DiagHelp version v1.4 -
http://www.malekal.comexcute le 22/12/2008 à 15:14:04,31
Liste des derniers fichies modifies/crees dans windir\system32 et prefetch
C:\WINDOWS\prefetch\CHCP.COM-18156052.pf -->22/12/2008 15:13:48
C:\WINDOWS\prefetch\RUNDLL32.EXE-2189AAED.pf -->22/12/2008 15:13:45
C:\WINDOWS\prefetch\RUNDLL32.EXE-188DF14E.pf -->22/12/2008 15:13:44
C:\WINDOWS\prefetch\CMD.EXE-087B4001.pf -->22/12/2008 15:13:37
C:\WINDOWS\prefetch\DIFF.EXE-39C11772.pf -->22/12/2008 15:13:22
C:\WINDOWS\prefetch\NOTEPAD.EXE-336351A9.pf -->22/12/2008 15:12:58
C:\WINDOWS\prefetch\AVWSC.EXE-236190C6.pf -->22/12/2008 15:12:26
C:\WINDOWS\prefetch\VERCLSID.EXE-3667BD89.pf -->22/12/2008 15:10:31
C:\WINDOWS\prefetch\RUNDLL32.EXE-451FC2C0.pf -->22/12/2008 15:10:25
C:\WINDOWS\prefetch\RUNDLL32.EXE-36FA9141.pf -->22/12/2008 15:05:31
C:\WINDOWS\System32\drivers\gmer.sys -->15/12/2008 20:46:43
C:\WINDOWS\System32\drivers\StarOpen.sys -->12/12/2008 13:24:28
C:\WINDOWS\System32\drivers\avipbb.sys -->25/11/2008 22:51:40
C:\WINDOWS\System32\drivers\mrxsmb.sys -->24/10/2008 12:21:09
C:\WINDOWS\System32\drivers\PnkBstrK.sys -->09/09/2008 15:58:19
C:\WINDOWS\System32\drivers\srv.sys -->08/09/2008 11:41:42
C:\WINDOWS\System32\drivers\afd.sys -->14/08/2008 11:04:36
C:\WINDOWS\System32\nvapps.xml -->22/12/2008 11:14:52
C:\WINDOWS\System32\TUProgSt.exe -->20/12/2008 21:44:05
C:\WINDOWS\System32\TuneUpDefragService.exe -->20/12/2008 21:44:04
C:\WINDOWS\System32\d3d9caps.dat -->20/12/2008 19:08:43
C:\WINDOWS\System32\wpa.dbl -->20/12/2008 18:53:28
C:\WINDOWS\System32\perfh00C.dat -->18/12/2008 00:04:02
C:\WINDOWS\System32\perfh009.dat -->18/12/2008 00:04:01
C:\WINDOWS\System32\perfc00C.dat -->18/12/2008 00:04:01
C:\WINDOWS\System32\perfc009.dat -->18/12/2008 00:04:01
C:\WINDOWS\System32\PerfStringBackup.INI -->18/12/2008 00:03:58
C:\WINDOWS\System32\spupdwxp.log -->16/12/2008 00:28:57
C:\WINDOWS\System32\FNTCACHE.DAT -->16/12/2008 00:25:01
C:\WINDOWS\System32\javaws.exe -->15/12/2008 21:30:14
C:\WINDOWS\System32\javaw.exe -->15/12/2008 21:30:14
C:\WINDOWS\System32\javacpl.cpl -->15/12/2008 21:30:14
C:\WINDOWS\System32\java.exe -->15/12/2008 21:30:14
C:\WINDOWS\System32\deploytk.dll -->15/12/2008 21:30:13
C:\WINDOWS\System32\080dc201-.txt -->14/12/2008 19:56:35
C:\WINDOWS\System32\mshtml.dll -->12/12/2008 18:02:12
C:\WINDOWS\System32\uxtuneup.dll -->11/12/2008 13:31:36
C:\WINDOWS\System32\TZLog.log -->11/12/2008 03:01:17
C:\WINDOWS\System32\MRT.exe -->10/12/2008 00:24:37
C:\WINDOWS\System32\CmdLineExt.dll -->30/11/2008 16:54:00
C:\WINDOWS\System32\gdi32.dll -->23/10/2008 13:36:51
C:\WINDOWS\System32\wuweb.dll -->16/10/2008 14:13:40
C:\WINDOWS\WindowsUpdate.log -->22/12/2008 12:36:22
C:\WINDOWS\setupapi.log -->22/12/2008 11:22:17
C:\WINDOWS\0.log -->22/12/2008 11:22:12
C:\WINDOWS\wiaservc.log -->22/12/2008 11:19:49
C:\WINDOWS\wiadebug.log -->22/12/2008 11:19:49
C:\WINDOWS\LogonStudio.ini -->22/12/2008 11:19:18
C:\WINDOWS\bootstat.dat -->22/12/2008 11:12:02
C:\WINDOWS\SchedLgU.Txt -->21/12/2008 18:00:00
C:\WINDOWS\tsoc.log -->21/12/2008 03:06:25
C:\WINDOWS\tabletoc.log -->21/12/2008 03:06:25
C:\WINDOWS\ocmsn.log -->21/12/2008 03:06:25
C:\WINDOWS\ntdtcsetup.log -->21/12/2008 03:06:25
C:\WINDOWS\MedCtrOC.log -->21/12/2008 03:06:25
C:\WINDOWS\KB960714.log -->21/12/2008 03:06:25
C:\WINDOWS\imsins.log -->21/12/2008 03:06:25
winlogon.exe
Verified: Signed
svchost.exe
Verified: Signed
ws2_32.dll
Verified: Signed
user32.dll
Verified: Signed
tcpip.sys
Verified: Signed
ndis.sys
Verified: Signed
null.sys
Verified: Signed
ListDLLs v2.25 - DLL lister for Win9x/NT
Copyright (C) 1997-2004 Mark Russinovich
Sysinternals -
http://www.sysinternals.com------------------------------------------------------------------------------
explorer.exe pid: 1996
Command line: C:\WINDOWS\Explorer.EXE
Base Size Version Path
0x77be0000 0x58000 7.00.2600.5512 C:\WINDOWS\system32\msvcrt.dll
0x779e0000 0x97000 5.131.2600.5512 C:\WINDOWS\system32\CRYPT32.dll
0x76610000 0x84000 5.131.2600.5512 C:\WINDOWS\system32\CRYPTUI.dll
0x76be0000 0x2e000 5.131.2600.5512 C:\WINDOWS\system32\WINTRUST.dll
0x753c0000 0x6b000 1.420.2600.5512 C:\WINDOWS\system32\USP10.dll
0x58b50000 0x9a000 5.82.2900.5512 C:\WINDOWS\system32\comctl32.dll
0x76f80000 0x7f000 2001.12.4414.0700 C:\WINDOWS\system32\CLBCATQ.DLL
0x77000000 0xd4000 2001.12.4414.0700 C:\WINDOWS\system32\COMRes.dll
0x13420000 0x1a000 11.00.5721.5145 C:\PROGRA~1\WINDOW~1\wmpband.dll
0x76ac0000 0x11000 3.05.2284.0001 C:\WINDOWS\system32\ATL.DLL
0x61c20000 0x54000 8.00.0000.9118 C:\Program Files\OpenOffice.org 2.2\program\shlxthdl.dll
0x5fc70000 0x18000 8.00.0000.9107 C:\Program Files\OpenOffice.org 2.2\program\uwinapi.dll
0x7c340000 0x56000 7.10.3052.0004 C:\Program Files\OpenOffice.org 2.2\program\MSVCR71.dll
0x4eb80000 0x1a6000 5.01.3102.5512 C:\WINDOWS\WinSxS\x86_Microsoft.Windows.GdiPlus_6595b64144ccf1df_1.0.2600.5512_x-ww_dfb54e0c\gdiplus.dll
0x61740000 0x8e000 4.05.2003.0120 C:\Program Files\OpenOffice.org 2.2\program\stlport_vc7145.dll
0x7c3a0000 0x7b000 7.10.3077.0000 C:\Program Files\OpenOffice.org 2.2\program\MSVCP71.dll
0x10000000 0x1c000 7.00.0000.0000 C:\Program Files\Adobe\Acrobat 7.0\ActiveX\PDFShell.dll
0x76010000 0x65000 6.02.3104.0000 C:\WINDOWS\system32\MSVCP60.dll
0x164a0000 0x23000 5.02.5721.5145 C:\WINDOWS\system32\WPDShServiceObj.dll
0x109c0000 0x2c000 5.02.5721.5145 C:\WINDOWS\system32\PortableDeviceTypes.dll
0x10930000 0x49000 5.02.5721.5145 C:\WINDOWS\system32\PortableDeviceApi.dll
0x7d200000 0x2bc000 3.01.4001.5512 C:\WINDOWS\system32\msi.dll
0x031f0000 0x188000 1.06.0002.0014 C:\PROGRA~1\SPYBOT~1\SDHelper.dll
0x75be0000 0x7d000 5.07.0000.18066 C:\WINDOWS\system32\jscript.dll
0x74730000 0x3d000 3.525.1132.0000 C:\WINDOWS\system32\ODBC32.dll
