Ceci est la meilleure réponse
ah ok, je croyais que ça bloquait le reste... voilà le rapport... et bonne soirée !
DiagHelp version v1.4 -
http://www.malekal.com excute le 23/01/2008 à 19:36:07,43
Liste des derniers fichies modifies/crees dans windir\system32 et prefetch
C:\WINDOWS\prefetch\CMD.EXE-087B4001.pf -->23/01/2008 19:35:23
C:\WINDOWS\prefetch\WINRAR.EXE-39C6DAD9.pf -->23/01/2008 19:33:29
C:\WINDOWS\prefetch\NOTEPAD.EXE-336351A9.pf -->23/01/2008 19:28:55
C:\WINDOWS\prefetch\WMIPRVSE.EXE-28F301A9.pf -->23/01/2008 19:22:25
C:\WINDOWS\prefetch\WUAUCLT.EXE-399A8E72.pf -->23/01/2008 19:22:24
C:\WINDOWS\prefetch\NTOSBOOT-B00DFAAD.pf -->23/01/2008 19:22:23
C:\WINDOWS\prefetch\RUNDLL32.EXE-451FC2C0.pf -->23/01/2008 19:13:51
C:\WINDOWS\prefetch\UNLOCKER.EXE-069B06F9.pf -->23/01/2008 19:05:48
C:\WINDOWS\prefetch\IMAPI.EXE-0BF740A4.pf -->23/01/2008 18:48:46
C:\WINDOWS\prefetch\NERO.EXE-3017C357.pf -->23/01/2008 18:48:37
C:\WINDOWS\System32\drivers\avipbb.sys -->22/01/2008 16:43:16
C:\WINDOWS\System32\drivers\vnbkqahq.dat -->21/01/2008 00:43:00
C:\WINDOWS\System32\drivers\avgntdd.sys -->09/08/2007 13:04:11
C:\WINDOWS\System32\drivers\avgntmgr.sys -->18/07/2007 14:22:19
C:\WINDOWS\System32\drivers\nmwcdcm.sys -->28/06/2007 11:44:18
C:\WINDOWS\System32\drivers\ssmdrv.sys -->01/03/2007 10:34:36
C:\WINDOWS\System32\drivers\pfc.sys -->06/11/2006 14:34:54
C:\WINDOWS\System32\wpa.dbl -->31/12/2007 19:44:59
C:\WINDOWS\System32\FNTCACHE.DAT -->27/12/2007 07:28:01
C:\WINDOWS\System32\PerfStringBackup.INI -->07/12/2007 10:30:42
C:\WINDOWS\System32\perfh00C.dat -->07/12/2007 10:30:42
C:\WINDOWS\System32\perfh009.dat -->07/12/2007 10:30:42
C:\WINDOWS\System32\perfc00C.dat -->07/12/2007 10:30:42
C:\WINDOWS\System32\perfc009.dat -->07/12/2007 10:30:42
C:\WINDOWS\System32\LegitCheckControl.dll -->11/10/2007 14:12:48
C:\WINDOWS\System32\spmsg.dll -->08/10/2007 14:46:18
C:\WINDOWS\System32\jupdate-1.6.0_03-b05.log -->03/10/2007 08:10:07
C:\WINDOWS\System32\javaws.exe -->24/09/2007 22:31:42
C:\WINDOWS\System32\javacpl.cpl -->24/09/2007 22:31:42
C:\WINDOWS\System32\javaw.exe -->24/09/2007 21:30:30
C:\WINDOWS\System32\java.exe -->24/09/2007 21:30:28
C:\WINDOWS\System32\ffnd.exe -->14/08/2007 13:04:24
C:\WINDOWS\System32\wuaucpl.cpl.mui -->30/07/2007 19:20:06
C:\WINDOWS\System32\wuapi.dll.mui -->30/07/2007 19:19:52
C:\WINDOWS\System32\wuweb.dll -->30/07/2007 19:19:46
C:\WINDOWS\System32\wuaueng.dll -->30/07/2007 19:19:42
C:\WINDOWS\System32\wuapi.dll -->30/07/2007 19:19:36
C:\WINDOWS\System32\wucltui.dll -->30/07/2007 19:19:32
C:\WINDOWS\System32\wuaucpl.cpl -->30/07/2007 19:19:28
C:\WINDOWS\System32\cdm.dll -->30/07/2007 19:19:20
C:\WINDOWS\System32\wuauclt.exe -->30/07/2007 19:19:16
C:\WINDOWS\System32\wups2.dll -->30/07/2007 19:19:12
C:\WINDOWS\WindowsUpdate.log -->23/01/2008 19:21:30
C:\WINDOWS\0.log -->23/01/2008 19:21:30
C:\WINDOWS\wiadebug.log -->23/01/2008 19:21:28
C:\WINDOWS\wiaservc.log -->23/01/2008 19:21:25
C:\WINDOWS\bootstat.dat -->23/01/2008 19:20:56
C:\WINDOWS\ntbtlog.txt -->23/01/2008 19:19:53
C:\WINDOWS\SchedLgU.Txt -->23/01/2008 19:16:22
C:\WINDOWS\system.ini -->23/01/2008 14:31:53
C:\WINDOWS\setupapi.log -->21/01/2008 21:56:26
C:\WINDOWS\setuperr.log -->21/01/2008 19:55:26
C:\WINDOWS\setupact.log -->21/01/2008 19:55:26
C:\WINDOWS\QTFont.qfn -->21/01/2008 00:21:54
C:\WINDOWS\CleanRAW.INI -->19/01/2008 22:41:32
C:\WINDOWS\QTFont.for -->01/01/2008 14:21:10
C:\WINDOWS\win.ini -->11/07/2007 15:57:00
winlogon.exe
Verified: Signed
svchost.exe
Verified: Signed
ws2_32.dll
Verified: Signed
user32.dll
Verified: Signed
tcpip.sys
Verified: Signed
ndis.sys
Verified: Signed
null.sys
Verified: Signed
ListDLLs v2.25 - DLL lister for Win9x/NT
Copyright (C) 1997-2004 Mark Russinovich
Sysinternals -
www.sysinternals.com ------------------------------------------------------------------------------
explorer.exe pid: 1176
Command line: C:\WINDOWS\Explorer.EXE
