voici, voilou....
############################# | UsbFix V6.034 |
User : test (Administrateurs) # P4FREDO
Update on 17/09/2009 by Chiquitine29, C_XX & Chimay8
Start at: 15:55:57 | 17/09/2009
Website :
http://pagesperso-orange.fr/NosTools/index.html
Intel(R) Pentium(R) 4 CPU 2.40GHz
Microsoft Windows XP Professionnel (5.1.2600 32-bit) # Service Pack 3
Internet Explorer 6.0.2900.5512
Windows Firewall Status : Enabled
AV : avast! antivirus 4.8.1351 [VPS 090916-0] 4.8.1351 [ Enabled | Updated ]
A:\ -> Lecteur de disquettes 3 ½ pouces
C:\ -> Disque fixe local # 19,53 Go (1,09 Go free) [Disque local] # NTFS
D:\ -> Disque fixe local # 37,73 Go (3,15 Go free) [soft] # NTFS
E:\ -> Disque CD-ROM
F:\ -> Disque CD-ROM
G:\ -> Disque fixe local # 37,3 Go (6,04 Go free) # FAT32
H:\ -> Disque fixe local # 232,85 Go (131,84 Go free) # FAT32
############################## | Processus actifs |
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\csrss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
G:\adawre\aawservice.exe
D:\applic\avast\aswUpdSv.exe
D:\applic\avast\ashServ.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\a-squared Free\a2service.exe
C:\Program Files\Canon\DIAS\CnxDIAS.exe
C:\Program Files\Fichiers communs\Nero\Nero BackItUp 4\NBService.exe
C:\Program Files\Google\Update\1.2.183.7\GoogleCrashHandler.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\O9X00MC.EXE
D:\applic\avast\ashMaiSv.exe
D:\applic\avast\ashWebSv.exe
C:\WINDOWS\System32\alg.exe
C:\WINDOWS\Explorer.EXE
D:\applic\avast\ashDisp.exe
C:\Documents and Settings\test\laqig.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\WINDOWS\system32\ntvdm.exe
D:\Program Files\Corel\Corel Graphics 12\Programs\CorelDRW.exe
C:\Program Files\Microsoft Office\Office\EXCEL.EXE
C:\WINDOWS\system32\wbem\wmiprvse.exe
C:\ACCESS\MSACCESS.EXE
C:\WINDOWS\SYSTEM32\WOWEXEC.EXE
################## | Fichiers # Dossiers infectieux |
D:\desktop.ini
H:\autorun.inf
H:\em8tqm.cmd
################## | Registre # Clés Run infectieuses |
[HKLM\software\microsoft\shared tools\msconfig\startupreg\cdoosoft]
################## | Registre # Mountpoints2 |
HKCU\..\..\Explorer\MountPoints2\{04d62153-7b27-11dc-8289-000c6e5f2fda}
Shell\AutoRun\command =C:\WINDOWS\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL copy.exe
HKCU\..\..\Explorer\MountPoints2\{091d1932-a988-11dd-8426-000c6e5f2fda}
Shell\AutoRun\command =C:\WINDOWS\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL copy.exe
HKCU\..\..\Explorer\MountPoints2\{0ba0cb89-dd87-11dd-845c-000c6e5f2fda}
Shell\AutoRun\command =wscript.exe antinul.vbe
Shell\open\Command =wscript.exe antinul.vbe
HKCU\..\..\Explorer\MountPoints2\{0e37fe19-6244-11da-9ca1-000c6e5f2fda}
Shell\Auto\command =H:\AdobeR.exe e
Shell\AutoRun\command =C:\WINDOWS\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL AdobeR.exe e
HKCU\..\..\Explorer\MountPoints2\{10aa1fe4-c83f-11dd-8449-000c6e5f2fda}
Shell\AutoRun\command =H:\Memorybar.exe
HKCU\..\..\Explorer\MountPoints2\{10d021fa-60af-11de-8508-00160a148ec7}
Shell\AutoRun\command =wscript.exe antinul.vbe
Shell\open\Command =wscript.exe antinul.vbe
HKCU\..\..\Explorer\MountPoints2\{191b8a4a-0c57-11dd-8358-000c6e5f2fda}
Shell\AutoRun\command =ix8bmwx.bat
