bonjour,
voici les temperatures demander avec siw :
analog device AMD1031
temperature value min max
local 44° 44° 44°
remote 1 43° 40° 56°
remote 2 54° 54° 54°
fans
famino 2147483648RPM
famini 2147483648RPM
ACPI
teperatures
TZ1 43° 40° 45°
TZ2 54° 54° 54°
TZ3 28° 28° 28°
raport Diaghelp :
DiagHelp version v1.4 - http://www.malekal.com
excute le 09/06/2008 à 16:52:58,56
Liste des derniers fichies modifies/crees dans windir\system32 et prefetch
C:\WINDOWS\prefetch\CHCP.COM-18156052.pf -->09/06/2008 16:52:53
C:\WINDOWS\prefetch\CMD.EXE-087B4001.pf -->09/06/2008 16:52:52
C:\WINDOWS\prefetch\AVWSC.EXE-347FCF75.pf -->09/06/2008 16:51:25
C:\WINDOWS\prefetch\EXPLORER.EXE-082F38A9.pf -->09/06/2008 16:50:25
C:\WINDOWS\prefetch\VERCLSID.EXE-3667BD89.pf -->09/06/2008 16:49:53
C:\WINDOWS\prefetch\HPZENG04.EXE-129A6FF3.pf -->09/06/2008 16:46:54
C:\WINDOWS\prefetch\HPZSTC04.EXE-1001DF4D.pf -->09/06/2008 16:46:50
C:\WINDOWS\prefetch\WLLOGINPROXY.EXE-2D4B6027.pf -->09/06/2008 16:45:36
C:\WINDOWS\prefetch\GOOGLETOOLBARNOTIFIER.EXE-3629C61D.pf -->09/06/2008 16:45:36
C:\WINDOWS\prefetch\CTFMON.EXE-0E17969B.pf -->09/06/2008 16:45:29
C:\WINDOWS\System32\drivers\mbamcatchme.sys -->05/06/2008 16:04:16
C:\WINDOWS\System32\drivers\mbam.sys -->05/06/2008 16:04:12
C:\WINDOWS\System32\drivers\MS1000.sys -->19/05/2008 00:26:17
C:\WINDOWS\System32\drivers\HP_HP CPQ nc6000 (DJ333A ABF)_YN_U_QCNU428_E_4_I0890_SHP_V8051 Version 1A.19_B68BDD Ver. F.0E_T040422_WXP1_L40C_M1024_J40_7Intel_8Pentium M_91,5_1_N_P12177223_Z808624C6_K_A_U808624C2_G10024E50.MRK -->12/05/2008 22:58:01
C:\WINDOWS\System32\drivers\rdpwd.sys -->14/04/2008 04:34:54
C:\WINDOWS\System32\drivers\tdtcp.sys -->14/04/2008 04:34:53
C:\WINDOWS\System32\drivers\termdd.sys -->14/04/2008 04:34:52
C:\WINDOWS\System32\wpa.dbl -->09/06/2008 11:45:25
C:\WINDOWS\System32\FNTCACHE.DAT -->08/06/2008 17:14:35
C:\WINDOWS\System32\nscompat.tlb -->08/06/2008 16:29:58
C:\WINDOWS\System32\amcompat.tlb -->08/06/2008 16:29:58
C:\WINDOWS\System32\GDIPFONTCACHEV1.DAT -->02/06/2008 03:08:58
C:\WINDOWS\System32\perfh00C.dat -->29/05/2008 15:46:45
C:\WINDOWS\System32\perfh009.dat -->29/05/2008 15:46:45
C:\WINDOWS\System32\perfc00C.dat -->29/05/2008 15:46:45
C:\WINDOWS\System32\perfc009.dat -->29/05/2008 15:46:45
C:\WINDOWS\System32\PerfStringBackup.INI -->29/05/2008 15:46:44
C:\WINDOWS\System32\lvcoinst.log -->29/05/2008 15:44:53
C:\WINDOWS\System32\jupdate-1.6.0_06-b02.log -->27/05/2008 18:22:19
C:\WINDOWS\System32\zllictbl.dat -->17/05/2008 15:36:56
C:\WINDOWS\System32\TuneUpDefragService.exe -->14/05/2008 18:14:58
C:\WINDOWS\System32\spupdwxp.log -->13/05/2008 19:40:28
C:\WINDOWS\System32\wbocx.ocx -->13/05/2008 17:43:01
C:\WINDOWS\System32\wbhelp2.dll -->13/05/2008 17:43:01
C:\WINDOWS\System32\AniGIF.ocx -->13/05/2008 17:43:01
C:\WINDOWS\System32\h323log.txt -->12/05/2008 23:14:30
C:\WINDOWS\System32\wmpscheme.xml -->12/05/2008 22:31:10
C:\WINDOWS\System32\$winnt$.inf -->12/05/2008 22:25:17
C:\WINDOWS\System32\CONFIG.NT -->12/05/2008 22:21:53
C:\WINDOWS\System32\WindowsLogon.manifest -->12/05/2008 22:20:13
