resalut
il est super lon bonne lecture
DiagHelp version v1.4 -
http://www.malekal.com
excute le 26/03/2008 à 13:11:48,56
Liste des derniers fichies modifies/crees dans windir\system32 et prefetch
C:\WINDOWS\prefetch\CHCP.COM-18156052.pf -->26/03/2008 13:11:47
C:\WINDOWS\prefetch\CCLEANER.EXE-0BCE437C.pf -->26/03/2008 13:11:23
C:\WINDOWS\prefetch\NOTEPAD.EXE-336351A9.pf -->26/03/2008 13:06:38
C:\WINDOWS\prefetch\HIJACKTHIS.EXE-04D01919.pf -->26/03/2008 13:06:38
C:\WINDOWS\prefetch\USNSVC.EXE-373E4DBC.pf -->26/03/2008 12:58:49
C:\WINDOWS\prefetch\IEXPLORE.EXE-27122324.pf -->26/03/2008 12:58:34
C:\WINDOWS\prefetch\AVAST.SETUP-032170A8.pf -->26/03/2008 12:54:59
C:\WINDOWS\prefetch\WUAUCLT.EXE-399A8E72.pf -->26/03/2008 12:52:58
C:\WINDOWS\prefetch\WMIPRVSE.EXE-28F301A9.pf -->26/03/2008 12:52:35
C:\WINDOWS\prefetch\SKYPEPM.EXE-2BC7DD5C.pf -->26/03/2008 12:52:35
C:\WINDOWS\System32\drivers\MS1000.sys -->14/03/2008 14:20:18
C:\WINDOWS\System32\drivers\aswmon.sys -->04/12/2007 15:56:02
C:\WINDOWS\System32\drivers\aswmon2.sys -->04/12/2007 15:55:46
C:\WINDOWS\System32\drivers\aswRdr.sys -->04/12/2007 15:53:39
C:\WINDOWS\System32\drivers\aswTdi.sys -->04/12/2007 15:51:52
C:\WINDOWS\System32\drivers\aavmker4.sys -->04/12/2007 15:49:02
C:\WINDOWS\System32\drivers\NSDriver.sys -->04/06/2007 15:18:48
C:\WINDOWS\System32\nvapps.xml -->26/03/2008 12:51:26
C:\WINDOWS\System32\wpa.dbl -->20/03/2008 17:45:20
C:\WINDOWS\System32\perfh00C.dat -->14/03/2008 16:26:24
C:\WINDOWS\System32\perfh009.dat -->14/03/2008 16:26:24
C:\WINDOWS\System32\perfc00C.dat -->14/03/2008 16:26:24
C:\WINDOWS\System32\perfc009.dat -->14/03/2008 16:26:24
C:\WINDOWS\System32\PerfStringBackup.INI -->14/03/2008 16:26:23
C:\WINDOWS\System32\qtplugin.log -->13/03/2008 00:29:07
C:\WINDOWS\System32\346752093.dat -->13/03/2008 00:11:54
C:\WINDOWS\System32\FNTCACHE.DAT -->29/12/2007 10:47:45
C:\WINDOWS\System32\jupdate-1.6.0_03-b05.log -->15/12/2007 00:10:26
C:\WINDOWS\System32\CmdLineExt.dll -->10/12/2007 12:20:34
C:\WINDOWS\System32\CONFIG.NT -->07/12/2007 18:47:23
C:\WINDOWS\System32\$winnt$.inf -->07/12/2007 18:28:28
C:\WINDOWS\System32\wmpscheme.xml -->07/12/2007 18:24:44
C:\WINDOWS\System32\nscompat.tlb -->07/12/2007 18:24:44
C:\WINDOWS\System32\amcompat.tlb -->07/12/2007 18:24:44
C:\WINDOWS\System32\WindowsLogon.manifest -->07/12/2007 18:23:39
C:\WINDOWS\System32\logonui.exe.manifest -->07/12/2007 18:23:39
C:\WINDOWS\System32\wuaucpl.cpl.manifest -->07/12/2007 18:23:32
C:\WINDOWS\System32\sapi.cpl.manifest -->07/12/2007 18:23:32
C:\WINDOWS\System32\nwc.cpl.manifest -->07/12/2007 18:23:32
C:\WINDOWS\System32\ncpa.cpl.manifest -->07/12/2007 18:23:32
C:\WINDOWS\System32\cdplayer.exe.manifest -->07/12/2007 18:23:32
C:\WINDOWS\System32\emptyregdb.dat -->07/12/2007 18:21:47
C:\WINDOWS\wiadebug.log -->26/03/2008 12:51:38
C:\WINDOWS\wiaservc.log -->26/03/2008 12:51:32
C:\WINDOWS\bootstat.dat -->26/03/2008 12:51:07
C:\WINDOWS\SchedLgU.Txt -->26/03/2008 00:24:58
C:\WINDOWS\system.ini -->24/03/2008 10:59:40
C:\WINDOWS\unins000.dat -->13/03/2008 18:09:49