Shell\open\Command =ix8bmwx.bat
HKCU\..\..\Explorer\MountPoints2\{2185953c-28cf-11de-84ba-000c6e5f2fda}
Shell\AutoRun\command =H:\RavMon.exe
Shell\explore\Command =H:\RavMon.exe -e
Shell\open\Command =H:\RavMon.exe
HKCU\..\..\Explorer\MountPoints2\{2185953d-28cf-11de-84ba-000c6e5f2fda}
Shell\Auto\command =msnmsgr_plus.exe
Shell\AutoRun\command =C:\WINDOWS\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL msnmsgr_plus.exe
HKCU\..\..\Explorer\MountPoints2\{221d229d-15fd-11de-84a1-000c6e5f2fda}
Shell\AutoRun\command =H:\jm3cx96.bat
Shell\open\Command =H:\jm3cx96.bat
HKCU\..\..\Explorer\MountPoints2\{221d22a1-15fd-11de-84a1-000c6e5f2fda}
Shell\AutoRun\command =H:\jm3cx96.bat
Shell\open\Command =H:\jm3cx96.bat
HKCU\..\..\Explorer\MountPoints2\{23470d5c-1852-11de-84a4-000c6e5f2fda}
Shell\AutoRun\command =H:\em8tqm.cmd
Shell\open\Command =H:\em8tqm.cmd
HKCU\..\..\Explorer\MountPoints2\{238e9326-c39c-11dd-843c-000c6e5f2fda}
Shell\AutoRun\command =wscript.exe antinul.vbe
Shell\open\Command =wscript.exe antinul.vbe
HKCU\..\..\Explorer\MountPoints2\{241935a7-ef44-11dc-832c-000c6e5f2fda}
Shell\AutoRun\command =H:\cqxj.exe
Shell\open\Command =H:\cqxj.exe
HKCU\..\..\Explorer\MountPoints2\{275bbabe-2033-11de-84ab-000c6e5f2fda}
Shell\AutoRun\command =H:\Memorybar.exe
HKCU\..\..\Explorer\MountPoints2\{2c46900f-6b00-11de-8515-00160a148ec7}
Shell\AutoRun\command =C:\WINDOWS\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL wscript.exe MS32DLL.dll.vbs
HKCU\..\..\Explorer\MountPoints2\{2c8ee3bc-0894-11de-848d-000c6e5f2fda}
Shell\AutoRun\command =H:\o.exe
Shell\open\Command =H:\o.exe
HKCU\..\..\Explorer\MountPoints2\{2df84516-ce53-11dc-82f9-000c6e5f2fda}
Shell\AutoRun\command =husyu8n.exe
Shell\open\Command =husyu8n.exe
HKCU\..\..\Explorer\MountPoints2\{31ddccf9-e31f-11dd-8463-000c6e5f2fda}
Shell\AutoRun\command =2u.com
Shell\explore\Command =2u.com
Shell\open\Command =2u.com
HKCU\..\..\Explorer\MountPoints2\{358237be-f433-11dd-8477-000c6e5f2fda}
Shell\AutoRun\command =H:\em8tqm.cmd
Shell\open\Command =H:\em8tqm.cmd
HKCU\..\..\Explorer\MountPoints2\{39e02ed2-2d96-11de-84c6-000c6e5f2fda}
Shell\AutoRun\command =C:\WINDOWS\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL wscript.exe .MS32DLL.dll.vbs
HKCU\..\..\Explorer\MountPoints2\{3be55d2a-3ed9-11de-84dc-00160a148ec7}
Shell\AutoRun\command =C:\WINDOWS\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL wscript.exe MS32DLL.dll.vbs
HKCU\..\..\Explorer\MountPoints2\{3e39bba9-ad25-11db-b767-000c6e5f2fda}
Shell\AutoRun\command =wscript.exe antinul.vbe
Shell\open\Command =wscript.exe antinul.vbe
HKCU\..\..\Explorer\MountPoints2\{5a3bcd2b-191a-11de-84a5-000c6e5f2fda}
Shell\AutoRun\command =H:\em8tqm.cmd
Shell\open\Command =H:\em8tqm.cmd
HKCU\..\..\Explorer\MountPoints2\{65c3841e-4776-11de-84ec-00160a148ec7}
Shell\AutoRun\command =H:\ej10fkdo.bat
Shell\open\Command =H:\ej10fkdo.bat
HKCU\..\..\Explorer\MountPoints2\{67b33b2c-2a5d-11de-84c1-000c6e5f2fda}
Shell\AutoRun\command =C:\WINDOWS\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL wscript.exe .MS32DLL.dll.vbs
HKCU\..\..\Explorer\MountPoints2\{67b33b31-2a5d-11de-84c1-000c6e5f2fda}
Shell\AutoRun\command =H:\EmDesk.exe
Shell\EmDesk\command =H:\EmDesk.exe
