swifer67
Inscrit le: 16 Avr 2007 Messages: 14
|
Posté le: Sam Fév 16, 2008 5:23 pm Sujet du message: - : Fenêtres pubs intempestives |
|
|
Navilog :
catchme 0.3.1319 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-02-16 16:19:39
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden services & system hive ...
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04]
"h0"=dword:00000000
"ujdew"=hex:30,77,ae,91,39,7b,b7,91,75,1f,11,44,4e,89,4f,c7,fe,f6,62,44,3c,..
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4]
"h0"=dword:00000001
"khjeh"=hex:51,e6,6f,c3,c9,40,49,a8,3c,e5,b1,95,d0,bc,86,c6,dc,75,3a,8d,55,..
"p0"="C:\Program Files\DAEMON Tools\"
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001]
"a0"=hex:20,01,00,00,32,f2,17,51,8b,df,00,39,86,9d,de,a9,32,7d,ea,a0,84,..
"khjeh"=hex:d0,62,32,49,3d,d0,87,d7,76,6b,9e,99,22,e9,54,7a,cf,65,0b,24,ed,..
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001\0Jf40]
"khjeh"=hex:41,8e,f3,c6,12,89,de,12,fc,90,6a,95,3f,e8,bd,51,c6,99,4e,32,d6,..
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04]
"h0"=dword:00000000
"ujdew"=hex:30,77,ae,91,39,7b,b7,91,75,1f,11,44,4e,89,4f,c7,fe,f6,62,44,3c,..
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4]
"h0"=dword:00000001
"khjeh"=hex:51,e6,6f,c3,c9,40,49,a8,3c,e5,b1,95,d0,bc,86,c6,dc,75,3a,8d,55,..
"p0"="C:\Program Files\DAEMON Tools\"
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001]
"a0"=hex:20,01,00,00,32,f2,17,51,8b,df,00,39,86,9d,de,a9,32,7d,ea,a0,84,..
"khjeh"=hex:d0,62,32,49,3d,d0,87,d7,76,6b,9e,99,22,e9,54,7a,cf,65,0b,24,ed,..
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001\0Jf40]
"khjeh"=hex:41,8e,f3,c6,12,89,de,12,fc,90,6a,95,3f,e8,bd,51,c6,99,4e,32,d6,..
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet003\Services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04]
"h0"=dword:00000000
"ujdew"=hex:30,77,ae,91,39,7b,b7,91,75,1f,11,44,4e,89,4f,c7,fe,f6,62,44,3c,..
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet003\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4]
"h0"=dword:00000001
"khjeh"=hex:51,e6,6f,c3,c9,40,49,a8,3c,e5,b1,95,d0,bc,86,c6,dc,75,3a,8d,55,..
"p0"="C:\Program Files\DAEMON Tools\"
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet003\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001]
"a0"=hex:20,01,00,00,32,f2,17,51,8b,df,00,39,86,9d,de,a9,32,7d,ea,a0,84,..
"khjeh"=hex:d0,62,32,49,3d,d0,87,d7,76,6b,9e,99,22,e9,54,7a,cf,65,0b,24,ed,..
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet003\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001\0Jf40]
"khjeh"=hex:78,2a,c0,d5,e7,f1,c7,ea,f2,de,1b,f6,5f,27,74,c7,94,19,ba,46,89,..
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet004\Services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04]
"h0"=dword:00000000
"ujdew"=hex:30,77,ae,91,39,7b,b7,91,75,1f,11,44,4e,89,4f,c7,fe,f6,62,44,3c,..
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet004\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4]
"h0"=dword:00000001
"khjeh"=hex:51,e6,6f,c3,c9,40,49,a8,3c,e5,b1,95,d0,bc,86,c6,dc,75,3a,8d,55,..
"p0"="C:\Program Files\DAEMON Tools\"
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet004\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001]
"a0"=hex:20,01,00,00,32,f2,17,51,8b,df,00,39,86,9d,de,a9,32,7d,ea,a0,84,..
"khjeh"=hex:d0,62,32,49,3d,d0,87,d7,76,6b,9e,99,22,e9,54,7a,cf,65,0b,24,ed,..
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet004\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001\0Jf40]
"khjeh"=hex:78,2a,c0,d5,e7,f1,c7,ea,f2,de,1b,f6,5f,27,74,c7,94,19,ba,46,89,..
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet005\Services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04]
"h0"=dword:00000000
"ujdew"=hex:30,77,ae,91,39,7b,b7,91,75,1f,11,44,4e,89,4f,c7,fe,f6,62,44,3c,..
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet005\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4]
"h0"=dword:00000001
"khjeh"=hex:51,e6,6f,c3,c9,40,49,a8,3c,e5,b1,95,d0,bc,86,c6,dc,75,3a,8d,55,..
"p0"="C:\Program Files\DAEMON Tools\"
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet005\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001]
"a0"=hex:20,01,00,00,32,f2,17,51,8b,df,00,39,86,9d,de,a9,32,7d,ea,a0,84,..
"khjeh"=hex:d0,62,32,49,3d,d0,87,d7,76,6b,9e,99,22,e9,54,7a,cf,65,0b,24,ed,..
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet005\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001\0Jf40]
"khjeh"=hex:78,2a,c0,d5,e7,f1,c7,ea,f2,de,1b,f6,5f,27,74,c7,94,19,ba,46,89,..
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet006\Services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04]
"h0"=dword:00000000
"ujdew"=hex:30,77,ae,91,39,7b,b7,91,75,1f,11,44,4e,89,4f,c7,fe,f6,62,44,3c,..
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet006\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4]
"h0"=dword:00000001
"khjeh"=hex:51,e6,6f,c3,c9,40,49,a8,3c,e5,b1,95,d0,bc,86,c6,dc,75,3a,8d,55,..
"p0"="C:\Program Files\DAEMON Tools\"
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet006\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001]
"a0"=hex:20,01,00,00,32,f2,17,51,8b,df,00,39,86,9d,de,a9,32,7d,ea,a0,84,..
"khjeh"=hex:d0,62,32,49,3d,d0,87,d7,76,6b,9e,99,22,e9,54,7a,cf,65,0b,24,ed,..
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet006\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001\0Jf40]
"khjeh"=hex:78,2a,c0,d5,e7,f1,c7,ea,f2,de,1b,f6,5f,27,74,c7,94,19,ba,46,89,..
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet007\Services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04]
"h0"=dword:00000000
"ujdew"=hex:30,77,ae,91,39,7b,b7,91,75,1f,11,44,4e,89,4f,c7,fe,f6,62,44,3c,..
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet007\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4]
"h0"=dword:00000001
"khjeh"=hex:51,e6,6f,c3,c9,40,49,a8,3c,e5,b1,95,d0,bc,86,c6,dc,75,3a,8d,55,..
"p0"="C:\Program Files\DAEMON Tools\"
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet007\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001]
"a0"=hex:20,01,00,00,32,f2,17,51,8b,df,00,39,86,9d,de,a9,32,7d,ea,a0,84,..
"khjeh"=hex:d0,62,32,49,3d,d0,87,d7,76,6b,9e,99,22,e9,54,7a,cf,65,0b,24,ed,..
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet007\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001\0Jf40]
"khjeh"=hex:78,2a,c0,d5,e7,f1,c7,ea,f2,de,1b,f6,5f,27,74,c7,94,19,ba,46,89,..
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet008\Services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04]
"h0"=dword:00000000
"ujdew"=hex:30,77,ae,91,39,7b,b7,91,75,1f,11,44,4e,89,4f,c7,fe,f6,62,44,3c,..
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet008\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4]
"h0"=dword:00000001
"khjeh"=hex:51,e6,6f,c3,c9,40,49,a8,3c,e5,b1,95,d0,bc,86,c6,dc,75,3a,8d,55,..
"p0"="C:\Program Files\DAEMON Tools\"
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet008\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001]
"a0"=hex:20,01,00,00,32,f2,17,51,8b,df,00,39,86,9d,de,a9,32,7d,ea,a0,84,..
"khjeh"=hex:d0,62,32,49,3d,d0,87,d7,76,6b,9e,99,22,e9,54,7a,cf,65,0b,24,ed,..
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet008\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001\0Jf40]
"khjeh"=hex:78,2a,c0,d5,e7,f1,c7,ea,f2,de,1b,f6,5f,27,74,c7,94,19,ba,46,89,..
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet009\Services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04]
"h0"=dword:00000000
"ujdew"=hex:30,77,ae,91,39,7b,b7,91,75,1f,11,44,4e,89,4f,c7,fe,f6,62,44,3c,..
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet009\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4]
"h0"=dword:00000001
"khjeh"=hex:51,e6,6f,c3,c9,40,49,a8,3c,e5,b1,95,d0,bc,86,c6,dc,75,3a,8d,55,..
"p0"="C:\Program Files\DAEMON Tools\"
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet009\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001]
"a0"=hex:20,01,00,00,32,f2,17,51,8b,df,00,39,86,9d,de,a9,32,7d,ea,a0,84,..
"khjeh"=hex:d0,62,32,49,3d,d0,87,d7,76,6b,9e,99,22,e9,54,7a,cf,65,0b,24,ed,..
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet009\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001\0Jf40]
"khjeh"=hex:78,2a,c0,d5,e7,f1,c7,ea,f2,de,1b,f6,5f,27,74,c7,94,19,ba,46,89,..