Base Size Version Path
0x01000000 0xf8000 6.00.2600.0000 C:\WINDOWS\Explorer.EXE
0x77be0000 0x53000 7.00.2600.0000 C:\WINDOWS\system32\msvcrt.dll
0x77290000 0x64000 6.00.2750.0167 C:\WINDOWS\system32\SHLWAPI.dll
0x77390000 0x7fd000 6.00.2750.0166 C:\WINDOWS\system32\SHELL32.dll
0x770e0000 0x8b000 3.50.5014.0000 C:\WINDOWS\system32\OLEAUT32.dll
0x71500000 0xfd000 6.00.2737.1600 C:\WINDOWS\System32\BROWSEUI.dll
0x71700000 0x148000 6.00.2750.0167 C:\WINDOWS\System32\SHDOCVW.dll
0x5b090000 0x34000 6.00.2600.0000 C:\WINDOWS\System32\UxTheme.dll
0x71950000 0xe4000 6.00.2600.0000 C:\WINDOWS\WinSxS\x86_Microsoft.Windows.Common-Controls_6595b64144ccf1df_6.0.0.0_x-ww_1382d70a\comctl32.dll
0x77300000 0x8b000 5.82.2600.0000 C:\WINDOWS\system32\comctl32.dll
0x7c620000 0x81000 2001.12.4414.0053 C:\WINDOWS\System32\CLBCATQ.DLL
0x77000000 0xd4000 2001.12.4414.0042 C:\WINDOWS\System32\COMRes.dll
0x65000000 0x25c000 2.00.0001.0002 C:\Program Files\PixVue.Com\PixVue\bin\PixVue.dll
0x65570000 0xef000 C:\Program Files\PixVue.Com\PixVue\bin\CORE_RL_libxml_.dll
0x7c340000 0x56000 7.10.3052.0004 C:\Program Files\PixVue.Com\PixVue\bin\MSVCR71.dll
0x7c3a0000 0x7b000 7.10.3077.0000 C:\Program Files\PixVue.Com\PixVue\bin\MSVCP71.dll
0x65490000 0x63000 C:\Program Files\PixVue.Com\PixVue\bin\CORE_RL_Magick++_.dll
0x65290000 0x21000 6.03.0000.0000 C:\Program Files\PixVue.Com\PixVue\bin\CORE_RL_wand_.dll
0x652c0000 0x1c2000 6.03.0000.0000 C:\Program Files\PixVue.Com\PixVue\bin\CORE_RL_magick_.dll
0x656e0000 0x12000 1.01.0003.0000 C:\Program Files\PixVue.Com\PixVue\bin\CORE_RL_zlib_.dll
0x65660000 0xf000 1.00.0001.0000 C:\Program Files\PixVue.Com\PixVue\bin\CORE_RL_bzlib_.dll
0x65260000 0x29000 C:\Program Files\PixVue.Com\PixVue\bin\CORE_RL_lcms_.dll
0x65690000 0x45000 3.05.0006.0000 C:\Program Files\PixVue.Com\PixVue\bin\CORE_RL_tiff_.dll
0x65500000 0x5b000 2.00.0006.0000 C:\Program Files\PixVue.Com\PixVue\bin\CORE_RL_ttf_.dll
0x65560000 0xa000 C:\Program Files\PixVue.Com\PixVue\bin\CORE_RL_xlib_.dll
0x5b950000 0x71000 6.00.2600.0000 C:\WINDOWS\System32\themeui.dll
0x71ca0000 0x1b000 6.00.2600.0000 C:\WINDOWS\System32\ACTXPRXY.DLL
0x76ac0000 0x15000 3.00.9238.0000 C:\WINDOWS\System32\ATL.DLL
0x745e0000 0x2c6000 3.01.4000.2435 C:\WINDOWS\System32\msi.dll
0x76250000 0x8a000 5.131.2600.1123 C:\WINDOWS\system32\CRYPT32.dll
0x74aa0000 0x43000 6.00.2600.0000 C:\WINDOWS\System32\webcheck.dll
0x74a60000 0x9000 6.00.2600.0000 C:\WINDOWS\System32\BatMeter.dll
0x74a40000 0x7000 6.00.2600.0000 C:\WINDOWS\System32\POWRPROF.dll
0x10000000 0xd4000 6.14.0010.4523 C:\WINDOWS\System32\nView.dll
0x5f140000 0x1a000 5.00.5014.0000 C:\WINDOWS\System32\OLEPRO32.DLL
0x017f0000 0x2a000 6.14.0010.4523 C:\WINDOWS\System32\NVWRSFR.DLL
0x723a0000 0x13000 6.00.2600.0000 C:\WINDOWS\System32\browselc.dll
0x63000000 0x96000 6.00.2737.0800 C:\WINDOWS\system32\WININET.dll
0x1a400000 0x7b000 6.00.2745.2300 C:\WINDOWS\system32\urlmon.dll
0x01cf0000 0x8e000 6.00.2715.0400 C:\WINDOWS\System32\shdoclc.dll
0x01e10000 0x99000 C:\Program Files\PixVue.Com\PixVue\bin\PixVueFRA.dll
0x01d90000 0x32000 3.520.9002.0000 C:\WINDOWS\System32\ODBC32.dll
0x76340000 0x46000 6.00.2600.0000 C:\WINDOWS\system32\comdlg32.dll
0x1f850000 0x18000 3.520.7713.0000 C:\WINDOWS\System32\odbcint.dll
0x732d0000 0x52000 6.00.2750.0167 C:\WINDOWS\System32\zipfldr.dll
0x00960000 0xe000 1.00.0000.1000 C:\Program Files\Nikon\NkView6\NkvDropExt.dll
0x72380000 0x19000 6.00.2600.0000 C:\WINDOWS\System32\mydocs.dll
0x00a00000 0x85000 6.81.0046.0001 C:\Program Files\Nokia\Nokia PC Suite 6\PhoneBrowser.dll
0x00a90000 0x8c000 6.81.0068.0000 C:\Program Files\Nokia\Nokia PC Suite 6\PCSCM.dll
0x00b20000 0x3f000 6.81.0062.0000 C:\WINDOWS\System32\ConnAPI.DLL
0x00b60000 0xb000 6.81.0029.0000 C:\Program Files\Nokia\Nokia PC Suite 6\Lang\PhoneBrowser_fre.nlr
0x00b70000 0x8b000 6.81.0011.0000 C:\Program Files\Nokia\Nokia PC Suite 6\Resource\PhoneBrowser_Nokia.ngr
