Windows XP ne démarre plus => scan

Bonsoir,

J'ai posté ici hier soir :
http://www.commentcamarche.net/forum/affich-21552278-windows-xp-ne-demarre-plus

Après tentative de restauration système et test RAM, Skull-Shadow a eu la gentillesse de me suggérer ZHPDIag.

Voici donc le lien vers le rapport, que je me permets de copier aussi sur ce forum :
http://www.cijoint.fr/cjlink.php?file=cj201104/cijEDPsgUb.txt

Mille mercis d'avance si vous pouvez m'éclairer (car bien sûr pour moi c'est incompréhensible !)

ldelort

62 réponses

Résumé de la discussion

Problème récurrent : un système Windows XP ne démarre plus après une restauration et un test de RAM, ce qui pousse à solliciter des diagnostics externes comme ZHPDiag. Des échanges convergent vers l'utilisation de ZHPDiag, le rapport généré listant de nombreuses entrées système et pilotes, ce qui alerte sur d'éventuels éléments malveillants ou problématiques dans la configuration. Des pistes complémentaires évoquées incluent l'analyse du rapport ZHPFix et des conseils de sécurisation lors du passage à un nouvel ordinateur, certains participants soulignant des difficultés liées à l'absence de connexion en mode sans échec.

Bobot (l’IA à votre service)
  1. salut tu as plusieurs antivirus d'installés ca doit etre pour ca que ca beugue
    0
    1. Merci de ta réponse.

      J'ai plusieurs antivirus ???
      Lequel en plus d'avast ?

      McAfee Security Scan Plus est installé mais c'est juste un utilitaire de diagnostic.

      De plus, c'est récemment que mon PC a commencé à sérieusement patiner, et récemment je n'ai procéder à aucun changement niveau antivirus.

      Le rapport de ZHPDiag n'indique rien d'autre ?

      Je pense aussi lancer un scan via un autre utilitaire et copier ici le rapport.
      Multi Virus Cleaner est-il bon ?
      0
  2. non il vaut rien ne lance rien d'autre que ce que je te dirai

    sélectionne les lignes ci-dessous et copie les dans le Presse-papier (Ctrl C)

    M3 - MFPP: Plugins - [Sylvie] -- C:\Documents and Settings\Sylvie\Application Data\Mozilla\Firefox\Profiles\ejukew0j.default\searchplugins\hooseek.xml
    OPT:O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] . (.Adobe Systems Incorporated - Adobe Acrobat SpeedLauncher.) -- C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe
    OPT:O4 - HKLM\..\Run: [SunJavaUpdateSched] . (.Sun Microsystems, Inc. - Java Update Scheduler.) -- C:\Program Files\Fichiers communs\Java\Java Update\jusched.exe
    O42 - Logiciel: Java 6 Update 18 - (.Sun Microsystems, Inc..) [HKLM] -- {26A24AE4-039D-4CA4-87B4-2F83216018FF}
    [HKLM\Software\AFBARRE]
    O47 - AAKE:Key Export SP - "E:\data\eSKernel.exe" [Enabled] .(.Pas de propriétaire - Pas de description.) -- E:\data\eSKernel.exe (.not file.)
    O64 - Services: CurCS - (.not file.) - Kl1 (kl1) .(...) - LEGACY_KL1
    O64 - Services: CurCS - (.not file.) - Kaspersky Lab Boot Guard Driver (klbg) .(...) - LEGACY_KLBG
    O64 - Services: CurCS - (.not file.) - Kaspersky Lab Driver (KLIF) .(...) - LEGACY_KLIF


    Pour Xp : Double clique sur l'icône ZHPFix.exe sur ton Bureau.

    Pour Vista : Clique droit sur l'icône ZHPFix.exe sur ton Bureau,
    puis sélectionne 'Exécuter en tant qu'administrateur'.

    - Clique sur l'icone représentant la lettre H (« coller les lignes Helper »)
    - Les lignes se collent automatiquement dans ZHPFix, sinon colle les lignes
    - Clique sur le bouton « GO » pour lancer le nettoyage,
    - Copie/colle la totalité du rapport dans ta prochaine réponse
    0
    1. Rapport de ZHPFix 1.12.3274 par Nicolas Coolman, Update du 06/04/2011
      Fichier d'export Registre : C:\ZHPExportRegistry-08-04-2011-02-37-44.txt
      Run by Sylvie at 08/04/2011 02:37:44
      Windows XP Professional Service Pack 3 (Build 2600)
      Web site : http://www.premiumorange.com/zeb-help-process/zhpfix.html

      ========== Clé(s) du Registre ==========
      O42 - Logiciel: Java 6 Update 18 - (.Sun Microsystems, Inc..) [HKLM] -- {26A24AE4-039D-4CA4-87B4-2F83216018FF} => Clé supprimée avec succès
      HKLM\Software\AFBARRE => Clé supprimée avec succès
      O64 - Services: CurCS - (.not file.) - Kl1 (kl1) .(...) - LEGACY_KL1 => Clé supprimée avec succès
      O64 - Services: CurCS - (.not file.) - Kaspersky Lab Boot Guard Driver (klbg) .(...) - LEGACY_KLBG => Clé supprimée avec succès
      O64 - Services: CurCS - (.not file.) - Kaspersky Lab Driver (KLIF) .(...) - LEGACY_KLIF => Clé supprimée avec succès

      ========== Valeur(s) du Registre ==========
      O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] . (.Adobe Systems Incorporated - Adobe Acrobat SpeedLauncher.) -- C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe => Valeur supprimée avec succès
      O4 - HKLM\..\Run: [SunJavaUpdateSched] . (.Sun Microsystems, Inc. - Java Update Scheduler.) -- C:\Program Files\Fichiers communs\Java\Java Update\jusched.exe => Valeur supprimée avec succès
      O47 - AAKE:Key Export SP - "E:\data\eSKernel.exe" [Enabled] .(.) -- E:\data\eSKernel.exe (.not file.) => Valeur supprimée avec succès

      ========== Fichier(s) ==========
      c:\documents and settings\sylvie\application data\mozilla\firefox\profiles\ejukew0j.default\searchplugins\hooseek.xml => Supprimé et mis en quarantaine
      e:\data\eskernel.exe => Fichier absent

      ========== Récapitulatif ==========
      5 : Clé(s) du Registre
      3 : Valeur(s) du Registre
      2 : Fichier(s)

      End of the scan
      0
      1. ▶ Télécharge ici : USBFIX sur ton bureau

        branche tous tes periphériques sans les ouvrir

        /!\ Désactive provisoirement et seulement le temps de l'utilisation d'USBFIX, la protection en temps réel de ton Antivirus et de tes Antispywares, qui peuvent gêner fortement la procédure de recherche et de nettoyage de l'outil.

        si tu as XP => double clique
        si tu as Vista ou windows 7 => clic droit "executer en tant que...."


        sur l'icône Usbfix située sur ton Bureau.
        Sur la page, clique sur le bouton :

        ▶ choisi l option Suppression

        ▶ UsbFix scannera ton pc , laisse travailler l outil.

        ▶ Ensuite post le rapport UsbFix.txt qui apparaitra avec le bureau .

        ▶ Note : Le rapport UsbFix.txt est sauvegardé a la racine du disque.( C:\UsbFix.txt )

        ( CTRL+A Pour tout selectionner , CTRL+C pour copier et CTRL+V pour coller )

        0
        1. re maintenant que tu es inscrit tes posts passeront mieux

          ############################## | UsbFix 7.043 | [Suppression]

          Utilisateur: Sylvie (Administrateur) # SYLVIE-Q44LUXFR [ ]
          Mis à jour le 06/04/2011 par TeamXscript
          Lancé à 02:58:46 | 08/04/2011
          Site Web: http://www.teamxscript.org
          Submit your sample: http://www.teamxscript.org/Upload.php
          Contact: TeamXscript.ElDesaparecido@gmail.com

          CPU: Intel(R) Celeron(R) CPU 2.66GHz
          Microsoft Windows XP Professionnel (5.1.2600 32-Bit) # Service Pack 3
          Internet Explorer 8.0.6001.18702

          Antivirus: avast! Antivirus 5.0.100664296 [Enabled | Updated]
          RAM -> 1471 Mo
          C:\ (%systemdrive%) -> Disque fixe # 76 Go (37 Go libre(s) - 48%) [] # NTFS
          D:\ -> CD-ROM
          E:\ -> CD-ROM
          F:\ -> Disque amovible # 4 Go (4 Go libre(s) - 100%) [USB] # FAT32

          ################## | Éléments infectieux |

          Supprimé! C:\WINDOWS\Temp\sig4.tmp
          Supprimé! C:\WINDOWS\Temp\sig5.tmp
          Supprimé! C:\Recycler\S-1-5-21-1123561945-343818398-682003330-1003

          ################## | Registre |

          ################## | Mountpoints2 |

          ################## | Listing |

          [02/11/2009 - 21:07:44 | N | 1024] C:\.rnd
          [11/11/2009 - 15:13:34 | D ] C:\69e3a0c3dd8f62575206
          [29/12/2010 - 22:24:27 | N | 2006] C:\aqua_bitmap.cpp
          [02/11/2009 - 20:47:18 | N | 0] C:\AUTOEXEC.BAT
          [02/11/2009 - 21:35:02 | N | 212] C:\boot.ini
          [28/08/2001 - 14:00:00 | N | 4952] C:\Bootfont.bin
          [16/03/2011 - 02:02:51 | D ] C:\Config.Msi
          [02/11/2009 - 20:47:18 | N | 0] C:\CONFIG.SYS
          [03/11/2009 - 03:11:12 | D ] C:\daba99ca4641c6634a1714
          [02/11/2009 - 21:09:08 | D ] C:\Documents and Settings
          [02/11/2009 - 21:16:21 | D ] C:\I386
          [02/11/2009 - 20:47:18 | N | 0] C:\IO.SYS
          [02/11/2009 - 20:47:18 | N | 0] C:\MSDOS.SYS
          [02/11/2009 - 21:28:56 | N | 47564] C:\NTDETECT.COM
          [03/11/2009 - 02:16:06 | N | 252240] C:\ntldr
          [08/04/2011 - 00:31:36 | ASH | 704643072] C:\pagefile.sys
          [08/04/2011 - 00:55:21 | N | 512] C:\PhysicalDisk0_MBR.bin
          [08/04/2011 - 02:32:41 | D ] C:\Program Files
          [08/04/2011 - 03:00:36 | SHD ] C:\RECYCLER
          [03/11/2009 - 19:49:37 | SHD ] C:\System Volume Information
          [08/04/2011 - 03:00:36 | D ] C:\UsbFix
          [08/04/2011 - 03:00:36 | A | 972] C:\UsbFix.txt
          [07/04/2011 - 20:40:09 | D ] C:\WINDOWS
          [08/04/2011 - 02:37:44 | N | 13950] C:\ZHPExportRegistry-08-04-2011-02-37-44.txt
          [21/01/2011 - 13:29:54 | D ] F:\Administratif
          [07/04/2011 - 22:57:44 | D ] F:\Animo
          [21/01/2011 - 13:30:06 | D ] F:\CV + LM

          ################## | Vaccin |

          C:\Autorun.inf -> Vaccin créé par UsbFix (TeamXscript)
          F:\Autorun.inf -> Vaccin créé par UsbFix (TeamXscript)

          ################## | Upload |

          Veuillez envoyer le fichier: C:\UsbFix_Upload_Me_SYLVIE-Q44LUXFR.zip
          http://www.teamxscript.org/Upload.php
          Merci de votre contribution.

          ################## | E.O.F |
          0
          1. Merci beaucoup de ton aide gen-hackman.
            Je n'arrivais plus à poster sur ce sujet (me demande un titre ??) alos je me suis permise un mp mais même pas sûre qu'il ait été envoyé.

