisateur: KAM Apollinaire M (Administrateur) # PC-DE-KAM
                                Mis à jour le 05/02/2012 par El Desaparecido
                                Lancé à 21:06:24 | 12/02/2012

                                Site Web: https://www.sosvirus.net/
                                Fichier suspect ? : http://eldesaparecido.com/upload.html
                                Contact: contact@eldesaparecido.com

                                PC: Acer (Extensa 5220 ) (X86-based PC) # Notebook
                                CPU: Intel(R) Celeron(R) CPU 540 @ 1.86GHz (1862)
                                RAM -> [ Total : 1526 | Free : 593 ]
                                BIOS: Ver 1.00PARTTBL
                                BOOT: Normal boot

                                OS: Microsoft® Windows Vista(TM) Édition Familiale Basique (6.0.6000 32-Bit) #
                                WB: Windows Internet Explorer 7.0.6000.16982

                                SC: Security Center Service [ Enabled ]
                                WU: Windows Update Service [ Enabled ]
                                FW: Windows FireWall Service [ Enabled ]

                                C:\ (%systemdrive%) -> Disque fixe # 32 Go (2 Go libre(s) - 5%) [ACER] # NTFS
                                D:\ -> Disque fixe # 32 Go (30 Go libre(s) - 92%) [DATA] # NTFS
                                E:\ -> CD-ROM
                                F:\ -> Disque amovible # 4 Go (871 Mo libre(s) - 23%) [PUBLIC] # FAT32

                                ################## | Processus Actif |

                                C:\Windows\system32\csrss.exe (524)
                                C:\Windows\system32\wininit.exe (568)
                                C:\Windows\system32\csrss.exe (576)
                                C:\Windows\system32\services.exe (620)
                                C:\Windows\system32\lsass.exe (636)
                                C:\Windows\system32\lsm.exe (644)
                                C:\Windows\system32\winlogon.exe (668)
                                C:\Windows\system32\svchost.exe (836)
                                C:\Windows\system32\svchost.exe (908)
                                C:\Windows\System32\svchost.exe (944)
                                C:\Windows\System32\svchost.exe (1072)
                                C:\Windows\system32\svchost.exe (1092)
                                C:\Windows\system32\SLsvc.exe (1196)
                                C:\Windows\system32\svchost.exe (1228)
                                C:\Windows\System32\spoolsv.exe (1568)
                                C:\Windows\system32\Dwm.exe (1768)
                                C:\Windows\Explorer.EXE (1812)
                                C:\Windows\system32\CAP3RSK.EXE (1832)
                                C:\WINDOWS\SYSTEM32\SPOOL\DRIVERS\W32X86\3\CAP3SWK.EXE (312)
                                C:\Windows\RtHDVCpl.exe (588)
                                C:\Program Files\Synaptics\SynTP\SynTPEnh.exe (560)
                                C:\Windows\System32\igfxtray.exe (428)
                                C:\Windows\System32\hkcmd.exe (824)
                                C:\Windows\System32\igfxpers.exe (640)
                                C:\Program Files\Intel\Intel Matrix Storage Manager\IAAnotif.exe (284)
                                C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe (988)
                                C:\Acer\Empowering Technology\eDataSecurity\eDSLoader.exe (1152)
                                C:\Program Files\Yahoo!\Search Protection\SearchProtection.exe (1304)
                                C:\Program Files\HP\HP UT LEDM\bin\hppusg.exe (1312)
                                C:\Program Files\ESET\ESET Smart Security\egui.exe (1384)
                                C:\Program Files\Kodak\Kodak EasyShare software\bin\EasyShare.exe (1368)
                                C:\Windows\System32\spool\drivers\w32x86\3\CAP3LAK.EXE (1296)
                                C:\Windows\system32\igfxsrvc.exe (1012)
                                C:\Acer\Empowering Technology\EPOWER\EPOWER_DMC.EXE (1704)
                                C:\Acer\Empowering Technology\ACER.EMPOWERING.FRAMEWORK.SUPERVISOR.EXE (480)
                                C:\Acer\Empowering Technology\eRecovery\ERAGENT.EXE (1708)
                                C:\Windows\system32\wuauclt.exe (376)
                                C:\Users\KAMAPO~1\AppData\Local\Temp\RtkBtMnt.exe (1636)
                                C:\Windows\system32\svchost.exe (1448)
                                C:\Windows\System32\svchost.exe (1736)
                                C:\Acer\Empowering Technology\eDataSecurity\eDSService.exe (1032)
                                C:\Program Files\ESET\ESET Smart Security\ekrn.exe (716)
                                C:\Acer\Empowering Technology\eLock\Service\eLockServ.exe (2132)
                                C:\Acer\Empowering Technology\eNet\eNet Service.exe (2172)
                                C:\Program Files\HP\HPLaserJetService\HPLaserJetService.exe (2248)
                                C:\Windows\system32\HPSIsvc.exe (2292)
                                C:\Program Files\Intel\Intel Matrix Storage Manager\Iaantmon.exe (2328)
                                C:\Program Files\Common Files\LightScribe\LSSrvc.exe (2364)
                                C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE (2384)
                                C:\Acer\Mobility Center\MobilityService.exe (2400)
                                C:\Program Files\Microsoft SQL Server\MSSQL.1\MSSQL\Binn\sqlservr.exe (2456)
                                C:\Program Files\CyberLink\Shared Files\RichVideo.exe (2684)
                                C:\Windows\system32\svchost.exe (2720)
                                C:\Program Files\ZTE Wireless Terminal\bin\MonServiceUDisk.exe (2768)
                                C:\Windows\System32\svchost.exe (2824)
                                C:\Windows\system32\SearchIndexer.exe (2848)
                                C:\Windows\system32\DRIVERS\xaudio.exe (3088)
                                C:\Program Files\Yahoo!\SoftwareUpdate\YahooAUService.exe (3116)
                                C:\Acer\Empowering Technology\eRecovery\eRecoveryService.exe (3168)
                                C:\Acer\Empowering Technology\eSettings\Service\capuserv.exe (3208)
                                C:\Acer\Empowering Technology\ePower\ePowerSvc.exe (3264)
                                C:\Windows\system32\wbem\wmiprvse.exe (3616)
                                C:\Windows\system32\wbem\wmiprvse.exe (3668)
                                C:\Windows\system32\wbem\unsecapp.exe (2468)
                                C:\Windows\system32\taskeng.exe (2992)
                                C:\Windows\system32\taskeng.exe (3160)
                                C:\Windows\system32\conime.exe (3148)
                                C:\Users\KAM Apollinaire M\bpraay.exe (3736)
                                C:\Users\KAM Apollinaire M\2buk.exe (3572)
                                C:\Windows\system32\WUDFHost.exe (3912)
                                \\?\C:\Windows\system32\wbem\WMIADAP.EXE (1680)
                                C:\UsbFix\Go.exe (3968)

