############################## [ UsbFix V3.016 # Scan ]
# User : Administrateur (Administrateurs) # JULIEN
# Update on 02/05/09 by Chiquitine29, C_XX & Chimay8
# WebSite :
http://pagesperso-orange.fr/NosTools/usbfix.html
# Start at: 11:09:10 | 05/05/2009
# Intel(R) Pentium(R) 4 CPU 2.00GHz
# Microsoft Windows XP Professionnel (5.1.2600 32-bit) # Service Pack 3
# Internet Explorer 6.0.2900.5512
# Windows Firewall Status : Disabled
# AV : AVG 7.5.476 7.5.476 [ Enabled | (!) Outdated ]
# AV : Avira AntiVir PersonalEdition Classic 8.0.1.30 [ (!) Disabled | (!) Outdated ]
# FW : Norton AntiVirus[ (!) Disabled ]15.5.0.23
# A:\ # Lecteur de disquettes 3 ½ pouces
# C:\ # Disque fixe local # 48,82 Go (1,46 Go free) # FAT32
# D:\ # Disque fixe local # 25,67 Go (14,13 Go free) # NTFS
# E:\ # Disque CD-ROM
# F:\ # Disque amovible # 488,01 Mo (394 Mo free) # FAT32
############################## [ Processus actifs ]
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\csrss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Fichiers communs\Symantec Shared\ccSvcHst.exe
C:\Program Files\Avira\AntiVir PersonalEdition Classic\sched.exe
C:\WINDOWS\system32\issat.exe
C:\WINDOWS\system32\runouce.exe
C:\Program Files\AVG\Identity Protection\agent\bin\AVGIDSUI.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\DNA\btdna.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\spool\drivers\w32x86\2\CAPPSWN.EXE
C:\WINDOWS\system32\spool\drivers\w32x86\2\CAPPSWN.EXE
C:\Program Files\Avira\AntiVir PersonalEdition Classic\avguard.exe
C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe
C:\Program Files\AVG\Identity Protection\agent\Bin\AVGIDSWatcher.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\AVG\Identity Protection\agent\Bin\AVGIDSAgent.exe
C:\PROGRA~1\BANDOO\BANDOO.EXE
C:\Program Files\AVG\Identity Protection\agent\bin\AVGIDSMonitor.exe
C:\WINDOWS\System32\svchost.exe
C:\Documents and Settings\Administrateur.DELL\Bureau\xp\ToolsCleaner2.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Documents and Settings\Administrateur.DELL\Bureau\BitTorrent-6.1.2(2).exe
C:\Documents and Settings\Administrateur.DELL\Local Settings\Temporary Internet Files\Content.IE5\01234567\IE7-WindowsXP-x86-fra[1].exe
d:\fa49783ecf129fe6f3bd9c\update\iesetup.exe
C:\WINDOWS\system32\wbem\wmiprvse.exe
################## [ Registre # Startup ]
HKCU_Main: "Local Page"="C:\\WINDOWS\\system32\\blank.htm"
HKCU_Main: "Search Page"="
http://www.google.com"
HKCU_Main: "Start Page"="
http://www.yahoo.fr/"
HKLM_logon: "Userinit"="C:\\WINDOWS\\system32\\userinit.exe,"
HKLM_logon: "DefaultUserName"="Administrateur"
HKLM_logon: "AltDefaultUserName"="Administrateur"
HKLM_logon: "LegalNoticeCaption"=""
HKLM_logon: "LegalNoticeText"=""
HKLM_Run: CAPON=C:\WINDOWS\system32\Spool\Drivers\w32x86\2\CAPONN.EXE
HKLM_Run: WpsRePsw=C:\WINDOWS\System32\spool\DRIVERS\W32X86\2\WpsRePsw.EXE
HKLM_Run: WinampAgent="C:\Program Files\Winamp\winampa.exe"
HKLM_Run: FrameWorkService=
HKLM_Run: issat=C:\WINDOWS\system32\issat.exe
