Virus win32 sirefef.0

lucie -  
juju666 Messages postés 35446 Date d'inscription   Statut Contributeur sécurité Dernière intervention   -
Bonjour,

Même virus que pour beaucoup apparemment,
mon problème est que je n'arrive pas à télécharger les petits logiciels pour faire des rapports et les poster, les liens qui s'ouvrent sont des pubs ou même quand j'arrive sur les sites, impossible de télécharger..
merci de m'aider
lucie

14 réponses

  1. juju666 Messages postés 35446 Date d'inscription   Statut Contributeur sécurité Dernière intervention   4 796
     
    Salut,

    ▶ Fais un clic droit sur le lien ci dessous, choisi "Enregistrer la cible du lien sous", comme destination : ton Bureau, change son nom (ton_pseudo.exe par exemple) :

    http://download.bleepingcomputer.com/sUBs/ComboFix.exe

    ▶ Double-clique sur ComboFix.exe
    Un "pop-up" va apparaître qui dit que ComboFix est utilisé à vos risques et avec aucune garantie... Clique sur oui pour accepter

    ▶ ▶ Ne touche à rien (souris, clavier) tant que le scan n'est pas terminé, car tu risques de planter ton PC

    ▶ En fin de scan, il est possible que ComboFix ait besoin de redémarrer le PC pour finaliser la désinfection, laisse-le faire.
    ▶ Une fois le scan achevé, un rapport va s''afficher : Poste son contenu

    Notes:
    -> Le rapport se trouve également là : C:\ComboFix.txt
    -> tutoriel combofix
    .::. Contributeur Sécurité .::.
    0
  2. lucie
     
    Merci de ton aide, le scan n'est toujours pas fini mais je poste dès que c'est fini
    0
  3. juju666 Messages postés 35446 Date d'inscription   Statut Contributeur sécurité Dernière intervention   4 796
     
    D'acc :>
    0
  4. lucie
     
    ComboFix 11-11-04.04 - Guillaume 05/11/2011 0:58.1.2 - x86
    Microsoft Windows 7 Édition Familiale Premium 6.1.7600.0.1252.33.1036.18.3037.2093 [GMT 1:00]
    Lancé depuis: c:\users\Guillaume\Desktop\ComboFix.exe
    AV: AntiVir Desktop *Disabled/Updated* {090F9C29-64CE-6C6F-379C-5901B49A85B7}
    SP: AntiVir Desktop *Disabled/Updated* {B26E7DCD-42F4-63E1-0D2C-6273CF1DCF0A}
    SP: Windows Defender *Enabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
    .
    .
    (((((((((((((((((((((((((((((((((((( Autres suppressions ))))))))))))))))))))))))))))))))))))))))))))))))
    .
    .
    c:\programdata\FullRemove.exe
    c:\users\Guillaume\AppData\Local\3a3401aa
    c:\users\Guillaume\AppData\Local\3a3401aa\@
    c:\users\Guillaume\AppData\Local\3a3401aa\U\80000000.@
    c:\users\Guillaume\AppData\Local\3a3401aa\U\800000cb.@
    c:\users\Guillaume\AppData\Local\3a3401aa\X
    c:\users\Guillaume\AppData\Roaming\.#
    c:\users\Guillaume\Favorites\Translator.url
    c:\windows\$NtUninstallKB50273$\1884346020
    c:\windows\$NtUninstallKB50273$\976486826\@
    c:\windows\$NtUninstallKB50273$\976486826\L\xadqgnnk
    c:\windows\$NtUninstallKB50273$\976486826\loader.tlb
    c:\windows\$NtUninstallKB50273$\976486826\U\@00000001
    c:\windows\$NtUninstallKB50273$\976486826\U\@000000c0
    c:\windows\$NtUninstallKB50273$\976486826\U\@000000cb
    c:\windows\$NtUninstallKB50273$\976486826\U\@000000cf
    c:\windows\$NtUninstallKB50273$\976486826\U\@80000000
    c:\windows\$NtUninstallKB50273$\976486826\U\@800000c0
    c:\windows\$NtUninstallKB50273$\976486826\U\@800000cb
    c:\windows\$NtUninstallKB50273$\976486826\U\@800000cf
    c:\windows\system32\
    c:\windows\system32\c_21904.nls
    c:\windows\system32\Nagasoft
    c:\windows\system32\Nagasoft\Codecs\asyncflt.ax
    c:\windows\system32\Nagasoft\Codecs\atrc.dll
    c:\windows\system32\Nagasoft\Codecs\cook.dll
    c:\windows\system32\Nagasoft\Codecs\drvc.dll
    c:\windows\system32\Nagasoft\Codecs\raac.dll
    c:\windows\system32\Nagasoft\Codecs\RealMediaSplitter.ax
    c:\windows\system32\Nagasoft\Codecs\WMFDemux.dll
    c:\windows\system32\Nagasoft\GifShower.dll
    c:\windows\system32\Nagasoft\vjocx.dll
    c:\windows\system32\odbcad32.exe
    c:\windows\$NtUninstallKB50273$ . . . . impossible à supprimer
    .
    Une copie infectée de c:\program files\LSI SoftModem\agrsmsvc.exe a été trouvée et désinfectée
    Copie restaurée à partir de - c:\combofix\HarddiskVolumeShadowCopy9_!Program Files!LSI SoftModem!agrsmsvc.exe
    .
    Une copie infectée de c:\windows\system32\atiesrxx.exe a été trouvée et désinfectée
    Copie restaurée à partir de - c:\combofix\HarddiskVolumeShadowCopy9_!Windows!System32!atiesrxx.exe
    .
    Une copie infectée de c:\program files\Avira\AntiVir Desktop\sched.exe a été trouvée et désinfectée
    Copie restaurée à partir de - c:\combofix\HarddiskVolumeShadowCopy9_!Program Files!Avira!AntiVir Desktop!sched.exe
    .
    Une copie infectée de c:\program files\Common Files\AOL\ACS\AOLAcsd.exe a été trouvée et désinfectée
    Copie restaurée à partir de - c:\combofix\HarddiskVolumeShadowCopy9_!Program Files!Common Files!AOL!acs!AOLAcsd.exe
    .
    Une copie infectée de c:\program files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe a été trouvée et désinfectée
    Copie restaurée à partir de - c:\combofix\HarddiskVolumeShadowCopy9_!Program Files!Common Files!Apple!Mobile Device Support!AppleMobileDeviceService.exe
    .
    Une copie infectée de c:\program files\Bonjour\mDNSResponder.exe a été trouvée et désinfectée
    Copie restaurée à partir de - c:\combofix\HarddiskVolumeShadowCopy9_!Program Files!Bonjour!mDNSResponder.exe
    .
    Une copie infectée de c:\program files\iPod\bin\iPodService.exe a été trouvée et désinfectée
    Copie restaurée à partir de - c:\combofix\HarddiskVolumeShadowCopy9_!Program Files!iPod!bin!iPodService.exe
    .
    Une copie infectée de c:\windows\SYSTEM32\Rezip.exe a été trouvée et désinfectée
    Copie restaurée à partir de - c:\combofix\HarddiskVolumeShadowCopy9_!Windows!System32!Rezip.exe
    .
    Une copie infectée de c:\program files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE a été trouvée et désinfectée
    Copie restaurée à partir de - c:\combofix\HarddiskVolumeShadowCopy9_!Program Files!Common Files!microsoft shared!Windows Live!WLIDSVC.EXE
    .
    Une copie infectée de c:\windows\SYSTEM32\Rezip.exe a été trouvée et désinfectée
    Copie restaurée à partir de - c:\combofix\HarddiskVolumeShadowCopy9_!Windows!System32!Rezip.exe
    .
    ((((((((((((((((((((((((((((((((((((((( Pilotes/Services )))))))))))))))))))))))))))))))))))))))))))))))))
    .
    .
    -------\Service_vvdsvc
    -------\Service_vvdsvc
    .
    .
    ((((((((((((((((((((((((((((( Fichiers créés du 2011-10-05 au 2011-11-05 ))))))))))))))))))))))))))))))))))))
    .
    .
    2011-11-05 00:19 . 2011-11-05 00:23 -------- d-----w- c:\users\Guillaume\AppData\Local\temp
    2011-11-05 00:19 . 2011-11-05 00:19 -------- d-----w- c:\users\postgres\AppData\Local\temp
    2011-11-05 00:19 . 2011-11-05 00:19 -------- d-----w- c:\users\Default\AppData\Local\temp
    2011-11-05 00:19 . 2009-09-02 07:55 172032 ----a-w- c:\windows\system32\atiesrxx.exe
    2011-11-04 23:56 . 2011-11-05 00:22 56200 ----a-w- c:\programdata\Microsoft\Windows Defender\Definition Updates\{C1B1DC20-6F7E-40EA-8611-AB6534DE3247}\offreg.dll
    2011-11-04 23:54 . 2009-07-13 23:11 80896 ----a-w- c:\windows\system32\drivers\i8042prt.sys
    2011-11-04 19:38 . 2011-11-04 23:03 -------- d-sh--w- c:\windows\system32\%APPDATA%
    2011-11-04 11:23 . 2011-11-04 23:03 -------- d-----w- c:\users\Guillaume\AppData\Roaming\Media Player
    2011-11-04 11:22 . 2011-11-04 11:22 -------- d-----w- c:\program files\Orange
    2011-11-04 07:21 . 2011-10-07 03:48 6668624 ----a-w- c:\programdata\Microsoft\Windows Defender\Definition Updates\{C1B1DC20-6F7E-40EA-8611-AB6534DE3247}\mpengine.dll
    2011-10-26 19:58 . 2011-11-04 23:03 -------- d-----w- c:\program files\AOL Desktop 9.6
    2011-10-26 19:58 . 2011-10-26 19:59 -------- d-----w- c:\program files\Common Files\AOL
    2011-10-26 19:58 . 2011-10-26 19:59 -------- d-----w- c:\program files\Common Files\aolshare
    2011-10-13 10:59 . 2011-10-13 11:00 -------- d-----w- c:\program files\proXPN
    2011-10-12 16:11 . 2011-10-12 16:11 -------- d-----w- c:\users\Guillaume\AppData\Local\Ilivid Player
    2011-10-12 16:11 . 2011-10-12 16:13 -------- d-----w- c:\program files\iLivid
    2011-10-12 16:10 . 2011-10-12 16:10 -------- d-----w- c:\users\Guillaume\AppData\Local\PackageAware
    2011-10-12 13:12 . 2011-08-17 04:26 465408 ----a-w- c:\windows\system32\psisdecd.dll
    2011-10-12 13:12 . 2011-08-17 04:22 75776 ----a-w- c:\windows\system32\psisrndr.ax
    2011-10-12 13:12 . 2011-08-17 04:22 72704 ----a-w- c:\windows\system32\Mpeg2Data.ax
    2011-10-12 13:12 . 2011-08-17 04:22 59904 ----a-w- c:\windows\system32\MSDvbNP.ax
    2011-10-12 13:12 . 2011-08-17 04:22 204288 ----a-w- c:\windows\system32\MSNP.ax
    2011-10-12 13:12 . 2011-08-27 04:43 571904 ----a-w- c:\windows\system32\oleaut32.dll
    2011-10-12 13:12 . 2011-08-27 04:43 233472 ----a-w- c:\windows\system32\oleacc.dll
    2011-10-12 13:12 . 2011-09-06 02:38 2332672 ----a-w- c:\windows\system32\win32k.sys
    2011-10-10 19:41 . 2011-10-10 19:41 -------- d-----w- c:\users\Guillaume\AppData\Roaming\Move Networks
    .
    .
    .
    (((((((((((((((((((((((((((((((((( Compte-rendu de Find3M ))))))))))))))))))))))))))))))))))))))))))))))))
    .
    2011-09-10 17:26 . 2011-09-10 17:41 58696 ----a-w- c:\windows\system32\AOLParconLink.exe
    2011-09-09 10:51 . 2011-09-09 10:51 404640 ----a-w- c:\windows\system32\FlashPlayerCPLApp.cpl
    .
    .
    ((((((((((((((((((((((((((((((((( Points de chargement Reg ))))))))))))))))))))))))))))))))))))))))))))))))
    .
    .
    *Note* les éléments vides & les éléments initiaux légitimes ne sont pas listés
    REGEDIT4
    .
    [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
    "AOL Fast Start"="c:\program files\AOL Desktop 9.6\AOL.EXE" [2011-04-25 42320]
    "OrangePlayer"="c:\program files\Orange\Media Player\Media Player.exe" [2009-09-05 319488]
    .
    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
    "StartCCC"="c:\program files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" [2009-09-01 98304]
    "RtHDVCpl"="c:\program files\Realtek\Audio\HDA\RtHDVCpl.exe" [2009-08-19 7711264]
    "SynTPEnh"="c:\program files\Synaptics\SynTP\SynTPEnh.exe" [2009-07-14 1541416]
    "UCam_Menu"="c:\program files\CyberLink\YouCam\MUITransfer\MUIStartMenu.exe" [2009-02-25 218408]
    "avgnt"="c:\program files\Avira\AntiVir Desktop\avgnt.exe" [2009-03-02 209153]
    "QuickTime Task"="c:\program files\QuickTime\QTTask.exe" [2010-03-17 421888]
    "iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2010-04-24 142120]
    "Lingvo Launcher"="c:\program files\ABBYY Lingvo 12\Lvagent.exe" [2006-12-14 258048]
    "Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2011-06-08 37296]
    "Adobe ARM"="c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2011-03-30 937920]
    "SunJavaUpdateSched"="c:\program files\Common Files\Java\Java Update\jusched.exe" [2011-04-08 254696]
    "HostManager"="c:\program files\Common Files\AOL\1319659121\ee\AOLSoftware.exe" [2010-03-08 41800]
    .
    [HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
    "OrangePlayer"="c:\program files\Orange\Media Player\Media Player.exe" [2009-09-05 319488]
    .
    c:\users\Guillaume\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\
    EvernoteClipper.lnk - c:\program files\Evernote\Evernote\EvernoteClipper.exe [2011-4-12 973824]
    Kuma_Tray.lnk - c:\program files\Kuma Games\kgsystray\Kuma_tray.exe [2011-5-12 33472]
    .
    [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
    "ConsentPromptBehaviorAdmin"= 5 (0x5)
    "ConsentPromptBehaviorUser"= 3 (0x3)
    "EnableUIADesktopToggle"= 0 (0x0)
    .
    [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
    "aux2"=wdmaud.drv
    .
    [HKEY_LOCAL_MACHINE\system\currentcontrolset\control\lsa]
    Security Packages REG_MULTI_SZ kerberos msv1_0 schannel wdigest tspkg pku2u livessp
    .
    R2 AntiVirSchedulerService;Avira AntiVir Planificateur;c:\program files\Avira\AntiVir Desktop\sched.exe [x]
    R2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;c:\windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-03-18 130384]
    R2 gupdate;Service Google Update (gupdate);c:\program files\Google\Update\GoogleUpdate.exe [2011-04-28 136176]
    R3 gupdatem;Service Google Update (gupdatem);c:\program files\Google\Update\GoogleUpdate.exe [2011-04-28 136176]
    R3 RTL8167;Realtek 8167 NT Driver;c:\windows\system32\DRIVERS\Rt86win7.sys [2009-07-13 139776]
    R3 WatAdminSvc;Service Windows Activation Technologies;c:\windows\system32\Wat\WatAdminSvc.exe [2010-05-19 1343400]
    S1 SABI;SAMSUNG Kernel Driver For Windows 7;c:\windows\system32\Drivers\SABI.sys [2009-05-28 10752]
    S1 vwififlt;Virtual WiFi Filter Driver;c:\windows\system32\DRIVERS\vwififlt.sys [2009-07-13 48128]
    S2 Akamai;Akamai NetSession Interface;c:\windows\System32\svchost.exe [2009-07-14 20992]
    S2 AMD External Events Utility;AMD External Events Utility;c:\windows\system32\atiesrxx.exe [2009-09-02 172032]
    S2 pgsql-8.3;PostgreSQL Database Server 8.3;c:\program files\PostgreSQL\8.3\bin\pg_ctl.exe [2008-09-19 65536]
    S2 Rezip;Rezip;c:\windows\SYSTEM32\Rezip.exe [2009-03-05 311296]
    S2 yksvc;Marvell Yukon Service;c:\windows\System32\svchost.exe [2009-07-14 20992]
    S3 VMC326;Vimicro Camera Service VMC326;c:\windows\system32\Drivers\VMC326.sys [2009-08-10 237696]
    S3 yukonw7;NDIS6.2 Miniport Driver for Marvell Yukon Ethernet Controller;c:\windows\system32\DRIVERS\yk62x86.sys [2009-06-15 313856]
    .
    .
    [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
    yksvcs REG_MULTI_SZ yksvc
    vvdsvc REG_MULTI_SZ vvdsvc
    Akamai REG_MULTI_SZ Akamai
    .
    Contenu du dossier 'Tâches planifiées'
    .
    2011-11-05 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
    - c:\program files\Google\Update\GoogleUpdate.exe [2011-04-28 10:09]
    .
    2011-11-05 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
    - c:\program files\Google\Update\GoogleUpdate.exe [2011-04-28 10:09]
    .
    .
    ------- Examen supplémentaire -------
    .
    uStart Page = hxxp://www.google.com/ig/redirectdomain?brand=smsn&bmod=smsn
    uInternet Settings,ProxyServer = 216.49.160.27:80
    uInternet Settings,ProxyOverride = local
    IE: Add to Evernote 4.0 - c:\program files\Evernote\Evernote\EvernoteIE.dll/204
    IE: E&xporter vers Microsoft Excel - c:\progra~1\MICROS~2\Office12\EXCEL.EXE/3000
    IE: Google Sidewiki... - c:\program files\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_en_D183CA64F05FDD98.dll/cmsidewiki.html
    IE: Translate with ABBYY &Lingvo... - c:\program files\ABBYY Lingvo 12\Lingvo.exe/3000
    IE: {{A95fe080-8f5d-11d2-a20b-00aa003c157a} - res://c:\program files\Evernote\Evernote\EvernoteIE.dll/204
    TCP: DhcpNameServer = 192.168.1.1 192.168.1.1
    FF - ProfilePath - c:\users\Guillaume\AppData\Roaming\Mozilla\Firefox\Profiles\xtme9jwa.default\
    FF - prefs.js: browser.startup.homepage - hxxp://www.google.com/ig/redirectdomain?brand=smsn&bmod=smsn
    FF - prefs.js: network.proxy.type - 0
    FF - Ext: Default: {972ce4c6-7e08-4474-a285-3208198ce6fd} - c:\program files\Mozilla Firefox\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd}
    FF - Ext: Java Console: {CAFEEFAC-0016-0000-0023-ABCDEFFEDCBA} - c:\program files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0023-ABCDEFFEDCBA}
    FF - Ext: Java Console: {CAFEEFAC-0016-0000-0024-ABCDEFFEDCBA} - c:\program files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0024-ABCDEFFEDCBA}
    FF - Ext: Java Console: {CAFEEFAC-0016-0000-0026-ABCDEFFEDCBA} - c:\program files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0026-ABCDEFFEDCBA}
    FF - Ext: Google Toolbar for Firefox: {3112ca9c-de6d-4884-a869-9855de68056c} - c:\programdata\Google\Toolbar for Firefox\{3112ca9c-de6d-4884-a869-9855de68056c}
    .
    - - - - ORPHELINS SUPPRIMES - - - -
    .
    Toolbar-Locked - (no file)
    HKLM-Run-POEngine - (no file)
    SafeBoot-mcmscsvc
    SafeBoot-MCODS
    AddRemove-LSI Soft Modem - c:\windows\agrsmdel
    .
    .
    .
    --------------------- CLES DE REGISTRE BLOQUEES ---------------------
    .
    [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0000\AllUserSettings]
    @Denied: (A) (Users)
    @Denied: (A) (Everyone)
    @Allowed: (B 1 2 3 4 5) (S-1-5-20)
    "BlindDial"=dword:00000000
    "MSCurrentCountry"=dword:000000b5
    .
    [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\PCW\Security]
    @Denied: (Full) (Everyone)
    .
    --------------------- DLLs chargées dans les processus actifs ---------------------
    .
    - - - - - - - > 'Explorer.exe'(1904)
    c:\program files\ABBYY Lingvo 12\LvHook.dll
    .
    ------------------------ Autres processus actifs ------------------------
    .
    c:\windows\system32\atieclxx.exe
    c:\program files\LSI SoftModem\agrsmsvc.exe
    c:\program files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
    c:\program files\Bonjour\mDNSResponder.exe
    c:\windows\system32\taskhost.exe
    c:\program files\Samsung\Samsung Recovery Solution 4\WCScheduler.exe
    c:\program files\Samsung\Samsung Update Plus\SUPBackground.exe
    c:\program files\Samsung\Samsung Support Center\SSCKbdHk.exe
    c:\program files\PostgreSQL\8.3\bin\postgres.exe
    c:\windows\system32\conhost.exe
    c:\program files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE
    c:\program files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe
    c:\program files\PostgreSQL\8.3\bin\postgres.exe
    c:\program files\PostgreSQL\8.3\bin\postgres.exe
    c:\program files\PostgreSQL\8.3\bin\postgres.exe
    c:\program files\PostgreSQL\8.3\bin\postgres.exe
    c:\program files\PostgreSQL\8.3\bin\postgres.exe
    c:\windows\servicing\TrustedInstaller.exe
    c:\windows\system32\conhost.exe
    c:\program files\ATI Technologies\ATI.ACE\Core-Static\MOM.exe
    c:\program files\Synaptics\SynTP\SynTPHelper.exe
    c:\program files\Windows Media Player\wmpnetwk.exe
    c:\program files\iPod\bin\iPodService.exe
    c:\windows\system32\DllHost.exe
    c:\windows\system32\sppsvc.exe
    c:\program files\Windows Media Player\wmpnscfg.exe
    c:\program files\Windows Media Player\wmpnscfg.exe
    c:\program files\Windows Media Player\wmpnscfg.exe
    c:\program files\Windows Media Player\wmpnscfg.exe
    .
    **************************************************************************
    .
    Heure de fin: 2011-11-05 01:29:46 - La machine a redémarré
    ComboFix-quarantined-files.txt 2011-11-05 00:29
    .
    Avant-CF: 53 596 119 040 octets libres
    Après-CF: 54 896 844 800 octets libres
    .
    - - End Of File - - BE5A5F8C12C34AAEBB84A8BFF90A8161
    0
  5. Vous n’avez pas trouvé la réponse que vous recherchez ?