0x1f840000 0x18000 3.525.1117.0000 C:\WINDOWS\system32\odbcint.dll
0x50640000 0xa000 7.02.6001.0788 C:\WINDOWS\system32\wups.dll
0x02f50000 0x2c000 C:\Program Files\WinRAR\rarext.dll
0x04ac0000 0x74e000 6.14.0010.8638 C:\WINDOWS\system32\nvcpl.dll
0x74bf0000 0x2c000 4.02.5406.0000 C:\WINDOWS\system32\OLEACC.dll
0x04930000 0x45000 6.14.0010.8638 C:\WINDOWS\system32\NVRSFR.DLL
0x04980000 0x73000 6.14.0010.11058 C:\WINDOWS\system32\nvshell.dll
ListDLLs v2.25 - DLL lister for Win9x/NT
Copyright (C) 1997-2004 Mark Russinovich
Sysinternals -
http://www.sysinternals.com------------------------------------------------------------------------------
winlogon.exe pid: 1008
Command line: winlogon.exe
Base Size Version Path
0x01000000 0x82000 \??\C:\WINDOWS\system32\winlogon.exe
0x77be0000 0x58000 7.00.2600.5512 C:\WINDOWS\system32\msvcrt.dll
0x779e0000 0x97000 5.131.2600.5512 C:\WINDOWS\system32\CRYPT32.dll
0x76be0000 0x2e000 5.131.2600.5512 C:\WINDOWS\system32\WINTRUST.dll
0x753c0000 0x6b000 1.420.2600.5512 C:\WINDOWS\system32\USP10.dll
0x58b50000 0x9a000 5.82.2900.5512 C:\WINDOWS\system32\COMCTL32.dll
0x74730000 0x3d000 3.525.1132.0000 C:\WINDOWS\system32\ODBC32.dll
0x1f840000 0x18000 3.525.1117.0000 C:\WINDOWS\system32\odbcint.dll
0x77000000 0xd4000 2001.12.4414.0700 C:\WINDOWS\system32\COMRes.dll
0x76f80000 0x7f000 2001.12.4414.0700 C:\WINDOWS\system32\CLBCATQ.DLL
0x76010000 0x65000 6.02.3104.0000 C:\WINDOWS\system32\MSVCP60.dll
Le volume dans le lecteur C n'a pas de nom.
Le numéro de série du volume est 032E-06D0
Répertoire de C:\WINDOWS\system32
14/04/2008 03:33 6 144 csrss.exe
1 fichier(s) 6 144 octets
0 Rép(s) 6 784 118 784 octets libres
Contenu de Downloaded Program Files
Le volume dans le lecteur C n'a pas de nom.
Le numéro de série du volume est 032E-06D0
Répertoire de C:\WINDOWS\Downloaded Program Files
14/12/2008 20:25 <REP> .
14/12/2008 20:25 <REP> ..
29/06/2006 10:09 65 desktop.ini
25/07/2002 17:13 24 576 dwusplay.dll
25/07/2002 17:13 196 608 dwusplay.exe
09/08/2004 05:02 327 680 isusweb.dll
13/08/2008 15:03 575 kavwebscan.inf
20/01/2000 14:25 1 162 Microsoft XML Parser for Java.osd
16/08/2007 11:41 267 568 popcaploader.dll
18/04/2005 12:45 242 popcaploader.inf
09/11/2006 14:36 5 019 swflash.inf
9 fichier(s) 823 495 octets
Total des fichiers listés :
9 fichier(s) 823 495 octets
2 Rép(s) 6 784 114 688 octets libres
Recherche de rootkit! (Merci S!Ri)
Recherche d'infections connues
Export des clefs sensibles..
Liste des fichiers en exception sur le pare-feu XP SP2
"%windir%\\system32\\sessmgr.exe"="%windir%\\system32\\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
"C:\\WINDOWS\\system32\\mqsvc.exe"="C:\\WINDOWS\\system32\\mqsvc.exe:*:Enabled:Message Queuing"
"C:\\Program Files\\Messenger\\msmsgs.exe"="C:\\Program Files\\Messenger\\msmsgs.exe:*:Enabled:Windows Messenger"
"C:\\Program Files\\Microsoft Games\\Age of Empires II\\EMPIRES2.ICD"="C:\\Program Files\\Microsoft Games\\Age of Empires II\\EMPIRES2.ICD:*:Enabled:Age of Empires II"
"C:\\Program Files\\TrackMania Nations ESWC\\TmNationsESWC.exe"="C:\\Program Files\\TrackMania Nations ESWC\\TmNationsESWC.exe:*:Enabled:TmNationsESWC"
"C:\\Program Files\\EA GAMES\\Battlefield 2 Demo\\BF2.exe"="C:\\Program Files\\EA GAMES\\Battlefield 2 Demo\\BF2.exe:*:Enabled:Battlefield 2"
"C:\\Program Files\\MessengerDiscovery\\MessengerDiscovery Live.exe"="C:\\Program Files\\MessengerDiscovery\\MessengerDiscovery Live.exe:*:Enabled:MessengerDiscovery Live the Windows Live Messenger addon"
"C:\\Program Files\\BitComet\\BitComet.exe"="C:\\Program Files\\BitComet\\BitComet.exe:*:Enabled:BitComet - a BitTorrent Client"
"C:\\Program Files\\Warcraft III\\Warcraft III.exe"="C:\\Program Files\\Warcraft III\\Warcraft III.exe:*:Enabled:Warcraft III"
"C:\\Program Files\\Electronic Arts\\Battlefield 2142 Demo\\BF2142.exe"="C:\\Program Files\\Electronic Arts\\Battlefield 2142 Demo\\BF2142.exe:*:Enabled:Battlefield 2"
"C:\\Program Files\\Side Effects Software\\Houdini 9.0.688\\bin\\hmaster.exe"="C:\\Program Files\\Side Effects Software\\Houdini 9.0.688\\bin\\hmaster.exe:*:Enabled:hmaster"
"C:\\Program Files\\Side Effects Software\\Houdini 9.0.688\\bin\\mplay.exe"="C:\\Program Files\\Side Effects Software\\Houdini 9.0.688\\bin\\mplay.exe:*:Enabled:mplay"
"C:\\WINDOWS\\system32\\dpnsvr.exe"="C:\\WINDOWS\\system32\\dpnsvr.exe:*:Enabled:Microsoft DirectPlay8 Server"
"C:\\Program Files\\Bonjour\\mDNSResponder.exe"="C:\\Program Files\\Bonjour\\mDNSResponder.exe:*:Enabled:Bonjour"
"C:\\Documents and Settings\\Administrator\\Mes documents\\My documents\\Delphi\\Server-Client\\Server\\ServerApp.exe"="C:\\Documents and Settings\\Administrator\\Mes documents\\My documents\\Delphi\\Server-Client\\Server\\ServerApp.exe:*:Enabled:ServerApp"
"C:\\Documents and Settings\\Administrator\\Mes documents\\My documents\\Delphi\\Server-Client\\ServerApp.exe"="C:\\Documents and Settings\\Administrator\\Mes documents\\My documents\\Delphi\\Server-Client\\ServerApp.exe:*:Enabled:ServerApp"
"C:\\Documents and Settings\\Administrator\\Mes documents\\My documents\\Stargate\\Desktop HUD\\socket\\transfer.exe"="C:\\Documents and Settings\\Administrator\\Mes documents\\My documents\\Stargate\\Desktop HUD\\socket\\transfer.exe:*:Enabled:transfer"
"C:\\Documents and Settings\\Administrator\\Mes documents\\My documents\\Stargate\\Desktop HUD\\socket\\Delphi.exe"="C:\\Documents and Settings\\Administrator\\Mes documents\\My documents\\Stargate\\Desktop HUD\\socket\\Delphi.exe:*:Enabled:Delphi"
"C:\\Documents and Settings\\Administrator\\Mes documents\\My documents\\Stargate\\Desktop HUD\\socket\\socks.exe"="C:\\Documents and Settings\\Administrator\\Mes documents\\My documents\\Stargate\\Desktop HUD\\socket\\socks.exe:*:Enabled:Socket server for port 4000."
