############################## [ UsbFix V3.023 # Scan ]
# User : Vir () # VIR
# Update on 20/05/09 by Chiquitine29, C_XX & Chimay8
# WebSite : http://pagesperso-orange.fr/NosTools/usbfix.html
# Start at: 12:17:03 | 20/05/2009
# Genuine Intel(R) CPU T2080 @ 1.73GHz
# Microsoft® Windows Vista™ Édition Familiale Premium (6.0.6001 32-bit) # Service Pack 1
# Internet Explorer 8.0.6001.18702
# Windows Firewall Status : Disabled
# AV : avast! antivirus 4.8.1229 [VPS 090327-0] 4.8.1229 [ Enabled | (!) Outdated ]
# AV : Norton Internet Security 2007 [ (!) Disabled | (!) Outdated ]
# FW : Norton Internet Security[ Enabled ]2007
# C:\ # Disque fixe local # 93,16 Go (10,09 Go free) [Vista] # NTFS
# D:\ # Disque amovible # 7,47 Go (3,18 Go free) [VIR] # FAT32
# E:\ # Disque fixe local # 91,69 Go (7,34 Go free) [Data] # NTFS
# F:\ # Disque CD-ROM # 3,31 Go (0 Mo free) [Mon disque] # CDFS
############################## [ Processus actifs ]
C:\Windows\System32\smss.exe
C:\Windows\system32\csrss.exe
C:\Windows\system32\csrss.exe
C:\Windows\system32\wininit.exe
C:\Windows\system32\winlogon.exe
C:\Windows\system32\services.exe
C:\Windows\system32\lsass.exe
C:\Windows\system32\lsm.exe
C:\Windows\system32\svchost.exe
C:\Windows\system32\svchost.exe
C:\Windows\System32\svchost.exe
C:\Windows\system32\svchost.exe
C:\Program Files\Lavasoft\Ad-Aware\AAWService.exe
C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
C:\Windows\system32\svchost.exe
C:\Windows\Explorer.EXE
C:\Windows\system32\wbem\unsecapp.exe
C:\Windows\system32\wbem\wmiprvse.exe
C:\Program Files\Lavasoft\Ad-Aware\AAWTray.exe
C:\Windows\system32\wbem\wmiprvse.exe
################## [ Registre # Startup ]
HKCU_Main: "Local Page"="C:\\Windows\\system32\\blank.htm"
HKCU_Main: "Search Page"="http://go.microsoft.com/fwlink/?LinkId=54896"
HKCU_Main: "Start Page"="http://go.microsoft.com/fwlink/?LinkId=69157"
HKCU_Main: "Start Page Redirect Cache"="http://fr.msn.com/?ocid=iehp"
HKCU_Main: "Start Page Redirect Cache_TIMESTAMP"=hex:d6,fb,d2,9c,7c,d5,c9,01
HKCU_Main: "Start Page Redirect Cache AcceptLangs"="fr"
HKLM_logon: "Userinit"="C:\\Windows\\system32\\userinit.exe,"
HKLM_logon: "LegalNoticeCaption"=""
HKLM_logon: "LegalNoticeText"=""
HKLM_Run: Windows Defender=%ProgramFiles%\Windows Defender\MSASCui.exe -hide
HKLM_Run: NvSvc=RUNDLL32.EXE C:\Windows\system32\nvsvc.dll,nvsvcStart
HKLM_Run: NvCplDaemon=RUNDLL32.EXE C:\Windows\system32\NvCpl.dll,NvStartup
HKLM_Run: NvMediaCenter=RUNDLL32.EXE C:\Windows\system32\NvMcTray.dll,NvTaskbarInit
HKLM_Run: IgfxTray=C:\Windows\system32\igfxtray.exe
HKLM_Run: HotKeysCmds=C:\Windows\system32\hkcmd.exe
HKLM_Run: Persistence=C:\Windows\system32\igfxpers.exe
HKLM_Run: SynTPEnh=C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
HKLM_Run: Camera Assistant Software="C:\Program Files\Camera Assistant Software for Toshiba\traybar.exe"