HKLM_Run: Runonce=C:\WINDOWS\system32\runouce.exe
HKLM_Run: ccApp="C:\Program Files\Fichiers communs\Symantec Shared\ccApp.exe"
HKLM_Run: avgnt="C:\Program Files\Avira\AntiVir PersonalEdition Classic\avgnt.exe" /min
HKLM_Run: KernelFaultCheck=%systemroot%\system32\dumprep 0 -k
HKLM_Run: AVGIDS="C:\Program Files\AVG\Identity Protection\agent\bin\AVGIDSUI.exe"
HKLM_Run: HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run\OptionalComponents=
HKCU_Run: CTFMON.EXE=C:\WINDOWS\system32\ctfmon.exe
HKCU_Run: FrameWorkService=
HKCU_Run: BitTorrent DNA="C:\Program Files\DNA\btdna.exe"
################## [ Informations ]
################## [ Fichiers # Dossiers infectieux ]
Found ! "C:\Documents and Settings\Administrateur.DELL\RavMonLog"
Found ! C:\DOCUME~1\ADMINI~1.DEL\LOCALS~1\Temp\IncrediMail\IMInstall\data\lex\lex.exe
Found ! C:\DOCUME~1\ADMINI~1.DEL\LOCALS~1\Temp\NERO14399\SetupX.exe
Found ! C:\DOCUME~1\ADMINI~1.DEL\LOCALS~1\Temp\NERO14399\Data\Redist\DirectX\DirectX.exe
Found ! C:\DOCUME~1\ADMINI~1.DEL\LOCALS~1\Temp\NAV15.5.0.23\NAV\External\CommonFi\SYMSHARE\ncwHyPEX\ncwHyPEX.exe
Found ! C:\DOCUME~1\ADMINI~1.DEL\LOCALS~1\Temp\NAV15.5.0.23\Support\Help\Help.exe
Found ! C:\DOCUME~1\ADMINI~1.DEL\LOCALS~1\Temp\NAV15.5.0.23\Support\LUpdate\WLUEX\WLUEX.exe
C:\autorun.inf # -> fichier appelé : "C:\host232.exe" ( présent ! )
Found ! C:\autorun.inf
D:\autorun.inf # -> fichier appelé : "D:\host232.exe" ( présent ! )
Found ! D:\Setup.exe
Found ! D:\autorun.inf
F:\autorun.inf # -> fichier appelé : "F:\wkbyk.pif" ( absent ! )
Found ! F:\0xuc.com
################## [ Registre # Clés Run infectieuses ]
Found ! HKLM\software\microsoft\security center\\ "AntiVirusDisableNotify"
# -> ( Value = 0x1 | Good = 0x0 Bad = 0x1 )
Found ! HKLM\software\microsoft\security center\\ "AntiVirusOverride"
# -> ( Value = 0x1 | Good = 0x0 Bad = 0x1 )
Found ! HKLM\software\microsoft\security center\\ "UpdatesDisableNotify"
# -> ( Value = 0x1 | Good = 0x0 Bad = 0x1 )
Found ! HKLM\Software\Microsoft\Windows\CurrentVersion\Run "FrameWorkService"
Found ! HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Run "FrameWorkService"
Found ! HKU\S-1-5-21-583907252-926492609-839522115-500\SOFTWARE\Microsoft\Windows\CurrentVersion\Run "FrameWorkService"
################## [ Registre # Mountpoints2 ]
HKCU\Software\Microsoft\....\MountPoints2\{06da70c0-8945-11dc-8790-00c0a88e9ea7}\Shell\Auto\command
HKCU\Software\Microsoft\....\MountPoints2\{06da70c0-8945-11dc-8790-00c0a88e9ea7}\Shell\AutoRun\command
HKCU\Software\Microsoft\....\MountPoints2\{0bb32d18-75cb-11dc-98a6-00c0a88e9ea7}\Shell\Auto\command
HKCU\Software\Microsoft\....\MountPoints2\{0bb32d18-75cb-11dc-98a6-00c0a88e9ea7}\Shell\AutoRun\command
HKCU\Software\Microsoft\....\MountPoints2\{0bfdbad3-86c8-11dc-98bd-00c0a88e9ea7}\Shell\Auto\command
HKCU\Software\Microsoft\....\MountPoints2\{0bfdbad3-86c8-11dc-98bd-00c0a88e9ea7}\Shell\AutoRun\command
HKCU\Software\Microsoft\....\MountPoints2\{11a1acce-8eb0-11dc-879c-00c0a88e9ea7}\Shell\AutoRun\command