0x00c40000 0xd000 7.00.0009.0050 C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
0x01a50000 0xd5000 1.04.0000.0000 C:\PROGRA~1\SPYBOT~1\SDHelper.dll
0x32520000 0x12000 10.00.2609.0000 C:\Program Files\Microsoft Office\Office10\msohev.dll
0x00c70000 0x1c000 7.00.0000.0000 C:\Program Files\Adobe\Acrobat 7.0\ActiveX\PDFShell.dll
0x00ca0000 0x6000 C:\Program Files\Unlocker\UnlockerCOM.dll
0x00f50000 0x11000 7.00.0000.0010 C:\Program Files\Avira\AntiVir PersonalEdition Classic\shlext.dll
0x01fb0000 0x102000 7.10.3077.0000 C:\Program Files\Avira\AntiVir PersonalEdition Classic\MFC71U.DLL
0x5d360000 0xf000 7.10.3077.0000 C:\WINDOWS\System32\MFC71FRA.DLL
0x76be0000 0x2b000 5.131.2600.0000 C:\WINDOWS\System32\WINTRUST.dll
0x0ffd0000 0x22000 5.01.2518.0000 C:\WINDOWS\System32\rsaenh.dll
ListDLLs v2.25 - DLL lister for Win9x/NT
Copyright (C) 1997-2004 Mark Russinovich
Sysinternals -
www.sysinternals.com ------------------------------------------------------------------------------
winlogon.exe pid: 524
Command line: winlogon.exe
Base Size Version Path
0x01000000 0x6f000 \??\C:\WINDOWS\system32\winlogon.exe
0x77be0000 0x53000 7.00.2600.0000 C:\WINDOWS\system32\msvcrt.dll
0x76250000 0x8a000 5.131.2600.1123 C:\WINDOWS\system32\CRYPT32.dll
0x77390000 0x7fd000 6.00.2750.0166 C:\WINDOWS\system32\SHELL32.dll
0x77290000 0x64000 6.00.2750.0167 C:\WINDOWS\system32\SHLWAPI.dll
0x77300000 0x8b000 5.82.2600.0000 C:\WINDOWS\system32\COMCTL32.dll
0x007a0000 0x32000 3.520.9002.0000 C:\WINDOWS\system32\ODBC32.dll
0x76340000 0x46000 6.00.2600.0000 C:\WINDOWS\system32\comdlg32.dll
0x007e0000 0xe4000 6.00.2600.0000 C:\WINDOWS\WinSxS\x86_Microsoft.Windows.Common-Controls_6595b64144ccf1df_6.0.0.0_x-ww_1382d70a\comctl32.dll
0x1f850000 0x18000 3.520.7713.0000 C:\WINDOWS\system32\odbcint.dll
0x76b70000 0x1f000 6.00.2600.0000 C:\WINDOWS\system32\SHSVCS.dll
0x76be0000 0x2b000 5.131.2600.0000 C:\WINDOWS\system32\WINTRUST.dll
0x5b090000 0x34000 6.00.2600.0000 C:\WINDOWS\system32\uxtheme.dll
0x0ffd0000 0x22000 5.01.2518.0000 C:\WINDOWS\System32\rsaenh.dll
0x65260000 0xc000 2.00.0001.0000 C:\Program Files\PixVue.Com\PixVue\bin\WinLogon.DLL
0x7c620000 0x81000 2001.12.4414.0053 C:\WINDOWS\system32\CLBCATQ.DLL
0x770e0000 0x8b000 3.50.5014.0000 C:\WINDOWS\system32\OLEAUT32.dll
0x77000000 0xd4000 2001.12.4414.0042 C:\WINDOWS\system32\COMRes.dll
Le volume dans le lecteur C n'a pas de nom.
Le numéro de série du volume est 806F-EDF7
Répertoire de C:\WINDOWS\system
16/06/1995 01:03 4 160 QTNOTIFY.EXE
1 fichier(s) 4 160 octets
0 Rép(s) 13 265 977 344 octets libres
Le volume dans le lecteur C n'a pas de nom.
Le numéro de série du volume est 806F-EDF7
Répertoire de C:\WINDOWS\system32
28/09/2001 18:19 4 096 csrss.exe
1 fichier(s) 4 096 octets
0 Rép(s) 13 265 977 344 octets libres
Le volume dans le lecteur C n'a pas de nom.
Le numéro de série du volume est 806F-EDF7
Répertoire de C:\WINDOWS\system32
28/07/2003 14:19 1 323 008 dmcpl.exe
1 fichier(s) 1 323 008 octets
0 Rép(s) 13 265 977 344 octets libres
Contenu de Downloaded Program Files
Le volume dans le lecteur C n'a pas de nom.
Le numéro de série du volume est 806F-EDF7
Répertoire de C:\WINDOWS\Downloaded Program Files
23/01/2008 18:01 <REP> .
23/01/2008 18:01 <REP> ..
22/08/2006 08:06 537 asinst.inf
24/07/2003 10:42 65 desktop.ini
02/07/2005 09:02 378 ImageUploader3.inf
06/06/2007 18:32 377 ImageUploader4.inf
08/08/2006 11:45 576 kavwebscan.inf
20/01/2000 14:25 1 162 Microsoft XML Parser for Java.osd
27/04/2007 06:33 144 QTPlugin.inf
26/02/2004 12:41 3 888 swflash.inf
30/06/2003 22:41 1 689 WMV9VCM.inf
30/07/2007 19:24 293 wuweb.inf
02/11/2005 18:01 1 777 xscan.inf
11 fichier(s) 10 886 octets
Total des fichiers listés :
11 fichier(s) 10 886 octets
2 Rép(s) 13 265 973 248 octets libres
Recherche de rootkit! (Merci S!Ri)
Recherche d'infections connues
Export des clefs sensibles..