HKCU\..\..\Explorer\MountPoints2\{67b95ec8-a664-11dd-8422-000c6e5f2fda}
Shell\Auto\command =H:\AdobeR.exe e
Shell\AutoRun\command =C:\WINDOWS\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL AdobeR.exe e
HKCU\..\..\Explorer\MountPoints2\{67b95ecd-a664-11dd-8422-000c6e5f2fda}
Shell\AutoRun\command =H:\LaunchU3.exe -a
HKCU\..\..\Explorer\MountPoints2\{67cd56e0-355b-11de-84d1-000c6e5f2fda}
Shell\AutoRun\command =H:\ReadMe.exe
HKCU\..\..\Explorer\MountPoints2\{6fe774b1-f6b4-11dd-847a-000c6e5f2fda}
Shell\AutoRun\command =H:\gyn.cmd
Shell\open\Command =H:\gyn.cmd
HKCU\..\..\Explorer\MountPoints2\{70b64542-2e6d-11de-84c7-000c6e5f2fda}
Shell\AutoRun\command =H:\Memorybar.exe
HKCU\..\..\Explorer\MountPoints2\{7362b038-987d-11de-8542-00160a148ec7}
Shell\AutoRun\command =C:\WINDOWS\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL JuLES.eXe
HKCU\..\..\Explorer\MountPoints2\{7387ae34-db0d-11dd-845a-000c6e5f2fda}
Shell\AutoRun\command =H:\npee.com
Shell\open\Command =H:\npee.com
HKCU\..\..\Explorer\MountPoints2\{781c535b-50f1-11de-84f6-00160a148ec7}
Shell\AutoRun\command =C:\WINDOWS\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL wscript.exe .MS32DLL.dll.vbs
HKCU\..\..\Explorer\MountPoints2\{781c535c-50f1-11de-84f6-00160a148ec7}
Shell\AutoRun\command =C:\WINDOWS\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL wscript.exe .MS32DLL.dll.vbs
HKCU\..\..\Explorer\MountPoints2\{7b0810bc-3178-11de-84ce-000c6e5f2fda}
Shell\AutoRun\command =I:\npee.com
Shell\open\Command =I:\npee.com
HKCU\..\..\Explorer\MountPoints2\{7c17aea0-7dab-11de-8529-00160a148ec7}
Shell\Auto\Command =wscript.exe SemiAntiVirus.vbs
Shell\AutoRun\command =wscript.exe SemiAntiVirus.vbs
Shell\Explore\Command =wscript.exe SemiAntiVirus.vbs
Shell\Find\Command =wscript.exe SemiAntiVirus.vbs
Shell\Format...\Command =wscript.exe SemiAntiVirus.vbs
Shell\open\Command =wscript.exe SemiAntiVirus.vbs
HKCU\..\..\Explorer\MountPoints2\{8196b983-88f7-11db-b735-000c6e5f2fda}
Shell\AutoRun\command =C:\WINDOWS\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL TEST.exE
HKCU\..\..\Explorer\MountPoints2\{840fb281-068e-11de-848c-000c6e5f2fda}
Shell\AutoRun\command =H:\i.com
Shell\open\Command =H:\i.com
HKCU\..\..\Explorer\MountPoints2\{840fb284-068e-11de-848c-000c6e5f2fda}
Shell\AutoRun\command =C:\WINDOWS\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL wscript.exe MS32DLL.dll.vbs
HKCU\..\..\Explorer\MountPoints2\{87019591-ff2b-11dd-8485-000c6e5f2fda}
Shell\AutoRun\command =H:\dbrxubcw.com
Shell\open\Command =H:\dbrxubcw.com
HKCU\..\..\Explorer\MountPoints2\{875c37eb-32d4-11dd-8394-000c6e5f2fda}
Shell\AutoRun\command =H:\luk1ylq.com
Shell\open\Command =H:\luk1ylq.com
HKCU\..\..\Explorer\MountPoints2\{898c6ef5-0a29-11de-848e-000c6e5f2fda}
Shell\AutoRun\command =H:\dbrxubcw.com
Shell\open\Command =H:\dbrxubcw.com
HKCU\..\..\Explorer\MountPoints2\{89b02c12-19db-11de-84a6-000c6e5f2fda}
Shell\AutoRun\command =H:\em8tqm.cmd
Shell\open\Command =H:\em8tqm.cmd
HKCU\..\..\Explorer\MountPoints2\{8a5d6304-ab24-11dd-8428-000c6e5f2fda}
Shell\AutoRun\command =C:\WINDOWS\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL copy.exe
HKCU\..\..\Explorer\MountPoints2\{8d0a6895-49c8-11de-84ef-00160a148ec7}
