Windows ne parvient pas à accéder

[Résolu/Fermé]
Signaler
-
Messages postés
35445
Date d'inscription
jeudi 18 décembre 2008
Statut
Contributeur sécurité
Dernière intervention
5 mai 2017
-
Bonjour,





J'ai voulu installer un programme de fax, et apparemment, malgré le scan via AVG, je me suis chopé un virus qui me bloque complètement. La poisse, c'est que je ne parviens pas à savoir de quel virus il s'agit.

J'ai installé "HijackThis", mais lorsque je clique dessus, ça m'indique "Windows ne parvient pas à accéder au périphérique, au chemin d'accès ou au fichier spécifié. Vous ne disposez peut-être pas des autorisations appropriées pour avoir accès à l'élément.".

J'ai tenté de faire un scan antivirus en ligne par "Secuser.com" via "Internet explorer", mais depuis, j'ai le même message d'erreur lorsque j'essaie d'accéder à Internet Explorer.

Dans la configuration d'AVG, l'identity protection a été désactivée, et impossible de la réactiver. J'obtiens le message "Une erreur s'est produite au cours de l'enregistrement de la configuration. Une erreur innatendue s'est produite dans le composant "IDP".

J'ai tenté de faire une restauration XP à une date antérieure, mais à chaque fois la restauration n'a pu se faire.

Maintenant, l'UC du pc est non stop à 100%.

Merci d'avance de toute l'aide que vous pourrez m'apporter, car mon pc est quasiment inutilisable.

51 réponses

Bonjour et un tout rand merci pour ton aide.

Dans cette réponse, je vais coller le rapport émis par "Reload_TDSSKiller ". Malgré le message de demande de redémarrage du pc que ce logiciel m'indiquait à la fin de l'opération, je n'ai pas redémarrer le pc (pour que la cure soit complète). Dois-je le faire?

Dans une seconde réponse, je vais coller le rapport émis par "RogueKiller".

Voici celui émis par émis par "Reload_TDSSKiller " :


16:20:01.0265 1636 TDSS rootkit removing tool 2.6.2.0 Sep 26 2011 18:56:43
16:20:01.0406 1636 ============================================================
16:20:01.0406 1636 Current date / time: 2011/09/27 16:20:01.0406
16:20:01.0406 1636 SystemInfo:
16:20:01.0406 1636
16:20:01.0406 1636 OS Version: 5.1.2600 ServicePack: 3.0
16:20:01.0406 1636 Product type: Workstation
16:20:01.0406 1636 ComputerName: CHR
16:20:01.0406 1636 UserName: dmi
16:20:01.0406 1636 Windows directory: C:\WINDOWS
16:20:01.0406 1636 System windows directory: C:\WINDOWS
16:20:01.0406 1636 Processor architecture: Intel x86
16:20:01.0406 1636 Number of processors: 2
16:20:01.0406 1636 Page size: 0x1000
16:20:01.0406 1636 Boot type: Normal boot
16:20:01.0406 1636 ============================================================
16:20:01.0671 1636 Initialize success
16:20:07.0843 3836 ============================================================
16:20:07.0843 3836 Scan started
16:20:07.0843 3836 Mode: Manual;
16:20:07.0843 3836 ============================================================
16:20:08.0156 3836 a347bus (1f61cacacb521215f39061789147968c) C:\WINDOWS\system32\DRIVERS\a347bus.sys
16:20:08.0156 3836 a347bus - ok
16:20:08.0187 3836 a347scsi (113e4b318bbaa7483ca4e582a4d63f49) C:\WINDOWS\system32\Drivers\a347scsi.sys
16:20:08.0187 3836 a347scsi - ok
16:20:08.0203 3836 Abiosdsk - ok
16:20:08.0218 3836 abp480n5 - ok
16:20:08.0281 3836 Accelerometer (6c2e405d98e6342a9d66a2493e7ab15e) C:\WINDOWS\system32\DRIVERS\Accelerometer.sys
16:20:08.0281 3836 Accelerometer - ok
16:20:08.0359 3836 ACPI (e5e6dbfc41ea8aad005cb9a57a96b43b) C:\WINDOWS\system32\DRIVERS\ACPI.sys
16:20:08.0359 3836 ACPI - ok
16:20:08.0390 3836 ACPIEC (e4abc1212b70bb03d35e60681c447210) C:\WINDOWS\system32\DRIVERS\ACPIEC.sys
16:20:08.0406 3836 ACPIEC - ok
16:20:08.0515 3836 ADIHdAudAddService (ff60db2aca88543c025eacba25cee5c1) C:\WINDOWS\system32\drivers\ADIHdAud.sys
16:20:08.0515 3836 ADIHdAudAddService - ok
16:20:08.0531 3836 adpu160m - ok
16:20:08.0562 3836 AEAudio (fff87a9b1ab36ee4b7bec98a4cb01b79) C:\WINDOWS\system32\drivers\AEAudio.sys
16:20:08.0562 3836 AEAudio - ok
16:20:08.0656 3836 aec (8bed39e3c35d6a489438b8141717a557) C:\WINDOWS\system32\drivers\aec.sys
16:20:08.0656 3836 aec - ok
16:20:08.0734 3836 AFD (355556d9e580915118cd7ef736653a89) C:\WINDOWS\System32\drivers\afd.sys
16:20:08.0734 3836 AFD - ok
16:20:08.0859 3836 AgereSoftModem (1cfeba39fc613e45b49d3eddfbcda289) C:\WINDOWS\system32\DRIVERS\AGRSM.sys
16:20:08.0906 3836 AgereSoftModem - ok
16:20:08.0937 3836 Aha154x - ok
16:20:08.0953 3836 aic78u2 - ok
16:20:08.0984 3836 aic78xx - ok
16:20:09.0000 3836 AliIde - ok
16:20:09.0031 3836 amsint - ok
16:20:09.0109 3836 Arp1394 (b5b8a80875c1dededa8b02765642c32f) C:\WINDOWS\system32\DRIVERS\arp1394.sys
16:20:09.0109 3836 Arp1394 - ok
16:20:09.0140 3836 asc - ok
16:20:09.0171 3836 asc3350p - ok
16:20:09.0187 3836 asc3550 - ok
16:20:09.0250 3836 AsyncMac (b153affac761e7f5fcfa822b9c4e97bc) C:\WINDOWS\system32\DRIVERS\asyncmac.sys
16:20:09.0250 3836 AsyncMac - ok
16:20:09.0281 3836 atapi (9f3a2f5aa6875c72bf062c712cfa2674) C:\WINDOWS\system32\drivers\atapi.sys
16:20:09.0281 3836 atapi - ok
16:20:09.0296 3836 Atdisk - ok
16:20:09.0343 3836 Atmarpc (9916c1225104ba14794209cfa8012159) C:\WINDOWS\system32\DRIVERS\atmarpc.sys
16:20:09.0343 3836 Atmarpc - ok
16:20:09.0453 3836 ATSwpWDF (a9f9d1d24441889beb1aa2b917457e23) C:\WINDOWS\system32\Drivers\ATSwpWDF.sys
16:20:09.0468 3836 ATSwpWDF - ok
16:20:09.0546 3836 audstub (d9f724aa26c010a217c97606b160ed68) C:\WINDOWS\system32\DRIVERS\audstub.sys
16:20:09.0546 3836 audstub - ok
16:20:09.0625 3836 AVGIDSDriver (2d18221aab3db2d408d6c55c0f23090a) C:\WINDOWS\system32\DRIVERS\AVGIDSDriver.Sys
16:20:09.0625 3836 AVGIDSDriver - ok
16:20:09.0703 3836 AVGIDSEH (1af676db3f3d4cc709cfab2571cf5fc3) C:\WINDOWS\system32\DRIVERS\AVGIDSEH.Sys
16:20:09.0703 3836 AVGIDSEH - ok
16:20:09.0734 3836 AVGIDSFilter (4c51e233c87f9ec7598551de554bc99d) C:\WINDOWS\system32\DRIVERS\AVGIDSFilter.Sys
16:20:09.0734 3836 AVGIDSFilter - ok
16:20:09.0781 3836 AVGIDSShim (c3fc426e54f55c1cc3219e415b88e10c) C:\WINDOWS\system32\DRIVERS\AVGIDSShim.Sys
16:20:09.0781 3836 AVGIDSShim - ok
16:20:09.0843 3836 Avgldx86 (4e796d3d2c3182b13b3e3b5a2ad4ef0a) C:\WINDOWS\system32\DRIVERS\avgldx86.sys
16:20:09.0843 3836 Avgldx86 - ok
16:20:09.0859 3836 Avgmfx86 (5639de66b37d02bd22df4cf3155fba60) C:\WINDOWS\system32\DRIVERS\avgmfx86.sys
16:20:09.0859 3836 Avgmfx86 - ok
16:20:09.0890 3836 Avgrkx86 (d1baf652eda0ae70896276a1fb32c2d4) C:\WINDOWS\system32\DRIVERS\avgrkx86.sys
16:20:09.0890 3836 Avgrkx86 - ok
16:20:09.0937 3836 Avgtdix (aaf0ebcad95f2164cffb544e00392498) C:\WINDOWS\system32\DRIVERS\avgtdix.sys
16:20:09.0937 3836 Avgtdix - ok
16:20:10.0031 3836 b57w2k (ea377a8e8e1000877210259750cbbf5f) C:\WINDOWS\system32\DRIVERS\b57xp32.sys
16:20:10.0031 3836 b57w2k - ok
16:20:10.0093 3836 Beep (da1f27d85e0d1525f6621372e7b685e9) C:\WINDOWS\system32\drivers\Beep.sys
16:20:10.0093 3836 Beep - ok
16:20:10.0171 3836 BTKRNL (ef5e0de0a7ca2977a9255f36f4d915ab) C:\WINDOWS\system32\DRIVERS\btkrnl.sys
16:20:10.0171 3836 BTKRNL - ok
16:20:10.0187 3836 BTWUSB (053dc5be74621b63bb48c2b86bafc7b0) C:\WINDOWS\system32\Drivers\btwusb.sys
16:20:10.0187 3836 BTWUSB - ok
16:20:10.0218 3836 cbidf2k (90a673fc8e12a79afbed2576f6a7aaf9) C:\WINDOWS\system32\drivers\cbidf2k.sys
16:20:10.0218 3836 cbidf2k - ok
16:20:10.0281 3836 CCDECODE (0be5aef125be881c4f854c554f2b025c) C:\WINDOWS\system32\DRIVERS\CCDECODE.sys
16:20:10.0281 3836 CCDECODE - ok
16:20:10.0312 3836 cd20xrnt - ok
16:20:10.0343 3836 Cdaudio (c1b486a7658353d33a10cc15211a873b) C:\WINDOWS\system32\drivers\Cdaudio.sys
16:20:10.0343 3836 Cdaudio - ok
16:20:10.0406 3836 Cdfs (c885b02847f5d2fd45a24e219ed93b32) C:\WINDOWS\system32\drivers\Cdfs.sys
16:20:10.0421 3836 Cdfs - ok
16:20:10.0437 3836 Cdrom (1f4260cc5b42272d71f79e570a27a4fe) C:\WINDOWS\system32\DRIVERS\cdrom.sys
16:20:10.0453 3836 Cdrom - ok
16:20:10.0484 3836 Changer - ok
16:20:10.0500 3836 CmBatt (0f6c187d38d98f8df904589a5f94d411) C:\WINDOWS\system32\DRIVERS\CmBatt.sys
16:20:10.0500 3836 CmBatt - ok
16:20:10.0531 3836 CmdIde - ok
16:20:10.0562 3836 Compbatt (6e4c9f21f0fae8940661144f41b13203) C:\WINDOWS\system32\DRIVERS\compbatt.sys
16:20:10.0562 3836 Compbatt - ok
16:20:10.0593 3836 Cpqarray - ok
16:20:10.0718 3836 CrystalSysInfo (f054744f67576a01139885173392502b) C:\Program Files\MediaCoder\SysInfo.sys
16:20:10.0734 3836 CrystalSysInfo - ok
16:20:10.0781 3836 dac2w2k - ok
16:20:10.0796 3836 dac960nt - ok
16:20:10.0875 3836 Disk (044452051f3e02e7963599fc8f4f3e25) C:\WINDOWS\system32\DRIVERS\disk.sys
16:20:10.0875 3836 Disk - ok
16:20:10.0921 3836 dmboot (f5deadd42335fb33edca74ecb2f36cba) C:\WINDOWS\system32\drivers\dmboot.sys
16:20:10.0953 3836 dmboot - ok
16:20:10.0984 3836 dmio (5a7c47c9b3f9fb92a66410a7509f0c71) C:\WINDOWS\system32\drivers\dmio.sys
16:20:10.0984 3836 dmio - ok
16:20:11.0015 3836 dmload (e9317282a63ca4d188c0df5e09c6ac5f) C:\WINDOWS\system32\drivers\dmload.sys
16:20:11.0015 3836 dmload - ok
16:20:11.0109 3836 DMusic (8a208dfcf89792a484e76c40e5f50b45) C:\WINDOWS\system32\drivers\DMusic.sys
16:20:11.0109 3836 DMusic - ok
16:20:11.0171 3836 dpti2o - ok
16:20:11.0187 3836 drmkaud (8f5fcff8e8848afac920905fbd9d33c8) C:\WINDOWS\system32\drivers\drmkaud.sys
16:20:11.0187 3836 drmkaud - ok
16:20:11.0250 3836 dsNcAdpt (b2c3f71b86e25c3df78339ddb40a7562) C:\WINDOWS\system32\DRIVERS\dsNcAdpt.sys
16:20:11.0250 3836 dsNcAdpt - ok
16:20:11.0281 3836 f7bd01a7 (814f20ada863444953f10261740cf4b1) C:\WINDOWS\2801909239:138608216.exe
16:20:11.0281 3836 Suspicious file (Hidden): C:\WINDOWS\2801909239:138608216.exe. md5: 814f20ada863444953f10261740cf4b1
16:20:11.0281 3836 f7bd01a7 ( HiddenFile.Multi.Generic ) - warning
16:20:11.0281 3836 f7bd01a7 - detected HiddenFile.Multi.Generic (1)
16:20:11.0343 3836 Fastfat (38d332a6d56af32635675f132548343e) C:\WINDOWS\system32\drivers\Fastfat.sys
16:20:11.0343 3836 Fastfat - ok
16:20:11.0406 3836 Fdc (92cdd60b6730b9f50f6a1a0c1f8cdc81) C:\WINDOWS\system32\drivers\Fdc.sys
16:20:11.0406 3836 Fdc - ok
16:20:11.0421 3836 Fips (31f923eb2170fc172c81abda0045d18c) C:\WINDOWS\system32\drivers\Fips.sys
16:20:11.0437 3836 Fips - ok
16:20:11.0453 3836 Flpydisk (9d27e7b80bfcdf1cdd9b555862d5e7f0) C:\WINDOWS\system32\drivers\Flpydisk.sys
16:20:11.0468 3836 Flpydisk - ok
16:20:11.0515 3836 FltMgr (b2cf4b0786f8212cb92ed2b50c6db6b0) C:\WINDOWS\system32\DRIVERS\fltMgr.sys
16:20:11.0531 3836 FltMgr - ok
16:20:11.0562 3836 Fs_Rec (3e1e2bd4f39b0e2b7dc4f4d2bcc2779a) C:\WINDOWS\system32\drivers\Fs_Rec.sys
16:20:11.0562 3836 Fs_Rec - ok
16:20:11.0609 3836 Ftdisk (a86859b77b908c18c2657f284aa29fe3) C:\WINDOWS\system32\DRIVERS\ftdisk.sys
16:20:11.0609 3836 Ftdisk - ok
16:20:11.0703 3836 Gpc (0a02c63c8b144bd8c86b103dee7c86a2) C:\WINDOWS\system32\DRIVERS\msgpc.sys
16:20:11.0718 3836 Gpc - ok
16:20:11.0781 3836 HBtnKey (407e41ddb2bfece109132aec296e0d98) C:\WINDOWS\system32\DRIVERS\cpqbttn.sys
16:20:11.0781 3836 HBtnKey - ok
16:20:11.0859 3836 HDAudBus (573c7d0a32852b48f3058cfd8026f511) C:\WINDOWS\system32\DRIVERS\HDAudBus.sys
16:20:11.0859 3836 HDAudBus - ok
16:20:11.0906 3836 HidUsb (ccf82c5ec8a7326c3066de870c06daf1) C:\WINDOWS\system32\DRIVERS\hidusb.sys
16:20:11.0906 3836 HidUsb - ok
16:20:11.0968 3836 hpdskflt (e8a95df23097bca840814d42f2ee5164) C:\WINDOWS\system32\DRIVERS\hpdskflt.sys
16:20:11.0968 3836 hpdskflt - ok
16:20:11.0984 3836 hpn - ok
16:20:12.0031 3836 HpqKbFiltr (35956140e686d53bf676cf0c778880fc) C:\WINDOWS\system32\DRIVERS\HpqKbFiltr.sys
16:20:12.0046 3836 HpqKbFiltr - ok
16:20:12.0125 3836 HTTP (f80a415ef82cd06ffaf0d971528ead38) C:\WINDOWS\system32\Drivers\HTTP.sys
16:20:12.0140 3836 HTTP - ok
16:20:12.0171 3836 i2omgmt - ok
16:20:12.0203 3836 i2omp - ok
16:20:12.0218 3836 i8042prt (a09bdc4ed10e3b2e0ec27bb94af32516) C:\WINDOWS\system32\DRIVERS\i8042prt.sys
16:20:12.0234 3836 i8042prt - ok
16:20:12.0468 3836 ialm (f592a1b020723cfbd3d2722514066449) C:\WINDOWS\system32\DRIVERS\igxpmp32.sys
16:20:12.0609 3836 ialm - ok
16:20:12.0703 3836 iaStor (db0cc620b27a928d968c1a1e9cd9cb87) C:\WINDOWS\system32\DRIVERS\iaStor.sys
16:20:12.0703 3836 iaStor - ok
16:20:12.0765 3836 IFXTPM (667cfdb801df771f47b7c39373c2d850) C:\WINDOWS\system32\DRIVERS\IFXTPM.SYS
16:20:12.0765 3836 IFXTPM - ok
16:20:12.0859 3836 Imapi (083a052659f5310dd8b6a6cb05edcf8e) C:\WINDOWS\system32\DRIVERS\imapi.sys
16:20:12.0859 3836 Imapi - ok
16:20:12.0906 3836 ini910u - ok
16:20:12.0953 3836 IntelIde - ok
16:20:12.0984 3836 intelppm (ad340800c35a42d4de1641a37feea34c) C:\WINDOWS\system32\DRIVERS\intelppm.sys
16:20:12.0984 3836 intelppm - ok
16:20:13.0031 3836 Ip6Fw (3bb22519a194418d5fec05d800a19ad0) C:\WINDOWS\system32\DRIVERS\Ip6Fw.sys
16:20:13.0031 3836 Ip6Fw - ok
16:20:13.0062 3836 IpFilterDriver (731f22ba402ee4b62748adaf6363c182) C:\WINDOWS\system32\DRIVERS\ipfltdrv.sys
16:20:13.0062 3836 IpFilterDriver - ok
16:20:13.0078 3836 IpInIp (b87ab476dcf76e72010632b5550955f5) C:\WINDOWS\system32\DRIVERS\ipinip.sys
16:20:13.0078 3836 IpInIp - ok
16:20:13.0109 3836 IpNat (cc748ea12c6effde940ee98098bf96bb) C:\WINDOWS\system32\DRIVERS\ipnat.sys
16:20:13.0109 3836 IpNat - ok
16:20:13.0187 3836 IPSec (23c74d75e36e7158768dd63d92789a91) C:\WINDOWS\system32\DRIVERS\ipsec.sys
16:20:13.0187 3836 IPSec - ok
16:20:13.0218 3836 IRENUM (c93c9ff7b04d772627a3646d89f7bf89) C:\WINDOWS\system32\DRIVERS\irenum.sys
16:20:13.0218 3836 IRENUM - ok
16:20:13.0265 3836 isapnp (355836975a67b6554bca60328cd6cb74) C:\WINDOWS\system32\DRIVERS\isapnp.sys
16:20:13.0265 3836 isapnp - ok
16:20:13.0328 3836 Kbdclass (16813155807c6881f4bfbf6657424659) C:\WINDOWS\system32\DRIVERS\kbdclass.sys
16:20:13.0328 3836 Kbdclass - ok
16:20:13.0359 3836 kbdhid (94c59cb884ba010c063687c3a50dce8e) C:\WINDOWS\system32\DRIVERS\kbdhid.sys
16:20:13.0359 3836 kbdhid - ok
16:20:13.0421 3836 kmixer (692bcf44383d056aed41b045a323d378) C:\WINDOWS\system32\drivers\kmixer.sys
16:20:13.0421 3836 kmixer - ok
16:20:13.0484 3836 KSecDD (b467646c54cc746128904e1654c750c1) C:\WINDOWS\system32\drivers\KSecDD.sys
16:20:13.0484 3836 KSecDD - ok
16:20:13.0546 3836 Lavasoft Kernexplorer - ok
16:20:13.0640 3836 Lbd (b7c19ec8b0dd7efa58ad41ffeb8b8cda) C:\WINDOWS\system32\DRIVERS\Lbd.sys
16:20:13.0640 3836 Lbd - ok
16:20:13.0656 3836 lbrtfdc - ok
16:20:13.0750 3836 LMIInfo (4f69faaabb7db0d43e327c0b6aab40fc) C:\Program Files\LogMeIn\x86\RaInfo.sys
16:20:13.0765 3836 LMIInfo - ok
16:20:13.0796 3836 lmimirr (4477689e2d8ae6b78ba34c9af4cc1ed1) C:\WINDOWS\system32\DRIVERS\lmimirr.sys
16:20:13.0796 3836 lmimirr - ok
16:20:13.0812 3836 LMIRfsClientNP - ok
16:20:13.0859 3836 LMIRfsDriver (3faa563ddf853320f90259d455a01d79) C:\WINDOWS\system32\drivers\LMIRfsDriver.sys
16:20:13.0859 3836 LMIRfsDriver - ok
16:20:13.0953 3836 mnmdd (4ae068242760a1fb6e1a44bf4e16afa6) C:\WINDOWS\system32\drivers\mnmdd.sys
16:20:13.0953 3836 mnmdd - ok
16:20:14.0031 3836 Modem (510ade9327fe84c10254e1902697e25f) C:\WINDOWS\system32\drivers\Modem.sys
16:20:14.0031 3836 Modem - ok
16:20:14.0093 3836 Mouclass (027c01bd7ef3349aaebc883d8a799efb) C:\WINDOWS\system32\DRIVERS\mouclass.sys
16:20:14.0093 3836 Mouclass - ok
16:20:14.0156 3836 mouhid (124d6846040c79b9c997f78ef4b2a4e5) C:\WINDOWS\system32\DRIVERS\mouhid.sys
16:20:14.0156 3836 mouhid - ok
16:20:14.0171 3836 MountMgr (a80b9a0bad1b73637dbcbba7df72d3fd) C:\WINDOWS\system32\drivers\MountMgr.sys
16:20:14.0171 3836 MountMgr - ok
16:20:14.0171 3836 mraid35x - ok
16:20:14.0218 3836 MRxDAV (e3f17e1ea5256709d4e97ef0da04b3c9) C:\WINDOWS\system32\DRIVERS\mrxdav.sys
16:20:14.0218 3836 MRxDAV - ok
16:20:14.0265 3836 MRxSmb (0ea4d8ed179b75f8afa7998ba22285ca) C:\WINDOWS\system32\DRIVERS\mrxsmb.sys
16:20:14.0281 3836 MRxSmb - ok
16:20:14.0343 3836 Msfs (c941ea2454ba8350021d774daf0f1027) C:\WINDOWS\system32\drivers\Msfs.sys
16:20:14.0343 3836 Msfs - ok
16:20:14.0390 3836 MSKSSRV (d1575e71568f4d9e14ca56b7b0453bf1) C:\WINDOWS\system32\drivers\MSKSSRV.sys
16:20:14.0406 3836 MSKSSRV - ok
16:20:14.0468 3836 MSPCLOCK (325bb26842fc7ccc1fcce2c457317f3e) C:\WINDOWS\system32\drivers\MSPCLOCK.sys
16:20:14.0484 3836 MSPCLOCK - ok
16:20:14.0546 3836 MSPQM (bad59648ba099da4a17680b39730cb3d) C:\WINDOWS\system32\drivers\MSPQM.sys
16:20:14.0546 3836 MSPQM - ok
16:20:14.0609 3836 mssmbios (af5f4f3f14a8ea2c26de30f7a1e17136) C:\WINDOWS\system32\DRIVERS\mssmbios.sys
16:20:14.0609 3836 mssmbios - ok
16:20:14.0656 3836 MSTEE (e53736a9e30c45fa9e7b5eac55056d1d) C:\WINDOWS\system32\drivers\MSTEE.sys
16:20:14.0656 3836 MSTEE - ok
16:20:14.0750 3836 Mup (de6a75f5c270e756c5508d94b6cf68f5) C:\WINDOWS\system32\drivers\Mup.sys
16:20:14.0750 3836 Mup - ok
16:20:14.0812 3836 NABTSFEC (5b50f1b2a2ed47d560577b221da734db) C:\WINDOWS\system32\DRIVERS\NABTSFEC.sys
16:20:14.0812 3836 NABTSFEC - ok
16:20:14.0875 3836 NDIS (1df7f42665c94b825322fae71721130d) C:\WINDOWS\system32\drivers\NDIS.sys
16:20:14.0875 3836 NDIS - ok
16:20:14.0921 3836 NdisIP (7ff1f1fd8609c149aa432f95a8163d97) C:\WINDOWS\system32\DRIVERS\NdisIP.sys
16:20:14.0937 3836 NdisIP - ok
16:20:15.0000 3836 NdisTapi (1ab3d00c991ab086e69db84b6c0ed78f) C:\WINDOWS\system32\DRIVERS\ndistapi.sys
16:20:15.0000 3836 NdisTapi - ok
16:20:15.0078 3836 Ndisuio (f927a4434c5028758a842943ef1a3849) C:\WINDOWS\system32\DRIVERS\ndisuio.sys
16:20:15.0078 3836 Ndisuio - ok
16:20:15.0125 3836 NdisWan (edc1531a49c80614b2cfda43ca8659ab) C:\WINDOWS\system32\DRIVERS\ndiswan.sys
16:20:15.0125 3836 NdisWan - ok
16:20:15.0500 3836 NDProxy (9282bd12dfb069d3889eb3fcc1000a9b) C:\WINDOWS\system32\drivers\NDProxy.sys
16:20:15.0500 3836 NDProxy - ok
16:20:15.0531 3836 NetBIOS (5d81cf9a2f1a3a756b66cf684911cdf0) C:\WINDOWS\system32\DRIVERS\netbios.sys
16:20:15.0546 3836 NetBIOS - ok
16:20:15.0640 3836 NetBT (74b2b2f5bea5e9a3dc021d685551bd3d) C:\WINDOWS\system32\DRIVERS\netbt.sys
16:20:15.0656 3836 NetBT - ok
16:20:15.0843 3836 NETw5x32 (05743fffc2bc88cc8e426321bc6a762e) C:\WINDOWS\system32\DRIVERS\NETw5x32.sys
16:20:15.0937 3836 NETw5x32 - ok
16:20:15.0968 3836 NIC1394 (e9e47cfb2d461fa0fc75b7a74c6383ea) C:\WINDOWS\system32\DRIVERS\nic1394.sys
16:20:15.0968 3836 NIC1394 - ok
16:20:16.0015 3836 nm (1e421a6bcf2203cc61b821ada9de878b) C:\WINDOWS\system32\DRIVERS\NMnt.sys
16:20:16.0015 3836 nm - ok
16:20:16.0093 3836 NPF (243126da7ba441d7c7c3262dcf435a9c) C:\WINDOWS\system32\drivers\npf.sys
16:20:16.0093 3836 NPF - ok
16:20:16.0171 3836 Npfs (3182d64ae053d6fb034f44b6def8034a) C:\WINDOWS\system32\drivers\Npfs.sys
16:20:16.0171 3836 Npfs - ok
16:20:16.0203 3836 Ntfs (78a08dd6a8d65e697c18e1db01c5cdca) C:\WINDOWS\system32\drivers\Ntfs.sys
16:20:16.0234 3836 Ntfs - ok
16:20:16.0296 3836 Null (73c1e1f395918bc2c6dd67af7591a3ad) C:\WINDOWS\system32\drivers\Null.sys
16:20:16.0296 3836 Null - ok
16:20:16.0343 3836 NwlnkFlt (b305f3fad35083837ef46a0bbce2fc57) C:\WINDOWS\system32\DRIVERS\nwlnkflt.sys
16:20:16.0359 3836 NwlnkFlt - ok
16:20:16.0406 3836 NwlnkFwd (c99b3415198d1aab7227f2c88fd664b9) C:\WINDOWS\system32\DRIVERS\nwlnkfwd.sys
16:20:16.0406 3836 NwlnkFwd - ok
16:20:16.0453 3836 ohci1394 (ca33832df41afb202ee7aeb05145922f) C:\WINDOWS\system32\DRIVERS\ohci1394.sys
16:20:16.0453 3836 ohci1394 - ok
16:20:16.0546 3836 Parport (8fd0bdbea875d06ccf6c945ca9abaf75) C:\WINDOWS\system32\DRIVERS\parport.sys
16:20:16.0546 3836 Parport - ok
16:20:16.0578 3836 PartMgr (beb3ba25197665d82ec7065b724171c6) C:\WINDOWS\system32\drivers\PartMgr.sys
16:20:16.0578 3836 PartMgr - ok
16:20:16.0640 3836 ParVdm (9575c5630db8fb804649a6959737154c) C:\WINDOWS\system32\drivers\ParVdm.sys
16:20:16.0640 3836 ParVdm - ok
16:20:16.0718 3836 PCI (043410877bda580c528f45165f7125bc) C:\WINDOWS\system32\DRIVERS\pci.sys
16:20:16.0718 3836 PCI - ok
16:20:16.0750 3836 PCIDump - ok
16:20:16.0765 3836 PCIIde - ok
16:20:16.0828 3836 Pcmcia (f0406cbc60bdb0394a0e17ffb04cdd3d) C:\WINDOWS\system32\drivers\Pcmcia.sys
16:20:16.0828 3836 Pcmcia - ok
16:20:16.0875 3836 PDCOMP - ok
16:20:16.0890 3836 PDFRAME - ok
16:20:16.0906 3836 PDRELI - ok
16:20:16.0984 3836 PDRFRAME - ok
16:20:17.0000 3836 perc2 - ok
16:20:17.0031 3836 perc2hib - ok
16:20:17.0078 3836 PptpMiniport (efeec01b1d3cf84f16ddd24d9d9d8f99) C:\WINDOWS\system32\DRIVERS\raspptp.sys
16:20:17.0078 3836 PptpMiniport - ok
16:20:17.0109 3836 PSched (09298ec810b07e5d582cb3a3f9255424) C:\WINDOWS\system32\DRIVERS\psched.sys
16:20:17.0109 3836 PSched - ok
16:20:17.0125 3836 Ptilink (80d317bd1c3dbc5d4fe7b1678c60cadd) C:\WINDOWS\system32\DRIVERS\ptilink.sys
16:20:17.0125 3836 Ptilink - ok
16:20:17.0140 3836 ql1080 - ok
16:20:17.0156 3836 Ql10wnt - ok
16:20:17.0156 3836 ql12160 - ok
16:20:17.0171 3836 ql1240 - ok
16:20:17.0187 3836 ql1280 - ok
16:20:17.0218 3836 RasAcd (fe0d99d6f31e4fad8159f690d68ded9c) C:\WINDOWS\system32\DRIVERS\rasacd.sys
16:20:17.0218 3836 RasAcd - ok
16:20:17.0281 3836 Rasl2tp (11b4a627bc9614b885c4969bfa5ff8a6) C:\WINDOWS\system32\DRIVERS\rasl2tp.sys
16:20:17.0281 3836 Rasl2tp - ok
16:20:17.0296 3836 RasPppoe (5bc962f2654137c9909c3d4603587dee) C:\WINDOWS\system32\DRIVERS\raspppoe.sys
16:20:17.0296 3836 RasPppoe - ok
16:20:17.0312 3836 Raspti (fdbb1d60066fcfbb7452fd8f9829b242) C:\WINDOWS\system32\DRIVERS\raspti.sys
16:20:17.0312 3836 Raspti - ok
16:20:17.0359 3836 Rdbss (7ad224ad1a1437fe28d89cf22b17780a) C:\WINDOWS\system32\DRIVERS\rdbss.sys
16:20:17.0359 3836 Rdbss - ok
16:20:17.0375 3836 RDPCDD (4912d5b403614ce99c28420f75353332) C:\WINDOWS\system32\DRIVERS\RDPCDD.sys
16:20:17.0375 3836 RDPCDD - ok
16:20:17.0437 3836 rdpdr (15cabd0f7c00c47c70124907916af3f1) C:\WINDOWS\system32\DRIVERS\rdpdr.sys
16:20:17.0437 3836 rdpdr - ok
16:20:17.0515 3836 RDPWD (6728e45b66f93c08f11de2e316fc70dd) C:\WINDOWS\system32\drivers\RDPWD.sys
16:20:17.0515 3836 RDPWD - ok
16:20:17.0546 3836 redbook (bdefd9d248add5d35dfb36485d58ef52) C:\WINDOWS\system32\DRIVERS\redbook.sys
16:20:17.0562 3836 Suspicious file (Forged): C:\WINDOWS\system32\DRIVERS\redbook.sys. Real md5: bdefd9d248add5d35dfb36485d58ef52, Fake md5: d8eb2a7904db6c916eb5361878ddcbae
16:20:17.0562 3836 redbook ( Rootkit.Win32.ZAccess.e ) - infected
16:20:17.0562 3836 redbook - detected Rootkit.Win32.ZAccess.e (0)
16:20:17.0640 3836 SCR3XX2K (fc87d5e0328afa97bf6d39df96d5d356) C:\WINDOWS\system32\DRIVERS\SCR3XX2K.sys
16:20:17.0656 3836 SCR3XX2K - ok
16:20:17.0718 3836 Secdrv (90a3935d05b494a5a39d37e71f09a677) C:\WINDOWS\system32\DRIVERS\secdrv.sys
16:20:17.0718 3836 Secdrv - ok
16:20:17.0765 3836 serenum (0f29512ccd6bead730039fb4bd2c85ce) C:\WINDOWS\system32\DRIVERS\serenum.sys
16:20:17.0765 3836 serenum - ok
16:20:17.0796 3836 Serial (93d313c31f7ad9ea2b75f26075413c7c) C:\WINDOWS\system32\DRIVERS\serial.sys
16:20:17.0796 3836 Serial - ok
16:20:17.0875 3836 SFAUDIO (b6401608579b6431994425ba7653f774) C:\WINDOWS\system32\drivers\sfaudio.sys
16:20:17.0875 3836 SFAUDIO - ok
16:20:17.0968 3836 Sfloppy (8e6b8c671615d126fdc553d1e2de5562) C:\WINDOWS\system32\DRIVERS\sfloppy.sys
16:20:17.0968 3836 Sfloppy - ok
16:20:18.0015 3836 Simbad - ok
16:20:18.0062 3836 SLIP (866d538ebe33709a5c9f5c62b73b7d14) C:\WINDOWS\system32\DRIVERS\SLIP.sys
16:20:18.0062 3836 SLIP - ok
16:20:18.0203 3836 SNP2UVC (cf9cde12fbc19dba8de528b7511a2f4f) C:\WINDOWS\system32\DRIVERS\snp2uvc.sys
16:20:18.0250 3836 SNP2UVC - ok
16:20:18.0281 3836 Sparrow - ok
16:20:18.0343 3836 splitter (ab8b92451ecb048a4d1de7c3ffcb4a9f) C:\WINDOWS\system32\drivers\splitter.sys
16:20:18.0343 3836 splitter - ok
16:20:18.0437 3836 sptd (d15da1ba189770d93eea2d7e18f95af9) C:\WINDOWS\system32\Drivers\sptd.sys
16:20:18.0437 3836 Suspicious file (NoAccess): C:\WINDOWS\system32\Drivers\sptd.sys. md5: d15da1ba189770d93eea2d7e18f95af9
16:20:18.0437 3836 sptd ( LockedFile.Multi.Generic ) - warning
16:20:18.0437 3836 sptd - detected LockedFile.Multi.Generic (1)
16:20:18.0531 3836 sr (39626e6dc1fb39434ec40c42722b660a) C:\WINDOWS\system32\DRIVERS\sr.sys
16:20:18.0531 3836 sr - ok
16:20:18.0625 3836 Srv (47ddfc2f003f7f9f0592c6874962a2e7) C:\WINDOWS\system32\DRIVERS\srv.sys
16:20:18.0625 3836 Srv - ok
16:20:18.0687 3836 streamip (77813007ba6265c4b6098187e6ed79d2) C:\WINDOWS\system32\DRIVERS\StreamIP.sys
16:20:18.0687 3836 streamip - ok
16:20:18.0765 3836 swenum (3941d127aef12e93addf6fe6ee027e0f) C:\WINDOWS\system32\DRIVERS\swenum.sys
16:20:18.0781 3836 swenum - ok
16:20:18.0843 3836 swmidi (8ce882bcc6cf8a62f2b2323d95cb3d01) C:\WINDOWS\system32\drivers\swmidi.sys
16:20:18.0843 3836 swmidi - ok
16:20:18.0906 3836 symc810 - ok
16:20:18.0968 3836 symc8xx - ok
16:20:18.0984 3836 sym_hi - ok
16:20:19.0015 3836 sym_u3 - ok
16:20:19.0093 3836 SynTP (f08667f79bbd339547f477c75c3ed0b9) C:\WINDOWS\system32\DRIVERS\SynTP.sys
16:20:19.0093 3836 SynTP - ok
16:20:19.0125 3836 sysaudio (8b83f3ed0f1688b4958f77cd6d2bf290) C:\WINDOWS\system32\drivers\sysaudio.sys
16:20:19.0125 3836 sysaudio - ok
16:20:19.0203 3836 tap0801 (846b7c0e3f6370cdcce157a5b36e70cd) C:\WINDOWS\system32\DRIVERS\tap0801.sys
16:20:19.0203 3836 tap0801 - ok
16:20:19.0296 3836 Tcpip (9aefa14bd6b182d61e3119fa5f436d3d) C:\WINDOWS\system32\DRIVERS\tcpip.sys
16:20:19.0296 3836 Tcpip - ok
16:20:19.0406 3836 TDPIPE (6471a66807f5e104e4885f5b67349397) C:\WINDOWS\system32\drivers\TDPIPE.sys
16:20:19.0406 3836 TDPIPE - ok
16:20:19.0453 3836 TDTCP (c56b6d0402371cf3700eb322ef3aaf61) C:\WINDOWS\system32\drivers\TDTCP.sys
16:20:19.0453 3836 TDTCP - ok
16:20:19.0500 3836 teamviewervpn (9101fffcfccd1a30e870a5b8a9091b10) C:\WINDOWS\system32\DRIVERS\teamviewervpn.sys
16:20:19.0515 3836 teamviewervpn - ok
16:20:19.0562 3836 TermDD (88155247177638048422893737429d9e) C:\WINDOWS\system32\DRIVERS\termdd.sys
16:20:19.0562 3836 TermDD - ok
16:20:19.0656 3836 tmcomm (eb2283c0a4dfbd2e53d14f2c4d5a1e89) C:\WINDOWS\system32\drivers\tmcomm.sys
16:20:19.0656 3836 tmcomm - ok
16:20:19.0687 3836 TosIde - ok
16:20:19.0875 3836 TrueSight (ddbf8e194041469f26fc6cbc8264beb0) C:\Documents and Settings\dmi\Bureau\TrueSight.sys
16:20:19.0890 3836 TrueSight - ok
16:20:19.0984 3836 Udfs (5787b80c2e3c5e2f56c2a233d91fa2c9) C:\WINDOWS\system32\drivers\Udfs.sys
16:20:19.0984 3836 Udfs - ok
16:20:20.0031 3836 ultra - ok
16:20:20.0093 3836 Update (402ddc88356b1bac0ee3dd1580c76a31) C:\WINDOWS\system32\DRIVERS\update.sys
16:20:20.0109 3836 Update - ok
16:20:20.0171 3836 usbccgp (173f317ce0db8e21322e71b7e60a27e8) C:\WINDOWS\system32\DRIVERS\usbccgp.sys
16:20:20.0171 3836 usbccgp - ok
16:20:20.0265 3836 usbehci (65dcf09d0e37d4c6b11b5b0b76d470a7) C:\WINDOWS\system32\DRIVERS\usbehci.sys
16:20:20.0265 3836 usbehci - ok
16:20:20.0296 3836 usbhub (1ab3cdde553b6e064d2e754efe20285c) C:\WINDOWS\system32\DRIVERS\usbhub.sys
16:20:20.0312 3836 usbhub - ok
16:20:20.0375 3836 usbprint (a717c8721046828520c9edf31288fc00) C:\WINDOWS\system32\DRIVERS\usbprint.sys
16:20:20.0375 3836 usbprint - ok
16:20:20.0437 3836 usbscan (a0b8cf9deb1184fbdd20784a58fa75d4) C:\WINDOWS\system32\DRIVERS\usbscan.sys
16:20:20.0437 3836 usbscan - ok
16:20:20.0500 3836 USBSTOR (a32426d9b14a089eaa1d922e0c5801a9) C:\WINDOWS\system32\DRIVERS\USBSTOR.SYS
16:20:20.0515 3836 USBSTOR - ok
16:20:20.0593 3836 usbuhci (26496f9dee2d787fc3e61ad54821ffe6) C:\WINDOWS\system32\DRIVERS\usbuhci.sys
16:20:20.0593 3836 usbuhci - ok
16:20:20.0656 3836 usbvideo (63bbfca7f390f4c49ed4b96bfb1633e0) C:\WINDOWS\system32\Drivers\usbvideo.sys
16:20:20.0656 3836 usbvideo - ok
16:20:20.0750 3836 VgaSave (0d3a8fafceacd8b7625cd549757a7df1) C:\WINDOWS\System32\drivers\vga.sys
16:20:20.0765 3836 VgaSave - ok
16:20:20.0781 3836 ViaIde - ok
16:20:20.0812 3836 VolSnap (46de1126684369bace4849e4fc8c43ca) C:\WINDOWS\system32\drivers\VolSnap.sys
16:20:20.0812 3836 VolSnap - ok
16:20:20.0859 3836 Wanarp (e20b95baedb550f32dd489265c1da1f6) C:\WINDOWS\system32\DRIVERS\wanarp.sys
16:20:20.0859 3836 Wanarp - ok
16:20:20.0937 3836 Wdf01000 (fd47474bd21794508af449d9d91af6e6) C:\WINDOWS\system32\DRIVERS\Wdf01000.sys
16:20:20.0937 3836 Wdf01000 - ok
16:20:21.0000 3836 WDICA - ok
16:20:21.0062 3836 wdmaud (6768acf64b18196494413695f0c3a00f) C:\WINDOWS\system32\drivers\wdmaud.sys
16:20:21.0062 3836 wdmaud - ok
16:20:21.0156 3836 WmiAcpi (c42584fd66ce9e17403aebca199f7bdb) C:\WINDOWS\system32\DRIVERS\wmiacpi.sys
16:20:21.0156 3836 WmiAcpi - ok
16:20:21.0218 3836 WSTCODEC (c98b39829c2bbd34e454150633c62c78) C:\WINDOWS\system32\DRIVERS\WSTCODEC.SYS
16:20:21.0234 3836 WSTCODEC - ok
16:20:21.0312 3836 WudfPf (f15feafffbb3644ccc80c5da584e6311) C:\WINDOWS\system32\DRIVERS\WudfPf.sys
16:20:21.0312 3836 WudfPf - ok
16:20:21.0390 3836 WudfRd (28b524262bce6de1f7ef9f510ba3985b) C:\WINDOWS\system32\DRIVERS\wudfrd.sys
16:20:21.0390 3836 WudfRd - ok
16:20:21.0437 3836 MBR (0x1B8) (c99c3199cfaa4cbdcd91493f6d113a50) \Device\Harddisk0\DR0
16:20:21.0593 3836 \Device\Harddisk0\DR0 - ok
16:20:21.0609 3836 Boot (0x1200) (7c8d0dcb31f179aff5003f6445918649) \Device\Harddisk0\DR0\Partition0
16:20:21.0609 3836 \Device\Harddisk0\DR0\Partition0 - ok
16:20:21.0609 3836 ============================================================
16:20:21.0609 3836 Scan finished
16:20:21.0609 3836 ============================================================
16:20:21.0625 3224 Detected object count: 3
16:20:21.0625 3224 Actual detected object count: 3
16:22:46.0453 3224 f7bd01a7 ( HiddenFile.Multi.Generic ) - skipped by user
16:22:46.0453 3224 f7bd01a7 ( HiddenFile.Multi.Generic ) - User select action: Skip
16:22:48.0203 3224 Backup copy found, using it..
16:22:48.0218 3224 C:\WINDOWS\system32\DRIVERS\redbook.sys - will be cured on reboot
16:22:48.0218 3224 redbook ( Rootkit.Win32.ZAccess.e ) - User select action: Cure
16:22:48.0234 3224 sptd ( LockedFile.Multi.Generic ) - skipped by user
16:22:48.0234 3224 sptd ( LockedFile.Multi.Generic ) - User select action: Skip
16:23:12.0718 1036 Deinitialize success
Voici le rapport émis par "RogueKiller" :

