List'em by g3n-h@ckm@n 1.1.5.1
Thx to Chiquitine29.....& CCM team
User : Administrateur (Administrateurs) # SWEET-678855FE0
Update on 11/12/2009 by g3n-h@ckm@n ::::: 20:30
Start at: 21:06:22 | 11/12/2009
Contact : g3n-h@ckm@n sur CCM
Intel(R) Pentium(R) Dual CPU T3400 @ 2.16GHz
Microsoft Windows XP Professionnel (5.1.2600 32-bit) # Service Pack 3
Internet Explorer 7.0.5730.13
Windows Firewall Status : Disabled
AV : avast! antivirus 4.8.1356 [VPS 091211-0] 4.8.1356 [ (!) Disabled | Updated ]
C:\ -> Disque fixe local | 116,29 Go (29,86 Go free) | NTFS
D:\ -> Disque fixe local | 115,13 Go (37,38 Go free) [Data] | NTFS
E:\ -> Disque CD-ROM
F:\ -> Disque CD-ROM
G:\ -> Disque CD-ROM
H:\ -> Disque amovible | 7,46 Go (6,79 Go free) | FAT32
¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤ Processes running
C:\WINDOWS\System32\smss.exe 1140
C:\WINDOWS\system32\csrss.exe 1708
C:\WINDOWS\system32\winlogon.exe 1956
C:\WINDOWS\system32\services.exe 544
C:\WINDOWS\system32\lsass.exe 556
C:\WINDOWS\system32\svchost.exe 884
C:\WINDOWS\system32\svchost.exe 992
C:\WINDOWS\System32\svchost.exe 1112
C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe 232
C:\Program Files\Alwil Software\Avast4\ashServ.exe 292
C:\WINDOWS\system32\spoolsv.exe 1624
C:\WINDOWS\Explorer.EXE 1872
C:\Program Files\Fichiers communs\Autodesk Shared\Service\AdskScSrv.exe 1332
C:\Program Files\Google\Update\GoogleUpdate.exe 1784
C:\Program Files\Hotspot Shield\bin\openvpnas.exe 1976
C:\WINDOWS\RTHDCPL.EXE 1004
C:\Program Files\Elaborate Bytes\VirtualCloneDrive\VCDDaemon.exe 1200
C:\Program Files\Hotspot Shield\HssWPR\hsssrv.exe 1220
C:\Program Files\Canon\IJPLM\IJPLMSVC.EXE 1484
C:\Program Files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe 1508
C:\WINDOWS\system32\igfxtray.exe 356
C:\WINDOWS\system32\hkcmd.exe 716
C:\WINDOWS\system32\igfxsrvc.exe 636
C:\WINDOWS\system32\igfxpers.exe 684
C:\Program Files\Thomson\SpeedTouch USB\Dragdiag.exe 956
C:\Program Files\ScanSoft\OmniPageSE4\OpwareSE4.exe 1064
C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe 1824
C:\Program Files\WinMover\WinMover.exe 1316
C:\WINDOWS\system32\svchost.exe 2656
C:\Program Files\TVersity\Media Server\MediaServer.exe 2764
C:\Program Files\Hotspot Shield\bin\openvpntray.exe 2596
C:\Program Files\Opera\opera.exe 1612
C:\Documents and Settings\Administrateur\Bureau\BLEACH\List_Kill'em.scr 1460
C:\WINDOWS\system32\cmd.exe 2012
C:\WINDOWS\system32\wbem\wmiprvse.exe 3664
C:\Documents and Settings\Administrateur\Local Settings\Temp\4D.tmp\pv.exe 2744
======================
Keys "Run"
======================
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
WinMover REG_SZ "C:\Program Files\WinMover\WinMover.exe" /q
msnmsgr REG_SZ "C:\Program Files\Windows Live\Messenger\msnmsgr.exe" /background
Skype REG_SZ "C:\Program Files\Skype\Phone\Skype.exe" /nosplash /minimized
DAEMON Tools Lite REG_SZ "C:\Program Files\DAEMON Tools Lite\DTLite.exe" -autorun
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
RTHDCPL REG_SZ RTHDCPL.EXE
Alcmtr REG_SZ ALCMTR.EXE
VirtualCloneDrive REG_SZ "C:\Program Files\Elaborate Bytes\VirtualCloneDrive\VCDDaemon.exe" /s
IgfxTray REG_SZ C:\WINDOWS\system32\igfxtray.exe
