Bonjour Gabriel !
Suite à la trêve de Noêl, voici le rapport du PRE_Scan :
¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤ Pre_Scan | g3n-h@ckm@n | Saachaa | 3.1226.1 ¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤
~ ¤¤¤¤¤ XP | Vista | 7 | 8 - 32/64 bits ¤¤¤¤¤ - Start 14:26:42
~ Update on 26/12/2013 | 09.30 by g3n-h@ckm@n
~ Evolution :
http://security-helpzone.com/gen-hackma ... og/2013-2/
~ Pre_Script Infos :
http://security-helpzone.com/gen-hackma ... re_script/
~ Pre_scan Feedbacks :
http://security-helpzone.com/gen-hackma ... ours-bugs/
~ [Utilisateur (Administrator)] - [UTILISAT-8D2984]
~ SID = S-1-5-21-583907252-606747145-527237240-1002
~ System : Microsoft Windows XP (32 bits) Service Pack 3
~ ProcessorNameString : Intel(R) Atom(TM) CPU 330 @ 1.60GHz
~ Identifier : x86 Family 6 Model 28 Stepping 2
~ Memory RAM = Total (MB) : 1040 | Free (MB) : 482
~ Pagefile = Total (MB) : 3034 | Free (MB) : 2383
~ Virtual = Total (MB) : 2097 | Free (MB) : 2014
¤¤¤¤¤¤¤¤¤¤ | Boot's scripts
¤¤¤¤¤¤¤¤¤¤ | Drives
c:\- [Fixed] | [] | Total : 238460 Mo | Free : 182320 Mo - NTFS
¤¤¤¤¤¤¤¤¤¤ | Windows Updates
Last(s) détection(s) : 2013-12-26 09:58:22
Last(s) download(s) : 2013-12-26 09:30:05
Last(s) installation(s) : 2013-12-25 20:53:53
Next search : 2013-12-27 06:34:05
¤¤¤¤¤¤¤¤¤¤ | Sessions
~ C:\WINDOWS\system32\config\systemprofile
~ C:\Documents and Settings\LocalService
~ C:\Documents and Settings\NetworkService
~ C:\Documents and Settings\Utilisateur
~ C:\Documents and Settings\LogMeInRemoteUser
~ C:\Documents and Settings\LogMeInRemoteUser.UTILISAT-8D2984
~ C:\Documents and Settings\LogMeInRemoteUser.UTILISAT-8D2984.000
New restorepoint created : To restore the registry : C:\Pre_Scan\Save\Scan\ERDNT.exe
Standby deleted !
¤¤¤¤¤¤¤¤¤¤ | Browsers
IE : 8.0.6001.18702 (© Microsoft Corporation.)
¤¤¤¤¤¤¤¤¤¤ | FlashPlayer
FlashPlayer ActiveX : 11.8.800.94
¤¤¤¤¤¤¤¤¤¤ | stopped Processes
(1964) -- brsvc01a.exe
(1992) -- LEXBCES.EXE
(2004) -- brss01a.exe
(180) -- spoolsv.exe
(264) -- LEXPPS.EXE
(740) -- explorer.exe
(876) -- RTHDCPL.EXE
(892) -- igfxtray.exe
(904) -- hkcmd.exe
(912) -- igfxpers.exe
(924) -- SSMMgr.exe
(952) -- LogMeInSystray.exe
(984) -- igfxsrvc.exe
(992) -- vspdfprsrv.exe
(1040) -- brctrcen.exe
(1300) -- Skype.exe
(1232) -- LMIGuardian.exe
(1524) -- ctfmon.exe
(1700) -- BrMfcWnd.exe
(1672) -- McUICnt.exe
(1088) -- BrMfcMon.exe
(1568) -- mDNSResponder.exe
(1100) -- mbamscheduler.exe
(1752) -- McSACore.exe
(1668) -- McAPExe.exe
(1864) -- McSvHost.exe
(2120) -- mfevtps.exe
(2160) -- mbamgui.exe
(2612) -- mcshield.exe
(2680) -- mfefire.exe
(3348) -- CALMAIN.exe
(920) -- msimn.exe
(3840) -- wuauclt.exe
(1688) -- chrome.exe
(484) -- chrome.exe
(2428) -- chrome.exe
(508) -- chrome.exe
Boot : Normal
¤¤¤¤¤¤¤¤¤¤ | Winlogon User : OK !
¤¤¤¤¤¤¤¤¤¤ | Winlogon Machine : OK !