RogueKiller V6.1.0 [22/09/2011] par Tigzy
contact sur http://www.sur-la-toile.com
mail: tigzyRK<at>gmail<dot>com
Remontees: http://www.sur-la-toile.com/discussion-193725-1-BRogueKillerD-Remontees.html

Systeme d'exploitation: Windows XP (5.1.2600 Service Pack 3) 32 bits version
Demarrage : Mode normal
Utilisateur: dmi [Droits d'admin]
Mode: Recherche -- Date : 27/09/2011 16:11:16

Processus malicieux: 2
[SUSP PATH] 2801909239:138608216.exe -- c:\windows\2801909239:138608216.exe -> KILLED [TermProc]
[RESIDUE] 2801909239:138608216.exe -- c:\windows\2801909239:138608216.exe -> KILLED [TermProc]

Entrees de registre: 1
[HJ] HKLM\[...]\NewStartPanel : {20D04FE0-3AEA-1069-A2D8-08002B30309D} (1) -> FOUND

Fichiers / Dossiers particuliers:

Driver: [LOADED]
SSDT[277] : NtWriteVirtualMemory @ 0x805B43CC -> HOOKED (\SystemRoot\system32\DRIVERS\AVGIDSShim.Sys @ 0xB431A914)
SSDT[258] : NtTerminateThread @ 0x805D2BDC -> HOOKED (\SystemRoot\system32\DRIVERS\AVGIDSShim.Sys @ 0xB431A878)
SSDT[257] : NtTerminateProcess @ 0x805D29E2 -> HOOKED (\SystemRoot\system32\DRIVERS\AVGIDSShim.Sys @ 0xB431A7DC)
SSDT[247] : NtSetValueKey @ 0x80622662 -> HOOKED (Lbd.sys @ 0xBA118BFE)
SSDT[241] : NtSetSystemPowerState @ 0x80653E18 -> HOOKED (a347bus.sys @ 0xB9E73550)
SSDT[177] : NtQueryValueKey @ 0x80622314 -> HOOKED (a347bus.sys @ 0xB9E74076)
SSDT[160] : NtQueryKey @ 0x80625810 -> HOOKED (a347bus.sys @ 0xB9E685FC)
SSDT[122] : NtOpenProcess @ 0x805CB440 -> HOOKED (\SystemRoot\system32\DRIVERS\AVGIDSShim.Sys @ 0xB431A738)
SSDT[119] : NtOpenKey @ 0x806254CE -> HOOKED (a347bus.sys @ 0xB9E73FA4)
SSDT[116] : NtOpenFile @ 0x8057A1A6 -> HOOKED (a347bus.sys @ 0xB9E67B40)
SSDT[73] : NtEnumerateValueKey @ 0x80624BA6 -> HOOKED (a347bus.sys @ 0xB9E74120)
SSDT[71] : NtEnumerateKey @ 0x8062493C -> HOOKED (a347bus.sys @ 0xB9E685DC)
SSDT[45] : NtCreatePagingFile @ 0x805AB9EE -> HOOKED (a347bus.sys @ 0xB9E67B00)
SSDT[41] : NtCreateKey @ 0x806240F0 -> HOOKED (Lbd.sys @ 0xBA11887E)
SSDT[25] : NtClose @ 0x805BC530 -> HOOKED (a347bus.sys @ 0xB9E74028)
S_SSDT[549] : Unknown -> HOOKED (\SystemRoot\system32\DRIVERS\AVGIDSShim.Sys @ 0xB4319CBA)
S_SSDT[416] : Unknown -> HOOKED (\SystemRoot\system32\DRIVERS\AVGIDSShim.Sys @ 0xB4319D90)
S_SSDT[414] : Unknown -> HOOKED (\SystemRoot\system32\DRIVERS\AVGIDSShim.Sys @ 0xB4319D3C)
S_SSDT[383] : Unknown -> HOOKED (\SystemRoot\system32\DRIVERS\AVGIDSShim.Sys @ 0xB4319DFC)

Fichier HOSTS:


Termine : << RKreport[1].txt >>
RKreport[1].txt
Messages postés
35445
Date d'inscription
jeudi 18 décembre 2008
Statut
Contributeur sécurité
Dernière intervention
5 mai 2017
4 783
Pourquoi as-tu fait RogueKiller ? On te l'a demandé ?

Refais TDSS Killer, et cette fois supprime ces 2 détections: f7bd01a7

Ensuite redémarre et fais à nouveau TDSS Killer
Vraiment un tout grand merci pour ton aide....

J'avais exécuter RogueKiller car, avant de voir ta réponse, sur un autre forum, j'avais lu que c'était un préalable avant de de poster un message.