                                ################## | Processus Stoppés |

                                Stoppé! C:\Windows\system32\SLsvc.exe (1196)
                                Stoppé! C:\Windows\System32\spoolsv.exe (1568)
                                Stoppé! C:\Windows\system32\CAP3RSK.EXE (1832)
                                Stoppé! C:\WINDOWS\SYSTEM32\SPOOL\DRIVERS\W32X86\3\CAP3SWK.EXE (312)
                                Stoppé! C:\Windows\RtHDVCpl.exe (588)
                                Stoppé! C:\Program Files\Synaptics\SynTP\SynTPEnh.exe (560)
                                Stoppé! C:\Windows\System32\igfxtray.exe (428)
                                Stoppé! C:\Windows\System32\hkcmd.exe (824)
                                Stoppé! C:\Windows\System32\igfxpers.exe (640)
                                Stoppé! C:\Program Files\Intel\Intel Matrix Storage Manager\IAAnotif.exe (284)
                                Stoppé! C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe (988)
                                Stoppé! C:\Acer\Empowering Technology\eDataSecurity\eDSLoader.exe (1152)
                                Stoppé! C:\Program Files\Yahoo!\Search Protection\SearchProtection.exe (1304)
                                Stoppé! C:\Program Files\HP\HP UT LEDM\bin\hppusg.exe (1312)
                                Stoppé! C:\Program Files\ESET\ESET Smart Security\egui.exe (1384)
                                Stoppé! C:\Program Files\Kodak\Kodak EasyShare software\bin\EasyShare.exe (1368)
                                Stoppé! C:\Windows\System32\spool\drivers\w32x86\3\CAP3LAK.EXE (1296)
                                Stoppé! C:\Windows\system32\igfxsrvc.exe (1012)
                                Stoppé! C:\Acer\Empowering Technology\EPOWER\EPOWER_DMC.EXE (1704)
                                Stoppé! C:\Acer\Empowering Technology\ACER.EMPOWERING.FRAMEWORK.SUPERVISOR.EXE (480)
                                Stoppé! C:\Acer\Empowering Technology\eRecovery\ERAGENT.EXE (1708)
                                Stoppé! C:\Windows\system32\wuauclt.exe (376)
                                Stoppé! C:\Users\KAMAPO~1\AppData\Local\Temp\RtkBtMnt.exe (1636)
                                Stoppé! C:\Acer\Empowering Technology\eDataSecurity\eDSService.exe (1032)
                                Stoppé! C:\Program Files\ESET\ESET Smart Security\ekrn.exe (716)
                                Stoppé! C:\Acer\Empowering Technology\eLock\Service\eLockServ.exe (2132)
                                Stoppé! C:\Acer\Empowering Technology\eNet\eNet Service.exe (2172)
                                Stoppé! C:\Program Files\HP\HPLaserJetService\HPLaserJetService.exe (2248)
                                Stoppé! C:\Windows\system32\HPSIsvc.exe (2292)
                                Stoppé! C:\Program Files\Intel\Intel Matrix Storage Manager\Iaantmon.exe (2328)
                                Stoppé! C:\Program Files\Common Files\LightScribe\LSSrvc.exe (2364)
                                Stoppé! C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE (2384)
                                Stoppé! C:\Acer\Mobility Center\MobilityService.exe (2400)
                                Stoppé! C:\Program Files\Microsoft SQL Server\MSSQL.1\MSSQL\Binn\sqlservr.exe (2456)
                                Stoppé! C:\Program Files\CyberLink\Shared Files\RichVideo.exe (2684)
                                Stoppé! C:\Program Files\ZTE Wireless Terminal\bin\MonServiceUDisk.exe (2768)
                                Stoppé! C:\Windows\system32\SearchIndexer.exe (2848)
                                Stoppé! C:\Windows\system32\DRIVERS\xaudio.exe (3088)
                                Stoppé! C:\Program Files\Yahoo!\SoftwareUpdate\YahooAUService.exe (3116)
                                Stoppé! C:\Acer\Empowering Technology\eRecovery\eRecoveryService.exe (3168)
                                Stoppé! C:\Acer\Empowering Technology\eSettings\Service\capuserv.exe (3208)
                                Stoppé! C:\Acer\Empowering Technology\ePower\ePowerSvc.exe (3264)
                                Stoppé! C:\Windows\system32\taskeng.exe (2992)
                                Stoppé! C:\Windows\system32\taskeng.exe (3160)
                                Stoppé! C:\Windows\system32\conime.exe (3148)
                                Stoppé! C:\Users\KAM Apollinaire M\bpraay.exe (3736)
                                Stoppé! C:\Users\KAM Apollinaire M\2buk.exe (3572)
                                Stoppé! C:\Windows\system32\WUDFHost.exe (3912)

                                ################## | Éléments infectieux |

                                Supprimé! C:\SYSTEMES FINANCIERS NON FORMELS.lnk
                                Supprimé! C:\Users\KAM Apollinaire M\AppData\Local\AresXZ
                                Supprimé! C:\Users\KAM Apollinaire M\AppData\Local\S-1-5-31-1286970278978-5713669491-166975984-320
                                Supprimé! C:\Users\KAM Apollinaire M\AppData\Local\Start
                                Supprimé! C:\Users\KAM Apollinaire M\AppData\Roaming\LimeRunner
                                Supprimé! C:\Program Files\LP
                                Supprimé! C:\Users\KAMAPO~1\AppData\Local\Temp\100.exe
                                Supprimé! C:\Users\KAMAPO~1\AppData\Local\Temp\121.exe
                                Supprimé! C:\Users\KAMAPO~1\AppData\Local\Temp\126.exe
                                Supprimé! C:\Users\KAMAPO~1\AppData\Local\Temp\135.exe
                                Supprimé! C:\Users\KAMAPO~1\AppData\Local\Temp\146.exe
                                Supprimé! C:\Users\KAMAPO~1\AppData\Local\Temp\160.exe
                                Supprimé! C:\Users\KAMAPO~1\AppData\Local\Temp\251.exe
                                Supprimé! C:\Users\KAMAPO~1\AppData\Local\Temp\336.exe
                                Supprimé! C:\Users\KAMAPO~1\AppData\Local\Temp\337.exe
                                Supprimé! C:\Users\KAMAPO~1\AppData\Local\Temp\451.exe
                                Supprimé! C:\Users\KAMAPO~1\AppData\Local\Temp\453.exe
                                Supprimé! C:\Users\KAMAPO~1\AppData\Local\Temp\534.exe
                                Supprimé! C:\Users\KAMAPO~1\AppData\Local\Temp\630.exe
                                Supprimé! C:\Users\KAMAPO~1\AppData\Local\Temp\718.exe
                                Supprimé! C:\Users\KAMAPO~1\AppData\Local\Temp\742.exe
                                Supprimé! C:\Users\KAMAPO~1\AppData\Local\Temp\774.exe
                                Supprimé! C:\Users\KAMAPO~1\AppData\Local\Temp\828.exe
                                Supprimé! C:\Users\KAMAPO~1\AppData\Local\Temp\921.exe
                                Supprimé! C:\Users\KAMAPO~1\AppData\Local\Temp\988.exe
                                Supprimé! C:\Users\KAMAPO~1\AppData\Local\Temp\399798.exe
                                Supprimé! C:\Users\KAMAPO~1\AppData\Local\Temp\9755210.exe
                                Supprimé! C:\Users\KAMAPO~1\AppData\Local\Temp\9846411.exe
                                Supprimé! C:\Users\KAMAPO~1\AppData\Local\Temp\E_4
                                Supprimé! C:\Users\KAM Apollinaire M\calc.exe
                                Supprimé! C:\Users\KAM Apollinaire M\spkpod
                                Supprimé! D:\zPharaoh.exe
                                Supprimé! C:\$RECYCLE.BIN\S-1-5-21-1209201674-4029264647-1254799989-1003
                                Supprimé! C:\$RECYCLE.BIN\S-1-5-21-1209201674-4029264647-1254799989-500
                                Supprimé! C:\Recycler\S-1-5-21-1482476501-1644491937-682003330-1013
                                Supprimé! C:\Recycler\S-1-5-21-1625604208-5489677165-028599915-6245
                                Supprimé! C:\Recycler\S-1-5-21-2202729271-4171784730-066912192-6690
                                Supprimé! C:\Recycler\S-1-5-21-2495680563-8324568200-115959518-7203
                                Supprimé! C:\Recycler\S-1-5-21-4662043520-7399280772-472366034-3832
                                Supprimé! C:\Recycler\S-1-5-21-5391432259-1327072928-703239166-2923
                                Supprimé! C:\Recycler\S-1-5-21-6061203905-6979317975-670582519-4940
                                Supprimé! C:\Recycler\S-1-5-21-8453595950-7098148093-228555026-9579
                                Supprimé! C:\Recycler\S-1-5-21-9815145211-3546003208-334757906-9359
                                Supprimé! D:\$RECYCLE.BIN\S-1-5-21-1209201674-4029264647-1254799989-1003
                                Supprimé! D:\$RECYCLE.BIN\S-1-5-21-1209201674-4029264647-1254799989-500
                                Supprimé! D:\autorun.inf

