Virus arret de firefox à répétition

Bonjour,
je pense qu'il est possible que mon ordinateur soit infecté par un virus. J'ai quelques soucis avec Firefox qui cesse de fonctionner très régulièrement et a répétition. Alors peut être que ce n'est pas un virus qui est la cause de ce problème mais peut être que mon ordinateur est infecté quand même.
De plus j'aimerais avoir des avis sur mon anti-virus qui est bit difender et je voudrais savoir quel logiciel utiliser pour le compléter afin d'avoir un bonne protection.
merci

19 réponses

  1. Contributeur sécurité
    Bonjour

    Nous allons effectuer un diagnostic de ton PC:

    ▶ Télécharge ZHPDiag

    ▶ Laisse toi guider lors de l'installation,coche "Ajouter une icône sur le bureau" et "Exécuter ZHPDiag"

    ▶ Clique sur l'icône représentant un tournevis vert et coche tout, puis sur l'icone représentant une loupe (« Lancer le diagnostic »)

    ▶ Une fois le scan aux 100%, ferme ZHPDiag. Héberge le rapport ZHPDiag.txt présent sur ton bureau.

    Voici comment procéder

    ▶ Rends toi sur pjjoint.malekal.com
    ▶ Clique sur le bouton Parcourir
    ▶ Sélectionne le fichier que tu veux héberger et clique sur Ouvrir
    ▶ Clique sur le bouton Envoyer
    ▶ Un message de confirmation s'affiche (L'upload a réussi ! - Le lien à transmettre à vos correspondant pour visualiser le fichier est : https://pjjoint.malekal.com/files.php?id=df5ea299241015

    ▶ Copie le lien dans ta prochaine réponse.

    A bientôt.
    0
    1. Contributeur sécurité
      Ok il y a un rootkit TDSS.TDL4

      ▶ Télécharge Reload_TDSSKiller

      ▶ Lance le

      choisis : lancer le nettoyage

      l'outil va automatiquement télécharger la derniere version puis

      TDSSKiller va s'ouvrir , clique sur "Start Scan" Clique ici pour l'aide en image

      Si TDSS.tdl2 est détecté: l'option delete sera cochée par défaut.
      Si TDSS.tdl3 est détecté: assure toi que Cure est bien cochée.
      Si TDSS.tdl4(\HardDisk0\MBR) est détecté: assure toi que Cure est bien cochée.
      Si Rootkit.Win32.ZAccess.* est détecté : règle sur "cure" en haut , et "delete" en bas
      Si Suspicious file est indiqué, laisse l''option cochée sur Skip
      une fois qu'il a terminé , redémarre s'il te le demande pour finir de nettoyer

      sinon , ferme TDSSKiller et le rapport s'affichera sur le bureau

      ▶ Copie/Colle son contenu dans ta prochaine réponse.
      0
      1. voila le rapport :