Liste des fichiers en exception sur le pare-feu XP SP2
Export de la clef SharedTaskScheduler
[SharedTaskScheduler]
"{438755C2-A8BA-11D1-B96B-00A0C90312E1}"="Pré-chargeur Browseui"
"{8C7461EF-2B13-11d2-BE35-3078302C2030}"="Démon de cache des catégories de composant"
exports des policies
REGEDIT4
[system]
"dontdisplaylastusername"=dword:00000000
"legalnoticecaption"=""
"legalnoticetext"=""
"shutdownwithoutlogon"=dword:00000001
"undockwithoutlogon"=dword:00000001
Export des clefs sensibles..
Rechercher adresses sensibles dans le fichier HOSTS...
catchme 0.3.1319 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.net Rootkit scan 2008-01-23 19:37:06
Windows 5.1.2600 NTFS
scanning hidden services & system hive ...
scanning hidden registry entries ...
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved\{2FDA15E6-60F0-A875-598A-C15CF4773F93}]
"iapllnbileplniigce"=hex:6b,61,66,67,64,69,66,6b,6c,67,65,63,67,67,61,65,68,64,6c,70,6f,..
"habmnbnechfdmpnp"=hex:6b,61,66,67,64,69,66,6b,6c,67,65,63,67,67,61,65,68,64,6c,70,6f,..
scanning hidden files ...
scan completed successfully
hidden services: 0
hidden files: 0
KProcCheck Version 0.2-beta1 Proof-of-Concept by SIG^2 (www.security.org.sg)
Process list by traversal of KiWaitListHead
4 - System
128 - alg.exe
396 - Daemon.exe
484 - IEXPLORE.EXE
500 - csrss.exe
524 - winlogon.exe
568 - services.exe
580 - lsass.exe
796 - svchost.exe
900 - svchost.exe
1176 - explorer.exe
1284 - avguard.exe
1448 - rundll32.exe
1472 - mixer.exe
1520 - LAUNCH~1.EXE
1532 - avgnt.exe
1568 - GoogleToolbarNo
1584 - PcSync2.exe
1636 - NkbMonitor.exe
1652 - NkvMon.exe
1696 - rundll32.exe
2148 - ServiceLayer.ex
3424 - cmd.exe
Total number of processes = 23
NOTE: Under WinXP, this will not show all processes.
KProcCheck Version 0.2-beta1 Proof-of-Concept by SIG^2 (www.security.org.sg)
Driver/Module list by traversal of PsLoadedModuleList
804D0000 - \WINDOWS\system32\ntoskrnl.exe
8069D000 - \WINDOWS\system32\hal.dll
F7A2F000 - \WINDOWS\system32\KDCOM.DLL
F793F000 - \WINDOWS\system32\BOOTVID.dll
F74E2000 - ACPI.sys
F7A31000 - \WINDOWS\System32\DRIVERS\WMILIB.SYS
F752F000 - pci.sys
F753F000 - isapnp.sys
F77AF000 - vnbkqahq.dat
F7A33000 - intelide.sys
F77B7000 - \WINDOWS\System32\DRIVERS\PCIIDEX.SYS
F754F000 - MountMgr.sys
F74C3000 - ftdisk.sys
F7A35000 - dmload.sys
F749F000 - dmio.sys
F77BF000 - PartMgr.sys
F755F000 - VolSnap.sys
F7489000 - atapi.sys
F756F000 - disk.sys
F757F000 - \WINDOWS\System32\DRIVERS\CLASSPNP.SYS
F7477000 - sr.sys
F758F000 - avgntmgr.sys
F7466000 - TPkd.sys
F7452000 - KSecDD.sys
F759F000 - Defrag32b.sys
F73D3000 - Ntfs.sys
F73AB000 - NDIS.sys
F7392000 - Mup.sys
F77C7000 - agp440.sys
F776F000 - \SystemRoot\System32\DRIVERS\processr.sys
F6C3D000 - \SystemRoot\System32\DRIVERS\nv4_mini.sys
F777F000 - \SystemRoot\System32\DRIVERS\VIDEOPRT.SYS
F6BE0000 - \SystemRoot\system32\drivers\cmaudio.sys
F6B9D000 - \SystemRoot\system32\drivers\portcls.sys
F778F000 - \SystemRoot\system32\drivers\drmk.sys
F6B7C000 - \SystemRoot\system32\drivers\ks.sys
F7A07000 - \SystemRoot\System32\DRIVERS\usbohci.sys
F6B5B000 - \SystemRoot\System32\DRIVERS\USBPORT.SYS
F786F000 - \SystemRoot\System32\DRIVERS\usbehci.sys
F6B4A000 - \SystemRoot\System32\DRIVERS\HSF_BSC2.sys
F779F000 - \SystemRoot\System32\DRIVERS\HSF_SOAR.SYS
F75CF000 - \SystemRoot\System32\DRIVERS\HSF_SAMP.sys
F6AC5000 - \SystemRoot\System32\DRIVERS\HSF_MSFT.sys
F6AA0000 - \SystemRoot\System32\DRIVERS\HSF_AMOS.SYS
F7877000 - \SystemRoot\System32\Drivers\Modem.SYS
F787F000 - \SystemRoot\System32\DRIVERS\fdc.sys
F6A8D000 - \SystemRoot\System32\DRIVERS\parport.sys
F75DF000 - \SystemRoot\System32\DRIVERS\serial.sys
F7A0B000 - \SystemRoot\System32\DRIVERS\serenum.sys
F75EF000 - \SystemRoot\System32\DRIVERS\i8042prt.sys
F7887000 - \SystemRoot\System32\DRIVERS\kbdclass.sys
F788F000 - \SystemRoot\System32\DRIVERS\mouclass.sys
F7A0F000 - \SystemRoot\system32\drivers\pfc.sys
F75FF000 - \SystemRoot\system32\drivers\NeroCd2k.sys
F760F000 - \SystemRoot\System32\DRIVERS\cdrom.sys
F761F000 - \SystemRoot\System32\DRIVERS\redbook.sys
F762F000 - \SystemRoot\System32\Drivers\Imapi.SYS
F7897000 - \SystemRoot\System32\DRIVERS\usbuhci.sys
