Salut dédétraqué,
voici le rapport demandé
DiagHelp version v1.4 -
http://www.malekal.com
excute le 2009-05-10 à 18:41:01.14
System information for \\ALBERTO:
Uptime: Error reading uptime
Kernel version: Microsoft Windows XP, Uniprocessor Free
Product type: Professional
Product version: 5.1
Service pack: 3
Kernel build number: 2600
Registered organization:
Registered owner: Alberto DELGADO
Install date: 2006-07-25, 19:41
Activation status: Error reading status
IE version: 7.0000
System root: C:\WINDOWS
Processors: 1
Processor speed: 1.7 GHz
Processor type: Mobile AMD Sempron(tm) Processor 3000+
Physical memory: 894 MB
Video driver: ATI MOBILITY RADEON Xpress 200 Series
Volume Type Format Label Size Free Free
C: Fixed NTFS 68.94 GB 4.26 GB 6.2%
D: Fixed FAT32 PRESARIO_RP 5.57 GB 1.08 GB 19.4%
E: CD-ROM 0.0%
F: CD-ROM 0.0%
C:\WINDOWS\prefetch\WMIAPSRV.EXE-1E2270A5.pf -->2009-05-10 18:41:31
C:\WINDOWS\prefetch\PSINFO.EXE-2F8428F9.pf -->2009-05-10 18:41:11
C:\WINDOWS\prefetch\CMD.EXE-087B4001.pf -->2009-05-10 18:41:03
C:\WINDOWS\prefetch\CHCP.COM-18156052.pf -->2009-05-10 18:40:56
C:\WINDOWS\prefetch\WINRAR.EXE-39C6DAD9.pf -->2009-05-10 18:40:42
C:\WINDOWS\prefetch\VERCLSID.EXE-3667BD89.pf -->2009-05-10 18:40:39
C:\WINDOWS\prefetch\WSCNTFY.EXE-1B24F5EB.pf -->2009-05-10 18:40:32
C:\WINDOWS\prefetch\IMAPI.EXE-0BF740A4.pf -->2009-05-10 18:40:31
C:\WINDOWS\prefetch\RUNDLL32.EXE-451FC2C0.pf -->2009-05-10 18:40:24
C:\WINDOWS\prefetch\AVWSC.EXE-0283F9DD.pf -->2009-05-10 18:40:22
C:\WINDOWS\System32\drivers\mbamswissarmy.sys -->2009-04-06 15:32:54
C:\WINDOWS\System32\drivers\mbam.sys -->2009-04-06 15:32:46
C:\WINDOWS\System32\drivers\avipbb.sys -->2009-03-30 10:32:47
C:\WINDOWS\System32\drivers\avgntflt.sys -->2009-03-24 16:07:58
C:\WINDOWS\System32\drivers\ssmdrv.sys -->2009-02-13 12:49:30
C:\WINDOWS\System32\drivers\avgntmgr.sys -->2009-02-13 12:28:39
C:\WINDOWS\System32\drivers\avgntdd.sys -->2009-02-13 12:17:49
C:\WINDOWS\System32\perfh00C.dat -->2009-05-10 18:41:31
C:\WINDOWS\System32\perfh009.dat -->2009-05-10 18:41:31
C:\WINDOWS\System32\perfc00C.dat -->2009-05-10 18:41:31
C:\WINDOWS\System32\perfc009.dat -->2009-05-10 18:41:31
C:\WINDOWS\System32\PerfStringBackup.INI -->2009-05-10 18:41:30
C:\WINDOWS\System32\wpa.dbl -->2009-05-02 15:04:54
C:\WINDOWS\System32\MRT.exe -->2009-04-06 16:57:24
C:\WINDOWS\System32\wrap_oal.dll -->2009-03-24 22:20:01
C:\WINDOWS\System32\OpenAL32.dll -->2009-03-24 22:20:01
C:\WINDOWS\System32\kernel32.dll -->2009-03-21 16:07:58
C:\WINDOWS\System32\FNTCACHE.DAT -->2009-03-15 20:54:56
C:\WINDOWS\System32\msrating.dll.mui -->2009-03-08 14:17:46
C:\WINDOWS\System32\mshta.exe.mui -->2009-03-08 14:17:30
C:\WINDOWS\System32\ie4uinit.exe.mui -->2009-03-08 14:16:06
C:\WINDOWS\System32\iedkcs32.dll.mui -->2009-03-08 14:15:48
C:\WINDOWS\System32\html.iec -->2009-03-08 04:35:10
C:\WINDOWS\System32\ieudinit.exe -->2009-03-08 04:32:52
C:\WINDOWS\System32\pdh.dll -->2009-03-06 16:20:52
C:\WINDOWS\System32\wininet.dll -->2009-03-03 02:13:06
C:\WINDOWS\System32\msctfime.ime -->2009-02-27 06:57:11
C:\WINDOWS\System32\ieencode.dll -->2009-02-20 19:10:57
C:\WINDOWS\System32\webcheck.dll -->2009-02-20 19:10:56
C:\WINDOWS\System32\urlmon.dll -->2009-02-20 19:10:56
C:\WINDOWS\System32\url.dll -->2009-02-20 19:10:55
C:\WINDOWS\System32\pngfilt.dll -->2009-02-20 19:10:55
C:\WINDOWS\WindowsUpdate.log -->2009-05-10 17:32:16
C:\WINDOWS\SchedLgU.Txt -->2009-05-10 00:04:00
C:\WINDOWS\0.log -->2009-05-09 20:00:59
C:\WINDOWS\wiadebug.log -->2009-05-09 20:00:56
C:\WINDOWS\wiaservc.log -->2009-05-09 20:00:50
C:\WINDOWS\bootstat.dat -->2009-05-09 20:00:29
C:\WINDOWS\setupapi.log -->2009-05-09 19:57:10
C:\WINDOWS\NeroDigital.ini -->2009-05-09 00:14:47
C:\WINDOWS\ntbtlog.txt -->2009-05-08 14:17:25
C:\WINDOWS\system.ini -->2009-05-08 02:06:53
C:\WINDOWS\wmsetup.log -->2009-05-04 23:18:25
C:\WINDOWS\KB960715.log -->2009-05-03 03:01:21
C:\WINDOWS\tsoc.log -->2009-05-03 02:24:54
C:\WINDOWS\ocmsn.log -->2009-05-03 02:24:54
C:\WINDOWS\ntdtcsetup.log -->2009-05-03 02:24:54
Le volume dans le lecteur C n'a pas de nom.
Le numéro de série du volume est 33C5-1859
Répertoire de C:\WINDOWS
2009-05-02 02:18 <REP> $hf_mig$
2006-02-20 06:42 <REP> $MSI31Uninstall_KB893803v2$
2006-02-20 06:15 <REP> $NtUninstallKB885250$
2006-02-20 06:24 <REP> $NtUninstallKB885464$
2009-05-03 01:50 <REP> $NtUninstallKB915865$
2009-04-15 09:33 <REP> $NtUninstallKB923561$
2009-03-11 04:02 <REP> $NtUninstallKB938464-v2$
2009-04-15 09:36 <REP> $NtUninstallKB952004$
2009-04-15 09:36 <REP> $NtUninstallKB956572$
2009-01-15 18:52 <REP> $NtUninstallKB958687$
2009-03-11 04:02 <REP> $NtUninstallKB958690$
2009-04-15 09:40 <REP> $NtUninstallKB959426$
2009-03-11 04:00 <REP> $NtUninstallKB959772_WM11$
2009-03-11 04:03 <REP> $NtUninstallKB960225$
2009-02-13 03:15 <REP> $NtUninstallKB960715$
2009-04-15 09:35 <REP> $NtUninstallKB960803$
2009-04-15 09:39 <REP> $NtUninstallKB961373$
2009-04-29 01:37 <REP> $NtUninstallKB961503$
2009-03-06 00:27 <REP> $NtUninstallKB967715$
2008-04-13 18:13 <REP> ftpcache
2009-05-03 01:53 <REP> ie7
2009-05-09 19:24 <REP> inf
2009-05-03 02:38 <REP> Installer
2009-05-02 14:59 <REP> msdownld.tmp
2006-08-21 02:54 <REP> PIF
2006-08-29 22:20 8,192 Thumbs.db
2004-09-06 16:03 1,494 WdRX.pin
2004-08-05 10:00 49,102 winnt.bmp
2004-08-05 10:00 49,102 winnt256.bmp
5 fichier(s) 108,639 octets
25 Rép(s) 4,575,805,440 octets libres
Le volume dans le lecteur C n'a pas de nom.