            Je tente à nouveau de copier le rapport d'UsbFix :

            ############################## | UsbFix 7.043 | [Suppression]

            Utilisateur: Sylvie (Administrateur) # SYLVIE-Q44LUXFR [ ]
            Mis à jour le 06/04/2011 par TeamXscript
            Lancé à 02:58:46 | 08/04/2011
            Site Web: http://www.teamxscript.org
            Submit your sample: http://www.teamxscript.org/Upload.php
            Contact: TeamXscript.ElDesaparecido@gmail.com

            CPU: Intel(R) Celeron(R) CPU 2.66GHz
            Microsoft Windows XP Professionnel (5.1.2600 32-Bit) # Service Pack 3
            Internet Explorer 8.0.6001.18702

            Antivirus: avast! Antivirus 5.0.100664296 [Enabled | Updated]
            RAM -> 1471 Mo
            C:\ (%systemdrive%) -> Disque fixe # 76 Go (37 Go libre(s) - 48%) [] # NTFS
            D:\ -> CD-ROM
            E:\ -> CD-ROM
            F:\ -> Disque amovible # 4 Go (4 Go libre(s) - 100%) [USB] # FAT32

            ################## | Éléments infectieux |

            Supprimé! C:\WINDOWS\Temp\sig4.tmp
            Supprimé! C:\WINDOWS\Temp\sig5.tmp
            Supprimé! C:\Recycler\S-1-5-21-1123561945-343818398-682003330-1003

            ################## | Registre |

            ################## | Mountpoints2 |

            ################## | Listing |

            [02/11/2009 - 21:07:44 | N | 1024] C:\.rnd
            [11/11/2009 - 15:13:34 | D ] C:\69e3a0c3dd8f62575206
            [29/12/2010 - 22:24:27 | N | 2006] C:\aqua_bitmap.cpp
            [02/11/2009 - 20:47:18 | N | 0] C:\AUTOEXEC.BAT
            [02/11/2009 - 21:35:02 | N | 212] C:\boot.ini
            [28/08/2001 - 14:00:00 | N | 4952] C:\Bootfont.bin
            [16/03/2011 - 02:02:51 | D ] C:\Config.Msi
            [02/11/2009 - 20:47:18 | N | 0] C:\CONFIG.SYS
            [03/11/2009 - 03:11:12 | D ] C:\daba99ca4641c6634a1714
            [02/11/2009 - 21:09:08 | D ] C:\Documents and Settings
            [02/11/2009 - 21:16:21 | D ] C:\I386
            [02/11/2009 - 20:47:18 | N | 0] C:\IO.SYS
            [02/11/2009 - 20:47:18 | N | 0] C:\MSDOS.SYS
            [02/11/2009 - 21:28:56 | N | 47564] C:\NTDETECT.COM
            [03/11/2009 - 02:16:06 | N | 252240] C:\ntldr
            [08/04/2011 - 00:31:36 | ASH | 704643072] C:\pagefile.sys
            [08/04/2011 - 00:55:21 | N | 512] C:\PhysicalDisk0_MBR.bin
            [08/04/2011 - 02:32:41 | D ] C:\Program Files
            [08/04/2011 - 03:00:36 | SHD ] C:\RECYCLER
            [03/11/2009 - 19:49:37 | SHD ] C:\System Volume Information
            [08/04/2011 - 03:00:36 | D ] C:\UsbFix
            [08/04/2011 - 03:00:36 | A | 972] C:\UsbFix.txt
            [07/04/2011 - 20:40:09 | D ] C:\WINDOWS
            [08/04/2011 - 02:37:44 | N | 13950] C:\ZHPExportRegistry-08-04-2011-02-37-44.txt
            [21/01/2011 - 13:29:54 | D ] F:\Administratif
            [07/04/2011 - 22:57:44 | D ] F:\Animo
            [21/01/2011 - 13:30:06 | D ] F:\CV + LM

            ################## | Vaccin |

            C:\Autorun.inf -> Vaccin créé par UsbFix (TeamXscript)
            F:\Autorun.inf -> Vaccin créé par UsbFix (TeamXscript)

            ################## | Upload |

            Veuillez envoyer le fichier: C:\UsbFix_Upload_Me_SYLVIE-Q44LUXFR.zip
            http://www.teamxscript.org/Upload.php
            Merci de votre contribution.

            ################## | E.O.F |
            0
            1. ▶ Télécharge TDSSKiller

              ▶ Lance le ( Utilisateurs de vista/Seven -> Clic droit puis " Exécuter en tant que........... " )

              L'outil va télécharger automatiquement la dernière version de TDSSKiller puis lancera une analyse.

              Patiente pendant le scan. A la fin de l'analyse, appuies sur une touche. Un rapport va s'ouvrir.

              ▶ Copie/Colle son contenu dans ta prochaine réponse.

              Note : Le rapport se trouve également sous C:\tdsskiller.txt.
              0
              1. Je n'arrive pas à le lancer.

                J'ai le message d'erreur qui commence par "Windows ne trouve pas 'C:\tdsskiller\tdsskiller.exe'..."
                0
            2. desactive tes protections puis enregistre ceci sur ton bureau

              Pre_Scan

              si l'outil detecte un proxy et que tu n'en as pas installé clique sur "supprimer le proxy"

              une fois telechargé lance-le , laisse faire le scan puis colle le contenu de " rapport.txt" qui apparaitra à son terme , sur le bureau.
              0
              1. ¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤ Pre_Scan 1.0.0.20 ¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤

                ¤ XP | Vista | Seven - 32/64 ¤

                Mis à jour le 08/04/2011 | 02.35 par g3n-h@ckm@n
                Utilisateur : Sylvie (Administrateurs)
                Ordinateur : SYLVIE-Q44LUXFR

                Système d'exploitation : Microsoft Windows XP (32 bits)
                Architecture OS : X86
                Internet Explorer : 8.0.6001.18702
                Mozilla Firefox : 4.0 (fr)

                Scan : 04:06:12 | 08/04/2011

                ¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤

                [HKLM\..\..\Winlogon] | Shell -> Aucune modification : Explorer.exe -> Explorer.exe
                [HKLM\..\..\Winlogon] | AutoRestartShell -> Aucune modification : 1 -> 1
                [HKLM\..\..\Winlogon] | userinit -> Aucune modification : C:\WINDOWS\system32\Userinit.exe, -> C:\WINDOWS\system32\Userinit.exe,
                [HKLM\..\..\Winlogon] | PowerDownAfterShutdown -> Modification apportée : 0 -> 1

                ¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤ Associations ¤¤¤¤¤¤¤¤¤¤¤¤¤¤

                [exefile | command] : "%1" %*
                [comfile | command] : "%1" %*
                [scrfile | command] : "%1" /S
                [batfile | command] : "%1" %*
                [piffile | command] : "%1" %*
                [Firefox | Command] | @ -> Modification apportée : C:\Program Files\Mozilla Firefox\firefox.exe -> "C:\Program Files\Mozilla Firefox\Firefox.exe"
                [Firefox - Safemode | Command] | @ -> Aucune modification : "C:\Program Files\Mozilla Firefox\firefox.exe" -safe-mode -> "C:\Program Files\Mozilla Firefox\firefox.exe" -safe-mode
                [IE | Command] | @ -> Modification apportée : C:\Program Files\Internet Explorer\iexplore.exe -> "C:\Program Files\Internet Explorer\iexplore.exe"
                [Applications | IE | Command] | @ -> Aucune modification : "C:\Program Files\Internet Explorer\IEXPLORE.EXE" %1 -> "C:\Program Files\Internet Explorer\IEXPLORE.EXE" %1

                ¤¤¤¤¤¤¤¤¤¤ Services ¤¤¤¤¤¤¤¤¤¤

                [Ndisuio] | Start -> Aucune modification : 3 -> 3
                [ERSvc] | Start -> Aucune modification : 2 -> 2
                [Bits] | Start -> Modification apportée : 3 -> 2
                [EapHost] | Start -> Modification apportée : 3 -> 2
                [SharedAccess] | Start -> Aucune modification : 2 -> 2
                [wuauserv] | Start -> Aucune modification : 2 -> 2
                [wscsvc] | Start -> Aucune modification : 2 -> 2
                [wzcsvc] | Start -> Aucune modification : 2 -> 2

                ¤¤¤¤¤¤¤¤¤¤ Internet Explorer ¤¤¤¤¤¤¤¤¤¤

                [HKCU | Main] | Start Page -> Modification apportée : https://www.msn.com/fr-fr -> https://www.google.com/?gws_rd=ssl
                [HKCU | Main] | Local Page -> Aucune Modification : C:\WINDOWS\system32\blank.htm -> C:\WINDOWS\system32\blank.htm
                [HKCU | Main] | Search Page -> Modification apportée : https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF -> http://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch

                [HKLM | Main] | Start Page -> Modification apportée : https://www.msn.com/fr-fr -> https://www.msn.com/fr-fr/?ocid=iehp
                [HKLM | Main] | Local Page -> Aucune Modification : C:\WINDOWS\system32\blank.htm -> C:\WINDOWS\system32\blank.htm
                [HKLM | Main] | Default_Search_URL -> Modification apportée : http://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch -> https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
                [HKLM | Main] | Default_Page_URL -> Modification apportée : http://www.microsoft.com/isapi/redir.dll?prd=ie&pver=6&ar=msnhome -> https://www.msn.com/fr-fr/?ocid=iehp
                [HKLM | Main] | Search Page -> Aucune Modification : https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF -> https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF

                ¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤ Processus ¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤

                explorer.exe -> Processus stoppé

                ¤¤¤¤¤¤¤¤¤¤ Clés supprimées et Fichier mis en quarantaine ¤¤¤¤¤¤¤¤¤¤

                ¤¤¤¤¤¤¤¤¤¤ IFEO ¤¤¤¤¤¤¤¤¤¤

                ¤¤¤¤¤¤¤¤¤¤ Mountpoints2 ¤¤¤¤¤¤¤¤¤¤

                ¤¤¤¤¤¤¤¤¤¤ MBR ¤¤¤¤¤¤¤¤¤¤

                MBRCheck, version 1.2.3

                (c) 2010, AD

                Command-line: -za C:\MBR\MBR.bin

                Windows Version: Windows XP Professional

                Windows Information: Service Pack 3 (build 2600)

                Logical Drives Mask: 0x0000003d

                Analysis of file "C:\MBR\MBR.bin":

                Windows XP MBR code detected

                Done!
                ¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤

                explorer.exe -> Processus redémarré

                Fin : 04:06:14

                ¤¤¤¤¤¤¤¤¤¤( EOF )¤¤¤¤¤¤¤¤¤¤
                0
            3. ok reessaie tdsskiller en desactivant tes protections.
              0
              1. Je n'ai pas réussi via ton lien, j'ai été chercher tdsskiller sur le site de Kaspersky.
                Copie du rapport :