HotKeysCmds REG_SZ C:\WINDOWS\system32\hkcmd.exe
Persistence REG_SZ C:\WINDOWS\system32\igfxpers.exe
Camera Assistant Software REG_SZ "C:\Program Files\Camera Assistant Software for Toshiba\traybar.exe" /start
SpeedTouch USB Diagnostics REG_SZ "C:\Program Files\Thomson\SpeedTouch USB\Dragdiag.exe" /icon
SSBkgdUpdate REG_SZ "C:\Program Files\Fichiers communs\Scansoft Shared\SSBkgdUpdate\SSBkgdupdate.exe" -Embedding -boot
OpwareSE4 REG_SZ "C:\Program Files\ScanSoft\OmniPageSE4\OpwareSE4.exe"
avast! REG_SZ C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
KernelFaultCheck REG_EXPAND_SZ %systemroot%\system32\dumprep 0 -k
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\RunServices]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\RunOnce]
=====================
Other Keys
=====================
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
dontdisplaylastusername REG_DWORD 1 (0x1)
legalnoticecaption REG_SZ
legalnoticetext REG_SZ
shutdownwithoutlogon REG_DWORD 1 (0x1)
undockwithoutlogon REG_DWORD 1 (0x1)
NoInternetOpenWith REG_DWORD 1 (0x1)
===============
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
NoDriveTypeAutoRun REG_DWORD 145 (0x91)
ForceClassicControlPanel REG_DWORD 1 (0x1)
LinkResolveIgnoreLinkInfo REG_DWORD 1 (0x1)
NoDesktopCleanupWizard REG_DWORD 1 (0x1)
NoInstrumentation REG_DWORD 1 (0x1)
NoLowDiskSpaceChecks REG_DWORD 1 (0x1)
NoResolveTrack REG_DWORD 1 (0x1)
NoSMBalloonTip REG_DWORD 1 (0x1)
NoSMConfigurePrograms REG_DWORD 1 (0x1)
NoSMHelp REG_DWORD 1 (0x1)
NoStartBanner REG_DWORD 1 (0x1)
NoStartMenuMFUprogramsList REG_DWORD 1 (0x1)
NoStrCmpLogical REG_DWORD 0 (0x0)
NoWelcomeScreen REG_DWORD 1 (0x1)
NoDriveAutoRun REG_DWORD 145 (0x91)
HonorAutoRunSetting REG_DWORD 0 (0x0)
===============
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
HonorAutoRunSetting REG_DWORD 0 (0x0)
CDRAutoRun REG_DWORD 1 (0x1)
HideRunAsVerb REG_DWORD 1 (0x1)
NoActiveDesktop REG_DWORD 0 (0x0)
NoCDBurning REG_DWORD 1 (0x1)
NoDesktopCleanupWizard REG_DWORD 1 (0x1)
NoDriveTypeAutoRun REG_DWORD 145 (0x91)
NoInstrumentation REG_DWORD 1 (0x1)
NoNetConnectDisconnect REG_DWORD 1 (0x1)
NoRemoteRecursiveEvents REG_DWORD 1 (0x1)
NoResolveTrack REG_DWORD 1 (0x1)
NoSetActiveDesktop REG_DWORD 0 (0x0)
NoStartMenuMFUprogramsList REG_DWORD 1 (0x1)
NoDriveAutoRun REG_DWORD 145 (0x91)
===============
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows]
AppInit_DLLS REG_SZ
===============
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\crypt32chain]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\cryptnet]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\cscdll]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\dimsntfy]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\igfxcui]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\ScCertProp]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\Schedule]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\sclgntfy]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\SensLogn]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\termsrv]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\WgaLogon]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\wlballoon]
