A voir également:
- Zph diag
- User diag - Télécharger - Informations & Diagnostic
- Zhp diag - Télécharger - Informations & Diagnostic
- Zph cleaner - Télécharger - Informations & Diagnostic
- Mp3 diag - Télécharger - Audio & Musique
- Windows memory diag - Télécharger - Optimisation
15 réponses
bonjour;
désinstalle spybot, il est inutile !
attention à Boonty game, problème de confidentilité !!!
* Télécharge de AD-Remover sur ton Bureau. (Merci à l'équipe TeamXscript)
http://www.teamxscript.org/adremoverTelechargement.html
( Lien officiel )
https://www.androidworld.fr/
( Miroir )
/!\ Ferme toutes applications en cours /!\
- Double-clique sur l'icône Ad-remover située sur ton Bureau.
- Sur la page, clique sur le bouton « Nettoyer »
- Confirme lancement du scan
- Laisse travailler l'outil.
- Poste le rapport qui apparaît à la fin.
(Le rapport est sauvegardé aussi sous C:\Ad-report(Scan/clean).Txt)
(CTRL+A pour tout sélectionner, CTRL+C pour copier et CTRL+V pour coller)
désinstalle spybot, il est inutile !
attention à Boonty game, problème de confidentilité !!!
* Télécharge de AD-Remover sur ton Bureau. (Merci à l'équipe TeamXscript)
http://www.teamxscript.org/adremoverTelechargement.html
( Lien officiel )
https://www.androidworld.fr/
( Miroir )
/!\ Ferme toutes applications en cours /!\
- Double-clique sur l'icône Ad-remover située sur ton Bureau.
- Sur la page, clique sur le bouton « Nettoyer »
- Confirme lancement du scan
- Laisse travailler l'outil.
- Poste le rapport qui apparaît à la fin.
(Le rapport est sauvegardé aussi sous C:\Ad-report(Scan/clean).Txt)
(CTRL+A pour tout sélectionner, CTRL+C pour copier et CTRL+V pour coller)
======= RAPPORT D'AD-REMOVER 2.0.0.2,E | UNIQUEMENT XP/VISTA/7 =======
Mis à jour par TeamXscript le 08/02/11
Contact: AdRemover[DOT]contact[AT]gmail[DOT]com
Site web: http://www.teamxscript.org
C:\Program Files\Ad-Remover\main.exe (CLEAN [1]) -> Lancé à 15:16:39 le 14/02/2011, Mode normal
Microsoft® Windows Vista(TM) Édition Familiale Premium Service Pack 2 (X86)
jeremie@PC-DE-BUREAU (Acer Aspire 5738)
============== ACTION(S) ==============
Fichier supprimé: C:\Users\Public\Desktop\Everest Poker.fr.lnk
Fichier supprimé: C:\Users\jeremie\Downloads\PartyPokerFrSetup(2).exe
Fichier supprimé: C:\Users\jeremie\Downloads\PartyPokerFrSetup.exe
(!) -- Fichiers temporaires supprimés.
Clé supprimée: HKLM\Software\Classes\CLSID\{9CB65201-89C4-402c-BA80-02D8C59F9B1D}
Clé supprimée: HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{9CB65201-89C4-402c-BA80-02D8C59F9B1D}
Clé supprimée: HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{9CB65201-89C4-402c-BA80-02D8C59F9B1D}
Clé supprimée: HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{9CB65201-89C4-402c-BA80-02D8C59F9B1D}
Clé supprimée: HKLM\Software\Classes\CLSID\{FE063DB1-4EC0-403e-8DD8-394C54984B2C}
Clé supprimée: HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{FE063DB1-4EC0-403e-8DD8-394C54984B2C}
Clé supprimée: HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{FE063DB1-4EC0-403e-8DD8-394C54984B2C}
Clé supprimée: HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{FE063DB1-4EC0-403e-8DD8-394C54984B2C}
Clé supprimée: HKLM\Software\Classes\CLSID\{FE063DB9-4EC0-403e-8DD8-394C54984B2C}
Clé supprimée: HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{FE063DB9-4EC0-403e-8DD8-394C54984B2C}
Clé supprimée: HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{FE063DB9-4EC0-403e-8DD8-394C54984B2C}
Clé supprimée: HKLM\Software\Classes\Interface\{DB885111-F39F-4D88-9EE5-C88460B6DF7B}
Clé supprimée: HKLM\Software\PopCap
Clé supprimée: HKCU\Software\Grand Virtual
Clé supprimée: HKCU\Software\Microsoft\Windows\CurrentVersion\App Management\ARPCache\Everest Poker
Valeur supprimée: HKCU\Software\Microsoft\Internet Explorer\URLSearchHooks|{9CB65206-89C4-402C-BA80-02D8C59F9B1D}
Valeur supprimée: HKLM\Software\Microsoft\Internet Explorer\Toolbar|{FE063DB9-4EC0-403E-8DD8-394C54984B2C}
Valeur supprimée: HKCU\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser|{FE063DB9-4EC0-403E-8DD8-394C54984B2C}
============== SCAN ADDITIONNEL ==============
**** Mozilla Firefox Version [3.6.13 (fr)] ****
Extensions\{AB2CE124-6272-4b12-94A9-7303C7397BD1} (Skype extension for Firefox )
-- C:\Users\jeremie\AppData\Roaming\Mozilla\FireFox\Profiles\y2zu2cmm.default --
Prefs.js - browser.download.lastDir, C:\\Users\\jeremie\\Desktop
Prefs.js - browser.startup.homepage, www.google.fr
Prefs.js - browser.startup.homepage_override.mstone, rv:1.9.2.13
========================================
**** Google Chrome Version [9.0.597.98] ****
-- C:\Users\jeremie\AppData\Local\Google\Chrome\User Data\Default --
Preferences - default_search_provider: "Google" (Activé: ) (?)
Preferences - urls_to_restore_on_startup:
========================================
**** Internet Explorer Version [8.0.6001.19019] ****
HKCU_Main|Default_Page_URL - hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&pver=6&ar=msnhome
HKCU_Main|Default_Search_URL - hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
HKCU_Main|Search bar - hxxp://go.microsoft.com/fwlink/?linkid=54896
HKCU_Main|Start Page - hxxp://fr.msn.com/
HKLM_Main|Default_Page_URL - hxxp://go.microsoft.com/fwlink/?LinkId=54896
HKLM_Main|Default_Search_URL - hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
HKLM_Main|Search bar - hxxp://search.msn.com/spbasic.htm
HKLM_Main|Search Page - hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
HKLM_Main|Start Page - hxxp://fr.msn.com/
HKCU_SearchScopes\{70D46D94-BF1E-45ED-B567-48701376298E} - "Google Desktop" (hxxp://127.0.0.1:4664/search&s=G2IVl71TceZdYySAzFYtZQyuHWs?q={searchTerms})
HKCU_SearchScopes\{AD22EBAF-0D18-4fc7-90CC-5EA0ABBE9EB8} - "DAEMON Search" (hxxp://www.daemon-search.com/search?q={searchTerms})
HKCU_Toolbar\WebBrowser|{32099AAC-C132-4136-9E9A-4E364A424E17} (C:\Program Files\DAEMON Tools Toolbar\DTToolbar.dll)
HKLM_Toolbar|{32099AAC-C132-4136-9E9A-4E364A424E17} (C:\Program Files\DAEMON Tools Toolbar\DTToolbar.dll)
HKCU_ElevationPolicy\{83EED7CF-C0E1-4D8F-8AD8-97966F44F8BB} - C:\Program Files\eMule\emule.exe (http://www.emule-project.net)
HKLM_ElevationPolicy\{28A36D69-07EA-44CE-B298-1A8B3E8B6FE1} - C:\Program Files\Skype\Phone\Skype.exe (Skype Technologies S.A.)
HKLM_ElevationPolicy\{70f641fd-9ffc-4d5b-a4dc-962af4ed7999} - C:\Program Files\Internet Explorer\iedw.exe (x)
HKLM_ElevationPolicy\{71274DC5-D6B8-4B74-BBCF-04D76E30772B} - C:\Program Files\Skype\Toolbars\Shared\SkypeNames2.exe (Skype Technologies S.A.)
HKLM_ElevationPolicy\{74351F14-5437-4d87-805B-04D409B09976} - C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe (Google)
HKLM_ElevationPolicy\{88B89B96-F7B2-469D-8F22-5F3BE33DEDDE} - C:\Program Files\Skype\Toolbars\Internet Explorer\SkypeIEPluginBroker.exe (Skype Technologies S.A.)
HKLM_ElevationPolicy\{A6E2003F-95C5-4591-BA9A-0093080FDB5C} - C:\Program Files\Common Files\Oberon Media\OberonBroker\1.0.0.63\OberonBroker.exe (?)
HKCU_Extensions\{00000000-0000-0000-0000-000000000000} - "Unibet" (C:\MicroGaming\Poker\unibetpokerMPP\MPPoker.exe,1)
HKLM_Extensions\{06568ceb-5721-47d4-9d93-7e604fcbaeab} - "PMU Poker" (C:\Programs\PMU\PMUPoker\images\ppicon.ico)
HKLM_Extensions\{725EC34E-943C-4df6-B0B2-FBDE7F242276} - "PartyPoker.fr" (C:\Programs\PartyFrance\PartyPokerFr\images\ppicon.ico)
HKLM_Extensions\{898EA8C8-E7FF-479B-8935-AEC46303B9E5} - "Skype add-on for Internet Explorer" (C:\Program Files\Skype\Toolbars\Internet Explorer\icon.ico)
HKLM_Extensions\{DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - "?" (?)
BHO\{53707962-6F74-2D53-2644-206D7942484F} - "Spybot-S&D IE Protection" (C:\PROGRA~1\SPYBOT~1\SDHelper.dll)
BHO\{5C255C8A-E604-49b4-9D64-90988571CECB} (?)
BHO\{AE805869-2E5C-4ED4-8F7B-F1F7851A4497} - "Skype add-on for Internet Explorer" (C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll)
========================================
C:\Program Files\Ad-Remover\Quarantine: 3 Fichier(s)
C:\Program Files\Ad-Remover\Backup: 16 Fichier(s)
C:\Ad-Report-CLEAN[1].txt - 14/02/2011 (6532 Octet(s))
C:\Ad-Report-SCAN[1].txt - 14/02/2011 (7130 Octet(s))
Fin à: 15:17:53, 14/02/2011
============== E.O.F ==============
Mis à jour par TeamXscript le 08/02/11
Contact: AdRemover[DOT]contact[AT]gmail[DOT]com
Site web: http://www.teamxscript.org
C:\Program Files\Ad-Remover\main.exe (CLEAN [1]) -> Lancé à 15:16:39 le 14/02/2011, Mode normal
Microsoft® Windows Vista(TM) Édition Familiale Premium Service Pack 2 (X86)
jeremie@PC-DE-BUREAU (Acer Aspire 5738)
============== ACTION(S) ==============
Fichier supprimé: C:\Users\Public\Desktop\Everest Poker.fr.lnk
Fichier supprimé: C:\Users\jeremie\Downloads\PartyPokerFrSetup(2).exe
Fichier supprimé: C:\Users\jeremie\Downloads\PartyPokerFrSetup.exe
(!) -- Fichiers temporaires supprimés.
Clé supprimée: HKLM\Software\Classes\CLSID\{9CB65201-89C4-402c-BA80-02D8C59F9B1D}
Clé supprimée: HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{9CB65201-89C4-402c-BA80-02D8C59F9B1D}
Clé supprimée: HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{9CB65201-89C4-402c-BA80-02D8C59F9B1D}
Clé supprimée: HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{9CB65201-89C4-402c-BA80-02D8C59F9B1D}
Clé supprimée: HKLM\Software\Classes\CLSID\{FE063DB1-4EC0-403e-8DD8-394C54984B2C}
Clé supprimée: HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{FE063DB1-4EC0-403e-8DD8-394C54984B2C}
Clé supprimée: HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{FE063DB1-4EC0-403e-8DD8-394C54984B2C}
Clé supprimée: HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{FE063DB1-4EC0-403e-8DD8-394C54984B2C}
Clé supprimée: HKLM\Software\Classes\CLSID\{FE063DB9-4EC0-403e-8DD8-394C54984B2C}
Clé supprimée: HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{FE063DB9-4EC0-403e-8DD8-394C54984B2C}
Clé supprimée: HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{FE063DB9-4EC0-403e-8DD8-394C54984B2C}
Clé supprimée: HKLM\Software\Classes\Interface\{DB885111-F39F-4D88-9EE5-C88460B6DF7B}
Clé supprimée: HKLM\Software\PopCap
Clé supprimée: HKCU\Software\Grand Virtual
Clé supprimée: HKCU\Software\Microsoft\Windows\CurrentVersion\App Management\ARPCache\Everest Poker
Valeur supprimée: HKCU\Software\Microsoft\Internet Explorer\URLSearchHooks|{9CB65206-89C4-402C-BA80-02D8C59F9B1D}
Valeur supprimée: HKLM\Software\Microsoft\Internet Explorer\Toolbar|{FE063DB9-4EC0-403E-8DD8-394C54984B2C}
Valeur supprimée: HKCU\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser|{FE063DB9-4EC0-403E-8DD8-394C54984B2C}
============== SCAN ADDITIONNEL ==============
**** Mozilla Firefox Version [3.6.13 (fr)] ****
Extensions\{AB2CE124-6272-4b12-94A9-7303C7397BD1} (Skype extension for Firefox )
-- C:\Users\jeremie\AppData\Roaming\Mozilla\FireFox\Profiles\y2zu2cmm.default --
Prefs.js - browser.download.lastDir, C:\\Users\\jeremie\\Desktop
Prefs.js - browser.startup.homepage, www.google.fr
Prefs.js - browser.startup.homepage_override.mstone, rv:1.9.2.13
========================================
**** Google Chrome Version [9.0.597.98] ****
-- C:\Users\jeremie\AppData\Local\Google\Chrome\User Data\Default --
Preferences - default_search_provider: "Google" (Activé: ) (?)
Preferences - urls_to_restore_on_startup:
========================================
**** Internet Explorer Version [8.0.6001.19019] ****
HKCU_Main|Default_Page_URL - hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&pver=6&ar=msnhome
HKCU_Main|Default_Search_URL - hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
HKCU_Main|Search bar - hxxp://go.microsoft.com/fwlink/?linkid=54896
HKCU_Main|Start Page - hxxp://fr.msn.com/
HKLM_Main|Default_Page_URL - hxxp://go.microsoft.com/fwlink/?LinkId=54896
HKLM_Main|Default_Search_URL - hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
HKLM_Main|Search bar - hxxp://search.msn.com/spbasic.htm
HKLM_Main|Search Page - hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
HKLM_Main|Start Page - hxxp://fr.msn.com/
HKCU_SearchScopes\{70D46D94-BF1E-45ED-B567-48701376298E} - "Google Desktop" (hxxp://127.0.0.1:4664/search&s=G2IVl71TceZdYySAzFYtZQyuHWs?q={searchTerms})
HKCU_SearchScopes\{AD22EBAF-0D18-4fc7-90CC-5EA0ABBE9EB8} - "DAEMON Search" (hxxp://www.daemon-search.com/search?q={searchTerms})
HKCU_Toolbar\WebBrowser|{32099AAC-C132-4136-9E9A-4E364A424E17} (C:\Program Files\DAEMON Tools Toolbar\DTToolbar.dll)
HKLM_Toolbar|{32099AAC-C132-4136-9E9A-4E364A424E17} (C:\Program Files\DAEMON Tools Toolbar\DTToolbar.dll)
HKCU_ElevationPolicy\{83EED7CF-C0E1-4D8F-8AD8-97966F44F8BB} - C:\Program Files\eMule\emule.exe (http://www.emule-project.net)
HKLM_ElevationPolicy\{28A36D69-07EA-44CE-B298-1A8B3E8B6FE1} - C:\Program Files\Skype\Phone\Skype.exe (Skype Technologies S.A.)
HKLM_ElevationPolicy\{70f641fd-9ffc-4d5b-a4dc-962af4ed7999} - C:\Program Files\Internet Explorer\iedw.exe (x)
HKLM_ElevationPolicy\{71274DC5-D6B8-4B74-BBCF-04D76E30772B} - C:\Program Files\Skype\Toolbars\Shared\SkypeNames2.exe (Skype Technologies S.A.)
HKLM_ElevationPolicy\{74351F14-5437-4d87-805B-04D409B09976} - C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe (Google)
HKLM_ElevationPolicy\{88B89B96-F7B2-469D-8F22-5F3BE33DEDDE} - C:\Program Files\Skype\Toolbars\Internet Explorer\SkypeIEPluginBroker.exe (Skype Technologies S.A.)
HKLM_ElevationPolicy\{A6E2003F-95C5-4591-BA9A-0093080FDB5C} - C:\Program Files\Common Files\Oberon Media\OberonBroker\1.0.0.63\OberonBroker.exe (?)
HKCU_Extensions\{00000000-0000-0000-0000-000000000000} - "Unibet" (C:\MicroGaming\Poker\unibetpokerMPP\MPPoker.exe,1)
HKLM_Extensions\{06568ceb-5721-47d4-9d93-7e604fcbaeab} - "PMU Poker" (C:\Programs\PMU\PMUPoker\images\ppicon.ico)
HKLM_Extensions\{725EC34E-943C-4df6-B0B2-FBDE7F242276} - "PartyPoker.fr" (C:\Programs\PartyFrance\PartyPokerFr\images\ppicon.ico)
HKLM_Extensions\{898EA8C8-E7FF-479B-8935-AEC46303B9E5} - "Skype add-on for Internet Explorer" (C:\Program Files\Skype\Toolbars\Internet Explorer\icon.ico)
HKLM_Extensions\{DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - "?" (?)
BHO\{53707962-6F74-2D53-2644-206D7942484F} - "Spybot-S&D IE Protection" (C:\PROGRA~1\SPYBOT~1\SDHelper.dll)
BHO\{5C255C8A-E604-49b4-9D64-90988571CECB} (?)
BHO\{AE805869-2E5C-4ED4-8F7B-F1F7851A4497} - "Skype add-on for Internet Explorer" (C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll)
========================================
C:\Program Files\Ad-Remover\Quarantine: 3 Fichier(s)
C:\Program Files\Ad-Remover\Backup: 16 Fichier(s)
C:\Ad-Report-CLEAN[1].txt - 14/02/2011 (6532 Octet(s))
C:\Ad-Report-SCAN[1].txt - 14/02/2011 (7130 Octet(s))
Fin à: 15:17:53, 14/02/2011
============== E.O.F ==============
Vous n’avez pas trouvé la réponse que vous recherchez ?
Posez votre question
relance ADR, clique sur désinstaller,
as tu désinstallé spybot ?
as tu lu mon pessage pour Boonty ?
ton pc a été rootkité, il y a également une infection de MBR qui traine !!!
Rends-toi à cette adresse :
https://www.bleepingcomputer.com/submit-malware.php?channel=12
Remplis le formulaire ainsi :
Link to topic where this file was requested:
https://forums.commentcamarche.net/forum/affich-20859434-zph-diag
Browse to the file you want to submit:
=> Sélectionne ce fichier :
C:\windows\wincra\mirc.exe
Leave any comments, further information about this file, or contact information:
=> Copie-colle ceci :
De la part de Electricien69 pour « IRCBOT ».
Merci
as tu désinstallé spybot ?
as tu lu mon pessage pour Boonty ?
ton pc a été rootkité, il y a également une infection de MBR qui traine !!!
Rends-toi à cette adresse :
https://www.bleepingcomputer.com/submit-malware.php?channel=12
Remplis le formulaire ainsi :
Link to topic where this file was requested:
https://forums.commentcamarche.net/forum/affich-20859434-zph-diag
Browse to the file you want to submit:
=> Sélectionne ce fichier :
C:\windows\wincra\mirc.exe
Leave any comments, further information about this file, or contact information:
=> Copie-colle ceci :
De la part de Electricien69 pour « IRCBOT ».
Merci
super,
on va lancer les hostilités !
suis les tapes suivantes :
* Lance ZHPFix (soit via le raccourci sur ton Bureau, soit via ZHPDiag en cliquant sur l'écusson vert)
Clique sur l'icone représentant la lettre H (« coller les lignes Helper »)
Copie/colle les lignes suivantes en gras et place les dans ZHPFix :
----------------------------------------------------------
[MD5.52F9F2101923E84DD146FD1058D97B60] - (.mIRC Co. Ltd. - mIRC.) -- C:\Windows\Wincra\mirc.exe [2076672]
O4 - HKLM\..\Run: [mirc] . (.mIRC Co. Ltd. - mIRC.) -- C:\WINDOWS\WINCRA\mirc.exe
O87 - FAEL: "TCP Query User{198811E4-08D7-4D22-B8EB-2A5099B9A608}C:\windows\wincra\mirc.exe" | In - Private - P6 - TRUE | .(.mIRC Co. Ltd. - mIRC.) -- C:\windows\wincra\mirc.exe
O87 - FAEL: "UDP Query User{32755452-2CB5-47C0-80F1-AAD9DF08EF37}C:\windows\wincra\mirc.exe" | In - Private - P17 - TRUE | .(.mIRC Co. Ltd. - mIRC.) -- C:\windows\wincra\mirc.exe
O87 - FAEL: "TCP Query User{62BCC2CD-71AE-4766-BF09-56C666AEB476}C:\windows\wincra\mirc.exe" | In - Public - P6 - TRUE | .(.mIRC Co. Ltd. - mIRC.) -- C:\windows\wincra\mirc.exe
O87 - FAEL: "UDP Query User{AAC8C20C-C5BD-41AA-9BFD-B581EB08D46D}C:\windows\wincra\mirc.exe" | In - Public - P17 - TRUE | .(.mIRC Co. Ltd. - mIRC.) -- C:\windows\wincra\mirc.exe
MBRFIX
----------------------------------------------------------
- Clique sur « Tous », puis sur « Nettoyer »
- Copie/colle la totalité du rapport dans ta prochaine réponse
Tuto :
http://www.premiumorange.com/zeb-help-process/zhpfix.html
* Télécharge TDSSKiller sur ton bureau :
https://support.kaspersky.com/downloads/utils/tdsskiller.exe
* Lance le ( Utilisateurs de vista/Seven -> Clic droit puis " Exécuter en tant qu'administrateur " )
* Clique sur [Start Scan] pour démarrer l'analyse.
* Si des élements sont trouvés, cliques sur [Continue] puis sur [Reboot Now]
* Un rapport s'ouvrira au redémarrage du PC.
* Copie/Colle son contenu dans ta prochaine réponse.
Note : Le rapport se trouve également sous C:\TDSSKiller.N°deversion_Date_Heure_log.txt.
on va lancer les hostilités !
suis les tapes suivantes :
* Lance ZHPFix (soit via le raccourci sur ton Bureau, soit via ZHPDiag en cliquant sur l'écusson vert)
Clique sur l'icone représentant la lettre H (« coller les lignes Helper »)
Copie/colle les lignes suivantes en gras et place les dans ZHPFix :
----------------------------------------------------------
[MD5.52F9F2101923E84DD146FD1058D97B60] - (.mIRC Co. Ltd. - mIRC.) -- C:\Windows\Wincra\mirc.exe [2076672]
O4 - HKLM\..\Run: [mirc] . (.mIRC Co. Ltd. - mIRC.) -- C:\WINDOWS\WINCRA\mirc.exe
O87 - FAEL: "TCP Query User{198811E4-08D7-4D22-B8EB-2A5099B9A608}C:\windows\wincra\mirc.exe" | In - Private - P6 - TRUE | .(.mIRC Co. Ltd. - mIRC.) -- C:\windows\wincra\mirc.exe
O87 - FAEL: "UDP Query User{32755452-2CB5-47C0-80F1-AAD9DF08EF37}C:\windows\wincra\mirc.exe" | In - Private - P17 - TRUE | .(.mIRC Co. Ltd. - mIRC.) -- C:\windows\wincra\mirc.exe
O87 - FAEL: "TCP Query User{62BCC2CD-71AE-4766-BF09-56C666AEB476}C:\windows\wincra\mirc.exe" | In - Public - P6 - TRUE | .(.mIRC Co. Ltd. - mIRC.) -- C:\windows\wincra\mirc.exe
O87 - FAEL: "UDP Query User{AAC8C20C-C5BD-41AA-9BFD-B581EB08D46D}C:\windows\wincra\mirc.exe" | In - Public - P17 - TRUE | .(.mIRC Co. Ltd. - mIRC.) -- C:\windows\wincra\mirc.exe
MBRFIX
----------------------------------------------------------
- Clique sur « Tous », puis sur « Nettoyer »
- Copie/colle la totalité du rapport dans ta prochaine réponse
Tuto :
http://www.premiumorange.com/zeb-help-process/zhpfix.html
* Télécharge TDSSKiller sur ton bureau :
https://support.kaspersky.com/downloads/utils/tdsskiller.exe
* Lance le ( Utilisateurs de vista/Seven -> Clic droit puis " Exécuter en tant qu'administrateur " )
* Clique sur [Start Scan] pour démarrer l'analyse.
* Si des élements sont trouvés, cliques sur [Continue] puis sur [Reboot Now]
* Un rapport s'ouvrira au redémarrage du PC.
* Copie/Colle son contenu dans ta prochaine réponse.
Note : Le rapport se trouve également sous C:\TDSSKiller.N°deversion_Date_Heure_log.txt.
Rapport de ZHPFix 1.12.3251 par Nicolas Coolman, Update du 07/02/2011
Fichier d'export Registre :
Run by jeremie at 14/02/2011 15:51:03
Windows Vista Home Premium Edition, 32-bit Service Pack 2 (Build 6002)
Web site : http://www.premiumorange.com/zeb-help-process/zhpfix.html
Contact : nicolascoolman@yahoo.fr
========== Processus mémoire ==========
C:\Windows\Wincra\mirc.exe [2076672] => Supprimé et mis en quarantaine
========== Valeur(s) du Registre ==========
O4 - HKLM\..\Run: [mirc] . (.mIRC Co. Ltd. - mIRC.) -- C:\WINDOWS\WINCRA\mirc.exe => Valeur supprimée avec succès
TCP Query User{198811E4-08D7-4D22-B8EB-2A5099B9A608}C:\windows\wincra\mirc.exe => Valeur supprimée avec succès
UDP Query User{32755452-2CB5-47C0-80F1-AAD9DF08EF37}C:\windows\wincra\mirc.exe => Valeur supprimée avec succès
TCP Query User{62BCC2CD-71AE-4766-BF09-56C666AEB476}C:\windows\wincra\mirc.exe => Valeur supprimée avec succès
UDP Query User{AAC8C20C-C5BD-41AA-9BFD-B581EB08D46D}C:\windows\wincra\mirc.exe => Valeur supprimée avec succès
========== Fichier(s) ==========
========== Master Boot Record ==========
Stealth MBR rootkit/Mebroot/Sinowal/TDL4 detector 0.4.1 by Gmer, http://www.gmer.net
Windows 6.0.6002 Disk: WDC_WD50 rev.01.0 -> \Device\Ide\IAAStorageDevice-1
device: opened successfully
user: MBR read successfully
Disk trace:
called modules: ntkrnlpa.exe CLASSPNP.SYS disk.sys iaStor.sys spkr.sys hal.dll >>UNKNOWN [0x86464938]<<
C:\Windows\system32\DRIVERS\iaStor.sys Intel Corporation Intel Matrix Storage Manager driver
System32\Drivers\spkr.sys
1 ntkrnlpa!IofCallDriver[0x8308B912] -> \Device\Harddisk0\DR0[0x87032AC8]
3 CLASSPNP[0x8B3A28B3] -> ntkrnlpa!IofCallDriver[0x8308B912] -> \Device\Ide\IAAStorageDevice-1[0x86556028]
kernel: MBR read successfully
detected hooks:
\Driver\atapi -> 0x864ad1f8
user & kernel MBR OK
Warning: possible MBR rootkit infection !
Resultat après le fix :
Stealth MBR rootkit/Mebroot/Sinowal/TDL4 detector 0.4.1 by Gmer, http://www.gmer.net
Windows 6.0.6002 Disk: WDC_WD50 rev.01.0 -> \Device\Ide\IAAStorageDevice-1
device: opened successfully
user: MBR read successfully
Disk trace:
called modules: ntkrnlpa.exe CLASSPNP.SYS disk.sys iaStor.sys spkr.sys hal.dll >>UNKNOWN [0x86464938]<<
C:\Windows\system32\DRIVERS\iaStor.sys Intel Corporation Intel Matrix Storage Manager driver
System32\Drivers\spkr.sys
1 ntkrnlpa!IofCallDriver[0x8308B912] -> \Device\Harddisk0\DR0[0x87032AC8]
3 CLASSPNP[0x8B3A28B3] -> ntkrnlpa!IofCallDriver[0x8308B912] -> \Device\Ide\IAAStorageDevice-1[0x86556028]
kernel: MBR read successfully
detected hooks:
\Driver\atapi -> 0x864ad1f8
user & kernel MBR OK
Warning: possible MBR rootkit infection !