                                (!) Fichiers temporaires supprimés.

                                ################## | Mabezat |

                                Supprimé! C:\Users\KAM Apollinaire M\AppData\Roaming\tazebama

                                ################## | Registre |

                                Supprimé! HKCU\Software\AresXZ
                                Supprimé! HKCU\Software\Microsoft\Windows\CurrentVersion\Run|Regedit32

                                ################## | Mountpoints2 |

                                Supprimé! HKCU\.\.\.\.\Explorer\MountPoints2\F
                                Supprimé! HKCU\.\.\.\.\Explorer\MountPoints2\{01f4e92b-54e0-11de-9f7e-000000000000}
                                Supprimé! HKCU\.\.\.\.\Explorer\MountPoints2\{158a9ad4-c484-11df-bbb4-001812f9284e}
                                Supprimé! HKCU\.\.\.\.\Explorer\MountPoints2\{1ff4d9b4-09c7-11e0-8f86-000000000000}
                                Supprimé! HKCU\.\.\.\.\Explorer\MountPoints2\{1ff4d9da-09c7-11e0-8f86-0018120189ce}
                                Supprimé! HKCU\.\.\.\.\Explorer\MountPoints2\{232b579e-41c4-11e0-85f5-000000000000}
                                Supprimé! HKCU\.\.\.\.\Explorer\MountPoints2\{247bfd1d-86b1-11e0-9921-000000000000}
                                Supprimé! HKCU\.\.\.\.\Explorer\MountPoints2\{249d0296-2930-11e0-b727-000000000000}
                                Supprimé! HKCU\.\.\.\.\Explorer\MountPoints2\{3ab9b76b-3346-11df-9c5a-001812f9284e}
                                Supprimé! HKCU\.\.\.\.\Explorer\MountPoints2\{3ab9b777-3346-11df-9c5a-001812f9284e}
                                Supprimé! HKCU\.\.\.\.\Explorer\MountPoints2\{4a8169de-96cf-11de-83a8-001812f9284e}
                                Supprimé! HKCU\.\.\.\.\Explorer\MountPoints2\{4bc2378f-dac0-11e0-a687-000000000000}
                                Supprimé! HKCU\.\.\.\.\Explorer\MountPoints2\{53de23ad-b554-11dd-8d0e-000000000000}
                                Supprimé! HKCU\.\.\.\.\Explorer\MountPoints2\{55b661e7-ca49-11e0-9d47-000000000000}
                                Supprimé! HKCU\.\.\.\.\Explorer\MountPoints2\{66188ab2-43b6-11df-931f-001812f9284e}
                                Supprimé! HKCU\.\.\.\.\Explorer\MountPoints2\{7935b8ff-2959-11de-969f-000000000000}
                                Supprimé! HKCU\.\.\.\.\Explorer\MountPoints2\{8196b5f4-73a8-11df-b7e1-000000000000}
                                Supprimé! HKCU\.\.\.\.\Explorer\MountPoints2\{99e73ec3-c46d-11de-9500-001812f9284e}
                                Supprimé! HKCU\.\.\.\.\Explorer\MountPoints2\{9d90d0ed-b585-11dd-bb6f-000000000000}
                                Supprimé! HKCU\.\.\.\.\Explorer\MountPoints2\{a33e7b5f-3814-11e0-8273-001812f9284e}
                                Supprimé! HKCU\.\.\.\.\Explorer\MountPoints2\{a8c7e2ba-d8af-11de-8a2e-000000000000}
                                Supprimé! HKCU\.\.\.\.\Explorer\MountPoints2\{b1df86a7-9390-11dd-80fd-000000000000}
                                Supprimé! HKCU\.\.\.\.\Explorer\MountPoints2\{bca9dd95-a425-11df-9e3a-001812f9284e}
                                Supprimé! HKCU\.\.\.\.\Explorer\MountPoints2\{cb8ab4a2-fcac-11e0-9abc-000000000000}
                                Supprimé! HKCU\.\.\.\.\Explorer\MountPoints2\{e7a2b77f-5b40-11de-8d0d-000000000000}
                                Supprimé! HKCU\.\.\.\.\Explorer\MountPoints2\{eab47d61-da99-11de-8858-000000000000}
                                Supprimé! HKCU\.\.\.\.\Explorer\MountPoints2\{f8eab2b4-5672-11de-a9bb-000000000000}
                                Supprimé! HKCU\.\.\.\.\Explorer\MountPoints2\{fc831a98-d9da-11de-834c-806e6f6e6963}
                                Supprimé! HKCU\.\.\.\.\Explorer\MountPoints2\{fe671c14-7822-11de-b91e-001812f9284e}