Voici maintenant le rapport de TDSS Killer après avoir redémarré le pc :

16:43:08.0859 2856 TDSS rootkit removing tool 2.6.2.0 Sep 26 2011 18:56:43
16:43:08.0968 2856 ============================================================
16:43:08.0968 2856 Current date / time: 2011/09/27 16:43:08.0968
16:43:08.0968 2856 SystemInfo:
16:43:08.0968 2856
16:43:08.0968 2856 OS Version: 5.1.2600 ServicePack: 3.0
16:43:08.0968 2856 Product type: Workstation
16:43:08.0968 2856 ComputerName: CHR
16:43:08.0968 2856 UserName: dmi
16:43:08.0968 2856 Windows directory: C:\WINDOWS
16:43:08.0968 2856 System windows directory: C:\WINDOWS
16:43:08.0968 2856 Processor architecture: Intel x86
16:43:08.0968 2856 Number of processors: 2
16:43:08.0968 2856 Page size: 0x1000
16:43:08.0968 2856 Boot type: Normal boot
16:43:08.0968 2856 ============================================================
16:43:09.0375 2856 Initialize success
16:43:11.0203 2888 ============================================================
16:43:11.0203 2888 Scan started
16:43:11.0203 2888 Mode: Manual;
16:43:11.0203 2888 ============================================================
16:43:11.0828 2888 a347bus (1f61cacacb521215f39061789147968c) C:\WINDOWS\system32\DRIVERS\a347bus.sys
16:43:11.0828 2888 a347bus - ok
16:43:11.0859 2888 a347scsi (113e4b318bbaa7483ca4e582a4d63f49) C:\WINDOWS\system32\Drivers\a347scsi.sys
16:43:11.0859 2888 a347scsi - ok
16:43:11.0875 2888 Abiosdsk - ok
16:43:11.0906 2888 abp480n5 - ok
16:43:11.0953 2888 Accelerometer (6c2e405d98e6342a9d66a2493e7ab15e) C:\WINDOWS\system32\DRIVERS\Accelerometer.sys
16:43:11.0953 2888 Accelerometer - ok
16:43:12.0000 2888 ACPI (e5e6dbfc41ea8aad005cb9a57a96b43b) C:\WINDOWS\system32\DRIVERS\ACPI.sys
16:43:12.0015 2888 ACPI - ok
16:43:12.0062 2888 ACPIEC (e4abc1212b70bb03d35e60681c447210) C:\WINDOWS\system32\DRIVERS\ACPIEC.sys
16:43:12.0062 2888 ACPIEC - ok
16:43:12.0156 2888 ADIHdAudAddService (ff60db2aca88543c025eacba25cee5c1) C:\WINDOWS\system32\drivers\ADIHdAud.sys
16:43:12.0156 2888 ADIHdAudAddService - ok
16:43:12.0187 2888 adpu160m - ok
16:43:12.0218 2888 AEAudio (fff87a9b1ab36ee4b7bec98a4cb01b79) C:\WINDOWS\system32\drivers\AEAudio.sys
16:43:12.0218 2888 AEAudio - ok
16:43:12.0281 2888 aec (8bed39e3c35d6a489438b8141717a557) C:\WINDOWS\system32\drivers\aec.sys
16:43:12.0296 2888 aec - ok
16:43:12.0375 2888 AFD (355556d9e580915118cd7ef736653a89) C:\WINDOWS\System32\drivers\afd.sys
16:43:12.0375 2888 AFD - ok
16:43:12.0468 2888 AgereSoftModem (1cfeba39fc613e45b49d3eddfbcda289) C:\WINDOWS\system32\DRIVERS\AGRSM.sys
16:43:12.0515 2888 AgereSoftModem - ok
16:43:12.0546 2888 Aha154x - ok
16:43:12.0562 2888 aic78u2 - ok
16:43:12.0593 2888 aic78xx - ok
16:43:12.0625 2888 AliIde - ok
16:43:12.0640 2888 amsint - ok
16:43:12.0718 2888 Arp1394 (b5b8a80875c1dededa8b02765642c32f) C:\WINDOWS\system32\DRIVERS\arp1394.sys
16:43:12.0718 2888 Arp1394 - ok
16:43:12.0750 2888 asc - ok
16:43:12.0765 2888 asc3350p - ok
16:43:12.0796 2888 asc3550 - ok
16:43:12.0843 2888 AsyncMac (b153affac761e7f5fcfa822b9c4e97bc) C:\WINDOWS\system32\DRIVERS\asyncmac.sys
16:43:12.0843 2888 AsyncMac - ok
16:43:12.0875 2888 atapi (9f3a2f5aa6875c72bf062c712cfa2674) C:\WINDOWS\system32\drivers\atapi.sys
16:43:12.0890 2888 atapi - ok
16:43:12.0906 2888 Atdisk - ok
16:43:12.0953 2888 Atmarpc (9916c1225104ba14794209cfa8012159) C:\WINDOWS\system32\DRIVERS\atmarpc.sys
16:43:12.0968 2888 Atmarpc - ok
16:43:13.0062 2888 ATSwpWDF (a9f9d1d24441889beb1aa2b917457e23) C:\WINDOWS\system32\Drivers\ATSwpWDF.sys
16:43:13.0062 2888 ATSwpWDF - ok
16:43:13.0140 2888 audstub (d9f724aa26c010a217c97606b160ed68) C:\WINDOWS\system32\DRIVERS\audstub.sys
16:43:13.0140 2888 audstub - ok
16:43:13.0218 2888 AVGIDSDriver (2d18221aab3db2d408d6c55c0f23090a) C:\WINDOWS\system32\DRIVERS\AVGIDSDriver.Sys
16:43:13.0234 2888 AVGIDSDriver - ok
16:43:13.0312 2888 AVGIDSEH (1af676db3f3d4cc709cfab2571cf5fc3) C:\WINDOWS\system32\DRIVERS\AVGIDSEH.Sys
16:43:13.0312 2888 AVGIDSEH - ok
16:43:13.0343 2888 AVGIDSFilter (4c51e233c87f9ec7598551de554bc99d) C:\WINDOWS\system32\DRIVERS\AVGIDSFilter.Sys
16:43:13.0343 2888 AVGIDSFilter - ok
16:43:13.0406 2888 AVGIDSShim (c3fc426e54f55c1cc3219e415b88e10c) C:\WINDOWS\system32\DRIVERS\AVGIDSShim.Sys
16:43:13.0421 2888 AVGIDSShim - ok
16:43:13.0484 2888 Avgldx86 (4e796d3d2c3182b13b3e3b5a2ad4ef0a) C:\WINDOWS\system32\DRIVERS\avgldx86.sys
16:43:13.0484 2888 Avgldx86 - ok
16:43:13.0515 2888 Avgmfx86 (5639de66b37d02bd22df4cf3155fba60) C:\WINDOWS\system32\DRIVERS\avgmfx86.sys
16:43:13.0515 2888 Avgmfx86 - ok
16:43:13.0546 2888 Avgrkx86 (d1baf652eda0ae70896276a1fb32c2d4) C:\WINDOWS\system32\DRIVERS\avgrkx86.sys
16:43:13.0562 2888 Avgrkx86 - ok
16:43:13.0609 2888 Avgtdix (aaf0ebcad95f2164cffb544e00392498) C:\WINDOWS\system32\DRIVERS\avgtdix.sys
16:43:13.0609 2888 Avgtdix - ok
16:43:13.0703 2888 b57w2k (ea377a8e8e1000877210259750cbbf5f) C:\WINDOWS\system32\DRIVERS\b57xp32.sys
16:43:13.0718 2888 b57w2k - ok
16:43:13.0781 2888 Beep (da1f27d85e0d1525f6621372e7b685e9) C:\WINDOWS\system32\drivers\Beep.sys
16:43:13.0796 2888 Beep - ok
16:43:13.0937 2888 BTKRNL (ef5e0de0a7ca2977a9255f36f4d915ab) C:\WINDOWS\system32\DRIVERS\btkrnl.sys
16:43:13.0953 2888 BTKRNL - ok
16:43:13.0984 2888 BTWUSB (053dc5be74621b63bb48c2b86bafc7b0) C:\WINDOWS\system32\Drivers\btwusb.sys
16:43:13.0984 2888 BTWUSB - ok
16:43:14.0031 2888 cbidf2k (90a673fc8e12a79afbed2576f6a7aaf9) C:\WINDOWS\system32\drivers\cbidf2k.sys
16:43:14.0031 2888 cbidf2k - ok
16:43:14.0109 2888 CCDECODE (0be5aef125be881c4f854c554f2b025c) C:\WINDOWS\system32\DRIVERS\CCDECODE.sys
16:43:14.0109 2888 CCDECODE - ok
16:43:14.0140 2888 cd20xrnt - ok
16:43:14.0187 2888 Cdaudio (c1b486a7658353d33a10cc15211a873b) C:\WINDOWS\system32\drivers\Cdaudio.sys
16:43:14.0187 2888 Cdaudio - ok
16:43:14.0296 2888 Cdfs (c885b02847f5d2fd45a24e219ed93b32) C:\WINDOWS\system32\drivers\Cdfs.sys
16:43:14.0296 2888 Cdfs - ok
16:43:14.0328 2888 Cdrom (1f4260cc5b42272d71f79e570a27a4fe) C:\WINDOWS\system32\DRIVERS\cdrom.sys
16:43:14.0328 2888 Cdrom - ok
16:43:14.0359 2888 Changer - ok
16:43:14.0421 2888 CmBatt (0f6c187d38d98f8df904589a5f94d411) C:\WINDOWS\system32\DRIVERS\CmBatt.sys
16:43:14.0421 2888 CmBatt - ok
16:43:14.0453 2888 CmdIde - ok
16:43:14.0484 2888 Compbatt (6e4c9f21f0fae8940661144f41b13203) C:\WINDOWS\system32\DRIVERS\compbatt.sys
16:43:14.0500 2888 Compbatt - ok
16:43:14.0546 2888 Cpqarray - ok
16:43:14.0656 2888 CrystalSysInfo (f054744f67576a01139885173392502b) C:\Program Files\MediaCoder\SysInfo.sys
16:43:14.0656 2888 CrystalSysInfo - ok
16:43:14.0703 2888 dac2w2k - ok
16:43:14.0718 2888 dac960nt - ok
16:43:14.0796 2888 Disk (044452051f3e02e7963599fc8f4f3e25) C:\WINDOWS\system32\DRIVERS\disk.sys
16:43:14.0812 2888 Disk - ok
16:43:14.0875 2888 dmboot (f5deadd42335fb33edca74ecb2f36cba) C:\WINDOWS\system32\drivers\dmboot.sys
16:43:14.0906 2888 dmboot - ok
16:43:14.0968 2888 dmio (5a7c47c9b3f9fb92a66410a7509f0c71) C:\WINDOWS\system32\drivers\dmio.sys
16:43:14.0984 2888 dmio - ok
16:43:15.0015 2888 dmload (e9317282a63ca4d188c0df5e09c6ac5f) C:\WINDOWS\system32\drivers\dmload.sys
16:43:15.0015 2888 dmload - ok
16:43:15.0109 2888 DMusic (8a208dfcf89792a484e76c40e5f50b45) C:\WINDOWS\system32\drivers\DMusic.sys
16:43:15.0125 2888 DMusic - ok
16:43:15.0140 2888 dpti2o - ok
16:43:15.0171 2888 drmkaud (8f5fcff8e8848afac920905fbd9d33c8) C:\WINDOWS\system32\drivers\drmkaud.sys
16:43:15.0171 2888 drmkaud - ok
16:43:15.0218 2888 dsNcAdpt (b2c3f71b86e25c3df78339ddb40a7562) C:\WINDOWS\system32\DRIVERS\dsNcAdpt.sys
16:43:15.0218 2888 dsNcAdpt - ok
16:43:15.0281 2888 f7bd01a7 (814f20ada863444953f10261740cf4b1) C:\WINDOWS\2801909239:138608216.exe
16:43:16.0062 2888 Suspicious file (Hidden): C:\WINDOWS\2801909239:138608216.exe. md5: 814f20ada863444953f10261740cf4b1
16:43:16.0062 2888 f7bd01a7 ( HiddenFile.Multi.Generic ) - warning
16:43:16.0062 2888 f7bd01a7 - detected HiddenFile.Multi.Generic (1)
16:43:16.0156 2888 Fastfat (38d332a6d56af32635675f132548343e) C:\WINDOWS\system32\drivers\Fastfat.sys
16:43:16.0156 2888 Fastfat - ok
16:43:16.0203 2888 Fdc (92cdd60b6730b9f50f6a1a0c1f8cdc81) C:\WINDOWS\system32\drivers\Fdc.sys
16:43:16.0203 2888 Fdc - ok
16:43:16.0234 2888 Fips (31f923eb2170fc172c81abda0045d18c) C:\WINDOWS\system32\drivers\Fips.sys
16:43:16.0234 2888 Fips - ok
16:43:16.0250 2888 Flpydisk (9d27e7b80bfcdf1cdd9b555862d5e7f0) C:\WINDOWS\system32\drivers\Flpydisk.sys
16:43:16.0250 2888 Flpydisk - ok
16:43:16.0312 2888 FltMgr (b2cf4b0786f8212cb92ed2b50c6db6b0) C:\WINDOWS\system32\DRIVERS\fltMgr.sys
16:43:16.0312 2888 FltMgr - ok
16:43:16.0343 2888 Fs_Rec (3e1e2bd4f39b0e2b7dc4f4d2bcc2779a) C:\WINDOWS\system32\drivers\Fs_Rec.sys
16:43:16.0359 2888 Fs_Rec - ok
16:43:16.0390 2888 Ftdisk (a86859b77b908c18c2657f284aa29fe3) C:\WINDOWS\system32\DRIVERS\ftdisk.sys
16:43:16.0406 2888 Ftdisk - ok
16:43:16.0500 2888 Gpc (0a02c63c8b144bd8c86b103dee7c86a2) C:\WINDOWS\system32\DRIVERS\msgpc.sys
16:43:16.0500 2888 Gpc - ok
16:43:16.0562 2888 HBtnKey (407e41ddb2bfece109132aec296e0d98) C:\WINDOWS\system32\DRIVERS\cpqbttn.sys
16:43:16.0578 2888 HBtnKey - ok
16:43:16.0640 2888 HDAudBus (573c7d0a32852b48f3058cfd8026f511) C:\WINDOWS\system32\DRIVERS\HDAudBus.sys
16:43:16.0640 2888 HDAudBus - ok
16:43:16.0687 2888 HidUsb (ccf82c5ec8a7326c3066de870c06daf1) C:\WINDOWS\system32\DRIVERS\hidusb.sys
16:43:16.0687 2888 HidUsb - ok
16:43:16.0734 2888 hpdskflt (e8a95df23097bca840814d42f2ee5164) C:\WINDOWS\system32\DRIVERS\hpdskflt.sys
16:43:16.0734 2888 hpdskflt - ok
16:43:16.0765 2888 hpn - ok
16:43:16.0828 2888 HpqKbFiltr (35956140e686d53bf676cf0c778880fc) C:\WINDOWS\system32\DRIVERS\HpqKbFiltr.sys
16:43:16.0843 2888 HpqKbFiltr - ok
16:43:16.0937 2888 HTTP (f80a415ef82cd06ffaf0d971528ead38) C:\WINDOWS\system32\Drivers\HTTP.sys
16:43:16.0937 2888 HTTP - ok
16:43:16.0984 2888 i2omgmt - ok
16:43:17.0015 2888 i2omp - ok
16:43:17.0062 2888 i8042prt (a09bdc4ed10e3b2e0ec27bb94af32516) C:\WINDOWS\system32\DRIVERS\i8042prt.sys
16:43:17.0062 2888 i8042prt - ok
16:43:17.0343 2888 ialm (f592a1b020723cfbd3d2722514066449) C:\WINDOWS\system32\DRIVERS\igxpmp32.sys
16:43:17.0562 2888 ialm - ok
16:43:17.0703 2888 iaStor (db0cc620b27a928d968c1a1e9cd9cb87) C:\WINDOWS\system32\DRIVERS\iaStor.sys
16:43:17.0703 2888 iaStor - ok
16:43:17.0781 2888 IFXTPM (667cfdb801df771f47b7c39373c2d850) C:\WINDOWS\system32\DRIVERS\IFXTPM.SYS
16:43:17.0781 2888 IFXTPM - ok
16:43:17.0843 2888 Imapi (083a052659f5310dd8b6a6cb05edcf8e) C:\WINDOWS\system32\DRIVERS\imapi.sys
16:43:17.0843 2888 Imapi - ok
16:43:17.0875 2888 ini910u - ok
16:43:17.0906 2888 IntelIde - ok
16:43:17.0968 2888 intelppm (ad340800c35a42d4de1641a37feea34c) C:\WINDOWS\system32\DRIVERS\intelppm.sys
16:43:17.0968 2888 intelppm - ok
16:43:18.0031 2888 Ip6Fw (3bb22519a194418d5fec05d800a19ad0) C:\WINDOWS\system32\DRIVERS\Ip6Fw.sys
16:43:18.0031 2888 Ip6Fw - ok
16:43:18.0093 2888 IpFilterDriver (731f22ba402ee4b62748adaf6363c182) C:\WINDOWS\system32\DRIVERS\ipfltdrv.sys
16:43:18.0109 2888 IpFilterDriver - ok
16:43:18.0140 2888 IpInIp (b87ab476dcf76e72010632b5550955f5) C:\WINDOWS\system32\DRIVERS\ipinip.sys
16:43:18.0140 2888 IpInIp - ok
16:43:18.0203 2888 IpNat (cc748ea12c6effde940ee98098bf96bb) C:\WINDOWS\system32\DRIVERS\ipnat.sys
16:43:18.0203 2888 IpNat - ok
16:43:18.0250 2888 IPSec (23c74d75e36e7158768dd63d92789a91) C:\WINDOWS\system32\DRIVERS\ipsec.sys
16:43:18.0250 2888 IPSec - ok
16:43:18.0296 2888 IRENUM (c93c9ff7b04d772627a3646d89f7bf89) C:\WINDOWS\system32\DRIVERS\irenum.sys
16:43:18.0296 2888 IRENUM - ok
16:43:18.0390 2888 isapnp (355836975a67b6554bca60328cd6cb74) C:\WINDOWS\system32\DRIVERS\isapnp.sys
16:43:18.0390 2888 isapnp - ok
16:43:18.0453 2888 Kbdclass (16813155807c6881f4bfbf6657424659) C:\WINDOWS\system32\DRIVERS\kbdclass.sys
16:43:18.0453 2888 Kbdclass - ok
16:43:18.0515 2888 kbdhid (94c59cb884ba010c063687c3a50dce8e) C:\WINDOWS\system32\DRIVERS\kbdhid.sys
16:43:18.0531 2888 kbdhid - ok
16:43:18.0578 2888 kmixer (692bcf44383d056aed41b045a323d378) C:\WINDOWS\system32\drivers\kmixer.sys
16:43:18.0593 2888 kmixer - ok
16:43:18.0640 2888 KSecDD (b467646c54cc746128904e1654c750c1) C:\WINDOWS\system32\drivers\KSecDD.sys
16:43:18.0640 2888 KSecDD - ok
16:43:18.0687 2888 Lavasoft Kernexplorer - ok
16:43:18.0781 2888 Lbd (b7c19ec8b0dd7efa58ad41ffeb8b8cda) C:\WINDOWS\system32\DRIVERS\Lbd.sys
16:43:18.0781 2888 Lbd - ok
16:43:18.0796 2888 lbrtfdc - ok
16:43:18.0906 2888 LMIInfo (4f69faaabb7db0d43e327c0b6aab40fc) C:\Program Files\LogMeIn\x86\RaInfo.sys
16:43:18.0906 2888 LMIInfo - ok
16:43:18.0953 2888 lmimirr (4477689e2d8ae6b78ba34c9af4cc1ed1) C:\WINDOWS\system32\DRIVERS\lmimirr.sys
16:43:18.0953 2888 lmimirr - ok
16:43:18.0984 2888 LMIRfsClientNP - ok
16:43:19.0000 2888 LMIRfsDriver (3faa563ddf853320f90259d455a01d79) C:\WINDOWS\system32\drivers\LMIRfsDriver.sys
16:43:19.0000 2888 LMIRfsDriver - ok
16:43:19.0093 2888 mnmdd (4ae068242760a1fb6e1a44bf4e16afa6) C:\WINDOWS\system32\drivers\mnmdd.sys
16:43:19.0093 2888 mnmdd - ok
16:43:19.0171 2888 Modem (510ade9327fe84c10254e1902697e25f) C:\WINDOWS\system32\drivers\Modem.sys
16:43:19.0171 2888 Modem - ok
16:43:19.0234 2888 Mouclass (027c01bd7ef3349aaebc883d8a799efb) C:\WINDOWS\system32\DRIVERS\mouclass.sys
16:43:19.0250 2888 Mouclass - ok
16:43:19.0312 2888 mouhid (124d6846040c79b9c997f78ef4b2a4e5) C:\WINDOWS\system32\DRIVERS\mouhid.sys
16:43:19.0312 2888 mouhid - ok
16:43:19.0359 2888 MountMgr (a80b9a0bad1b73637dbcbba7df72d3fd) C:\WINDOWS\system32\drivers\MountMgr.sys
16:43:19.0359 2888 MountMgr - ok
16:43:19.0375 2888 mraid35x - ok
16:43:19.0437 2888 MRxDAV (e3f17e1ea5256709d4e97ef0da04b3c9) C:\WINDOWS\system32\DRIVERS\mrxdav.sys
16:43:19.0437 2888 MRxDAV - ok
16:43:19.0531 2888 MRxSmb (0ea4d8ed179b75f8afa7998ba22285ca) C:\WINDOWS\system32\DRIVERS\mrxsmb.sys
16:43:19.0546 2888 MRxSmb - ok
16:43:19.0625 2888 Msfs (c941ea2454ba8350021d774daf0f1027) C:\WINDOWS\system32\drivers\Msfs.sys
16:43:19.0625 2888 Msfs - ok
16:43:19.0703 2888 MSKSSRV (d1575e71568f4d9e14ca56b7b0453bf1) C:\WINDOWS\system32\drivers\MSKSSRV.sys
16:43:19.0703 2888 MSKSSRV - ok
16:43:19.0718 2888 MSPCLOCK (325bb26842fc7ccc1fcce2c457317f3e) C:\WINDOWS\system32\drivers\MSPCLOCK.sys
16:43:19.0718 2888 MSPCLOCK - ok
16:43:19.0734 2888 MSPQM (bad59648ba099da4a17680b39730cb3d) C:\WINDOWS\system32\drivers\MSPQM.sys
16:43:19.0750 2888 MSPQM - ok
16:43:19.0781 2888 mssmbios (af5f4f3f14a8ea2c26de30f7a1e17136) C:\WINDOWS\system32\DRIVERS\mssmbios.sys
16:43:19.0781 2888 mssmbios - ok
16:43:19.0828 2888 MSTEE (e53736a9e30c45fa9e7b5eac55056d1d) C:\WINDOWS\system32\drivers\MSTEE.sys
16:43:19.0843 2888 MSTEE - ok
16:43:19.0859 2888 Mup (de6a75f5c270e756c5508d94b6cf68f5) C:\WINDOWS\system32\drivers\Mup.sys
16:43:19.0906 2888 Mup - ok
16:43:19.0937 2888 NABTSFEC (5b50f1b2a2ed47d560577b221da734db) C:\WINDOWS\system32\DRIVERS\NABTSFEC.sys
16:43:19.0953 2888 NABTSFEC - ok
16:43:19.0984 2888 NDIS (1df7f42665c94b825322fae71721130d) C:\WINDOWS\system32\drivers\NDIS.sys
16:43:20.0000 2888 NDIS - ok
16:43:20.0078 2888 NdisIP (7ff1f1fd8609c149aa432f95a8163d97) C:\WINDOWS\system32\DRIVERS\NdisIP.sys
16:43:20.0078 2888 NdisIP - ok
16:43:20.0140 2888 NdisTapi (1ab3d00c991ab086e69db84b6c0ed78f) C:\WINDOWS\system32\DRIVERS\ndistapi.sys
16:43:20.0156 2888 NdisTapi - ok
16:43:20.0203 2888 Ndisuio (f927a4434c5028758a842943ef1a3849) C:\WINDOWS\system32\DRIVERS\ndisuio.sys
16:43:20.0203 2888 Ndisuio - ok
16:43:20.0234 2888 NdisWan (edc1531a49c80614b2cfda43ca8659ab) C:\WINDOWS\system32\DRIVERS\ndiswan.sys
16:43:20.0250 2888 NdisWan - ok
16:43:20.0281 2888 NDProxy (9282bd12dfb069d3889eb3fcc1000a9b) C:\WINDOWS\system32\drivers\NDProxy.sys
16:43:20.0281 2888 NDProxy - ok
16:43:20.0312 2888 NetBIOS (5d81cf9a2f1a3a756b66cf684911cdf0) C:\WINDOWS\system32\DRIVERS\netbios.sys
16:43:20.0328 2888 NetBIOS - ok
16:43:20.0359 2888 NetBT (74b2b2f5bea5e9a3dc021d685551bd3d) C:\WINDOWS\system32\DRIVERS\netbt.sys
16:43:20.0359 2888 NetBT - ok
16:43:20.0546 2888 NETw5x32 (05743fffc2bc88cc8e426321bc6a762e) C:\WINDOWS\system32\DRIVERS\NETw5x32.sys
16:43:20.0671 2888 NETw5x32 - ok
16:43:20.0687 2888 NIC1394 (e9e47cfb2d461fa0fc75b7a74c6383ea) C:\WINDOWS\system32\DRIVERS\nic1394.sys
16:43:20.0687 2888 NIC1394 - ok
16:43:20.0750 2888 nm (1e421a6bcf2203cc61b821ada9de878b) C:\WINDOWS\system32\DRIVERS\NMnt.sys
16:43:20.0750 2888 nm - ok
16:43:20.0828 2888 NPF (243126da7ba441d7c7c3262dcf435a9c) C:\WINDOWS\system32\drivers\npf.sys
16:43:20.0828 2888 NPF - ok
16:43:20.0921 2888 Npfs (3182d64ae053d6fb034f44b6def8034a) C:\WINDOWS\system32\drivers\Npfs.sys
16:43:20.0921 2888 Npfs - ok
16:43:21.0015 2888 Ntfs (78a08dd6a8d65e697c18e1db01c5cdca) C:\WINDOWS\system32\drivers\Ntfs.sys
16:43:21.0046 2888 Ntfs - ok
16:43:21.0125 2888 Null (73c1e1f395918bc2c6dd67af7591a3ad) C:\WINDOWS\system32\drivers\Null.sys
16:43:21.0125 2888 Null - ok
16:43:21.0171 2888 NwlnkFlt (b305f3fad35083837ef46a0bbce2fc57) C:\WINDOWS\system32\DRIVERS\nwlnkflt.sys
16:43:21.0171 2888 NwlnkFlt - ok
16:43:21.0218 2888 NwlnkFwd (c99b3415198d1aab7227f2c88fd664b9) C:\WINDOWS\system32\DRIVERS\nwlnkfwd.sys
16:43:21.0218 2888 NwlnkFwd - ok
16:43:21.0265 2888 ohci1394 (ca33832df41afb202ee7aeb05145922f) C:\WINDOWS\system32\DRIVERS\ohci1394.sys
16:43:21.0265 2888 ohci1394 - ok
16:43:21.0328 2888 Parport (8fd0bdbea875d06ccf6c945ca9abaf75) C:\WINDOWS\system32\DRIVERS\parport.sys
16:43:21.0343 2888 Parport - ok
16:43:21.0375 2888 PartMgr (beb3ba25197665d82ec7065b724171c6) C:\WINDOWS\system32\drivers\PartMgr.sys
16:43:21.0375 2888 PartMgr - ok
16:43:21.0421 2888 ParVdm (9575c5630db8fb804649a6959737154c) C:\WINDOWS\system32\drivers\ParVdm.sys
16:43:21.0421 2888 ParVdm - ok
16:43:21.0500 2888 PCI (043410877bda580c528f45165f7125bc) C:\WINDOWS\system32\DRIVERS\pci.sys
16:43:21.0515 2888 PCI - ok
16:43:21.0531 2888 PCIDump - ok
16:43:21.0562 2888 PCIIde - ok
16:43:21.0609 2888 Pcmcia (f0406cbc60bdb0394a0e17ffb04cdd3d) C:\WINDOWS\system32\drivers\Pcmcia.sys
16:43:21.0625 2888 Pcmcia - ok
16:43:21.0656 2888 PDCOMP - ok
16:43:21.0671 2888 PDFRAME - ok
16:43:21.0718 2888 PDRELI - ok
16:43:21.0765 2888 PDRFRAME - ok
16:43:21.0828 2888 perc2 - ok
16:43:21.0843 2888 perc2hib - ok
16:43:21.0890 2888 PptpMiniport (efeec01b1d3cf84f16ddd24d9d9d8f99) C:\WINDOWS\system32\DRIVERS\raspptp.sys
16:43:21.0906 2888 PptpMiniport - ok
16:43:21.0921 2888 PSched (09298ec810b07e5d582cb3a3f9255424) C:\WINDOWS\system32\DRIVERS\psched.sys
16:43:21.0921 2888 PSched - ok
16:43:21.0968 2888 Ptilink (80d317bd1c3dbc5d4fe7b1678c60cadd) C:\WINDOWS\system32\DRIVERS\ptilink.sys
16:43:21.0968 2888 Ptilink - ok
16:43:22.0015 2888 ql1080 - ok
16:43:22.0031 2888 Ql10wnt - ok
16:43:22.0062 2888 ql12160 - ok
16:43:22.0093 2888 ql1240 - ok
16:43:22.0125 2888 ql1280 - ok
16:43:22.0187 2888 RasAcd (fe0d99d6f31e4fad8159f690d68ded9c) C:\WINDOWS\system32\DRIVERS\rasacd.sys
16:43:22.0187 2888 RasAcd - ok
16:43:22.0265 2888 Rasl2tp (11b4a627bc9614b885c4969bfa5ff8a6) C:\WINDOWS\system32\DRIVERS\rasl2tp.sys
16:43:22.0265 2888 Rasl2tp - ok
16:43:22.0296 2888 RasPppoe (5bc962f2654137c9909c3d4603587dee) C:\WINDOWS\system32\DRIVERS\raspppoe.sys
16:43:22.0312 2888 RasPppoe - ok
16:43:22.0375 2888 Raspti (fdbb1d60066fcfbb7452fd8f9829b242) C:\WINDOWS\system32\DRIVERS\raspti.sys
16:43:22.0375 2888 Raspti - ok
16:43:22.0406 2888 Rdbss (7ad224ad1a1437fe28d89cf22b17780a) C:\WINDOWS\system32\DRIVERS\rdbss.sys
16:43:22.0421 2888 Rdbss - ok
16:43:22.0453 2888 RDPCDD (4912d5b403614ce99c28420f75353332) C:\WINDOWS\system32\DRIVERS\RDPCDD.sys
16:43:22.0453 2888 RDPCDD - ok
16:43:22.0515 2888 rdpdr (15cabd0f7c00c47c70124907916af3f1) C:\WINDOWS\system32\DRIVERS\rdpdr.sys
16:43:22.0515 2888 rdpdr - ok
16:43:22.0578 2888 RDPWD (6728e45b66f93c08f11de2e316fc70dd) C:\WINDOWS\system32\drivers\RDPWD.sys
16:43:22.0578 2888 RDPWD - ok
16:43:22.0640 2888 redbook (d8eb2a7904db6c916eb5361878ddcbae) C:\WINDOWS\system32\DRIVERS\redbook.sys
16:43:22.0656 2888 redbook - ok
16:43:22.0750 2888 SCR3XX2K (fc87d5e0328afa97bf6d39df96d5d356) C:\WINDOWS\system32\DRIVERS\SCR3XX2K.sys
16:43:22.0765 2888 SCR3XX2K - ok
16:43:22.0843 2888 Secdrv (90a3935d05b494a5a39d37e71f09a677) C:\WINDOWS\system32\DRIVERS\secdrv.sys
16:43:22.0843 2888 Secdrv - ok
16:43:22.0906 2888 serenum (0f29512ccd6bead730039fb4bd2c85ce) C:\WINDOWS\system32\DRIVERS\serenum.sys
16:43:22.0906 2888 serenum - ok
16:43:22.0968 2888 Serial (93d313c31f7ad9ea2b75f26075413c7c) C:\WINDOWS\system32\DRIVERS\serial.sys
16:43:22.0968 2888 Serial - ok
16:43:23.0062 2888 SFAUDIO (b6401608579b6431994425ba7653f774) C:\WINDOWS\system32\drivers\sfaudio.sys
16:43:23.0062 2888 SFAUDIO - ok
16:43:23.0109 2888 Sfloppy (8e6b8c671615d126fdc553d1e2de5562) C:\WINDOWS\system32\DRIVERS\sfloppy.sys
16:43:23.0109 2888 Sfloppy - ok
16:43:23.0156 2888 Simbad - ok
16:43:23.0203 2888 SLIP (866d538ebe33709a5c9f5c62b73b7d14) C:\WINDOWS\system32\DRIVERS\SLIP.sys
16:43:23.0203 2888 SLIP - ok
16:43:23.0359 2888 SNP2UVC (cf9cde12fbc19dba8de528b7511a2f4f) C:\WINDOWS\system32\DRIVERS\snp2uvc.sys
16:43:23.0437 2888 SNP2UVC - ok
16:43:23.0500 2888 Sparrow - ok
16:43:23.0562 2888 splitter (ab8b92451ecb048a4d1de7c3ffcb4a9f) C:\WINDOWS\system32\drivers\splitter.sys
16:43:23.0562 2888 splitter - ok
16:43:23.0671 2888 sptd (d15da1ba189770d93eea2d7e18f95af9) C:\WINDOWS\system32\Drivers\sptd.sys
16:43:23.0671 2888 Suspicious file (NoAccess): C:\WINDOWS\system32\Drivers\sptd.sys. md5: d15da1ba189770d93eea2d7e18f95af9
16:43:23.0671 2888 sptd ( LockedFile.Multi.Generic ) - warning
16:43:23.0671 2888 sptd - detected LockedFile.Multi.Generic (1)
16:43:23.0718 2888 sr (39626e6dc1fb39434ec40c42722b660a) C:\WINDOWS\system32\DRIVERS\sr.sys
16:43:23.0734 2888 sr - ok
16:43:23.0828 2888 Srv (47ddfc2f003f7f9f0592c6874962a2e7) C:\WINDOWS\system32\DRIVERS\srv.sys
16:43:23.0875 2888 Srv - ok
16:43:23.0984 2888 streamip (77813007ba6265c4b6098187e6ed79d2) C:\WINDOWS\system32\DRIVERS\StreamIP.sys
16:43:23.0984 2888 streamip - ok
16:43:24.0093 2888 swenum (3941d127aef12e93addf6fe6ee027e0f) C:\WINDOWS\system32\DRIVERS\swenum.sys
16:43:24.0093 2888 swenum - ok
16:43:24.0171 2888 swmidi (8ce882bcc6cf8a62f2b2323d95cb3d01) C:\WINDOWS\system32\drivers\swmidi.sys
16:43:24.0171 2888 swmidi - ok
16:43:24.0203 2888 symc810 - ok
16:43:24.0218 2888 symc8xx - ok
16:43:24.0250 2888 sym_hi - ok
16:43:24.0265 2888 sym_u3 - ok
16:43:24.0359 2888 SynTP (f08667f79bbd339547f477c75c3ed0b9) C:\WINDOWS\system32\DRIVERS\SynTP.sys
16:43:24.0359 2888 SynTP - ok
16:43:24.0421 2888 sysaudio (8b83f3ed0f1688b4958f77cd6d2bf290) C:\WINDOWS\system32\drivers\sysaudio.sys
16:43:24.0421 2888 sysaudio - ok
16:43:24.0500 2888 tap0801 (846b7c0e3f6370cdcce157a5b36e70cd) C:\WINDOWS\system32\DRIVERS\tap0801.sys
16:43:24.0500 2888 tap0801 - ok
16:43:24.0593 2888 Tcpip (9aefa14bd6b182d61e3119fa5f436d3d) C:\WINDOWS\system32\DRIVERS\tcpip.sys
16:43:24.0609 2888 Tcpip - ok
16:43:24.0671 2888 TDPIPE (6471a66807f5e104e4885f5b67349397) C:\WINDOWS\system32\drivers\TDPIPE.sys
16:43:24.0671 2888 TDPIPE - ok
16:43:24.0718 2888 TDTCP (c56b6d0402371cf3700eb322ef3aaf61) C:\WINDOWS\system32\drivers\TDTCP.sys
16:43:24.0734 2888 TDTCP - ok
16:43:24.0781 2888 teamviewervpn (9101fffcfccd1a30e870a5b8a9091b10) C:\WINDOWS\system32\DRIVERS\teamviewervpn.sys
16:43:24.0781 2888 teamviewervpn - ok
16:43:24.0875 2888 TermDD (88155247177638048422893737429d9e) C:\WINDOWS\system32\DRIVERS\termdd.sys
16:43:24.0875 2888 TermDD - ok
16:43:24.0953 2888 tmcomm (eb2283c0a4dfbd2e53d14f2c4d5a1e89) C:\WINDOWS\system32\drivers\tmcomm.sys
16:43:24.0953 2888 tmcomm - ok
16:43:24.0984 2888 TosIde - ok
16:43:25.0171 2888 TrueSight (ddbf8e194041469f26fc6cbc8264beb0) C:\Documents and Settings\dmi\Bureau\TrueSight.sys
16:43:25.0171 2888 TrueSight - ok
16:43:25.0281 2888 Udfs (5787b80c2e3c5e2f56c2a233d91fa2c9) C:\WINDOWS\system32\drivers\Udfs.sys
16:43:25.0296 2888 Udfs - ok
16:43:25.0328 2888 ultra - ok
16:43:25.0390 2888 Update (402ddc88356b1bac0ee3dd1580c76a31) C:\WINDOWS\system32\DRIVERS\update.sys
16:43:25.0421 2888 Update - ok
16:43:25.0484 2888 usbccgp (173f317ce0db8e21322e71b7e60a27e8) C:\WINDOWS\system32\DRIVERS\usbccgp.sys
16:43:25.0484 2888 usbccgp - ok
16:43:25.0562 2888 usbehci (65dcf09d0e37d4c6b11b5b0b76d470a7) C:\WINDOWS\system32\DRIVERS\usbehci.sys
16:43:25.0578 2888 usbehci - ok
16:43:25.0640 2888 usbhub (1ab3cdde553b6e064d2e754efe20285c) C:\WINDOWS\system32\DRIVERS\usbhub.sys
16:43:25.0640 2888 usbhub - ok
16:43:25.0687 2888 usbprint (a717c8721046828520c9edf31288fc00) C:\WINDOWS\system32\DRIVERS\usbprint.sys
16:43:25.0703 2888 usbprint - ok
16:43:25.0765 2888 usbscan (a0b8cf9deb1184fbdd20784a58fa75d4) C:\WINDOWS\system32\DRIVERS\usbscan.sys
16:43:25.0765 2888 usbscan - ok
16:43:25.0828 2888 USBSTOR (a32426d9b14a089eaa1d922e0c5801a9) C:\WINDOWS\system32\DRIVERS\USBSTOR.SYS
16:43:25.0828 2888 USBSTOR - ok
16:43:25.0875 2888 usbuhci (26496f9dee2d787fc3e61ad54821ffe6) C:\WINDOWS\system32\DRIVERS\usbuhci.sys
16:43:25.0875 2888 usbuhci - ok
16:43:25.0921 2888 usbvideo (63bbfca7f390f4c49ed4b96bfb1633e0) C:\WINDOWS\system32\Drivers\usbvideo.sys
16:43:25.0937 2888 usbvideo - ok
16:43:26.0046 2888 VgaSave (0d3a8fafceacd8b7625cd549757a7df1) C:\WINDOWS\System32\drivers\vga.sys
16:43:26.0046 2888 VgaSave - ok
16:43:26.0078 2888 ViaIde - ok
16:43:26.0109 2888 VolSnap (46de1126684369bace4849e4fc8c43ca) C:\WINDOWS\system32\drivers\VolSnap.sys
16:43:26.0109 2888 VolSnap - ok
16:43:26.0156 2888 Wanarp (e20b95baedb550f32dd489265c1da1f6) C:\WINDOWS\system32\DRIVERS\wanarp.sys
16:43:26.0171 2888 Wanarp - ok
16:43:26.0250 2888 Wdf01000 (fd47474bd21794508af449d9d91af6e6) C:\WINDOWS\system32\DRIVERS\Wdf01000.sys
16:43:26.0250 2888 Wdf01000 - ok
16:43:26.0265 2888 WDICA - ok
16:43:26.0343 2888 wdmaud (6768acf64b18196494413695f0c3a00f) C:\WINDOWS\system32\drivers\wdmaud.sys
16:43:26.0343 2888 wdmaud - ok
16:43:26.0421 2888 WmiAcpi (c42584fd66ce9e17403aebca199f7bdb) C:\WINDOWS\system32\DRIVERS\wmiacpi.sys
16:43:26.0421 2888 WmiAcpi - ok
16:43:26.0468 2888 WSTCODEC (c98b39829c2bbd34e454150633c62c78) C:\WINDOWS\system32\DRIVERS\WSTCODEC.SYS
16:43:26.0468 2888 WSTCODEC - ok
16:43:26.0546 2888 WudfPf (f15feafffbb3644ccc80c5da584e6311) C:\WINDOWS\system32\DRIVERS\WudfPf.sys
16:43:26.0546 2888 WudfPf - ok
16:43:26.0593 2888 WudfRd (28b524262bce6de1f7ef9f510ba3985b) C:\WINDOWS\system32\DRIVERS\wudfrd.sys
16:43:26.0593 2888 WudfRd - ok
16:43:26.0625 2888 MBR (0x1B8) (c99c3199cfaa4cbdcd91493f6d113a50) \Device\Harddisk0\DR0
16:43:26.0765 2888 \Device\Harddisk0\DR0 - ok
16:43:26.0765 2888 Boot (0x1200) (7c8d0dcb31f179aff5003f6445918649) \Device\Harddisk0\DR0\Partition0
16:43:26.0765 2888 \Device\Harddisk0\DR0\Partition0 - ok
16:43:26.0765 2888 ============================================================
16:43:26.0765 2888 Scan finished
16:43:26.0765 2888 ============================================================
16:43:26.0781 2680 Detected object count: 2
16:43:26.0781 2680 Actual detected object count: 2
16:43:31.0046 2680 f7bd01a7 ( HiddenFile.Multi.Generic ) - skipped by user
16:43:31.0046 2680 f7bd01a7 ( HiddenFile.Multi.Generic ) - User select action: Skip
16:43:31.0046 2680 sptd ( LockedFile.Multi.Generic ) - skipped by user
16:43:31.0046 2680 sptd ( LockedFile.Multi.Generic ) - User select action: Skip
Messages postés
35445
Date d'inscription
jeudi 18 décembre 2008
Statut
Contributeur sécurité
Dernière intervention
5 mai 2017
4 783
16:43:31.0046 2680 f7bd01a7 ( HiddenFile.Multi.Generic ) - skipped by user