        2011/07/02 22:54:14.0079 4064 TDSS rootkit removing tool 2.5.8.0 Jun 28 2011 19:12:16
        2011/07/02 22:54:16.0081 4064 ================================================================================
        2011/07/02 22:54:16.0081 4064 SystemInfo:
        2011/07/02 22:54:16.0081 4064
        2011/07/02 22:54:16.0082 4064 OS Version: 6.1.7600 ServicePack: 0.0
        2011/07/02 22:54:16.0082 4064 Product type: Workstation
        2011/07/02 22:54:16.0082 4064 ComputerName: PC-DE-MARIE
        2011/07/02 22:54:16.0082 4064 UserName: melvynou
        2011/07/02 22:54:16.0082 4064 Windows directory: C:\Windows
        2011/07/02 22:54:16.0082 4064 System windows directory: C:\Windows
        2011/07/02 22:54:16.0082 4064 Processor architecture: Intel x86
        2011/07/02 22:54:16.0082 4064 Number of processors: 2
        2011/07/02 22:54:16.0082 4064 Page size: 0x1000
        2011/07/02 22:54:16.0082 4064 Boot type: Normal boot
        2011/07/02 22:54:16.0082 4064 ================================================================================
        2011/07/02 22:54:22.0854 4064 Initialize success
        2011/07/02 22:55:20.0996 5684 ================================================================================
        2011/07/02 22:55:20.0996 5684 Scan started
        2011/07/02 22:55:20.0996 5684 Mode: Manual;
        2011/07/02 22:55:20.0996 5684 ================================================================================
        2011/07/02 22:55:23.0814 5684 1394ohci (6d2aca41739bfe8cb86ee8e85f29697d) C:\Windows\system32\DRIVERS\1394ohci.sys
        2011/07/02 22:55:23.0858 5684 ACPI (f0e07d144c8685b8774bc32fc8da4df0) C:\Windows\system32\DRIVERS\ACPI.sys
        2011/07/02 22:55:23.0899 5684 AcpiPmi (98d81ca942d19f7d9153b095162ac013) C:\Windows\system32\DRIVERS\acpipmi.sys
        2011/07/02 22:55:24.0050 5684 adp94xx (21e785ebd7dc90a06391141aac7892fb) C:\Windows\system32\DRIVERS\adp94xx.sys
        2011/07/02 22:55:24.0083 5684 adpahci (0c676bc278d5b59ff5abd57bbe9123f2) C:\Windows\system32\DRIVERS\adpahci.sys
        2011/07/02 22:55:24.0113 5684 adpu320 (7c7b5ee4b7b822ec85321fe23a27db33) C:\Windows\system32\DRIVERS\adpu320.sys
        2011/07/02 22:55:24.0198 5684 AFD (0db7a48388d54d154ebec120461a0fcd) C:\Windows\system32\drivers\afd.sys
        2011/07/02 22:55:24.0222 5684 agp440 (507812c3054c21cef746b6ee3d04dd6e) C:\Windows\system32\DRIVERS\agp440.sys
        2011/07/02 22:55:24.0299 5684 aic78xx (8b30250d573a8f6b4bd23195160d8707) C:\Windows\system32\DRIVERS\djsvs.sys
        2011/07/02 22:55:24.0367 5684 aliide (0d40bcf52ea90fc7df2aeab6503dea44) C:\Windows\system32\DRIVERS\aliide.sys
        2011/07/02 22:55:24.0419 5684 amdagp (3c6600a0696e90a463771c7422e23ab5) C:\Windows\system32\DRIVERS\amdagp.sys
        2011/07/02 22:55:24.0444 5684 amdide (cd5914170297126b6266860198d1d4f0) C:\Windows\system32\DRIVERS\amdide.sys