HKCU\Software\Microsoft\....\MountPoints2\{11a1acce-8eb0-11dc-879c-00c0a88e9ea7}\Shell\explore\Command
HKCU\Software\Microsoft\....\MountPoints2\{11a1acce-8eb0-11dc-879c-00c0a88e9ea7}\Shell\open\Command
HKCU\Software\Microsoft\....\MountPoints2\{1464b8da-719f-11dc-988d-00c0a88e9ea7}\Shell\AutoRun\command
HKCU\Software\Microsoft\....\MountPoints2\{1464b8da-719f-11dc-988d-00c0a88e9ea7}\Shell\explore\Command
HKCU\Software\Microsoft\....\MountPoints2\{1464b8da-719f-11dc-988d-00c0a88e9ea7}\Shell\open\Command
HKCU\Software\Microsoft\....\MountPoints2\{1636c3b7-fe97-11dd-8a76-00c0a88e9ea7}\Shell\AutoRun\command
HKCU\Software\Microsoft\....\MountPoints2\{1636c3b7-fe97-11dd-8a76-00c0a88e9ea7}\Shell\open\Command
HKCU\Software\Microsoft\....\MountPoints2\{208ae3aa-b56a-11dc-87f0-00c0a88e9ea7}\Shell\AutoRun\command
HKCU\Software\Microsoft\....\MountPoints2\{25ef8862-a422-11dd-89bf-00c0a88e9ea7}\Shell\AutoRun\command
HKCU\Software\Microsoft\....\MountPoints2\{25ef8862-a422-11dd-89bf-00c0a88e9ea7}\Shell\explore\Command
HKCU\Software\Microsoft\....\MountPoints2\{25ef8862-a422-11dd-89bf-00c0a88e9ea7}\Shell\open\Command
HKCU\Software\Microsoft\....\MountPoints2\{286d4fb4-a581-11dc-87ce-00c0a88e9ea7}\Shell\Auto\command
HKCU\Software\Microsoft\....\MountPoints2\{286d4fb4-a581-11dc-87ce-00c0a88e9ea7}\Shell\AutoRun\command
HKCU\Software\Microsoft\....\MountPoints2\{28c2c1bb-9c22-11dd-89b1-00c0a88e9ea7}\Shell\AutoRun\command
HKCU\Software\Microsoft\....\MountPoints2\{28c2c1bb-9c22-11dd-89b1-00c0a88e9ea7}\Shell\explore\Command
HKCU\Software\Microsoft\....\MountPoints2\{28c2c1bb-9c22-11dd-89b1-00c0a88e9ea7}\Shell\open\Command
HKCU\Software\Microsoft\....\MountPoints2\{2abd83ac-9830-11dc-87b1-00c0a88e9ea7}\Shell\Auto\command
HKCU\Software\Microsoft\....\MountPoints2\{2abd83ac-9830-11dc-87b1-00c0a88e9ea7}\Shell\AutoRun\command
HKCU\Software\Microsoft\....\MountPoints2\{2ed64aac-9e9b-11dc-87bc-00c0a88e9ea7}\Shell\Auto\command
HKCU\Software\Microsoft\....\MountPoints2\{2ed64aac-9e9b-11dc-87bc-00c0a88e9ea7}\Shell\AutoRun\command
HKCU\Software\Microsoft\....\MountPoints2\{38f69044-9ce0-11dc-87b6-00c0a88e9ea7}\Shell\Auto\command
HKCU\Software\Microsoft\....\MountPoints2\{38f69044-9ce0-11dc-87b6-00c0a88e9ea7}\Shell\AutoRun\command
HKCU\Software\Microsoft\....\MountPoints2\{40f1568d-7290-11dc-989b-00c0a88e9ea7}\Shell\Auto\command
HKCU\Software\Microsoft\....\MountPoints2\{40f1568d-7290-11dc-989b-00c0a88e9ea7}\Shell\AutoRun\command
HKCU\Software\Microsoft\....\MountPoints2\{43dc21b5-d5b4-11dd-8a24-00c0a88e9ea7}\Shell\AutoRun\command
HKCU\Software\Microsoft\....\MountPoints2\{4d95d8b8-f8e8-11dd-8a64-00c0a88e9ea7}\Shell\AutoRun\command
HKCU\Software\Microsoft\....\MountPoints2\{4d95d8b8-f8e8-11dd-8a64-00c0a88e9ea7}\Shell\open\Command
HKCU\Software\Microsoft\....\MountPoints2\{509fdfce-fc67-11dd-8a6e-00c0a88e9ea7}\Shell\Auto\command
HKCU\Software\Microsoft\....\MountPoints2\{509fdfce-fc67-11dd-8a6e-00c0a88e9ea7}\Shell\AutoRun\command
