ComboFix 07-12-08.1 - Propriétaire 2007-12-08 18:42:04.1 - NTFSx86
Running from: C:\Documents and Settings\Propriétaire\Bureau\ComboFix.exe
.
(((((((((((((((((((((((((((((((((((( Autres suppressions ))))))))))))))))))))))))))))))))))))))))))))))))
.
C:\Documents and Settings\All Users\Application Data\Starware370
C:\Documents and Settings\All Users\Application Data\Starware370\buttons\563_button_1b_def.bmp
C:\Documents and Settings\All Users\Application Data\Starware370\buttons\563_button_1b_over.bmp
C:\Documents and Settings\All Users\Application Data\Starware370\buttons\572_button_1b_def.bmp
C:\Documents and Settings\All Users\Application Data\Starware370\buttons\572_button_1b_over.bmp
C:\Documents and Settings\All Users\Application Data\Starware370\buttons\573_button_1b_def.bmp
C:\Documents and Settings\All Users\Application Data\Starware370\buttons\573_button_1b_over.bmp
C:\Documents and Settings\All Users\Application Data\Starware370\buttons\Button_60.bmp
C:\Documents and Settings\All Users\Application Data\Starware370\buttons\Button_70.bmp
C:\Documents and Settings\All Users\Application Data\Starware370\buttons\Button_80.bmp
C:\Documents and Settings\All Users\Application Data\Starware370\buttons\FindIt.bmp
C:\Documents and Settings\All Users\Application Data\Starware370\buttons\FindItHot.bmp
C:\Documents and Settings\All Users\Application Data\Starware370\buttons\findithotxp.png
C:\Documents and Settings\All Users\Application Data\Starware370\buttons\finditxp.png
C:\Documents and Settings\All Users\Application Data\Starware370\buttons\logo.bmp
C:\Documents and Settings\All Users\Application Data\Starware370\buttons\logoxp.bmp
C:\Documents and Settings\All Users\Application Data\Starware370\contexts\error.xml
C:\Documents and Settings\All Users\Application Data\Starware370\contexts\Related.xml
C:\Documents and Settings\All Users\Application Data\Starware370\contexts\Travel.xml
C:\Documents and Settings\All Users\Application Data\Starware370\SimpleUpdate\ProductMessagingConfig.xml
C:\Documents and Settings\All Users\Application Data\Starware370\SimpleUpdate\ProductMessagingConfig.xml.backup
C:\Documents and Settings\All Users\Application Data\Starware370\SimpleUpdate\SimpleUpdateConfig.xml
C:\Documents and Settings\All Users\Application Data\Starware370\SimpleUpdate\SimpleUpdateConfig.xml.backup
C:\Documents and Settings\All Users\Application Data\Starware370\SimpleUpdate\TimerManagerConfig.xml
C:\Documents and Settings\All Users\Application Data\Starware370\SimpleUpdate\TimerManagerConfig.xml.backup
C:\Documents and Settings\Propriétaire\Application Data\Starware370
C:\Documents and Settings\Propriétaire\Application Data\Starware370\BrowserSearch\BrowserSearch.xml
C:\Documents and Settings\Propriétaire\Application Data\Starware370\BrowserSearch\BrowserSearch.xml.backup
C:\Documents and Settings\Propriétaire\Application Data\Starware370\Button_6\Button_6Options.xml
C:\Documents and Settings\Propriétaire\Application Data\Starware370\Button_6\Button_6Options.xml.backup
C:\Documents and Settings\Propriétaire\Application Data\Starware370\Button_7\Button_7Options.xml
C:\Documents and Settings\Propriétaire\Application Data\Starware370\Button_7\Button_7Options.xml.backup