"C:\\Documents and Settings\\Administrator\\Mes documents\\My documents\\PHP\\Webserver\\wamp\\bin\\apache\\apache2.2.6\\bin\\httpd.exe"="C:\\Documents and Settings\\Administrator\\Mes documents\\My documents\\PHP\\Webserver\\wamp\\bin\\apache\\apache2.2.6\\bin\\httpd.exe:*:Enabled:Apache HTTP Server"
"C:\\WINDOWS\\system32\\dpvsetup.exe"="C:\\WINDOWS\\system32\\dpvsetup.exe:*:Enabled:Microsoft DirectPlay Voice Test"
"C:\\Documents and Settings\\Administrator\\Mes documents\\My documents\\Stargate\\Desktop HUD\\UDPChat\\chat.exe"="C:\\Documents and Settings\\Administrator\\Mes documents\\My documents\\Stargate\\Desktop HUD\\UDPChat\\chat.exe:*:Enabled:chat"
"C:\\Documents and Settings\\Administrator\\Mes documents\\My documents\\Privat\\3DBuzz\\Test2\\IP_Exchange\\ip_exchange.exe"="C:\\Documents and Settings\\Administrator\\Mes documents\\My documents\\Privat\\3DBuzz\\Test2\\IP_Exchange\\ip_exchange.exe:*:Enabled:ip_exchange"
"C:\\Program Files\\Zattoo\\zattood.exe"="C:\\Program Files\\Zattoo\\zattood.exe:*:Enabled:zattood"
"C:\\Documents and Settings\\Administrator\\Mes documents\\My documents\\Privat\\3DBuzz\\TCP\\Project1.exe"="C:\\Documents and Settings\\Administrator\\Mes documents\\My documents\\Privat\\3DBuzz\\TCP\\Project1.exe:*:Enabled:Project1"
"C:\\Documents and Settings\\Administrator\\Mes documents\\My documents\\Privat\\3DBuzz\\Test3\\MiniServer.exe"="C:\\Documents and Settings\\Administrator\\Mes documents\\My documents\\Privat\\3DBuzz\\Test3\\MiniServer.exe:*:Enabled:MiniServer"
"C:\\Program Files\\Zattoo\\Zattoo2.exe"="C:\\Program Files\\Zattoo\\Zattoo2.exe:*:Enabled: "
"C:\\Program Files\\RealVNC\\VNC4\\vncviewer.exe"="C:\\Program Files\\RealVNC\\VNC4\\vncviewer.exe:*:Enabled:VNC Viewer Free Edition for Win32"
"C:\\Program Files\\RealVNC\\VNC4\\winvnc4.exe"="C:\\Program Files\\RealVNC\\VNC4\\winvnc4.exe:*:Enabled:VNC Server Free Edition for Win32"
"C:\\Program Files\\Mozilla Firefox\\firefox.exe"="C:\\Program Files\\Mozilla Firefox\\firefox.exe:*:Enabled:Firefox"
"C:\\Program Files\\TeamViewer3\\TeamViewer.exe"="C:\\Program Files\\TeamViewer3\\TeamViewer.exe:*:Enabled:Application de pilotage à distance TeamViewer"
"C:\\Program Files\\Zattoo\\Zattoo.exe"="C:\\Program Files\\Zattoo\\Zattoo.exe:*:Enabled: "
"C:\\Program Files\\Glest_3.1.2\\glest.exe"="C:\\Program Files\\Glest_3.1.2\\glest.exe:*:Enabled:glest"
"%windir%\\Network Diagnostic\\xpnetdiag.exe"="%windir%\\Network Diagnostic\\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000"
"C:\\Program Files\\MSN Messenger\\msnmsgr.exe"="C:\\Program Files\\MSN Messenger\\msnmsgr.exe:*:Enabled:Windows Live Messenger 8.1"
"C:\\Program Files\\MSN Messenger\\livecall.exe"="C:\\Program Files\\MSN Messenger\\livecall.exe:*:Enabled:Windows Live Messenger 8.1 (Phone)"
"C:\\Program Files\\Skype\\Phone\\Skype.exe"="C:\\Program Files\\Skype\\Phone\\Skype.exe:*:Enabled:Skype"
"%windir%\\system32\\sessmgr.exe"="%windir%\\system32\\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
"C:\\WINDOWS\\system32\\mqsvc.exe"="C:\\WINDOWS\\system32\\mqsvc.exe:*:Enabled:Message Queuing"
"C:\\Program Files\\MSN Messenger\\msncall.exe"="C:\\Program Files\\MSN Messenger\\msncall.exe:*:Enabled:Windows Live Messenger 8.0 (Phone)"
"%windir%\\Network Diagnostic\\xpnetdiag.exe"="%windir%\\Network Diagnostic\\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000"
"C:\\Program Files\\MSN Messenger\\msnmsgr.exe"="C:\\Program Files\\MSN Messenger\\msnmsgr.exe:*:Enabled:Windows Live Messenger 8.1"
"C:\\Program Files\\MSN Messenger\\livecall.exe"="C:\\Program Files\\MSN Messenger\\livecall.exe:*:Enabled:Windows Live Messenger 8.1 (Phone)"
Export de la clef SharedTaskScheduler
[SharedTaskScheduler]
"{438755C2-A8BA-11D1-B96B-00A0C90312E1}"="Pré-chargeur Browseui"
"{8C7461EF-2B13-11d2-BE35-3078302C2030}"="Démon de cache des catégories de composant"
REGEDIT4
[taskmgr.exe]
exports des policies
REGEDIT4
[system]
"dontdisplaylastusername"=dword:00000000
"legalnoticecaption"=""
"legalnoticetext"=""
"shutdownwithoutlogon"=dword:00000001
"undockwithoutlogon"=dword:00000001
"InstallVisualStyle"=hex(2):43,3a,5c,57,49,4e,44,4f,57,53,5c,52,65,73,6f,75,72,\
63,65,73,5c,54,68,65,6d,65,73,5c,52,6f,79,61,6c,65,5c,52,6f,79,61,6c,65,2e,\
6d,73,73,74,79,6c,65,73,00
"InstallTheme"=hex(2):43,3a,5c,57,49,4e,44,4f,57,53,5c,52,65,73,6f,75,72,63,65,\
73,5c,54,68,65,6d,65,73,5c,52,6f,79,61,6c,65,2e,74,68,65,6d,65,00
"DisableRegistryTools"=dword:00000000
"HideLegacyLogonScripts"=dword:00000000
"HideLogoffScripts"=dword:00000000
"RunLogonScriptSync"=dword:00000001
"RunStartupScriptSync"=dword:00000000
"HideStartupScripts"=dword:00000000
Export des clefs sensibles..
