Coller

zaktout Messages postés 7 Statut Membre -  
 Utilisateur anonyme -
Bonjour,
Rebooting

[b]Checking Files [/b]:

No Trojan Files Found

Removing Temp Files

[b]ADS Check [/b]:

[b]Final Check [/b]:

catchme 0.3.1344.2 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-02-27 13:22:56
Windows 5.1.2600 Service Pack 2 NTFS

scanning hidden processes ...

scanning hidden services & system hive ...

scanning hidden registry entries ...

scanning hidden files ...

scan completed successfully
hidden processes: 0
hidden services: 0
hidden files: 0

[b]Remaining Services [/b]:

Authorized Application Key Export:

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
"C:\\Program Files\\Messenger\\msmsgs.exe"="C:\\Program Files\\Messenger\\msmsgs.exe:*:Enabled:Windows Messenger"
"C:\\WINDOWS\\system32\\usmt\\migwiz.exe"="C:\\WINDOWS\\system32\\usmt\\migwiz.exe:*:Disabled:Assistant Transfert de fichiers et de paramŠtres"
"C:\\Program Files\\MSN Messenger\\msnmsgr.exe"="C:\\Program Files\\MSN Messenger\\msnmsgr.exe:*:Enabled:Windows Live Messenger 8.1"
"C:\\Program Files\\MSN Messenger\\livecall.exe"="C:\\Program Files\\MSN Messenger\\livecall.exe:*:Enabled:Windows Live Messenger 8.1 (Phone)"
"%windir%\\Network Diagnostic\\xpnetdiag.exe"="%windir%\\Network Diagnostic\\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000"
"C:\\Program Files\\LimeWire\\LimeWire.exe"="C:\\Program Files\\LimeWire\\LimeWire.exe:*:Enabled:LimeWire"
"C:\\WINDOWS\\system32\\sessmgr.exe"="C:\\WINDOWS\\system32\\sessmgr.exe:*:Disabled:@xpsp2res.dll,-22019"

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
"%windir%\\system32\\sessmgr.exe"="%windir%\\system32\\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
"C:\\Program Files\\MSN Messenger\\msnmsgr.exe"="C:\\Program Files\\MSN Messenger\\msnmsgr.exe:*:Enabled:Windows Live Messenger 8.1"
"C:\\Program Files\\MSN Messenger\\livecall.exe"="C:\\Program Files\\MSN Messenger\\livecall.exe:*:Enabled:Windows Live Messenger 8.1 (Phone)"
"%windir%\\Network Diagnostic\\xpnetdiag.exe"="%windir%\\Network Diagnostic\\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000"

[b]Remaining Files [/b]:

[b]Files with Hidden Attributes [/b]:

Sun 16 Dec 2007 56 ..SHR --- "C:\WINDOWS\system32\19952B7151.sys"
Sun 16 Dec 2007 1,890 A.SH. --- "C:\WINDOWS\system32\KGyGaAvL.sys"
Thu 31 May 2007 50,176 A..H. --- "C:\Documents and Settings\Administrateur\Bureau\SLIM iberchem\~WRL2271.tmp"
Thu 31 May 2007 61,952 A..H. --- "C:\Documents and Settings\Administrateur\Bureau\SLIM iberchem\~WRL2476.tmp"
Thu 31 May 2007 55,808 A..H. --- "C:\Documents and Settings\Administrateur\Bureau\SLIM iberchem\~WRL2525.tmp"
Thu 31 May 2007 61,952 A..H. --- "C:\Documents and Settings\Administrateur\Bureau\SLIM iberchem\~WRL3082.tmp"
Thu 31 May 2007 58,880 A..H. --- "C:\Documents and Settings\Administrateur\Bureau\SLIM iberchem\~WRL3102.tmp"
Thu 31 May 2007 56,320 A..H. --- "C:\Documents and Settings\Administrateur\Bureau\SLIM iberchem\~WRL3783.tmp"
Thu 31 May 2007 60,416 A..H. --- "C:\Documents and Settings\Administrateur\Bureau\SLIM iberchem\~WRL3799.tmp"
Tue 22 Jan 2008 0 A.SH. --- "C:\Documents and Settings\All Users.WINDOWS\DRM\Cache\Indiv01.tmp"
Thu 15 May 2003 43,008 A..H. --- "C:\Program Files\Fichiers communs\Adobe\ESD\DLMCleanup.exe"
Thu 31 May 2007 50,176 A..H. --- "C:\Documents and Settings\Administrateur\Bureau\espagne ord Myriam\SLIM iberchem\~WRL2271.tmp"
Thu 31 May 2007 61,952 A..H. --- "C:\Documents and Settings\Administrateur\Bureau\espagne ord Myriam\SLIM iberchem\~WRL2476.tmp"
Thu 31 May 2007 55,808 A..H. --- "C:\Documents and Settings\Administrateur\Bureau\espagne ord Myriam\SLIM iberchem\~WRL2525.tmp"
Thu 31 May 2007 61,952 A..H. --- "C:\Documents and Settings\Administrateur\Bureau\espagne ord Myriam\SLIM iberchem\~WRL3082.tmp"
Thu 31 May 2007 58,880 A..H. --- "C:\Documents and Settings\Administrateur\Bureau\espagne ord Myriam\SLIM iberchem\~WRL3102.tmp"
Thu 31 May 2007 56,320 A..H. --- "C:\Documents and Settings\Administrateur\Bureau\espagne ord Myriam\SLIM iberchem\~WRL3783.tmp"
Thu 31 May 2007 60,416 A..H. --- "C:\Documents and Settings\Administrateur\Bureau\espagne ord Myriam\SLIM iberchem\~WRL3799.tmp"

[b]Finished![/b]

1 réponse

Utilisateur anonyme
 
Salut,
je trouve que le titre vas bien avec les explications ;)
0