C:\WINDOWS\videodeLuxe.INI -->27/02/2008 16:09:31
C:\WINDOWS\WMSysPr9.prx -->29/12/2007 11:24:34
C:\WINDOWS\magix.ini -->28/12/2007 20:41:11
C:\WINDOWS\IniFile1.ini -->28/12/2007 20:26:25
C:\WINDOWS\avisplitter.INI -->21/12/2007 14:07:29
C:\WINDOWS\pp.enc -->08/12/2007 16:45:03
C:\WINDOWS\REGLOCS.OLD -->07/12/2007 18:29:08
C:\WINDOWS\win.ini -->07/12/2007 18:25:59
C:\WINDOWS\control.ini -->07/12/2007 18:24:46
winlogon.exe
Verified: Signed
svchost.exe
Verified: Signed
ws2_32.dll
Verified: Signed
user32.dll
Verified: Signed
tcpip.sys
Verified: Signed
ndis.sys
Verified: Signed
null.sys
Verified: Signed
ListDLLs v2.25 - DLL lister for Win9x/NT
Copyright (C) 1997-2004 Mark Russinovich
Sysinternals -
www.sysinternals.com
------------------------------------------------------------------------------
explorer.exe pid: 1512
Command line: C:\WINDOWS\Explorer.EXE
Base Size Version Path
0x01000000 0xf9000 6.00.2800.1106 C:\WINDOWS\Explorer.EXE
0x77be0000 0x53000 7.00.2600.1106 C:\WINDOWS\system32\msvcrt.dll
0x77290000 0x64000 6.00.2800.1106 C:\WINDOWS\system32\SHLWAPI.dll
0x77390000 0x805000 6.00.2800.1106 C:\WINDOWS\system32\SHELL32.dll
0x770e0000 0x8b000 3.50.5016.0000 C:\WINDOWS\system32\OLEAUT32.dll
0x75f10000 0xfc000 6.00.2800.1106 C:\WINDOWS\System32\BROWSEUI.dll
0x76960000 0x14a000 6.00.2800.1106 C:\WINDOWS\System32\SHDOCVW.dll
0x5b090000 0x34000 6.00.2800.1106 C:\WINDOWS\System32\UxTheme.dll
0x78090000 0xe4000 6.00.2800.1106 C:\WINDOWS\WinSxS\x86_Microsoft.Windows.Common-Controls_6595b64144ccf1df_6.0.10.0_x-ww_f7fb5805\comctl32.dll
0x77300000 0x8b000 5.82.2800.1106 C:\WINDOWS\system32\comctl32.dll
0x76f80000 0x78000 2001.12.4414.0042 C:\WINDOWS\System32\CLBCATQ.DLL
0x77000000 0xd4000 2001.12.4414.0042 C:\WINDOWS\System32\COMRes.dll
0x5b950000 0x72000 6.00.2800.1106 C:\WINDOWS\System32\themeui.dll
0x76ac0000 0x15000 3.00.9435.0000 C:\WINDOWS\System32\ATL.DLL
0x76080000 0x7a000 6.00.2800.1106 C:\WINDOWS\system32\urlmon.dll
0x01400000 0x201000 2.00.2600.1106 C:\WINDOWS\System32\msi.dll
0x74aa0000 0x43000 6.00.2800.1106 C:\WINDOWS\System32\webcheck.dll
0x74a60000 0x9000 6.00.2600.0000 C:\WINDOWS\System32\BatMeter.dll
0x74a40000 0x7000 6.00.2600.0000 C:\WINDOWS\System32\POWRPROF.dll
0x76be0000 0x2b000 5.131.2600.0000 C:\WINDOWS\System32\WINTRUST.dll
0x76250000 0x8d000 5.131.2600.1106 C:\WINDOWS\system32\CRYPT32.dll
0x76190000 0x99000 6.00.2800.1106 C:\WINDOWS\system32\WININET.dll
0x76100000 0x8e000 6.00.2600.0000 C:\WINDOWS\System32\shdoclc.dll
0x723a0000 0x13000 6.00.2800.1106 C:\WINDOWS\System32\browselc.dll
0x1f7b0000 0x31000 3.520.9030.0000 C:\WINDOWS\System32\ODBC32.dll
0x76340000 0x46000 6.00.2800.1106 C:\WINDOWS\system32\comdlg32.dll
0x1f850000 0x18000 3.520.7713.0000 C:\WINDOWS\System32\odbcint.dll
0x00bc0000 0x2e000 C:\Program Files\WinRAR\rarext.dll
0x00c10000 0x76000 1.00.0008.0046 C:\PROGRA~1\TROJAN~1\Trshlex.dll
0x5f140000 0x1a000 5.00.5014.0000 C:\WINDOWS\System32\olepro32.dll
0x64f00000 0x12000 4.07.1098.0000 C:\Program Files\Alwil Software\Avast4\ashShell.dll
0x10000000 0x8000 1.00.0000.0001 C:\Program Files\Adobe\Acrobat 5.0\Reader\ActiveX\AcroIEHelper.ocx