Rechercher adresses sensibles dans le fichier HOSTS...
catchme 0.3.1351 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.netRootkit scan 2008-12-22 15:14:26
Windows 5.1.2600 Service Pack 3 NTFS
scanning hidden services & system hive ...
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4]
"p0"="C:\Program Files\DAEMON Tools\"
"h0"=dword:00000000
"khjeh"=hex:dc,55,ae,ba,be,3b,ec,b4,f5,c6,35,d0,38,21,e5,5a,8a,7b,23,f7,2f,..
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001]
"a0"=hex:20,01,00,00,c6,73,3d,7e,8f,8b,66,be,72,13,33,08,96,c2,13,63,a8,..
"khjeh"=hex:57,3a,27,ed,a5,72,ae,bd,4d,71,38,15,eb,5f,eb,92,20,6f,56,19,24,..
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001\0Jf40]
"khjeh"=hex:a1,39,42,32,d5,8d,f1,36,0f,4d,ac,10,e7,68,24,14,01,28,41,38,ea,..
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001\0Jf41]
"khjeh"=hex:9d,5c,35,3f,80,54,a9,dc,21,1c,c3,38,ae,2f,94,96,2c,55,cc,2b,d5,..
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001\0Jf42]
"khjeh"=hex:9d,5c,35,3f,80,54,a9,dc,21,1c,c3,38,ae,2f,94,96,2c,55,cc,2b,d5,..
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001\0Jf43]
"khjeh"=hex:9d,5c,35,3f,80,54,a9,dc,21,1c,c3,38,ae,2f,94,96,2c,55,cc,2b,d5,..
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4]
"p0"="C:\Program Files\DAEMON Tools\"
"h0"=dword:00000000
"khjeh"=hex:dc,55,ae,ba,be,3b,ec,b4,f5,c6,35,d0,38,21,e5,5a,8a,7b,23,f7,2f,..
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001]
"a0"=hex:20,01,00,00,c6,73,3d,7e,8f,8b,66,be,72,13,33,08,96,c2,13,63,a8,..
"khjeh"=hex:57,3a,27,ed,a5,72,ae,bd,4d,71,38,15,eb,5f,eb,92,20,6f,56,19,24,..
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001\0Jf40]
"khjeh"=hex:a1,39,42,32,d5,8d,f1,36,0f,4d,ac,10,e7,68,24,14,01,28,41,38,ea,..
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001\0Jf41]
"khjeh"=hex:9d,5c,35,3f,80,54,a9,dc,21,1c,c3,38,ae,2f,94,96,2c,55,cc,2b,d5,..
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001\0Jf42]
"khjeh"=hex:9d,5c,35,3f,80,54,a9,dc,21,1c,c3,38,ae,2f,94,96,2c,55,cc,2b,d5,..
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001\0Jf43]
"khjeh"=hex:9d,5c,35,3f,80,54,a9,dc,21,1c,c3,38,ae,2f,94,96,2c,55,cc,2b,d5,..
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\sptd\Cfg]
"s1"=dword:d0c484d3
"s2"=dword:9c0d7c4d
"h0"=dword:00000001
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4]
"p0"="C:\Program Files\DAEMON Tools\"
"h0"=dword:00000000
"khjeh"=hex:dc,55,ae,ba,be,3b,ec,b4,f5,c6,35,d0,38,21,e5,5a,8a,7b,23,f7,2f,..
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001]
"a0"=hex:20,01,00,00,c6,73,3d,7e,8f,8b,66,be,72,13,33,08,96,c2,13,63,a8,..
"khjeh"=hex:57,3a,27,ed,a5,72,ae,bd,4d,71,38,15,eb,5f,eb,92,20,6f,56,19,24,..
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001\0Jf40]
"khjeh"=hex:a1,39,42,32,d5,8d,f1,36,0f,4d,ac,10,e7,68,24,14,01,28,41,38,ea,..
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001\0Jf41]
"khjeh"=hex:9d,5c,35,3f,80,54,a9,dc,21,1c,c3,38,ae,2f,94,96,2c,55,cc,2b,d5,..
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001\0Jf42]
"khjeh"=hex:9d,5c,35,3f,80,54,a9,dc,21,1c,c3,38,ae,2f,94,96,2c,55,cc,2b,d5,..
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001\0Jf43]
"khjeh"=hex:9d,5c,35,3f,80,54,a9,dc,21,1c,c3,38,ae,2f,94,96,2c,55,cc,2b,d5,..
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet004\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4]
"p0"="C:\Program Files\DAEMON Tools\"
"h0"=dword:00000000
"khjeh"=hex:dc,55,ae,ba,be,3b,ec,b4,f5,c6,35,d0,38,21,e5,5a,8a,7b,23,f7,2f,..
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet004\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001]
"a0"=hex:20,01,00,00,c6,73,3d,7e,8f,8b,66,be,72,13,33,08,96,c2,13,63,a8,..
"khjeh"=hex:57,3a,27,ed,a5,72,ae,bd,4d,71,38,15,eb,5f,eb,92,20,6f,56,19,24,..
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet004\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001\0Jf40]
"khjeh"=hex:a1,39,42,32,d5,8d,f1,36,0f,4d,ac,10,e7,68,24,14,01,28,41,38,ea,..
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet004\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001\0Jf41]
"khjeh"=hex:9d,5c,35,3f,80,54,a9,dc,21,1c,c3,38,ae,2f,94,96,2c,55,cc,2b,d5,..
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet004\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001\0Jf42]
"khjeh"=hex:9d,5c,35,3f,80,54,a9,dc,21,1c,c3,38,ae,2f,94,96,2c,55,cc,2b,d5,..
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet004\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001\0Jf43]
"khjeh"=hex:9d,5c,35,3f,80,54,a9,dc,21,1c,c3,38,ae,2f,94,96,2c,55,cc,2b,d5,..
scanning hidden registry entries ...
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Prefetcher]
"TracesProcessed"=dword:000000dd
"TracesSuccessful"=dword:000000dc
"LastTraceFailure"=dword:00000020
scanning hidden files ...
scan completed successfully
hidden services: 0
hidden files: 0
KProcCheck Version 0.2-beta1 Proof-of-Concept by SIG^2 (http://www.security.org.sg)
Process list by traversal of KiWaitListHead
4 - System
380 - sesinetd.exe
436 - sched.exe
760 - svchost.exe
796 - jqs.exe
980 - csrss.exe
1008 - winlogon.exe
1056 - services.exe
1068 - lsass.exe
1236 - svchost.exe
1380 - svchost.exe
1420 - svchost.exe
1592 - hserver.exe
1764 - msdtc.exe
1996 - explorer.exe
2088 - mdm.exe
2152 - hpqimzone.exe
2200 - nvsvc32.exe
2216 - alg.exe
2228 - PnkBstrA.exe
2276 - svchost.exe
2296 - svchost.exe
2360 - msiexec.exe
2388 - TUProgSt.exe
2508 - mcrdsvc.exe
2636 - mqsvc.exe
2868 - wmpnetwk.exe
2968 - iexplore.exe
3288 - cmd.exe
3864 - wmiapsrv.exe
Total number of processes = 30
NOTE: Under WinXP, this will not show all processes.