Le numéro de série du volume est 33C5-1859
Répertoire de C:\WINDOWS\system32
2008-10-01 22:20 6,144 access.ctl
2009-05-03 02:26 <REP> dllcache
2008-11-07 16:16 56 ezsidmv.dat
9 fichier(s) 10,921 octets
1 Rép(s) 4,575,797,248 octets libres
winlogon.exe
Verified: Signed
svchost.exe
Verified: Signed
ws2_32.dll
Verified: Signed
user32.dll
Verified: Signed
tcpip.sys
Verified: Signed
ndis.sys
Verified: Signed
null.sys
Verified: Signed
userinit.exe
kernel32.dll
ListDLLs v2.25 - DLL lister for Win9x/NT
Copyright (C) 1997-2004 Mark Russinovich
Sysinternals -
www.sysinternals.com
------------------------------------------------------------------------------
explorer.exe pid: 316
Command line: C:\WINDOWS\Explorer.EXE
Base Size Version Path
0x77be0000 0x58000 7.00.2600.5512 C:\WINDOWS\system32\msvcrt.dll
0x779e0000 0x97000 5.131.2600.5512 C:\WINDOWS\system32\CRYPT32.dll
0x76610000 0x84000 5.131.2600.5512 C:\WINDOWS\system32\CRYPTUI.dll
0x44080000 0xd0000 7.00.6000.16827 C:\WINDOWS\system32\WININET.dll
0x00400000 0x9000 6.00.5441.0000 C:\WINDOWS\system32\Normaliz.dll
0x43e00000 0x45000 7.00.6000.16825 C:\WINDOWS\system32\iertutil.dll
0x76be0000 0x2e000 5.131.2600.5512 C:\WINDOWS\system32\WINTRUST.dll
0x753c0000 0x6b000 1.420.2600.5512 C:\WINDOWS\system32\USP10.dll
0x58b50000 0x9a000 5.82.2900.5512 C:\WINDOWS\system32\comctl32.dll
0x76f80000 0x7f000 2001.12.4414.0700 C:\WINDOWS\system32\CLBCATQ.DLL
0x77000000 0xd4000 2001.12.4414.0700 C:\WINDOWS\system32\COMRes.dll
0x45180000 0x127000 7.00.6000.16825 C:\WINDOWS\system32\urlmon.dll
0x44360000 0x5cd000 7.00.6000.16825 C:\WINDOWS\system32\ieframe.dll
0x76ac0000 0x11000 3.05.2284.0001 C:\WINDOWS\system32\ATL.DLL
0x7d200000 0x2bc000 3.01.4001.5512 C:\WINDOWS\system32\msi.dll
0x442b0000 0x3c000 7.00.6000.16825 C:\WINDOWS\system32\webcheck.dll
0x164a0000 0x23000 5.02.5721.5145 C:\WINDOWS\system32\WPDShServiceObj.dll
0x109c0000 0x2c000 5.02.5721.5145 C:\WINDOWS\system32\PortableDeviceTypes.dll
0x10930000 0x49000 5.02.5721.5145 C:\WINDOWS\system32\PortableDeviceApi.dll
0x76010000 0x65000 6.02.3104.0000 C:\WINDOWS\system32\MSVCP60.dll
0x10000000 0x1c000 7.00.0000.0000 C:\Program Files\Adobe\Acrobat 7.0\ActiveX\PDFShell.dll
0x03b60000 0x45000 5.20.0006.0002 C:\Program Files\HPQ\Quick Launch Buttons\CPQINFO.DLL
0x03910000 0x12000 1.01.0000.0000 C:\Program Files\Malwarebytes' Anti-Malware\mbamext.dll
0x03aa0000 0x2c000 C:\Program Files\WinRAR\rarext.dll
0x03930000 0x18000 9.00.0000.0003 C:\Program Files\Avira\AntiVir Desktop\shlext.dll
0x789e0000 0x3a1000 9.00.30729.0001 C:\WINDOWS\WinSxS\x86_Microsoft.VC90.MFC_1fc8b3b9a1e18e3b_9.0.30729.1_x-ww_405b0943\mfc90u.dll
0x78520000 0xa3000 9.00.30729.0001 C:\WINDOWS\WinSxS\x86_Microsoft.VC90.CRT_1fc8b3b9a1e18e3b_9.0.30729.1_x-ww_6f74963e\MSVCR90.dll
0x5d360000 0xf000 9.00.30729.0001 C:\WINDOWS\WinSxS\x86_Microsoft.VC90.MFCLOC_1fc8b3b9a1e18e3b_9.0.30729.1_x-ww_b0db7d03\MFC90FRA.DLL
0x03fc0000 0x1a000 2.02.0000.0000 C:\Program Files\Pando Networks\Pando\PandoShellExt.dll
0x04100000 0xa000 C:\Program Files\EditPlus 3\eppshell.dll
0x4eb80000 0x1a6000 5.01.3102.5581 C:\WINDOWS\WinSxS\x86_Microsoft.Windows.GdiPlus_6595b64144ccf1df_1.0.2600.5581_x-ww_dfbc4fc4\gdiplus.dll
0x73600000 0x7000 6.05.2600.5512 C:\WINDOWS\system32\msdmo.dll
0x056a0000 0xb8000 0.09.0001.0000 C:\WINDOWS\system32\lameACM.acm
0x43c10000 0x1d000 7.00.6000.16825 C:\WINDOWS\system32\URL.dll
0x74730000 0x3d000 3.525.1132.0000 C:\WINDOWS\system32\ODBC32.dll
0x1f840000 0x18000 3.525.1117.0000 C:\WINDOWS\system32\odbcint.dll
ListDLLs v2.25 - DLL lister for Win9x/NT
Copyright (C) 1997-2004 Mark Russinovich
Sysinternals -
www.sysinternals.com
------------------------------------------------------------------------------
winlogon.exe pid: 912
Command line: winlogon.exe
Base Size Version Path
0x01000000 0x82000 \??\C:\WINDOWS\system32\winlogon.exe
0x77be0000 0x58000 7.00.2600.5512 C:\WINDOWS\system32\msvcrt.dll
0x779e0000 0x97000 5.131.2600.5512 C:\WINDOWS\system32\CRYPT32.dll
0x76be0000 0x2e000 5.131.2600.5512 C:\WINDOWS\system32\WINTRUST.dll
0x753c0000 0x6b000 1.420.2600.5512 C:\WINDOWS\system32\USP10.dll
0x58b50000 0x9a000 5.82.2900.5512 C:\WINDOWS\system32\COMCTL32.dll
0x74730000 0x3d000 3.525.1132.0000 C:\WINDOWS\system32\ODBC32.dll
0x1f840000 0x18000 3.525.1117.0000 C:\WINDOWS\system32\odbcint.dll
0x10000000 0x17000 6.14.0010.4140 C:\WINDOWS\system32\Ati2evxx.dll
0x77000000 0xd4000 2001.12.4414.0700 C:\WINDOWS\system32\COMRes.dll
0x76f80000 0x7f000 2001.12.4414.0700 C:\WINDOWS\system32\CLBCATQ.DLL
Contenu de Downloaded Program Files
Le volume dans le lecteur C n'a pas de nom.
Le numéro de série du volume est 33C5-1859
Répertoire de C:\WINDOWS\Downloaded Program Files
2009-05-09 19:24 <REP> .
2009-05-09 19:24 <REP> ..
2005-02-14 09:54 450,240 AXVidCap.ocx
2004-12-07 18:07 32 bdcore.dll
2005-03-01 16:08 118,784 bdupd.dll
2004-08-17 11:16 65 desktop.ini
2002-07-25 19:13 24,576 dwusplay.dll
2002-07-25 19:13 196,608 dwusplay.exe
2008-05-29 16:52 3,200,272 EPUWALcontrol.dll
2008-03-24 19:33 1,527,056 FP_AX_CAB_INSTALLER.exe
2005-03-01 16:08 53,248 ipsupd.dll
2004-07-27 17:48 323,584 isusweb.dll
2008-08-13 15:03 575 kavwebscan.inf
2005-03-09 17:42 6,742 lang.ini
2006-07-27 14:52 367 LegitCheckControl.inf
2004-12-07 18:07 32 libfn.dll
2005-02-18 18:22 126 live.ini
2003-05-29 17:00 160,864 messengerstatsclient.dll
2007-02-23 00:41 304,544 MessengerStatsPAClient.dll
2000-01-20 16:25 1,162 Microsoft XML Parser for Java.osd
2007-02-28 14:21 130,472 MineSweeper.dll
2006-06-20 15:44 379,704 MsnPUpld.dll
2006-06-19 14:40 393 MsnPUpld.inf
2006-06-01 04:57 1,331 oscan8.inf
2006-06-01 04:54 471,040 oscan8.ocx
2006-05-31 06:15 10 oscan81.ocx_x
2006-06-20 15:44 117,560 PURen-us.dll
2007-01-09 08:30 110,592 PURfr-fr.dll
2004-10-15 09:59 110,592 PURfr-xx.dll
2005-03-09 17:43 6,828 scanoptions.tsi
2007-05-03 16:35 300 setup.MSNFix
2008-03-24 19:18 247 swflash.inf
30 fichier(s) 7,697,946 octets
Total des fichiers listés :
30 fichier(s) 7,697,946 octets
2 Rép(s) 4,575,936,512 octets libres
Recherche de rootkit! (Merci S!Ri)
Recherche d'infections connues
Export des clefs sensibles..