                                ################## | Listing |

                                [12/02/2012 - 22:33:30 | SHD ] C:\$RECYCLE.BIN
                                [10/02/2012 - 19:26:02 | D ] C:\32788R22FWJFW
                                [29/04/2008 - 15:57:32 | D ] C:\Acer
                                [03/02/2012 - 07:37:03 | D ] C:\ASSOCOATIONS ET AMICALES
                                [18/09/2006 - 22:43:36 | N | 24] C:\autoexec.bat
                                [19/02/2010 - 11:12:29 | D ] C:\Book
                                [10/12/2006 - 03:40:07 | D ] C:\Boot
                                [02/11/2006 - 10:53:57 | RASH | 438840] C:\bootmgr
                                [17/10/2011 - 10:51:18 | D ] C:\BULLETINS D'ANALYSE
                                [17/11/2011 - 12:15:23 | D ] C:\CHLOROPHYLLE
                                [24/01/2012 - 15:23:25 | D ] C:\COMPTES RENDUS
                                [18/09/2006 - 22:43:37 | N | 10] C:\config.sys
                                [04/05/2007 - 13:31:34 | N | 43008] C:\CONSOV.PR.doc
                                [31/07/2008 - 18:12:00 | N | 59392] C:\CURRICULUM VITAE DETAILLE KAM Apollinaire.doc
                                [05/12/2007 - 08:36:44 | N | 66048] C:\DEMANDE DE CLASSEMENT COURRIER SDRSQV.doc
                                [17/11/2011 - 13:19:47 | D ] C:\DERNIER SPRINT
                                [07/12/2005 - 15:48:20 | N | 2119680] C:\DIAGNOSTIC2.doc
                                [03/02/2012 - 08:04:12 | D ] C:\DISCOURS
                                [02/11/2006 - 13:59:44 | SHD ] C:\Documents and Settings
                                [05/09/2011 - 12:39:44 | D ] C:\Dossier GIC
                                [27/11/2007 - 14:40:10 | N | 50176] C:\Echantillonnage.doc
                                [17/10/2011 - 15:39:23 | D ] C:\EQUIPEMENT LABO BIP
                                [09/06/2008 - 14:27:16 | N | 37376] C:\ETATS PREPARATIFS ASSEMBLEE GENERALE ELITES.xls
                                [07/05/2007 - 13:50:20 | N | 28672] C:\Exposé des motifs de la loi AB du 03 05 07.doc
                                [05/01/2012 - 18:35:32 | D ] C:\FEUILES DE ROUTE 2012
                                [13/01/2012 - 15:32:05 | D ] C:\Fiche des projets
                                [09/01/2008 - 10:14:44 | N | 68096] C:\FICHE MARCHE PHYTO CAMEROUN 2007[1].doc
                                [05/02/2012 - 12:14:20 | D ] C:\FONDS SEMENCIER
                                [07/02/2008 - 12:24:44 | N | 67584] C:\Formulaire pour programme maïs.doc
                                [12/02/2012 - 20:55:59 | ASH | 1600577536] C:\hiberfil.sys
                                [12/01/2012 - 13:58:34 | N | 111959] C:\Industrie des semences.pptx
                                [30/12/2008 - 13:45:40 | N | 0] C:\IO.SYS
                                [30/12/2011 - 11:27:37 | D ] C:\JUSTIFS COMPTES STATION DE QUARANTAINE
                                [03/02/2012 - 08:06:19 | D ] C:\KAM
                                [12/02/2012 - 16:32:09 | D ] C:\Kill'em
                                [29/11/2011 - 11:10:18 | D ] C:\KOUOGUENG ET FILS
                                [06/05/2008 - 16:10:52 | N | 41984] C:\L'intensification agricole en 10 questions réponses.doc
                                [02/05/2008 - 14:58:12 | N | 21373] C:\L'intensification agricole en 10 questions réponses.docx
                                [18/03/2008 - 17:03:14 | N | 29696] C:\Le financement de l'agriculture en 10 questions réponses.doc
                                [19/04/2008 - 23:25:04 | N | 22016] C:\Lettre de condoleances Maurice.doc
                                [10/02/2012 - 10:34:11 | D ] C:\LETTRE DRCQ
                                [09/02/2012 - 15:29:42 | D ] C:\LETTRES MINADER
                                [22/05/2007 - 10:17:02 | N | 140288] C:\Libellé.doc
                                [12/02/2012 - 20:57:19 | N | 608] C:\logfile
                                [12/09/2011 - 16:36:12 | D ] C:\MARCHES 2011
                                [22/11/2011 - 10:36:22 | D ] C:\MARCHES DIVERS
                                [05/09/2011 - 18:00:07 | D ] C:\MARCHES EIC
                                [10/11/2011 - 11:52:28 | D ] C:\Marchés publics
                                [25/12/2008 - 07:32:32 | D ] C:\Mes documents
                                [30/12/2008 - 13:45:40 | N | 0] C:\MSDOS.SYS
                                [26/05/2008 - 18:34:59 | RHD ] C:\MSOCache
                                [06/02/2012 - 20:53:38 | D ] C:\NOTES DRCQ
                                [12/02/2012 - 20:55:57 | ASH | 1914503168] C:\pagefile.sys
                                [16/11/2007 - 23:52:48 | N | 8676] C:\Patch.rev
                                [15/11/2007 - 04:22:10 | N | 1263] C:\Patch2.rev
                                [11/01/2007 - 01:52:52 | N | 631] C:\PDVD.iss
                                [27/01/2012 - 15:51:07 | D ] C:\PERMIS D'IMPORATION
                                [25/04/2007 - 10:10:08 | N | 65536] C:\Permis Unilever.doc
                                [06/07/2007 - 15:49:42 | N | 135] C:\preload.rev
                                [10/02/2012 - 16:16:43 | N | 87873] C:\Pre_Scan.txt
                                [12/02/2012 - 22:31:45 | D ] C:\Program Files
                                [10/02/2012 - 16:26:35 | HD ] C:\ProgramData
                                [09/01/2008 - 10:16:50 | N | 35328] C:\PROGRAMME DEFINITIF AG du 25 01 08[1].doc
                                [12/12/2011 - 20:27:41 | D ] C:\Projet FAO semences
                                [10/02/2012 - 10:22:25 | D ] C:\Projets élevage
                                [09/06/2011 - 10:09:08 | D ] C:\PV DE RECEPTION
                                [10/02/2012 - 19:26:03 | D ] C:\Qoobox
                                [10/05/2007 - 12:36:36 | N | 192512] C:\Questionnaire-Codex.doc
                                [05/02/2010 - 17:02:34 | D ] C:\RAPPORTS ET COMPTES RENDUS
                                [14/10/2011 - 13:39:05 | D ] C:\Recepisse de Declaration d'importattion
                                [12/02/2012 - 22:33:27 | RSHD ] C:\RECYCLER
                                [25/12/2008 - 07:32:39 | D ] C:\relating to seed production and marketing
                                [02/02/2011 - 17:16:02 | D ] C:\Ringo
                                [11/10/2011 - 12:35:56 | N | 2034737] C:\scanneur.jpg
                                [27/10/2011 - 10:31:08 | D ] C:\SEMINAIRES ET ATELIETS
                                [26/05/2008 - 17:02:36 | N | 16896] C:\Simulation budjet atelier.xls
                                [31/01/2012 - 10:58:13 | D ] C:\STATION DE QUARANTAINE
                                [15/06/2003 - 10:35:24 | D ] C:\Stratégie S Rural
                                [12/02/2012 - 19:09:12 | SHD ] C:\System Volume Information
                                [16/08/2011 - 14:06:15 | D ] C:\TAKAM STEPHEN
                                [12/02/2012 - 22:35:34 | D ] C:\UsbFix
                                [12/02/2012 - 21:07:58 | A | 17948] C:\UsbFix.txt
                                [29/04/2008 - 15:57:00 | D ] C:\Users
                                [10/02/2012 - 19:44:55 | D ] C:\Windows
                                [06/10/2008 - 11:36:42 | N | 296] C:\WMPInfo.xml
                                [20/04/2007 - 11:36:55 | N | 4] C:\wps.dat
                                [12/02/2012 - 14:53:50 | D ] C:\x
                                [10/02/2012 - 15:29:58 | D ] C:\ZHP
                                [12/02/2012 - 15:04:16 | | 165] C:\~$Industrie des semences.pptx
                                [12/02/2012 - 22:33:30 | SHD ] D:\$RECYCLE.BIN
                                [29/06/2009 - 14:06:53 | N | 121856] D:\Budjet 2009 fonds semencier.doc
                                [24/11/2009 - 14:57:05 | N | 179] D:\Disque amovible (F) - Raccourci.lnk
                                [29/12/2007 - 03:42:07 | D ] D:\erData
                                [11/10/2010 - 12:43:50 | N | 8591704] D:\Firefox Setup 3.6.10.exe
                                [26/11/2009 - 19:11:30 | N | 106496] D:\Groupe II (amende).ppt
                                [18/11/2008 - 16:45:35 | N | 276992] D:\MARCHE AGEM EQUIPEMENT LABO NATIONAL corrigé.doc
                                [25/07/2009 - 18:09:42 | D ] D:\NFS
                                [16/12/2010 - 07:36:54 | N | 27532080] D:\RingoDialer_1.11_with_jre.exe
                                [29/12/2007 - 03:02:43 | SHD ] D:\System Volume Information
                                [28/06/2011 - 14:36:56 | N | 68634] D:\The Project.zip
                                [25/07/2009 - 17:54:39 | D ] D:\XIII