========== Récapitulatif ==========
1 : Processus mémoire
5 : Valeur(s) du Registre
1 : Master Boot Record
End of the scan
2011/02/14 15:52:58.0447 4884 TDSS rootkit removing tool 2.4.17.0 Feb 10 2011 11:07:20
2011/02/14 15:52:58.0768 4884 ================================================================================
2011/02/14 15:52:58.0769 4884 SystemInfo:
2011/02/14 15:52:58.0769 4884
2011/02/14 15:52:58.0769 4884 OS Version: 6.0.6002 ServicePack: 2.0
2011/02/14 15:52:58.0769 4884 Product type: Workstation
2011/02/14 15:52:58.0769 4884 ComputerName: PC-DE-BUREAU
2011/02/14 15:52:58.0770 4884 UserName: jeremie
2011/02/14 15:52:58.0770 4884 Windows directory: C:\Windows
2011/02/14 15:52:58.0770 4884 System windows directory: C:\Windows
2011/02/14 15:52:58.0770 4884 Processor architecture: Intel x86
2011/02/14 15:52:58.0770 4884 Number of processors: 2
2011/02/14 15:52:58.0770 4884 Page size: 0x1000
2011/02/14 15:52:58.0770 4884 Boot type: Normal boot
2011/02/14 15:52:58.0770 4884 ================================================================================
2011/02/14 15:53:03.0804 4884 Initialize success
2011/02/14 15:53:12.0658 3416 ================================================================================
2011/02/14 15:53:12.0658 3416 Scan started
2011/02/14 15:53:12.0658 3416 Mode: Manual;
2011/02/14 15:53:12.0658 3416 ================================================================================
2011/02/14 15:53:13.0112 3416 acedrv11 (a6fe70357a68ad1e279cd1012419cce6) C:\Windows\system32\drivers\acedrv11.sys
2011/02/14 15:53:13.0200 3416 ACPI (82b296ae1892fe3dbee00c9cf92f8ac7) C:\Windows\system32\drivers\acpi.sys
2011/02/14 15:53:13.0276 3416 adp94xx (04f0fcac69c7c71a3ac4eb97fafc8303) C:\Windows\system32\drivers\adp94xx.sys
2011/02/14 15:53:13.0329 3416 adpahci (60505e0041f7751bdbb80f88bf45c2ce) C:\Windows\system32\drivers\adpahci.sys
2011/02/14 15:53:13.0363 3416 adpu160m (8a42779b02aec986eab64ecfc98f8bd7) C:\Windows\system32\drivers\adpu160m.sys
2011/02/14 15:53:13.0398 3416 adpu320 (241c9e37f8ce45ef51c3de27515ca4e5) C:\Windows\system32\drivers\adpu320.sys
2011/02/14 15:53:13.0500 3416 AFD (a201207363aa900abf1a388468688570) C:\Windows\system32\drivers\afd.sys
2011/02/14 15:53:13.0614 3416 AgereSoftModem (38325c6aa8eae011897d61ce48ec6435) C:\Windows\system32\DRIVERS\AGRSM.sys
2011/02/14 15:53:13.0692 3416 agp440 (13f9e33747e6b41a3ff305c37db0d360) C:\Windows\system32\drivers\agp440.sys
2011/02/14 15:53:13.0735 3416 aic78xx (ae1fdf7bf7bb6c6a70f67699d880592a) C:\Windows\system32\drivers\djsvs.sys
2011/02/14 15:53:13.0776 3416 aliide (9eaef5fc9b8e351afa7e78a6fae91f91) C:\Windows\system32\drivers\aliide.sys
2011/02/14 15:53:13.0819 3416 amdagp (c47344bc706e5f0b9dce369516661578) C:\Windows\system32\drivers\amdagp.sys
2011/02/14 15:53:13.0844 3416 amdide (9b78a39a4c173fdbc1321e0dd659b34c) C:\Windows\system32\drivers\amdide.sys
2011/02/14 15:53:13.0912 3416 AmdK7 (18f29b49ad23ecee3d2a826c725c8d48) C:\Windows\system32\drivers\amdk7.sys
2011/02/14 15:53:13.0943 3416 AmdK8 (93ae7f7dd54ab986a6f1a1b37be7442d) C:\Windows\system32\drivers\amdk8.sys
2011/02/14 15:53:14.0085 3416 appdrv01 (c42cad1bf0be180c84b03932428429ff) C:\Windows\system32\Drivers\appdrv01.sys
2011/02/14 15:53:14.0341 3416 arc (5d2888182fb46632511acee92fdad522) C:\Windows\system32\drivers\arc.sys
2011/02/14 15:53:14.0422 3416 arcsas (5e2a321bd7c8b3624e41fdec3e244945) C:\Windows\system32\drivers\arcsas.sys
2011/02/14 15:53:14.0481 3416 aswFsBlk (cba53c5e29ae0a0ce76f9a2be3a40d9e) C:\Windows\system32\drivers\aswFsBlk.sys
2011/02/14 15:53:14.0560 3416 aswMonFlt (317f85fb68a3be507e9ccede5e6d9ee0) C:\Windows\system32\drivers\aswMonFlt.sys
2011/02/14 15:53:14.0604 3416 aswRdr (b6e8c5874377a42756c282fac2e20836) C:\Windows\system32\drivers\aswRdr.sys
2011/02/14 15:53:14.0637 3416 aswSP (b93a553c9b0f14263c8f016a44c3258c) C:\Windows\system32\drivers\aswSP.sys
2011/02/14 15:53:14.0667 3416 aswTdi (1408421505257846eb336feeef33352d) C:\Windows\system32\drivers\aswTdi.sys
2011/02/14 15:53:14.0725 3416 AsyncMac (53b202abee6455406254444303e87be1) C:\Windows\system32\DRIVERS\asyncmac.sys
2011/02/14 15:53:14.0771 3416 atapi (1f05b78ab91c9075565a9d8a4b880bc4) C:\Windows\system32\drivers\atapi.sys
2011/02/14 15:53:14.0825 3416 athr (acdb46b1a467752a2f280c68c8461556) C:\Windows\system32\DRIVERS\athr.sys
2011/02/14 15:53:14.0922 3416 atksgt (f0d933b42cd0594048e4d5200ae9e417) C:\Windows\system32\DRIVERS\atksgt.sys
2011/02/14 15:53:15.0037 3416 b57nd60x (502f1c30bd50b32d00ce4dcaecc3d3c7) C:\Windows\system32\DRIVERS\b57nd60x.sys
2011/02/14 15:53:15.0120 3416 Beep (67e506b75bd5326a3ec7b70bd014dfb6) C:\Windows\system32\drivers\Beep.sys
2011/02/14 15:53:15.0212 3416 blbdrive (d4df28447741fd3d953526e33a617397) C:\Windows\system32\drivers\blbdrive.sys
2011/02/14 15:53:15.0266 3416 bowser (74b442b2be1260b7588c136177ceac66) C:\Windows\system32\DRIVERS\bowser.sys
2011/02/14 15:53:15.0318 3416 BrFiltLo (9f9acc7f7ccde8a15c282d3f88b43309) C:\Windows\system32\drivers\brfiltlo.sys
2011/02/14 15:53:15.0349 3416 BrFiltUp (56801ad62213a41f6497f96dee83755a) C:\Windows\system32\drivers\brfiltup.sys
2011/02/14 15:53:15.0385 3416 Brserid (b304e75cff293029eddf094246747113) C:\Windows\system32\drivers\brserid.sys
2011/02/14 15:53:15.0410 3416 BrSerWdm (203f0b1e73adadbbb7b7b1fabd901f6b) C:\Windows\system32\drivers\brserwdm.sys
2011/02/14 15:53:15.0455 3416 BrUsbMdm (bd456606156ba17e60a04e18016ae54b) C:\Windows\system32\drivers\brusbmdm.sys
2011/02/14 15:53:15.0481 3416 BrUsbSer (af72ed54503f717a43268b3cc5faec2e) C:\Windows\system32\drivers\brusbser.sys
2011/02/14 15:53:15.0518 3416 BTHMODEM (ad07c1ec6665b8b35741ab91200c6b68) C:\Windows\system32\drivers\bthmodem.sys
2011/02/14 15:53:15.0675 3416 cdfs (7add03e75beb9e6dd102c3081d29840a) C:\Windows\system32\DRIVERS\cdfs.sys
2011/02/14 15:53:15.0731 3416 cdrom (6b4bffb9becd728097024276430db314) C:\Windows\system32\DRIVERS\cdrom.sys
2011/02/14 15:53:15.0775 3416 circlass (e5d4133f37219dbcfe102bc61072589d) C:\Windows\system32\drivers\circlass.sys
2011/02/14 15:53:15.0812 3416 CLFS (d7659d3b5b92c31e84e53c1431f35132) C:\Windows\system32\CLFS.sys
2011/02/14 15:53:15.0909 3416 CmBatt (99afc3795b58cc478fbbbcdc658fcb56) C:\Windows\system32\DRIVERS\CmBatt.sys
2011/02/14 15:53:15.0957 3416 cmdide (0ca25e686a4928484e9fdabd168ab629) C:\Windows\system32\drivers\cmdide.sys
2011/02/14 15:53:15.0982 3416 Compbatt (6afef0b60fa25de07c0968983ee4f60a) C:\Windows\system32\DRIVERS\compbatt.sys
2011/02/14 15:53:16.0004 3416 crcdisk (741e9dff4f42d2d8477d0fc1dc0df871) C:\Windows\system32\drivers\crcdisk.sys
2011/02/14 15:53:16.0035 3416 Crusoe (1f07becdca750766a96cda811ba86410) C:\Windows\system32\drivers\crusoe.sys
2011/02/14 15:53:16.0121 3416 DfsC (218d8ae46c88e82014f5d73d0236d9b2) C:\Windows\system32\Drivers\dfsc.sys
2011/02/14 15:53:16.0215 3416 disk (5d4aefc3386920236a548271f8f1af6a) C:\Windows\system32\drivers\disk.sys
2011/02/14 15:53:16.0277 3416 DKbFltr (73baf270d24fe726b9cd7f80bb17a23d) C:\Windows\system32\DRIVERS\DKbFltr.sys
2011/02/14 15:53:16.0347 3416 drmkaud (97fef831ab90bee128c9af390e243f80) C:\Windows\system32\drivers\drmkaud.sys
2011/02/14 15:53:16.0413 3416 DXGKrnl (c68ac676b0ef30cfbb1080adce49eb1f) C:\Windows\System32\drivers\dxgkrnl.sys
2011/02/14 15:53:16.0469 3416 E1G60 (5425f74ac0c1dbd96a1e04f17d63f94c) C:\Windows\system32\DRIVERS\E1G60I32.sys
2011/02/14 15:53:16.0559 3416 Ecache (7f64ea048dcfac7acf8b4d7b4e6fe371) C:\Windows\system32\drivers\ecache.sys
2011/02/14 15:53:16.0659 3416 elxstor (23b62471681a124889978f6295b3f4c6) C:\Windows\system32\drivers\elxstor.sys
2011/02/14 15:53:16.0749 3416 ErrDev (3db974f3935483555d7148663f726c61) C:\Windows\system32\drivers\errdev.sys
2011/02/14 15:53:16.0839 3416 exfat (22b408651f9123527bcee54b4f6c5cae) C:\Windows\system32\drivers\exfat.sys
2011/02/14 15:53:16.0882 3416 fastfat (1e9b9a70d332103c52995e957dc09ef8) C:\Windows\system32\drivers\fastfat.sys
2011/02/14 15:53:16.0938 3416 fdc (afe1e8b9782a0dd7fb46bbd88e43f89a) C:\Windows\system32\DRIVERS\fdc.sys
2011/02/14 15:53:17.0000 3416 FileInfo (a8c0139a884861e3aae9cfe73b208a9f) C:\Windows\system32\drivers\fileinfo.sys
2011/02/14 15:53:17.0036 3416 Filetrace (0ae429a696aecbc5970e3cf2c62635ae) C:\Windows\system32\drivers\filetrace.sys
2011/02/14 15:53:17.0061 3416 flpydisk (85b7cf99d532820495d68d747fda9ebd) C:\Windows\system32\DRIVERS\flpydisk.sys
2011/02/14 15:53:17.0097 3416 FltMgr (01334f9ea68e6877c4ef05d3ea8abb05) C:\Windows\system32\drivers\fltmgr.sys
2011/02/14 15:53:17.0159 3416 Fs_Rec (65ea8b77b5851854f0c55c43fa51a198) C:\Windows\system32\drivers\Fs_Rec.sys
2011/02/14 15:53:17.0223 3416 gagp30kx (34582a6e6573d54a07ece5fe24a126b5) C:\Windows\system32\drivers\gagp30kx.sys
2011/02/14 15:53:17.0270 3416 GEARAspiWDM (8182ff89c65e4d38b2de4bb0fb18564e) C:\Windows\system32\DRIVERS\GEARAspiWDM.sys
2011/02/14 15:53:17.0344 3416 HdAudAddService (cb04c744be0a61b1d648faed182c3b59) C:\Windows\system32\drivers\HdAudio.sys
2011/02/14 15:53:17.0421 3416 HDAudBus (062452b7ffd68c8c042a6261fe8dff4a) C:\Windows\system32\DRIVERS\HDAudBus.sys
2011/02/14 15:53:17.0470 3416 HidBth (1338520e78d90154ed6be8f84de5fceb) C:\Windows\system32\drivers\hidbth.sys
2011/02/14 15:53:17.0498 3416 HidIr (ff3160c3a2445128c5a6d9b076da519e) C:\Windows\system32\drivers\hidir.sys
2011/02/14 15:53:17.0542 3416 HidUsb (cca4b519b17e23a00b826c55716809cc) C:\Windows\system32\DRIVERS\hidusb.sys
2011/02/14 15:53:17.0579 3416 HpCISSs (16ee7b23a009e00d835cdb79574a91a6) C:\Windows\system32\drivers\hpcisss.sys
2011/02/14 15:53:17.0649 3416 HTTP (f870aa3e254628ebeafe754108d664de) C:\Windows\system32\drivers\HTTP.sys
2011/02/14 15:53:17.0680 3416 i2omp (c6b032d69650985468160fc9937cf5b4) C:\Windows\system32\drivers\i2omp.sys
2011/02/14 15:53:17.0732 3416 i8042prt (22d56c8184586b7a1f6fa60be5f5a2bd) C:\Windows\system32\DRIVERS\i8042prt.sys
2011/02/14 15:53:17.0777 3416 iaStor (71ecc07bc7c5e24c3dd01d8a29a24054) C:\Windows\system32\DRIVERS\iaStor.sys
2011/02/14 15:53:17.0896 3416 iaStorV (54155ea1b0df185878e0fc9ec3ac3a14) C:\Windows\system32\drivers\iastorv.sys
2011/02/14 15:53:18.0298 3416 igfx (8266ae06df974e5ba047b3e9e9e70b3f) C:\Windows\system32\DRIVERS\igdkmd32.sys
2011/02/14 15:53:18.0476 3416 iirsp (2d077bf86e843f901d8db709c95b49a5) C:\Windows\system32\drivers\iirsp.sys
2011/02/14 15:53:18.0610 3416 IntcAzAudAddService (80919a856693b1d1d4177f11f5bda545) C:\Windows\system32\drivers\RTKVHDA.sys
2011/02/14 15:53:18.0736 3416 IntcHdmiAddService (092a78e9c6f71bf0e22379503b90e800) C:\Windows\system32\drivers\IntcHdmi.sys
2011/02/14 15:53:18.0795 3416 intelide (83aa759f3189e6370c30de5dc5590718) C:\Windows\system32\drivers\intelide.sys
2011/02/14 15:53:18.0824 3416 intelppm (224191001e78c89dfa78924c3ea595ff) C:\Windows\system32\DRIVERS\intelppm.sys
2011/02/14 15:53:18.0882 3416 IpFilterDriver (62c265c38769b864cb25b4bcf62df6c3) C:\Windows\system32\DRIVERS\ipfltdrv.sys
2011/02/14 15:53:18.0944 3416 IPMIDRV (b25aaf203552b7b3491139d582b39ad1) C:\Windows\system32\drivers\ipmidrv.sys
2011/02/14 15:53:18.0981 3416 IPNAT (8793643a67b42cec66490b2a0cf92d68) C:\Windows\system32\DRIVERS\ipnat.sys
2011/02/14 15:53:19.0040 3416 irda (e50a95179211b12946f7e035d60af560) C:\Windows\system32\DRIVERS\irda.sys
2011/02/14 15:53:19.0069 3416 IRENUM (109c0dfb82c3632fbd11949b73aeeac9) C:\Windows\system32\drivers\irenum.sys
2011/02/14 15:53:19.0127 3416 isapnp (6c70698a3e5c4376c6ab5c7c17fb0614) C:\Windows\system32\drivers\isapnp.sys
2011/02/14 15:53:19.0211 3416 iScsiPrt (232fa340531d940aac623b121a595034) C:\Windows\system32\DRIVERS\msiscsi.sys
2011/02/14 15:53:19.0260 3416 iteatapi (bced60d16156e428f8df8cf27b0df150) C:\Windows\system32\drivers\iteatapi.sys
2011/02/14 15:53:19.0303 3416 iteraid (06fa654504a498c30adca8bec4e87e7e) C:\Windows\system32\drivers\iteraid.sys
2011/02/14 15:53:19.0340 3416 k57nd60x (eac21e8014c7e6ee341afffb7e2bbd54) C:\Windows\system32\DRIVERS\k57nd60x.sys
2011/02/14 15:53:19.0363 3416 kbdclass (37605e0a8cf00cbba538e753e4344c6e) C:\Windows\system32\DRIVERS\kbdclass.sys
2011/02/14 15:53:19.0406 3416 kbdhid (18247836959ba67e3511b62846b9c2e0) C:\Windows\system32\drivers\kbdhid.sys
2011/02/14 15:53:19.0461 3416 KSecDD (86165728af9bf72d6442a894fdfb4f8b) C:\Windows\system32\Drivers\ksecdd.sys
2011/02/14 15:53:19.0564 3416 lirsgt (f8a7212d0864ef5e9185fb95e6623f4d) C:\Windows\system32\DRIVERS\lirsgt.sys
2011/02/14 15:53:19.0585 3416 lltdio (d1c5883087a0c3f1344d9d55a44901f6) C:\Windows\system32\DRIVERS\lltdio.sys
2011/02/14 15:53:19.0653 3416 LSI_FC (c7e15e82879bf3235b559563d4185365) C:\Windows\system32\drivers\lsi_fc.sys
2011/02/14 15:53:19.0688 3416 LSI_SAS (ee01ebae8c9bf0fa072e0ff68718920a) C:\Windows\system32\drivers\lsi_sas.sys
2011/02/14 15:53:19.0728 3416 LSI_SCSI (912a04696e9ca30146a62afa1463dd5c) C:\Windows\system32\drivers\lsi_scsi.sys
2011/02/14 15:53:19.0746 3416 luafv (8f5c7426567798e62a3b3614965d62cc) C:\Windows\system32\drivers\luafv.sys
2011/02/14 15:53:19.0790 3416 megasas (0001ce609d66632fa17b84705f658879) C:\Windows\system32\drivers\megasas.sys
2011/02/14 15:53:19.0842 3416 MegaSR (c252f32cd9a49dbfc25ecf26ebd51a99) C:\Windows\system32\drivers\megasr.sys
2011/02/14 15:53:19.0882 3416 Modem (e13b5ea0f51ba5b1512ec671393d09ba) C:\Windows\system32\drivers\modem.sys
2011/02/14 15:53:19.0930 3416 monitor (0a9bb33b56e294f686abb7c1e4e2d8a8) C:\Windows\system32\DRIVERS\monitor.sys
2011/02/14 15:53:19.0947 3416 mouclass (5bf6a1326a335c5298477754a506d263) C:\Windows\system32\DRIVERS\mouclass.sys
2011/02/14 15:53:19.0993 3416 mouhid (93b8d4869e12cfbe663915502900876f) C:\Windows\system32\DRIVERS\mouhid.sys
2011/02/14 15:53:20.0015 3416 MountMgr (bdafc88aa6b92f7842416ea6a48e1600) C:\Windows\system32\drivers\mountmgr.sys
2011/02/14 15:53:20.0067 3416 mpio (511d011289755dd9f9a7579fb0b064e6) C:\Windows\system32\drivers\mpio.sys
2011/02/14 15:53:20.0105 3416 mpsdrv (22241feba9b2defa669c8cb0a8dd7d2e) C:\Windows\system32\drivers\mpsdrv.sys
2011/02/14 15:53:20.0157 3416 Mraid35x (4fbbb70d30fd20ec51f80061703b001e) C:\Windows\system32\drivers\mraid35x.sys
2011/02/14 15:53:20.0196 3416 MRxDAV (82cea0395524aacfeb58ba1448e8325c) C:\Windows\system32\drivers\mrxdav.sys
2011/02/14 15:53:20.0233 3416 mrxsmb (454341e652bdf5e01b0f2140232b073e) C:\Windows\system32\DRIVERS\mrxsmb.sys
2011/02/14 15:53:20.0262 3416 mrxsmb10 (2a4901aff069944fa945ed5bbf4dcde3) C:\Windows\system32\DRIVERS\mrxsmb10.sys
2011/02/14 15:53:20.0292 3416 mrxsmb20 (28b3f1ab44bdd4432c041581412f17d9) C:\Windows\system32\DRIVERS\mrxsmb20.sys
2011/02/14 15:53:20.0341 3416 msahci (28023e86f17001f7cd9b15a5bc9ae07d) C:\Windows\system32\drivers\msahci.sys
2011/02/14 15:53:20.0376 3416 msdsm (4468b0f385a86ecddaf8d3ca662ec0e7) C:\Windows\system32\drivers\msdsm.sys
2011/02/14 15:53:20.0426 3416 Msfs (a9927f4a46b816c92f461acb90cf8515) C:\Windows\system32\drivers\Msfs.sys
2011/02/14 15:53:20.0481 3416 msisadrv (0f400e306f385c56317357d6dea56f62) C:\Windows\system32\drivers\msisadrv.sys
2011/02/14 15:53:20.0522 3416 MSKSSRV (d8c63d34d9c9e56c059e24ec7185cc07) C:\Windows\system32\drivers\MSKSSRV.sys
2011/02/14 15:53:20.0568 3416 MSPCLOCK (1d373c90d62ddb641d50e55b9e78d65e) C:\Windows\system32\drivers\MSPCLOCK.sys
2011/02/14 15:53:20.0600 3416 MSPQM (b572da05bf4e098d4bba3a4734fb505b) C:\Windows\system32\drivers\MSPQM.sys
2011/02/14 15:53:20.0639 3416 MsRPC (b49456d70555de905c311bcda6ec6adb) C:\Windows\system32\drivers\MsRPC.sys
2011/02/14 15:53:20.0673 3416 mssmbios (e384487cb84be41d09711c30ca79646c) C:\Windows\system32\DRIVERS\mssmbios.sys
2011/02/14 15:53:20.0726 3416 MSTEE (7199c1eec1e4993caf96b8c0a26bd58a) C:\Windows\system32\drivers\MSTEE.sys
2011/02/14 15:53:20.0750 3416 Mup (6a57b5733d4cb702c8ea4542e836b96c) C:\Windows\system32\Drivers\mup.sys
2011/02/14 15:53:20.0802 3416 mwlPSDFilter (2de94e435c3efde58c7b1856d4f20724) C:\Windows\system32\DRIVERS\mwlPSDFilter.sys
2011/02/14 15:53:20.0822 3416 mwlPSDNServ (61920a7146eed3d903dbbb8ec295af76) C:\Windows\system32\DRIVERS\mwlPSDNServ.sys
2011/02/14 15:53:20.0846 3416 mwlPSDVDisk (e0f49721e68ebd2983e84c44fada6665) C:\Windows\system32\DRIVERS\mwlPSDVDisk.sys
2011/02/14 15:53:20.0909 3416 NativeWifiP (85c44fdff9cf7e72a40dcb7ec06a4416) C:\Windows\system32\DRIVERS\nwifi.sys
2011/02/14 15:53:20.0988 3416 NDIS (1357274d1883f68300aeadd15d7bbb42) C:\Windows\system32\drivers\ndis.sys
2011/02/14 15:53:21.0055 3416 NdisTapi (0e186e90404980569fb449ba7519ae61) C:\Windows\system32\DRIVERS\ndistapi.sys
2011/02/14 15:53:21.0083 3416 Ndisuio (d6973aa34c4d5d76c0430b181c3cd389) C:\Windows\system32\DRIVERS\ndisuio.sys
2011/02/14 15:53:21.0121 3416 NdisWan (818f648618ae34f729fdb47ec68345c3) C:\Windows\system32\DRIVERS\ndiswan.sys
2011/02/14 15:53:21.0158 3416 NDProxy (71dab552b41936358f3b541ae5997fb3) C:\Windows\system32\drivers\NDProxy.sys
2011/02/14 15:53:21.0212 3416 NetBIOS (bcd093a5a6777cf626434568dc7dba78) C:\Windows\system32\DRIVERS\netbios.sys
2011/02/14 15:53:21.0259 3416 netbt (ecd64230a59cbd93c85f1cd1cab9f3f6) C:\Windows\system32\DRIVERS\netbt.sys
2011/02/14 15:53:21.0344 3416 nfrd960 (2e7fb731d4790a1bc6270accefacb36e) C:\Windows\system32\drivers\nfrd960.sys
2011/02/14 15:53:21.0404 3416 Npfs (d36f239d7cce1931598e8fb90a0dbc26) C:\Windows\system32\drivers\Npfs.sys
2011/02/14 15:53:21.0446 3416 NSCIRDA (6d8d2e5652fc2442c810c5d8be784148) C:\Windows\system32\DRIVERS\nscirda.sys
2011/02/14 15:53:21.0467 3416 nsiproxy (609773e344a97410ce4ebf74a8914fcf) C:\Windows\system32\drivers\nsiproxy.sys
2011/02/14 15:53:21.0543 3416 Ntfs (6a4a98cee84cf9e99564510dda4baa47) C:\Windows\system32\drivers\Ntfs.sys
2011/02/14 15:53:21.0594 3416 NTIDrvr (6dcaa65f49ef3b97a5cffc0cb5de1c2f) C:\Windows\system32\Drivers\NTIDrvr.sys
2011/02/14 15:53:21.0638 3416 ntrigdigi (e875c093aec0c978a90f30c9e0dfbb72) C:\Windows\system32\drivers\ntrigdigi.sys
2011/02/14 15:53:21.0674 3416 Null (c5dbbcda07d780bda9b685df333bb41e) C:\Windows\system32\drivers\Null.sys
2011/02/14 15:53:21.0704 3416 nvraid (2edf9e7751554b42cbb60116de727101) C:\Windows\system32\drivers\nvraid.sys
2011/02/14 15:53:21.0737 3416 nvstor (abed0c09758d1d97db0042dbb2688177) C:\Windows\system32\drivers\nvstor.sys
2011/02/14 15:53:21.0770 3416 nv_agp (18bbdf913916b71bd54575bdb6eeac0b) C:\Windows\system32\drivers\nv_agp.sys
2011/02/14 15:53:21.0858 3416 ohci1394 (790e27c3db53410b40ff9ef2fd10a1d9) C:\Windows\system32\DRIVERS\ohci1394.sys
2011/02/14 15:53:21.0920 3416 Parport (0fa9b5055484649d63c303fe404e5f4d) C:\Windows\system32\drivers\parport.sys
2011/02/14 15:53:22.0010 3416 partmgr (57389fa59a36d96b3eb09d0cb91e9cdc) C:\Windows\system32\drivers\partmgr.sys
2011/02/14 15:53:22.0044 3416 Parvdm (4f9a6a8a31413180d0fcb279ad5d8112) C:\Windows\system32\drivers\parvdm.sys
2011/02/14 15:53:22.0109 3416 pci (941dc1d19e7e8620f40bbc206981efdb) C:\Windows\system32\drivers\pci.sys
2011/02/14 15:53:22.0151 3416 pciide (fc175f5ddab666d7f4d17449a547626f) C:\Windows\system32\drivers\pciide.sys
2011/02/14 15:53:22.0208 3416 pcmcia (b7c5a8769541900f6dfa6fe0c5e4d513) C:\Windows\system32\DRIVERS\pcmcia.sys
2011/02/14 15:53:22.0283 3416 PEAUTH (6349f6ed9c623b44b52ea3c63c831a92) C:\Windows\system32\drivers\peauth.sys