F7B6E000 - \SystemRoot\System32\DRIVERS\audstub.sys
F763F000 - \SystemRoot\System32\DRIVERS\rasl2tp.sys
F7A1B000 - \SystemRoot\System32\DRIVERS\ndistapi.sys
F6A77000 - \SystemRoot\System32\DRIVERS\ndiswan.sys
F764F000 - \SystemRoot\System32\DRIVERS\raspppoe.sys
F6E05000 - \SystemRoot\System32\DRIVERS\raspptp.sys
F7A1F000 - \SystemRoot\System32\DRIVERS\TDI.SYS
F6A66000 - \SystemRoot\System32\DRIVERS\psched.sys
F6DF5000 - \SystemRoot\System32\DRIVERS\msgpc.sys
F697F000 - \SystemRoot\System32\drivers\dmboot.sys
F789F000 - \SystemRoot\System32\DRIVERS\ptilink.sys
F78A7000 - \SystemRoot\System32\DRIVERS\raspti.sys
F6952000 - \SystemRoot\System32\DRIVERS\rdpdr.sys
F6DE5000 - \SystemRoot\System32\DRIVERS\termdd.sys
F7BE1000 - \SystemRoot\System32\DRIVERS\swenum.sys
F6930000 - \SystemRoot\System32\DRIVERS\update.sys
F6DD5000 - \SystemRoot\System32\DRIVERS\usbhub.sys
F7A65000 - \SystemRoot\System32\DRIVERS\USBD.SYS
F6DC5000 - \SystemRoot\System32\Drivers\NDProxy.SYS
F79C3000 - \SystemRoot\System32\DRIVERS\gameenum.sys
F78AF000 - \SystemRoot\System32\DRIVERS\flpydisk.sys
F6D95000 - \SystemRoot\SYSTEM32\DRIVERS\avgntdd.sys
F7A6D000 - \SystemRoot\System32\Drivers\Fs_Rec.SYS
F7BFA000 - \SystemRoot\System32\Drivers\Null.SYS
F7A6F000 - \SystemRoot\System32\Drivers\Beep.SYS
F78BF000 - \SystemRoot\System32\drivers\vga.sys
F7A71000 - \SystemRoot\System32\Drivers\mnmdd.SYS
F7A73000 - \SystemRoot\System32\DRIVERS\RDPCDD.sys
F78C7000 - \SystemRoot\System32\Drivers\Msfs.SYS
F78CF000 - \SystemRoot\System32\Drivers\Npfs.SYS
F79D3000 - \SystemRoot\System32\DRIVERS\rasacd.sys
F6D85000 - \SystemRoot\System32\DRIVERS\ipsec.sys
F16E8000 - \SystemRoot\System32\DRIVERS\tcpip.sys
F16C3000 - \SystemRoot\System32\DRIVERS\netbt.sys
F6D75000 - \SystemRoot\System32\DRIVERS\netbios.sys
F78D7000 - \SystemRoot\System32\DRIVERS\ssmdrv.sys
F169B000 - \SystemRoot\System32\DRIVERS\rdbss.sys
F1613000 - \SystemRoot\System32\DRIVERS\mrxsmb.sys
F765F000 - \SystemRoot\System32\Drivers\Fips.SYS
F766F000 - \SystemRoot\System32\DRIVERS\wanarp.sys
F767F000 - \SystemRoot\System32\DRIVERS\avipbb.sys
F78E7000 - \SystemRoot\System32\DRIVERS\fbxusb32.sys
F768F000 - \SystemRoot\System32\Drivers\Cdfs.SYS
F15FD000 - \SystemRoot\System32\Drivers\dump_atapi.sys
F7A75000 - \SystemRoot\System32\Drivers\dump_WMILIB.SYS
BF800000 - \??\C:\WINDOWS\system32\win32k.sys
F6A56000 - \??\C:\WINDOWS\system32\watchdog.sys
BFF80000 - \SystemRoot\System32\drivers\dxg.sys
F7C6B000 - \SystemRoot\System32\drivers\dxgthk.sys
BF993000 - \SystemRoot\System32\nv4_disp.dll
F131C000 - \SystemRoot\System32\drivers\afd.sys
F13A0000 - \SystemRoot\System32\DRIVERS\ndisuio.sys
F1021000 - \SystemRoot\System32\DRIVERS\mrxdav.sys
F0FE5000 - \SystemRoot\system32\drivers\wdmaud.sys
F11CC000 - \SystemRoot\system32\drivers\sysaudio.sys
F7AF3000 - \SystemRoot\System32\Drivers\ParVdm.SYS
F0DEA000 - \SystemRoot\System32\Drivers\Defrag32.SYS
F0B9B000 - \SystemRoot\System32\DRIVERS\HSF_FALL.sys
F0B7E000 - \SystemRoot\System32\DRIVERS\HSF_FSKS.sys
F0B1E000 - \SystemRoot\System32\DRIVERS\HSF_K56K.sys
F0AA7000 - \SystemRoot\System32\DRIVERS\srv.sys
F0987000 - \SystemRoot\System32\DRIVERS\HSF_FAXX.sys
F0C1A000 - \SystemRoot\System32\DRIVERS\HSF_TONE.sys
F081F000 - \SystemRoot\System32\DRIVERS\HSF_V124.sys
F071C000 - \SystemRoot\System32\DRIVERS\ipnat.sys
F7B80000 - \SystemRoot\System32\DRIVERS\KProcCheck.sys
Total number of drivers = 124
Liste des programmes installes
a-squared Free 2.0
AC3Filter (remove only)
Ad-Aware SE Personal
Adobe Flash Player 9 ActiveX
Adobe Photoshop CS
Adobe Reader 7.0.9 - Français
Adobe SVG Viewer
Apple Software Update
Archiveur WinRAR
AsusUpdate
Avira AntiVir PersonalEdition Classic
C-Dilla Licence Management System
CCleaner (remove only)
Correctif pour le Lecteur Windows Media [Voir wm828026 pour plus d'informations]
Correctif Windows XP - Article Base de Connaissances 834707
Correctif Windows XP - KB823559
Correctif Windows XP - KB824141
Correctif Windows XP - KB824146
Correctif Windows XP - KB825119
Correctif Windows XP - KB828028
Correctif Windows XP - KB828035
Correctif Windows XP - KB828741
Correctif Windows XP - KB833987
