List'em by g3n-h@ckm@n 1.2.1.0
User : JA (Administrateurs)
Update on 21/01/2010 by g3n-h@ckm@n ::::: 10:30
Start at: 08:36:50 | 23/01/2010
Contact :
g3n-h@ckm@n sur CCM
Intel(R) Core(TM)2 CPU 6600 @ 2.40GHz
Microsoft® Windows Vista™ Professionnel (6.0.6002 32-bit) # Service Pack 2
Internet Explorer 7.0.6002.18005
Windows Firewall Status : Enabled
A:\ -> Lecteur de disquettes 3 ½ pouces
C:\ -> Disque fixe local | 113,2 Go (66,76 Go free) [ACER] | NTFS
D:\ -> Disque fixe local | 112,85 Go (112,76 Go free) [DATA] | NTFS
E:\ -> Disque CD-ROM | 533,66 Mo (0 Mo free) [BB User Tools] | CDFS
F:\ -> Disque amovible | 3,74 Go (3,73 Go free) | FAT32
G:\ -> Disque amovible | 920,19 Mo (554,62 Mo free) [USB DISK] | FAT
¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤ Processes running
C:\Windows\System32\smss.exe
C:\Windows\system32\csrss.exe
C:\Windows\system32\wininit.exe
C:\Windows\system32\csrss.exe
C:\Windows\system32\services.exe
C:\Windows\system32\lsass.exe
C:\Windows\system32\lsm.exe
C:\Windows\system32\winlogon.exe
C:\Windows\system32\svchost.exe
C:\Windows\system32\svchost.exe
C:\Windows\System32\svchost.exe
C:\Windows\system32\Ati2evxx.exe
C:\Windows\System32\svchost.exe
C:\Windows\System32\svchost.exe
C:\Windows\system32\svchost.exe
C:\Windows\system32\SLsvc.exe
C:\Windows\system32\svchost.exe
C:\Windows\system32\Ati2evxx.exe
C:\Windows\system32\svchost.exe
C:\Program Files\CheckPoint\ZAForceField\IswSvc.exe
C:\Program Files\EPSON\EPSON Advanced Printer Driver 4\EpsonPHLog.exe
C:\Program Files\EPSON\EPSON Advanced Printer Driver 4\EpsonPH.exe
C:\Windows\System32\spoolsv.exe
C:\Windows\system32\svchost.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\Program Files\Intel\AMT\atchksrv.exe
C:\Program Files\Microsoft Small Business\Business Contact Manager\BcmSqlStartupSvc.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\Program Files\Acer\eProtection\Service\eProtectionServ.exe
C:\Program Files\Common Files\LightScribe\LSSrvc.exe
C:\Program Files\Intel\AMT\LMS.exe
C:\Windows\system32\svchost.exe
C:\Program Files\Microsoft SQL Server\90\Shared\sqlbrowser.exe
C:\Program Files\Microsoft SQL Server\90\Shared\sqlwriter.exe
C:\Windows\system32\svchost.exe
C:\Windows\System32\svchost.exe
C:\Windows\system32\SearchIndexer.exe
C:\Acer\Empowering Technology\eRecovery\eRecoveryService.exe
C:\Program Files\Spybot - Search & Destroy\SDWinSec.exe
C:\Windows\system32\wbem\wmiprvse.exe
C:\Windows\system32\taskeng.exe
C:\Program Files\CheckPoint\ZAForceField\ForceField.exe
C:\Windows\system32\taskeng.exe
C:\Windows\system32\Dwm.exe
C:\Windows\Explorer.EXE
C:\Program Files\Windows Defender\MSASCui.exe
C:\Windows\RtHDVCpl.exe
C:\Program Files\Intel\AMT\atchk.exe
C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe
C:\Program Files\Adobe\Photoshop Album Edition Découverte\3.2\Apps\apdproxy.exe
C:\Program Files\Java\jre6\bin\jusched.exe
C:\Program Files\Windows Media Player\wmpnscfg.exe
C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\MOM.EXE
C:\Users\JA\ktper.exe
C:\Program Files\Brother\ControlCenter3\brccMCtl.exe
C:\Program Files\NETGEAR WG311v2 Adapter\wlancfg5.exe
C:\Program Files\Windows Media Player\wmpnetwk.exe
C:\Users\JA\AppData\Local\Temp\Vhd.exe
C:\Program Files\OpenOffice.org 3\program\soffice.exe
C:\Program Files\OpenOffice.org 3\program\soffice.bin
C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CCC.exe
C:\Acer\LANScope Agent\awServ.exe
C:\Acer\Empowering Technology\eRecovery\ERAGENT.EXE
C:\Windows\system32\UI0Detect.exe
C:\Program Files\TouchKit\xTouchMon.exe