        2011/07/02 22:55:24.0472 5684 AmdK8 (00dda200d71bac534bf56a9db5dfd666) C:\Windows\system32\DRIVERS\amdk8.sys
        2011/07/02 22:55:24.0541 5684 AmdPPM (3cbf30f5370fda40dd3e87df38ea53b6) C:\Windows\system32\DRIVERS\amdppm.sys
        2011/07/02 22:55:24.0596 5684 amdsata (19ce906b4cdc11fc4fef5745f33a63b6) C:\Windows\system32\drivers\amdsata.sys
        2011/07/02 22:55:24.0625 5684 amdsbs (ea43af0c423ff267355f74e7a53bdaba) C:\Windows\system32\DRIVERS\amdsbs.sys
        2011/07/02 22:55:24.0654 5684 amdxata (869e67d66be326a5a9159fba8746fa70) C:\Windows\system32\drivers\amdxata.sys
        2011/07/02 22:55:24.0696 5684 AppID (feb834c02ce1e84b6a38f953ca067706) C:\Windows\system32\drivers\appid.sys
        2011/07/02 22:55:24.0776 5684 arc (2932004f49677bd84dbc72edb754ffb3) C:\Windows\system32\DRIVERS\arc.sys
        2011/07/02 22:55:24.0806 5684 arcsas (5d6f36c46fd283ae1b57bd2e9feb0bc7) C:\Windows\system32\DRIVERS\arcsas.sys
        2011/07/02 22:55:24.0864 5684 AsyncMac (add2ade1c2b285ab8378d2daaf991481) C:\Windows\system32\DRIVERS\asyncmac.sys
        2011/07/02 22:55:24.0916 5684 atapi (338c86357871c167a96ab976519bf59e) C:\Windows\system32\DRIVERS\atapi.sys
        2011/07/02 22:55:25.0006 5684 b06bdrv (1a231abec60fd316ec54c66715543cec) C:\Windows\system32\DRIVERS\bxvbdx.sys
        2011/07/02 22:55:25.0060 5684 b57nd60x (bd8869eb9cde6bbe4508d869929869ee) C:\Windows\system32\DRIVERS\b57nd60x.sys
        2011/07/02 22:55:25.0151 5684 BDFM (67c2a47db7190673350a3f9f5a1507cb) C:\Windows\system32\DRIVERS\bdfm.sys
        2011/07/02 22:55:25.0193 5684 BdfNdisf (2e82edc5e70163b2f72f7011e251ea63) C:\Windows\system32\DRIVERS\BdfNdisf6.sys
        2011/07/02 22:55:25.0268 5684 bdfsfltr (a21a4a0e6bdf0c2be0fabfa16d8c8f76) C:\Windows\system32\DRIVERS\bdfsfltr.sys
        2011/07/02 22:55:25.0396 5684 bdfwfpf (896ac9c2a81696861404a87575444b87) C:\Program Files\Common Files\BitDefender\BitDefender Firewall\bdfwfpf.sys
        2011/07/02 22:55:25.0452 5684 BDVEDISK (375cd0b9f433465ec6f50d4df44e9448) C:\Program Files\BitDefender\BitDefender 2010\bdvedisk.sys
        2011/07/02 22:55:25.0629 5684 Beep (505506526a9d467307b3c393dedaf858) C:\Windows\system32\drivers\Beep.sys
        2011/07/02 22:55:25.0687 5684 blbdrive (2287078ed48fcfc477b05b20cf38f36f) C:\Windows\system32\DRIVERS\blbdrive.sys
        2011/07/02 22:55:25.0782 5684 bowser (9a5c671b7fbae4865149bb11f59b91b2) C:\Windows\system32\DRIVERS\bowser.sys
        2011/07/02 22:55:25.0840 5684 BrFiltLo (9f9acc7f7ccde8a15c282d3f88b43309) C:\Windows\system32\DRIVERS\BrFiltLo.sys
        2011/07/02 22:55:25.0862 5684 BrFiltUp (56801ad62213a41f6497f96dee83755a) C:\Windows\system32\DRIVERS\BrFiltUp.sys
        2011/07/02 22:55:25.0901 5684 Brserid (845b8ce732e67f3b4133164868c666ea) C:\Windows\System32\Drivers\Brserid.sys