C:\Documents and Settings\Propriétaire\Application Data\Starware370\Button_8\Button_8Options.xml
C:\Documents and Settings\Propriétaire\Application Data\Starware370\Button_8\Button_8Options.xml.backup
C:\Documents and Settings\Propriétaire\Application Data\Starware370\Configurator\Configurator.xml
C:\Documents and Settings\Propriétaire\Application Data\Starware370\Configurator\Configurator.xml.backup
C:\Documents and Settings\Propriétaire\Application Data\Starware370\ErrorSearch\ErrorSearchOptions.xml
C:\Documents and Settings\Propriétaire\Application Data\Starware370\ErrorSearch\ErrorSearchOptions.xml.backup
C:\Documents and Settings\Propriétaire\Application Data\Starware370\Layouts\ToolbarLayout.xml
C:\Documents and Settings\Propriétaire\Application Data\Starware370\Layouts\ToolbarLayout.xml.backup
C:\Documents and Settings\Propriétaire\Application Data\Starware370\Manager\ManagerOptions.xml
C:\Documents and Settings\Propriétaire\Application Data\Starware370\Manager\ManagerOptions.xml.backup
C:\Documents and Settings\Propriétaire\Application Data\Starware370\Paroles\ParolesOptions.xml
C:\Documents and Settings\Propriétaire\Application Data\Starware370\Paroles\ParolesOptions.xml.backup
C:\Documents and Settings\Propriétaire\Application Data\Starware370\Radio_FR\Radio_FROptions.xml
C:\Documents and Settings\Propriétaire\Application Data\Starware370\Radio_FR\Radio_FROptions.xml.backup
C:\Documents and Settings\Propriétaire\Application Data\Starware370\Recherche_de_musique\Recherche_de_musiqueOptions.xml
C:\Documents and Settings\Propriétaire\Application Data\Starware370\Recherche_de_musique\Recherche_de_musiqueOptions.xml.backup
C:\Documents and Settings\Propriétaire\Application Data\Starware370\RelatedSearch\RelatedSearchOptions.xml
C:\Documents and Settings\Propriétaire\Application Data\Starware370\RelatedSearch\RelatedSearchOptions.xml.backup
C:\Documents and Settings\Propriétaire\Application Data\Starware370\Telechargement\TelechargementOptions.xml
C:\Documents and Settings\Propriétaire\Application Data\Starware370\Telechargement\TelechargementOptions.xml.backup
C:\Documents and Settings\Propriétaire\Application Data\Starware370\Toolbar\TBProductsOptions.xml
C:\Documents and Settings\Propriétaire\Application Data\Starware370\Toolbar\TBProductsOptions.xml.backup
C:\Documents and Settings\Propriétaire\Application Data\Starware370\ToolbarLogo\ToolbarLogoOptions.xml
C:\Documents and Settings\Propriétaire\Application Data\Starware370\ToolbarLogo\ToolbarLogoOptions.xml.backup
C:\Documents and Settings\Propriétaire\Application Data\Starware370\ToolbarSearch\ToolbarSearchOptions.xml
C:\Documents and Settings\Propriétaire\Application Data\Starware370\ToolbarSearch\ToolbarSearchOptions.xml.backup
C:\Documents and Settings\Propriétaire\Application Data\Starware370\TravelSearch\TravelSearchOptions.xml
C:\Documents and Settings\Propriétaire\Application Data\Starware370\TravelSearch\TravelSearchOptions.xml.backup
C:\msn.exe
C:\Program Files\Starware370
C:\Program Files\Starware370\brand.bmp
C:\Program Files\Starware370\icons\star_16.ico
C:\Program Files\Starware370\Starware370Config.xml
C:\Program Files\Starware370\Starware370Uninstall.exe
.
((((((((((((((((((((((((((((( Fichiers créés 2007-11-08 to 2007-12-08 ))))))))))))))))))))))))))))))))))))
.
