いいいいいいい� Pre_Scan | g3n-h@ckm@n | Saachaa | 3.1229.2 いいいいいいい�
~ いい� XP | Vista | 7 | 8 - 32/64 bits いい� - Start 18:19:58
~ Update on 29/12/2013 | 14.30 by g3n-h@ckm@n
~ Evolution :
http://security-helpzone.com/gen-hackma ... og/2013-2/
~ Pre_Script Infos :
http://security-helpzone.com/gen-hackma ... re_script/
~ Pre_scan Feedbacks :
http://security-helpzone.com/gen-hackma ... ours-bugs/
~ [Sandrine (Administrator)] - [SANDRINE]
~ SID = S-1-5-21-2540246271-1139162819-2694259315
~ System : Windows 8 (64 bits) Core
~ ProcessorNameString : Intel(R) Core(TM) i3-3110M CPU @ 2.40GHz
~ Identifier : Intel64 Family 6 Model 58 Stepping 9
~ Memory RAM = Total (MB) : 4084 | Free (MB) : 2750
~ Pagefile = Total (MB) : 5526 | Free (MB) : 3993
~ Virtual = Total (MB) : 4194 | Free (MB) : 4041
いいいいい | Boot's scripts
いいいいい | Drives
c:\- [Fixed] | [Windows] | Total : 691280 Mo | Free : 638440 Mo - NTFS
d:\- [Fixed] | [RECOVERY] | Total : 23330 Mo | Free : 2350 Mo - NTFS
e:\- [CDROM] | [AOM_D1] | Total : 480 Mo | Free : 0 Mo - CDFS
いいいいい | Windows Updates
No windows updates detected !!!
いいいいい | Sessions
~ C:\Windows\system32\config\systemprofile
~ C:\Windows\ServiceProfiles\LocalService
~ C:\Windows\ServiceProfiles\NetworkService
~ C:\Users\Sandrine
New restorepoint created : To restore the registry : C:\Pre_Scan\Save\Scan\ERDNT.exe
Standby deleted !
いいいいい | Browsers
IE : 10.0.9200.16537 (� Microsoft Corporation.)
FF : 24.0.0.5001 (〧irefox and Mozilla Developers; available under the MPL 2 license.)
GC : 30.0.1599.101 (Copyright 2012 Google Inc.)
いいいいい | FlashPlayer
FlashPlayer ActiveX : 11.9.900.170
FlashPlayer Plugin : 11.9.900.170
いいいいい | Security
いいいいい | stopped Processes
Boot : Normal
いいいいい | Running processes
いいいいい | Winlogon User : OK !
いいいいい | Winlogon Machine
Changed : [HKLM64\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon]|[AutoRestartShell] : 1 - 0
Repaired : [HKLM | Winlogon]|[userinit] : userinit.exe - C:\Windows\SysWOW64\userinit.exe,
いいいいい | Associations
Repaired : [HKCR\Application.Manifest\shell\open\command] : "C:\Windows\System32\rundll32.exe" "C:\Windows\System32\dfshim.dll",ShOpenVerbApplication %1 - rundll32.exe dfshim.dll,ShOpenVerbApplication %1
Repaired : [HKCR\Application.Reference\shell\open\command] : "C:\Windows\System32\rundll32.exe" "C:\Windows\System32\dfshim.dll",ShOpenVerbShortcut %1|%2 - rundll32.exe dfshim.dll,ShOpenVerbShortcut %1|%2
Repaired : [HKCR\Folder\shell\open\command] : %SystemRoot%\Explorer.exe - C:\Windows\Explorer.exe
�
Repaired : [HKLM\Software\Clients\StartMenuInternet\IExplore.exe\shell\open\command] : C:\Program Files\Internet Explorer\iexplore.exe - "C:\Program Files (x86)\Internet Explorer\iexplore.exe"
いいいいい | Registry
Repaired : [HKLM\software\Microsoft\Windows\CurrentVersion\Explorer\HideDesktopIcons\NewStartPanel]|[{9343812e-1c37-4a49-a12e-4b2d810d956b}] : 1 - 0
Repaired : [HKLM64\software\Microsoft\Windows\CurrentVersion\Explorer\HideDesktopIcons\NewStartPanel]|[{9343812e-1c37-4a49-a12e-4b2d810d956b}] : 1 - 0
Repaired : [HKLM\software\Microsoft\Windows\CurrentVersion\Explorer\HideDesktopIcons\NewStartPanel]|[{F02C1A0D-BE21-4350-88B0-7367FC96EF3C}] : 1 - 0
Repaired : [HKLM64\software\Microsoft\Windows\CurrentVersion\Explorer\HideDesktopIcons\NewStartPanel]|[{F02C1A0D-BE21-4350-88B0-7367FC96EF3C}] : 1 - 0
Repaired : [HKLM\software\Microsoft\Windows\CurrentVersion\Explorer\HideDesktopIcons\NewStartPanel]|[{20D04FE0-3AEA-1069-A2D8-08002B30309D}] : 1 - 0