C:\Windows\system32\conime.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\Java\jre6\bin\jucheck.exe
C:\Program Files\Adobe\Reader 8.0\Reader\AcroRd32.exe
C:\Windows\system32\WUDFHost.exe
\\?\C:\Windows\system32\wbem\WMIADAP.EXE
C:\Windows\system32\wbem\wmiprvse.exe
C:\Windows\system32\SearchProtocolHost.exe
C:\Windows\system32\SearchFilterHost.exe
C:\Program Files\List_Kill'em\List_Kill'em.exe
C:\Windows\system32\cmd.exe
C:\Users\JA\AppData\Local\Temp\D23D.tmp\pv.exe
======================
Keys "Run"
======================
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
Acer Tour Reminder REG_SZ
WMPNSCFG REG_SZ C:\Program Files\Windows Media Player\WMPNSCFG.exe
ktper REG_SZ C:\Users\JA\ktper.exe
BMIMZMHMFM REG_SZ C:\Users\JA\AppData\Local\Temp\Vhd.exe
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
Windows Defender REG_EXPAND_SZ %ProgramFiles%\Windows Defender\MSASCui.exe -hide
IgfxTray REG_SZ C:\Windows\system32\igfxtray.exe
HotKeysCmds REG_SZ C:\Windows\system32\hkcmd.exe
Persistence REG_SZ C:\Windows\system32\igfxpers.exe
RtHDVCpl REG_SZ RtHDVCpl.exe
atchk REG_SZ "C:\Program Files\Intel\AMT\atchk.exe"
RemoteControl REG_SZ "C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe"
installnet.exe REG_SZ "C:\Acer\LANScope Agent\Installnet.exe" "C:\Acer\LANScope Agent\
AdminWorks Tray REG_SZ "C:\Acer\LANScope Agent\awtray.exe"
Acer Tour REG_SZ
Apanel REG_SZ C:\ACERSW\config\SetApanel.cmd
StartCCC REG_SZ C:\Program Files\ATI Technologies\ATI.ACE\Core-
Static\CLIStart.exe
WarReg_PopUp REG_SZ C:\Acer\WR_PopUp\WarReg_PopUp.exe
eRecoveryService REG_SZ
Acer Tour Reminder REG_SZ C:\Acer\AcerTour\Reminder.exe
BrMfcWnd REG_SZ C:\Program Files\Brother\Brmfcmon\BrMfcWnd.exe /AUTORUN
ControlCenter3 REG_SZ C:\Program Files\Brother\ControlCenter3\brctrcen.exe /autorun
Adobe Photo Downloader REG_SZ "C:\Program Files\Adobe\Photoshop Album Edition
Découverte\3.2\Apps\apdproxy.exe"
SunJavaUpdateSched REG_SZ "C:\Program Files\Java\jre6\bin\jusched.exe"
QuickTime Task REG_SZ "C:\Program Files\QuickTime\QTTask.exe" -atboottime
ClearTKHandle REG_SZ C:\Program Files\TouchKit\ClearTKHandle.exe
Adobe Reader Speed Launcher REG_SZ "C:\Program Files\Adobe\Reader 8.0
\Reader\Reader_sl.exe"
ZoneAlarm Client REG_SZ "C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe"
ISW REG_SZ "C:\Program Files\CheckPoint\ZAForceField\ForceField.exe" /icon="hidden"
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\RunServices]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\RunOnce]
=====================
Other Keys
=====================
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
ConsentPromptBehaviorAdmin REG_DWORD 2 (0x2)
ConsentPromptBehaviorUser REG_DWORD 1 (0x1)
EnableInstallerDetection REG_DWORD 1 (0x1)
EnableLUA REG_DWORD 0 (0x0)
EnableSecureUIAPaths REG_DWORD 1 (0x1)
EnableVirtualization REG_DWORD 1 (0x1)
PromptOnSecureDesktop REG_DWORD 1 (0x1)
ValidateAdminCodeSignatures REG_DWORD 0 (0x0)
dontdisplaylastusername REG_DWORD 0 (0x0)
legalnoticecaption REG_SZ
legalnoticetext REG_SZ
scforceoption REG_DWORD 0 (0x0)
shutdownwithoutlogon REG_DWORD 1 (0x1)
undockwithoutlogon REG_DWORD 1 (0x1)
FilterAdministratorToken REG_DWORD 0 (0x0)
EnableUIADesktopToggle REG_DWORD 0 (0x0)
===============
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
===============
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
BindDirectlyToPropertySetStorage REG_DWORD 0 (0x0)
===============
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows]
AppInit_DLLS REG_SZ
===============