Liste des fichiers en exception sur le pare-feu XP SP2
"%windir%\\system32\\sessmgr.exe"="%windir%\\system32\\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
"C:\\Program Files\\Messenger\\msmsgs.exe"="C:\\Program Files\\Messenger\\msmsgs.exe:*:Enabled:Windows Messenger"
"C:\\Program Files\\Pando Networks\\Pando\\pando.exe"="C:\\Program Files\\Pando Networks\\Pando\\pando.exe:*:Enabled:pando"
"C:\\Program Files\\eMule\\emule.exe"="C:\\Program Files\\eMule\\emule.exe:*:Enabled:eMule"
"%windir%\\Network Diagnostic\\xpnetdiag.exe"="%windir%\\Network Diagnostic\\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000"
"C:\\Program Files\\AMSN\\bin\\wish.exe"="C:\\Program Files\\AMSN\\bin\\wish.exe:*:Enabled:Wish Application"
"C:\\Program Files\\Counter-Strike Source\\hl2.exe"="C:\\Program Files\\Counter-Strike Source\\hl2.exe:*:Enabled:hl2"
"C:\\Program Files\\Counter-Strike Source\\srcds.exe"="C:\\Program Files\\Counter-Strike Source\\srcds.exe:*:Enabled:srcds"
"C:\\Program Files\\uTorrent\\uTorrent.exe"="C:\\Program Files\\uTorrent\\uTorrent.exe:*:Enabled:µTorrent"
"C:\\WINDOWS\\pchealth\\helpctr\\binaries\\HelpCtr.exe"="C:\\WINDOWS\\pchealth\\helpctr\\binaries\\HelpCtr.exe:*:Enabled:Assistance à distance - Windows Messenger et voix"
"C:\\Program Files\\Microsoft ActiveSync\\rapimgr.exe"="C:\\Program Files\\Microsoft ActiveSync\\rapimgr.exe:169.254.2.0/255.255.255.0:Enabled:ActiveSync RAPI Manager"
"C:\\Program Files\\Microsoft ActiveSync\\wcescomm.exe"="C:\\Program Files\\Microsoft ActiveSync\\wcescomm.exe:169.254.2.0/255.255.255.0:Enabled:ActiveSync Connection Manager"
"C:\\Program Files\\Microsoft ActiveSync\\WCESMgr.exe"="C:\\Program Files\\Microsoft ActiveSync\\WCESMgr.exe:169.254.2.0/255.255.255.0:Enabled:ActiveSync Application"
"C:\\Program Files\\Skype\\Phone\\Skype.exe"="C:\\Program Files\\Skype\\Phone\\Skype.exe:*:Enabled:Skype"
"C:\\Program Files\\VideoLAN\\VLC\\vlc.exe"="C:\\Program Files\\VideoLAN\\VLC\\vlc.exe:*:Enabled:VLC media player"
"C:\\Program Files\\Windows Live\\Messenger\\wlcsdk.exe"="C:\\Program Files\\Windows Live\\Messenger\\wlcsdk.exe:*:Enabled:Windows Live Call"
"C:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"="C:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe:*:Enabled:Windows Live Messenger"
"C:\\Program Files\\SopCast\\adv\\SopAdver.exe"="C:\\Program Files\\SopCast\\adv\\SopAdver.exe:*:Enabled:SopCast Adver"
"C:\\Program Files\\SopCast\\SopCast.exe"="C:\\Program Files\\SopCast\\SopCast.exe:*:Enabled:SopCast Main Application"
"%windir%\\system32\\sessmgr.exe"="%windir%\\system32\\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
"%windir%\\Network Diagnostic\\xpnetdiag.exe"="%windir%\\Network Diagnostic\\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000"
"C:\\Program Files\\Microsoft ActiveSync\\rapimgr.exe"="C:\\Program Files\\Microsoft ActiveSync\\rapimgr.exe:169.254.2.0/255.255.255.0:Enabled:ActiveSync RAPI Manager"
"C:\\Program Files\\Microsoft ActiveSync\\wcescomm.exe"="C:\\Program Files\\Microsoft ActiveSync\\wcescomm.exe:169.254.2.0/255.255.255.0:Enabled:ActiveSync Connection Manager"
"C:\\Program Files\\Microsoft ActiveSync\\WCESMgr.exe"="C:\\Program Files\\Microsoft ActiveSync\\WCESMgr.exe:169.254.2.0/255.255.255.0:Enabled:ActiveSync Application"
"C:\\Program Files\\Windows Live\\Messenger\\wlcsdk.exe"="C:\\Program Files\\Windows Live\\Messenger\\wlcsdk.exe:*:Enabled:Windows Live Call"
"C:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"="C:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe:*:Enabled:Windows Live Messenger"
Export de la clef SharedTaskScheduler
[SharedTaskScheduler]
"{438755C2-A8BA-11D1-B96B-00A0C90312E1}"="Pré-chargeur Browseui"
"{8C7461EF-2B13-11d2-BE35-3078302C2030}"="Démon de cache des catégories de composant"
exports des policies
REGEDIT4
[system]
"dontdisplaylastusername"=dword:00000000
"legalnoticecaption"=""
"legalnoticetext"=""
"shutdownwithoutlogon"=dword:00000001
"undockwithoutlogon"=dword:00000001
"DisableRegistryTools"=dword:00000000
Export des clefs sensibles..
Rechercher adresses sensibles dans le fichier HOSTS...
catchme 0.3.1344 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.net
Rootkit scan 2009-05-10 18:42:18
Windows 5.1.2600 Service Pack 3 NTFS
scanning hidden services & system hive ...
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\sptd\Cfg]
"s0"=dword:4e445e12
"s1"=dword:0f54483e
"s2"=dword:0f8117ef
"h0"=dword:00000001
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4]
"p0"="C:\Program Files\DAEMON Tools\"
"h0"=dword:00000000
"khjeh"=hex:2e,3f,92,7c,ed,3e,62,28,55,b8,54,f5,35,5b,88,23,17,5a,42,af,f8,..
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001]
"a0"=hex:20,01,00,00,65,53,bb,9f,82,dc,63,e5,bd,49,a1,0e,23,a6,fe,8b,1b,..
"khjeh"=hex:01,3d,b0,fd,eb,04,3f,21,ac,78,a8,56,5c,ed,49,08,ea,ae,ad,04,8c,..
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001\0Jf40]
"khjeh"=hex:08,90,1c,55,8a,b1,32,07,6a,5a,a4,52,55,47,7a,2b,92,7d,aa,cd,48,..
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4]
"p0"="C:\Program Files\DAEMON Tools\"
"h0"=dword:00000000
"khjeh"=hex:2e,3f,92,7c,ed,3e,62,28,55,b8,54,f5,35,5b,88,23,17,5a,42,af,f8,..
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001]
"a0"=hex:20,01,00,00,65,53,bb,9f,82,dc,63,e5,bd,49,a1,0e,23,a6,fe,8b,1b,..
"khjeh"=hex:01,3d,b0,fd,eb,04,3f,21,ac,78,a8,56,5c,ed,49,08,ea,ae,ad,04,8c,..
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001\0Jf40]
"khjeh"=hex:03,e1,93,3a,c3,f9,1e,84,65,cd,1d,ec,5c,2d,d3,fa,35,00,cc,0b,4b,..
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet003\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4]
"p0"="C:\Program Files\DAEMON Tools\"
"h0"=dword:00000000
"khjeh"=hex:2e,3f,92,7c,ed,3e,62,28,55,b8,54,f5,35,5b,88,23,17,5a,42,af,f8,..
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet003\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001]
"a0"=hex:20,01,00,00,65,53,bb,9f,82,dc,63,e5,bd,49,a1,0e,23,a6,fe,8b,1b,..
"khjeh"=hex:01,3d,b0,fd,eb,04,3f,21,ac,78,a8,56,5c,ed,49,08,ea,ae,ad,04,8c,..
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet003\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001\0Jf40]
"khjeh"=hex:08,90,1c,55,8a,b1,32,07,6a,5a,a4,52,55,47,7a,2b,92,7d,aa,cd,48,..
scanning hidden registry entries ...