2007-12-08 18:25 . 2007-12-08 18:25 82,426 --a------ C:\lol1.exe
2007-12-08 17:43 . 2007-12-08 17:43 0 --a------ C:\adware.exe
2007-12-08 17:28 . 2007-12-08 17:28 <REP> d-------- C:\WINDOWS\ERUNT
2007-12-07 17:54 . 2007-12-08 14:06 53 --a------ C:\WINDOWS\SYSTEM32\x
2007-12-07 13:15 . 2007-12-07 13:17 49,090 --a------ C:\sexy.exe
2007-12-07 13:06 . 2007-12-07 13:08 36,977 --a------ C:\WINDOWS\SYSTEM32\osso.exe
2007-12-07 12:55 . 2007-12-07 12:56 14,254 --a------ C:\WINDOWS\SYSTEM32\jhsadlsghw.exe
2007-12-07 10:52 . 2007-12-07 10:52 <REP> d-------- C:\Program Files\Trend Micro
2007-12-07 09:25 . 2007-12-05 21:09 458,752 ---hs---- C:\WINDOWS\SYSTEM32\Wseclayer.exe
2007-12-07 09:24 . 2007-12-05 20:14 27 --a------ C:\WINDOWS\SYSTEM32\kuki.bat
2007-12-06 10:26 . 2007-12-06 10:29 41,771 --a------ C:\djkfijelc.exe
2007-12-05 14:31 . 2007-12-07 17:22 6,814 --a------ C:\eg.exe
2007-12-04 18:53 . 2007-12-05 18:41 441,856 --a------ C:\WINDOWS\SYSTEM32\fy.exe
2007-12-04 18:48 . 2007-12-05 18:49 70,869 --a------ C:\fy.exe
2007-12-03 19:09 . 2007-12-03 19:10 57,344 --a------ C:\WINDOWS\SYSTEM32\ioouoi.exe
2007-12-03 19:07 . 2007-12-03 19:08 195,754 --a------ C:\WINDOWS\SYSTEM32\ksioelskdew.exe
2007-12-03 13:47 . 2007-12-03 13:48 57,344 --a------ C:\WINDOWS\SYSTEM32\mmz.exe
2007-12-03 11:56 . 2007-12-03 11:56 991,314 --a------ C:\WINDOWS\SYSTEM32\dsgsf.exe
2007-12-02 23:15 . 2007-12-02 23:15 57,344 --a------ C:\WINDOWS\SYSTEM32\orc.exe
2007-12-02 19:54 . 2007-12-02 19:53 458,752 -r-hs---- C:\WINDOWS\SYSTEM32\dllcache\wintcpack.exe
2007-12-02 18:00 . 2007-12-02 19:20 12,527 --a------ C:\WINDOWS\SYSTEM32\exe.exe
2007-12-02 17:15 . 2007-12-03 11:59 <REP> d-------- C:\Program Files\dsfdsfsdfs
2007-12-02 16:55 . 2007-12-02 17:14 696,623 --a------ C:\WINDOWS\SYSTEM32\dsfsdfscx.exe
2007-12-02 16:51 . 2007-12-02 16:52 14,182 --a------ C:\WINDOWS\SYSTEM32\dsfsdfs.exe
2007-12-02 15:52 . 2007-12-02 15:52 <REP> d--h----- C:\WINDOWS\PIF
2007-12-01 11:42 . 2007-12-01 11:42 548,864 --a------ C:\WINDOWS\SYSTEM32\Syst3m32.exe
2007-12-01 11:32 . 2007-12-01 11:32 471,040 --a------ C:\WINDOWS\SYSTEM32\load.exe
2007-11-30 19:27 . 2007-12-07 15:43 56,351 --a------ C:\WINDOWS\SYSTEM32\djkfijelc.exe
2007-11-30 17:14 . 2007-12-07 10:57 <REP> d-------- C:\WINDOWS\SYSTEM32\ndafs
2007-11-30 17:14 . 2007-12-07 11:34 82,486 --a------ C:\nawaf.exe
2007-11-30 14:49 . 2007-11-30 14:49 495,616 -r-hs---- C:\WINDOWS\SYSTEM32\dllcache\windmns.exe
2007-11-25 13:34 . 2007-11-25 15:40 <REP> d-------- C:\Program Files\dfksdkfksdl
2007-11-25 13:34 . 2007-11-25 15:40 991,319 --a------ C:\WINDOWS\SYSTEM32\dsfds.pif
2007-11-25 11:22 . 2007-11-27 10:00 79,604 --a------ C:\WINDOWS\SYSTEM32\zudkkd.exe
2007-11-24 19:09 . 2007-11-24 19:08 851,968 --a------ C:\WINDOWS\SYSTEM32\Srb0ty.exe
2007-11-23 19:57 . 2007-11-23 19:57 28,017 --a------ C:\WINDOWS\SYSTEM32\lovelyx.sys