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet010\Services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04]
"h0"=dword:00000000
"ujdew"=hex:30,77,ae,91,39,7b,b7,91,75,1f,11,44,4e,89,4f,c7,fe,f6,62,44,3c,..
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet010\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4]
"h0"=dword:00000001
"khjeh"=hex:51,e6,6f,c3,c9,40,49,a8,3c,e5,b1,95,d0,bc,86,c6,dc,75,3a,8d,55,..
"p0"="C:\Program Files\DAEMON Tools\"
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet010\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001]
"a0"=hex:20,01,00,00,32,f2,17,51,8b,df,00,39,86,9d,de,a9,32,7d,ea,a0,84,..
"khjeh"=hex:d0,62,32,49,3d,d0,87,d7,76,6b,9e,99,22,e9,54,7a,cf,65,0b,24,ed,..
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet010\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001\0Jf40]
"khjeh"=hex:78,2a,c0,d5,e7,f1,c7,ea,f2,de,1b,f6,5f,27,74,c7,94,19,ba,46,89,..
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet011\Services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04]
"h0"=dword:00000000
"ujdew"=hex:30,77,ae,91,39,7b,b7,91,75,1f,11,44,4e,89,4f,c7,fe,f6,62,44,3c,..
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet011\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4]
"h0"=dword:00000001
"khjeh"=hex:51,e6,6f,c3,c9,40,49,a8,3c,e5,b1,95,d0,bc,86,c6,dc,75,3a,8d,55,..
"p0"="C:\Program Files\DAEMON Tools\"
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet011\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001]
"a0"=hex:20,01,00,00,32,f2,17,51,8b,df,00,39,86,9d,de,a9,32,7d,ea,a0,84,..
"khjeh"=hex:d0,62,32,49,3d,d0,87,d7,76,6b,9e,99,22,e9,54,7a,cf,65,0b,24,ed,..
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet011\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001\0Jf40]
"khjeh"=hex:78,2a,c0,d5,e7,f1,c7,ea,f2,de,1b,f6,5f,27,74,c7,94,19,ba,46,89,..
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet012\Services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04]
"h0"=dword:00000000
"ujdew"=hex:30,77,ae,91,39,7b,b7,91,75,1f,11,44,4e,89,4f,c7,fe,f6,62,44,3c,..
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet012\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4]
"h0"=dword:00000001
"khjeh"=hex:51,e6,6f,c3,c9,40,49,a8,3c,e5,b1,95,d0,bc,86,c6,dc,75,3a,8d,55,..
"p0"="C:\Program Files\DAEMON Tools\"
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet012\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001]
"a0"=hex:20,01,00,00,32,f2,17,51,8b,df,00,39,86,9d,de,a9,32,7d,ea,a0,84,..
"khjeh"=hex:d0,62,32,49,3d,d0,87,d7,76,6b,9e,99,22,e9,54,7a,cf,65,0b,24,ed,..
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet012\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001\0Jf40]
"khjeh"=hex:78,2a,c0,d5,e7,f1,c7,ea,f2,de,1b,f6,5f,27,74,c7,94,19,ba,46,89,..
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet013\Services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04]
"h0"=dword:00000000
"ujdew"=hex:30,77,ae,91,39,7b,b7,91,75,1f,11,44,4e,89,4f,c7,fe,f6,62,44,3c,..
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet013\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4]
"h0"=dword:00000001
"khjeh"=hex:51,e6,6f,c3,c9,40,49,a8,3c,e5,b1,95,d0,bc,86,c6,dc,75,3a,8d,55,..
"p0"="C:\Program Files\DAEMON Tools\"
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet013\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001]
"a0"=hex:20,01,00,00,32,f2,17,51,8b,df,00,39,86,9d,de,a9,32,7d,ea,a0,84,..
"khjeh"=hex:d0,62,32,49,3d,d0,87,d7,76,6b,9e,99,22,e9,54,7a,cf,65,0b,24,ed,..
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet013\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001\0Jf40]
"khjeh"=hex:78,2a,c0,d5,e7,f1,c7,ea,f2,de,1b,f6,5f,27,74,c7,94,19,ba,46,89,..
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet014\Services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04]
"h0"=dword:00000000
"ujdew"=hex:30,77,ae,91,39,7b,b7,91,75,1f,11,44,4e,89,4f,c7,fe,f6,62,44,3c,..
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet014\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4]
"h0"=dword:00000001
"khjeh"=hex:51,e6,6f,c3,c9,40,49,a8,3c,e5,b1,95,d0,bc,86,c6,dc,75,3a,8d,55,..
"p0"="C:\Program Files\DAEMON Tools\"
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet014\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001]
"a0"=hex:20,01,00,00,32,f2,17,51,8b,df,00,39,86,9d,de,a9,32,7d,ea,a0,84,..
"khjeh"=hex:d0,62,32,49,3d,d0,87,d7,76,6b,9e,99,22,e9,54,7a,cf,65,0b,24,ed,..
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet014\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001\0Jf40]
"khjeh"=hex:78,2a,c0,d5,e7,f1,c7,ea,f2,de,1b,f6,5f,27,74,c7,94,19,ba,46,89,..
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet015\Services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04]
"h0"=dword:00000000
"ujdew"=hex:30,77,ae,91,39,7b,b7,91,75,1f,11,44,4e,89,4f,c7,fe,f6,62,44,3c,..
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet015\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4]
"h0"=dword:00000001
"khjeh"=hex:51,e6,6f,c3,c9,40,49,a8,3c,e5,b1,95,d0,bc,86,c6,dc,75,3a,8d,55,..
"p0"="C:\Program Files\DAEMON Tools\"
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet015\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001]
"a0"=hex:20,01,00,00,32,f2,17,51,8b,df,00,39,86,9d,de,a9,32,7d,ea,a0,84,..
"khjeh"=hex:d0,62,32,49,3d,d0,87,d7,76,6b,9e,99,22,e9,54,7a,cf,65,0b,24,ed,..
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet015\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001\0Jf40]
"khjeh"=hex:78,2a,c0,d5,e7,f1,c7,ea,f2,de,1b,f6,5f,27,74,c7,94,19,ba,46,89,..
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet016\Services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04]
"h0"=dword:00000000
"ujdew"=hex:30,77,ae,91,39,7b,b7,91,75,1f,11,44,4e,89,4f,c7,fe,f6,62,44,3c,..
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet016\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4]
"h0"=dword:00000001
"khjeh"=hex:51,e6,6f,c3,c9,40,49,a8,3c,e5,b1,95,d0,bc,86,c6,dc,75,3a,8d,55,..
"p0"="C:\Program Files\DAEMON Tools\"
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet016\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001]
"a0"=hex:20,01,00,00,32,f2,17,51,8b,df,00,39,86,9d,de,a9,32,7d,ea,a0,84,..
"khjeh"=hex:d0,62,32,49,3d,d0,87,d7,76,6b,9e,99,22,e9,54,7a,cf,65,0b,24,ed,..
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet016\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001\0Jf40]
"khjeh"=hex:78,2a,c0,d5,e7,f1,c7,ea,f2,de,1b,f6,5f,27,74,c7,94,19,ba,46,89,..
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet017\Services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04]
"h0"=dword:00000000
"ujdew"=hex:30,77,ae,91,39,7b,b7,91,75,1f,11,44,4e,89,4f,c7,fe,f6,62,44,3c,..
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet017\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4]
"h0"=dword:00000001
"khjeh"=hex:51,e6,6f,c3,c9,40,49,a8,3c,e5,b1,95,d0,bc,86,c6,dc,75,3a,8d,55,..
"p0"="C:\Program Files\DAEMON Tools\"
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet017\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001]
"a0"=hex:20,01,00,00,32,f2,17,51,8b,df,00,39,86,9d,de,a9,32,7d,ea,a0,84,..
"khjeh"=hex:d0,62,32,49,3d,d0,87,d7,76,6b,9e,99,22,e9,54,7a,cf,65,0b,24,ed,..
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet017\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001\0Jf40]
"khjeh"=hex:78,2a,c0,d5,e7,f1,c7,ea,f2,de,1b,f6,5f,27,74,c7,94,19,ba,46,89,..
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet018\Services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04]
"h0"=dword:00000000
"ujdew"=hex:30,77,ae,91,39,7b,b7,91,75,1f,11,44,4e,89,4f,c7,fe,f6,62,44,3c,..
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet018\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4]
"h0"=dword:00000001
"khjeh"=hex:51,e6,6f,c3,c9,40,49,a8,3c,e5,b1,95,d0,bc,86,c6,dc,75,3a,8d,55,..
"p0"="C:\Program Files\DAEMON Tools\"
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet018\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001]
"a0"=hex:20,01,00,00,32,f2,17,51,8b,df,00,39,86,9d,de,a9,32,7d,ea,a0,84,..
"khjeh"=hex:d0,62,32,49,3d,d0,87,d7,76,6b,9e,99,22,e9,54,7a,cf,65,0b,24,ed,..
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet018\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001\0Jf40]
"khjeh"=hex:78,2a,c0,d5,e7,f1,c7,ea,f2,de,1b,f6,5f,27,74,c7,94,19,ba,46,89,..
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet019\Services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04]
"h0"=dword:00000000
"ujdew"=hex:30,77,ae,91,39,7b,b7,91,75,1f,11,44,4e,89,4f,c7,fe,f6,62,44,3c,..
