Accent circonflexe/tréma n'apparaissent plus

massoun Messages postés 1041 Statut Membre -  
 gen-hackman -
Bonjour, lorsque je souhaite écrire un mot contenant un accent circonflexe/tréma, je peux l'écrire correctement, en effet, la touche de ces accents ne fonctionne plus correctement. Elle ne fonctionne que lorsque j'appuie deux fois consécutive, (^^¨¨), mais impossible d'écrire un mot contenant ces accents. J'ai fais un scan avec Avira, mais il n'a rien trouvé. Le PC (portable) est neuf (à peine un mois) donc ça ne vient pas de ça. Pourriez-vous me dire si cela vient d'un virus ou non svp?

25 réponses

  • 1
  • 2
  1. gen-hackman
     
    salut

    ▶ Télécharge ici : USBFIX sur ton bureau

    branche tous tes periphériques sans les ouvrir

    /!\ Désactive provisoirement et seulement le temps de l'utilisation d'USBFIX, la protection en temps réel de ton Antivirus et de tes Antispywares, qui peuvent gêner fortement la procédure de recherche et de nettoyage de l'outil.

    si tu as XP => double clique
    si tu as Vista ou windows 7 => clic droit "executer en tant que...."


    sur l'icône Usbfix située sur ton Bureau.
    Sur la page, clique sur le bouton :

    ▶ choisi l option Suppression

    ▶ UsbFix scannera ton pc , laisse travailler l outil.

    ▶ Ensuite post le rapport UsbFix.txt qui apparaitra avec le bureau .

    ▶ Note : Le rapport UsbFix.txt est sauvegardé a la racine du disque.( C:\UsbFix.txt )

    ( CTRL+A Pour tout selectionner , CTRL+C pour copier et CTRL+V pour coller )

    0
  2. massoun Messages postés 1041 Statut Membre 44
     
    Merci pour ta réponse, voici le rapport:
    ############################## | UsbFix 7.043 | [Suppression]

    Utilisateur: Geoffrey (Administrateur) # PC-DE-GEOFFREY [TOSHIBA Satellite L655]
    Mis à jour le 06/04/2011 par TeamXscript
    Lancé à 13:06:43 | 06/04/2011
    Site Web: http://www.teamxscript.org
    Submit your sample: http://www.teamxscript.org/Upload.php
    Contact: TeamXscript.ElDesaparecido@gmail.com

    CPU: Intel(R) Core(TM) i5 CPU M 480 @ 2.67GHz
    CPU 2: Intel(R) Core(TM) i5 CPU M 480 @ 2.67GHz
    Microsoft Windows 7 Édition Familiale Premium (6.1.7600 64-Bit) #
    Internet Explorer 8.0.7600.16385

    Pare-feu Windows: Activé
    RAM -> 3959 Mo
    C:\ (%systemdrive%) -> Disque fixe # 298 Go (198 Go libre(s) - 66%) [WINDOWS] # NTFS
    D:\ -> Disque fixe # 298 Go (289 Go libre(s) - 97%) [Data] # NTFS
    E:\ -> CD-ROM
    F:\ -> Disque amovible # 4 Go (2 Go libre(s) - 40%) [] # FAT32
    G:\ -> CD-ROM

    ################## | Éléments infectieux |

    Supprimé! C:\Users\Geoffrey\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\rundll32 .exe
    Supprimé! C:\Users\Geoffrey\AppData\Local\Temp\IXP000.TMP
    Supprimé! C:\Users\Geoffrey\AppData\Local\Temp\rundll32 .exe
    Supprimé! C:\Users\Geoffrey\AppData\Local\Temp\TCD1054.tmp
    Supprimé! C:\Users\Geoffrey\AppData\Local\Temp\TCD10B4.tmp
    Supprimé! C:\Users\Geoffrey\AppData\Local\Temp\TCD121D.tmp
    Supprimé! C:\Users\Geoffrey\AppData\Local\Temp\TCD18A5.tmp
    Supprimé! C:\Users\Geoffrey\AppData\Local\Temp\TCDA6EA.tmp
    Supprimé! C:\Users\Geoffrey\AppData\Local\Temp\TCDA8E0.tmp
    Supprimé! C:\Users\Geoffrey\AppData\Local\Temp\TCDAA39.tmp
    Supprimé! C:\Users\Geoffrey\AppData\Local\Temp\TCDB37E.tmp
    Supprimé! C:\Users\Geoffrey\AppData\Local\Temp\TCDB42C.tmp
    Supprimé! C:\Users\Geoffrey\AppData\Local\Temp\TCDBB6E.tmp
    Supprimé! C:\Users\Geoffrey\AppData\Local\Temp\TCDBD73.tmp
    Supprimé! C:\Users\Geoffrey\AppData\Local\Temp\TCDBEAD.tmp
    Supprimé! C:\Users\Geoffrey\AppData\Local\Temp\TCDBEFD.tmp
    Supprimé! C:\Users\Geoffrey\AppData\Local\Temp\TCDC0D3.tmp
    Supprimé! C:\Users\Geoffrey\AppData\Local\Temp\TCDC1AF.tmp
    Supprimé! C:\Users\Geoffrey\AppData\Local\Temp\TCDC23E.tmp
    Supprimé! C:\Users\Geoffrey\AppData\Local\Temp\TCDC349.tmp
    Supprimé! C:\Users\Geoffrey\AppData\Local\Temp\TCDC5BB.tmp
    Supprimé! C:\Users\Geoffrey\AppData\Local\Temp\TCDC733.tmp
    Supprimé! C:\Users\Geoffrey\AppData\Local\Temp\TCDCA41.tmp
    Supprimé! C:\Users\Geoffrey\AppData\Local\Temp\TCDCC46.tmp
    Supprimé! C:\Users\Geoffrey\AppData\Local\Temp\TCDD250.tmp
    Supprimé! C:\Users\Geoffrey\AppData\Local\Temp\TCDD31D.tmp
    Supprimé! C:\Users\Geoffrey\AppData\Local\Temp\TCDD409.tmp
    Supprimé! C:\Users\Geoffrey\AppData\Local\Temp\TCDD514.tmp
    Supprimé! C:\Users\Geoffrey\AppData\Local\Temp\TCDD69C.tmp
    Supprimé! C:\Users\Geoffrey\AppData\Local\Temp\TCDDB9E.tmp
    Supprimé! C:\Users\Geoffrey\AppData\Local\Temp\TCDDBCE.tmp
    Supprimé! C:\Users\Geoffrey\AppData\Local\Temp\TCDDD85.tmp
    Supprimé! C:\Users\Geoffrey\AppData\Local\Temp\TCDDEDE.tmp
    Supprimé! C:\Users\Geoffrey\AppData\Local\Temp\TCDE5F3.tmp
    Supprimé! C:\Users\Geoffrey\AppData\Local\Temp\TCDE5F4.tmp
    Supprimé! C:\Users\Geoffrey\AppData\Local\Temp\TCDEBD.tmp
    Supprimé! C:\Users\Geoffrey\AppData\Local\Temp\TCDF7A2.tmp
    Supprimé! C:\$RECYCLE.BIN\S-1-5-21-655946051-1420395869-2231756748-1000
    Supprimé! C:\$RECYCLE.BIN\S-1-5-21-655946051-1420395869-2231756748-500
    Supprimé! D:\$RECYCLE.BIN\S-1-5-21-655946051-1420395869-2231756748-1000
    Supprimé! D:\$RECYCLE.BIN\S-1-5-21-655946051-1420395869-2231756748-500

    ################## | Registre |

    Supprimé! HKCU\Software\Microsoft\Windows\CurrentVersion\Run|rundll32

    ################## | Mountpoints2 |

    ################## | Listing |

    [06/04/2011 - 13:09:49 | SHD ] C:\$RECYCLE.BIN
    [14/07/2009 - 07:08:56 | SHD ] C:\Documents and Settings
    [06/04/2011 - 11:50:29 | ASH | 3113361408] C:\hiberfil.sys
    [10/01/2011 - 20:45:09 | D ] C:\Intel
    [15/03/2011 - 14:40:04 | RHD ] C:\MSOCache
    [06/04/2011 - 11:50:31 | ASH | 4151148544] C:\pagefile.sys
    [14/07/2009 - 05:20:08 | D ] C:\PerfLogs
    [21/03/2011 - 21:15:38 | D ] C:\Program Files
    [03/04/2011 - 20:37:47 | D ] C:\Program Files (x86)
    [28/03/2011 - 18:46:43 | HD ] C:\ProgramData
    [09/11/2010 - 15:49:02 | N | 70] C:\SWSTAMP.TXT
    [05/04/2011 - 20:11:02 | SHD ] C:\System Volume Information
    [15/03/2011 - 14:08:03 | D ] C:\Toshiba
    [06/04/2011 - 13:09:49 | D ] C:\UsbFix
    [06/04/2011 - 13:06:49 | A | 4349] C:\UsbFix.txt
    [15/03/2011 - 14:05:41 | D ] C:\Users
    [30/03/2011 - 20:53:41 | D ] C:\Windows
    [06/04/2011 - 13:09:49 | SHD ] D:\$RECYCLE.BIN
    [15/03/2011 - 23:01:07 | D ] D:\HDDRecovery
    [02/05/2010 - 09:46:22 | N | 11] D:\R14479FR.tag
    [10/01/2011 - 20:40:12 | SHD ] D:\System Volume Information
    [14/03/2011 - 08:00:54 | N | 833159168] F:\MICROSOFT.OFFICE.2010.VF.64.BIT.FRENCH.RETAIL.FINAL.BY.PARISIEN99.SMS.iso
    [14/03/2011 - 13:11:40 | N | 11193664] F:\daemon-tools_daemon_tools_4.40.2.0131_francais_10729(2).exe
    [14/03/2011 - 21:32:50 | N | 2279830] F:\winrar-x64-400fr.exe
    [14/03/2011 - 21:32:46 | D ] F:\WinRAR.4.00.Final.FRENCH.AiO.Corporate.Edition.WinALL-DTC
    [13/09/2009 - 19:17:54 | N | 26] F:\Livebox.txt
    [15/03/2011 - 13:48:26 | N | 8649320] F:\Firefox Setup 3.6.15.exe
    [15/03/2011 - 13:51:44 | N | 6463660] F:\RocketDock-v1.3.5.exe
    [15/03/2011 - 13:51:54 | N | 10058] F:\Vista_Black_for_Rocketdock_by_WhiteRaven92.zip
    [15/03/2011 - 13:51:00 | N | 51132808] F:\avira_antivir_personal_fr.exe
    [15/03/2011 - 13:57:16 | N | 68256] F:\3854-40983.png
    [15/03/2011 - 13:57:18 | N | 48358] F:\16951-DjpOner-CCleaner.png
    [24/03/2011 - 19:29:44 | N | 798308352] F:\Dikkenek-Grande Gueule-Version Longue Making Of.avi
    [04/10/2010 - 17:41:00 | N | 1702457] F:\chimie11950521510962095784714.pdf
    [02/04/2011 - 20:27:08 | N | 732332032] F:\Gullivers.Travels.FRENCH.DVDRip.XviD-AYMO.avi

    ################## | Vaccin |

    C:\Autorun.inf -> Vaccin créé par UsbFix (TeamXscript)
    D:\Autorun.inf -> Vaccin créé par UsbFix (TeamXscript)
    F:\Autorun.inf -> Vaccin créé par UsbFix (TeamXscript)

    ################## | Upload |

    Veuillez envoyer le fichier: C:\UsbFix_Upload_Me_PC-DE-GEOFFREY.zip
    http://www.teamxscript.org/Upload.php
    Merci de votre contribution.

    ################## | E.O.F |
    0
  3. gen-hackman
     
    ▶ Télécharge TDSSKiller

    ▶ Lance le ( Utilisateurs de vista/Seven -> Clic droit puis " Exécuter en tant que........... " )

    L'outil va télécharger automatiquement la dernière version de TDSSKiller puis lancera une analyse.

    Patiente pendant le scan. A la fin de l'analyse, appuies sur une touche. Un rapport va s'ouvrir.

    ▶ Copie/Colle son contenu dans ta prochaine réponse.