KProcCheck Version 0.2-beta1 Proof-of-Concept by SIG^2 (http://www.security.org.sg)
Driver/Module list by traversal of PsLoadedModuleList
804D7000 - \WINDOWS\system32\ntkrnlpa.exe
806E4000 - \WINDOWS\system32\hal.dll
F7987000 - \WINDOWS\system32\KDCOM.DLL
F7897000 - \WINDOWS\system32\BOOTVID.dll
F7287000 - sptd.sys
F7989000 - \WINDOWS\System32\Drivers\WMILIB.SYS
F726F000 - \WINDOWS\System32\Drivers\SCSIPORT.SYS
F7240000 - ACPI.sys
F722F000 - pci.sys
F7487000 - ohci1394.sys
F7497000 - \WINDOWS\system32\DRIVERS\1394BUS.SYS
F74A7000 - isapnp.sys
F789B000 - compbatt.sys
F789F000 - \WINDOWS\system32\DRIVERS\BATTC.SYS
F7707000 - \WINDOWS\system32\DRIVERS\PCIIDEX.SYS
F798B000 - intelide.sys
F74B7000 - MountMgr.sys
F71F2000 - ftdisk.sys
F7991000 - dmload.sys
F71CC000 - dmio.sys
F78A3000 - ACPIEC.sys
F7A50000 - \WINDOWS\system32\DRIVERS\OPRGHDLR.SYS
F770F000 - PartMgr.sys
F74C7000 - VolSnap.sys
F71B4000 - atapi.sys
F70DE000 - iaStor.sys
F74D7000 - disk.sys
F74E7000 - \WINDOWS\system32\DRIVERS\CLASSPNP.SYS
F70BE000 - fltmgr.sys
F70AC000 - sr.sys
F74F7000 - PxHelp20.sys
F7095000 - KSecDD.sys
F7082000 - WudfPf.sys
F6FF5000 - Ntfs.sys
F6FC8000 - NDIS.sys
F6F9A000 - Teefer.sys
F7993000 - speedfan.sys
F6F87000 - sfvfs02.sys
F7717000 - sfhlp02.sys
F6F75000 - sfdrv01.sys
F6F5B000 - Mup.sys
F7A51000 - giveio.sys
F7677000 - \SystemRoot\system32\DRIVERS\intelppm.sys
F6F2F000 - \SystemRoot\system32\DRIVERS\CmBatt.sys
F6F27000 - \SystemRoot\system32\DRIVERS\wmiacpi.sys
F6AFB000 - \SystemRoot\system32\DRIVERS\nv4_mini.sys
F6AE7000 - \SystemRoot\system32\DRIVERS\VIDEOPRT.SYS
F6A97000 - \SystemRoot\system32\DRIVERS\HDAudBus.sys
F68F5000 - \SystemRoot\system32\DRIVERS\NETw3x32.sys
F68C9000 - \SystemRoot\system32\DRIVERS\e1e5132.sys
F7827000 - \SystemRoot\system32\DRIVERS\usbuhci.sys
F68A5000 - \SystemRoot\system32\DRIVERS\USBPORT.SYS
F7857000 - \SystemRoot\system32\DRIVERS\usbehci.sys
F7547000 - \SystemRoot\system32\DRIVERS\nic1394.sys
F6891000 - \SystemRoot\system32\DRIVERS\sdbus.sys
F7887000 - \SystemRoot\system32\DRIVERS\rimmptsk.sys
F7557000 - \SystemRoot\system32\DRIVERS\rimsptsk.sys
F6845000 - \SystemRoot\system32\DRIVERS\rixdptsk.sys
F6ED2000 - \SystemRoot\system32\DRIVERS\cpqbttn.sys
F7567000 - \SystemRoot\system32\DRIVERS\HIDCLASS.SYS
F7797000 - \SystemRoot\system32\DRIVERS\HIDPARSE.SYS
F7577000 - \SystemRoot\system32\DRIVERS\i8042prt.sys
F77B7000 - \SystemRoot\system32\DRIVERS\kbdclass.sys
F6815000 - \SystemRoot\system32\DRIVERS\SynTP.sys
F79AB000 - \SystemRoot\system32\DRIVERS\USBD.SYS
F77F7000 - \SystemRoot\system32\DRIVERS\mouclass.sys
F7587000 - \SystemRoot\system32\DRIVERS\imapi.sys
F7597000 - \SystemRoot\system32\DRIVERS\cdrom.sys
F75A7000 - \SystemRoot\system32\DRIVERS\redbook.sys
F67F2000 - \SystemRoot\system32\DRIVERS\ks.sys
F67A8000 - \SystemRoot\System32\Drivers\a3p7qlf2.SYS
F7B50000 - \SystemRoot\system32\DRIVERS\audstub.sys
F75D7000 - \SystemRoot\system32\DRIVERS\rasl2tp.sys
F6F33000 - \SystemRoot\system32\DRIVERS\ndistapi.sys
F6791000 - \SystemRoot\system32\DRIVERS\ndiswan.sys
F75E7000 - \SystemRoot\system32\DRIVERS\raspppoe.sys
F75F7000 - \SystemRoot\system32\DRIVERS\raspptp.sys
F77C7000 - \SystemRoot\system32\DRIVERS\TDI.SYS
F6780000 - \SystemRoot\system32\DRIVERS\psched.sys
F7607000 - \SystemRoot\system32\DRIVERS\msgpc.sys
F77EF000 - \SystemRoot\system32\DRIVERS\ptilink.sys
F7807000 - \SystemRoot\system32\DRIVERS\raspti.sys
F66B0000 - \SystemRoot\system32\DRIVERS\rdpdr.sys
F7627000 - \SystemRoot\system32\DRIVERS\termdd.sys
F79B9000 - \SystemRoot\system32\DRIVERS\swenum.sys
F662A000 - \SystemRoot\system32\DRIVERS\update.sys
F6AC7000 - \SystemRoot\system32\DRIVERS\mssmbios.sys
F6ABF000 - \SystemRoot\system32\DRIVERS\kbdhid.sys
F7617000 - \SystemRoot\System32\Drivers\NDProxy.SYS
F456D000 - \SystemRoot\system32\drivers\CHDAud.sys
F4549000 - \SystemRoot\system32\drivers\portcls.sys
F7637000 - \SystemRoot\system32\drivers\drmk.sys
F4516000 - \SystemRoot\system32\DRIVERS\HSFHWAZL.sys
F4422000 - \SystemRoot\system32\DRIVERS\HSF_DPV.sys
F4370000 - \SystemRoot\system32\DRIVERS\HSF_CNXT.sys
F784F000 - \SystemRoot\System32\Drivers\Modem.SYS
F7517000 - \SystemRoot\system32\DRIVERS\usbhub.sys
F6EBE000 - \SystemRoot\System32\Drivers\i2omgmt.SYS
F79C9000 - \SystemRoot\System32\Drivers\Fs_Rec.SYS
F7BD9000 - \SystemRoot\System32\Drivers\Null.SYS
F79CD000 - \SystemRoot\System32\Drivers\Beep.SYS
F7767000 - \SystemRoot\System32\drivers\vga.sys
F79D1000 - \SystemRoot\System32\Drivers\mnmdd.SYS
F79D5000 - \SystemRoot\System32\DRIVERS\RDPCDD.sys
F7777000 - \SystemRoot\System32\Drivers\Msfs.SYS
F7787000 - \SystemRoot\System32\Drivers\Npfs.SYS
F6EB6000 - \SystemRoot\system32\DRIVERS\rasacd.sys
F42F5000 - \SystemRoot\system32\DRIVERS\ipsec.sys
F429C000 - \SystemRoot\system32\DRIVERS\tcpip.sys
F75B7000 - \SystemRoot\system32\DRIVERS\wanarp.sys
F75C7000 - \??\C:\WINDOWS\system32\drivers\wpsdrvnt.sys
F424E000 - \SystemRoot\system32\DRIVERS\ipnat.sys
F6760000 - \SystemRoot\system32\DRIVERS\arp1394.sys
F4226000 - \SystemRoot\system32\DRIVERS\netbt.sys
F4204000 - \SystemRoot\System32\drivers\afd.sys
F6750000 - \SystemRoot\system32\DRIVERS\netbios.sys
F79DF000 - \SystemRoot\system32\DRIVERS\eabfiltr.sys
F77AF000 - \SystemRoot\System32\Drivers\StarOpen.SYS
F77CF000 - \SystemRoot\system32\DRIVERS\ssmdrv.sys
F4139000 - \SystemRoot\system32\DRIVERS\rdbss.sys
F40C9000 - \SystemRoot\system32\DRIVERS\mrxsmb.sys
F6740000 - \SystemRoot\system32\DRIVERS\snp2uvc.sys