                2011/04/08 04:32:51.0453 1624 TDSS rootkit removing tool 2.4.21.0 Mar 10 2011 12:26:28
                2011/04/08 04:32:51.0515 1624 ================================================================================
                2011/04/08 04:32:51.0515 1624 SystemInfo:
                2011/04/08 04:32:51.0515 1624
                2011/04/08 04:32:51.0515 1624 OS Version: 5.1.2600 ServicePack: 3.0
                2011/04/08 04:32:51.0515 1624 Product type: Workstation
                2011/04/08 04:32:51.0515 1624 ComputerName: SYLVIE-Q44LUXFR
                2011/04/08 04:32:51.0515 1624 UserName: Sylvie
                2011/04/08 04:32:51.0515 1624 Windows directory: C:\WINDOWS
                2011/04/08 04:32:51.0515 1624 System windows directory: C:\WINDOWS
                2011/04/08 04:32:51.0515 1624 Processor architecture: Intel x86
                2011/04/08 04:32:51.0515 1624 Number of processors: 1
                2011/04/08 04:32:51.0515 1624 Page size: 0x1000
                2011/04/08 04:32:51.0515 1624 Boot type: Safe boot
                2011/04/08 04:32:51.0515 1624 ================================================================================
                2011/04/08 04:32:52.0062 1624 Initialize success
                2011/04/08 04:33:23.0671 1696 ================================================================================
                2011/04/08 04:33:23.0671 1696 Scan started
                2011/04/08 04:33:23.0671 1696 Mode: Manual;
                2011/04/08 04:33:23.0671 1696 ================================================================================
                2011/04/08 04:33:28.0328 1696 Aavmker4 (83631291adf2887cffc786d034d3fa15) C:\WINDOWS\system32\drivers\Aavmker4.sys
                2011/04/08 04:33:29.0796 1696 ACPI (e5e6dbfc41ea8aad005cb9a57a96b43b) C:\WINDOWS\system32\DRIVERS\ACPI.sys
                2011/04/08 04:33:30.0343 1696 ACPIEC (e4abc1212b70bb03d35e60681c447210) C:\WINDOWS\system32\drivers\ACPIEC.sys
                2011/04/08 04:33:31.0234 1696 aeaudio (11c04b17ed2abbb4833694bcd644ac90) C:\WINDOWS\system32\drivers\aeaudio.sys
                2011/04/08 04:33:31.0828 1696 aec (8bed39e3c35d6a489438b8141717a557) C:\WINDOWS\system32\drivers\aec.sys
                2011/04/08 04:33:32.0484 1696 AFD (7e775010ef291da96ad17ca4b17137d7) C:\WINDOWS\System32\drivers\afd.sys
                2011/04/08 04:33:36.0484 1696 aswFsBlk (1c2e6bb4fe8621b1b863855b02bc33eb) C:\WINDOWS\system32\drivers\aswFsBlk.sys
                2011/04/08 04:33:37.0078 1696 aswMon2 (452d0ecd14fa02f9b061f42c8a30dd49) C:\WINDOWS\system32\drivers\aswMon2.sys
                2011/04/08 04:33:37.0656 1696 aswRdr (b6a9373619d851be80fb5f1b5eed0d4e) C:\WINDOWS\system32\drivers\aswRdr.sys
                2011/04/08 04:33:38.0437 1696 aswSnx (9be41c1ae8bc481eb662d85c98d979c2) C:\WINDOWS\system32\drivers\aswSnx.sys
                2011/04/08 04:33:39.0312 1696 aswSP (4b1a54ba2bc5873a774df6b70ab8b0b3) C:\WINDOWS\system32\drivers\aswSP.sys
                2011/04/08 04:33:40.0000 1696 aswTdi (c7f1cea32766184911293f4e1ee653f5) C:\WINDOWS\system32\drivers\aswTdi.sys
                2011/04/08 04:33:40.0531 1696 AsyncMac (b153affac761e7f5fcfa822b9c4e97bc) C:\WINDOWS\system32\DRIVERS\asyncmac.sys
                2011/04/08 04:33:41.0125 1696 atapi (9f3a2f5aa6875c72bf062c712cfa2674) C:\WINDOWS\system32\DRIVERS\atapi.sys
                2011/04/08 04:33:42.0484 1696 ati2mtag (e82021ab2021a618199709af5da58074) C:\WINDOWS\system32\DRIVERS\ati2mtag.sys
                2011/04/08 04:33:43.0359 1696 Atmarpc (9916c1225104ba14794209cfa8012159) C:\WINDOWS\system32\DRIVERS\atmarpc.sys
                2011/04/08 04:33:43.0937 1696 audstub (d9f724aa26c010a217c97606b160ed68) C:\WINDOWS\system32\DRIVERS\audstub.sys
                2011/04/08 04:33:44.0515 1696 basic2 (1b9c81ab9a456eabd9f8335f04b5f495) C:\WINDOWS\system32\DRIVERS\HSF_BSC2.sys
                2011/04/08 04:33:45.0031 1696 Beep (da1f27d85e0d1525f6621372e7b685e9) C:\WINDOWS\system32\drivers\Beep.sys
                2011/04/08 04:33:45.0562 1696 caboagp (10d5fb74ee18ea49c30daaa203c0e0ec) C:\WINDOWS\system32\DRIVERS\atisgkaf.sys
                2011/04/08 04:33:46.0093 1696 cbidf2k (90a673fc8e12a79afbed2576f6a7aaf9) C:\WINDOWS\system32\drivers\cbidf2k.sys
                2011/04/08 04:33:46.0984 1696 Cdaudio (c1b486a7658353d33a10cc15211a873b) C:\WINDOWS\system32\drivers\Cdaudio.sys
                2011/04/08 04:33:47.0468 1696 Cdfs (c885b02847f5d2fd45a24e219ed93b32) C:\WINDOWS\system32\drivers\Cdfs.sys
                2011/04/08 04:33:48.0046 1696 Cdrom (1f4260cc5b42272d71f79e570a27a4fe) C:\WINDOWS\system32\DRIVERS\cdrom.sys
                2011/04/08 04:33:50.0843 1696 dgderdrv (3be1651c63954067940e7f473498ad70) C:\WINDOWS\system32\drivers\dgderdrv.sys
                2011/04/08 04:33:51.0484 1696 Disk (044452051f3e02e7963599fc8f4f3e25) C:\WINDOWS\system32\DRIVERS\disk.sys
                2011/04/08 04:33:52.0484 1696 dmboot (f5deadd42335fb33edca74ecb2f36cba) C:\WINDOWS\system32\drivers\dmboot.sys
                2011/04/08 04:33:53.0515 1696 dmio (5a7c47c9b3f9fb92a66410a7509f0c71) C:\WINDOWS\system32\drivers\dmio.sys
                2011/04/08 04:33:54.0109 1696 dmload (e9317282a63ca4d188c0df5e09c6ac5f) C:\WINDOWS\system32\drivers\dmload.sys
                2011/04/08 04:33:54.0609 1696 DMusic (8a208dfcf89792a484e76c40e5f50b45) C:\WINDOWS\system32\drivers\DMusic.sys
                2011/04/08 04:33:55.0343 1696 driverhardwarev2 (a694d8db6d360a3bbb0bd1517f1c1aee) C:\Program Files\ma-config.com\Drivers\driverhardwarev2.sys
                2011/04/08 04:33:55.0828 1696 drmkaud (8f5fcff8e8848afac920905fbd9d33c8) C:\WINDOWS\system32\drivers\drmkaud.sys
                2011/04/08 04:33:56.0390 1696 EL90Xbc (0b044aac3e9b7e94d939824ac7e105ae) C:\WINDOWS\system32\DRIVERS\el90Xbc5.SYS
                2011/04/08 04:33:57.0203 1696 Fallback (c823debe2548656549f84a875d65237b) C:\WINDOWS\system32\DRIVERS\HSF_FALL.sys
                2011/04/08 04:33:57.0906 1696 Fastfat (38d332a6d56af32635675f132548343e) C:\WINDOWS\system32\drivers\Fastfat.sys
                2011/04/08 04:33:58.0687 1696 Fdc (92cdd60b6730b9f50f6a1a0c1f8cdc81) C:\WINDOWS\system32\DRIVERS\fdc.sys
                2011/04/08 04:33:59.0203 1696 Fips (31f923eb2170fc172c81abda0045d18c) C:\WINDOWS\system32\drivers\Fips.sys
                2011/04/08 04:33:59.0734 1696 Flpydisk (9d27e7b80bfcdf1cdd9b555862d5e7f0) C:\WINDOWS\system32\DRIVERS\flpydisk.sys
                2011/04/08 04:34:00.0281 1696 FltMgr (b2cf4b0786f8212cb92ed2b50c6db6b0) C:\WINDOWS\system32\drivers\fltmgr.sys
                2011/04/08 04:34:00.0890 1696 Fsks (6483414841d4cab6c3b4db2ac6edd70b) C:\WINDOWS\system32\DRIVERS\HSF_FSKS.sys
                2011/04/08 04:34:01.0453 1696 FsUsbExDisk (b07663a810e861eebfd0eac7e82ca62d) C:\WINDOWS\system32\FsUsbExDisk.SYS
                2011/04/08 04:34:01.0937 1696 Fs_Rec (3e1e2bd4f39b0e2b7dc4f4d2bcc2779a) C:\WINDOWS\system32\drivers\Fs_Rec.sys
                2011/04/08 04:34:02.0515 1696 Ftdisk (a86859b77b908c18c2657f284aa29fe3) C:\WINDOWS\system32\DRIVERS\ftdisk.sys
                2011/04/08 04:34:03.0093 1696 Gpc (0a02c63c8b144bd8c86b103dee7c86a2) C:\WINDOWS\system32\DRIVERS\msgpc.sys
                2011/04/08 04:34:03.0765 1696 hidusb (ccf82c5ec8a7326c3066de870c06daf1) C:\WINDOWS\system32\DRIVERS\hidusb.sys
                2011/04/08 04:34:05.0218 1696 HSFHWBS2 (e53970b0d5614f0b1220e35052828cc3) C:\WINDOWS\system32\DRIVERS\HSFHWBS2.sys
                2011/04/08 04:34:06.0312 1696 HSF_DP (7129d0662665b2442898a0ef8fc85bb5) C:\WINDOWS\system32\DRIVERS\HSF_DP.sys
                2011/04/08 04:34:07.0687 1696 hsf_msft (74e379857d4c0dfb56de2d19b8f4c434) C:\WINDOWS\system32\DRIVERS\HSF_MSFT.sys
                2011/04/08 04:34:08.0656 1696 HTTP (f80a415ef82cd06ffaf0d971528ead38) C:\WINDOWS\system32\Drivers\HTTP.sys
                2011/04/08 04:34:10.0109 1696 i8042prt (a09bdc4ed10e3b2e0ec27bb94af32516) C:\WINDOWS\system32\DRIVERS\i8042prt.sys
                2011/04/08 04:34:10.0687 1696 Imapi (083a052659f5310dd8b6a6cb05edcf8e) C:\WINDOWS\system32\drivers\Imapi.sys
                2011/04/08 04:34:12.0031 1696 intelppm (ad340800c35a42d4de1641a37feea34c) C:\WINDOWS\system32\DRIVERS\intelppm.sys
                2011/04/08 04:34:12.0562 1696 ip6fw (3bb22519a194418d5fec05d800a19ad0) C:\WINDOWS\system32\drivers\ip6fw.sys
                2011/04/08 04:34:13.0046 1696 IpFilterDriver (731f22ba402ee4b62748adaf6363c182) C:\WINDOWS\system32\DRIVERS\ipfltdrv.sys
                2011/04/08 04:34:13.0609 1696 IpInIp (b87ab476dcf76e72010632b5550955f5) C:\WINDOWS\system32\DRIVERS\ipinip.sys
                2011/04/08 04:34:14.0187 1696 IpNat (cc748ea12c6effde940ee98098bf96bb) C:\WINDOWS\system32\DRIVERS\ipnat.sys
                2011/04/08 04:34:14.0796 1696 IPSec (23c74d75e36e7158768dd63d92789a91) C:\WINDOWS\system32\DRIVERS\ipsec.sys
                2011/04/08 04:34:15.0296 1696 IRENUM (c93c9ff7b04d772627a3646d89f7bf89) C:\WINDOWS\system32\DRIVERS\irenum.sys
                2011/04/08 04:34:15.0843 1696 isapnp (355836975a67b6554bca60328cd6cb74) C:\WINDOWS\system32\DRIVERS\isapnp.sys
                2011/04/08 04:34:16.0609 1696 K56 (9c5e3fdbfcc30cf71a49ca178b9ad442) C:\WINDOWS\system32\DRIVERS\HSF_K56K.sys
                2011/04/08 04:34:17.0343 1696 Kbdclass (16813155807c6881f4bfbf6657424659) C:\WINDOWS\system32\DRIVERS\kbdclass.sys
                2011/04/08 04:34:17.0968 1696 kmixer (692bcf44383d056aed41b045a323d378) C:\WINDOWS\system32\drivers\kmixer.sys
                2011/04/08 04:34:18.0609 1696 KMWDFILTER (566c5fd480fdbce3ba5cf9fbcffaea9a) C:\WINDOWS\system32\DRIVERS\KMWDFILTER.sys
                2011/04/08 04:34:19.0171 1696 KSecDD (b467646c54cc746128904e1654c750c1) C:\WINDOWS\system32\drivers\KSecDD.sys
                2011/04/08 04:34:20.0812 1696 mdmxsdk (eeaea6514ba7c9d273b5e87c4e1aab30) C:\WINDOWS\system32\DRIVERS\mdmxsdk.sys
                2011/04/08 04:34:21.0296 1696 mnmdd (4ae068242760a1fb6e1a44bf4e16afa6) C:\WINDOWS\system32\drivers\mnmdd.sys
                2011/04/08 04:34:21.0828 1696 Modem (510ade9327fe84c10254e1902697e25f) C:\WINDOWS\system32\drivers\Modem.sys
                2011/04/08 04:34:22.0328 1696 Mouclass (027c01bd7ef3349aaebc883d8a799efb) C:\WINDOWS\system32\DRIVERS\mouclass.sys
                2011/04/08 04:34:22.0812 1696 mouhid (124d6846040c79b9c997f78ef4b2a4e5) C:\WINDOWS\system32\DRIVERS\mouhid.sys
                2011/04/08 04:34:23.0296 1696 MountMgr (a80b9a0bad1b73637dbcbba7df72d3fd) C:\WINDOWS\system32\drivers\MountMgr.sys
                2011/04/08 04:34:24.0343 1696 MRxDAV (11d42bb6206f33fbb3ba0288d3ef81bd) C:\WINDOWS\system32\DRIVERS\mrxdav.sys
                2011/04/08 04:34:25.0109 1696 MRxSmb (f3aefb11abc521122b67095044169e98) C:\WINDOWS\system32\DRIVERS\mrxsmb.sys
                2011/04/08 04:34:25.0875 1696 Msfs (c941ea2454ba8350021d774daf0f1027) C:\WINDOWS\system32\drivers\Msfs.sys
                2011/04/08 04:34:26.0406 1696 MSKSSRV (d1575e71568f4d9e14ca56b7b0453bf1) C:\WINDOWS\system32\drivers\MSKSSRV.sys
                2011/04/08 04:34:26.0890 1696 MSPCLOCK (325bb26842fc7ccc1fcce2c457317f3e) C:\WINDOWS\system32\drivers\MSPCLOCK.sys
                2011/04/08 04:34:27.0359 1696 MSPQM (bad59648ba099da4a17680b39730cb3d) C:\WINDOWS\system32\drivers\MSPQM.sys
                2011/04/08 04:34:27.0843 1696 mssmbios (af5f4f3f14a8ea2c26de30f7a1e17136) C:\WINDOWS\system32\DRIVERS\mssmbios.sys
                2011/04/08 04:34:28.0375 1696 Mup (2f625d11385b1a94360bfc70aaefdee1) C:\WINDOWS\system32\drivers\Mup.sys
                2011/04/08 04:34:29.0062 1696 NDIS (1df7f42665c94b825322fae71721130d) C:\WINDOWS\system32\drivers\NDIS.sys
                2011/04/08 04:34:29.0593 1696 NdisTapi (1ab3d00c991ab086e69db84b6c0ed78f) C:\WINDOWS\system32\DRIVERS\ndistapi.sys
                2011/04/08 04:34:30.0093 1696 Ndisuio (f927a4434c5028758a842943ef1a3849) C:\WINDOWS\system32\DRIVERS\ndisuio.sys
                2011/04/08 04:34:30.0625 1696 NdisWan (edc1531a49c80614b2cfda43ca8659ab) C:\WINDOWS\system32\DRIVERS\ndiswan.sys
                2011/04/08 04:34:31.0156 1696 NDProxy (9282bd12dfb069d3889eb3fcc1000a9b) C:\WINDOWS\system32\drivers\NDProxy.sys
                2011/04/08 04:34:31.0718 1696 NetBIOS (5d81cf9a2f1a3a756b66cf684911cdf0) C:\WINDOWS\system32\DRIVERS\netbios.sys
                2011/04/08 04:34:32.0296 1696 NetBT (74b2b2f5bea5e9a3dc021d685551bd3d) C:\WINDOWS\system32\DRIVERS\netbt.sys
                2011/04/08 04:34:33.0000 1696 Npfs (3182d64ae053d6fb034f44b6def8034a) C:\WINDOWS\system32\drivers\Npfs.sys
                2011/04/08 04:34:33.0781 1696 Ntfs (78a08dd6a8d65e697c18e1db01c5cdca) C:\WINDOWS\system32\drivers\Ntfs.sys
                2011/04/08 04:34:34.0671 1696 Null (73c1e1f395918bc2c6dd67af7591a3ad) C:\WINDOWS\system32\drivers\Null.sys
                2011/04/08 04:34:35.0093 1696 NwlnkFlt (b305f3fad35083837ef46a0bbce2fc57) C:\WINDOWS\system32\DRIVERS\nwlnkflt.sys
                2011/04/08 04:34:35.0562 1696 NwlnkFwd (c99b3415198d1aab7227f2c88fd664b9) C:\WINDOWS\system32\DRIVERS\nwlnkfwd.sys
                2011/04/08 04:34:36.0125 1696 Parport (8fd0bdbea875d06ccf6c945ca9abaf75) C:\WINDOWS\system32\DRIVERS\parport.sys
                2011/04/08 04:34:36.0671 1696 PartMgr (beb3ba25197665d82ec7065b724171c6) C:\WINDOWS\system32\drivers\PartMgr.sys
                2011/04/08 04:34:37.0140 1696 ParVdm (9575c5630db8fb804649a6959737154c) C:\WINDOWS\system32\drivers\ParVdm.sys
                2011/04/08 04:34:37.0656 1696 PCI (043410877bda580c528f45165f7125bc) C:\WINDOWS\system32\DRIVERS\pci.sys
                2011/04/08 04:34:38.0562 1696 PCIIde (f4bfde7209c14a07aaa61e4d6ae69eac) C:\WINDOWS\system32\DRIVERS\pciide.sys
                2011/04/08 04:34:39.0125 1696 Pcmcia (f0406cbc60bdb0394a0e17ffb04cdd3d) C:\WINDOWS\system32\drivers\Pcmcia.sys
                2011/04/08 04:34:42.0203 1696 PptpMiniport (efeec01b1d3cf84f16ddd24d9d9d8f99) C:\WINDOWS\system32\DRIVERS\raspptp.sys
                2011/04/08 04:34:42.0718 1696 Processor (e19c9632ac828f6f214391e2bdda11cb) C:\WINDOWS\system32\DRIVERS\processr.sys
                2011/04/08 04:34:43.0281 1696 PSched (09298ec810b07e5d582cb3a3f9255424) C:\WINDOWS\system32\DRIVERS\psched.sys
                2011/04/08 04:34:43.0781 1696 Ptilink (80d317bd1c3dbc5d4fe7b1678c60cadd) C:\WINDOWS\system32\DRIVERS\ptilink.sys
                2011/04/08 04:34:46.0312 1696 RasAcd (fe0d99d6f31e4fad8159f690d68ded9c) C:\WINDOWS\system32\DRIVERS\rasacd.sys
                2011/04/08 04:34:46.0828 1696 Rasl2tp (11b4a627bc9614b885c4969bfa5ff8a6) C:\WINDOWS\system32\DRIVERS\rasl2tp.sys
                2011/04/08 04:34:47.0359 1696 RasPppoe (5bc962f2654137c9909c3d4603587dee) C:\WINDOWS\system32\DRIVERS\raspppoe.sys
                2011/04/08 04:34:47.0859 1696 Raspti (fdbb1d60066fcfbb7452fd8f9829b242) C:\WINDOWS\system32\DRIVERS\raspti.sys
                2011/04/08 04:34:48.0468 1696 Rdbss (7ad224ad1a1437fe28d89cf22b17780a) C:\WINDOWS\system32\DRIVERS\rdbss.sys
                2011/04/08 04:34:49.0078 1696 RDPCDD (4912d5b403614ce99c28420f75353332) C:\WINDOWS\system32\DRIVERS\RDPCDD.sys
                2011/04/08 04:34:49.0687 1696 rdpdr (15cabd0f7c00c47c70124907916af3f1) C:\WINDOWS\system32\DRIVERS\rdpdr.sys
                2011/04/08 04:34:50.0375 1696 RDPWD (6728e45b66f93c08f11de2e316fc70dd) C:\WINDOWS\system32\drivers\RDPWD.sys
                2011/04/08 04:34:51.0000 1696 redbook (d8eb2a7904db6c916eb5361878ddcbae) C:\WINDOWS\system32\DRIVERS\redbook.sys
                2011/04/08 04:34:51.0578 1696 Rksample (bb7549bd94d1aac3599c7606c50c48a0) C:\WINDOWS\system32\DRIVERS\HSF_SAMP.sys
                2011/04/08 04:34:52.0234 1696 Secdrv (90a3935d05b494a5a39d37e71f09a677) C:\WINDOWS\system32\DRIVERS\secdrv.sys
                2011/04/08 04:34:52.0750 1696 serenum (0f29512ccd6bead730039fb4bd2c85ce) C:\WINDOWS\system32\DRIVERS\serenum.sys
                2011/04/08 04:34:53.0312 1696 Serial (93d313c31f7ad9ea2b75f26075413c7c) C:\WINDOWS\system32\DRIVERS\serial.sys
                2011/04/08 04:34:53.0968 1696 Sfloppy (8e6b8c671615d126fdc553d1e2de5562) C:\WINDOWS\system32\drivers\Sfloppy.sys
                2011/04/08 04:34:55.0234 1696 smwdm (13739b36bd8d94d0fed7662aa7a4235d) C:\WINDOWS\system32\drivers\smwdm.sys
                2011/04/08 04:34:56.0156 1696 SoftFax (d9e8e0ce154a2f6430d9efabdf730867) C:\WINDOWS\system32\DRIVERS\HSF_FAXX.sys
                2011/04/08 04:34:57.0203 1696 splitter (ab8b92451ecb048a4d1de7c3ffcb4a9f) C:\WINDOWS\system32\drivers\splitter.sys
                2011/04/08 04:34:57.0734 1696 sr (39626e6dc1fb39434ec40c42722b660a) C:\WINDOWS\system32\DRIVERS\sr.sys
                2011/04/08 04:34:58.0562 1696 Srv (0f6aefad3641a657e18081f52d0c15af) C:\WINDOWS\system32\DRIVERS\srv.sys
                2011/04/08 04:34:59.0375 1696 ssadbus (6d83ff6722baf7e82a4521dbec363e5a) C:\WINDOWS\system32\DRIVERS\ssadbus.sys
                2011/04/08 04:34:59.0968 1696 ssadmdfl (5ae42e90f99749e0e35b9989a2d0275c) C:\WINDOWS\system32\DRIVERS\ssadmdfl.sys
                2011/04/08 04:35:00.0531 1696 ssadmdm (9285d8aba50a4d6482b1574448f9eb76) C:\WINDOWS\system32\DRIVERS\ssadmdm.sys
                2011/04/08 04:35:01.0109 1696 swenum (3941d127aef12e93addf6fe6ee027e0f) C:\WINDOWS\system32\DRIVERS\swenum.sys
                2011/04/08 04:35:01.0625 1696 swmidi (8ce882bcc6cf8a62f2b2323d95cb3d01) C:\WINDOWS\system32\drivers\swmidi.sys
                2011/04/08 04:35:03.0781 1696 sysaudio (8b83f3ed0f1688b4958f77cd6d2bf290) C:\WINDOWS\system32\drivers\sysaudio.sys
                2011/04/08 04:35:04.0562 1696 Tcpip (9aefa14bd6b182d61e3119fa5f436d3d) C:\WINDOWS\system32\DRIVERS\tcpip.sys
                2011/04/08 04:35:05.0343 1696 TDPIPE (6471a66807f5e104e4885f5b67349397) C:\WINDOWS\system32\drivers\TDPIPE.sys
                2011/04/08 04:35:05.0859 1696 TDTCP (c56b6d0402371cf3700eb322ef3aaf61) C:\WINDOWS\system32\drivers\TDTCP.sys
                2011/04/08 04:35:06.0390 1696 TermDD (88155247177638048422893737429d9e) C:\WINDOWS\system32\DRIVERS\termdd.sys
                2011/04/08 04:35:06.0953 1696 Tones (8021a499db46b2961c285168671cb9af) C:\WINDOWS\system32\DRIVERS\HSF_TONE.sys
                2011/04/08 04:35:07.0937 1696 Udfs (5787b80c2e3c5e2f56c2a233d91fa2c9) C:\WINDOWS\system32\drivers\Udfs.sys
                2011/04/08 04:35:09.0046 1696 Update (402ddc88356b1bac0ee3dd1580c76a31) C:\WINDOWS\system32\DRIVERS\update.sys
                2011/04/08 04:35:09.0843 1696 usbccgp (173f317ce0db8e21322e71b7e60a27e8) C:\WINDOWS\system32\DRIVERS\usbccgp.sys
                2011/04/08 04:35:10.0359 1696 usbehci (65dcf09d0e37d4c6b11b5b0b76d470a7) C:\WINDOWS\system32\DRIVERS\usbehci.sys
                2011/04/08 04:35:10.0875 1696 usbhub (1ab3cdde553b6e064d2e754efe20285c) C:\WINDOWS\system32\DRIVERS\usbhub.sys
                2011/04/08 04:35:11.0406 1696 usbohci (0daecce65366ea32b162f85f07c6753b) C:\WINDOWS\system32\DRIVERS\usbohci.sys
                2011/04/08 04:35:11.0859 1696 USBSTOR (a32426d9b14a089eaa1d922e0c5801a9) C:\WINDOWS\system32\DRIVERS\USBSTOR.SYS
                2011/04/08 04:35:12.0687 1696 V124 (269c0ade94b90029b12497747be408cb) C:\WINDOWS\system32\DRIVERS\HSF_V124.sys
                2011/04/08 04:35:13.0500 1696 VgaSave (0d3a8fafceacd8b7625cd549757a7df1) C:\WINDOWS\System32\drivers\vga.sys
                2011/04/08 04:35:14.0406 1696 VolSnap (46de1126684369bace4849e4fc8c43ca) C:\WINDOWS\system32\drivers\VolSnap.sys
                2011/04/08 04:35:15.0000 1696 Wanarp (e20b95baedb550f32dd489265c1da1f6) C:\WINDOWS\system32\DRIVERS\wanarp.sys
                2011/04/08 04:35:15.0921 1696 wdmaud (6768acf64b18196494413695f0c3a00f) C:\WINDOWS\system32\drivers\wdmaud.sys
                2011/04/08 04:35:16.0812 1696 winachsf (292b0bba146793a7937d9849bddb4298) C:\WINDOWS\system32\DRIVERS\HSF_CNXT.sys
                2011/04/08 04:35:17.0890 1696 WpdUsb (cf4def1bf66f06964dc0d91844239104) C:\WINDOWS\system32\DRIVERS\wpdusb.sys
                2011/04/08 04:35:18.0484 1696 WudfPf (f15feafffbb3644ccc80c5da584e6311) C:\WINDOWS\system32\DRIVERS\WudfPf.sys
                2011/04/08 04:35:19.0046 1696 WudfRd (28b524262bce6de1f7ef9f510ba3985b) C:\WINDOWS\system32\DRIVERS\wudfrd.sys
                2011/04/08 04:35:20.0109 1696 ================================================================================
                2011/04/08 04:35:20.0109 1696 Scan finished
                2011/04/08 04:35:20.0109 1696 ================================================================================
                2011/04/08 04:36:35.0750 1460 Deinitialize success
                0
            4. Télécharge ici :OTL