0x6d7c0000 0x79000 6.00.0030.0005 C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
0x7c340000 0x56000 7.10.3052.0004 C:\Program Files\Java\jre1.6.0_03\bin\MSVCR71.dll
0x62350000 0x53000 2.00.0500.0000 C:\Program Files\OpenOffice.org 2.3\program\shlxthdl.dll
0x60400000 0x18000 2.00.0500.0000 C:\Program Files\OpenOffice.org 2.3\program\uwinapi.dll
0x78190000 0x1a1000 5.01.3101.0000 C:\WINDOWS\WinSxS\x86_Microsoft.Windows.GdiPlus_6595b64144ccf1df_1.0.10.0_x-ww_712befd8\gdiplus.dll
0x61e70000 0x8e000 4.05.2003.0120 C:\Program Files\OpenOffice.org 2.3\program\stlport_vc7145.dll
0x7c3a0000 0x7b000 7.10.3077.0000 C:\Program Files\OpenOffice.org 2.3\program\MSVCP71.dll
0x70ee0000 0x7000 1.01.0000.3917 C:\WINDOWS\System32\asfsipc.dll
0x60990000 0xd000 2.00.2600.0000 C:\WINDOWS\System32\MSISIP.DLL
0x74e10000 0x10000 5.06.0000.6626 C:\WINDOWS\System32\wshext.dll
0x59000000 0xe000 5.06.0000.6626 C:\WINDOWS\System32\wshFR.DLL
ListDLLs v2.25 - DLL lister for Win9x/NT
Copyright (C) 1997-2004 Mark Russinovich
Sysinternals -
www.sysinternals.com
------------------------------------------------------------------------------
winlogon.exe pid: 592
Command line: winlogon.exe
Base Size Version Path
0x01000000 0x84000 \??\C:\WINDOWS\system32\winlogon.exe
0x77be0000 0x53000 7.00.2600.1106 C:\WINDOWS\system32\msvcrt.dll
0x76250000 0x8d000 5.131.2600.1106 C:\WINDOWS\system32\CRYPT32.dll
0x77390000 0x805000 6.00.2800.1106 C:\WINDOWS\system32\SHELL32.dll
0x77290000 0x64000 6.00.2800.1106 C:\WINDOWS\system32\SHLWAPI.dll
0x77300000 0x8b000 5.82.2800.1106 C:\WINDOWS\system32\COMCTL32.dll
0x1f7b0000 0x31000 3.520.9030.0000 C:\WINDOWS\System32\ODBC32.dll
0x76340000 0x46000 6.00.2800.1106 C:\WINDOWS\system32\comdlg32.dll
0x78090000 0xe4000 6.00.2800.1106 C:\WINDOWS\WinSxS\x86_Microsoft.Windows.Common-Controls_6595b64144ccf1df_6.0.10.0_x-ww_f7fb5805\comctl32.dll
0x1f850000 0x18000 3.520.7713.0000 C:\WINDOWS\System32\odbcint.dll
0x76b70000 0x20000 6.00.2800.1106 C:\WINDOWS\System32\SHSVCS.dll
0x76be0000 0x2b000 5.131.2600.0000 C:\WINDOWS\System32\WINTRUST.dll
0x5b090000 0x34000 6.00.2800.1106 C:\WINDOWS\System32\uxtheme.dll
0x77000000 0xd4000 2001.12.4414.0042 C:\WINDOWS\System32\COMRes.dll
0x770e0000 0x8b000 3.50.5016.0000 C:\WINDOWS\system32\OLEAUT32.dll
0x76f80000 0x78000 2001.12.4414.0042 C:\WINDOWS\System32\CLBCATQ.DLL
Le volume dans le lecteur C s'appelle first disk
Le numéro de série du volume est 14AB-045D
Répertoire de C:\WINDOWS\system
17/02/2004 10:51 1 458 176 SmWizard.exe
1 fichier(s) 1 458 176 octets
0 Rép(s) 39 604 367 360 octets libres
Le volume dans le lecteur C s'appelle first disk
Le numéro de série du volume est 14AB-045D
Répertoire de C:\WINDOWS\system32
28/08/2001 15:00 4 096 csrss.exe
1 fichier(s) 4 096 octets
0 Rép(s) 39 604 367 360 octets libres
Contenu de Downloaded Program Files
Le volume dans le lecteur C s'appelle first disk
Le numéro de série du volume est 14AB-045D
Répertoire de C:\WINDOWS\Downloaded Program Files
25/03/2008 20:31 <REP> .
25/03/2008 20:31 <REP> ..