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet019\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4]
"h0"=dword:00000001
"khjeh"=hex:51,e6,6f,c3,c9,40,49,a8,3c,e5,b1,95,d0,bc,86,c6,dc,75,3a,8d,55,..
"p0"="C:\Program Files\DAEMON Tools\"
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet019\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001]
"a0"=hex:20,01,00,00,32,f2,17,51,8b,df,00,39,86,9d,de,a9,32,7d,ea,a0,84,..
"khjeh"=hex:d0,62,32,49,3d,d0,87,d7,76,6b,9e,99,22,e9,54,7a,cf,65,0b,24,ed,..
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet019\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001\0Jf40]
"khjeh"=hex:78,2a,c0,d5,e7,f1,c7,ea,f2,de,1b,f6,5f,27,74,c7,94,19,ba,46,89,..
IPC error: 2 Le fichier spécifié est introuvable.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\sptd\Cfg]
"s1"=dword:2df9c43f
"s2"=dword:110480d0
"h0"=dword:00000002
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04]
"h0"=dword:00000000
"ujdew"=hex:30,77,ae,91,39,7b,b7,91,75,1f,11,44,4e,89,4f,c7,fe,f6,62,44,3c,..
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4]
"h0"=dword:00000001
"khjeh"=hex:51,e6,6f,c3,c9,40,49,a8,3c,e5,b1,95,d0,bc,86,c6,dc,75,3a,8d,55,..
"p0"="C:\Program Files\DAEMON Tools\"
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001]
"a0"=hex:20,01,00,00,32,f2,17,51,8b,df,00,39,86,9d,de,a9,32,7d,ea,a0,84,..
"khjeh"=hex:d0,62,32,49,3d,d0,87,d7,76,6b,9e,99,22,e9,54,7a,cf,65,0b,24,ed,..
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001\0Jf40]
"khjeh"=hex:78,2a,c0,d5,e7,f1,c7,ea,f2,de,1b,f6,5f,27,74,c7,94,19,ba,46,89,..
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet021\Services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04]
"h0"=dword:00000000
"ujdew"=hex:30,77,ae,91,39,7b,b7,91,75,1f,11,44,4e,89,4f,c7,fe,f6,62,44,3c,..
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet021\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4]
"h0"=dword:00000001
"khjeh"=hex:51,e6,6f,c3,c9,40,49,a8,3c,e5,b1,95,d0,bc,86,c6,dc,75,3a,8d,55,..
"p0"="C:\Program Files\DAEMON Tools\"
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet021\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001]
"a0"=hex:20,01,00,00,32,f2,17,51,8b,df,00,39,86,9d,de,a9,32,7d,ea,a0,84,..
"khjeh"=hex:d0,62,32,49,3d,d0,87,d7,76,6b,9e,99,22,e9,54,7a,cf,65,0b,24,ed,..
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet021\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001\0Jf40]
"khjeh"=hex:78,2a,c0,d5,e7,f1,c7,ea,f2,de,1b,f6,5f,27,74,c7,94,19,ba,46,89,..
scanning hidden registry entries ...
scanning hidden files ...
scan completed successfully
hidden services: 0
hidden files: 0
DiagHelp :
DiagHelp version v1.4 - http://www.malekal.com
excute le 16/02/2008 à 16:18:21,09
Liste des derniers fichies modifies/crees dans windir\system32 et prefetch
C:\WINDOWS\prefetch\NTOSBOOT-B00DFAAD.pf -->16/02/2008 11:38:48
C:\WINDOWS\prefetch\Layout.ini -->13/02/2008 14:13:59
C:\WINDOWS\System32\drivers\avg7core.sys -->01/01/2008 20:34:44
C:\WINDOWS\System32\drivers\avgmfx86.sys -->01/01/2008 20:34:43
C:\WINDOWS\System32\drivers\avgclean.sys -->01/01/2008 20:34:43
C:\WINDOWS\System32\drivers\avg7rsxp.sys -->01/01/2008 20:34:43
C:\WINDOWS\System32\drivers\avgtdi.sys -->26/12/2007 21:49:33
C:\WINDOWS\System32\drivers\avg7rsw.sys -->26/12/2007 21:49:32
C:\WINDOWS\System32\drivers\mrxdav.sys -->18/12/2007 10:51:35
C:\WINDOWS\System32\version69ie7fix.dll -->13/02/2008 12:20:06
C:\WINDOWS\System32\wpa.dbl -->12/02/2008 11:17:23
C:\WINDOWS\System32\mrt.exe -->05/02/2008 00:09:46
C:\WINDOWS\System32\pngfilt.dll -->11/01/2008 06:36:55
C:\WINDOWS\System32\QuickTimeVR.qtx -->10/01/2008 15:27:46
C:\WINDOWS\System32\QuickTime.qts -->10/01/2008 15:27:44
C:\WINDOWS\System32\PerfStringBackup.INI -->03/01/2008 20:59:36
C:\WINDOWS\System32\perfh00C.dat -->03/01/2008 20:59:36
C:\WINDOWS\System32\perfh009.dat -->03/01/2008 20:59:36
C:\WINDOWS\System32\perfc00C.dat -->03/01/2008 20:59:36
C:\WINDOWS\System32\perfc009.dat -->03/01/2008 20:59:36
C:\WINDOWS\System32\nscompat.tlb -->02/01/2008 13:24:12
C:\WINDOWS\System32\amcompat.tlb -->02/01/2008 13:24:12
C:\WINDOWS\System32\tmpA8B2A.FOT -->29/12/2007 14:15:38
C:\WINDOWS\System32\tmp7592A.FOT -->29/12/2007 14:15:38
C:\WINDOWS\System32\tmp5372A.FOT -->29/12/2007 14:15:37
C:\WINDOWS\System32\tmp2F42A.FOT -->29/12/2007 14:15:37
C:\WINDOWS\System32\tmp4022A.FOT -->29/12/2007 14:15:36
C:\WINDOWS\System32\tmpB6490.FOT -->28/12/2007 12:13:23
C:\WINDOWS\System32\tmp9B490.FOT -->28/12/2007 12:13:23
C:\WINDOWS\System32\tmp70590.FOT -->28/12/2007 12:13:23
C:\WINDOWS\System32\tmp56590.FOT -->28/12/2007 12:13:23
C:\WINDOWS\System32\tmp2C590.FOT -->28/12/2007 12:13:23
C:\WINDOWS\System32\CONFIG.NT -->26/12/2007 21:45:03
C:\WINDOWS\System32\FNTCACHE.DAT -->22/12/2007 12:02:26
C:\WINDOWS\WindowsUpdate.log -->16/02/2008 15:34:51
C:\WINDOWS\QTFont.qfn -->16/02/2008 11:37:56
C:\WINDOWS\0.log -->16/02/2008 11:37:48
C:\WINDOWS\wiadebug.log -->16/02/2008 11:36:11
C:\WINDOWS\wiaservc.log -->16/02/2008 11:36:07
C:\WINDOWS\SchedLgU.Txt -->16/02/2008 11:36:05
C:\WINDOWS\bootstat.dat -->16/02/2008 11:35:51
C:\WINDOWS\setupapi.log -->15/02/2008 22:32:55
C:\WINDOWS\QTFont.for -->15/02/2008 16:34:53
C:\WINDOWS\Sti_Trace.log -->15/02/2008 16:29:43
C:\WINDOWS\ntbtlog.txt -->15/02/2008 16:24:03
C:\WINDOWS\unins000.dat -->15/02/2008 14:07:32
C:\WINDOWS\unins000.exe -->15/02/2008 14:06:31
C:\WINDOWS\NeroDigital.ini -->13/02/2008 13:11:53
C:\WINDOWS\Composer.INI -->12/02/2008 13:36:47
winlogon.exe
Verified: Unsigned
svchost.exe
Verified: Signed
ws2_32.dll
Verified: Signed
user32.dll
Verified: Signed
tcpip.sys
Verified: Signed
ndis.sys
Verified: Signed
null.sys
Verified: Signed
ListDLLs v2.25 - DLL lister for Win9x/NT
Copyright (C) 1997-2004 Mark Russinovich
Sysinternals - www.sysinternals.com
------------------------------------------------------------------------------
explorer.exe pid: 1492
Command line: C:\WINDOWS\Explorer.EXE
Base Size Version Path
0x44080000 0xcf000 7.00.6000.16608 C:\WINDOWS\system32\WININET.dll
0x00400000 0x9000 6.00.5441.0000 C:\WINDOWS\system32\Normaliz.dll
0x43e00000 0x45000 7.00.6000.16608 C:\WINDOWS\system32\iertutil.dll
0x58b50000 0xdb000 5.82.2900.2982 C:\WINDOWS\system32\comctl32.dll
0x76f80000 0x7f000 2001.12.4414.0310 C:\WINDOWS\system32\CLBCATQ.DLL
0x01100000 0x188000 2001.12.4414.0258 C:\WINDOWS\system32\COMRes.dll
0x10000000 0x13000 7.05.0001.0036 C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\shellexecutehook.dll
0x44160000 0x127000 7.00.6000.16608 C:\WINDOWS\system32\urlmon.dll