                                ################## | Vaccin |

                                C:\Autorun.inf -> Vaccin créé par UsbFix (El Desaparecido)
                                D:\Autorun.inf -> Vaccin créé par UsbFix (El Desaparecido)

                                ################## | Upload |

                                Veuillez envoyer le fichier: C:\UsbFix_Upload_Me_PC-DE-KAM.zip
                                http://eldesaparecido.com/upload.html
                                Merci de votre contribution.

                                ################## | E.O.F |
                                0
                                1. je l'ai relancé, il s'est exécuté beaucoup plus vite.

                                  ############################## | UsbFix V 7.081 | [Suppression]

                                  Utilisateur: KAM Apollinaire M (Administrateur) # PC-DE-KAM
                                  Mis à jour le 05/02/2012 par El Desaparecido
                                  Lancé à 09:59:14 | 13/02/2012

                                  Site Web: https://www.sosvirus.net/
                                  Fichier suspect ? : http://eldesaparecido.com/upload.html
                                  Contact: contact@eldesaparecido.com

                                  PC: Acer (Extensa 5220 ) (X86-based PC) # Notebook
                                  CPU: Intel(R) Celeron(R) CPU 540 @ 1.86GHz (1862)
                                  RAM -> [ Total : 1526 | Free : 730 ]
                                  BIOS: Ver 1.00PARTTBL
                                  BOOT: Normal boot

                                  OS: Microsoft® Windows Vista(TM) Édition Familiale Basique (6.0.6000 32-Bit) #
                                  WB: Windows Internet Explorer 7.0.6000.16982

                                  SC: Security Center Service [ Enabled ]
                                  WU: Windows Update Service [ Enabled ]
                                  FW: Windows FireWall Service [ Enabled ]

                                  C:\ (%systemdrive%) -> Disque fixe # 32 Go (2 Go libre(s) - 6%) [ACER] # NTFS
                                  D:\ -> Disque fixe # 32 Go (30 Go libre(s) - 92%) [DATA] # NTFS
                                  E:\ -> CD-ROM

