effectivement ca marche mieux voila le résultat
DiagHelp version v1.4 -
http://www.malekal.comexcute le 05/03/2008 à 21:21:29,12
Liste des derniers fichies modifies/crees dans windir\system32 et prefetch
C:\Windows\prefetch\CHCP.COM-950EAF32.pf -->05/03/2008 21:21:27
C:\Windows\prefetch\WMPNSCFG.EXE-DF1DD51A.pf -->05/03/2008 21:21:08
C:\Windows\prefetch\WMIPRVSE.EXE-43972D0F.pf -->05/03/2008 21:20:56
C:\Windows\prefetch\UPD2476.TMP.EXE-5CA731F7.pf -->05/03/2008 21:20:56
C:\Windows\prefetch\DLLHOST.EXE-A1CD8B86.pf -->05/03/2008 21:20:56
C:\Windows\prefetch\COH32.EXE-D1B20C81.pf -->05/03/2008 21:20:56
C:\Windows\prefetch\AgGlFgAppHistory.db -->05/03/2008 21:18:59
C:\Windows\prefetch\AgGlGlobalHistory.db -->05/03/2008 21:18:58
C:\Windows\prefetch\AgGlFaultHistory.db -->05/03/2008 21:18:58
C:\Windows\prefetch\PfSvPerfStats.bin -->05/03/2008 21:18:54
C:\Windows\System32\drivers\mrxdav.sys -->14/02/2008 03:12:52
C:\Windows\System32\drivers\WdfLdr.sys -->14/02/2008 03:10:51
C:\Windows\System32\drivers\Wdf01000.sys -->14/02/2008 03:10:51
C:\Windows\System32\drivers\sermouse.sys -->14/02/2008 03:10:50
C:\Windows\System32\drivers\mouhid.sys -->14/02/2008 03:10:50
C:\Windows\System32\drivers\mouclass.sys -->14/02/2008 03:10:50
C:\Windows\System32\drivers\kbdclass.sys -->14/02/2008 03:10:49
C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-1.C7483456-A289-439d-8115-601632D005A0 -->05/03/2008 21:20:06
C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-0.C7483456-A289-439d-8115-601632D005A0 -->05/03/2008 21:20:06
C:\Windows\System32\tmp.txt -->05/03/2008 20:38:19
C:\Windows\System32\tmp.reg -->05/03/2008 20:38:19
C:\Windows\System32\PerfStringBackup.INI -->05/03/2008 19:13:37
C:\Windows\System32\perfh00C.dat -->05/03/2008 19:13:37
C:\Windows\System32\perfh009.dat -->05/03/2008 19:13:37
C:\Windows\System32\perfc00C.dat -->05/03/2008 19:13:37
C:\Windows\System32\perfc009.dat -->05/03/2008 19:13:37
C:\Windows\System32\VACFix.exe -->01/03/2008 23:12:41
C:\Windows\System32\DcadsSocial-uninstall.exe -->01/03/2008 10:53:41
C:\Windows\System32\mysidesearch_sidebar_uninstall.exe -->01/03/2008 10:50:53
C:\Windows\System32\dcads-remove.exe -->01/03/2008 10:50:22
C:\Windows\System32\IEDFix.exe -->29/02/2008 23:48:02
C:\Windows\System32\mysidesearch_sidebar.dll -->25/02/2008 15:34:48
C:\Windows\System32\WebClnt.dll -->14/02/2008 03:12:52
C:\Windows\System32\wpd_ci.dll -->14/02/2008 03:10:55
C:\Windows\System32\drvinst.exe -->14/02/2008 03:10:54
C:\Windows\System32\clfs.sys -->14/02/2008 03:10:54
C:\Windows\System32\cfgmgr32.dll -->14/02/2008 03:10:54
C:\Windows\System32\umpnpmgr.dll -->14/02/2008 03:10:53
C:\Windows\System32\dpx.dll -->14/02/2008 03:10:53
C:\Windows\System32\setupapi.dll -->14/02/2008 03:10:52
C:\Windows\System32\oleaut32.dll -->14/02/2008 03:10:52