              enregistre le sur ton Bureau.

              si tu as XP => double clique
              si tu as Vista ou windows 7 => clic droit "executer en tant que...."


              sur OTL.exe pour le lancer.

              => Configuration

              ▶Clic sur Analyse.

              A la fin du scan, le Bloc-Notes va s'ouvrir avec le rapport (OTL.txt).

              Ce fichier est sur ton Bureau (en général C:\Documents and settings\le_nom_de_ta_session\OTL.txt)

              ▶▶▶ NE LE POSTE PAS SUR LE FORUM (il est trop long)

              Pour me le transmettre clique sur ce lien : http://www.cijoint.fr/

              ▶ Clique sur Parcourir et cherche le fichier ci-dessus.

              ▶ Clique sur Ouvrir.

              ▶ Clique sur "Cliquez ici pour déposer le fichier".

              juste au niveau du bouton , en fin de chargement du fichier , Un lien de cette forme apparaitra :

              http://www.cijoint.fr/cjlink.php?file=cjge368/cijSKAP5fU.txt

              ▶ Copie ce lien dans ta réponse.

              ▶▶ Tu feras la meme chose avec le "Extra.txt" qui logiquement sera aussi sur ton bureau.
              0
              1. Lien vers le rapport OTL.exe :
                http://www.cijoint.fr/cjlink.php?file=cj201104/cijGokPyhl.txt
                0
              2. Extras.txt :
                http://www.cijoint.fr/cjlink.php?file=cj201104/cij26GCuuh.txt

                Euh désolée mais est-ce que tu penses qu'il va y avoir encore de nombreux rapports à générer ?
                Car je vais bientôt devoir me déconnecter
                0
              3. on peut continuer demain sans soucis si tu veux
                0
              4. Ca dépend, si c'est plusieurs heures encore, je dois en effet différer à demain.

                Si moins d'une heure, autant poursuivre sur la lancée.

                Mais si je comprends bien mon PC est en effet infecté, ce qui explique que Windows XP ne démarre plus ?
                0
              5. oui on continuera demain on aura la tete reposée ;)

                je devrait etre là vers 13h GMT
                0
            5. Je viens de m'apercevoir que Windows XP démarre à nouveau (je voulais démarrer en mode sans échec mais n'ai pas tapé F8 assez vite).

              Cependant, comme je ne veux pas risquer de faire foirer ce qui a été fait et ne sais pas si je peux utiliser Windows sans risque, je reste en mode sans échec jusqu'à davantage d'infos ici.

              Merci !

              (merci donc de ne pas clôturer le sujet)
              0
              1. ATTENTION !!! : Script personnalisé pour cette machine uniquement , ne pas reproduire !!

                si tu as XP => double clique
                si tu as Vista ou windows 7 => clic droit "executer en tant que...."


                sur OTL.exe pour le lancer.

                ▶Copie la liste qui se trouve en gras ci-dessous,

                ▶ colle-la dans la zone sous "Personnalisation" :


                :processes
                explorer.exe
                iexplore.exe
                firefox.exe
                msnmsgr.exe
                Teatimer.exe

                :OTL
                FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0018-ABCDEFFEDCBA}:6.0.18
                FF - prefs.js..browser.search.selectedEngine: "hooseek"
                O4 - HKLM\..\RunOnce: [] File not found
                O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-1_6_0_18-windows-i586.cab (Java Plug-in 1.6.0_18)
                O16 - DPF: {CAFEEFAC-0016-0000-0018-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-1_6_0_18-windows-i586.cab (Java Plug-in 1.6.0_18)

                :commands
                [emptytemp]
                [start explorer]
                [reboot]


                ▶ Clique sur "Correction" pour lancer la suppression.

                ▶ Poste le rapport qui logiquement s'ouvrira tout seul en fin de travail appres le redemarrage.
                0
                1. J'espère que c'est bien ça ?
                  :

                  All processes killed
                  ========== PROCESSES ==========
                  Process explorer.exe killed successfully!
                  No active process named iexplore.exe was found!
                  No active process named firefox.exe was found!
                  No active process named msnmsgr.exe was found!
                  No active process named Teatimer.exe was found!
                  ========== OTL ==========
                  Prefs.js: {CAFEEFAC-0016-0000-0018-ABCDEFFEDCBA}:6.0.18 removed from extensions.enabledItems
                  Prefs.js: "hooseek" removed from browser.search.selectedEngine
                  Registry key HKEY_LOCAL_MACHINE\\Software\Microsoft\Windows\CurrentVersion\RunOnce not found.
                  Starting removal of ActiveX control {8AD9C840-044E-11D1-B3E9-00805F499D93}
                  Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Distribution Units\{8AD9C840-044E-11D1-B3E9-00805F499D93}\ deleted successfully.
                  Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{8AD9C840-044E-11D1-B3E9-00805F499D93}\ deleted successfully.
                  Registry key HKEY_CURRENT_USER\SOFTWARE\Classes\CLSID\{8AD9C840-044E-11D1-B3E9-00805F499D93}\ deleted successfully.
                  Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{8AD9C840-044E-11D1-B3E9-00805F499D93}\ not found.
                  Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{8AD9C840-044E-11D1-B3E9-00805F499D93}\ not found.
                  Starting removal of ActiveX control {CAFEEFAC-0016-0000-0018-ABCDEFFEDCBA}
                  Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Distribution Units\{CAFEEFAC-0016-0000-0018-ABCDEFFEDCBA}\ deleted successfully.
                  Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{CAFEEFAC-0016-0000-0018-ABCDEFFEDCBA}\ deleted successfully.
                  Registry key HKEY_CURRENT_USER\SOFTWARE\Classes\CLSID\{CAFEEFAC-0016-0000-0018-ABCDEFFEDCBA}\ deleted successfully.
                  Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{CAFEEFAC-0016-0000-0018-ABCDEFFEDCBA}\ not found.
                  Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{CAFEEFAC-0016-0000-0018-ABCDEFFEDCBA}\ not found.
                  ========== COMMANDS ==========

                  [EMPTYTEMP]

                  User: All Users

                  User: Default User
                  ->Temp folder emptied: 0 bytes
                  ->Temporary Internet Files folder emptied: 33170 bytes

                  User: LocalService
                  ->Temp folder emptied: 66016 bytes
                  ->Temporary Internet Files folder emptied: 63170 bytes

                  User: LogMeInRemoteUser
                  ->Temp folder emptied: 0 bytes
                  ->Temporary Internet Files folder emptied: 33170 bytes

                  User: NetworkService
                  ->Temp folder emptied: 0 bytes
                  ->Temporary Internet Files folder emptied: 33237 bytes

                  User: Sylvie
                  ->Temp folder emptied: 1721845964 bytes
                  ->Temporary Internet Files folder emptied: 5634228 bytes
                  ->Java cache emptied: 1115891 bytes
                  ->FireFox cache emptied: 49442434 bytes
                  ->Flash cache emptied: 65670 bytes