0x44360000 0x5cd000 7.00.6000.16608 C:\WINDOWS\system32\ieframe.dll
0x01fe0000 0x21000 7.06.0000.0029 C:\Program Files\iTunes\iTunesMiniPlayer.dll
0x02080000 0xe000 7.06.0000.0021 C:\Program Files\iTunes\iTunesMiniPlayer.Resources\fr.lproj\iTunesMiniPlayerLocalized.dll
0x021b0000 0x23000 7.06.0000.0029 C:\Program Files\iTunes\iTunesMiniPlayer.Resources\iTunesMiniPlayer.dll
0x76ac0000 0x11000 3.05.2284.0000 C:\WINDOWS\system32\ATL.DLL
0x7d200000 0x2be000 3.01.4000.4039 C:\WINDOWS\system32\msi.dll
0x442b0000 0x3c000 7.00.6000.16608 C:\WINDOWS\system32\webcheck.dll
0x164a0000 0x23000 5.02.5721.5145 C:\WINDOWS\system32\WPDShServiceObj.dll
0x109c0000 0x2c000 5.02.5721.5145 C:\WINDOWS\system32\PortableDeviceTypes.dll
0x10930000 0x49000 5.02.5721.5145 C:\WINDOWS\system32\PortableDeviceApi.dll
0x02ea0000 0x5b000 8.01.0000.0000 C:\Program Files\Fichiers communs\Adobe\Acrobat\ActiveX\PDFShell.dll
0x78130000 0x9b000 8.00.50727.0762 C:\WINDOWS\WinSxS\x86_Microsoft.VC80.CRT_1fc8b3b9a1e18e3b_8.0.50727.762_x-ww_6b128700\MSVCR80.dll
0x02f00000 0x4c000 8.00.0000.0000 C:\Program Files\Fichiers communs\Adobe\Acrobat\ActiveX\PDFShell.FRA
0x03290000 0x2c000 C:\Program Files\WinRAR\rarext.dll
0x00a90000 0x10000 8.00.0000.0456 C:\Program Files\Fichiers communs\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
0x032c0000 0xd5000 1.04.0000.0000 C:\PROGRA~1\SPYBOT~1\SDHelper.dll
0x6d7c0000 0x79000 6.00.0020.0006 C:\Program Files\Java\jre1.6.0_02\bin\ssv.dll
0x7c340000 0x56000 7.10.3052.0004 C:\Program Files\Java\jre1.6.0_02\bin\MSVCR71.dll
0x325c0000 0x12000 11.00.5510.0000 C:\Program Files\Microsoft Office\OFFICE11\msohev.dll
ListDLLs v2.25 - DLL lister for Win9x/NT
Copyright (C) 1997-2004 Mark Russinovich
Sysinternals - www.sysinternals.com
------------------------------------------------------------------------------
winlogon.exe pid: 860
Command line: winlogon.exe
Base Size Version Path
0x01000000 0x81000 \??\C:\WINDOWS\system32\winlogon.exe
0x58b50000 0xdb000 5.82.2900.2982 C:\WINDOWS\system32\COMCTL32.dll
0x74730000 0x3d000 3.525.1117.0000 C:\WINDOWS\system32\ODBC32.dll
0x20000000 0x18000 3.525.1117.0000 C:\WINDOWS\system32\odbcint.dll
0x77000000 0x188000 2001.12.4414.0258 C:\WINDOWS\system32\COMRes.dll
0x76f80000 0x7f000 2001.12.4414.0310 C:\WINDOWS\system32\CLBCATQ.DLL
0x76010000 0x65000 6.02.3104.0000 C:\WINDOWS\system32\MSVCP60.dll
Le volume dans le lecteur C n'a pas de nom.
Le numéro de série du volume est 5CA0-33EB
Répertoire de C:\WINDOWS\system
28/05/2003 17:53 4 672 WOWPOST.EXE
1 fichier(s) 4 672 octets
0 Rép(s) 59 104 346 112 octets libres
Le volume dans le lecteur C n'a pas de nom.
Le numéro de série du volume est 5CA0-33EB
Répertoire de C:\WINDOWS\system32
04/08/2004 01:54 6 144 csrss.exe
1 fichier(s) 6 144 octets
0 Rép(s) 59 104 346 112 octets libres
Contenu de Downloaded Program Files
Le volume dans le lecteur C n'a pas de nom.
Le numéro de série du volume est 5CA0-33EB
Répertoire de C:\WINDOWS\Downloaded Program Files
15/02/2008 22:32 <REP> .
15/02/2008 22:32 <REP> ..
07/12/2004 17:07 32 bdcore.dll
25/05/2006 01:21 118 784 bdupd.dll
26/04/2007 22:42 65 desktop.ini
02/07/2007 11:36 155 DivXPlugin.inf
20/11/2007 16:04 1 523 536 FP_AX_CAB_INSTALLER.exe
13/04/2007 02:14 382 344 GAME_UNO1.dll
17/01/2007 15:44 316 GAME_UNO1.INF
25/05/2006 01:21 53 248 ipsupd.dll
08/08/2006 11:45 576 kavwebscan.inf
16/03/2005 12:34 7 407 lang.ini
13/04/2007 14:27 367 LegitCheckControl.inf
07/12/2004 17:07 32 libfn.dll
21/01/2008 17:43 130 live.ini
22/02/2007 23:41 304 544 MessengerStatsPAClient.dll
29/10/2007 16:45 1 244 oscan8.inf
25/10/2007 16:54 471 040 oscan8.ocx
14/03/2005 14:58 7 073 scanoptions.tsi
14/02/2007 15:30 144 setup.inf
20/11/2007 15:50 247 swflash.inf
19 fichier(s) 2 871 284 octets
Total des fichiers listés :
19 fichier(s) 2 871 284 octets
2 Rép(s) 59 104 342 016 octets libres
Recherche de rootkit! (Merci S!Ri)
Recherche d'infections connues
Export des clefs sensibles..
Liste des fichiers en exception sur le pare-feu XP SP2
"C:\\Program Files\\MSN Messenger\\msnmsgr.exe"="C:\\Program Files\\MSN Messenger\\msnmsgr.exe:*:Enabled:Messenger"
"C:\\Program Files\\Mozilla Firefox\\firefox.exe"="C:\\Program Files\\Mozilla Firefox\\firefox.exe:*:Enabled:Firefox"
"C:\\Program Files\\adslTV\\adsltv.exe"="C:\\Program Files\\adslTV\\adsltv.exe:*:Enabled:adsltv"
"C:\\Program Files\\adslTV\\vlc.exe"="C:\\Program Files\\adslTV\\vlc.exe:*:Enabled:VLC media player"
"C:\\Program Files\\Veoh Networks\\Veoh\\VeohClient.exe"="C:\\Program Files\\Veoh Networks\\Veoh\\VeohClient.exe:*:Enabled:Veoh Client"
"C:\\Program Files\\MessengerDiscovery\\MessengerDiscovery Live.exe"="C:\\Program Files\\MessengerDiscovery\\MessengerDiscovery Live.exe:*:Enabled:MessengerDiscovery Live the Windows Live Messenger addon"
"C:\\Program Files\\LimeWire\\LimeWire.exe"="C:\\Program Files\\LimeWire\\LimeWire.exe:*:Enabled:LimeWire"
"%windir%\\Network Diagnostic\\xpnetdiag.exe"="%windir%\\Network Diagnostic\\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000"
"C:\\Program Files\\Grisoft\\AVG Free\\avginet.exe"="C:\\Program Files\\Grisoft\\AVG Free\\avginet.exe:*:Enabled:avginet.exe"
"C:\\Program Files\\Grisoft\\AVG Free\\avgamsvr.exe"="C:\\Program Files\\Grisoft\\AVG Free\\avgamsvr.exe:*:Enabled:avgamsvr.exe"
"C:\\Program Files\\Grisoft\\AVG Free\\avgcc.exe"="C:\\Program Files\\Grisoft\\AVG Free\\avgcc.exe:*:Enabled:avgcc.exe"
"C:\\Program Files\\Grisoft\\AVG Free\\avgemc.exe"="C:\\Program Files\\Grisoft\\AVG Free\\avgemc.exe:*:Enabled:avgemc.exe"
"C:\\Program Files\\iTunes\\iTunes.exe"="C:\\Program Files\\iTunes\\iTunes.exe:*:Enabled:iTunes"
"C:\\Program Files\\MSN Messenger\\livecall.exe"="C:\\Program Files\\MSN Messenger\\livecall.exe:*:Enabled:Windows Live Call"
"C:\\Program Files\\BitTorrent_DNA\\dna.exe"="C:\\Program Files\\BitTorrent_DNA\\dna.exe:*:Enabled:BitTorrent DNA"
"C:\\Program Files\\BitTorrent\\bittorrent.exe"="C:\\Program Files\\BitTorrent\\bittorrent.exe:*:Enabled:BitTorrent"
"%windir%\\Network Diagnostic\\xpnetdiag.exe"="%windir%\\Network Diagnostic\\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000"
Export de la clef SharedTaskScheduler
[SharedTaskScheduler]
"{438755C2-A8BA-11D1-B96B-00A0C90312E1}"="Pré-chargeur Browseui"
"{8C7461EF-2B13-11d2-BE35-3078302C2030}"="Démon de cache des catégories de composant"
exports des policies
REGEDIT4
[system]
"dontdisplaylastusername"=dword:00000000
"legalnoticecaption"=""
"legalnoticetext"=""
"shutdownwithoutlogon"=dword:00000001
"undockwithoutlogon"=dword:00000001
Export des clefs sensibles..