    Note : Le rapport se trouve également sous C:\tdsskiller.txt.
    0
  4. massoun Messages postés 1041 Statut Membre 44
     
    2011/04/06 13:31:19.0089 2112 TDSS rootkit removing tool 2.4.21.0 Mar 10 2011 12:26:28
    2011/04/06 13:31:20.0197 2112 ================================================================================
    2011/04/06 13:31:20.0197 2112 SystemInfo:
    2011/04/06 13:31:20.0197 2112
    2011/04/06 13:31:20.0197 2112 OS Version: 6.1.7600 ServicePack: 0.0
    2011/04/06 13:31:20.0197 2112 Product type: Workstation
    2011/04/06 13:31:20.0197 2112 ComputerName: PC-DE-GEOFFREY
    2011/04/06 13:31:20.0197 2112 UserName: Geoffrey
    2011/04/06 13:31:20.0197 2112 Windows directory: C:\Windows
    2011/04/06 13:31:20.0197 2112 System windows directory: C:\Windows
    2011/04/06 13:31:20.0197 2112 Running under WOW64
    2011/04/06 13:31:20.0197 2112 Processor architecture: Intel x64
    2011/04/06 13:31:20.0197 2112 Number of processors: 4
    2011/04/06 13:31:20.0197 2112 Page size: 0x1000
    2011/04/06 13:31:20.0197 2112 Boot type: Normal boot
    2011/04/06 13:31:20.0197 2112 ================================================================================
    2011/04/06 13:31:20.0465 2112 Initialize success
    2011/04/06 13:31:23.0542 2400 ================================================================================
    2011/04/06 13:31:23.0542 2400 Scan started
    2011/04/06 13:31:23.0542 2400 Mode: Manual;
    2011/04/06 13:31:23.0542 2400 ================================================================================
    2011/04/06 13:31:24.0169 2400 1394ohci (1b00662092f9f9568b995902f0cc40d5) C:\Windows\system32\DRIVERS\1394ohci.sys
    2011/04/06 13:31:24.0322 2400 ACPI (6f11e88748cdefd2f76aa215f97ddfe5) C:\Windows\system32\DRIVERS\ACPI.sys
    2011/04/06 13:31:24.0447 2400 AcpiPmi (63b05a0420ce4bf0e4af6dcc7cada254) C:\Windows\system32\DRIVERS\acpipmi.sys
    2011/04/06 13:31:24.0594 2400 adp94xx (2f6b34b83843f0c5118b63ac634f5bf4) C:\Windows\system32\DRIVERS\adp94xx.sys
    2011/04/06 13:31:24.0718 2400 adpahci (597f78224ee9224ea1a13d6350ced962) C:\Windows\system32\DRIVERS\adpahci.sys
    2011/04/06 13:31:24.0841 2400 adpu320 (e109549c90f62fb570b9540c4b148e54) C:\Windows\system32\DRIVERS\adpu320.sys
    2011/04/06 13:31:24.0985 2400 AFD (b9384e03479d2506bc924c16a3db87bc) C:\Windows\system32\drivers\afd.sys
    2011/04/06 13:31:25.0108 2400 agp440 (608c14dba7299d8cb6ed035a68a15799) C:\Windows\system32\DRIVERS\agp440.sys
    2011/04/06 13:31:25.0258 2400 aliide (5812713a477a3ad7363c7438ca2ee038) C:\Windows\system32\DRIVERS\aliide.sys
    2011/04/06 13:31:25.0385 2400 amdide (1ff8b4431c353ce385c875f194924c0c) C:\Windows\system32\DRIVERS\amdide.sys
    2011/04/06 13:31:25.0517 2400 AmdK8 (7024f087cff1833a806193ef9d22cda9) C:\Windows\system32\DRIVERS\amdk8.sys
    2011/04/06 13:31:25.0821 2400 amdkmdag (f05b22ce901fc26ae55a1a27aa674d96) C:\Windows\system32\DRIVERS\atikmdag.sys
    2011/04/06 13:31:26.0148 2400 amdkmdap (ed25d58581b5a28593c277f482fccd62) C:\Windows\system32\DRIVERS\atikmpag.sys
    2011/04/06 13:31:26.0252 2400 AmdPPM (1e56388b3fe0d031c44144eb8c4d6217) C:\Windows\system32\DRIVERS\amdppm.sys
    2011/04/06 13:31:26.0359 2400 amdsata (7a4b413614c055935567cf88a9734d38) C:\Windows\system32\DRIVERS\amdsata.sys
    2011/04/06 13:31:26.0484 2400 amdsbs (f67f933e79241ed32ff46a4f29b5120b) C:\Windows\system32\DRIVERS\amdsbs.sys
    2011/04/06 13:31:26.0593 2400 amdxata (b4ad0cacbab298671dd6f6ef7e20679d) C:\Windows\system32\DRIVERS\amdxata.sys
    2011/04/06 13:31:26.0716 2400 AppID (42fd751b27fa0e9c69bb39f39e409594) C:\Windows\system32\drivers\appid.sys
    2011/04/06 13:31:26.0871 2400 arc (c484f8ceb1717c540242531db7845c4e) C:\Windows\system32\DRIVERS\arc.sys
    2011/04/06 13:31:26.0984 2400 arcsas (019af6924aefe7839f61c830227fe79c) C:\Windows\system32\DRIVERS\arcsas.sys
    2011/04/06 13:31:27.0102 2400 AsyncMac (769765ce2cc62867468cea93969b2242) C:\Windows\system32\DRIVERS\asyncmac.sys
    2011/04/06 13:31:27.0215 2400 atapi (02062c0b390b7729edc9e69c680a6f3c) C:\Windows\system32\DRIVERS\atapi.sys
    2011/04/06 13:31:27.0344 2400 athr (e857eee6b92aaa473ebb3465add8f7e7) C:\Windows\system32\DRIVERS\athrx.sys
    2011/04/06 13:31:27.0488 2400 avgntflt (39c2e2870fc0c2ae0595b883cbe716b4) C:\Windows\system32\DRIVERS\avgntflt.sys
    2011/04/06 13:31:27.0592 2400 avipbb (c98fa6e5ad0e857d22716bd2b8b1f399) C:\Windows\system32\DRIVERS\avipbb.sys
    2011/04/06 13:31:27.0746 2400 b06bdrv (3e5b191307609f7514148c6832bb0842) C:\Windows\system32\DRIVERS\bxvbda.sys
    2011/04/06 13:31:27.0871 2400 b57nd60a (b5ace6968304a3900eeb1ebfd9622df2) C:\Windows\system32\DRIVERS\b57nd60a.sys
    2011/04/06 13:31:27.0998 2400 Beep (16a47ce2decc9b099349a5f840654746) C:\Windows\system32\drivers\Beep.sys
    2011/04/06 13:31:28.0126 2400 blbdrive (61583ee3c3a17003c4acd0475646b4d3) C:\Windows\system32\DRIVERS\blbdrive.sys
    2011/04/06 13:31:28.0238 2400 bowser (91ce0d3dc57dd377e690a2d324022b08) C:\Windows\system32\DRIVERS\bowser.sys
    2011/04/06 13:31:28.0344 2400 BrFiltLo (f09eee9edc320b5e1501f749fde686c8) C:\Windows\system32\DRIVERS\BrFiltLo.sys
    2011/04/06 13:31:28.0450 2400 BrFiltUp (b114d3098e9bdb8bea8b053685831be6) C:\Windows\system32\DRIVERS\BrFiltUp.sys
    2011/04/06 13:31:28.0553 2400 Brserid (43bea8d483bf1870f018e2d02e06a5bd) C:\Windows\System32\Drivers\Brserid.sys
    2011/04/06 13:31:28.0665 2400 BrSerWdm (a6eca2151b08a09caceca35c07f05b42) C:\Windows\System32\Drivers\BrSerWdm.sys
    2011/04/06 13:31:28.0772 2400 BrUsbMdm (b79968002c277e869cf38bd22cd61524) C:\Windows\System32\Drivers\BrUsbMdm.sys
    2011/04/06 13:31:28.0872 2400 BrUsbSer (a87528880231c54e75ea7a44943b38bf) C:\Windows\System32\Drivers\BrUsbSer.sys
    2011/04/06 13:31:28.0973 2400 BTHMODEM (9da669f11d1f894ab4eb69bf546a42e8) C:\Windows\system32\DRIVERS\bthmodem.sys
    2011/04/06 13:31:29.0130 2400 cdfs (b8bd2bb284668c84865658c77574381a) C:\Windows\system32\DRIVERS\cdfs.sys
    2011/04/06 13:31:29.0251 2400 cdrom (83d2d75e1efb81b3450c18131443f7db) C:\Windows\system32\DRIVERS\cdrom.sys
    2011/04/06 13:31:29.0385 2400 circlass (d7cd5c4e1b71fa62050515314cfb52cf) C:\Windows\system32\DRIVERS\circlass.sys
    2011/04/06 13:31:29.0488 2400 CLFS (fe1ec06f2253f691fe36217c592a0206) C:\Windows\system32\CLFS.sys
    2011/04/06 13:31:29.0654 2400 CmBatt (0840155d0bddf1190f84a663c284bd33) C:\Windows\system32\DRIVERS\CmBatt.sys
    2011/04/06 13:31:29.0752 2400 cmdide (e19d3f095812725d88f9001985b94edd) C:\Windows\system32\DRIVERS\cmdide.sys
    2011/04/06 13:31:29.0873 2400 CNG (f95fd4cb7da00ba2a63ce9f6b5c053e1) C:\Windows\system32\Drivers\cng.sys
    2011/04/06 13:31:30.0005 2400 CnxtHdAudService (25c58ee97be0416a373e3e4f855206b5) C:\Windows\system32\drivers\CHDRT64.sys
    2011/04/06 13:31:30.0137 2400 CnxtHdmiAudService (89c99ab4ae9535f727791592d84d4821) C:\Windows\system32\drivers\CHDMI64.sys
    2011/04/06 13:31:30.0270 2400 Compbatt (102de219c3f61415f964c88e9085ad14) C:\Windows\system32\DRIVERS\compbatt.sys
    2011/04/06 13:31:30.0381 2400 CompositeBus (f26b3a86f6fa87ca360b879581ab4123) C:\Windows\system32\DRIVERS\CompositeBus.sys
    2011/04/06 13:31:30.0493 2400 crcdisk (1c827878a998c18847245fe1f34ee597) C:\Windows\system32\DRIVERS\crcdisk.sys
    2011/04/06 13:31:30.0628 2400 DfsC (3f1dc527070acb87e40afe46ef6da749) C:\Windows\system32\Drivers\dfsc.sys
    2011/04/06 13:31:30.0750 2400 discache (13096b05847ec78f0977f2c0f79e9ab3) C:\Windows\system32\drivers\discache.sys
    2011/04/06 13:31:30.0873 2400 Disk (9819eee8b5ea3784ec4af3b137a5244c) C:\Windows\system32\DRIVERS\disk.sys
    2011/04/06 13:31:31.0011 2400 drmkaud (9b19f34400d24df84c858a421c205754) C:\Windows\system32\drivers\drmkaud.sys
    2011/04/06 13:31:31.0110 2400 dtsoftbus01 (fb9bef3401ee5ecc2603311b9c64f44a) C:\Windows\system32\DRIVERS\dtsoftbus01.sys
    2011/04/06 13:31:31.0240 2400 DXGKrnl (601e731bf8e3f22906ce7d4d724b0439) C:\Windows\System32\drivers\dxgkrnl.sys
    2011/04/06 13:31:31.0431 2400 ebdrv (dc5d737f51be844d8c82c695eb17372f) C:\Windows\system32\DRIVERS\evbda.sys
    2011/04/06 13:31:31.0637 2400 elxstor (0e5da5369a0fcaea12456dd852545184) C:\Windows\system32\DRIVERS\elxstor.sys
    2011/04/06 13:31:31.0740 2400 ErrDev (34a3c54752046e79a126e15c51db409b) C:\Windows\system32\DRIVERS\errdev.sys
    2011/04/06 13:31:31.0860 2400 exfat (a510c654ec00c1e9bdd91eeb3a59823b) C:\Windows\system32\drivers\exfat.sys
    2011/04/06 13:31:31.0966 2400 fastfat (0adc83218b66a6db380c330836f3e36d) C:\Windows\system32\drivers\fastfat.sys
    2011/04/06 13:31:32.0091 2400 fdc (d765d19cd8ef61f650c384f62fac00ab) C:\Windows\system32\DRIVERS\fdc.sys
    2011/04/06 13:31:32.0193 2400 FileInfo (655661be46b5f5f3fd454e2c3095b930) C:\Windows\system32\drivers\fileinfo.sys
    2011/04/06 13:31:32.0291 2400 Filetrace (5f671ab5bc87eea04ec38a6cd5962a47) C:\Windows\system32\drivers\filetrace.sys
    2011/04/06 13:31:32.0397 2400 flpydisk (c172a0f53008eaeb8ea33fe10e177af5) C:\Windows\system32\DRIVERS\flpydisk.sys
    2011/04/06 13:31:32.0497 2400 FltMgr (f7866af72abbaf84b1fa5aa195378c59) C:\Windows\system32\drivers\fltmgr.sys
    2011/04/06 13:31:32.0623 2400 FsDepends (d43703496149971890703b4b1b723eac) C:\Windows\system32\drivers\FsDepends.sys
    2011/04/06 13:31:32.0726 2400 Fs_Rec (e95ef8547de20cf0603557c0cf7a9462) C:\Windows\system32\drivers\Fs_Rec.sys
    2011/04/06 13:31:32.0843 2400 fvevol (ae87ba80d0ec3b57126ed2cdc15b24ed) C:\Windows\system32\DRIVERS\fvevol.sys
    2011/04/06 13:31:32.0965 2400 FwLnk (60acb128e64c35c2b4e4aab1b0a5c293) C:\Windows\system32\DRIVERS\FwLnk.sys
    2011/04/06 13:31:33.0068 2400 gagp30kx (8c778d335c9d272cfd3298ab02abe3b6) C:\Windows\system32\DRIVERS\gagp30kx.sys
    2011/04/06 13:31:33.0171 2400 GEARAspiWDM (e403aacf8c7bb11375122d2464560311) C:\Windows\system32\DRIVERS\GEARAspiWDM.sys
    2011/04/06 13:31:33.0264 2400 hcw85cir (f2523ef6460fc42405b12248338ab2f0) C:\Windows\system32\drivers\hcw85cir.sys
    2011/04/06 13:31:33.0361 2400 HdAudAddService (6410f6f415b2a5a9037224c41da8bf12) C:\Windows\system32\drivers\HdAudio.sys
    2011/04/06 13:31:33.0459 2400 HDAudBus (0a49913402747a0b67de940fb42cbdbb) C:\Windows\system32\DRIVERS\HDAudBus.sys
    2011/04/06 13:31:33.0564 2400 HECIx64 (b6ac71aaa2b10848f57fc49d55a651af) C:\Windows\system32\DRIVERS\HECIx64.sys
    2011/04/06 13:31:33.0618 2400 HidBatt (78e86380454a7b10a5eb255dc44a355f) C:\Windows\system32\DRIVERS\HidBatt.sys