HKLM_Run: avast!=C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
HKLM_Run: MSConfig="C:\Windows\system32\msconfig.exe" /auto
HKLM_Run: NeroFilterCheck=C:\Windows\system32\NeroCheck.exe
HKLM_Run: RtHDVCpl=RtHDVCpl.exe
HKLM_Run: Symantec PIF AlertEng="C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc.exe" /a /m "C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\AlertEng.dll"
HKLM_Run: Ad-Watch=C:\Program Files\Lavasoft\Ad-Aware\AAWTray.exe
HKLM_Run: SunJavaUpdateSched="C:\Program Files\Java\jre6\bin\jusched.exe"
HKCU_Run: TOSCDSPD=TOSCDSPD.EXE
HKCU_Run: MsnMsgr="C:\Program Files\Windows Live\Messenger\MsnMsgr.Exe" /background
HKCU_Run: ehTray.exe=C:\Windows\ehome\ehTray.exe
HKCU_Run: CTSyncU.exe="C:\Program Files\Creative\Sync Manager Unicode\CTSyncU.exe"
HKCU_Run: ares="C:\Program Files\Ares\Ares.exe" -h
################## [ Fichiers # Dossiers infectieux ]
D:\autorun.inf # -> fichier appelé : "D:\icxpa.cmd" ( présent ! )
Found ! D:\icxpa.cmd
Found ! D:\autorun.inf
################## [ Registre # Clés Run infectieuses ]
Found ! HKLM\software\microsoft\security center\\ "UacDisableNotify"
# -> ( Value = 0x1 | Good = 0x0 Bad = 0x1 )
################## [ Registre # Mountpoints2 ]
HKCU\...\Explorer\MountPoints2\{14131632-82f5-11dc-a935-001b3810c714}\Shell\AutoRun\Command
HKCU\...\Explorer\MountPoints2\{14131632-82f5-11dc-a935-001b3810c714}\Shell\open\Command
HKCU\...\Explorer\MountPoints2\{350ac331-ed04-11dc-89f9-001b3810c714}\Shell\AutoRun\Command
HKCU\...\Explorer\MountPoints2\{350ac331-ed04-11dc-89f9-001b3810c714}\Shell\explore\Command
HKCU\...\Explorer\MountPoints2\{350ac331-ed04-11dc-89f9-001b3810c714}\Shell\open\Command
HKCU\...\Explorer\MountPoints2\{4e547eda-dd96-11dd-b931-001b3810c714}\Shell\AutoRun\Command
HKCU\...\Explorer\MountPoints2\{4e547eda-dd96-11dd-b931-001b3810c714}\Shell\open\Command
HKCU\...\Explorer\MountPoints2\{7cd291f6-7925-11dc-b831-001b3810c714}\Shell\AutoRun\Command
HKCU\...\Explorer\MountPoints2\{7fb5aa65-f5e3-11dd-a3b5-001b3810c714}\Shell\AutoRun\Command
HKCU\...\Explorer\MountPoints2\{92c05f17-9280-11dc-ac27-001b3810c714}\Shell\AutoRun\Command
HKCU\...\Explorer\MountPoints2\{a55cd2be-32fd-11de-8d9b-001b3810c714}\Shell\AutoRun\Command
HKCU\...\Explorer\MountPoints2\{a60e099e-372d-11dd-a978-001b3810c714}\Shell\AutoRun\Command
HKCU\...\Explorer\MountPoints2\{a60e099e-372d-11dd-a978-001b3810c714}\Shell\open\Command
HKCU\...\Explorer\MountPoints2\{e1c65e08-1a20-11dd-b02a-001b3810c714}\Shell\AutoRun\Command
HKCU\...\Explorer\MountPoints2\{e1c65e08-1a20-11dd-b02a-001b3810c714}\Shell\explore\Command
HKCU\...\Explorer\MountPoints2\{e1c65e08-1a20-11dd-b02a-001b3810c714}\Shell\open\Command
HKCU\...\Explorer\MountPoints2\{e6e1d7dc-dbb9-11dd-8eee-001b3810c714}\Shell\AutoRun\Command
################## [ ! Fin du rapport # UsbFix V3.023 ! ]