        2011/07/02 22:55:25.0928 5684 BrSerWdm (203f0b1e73adadbbb7b7b1fabd901f6b) C:\Windows\System32\Drivers\BrSerWdm.sys
        2011/07/02 22:55:25.0957 5684 BrUsbMdm (bd456606156ba17e60a04e18016ae54b) C:\Windows\System32\Drivers\BrUsbMdm.sys
        2011/07/02 22:55:25.0982 5684 BrUsbSer (af72ed54503f717a43268b3cc5faec2e) C:\Windows\System32\Drivers\BrUsbSer.sys
        2011/07/02 22:55:26.0018 5684 BTHMODEM (ed3df7c56ce0084eb2034432fc56565a) C:\Windows\system32\DRIVERS\bthmodem.sys
        2011/07/02 22:55:26.0086 5684 cdfs (77ea11b065e0a8ab902d78145ca51e10) C:\Windows\system32\DRIVERS\cdfs.sys
        2011/07/02 22:55:26.0128 5684 cdrom (ba6e70aa0e6091bc39de29477d866a77) C:\Windows\system32\DRIVERS\cdrom.sys
        2011/07/02 22:55:26.0157 5684 circlass (3fe3fe94a34df6fb06e6418d0f6a0060) C:\Windows\system32\DRIVERS\circlass.sys
        2011/07/02 22:55:26.0214 5684 CLFS (635181e0e9bbf16871bf5380d71db02d) C:\Windows\system32\CLFS.sys
        2011/07/02 22:55:26.0264 5684 CmBatt (dea805815e587dad1dd2c502220b5616) C:\Windows\system32\DRIVERS\CmBatt.sys
        2011/07/02 22:55:26.0284 5684 cmdide (c537b1db64d495b9b4717b4d6d9edbf2) C:\Windows\system32\DRIVERS\cmdide.sys
        2011/07/02 22:55:26.0315 5684 CNG (1b675691ed940766149c93e8f4488d68) C:\Windows\system32\Drivers\cng.sys
        2011/07/02 22:55:26.0347 5684 Compbatt (a6023d3823c37043986713f118a89bee) C:\Windows\system32\DRIVERS\compbatt.sys
        2011/07/02 22:55:26.0386 5684 CompositeBus (f1724ba27e97d627f808fb0ba77a28a6) C:\Windows\system32\DRIVERS\CompositeBus.sys
        2011/07/02 22:55:26.0419 5684 crcdisk (2c4ebcfc84a9b44f209dff6c6e6c61d1) C:\Windows\system32\DRIVERS\crcdisk.sys
        2011/07/02 22:55:26.0512 5684 DfsC (83d1ecea8faae75604c0fa49ac7ad996) C:\Windows\system32\Drivers\dfsc.sys
        2011/07/02 22:55:26.0551 5684 discache (1a050b0274bfb3890703d490f330c0da) C:\Windows\system32\drivers\discache.sys
        2011/07/02 22:55:26.0587 5684 Disk (565003f326f99802e68ca78f2a68e9ff) C:\Windows\system32\DRIVERS\disk.sys
        2011/07/02 22:55:26.0652 5684 Dot4 (b5e479eb83707dd698f66953e922042c) C:\Windows\system32\DRIVERS\Dot4.sys
        2011/07/02 22:55:26.0680 5684 Dot4Print (c25fea07a8e7767e8b89ab96a3b96519) C:\Windows\system32\DRIVERS\Dot4Prt.sys
        2011/07/02 22:55:26.0703 5684 dot4usb (cf491ff38d62143203c065260567e2f7) C:\Windows\system32\DRIVERS\dot4usb.sys
        2011/07/02 22:55:26.0877 5684 driverhardwarev2 (b019db2d3bc4530759abd8440e6bcd28) C:\Program Files\ma-config.com\Drivers\driverhardwarev2.sys
        2011/07/02 22:55:27.0103 5684 drmkaud (b918e7c5f9bf77202f89e1a9539f2eb4) C:\Windows\system32\drivers\drmkaud.sys
        2011/07/02 22:55:27.0166 5684 DXGKrnl (1679a4669326cb1a67cc95658d273234) C:\Windows\System32\drivers\dxgkrnl.sys
        2011/07/02 22:55:27.0283 5684 ebdrv (024e1b5cac09731e4d868e64dbfb4ab0) C:\Windows\system32\DRIVERS\evbdx.sys