    Posez votre question
  6. juju666 Messages postés 35446 Date d'inscription   Statut Contributeur sécurité Dernière intervention   4 796
     
    Salut :>

    Relance combo voir ?
    0
  7. lucie
     
    Bonjour,
    Voila le nouveau compte rendu :
    merci beaucoup en tt cas

    ComboFix 11-11-04.04 - 05/11/2011 14:13:34.3.2 - x86
    Microsoft Windows 7 Édition Familiale Premium 6.1.7600.0.1252.33.1036.18.3037.1862 [GMT 1:00]
    Lancé depuis: c:\users\Guillaume\Desktop\ComboFix.exe
    AV: AntiVir Desktop *Disabled/Updated* {090F9C29-64CE-6C6F-379C-5901B49A85B7}
    SP: AntiVir Desktop *Disabled/Updated* {B26E7DCD-42F4-63E1-0D2C-6273CF1DCF0A}
    SP: Windows Defender *Enabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
    .
    .
    ((((((((((((((((((((((((((((( Fichiers créés du 2011-10-05 au 2011-11-05 ))))))))))))))))))))))))))))))))))))
    .
    .
    2011-11-05 13:25 . 2011-11-05 13:25 -------- d-----w- c:\users\postgres\AppData\Local\temp
    2011-11-05 13:25 . 2011-11-05 13:25 -------- d-----w- c:\users\Default\AppData\Local\temp
    2011-11-05 09:56 . 2011-11-05 09:56 -------- d-----w- c:\program files\Common Files\Java
    2011-11-05 09:50 . 2011-11-05 09:50 56200 ----a-w- c:\programdata\Microsoft\Windows Defender\Definition Updates\{C1B1DC20-6F7E-40EA-8611-AB6534DE3247}\offreg.dll
    2011-11-05 00:19 . 2011-11-05 13:25 -------- d-----w- c:\users\Guillaume\AppData\Local\temp
    2011-11-05 00:19 . 2009-09-02 07:55 172032 ----a-w- c:\windows\system32\atiesrxx.exe
    2011-11-04 23:54 . 2009-07-13 23:11 80896 ----a-w- c:\windows\system32\drivers\i8042prt.sys
    2011-11-04 19:38 . 2011-11-04 23:03 -------- d-sh--w- c:\windows\system32\%APPDATA%
    2011-11-04 11:23 . 2011-11-04 23:03 -------- d-----w- c:\users\Guillaume\AppData\Roaming\Media Player
    2011-11-04 11:22 . 2011-11-04 11:22 -------- d-----w- c:\program files\Orange
    2011-11-04 07:21 . 2011-10-07 03:48 6668624 ----a-w- c:\programdata\Microsoft\Windows Defender\Definition Updates\{C1B1DC20-6F7E-40EA-8611-AB6534DE3247}\mpengine.dll
    2011-10-26 19:58 . 2011-11-04 23:03 -------- d-----w- c:\program files\AOL Desktop 9.6
    2011-10-26 19:58 . 2011-10-26 19:59 -------- d-----w- c:\program files\Common Files\AOL
    2011-10-26 19:58 . 2011-10-26 19:59 -------- d-----w- c:\program files\Common Files\aolshare
    2011-10-13 10:59 . 2011-10-13 11:00 -------- d-----w- c:\program files\proXPN
    2011-10-12 16:11 . 2011-10-12 16:11 -------- d-----w- c:\users\Guillaume\AppData\Local\Ilivid Player
    2011-10-12 16:11 . 2011-10-12 16:13 -------- d-----w- c:\program files\iLivid
    2011-10-12 16:10 . 2011-10-12 16:10 -------- d-----w- c:\users\Guillaume\AppData\Local\PackageAware
    2011-10-12 13:12 . 2011-08-17 04:26 465408 ----a-w- c:\windows\system32\psisdecd.dll
    2011-10-12 13:12 . 2011-08-17 04:22 75776 ----a-w- c:\windows\system32\psisrndr.ax
    2011-10-12 13:12 . 2011-08-17 04:22 72704 ----a-w- c:\windows\system32\Mpeg2Data.ax
    2011-10-12 13:12 . 2011-08-17 04:22 59904 ----a-w- c:\windows\system32\MSDvbNP.ax
    2011-10-12 13:12 . 2011-08-17 04:22 204288 ----a-w- c:\windows\system32\MSNP.ax
    2011-10-12 13:12 . 2011-08-27 04:43 571904 ----a-w- c:\windows\system32\oleaut32.dll
    2011-10-12 13:12 . 2011-08-27 04:43 233472 ----a-w- c:\windows\system32\oleacc.dll
    2011-10-12 13:12 . 2011-09-06 02:38 2332672 ----a-w- c:\windows\system32\win32k.sys
    2011-10-10 19:41 . 2011-10-10 19:41 -------- d-----w- c:\users\Guillaume\AppData\Roaming\Move Networks
    .
    .
    .
    (((((((((((((((((((((((((((((((((( Compte-rendu de Find3M ))))))))))))))))))))))))))))))))))))))))))))))))
    .
    2011-10-03 04:06 . 2011-02-04 21:54 472808 ----a-w- c:\windows\system32\deployJava1.dll
    2011-09-10 17:26 . 2011-09-10 17:41 58696 ----a-w- c:\windows\system32\AOLParconLink.exe
    2011-09-09 10:51 . 2011-09-09 10:51 404640 ----a-w- c:\windows\system32\FlashPlayerCPLApp.cpl
    .
    .
    ((((((((((((((((((((((((((((((((( Points de chargement Reg ))))))))))))))))))))))))))))))))))))))))))))))))
    .
    .
    *Note* les éléments vides & les éléments initiaux légitimes ne sont pas listés
    REGEDIT4
    .
    [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
    "AOL Fast Start"="c:\program files\AOL Desktop 9.6\AOL.EXE" [2011-04-25 42320]
    "OrangePlayer"="c:\program files\Orange\Media Player\Media Player.exe" [2009-09-05 319488]
    .
    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
    "StartCCC"="c:\program files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" [2009-09-01 98304]
    "RtHDVCpl"="c:\program files\Realtek\Audio\HDA\RtHDVCpl.exe" [2009-08-19 7711264]
    "SynTPEnh"="c:\program files\Synaptics\SynTP\SynTPEnh.exe" [2009-07-14 1541416]
    "UCam_Menu"="c:\program files\CyberLink\YouCam\MUITransfer\MUIStartMenu.exe" [2009-02-25 218408]
    "avgnt"="c:\program files\Avira\AntiVir Desktop\avgnt.exe" [2009-03-02 209153]
    "QuickTime Task"="c:\program files\QuickTime\QTTask.exe" [2010-03-17 421888]
    "iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2010-04-24 142120]
    "Lingvo Launcher"="c:\program files\ABBYY Lingvo 12\Lvagent.exe" [2006-12-14 258048]
    "Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2011-06-08 37296]
    "Adobe ARM"="c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2011-03-30 937920]
    "HostManager"="c:\program files\Common Files\AOL\1319659121\ee\AOLSoftware.exe" [2010-03-08 41800]
    "SunJavaUpdateSched"="c:\program files\Common Files\Java\Java Update\jusched.exe" [2011-06-09 254696]
    .
    [HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
    "OrangePlayer"="c:\program files\Orange\Media Player\Media Player.exe" [2009-09-05 319488]
    .
    c:\users\Guillaume\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\
    EvernoteClipper.lnk - c:\program files\Evernote\Evernote\EvernoteClipper.exe [2011-4-12 973824]
    Kuma_Tray.lnk - c:\program files\Kuma Games\kgsystray\Kuma_tray.exe [2011-5-12 33472]
    .
    [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
    "ConsentPromptBehaviorAdmin"= 5 (0x5)
    "ConsentPromptBehaviorUser"= 3 (0x3)
    "EnableUIADesktopToggle"= 0 (0x0)
    .
    [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
    "aux2"=wdmaud.drv
    .
    [HKEY_LOCAL_MACHINE\system\currentcontrolset\control\lsa]
    Security Packages REG_MULTI_SZ kerberos msv1_0 schannel wdigest tspkg pku2u livessp
    .
    R2 AntiVirSchedulerService;Avira AntiVir Planificateur;c:\program files\Avira\AntiVir Desktop\sched.exe [x]
    R2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;c:\windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-03-18 130384]
    R2 gupdate;Service Google Update (gupdate);c:\program files\Google\Update\GoogleUpdate.exe [2011-04-28 136176]
    R3 gupdatem;Service Google Update (gupdatem);c:\program files\Google\Update\GoogleUpdate.exe [2011-04-28 136176]
    R3 RTL8167;Realtek 8167 NT Driver;c:\windows\system32\DRIVERS\Rt86win7.sys [2009-07-13 139776]
    R3 WatAdminSvc;Service Windows Activation Technologies;c:\windows\system32\Wat\WatAdminSvc.exe [2010-05-19 1343400]
    S1 SABI;SAMSUNG Kernel Driver For Windows 7;c:\windows\system32\Drivers\SABI.sys [2009-05-28 10752]
    S1 vwififlt;Virtual WiFi Filter Driver;c:\windows\system32\DRIVERS\vwififlt.sys [2009-07-13 48128]
    S2 Akamai;Akamai NetSession Interface;c:\windows\System32\svchost.exe [2009-07-14 20992]
    S2 AMD External Events Utility;AMD External Events Utility;c:\windows\system32\atiesrxx.exe [2009-09-02 172032]
    S2 pgsql-8.3;PostgreSQL Database Server 8.3;c:\program files\PostgreSQL\8.3\bin\pg_ctl.exe [2008-09-19 65536]
    S2 Rezip;Rezip;c:\windows\SYSTEM32\Rezip.exe [2009-03-05 311296]
    S2 yksvc;Marvell Yukon Service;c:\windows\System32\svchost.exe [2009-07-14 20992]
    S3 VMC326;Vimicro Camera Service VMC326;c:\windows\system32\Drivers\VMC326.sys [2009-08-10 237696]
    S3 yukonw7;NDIS6.2 Miniport Driver for Marvell Yukon Ethernet Controller;c:\windows\system32\DRIVERS\yk62x86.sys [2009-06-15 313856]
    .
    .
    [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
    yksvcs REG_MULTI_SZ yksvc
    vvdsvc REG_MULTI_SZ vvdsvc
    Akamai REG_MULTI_SZ Akamai
    .
    Contenu du dossier 'Tâches planifiées'
    .
    2011-11-05 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
    - c:\program files\Google\Update\GoogleUpdate.exe [2011-04-28 10:09]
    .
    2011-11-05 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
    - c:\program files\Google\Update\GoogleUpdate.exe [2011-04-28 10:09]
    .
    .
    ------- Examen supplémentaire -------
    .
    uStart Page = hxxp://www.google.com/ig/redirectdomain?brand=smsn&bmod=smsn
    uInternet Settings,ProxyServer = 216.49.160.27:80
    uInternet Settings,ProxyOverride = local
    IE: Add to Evernote 4.0 - c:\program files\Evernote\Evernote\EvernoteIE.dll/204
    IE: E&xporter vers Microsoft Excel - c:\progra~1\MICROS~2\Office12\EXCEL.EXE/3000
    IE: Google Sidewiki... - c:\program files\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_en_D183CA64F05FDD98.dll/cmsidewiki.html
    IE: Translate with ABBYY &Lingvo... - c:\program files\ABBYY Lingvo 12\Lingvo.exe/3000
    IE: {{A95fe080-8f5d-11d2-a20b-00aa003c157a} - res://c:\program files\Evernote\Evernote\EvernoteIE.dll/204
    TCP: DhcpNameServer = 192.168.1.1 192.168.1.1
    FF - ProfilePath - c:\users\Guillaume\AppData\Roaming\Mozilla\Firefox\Profiles\xtme9jwa.default\
    FF - prefs.js: browser.startup.homepage - hxxp://www.google.com/ig/redirectdomain?brand=smsn&bmod=smsn
    FF - prefs.js: network.proxy.type - 0
    FF - Ext: Default: {972ce4c6-7e08-4474-a285-3208198ce6fd} - c:\program files\Mozilla Firefox\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd}
    FF - Ext: Java Console: {CAFEEFAC-0016-0000-0023-ABCDEFFEDCBA} - c:\program files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0023-ABCDEFFEDCBA}
    FF - Ext: Java Console: {CAFEEFAC-0016-0000-0024-ABCDEFFEDCBA} - c:\program files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0024-ABCDEFFEDCBA}
    FF - Ext: Java Console: {CAFEEFAC-0016-0000-0026-ABCDEFFEDCBA} - c:\program files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0026-ABCDEFFEDCBA}
    FF - Ext: Google Toolbar for Firefox: {3112ca9c-de6d-4884-a869-9855de68056c} - c:\programdata\Google\Toolbar for Firefox\{3112ca9c-de6d-4884-a869-9855de68056c}
    .
    .
    --------------------- CLES DE REGISTRE BLOQUEES ---------------------
    .
    [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0000\AllUserSettings]
    @Denied: (A) (Users)
    @Denied: (A) (Everyone)
    @Allowed: (B 1 2 3 4 5) (S-1-5-20)
    "BlindDial"=dword:00000000
    "MSCurrentCountry"=dword:000000b5
    .
    [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\PCW\Security]
    @Denied: (Full) (Everyone)
    .
    --------------------- DLLs chargées dans les processus actifs ---------------------
    .
    - - - - - - - > 'Explorer.exe'(6012)
    c:\program files\ABBYY Lingvo 12\LvHook.dll
    .
    Heure de fin: 2011-11-05 14:34:03
    ComboFix-quarantined-files.txt 2011-11-05 13:34
    ComboFix2.txt 2011-11-05 00:29
    .
    Avant-CF: 55 654 576 128 octets libres
    Après-CF: 55 371 116 544 octets libres
    .
    - - End Of File - - DFBB5BEF2BA13D93BE3CF3EF460F0840
    0
  8. juju666 Messages postés 35446 Date d'inscription   Statut Contributeur sécurité Dernière intervention   4 796
     