===============
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks]
{AEB6717E-7E19-11d0-97EE-00C04FD91972} REG_SZ
===============
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
%windir%\Network Diagnostic\xpnetdiag.exe REG_SZ %windir%\Network Diagnostic\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000
%windir%\system32\sessmgr.exe REG_SZ %windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019
C:\Program Files\Mozilla Firefox\firefox.exe REG_SZ C:\Program Files\Mozilla Firefox\firefox.exe:*:Enabled:Mozilla Firefox
C:\Program Files\VideoLAN\VLC\vlc.exe REG_SZ C:\Program Files\VideoLAN\VLC\vlc.exe:*:Enabled:VLC media player
C:\Program Files\eMule\emule.exe REG_SZ C:\Program Files\eMule\emule.exe:*:Enabled:eMule
D:\3dsmax7\3dsmax.exe REG_SZ D:\3dsmax7\3dsmax.exe:*:Enabled:3ds max 7
C:\Program Files\backburner 2\monitor.exe REG_SZ C:\Program Files\backburner 2\monitor.exe:*:Enabled:backburner 2.3 monitor
C:\Program Files\backburner 2\manager.exe REG_SZ C:\Program Files\backburner 2\manager.exe:*:Enabled:backburner 2.3 manager
C:\Program Files\backburner 2\server.exe REG_SZ C:\Program Files\backburner 2\server.exe:*:Enabled:backburner 2.3 server
C:\Program Files\TVersity\Media Server\MediaServer.exe REG_SZ C:\Program Files\TVersity\Media Server\MediaServer.exe:*:Enabled:TVersity Media Server
C:\Program Files\Skype\Phone\Skype.exe REG_SZ C:\Program Files\Skype\Phone\Skype.exe:*:Enabled:Skype
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
%windir%\Network Diagnostic\xpnetdiag.exe REG_SZ %windir%\Network Diagnostic\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000
%windir%\system32\sessmgr.exe REG_SZ %windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019
===============
BHO :
======
[<NO NAME> REG_SZ ]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\browser helper objects\{18DF081C-E8AD-4283-A596-FA578C2EBDC3}]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\browser helper objects\{6EBF7485-159F-4bff-A14F-B9E3AAC4465B}]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\browser helper objects\{761497BB-D6F0-462C-B6EB-D4DAF1D92D43}]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\browser helper objects\{c95a4e8e-816d-4655-8c79-d736da1adb6d}]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\browser helper objects\{E5A1691B-D188-4419-AD02-90002030B8EE}]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\browser helper objects\{F9E4A054-E9B1-4BC3-83A3-76A1AE736170}]
================
Internet Explorer :
================
[HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Main]
Start Page REG_SZ
http://fr.msn.com/
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main]
Start Page REG_SZ
http://fr.msn.com/
========
Services
========
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services]
Ndisuio : 0x3
EapHost : 0x4
SharedAccess : 0x2
wuauserv : 0x2
=========
=======
Drive :
=======
D‚fragmenteur de disque Windows
Copyright (c) 2001 Microsoft Corp. et Executive Software International Inc.
Rapport d'analyse
116 Go total, 29,86 Go libre (25%), 0% fragment‚ (fragmentation du fichier 0%)
Il ne vous est pas n‚cessaire de d‚fragmenter ce volume.