        2011/07/02 22:55:27.0427 5684 elxstor (0ed67910c8c326796faa00b2bf6d9d3c) C:\Windows\system32\DRIVERS\elxstor.sys
        2011/07/02 22:55:27.0499 5684 EMSUSB2 (c3b1765e8f6dcccaa2c963e3992d6ce9) C:\Windows\system32\DRIVERS\EMSUSB2.sys
        2011/07/02 22:55:27.0560 5684 ErrDev (8fc3208352dd3912c94367a206ab3f11) C:\Windows\system32\DRIVERS\errdev.sys
        2011/07/02 22:55:27.0614 5684 exfat (2dc9108d74081149cc8b651d3a26207f) C:\Windows\system32\drivers\exfat.sys
        2011/07/02 22:55:27.0655 5684 fastfat (7e0ab74553476622fb6ae36f73d97d35) C:\Windows\system32\drivers\fastfat.sys
        2011/07/02 22:55:27.0691 5684 fdc (e817a017f82df2a1f8cfdbda29388b29) C:\Windows\system32\DRIVERS\fdc.sys
        2011/07/02 22:55:27.0767 5684 FileInfo (6cf00369c97f3cf563be99be983d13d8) C:\Windows\system32\drivers\fileinfo.sys
        2011/07/02 22:55:27.0818 5684 Filetrace (42c51dc94c91da21cb9196eb64c45db9) C:\Windows\system32\drivers\filetrace.sys
        2011/07/02 22:55:27.0887 5684 flpydisk (87907aa70cb3c56600f1c2fb8841579b) C:\Windows\system32\DRIVERS\flpydisk.sys
        2011/07/02 22:55:27.0921 5684 FltMgr (7520ec808e0c35e0ee6f841294316653) C:\Windows\system32\drivers\fltmgr.sys
        2011/07/02 22:55:27.0962 5684 FsDepends (1a16b57943853e598cff37fe2b8cbf1d) C:\Windows\system32\drivers\FsDepends.sys
        2011/07/02 22:55:28.0036 5684 fssfltr (d909075fa72c090f27aa926c32cb4612) C:\Windows\system32\DRIVERS\fssfltr.sys
        2011/07/02 22:55:28.0105 5684 FsUsbExDisk (790a4ca68f44be35967b3df61f3e4675) C:\Windows\system32\FsUsbExDisk.SYS
        2011/07/02 22:55:28.0146 5684 Fs_Rec (a574b4360e438977038aae4bf60d79a2) C:\Windows\system32\drivers\Fs_Rec.sys
        2011/07/02 22:55:28.0223 5684 fvevol (dafbd9fe39197495aed6d51f3b85b5d2) C:\Windows\system32\DRIVERS\fvevol.sys
        2011/07/02 22:55:28.0266 5684 gagp30kx (65ee0c7a58b65e74ae05637418153938) C:\Windows\system32\DRIVERS\gagp30kx.sys
        2011/07/02 22:55:28.0340 5684 GEARAspiWDM (8182ff89c65e4d38b2de4bb0fb18564e) C:\Windows\system32\DRIVERS\GEARAspiWDM.sys
        2011/07/02 22:55:28.0415 5684 hcw85cir (c44e3c2bab6837db337ddee7544736db) C:\Windows\system32\drivers\hcw85cir.sys
        2011/07/02 22:55:28.0482 5684 HDAudBus (717a2207fd6f13ad3e664c7d5a43c7bf) C:\Windows\system32\DRIVERS\HDAudBus.sys
        2011/07/02 22:55:28.0551 5684 HidBatt (1d58a7f3e11a9731d0eaaaa8405acc36) C:\Windows\system32\DRIVERS\HidBatt.sys
        2011/07/02 22:55:28.0594 5684 HidBth (89448f40e6df260c206a193a4683ba78) C:\Windows\system32\DRIVERS\hidbth.sys
        2011/07/02 22:55:28.0640 5684 HidIr (cf50b4cf4a4f229b9f3c08351f99ca5e) C:\Windows\system32\DRIVERS\hidir.sys
        2011/07/02 22:55:28.0669 5684 HidUsb (25072fb35ac90b25f9e4e3bacf774102) C:\Windows\system32\DRIVERS\hidusb.sys
        2011/07/02 22:55:28.0716 5684 HpSAMD (295fdc419039090eb8b49ffdbb374549) C:\Windows\system32\DRIVERS\HpSAMD.sys