    2011/04/06 13:31:33.0745 2400 HidBth (7fd2a313f7afe5c4dab14798c48dd104) C:\Windows\system32\DRIVERS\hidbth.sys
    2011/04/06 13:31:33.0840 2400 HidIr (0a77d29f311b88cfae3b13f9c1a73825) C:\Windows\system32\DRIVERS\hidir.sys
    2011/04/06 13:31:33.0949 2400 HidUsb (b3bf6b5b50006def50b66306d99fcf6f) C:\Windows\system32\DRIVERS\hidusb.sys
    2011/04/06 13:31:34.0081 2400 HpSAMD (0886d440058f203eba0e1825e4355914) C:\Windows\system32\DRIVERS\HpSAMD.sys
    2011/04/06 13:31:34.0126 2400 HTTP (cee049cac4efa7f4e1e4ad014414a5d4) C:\Windows\system32\drivers\HTTP.sys
    2011/04/06 13:31:34.0216 2400 hwpolicy (f17766a19145f111856378df337a5d79) C:\Windows\system32\drivers\hwpolicy.sys
    2011/04/06 13:31:34.0314 2400 i8042prt (fa55c73d4affa7ee23ac4be53b4592d3) C:\Windows\system32\DRIVERS\i8042prt.sys
    2011/04/06 13:31:34.0414 2400 iaStor (85977cd13fc16069ce0af7943a811775) C:\Windows\system32\DRIVERS\iaStor.sys
    2011/04/06 13:31:34.0528 2400 iaStorV (d83efb6fd45df9d55e9a1afc63640d50) C:\Windows\system32\DRIVERS\iaStorV.sys
    2011/04/06 13:31:34.0645 2400 iirsp (5c18831c61933628f5bb0ea2675b9d21) C:\Windows\system32\DRIVERS\iirsp.sys
    2011/04/06 13:31:34.0766 2400 Impcd (4b6363cd4610bb848531bb260b15dfcc) C:\Windows\system32\DRIVERS\Impcd.sys
    2011/04/06 13:31:34.0878 2400 intelide (f00f20e70c6ec3aa366910083a0518aa) C:\Windows\system32\DRIVERS\intelide.sys
    2011/04/06 13:31:34.0974 2400 intelppm (ada036632c664caa754079041cf1f8c1) C:\Windows\system32\DRIVERS\intelppm.sys
    2011/04/06 13:31:35.0076 2400 IpFilterDriver (722dd294df62483cecaae6e094b4d695) C:\Windows\system32\DRIVERS\ipfltdrv.sys
    2011/04/06 13:31:35.0182 2400 IPMIDRV (e2b4a4494db7cb9b89b55ca268c337c5) C:\Windows\system32\DRIVERS\IPMIDrv.sys
    2011/04/06 13:31:35.0295 2400 IPNAT (af9b39a7e7b6caa203b3862582e9f2d0) C:\Windows\system32\drivers\ipnat.sys
    2011/04/06 13:31:35.0392 2400 IRENUM (3abf5e7213eb28966d55d58b515d5ce9) C:\Windows\system32\drivers\irenum.sys
    2011/04/06 13:31:35.0492 2400 isapnp (2f7b28dc3e1183e5eb418df55c204f38) C:\Windows\system32\DRIVERS\isapnp.sys
    2011/04/06 13:31:35.0537 2400 iScsiPrt (fa4d2557de56d45b0a346f93564be6e1) C:\Windows\system32\DRIVERS\msiscsi.sys
    2011/04/06 13:31:35.0671 2400 kbdclass (bc02336f1cba7dcc7d1213bb588a68a5) C:\Windows\system32\DRIVERS\kbdclass.sys
    2011/04/06 13:31:35.0762 2400 kbdhid (6def98f8541e1b5dceb2c822a11f7323) C:\Windows\system32\DRIVERS\kbdhid.sys
    2011/04/06 13:31:35.0816 2400 KSecDD (e8b6fcc9c83535c67f835d407620bd27) C:\Windows\system32\Drivers\ksecdd.sys
    2011/04/06 13:31:35.0908 2400 KSecPkg (a8c63880ef6f4d3fec7b616b9c060215) C:\Windows\system32\Drivers\ksecpkg.sys
    2011/04/06 13:31:36.0017 2400 ksthunk (6869281e78cb31a43e969f06b57347c4) C:\Windows\system32\drivers\ksthunk.sys
    2011/04/06 13:31:36.0119 2400 L1C (55480b9c63f3f91a8ebbadcbf28fe581) C:\Windows\system32\DRIVERS\L1C62x64.sys
    2011/04/06 13:31:36.0239 2400 lltdio (1538831cf8ad2979a04c423779465827) C:\Windows\system32\DRIVERS\lltdio.sys
    2011/04/06 13:31:36.0372 2400 LSI_FC (1a93e54eb0ece102495a51266dcdb6a6) C:\Windows\system32\DRIVERS\lsi_fc.sys
    2011/04/06 13:31:36.0475 2400 LSI_SAS (1047184a9fdc8bdbff857175875ee810) C:\Windows\system32\DRIVERS\lsi_sas.sys
    2011/04/06 13:31:36.0598 2400 LSI_SAS2 (30f5c0de1ee8b5bc9306c1f0e4a75f93) C:\Windows\system32\DRIVERS\lsi_sas2.sys
    2011/04/06 13:31:36.0713 2400 LSI_SCSI (0504eacaff0d3c8aed161c4b0d369d4a) C:\Windows\system32\DRIVERS\lsi_scsi.sys
    2011/04/06 13:31:36.0820 2400 luafv (43d0f98e1d56ccddb0d5254cff7b356e) C:\Windows\system32\drivers\luafv.sys
    2011/04/06 13:31:36.0923 2400 megasas (a55805f747c6edb6a9080d7c633bd0f4) C:\Windows\system32\DRIVERS\megasas.sys
    2011/04/06 13:31:37.0036 2400 MegaSR (baf74ce0072480c3b6b7c13b2a94d6b3) C:\Windows\system32\DRIVERS\MegaSR.sys
    2011/04/06 13:31:37.0154 2400 Modem (800ba92f7010378b09f9ed9270f07137) C:\Windows\system32\drivers\modem.sys
    2011/04/06 13:31:37.0253 2400 monitor (b03d591dc7da45ece20b3b467e6aadaa) C:\Windows\system32\DRIVERS\monitor.sys
    2011/04/06 13:31:37.0353 2400 mouclass (7d27ea49f3c1f687d357e77a470aea99) C:\Windows\system32\DRIVERS\mouclass.sys
    2011/04/06 13:31:37.0452 2400 mouhid (d3bf052c40b0c4166d9fd86a4288c1e6) C:\Windows\system32\DRIVERS\mouhid.sys
    2011/04/06 13:31:37.0588 2400 mountmgr (791af66c4d0e7c90a3646066386fb571) C:\Windows\system32\drivers\mountmgr.sys
    2011/04/06 13:31:37.0704 2400 mpio (609d1d87649ecc19796f4d76d4c15cea) C:\Windows\system32\DRIVERS\mpio.sys
    2011/04/06 13:31:37.0800 2400 mpsdrv (6c38c9e45ae0ea2fa5e551f2ed5e978f) C:\Windows\system32\drivers\mpsdrv.sys
    2011/04/06 13:31:37.0903 2400 MRxDAV (30524261bb51d96d6fcbac20c810183c) C:\Windows\system32\drivers\mrxdav.sys
    2011/04/06 13:31:38.0004 2400 mrxsmb (767a4c3bcf9410c286ced15a2db17108) C:\Windows\system32\DRIVERS\mrxsmb.sys
    2011/04/06 13:31:38.0107 2400 mrxsmb10 (920ee0ff995fcfdeb08c41605a959e1c) C:\Windows\system32\DRIVERS\mrxsmb10.sys
    2011/04/06 13:31:38.0196 2400 mrxsmb20 (740d7ea9d72c981510a5292cf6adc941) C:\Windows\system32\DRIVERS\mrxsmb20.sys
    2011/04/06 13:31:38.0285 2400 msahci (2ba4ff3d5eb68587dd662a896f649c7d) C:\Windows\system32\DRIVERS\msahci.sys
    2011/04/06 13:31:38.0384 2400 msdsm (8d27b597229aed79430fb9db3bcbfbd0) C:\Windows\system32\DRIVERS\msdsm.sys
    2011/04/06 13:31:38.0496 2400 Msfs (aa3fb40e17ce1388fa1bedab50ea8f96) C:\Windows\system32\drivers\Msfs.sys
    2011/04/06 13:31:38.0604 2400 mshidkmdf (f9d215a46a8b9753f61767fa72a20326) C:\Windows\System32\drivers\mshidkmdf.sys
    2011/04/06 13:31:38.0696 2400 msisadrv (d916874bbd4f8b07bfb7fa9b3ccae29d) C:\Windows\system32\DRIVERS\msisadrv.sys
    2011/04/06 13:31:38.0811 2400 MSKSSRV (49ccf2c4fea34ffad8b1b59d49439366) C:\Windows\system32\drivers\MSKSSRV.sys
    2011/04/06 13:31:38.0909 2400 MSPCLOCK (bdd71ace35a232104ddd349ee70e1ab3) C:\Windows\system32\drivers\MSPCLOCK.sys
    2011/04/06 13:31:39.0013 2400 MSPQM (4ed981241db27c3383d72092b618a1d0) C:\Windows\system32\drivers\MSPQM.sys
    2011/04/06 13:31:39.0102 2400 MsRPC (89cb141aa8616d8c6a4610fa26c60964) C:\Windows\system32\drivers\MsRPC.sys
    2011/04/06 13:31:39.0211 2400 mssmbios (0eed230e37515a0eaee3c2e1bc97b288) C:\Windows\system32\DRIVERS\mssmbios.sys
    2011/04/06 13:31:39.0311 2400 MSTEE (2e66f9ecb30b4221a318c92ac2250779) C:\Windows\system32\drivers\MSTEE.sys
    2011/04/06 13:31:39.0403 2400 MTConfig (7ea404308934e675bffde8edf0757bcd) C:\Windows\system32\DRIVERS\MTConfig.sys
    2011/04/06 13:31:39.0512 2400 Mup (f9a18612fd3526fe473c1bda678d61c8) C:\Windows\system32\Drivers\mup.sys
    2011/04/06 13:31:39.0659 2400 NativeWifiP (1ea3749c4114db3e3161156ffffa6b33) C:\Windows\system32\DRIVERS\nwifi.sys
    2011/04/06 13:31:39.0808 2400 NDIS (cad515dbd07d082bb317d9928ce8962c) C:\Windows\system32\drivers\ndis.sys
    2011/04/06 13:31:39.0920 2400 NdisCap (9f9a1f53aad7da4d6fef5bb73ab811ac) C:\Windows\system32\DRIVERS\ndiscap.sys
    2011/04/06 13:31:40.0023 2400 NdisTapi (30639c932d9fef22b31268fe25a1b6e5) C:\Windows\system32\DRIVERS\ndistapi.sys
    2011/04/06 13:31:40.0123 2400 Ndisuio (f105ba1e22bf1f2ee8f005d4305e4bec) C:\Windows\system32\DRIVERS\ndisuio.sys
    2011/04/06 13:31:40.0215 2400 NdisWan (557dfab9ca1fcb036ac77564c010dad3) C:\Windows\system32\DRIVERS\ndiswan.sys
    2011/04/06 13:31:40.0316 2400 NDProxy (659b74fb74b86228d6338d643cd3e3cf) C:\Windows\system32\drivers\NDProxy.sys
    2011/04/06 13:31:40.0405 2400 NetBIOS (86743d9f5d2b1048062b14b1d84501c4) C:\Windows\system32\DRIVERS\netbios.sys
    2011/04/06 13:31:40.0498 2400 NetBT (9162b273a44ab9dce5b44362731d062a) C:\Windows\system32\DRIVERS\netbt.sys
    2011/04/06 13:31:40.0648 2400 nfrd960 (77889813be4d166cdab78ddba990da92) C:\Windows\system32\DRIVERS\nfrd960.sys
    2011/04/06 13:31:40.0756 2400 Npfs (1e4c4ab5c9b8dd13179bbdc75a2a01f7) C:\Windows\system32\drivers\Npfs.sys
    2011/04/06 13:31:40.0856 2400 nsiproxy (e7f5ae18af4168178a642a9247c63001) C:\Windows\system32\drivers\nsiproxy.sys
    2011/04/06 13:31:40.0987 2400 Ntfs (356698a13c4630d5b31c37378d469196) C:\Windows\system32\drivers\Ntfs.sys
    2011/04/06 13:31:41.0109 2400 Null (9899284589f75fa8724ff3d16aed75c1) C:\Windows\system32\drivers\Null.sys
    2011/04/06 13:31:41.0209 2400 nvraid (3e38712941e9bb4ddbee00affe3fed3d) C:\Windows\system32\DRIVERS\nvraid.sys
    2011/04/06 13:31:41.0313 2400 nvstor (477dc4d6deb99be37084c9ac6d013da1) C:\Windows\system32\DRIVERS\nvstor.sys
    2011/04/06 13:31:41.0416 2400 nv_agp (270d7cd42d6e3979f6dd0146650f0e05) C:\Windows\system32\DRIVERS\nv_agp.sys
    2011/04/06 13:31:41.0530 2400 ohci1394 (3589478e4b22ce21b41fa1bfc0b8b8a0) C:\Windows\system32\DRIVERS\ohci1394.sys
    2011/04/06 13:31:41.0680 2400 Parport (0086431c29c35be1dbc43f52cc273887) C:\Windows\system32\DRIVERS\parport.sys
    2011/04/06 13:31:41.0771 2400 partmgr (7daa117143316c4a1537e074a5a9eaf0) C:\Windows\system32\drivers\partmgr.sys
    2011/04/06 13:31:41.0843 2400 pci (f36f6504009f2fb0dfd1b17a116ad74b) C:\Windows\system32\DRIVERS\pci.sys
    2011/04/06 13:31:41.0939 2400 pciide (b5b8b5ef2e5cb34df8dcf8831e3534fa) C:\Windows\system32\DRIVERS\pciide.sys
    2011/04/06 13:31:42.0023 2400 pcmcia (b2e81d4e87ce48589f98cb8c05b01f2f) C:\Windows\system32\DRIVERS\pcmcia.sys
    2011/04/06 13:31:42.0118 2400 pcw (d6b9c2e1a11a3a4b26a182ffef18f603) C:\Windows\system32\drivers\pcw.sys
    2011/04/06 13:31:42.0219 2400 PEAUTH (68769c3356b3be5d1c732c97b9a80d6e) C:\Windows\system32\drivers\peauth.sys
    2011/04/06 13:31:42.0352 2400 PGEffect (663962900e7fea522126ba287715bb4a) C:\Windows\system32\DRIVERS\pgeffect.sys
    2011/04/06 13:31:42.0477 2400 PptpMiniport (27cc19e81ba5e3403c48302127bda717) C:\Windows\system32\DRIVERS\raspptp.sys
    2011/04/06 13:31:42.0576 2400 Processor (0d922e23c041efb1c3fac2a6f943c9bf) C:\Windows\system32\DRIVERS\processr.sys
    2011/04/06 13:31:42.0693 2400 Psched (ee992183bd8eaefd9973f352e587a299) C:\Windows\system32\DRIVERS\pacer.sys
    2011/04/06 13:31:42.0825 2400 ql2300 (a53a15a11ebfd21077463ee2c7afeef0) C:\Windows\system32\DRIVERS\ql2300.sys
    2011/04/06 13:31:42.0935 2400 ql40xx (4f6d12b51de1aaeff7dc58c4d75423c8) C:\Windows\system32\DRIVERS\ql40xx.sys
    2011/04/06 13:31:43.0041 2400 QWAVEdrv (76707bb36430888d9ce9d705398adb6c) C:\Windows\system32\drivers\qwavedrv.sys
    2011/04/06 13:31:43.0134 2400 RasAcd (5a0da8ad5762fa2d91678a8a01311704) C:\Windows\system32\DRIVERS\rasacd.sys