C:\Windows\System32\kbd106n.dll -->14/02/2008 03:10:52
C:\Windows\bootstat.dat -->05/03/2008 21:19:55
C:\Windows\WindowsUpdate.log -->05/03/2008 21:18:53
C:\Windows\PFRO.log -->03/03/2008 09:52:44
C:\Windows\setupact.log -->23/02/2008 12:58:29
C:\Windows\S84BF1DA8.tmp -->03/02/2008 18:56:40
C:\Windows\DirectX.log -->01/02/2008 15:11:01
C:\Windows\win.ini -->31/01/2008 14:49:48
C:\Windows\king-uninstall.exe -->31/01/2008 14:28:17
C:\Windows\msxml4-KB941833-enu.LOG -->31/01/2008 13:06:35
C:\Windows\WindowsShell.Manifest -->31/01/2008 11:09:55
C:\Windows\explorer.exe -->31/01/2008 11:00:44
C:\Windows\msxml4-KB936181-enu.LOG -->31/01/2008 10:50:40
C:\Windows\DtcInstall.log -->24/09/2007 10:40:59
C:\Windows\TSSysprep.log -->24/09/2007 10:37:23
C:\Windows\xpsp1hfm.log -->14/09/2007 22:09:07
winlogon.exe
Verified: Signed
svchost.exe
Verified: Signed
ws2_32.dll
Verified: Signed
user32.dll
Verified: Signed
tcpip.sys
Verified: Signed
ndis.sys
Verified: Signed
null.sys
Verified: Signed
ListDLLs v2.25 - DLL lister for Win9x/NT
Copyright (C) 1997-2004 Mark Russinovich
Sysinternals -
http://www.sysinternals.com------------------------------------------------------------------------------
explorer.exe pid: 1888
Command line: C:\Windows\Explorer.EXE
Base Size Version Path
0x002f0000 0x2cd000 6.00.6000.16549 C:\Windows\Explorer.EXE
0x77940000 0x11e000 6.00.6000.16386 C:\Windows\system32\ntdll.dll
0x77aa0000 0xd8000 6.00.6000.16386 C:\Windows\system32\kernel32.dll
0x768c0000 0xbf000 6.00.6000.16386 C:\Windows\system32\ADVAPI32.dll
0x769a0000 0xc3000 6.00.6000.16525 C:\Windows\system32\RPCRT4.dll
0x777f0000 0x4b000 6.00.6000.16386 C:\Windows\system32\GDI32.dll
0x778a0000 0x9e000 6.00.6000.16438 C:\Windows\system32\USER32.dll
0x76aa0000 0xaa000 7.00.6000.16386 C:\Windows\system32\msvcrt.dll
0x77840000 0x55000 6.00.6000.16386 C:\Windows\system32\SHLWAPI.dll
0x76bd0000 0xace000 6.00.6000.16513 C:\Windows\system32\SHELL32.dll
0x776a0000 0x144000 6.00.6000.16386 C:\Windows\system32\ole32.dll
0x764a0000 0x8c000 6.00.6000.16609 C:\Windows\system32\OLEAUT32.dll
0x73350000 0x107000 6.00.6000.16386 C:\Windows\system32\SHDOCVW.dll
0x752a0000 0x3f000 6.00.6000.16386 C:\Windows\system32\UxTheme.dll
0x75550000 0x1a000 6.00.6000.16386 C:\Windows\system32\POWRPROF.dll
0x74000000 0xc000 6.00.6000.20640 C:\Windows\system32\dwmapi.dll
0x74a50000 0x1aa000 5.02.6000.16386 C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.0.6000.16386_none_9ea0ac9ec96e7127\gdiplus.dll
0x75b20000 0x39000 6.00.6000.16509 C:\Windows\system32\slc.dll
0x74c70000 0xb7000 6.00.6000.16386 C:\Windows\system32\PROPSYS.dll
0x73200000 0x145000 6.00.6000.16386 C:\Windows\system32\BROWSEUI.dll
0x76980000 0x1e000 6.00.6000.16386 C:\Windows\system32\IMM32.dll
0x76610000 0xc7000 6.00.6000.16386 C:\Windows\system32\MSCTF.dll