        2011/07/02 22:55:28.0753 5684 HTTP (c531c7fd9e8b62021112787c4e2c5a5a) C:\Windows\system32\drivers\HTTP.sys
        2011/07/02 22:55:28.0820 5684 hwpolicy (8305f33cde89ad6c7a0763ed0b5a8d42) C:\Windows\system32\drivers\hwpolicy.sys
        2011/07/02 22:55:28.0845 5684 i8042prt (f151f0bdc47f4a28b1b20a0818ea36d6) C:\Windows\system32\DRIVERS\i8042prt.sys
        2011/07/02 22:55:28.0900 5684 iaStor (d483687eace0c065ee772481a96e05f5) C:\Windows\system32\DRIVERS\iaStor.sys
        2011/07/02 22:55:28.0962 5684 iaStorV (71f1a494fedf4b33c02c4a6a28d6d9e9) C:\Windows\system32\drivers\iaStorV.sys
        2011/07/02 22:55:28.0999 5684 iirsp (4173ff5708f3236cf25195fecd742915) C:\Windows\system32\DRIVERS\iirsp.sys
        2011/07/02 22:55:29.0069 5684 int15 (58ff11c95c3681c9250914521cb9f036) C:\Windows\system32\drivers\int15.sys
        2011/07/02 22:55:29.0173 5684 IntcAzAudAddService (4c01298060cf930d26a75a86b874b6ae) C:\Windows\system32\drivers\RTKVHDA.sys
        2011/07/02 22:55:29.0252 5684 intelide (a0f12f2c9ba6c72f3987ce780e77c130) C:\Windows\system32\DRIVERS\intelide.sys
        2011/07/02 22:55:29.0279 5684 intelppm (3b514d27bfc4accb4037bc6685f766e0) C:\Windows\system32\DRIVERS\intelppm.sys
        2011/07/02 22:55:29.0311 5684 IpFilterDriver (709d1761d3b19a932ff0238ea6d50200) C:\Windows\system32\DRIVERS\ipfltdrv.sys
        2011/07/02 22:55:29.0359 5684 IPMIDRV (e4454b6c37d7ffd5649611f6496308a7) C:\Windows\system32\DRIVERS\IPMIDrv.sys
        2011/07/02 22:55:29.0389 5684 IPNAT (a5fa468d67abcdaa36264e463a7bb0cd) C:\Windows\system32\drivers\ipnat.sys
        2011/07/02 22:55:29.0437 5684 IRENUM (42996cff20a3084a56017b7902307e9f) C:\Windows\system32\drivers\irenum.sys
        2011/07/02 22:55:29.0461 5684 isapnp (1f32bb6b38f62f7df1a7ab7292638a35) C:\Windows\system32\DRIVERS\isapnp.sys
        2011/07/02 22:55:29.0533 5684 iScsiPrt (ed46c223ae46c6866ab77cdc41c404b7) C:\Windows\system32\DRIVERS\msiscsi.sys
        2011/07/02 22:55:29.0572 5684 kbdclass (adef52ca1aeae82b50df86b56413107e) C:\Windows\system32\DRIVERS\kbdclass.sys
        2011/07/02 22:55:29.0610 5684 kbdhid (3d9f0ebf350edcfd6498057301455964) C:\Windows\system32\DRIVERS\kbdhid.sys
        2011/07/02 22:55:29.0672 5684 KSecDD (e36a061ec11b373826905b21be10948f) C:\Windows\system32\Drivers\ksecdd.sys
        2011/07/02 22:55:29.0744 5684 KSecPkg (365c6154bbbc5377173f1ca7bfb6cc59) C:\Windows\system32\Drivers\ksecpkg.sys
        2011/07/02 22:55:29.0858 5684 lltdio (f7611ec07349979da9b0ae1f18ccc7a6) C:\Windows\system32\DRIVERS\lltdio.sys
        2011/07/02 22:55:29.0906 5684 LSI_FC (eb119a53ccf2acc000ac71b065b78fef) C:\Windows\system32\DRIVERS\lsi_fc.sys
        2011/07/02 22:55:29.0937 5684 LSI_SAS (8ade1c877256a22e49b75d1cc9161f9c) C:\Windows\system32\DRIVERS\lsi_sas.sys
        2011/07/02 22:55:29.0962 5684 LSI_SAS2 (dc9dc3d3daa0e276fd2ec262e38b11e9) C:\Windows\system32\DRIVERS\lsi_sas2.sys