Rechercher adresses sensibles dans le fichier HOSTS...
catchme 0.3.1319 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-02-16 16:19:39
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden services & system hive ...
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04]
"h0"=dword:00000000
"ujdew"=hex:30,77,ae,91,39,7b,b7,91,75,1f,11,44,4e,89,4f,c7,fe,f6,62,44,3c,..
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4]
"h0"=dword:00000001
"khjeh"=hex:51,e6,6f,c3,c9,40,49,a8,3c,e5,b1,95,d0,bc,86,c6,dc,75,3a,8d,55,..
"p0"="C:\Program Files\DAEMON Tools\"
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001]
"a0"=hex:20,01,00,00,32,f2,17,51,8b,df,00,39,86,9d,de,a9,32,7d,ea,a0,84,..
"khjeh"=hex:d0,62,32,49,3d,d0,87,d7,76,6b,9e,99,22,e9,54,7a,cf,65,0b,24,ed,..
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001\0Jf40]
"khjeh"=hex:41,8e,f3,c6,12,89,de,12,fc,90,6a,95,3f,e8,bd,51,c6,99,4e,32,d6,..
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04]
"h0"=dword:00000000
"ujdew"=hex:30,77,ae,91,39,7b,b7,91,75,1f,11,44,4e,89,4f,c7,fe,f6,62,44,3c,..
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4]
"h0"=dword:00000001
"khjeh"=hex:51,e6,6f,c3,c9,40,49,a8,3c,e5,b1,95,d0,bc,86,c6,dc,75,3a,8d,55,..
"p0"="C:\Program Files\DAEMON Tools\"
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001]
"a0"=hex:20,01,00,00,32,f2,17,51,8b,df,00,39,86,9d,de,a9,32,7d,ea,a0,84,..
"khjeh"=hex:d0,62,32,49,3d,d0,87,d7,76,6b,9e,99,22,e9,54,7a,cf,65,0b,24,ed,..
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001\0Jf40]
"khjeh"=hex:41,8e,f3,c6,12,89,de,12,fc,90,6a,95,3f,e8,bd,51,c6,99,4e,32,d6,..
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet003\Services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04]
"h0"=dword:00000000
"ujdew"=hex:30,77,ae,91,39,7b,b7,91,75,1f,11,44,4e,89,4f,c7,fe,f6,62,44,3c,..
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet003\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4]
"h0"=dword:00000001
"khjeh"=hex:51,e6,6f,c3,c9,40,49,a8,3c,e5,b1,95,d0,bc,86,c6,dc,75,3a,8d,55,..
"p0"="C:\Program Files\DAEMON Tools\"
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet003\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001]
"a0"=hex:20,01,00,00,32,f2,17,51,8b,df,00,39,86,9d,de,a9,32,7d,ea,a0,84,..
"khjeh"=hex:d0,62,32,49,3d,d0,87,d7,76,6b,9e,99,22,e9,54,7a,cf,65,0b,24,ed,..
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet003\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001\0Jf40]
"khjeh"=hex:78,2a,c0,d5,e7,f1,c7,ea,f2,de,1b,f6,5f,27,74,c7,94,19,ba,46,89,..
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet004\Services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04]
"h0"=dword:00000000
"ujdew"=hex:30,77,ae,91,39,7b,b7,91,75,1f,11,44,4e,89,4f,c7,fe,f6,62,44,3c,..
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet004\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4]
"h0"=dword:00000001
"khjeh"=hex:51,e6,6f,c3,c9,40,49,a8,3c,e5,b1,95,d0,bc,86,c6,dc,75,3a,8d,55,..
"p0"="C:\Program Files\DAEMON Tools\"
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet004\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001]
"a0"=hex:20,01,00,00,32,f2,17,51,8b,df,00,39,86,9d,de,a9,32,7d,ea,a0,84,..
"khjeh"=hex:d0,62,32,49,3d,d0,87,d7,76,6b,9e,99,22,e9,54,7a,cf,65,0b,24,ed,..
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet004\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001\0Jf40]
"khjeh"=hex:78,2a,c0,d5,e7,f1,c7,ea,f2,de,1b,f6,5f,27,74,c7,94,19,ba,46,89,..
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet005\Services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04]
"h0"=dword:00000000
"ujdew"=hex:30,77,ae,91,39,7b,b7,91,75,1f,11,44,4e,89,4f,c7,fe,f6,62,44,3c,..
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet005\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4]
"h0"=dword:00000001
"khjeh"=hex:51,e6,6f,c3,c9,40,49,a8,3c,e5,b1,95,d0,bc,86,c6,dc,75,3a,8d,55,..
"p0"="C:\Program Files\DAEMON Tools\"
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet005\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001]
"a0"=hex:20,01,00,00,32,f2,17,51,8b,df,00,39,86,9d,de,a9,32,7d,ea,a0,84,..
"khjeh"=hex:d0,62,32,49,3d,d0,87,d7,76,6b,9e,99,22,e9,54,7a,cf,65,0b,24,ed,..
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet005\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001\0Jf40]
"khjeh"=hex:78,2a,c0,d5,e7,f1,c7,ea,f2,de,1b,f6,5f,27,74,c7,94,19,ba,46,89,..
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet006\Services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04]
"h0"=dword:00000000
"ujdew"=hex:30,77,ae,91,39,7b,b7,91,75,1f,11,44,4e,89,4f,c7,fe,f6,62,44,3c,..
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet006\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4]
"h0"=dword:00000001
"khjeh"=hex:51,e6,6f,c3,c9,40,49,a8,3c,e5,b1,95,d0,bc,86,c6,dc,75,3a,8d,55,..
"p0"="C:\Program Files\DAEMON Tools\"
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet006\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001]
"a0"=hex:20,01,00,00,32,f2,17,51,8b,df,00,39,86,9d,de,a9,32,7d,ea,a0,84,..
"khjeh"=hex:d0,62,32,49,3d,d0,87,d7,76,6b,9e,99,22,e9,54,7a,cf,65,0b,24,ed,..
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet006\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001\0Jf40]
"khjeh"=hex:78,2a,c0,d5,e7,f1,c7,ea,f2,de,1b,f6,5f,27,74,c7,94,19,ba,46,89,..
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet007\Services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04]
"h0"=dword:00000000
"ujdew"=hex:30,77,ae,91,39,7b,b7,91,75,1f,11,44,4e,89,4f,c7,fe,f6,62,44,3c,..
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet007\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4]
"h0"=dword:00000001
"khjeh"=hex:51,e6,6f,c3,c9,40,49,a8,3c,e5,b1,95,d0,bc,86,c6,dc,75,3a,8d,55,..
"p0"="C:\Program Files\DAEMON Tools\"
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet007\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001]
"a0"=hex:20,01,00,00,32,f2,17,51,8b,df,00,39,86,9d,de,a9,32,7d,ea,a0,84,..
"khjeh"=hex:d0,62,32,49,3d,d0,87,d7,76,6b,9e,99,22,e9,54,7a,cf,65,0b,24,ed,..
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet007\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001\0Jf40]
"khjeh"=hex:78,2a,c0,d5,e7,f1,c7,ea,f2,de,1b,f6,5f,27,74,c7,94,19,ba,46,89,..
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet008\Services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04]
"h0"=dword:00000000
"ujdew"=hex:30,77,ae,91,39,7b,b7,91,75,1f,11,44,4e,89,4f,c7,fe,f6,62,44,3c,..
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet008\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4]
"h0"=dword:00000001
"khjeh"=hex:51,e6,6f,c3,c9,40,49,a8,3c,e5,b1,95,d0,bc,86,c6,dc,75,3a,8d,55,..
"p0"="C:\Program Files\DAEMON Tools\"
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet008\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001]
"a0"=hex:20,01,00,00,32,f2,17,51,8b,df,00,39,86,9d,de,a9,32,7d,ea,a0,84,..
"khjeh"=hex:d0,62,32,49,3d,d0,87,d7,76,6b,9e,99,22,e9,54,7a,cf,65,0b,24,ed,..
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet008\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001\0Jf40]
"khjeh"=hex:78,2a,c0,d5,e7,f1,c7,ea,f2,de,1b,f6,5f,27,74,c7,94,19,ba,46,89,..
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet009\Services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04]
"h0"=dword:00000000
"ujdew"=hex:30,77,ae,91,39,7b,b7,91,75,1f,11,44,4e,89,4f,c7,fe,f6,62,44,3c,..
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet009\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4]
"h0"=dword:00000001
"khjeh"=hex:51,e6,6f,c3,c9,40,49,a8,3c,e5,b1,95,d0,bc,86,c6,dc,75,3a,8d,55,..
"p0"="C:\Program Files\DAEMON Tools\"
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet009\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001]
"a0"=hex:20,01,00,00,32,f2,17,51,8b,df,00,39,86,9d,de,a9,32,7d,ea,a0,84,..
"khjeh"=hex:d0,62,32,49,3d,d0,87,d7,76,6b,9e,99,22,e9,54,7a,cf,65,0b,24,ed,..
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet009\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001\0Jf40]
"khjeh"=hex:78,2a,c0,d5,e7,f1,c7,ea,f2,de,1b,f6,5f,27,74,c7,94,19,ba,46,89,..
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet010\Services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04]
"h0"=dword:00000000
"ujdew"=hex:30,77,ae,91,39,7b,b7,91,75,1f,11,44,4e,89,4f,c7,fe,f6,62,44,3c,..