2011/02/14 15:53:22.0437 3416 PptpMiniport (ecfffaec0c1ecd8dbc77f39070ea1db1) C:\Windows\system32\DRIVERS\raspptp.sys
2011/02/14 15:53:22.0474 3416 Processor (2027293619dd0f047c584cf2e7df4ffd) C:\Windows\system32\drivers\processr.sys
2011/02/14 15:53:22.0534 3416 PSched (99514faa8df93d34b5589187db3aa0ba) C:\Windows\system32\DRIVERS\pacer.sys
2011/02/14 15:53:22.0613 3416 ql2300 (0a6db55afb7820c99aa1f3a1d270f4f6) C:\Windows\system32\drivers\ql2300.sys
2011/02/14 15:53:22.0704 3416 ql40xx (81a7e5c076e59995d54bc1ed3a16e60b) C:\Windows\system32\drivers\ql40xx.sys
2011/02/14 15:53:22.0776 3416 QWAVEdrv (9f5e0e1926014d17486901c88eca2db7) C:\Windows\system32\drivers\qwavedrv.sys
2011/02/14 15:53:22.0796 3416 RasAcd (147d7f9c556d259924351feb0de606c3) C:\Windows\system32\DRIVERS\rasacd.sys
2011/02/14 15:53:22.0857 3416 Rasl2tp (a214adbaf4cb47dd2728859ef31f26b0) C:\Windows\system32\DRIVERS\rasl2tp.sys
2011/02/14 15:53:22.0940 3416 RasPppoe (509a98dd18af4375e1fc40bc175f1def) C:\Windows\system32\DRIVERS\raspppoe.sys
2011/02/14 15:53:22.0990 3416 RasSstp (2005f4a1e05fa09389ac85840f0a9e4d) C:\Windows\system32\DRIVERS\rassstp.sys
2011/02/14 15:53:23.0038 3416 rdbss (b14c9d5b9add2f84f70570bbbfaa7935) C:\Windows\system32\DRIVERS\rdbss.sys
2011/02/14 15:53:23.0075 3416 RDPCDD (89e59be9a564262a3fb6c4f4f1cd9899) C:\Windows\system32\DRIVERS\RDPCDD.sys
2011/02/14 15:53:23.0119 3416 rdpdr (fbc0bacd9c3d7f6956853f64a66e252d) C:\Windows\system32\drivers\rdpdr.sys
2011/02/14 15:53:23.0144 3416 RDPENCDD (9d91fe5286f748862ecffa05f8a0710c) C:\Windows\system32\drivers\rdpencdd.sys
2011/02/14 15:53:23.0191 3416 RDPWD (30bfbdfb7f95559ede971f9ddb9a00ba) C:\Windows\system32\drivers\RDPWD.sys
2011/02/14 15:53:23.0304 3416 rspndr (9c508f4074a39e8b4b31d27198146fad) C:\Windows\system32\DRIVERS\rspndr.sys
2011/02/14 15:53:23.0334 3416 RTSTOR (9b09f336de36a7a6ca871de8a7847b65) C:\Windows\system32\drivers\RTSTOR.SYS
2011/02/14 15:53:23.0421 3416 sbp2port (3ce8f073a557e172b330109436984e30) C:\Windows\system32\drivers\sbp2port.sys
2011/02/14 15:53:23.0489 3416 sdbus (126ea89bcc413ee45e3004fb0764888f) C:\Windows\system32\DRIVERS\sdbus.sys
2011/02/14 15:53:23.0518 3416 secdrv (90a3935d05b494a5a39d37e71f09a677) C:\Windows\system32\drivers\secdrv.sys
2011/02/14 15:53:23.0555 3416 Serenum (68e44e331d46f0fb38f0863a84cd1a31) C:\Windows\system32\drivers\serenum.sys
2011/02/14 15:53:23.0584 3416 Serial (c70d69a918b178d3c3b06339b40c2e1b) C:\Windows\system32\drivers\serial.sys
2011/02/14 15:53:23.0609 3416 sermouse (8af3d28a879bf75db53a0ee7a4289624) C:\Windows\system32\drivers\sermouse.sys
2011/02/14 15:53:23.0656 3416 sffdisk (3efa810bdca87f6ecc24f9832243fe86) C:\Windows\system32\drivers\sffdisk.sys
2011/02/14 15:53:23.0688 3416 sffp_mmc (e95d451f7ea3e583aec75f3b3ee42dc5) C:\Windows\system32\drivers\sffp_mmc.sys
2011/02/14 15:53:23.0716 3416 sffp_sd (3d0ea348784b7ac9ea9bd9f317980979) C:\Windows\system32\drivers\sffp_sd.sys
2011/02/14 15:53:23.0751 3416 sfloppy (46ed8e91793b2e6f848015445a0ac188) C:\Windows\system32\drivers\sfloppy.sys
2011/02/14 15:53:23.0798 3416 sisagp (1d76624a09a054f682d746b924e2dbc3) C:\Windows\system32\drivers\sisagp.sys
2011/02/14 15:53:23.0825 3416 SiSRaid2 (43cb7aa756c7db280d01da9b676cfde2) C:\Windows\system32\drivers\sisraid2.sys
2011/02/14 15:53:23.0853 3416 SiSRaid4 (a99c6c8b0baa970d8aa59ddc50b57f94) C:\Windows\system32\drivers\sisraid4.sys
2011/02/14 15:53:23.0904 3416 Smb (7b75299a4d201d6a6533603d6914ab04) C:\Windows\system32\DRIVERS\smb.sys
2011/02/14 15:53:23.0982 3416 spldr (7aebdeef071fe28b0eef2cdd69102bff) C:\Windows\system32\drivers\spldr.sys
2011/02/14 15:53:24.0073 3416 sptd (cdddec541bc3c96f91ecb48759673505) C:\Windows\system32\Drivers\sptd.sys
2011/02/14 15:53:24.0073 3416 Suspicious file (NoAccess): C:\Windows\system32\Drivers\sptd.sys. md5: cdddec541bc3c96f91ecb48759673505
2011/02/14 15:53:24.0081 3416 sptd - detected Locked file (1)
2011/02/14 15:53:24.0111 3416 srv (ff3cbc13db84d81f56931bc922cc37c4) C:\Windows\system32\DRIVERS\srv.sys
2011/02/14 15:53:24.0166 3416 srv2 (d15959d9f69f0d39a0153e9c244f20dd) C:\Windows\system32\DRIVERS\srv2.sys
2011/02/14 15:53:24.0188 3416 srvnet (faa0d553a49e85008c6bb3781987c574) C:\Windows\system32\DRIVERS\srvnet.sys
2011/02/14 15:53:24.0279 3416 swenum (7ba58ecf0c0a9a69d44b3dca62becf56) C:\Windows\system32\DRIVERS\swenum.sys
2011/02/14 15:53:24.0315 3416 Symc8xx (192aa3ac01df071b541094f251deed10) C:\Windows\system32\drivers\symc8xx.sys
2011/02/14 15:53:24.0344 3416 Sym_hi (8c8eb8c76736ebaf3b13b633b2e64125) C:\Windows\system32\drivers\sym_hi.sys
2011/02/14 15:53:24.0379 3416 Sym_u3 (8072af52b5fd103bbba387a1e49f62cb) C:\Windows\system32\drivers\sym_u3.sys
2011/02/14 15:53:24.0458 3416 SynTP (aee6e411a915f50101895ba8dc5c15d4) C:\Windows\system32\DRIVERS\SynTP.sys
2011/02/14 15:53:24.0682 3416 Tcpip (a474879afa4a596b3a531f3e69730dbf) C:\Windows\system32\drivers\tcpip.sys
2011/02/14 15:53:24.0830 3416 Tcpip6 (a474879afa4a596b3a531f3e69730dbf) C:\Windows\system32\DRIVERS\tcpip.sys
2011/02/14 15:53:24.0910 3416 tcpipreg (608c345a255d82a6289c2d468eb41fd7) C:\Windows\system32\drivers\tcpipreg.sys
2011/02/14 15:53:24.0990 3416 TDPIPE (5dcf5e267be67a1ae926f2df77fbcc56) C:\Windows\system32\drivers\tdpipe.sys
2011/02/14 15:53:25.0038 3416 TDTCP (389c63e32b3cefed425b61ed92d3f021) C:\Windows\system32\drivers\tdtcp.sys
2011/02/14 15:53:25.0092 3416 tdx (76b06eb8a01fc8624d699e7045303e54) C:\Windows\system32\DRIVERS\tdx.sys
2011/02/14 15:53:25.0143 3416 TermDD (3cad38910468eab9a6479e2f01db43c7) C:\Windows\system32\DRIVERS\termdd.sys
2011/02/14 15:53:25.0221 3416 tssecsrv (dcf0f056a2e4f52287264f5ab29cf206) C:\Windows\system32\DRIVERS\tssecsrv.sys
2011/02/14 15:53:25.0263 3416 tunmp (caecc0120ac49e3d2f758b9169872d38) C:\Windows\system32\DRIVERS\tunmp.sys
2011/02/14 15:53:25.0311 3416 tunnel (300db877ac094feab0be7688c3454a9c) C:\Windows\system32\DRIVERS\tunnel.sys
2011/02/14 15:53:25.0342 3416 uagp35 (7d33c4db2ce363c8518d2dfcf533941f) C:\Windows\system32\drivers\uagp35.sys
2011/02/14 15:53:25.0399 3416 udfs (d9728af68c4c7693cb100b8441cbdec6) C:\Windows\system32\DRIVERS\udfs.sys
2011/02/14 15:53:25.0465 3416 uliagpkx (b0acfdc9e4af279e9116c03e014b2b27) C:\Windows\system32\drivers\uliagpkx.sys
2011/02/14 15:53:25.0505 3416 uliahci (9224bb254f591de4ca8d572a5f0d635c) C:\Windows\system32\drivers\uliahci.sys
2011/02/14 15:53:25.0547 3416 UlSata (8514d0e5cd0534467c5fc61be94a569f) C:\Windows\system32\drivers\ulsata.sys
2011/02/14 15:53:25.0591 3416 ulsata2 (38c3c6e62b157a6bc46594fada45c62b) C:\Windows\system32\drivers\ulsata2.sys
2011/02/14 15:53:25.0620 3416 umbus (32cff9f809ae9aed85464492bf3e32d2) C:\Windows\system32\DRIVERS\umbus.sys
2011/02/14 15:53:25.0679 3416 USBAAPL (4b8a9c16b6d9258ed99c512aecb8c555) C:\Windows\system32\Drivers\usbaapl.sys
2011/02/14 15:53:25.0738 3416 usbccgp (caf811ae4c147ffcd5b51750c7f09142) C:\Windows\system32\DRIVERS\usbccgp.sys
2011/02/14 15:53:25.0766 3416 usbcir (e9476e6c486e76bc4898074768fb7131) C:\Windows\system32\drivers\usbcir.sys
2011/02/14 15:53:25.0787 3416 usbehci (79e96c23a97ce7b8f14d310da2db0c9b) C:\Windows\system32\DRIVERS\usbehci.sys
2011/02/14 15:53:25.0824 3416 usbhub (4673bbcb006af60e7abddbe7a130ba42) C:\Windows\system32\DRIVERS\usbhub.sys
2011/02/14 15:53:25.0855 3416 usbohci (38dbc7dd6cc5a72011f187425384388b) C:\Windows\system32\drivers\usbohci.sys
2011/02/14 15:53:25.0903 3416 usbprint (e75c4b5269091d15a2e7dc0b6d35f2f5) C:\Windows\system32\DRIVERS\usbprint.sys
2011/02/14 15:53:25.0968 3416 usbscan (a508c9bd8724980512136b039bba65e9) C:\Windows\system32\DRIVERS\usbscan.sys
2011/02/14 15:53:26.0021 3416 USBSTOR (be3da31c191bc222d9ad503c5224f2ad) C:\Windows\system32\DRIVERS\USBSTOR.SYS
2011/02/14 15:53:26.0047 3416 usbuhci (814d653efc4d48be3b04a307eceff56f) C:\Windows\system32\DRIVERS\usbuhci.sys
2011/02/14 15:53:26.0079 3416 usbvideo (e67998e8f14cb0627a769f6530bcb352) C:\Windows\system32\Drivers\usbvideo.sys
2011/02/14 15:53:26.0139 3416 vga (87b06e1f30b749a114f74622d013f8d4) C:\Windows\system32\DRIVERS\vgapnp.sys
2011/02/14 15:53:26.0175 3416 VgaSave (2e93ac0a1d8c79d019db6c51f036636c) C:\Windows\System32\drivers\vga.sys
2011/02/14 15:53:26.0211 3416 viaagp (5d7159def58a800d5781ba3a879627bc) C:\Windows\system32\drivers\viaagp.sys
2011/02/14 15:53:26.0246 3416 ViaC7 (c4f3a691b5bad343e6249bd8c2d45dee) C:\Windows\system32\drivers\viac7.sys
2011/02/14 15:53:26.0282 3416 viaide (aadf5587a4063f52c2c3fed7887426fc) C:\Windows\system32\drivers\viaide.sys
2011/02/14 15:53:26.0311 3416 volmgr (69503668ac66c77c6cd7af86fbdf8c43) C:\Windows\system32\drivers\volmgr.sys
2011/02/14 15:53:26.0360 3416 volmgrx (23e41b834759917bfd6b9a0d625d0c28) C:\Windows\system32\drivers\volmgrx.sys
2011/02/14 15:53:26.0393 3416 volsnap (147281c01fcb1df9252de2a10d5e7093) C:\Windows\system32\drivers\volsnap.sys
2011/02/14 15:53:26.0455 3416 vsmraid (587253e09325e6bf226b299774b728a9) C:\Windows\system32\drivers\vsmraid.sys
2011/02/14 15:53:26.0514 3416 WacomPen (48dfee8f1af7c8235d4e626f0c4fe031) C:\Windows\system32\drivers\wacompen.sys
2011/02/14 15:53:26.0551 3416 Wanarp (55201897378cca7af8b5efd874374a26) C:\Windows\system32\DRIVERS\wanarp.sys
2011/02/14 15:53:26.0574 3416 Wanarpv6 (55201897378cca7af8b5efd874374a26) C:\Windows\system32\DRIVERS\wanarp.sys
2011/02/14 15:53:26.0635 3416 Wd (78fe9542363f297b18c027b2d7e7c07f) C:\Windows\system32\drivers\wd.sys
2011/02/14 15:53:26.0693 3416 Wdf01000 (b6f0a7ad6d4bd325fbcd8bac96cd8d96) C:\Windows\system32\drivers\Wdf01000.sys
2011/02/14 15:53:26.0819 3416 WmiAcpi (2e7255d172df0b8283cdfb7b433b864e) C:\Windows\system32\DRIVERS\wmiacpi.sys
2011/02/14 15:53:26.0893 3416 WpdUsb (de9d36f91a4df3d911626643debf11ea) C:\Windows\system32\DRIVERS\wpdusb.sys
2011/02/14 15:53:26.0941 3416 ws2ifsl (e3a3cb253c0ec2494d4a61f5e43a389c) C:\Windows\system32\drivers\ws2ifsl.sys
2011/02/14 15:53:27.0036 3416 WUDFRd (ac13cb789d93412106b0fb6c7eb2bcb6) C:\Windows\system32\DRIVERS\WUDFRd.sys
2011/02/14 15:53:27.0277 3416 ================================================================================
2011/02/14 15:53:27.0277 3416 Scan finished
2011/02/14 15:53:27.0277 3416 ================================================================================
2011/02/14 15:53:27.0295 2556 Detected object count: 1
2011/02/14 15:55:02.0288 2556 Locked file(sptd) - User select action: Skip
2011/02/14 15:55:21.0472 4728 ================================================================================
2011/02/14 15:55:21.0472 4728 Scan started
2011/02/14 15:55:21.0472 4728 Mode: Manual;
2011/02/14 15:55:21.0472 4728 ================================================================================
2011/02/14 15:55:21.0800 4728 acedrv11 (a6fe70357a68ad1e279cd1012419cce6) C:\Windows\system32\drivers\acedrv11.sys
2011/02/14 15:55:21.0854 4728 ACPI (82b296ae1892fe3dbee00c9cf92f8ac7) C:\Windows\system32\drivers\acpi.sys
2011/02/14 15:55:21.0908 4728 adp94xx (04f0fcac69c7c71a3ac4eb97fafc8303) C:\Windows\system32\drivers\adp94xx.sys
2011/02/14 15:55:21.0939 4728 adpahci (60505e0041f7751bdbb80f88bf45c2ce) C:\Windows\system32\drivers\adpahci.sys
2011/02/14 15:55:21.0972 4728 adpu160m (8a42779b02aec986eab64ecfc98f8bd7) C:\Windows\system32\drivers\adpu160m.sys
2011/02/14 15:55:22.0008 4728 adpu320 (241c9e37f8ce45ef51c3de27515ca4e5) C:\Windows\system32\drivers\adpu320.sys
2011/02/14 15:55:22.0076 4728 AFD (a201207363aa900abf1a388468688570) C:\Windows\system32\drivers\afd.sys
2011/02/14 15:55:22.0157 4728 AgereSoftModem (38325c6aa8eae011897d61ce48ec6435) C:\Windows\system32\DRIVERS\AGRSM.sys
2011/02/14 15:55:22.0202 4728 agp440 (13f9e33747e6b41a3ff305c37db0d360) C:\Windows\system32\drivers\agp440.sys
2011/02/14 15:55:22.0233 4728 aic78xx (ae1fdf7bf7bb6c6a70f67699d880592a) C:\Windows\system32\drivers\djsvs.sys
2011/02/14 15:55:22.0274 4728 aliide (9eaef5fc9b8e351afa7e78a6fae91f91) C:\Windows\system32\drivers\aliide.sys
2011/02/14 15:55:22.0296 4728 amdagp (c47344bc706e5f0b9dce369516661578) C:\Windows\system32\drivers\amdagp.sys
2011/02/14 15:55:22.0321 4728 amdide (9b78a39a4c173fdbc1321e0dd659b34c) C:\Windows\system32\drivers\amdide.sys
2011/02/14 15:55:22.0344 4728 AmdK7 (18f29b49ad23ecee3d2a826c725c8d48) C:\Windows\system32\drivers\amdk7.sys
2011/02/14 15:55:22.0375 4728 AmdK8 (93ae7f7dd54ab986a6f1a1b37be7442d) C:\Windows\system32\drivers\amdk8.sys
2011/02/14 15:55:22.0484 4728 appdrv01 (c42cad1bf0be180c84b03932428429ff) C:\Windows\system32\Drivers\appdrv01.sys
2011/02/14 15:55:22.0550 4728 arc (5d2888182fb46632511acee92fdad522) C:\Windows\system32\drivers\arc.sys
2011/02/14 15:55:22.0586 4728 arcsas (5e2a321bd7c8b3624e41fdec3e244945) C:\Windows\system32\drivers\arcsas.sys
2011/02/14 15:55:22.0624 4728 aswFsBlk (cba53c5e29ae0a0ce76f9a2be3a40d9e) C:\Windows\system32\drivers\aswFsBlk.sys
2011/02/14 15:55:22.0658 4728 aswMonFlt (317f85fb68a3be507e9ccede5e6d9ee0) C:\Windows\system32\drivers\aswMonFlt.sys
2011/02/14 15:55:22.0702 4728 aswRdr (b6e8c5874377a42756c282fac2e20836) C:\Windows\system32\drivers\aswRdr.sys
2011/02/14 15:55:22.0747 4728 aswSP (b93a553c9b0f14263c8f016a44c3258c) C:\Windows\system32\drivers\aswSP.sys
2011/02/14 15:55:22.0776 4728 aswTdi (1408421505257846eb336feeef33352d) C:\Windows\system32\drivers\aswTdi.sys
2011/02/14 15:55:22.0811 4728 AsyncMac (53b202abee6455406254444303e87be1) C:\Windows\system32\DRIVERS\asyncmac.sys
2011/02/14 15:55:22.0846 4728 atapi (1f05b78ab91c9075565a9d8a4b880bc4) C:\Windows\system32\drivers\atapi.sys
2011/02/14 15:55:22.0901 4728 athr (acdb46b1a467752a2f280c68c8461556) C:\Windows\system32\DRIVERS\athr.sys
2011/02/14 15:55:22.0953 4728 atksgt (f0d933b42cd0594048e4d5200ae9e417) C:\Windows\system32\DRIVERS\atksgt.sys
2011/02/14 15:55:23.0013 4728 b57nd60x (502f1c30bd50b32d00ce4dcaecc3d3c7) C:\Windows\system32\DRIVERS\b57nd60x.sys
2011/02/14 15:55:23.0052 4728 Beep (67e506b75bd5326a3ec7b70bd014dfb6) C:\Windows\system32\drivers\Beep.sys
2011/02/14 15:55:23.0099 4728 blbdrive (d4df28447741fd3d953526e33a617397) C:\Windows\system32\drivers\blbdrive.sys
2011/02/14 15:55:23.0142 4728 bowser (74b442b2be1260b7588c136177ceac66) C:\Windows\system32\DRIVERS\bowser.sys
2011/02/14 15:55:23.0172 4728 BrFiltLo (9f9acc7f7ccde8a15c282d3f88b43309) C:\Windows\system32\drivers\brfiltlo.sys
2011/02/14 15:55:23.0214 4728 BrFiltUp (56801ad62213a41f6497f96dee83755a) C:\Windows\system32\drivers\brfiltup.sys
2011/02/14 15:55:23.0261 4728 Brserid (b304e75cff293029eddf094246747113) C:\Windows\system32\drivers\brserid.sys
2011/02/14 15:55:23.0286 4728 BrSerWdm (203f0b1e73adadbbb7b7b1fabd901f6b) C:\Windows\system32\drivers\brserwdm.sys
2011/02/14 15:55:23.0320 4728 BrUsbMdm (bd456606156ba17e60a04e18016ae54b) C:\Windows\system32\drivers\brusbmdm.sys
2011/02/14 15:55:23.0346 4728 BrUsbSer (af72ed54503f717a43268b3cc5faec2e) C:\Windows\system32\drivers\brusbser.sys
2011/02/14 15:55:23.0372 4728 BTHMODEM (ad07c1ec6665b8b35741ab91200c6b68) C:\Windows\system32\drivers\bthmodem.sys
2011/02/14 15:55:23.0496 4728 cdfs (7add03e75beb9e6dd102c3081d29840a) C:\Windows\system32\DRIVERS\cdfs.sys
2011/02/14 15:55:23.0530 4728 cdrom (6b4bffb9becd728097024276430db314) C:\Windows\system32\DRIVERS\cdrom.sys
2011/02/14 15:55:23.0562 4728 circlass (e5d4133f37219dbcfe102bc61072589d) C:\Windows\system32\drivers\circlass.sys
2011/02/14 15:55:23.0599 4728 CLFS (d7659d3b5b92c31e84e53c1431f35132) C:\Windows\system32\CLFS.sys
2011/02/14 15:55:23.0634 4728 CmBatt (99afc3795b58cc478fbbbcdc658fcb56) C:\Windows\system32\DRIVERS\CmBatt.sys
2011/02/14 15:55:23.0666 4728 cmdide (0ca25e686a4928484e9fdabd168ab629) C:\Windows\system32\drivers\cmdide.sys
2011/02/14 15:55:23.0691 4728 Compbatt (6afef0b60fa25de07c0968983ee4f60a) C:\Windows\system32\DRIVERS\compbatt.sys
2011/02/14 15:55:23.0715 4728 crcdisk (741e9dff4f42d2d8477d0fc1dc0df871) C:\Windows\system32\drivers\crcdisk.sys
2011/02/14 15:55:23.0756 4728 Crusoe (1f07becdca750766a96cda811ba86410) C:\Windows\system32\drivers\crusoe.sys
2011/02/14 15:55:23.0831 4728 DfsC (218d8ae46c88e82014f5d73d0236d9b2) C:\Windows\system32\Drivers\dfsc.sys
2011/02/14 15:55:23.0880 4728 disk (5d4aefc3386920236a548271f8f1af6a) C:\Windows\system32\drivers\disk.sys
2011/02/14 15:55:23.0908 4728 DKbFltr (73baf270d24fe726b9cd7f80bb17a23d) C:\Windows\system32\DRIVERS\DKbFltr.sys
2011/02/14 15:55:23.0968 4728 drmkaud (97fef831ab90bee128c9af390e243f80) C:\Windows\system32\drivers\drmkaud.sys
2011/02/14 15:55:24.0034 4728 DXGKrnl (c68ac676b0ef30cfbb1080adce49eb1f) C:\Windows\System32\drivers\dxgkrnl.sys
2011/02/14 15:55:24.0079 4728 E1G60 (5425f74ac0c1dbd96a1e04f17d63f94c) C:\Windows\system32\DRIVERS\E1G60I32.sys
2011/02/14 15:55:24.0135 4728 Ecache (7f64ea048dcfac7acf8b4d7b4e6fe371) C:\Windows\system32\drivers\ecache.sys
2011/02/14 15:55:24.0192 4728 elxstor (23b62471681a124889978f6295b3f4c6) C:\Windows\system32\drivers\elxstor.sys
2011/02/14 15:55:24.0247 4728 ErrDev (3db974f3935483555d7148663f726c61) C:\Windows\system32\drivers\errdev.sys
2011/02/14 15:55:24.0304 4728 exfat (22b408651f9123527bcee54b4f6c5cae) C:\Windows\system32\drivers\exfat.sys
2011/02/14 15:55:24.0347 4728 fastfat (1e9b9a70d332103c52995e957dc09ef8) C:\Windows\system32\drivers\fastfat.sys
2011/02/14 15:55:24.0381 4728 fdc (afe1e8b9782a0dd7fb46bbd88e43f89a) C:\Windows\system32\DRIVERS\fdc.sys
2011/02/14 15:55:24.0421 4728 FileInfo (a8c0139a884861e3aae9cfe73b208a9f) C:\Windows\system32\drivers\fileinfo.sys
2011/02/14 15:55:24.0457 4728 Filetrace (0ae429a696aecbc5970e3cf2c62635ae) C:\Windows\system32\drivers\filetrace.sys
2011/02/14 15:55:24.0504 4728 flpydisk (85b7cf99d532820495d68d747fda9ebd) C:\Windows\system32\DRIVERS\flpydisk.sys
2011/02/14 15:55:24.0540 4728 FltMgr (01334f9ea68e6877c4ef05d3ea8abb05) C:\Windows\system32\drivers\fltmgr.sys
2011/02/14 15:55:24.0573 4728 Fs_Rec (65ea8b77b5851854f0c55c43fa51a198) C:\Windows\system32\drivers\Fs_Rec.sys
2011/02/14 15:55:24.0610 4728 gagp30kx (34582a6e6573d54a07ece5fe24a126b5) C:\Windows\system32\drivers\gagp30kx.sys
2011/02/14 15:55:24.0657 4728 GEARAspiWDM (8182ff89c65e4d38b2de4bb0fb18564e) C:\Windows\system32\DRIVERS\GEARAspiWDM.sys
2011/02/14 15:55:24.0731 4728 HdAudAddService (cb04c744be0a61b1d648faed182c3b59) C:\Windows\system32\drivers\HdAudio.sys
2011/02/14 15:55:24.0786 4728 HDAudBus (062452b7ffd68c8c042a6261fe8dff4a) C:\Windows\system32\DRIVERS\HDAudBus.sys
2011/02/14 15:55:24.0824 4728 HidBth (1338520e78d90154ed6be8f84de5fceb) C:\Windows\system32\drivers\hidbth.sys
2011/02/14 15:55:24.0852 4728 HidIr (ff3160c3a2445128c5a6d9b076da519e) C:\Windows\system32\drivers\hidir.sys
2011/02/14 15:55:24.0907 4728 HidUsb (cca4b519b17e23a00b826c55716809cc) C:\Windows\system32\DRIVERS\hidusb.sys
2011/02/14 15:55:24.0944 4728 HpCISSs (16ee7b23a009e00d835cdb79574a91a6) C:\Windows\system32\drivers\hpcisss.sys
2011/02/14 15:55:24.0993 4728 HTTP (f870aa3e254628ebeafe754108d664de) C:\Windows\system32\drivers\HTTP.sys
2011/02/14 15:55:25.0023 4728 i2omp (c6b032d69650985468160fc9937cf5b4) C:\Windows\system32\drivers\i2omp.sys
2011/02/14 15:55:25.0053 4728 i8042prt (22d56c8184586b7a1f6fa60be5f5a2bd) C:\Windows\system32\DRIVERS\i8042prt.sys
2011/02/14 15:55:25.0097 4728 iaStor (71ecc07bc7c5e24c3dd01d8a29a24054) C:\Windows\system32\DRIVERS\iaStor.sys