==========
Programs
==========
7-Zip
Ad-Remover
Adobe
Alwil Software
Atheros
Audacity
backburner 2
Camera Assistant Software for Toshiba
Canon
CanonBJ
Combined Community Codec Pack
ComPlus Applications
Conduit
DAEMON Tools Lite
DAMN NFO Viewer
DIFX
DVD Decrypter
Elaborate Bytes
eMule
Fichiers communs
FlashFXP
Google
Hotspot Shield
Hotspot_Shield
ImgBurn
InstallShield Installation Information
Internet Explorer
Java
Magic Translator
Microsoft
Microsoft Office
Microsoft Silverlight
Microsoft Visual Studio
Microsoft Works
Movie Maker
Mozilla Firefox
MSECache
MSN Gaming Zone
Nero
NetMeeting
Notepad++
Opera
Outlook Express
Pandora Recovery
Pcsx2
PuTTY
QT Lite
QuickPar
Real Alternative
SABnzbd
SABnzbOpen
Samsung
ScanSoft
Services en ligne
Skype
Tetron4
Thomson
Toshiba
TVersity
TVersity Codec Pack
UFDisk Format Tool2
Uninstall Information
Unlocker
Utilitaires
VideoLAN
Windows Live
Windows Live Safety Center
Windows Media Connect 2
Windows Media Player
Windows NT
WindowsUpdate
WinMover
WinRAR
World of Warcraft Trial
XnView
¤¤¤¤¤¤¤¤¤¤ Files/folders :
C:\WINDOWS\System32\drivers\etc\hosts.msn
¤¤¤¤¤¤¤¤¤¤ Keys :
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer "NoSetActiveDesktop"
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\Setup.exe"
=========
Rootkits
=========
catchme 0.3.1398.3 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.net
Rootkit scan 2009-12-11 21:07:49
Windows 5.1.2600 Service Pack 3 NTFS
scanning hidden processes ...
scanning hidden services & system hive ...
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\sptd\Cfg]
"s1"=dword:2df9c43f
"s2"=dword:110480d0
"h0"=dword:00000001
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC]
"u0"=hex:d4,c3,97,02,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,..
"h0"=dword:00000000
"hdf12"=hex:24,45,86,7c,45,45,f4,43,ad,ca,37,c7,53,55,57,a3,d1,f1,9e,77,bc,..
"p0"="C:\Program Files\DAEMON Tools Lite\"
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001]
"a0"=hex:20,01,00,00,04,f3,cf,ed,a3,1b,1f,bd,ac,66,ba,08,b8,c9,54,4a,8a,..
"hdf12"=hex:e2,9d,be,a3,e9,7c,da,94,67,30,e0,0c,03,e7,2f,9c,e2,23,36,d8,c3,..
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001\gdq0]
"hdf12"=hex:2f,42,4c,a5,d4,70,f6,2d,f5,b0,d5,58,db,d4,bb,8c,ef,52,f6,dd,1e,..
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC]
"u0"=hex:d4,c3,97,02,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,..
"h0"=dword:00000000
"hdf12"=hex:24,45,86,7c,45,45,f4,43,ad,ca,37,c7,53,55,57,a3,d1,f1,9e,77,bc,..
"p0"="C:\Program Files\DAEMON Tools Lite\"
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001]
"a0"=hex:20,01,00,00,04,f3,cf,ed,a3,1b,1f,bd,ac,66,ba,08,b8,c9,54,4a,8a,..
"hdf12"=hex:e2,9d,be,a3,e9,7c,da,94,67,30,e0,0c,03,e7,2f,9c,e2,23,36,d8,c3,..
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001\gdq0]
"hdf12"=hex:2f,42,4c,a5,d4,70,f6,2d,f5,b0,d5,58,db,d4,bb,8c,ef,52,f6,dd,1e,..
scanning hidden registry entries ...
scanning hidden files ...
scan completed successfully
hidden processes: 0
hidden services: 0
hidden files: 0
Stealth MBR rootkit/Mebroot/Sinowal detector 0.3.7 by Gmer,
http://www.gmer.net
device: opened successfully
user: MBR read successfully
kernel: MBR read successfully
user & kernel MBR OK
¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤( EOF )¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