############################## [ UsbFix V3.016 # Scan ]
# User : Daphné Orenge (Administrateurs) # DAPHNÉ
# Update on 02/05/09 by Chiquitine29, C_XX & Chimay8
# WebSite :
http://pagesperso-orange.fr/NosTools/usbfix.html
# Start at: 22:33:12 | 05/05/2009
# Intel(R) Atom(TM) CPU N270 @ 1.60GHz
# Microsoft Windows XP Édition familiale (5.1.2600 32-bit) # Service Pack 3
# Internet Explorer 7.0.5730.13
# Windows Firewall Status : Enabled
# AV : avast! antivirus 4.8.1335 [VPS 090505-0] 4.8.1335 [ Enabled | Updated ]
# C:\ # Disque fixe local # 71,04 Go (50,29 Go free) # NTFS
# D:\ # Disque fixe local # 72 Go (4,1 Go free) [Données] # NTFS
# E:\ # Disque CD-ROM
# F:\ # Disque amovible # 963,73 Mo (960,69 Mo free) # FAT
# G:\ # Disque amovible # 963,73 Mo (867,12 Mo free) # FAT
############################## [ Processus actifs ]
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\csrss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\WIDCOMM\Bluetooth Software\bin\btwdins.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
C:\Program Files\Alwil Software\Avast4\ashServ.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Java\jre1.5.0\bin\jusched.exe
C:\WINDOWS\RTHDCPL.EXE
C:\Program Files\Samsung\Samsung EDS\EDSAgent.exe
C:\WINDOWS\system32\igfxtray.exe
C:\WINDOWS\system32\igfxpers.exe
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\Program Files\Samsung\Samsung Battery Manager\BatteryManager.exe
C:\WINDOWS\system32\igfxsrvc.exe
C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
C:\Program Files\LogMeIn\x86\LogMeInSystray.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Google\Update\GoogleUpdate.exe
C:\Program Files\Samsung\Easy Display Manager\dmhkcore.exe
C:\Program Files\SAMSUNG\MagicKBD\MagicKBD.exe
C:\Program Files\Windows Live\Messenger\msnmsgr.exe
C:\Program Files\SAMSUNG\MagicKBD\PerformanceManager.exe
C:\Program Files\Microsoft ActiveSync\Wcescomm.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\PowerArchiver\PASTARTER.EXE
C:\Program Files\DAEMON Tools Lite\daemon.exe
C:\Program Files\Windows Media Player\WMPNSCFG.exe
C:\Program Files\LogMeIn\x86\LMIGuardian.exe
C:\PROGRA~1\MICROS~3\rapimgr.exe
C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\samsung\Samsung Network Manager\SNMWLANService.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\TUProgSt.exe
C:\WINDOWS\system32\RUNDLL32.EXE
C:\Program Files\Windows Media Player\WMPNetwk.exe
C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
C:\WINDOWS\System32\alg.exe
C:\WINDOWS\system32\igfxext.exe
C:\WINDOWS\system32\wbem\wmiprvse.exe
################## [ Registre # Startup ]
HKCU_Main: "Local Page"="C:\\WINDOWS\\system32\\blank.htm"
HKCU_Main: "Search Page"="
http://www.google.com"
HKCU_Main: "Start Page"="
http://www.microsoft.com/isapi/redir.dll?prd=ie&pver=6&ar=msnhome"
HKLM_logon: "Userinit"="C:\\WINDOWS\\system32\\userinit.exe,"
HKLM_logon: "DefaultUserName"="Daphn‚ Orenge"
HKLM_logon: "AltDefaultUserName"="Daphn‚ Orenge"
HKLM_logon: "LegalNoticeCaption"=""
HKLM_logon: "LegalNoticeText"=""
HKLM_Run: SunJavaUpdateSched=C:\Program Files\Java\jre1.5.0\bin\jusched.exe
HKLM_Run: RTHDCPL=RTHDCPL.EXE
HKLM_Run: Alcmtr=ALCMTR.EXE
HKLM_Run: EDS=C:\Program Files\Samsung\Samsung EDS\EDSAgent.exe
HKLM_Run: IgfxTray=C:\WINDOWS\system32\igfxtray.exe
HKLM_Run: HotKeysCmds=C:\WINDOWS\system32\hkcmd.exe
HKLM_Run: Persistence=C:\WINDOWS\system32\igfxpers.exe
HKLM_Run: SynTPEnh=C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
HKLM_Run: DMHotKey=C:\Program Files\Samsung\Easy Display Manager\DMLoader.exe
HKLM_Run: BatteryManager=C:\Program Files\Samsung\Samsung Battery Manager\BatteryManager.exe
HKLM_Run: MagicKeyboard=C:\Program Files\SAMSUNG\MagicKBD\PreMKBD.exe
HKLM_Run: SUPBackGround=C:\Program Files\Samsung\Samsung Update Plus\SUPBackGround.exe