2011/02/14 15:55:25.0127 4728 iaStorV (54155ea1b0df185878e0fc9ec3ac3a14) C:\Windows\system32\drivers\iastorv.sys
2011/02/14 15:55:25.0375 4728 igfx (8266ae06df974e5ba047b3e9e9e70b3f) C:\Windows\system32\DRIVERS\igdkmd32.sys
2011/02/14 15:55:25.0452 4728 iirsp (2d077bf86e843f901d8db709c95b49a5) C:\Windows\system32\drivers\iirsp.sys
2011/02/14 15:55:25.0553 4728 IntcAzAudAddService (80919a856693b1d1d4177f11f5bda545) C:\Windows\system32\drivers\RTKVHDA.sys
2011/02/14 15:55:25.0612 4728 IntcHdmiAddService (092a78e9c6f71bf0e22379503b90e800) C:\Windows\system32\drivers\IntcHdmi.sys
2011/02/14 15:55:25.0638 4728 intelide (83aa759f3189e6370c30de5dc5590718) C:\Windows\system32\drivers\intelide.sys
2011/02/14 15:55:25.0667 4728 intelppm (224191001e78c89dfa78924c3ea595ff) C:\Windows\system32\DRIVERS\intelppm.sys
2011/02/14 15:55:25.0714 4728 IpFilterDriver (62c265c38769b864cb25b4bcf62df6c3) C:\Windows\system32\DRIVERS\ipfltdrv.sys
2011/02/14 15:55:25.0765 4728 IPMIDRV (b25aaf203552b7b3491139d582b39ad1) C:\Windows\system32\drivers\ipmidrv.sys
2011/02/14 15:55:25.0791 4728 IPNAT (8793643a67b42cec66490b2a0cf92d68) C:\Windows\system32\DRIVERS\ipnat.sys
2011/02/14 15:55:25.0827 4728 irda (e50a95179211b12946f7e035d60af560) C:\Windows\system32\DRIVERS\irda.sys
2011/02/14 15:55:25.0857 4728 IRENUM (109c0dfb82c3632fbd11949b73aeeac9) C:\Windows\system32\drivers\irenum.sys
2011/02/14 15:55:25.0893 4728 isapnp (6c70698a3e5c4376c6ab5c7c17fb0614) C:\Windows\system32\drivers\isapnp.sys
2011/02/14 15:55:25.0954 4728 iScsiPrt (232fa340531d940aac623b121a595034) C:\Windows\system32\DRIVERS\msiscsi.sys
2011/02/14 15:55:25.0981 4728 iteatapi (bced60d16156e428f8df8cf27b0df150) C:\Windows\system32\drivers\iteatapi.sys
2011/02/14 15:55:26.0012 4728 iteraid (06fa654504a498c30adca8bec4e87e7e) C:\Windows\system32\drivers\iteraid.sys
2011/02/14 15:55:26.0061 4728 k57nd60x (eac21e8014c7e6ee341afffb7e2bbd54) C:\Windows\system32\DRIVERS\k57nd60x.sys
2011/02/14 15:55:26.0084 4728 kbdclass (37605e0a8cf00cbba538e753e4344c6e) C:\Windows\system32\DRIVERS\kbdclass.sys
2011/02/14 15:55:26.0116 4728 kbdhid (18247836959ba67e3511b62846b9c2e0) C:\Windows\system32\drivers\kbdhid.sys
2011/02/14 15:55:26.0170 4728 KSecDD (86165728af9bf72d6442a894fdfb4f8b) C:\Windows\system32\Drivers\ksecdd.sys
2011/02/14 15:55:26.0240 4728 lirsgt (f8a7212d0864ef5e9185fb95e6623f4d) C:\Windows\system32\DRIVERS\lirsgt.sys
2011/02/14 15:55:26.0262 4728 lltdio (d1c5883087a0c3f1344d9d55a44901f6) C:\Windows\system32\DRIVERS\lltdio.sys
2011/02/14 15:55:26.0319 4728 LSI_FC (c7e15e82879bf3235b559563d4185365) C:\Windows\system32\drivers\lsi_fc.sys
2011/02/14 15:55:26.0342 4728 LSI_SAS (ee01ebae8c9bf0fa072e0ff68718920a) C:\Windows\system32\drivers\lsi_sas.sys
2011/02/14 15:55:26.0371 4728 LSI_SCSI (912a04696e9ca30146a62afa1463dd5c) C:\Windows\system32\drivers\lsi_scsi.sys
2011/02/14 15:55:26.0388 4728 luafv (8f5c7426567798e62a3b3614965d62cc) C:\Windows\system32\drivers\luafv.sys
2011/02/14 15:55:26.0422 4728 megasas (0001ce609d66632fa17b84705f658879) C:\Windows\system32\drivers\megasas.sys
2011/02/14 15:55:26.0461 4728 MegaSR (c252f32cd9a49dbfc25ecf26ebd51a99) C:\Windows\system32\drivers\megasr.sys
2011/02/14 15:55:26.0502 4728 Modem (e13b5ea0f51ba5b1512ec671393d09ba) C:\Windows\system32\drivers\modem.sys
2011/02/14 15:55:26.0529 4728 monitor (0a9bb33b56e294f686abb7c1e4e2d8a8) C:\Windows\system32\DRIVERS\monitor.sys
2011/02/14 15:55:26.0547 4728 mouclass (5bf6a1326a335c5298477754a506d263) C:\Windows\system32\DRIVERS\mouclass.sys
2011/02/14 15:55:26.0580 4728 mouhid (93b8d4869e12cfbe663915502900876f) C:\Windows\system32\DRIVERS\mouhid.sys
2011/02/14 15:55:26.0598 4728 MountMgr (bdafc88aa6b92f7842416ea6a48e1600) C:\Windows\system32\drivers\mountmgr.sys
2011/02/14 15:55:26.0632 4728 mpio (511d011289755dd9f9a7579fb0b064e6) C:\Windows\system32\drivers\mpio.sys
2011/02/14 15:55:26.0670 4728 mpsdrv (22241feba9b2defa669c8cb0a8dd7d2e) C:\Windows\system32\drivers\mpsdrv.sys
2011/02/14 15:55:26.0700 4728 Mraid35x (4fbbb70d30fd20ec51f80061703b001e) C:\Windows\system32\drivers\mraid35x.sys
2011/02/14 15:55:26.0739 4728 MRxDAV (82cea0395524aacfeb58ba1448e8325c) C:\Windows\system32\drivers\mrxdav.sys
2011/02/14 15:55:26.0776 4728 mrxsmb (454341e652bdf5e01b0f2140232b073e) C:\Windows\system32\DRIVERS\mrxsmb.sys
2011/02/14 15:55:26.0805 4728 mrxsmb10 (2a4901aff069944fa945ed5bbf4dcde3) C:\Windows\system32\DRIVERS\mrxsmb10.sys
2011/02/14 15:55:26.0835 4728 mrxsmb20 (28b3f1ab44bdd4432c041581412f17d9) C:\Windows\system32\DRIVERS\mrxsmb20.sys
2011/02/14 15:55:26.0873 4728 msahci (28023e86f17001f7cd9b15a5bc9ae07d) C:\Windows\system32\drivers\msahci.sys
2011/02/14 15:55:26.0908 4728 msdsm (4468b0f385a86ecddaf8d3ca662ec0e7) C:\Windows\system32\drivers\msdsm.sys
2011/02/14 15:55:26.0943 4728 Msfs (a9927f4a46b816c92f461acb90cf8515) C:\Windows\system32\drivers\Msfs.sys
2011/02/14 15:55:26.0979 4728 msisadrv (0f400e306f385c56317357d6dea56f62) C:\Windows\system32\drivers\msisadrv.sys
2011/02/14 15:55:27.0020 4728 MSKSSRV (d8c63d34d9c9e56c059e24ec7185cc07) C:\Windows\system32\drivers\MSKSSRV.sys
2011/02/14 15:55:27.0044 4728 MSPCLOCK (1d373c90d62ddb641d50e55b9e78d65e) C:\Windows\system32\drivers\MSPCLOCK.sys
2011/02/14 15:55:27.0065 4728 MSPQM (b572da05bf4e098d4bba3a4734fb505b) C:\Windows\system32\drivers\MSPQM.sys
2011/02/14 15:55:27.0104 4728 MsRPC (b49456d70555de905c311bcda6ec6adb) C:\Windows\system32\drivers\MsRPC.sys
2011/02/14 15:55:27.0149 4728 mssmbios (e384487cb84be41d09711c30ca79646c) C:\Windows\system32\DRIVERS\mssmbios.sys
2011/02/14 15:55:27.0180 4728 MSTEE (7199c1eec1e4993caf96b8c0a26bd58a) C:\Windows\system32\drivers\MSTEE.sys
2011/02/14 15:55:27.0204 4728 Mup (6a57b5733d4cb702c8ea4542e836b96c) C:\Windows\system32\Drivers\mup.sys
2011/02/14 15:55:27.0234 4728 mwlPSDFilter (2de94e435c3efde58c7b1856d4f20724) C:\Windows\system32\DRIVERS\mwlPSDFilter.sys
2011/02/14 15:55:27.0265 4728 mwlPSDNServ (61920a7146eed3d903dbbb8ec295af76) C:\Windows\system32\DRIVERS\mwlPSDNServ.sys
2011/02/14 15:55:27.0289 4728 mwlPSDVDisk (e0f49721e68ebd2983e84c44fada6665) C:\Windows\system32\DRIVERS\mwlPSDVDisk.sys
2011/02/14 15:55:27.0340 4728 NativeWifiP (85c44fdff9cf7e72a40dcb7ec06a4416) C:\Windows\system32\DRIVERS\nwifi.sys
2011/02/14 15:55:27.0398 4728 NDIS (1357274d1883f68300aeadd15d7bbb42) C:\Windows\system32\drivers\ndis.sys
2011/02/14 15:55:27.0443 4728 NdisTapi (0e186e90404980569fb449ba7519ae61) C:\Windows\system32\DRIVERS\ndistapi.sys
2011/02/14 15:55:27.0471 4728 Ndisuio (d6973aa34c4d5d76c0430b181c3cd389) C:\Windows\system32\DRIVERS\ndisuio.sys
2011/02/14 15:55:27.0508 4728 NdisWan (818f648618ae34f729fdb47ec68345c3) C:\Windows\system32\DRIVERS\ndiswan.sys
2011/02/14 15:55:27.0535 4728 NDProxy (71dab552b41936358f3b541ae5997fb3) C:\Windows\system32\drivers\NDProxy.sys
2011/02/14 15:55:27.0566 4728 NetBIOS (bcd093a5a6777cf626434568dc7dba78) C:\Windows\system32\DRIVERS\netbios.sys
2011/02/14 15:55:27.0614 4728 netbt (ecd64230a59cbd93c85f1cd1cab9f3f6) C:\Windows\system32\DRIVERS\netbt.sys
2011/02/14 15:55:27.0676 4728 nfrd960 (2e7fb731d4790a1bc6270accefacb36e) C:\Windows\system32\drivers\nfrd960.sys
2011/02/14 15:55:27.0722 4728 Npfs (d36f239d7cce1931598e8fb90a0dbc26) C:\Windows\system32\drivers\Npfs.sys
2011/02/14 15:55:27.0756 4728 NSCIRDA (6d8d2e5652fc2442c810c5d8be784148) C:\Windows\system32\DRIVERS\nscirda.sys
2011/02/14 15:55:27.0783 4728 nsiproxy (609773e344a97410ce4ebf74a8914fcf) C:\Windows\system32\drivers\nsiproxy.sys
2011/02/14 15:55:27.0852 4728 Ntfs (6a4a98cee84cf9e99564510dda4baa47) C:\Windows\system32\drivers\Ntfs.sys
2011/02/14 15:55:27.0892 4728 NTIDrvr (6dcaa65f49ef3b97a5cffc0cb5de1c2f) C:\Windows\system32\Drivers\NTIDrvr.sys
2011/02/14 15:55:27.0937 4728 ntrigdigi (e875c093aec0c978a90f30c9e0dfbb72) C:\Windows\system32\drivers\ntrigdigi.sys
2011/02/14 15:55:27.0973 4728 Null (c5dbbcda07d780bda9b685df333bb41e) C:\Windows\system32\drivers\Null.sys
2011/02/14 15:55:28.0002 4728 nvraid (2edf9e7751554b42cbb60116de727101) C:\Windows\system32\drivers\nvraid.sys
2011/02/14 15:55:28.0035 4728 nvstor (abed0c09758d1d97db0042dbb2688177) C:\Windows\system32\drivers\nvstor.sys
2011/02/14 15:55:28.0068 4728 nv_agp (18bbdf913916b71bd54575bdb6eeac0b) C:\Windows\system32\drivers\nv_agp.sys
2011/02/14 15:55:28.0179 4728 ohci1394 (790e27c3db53410b40ff9ef2fd10a1d9) C:\Windows\system32\DRIVERS\ohci1394.sys
2011/02/14 15:55:28.0230 4728 Parport (0fa9b5055484649d63c303fe404e5f4d) C:\Windows\system32\drivers\parport.sys
2011/02/14 15:55:28.0264 4728 partmgr (57389fa59a36d96b3eb09d0cb91e9cdc) C:\Windows\system32\drivers\partmgr.sys
2011/02/14 15:55:28.0287 4728 Parvdm (4f9a6a8a31413180d0fcb279ad5d8112) C:\Windows\system32\drivers\parvdm.sys
2011/02/14 15:55:28.0340 4728 pci (941dc1d19e7e8620f40bbc206981efdb) C:\Windows\system32\drivers\pci.sys
2011/02/14 15:55:28.0372 4728 pciide (fc175f5ddab666d7f4d17449a547626f) C:\Windows\system32\drivers\pciide.sys
2011/02/14 15:55:28.0407 4728 pcmcia (b7c5a8769541900f6dfa6fe0c5e4d513) C:\Windows\system32\DRIVERS\pcmcia.sys
2011/02/14 15:55:28.0458 4728 PEAUTH (6349f6ed9c623b44b52ea3c63c831a92) C:\Windows\system32\drivers\peauth.sys
2011/02/14 15:55:28.0547 4728 PptpMiniport (ecfffaec0c1ecd8dbc77f39070ea1db1) C:\Windows\system32\DRIVERS\raspptp.sys
2011/02/14 15:55:28.0584 4728 Processor (2027293619dd0f047c584cf2e7df4ffd) C:\Windows\system32\drivers\processr.sys
2011/02/14 15:55:28.0633 4728 PSched (99514faa8df93d34b5589187db3aa0ba) C:\Windows\system32\DRIVERS\pacer.sys
2011/02/14 15:55:28.0689 4728 ql2300 (0a6db55afb7820c99aa1f3a1d270f4f6) C:\Windows\system32\drivers\ql2300.sys
2011/02/14 15:55:28.0725 4728 ql40xx (81a7e5c076e59995d54bc1ed3a16e60b) C:\Windows\system32\drivers\ql40xx.sys
2011/02/14 15:55:28.0764 4728 QWAVEdrv (9f5e0e1926014d17486901c88eca2db7) C:\Windows\system32\drivers\qwavedrv.sys
2011/02/14 15:55:28.0779 4728 RasAcd (147d7f9c556d259924351feb0de606c3) C:\Windows\system32\DRIVERS\rasacd.sys
2011/02/14 15:55:28.0811 4728 Rasl2tp (a214adbaf4cb47dd2728859ef31f26b0) C:\Windows\system32\DRIVERS\rasl2tp.sys
2011/02/14 15:55:28.0860 4728 RasPppoe (509a98dd18af4375e1fc40bc175f1def) C:\Windows\system32\DRIVERS\raspppoe.sys
2011/02/14 15:55:28.0888 4728 RasSstp (2005f4a1e05fa09389ac85840f0a9e4d) C:\Windows\system32\DRIVERS\rassstp.sys
2011/02/14 15:55:28.0925 4728 rdbss (b14c9d5b9add2f84f70570bbbfaa7935) C:\Windows\system32\DRIVERS\rdbss.sys
2011/02/14 15:55:28.0963 4728 RDPCDD (89e59be9a564262a3fb6c4f4f1cd9899) C:\Windows\system32\DRIVERS\RDPCDD.sys
2011/02/14 15:55:29.0006 4728 rdpdr (fbc0bacd9c3d7f6956853f64a66e252d) C:\Windows\system32\drivers\rdpdr.sys
2011/02/14 15:55:29.0022 4728 RDPENCDD (9d91fe5286f748862ecffa05f8a0710c) C:\Windows\system32\drivers\rdpencdd.sys
2011/02/14 15:55:29.0078 4728 RDPWD (30bfbdfb7f95559ede971f9ddb9a00ba) C:\Windows\system32\drivers\RDPWD.sys
2011/02/14 15:55:29.0147 4728 rspndr (9c508f4074a39e8b4b31d27198146fad) C:\Windows\system32\DRIVERS\rspndr.sys
2011/02/14 15:55:29.0188 4728 RTSTOR (9b09f336de36a7a6ca871de8a7847b65) C:\Windows\system32\drivers\RTSTOR.SYS
2011/02/14 15:55:29.0219 4728 sbp2port (3ce8f073a557e172b330109436984e30) C:\Windows\system32\drivers\sbp2port.sys
2011/02/14 15:55:29.0265 4728 sdbus (126ea89bcc413ee45e3004fb0764888f) C:\Windows\system32\DRIVERS\sdbus.sys
2011/02/14 15:55:29.0305 4728 secdrv (90a3935d05b494a5a39d37e71f09a677) C:\Windows\system32\drivers\secdrv.sys
2011/02/14 15:55:29.0342 4728 Serenum (68e44e331d46f0fb38f0863a84cd1a31) C:\Windows\system32\drivers\serenum.sys
2011/02/14 15:55:29.0372 4728 Serial (c70d69a918b178d3c3b06339b40c2e1b) C:\Windows\system32\drivers\serial.sys
2011/02/14 15:55:29.0407 4728 sermouse (8af3d28a879bf75db53a0ee7a4289624) C:\Windows\system32\drivers\sermouse.sys
2011/02/14 15:55:29.0455 4728 sffdisk (3efa810bdca87f6ecc24f9832243fe86) C:\Windows\system32\drivers\sffdisk.sys
2011/02/14 15:55:29.0487 4728 sffp_mmc (e95d451f7ea3e583aec75f3b3ee42dc5) C:\Windows\system32\drivers\sffp_mmc.sys
2011/02/14 15:55:29.0526 4728 sffp_sd (3d0ea348784b7ac9ea9bd9f317980979) C:\Windows\system32\drivers\sffp_sd.sys
2011/02/14 15:55:29.0551 4728 sfloppy (46ed8e91793b2e6f848015445a0ac188) C:\Windows\system32\drivers\sfloppy.sys
2011/02/14 15:55:29.0597 4728 sisagp (1d76624a09a054f682d746b924e2dbc3) C:\Windows\system32\drivers\sisagp.sys
2011/02/14 15:55:29.0624 4728 SiSRaid2 (43cb7aa756c7db280d01da9b676cfde2) C:\Windows\system32\drivers\sisraid2.sys
2011/02/14 15:55:29.0652 4728 SiSRaid4 (a99c6c8b0baa970d8aa59ddc50b57f94) C:\Windows\system32\drivers\sisraid4.sys
2011/02/14 15:55:29.0703 4728 Smb (7b75299a4d201d6a6533603d6914ab04) C:\Windows\system32\DRIVERS\smb.sys
2011/02/14 15:55:29.0747 4728 spldr (7aebdeef071fe28b0eef2cdd69102bff) C:\Windows\system32\drivers\spldr.sys
2011/02/14 15:55:29.0805 4728 sptd (cdddec541bc3c96f91ecb48759673505) C:\Windows\system32\Drivers\sptd.sys
2011/02/14 15:55:29.0805 4728 Suspicious file (NoAccess): C:\Windows\system32\Drivers\sptd.sys. md5: cdddec541bc3c96f91ecb48759673505
2011/02/14 15:55:29.0812 4728 sptd - detected Locked file (1)
2011/02/14 15:55:29.0842 4728 srv (ff3cbc13db84d81f56931bc922cc37c4) C:\Windows\system32\DRIVERS\srv.sys
2011/02/14 15:55:29.0887 4728 srv2 (d15959d9f69f0d39a0153e9c244f20dd) C:\Windows\system32\DRIVERS\srv2.sys
2011/02/14 15:55:29.0905 4728 srvnet (faa0d553a49e85008c6bb3781987c574) C:\Windows\system32\DRIVERS\srvnet.sys
2011/02/14 15:55:29.0948 4728 swenum (7ba58ecf0c0a9a69d44b3dca62becf56) C:\Windows\system32\DRIVERS\swenum.sys
2011/02/14 15:55:29.0992 4728 Symc8xx (192aa3ac01df071b541094f251deed10) C:\Windows\system32\drivers\symc8xx.sys
2011/02/14 15:55:30.0021 4728 Sym_hi (8c8eb8c76736ebaf3b13b633b2e64125) C:\Windows\system32\drivers\sym_hi.sys
2011/02/14 15:55:30.0056 4728 Sym_u3 (8072af52b5fd103bbba387a1e49f62cb) C:\Windows\system32\drivers\sym_u3.sys
2011/02/14 15:55:30.0101 4728 SynTP (aee6e411a915f50101895ba8dc5c15d4) C:\Windows\system32\DRIVERS\SynTP.sys
2011/02/14 15:55:30.0190 4728 Tcpip (a474879afa4a596b3a531f3e69730dbf) C:\Windows\system32\drivers\tcpip.sys
2011/02/14 15:55:30.0245 4728 Tcpip6 (a474879afa4a596b3a531f3e69730dbf) C:\Windows\system32\DRIVERS\tcpip.sys
2011/02/14 15:55:30.0298 4728 tcpipreg (608c345a255d82a6289c2d468eb41fd7) C:\Windows\system32\drivers\tcpipreg.sys
2011/02/14 15:55:30.0353 4728 TDPIPE (5dcf5e267be67a1ae926f2df77fbcc56) C:\Windows\system32\drivers\tdpipe.sys
2011/02/14 15:55:30.0381 4728 TDTCP (389c63e32b3cefed425b61ed92d3f021) C:\Windows\system32\drivers\tdtcp.sys
2011/02/14 15:55:30.0424 4728 tdx (76b06eb8a01fc8624d699e7045303e54) C:\Windows\system32\DRIVERS\tdx.sys
2011/02/14 15:55:30.0475 4728 TermDD (3cad38910468eab9a6479e2f01db43c7) C:\Windows\system32\DRIVERS\termdd.sys
2011/02/14 15:55:30.0553 4728 tssecsrv (dcf0f056a2e4f52287264f5ab29cf206) C:\Windows\system32\DRIVERS\tssecsrv.sys
2011/02/14 15:55:30.0584 4728 tunmp (caecc0120ac49e3d2f758b9169872d38) C:\Windows\system32\DRIVERS\tunmp.sys
2011/02/14 15:55:30.0620 4728 tunnel (300db877ac094feab0be7688c3454a9c) C:\Windows\system32\DRIVERS\tunnel.sys
2011/02/14 15:55:30.0652 4728 uagp35 (7d33c4db2ce363c8518d2dfcf533941f) C:\Windows\system32\drivers\uagp35.sys
2011/02/14 15:55:30.0708 4728 udfs (d9728af68c4c7693cb100b8441cbdec6) C:\Windows\system32\DRIVERS\udfs.sys
2011/02/14 15:55:30.0753 4728 uliagpkx (b0acfdc9e4af279e9116c03e014b2b27) C:\Windows\system32\drivers\uliagpkx.sys
2011/02/14 15:55:30.0803 4728 uliahci (9224bb254f591de4ca8d572a5f0d635c) C:\Windows\system32\drivers\uliahci.sys
2011/02/14 15:55:30.0834 4728 UlSata (8514d0e5cd0534467c5fc61be94a569f) C:\Windows\system32\drivers\ulsata.sys
2011/02/14 15:55:30.0878 4728 ulsata2 (38c3c6e62b157a6bc46594fada45c62b) C:\Windows\system32\drivers\ulsata2.sys
2011/02/14 15:55:30.0908 4728 umbus (32cff9f809ae9aed85464492bf3e32d2) C:\Windows\system32\DRIVERS\umbus.sys
2011/02/14 15:55:30.0956 4728 USBAAPL (4b8a9c16b6d9258ed99c512aecb8c555) C:\Windows\system32\Drivers\usbaapl.sys
2011/02/14 15:55:30.0992 4728 usbccgp (caf811ae4c147ffcd5b51750c7f09142) C:\Windows\system32\DRIVERS\usbccgp.sys
2011/02/14 15:55:31.0021 4728 usbcir (e9476e6c486e76bc4898074768fb7131) C:\Windows\system32\drivers\usbcir.sys
2011/02/14 15:55:31.0040 4728 usbehci (79e96c23a97ce7b8f14d310da2db0c9b) C:\Windows\system32\DRIVERS\usbehci.sys
2011/02/14 15:55:31.0089 4728 usbhub (4673bbcb006af60e7abddbe7a130ba42) C:\Windows\system32\DRIVERS\usbhub.sys
2011/02/14 15:55:31.0120 4728 usbohci (38dbc7dd6cc5a72011f187425384388b) C:\Windows\system32\drivers\usbohci.sys
2011/02/14 15:55:31.0179 4728 usbprint (e75c4b5269091d15a2e7d
Fichier d'export Registre :
Run by jeremie at 14/02/2011 15:51:03
Windows Vista Home Premium Edition, 32-bit Service Pack 2 (Build 6002)
Web site : http://www.premiumorange.com/zeb-help-process/zhpfix.html
Contact : nicolascoolman@yahoo.fr
========== Processus mémoire ==========
C:\Windows\Wincra\mirc.exe [2076672] => Supprimé et mis en quarantaine
========== Valeur(s) du Registre ==========
O4 - HKLM\..\Run: [mirc] . (.mIRC Co. Ltd. - mIRC.) -- C:\WINDOWS\WINCRA\mirc.exe => Valeur supprimée avec succès
TCP Query User{198811E4-08D7-4D22-B8EB-2A5099B9A608}C:\windows\wincra\mirc.exe => Valeur supprimée avec succès
UDP Query User{32755452-2CB5-47C0-80F1-AAD9DF08EF37}C:\windows\wincra\mirc.exe => Valeur supprimée avec succès
TCP Query User{62BCC2CD-71AE-4766-BF09-56C666AEB476}C:\windows\wincra\mirc.exe => Valeur supprimée avec succès
UDP Query User{AAC8C20C-C5BD-41AA-9BFD-B581EB08D46D}C:\windows\wincra\mirc.exe => Valeur supprimée avec succès
========== Fichier(s) ==========
========== Master Boot Record ==========
Stealth MBR rootkit/Mebroot/Sinowal/TDL4 detector 0.4.1 by Gmer, http://www.gmer.net
Windows 6.0.6002 Disk: WDC_WD50 rev.01.0 -> \Device\Ide\IAAStorageDevice-1
device: opened successfully
user: MBR read successfully
Disk trace:
called modules: ntkrnlpa.exe CLASSPNP.SYS disk.sys iaStor.sys spkr.sys hal.dll >>UNKNOWN [0x86464938]<<
C:\Windows\system32\DRIVERS\iaStor.sys Intel Corporation Intel Matrix Storage Manager driver
System32\Drivers\spkr.sys
1 ntkrnlpa!IofCallDriver[0x8308B912] -> \Device\Harddisk0\DR0[0x87032AC8]
3 CLASSPNP[0x8B3A28B3] -> ntkrnlpa!IofCallDriver[0x8308B912] -> \Device\Ide\IAAStorageDevice-1[0x86556028]
kernel: MBR read successfully
detected hooks:
\Driver\atapi -> 0x864ad1f8
user & kernel MBR OK
Warning: possible MBR rootkit infection !
Resultat après le fix :
Stealth MBR rootkit/Mebroot/Sinowal/TDL4 detector 0.4.1 by Gmer, http://www.gmer.net
Windows 6.0.6002 Disk: WDC_WD50 rev.01.0 -> \Device\Ide\IAAStorageDevice-1
device: opened successfully
user: MBR read successfully
Disk trace:
called modules: ntkrnlpa.exe CLASSPNP.SYS disk.sys iaStor.sys spkr.sys hal.dll >>UNKNOWN [0x86464938]<<
C:\Windows\system32\DRIVERS\iaStor.sys Intel Corporation Intel Matrix Storage Manager driver
System32\Drivers\spkr.sys
1 ntkrnlpa!IofCallDriver[0x8308B912] -> \Device\Harddisk0\DR0[0x87032AC8]
3 CLASSPNP[0x8B3A28B3] -> ntkrnlpa!IofCallDriver[0x8308B912] -> \Device\Ide\IAAStorageDevice-1[0x86556028]
kernel: MBR read successfully
detected hooks:
\Driver\atapi -> 0x864ad1f8
user & kernel MBR OK
Warning: possible MBR rootkit infection !