Tu n'as que cette possibilité ?
Tu ne peux pas cure ou delete ?
Réessaie stp.

~~

/!\ Ne pas utiliser ce logiciel en dehors du cadre de cette désinfection : DANGEREUX /!\

▶ /!\ IMPORTANT /!\

Désactive ton Antivirus, antispyware et Pare feu avant le scan avec Combofix :
Protections résidentes : https://forum.pcastuces.com/default.asp
et https://www.bleepingcomputer.com/forums/t/114351/how-to-temporarily-disable-your-anti-virus-firewall-and-anti-malware-programs/
~~
Pare feu Windows XP : http://support.microsoft.com/kb/283673/fr
Pare feu Windows Vista/7 : https://support.microsoft.com/en-us/windows?ui=en-US&rs=en-001&ad=US
~~
Windows Defender : https://support.microsoft.com/en-us/windows?ui=en-US&rs=en-001&ad=US
_______________________________________________________________

▶ Fais un clic droit sur le lien ci dessous, choisi "Enregistrer la cible du lien sous", comme destination : ton Bureau, change son nom (ton_pseudo.exe par exemple) :

http://download.bleepingcomputer.com/sUBs/ComboFix.exe

▶ Double-clique sur ComboFix.exe
Un "pop-up" va apparaître qui dit que ComboFix est utilisé à vos risques et avec aucune garantie... Clique sur oui pour accepter

▶ ▶ SI TU ES SOUS WINDOWS XP, SURTOUT INSTALLES LA CONSOLE DE RÉCUPÉRATION [Si tu travailles avec Vista ou seven ne tiens pas compte de cet avertissement]
▶ ▶ Ne touche à rien (souris, clavier) tant que le scan n'est pas terminé, car tu risques de planter ton PC

▶ En fin de scan, il est possible que ComboFix ait besoin de redémarrer le PC pour finaliser la désinfection, laisse-le faire.

▶ Une fois le scan achevé, un rapport va s''afficher : Poste son contenu
▶ ▶ /!\ Réactive la protection en temps réel de ton antivirus avant de te reconnecter à Internet. /!\

Notes:
-> Le rapport se trouve également là : C:\ComboFix.txt
-> tutoriel combofix
J'ai remarqué que j'avais oublié de supprimer le f7bd01a7. Je l'ai donc supprimé. Je n'ai pas supprimé le lokked file. Fallait-il le faire également?

Voici don le rapport après avoir supprimé le f7bd01a7 et avoir redémarrer le pc :