                                  ################## | Processus Actif |

                                  C:\Windows\system32\csrss.exe (516)
                                  C:\Windows\system32\wininit.exe (564)
                                  C:\Windows\system32\csrss.exe (572)
                                  C:\Windows\system32\services.exe (616)
                                  C:\Windows\system32\lsass.exe (628)
                                  C:\Windows\system32\lsm.exe (636)
                                  C:\Windows\system32\winlogon.exe (660)
                                  C:\Windows\system32\svchost.exe (828)
                                  C:\Windows\system32\svchost.exe (900)
                                  C:\Windows\System32\svchost.exe (936)
                                  C:\Windows\System32\svchost.exe (1064)
                                  C:\Windows\system32\svchost.exe (1088)
                                  C:\Windows\system32\SLsvc.exe (1192)
                                  C:\Windows\system32\svchost.exe (1224)
                                  C:\Windows\System32\spoolsv.exe (1564)
                                  C:\Windows\system32\Dwm.exe (1816)
                                  C:\Windows\system32\CAP3RSK.EXE (1844)
                                  C:\Windows\explorer.exe (1928)
                                  C:\WINDOWS\SYSTEM32\SPOOL\DRIVERS\W32X86\3\CAP3SWK.EXE (2008)
                                  C:\Windows\RtHDVCpl.exe (1344)
                                  C:\Program Files\Synaptics\SynTP\SynTPEnh.exe (1384)
                                  C:\Windows\System32\igfxtray.exe (1372)
                                  C:\Windows\System32\hkcmd.exe (1380)
                                  C:\Windows\System32\igfxpers.exe (284)
                                  C:\Program Files\Intel\Intel Matrix Storage Manager\IAAnotif.exe (1512)
                                  C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe (824)
                                  C:\Acer\Empowering Technology\eDataSecurity\eDSLoader.exe (1492)
                                  C:\Program Files\Yahoo!\Search Protection\SearchProtection.exe (1044)
                                  C:\Program Files\ESET\ESET Smart Security\egui.exe (612)
                                  C:\Program Files\Kodak\Kodak EasyShare software\bin\EasyShare.exe (1252)
                                  C:\Windows\system32\igfxsrvc.exe (116)
                                  C:\Windows\System32\spool\drivers\w32x86\3\CAP3LAK.EXE (1028)
                                  C:\Acer\Empowering Technology\EPOWER\EPOWER_DMC.EXE (632)
                                  C:\Acer\Empowering Technology\ACER.EMPOWERING.FRAMEWORK.SUPERVISOR.EXE (520)
                                  C:\Acer\Empowering Technology\eRecovery\ERAGENT.EXE (508)
                                  C:\Windows\system32\wuauclt.exe (1200)
                                  C:\Users\KAMAPO~1\AppData\Local\Temp\RtkBtMnt.exe (304)
                                  C:\Windows\system32\svchost.exe (468)
                                  C:\Windows\System32\svchost.exe (1776)
                                  C:\Acer\Empowering Technology\eDataSecurity\eDSService.exe (732)
                                  C:\Program Files\ESET\ESET Smart Security\ekrn.exe (1740)
                                  C:\Acer\Empowering Technology\eLock\Service\eLockServ.exe (2116)
                                  C:\Acer\Empowering Technology\eNet\eNet Service.exe (2152)
                                  C:\Program Files\HP\HPLaserJetService\HPLaserJetService.exe (2224)
                                  C:\Windows\system32\HPSIsvc.exe (2300)
                                  C:\Program Files\Intel\Intel Matrix Storage Manager\Iaantmon.exe (2336)
                                  C:\Program Files\Common Files\LightScribe\LSSrvc.exe (2356)
                                  C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE (2380)
                                  C:\Acer\Mobility Center\MobilityService.exe (2408)
                                  C:\Program Files\Microsoft SQL Server\MSSQL.1\MSSQL\Binn\sqlservr.exe (2476)
                                  C:\Program Files\CyberLink\Shared Files\RichVideo.exe (2624)
                                  C:\Windows\system32\svchost.exe (2668)
                                  C:\Program Files\ZTE Wireless Terminal\bin\MonServiceUDisk.exe (2752)
                                  C:\Windows\System32\svchost.exe (2804)
                                  C:\Windows\system32\SearchIndexer.exe (2832)
                                  C:\Windows\system32\DRIVERS\xaudio.exe (3008)
                                  C:\Program Files\Yahoo!\SoftwareUpdate\YahooAUService.exe (3036)
                                  C:\Acer\Empowering Technology\eRecovery\eRecoveryService.exe (3060)
                                  C:\Acer\Empowering Technology\eSettings\Service\capuserv.exe (3128)
                                  C:\Acer\Empowering Technology\ePower\ePowerSvc.exe (3192)
                                  C:\Windows\system32\wbem\wmiprvse.exe (3748)
                                  C:\Windows\system32\wbem\wmiprvse.exe (3756)
                                  C:\Windows\system32\wbem\unsecapp.exe (4028)
                                  C:\Windows\system32\taskeng.exe (2612)
                                  C:\Windows\system32\taskeng.exe (2296)
                                  C:\Windows\system32\conime.exe (3176)
                                  C:\Users\KAM Apollinaire M\douke.exe (3852)
                                  C:\Users\KAM Apollinaire M\2yup.exe (3844)
                                  C:\Windows\system32\NOTEPAD.EXE (2944)
                                  C:\Program Files\Mozilla Firefox\firefox.exe (1456)
                                  C:\Program Files\Mozilla Firefox\plugin-container.exe (2088)
                                  C:\Windows\system32\taskeng.exe (3568)
                                  C:\UsbFix\Go.exe (404)

                                  ################## | Processus Stoppés |

                                  Stoppé! C:\Windows\system32\SLsvc.exe (1192)
                                  Stoppé! C:\Windows\System32\spoolsv.exe (1564)
                                  Stoppé! C:\Windows\system32\CAP3RSK.EXE (1844)
                                  Stoppé! C:\WINDOWS\SYSTEM32\SPOOL\DRIVERS\W32X86\3\CAP3SWK.EXE (2008)
                                  Stoppé! C:\Windows\RtHDVCpl.exe (1344)
                                  Stoppé! C:\Program Files\Synaptics\SynTP\SynTPEnh.exe (1384)
                                  Stoppé! C:\Windows\System32\igfxtray.exe (1372)
                                  Stoppé! C:\Windows\System32\hkcmd.exe (1380)
                                  Stoppé! C:\Windows\System32\igfxpers.exe (284)
                                  Stoppé! C:\Program Files\Intel\Intel Matrix Storage Manager\IAAnotif.exe (1512)
                                  Stoppé! C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe (824)
                                  Stoppé! C:\Acer\Empowering Technology\eDataSecurity\eDSLoader.exe (1492)
                                  Stoppé! C:\Program Files\Yahoo!\Search Protection\SearchProtection.exe (1044)
                                  Stoppé! C:\Program Files\ESET\ESET Smart Security\egui.exe (612)
                                  Stoppé! C:\Program Files\Kodak\Kodak EasyShare software\bin\EasyShare.exe (1252)
                                  Stoppé! C:\Windows\system32\igfxsrvc.exe (116)
                                  Stoppé! C:\Windows\System32\spool\drivers\w32x86\3\CAP3LAK.EXE (1028)
                                  Stoppé! C:\Acer\Empowering Technology\EPOWER\EPOWER_DMC.EXE (632)
                                  Stoppé! C:\Acer\Empowering Technology\ACER.EMPOWERING.FRAMEWORK.SUPERVISOR.EXE (520)
                                  Stoppé! C:\Acer\Empowering Technology\eRecovery\ERAGENT.EXE (508)
                                  Stoppé! C:\Windows\system32\wuauclt.exe (1200)
                                  Stoppé! C:\Users\KAMAPO~1\AppData\Local\Temp\RtkBtMnt.exe (304)
                                  Stoppé! C:\Acer\Empowering Technology\eDataSecurity\eDSService.exe (732)
                                  Stoppé! C:\Program Files\ESET\ESET Smart Security\ekrn.exe (1740)
                                  Stoppé! C:\Acer\Empowering Technology\eLock\Service\eLockServ.exe (2116)
                                  Stoppé! C:\Acer\Empowering Technology\eNet\eNet Service.exe (2152)
                                  Stoppé! C:\Program Files\HP\HPLaserJetService\HPLaserJetService.exe (2224)
                                  Stoppé! C:\Windows\system32\HPSIsvc.exe (2300)
                                  Stoppé! C:\Program Files\Intel\Intel Matrix Storage Manager\Iaantmon.exe (2336)
                                  Stoppé! C:\Program Files\Common Files\LightScribe\LSSrvc.exe (2356)
                                  Stoppé! C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE (2380)
                                  Stoppé! C:\Acer\Mobility Center\MobilityService.exe (2408)
                                  Stoppé! C:\Program Files\Microsoft SQL Server\MSSQL.1\MSSQL\Binn\sqlservr.exe (2476)
                                  Stoppé! C:\Program Files\CyberLink\Shared Files\RichVideo.exe (2624)
                                  Stoppé! C:\Program Files\ZTE Wireless Terminal\bin\MonServiceUDisk.exe (2752)
                                  Stoppé! C:\Windows\system32\SearchIndexer.exe (2832)
                                  Stoppé! C:\Windows\system32\DRIVERS\xaudio.exe (3008)
                                  Stoppé! C:\Program Files\Yahoo!\SoftwareUpdate\YahooAUService.exe (3036)
                                  Stoppé! C:\Acer\Empowering Technology\eRecovery\eRecoveryService.exe (3060)
                                  Stoppé! C:\Acer\Empowering Technology\eSettings\Service\capuserv.exe (3128)
                                  Stoppé! C:\Acer\Empowering Technology\ePower\ePowerSvc.exe (3192)
                                  Stoppé! C:\Windows\system32\taskeng.exe (2612)
                                  Stoppé! C:\Windows\system32\taskeng.exe (2296)
                                  Stoppé! C:\Windows\system32\conime.exe (3176)
                                  Stoppé! C:\Users\KAM Apollinaire M\douke.exe (3852)
                                  Stoppé! C:\Users\KAM Apollinaire M\2yup.exe (3844)
                                  Stoppé! C:\Program Files\Mozilla Firefox\firefox.exe (1456)
                                  Stoppé! C:\Program Files\Mozilla Firefox\plugin-container.exe (2088)
                                  Stoppé! C:\Windows\system32\taskeng.exe (3568)