    ▶ Télécharge Reload_TDSSKiller

    ▶ Lance le

    choisis : lancer le nettoyage

    l'outil va automatiquement télécharger la derniere version puis

    TDSSKiller va s'ouvrir , clique sur "Start Scan" Clique ici pour l'aide en image

    Si TDSS.tdl2 est détecté: l'option delete sera cochée par défaut.
    Si TDSS.tdl3 est détecté: assure toi que Cure est bien cochée.
    Si TDSS.tdl4(\HardDisk0\MBR) est détecté: assure toi que Cure est bien cochée.
    Si Rootkit.Win32.ZAccess.* est détecté : règle sur "cure" en haut , et "delete" en bas
    Si Suspicious file est indiqué, laisse l''option cochée sur Skip
    une fois qu'il a terminé , redémarre s'il te le demande pour finir de nettoyer

    sinon , ferme TDSSKiller et le rapport s'affichera sur le bureau

    ▶ Copie/Colle son contenu dans ta prochaine réponse.
    0
  9. lucie
     
    15:36:05.0849 2816 TDSS rootkit removing tool 2.6.14.0 Oct 28 2011 11:11:01
    15:36:15.0032 2816 Perform update action was selected
    15:36:15.0042 5624 Deinitialize success
    0
    1. tant pis
       
      lol
      0
    2. lucie
       
      hahaha
      0
    3. juju666 Messages postés 35446 Date d'inscription   Statut Contributeur sécurité Dernière intervention   4 796
       
      Bah t'as pas lancé le scan là pourtant je me suis tué à te faire une belle image ^^
      0
  10. lucie
     