HKCU\Software\Microsoft\....\MountPoints2\{509fdfce-fc67-11dd-8a6e-00c0a88e9ea7}\Shell\explore\Command
HKCU\Software\Microsoft\....\MountPoints2\{509fdfce-fc67-11dd-8a6e-00c0a88e9ea7}\Shell\find\Command
HKCU\Software\Microsoft\....\MountPoints2\{509fdfce-fc67-11dd-8a6e-00c0a88e9ea7}\Shell\open\Command
HKCU\Software\Microsoft\....\MountPoints2\{56098df9-a028-11dc-87c3-00c0a88e9ea7}\Shell\Auto\command
HKCU\Software\Microsoft\....\MountPoints2\{56098df9-a028-11dc-87c3-00c0a88e9ea7}\Shell\AutoRun\command
HKCU\Software\Microsoft\....\MountPoints2\{571bef4a-b065-11dc-87e6-00c0a88e9ea7}\Shell\Auto\command
HKCU\Software\Microsoft\....\MountPoints2\{571bef4a-b065-11dc-87e6-00c0a88e9ea7}\Shell\AutoRun\command
HKCU\Software\Microsoft\....\MountPoints2\{67e11d88-16c6-11dd-88a8-00c0a88e9ea7}\Shell\AutoRun\command
HKCU\Software\Microsoft\....\MountPoints2\{67e11d88-16c6-11dd-88a8-00c0a88e9ea7}\Shell\explore\Command
HKCU\Software\Microsoft\....\MountPoints2\{67e11d88-16c6-11dd-88a8-00c0a88e9ea7}\Shell\open\Command
HKCU\Software\Microsoft\....\MountPoints2\{6b3293b0-e603-11dd-8a42-00c0a88e9ea7}\Shell\AutoRun\command
HKCU\Software\Microsoft\....\MountPoints2\{6b3293b0-e603-11dd-8a42-00c0a88e9ea7}\Shell\explore\Command
HKCU\Software\Microsoft\....\MountPoints2\{6b3293b0-e603-11dd-8a42-00c0a88e9ea7}\Shell\open\Command
HKCU\Software\Microsoft\....\MountPoints2\{88c515d4-3814-11de-8b0b-00c0a88e9ea7}\Shell\AutoRun\command
HKCU\Software\Microsoft\....\MountPoints2\{88c515d4-3814-11de-8b0b-00c0a88e9ea7}\Shell\explore\Command
HKCU\Software\Microsoft\....\MountPoints2\{88c515d4-3814-11de-8b0b-00c0a88e9ea7}\Shell\open\Command
HKCU\Software\Microsoft\....\MountPoints2\{89ef7a92-2f29-11de-8ae8-00c0a88e9ea7}\Shell\AutoRun\command
HKCU\Software\Microsoft\....\MountPoints2\{89ef7a92-2f29-11de-8ae8-00c0a88e9ea7}\Shell\explore\Command
HKCU\Software\Microsoft\....\MountPoints2\{89ef7a92-2f29-11de-8ae8-00c0a88e9ea7}\Shell\open\Command
HKCU\Software\Microsoft\....\MountPoints2\{a072e4e2-703a-11dd-894d-00c0a88e9ea7}\Shell\AutoRun\command
HKCU\Software\Microsoft\....\MountPoints2\{a072e4e2-703a-11dd-894d-00c0a88e9ea7}\Shell\explore\Command
HKCU\Software\Microsoft\....\MountPoints2\{a072e4e2-703a-11dd-894d-00c0a88e9ea7}\Shell\open\Command
HKCU\Software\Microsoft\....\MountPoints2\{b763dc45-e37a-11dc-8865-00c0a88e9ea7}\Shell\AutoRun\command
HKCU\Software\Microsoft\....\MountPoints2\{b763dc46-e37a-11dc-8865-00c0a88e9ea7}\Shell\Auto\command
HKCU\Software\Microsoft\....\MountPoints2\{b763dc46-e37a-11dc-8865-00c0a88e9ea7}\Shell\AutoRun\command
HKCU\Software\Microsoft\....\MountPoints2\{b8099310-2919-11de-8ad4-00c0a88e9ea7}\Shell\AutoRun\command
HKCU\Software\Microsoft\....\MountPoints2\{b8099310-2919-11de-8ad4-00c0a88e9ea7}\Shell\explore\Command
HKCU\Software\Microsoft\....\MountPoints2\{b8099310-2919-11de-8ad4-00c0a88e9ea7}\Shell\open\Command
HKCU\Software\Microsoft\....\MountPoints2\{b88379ee-c9b2-11dd-8a10-00c0a88e9ea7}\Shell\AutoRun\command
HKCU\Software\Microsoft\....\MountPoints2\{b88379ee-c9b2-11dd-8a10-00c0a88e9ea7}\Shell\explore\Command