                                  ################## | Éléments infectieux |

                                  Supprimé! C:\$RECYCLE.BIN\S-1-5-21-1209201674-4029264647-1254799989-1003
                                  Supprimé! D:\$RECYCLE.BIN\S-1-5-21-1209201674-4029264647-1254799989-1003

                                  (!) Fichiers temporaires supprimés.

                                  ################## | Registre |

                                  ################## | Mountpoints2 |

                                  Supprimé! HKCU\.\.\.\.\Explorer\MountPoints2\{17805c7c-2499-11e1-b69c-000000000000}
                                  Supprimé! HKCU\.\.\.\.\Explorer\MountPoints2\{211f3996-a36f-11de-ab76-001812f9284e}
                                  Supprimé! HKCU\.\.\.\.\Explorer\MountPoints2\{4903a86c-6a63-11e0-86de-000000000000}
                                  Supprimé! HKCU\.\.\.\.\Explorer\MountPoints2\{53de23c3-b554-11dd-8d0e-000000000000}
                                  Supprimé! HKCU\.\.\.\.\Explorer\MountPoints2\{5ad67c2d-a2f8-11e0-abd7-000000000000}
                                  Supprimé! HKCU\.\.\.\.\Explorer\MountPoints2\{a4677b57-89a6-11df-865c-001812f9284e}
                                  Supprimé! HKCU\.\.\.\.\Explorer\MountPoints2\{b520bda4-0b20-11df-b233-000000000000}
                                  Supprimé! HKCU\.\.\.\.\Explorer\MountPoints2\{c13fbb53-ee6e-11df-ad3a-000000000000}
                                  Supprimé! HKCU\.\.\.\.\Explorer\MountPoints2\{e850dc77-72b1-11de-ba39-000000000000}
                                  Supprimé! HKCU\.\.\.\.\Explorer\MountPoints2\{eab47d76-da99-11de-8858-000000000000}
                                  Supprimé! HKCU\.\.\.\.\Explorer\MountPoints2\{fe671c11-7822-11de-b91e-001812f9284e}