07/12/2007 18:23 65 desktop.ini
14/10/1997 18:52 697 DirectAnimation Java Classes.osd
11/04/2007 14:55 1 292 erma.inf
28/09/2007 04:41 381 960 GAME_UNO1.dll
17/01/2007 15:44 316 GAME_UNO1.INF
08/08/2006 11:45 576 kavwebscan.inf
22/02/2007 23:41 304 544 MessengerStatsPAClient.dll
20/01/2000 15:25 1 162 Microsoft XML Parser for Java.osd
8 fichier(s) 690 612 octets
Total des fichiers listés :
8 fichier(s) 690 612 octets
2 Rép(s) 39 604 367 360 octets libres
Recherche de rootkit! (Merci S!Ri)
Recherche d'infections connues
Export des clefs sensibles..
Liste des fichiers en exception sur le pare-feu XP SP2
Export de la clef SharedTaskScheduler
[SharedTaskScheduler]
"{438755C2-A8BA-11D1-B96B-00A0C90312E1}"="Pré-chargeur Browseui"
"{8C7461EF-2B13-11d2-BE35-3078302C2030}"="Démon de cache des catégories de composant"
exports des policies
REGEDIT4
[system]
"dontdisplaylastusername"=dword:00000000
"legalnoticecaption"=""
"legalnoticetext"=""
"shutdownwithoutlogon"=dword:00000001
"undockwithoutlogon"=dword:00000001
"DisableRegistryTools"=dword:00000000
"HideLegacyLogonScripts"=dword:00000000
"HideLogoffScripts"=dword:00000000
"RunLogonScriptSync"=dword:00000001
"RunStartupScriptSync"=dword:00000001
"HideStartupScripts"=dword:00000000
Export des clefs sensibles..
Rechercher adresses sensibles dans le fichier HOSTS...
127.0.0.1 www.activexupdate.com
127.0.0.1 activexupdate.com
127.0.0.1 www.antispywareupdates.net
127.0.0.1 antispywareupdates.net
127.0.0.1 www.avpcheckupdate.com
127.0.0.1 avpcheckupdate.com
127.0.0.1 client.exeupdate.com
127.0.0.1 www.eupdatepage.com
127.0.0.1 eupdatepage.com
127.0.0.1 www.exeupdate.com
127.0.0.1 exeupdate.com
127.0.0.1 www.hotwinupdates.com
127.0.0.1 hotwinupdates.com
127.0.0.1 www.lavasoftupdate.com
127.0.0.1 lavasoftupdate.com
127.0.0.1 www.malwarewipeupdate.com
127.0.0.1 malwarewipeupdate.com
127.0.0.1 www.msupdate.net
127.0.0.1 msupdate.net
127.0.0.1 www.msupdater.net
127.0.0.1 msupdater.net
127.0.0.1 www.necessaryupdates.com
127.0.0.1 necessaryupdates.com
127.0.0.1 newupdates.lzio.com
127.0.0.1 redirect.msupdate.net
127.0.0.1 search.keyword.exeupdate.com
127.0.0.1 www.securityupdatesite.com
127.0.0.1 securityupdatesite.com
127.0.0.1 settings.updatemysettings.com
127.0.0.1 www.spyaxeupdate.com
127.0.0.1 spyaxeupdate.com
127.0.0.1 www.spyfalconupdate.com
127.0.0.1 spyfalconupdate.com
127.0.0.1 www.systemupdates.net
127.0.0.1 systemupdates.net
127.0.0.1 trial.updates.winsoftware.com
127.0.0.1 update.680180.net
127.0.0.1 update.shareaza.com
127.0.0.1 www.updatemysettings.com
127.0.0.1 updatemysettings.com
127.0.0.1 updates.spywarequake.com
127.0.0.1 www.urgentsystemupdate.biz
127.0.0.1 urgentsystemupdate.biz
127.0.0.1 www.urgentsystemupdate.com
127.0.0.1 urgentsystemupdate.com
127.0.0.1 windupdates.com
127.0.0.1 www.pandaantivirus-2007.com
127.0.0.1 pandaantivirus-2007.com
127.0.0.1 www.pandadownload-now.com
127.0.0.1 pandadownload-now.com
127.0.0.1 www.panda-hq.com
127.0.0.1 panda-hq.com
catchme 0.3.1319 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.net
Rootkit scan 2008-03-26 13:12:22
Windows 5.1.2600 Service Pack 1 NTFS
scanning hidden services & system hive ...