========== Récapitulatif ==========
1 : Processus mémoire
5 : Valeur(s) du Registre
1 : Master Boot Record
End of the scan
2011/02/14 15:52:58.0447 4884 TDSS rootkit removing tool 2.4.17.0 Feb 10 2011 11:07:20
2011/02/14 15:52:58.0768 4884 ================================================================================
2011/02/14 15:52:58.0769 4884 SystemInfo:
2011/02/14 15:52:58.0769 4884
2011/02/14 15:52:58.0769 4884 OS Version: 6.0.6002 ServicePack: 2.0
2011/02/14 15:52:58.0769 4884 Product type: Workstation
2011/02/14 15:52:58.0769 4884 ComputerName: PC-DE-BUREAU
2011/02/14 15:52:58.0770 4884 UserName: jeremie
2011/02/14 15:52:58.0770 4884 Windows directory: C:\Windows
2011/02/14 15:52:58.0770 4884 System windows directory: C:\Windows
2011/02/14 15:52:58.0770 4884 Processor architecture: Intel x86
2011/02/14 15:52:58.0770 4884 Number of processors: 2
2011/02/14 15:52:58.0770 4884 Page size: 0x1000
2011/02/14 15:52:58.0770 4884 Boot type: Normal boot
2011/02/14 15:52:58.0770 4884 ================================================================================
2011/02/14 15:53:03.0804 4884 Initialize success
2011/02/14 15:53:12.0658 3416 ================================================================================
2011/02/14 15:53:12.0658 3416 Scan started
2011/02/14 15:53:12.0658 3416 Mode: Manual;
2011/02/14 15:53:12.0658 3416 ================================================================================
2011/02/14 15:53:13.0112 3416 acedrv11 (a6fe70357a68ad1e279cd1012419cce6) C:\Windows\system32\drivers\acedrv11.sys
2011/02/14 15:53:13.0200 3416 ACPI (82b296ae1892fe3dbee00c9cf92f8ac7) C:\Windows\system32\drivers\acpi.sys
2011/02/14 15:53:13.0276 3416 adp94xx (04f0fcac69c7c71a3ac4eb97fafc8303) C:\Windows\system32\drivers\adp94xx.sys
2011/02/14 15:53:13.0329 3416 adpahci (60505e0041f7751bdbb80f88bf45c2ce) C:\Windows\system32\drivers\adpahci.sys
2011/02/14 15:53:13.0363 3416 adpu160m (8a42779b02aec986eab64ecfc98f8bd7) C:\Windows\system32\drivers\adpu160m.sys
2011/02/14 15:53:13.0398 3416 adpu320 (241c9e37f8ce45ef51c3de27515ca4e5) C:\Windows\system32\drivers\adpu320.sys
2011/02/14 15:53:13.0500 3416 AFD (a201207363aa900abf1a388468688570) C:\Windows\system32\drivers\afd.sys
2011/02/14 15:53:13.0614 3416 AgereSoftModem (38325c6aa8eae011897d61ce48ec6435) C:\Windows\system32\DRIVERS\AGRSM.sys
2011/02/14 15:53:13.0692 3416 agp440 (13f9e33747e6b41a3ff305c37db0d360) C:\Windows\system32\drivers\agp440.sys
2011/02/14 15:53:13.0735 3416 aic78xx (ae1fdf7bf7bb6c6a70f67699d880592a) C:\Windows\system32\drivers\djsvs.sys
2011/02/14 15:53:13.0776 3416 aliide (9eaef5fc9b8e351afa7e78a6fae91f91) C:\Windows\system32\drivers\aliide.sys
2011/02/14 15:53:13.0819 3416 amdagp (c47344bc706e5f0b9dce369516661578) C:\Windows\system32\drivers\amdagp.sys
2011/02/14 15:53:13.0844 3416 amdide (9b78a39a4c173fdbc1321e0dd659b34c) C:\Windows\system32\drivers\amdide.sys
2011/02/14 15:53:13.0912 3416 AmdK7 (18f29b49ad23ecee3d2a826c725c8d48) C:\Windows\system32\drivers\amdk7.sys
2011/02/14 15:53:13.0943 3416 AmdK8 (93ae7f7dd54ab986a6f1a1b37be7442d) C:\Windows\system32\drivers\amdk8.sys
2011/02/14 15:53:14.0085 3416 appdrv01 (c42cad1bf0be180c84b03932428429ff) C:\Windows\system32\Drivers\appdrv01.sys
2011/02/14 15:53:14.0341 3416 arc (5d2888182fb46632511acee92fdad522) C:\Windows\system32\drivers\arc.sys
2011/02/14 15:53:14.0422 3416 arcsas (5e2a321bd7c8b3624e41fdec3e244945) C:\Windows\system32\drivers\arcsas.sys
2011/02/14 15:53:14.0481 3416 aswFsBlk (cba53c5e29ae0a0ce76f9a2be3a40d9e) C:\Windows\system32\drivers\aswFsBlk.sys
2011/02/14 15:53:14.0560 3416 aswMonFlt (317f85fb68a3be507e9ccede5e6d9ee0) C:\Windows\system32\drivers\aswMonFlt.sys
2011/02/14 15:53:14.0604 3416 aswRdr (b6e8c5874377a42756c282fac2e20836) C:\Windows\system32\drivers\aswRdr.sys
2011/02/14 15:53:14.0637 3416 aswSP (b93a553c9b0f14263c8f016a44c3258c) C:\Windows\system32\drivers\aswSP.sys
2011/02/14 15:53:14.0667 3416 aswTdi (1408421505257846eb336feeef33352d) C:\Windows\system32\drivers\aswTdi.sys
2011/02/14 15:53:14.0725 3416 AsyncMac (53b202abee6455406254444303e87be1) C:\Windows\system32\DRIVERS\asyncmac.sys
2011/02/14 15:53:14.0771 3416 atapi (1f05b78ab91c9075565a9d8a4b880bc4) C:\Windows\system32\drivers\atapi.sys
2011/02/14 15:53:14.0825 3416 athr (acdb46b1a467752a2f280c68c8461556) C:\Windows\system32\DRIVERS\athr.sys
2011/02/14 15:53:14.0922 3416 atksgt (f0d933b42cd0594048e4d5200ae9e417) C:\Windows\system32\DRIVERS\atksgt.sys
2011/02/14 15:53:15.0037 3416 b57nd60x (502f1c30bd50b32d00ce4dcaecc3d3c7) C:\Windows\system32\DRIVERS\b57nd60x.sys
2011/02/14 15:53:15.0120 3416 Beep (67e506b75bd5326a3ec7b70bd014dfb6) C:\Windows\system32\drivers\Beep.sys
2011/02/14 15:53:15.0212 3416 blbdrive (d4df28447741fd3d953526e33a617397) C:\Windows\system32\drivers\blbdrive.sys
2011/02/14 15:53:15.0266 3416 bowser (74b442b2be1260b7588c136177ceac66) C:\Windows\system32\DRIVERS\bowser.sys
2011/02/14 15:53:15.0318 3416 BrFiltLo (9f9acc7f7ccde8a15c282d3f88b43309) C:\Windows\system32\drivers\brfiltlo.sys
2011/02/14 15:53:15.0349 3416 BrFiltUp (56801ad62213a41f6497f96dee83755a) C:\Windows\system32\drivers\brfiltup.sys
2011/02/14 15:53:15.0385 3416 Brserid (b304e75cff293029eddf094246747113) C:\Windows\system32\drivers\brserid.sys
2011/02/14 15:53:15.0410 3416 BrSerWdm (203f0b1e73adadbbb7b7b1fabd901f6b) C:\Windows\system32\drivers\brserwdm.sys
2011/02/14 15:53:15.0455 3416 BrUsbMdm (bd456606156ba17e60a04e18016ae54b) C:\Windows\system32\drivers\brusbmdm.sys
2011/02/14 15:53:15.0481 3416 BrUsbSer (af72ed54503f717a43268b3cc5faec2e) C:\Windows\system32\drivers\brusbser.sys
2011/02/14 15:53:15.0518 3416 BTHMODEM (ad07c1ec6665b8b35741ab91200c6b68) C:\Windows\system32\drivers\bthmodem.sys
2011/02/14 15:53:15.0675 3416 cdfs (7add03e75beb9e6dd102c3081d29840a) C:\Windows\system32\DRIVERS\cdfs.sys
2011/02/14 15:53:15.0731 3416 cdrom (6b4bffb9becd728097024276430db314) C:\Windows\system32\DRIVERS\cdrom.sys
2011/02/14 15:53:15.0775 3416 circlass (e5d4133f37219dbcfe102bc61072589d) C:\Windows\system32\drivers\circlass.sys
2011/02/14 15:53:15.0812 3416 CLFS (d7659d3b5b92c31e84e53c1431f35132) C:\Windows\system32\CLFS.sys
2011/02/14 15:53:15.0909 3416 CmBatt (99afc3795b58cc478fbbbcdc658fcb56) C:\Windows\system32\DRIVERS\CmBatt.sys
2011/02/14 15:53:15.0957 3416 cmdide (0ca25e686a4928484e9fdabd168ab629) C:\Windows\system32\drivers\cmdide.sys
2011/02/14 15:53:15.0982 3416 Compbatt (6afef0b60fa25de07c0968983ee4f60a) C:\Windows\system32\DRIVERS\compbatt.sys
2011/02/14 15:53:16.0004 3416 crcdisk (741e9dff4f42d2d8477d0fc1dc0df871) C:\Windows\system32\drivers\crcdisk.sys
2011/02/14 15:53:16.0035 3416 Crusoe (1f07becdca750766a96cda811ba86410) C:\Windows\system32\drivers\crusoe.sys
2011/02/14 15:53:16.0121 3416 DfsC (218d8ae46c88e82014f5d73d0236d9b2) C:\Windows\system32\Drivers\dfsc.sys
2011/02/14 15:53:16.0215 3416 disk (5d4aefc3386920236a548271f8f1af6a) C:\Windows\system32\drivers\disk.sys
2011/02/14 15:53:16.0277 3416 DKbFltr (73baf270d24fe726b9cd7f80bb17a23d) C:\Windows\system32\DRIVERS\DKbFltr.sys
2011/02/14 15:53:16.0347 3416 drmkaud (97fef831ab90bee128c9af390e243f80) C:\Windows\system32\drivers\drmkaud.sys
2011/02/14 15:53:16.0413 3416 DXGKrnl (c68ac676b0ef30cfbb1080adce49eb1f) C:\Windows\System32\drivers\dxgkrnl.sys
2011/02/14 15:53:16.0469 3416 E1G60 (5425f74ac0c1dbd96a1e04f17d63f94c) C:\Windows\system32\DRIVERS\E1G60I32.sys
2011/02/14 15:53:16.0559 3416 Ecache (7f64ea048dcfac7acf8b4d7b4e6fe371) C:\Windows\system32\drivers\ecache.sys
2011/02/14 15:53:16.0659 3416 elxstor (23b62471681a124889978f6295b3f4c6) C:\Windows\system32\drivers\elxstor.sys
2011/02/14 15:53:16.0749 3416 ErrDev (3db974f3935483555d7148663f726c61) C:\Windows\system32\drivers\errdev.sys
2011/02/14 15:53:16.0839 3416 exfat (22b408651f9123527bcee54b4f6c5cae) C:\Windows\system32\drivers\exfat.sys
2011/02/14 15:53:16.0882 3416 fastfat (1e9b9a70d332103c52995e957dc09ef8) C:\Windows\system32\drivers\fastfat.sys
2011/02/14 15:53:16.0938 3416 fdc (afe1e8b9782a0dd7fb46bbd88e43f89a) C:\Windows\system32\DRIVERS\fdc.sys
2011/02/14 15:53:17.0000 3416 FileInfo (a8c0139a884861e3aae9cfe73b208a9f) C:\Windows\system32\drivers\fileinfo.sys
2011/02/14 15:53:17.0036 3416 Filetrace (0ae429a696aecbc5970e3cf2c62635ae) C:\Windows\system32\drivers\filetrace.sys
2011/02/14 15:53:17.0061 3416 flpydisk (85b7cf99d532820495d68d747fda9ebd) C:\Windows\system32\DRIVERS\flpydisk.sys
2011/02/14 15:53:17.0097 3416 FltMgr (01334f9ea68e6877c4ef05d3ea8abb05) C:\Windows\system32\drivers\fltmgr.sys
2011/02/14 15:53:17.0159 3416 Fs_Rec (65ea8b77b5851854f0c55c43fa51a198) C:\Windows\system32\drivers\Fs_Rec.sys
2011/02/14 15:53:17.0223 3416 gagp30kx (34582a6e6573d54a07ece5fe24a126b5) C:\Windows\system32\drivers\gagp30kx.sys
2011/02/14 15:53:17.0270 3416 GEARAspiWDM (8182ff89c65e4d38b2de4bb0fb18564e) C:\Windows\system32\DRIVERS\GEARAspiWDM.sys
2011/02/14 15:53:17.0344 3416 HdAudAddService (cb04c744be0a61b1d648faed182c3b59) C:\Windows\system32\drivers\HdAudio.sys
2011/02/14 15:53:17.0421 3416 HDAudBus (062452b7ffd68c8c042a6261fe8dff4a) C:\Windows\system32\DRIVERS\HDAudBus.sys
2011/02/14 15:53:17.0470 3416 HidBth (1338520e78d90154ed6be8f84de5fceb) C:\Windows\system32\drivers\hidbth.sys
2011/02/14 15:53:17.0498 3416 HidIr (ff3160c3a2445128c5a6d9b076da519e) C:\Windows\system32\drivers\hidir.sys
2011/02/14 15:53:17.0542 3416 HidUsb (cca4b519b17e23a00b826c55716809cc) C:\Windows\system32\DRIVERS\hidusb.sys
2011/02/14 15:53:17.0579 3416 HpCISSs (16ee7b23a009e00d835cdb79574a91a6) C:\Windows\system32\drivers\hpcisss.sys
2011/02/14 15:53:17.0649 3416 HTTP (f870aa3e254628ebeafe754108d664de) C:\Windows\system32\drivers\HTTP.sys
2011/02/14 15:53:17.0680 3416 i2omp (c6b032d69650985468160fc9937cf5b4) C:\Windows\system32\drivers\i2omp.sys
2011/02/14 15:53:17.0732 3416 i8042prt (22d56c8184586b7a1f6fa60be5f5a2bd) C:\Windows\system32\DRIVERS\i8042prt.sys
2011/02/14 15:53:17.0777 3416 iaStor (71ecc07bc7c5e24c3dd01d8a29a24054) C:\Windows\system32\DRIVERS\iaStor.sys
2011/02/14 15:53:17.0896 3416 iaStorV (54155ea1b0df185878e0fc9ec3ac3a14) C:\Windows\system32\drivers\iastorv.sys
2011/02/14 15:53:18.0298 3416 igfx (8266ae06df974e5ba047b3e9e9e70b3f) C:\Windows\system32\DRIVERS\igdkmd32.sys
2011/02/14 15:53:18.0476 3416 iirsp (2d077bf86e843f901d8db709c95b49a5) C:\Windows\system32\drivers\iirsp.sys
2011/02/14 15:53:18.0610 3416 IntcAzAudAddService (80919a856693b1d1d4177f11f5bda545) C:\Windows\system32\drivers\RTKVHDA.sys
2011/02/14 15:53:18.0736 3416 IntcHdmiAddService (092a78e9c6f71bf0e22379503b90e800) C:\Windows\system32\drivers\IntcHdmi.sys
2011/02/14 15:53:18.0795 3416 intelide (83aa759f3189e6370c30de5dc5590718) C:\Windows\system32\drivers\intelide.sys
2011/02/14 15:53:18.0824 3416 intelppm (224191001e78c89dfa78924c3ea595ff) C:\Windows\system32\DRIVERS\intelppm.sys
2011/02/14 15:53:18.0882 3416 IpFilterDriver (62c265c38769b864cb25b4bcf62df6c3) C:\Windows\system32\DRIVERS\ipfltdrv.sys
2011/02/14 15:53:18.0944 3416 IPMIDRV (b25aaf203552b7b3491139d582b39ad1) C:\Windows\system32\drivers\ipmidrv.sys
2011/02/14 15:53:18.0981 3416 IPNAT (8793643a67b42cec66490b2a0cf92d68) C:\Windows\system32\DRIVERS\ipnat.sys
2011/02/14 15:53:19.0040 3416 irda (e50a95179211b12946f7e035d60af560) C:\Windows\system32\DRIVERS\irda.sys
2011/02/14 15:53:19.0069 3416 IRENUM (109c0dfb82c3632fbd11949b73aeeac9) C:\Windows\system32\drivers\irenum.sys
2011/02/14 15:53:19.0127 3416 isapnp (6c70698a3e5c4376c6ab5c7c17fb0614) C:\Windows\system32\drivers\isapnp.sys
2011/02/14 15:53:19.0211 3416 iScsiPrt (232fa340531d940aac623b121a595034) C:\Windows\system32\DRIVERS\msiscsi.sys
2011/02/14 15:53:19.0260 3416 iteatapi (bced60d16156e428f8df8cf27b0df150) C:\Windows\system32\drivers\iteatapi.sys
2011/02/14 15:53:19.0303 3416 iteraid (06fa654504a498c30adca8bec4e87e7e) C:\Windows\system32\drivers\iteraid.sys
2011/02/14 15:53:19.0340 3416 k57nd60x (eac21e8014c7e6ee341afffb7e2bbd54) C:\Windows\system32\DRIVERS\k57nd60x.sys
2011/02/14 15:53:19.0363 3416 kbdclass (37605e0a8cf00cbba538e753e4344c6e) C:\Windows\system32\DRIVERS\kbdclass.sys
2011/02/14 15:53:19.0406 3416 kbdhid (18247836959ba67e3511b62846b9c2e0) C:\Windows\system32\drivers\kbdhid.sys
2011/02/14 15:53:19.0461 3416 KSecDD (86165728af9bf72d6442a894fdfb4f8b) C:\Windows\system32\Drivers\ksecdd.sys
2011/02/14 15:53:19.0564 3416 lirsgt (f8a7212d0864ef5e9185fb95e6623f4d) C:\Windows\system32\DRIVERS\lirsgt.sys
2011/02/14 15:53:19.0585 3416 lltdio (d1c5883087a0c3f1344d9d55a44901f6) C:\Windows\system32\DRIVERS\lltdio.sys
2011/02/14 15:53:19.0653 3416 LSI_FC (c7e15e82879bf3235b559563d4185365) C:\Windows\system32\drivers\lsi_fc.sys
2011/02/14 15:53:19.0688 3416 LSI_SAS (ee01ebae8c9bf0fa072e0ff68718920a) C:\Windows\system32\drivers\lsi_sas.sys
2011/02/14 15:53:19.0728 3416 LSI_SCSI (912a04696e9ca30146a62afa1463dd5c) C:\Windows\system32\drivers\lsi_scsi.sys
2011/02/14 15:53:19.0746 3416 luafv (8f5c7426567798e62a3b3614965d62cc) C:\Windows\system32\drivers\luafv.sys
2011/02/14 15:53:19.0790 3416 megasas (0001ce609d66632fa17b84705f658879) C:\Windows\system32\drivers\megasas.sys
2011/02/14 15:53:19.0842 3416 MegaSR (c252f32cd9a49dbfc25ecf26ebd51a99) C:\Windows\system32\drivers\megasr.sys
2011/02/14 15:53:19.0882 3416 Modem (e13b5ea0f51ba5b1512ec671393d09ba) C:\Windows\system32\drivers\modem.sys
2011/02/14 15:53:19.0930 3416 monitor (0a9bb33b56e294f686abb7c1e4e2d8a8) C:\Windows\system32\DRIVERS\monitor.sys
2011/02/14 15:53:19.0947 3416 mouclass (5bf6a1326a335c5298477754a506d263) C:\Windows\system32\DRIVERS\mouclass.sys
2011/02/14 15:53:19.0993 3416 mouhid (93b8d4869e12cfbe663915502900876f) C:\Windows\system32\DRIVERS\mouhid.sys
2011/02/14 15:53:20.0015 3416 MountMgr (bdafc88aa6b92f7842416ea6a48e1600) C:\Windows\system32\drivers\mountmgr.sys
2011/02/14 15:53:20.0067 3416 mpio (511d011289755dd9f9a7579fb0b064e6) C:\Windows\system32\drivers\mpio.sys
2011/02/14 15:53:20.0105 3416 mpsdrv (22241feba9b2defa669c8cb0a8dd7d2e) C:\Windows\system32\drivers\mpsdrv.sys
2011/02/14 15:53:20.0157 3416 Mraid35x (4fbbb70d30fd20ec51f80061703b001e) C:\Windows\system32\drivers\mraid35x.sys
2011/02/14 15:53:20.0196 3416 MRxDAV (82cea0395524aacfeb58ba1448e8325c) C:\Windows\system32\drivers\mrxdav.sys
2011/02/14 15:53:20.0233 3416 mrxsmb (454341e652bdf5e01b0f2140232b073e) C:\Windows\system32\DRIVERS\mrxsmb.sys
2011/02/14 15:53:20.0262 3416 mrxsmb10 (2a4901aff069944fa945ed5bbf4dcde3) C:\Windows\system32\DRIVERS\mrxsmb10.sys
2011/02/14 15:53:20.0292 3416 mrxsmb20 (28b3f1ab44bdd4432c041581412f17d9) C:\Windows\system32\DRIVERS\mrxsmb20.sys
2011/02/14 15:53:20.0341 3416 msahci (28023e86f17001f7cd9b15a5bc9ae07d) C:\Windows\system32\drivers\msahci.sys
2011/02/14 15:53:20.0376 3416 msdsm (4468b0f385a86ecddaf8d3ca662ec0e7) C:\Windows\system32\drivers\msdsm.sys
2011/02/14 15:53:20.0426 3416 Msfs (a9927f4a46b816c92f461acb90cf8515) C:\Windows\system32\drivers\Msfs.sys
2011/02/14 15:53:20.0481 3416 msisadrv (0f400e306f385c56317357d6dea56f62) C:\Windows\system32\drivers\msisadrv.sys
2011/02/14 15:53:20.0522 3416 MSKSSRV (d8c63d34d9c9e56c059e24ec7185cc07) C:\Windows\system32\drivers\MSKSSRV.sys
2011/02/14 15:53:20.0568 3416 MSPCLOCK (1d373c90d62ddb641d50e55b9e78d65e) C:\Windows\system32\drivers\MSPCLOCK.sys
2011/02/14 15:53:20.0600 3416 MSPQM (b572da05bf4e098d4bba3a4734fb505b) C:\Windows\system32\drivers\MSPQM.sys
2011/02/14 15:53:20.0639 3416 MsRPC (b49456d70555de905c311bcda6ec6adb) C:\Windows\system32\drivers\MsRPC.sys
2011/02/14 15:53:20.0673 3416 mssmbios (e384487cb84be41d09711c30ca79646c) C:\Windows\system32\DRIVERS\mssmbios.sys
2011/02/14 15:53:20.0726 3416 MSTEE (7199c1eec1e4993caf96b8c0a26bd58a) C:\Windows\system32\drivers\MSTEE.sys
2011/02/14 15:53:20.0750 3416 Mup (6a57b5733d4cb702c8ea4542e836b96c) C:\Windows\system32\Drivers\mup.sys
2011/02/14 15:53:20.0802 3416 mwlPSDFilter (2de94e435c3efde58c7b1856d4f20724) C:\Windows\system32\DRIVERS\mwlPSDFilter.sys
2011/02/14 15:53:20.0822 3416 mwlPSDNServ (61920a7146eed3d903dbbb8ec295af76) C:\Windows\system32\DRIVERS\mwlPSDNServ.sys
2011/02/14 15:53:20.0846 3416 mwlPSDVDisk (e0f49721e68ebd2983e84c44fada6665) C:\Windows\system32\DRIVERS\mwlPSDVDisk.sys
2011/02/14 15:53:20.0909 3416 NativeWifiP (85c44fdff9cf7e72a40dcb7ec06a4416) C:\Windows\system32\DRIVERS\nwifi.sys
2011/02/14 15:53:20.0988 3416 NDIS (1357274d1883f68300aeadd15d7bbb42) C:\Windows\system32\drivers\ndis.sys
2011/02/14 15:53:21.0055 3416 NdisTapi (0e186e90404980569fb449ba7519ae61) C:\Windows\system32\DRIVERS\ndistapi.sys
2011/02/14 15:53:21.0083 3416 Ndisuio (d6973aa34c4d5d76c0430b181c3cd389) C:\Windows\system32\DRIVERS\ndisuio.sys
2011/02/14 15:53:21.0121 3416 NdisWan (818f648618ae34f729fdb47ec68345c3) C:\Windows\system32\DRIVERS\ndiswan.sys
2011/02/14 15:53:21.0158 3416 NDProxy (71dab552b41936358f3b541ae5997fb3) C:\Windows\system32\drivers\NDProxy.sys
2011/02/14 15:53:21.0212 3416 NetBIOS (bcd093a5a6777cf626434568dc7dba78) C:\Windows\system32\DRIVERS\netbios.sys
2011/02/14 15:53:21.0259 3416 netbt (ecd64230a59cbd93c85f1cd1cab9f3f6) C:\Windows\system32\DRIVERS\netbt.sys
2011/02/14 15:53:21.0344 3416 nfrd960 (2e7fb731d4790a1bc6270accefacb36e) C:\Windows\system32\drivers\nfrd960.sys
2011/02/14 15:53:21.0404 3416 Npfs (d36f239d7cce1931598e8fb90a0dbc26) C:\Windows\system32\drivers\Npfs.sys
2011/02/14 15:53:21.0446 3416 NSCIRDA (6d8d2e5652fc2442c810c5d8be784148) C:\Windows\system32\DRIVERS\nscirda.sys
2011/02/14 15:53:21.0467 3416 nsiproxy (609773e344a97410ce4ebf74a8914fcf) C:\Windows\system32\drivers\nsiproxy.sys
2011/02/14 15:53:21.0543 3416 Ntfs (6a4a98cee84cf9e99564510dda4baa47) C:\Windows\system32\drivers\Ntfs.sys
2011/02/14 15:53:21.0594 3416 NTIDrvr (6dcaa65f49ef3b97a5cffc0cb5de1c2f) C:\Windows\system32\Drivers\NTIDrvr.sys
2011/02/14 15:53:21.0638 3416 ntrigdigi (e875c093aec0c978a90f30c9e0dfbb72) C:\Windows\system32\drivers\ntrigdigi.sys
2011/02/14 15:53:21.0674 3416 Null (c5dbbcda07d780bda9b685df333bb41e) C:\Windows\system32\drivers\Null.sys
2011/02/14 15:53:21.0704 3416 nvraid (2edf9e7751554b42cbb60116de727101) C:\Windows\system32\drivers\nvraid.sys
2011/02/14 15:53:21.0737 3416 nvstor (abed0c09758d1d97db0042dbb2688177) C:\Windows\system32\drivers\nvstor.sys
2011/02/14 15:53:21.0770 3416 nv_agp (18bbdf913916b71bd54575bdb6eeac0b) C:\Windows\system32\drivers\nv_agp.sys
2011/02/14 15:53:21.0858 3416 ohci1394 (790e27c3db53410b40ff9ef2fd10a1d9) C:\Windows\system32\DRIVERS\ohci1394.sys
2011/02/14 15:53:21.0920 3416 Parport (0fa9b5055484649d63c303fe404e5f4d) C:\Windows\system32\drivers\parport.sys
2011/02/14 15:53:22.0010 3416 partmgr (57389fa59a36d96b3eb09d0cb91e9cdc) C:\Windows\system32\drivers\partmgr.sys
2011/02/14 15:53:22.0044 3416 Parvdm (4f9a6a8a31413180d0fcb279ad5d8112) C:\Windows\system32\drivers\parvdm.sys
2011/02/14 15:53:22.0109 3416 pci (941dc1d19e7e8620f40bbc206981efdb) C:\Windows\system32\drivers\pci.sys
2011/02/14 15:53:22.0151 3416 pciide (fc175f5ddab666d7f4d17449a547626f) C:\Windows\system32\drivers\pciide.sys
2011/02/14 15:53:22.0208 3416 pcmcia (b7c5a8769541900f6dfa6fe0c5e4d513) C:\Windows\system32\DRIVERS\pcmcia.sys
2011/02/14 15:53:22.0283 3416 PEAUTH (6349f6ed9c623b44b52ea3c63c831a92) C:\Windows\system32\drivers\peauth.sys
2011/02/14 15:53:22.0437 3416 PptpMiniport (ecfffaec0c1ecd8dbc77f39070ea1db1) C:\Windows\system32\DRIVERS\raspptp.sys
2011/02/14 15:53:22.0474 3416 Processor (2027293619dd0f047c584cf2e7df4ffd) C:\Windows\system32\drivers\processr.sys
2011/02/14 15:53:22.0534 3416 PSched (99514faa8df93d34b5589187db3aa0ba) C:\Windows\system32\DRIVERS\pacer.sys
2011/02/14 15:53:22.0613 3416 ql2300 (0a6db55afb7820c99aa1f3a1d270f4f6) C:\Windows\system32\drivers\ql2300.sys
2011/02/14 15:53:22.0704 3416 ql40xx (81a7e5c076e59995d54bc1ed3a16e60b) C:\Windows\system32\drivers\ql40xx.sys
2011/02/14 15:53:22.0776 3416 QWAVEdrv (9f5e0e1926014d17486901c88eca2db7) C:\Windows\system32\drivers\qwavedrv.sys
2011/02/14 15:53:22.0796 3416 RasAcd (147d7f9c556d259924351feb0de606c3) C:\Windows\system32\DRIVERS\rasacd.sys
2011/02/14 15:53:22.0857 3416 Rasl2tp (a214adbaf4cb47dd2728859ef31f26b0) C:\Windows\system32\DRIVERS\rasl2tp.sys
2011/02/14 15:53:22.0940 3416 RasPppoe (509a98dd18af4375e1fc40bc175f1def) C:\Windows\system32\DRIVERS\raspppoe.sys
2011/02/14 15:53:22.0990 3416 RasSstp (2005f4a1e05fa09389ac85840f0a9e4d) C:\Windows\system32\DRIVERS\rassstp.sys
2011/02/14 15:53:23.0038 3416 rdbss (b14c9d5b9add2f84f70570bbbfaa7935) C:\Windows\system32\DRIVERS\rdbss.sys
2011/02/14 15:53:23.0075 3416 RDPCDD (89e59be9a564262a3fb6c4f4f1cd9899) C:\Windows\system32\DRIVERS\RDPCDD.sys
2011/02/14 15:53:23.0119 3416 rdpdr (fbc0bacd9c3d7f6956853f64a66e252d) C:\Windows\system32\drivers\rdpdr.sys
2011/02/14 15:53:23.0144 3416 RDPENCDD (9d91fe5286f748862ecffa05f8a0710c) C:\Windows\system32\drivers\rdpencdd.sys
2011/02/14 15:53:23.0191 3416 RDPWD (30bfbdfb7f95559ede971f9ddb9a00ba) C:\Windows\system32\drivers\RDPWD.sys
2011/02/14 15:53:23.0304 3416 rspndr (9c508f4074a39e8b4b31d27198146fad) C:\Windows\system32\DRIVERS\rspndr.sys
2011/02/14 15:53:23.0334 3416 RTSTOR (9b09f336de36a7a6ca871de8a7847b65) C:\Windows\system32\drivers\RTSTOR.SYS
2011/02/14 15:53:23.0421 3416 sbp2port (3ce8f073a557e172b330109436984e30) C:\Windows\system32\drivers\sbp2port.sys
2011/02/14 15:53:23.0489 3416 sdbus (126ea89bcc413ee45e3004fb0764888f) C:\Windows\system32\DRIVERS\sdbus.sys
2011/02/14 15:53:23.0518 3416 secdrv (90a3935d05b494a5a39d37e71f09a677) C:\Windows\system32\drivers\secdrv.sys
2011/02/14 15:53:23.0555 3416 Serenum (68e44e331d46f0fb38f0863a84cd1a31) C:\Windows\system32\drivers\serenum.sys
2011/02/14 15:53:23.0584 3416 Serial (c70d69a918b178d3c3b06339b40c2e1b) C:\Windows\system32\drivers\serial.sys
2011/02/14 15:53:23.0609 3416 sermouse (8af3d28a879bf75db53a0ee7a4289624) C:\Windows\system32\drivers\sermouse.sys
2011/02/14 15:53:23.0656 3416 sffdisk (3efa810bdca87f6ecc24f9832243fe86) C:\Windows\system32\drivers\sffdisk.sys
2011/02/14 15:53:23.0688 3416 sffp_mmc (e95d451f7ea3e583aec75f3b3ee42dc5) C:\Windows\system32\drivers\sffp_mmc.sys
2011/02/14 15:53:23.0716 3416 sffp_sd (3d0ea348784b7ac9ea9bd9f317980979) C:\Windows\system32\drivers\sffp_sd.sys
2011/02/14 15:53:23.0751 3416 sfloppy (46ed8e91793b2e6f848015445a0ac188) C:\Windows\system32\drivers\sfloppy.sys
2011/02/14 15:53:23.0798 3416 sisagp (1d76624a09a054f682d746b924e2dbc3) C:\Windows\system32\drivers\sisagp.sys
2011/02/14 15:53:23.0825 3416 SiSRaid2 (43cb7aa756c7db280d01da9b676cfde2) C:\Windows\system32\drivers\sisraid2.sys
2011/02/14 15:53:23.0853 3416 SiSRaid4 (a99c6c8b0baa970d8aa59ddc50b57f94) C:\Windows\system32\drivers\sisraid4.sys
2011/02/14 15:53:23.0904 3416 Smb (7b75299a4d201d6a6533603d6914ab04) C:\Windows\system32\DRIVERS\smb.sys
2011/02/14 15:53:23.0982 3416 spldr (7aebdeef071fe28b0eef2cdd69102bff) C:\Windows\system32\drivers\spldr.sys
2011/02/14 15:53:24.0073 3416 sptd (cdddec541bc3c96f91ecb48759673505) C:\Windows\system32\Drivers\sptd.sys
2011/02/14 15:53:24.0073 3416 Suspicious file (NoAccess): C:\Windows\system32\Drivers\sptd.sys. md5: cdddec541bc3c96f91ecb48759673505
2011/02/14 15:53:24.0081 3416 sptd - detected Locked file (1)
2011/02/14 15:53:24.0111 3416 srv (ff3cbc13db84d81f56931bc922cc37c4) C:\Windows\system32\DRIVERS\srv.sys
2011/02/14 15:53:24.0166 3416 srv2 (d15959d9f69f0d39a0153e9c244f20dd) C:\Windows\system32\DRIVERS\srv2.sys
2011/02/14 15:53:24.0188 3416 srvnet (faa0d553a49e85008c6bb3781987c574) C:\Windows\system32\DRIVERS\srvnet.sys