C:\WINDOWS\System32\logonui.exe.manifest -->12/05/2008 22:20:13
C:\WINDOWS\System32\wuaucpl.cpl.manifest -->12/05/2008 22:20:04
C:\WINDOWS\WindowsUpdate.log -->09/06/2008 11:43:42
C:\WINDOWS\wiadebug.log -->09/06/2008 10:30:13
C:\WINDOWS\wiaservc.log -->09/06/2008 10:30:07
C:\WINDOWS\bootstat.dat -->09/06/2008 10:29:34
C:\WINDOWS\SchedLgU.Txt -->09/06/2008 03:22:43
C:\WINDOWS\mscpt.dat -->09/06/2008 02:04:32
C:\WINDOWS\ODBC.INI -->05/06/2008 18:03:36
C:\WINDOWS\vbaddin.ini -->05/06/2008 18:03:26
C:\WINDOWS\win.ini -->05/06/2008 18:02:42
C:\WINDOWS\mdm.ini -->05/06/2008 17:57:19
C:\WINDOWS\Sti_Trace.log -->02/06/2008 03:08:38
C:\WINDOWS\WMSysPr9.prx -->29/05/2008 15:44:10
C:\WINDOWS\system.ini -->21/05/2008 16:46:58
C:\WINDOWS\Cpqdiag.ini -->20/05/2008 17:15:30
C:\WINDOWS\factory.ini -->20/05/2008 17:15:08
winlogon.exe
Verified: Signed
svchost.exe
Verified: Signed
ws2_32.dll
Verified: Signed
user32.dll
Verified: Signed
tcpip.sys
Verified: Signed
ndis.sys
Verified: Signed
null.sys
Verified: Signed
ListDLLs v2.25 - DLL lister for Win9x/NT
Copyright (C) 1997-2004 Mark Russinovich
Sysinternals - www.sysinternals.com
------------------------------------------------------------------------------
explorer.exe pid: 1816
Command line: C:\WINDOWS\Explorer.EXE
Base Size Version Path
0x77be0000 0x58000 7.00.2600.5512 C:\WINDOWS\system32\msvcrt.dll
0x779e0000 0x97000 5.131.2600.5512 C:\WINDOWS\system32\CRYPT32.dll
0x76610000 0x84000 5.131.2600.5512 C:\WINDOWS\system32\CRYPTUI.dll
0x771b0000 0xce000 7.00.5730.0013 C:\WINDOWS\system32\WININET.dll
0x00400000 0x9000 6.00.5441.0000 C:\WINDOWS\system32\Normaliz.dll
0x5dca0000 0x45000 7.00.5730.0013 C:\WINDOWS\system32\iertutil.dll
0x76be0000 0x2e000 5.131.2600.5512 C:\WINDOWS\system32\WINTRUST.dll
0x58b50000 0x9a000 5.82.2900.5512 C:\WINDOWS\system32\comctl32.dll
0x76f80000 0x7f000 2001.12.4414.0700 C:\WINDOWS\system32\CLBCATQ.DLL
0x77000000 0xd4000 2001.12.4414.0700 C:\WINDOWS\system32\COMRes.dll
0x01730000 0x5c9000 7.00.5730.0013 C:\WINDOWS\system32\ieframe.dll
0x61410000 0x124000 7.00.5730.0013 C:\WINDOWS\system32\urlmon.dll
0x7e830000 0x36f000 7.00.5730.0013 C:\WINDOWS\system32\mshtml.dll
0x746c0000 0x29000 3.10.0349.0000 C:\WINDOWS\system32\msls31.dll
0x76ac0000 0x11000 3.05.2284.0001 C:\WINDOWS\system32\ATL.DLL
0x76010000 0x65000 6.02.3104.0000 C:\WINDOWS\system32\MSVCP60.dll
0x7d200000 0x2bc000 3.01.4001.5512 C:\WINDOWS\system32\msi.dll
0x10000000 0x12000 C:\Program Files\RocketDock\RocketDock.dll
0x74b30000 0x3b000 7.00.5730.0013 C:\WINDOWS\system32\webcheck.dll
0x030c0000 0x27000 1.00.0003.0021 C:\Program Files\IncrediMail\bin\B4ImApp.dll
0x69270000 0x8d000 5.02.2600.5512 C:\WINDOWS\system32\fxsst.dll
0x036f0000 0x72000 5.02.2600.5512 C:\WINDOWS\system32\FXSAPI.dll
0x76200000 0x77000 7.00.5730.0013 C:\WINDOWS\system32\mshtmled.dll
0x74730000 0x3d000 3.525.1132.0000 C:\WINDOWS\system32\ODBC32.dll
0x1f840000 0x18000 3.525.1117.0000 C:\WINDOWS\system32\odbcint.dll
0x736b0000 0x4b000 5.03.2600.5512 C:\WINDOWS\system32\ddraw.dll