2007-11-23 18:12 . 2007-11-23 18:12 923,908 --a------ C:\WINDOWS\SYSTEM32\guygay.exe
2007-11-20 18:48 . 2007-11-20 18:48 726,066 --a------ C:\WINDOWS\SYSTEM32\-r
2007-11-17 17:19 . 2007-11-17 17:19 2,565 --a------ C:\WINDOWS\SYSTEM32\o1o2o3o4
2007-11-17 17:13 . 2007-11-17 17:13 27,038 --a------ C:\WINDOWS\SYSTEM32\niamx
2007-11-17 09:25 . 2007-11-20 17:47 79,604 --a------ C:\WINDOWS\SYSTEM32\zuirna.exe
2007-11-16 18:24 . 2007-11-16 18:30 271,939 --a------ C:\wzipse30.exe
2007-11-15 12:08 . 2007-11-15 12:08 927,214 --a------ C:\sdsdfsdf.exe
2007-11-15 09:21 . 2007-12-07 11:23 991,307 --a------ C:\WINDOWS\SYSTEM32\Sh.exe
2007-11-15 09:21 . 2007-11-15 09:21 72,803 --a------ C:\WINDOWS\SYSTEM32\binsetx.exe
2007-11-14 16:41 . 2007-12-03 15:59 991,310 --a------ C:\cg.pif
2007-11-14 13:33 . 2007-11-14 13:34 <REP> d-------- C:\WINDOWS\SYSTEM32\ksomik
2007-11-14 13:27 . 2007-11-14 13:27 725,861 --a------ C:\hidfdfdffdz.pif
2007-11-14 10:49 . 2007-11-14 10:49 1,129,575 --a------ C:\WINDOWS\SYSTEM32\fkdksae.exe
2007-11-14 10:48 . 2007-11-14 10:48 1,129,575 --a------ C:\WINDOWS\SYSTEM32\fkigldje.exe
2007-11-11 20:55 . 2007-11-11 20:55 79,604 --a------ C:\lekzing.exe
2007-11-10 20:11 . 2007-11-10 20:11 991,314 --a------ C:\gexa.exe
.
(((((((((((((((((((((((((((((((((( Compte-rendu de Find3M ))))))))))))))))))))))))))))))))))))))))))))))))
.
2007-12-07 16:25 552,960 ----a-w C:\WINDOWS\SYSTEM32\eXtream.exe
2007-12-07 10:24 49,105 ----a-w C:\Sh.exe
2007-12-07 10:23 --------- d-----w C:\Program Files\killSh
2007-12-07 09:41 --------- d-----w C:\Program Files\sdfhfgd
2007-12-05 17:56 --------- d-----w C:\Program Files\fjhgfdsdfg
2007-12-05 17:41 991,314 ----a-w C:\WINDOWS\SYSTEM32\eg.exe
2007-12-03 15:02 --------- d-----w C:\Program Files\dfrerter
2007-11-26 18:21 --------- d-----w C:\Program Files\sdfsdfsdfs
2007-11-26 18:19 775,031 ----a-w C:\WINDOWS\SYSTEM32\sex.exe
2007-11-23 09:54 46,127 ----a-w C:\WINDOWS\SYSTEM32\ProtectionV.exe
2007-11-20 16:04 112,702 ----a-w C:\esd.exe
2007-11-20 12:31 106,698 ----a-w C:\ddsds.exe
2007-11-18 10:17 544,768 ----a-w C:\WINDOWS\SYSTEM32\kdjfsdklfjsl.exe
2007-11-14 11:02 56,343 ----a-w C:\WINDOWS\SYSTEM32\Fuck.exe
2007-11-11 18:12 60,699 ----a-w C:\kek.exe
2007-11-05 16:35 991,310 ----a-w C:\WINDOWS\SYSTEM32\cg.pif
2007-11-04 17:39 991,314 ----a-w C:\gezzxa.exe
2007-11-02 12:15 523,887 ----a-w C:\WINDOWS\SYSTEM32\kek.exe
2007-11-02 11:51 1,771,008 ----a-r C:\WINDOWS\SYSTEM32\uae.exe
2007-10-31 19:00 29,344 ----a-w C:\WINDOWS\SYSTEM32\ybn3e.dll
2007-10-31 16:09 1,044,509 ----a-w C:\WINDOWS\SYSTEM32\testmangerx.exe
2007-10-31 16:07 923,839 ----a-w C:\WINDOWS\SYSTEM32\testooo.exe
2007-10-29 19:25 725,446 ----a-w C:\klertf.exe
2007-10-29 11:30 725,446 ----a-w C:\hjuing.exe
2007-10-28 19:58 883,093 ----a-w C:\WINDOWS\SYSTEM32\darkworlk.exe