16:58:54.0390 3396 TDSS rootkit removing tool 2.6.2.0 Sep 26 2011 18:56:43
16:58:54.0500 3396 ============================================================
16:58:54.0500 3396 Current date / time: 2011/09/27 16:58:54.0500
16:58:54.0500 3396 SystemInfo:
16:58:54.0500 3396
16:58:54.0500 3396 OS Version: 5.1.2600 ServicePack: 3.0
16:58:54.0500 3396 Product type: Workstation
16:58:54.0500 3396 ComputerName: CHR
16:58:54.0500 3396 UserName: dmi
16:58:54.0500 3396 Windows directory: C:\WINDOWS
16:58:54.0500 3396 System windows directory: C:\WINDOWS
16:58:54.0500 3396 Processor architecture: Intel x86
16:58:54.0500 3396 Number of processors: 2
16:58:54.0500 3396 Page size: 0x1000
16:58:54.0500 3396 Boot type: Normal boot
16:58:54.0500 3396 ============================================================
16:58:55.0078 3396 Initialize success
16:58:56.0359 2080 ============================================================
16:58:56.0359 2080 Scan started
16:58:56.0359 2080 Mode: Manual;
16:58:56.0359 2080 ============================================================
16:58:57.0078 2080 a347bus (1f61cacacb521215f39061789147968c) C:\WINDOWS\system32\DRIVERS\a347bus.sys
16:58:57.0078 2080 a347bus - ok
16:58:57.0109 2080 a347scsi (113e4b318bbaa7483ca4e582a4d63f49) C:\WINDOWS\system32\Drivers\a347scsi.sys
16:58:57.0109 2080 a347scsi - ok
16:58:57.0140 2080 Abiosdsk - ok
16:58:57.0156 2080 abp480n5 - ok
16:58:57.0218 2080 Accelerometer (6c2e405d98e6342a9d66a2493e7ab15e) C:\WINDOWS\system32\DRIVERS\Accelerometer.sys
16:58:57.0218 2080 Accelerometer - ok
16:58:57.0265 2080 ACPI (e5e6dbfc41ea8aad005cb9a57a96b43b) C:\WINDOWS\system32\DRIVERS\ACPI.sys
16:58:57.0281 2080 ACPI - ok
16:58:57.0328 2080 ACPIEC (e4abc1212b70bb03d35e60681c447210) C:\WINDOWS\system32\DRIVERS\ACPIEC.sys
16:58:57.0328 2080 ACPIEC - ok
16:58:57.0437 2080 ADIHdAudAddService (ff60db2aca88543c025eacba25cee5c1) C:\WINDOWS\system32\drivers\ADIHdAud.sys
16:58:57.0437 2080 ADIHdAudAddService - ok
16:58:57.0468 2080 adpu160m - ok
16:58:57.0484 2080 AEAudio (fff87a9b1ab36ee4b7bec98a4cb01b79) C:\WINDOWS\system32\drivers\AEAudio.sys
16:58:57.0484 2080 AEAudio - ok
16:58:57.0546 2080 aec (8bed39e3c35d6a489438b8141717a557) C:\WINDOWS\system32\drivers\aec.sys
16:58:57.0562 2080 aec - ok
16:58:57.0625 2080 AFD (355556d9e580915118cd7ef736653a89) C:\WINDOWS\System32\drivers\afd.sys
16:58:57.0625 2080 AFD - ok
16:58:57.0718 2080 AgereSoftModem (1cfeba39fc613e45b49d3eddfbcda289) C:\WINDOWS\system32\DRIVERS\AGRSM.sys
16:58:57.0750 2080 AgereSoftModem - ok
16:58:57.0781 2080 Aha154x - ok
16:58:57.0796 2080 aic78u2 - ok
16:58:57.0828 2080 aic78xx - ok
16:58:57.0843 2080 AliIde - ok
16:58:57.0859 2080 amsint - ok
16:58:57.0906 2080 Arp1394 (b5b8a80875c1dededa8b02765642c32f) C:\WINDOWS\system32\DRIVERS\arp1394.sys
16:58:57.0906 2080 Arp1394 - ok
16:58:57.0937 2080 asc - ok
16:58:57.0968 2080 asc3350p - ok
16:58:57.0984 2080 asc3550 - ok
16:58:58.0031 2080 AsyncMac (b153affac761e7f5fcfa822b9c4e97bc) C:\WINDOWS\system32\DRIVERS\asyncmac.sys
16:58:58.0031 2080 AsyncMac - ok
16:58:58.0062 2080 atapi (9f3a2f5aa6875c72bf062c712cfa2674) C:\WINDOWS\system32\drivers\atapi.sys
16:58:58.0062 2080 atapi - ok
16:58:58.0093 2080 Atdisk - ok
16:58:58.0140 2080 Atmarpc (9916c1225104ba14794209cfa8012159) C:\WINDOWS\system32\DRIVERS\atmarpc.sys
16:58:58.0140 2080 Atmarpc - ok
16:58:58.0234 2080 ATSwpWDF (a9f9d1d24441889beb1aa2b917457e23) C:\WINDOWS\system32\Drivers\ATSwpWDF.sys
16:58:58.0250 2080 ATSwpWDF - ok
16:58:58.0312 2080 audstub (d9f724aa26c010a217c97606b160ed68) C:\WINDOWS\system32\DRIVERS\audstub.sys
16:58:58.0312 2080 audstub - ok
16:58:58.0406 2080 AVGIDSDriver (2d18221aab3db2d408d6c55c0f23090a) C:\WINDOWS\system32\DRIVERS\AVGIDSDriver.Sys
16:58:58.0406 2080 AVGIDSDriver - ok
16:58:58.0453 2080 AVGIDSEH (1af676db3f3d4cc709cfab2571cf5fc3) C:\WINDOWS\system32\DRIVERS\AVGIDSEH.Sys
16:58:58.0453 2080 AVGIDSEH - ok
16:58:58.0484 2080 AVGIDSFilter (4c51e233c87f9ec7598551de554bc99d) C:\WINDOWS\system32\DRIVERS\AVGIDSFilter.Sys
16:58:58.0484 2080 AVGIDSFilter - ok
16:58:58.0515 2080 AVGIDSShim (c3fc426e54f55c1cc3219e415b88e10c) C:\WINDOWS\system32\DRIVERS\AVGIDSShim.Sys
16:58:58.0515 2080 AVGIDSShim - ok
16:58:58.0562 2080 Avgldx86 (4e796d3d2c3182b13b3e3b5a2ad4ef0a) C:\WINDOWS\system32\DRIVERS\avgldx86.sys
16:58:58.0578 2080 Avgldx86 - ok
16:58:58.0578 2080 Avgmfx86 (5639de66b37d02bd22df4cf3155fba60) C:\WINDOWS\system32\DRIVERS\avgmfx86.sys
16:58:58.0593 2080 Avgmfx86 - ok
16:58:58.0625 2080 Avgrkx86 (d1baf652eda0ae70896276a1fb32c2d4) C:\WINDOWS\system32\DRIVERS\avgrkx86.sys
16:58:58.0625 2080 Avgrkx86 - ok
16:58:58.0656 2080 Avgtdix (aaf0ebcad95f2164cffb544e00392498) C:\WINDOWS\system32\DRIVERS\avgtdix.sys
16:58:58.0671 2080 Avgtdix - ok
16:58:58.0734 2080 b57w2k (ea377a8e8e1000877210259750cbbf5f) C:\WINDOWS\system32\DRIVERS\b57xp32.sys
16:58:58.0734 2080 b57w2k - ok
16:58:58.0781 2080 Beep (da1f27d85e0d1525f6621372e7b685e9) C:\WINDOWS\system32\drivers\Beep.sys
16:58:58.0796 2080 Beep - ok
16:58:58.0890 2080 BTKRNL (ef5e0de0a7ca2977a9255f36f4d915ab) C:\WINDOWS\system32\DRIVERS\btkrnl.sys
16:58:58.0906 2080 BTKRNL - ok
16:58:58.0953 2080 BTWUSB (053dc5be74621b63bb48c2b86bafc7b0) C:\WINDOWS\system32\Drivers\btwusb.sys
16:58:58.0953 2080 BTWUSB - ok
16:58:59.0000 2080 cbidf2k (90a673fc8e12a79afbed2576f6a7aaf9) C:\WINDOWS\system32\drivers\cbidf2k.sys
16:58:59.0015 2080 cbidf2k - ok
16:58:59.0078 2080 CCDECODE (0be5aef125be881c4f854c554f2b025c) C:\WINDOWS\system32\DRIVERS\CCDECODE.sys
16:58:59.0078 2080 CCDECODE - ok
16:58:59.0125 2080 cd20xrnt - ok
16:58:59.0140 2080 Cdaudio (c1b486a7658353d33a10cc15211a873b) C:\WINDOWS\system32\drivers\Cdaudio.sys
16:58:59.0156 2080 Cdaudio - ok
16:58:59.0218 2080 Cdfs (c885b02847f5d2fd45a24e219ed93b32) C:\WINDOWS\system32\drivers\Cdfs.sys
16:58:59.0218 2080 Cdfs - ok
16:58:59.0234 2080 Cdrom (1f4260cc5b42272d71f79e570a27a4fe) C:\WINDOWS\system32\DRIVERS\cdrom.sys
16:58:59.0250 2080 Cdrom - ok
16:58:59.0265 2080 Changer - ok
16:58:59.0296 2080 CmBatt (0f6c187d38d98f8df904589a5f94d411) C:\WINDOWS\system32\DRIVERS\CmBatt.sys
16:58:59.0296 2080 CmBatt - ok
16:58:59.0343 2080 CmdIde - ok
16:58:59.0390 2080 Compbatt (6e4c9f21f0fae8940661144f41b13203) C:\WINDOWS\system32\DRIVERS\compbatt.sys
16:58:59.0406 2080 Compbatt - ok
16:58:59.0437 2080 Cpqarray - ok
16:58:59.0562 2080 CrystalSysInfo (f054744f67576a01139885173392502b) C:\Program Files\MediaCoder\SysInfo.sys
16:58:59.0562 2080 CrystalSysInfo - ok
16:58:59.0609 2080 dac2w2k - ok
16:58:59.0640 2080 dac960nt - ok
16:58:59.0718 2080 Disk (044452051f3e02e7963599fc8f4f3e25) C:\WINDOWS\system32\DRIVERS\disk.sys
16:58:59.0718 2080 Disk - ok
16:58:59.0781 2080 dmboot (f5deadd42335fb33edca74ecb2f36cba) C:\WINDOWS\system32\drivers\dmboot.sys
16:58:59.0812 2080 dmboot - ok
16:58:59.0875 2080 dmio (5a7c47c9b3f9fb92a66410a7509f0c71) C:\WINDOWS\system32\drivers\dmio.sys
16:58:59.0890 2080 dmio - ok
16:58:59.0921 2080 dmload (e9317282a63ca4d188c0df5e09c6ac5f) C:\WINDOWS\system32\drivers\dmload.sys
16:58:59.0937 2080 dmload - ok
16:59:00.0000 2080 DMusic (8a208dfcf89792a484e76c40e5f50b45) C:\WINDOWS\system32\drivers\DMusic.sys
16:59:00.0000 2080 DMusic - ok
16:59:00.0031 2080 dpti2o - ok
16:59:00.0062 2080 drmkaud (8f5fcff8e8848afac920905fbd9d33c8) C:\WINDOWS\system32\drivers\drmkaud.sys
16:59:00.0062 2080 drmkaud - ok
16:59:00.0109 2080 dsNcAdpt (b2c3f71b86e25c3df78339ddb40a7562) C:\WINDOWS\system32\DRIVERS\dsNcAdpt.sys
16:59:00.0109 2080 dsNcAdpt - ok
16:59:00.0187 2080 Fastfat (38d332a6d56af32635675f132548343e) C:\WINDOWS\system32\drivers\Fastfat.sys
16:59:00.0187 2080 Fastfat - ok
16:59:00.0281 2080 Fdc (92cdd60b6730b9f50f6a1a0c1f8cdc81) C:\WINDOWS\system32\drivers\Fdc.sys
16:59:00.0281 2080 Fdc - ok
16:59:00.0312 2080 Fips (31f923eb2170fc172c81abda0045d18c) C:\WINDOWS\system32\drivers\Fips.sys
16:59:00.0312 2080 Fips - ok
16:59:00.0343 2080 Flpydisk (9d27e7b80bfcdf1cdd9b555862d5e7f0) C:\WINDOWS\system32\drivers\Flpydisk.sys
16:59:00.0343 2080 Flpydisk - ok
16:59:00.0406 2080 FltMgr (b2cf4b0786f8212cb92ed2b50c6db6b0) C:\WINDOWS\system32\DRIVERS\fltMgr.sys
16:59:00.0421 2080 FltMgr - ok
16:59:00.0468 2080 Fs_Rec (3e1e2bd4f39b0e2b7dc4f4d2bcc2779a) C:\WINDOWS\system32\drivers\Fs_Rec.sys
16:59:00.0468 2080 Fs_Rec - ok
16:59:00.0515 2080 Ftdisk (a86859b77b908c18c2657f284aa29fe3) C:\WINDOWS\system32\DRIVERS\ftdisk.sys
16:59:00.0515 2080 Ftdisk - ok
16:59:00.0578 2080 Gpc (0a02c63c8b144bd8c86b103dee7c86a2) C:\WINDOWS\system32\DRIVERS\msgpc.sys
16:59:00.0578 2080 Gpc - ok
16:59:00.0687 2080 HBtnKey (407e41ddb2bfece109132aec296e0d98) C:\WINDOWS\system32\DRIVERS\cpqbttn.sys
16:59:00.0687 2080 HBtnKey - ok
16:59:00.0765 2080 HDAudBus (573c7d0a32852b48f3058cfd8026f511) C:\WINDOWS\system32\DRIVERS\HDAudBus.sys
16:59:00.0765 2080 HDAudBus - ok
16:59:00.0796 2080 HidUsb (ccf82c5ec8a7326c3066de870c06daf1) C:\WINDOWS\system32\DRIVERS\hidusb.sys
16:59:00.0796 2080 HidUsb - ok
16:59:00.0875 2080 hpdskflt (e8a95df23097bca840814d42f2ee5164) C:\WINDOWS\system32\DRIVERS\hpdskflt.sys
16:59:00.0875 2080 hpdskflt - ok
16:59:00.0906 2080 hpn - ok
16:59:00.0937 2080 HpqKbFiltr (35956140e686d53bf676cf0c778880fc) C:\WINDOWS\system32\DRIVERS\HpqKbFiltr.sys
16:59:00.0937 2080 HpqKbFiltr - ok
16:59:01.0015 2080 HTTP (f80a415ef82cd06ffaf0d971528ead38) C:\WINDOWS\system32\Drivers\HTTP.sys
16:59:01.0031 2080 HTTP - ok
16:59:01.0093 2080 i2omgmt - ok
16:59:01.0109 2080 i2omp - ok
16:59:01.0156 2080 i8042prt (a09bdc4ed10e3b2e0ec27bb94af32516) C:\WINDOWS\system32\DRIVERS\i8042prt.sys
16:59:01.0156 2080 i8042prt - ok
16:59:01.0437 2080 ialm (f592a1b020723cfbd3d2722514066449) C:\WINDOWS\system32\DRIVERS\igxpmp32.sys
16:59:01.0671 2080 ialm - ok
16:59:01.0765 2080 iaStor (db0cc620b27a928d968c1a1e9cd9cb87) C:\WINDOWS\system32\DRIVERS\iaStor.sys
16:59:01.0781 2080 iaStor - ok
16:59:01.0843 2080 IFXTPM (667cfdb801df771f47b7c39373c2d850) C:\WINDOWS\system32\DRIVERS\IFXTPM.SYS
16:59:01.0843 2080 IFXTPM - ok
16:59:01.0937 2080 Imapi (083a052659f5310dd8b6a6cb05edcf8e) C:\WINDOWS\system32\DRIVERS\imapi.sys
16:59:01.0937 2080 Imapi - ok
16:59:01.0968 2080 ini910u - ok
16:59:01.0984 2080 IntelIde - ok
16:59:02.0015 2080 intelppm (ad340800c35a42d4de1641a37feea34c) C:\WINDOWS\system32\DRIVERS\intelppm.sys
16:59:02.0015 2080 intelppm - ok
16:59:02.0062 2080 Ip6Fw (3bb22519a194418d5fec05d800a19ad0) C:\WINDOWS\system32\DRIVERS\Ip6Fw.sys
16:59:02.0062 2080 Ip6Fw - ok
16:59:02.0125 2080 IpFilterDriver (731f22ba402ee4b62748adaf6363c182) C:\WINDOWS\system32\DRIVERS\ipfltdrv.sys
16:59:02.0140 2080 IpFilterDriver - ok
16:59:02.0234 2080 IpInIp (b87ab476dcf76e72010632b5550955f5) C:\WINDOWS\system32\DRIVERS\ipinip.sys
16:59:02.0234 2080 IpInIp - ok
16:59:02.0296 2080 IpNat (cc748ea12c6effde940ee98098bf96bb) C:\WINDOWS\system32\DRIVERS\ipnat.sys
16:59:02.0296 2080 IpNat - ok
16:59:02.0328 2080 IPSec (23c74d75e36e7158768dd63d92789a91) C:\WINDOWS\system32\DRIVERS\ipsec.sys
16:59:02.0343 2080 IPSec - ok
16:59:02.0390 2080 IRENUM (c93c9ff7b04d772627a3646d89f7bf89) C:\WINDOWS\system32\DRIVERS\irenum.sys
16:59:02.0406 2080 IRENUM - ok
16:59:02.0484 2080 isapnp (355836975a67b6554bca60328cd6cb74) C:\WINDOWS\system32\DRIVERS\isapnp.sys
16:59:02.0484 2080 isapnp - ok
16:59:02.0562 2080 Kbdclass (16813155807c6881f4bfbf6657424659) C:\WINDOWS\system32\DRIVERS\kbdclass.sys
16:59:02.0562 2080 Kbdclass - ok
16:59:02.0609 2080 kbdhid (94c59cb884ba010c063687c3a50dce8e) C:\WINDOWS\system32\DRIVERS\kbdhid.sys
16:59:02.0609 2080 kbdhid - ok
16:59:02.0671 2080 kmixer (692bcf44383d056aed41b045a323d378) C:\WINDOWS\system32\drivers\kmixer.sys
16:59:02.0671 2080 kmixer - ok
16:59:02.0718 2080 KSecDD (b467646c54cc746128904e1654c750c1) C:\WINDOWS\system32\drivers\KSecDD.sys
16:59:02.0718 2080 KSecDD - ok
16:59:02.0781 2080 Lavasoft Kernexplorer - ok
16:59:02.0859 2080 Lbd (b7c19ec8b0dd7efa58ad41ffeb8b8cda) C:\WINDOWS\system32\DRIVERS\Lbd.sys
16:59:02.0859 2080 Lbd - ok
16:59:02.0937 2080 lbrtfdc - ok
16:59:03.0046 2080 LMIInfo (4f69faaabb7db0d43e327c0b6aab40fc) C:\Program Files\LogMeIn\x86\RaInfo.sys
16:59:03.0046 2080 LMIInfo - ok
16:59:03.0140 2080 lmimirr (4477689e2d8ae6b78ba34c9af4cc1ed1) C:\WINDOWS\system32\DRIVERS\lmimirr.sys
16:59:03.0140 2080 lmimirr - ok
16:59:03.0171 2080 LMIRfsClientNP - ok
16:59:03.0203 2080 LMIRfsDriver (3faa563ddf853320f90259d455a01d79) C:\WINDOWS\system32\drivers\LMIRfsDriver.sys
16:59:03.0203 2080 LMIRfsDriver - ok
16:59:03.0265 2080 mnmdd (4ae068242760a1fb6e1a44bf4e16afa6) C:\WINDOWS\system32\drivers\mnmdd.sys
16:59:03.0265 2080 mnmdd - ok
16:59:03.0343 2080 Modem (510ade9327fe84c10254e1902697e25f) C:\WINDOWS\system32\drivers\Modem.sys
16:59:03.0359 2080 Modem - ok
16:59:03.0421 2080 Mouclass (027c01bd7ef3349aaebc883d8a799efb) C:\WINDOWS\system32\DRIVERS\mouclass.sys
16:59:03.0421 2080 Mouclass - ok
16:59:03.0500 2080 mouhid (124d6846040c79b9c997f78ef4b2a4e5) C:\WINDOWS\system32\DRIVERS\mouhid.sys
16:59:03.0500 2080 mouhid - ok
16:59:03.0531 2080 MountMgr (a80b9a0bad1b73637dbcbba7df72d3fd) C:\WINDOWS\system32\drivers\MountMgr.sys
16:59:03.0531 2080 MountMgr - ok
16:59:03.0562 2080 mraid35x - ok
16:59:03.0640 2080 MRxDAV (e3f17e1ea5256709d4e97ef0da04b3c9) C:\WINDOWS\system32\DRIVERS\mrxdav.sys
16:59:03.0656 2080 MRxDAV - ok
16:59:03.0734 2080 MRxSmb (0ea4d8ed179b75f8afa7998ba22285ca) C:\WINDOWS\system32\DRIVERS\mrxsmb.sys
16:59:03.0750 2080 MRxSmb - ok
16:59:03.0812 2080 Msfs (c941ea2454ba8350021d774daf0f1027) C:\WINDOWS\system32\drivers\Msfs.sys
16:59:03.0812 2080 Msfs - ok
16:59:03.0890 2080 MSKSSRV (d1575e71568f4d9e14ca56b7b0453bf1) C:\WINDOWS\system32\drivers\MSKSSRV.sys
16:59:03.0890 2080 MSKSSRV - ok
16:59:03.0953 2080 MSPCLOCK (325bb26842fc7ccc1fcce2c457317f3e) C:\WINDOWS\system32\drivers\MSPCLOCK.sys
16:59:03.0953 2080 MSPCLOCK - ok
16:59:04.0015 2080 MSPQM (bad59648ba099da4a17680b39730cb3d) C:\WINDOWS\system32\drivers\MSPQM.sys
16:59:04.0015 2080 MSPQM - ok
16:59:04.0062 2080 mssmbios (af5f4f3f14a8ea2c26de30f7a1e17136) C:\WINDOWS\system32\DRIVERS\mssmbios.sys
16:59:04.0062 2080 mssmbios - ok
16:59:04.0109 2080 MSTEE (e53736a9e30c45fa9e7b5eac55056d1d) C:\WINDOWS\system32\drivers\MSTEE.sys
16:59:04.0109 2080 MSTEE - ok
16:59:04.0218 2080 Mup (de6a75f5c270e756c5508d94b6cf68f5) C:\WINDOWS\system32\drivers\Mup.sys
16:59:04.0234 2080 Mup - ok
16:59:04.0296 2080 NABTSFEC (5b50f1b2a2ed47d560577b221da734db) C:\WINDOWS\system32\DRIVERS\NABTSFEC.sys
16:59:04.0296 2080 NABTSFEC - ok
16:59:04.0390 2080 NDIS (1df7f42665c94b825322fae71721130d) C:\WINDOWS\system32\drivers\NDIS.sys
16:59:04.0406 2080 NDIS - ok
16:59:04.0468 2080 NdisIP (7ff1f1fd8609c149aa432f95a8163d97) C:\WINDOWS\system32\DRIVERS\NdisIP.sys
16:59:04.0468 2080 NdisIP - ok
16:59:04.0531 2080 NdisTapi (1ab3d00c991ab086e69db84b6c0ed78f) C:\WINDOWS\system32\DRIVERS\ndistapi.sys
16:59:04.0531 2080 NdisTapi - ok
16:59:04.0578 2080 Ndisuio (f927a4434c5028758a842943ef1a3849) C:\WINDOWS\system32\DRIVERS\ndisuio.sys
16:59:04.0578 2080 Ndisuio - ok
16:59:04.0609 2080 NdisWan (edc1531a49c80614b2cfda43ca8659ab) C:\WINDOWS\system32\DRIVERS\ndiswan.sys
16:59:04.0609 2080 NdisWan - ok
16:59:04.0671 2080 NDProxy (9282bd12dfb069d3889eb3fcc1000a9b) C:\WINDOWS\system32\drivers\NDProxy.sys
16:59:04.0671 2080 NDProxy - ok
16:59:04.0765 2080 NetBIOS (5d81cf9a2f1a3a756b66cf684911cdf0) C:\WINDOWS\system32\DRIVERS\netbios.sys
16:59:04.0765 2080 NetBIOS - ok
16:59:04.0796 2080 NetBT (74b2b2f5bea5e9a3dc021d685551bd3d) C:\WINDOWS\system32\DRIVERS\netbt.sys
16:59:04.0812 2080 NetBT - ok
16:59:05.0015 2080 NETw5x32 (05743fffc2bc88cc8e426321bc6a762e) C:\WINDOWS\system32\DRIVERS\NETw5x32.sys
16:59:05.0125 2080 NETw5x32 - ok
16:59:05.0156 2080 NIC1394 (e9e47cfb2d461fa0fc75b7a74c6383ea) C:\WINDOWS\system32\DRIVERS\nic1394.sys
16:59:05.0156 2080 NIC1394 - ok
16:59:05.0203 2080 nm (1e421a6bcf2203cc61b821ada9de878b) C:\WINDOWS\system32\DRIVERS\NMnt.sys
16:59:05.0218 2080 nm - ok
16:59:05.0296 2080 NPF (243126da7ba441d7c7c3262dcf435a9c) C:\WINDOWS\system32\drivers\npf.sys
16:59:05.0296 2080 NPF - ok
16:59:05.0375 2080 Npfs (3182d64ae053d6fb034f44b6def8034a) C:\WINDOWS\system32\drivers\Npfs.sys
16:59:05.0375 2080 Npfs - ok
16:59:05.0437 2080 Ntfs (78a08dd6a8d65e697c18e1db01c5cdca) C:\WINDOWS\system32\drivers\Ntfs.sys
16:59:05.0453 2080 Ntfs - ok
16:59:05.0531 2080 Null (73c1e1f395918bc2c6dd67af7591a3ad) C:\WINDOWS\system32\drivers\Null.sys
16:59:05.0531 2080 Null - ok
16:59:05.0609 2080 NwlnkFlt (b305f3fad35083837ef46a0bbce2fc57) C:\WINDOWS\system32\DRIVERS\nwlnkflt.sys
16:59:05.0609 2080 NwlnkFlt - ok
16:59:05.0671 2080 NwlnkFwd (c99b3415198d1aab7227f2c88fd664b9) C:\WINDOWS\system32\DRIVERS\nwlnkfwd.sys
16:59:05.0671 2080 NwlnkFwd - ok
16:59:05.0750 2080 ohci1394 (ca33832df41afb202ee7aeb05145922f) C:\WINDOWS\system32\DRIVERS\ohci1394.sys
16:59:05.0750 2080 ohci1394 - ok
16:59:05.0859 2080 Parport (8fd0bdbea875d06ccf6c945ca9abaf75) C:\WINDOWS\system32\DRIVERS\parport.sys
16:59:05.0859 2080 Parport - ok
16:59:05.0890 2080 PartMgr (beb3ba25197665d82ec7065b724171c6) C:\WINDOWS\system32\drivers\PartMgr.sys
16:59:05.0890 2080 PartMgr - ok
16:59:05.0984 2080 ParVdm (9575c5630db8fb804649a6959737154c) C:\WINDOWS\system32\drivers\ParVdm.sys
16:59:05.0984 2080 ParVdm - ok
16:59:06.0031 2080 PCI (043410877bda580c528f45165f7125bc) C:\WINDOWS\system32\DRIVERS\pci.sys
16:59:06.0031 2080 PCI - ok
16:59:06.0078 2080 PCIDump - ok
16:59:06.0093 2080 PCIIde - ok
16:59:06.0156 2080 Pcmcia (f0406cbc60bdb0394a0e17ffb04cdd3d) C:\WINDOWS\system32\drivers\Pcmcia.sys
16:59:06.0156 2080 Pcmcia - ok
16:59:06.0203 2080 PDCOMP - ok
16:59:06.0218 2080 PDFRAME - ok
16:59:06.0250 2080 PDRELI - ok
16:59:06.0265 2080 PDRFRAME - ok
16:59:06.0281 2080 perc2 - ok
16:59:06.0328 2080 perc2hib - ok
16:59:06.0421 2080 PptpMiniport (efeec01b1d3cf84f16ddd24d9d9d8f99) C:\WINDOWS\system32\DRIVERS\raspptp.sys
16:59:06.0421 2080 PptpMiniport - ok
16:59:06.0484 2080 PSched (09298ec810b07e5d582cb3a3f9255424) C:\WINDOWS\system32\DRIVERS\psched.sys
16:59:06.0500 2080 PSched - ok
16:59:06.0546 2080 Ptilink (80d317bd1c3dbc5d4fe7b1678c60cadd) C:\WINDOWS\system32\DRIVERS\ptilink.sys
16:59:06.0546 2080 Ptilink - ok
16:59:06.0578 2080 ql1080 - ok
16:59:06.0593 2080 Ql10wnt - ok
16:59:06.0625 2080 ql12160 - ok
16:59:06.0640 2080 ql1240 - ok
16:59:06.0671 2080 ql1280 - ok
16:59:06.0703 2080 RasAcd (fe0d99d6f31e4fad8159f690d68ded9c) C:\WINDOWS\system32\DRIVERS\rasacd.sys
16:59:06.0718 2080 RasAcd - ok
16:59:06.0828 2080 Rasl2tp (11b4a627bc9614b885c4969bfa5ff8a6) C:\WINDOWS\system32\DRIVERS\rasl2tp.sys
16:59:06.0828 2080 Rasl2tp - ok
16:59:06.0968 2080 RasPppoe (5bc962f2654137c9909c3d4603587dee) C:\WINDOWS\system32\DRIVERS\raspppoe.sys
16:59:06.0984 2080 RasPppoe - ok
16:59:07.0234 2080 Raspti (fdbb1d60066fcfbb7452fd8f9829b242) C:\WINDOWS\system32\DRIVERS\raspti.sys
16:59:07.0250 2080 Raspti - ok
16:59:07.0468 2080 Rdbss (7ad224ad1a1437fe28d89cf22b17780a) C:\WINDOWS\system32\DRIVERS\rdbss.sys
16:59:07.0500 2080 Rdbss - ok
16:59:07.0781 2080 RDPCDD (4912d5b403614ce99c28420f75353332) C:\WINDOWS\system32\DRIVERS\RDPCDD.sys
16:59:07.0796 2080 RDPCDD - ok
16:59:08.0031 2080 rdpdr (15cabd0f7c00c47c70124907916af3f1) C:\WINDOWS\system32\DRIVERS\rdpdr.sys
16:59:08.0062 2080 rdpdr - ok
16:59:08.0328 2080 RDPWD (6728e45b66f93c08f11de2e316fc70dd) C:\WINDOWS\system32\drivers\RDPWD.sys
16:59:08.0390 2080 RDPWD - ok
16:59:08.0625 2080 redbook (d8eb2a7904db6c916eb5361878ddcbae) C:\WINDOWS\system32\DRIVERS\redbook.sys
16:59:08.0656 2080 redbook - ok
16:59:08.0828 2080 SCR3XX2K (fc87d5e0328afa97bf6d39df96d5d356) C:\WINDOWS\system32\DRIVERS\SCR3XX2K.sys
16:59:08.0859 2080 SCR3XX2K - ok
16:59:09.0046 2080 Secdrv (90a3935d05b494a5a39d37e71f09a677) C:\WINDOWS\system32\DRIVERS\secdrv.sys
16:59:09.0062 2080 Secdrv - ok
16:59:09.0109 2080 serenum (0f29512ccd6bead730039fb4bd2c85ce) C:\WINDOWS\system32\DRIVERS\serenum.sys
16:59:09.0109 2080 serenum - ok
16:59:09.0250 2080 Serial (93d313c31f7ad9ea2b75f26075413c7c) C:\WINDOWS\system32\DRIVERS\serial.sys
16:59:09.0312 2080 Serial - ok
16:59:09.0578 2080 SFAUDIO (b6401608579b6431994425ba7653f774) C:\WINDOWS\system32\drivers\sfaudio.sys
16:59:09.0578 2080 SFAUDIO - ok
16:59:09.0718 2080 Sfloppy (8e6b8c671615d126fdc553d1e2de5562) C:\WINDOWS\system32\DRIVERS\sfloppy.sys
16:59:09.0718 2080 Sfloppy - ok
16:59:09.0812 2080 Simbad - ok
16:59:09.0937 2080 SLIP (866d538ebe33709a5c9f5c62b73b7d14) C:\WINDOWS\system32\DRIVERS\SLIP.sys
16:59:09.0937 2080 SLIP - ok
16:59:10.0109 2080 SNP2UVC (cf9cde12fbc19dba8de528b7511a2f4f) C:\WINDOWS\system32\DRIVERS\snp2uvc.sys
16:59:10.0171 2080 SNP2UVC - ok
16:59:10.0203 2080 Sparrow - ok
16:59:10.0265 2080 splitter (ab8b92451ecb048a4d1de7c3ffcb4a9f) C:\WINDOWS\system32\drivers\splitter.sys
16:59:10.0265 2080 splitter - ok
16:59:10.0390 2080 sptd (d15da1ba189770d93eea2d7e18f95af9) C:\WINDOWS\system32\Drivers\sptd.sys
16:59:10.0390 2080 Suspicious file (NoAccess): C:\WINDOWS\system32\Drivers\sptd.sys. md5: d15da1ba189770d93eea2d7e18f95af9
16:59:10.0390 2080 sptd ( LockedFile.Multi.Generic ) - warning
16:59:10.0390 2080 sptd - detected LockedFile.Multi.Generic (1)
16:59:10.0437 2080 sr (39626e6dc1fb39434ec40c42722b660a) C:\WINDOWS\system32\DRIVERS\sr.sys
16:59:10.0453 2080 sr - ok
16:59:10.0546 2080 Srv (47ddfc2f003f7f9f0592c6874962a2e7) C:\WINDOWS\system32\DRIVERS\srv.sys
16:59:10.0593 2080 Srv - ok
16:59:10.0687 2080 streamip (77813007ba6265c4b6098187e6ed79d2) C:\WINDOWS\system32\DRIVERS\StreamIP.sys
16:59:10.0687 2080 streamip - ok
16:59:10.0781 2080 swenum (3941d127aef12e93addf6fe6ee027e0f) C:\WINDOWS\system32\DRIVERS\swenum.sys
16:59:10.0781 2080 swenum - ok
16:59:10.0875 2080 swmidi (8ce882bcc6cf8a62f2b2323d95cb3d01) C:\WINDOWS\system32\drivers\swmidi.sys
16:59:10.0875 2080 swmidi - ok
16:59:10.0906 2080 symc810 - ok
16:59:10.0921 2080 symc8xx - ok
16:59:10.0937 2080 sym_hi - ok
16:59:10.0953 2080 sym_u3 - ok
16:59:11.0015 2080 SynTP (f08667f79bbd339547f477c75c3ed0b9) C:\WINDOWS\system32\DRIVERS\SynTP.sys
16:59:11.0015 2080 SynTP - ok
16:59:11.0046 2080 sysaudio (8b83f3ed0f1688b4958f77cd6d2bf290) C:\WINDOWS\system32\drivers\sysaudio.sys
16:59:11.0046 2080 sysaudio - ok
16:59:11.0093 2080 tap0801 (846b7c0e3f6370cdcce157a5b36e70cd) C:\WINDOWS\system32\DRIVERS\tap0801.sys
16:59:11.0093 2080 tap0801 - ok
16:59:11.0171 2080 Tcpip (9aefa14bd6b182d61e3119fa5f436d3d) C:\WINDOWS\system32\DRIVERS\tcpip.sys
16:59:11.0203 2080 Tcpip - ok
16:59:11.0250 2080 TDPIPE (6471a66807f5e104e4885f5b67349397) C:\WINDOWS\system32\drivers\TDPIPE.sys
16:59:11.0250 2080 TDPIPE - ok
16:59:11.0265 2080 TDTCP (c56b6d0402371cf3700eb322ef3aaf61) C:\WINDOWS\system32\drivers\TDTCP.sys
16:59:11.0265 2080 TDTCP - ok
16:59:11.0281 2080 teamviewervpn (9101fffcfccd1a30e870a5b8a9091b10) C:\WINDOWS\system32\DRIVERS\teamviewervpn.sys
16:59:11.0281 2080 teamviewervpn - ok
16:59:11.0375 2080 TermDD (88155247177638048422893737429d9e) C:\WINDOWS\system32\DRIVERS\termdd.sys
16:59:11.0390 2080 TermDD - ok
16:59:11.0484 2080 tmcomm (eb2283c0a4dfbd2e53d14f2c4d5a1e89) C:\WINDOWS\system32\drivers\tmcomm.sys
16:59:11.0484 2080 tmcomm - ok
16:59:11.0515 2080 TosIde - ok
16:59:11.0687 2080 TrueSight (ddbf8e194041469f26fc6cbc8264beb0) C:\Documents and Settings\dmi\Bureau\TrueSight.sys
16:59:11.0703 2080 TrueSight - ok
16:59:11.0765 2080 Udfs (5787b80c2e3c5e2f56c2a233d91fa2c9) C:\WINDOWS\system32\drivers\Udfs.sys
16:59:11.0781 2080 Udfs - ok
16:59:11.0859 2080 ultra - ok
16:59:11.0953 2080 Update (402ddc88356b1bac0ee3dd1580c76a31) C:\WINDOWS\system32\DRIVERS\update.sys
16:59:11.0968 2080 Update - ok
16:59:12.0031 2080 usbccgp (173f317ce0db8e21322e71b7e60a27e8) C:\WINDOWS\system32\DRIVERS\usbccgp.sys
16:59:12.0031 2080 usbccgp - ok
16:59:12.0125 2080 usbehci (65dcf09d0e37d4c6b11b5b0b76d470a7) C:\WINDOWS\system32\DRIVERS\usbehci.sys
16:59:12.0125 2080 usbehci - ok
16:59:12.0156 2080 usbhub (1ab3cdde553b6e064d2e754efe20285c) C:\WINDOWS\system32\DRIVERS\usbhub.sys
16:59:12.0156 2080 usbhub - ok
16:59:12.0218 2080 usbprint (a717c8721046828520c9edf31288fc00) C:\WINDOWS\system32\DRIVERS\usbprint.sys
16:59:12.0218 2080 usbprint - ok
16:59:12.0281 2080 usbscan (a0b8cf9deb1184fbdd20784a58fa75d4) C:\WINDOWS\system32\DRIVERS\usbscan.sys
16:59:12.0281 2080 usbscan - ok
16:59:12.0375 2080 USBSTOR (a32426d9b14a089eaa1d922e0c5801a9) C:\WINDOWS\system32\DRIVERS\USBSTOR.SYS
16:59:12.0375 2080 USBSTOR - ok
16:59:12.0390 2080 usbuhci (26496f9dee2d787fc3e61ad54821ffe6) C:\WINDOWS\system32\DRIVERS\usbuhci.sys
16:59:12.0390 2080 usbuhci - ok
16:59:12.0421 2080 usbvideo (63bbfca7f390f4c49ed4b96bfb1633e0) C:\WINDOWS\system32\Drivers\usbvideo.sys
16:59:12.0421 2080 usbvideo - ok
16:59:12.0468 2080 VgaSave (0d3a8fafceacd8b7625cd549757a7df1) C:\WINDOWS\System32\drivers\vga.sys
16:59:12.0468 2080 VgaSave - ok
16:59:12.0484 2080 ViaIde - ok
16:59:12.0515 2080 VolSnap (46de1126684369bace4849e4fc8c43ca) C:\WINDOWS\system32\drivers\VolSnap.sys
16:59:12.0515 2080 VolSnap - ok
16:59:12.0546 2080 Wanarp (e20b95baedb550f32dd489265c1da1f6) C:\WINDOWS\system32\DRIVERS\wanarp.sys
16:59:12.0546 2080 Wanarp - ok
16:59:12.0625 2080 Wdf01000 (fd47474bd21794508af449d9d91af6e6) C:\WINDOWS\system32\DRIVERS\Wdf01000.sys
16:59:12.0640 2080 Wdf01000 - ok
16:59:12.0640 2080 WDICA - ok
16:59:12.0703 2080 wdmaud (6768acf64b18196494413695f0c3a00f) C:\WINDOWS\system32\drivers\wdmaud.sys
16:59:12.0718 2080 wdmaud - ok
16:59:12.0828 2080 WmiAcpi (c42584fd66ce9e17403aebca199f7bdb) C:\WINDOWS\system32\DRIVERS\wmiacpi.sys
16:59:12.0828 2080 WmiAcpi - ok
16:59:12.0843 2080 WSTCODEC (c98b39829c2bbd34e454150633c62c78) C:\WINDOWS\system32\DRIVERS\WSTCODEC.SYS
16:59:12.0843 2080 WSTCODEC - ok
16:59:12.0890 2080 WudfPf (f15feafffbb3644ccc80c5da584e6311) C:\WINDOWS\system32\DRIVERS\WudfPf.sys
16:59:12.0890 2080 WudfPf - ok
16:59:12.0921 2080 WudfRd (28b524262bce6de1f7ef9f510ba3985b) C:\WINDOWS\system32\DRIVERS\wudfrd.sys
16:59:12.0921 2080 WudfRd - ok
16:59:12.0953 2080 MBR (0x1B8) (c99c3199cfaa4cbdcd91493f6d113a50) \Device\Harddisk0\DR0
16:59:13.0062 2080 \Device\Harddisk0\DR0 - ok
16:59:13.0062 2080 Boot (0x1200) (7c8d0dcb31f179aff5003f6445918649) \Device\Harddisk0\DR0\Partition0
16:59:13.0062 2080 \Device\Harddisk0\DR0\Partition0 - ok
16:59:13.0062 2080 ============================================================
16:59:13.0062 2080 Scan finished
16:59:13.0062 2080 ============================================================
16:59:13.0078 2232 Detected object count: 1
16:59:13.0078 2232 Actual detected object count: 1
16:59:19.0546 2232 sptd ( LockedFile.Multi.Generic ) - skipped by user
16:59:19.0546 2232 sptd ( LockedFile.Multi.Generic ) - User select action: Skip
Désolé, je dois faire une petite pause de 20 minutes car je dois impérativement m'occuper de mes filles...

