Bit comet, Toolbar HP et ASK...

Résolu
Bonjour,

J'ai recemment télécharger bitcomet,depuis ad aware me detecte deux virus (Rogue.Link et un virus wslib.dll dans le répertoire de bit defender )
Que faire pour réparer cela?

Merci d'avance de votre réponse !
XS

PS:J'ai également remarqué l'apparition d'une toolbar "ASK.COM" (dont je n'ai jamais demandé l'installation ) et d'une toolbar "HP" qui a du s'installer quand j'ai installer les pilotes de mon imprimantes mais c'est quoi cette folie de créer des toolbars? Sa sert a quoi une toolbar?Comment les enlever ?

Aurevoir

21 réponses

Résumé de la discussion

L’installation de BitComet déclenche des détections Rogue.Link et wslib.dll par Ad-Aware et l’apparition de toolbars non sollicitées (Ask.com et HP), suscitant des questions sur les mesures à prendre. Plusieurs solutions évoquées impliquent des outils de nettoyage et de diagnostic comme ZHPDiag et ZHPFix, DelFix et Ad-Remover, puis redémarrage et vérification des rapports pour confirmer la suppression des éléments indésirables. D'autres proposent Malwarebytes, le retrait des toolbars et l'examen du système de démarrage, ou l'utilisation d'un outil comme mbr.exe pour vérifier le MBR et éviter les rootkits. D'un autre côté, certains soulignent des faux positifs et recommandent de vérifier les rapports finaux pour confirmer une désinfection complète.

Bobot (l’IA à votre service)
  1. Contributeur sécurité
    1)

    Copie tout le texte présent en gras ci-dessous ( tu le selectionnes avec ta souris / Clique droit dessus et choisis "copier" ou fait Ctrl+C )

    P2 - FPN:Firefox Plugin Navigator . (.BitComet - BitCometAgent v1.23 for Firefox.) -- C:\Program Files\Mozilla Firefox\Plugins\npBitCometAgent.dll
    M2 - MFEP: prefs.js [skyfucker - plnl7upj.default\{B042753D-F57E-4e8e-A01B-7379A6D4CEFB}] [] BitComet è§+é¢`ä¸<è½½å(TM)¨ v1.25 (.BitComet.)
    O2 - BHO: BitComet ClickCapture - {39F7E362-828A-4B5A-BCAF-5B79BFDFEA60} . (.BitComet - BitCometBHO.) -- C:\Program Files\BitComet\tools\BitCometBHO_1.4.12.6.dll
    O8 - Extra context menu item: Tout télécharger avec BitComet . (.www.BitComet.com - BitComet - a BitTorrent Client.) -- C:\Program Files\BitComet\BitComet.exe
    O8 - Extra context menu item: Télécharger avec BitComet . (.www.BitComet.com - BitComet - a BitTorrent Client.) -- C:\Program Files\BitComet\BitComet.exe
    O9 - Extra button: @btrez.dll,-12650 - {D18A0B52-D63C-4ed0-AFC6-C1E3DC1AF43A} . (.BitComet - BitCometBHO.) -- C:\Program Files\BitComet\tools\BitCometBHO_1.4.12.6.dll
    O23 - Service: (BITCOMET_HELPER_SERVICE) . (.www.BitComet.com - BitComet disk boost service.) - C:\Program Files\BitComet\tools\BitCometService.exe
    O42 - Logiciel: BitComet 1.26 - (.CometNetwork.) [HKLM] -- BitComet
    [HKCU\Software\BitComet]
    O43 - CFD: 20/03/2011 - 15:15:08 - [25565118] ----D- C:\Program Files\BitComet
    O43 - CFD: 21/03/2011 - 07:30:00 - [324704] ----D- C:\Users\skyfucker\AppData\Roaming\BitComet
    O87 - FAEL: "{BACC0B78-6219-41BB-A089-D282686C58B5}" | In - Private - P6 - TRUE | .(.www.BitComet.com - BitComet - a BitTorrent Client.) -- C:\Program Files\BitComet\BitComet.exe
    O87 - FAEL: "{07F3E719-6A24-4B7C-9A52-4473C1C51D7F}" | In - Private - P17 - TRUE | .(.www.BitComet.com - BitComet - a BitTorrent Client.) -- C:\Program Files\BitComet\BitComet.exe
    SS - | Demand 28/12/2010 1296728 | (BITCOMET_HELPER_SERVICE) . (.www.BitComet.com.) - C:\Program Files\BitComet\tools\BitCometService.exe
    O4 - Global Startup: C:\Users\skyfucker\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\eBay Startseite.lnk . (...) -- C:\Program Files\ClearProg\eBay\eBayShortcuts.exe (.not file.)
    O4 - Global Startup: C:\Users\skyfucker\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Safe.lnk . (...) -- C:\Program Files\Steganos Safe One\Safe.exe


    Puis Lance ZHPFix depuis le raccourci du bureau .

    * Une fois l'outil ZHPFix ouvert , clique sur le bouton [ H ] ( "coller les lignes Helper" ) .

    * Dans l'encadré principal tu verras donc les lignes que tu as copié précédemment apparaitrent .

    Vérifie que toutes les lignes que je t'ai demandé de copier (et seulement elles) sont dans la fenêtre.

    Clique sur " Ok " , puis " Tous " et enfin " Nettoyer ".

    Copie/Colle le rapport à l'écran dans ton prochain message

    le rapport se trouve dans le dossier de zhpdiag dans program files sous le nom de ZHPFixReport

    _____________

    2)

    redemarre le pc et dis moi si tu as encore des soucis
    1
    1. Sa va pas supprimer steganos au moins?
      0
    2. Contributeur sécurité
      tu parles de ca ?

      O4 - Global Startup: C:\Users\skyfucker\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Safe.lnk . (...) -- C:\Program Files\Steganos Safe One\Safe.exe
      0
    3. Ouais
      0
    4. Contributeur sécurité
      non c'est lui Safe.lnk qui est de plus absent car (...)

      juste la trace
      0
    5. Ok !
      0
  2. Contributeur sécurité
    bonjour

    fais ceci

    1)

    * Télécharge de AD-Remover sur ton Bureau. (Merci à C_XX)
    http://www.teamxscript.org/adremoverTelechargement.html

    /!\ Déconnecte-toi d'internet et ferme toutes applications en cours /!\

    Désactive provisoirement et seulement le temps de l'utilisation de ADremover, la protection en temps réel de ton Antivirus et de tes Antispywares, qui peuvent gêner fortement la procédure de recherche et de nettoyage de l'outil.

    - Double-clique sur l'icône Ad-remover située sur ton Bureau.
    - Sur la page, clique sur le bouton « NETTOYER »
    - Confirme lancement du scan
    - Laisse travailler l'outil.
    - Poste le rapport qui apparaît à la fin.

    (Le rapport est sauvegardé aussi sous C:\Ad-report(Scan/clean).Txt)

    (CTRL+A pour tout sélectionner, CTRL+C pour copier et CTRL+V pour coller)

    _____________

    2)

    Télécharge ZHPDiag ( de Nicolas coolman ).
    https://www.zebulon.fr/telechargements/securite/systeme/zhpdiag.html

    ou

    https://www.commentcamarche.net/telecharger/utilitaires/24803-zhpdiag/


    (outil de diagnostic)


    Double clique sur le fichier d'installation, puis installe le avec les paramètres par défaut ( N'oublie pas de cocher " Créer une icône sur le bureau " )

    Lance ZHPDiag en double cliquant sur l'icône présente sur ton bureau (Clique droit -> Executer en tant qu'admin ( vista )

    Clique sur la loupe en haut à gauche, puis laisse l'outil scanner.

    Une fois le scan terminé, clique sur l'icône en forme de disquette et enregistre le fichier sur ton bureau.

    Rend toi sur http://pjjoint.malekal.com/

    Clique sur "Parcourir "

    Sélectionne le rapport ZHPdiag.txt qui se trouve sur ton bureau

    Clique ensuite sur "Envoyer le fichier " et copie/colle le lien dans ton prochain message

    0
    1. Ok je fais sa !
      0
  3. pour wslib.dll c'est un faux positif
    et ad aware tu peu le virer il est complètement désuet
    ASK peut etre virer avec ad-remover https://www.commentcamarche.net/telecharger/securite/2547-ad-remover/

    Quand les bornes sont franchies, il n'y a plus de limite
    Ce que j'ai écrit, je l'ai écrit
    0
    1. Pourquoi ad aware est désuet?
      0
    2. ok c'est fait moment de grace =)
      0
  4. Rapport ad-r: http://pjjoint.malekal.com/files.php?read=f49df536dd51312
    0
    1. Rapport Zhp Diag: http://pjjoint.malekal.com/files.php?read=5f135bcfc914149
      0
      1. Et autre probleme je ne peux pas mettre a jour la base de signature de virus de bit defender (??) Pourquoi?
        Merci encore de votre aide !
        0
        1. Contributeur sécurité
          le zhp ne montre pas grand chose

          1)

          Lances ZHPFix depuis le raccourci du Bureau (en mode administrateur si Vista/W7),
          Cliques sur le bouton 'MBRFix' situé dans la partie droite de l'écran,
          Cliques sur 'Non' au message qui s'affiche à l'écran,
          Laisses travailler l'outil,
          A la fin du traitement, un rapport s'affiche
          Copie ce rapport
          Redémarre le pc pour prendre en compte les modifications.

          __________

          2)

          Téléchargez MalwareByte's Anti-Malware (que tu pourras garder ensuite)

          https://www.commentcamarche.net/telecharger/securite/14361-malwarebytes-anti-malware/

          . Enregistres le sur le bureau
          . Double cliques sur le fichier téléchargé pour lancer le processus d'installation.
          . Dans l'onglet "mise à jour", cliques sur le bouton Recherche de mise à jour
          . Si le pare-feu demande l'autorisation de se connecter pour malwarebytes, accepte
          . Une fois la mise à jour terminé
          . Rend-toi dans l'onglet, Recherche
          . Sélectionnes Exécuter un examen rapide
          . Cliques sur Rechercher
          . Le scan démarre.
          . A la fin de l'analyse, un message s'affiche : L'examen s'est terminé normalement. Cliquez sur 'Afficher les résultats' pour afficher tous les objets trouvés.
          . Cliques sur Ok pour poursuivre.
          . Si des malwares ont été détectés, clique sur Afficher les résultats
          . Sélectionnes tout (ou laisses cochés) et cliques sur Supprimer la sélection Malwarebytes va détruire les fichiers et clés de registre et en mettre une copie dans la quarantaine.
          . Malwarebytes va ouvrir le bloc-notes et y copier le rapport d'analyse.
          . Rends toi dans l'onglet rapport/log
          . Tu cliques dessus pour l'afficher, une fois affiché
          . Tu cliques sur edition en haut du boc notes, et puis sur sélectionner tous
          . Tu recliques sur edition et puis sur copier et tu reviens sur le forum et dans ta réponse
          . tu cliques droit dans le cadre de la reponse et coller