2011/02/14 15:53:24.0279 3416 swenum (7ba58ecf0c0a9a69d44b3dca62becf56) C:\Windows\system32\DRIVERS\swenum.sys
2011/02/14 15:53:24.0315 3416 Symc8xx (192aa3ac01df071b541094f251deed10) C:\Windows\system32\drivers\symc8xx.sys
2011/02/14 15:53:24.0344 3416 Sym_hi (8c8eb8c76736ebaf3b13b633b2e64125) C:\Windows\system32\drivers\sym_hi.sys
2011/02/14 15:53:24.0379 3416 Sym_u3 (8072af52b5fd103bbba387a1e49f62cb) C:\Windows\system32\drivers\sym_u3.sys
2011/02/14 15:53:24.0458 3416 SynTP (aee6e411a915f50101895ba8dc5c15d4) C:\Windows\system32\DRIVERS\SynTP.sys
2011/02/14 15:53:24.0682 3416 Tcpip (a474879afa4a596b3a531f3e69730dbf) C:\Windows\system32\drivers\tcpip.sys
2011/02/14 15:53:24.0830 3416 Tcpip6 (a474879afa4a596b3a531f3e69730dbf) C:\Windows\system32\DRIVERS\tcpip.sys
2011/02/14 15:53:24.0910 3416 tcpipreg (608c345a255d82a6289c2d468eb41fd7) C:\Windows\system32\drivers\tcpipreg.sys
2011/02/14 15:53:24.0990 3416 TDPIPE (5dcf5e267be67a1ae926f2df77fbcc56) C:\Windows\system32\drivers\tdpipe.sys
2011/02/14 15:53:25.0038 3416 TDTCP (389c63e32b3cefed425b61ed92d3f021) C:\Windows\system32\drivers\tdtcp.sys
2011/02/14 15:53:25.0092 3416 tdx (76b06eb8a01fc8624d699e7045303e54) C:\Windows\system32\DRIVERS\tdx.sys
2011/02/14 15:53:25.0143 3416 TermDD (3cad38910468eab9a6479e2f01db43c7) C:\Windows\system32\DRIVERS\termdd.sys
2011/02/14 15:53:25.0221 3416 tssecsrv (dcf0f056a2e4f52287264f5ab29cf206) C:\Windows\system32\DRIVERS\tssecsrv.sys
2011/02/14 15:53:25.0263 3416 tunmp (caecc0120ac49e3d2f758b9169872d38) C:\Windows\system32\DRIVERS\tunmp.sys
2011/02/14 15:53:25.0311 3416 tunnel (300db877ac094feab0be7688c3454a9c) C:\Windows\system32\DRIVERS\tunnel.sys
2011/02/14 15:53:25.0342 3416 uagp35 (7d33c4db2ce363c8518d2dfcf533941f) C:\Windows\system32\drivers\uagp35.sys
2011/02/14 15:53:25.0399 3416 udfs (d9728af68c4c7693cb100b8441cbdec6) C:\Windows\system32\DRIVERS\udfs.sys
2011/02/14 15:53:25.0465 3416 uliagpkx (b0acfdc9e4af279e9116c03e014b2b27) C:\Windows\system32\drivers\uliagpkx.sys
2011/02/14 15:53:25.0505 3416 uliahci (9224bb254f591de4ca8d572a5f0d635c) C:\Windows\system32\drivers\uliahci.sys
2011/02/14 15:53:25.0547 3416 UlSata (8514d0e5cd0534467c5fc61be94a569f) C:\Windows\system32\drivers\ulsata.sys
2011/02/14 15:53:25.0591 3416 ulsata2 (38c3c6e62b157a6bc46594fada45c62b) C:\Windows\system32\drivers\ulsata2.sys
2011/02/14 15:53:25.0620 3416 umbus (32cff9f809ae9aed85464492bf3e32d2) C:\Windows\system32\DRIVERS\umbus.sys
2011/02/14 15:53:25.0679 3416 USBAAPL (4b8a9c16b6d9258ed99c512aecb8c555) C:\Windows\system32\Drivers\usbaapl.sys
2011/02/14 15:53:25.0738 3416 usbccgp (caf811ae4c147ffcd5b51750c7f09142) C:\Windows\system32\DRIVERS\usbccgp.sys
2011/02/14 15:53:25.0766 3416 usbcir (e9476e6c486e76bc4898074768fb7131) C:\Windows\system32\drivers\usbcir.sys
2011/02/14 15:53:25.0787 3416 usbehci (79e96c23a97ce7b8f14d310da2db0c9b) C:\Windows\system32\DRIVERS\usbehci.sys
2011/02/14 15:53:25.0824 3416 usbhub (4673bbcb006af60e7abddbe7a130ba42) C:\Windows\system32\DRIVERS\usbhub.sys
2011/02/14 15:53:25.0855 3416 usbohci (38dbc7dd6cc5a72011f187425384388b) C:\Windows\system32\drivers\usbohci.sys
2011/02/14 15:53:25.0903 3416 usbprint (e75c4b5269091d15a2e7dc0b6d35f2f5) C:\Windows\system32\DRIVERS\usbprint.sys
2011/02/14 15:53:25.0968 3416 usbscan (a508c9bd8724980512136b039bba65e9) C:\Windows\system32\DRIVERS\usbscan.sys
2011/02/14 15:53:26.0021 3416 USBSTOR (be3da31c191bc222d9ad503c5224f2ad) C:\Windows\system32\DRIVERS\USBSTOR.SYS
2011/02/14 15:53:26.0047 3416 usbuhci (814d653efc4d48be3b04a307eceff56f) C:\Windows\system32\DRIVERS\usbuhci.sys
2011/02/14 15:53:26.0079 3416 usbvideo (e67998e8f14cb0627a769f6530bcb352) C:\Windows\system32\Drivers\usbvideo.sys
2011/02/14 15:53:26.0139 3416 vga (87b06e1f30b749a114f74622d013f8d4) C:\Windows\system32\DRIVERS\vgapnp.sys
2011/02/14 15:53:26.0175 3416 VgaSave (2e93ac0a1d8c79d019db6c51f036636c) C:\Windows\System32\drivers\vga.sys
2011/02/14 15:53:26.0211 3416 viaagp (5d7159def58a800d5781ba3a879627bc) C:\Windows\system32\drivers\viaagp.sys
2011/02/14 15:53:26.0246 3416 ViaC7 (c4f3a691b5bad343e6249bd8c2d45dee) C:\Windows\system32\drivers\viac7.sys
2011/02/14 15:53:26.0282 3416 viaide (aadf5587a4063f52c2c3fed7887426fc) C:\Windows\system32\drivers\viaide.sys
2011/02/14 15:53:26.0311 3416 volmgr (69503668ac66c77c6cd7af86fbdf8c43) C:\Windows\system32\drivers\volmgr.sys
2011/02/14 15:53:26.0360 3416 volmgrx (23e41b834759917bfd6b9a0d625d0c28) C:\Windows\system32\drivers\volmgrx.sys
2011/02/14 15:53:26.0393 3416 volsnap (147281c01fcb1df9252de2a10d5e7093) C:\Windows\system32\drivers\volsnap.sys
2011/02/14 15:53:26.0455 3416 vsmraid (587253e09325e6bf226b299774b728a9) C:\Windows\system32\drivers\vsmraid.sys
2011/02/14 15:53:26.0514 3416 WacomPen (48dfee8f1af7c8235d4e626f0c4fe031) C:\Windows\system32\drivers\wacompen.sys
2011/02/14 15:53:26.0551 3416 Wanarp (55201897378cca7af8b5efd874374a26) C:\Windows\system32\DRIVERS\wanarp.sys
2011/02/14 15:53:26.0574 3416 Wanarpv6 (55201897378cca7af8b5efd874374a26) C:\Windows\system32\DRIVERS\wanarp.sys
2011/02/14 15:53:26.0635 3416 Wd (78fe9542363f297b18c027b2d7e7c07f) C:\Windows\system32\drivers\wd.sys
2011/02/14 15:53:26.0693 3416 Wdf01000 (b6f0a7ad6d4bd325fbcd8bac96cd8d96) C:\Windows\system32\drivers\Wdf01000.sys
2011/02/14 15:53:26.0819 3416 WmiAcpi (2e7255d172df0b8283cdfb7b433b864e) C:\Windows\system32\DRIVERS\wmiacpi.sys
2011/02/14 15:53:26.0893 3416 WpdUsb (de9d36f91a4df3d911626643debf11ea) C:\Windows\system32\DRIVERS\wpdusb.sys
2011/02/14 15:53:26.0941 3416 ws2ifsl (e3a3cb253c0ec2494d4a61f5e43a389c) C:\Windows\system32\drivers\ws2ifsl.sys
2011/02/14 15:53:27.0036 3416 WUDFRd (ac13cb789d93412106b0fb6c7eb2bcb6) C:\Windows\system32\DRIVERS\WUDFRd.sys
2011/02/14 15:53:27.0277 3416 ================================================================================
2011/02/14 15:53:27.0277 3416 Scan finished
2011/02/14 15:53:27.0277 3416 ================================================================================
2011/02/14 15:53:27.0295 2556 Detected object count: 1
2011/02/14 15:55:02.0288 2556 Locked file(sptd) - User select action: Skip
2011/02/14 15:55:21.0472 4728 ================================================================================
2011/02/14 15:55:21.0472 4728 Scan started
2011/02/14 15:55:21.0472 4728 Mode: Manual;
2011/02/14 15:55:21.0472 4728 ================================================================================
2011/02/14 15:55:21.0800 4728 acedrv11 (a6fe70357a68ad1e279cd1012419cce6) C:\Windows\system32\drivers\acedrv11.sys
2011/02/14 15:55:21.0854 4728 ACPI (82b296ae1892fe3dbee00c9cf92f8ac7) C:\Windows\system32\drivers\acpi.sys
2011/02/14 15:55:21.0908 4728 adp94xx (04f0fcac69c7c71a3ac4eb97fafc8303) C:\Windows\system32\drivers\adp94xx.sys
2011/02/14 15:55:21.0939 4728 adpahci (60505e0041f7751bdbb80f88bf45c2ce) C:\Windows\system32\drivers\adpahci.sys
2011/02/14 15:55:21.0972 4728 adpu160m (8a42779b02aec986eab64ecfc98f8bd7) C:\Windows\system32\drivers\adpu160m.sys
2011/02/14 15:55:22.0008 4728 adpu320 (241c9e37f8ce45ef51c3de27515ca4e5) C:\Windows\system32\drivers\adpu320.sys
2011/02/14 15:55:22.0076 4728 AFD (a201207363aa900abf1a388468688570) C:\Windows\system32\drivers\afd.sys
2011/02/14 15:55:22.0157 4728 AgereSoftModem (38325c6aa8eae011897d61ce48ec6435) C:\Windows\system32\DRIVERS\AGRSM.sys
2011/02/14 15:55:22.0202 4728 agp440 (13f9e33747e6b41a3ff305c37db0d360) C:\Windows\system32\drivers\agp440.sys
2011/02/14 15:55:22.0233 4728 aic78xx (ae1fdf7bf7bb6c6a70f67699d880592a) C:\Windows\system32\drivers\djsvs.sys
2011/02/14 15:55:22.0274 4728 aliide (9eaef5fc9b8e351afa7e78a6fae91f91) C:\Windows\system32\drivers\aliide.sys
2011/02/14 15:55:22.0296 4728 amdagp (c47344bc706e5f0b9dce369516661578) C:\Windows\system32\drivers\amdagp.sys
2011/02/14 15:55:22.0321 4728 amdide (9b78a39a4c173fdbc1321e0dd659b34c) C:\Windows\system32\drivers\amdide.sys
2011/02/14 15:55:22.0344 4728 AmdK7 (18f29b49ad23ecee3d2a826c725c8d48) C:\Windows\system32\drivers\amdk7.sys
2011/02/14 15:55:22.0375 4728 AmdK8 (93ae7f7dd54ab986a6f1a1b37be7442d) C:\Windows\system32\drivers\amdk8.sys
2011/02/14 15:55:22.0484 4728 appdrv01 (c42cad1bf0be180c84b03932428429ff) C:\Windows\system32\Drivers\appdrv01.sys
2011/02/14 15:55:22.0550 4728 arc (5d2888182fb46632511acee92fdad522) C:\Windows\system32\drivers\arc.sys
2011/02/14 15:55:22.0586 4728 arcsas (5e2a321bd7c8b3624e41fdec3e244945) C:\Windows\system32\drivers\arcsas.sys
2011/02/14 15:55:22.0624 4728 aswFsBlk (cba53c5e29ae0a0ce76f9a2be3a40d9e) C:\Windows\system32\drivers\aswFsBlk.sys
2011/02/14 15:55:22.0658 4728 aswMonFlt (317f85fb68a3be507e9ccede5e6d9ee0) C:\Windows\system32\drivers\aswMonFlt.sys
2011/02/14 15:55:22.0702 4728 aswRdr (b6e8c5874377a42756c282fac2e20836) C:\Windows\system32\drivers\aswRdr.sys
2011/02/14 15:55:22.0747 4728 aswSP (b93a553c9b0f14263c8f016a44c3258c) C:\Windows\system32\drivers\aswSP.sys
2011/02/14 15:55:22.0776 4728 aswTdi (1408421505257846eb336feeef33352d) C:\Windows\system32\drivers\aswTdi.sys
2011/02/14 15:55:22.0811 4728 AsyncMac (53b202abee6455406254444303e87be1) C:\Windows\system32\DRIVERS\asyncmac.sys
2011/02/14 15:55:22.0846 4728 atapi (1f05b78ab91c9075565a9d8a4b880bc4) C:\Windows\system32\drivers\atapi.sys
2011/02/14 15:55:22.0901 4728 athr (acdb46b1a467752a2f280c68c8461556) C:\Windows\system32\DRIVERS\athr.sys
2011/02/14 15:55:22.0953 4728 atksgt (f0d933b42cd0594048e4d5200ae9e417) C:\Windows\system32\DRIVERS\atksgt.sys
2011/02/14 15:55:23.0013 4728 b57nd60x (502f1c30bd50b32d00ce4dcaecc3d3c7) C:\Windows\system32\DRIVERS\b57nd60x.sys
2011/02/14 15:55:23.0052 4728 Beep (67e506b75bd5326a3ec7b70bd014dfb6) C:\Windows\system32\drivers\Beep.sys
2011/02/14 15:55:23.0099 4728 blbdrive (d4df28447741fd3d953526e33a617397) C:\Windows\system32\drivers\blbdrive.sys
2011/02/14 15:55:23.0142 4728 bowser (74b442b2be1260b7588c136177ceac66) C:\Windows\system32\DRIVERS\bowser.sys
2011/02/14 15:55:23.0172 4728 BrFiltLo (9f9acc7f7ccde8a15c282d3f88b43309) C:\Windows\system32\drivers\brfiltlo.sys
2011/02/14 15:55:23.0214 4728 BrFiltUp (56801ad62213a41f6497f96dee83755a) C:\Windows\system32\drivers\brfiltup.sys
2011/02/14 15:55:23.0261 4728 Brserid (b304e75cff293029eddf094246747113) C:\Windows\system32\drivers\brserid.sys
2011/02/14 15:55:23.0286 4728 BrSerWdm (203f0b1e73adadbbb7b7b1fabd901f6b) C:\Windows\system32\drivers\brserwdm.sys
2011/02/14 15:55:23.0320 4728 BrUsbMdm (bd456606156ba17e60a04e18016ae54b) C:\Windows\system32\drivers\brusbmdm.sys
2011/02/14 15:55:23.0346 4728 BrUsbSer (af72ed54503f717a43268b3cc5faec2e) C:\Windows\system32\drivers\brusbser.sys
2011/02/14 15:55:23.0372 4728 BTHMODEM (ad07c1ec6665b8b35741ab91200c6b68) C:\Windows\system32\drivers\bthmodem.sys
2011/02/14 15:55:23.0496 4728 cdfs (7add03e75beb9e6dd102c3081d29840a) C:\Windows\system32\DRIVERS\cdfs.sys
2011/02/14 15:55:23.0530 4728 cdrom (6b4bffb9becd728097024276430db314) C:\Windows\system32\DRIVERS\cdrom.sys
2011/02/14 15:55:23.0562 4728 circlass (e5d4133f37219dbcfe102bc61072589d) C:\Windows\system32\drivers\circlass.sys
2011/02/14 15:55:23.0599 4728 CLFS (d7659d3b5b92c31e84e53c1431f35132) C:\Windows\system32\CLFS.sys
2011/02/14 15:55:23.0634 4728 CmBatt (99afc3795b58cc478fbbbcdc658fcb56) C:\Windows\system32\DRIVERS\CmBatt.sys
2011/02/14 15:55:23.0666 4728 cmdide (0ca25e686a4928484e9fdabd168ab629) C:\Windows\system32\drivers\cmdide.sys
2011/02/14 15:55:23.0691 4728 Compbatt (6afef0b60fa25de07c0968983ee4f60a) C:\Windows\system32\DRIVERS\compbatt.sys
2011/02/14 15:55:23.0715 4728 crcdisk (741e9dff4f42d2d8477d0fc1dc0df871) C:\Windows\system32\drivers\crcdisk.sys
2011/02/14 15:55:23.0756 4728 Crusoe (1f07becdca750766a96cda811ba86410) C:\Windows\system32\drivers\crusoe.sys
2011/02/14 15:55:23.0831 4728 DfsC (218d8ae46c88e82014f5d73d0236d9b2) C:\Windows\system32\Drivers\dfsc.sys
2011/02/14 15:55:23.0880 4728 disk (5d4aefc3386920236a548271f8f1af6a) C:\Windows\system32\drivers\disk.sys
2011/02/14 15:55:23.0908 4728 DKbFltr (73baf270d24fe726b9cd7f80bb17a23d) C:\Windows\system32\DRIVERS\DKbFltr.sys
2011/02/14 15:55:23.0968 4728 drmkaud (97fef831ab90bee128c9af390e243f80) C:\Windows\system32\drivers\drmkaud.sys
2011/02/14 15:55:24.0034 4728 DXGKrnl (c68ac676b0ef30cfbb1080adce49eb1f) C:\Windows\System32\drivers\dxgkrnl.sys
2011/02/14 15:55:24.0079 4728 E1G60 (5425f74ac0c1dbd96a1e04f17d63f94c) C:\Windows\system32\DRIVERS\E1G60I32.sys
2011/02/14 15:55:24.0135 4728 Ecache (7f64ea048dcfac7acf8b4d7b4e6fe371) C:\Windows\system32\drivers\ecache.sys
2011/02/14 15:55:24.0192 4728 elxstor (23b62471681a124889978f6295b3f4c6) C:\Windows\system32\drivers\elxstor.sys
2011/02/14 15:55:24.0247 4728 ErrDev (3db974f3935483555d7148663f726c61) C:\Windows\system32\drivers\errdev.sys
2011/02/14 15:55:24.0304 4728 exfat (22b408651f9123527bcee54b4f6c5cae) C:\Windows\system32\drivers\exfat.sys
2011/02/14 15:55:24.0347 4728 fastfat (1e9b9a70d332103c52995e957dc09ef8) C:\Windows\system32\drivers\fastfat.sys
2011/02/14 15:55:24.0381 4728 fdc (afe1e8b9782a0dd7fb46bbd88e43f89a) C:\Windows\system32\DRIVERS\fdc.sys
2011/02/14 15:55:24.0421 4728 FileInfo (a8c0139a884861e3aae9cfe73b208a9f) C:\Windows\system32\drivers\fileinfo.sys
2011/02/14 15:55:24.0457 4728 Filetrace (0ae429a696aecbc5970e3cf2c62635ae) C:\Windows\system32\drivers\filetrace.sys
2011/02/14 15:55:24.0504 4728 flpydisk (85b7cf99d532820495d68d747fda9ebd) C:\Windows\system32\DRIVERS\flpydisk.sys
2011/02/14 15:55:24.0540 4728 FltMgr (01334f9ea68e6877c4ef05d3ea8abb05) C:\Windows\system32\drivers\fltmgr.sys
2011/02/14 15:55:24.0573 4728 Fs_Rec (65ea8b77b5851854f0c55c43fa51a198) C:\Windows\system32\drivers\Fs_Rec.sys
2011/02/14 15:55:24.0610 4728 gagp30kx (34582a6e6573d54a07ece5fe24a126b5) C:\Windows\system32\drivers\gagp30kx.sys
2011/02/14 15:55:24.0657 4728 GEARAspiWDM (8182ff89c65e4d38b2de4bb0fb18564e) C:\Windows\system32\DRIVERS\GEARAspiWDM.sys
2011/02/14 15:55:24.0731 4728 HdAudAddService (cb04c744be0a61b1d648faed182c3b59) C:\Windows\system32\drivers\HdAudio.sys
2011/02/14 15:55:24.0786 4728 HDAudBus (062452b7ffd68c8c042a6261fe8dff4a) C:\Windows\system32\DRIVERS\HDAudBus.sys
2011/02/14 15:55:24.0824 4728 HidBth (1338520e78d90154ed6be8f84de5fceb) C:\Windows\system32\drivers\hidbth.sys
2011/02/14 15:55:24.0852 4728 HidIr (ff3160c3a2445128c5a6d9b076da519e) C:\Windows\system32\drivers\hidir.sys
2011/02/14 15:55:24.0907 4728 HidUsb (cca4b519b17e23a00b826c55716809cc) C:\Windows\system32\DRIVERS\hidusb.sys
2011/02/14 15:55:24.0944 4728 HpCISSs (16ee7b23a009e00d835cdb79574a91a6) C:\Windows\system32\drivers\hpcisss.sys
2011/02/14 15:55:24.0993 4728 HTTP (f870aa3e254628ebeafe754108d664de) C:\Windows\system32\drivers\HTTP.sys
2011/02/14 15:55:25.0023 4728 i2omp (c6b032d69650985468160fc9937cf5b4) C:\Windows\system32\drivers\i2omp.sys
2011/02/14 15:55:25.0053 4728 i8042prt (22d56c8184586b7a1f6fa60be5f5a2bd) C:\Windows\system32\DRIVERS\i8042prt.sys
2011/02/14 15:55:25.0097 4728 iaStor (71ecc07bc7c5e24c3dd01d8a29a24054) C:\Windows\system32\DRIVERS\iaStor.sys
2011/02/14 15:55:25.0127 4728 iaStorV (54155ea1b0df185878e0fc9ec3ac3a14) C:\Windows\system32\drivers\iastorv.sys
2011/02/14 15:55:25.0375 4728 igfx (8266ae06df974e5ba047b3e9e9e70b3f) C:\Windows\system32\DRIVERS\igdkmd32.sys
2011/02/14 15:55:25.0452 4728 iirsp (2d077bf86e843f901d8db709c95b49a5) C:\Windows\system32\drivers\iirsp.sys
2011/02/14 15:55:25.0553 4728 IntcAzAudAddService (80919a856693b1d1d4177f11f5bda545) C:\Windows\system32\drivers\RTKVHDA.sys
2011/02/14 15:55:25.0612 4728 IntcHdmiAddService (092a78e9c6f71bf0e22379503b90e800) C:\Windows\system32\drivers\IntcHdmi.sys
2011/02/14 15:55:25.0638 4728 intelide (83aa759f3189e6370c30de5dc5590718) C:\Windows\system32\drivers\intelide.sys
2011/02/14 15:55:25.0667 4728 intelppm (224191001e78c89dfa78924c3ea595ff) C:\Windows\system32\DRIVERS\intelppm.sys
2011/02/14 15:55:25.0714 4728 IpFilterDriver (62c265c38769b864cb25b4bcf62df6c3) C:\Windows\system32\DRIVERS\ipfltdrv.sys
2011/02/14 15:55:25.0765 4728 IPMIDRV (b25aaf203552b7b3491139d582b39ad1) C:\Windows\system32\drivers\ipmidrv.sys
2011/02/14 15:55:25.0791 4728 IPNAT (8793643a67b42cec66490b2a0cf92d68) C:\Windows\system32\DRIVERS\ipnat.sys
2011/02/14 15:55:25.0827 4728 irda (e50a95179211b12946f7e035d60af560) C:\Windows\system32\DRIVERS\irda.sys
2011/02/14 15:55:25.0857 4728 IRENUM (109c0dfb82c3632fbd11949b73aeeac9) C:\Windows\system32\drivers\irenum.sys
2011/02/14 15:55:25.0893 4728 isapnp (6c70698a3e5c4376c6ab5c7c17fb0614) C:\Windows\system32\drivers\isapnp.sys
2011/02/14 15:55:25.0954 4728 iScsiPrt (232fa340531d940aac623b121a595034) C:\Windows\system32\DRIVERS\msiscsi.sys
2011/02/14 15:55:25.0981 4728 iteatapi (bced60d16156e428f8df8cf27b0df150) C:\Windows\system32\drivers\iteatapi.sys
2011/02/14 15:55:26.0012 4728 iteraid (06fa654504a498c30adca8bec4e87e7e) C:\Windows\system32\drivers\iteraid.sys
2011/02/14 15:55:26.0061 4728 k57nd60x (eac21e8014c7e6ee341afffb7e2bbd54) C:\Windows\system32\DRIVERS\k57nd60x.sys
2011/02/14 15:55:26.0084 4728 kbdclass (37605e0a8cf00cbba538e753e4344c6e) C:\Windows\system32\DRIVERS\kbdclass.sys
2011/02/14 15:55:26.0116 4728 kbdhid (18247836959ba67e3511b62846b9c2e0) C:\Windows\system32\drivers\kbdhid.sys
2011/02/14 15:55:26.0170 4728 KSecDD (86165728af9bf72d6442a894fdfb4f8b) C:\Windows\system32\Drivers\ksecdd.sys
2011/02/14 15:55:26.0240 4728 lirsgt (f8a7212d0864ef5e9185fb95e6623f4d) C:\Windows\system32\DRIVERS\lirsgt.sys
2011/02/14 15:55:26.0262 4728 lltdio (d1c5883087a0c3f1344d9d55a44901f6) C:\Windows\system32\DRIVERS\lltdio.sys
2011/02/14 15:55:26.0319 4728 LSI_FC (c7e15e82879bf3235b559563d4185365) C:\Windows\system32\drivers\lsi_fc.sys
2011/02/14 15:55:26.0342 4728 LSI_SAS (ee01ebae8c9bf0fa072e0ff68718920a) C:\Windows\system32\drivers\lsi_sas.sys
2011/02/14 15:55:26.0371 4728 LSI_SCSI (912a04696e9ca30146a62afa1463dd5c) C:\Windows\system32\drivers\lsi_scsi.sys
2011/02/14 15:55:26.0388 4728 luafv (8f5c7426567798e62a3b3614965d62cc) C:\Windows\system32\drivers\luafv.sys
2011/02/14 15:55:26.0422 4728 megasas (0001ce609d66632fa17b84705f658879) C:\Windows\system32\drivers\megasas.sys
2011/02/14 15:55:26.0461 4728 MegaSR (c252f32cd9a49dbfc25ecf26ebd51a99) C:\Windows\system32\drivers\megasr.sys
2011/02/14 15:55:26.0502 4728 Modem (e13b5ea0f51ba5b1512ec671393d09ba) C:\Windows\system32\drivers\modem.sys
2011/02/14 15:55:26.0529 4728 monitor (0a9bb33b56e294f686abb7c1e4e2d8a8) C:\Windows\system32\DRIVERS\monitor.sys
2011/02/14 15:55:26.0547 4728 mouclass (5bf6a1326a335c5298477754a506d263) C:\Windows\system32\DRIVERS\mouclass.sys
2011/02/14 15:55:26.0580 4728 mouhid (93b8d4869e12cfbe663915502900876f) C:\Windows\system32\DRIVERS\mouhid.sys
2011/02/14 15:55:26.0598 4728 MountMgr (bdafc88aa6b92f7842416ea6a48e1600) C:\Windows\system32\drivers\mountmgr.sys
2011/02/14 15:55:26.0632 4728 mpio (511d011289755dd9f9a7579fb0b064e6) C:\Windows\system32\drivers\mpio.sys
2011/02/14 15:55:26.0670 4728 mpsdrv (22241feba9b2defa669c8cb0a8dd7d2e) C:\Windows\system32\drivers\mpsdrv.sys
2011/02/14 15:55:26.0700 4728 Mraid35x (4fbbb70d30fd20ec51f80061703b001e) C:\Windows\system32\drivers\mraid35x.sys
2011/02/14 15:55:26.0739 4728 MRxDAV (82cea0395524aacfeb58ba1448e8325c) C:\Windows\system32\drivers\mrxdav.sys
2011/02/14 15:55:26.0776 4728 mrxsmb (454341e652bdf5e01b0f2140232b073e) C:\Windows\system32\DRIVERS\mrxsmb.sys
2011/02/14 15:55:26.0805 4728 mrxsmb10 (2a4901aff069944fa945ed5bbf4dcde3) C:\Windows\system32\DRIVERS\mrxsmb10.sys
2011/02/14 15:55:26.0835 4728 mrxsmb20 (28b3f1ab44bdd4432c041581412f17d9) C:\Windows\system32\DRIVERS\mrxsmb20.sys
2011/02/14 15:55:26.0873 4728 msahci (28023e86f17001f7cd9b15a5bc9ae07d) C:\Windows\system32\drivers\msahci.sys
2011/02/14 15:55:26.0908 4728 msdsm (4468b0f385a86ecddaf8d3ca662ec0e7) C:\Windows\system32\drivers\msdsm.sys
2011/02/14 15:55:26.0943 4728 Msfs (a9927f4a46b816c92f461acb90cf8515) C:\Windows\system32\drivers\Msfs.sys
2011/02/14 15:55:26.0979 4728 msisadrv (0f400e306f385c56317357d6dea56f62) C:\Windows\system32\drivers\msisadrv.sys
2011/02/14 15:55:27.0020 4728 MSKSSRV (d8c63d34d9c9e56c059e24ec7185cc07) C:\Windows\system32\drivers\MSKSSRV.sys
2011/02/14 15:55:27.0044 4728 MSPCLOCK (1d373c90d62ddb641d50e55b9e78d65e) C:\Windows\system32\drivers\MSPCLOCK.sys
2011/02/14 15:55:27.0065 4728 MSPQM (b572da05bf4e098d4bba3a4734fb505b) C:\Windows\system32\drivers\MSPQM.sys
2011/02/14 15:55:27.0104 4728 MsRPC (b49456d70555de905c311bcda6ec6adb) C:\Windows\system32\drivers\MsRPC.sys
2011/02/14 15:55:27.0149 4728 mssmbios (e384487cb84be41d09711c30ca79646c) C:\Windows\system32\DRIVERS\mssmbios.sys
2011/02/14 15:55:27.0180 4728 MSTEE (7199c1eec1e4993caf96b8c0a26bd58a) C:\Windows\system32\drivers\MSTEE.sys
2011/02/14 15:55:27.0204 4728 Mup (6a57b5733d4cb702c8ea4542e836b96c) C:\Windows\system32\Drivers\mup.sys
2011/02/14 15:55:27.0234 4728 mwlPSDFilter (2de94e435c3efde58c7b1856d4f20724) C:\Windows\system32\DRIVERS\mwlPSDFilter.sys
2011/02/14 15:55:27.0265 4728 mwlPSDNServ (61920a7146eed3d903dbbb8ec295af76) C:\Windows\system32\DRIVERS\mwlPSDNServ.sys
2011/02/14 15:55:27.0289 4728 mwlPSDVDisk (e0f49721e68ebd2983e84c44fada6665) C:\Windows\system32\DRIVERS\mwlPSDVDisk.sys
2011/02/14 15:55:27.0340 4728 NativeWifiP (85c44fdff9cf7e72a40dcb7ec06a4416) C:\Windows\system32\DRIVERS\nwifi.sys
2011/02/14 15:55:27.0398 4728 NDIS (1357274d1883f68300aeadd15d7bbb42) C:\Windows\system32\drivers\ndis.sys
2011/02/14 15:55:27.0443 4728 NdisTapi (0e186e90404980569fb449ba7519ae61) C:\Windows\system32\DRIVERS\ndistapi.sys
2011/02/14 15:55:27.0471 4728 Ndisuio (d6973aa34c4d5d76c0430b181c3cd389) C:\Windows\system32\DRIVERS\ndisuio.sys
2011/02/14 15:55:27.0508 4728 NdisWan (818f648618ae34f729fdb47ec68345c3) C:\Windows\system32\DRIVERS\ndiswan.sys
2011/02/14 15:55:27.0535 4728 NDProxy (71dab552b41936358f3b541ae5997fb3) C:\Windows\system32\drivers\NDProxy.sys
2011/02/14 15:55:27.0566 4728 NetBIOS (bcd093a5a6777cf626434568dc7dba78) C:\Windows\system32\DRIVERS\netbios.sys
2011/02/14 15:55:27.0614 4728 netbt (ecd64230a59cbd93c85f1cd1cab9f3f6) C:\Windows\system32\DRIVERS\netbt.sys
2011/02/14 15:55:27.0676 4728 nfrd960 (2e7fb731d4790a1bc6270accefacb36e) C:\Windows\system32\drivers\nfrd960.sys
2011/02/14 15:55:27.0722 4728 Npfs (d36f239d7cce1931598e8fb90a0dbc26) C:\Windows\system32\drivers\Npfs.sys
2011/02/14 15:55:27.0756 4728 NSCIRDA (6d8d2e5652fc2442c810c5d8be784148) C:\Windows\system32\DRIVERS\nscirda.sys
2011/02/14 15:55:27.0783 4728 nsiproxy (609773e344a97410ce4ebf74a8914fcf) C:\Windows\system32\drivers\nsiproxy.sys
2011/02/14 15:55:27.0852 4728 Ntfs (6a4a98cee84cf9e99564510dda4baa47) C:\Windows\system32\drivers\Ntfs.sys
2011/02/14 15:55:27.0892 4728 NTIDrvr (6dcaa65f49ef3b97a5cffc0cb5de1c2f) C:\Windows\system32\Drivers\NTIDrvr.sys
2011/02/14 15:55:27.0937 4728 ntrigdigi (e875c093aec0c978a90f30c9e0dfbb72) C:\Windows\system32\drivers\ntrigdigi.sys
2011/02/14 15:55:27.0973 4728 Null (c5dbbcda07d780bda9b685df333bb41e) C:\Windows\system32\drivers\Null.sys
2011/02/14 15:55:28.0002 4728 nvraid (2edf9e7751554b42cbb60116de727101) C:\Windows\system32\drivers\nvraid.sys
2011/02/14 15:55:28.0035 4728 nvstor (abed0c09758d1d97db0042dbb2688177) C:\Windows\system32\drivers\nvstor.sys
2011/02/14 15:55:28.0068 4728 nv_agp (18bbdf913916b71bd54575bdb6eeac0b) C:\Windows\system32\drivers\nv_agp.sys
2011/02/14 15:55:28.0179 4728 ohci1394 (790e27c3db53410b40ff9ef2fd10a1d9) C:\Windows\system32\DRIVERS\ohci1394.sys
2011/02/14 15:55:28.0230 4728 Parport (0fa9b5055484649d63c303fe404e5f4d) C:\Windows\system32\drivers\parport.sys