                  %systemdrive% .tmp files removed: 0 bytes
                  %systemroot% .tmp files removed: 1138958 bytes
                  %systemroot%\System32 .tmp files removed: 3072 bytes
                  %systemroot%\System32\dllcache .tmp files removed: 0 bytes
                  %systemroot%\System32\drivers .tmp files removed: 0 bytes
                  Windows Temp folder emptied: 26957510 bytes
                  %systemroot%\system32\config\systemprofile\Local Settings\Temp folder emptied: 78348392 bytes
                  %systemroot%\system32\config\systemprofile\Local Settings\Temporary Internet Files folder emptied: 52332 bytes
                  RecycleBin emptied: 9366052 bytes

                  Total Files Cleaned = 1 806,00 mb
                  0
              2. DESACTIVE TON ANTIVIRUS ET TON PAREFEU SI PRESENTS !!!!! (car l'outil est detecté a tort comme infection contenant un module qui sert à arrêter des processus , et un autre servant à prendre des droits dans le registre pour effectuer des suppressions)

                ▶ Télécharge ici :List_Kill'em

                et enregistre le sur ton bureau et lance l'installation

                Laisse coché :

                ♦ Executer List_Kill'em

                une fois terminée , clic sur "terminer"

                choisis l'option Search

                ▶ laisse travailler l'outil

                Attention : il se peut que l'outil bloque anormalement longtemps arrivé à 95%, relance-le avec le raccourci sur le bureau sans l'arreter , puis clique sur le tout petit "X" en bas de la fenetre d'accueil du programme, ca le debloquera pour finir son scan

                ▶ Poste les rapports qui apparaitront sur ton bureau : List'em.txt et More.txt

                ▶▶▶ NE LES POSTE PAS SUR LE FORUM

                Pour me le transmettre clique sur ce lien : http://www.cijoint.fr/

                ▶ Clique sur Parcourir et selectionne , un par un , les fichiers concernés apparus sur ton bureau

                ▶ Clique sur Ouvrir.

                ▶ Clique sur "Cliquez ici pour déposer le fichier".

                Un lien de cette forme :

                http://www.cijoint.fr/cjlink.php?file=265368/cijSKAP5fU.txt

                est ajouté dans la page.

                ▶ Copie ces liens dans ta réponse.
                0
                1. avast indique qu'il "a été arrêté ou est instable." ; est-ce OK ?

                  Quant au firewall, j'utilise le pare-feu Windows et je n'arrive pas à le désactiver (cause Mode sans échec ?).

                  Comment dois-je procéder ?
                  0
                2. Windows démarre toujours en mode "normal", ce qui me permettrait donc de désactiver antivirus et firewall, mais je préfère attendre confirmation que ça serait OK, histoire de ne pas faire de boulette !
                  0
              3. lance-le tout simplement , en mode sans echec y a pas de protections :)
                0
                1. List'em.txt :
                  http://www.cijoint.fr/cjlink.php?file=cj201104/cij6pSp9Bk.txt
                  0
                2. More.txt :
                  http://www.cijoint.fr/cjlink.php?file=cj201104/cijRWm5qK5.txt
                  0
              4. Fais analyser le(s) fichier(s) suivants sur Virustotal :

                Virus Total

                clique sur "Parcourir" et trouve puis selectionne ce(s) fichier(s) :

                C:\Windows\System32\DRIVERS\atisgkaf.sys

                * Clique maintenant sur Envoyer le fichier. et laisse travailler tant que "Situation actuelle : en cours d'analyse" est affiché.
                * Il est possible que le fichier soit mis en file d'attente en raison d'un grand nombre de demandes d'analyses. En ce cas, il te faudra patienter sans actualiser la page.
                * Lorsque l'analyse est terminée colle le lien de(s)( la) page(s) dans ta prochaine réponse.
                0
                1. Je ne parviens pas à accéder à Virus Total.

                  Je ne suis pas sur le PC infecté mais sur un netbook de secours ; le problème détecté est :
                  "Le site web est en ligne mais ne répond pas aux tentatives de connexions".

                  Je peux l'avoir ailleurs ?
                  0
                2. Message précedent annulé et remplacé par celui-ci :

                  je n'ai pas d'accès internent sur le PC infecté en mode sans échec.
                  Je lance Windows en mode "normal" ?
                  0
              5. ah oui :)
                0
                1. En anglais et ça a été très rapide, j'espère que c'est bon ?

                  lien page :
                  http://www.virustotal.com/file-scan/report.html?id=fb5945574f73569a8fddd3348f562d9fbd0d7c20461b615163c47fb4481ef0c8-1302297607