Je retravaille sur ce problème juste après...
Messages postés
35445
Date d'inscription
jeudi 18 décembre 2008
Statut
Contributeur sécurité
Dernière intervention
5 mai 2017
4 783
Non, le locked c'est le driver de Daemon Tool :)

En attente de combofix donc ;)
Messages postés
42
Date d'inscription
mardi 27 septembre 2011
Statut
Membre
Dernière intervention
29 septembre 2011

Me voilà de retour...

Voici donc le rapport de Combofix :

ComboFix 11-09-27.01 - dmi 27/09/2011 17:39:36.1.2 - x86
Microsoft Windows XP Professionnel 5.1.2600.3.1252.33.1036.18.1977.1391 [GMT 2:00]
Lancé depuis: c:\documents and settings\dmi\Bureau\dubitoph.exe
AV: AVG Anti-Virus Free Edition 2011 *Disabled/Updated* {17DDD097-36FF-435F-9E1B-52D74245D6BF}
.
[i] ADS - system32: deleted 40 bytes in 1 streams. [/i]
[i] ADS - WINDOWS: deleted 24 bytes in 1 streams. [/i]
.
(((((((((((((((((((((((((((((((((((( Autres suppressions ))))))))))))))))))))))))))))))))))))))))))))))))
.
.
c:\documents and settings\chr\Local Settings\Application Data\ApplicationHistory
c:\documents and settings\chr\Local Settings\Application Data\ApplicationHistory\ngen.exe.2c05686e.ini
c:\documents and settings\dmi\foito.exe
c:\documents and settings\dmi\gob.exe
c:\documents and settings\dmi\iob.exe
c:\documents and settings\dmi\Mes documents\HiJackThis.exe
c:\documents and settings\dmi\sod64.exe
c:\program files\InstallPedia
c:\program files\InstallPedia\Ionic.Zip.Reduced.dll
c:\program files\InstallPedia\lnetworker.exe
c:\program files\InstallPedia\pref_updater.exe
c:\program files\InstallPedia\service.exe
c:\program files\InstallPedia\Utils.dll
c:\program files\Mozilla Firefox\extensions\searchsettings@spigot.com
c:\program files\Search Settings
c:\program files\Search Settings\FF\chrome.manifest
c:\program files\Search Settings\FF\chrome\content\plugin.js
c:\program files\Search Settings\FF\chrome\content\plugin.xul
c:\program files\Search Settings\FF\chrome\content\protection.js
c:\program files\Search Settings\FF\chrome\content\utils.js
c:\program files\Search Settings\FF\chrome\locale\en-US\searchsettingsplugin.dtd
c:\program files\Search Settings\FF\chrome\locale\en-US\searchsettingsplugin.properties
c:\program files\Search Settings\FF\components\IFBHOSearch.xpt
c:\program files\Search Settings\FF\components\IFBHOSearchHelperEngine.xpt
c:\program files\Search Settings\FF\components\IFHelperPreferences.xpt
c:\program files\Search Settings\FF\install.rdf
c:\program files\Search Settings\SeARchsettings.dll
c:\program files\Search Settings\SearchSettings.exe
c:\windows\$NtUninstallKB2533$
c:\windows\$NtUninstallKB2533$\2962961871
c:\windows\$NtUninstallKB2533$\4156359079\@
c:\windows\$NtUninstallKB2533$\4156359079\bckfg.tmp
c:\windows\$NtUninstallKB2533$\4156359079\cfg.ini
c:\windows\$NtUninstallKB2533$\4156359079\Desktop.ini
c:\windows\$NtUninstallKB2533$\4156359079\kwrd.dll
c:\windows\$NtUninstallKB2533$\4156359079\L\owrwkutu
c:\windows\$NtUninstallKB2533$\4156359079\U\00000001.@
c:\windows\$NtUninstallKB2533$\4156359079\U\00000002.@
c:\windows\$NtUninstallKB2533$\4156359079\U\80000000.@
c:\windows\$NtUninstallKB2533$\4156359079\U\80000032.@
c:\windows\2801909239
c:\windows\system32\instsrv.exe
.
.
((((((((((((((((((((((((((((((((((((((( Pilotes/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
-------\Legacy_NOTEPAD
-------\Legacy_I.P_services
-------\Legacy_I.P_services
-------\Service_I.P services
-------\Service_I.P services
.
.
((((((((((((((((((((((((((((( Fichiers créés du 2011-08-27 au 2011-09-27 ))))))))))))))))))))))))))))))))))))
.
.
2011-09-27 13:32 . 2011-09-27 13:32 -------- d--h--w- c:\windows\msdownld.tmp
2011-09-27 12:21 . 2011-09-27 12:21 -------- d-----w- c:\documents and settings\dmi\Application Data\QuickScan
2011-09-27 11:54 . 2011-09-27 11:54 -------- d-----w- c:\program files\Trend Micro
2011-09-27 10:21 . 2011-09-27 10:24 -------- d-----w- c:\documents and settings\All Users\Application Data\InternetFax
2011-09-27 10:21 . 2011-09-27 10:22 -------- d-----w- c:\documents and settings\All Users\Application Data\tpfmon
2011-09-27 10:21 . 2011-09-27 10:21 -------- d-----w- c:\program files\Alliance MCA
2011-09-17 12:42 . 2011-09-17 12:42 -------- d-----w- C:\Poker
2011-09-16 21:44 . 2011-09-16 21:44 -------- d-----w- c:\documents and settings\dmi\Application Data\BankPerfect
2011-09-16 17:26 . 2011-09-16 17:26 -------- d-----w- c:\documents and settings\dmi\Application Data\AlauxSoft
2011-09-16 16:45 . 2011-09-16 16:54 -------- d-----w- c:\program files\Microsoft Money 2005
2011-09-11 10:06 . 2011-09-11 10:06 -------- d-----w- c:\program files\AnglaisFacile.com
2011-09-09 11:03 . 2011-09-09 11:09 -------- d-----w- c:\program files\PDFCreator
.
.
.
(((((((((((((((((((((((((((((((((( Compte-rendu de Find3M ))))))))))))))))))))))))))))))))))))))))))))))))
.
2011-09-27 14:39 . 2008-10-07 12:04 58752 ----a-w- c:\windows\system32\drivers\redbook.sys
2011-09-27 11:41 . 2011-05-15 11:40 404640 ----a-w- c:\windows\system32\FlashPlayerCPLApp.cpl
2011-07-18 17:19 . 2011-07-18 17:19 0 ---ha-w- c:\documents and settings\dmi\Local Settings\Application Data\BITA2.tmp
2011-06-29 16:51 . 2010-12-19 12:37 101720 ----a-w- c:\windows\system32\drivers\SBREDrv.sys
2011-09-09 11:02 . 2011-05-20 18:20 134104 ----a-w- c:\program files\mozilla firefox\components\browsercomps.dll
.
.
------- Sigcheck -------
Note: Unsigned files aren't necessarily malware.
.
[-] 2008-10-07 . 43D3342D9612FB5BE00807C32EEED77D . 1571840 . . [5.1.2600.5512] . . c:\windows\system32\sfcfiles.dll
.
[7] 2011-04-21 . B6E13F9C120C776A89D783E26D6C15C5 . 634648 . . [7.00.6000.17098] . . c:\windows\system32\dllcache\iexplore.exe
[7] 2011-04-21 . 3E23DBEBE1020D52C63235E4189FAC03 . 634648 . . [7.00.6000.21300] . . c:\windows\$hf_mig$\KB2530548-IE7\SP3QFE\iexplore.exe
[7] 2011-02-14 . E4A798DFDE7FE6E79F23548F0EF0F844 . 634648 . . [7.00.6000.17096] . . c:\windows\ie7updates\KB2530548-IE7\iexplore.exe
[7] 2011-02-14 . E3CC8CCF21BFDC954255BB17083FB9F0 . 634648 . . [7.00.6000.21298] . . c:\windows\$hf_mig$\KB2497640-IE7\SP3QFE\iexplore.exe
[7] 2010-10-18 . 72D1F43C4146D312B0DB6AB98C21340E . 634648 . . [7.00.6000.17093] . . c:\windows\ie7updates\KB2497640-IE7\iexplore.exe
[7] 2010-10-18 . DA6E1F0F1932B62DD2F6ED05541C555C . 634648 . . [7.00.6000.21295] . . c:\windows\$hf_mig$\KB2416400-IE7\SP3QFE\iexplore.exe
[7] 2010-08-25 . E5412ED9E07C42C20C48D3FF71E6B1E8 . 634648 . . [7.00.6000.17091] . . c:\windows\ie7updates\KB2416400-IE7\iexplore.exe
[7] 2010-08-25 . F047BEB9771E45A05F425499A30F9BBA . 634648 . . [7.00.6000.21293] . . c:\windows\$hf_mig$\KB2360131-IE7\SP3QFE\iexplore.exe
[7] 2010-04-16 . C4BA5E36FB57F547117305BF1E0FE454 . 634656 . . [7.00.6000.17055] . . c:\windows\ie7updates\KB2360131-IE7\iexplore.exe
[7] 2010-04-16 . B24A4E23A2FEDB6976EB04D334AD82B2 . 634648 . . [7.00.6000.21256] . . c:\windows\$hf_mig$\KB982381-IE7\SP3QFE\iexplore.exe
[7] 2009-12-18 . 53C291F3B01EECECBD7FD358EA3ACC94 . 634648 . . [7.00.6000.16981] . . c:\windows\ie7updates\KB982381-IE7\iexplore.exe
[7] 2009-12-18 . D19E56D5930C37CF211867DF450C372A . 634632 . . [7.00.6000.21183] . . c:\windows\$hf_mig$\KB978207-IE7\SP3QFE\iexplore.exe
[7] 2009-10-28 . 80675329E0FD54F016C4F8A83C616349 . 634632 . . [7.00.6000.21148] . . c:\windows\$hf_mig$\KB976325-IE7\SP3QFE\iexplore.exe
[7] 2009-10-28 . 4F9B04D546C23A295F3F0AE015BE51DB . 634632 . . [7.00.6000.16945] . . c:\windows\ie7updates\KB978207-IE7\iexplore.exe
[7] 2009-08-27 . F232BA9F39BC0F722672C7E79E68EBEA . 634648 . . [7.00.6000.16915] . . c:\windows\ie7updates\KB976325-IE7\iexplore.exe
[7] 2009-08-27 . 332EC7562F3AA7364F2D4231C56DA986 . 634648 . . [7.00.6000.21115] . . c:\windows\$hf_mig$\KB974455-IE7\SP3QFE\iexplore.exe
[7] 2009-06-29 . 3CFC56F73D494FC1AA2B6E981DF15ACD . 634632 . . [7.00.6000.16876] . . c:\windows\ie7updates\KB974455-IE7\iexplore.exe
[7] 2009-06-29 . 02E2754D3E566C11A4934825920C47DD . 634632 . . [7.00.6000.21073] . . c:\windows\$hf_mig$\KB972260-IE7\SP3QFE\iexplore.exe
[7] 2009-04-25 . 092A7F2B49A19ECCE5369D3CB2276148 . 636088 . . [7.00.6000.16850] . . c:\windows\ie7updates\KB972260-IE7\iexplore.exe
[7] 2009-04-25 . C0503FD8D163652735C1EE900672A75C . 636088 . . [7.00.6000.21045] . . c:\windows\$hf_mig$\KB969897-IE7\SP3QFE\iexplore.exe
[7] 2009-02-28 . BCD8E48709BE4A79606F0B6E8E9A6162 . 636088 . . [7.00.6000.21020] . . c:\windows\$hf_mig$\KB963027-IE7\SP3QFE\iexplore.exe
[7] 2009-02-28 . A251068640DDB69FD7805B57D89D7FF7 . 636072 . . [7.00.6000.16827] . . c:\windows\ie7updates\KB969897-IE7\iexplore.exe
[7] 2008-12-19 . 15E8A89499741D5CF59A9CF6463A4339 . 634024 . . [7.00.6000.20978] . . c:\windows\$hf_mig$\KB961260-IE7\SP2QFE\iexplore.exe
[7] 2008-12-19 . 030D78FE84A086ED376EFCBD2D72C522 . 634024 . . [7.00.6000.16791] . . c:\windows\ie7updates\KB963027-IE7\iexplore.exe
[7] 2008-07-30 . DE49B348A18369B4626FBA1D49B07FB4 . 622080 . . [7.00.5730.13] . . c:\windows\ie7updates\KB953838-IE7\iexplore.exe
[7] 2008-06-23 . 64E376A47763DAEABCDA14BD5B6EA286 . 625664 . . [7.00.6000.16705] . . c:\windows\ie7updates\KB961260-IE7\iexplore.exe
[7] 2008-06-23 . C52A9EF571E91535EB78DB4B8B95EA07 . 625664 . . [7.00.6000.20861] . . c:\windows\$hf_mig$\KB953838-IE7\SP2QFE\iexplore.exe
.
((((((((((((((((((((((((((((((((( Points de chargement Reg ))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* les éléments vides & les éléments initiaux légitimes ne sont pas listés
REGEDIT4
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"AVG_TRAY"="c:\program files\AVG\AVG10\avgtray.exe" [2011-09-10 2338656]
"QuickTime Task"="c:\program files\QuickTime\qttask.exe" [2010-11-29 421888]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2011-09-07 37296]
"Adobe ARM"="c:\program files\Fichiers communs\Adobe\ARM\1.0\AdobeARM.exe" [2011-03-30 937920]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce]
"AvgUninstallURL"="start http://www.avg.fr/fr.special-uninstallation-feedback-appf?lic=OQBBAFYARgBSAEUARQAtAFYAQQBFAEEAWQAtAFQAMwBMAFUARQAtAE4ATAAzAEQAQQAtAEMAQgBVAEsASAAtAEoARgA3AE0AOQA&inst=NwA3AC0ANAA0ADcAMQAzADQAOAA5ADUALQBUADQALQBGAEwAKwA5AC0AWABPADMANgArADEALQBYAE8AOQArADEA&prod=90&ver=9.0.894" [?]
.
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\CTFMON.EXE" [2008-04-13 15360]
.
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\RunOnce]
"nltide_2"="shell32" [X]
.
c:\documents and settings\utilisateur\Menu D'marrer\Programmes\D'marrage\
OpenOffice.org 3.1.lnk - c:\program files\OpenOffice.org 3\program\quickstart.exe [2009-8-18 384000]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\LMIinit]
2010-12-08 12:11 87424 ----a-w- c:\windows\system32\LMIinit.dll
.
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\session manager]
BootExecute REG_MULTI_SZ autocheck autochk *\0c:\progra~1\AVG\AVG10\avgchsvx.exe /sync\0c:\progra~1\AVG\AVG10\avgrsx.exe /sync /restart
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Wdf01000.sys]
@="Driver"
.
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Menu Démarrer^Programmes^Démarrage^BTTray.lnk]
path=c:\documents and settings\All Users\Menu Démarrer\Programmes\Démarrage\BTTray.lnk
backup=c:\windows\pss\BTTray.lnkCommon Startup
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\AccelerometerSysTrayApplet]
2008-04-11 12:16 77672 ----a-w- c:\windows\system32\accelerometerST.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe ARM]
2011-03-30 04:59 937920 ----a-r- c:\program files\Fichiers communs\Adobe\ARM\1.0\AdobeARM.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe Reader Speed Launcher]
2011-09-07 22:58 37296 ----a-w- c:\program files\Adobe\Reader 9.0\Reader\reader_sl.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\CanonMyPrinter]
2009-10-19 01:12 1983816 ----a-w- c:\program files\Canon\MyPrinter\BJMYPRT.EXE
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Client Access Express Welcome]
2005-06-09 03:30 20480 ----a-w- c:\program files\IBM\Client Access\cwbwlwiz.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Client Access Help Update]
2005-06-09 03:30 24626 ----a-w- c:\program files\IBM\Client Access\cwbinhlp.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Client Access PC5250 Sound]
2005-06-09 03:30 40960 ----a-w- c:\program files\IBM\Client Access\Emulator\pcssnd.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Client Access Service]
2005-06-09 03:30 20530 ----a-w- c:\program files\IBM\Client Access\cwbsvstr.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ctfmon.exe]
2008-04-13 17:34 15360 ----a-w- c:\windows\system32\ctfmon.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Firefox]
2011-09-09 11:02 924632 ----a-w- c:\program files\Mozilla Firefox\firefox.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\HotKeysCmds]
2008-06-05 08:09 170520 ----a-w- c:\windows\system32\hkcmd.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\IAAnotif]
2008-04-18 11:53 178712 ----a-w- c:\program files\Intel\Intel Matrix Storage Manager\IAAnotif.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\IgfxTray]
2008-06-05 08:09 150040 ----a-w- c:\windows\system32\igfxtray.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\LogMeIn GUI]
2010-01-27 10:22 63048 ----a-w- c:\program files\LogMeIn\x86\LogMeInSystray.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\openvpn-gui]
2005-08-18 08:55 99328 ----a-w- c:\program files\OpenVPN\bin\openvpn-gui.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Persistence]
2008-06-05 08:09 141848 ----a-w- c:\windows\system32\igfxpers.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QlbCtrl.exe]
2008-06-03 14:40 177456 ----a-w- c:\program files\Hewlett-Packard\HP Quick Launch Buttons\QLBCTRL.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task]
2010-11-29 16:38 421888 ----a-w- c:\program files\QuickTime\QTTask.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SoundMAX]
2008-03-24 11:43 884736 ----a-w- c:\program files\Analog Devices\SoundMAX\SMax4.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SoundMAXPnP]
2008-04-04 13:09 1044480 ----a-w- c:\program files\Analog Devices\Core\smax4pnp.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SunJavaUpdateSched]
2010-05-14 09:44 248552 ----a-w- c:\program files\Fichiers communs\Java\Java Update\jusched.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SynTPEnh]
2008-06-20 14:19 1310720 ----a-w- c:\program files\Synaptics\SynTP\SynTPEnh.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\TomTomHOME.exe]
2010-12-10 12:28 247144 ----a-w- c:\program files\TomTom HOME 2\TomTomHOMERunner.exe
.
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
.
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\Mozilla Firefox\\firefox.exe"=
"c:\\Program Files\\eMule\\emule.exe"=
"c:\\Program Files\\TeamViewer\\Version5\\TeamViewer.exe"=
"c:\\Program Files\\UltraVNC\\winvnc.exe"=
"c:\\wamp\\bin\\apache\\Apache2.2.11\\bin\\httpd.exe"=
"c:\\hb32.exe"=
"c:\\WINDOWS\\system32\\mmc.exe"=
"c:\\Program Files\\Maïdo Production\\IziSpot 4\\IziSpot.exe"=
"c:\\Program Files\\AVG\\AVG10\\avgmfapx.exe"=
"c:\\Program Files\\Skype\\Phone\\Skype.exe"=
"c:\\Program Files\\AVG\\AVG10\\avgdiagex.exe"=
"c:\\Program Files\\AVG\\AVG10\\avgnsx.exe"=
"c:\\Program Files\\AVG\\AVG10\\avgemcx.exe"=
.
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"5900:TCP"= 5900:TCP:VNC
"5800:TCP"= 5800:TCP:vnc5800
"22:TCP"= 22:TCP:SSHD
"8000:UDP"= 8000:UDP:Express Talk RTP Incoming Audio (UDP)
"8001:UDP"= 8001:UDP:Express Talk RTP Incoming Audio (UDP)
"8002:UDP"= 8002:UDP:Express Talk RTP Incoming Audio (UDP)
"8003:UDP"= 8003:UDP:Express Talk RTP Incoming Audio (UDP)
"8004:UDP"= 8004:UDP:Express Talk RTP Incoming Audio (UDP)
"8005:UDP"= 8005:UDP:Express Talk RTP Incoming Audio (UDP)
"81:TCP"= 81:TCP:Axon Virtual PBX Web Server
"4100:UDP"= 4100:UDP:uPNP Router Control Port
"8006:UDP"= 8006:UDP:Express Talk RTP Incoming Audio (UDP)
"8007:UDP"= 8007:UDP:Express Talk RTP Incoming Audio (UDP)
"8008:UDP"= 8008:UDP:Express Talk RTP Incoming Audio (UDP)
"8009:UDP"= 8009:UDP:Express Talk RTP Incoming Audio (UDP)
"5060:UDP"= 5060:UDP:Express Talk Sip Incoming Calls (UDP)
"5985:TCP"= 5985:TCP:*:Disabled:Gestion à distance de Windows
.
R0 a347bus;a347bus;c:\windows\system32\drivers\a347bus.sys [07/03/2010 19:08 160640]
R0 a347scsi;a347scsi;c:\windows\system32\drivers\a347scsi.sys [07/03/2010 19:08 5248]
R0 AVGIDSEH;AVGIDSEH;c:\windows\system32\drivers\AVGIDSEH.sys [22/02/2011 08:13 22992]
R0 Avgrkx86;AVG Anti-Rootkit Driver;c:\windows\system32\drivers\avgrkx86.sys [19/01/2011 04:32 32592]
R0 Lbd;Lbd;c:\windows\system32\drivers\Lbd.sys [19/12/2010 14:37 64288]
R0 SFAUDIO;Sonic Focus DSP Driver;c:\windows\system32\drivers\sfaudio.sys [28/03/2008 10:14 24064]
R0 sptd;sptd;c:\windows\system32\drivers\sptd.sys [17/05/2009 18:52 721904]
R1 Avgldx86;AVG AVI Loader Driver;c:\windows\system32\drivers\avgldx86.sys [07/01/2011 06:41 248656]
R1 Avgtdix;AVG TDI Driver;c:\windows\system32\drivers\avgtdix.sys [10/02/2011 07:54 297168]
R2 Application Updater;Application Updater;c:\program files\Application Updater\ApplicationUpdater.exe [08/01/2010 00:51 380928]
R2 ATService;AuthenTec Fingerprint Service;c:\program files\Fingerprint Sensor\AtService.exe [09/05/2008 16:09 1168632]
R2 avgwd;AVG WatchDog;c:\program files\AVG\AVG10\avgwdsvc.exe [08/02/2011 05:33 269520]
R2 backupSpeedCall;backupSpeedCall;c:\windows\system32\srvany.exe [28/01/2010 20:20 8192]
R2 LMIGuardianSvc;LMIGuardianSvc;c:\program files\LogMeIn\x86\LMIGuardianSvc.exe [01/10/2010 12:40 374152]
R2 LMIInfo;LogMeIn Kernel Information Provider;c:\program files\LogMeIn\x86\rainfo.sys [27/01/2010 12:22 12856]
R2 OCS INVENTORY;OCS INVENTORY SERVICE;c:\program files\OCS Inventory Agent\OcsService.exe [28/10/2009 00:37 69632]
R2 OpenSSHd;OpenSSH Server;c:\program files\OpenSSH\bin\cygrunsrv.exe [18/03/2008 12:28 68096]
R2 TomTomHOMEService;TomTomHOMEService;c:\program files\TomTom HOME 2\TomTomHOMEService.exe [10/12/2010 14:29 92008]
R2 uvnc_service;uvnc_service;c:\program files\UltraVNC\winvnc.exe [07/10/2008 14:32 1590216]
R3 ATSwpWDF;AuthenTec TruePrint USB WDF Driver;c:\windows\system32\drivers\ATSwpWDF.sys [13/05/2008 08:30 475520]
R3 AVGIDSDriver;AVGIDSDriver;c:\windows\system32\drivers\AVGIDSDriver.sys [30/03/2011 17:17 134480]
R3 AVGIDSFilter;AVGIDSFilter;c:\windows\system32\drivers\AVGIDSFilter.sys [10/02/2011 07:53 24144]
R3 AVGIDSShim;AVGIDSShim;c:\windows\system32\drivers\AVGIDSShim.sys [10/02/2011 07:53 27216]
R3 IFXTPM;IFXTPM;c:\windows\system32\drivers\ifxtpm.sys [04/04/2007 19:16 41216]
R3 tap0801;TAP-Win32 Adapter V8;c:\windows\system32\drivers\tap0801.sys [24/06/2004 03:54 23552]
S2 AVGIDSAgent;AVGIDSAgent;c:\program files\AVG\AVG10\Identity Protection\Agent\Bin\AVGIDSAgent.exe [18/08/2011 01:33 7390560]
S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;c:\windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [18/03/2010 13:16 130384]
S2 gupdate1cb0bdd975ae192;Service Google Update (gupdate1cb0bdd975ae192);c:\program files\Google\Update\GoogleUpdate.exe [14/06/2010 18:21 133104]
S3 Com4QLBEx;Com4QLBEx;c:\program files\Hewlett-Packard\HP Quick Launch Buttons\Com4QLBEx.exe [07/10/2008 15:42 193840]
S3 gupdatem;Service Google Update (gupdatem);c:\program files\Google\Update\GoogleUpdate.exe [14/06/2010 18:21 133104]
S3 Lavasoft Kernexplorer;Lavasoft helper driver;\??\c:\program files\Lavasoft\Ad-Aware\KernExplorer.sys --> c:\program files\Lavasoft\Ad-Aware\KernExplorer.sys [?]
S3 NPF;NetGroup Packet Filter Driver;c:\windows\system32\drivers\npf.sys [29/06/2007 02:01 42512]
S3 SCR3XX2K;SCR3xx USB SmartCardReader;c:\windows\system32\drivers\SCR3XX2K.sys [21/06/2007 04:40 56448]
S3 teamviewervpn;TeamViewer VPN Adapter;c:\windows\system32\drivers\teamviewervpn.sys [25/01/2008 11:12 25088]
S3 TrueSight;TrueSight;c:\documents and settings\dmi\Bureau\TrueSight.sys [27/09/2011 16:10 60800]
S3 WinRM;Windows Remote Management (WS-Management);c:\windows\system32\svchost.exe -k WINRM [13/04/2008 19:34 14336]
S3 WPFFontCache_v0400;Windows Presentation Foundation Font Cache 4.0.0.0;c:\windows\Microsoft.NET\Framework\v4.0.30319\WPF\WPFFontCache_v0400.exe [18/03/2010 13:16 753504]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
WINRM REG_MULTI_SZ WINRM
.
Contenu du dossier 'Tâches planifiées'
.
2011-07-22 c:\windows\Tasks\AppleSoftwareUpdate.job
- c:\program files\Apple Software Update\SoftwareUpdate.exe [2011-06-01 15:57]
.
2011-09-27 c:\windows\Tasks\Google Software Updater.job
- c:\program files\Google\Common\Google Updater\GoogleUpdaterService.exe [2009-07-23 17:26]
.
2011-09-27 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\program files\Google\Update\GoogleUpdate.exe [2010-06-14 16:21]
.
2011-09-27 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\program files\Google\Update\GoogleUpdate.exe [2010-06-14 16:21]
.
.
------- Examen supplémentaire -------
.
uStart Page = hxxp://www.01net.com/
mStart Page = hxxp://www.foozir.com/
uInternet Connection Wizard,ShellNext = https://217.145.35.171/dana-na/auth/url_2/welcome.cgi
uInternet Settings,ProxyOverride = <local>
uSearchURL,(Default) = hxxp://www.google.com/keyword/%s
IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~3\OFFICE11\EXCEL.EXE/3000
IE: Envoyer au périphérique &Bluetooth... - c:\program files\WIDCOMM\Bluetooth Software\btsendto_ie_ctx.htm
IE: Envoyer à Bluetooth - c:\program files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
Trusted Zone: chrnamur.be\chrvpn
Trusted Zone: fgov.be\*.minfin
Trusted Zone: localhost
Trusted Zone: winamax.fr\www
TCP: DhcpNameServer = 192.168.1.1
TCP: Interfaces\{0C17677C-5955-430B-969C-DD06005077E0}: NameServer = 216.146.35.35,216.146.36.36
TCP: Interfaces\{20D93359-B78E-45FE-8D0D-7B2198E2F30B}: NameServer = 216.146.35.35,216.146.36.36
TCP: Interfaces\{B947F0E2-0709-49E4-BD00-1240DDE8A598}: NameServer = 216.146.35.35,216.146.36.36
FF - ProfilePath - c:\documents and settings\dmi\Application Data\Mozilla\Firefox\Profiles\agx015nf.default\
FF - prefs.js: browser.startup.homepage - hxxp://localhost/speedcall/interfaces/interface.php
.
- - - - ORPHELINS SUPPRIMES - - - -
.
URLSearchHooks-{E312764E-7706-43F1-8DAB-FCDD2B1E416D} - (no file)
URLSearchHooks-{9CB65206-89C4-402c-BA80-02D8C59F9B1D} - (no file)
SafeBoot-19690823.sys
SafeBoot-61297986.sys
MSConfigStartUp-AVG9_TRAY - c:\progra~1\AVG\AVG9\avgtray.exe
MSConfigStartUp-IP Network - c:\program files\InstallPedia\lnetworker.exe
MSConfigStartUp-SearchSettings - c:\program files\Search Settings\SearchSettings.exe
MSConfigStartUp-SpybotSD TeaTimer - c:\program files\Spybot - Search & Destroy\TeaTimer.exe
.
.
.
**************************************************************************
.
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2011-09-27 17:49
Windows 5.1.2600 Service Pack 3 NTFS
.
Recherche de processus cachés ...
.
Recherche d'éléments en démarrage automatique cachés ...
.
Recherche de fichiers cachés ...
.
Scan terminé avec succès
Fichiers cachés: 0
.
**************************************************************************
.
--------------------- DLLs chargées dans les processus actifs ---------------------
.
- - - - - - - > 'winlogon.exe'(1436)
c:\windows\system32\LMIinit.dll
.
- - - - - - - > 'explorer.exe'(3544)
c:\windows\system32\eappprxy.dll
c:\windows\system32\WPDShServiceObj.dll
c:\windows\system32\btncopy.dll
c:\windows\system32\PortableDeviceTypes.dll
c:\windows\system32\PortableDeviceApi.dll
.
------------------------ Autres processus actifs ------------------------
.
c:\progra~1\AVG\AVG10\avgchsvx.exe
c:\progra~1\AVG\AVG10\avgrsx.exe
c:\program files\WIDCOMM\Bluetooth Software\bin\btwdins.exe
c:\windows\System32\SCardSvr.exe
c:\windows\system32\agrsmsvc.exe
c:\program files\Juniper Networks\Common Files\dsNcService.exe
c:\program files\Intel\Intel Matrix Storage Manager\IAANTMon.exe
c:\program files\Java\jre6\bin\jqs.exe
c:\program files\LogMeIn\x86\RaMaint.exe
c:\program files\LogMeIn\x86\LogMeIn.exe
c:\program files\AVG\AVG10\avgnsx.exe
c:\oracle\ora92\bin\omtsreco.exe
c:\program files\OpenSSH\usr\sbin\sshd.exe
c:\windows\system32\wscntfy.exe
c:\program files\AVG\AVG10\Identity Protection\agent\bin\avgidsmonitor.exe
.
**************************************************************************
.
Heure de fin: 2011-09-27 17:52:48 - La machine a redémarré
ComboFix-quarantined-files.txt 2011-09-27 15:52
.
Avant-CF: 120 411 574 272 octets libres
Après-CF: 120 935 960 576 octets libres
.
WindowsXP-KB310994-SP2-Pro-BootDisk-FRA.exe
[boot loader]
timeout=2
default=multi(0)disk(0)rdisk(0)partition(1)\WINDOWS
[operating systems]
c:\cmdcons\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons
UnsupportedDebug="do not select this" /debug
multi(0)disk(0)rdisk(0)partition(1)\WINDOWS="Microsoft Windows XP Professionnel" /noexecute=optin /fastdetect
.
- - End Of File - - A3BEBBEF2075ECB13888C93CA213601E
Messages postés
35445
Date d'inscription
jeudi 18 décembre 2008
Statut
Contributeur sécurité
Dernière intervention
5 mai 2017
4 783
▶ ▶ DÉSACTIVE TES PROTECTIONS DURANT LA PROCÉDURE