    2011/04/06 13:31:43.0249 2400 RasAgileVpn (7ecff9b22276b73f43a99a15a6094e90) C:\Windows\system32\DRIVERS\AgileVpn.sys
    2011/04/06 13:31:43.0364 2400 Rasl2tp (87a6e852a22991580d6d39adc4790463) C:\Windows\system32\DRIVERS\rasl2tp.sys
    2011/04/06 13:31:43.0487 2400 RasPppoe (855c9b1cd4756c5e9a2aa58a15f58c25) C:\Windows\system32\DRIVERS\raspppoe.sys
    2011/04/06 13:31:43.0622 2400 RasSstp (e8b1e447b008d07ff47d016c2b0eeecb) C:\Windows\system32\DRIVERS\rassstp.sys
    2011/04/06 13:31:43.0739 2400 rdbss (3bac8142102c15d59a87757c1d41dce5) C:\Windows\system32\DRIVERS\rdbss.sys
    2011/04/06 13:31:43.0836 2400 rdpbus (302da2a0539f2cf54d7c6cc30c1f2d8d) C:\Windows\system32\DRIVERS\rdpbus.sys
    2011/04/06 13:31:43.0933 2400 RDPCDD (cea6cc257fc9b7715f1c2b4849286d24) C:\Windows\system32\DRIVERS\RDPCDD.sys
    2011/04/06 13:31:44.0042 2400 RDPENCDD (bb5971a4f00659529a5c44831af22365) C:\Windows\system32\drivers\rdpencdd.sys
    2011/04/06 13:31:44.0144 2400 RDPREFMP (216f3fa57533d98e1f74ded70113177a) C:\Windows\system32\drivers\rdprefmp.sys
    2011/04/06 13:31:44.0240 2400 RDPWD (8a3e6bea1c53ea6177fe2b6eba2c80d7) C:\Windows\system32\drivers\RDPWD.sys
    2011/04/06 13:31:44.0363 2400 rdyboost (e5dc9ba9e439d6dbdd79f8caacb5bf01) C:\Windows\system32\drivers\rdyboost.sys
    2011/04/06 13:31:44.0507 2400 rspndr (ddc86e4f8e7456261e637e3552e804ff) C:\Windows\system32\DRIVERS\rspndr.sys
    2011/04/06 13:31:44.0637 2400 RSUSBSTOR (907c4464381b5ebdfdc60f6c7d0dedfc) C:\Windows\System32\Drivers\RtsUStor.sys
    2011/04/06 13:31:44.0752 2400 rtl8192se (7475548b0ba58eba4d12414fc9e9dfe6) C:\Windows\system32\DRIVERS\rtl8192se.sys
    2011/04/06 13:31:44.0867 2400 sbp2port (e3bbb89983daf5622c1d50cf49f28227) C:\Windows\system32\DRIVERS\sbp2port.sys
    2011/04/06 13:31:44.0969 2400 scfilter (c94da20c7e3ba1dca269bc8460d98387) C:\Windows\system32\DRIVERS\scfilter.sys
    2011/04/06 13:31:45.0085 2400 secdrv (3ea8a16169c26afbeb544e0e48421186) C:\Windows\system32\drivers\secdrv.sys
    2011/04/06 13:31:45.0195 2400 Serenum (cb624c0035412af0debec78c41f5ca1b) C:\Windows\system32\DRIVERS\serenum.sys
    2011/04/06 13:31:45.0307 2400 Serial (c1d8e28b2c2adfaec4ba89e9fda69bd6) C:\Windows\system32\DRIVERS\serial.sys
    2011/04/06 13:31:45.0430 2400 sermouse (1c545a7d0691cc4a027396535691c3e3) C:\Windows\system32\DRIVERS\sermouse.sys
    2011/04/06 13:31:45.0545 2400 sffdisk (a554811bcd09279536440c964ae35bbf) C:\Windows\system32\DRIVERS\sffdisk.sys
    2011/04/06 13:31:45.0648 2400 sffp_mmc (ff414f0baefeba59bc6c04b3db0b87bf) C:\Windows\system32\DRIVERS\sffp_mmc.sys
    2011/04/06 13:31:45.0752 2400 sffp_sd (178298f767fe638c9fedcbdef58bb5e4) C:\Windows\system32\DRIVERS\sffp_sd.sys
    2011/04/06 13:31:45.0858 2400 sfloppy (a9d601643a1647211a1ee2ec4e433ff4) C:\Windows\system32\DRIVERS\sfloppy.sys
    2011/04/06 13:31:45.0974 2400 SiSRaid2 (843caf1e5fde1ffd5ff768f23a51e2e1) C:\Windows\system32\DRIVERS\SiSRaid2.sys
    2011/04/06 13:31:46.0069 2400 SiSRaid4 (6a6c106d42e9ffff8b9fcb4f754f6da4) C:\Windows\system32\DRIVERS\sisraid4.sys
    2011/04/06 13:31:46.0182 2400 Smb (548260a7b8654e024dc30bf8a7c5baa4) C:\Windows\system32\DRIVERS\smb.sys
    2011/04/06 13:31:46.0307 2400 spldr (b9e31e5cacdfe584f34f730a677803f9) C:\Windows\system32\drivers\spldr.sys
    2011/04/06 13:31:46.0430 2400 srv (de6f5658da951c4bc8e498570b5b0d5f) C:\Windows\system32\DRIVERS\srv.sys
    2011/04/06 13:31:46.0535 2400 srv2 (4d33d59c0b930c523d29f9bd40cda9d2) C:\Windows\system32\DRIVERS\srv2.sys
    2011/04/06 13:31:46.0635 2400 srvnet (5a663fd67049267bc5c3f3279e631ffb) C:\Windows\system32\DRIVERS\srvnet.sys
    2011/04/06 13:31:46.0751 2400 stexstor (f3817967ed533d08327dc73bc4d5542a) C:\Windows\system32\DRIVERS\stexstor.sys
    2011/04/06 13:31:46.0876 2400 StillCam (decacb6921ded1a38642642685d77dac) C:\Windows\system32\DRIVERS\serscan.sys
    2011/04/06 13:31:46.0979 2400 swenum (d01ec09b6711a5f8e7e6564a4d0fbc90) C:\Windows\system32\DRIVERS\swenum.sys
    2011/04/06 13:31:47.0108 2400 SynTP (470c47daba9ca3966f0ab3f835d7d135) C:\Windows\system32\DRIVERS\SynTP.sys
    2011/04/06 13:31:47.0278 2400 Tcpip (90a2d722cf64d911879d6c4a4f802a4d) C:\Windows\system32\drivers\tcpip.sys
    2011/04/06 13:31:47.0444 2400 TCPIP6 (90a2d722cf64d911879d6c4a4f802a4d) C:\Windows\system32\DRIVERS\tcpip.sys
    2011/04/06 13:31:47.0563 2400 tcpipreg (76d078af6f587b162d50210f761eb9ed) C:\Windows\system32\drivers\tcpipreg.sys
    2011/04/06 13:31:47.0685 2400 tdcmdpst (fd542b661bd22fa69ca789ad0ac58c29) C:\Windows\system32\DRIVERS\tdcmdpst.sys
    2011/04/06 13:31:47.0748 2400 TDPIPE (3371d21011695b16333a3934340c4e7c) C:\Windows\system32\drivers\tdpipe.sys
    2011/04/06 13:31:47.0848 2400 TDTCP (e4245bda3190a582d55ed09e137401a9) C:\Windows\system32\drivers\tdtcp.sys
    2011/04/06 13:31:47.0954 2400 tdx (079125c4b17b01fcaeebce0bcb290c0f) C:\Windows\system32\DRIVERS\tdx.sys
    2011/04/06 13:31:48.0070 2400 TermDD (c448651339196c0e869a355171875522) C:\Windows\system32\DRIVERS\termdd.sys
    2011/04/06 13:31:48.0203 2400 TIEHDUSB (199c2e87d9a5ec58d0bcd94e893bf629) C:\Windows\system32\DRIVERS\tiehdusb.sys
    2011/04/06 13:31:48.0344 2400 tssecsrv (61b96c26131e37b24e93327a0bd1fb95) C:\Windows\system32\DRIVERS\tssecsrv.sys
    2011/04/06 13:31:48.0455 2400 tunnel (3836171a2cdf3af8ef10856db9835a70) C:\Windows\system32\DRIVERS\tunnel.sys
    2011/04/06 13:31:48.0566 2400 TVALZ (550b567f9364d8f7684c3fb3ea665a72) C:\Windows\system32\DRIVERS\TVALZ_O.SYS
    2011/04/06 13:31:48.0666 2400 TVALZFL (9c7191f4b2e49bff47a6c1144b5923fa) C:\Windows\system32\DRIVERS\TVALZFL.sys
    2011/04/06 13:31:48.0767 2400 uagp35 (b4dd609bd7e282bfc683cec7eaaaad67) C:\Windows\system32\DRIVERS\uagp35.sys
    2011/04/06 13:31:48.0876 2400 udfs (d47baead86c65d4f4069d7ce0a4edceb) C:\Windows\system32\DRIVERS\udfs.sys
    2011/04/06 13:31:48.0998 2400 uliagpkx (4bfe1bc28391222894cbf1e7d0e42320) C:\Windows\system32\DRIVERS\uliagpkx.sys
    2011/04/06 13:31:49.0103 2400 umbus (eab6c35e62b1b0db0d1b48b671d3a117) C:\Windows\system32\DRIVERS\umbus.sys
    2011/04/06 13:31:49.0209 2400 UmPass (b2e8e8cb557b156da5493bbddcc1474d) C:\Windows\system32\DRIVERS\umpass.sys
    2011/04/06 13:31:49.0323 2400 USBAAPL64 (54d4b48d443e7228bf64cf7cdc3118ac) C:\Windows\system32\Drivers\usbaapl64.sys
    2011/04/06 13:31:49.0434 2400 usbccgp (b26afb54a534d634523c4fb66765b026) C:\Windows\system32\DRIVERS\usbccgp.sys
    2011/04/06 13:31:49.0549 2400 usbcir (af0892a803fdda7492f595368e3b68e7) C:\Windows\system32\DRIVERS\usbcir.sys
    2011/04/06 13:31:49.0676 2400 usbehci (cb490987a7f6928a04bb838e3bd8a936) C:\Windows\system32\DRIVERS\usbehci.sys
    2011/04/06 13:31:49.0807 2400 usbhub (18124ef0a881a00ee222d02a3ee30270) C:\Windows\system32\DRIVERS\usbhub.sys
    2011/04/06 13:31:49.0917 2400 usbohci (58e546bbaf87664fc57e0f6081e4f609) C:\Windows\system32\DRIVERS\usbohci.sys
    2011/04/06 13:31:50.0023 2400 usbprint (73188f58fb384e75c4063d29413cee3d) C:\Windows\system32\DRIVERS\usbprint.sys
    2011/04/06 13:31:50.0130 2400 USBSTOR (080d3820da6c046be82fc8b45a893e83) C:\Windows\system32\DRIVERS\USBSTOR.SYS
    2011/04/06 13:31:50.0237 2400 usbuhci (81fb2216d3a60d1284455d511797db3d) C:\Windows\system32\DRIVERS\usbuhci.sys
    2011/04/06 13:31:50.0347 2400 usbvideo (7cb8c573c6e4a2714402cc0a36eab4fe) C:\Windows\system32\Drivers\usbvideo.sys
    2011/04/06 13:31:50.0469 2400 vdrvroot (c5c876ccfc083ff3b128f933823e87bd) C:\Windows\system32\DRIVERS\vdrvroot.sys
    2011/04/06 13:31:50.0574 2400 vga (da4da3f5e02943c2dc8c6ed875de68dd) C:\Windows\system32\DRIVERS\vgapnp.sys
    2011/04/06 13:31:50.0689 2400 VgaSave (53e92a310193cb3c03bea963de7d9cfc) C:\Windows\System32\drivers\vga.sys
    2011/04/06 13:31:50.0802 2400 vhdmp (c82e748660f62a242b2dfac1442f22a4) C:\Windows\system32\DRIVERS\vhdmp.sys
    2011/04/06 13:31:50.0923 2400 viaide (e5689d93ffe4e5d66c0178761240dd54) C:\Windows\system32\DRIVERS\viaide.sys
    2011/04/06 13:31:51.0016 2400 volmgr (2b1a3dae2b4e70dbba822b7a03fbd4a3) C:\Windows\system32\DRIVERS\volmgr.sys
    2011/04/06 13:31:51.0126 2400 volmgrx (99b0cbb569ca79acaed8c91461d765fb) C:\Windows\system32\drivers\volmgrx.sys
    2011/04/06 13:31:51.0241 2400 volsnap (58f82eed8ca24b461441f9c3e4f0bf5c) C:\Windows\system32\DRIVERS\volsnap.sys
    2011/04/06 13:31:51.0357 2400 vsmraid (5e2016ea6ebaca03c04feac5f330d997) C:\Windows\system32\DRIVERS\vsmraid.sys
    2011/04/06 13:31:51.0467 2400 vwifibus (36d4720b72b5c5d9cb2b9c29e9df67a1) C:\Windows\system32\DRIVERS\vwifibus.sys
    2011/04/06 13:31:51.0587 2400 vwififlt (6a3d66263414ff0d6fa754c646612f3f) C:\Windows\system32\DRIVERS\vwififlt.sys
    2011/04/06 13:31:51.0746 2400 WacomPen (4e9440f4f152a7b944cb1663d3935a3e) C:\Windows\system32\DRIVERS\wacompen.sys
    2011/04/06 13:31:51.0863 2400 WANARP (47ca49400643effd3f1c9a27e1d69324) C:\Windows\system32\DRIVERS\wanarp.sys
    2011/04/06 13:31:51.0888 2400 Wanarpv6 (47ca49400643effd3f1c9a27e1d69324) C:\Windows\system32\DRIVERS\wanarp.sys
    2011/04/06 13:31:52.0011 2400 Wd (72889e16ff12ba0f235467d6091b17dc) C:\Windows\system32\DRIVERS\wd.sys
    2011/04/06 13:31:52.0118 2400 Wdf01000 (441bd2d7b4f98134c3a4f9fa570fd250) C:\Windows\system32\drivers\Wdf01000.sys
    2011/04/06 13:31:52.0274 2400 WfpLwf (611b23304bf067451a9fdee01fbdd725) C:\Windows\system32\DRIVERS\wfplwf.sys
    2011/04/06 13:31:52.0380 2400 WIMMount (05ecaec3e4529a7153b3136ceb49f0ec) C:\Windows\system32\drivers\wimmount.sys
    2011/04/06 13:31:52.0529 2400 WinUsb (817eaff5d38674edd7713b9dfb8e9791) C:\Windows\system32\DRIVERS\WinUsb.sys
    2011/04/06 13:31:52.0680 2400 WmiAcpi (f6ff8944478594d0e414d3f048f0d778) C:\Windows\system32\DRIVERS\wmiacpi.sys
    2011/04/06 13:31:52.0802 2400 ws2ifsl (6bcc1d7d2fd2453957c5479a32364e52) C:\Windows\system32\drivers\ws2ifsl.sys
    2011/04/06 13:31:52.0936 2400 WudfPf (7cadc74271dd6461c452c271b30bd378) C:\Windows\system32\drivers\WudfPf.sys
    2011/04/06 13:31:53.0052 2400 WUDFRd (3b197af0fff08aa66b6b2241ca538d64) C:\Windows\system32\DRIVERS\WUDFRd.sys
    2011/04/06 13:31:53.0119 2400 ================================================================================
    2011/04/06 13:31:53.0119 2400 Scan finished
    2011/04/06 13:31:53.0119 2400 ================================================================================
    2011/04/06 13:32:07.0177 2140 Deinitialize success
    0
  5. Vous n’avez pas trouvé la réponse que vous recherchez ?