Shell\AutoRun\command =H:\memorybar.exe
HKCU\..\..\Explorer\MountPoints2\{95011c41-661d-11de-850c-00160a148ec7}
Shell\AutoRun\command =H:\9dlvtiil.exe
Shell\open\Command =H:\9dlvtiil.exe
HKCU\..\..\Explorer\MountPoints2\{96bcd985-4c23-11de-84f2-00160a148ec7}
Shell\AutoRun\command =H:\setupSNK.exe
HKCU\..\..\Explorer\MountPoints2\{9ca291f2-fb16-11dc-833e-000c6e5f2fda}
Shell\Auto\Command =wscript.exe SemiAntiVirus.vbs
Shell\AutoRun\command =wscript.exe SemiAntiVirus.vbs
Shell\Explore\Command =wscript.exe SemiAntiVirus.vbs
Shell\Find\Command =wscript.exe SemiAntiVirus.vbs
Shell\Format...\Command =wscript.exe SemiAntiVirus.vbs
Shell\open\Command =wscript.exe SemiAntiVirus.vbs
HKCU\..\..\Explorer\MountPoints2\{a34ca570-9228-11de-853b-00160a148ec7}
Shell\AutoRun\command =I:\LaunchU3.exe -a
HKCU\..\..\Explorer\MountPoints2\{a66f2f35-0c81-11de-8490-000c6e5f2fda}
Shell\AutoRun\command =H:\i.com
Shell\open\Command =H:\i.com
HKCU\..\..\Explorer\MountPoints2\{a66f2f39-0c81-11de-8490-000c6e5f2fda}
Shell\AutoRun\command =H:\cb.exe
Shell\open\Command =H:\cb.exe
HKCU\..\..\Explorer\MountPoints2\{a66f2f3c-0c81-11de-8490-000c6e5f2fda}
Shell\AutoRun\command =H:\cb.exe
Shell\open\Command =H:\cb.exe
HKCU\..\..\Explorer\MountPoints2\{b1fd4f36-67a6-11de-850e-00160a148ec7}
Shell\AutoRun\command =H:\memorybar.exe
HKCU\..\..\Explorer\MountPoints2\{b509f246-2622-11dc-b84c-000c6e5f2fda}
Shell\Auto\command =ftxcsqbfg.exe
Shell\AutoRun\command =C:\WINDOWS\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL ftxcsqbfg.exe
HKCU\..\..\Explorer\MountPoints2\{b73f9224-227f-11de-84b2-000c6e5f2fda}
Shell\AutoRun\command =H:\upw.bat
Shell\open\Command =H:\upw.bat
HKCU\..\..\Explorer\MountPoints2\{b8d82d48-e11c-11dc-8318-000c6e5f2fda}
Shell\Auto\command =AdobeR.exe e
Shell\AutoRun\command =C:\WINDOWS\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL AdobeR.exe e
HKCU\..\..\Explorer\MountPoints2\{c1aa71b7-1232-11de-8494-000c6e5f2fda}
Shell\AutoRun\command =H:\luk1ylq.com
Shell\open\Command =H:\luk1ylq.com
HKCU\..\..\Explorer\MountPoints2\{c2ee3370-4cf6-11de-84f4-00160a148ec7}
Shell\1\Command =H:\Recycled.exe
Shell\2\Command =H:\Recycled.exe
Shell\AutoRun\command =C:\WINDOWS\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL Recycled.exe
HKCU\..\..\Explorer\MountPoints2\{c86231a7-ce7e-11dd-844f-000c6e5f2fda}
Shell\AutoRun\command =H:\dbrxubcw.com
Shell\open\Command =H:\dbrxubcw.com
HKCU\..\..\Explorer\MountPoints2\{d14c2e57-f910-11dd-847d-000c6e5f2fda}
Shell\AutoRun\command =C:\WINDOWS\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL wscript.exe MS32DLL.dll.vbs
HKCU\..\..\Explorer\MountPoints2\{d1b4839e-13b6-11de-8496-000c6e5f2fda}
Shell\AutoRun\command =H:\0bcobed.exe
Shell\open\Command =H:\0bcobed.exe
HKCU\..\..\Explorer\MountPoints2\{d3338c8c-c6d5-11dd-8443-000c6e5f2fda}
Shell\AutoRun\command =RECYCLER\S-1-5-21-1482476501-1644491937-682003330-1013\ise32.exe
Shell\open\command =RECYCLER\S-1-5-21-1482476501-1644491937-682003330-1013\ise32.exe
HKCU\..\..\Explorer\MountPoints2\{d442adf0-fd9f-11dd-8483-000c6e5f2fda}
Shell\AutoRun\command =C:\WINDOWS\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL copy.exe
HKCU\..\..\Explorer\MountPoints2\{d9a44692-e303-11dd-8461-000c6e5f2fda}