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\igfxcui]
===============
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks]
===============
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\sta
ndardprofile\authorizedapplications\list]
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\dom
ainprofile\authorizedapplications\list]
===============
ActivX controls
===============
HKEY_LOCAL_MACHINE\software\microsoft\code store database\distribution units\{5D637FAD-E202-
48D1-8F18-5B9C459BD1E3}
HKEY_LOCAL_MACHINE\software\microsoft\code store database\distribution units\{8AD9C840-044E-
11D1-B3E9-00805F499D93}
HKEY_LOCAL_MACHINE\software\microsoft\code store database\distribution units\{8FFBE65D-2C9C-
4669-84BD-5829DC0B603C}
HKEY_LOCAL_MACHINE\software\microsoft\code store database\distribution units\{CAFEEFAC-0016-
0000-0003-ABCDEFFEDCBA}
HKEY_LOCAL_MACHINE\software\microsoft\code store database\distribution units\{CAFEEFAC-0016-
0000-0013-ABCDEFFEDCBA}
HKEY_LOCAL_MACHINE\software\microsoft\code store database\distribution units\{CAFEEFAC-FFFF-
FFFF-FFFF-ABCDEFFEDCBA}
===============
HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\>{22d6f312-b0f6-11d0-
94ab-0080c74c7e95}
HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\>{26923b43-4d38-484f-
9b9e-de460746276c}
HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\>{60B49E34-C7CC-11D0-
8953-00A0C90347FF}
HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{08B0E5C0-4FCB-11CF-
AAA5-00401C608500}
HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{2179C5D3-EBFF-11CF-
B6FD-00AA00B4E220}
HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{22d6f312-b0f6-11d0-
94ab-0080c74c7e95}
HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{2C7339CF-2B09-4501-
B3F3-F3508C9228ED}
HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{3af36230-a269-11d1-
b5bf-0000f8051515}
HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{411EDCF7-755D-414E-
A74B-3DCD6583F589}
HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{44BBA840-CC51-11CF-
AAFA-00AA00B6015C}
HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{44BBA848-CC51-11CF-
AAFA-00AA00B6015C}
HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{44BBA855-CC51-11CF-
AAFA-00AA00B6015F}
HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{45ea75a0-a269-11d1-
b5bf-0000f8051515}
HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{4f645220-306d-11d2-
995d-00c04f98bbc9}
HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{5fd399c0-a70a-11d1-
9948-00c04f98bbc9}
HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{630b1da0-b465-11d1-
9948-00c04f98bbc9}
HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{6BF52A52-394A-11d3-
B153-00C04F79FAA6}
HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{6fab99d0-bab8-11d1-
994a-00c04f98bbc9}
HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{73FA19D0-2D75-11D2-
995D-00C04F98BBC9}
HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{7790769C-0471-11d2-
AF11-00C04FA35D02}
HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{7C028AF8-F614-47B3-
82DA-BA94E41B1089}
HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{89820200-ECBD-11cf-
8B85-00AA005B4340}
HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{89820200-ECBD-11cf-
8B85-00AA005B4383}
HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{89B4C1CD-B018-4511-
B0A1-5476DBF70820}
HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{9381D8F2-0288-11D0-
9501-00AA00B911A5}
HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{9A394342-4A68-4EBA-
85A6-55B559F4E700}
HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{C6BAF60B-6E91-453F-
BFF9-D3789CFEFCDD}
HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{C9E9A340-D1F1-11D0-
821E-444553540600}
HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{CB2F7EDD-9D1F-43C1-
90FC-4F52EAE172A1}
HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{CDD7975E-60F8-41d5-
8149-19E51D6F71D0}
HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{D27CDB6E-AE6D-11CF-
96B8-444553540000}
HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{DAA94A2A-2A8D-4D3B-
9DB8-56FBECED082D}
HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{de5aed00-a4bf-11d1-
9948-00c04f98bbc9}
HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{E92B03AB-B707-11d2-
9CBD-0000F87A369E}
==============
BHO :
======
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\browser helper
objects\{06849E9F-C8D7-4D59-B87D-784B7D6BE0B3}]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\browser helper
objects\{53707962-6F74-2D53-2644-206D7942484F}]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\browser helper
objects\{5C255C8A-E604-49b4-9D64-90988571CECB}]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\browser helper
objects\{8A4A36C2-0535-4D2C-BD3D-496CB7EED6E3}]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\browser helper
objects\{9030D464-4C02-4ABF-8ECC-5164760863C6}]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\browser helper
objects\{DBC80044-A445-435b-BC74-9C25C1C588A9}]
================
Internet Explorer :
================
[HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Main]
Start Page REG_SZ
http://fr.fr.acer.yahoo.com
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main]
Start Page REG_SZ
http://www.gmail.com/
========
Services
========
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services]
Ndisuio : 0x3
EapHost : 0x3
Wlansvc : 0x2
SharedAccess : 0x4
windefend : 0x2
wuauserv : 0x2
wscsvc : 0x2
=========
Atapi.sys
=========
%%%% HASHDEEP-1.0
%%%% size,md5,sha256,filename
## Invoked from: C:\Users\JA\AppData\Local\Temp\D23D.tmp
## C:\> hashdeep C:\Windows\System32\Drivers\atapi.sys
##
19944,1f05b78ab91c9075565a9d8a4b880bc4,737be9f9376dab0ccdfed93ea6d67f0c432367ea63cd772a453485be7
69af3bd,C:\Windows\System32\Drivers\atapi.sys
Sources
=======
C:\Windows\System32\drivers\atapi.sys
C:\Windows\System32\DriverStore\FileRepository\mshdc.inf_7de13c21\atapi.sys
C:\Windows\System32\DriverStore\FileRepository\mshdc.inf_b12d8e84\atapi.sys
C:\Windows\System32\DriverStore\FileRepository\mshdc.inf_c6c2e699\atapi.sys
C:\Windows\System32\DriverStore\FileRepository\mshdc.inf_cc18792d\atapi.sys
C:\Windows\winsxs\x86_mshdc.inf_31bf3856ad364e35_6.0.6000.16632_none_db337a442479c42c\atapi.sys
C:\Windows\winsxs\x86_mshdc.inf_31bf3856ad364e35_6.0.6000.20757_none_dbac78a93da31a8b\atapi.sys
C:\Windows\winsxs\x86_mshdc.inf_31bf3856ad364e35_6.0.6001.18000_none_dd38281a2189ce9c\atapi.sys
C:\Windows\winsxs\x86_mshdc.inf_31bf3856ad364e35_6.0.6002.18005_none_df23a1261eab99e8\atapi.sys
Référence :
==========
Win XP_SP2_32b : CDFE4411A69C224BD1D11B2DA92DAC51
Win XP_SP3_32b : 9F3A2F5AA6875C72BF062C712CFA2674
Vista_SP2_32b : 1F05B78AB91C9075565A9D8A4B880BC4
Vista_SP2_64b : 1898FAE8E07D97F2F6C2D5326C633FAC
Windows 7_32b : 80C40F7FDFC376E4C5FEEC28B41C119E
Windows 7_64b : 02062C0B390B7729EDC9E69C680A6F3C
E:\Autorun.inf :
----------------
[autorun]
open=start.exe
F:\Autorun.inf :
----------------
G:\Autorun.inf :
----------------
=======
Drive :
=======
D‚fragmenteur de disque Windows
Copyright (c) 2006 Microsoft Corp.