                  J'ai réussi à la 3ème tentative, les deux 1ères fois Windows a redemarré au bout de moins de 2 mn, avec singnalement de récupération d'une erreur sérieuse au redémarrage
                  0
              6. refais tdsskiller en mode normal
                0
                1. En désactivant antivirus et pare-feu ?
                  0
              7. 2011/04/08 23:59:54.0953 3848 TDSS rootkit removing tool 2.4.21.0 Mar 10 2011 12:26:28
                2011/04/08 23:59:55.0250 3848 ================================================================================
                2011/04/08 23:59:55.0250 3848 SystemInfo:
                2011/04/08 23:59:55.0250 3848
                2011/04/08 23:59:55.0250 3848 OS Version: 5.1.2600 ServicePack: 3.0
                2011/04/08 23:59:55.0250 3848 Product type: Workstation
                2011/04/08 23:59:55.0250 3848 ComputerName: SYLVIE-Q44LUXFR
                2011/04/08 23:59:55.0250 3848 UserName: Sylvie
                2011/04/08 23:59:55.0250 3848 Windows directory: C:\WINDOWS
                2011/04/08 23:59:55.0250 3848 System windows directory: C:\WINDOWS
                2011/04/08 23:59:55.0250 3848 Processor architecture: Intel x86
                2011/04/08 23:59:55.0250 3848 Number of processors: 1
                2011/04/08 23:59:55.0250 3848 Page size: 0x1000
                2011/04/08 23:59:55.0250 3848 Boot type: Normal boot
                2011/04/08 23:59:55.0250 3848 ================================================================================
                2011/04/08 23:59:55.0609 3848 Initialize success
                2011/04/09 00:00:01.0546 3928 ================================================================================
                2011/04/09 00:00:01.0546 3928 Scan started
                2011/04/09 00:00:01.0546 3928 Mode: Manual;
                2011/04/09 00:00:01.0546 3928 ================================================================================
                2011/04/09 00:00:03.0140 3928 Aavmker4 (83631291adf2887cffc786d034d3fa15) C:\WINDOWS\system32\drivers\Aavmker4.sys
                2011/04/09 00:00:03.0843 3928 ACPI (e5e6dbfc41ea8aad005cb9a57a96b43b) C:\WINDOWS\system32\DRIVERS\ACPI.sys
                2011/04/09 00:00:04.0109 3928 ACPIEC (e4abc1212b70bb03d35e60681c447210) C:\WINDOWS\system32\drivers\ACPIEC.sys
                2011/04/09 00:00:04.0531 3928 aeaudio (11c04b17ed2abbb4833694bcd644ac90) C:\WINDOWS\system32\drivers\aeaudio.sys
                2011/04/09 00:00:04.0890 3928 aec (8bed39e3c35d6a489438b8141717a557) C:\WINDOWS\system32\drivers\aec.sys
                2011/04/09 00:00:05.0218 3928 AFD (7e775010ef291da96ad17ca4b17137d7) C:\WINDOWS\System32\drivers\afd.sys
                2011/04/09 00:00:06.0843 3928 aswFsBlk (1c2e6bb4fe8621b1b863855b02bc33eb) C:\WINDOWS\system32\drivers\aswFsBlk.sys
                2011/04/09 00:00:07.0093 3928 aswMon2 (452d0ecd14fa02f9b061f42c8a30dd49) C:\WINDOWS\system32\drivers\aswMon2.sys
                2011/04/09 00:00:07.0328 3928 aswRdr (b6a9373619d851be80fb5f1b5eed0d4e) C:\WINDOWS\system32\drivers\aswRdr.sys
                2011/04/09 00:00:07.0734 3928 aswSnx (9be41c1ae8bc481eb662d85c98d979c2) C:\WINDOWS\system32\drivers\aswSnx.sys
                2011/04/09 00:00:08.0125 3928 aswSP (4b1a54ba2bc5873a774df6b70ab8b0b3) C:\WINDOWS\system32\drivers\aswSP.sys
                2011/04/09 00:00:08.0406 3928 aswTdi (c7f1cea32766184911293f4e1ee653f5) C:\WINDOWS\system32\drivers\aswTdi.sys
                2011/04/09 00:00:08.0609 3928 AsyncMac (b153affac761e7f5fcfa822b9c4e97bc) C:\WINDOWS\system32\DRIVERS\asyncmac.sys
                2011/04/09 00:00:08.0859 3928 atapi (9f3a2f5aa6875c72bf062c712cfa2674) C:\WINDOWS\system32\DRIVERS\atapi.sys
                2011/04/09 00:00:09.0203 3928 ati2mtag (e82021ab2021a618199709af5da58074) C:\WINDOWS\system32\DRIVERS\ati2mtag.sys
                2011/04/09 00:00:09.0390 3928 Atmarpc (9916c1225104ba14794209cfa8012159) C:\WINDOWS\system32\DRIVERS\atmarpc.sys
                2011/04/09 00:00:09.0656 3928 audstub (d9f724aa26c010a217c97606b160ed68) C:\WINDOWS\system32\DRIVERS\audstub.sys
                2011/04/09 00:00:10.0453 3928 basic2 (1b9c81ab9a456eabd9f8335f04b5f495) C:\WINDOWS\system32\DRIVERS\HSF_BSC2.sys
                2011/04/09 00:00:10.0953 3928 Beep (da1f27d85e0d1525f6621372e7b685e9) C:\WINDOWS\system32\drivers\Beep.sys
                2011/04/09 00:00:11.0640 3928 caboagp (10d5fb74ee18ea49c30daaa203c0e0ec) C:\WINDOWS\system32\DRIVERS\atisgkaf.sys
                2011/04/09 00:00:12.0671 3928 cbidf2k (90a673fc8e12a79afbed2576f6a7aaf9) C:\WINDOWS\system32\drivers\cbidf2k.sys
                2011/04/09 00:00:15.0421 3928 Cdaudio (c1b486a7658353d33a10cc15211a873b) C:\WINDOWS\system32\drivers\Cdaudio.sys
                2011/04/09 00:00:16.0343 3928 Cdfs (c885b02847f5d2fd45a24e219ed93b32) C:\WINDOWS\system32\drivers\Cdfs.sys
                2011/04/09 00:00:16.0640 3928 Cdrom (1f4260cc5b42272d71f79e570a27a4fe) C:\WINDOWS\system32\DRIVERS\cdrom.sys
                2011/04/09 00:00:17.0500 3928 dgderdrv (3be1651c63954067940e7f473498ad70) C:\WINDOWS\system32\drivers\dgderdrv.sys
                2011/04/09 00:00:17.0765 3928 Disk (044452051f3e02e7963599fc8f4f3e25) C:\WINDOWS\system32\DRIVERS\disk.sys
                2011/04/09 00:00:17.0937 3928 dmboot (f5deadd42335fb33edca74ecb2f36cba) C:\WINDOWS\system32\drivers\dmboot.sys
                2011/04/09 00:00:18.0375 3928 dmio (5a7c47c9b3f9fb92a66410a7509f0c71) C:\WINDOWS\system32\drivers\dmio.sys
                2011/04/09 00:00:18.0734 3928 dmload (e9317282a63ca4d188c0df5e09c6ac5f) C:\WINDOWS\system32\drivers\dmload.sys
                2011/04/09 00:00:19.0421 3928 DMusic (8a208dfcf89792a484e76c40e5f50b45) C:\WINDOWS\system32\drivers\DMusic.sys
                2011/04/09 00:00:20.0515 3928 driverhardwarev2 (a694d8db6d360a3bbb0bd1517f1c1aee) C:\Program Files\ma-config.com\Drivers\driverhardwarev2.sys
                2011/04/09 00:00:21.0437 3928 drmkaud (8f5fcff8e8848afac920905fbd9d33c8) C:\WINDOWS\system32\drivers\drmkaud.sys
                2011/04/09 00:00:22.0203 3928 EL90Xbc (0b044aac3e9b7e94d939824ac7e105ae) C:\WINDOWS\system32\DRIVERS\el90Xbc5.SYS
                2011/04/09 00:00:23.0140 3928 Fallback (c823debe2548656549f84a875d65237b) C:\WINDOWS\system32\DRIVERS\HSF_FALL.sys
                2011/04/09 00:00:24.0125 3928 Fastfat (38d332a6d56af32635675f132548343e) C:\WINDOWS\system32\drivers\Fastfat.sys
                2011/04/09 00:00:24.0953 3928 Fdc (92cdd60b6730b9f50f6a1a0c1f8cdc81) C:\WINDOWS\system32\DRIVERS\fdc.sys
                2011/04/09 00:00:25.0734 3928 Fips (31f923eb2170fc172c81abda0045d18c) C:\WINDOWS\system32\drivers\Fips.sys
                2011/04/09 00:00:26.0562 3928 Flpydisk (9d27e7b80bfcdf1cdd9b555862d5e7f0) C:\WINDOWS\system32\DRIVERS\flpydisk.sys
                2011/04/09 00:00:27.0375 3928 FltMgr (b2cf4b0786f8212cb92ed2b50c6db6b0) C:\WINDOWS\system32\drivers\fltmgr.sys
                2011/04/09 00:00:28.0468 3928 Fsks (6483414841d4cab6c3b4db2ac6edd70b) C:\WINDOWS\system32\DRIVERS\HSF_FSKS.sys
                2011/04/09 00:00:29.0812 3928 FsUsbExDisk (b07663a810e861eebfd0eac7e82ca62d) C:\WINDOWS\system32\FsUsbExDisk.SYS
                2011/04/09 00:00:30.0921 3928 Fs_Rec (3e1e2bd4f39b0e2b7dc4f4d2bcc2779a) C:\WINDOWS\system32\drivers\Fs_Rec.sys
                2011/04/09 00:00:31.0859 3928 Ftdisk (a86859b77b908c18c2657f284aa29fe3) C:\WINDOWS\system32\DRIVERS\ftdisk.sys
                2011/04/09 00:00:33.0250 3928 Gpc (0a02c63c8b144bd8c86b103dee7c86a2) C:\WINDOWS\system32\DRIVERS\msgpc.sys
                2011/04/09 00:00:34.0140 3928 hidusb (ccf82c5ec8a7326c3066de870c06daf1) C:\WINDOWS\system32\DRIVERS\hidusb.sys
                2011/04/09 00:00:35.0906 3928 HSFHWBS2 (e53970b0d5614f0b1220e35052828cc3) C:\WINDOWS\system32\DRIVERS\HSFHWBS2.sys
                2011/04/09 00:00:36.0593 3928 HSF_DP (7129d0662665b2442898a0ef8fc85bb5) C:\WINDOWS\system32\DRIVERS\HSF_DP.sys
                2011/04/09 00:00:37.0265 3928 hsf_msft (74e379857d4c0dfb56de2d19b8f4c434) C:\WINDOWS\system32\DRIVERS\HSF_MSFT.sys
                2011/04/09 00:00:38.0296 3928 HTTP (f80a415ef82cd06ffaf0d971528ead38) C:\WINDOWS\system32\Drivers\HTTP.sys
                2011/04/09 00:00:39.0812 3928 i8042prt (a09bdc4ed10e3b2e0ec27bb94af32516) C:\WINDOWS\system32\DRIVERS\i8042prt.sys
                2011/04/09 00:00:40.0812 3928 Imapi (083a052659f5310dd8b6a6cb05edcf8e) C:\WINDOWS\system32\drivers\Imapi.sys
                2011/04/09 00:00:43.0687 3928 intelppm (ad340800c35a42d4de1641a37feea34c) C:\WINDOWS\system32\DRIVERS\intelppm.sys
                2011/04/09 00:00:44.0687 3928 ip6fw (3bb22519a194418d5fec05d800a19ad0) C:\WINDOWS\system32\drivers\ip6fw.sys
                2011/04/09 00:00:45.0703 3928 IpFilterDriver (731f22ba402ee4b62748adaf6363c182) C:\WINDOWS\system32\DRIVERS\ipfltdrv.sys
                2011/04/09 00:00:46.0734 3928 IpInIp (b87ab476dcf76e72010632b5550955f5) C:\WINDOWS\system32\DRIVERS\ipinip.sys
                2011/04/09 00:00:47.0609 3928 IpNat (cc748ea12c6effde940ee98098bf96bb) C:\WINDOWS\system32\DRIVERS\ipnat.sys
                2011/04/09 00:00:48.0390 3928 IPSec (23c74d75e36e7158768dd63d92789a91) C:\WINDOWS\system32\DRIVERS\ipsec.sys
                2011/04/09 00:00:49.0000 3928 IRENUM (c93c9ff7b04d772627a3646d89f7bf89) C:\WINDOWS\system32\DRIVERS\irenum.sys
                2011/04/09 00:00:49.0484 3928 isapnp (355836975a67b6554bca60328cd6cb74) C:\WINDOWS\system32\DRIVERS\isapnp.sys
                2011/04/09 00:00:50.0000 3928 K56 (9c5e3fdbfcc30cf71a49ca178b9ad442) C:\WINDOWS\system32\DRIVERS\HSF_K56K.sys
                2011/04/09 00:00:50.0468 3928 Kbdclass (16813155807c6881f4bfbf6657424659) C:\WINDOWS\system32\DRIVERS\kbdclass.sys
                2011/04/09 00:00:50.0937 3928 kmixer (692bcf44383d056aed41b045a323d378) C:\WINDOWS\system32\drivers\kmixer.sys
                2011/04/09 00:00:51.0484 3928 KMWDFILTER (566c5fd480fdbce3ba5cf9fbcffaea9a) C:\WINDOWS\system32\DRIVERS\KMWDFILTER.sys
                2011/04/09 00:00:52.0031 3928 KSecDD (b467646c54cc746128904e1654c750c1) C:\WINDOWS\system32\drivers\KSecDD.sys
                2011/04/09 00:00:53.0265 3928 mdmxsdk (eeaea6514ba7c9d273b5e87c4e1aab30) C:\WINDOWS\system32\DRIVERS\mdmxsdk.sys
                2011/04/09 00:00:53.0546 3928 mnmdd (4ae068242760a1fb6e1a44bf4e16afa6) C:\WINDOWS\system32\drivers\mnmdd.sys
                2011/04/09 00:00:53.0921 3928 Modem (510ade9327fe84c10254e1902697e25f) C:\WINDOWS\system32\drivers\Modem.sys