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\\xd8\x2022\x20ac|\xff\xff\xff\xff\22\x2022\x20ac|\xf9\x20229~\2]
"C040110900063D11C8EF10054038389C"="C?\WINDOWS\system32\FM20ENU.DLL"
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\h\x2013\x20ac|\xff\xff\xff\xff\xa4\x2022\x20ac|\xf9\x20229~\2]
"C040110900063D11C8EF10054038389C"="C?\WINDOWS\system32\FM20ENU.DLL"
scanning hidden files ...
scan completed successfully
hidden services: 0
hidden files: 0
Stealth MBR rootkit detector 0.2.4 by Gmer,
http://www.gmer.net
device: opened successfully
user: MBR read successfully
kernel: MBR read successfully
user & kernel MBR OK
KProcCheck Version 0.2-beta1 Proof-of-Concept by SIG^2 (www.security.org.sg)
Process list by traversal of KiWaitListHead
4 - System
224 - pando.exe
316 - explorer.exe
344 - spoolsv.exe
440 - wlcomm.exe
448 - sched.exe
512 - avguard.exe
636 - MsPMSPSv.exe
644 - SynTPEnh.exe
656 - QPService.exe
672 - eabservr.exe
712 - HP Wireless Ass
764 - avgnt.exe
784 - wcescomm.exe
812 - ctfmon.exe
856 - GoogleToolbarNo
872 - jqs.exe
884 - csrss.exe
912 - winlogon.exe
960 - services.exe
972 - lsass.exe
1136 - ati2evxx.exe
1152 - svchost.exe
1164 - LSSrvc.exe
1236 - svchost.exe
1380 - svchost.exe
1440 - svchost.exe
1560 - ati2evxx.exe
1584 - hpqwmiex.exe
1620 - svchost.exe
1852 - rapimgr.exe
1880 - svchost.exe
2220 - wmiprvse.exe
2596 - alg.exe
2644 - msnmsgr.exe
2964 - iexplore.exe
3080 - cmd.exe
3304 - HpqToaster.exe
3904 - wscntfy.exe
Total number of processes = 39
NOTE: Under WinXP, this will not show all processes.
KProcCheck Version 0.2-beta1 Proof-of-Concept by SIG^2 (www.security.org.sg)
Driver/Module list by traversal of PsLoadedModuleList
804D7000 - \WINDOWS\system32\ntkrnlpa.exe
806D0000 - \WINDOWS\system32\hal.dll
F7A92000 - \WINDOWS\system32\KDCOM.DLL
F79A2000 - \WINDOWS\system32\BOOTVID.dll
F73C1000 - sptd.sys
F7A94000 - \WINDOWS\System32\Drivers\WMILIB.SYS
F73A9000 - \WINDOWS\System32\Drivers\SPTD2253.SYS
F737A000 - ACPI.sys
F7369000 - pci.sys
F7592000 - isapnp.sys
F75A2000 - ohci1394.sys
F75B2000 - \WINDOWS\system32\DRIVERS\1394BUS.SYS
F79A6000 - compbatt.sys
F79AA000 - \WINDOWS\system32\DRIVERS\BATTC.SYS
F7B5A000 - pciide.sys
F7812000 - \WINDOWS\system32\DRIVERS\PCIIDEX.SYS
F7A96000 - intelide.sys
F7A98000 - viaide.sys
F7A9A000 - aliide.sys
F734B000 - pcmcia.sys
F75C2000 - MountMgr.sys
F732C000 - ftdisk.sys
F79AE000 - ACPIEC.sys
F7B5B000 - \WINDOWS\system32\DRIVERS\OPRGHDLR.SYS
F781A000 - PartMgr.sys
F75D2000 - VolSnap.sys
F7314000 - atapi.sys
F75E2000 - disk.sys
F75F2000 - \WINDOWS\system32\DRIVERS\CLASSPNP.SYS
F72F4000 - fltmgr.sys
F72E2000 - sr.sys
F7822000 - PxHelp20.sys
F72CB000 - KSecDD.sys
F723E000 - Ntfs.sys
F7211000 - NDIS.sys
F7200000 - serial.sys
F71E6000 - Mup.sys
F7169000 - \SystemRoot\system32\DRIVERS\tunmp.sys
F7692000 - \SystemRoot\system32\DRIVERS\AmdK8.sys
F7165000 - \SystemRoot\system32\DRIVERS\wmiacpi.sys
F6A98000 - \SystemRoot\system32\DRIVERS\ati2mtag.sys
F6A84000 - \SystemRoot\system32\DRIVERS\VIDEOPRT.SYS
F7942000 - \SystemRoot\system32\DRIVERS\usbohci.sys
F6A60000 - \SystemRoot\system32\DRIVERS\USBPORT.SYS
F794A000 - \SystemRoot\system32\DRIVERS\usbehci.sys
F76A2000 - \SystemRoot\system32\DRIVERS\imapi.sys
F76B2000 - \SystemRoot\system32\DRIVERS\cdrom.sys
F76C2000 - \SystemRoot\system32\DRIVERS\redbook.sys
F6A3D000 - \SystemRoot\system32\DRIVERS\ks.sys
F76D2000 - \SystemRoot\system32\DRIVERS\i8042prt.sys
F7952000 - \SystemRoot\system32\DRIVERS\kbdclass.sys
F69D1000 - \SystemRoot\system32\DRIVERS\SynTP.sys
F7AE0000 - \SystemRoot\system32\DRIVERS\USBD.SYS
F795A000 - \SystemRoot\system32\DRIVERS\mouclass.sys
F7067000 - \SystemRoot\system32\DRIVERS\CmBatt.sys
F697B000 - \SystemRoot\system32\drivers\camc6hal.sys
F76E2000 - \SystemRoot\system32\drivers\camc6aud.sys
F6957000 - \SystemRoot\system32\drivers\portcls.sys
F76F2000 - \SystemRoot\system32\drivers\drmk.sys
F691E000 - \SystemRoot\system32\DRIVERS\HSFHWATI.sys
F6821000 - \SystemRoot\system32\DRIVERS\HSF_DP.sys
F6771000 - \SystemRoot\system32\DRIVERS\HSF_CNXT.sys
F7962000 - \SystemRoot\System32\Drivers\Modem.SYS
F6727000 - \SystemRoot\System32\Drivers\dtscsi.sys
F670F000 - \SystemRoot\System32\Drivers\SCSIPORT.SYS
F7BE9000 - \SystemRoot\system32\DRIVERS\audstub.sys
F7742000 - \SystemRoot\system32\DRIVERS\rasl2tp.sys
F7057000 - \SystemRoot\system32\DRIVERS\ndistapi.sys
F66F8000 - \SystemRoot\system32\DRIVERS\ndiswan.sys
F7752000 - \SystemRoot\system32\DRIVERS\raspppoe.sys
F7762000 - \SystemRoot\system32\DRIVERS\raspptp.sys
F797A000 - \SystemRoot\system32\DRIVERS\TDI.SYS
F66E7000 - \SystemRoot\system32\DRIVERS\psched.sys
F7772000 - \SystemRoot\system32\DRIVERS\msgpc.sys
F7982000 - \SystemRoot\system32\DRIVERS\ptilink.sys
F798A000 - \SystemRoot\system32\DRIVERS\raspti.sys
F7992000 - \SystemRoot\system32\DRIVERS\hamachi.sys
F7782000 - \SystemRoot\system32\DRIVERS\termdd.sys
F7AF8000 - \SystemRoot\system32\DRIVERS\swenum.sys
F6689000 - \SystemRoot\system32\DRIVERS\update.sys
F704F000 - \SystemRoot\system32\DRIVERS\mssmbios.sys
F7792000 - \SystemRoot\System32\Drivers\NDProxy.SYS
F77C2000 - \SystemRoot\system32\DRIVERS\usbhub.sys
F7B30000 - \SystemRoot\System32\Drivers\Fs_Rec.SYS
F7B72000 - \SystemRoot\System32\Drivers\Null.SYS
F7B32000 - \SystemRoot\System32\Drivers\Beep.SYS
F7872000 - \SystemRoot\system32\DRIVERS\HIDPARSE.SYS
F787A000 - \SystemRoot\System32\drivers\vga.sys
F7B34000 - \SystemRoot\System32\Drivers\mnmdd.SYS
F7B36000 - \SystemRoot\System32\DRIVERS\RDPCDD.sys
F7882000 - \SystemRoot\System32\Drivers\Msfs.SYS
F788A000 - \SystemRoot\System32\Drivers\Npfs.SYS
F7181000 - \SystemRoot\system32\DRIVERS\rasacd.sys
EE60E000 - \SystemRoot\system32\DRIVERS\ipsec.sys
EE5B5000 - \SystemRoot\system32\DRIVERS\tcpip.sys
EE57D000 - \SystemRoot\system32\DRIVERS\tcpip6.sys
EE555000 - \SystemRoot\system32\DRIVERS\netbt.sys
EE533000 - \SystemRoot\System32\drivers\afd.sys
F77E2000 - \SystemRoot\system32\DRIVERS\netbios.sys
F7892000 - \SystemRoot\system32\DRIVERS\ssmdrv.sys
EE508000 - \SystemRoot\system32\DRIVERS\rdbss.sys
EE498000 - \SystemRoot\system32\DRIVERS\mrxsmb.sys
F7802000 - \SystemRoot\System32\Drivers\Fips.SYS
EE472000 - \SystemRoot\system32\DRIVERS\ipnat.sys
F6CD2000 - \SystemRoot\system32\drivers\ip6fw.sys
F6CC2000 - \SystemRoot\system32\DRIVERS\wanarp.sys
F7B38000 - \??\C:\WINDOWS\system32\drivers\EABFiltr.sys
EE42E000 - \SystemRoot\system32\DRIVERS\avipbb.sys
F7B3E000 - \??\C:\Program Files\Avira\AntiVir Desktop\avgio.sys
EE40A000 - \SystemRoot\System32\Drivers\Fastfat.SYS
EE3AD000 - \SystemRoot\system32\DRIVERS\WlanUIG.sys