F6730000 - \SystemRoot\system32\DRIVERS\STREAM.SYS
F779F000 - \SystemRoot\system32\DRIVERS\sncduvc.SYS
F7AAB000 - \SystemRoot\System32\Drivers\hwinterface.sys
F6720000 - \SystemRoot\System32\Drivers\Fips.SYS
F40B8000 - \SystemRoot\system32\DRIVERS\avipbb.sys
F79E5000 - \??\C:\Program Files\AntiVir PersonalEdition Classic\avgio.sys
F406C000 - \SystemRoot\System32\Drivers\Fastfat.SYS
F3F96000 - \SystemRoot\System32\Drivers\dump_iaStor.sys
BF800000 - \SystemRoot\System32\win32k.sys
F4280000 - \SystemRoot\System32\drivers\Dxapi.sys
F77A7000 - \SystemRoot\System32\watchdog.sys
BF9C3000 - \SystemRoot\System32\drivers\dxg.sys
F7BD7000 - \SystemRoot\System32\drivers\dxgthk.sys
BF9D5000 - \SystemRoot\System32\nv4_disp.dll
BFFA0000 - \SystemRoot\System32\ATMFD.DLL
BACB4000 - \SystemRoot\system32\DRIVERS\ndisuio.sys
BABC0000 - \SystemRoot\SYSTEM32\Drivers\wg3n.sys
BABB4000 - \SystemRoot\SYSTEM32\Drivers\wg4n.sys
BABA8000 - \SystemRoot\SYSTEM32\Drivers\wg5n.sys
BACA4000 - \SystemRoot\SYSTEM32\Drivers\wg6n.sys
B9CDF000 - \SystemRoot\system32\drivers\wdmaud.sys
BAC30000 - \SystemRoot\system32\drivers\sysaudio.sys
B9BE9000 - \SystemRoot\System32\Drivers\Cdfs.SYS
B9AAC000 - \SystemRoot\system32\DRIVERS\mrxdav.sys
B8CD6000 - \SystemRoot\System32\Drivers\HTTP.sys
B6C41000 - \SystemRoot\system32\DRIVERS\srv.sys
B8A18000 - \SystemRoot\system32\DRIVERS\mdmxsdk.sys
B6C02000 - \??\C:\WINDOWS\system32\drivers\mqac.sys
B6B30000 - \??\C:\WINDOWS\system32\drivers\RMCast.sys
B4E0B000 - \SystemRoot\system32\drivers\kmixer.sys
F7A74000 - \SystemRoot\System32\DRIVERS\KProcCheck.sys
Total number of drivers = 153
Liste des programmes installes
3d Dialing
Adobe After Effects CS3
Adobe After Effects CS3
Adobe After Effects CS3 Presets
Adobe Anchor Service CS3
Adobe Asset Services CS3
Adobe Bridge 1.0
Adobe Bridge CS3
Adobe Bridge Start Meeting
Adobe Camera Raw 4.0
Adobe CMaps
Adobe Color - Photoshop Specific
Adobe Color Common Settings
Adobe Color EU Extra Settings
Adobe Color JA Extra Settings
Adobe Color NA Recommended Settings
Adobe Common File Installer
Adobe Default Language CS3
Adobe Device Central CS3
Adobe ExtendScript Toolkit 2
Adobe Flash CS3
Adobe Flash CS3 Professional
Adobe Flash Player 10 Plugin
Adobe Flash Player ActiveX
Adobe Flash Video Encoder
Adobe Fonts All
Adobe Help Center 1.0
Adobe Help Viewer CS3
Adobe Linguistics CS3
Adobe MotionPicture Color Files
Adobe PDF Library Files
Adobe Photoshop CS2
Adobe Photoshop CS2
Adobe Reader 7.0.5 - Français
Adobe Setup
Adobe Setup
Adobe Shockwave Player
Adobe Stock Photos 1.0
Adobe SVG Viewer 3.0
Adobe Type Support
Adobe Update Manager CS3
Adobe Version Cue CS3 Client
Adobe Video Profiles
Adobe WinSoft Linguistics Plugin
Adobe XMP DVA Panels CS3
Adobe XMP Panels CS3
Amélioration de nos services
Amélioration de nos services
Apple Software Update
Atlantis Xtreme V0.9.1
Avira AntiVir Personal - Free Antivirus
BitComet 0.90
BootSkin
Borland Delphi 6
Borland Delphi 7
Borland Turbo Delphi
BSPlayer
BufferChm
CamStudio
CCleaner (remove only)
Color Cop 5.4.3
Conexant HD Audio
Connexion Facile à Internet
Connexion Facile à Internet
Correctif n° 2 pour Windows XP Édition Media Center 2005
Correctif pour Lecteur Windows Media 11 (KB939683)
Correctif pour Windows XP (KB952287)
CP_AtenaShokunin1Config
CP_CalendarTemplates1
cp_LightScribeConfig
cp_OnlineProjectsConfig
CP_Package_Basic1
CP_Package_Variety1
CP_Package_Variety2
CP_Package_Variety3
CP_Panorama1Config
cp_PosterPrintConfig
cp_UpdateProjectsConfig
CrossKylix 1.0.0
CueTour
Destinations
Dev-C++ 5 beta 9 release (4.9.9.2)
DeviceManagementQFolder
DiskRedactor
DivX Codec
DivX Content Uploader
DivX Converter
DivX Player
DivX Web Player
Désinstaller SAS
EVEREST Home Edition v2.20
Finale NotePad 2005a
FullDPAppQFolder
GemMaster Mystic
Glest 3.1.2
GPL Ghostscript 8.63
GSview 4.9
GUILD WARS
HijackThis 2.0.2
Hotfix for Windows Media Format 11 SDK (KB929399)
Hotfix for Windows Media Player 10 (KB903157)
Houdini 9.0.688
HP Imaging Device Functions 6.0
HP Photosmart Premier Software 6.0
HP Update
HpSdpAppCoreApp
IconPackager
Indy 9 for Delphi 6
Install Creator
InstantShareDevices
Intel(R) PRO Network Connections Drivers
InterBase 6.5
J2SE Runtime Environment 5.0 Update 6
Java(TM) 6 Update 11
Java(TM) 6 Update 5
Java(TM) SE Runtime Environment 6
Kaspersky Online Scanner
Lecteur Windows Media 11
LightScribe 1.4.97.1
LogonStudio
Macromedia Flash Player 8
Macromedia Shockwave Player
MessengerDiscovery Live 1.4.5408
Microsoft .NET Framework 1.1
Microsoft .NET Framework 1.1
Microsoft .NET Framework 1.1 French Language Pack
Microsoft .NET Framework 1.1 Hotfix (KB928366)
Microsoft .NET Framework 2.0 Service Pack 1
Microsoft .NET Framework SDK (English) 1.1
Microsoft Age of Empires II
Microsoft Compression Client Pack 1.0 for Windows XP
Microsoft Game Studios Common Redistributables Pack 1
Microsoft User-Mode Driver Framework Feature Pack 1.0
Microsoft Visual C++ 2005 Redistributable
Microsoft Visual J# .NET Redistributable Package 1.1
Microsoft Works
Microsoft XML Parser
MiKTeX 2.7
Mise à jour de sécurité pour Lecteur Windows Media (KB911564)
Mise à jour de sécurité pour Lecteur Windows Media (KB952069)
Mise à jour de sécurité pour Lecteur Windows Media 10 (KB911565)
Mise à jour de sécurité pour Lecteur Windows Media 10 (KB917734)
Mise à jour de sécurité pour Lecteur Windows Media 11 (KB936782)
Mise à jour de sécurité pour Lecteur Windows Media 11 (KB954154)