          Si tu as besoin d'aide regarde ces tutoriels :
          Aide: https://www.malekal.com/tutoriel-malwarebyte-anti-malware/
          http://www.infos-du-net.com/forum/278396-11-tuto-malwarebytes-anti-malware-mbam
          0
          1. J'ai deja malware bytes xD
            0
        2. Rapport MBR FIX:http://pjjoint.malekal.com/files.php?read=1064104c1e10913
          Juste : C'est quoi Mbr fix ?
          J'ai quoi comme virus?
          Merci de ton aide !
          0
          1. Re !
            Aucune detection de malwarbytes !
            A+
            0
            1. Contributeur sécurité
              le mbr est ce qui précède windows lors du lancement

              /!\ Il faut impérativement désactiver tous tes logiciels de protection pour utiliser ce programme/!\
              * Télécharge mbr.exe de Gmer ici : http://www2.gmer.net/mbr/mbr.exe et enregistre le fichier sur le Bureau.
              * Merci à Malekal pour le tutoriel
              * Désactive tes protections et coupe la connexion. (Antivirus et antispywares, HIPS et autre résident)
              * Double clique sur mbr.exe
              * Un rapport sera généré : mbr.log
              * En cas d'infection, ce message "MBR rootkit code detected" va apparaitre.
              * Pour supprimer le rootkit aller dans le menu Démarrer=> Exécuter et tapez la commande en gras:

              => Sous XP : "%userprofile%\Bureau\mbr" -f

              => Sous Vista/Seven : "%userprofile%\Desktop\mbr" -f

              * (veuillez à bien respecter les guillemets)
              * Dans le mbr.log cette ligne apparaitra "original MBR restored successfully !"
              * Réactive tes protections .Poste ce rapport et supprime le ensuite.

              o Pour vérifier désactive tes protections et coupe la connexion. (Antivirus et antispywares, HIPS et autre résident)
              o Relance mbr.exe
              o Réactive tes protections.
              o Le nouveau mbr.log devrait être celui-ci :
              o Stealth MBR rootkit detector 0.2.4 by Gmer, http://www.gmer.net
              o device: opened successfully
              user: MBR read successfully
              kernel: MBR read successfully
              user & kernel MBR OK
              0
              1. Dans le mbr.log il y a pas de rootkit et quand je clique sur mbr.exe sa met une fenetre dos et m enregistre un le .log
                0
              2. Contributeur sécurité
                colle le contenu ici
                0
              3. Stealth MBR rootkit/Mebroot/Sinowal/TDL4 detector 0.4.2 by Gmer, http://www.gmer.net
                Windows 6.0.6001 Disk: TOSHIBA_MK3255GSX rev.FG010A -> Harddisk0\DR0 -> \Device\Ide\IdeDeviceP0T0L0-2

                device: opened successfully
                user: MBR read successfully
                kernel: MBR read successfully
                user & kernel MBR OK
                0
            2. Contributeur sécurité
              dans le doute