0x022f0000 0x9000 2.00.0000.0004 C:\Program Files\TuneUp Utilities 2008\SDShelEx-win32.dll
0x2d480000 0xe000 8.05.0000.0001 C:\PROGRA~1\DAP\PRIVAC~1\DAPCTX~1.DLL
0x73d20000 0xfe000 6.02.4131.0000 C:\WINDOWS\system32\MFC42.DLL
0x61d70000 0xe000 6.00.8665.0000 C:\WINDOWS\system32\MFC42LOC.DLL
0x02300000 0x6000 C:\Program Files\Unlocker\UnlockerCOM.dll
0x02ab0000 0x13000 7.00.0000.0011 C:\Program Files\Avira\AntiVir PersonalEdition Classic\shlext.dll
0x7c250000 0x102000 7.10.3077.0000 C:\Program Files\Avira\AntiVir PersonalEdition Classic\MFC71U.DLL
0x042d0000 0x56000 7.10.3052.0004 C:\Program Files\Avira\AntiVir PersonalEdition Classic\MSVCR71.dll
0x7c3a0000 0x7b000 7.10.3077.0000 C:\Program Files\Avira\AntiVir PersonalEdition Classic\MSVCP71.dll
0x02ad0000 0x8000 1.00.0000.0000 C:\Program Files\Malwarebytes' Anti-Malware\mbamext.dll
------------------------------------------------------------------------------
explorer.exe pid: 2432
Command line: "C:\WINDOWS\explorer.exe" C:\Documents and Settings\pascale legendre\Bureau\DiagHelp
Base Size Version Path
0x77be0000 0x58000 7.00.2600.5512 C:\WINDOWS\system32\msvcrt.dll
0x779e0000 0x97000 5.131.2600.5512 C:\WINDOWS\system32\CRYPT32.dll
0x76610000 0x84000 5.131.2600.5512 C:\WINDOWS\system32\CRYPTUI.dll
0x771b0000 0xce000 7.00.5730.0013 C:\WINDOWS\system32\WININET.dll
0x00400000 0x9000 6.00.5441.0000 C:\WINDOWS\system32\Normaliz.dll
0x5dca0000 0x45000 7.00.5730.0013 C:\WINDOWS\system32\iertutil.dll
0x76be0000 0x2e000 5.131.2600.5512 C:\WINDOWS\system32\WINTRUST.dll
0x58b50000 0x9a000 5.82.2900.5512 C:\WINDOWS\system32\comctl32.dll
0x10000000 0x12000 C:\Program Files\RocketDock\RocketDock.dll
0x76f80000 0x7f000 2001.12.4414.0700 C:\WINDOWS\system32\CLBCATQ.DLL
0x77000000 0xd4000 2001.12.4414.0700 C:\WINDOWS\system32\COMRes.dll
0x01200000 0x5c9000 7.00.5730.0013 C:\WINDOWS\system32\ieframe.dll
0x61410000 0x124000 7.00.5730.0013 C:\WINDOWS\system32\urlmon.dll
0x01cf0000 0x27000 1.00.0003.0021 C:\Program Files\IncrediMail\bin\B4ImApp.dll
0x76ac0000 0x11000 3.05.2284.0001 C:\WINDOWS\system32\ATL.DLL
ListDLLs v2.25 - DLL lister for Win9x/NT
Copyright (C) 1997-2004 Mark Russinovich
Sysinternals - www.sysinternals.com
------------------------------------------------------------------------------
winlogon.exe pid: 720
Command line: winlogon.exe
Base Size Version Path
0x01000000 0x82000 \??\C:\WINDOWS\system32\winlogon.exe
0x77be0000 0x58000 7.00.2600.5512 C:\WINDOWS\system32\msvcrt.dll
0x779e0000 0x97000 5.131.2600.5512 C:\WINDOWS\system32\CRYPT32.dll
0x76be0000 0x2e000 5.131.2600.5512 C:\WINDOWS\system32\WINTRUST.dll
0x58b50000 0x9a000 5.82.2900.5512 C:\WINDOWS\system32\COMCTL32.dll
0x74730000 0x3d000 3.525.1132.0000 C:\WINDOWS\system32\ODBC32.dll
0x1f840000 0x18000 3.525.1117.0000 C:\WINDOWS\system32\odbcint.dll
0x77000000 0xd4000 2001.12.4414.0700 C:\WINDOWS\system32\COMRes.dll
0x76f80000 0x7f000 2001.12.4414.0700 C:\WINDOWS\system32\CLBCATQ.DLL
0x76010000 0x65000 6.02.3104.0000 C:\WINDOWS\system32\MSVCP60.dll
Le volume dans le lecteur C n'a pas de nom.