        2011/07/02 22:55:29.0991 5684 LSI_SCSI (0a036c7d7cab643a7f07135ac47e0524) C:\Windows\system32\DRIVERS\lsi_scsi.sys
        2011/07/02 22:55:30.0021 5684 luafv (6703e366cc18d3b6e534f5cf7df39cee) C:\Windows\system32\drivers\luafv.sys
        2011/07/02 22:55:30.0081 5684 MAUSBFASTTRACK (862d7bd3be3399670a7e3358ce7e6344) C:\Windows\system32\DRIVERS\MAudioFastTrack.sys
        2011/07/02 22:55:30.0138 5684 megasas (0fff5b045293002ab38eb1fd1fc2fb74) C:\Windows\system32\DRIVERS\megasas.sys
        2011/07/02 22:55:30.0188 5684 MegaSR (dcbab2920c75f390caf1d29f675d03d6) C:\Windows\system32\DRIVERS\MegaSR.sys
        2011/07/02 22:55:30.0236 5684 Modem (f001861e5700ee84e2d4e52c712f4964) C:\Windows\system32\drivers\modem.sys
        2011/07/02 22:55:30.0274 5684 monitor (79d10964de86b292320e9dfe02282a23) C:\Windows\system32\DRIVERS\monitor.sys
        2011/07/02 22:55:30.0292 5684 mouclass (fb18cc1d4c2e716b6b903b0ac0cc0609) C:\Windows\system32\DRIVERS\mouclass.sys
        2011/07/02 22:55:30.0327 5684 mouhid (2c388d2cd01c9042596cf3c8f3c7b24d) C:\Windows\system32\DRIVERS\mouhid.sys
        2011/07/02 22:55:30.0357 5684 mountmgr (921c18727c5920d6c0300736646931c2) C:\Windows\system32\drivers\mountmgr.sys
        2011/07/02 22:55:30.0435 5684 mpio (2af5997438c55fb79d33d015c30e1974) C:\Windows\system32\DRIVERS\mpio.sys
        2011/07/02 22:55:30.0463 5684 mpsdrv (ad2723a7b53dd1aacae6ad8c0bfbf4d0) C:\Windows\system32\drivers\mpsdrv.sys
        2011/07/02 22:55:30.0491 5684 MRxDAV (b1be47008d20e43da3adc37c24cdb89d) C:\Windows\system32\drivers\mrxdav.sys
        2011/07/02 22:55:30.0562 5684 mrxsmb (ca7570e42522e24324a12161db14ec02) C:\Windows\system32\DRIVERS\mrxsmb.sys
        2011/07/02 22:55:30.0597 5684 mrxsmb10 (c108952d3660375dcb716b222912e868) C:\Windows\system32\DRIVERS\mrxsmb10.sys
        2011/07/02 22:55:30.0620 5684 mrxsmb20 (25c38264a3c72594dd21d355d70d7a5d) C:\Windows\system32\DRIVERS\mrxsmb20.sys
        2011/07/02 22:55:30.0647 5684 msahci (4326d168944123f38dd3b2d9c37a0b12) C:\Windows\system32\DRIVERS\msahci.sys
        2011/07/02 22:55:30.0676 5684 msdsm (455029c7174a2dbb03dba8a0d8bddd9a) C:\Windows\system32\DRIVERS\msdsm.sys
        2011/07/02 22:55:30.0720 5684 Msfs (daefb28e3af5a76abcc2c3078c07327f) C:\Windows\system32\drivers\Msfs.sys
        2011/07/02 22:55:30.0743 5684 mshidkmdf (3e1e5767043c5af9367f0056295e9f84) C:\Windows\System32\drivers\mshidkmdf.sys
        2011/07/02 22:55:30.0765 5684 msisadrv (0a4e5757ae09fa9622e3158cc1aef114) C:\Windows\system32\DRIVERS\msisadrv.sys
        2011/07/02 22:55:30.0818 5684 MSKSSRV (8c0860d6366aaffb6c5bb9df9448e631) C:\Windows\system32\drivers\MSKSSRV.sys
        2011/07/02 22:55:30.0839 5684 MSPCLOCK (3ea8b949f963562cedbb549eac0c11ce) C:\Windows\system32\drivers\MSPCLOCK.sys
        2011/07/02 22:55:30.0864 5684 MSPQM (f456e973590d663b1073e9c463b40932) C:\Windows\system32\drivers\MSPQM.sys