                                  ################## | Listing |

                                  [13/02/2012 - 10:04:28 | SHD ] C:\$RECYCLE.BIN
                                  [10/02/2012 - 19:26:02 | D ] C:\32788R22FWJFW
                                  [29/04/2008 - 15:57:32 | D ] C:\Acer
                                  [03/02/2012 - 07:37:03 | D ] C:\ASSOCOATIONS ET AMICALES
                                  [18/09/2006 - 22:43:36 | N | 24] C:\autoexec.bat
                                  [12/02/2012 - 22:37:25 | RASHD ] C:\Autorun.inf
                                  [19/02/2010 - 11:12:29 | D ] C:\Book
                                  [10/12/2006 - 03:40:07 | D ] C:\Boot
                                  [02/11/2006 - 10:53:57 | RASH | 438840] C:\bootmgr
                                  [17/10/2011 - 10:51:18 | D ] C:\BULLETINS D'ANALYSE
                                  [17/11/2011 - 12:15:23 | D ] C:\CHLOROPHYLLE
                                  [24/01/2012 - 15:23:25 | D ] C:\COMPTES RENDUS
                                  [18/09/2006 - 22:43:37 | N | 10] C:\config.sys
                                  [04/05/2007 - 13:31:34 | N | 43008] C:\CONSOV.PR.doc
                                  [31/07/2008 - 18:12:00 | N | 59392] C:\CURRICULUM VITAE DETAILLE KAM Apollinaire.doc
                                  [05/12/2007 - 08:36:44 | N | 66048] C:\DEMANDE DE CLASSEMENT COURRIER SDRSQV.doc
                                  [17/11/2011 - 13:19:47 | D ] C:\DERNIER SPRINT
                                  [07/12/2005 - 15:48:20 | N | 2119680] C:\DIAGNOSTIC2.doc
                                  [03/02/2012 - 08:04:12 | D ] C:\DISCOURS
                                  [02/11/2006 - 13:59:44 | SHD ] C:\Documents and Settings
                                  [05/09/2011 - 12:39:44 | D ] C:\Dossier GIC
                                  [27/11/2007 - 14:40:10 | N | 50176] C:\Echantillonnage.doc
                                  [17/10/2011 - 15:39:23 | D ] C:\EQUIPEMENT LABO BIP
                                  [09/06/2008 - 14:27:16 | N | 37376] C:\ETATS PREPARATIFS ASSEMBLEE GENERALE ELITES.xls
                                  [07/05/2007 - 13:50:20 | N | 28672] C:\Exposé des motifs de la loi AB du 03 05 07.doc
                                  [05/01/2012 - 18:35:32 | D ] C:\FEUILES DE ROUTE 2012
                                  [13/01/2012 - 15:32:05 | D ] C:\Fiche des projets
                                  [09/01/2008 - 10:14:44 | N | 68096] C:\FICHE MARCHE PHYTO CAMEROUN 2007[1].doc
                                  [05/02/2012 - 12:14:20 | D ] C:\FONDS SEMENCIER
                                  [07/02/2008 - 12:24:44 | N | 67584] C:\Formulaire pour programme maïs.doc
                                  [13/02/2012 - 08:39:56 | ASH | 1600577536] C:\hiberfil.sys
                                  [12/01/2012 - 13:58:34 | N | 111959] C:\Industrie des semences.pptx
                                  [30/12/2008 - 13:45:40 | N | 0] C:\IO.SYS
                                  [30/12/2011 - 11:27:37 | D ] C:\JUSTIFS COMPTES STATION DE QUARANTAINE
                                  [03/02/2012 - 08:06:19 | D ] C:\KAM
                                  [12/02/2012 - 16:32:09 | D ] C:\Kill'em
                                  [29/11/2011 - 11:10:18 | D ] C:\KOUOGUENG ET FILS
                                  [06/05/2008 - 16:10:52 | N | 41984] C:\L'intensification agricole en 10 questions réponses.doc
                                  [02/05/2008 - 14:58:12 | N | 21373] C:\L'intensification agricole en 10 questions réponses.docx
                                  [18/03/2008 - 17:03:14 | N | 29696] C:\Le financement de l'agriculture en 10 questions réponses.doc
                                  [19/04/2008 - 23:25:04 | N | 22016] C:\Lettre de condoleances Maurice.doc
                                  [10/02/2012 - 10:34:11 | D ] C:\LETTRE DRCQ
                                  [09/02/2012 - 15:29:42 | D ] C:\LETTRES MINADER
                                  [22/05/2007 - 10:17:02 | N | 140288] C:\Libellé.doc
                                  [13/02/2012 - 08:41:28 | N | 760] C:\logfile
                                  [12/09/2011 - 16:36:12 | D ] C:\MARCHES 2011
                                  [22/11/2011 - 10:36:22 | D ] C:\MARCHES DIVERS
                                  [05/09/2011 - 18:00:07 | D ] C:\MARCHES EIC
                                  [10/11/2011 - 11:52:28 | D ] C:\Marchés publics
                                  [25/12/2008 - 07:32:32 | D ] C:\Mes documents
                                  [30/12/2008 - 13:45:40 | N | 0] C:\MSDOS.SYS
                                  [26/05/2008 - 18:34:59 | RHD ] C:\MSOCache
                                  [06/02/2012 - 20:53:38 | D ] C:\NOTES DRCQ
                                  [13/02/2012 - 08:39:55 | ASH | 1914503168] C:\pagefile.sys
                                  [16/11/2007 - 23:52:48 | N | 8676] C:\Patch.rev
                                  [15/11/2007 - 04:22:10 | N | 1263] C:\Patch2.rev
                                  [11/01/2007 - 01:52:52 | N | 631] C:\PDVD.iss
                                  [13/02/2012 - 09:37:13 | D ] C:\PERMIS D'IMPORATION
                                  [25/04/2007 - 10:10:08 | N | 65536] C:\Permis Unilever.doc
                                  [06/07/2007 - 15:49:42 | N | 135] C:\preload.rev
                                  [10/02/2012 - 16:16:43 | N | 87873] C:\Pre_Scan.txt
                                  [12/02/2012 - 22:31:45 | D ] C:\Program Files
                                  [10/02/2012 - 16:26:35 | HD ] C:\ProgramData
                                  [09/01/2008 - 10:16:50 | N | 35328] C:\PROGRAMME DEFINITIF AG du 25 01 08[1].doc
                                  [12/12/2011 - 20:27:41 | D ] C:\Projet FAO semences
                                  [10/02/2012 - 10:22:25 | D ] C:\Projets élevage
                                  [09/06/2011 - 10:09:08 | D ] C:\PV DE RECEPTION
                                  [10/02/2012 - 19:26:03 | D ] C:\Qoobox
                                  [10/05/2007 - 12:36:36 | N | 192512] C:\Questionnaire-Codex.doc
                                  [05/02/2010 - 17:02:34 | D ] C:\RAPPORTS ET COMPTES RENDUS
                                  [14/10/2011 - 13:39:05 | D ] C:\Recepisse de Declaration d'importattion
                                  [12/02/2012 - 22:33:27 | RSHD ] C:\RECYCLER
                                  [25/12/2008 - 07:32:39 | D ] C:\relating to seed production and marketing
                                  [02/02/2011 - 17:16:02 | D ] C:\Ringo
                                  [11/10/2011 - 12:35:56 | N | 2034737] C:\scanneur.jpg
                                  [27/10/2011 - 10:31:08 | D ] C:\SEMINAIRES ET ATELIETS
                                  [26/05/2008 - 17:02:36 | N | 16896] C:\Simulation budjet atelier.xls
                                  [31/01/2012 - 10:58:13 | D ] C:\STATION DE QUARANTAINE
                                  [15/06/2003 - 10:35:24 | D ] C:\Stratégie S Rural
                                  [12/02/2012 - 23:26:52 | SHD ] C:\System Volume Information
                                  [16/08/2011 - 14:06:15 | D ] C:\TAKAM STEPHEN
                                  [13/02/2012 - 10:04:28 | D ] C:\UsbFix
                                  [13/02/2012 - 09:59:39 | A | 13779] C:\UsbFix.txt
                                  [12/02/2012 - 22:37:34 | N | 5873] C:\UsbFix_Upload_Me_PC-DE-KAM.zip
                                  [29/04/2008 - 15:57:00 | D ] C:\Users
                                  [10/02/2012 - 19:44:55 | D ] C:\Windows
                                  [06/10/2008 - 11:36:42 | N | 296] C:\WMPInfo.xml
                                  [20/04/2007 - 11:36:55 | N | 4] C:\wps.dat
                                  [12/02/2012 - 14:53:50 | D ] C:\x
                                  [10/02/2012 - 15:29:58 | D ] C:\ZHP
                                  [12/02/2012 - 15:04:16 | | 165] C:\~$Industrie des semences.pptx
                                  [13/02/2012 - 10:04:28 | SHD ] D:\$RECYCLE.BIN
                                  [12/02/2012 - 22:37:25 | RASHD ] D:\Autorun.inf
                                  [29/06/2009 - 14:06:53 | N | 121856] D:\Budjet 2009 fonds semencier.doc
                                  [24/11/2009 - 14:57:05 | N | 179] D:\Disque amovible (F) - Raccourci.lnk
                                  [29/12/2007 - 03:42:07 | D ] D:\erData
                                  [11/10/2010 - 12:43:50 | N | 8591704] D:\Firefox Setup 3.6.10.exe
                                  [26/11/2009 - 19:11:30 | N | 106496] D:\Groupe II (amende).ppt
                                  [18/11/2008 - 16:45:35 | N | 276992] D:\MARCHE AGEM EQUIPEMENT LABO NATIONAL corrigé.doc
                                  [25/07/2009 - 18:09:42 | D ] D:\NFS
                                  [16/12/2010 - 07:36:54 | N | 27532080] D:\RingoDialer_1.11_with_jre.exe
                                  [29/12/2007 - 03:02:43 | SHD ] D:\System Volume Information
                                  [28/06/2011 - 14:36:56 | N | 68634] D:\The Project.zip
                                  [25/07/2009 - 17:54:39 | D ] D:\XIII

                                  ################## | Vaccin |

                                  C:\Autorun.inf -> Vaccin créé par UsbFix (El Desaparecido)
                                  D:\Autorun.inf -> Vaccin créé par UsbFix (El Desaparecido)

                                  ################## | Upload |

                                  Veuillez envoyer le fichier: C:\UsbFix_Upload_Me_PC-DE-KAM.zip
                                  http://eldesaparecido.com/upload.html
                                  Merci de votre contribution.

                                  ################## | E.O.F |
                                  0
                                  1. hello c est à toi ca ?

                                    C:\x

                                    =====

                                    supprime pre_scan , retelecharge-le puis lance-le et choisis l 'option "Kill" si ca t'est proposé sinon laisse-le bosser
                                    0
                                    1. oui, je crois que le x c'est le combofix que j'avais renommé
                                      0
                                      • 1
                                      • 2
                                      • 3
                                      • 4
                                      • 5