Rapport d'analyse pour le volume C: ACER
Taille du volume = 113 Go
Espace libre = 66.77 Go
tendue d'espace libre la plus grande = 36.79 Go
Pourcentage de fragmentation des fichiers = 1 %
Remarqueÿ: sur les volumes NTFS, les fragments de fichiers de plus de 64ÿMo ne sont pas
inclus dans les statistiques de fragmentation.
Il n'est pas n‚cessaire de d‚fragmenter ce volume.
¤¤¤¤¤¤¤¤¤¤ Files/folders :
Present !! : C:\Program Files\ContextEnhancer
Present !! : C:\Windows\System32\drivers\etc\hosts.msn
Present !! : C:\Windows\System32\log.txt
Present !! : C:\Windows\System32\x64
Present !! : C:\Windows\tasks\{66BA574B-1E11-49b8-909C-8CC9E0E8E015}.job
Present !! : C:\Users\JA\Local Settings\Temp\a.dat
Present !! : C:\Users\JA\Local Settings\Temp\Vhb.exe
Present !! : C:\Users\JA\Local Settings\Temp\Vhc.exe
Present !! : C:\Users\JA\Local Settings\Temp\Vhd.exe
Present !! : C:\Users\JA\LOCAL Settings\Temp\jre-6u17-windows-i586-iftw-rv.exe
Present !! : C:\Users\JA\LOCAL Settings\Temp\Vhb.exe
Present !! : C:\Users\JA\LOCAL Settings\Temp\Vhc.exe
Present !! : C:\Users\JA\LOCAL Settings\Temp\Vhd.exe
¤¤¤¤¤¤¤¤¤¤ Keys :
Present !! : HKCU\SOFTWARE\BMIMZMHMFM
Present !! : HKCU\SOFTWARE\XML
================
Other infections
================
catchme 0.3.1398.3 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.net
Rootkit scan 2010-01-23 08:42:43
Windows 6.0.6002 Service Pack 2 NTFS
scanning hidden processes ...
scanning hidden services & system hive ...
scanning hidden registry entries ...
scanning hidden files ...
C:\Users\JA\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\8RY2I7P7
\8_135835[1].jpg 14346 bytes
C:\Users\JA\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\8RY2I7P7
\8_72363[1].jpg
C:\Users\JA\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\8RY2I7P7
\im_bg_0[1].gif 5160 bytes
C:\Users\JA\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\8RY2I7P7
\9_108462[1].jpg 12176 bytes
C:\Users\JA\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\8RY2I7P7
\9_116411[1].jpg
C:\Users\JA\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\8RY2I7P7
\a130838_140h[1].jpg
C:\Users\JA\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\8RY2I7P7
\a130897_140h[1].jpg
C:\Users\JA\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\8RY2I7P7
\aaa35bf05dd34e0e3642688ec503f8a0[1].swf
C:\Users\JA\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\8RY2I7P7
\5_94017[1].jpg 11114 bytes
C:\Users\JA\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\8RY2I7P7
\dnserrordiagoff_webOC[1] 6884 bytes
C:\Users\JA\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\8RY2I7P7
\10_43023[1].jpg
C:\Users\JA\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\8RY2I7P7\10_68
[1].jpg
C:\Users\JA\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\8RY2I7P7\logo
[1].gif
C:\Users\JA\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\8RY2I7P7
\GDB0LCpZQoxXSredP29D5Q[1].jpg
C:\Users\JA\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\8RY2I7P7\tour
[1]
C:\Users\JA\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\8RY2I7P7
\sheduler[1].htm
C:\Users\JA\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\8RY2I7P7
\950x250[1].css
C:\Users\JA\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\8RY2I7P7
\3_101792[1].jpg
C:\Users\JA\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\8RY2I7P7
\3_102242[1].jpg
C:\Users\JA\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\8RY2I7P7
\3_10469[1].jpg
C:\Users\JA\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\8RY2I7P7
\3_111753[1].jpg
C:\Users\JA\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\8RY2I7P7
\2_63065[1].jpg
C:\Users\JA\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\8RY2I7P7