0x75270000 0x30000 6.00.6000.16386 C:\Windows\system32\DUser.dll
0x77a60000 0x9000 6.00.6000.16386 C:\Windows\system32\LPK.DLL
0x76200000 0x7d000 1.626.6000.16386 C:\Windows\system32\USP10.dll
0x74fa0000 0x194000 6.10.6000.16386 C:\Windows\WinSxS\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.6000.16386_none_5d07289e07e1d100\comctl32.dll
0x74450000 0xb2000 6.00.6000.16493 C:\Windows\system32\WindowsCodecs.dll
0x73850000 0x6000 6.00.6000.16386 C:\Windows\system32\IconCodecService.dll
0x76030000 0x2c000 6.00.6000.16386 C:\Windows\system32\apphelp.dll
0x76090000 0x14000 6.00.6000.16386 C:\Windows\system32\Secur32.dll
0x76410000 0x84000 2001.12.6930.16386 C:\Windows\system32\CLBCatQ.DLL
0x75620000 0x38000 6.00.6000.16386 C:\Windows\system32\rsaenh.dll
0x72880000 0xb2000 6.00.6000.16549 C:\Windows\system32\timedate.cpl
0x74850000 0x14000 3.05.2284.0000 C:\Windows\system32\ATL.DLL
0x75dd0000 0x6a000 6.00.6000.16386 C:\Windows\system32\NETAPI32.dll
0x76160000 0x7000 6.00.6000.16386 C:\Windows\system32\PSAPI.DLL
0x74d70000 0x38000 4.02.5406.0000 C:\Windows\system32\OLEACC.dll
0x72820000 0x53000 6.00.6000.16386 C:\Windows\system32\actxprxy.dll
0x760b0000 0x1e000 6.00.6000.16386 C:\Windows\system32\USERENV.dll
0x725e0000 0x2b000 6.00.6000.16386 C:\Windows\system32\msutb.dll
0x756e0000 0xd7000 6.00.6000.16386 C:\Windows\system32\WINBRAND.dll
0x74d30000 0x16000 6.00.6000.16386 C:\Windows\System32\shacct.dll
0x75cd0000 0x11000 6.00.6000.16386 C:\Windows\System32\SAMLIB.dll
0x72480000 0x3c000 6.00.6000.16404 C:\Windows\System32\msshsq.dll
0x72050000 0xc5000 6.00.6000.16386 C:\Windows\System32\NaturalLanguage6.dll
0x75b60000 0xf1000 6.00.6000.16425 C:\Windows\System32\CRYPT32.dll
0x75cb0000 0x12000 6.00.6000.16386 C:\Windows\System32\MSASN1.dll
0x71b30000 0x28c000 6.00.6000.16386 C:\Windows\System32\NLSData000c.dll
0x70f30000 0x5f4000 6.00.6000.16386 C:\Windows\System32\NLSLexicons000c.dll
0x74db0000 0x1e7000 6.00.6000.16513 C:\Windows\system32\authui.dll
0x75540000 0x5000 6.00.6000.16386 C:\Windows\system32\MSIMG32.dll
0x766f0000 0x127000 7.00.6000.16609 C:\Windows\system32\urlmon.dll
0x76820000 0x45000 7.00.6000.16386 C:\Windows\system32\iertutil.dll
0x75570000 0x21000 6.00.6000.16386 C:\Windows\system32\NTMARTA.DLL
0x76870000 0x49000 6.00.6000.16386 C:\Windows\system32\WLDAP32.dll
0x77a70000 0x2d000 6.00.6000.16386 C:\Windows\system32\WS2_32.dll
0x766e0000 0x6000 6.00.6000.16386 C:\Windows\system32\NSI.dll
0x71560000 0x5cd000 7.00.6000.16609 C:\Windows\system32\ieframe.dll
0x72ae0000 0x9000 6.00.6000.16386 C:\Windows\system32\LINKINFO.dll
0x75140000 0x33000 6.00.6000.16386 C:\Windows\system32\WINMM.dll
0x748d0000 0x30000 6.00.6000.16386 C:\Windows\system32\wdmaud.drv
0x748c0000 0x4000 6.00.6000.16386 C:\Windows\system32\ksuser.dll