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet010\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4]
"h0"=dword:00000001
"khjeh"=hex:51,e6,6f,c3,c9,40,49,a8,3c,e5,b1,95,d0,bc,86,c6,dc,75,3a,8d,55,..
"p0"="C:\Program Files\DAEMON Tools\"
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet010\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001]
"a0"=hex:20,01,00,00,32,f2,17,51,8b,df,00,39,86,9d,de,a9,32,7d,ea,a0,84,..
"khjeh"=hex:d0,62,32,49,3d,d0,87,d7,76,6b,9e,99,22,e9,54,7a,cf,65,0b,24,ed,..
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet010\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001\0Jf40]
"khjeh"=hex:78,2a,c0,d5,e7,f1,c7,ea,f2,de,1b,f6,5f,27,74,c7,94,19,ba,46,89,..
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet011\Services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04]
"h0"=dword:00000000
"ujdew"=hex:30,77,ae,91,39,7b,b7,91,75,1f,11,44,4e,89,4f,c7,fe,f6,62,44,3c,..
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet011\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4]
"h0"=dword:00000001
"khjeh"=hex:51,e6,6f,c3,c9,40,49,a8,3c,e5,b1,95,d0,bc,86,c6,dc,75,3a,8d,55,..
"p0"="C:\Program Files\DAEMON Tools\"
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet011\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001]
"a0"=hex:20,01,00,00,32,f2,17,51,8b,df,00,39,86,9d,de,a9,32,7d,ea,a0,84,..
"khjeh"=hex:d0,62,32,49,3d,d0,87,d7,76,6b,9e,99,22,e9,54,7a,cf,65,0b,24,ed,..
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet011\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001\0Jf40]
"khjeh"=hex:78,2a,c0,d5,e7,f1,c7,ea,f2,de,1b,f6,5f,27,74,c7,94,19,ba,46,89,..
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet012\Services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04]
"h0"=dword:00000000
"ujdew"=hex:30,77,ae,91,39,7b,b7,91,75,1f,11,44,4e,89,4f,c7,fe,f6,62,44,3c,..
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet012\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4]
"h0"=dword:00000001
"khjeh"=hex:51,e6,6f,c3,c9,40,49,a8,3c,e5,b1,95,d0,bc,86,c6,dc,75,3a,8d,55,..
"p0"="C:\Program Files\DAEMON Tools\"
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet012\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001]
"a0"=hex:20,01,00,00,32,f2,17,51,8b,df,00,39,86,9d,de,a9,32,7d,ea,a0,84,..
"khjeh"=hex:d0,62,32,49,3d,d0,87,d7,76,6b,9e,99,22,e9,54,7a,cf,65,0b,24,ed,..
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet012\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001\0Jf40]
"khjeh"=hex:78,2a,c0,d5,e7,f1,c7,ea,f2,de,1b,f6,5f,27,74,c7,94,19,ba,46,89,..
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet013\Services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04]
"h0"=dword:00000000
"ujdew"=hex:30,77,ae,91,39,7b,b7,91,75,1f,11,44,4e,89,4f,c7,fe,f6,62,44,3c,..
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet013\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4]
"h0"=dword:00000001
"khjeh"=hex:51,e6,6f,c3,c9,40,49,a8,3c,e5,b1,95,d0,bc,86,c6,dc,75,3a,8d,55,..
"p0"="C:\Program Files\DAEMON Tools\"
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet013\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001]
"a0"=hex:20,01,00,00,32,f2,17,51,8b,df,00,39,86,9d,de,a9,32,7d,ea,a0,84,..
"khjeh"=hex:d0,62,32,49,3d,d0,87,d7,76,6b,9e,99,22,e9,54,7a,cf,65,0b,24,ed,..
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet013\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001\0Jf40]
"khjeh"=hex:78,2a,c0,d5,e7,f1,c7,ea,f2,de,1b,f6,5f,27,74,c7,94,19,ba,46,89,..
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet014\Services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04]
"h0"=dword:00000000
"ujdew"=hex:30,77,ae,91,39,7b,b7,91,75,1f,11,44,4e,89,4f,c7,fe,f6,62,44,3c,..
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet014\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4]
"h0"=dword:00000001
"khjeh"=hex:51,e6,6f,c3,c9,40,49,a8,3c,e5,b1,95,d0,bc,86,c6,dc,75,3a,8d,55,..
"p0"="C:\Program Files\DAEMON Tools\"
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet014\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001]
"a0"=hex:20,01,00,00,32,f2,17,51,8b,df,00,39,86,9d,de,a9,32,7d,ea,a0,84,..
"khjeh"=hex:d0,62,32,49,3d,d0,87,d7,76,6b,9e,99,22,e9,54,7a,cf,65,0b,24,ed,..
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet014\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001\0Jf40]
"khjeh"=hex:78,2a,c0,d5,e7,f1,c7,ea,f2,de,1b,f6,5f,27,74,c7,94,19,ba,46,89,..
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet015\Services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04]
"h0"=dword:00000000
"ujdew"=hex:30,77,ae,91,39,7b,b7,91,75,1f,11,44,4e,89,4f,c7,fe,f6,62,44,3c,..
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet015\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4]
"h0"=dword:00000001
"khjeh"=hex:51,e6,6f,c3,c9,40,49,a8,3c,e5,b1,95,d0,bc,86,c6,dc,75,3a,8d,55,..
"p0"="C:\Program Files\DAEMON Tools\"
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet015\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001]
"a0"=hex:20,01,00,00,32,f2,17,51,8b,df,00,39,86,9d,de,a9,32,7d,ea,a0,84,..
"khjeh"=hex:d0,62,32,49,3d,d0,87,d7,76,6b,9e,99,22,e9,54,7a,cf,65,0b,24,ed,..
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet015\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001\0Jf40]
"khjeh"=hex:78,2a,c0,d5,e7,f1,c7,ea,f2,de,1b,f6,5f,27,74,c7,94,19,ba,46,89,..
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet016\Services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04]
"h0"=dword:00000000
"ujdew"=hex:30,77,ae,91,39,7b,b7,91,75,1f,11,44,4e,89,4f,c7,fe,f6,62,44,3c,..
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet016\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4]
"h0"=dword:00000001
"khjeh"=hex:51,e6,6f,c3,c9,40,49,a8,3c,e5,b1,95,d0,bc,86,c6,dc,75,3a,8d,55,..
"p0"="C:\Program Files\DAEMON Tools\"
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet016\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001]
"a0"=hex:20,01,00,00,32,f2,17,51,8b,df,00,39,86,9d,de,a9,32,7d,ea,a0,84,..
"khjeh"=hex:d0,62,32,49,3d,d0,87,d7,76,6b,9e,99,22,e9,54,7a,cf,65,0b,24,ed,..
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet016\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001\0Jf40]
"khjeh"=hex:78,2a,c0,d5,e7,f1,c7,ea,f2,de,1b,f6,5f,27,74,c7,94,19,ba,46,89,..
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet017\Services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04]
"h0"=dword:00000000
"ujdew"=hex:30,77,ae,91,39,7b,b7,91,75,1f,11,44,4e,89,4f,c7,fe,f6,62,44,3c,..
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet017\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4]
"h0"=dword:00000001
"khjeh"=hex:51,e6,6f,c3,c9,40,49,a8,3c,e5,b1,95,d0,bc,86,c6,dc,75,3a,8d,55,..
"p0"="C:\Program Files\DAEMON Tools\"
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet017\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001]
"a0"=hex:20,01,00,00,32,f2,17,51,8b,df,00,39,86,9d,de,a9,32,7d,ea,a0,84,..
"khjeh"=hex:d0,62,32,49,3d,d0,87,d7,76,6b,9e,99,22,e9,54,7a,cf,65,0b,24,ed,..
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet017\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001\0Jf40]
"khjeh"=hex:78,2a,c0,d5,e7,f1,c7,ea,f2,de,1b,f6,5f,27,74,c7,94,19,ba,46,89,..
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet018\Services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04]
"h0"=dword:00000000
"ujdew"=hex:30,77,ae,91,39,7b,b7,91,75,1f,11,44,4e,89,4f,c7,fe,f6,62,44,3c,..
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet018\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4]
"h0"=dword:00000001
"khjeh"=hex:51,e6,6f,c3,c9,40,49,a8,3c,e5,b1,95,d0,bc,86,c6,dc,75,3a,8d,55,..
"p0"="C:\Program Files\DAEMON Tools\"
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet018\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001]
"a0"=hex:20,01,00,00,32,f2,17,51,8b,df,00,39,86,9d,de,a9,32,7d,ea,a0,84,..
"khjeh"=hex:d0,62,32,49,3d,d0,87,d7,76,6b,9e,99,22,e9,54,7a,cf,65,0b,24,ed,..
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet018\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001\0Jf40]
"khjeh"=hex:78,2a,c0,d5,e7,f1,c7,ea,f2,de,1b,f6,5f,27,74,c7,94,19,ba,46,89,..
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet019\Services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04]
"h0"=dword:00000000
"ujdew"=hex:30,77,ae,91,39,7b,b7,91,75,1f,11,44,4e,89,4f,c7,fe,f6,62,44,3c,..
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet019\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4]
"h0"=dword:00000001
"khjeh"=hex:51,e6,6f,c3,c9,40,49,a8,3c,e5,b1,95,d0,bc,86,c6,dc,75,3a,8d,55,..