Le numéro de série du volume est CC9C-98B8
Répertoire de C:\WINDOWS\system32
14/04/2008 04:33 6 144 csrss.exe
1 fichier(s) 6 144 octets
0 Rép(s) 31 023 235 072 octets libres
Contenu de Downloaded Program Files
Le volume dans le lecteur C n'a pas de nom.
Le numéro de série du volume est CC9C-98B8
Répertoire de C:\WINDOWS\Downloaded Program Files
09/06/2008 01:46 <REP> .
09/06/2008 01:46 <REP> ..
27/02/2008 15:59 290 816 auc_lib.dll
07/12/2004 17:07 32 bdcore.dll
25/05/2006 01:21 118 784 bdupd.dll
27/02/2008 15:59 541 ca.pub
27/02/2008 15:59 495 616 daas_s.dll
08/06/2008 16:29 65 desktop.ini
11/04/2007 14:55 1 292 erma.inf
27/02/2008 16:00 262 144 fscax.dll
27/02/2008 15:59 614 fscax.inf
27/02/2008 15:59 588 392 gatelauncher.exe
19/05/2008 09:29 1 570 hardwaredetection.inf
30/06/2007 19:09 175 968 IEAWSDC.DLL
30/06/2007 18:46 452 ieawsdc.inf
25/05/2006 01:21 53 248 ipsupd.dll
08/08/2006 11:45 576 kavwebscan.inf
16/03/2005 12:34 7 407 lang.ini
07/12/2004 17:07 32 libfn.dll
13/02/2008 17:55 130 live.ini
29/10/2007 16:45 1 244 oscan8.inf
25/10/2007 16:54 471 040 oscan8.ocx
14/03/2005 14:58 7 073 scanoptions.tsi
19/03/2008 18:36 144 swdir.inf
29/04/2008 08:49 456 768 wlscBase.dll
29/04/2008 08:52 320 wlscBase.inf
30/07/2007 19:24 293 wuweb.inf
25 fichier(s) 2 934 561 octets
Total des fichiers listés :
25 fichier(s) 2 934 561 octets
2 Rép(s) 31 023 235 072 octets libres
Recherche de rootkit! (Merci S!Ri)
Recherche d'infections connues
Export des clefs sensibles..
Liste des fichiers en exception sur le pare-feu XP SP2
"%windir%\\system32\\sessmgr.exe"="%windir%\\system32\\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
"%windir%\\Network Diagnostic\\xpnetdiag.exe"="%windir%\\Network Diagnostic\\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000"
"C:\\Program Files\\Messenger\\msmsgs.exe"="C:\\Program Files\\Messenger\\msmsgs.exe:*:Enabled:Windows Messenger"
"C:\\Program Files\\IncrediMail\\bin\\ImApp.exe"="C:\\Program Files\\IncrediMail\\bin\\ImApp.exe:*:Enabled:IncrediMail"
"C:\\Program Files\\IncrediMail\\bin\\IncMail.exe"="C:\\Program Files\\IncrediMail\\bin\\IncMail.exe:*:Enabled:IncrediMail"
"C:\\Program Files\\IncrediMail\\bin\\ImpCnt.exe"="C:\\Program Files\\IncrediMail\\bin\\ImpCnt.exe:*:Enabled:IncrediMail"
"C:\\Program Files\\HP\\Digital Imaging\\bin\\hpqste08.exe"="C:\\Program Files\\HP\\Digital Imaging\\bin\\hpqste08.exe:*:Enabled:hpqste08.exe"
"C:\\Program Files\\HP\\Digital Imaging\\bin\\hpofxm08.exe"="C:\\Program Files\\HP\\Digital Imaging\\bin\\hpofxm08.exe:*:Enabled:hpofxm08.exe"
"C:\\Program Files\\HP\\Digital Imaging\\bin\\hposfx08.exe"="C:\\Program Files\\HP\\Digital Imaging\\bin\\hposfx08.exe:*:Enabled:hposfx08.exe"
"C:\\Program Files\\HP\\Digital Imaging\\bin\\hposid01.exe"="C:\\Program Files\\HP\\Digital Imaging\\bin\\hposid01.exe:*:Enabled:hposid01.exe"
"C:\\Program Files\\HP\\Digital Imaging\\bin\\hpqscnvw.exe"="C:\\Program Files\\HP\\Digital Imaging\\bin\\hpqscnvw.exe:*:Enabled:hpqscnvw.exe"
"C:\\Program Files\\HP\\Digital Imaging\\bin\\hpqkygrp.exe"="C:\\Program Files\\HP\\Digital Imaging\\bin\\hpqkygrp.exe:*:Enabled:hpqkygrp.exe"
"C:\\Program Files\\HP\\Digital Imaging\\bin\\hpqCopy.exe"="C:\\Program Files\\HP\\Digital Imaging\\bin\\hpqCopy.exe:*:Enabled:hpqcopy.exe"
"C:\\Program Files\\HP\\Digital Imaging\\bin\\hpfccopy.exe"="C:\\Program Files\\HP\\Digital Imaging\\bin\\hpfccopy.exe:*:Enabled:hpfccopy.exe"