EE395000 - \SystemRoot\System32\Drivers\dump_atapi.sys
F7B52000 - \SystemRoot\System32\Drivers\dump_WMILIB.SYS
BF800000 - \SystemRoot\System32\win32k.sys
F7A82000 - \SystemRoot\System32\drivers\Dxapi.sys
F789A000 - \SystemRoot\System32\watchdog.sys
BF9C3000 - \SystemRoot\System32\drivers\dxg.sys
F7BDC000 - \SystemRoot\System32\drivers\dxgthk.sys
BF9D5000 - \SystemRoot\System32\ati2dvag.dll
BFA18000 - \SystemRoot\System32\ati2cqag.dll
BFA5E000 - \SystemRoot\System32\atikvmag.dll
BFAA2000 - \SystemRoot\System32\ati3duag.dll
BFCE6000 - \SystemRoot\System32\ativvaxx.dll
EC141000 - \SystemRoot\system32\DRIVERS\avgntflt.sys
EC13D000 - \SystemRoot\system32\DRIVERS\mdc8021x.sys
EC013000 - \SystemRoot\system32\DRIVERS\nwlnkipx.sys
EE1DD000 - \SystemRoot\system32\DRIVERS\nwlnknb.sys
EC139000 - \SystemRoot\system32\DRIVERS\ndisuio.sys
EBCEE000 - \SystemRoot\system32\DRIVERS\mrxdav.sys
EBE73000 - \SystemRoot\system32\DRIVERS\nwlnkspx.sys
EBC11000 - \SystemRoot\system32\drivers\wdmaud.sys
EBDB3000 - \SystemRoot\system32\drivers\sysaudio.sys
EBB2B000 - \SystemRoot\System32\Drivers\Cdfs.SYS
EBDEB000 - \SystemRoot\System32\Drivers\Aspi32.SYS
EB8D0000 - \SystemRoot\system32\DRIVERS\atksgt.sys
EB7B6000 - \SystemRoot\system32\DRIVERS\srv.sys
F7852000 - \SystemRoot\system32\DRIVERS\lirsgt.sys
EBE0F000 - \SystemRoot\system32\DRIVERS\mdmxsdk.sys
EC079000 - \SystemRoot\system32\DRIVERS\secdrv.sys
EB4A5000 - \SystemRoot\System32\Drivers\HTTP.sys
EC00B000 - \SystemRoot\system32\DRIVERS\hidusb.sys
BA7BB000 - \SystemRoot\system32\DRIVERS\HIDCLASS.SYS
BAA65000 - \SystemRoot\system32\DRIVERS\mouhid.sys
BA67A000 - \SystemRoot\system32\drivers\kmixer.sys
F7AE4000 - \??\C:\DOCUME~1\ALBERT~1\LOCALS~1\Temp\mbr.sys
F7BE5000 - \SystemRoot\System32\DRIVERS\KProcCheck.sys
Total number of drivers = 146
Liste des programmes installes
Ad-aware 6 Professional
Adobe Flash Player 10 ActiveX
Adobe Reader 7.1.0 - Français
Adobe SVG Viewer 3.0
Advanced PDF Password Recovery Pro
AGPGen 1.00
AMSN-Pack (remove only)
aMSN 0.97.2
Amélioration de nos services
Amélioration de nos services
Archiveur WinRAR
Assistant de connexion Windows Live
Athlon 64 Processor Driver
ATI - Software Uninstall Utility
ATI Catalyst Control Center
ATI Display Driver
AudioConvert
Avira AntiVir Personal - Free Antivirus
BaseDVDivX 2.5.7.2
BitTorrent 4.0.2
BSPlayer
BufferChm
CamfrogWEB Advanced ActiveX Plugin (remove only)
CamfrogWEB Advanced ActiveX Plugin (www.bobtv.fr)
CCleaner (remove only)
CDex extraction audio
Choice Guard
Conexant AC-Link Audio
Connexion Facile à Internet
Connexion Facile à Internet
Cool Edit Pro 2.1
Correctif pour Windows XP (KB952287)
Counter-Strike: Source v17
CP_AtenaShokunin1Config
CP_CalendarTemplates1
cp_LightScribeConfig
cp_OnlineProjectsConfig
CP_Package_Basic1
CP_Package_Variety1
CP_Package_Variety2
CP_Package_Variety3
CP_Panorama1Config
cp_PosterPrintConfig
cp_UpdateProjectsConfig
CueTour
Destinations
DeviceManagementQFolder
Direct Show Ogg Vorbis Filter (remove only)
Désinstaller Raveille
DVD Decrypter (Remove Only)
EditPlus 3
eMule
EVEREST Home Edition v2.20
Excel Key
FullDPAppQFolder
Google Earth
Google Toolbar for Internet Explorer
Google Toolbar for Internet Explorer
GrabIt 1.7.2 Beta 3 (build 996)
Grand Theft Auto Vice City
GSpot Codec Information Appliance
GTK+ 1.3.0-20030216 runtime environment
GTK+ 2.4.14 runtime environment
Haali Media Splitter
Hamachi 1.0.3.0
Heroes of Might and Magic® IV The Gathering Storm
HijackThis 2.0.2
Hotfix for Windows XP (KB915865)
hp deskjet 3600
HP DVD Play 2.0
HP Help and Support
HP Imaging Device Functions 6.0
HP Photosmart Premier Software 6.0
HP Product Detection
HP Software Update
HP User Guides--System Recovery
HP User Guides 0025
HP Wireless Assistant 2.00 C1
HpSdpAppCoreApp
ICatch (VI) PC Camera
Installation Windows Live
Installation Windows Live
InstantShareDevices
J2SE Runtime Environment 5.0 Update 10
J2SE Runtime Environment 5.0 Update 11
J2SE Runtime Environment 5.0 Update 6
J2SE Runtime Environment 5.0 Update 9
Java(TM) 6 Update 11
Java(TM) 6 Update 2
Java(TM) 6 Update 3
Java(TM) 6 Update 5
Java(TM) 6 Update 7
Java(TM) SE Runtime Environment 6 Update 1
K-Lite Codec Pack 2.35 Full
Kaspersky On-line Scanner
Kaspersky Online Scanner
Language Pack for Ad-aware 6
Le Franglophile-Windows
Lecteur Windows Media 11
LightScribe 1.4.56.1
Malwarebytes' Anti-Malware
Manuel de l'appareil Windows Mobile®
Matroska Pack
Microsoft .NET Framework 1.1
Microsoft .NET Framework 1.1
Microsoft .NET Framework 1.1 French Language Pack
Microsoft .NET Framework 1.1 Hotfix (KB928366)
Microsoft .NET Framework 2.0 Service Pack 1
Microsoft ActiveSync
Microsoft Application Error Reporting
Microsoft Internationalized Domain Names Mitigation APIs
Microsoft National Language Support Downlevel APIs
Microsoft Office Professional Edition 2003
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17
Mise à jour critique pour Lecteur Windows Media 11 (KB959772)
Mise à jour de sécurité pour Lecteur Windows Media (KB911564)
Mise à jour de sécurité pour Lecteur Windows Media 10 (KB917734)
Mise à jour de sécurité pour Windows Internet Explorer 7 (KB938127-v2)
Mise à jour de sécurité pour Windows Internet Explorer 7 (KB938127)
Mise à jour de sécurité pour Windows Internet Explorer 7 (KB944533)
Mise à jour de sécurité pour Windows Internet Explorer 7 (KB950759)
Mise à jour de sécurité pour Windows Internet Explorer 7 (KB958215)
Mise à jour de sécurité pour Windows Internet Explorer 7 (KB961260)
Mise à jour de sécurité pour Windows Internet Explorer 7 (KB963027)
Mise à jour de sécurité pour Windows XP (KB923561)
Mise à jour de sécurité pour Windows XP (KB938464-v2)
Mise à jour de sécurité pour Windows XP (KB938464)
Mise à jour de sécurité pour Windows XP (KB946648)
Mise à jour de sécurité pour Windows XP (KB950762)
Mise à jour de sécurité pour Windows XP (KB950974)
Mise à jour de sécurité pour Windows XP (KB951066)
Mise à jour de sécurité pour Windows XP (KB951376-v2)
Mise à jour de sécurité pour Windows XP (KB951376)
Mise à jour de sécurité pour Windows XP (KB951698)
Mise à jour de sécurité pour Windows XP (KB951748)
Mise à jour de sécurité pour Windows XP (KB952004)
Mise à jour de sécurité pour Windows XP (KB952954)
Mise à jour de sécurité pour Windows XP (KB954211)
Mise à jour de sécurité pour Windows XP (KB956572)
Mise à jour de sécurité pour Windows XP (KB956803)
Mise à jour de sécurité pour Windows XP (KB956841)
Mise à jour de sécurité pour Windows XP (KB957095)
Mise à jour de sécurité pour Windows XP (KB958687)
Mise à jour de sécurité pour Windows XP (KB958690)