Mise à jour de sécurité pour Step by Step Interactive Training (KB898458)
Mise à jour de sécurité pour Step by Step Interactive Training (KB923723)
Mise à jour de sécurité pour Windows XP (KB938464)
Mise à jour de sécurité pour Windows XP (KB941569)
Mise à jour de sécurité pour Windows XP (KB946648)
Mise à jour de sécurité pour Windows XP (KB950759)
Mise à jour de sécurité pour Windows XP (KB950760)
Mise à jour de sécurité pour Windows XP (KB950762)
Mise à jour de sécurité pour Windows XP (KB950974)
Mise à jour de sécurité pour Windows XP (KB951066)
Mise à jour de sécurité pour Windows XP (KB951376-v2)
Mise à jour de sécurité pour Windows XP (KB951376)
Mise à jour de sécurité pour Windows XP (KB951698)
Mise à jour de sécurité pour Windows XP (KB951748)
Mise à jour de sécurité pour Windows XP (KB952954)
Mise à jour de sécurité pour Windows XP (KB953838)
Mise à jour de sécurité pour Windows XP (KB953839)
Mise à jour de sécurité pour Windows XP (KB954211)
Mise à jour de sécurité pour Windows XP (KB954459)
Mise à jour de sécurité pour Windows XP (KB954600)
Mise à jour de sécurité pour Windows XP (KB955069)
Mise à jour de sécurité pour Windows XP (KB956390)
Mise à jour de sécurité pour Windows XP (KB956391)
Mise à jour de sécurité pour Windows XP (KB956802)
Mise à jour de sécurité pour Windows XP (KB956803)
Mise à jour de sécurité pour Windows XP (KB956841)
Mise à jour de sécurité pour Windows XP (KB957095)
Mise à jour de sécurité pour Windows XP (KB957097)
Mise à jour de sécurité pour Windows XP (KB958215)
Mise à jour de sécurité pour Windows XP (KB958644)
Mise à jour de sécurité pour Windows XP (KB960714)
Mise à jour pour Lecteur Windows Media 10 (KB910393)
Mise à jour pour Lecteur Windows Media 10 (KB913800)
Mise à jour pour Lecteur Windows Media 10 (KB926251)
Mise à jour pour Windows XP (KB951072-v2)
Mise à jour pour Windows XP (KB951978)
Mise à jour pour Windows XP (KB955839)
Mozilla Firefox (2.0.0.18)
MSN
MSVC80_x86
MSXML 4.0 SP2 (KB927978)
MSXML 4.0 SP2 (KB936181)
MSXML 4.0 SP2 (KB954430)
MSXML 6 Service Pack 2 (KB954459)
neroxml
Nullsoft Install System
NVIDIA Drivers
Nvu 1.0
OpenMG Secure Module 4.4.00
OpenMG Secure Module 4.4.00
OpenOffice.org 2.2
OptionalContentQFolder
Otto
PDF Settings
PhotoGallery
Phun beta 4.11
QuickTime
RandMap
RealPlayer
SAMSUNG Mobile Modem Driver Set
Samsung Mobile phone USB driver Software
SAMSUNG Mobile USB Modem 1.0 Software
SAMSUNG Mobile USB Modem Software
SAPI 5.1 Speech Recognition Engine Redistribution by CoolSoft
save2pc Light 3.22
SkinsHP1
SkinStudio
SkinStudio
Skype 3.0
Skype Plugin Manager
Soft Data Fax Modem with SmartCP
Sonic_PrimoSDK
SonicAC3Encoder
SonicMPEGEncoder
SpeedFan (remove only)
Spybot - Search & Destroy
Spybot - Search & Destroy 1.5.2.20
StarGate_Program_v2-2-1
SuperTux 0.1.2
Synaptics Pointing Device Driver
TeamSpeak 2 RC2
TeamViewer 3
TeXnicCenter Version 1.0 Stable RC1
TI Connect 1.6
TrackMania Nations ESWC 1.7.9
TuneUp Utilities 2009
Unload
VNC Free Edition 4.1.3
Voice Activated Commands Full
WampServer 2.0
WebFldrs XP
Windows Genuine Advantage Validation Tool
Windows Imaging Component
Windows Live Messenger
Windows Media Connect
Windows Media Format 11 runtime
Windows Media Format 11 runtime
Windows Media Player 11
Windows Media Player Firefox Plugin
Windows XP Media Center Edition 2005 KB925766
Windows XP Service Pack 3
WinRAR archiver
WinStars 2.0
WinStars 2.0 (Tycho 2 catalogue)
wxChecksums 1.2.0
XML Paper Specification Shared Components Pack 1.0
XnView 1.93.1
Xplore 2.0.22
YouTube Downloader 2.5
Zattoo 3.3.1 Beta
Le volume dans le lecteur C n'a pas de nom.
Le numéro de série du volume est 032E-06D0
Répertoire de C:\Program Files
20/12/2008 21:41 <REP> .
20/12/2008 21:41 <REP> ..
14/06/2007 20:53 <REP> [BETA-TEST]Sas
30/06/2007 18:28 <REP> 3d Dialing
14/01/2008 21:59 <REP> Adobe
21/12/2008 18:55 <REP> AntiVir PersonalEdition Classic
22/12/2007 11:20 <REP> Apache Group
17/02/2007 19:39 <REP> Apple Software Update
20/06/2007 18:15 <REP> AS2I Software
13/12/2008 13:08 <REP> BitComet
06/11/2007 15:46 <REP> Bonjour
29/02/2008 12:02 <REP> Borland
02/08/2007 11:18 <REP> CamStudio
15/12/2008 19:12 <REP> CCleaner
27/03/2008 10:34 <REP> CEZEO software
07/10/2007 18:21 <REP> Chevron Entertainment.INC Copyright 2006-2007
03/11/2007 19:17 <REP> Color_Cop
19/09/2006 22:41 <REP> ComPlus Applications
19/09/2006 15:22 <REP> CONEXANT
04/08/2008 15:59 <REP> CrossKylix
27/07/2007 20:05 <REP> DAEMON Tools
20/02/2007 10:10 <REP> DivX
28/01/2007 17:23 <REP> EA GAMES
23/06/2008 22:16 <REP> EasyPHP 2.0b1
28/08/2007 16:07 <REP> Electronic Arts
01/01/2008 16:33 <REP> FDRLab
15/12/2008 19:49 <REP> Fichiers communs
31/08/2007 08:44 <REP> Finale NotePad 2005a
19/09/2006 15:10 <REP> FrenchOtto
19/09/2006 15:10 <REP> GemMasterFrench
06/12/2008 17:39 <REP> Ghostgum
30/11/2008 12:31 <REP> Glest_3.1.2
05/09/2007 08:29 <REP> Google
06/12/2008 18:06 <REP> gs
17/09/2007 14:33 <REP> GUILD WARS
20/12/2006 04:19 <REP> Hewlett-Packard
19/09/2006 15:20 <REP> HP
20/12/2006 04:01 <REP> HPQ
04/02/2008 21:03 <REP> Indy 9 for Delphi 6
18/12/2007 17:30 <REP> Install Creator
15/12/2008 21:40 <REP> Internet Explorer
15/12/2008 21:30 <REP> Java
08/05/2008 13:44 <REP> Lavalys
15/12/2008 21:44 <REP> Messenger
21/12/2008 12:02 <REP> MessengerDiscovery
19/09/2006 22:41 <REP> microsoft frontpage
22/11/2008 15:05 <REP> Microsoft Games
17/11/2007 22:15 <REP> Microsoft Office
17/11/2007 22:15 <REP> Microsoft Visual Studio .NET 2003
19/09/2006 15:13 <REP> Microsoft Works