\4_103471[1].jpg
C:\Users\JA\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\8RY2I7P7
\4_75277[1].jpg
C:\Users\JA\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\8RY2I7P7
\3_23198[1].jpg
C:\Users\JA\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\8RY2I7P7\h
[1].js
C:\Users\JA\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\8RY2I7P7
\viewjs[1].htm 17987 bytes
C:\Users\JA\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\8RY2I7P7
\3_35167[1].jpg 9517 bytes
C:\Users\JA\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\8RY2I7P7
\3_41248[1].jpg
C:\Users\JA\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\8RY2I7P7
\3_44891[1].jpg 8498 bytes
C:\Users\JA\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\8RY2I7P7
\3_48382[1].jpg
C:\Users\JA\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\8RY2I7P7
\3_57668[1].jpg
C:\Users\JA\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\8RY2I7P7
\3_65196[1].jpg
C:\Users\JA\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\8RY2I7P7
\3_67620[1].jpg
C:\Users\JA\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\8RY2I7P7
\3_75256[1].jpg 15824 bytes
C:\Users\JA\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\8RY2I7P7
\3_77895[1].jpg
C:\Users\JA\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\8RY2I7P7
\3_87088[1].jpg
C:\Users\JA\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\8RY2I7P7
\3_89807[1].jpg
C:\Users\JA\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\8RY2I7P7
\3_92228[1].jpg 10020 bytes
C:\Users\JA\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\8RY2I7P7
\3_98486[1].jpg
C:\Users\JA\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\8RY2I7P7\young
-adult_com[1].htm 119837 bytes
C:\Users\JA\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\8RY2I7P7
\bgTile[1].gif
C:\Users\JA\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\8RY2I7P7
\density_banner[1] 17243 bytes
C:\Users\JA\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\8RY2I7P7\count
[1].htm 0 bytes
C:\Users\JA\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\8RY2I7P7
\3_112182[1].jpg
C:\Users\JA\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\8RY2I7P7
\3_126317[1].jpg
C:\Users\JA\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\8RY2I7P7
\3_129571[1].jpg
C:\Users\JA\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\8RY2I7P7
\3_146843[1].jpg 7404 bytes
C:\Users\JA\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\8RY2I7P7
\3_18456[1].jpg
C:\Users\JA\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\8RY2I7P7
\3_23102[1].jpg 9866 bytes
C:\Users\JA\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\8RY2I7P7
\thumb.2009-07-17-lafat_mom_son_00.wmv.flv.1.240.180[1].jpg
C:\Users\JA\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\8RY2I7P7
\7_120670[1].jpg
C:\Users\JA\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\8RY2I7P7
\7_59626[1].jpg
C:\Users\JA\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\CI0AI5LP\as
[1].htm
C:\Users\JA\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\CI0AI5LP\as
[2].htm
C:\Users\JA\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\CI0AI5LP\as
[3].htm
C:\Users\JA\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\CI0AI5LP\as
[4].htm
C:\Users\JA\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\CI0AI5LP\a_ft
[1].htm
C:\Users\JA\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5
\CI0AI5LP\5_151663[1].jpg
C:\Users\JA\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5
\CI0AI5LP\5_32216[1].jpg
C:\Users\JA\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5
\CI0AI5LP\5_87636[1].jpg
C:\Users\JA\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5
\CI0AI5LP\biggal[1].css