IPC error: 2 Le fichier spécifié est introuvable.
scanning hidden registry entries ...
scanning hidden files ...
scan completed successfully
hidden services: 0
hidden files: 0
KProcCheck Version 0.2-beta1 Proof-of-Concept by SIG^2 (www.security.org.sg)
Process list by traversal of KiWaitListHead
4 - System
220 - aawservice.exe
256 - IEXPLORE.EXE
356 - alg.exe
408 - nvsvc32.exe
568 - csrss.exe
592 - winlogon.exe
636 - services.exe
648 - lsass.exe
816 - svchost.exe
848 - svchost.exe
892 - svchost.exe
972 - svchost.exe
1040 - svchost.exe
1296 - ashServ.exe
1512 - explorer.exe
1748 - NetgearAG.exe
1756 - McciTrayApp.exe
1772 - ashDisp.exe
1836 - vphc600.exe
1876 - ctfmon.exe
1920 - ashWebSv.exe
1924 - msnmsgr.exe
1952 - ashMaiSv.exe
1956 - msmsgs.exe
2424 - cmd.exe
2516 - wuauclt.exe
2912 - skypePM.exe
3184 - Skype.exe
3232 - soffice.bin
Total number of processes = 30
NOTE: Under WinXP, this will not show all processes.
KProcCheck Version 0.2-beta1 Proof-of-Concept by SIG^2 (www.security.org.sg)
Driver/Module list by traversal of PsLoadedModuleList
804D4000 - \WINDOWS\system32\ntoskrnl.exe
806C8000 - \WINDOWS\system32\hal.dll
F7D2F000 - \WINDOWS\system32\KDCOM.DLL
F7C3F000 - \WINDOWS\system32\BOOTVID.dll
F77E2000 - ACPI.sys
F7D31000 - \WINDOWS\System32\DRIVERS\WMILIB.SYS
F782F000 - pci.sys
F783F000 - isapnp.sys
F7DF7000 - pciide.sys
F7AAF000 - \WINDOWS\System32\DRIVERS\PCIIDEX.SYS
F784F000 - MountMgr.sys
F77C3000 - ftdisk.sys
F7D33000 - dmload.sys
F779F000 - dmio.sys
F7AB7000 - PartMgr.sys
F785F000 - VolSnap.sys
F7789000 - atapi.sys
F786F000 - disk.sys
F787F000 - \WINDOWS\System32\DRIVERS\CLASSPNP.SYS
F7778000 - sr.sys
F7764000 - KSecDD.sys
F76DA000 - Ntfs.sys
F76B1000 - NDIS.sys
F7697000 - Mup.sys
F794F000 - \SystemRoot\System32\DRIVERS\amdk7.sys
F727F000 - \SystemRoot\System32\DRIVERS\nv4_mini.sys
F726D000 - \SystemRoot\System32\DRIVERS\VIDEOPRT.SYS
F795F000 - \SystemRoot\System32\DRIVERS\i8042prt.sys
F7B27000 - \SystemRoot\System32\DRIVERS\mouclass.sys
F7B2F000 - \SystemRoot\System32\DRIVERS\kbdclass.sys
F796F000 - \SystemRoot\System32\DRIVERS\imapi.sys
F797F000 - \SystemRoot\System32\DRIVERS\cdrom.sys
F798F000 - \SystemRoot\System32\DRIVERS\redbook.sys
F724D000 - \SystemRoot\System32\DRIVERS\ks.sys
F70FF000 - \SystemRoot\system32\drivers\cmuda.sys
F70DE000 - \SystemRoot\system32\drivers\portcls.sys
F799F000 - \SystemRoot\system32\drivers\drmk.sys
F7CF7000 - \SystemRoot\System32\DRIVERS\usbohci.sys
F70BC000 - \SystemRoot\System32\DRIVERS\USBPORT.SYS
F7B37000 - \SystemRoot\System32\DRIVERS\usbehci.sys
F7B3F000 - \SystemRoot\System32\DRIVERS\sisnic.sys
F7070000 - \SystemRoot\System32\DRIVERS\wg311nd5.sys
F7B47000 - \SystemRoot\System32\DRIVERS\fdc.sys
F79AF000 - \SystemRoot\System32\DRIVERS\serial.sys
F7CFB000 - \SystemRoot\System32\DRIVERS\serenum.sys
F705D000 - \SystemRoot\System32\DRIVERS\parport.sys
F7CFF000 - \SystemRoot\System32\DRIVERS\gameenum.sys
F7F1C000 - \SystemRoot\System32\DRIVERS\audstub.sys
F79BF000 - \SystemRoot\System32\DRIVERS\rasl2tp.sys
F7D03000 - \SystemRoot\System32\DRIVERS\ndistapi.sys
F7047000 - \SystemRoot\System32\DRIVERS\ndiswan.sys
F79CF000 - \SystemRoot\System32\DRIVERS\raspppoe.sys
F79DF000 - \SystemRoot\System32\DRIVERS\raspptp.sys
F7D07000 - \SystemRoot\System32\DRIVERS\TDI.SYS
F7036000 - \SystemRoot\System32\DRIVERS\psched.sys
F79EF000 - \SystemRoot\System32\DRIVERS\msgpc.sys
F7B4F000 - \SystemRoot\System32\DRIVERS\ptilink.sys
F7B57000 - \SystemRoot\System32\DRIVERS\raspti.sys
F6FE9000 - \SystemRoot\System32\DRIVERS\rdpdr.sys
F79FF000 - \SystemRoot\System32\DRIVERS\termdd.sys
F7F2A000 - \SystemRoot\System32\DRIVERS\swenum.sys