    Posez votre question
  6. gen-hackman
     
    Télécharge ici :OTL

    enregistre le sur ton Bureau.

    si tu as XP => double clique
    si tu as Vista ou windows 7 => clic droit "executer en tant que...."


    sur OTL.exe pour le lancer.

    ▶ Configuration

    ▶Clic sur Analyse.

    A la fin du scan, le Bloc-Notes va s'ouvrir avec le rapport (OTL.txt).

    Ce fichier est sur ton Bureau (en général C:\Documents and settings\le_nom_de_ta_session\OTL.txt)

    ▶▶▶ NE LE POSTE PAS SUR LE FORUM (il est trop long)

    Pour me le transmettre clique sur ce lien : http://www.cijoint.fr/

    ▶ Clique sur Parcourir et cherche le fichier ci-dessus.

    ▶ Clique sur Ouvrir.

    ▶ Clique sur "Cliquez ici pour déposer le fichier".

    juste au niveau du bouton , en fin de chargement du fichier , Un lien de cette forme apparaitra :

    http://www.cijoint.fr/cjlink.php?file=cjge368/cijSKAP5fU.txt

    ▶ Copie ce lien dans ta réponse.

    ▶▶ Tu feras la meme chose avec le "Extra.txt" qui logiquement sera aussi sur ton bureau.
    0
  7. massoun Messages postés 1041 Statut Membre 44
     
    Extra:
    http://www.cijoint.fr/cjlink.php?file=cj201104/cijCiibyBS.txt

    OTL:
    http://www.cijoint.fr/cjlink.php?file=cj201104/cij28zn5qV.txt
    0
  8. gen-hackman
     
    fermer toutes les fenêtres et applications lors de l'installation et de l'analyse.

    ▶ Télécharge ici :

    Malwarebytes

    ▶ Installe le ( choisis bien "francais" ; ne modifie pas les paramètres d'installe ) et mets le à jour .

    (NB : Si tu as un message d'erreur t'indiquant qu'il te manque "COMCTL32.OCX" lors de l'installe, alors télécharge le ici : COMCTL32.OCX

    ▶ Potasses le Tuto pour te familiariser avec le prg :

    ( cela dit, il est très simple d'utilisation ).

    relance malwarebytes en suivant scrupuleusement ces consignes :

    ! Déconnecte toi et ferme toutes applications en cours !

    ▶ Lance Malwarebyte's .

    Fais un examen dit "Complet" .

    ▶ Laisse le programme travailler ( et ne rien faire d'autre avec le PC durant le scan ).
    ▶ à la fin tu cliques sur "résultat" .
    Vérifie que tous les objets infectés soient validés, puis clique sur " suppression " .

    Note : si il faut redémarrer ton PC pour finir le nettoyage, fais le !

    Poste le rapport sauvegardé après la suppression des objets infectés (dans l'onglet "rapport/log"de Malwarebytes, le dernier en date)

    0
  9. massoun Messages postés 1041 Statut Membre 44
     
    Malwarebytes' Anti-Malware 1.50.1.1100
    www.malwarebytes.org

    Version de la base de données: 6286

    Windows 6.1.7600
    Internet Explorer 8.0.7600.16385

    06/04/2011 14:45:47
    mbam-log-2011-04-06 (14-45-47).txt

    Type d'examen: Examen complet (C:\|D:\|)
    Elément(s) analysé(s): 316688
    Temps écoulé: 34 minute(s), 57 seconde(s)

    Processus mémoire infecté(s): 0
    Module(s) mémoire infecté(s): 0
    Clé(s) du Registre infectée(s): 1
    Valeur(s) du Registre infectée(s): 0
    Elément(s) de données du Registre infecté(s): 1
    Dossier(s) infecté(s): 0
    Fichier(s) infecté(s): 1

    Processus mémoire infecté(s):
    (Aucun élément nuisible détecté)

    Module(s) mémoire infecté(s):
    (Aucun élément nuisible détecté)

    Clé(s) du Registre infectée(s):
    HKEY_CURRENT_USER\Software\DC3_FEXEC (Malware.Trace) -> Quarantined and deleted successfully.

    Valeur(s) du Registre infectée(s):
    (Aucun élément nuisible détecté)

    Elément(s) de données du Registre infecté(s):
    HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\AntiVirusDisableNotify (PUM.Disabled.SecurityCenter) -> Bad: (1) Good: (0) -> Quarantined and deleted successfully.

    Dossier(s) infecté(s):
    (Aucun élément nuisible détecté)

    Fichier(s) infecté(s):
    c:\Windows\Temp\svhost.exe (Heuristics.Reserved.Word.Exploit) -> Quarantined and deleted successfully.
    0
  10. massoun Messages postés 1041 Statut Membre 44
     
    Extra:
    http://www.cijoint.fr/cjlink.php?file=cj201104/cijUQsmoOQ.txt

    OTL:
    http://www.cijoint.fr/cjlink.php?file=cj201104/cijkuZc72f.txt
    0
  11. gen-hackman
     
    DESACTIVE TON ANTIVIRUS ET TON PAREFEU SI PRESENTS !!!!! (car l'outil est detecté a tort comme infection contenant un module qui sert à arrêter des processus , et un autre servant à prendre des droits dans le registre pour effectuer des suppressions)

    ▶ Télécharge ici :List_Kill'em

    et enregistre le sur ton bureau et lance l'installation

    Laisse coché :

    ♦ Executer List_Kill'em

    une fois terminée , clic sur "terminer"

    choisis l'option Search

    ▶ laisse travailler l'outil

    Attention : il se peut que l'outil bloque anormalement longtemps arrivé à 95%, relance-le avec le raccourci sur le bureau sans l'arreter , puis clique sur le tout petit "X" en bas de la fenetre d'accueil du programme, ca le debloquera pour finir son scan

    ▶ Poste les rapports qui apparaitront sur ton bureau : List'em.txt et More.txt

    ▶▶▶ NE LES POSTE PAS SUR LE FORUM

    Pour me le transmettre clique sur ce lien : http://www.cijoint.fr/

    ▶ Clique sur Parcourir et selectionne , un par un , les fichiers concernés apparus sur ton bureau

    ▶ Clique sur Ouvrir.

    ▶ Clique sur "Cliquez ici pour déposer le fichier".

    Un lien de cette forme :

    http://www.cijoint.fr/cjlink.php?file=265368/cijSKAP5fU.txt

    est ajouté dans la page.