Mise à jour de sécurité pour Windows XP (KB959426)
Mise à jour de sécurité pour Windows XP (KB960225)
Mise à jour de sécurité pour Windows XP (KB960715)
Mise à jour de sécurité pour Windows XP (KB960803)
Mise à jour de sécurité pour Windows XP (KB961373)
Mise à jour pour Windows XP (KB951978)
Mise à jour pour Windows XP (KB961503)
Mise à jour pour Windows XP (KB967715)
MSVCRT
MSXML 4.0 SP2 (KB927978)
MSXML 4.0 SP2 (KB936181)
MSXML 4.0 SP2 (KB954430)
Nero 6 Ultra Edition
OpenAL
OptionalContentQFolder
Outil de mise à jour Google
Outil de téléchargement Windows Live
overland
Pando
Panneau de contrôle ATI
PhotoGallery
PowerDVD
Praetorians
Quick Launch Buttons 5.20 F2
RandMap
Real Alternative 1.48
Ripp-It Codec Pack v 4.2.0
Security Update for CAPICOM (KB931906)
Security Update for CAPICOM (KB931906)
Segoe UI
SkinsHP1
Skype™ 3.8
Sleepy
Soft Data Fax Modem with SmartCP
Sonic Audio Module
Sonic Copy Module
Sonic Data Module
Sonic Express Labeler
Sonic MyDVD Plus
Sonic Update Manager
Sonic_PrimoSDK
SopCast 3.0.3
Steam
Synaptics Pointing Device Driver
Tute Subastado
Unload
Utilitaire réseau pour SAGEM Wi-Fi 11g USB adapter
Vimicro USB PC Camera (ZC0301PL)
VLC media player 0.9.8a
WebFldrs XP
Windows Genuine Advantage Notifications (KB905474)
Windows Internet Explorer 7
Windows Live Call
Windows Live Communications Platform
Windows Live Messenger
Windows Live OneCare safety scanner
Windows Media Format 11 runtime
Windows Media Format 11 runtime
Windows Media Player 11
WinPcap 3.1
x264 Revision 387 x264.nl (remove only)
XnView 1.94.2
Le volume dans le lecteur C n'a pas de nom.
Le numéro de série du volume est 33C5-1859
Répertoire de C:\Program Files
2009-05-08 13:20 <REP> .
2009-05-08 13:20 <REP> ..
2006-09-03 15:43 <REP> 3DO
2008-04-27 15:17 <REP> Adobe
2006-08-27 20:15 <REP> Ahead
2009-05-05 20:27 <REP> AirGobbler Packet Generator
2006-02-20 06:26 <REP> AMD
2006-09-22 16:02 <REP> AMSN
2008-02-22 22:56 <REP> APDFPRP
2007-09-11 22:59 <REP> Arctic Quest
2006-08-28 21:48 <REP> ATI Technologies
2007-07-28 02:14 <REP> Attack on Pearl Harbor
2008-05-17 14:42 <REP> AudioConvert
2007-11-17 12:45 <REP> AvantGo
2009-01-03 15:55 <REP> AvantGo Client
2009-05-03 02:41 <REP> Avira
2007-11-17 12:45 <REP> AviSynth 2.5
2006-09-07 19:25 <REP> BaseDVDivX
2006-07-26 22:15 <REP> BeWAN ADSL V1.9.0.10
2008-09-12 09:15 <REP> BitComet
2006-12-21 13:14 <REP> BitTorrent
2007-07-12 20:40 <REP> CasinoOnNet
2009-01-14 23:53 <REP> CCleaner
2007-11-17 17:08 <REP> CDex_150
2007-11-17 12:51 <REP> Cerience
2006-09-23 20:51 <REP> CFWebAdvancedU
2009-03-19 02:01 <REP> CFWebAdvancedU_BOBTV.FR
2006-09-19 21:00 <REP> Common Files
2006-02-20 15:03 <REP> ComPlus Applications
2006-10-03 00:05 <REP> CONEXANT
2007-11-17 16:00 <REP> coolpro2
2008-09-18 22:11 <REP> Counter-Strike Source
2007-01-04 17:28 <REP> CyberLink
2007-05-09 02:26 <REP> DAEMON Tools
2007-03-21 18:24 <REP> Dial-Messenger
2007-02-12 07:10 <REP> DVD Decrypter
2008-05-27 21:04 <REP> EditPlus 3
2007-07-18 11:37 <REP> Eidos Interactive
2006-08-28 22:01 <REP> Emjysoft
2009-03-21 04:46 <REP> eMule
2008-03-12 19:22 <REP> ESET
2009-01-03 15:52 <REP> eToro
2007-03-10 20:16 <REP> ewido anti-spyware 4.0
2009-05-08 02:04 <REP> Fichiers communs
2007-09-11 23:00 <REP> GameHouse
2007-09-16 14:48 <REP> GameShadow
2008-09-10 18:50 <REP> GameSpy Arcade
2006-10-18 01:09 <REP> Glory of the Roman Empire
2009-03-19 23:34 <REP> Google
2009-03-14 15:30 <REP> GrabIt
2007-03-10 20:09 <REP> Grisoft
2006-08-01 02:12 <REP> GSpot
2007-05-05 16:12 <REP> Hamachi
2007-09-17 19:33 <REP> Hewlett-Packard
2007-09-17 19:33 <REP> HP
2006-07-25 19:46 <REP> HPQ
2007-11-17 15:15 <REP> iMesh
2009-05-03 02:26 <REP> Internet Explorer
2008-12-16 21:57 <REP> Java
2006-07-29 16:32 <REP> K-Lite Codec Pack
2006-08-28 19:31 <REP> Lavalys
2006-11-14 03:32 <REP> Lavasoft
2006-07-29 16:13 <REP> le franglophile
2006-09-27 15:00 <REP> lecteur windows media 11
2007-07-17 15:53 <REP> L'Entraîneur 2007
2006-09-20 18:36 <REP> Macromedia
2009-05-08 13:21 <REP> Malwarebytes' Anti-Malware
2009-01-03 15:50 <REP> MAME32k
2006-09-03 04:54 <REP> Matroska Pack
2006-09-03 05:00 <REP> Media Player Classic
2008-10-22 00:20 <REP> Messenger
2009-03-15 17:25 <REP> Microsoft
2009-01-18 13:16 <REP> Microsoft ActiveSync
2008-04-11 00:08 <REP> Microsoft CAPICOM 2.1.0.2
2006-02-20 15:03 <REP> microsoft frontpage
2009-01-17 13:41 <REP> Microsoft Office
2009-01-17 13:39 <REP> Microsoft.NET
2008-10-22 00:15 <REP> Movie Maker
2008-10-22 00:15 <REP> msn
2006-02-20 15:03 <REP> MSN Gaming Zone
2008-04-10 00:30 <REP> MSN Messenger
2006-11-17 13:27 <REP> MSXML 4.0
2008-01-12 22:20 <REP> MyFreeTV
2008-10-22 00:11 <REP> NetMeeting
2008-03-08 13:52 <REP> ObjectRescue Pro
2006-02-20 15:03 <REP> Online Services
2009-03-24 22:20 <REP> OpenAL
2008-10-22 00:11 <REP> Outlook Express
2007-12-20 11:29 <REP> Overland
2009-01-03 15:50 <REP> palmOne
2008-06-07 11:10 <REP> Pando Networks
2009-03-19 01:51 <REP> Passware
2007-03-04 00:45 <REP> PPLive
2009-01-03 15:54 <REP> PSX-STATION
2007-03-19 02:31 <REP> Raveille
2006-09-04 16:59 <REP> Real Alternative
2007-09-11 22:50 <REP> ReflexiveArcade
2006-09-03 04:52 <REP> Ripp-It Codec Pack
2006-07-29 20:54 <REP> Rockstar Games
2006-02-20 06:47 <REP> Services en ligne
2008-11-07 16:16 <REP> Skype
2009-03-23 03:35 <REP> Sleepy
2006-12-18 17:27 <REP> SlySoft
2006-02-20 06:35 <REP> Sonic
2009-04-26 20:03 <REP> SopCast
2006-10-18 01:11 <REP> Sports Interactive
2008-01-20 03:04 <REP> Spybot - Search & Destroy
2008-10-11 21:12 <REP> Steam
2007-10-19 18:44 <REP> Sword of The New World
2006-02-20 06:37 <REP> Synaptics
2008-05-17 15:11 <REP> TechSmith
2009-05-07 20:43 <REP> Trend Micro
2009-05-03 01:16 <REP> TuneUp Utilities 2009
2008-01-26 00:45 <REP> Tute Subastado
2007-03-04 00:44 <REP> TVAnts
2009-02-04 14:16 <REP> Utilitaire réseau pour SAGEM Wi-Fi 11g USB adapter
2008-09-11 15:20 <REP> uTorrent
2008-05-17 14:56 <REP> VideoCap
2009-03-12 20:51 <REP> VideoLAN
2008-05-12 21:05 <REP> Vimicro
2007-11-17 18:50 <REP> VPHoldem
2007-05-04 00:12 <REP> Warcraft 3 Frozen Throne
2006-07-29 16:29 <REP> Webteh
2009-03-15 17:24 <REP> Windows Live
2009-05-08 01:39 <REP> Windows Live Safety Center
2009-03-15 17:25 <REP> Windows Live SkyDrive
2006-12-24 17:26 <REP> Windows Media Connect 2
2008-10-22 00:11 <REP> Windows Media Player
2009-01-03 16:29 <REP> Windows Mobile Device Handbook
2008-10-22 00:11 <REP> Windows NT
2007-08-23 22:35 <REP> WinPcap
2006-07-25 22:29 <REP> WinRAR
2006-09-03 04:53 <REP> x264
2006-02-20 15:03 <REP> xerox
2008-09-16 21:09 <REP> XnView
2009-01-14 23:56 <REP> Yahoo!