F6F9F000 - \SystemRoot\System32\DRIVERS\update.sys
F7A2F000 - \SystemRoot\System32\Drivers\NDProxy.SYS
F7A3F000 - \SystemRoot\System32\DRIVERS\usbhub.sys
F7D51000 - \SystemRoot\System32\DRIVERS\USBD.SYS
F7B5F000 - \SystemRoot\System32\DRIVERS\flpydisk.sys
F7D53000 - \SystemRoot\System32\Drivers\Fs_Rec.SYS
F7E2F000 - \SystemRoot\System32\Drivers\Null.SYS
F7D55000 - \SystemRoot\System32\Drivers\Beep.SYS
F7B6F000 - \SystemRoot\System32\drivers\vga.sys
F7D57000 - \SystemRoot\System32\Drivers\mnmdd.SYS
F7D59000 - \SystemRoot\System32\DRIVERS\RDPCDD.sys
F7B77000 - \SystemRoot\System32\Drivers\Msfs.SYS
F7B7F000 - \SystemRoot\System32\Drivers\Npfs.SYS
F765B000 - \SystemRoot\System32\DRIVERS\rasacd.sys
F7A6F000 - \SystemRoot\System32\DRIVERS\ipsec.sys
F5D65000 - \SystemRoot\System32\DRIVERS\tcpip.sys
F7A7F000 - \SystemRoot\System32\Drivers\aswTdi.SYS
F5D3E000 - \SystemRoot\System32\DRIVERS\netbt.sys
F7A8F000 - \SystemRoot\System32\DRIVERS\netbios.sys
F5D16000 - \SystemRoot\System32\DRIVERS\rdbss.sys
F5CB2000 - \SystemRoot\System32\DRIVERS\mrxsmb.sys
F7A9F000 - \SystemRoot\System32\Drivers\Fips.SYS
F78AF000 - \SystemRoot\System32\DRIVERS\wanarp.sys
F7B97000 - \SystemRoot\System32\Drivers\Aavmker4.SYS
F7BA7000 - \SystemRoot\System32\DRIVERS\usbccgp.sys
F5C46000 - \SystemRoot\System32\DRIVERS\phc600.sys
F78BF000 - \SystemRoot\System32\DRIVERS\STREAM.SYS
F78CF000 - \SystemRoot\system32\drivers\usbaudio.sys
F792F000 - \SystemRoot\System32\Drivers\Cdfs.SYS
F5B68000 - \SystemRoot\System32\Drivers\dump_atapi.sys
F7D6B000 - \SystemRoot\System32\Drivers\dump_WMILIB.SYS
BF800000 - \SystemRoot\System32\win32k.sys
F6FE1000 - \SystemRoot\System32\watchdog.sys
F6FDD000 - \SystemRoot\System32\drivers\Dxapi.sys
BFF80000 - \SystemRoot\System32\drivers\dxg.sys
F7E37000 - \SystemRoot\System32\drivers\dxgthk.sys
BF9BB000 - \SystemRoot\System32\nv4_disp.dll
BAC9F000 - \SystemRoot\System32\drivers\afd.sys
BAD30000 - \SystemRoot\System32\DRIVERS\ndisuio.sys
BA371000 - \SystemRoot\System32\Drivers\aswMon2.SYS
BA12E000 - \SystemRoot\system32\drivers\wdmaud.sys
BA279000 - \SystemRoot\system32\drivers\sysaudio.sys
B9E81000 - \SystemRoot\System32\DRIVERS\mrxdav.sys
F7D89000 - \SystemRoot\System32\Drivers\ParVdm.SYS
B9D18000 - \SystemRoot\System32\DRIVERS\srv.sys
B9AFC000 - \SystemRoot\System32\DRIVERS\ipnat.sys
F7B87000 - \??\C:\PROGRA~1\COMMON~1\Motive\MRENDIS5.SYS
B9AF4000 - \??\C:\WINDOWS\System32\AWINDIS5.SYS
B9AF0000 - \SystemRoot\System32\Drivers\aswRdr.SYS
B80F8000 - \SystemRoot\system32\drivers\kmixer.sys
F7E1A000 - \SystemRoot\System32\DRIVERS\KProcCheck.sys
Total number of drivers = 112
Liste des programmes installes
Ad-Aware 2007
Adobe Acrobat 5.0
Adobe Flash Player ActiveX
Adobe Flash Player Plugin
avast! Antivirus
AVIcodec (remove only)
AviSynth 2.5
C-Media WDM Audio Driver
CCleaner (remove only)
Club Internet Agent Wi-Fi V2.1
Football Manager 2008
HijackThis 1.99.1
Indeo® Software
Java(TM) 6 Update 3
K-Lite Codec Pack 3.5.7 Full
Kaspersky Online Scanner
Lame ACM MP3 Codec
Lanceur Club Internet v6
MAGIX Media Manager 2004 silver
MAGIX video deLuxe 2005
Messenger Plus! Live
Microsoft XML Parser
MKVtoolnix 2.1.0
Nero - Burning Rom
NETGEAR Wireless PCI Adapter
NVIDIA Drivers
OpenOffice.org 2.3
Philips SPC 600NC PC Camera
Philips VLounge
Ri4m v5.0.1d
Shareaza 2.3.1.0
Skype™ 3.6
The Cleaner 5
Trojan Remover 6.6.4
Unibet Poker
WebFldrs XP
Windows Live Messenger
WinRAR archiver
Yahoo! Install Manager
Yahoo! Toolbar
Yahoo! Toolbar avec bloqueur de fenêtres pop-up
Le volume dans le lecteur C s'appelle first disk
Le numéro de série du volume est 14AB-045D
Répertoire de C:\Program Files
14/03/2008 16:49 <REP> .