0x752e0000 0x7000 6.00.6000.16386 C:\Windows\system32\AVRT.dll
0x75240000 0x27000 6.00.6000.20564 C:\Windows\system32\MMDevAPI.DLL
0x76280000 0x189000 6.00.6000.16609 C:\Windows\system32\SETUPAPI.dll
0x74c00000 0x2d000 6.00.6000.16386 C:\Windows\system32\WINTRUST.dll
0x76a70000 0x29000 6.00.6000.16470 C:\Windows\system32\imagehlp.dll
0x746a0000 0x21000 6.00.6000.16386 C:\Windows\System32\audioses.dll
0x74630000 0x66000 6.00.6000.16386 C:\Windows\System32\audioeng.dll
0x74840000 0x9000 6.00.6000.16386 C:\Windows\system32\msacm32.drv
0x747f0000 0x15000 6.00.6000.16386 C:\Windows\system32\MSACM32.dll
0x74620000 0x7000 6.00.6000.16386 C:\Windows\system32\midimap.dll
0x72a50000 0x4a000 6.00.6000.16386 C:\Windows\system32\ntshrui.dll
0x72ad0000 0xa000 6.00.6000.16386 C:\Windows\system32\cscapi.dll
0x72ac0000 0x9000 6.00.6000.16386 C:\Windows\system32\ExplorerFrame.dll
0x76540000 0xcf000 7.00.6000.16609 C:\Windows\system32\WININET.dll
0x76530000 0x3000 6.00.6000.16386 C:\Windows\system32\Normaliz.dll
0x74d60000 0x7000 4.00.6000.16386 C:\Windows\system32\msiltcfg.dll
0x75900000 0x8000 6.00.6000.16386 C:\Windows\system32\VERSION.dll
0x72eb0000 0x204000 4.00.6000.16386 C:\Windows\system32\msi.dll
0x729b0000 0x92000 6.00.6000.16386 C:\Windows\system32\stobject.dll
0x71ea0000 0xb6000 6.00.6000.16386 C:\Windows\system32\BatMeter.dll
0x75470000 0x9000 6.00.6000.16553 C:\Windows\system32\WTSAPI32.dll
0x755d0000 0x24000 6.00.6000.16386 C:\Windows\system32\WINSTA.dll
0x74510000 0x45000 2001.12.6930.16386 C:\Windows\system32\es.dll
0x75370000 0x30000 6.00.6000.16386 C:\Windows\System32\SndVolSSO.dll
0x75340000 0x21000 6.00.6000.16386 C:\Windows\ehome\ehSSO.dll
0x74610000 0x9000 6.00.6000.16386 C:\Windows\system32\HID.DLL
0x70910000 0x30b000 6.00.6000.16386 C:\Windows\System32\netshell.dll
0x75ac0000 0x19000 6.00.6000.16386 C:\Windows\System32\IPHLPAPI.DLL
0x75a80000 0x35000 6.00.6000.16512 C:\Windows\System32\dhcpcsvc.DLL
0x75cf0000 0x2b000 6.00.6000.20492 C:\Windows\System32\DNSAPI.dll
0x75a70000 0x7000 6.00.6000.16386 C:\Windows\System32\WINNSI.DLL
0x75a50000 0x20000 6.00.6000.16512 C:\Windows\System32\dhcpcsvc6.DLL
0x74870000 0xf000 6.00.6000.16386 C:\Windows\System32\nlaapi.dll
0x75480000 0x63000 6.00.6000.16501 C:\Windows\system32\FirewallAPI.dll
0x70d70000 0x1bf000 6.00.6000.16386 C:\Windows\system32\pnidui.dll
0x753b0000 0x17000 6.00.6000.16386 C:\Windows\system32\QUtil.dll
0x75ae0000 0x3e000 6.00.6000.16386 C:\Windows\system32\wevtapi.dll
0x753a0000 0x6000 6.00.6000.16386 C:\Windows\system32\wlanutil.dll
0x725b0000 0x27000 6.00.6000.16386 C:\Windows\system32\FunDisc.dll
0x75330000 0x9000 6.00.6000.16386 C:\Windows\system32\fdproxy.dll
0x72350000 0x126000 8.90.1101.0000 C:\Windows\System32\msxml3.dll
0x70260000 0x8000 6.00.6000.16386 C:\Windows\System32\npmproxy.dll