2011/02/14 15:55:28.0264 4728 partmgr (57389fa59a36d96b3eb09d0cb91e9cdc) C:\Windows\system32\drivers\partmgr.sys
2011/02/14 15:55:28.0287 4728 Parvdm (4f9a6a8a31413180d0fcb279ad5d8112) C:\Windows\system32\drivers\parvdm.sys
2011/02/14 15:55:28.0340 4728 pci (941dc1d19e7e8620f40bbc206981efdb) C:\Windows\system32\drivers\pci.sys
2011/02/14 15:55:28.0372 4728 pciide (fc175f5ddab666d7f4d17449a547626f) C:\Windows\system32\drivers\pciide.sys
2011/02/14 15:55:28.0407 4728 pcmcia (b7c5a8769541900f6dfa6fe0c5e4d513) C:\Windows\system32\DRIVERS\pcmcia.sys
2011/02/14 15:55:28.0458 4728 PEAUTH (6349f6ed9c623b44b52ea3c63c831a92) C:\Windows\system32\drivers\peauth.sys
2011/02/14 15:55:28.0547 4728 PptpMiniport (ecfffaec0c1ecd8dbc77f39070ea1db1) C:\Windows\system32\DRIVERS\raspptp.sys
2011/02/14 15:55:28.0584 4728 Processor (2027293619dd0f047c584cf2e7df4ffd) C:\Windows\system32\drivers\processr.sys
2011/02/14 15:55:28.0633 4728 PSched (99514faa8df93d34b5589187db3aa0ba) C:\Windows\system32\DRIVERS\pacer.sys
2011/02/14 15:55:28.0689 4728 ql2300 (0a6db55afb7820c99aa1f3a1d270f4f6) C:\Windows\system32\drivers\ql2300.sys
2011/02/14 15:55:28.0725 4728 ql40xx (81a7e5c076e59995d54bc1ed3a16e60b) C:\Windows\system32\drivers\ql40xx.sys
2011/02/14 15:55:28.0764 4728 QWAVEdrv (9f5e0e1926014d17486901c88eca2db7) C:\Windows\system32\drivers\qwavedrv.sys
2011/02/14 15:55:28.0779 4728 RasAcd (147d7f9c556d259924351feb0de606c3) C:\Windows\system32\DRIVERS\rasacd.sys
2011/02/14 15:55:28.0811 4728 Rasl2tp (a214adbaf4cb47dd2728859ef31f26b0) C:\Windows\system32\DRIVERS\rasl2tp.sys
2011/02/14 15:55:28.0860 4728 RasPppoe (509a98dd18af4375e1fc40bc175f1def) C:\Windows\system32\DRIVERS\raspppoe.sys
2011/02/14 15:55:28.0888 4728 RasSstp (2005f4a1e05fa09389ac85840f0a9e4d) C:\Windows\system32\DRIVERS\rassstp.sys
2011/02/14 15:55:28.0925 4728 rdbss (b14c9d5b9add2f84f70570bbbfaa7935) C:\Windows\system32\DRIVERS\rdbss.sys
2011/02/14 15:55:28.0963 4728 RDPCDD (89e59be9a564262a3fb6c4f4f1cd9899) C:\Windows\system32\DRIVERS\RDPCDD.sys
2011/02/14 15:55:29.0006 4728 rdpdr (fbc0bacd9c3d7f6956853f64a66e252d) C:\Windows\system32\drivers\rdpdr.sys
2011/02/14 15:55:29.0022 4728 RDPENCDD (9d91fe5286f748862ecffa05f8a0710c) C:\Windows\system32\drivers\rdpencdd.sys
2011/02/14 15:55:29.0078 4728 RDPWD (30bfbdfb7f95559ede971f9ddb9a00ba) C:\Windows\system32\drivers\RDPWD.sys
2011/02/14 15:55:29.0147 4728 rspndr (9c508f4074a39e8b4b31d27198146fad) C:\Windows\system32\DRIVERS\rspndr.sys
2011/02/14 15:55:29.0188 4728 RTSTOR (9b09f336de36a7a6ca871de8a7847b65) C:\Windows\system32\drivers\RTSTOR.SYS
2011/02/14 15:55:29.0219 4728 sbp2port (3ce8f073a557e172b330109436984e30) C:\Windows\system32\drivers\sbp2port.sys
2011/02/14 15:55:29.0265 4728 sdbus (126ea89bcc413ee45e3004fb0764888f) C:\Windows\system32\DRIVERS\sdbus.sys
2011/02/14 15:55:29.0305 4728 secdrv (90a3935d05b494a5a39d37e71f09a677) C:\Windows\system32\drivers\secdrv.sys
2011/02/14 15:55:29.0342 4728 Serenum (68e44e331d46f0fb38f0863a84cd1a31) C:\Windows\system32\drivers\serenum.sys
2011/02/14 15:55:29.0372 4728 Serial (c70d69a918b178d3c3b06339b40c2e1b) C:\Windows\system32\drivers\serial.sys
2011/02/14 15:55:29.0407 4728 sermouse (8af3d28a879bf75db53a0ee7a4289624) C:\Windows\system32\drivers\sermouse.sys
2011/02/14 15:55:29.0455 4728 sffdisk (3efa810bdca87f6ecc24f9832243fe86) C:\Windows\system32\drivers\sffdisk.sys
2011/02/14 15:55:29.0487 4728 sffp_mmc (e95d451f7ea3e583aec75f3b3ee42dc5) C:\Windows\system32\drivers\sffp_mmc.sys
2011/02/14 15:55:29.0526 4728 sffp_sd (3d0ea348784b7ac9ea9bd9f317980979) C:\Windows\system32\drivers\sffp_sd.sys
2011/02/14 15:55:29.0551 4728 sfloppy (46ed8e91793b2e6f848015445a0ac188) C:\Windows\system32\drivers\sfloppy.sys
2011/02/14 15:55:29.0597 4728 sisagp (1d76624a09a054f682d746b924e2dbc3) C:\Windows\system32\drivers\sisagp.sys
2011/02/14 15:55:29.0624 4728 SiSRaid2 (43cb7aa756c7db280d01da9b676cfde2) C:\Windows\system32\drivers\sisraid2.sys
2011/02/14 15:55:29.0652 4728 SiSRaid4 (a99c6c8b0baa970d8aa59ddc50b57f94) C:\Windows\system32\drivers\sisraid4.sys
2011/02/14 15:55:29.0703 4728 Smb (7b75299a4d201d6a6533603d6914ab04) C:\Windows\system32\DRIVERS\smb.sys
2011/02/14 15:55:29.0747 4728 spldr (7aebdeef071fe28b0eef2cdd69102bff) C:\Windows\system32\drivers\spldr.sys
2011/02/14 15:55:29.0805 4728 sptd (cdddec541bc3c96f91ecb48759673505) C:\Windows\system32\Drivers\sptd.sys
2011/02/14 15:55:29.0805 4728 Suspicious file (NoAccess): C:\Windows\system32\Drivers\sptd.sys. md5: cdddec541bc3c96f91ecb48759673505
2011/02/14 15:55:29.0812 4728 sptd - detected Locked file (1)
2011/02/14 15:55:29.0842 4728 srv (ff3cbc13db84d81f56931bc922cc37c4) C:\Windows\system32\DRIVERS\srv.sys
2011/02/14 15:55:29.0887 4728 srv2 (d15959d9f69f0d39a0153e9c244f20dd) C:\Windows\system32\DRIVERS\srv2.sys
2011/02/14 15:55:29.0905 4728 srvnet (faa0d553a49e85008c6bb3781987c574) C:\Windows\system32\DRIVERS\srvnet.sys
2011/02/14 15:55:29.0948 4728 swenum (7ba58ecf0c0a9a69d44b3dca62becf56) C:\Windows\system32\DRIVERS\swenum.sys
2011/02/14 15:55:29.0992 4728 Symc8xx (192aa3ac01df071b541094f251deed10) C:\Windows\system32\drivers\symc8xx.sys
2011/02/14 15:55:30.0021 4728 Sym_hi (8c8eb8c76736ebaf3b13b633b2e64125) C:\Windows\system32\drivers\sym_hi.sys
2011/02/14 15:55:30.0056 4728 Sym_u3 (8072af52b5fd103bbba387a1e49f62cb) C:\Windows\system32\drivers\sym_u3.sys
2011/02/14 15:55:30.0101 4728 SynTP (aee6e411a915f50101895ba8dc5c15d4) C:\Windows\system32\DRIVERS\SynTP.sys
2011/02/14 15:55:30.0190 4728 Tcpip (a474879afa4a596b3a531f3e69730dbf) C:\Windows\system32\drivers\tcpip.sys
2011/02/14 15:55:30.0245 4728 Tcpip6 (a474879afa4a596b3a531f3e69730dbf) C:\Windows\system32\DRIVERS\tcpip.sys
2011/02/14 15:55:30.0298 4728 tcpipreg (608c345a255d82a6289c2d468eb41fd7) C:\Windows\system32\drivers\tcpipreg.sys
2011/02/14 15:55:30.0353 4728 TDPIPE (5dcf5e267be67a1ae926f2df77fbcc56) C:\Windows\system32\drivers\tdpipe.sys
2011/02/14 15:55:30.0381 4728 TDTCP (389c63e32b3cefed425b61ed92d3f021) C:\Windows\system32\drivers\tdtcp.sys
2011/02/14 15:55:30.0424 4728 tdx (76b06eb8a01fc8624d699e7045303e54) C:\Windows\system32\DRIVERS\tdx.sys
2011/02/14 15:55:30.0475 4728 TermDD (3cad38910468eab9a6479e2f01db43c7) C:\Windows\system32\DRIVERS\termdd.sys
2011/02/14 15:55:30.0553 4728 tssecsrv (dcf0f056a2e4f52287264f5ab29cf206) C:\Windows\system32\DRIVERS\tssecsrv.sys
2011/02/14 15:55:30.0584 4728 tunmp (caecc0120ac49e3d2f758b9169872d38) C:\Windows\system32\DRIVERS\tunmp.sys
2011/02/14 15:55:30.0620 4728 tunnel (300db877ac094feab0be7688c3454a9c) C:\Windows\system32\DRIVERS\tunnel.sys
2011/02/14 15:55:30.0652 4728 uagp35 (7d33c4db2ce363c8518d2dfcf533941f) C:\Windows\system32\drivers\uagp35.sys
2011/02/14 15:55:30.0708 4728 udfs (d9728af68c4c7693cb100b8441cbdec6) C:\Windows\system32\DRIVERS\udfs.sys
2011/02/14 15:55:30.0753 4728 uliagpkx (b0acfdc9e4af279e9116c03e014b2b27) C:\Windows\system32\drivers\uliagpkx.sys
2011/02/14 15:55:30.0803 4728 uliahci (9224bb254f591de4ca8d572a5f0d635c) C:\Windows\system32\drivers\uliahci.sys
2011/02/14 15:55:30.0834 4728 UlSata (8514d0e5cd0534467c5fc61be94a569f) C:\Windows\system32\drivers\ulsata.sys
2011/02/14 15:55:30.0878 4728 ulsata2 (38c3c6e62b157a6bc46594fada45c62b) C:\Windows\system32\drivers\ulsata2.sys
2011/02/14 15:55:30.0908 4728 umbus (32cff9f809ae9aed85464492bf3e32d2) C:\Windows\system32\DRIVERS\umbus.sys
2011/02/14 15:55:30.0956 4728 USBAAPL (4b8a9c16b6d9258ed99c512aecb8c555) C:\Windows\system32\Drivers\usbaapl.sys
2011/02/14 15:55:30.0992 4728 usbccgp (caf811ae4c147ffcd5b51750c7f09142) C:\Windows\system32\DRIVERS\usbccgp.sys
2011/02/14 15:55:31.0021 4728 usbcir (e9476e6c486e76bc4898074768fb7131) C:\Windows\system32\drivers\usbcir.sys
2011/02/14 15:55:31.0040 4728 usbehci (79e96c23a97ce7b8f14d310da2db0c9b) C:\Windows\system32\DRIVERS\usbehci.sys
2011/02/14 15:55:31.0089 4728 usbhub (4673bbcb006af60e7abddbe7a130ba42) C:\Windows\system32\DRIVERS\usbhub.sys
2011/02/14 15:55:31.0120 4728 usbohci (38dbc7dd6cc5a72011f187425384388b) C:\Windows\system32\drivers\usbohci.sys
2011/02/14 15:55:31.0179 4728 usbprint (e75c4b5269091d15a2e7d
le rapport n'est pas comple, mais ce n'est pas grave !
* /!\ Utilisateur de Vista : Ne pas oublier de désactiver l'UAC juste le temps de désinfection de ton pc, il sera à réactiver plus tard :
Tuto : https://www.commentcamarche.net/faq/8343-vista-desactiver-l-uac
Télécharge mbr.exe de Gmer ici :
http://www2.gmer.net/mbr/mbr.exe
et enregistre le fichier sur le Bureau.
Désactive tes protections et coupe la connexion. (Antivirus et antispywares, HIPS et autre résident)
Double clique sur mbr.exe
/!\Utilisateur de Vista : Clique droit sur le logo de MBR, « exécuter en tant qu'Administrateur »
Un rapport sera généré : mbr.log
En cas d'infection, ce message "MBR rootkit code detected" va apparaitre.
Si c'est le cas, continue comme ça :
Dans le menu Démarrer- Exécuter tape : "%userprofile%\Bureau\mbr" -f
Dans le mbr.log cette ligne apparaitra "original MBR restored successfully !"
Réactive tes protections
Poste ce rapport et supprimes-le ensuite.
Pour vérifier
Désactive tes protections et coupe la connexion. (Antivirus et antispywares, HIPS et autre résident)
Relance mbr.exe
Réactive tes protections.
Le nouveau mbr.log devrait être celui-ci :
Stealth MBR rootkit detector 0.2.4 by Gmer, http://www.gmer.net
device: opened successfully
user: MBR read successfully
kernel: MBR read successfully
user & kernel MBR OK
* /!\ Utilisateur de Vista : Ne pas oublier de désactiver l'UAC juste le temps de désinfection de ton pc, il sera à réactiver plus tard :
Tuto : https://www.commentcamarche.net/faq/8343-vista-desactiver-l-uac
Télécharge mbr.exe de Gmer ici :
http://www2.gmer.net/mbr/mbr.exe
et enregistre le fichier sur le Bureau.
Désactive tes protections et coupe la connexion. (Antivirus et antispywares, HIPS et autre résident)
Double clique sur mbr.exe
/!\Utilisateur de Vista : Clique droit sur le logo de MBR, « exécuter en tant qu'Administrateur »
Un rapport sera généré : mbr.log
En cas d'infection, ce message "MBR rootkit code detected" va apparaitre.
Si c'est le cas, continue comme ça :
Dans le menu Démarrer- Exécuter tape : "%userprofile%\Bureau\mbr" -f
Dans le mbr.log cette ligne apparaitra "original MBR restored successfully !"
Réactive tes protections
Poste ce rapport et supprimes-le ensuite.
Pour vérifier
Désactive tes protections et coupe la connexion. (Antivirus et antispywares, HIPS et autre résident)
Relance mbr.exe
Réactive tes protections.
Le nouveau mbr.log devrait être celui-ci :
Stealth MBR rootkit detector 0.2.4 by Gmer, http://www.gmer.net
device: opened successfully
user: MBR read successfully
kernel: MBR read successfully
user & kernel MBR OK
voila le rapport mais j'ai pas saisi ce que je devais faire
MBRCheck, version 1.2.3
(c) 2010, AD
Command-line:
Windows Version: Windows Vista Home Premium Edition
Windows Information: Service Pack 2 (build 6002), 32-bit
Base Board Manufacturer: Acer
BIOS Manufacturer: Phoenix Technologies LTD
System Manufacturer: Acer
System Product Name: Aspire 5738
Logical Drives Mask: 0x0000001c
Kernel Drivers (total 156):
0x83047000 \SystemRoot\system32\ntkrnlpa.exe
0x83014000 \SystemRoot\system32\hal.dll
0x80407000 \SystemRoot\system32\kdcom.dll
0x8040E000 \SystemRoot\system32\mcupdate_GenuineIntel.dll
0x8047E000 \SystemRoot\system32\PSHED.dll
0x8048F000 \SystemRoot\system32\BOOTVID.dll
0x80497000 \SystemRoot\system32\CLFS.SYS
0x804D8000 \SystemRoot\system32\CI.dll
0x80608000 \SystemRoot\system32\drivers\Wdf01000.sys
0x80684000 \SystemRoot\system32\drivers\WDFLDR.SYS
0x80691000 \SystemRoot\System32\Drivers\spkr.sys
0x80784000 \SystemRoot\System32\Drivers\WMILIB.SYS
0x8078D000 \SystemRoot\System32\Drivers\SCSIPORT.SYS
0x807B3000 \SystemRoot\system32\drivers\acpi.sys
0x80600000 \SystemRoot\system32\drivers\msisadrv.sys
0x805B8000 \SystemRoot\system32\drivers\pci.sys
0x805DF000 \SystemRoot\System32\drivers\partmgr.sys
0x807F9000 \SystemRoot\system32\DRIVERS\compbatt.sys
0x805EE000 \SystemRoot\system32\DRIVERS\BATTC.SYS
0x83601000 \SystemRoot\system32\drivers\volmgr.sys
0x83610000 \SystemRoot\System32\drivers\volmgrx.sys
0x8365A000 \SystemRoot\System32\drivers\mountmgr.sys
0x8366A000 \SystemRoot\system32\DRIVERS\iaStor.sys
0x83745000 \SystemRoot\system32\drivers\atapi.sys
0x8374D000 \SystemRoot\system32\drivers\ataport.SYS
0x8376B000 \SystemRoot\system32\drivers\msahci.sys
0x83775000 \SystemRoot\system32\drivers\PCIIDEX.SYS
0x83783000 \SystemRoot\system32\drivers\fltmgr.sys
0x837B5000 \SystemRoot\system32\drivers\fileinfo.sys
0x8B003000 \SystemRoot\System32\Drivers\ksecdd.sys
0x8B074000 \SystemRoot\system32\drivers\ndis.sys
0x8B17F000 \SystemRoot\system32\drivers\msrpc.sys
0x8B1AA000 \SystemRoot\system32\drivers\NETIO.SYS
0x8B205000 \SystemRoot\System32\Drivers\Ntfs.sys
0x8B315000 \SystemRoot\system32\drivers\volsnap.sys
0x8B34E000 \SystemRoot\System32\Drivers\spldr.sys
0x8B356000 \SystemRoot\System32\Drivers\mup.sys
0x8B365000 \SystemRoot\System32\drivers\ecache.sys
0x8B38C000 \SystemRoot\system32\drivers\disk.sys
0x8B39D000 \SystemRoot\system32\drivers\CLASSPNP.SYS
0x8B3BE000 \SystemRoot\system32\drivers\crcdisk.sys
0x8EAF1000 \SystemRoot\system32\DRIVERS\tunnel.sys
0x8EAFC000 \SystemRoot\system32\DRIVERS\tunmp.sys
0x8F202000 \SystemRoot\system32\DRIVERS\igdkmd32.sys
0x8FB1F000 \SystemRoot\System32\drivers\dxgkrnl.sys
0x8FBBF000 \SystemRoot\System32\drivers\watchdog.sys
0x8FBCB000 \SystemRoot\system32\DRIVERS\usbuhci.sys
0x8EB05000 \SystemRoot\system32\DRIVERS\USBPORT.SYS
0x8FBD6000 \SystemRoot\system32\DRIVERS\usbehci.sys
0x8EB43000 \SystemRoot\system32\DRIVERS\HDAudBus.sys
0x837C5000 \SystemRoot\system32\DRIVERS\k57nd60x.sys
0x8EE0A000 \SystemRoot\system32\DRIVERS\athr.sys
0x8EEFA000 \SystemRoot\system32\DRIVERS\CmBatt.sys
0x8EEFE000 \SystemRoot\system32\DRIVERS\i8042prt.sys
0x8EF11000 \SystemRoot\system32\DRIVERS\DKbFltr.sys
0x8EF1B000 \SystemRoot\system32\DRIVERS\kbdclass.sys
0x8EF26000 \SystemRoot\system32\DRIVERS\SynTP.sys
0x8EF57000 \SystemRoot\system32\DRIVERS\USBD.SYS
0x8EF59000 \SystemRoot\system32\DRIVERS\mouclass.sys
0x8EF64000 \SystemRoot\system32\DRIVERS\cdrom.sys
0x8EF7C000 \SystemRoot\system32\Drivers\NTIDrvr.sys
0x8EF84000 \SystemRoot\system32\DRIVERS\GEARAspiWDM.sys
0x8EF8A000 \SystemRoot\System32\Drivers\ancwjlvw.SYS
0x8EFC3000 \SystemRoot\system32\DRIVERS\wmiacpi.sys
0x8EFCC000 \SystemRoot\system32\DRIVERS\intelppm.sys
0x8EBD0000 \SystemRoot\system32\DRIVERS\msiscsi.sys
0x8FE08000 \SystemRoot\system32\DRIVERS\storport.sys
0x8FE49000 \SystemRoot\system32\DRIVERS\TDI.SYS
0x8FE54000 \SystemRoot\system32\DRIVERS\rasl2tp.sys
0x8FE6B000 \SystemRoot\system32\DRIVERS\ndistapi.sys
0x8FE76000 \SystemRoot\system32\DRIVERS\ndiswan.sys
0x8FE99000 \SystemRoot\system32\DRIVERS\raspppoe.sys
0x8FEA8000 \SystemRoot\system32\DRIVERS\raspptp.sys
0x8FEBC000 \SystemRoot\system32\DRIVERS\rassstp.sys
0x8FED1000 \SystemRoot\system32\DRIVERS\termdd.sys
0x8FEE1000 \SystemRoot\system32\DRIVERS\swenum.sys
0x8FEE3000 \SystemRoot\system32\DRIVERS\ks.sys
0x8FF0D000 \SystemRoot\system32\DRIVERS\mssmbios.sys
0x8FF17000 \SystemRoot\system32\DRIVERS\umbus.sys
0x8FF24000 \SystemRoot\system32\DRIVERS\usbhub.sys
0x8FF59000 \SystemRoot\System32\Drivers\NDProxy.SYS
0x9000F000 \SystemRoot\system32\drivers\RTKVHDA.sys
0x90245000 \SystemRoot\system32\drivers\portcls.sys
0x90272000 \SystemRoot\system32\drivers\drmk.sys
0x90297000 \SystemRoot\system32\DRIVERS\AGRSM.sys
0x903BD000 \SystemRoot\system32\drivers\modem.sys
0x903CA000 \SystemRoot\system32\drivers\IntcHdmi.sys
0x903EB000 \SystemRoot\System32\Drivers\Fs_Rec.SYS
0x903F4000 \SystemRoot\System32\Drivers\Null.SYS
0x90000000 \SystemRoot\System32\Drivers\Beep.SYS
0x8FF6A000 \SystemRoot\System32\drivers\vga.sys
0x8FF76000 \SystemRoot\System32\drivers\VIDEOPRT.SYS
0x90007000 \SystemRoot\System32\DRIVERS\RDPCDD.sys
0x8FF97000 \SystemRoot\system32\drivers\rdpencdd.sys
0x8FF9F000 \SystemRoot\System32\Drivers\Msfs.SYS
0x8FFAA000 \SystemRoot\System32\Drivers\Npfs.SYS
0x8FFB8000 \SystemRoot\System32\DRIVERS\rasacd.sys
0x9040C000 \SystemRoot\System32\drivers\tcpip.sys
0x904F6000 \SystemRoot\System32\drivers\fwpkclnt.sys
0x90511000 \SystemRoot\system32\DRIVERS\tdx.sys
0x90527000 \SystemRoot\System32\Drivers\aswTdi.SYS
0x90531000 \SystemRoot\system32\DRIVERS\smb.sys
0x90545000 \SystemRoot\system32\drivers\afd.sys
0x9058D000 \SystemRoot\System32\Drivers\aswRdr.SYS
0x90592000 \SystemRoot\System32\DRIVERS\netbt.sys
0x905C4000 \SystemRoot\system32\DRIVERS\pacer.sys
0x905DA000 \SystemRoot\system32\DRIVERS\netbios.sys
0x905E8000 \SystemRoot\system32\DRIVERS\wanarp.sys
0x8FFC1000 \SystemRoot\system32\DRIVERS\rdbss.sys
0x90400000 \SystemRoot\system32\drivers\nsiproxy.sys
0x8EFDB000 \SystemRoot\System32\Drivers\dfsc.sys
0x9080E000 \SystemRoot\System32\Drivers\aswSP.SYS
0x90A02000 \SystemRoot\System32\Drivers\appdrv01.sys
0x90D55000 \SystemRoot\system32\DRIVERS\usbccgp.sys
0x90D6C000 \SystemRoot\System32\Drivers\usbvideo.sys
0x90D8D000 \SystemRoot\System32\Drivers\fastfat.SYS
0x90DB5000 \SystemRoot\System32\Drivers\crashdmp.sys
0x90855000 \SystemRoot\System32\Drivers\dump_iaStor.sys
0x9A250000 \SystemRoot\System32\win32k.sys
0x90DC2000 \SystemRoot\System32\drivers\Dxapi.sys
0x90DCC000 \SystemRoot\system32\DRIVERS\monitor.sys
0x9A470000 \SystemRoot\System32\TSDDD.dll
0x9A490000 \SystemRoot\System32\cdd.dll
0x90DDB000 \SystemRoot\system32\drivers\luafv.sys
0x90930000 \??\C:\Windows\system32\drivers\aswMonFlt.sys
0x90DF6000 \SystemRoot\System32\Drivers\aswFsBlk.SYS
0x90967000 \SystemRoot\system32\DRIVERS\mwlPSDFilter.sys
0x8EA00000 \SystemRoot\system32\drivers\spsys.sys
0x90970000 \SystemRoot\system32\DRIVERS\irda.sys
0x9098E000 \SystemRoot\system32\DRIVERS\lltdio.sys
0x9099E000 \SystemRoot\system32\DRIVERS\nwifi.sys
0x909C8000 \SystemRoot\system32\DRIVERS\ndisuio.sys
0x909D2000 \SystemRoot\system32\DRIVERS\rspndr.sys
0xADC01000 \SystemRoot\system32\drivers\HTTP.sys
0xADC6E000 \SystemRoot\System32\DRIVERS\srvnet.sys
0xADC8B000 \SystemRoot\system32\DRIVERS\bowser.sys
0xADCA4000 \SystemRoot\System32\drivers\mpsdrv.sys
0xADCB9000 \SystemRoot\system32\drivers\mrxdav.sys
0xADCDA000 \SystemRoot\system32\DRIVERS\mrxsmb.sys
0xADCF9000 \SystemRoot\system32\DRIVERS\mrxsmb10.sys
0xADD32000 \SystemRoot\system32\DRIVERS\mrxsmb20.sys
0xADD4A000 \SystemRoot\System32\DRIVERS\srv2.sys
0xADD72000 \SystemRoot\System32\DRIVERS\srv.sys
0xAE004000 \??\C:\Windows\system32\drivers\acedrv11.sys
0xAE047000 \SystemRoot\system32\DRIVERS\atksgt.sys
0xAE08A000 \SystemRoot\system32\DRIVERS\lirsgt.sys
0xAE08F000 \SystemRoot\system32\DRIVERS\mwlPSDNServ.sys
0xAE098000 \SystemRoot\system32\DRIVERS\mwlPSDVDisk.sys
0xAE0AA000 \SystemRoot\system32\drivers\peauth.sys
0xAE188000 \SystemRoot\System32\Drivers\secdrv.SYS
0xAE192000 \SystemRoot\System32\drivers\tcpipreg.sys
0xAE19E000 \SystemRoot\system32\DRIVERS\cdfs.sys
0xAE1B4000 \??\C:\Users\jeremie\AppData\Local\Temp\catchme.sys
0xAE1BC000 \??\C:\Users\jeremie\AppData\Local\Temp\mbr.sys
0x77BF0000 \Windows\System32\ntdll.dll
0x10000000 \Program Files\DAEMON Tools Lite\Engine.dll
Processes (total 86):
0 System Idle Process
4 System
560 C:\Windows\System32\smss.exe
628 csrss.exe
672 C:\Windows\System32\wininit.exe
680 csrss.exe
724 C:\Windows\System32\services.exe
736 C:\Windows\System32\lsass.exe
748 C:\Windows\System32\lsm.exe
832 C:\Windows\System32\winlogon.exe
948 C:\Windows\System32\svchost.exe
1024 C:\Windows\System32\svchost.exe
1172 C:\Windows\System32\svchost.exe
1208 C:\Windows\System32\svchost.exe
1224 C:\Windows\System32\svchost.exe
1340 C:\Windows\System32\audiodg.exe
1364 C:\Windows\System32\svchost.exe
1392 C:\Windows\System32\SLsvc.exe
1436 C:\Windows\System32\svchost.exe
1636 C:\Windows\System32\svchost.exe
1756 C:\Program Files\Alwil Software\Avast5\AvastSvc.exe
2032 C:\Windows\System32\spoolsv.exe
364 C:\Windows\System32\svchost.exe
844 C:\Windows\System32\agrsmsvc.exe
1188 C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
1332 C:\Program Files\Bonjour\mDNSResponder.exe
1484 C:\Program Files\Acer Arcade Deluxe\HomeMedia\Kernel\DMP\CLHNService.exe
1612 C:\Program Files\Acer\Acer PowerSmart Manager\ePowerSvc.exe
1584 C:\Program Files\EgisTec\MyWinLocker 3\x86\MWLService.exe
2072 C:\Program Files\NewTech Infosystems\Acer Backup Manager\IScheduleSvc.exe
2148 C:\Program Files\NewTech Infosystems\NTI Backup Now 5\SchedulerSvc.exe
2176 C:\Windows\System32\svchost.exe
2196 C:\Windows\System32\svchost.exe
2224 C:\Windows\System32\svchost.exe
2248 C:\Windows\System32\SearchIndexer.exe
2716 C:\Windows\System32\taskeng.exe
2760 C:\Windows\System32\dwm.exe
2812 C:\Windows\System32\taskeng.exe
2832 C:\Windows\explorer.exe
3244 C:\Program Files\Acer Arcade Deluxe\Acer Arcade Deluxe\ArcadeDeluxeAgent.exe
3252 C:\Windows\System32\igfxsrvc.exe
3268 C:\Program Files\Acer Arcade Deluxe\Acer Arcade Deluxe\Kernel\CLML\CLMLSvc.exe
3276 C:\Program Files\Realtek\Audio\HDA\RtHDVCpl.exe
3284 C:\Windows\PLFSetI.exe
3292 C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
3364 C:\Program Files\Launch Manager\LManager.exe
3420 C:\Program Files\NewTech Infosystems\Acer Backup Manager\BackupManagerTray.exe
3540 C:\Program Files\EgisTec Egis Software Update\EgisUpdate.exe
3564 C:\Program Files\EgisTec\MyWinLocker 3\x86\mwlDaemon.exe
3592 C:\Program Files\Acer Arcade Deluxe\PlayMovie\PMVService.exe
3692 C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe
3712 C:\Program Files\Acer\Acer PowerSmart Manager\ePowerTray.exe
3836 C:\Program Files\Alwil Software\Avast5\AvastUI.exe
3844 C:\Program Files\ZHPDiag\Quarantine\mirc.exe.VIR
3904 C:\Users\jeremie\AppData\Local\Temp\RtkBtMnt.exe
3944 C:\Windows\System32\igfxext.exe
3964 C:\Program Files\Common Files\Java\Java Update\jusched.exe
3996 C:\Windows\System32\wbem\unsecapp.exe
2188 WmiPrvSE.exe
2240 C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe
2456 C:\Program Files\iTunes\iTunesHelper.exe
2756 C:\Windows\System32\igfxtray.exe
3084 C:\Windows\System32\hkcmd.exe
720 C:\Windows\System32\igfxpers.exe
2680 C:\Program Files\Acer\Acer PowerSmart Manager\ePowerEvent.exe
2632 C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
3360 C:\Program Files\Windows Live\Messenger\msnmsgr.exe
3536 C:\Windows\System32\mobsync.exe
3396 C:\Windows\System32\igfxext.exe
3580 C:\Program Files\Common Files\Ahead\Lib\NMBgMonitor.exe
3760 C:\Program Files\Steam\steam.exe
3880 C:\Windows\System32\igfxsrvc.exe
3148 C:\Program Files\DAEMON Tools Lite\DTLite.exe
1456 C:\Program Files\Skype\Phone\Skype.exe
3584 C:\Program Files\WinZip\WZQKPICK.EXE
3220 C:\Program Files\Common Files\Ahead\Lib\NMIndexingService.exe
1616 C:\Program Files\Common Files\Ahead\Lib\NMIndexStoreSvr.exe
3180 C:\Program Files\iPod\bin\iPodService.exe
3356 C:\Program Files\Synaptics\SynTP\SynTPHelper.exe
4476 C:\Windows\System32\svchost.exe
5264 C:\Program Files\Mozilla Firefox\firefox.exe
5356 C:\Program Files\Skype\Toolbars\Shared\SkypeNames2.exe
5512 C:\Program Files\Mozilla Firefox\plugin-container.exe
5908 C:\Windows\System32\wuauclt.exe
3040 C:\Windows\System32\conime.exe
5500 C:\Program Files\ZHPDiag\mbrcheck.exe
\\.\C: --> \\.\PhysicalDrive0 at offset 0x00000002'71100000 (NTFS)
PhysicalDrive0 Model Number: WDCWD5000BEVT-22ZAT0, Rev: 01.01A01
Size Device Name MBR Status
--------------------------------------------
465 GB \\.\PhysicalDrive0 Unknown MBR code
SHA1: 00DA077E92625BC67BBA239DB4218A4A12648922
Found non-standard or infected MBR.