                2011/04/09 00:00:54.0406 3928 Mouclass (027c01bd7ef3349aaebc883d8a799efb) C:\WINDOWS\system32\DRIVERS\mouclass.sys
                2011/04/09 00:00:54.0750 3928 mouhid (124d6846040c79b9c997f78ef4b2a4e5) C:\WINDOWS\system32\DRIVERS\mouhid.sys
                2011/04/09 00:00:55.0156 3928 MountMgr (a80b9a0bad1b73637dbcbba7df72d3fd) C:\WINDOWS\system32\drivers\MountMgr.sys
                2011/04/09 00:00:55.0906 3928 MRxDAV (11d42bb6206f33fbb3ba0288d3ef81bd) C:\WINDOWS\system32\DRIVERS\mrxdav.sys
                2011/04/09 00:00:56.0421 3928 MRxSmb (f3aefb11abc521122b67095044169e98) C:\WINDOWS\system32\DRIVERS\mrxsmb.sys
                2011/04/09 00:00:57.0046 3928 Msfs (c941ea2454ba8350021d774daf0f1027) C:\WINDOWS\system32\drivers\Msfs.sys
                2011/04/09 00:00:57.0250 3928 MSKSSRV (d1575e71568f4d9e14ca56b7b0453bf1) C:\WINDOWS\system32\drivers\MSKSSRV.sys
                2011/04/09 00:00:57.0625 3928 MSPCLOCK (325bb26842fc7ccc1fcce2c457317f3e) C:\WINDOWS\system32\drivers\MSPCLOCK.sys
                2011/04/09 00:00:58.0000 3928 MSPQM (bad59648ba099da4a17680b39730cb3d) C:\WINDOWS\system32\drivers\MSPQM.sys
                2011/04/09 00:00:58.0171 3928 mssmbios (af5f4f3f14a8ea2c26de30f7a1e17136) C:\WINDOWS\system32\DRIVERS\mssmbios.sys
                2011/04/09 00:00:58.0359 3928 Mup (2f625d11385b1a94360bfc70aaefdee1) C:\WINDOWS\system32\drivers\Mup.sys
                2011/04/09 00:00:58.0640 3928 NDIS (1df7f42665c94b825322fae71721130d) C:\WINDOWS\system32\drivers\NDIS.sys
                2011/04/09 00:00:58.0937 3928 NdisTapi (1ab3d00c991ab086e69db84b6c0ed78f) C:\WINDOWS\system32\DRIVERS\ndistapi.sys
                2011/04/09 00:00:59.0109 3928 Ndisuio (f927a4434c5028758a842943ef1a3849) C:\WINDOWS\system32\DRIVERS\ndisuio.sys
                2011/04/09 00:00:59.0281 3928 NdisWan (edc1531a49c80614b2cfda43ca8659ab) C:\WINDOWS\system32\DRIVERS\ndiswan.sys
                2011/04/09 00:00:59.0484 3928 NDProxy (9282bd12dfb069d3889eb3fcc1000a9b) C:\WINDOWS\system32\drivers\NDProxy.sys
                2011/04/09 00:00:59.0703 3928 NetBIOS (5d81cf9a2f1a3a756b66cf684911cdf0) C:\WINDOWS\system32\DRIVERS\netbios.sys
                2011/04/09 00:00:59.0968 3928 NetBT (74b2b2f5bea5e9a3dc021d685551bd3d) C:\WINDOWS\system32\DRIVERS\netbt.sys
                2011/04/09 00:01:00.0265 3928 Npfs (3182d64ae053d6fb034f44b6def8034a) C:\WINDOWS\system32\drivers\Npfs.sys
                2011/04/09 00:01:00.0531 3928 Ntfs (78a08dd6a8d65e697c18e1db01c5cdca) C:\WINDOWS\system32\drivers\Ntfs.sys
                2011/04/09 00:01:00.0750 3928 Null (73c1e1f395918bc2c6dd67af7591a3ad) C:\WINDOWS\system32\drivers\Null.sys
                2011/04/09 00:01:01.0015 3928 NwlnkFlt (b305f3fad35083837ef46a0bbce2fc57) C:\WINDOWS\system32\DRIVERS\nwlnkflt.sys
                2011/04/09 00:01:01.0156 3928 NwlnkFwd (c99b3415198d1aab7227f2c88fd664b9) C:\WINDOWS\system32\DRIVERS\nwlnkfwd.sys
                2011/04/09 00:01:01.0343 3928 Parport (8fd0bdbea875d06ccf6c945ca9abaf75) C:\WINDOWS\system32\DRIVERS\parport.sys
                2011/04/09 00:01:01.0546 3928 PartMgr (beb3ba25197665d82ec7065b724171c6) C:\WINDOWS\system32\drivers\PartMgr.sys
                2011/04/09 00:01:01.0718 3928 ParVdm (9575c5630db8fb804649a6959737154c) C:\WINDOWS\system32\drivers\ParVdm.sys
                2011/04/09 00:01:01.0843 3928 PCI (043410877bda580c528f45165f7125bc) C:\WINDOWS\system32\DRIVERS\pci.sys
                2011/04/09 00:01:02.0203 3928 PCIIde (f4bfde7209c14a07aaa61e4d6ae69eac) C:\WINDOWS\system32\DRIVERS\pciide.sys
                2011/04/09 00:01:02.0343 3928 Pcmcia (f0406cbc60bdb0394a0e17ffb04cdd3d) C:\WINDOWS\system32\drivers\Pcmcia.sys
                2011/04/09 00:01:03.0515 3928 PptpMiniport (efeec01b1d3cf84f16ddd24d9d9d8f99) C:\WINDOWS\system32\DRIVERS\raspptp.sys
                2011/04/09 00:01:03.0734 3928 Processor (e19c9632ac828f6f214391e2bdda11cb) C:\WINDOWS\system32\DRIVERS\processr.sys
                2011/04/09 00:01:03.0906 3928 PSched (09298ec810b07e5d582cb3a3f9255424) C:\WINDOWS\system32\DRIVERS\psched.sys
                2011/04/09 00:01:04.0125 3928 Ptilink (80d317bd1c3dbc5d4fe7b1678c60cadd) C:\WINDOWS\system32\DRIVERS\ptilink.sys
                2011/04/09 00:01:04.0937 3928 RasAcd (fe0d99d6f31e4fad8159f690d68ded9c) C:\WINDOWS\system32\DRIVERS\rasacd.sys
                2011/04/09 00:01:05.0250 3928 Rasl2tp (11b4a627bc9614b885c4969bfa5ff8a6) C:\WINDOWS\system32\DRIVERS\rasl2tp.sys
                2011/04/09 00:01:05.0375 3928 RasPppoe (5bc962f2654137c9909c3d4603587dee) C:\WINDOWS\system32\DRIVERS\raspppoe.sys
                2011/04/09 00:01:05.0531 3928 Raspti (fdbb1d60066fcfbb7452fd8f9829b242) C:\WINDOWS\system32\DRIVERS\raspti.sys
                2011/04/09 00:01:05.0671 3928 Rdbss (7ad224ad1a1437fe28d89cf22b17780a) C:\WINDOWS\system32\DRIVERS\rdbss.sys
                2011/04/09 00:01:05.0828 3928 RDPCDD (4912d5b403614ce99c28420f75353332) C:\WINDOWS\system32\DRIVERS\RDPCDD.sys
                2011/04/09 00:01:05.0968 3928 rdpdr (15cabd0f7c00c47c70124907916af3f1) C:\WINDOWS\system32\DRIVERS\rdpdr.sys
                2011/04/09 00:01:06.0187 3928 RDPWD (6728e45b66f93c08f11de2e316fc70dd) C:\WINDOWS\system32\drivers\RDPWD.sys
                2011/04/09 00:01:06.0484 3928 redbook (d8eb2a7904db6c916eb5361878ddcbae) C:\WINDOWS\system32\DRIVERS\redbook.sys
                2011/04/09 00:01:06.0656 3928 Rksample (bb7549bd94d1aac3599c7606c50c48a0) C:\WINDOWS\system32\DRIVERS\HSF_SAMP.sys
                2011/04/09 00:01:06.0921 3928 Secdrv (90a3935d05b494a5a39d37e71f09a677) C:\WINDOWS\system32\DRIVERS\secdrv.sys
                2011/04/09 00:01:07.0109 3928 serenum (0f29512ccd6bead730039fb4bd2c85ce) C:\WINDOWS\system32\DRIVERS\serenum.sys
                2011/04/09 00:01:07.0234 3928 Serial (93d313c31f7ad9ea2b75f26075413c7c) C:\WINDOWS\system32\DRIVERS\serial.sys
                2011/04/09 00:01:07.0406 3928 Sfloppy (8e6b8c671615d126fdc553d1e2de5562) C:\WINDOWS\system32\drivers\Sfloppy.sys
                2011/04/09 00:01:07.0750 3928 smwdm (13739b36bd8d94d0fed7662aa7a4235d) C:\WINDOWS\system32\drivers\smwdm.sys
                2011/04/09 00:01:08.0078 3928 SoftFax (d9e8e0ce154a2f6430d9efabdf730867) C:\WINDOWS\system32\DRIVERS\HSF_FAXX.sys
                2011/04/09 00:01:08.0390 3928 splitter (ab8b92451ecb048a4d1de7c3ffcb4a9f) C:\WINDOWS\system32\drivers\splitter.sys
                2011/04/09 00:01:08.0578 3928 sr (39626e6dc1fb39434ec40c42722b660a) C:\WINDOWS\system32\DRIVERS\sr.sys
                2011/04/09 00:01:08.0875 3928 Srv (0f6aefad3641a657e18081f52d0c15af) C:\WINDOWS\system32\DRIVERS\srv.sys
                2011/04/09 00:01:09.0062 3928 ssadbus (6d83ff6722baf7e82a4521dbec363e5a) C:\WINDOWS\system32\DRIVERS\ssadbus.sys
                2011/04/09 00:01:09.0359 3928 ssadmdfl (5ae42e90f99749e0e35b9989a2d0275c) C:\WINDOWS\system32\DRIVERS\ssadmdfl.sys
                2011/04/09 00:01:09.0500 3928 ssadmdm (9285d8aba50a4d6482b1574448f9eb76) C:\WINDOWS\system32\DRIVERS\ssadmdm.sys
                2011/04/09 00:01:09.0687 3928 swenum (3941d127aef12e93addf6fe6ee027e0f) C:\WINDOWS\system32\DRIVERS\swenum.sys
                2011/04/09 00:01:09.0859 3928 swmidi (8ce882bcc6cf8a62f2b2323d95cb3d01) C:\WINDOWS\system32\drivers\swmidi.sys
                2011/04/09 00:01:10.0343 3928 sysaudio (8b83f3ed0f1688b4958f77cd6d2bf290) C:\WINDOWS\system32\drivers\sysaudio.sys
                2011/04/09 00:01:10.0578 3928 Tcpip (9aefa14bd6b182d61e3119fa5f436d3d) C:\WINDOWS\system32\DRIVERS\tcpip.sys
                2011/04/09 00:01:10.0750 3928 TDPIPE (6471a66807f5e104e4885f5b67349397) C:\WINDOWS\system32\drivers\TDPIPE.sys
                2011/04/09 00:01:10.0953 3928 TDTCP (c56b6d0402371cf3700eb322ef3aaf61) C:\WINDOWS\system32\drivers\TDTCP.sys
                2011/04/09 00:01:11.0125 3928 TermDD (88155247177638048422893737429d9e) C:\WINDOWS\system32\DRIVERS\termdd.sys
                2011/04/09 00:01:11.0312 3928 Tones (8021a499db46b2961c285168671cb9af) C:\WINDOWS\system32\DRIVERS\HSF_TONE.sys
                2011/04/09 00:01:11.0546 3928 Udfs (5787b80c2e3c5e2f56c2a233d91fa2c9) C:\WINDOWS\system32\drivers\Udfs.sys
                2011/04/09 00:01:11.0953 3928 Update (402ddc88356b1bac0ee3dd1580c76a31) C:\WINDOWS\system32\DRIVERS\update.sys
                2011/04/09 00:01:12.0328 3928 usbccgp (173f317ce0db8e21322e71b7e60a27e8) C:\WINDOWS\system32\DRIVERS\usbccgp.sys
                2011/04/09 00:01:12.0484 3928 usbehci (65dcf09d0e37d4c6b11b5b0b76d470a7) C:\WINDOWS\system32\DRIVERS\usbehci.sys
                2011/04/09 00:01:12.0687 3928 usbhub (1ab3cdde553b6e064d2e754efe20285c) C:\WINDOWS\system32\DRIVERS\usbhub.sys
                2011/04/09 00:01:12.0875 3928 usbohci (0daecce65366ea32b162f85f07c6753b) C:\WINDOWS\system32\DRIVERS\usbohci.sys
                2011/04/09 00:01:13.0046 3928 USBSTOR (a32426d9b14a089eaa1d922e0c5801a9) C:\WINDOWS\system32\DRIVERS\USBSTOR.SYS
                2011/04/09 00:01:13.0390 3928 V124 (269c0ade94b90029b12497747be408cb) C:\WINDOWS\system32\DRIVERS\HSF_V124.sys
                2011/04/09 00:01:13.0640 3928 VgaSave (0d3a8fafceacd8b7625cd549757a7df1) C:\WINDOWS\System32\drivers\vga.sys
                2011/04/09 00:01:14.0031 3928 VolSnap (46de1126684369bace4849e4fc8c43ca) C:\WINDOWS\system32\drivers\VolSnap.sys
                2011/04/09 00:01:14.0265 3928 Wanarp (e20b95baedb550f32dd489265c1da1f6) C:\WINDOWS\system32\DRIVERS\wanarp.sys
                2011/04/09 00:01:14.0656 3928 wdmaud (6768acf64b18196494413695f0c3a00f) C:\WINDOWS\system32\drivers\wdmaud.sys
                2011/04/09 00:01:15.0015 3928 winachsf (292b0bba146793a7937d9849bddb4298) C:\WINDOWS\system32\DRIVERS\HSF_CNXT.sys
                2011/04/09 00:01:15.0328 3928 WpdUsb (cf4def1bf66f06964dc0d91844239104) C:\WINDOWS\system32\DRIVERS\wpdusb.sys
                2011/04/09 00:01:15.0515 3928 WudfPf (f15feafffbb3644ccc80c5da584e6311) C:\WINDOWS\system32\DRIVERS\WudfPf.sys
                2011/04/09 00:01:15.0781 3928 WudfRd (28b524262bce6de1f7ef9f510ba3985b) C:\WINDOWS\system32\DRIVERS\wudfrd.sys
                2011/04/09 00:01:16.0687 3928 ================================================================================
                2011/04/09 00:01:16.0687 3928 Scan finished
                2011/04/09 00:01:16.0687 3928 ================================================================================
                0
                1. fermer toutes les fenêtres et applications lors de l'installation et de l'analyse.