0 fichier(s) 0 octets
136 Rép(s) 4,561,887,232 octets libres
Le volume dans le lecteur C n'a pas de nom.
Le numéro de série du volume est 33C5-1859
Répertoire de C:\Program Files\fichiers communs
2009-05-08 02:04 <REP> .
2009-05-08 02:04 <REP> ..
2008-08-02 22:36 <REP> 3DO Shared
2008-05-17 15:16 <REP> Adobe
2006-08-27 20:14 <REP> Ahead
2007-11-17 12:47 <REP> DataViz
2009-01-17 13:41 <REP> DESIGNER
2007-08-23 22:42 <REP> GTK
2006-02-20 06:26 <REP> HP
2006-02-20 06:36 <REP> InstallShield
2006-02-20 06:17 <REP> Java
2006-02-20 06:50 <REP> LightScribe
2009-05-03 02:38 <REP> Microsoft Shared
2006-02-20 15:03 <REP> MSSoap
2006-02-20 15:03 <REP> ODBC
2008-02-12 00:29 <REP> Real
2006-02-20 15:03 <REP> Services
2008-11-07 16:16 <REP> Skype
2006-02-20 06:35 <REP> Sonic Shared
2006-02-20 15:03 <REP> SpeechEngines
2006-02-20 06:35 <REP> SureThing Shared
2006-07-25 21:38 <REP> Symantec Shared
2007-03-04 00:45 <REP> Synacast
2009-01-17 13:40 <REP> System
2006-02-20 06:36 <REP> TiVo Shared
2009-03-15 17:21 <REP> Windows Live
2008-07-26 15:04 <REP> Wise Installation Wizard
0 fichier(s) 0 octets
27 Rép(s) 4,561,891,328 octets libres
Le volume dans le lecteur C n'a pas de nom.
Le numéro de série du volume est 33C5-1859
Répertoire de C:\Program Files\fichiers communs\Microsoft Shared\Web Folders
2009-01-18 13:14 <REP> .
2009-01-18 13:14 <REP> ..
2006-07-25 22:33 <REP> 1033
2009-01-18 13:15 <REP> 1036
2005-09-20 12:33 1,293,008 MSONSEXT.DLL
2007-03-22 20:29 39,256 MSOSV.DLL
1999-06-03 07:09 122,937 MSOWS409.DLL
2001-03-07 02:00 127,033 MSOWS40c.DLL
2003-07-11 02:25 80,448 PKMWS.DLL
5 fichier(s) 1,662,682 octets
4 Rép(s) 4,561,887,232 octets libres
Le volume dans le lecteur C n'a pas de nom.
Le numéro de série du volume est 33C5-1859
Répertoire de C:\Program Files\common files
2006-09-19 21:00 <REP> .
2006-09-19 21:00 <REP> ..
2006-09-19 21:01 <REP> Motive
0 fichier(s) 0 octets
3 Rép(s) 4,561,887,232 octets libres
Attention : C:\autorun.inf existe
Le volume dans le lecteur C n'a pas de nom.
Le numéro de série du volume est 33C5-1859
Répertoire de C:\
c:\Documents and Settings\Alberto DELGADO\Application Data\Adobe\Acrobat\7.0\Updater\AdbeRdr709_fr_FR.exe
c:\Documents and Settings\Alberto DELGADO\Application Data\Adobe\Acrobat\7.0\Updater\AdbeRdr710_fr_FR.exe
c:\Documents and Settings\Alberto DELGADO\Application Data\Microsoft\Installer\{CAE7D1D9-3794-4169-B4DD-964ADBC534EE}\ARPPRODUCTICON.exe
c:\Documents and Settings\Alberto DELGADO\Application Data\Microsoft\Installer\{E434580A-2D4A-4433-A81E-4BCAE86AD148}\NewShortcut1.4DA64122_6F1D_4317_BC6A_2B3299881D1B.exe
c:\Documents and Settings\Alberto DELGADO\Application Data\Microsoft\Installer\{E434580A-2D4A-4433-A81E-4BCAE86AD148}\NewShortcut2.4DA64122_6F1D_4317_BC6A_2B3299881D1B.exe
c:\Documents and Settings\Alberto DELGADO\Application Data\Microsoft\Installer\{E434580A-2D4A-4433-A81E-4BCAE86AD148}\NewShortcut3.4DA64122_6F1D_4317_BC6A_2B3299881D1B.exe
c:\Documents and Settings\Alberto DELGADO\Application Data\Microsoft\Installer\{E434580A-2D4A-4433-A81E-4BCAE86AD148}\NewShortcut4.4DA64122_6F1D_4317_BC6A_2B3299881D1B.exe
c:\Documents and Settings\Alberto DELGADO\Application Data\Microsoft\Installer\{E434580A-2D4A-4433-A81E-4BCAE86AD148}\NewShortcut6.4DA64122_6F1D_4317_BC6A_2B3299881D1B.exe
c:\Documents and Settings\Alberto DELGADO\Application Data\Microsoft\Installer\{FF24F097-D090-41D2-8E9C-BAFEBBFD938C}\NewShortcut1.4DA64122_6F1D_4317_BC6A_2B3299881D1B.exe
c:\Documents and Settings\Alberto DELGADO\Application Data\Microsoft\Installer\{FF24F097-D090-41D2-8E9C-BAFEBBFD938C}\NewShortcut2.4DA64122_6F1D_4317_BC6A_2B3299881D1B.exe
c:\Documents and Settings\Alberto DELGADO\Application Data\Microsoft\Installer\{FF24F097-D090-41D2-8E9C-BAFEBBFD938C}\NewShortcut3.4DA64122_6F1D_4317_BC6A_2B3299881D1B.exe
c:\Documents and Settings\Alberto DELGADO\Application Data\Microsoft\Installer\{FF24F097-D090-41D2-8E9C-BAFEBBFD938C}\NewShortcut4.4DA64122_6F1D_4317_BC6A_2B3299881D1B.exe
c:\Documents and Settings\Alberto DELGADO\Application Data\Microsoft\Installer\{FF24F097-D090-41D2-8E9C-BAFEBBFD938C}\NewShortcut6.4DA64122_6F1D_4317_BC6A_2B3299881D1B.exe
c:\Documents and Settings\Alberto DELGADO\Bureau\Xtremsplit.exe
c:\Documents and Settings\Alberto DELGADO\Bureau\DiagHelp\DiagHelp\catchme.exe
c:\Documents and Settings\Alberto DELGADO\Bureau\DiagHelp\DiagHelp\diff.exe
c:\Documents and Settings\Alberto DELGADO\Bureau\DiagHelp\DiagHelp\dumphive.exe
c:\Documents and Settings\Alberto DELGADO\Bureau\DiagHelp\DiagHelp\FilesInfoCmd.exe
c:\Documents and Settings\Alberto DELGADO\Bureau\DiagHelp\DiagHelp\find2.exe
c:\Documents and Settings\Alberto DELGADO\Bureau\DiagHelp\DiagHelp\Fport.exe
c:\Documents and Settings\Alberto DELGADO\Bureau\DiagHelp\DiagHelp\grep.exe
c:\Documents and Settings\Alberto DELGADO\Bureau\DiagHelp\DiagHelp\gzip.exe
c:\Documents and Settings\Alberto DELGADO\Bureau\DiagHelp\DiagHelp\KProcCheck.exe
c:\Documents and Settings\Alberto DELGADO\Bureau\DiagHelp\DiagHelp\LFiles.exe
c:\Documents and Settings\Alberto DELGADO\Bureau\DiagHelp\DiagHelp\LISTDLLS.exe
c:\Documents and Settings\Alberto DELGADO\Bureau\DiagHelp\DiagHelp\mbr.exe
c:\Documents and Settings\Alberto DELGADO\Bureau\DiagHelp\DiagHelp\md5sums.exe
c:\Documents and Settings\Alberto DELGADO\Bureau\DiagHelp\DiagHelp\Psinfo.exe
c:\Documents and Settings\Alberto DELGADO\Bureau\DiagHelp\DiagHelp\pslist.exe