    15:36:41.0072 4968 TDSS rootkit removing tool 2.6.15.0 Nov 3 2011 17:15:49
    15:36:41.0200 4968 ============================================================
    15:36:41.0200 4968 Current date / time: 2011/11/05 15:36:41.0200
    15:36:41.0200 4968 SystemInfo:
    15:36:41.0200 4968
    15:36:41.0200 4968 OS Version: 6.1.7600 ServicePack: 0.0
    15:36:41.0200 4968 Product type: Workstation
    15:36:41.0200 4968 ComputerName: GUILLAUME-PC
    15:36:41.0200 4968 UserName: Guillaume
    15:36:41.0200 4968 Windows directory: C:\windows
    15:36:41.0200 4968 System windows directory: C:\windows
    15:36:41.0200 4968 Processor architecture: Intel x86
    15:36:41.0200 4968 Number of processors: 2
    15:36:41.0200 4968 Page size: 0x1000
    15:36:41.0200 4968 Boot type: Normal boot
    15:36:41.0200 4968 ============================================================
    15:36:41.0871 4968 Initialize success
    15:36:45.0615 2156 ============================================================
    15:36:45.0615 2156 Scan started
    15:36:45.0615 2156 Mode: Manual;
    15:36:45.0615 2156 ============================================================
    15:36:46.0591 2156 1394ohci (6d2aca41739bfe8cb86ee8e85f29697d) C:\windows\system32\DRIVERS\1394ohci.sys
    15:36:46.0591 2156 1394ohci - ok
    15:36:46.0721 2156 ACPI (f0e07d144c8685b8774bc32fc8da4df0) C:\windows\system32\DRIVERS\ACPI.sys
    15:36:46.0731 2156 ACPI - ok
    15:36:46.0821 2156 AcpiPmi (98d81ca942d19f7d9153b095162ac013) C:\windows\system32\DRIVERS\acpipmi.sys
    15:36:46.0821 2156 AcpiPmi - ok
    15:36:46.0951 2156 adp94xx (21e785ebd7dc90a06391141aac7892fb) C:\windows\system32\DRIVERS\adp94xx.sys
    15:36:46.0961 2156 adp94xx - ok
    15:36:47.0071 2156 adpahci (0c676bc278d5b59ff5abd57bbe9123f2) C:\windows\system32\DRIVERS\adpahci.sys
    15:36:47.0081 2156 adpahci - ok
    15:36:47.0181 2156 adpu320 (7c7b5ee4b7b822ec85321fe23a27db33) C:\windows\system32\DRIVERS\adpu320.sys
    15:36:47.0181 2156 adpu320 - ok
    15:36:47.0361 2156 AFD (0db7a48388d54d154ebec120461a0fcd) C:\windows\system32\drivers\afd.sys
    15:36:47.0371 2156 AFD - ok
    15:36:47.0511 2156 AgereSoftModem (07758c2196a62f207f77556311e7459a) C:\windows\system32\DRIVERS\AGRSM.sys
    15:36:47.0531 2156 AgereSoftModem - ok
    15:36:47.0621 2156 agp440 (507812c3054c21cef746b6ee3d04dd6e) C:\windows\system32\DRIVERS\agp440.sys
    15:36:47.0631 2156 agp440 - ok
    15:36:47.0771 2156 aic78xx (8b30250d573a8f6b4bd23195160d8707) C:\windows\system32\DRIVERS\djsvs.sys
    15:36:47.0771 2156 aic78xx - ok
    15:36:47.0921 2156 aliide (0d40bcf52ea90fc7df2aeab6503dea44) C:\windows\system32\DRIVERS\aliide.sys
    15:36:47.0921 2156 aliide - ok
    15:36:48.0001 2156 amdagp (3c6600a0696e90a463771c7422e23ab5) C:\windows\system32\DRIVERS\amdagp.sys
    15:36:48.0001 2156 amdagp - ok
    15:36:48.0141 2156 amdide (cd5914170297126b6266860198d1d4f0) C:\windows\system32\DRIVERS\amdide.sys
    15:36:48.0141 2156 amdide - ok
    15:36:48.0241 2156 AmdK8 (00dda200d71bac534bf56a9db5dfd666) C:\windows\system32\DRIVERS\amdk8.sys
    15:36:48.0241 2156 AmdK8 - ok
    15:36:48.0331 2156 AmdPPM (3cbf30f5370fda40dd3e87df38ea53b6) C:\windows\system32\DRIVERS\amdppm.sys
    15:36:48.0331 2156 AmdPPM - ok
    15:36:48.0451 2156 amdsata (19ce906b4cdc11fc4fef5745f33a63b6) C:\windows\system32\drivers\amdsata.sys
    15:36:48.0451 2156 amdsata - ok
    15:36:48.0561 2156 amdsbs (ea43af0c423ff267355f74e7a53bdaba) C:\windows\system32\DRIVERS\amdsbs.sys
    15:36:48.0561 2156 amdsbs - ok
    15:36:48.0611 2156 amdxata (869e67d66be326a5a9159fba8746fa70) C:\windows\system32\drivers\amdxata.sys
    15:36:48.0611 2156 amdxata - ok
    15:36:48.0791 2156 AppID (feb834c02ce1e84b6a38f953ca067706) C:\windows\system32\drivers\appid.sys
    15:36:48.0791 2156 AppID - ok
    15:36:48.0981 2156 arc (2932004f49677bd84dbc72edb754ffb3) C:\windows\system32\DRIVERS\arc.sys
    15:36:48.0981 2156 arc - ok
    15:36:49.0071 2156 arcsas (5d6f36c46fd283ae1b57bd2e9feb0bc7) C:\windows\system32\DRIVERS\arcsas.sys
    15:36:49.0071 2156 arcsas - ok
    15:36:49.0171 2156 AsyncMac (add2ade1c2b285ab8378d2daaf991481) C:\windows\system32\DRIVERS\asyncmac.sys
    15:36:49.0171 2156 AsyncMac - ok
    15:36:49.0281 2156 atapi (338c86357871c167a96ab976519bf59e) C:\windows\system32\DRIVERS\atapi.sys
    15:36:49.0281 2156 atapi - ok
    15:36:49.0401 2156 athr (ac4adac154563ab41cc79b0257bc685a) C:\windows\system32\DRIVERS\athr.sys
    15:36:49.0411 2156 athr - ok
    15:36:49.0681 2156 atikmdag (745c79700646c3f285cd09775618a04b) C:\windows\system32\DRIVERS\atikmdag.sys
    15:36:49.0731 2156 atikmdag - ok
    15:36:49.0849 2156 avgio (f1d43170fdd7399ee17ea32d4f868b0c) C:\Program Files\Avira\AntiVir Desktop\avgio.sys
    15:36:49.0849 2156 avgio - ok
    15:36:50.0005 2156 avgntflt (14fe36d8f2c6a2435275338d061a0b66) C:\windows\system32\DRIVERS\avgntflt.sys
    15:36:50.0005 2156 avgntflt - ok
    15:36:50.0114 2156 avipbb (ad9bd66a862116e79cb45bb6be46055f) C:\windows\system32\DRIVERS\avipbb.sys
    15:36:50.0114 2156 avipbb - ok
    15:36:50.0239 2156 b06bdrv (1a231abec60fd316ec54c66715543cec) C:\windows\system32\DRIVERS\bxvbdx.sys
    15:36:50.0255 2156 b06bdrv - ok
    15:36:50.0333 2156 b57nd60x (bd8869eb9cde6bbe4508d869929869ee) C:\windows\system32\DRIVERS\b57nd60x.sys
    15:36:50.0348 2156 b57nd60x - ok
    15:36:50.0458 2156 Beep (505506526a9d467307b3c393dedaf858) C:\windows\system32\drivers\Beep.sys
    15:36:50.0458 2156 Beep - ok
    15:36:50.0551 2156 blbdrive (2287078ed48fcfc477b05b20cf38f36f) C:\windows\system32\DRIVERS\blbdrive.sys
    15:36:50.0551 2156 blbdrive - ok
    15:36:50.0660 2156 bowser (9a5c671b7fbae4865149bb11f59b91b2) C:\windows\system32\DRIVERS\bowser.sys
    15:36:50.0660 2156 bowser - ok
    15:36:50.0770 2156 BrFiltLo (9f9acc7f7ccde8a15c282d3f88b43309) C:\windows\system32\DRIVERS\BrFiltLo.sys
    15:36:50.0770 2156 BrFiltLo - ok
    15:36:50.0863 2156 BrFiltUp (56801ad62213a41f6497f96dee83755a) C:\windows\system32\DRIVERS\BrFiltUp.sys
    15:36:50.0863 2156 BrFiltUp - ok
    15:36:50.0972 2156 Brserid (845b8ce732e67f3b4133164868c666ea) C:\windows\System32\Drivers\Brserid.sys
    15:36:50.0988 2156 Brserid - ok
    15:36:51.0082 2156 BrSerWdm (203f0b1e73adadbbb7b7b1fabd901f6b) C:\windows\System32\Drivers\BrSerWdm.sys
    15:36:51.0082 2156 BrSerWdm - ok
    15:36:51.0175 2156 BrUsbMdm (bd456606156ba17e60a04e18016ae54b) C:\windows\System32\Drivers\BrUsbMdm.sys
    15:36:51.0175 2156 BrUsbMdm - ok
    15:36:51.0253 2156 BrUsbSer (af72ed54503f717a43268b3cc5faec2e) C:\windows\System32\Drivers\BrUsbSer.sys
    15:36:51.0253 2156 BrUsbSer - ok
    15:36:51.0409 2156 BthEnum (2865a5c8e98c70c605f417908cebb3a4) C:\windows\system32\drivers\BthEnum.sys
    15:36:51.0425 2156 BthEnum - ok
    15:36:51.0456 2156 BTHMODEM (ed3df7c56ce0084eb2034432fc56565a) C:\windows\system32\DRIVERS\bthmodem.sys
    15:36:51.0472 2156 BTHMODEM - ok
    15:36:51.0565 2156 BthPan (ad1872e5829e8a2c3b5b4b641c3eab0e) C:\windows\system32\DRIVERS\bthpan.sys
    15:36:51.0565 2156 BthPan - ok
    15:36:51.0674 2156 BTHPORT (88059ff1ded4472acd17eebabd393069) C:\windows\System32\Drivers\BTHport.sys
    15:36:51.0674 2156 BTHPORT - ok
    15:36:51.0799 2156 BTHUSB (80e6384beec03b8bd45edea29802d657) C:\windows\System32\Drivers\BTHUSB.sys
    15:36:51.0799 2156 BTHUSB - ok
    15:36:51.0893 2156 catchme - ok
    15:36:51.0971 2156 cdfs (77ea11b065e0a8ab902d78145ca51e10) C:\windows\system32\DRIVERS\cdfs.sys
    15:36:51.0971 2156 cdfs - ok
    15:36:52.0080 2156 cdrom (ba6e70aa0e6091bc39de29477d866a77) C:\windows\system32\DRIVERS\cdrom.sys
    15:36:52.0080 2156 cdrom - ok
    15:36:52.0174 2156 circlass (3fe3fe94a34df6fb06e6418d0f6a0060) C:\windows\system32\DRIVERS\circlass.sys
    15:36:52.0174 2156 circlass - ok
    15:36:52.0267 2156 CLFS (635181e0e9bbf16871bf5380d71db02d) C:\windows\system32\CLFS.sys
    15:36:52.0267 2156 CLFS - ok
    15:36:52.0392 2156 CmBatt (dea805815e587dad1dd2c502220b5616) C:\windows\system32\DRIVERS\CmBatt.sys
    15:36:52.0392 2156 CmBatt - ok
    15:36:52.0439 2156 cmdide (c537b1db64d495b9b4717b4d6d9edbf2) C:\windows\system32\DRIVERS\cmdide.sys
    15:36:52.0439 2156 cmdide - ok
    15:36:52.0501 2156 CNG (1b675691ed940766149c93e8f4488d68) C:\windows\system32\Drivers\cng.sys
    15:36:52.0501 2156 CNG - ok
    15:36:52.0595 2156 Compbatt (a6023d3823c37043986713f118a89bee) C:\windows\system32\DRIVERS\compbatt.sys
    15:36:52.0610 2156 Compbatt - ok
    15:36:52.0720 2156 CompositeBus (f1724ba27e97d627f808fb0ba77a28a6) C:\windows\system32\DRIVERS\CompositeBus.sys
    15:36:52.0720 2156 CompositeBus - ok
    15:36:52.0829 2156 crcdisk (2c4ebcfc84a9b44f209dff6c6e6c61d1) C:\windows\system32\DRIVERS\crcdisk.sys
    15:36:52.0829 2156 crcdisk - ok
    15:36:52.0969 2156 DfsC (fdecdde6b28bb17c8db0d70e487476db) C:\windows\system32\Drivers\dfsc.sys
    15:36:52.0969 2156 DfsC - ok
    15:36:53.0078 2156 discache (1a050b0274bfb3890703d490f330c0da) C:\windows\system32\drivers\discache.sys
    15:36:53.0078 2156 discache - ok
    15:36:53.0172 2156 Disk (565003f326f99802e68ca78f2a68e9ff) C:\windows\system32\DRIVERS\disk.sys
    15:36:53.0172 2156 Disk - ok
    15:36:53.0266 2156 drmkaud (b918e7c5f9bf77202f89e1a9539f2eb4) C:\windows\system32\drivers\drmkaud.sys
    15:36:53.0266 2156 drmkaud - ok
    15:36:53.0390 2156 DXGKrnl (1679a4669326cb1a67cc95658d273234) C:\windows\System32\drivers\dxgkrnl.sys
    15:36:53.0390 2156 DXGKrnl - ok
    15:36:53.0593 2156 ebdrv (024e1b5cac09731e4d868e64dbfb4ab0) C:\windows\system32\DRIVERS\evbdx.sys
    15:36:53.0624 2156 ebdrv - ok
    15:36:53.0765 2156 elxstor (0ed67910c8c326796faa00b2bf6d9d3c) C:\windows\system32\DRIVERS\elxstor.sys
    15:36:53.0765 2156 elxstor - ok