0x6fe00000 0xe000 6.00.6000.16551 C:\Windows\system32\Wlanapi.dll
0x6ea20000 0x2d000 6.00.6000.16386 C:\Windows\system32\OneX.DLL
0x6f9a0000 0xd000 6.00.6000.16386 C:\Windows\system32\eappprxy.dll
0x6e9f0000 0x28000 6.00.6000.16386 C:\Windows\system32\eappcfg.dll
0x759b0000 0x44000 6.00.6000.16386 C:\Windows\system32\bcrypt.dll
0x6e9d0000 0xd000 6.00.6000.16386 C:\Windows\System32\AltTab.dll
0x6e920000 0x23000 6.00.6000.16386 C:\Windows\system32\wpdshserviceobj.dll
0x72e00000 0x5f000 6.00.6000.16386 C:\Windows\system32\WINHTTP.dll
0x6e8e0000 0x40000 6.00.6000.16386 C:\Windows\System32\srchadmin.dll
0x6dd60000 0x3c000 7.00.6000.16386 C:\Windows\system32\webcheck.dll
0x6d920000 0x21c000 6.00.6000.16386 C:\Windows\System32\SyncCenter.dll
0x6e990000 0x39000 6.00.6000.16386 C:\Windows\system32\wscntfy.dll
0x729a0000 0xb000 6.00.6000.16386 C:\Windows\system32\WSCAPI.dll
0x6e770000 0x51000 6.00.6000.16386 C:\Windows\system32\imapi2.dll
0x70850000 0xb000 6.00.6000.16386 C:\Windows\system32\mssprxy.dll
0x75890000 0x3b000 6.00.6000.16386 C:\Windows\system32\mswsock.dll
0x75530000 0x6000 6.00.6000.16386 C:\Windows\System32\wshtcpip.dll
0x758f0000 0x6000 6.00.6000.16386 C:\Windows\System32\wship6.dll
0x72320000 0x8000 6.00.6000.16386 C:\Windows\System32\winrnr.dll
0x72310000 0xf000 6.00.6000.16386 C:\Windows\system32\napinsp.dll
0x72140000 0x12000 6.00.6000.16386 C:\Windows\system32\pnrpnsp.dll
0x73860000 0x6000 6.00.6000.16386 C:\Windows\system32\rasadhlp.dll
0x10000000 0x19000 1.00.0000.0003 C:\Program Files\SlySoft\AnyDVD\ADvdDiscHlp.dll
0x6ede0000 0x2b000 6.00.6000.16386 C:\Windows\system32\PortableDeviceTypes.dll
0x6fee0000 0x46000 6.00.6000.16386 C:\Windows\system32\PortableDeviceApi.dll
0x75f70000 0x5f000 6.00.6000.16386 C:\Windows\system32\SXS.DLL
0x6ba30000 0xf9000 6.00.6000.16386 C:\Windows\system32\bthprops.cpl
0x6f730000 0x2c000 6.00.6000.16386 C:\Windows\System32\QAgent.dll
0x72520000 0x8a000 6.00.6000.16386 C:\Windows\System32\fwpuclnt.dll
0x75c60000 0x14000 6.00.6000.16386 C:\Windows\system32\MPR.dll
0x6e1a0000 0x60000 6.00.6000.16386 C:\Program Files\Common Files\microsoft shared\ink\tiptsf.dll
0x02d20000 0x10000 8.00.0000.0456 C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
0x73930000 0x9b000 8.00.50727.0762 C:\Windows\WinSxS\x86_microsoft.vc80.crt_1fc8b3b9a1e18e3b_8.0.50727.762_none_10b2f55f9bffb8f8\MSVCR80.dll
0x03250000 0x4a000 1.00.0000.0000 C:\Windows\system32\iebrowserc.dll
0x739d0000 0x87000 8.00.50727.0762 C:\Windows\WinSxS\x86_microsoft.vc80.crt_1fc8b3b9a1e18e3b_8.0.50727.762_none_10b2f55f9bffb8f8\MSVCP80.dll
0x6b170000 0x9a000 107.00.0003.0007 C:\Program Files\Common Files\Symantec Shared\ccL70U.dll
0x75210000 0x22000 1.01.1002.0000 C:\Windows\system32\xmllite.dll
0x70810000 0x12000 6.00.6000.16386 C:\Windows\system32\thumbcache.dll