2007-10-28 11:15 6,156 ----a-w C:\ddfsd.pif
2007-10-28 10:46 883,093 ----a-w C:\WINDOWS\SYSTEM32\antivirusv1.exe
2007-10-26 07:38 1,044,520 ----a-w C:\WINDOWS\SYSTEM32\ksxchii.exe
2007-10-25 18:43 1,043,792 ----a-w C:\WINDOWS\SYSTEM32\jdjsdsj.exe
2007-10-25 18:29 922,963 ----a-w C:\WINDOWS\SYSTEM32\chii.exe
2007-10-25 17:05 94,416 ----a-w C:\WINDOWS\system32\drivers\aswmon2.sys
2007-10-25 17:05 93,264 ----a-w C:\WINDOWS\system32\drivers\aswmon.sys
2007-10-25 17:03 23,152 ----a-w C:\WINDOWS\system32\drivers\aswRdr.sys
2007-10-25 17:01 42,912 ----a-w C:\WINDOWS\system32\drivers\aswTdi.sys
2007-10-25 16:58 26,624 ----a-w C:\WINDOWS\system32\drivers\aavmker4.sys
2007-10-25 16:24 815,480 ----a-w C:\WINDOWS\SYSTEM32\aswBoot.exe
2007-10-25 16:14 95,608 ----a-w C:\WINDOWS\SYSTEM32\AvastSS.scr
2007-10-25 15:48 --------- d-----w C:\Program Files\Symantic
2007-10-25 15:28 156,653 ----a-w C:\essd.exe
2007-10-24 16:06 1,771,008 ----a-w C:\WINDOWS\SYSTEM32\d4rk.exe
2007-10-19 19:23 --------- d-----w C:\Program Files\sddsada
2007-10-18 18:35 2,076,261 ----a-w C:\dfsd.exe
2007-10-14 19:25 1,044,509 ----a-w C:\WINDOWS\SYSTEM32\fvist.com.exe
2007-10-09 08:05 --------- d-----w C:\Program Files\Fichiers communs\Adobe
2007-10-07 16:19 463,360 ----a-w C:\ddxf.exe
2007-09-30 08:05 381,440 ----a-w C:\games.exe
2007-09-27 14:05 767,053 ----a-w C:\sfsdfsda.exe
2007-09-27 14:02 991,308 ----a-w C:\WINDOWS\SYSTEM32\Sxfgfd.exe
2007-09-27 13:59 991,308 ----a-w C:\WINDOWS\SYSTEM32\Sx.exe
2007-09-22 10:35 610,304 ----a-w C:\gt.exe
.
((((((((((((((((((((((((((((((((( Point de chargement Reg )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
REGEDIT4
*Note* les éléments vides & les éléments initiaux légitimes ne sont pas listés
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"swg"="C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2007-06-14 07:48]
"ErrorSafeFree"="C:\Program Files\ErrorSafe Free\uers.exe" []
"MsnMsgr"="C:\Program Files\MSN Messenger\MsnMsgr.exe" []
"MicroSoft ssadsadas3s1"="eXtream.exe" [2007-12-07 17:25 C:\WINDOWS\SYSTEM32\eXtream.exe]
"MicroSoft ssadssjdhasjadas3s1"="kdjfsdklfjsl.exe" [2007-11-18 11:17 C:\WINDOWS\SYSTEM32\kdjfsdklfjsl.exe]
"MicroSoft Getway mqbol"="xbvuxowlewiv.exe" []
"MicroSoft Legal Service"="Srb0ty.exe" [2007-11-24 19:08 C:\WINDOWS\SYSTEM32\Srb0ty.exe]
"Windows Secure Update"="load.exe" [2007-12-01 11:32 C:\WINDOWS\SYSTEM32\load.exe]
"MicroSoft Legal Syst3m32"="Syst3m32.exe" [2007-12-01 11:42 C:\WINDOWS\SYSTEM32\Syst3m32.exe]
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce]
"MicroSoft ssadssjdhasjadas3s1"="kdjfsdklfjsl.exe" [2007-11-18 11:17 C:\WINDOWS\SYSTEM32\kdjfsdklfjsl.exe]
"MicroSoft Legal Service"="Srb0ty.exe" [2007-11-24 19:08 C:\WINDOWS\SYSTEM32\Srb0ty.exe]
"Windows Secure Update"="load.exe" [2007-12-01 11:32 C:\WINDOWS\SYSTEM32\load.exe]