Enter 'Y' and hit ENTER for more options, or 'N' to exit:
MBRCheck, version 1.2.3
(c) 2010, AD
Command-line:
Windows Version: Windows Vista Home Premium Edition
Windows Information: Service Pack 2 (build 6002), 32-bit
Base Board Manufacturer: Acer
BIOS Manufacturer: Phoenix Technologies LTD
System Manufacturer: Acer
System Product Name: Aspire 5738
Logical Drives Mask: 0x0000001c
Kernel Drivers (total 156):
0x83047000 \SystemRoot\system32\ntkrnlpa.exe
0x83014000 \SystemRoot\system32\hal.dll
0x80407000 \SystemRoot\system32\kdcom.dll
0x8040E000 \SystemRoot\system32\mcupdate_GenuineIntel.dll
0x8047E000 \SystemRoot\system32\PSHED.dll
0x8048F000 \SystemRoot\system32\BOOTVID.dll
0x80497000 \SystemRoot\system32\CLFS.SYS
0x804D8000 \SystemRoot\system32\CI.dll
0x80608000 \SystemRoot\system32\drivers\Wdf01000.sys
0x80684000 \SystemRoot\system32\drivers\WDFLDR.SYS
0x80691000 \SystemRoot\System32\Drivers\spkr.sys
0x80784000 \SystemRoot\System32\Drivers\WMILIB.SYS
0x8078D000 \SystemRoot\System32\Drivers\SCSIPORT.SYS
0x807B3000 \SystemRoot\system32\drivers\acpi.sys
0x80600000 \SystemRoot\system32\drivers\msisadrv.sys
0x805B8000 \SystemRoot\system32\drivers\pci.sys
0x805DF000 \SystemRoot\System32\drivers\partmgr.sys
0x807F9000 \SystemRoot\system32\DRIVERS\compbatt.sys
0x805EE000 \SystemRoot\system32\DRIVERS\BATTC.SYS
0x83601000 \SystemRoot\system32\drivers\volmgr.sys
0x83610000 \SystemRoot\System32\drivers\volmgrx.sys
0x8365A000 \SystemRoot\System32\drivers\mountmgr.sys
0x8366A000 \SystemRoot\system32\DRIVERS\iaStor.sys
0x83745000 \SystemRoot\system32\drivers\atapi.sys
0x8374D000 \SystemRoot\system32\drivers\ataport.SYS
0x8376B000 \SystemRoot\system32\drivers\msahci.sys
0x83775000 \SystemRoot\system32\drivers\PCIIDEX.SYS
0x83783000 \SystemRoot\system32\drivers\fltmgr.sys
0x837B5000 \SystemRoot\system32\drivers\fileinfo.sys
0x8B003000 \SystemRoot\System32\Drivers\ksecdd.sys
0x8B074000 \SystemRoot\system32\drivers\ndis.sys
0x8B17F000 \SystemRoot\system32\drivers\msrpc.sys
0x8B1AA000 \SystemRoot\system32\drivers\NETIO.SYS
0x8B205000 \SystemRoot\System32\Drivers\Ntfs.sys
0x8B315000 \SystemRoot\system32\drivers\volsnap.sys
0x8B34E000 \SystemRoot\System32\Drivers\spldr.sys
0x8B356000 \SystemRoot\System32\Drivers\mup.sys
0x8B365000 \SystemRoot\System32\drivers\ecache.sys
0x8B38C000 \SystemRoot\system32\drivers\disk.sys
0x8B39D000 \SystemRoot\system32\drivers\CLASSPNP.SYS
0x8B3BE000 \SystemRoot\system32\drivers\crcdisk.sys
0x8EAF1000 \SystemRoot\system32\DRIVERS\tunnel.sys
0x8EAFC000 \SystemRoot\system32\DRIVERS\tunmp.sys
0x8F202000 \SystemRoot\system32\DRIVERS\igdkmd32.sys
0x8FB1F000 \SystemRoot\System32\drivers\dxgkrnl.sys
0x8FBBF000 \SystemRoot\System32\drivers\watchdog.sys
0x8FBCB000 \SystemRoot\system32\DRIVERS\usbuhci.sys
0x8EB05000 \SystemRoot\system32\DRIVERS\USBPORT.SYS
0x8FBD6000 \SystemRoot\system32\DRIVERS\usbehci.sys
0x8EB43000 \SystemRoot\system32\DRIVERS\HDAudBus.sys
0x837C5000 \SystemRoot\system32\DRIVERS\k57nd60x.sys
0x8EE0A000 \SystemRoot\system32\DRIVERS\athr.sys
0x8EEFA000 \SystemRoot\system32\DRIVERS\CmBatt.sys
0x8EEFE000 \SystemRoot\system32\DRIVERS\i8042prt.sys
0x8EF11000 \SystemRoot\system32\DRIVERS\DKbFltr.sys
0x8EF1B000 \SystemRoot\system32\DRIVERS\kbdclass.sys
0x8EF26000 \SystemRoot\system32\DRIVERS\SynTP.sys
0x8EF57000 \SystemRoot\system32\DRIVERS\USBD.SYS
0x8EF59000 \SystemRoot\system32\DRIVERS\mouclass.sys
0x8EF64000 \SystemRoot\system32\DRIVERS\cdrom.sys
0x8EF7C000 \SystemRoot\system32\Drivers\NTIDrvr.sys
0x8EF84000 \SystemRoot\system32\DRIVERS\GEARAspiWDM.sys
0x8EF8A000 \SystemRoot\System32\Drivers\ancwjlvw.SYS
0x8EFC3000 \SystemRoot\system32\DRIVERS\wmiacpi.sys
0x8EFCC000 \SystemRoot\system32\DRIVERS\intelppm.sys
0x8EBD0000 \SystemRoot\system32\DRIVERS\msiscsi.sys
0x8FE08000 \SystemRoot\system32\DRIVERS\storport.sys
0x8FE49000 \SystemRoot\system32\DRIVERS\TDI.SYS
0x8FE54000 \SystemRoot\system32\DRIVERS\rasl2tp.sys
0x8FE6B000 \SystemRoot\system32\DRIVERS\ndistapi.sys
0x8FE76000 \SystemRoot\system32\DRIVERS\ndiswan.sys
0x8FE99000 \SystemRoot\system32\DRIVERS\raspppoe.sys
0x8FEA8000 \SystemRoot\system32\DRIVERS\raspptp.sys
0x8FEBC000 \SystemRoot\system32\DRIVERS\rassstp.sys
0x8FED1000 \SystemRoot\system32\DRIVERS\termdd.sys
0x8FEE1000 \SystemRoot\system32\DRIVERS\swenum.sys
0x8FEE3000 \SystemRoot\system32\DRIVERS\ks.sys
0x8FF0D000 \SystemRoot\system32\DRIVERS\mssmbios.sys
0x8FF17000 \SystemRoot\system32\DRIVERS\umbus.sys
0x8FF24000 \SystemRoot\system32\DRIVERS\usbhub.sys
0x8FF59000 \SystemRoot\System32\Drivers\NDProxy.SYS
0x9000F000 \SystemRoot\system32\drivers\RTKVHDA.sys
0x90245000 \SystemRoot\system32\drivers\portcls.sys
0x90272000 \SystemRoot\system32\drivers\drmk.sys
0x90297000 \SystemRoot\system32\DRIVERS\AGRSM.sys
0x903BD000 \SystemRoot\system32\drivers\modem.sys
0x903CA000 \SystemRoot\system32\drivers\IntcHdmi.sys
0x903EB000 \SystemRoot\System32\Drivers\Fs_Rec.SYS
0x903F4000 \SystemRoot\System32\Drivers\Null.SYS
0x90000000 \SystemRoot\System32\Drivers\Beep.SYS
0x8FF6A000 \SystemRoot\System32\drivers\vga.sys
0x8FF76000 \SystemRoot\System32\drivers\VIDEOPRT.SYS
0x90007000 \SystemRoot\System32\DRIVERS\RDPCDD.sys
0x8FF97000 \SystemRoot\system32\drivers\rdpencdd.sys
0x8FF9F000 \SystemRoot\System32\Drivers\Msfs.SYS
0x8FFAA000 \SystemRoot\System32\Drivers\Npfs.SYS
0x8FFB8000 \SystemRoot\System32\DRIVERS\rasacd.sys
0x9040C000 \SystemRoot\System32\drivers\tcpip.sys
0x904F6000 \SystemRoot\System32\drivers\fwpkclnt.sys
0x90511000 \SystemRoot\system32\DRIVERS\tdx.sys
0x90527000 \SystemRoot\System32\Drivers\aswTdi.SYS
0x90531000 \SystemRoot\system32\DRIVERS\smb.sys
0x90545000 \SystemRoot\system32\drivers\afd.sys
0x9058D000 \SystemRoot\System32\Drivers\aswRdr.SYS
0x90592000 \SystemRoot\System32\DRIVERS\netbt.sys
0x905C4000 \SystemRoot\system32\DRIVERS\pacer.sys
0x905DA000 \SystemRoot\system32\DRIVERS\netbios.sys
0x905E8000 \SystemRoot\system32\DRIVERS\wanarp.sys
0x8FFC1000 \SystemRoot\system32\DRIVERS\rdbss.sys
0x90400000 \SystemRoot\system32\drivers\nsiproxy.sys
0x8EFDB000 \SystemRoot\System32\Drivers\dfsc.sys
0x9080E000 \SystemRoot\System32\Drivers\aswSP.SYS
0x90A02000 \SystemRoot\System32\Drivers\appdrv01.sys
0x90D55000 \SystemRoot\system32\DRIVERS\usbccgp.sys
0x90D6C000 \SystemRoot\System32\Drivers\usbvideo.sys
0x90D8D000 \SystemRoot\System32\Drivers\fastfat.SYS
0x90DB5000 \SystemRoot\System32\Drivers\crashdmp.sys
0x90855000 \SystemRoot\System32\Drivers\dump_iaStor.sys
0x9A250000 \SystemRoot\System32\win32k.sys
0x90DC2000 \SystemRoot\System32\drivers\Dxapi.sys
0x90DCC000 \SystemRoot\system32\DRIVERS\monitor.sys
0x9A470000 \SystemRoot\System32\TSDDD.dll
0x9A490000 \SystemRoot\System32\cdd.dll
0x90DDB000 \SystemRoot\system32\drivers\luafv.sys
0x90930000 \??\C:\Windows\system32\drivers\aswMonFlt.sys
0x90DF6000 \SystemRoot\System32\Drivers\aswFsBlk.SYS
0x90967000 \SystemRoot\system32\DRIVERS\mwlPSDFilter.sys
0x8EA00000 \SystemRoot\system32\drivers\spsys.sys
0x90970000 \SystemRoot\system32\DRIVERS\irda.sys
0x9098E000 \SystemRoot\system32\DRIVERS\lltdio.sys
0x9099E000 \SystemRoot\system32\DRIVERS\nwifi.sys
0x909C8000 \SystemRoot\system32\DRIVERS\ndisuio.sys
0x909D2000 \SystemRoot\system32\DRIVERS\rspndr.sys
0xADC01000 \SystemRoot\system32\drivers\HTTP.sys
0xADC6E000 \SystemRoot\System32\DRIVERS\srvnet.sys
0xADC8B000 \SystemRoot\system32\DRIVERS\bowser.sys
0xADCA4000 \SystemRoot\System32\drivers\mpsdrv.sys
0xADCB9000 \SystemRoot\system32\drivers\mrxdav.sys
0xADCDA000 \SystemRoot\system32\DRIVERS\mrxsmb.sys
0xADCF9000 \SystemRoot\system32\DRIVERS\mrxsmb10.sys
0xADD32000 \SystemRoot\system32\DRIVERS\mrxsmb20.sys
0xADD4A000 \SystemRoot\System32\DRIVERS\srv2.sys
0xADD72000 \SystemRoot\System32\DRIVERS\srv.sys
0xAE004000 \??\C:\Windows\system32\drivers\acedrv11.sys
0xAE047000 \SystemRoot\system32\DRIVERS\atksgt.sys
0xAE08A000 \SystemRoot\system32\DRIVERS\lirsgt.sys
0xAE08F000 \SystemRoot\system32\DRIVERS\mwlPSDNServ.sys
0xAE098000 \SystemRoot\system32\DRIVERS\mwlPSDVDisk.sys
0xAE0AA000 \SystemRoot\system32\drivers\peauth.sys
0xAE188000 \SystemRoot\System32\Drivers\secdrv.SYS
0xAE192000 \SystemRoot\System32\drivers\tcpipreg.sys
0xAE19E000 \SystemRoot\system32\DRIVERS\cdfs.sys
0xAE1B4000 \??\C:\Users\jeremie\AppData\Local\Temp\catchme.sys
0xAE1BC000 \??\C:\Users\jeremie\AppData\Local\Temp\mbr.sys
0x77BF0000 \Windows\System32\ntdll.dll
0x10000000 \Program Files\DAEMON Tools Lite\Engine.dll
Processes (total 86):
0 System Idle Process
4 System
560 C:\Windows\System32\smss.exe
628 csrss.exe
672 C:\Windows\System32\wininit.exe
680 csrss.exe
724 C:\Windows\System32\services.exe
736 C:\Windows\System32\lsass.exe
748 C:\Windows\System32\lsm.exe
832 C:\Windows\System32\winlogon.exe
948 C:\Windows\System32\svchost.exe
1024 C:\Windows\System32\svchost.exe
1172 C:\Windows\System32\svchost.exe
1208 C:\Windows\System32\svchost.exe
1224 C:\Windows\System32\svchost.exe
1340 C:\Windows\System32\audiodg.exe
1364 C:\Windows\System32\svchost.exe
1392 C:\Windows\System32\SLsvc.exe
1436 C:\Windows\System32\svchost.exe
1636 C:\Windows\System32\svchost.exe
1756 C:\Program Files\Alwil Software\Avast5\AvastSvc.exe
2032 C:\Windows\System32\spoolsv.exe
364 C:\Windows\System32\svchost.exe
844 C:\Windows\System32\agrsmsvc.exe
1188 C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
1332 C:\Program Files\Bonjour\mDNSResponder.exe
1484 C:\Program Files\Acer Arcade Deluxe\HomeMedia\Kernel\DMP\CLHNService.exe
1612 C:\Program Files\Acer\Acer PowerSmart Manager\ePowerSvc.exe
1584 C:\Program Files\EgisTec\MyWinLocker 3\x86\MWLService.exe
2072 C:\Program Files\NewTech Infosystems\Acer Backup Manager\IScheduleSvc.exe
2148 C:\Program Files\NewTech Infosystems\NTI Backup Now 5\SchedulerSvc.exe
2176 C:\Windows\System32\svchost.exe
2196 C:\Windows\System32\svchost.exe
2224 C:\Windows\System32\svchost.exe
2248 C:\Windows\System32\SearchIndexer.exe
2716 C:\Windows\System32\taskeng.exe
2760 C:\Windows\System32\dwm.exe
2812 C:\Windows\System32\taskeng.exe
2832 C:\Windows\explorer.exe
3244 C:\Program Files\Acer Arcade Deluxe\Acer Arcade Deluxe\ArcadeDeluxeAgent.exe
3252 C:\Windows\System32\igfxsrvc.exe
3268 C:\Program Files\Acer Arcade Deluxe\Acer Arcade Deluxe\Kernel\CLML\CLMLSvc.exe
3276 C:\Program Files\Realtek\Audio\HDA\RtHDVCpl.exe
3284 C:\Windows\PLFSetI.exe
3292 C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
3364 C:\Program Files\Launch Manager\LManager.exe
3420 C:\Program Files\NewTech Infosystems\Acer Backup Manager\BackupManagerTray.exe
3540 C:\Program Files\EgisTec Egis Software Update\EgisUpdate.exe
3564 C:\Program Files\EgisTec\MyWinLocker 3\x86\mwlDaemon.exe
3592 C:\Program Files\Acer Arcade Deluxe\PlayMovie\PMVService.exe
3692 C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe
3712 C:\Program Files\Acer\Acer PowerSmart Manager\ePowerTray.exe
3836 C:\Program Files\Alwil Software\Avast5\AvastUI.exe
3844 C:\Program Files\ZHPDiag\Quarantine\mirc.exe.VIR
3904 C:\Users\jeremie\AppData\Local\Temp\RtkBtMnt.exe
3944 C:\Windows\System32\igfxext.exe
3964 C:\Program Files\Common Files\Java\Java Update\jusched.exe
3996 C:\Windows\System32\wbem\unsecapp.exe
2188 WmiPrvSE.exe
2240 C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe
2456 C:\Program Files\iTunes\iTunesHelper.exe
2756 C:\Windows\System32\igfxtray.exe
3084 C:\Windows\System32\hkcmd.exe
720 C:\Windows\System32\igfxpers.exe
2680 C:\Program Files\Acer\Acer PowerSmart Manager\ePowerEvent.exe
2632 C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
3360 C:\Program Files\Windows Live\Messenger\msnmsgr.exe
3536 C:\Windows\System32\mobsync.exe
3396 C:\Windows\System32\igfxext.exe
3580 C:\Program Files\Common Files\Ahead\Lib\NMBgMonitor.exe
3760 C:\Program Files\Steam\steam.exe
3880 C:\Windows\System32\igfxsrvc.exe
3148 C:\Program Files\DAEMON Tools Lite\DTLite.exe
1456 C:\Program Files\Skype\Phone\Skype.exe
3584 C:\Program Files\WinZip\WZQKPICK.EXE
3220 C:\Program Files\Common Files\Ahead\Lib\NMIndexingService.exe
1616 C:\Program Files\Common Files\Ahead\Lib\NMIndexStoreSvr.exe
3180 C:\Program Files\iPod\bin\iPodService.exe
3356 C:\Program Files\Synaptics\SynTP\SynTPHelper.exe
4476 C:\Windows\System32\svchost.exe
5264 C:\Program Files\Mozilla Firefox\firefox.exe
5356 C:\Program Files\Skype\Toolbars\Shared\SkypeNames2.exe
5512 C:\Program Files\Mozilla Firefox\plugin-container.exe
5908 C:\Windows\System32\wuauclt.exe
3040 C:\Windows\System32\conime.exe
5500 C:\Program Files\ZHPDiag\mbrcheck.exe
\\.\C: --> \\.\PhysicalDrive0 at offset 0x00000002'71100000 (NTFS)
PhysicalDrive0 Model Number: WDCWD5000BEVT-22ZAT0, Rev: 01.01A01
Size Device Name MBR Status
--------------------------------------------
465 GB \\.\PhysicalDrive0 Unknown MBR code
SHA1: 00DA077E92625BC67BBA239DB4218A4A12648922
Found non-standard or infected MBR.
Enter 'Y' and hit ENTER for more options, or 'N' to exit:
pas cool !!!
* /!\Avertissement :
Ce logiciel n'est à utiliser que prescrit par un helper qualifié.
Ne pas utiliser en dehors de ce cas de figure : dangereux!
/!\ Utilisateur de Vista : Ne pas oublier de désactiver l'UAC juste le temps de désinfection de ton pc, il sera à réactiver plus tard :
Tuto : https://www.commentcamarche.net/faq/8343-vista-desactiver-l-uac
► Télécharges ComboFix à partir de ce lien et enregistres le sur ton bureau :
https://forum.pcastuces.com/combofix_renomme_au_telechargement-f31s22.htm
ou ici :
http://download.bleepingcomputer.com/sUBs/ComboFix.exe
A lire
https://www.bleepingcomputer.com/combofix/fr/comment-utiliser-combofix
Avant d'utiliser ComboFix :
► ferme les fenêtres de tous les programmes en cours.
► Désactive provisoirement et seulement le temps de l'utilisation de ComboFix, la protection en temps réel de ton Antivirus et de tes Antispywares, qui peuvent gêner fortement la procédure de recherche et de nettoyage de l'outil.
Une fois fait, sur ton bureau double-clic sur Combofix.exe.
/!\Utilisateur de Vista : Clique droit sur le logo de Combofix, « exécuter en tant qu'Administrateur »
- Répond oui au message d'avertissement, pour que le programme commence à procéder à l'analyse du pc.
- il se peut que Combofix ait besoin de se connecter à internet pour trouver les mises à jour, donc il faut l'autoriser.
/!\ Pendant la durée de cette étape, ne te sert pas du pc et n'ouvre aucun programmes.
- En fin de scan il est possible que ComboFix ait besoin de redémarrer le pc pour finaliser la désinfection\recherche, laisses-le faire.
- Un rapport s'ouvrira ensuite dans le bloc notes, ce fichier rapport Combofix.txt, est automatiquement sauvegardé et rangé à C:\Combofix.txt)
► Réactive la protection en temps réel de ton Antivirus et de tes Antispywares, avant de te reconnecter à internet.
► Reviens sur le forum, et copie et colle la totalité du contenu de C:\Combofix.txt dans ton prochain message
* /!\Avertissement :
Ce logiciel n'est à utiliser que prescrit par un helper qualifié.
Ne pas utiliser en dehors de ce cas de figure : dangereux!
/!\ Utilisateur de Vista : Ne pas oublier de désactiver l'UAC juste le temps de désinfection de ton pc, il sera à réactiver plus tard :
Tuto : https://www.commentcamarche.net/faq/8343-vista-desactiver-l-uac
► Télécharges ComboFix à partir de ce lien et enregistres le sur ton bureau :
https://forum.pcastuces.com/combofix_renomme_au_telechargement-f31s22.htm
ou ici :
http://download.bleepingcomputer.com/sUBs/ComboFix.exe
A lire
https://www.bleepingcomputer.com/combofix/fr/comment-utiliser-combofix
Avant d'utiliser ComboFix :
► ferme les fenêtres de tous les programmes en cours.
► Désactive provisoirement et seulement le temps de l'utilisation de ComboFix, la protection en temps réel de ton Antivirus et de tes Antispywares, qui peuvent gêner fortement la procédure de recherche et de nettoyage de l'outil.
Une fois fait, sur ton bureau double-clic sur Combofix.exe.
/!\Utilisateur de Vista : Clique droit sur le logo de Combofix, « exécuter en tant qu'Administrateur »
- Répond oui au message d'avertissement, pour que le programme commence à procéder à l'analyse du pc.
- il se peut que Combofix ait besoin de se connecter à internet pour trouver les mises à jour, donc il faut l'autoriser.
/!\ Pendant la durée de cette étape, ne te sert pas du pc et n'ouvre aucun programmes.
- En fin de scan il est possible que ComboFix ait besoin de redémarrer le pc pour finaliser la désinfection\recherche, laisses-le faire.
- Un rapport s'ouvrira ensuite dans le bloc notes, ce fichier rapport Combofix.txt, est automatiquement sauvegardé et rangé à C:\Combofix.txt)
► Réactive la protection en temps réel de ton Antivirus et de tes Antispywares, avant de te reconnecter à internet.
► Reviens sur le forum, et copie et colle la totalité du contenu de C:\Combofix.txt dans ton prochain message