HKCU\Software\Microsoft\....\MountPoints2\{b88379ee-c9b2-11dd-8a10-00c0a88e9ea7}\Shell\open\Command
HKCU\Software\Microsoft\....\MountPoints2\{b88379ef-c9b2-11dd-8a10-00c0a88e9ea7}\Shell\AutoRun\command
HKCU\Software\Microsoft\....\MountPoints2\{b88379ef-c9b2-11dd-8a10-00c0a88e9ea7}\Shell\explore\Command
HKCU\Software\Microsoft\....\MountPoints2\{b88379ef-c9b2-11dd-8a10-00c0a88e9ea7}\Shell\open\Command
HKCU\Software\Microsoft\....\MountPoints2\{cbe65652-74d4-11dc-98a4-00c0a88e9ea7}\Shell\Auto\command
HKCU\Software\Microsoft\....\MountPoints2\{cbe65652-74d4-11dc-98a4-00c0a88e9ea7}\Shell\AutoRun\command
HKCU\Software\Microsoft\....\MountPoints2\{cc409b0a-6f8b-11dd-894b-00c0a88e9ea7}\Shell\Auto\command
HKCU\Software\Microsoft\....\MountPoints2\{cc409b0a-6f8b-11dd-894b-00c0a88e9ea7}\Shell\AutoRun\command
HKCU\Software\Microsoft\....\MountPoints2\{d0a89b30-a8c4-11dd-89d1-00c0a88e9ea7}\Shell\AutoRun\command
HKCU\Software\Microsoft\....\MountPoints2\{d0a89b30-a8c4-11dd-89d1-00c0a88e9ea7}\Shell\explore\Command
HKCU\Software\Microsoft\....\MountPoints2\{d0a89b30-a8c4-11dd-89d1-00c0a88e9ea7}\Shell\open\Command
HKCU\Software\Microsoft\....\MountPoints2\{d17d3053-8df8-11dd-8990-00c0a88e9ea7}\Shell\AutoRun\command
HKCU\Software\Microsoft\....\MountPoints2\{d17d3053-8df8-11dd-8990-00c0a88e9ea7}\Shell\explore\Command
HKCU\Software\Microsoft\....\MountPoints2\{d17d3053-8df8-11dd-8990-00c0a88e9ea7}\Shell\open\Command
HKCU\Software\Microsoft\....\MountPoints2\{d711c260-941d-11dc-87a7-00c0a88e9ea7}\Shell\Auto\command
HKCU\Software\Microsoft\....\MountPoints2\{d711c260-941d-11dc-87a7-00c0a88e9ea7}\Shell\AutoRun\command
HKCU\Software\Microsoft\....\MountPoints2\{d711c261-941d-11dc-87a7-00c0a88e9ea7}\Shell\Auto\command
HKCU\Software\Microsoft\....\MountPoints2\{d711c261-941d-11dc-87a7-00c0a88e9ea7}\Shell\AutoRun\command
HKCU\Software\Microsoft\....\MountPoints2\{dd651aad-c377-11dc-880f-00c0a88e9ea7}\Shell\Auto\command
HKCU\Software\Microsoft\....\MountPoints2\{dd651aad-c377-11dc-880f-00c0a88e9ea7}\Shell\AutoRun\command
HKCU\Software\Microsoft\....\MountPoints2\{dd651aae-c377-11dc-880f-00c0a88e9ea7}\Shell\Auto\command
HKCU\Software\Microsoft\....\MountPoints2\{dd651aae-c377-11dc-880f-00c0a88e9ea7}\Shell\AutoRun\command
HKCU\Software\Microsoft\....\MountPoints2\{e11120ba-d36d-11dd-8a21-00c0a88e9ea7}\Shell\AutoRun\command
HKCU\Software\Microsoft\....\MountPoints2\{e7e75fef-908f-11dd-8995-00c0a88e9ea7}\Shell\AutoRun\command
HKCU\Software\Microsoft\....\MountPoints2\{eb76f9be-04a6-11de-8a86-00c0a88e9ea7}\Shell\AutoRun\command
HKCU\Software\Microsoft\....\MountPoints2\{fd6a06ce-227f-11de-8ac4-00c0a88e9ea7}\Shell\AutoRun\command
HKCU\Software\Microsoft\....\MountPoints2\{fdbb9982-b964-11dd-89f2-00c0a88e9ea7}\Shell\AutoRun\command
HKCU\Software\Microsoft\....\MountPoints2\{fdbb9982-b964-11dd-89f2-00c0a88e9ea7}\Shell\explore\Command
HKCU\Software\Microsoft\....\MountPoints2\{fdbb9982-b964-11dd-89f2-00c0a88e9ea7}\Shell\open\Command
################## [ ! Fin du rapport # UsbFix V3.016 ! ]