Rooter.exe (v1.0.2) by Eric_71
.
SeDebugPrivilege granted successfully ...
.
Windows XP . (5.1.2600) Service Pack 3
[32_bits] - x86 Family 6 Model 8 Stepping 1, AuthenticAMD
.
[wscsvc] STOPPED (state:1) : Security Center -> Disabled !
[SharedAccess] RUNNING (state:4)
Windows Firewall -> Disabled !
.
Internet Explorer 8.0.6001.18702
Mozilla Firefox 3.6.9 (en-US)
.
C:\ [Fixed-NTFS] .. ( Total:38 Go - Free:16 Go )
D:\ [CD_Rom]
E:\ [CD_Rom]
U:\ [Fixed-NTFS] .. ( Total:38 Go - Free:36 Go )
.
Scan : 00:59.58
Path : C:\Documents and Settings\Administrator\Desktop\Rooter.exe
User : Administrator ( Administrator -> YES )
.
----------------------\\ Processes
.
Locked [System Process] (0)
______ System (4)
______ \SystemRoot\System32\smss.exe (404)
______ \??\C:\WINDOWS\system32\csrss.exe (452)
______ \??\C:\WINDOWS\system32\winlogon.exe (476)
______ C:\WINDOWS\system32\services.exe (520)
______ C:\WINDOWS\system32\lsass.exe (540)
______ C:\WINDOWS\system32\svchost.exe (700)
______ C:\WINDOWS\system32\svchost.exe (760)
______ C:\Program Files\Microsoft Security Essentials\MsMpEng.exe (800)
______ C:\WINDOWS\System32\svchost.exe (836)
______ C:\WINDOWS\system32\svchost.exe (920)
______ C:\WINDOWS\system32\svchost.exe (1020)
______ C:\WINDOWS\system32\svchost.exe (1088)
______ C:\Program Files\Tall Emu\Online Armor\oacat.exe (1192)
______ C:\Program Files\Tall Emu\Online Armor\oasrv.exe (1208)
______ C:\WINDOWS\system32\spoolsv.exe (1492)
______ C:\WINDOWS\system32\svchost.exe (1656)
______ C:\Program Files\Java\jre6\bin\jqs.exe (1896)
______ C:\WINDOWS\system32\HPZipm12.exe (2044)
______ C:\WINDOWS\system32\svchost.exe (240)
______ C:\WINDOWS\System32\alg.exe (1252)
______ C:\WINDOWS\Explorer.EXE (3220)
______ C:\Program Files\HP\HP Software Update\HPWuSchd2.exe (3724)
______ C:\WINDOWS\PixArt\PAC7302\Monitor.exe (3896)
______ C:\Program Files\Tall Emu\Online Armor\oaui.exe (4000)
______ C:\Program Files\Microsoft Security Essentials\msseces.exe (392)
______ C:\Program Files\Common Files\Java\Java Update\jusched.exe (1572)
______ C:\Program Files\Sony Ericsson\Sony Ericsson PC Suite\SEPCSuite.exe (1036)
______ C:\Program Files\Tall Emu\Online Armor\OAhlp.exe (2256)
______ C:\WINDOWS\system32\ctfmon.exe (2208)
______ C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe (1752)
______ C:\Program Files\Micronet Wireless Network Utility\RtWlan.exe (2732)
______ C:\Program Files\HP\Digital Imaging\bin\hpqSTE08.exe (368)
______ C:\Program Files\Mozilla Firefox\firefox.exe (3888)
______ C:\Program Files\Microsoft Security Essentials\MpCmdRun.exe (324)
______ C:\Documents and Settings\Administrator\Desktop\Rooter.exe (2776)
.
----------------------\\ Device\Harddisk0\
.
\Device\Harddisk0 [Sectors : 63 x 512 Bytes]
.
\Device\Harddisk0\Partition1 --[ MBR ]-- (Start_Offset:32256 | Length:41093466624)
.
----------------------\\ Scheduled Tasks
.
C:\WINDOWS\Tasks\AppleSoftwareUpdate.job
C:\WINDOWS\Tasks\desktop.ini
C:\WINDOWS\Tasks\Disk Cleanup.job
C:\WINDOWS\Tasks\Google Software Updater.job
C:\WINDOWS\Tasks\MP Scheduled Scan.job
C:\WINDOWS\Tasks\SA.DAT
.
----------------------\\ Registry
.
.
----------------------\\ Files & Folders
.
----------------------\\ Scan completed at 01:00.26
.
C:\Rooter$\Rooter_1.txt - (10/09/2010 | 01:00.26)