"C:\\Program Files\\HP\\Digital Imaging\\bin\\hpzwiz01.exe"="C:\\Program Files\\HP\\Digital Imaging\\bin\\hpzwiz01.exe:*:Enabled:hpzwiz01.exe"
"C:\\Program Files\\HP\\Digital Imaging\\Unload\\HpqPhUnl.exe"="C:\\Program Files\\HP\\Digital Imaging\\Unload\\HpqPhUnl.exe:*:Enabled:hpqphunl.exe"
"C:\\Program Files\\HP\\Digital Imaging\\bin\\hpoews01.exe"="C:\\Program Files\\HP\\Digital Imaging\\bin\\hpoews01.exe:*:Enabled:hpoews01.exe"
"C:\\Program Files\\Bonjour\\mDNSResponder.exe"="C:\\Program Files\\Bonjour\\mDNSResponder.exe:*:Enabled:Bonjour"
"C:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"="C:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe:*:Enabled:Windows Live Messenger"
"%windir%\\system32\\sessmgr.exe"="%windir%\\system32\\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
"%windir%\\Network Diagnostic\\xpnetdiag.exe"="%windir%\\Network Diagnostic\\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000"
"C:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"="C:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe:*:Enabled:Windows Live Messenger"
Export de la clef SharedTaskScheduler
[SharedTaskScheduler]
"{438755C2-A8BA-11D1-B96B-00A0C90312E1}"="Pré-chargeur Browseui"
"{8C7461EF-2B13-11d2-BE35-3078302C2030}"="Démon de cache des catégories de composant"
REGEDIT4
[taskmgr.exe]
exports des policies
REGEDIT4
[system]
"dontdisplaylastusername"=dword:00000000
"legalnoticecaption"=""
"legalnoticetext"=""
"shutdownwithoutlogon"=dword:00000001
"undockwithoutlogon"=dword:00000001
Export des clefs sensibles..
Rechercher adresses sensibles dans le fichier HOSTS...
127.0.0.1 www.activexupdate.com
127.0.0.1 activexupdate.com
127.0.0.1 www.antispywareupdates.net
127.0.0.1 antispywareupdates.net
127.0.0.1 www.avpcheckupdate.com
127.0.0.1 avpcheckupdate.com
127.0.0.1 client.exeupdate.com
127.0.0.1 www.eupdatepage.com
127.0.0.1 eupdatepage.com
127.0.0.1 www.exeupdate.com
127.0.0.1 exeupdate.com
127.0.0.1 www.hotwinupdates.com
127.0.0.1 hotwinupdates.com
127.0.0.1 www.lavasoftupdate.com
127.0.0.1 lavasoftupdate.com
127.0.0.1 www.malwarewipeupdate.com
127.0.0.1 malwarewipeupdate.com
127.0.0.1 www.msupdate.net
127.0.0.1 msupdate.net
127.0.0.1 www.msupdater.net
127.0.0.1 msupdater.net
127.0.0.1 www.necessaryupdates.com
127.0.0.1 necessaryupdates.com
127.0.0.1 newupdates.lzio.com
127.0.0.1 redirect.msupdate.net
127.0.0.1 search.keyword.exeupdate.com
127.0.0.1 www.securityupdatesite.com
127.0.0.1 securityupdatesite.com
127.0.0.1 settings.updatemysettings.com
127.0.0.1 www.spyaxeupdate.com
127.0.0.1 spyaxeupdate.com
127.0.0.1 www.spyfalconupdate.com
127.0.0.1 spyfalconupdate.com
127.0.0.1 www.systemupdates.net
127.0.0.1 systemupdates.net
127.0.0.1 trial.updates.winsoftware.com
127.0.0.1 update.680180.net
127.0.0.1 update.shareaza.com
127.0.0.1 www.updatemysettings.com
127.0.0.1 updatemysettings.com
127.0.0.1 updates.spywarequake.com
127.0.0.1 www.urgentsystemupdate.biz
127.0.0.1 urgentsystemupdate.biz
127.0.0.1 www.urgentsystemupdate.com
127.0.0.1 urgentsystemupdate.com
127.0.0.1 windupdates.com
127.0.0.1 www.pandaantivirus-2007.com
127.0.0.1 pandaantivirus-2007.com
127.0.0.1 www.pandadownload-now.com
127.0.0.1 pandadownload-now.com
127.0.0.1 www.panda-hq.com
127.0.0.1 panda-hq.com
catchme 0.3.1351 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-06-09 16:53:50
Windows 5.1.2600 Service Pack 3 NTFS
scanning hidden services & system hive ...