Correctif Windows XP - KB835732
Correctif Windows XP - KB837001
Correctif Windows XP - KB839643
Correctif Windows XP - KB839645
Correctif Windows XP - KB840315
Correctif Windows XP - KB840374
Correctif Windows XP - KB840987
Correctif Windows XP - KB841356
Correctif Windows XP - KB841533
Correctif Windows XP - KB841873
Correctif Windows XP - KB842773
Correctif Windows XP - KB873376
Correctif Windows XP - KB883357
Correctif Windows XP - KB887822
Direct Show Ogg Vorbis Filter (remove only)
DivX Codec
EasyRecovery Professional
EasyRecovery Professional
FileZilla (remove only)
FreeFixer
FTP Expert 3
Google Earth
Google Toolbar for Internet Explorer
Google Toolbar for Internet Explorer
HijackThis 2.0.2
Image Rescue
J2SE Runtime Environment 5.0 Update 10
J2SE Runtime Environment 5.0 Update 11
J2SE Runtime Environment 5.0 Update 2
J2SE Runtime Environment 5.0 Update 4
J2SE Runtime Environment 5.0 Update 6
J2SE Runtime Environment 5.0 Update 9
Java 2 Runtime Environment, SE v1.4.2_04
Java(TM) 6 Update 3
Java(TM) SE Runtime Environment 6 Update 1
Kaspersky Online Scanner
Lecteur Windows Media 10
LexarMedia ImageRescue Software
Macromedia Dreamweaver MX 2004
Macromedia Extension Manager
MacromediaDreamweaver MX
Microsoft .NET Framework 2.0
Microsoft .NET Framework 2.0
Microsoft .NET Framework 2.0 Language Pack - FRA
Microsoft Data Access Components KB870669
Microsoft Office XP Professional
Microsoft Visual C++ 2005 Redistributable
Module de prise en charge linguistique de Microsoft .NET Framework 2.0 - FRA
Mozilla Firefox (2.0.0.11)
MuseTools
Navilog1 3.4.2
NEF Thumbnail Updater
Nero - Burning Rom
Nikon FotoShare
Nikon Message Center
Nikon NEF Plugin
Nikon Scan
Nikon View 6
NikonCapture
Nokia Connectivity Cable Driver
Nokia PC Connectivity Solution
Nokia PC Suite
NVIDIA Windows 2000/XP Display Drivers
Package du correctif Windows XP [voir Q329115 pour plus de détails]
Panda ActiveScan
PCI Audio Applications
PCI Audio Driver
PerfectDisk
PictureProject
PixVue
QuickTime
RealPlayer
RenMultiFiles Pro
Shockwave
SLD CODEC PACK 1.5.3
Spybot - Search & Destroy 1.4
Unlocker 1.7.7
Wanadoo eXtense ECI
WebFldrs XP
Windows Driver Package - Nokia Modem (06/12/2006 6.81.0.21)
Windows Genuine Advantage Validation Tool (KB892130)
Windows Genuine Advantage Validation Tool (KB892130)
Windows Installer 3.0 (KB884016)
Windows Installer 3.1 (KB893803)
Windows Media Format Runtime
Windows XP Application Compatibility Update[Q319580]
Windows XP Hotfix - KB821557
Windows XP Hotfix - KB823182
Windows XP Hotfix - KB823980
Windows XP Hotfix - KB824105
Windows XP Hotfix (SP1) [See Q309521 for more information]
Windows XP Hotfix (SP1) [See Q311889 for more information]
Windows XP Hotfix (SP1) [See Q311967 for more information]
Windows XP Hotfix (SP1) [See Q312370 for more information]
Windows XP Hotfix (SP1) [See Q313450 for more information]
Windows XP Hotfix (SP1) [See Q314862 for more information]
Windows XP Hotfix (SP1) [See Q315000 for more information]
Windows XP Hotfix (SP1) [See Q315403 for more information]
Windows XP Hotfix (SP1) [See Q317277 for more information]
Windows XP Hotfix (SP1) [See Q318138 for more information]
Windows XP Hotfix (SP1) [See Q323172 for more information]
Windows XP Hotfix (SP1) [See Q324096 for more information]
Windows XP Hotfix (SP1) [See Q324380 for more information]
Windows XP Hotfix (SP1) [See Q326830 for more information]
Windows XP Hotfix (SP1) [See Q328940 for more information]
Windows XP Hotfix (SP1) [See Q329048 for more information]
Windows XP Hotfix (SP1) [See Q329390 for more information]
Windows XP Hotfix (SP1) [See Q329441 for more information]
Windows XP Hotfix (SP1) [See Q329834 for more information]
Windows XP Hotfix (SP1) Q328310
Windows XP Hotfix (SP1) Q329170
Windows XP Hotfix (SP1) Q810577
Windows XP Hotfix (SP1) Q810833
Windows XP Hotfix (SP1) Q811493
Windows XP Hotfix (SP1) Q815021
Windows XP Hotfix (SP1) Q817606
Windows XP Hotfix (SP1) Q819696
wxChecksums 1.2.0
XnView 1.91.1
Yooda Map
Le volume dans le lecteur C n'a pas de nom.
Le numéro de série du volume est 806F-EDF7
Répertoire de C:\Program Files
23/01/2008 17:47 <REP> .
23/01/2008 17:47 <REP> ..