              * Télécharge load_tdsskiller (de Loup Blanc) sur ton Bureau

              http://fradesch.perso.cegetel.net/transf/Load_tdsskiller.exe

              * Lance load_tdsskiller en faisant un double-clic dessus / Lance par un clic-droit dessus ? Exécuter en temps qu'administrateur
              * L'outil va se connecter pour télécharger une copie à jour de TDSSKiller, puis va lancer une analyse
              * Lorsque l'outil a terminé son travail d'inspection, si des nuisibles ("Malicious objects") ont été trouvés, vérifier que l'option (Cure) est sélectionnée,
              * Si des objects suspects ("Suspicious objects") ont été détectés, sur l'écran de demande de confirmation, modifier l'action à entreprendre et indiquer Quarantine (au lieu de Skip),
              * A la fin, il te sera demandé d'appuyer sur une touche, puis le rapport s'affichera automatiquement : copie-colle son contenu dans ta prochaine réponse (C:\tdsskiller\report.txt)
              0
              1. 2011/03/27 12:21:58.0242 6096 TDSS rootkit removing tool 2.4.21.0 Mar 10 2011 12:26:28
                2011/03/27 12:22:00.0247 6096 ================================================================================
                2011/03/27 12:22:00.0247 6096 SystemInfo:
                2011/03/27 12:22:00.0247 6096
                2011/03/27 12:22:00.0247 6096 OS Version: 6.0.6001 ServicePack: 1.0
                2011/03/27 12:22:00.0248 6096 Product type: Workstation
                2011/03/27 12:22:00.0248 6096 ComputerName: PC-DE-SKYFUCKER
                2011/03/27 12:22:00.0248 6096 UserName: skyfucker
                2011/03/27 12:22:00.0248 6096 Windows directory: C:\Windows
                2011/03/27 12:22:00.0249 6096 System windows directory: C:\Windows
                2011/03/27 12:22:00.0249 6096 Processor architecture: Intel x86
                2011/03/27 12:22:00.0249 6096 Number of processors: 2
                2011/03/27 12:22:00.0249 6096 Page size: 0x1000
                2011/03/27 12:22:00.0249 6096 Boot type: Normal boot
                2011/03/27 12:22:00.0249 6096 ================================================================================
                2011/03/27 12:22:11.0053 6096 Initialize success
                2011/03/27 12:22:32.0691 2012 ================================================================================
                2011/03/27 12:22:32.0691 2012 Scan started
                2011/03/27 12:22:32.0691 2012 Mode: Manual;
                2011/03/27 12:22:32.0691 2012 ================================================================================
                2011/03/27 12:22:35.0065 2012 ACPI (fcb8c7210f0135e24c6580f7f649c73c) C:\Windows\system32\drivers\acpi.sys
                2011/03/27 12:22:36.0419 2012 acpihid (48fc4b61b87f1fc06f0848c3421e3a1f) C:\Windows\system32\DRIVERS\acpihid.sys
                2011/03/27 12:22:37.0755 2012 adp94xx (04f0fcac69c7c71a3ac4eb97fafc8303) C:\Windows\system32\drivers\adp94xx.sys
                2011/03/27 12:22:39.0112 2012 adpahci (60505e0041f7751bdbb80f88bf45c2ce) C:\Windows\system32\drivers\adpahci.sys
                2011/03/27 12:22:40.0481 2012 adpu160m (8a42779b02aec986eab64ecfc98f8bd7) C:\Windows\system32\drivers\adpu160m.sys
                2011/03/27 12:22:41.0811 2012 adpu320 (241c9e37f8ce45ef51c3de27515ca4e5) C:\Windows\system32\drivers\adpu320.sys
                2011/03/27 12:22:43.0171 2012 AFD (763e172a55177e478cb419f88fd0ba03) C:\Windows\system32\drivers\afd.sys
                2011/03/27 12:22:44.0511 2012 agp440 (13f9e33747e6b41a3ff305c37db0d360) C:\Windows\system32\drivers\agp440.sys
                2011/03/27 12:22:45.0874 2012 aic78xx (ae1fdf7bf7bb6c6a70f67699d880592a) C:\Windows\system32\drivers\djsvs.sys
                2011/03/27 12:22:47.0224 2012 aliide (9eaef5fc9b8e351afa7e78a6fae91f91) C:\Windows\system32\drivers\aliide.sys
                2011/03/27 12:22:48.0793 2012 amdagp (c47344bc706e5f0b9dce369516661578) C:\Windows\system32\drivers\amdagp.sys
                2011/03/27 12:22:50.0094 2012 amdide (9b78a39a4c173fdbc1321e0dd659b34c) C:\Windows\system32\drivers\amdide.sys
                2011/03/27 12:22:51.0407 2012 AmdK7 (18f29b49ad23ecee3d2a826c725c8d48) C:\Windows\system32\drivers\amdk7.sys
                2011/03/27 12:22:52.0775 2012 AmdK8 (93ae7f7dd54ab986a6f1a1b37be7442d) C:\Windows\system32\drivers\amdk8.sys
                2011/03/27 12:22:54.0125 2012 arc (5d2888182fb46632511acee92fdad522) C:\Windows\system32\drivers\arc.sys
                2011/03/27 12:22:55.0473 2012 arcsas (5e2a321bd7c8b3624e41fdec3e244945) C:\Windows\system32\drivers\arcsas.sys
                2011/03/27 12:22:56.0850 2012 AsyncMac (53b202abee6455406254444303e87be1) C:\Windows\system32\DRIVERS\asyncmac.sys
                2011/03/27 12:22:58.0174 2012 atapi (2d9c903dc76a66813d350a562de40ed9) C:\Windows\system32\drivers\atapi.sys
                2011/03/27 12:22:59.0711 2012 ATDrv (4bc14462b5e6e6c28d35e87e57968bd5) C:\Windows\system32\DRIVERS\ATDrv.sys
                2011/03/27 12:23:01.0080 2012 BDFM (0de9617eaa4ca5587c2f950c73eaba3c) C:\Windows\system32\DRIVERS\bdfm.sys
                2011/03/27 12:23:02.0501 2012 BdfNdisf (4ef599e45410eaec7b99a42121a23027) C:\Windows\system32\DRIVERS\BdfNdisf6.sys
                2011/03/27 12:23:04.0235 2012 bdfsfltr (9b281f5f673cbc5b9ec886d59e0b4f26) C:\Windows\system32\DRIVERS\bdfsfltr.sys
                2011/03/27 12:23:04.0435 2012 bdftdif (8a967659eb0181c55da7b01d1d061005) C:\Program Files\Common Files\BitDefender\BitDefender Firewall\bdftdif.sys
                2011/03/27 12:23:04.0636 2012 BDSelfPr (5eaf583c0b1cc2499761ea3b065f5db2) C:\Program Files\BitDefender\BitDefender 2010\bdselfpr.sys
                2011/03/27 12:23:04.0962 2012 BDVEDISK (bc79b27bc351436b07f57d80bec76036) C:\Program Files\BitDefender\BitDefender 2010\bdvedisk.sys
                2011/03/27 12:23:06.0417 2012 Beep (67e506b75bd5326a3ec7b70bd014dfb6) C:\Windows\system32\drivers\Beep.sys
                2011/03/27 12:23:08.0141 2012 blbdrive (d4df28447741fd3d953526e33a617397) C:\Windows\system32\drivers\blbdrive.sys
                2011/03/27 12:23:09.0453 2012 bowser (74b442b2be1260b7588c136177ceac66) C:\Windows\system32\DRIVERS\bowser.sys
                2011/03/27 12:23:10.0776 2012 BrFiltLo (9f9acc7f7ccde8a15c282d3f88b43309) C:\Windows\system32\drivers\brfiltlo.sys
                2011/03/27 12:23:12.0076 2012 BrFiltUp (56801ad62213a41f6497f96dee83755a) C:\Windows\system32\drivers\brfiltup.sys
                2011/03/27 12:23:13.0429 2012 Brserid (b304e75cff293029eddf094246747113) C:\Windows\system32\drivers\brserid.sys
                2011/03/27 12:23:14.0754 2012 BrSerWdm (203f0b1e73adadbbb7b7b1fabd901f6b) C:\Windows\system32\drivers\brserwdm.sys
                2011/03/27 12:23:16.0128 2012 BrUsbMdm (bd456606156ba17e60a04e18016ae54b) C:\Windows\system32\drivers\brusbmdm.sys
                2011/03/27 12:23:17.0433 2012 BrUsbSer (af72ed54503f717a43268b3cc5faec2e) C:\Windows\system32\drivers\brusbser.sys
                2011/03/27 12:23:18.0767 2012 BthEnum (da7b195275bda7f8fcf79b40e0f45dde) C:\Windows\system32\DRIVERS\BthEnum.sys
                2011/03/27 12:23:20.0103 2012 BTHMODEM (ad07c1ec6665b8b35741ab91200c6b68) C:\Windows\system32\drivers\bthmodem.sys
                2011/03/27 12:23:21.0441 2012 BthPan (5904efa25f829bf84ea6fb045134a1d8) C:\Windows\system32\DRIVERS\bthpan.sys
                2011/03/27 12:23:22.0810 2012 BTHPORT (73d53f8e90550ba81e2cf44a0873b410) C:\Windows\system32\Drivers\BTHport.sys
                2011/03/27 12:23:24.0148 2012 BTHUSB (32045a4bb143bbc5bab1298c4e9e309a) C:\Windows\system32\Drivers\BTHUSB.sys
                2011/03/27 12:23:25.0471 2012 btwaudio (f2f7342742180d5060285499dee50f99) C:\Windows\system32\drivers\btwaudio.sys
                2011/03/27 12:23:26.0890 2012 btwavdt (32f59f26a30cfc508da11db3ea0f8b77) C:\Windows\system32\drivers\btwavdt.sys
                2011/03/27 12:23:28.0268 2012 btwl2cap (ecb98391c756a7b9cfbae89d9d1235e1) C:\Windows\system32\DRIVERS\btwl2cap.sys
                2011/03/27 12:23:29.0577 2012 btwrchid (03658734ef7d0f3b3f4636d3e8a38964) C:\Windows\system32\DRIVERS\btwrchid.sys
                2011/03/27 12:23:31.0000 2012 Cam5607 (a62a03b222a06379b100ee1187076d52) C:\Windows\system32\Drivers\BisonC07.sys
                2011/03/27 12:23:32.0333 2012 cdfs (7add03e75beb9e6dd102c3081d29840a) C:\Windows\system32\DRIVERS\cdfs.sys
                2011/03/27 12:23:33.0670 2012 cdrom (1ec25cea0de6ac4718bf89f9e1778b57) C:\Windows\system32\DRIVERS\cdrom.sys
                2011/03/27 12:23:34.0983 2012 circlass (e5d4133f37219dbcfe102bc61072589d) C:\Windows\system32\DRIVERS\circlass.sys
                2011/03/27 12:23:36.0156 2012 CLFS (465745561c832b29f7c48b488aab3842) C:\Windows\system32\CLFS.sys
                2011/03/27 12:23:37.0485 2012 CmBatt (99afc3795b58cc478fbbbcdc658fcb56) C:\Windows\system32\DRIVERS\CmBatt.sys
                2011/03/27 12:23:38.0863 2012 cmdide (0ca25e686a4928484e9fdabd168ab629) C:\Windows\system32\drivers\cmdide.sys
                2011/03/27 12:23:40.0787 2012 Compbatt (6afef0b60fa25de07c0968983ee4f60a) C:\Windows\system32\DRIVERS\compbatt.sys
                2011/03/27 12:23:42.0447 2012 crcdisk (741e9dff4f42d2d8477d0fc1dc0df871) C:\Windows\system32\drivers\crcdisk.sys
                2011/03/27 12:23:45.0015 2012 Crusoe (1f07becdca750766a96cda811ba86410) C:\Windows\system32\drivers\crusoe.sys
                2011/03/27 12:23:47.0927 2012 DfsC (9e635ae5e8ad93e2b5989e2e23679f97) C:\Windows\system32\Drivers\dfsc.sys
                2011/03/27 12:23:50.0909 2012 disk (64109e623abd6955c8fb110b592e68b7) C:\Windows\system32\drivers\disk.sys