scanning hidden registry entries ...
scanning hidden files ...
scan completed successfully
hidden services: 0
hidden files: 0
KProcCheck Version 0.2-beta1 Proof-of-Concept by SIG^2 (www.security.org.sg)
Process list by traversal of KiWaitListHead
4 - System
256 - ImApp.exe
376 - avguard.exe
388 - dllhost.exe
572 - HPZipm12.exe
696 - csrss.exe
720 - winlogon.exe
764 - services.exe
776 - lsass.exe
836 - usnsvc.exe
948 - svchost.exe
996 - GoogleToolbarNo
1052 - svchost.exe
1092 - svchost.exe
1184 - svchost.exe
1632 - SynTPLpr.exe
1644 - avgnt.exe
1724 - RocketDock.exe
1816 - explorer.exe
2432 - explorer.exe
2748 - MSNmsgr.exe
3040 - ctfmon.exe
3480 - DAP.exe
3676 - cmd.exe
Total number of processes = 24
NOTE: Under WinXP, this will not show all processes.
KProcCheck Version 0.2-beta1 Proof-of-Concept by SIG^2 (www.security.org.sg)
Driver/Module list by traversal of PsLoadedModuleList
804D7000 - \WINDOWS\system32\ntoskrnl.exe
806EE000 - \WINDOWS\system32\hal.dll
F7D2D000 - \WINDOWS\system32\KDCOM.DLL
F7C3D000 - \WINDOWS\system32\BOOTVID.dll
F77DD000 - ACPI.sys
F7D2F000 - \WINDOWS\System32\DRIVERS\WMILIB.SYS
F77CC000 - pci.sys
F782D000 - isapnp.sys
F7C41000 - compbatt.sys
F7C45000 - \WINDOWS\System32\DRIVERS\BATTC.SYS
F7DF5000 - pciide.sys
F7AAD000 - \WINDOWS\System32\DRIVERS\PCIIDEX.SYS
F7D31000 - intelide.sys
F77AE000 - pcmcia.sys
F783D000 - MountMgr.sys
F778F000 - ftdisk.sys
F7D33000 - dmload.sys
F7769000 - dmio.sys
F7C49000 - ACPIEC.sys
F7DF6000 - \WINDOWS\System32\DRIVERS\OPRGHDLR.SYS
F7AB5000 - PartMgr.sys
F784D000 - VolSnap.sys
F7751000 - atapi.sys
F785D000 - disk.sys
F786D000 - \WINDOWS\System32\DRIVERS\CLASSPNP.SYS
F7731000 - fltmgr.sys
F771F000 - sr.sys
F7708000 - KSecDD.sys
F767B000 - Ntfs.sys
F764E000 - NDIS.sys
F7634000 - Mup.sys
F787D000 - agp440.sys
F78AD000 - \SystemRoot\System32\DRIVERS\intelppm.sys
F7536000 - \SystemRoot\System32\DRIVERS\ati2mtag.sys
F7522000 - \SystemRoot\System32\DRIVERS\VIDEOPRT.SYS
F7ADD000 - \SystemRoot\System32\DRIVERS\usbuhci.sys
F74FE000 - \SystemRoot\System32\DRIVERS\USBPORT.SYS
F7AE5000 - \SystemRoot\System32\DRIVERS\usbehci.sys
F72A1000 - \SystemRoot\System32\DRIVERS\w70n51.sys
F7D3B000 - \SystemRoot\system32\drivers\MbxStby.sys
F7274000 - \SystemRoot\system32\drivers\o2mmb.sys
F7263000 - \SystemRoot\System32\DRIVERS\serial.sys
F7CE5000 - \SystemRoot\System32\DRIVERS\serenum.sys
F78BD000 - \SystemRoot\System32\DRIVERS\smcirda.sys
F7CE9000 - \SystemRoot\System32\DRIVERS\irenum.sys
F7227000 - \SystemRoot\System32\DRIVERS\parport.sys
F78CD000 - \SystemRoot\System32\DRIVERS\i8042prt.sys
F7B0D000 - \SystemRoot\System32\DRIVERS\kbdclass.sys
F71E5000 - \SystemRoot\System32\DRIVERS\SynTP.sys
F7D41000 - \SystemRoot\System32\DRIVERS\USBD.SYS
F7B1D000 - \SystemRoot\System32\DRIVERS\mouclass.sys
F78DD000 - \SystemRoot\System32\DRIVERS\imapi.sys
F78ED000 - \SystemRoot\System32\DRIVERS\cdrom.sys
