voila le log
############################## | UsbFix V6.023 |
User : nosgraf (Administrateurs) # PC-DE-NOSGRAF
Update on 25/08/09 by Chiquitine29
Start at: 15:01:52 | 26/08/2009
Website :
http://pagesperso-orange.fr/NosTools/index.html
Intel(R) Pentium(R) Dual CPU T2370 @ 1.73GHz
Microsoft® Windows Vista™ Édition Familiale Premium (6.0.6001 32-bit) # Service Pack 1
Internet Explorer 7.0.6001.18000
Windows Firewall Status : Enabled
AV : avast! antivirus 4.8.1195 [VPS 090220-0] 4.8.1195 [ Enabled | Updated ]
C:\ -> Disque fixe local # 224,88 Go (3,39 Go free) [HDD] # NTFS
D:\ -> Disque CD-ROM
############################## | Processus actifs |
C:\Windows\System32\smss.exe
C:\Windows\system32\csrss.exe
C:\Windows\system32\wininit.exe
C:\Windows\system32\csrss.exe
C:\Windows\system32\services.exe
C:\Windows\system32\lsass.exe
C:\Windows\system32\lsm.exe
C:\Windows\system32\winlogon.exe
C:\Windows\system32\svchost.exe
C:\Windows\system32\svchost.exe
C:\Windows\System32\svchost.exe
C:\Windows\System32\svchost.exe
C:\Windows\System32\svchost.exe
C:\Windows\system32\svchost.exe
C:\Windows\system32\SLsvc.exe
C:\Windows\system32\svchost.exe
C:\Windows\system32\svchost.exe
C:\Windows\System32\spoolsv.exe
C:\Windows\system32\svchost.exe
C:\Windows\system32\svchost.exe
C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
C:\Program Files\Alwil Software\Avast4\ashServ.exe
C:\PROGRA~1\COMMON~1\France Telecom\Shared Modules\FTRTSVC\0\FTRTSVC.exe
C:\Program Files\Intel\Intel Matrix Storage Manager\Iaantmon.exe
C:\Windows\System32\svchost.exe
c:\Program Files\Microsoft SQL Server\MSSQL10.SQLEXPRESS\MSSQL\Binn\sqlservr.exe
C:\Windows\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\SMSvcHost.exe
C:\Windows\system32\svchost.exe
C:\Windows\System32\tcpsvcs.exe
c:\Program Files\Microsoft SQL Server\90\Shared\sqlwriter.exe
C:\Windows\system32\svchost.exe
C:\Windows\system32\svchost.exe
C:\Windows\System32\svchost.exe
C:\Windows\system32\SearchIndexer.exe
C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
C:\Windows\system32\taskeng.exe
C:\Windows\system32\Dwm.exe
C:\Windows\Explorer.EXE
C:\Program Files\Alwil Software\Avast4\ashDisp.exe
C:\Program Files\CardDetector\HUAWEI\CardDetector.exe
C:\Program Files\Windows Media Player\wmpnscfg.exe
C:\Program Files\Windows Media Player\wmpnetwk.exe
C:\Program Files\Windows Live\Messenger\msnmsgr.exe
C:\Windows\system32\taskeng.exe
C:\Program Files\Windows Live\Contacts\wlcomm.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\Windows Defender\MSASCui.exe
C:\Windows\system32\conime.exe
C:\Windows\system32\SearchProtocolHost.exe
C:\Windows\system32\SearchFilterHost.exe
C:\Windows\system32\wbem\wmiprvse.exe
################## | Fichiers # Dossiers infectieux |
Présent ! C:\update.exe
Présent ! C:\Config\S-1-5-21-1482476501-1644491937-682003330-1013
Présent ! C:\Config\S-1-5-21-1482476501-1644491937-682003330-1013\Desktop.ini
################## | Suspect ! ... |
http://www.virustotal.com |
################## | Registre # Clés Run infectieuses |
################## | Registre # Mountpoints2 |
HKCU\..\..\Explorer\MountPoints2\D
shell\AutoRun\command =D:\setupss.exe
HKCU\..\..\Explorer\MountPoints2\H
shell\AutoRun\command =H:\ClickMe.exe
HKCU\..\..\Explorer\MountPoints2\{27a2a7b0-6427-11dd-9bb9-001e6811489a}
shell\AutoRun\command =
shell\explore\Command =
shell\open\Command =
HKCU\..\..\Explorer\MountPoints2\{38e64842-a78a-11dd-b953-0017c41c5895}
shell\AutoRun\command =C:\Windows\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL copy.exe
HKCU\..\..\Explorer\MountPoints2\{40f6e2e3-2732-11dd-88e2-0017c41c5895}
shell\AutoRun\command =E:\CONFIG\S-1-5-21-1482476501-1644491937-682003330-1013\Cfg.exe
shell\open\command =E:\CONFIG\S-1-5-21-1482476501-1644491937-682003330-1013\Cfg.exe
HKCU\..\..\Explorer\MountPoints2\{60e21893-c7de-11dd-bb06-001e6811489a}
shell\AutoRun\command =RECYCLER\S-1-5-21-1482476501-1644491937-682003330-1013\ise32.exe
shell\open\command =RECYCLER\S-1-5-21-1482476501-1644491937-682003330-1013\ise32.exe
HKCU\..\..\Explorer\MountPoints2\{74e44cd0-60b0-11dd-bf12-001e6811489a}
shell\AutoRun\command =copetttt.com
shell\explore\Command =copetttt.com
shell\open\Command =copetttt.com
HKCU\..\..\Explorer\MountPoints2\{bbdb6cf1-df50-11dd-97d4-001e6811489a}
shell\AutoRun\command =E:\copetttt.com
shell\explore\Command =E:\copetttt.com
shell\open\Command =E:\copetttt.com
HKCU\..\..\Explorer\MountPoints2\{e86fa660-0837-11de-849c-001e6811489a}
shell\Auto\command =tel.xls.exe
shell\AutoRun\command =C:\Windows\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL tel.xls.exe
HKCU\..\..\Explorer\MountPoints2\{eac4c37a-1ec0-11dd-bf60-0017c41c5895}
shell\AutoRun\command =H:\ClickMe.exe
HKCU\..\..\Explorer\MountPoints2\{eed93c53-5888-11de-acf2-001e6811489a}
shell\AutoRun\command =E:\AutoRunCardDetector.exe
################## | Cracks / Keygens / Serials |