                2011/03/27 12:23:51.0275 2012 driverhardwarev2 (a694d8db6d360a3bbb0bd1517f1c1aee) C:\Program Files\ma-config.com\Drivers\driverhardwarev2.sys
                2011/03/27 12:23:54.0041 2012 drmkaud (97fef831ab90bee128c9af390e243f80) C:\Windows\system32\drivers\drmkaud.sys
                2011/03/27 12:23:57.0184 2012 dtsoftbus01 (555e54ac2f601a8821cef58961653991) C:\Windows\system32\DRIVERS\dtsoftbus01.sys
                2011/03/27 12:24:00.0143 2012 DXGKrnl (85f33880b8cfb554bd3d9ccdb486845a) C:\Windows\System32\drivers\dxgkrnl.sys
                2011/03/27 12:24:02.0558 2012 E1G60 (5425f74ac0c1dbd96a1e04f17d63f94c) C:\Windows\system32\DRIVERS\E1G60I32.sys
                2011/03/27 12:24:04.0073 2012 Ecache (dd2cd259d83d8b72c02c5f2331ff9d68) C:\Windows\system32\drivers\ecache.sys
                2011/03/27 12:24:05.0699 2012 elxstor (23b62471681a124889978f6295b3f4c6) C:\Windows\system32\drivers\elxstor.sys
                2011/03/27 12:24:07.0130 2012 ErrDev (3db974f3935483555d7148663f726c61) C:\Windows\system32\drivers\errdev.sys
                2011/03/27 12:24:09.0047 2012 exfat (0d858eb20589a34efb25695acaa6aa2d) C:\Windows\system32\drivers\exfat.sys
                2011/03/27 12:24:10.0471 2012 fastfat (3c489390c2e2064563727752af8eab9e) C:\Windows\system32\drivers\fastfat.sys
                2011/03/27 12:24:11.0817 2012 fdc (afe1e8b9782a0dd7fb46bbd88e43f89a) C:\Windows\system32\DRIVERS\fdc.sys
                2011/03/27 12:24:13.0575 2012 FileInfo (a8c0139a884861e3aae9cfe73b208a9f) C:\Windows\system32\drivers\fileinfo.sys
                2011/03/27 12:24:15.0498 2012 Filetrace (0ae429a696aecbc5970e3cf2c62635ae) C:\Windows\system32\drivers\filetrace.sys
                2011/03/27 12:24:17.0699 2012 flpydisk (85b7cf99d532820495d68d747fda9ebd) C:\Windows\system32\DRIVERS\flpydisk.sys
                2011/03/27 12:24:20.0027 2012 FltMgr (05ea53afe985443011e36dab07343b46) C:\Windows\system32\drivers\fltmgr.sys
                2011/03/27 12:24:22.0551 2012 fspad_wlh32 (eca2799ecb18ce0c0dced502f5261b82) C:\Windows\system32\DRIVERS\fspad_wlh32.sys
                2011/03/27 12:24:25.0107 2012 Fs_Rec (65ea8b77b5851854f0c55c43fa51a198) C:\Windows\system32\drivers\Fs_Rec.sys
                2011/03/27 12:24:27.0379 2012 gagp30kx (34582a6e6573d54a07ece5fe24a126b5) C:\Windows\system32\drivers\gagp30kx.sys
                2011/03/27 12:24:30.0669 2012 HdAudAddService (cb04c744be0a61b1d648faed182c3b59) C:\Windows\system32\drivers\HdAudio.sys
                2011/03/27 12:24:33.0872 2012 HDAudBus (c87b1ee051c0464491c1a7b03fa0bc99) C:\Windows\system32\DRIVERS\HDAudBus.sys
                2011/03/27 12:24:37.0156 2012 HidBth (1338520e78d90154ed6be8f84de5fceb) C:\Windows\system32\drivers\hidbth.sys
                2011/03/27 12:24:40.0444 2012 HidIr (d8df3722d5e961baa1292aa2f12827e2) C:\Windows\system32\DRIVERS\hidir.sys
                2011/03/27 12:24:43.0212 2012 hidshim (b4f84e0ecf5bf85af1991314ba5de01c) C:\Windows\system32\DRIVERS\hidshim.sys
                2011/03/27 12:24:45.0422 2012 HidUsb (854ca287ab7faf949617a788306d967e) C:\Windows\system32\DRIVERS\hidusb.sys
                2011/03/27 12:24:48.0065 2012 HpCISSs (16ee7b23a009e00d835cdb79574a91a6) C:\Windows\system32\drivers\hpcisss.sys
                2011/03/27 12:24:49.0479 2012 HTTP (96e241624c71211a79c84f50a8e71cab) C:\Windows\system32\drivers\HTTP.sys
                2011/03/27 12:24:50.0896 2012 i2omp (c6b032d69650985468160fc9937cf5b4) C:\Windows\system32\drivers\i2omp.sys
                2011/03/27 12:24:55.0545 2012 i8042prt (22d56c8184586b7a1f6fa60be5f5a2bd) C:\Windows\system32\DRIVERS\i8042prt.sys
                2011/03/27 12:25:03.0470 2012 iaStorV (54155ea1b0df185878e0fc9ec3ac3a14) C:\Windows\system32\drivers\iastorv.sys
                2011/03/27 12:25:10.0298 2012 igfx (8266ae06df974e5ba047b3e9e9e70b3f) C:\Windows\system32\DRIVERS\igdkmd32.sys
                2011/03/27 12:25:15.0674 5528 ================================================================================
                2011/03/27 12:25:15.0674 5528 Scan started
                2011/03/27 12:25:15.0674 5528 Mode: Manual;
                2011/03/27 12:25:15.0674 5528 ================================================================================
                2011/03/27 12:25:19.0040 5528 ACPI (fcb8c7210f0135e24c6580f7f649c73c) C:\Windows\system32\drivers\acpi.sys
                2011/03/27 12:25:22.0060 5528 acpihid (48fc4b61b87f1fc06f0848c3421e3a1f) C:\Windows\system32\DRIVERS\acpihid.sys
                2011/03/27 12:25:25.0163 5528 adp94xx (04f0fcac69c7c71a3ac4eb97fafc8303) C:\Windows\system32\drivers\adp94xx.sys
                2011/03/27 12:25:27.0654 5528 adpahci (60505e0041f7751bdbb80f88bf45c2ce) C:\Windows\system32\drivers\adpahci.sys
                2011/03/27 12:25:30.0123 5528 adpu160m (8a42779b02aec986eab64ecfc98f8bd7) C:\Windows\system32\drivers\adpu160m.sys
                2011/03/27 12:25:32.0499 5528 adpu320 (241c9e37f8ce45ef51c3de27515ca4e5) C:\Windows\system32\drivers\adpu320.sys
                2011/03/27 12:25:35.0159 5528 AFD (763e172a55177e478cb419f88fd0ba03) C:\Windows\system32\drivers\afd.sys
                2011/03/27 12:25:37.0865 5528 agp440 (13f9e33747e6b41a3ff305c37db0d360) C:\Windows\system32\drivers\agp440.sys
                2011/03/27 12:25:39.0439 5528 aic78xx (ae1fdf7bf7bb6c6a70f67699d880592a) C:\Windows\system32\drivers\djsvs.sys
                2011/03/27 12:25:40.0988 5528 aliide (9eaef5fc9b8e351afa7e78a6fae91f91) C:\Windows\system32\drivers\aliide.sys
                2011/03/27 12:25:42.0857 5528 amdagp (c47344bc706e5f0b9dce369516661578) C:\Windows\system32\drivers\amdagp.sys
                2011/03/27 12:25:45.0424 5528 amdide (9b78a39a4c173fdbc1321e0dd659b34c) C:\Windows\system32\drivers\amdide.sys
                2011/03/27 12:25:46.0749 5528 AmdK7 (18f29b49ad23ecee3d2a826c725c8d48) C:\Windows\system32\drivers\amdk7.sys
                2011/03/27 12:25:48.0062 5528 AmdK8 (93ae7f7dd54ab986a6f1a1b37be7442d) C:\Windows\system32\drivers\amdk8.sys
                2011/03/27 12:25:49.0434 5528 arc (5d2888182fb46632511acee92fdad522) C:\Windows\system32\drivers\arc.sys
                2011/03/27 12:25:50.0793 5528 arcsas (5e2a321bd7c8b3624e41fdec3e244945) C:\Windows\system32\drivers\arcsas.sys
                2011/03/27 12:25:52.0593 5528 AsyncMac (53b202abee6455406254444303e87be1) C:\Windows\system32\DRIVERS\asyncmac.sys
                2011/03/27 12:25:53.0917 5528 atapi (2d9c903dc76a66813d350a562de40ed9) C:\Windows\system32\drivers\atapi.sys
                2011/03/27 12:25:55.0221 5528 ATDrv (4bc14462b5e6e6c28d35e87e57968bd5) C:\Windows\system32\DRIVERS\ATDrv.sys
                2011/03/27 12:25:56.0800 5528 BDFM (0de9617eaa4ca5587c2f950c73eaba3c) C:\Windows\system32\DRIVERS\bdfm.sys
                2011/03/27 12:25:58.0155 5528 BdfNdisf (4ef599e45410eaec7b99a42121a23027) C:\Windows\system32\DRIVERS\BdfNdisf6.sys
                2011/03/27 12:25:59.0500 5528 bdfsfltr (9b281f5f673cbc5b9ec886d59e0b4f26) C:\Windows\system32\DRIVERS\bdfsfltr.sys
                2011/03/27 12:25:59.0733 5528 bdftdif (8a967659eb0181c55da7b01d1d061005) C:\Program Files\Common Files\BitDefender\BitDefender Firewall\bdftdif.sys
                2011/03/27 12:26:00.0012 5528 BDSelfPr (5eaf583c0b1cc2499761ea3b065f5db2) C:\Program Files\BitDefender\BitDefender 2010\bdselfpr.sys
                2011/03/27 12:26:00.0305 5528 BDVEDISK (bc79b27bc351436b07f57d80bec76036) C:\Program Files\BitDefender\BitDefender 2010\bdvedisk.sys
                2011/03/27 12:26:01.0615 5528 Beep (67e506b75bd5326a3ec7b70bd014dfb6) C:\Windows\system32\drivers\Beep.sys
                2011/03/27 12:26:02.0950 5528 blbdrive (d4df28447741fd3d953526e33a617397) C:\Windows\system32\drivers\blbdrive.sys
                2011/03/27 12:26:04.0731 5528 bowser (74b442b2be1260b7588c136177ceac66) C:\Windows\system32\DRIVERS\bowser.sys
                2011/03/27 12:26:07.0074 5528 BrFiltLo (9f9acc7f7ccde8a15c282d3f88b43309) C:\Windows\system32\drivers\brfiltlo.sys
                2011/03/27 12:26:08.0397 5528 BrFiltUp (56801ad62213a41f6497f96dee83755a) C:\Windows\system32\drivers\brfiltup.sys
                2011/03/27 12:26:10.0005 5528 Brserid (b304e75cff293029eddf094246747113) C:\Windows\system32\drivers\brserid.sys
                2011/03/27 12:26:11.0752 5528 BrSerWdm (203f0b1e73adadbbb7b7b1fabd901f6b) C:\Windows\system32\drivers\brserwdm.sys
                2011/03/27 12:26:13.0576 5528 BrUsbMdm (bd456606156ba17e60a04e18016ae54b) C:\Windows\system32\drivers\brusbmdm.sys
                2011/03/27 12:26:16.0020 5528 BrUsbSer (af72ed54503f717a43268b3cc5faec2e) C:\Windows\system32\drivers\brusbser.sys
                2011/03/27 12:26:17.0732 5528 BthEnum (da7b195275bda7f8fcf79b40e0f45dde) C:\Windows\system32\DRIVERS\BthEnum.sys
                2011/03/27 12:26:19.0080 5528 BTHMODEM (ad07c1ec6665b8b35741ab91200c6b68) C:\Windows\system32\drivers\bthmodem.sys
                2011/03/27 12:26:20.0551 5528 BthPan (5904efa25f829bf84ea6fb045134a1d8) C:\Windows\system32\DRIVERS\bthpan.sys
                2011/03/27 12:26:21.0920 5528 BTHPORT (73d53f8e90550ba81e2cf44a0873b410) C:\Windows\system32\Drivers\BTHport.sys
                2011/03/27 12:26:23.0281 5528 BTHUSB (32045a4bb143bbc5bab1298c4e9e309a) C:\Windows\system32\Drivers\BTHUSB.sys
                2011/03/27 12:26:24.0625 5528 btwaudio (f2f7342742180d5060285499dee50f99) C:\Windows\system32\drivers\btwaudio.sys
                2011/03/27 12:26:26.0611 5528 btwavdt (32f59f26a30cfc508da11db3ea0f8b77) C:\Windows\system32\drivers\btwavdt.sys
                2011/03/27 12:26:27.0955 5528 btwl2cap (ecb98391c756a7b9cfbae89d9d1235e1) C:\Windows\system32\DRIVERS\btwl2cap.sys