0x74c50000 0x14000 6.00.6000.16386 C:\Windows\system32\Cabinet.dll
ListDLLs v2.25 - DLL lister for Win9x/NT
Copyright (C) 1997-2004 Mark Russinovich
Sysinternals -
http://www.sysinternals.com------------------------------------------------------------------------------
winlogon.exe pid: 744
Command line: winlogon.exe
Base Size Version Path
0x007f0000 0x4e000 6.00.6000.16386 C:\Windows\system32\winlogon.exe
0x77940000 0x11e000 6.00.6000.16386 C:\Windows\system32\ntdll.dll
0x77aa0000 0xd8000 6.00.6000.16386 C:\Windows\system32\kernel32.dll
0x768c0000 0xbf000 6.00.6000.16386 C:\Windows\system32\ADVAPI32.dll
0x769a0000 0xc3000 6.00.6000.16525 C:\Windows\system32\RPCRT4.dll
0x778a0000 0x9e000 6.00.6000.16438 C:\Windows\system32\USER32.dll
0x777f0000 0x4b000 6.00.6000.16386 C:\Windows\system32\GDI32.dll
0x76aa0000 0xaa000 7.00.6000.16386 C:\Windows\system32\msvcrt.dll
0x76090000 0x14000 6.00.6000.16386 C:\Windows\system32\Secur32.dll
0x755d0000 0x24000 6.00.6000.16386 C:\Windows\system32\WINSTA.dll
0x76160000 0x7000 6.00.6000.16386 C:\Windows\system32\PSAPI.DLL
0x760b0000 0x1e000 6.00.6000.16386 C:\Windows\system32\USERENV.dll
0x76980000 0x1e000 6.00.6000.16386 C:\Windows\system32\IMM32.DLL
0x76610000 0xc7000 6.00.6000.16386 C:\Windows\system32\MSCTF.dll
0x77a60000 0x9000 6.00.6000.16386 C:\Windows\system32\LPK.DLL
0x76200000 0x7d000 1.626.6000.16386 C:\Windows\system32\USP10.dll
0x76030000 0x2c000 6.00.6000.16386 C:\Windows\system32\apphelp.dll
0x75570000 0x21000 6.00.6000.16386 C:\Windows\system32\NTMARTA.DLL
0x76870000 0x49000 6.00.6000.16386 C:\Windows\system32\WLDAP32.dll
0x77a70000 0x2d000 6.00.6000.16386 C:\Windows\system32\WS2_32.dll
0x766e0000 0x6000 6.00.6000.16386 C:\Windows\system32\NSI.dll
0x75cd0000 0x11000 6.00.6000.16386 C:\Windows\system32\SAMLIB.dll
0x776a0000 0x144000 6.00.6000.16386 C:\Windows\system32\ole32.dll
0x745b0000 0x3e000 6.00.6000.16386 C:\Windows\system32\SHSVCS.dll
0x752a0000 0x3f000 6.00.6000.16386 C:\Windows\system32\uxtheme.dll
0x75620000 0x38000 6.00.6000.16386 C:\Windows\system32\rsaenh.dll
0x74450000 0xb2000 6.00.6000.16493 C:\Windows\system32\WindowsCodecs.dll
0x75dd0000 0x6a000 6.00.6000.16386 C:\Windows\system32\NETAPI32.dll
0x75b20000 0x39000 6.00.6000.16509 C:\Windows\system32\slc.dll
0x75c60000 0x14000 6.00.6000.16386 C:\Windows\system32\MPR.dll
Le volume dans le lecteur C s'appelle HP
Le numéro de série du volume est 0E4E-466E
Répertoire de C:\Windows\system32
02/11/2006 10:45 7 680 csrss.exe
1 fichier(s) 7 680 octets
0 Rép(s) 230 782 337 024 octets libres
Contenu de Downloaded Program Files
Le volume dans le lecteur C s'appelle HP
Le numéro de série du volume est 0E4E-466E
Répertoire de C:\Windows\Downloaded Program Files
31/01/2008 14:23 <REP> .
31/01/2008 14:23 <REP> ..