14/03/2008 16:49 <REP> ..
07/12/2007 22:44 <REP> Adobe
14/03/2008 13:26 <REP> AdwareSpywareScannerDeleter
07/12/2007 22:40 <REP> Ahead
07/12/2007 18:47 <REP> Alwil Software
14/03/2008 13:26 <REP> a-squared Anti-Malware
08/12/2007 17:43 <REP> AVIcodec
28/12/2007 19:25 <REP> AviSynth 2.5
14/03/2008 16:49 <REP> CCleaner
07/12/2007 18:38 <REP> Club-Internet
07/12/2007 18:36 <REP> Common Files
07/12/2007 18:21 <REP> ComPlus Applications
20/02/2008 20:50 <REP> Fichiers communs
14/03/2008 16:24 <REP> Google
07/12/2007 18:24 <REP> Internet Explorer
15/12/2007 00:10 <REP> Java
08/12/2007 17:12 <REP> K-Lite Codec Pack
13/12/2007 18:40 <REP> Lavasoft
08/12/2007 17:47 <REP> Ligos
07/12/2007 18:21 <REP> Messenger
08/12/2007 13:41 <REP> Messenger Plus! Live
07/12/2007 18:26 <REP> microsoft frontpage
29/12/2007 12:14 <REP> MKVtoolnix
07/12/2007 18:23 <REP> Movie Maker
07/12/2007 18:21 <REP> MSN
07/12/2007 18:21 <REP> MSN Gaming Zone
08/12/2007 13:41 <REP> MSN Messenger
07/12/2007 18:32 <REP> NETGEAR
07/12/2007 18:22 <REP> NetMeeting
15/12/2007 00:11 <REP> OpenOffice.org 2.3
07/12/2007 18:22 <REP> Outlook Express
08/12/2007 14:21 <REP> Philips
14/03/2008 13:26 <REP> QuickTime(2)
29/12/2007 15:23 <REP> Ripp-it_AM
07/12/2007 18:21 <REP> Services en ligne
06/01/2008 22:53 <REP> Shareaza
20/02/2008 20:51 <REP> Skype
10/12/2007 12:17 <REP> Sports Interactive
14/03/2008 13:26 <REP> Spybot - Search & Destroy
15/03/2008 10:47 <REP> The Cleaner Free
14/03/2008 14:40 <REP> Trojan Remover
08/12/2007 13:41 <REP> Windows Live
29/12/2007 11:24 <REP> Windows Media Player
14/03/2008 16:30 <REP> Windows NT
12/12/2007 14:41 <REP> WinRAR
07/12/2007 18:26 <REP> xerox
14/03/2008 16:49 <REP> Yahoo!
0 fichier(s) 0 octets
48 Rép(s) 39 604 187 136 octets libres
Le volume dans le lecteur C s'appelle first disk
Le numéro de série du volume est 14AB-045D
Répertoire de C:\Program Files\fichiers communs
20/02/2008 20:50 <REP> .
20/02/2008 20:50 <REP> ..
14/12/2007 13:30 <REP> Adobe
08/12/2007 14:21 <REP> ArcSoft
07/12/2007 22:39 <REP> InstallShield
15/12/2007 00:09 <REP> Java
07/12/2007 22:36 <REP> Microsoft Shared
07/12/2007 18:36 <REP> Motive
07/12/2007 18:22 <REP> MSSoap
07/12/2007 18:09 <REP> ODBC
07/12/2007 18:22 <REP> Services
20/02/2008 20:51 <REP> Skype
07/12/2007 18:09 <REP> SpeechEngines
07/12/2007 18:22 <REP> System
13/12/2007 18:40 <REP> Wise Installation Wizard
0 fichier(s) 0 octets
15 Rép(s) 39 604 183 040 octets libres
Le volume dans le lecteur C s'appelle first disk
Le numéro de série du volume est 14AB-045D
Répertoire de C:\Program Files\fichiers communs\Microsoft Shared\Web Folders
07/12/2007 18:30 <REP> .