                2011/03/27 12:26:29.0786 5528 btwrchid (03658734ef7d0f3b3f4636d3e8a38964) C:\Windows\system32\DRIVERS\btwrchid.sys
                2011/03/27 12:26:31.0252 5528 Cam5607 (a62a03b222a06379b100ee1187076d52) C:\Windows\system32\Drivers\BisonC07.sys
                2011/03/27 12:26:32.0598 5528 cdfs (7add03e75beb9e6dd102c3081d29840a) C:\Windows\system32\DRIVERS\cdfs.sys
                2011/03/27 12:26:34.0368 5528 cdrom (1ec25cea0de6ac4718bf89f9e1778b57) C:\Windows\system32\DRIVERS\cdrom.sys
                2011/03/27 12:26:35.0703 5528 circlass (e5d4133f37219dbcfe102bc61072589d) C:\Windows\system32\DRIVERS\circlass.sys
                2011/03/27 12:26:36.0899 5528 CLFS (465745561c832b29f7c48b488aab3842) C:\Windows\system32\CLFS.sys
                2011/03/27 12:26:38.0250 5528 CmBatt (99afc3795b58cc478fbbbcdc658fcb56) C:\Windows\system32\DRIVERS\CmBatt.sys
                2011/03/27 12:26:39.0595 5528 cmdide (0ca25e686a4928484e9fdabd168ab629) C:\Windows\system32\drivers\cmdide.sys
                2011/03/27 12:26:41.0041 5528 Compbatt (6afef0b60fa25de07c0968983ee4f60a) C:\Windows\system32\DRIVERS\compbatt.sys
                2011/03/27 12:26:42.0544 5528 crcdisk (741e9dff4f42d2d8477d0fc1dc0df871) C:\Windows\system32\drivers\crcdisk.sys
                2011/03/27 12:26:43.0857 5528 Crusoe (1f07becdca750766a96cda811ba86410) C:\Windows\system32\drivers\crusoe.sys
                2011/03/27 12:26:45.0214 5528 DfsC (9e635ae5e8ad93e2b5989e2e23679f97) C:\Windows\system32\Drivers\dfsc.sys
                2011/03/27 12:26:46.0562 5528 disk (64109e623abd6955c8fb110b592e68b7) C:\Windows\system32\drivers\disk.sys
                2011/03/27 12:26:46.0784 5528 driverhardwarev2 (a694d8db6d360a3bbb0bd1517f1c1aee) C:\Program Files\ma-config.com\Drivers\driverhardwarev2.sys
                2011/03/27 12:26:48.0094 5528 drmkaud (97fef831ab90bee128c9af390e243f80) C:\Windows\system32\drivers\drmkaud.sys
                2011/03/27 12:26:49.0414 5528 dtsoftbus01 (555e54ac2f601a8821cef58961653991) C:\Windows\system32\DRIVERS\dtsoftbus01.sys
                2011/03/27 12:26:50.0767 5528 DXGKrnl (85f33880b8cfb554bd3d9ccdb486845a) C:\Windows\System32\drivers\dxgkrnl.sys
                2011/03/27 12:26:52.0212 5528 E1G60 (5425f74ac0c1dbd96a1e04f17d63f94c) C:\Windows\system32\DRIVERS\E1G60I32.sys
                2011/03/27 12:26:53.0791 5528 Ecache (dd2cd259d83d8b72c02c5f2331ff9d68) C:\Windows\system32\drivers\ecache.sys
                2011/03/27 12:26:55.0165 5528 elxstor (23b62471681a124889978f6295b3f4c6) C:\Windows\system32\drivers\elxstor.sys
                2011/03/27 12:26:56.0540 5528 ErrDev (3db974f3935483555d7148663f726c61) C:\Windows\system32\drivers\errdev.sys
                2011/03/27 12:26:57.0911 5528 exfat (0d858eb20589a34efb25695acaa6aa2d) C:\Windows\system32\drivers\exfat.sys
                2011/03/27 12:26:59.0214 5528 fastfat (3c489390c2e2064563727752af8eab9e) C:\Windows\system32\drivers\fastfat.sys
                2011/03/27 12:27:00.0582 5528 fdc (afe1e8b9782a0dd7fb46bbd88e43f89a) C:\Windows\system32\DRIVERS\fdc.sys
                2011/03/27 12:27:01.0939 5528 FileInfo (a8c0139a884861e3aae9cfe73b208a9f) C:\Windows\system32\drivers\fileinfo.sys
                2011/03/27 12:27:03.0251 5528 Filetrace (0ae429a696aecbc5970e3cf2c62635ae) C:\Windows\system32\drivers\filetrace.sys
                2011/03/27 12:27:04.0597 5528 flpydisk (85b7cf99d532820495d68d747fda9ebd) C:\Windows\system32\DRIVERS\flpydisk.sys
                2011/03/27 12:27:06.0292 5528 FltMgr (05ea53afe985443011e36dab07343b46) C:\Windows\system32\drivers\fltmgr.sys
                2011/03/27 12:27:07.0616 5528 fspad_wlh32 (eca2799ecb18ce0c0dced502f5261b82) C:\Windows\system32\DRIVERS\fspad_wlh32.sys
                2011/03/27 12:27:08.0961 5528 Fs_Rec (65ea8b77b5851854f0c55c43fa51a198) C:\Windows\system32\drivers\Fs_Rec.sys
                2011/03/27 12:27:10.0278 5528 gagp30kx (34582a6e6573d54a07ece5fe24a126b5) C:\Windows\system32\drivers\gagp30kx.sys
                2011/03/27 12:27:11.0833 5528 HdAudAddService (cb04c744be0a61b1d648faed182c3b59) C:\Windows\system32\drivers\HdAudio.sys
                2011/03/27 12:27:13.0214 5528 HDAudBus (c87b1ee051c0464491c1a7b03fa0bc99) C:\Windows\system32\DRIVERS\HDAudBus.sys
                2011/03/27 12:27:14.0533 5528 HidBth (1338520e78d90154ed6be8f84de5fceb) C:\Windows\system32\drivers\hidbth.sys
                2011/03/27 12:27:16.0163 5528 HidIr (d8df3722d5e961baa1292aa2f12827e2) C:\Windows\system32\DRIVERS\hidir.sys
                2011/03/27 12:27:17.0576 5528 hidshim (b4f84e0ecf5bf85af1991314ba5de01c) C:\Windows\system32\DRIVERS\hidshim.sys
                2011/03/27 12:27:18.0908 5528 HidUsb (854ca287ab7faf949617a788306d967e) C:\Windows\system32\DRIVERS\hidusb.sys
                2011/03/27 12:27:20.0262 5528 HpCISSs (16ee7b23a009e00d835cdb79574a91a6) C:\Windows\system32\drivers\hpcisss.sys
                2011/03/27 12:27:21.0598 5528 HTTP (96e241624c71211a79c84f50a8e71cab) C:\Windows\system32\drivers\HTTP.sys
                2011/03/27 12:27:22.0927 5528 i2omp (c6b032d69650985468160fc9937cf5b4) C:\Windows\system32\drivers\i2omp.sys
                2011/03/27 12:27:24.0264 5528 i8042prt (22d56c8184586b7a1f6fa60be5f5a2bd) C:\Windows\system32\DRIVERS\i8042prt.sys
                2011/03/27 12:27:25.0589 5528 iaStorV (54155ea1b0df185878e0fc9ec3ac3a14) C:\Windows\system32\drivers\iastorv.sys
                2011/03/27 12:27:27.0282 5528 igfx (8266ae06df974e5ba047b3e9e9e70b3f) C:\Windows\system32\DRIVERS\igdkmd32.sys
                2011/03/27 12:27:28.0721 5528 iirsp (2d077bf86e843f901d8db709c95b49a5) C:\Windows\system32\drivers\iirsp.sys
                2011/03/27 12:27:30.0145 5528 IntcAzAudAddService (2e06052066ce4489cdfbfb8329ea52b1) C:\Windows\system32\drivers\RTKVHDA.sys
                2011/03/27 12:27:31.0469 5528 IntcHdmiAddService (8dab99684cfe8b4ddd5d6d0c5d55fdac) C:\Windows\system32\drivers\IntcHdmi.sys
                2011/03/27 12:27:32.0836 5528 intelide (83aa759f3189e6370c30de5dc5590718) C:\Windows\system32\drivers\intelide.sys
                2011/03/27 12:27:34.0160 5528 intelppm (224191001e78c89dfa78924c3ea595ff) C:\Windows\system32\DRIVERS\intelppm.sys
                2011/03/27 12:27:35.0506 5528 IpFilterDriver (62c265c38769b864cb25b4bcf62df6c3) C:\Windows\system32\DRIVERS\ipfltdrv.sys
                2011/03/27 12:27:38.0333 5528 IPMIDRV (b25aaf203552b7b3491139d582b39ad1) C:\Windows\system32\drivers\ipmidrv.sys
                2011/03/27 12:27:39.0679 5528 IPNAT (8793643a67b42cec66490b2a0cf92d68) C:\Windows\system32\DRIVERS\ipnat.sys
                2011/03/27 12:27:41.0014 5528 IRENUM (109c0dfb82c3632fbd11949b73aeeac9) C:\Windows\system32\drivers\irenum.sys
                2011/03/27 12:27:42.0350 5528 isapnp (6c70698a3e5c4376c6ab5c7c17fb0614) C:\Windows\system32\drivers\isapnp.sys
                2011/03/27 12:27:43.0699 5528 iScsiPrt (f247eec28317f6c739c16de420097301) C:\Windows\system32\DRIVERS\msiscsi.sys
                2011/03/27 12:27:45.0028 5528 iteatapi (bced60d16156e428f8df8cf27b0df150) C:\Windows\system32\drivers\iteatapi.sys
                2011/03/27 12:27:46.0450 5528 iteraid (06fa654504a498c30adca8bec4e87e7e) C:\Windows\system32\drivers\iteraid.sys
                2011/03/27 12:27:47.0809 5528 kbdclass (37605e0a8cf00cbba538e753e4344c6e) C:\Windows\system32\DRIVERS\kbdclass.sys
                2011/03/27 12:27:49.0143 5528 kbdhid (18247836959ba67e3511b62846b9c2e0) C:\Windows\system32\DRIVERS\kbdhid.sys
                2011/03/27 12:27:50.0484 5528 KBFilter (c1068e335f0419126221847bc204def6) C:\Windows\system32\DRIVERS\KBFilter.sys
                2011/03/27 12:27:51.0849 5528 KSecDD (7a0cf7908b6824d6a2a1d313e5ae3dca) C:\Windows\system32\Drivers\ksecdd.sys
                2011/03/27 12:27:52.0068 5528 Lavasoft Kernexplorer (6c4a3804510ad8e0f0c07b5be3d44ddb) C:\Program Files\Lavasoft\Ad-Aware\KernExplorer.sys
                2011/03/27 12:27:53.0423 5528 Lbd (336abe8721cbc3110f1c6426da633417) C:\Windows\system32\DRIVERS\Lbd.sys
                2011/03/27 12:27:54.0764 5528 lltdio (d1c5883087a0c3f1344d9d55a44901f6) C:\Windows\system32\DRIVERS\lltdio.sys
                2011/03/27 12:27:56.0135 5528 LSI_FC (c7e15e82879bf3235b559563d4185365) C:\Windows\system32\drivers\lsi_fc.sys
                2011/03/27 12:27:57.0496 5528 LSI_SAS (ee01ebae8c9bf0fa072e0ff68718920a) C:\Windows\system32\drivers\lsi_sas.sys
                2011/03/27 12:27:58.0869 5528 LSI_SCSI (912a04696e9ca30146a62afa1463dd5c) C:\Windows\system32\drivers\lsi_scsi.sys
                2011/03/27 12:28:00.0412 5528 luafv (8f5c7426567798e62a3b3614965d62cc) C:\Windows\system32\drivers\luafv.sys
                2011/03/27 12:28:01.0848 5528 megasas (0001ce609d66632fa17b84705f658879) C:\Windows\system32\drivers\megasas.sys
                2011/03/27 12:28:03.0481 5528 MegaSR (c252f32cd9a49dbfc25ecf26ebd51a99) C:\Windows\system32\drivers\megasr.sys
                2011/03/27 12:28:04.0819 5528 MLowCtl (d64ebbc1f4bbc745ec16a2947bcc6dbd) C:\Windows\system32\DRIVERS\MLowCtl.sys
                2011/03/27 12:28:06.0191 5528 Modem (e13b5ea0f51ba5b1512ec671393d09ba) C:\Windows\system32\drivers\modem.sys
                2011/03/27 12:28:07.0638 5528 monitor (0a9bb33b56e294f686abb7c1e4e2d8a8) C:\Windows\system32\DRIVERS\monitor.sys
                2011/03/27 12:28:08.0938 5528 mouclass (5bf6a1326a335c5298477754a506d263) C:\Windows\system32\DRIVERS\mouclass.sys
                2011/03/27 12:28:10.0292 5528 mouhid (93b8d4869e12cfbe663915502900876f) C:\Windows\system32\DRIVERS\mouhid.sys
                2011/03/27 12:28:11.0585 5528 MountMgr (bdafc88aa6b92f7842416ea6a48e1600) C:\Windows\system32\drivers\mountmgr.sys