    ▶ Copie ces liens dans ta réponse.
    0
  12. massoun Messages postés 1041 Statut Membre 44
     
    List'em:
    http://www.cijoint.fr/cjlink.php?file=cj201104/cijxOBA04H.txt

    More:
    http://www.cijoint.fr/cjlink.php?file=cj201104/cijblcC4oI.txt
    0
  13. gen-hackman
     
    Fais analyser le(s) fichier(s) suivants sur Virustotal :

    Virus Total

    * * Colle directement le chemin des fichiers , un par un , dans l'espace "Parcourir" apres chaque analyse :

    C:\Windows\system32\DRIVERS\TVALZ_O.SYS

    * Clique maintenant sur Envoyer le fichier. et laisse travailler tant que "Situation actuelle : en cours d'analyse" est affiché.
    * Il est possible que le fichier soit mis en file d'attente en raison d'un grand nombre de demandes d'analyses. En ce cas, il te faudra patienter sans actualiser la page.
    * Lorsque l'analyse est terminée colle le lien de(s)( la) page(s) dans ta prochaine réponse.
    G3?-?@¢??@?......Concepteur de List_Kill'em...Pre_Scan....
    0
  14. massoun Messages postés 1041 Statut Membre 44
     
    Je ne peux pas l'analyser, il n'apparait pas dans la liste, pourtant il est bl et bien présent dans l'ordi...
    0
  15. gen-hackman
     
    ▶ Relance List_Kill'em,avec le raccourci sur ton bureau.

    mais cette fois-ci :

    ▶ choisis l'Option Suppression

    ▶▶▶ Ne clique qu'une seule fois sur le bouton !!

    laisse travailler l'outil.

    en fin de scan la fenetre se ferme , et tu as un rapport du nom de Kill'em.txt sur ton bureau ,

    ▶ colle le contenu dans ta reponse

    ▶ envoie le zip Upload_ta-session_List_Kill'em.zip via cijoint.fr
    0
  16. massoun Messages postés 1041 Statut Membre 44
     
    ¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤ Kill'em by g3n-h@ckm@n 2.1.3.8 ¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤

    Mis à jour le 06/04/2011 | 15.30 par g3n-h@ckm@n
    Utilisateur : Geoffrey (Administrateurs)
    Ordinateur : PC-DE-GEOFFREY

    Système d'exploitation : Windows 7 Home Premium HomePremium (64 bits)

    c:\ -> [Fixed] | [WINDOWS] | Total : 305000 Mo | Free : 198790 Mo -> NTFS
    d:\ -> [Fixed] | [Data] | Total : 305070 Mo | Free : 295850 Mo -> NTFS
    e:\ -> [CDROM] | [] | Total : 0 Mo | Free : 0 Mo ->
    g:\ -> [CDROM] | [] | Total : 0 Mo | Free : 0 Mo ->

    Scan : 16:50:03 | 06/04/2011

    ¤¤¤¤¤¤¤¤¤¤ IFEO ¤¤¤¤¤¤¤¤¤¤

    ¤¤¤¤¤¤¤¤¤¤ Mountpoints2 ¤¤¤¤¤¤¤¤¤¤

    ¤¤¤¤¤¤¤¤¤¤ Hosts ¤¤¤¤¤¤¤¤¤¤

    ¤¤¤¤¤¤¤¤¤¤ Supression Fichiers | Dossiers ¤¤¤¤¤¤¤¤¤¤

    ¤¤¤¤¤¤¤¤¤¤ Suppression Clés ¤¤¤¤¤¤¤¤¤¤

    ¤¤¤¤¤¤¤¤¤¤¤ Services néfastes ¤¤¤¤¤¤¤¤¤¤

    ¤¤¤¤¤¤¤¤¤¤ Suppression Valeurs ¤¤¤¤¤¤¤¤¤¤

    Valeur Supprimée : [HKLM\..\..\Policies\Explorer] | NoActiveDesktop
    Valeur Supprimée : [HKLM\..\..\Policies\Explorer] | NoActiveDesktopChanges

    ¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤

    [HKLM\..\..\Security Center] | AntiVirusDisableNotify = 0

    Fin : 16:53:23

    ¤¤¤¤¤¤¤¤¤¤¤¤¤( EOF )¤¤¤¤¤¤¤¤¤¤¤¤
    0
  17. gen-hackman
     

    /!\ ATTENTION SUIVRE A LA LETTRE CES INDICATIONS/!\

    __________________________________________________________
    >Ce logiciel n'est à utiliser que prescrit par un helper qualifié et formé à l'outil.<
    >>>>>>>Ne pas utiliser en dehors de ce cas de figure : dangereux!<<<<<<<<
    =====================================================


    ▶ Surtout , pense à l'enregistrement à renommer Combofix en "ton prenom.exe" avant qu'il soit enregistré sur ton disque dur

    Telecharge ici : Combofix

    Avant d'utiliser ComboFix :

    Si tu utilises AVG, IL FAUT IMPERATIVEMENT LE DESINSTALLER avant d'utiliser Combofix car il peut causer des dégâts en interaction avec l'outil pouvant mener à la réinstallation totale du système.
    La simple désactivation du résident n'est pas suffisante.
    Télécharge le désinstalleur d'AVG sur ce lien : https://www.avg.com/fr-fr/avg-remover
    Choisis la version adéquate (32 ou 64 bits)/!\

    Les logiciels d'émulation de CD comme Daemon Tools peuvent gêner les outils de désinfection. Utilise Defogger pour les désactiver temporairement :

    ▶ Télécharge Defogger (de jpshortstuff) sur ton Bureau

    ▶ Lance le

    Une fenêtre apparait : clique sur "Disable"

    ▶ Fais redémarrer l'ordinateur si l'outil te le demande

    Note : Quand nous aurons terminé la désinfection, tu pourras réactiver ces logiciels en relançant Defogger et en cliquant sur "Re-enable"

    _________________________________________________________
    >> referme les fenêtres de tous les programmes en cours.
    >> Désactive provisoirement et seulement le temps de l'utilisation de ComboFix,
    >>la protection en temps réel de ton Antivirus et de tes Antispywares,
    >>qui peuvent gêner fortement la procédure de recherche et de nettoyage de l'outil.

    °°°°°°°°°°°°°°°°°°°°°°°°°°°°°°°°°°°°°°°°°°°°°°°°°°°°°°°°°°°°°°°°°°°°°°°°°°°


    si tu as XP => double clique
    si tu as Vista ou windows 7 => clic droit "executer en tant que...."


    sur combofix renommé

    ¤¤¤¤¤¤¤¤¤¤ LAISSE-LE INSTALLER LA CONSOLE DE RECUPERATION S'IL TE LE DEMANDE ¤¤¤¤¤¤¤¤¤¤

    ▶ !!!!!NE TOUCHE A RIEN PENDANT LE TRAVAIL DE COMBOFIX (SOURIS/CLAVIER.....)!!!!!

    ▶ n'oublie pas de reactiver la garde de ton Antivirus et de tes Antispywares, avant de te reconnecter à internet.

    ▶▶ Reviens sur le forum, et copie et colle la totalité du contenu de C:\Combofix.txt dans ton prochain message.

