############################## | UsbFix V6.029 |
User : ASMA (Administrateurs) # PC-DE-ASMA
Update on 09/09/2009 by Chiquitine29, C_XX & Chimay8
Start at: 03:59:37 | 11/09/2009
Website :
http://pagesperso-orange.fr/NosTools/index.html
Intel(R) Pentium(R) Dual CPU T2330 @ 1.60GHz
Microsoft® Windows Vista™ Édition Familiale Premium (6.0.6001 32-bit) # Service Pack 1
Internet Explorer 7.0.6001.18000
Windows Firewall Status : Disabled
AV : AVG Internet Security 8.5 [ Enabled | Updated ]
FW : AVG Firewall[ Enabled ]8.5
C:\ -> Disque fixe local # 92,77 Go (48,25 Go free) [Vista] # NTFS
E:\ -> Disque fixe local # 92,07 Go (91,98 Go free) [Data] # NTFS
F:\ -> Disque CD-ROM
############################## | Processus actifs |
C:\Windows\System32\smss.exe
C:\Windows\system32\csrss.exe
C:\Windows\system32\wininit.exe
C:\Windows\system32\csrss.exe
C:\Windows\system32\services.exe
C:\Windows\system32\lsass.exe
C:\Windows\system32\lsm.exe
C:\Windows\system32\winlogon.exe
C:\Windows\system32\svchost.exe
C:\Windows\Microsoft.Net\Framework\v3.0\WPF\PresentationFontCache.exe
C:\Windows\system32\svchost.exe
C:\Windows\System32\svchost.exe
C:\Windows\System32\svchost.exe
C:\Windows\System32\svchost.exe
C:\Windows\system32\svchost.exe
C:\Windows\system32\SLsvc.exe
C:\Windows\system32\svchost.exe
C:\Windows\system32\svchost.exe
C:\Windows\System32\spoolsv.exe
C:\Windows\system32\svchost.exe
C:\Windows\system32\agrsmsvc.exe
C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
C:\PROGRA~1\AVG\AVG8\avgfws8.exe
C:\Program Files\TOSHIBA\ConfigFree\CFSvcs.exe
C:\Program Files\Intel\Intel Matrix Storage Manager\IAANTMon.exe
C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc.exe
C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe
C:\Windows\system32\svchost.exe
C:\Windows\system32\svchost.exe
C:\Program Files\TeamViewer\Version4\TeamViewer_Service.exe
C:\Program Files\TOSHIBA\TOSHIBA DVD PLAYER\TNaviSrv.exe
C:\Windows\system32\TODDSrv.exe
C:\Program Files\TOSHIBA\Power Saver\TosCoSrv.exe
C:\Program Files\Common Files\Ulead Systems\DVD\ULCDRSvr.exe
C:\PROGRA~1\AVG\AVG8\avgam.exe
C:\PROGRA~1\AVG\AVG8\avgrsx.exe
C:\PROGRA~1\AVG\AVG8\avgnsx.exe
C:\Windows\System32\svchost.exe
C:\Program Files\TeamViewer\Version4\TeamViewer.exe
C:\Windows\system32\SearchIndexer.exe
C:\PROGRA~1\AVG\AVG8\avgemc.exe
C:\Program Files\AVG\AVG8\avgcsrvx.exe
C:\Windows\system32\taskeng.exe
C:\Windows\system32\Dwm.exe
C:\Windows\system32\taskeng.exe
C:\Windows\Explorer.EXE
C:\Program Files\Windows Defender\MSASCui.exe
C:\Program Files\TOSHIBA\Utilities\KeNotify.exe
C:\Windows\RtHDVCpl.exe
C:\Program Files\TOSHIBA\Power Saver\TPwrMain.exe
C:\Program Files\TOSHIBA\SmoothView\SmoothView.exe
C:\Program Files\TOSHIBA\FlashCards\TCrdMain.exe
C:\Program Files\TOSHIBA\ConfigFree\NDSTray.exe
C:\Program Files\IDM\Desktop SMS\DesktopSMS.exe
C:\Windows\System32\igfxtray.exe
C:\Windows\System32\igfxpers.exe
C:\Program Files\Camera Assistant Software for Toshiba\traybar.exe
C:\Windows\system32\igfxsrvc.exe
C:\Program Files\TOSHIBA\Registration\ToshibaRegistration.exe
C:\Program Files\Intel\Intel Matrix Storage Manager\IAAnotif.exe
C:\Program Files\DAP\DAP.exe
C:\Program Files\SpeedBit Video Accelerator\VideoAccelerator.exe
C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc.exe
C:\Program Files\AVG\AVG8\avgtray.exe
C:\Program Files\Winamp\winampa.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\Program Files\Java\jre6\bin\jusched.exe
C:\Program Files\Windows Sidebar\sidebar.exe
C:\Program Files\TOSHIBA\TOSCDSPD\TOSCDSPD.exe
C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
C:\Program Files\Vidalia Bundle\Vidalia\vidalia.exe
C:\Program Files\Windows Media Player\wmpnscfg.exe
C:\Program Files\TOSHIBA\Bluetooth Monitor\BtMon2.exe
C:\Program Files\Camera Assistant Software for Toshiba\CEC_MAIN.exe
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\Program Files\Windows Media Player\wmpnetwk.exe
C:\Program Files\Synaptics\SynTP\SynToshiba.exe
C:\Program Files\Magentic\bin\mgapp.exe
C:\Program Files\TOSHIBA\ConfigFree\CFSwMgr.exe
C:\Program Files\Windows Mail\WinMail.exe
C:\Program Files\Vidalia Bundle\Tor\tor.exe
C:\Program Files\Windows Live\Messenger\msnmsgr.exe