18/09/2006 22:26 65 desktop.ini
04/01/2008 09:51 144 swdir.inf
2 fichier(s) 209 octets
Total des fichiers listés :
2 fichier(s) 209 octets
2 Rép(s) 230 782 337 024 octets libres
Recherche de rootkit! (Merci S!Ri)
Recherche d'infections connues
Export des clefs sensibles..
Liste des fichiers en exception sur le pare-feu XP SP2
Export de la clef SharedTaskScheduler
[SharedTaskScheduler]
exports des policies
REGEDIT4
[System]
"ConsentPromptBehaviorAdmin"=dword:00000002
"ConsentPromptBehaviorUser"=dword:00000001
"EnableInstallerDetection"=dword:00000001
"EnableLUA"=dword:00000000
"EnableSecureUIAPaths"=dword:00000001
"EnableVirtualization"=dword:00000001
"PromptOnSecureDesktop"=dword:00000001
"ValidateAdminCodeSignatures"=dword:00000000
"dontdisplaylastusername"=dword:00000000
"legalnoticecaption"=""
"legalnoticetext"=""
"scforceoption"=dword:00000000
"shutdownwithoutlogon"=dword:00000001
"undockwithoutlogon"=dword:00000001
"FilterAdministratorToken"=dword:00000000
[System\UIPI]
[System\UIPI\Clipboard]
[System\UIPI\Clipboard\ExceptionFormats]
"CF_TEXT"=dword:00000001
"CF_BITMAP"=dword:00000002
"CF_OEMTEXT"=dword:00000007
"CF_DIB"=dword:00000008
"CF_PALETTE"=dword:00000009
"CF_UNICODETEXT"=dword:0000000d
"CF_DIBV5"=dword:00000011
Export des clefs sensibles..
Rechercher adresses sensibles dans le fichier HOSTS...
catchme 0.3.1319 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.netRootkit scan 2008-03-05 21:21:53
Windows 6.0.6000 NTFS
scanning hidden services & system hive ...
IPC error: 2 Le fichier spécifié est introuvable.
scanning hidden registry entries ...
scanning hidden files ...
scan completed successfully
hidden services: 0
hidden files: 0
KProcCheck Version 0.2-beta1 Proof-of-Concept by SIG^2 (
http://www.security.org.sg)
Sorry, this version supports only Win2K/XP
KProcCheck Version 0.2-beta1 Proof-of-Concept by SIG^2 (
http://www.security.org.sg)
Sorry, this version supports only Win2K/XP
Le volume dans le lecteur C s'appelle HP
Le numéro de série du volume est 0E4E-466E
Répertoire de C:\Program Files
04/03/2008 22:13 <REP> .
04/03/2008 22:13 <REP> ..
14/09/2007 22:17 <REP> Adobe
01/03/2008 10:50 <REP> Adssite Games Collection
14/09/2007 22:01 <REP> ATI
14/09/2007 22:03 <REP> ATI Technologies
02/02/2008 10:21 <REP> Azureus
06/02/2008 20:11 <REP> Common Files
05/03/2008 21:20 <REP> ContextEnhancer
31/01/2008 19:03 <REP> DivX
31/01/2008 12:37 <REP> DVD Shrink
15/09/2007 06:59 <REP> EasyBits
03/02/2008 20:03 <REP> Elaborate Bytes
04/03/2008 22:13 <REP> Google
14/09/2007 22:24 <REP> Hewlett-Packard
01/02/2008 16:36 <REP> HomePlayer1.5
14/09/2007 22:18 <REP> HP
14/02/2008 03:19 <REP> Internet Explorer
14/09/2007 22:18 <REP> Java
02/03/2008 11:25 <REP> LimeWire
02/11/2006 13:37 <REP> Microsoft Games
31/01/2008 12:27 <REP> Microsoft Office
03/03/2008 10:55 <REP> Microsoft Silverlight
31/01/2008 12:27 <REP> Microsoft Visual Studio
31/01/2008 12:24 <REP> Microsoft Visual Studio 8
04/03/2008 22:13 <REP> Microsoft Works
31/01/2008 12:26 <REP> Microsoft.NET