    15:36:53.0843 2156 ErrDev (8fc3208352dd3912c94367a206ab3f11) C:\windows\system32\DRIVERS\errdev.sys
    15:36:53.0843 2156 ErrDev - ok
    15:36:53.0952 2156 exfat (2dc9108d74081149cc8b651d3a26207f) C:\windows\system32\drivers\exfat.sys
    15:36:53.0952 2156 exfat - ok
    15:36:54.0030 2156 fastfat (7e0ab74553476622fb6ae36f73d97d35) C:\windows\system32\drivers\fastfat.sys
    15:36:54.0030 2156 fastfat - ok
    15:36:54.0139 2156 fdc (e817a017f82df2a1f8cfdbda29388b29) C:\windows\system32\DRIVERS\fdc.sys
    15:36:54.0139 2156 fdc - ok
    15:36:54.0233 2156 FileInfo (6cf00369c97f3cf563be99be983d13d8) C:\windows\system32\drivers\fileinfo.sys
    15:36:54.0248 2156 FileInfo - ok
    15:36:54.0342 2156 Filetrace (42c51dc94c91da21cb9196eb64c45db9) C:\windows\system32\drivers\filetrace.sys
    15:36:54.0342 2156 Filetrace - ok
    15:36:54.0436 2156 flpydisk (87907aa70cb3c56600f1c2fb8841579b) C:\windows\system32\DRIVERS\flpydisk.sys
    15:36:54.0436 2156 flpydisk - ok
    15:36:54.0529 2156 FltMgr (7520ec808e0c35e0ee6f841294316653) C:\windows\system32\drivers\fltmgr.sys
    15:36:54.0545 2156 FltMgr - ok
    15:36:54.0638 2156 FsDepends (1a16b57943853e598cff37fe2b8cbf1d) C:\windows\system32\drivers\FsDepends.sys
    15:36:54.0638 2156 FsDepends - ok
    15:36:54.0748 2156 fssfltr (d909075fa72c090f27aa926c32cb4612) C:\windows\system32\DRIVERS\fssfltr.sys
    15:36:54.0748 2156 fssfltr - ok
    15:36:54.0841 2156 Fs_Rec (a574b4360e438977038aae4bf60d79a2) C:\windows\system32\drivers\Fs_Rec.sys
    15:36:54.0841 2156 Fs_Rec - ok
    15:36:54.0935 2156 fvevol (dafbd9fe39197495aed6d51f3b85b5d2) C:\windows\system32\DRIVERS\fvevol.sys
    15:36:54.0935 2156 fvevol - ok
    15:36:55.0028 2156 gagp30kx (65ee0c7a58b65e74ae05637418153938) C:\windows\system32\DRIVERS\gagp30kx.sys
    15:36:55.0028 2156 gagp30kx - ok
    15:36:55.0122 2156 GEARAspiWDM (8182ff89c65e4d38b2de4bb0fb18564e) C:\windows\system32\DRIVERS\GEARAspiWDM.sys
    15:36:55.0122 2156 GEARAspiWDM - ok
    15:36:55.0231 2156 hcw85cir (c44e3c2bab6837db337ddee7544736db) C:\windows\system32\drivers\hcw85cir.sys
    15:36:55.0231 2156 hcw85cir - ok
    15:36:55.0356 2156 HdAudAddService (3530cad25deba7dc7de8bb51632cbc5f) C:\windows\system32\drivers\HdAudio.sys
    15:36:55.0356 2156 HdAudAddService - ok
    15:36:55.0465 2156 HDAudBus (717a2207fd6f13ad3e664c7d5a43c7bf) C:\windows\system32\DRIVERS\HDAudBus.sys
    15:36:55.0465 2156 HDAudBus - ok
    15:36:55.0668 2156 HidBatt (1d58a7f3e11a9731d0eaaaa8405acc36) C:\windows\system32\DRIVERS\HidBatt.sys
    15:36:55.0668 2156 HidBatt - ok
    15:36:55.0824 2156 HidBth (89448f40e6df260c206a193a4683ba78) C:\windows\system32\DRIVERS\hidbth.sys
    15:36:55.0824 2156 HidBth - ok
    15:36:55.0949 2156 HidIr (cf50b4cf4a4f229b9f3c08351f99ca5e) C:\windows\system32\DRIVERS\hidir.sys
    15:36:55.0949 2156 HidIr - ok
    15:36:56.0058 2156 HidUsb (25072fb35ac90b25f9e4e3bacf774102) C:\windows\system32\DRIVERS\hidusb.sys
    15:36:56.0058 2156 HidUsb - ok
    15:36:56.0183 2156 HpSAMD (295fdc419039090eb8b49ffdbb374549) C:\windows\system32\DRIVERS\HpSAMD.sys
    15:36:56.0183 2156 HpSAMD - ok
    15:36:56.0276 2156 HTTP (c531c7fd9e8b62021112787c4e2c5a5a) C:\windows\system32\drivers\HTTP.sys
    15:36:56.0292 2156 HTTP - ok
    15:36:56.0370 2156 hwpolicy (8305f33cde89ad6c7a0763ed0b5a8d42) C:\windows\system32\drivers\hwpolicy.sys
    15:36:56.0370 2156 hwpolicy - ok
    15:36:56.0495 2156 i8042prt (f151f0bdc47f4a28b1b20a0818ea36d6) C:\windows\system32\DRIVERS\i8042prt.sys
    15:36:56.0510 2156 i8042prt - ok
    15:36:56.0604 2156 iaStor (d483687eace0c065ee772481a96e05f5) C:\windows\system32\DRIVERS\iaStor.sys
    15:36:56.0604 2156 iaStor - ok
    15:36:56.0729 2156 iaStorV (71f1a494fedf4b33c02c4a6a28d6d9e9) C:\windows\system32\drivers\iaStorV.sys
    15:36:56.0744 2156 iaStorV - ok
    15:36:56.0963 2156 igfx (ad626f6964f4d364d226c39e06872dd3) C:\windows\system32\DRIVERS\igdkmd32.sys
    15:36:56.0994 2156 igfx - ok
    15:36:57.0119 2156 iirsp (4173ff5708f3236cf25195fecd742915) C:\windows\system32\DRIVERS\iirsp.sys
    15:36:57.0119 2156 iirsp - ok
    15:36:57.0306 2156 IntcAzAudAddService (5ceef2cccb4fe00d3ffbfeb12bcfa07f) C:\windows\system32\drivers\RTKVHDA.sys
    15:36:57.0322 2156 IntcAzAudAddService - ok
    15:36:57.0431 2156 intelide (a0f12f2c9ba6c72f3987ce780e77c130) C:\windows\system32\DRIVERS\intelide.sys
    15:36:57.0446 2156 intelide - ok
    15:36:57.0540 2156 intelppm (3b514d27bfc4accb4037bc6685f766e0) C:\windows\system32\DRIVERS\intelppm.sys
    15:36:57.0540 2156 intelppm - ok
    15:36:57.0634 2156 IpFilterDriver (709d1761d3b19a932ff0238ea6d50200) C:\windows\system32\DRIVERS\ipfltdrv.sys
    15:36:57.0634 2156 IpFilterDriver - ok
    15:36:57.0727 2156 IPMIDRV (e4454b6c37d7ffd5649611f6496308a7) C:\windows\system32\DRIVERS\IPMIDrv.sys
    15:36:57.0727 2156 IPMIDRV - ok
    15:36:57.0805 2156 IPNAT (a5fa468d67abcdaa36264e463a7bb0cd) C:\windows\system32\drivers\ipnat.sys
    15:36:57.0805 2156 IPNAT - ok
    15:36:57.0946 2156 IRENUM (42996cff20a3084a56017b7902307e9f) C:\windows\system32\drivers\irenum.sys
    15:36:57.0946 2156 IRENUM - ok
    15:36:58.0024 2156 isapnp (1f32bb6b38f62f7df1a7ab7292638a35) C:\windows\system32\DRIVERS\isapnp.sys
    15:36:58.0024 2156 isapnp - ok
    15:36:58.0117 2156 iScsiPrt (ed46c223ae46c6866ab77cdc41c404b7) C:\windows\system32\DRIVERS\msiscsi.sys
    15:36:58.0117 2156 iScsiPrt - ok
    15:36:58.0226 2156 kbdclass (adef52ca1aeae82b50df86b56413107e) C:\windows\system32\DRIVERS\kbdclass.sys
    15:36:58.0242 2156 kbdclass - ok
    15:36:58.0336 2156 kbdhid (3d9f0ebf350edcfd6498057301455964) C:\windows\system32\DRIVERS\kbdhid.sys
    15:36:58.0336 2156 kbdhid - ok
    15:36:58.0429 2156 KSecDD (e36a061ec11b373826905b21be10948f) C:\windows\system32\Drivers\ksecdd.sys
    15:36:58.0429 2156 KSecDD - ok
    15:36:58.0538 2156 KSecPkg (365c6154bbbc5377173f1ca7bfb6cc59) C:\windows\system32\Drivers\ksecpkg.sys
    15:36:58.0538 2156 KSecPkg - ok
    15:36:58.0648 2156 lltdio (f7611ec07349979da9b0ae1f18ccc7a6) C:\windows\system32\DRIVERS\lltdio.sys
    15:36:58.0648 2156 lltdio - ok
    15:36:58.0788 2156 LSI_FC (eb119a53ccf2acc000ac71b065b78fef) C:\windows\system32\DRIVERS\lsi_fc.sys
    15:36:58.0804 2156 LSI_FC - ok
    15:36:58.0897 2156 LSI_SAS (8ade1c877256a22e49b75d1cc9161f9c) C:\windows\system32\DRIVERS\lsi_sas.sys
    15:36:58.0913 2156 LSI_SAS - ok
    15:36:59.0022 2156 LSI_SAS2 (dc9dc3d3daa0e276fd2ec262e38b11e9) C:\windows\system32\DRIVERS\lsi_sas2.sys
    15:36:59.0022 2156 LSI_SAS2 - ok
    15:36:59.0100 2156 LSI_SCSI (0a036c7d7cab643a7f07135ac47e0524) C:\windows\system32\DRIVERS\lsi_scsi.sys
    15:36:59.0100 2156 LSI_SCSI - ok
    15:36:59.0194 2156 luafv (6703e366cc18d3b6e534f5cf7df39cee) C:\windows\system32\drivers\luafv.sys
    15:36:59.0194 2156 luafv - ok
    15:36:59.0334 2156 LVRS (37072ec9299e825f4335cc554b6fac6a) C:\windows\system32\DRIVERS\lvrs.sys
    15:36:59.0334 2156 LVRS - ok
    15:36:59.0677 2156 LVUVC (a240e42a7402e927a71b6e8aa4629b13) C:\windows\system32\DRIVERS\lvuvc.sys
    15:36:59.0740 2156 LVUVC - ok
    15:36:59.0833 2156 megasas (0fff5b045293002ab38eb1fd1fc2fb74) C:\windows\system32\DRIVERS\megasas.sys
    15:36:59.0833 2156 megasas - ok
    15:36:59.0942 2156 MegaSR (dcbab2920c75f390caf1d29f675d03d6) C:\windows\system32\DRIVERS\MegaSR.sys
    15:36:59.0942 2156 MegaSR - ok
    15:37:00.0036 2156 Modem (f001861e5700ee84e2d4e52c712f4964) C:\windows\system32\drivers\modem.sys
    15:37:00.0036 2156 Modem - ok
    15:37:00.0130 2156 monitor (79d10964de86b292320e9dfe02282a23) C:\windows\system32\DRIVERS\monitor.sys
    15:37:00.0130 2156 monitor - ok
    15:37:00.0223 2156 mouclass (fb18cc1d4c2e716b6b903b0ac0cc0609) C:\windows\system32\DRIVERS\mouclass.sys
    15:37:00.0223 2156 mouclass - ok
    15:37:00.0332 2156 mouhid (2c388d2cd01c9042596cf3c8f3c7b24d) C:\windows\system32\DRIVERS\mouhid.sys
    15:37:00.0348 2156 mouhid - ok
    15:37:00.0426 2156 mountmgr (921c18727c5920d6c0300736646931c2) C:\windows\system32\drivers\mountmgr.sys
    15:37:00.0426 2156 mountmgr - ok
    15:37:00.0504 2156 mpio (2af5997438c55fb79d33d015c30e1974) C:\windows\system32\DRIVERS\mpio.sys
    15:37:00.0504 2156 mpio - ok
    15:37:00.0582 2156 mpsdrv (ad2723a7b53dd1aacae6ad8c0bfbf4d0) C:\windows\system32\drivers\mpsdrv.sys
    15:37:00.0582 2156 mpsdrv - ok
    15:37:00.0676 2156 MRxDAV (b1be47008d20e43da3adc37c24cdb89d) C:\windows\system32\drivers\mrxdav.sys
    15:37:00.0676 2156 MRxDAV - ok
    15:37:00.0769 2156 mrxsmb (ca7570e42522e24324a12161db14ec02) C:\windows\system32\DRIVERS\mrxsmb.sys
    15:37:00.0769 2156 mrxsmb - ok
    15:37:00.0878 2156 mrxsmb10 (f965c3ab2b2ae5c378f4562486e35051) C:\windows\system32\DRIVERS\mrxsmb10.sys
    15:37:00.0878 2156 mrxsmb10 - ok
    15:37:00.0972 2156 mrxsmb20 (25c38264a3c72594dd21d355d70d7a5d) C:\windows\system32\DRIVERS\mrxsmb20.sys
    15:37:00.0972 2156 mrxsmb20 - ok
    15:37:01.0050 2156 msahci (4326d168944123f38dd3b2d9c37a0b12) C:\windows\system32\DRIVERS\msahci.sys
    15:37:01.0050 2156 msahci - ok
    15:37:01.0144 2156 msdsm (455029c7174a2dbb03dba8a0d8bddd9a) C:\windows\system32\DRIVERS\msdsm.sys
    15:37:01.0144 2156 msdsm - ok
    15:37:01.0253 2156 Msfs (daefb28e3af5a76abcc2c3078c07327f) C:\windows\system32\drivers\Msfs.sys
    15:37:01.0253 2156 Msfs - ok
    15:37:01.0331 2156 mshidkmdf (3e1e5767043c5af9367f0056295e9f84) C:\windows\System32\drivers\mshidkmdf.sys
    15:37:01.0331 2156 mshidkmdf - ok
    15:37:01.0424 2156 msisadrv (0a4e5757ae09fa9622e3158cc1aef114) C:\windows\system32\DRIVERS\msisadrv.sys
    15:37:01.0424 2156 msisadrv - ok
    15:37:01.0534 2156 MSKSSRV (8c0860d6366aaffb6c5bb9df9448e631) C:\windows\system32\drivers\MSKSSRV.sys