    0
  18. massoun Messages postés 1041 Statut Membre 44
     
    ComboFix 11-04-05.02 - Geoffrey 06/04/2011 17:09:02.1.4 - x64
    Microsoft Windows 7 Édition Familiale Premium 6.1.7600.0.1252.33.1036.18.3959.2572 [GMT 2:00]
    Lancé depuis: c:\users\Geoffrey\Desktop\Geoffrey.exe
    AV: AntiVir Desktop *Enabled/Updated* {090F9C29-64CE-6C6F-379C-5901B49A85B7}
    SP: AntiVir Desktop *Enabled/Updated* {B26E7DCD-42F4-63E1-0D2C-6273CF1DCF0A}
    SP: Windows Defender *Enabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
    .
    .
    (((((((((((((((((((((((((((((((((((( Autres suppressions ))))))))))))))))))))))))))))))))))))))))))))))))
    .
    .
    c:\tdsskiller\tdsskiller.exe
    c:\users\Geoffrey\AppData\Local\Microsoft\Windows\Temporary Internet Files\{2B924C48-1A65-44B1-9EBD-8307CE96FFF7}.xps
    c:\users\Geoffrey\AppData\Local\Microsoft\Windows\Temporary Internet Files\{357F9C46-DAFE-4626-AD11-7F5CADE42D26}.xps
    c:\users\Geoffrey\AppData\Local\Microsoft\Windows\Temporary Internet Files\{AB86A8F1-EFF0-4A35-96AE-D3061F0DE66D}.xps
    c:\users\Geoffrey\AppData\Local\Microsoft\Windows\Temporary Internet Files\{CDC7C4EE-5E49-46D9-A7AF-0150697BE7DA}.xps
    c:\users\Geoffrey\AppData\Local\Microsoft\Windows\Temporary Internet Files\{FE00B319-93D2-4667-9A7D-D7C7186B9E65}.xps
    .
    .
    ((((((((((((((((((((((((((((( Fichiers créés du 2011-03-06 au 2011-04-06 ))))))))))))))))))))))))))))))))))))
    .
    .
    2011-04-06 15:12 . 2011-04-06 15:12 -------- d-----w- c:\users\Default\AppData\Local\temp
    2011-04-06 13:57 . 2011-04-06 13:57 -------- d-----w- C:\Kill'em
    2011-04-06 13:57 . 2011-04-06 14:53 -------- d-----w- c:\program files (x86)\List_Kill'em
    2011-04-06 12:04 . 2010-12-20 16:09 38224 ----a-w- c:\windows\SysWow64\drivers\mbamswissarmy.sys
    2011-04-06 12:04 . 2011-04-06 12:04 -------- d-----w- c:\programdata\Malwarebytes
    2011-04-06 12:04 . 2011-04-06 12:04 -------- d-----w- c:\program files (x86)\Malwarebytes' Anti-Malware
    2011-04-06 12:04 . 2010-12-20 16:08 24152 ----a-w- c:\windows\system32\drivers\mbam.sys
    2011-04-06 11:30 . 2011-04-06 15:12 -------- d-----w- C:\tdsskiller
    2011-04-06 11:06 . 2011-04-06 11:09 -------- d-----w- C:\UsbFix
    2011-04-05 09:07 . 2011-03-15 05:17 8424784 ----a-w- c:\programdata\Microsoft\Windows Defender\Definition Updates\{D6307EA5-8474-44A1-8FA1-167D3AF56283}\mpengine.dll
    2011-04-03 18:37 . 2011-04-03 18:38 -------- d-----w- c:\program files (x86)\Total Video Converter
    2011-04-02 11:44 . 2011-04-02 11:44 -------- d-----w- c:\program files (x86)\Lame For Audacity
    2011-04-02 11:43 . 2011-04-02 11:43 -------- d-----w- c:\program files (x86)\Audacity
    2011-03-29 18:00 . 2011-04-06 10:05 -------- d-----w- c:\program files (x86)\JDownloader
    2011-03-28 16:46 . 2011-03-28 16:46 -------- d-----w- c:\programdata\CanonIJ
    2011-03-26 20:48 . 2011-03-29 18:16 -------- d-----w- c:\program files (x86)\Internet Download Manager
    2011-03-26 19:58 . 2011-03-26 19:58 -------- d-----w- c:\program files (x86)\TeamViewer
    2011-03-21 19:16 . 2011-03-21 19:16 -------- d-----w- c:\windows\Sun
    2011-03-21 19:15 . 2011-03-21 19:15 -------- d-----w- c:\program files\Common Files\CANON
    2011-03-21 19:15 . 2011-03-21 19:15 -------- d-----w- c:\program files\Canon
    2011-03-21 19:12 . 2011-03-21 19:12 -------- d--h--w- c:\programdata\CanonBJ
    2011-03-21 19:12 . 2008-05-29 20:00 82944 ----a-w- c:\windows\system32\Spool\prtprocs\x64\CNMPP9D.DLL
    2011-03-21 19:12 . 2008-05-29 20:00 27648 ----a-w- c:\windows\system32\Spool\prtprocs\x64\CNMPD9D.DLL
    2011-03-21 19:12 . 2011-03-21 19:12 -------- d--h--w- c:\windows\system32\CanonIJ Uninstaller Information
    2011-03-21 19:12 . 2008-05-29 20:00 279040 ----a-w- c:\windows\system32\CNMLM9D.DLL
    2011-03-21 19:12 . 2008-05-30 00:28 293376 ----a-w- c:\windows\system32\CNC620L.DLL
    2011-03-21 19:12 . 2008-04-07 05:59 92672 ----a-w- c:\windows\system32\CNC620I.DLL
    2011-03-21 19:12 . 2007-03-15 05:13 229888 ----a-w- c:\windows\system32\CNC620O.DLL
    2011-03-21 19:12 . 2008-04-07 05:59 1354240 ----a-w- c:\windows\system32\CNC620C.DLL
    2011-03-21 19:11 . 2007-06-06 00:42 151552 ----a-w- c:\windows\system32\CNMN6UI.DLL
    2011-03-21 19:11 . 2007-06-06 00:42 251904 ----a-w- c:\windows\system32\CNMN6PPM.DLL
    2011-03-21 19:07 . 2011-03-21 19:20 -------- d-----w- c:\program files (x86)\Canon
    2011-03-19 16:04 . 2011-03-19 16:04 -------- d-----w- c:\program files\DIFX
    2011-03-19 16:04 . 2009-09-03 15:30 128512 ----a-w- c:\windows\system32\drivers\tiehdusb.sys
    2011-03-19 16:04 . 2011-03-19 16:04 -------- d-----w- c:\program files (x86)\Common Files\TI Shared
    2011-03-19 16:04 . 2011-03-19 16:04 -------- d-----w- c:\program files (x86)\TI Education
    2011-03-18 23:39 . 2011-03-18 23:39 -------- d-----w- c:\program files (x86)\Pod to PC
    2011-03-18 18:39 . 2011-03-18 18:39 -------- d-----w- c:\program files (x86)\FreeTime
    2011-03-17 20:45 . 2011-03-27 15:28 -------- d-----w- c:\program files (x86)\Free PDF to Word Converter
    2011-03-17 20:36 . 2011-03-17 20:36 -------- d-----w- c:\program files (x86)\Guitar Pro 6
    2011-03-17 07:52 . 2011-03-17 07:52 -------- d-----w- c:\windows\SysWow64\Wat
    2011-03-17 07:52 . 2011-03-17 07:52 -------- d-----w- c:\windows\system32\Wat
    2011-03-16 18:40 . 2010-09-14 06:45 367104 ----a-w- c:\windows\system32\wcncsvc.dll
    2011-03-16 18:40 . 2010-09-14 06:07 276992 ----a-w- c:\windows\SysWow64\wcncsvc.dll
    2011-03-16 18:37 . 2011-03-16 18:37 -------- d-----w- c:\program files (x86)\MSXML 4.0
    2011-03-16 18:36 . 2009-11-25 11:47 99176 ----a-w- c:\windows\SysWow64\PresentationHostProxy.dll
    2011-03-16 18:36 . 2009-11-25 11:47 49472 ----a-w- c:\windows\SysWow64\netfxperf.dll
    2011-03-16 18:36 . 2009-11-25 11:47 48960 ----a-w- c:\windows\system32\netfxperf.dll
    2011-03-16 18:36 . 2009-11-25 11:47 297808 ----a-w- c:\windows\SysWow64\mscoree.dll
    2011-03-16 18:36 . 2009-11-25 11:47 295264 ----a-w- c:\windows\SysWow64\PresentationHost.exe
    2011-03-16 18:36 . 2009-11-25 11:47 1130824 ----a-w- c:\windows\SysWow64\dfshim.dll
    2011-03-16 18:36 . 2009-11-25 11:47 109912 ----a-w- c:\windows\system32\PresentationHostProxy.dll
    2011-03-16 18:36 . 2009-11-25 11:47 444752 ----a-w- c:\windows\system32\mscoree.dll
    2011-03-16 18:36 . 2009-11-25 11:47 320352 ----a-w- c:\windows\system32\PresentationHost.exe
    2011-03-16 18:36 . 2009-11-25 11:47 1942856 ----a-w- c:\windows\system32\dfshim.dll
    2011-03-16 18:36 . 2010-02-23 08:16 294912 ----a-w- c:\windows\system32\browserchoice.exe
    2011-03-16 17:32 . 2011-03-16 17:32 -------- d-----w- c:\program files (x86)\VideoLAN
    2011-03-16 14:16 . 2010-12-18 06:11 714752 ----a-w- c:\windows\system32\kerberos.dll
    2011-03-16 14:15 . 2010-11-02 05:12 1837568 ----a-w- c:\windows\system32\d3d10warp.dll
    2011-03-16 14:14 . 2010-10-27 05:18 5510528 ----a-w- c:\windows\system32\ntoskrnl.exe
    2011-03-16 14:14 . 2010-10-27 05:16 1739176 ----a-w- c:\windows\system32\ntdll.dll
    2011-03-16 14:14 . 2010-10-27 04:43 3901824 ----a-w- c:\windows\SysWow64\ntoskrnl.exe
    2011-03-16 14:14 . 2010-10-27 04:43 3957120 ----a-w- c:\windows\SysWow64\ntkrnlpa.exe
    2011-03-16 14:14 . 2010-10-27 04:40 1293120 ----a-w- c:\windows\SysWow64\ntdll.dll
    2011-03-16 14:14 . 2011-01-07 08:06 46080 ----a-w- c:\windows\system32\atmlib.dll
    2011-03-16 14:14 . 2011-01-07 07:27 34304 ----a-w- c:\windows\SysWow64\atmlib.dll
    2011-03-16 14:14 . 2011-01-07 05:49 366080 ----a-w- c:\windows\system32\atmfd.dll
    2011-03-16 14:14 . 2011-01-07 05:33 294400 ----a-w- c:\windows\SysWow64\atmfd.dll
    2011-03-16 14:12 . 2010-12-23 06:07 961024 ----a-w- c:\windows\system32\CPFilters.dll
    2011-03-16 14:12 . 2010-12-23 06:07 723968 ----a-w- c:\windows\system32\EncDec.dll
    2011-03-16 14:12 . 2010-12-23 05:28 642048 ----a-w- c:\windows\SysWow64\CPFilters.dll
    2011-03-16 14:12 . 2010-12-23 05:28 534528 ----a-w- c:\windows\SysWow64\EncDec.dll
    2011-03-16 14:12 . 2010-12-23 06:07 1118720 ----a-w- c:\windows\system32\sbe.dll
    2011-03-16 14:12 . 2010-12-23 06:02 259072 ----a-w- c:\windows\system32\mpg2splt.ax
    2011-03-16 14:12 . 2010-12-23 05:28 850432 ----a-w- c:\windows\SysWow64\sbe.dll
    2011-03-16 14:12 . 2010-12-23 05:24 199680 ----a-w- c:\windows\SysWow64\mpg2splt.ax
    2011-03-16 14:12 . 2010-10-19 08:47 7680 ----a-w- c:\program files\Internet Explorer\iecompat.dll
    2011-03-16 14:12 . 2010-10-19 08:10 7680 ----a-w- c:\program files (x86)\Internet Explorer\iecompat.dll
    2011-03-16 14:11 . 2010-10-16 05:17 720896 ----a-w- c:\windows\system32\odbc32.dll
    2011-03-16 14:11 . 2010-10-16 05:16 495616 ----a-w- c:\program files\Common Files\System\ado\msadox.dll
    2011-03-16 14:11 . 2010-10-16 05:16 466944 ----a-w- c:\program files\Common Files\System\ado\msadomd.dll
    2011-03-16 14:11 . 2010-10-16 05:16 1425408 ----a-w- c:\program files\Common Files\System\ado\msado15.dll
    2011-03-16 14:11 . 2010-10-16 04:34 573440 ----a-w- c:\windows\SysWow64\odbc32.dll
    2011-03-16 14:11 . 2010-10-16 05:16 258048 ----a-w- c:\program files\Common Files\System\msadc\msadco.dll
    2011-03-16 14:11 . 2010-10-16 04:33 372736 ----a-w- c:\program files (x86)\Common Files\System\ado\msadox.dll
    2011-03-16 14:11 . 2010-10-16 04:33 352256 ----a-w- c:\program files (x86)\Common Files\System\ado\msadomd.dll
    2011-03-16 14:11 . 2010-10-16 04:33 987136 ----a-w- c:\program files (x86)\Common Files\System\ado\msado15.dll
    2011-03-16 14:11 . 2010-10-16 04:33 208896 ----a-w- c:\program files (x86)\Common Files\System\msadc\msadco.dll
    2011-03-16 14:10 . 2011-01-05 04:00 3127808 ----a-w- c:\windows\system32\win32k.sys
    2011-03-16 14:09 . 2004-08-04 02:56 431616 ----a-w- c:\windows\SysWow64\temp.000
    2011-03-16 14:09 . 2000-05-21 23:00 203976 ----a-w- c:\windows\SysWow64\RICHTX32.OCX
    2011-03-16 14:09 . 2011-03-16 14:09 -------- d-----w- c:\programdata\KLC
    2011-03-16 14:09 . 1999-12-07 06:00 61491 ----a-w- c:\windows\SysWow64\wbemdisp.TLB
    2011-03-16 14:02 . 2011-01-07 08:07 662528 ----a-w- c:\windows\system32\XpsPrint.dll
    2011-03-16 14:02 . 2011-01-07 08:07 475648 ----a-w- c:\windows\system32\XpsGdiConverter.dll
    2011-03-16 14:02 . 2011-01-07 07:31 442880 ----a-w- c:\windows\SysWow64\XpsPrint.dll
    2011-03-16 14:02 . 2011-01-07 07:31 288256 ----a-w- c:\windows\SysWow64\XpsGdiConverter.dll
    2011-03-16 14:01 . 2010-08-21 06:29 558592 ----a-w- c:\windows\system32\spoolsv.exe
    2011-03-16 13:54 . 2010-12-21 06:16 214016 ----a-w- c:\windows\system32\winsrv.dll
    2011-03-16 13:47 . 2010-10-16 05:19 395776 ----a-w- c:\windows\system32\webio.dll
    2011-03-16 13:47 . 2010-10-16 04:36 314368 ----a-w- c:\windows\SysWow64\webio.dll
    2011-03-16 13:44 . 2009-09-26 06:20 223448 ----a-w- c:\windows\system32\drivers\fvevol.sys
    2011-03-16 13:10 . 2010-10-12 05:05 35328 ----a-w- c:\program files\Windows Mail\wabfind.dll
    2011-03-16 13:10 . 2010-10-12 05:00 516096 ----a-w- c:\program files\Windows Mail\wab.exe
    2011-03-16 13:10 . 2010-10-12 04:25 516096 ----a-w- c:\program files (x86)\Windows Mail\wab.exe
    2011-03-16 13:04 . 2010-07-13 05:37 27008 ----a-w- c:\windows\system32\drivers\Diskdump.sys
    2011-03-16 12:33 . 2010-12-18 06:12 3138048 ----a-w- c:\windows\system32\mstscax.dll
    2011-03-16 12:33 . 2010-12-18 06:08 1097216 ----a-w- c:\windows\system32\mstsc.exe
    2011-03-16 12:33 . 2010-12-18 05:30 2690560 ----a-w- c:\windows\SysWow64\mstscax.dll
    2011-03-16 12:33 . 2010-12-18 05:26 1034240 ----a-w- c:\windows\SysWow64\mstsc.exe
    2011-03-16 12:32 . 2010-10-16 05:23 112000 ----a-w- c:\windows\system32\consent.exe
    2011-03-16 12:27 . 2011-03-16 12:27 -------- d-----w- c:\programdata\Guitar Pro 6
    2011-03-16 11:09 . 2011-03-16 11:10 -------- d-----w- c:\program files (x86)\WildTangent Games
    2011-03-15 19:09 . 2011-03-27 09:30 -------- d-----w- c:\program files (x86)\uTorrent
    2011-03-15 18:54 . 2011-03-15 18:54 -------- dc----w- c:\windows\system32\DRVSTORE
    2011-03-15 18:54 . 2009-05-18 12:17 34152 ----a-w- c:\windows\system32\drivers\GEARAspiWDM.sys
    2011-03-15 18:54 . 2008-04-17 11:12 126312 ----a-w- c:\windows\system32\GEARAspi64.dll
    2011-03-15 18:54 . 2008-04-17 11:12 107368 ----a-w- c:\windows\SysWow64\GEARAspi.dll
    2011-03-15 18:52 . 2011-03-15 18:52 -------- d-----w- c:\program files\Bonjour
    2011-03-15 18:52 . 2011-03-15 18:52 -------- d-----w- c:\program files (x86)\Bonjour
    2011-03-15 18:52 . 2011-03-15 19:04 -------- d-----w- c:\programdata\Apple
    2011-03-15 18:52 . 2011-03-15 18:53 -------- d-----w- c:\program files (x86)\Common Files\Apple
    2011-03-15 12:55 . 2011-03-15 12:55 -------- d-----w- c:\program files (x86)\RocketDock
    2011-03-15 12:54 . 2011-03-15 12:54 -------- d-----w- c:\programdata\Avira
    2011-03-15 12:54 . 2011-03-15 12:54 -------- d-----w- c:\program files (x86)\Avira
    .
    .
    (((((((((((((((((((((((((((((((((( Compte-rendu de Find3M ))))))))))))))))))))))))))))))))))))))))))))))))
    .
    2011-04-06 11:09 . 2011-04-06 11:09 988715 ----a-w- C:\UsbFix_Upload_Me_PC-DE-GEOFFREY.zip
    2011-03-29 17:17 . 2010-06-24 10:33 18328 ----a-w- c:\programdata\Microsoft\IdentityCRL\production\ppcrlconfig600.dll
    2011-02-18 15:36 . 2011-02-18 15:36 51712 ----a-w- c:\windows\system32\drivers\usbaapl64.sys
    2011-02-18 15:36 . 2011-02-18 15:36 4184352 ----a-w- c:\windows\system32\usbaaplrc.dll