F78FD000 - \SystemRoot\System32\DRIVERS\redbook.sys
F71C2000 - \SystemRoot\System32\DRIVERS\ks.sys
F7134000 - \SystemRoot\system32\drivers\smwdm.sys
F7110000 - \SystemRoot\system32\drivers\portcls.sys
F791D000 - \SystemRoot\system32\drivers\drmk.sys
F70F8000 - \SystemRoot\system32\drivers\aeaudio.sys
F7D0D000 - \SystemRoot\System32\DRIVERS\CmBatt.sys
F7D15000 - \SystemRoot\System32\DRIVERS\wmiacpi.sys
F7EB2000 - \SystemRoot\System32\DRIVERS\audstub.sys
F7B3D000 - \SystemRoot\System32\DRIVERS\rasirda.sys
F7B4D000 - \SystemRoot\System32\DRIVERS\TDI.SYS
F797D000 - \SystemRoot\System32\DRIVERS\rasl2tp.sys
F7D21000 - \SystemRoot\System32\DRIVERS\ndistapi.sys
F70E1000 - \SystemRoot\System32\DRIVERS\ndiswan.sys
F798D000 - \SystemRoot\System32\DRIVERS\raspppoe.sys
F799D000 - \SystemRoot\System32\DRIVERS\raspptp.sys
F70D0000 - \SystemRoot\System32\DRIVERS\psched.sys
F79AD000 - \SystemRoot\System32\DRIVERS\msgpc.sys
F7B6D000 - \SystemRoot\System32\DRIVERS\ptilink.sys
F7B7D000 - \SystemRoot\System32\DRIVERS\raspti.sys
F70A0000 - \SystemRoot\System32\DRIVERS\rdpdr.sys
F79BD000 - \SystemRoot\System32\DRIVERS\termdd.sys
F7D47000 - \SystemRoot\System32\DRIVERS\swenum.sys
F701A000 - \SystemRoot\System32\DRIVERS\update.sys
F75FC000 - \SystemRoot\System32\DRIVERS\mssmbios.sys
F79CD000 - \SystemRoot\System32\Drivers\NDProxy.SYS
F79FD000 - \SystemRoot\System32\DRIVERS\usbhub.sys
F7D4D000 - \SystemRoot\System32\Drivers\Fs_Rec.SYS
F7EEC000 - \SystemRoot\System32\Drivers\Null.SYS
F7D51000 - \SystemRoot\System32\Drivers\Beep.SYS
F7BB5000 - \SystemRoot\System32\drivers\vga.sys
F7D55000 - \SystemRoot\System32\Drivers\mnmdd.SYS
F7D59000 - \SystemRoot\System32\DRIVERS\RDPCDD.sys
F7BC5000 - \SystemRoot\System32\Drivers\Msfs.SYS
F7BD5000 - \SystemRoot\System32\Drivers\Npfs.SYS
F7CE1000 - \SystemRoot\System32\DRIVERS\rasacd.sys
AAFCD000 - \SystemRoot\System32\DRIVERS\ipsec.sys
AAF74000 - \SystemRoot\System32\DRIVERS\tcpip.sys
AAF4C000 - \SystemRoot\System32\DRIVERS\netbt.sys
F7A2D000 - \SystemRoot\System32\DRIVERS\wanarp.sys
AAF2A000 - \SystemRoot\System32\drivers\afd.sys
F7A3D000 - \SystemRoot\System32\DRIVERS\netbios.sys
F7BE5000 - \SystemRoot\system32\DRIVERS\ssmdrv.sys
AAEFF000 - \SystemRoot\System32\DRIVERS\rdbss.sys
AAE8F000 - \SystemRoot\System32\DRIVERS\mrxsmb.sys
F7A5D000 - \SystemRoot\System32\Drivers\Fips.SYS
F7D61000 - \??\C:\WINDOWS\System32\drivers\EABFiltr.sys
F7A6D000 - \SystemRoot\System32\Drivers\ClntMgmt.sys
AADA3000 - \SystemRoot\system32\DRIVERS\avipbb.sys
F7D69000 - \??\C:\Program Files\Avira\AntiVir PersonalEdition Classic\avgio.sys
F7C15000 - \SystemRoot\System32\DRIVERS\USBSTOR.SYS
F7C35000 - \SystemRoot\System32\DRIVERS\usbccgp.sys
F6FFA000 - \SystemRoot\system32\DRIVERS\LVUSBSta.sys
AAD4E000 - \SystemRoot\system32\DRIVERS\snpstd2.sys
F6FEA000 - \SystemRoot\system32\DRIVERS\STREAM.SYS
F6FDA000 - \SystemRoot\system32\drivers\usbaudio.sys