Changed : [HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon]|[AutoRestartShell] : 1 - 0
¤¤¤¤¤¤¤¤¤¤ | Associations
Repaired : [HKCR\Folder\shell\open\command] : %SystemRoot%\Explorer.exe /idlist,%I,%L - C:\WINDOWS\Explorer.exe
¤
Repaired : [HKLM\Software\Clients\StartMenuInternet\IExplore.exe\shell\open\command] : C:\Program Files\Internet Explorer\iexplore.exe - "C:\Program Files\Internet Explorer\iexplore.exe"
Repaired : [HKLM\Software\Clients\StartMenuInternet\Google Chrome\shell\open\command] : "C:\Documents and Settings\Utilisateur\Local Settings\Application Data\Google\Chrome\Application\chrome.exe" - "C:\Program Files\Google\Chrome\Application\chrome.exe"
¤¤¤¤¤¤¤¤¤¤ | Registry
Repaired : [HKLM\software\Microsoft\Windows\CurrentVersion\Explorer\HideDesktopIcons\NewStartPanel]|[{20D04FE0-3AEA-1069-A2D8-08002B30309D}] : 1 - 0
Repaired : [HKLM\software\Microsoft\Windows\CurrentVersion\Explorer\HideDesktopIcons\NewStartPanel]|[{208D2C60-3AEA-1069-A2D7-08002B30309D}] : 1 - 0
Repaired : [HKLM\software\Microsoft\Windows\CurrentVersion\Explorer\HideDesktopIcons\NewStartPanel]|[{871C5380-42A0-1069-A2EA-08002B30309D}] : 1 - 0
Repaired : [HKU\S-1-5-21-583907252-606747145-527237240-1002\software\Microsoft\Windows\CurrentVersion\Explorer\Advanced]| : 2 - 0
¤¤¤¤¤¤¤¤¤¤ | Taskmgr and Registry Access
¤¤¤¤¤¤¤¤¤¤ | SafeBoot | Control | Repair
Safeboot Keys are O.K
Alternate shell is OK !
¤
Repaired : [HKLM | Minimal\vds] : - Service
Repaired : [HKLM | Minimal\{533C5B84-EC70-11D2-9505-00C04F79DEAF}] : - Volume shadow copy
¤
Repaired : [HKLM | Network\rdsessmgr] : - Service
Repaired : [HKLM | Network\termservice] : - Service
Repaired : [HKLM | Network\rdpcdd.sys] : - Driver
Repaired : [HKLM | Network\rdpdd.sys] : - Driver
Repaired : [HKLM | Network\rdpwd.sys] : - Driver
Repaired : [HKLM | Network\tdpipe.sys] : - Driver
Repaired : [HKLM | Network\tdtcp.sys] : - Driver
¤¤¤¤¤¤¤¤¤¤ | IFEO
¤¤¤¤¤¤¤¤¤¤ | Mountpoints2
¤¤¤¤¤¤¤¤¤¤ | Windows
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\IniFileMapping\system.ini\Boot]|[Shell] : SYS:Microsoft\Windows NT\CurrentVersion\Winlogon
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\IniFileMapping\win.ini]|[winlogon] : SYS:Microsoft\Windows NT\CurrentVersion\Winlogon
Winsrv : OK !
[HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows]|[AppInit_DLLS] :
[HKCU\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows]|[Programs] : com exe bat pif cmd
¤¤¤¤¤¤¤¤¤¤ | Security Center
¤¤¤¤¤¤¤¤¤¤ | Services Corrections
Service : SWPRV : Restored
Service : WINMGMT : Restored
Repaired : [HKLM | Services\Browser] : 2 - 3
Repaired : [HKLM | Services\Bits] : 3 - 2
Repaired : [HKLM | Services\EapHost] : 3 - 2
¤¤¤¤¤¤¤¤¤¤ | Internet Explorer
Repaired : [HKU\S-1-5-21-583907252-606747145-527237240-1002\Software\Microsoft\Internet Explorer\Main]|[Search Bar] :
http://g.msn.fr/0SEFRFR/SAOS02 -
http://www.google.com/
Repaired : [HKU\S-1-5-21-583907252-606747145-527237240-1002\Software\Microsoft\Internet Explorer\Main]|[Start Page] :
http://www.google.com -
http://www.google.com/
Repaired : [HKU\S-1-5-18\Software\Microsoft\Internet Explorer\Main]|[Start Page] : aboutblank -
http://www.google.com/
Repaired : [HKU\S-1-5-21-583907252-606747145-527237240-1002\Software\Microsoft\Internet Explorer\Main]|[Search Page] :
http://home.microsoft.com/access/allinone.asp -