02/11/2003 20:33 <REP> AC3Filter
30/11/2006 17:55 <REP> Adobe
03/08/2003 19:21 <REP> ahead
10/08/2006 23:40 <REP> Alcatel
06/12/2007 21:37 <REP> Apple Software Update
21/01/2008 14:05 <REP> a-squared Free
04/12/2006 11:26 <REP> ASUS
22/01/2008 16:39 <REP> Avira
21/07/2006 21:39 <REP> CCleaner
19/11/2007 21:16 <REP> CleanRAW
24/07/2003 11:07 <REP> C-Media
21/07/2007 14:12 <REP> DIFX
01/11/2003 00:39 <REP> DivX
24/07/2003 23:05 <REP> ECI Telecom
01/08/2007 18:23 <REP> eMule
21/01/2008 11:02 <REP> Enigma Software Group
12/12/2007 11:55 <REP> Fichiers communs
19/10/2005 19:39 <REP> FileZilla
28/11/2006 17:55 <REP> FotoStation 4.5
10/08/2006 23:05 <REP> Free
21/01/2008 10:22 <REP> FreeFixer
03/10/2007 17:50 <REP> Google
23/01/2008 17:48 <REP> Grisoft
23/01/2008 18:33 <REP> HijackThis
07/12/2007 10:27 <REP> Internet Explorer
03/10/2007 08:10 <REP> Java
13/08/2006 20:21 <REP> Lavasoft
16/01/2005 09:51 <REP> LexarMedia
20/12/2006 19:09 <REP> Macromedia
24/07/2003 10:52 <REP> Messenger
05/07/2007 23:53 <REP> microsoft frontpage
15/10/2005 08:20 <REP> Microsoft Hardware
24/07/2003 17:16 <REP> Microsoft Office
05/07/2007 23:53 <REP> movie maker
22/01/2008 16:43 <REP> Mozilla Firefox
05/07/2007 23:53 <REP> msn gaming zone
03/08/2003 19:59 <REP> MuseTools
21/01/2008 22:42 <REP> Navilog1
05/07/2007 23:53 <REP> netmeeting
07/12/2007 10:34 <REP> Nikon
12/12/2007 11:54 <REP> Nokia
18/10/2003 21:44 <REP> NVIDIA
11/08/2003 00:27 <REP> Ontrack
06/09/2005 23:06 <REP> Outlook Express
24/07/2003 11:07 <REP> PCI Audio Applications
10/11/2006 11:19 <REP> PixVue.Com
06/12/2007 21:38 <REP> QuickTime
29/08/2006 19:26 <REP> Raxco
29/12/2003 20:21 <REP> Real
29/11/2005 23:06 <REP> RegCleaner
03/09/2007 21:50 <REP> RenMultiFiles Pro
03/09/2003 21:11 <REP> SLD CODEC PACK 1.5.3
12/08/2007 11:32 <REP> Spybot - Search & Destroy
09/01/2008 22:09 <REP> TallStick
11/07/2007 16:27 <REP> Unlocker
03/11/2003 19:57 <REP> Visicom Media
31/08/2005 21:36 <REP> Windows Media Player
24/07/2003 10:39 <REP> Windows NT
13/05/2004 14:33 <REP> WinRAR
13/12/2005 09:18 <REP> wxChecksums
24/07/2003 10:44 <REP> xerox
12/07/2007 14:10 <REP> XnView
21/07/2006 21:48 <REP> Yahoo!
0 fichier(s) 0 octets
65 Rép(s) 13 262 176 256 octets libres
Le volume dans le lecteur C n'a pas de nom.
Le numéro de série du volume est 806F-EDF7
Répertoire de C:\Program Files\fichiers communs
12/12/2007 11:55 <REP> .
12/12/2007 11:55 <REP> ..
23/01/2008 13:01 <REP> Adobe
17/12/2004 23:35 <REP> Adobe Systems Shared
26/07/2003 00:55 <REP> Ahead
24/07/2003 17:17 <REP> Designer
16/11/2004 11:32 <REP> InstallShield
29/12/2003 22:00 <REP> Java
20/12/2006 19:09 <REP> Macromedia
10/01/2004 00:28 <REP> Macromedia Shared
07/12/2007 10:27 <REP> Microsoft Shared
24/07/2003 10:41 <REP> MSSoap
06/05/2006 14:36 <REP> muvee Technologies
10/12/2007 22:17 <REP> Nikon
12/12/2007 11:55 <REP> Nokia
24/07/2003 11:31 <REP> ODBC
16/11/2004 12:47 <REP> PACE Anti-Piracy
12/12/2007 11:55 <REP> PCSuite
30/08/2006 10:30 <REP> Raxco
12/07/2005 13:31 <REP> Real
24/07/2003 11:31 <REP> SpeechEngines
06/09/2005 23:06 <REP> System
12/07/2005 13:31 <REP> xing shared
0 fichier(s) 0 octets
23 Rép(s) 13 262 176 256 octets libres
Le volume dans le lecteur C n'a pas de nom.
Le numéro de série du volume est 806F-EDF7
Répertoire de C:\Program Files\fichiers communs\Microsoft Shared\Web Folders
24/07/2003 17:17 <REP> .
24/07/2003 17:17 <REP> ..
24/07/2003 17:17 <REP> 1033
24/07/2003 17:16 <REP> 1036
15/02/2001 04:45 1 318 912 MSONSEXT.DLL
13/02/2001 07:23 58 784 MSOSV.DLL
03/06/1999 13:09 122 937 MSOWS409.DLL
07/03/2001 08:00 127 033 MSOWS40c.DLL
06/08/2000 08:04 401 462 MSVCP60.DLL
22/01/2001 02:25 69 632 PKMAXCTL.DLL
22/01/2001 02:25 872 448 PKMCDO.DLL
22/01/2001 02:25 159 744 PKMCORE.DLL
07/02/2001 08:59 106 496 PKMFORMS.DLL
12/02/2001 03:03 684 032 PKMRES.DLL
22/01/2001 02:25 28 672 PKMSSTLB.DLL
22/01/2001 02:25 40 960 PKMTEMPL.DLL
22/01/2001 02:25 24 576 PKMTRACE.DLL
22/01/2001 02:25 86 016 PKMWS.DLL
22/01/2001 02:25 237 568 PROMDEMO.DLL
22/01/2001 02:25 184 320 SECMGR.DLL
22/01/2001 02:25 323 584 VAIDDMGR.DLL
22/01/2001 02:25 32 768 VAIMEM.DLL
18 fichier(s) 4 879 944 octets
4 Rép(s) 13 262 176 256 octets libres
Le volume dans le lecteur C n'a pas de nom.