"MicroSoft Legal Syst3m32"="Syst3m32.exe" [2007-12-01 11:42 C:\WINDOWS\SYSTEM32\Syst3m32.exe]
"MicroSoft ssadsadas3s1"="eXtream.exe" [2007-12-07 17:25 C:\WINDOWS\SYSTEM32\eXtream.exe]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"hpsysdrv"="c:\windows\system\hpsysdrv.exe" [1998-05-07 08:04]
"KBD"="C:\HP\KBD\KBD.EXE" [2001-07-06 13:56]
"NvCplDaemon"="RUNDLL32.exe" [2001-08-24 01:47 C:\WINDOWS\SYSTEM32\rundll32.exe]
"IgfxTray"="C:\WINDOWS\System32\igfxtray.exe" [2001-08-07 16:25]
"HotKeysCmds"="C:\WINDOWS\System32\hkcmd.exe" [2001-08-07 15:36]
"PS2"="C:\WINDOWS\system32\ps2.exe" [2001-07-03 13:13]
"Microsoft Works Portfolio"="C:\Program Files\Microsoft Works\WksSb.exe" [2000-07-12 14:14]
"Microsoft Works Update Detection"="C:\Program Files\Microsoft Works\WkDetect.exe" [2000-08-04 03:01]
"PCTVOICE"="pctspk.exe" [2001-08-01 17:37 C:\WINDOWS\SYSTEM32\pctspk.exe]
"HPDJ Taskbar Utility"="C:\WINDOWS\System32\spool\drivers\w32x86\3\hpztsb04.exe" [2001-10-29 21:31]
"avast!"="C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe" [2007-10-25 17:20]
"kiss"="C:\Program Files\killSh\pingy.exe" [2007-09-14 05:14]
"Adobe Photo Downloader"="C:\Program Files\Adobe\Photoshop Album Edition Découverte\3.2\Apps\apdproxy.exe" []
"MicroSoft ssadsadas3s1"="eXtream.exe" [2007-12-07 17:25 C:\WINDOWS\SYSTEM32\eXtream.exe]
"MicroSoft ssadssjdhasjadas3s1"="kdjfsdklfjsl.exe" [2007-11-18 11:17 C:\WINDOWS\SYSTEM32\kdjfsdklfjsl.exe]
"MicroSoft Getway mqbol"="xbvuxowlewiv.exe" []
"MicroSoft Legal Service"="Srb0ty.exe" [2007-11-24 19:08 C:\WINDOWS\SYSTEM32\Srb0ty.exe]
"MicroSoft Legal Syst3m32"="Syst3m32.exe" [2007-12-01 11:42 C:\WINDOWS\SYSTEM32\Syst3m32.exe]
"smsger"="C:\WINDOWS\System32\Win.exe" []
"MicroSoft Visual Framwork"="MS32.exe" []
"WinDLL (Wseclayer.exe)"="C:\WINDOWS\System32\Wseclayer.exe" [2007-12-05 21:09]
"Windows Secure Update"="load.exe" [2007-12-01 11:32 C:\WINDOWS\SYSTEM32\load.exe]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce]
"Windows Secure Update"="load.exe" [2007-12-01 11:32 C:\WINDOWS\SYSTEM32\load.exe]
"MicroSoft ssadsadas3s1"="eXtream.exe" [2007-12-07 17:25 C:\WINDOWS\SYSTEM32\eXtream.exe]
"MicroSoft ssadssjdhasjadas3s1"="kdjfsdklfjsl.exe" [2007-11-18 11:17 C:\WINDOWS\SYSTEM32\kdjfsdklfjsl.exe]
"MicroSoft Legal Service"="Srb0ty.exe" [2007-11-24 19:08 C:\WINDOWS\SYSTEM32\Srb0ty.exe]
"MicroSoft Legal Syst3m32"="Syst3m32.exe" [2007-12-01 11:42 C:\WINDOWS\SYSTEM32\Syst3m32.exe]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\RunServices]
"MicroSoft ssadsadas3s1"="eXtream.exe" [2007-12-07 17:25 C:\WINDOWS\SYSTEM32\eXtream.exe]
"MicroSoft ssadssjdhasjadas3s1"="kdjfsdklfjsl.exe" [2007-11-18 11:17 C:\WINDOWS\SYSTEM32\kdjfsdklfjsl.exe]
"MicroSoft Getway mqbol"="xbvuxowlewiv.exe" []
"MicroSoft Legal Service"="Srb0ty.exe" [2007-11-24 19:08 C:\WINDOWS\SYSTEM32\Srb0ty.exe]