                2011/03/27 12:28:12.0898 5528 mpio (511d011289755dd9f9a7579fb0b064e6) C:\Windows\system32\drivers\mpio.sys
                2011/03/27 12:28:14.0220 5528 mpsdrv (22241feba9b2defa669c8cb0a8dd7d2e) C:\Windows\system32\drivers\mpsdrv.sys
                2011/03/27 12:28:15.0598 5528 Mraid35x (4fbbb70d30fd20ec51f80061703b001e) C:\Windows\system32\drivers\mraid35x.sys
                2011/03/27 12:28:17.0030 5528 MRxDAV (ae3de84536b6799d2267443cec8edbb9) C:\Windows\system32\drivers\mrxdav.sys
                2011/03/27 12:28:18.0358 5528 mrxsmb (7afc42e60432fd1014f5342f2b1b1f74) C:\Windows\system32\DRIVERS\mrxsmb.sys
                2011/03/27 12:28:19.0698 5528 mrxsmb10 (8a75752ae17924f65452746674b14b78) C:\Windows\system32\DRIVERS\mrxsmb10.sys
                2011/03/27 12:28:21.0045 5528 mrxsmb20 (f4d0f3252e651f02be64984ffa738394) C:\Windows\system32\DRIVERS\mrxsmb20.sys
                2011/03/27 12:28:22.0451 5528 msahci (28023e86f17001f7cd9b15a5bc9ae07d) C:\Windows\system32\drivers\msahci.sys
                2011/03/27 12:28:24.0134 5528 msdsm (4468b0f385a86ecddaf8d3ca662ec0e7) C:\Windows\system32\drivers\msdsm.sys
                2011/03/27 12:28:25.0756 5528 Msfs (a9927f4a46b816c92f461acb90cf8515) C:\Windows\system32\drivers\Msfs.sys
                2011/03/27 12:28:27.0324 5528 msisadrv (0f400e306f385c56317357d6dea56f62) C:\Windows\system32\drivers\msisadrv.sys
                2011/03/27 12:28:28.0666 5528 MSKSSRV (d8c63d34d9c9e56c059e24ec7185cc07) C:\Windows\system32\drivers\MSKSSRV.sys
                2011/03/27 12:28:30.0033 5528 MSPCLOCK (1d373c90d62ddb641d50e55b9e78d65e) C:\Windows\system32\drivers\MSPCLOCK.sys
                2011/03/27 12:28:31.0344 5528 MSPQM (b572da05bf4e098d4bba3a4734fb505b) C:\Windows\system32\drivers\MSPQM.sys
                2011/03/27 12:28:32.0803 5528 MsRPC (b5614aecb05a9340aa0fb55bf561cc63) C:\Windows\system32\drivers\MsRPC.sys
                2011/03/27 12:28:34.0145 5528 mssmbios (e384487cb84be41d09711c30ca79646c) C:\Windows\system32\DRIVERS\mssmbios.sys
                2011/03/27 12:28:35.0478 5528 MSTEE (7199c1eec1e4993caf96b8c0a26bd58a) C:\Windows\system32\drivers\MSTEE.sys
                2011/03/27 12:28:36.0813 5528 Mup (6dfd1d322de55b0b7db7d21b90bec49c) C:\Windows\system32\Drivers\mup.sys
                2011/03/27 12:28:38.0158 5528 NativeWifiP (3c21ce48ff529bb73dadb98770b54025) C:\Windows\system32\DRIVERS\nwifi.sys
                2011/03/27 12:28:39.0532 5528 NDIS (9bdc71790fa08f0a0b5f10462b1bd0b1) C:\Windows\system32\drivers\ndis.sys
                2011/03/27 12:28:40.0886 5528 NdisTapi (0e186e90404980569fb449ba7519ae61) C:\Windows\system32\DRIVERS\ndistapi.sys
                2011/03/27 12:28:42.0242 5528 Ndisuio (d6973aa34c4d5d76c0430b181c3cd389) C:\Windows\system32\DRIVERS\ndisuio.sys
                2011/03/27 12:28:43.0800 5528 NdisWan (3d14c3b3496f88890d431e8aa022a411) C:\Windows\system32\DRIVERS\ndiswan.sys
                2011/03/27 12:28:45.0158 5528 NDProxy (71dab552b41936358f3b541ae5997fb3) C:\Windows\system32\drivers\NDProxy.sys
                2011/03/27 12:28:46.0483 5528 NetBIOS (bcd093a5a6777cf626434568dc7dba78) C:\Windows\system32\DRIVERS\netbios.sys
                2011/03/27 12:28:47.0964 5528 netbt (7c5fee5b1c5728507cd96fb4a13e7a02) C:\Windows\system32\DRIVERS\netbt.sys
                2011/03/27 12:28:49.0342 5528 nfrd960 (2e7fb731d4790a1bc6270accefacb36e) C:\Windows\system32\drivers\nfrd960.sys
                2011/03/27 12:28:50.0721 5528 NPF (b9730495e0cf674680121e34bd95a73b) C:\Windows\system32\drivers\npf.sys
                2011/03/27 12:28:52.0187 5528 Npfs (ecb5003f484f9ed6c608d6d6c7886cbb) C:\Windows\system32\drivers\Npfs.sys
                2011/03/27 12:28:54.0421 5528 nsiproxy (609773e344a97410ce4ebf74a8914fcf) C:\Windows\system32\drivers\nsiproxy.sys
                2011/03/27 12:28:56.0912 5528 Ntfs (b4effe29eb4f15538fd8a9681108492d) C:\Windows\system32\drivers\Ntfs.sys
                2011/03/27 12:28:58.0580 5528 ntrigdigi (e875c093aec0c978a90f30c9e0dfbb72) C:\Windows\system32\drivers\ntrigdigi.sys
                2011/03/27 12:29:00.0249 5528 Null (c5dbbcda07d780bda9b685df333bb41e) C:\Windows\system32\drivers\Null.sys
                2011/03/27 12:29:01.0685 5528 nvraid (2edf9e7751554b42cbb60116de727101) C:\Windows\system32\drivers\nvraid.sys
                2011/03/27 12:29:03.0586 5528 nvstor (abed0c09758d1d97db0042dbb2688177) C:\Windows\system32\drivers\nvstor.sys
                2011/03/27 12:29:05.0427 5528 nv_agp (18bbdf913916b71bd54575bdb6eeac0b) C:\Windows\system32\drivers\nv_agp.sys
                2011/03/27 12:29:09.0619 5528 O2MDRDR (16dfa5eff3f104c1d66bcb60c06a101f) C:\Windows\system32\DRIVERS\o2media.sys
                2011/03/27 12:29:11.0066 5528 O2SDRDR (afcf62fdbb0002ec16374d21c65a9063) C:\Windows\system32\DRIVERS\o2sd.sys
                2011/03/27 12:29:13.0020 5528 ohci1394 (790e27c3db53410b40ff9ef2fd10a1d9) C:\Windows\system32\DRIVERS\ohci1394.sys
                2011/03/27 12:29:14.0469 5528 Parport (0fa9b5055484649d63c303fe404e5f4d) C:\Windows\system32\drivers\parport.sys
                2011/03/27 12:29:15.0814 5528 partmgr (3b38467e7c3daed009dfe359e17f139f) C:\Windows\system32\drivers\partmgr.sys
                2011/03/27 12:29:17.0159 5528 Parvdm (4f9a6a8a31413180d0fcb279ad5d8112) C:\Windows\system32\drivers\parvdm.sys
                2011/03/27 12:29:18.0613 5528 pci (01b94418deb235dff777cc80076354b4) C:\Windows\system32\drivers\pci.sys
                2011/03/27 12:29:19.0980 5528 pciide (fc175f5ddab666d7f4d17449a547626f) C:\Windows\system32\drivers\pciide.sys
                2011/03/27 12:29:21.0478 5528 pcmcia (e6f3fb1b86aa519e7698ad05e58b04e5) C:\Windows\system32\drivers\pcmcia.sys
                2011/03/27 12:29:22.0887 5528 PEAUTH (6349f6ed9c623b44b52ea3c63c831a92) C:\Windows\system32\drivers\peauth.sys
                2011/03/27 12:29:24.0340 5528 PptpMiniport (ecfffaec0c1ecd8dbc77f39070ea1db1) C:\Windows\system32\DRIVERS\raspptp.sys
                2011/03/27 12:29:25.0668 5528 Processor (2027293619dd0f047c584cf2e7df4ffd) C:\Windows\system32\drivers\processr.sys
                2011/03/27 12:29:25.0869 5528 Profos (de11f5c3e9bda993b65e1518d46bc438) C:\Program Files\Common Files\BitDefender\BitDefender Threat Scanner\profos.sys
                2011/03/27 12:29:27.0881 5528 PSched (bfef604508a0ed1eae2a73e872555ffb) C:\Windows\system32\DRIVERS\pacer.sys
                2011/03/27 12:29:29.0476 5528 ql2300 (0a6db55afb7820c99aa1f3a1d270f4f6) C:\Windows\system32\drivers\ql2300.sys
                2011/03/27 12:29:31.0080 5528 ql40xx (81a7e5c076e59995d54bc1ed3a16e60b) C:\Windows\system32\drivers\ql40xx.sys
                2011/03/27 12:29:32.0447 5528 QWAVEdrv (9f5e0e1926014d17486901c88eca2db7) C:\Windows\system32\drivers\qwavedrv.sys
                2011/03/27 12:29:33.0902 5528 RasAcd (147d7f9c556d259924351feb0de606c3) C:\Windows\system32\DRIVERS\rasacd.sys
                2011/03/27 12:29:35.0348 5528 Rasl2tp (a214adbaf4cb47dd2728859ef31f26b0) C:\Windows\system32\DRIVERS\rasl2tp.sys
                2011/03/27 12:29:37.0639 5528 RasPppoe (3e9d9b048107b40d87b97df2e48e0744) C:\Windows\system32\DRIVERS\raspppoe.sys
                2011/03/27 12:29:38.0998 5528 RasSstp (a7d141684e9500ac928a772ed8e6b671) C:\Windows\system32\DRIVERS\rassstp.sys
                2011/03/27 12:29:40.0306 5528 rdbss (6e1c5d0457622f9ee35f683110e93d14) C:\Windows\system32\DRIVERS\rdbss.sys
                2011/03/27 12:29:41.0685 5528 RDPCDD (89e59be9a564262a3fb6c4f4f1cd9899) C:\Windows\system32\DRIVERS\RDPCDD.sys
                2011/03/27 12:29:43.0277 5528 rdpdr (fbc0bacd9c3d7f6956853f64a66e252d) C:\Windows\system32\drivers\rdpdr.sys
                2011/03/27 12:29:46.0597 5528 RDPENCDD (9d91fe5286f748862ecffa05f8a0710c) C:\Windows\system32\drivers\rdpencdd.sys
                2011/03/27 12:29:49.0134 5528 RDPWD (e1c18f4097a5abcec941dc4b2f99db7e) C:\Windows\system32\drivers\RDPWD.sys
                2011/03/27 12:29:52.0047 5528 RFCOMM (34cc78c06587718c2ad6d3aa83b1f072) C:\Windows\system32\DRIVERS\rfcomm.sys
                2011/03/27 12:29:54.0732 5528 rspndr (9c508f4074a39e8b4b31d27198146fad) C:\Windows\system32\DRIVERS\rspndr.sys
                2011/03/27 12:29:57.0095 5528 RTL8169 (beb0aace3330d858bbb40ffb7aac3627) C:\Windows\system32\DRIVERS\Rtlh86.sys
                2011/03/27 12:29:59.0856 5528 RTL8187Se (3631bd508b84709c42eccdcee80110dd) C:\Windows\system32\DRIVERS\RTL8187Se.sys
                2011/03/27 12:30:00.0080 5528 SbieDrv (848c7a79dae9abccae1952ba561729f8) C:\Program Files\Sandboxie\SbieDrv.sys
                2011/03/27 12:30:02.0379 5528 sbp2port (3ce8f073a557e172b330109436984e30) C:\Windows\system32\drivers\sbp2port.sys
                2011/03/27 12:30:03.0721 5528 sdbus (126ea89bcc413ee45e3004fb0764888f) C:\Windows\system32\DRIVERS\sdbus.sys
                2011/03/27 12:30:05.0810 5528 secdrv (90a3935d05b494a5a39d37e71f09a677) C:\Windows\system32\drivers\secdrv.sys
                2011/03/27 12:30:09.0289 5528 Serenum (68e44e331d46f0fb38f0863a84cd1a31) C:\Windows\system32\drivers\serenum.sys
                2011/03/27 12:30:12.0371 5528 Serial (c70d69a918b178d3c3b06339b40c2e1b) C:\Windows\system32\drivers\serial.sys
                2011/03/27 12:30:14.0560 5528 sermouse (8af3d28a879bf75db53a0ee7a4289624) C:\Windows\system32\drivers\sermouse.sys
                2011/03/27 12:30:16.0497 5528 sffdisk (3efa810bdca87f6ecc24f9832243fe86) C:\Windows\system32\drivers\sffdisk.sys
                2011/03/27 12:30:18.0011 5528 sffp_mmc (e95d451f7ea3e583aec75f3b3ee42dc5) C:\Windows\system32\drivers\sffp_mmc.sys
                2011/03/27 12:30:19.0408 5528 sffp_sd (3d0ea348784b7ac9ea9bd9f317980979) C:\Windows\system32\drivers\sffp_sd.sys