C:\Program Files\Windows Live\Messenger\usnsvc.exe
C:\Program Files\Internet Explorer\IEUser.exe
C:\Program Files\Google\Google Toolbar\GoogleToolbarUser_32.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Windows\system32\Macromed\Flash\FlashUtil10c.exe
C:\Windows\system32\conime.exe
C:\Windows\system32\wbem\wmiprvse.exe
################## | Fichiers # Dossiers infectieux |
Présent ! C:\Users\ASMA\AppData\Roaming\tazebama
################## | Registre # Clés Run infectieuses |
################## | Registre # Mountpoints2 |
HKCU\..\..\Explorer\MountPoints2\{0a2553b8-71e1-11de-8538-001eec007135}
shell\AutoRun\command =RESTORE\S-1-5-21-1482476501-1644491937-682003330-1013\Taquito.exe
shell\open\command =RESTORE\S-1-5-21-1482476501-1644491937-682003330-1013\Taquito.exe
HKCU\..\..\Explorer\MountPoints2\{0a2553c3-71e1-11de-8538-001eec007135}
shell\AutoRun\command =G:\RESTORE\S-1-5-21-1482476501-1644491937-682003330-1013\Taquito.exe
shell\open\command =G:\RESTORE\S-1-5-21-1482476501-1644491937-682003330-1013\Taquito.exe
HKCU\..\..\Explorer\MountPoints2\{0ee9ef94-9489-11de-af69-001eec007135}
shell\AutoRun\command =photos.exe
shell\explore\command =photos.exe
shell\open\command =photos.exe
HKCU\..\..\Explorer\MountPoints2\{2997ee55-4b5f-11de-b965-001eec007135}
shell\AutoRun\command =D:\rcukd.cmd
shell\explore\Command =D:\rcukd.cmd
shell\open\Command =D:\rcukd.cmd
HKCU\..\..\Explorer\MountPoints2\{38e3e239-198f-11de-9fc5-001eec007135}
shell\AutoRun\command =D:\photos.exe
shell\explore\command =D:\photos.exe
shell\open\command =D:\photos.exe
HKCU\..\..\Explorer\MountPoints2\{428c993e-3184-11de-883c-001eec007135}
shell\AutoRun\command =D:\photos.exe
shell\explore\command =D:\photos.exe
shell\open\command =D:\photos.exe
HKCU\..\..\Explorer\MountPoints2\{428c9966-3184-11de-883c-001eec007135}
shell\AutoRun\command =D:\zPharaoh.exe
shell\explore\command =D:\zPharaoh.exe
shell\open\command =D:\zPharaoh.exe
HKCU\..\..\Explorer\MountPoints2\{5bc4649d-64ab-11de-a4f2-001eec007135}
Shell\AutoRun\command =C:\Windows\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL R\\\\\\\\\\dontspread.com
Shell\eXpLorE\Command =.\\\\\\\\\\\\R\\\\\\dontspread.com
Shell\Open\Command =.\\\\\\\\\\\\\r\\\\\\\\dontspread.com
HKCU\..\..\Explorer\MountPoints2\{6ff7e25d-66ed-11de-8b89-001eec007135}
shell\AutoRun\command =C:\Windows\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL Wscript.exe /e:vbs winfile.jpg
HKCU\..\..\Explorer\MountPoints2\{7409daf6-1ae0-11de-afdd-001eec007135}
shell\AutoRun\command =D:\photos.exe
shell\explore\command =D:\photos.exe
shell\open\command =D:\photos.exe
HKCU\..\..\Explorer\MountPoints2\{91839d0f-4a9d-11de-94c3-001eec007135}
Shell\AutoRun\command =C:\Windows\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL D:\R\\\\\\\\\\dontspread.com
Shell\eXpLorE\Command =D:\.\\\\\\\\\\\\R\\\\\\dontspread.com
Shell\Open\Command =D:\.\\\\\\\\\\\\\r\\\\\\\\dontspread.com
HKCU\..\..\Explorer\MountPoints2\{b2c47597-8277-11de-b0e1-001eec007135}
Shell\AutoRun\command =C:\Windows\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL R\\\\\\\\\\dontspread.com
Shell\eXpLorE\Command =.\\\\\\\\\\\\R\\\\\\dontspread.com
Shell\Open\Command =.\\\\\\\\\\\\\r\\\\\\\\dontspread.com
HKCU\..\..\Explorer\MountPoints2\{b6af9cb0-6091-11de-a7f6-001eec007135}
shell\AutoRun\command =D:\RESTORE\S-1-5-21-1482476501-1644491937-682003330-1013\Taquito.exe
shell\open\command =D:\RESTORE\S-1-5-21-1482476501-1644491937-682003330-1013\Taquito.exe
HKCU\..\..\Explorer\MountPoints2\{d4df8816-4540-11de-bb47-001eec007135}
shell\AutoRun\command =D:\RESTORE\S-1-5-21-1482476501-1644491937-682003330-1013\Taquito.exe
shell\open\command =D:\RESTORE\S-1-5-21-1482476501-1644491937-682003330-1013\Taquito.exe
HKCU\..\..\Explorer\MountPoints2\{f9cd810f-4a93-11de-95ce-001eec007135}
shell\AutoRun\command =D:\RESTORE\S-1-5-21-1482476501-1644491937-682003330-1013\Taquito.exe
shell\open\command =D:\RESTORE\S-1-5-21-1482476501-1644491937-682003330-1013\Taquito.exe
HKCU\..\..\Explorer\MountPoints2\{fb685d5b-2ce8-11de-a6c0-001eec007135}
shell\AutoRun\command =D:\zPharaoh.exe
shell\explore\command =D:\zPharaoh.exe
shell\open\command =D:\zPharaoh.exe
################## | ! Fin du rapport # UsbFix V6.029 ! |