Shell\Auto\Command =wscript.exe SemiAntiVirus.vbs
Shell\AutoRun\command =wscript.exe SemiAntiVirus.vbs
Shell\Explore\Command =wscript.exe SemiAntiVirus.vbs
Shell\Find\Command =wscript.exe SemiAntiVirus.vbs
Shell\Format...\Command =wscript.exe SemiAntiVirus.vbs
Shell\open\Command =wscript.exe SemiAntiVirus.vbs
HKCU\..\..\Explorer\MountPoints2\{dd6b60a5-c11b-11dd-843a-000c6e5f2fda}
Shell\AutoRun\command =wscript.exe antinul.vbe
Shell\open\Command =wscript.exe antinul.vbe
HKCU\..\..\Explorer\MountPoints2\{df7e6097-450c-11de-84e9-00160a148ec7}
Shell\AutoRun\command =wscript.exe antinul.vbe
Shell\open\Command =wscript.exe antinul.vbe
HKCU\..\..\Explorer\MountPoints2\{df8b4e7f-155f-11de-84a0-000c6e5f2fda}
Shell\AutoRun\command =H:\jm3cx96.bat
Shell\open\Command =H:\jm3cx96.bat
HKCU\..\..\Explorer\MountPoints2\{e04e37e7-1e96-11de-84a9-000c6e5f2fda}
Shell\AutoRun\command =C:\WINDOWS\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL copy.exe
HKCU\..\..\Explorer\MountPoints2\{e367c003-178c-11de-84a2-000c6e5f2fda}
Shell\AutoRun\command =em8tqm.cmd
Shell\open\Command =em8tqm.cmd
HKCU\..\..\Explorer\MountPoints2\{e6867b70-267f-11de-84b9-000c6e5f2fda}
Shell\AutoRun\command =C:\WINDOWS\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL NoLimit.exe
HKCU\..\..\Explorer\MountPoints2\{e6cf805e-24d4-11de-84b7-000c6e5f2fda}
Shell\AutoRun\command =1ogf.exe
Shell\open\Command =1ogf.exe
HKCU\..\..\Explorer\MountPoints2\{e6cf8061-24d4-11de-84b7-000c6e5f2fda}
Shell\AutoRun\command =1ogf.exe
Shell\open\Command =1ogf.exe
HKCU\..\..\Explorer\MountPoints2\{e93379f6-1d6f-11dc-b83d-000c6e5f2fda}
Shell\Auto\command =AdobeR.exe e
Shell\AutoRun\command =C:\WINDOWS\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL AdobeR.exe e
HKCU\..\..\Explorer\MountPoints2\{f0b3da42-0fa6-11de-8491-000c6e5f2fda}
Shell\AutoRun\command =H:\xdw.com
Shell\open\Command =H:\xdw.com
HKCU\..\..\Explorer\MountPoints2\{f65b952f-5659-11de-84fc-00160a148ec7}
Shell\Auto\command =Long.exe
Shell\AutoRun\command =C:\WINDOWS\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL Long.exe
HKCU\..\..\Explorer\MountPoints2\{f6c232ce-3305-11de-84cf-000c6e5f2fda}
Shell\AutoRun\command =C:\WINDOWS\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL wscript.exe fm9l903qihfjdt2b1g1cg6ywedd653.vbs
HKCU\..\..\Explorer\MountPoints2\{f6c232d5-3305-11de-84cf-000c6e5f2fda}
Shell\AutoRun\command =C:\WINDOWS\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL Recycled\ctfmon.exe
Shell\Open(&0)\command =Recycled\ctfmon.exe
HKCU\..\..\Explorer\MountPoints2\{f6c232d8-3305-11de-84cf-000c6e5f2fda}
Shell\AutoRun\command =i.cmd
Shell\open\Command =i.cmd
HKCU\..\..\Explorer\MountPoints2\{fb9e9863-205b-11de-84ae-000c6e5f2fda}
Shell\AutoRun\command =H:\cqxj.exe
Shell\open\Command =H:\cqxj.exe
HKCU\..\..\Explorer\MountPoints2\{fb9e9864-205b-11de-84ae-000c6e5f2fda}
Shell\Auto\command =AdobeR.exe e
Shell\AutoRun\command =C:\WINDOWS\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL AdobeR.exe e
HKCU\..\..\Explorer\MountPoints2\{fe8384c5-2fe7-11de-84cb-000c6e5f2fda}
Shell\AutoRun\command =C:\WINDOWS\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL copy.exe
################## | ! Fin du rapport # UsbFix V6.034 ! |