F6FCA000 - \SystemRoot\System32\Drivers\Cdfs.SYS
BF800000 - \SystemRoot\System32\win32k.sys
F6F6A000 - \SystemRoot\System32\drivers\Dxapi.sys
F7B15000 - \SystemRoot\System32\watchdog.sys
BF9C3000 - \SystemRoot\System32\drivers\dxg.sys
F7E5F000 - \SystemRoot\System32\drivers\dxgthk.sys
BF9D5000 - \SystemRoot\System32\ati2dvag.dll
BFA35000 - \SystemRoot\System32\ati3duag.dll
AAB08000 - \SystemRoot\System32\DRIVERS\irda.sys
AAC22000 - \SystemRoot\System32\DRIVERS\ndisuio.sys
AA84B000 - \SystemRoot\system32\drivers\wdmaud.sys
F792D000 - \SystemRoot\system32\drivers\sysaudio.sys
F7B95000 - \??\C:\WINDOWS\System32\drivers\cpqdfw.sys
AA9CC000 - \??\C:\WINDOWS\System32\drivers\cqcpu.sys
F7D6F000 - \??\C:\WINDOWS\System32\drivers\cq_mem.sys
F7D73000 - \SystemRoot\System32\Drivers\ParVdm.SYS
AA550000 - \??\C:\Program Files\Avira\AntiVir PersonalEdition Classic\avgntflt.sys
AA436000 - \SystemRoot\System32\DRIVERS\srv.sys
F7AF5000 - \SystemRoot\System32\DRIVERS\usbprint.sys
F7DDB000 - \SystemRoot\system32\drivers\MSPQM.sys
F7D97000 - \SystemRoot\system32\drivers\MSPCLOCK.sys
A9443000 - \SystemRoot\system32\drivers\kmixer.sys
F7F7B000 - \SystemRoot\System32\DRIVERS\KProcCheck.sys
Total number of drivers = 132
Liste des programmes installes
Adobe Flash Player ActiveX
Agent d'activation Diagnostics à distance
Agent Insight Management
Apple Software Update
Assistant de connexion Windows Live
ATI - Utilitaire de désinstallation du logiciel
ATI Control Panel
ATI Display Driver
Avira antivir Personal – Free Antivirus
Broadcom Gigabit Integrated Controller
Broadcom Gigabit Integrated Controller
Calendrier Xtra v9.006
CCleaner (remove only)
CP_Package_Variety1
CP_Package_Variety2
CP_Package_Variety3
Diagnostics pour Windows
Download Accelerator Plus (DAP)
ERUNT 1.1j
EVEREST Ultimate Edition v4.50
Foxit Reader
Google Toolbar for Internet Explorer
HijackThis 2.0.2
hp deskjet 825c series (Supprimer uniquement)
HP Image Zone Express
HP Integrated Wireless LAN W400-W500 Driver
IncrediMail Xe
InterVideo WinDVD
Java 2 Runtime Environment, SE v1.4.2
Java(TM) 6 Update 6
Malwarebytes' Anti-Malware
Microsoft .NET Framework 2.0
Microsoft .NET Framework 2.0
Microsoft Internationalized Domain Names Mitigation APIs
Microsoft National Language Support Downlevel APIs
Microsoft Office 2000 CD-ROM 2
Microsoft Office 2000 Premium
O2Micro MemoryCardBus Windows Driver
O2Micro MemoryCardBus Windows Driver
O2Micro SmartCardBus Reader Windows Driver Installer
ooVoo
Photo To Sketch 3.51
Quick Launch Buttons 4.10 D1
Remote Services Driver
RocketDock 1.3.1
SendMe 1.0.2
SIW version 2008-06-04
Sons Microsoft Office
SoundMAX
Spybot - Search & Destroy
Synaptics Pointing Device Driver
TuneUp Utilities 2008
Unlocker 1.8.7
VideoLAN VLC media player 0.8.6f
WebFldrs XP
Windows Internet Explorer 7
Windows Live installer
Windows Live Messenger
Windows Live OneCare safety scanner
Le vo