▶ ▶ SCRIPT PERSONNALISE A CET ORDINATEUR, NE PAS REPRODUIRE : DANGEREUX !!!!


▶ Créé un nouveau document texte : clic droit de souris sur le bureau > Nouveau > Document Texte, et copie dedans les lignes suivantes :

KillAll::

Driver::
Application Updater
backupSpeedCall
Lavasoft Kernexplorer

Folder::
c:\program files\Application Updater
c:\program files\Lavasoft

File::
c:\windows\system32\srvany.exe 

DDS::
uInternet Connection Wizard,ShellNext = https://217.145.35.171/dana-na/auth/url_2/welcome.cgi      
uInternet Settings,ProxyOverride = <local>      


▶ Enregistre ce fichier sous le nom CFScript

▶ Fait un glisser/déposer de ce fichier CFScript sur le fichier ComboFix.exe comme sur la capture :http://i261.photobucket.com/albums/ii49/Malekal_morte/CFScript-2.gif

▶ Combofix se lance, laisse toi guider..

▶ Patiente le temps du scan. Le bureau va disparaître à plusieurs reprises: c'est normal!
Ne touche à rien tant que le scan n'est pas terminé.
▶ Une fois le scan achevé, un rapport va s'afficher: poste son contenu, en précisant où en sont tes soucis

▶ Si le fichier ne s'ouvre pas, il se trouve ici > C:\ComboFix.txt
Messages postés
42
Date d'inscription
mardi 27 septembre 2011
Statut
Membre
Dernière intervention
29 septembre 2011

Voici le nouveau rapport, ci-après, le nouveau rapport. Je vais maintenant regarder au j'en suis au niveau des soucis rencontrés.

ComboFix 11-09-27.01 - dmi 27/09/2011 18:21:49.2.2 - x86
Microsoft Windows XP Professionnel 5.1.2600.3.1252.33.1036.18.1977.1227 [GMT 2:00]
Lancé depuis: c:\documents and settings\dmi\Bureau\dubitoph.exe
Commutateurs utilisés :: c:\documents and settings\dmi\Bureau\CFScript.txt
AV: AVG Anti-Virus Free Edition 2011 *Disabled/Updated* {17DDD097-36FF-435F-9E1B-52D74245D6BF}
.
FILE ::
"c:\windows\system32\srvany.exe"
.
.
(((((((((((((((((((((((((((((((((((( Autres suppressions ))))))))))))))))))))))))))))))))))))))))))))))))
.
.
c:\program files\Application Updater
c:\program files\Application Updater\ApplicationUpdater.exe
c:\program files\Application Updater\config.ini
c:\program files\Lavasoft
c:\windows\system32\srvany.exe
.
.
((((((((((((((((((((((((((((((((((((((( Pilotes/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
-------\Legacy_APPLICATION_UPDATER
-------\Legacy_BACKUPSPEEDCALL
-------\Legacy_LAVASOFT_KERNEXPLORER
-------\Service_Application Updater
-------\Service_backupSpeedCall
-------\Service_Lavasoft Kernexplorer
.
.
((((((((((((((((((((((((((((( Fichiers créés du 2011-08-27 au 2011-09-27 ))))))))))))))))))))))))))))))))))))
.
.
2011-09-27 13:32 . 2011-09-27 13:32 -------- d--h--w- c:\windows\msdownld.tmp
2011-09-27 12:21 . 2011-09-27 12:21 -------- d-----w- c:\documents and settings\dmi\Application Data\QuickScan
2011-09-27 11:54 . 2011-09-27 11:54 -------- d-----w- c:\program files\Trend Micro
2011-09-27 10:21 . 2011-09-27 10:24 -------- d-----w- c:\documents and settings\All Users\Application Data\InternetFax
2011-09-27 10:21 . 2011-09-27 10:22 -------- d-----w- c:\documents and settings\All Users\Application Data\tpfmon
2011-09-27 10:21 . 2011-09-27 10:21 -------- d-----w- c:\program files\Alliance MCA
2011-09-17 12:42 . 2011-09-17 12:42 -------- d-----w- C:\Poker
2011-09-16 21:44 . 2011-09-16 21:44 -------- d-----w- c:\documents and settings\dmi\Application Data\BankPerfect
2011-09-16 17:26 . 2011-09-16 17:26 -------- d-----w- c:\documents and settings\dmi\Application Data\AlauxSoft
2011-09-16 16:45 . 2011-09-16 16:54 -------- d-----w- c:\program files\Microsoft Money 2005
2011-09-11 10:06 . 2011-09-11 10:06 -------- d-----w- c:\program files\AnglaisFacile.com
2011-09-09 11:03 . 2011-09-09 11:09 -------- d-----w- c:\program files\PDFCreator
.
.
.
(((((((((((((((((((((((((((((((((( Compte-rendu de Find3M ))))))))))))))))))))))))))))))))))))))))))))))))
.
2011-09-27 14:39 . 2008-10-07 12:04 58752 ----a-w- c:\windows\system32\drivers\redbook.sys
2011-09-27 11:41 . 2011-05-15 11:40 404640 ----a-w- c:\windows\system32\FlashPlayerCPLApp.cpl
2011-07-18 17:19 . 2011-07-18 17:19 0 ---ha-w- c:\documents and settings\dmi\Local Settings\Application Data\BITA2.tmp
2011-06-29 16:51 . 2010-12-19 12:37 101720 ----a-w- c:\windows\system32\drivers\SBREDrv.sys
2011-09-09 11:02 . 2011-05-20 18:20 134104 ----a-w- c:\program files\mozilla firefox\components\browsercomps.dll
.
.
------- Sigcheck -------
Note: Unsigned files aren't necessarily malware.
.
[-] 2008-10-07 . 43D3342D9612FB5BE00807C32EEED77D . 1571840 . . [5.1.2600.5512] . . c:\windows\system32\sfcfiles.dll
.
[7] 2011-04-21 . B6E13F9C120C776A89D783E26D6C15C5 . 634648 . . [7.00.6000.17098] . . c:\windows\system32\dllcache\iexplore.exe
[7] 2011-04-21 . 3E23DBEBE1020D52C63235E4189FAC03 . 634648 . . [7.00.6000.21300] . . c:\windows\$hf_mig$\KB2530548-IE7\SP3QFE\iexplore.exe
[7] 2011-02-14 . E4A798DFDE7FE6E79F23548F0EF0F844 . 634648 . . [7.00.6000.17096] . . c:\windows\ie7updates\KB2530548-IE7\iexplore.exe
[7] 2011-02-14 . E3CC8CCF21BFDC954255BB17083FB9F0 . 634648 . . [7.00.6000.21298] . . c:\windows\$hf_mig$\KB2497640-IE7\SP3QFE\iexplore.exe
[7] 2010-10-18 . 72D1F43C4146D312B0DB6AB98C21340E . 634648 . . [7.00.6000.17093] . . c:\windows\ie7updates\KB2497640-IE7\iexplore.exe
[7] 2010-10-18 . DA6E1F0F1932B62DD2F6ED05541C555C . 634648 . . [7.00.6000.21295] . . c:\windows\$hf_mig$\KB2416400-IE7\SP3QFE\iexplore.exe
[7] 2010-08-25 . E5412ED9E07C42C20C48D3FF71E6B1E8 . 634648 . . [7.00.6000.17091] . . c:\windows\ie7updates\KB2416400-IE7\iexplore.exe
[7] 2010-08-25 . F047BEB9771E45A05F425499A30F9BBA . 634648 . . [7.00.6000.21293] . . c:\windows\$hf_mig$\KB2360131-IE7\SP3QFE\iexplore.exe
[7] 2010-04-16 . C4BA5E36FB57F547117305BF1E0FE454 . 634656 . . [7.00.6000.17055] . . c:\windows\ie7updates\KB2360131-IE7\iexplore.exe
[7] 2010-04-16 . B24A4E23A2FEDB6976EB04D334AD82B2 . 634648 . . [7.00.6000.21256] . . c:\windows\$hf_mig$\KB982381-IE7\SP3QFE\iexplore.exe
[7] 2009-12-18 . 53C291F3B01EECECBD7FD358EA3ACC94 . 634648 . . [7.00.6000.16981] . . c:\windows\ie7updates\KB982381-IE7\iexplore.exe
[7] 2009-12-18 . D19E56D5930C37CF211867DF450C372A . 634632 . . [7.00.6000.21183] . . c:\windows\$hf_mig$\KB978207-IE7\SP3QFE\iexplore.exe
[7] 2009-10-28 . 80675329E0FD54F016C4F8A83C616349 . 634632 . . [7.00.6000.21148] . . c:\windows\$hf_mig$\KB976325-IE7\SP3QFE\iexplore.exe
[7] 2009-10-28 . 4F9B04D546C23A295F3F0AE015BE51DB . 634632 . . [7.00.6000.16945] . . c:\windows\ie7updates\KB978207-IE7\iexplore.exe
[7] 2009-08-27 . F232BA9F39BC0F722672C7E79E68EBEA . 634648 . . [7.00.6000.16915] . . c:\windows\ie7updates\KB976325-IE7\iexplore.exe
[7] 2009-08-27 . 332EC7562F3AA7364F2D4231C56DA986 . 634648 . . [7.00.6000.21115] . . c:\windows\$hf_mig$\KB974455-IE7\SP3QFE\iexplore.exe
[7] 2009-06-29 . 3CFC56F73D494FC1AA2B6E981DF15ACD . 634632 . . [7.00.6000.16876] . . c:\windows\ie7updates\KB974455-IE7\iexplore.exe
[7] 2009-06-29 . 02E2754D3E566C11A4934825920C47DD . 634632 . . [7.00.6000.21073] . . c:\windows\$hf_mig$\KB972260-IE7\SP3QFE\iexplore.exe
[7] 2009-04-25 . 092A7F2B49A19ECCE5369D3CB2276148 . 636088 . . [7.00.6000.16850] . . c:\windows\ie7updates\KB972260-IE7\iexplore.exe
[7] 2009-04-25 . C0503FD8D163652735C1EE900672A75C . 636088 . . [7.00.6000.21045] . . c:\windows\$hf_mig$\KB969897-IE7\SP3QFE\iexplore.exe
[7] 2009-02-28 . BCD8E48709BE4A79606F0B6E8E9A6162 . 636088 . . [7.00.6000.21020] . . c:\windows\$hf_mig$\KB963027-IE7\SP3QFE\iexplore.exe
[7] 2009-02-28 . A251068640DDB69FD7805B57D89D7FF7 . 636072 . . [7.00.6000.16827] . . c:\windows\ie7updates\KB969897-IE7\iexplore.exe
[7] 2008-12-19 . 15E8A89499741D5CF59A9CF6463A4339 . 634024 . . [7.00.6000.20978] . . c:\windows\$hf_mig$\KB961260-IE7\SP2QFE\iexplore.exe
[7] 2008-12-19 . 030D78FE84A086ED376EFCBD2D72C522 . 634024 . . [7.00.6000.16791] . . c:\windows\ie7updates\KB963027-IE7\iexplore.exe
[7] 2008-07-30 . DE49B348A18369B4626FBA1D49B07FB4 . 622080 . . [7.00.5730.13] . . c:\windows\ie7updates\KB953838-IE7\iexplore.exe
[7] 2008-06-23 . 64E376A47763DAEABCDA14BD5B6EA286 . 625664 . . [7.00.6000.16705] . . c:\windows\ie7updates\KB961260-IE7\iexplore.exe
[7] 2008-06-23 . C52A9EF571E91535EB78DB4B8B95EA07 . 625664 . . [7.00.6000.20861] . . c:\windows\$hf_mig$\KB953838-IE7\SP2QFE\iexplore.exe
.
((((((((((((((((((((((((((((( SnapShot@2011-09-27_15.49.13 )))))))))))))))))))))))))))))))))))))))))
.
+ 2011-09-27 16:28 . 2011-09-27 16:28 16384 c:\windows\temp\Perflib_Perfdata_138.dat
.
((((((((((((((((((((((((((((((((( Points de chargement Reg ))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* les éléments vides & les éléments initiaux légitimes ne sont pas listés
REGEDIT4
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"AVG_TRAY"="c:\program files\AVG\AVG10\avgtray.exe" [2011-09-10 2338656]
"QuickTime Task"="c:\program files\QuickTime\qttask.exe" [2010-11-29 421888]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2011-09-07 37296]
"Adobe ARM"="c:\program files\Fichiers communs\Adobe\ARM\1.0\AdobeARM.exe" [2011-03-30 937920]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce]
"AvgUninstallURL"="start http://www.avg.fr/fr.special-uninstallation-feedback-appf?lic=OQBBAFYARgBSAEUARQAtAFYAQQBFAEEAWQAtAFQAMwBMAFUARQAtAE4ATAAzAEQAQQAtAEMAQgBVAEsASAAtAEoARgA3AE0AOQA&inst=NwA3AC0ANAA0ADcAMQAzADQAOAA5ADUALQBUADQALQBGAEwAKwA5AC0AWABPADMANgArADEALQBYAE8AOQArADEA&prod=90&ver=9.0.894" [?]
.
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\CTFMON.EXE" [2008-04-13 15360]
.
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\RunOnce]
"nltide_2"="shell32" [X]
.
c:\documents and settings\utilisateur\Menu D'marrer\Programmes\D'marrage\
OpenOffice.org 3.1.lnk - c:\program files\OpenOffice.org 3\program\quickstart.exe [2009-8-18 384000]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\LMIinit]
2010-12-08 12:11 87424 ----a-w- c:\windows\system32\LMIinit.dll
.
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\session manager]
BootExecute REG_MULTI_SZ autocheck autochk *\0c:\progra~1\AVG\AVG10\avgchsvx.exe /sync\0c:\progra~1\AVG\AVG10\avgrsx.exe /sync /restart
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Wdf01000.sys]
@="Driver"
.
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Menu Démarrer^Programmes^Démarrage^BTTray.lnk]
path=c:\documents and settings\All Users\Menu Démarrer\Programmes\Démarrage\BTTray.lnk
backup=c:\windows\pss\BTTray.lnkCommon Startup
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\AccelerometerSysTrayApplet]
2008-04-11 12:16 77672 ----a-w- c:\windows\system32\accelerometerST.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe ARM]
2011-03-30 04:59 937920 ----a-r- c:\program files\Fichiers communs\Adobe\ARM\1.0\AdobeARM.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe Reader Speed Launcher]
2011-09-07 22:58 37296 ----a-w- c:\program files\Adobe\Reader 9.0\Reader\reader_sl.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\CanonMyPrinter]
2009-10-19 01:12 1983816 ----a-w- c:\program files\Canon\MyPrinter\BJMYPRT.EXE
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Client Access Express Welcome]
2005-06-09 03:30 20480 ----a-w- c:\program files\IBM\Client Access\cwbwlwiz.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Client Access Help Update]
2005-06-09 03:30 24626 ----a-w- c:\program files\IBM\Client Access\cwbinhlp.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Client Access PC5250 Sound]
2005-06-09 03:30 40960 ----a-w- c:\program files\IBM\Client Access\Emulator\pcssnd.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Client Access Service]
2005-06-09 03:30 20530 ----a-w- c:\program files\IBM\Client Access\cwbsvstr.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ctfmon.exe]
2008-04-13 17:34 15360 ----a-w- c:\windows\system32\ctfmon.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Firefox]
2011-09-09 11:02 924632 ----a-w- c:\program files\Mozilla Firefox\firefox.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\HotKeysCmds]
2008-06-05 08:09 170520 ----a-w- c:\windows\system32\hkcmd.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\IAAnotif]
2008-04-18 11:53 178712 ----a-w- c:\program files\Intel\Intel Matrix Storage Manager\IAAnotif.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\IgfxTray]
2008-06-05 08:09 150040 ----a-w- c:\windows\system32\igfxtray.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\LogMeIn GUI]
2010-01-27 10:22 63048 ----a-w- c:\program files\LogMeIn\x86\LogMeInSystray.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\openvpn-gui]
2005-08-18 08:55 99328 ----a-w- c:\program files\OpenVPN\bin\openvpn-gui.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Persistence]
2008-06-05 08:09 141848 ----a-w- c:\windows\system32\igfxpers.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QlbCtrl.exe]
2008-06-03 14:40 177456 ----a-w- c:\program files\Hewlett-Packard\HP Quick Launch Buttons\QLBCTRL.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task]
2010-11-29 16:38 421888 ----a-w- c:\program files\QuickTime\QTTask.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SoundMAX]
2008-03-24 11:43 884736 ----a-w- c:\program files\Analog Devices\SoundMAX\SMax4.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SoundMAXPnP]
2008-04-04 13:09 1044480 ----a-w- c:\program files\Analog Devices\Core\smax4pnp.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SunJavaUpdateSched]
2010-05-14 09:44 248552 ----a-w- c:\program files\Fichiers communs\Java\Java Update\jusched.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SynTPEnh]
2008-06-20 14:19 1310720 ----a-w- c:\program files\Synaptics\SynTP\SynTPEnh.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\TomTomHOME.exe]
2010-12-10 12:28 247144 ----a-w- c:\program files\TomTom HOME 2\TomTomHOMERunner.exe
.
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
.
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\Mozilla Firefox\\firefox.exe"=
"c:\\Program Files\\eMule\\emule.exe"=
"c:\\Program Files\\TeamViewer\\Version5\\TeamViewer.exe"=
"c:\\Program Files\\UltraVNC\\winvnc.exe"=
"c:\\wamp\\bin\\apache\\Apache2.2.11\\bin\\httpd.exe"=
"c:\\hb32.exe"=
"c:\\WINDOWS\\system32\\mmc.exe"=
"c:\\Program Files\\Maïdo Production\\IziSpot 4\\IziSpot.exe"=
"c:\\Program Files\\AVG\\AVG10\\avgmfapx.exe"=
"c:\\Program Files\\Skype\\Phone\\Skype.exe"=
"c:\\Program Files\\AVG\\AVG10\\avgdiagex.exe"=
"c:\\Program Files\\AVG\\AVG10\\avgnsx.exe"=
"c:\\Program Files\\AVG\\AVG10\\avgemcx.exe"=
.
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"5900:TCP"= 5900:TCP:VNC
"5800:TCP"= 5800:TCP:vnc5800
"22:TCP"= 22:TCP:SSHD
"8000:UDP"= 8000:UDP:Express Talk RTP Incoming Audio (UDP)
"8001:UDP"= 8001:UDP:Express Talk RTP Incoming Audio (UDP)
"8002:UDP"= 8002:UDP:Express Talk RTP Incoming Audio (UDP)
"8003:UDP"= 8003:UDP:Express Talk RTP Incoming Audio (UDP)
"8004:UDP"= 8004:UDP:Express Talk RTP Incoming Audio (UDP)
"8005:UDP"= 8005:UDP:Express Talk RTP Incoming Audio (UDP)
"81:TCP"= 81:TCP:Axon Virtual PBX Web Server
"4100:UDP"= 4100:UDP:uPNP Router Control Port
"8006:UDP"= 8006:UDP:Express Talk RTP Incoming Audio (UDP)
"8007:UDP"= 8007:UDP:Express Talk RTP Incoming Audio (UDP)
"8008:UDP"= 8008:UDP:Express Talk RTP Incoming Audio (UDP)
"8009:UDP"= 8009:UDP:Express Talk RTP Incoming Audio (UDP)
"5060:UDP"= 5060:UDP:Express Talk Sip Incoming Calls (UDP)
"5985:TCP"= 5985:TCP:*:Disabled:Gestion à distance de Windows
.
R0 a347bus;a347bus;c:\windows\system32\drivers\a347bus.sys [07/03/2010 19:08 160640]
R0 a347scsi;a347scsi;c:\windows\system32\drivers\a347scsi.sys [07/03/2010 19:08 5248]
R0 AVGIDSEH;AVGIDSEH;c:\windows\system32\drivers\AVGIDSEH.sys [22/02/2011 08:13 22992]
R0 Avgrkx86;AVG Anti-Rootkit Driver;c:\windows\system32\drivers\avgrkx86.sys [19/01/2011 04:32 32592]
R0 Lbd;Lbd;c:\windows\system32\drivers\Lbd.sys [19/12/2010 14:37 64288]
R0 SFAUDIO;Sonic Focus DSP Driver;c:\windows\system32\drivers\sfaudio.sys [28/03/2008 10:14 24064]
R0 sptd;sptd;c:\windows\system32\drivers\sptd.sys [17/05/2009 18:52 721904]
R1 Avgldx86;AVG AVI Loader Driver;c:\windows\system32\drivers\avgldx86.sys [07/01/2011 06:41 248656]
R1 Avgtdix;AVG TDI Driver;c:\windows\system32\drivers\avgtdix.sys [10/02/2011 07:54 297168]
R2 ATService;AuthenTec Fingerprint Service;c:\program files\Fingerprint Sensor\AtService.exe [09/05/2008 16:09 1168632]
R2 avgwd;AVG WatchDog;c:\program files\AVG\AVG10\avgwdsvc.exe [08/02/2011 05:33 269520]
R2 LMIGuardianSvc;LMIGuardianSvc;c:\program files\LogMeIn\x86\LMIGuardianSvc.exe [01/10/2010 12:40 374152]
R2 LMIInfo;LogMeIn Kernel Information Provider;c:\program files\LogMeIn\x86\rainfo.sys [27/01/2010 12:22 12856]
R2 OCS INVENTORY;OCS INVENTORY SERVICE;c:\program files\OCS Inventory Agent\OcsService.exe [28/10/2009 00:37 69632]
R2 OpenSSHd;OpenSSH Server;c:\program files\OpenSSH\bin\cygrunsrv.exe [18/03/2008 12:28 68096]
R2 TomTomHOMEService;TomTomHOMEService;c:\program files\TomTom HOME 2\TomTomHOMEService.exe [10/12/2010 14:29 92008]
R2 uvnc_service;uvnc_service;c:\program files\UltraVNC\winvnc.exe [07/10/2008 14:32 1590216]
R3 ATSwpWDF;AuthenTec TruePrint USB WDF Driver;c:\windows\system32\drivers\ATSwpWDF.sys [13/05/2008 08:30 475520]
R3 AVGIDSDriver;AVGIDSDriver;c:\windows\system32\drivers\AVGIDSDriver.sys [30/03/2011 17:17 134480]
R3 AVGIDSFilter;AVGIDSFilter;c:\windows\system32\drivers\AVGIDSFilter.sys [10/02/2011 07:53 24144]
R3 AVGIDSShim;AVGIDSShim;c:\windows\system32\drivers\AVGIDSShim.sys [10/02/2011 07:53 27216]
R3 IFXTPM;IFXTPM;c:\windows\system32\drivers\ifxtpm.sys [04/04/2007 19:16 41216]
R3 tap0801;TAP-Win32 Adapter V8;c:\windows\system32\drivers\tap0801.sys [24/06/2004 03:54 23552]
S2 AVGIDSAgent;AVGIDSAgent;c:\program files\AVG\AVG10\Identity Protection\Agent\Bin\AVGIDSAgent.exe [18/08/2011 01:33 7390560]
S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;c:\windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [18/03/2010 13:16 130384]
S2 gupdate1cb0bdd975ae192;Service Google Update (gupdate1cb0bdd975ae192);c:\program files\Google\Update\GoogleUpdate.exe [14/06/2010 18:21 133104]
S3 Com4QLBEx;Com4QLBEx;c:\program files\Hewlett-Packard\HP Quick Launch Buttons\Com4QLBEx.exe [07/10/2008 15:42 193840]
S3 gupdatem;Service Google Update (gupdatem);c:\program files\Google\Update\GoogleUpdate.exe [14/06/2010 18:21 133104]
S3 NPF;NetGroup Packet Filter Driver;c:\windows\system32\drivers\npf.sys [29/06/2007 02:01 42512]
S3 SCR3XX2K;SCR3xx USB SmartCardReader;c:\windows\system32\drivers\SCR3XX2K.sys [21/06/2007 04:40 56448]
S3 teamviewervpn;TeamViewer VPN Adapter;c:\windows\system32\drivers\teamviewervpn.sys [25/01/2008 11:12 25088]
S3 TrueSight;TrueSight;c:\documents and settings\dmi\Bureau\TrueSight.sys [27/09/2011 16:10 60800]
S3 WinRM;Windows Remote Management (WS-Management);c:\windows\system32\svchost.exe -k WINRM [13/04/2008 19:34 14336]
S3 WPFFontCache_v0400;Windows Presentation Foundation Font Cache 4.0.0.0;c:\windows\Microsoft.NET\Framework\v4.0.30319\WPF\WPFFontCache_v0400.exe [18/03/2010 13:16 753504]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
WINRM REG_MULTI_SZ WINRM
.
Contenu du dossier 'Tâches planifiées'
.
2011-07-22 c:\windows\Tasks\AppleSoftwareUpdate.job
- c:\program files\Apple Software Update\SoftwareUpdate.exe [2011-06-01 15:57]
.
2011-09-27 c:\windows\Tasks\Google Software Updater.job
- c:\program files\Google\Common\Google Updater\GoogleUpdaterService.exe [2009-07-23 17:26]
.
2011-09-27 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\program files\Google\Update\GoogleUpdate.exe [2010-06-14 16:21]
.
2011-09-27 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\program files\Google\Update\GoogleUpdate.exe [2010-06-14 16:21]
.
.
------- Examen supplémentaire -------
.
uStart Page = hxxp://www.01net.com/
mStart Page = hxxp://www.foozir.com/
uInternet Settings,ProxyOverride = <local>
uSearchURL,(Default) = hxxp://www.google.com/keyword/%s
IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~3\OFFICE11\EXCEL.EXE/3000
IE: Envoyer au périphérique &Bluetooth... - c:\program files\WIDCOMM\Bluetooth Software\btsendto_ie_ctx.htm
IE: Envoyer à Bluetooth - c:\program files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
Trusted Zone: chrnamur.be\chrvpn
Trusted Zone: fgov.be\*.minfin
Trusted Zone: localhost
Trusted Zone: winamax.fr\www
TCP: DhcpNameServer = 192.168.1.1
TCP: Interfaces\{0C17677C-5955-430B-969C-DD06005077E0}: NameServer = 216.146.35.35,216.146.36.36
TCP: Interfaces\{20D93359-B78E-45FE-8D0D-7B2198E2F30B}: NameServer = 216.146.35.35,216.146.36.36
TCP: Interfaces\{B947F0E2-0709-49E4-BD00-1240DDE8A598}: NameServer = 216.146.35.35,216.146.36.36
FF - ProfilePath - c:\documents and settings\dmi\Application Data\Mozilla\Firefox\Profiles\agx015nf.default\
FF - prefs.js: browser.startup.homepage - hxxp://localhost/speedcall/interfaces/interface.php
.
.
**************************************************************************
.
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2011-09-27 18:28
Windows 5.1.2600 Service Pack 3 NTFS
.
Recherche de processus cachés ...
.
Recherche d'éléments en démarrage automatique cachés ...
.
Recherche de fichiers cachés ...
.
Scan terminé avec succès
Fichiers cachés: 0
.
**************************************************************************
.
--------------------- DLLs chargées dans les processus actifs ---------------------
.
- - - - - - - > 'winlogon.exe'(1436)
c:\windows\system32\LMIinit.dll
.
- - - - - - - > 'explorer.exe'(2768)
c:\windows\system32\LMIRfsClientNP.dll
c:\windows\system32\eappprxy.dll
c:\windows\system32\WPDShServiceObj.dll
c:\windows\system32\btncopy.dll
c:\windows\system32\PortableDeviceTypes.dll
c:\windows\system32\PortableDeviceApi.dll
.
------------------------ Autres processus actifs ------------------------
.
c:\progra~1\AVG\AVG10\avgchsvx.exe
c:\progra~1\AVG\AVG10\avgrsx.exe
c:\program files\WIDCOMM\Bluetooth Software\bin\btwdins.exe
c:\windows\System32\SCardSvr.exe
c:\windows\system32\agrsmsvc.exe
c:\program files\Juniper Networks\Common Files\dsNcService.exe
c:\program files\Intel\Intel Matrix Storage Manager\IAANTMon.exe
c:\program files\Java\jre6\bin\jqs.exe
c:\program files\AVG\AVG10\Identity Protection\agent\bin\avgidsmonitor.exe
c:\program files\LogMeIn\x86\RaMaint.exe
c:\program files\LogMeIn\x86\LogMeIn.exe
c:\program files\AVG\AVG10\avgnsx.exe
c:\oracle\ora92\bin\omtsreco.exe
c:\program files\OpenSSH\usr\sbin\sshd.exe
c:\windows\system32\wscntfy.exe
.
**************************************************************************
.
Heure de fin: 2011-09-27 18:31:43 - La machine a redémarré
ComboFix-quarantined-files.txt 2011-09-27 16:31
ComboFix2.txt 2011-09-27 15:52
.
Avant-CF: 120 984 879 104 octets libres
Après-CF: 120 968 224 768 octets libres
.
- - End Of File - - FD82EF89916E9EF027BCA14C55A6855A
Messages postés
35445
Date d'inscription
jeudi 18 décembre 2008
Statut
Contributeur sécurité
Dernière intervention
5 mai 2017
4 783
Ok.