C:\Users\JA\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5
\CI0AI5LP\8_64491[1].jpg
C:\Users\JA\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\CI0AI5LP\style
[2].css
C:\Users\JA\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\CI0AI5LP\style
[4].css
C:\Users\JA\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5
\CI0AI5LP\bz_flag[1].png
C:\Users\JA\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5
\CI0AI5LP\cg_flag[1].png
C:\Users\JA\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5
\CI0AI5LP\ck_flag[1].png
C:\Users\JA\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5
\CI0AI5LP\ae_flag[1].png
C:\Users\JA\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5
\CI0AI5LP\af_flag[1].png
C:\Users\JA\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5
\CI0AI5LP\bd_flag[1].png
C:\Users\JA\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5
\CI0AI5LP\bo_flag[1].png
C:\Users\JA\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5
\CI0AI5LP\cu_flag[1].png
scan completed successfully
hidden processes: 0
hidden services: 0
hidden files: 73
Stealth MBR rootkit/Mebroot/Sinowal detector 0.3.7 by Gmer,
http://www.gmer.net
device: opened successfully
user: MBR read successfully
kernel: MBR read successfully
user & kernel MBR OK
==========
Programs
==========
Acer
Acer Inc
Acro Software
Activation Assistant for the 2007 Microsoft Office suites
Adobe
Apple Software Update
ATI
ATI Technologies
Azureus
Bonjour
Brother
CCleaner
CheckPoint
Common Files
ContextEnhancer
CyberLink
desktop.ini
eMule
EPSON
eSobi
Fichiers communs
Google
GPLGS
InstallShield Installation Information
Intel
Internet Explorer
Java
JRE
Lavalys
List_Kill'em
Malwarebytes' Anti-Malware
Microsoft
Microsoft CAPICOM 2.1.0.2
Microsoft Office
Microsoft Office Outlook Connector
Microsoft Silverlight
Microsoft Small Business
Microsoft SQL Server
Microsoft SQL Server Compact Edition
Microsoft Visual Studio
Microsoft Works
Microsoft.NET
Movie Maker
Mozilla Firefox
Mozilla Thunderbird
MSBuild
NETGEAR WG311v2 Adapter
NewTech Infosystems
NOS
OpenOffice.org 3
PCXTools
pdfsam
QuickTime
Realtek
Reference Assemblies
Securitoo
Spybot - Search & Destroy
TF1Vision
TouchKit
trend micro
Uninstall Information
VideoLAN
WinamaxPoker
Windows Calendar
Windows Collaboration
Windows Defender
Windows Journal
Windows Live
Windows Live SkyDrive
Windows Mail
Windows Media Player
Windows NT
Windows Photo Gallery
Windows Portable Devices
Windows Sidebar
WinRAR
Yahoo!
ZiPhone
Zone Labs
============
Drive C:
============
$RECYCLE.BIN
-20070329.log
-20081125.log
Acer
AcerSW
Acrobat3
autoexec.bat
Book
Boot
bootmgr
BOOTSECT.BAK
config.sys
Documents and Settings
DRV
DrvInstReport.ini
EPSON Advanced Printer Driver
hiberfil.sys
HSF
Intel
IO.SYS
Kill'em
KPCMS
List'em.txt
MSDOS.SYS
MSOCache
OrchestraPDV
pagefile.sys
PDVD.iss
PerfLogs
Program Files
ProgramData
regxpcom.exe
RHDSetup.log
rsit
setup.log
sqmdata00.sqm
sqmdata01.sqm
sqmdata02.sqm
sqmdata03.sqm
sqmdata04.sqm
sqmdata05.sqm
sqmdata06.sqm
sqmdata07.sqm
sqmdata08.sqm
sqmdata09.sqm
sqmdata10.sqm
sqmdata11.sqm
sqmdata12.sqm
sqmnoopt00.sqm
sqmnoopt01.sqm
sqmnoopt02.sqm
sqmnoopt03.sqm
sqmnoopt04.sqm
sqmnoopt05.sqm
sqmnoopt06.sqm
sqmnoopt07.sqm
sqmnoopt08.sqm
sqmnoopt09.sqm
sqmnoopt10.sqm
sqmnoopt11.sqm
sqmnoopt12.sqm
System Volume Information
Temp
UsbFix
Users
Windows
¤¤¤¤¤¤¤¤¤¤ Cracks | Keygens | Serials
C:\Program Files\Microsoft SQL Server\90\Setup Bootstrap\Patch
C:\Program Files\Microsoft SQL Server\90\Setup Bootstrap\Patch\Sql
C:\Program Files\Microsoft SQL Server\90\Setup Bootstrap\Patch\Sql\SqlRun_SLP_SQL.msp
¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤( EOF )¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