                2011/03/27 12:30:20.0841 5528 sfloppy (46ed8e91793b2e6f848015445a0ac188) C:\Windows\system32\drivers\sfloppy.sys
                2011/03/27 12:30:23.0634 5528 sisagp (1d76624a09a054f682d746b924e2dbc3) C:\Windows\system32\drivers\sisagp.sys
                2011/03/27 12:30:25.0036 5528 SiSRaid2 (43cb7aa756c7db280d01da9b676cfde2) C:\Windows\system32\drivers\sisraid2.sys
                2011/03/27 12:30:26.0550 5528 SiSRaid4 (a99c6c8b0baa970d8aa59ddc50b57f94) C:\Windows\system32\drivers\sisraid4.sys
                2011/03/27 12:30:28.0182 5528 SLEE_16_DRIVER (4723512c035a3a880db4657705466240) C:\Windows\system32\drivers\Sleen16.sys
                2011/03/27 12:30:29.0574 5528 Smb (031e6bcd53c9b2b9ace111eafec347b6) C:\Windows\system32\DRIVERS\smb.sys
                2011/03/27 12:30:30.0964 5528 spldr (7aebdeef071fe28b0eef2cdd69102bff) C:\Windows\system32\drivers\spldr.sys
                2011/03/27 12:30:32.0539 5528 sptd (614deea4bdcec3fd5a07bdc705723ad7) C:\Windows\System32\Drivers\sptd.sys
                2011/03/27 12:30:32.0540 5528 Suspicious file (NoAccess): C:\Windows\System32\Drivers\sptd.sys. md5: 614deea4bdcec3fd5a07bdc705723ad7
                2011/03/27 12:30:32.0551 5528 sptd - detected Locked file (1)
                2011/03/27 12:30:33.0980 5528 srv (5754e8bae40943871d0ab9becbf335e8) C:\Windows\system32\DRIVERS\srv.sys
                2011/03/27 12:30:35.0435 5528 srv2 (d47b09ff7d28ee44d728f57c2d1fab86) C:\Windows\system32\DRIVERS\srv2.sys
                2011/03/27 12:30:37.0013 5528 srvnet (32d52290341a740881521e118106acd6) C:\Windows\system32\DRIVERS\srvnet.sys
                2011/03/27 12:30:38.0546 5528 swenum (7ba58ecf0c0a9a69d44b3dca62becf56) C:\Windows\system32\DRIVERS\swenum.sys
                2011/03/27 12:30:39.0955 5528 Symc8xx (192aa3ac01df071b541094f251deed10) C:\Windows\system32\drivers\symc8xx.sys
                2011/03/27 12:30:41.0434 5528 Sym_hi (8c8eb8c76736ebaf3b13b633b2e64125) C:\Windows\system32\drivers\sym_hi.sys
                2011/03/27 12:30:43.0242 5528 Sym_u3 (8072af52b5fd103bbba387a1e49f62cb) C:\Windows\system32\drivers\sym_u3.sys
                2011/03/27 12:30:45.0099 5528 Tcpip (782568ab6a43160a159b6215b70bcce9) C:\Windows\system32\drivers\tcpip.sys
                2011/03/27 12:30:46.0994 5528 Tcpip6 (782568ab6a43160a159b6215b70bcce9) C:\Windows\system32\DRIVERS\tcpip.sys
                2011/03/27 12:30:48.0608 5528 tcpipreg (d4a2e4a4b011f3a883af77315a5ae76b) C:\Windows\system32\drivers\tcpipreg.sys
                2011/03/27 12:30:50.0010 5528 TDPIPE (5dcf5e267be67a1ae926f2df77fbcc56) C:\Windows\system32\drivers\tdpipe.sys
                2011/03/27 12:30:51.0755 5528 TDTCP (389c63e32b3cefed425b61ed92d3f021) C:\Windows\system32\drivers\tdtcp.sys
                2011/03/27 12:30:53.0147 5528 tdx (d09276b1fab033ce1d40dcbdf303d10f) C:\Windows\system32\DRIVERS\tdx.sys
                2011/03/27 12:30:54.0528 5528 TermDD (a048056f5e1a96a9bf3071b91741a5aa) C:\Windows\system32\DRIVERS\termdd.sys
                2011/03/27 12:30:54.0795 5528 Trufos (b16d66a71de03285e14e9f165b59eda4) C:\Program Files\Common Files\BitDefender\BitDefender Threat Scanner\trufos.sys
                2011/03/27 12:30:56.0184 5528 tssecsrv (dcf0f056a2e4f52287264f5ab29cf206) C:\Windows\system32\DRIVERS\tssecsrv.sys
                2011/03/27 12:30:57.0606 5528 tunmp (caecc0120ac49e3d2f758b9169872d38) C:\Windows\system32\DRIVERS\tunmp.sys
                2011/03/27 12:30:58.0985 5528 tunnel (119b8184e106baedc83fce5ddf3950da) C:\Windows\system32\DRIVERS\tunnel.sys
                2011/03/27 12:31:00.0432 5528 uagp35 (7d33c4db2ce363c8518d2dfcf533941f) C:\Windows\system32\drivers\uagp35.sys
                2011/03/27 12:31:01.0959 5528 udfs (8b5088058fa1d1cd897a2113ccff6c58) C:\Windows\system32\DRIVERS\udfs.sys
                2011/03/27 12:31:03.0454 5528 uliagpkx (b0acfdc9e4af279e9116c03e014b2b27) C:\Windows\system32\drivers\uliagpkx.sys
                2011/03/27 12:31:04.0935 5528 uliahci (9224bb254f591de4ca8d572a5f0d635c) C:\Windows\system32\drivers\uliahci.sys
                2011/03/27 12:31:06.0380 5528 UlSata (8514d0e5cd0534467c5fc61be94a569f) C:\Windows\system32\drivers\ulsata.sys
                2011/03/27 12:31:07.0744 5528 ulsata2 (38c3c6e62b157a6bc46594fada45c62b) C:\Windows\system32\drivers\ulsata2.sys
                2011/03/27 12:31:09.0111 5528 umbus (32cff9f809ae9aed85464492bf3e32d2) C:\Windows\system32\DRIVERS\umbus.sys
                2011/03/27 12:31:10.0549 5528 usbccgp (caf811ae4c147ffcd5b51750c7f09142) C:\Windows\system32\DRIVERS\usbccgp.sys
                2011/03/27 12:31:12.0029 5528 usbcir (e9476e6c486e76bc4898074768fb7131) C:\Windows\system32\drivers\usbcir.sys
                2011/03/27 12:31:13.0455 5528 usbehci (cebe90821810e76320155beba722fcf9) C:\Windows\system32\DRIVERS\usbehci.sys
                2011/03/27 12:31:15.0330 5528 usbhub (cc6b28e4ce39951357963119ce47b143) C:\Windows\system32\DRIVERS\usbhub.sys
                2011/03/27 12:31:16.0704 5528 usbohci (38dbc7dd6cc5a72011f187425384388b) C:\Windows\system32\drivers\usbohci.sys
                2011/03/27 12:31:18.0046 5528 usbprint (e75c4b5269091d15a2e7dc0b6d35f2f5) C:\Windows\system32\DRIVERS\usbprint.sys
                2011/03/27 12:31:19.0417 5528 usbscan (a508c9bd8724980512136b039bba65e9) C:\Windows\system32\DRIVERS\usbscan.sys
                2011/03/27 12:31:20.0807 5528 USBSTOR (87ba6b83c5d19b69160968d07d6e2982) C:\Windows\system32\DRIVERS\USBSTOR.SYS
                2011/03/27 12:31:22.0141 5528 usbuhci (814d653efc4d48be3b04a307eceff56f) C:\Windows\system32\DRIVERS\usbuhci.sys
                2011/03/27 12:31:23.0481 5528 usbvideo (e67998e8f14cb0627a769f6530bcb352) C:\Windows\system32\Drivers\usbvideo.sys
                2011/03/27 12:31:24.0962 5528 vga (87b06e1f30b749a114f74622d013f8d4) C:\Windows\system32\DRIVERS\vgapnp.sys
                2011/03/27 12:31:26.0291 5528 VgaSave (2e93ac0a1d8c79d019db6c51f036636c) C:\Windows\System32\drivers\vga.sys
                2011/03/27 12:31:27.0642 5528 viaagp (5d7159def58a800d5781ba3a879627bc) C:\Windows\system32\drivers\viaagp.sys
                2011/03/27 12:31:29.0010 5528 ViaC7 (c4f3a691b5bad343e6249bd8c2d45dee) C:\Windows\system32\drivers\viac7.sys
                2011/03/27 12:31:30.0378 5528 viaide (aadf5587a4063f52c2c3fed7887426fc) C:\Windows\system32\drivers\viaide.sys
                2011/03/27 12:31:31.0743 5528 vmm (e41fef9e3056fe88c71e411f705be41e) C:\Windows\system32\Drivers\vmm.sys
                2011/03/27 12:31:33.0352 5528 volmgr (69503668ac66c77c6cd7af86fbdf8c43) C:\Windows\system32\drivers\volmgr.sys
                2011/03/27 12:31:34.0737 5528 volmgrx (98f5ffe6316bd74e9e2c97206c190196) C:\Windows\system32\drivers\volmgrx.sys
                2011/03/27 12:31:36.0117 5528 volsnap (d8b4a53dd2769f226b3eb374374987c9) C:\Windows\system32\drivers\volsnap.sys
                2011/03/27 12:31:37.0450 5528 VPCNetS2 (f96a678debdccb0b4bb7f38cb2580589) C:\Windows\system32\DRIVERS\VMNetSrv.sys
                2011/03/27 12:31:38.0802 5528 vsmraid (587253e09325e6bf226b299774b728a9) C:\Windows\system32\drivers\vsmraid.sys
                2011/03/27 12:31:40.0179 5528 WacomPen (48dfee8f1af7c8235d4e626f0c4fe031) C:\Windows\system32\drivers\wacompen.sys
                2011/03/27 12:31:41.0558 5528 Wanarp (55201897378cca7af8b5efd874374a26) C:\Windows\system32\DRIVERS\wanarp.sys
                2011/03/27 12:31:41.0616 5528 Wanarpv6 (55201897378cca7af8b5efd874374a26) C:\Windows\system32\DRIVERS\wanarp.sys
                2011/03/27 12:31:42.0994 5528 Wd (78fe9542363f297b18c027b2d7e7c07f) C:\Windows\system32\drivers\wd.sys
                2011/03/27 12:31:44.0663 5528 Wdf01000 (b6f0a7ad6d4bd325fbcd8bac96cd8d96) C:\Windows\system32\drivers\Wdf01000.sys
                2011/03/27 12:31:46.0053 5528 winbondcir (3fa87d56769838aac82fafc3e78fc732) C:\Windows\system32\DRIVERS\winbondcir.sys
                2011/03/27 12:31:47.0386 5528 winbondhidcir (ee946145663d7f29e535db7a0f6f5302) C:\Windows\system32\DRIVERS\winbondhidcir.sys
                2011/03/27 12:31:48.0827 5528 WmiAcpi (2e7255d172df0b8283cdfb7b433b864e) C:\Windows\system32\DRIVERS\wmiacpi.sys
                2011/03/27 12:31:50.0242 5528 ws2ifsl (e3a3cb253c0ec2494d4a61f5e43a389c) C:\Windows\system32\drivers\ws2ifsl.sys
                2011/03/27 12:31:51.0686 5528 WUDFRd (ac13cb789d93412106b0fb6c7eb2bcb6) C:\Windows\system32\DRIVERS\WUDFRd.sys
                2011/03/27 12:31:51.0902 5528 ================================================================================
                2011/03/27 12:31:51.0902 5528 Scan finished
                2011/03/27 12:31:51.0902 5528 ================================================================================
                2011/03/27 12:31:51.0925 2288 Detected object count: 1
                2011/03/27 12:32:25.0012 2288 sptd (614deea4bdcec3fd5a07bdc705723ad7) C:\Windows\System32\Drivers\sptd.sys
                2011/03/27 12:32:25.0012 2288 Suspicious file (NoAccess): C:\Windows\System32\Drivers\sptd.sys. md5: 614deea4bdcec3fd5a07bdc705723ad7
                2011/03/27 12:32:25.0024 2288 C:\Windows\System32\Drivers\sptd.sys - copied to quarantine
                2011/03/27 12:32:25.0069 2288 Locked file(sptd) - User select action: Quarantine
                2011/03/27 12:32:32.0990 0608 Deinitialize success
                0
                1. Contributeur sécurité
                  il te reste quoi comme soucis ?
                  0
                  1. Je crois que pour le moment il n'y a pas de probleme ... mais c'est bit comet qu est a l origine de toutes ses conneries?
                    0
                    1. Contributeur sécurité
                      surement oui....