http://www.microsoft.com/isapi/redir.dl ... r=iesearch
Repaired : [HKLM\Software\Microsoft\Internet Explorer\Search]|[SearchAssistant] :
http://ie.search.msn.com/{SUB_RFC1766}/ ... chasst.htm -
http://www.google.com/ie
Repaired : [HKLM\Software\Microsoft\Internet Explorer\Main]|[Start Page] :
http://www.google.com -
http://go.microsoft.com/fwlink/?LinkId=69157
Repaired : [HKLM\Software\Microsoft\Internet Explorer\Main]|[Default_Search_URL] :
http://www.microsoft.com/isapi/redir.dl ... r=iesearch -
http://go.microsoft.com/fwlink/?LinkId=54896
Repaired : [HKLM\Software\Microsoft\Internet Explorer\AboutURLs]|[Tabs] :
http://www.google.com - res://ieframe.dll/tabswelcome.htm
¤
Repaired : [HKU\S-1-5-19\Software\Microsoft\Windows\CurrentVersion\Internet settings]|[MigrateProxy] : 0 - 1
Repaired : [HKU\S-1-5-20\Software\Microsoft\Windows\CurrentVersion\Internet settings]|[MigrateProxy] : 0 - 1
Repaired : [HKU\S-1-5-21-583907252-606747145-527237240-1002\Software\Microsoft\Windows\CurrentVersion\Internet settings]|[WarnonZoneCrossing] : 0 - 1
¤¤¤¤¤¤¤¤¤¤ | Hosts
C:\WINDOWS\System32\Drivers\etc\hosts : Cleaned
¤¤¤¤¤¤¤¤¤¤ | reparsepoint
¤¤¤¤¤¤¤¤¤¤ | Offsets detection
¤¤¤¤¤¤¤¤¤¤ | Files | Folders | Registry
Moved to quarantine successfully : C:\Recycler\S-1-5-21-583907252-606747145-527237240-1002\desktop.ini
Moved to quarantine successfully : C:\Recycler\S-1-5-21-583907252-606747145-527237240-1002\INFO2
Removed : C:\Recycler\S-1-5-21-583907252-606747145-527237240-1002
Deleted : HKU\S-1-5-21-583907252-606747145-527237240-1002\Software\AVS4YOU
Deleted : HKLM\Software\AVS4YOU
Moved to quarantine successfully : C:\WINDOWS\Tasks\User_Feed_Synchronization-{57D37EF4-BA26-4D1B-B286-D2280C632801}.job
Moved to quarantine successfully : C:\Program Files\AVS4YOU
Moved to quarantine successfully : C:\Program Files\Fichiers communs\AVSMedia
Deleted : [HKLM\Software\Microsoft\Command Processor]|[AutoRun] :
Moved to quarantine successfully : C:\Documents and settings\All Users\Menu Démarrer\Programmes\Lexmark Z700-P700 Series\Lisez-moi.lnk - C:\WINDOWS\system32\spool\drivers\w32x86\3\LXBLRME.DOC
Moved to quarantine successfully : C:\Documents and settings\All Users\Menu Démarrer\Programmes\Realtek\REALTEK GbE FE Ethernet PCI NIC Driver\Uninstall.lnk - -runfromtemp
Moved to quarantine successfully : C:\Documents and Settings\All Users\Application Data\AVS4YOU
Moved to quarantine successfully : C:\Documents and Settings\Utilisateur\Menu Démarrer\Programmes\AVS4YOU
Moved to quarantine successfully : C:\Documents and Settings\All Users\Menu Démarrer\Programmes\AVS4YOU
Moved to quarantine successfully : C:\WINDOWS\assembly\tmp\
Prefetch - Emptied
¤¤¤¤¤¤¤¤¤¤ | Hidden files
~ [Drive C:] : Hidden : 1 | Restored : 1
~ [Program Files] : Hidden : 18 | Restored : 18
~ [Users] : Hidden : 4 | Restored : 4
~ [Desktop] : Hidden : 44 | Restored : 44
~ [Windows] : Hidden : 376 | Restored : 376
~ [Libraries] : Hidden : 40 | Restored : 40
¤¤¤¤¤¤¤¤¤¤ | Listing Partition(s)
Disk: 0 Size=238G
Pos MBRndx Type/Name Size Active Hide Start Sector Sectors
--- ------ ---------- ---- ------ ---- ------------ ------------
0 0 07-NTFS 238G Yes No 63 488,375,937
¤¤¤¤¤¤¤¤¤¤
[HKLM | Winlogon] | AutoRestartShell : 0 - 1
End : 14:53:33
Standby Restored !
¤¤¤¤¤¤¤¤¤¤( EOF )¤¤¤¤¤¤¤¤¤¤ - 264
Merci beaucoup,
A+tard
Julie