15/09/2007 07:11 <REP> Movie Maker
31/01/2008 12:27 <REP> MSBuild
02/11/2006 13:37 <REP> MSN
31/01/2008 10:50 <REP> MSXML 4.0
14/09/2007 22:16 <REP> muvee Technologies
25/02/2008 11:21 <REP> Nero
01/02/2008 10:49 <REP> Norton Internet Security
15/02/2008 15:00 <REP> Norton Security Scan
14/09/2007 22:40 <REP> PC-Doctor 5 for Windows
14/09/2007 22:05 <REP> Realtek
02/11/2006 13:37 <REP> Reference Assemblies
14/09/2007 22:15 <REP> Roxio
14/09/2007 22:26 <REP> Services en ligne
03/02/2008 19:26 <REP> SlySoft
01/02/2008 10:34 <REP> Symantec
02/02/2008 10:39 <REP> uTorrent
31/01/2008 11:06 <REP> Windows Calendar
15/09/2007 07:11 <REP> Windows Collaboration
15/09/2007 07:21 <REP> Windows Defender
15/09/2007 07:11 <REP> Windows Journal
31/01/2008 11:06 <REP> Windows Mail
31/01/2008 11:06 <REP> Windows Media Player
31/01/2008 10:33 <REP> Windows NT
15/09/2007 07:11 <REP> Windows Photo Gallery
31/01/2008 11:06 <REP> Windows Sidebar
01/02/2008 13:07 <REP> WinRAR
0 fichier(s) 0 octets
53 Rép(s) 230 775 607 296 octets libres
Le volume dans le lecteur C s'appelle HP
Le numéro de série du volume est 0E4E-466E
Répertoire de C:\Program Files\fichiers communs
Le volume dans le lecteur C s'appelle HP
Le numéro de série du volume est 0E4E-466E
Répertoire de C:\Program Files\fichiers communs\Microsoft Shared\Web Folders
31/01/2008 12:27 <REP> .
31/01/2008 12:27 <REP> ..
31/01/2008 12:23 <REP> 1036
26/10/2006 20:12 40 256 MSOSV.DLL
1 fichier(s) 40 256 octets
3 Rép(s) 230 775 607 296 octets libres
Le volume dans le lecteur C s'appelle HP
Le numéro de série du volume est 0E4E-466E
Répertoire de C:\Program Files\common files
06/02/2008 20:11 <REP> .
06/02/2008 20:11 <REP> ..
14/09/2007 22:17 <REP> Adobe
04/03/2008 21:55 <REP> Ahead
31/01/2008 12:27 <REP> DESIGNER
14/09/2007 22:08 <REP> HP
14/09/2007 22:09 <REP> InstallShield
14/09/2007 22:18 <REP> Java
14/09/2007 22:16 <REP> LightScribe
14/09/2007 22:15 <REP> LS Getting Started
31/01/2008 14:47 <REP> microsoft shared
14/09/2007 22:16 <REP> muvee Technologies
31/01/2008 18:56 <REP> PX Storage Engine
14/09/2007 22:14 <REP> Roxio Shared
02/11/2006 12:18 <REP> Services
14/09/2007 22:14 <REP> Sonic Shared
02/11/2006 12:18 <REP> SpeechEngines
04/03/2008 22:13 <REP> SureThing Shared
11/02/2008 23:54 <REP> Symantec Shared
31/01/2008 12:23 <REP> System
0 fichier(s) 0 octets
20 Rép(s) 230 775 603 200 octets libres
c:\Users\sandrine\Documents\Downloads\Clone DVD 2.9.1.0 & Clone CD 5.3.0.1\CloneCD 5.3.0.1.exe
c:\Users\sandrine\Documents\Downloads\Clone DVD 2.9.1.0 & Clone CD 5.3.0.1\CloneDVD 2.9.1.0 Keygen.exe
c:\Users\sandrine\Documents\Downloads\Clone DVD 2.9.1.0 & Clone CD 5.3.0.1\CloneDVD 2.9.1.0.exe
c:\Users\sandrine\Documents\Downloads\Clone DVD 2.9.1.0 & Clone CD 5.3.0.1\Slysoft Products Generic Crack 1.43.exe
c:\Users\sandrine\Documents\Downloads\Nero 7.8.5.0\Nero 7.8.5.0.exe
****** Fin du rapport DiagHelp
Veuillez svp envoyer le fichier C:\upload_moi_PC-de-sandrine.tar.gz a l'adresse
http://upload.malekal.com