                      Fais un nouveau rapport ZHPdiag stp

                      Rend toi sur http://pjjoint.malekal.com/

                      Clique sur "Parcourir "

                      Sélectionne le rapport ZHPdiag.txt qui se trouve sur ton bureau

                      Clique ensuite sur "Envoyer le fichier " et copie/colle le lien dans ton prochain message
                      0
                      1. J ai mis le rapport sur cijoint car pjjoint lag
                        http://www.cijoint.fr/cj201103/cijdO2fRrz.txt
                        Mais sinon comment je desinstalle bit commet ?
                        0
                        1. http://www.cijoint.fr/cj201103/cijZoVzr8i.txt
                          0
                          1. Contributeur sécurité
                            Non, pas résolu

                            Il y a ca avant

                            1)

                            Mettre à jour VISTA Et internet explorer (même si tu ne l'utlises pas)

                            Par internet explorer

                            http://www.windowsupdate.com/windowsupdate/v6/default.aspx

                            .....................

                            2)

                            Mettre à jour la Console Java ? :
                            https://www.java.com/fr/download/uninstalltool.jsp

                            et installer la nouvelle version si besoin est (dans ce cas désinstalle avant l'ancienne version).

                            voici pour desinstaller :

                            JavaRa
                            http://raproducts.org/click/click.php?id=1

                            Décompresse le fichier sur le Bureau (Clic droit > Extraire tout).
                            * Double-clique (clic droit "en tant qu'administrateur" pour Vista) sur le répertoire JavaRa.
                            * Puis double-clique sur le fichier JavaRa.exe (le exe peut ne pas s'afficher).
                            * Choisis Français puis clique sur Select.
                            * Clique sur Recherche de mises à jour.
                            * Sélectionne Mettre à jour via jucheck.exe puis clique sur Rechercher.
                            * Autorise le processus à se connecter s'il le demande, clique sur Installer et suis les instructions d'installation qui prennent quelques minutes.
                            * L'installation est terminée, reviens à l'écran de JavaRa et clique sur Effacer les anciennes versions.
                            * Clique sur Oui pour confirmer. Laisse travailler et clique ensuite sur OK, puis une deuxième fois sur OK.
                            * Un rapport va s'ouvrir. Poste-le dans ta prochaine réponse.
                            * Ferme l'application.

                            Note : le rapport se trouve aussi dans C:\ sous le nom JavaRa.log.

                            .............

                            3)
                            IMPORTANT

                            Purger les points de restauration système:

                            Télécharge OneClick2RestorePoint

                            http://www.multifa7.be/Laddy/OneClick2RP.exe (merci à elle)

                            Mirroirs si non accessible :
                            http://batchdhelus.open-web.fr/Laddy/OneClick2RP.exe
                            https://app.box.com/s/cqcsz5m0oz

                            * Double clic sur OneClick2RP pour l'exécuter (Clic-droit choisir Executer en tant qu'administrateur sous Vista/Seven)
                            * Clic sur le bouton "Purger", l'outil de nettoyage de windows va s'ouvrir
                            * Choisis ton disque dur principal en général (C:\) ... Patiente pendant le scan...
                            * * Rends toi dans l'onglet "Autres options"
                            * Dans la zone restauration système, clic sur le bouton nettoyer puis sur le bouton Supprimer.
                            * Les points de restauration système seront purgés sauf le dernier créé.

                            Ensuite avec le même outil
                            Créer un nouveau point de restauration reconnaissable
                            .................

                            4)
                            pour supprimer les outils de désinfection :

                            télécharge Delfix de Xplode

                            http://www.teamxscript.org/too/Xplode/DelFix.exe

                            choisis SUPPRESSION

                            poste son rapport
                            .............................................

                            Recommandations pour l'avenir

                            Tu es la meilleure protection pour ton pc que tout autre antivirus, si tu admets un minimum de rigueur dans son utilisation...Les virus sont vigilants et pénètrent ta machine par toutes les portes que tu laisseras ouvertes...
                            - logiciels non à jour (windows, internet explorer, java, adobe reader etc)
                            - installation de toolbar
                            - fréquentation de sites piégés
                            - P2P
                            - Application de cracks
                            - Supports usb

                            Pour t'aider dans cette tâche, voici quelques pistes

                            Pour naviguer sur internet plus en sécurité et à l'abri des publicités, je te conseille vivement d'installer et d'utiliser le navigateur firefox
                            http://www.mozilla-europe.org/fr/firefox/

                            Une fois que c'est fait, lances le et installe l'extension de sécurité adblock plus
                            pour bloquer les publicités
                            https://addons.mozilla.org/fr/firefox/addon/adblock-plus/

                            ............................

                            WOT - Extension pour ton navigateur internet :
                            Voici une extension à télécharger qui te permettra, en faisant tes recherches sur google, de savoir si le site proposé lors de tes recherches est un site de confiance ou un site à éviter car il pourrait infecter ton PC :
                            Pour Firefox : https://addons.mozilla.org/fr/firefox/addon/wot-safe-browsing-tool/
                            Pour internet explorer : https://chrome.google.com/webstore/detail/wot-web-of-trust-website/bhmmomiinigofkjcapegjjndpbikblnp

                            ........................

                            Pour éviter une infection toolbar, il faut tout lire attentivement lorsque tu installes un programme gratuit, et décocher tous les programmes additionnels qui sont proposés, en particulier les barres d'outils !

                            ..........................

                            Vaccines tes disques amovibles à l'aide de USBFix (de Chiquitine29 et C_XX)
                            http://www.teamxscript.org/too/UsbFix.exe
                            Au menu principal, choisis l'option 3 (Vaccination).
                            ............................

                            garder Malwarebytes et faire un examen de temps en temps ton PC, avec mise à jour avant chaque scan
                            .......................

                            Télécharge et installe CCleaner (N'installe pas la Yahoo Toolbar) :
                            https://www.commentcamarche.net/telecharger/utilitaires/5647-ccleaner/

                            * Lance-le.(clic droit "en tant qu'administrateur" pour Vista) Va dans Options puis Avancé et décoche la case Effacer uniquement les fichiers etc....
                            * Va dans Nettoyeur, choisis Analyse. Une fois terminé, lance le nettoyage.
                            * Ensuite, choisis Registre, puis Chercher des erreurs. Une fois terminé, répare toutes les erreurs tant de fois qu il en trouve a l analyse

                            ..........................

                            Pour vérifier régulièrement que tous tes programmes sont bien à jour, tu peux utiliser Sécunia
                            https://www.donnemoilinfo.com/sujet/Securiser/secunia-personal-inspector.php

                            .........................

                            utilitaire pour défragmenter , utilises pour ce faire Defraggler https://www.clubic.com/telecharger-fiche44314-defraggler.html

                            ........................
                            A lire pour mieux comprendre l'environnement qui t'entoure
                            http://assiste.com.free.fr/p/abc/a/zombies_et_botnets.html
                            https://www.malekal.com/fichiers/projetantimalwares/ProjetAntiMalware-courte.pdf

                            http://www.libellules.ch/...

                            https://www.commentcamarche.net/faq/13362-mettre-a-jour-son-pc-contre-les-failles-de-securite

                            0
                            1. Oulaa tout un programme mais mise a jour vista :3heures vu le nombre de mise a jour demandées et pk mettre un truc que j'utilise pas ?
                              0
                            2. Contributeur sécurité
                              Windows utilise uniquement internet explorer pour faire les MAJ de sécurité

                              et toi tu es truffé de failles exploitées par les virus

                              Les MAJ sont la base de toute sécurtité..sinon tu reviens ici
                              0
                            3. OK j'ai fait les Maj la
                              0
                            4. Java mis a jour ( a l aide d'une petite icone qui a apparu quand j'ai redemarrer le pc xD)
                              0
                            5. Contributeur sécurité
                              tu peux continuer jusqu'à delfix
                              0
                          2. # DelFix v7.5 - Rapport créé le 27/03/2011 à 17:41
                            # Mis à jour le 15/03/11 à 16h30 par Xplode
                            # Système d'exploitation : Windows Vista (TM) Home Premium (32 bits) [version 6.0.6001] Service Pack 1
                            # Nom d'utilisateur : skyfucker - PC-DE-SKYFUCKER (Administrateur)
                            # Exécuté depuis : C:\Users\skyfucker\Downloads\DelFix.exe
                            # Option [Suppression]

                            ~~~~~~ Dossier(s) ~~~~~~

                            Supprimé : C:\ToolBar SD
                            Supprimé : C:\tdsskiller
                            Supprimé : C:\Program Files\Ad-Remover
                            Supprimé : C:\Program Files\ZHPDiag
                            Supprimé : C:\ProgramData\Microsoft\Windows\Start Menu\Programs\ZHP

                            ~~~~~~ Fichier(s) ~~~~~~

                            Supprimé : C:\TB.txt
                            Supprimé : C:\Ad-Report-CLEAN[1].txt
                            Supprimé : C:\TDSSKiller.2.4.21.0_27.03.2011_12.21.58_log.txt
                            Supprimé : C:\ZHPExportRegistry-27-03-2011-14-49-09.txt
                            Supprimé : C:\Users\skyfucker\Desktop\ZHPDiag.txt
                            Supprimé : C:\Users\skyfucker\Desktop\ZHPFix.lnk
                            Supprimé : C:\Users\skyfucker\Desktop\ZHPFixReport.txt
                            Supprimé : C:\Users\skyfucker\Downloads\mbr.exe
                            Supprimé : C:\Users\skyfucker\Downloads\AD-R.exe
                            Supprimé : C:\Users\skyfucker\Downloads\Load_tdsskiller.exe
                            Supprimé : C:\Users\skyfucker\Downloads\ZHPDiag2.exe
                            Supprimé : C:\Users\skyfucker\Downloads\OneClick2RP.exe
                            ~~~~~~ Registre ~~~~~~

                            Clé Supprimée : HKCU\SOFTWARE\Ad-Remover
                            Clé Supprimée : HKLM\Software\Microsoft\Windows\CurrentVersion\Uninstall\Ad-Remover
                            Clé Supprimée : HKLM\Software\Microsoft\Windows\CurrentVersion\Uninstall\ZHPDiag_is1
                            ~~~~~~ Autre ~~~~~~

                            ########## EOF - "C:\DelFixSuppr.txt" - [581 octets] ##########-> Prefetch vidé

                            ########## EOF - "C:\DelFixSuppr.txt" - [664 octets] ##########
                            0
                            1. Contributeur sécurité
                              c'est tout bon

                              sauf soucis

                              => résolu

                              bonne continuation...
                              0
                              • 1
                              • 2