    .
    .
    ((((((((((((((((((((((((((((((((( Points de chargement Reg ))))))))))))))))))))))))))))))))))))))))))))))))
    .
    .
    *Note* les éléments vides & les éléments initiaux légitimes ne sont pas listés
    REGEDIT4
    .
    [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
    "RocketDock"="c:\program files (x86)\RocketDock\RocketDock.exe" [2007-09-02 495616]
    .
    [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run]
    "Adobe Reader Speed Launcher"="c:\program files (x86)\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2010-09-23 35760]
    "Adobe ARM"="c:\program files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2010-09-20 932288]
    "NBAgent"="c:\program files (x86)\Nero\Nero 10\Nero BackItUp\NBAgent.exe" [2010-09-02 1234216]
    "StartCCC"="c:\program files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" [2010-04-26 102400]
    "ToshibaServiceStation"="c:\program files (x86)\TOSHIBA\TOSHIBA Service Station\ToshibaServiceStation.exe" [2009-10-06 1294136]
    "TWebCamera"="c:\program files (x86)\TOSHIBA\TOSHIBA Web Camera Application\TWebCamera.exe" [2010-02-24 2454840]
    "avgnt"="c:\program files (x86)\Avira\AntiVir Desktop\avgnt.exe" [2011-02-04 281768]
    "QuickTime Task"="c:\program files (x86)\QuickTime\QTTask.exe" [2010-11-29 421888]
    "iTunesHelper"="c:\program files (x86)\iTunes\iTunesHelper.exe" [2011-03-07 421160]
    "IJNetworkScanUtility"="c:\program files (x86)\Canon\Canon IJ Network Scan Utility\CNMNSUT.EXE" [2007-11-19 128352]
    .
    [HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
    "TOSHIBA Online Product Information"="c:\program files (x86)\TOSHIBA\TOSHIBA Online Product Information\topi.exe" [2010-03-03 4581280]
    .
    c:\users\Geoffrey\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\
    OneNote 2010 - Capture d''cran et lancement.lnk - c:\program files\Microsoft Office\Office14\ONENOTEM.EXE [2010-3-29 245120]
    .
    c:\users\Default User\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\
    TRDCReminder.lnk - c:\program files (x86)\TOSHIBA\TRDCReminder\TRDCReminder.exe [2009-9-1 481184]
    .
    [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
    "ConsentPromptBehaviorAdmin"= 0 (0x0)
    "ConsentPromptBehaviorUser"= 3 (0x3)
    "EnableLUA"= 0 (0x0)
    "EnableUIADesktopToggle"= 0 (0x0)
    "PromptOnSecureDesktop"= 0 (0x0)
    "EnableLinkedConnections"= 1 (0x1)
    .
    [HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\system]
    "EnableLUA"= 0 (0x0)
    .
    [HKEY_LOCAL_MACHINE\system\currentcontrolset\control\lsa]
    Security Packages REG_MULTI_SZ kerberos msv1_0 schannel wdigest tspkg pku2u livessp
    .
    [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MCODS]
    @=""
    .
    R2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;c:\windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-03-18 130384]
    R2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;c:\windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [2010-03-18 138576]
    R3 GamesAppService;GamesAppService;c:\program files (x86)\WildTangent Games\App\GamesAppService.exe [2010-10-12 206072]
    R3 Microsoft SharePoint Workspace Audit Service;Microsoft SharePoint Workspace Audit Service;c:\program files\Microsoft Office\Office14\GROOVE.EXE [2010-03-25 51456888]
    R3 ose64;Office 64 Source Engine;c:\program files\Common Files\Microsoft Shared\Source Engine\OSE.EXE [2010-01-09 174440]
    R3 osppsvc;Office Software Protection Platform;c:\program files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPSVC.EXE [2010-01-09 4925184]
    R3 RSUSBSTOR;RtsUStor.Sys Realtek USB Card Reader;c:\windows\System32\Drivers\RtsUStor.sys [x]
    R3 USBAAPL64;Apple Mobile USB Driver;c:\windows\system32\Drivers\usbaapl64.sys [x]
    R3 WatAdminSvc;Service Windows Activation Technologies;c:\windows\system32\Wat\WatAdminSvc.exe [x]
    R4 wlcrasvc;Windows Live Mesh remote connections service;c:\program files\Windows Live\Mesh\wlcrasvc.exe [2010-09-22 57184]
    S1 dtsoftbus01;DAEMON Tools Virtual Bus Driver;c:\windows\system32\DRIVERS\dtsoftbus01.sys [x]
    S1 vwififlt;Virtual WiFi Filter Driver;c:\windows\system32\DRIVERS\vwififlt.sys [x]
    S2 AMD External Events Utility;AMD External Events Utility;c:\windows\system32\atiesrxx.exe [x]
    S2 AntiVirSchedulerService;Avira AntiVir Planificateur;c:\program files (x86)\Avira\AntiVir Desktop\sched.exe [2011-02-04 135336]
    S2 cfWiMAXService;ConfigFree WiMAX Service;c:\program files (x86)\TOSHIBA\ConfigFree\CFIWmxSvcs64.exe [2010-01-28 249200]
    S2 ConfigFree Service;ConfigFree Service;c:\program files (x86)\TOSHIBA\ConfigFree\CFSvcs.exe [2009-03-10 46448]
    S2 NAUpdate;Nero Update;c:\program files (x86)\Nero\Update\NASvc.exe [2010-05-04 503080]
    S2 TeamViewer6;TeamViewer 6;c:\program files (x86)\TeamViewer\Version6\TeamViewer_Service.exe [2011-03-18 2271608]
    S2 TemproMonitoringService;Notebook Performance Tuning Service (TEMPRO);c:\program files (x86)\Toshiba TEMPRO\TemproSvc.exe [2010-05-11 124368]
    S2 TOSHIBA eco Utility Service;TOSHIBA eco Utility Service;c:\program files\TOSHIBA\TECO\TecoService.exe [2010-03-17 258928]
    S2 TVALZFL;TOSHIBA ACPI-Based Value Added Logical and General Purpose Device Filter Driver;c:\windows\system32\DRIVERS\TVALZFL.sys [x]
    S2 UNS;Intel(R) Management & Security Application User Notification Service;c:\program files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe [2010-03-03 2320920]
    S3 amdkmdag;amdkmdag;c:\windows\system32\DRIVERS\atikmdag.sys [x]
    S3 amdkmdap;amdkmdap;c:\windows\system32\DRIVERS\atikmpag.sys [x]
    S3 CnxtHdmiAudService;Conexant UAA HDMI Function Driver for High Definition Audio Service;c:\windows\system32\drivers\CHDMI64.sys [x]
    S3 FwLnk;FwLnk Driver;c:\windows\system32\DRIVERS\FwLnk.sys [x]
    S3 HECIx64;Intel(R) Management Engine Interface;c:\windows\system32\DRIVERS\HECIx64.sys [x]
    S3 Impcd;Impcd;c:\windows\system32\DRIVERS\Impcd.sys [x]
    S3 L1C;NDIS Miniport Driver for Atheros AR813x/AR815x PCI-E Ethernet Controller;c:\windows\system32\DRIVERS\L1C62x64.sys [x]
    S3 PGEffect;Pangu effect driver;c:\windows\system32\DRIVERS\pgeffect.sys [x]
    S3 rtl8192se;Realtek Wireless LAN 802.11n PCI-E NIC NT Driver;c:\windows\system32\DRIVERS\rtl8192se.sys [x]
    S3 TMachInfo;TMachInfo;c:\program files (x86)\TOSHIBA\TOSHIBA Service Station\TMachInfo.exe [2009-10-06 51512]
    S3 TOSHIBA HDD SSD Alert Service;TOSHIBA HDD SSD Alert Service;c:\program files\TOSHIBA\TOSHIBA HDD SSD Alert\TosSmartSrv.exe [2010-02-05 137560]
    S3 TPCHSrv;TPCH Service;c:\program files\TOSHIBA\TPHM\TPCHSrv.exe [2010-02-23 835952]
    .
    .
    .
    --------- x86-64 -----------
    .
    .
    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
    "TosSENotify"="c:\program files\TOSHIBA\TOSHIBA HDD SSD Alert\TosWaitSrv.exe" [2010-02-05 709976]
    "Toshiba TEMPRO"="c:\program files (x86)\Toshiba TEMPRO\TemproTray.exe" [2010-05-11 1050072]
    "SmartAudio"="c:\program files\CONEXANT\SAII\SAIICpl.exe" [2009-11-19 307768]
    "cAudioFilterAgent"="c:\program files\Conexant\cAudioFilterAgent\cAudioFilterAgent64.exe" [2010-03-22 521272]
    "TosVolRegulator"="c:\program files\TOSHIBA\TosVolRegulator\TosVolRegulator.exe" [2009-11-11 24376]
    "Toshiba Registration"="c:\program files\Toshiba\Registration\ToshibaReminder.exe" [2010-04-19 136136]
    "BCSSync"="c:\program files\Microsoft Office\Office14\BCSSync.exe" [2010-03-13 112512]
    "CanonSolutionMenu"="c:\program files (x86)\Canon\SolutionMenu\CNSLMAIN.exe" [2008-03-10 689488]
    "CanonMyPrinter"="c:\program files\Canon\MyPrinter\BJMyPrt.exe" [2008-03-17 2114376]
    .
    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows]
    "LoadAppInit_DLLs"=0x0
    .
    ------- Examen supplémentaire -------
    .
    uLocal Page = c:\windows\system32\blank.htm
    mLocal Page = c:\windows\SysWOW64\blank.htm
    uInternet Settings,ProxyOverride = *.local
    IE: &Envoyer à OneNote - c:\progra~1\MICROS~2\Office14\ONBttnIE.dll/105
    IE: E&xporter vers Microsoft Excel - c:\progra~1\MICROS~2\Office14\EXCEL.EXE/3000
    IE: Télécharger avec Mipony - file://c:\program files (x86)\MiPony\Browser\IEContext.htm
    Filter: text/xml - {807573E5-5146-11D5-A672-00B0D022E945} - c:\program files (x86)\Common Files\microsoft shared\OFFICE14\MSOXMLMF.DLL
    FF - ProfilePath - c:\users\Geoffrey\AppData\Roaming\Mozilla\Firefox\Profiles\aovxzhnh.default\
    FF - Ext: Default: {972ce4c6-7e08-4474-a285-3208198ce6fd} - c:\program files (x86)\Mozilla Firefox\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd}
    FF - Ext: Aero Fox XL: {5c8bfb7c-9a54-11dc-8314-0800200c9a66} - %profile%\extensions\{5c8bfb7c-9a54-11dc-8314-0800200c9a66}
    FF - Ext: Adblock Plus: {d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d} - %profile%\extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}
    .
    - - - - ORPHELINS SUPPRIMES - - - -
    .
    Toolbar-Locked - (no file)
    Toolbar-Locked - (no file)
    HKLM-Run-TosReelTimeMonitor - %ProgramFiles%\TOSHIBA\ReelTime\TosReelTimeMonitor.exe
    HKLM-Run-TosNC - %ProgramFiles%\Toshiba\BulletinBoard\TosNcCore.exe
    HKLM-Run-SynTPEnh - %ProgramFiles%\Synaptics\SynTP\SynTPEnh.exe
    HKLM-Run-TPwrMain - %ProgramFiles%\TOSHIBA\Power Saver\TPwrMain.EXE
    HKLM-Run-HSON - %ProgramFiles%\TOSHIBA\TBS\HSON.exe
    HKLM-Run-SmoothView - %ProgramFiles%\Toshiba\SmoothView\SmoothView.exe
    HKLM-Run-00TCrdMain - %ProgramFiles%\TOSHIBA\FlashCards\TCrdMain.exe
    HKLM-Run-SmartFaceVWatcher - %ProgramFiles%\Toshiba\SmartFaceV\SmartFaceVWatcher.exe
    HKLM-Run-Teco - %ProgramFiles%\TOSHIBA\TECO\Teco.exe
    HKLM-Run-TosWaitSrv - %ProgramFiles%\TOSHIBA\TPHM\TosWaitSrv.exe
    .
    .
    .
    --------------------- CLES DE REGISTRE BLOQUEES ---------------------
    .
    [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{19114156-8E9A-4D4E-9EE9-17A0E48D3BBB}]
    @Denied: (A 2) (Everyone)
    @="FlashBroker"
    "LocalizedString"="@c:\\Windows\\system32\\Macromed\\Flash\\FlashUtil10e.exe,-101"
    .
    [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{19114156-8E9A-4D4E-9EE9-17A0E48D3BBB}\Elevation]
    "Enabled"=dword:00000001
    .
    [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{19114156-8E9A-4D4E-9EE9-17A0E48D3BBB}\LocalServer32]
    @="c:\\Windows\\SysWow64\\Macromed\\Flash\\FlashUtil10e.exe"
    .
    [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{19114156-8E9A-4D4E-9EE9-17A0E48D3BBB}\TypeLib]
    @="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
    .
    [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}]
    @Denied: (A 2) (Everyone)
    @="Shockwave Flash Object"
    .
    [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\InprocServer32]
    @="c:\\Windows\\SysWow64\\Macromed\\Flash\\Flash10e.ocx"
    "ThreadingModel"="Apartment"
    .
    [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\MiscStatus]
    @="0"
    .
    [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ProgID]
    @="ShockwaveFlash.ShockwaveFlash.10"
    .
    [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32]
    @="c:\\Windows\\SysWow64\\Macromed\\Flash\\Flash10e.ocx, 1"
    .
    [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\TypeLib]
    @="{D27CDB6B-AE6D-11cf-96B8-444553540000}"
    .
    [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\Version]
    @="1.0"
    .
    [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID]
    @="ShockwaveFlash.ShockwaveFlash"
    .
    [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}]
    @Denied: (A 2) (Everyone)
    @="Macromedia Flash Factory Object"
    .
    [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\InprocServer32]
    @="c:\\Windows\\SysWow64\\Macromed\\Flash\\Flash10e.ocx"
    "ThreadingModel"="Apartment"
    .
    [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ProgID]
    @="FlashFactory.FlashFactory.1"
    .
    [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32]
    @="c:\\Windows\\SysWow64\\Macromed\\Flash\\Flash10e.ocx, 1"
    .
    [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\TypeLib]
    @="{D27CDB6B-AE6D-11cf-96B8-444553540000}"
    .
    [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\Version]
    @="1.0"
    .
    [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID]
    @="FlashFactory.FlashFactory"
    .
    [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{1D4C8A81-B7AC-460A-8C23-98713C41D6B3}]
    @Denied: (A 2) (Everyone)
    @="IFlashBroker3"
    .
    [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{1D4C8A81-B7AC-460A-8C23-98713C41D6B3}\ProxyStubClsid32]
    @="{00020424-0000-0000-C000-000000000046}"
    .
    [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{1D4C8A81-B7AC-460A-8C23-98713C41D6B3}\TypeLib]
    @="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
    "Version"="1.0"
    .
    [HKEY_LOCAL_MACHINE\SOFTWARE\McAfee]
    "SymbolicLinkValue"=hex(6):5c,00,72,00,65,00,67,00,69,00,73,00,74,00,72,00,79,
    00,5c,00,6d,00,61,00,63,00,68,00,69,00,6e,00,65,00,5c,00,53,00,6f,00,66,00,\
    .
    [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\PCW\Security]
    @Denied: (Full) (Everyone)
    .
    Heure de fin: 2011-04-06 17:13:59
    ComboFix-quarantined-files.txt 2011-04-06 15:13
    .
    Avant-CF: 208 580 046 848 octets libres
    Après-CF: 208 332 849 152 octets libres
    .
    - - End Of File - - 2B7CD9E495E647587B2D5BCEC3E12147
    0
  • 1
  • 2