17/11/2007 22:15 <REP> Microsoft.NET
12/12/2008 21:46 <REP> MiKTeX 2.7
15/12/2008 21:39 <REP> Movie Maker
21/12/2008 15:33 <REP> Mozilla Firefox
27/12/2006 17:15 <REP> MSN
19/09/2006 22:41 <REP> MSN Gaming Zone
16/12/2008 00:28 <REP> MSN Messenger
22/12/2006 17:26 <REP> MSXML 4.0
25/01/2008 21:58 <REP> MSXML 6.0
04/12/2008 17:34 <REP> NeoTrace Express
15/12/2008 21:37 <REP> NetMeeting
19/09/2006 15:22 <REP> NetWaiting
27/03/2008 10:26 <REP> NSIS
14/01/2007 21:06 <REP> Nvu
29/06/2007 21:44 <REP> OpenOffice.org 2.2
15/12/2008 21:37 <REP> Outlook Express
26/12/2007 18:44 <REP> PHP
18/10/2008 10:26 <REP> Phun
12/09/2007 15:30 <REP> PSCS2Updater
17/02/2007 19:39 <REP> QuickTime
10/09/2007 11:43 <REP> Real
28/10/2008 21:14 <REP> RealVNC
13/12/2008 15:12 <REP> Samsung
05/02/2007 15:28 <REP> Screamer Radio
06/10/2007 11:30 <REP> Services en ligne
28/08/2007 12:58 <REP> Side Effects Software
01/01/2007 18:31 <REP> Skype
13/12/2008 15:15 <REP> Sony
20/12/2006 11:33 <REP> Sony Corporation
29/06/2008 14:38 <REP> SpeedFan
14/12/2008 15:50 <REP> Spybot - Search & Destroy
27/11/2007 22:07 <REP> Stardock
25/03/2008 20:32 <REP> StarGate_Program_v2-2-1
23/08/2007 17:06 <REP> SuperTux
20/12/2006 12:43 <REP> Sygate
19/09/2006 15:14 <REP> Synaptics
26/08/2008 19:47 <REP> Teamspeak2_RC2
21/11/2008 20:44 <REP> TeamViewer3
12/12/2008 22:50 <REP> TeXnicCenter
31/05/2007 10:00 <REP> TI Education
17/12/2008 18:23 <REP> TrackMania Nations ESWC
20/12/2008 21:42 <REP> TuneUp Utilities 2009
23/05/2008 10:31 <REP> VAC System
21/11/2008 20:54 <REP> VNCon
20/07/2007 21:37 <REP> Warcraft III
11/07/2007 18:42 <REP> Warcraft III Demo
17/11/2007 20:00 <REP> Webteh
03/10/2007 14:27 <REP> WinCustomize
06/07/2008 18:37 <REP> Windows Live
30/05/2007 19:00 <REP> Windows Live Safety Center
13/01/2007 20:44 <REP> Windows Media Connect 2
13/01/2007 20:46 <REP> Windows Media Player
15/12/2008 21:37 <REP> Windows NT
19/09/2006 22:41 <REP> Windows Plus
19/07/2007 22:10 <REP> WinRAR
01/01/2008 18:40 <REP> WinStars2
19/07/2007 11:14 251 wt3d.ini
18/08/2008 17:59 <REP> wxChecksums
19/09/2006 22:41 <REP> xerox
23/03/2008 09:05 <REP> XnView
12/09/2008 14:06 <REP> Zattoo
1 fichier(s) 251 octets
110 Rép(s) 6 752 006 144 octets libres
Le volume dans le lecteur C n'a pas de nom.
Le numéro de série du volume est 032E-06D0
Répertoire de C:\Program Files\fichiers communs
15/12/2008 19:49 <REP> .
15/12/2008 19:49 <REP> ..
14/01/2008 22:00 <REP> Adobe
12/09/2007 15:14 <REP> Adobe Systems Shared
27/07/2007 20:01 <REP> Ahead
06/10/2007 11:06 <REP> AOL
04/02/2008 20:42 <REP> Borland Shared
19/09/2006 22:41 <REP> HP
15/09/2007 17:11 <REP> InstallShield
19/09/2006 22:41 <REP> Java
30/01/2007 23:03 <REP> LightScribe
06/11/2007 15:36 <REP> Macrovision Shared
17/11/2007 22:15 <REP> Microsoft Shared
24/09/2008 15:16 <REP> Motive
19/09/2006 22:41 <REP> MSSoap
19/09/2006 22:41 <REP> ODBC
10/09/2007 11:55 <REP> Real
19/09/2006 22:41 <REP> Services
01/01/2007 18:31 <REP> Skype
22/12/2006 18:43 <REP> Sonic Shared
20/12/2006 11:33 <REP> Sony Shared
19/09/2006 22:41 <REP> SpeechEngines
24/01/2008 20:33 <REP> Stardock
22/12/2006 18:32 <REP> Symantec Shared
15/12/2008 21:37 <REP> System
31/05/2007 09:59 <REP> TI Shared
21/12/2008 09:40 <REP> Wise Installation Wizard
10/09/2007 11:55 <REP> xing shared
0 fichier(s) 0 octets
28 Rép(s) 6 752 002 048 octets libres
Le volume dans le lecteur C n'a pas de nom.
Le numéro de série du volume est 032E-06D0
Répertoire de C:\Program Files\fichiers communs\Microsoft Shared\Web Folders
19/09/2006 22:41 <REP> .
19/09/2006 22:41 <REP> ..
18/05/2001 22:57 561 209 MSONSEXT.DLL
03/06/1999 19:09 122 937 MSOWS409.DLL
07/03/2001 14:00 127 033 MSOWS40c.DLL
3 fichier(s) 811 179 octets
2 Rép(s) 6 752 002 048 octets libres
Le volume dans le lecteur C n'a pas de nom.
Le numéro de série du volume est 032E-06D0
Répertoire de C:\
20/12/2006 11:04 10 816 112 antivir_workstation_win7u_en_h.exe
20/12/2006 11:12 9 228 440 spf.exe
2 fichier(s) 20 044 552 octets
0 Rép(s) 6 752 002 048 octets libres
c:\Documents and Settings\Administrateur\Application Data\Microsoft\Installer\{52FBAE98-D389-4281-8C14-21B4046CCB4E}\ARPPRODUCTICON.exe
c:\Documents and Settings\Administrateur\Application Data\Microsoft\Installer\{6815FCDD-401D-481E-BA88-31B4754C2B46}\ARPPRODUCTICON.exe
c:\Documents and Settings\Administrateur\Application Data\Microsoft\Installer\{B16AF568-A644-483C-A6DA-5028CD019C8C}\ARPPRODUCTICON.exe
c:\Documents and Settings\Administrator\Application Data\Microsoft\Installer\{52FBAE98-D389-4281-8C14-21B4046CCB4E}\ARPPRODUCTICON.exe
c:\Documents and Settings\Administrator\Application Data\Microsoft\Installer\{54316F1C-4E8F-43B8-AB51-DFA69FE800AC}\NewShortcut1_CDE46766A2BC44FFA781D2C718336F65_1.exe
c:\Documents and Settings\Administrator\Application Data\Microsoft\Installer\{54316F1C-4E8F-43B8-AB51-DFA69FE800AC}\NewShortcut11_CDE46766A2BC44FFA781D2C718336F65.exe
c:\Documents and Settings\Administrator\Application Data\Microsoft\Installer\{54316F1C-4E8F-43B8-AB51-DFA69FE800AC}\NewShortcut4_54316F1C4E8F43B8AB51DFA69FE800AC.exe
c:\Documents and Settings\Administrator\Application Data\Microsoft\Installer\{B16AF568-A644-483C-A6DA-5028CD019C8C}\ARPPRODUCTICON.exe
c:\Documents and Settings\Administrator\Application Data\Microsoft\IdentityCRL\Production\ppcrlconfig.dll
****** Fin du rapport DiagHelp
Veuillez svp envoyer le fichier C:\upload_moi_PC-PX.tar.gz a l'adresse
http://upload.malekal.com