Le numéro de série du volume est 806F-EDF7
Répertoire de C:\
29/06/2007 06:24 286 720 QTTask.exe
1 fichier(s) 286 720 octets
0 Rép(s) 13 262 176 256 octets libres
c:\Documents and Settings\MR PREAU\Application Data\Adobe\Acrobat\7.0\Updater\AdbeRdr709_fr_FR.exe
c:\Documents and Settings\MR PREAU\Application Data\Microsoft\Installer\{633A27AE-C1C4-48E7-85D4-3C34994B5331}\_DB80C12A9E00_495E_9E74_DCEEA3A22A50.exe
c:\Documents and Settings\MR PREAU\Application Data\Microsoft\Installer\{93B8FF8A-E569-459F-BCF4-F17696799324}\ARPPRODUCTICON.exe
c:\Documents and Settings\MR PREAU\Application Data\Microsoft\Installer\{CC9F419B-1E64-49BB-8A13-9608EBF985D7}\_18be6784.exe
c:\Documents and Settings\MR PREAU\Application Data\Microsoft\Installer\{CC9F419B-1E64-49BB-8A13-9608EBF985D7}\_294823.exe
c:\Documents and Settings\MR PREAU\Application Data\Microsoft\Installer\{CC9F419B-1E64-49BB-8A13-9608EBF985D7}\_4ae13d6c.exe
c:\Documents and Settings\MR PREAU\Application Data\Nikon\Message Center\DOWNLOAD_LOG\11592\S-NC____-430WU-NSAEN.exe
c:\Documents and Settings\MR PREAU\Application Data\Nikon\Message Center\DOWNLOAD_LOG\11801\S-NC____-432WU-NSAEN.exe
c:\Documents and Settings\MR PREAU\Application Data\Nikon\Message Center\DOWNLOAD_LOG\11901\A-MCA___-112WU-NSAEN.exe
c:\Documents and Settings\MR PREAU\Application Data\Nikon\Message Center\DOWNLOAD_LOG\12003\S-NC____-440WU-NSAEN.exe
c:\Documents and Settings\MR PREAU\Application Data\Nikon\Message Center\DOWNLOAD_LOG\12219\S-NC____-442WU-NSAEN.exe
c:\Documents and Settings\MR PREAU\Application Data\Nikon\Message Center\DOWNLOAD_LOG\12531\A-MCA___-113W_U-NSAEN.exe
c:\Documents and Settings\MR PREAU\Bureau\avenger.exe
c:\Documents and Settings\MR PREAU\Bureau\ComboFix.exe
c:\Documents and Settings\MR PREAU\Bureau\dss.exe
c:\Documents and Settings\MR PREAU\Bureau\Fixwareout.exe
c:\Documents and Settings\MR PREAU\Bureau\OTMoveIt.exe
c:\Documents and Settings\MR PREAU\Bureau\XnView-win-fr.exe
c:\Documents and Settings\MR PREAU\Bureau\DiagHelp\catchme.exe
c:\Documents and Settings\MR PREAU\Bureau\DiagHelp\diff.exe
c:\Documents and Settings\MR PREAU\Bureau\DiagHelp\dumphive.exe
c:\Documents and Settings\MR PREAU\Bureau\DiagHelp\FilesInfoCmd.exe
c:\Documents and Settings\MR PREAU\Bureau\DiagHelp\find2.exe
c:\Documents and Settings\MR PREAU\Bureau\DiagHelp\Fport.exe
c:\Documents and Settings\MR PREAU\Bureau\DiagHelp\grep.exe
c:\Documents and Settings\MR PREAU\Bureau\DiagHelp\gzip.exe
c:\Documents and Settings\MR PREAU\Bureau\DiagHelp\KProcCheck.exe
c:\Documents and Settings\MR PREAU\Bureau\DiagHelp\LFiles.exe
c:\Documents and Settings\MR PREAU\Bureau\DiagHelp\LISTDLLS.exe
c:\Documents and Settings\MR PREAU\Bureau\DiagHelp\md5sums.exe
c:\Documents and Settings\MR PREAU\Bureau\DiagHelp\pslist.exe
c:\Documents and Settings\MR PREAU\Bureau\DiagHelp\sigcheck.exe
c:\Documents and Settings\MR PREAU\Bureau\DiagHelp\streams.exe
c:\Documents and Settings\MR PREAU\Bureau\DiagHelp\swreg.exe
c:\Documents and Settings\MR PREAU\Bureau\DiagHelp\tar.exe
c:\Documents and Settings\MR PREAU\Local Settings\Temporary Internet Files\Content.IE5\CCL1ZEIG\dss[1].exe
c:\Documents and Settings\All Users\Application Data\Avira\AntiVir PersonalEdition Classic\BACKUP\FAILSAFE\avewin32.dll
c:\Documents and Settings\All Users\Application Data\SecTaskMan\_entreelist.dll
c:\Documents and Settings\All Users\Application Data\SecTaskMan\_enviewlist.dll
c:\Documents and Settings\All Users\Application Data\SecTaskMan\ic_32418F9EE1126B64A90E8365B85CFCF6.dll
c:\Documents and Settings\All Users\Application Data\SecTaskMan\ic_467B7D4A04144D1188BE0005AD53970C.dll
c:\Documents and Settings\All Users\Application Data\SecTaskMan\ic_6099BB8A816EA6041B163738FA4FC693.dll
c:\Documents and Settings\All Users\Application Data\SecTaskMan\ic_68AB67CA7DA76301B744000000000010.dll
c:\Documents and Settings\All Users\Application Data\SecTaskMan\ic_68AB67CA7DA767A5A546E7A854000010.dll
c:\Documents and Settings\All Users\Application Data\SecTaskMan\ic_80BFDB1088EEE5E4496AEAE9CDAF045C.dll
c:\Documents and Settings\All Users\Application Data\SecTaskMan\ic_8A0F841731866D117AB7000B0D410203.dll
c:\Documents and Settings\All Users\Application Data\SecTaskMan\ic_8A0F841731866D117AB7000B0D410204.dll
c:\Documents and Settings\All Users\Application Data\SecTaskMan\ic_8B79C053C7D38EE4AB9A00CB3B5D2472.dll
c:\Documents and Settings\All Users\Application Data\SecTaskMan\ic_C040110900063D11C8EF00054038389C.dll
c:\Documents and Settings\MR PREAU\Application Data\Macromedia\Dreamweaver 8\Configuration\Flash Player\FlashPlayerW.dll
c:\Documents and Settings\MR PREAU\Application Data\Macromedia\Dreamweaver MX 2004\Configuration\Flash Player\FlashPlayerW.dll
c:\Documents and Settings\MR PREAU\Application Data\Macromedia\Dreamweaver MX 2004\Configuration\Flash Player\NPSWF32.dll
****** Fin du rapport DiagHelp
Veuillez svp envoyer le fichier C:\upload_moi_MR-6AIZY9QD1LAR.tar.gz a l'adresse
http://upload.malekal.com