"p0"="C:\Program Files\DAEMON Tools\"
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet019\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001]
"a0"=hex:20,01,00,00,32,f2,17,51,8b,df,00,39,86,9d,de,a9,32,7d,ea,a0,84,..
"khjeh"=hex:d0,62,32,49,3d,d0,87,d7,76,6b,9e,99,22,e9,54,7a,cf,65,0b,24,ed,..
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet019\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001\0Jf40]
"khjeh"=hex:78,2a,c0,d5,e7,f1,c7,ea,f2,de,1b,f6,5f,27,74,c7,94,19,ba,46,89,..
IPC error: 2 Le fichier spécifié est introuvable.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\sptd\Cfg]
"s1"=dword:2df9c43f
"s2"=dword:110480d0
"h0"=dword:00000002
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04]
"h0"=dword:00000000
"ujdew"=hex:30,77,ae,91,39,7b,b7,91,75,1f,11,44,4e,89,4f,c7,fe,f6,62,44,3c,..
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4]
"h0"=dword:00000001
"khjeh"=hex:51,e6,6f,c3,c9,40,49,a8,3c,e5,b1,95,d0,bc,86,c6,dc,75,3a,8d,55,..
"p0"="C:\Program Files\DAEMON Tools\"
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001]
"a0"=hex:20,01,00,00,32,f2,17,51,8b,df,00,39,86,9d,de,a9,32,7d,ea,a0,84,..
"khjeh"=hex:d0,62,32,49,3d,d0,87,d7,76,6b,9e,99,22,e9,54,7a,cf,65,0b,24,ed,..
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001\0Jf40]
"khjeh"=hex:78,2a,c0,d5,e7,f1,c7,ea,f2,de,1b,f6,5f,27,74,c7,94,19,ba,46,89,..
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet021\Services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04]
"h0"=dword:00000000
"ujdew"=hex:30,77,ae,91,39,7b,b7,91,75,1f,11,44,4e,89,4f,c7,fe,f6,62,44,3c,..
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet021\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4]
"h0"=dword:00000001
"khjeh"=hex:51,e6,6f,c3,c9,40,49,a8,3c,e5,b1,95,d0,bc,86,c6,dc,75,3a,8d,55,..
"p0"="C:\Program Files\DAEMON Tools\"
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet021\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001]
"a0"=hex:20,01,00,00,32,f2,17,51,8b,df,00,39,86,9d,de,a9,32,7d,ea,a0,84,..
"khjeh"=hex:d0,62,32,49,3d,d0,87,d7,76,6b,9e,99,22,e9,54,7a,cf,65,0b,24,ed,..
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet021\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001\0Jf40]
"khjeh"=hex:78,2a,c0,d5,e7,f1,c7,ea,f2,de,1b,f6,5f,27,74,c7,94,19,ba,46,89,..
scanning hidden registry entries ...
scanning hidden files ...
scan completed successfully
hidden services: 0
hidden files: 0
KProcCheck Version 0.2-beta1 Proof-of-Concept by SIG^2 (www.security.org.sg)
Process list by traversal of KiWaitListHead
4 - System
224 - NLSAgent.exe
444 - AppleMobileDevi
464 - guard.exe
488 - avgamsvr.exe
560 - avgemc.exe
600 - DkService.exe
664 - svchost.exe
800 - NLSAgentSvc.exe
824 - firefox.exe
832 - csrss.exe
860 - winlogon.exe
916 - services.exe
928 - lsass.exe
1104 - svchost.exe
1148 - svchost.exe
1196 - svchost.exe
1440 - EDICT.EXE
1492 - explorer.exe
1828 - aawservice.exe
1908 - iTunesHelper.ex
1956 - alg.exe
1992 - avgas.exe
2060 - dna.exe
2356 - iTunes.exe
2448 - iPodService.exe
2960 - bittorrent.exe
3044 - cmd.exe
3096 - DfrgNTFS.exe
3336 - usnsvc.exe
3624 - NOTEPAD.EXE
3968 - msnmsgr.exe
Total number of processes = 32
NOTE: Under WinXP, this will not show all processes.
KProcCheck Version 0.2-beta1 Proof-of-Concept by SIG^2 (www.security.org.sg)
Driver/Module list by traversal of PsLoadedModuleList
804D7000 - \WINDOWS\system32\ntoskrnl.exe
806EC000 - \WINDOWS\system32\hal.dll
F801B000 - \WINDOWS\system32\KDCOM.DLL
F7F2B000 - \WINDOWS\system32\BOOTVID.dll
F7A10000 - sptd.sys
F801D000 - \WINDOWS\System32\Drivers\WMILIB.SYS
F79F8000 - \WINDOWS\System32\Drivers\SCSIPORT.SYS
F79C9000 - ACPI.sys
F79B8000 - pci.sys
F7B1B000 - isapnp.sys
F80E3000 - pciide.sys
F7D9B000 - \WINDOWS\system32\DRIVERS\PCIIDEX.SYS
F7B2B000 - MountMgr.sys
F7999000 - ftdisk.sys
F801F000 - dmload.sys
F7973000 - dmio.sys
F7DA3000 - PartMgr.sys
F7B3B000 - VolSnap.sys
F795B000 - atapi.sys
F7B4B000 - SiSRaid.sys
F7B5B000 - Si3112.sys
F794A000 - Si3132.sys
F7B6B000 - disk.sys
F7B7B000 - \WINDOWS\system32\DRIVERS\CLASSPNP.SYS
F792A000 - fltMgr.sys
F7913000 - KSecDD.sys
F7900000 - WudfPf.sys
F7873000 - Ntfs.sys
F7846000 - NDIS.sys
F7B8B000 - uagp35.sys
F782C000 - Mup.sys
F6F30000 - \SystemRoot\system32\DRIVERS\intelppm.sys
F6EE0000 - \SystemRoot\system32\DRIVERS\sisgrp.sys
F6ECC000 - \SystemRoot\system32\DRIVERS\VIDEOPRT.SYS
F6F20000 - \SystemRoot\system32\DRIVERS\cdrom.sys
F7BBB000 - \SystemRoot\system32\DRIVERS\redbook.sys
F6EA9000 - \SystemRoot\system32\DRIVERS\ks.sys
F7E2B000 - \SystemRoot\System32\Drivers\GEARAspiWDM.sys
F6AD4000 - \SystemRoot\system32\drivers\ALCXWDM.SYS
F6AB0000 - \SystemRoot\system32\drivers\portcls.sys
F7BDB000 - \SystemRoot\system32\drivers\drmk.sys
F7E33000 - \SystemRoot\system32\DRIVERS\usbohci.sys
F6A8D000 - \SystemRoot\system32\DRIVERS\USBPORT.SYS
F7E3B000 - \SystemRoot\system32\DRIVERS\usbehci.sys
F7E43000 - \SystemRoot\system32\DRIVERS\sisnic.sys
F6A7C000 - \SystemRoot\system32\DRIVERS\serial.sys
F8017000 - \SystemRoot\system32\DRIVERS\serenum.sys
F6A68000 - \SystemRoot\system32\DRIVERS\parport.sys
F7BEB000 - \SystemRoot\system32\DRIVERS\i8042prt.sys
F7E4B000 - \SystemRoot\system32\DRIVERS\kbdclass.sys
F8141000 - \SystemRoot\system32\DRIVERS\audstub.sys
F7BFB000 - \SystemRoot\system32\DRIVERS\rasl2tp.sys
F7808000 - \SystemRoot\system32\DRIVERS\ndistapi.sys
F6A51000 - \SystemRoot\system32\DRIVERS\ndiswan.sys
F7C0B000 - \SystemRoot\system32\DRIVERS\raspppoe.sys
F7C1B000 - \SystemRoot\system32\DRIVERS\raspptp.sys
F7E53000 - \SystemRoot\system32\DRIVERS\TDI.SYS
F6A40000 - \SystemRoot\system32\DRIVERS\psched.sys
F7C2B000 - \SystemRoot\system32\DRIVERS\msgpc.sys
F7E5B000 - \SystemRoot\system32\DRIVERS\ptilink.sys
F7E63000 - \SystemRoot\system32\DRIVERS\raspti.sys
F69E8000 - \SystemRoot\system32\DRIVERS\rdpdr.sys
F7C3B000 - \SystemRoot\system32\DRIVERS\termdd.sys
F7E6B000 - \SystemRoot\system32\DRIVERS\mouclass.sys
F8043000 - \SystemRoot\system32\DRIVERS\swenum.sys
F698F000 - \SystemRoot\system32\DRIVERS\update.sys
F77E0000 - \SystemRoot\system32\DRIVERS\mssmbios.sys
F7C4B000 - \SystemRoot\System32\Drivers\NDProxy.SYS
F7C6B000 - \SystemRoot\system32\DRIVERS\usbhub.sys
F8045000 - \SystemRoot\system32\DRIVERS\USBD.SYS
F8047000 - \SystemRoot\System32\Drivers\Fs_Rec.SYS
F814E000 - \SystemRoot\System32\Drivers\Null.SYS
F8049000 - \SystemRoot\System32\Drivers\Beep.SYS
F8154000 - \SystemRoot\System32\DRIVERS\AvgAsCln.sys
F8156000 - \SystemRoot\System32\Drivers\avgclean.sys
F7E93000 - \??\C:\Program Files\Symantec\Norton Ghost 2003\ghpciscan.sys
F7E9B000 - \SystemRoot\System32\drivers\vga.sys
F804B000 - \SystemRoot\System32\DRIVERS\RDPCDD.sys
F7EA3000 - \SystemRoot\System32\Drivers\Msfs.SYS