HKLM_Run: avast!=C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
HKLM_Run: LogMeIn GUI="C:\Program Files\LogMeIn\x86\LogMeInSystray.exe"
HKLM_Run: HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run\OptionalComponents=
HKCU_Run: msnmsgr="C:\Program Files\Windows Live\Messenger\msnmsgr.exe" /background
HKCU_Run: H/PC Connection Agent="C:\Program Files\Microsoft ActiveSync\Wcescomm.exe"
HKCU_Run: ctfmon.exe=C:\WINDOWS\system32\ctfmon.exe
HKCU_Run: PowerArchiver Tray=C:\Program Files\PowerArchiver\PASTARTER.EXE
HKCU_Run: DAEMON Tools Lite="C:\Program Files\DAEMON Tools Lite\daemon.exe" -autorun
HKCU_Run: WMPNSCFG=C:\Program Files\Windows Media Player\WMPNSCFG.exe
HKCU_Run: cdoosoft=C:\WINDOWS\system32\olhrwef.exe
################## [ Informations ]
################## [ Fichiers # Dossiers infectieux ]
Found ! C:\WINDOWS\system32\nmdfgds0.dll
################## [ Registre # Clés Run infectieuses ]
Found ! HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Run "cdoosoft"
Found ! HKU\S-1-5-21-1760337732-58344948-399447844-1005\SOFTWARE\Microsoft\Windows\CurrentVersion\Run "cdoosoft"
################## [ Registre # Mountpoints2 ]
HKCU\Software\Microsoft\....\MountPoints2\{088727b6-1016-11de-b0f3-001377d40c32}\Shell\AutoRun\command
HKCU\Software\Microsoft\....\MountPoints2\{088727b6-1016-11de-b0f3-001377d40c32}\Shell\explore\Command
HKCU\Software\Microsoft\....\MountPoints2\{088727b6-1016-11de-b0f3-001377d40c32}\Shell\open\Command
HKCU\Software\Microsoft\....\MountPoints2\{088727ba-1016-11de-b0f3-001377d40c32}\Shell\AutoRun\command
HKCU\Software\Microsoft\....\MountPoints2\{088727ba-1016-11de-b0f3-001377d40c32}\Shell\explore\Command
HKCU\Software\Microsoft\....\MountPoints2\{088727ba-1016-11de-b0f3-001377d40c32}\Shell\open\Command
HKCU\Software\Microsoft\....\MountPoints2\{22b711c2-1dc8-11de-b120-001377d40c32}\Shell\AutoRun\command
HKCU\Software\Microsoft\....\MountPoints2\{22b711c2-1dc8-11de-b120-001377d40c32}\Shell\explore\Command
HKCU\Software\Microsoft\....\MountPoints2\{22b711c2-1dc8-11de-b120-001377d40c32}\Shell\open\Command
HKCU\Software\Microsoft\....\MountPoints2\{22b711c6-1dc8-11de-b120-001377d40c32}\Shell\AutoRun\command
HKCU\Software\Microsoft\....\MountPoints2\{22b711c6-1dc8-11de-b120-001377d40c32}\Shell\open\Command
HKCU\Software\Microsoft\....\MountPoints2\{6e4a6ac6-241b-11de-b13b-001377d40c32}\Shell\AutoRun\command
HKCU\Software\Microsoft\....\MountPoints2\{6e4a6ac6-241b-11de-b13b-001377d40c32}\Shell\open\Command
HKCU\Software\Microsoft\....\MountPoints2\{93a999d2-242d-11de-b13c-001377d40c32}\Shell\AutoRun\command
HKCU\Software\Microsoft\....\MountPoints2\{93a999d2-242d-11de-b13c-001377d40c32}\Shell\explore\Command
HKCU\Software\Microsoft\....\MountPoints2\{93a999d2-242d-11de-b13c-001377d40c32}\Shell\open\Command
HKCU\Software\Microsoft\....\MountPoints2\{ab92097c-0d77-11de-b0dd-002269e7051b}\Shell\AutoRun\command
HKCU\Software\Microsoft\....\MountPoints2\{ab92097c-0d77-11de-b0dd-002269e7051b}\Shell\open\Command
HKCU\Software\Microsoft\....\MountPoints2\{ae4932c3-3972-11de-b17e-00242b2e2ce8}\Shell\AutoRun\command
HKCU\Software\Microsoft\....\MountPoints2\{ae4932c3-3972-11de-b17e-00242b2e2ce8}\Shell\explore\Command
HKCU\Software\Microsoft\....\MountPoints2\{ae4932c3-3972-11de-b17e-00242b2e2ce8}\Shell\open\Command
HKCU\Software\Microsoft\....\MountPoints2\{d8077350-38d5-11de-b174-001377d40c32}\Shell\AutoRun\command
HKCU\Software\Microsoft\....\MountPoints2\{d8077350-38d5-11de-b174-001377d40c32}\Shell\open\Command
HKCU\Software\Microsoft\....\MountPoints2\{f292398e-22a4-11de-b131-001377d40c32}\Shell\AutoRun\command
HKCU\Software\Microsoft\....\MountPoints2\{f292398e-22a4-11de-b131-001377d40c32}\Shell\explore\Command
HKCU\Software\Microsoft\....\MountPoints2\{f292398e-22a4-11de-b131-001377d40c32}\Shell\open\Command
################## [ ! Fin du rapport # UsbFix V3.016 ! ]