    15:37:01.0534 2156 MSKSSRV - ok
    15:37:01.0643 2156 MSPCLOCK (3ea8b949f963562cedbb549eac0c11ce) C:\windows\system32\drivers\MSPCLOCK.sys
    15:37:01.0643 2156 MSPCLOCK - ok
    15:37:01.0736 2156 MSPQM (f456e973590d663b1073e9c463b40932) C:\windows\system32\drivers\MSPQM.sys
    15:37:01.0736 2156 MSPQM - ok
    15:37:01.0814 2156 MsRPC (0e008fc4819d238c51d7c93e7b41e560) C:\windows\system32\drivers\MsRPC.sys
    15:37:01.0814 2156 MsRPC - ok
    15:37:01.0908 2156 mssmbios (fc6b9ff600cc585ea38b12589bd4e246) C:\windows\system32\DRIVERS\mssmbios.sys
    15:37:01.0908 2156 mssmbios - ok
    15:37:02.0002 2156 MSTEE (b42c6b921f61a6e55159b8be6cd54a36) C:\windows\system32\drivers\MSTEE.sys
    15:37:02.0002 2156 MSTEE - ok
    15:37:02.0080 2156 MTConfig (33599130f44e1f34631cea241de8ac84) C:\windows\system32\DRIVERS\MTConfig.sys
    15:37:02.0080 2156 MTConfig - ok
    15:37:02.0142 2156 Mup (159fad02f64e6381758c990f753bcc80) C:\windows\system32\Drivers\mup.sys
    15:37:02.0142 2156 Mup - ok
    15:37:02.0267 2156 NativeWifiP (26384429fcd85d83746f63e798ab1480) C:\windows\system32\DRIVERS\nwifi.sys
    15:37:02.0267 2156 NativeWifiP - ok
    15:37:02.0376 2156 NDIS (23759d175a0a9baaf04d05047bc135a8) C:\windows\system32\drivers\ndis.sys
    15:37:02.0376 2156 NDIS - ok
    15:37:02.0470 2156 NdisCap (0e1787aa6c9191d3d319e8bafe86f80c) C:\windows\system32\DRIVERS\ndiscap.sys
    15:37:02.0470 2156 NdisCap - ok
    15:37:02.0579 2156 NdisTapi (e4a8aec125a2e43a9e32afeea7c9c888) C:\windows\system32\DRIVERS\ndistapi.sys
    15:37:02.0579 2156 NdisTapi - ok
    15:37:02.0688 2156 Ndisuio (b30ae7f2b6d7e343b0df32e6c08fce75) C:\windows\system32\DRIVERS\ndisuio.sys
    15:37:02.0688 2156 Ndisuio - ok
    15:37:02.0766 2156 NdisWan (267c415eadcbe53c9ca873dee39cf3a4) C:\windows\system32\DRIVERS\ndiswan.sys
    15:37:02.0766 2156 NdisWan - ok
    15:37:02.0860 2156 NDProxy (af7e7c63dcef3f8772726f86039d6eb4) C:\windows\system32\drivers\NDProxy.sys
    15:37:02.0860 2156 NDProxy - ok
    15:37:02.0969 2156 NetBIOS (80b275b1ce3b0e79909db7b39af74d51) C:\windows\system32\DRIVERS\netbios.sys
    15:37:02.0969 2156 NetBIOS - ok
    15:37:03.0078 2156 NetBT (dd52a733bf4ca5af84562a5e2f963b91) C:\windows\system32\DRIVERS\netbt.sys
    15:37:03.0078 2156 NetBT - ok
    15:37:03.0203 2156 nfrd960 (1d85c4b390b0ee09c7a46b91efb2c097) C:\windows\system32\DRIVERS\nfrd960.sys
    15:37:03.0203 2156 nfrd960 - ok
    15:37:03.0343 2156 Npfs (1db262a9f8c087e8153d89bef3d2235f) C:\windows\system32\drivers\Npfs.sys
    15:37:03.0343 2156 Npfs - ok
    15:37:03.0374 2156 nsiproxy (e9a0a4d07e53d8fea2bb8387a3293c58) C:\windows\system32\drivers\nsiproxy.sys
    15:37:03.0374 2156 nsiproxy - ok
    15:37:03.0515 2156 Ntfs (187002ce05693c306f43c873f821381f) C:\windows\system32\drivers\Ntfs.sys
    15:37:03.0530 2156 Ntfs - ok
    15:37:03.0608 2156 Null (f9756a98d69098dca8945d62858a812c) C:\windows\system32\drivers\Null.sys
    15:37:03.0624 2156 Null - ok
    15:37:03.0733 2156 nvraid (f1b0bed906f97e16f6d0c3629d2f21c6) C:\windows\system32\drivers\nvraid.sys
    15:37:03.0733 2156 nvraid - ok
    15:37:03.0858 2156 nvstor (4520b63899e867f354ee012d34e11536) C:\windows\system32\drivers\nvstor.sys
    15:37:03.0858 2156 nvstor - ok
    15:37:03.0952 2156 nv_agp (5a0983915f02bae73267cc2a041f717d) C:\windows\system32\DRIVERS\nv_agp.sys
    15:37:03.0952 2156 nv_agp - ok
    15:37:04.0061 2156 ohci1394 (08a70a1f2cdde9bb49b885cb817a66eb) C:\windows\system32\DRIVERS\ohci1394.sys
    15:37:04.0061 2156 ohci1394 - ok
    15:37:04.0186 2156 Parport (2ea877ed5dd9713c5ac74e8ea7348d14) C:\windows\system32\DRIVERS\parport.sys
    15:37:04.0201 2156 Parport - ok
    15:37:04.0279 2156 partmgr (ff4218952b51de44fe910953a3e686b9) C:\windows\system32\drivers\partmgr.sys
    15:37:04.0279 2156 partmgr - ok
    15:37:04.0373 2156 Parvdm (eb0a59f29c19b86479d36b35983daadc) C:\windows\system32\DRIVERS\parvdm.sys
    15:37:04.0373 2156 Parvdm - ok
    15:37:04.0466 2156 pci (c858cb77c577780ecc456a892e7e7d0f) C:\windows\system32\DRIVERS\pci.sys
    15:37:04.0466 2156 pci - ok
    15:37:04.0591 2156 pciide (afe86f419014db4e5593f69ffe26ce0a) C:\windows\system32\DRIVERS\pciide.sys
    15:37:04.0591 2156 pciide - ok
    15:37:04.0654 2156 pcmcia (f396431b31693e71e8a80687ef523506) C:\windows\system32\DRIVERS\pcmcia.sys
    15:37:04.0654 2156 pcmcia - ok
    15:37:04.0747 2156 pcw (250f6b43d2b613172035c6747aeeb19f) C:\windows\system32\drivers\pcw.sys
    15:37:04.0747 2156 pcw - ok
    15:37:04.0841 2156 PEAUTH (9e0104ba49f4e6973749a02bf41344ed) C:\windows\system32\drivers\peauth.sys
    15:37:04.0841 2156 PEAUTH - ok
    15:37:05.0012 2156 PptpMiniport (631e3e205ad6d86f2aed6a4a8e69f2db) C:\windows\system32\DRIVERS\raspptp.sys
    15:37:05.0012 2156 PptpMiniport - ok
    15:37:05.0090 2156 Processor (85b1e3a0c7585bc4aae6899ec6fcf011) C:\windows\system32\DRIVERS\processr.sys
    15:37:05.0090 2156 Processor - ok
    15:37:05.0215 2156 Psched (6270ccae2a86de6d146529fe55b3246a) C:\windows\system32\DRIVERS\pacer.sys
    15:37:05.0215 2156 Psched - ok
    15:37:05.0340 2156 ql2300 (ab95ecf1f6659a60ddc166d8315b0751) C:\windows\system32\DRIVERS\ql2300.sys
    15:37:05.0356 2156 ql2300 - ok
    15:37:05.0449 2156 ql40xx (b4dd51dd25182244b86737dc51af2270) C:\windows\system32\DRIVERS\ql40xx.sys
    15:37:05.0449 2156 ql40xx - ok
    15:37:05.0543 2156 QWAVEdrv (584078ca1b95ca72df2a27c336f9719d) C:\windows\system32\drivers\qwavedrv.sys
    15:37:05.0543 2156 QWAVEdrv - ok
    15:37:05.0636 2156 RasAcd (30a81b53c766d0133bb86d234e5556ab) C:\windows\system32\DRIVERS\rasacd.sys
    15:37:05.0636 2156 RasAcd - ok
    15:37:05.0730 2156 RasAgileVpn (57ec4aef73660166074d8f7f31c0d4fd) C:\windows\system32\DRIVERS\AgileVpn.sys
    15:37:05.0730 2156 RasAgileVpn - ok
    15:37:05.0839 2156 Rasl2tp (d9f91eafec2815365cbe6d167e4e332a) C:\windows\system32\DRIVERS\rasl2tp.sys
    15:37:05.0839 2156 Rasl2tp - ok
    15:37:05.0948 2156 RasPppoe (0fe8b15916307a6ac12bfb6a63e45507) C:\windows\system32\DRIVERS\raspppoe.sys
    15:37:05.0948 2156 RasPppoe - ok
    15:37:06.0042 2156 RasSstp (44101f495a83ea6401d886e7fd70096b) C:\windows\system32\DRIVERS\rassstp.sys
    15:37:06.0042 2156 RasSstp - ok
    15:37:06.0136 2156 rdbss (835d7e81bf517a3b72384bdcc85e1ce6) C:\windows\system32\DRIVERS\rdbss.sys
    15:37:06.0136 2156 rdbss - ok
    15:37:06.0214 2156 rdpbus (0d8f05481cb76e70e1da06ee9f0da9df) C:\windows\system32\DRIVERS\rdpbus.sys
    15:37:06.0214 2156 rdpbus - ok
    15:37:06.0292 2156 RDPCDD (1e016846895b15a99f9a176a05029075) C:\windows\system32\DRIVERS\RDPCDD.sys
    15:37:06.0292 2156 RDPCDD - ok
    15:37:06.0401 2156 RDPENCDD (5a53ca1598dd4156d44196d200c94b8a) C:\windows\system32\drivers\rdpencdd.sys
    15:37:06.0401 2156 RDPENCDD - ok
    15:37:06.0479 2156 RDPREFMP (44b0a53cd4f27d50ed461dae0c0b4e1f) C:\windows\system32\drivers\rdprefmp.sys
    15:37:06.0479 2156 RDPREFMP - ok
    15:37:06.0572 2156 RDPWD (801371ba9782282892d00aadb08ee367) C:\windows\system32\drivers\RDPWD.sys
    15:37:06.0572 2156 RDPWD - ok
    15:37:06.0666 2156 rdyboost (4ea225bf1cf05e158853f30a99ca29a7) C:\windows\system32\drivers\rdyboost.sys
    15:37:06.0666 2156 rdyboost - ok
    15:37:06.0775 2156 RFCOMM (cb928d9e6daf51879dd6ba8d02f01321) C:\windows\system32\DRIVERS\rfcomm.sys
    15:37:06.0775 2156 RFCOMM - ok
    15:37:06.0900 2156 rspndr (032b0d36ad92b582d869879f5af5b928) C:\windows\system32\DRIVERS\rspndr.sys
    15:37:06.0900 2156 rspndr - ok
    15:37:07.0009 2156 RTL8167 (7dfd48e24479b68b258d8770121155a0) C:\windows\system32\DRIVERS\Rt86win7.sys
    15:37:07.0009 2156 RTL8167 - ok
    15:37:07.0134 2156 SABI (6e5fbb7cbaec47038b945d5e9b144a64) C:\windows\system32\Drivers\SABI.sys
    15:37:07.0134 2156 SABI - ok
    15:37:07.0243 2156 sbp2port (34ee0c44b724e3e4ce2eff29126de5b5) C:\windows\system32\DRIVERS\sbp2port.sys
    15:37:07.0243 2156 sbp2port - ok
    15:37:07.0337 2156 scfilter (a95c54b2ac3cc9c73fcdf9e51a1d6b51) C:\windows\system32\DRIVERS\scfilter.sys
    15:37:07.0337 2156 scfilter - ok
    15:37:07.0446 2156 secdrv (90a3935d05b494a5a39d37e71f09a677) C:\windows\system32\drivers\secdrv.sys
    15:37:07.0446 2156 secdrv - ok
    15:37:07.0586 2156 Serenum (9ad8b8b515e3df6acd4212ef465de2d1) C:\windows\system32\DRIVERS\serenum.sys
    15:37:07.0586 2156 Serenum - ok
    15:37:07.0680 2156 Serial (5fb7fcea0490d821f26f39cc5ea3d1e2) C:\windows\system32\DRIVERS\serial.sys
    15:37:07.0680 2156 Serial - ok
    15:37:07.0774 2156 sermouse (79bffb520327ff916a582dfea17aa813) C:\windows\system32\DRIVERS\sermouse.sys
    15:37:07.0774 2156 sermouse - ok
    15:37:07.0883 2156 sffdisk (9f976e1eb233df46fce808d9dea3eb9c) C:\windows\system32\DRIVERS\sffdisk.sys
    15:37:07.0883 2156 sffdisk - ok
    15:37:07.0898 2156 sffp_mmc (932a68ee27833cfd57c1639d375f2731) C:\windows\system32\DRIVERS\sffp_mmc.sys
    15:37:07.0898 2156 sffp_mmc - ok
    15:37:07.0930 2156 sffp_sd (4f1e5b0fe7c8050668dbfade8999aefb) C:\windows\system32\DRIVERS\sffp_sd.sys
    15:37:07.0930 2156 sffp_sd - ok
    15:37:08.0023 2156 sfloppy (db96666cc8312ebc45032f30b007a547) C:\windows\system32\DRIVERS\sfloppy.sys
    15:37:08.0023 2156 sfloppy - ok
    15:37:08.0132 2156 sisagp (2565cac0dc9fe0371bdce60832582b2e) C:\windows\system32\DRIVERS\sisagp.sys
    15:37:08.0132 2156 sisagp - ok
    15:37:08.0242 2156 SiSRaid2 (a9f0486851becb6dda1d89d381e71055) C:\windows\system32\DRIVERS\SiSRaid2.sys
    15:37:08.0242 2156 SiSRaid2 - ok
    15:37:08.0335 2156 SiSRaid4 (3727097b55738e2f554972c3be5bc1aa) C:\windows\system32\DRIVERS\sisraid4.sys
    15:37:08.0335 2156 SiSRaid4 - ok
    15:37:08.0444 2156 Smb (3e21c083b8a01cb70ba1f09303010fce) C:\windows\system32\DRIVERS\smb.sys
    15:37:08.0444 2156 Smb - ok