Normalement l'infection est partie, cependant, il se peut que tu doives réinstaller les logiciels qui ne fonctionnent plus !

▶ Télécharge MBAM et installe le selon l'emplacement par défaut
https://www.malwarebytes.com/mwb-download/
▶ Effectue la mise à jour et lance Malwarebytes' Anti-Malware

▶ ▶ Si tu n''arrive pas à le mettre à jour, télécharge ce fichier , ferme MBAM, et exécute le

▶ Clique dans l'onglet du haut "Recherche"
▶ Coche l'option "Exécuter un examen complet" puis sur le bouton "Rechercher"
▶ Choisis de scanner tous tes disques durs, puis clique sur 'Lancer l'examen"

A la fin de l'analyse, si MBAM n'a rien trouvé :

▶ Clique sur OK, le rapport s'ouvre spontanément

Si des menaces ont été détectées :

▶ Clique sur OK puis "Afficher les résultats"
▶ Choisis l'option "Supprimer la sélection"
▶ Si MBAM demande le redémarrage de Windows : Clique sur "Oui"
▶ Une fois le PC redémarré, le rapport se trouve dans l'onglet "Rapports/Logs"
▶ Sinon le rapport s'ouvre automatiquement après la suppression

Quelque soit le résultat, copie/colle le rapport dans le prochain message
Messages postés
42
Date d'inscription
mardi 27 septembre 2011
Statut
Membre
Dernière intervention
29 septembre 2011

Après pas mal de temps dû au scan, voici le rapport de MBAM :

Malwarebytes' Anti-Malware 1.51.2.1300
www.malwarebytes.org

Version de la base de données: 7809

Windows 5.1.2600 Service Pack 3
Internet Explorer 7.0.5730.13

27/09/2011 19:59:08
mbam-log-2011-09-27 (19-58-54).txt

Type d'examen: Examen complet (C:\|)
Elément(s) analysé(s): 311337
Temps écoulé: 1 heure(s), 13 minute(s), 1 seconde(s)

Processus mémoire infecté(s): 0
Module(s) mémoire infecté(s): 0
Clé(s) du Registre infectée(s): 1
Valeur(s) du Registre infectée(s): 0
Elément(s) de données du Registre infecté(s): 0
Dossier(s) infecté(s): 0
Fichier(s) infecté(s): 16

Processus mémoire infecté(s):
(Aucun élément nuisible détecté)

Module(s) mémoire infecté(s):
(Aucun élément nuisible détecté)

Clé(s) du Registre infectée(s):
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Titan Poker (PUP.Casino) -> No action taken.

Valeur(s) du Registre infectée(s):
(Aucun élément nuisible détecté)

Elément(s) de données du Registre infecté(s):
(Aucun élément nuisible détecté)

Dossier(s) infecté(s):
(Aucun élément nuisible détecté)

Fichier(s) infecté(s):
c:\documents and settings\dmi\local settings\application data\assembly\dl3\KEM54HX4.TTQ\XZT13H87.R7G\368f3cec\00d34a37_f353cb01\Utils.DLL (Adware.InstallPedia) -> No action taken.
c:\documents and settings\dmi\local settings\application data\assembly\dl3\KEM54HX4.TTQ\XZT13H87.R7G\e1d5f1b9\00a61936_f353cb01\networker.exe (Adware.InstallPedia) -> No action taken.
c:\Poker\titan poker\_titanpsetup_6995c0[1].exe (PUP.Casino) -> No action taken.
c:\program files\Cain\Abel.exe (HackTool.Cain) -> No action taken.
c:\program files\Cain\Cain.exe (PUP.Passwordtool.Cain) -> No action taken.
c:\Qoobox\quarantine\C\documents and settings\dmi\gob.exe.vir (Backdoor.Bot) -> No action taken.
c:\Qoobox\quarantine\C\program files\installpedia\lnetworker.exe.vir (Adware.InstallPedia) -> No action taken.
c:\Qoobox\quarantine\C\program files\installpedia\service.exe.vir (Adware.InstallPedia) -> No action taken.
c:\Qoobox\quarantine\C\program files\installpedia\utils.dll.vir (Adware.InstallPedia) -> No action taken.
c:\system volume information\_restore{71a8f647-2a41-41a1-8a12-1ed46db6d989}\RP427\A0101085.exe (Backdoor.Bot) -> No action taken.
c:\system volume information\_restore{71a8f647-2a41-41a1-8a12-1ed46db6d989}\RP427\A0102089.exe (Adware.InstallPedia) -> No action taken.
c:\system volume information\_restore{71a8f647-2a41-41a1-8a12-1ed46db6d989}\RP430\A0104449.exe (Backdoor.Bot) -> No action taken.
c:\system volume information\_restore{71a8f647-2a41-41a1-8a12-1ed46db6d989}\RP430\A0104453.exe (Adware.InstallPedia) -> No action taken.
c:\system volume information\_restore{71a8f647-2a41-41a1-8a12-1ed46db6d989}\RP430\A0104455.exe (Adware.InstallPedia) -> No action taken.
c:\system volume information\_restore{71a8f647-2a41-41a1-8a12-1ed46db6d989}\RP430\A0104456.dll (Adware.InstallPedia) -> No action taken.
c:\WINDOWS\system32\Utils.dll (Adware.InstallPedia) -> No action taken.
Messages postés
42
Date d'inscription
mardi 27 septembre 2011
Statut
Membre
Dernière intervention
29 septembre 2011

AVG, lui, pendant ce temps, m'a affiché deux menaces :

"c:\Documents and Settings\dmi\Local Settings\Application Data\assembly\dl3\KEM54HX4.TTQ\XZT13H87.R7G\e1d5f1b9\00a61936_f353cb01\networker.EXE";"Adware Generic4.BSEA";"Objet potentiellement dangereux"
"c:\System Volume Information\_restore{71A8F647-2A41-41A1-8A12-1ED46DB6D989}\RP427\A0102089.exe";"Adware Generic4.BSEA";"Objet potentiellement dangereux"
Messages postés
35445
Date d'inscription
jeudi 18 décembre 2008
Statut
Contributeur sécurité
Dernière intervention
5 mai 2017
4 783
No action taken.

As-tu bien Supprimé la sélection ?
Si non, il faut recommencer le scan !

~~

Télécharge AdwCleaner ( d'Xplode ) sur ton bureau.
Lance le, clique sur [Suppression] puis patiente le temps du scan.
Une fois le scan fini, un rapport s'ouvrira. Poste moi son contenu dans ta prochaine réponse.

Note : Le rapport est également sauvegardé sous C:\AdwCleaner[S1].txt
Messages postés
42
Date d'inscription
mardi 27 septembre 2011
Statut
Membre
Dernière intervention
29 septembre 2011

Raaaaa... J'ai la tête ailleurs... Je n'avais pas lu que tu désirais le rapport après suppression. Je vais donc supprimer puis t'envoyer le rapport.
Messages postés
35445
Date d'inscription
jeudi 18 décembre 2008
Statut
Contributeur sécurité
Dernière intervention
5 mai 2017
4 783
:-)
Messages postés
42
Date d'inscription
mardi 27 septembre 2011
Statut
Membre
Dernière intervention
29 septembre 2011

Voici donc le rapport, avant redémarrage de la machine. Je vais la redémarré comme voulu par MBAM puis effectuerai la manoeuvre avec AdwCleaner.

Malwarebytes' Anti-Malware 1.51.2.1300
www.malwarebytes.org

Version de la base de données: 7809

Windows 5.1.2600 Service Pack 3
Internet Explorer 7.0.5730.13

27/09/2011 20:20:30
mbam-log-2011-09-27 (20-20-30).txt

Type d'examen: Examen complet (C:\|)
Elément(s) analysé(s): 311337
Temps écoulé: 1 heure(s), 13 minute(s), 1 seconde(s)

Processus mémoire infecté(s): 0
Module(s) mémoire infecté(s): 0
Clé(s) du Registre infectée(s): 1
Valeur(s) du Registre infectée(s): 0
Elément(s) de données du Registre infecté(s): 0
Dossier(s) infecté(s): 0
Fichier(s) infecté(s): 16

Processus mémoire infecté(s):
(Aucun élément nuisible détecté)

Module(s) mémoire infecté(s):
(Aucun élément nuisible détecté)

Clé(s) du Registre infectée(s):
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Titan Poker (PUP.Casino) -> Not selected for removal.

Valeur(s) du Registre infectée(s):
(Aucun élément nuisible détecté)

Elément(s) de données du Registre infecté(s):
(Aucun élément nuisible détecté)

Dossier(s) infecté(s):
(Aucun élément nuisible détecté)

Fichier(s) infecté(s):
c:\documents and settings\dmi\local settings\application data\assembly\dl3\KEM54HX4.TTQ\XZT13H87.R7G\368f3cec\00d34a37_f353cb01\Utils.DLL (Adware.InstallPedia) -> Quarantined and deleted successfully.
c:\documents and settings\dmi\local settings\application data\assembly\dl3\KEM54HX4.TTQ\XZT13H87.R7G\e1d5f1b9\00a61936_f353cb01\networker.exe (Adware.InstallPedia) -> Quarantined and deleted successfully.
c:\Poker\titan poker\_titanpsetup_6995c0[1].exe (PUP.Casino) -> Not selected for removal.
c:\program files\Cain\Abel.exe (HackTool.Cain) -> Quarantined and deleted successfully.
c:\program files\Cain\Cain.exe (PUP.Passwordtool.Cain) -> Not selected for removal.
c:\Qoobox\quarantine\C\documents and settings\dmi\gob.exe.vir (Backdoor.Bot) -> Quarantined and deleted successfully.
c:\Qoobox\quarantine\C\program files\installpedia\lnetworker.exe.vir (Adware.InstallPedia) -> Quarantined and deleted successfully.
c:\Qoobox\quarantine\C\program files\installpedia\service.exe.vir (Adware.InstallPedia) -> Quarantined and deleted successfully.
c:\Qoobox\quarantine\C\program files\installpedia\utils.dll.vir (Adware.InstallPedia) -> Quarantined and deleted successfully.
c:\system volume information\_restore{71a8f647-2a41-41a1-8a12-1ed46db6d989}\RP427\A0101085.exe (Backdoor.Bot) -> Quarantined and deleted successfully.
c:\system volume information\_restore{71a8f647-2a41-41a1-8a12-1ed46db6d989}\RP427\A0102089.exe (Adware.InstallPedia) -> Quarantined and deleted successfully.
c:\system volume information\_restore{71a8f647-2a41-41a1-8a12-1ed46db6d989}\RP430\A0104449.exe (Backdoor.Bot) -> Quarantined and deleted successfully.
c:\system volume information\_restore{71a8f647-2a41-41a1-8a12-1ed46db6d989}\RP430\A0104453.exe (Adware.InstallPedia) -> Quarantined and deleted successfully.
c:\system volume information\_restore{71a8f647-2a41-41a1-8a12-1ed46db6d989}\RP430\A0104455.exe (Adware.InstallPedia) -> Quarantined and deleted successfully.
c:\system volume information\_restore{71a8f647-2a41-41a1-8a12-1ed46db6d989}\RP430\A0104456.dll (Adware.InstallPedia) -> Quarantined and deleted successfully.
c:\WINDOWS\system32\Utils.dll (Adware.InstallPedia) -> Quarantined and deleted successfully.
Messages postés
35445
Date d'inscription
jeudi 18 décembre 2008
Statut
Contributeur sécurité
Dernière intervention
5 mai 2017
4 783
Ah c'est tout de suite mieux :)
Messages postés
42
Date d'inscription
mardi 27 septembre 2011
Statut
Membre
Dernière intervention
29 septembre 2011

Voici donc le rapport de AdwCleaner :

# AdwCleaner v1.308 - Rapport créé le 27/09/2011 à 20:30:27
# Mis à jour le 25/09/11 à 17h par Xplode
# Système d'exploitation : Microsoft Windows XP Service Pack 3 (32 bits)
# Nom d'utilisateur : dmi - CHR (Administrateur)
# Exécuté depuis : C:\Documents and Settings\dmi\Bureau\adwcleaner.exe
# Option [Suppression]


***** [KillNav] *****

Aucun navigateur n'était en cours d'exécution.

***** [Processus] *****


***** [Services] *****


***** [Fichiers / Dossiers] *****

Dossier Supprimé : C:\Documents and Settings\dmi\Application Data\Search Settings

***** [Registre] *****

Clé Supprimée : HKCU\Software\Search Settings
Clé Supprimée : HKLM\SOFTWARE\Application Updater
Clé Supprimée : HKLM\SOFTWARE\InstallPedia
Clé Supprimée : HKLM\SOFTWARE\Search Settings
Clé Supprimée : HKLM\SOFTWARE\Classes\pdfforge.DllInfo
Clé Supprimée : HKLM\SOFTWARE\Classes\pdfforge.PDF.PDF
Clé Supprimée : HKLM\SOFTWARE\Classes\pdfforge.PDF.PDFEncryptor
Clé Supprimée : HKLM\SOFTWARE\Classes\pdfforge.PDF.PDFLine
Clé Supprimée : HKLM\SOFTWARE\Classes\pdfforge.PDF.PDFText
Clé Supprimée : HKLM\SOFTWARE\Classes\pdfforge.Tools

***** [Navigateurs] *****

-\\ Internet Explorer v7.0.5730.13

[OK] Le registre ne contient aucune entrée illégitime.

-\\ Mozilla Firefox v6.0.2 (fr)

Profil : agx015nf.default
Fichier : C:\Documents and Settings\dmi\Application Data\Mozilla\Firefox\Profiles\agx015nf.default\prefs.js

[OK] Le fichier ne contient aucune entrée illégitime.

*************************

AdwCleaner[S1].txt - [1534 octets] - [27/09/2011 20:30:27]

*************************

Dossier Temporaire : 1 dossier(s) et 2 fichier(s) supprimé(s)

########## EOF - C:\AdwCleaner[S1].txt - [1756 octets] ##########
Messages postés
35445
Date d'inscription
jeudi 18 décembre 2008
Statut
Contributeur sécurité
Dernière intervention
5 mai 2017
4 783
Bien :)

On enchaîne :

Télécharge AD-Remover sur ton Bureau : (TeamXScript)

http://www.teamxscript.org/adremoverTelechargement.html ( Lien officiel )
OU
https://www.androidworld.fr/ ( Miroir )

/!\ Ferme toutes applications en cours /!\

▶ Double-clique sur l'icône Ad-remover située sur ton Bureau.
▶ Sur la page, clique sur le bouton « Scanner »
▶ Confirme le lancement du scan
▶ Laisse travailler l'outil.
▶ Quand il a fini, un rapport s'ouvrira : ferme le.

♦ Pour me transmettre le rapport

clique sur ce lien : http://www.cijoint.fr/

▶ Clique sur Parcourir et cherche le fichier C:\Ad-Report-SCAN[1].txt

▶ Clique sur Ouvrir.

▶ Clique sur "Cliquez ici pour déposer le fichier".

Un lien de cette forme :

http://www.cijoint.fr/cjlink.php?file=cjge368/cijSKAP5fU.txt

est ajouté dans la page.

▶ Copie ce lien dans ta réponse.