"MicroSoft Legal Syst3m32"="Syst3m32.exe" [2007-12-01 11:42 C:\WINDOWS\SYSTEM32\Syst3m32.exe]
"smsger"="C:\WINDOWS\System32\Win.exe" []
"MicroSoft Visual Framwork"="MS32.exe" []
"Windows Secure Update"="load.exe" [2007-12-01 11:32 C:\WINDOWS\SYSTEM32\load.exe]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="C:\WINDOWS\System32\ctfmon.exe" [2001-08-24 01:47]
"HOT FIX"="Gothic.exe" []
"MicroSoft ssadsadas3s1"="eXtream.exe" [2007-12-07 17:25 C:\WINDOWS\SYSTEM32\eXtream.exe]
"MicroSoft ssadssjdhasjadas3s1"="kdjfsdklfjsl.exe" [2007-11-18 11:17 C:\WINDOWS\SYSTEM32\kdjfsdklfjsl.exe]
"MicroSoft sys3s1"="h4ckn3t.exe" []
"MSMSGS"="C:\Program Files\Messenger\msmsgs.exe" [2001-08-02 06:14]
"MicroSoft Getway mqbol"="qrcffqqysayn.exe" []
"Critical Error Safe32"="C:\WINDOWS\System32\GetWaylayer32.exe" []
"MicroSoft Legal Service"="Srb0ty.exe" [2007-11-24 19:08 C:\WINDOWS\SYSTEM32\Srb0ty.exe]
"Windows Secure Update"="load.exe" [2007-12-01 11:32 C:\WINDOWS\SYSTEM32\load.exe]
"MicroSoft Legal Syst3m32"="Syst3m32.exe" [2007-12-01 11:42 C:\WINDOWS\SYSTEM32\Syst3m32.exe]
"MicroSoft Visual Framwork"="MS32.exe" []
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\RunOnce]
"MicroSoft sys3s1"="h4ckn3t.exe" []
"MicroSoft ssadssjdhasjadas3s1"="kdjfsdklfjsl.exe" [2007-11-18 11:17 C:\WINDOWS\SYSTEM32\kdjfsdklfjsl.exe]
"MicroSoft ssadsadas3s1"="eXtream.exe" [2007-12-07 17:25 C:\WINDOWS\SYSTEM32\eXtream.exe]
"HOT FIX"="Gothic.exe" []
"MicroSoft Legal Service"="Srb0ty.exe" [2007-11-24 19:08 C:\WINDOWS\SYSTEM32\Srb0ty.exe]
"Windows Secure Update"="load.exe" [2007-12-01 11:32 C:\WINDOWS\SYSTEM32\load.exe]
"MicroSoft Legal Syst3m32"="Syst3m32.exe" [2007-12-01 11:42 C:\WINDOWS\SYSTEM32\Syst3m32.exe]
"MicroSoft Visual Framwork"="MS32.exe" []
C:\Documents and Settings\All Users\Menu D‚marrer\Programmes\D‚marrage\
hp center.lnk - C:\Program Files\hp center\137903\Program\BackWeb-137903.exe [2001-09-26 19:42:50]
*Newly Created Service* - CATCHME
*Newly Created Service* - PROCEXP90
.
Contenu du dossier 'Scheduled Tasks/Tâches planifiées'
"2007-04-11 21:00:00 C:\WINDOWS\Tasks\Rappel d'abonnement 1 auprès de l'ISP.job"
- C:\WINDOWS\System32\OOBE\oobebaln.exe
"2007-04-13 20:30:00 C:\WINDOWS\Tasks\Rappel d'abonnement 2 auprès de l'ISP.job"
- C:\WINDOWS\System32\OOBE\oobebaln.exe
"2007-04-16 21:30:00 C:\WINDOWS\Tasks\Rappel d'abonnement 3 auprès de l'ISP.job"
- C:\WINDOWS\System32\OOBE\oobebaln.exe
.
**************************************************************************
catchme 0.3.1331 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2007-12-08 19:01:58
Windows 5.1.2600 NTFS
scanning hidden processes ...
? [44744]
? [12852]
? [12872]
? [12900]
scanning hidden autostart entries ...
scanning hidden files ...
**************************************************************************
.
Completion time: 2007-12-08 19:08:46
.
--- E O F ---