F7EAB000 - \SystemRoot\System32\Drivers\Npfs.SYS
F7FF3000 - \SystemRoot\system32\DRIVERS\rasacd.sys
B8FCD000 - \SystemRoot\system32\DRIVERS\ipsec.sys
B8F75000 - \SystemRoot\system32\DRIVERS\tcpip.sys
B8F4D000 - \SystemRoot\system32\DRIVERS\netbt.sys
B8F2B000 - \SystemRoot\System32\drivers\afd.sys
F7C7B000 - \SystemRoot\system32\DRIVERS\netbios.sys
F7EB3000 - \SystemRoot\System32\Drivers\StarOpen.SYS
F7FFB000 - \SystemRoot\system32\DRIVERS\srvkp.sys
B8F00000 - \SystemRoot\system32\DRIVERS\rdbss.sys
B8E69000 - \SystemRoot\system32\DRIVERS\mrxsmb.sys
F7C9B000 - \SystemRoot\System32\Drivers\Fips.SYS
B8E47000 - \SystemRoot\system32\DRIVERS\ipnat.sys
F7CAB000 - \SystemRoot\system32\DRIVERS\wanarp.sys
F6A34000 - \SystemRoot\system32\DRIVERS\hidusb.sys
F7CBB000 - \SystemRoot\system32\DRIVERS\HIDCLASS.SYS
F7EBB000 - \SystemRoot\system32\DRIVERS\HIDPARSE.SYS
B8DF1000 - \SystemRoot\system32\DRIVERS\WlanUIG.sys
F6A30000 - \SystemRoot\system32\DRIVERS\mouhid.sys
B8D29000 - \SystemRoot\System32\Drivers\avg7core.sys
F804D000 - \SystemRoot\System32\Drivers\avg7rsw.sys
F7ECB000 - \SystemRoot\System32\Drivers\avg7rsxp.sys
F7CFB000 - \SystemRoot\System32\Drivers\Cdfs.SYS
F825D000 - \??\C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.sys
B8D11000 - \SystemRoot\System32\Drivers\dump_atapi.sys
F8067000 - \SystemRoot\System32\Drivers\dump_WMILIB.SYS
BF800000 - \SystemRoot\System32\win32k.sys
F697F000 - \SystemRoot\System32\drivers\Dxapi.sys
F7EFB000 - \SystemRoot\System32\watchdog.sys
BF9C3000 - \SystemRoot\System32\drivers\dxg.sys
F8199000 - \SystemRoot\System32\drivers\dxgthk.sys
BF9D5000 - \SystemRoot\System32\SiSGRV.dll
BFFA0000 - \SystemRoot\System32\ATMFD.DLL
B8B7D000 - \SystemRoot\system32\DRIVERS\ndisuio.sys
F8051000 - \SystemRoot\System32\Drivers\ParVdm.SYS
B89A1000 - \SystemRoot\System32\Drivers\Aspi32.SYS
F8059000 - \SystemRoot\System32\Drivers\avgtdi.sys
B8760000 - \SystemRoot\System32\Drivers\HTTP.sys
B8723000 - \SystemRoot\system32\drivers\wdmaud.sys
B88F1000 - \SystemRoot\system32\drivers\sysaudio.sys
B85E6000 - \SystemRoot\system32\DRIVERS\srv.sys
B8A89000 - \SystemRoot\system32\DRIVERS\secdrv.sys
B7CB2000 - \SystemRoot\system32\drivers\kmixer.sys
F7F1B000 * --[Hidden]--
F81EE000 - \SystemRoot\System32\DRIVERS\KProcCheck.sys
Total number of drivers = 124
Liste des programmes installes
Ad-Aware 2007
Adobe Flash Player ActiveX
Adobe Flash Player Plugin
Adobe Reader 8.1.2 - Français
Adobe Shockwave Player
adsl TV
Apple Mobile Device Support
Apple Software Update
Archiveur WinRAR
Audacity 1.2.6
AVG Anti-Spyware 7.5
AVG Free Edition
BrowsingTool
CCleaner (remove only)
Correctif pour Lecteur Windows Media 11 (KB939683)
Correctif pour Windows XP (KB914440)
Correctif pour Windows XP (KB918093)
CSI-Dark Motives
Diskeeper Professional Edition
DivX Content Uploader
DivX Web Player
EVEREST Ultimate Edition v4.00
FBrowsingAdvisor
HijackThis 2.0.2
Hotfix for Windows Media Format 11 SDK (KB929399)
Hotfix for Windows XP (KB915865)
Hotfix for Windows XP (KB926239)
InterActual Player
iPod for Windows 2005-09-23
iPod for Windows 2005-09-23
iTunes
J2SE Runtime Environment 5.0 Update 3
Java(TM) 6 Update 2
Java(TM) SE Runtime Environment 6 Update 1
Kaspersky Online Scanner
Lecteur Windows Media 11
Les Experts - Las Vegas - Crimes en série 1.0
LimeWire 4.16.6
Messenger Plus! Live
Microsoft .NET Framework 1.1
Microsoft .NET Framework 1.1
Microsoft .NET Framework 1.1 French Language Pack
Microsoft .NET Framework 1.1 Hotfix (KB928366)
Microsoft .NET Framework 2.0
Microsoft .NET Framework 2.0
Microsoft .NET Framework 2.0 Language Pack - FRA
Microsoft Compression Client Pack 1.0 for Windows XP
Microsoft Encarta 2007 - Collection
Microsoft Internationalized Domain Names Mitigation APIs
Microsoft National Language Support Downlevel APIs
Microsoft Office Professional Edition 2003
Microsoft User-Mode Driver Framework Feature Pack 1.0
Microsoft Visual C++ 2005 Redistributable
Mise à jour de sécurité pour Lecteur Windows Media 11 (KB936782)
Mise à jour de sécurité pour Lecteur Windows Media 6.4 (KB925398)
Mise à jour de sécurité pour Windows Internet Explorer 7 (KB938127)
Mise à jour de sécurité pour Windows Internet Explorer 7 (KB942615)
Mise à jour de sécurité pour Windows Internet Explorer 7 (KB944533)
Mise à jour de sécurité pour Windows XP (KB918118)
Mise à jour de sécurité pour Windows XP (KB920213)
Mise à jour de sécurité pour Windows XP (KB921503)
Mise à jour de sécurité pour Windows XP (KB923694)
Mise à jour de sécurité pour Windows XP (KB923980)
Mise à jour de sécurité pour Windows XP (KB924270)
Mise à jour de sécurité pour Windows XP (KB924667)
Mise à jour de sécurité pour Windows XP (KB925902)
Mise à jour de sécurité pour Windows XP (KB926255)
Mise à jour de sécurité pour Windows XP (KB926436)
Mise à jour de sécurité pour Windows XP (KB927779)
Mise à jour de sécurité pour Windows XP (KB927802)
Mise à jour de sécurité pour Windows XP (KB928090)
Mise à jour de sécurité pour Windows XP (KB928255)
Mise à jour de sécurité pour Windows XP (KB928843)
Mise à jour de sécurité pour Windows XP (KB929123)
Mise à jour de sécurité pour Windows XP (KB929969)
Mise à jour de sécurité pour Windows XP (KB930178)
Mise à jour de sécurité pour Windows XP (KB931261)
Mise à jour de sécurité pour Windows XP (KB931768)
Mise à jour de sécurité pour Windows XP (KB931784)
Mise à jour de sécurité pour Windows XP (KB932168)
Mise à jour de sécurité pour Windows XP (KB933566)
Mise à jour de sécurité pour Windows XP (KB933729)
Mise à jour de sécurité pour Windows XP (KB935839)
Mise à jour de sécurité pour Windows XP (KB935840)
Mise à jour de sécurité pour Windows XP (KB936021)
Mise à jour de sécurité pour Windows XP (KB937143)
Mise à jour de sécurité pour Windows XP (KB937894)
Mise à jour de sécurité pour Windows XP (KB938127)
Mise à jour de sécurité pour Windows XP (KB938829)
Mise à jour de sécurité pour Windows XP (KB939653)
Mise à jour de sécurité pour Windows XP (KB941202)
Mise à jour de sécurité pour Windows XP (KB941568)
Mise à jour de sécurité pour Windows XP (KB941569)
Mise à jour de sécurité pour Windows XP (KB941644)
Mise à jour de sécurité pour Windows XP (KB943055)
Mise à jour de sécurité pour Windows XP (KB943460)
Mise à jour de sécurité pour Windows XP (KB943485)
Mise à jour de sécurité pour Windows XP (KB944653)
Mise à jour de sécurité pour Windows XP (KB946026)
Mise à jour pour Windows XP (KB927891)
Mise à jour pour Windows XP (KB930916)
Mise à jour pour Windows XP (KB931836)
Mise à jour pour Windows XP (KB933360)
Mise à jour pour Windows XP (KB936357)
Mise à jour pour Windows XP (KB938828)
Mise à jour pour Windows XP (KB942763)
Module de prise en charge linguistique de Microsoft .NET Framework 2.0 - FRA
Mozilla Fir |
|