Repaired : [HKLM\software\Microsoft\Windows\CurrentVersion\Explorer\HideDesktopIcons\NewStartPanel]|[{208D2C60-3AEA-1069-A2D7-08002B30309D}] : 1 - 0
Repaired : [HKLM64\software\Microsoft\Windows\CurrentVersion\Explorer\HideDesktopIcons\NewStartPanel]|[{208D2C60-3AEA-1069-A2D7-08002B30309D}] : 1 - 0
Repaired : [HKLM\software\Microsoft\Windows\CurrentVersion\Explorer\HideDesktopIcons\NewStartPanel]|[{871C5380-42A0-1069-A2EA-08002B30309D}] : 1 - 0
Repaired : [HKLM64\software\Microsoft\Windows\CurrentVersion\Explorer\HideDesktopIcons\NewStartPanel]|[{871C5380-42A0-1069-A2EA-08002B30309D}] : 1 - 0
Repaired : [HKLM\software\Microsoft\Windows\CurrentVersion\Explorer\HideDesktopIcons\NewStartPanel]|[{5399E694-6CE5-4D6C-8FCE-1D8870FDCBA0}] : 1 - 0
Repaired : [HKLM64\software\Microsoft\Windows\CurrentVersion\Explorer\HideDesktopIcons\NewStartPanel]|[{5399E694-6CE5-4D6C-8FCE-1D8870FDCBA0}] : 1 - 0
Repaired : [HKLM\software\Microsoft\Windows\CurrentVersion\Explorer\HideDesktopIcons\NewStartPanel]|[{59031a47-3f72-44a7-89c5-5595fe6b30ee}] : 1 - 0
Repaired : [HKLM\software\Microsoft\Windows\CurrentVersion\Policies\Explorer]|[NoActiveDesktop] : 1 - 0
Repaired : [HKLM\software\Microsoft\Windows\CurrentVersion\Policies\Explorer]|[NoActiveDesktopChanges] : 1 - 0
Repaired : [HKU\S-1-5-21-2540246271-1139162819-2694259315-1001\software\Microsoft\Windows\CurrentVersion\Explorer\Advanced]| : 2 - 0
Repaired : [HKU\S-1-5-21-2540246271-1139162819-2694259315-1001\software\Microsoft\Windows\CurrentVersion\Explorer\ControlPanel]|[AllItemsIconView] : 0 - 1
いいいいい | Taskmgr and Registry Access
いいいいい | SafeBoot | Control | Repair
Safeboot Keys are O.K
Alternate shell is OK !
�
Cannot repair ! [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\BasicDisplay.sys] : Driver
Cannot repair ! [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\BasicRender.sys] : Driver
Cannot repair ! [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\dxgkrnl.sys] : Driver
Cannot repair ! [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\FsDepends.sys] : Driver
Repaired : [HKLM | Minimal\vga.sys] : - Driver
Repaired : [HKLM | Minimal\vgasave.sys] : - Driver
�
Cannot repair ! [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\VirtualSmartcardReader] : Driver
Cannot repair ! [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\BasicDisplay.sys] : Driver
Cannot repair ! [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\BasicRender.sys] : Driver
Repaired : [HKLM | Network\vga.sys] : - Driver
Repaired : [HKLM | Network\vgasave.sys] : - Driver
いいいいい | IFEO
いいいいい | Mountpoints2
Deleted : HKU\S-1-5-21-2540246271-1139162819-2694259315-1001\Software\Microsoft\Windows\CurrentVersion\Explorer\Mountpoints2\{c014a7f8-d6a9-11e2-be72-806e6f6e6963} | AutoRun\command : "E:\setup.exe"
Deleted : HKU\S-1-5-21-2540246271-1139162819-2694259315-1001\Software\Microsoft\Windows\CurrentVersion\Explorer\Mountpoints2\{c014a7f8-d6a9-11e2-be72-806e6f6e6963} | setup\command : E:\setup.exe
Contenu de E:\Autorun.inf :
[autorun]
open=setup.exe
icon=setup.exe
shell\setup=Installer Age of Mythology
shell\setup\command=setup.exe
いいいいい | Windows
[HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\IniFileMapping\system.ini\Boot]|[Shell] : SYS:Microsoft\Windows NT\CurrentVersion\Winlogon
[HKLM64\SOFTWARE\Microsoft\Windows NT\CurrentVersion\IniFileMapping\system.ini\Boot]|[Shell] : SYS:Microsoft\Windows NT\CurrentVersion\Winlogon
[HKLM64\SOFTWARE\Microsoft\Windows NT\CurrentVersion\IniFileMapping\win.ini]|[winlogon] : SYS:Microsoft\Windows NT\CurrentVersion\Winlogon
Winsrv : OK !
[HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows]|[AppInit_DLLS] :
[HKLM64\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows]|[AppInit_DLLS] :
[HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows]|[LoadAppInit_DLLs] : 0
いいいいい | Security Center
いいいいい | Services Corrections
Repaired : [HKLM | Services\PlugPlay] : 3 - 2
Repaired : [HKLM | Services\agp440] : 0 - 2
Repaired : [HKLM | Services\Bits] : 3 - 2
Repaired : [HKLM | Services\EapHost] : 3 - 2
Repaired : [HKLM | Services\SharedAccess] : 4 - 2
Repaired : [HKLM | Services\wuauserv] : 3 - 2
Repaired : [HKLM | Services\wudfsvc] : 3 - 2
Repaired : [HKLM | Services\WerSvc] : 3 - 2
いいいいい | Internet Explorer
Repaired : [HKU\S-1-5-21-2540246271-1139162819-2694259315-1001\Software\Microsoft\Internet Explorer\Main]|[Start Page] :
http://www.google.fr/ -
http://www.google.com/
Repaired : [HKU\S-1-5-21-2540246271-1139162819-2694259315-1001\Software\Microsoft\Internet Explorer\Main]|[Local Page] : C:\Windows\system32\blank.htm - C:\Windows\SysWOW64\blank.htm
Repaired : [HKU\S-1-5-21-2540246271-1139162819-2694259315-1001\Software\Microsoft\Internet Explorer\Main]|[Search Page] :
http://go.microsoft.com/fwlink/?LinkId=54896 -
http://www.microsoft.com/isapi/redir.dl ... r=iesearch
Repaired : [HKLM\Software\Microsoft\Internet Explorer\Main]|[Start Page] :
http://g.uk.msn.com/HPNOT13/3 -
http://go.microsoft.com/fwlink/?LinkId=69157
Repaired : [HKLM64\Software\Microsoft\Internet Explorer\Main]|[Start Page] :
http://g.uk.msn.com/HPNOT13/3 -
http://go.microsoft.com/fwlink/?LinkId=69157
Repaired : [HKLM64\Software\Microsoft\Internet Explorer\Main]|[Local Page] : C:\Windows\System32\blank.htm - C:\Windows\SysWOW64\blank.htm
Repaired : [HKLM\Software\Microsoft\Internet Explorer\Main]|[Default_Page_URL] :
http://g.uk.msn.com/HPNOT13/3 -
http://go.microsoft.com/fwlink/?LinkId=69157
Repaired : [HKLM64\Software\Microsoft\Internet Explorer\Main]|[Default_Page_URL] :
http://g.uk.msn.com/HPNOT13/3 -
http://go.microsoft.com/fwlink/?LinkId=69157
�
Repaired : [HKU\S-1-5-21-2540246271-1139162819-2694259315-1001\Software\Microsoft\Windows\CurrentVersion\Internet settings]|[WarnonZoneCrossing] : 0 - 1
いいいいい | Hosts
C:\Windows\System32\Drivers\etc\hosts : Cleaned
いいいいい | reparsepoint
いいいいい | Offsets detection
いいいいい | Files | Folders | Registry
Removed : C:\$Recycle.bin\S-1-5-21-1659622286-4002775231-339507990-500
Removed : C:\$Recycle.bin\S-1-5-21-3925373928-3009158022-86986673-500
Removed : C:\$Recycle.bin\S-1-5-21-2540246271-1139162819-2694259315-500
Removed : C:\$Recycle.bin\S-1-5-18
Removed : C:\$Recycle.bin\S-1-5-21-2540246271-1139162819-2694259315-1001
Moved to quarantine successfully : C:\Windows\Tasks\FacebookUpdateTaskUserS-1-5-21-2540246271-1139162819-2694259315-1001Core.job
Moved to quarantine successfully : C:\Windows\Tasks\Plus-HD-4.9-updater.job
Moved to quarantine successfully : userinit.exe
Moved to quarantine successfully : C:\Windows\assembly\tmp\
Moved to quarantine successfully : C:\Users\Sandrine\AppData\LocalLow\Sun\Java\Deployment\cache\6.0
Prefetch - Emptied
Disinfected : C:\Users\All Users\Microsoft\Windows\Start Menu\Programs\Music, Photos and Videos\Photos Snapfish.lnk : C:\Program Files (x86)\Hewlett-Packard\Shared\WizLink.exe (hxxp://
www.snapfish.com/hp_notebook_desktopicon_2013_fr)
D:\ : Vaccinated (Vaccin created by Pre_Scan)
いいいいい | Hidden files
~ [Drive D:] : Hidden : 9 | Restored : 9
~ [Drive C:] : Hidden : 4 | Restored : 4
~ [Program Files] : Hidden : 3 | Restored : 3
~ [Users] : Hidden : 2 | Restored : 2
~ [Documents] : Hidden : 7 | Restored : 7
~ [Searches] : Hidden : 2 | Restored : 2
~ [Windows] : Hidden : 29 | Restored : 27
~ [Start Menu | Programs | Startup] : Hidden : 1 | Restored : 1
~ [Libraries] : Hidden : 27 | Restored : 27
いいいいい | Listing Partition(s)
Disk: 0 Size=715G
Pos MBRndx Type/Name Size Active Hide Start Sector Sectors
--- ------ ---------- ---- ------ ---- ------------ ------------
0 0 EE-UNKNWN 715G No No 1 465,149,167
いいいいい
[HKLM64 | Winlogon] | AutoRestartShell : 0 - 1
End : 18:27:12
Standby Restored !
いいいいい( EOF )いいいいい - 265