c:\Documents and Settings\Alberto DELGADO\Bureau\DiagHelp\DiagHelp\sigcheck.exe
c:\Documents and Settings\Alberto DELGADO\Bureau\DiagHelp\DiagHelp\streams.exe
c:\Documents and Settings\Alberto DELGADO\Bureau\DiagHelp\DiagHelp\swreg.exe
c:\Documents and Settings\Alberto DELGADO\Bureau\DiagHelp\DiagHelp\tar.exe
c:\Documents and Settings\Alberto DELGADO\Bureau\GenProc\GenProc\outil\curl.exe
c:\Documents and Settings\Alberto DELGADO\Bureau\GenProc\GenProc\outil\grep.exe
c:\Documents and Settings\Alberto DELGADO\Bureau\GenProc\GenProc\outil\sed.exe
c:\Documents and Settings\Alberto DELGADO\Bureau\GenProc\GenProc\outil\swreg.exe
c:\Documents and Settings\Alberto DELGADO\Bureau\GenProc\GenProc\outil\uniq.exe
c:\Documents and Settings\Alberto DELGADO\Local Settings\Application Data\Microsoft\Messenger\alberto69300@hotmail.com\Sharing Folders\narudel@hotmail.com\RemoveWGA 1.2 [Par Ratiatum.com].exe
c:\Documents and Settings\Alberto DELGADO\Local Settings\Application Data\Pando\Pando Files\Upgrade25156\PandoSetup-2.0.3.1\PandoPushInst.exe
c:\Documents and Settings\Alberto DELGADO\Local Settings\Application Data\Pando\Pando Files\Upgrade25156\PandoSetup-2.0.3.1\PandoSetup.exe
c:\Documents and Settings\Alberto DELGADO\Mes documents\Counter-Strike_Source_All_Versions\Steamengine.exe
c:\Documents and Settings\Alberto DELGADO\Mes documents\le franglophile\franglo.exe
c:\Documents and Settings\Alberto DELGADO\Mes documents\le franglophile\uninstlf.exe
c:\Documents and Settings\Alberto DELGADO\Mes documents\le franglophile\Reg\enreg.exe
c:\Documents and Settings\Alberto DELGADO\Mes documents\le franglophile\Reg\reg.exe
c:\Documents and Settings\Alberto DELGADO\Mes documents\Mises à jour de programme téléchargées\Update Manager\RecordNow Audio (Plus) 2.0.0.1\Audio2001Plus.exe
c:\Documents and Settings\Alberto DELGADO\Application Data\Microsoft\IdentityCRL\ppcrlconfig.dll
c:\Documents and Settings\Alberto DELGADO\Application Data\Microsoft\IdentityCRL\PROD\ppcrlconfig.dll
c:\Documents and Settings\Alberto DELGADO\Application Data\Microsoft\IdentityCRL\production\ppcrlconfig.dll
c:\Documents and Settings\Alberto DELGADO\Application Data\Sun\Java\jre1.6.0_10\lzma.dll
c:\Documents and Settings\Alberto DELGADO\Application Data\Sun\Java\jre1.6.0_11\lzma.dll
c:\Documents and Settings\All Users\Application Data\MGS\cache\3\3cardpoker.8e73a522a397f174eb628d05f72f1f40.dll
c:\Documents and Settings\All Users\Application Data\MGS\cache\a\advancedslots1.0a55799429d83e0cb0c51c4f8800bb5c.dll
c:\Documents and Settings\All Users\Application Data\MGS\cache\a\advancedslots1_temp.8a06ca9368d87091bc18256214f0ffe1.dll
c:\Documents and Settings\All Users\Application Data\MGS\cache\a\advancedslots1xxx.515b62c381b162125cd165ff444a9767.dll
c:\Documents and Settings\All Users\Application Data\MGS\cache\a\advancedslots1xxx_temp.5e88daf7f878d5efd2174cb92d6c65e0.dll
c:\Documents and Settings\All Users\Application Data\MGS\cache\a\atlanticcityblackjack.9baef784fe666fb9d90dc331d0239eed.dll
c:\Documents and Settings\All Users\Application Data\MGS\cache\e\euroroulette.fa2b524975a5d8bbc30203d094e2b084.dll
c:\Documents and Settings\All Users\Application Data\MGS\cache\g\gamble.212eaf21a4805f8521d0d0c57b6a933b.dll
c:\Documents and Settings\All Users\Application Data\MGS\cache\g\gamble2.04f884d96aad7f5c7b941fdd39ed766d.dll
c:\Documents and Settings\All Users\Application Data\MGS\cache\g\gambleplugin.c4d8c6f5542066f894b7f2e575038afb.dll
c:\Documents and Settings\All Users\Application Data\MGS\cache\m\mptadvancedslots.dad3e798b84695090d062c8c8b26aca2.dll
c:\Documents and Settings\All Users\Application Data\MGS\cache\m\mpvslotxxx.276f1f991ac5dec544df1ecad38bbc9a.dll
c:\Documents and Settings\All Users\Application Data\MGS\cache\p\powerpokersuite1_nl.cebfe8812d984716506c6d9d096a5f48.dll
c:\Documents and Settings\All Users\Application Data\MGS\cache\s\simplepickuntilbonus.571a904af34f5f3b18cf4feaec07913f.dll
c:\Documents and Settings\All Users\Application Data\MGS\cache\s\simplepickuntilbonus_temp.b6b7e588aedb05fa062fb8447406bca9.dll
c:\Documents and Settings\All Users\Application Data\MGS\cache\s\simplepickxofybonus.bb69121ba26b8b09500f7448266e3542.dll
c:\Documents and Settings\All Users\Application Data\MGS\cache\s\simplepickxofybonus_temp.ccad7e5a940d5494ce317984dbb504e2.dll
c:\Documents and Settings\All Users\Application Data\MGS\cache\t\type_3reelnormal1_2.6d58a1bcaf1d9165fa0b77fa9598b623.dll
c:\Documents and Settings\All Users\Application Data\MGS\cache\t\type_5reelnormal3_4_5.07db0a5618a0565d7bde7a2766c54711.dll
c:\Documents and Settings\All Users\Application Data\MGS\cache\v\videopokersuite1.03dd648f567bef124a1d270ad208752a.dll
c:\Documents and Settings\All Users\Application Data\MGS\cache\x\xmlparserplugin.57e9fd94cbd592ad475a3ca59462730f.dll
c:\Documents and Settings\All Users\Application Data\MGS\cache\_\_crt_keno.ed975aa9c9bb5e5ec89c8ffeee254e8a.dll
c:\Documents and Settings\All Users\Application Data\Microsoft\IdentityCRL\ppcrlconfig.dll
c:\Documents and Settings\All Users\Application Data\Microsoft\IdentityCRL\production\ppcrlconfig.dll
c:\Documents and Settings\All Users\Application Data\Microsoft\USMT\iconlib.dll
c:\Documents and Settings\LocalService\Application Data\Microsoft\UPnP Device Host\upnphost\udhisapi.dll
****** Fin du rapport DiagHelp
Veuillez svp envoyer le fichier C:\upload_moi_ALBERTO.tar.gz a l'adresse
http://upload.malekal.com
Que dois je faire ensuite stpl?
Merci d'avance
alberto