    15:37:08.0538 2156 spldr (95cf1ae7527fb70f7816563cbc09d942) C:\windows\system32\drivers\spldr.sys
    15:37:08.0554 2156 spldr - ok
    15:37:08.0663 2156 srv (c4a027b8c0bd3fc0699f41fa5e9e0c87) C:\windows\system32\DRIVERS\srv.sys
    15:37:08.0663 2156 srv - ok
    15:37:08.0788 2156 srv2 (414bb592cad8a79649d01f9d94318fb3) C:\windows\system32\DRIVERS\srv2.sys
    15:37:08.0788 2156 srv2 - ok
    15:37:08.0897 2156 srvnet (ff207d67700aa18242aaf985d3e7d8f4) C:\windows\system32\DRIVERS\srvnet.sys
    15:37:08.0897 2156 srvnet - ok
    15:37:09.0006 2156 ssmdrv (3ad0362cf68de3ac500e981700242cca) C:\windows\system32\DRIVERS\ssmdrv.sys
    15:37:09.0006 2156 ssmdrv - ok
    15:37:09.0084 2156 stexstor (db32d325c192b801df274bfd12a7e72b) C:\windows\system32\DRIVERS\stexstor.sys
    15:37:09.0084 2156 stexstor - ok
    15:37:09.0178 2156 swenum (e58c78a848add9610a4db6d214af5224) C:\windows\system32\DRIVERS\swenum.sys
    15:37:09.0178 2156 swenum - ok
    15:37:09.0302 2156 SynTP (7a9025d8f7852b06d6d08ed536135e7e) C:\windows\system32\DRIVERS\SynTP.sys
    15:37:09.0302 2156 SynTP - ok
    15:37:09.0412 2156 tap0901 (2d6bf6c02111f9cf9faf8acfb933dd78) C:\windows\system32\DRIVERS\tap0901.sys
    15:37:09.0412 2156 tap0901 - ok
    15:37:09.0568 2156 Tcpip (c2daaeb48f3a47c410b041a0d2382ee1) C:\windows\system32\drivers\tcpip.sys
    15:37:09.0583 2156 Tcpip - ok
    15:37:09.0739 2156 TCPIP6 (c2daaeb48f3a47c410b041a0d2382ee1) C:\windows\system32\DRIVERS\tcpip.sys
    15:37:09.0755 2156 TCPIP6 - ok
    15:37:09.0848 2156 tcpipreg (e64444523add154f86567c469bc0b17f) C:\windows\system32\drivers\tcpipreg.sys
    15:37:09.0848 2156 tcpipreg - ok
    15:37:09.0926 2156 TDPIPE (1875c1490d99e70e449e3afae9fcbadf) C:\windows\system32\drivers\tdpipe.sys
    15:37:09.0926 2156 TDPIPE - ok
    15:37:10.0004 2156 TDTCP (7551e91ea999ee9a8e9c331d5a9c31f3) C:\windows\system32\drivers\tdtcp.sys
    15:37:10.0004 2156 TDTCP - ok
    15:37:10.0082 2156 tdx (cb39e896a2a83702d1737bfd402b3542) C:\windows\system32\DRIVERS\tdx.sys
    15:37:10.0082 2156 tdx - ok
    15:37:10.0192 2156 TermDD (c36f41ee20e6999dbf4b0425963268a5) C:\windows\system32\DRIVERS\termdd.sys
    15:37:10.0192 2156 TermDD - ok
    15:37:10.0301 2156 tssecsrv (98ae6fa07d12cb4ec5cf4a9bfa5f4242) C:\windows\system32\DRIVERS\tssecsrv.sys
    15:37:10.0301 2156 tssecsrv - ok
    15:37:10.0426 2156 tunnel (3e461d890a97f9d4c168f5fda36e1d00) C:\windows\system32\DRIVERS\tunnel.sys
    15:37:10.0426 2156 tunnel - ok
    15:37:10.0504 2156 uagp35 (750fbcb269f4d7dd2e420c56b795db6d) C:\windows\system32\DRIVERS\uagp35.sys
    15:37:10.0519 2156 uagp35 - ok
    15:37:10.0597 2156 udfs (09cc3e16f8e5ee7168e01cf8fcbe061a) C:\windows\system32\DRIVERS\udfs.sys
    15:37:10.0597 2156 udfs - ok
    15:37:10.0691 2156 uliagpkx (44e8048ace47befbfdc2e9be4cbc8880) C:\windows\system32\DRIVERS\uliagpkx.sys
    15:37:10.0691 2156 uliagpkx - ok
    15:37:10.0816 2156 umbus (049b3a50b3d646baeeee9eec9b0668dc) C:\windows\system32\DRIVERS\umbus.sys
    15:37:10.0816 2156 umbus - ok
    15:37:10.0894 2156 UmPass (7550ad0c6998ba1cb4843e920ee0feac) C:\windows\system32\DRIVERS\umpass.sys
    15:37:10.0894 2156 UmPass - ok
    15:37:11.0018 2156 USBAAPL (e8c1b9ebac65288e1b51e8a987d98af6) C:\windows\system32\Drivers\usbaapl.sys
    15:37:11.0018 2156 USBAAPL - ok
    15:37:11.0128 2156 usbaudio (2436a42aab4ad48a9b714e5b0f344627) C:\windows\system32\drivers\usbaudio.sys
    15:37:11.0128 2156 usbaudio - ok
    15:37:11.0237 2156 usbccgp (c31ae588e403042632dc796cf09e30b0) C:\windows\system32\DRIVERS\usbccgp.sys
    15:37:11.0237 2156 usbccgp - ok
    15:37:11.0346 2156 usbcir (04ec7cec62ec3b6d9354eee93327fc82) C:\windows\system32\DRIVERS\usbcir.sys
    15:37:11.0346 2156 usbcir - ok
    15:37:11.0455 2156 usbehci (e4c436d914768ce965d5e659ba7eebd8) C:\windows\system32\DRIVERS\usbehci.sys
    15:37:11.0455 2156 usbehci - ok
    15:37:11.0564 2156 usbhub (bdcd7156ec37448f08633fd899823620) C:\windows\system32\DRIVERS\usbhub.sys
    15:37:11.0580 2156 usbhub - ok
    15:37:11.0596 2156 usbohci (eb2d819a639015253c871cda09d91d58) C:\windows\system32\drivers\usbohci.sys
    15:37:11.0596 2156 usbohci - ok
    15:37:11.0705 2156 usbprint (797d862fe0875e75c7cc4c1ad7b30252) C:\windows\system32\DRIVERS\usbprint.sys
    15:37:11.0705 2156 usbprint - ok
    15:37:11.0798 2156 USBSTOR (1c4287739a93594e57e2a9e6a3ed7353) C:\windows\system32\DRIVERS\USBSTOR.SYS
    15:37:11.0798 2156 USBSTOR - ok
    15:37:11.0908 2156 usbuhci (22480bf4e5a09192e5e30ba4dde79fa4) C:\windows\system32\DRIVERS\usbuhci.sys
    15:37:11.0908 2156 usbuhci - ok
    15:37:12.0001 2156 usbvideo (b5f6a992d996282b7fae7048e50af83a) C:\windows\System32\Drivers\usbvideo.sys
    15:37:12.0001 2156 usbvideo - ok
    15:37:12.0126 2156 vdrvroot (a059c4c3edb09e07d21a8e5c0aabd3cb) C:\windows\system32\DRIVERS\vdrvroot.sys
    15:37:12.0126 2156 vdrvroot - ok
    15:37:12.0220 2156 vga (17c408214ea61696cec9c66e388b14f3) C:\windows\system32\DRIVERS\vgapnp.sys
    15:37:12.0220 2156 vga - ok
    15:37:12.0329 2156 VgaSave (8e38096ad5c8570a6f1570a61e251561) C:\windows\System32\drivers\vga.sys
    15:37:12.0329 2156 VgaSave - ok
    15:37:12.0438 2156 vhdmp (3be6e1f3a4f1afec8cee0d7883f93583) C:\windows\system32\DRIVERS\vhdmp.sys
    15:37:12.0438 2156 vhdmp - ok
    15:37:12.0547 2156 viaagp (c829317a37b4bea8f39735d4b076e923) C:\windows\system32\DRIVERS\viaagp.sys
    15:37:12.0547 2156 viaagp - ok
    15:37:12.0641 2156 ViaC7 (e02f079a6aa107f06b16549c6e5c7b74) C:\windows\system32\DRIVERS\viac7.sys
    15:37:12.0641 2156 ViaC7 - ok
    15:37:12.0750 2156 viaide (e43574f6a56a0ee11809b48c09e4fd3c) C:\windows\system32\DRIVERS\viaide.sys
    15:37:12.0750 2156 viaide - ok
    15:37:12.0844 2156 VMC326 (88c52f322117f60b7a0c89d683e30f6a) C:\windows\system32\Drivers\VMC326.sys
    15:37:12.0844 2156 VMC326 - ok
    15:37:12.0937 2156 volmgr (384e5a2aa49934295171e499f86ba6f3) C:\windows\system32\DRIVERS\volmgr.sys
    15:37:12.0937 2156 volmgr - ok
    15:37:13.0031 2156 volmgrx (b5bb72067ddddbbfb04b2f89ff8c3c87) C:\windows\system32\drivers\volmgrx.sys
    15:37:13.0046 2156 volmgrx - ok
    15:37:13.0171 2156 volsnap (58df9d2481a56edde167e51b334d44fd) C:\windows\system32\DRIVERS\volsnap.sys
    15:37:13.0171 2156 volsnap - ok
    15:37:13.0265 2156 vsmraid (9dfa0cc2f8855a04816729651175b631) C:\windows\system32\DRIVERS\vsmraid.sys
    15:37:13.0280 2156 vsmraid - ok
    15:37:13.0392 2156 vwifibus (90567b1e658001e79d7c8bbd3dde5aa6) C:\windows\system32\DRIVERS\vwifibus.sys
    15:37:13.0392 2156 vwifibus - ok
    15:37:13.0492 2156 vwififlt (7090d3436eeb4e7da3373090a23448f7) C:\windows\system32\DRIVERS\vwififlt.sys
    15:37:13.0492 2156 vwififlt - ok
    15:37:13.0582 2156 WacomPen (de3721e89c653aa281428c8a69745d90) C:\windows\system32\DRIVERS\wacompen.sys
    15:37:13.0592 2156 WacomPen - ok
    15:37:13.0692 2156 WANARP (692a712062146e96d28ba0b7d75de31b) C:\windows\system32\DRIVERS\wanarp.sys
    15:37:13.0692 2156 WANARP - ok
    15:37:13.0702 2156 Wanarpv6 (692a712062146e96d28ba0b7d75de31b) C:\windows\system32\DRIVERS\wanarp.sys
    15:37:13.0702 2156 Wanarpv6 - ok
    15:37:13.0802 2156 wanatw (0a716c08cb13c3a8f4f51e882dbf7416) C:\windows\system32\DRIVERS\wanatw4.sys
    15:37:13.0802 2156 wanatw - ok
    15:37:13.0922 2156 Wd (1112a9badacb47b7c0bb0392e3158dff) C:\windows\system32\DRIVERS\wd.sys
    15:37:13.0922 2156 Wd - ok
    15:37:14.0032 2156 Wdf01000 (9950e3d0f08141c7e89e64456ae7dc73) C:\windows\system32\drivers\Wdf01000.sys
    15:37:14.0032 2156 Wdf01000 - ok
    15:37:14.0142 2156 WfpLwf (8b9a943f3b53861f2bfaf6c186168f79) C:\windows\system32\DRIVERS\wfplwf.sys
    15:37:14.0152 2156 WfpLwf - ok
    15:37:14.0242 2156 WIMMount (5cf95b35e59e2a38023836fff31be64c) C:\windows\system32\drivers\wimmount.sys
    15:37:14.0242 2156 WIMMount - ok
    15:37:14.0422 2156 WinUsb (30fc6e5448d0cbaaa95280eeef7fedae) C:\windows\system32\DRIVERS\WinUsb.sys
    15:37:14.0422 2156 WinUsb - ok
    15:37:14.0582 2156 WmiAcpi (0217679b8fca58714c3bf2726d2ca84e) C:\windows\system32\DRIVERS\wmiacpi.sys
    15:37:14.0582 2156 WmiAcpi - ok
    15:37:14.0712 2156 ws2ifsl (6db3276587b853bf886b69528fdb048c) C:\windows\system32\drivers\ws2ifsl.sys
    15:37:14.0712 2156 ws2ifsl - ok
    15:37:14.0822 2156 WudfPf (6f9b6c0c93232cff47d0f72d6db1d21e) C:\windows\system32\drivers\WudfPf.sys
    15:37:14.0822 2156 WudfPf - ok
    15:37:14.0912 2156 WUDFRd (f91ff1e51fca30b3c3981db7d5924252) C:\windows\system32\DRIVERS\WUDFRd.sys
    15:37:14.0912 2156 WUDFRd - ok
    15:37:15.0042 2156 yukonw7 (3eb1576f77b60a6c79dd7742b67219b8) C:\windows\system32\DRIVERS\yk62x86.sys
    15:37:15.0052 2156 yukonw7 - ok
    15:37:15.0102 2156 MBR (0x1B8) (2e5debb2116b3417023e0d6562d7ed07) \Device\Harddisk0\DR0
    15:37:15.0465 2156 \Device\Harddisk0\DR0 - ok
    15:37:15.0465 2156 Boot (0x1200) (620d63c6c70847cf6c08d4e280e7d476) \Device\Harddisk0\DR0\Partition0
    15:37:15.0481 2156 \Device\Harddisk0\DR0\Partition0 - ok
    15:37:15.0481 2156 Boot (0x1200) (93b8b723d3667bfa15dabe3a6fff28ff) \Device\Harddisk0\DR0\Partition1
    15:37:15.0481 2156 \Device\Harddisk0\DR0\Partition1 - ok
    15:37:15.0512 2156 Boot (0x1200) (3fc5efa4c5dde95fda309e6c1f5c5340) \Device\Harddisk0\DR0\Partition2
    15:37:15.0512 2156 \Device\Harddisk0\DR0\Partition2 - ok
    15:37:15.0528 2156 ============================================================
    15:37:15.0528 2156 Scan finished
    15:37:15.0528 2156 ============================================================
    15:37:15.0543 1652 Detected object count: 0
    15:37:15.0543 1652 Actual detected object count: 0
    15:37:34.0858 4244 Deinitialize success
    0
  11. juju666 Messages postés 35446 Date d'inscription   Statut Contributeur sécurité Dernière intervention   4 796
     