07/12/2007 18:30 <REP> ..
18/05/2001 17:57 561 209 MSONSEXT.DLL
03/06/1999 14:09 122 937 MSOWS409.DLL
07/03/2001 09:00 127 033 MSOWS40c.DLL
3 fichier(s) 811 179 octets
2 Rép(s) 39 604 183 040 octets libres
Le volume dans le lecteur C s'appelle first disk
Le numéro de série du volume est 14AB-045D
Répertoire de C:\Program Files\common files
07/12/2007 18:36 <REP> .
07/12/2007 18:36 <REP> ..
07/12/2007 18:37 <REP> Motive
0 fichier(s) 0 octets
3 Rép(s) 39 604 183 040 octets libres
c:\Documents and Settings\nans\Application Data\Simply Super Software\Trojan Remover\xsbA.exe
c:\Documents and Settings\nans\Bureau\93.71_forceware_winxp2k_international_whql.exe
c:\Documents and Settings\nans\Bureau\ATF-Cleaner.exe
c:\Documents and Settings\nans\Bureau\ccsetup205.exe
c:\Documents and Settings\nans\Bureau\cleaner5free.exe
c:\Documents and Settings\nans\Bureau\ComboFix.exe
c:\Documents and Settings\nans\Bureau\FxBeagle.exe
c:\Documents and Settings\nans\Bureau\HijackThis.exe
c:\Documents and Settings\nans\Bureau\ie6setup.exe
c:\Documents and Settings\nans\Bureau\Shareaza_2.3.1.0_Win32.exe
c:\Documents and Settings\nans\Bureau\SkypeSetup.exe
c:\Documents and Settings\nans\Bureau\trsetup.exe
c:\Documents and Settings\nans\Bureau\VundoFix.exe
c:\Documents and Settings\nans\Bureau\wrar371.exe
c:\Documents and Settings\nans\Bureau\DiagHelp\catchme.exe
c:\Documents and Settings\nans\Bureau\DiagHelp\diff.exe
c:\Documents and Settings\nans\Bureau\DiagHelp\dumphive.exe
c:\Documents and Settings\nans\Bureau\DiagHelp\FilesInfoCmd.exe
c:\Documents and Settings\nans\Bureau\DiagHelp\find2.exe
c:\Documents and Settings\nans\Bureau\DiagHelp\Fport.exe
c:\Documents and Settings\nans\Bureau\DiagHelp\grep.exe
c:\Documents and Settings\nans\Bureau\DiagHelp\gzip.exe
c:\Documents and Settings\nans\Bureau\DiagHelp\KProcCheck.exe
c:\Documents and Settings\nans\Bureau\DiagHelp\LFiles.exe
c:\Documents and Settings\nans\Bureau\DiagHelp\LISTDLLS.exe
c:\Documents and Settings\nans\Bureau\DiagHelp\md5sums.exe
c:\Documents and Settings\nans\Bureau\DiagHelp\pslist.exe
c:\Documents and Settings\nans\Bureau\DiagHelp\sigcheck.exe
c:\Documents and Settings\nans\Bureau\DiagHelp\streams.exe
c:\Documents and Settings\nans\Bureau\DiagHelp\swreg.exe
c:\Documents and Settings\nans\Bureau\DiagHelp\tar.exe
c:\Documents and Settings\nans\Bureau\GenProc\outil\swreg.exe
c:\Documents and Settings\nans\Bureau\OpenOffice.org 2.3 Installation Files\instmsia.exe
c:\Documents and Settings\nans\Bureau\OpenOffice.org 2.3 Installation Files\instmsiw.exe
c:\Documents and Settings\nans\Bureau\OpenOffice.org 2.3 Installation Files\setup.exe
c:\Documents and Settings\nans\Bureau\OpenOffice.org 2.3 Installation Files\java\jre-6u3-windows-i586-p.exe
c:\Documents and Settings\nans\Local Settings\temp\Install_WLMessenger.exe
c:\Documents and Settings\nans\Mes documents\Downloads\Shareaza_2.2.5.0.exe
c:\Documents and Settings\nans\Mes documents\WinRAR\Rar.exe
c:\Documents and Settings\nans\Mes documents\WinRAR\Uninstall.exe
c:\Documents and Settings\nans\Mes documents\WinRAR\UnRAR.exe
c:\Documents and Settings\nans\Mes documents\WinRAR\WinRAR.exe
c:\Documents and Settings\All Users\Application Data\Microsoft\IdentityCRL\production\ppcrlconfig.dll
c:\Documents and Settings\LocalService\Application Data\Microsoft\UPnP Device Host\upnphost\udhisapi.dll
****** Fin du rapport DiagHelp
Veuillez svp envoyer le fichier C:\upload_moi_NANS-622SMYP9YU.tar.gz a l'adresse
http://upload.malekal.com