                  ▶ Télécharge ici :

                  Malwarebytes

                  ▶ Installe le ( choisis bien "francais" ; ne modifie pas les paramètres d'installe ) et mets le à jour .

                  (NB : Si tu as un message d'erreur t'indiquant qu'il te manque "COMCTL32.OCX" lors de l'installe, alors télécharge le ici : COMCTL32.OCX

                  ▶ Potasses le Tuto pour te familiariser avec le prg :

                  ( cela dit, il est très simple d'utilisation ).

                  relance malwarebytes en suivant scrupuleusement ces consignes :

                  ! Déconnecte toi et ferme toutes applications en cours !

                  ▶ Lance Malwarebyte's .

                  Fais un examen dit "Complet" .

                  ▶ Laisse le programme travailler ( et ne rien faire d'autre avec le PC durant le scan ).
                  ▶ à la fin tu cliques sur "résultat" .
                  Vérifie que tous les objets infectés soient validés, puis clique sur " suppression " .

                  Note : si il faut redémarrer ton PC pour finir le nettoyage, fais le !

                  Poste le rapport sauvegardé après la suppression des objets infectés (dans l'onglet "rapport/log"de Malwarebytes, le dernier en date)

                  0
                  1. Je continue en mode normal (difficile car de nombreux redémarrages rapprochés) ou sans échec ?
                    0
                • 1
                • 2
                • 3
                • 4