    Nous allons effectuer un diagnostic de ton PC:

    Télécharge ZHPDiag

    ▶ Laisse toi guider lors de l'installation,coche "Ajouter une icône sur le bureau" et "Exécuter ZHPDiag"

    ▶ Clique sur l'icône représentant un tournevis vert et coche tout, puis sur l'icone représentant une loupe (« Lancer le diagnostic »)

    ▶ Une fois le scan aux 100%, ferme ZHPDiag. Héberge le rapport ZHPDiag.txt présent sur ton bureau.

    Voici comment procéder

    ▶ Rends toi sur pjjoint.malekal.com
    ▶ Clique sur le bouton Parcourir
    ▶ Sélectionne le fichier que tu veux héberger et clique sur Ouvrir
    ▶ Clique sur le bouton Envoyer
    ▶ Un message de confirmation s'affiche (L'upload a réussi ! - Le lien à transmettre à vos correspondant pour visualiser le fichier est : https://pjjoint.malekal.com/files.php?id=df5ea299241015

    ▶ Copie le lien dans ta prochaine réponse.

    A bientôt.
    0
  12. lucie
     
    Voila le lien:
    merci:

    http://pjjoint.malekal.com/files.php?id=ZHPDiag_e7n10j811v9b7b15f14m6w15g11x13l11n6w13j12b138m9o5
    0
  13. juju666 Messages postés 35446 Date d'inscription   Statut Contributeur sécurité Dernière intervention   4 796
     
    c'est normal qu'il y a ait un proxy qui pointe vers les states ?
    0
  14. lucie
     
    un proxy?
    j'ai récupéré l'ordinateur de mon frère donc je ne sais pas trop..
    désolée
    0
  15. juju666 Messages postés 35446 Date d'inscription   Statut Contributeur sécurité Dernière intervention   4 796
     
    dans ce cas on le vire !


    désactive ton antivirus
    désactive Windows defender si présent
    désactive ton pare-feu


    Télécharge Pre_scan (de gen-hackman)

    Si le lien ne fonctionne pas, utilise celui-ci

    ♦ Enregistre le sur ton bureau
    s'il n'est pas sur ton bureau, coupe-le de ton dossier téléchargements et colle-le sur ton bureau

    ▶ Exécute Pre_scan.
    Avertissement: Il y aura une courte extinction du bureau pendant que l'outil travaillera --> pas de panique.
    Si l'outil est bloqué, utilise cette version
    Si l'outil détecte un proxy clique sur "supprimer le proxy"

    ▶ Une fois qu'il aura fini, un rapport s'ouvrira.

    ♦ NE LE POSTE PAS SUR LE FORUM (il est trop long)

    clique sur ce lien : http://www.cijoint.fr/

    ▶ Clique sur Parcourir et cherche le fichier Pre_Scan.txt qui se trouve sur ton bureau (une copie est aussi à la racine : C:\Pre_Scan.txt)

    ▶ Clique sur Ouvrir.

    ▶ Clique sur "Cliquez ici pour déposer le fichier".

    Un lien de cette forme :

    http://www.cijoint.fr/cjlink.php?file=cjge368/cijSKAP5fU.txt

    est ajouté dans la page.

    ▶ Copie ce lien dans ta réponse.
    0