        2011/07/02 22:55:30.0891 5684 MsRPC (0e008fc4819d238c51d7c93e7b41e560) C:\Windows\system32\drivers\MsRPC.sys
        2011/07/02 22:55:30.0917 5684 mssmbios (fc6b9ff600cc585ea38b12589bd4e246) C:\Windows\system32\DRIVERS\mssmbios.sys
        2011/07/02 22:55:30.0941 5684 MSTEE (b42c6b921f61a6e55159b8be6cd54a36) C:\Windows\system32\drivers\MSTEE.sys
        2011/07/02 22:55:30.0967 5684 MTConfig (33599130f44e1f34631cea241de8ac84) C:\Windows\system32\DRIVERS\MTConfig.sys
        2011/07/02 22:55:30.0996 5684 Mup (159fad02f64e6381758c990f753bcc80) C:\Windows\system32\Drivers\mup.sys
        2011/07/02 22:55:31.0058 5684 NativeWifiP (26384429fcd85d83746f63e798ab1480) C:\Windows\system32\DRIVERS\nwifi.sys
        2011/07/02 22:55:31.0103 5684 NDIS (23759d175a0a9baaf04d05047bc135a8) C:\Windows\system32\drivers\ndis.sys
        2011/07/02 22:55:31.0138 5684 NdisCap (0e1787aa6c9191d3d319e8bafe86f80c) C:\Windows\system32\DRIVERS\ndiscap.sys
        2011/07/02 22:55:31.0170 5684 NdisTapi (e4a8aec125a2e43a9e32afeea7c9c888) C:\Windows\system32\DRIVERS\ndistapi.sys
        2011/07/02 22:55:31.0196 5684 Ndisuio (b30ae7f2b6d7e343b0df32e6c08fce75) C:\Windows\system32\DRIVERS\ndisuio.sys
        2011/07/02 22:55:31.0226 5684 NdisWan (267c415eadcbe53c9ca873dee39cf3a4) C:\Windows\system32\DRIVERS\ndiswan.sys
        2011/07/02 22:55:31.0244 5684 NDProxy (af7e7c63dcef3f8772726f86039d6eb4) C:\Windows\system32\drivers\NDProxy.sys
        2011/07/02 22:55:31.0287 5684 NetBIOS (80b275b1ce3b0e79909db7b39af74d51) C:\Windows\system32\DRIVERS\netbios.sys
        2011/07/02 22:55:31.0311 5684 NetBT (dd52a733bf4ca5af84562a5e2f963b91) C:\Windows\system32\DRIVERS\netbt.sys
        2011/07/02 22:55:31.0366 5684 nfrd960 (1d85c4b390b0ee09c7a46b91efb2c097) C:\Windows\system32\DRIVERS\nfrd960.sys
        2011/07/02 22:55:31.0419 5684 Npfs (1db262a9f8c087e8153d89bef3d2235f) C:\Windows\system32\drivers\Npfs.sys
        2011/07/02 22:55:31.0487 5684 nsiproxy (e9a0a4d07e53d8fea2bb8387a3293c58) C:\Windows\system32\drivers\nsiproxy.sys
        2011/07/02 22:55:31.0572 5684 Ntfs (187002ce05693c306f43c873f821381f) C:\Windows\system32\drivers\Ntfs.sys
        2011/07/02 22:55:31.0640 5684 NTIDrvr (2757d2ba59aee155209e24942ab127c9) C:\Windows\system32\DRIVERS\NTIDrvr.sys
        2011/07/02 22:55:31.0663 5684 Null (f9756a98d69098dca8945d62858a812c) C:\Windows\system32\drivers\Null.sys
        2011/07/02 22:55:31.0737 5684 NVHDA (f972dc046c374a9e02f2dfbe74ebb203) C:\Windows\system32\drivers\nvhda32v.sys
        2011/07/02 22:55:31.0941 5684 nvlddmkm (712d98d35e68d0006b121f4a3b8ee814) C:\Windows\system32\DRIVERS\nvlddmkm.sys
        2011/07/02 22:55:32.0156 5684 NVNET (5bf9c11586f4764446407f509f1beca8) C:\Windows\system32\DRIVERS\nvmf6232.sys
        2011/07/02 22:55:32.0215 5684 nvraid (f1b0bed906f97e16f6d0c3629d2f21c6) C:\Windows\system32\drivers\nvraid.sys
        2011/07/02 22:55:32.0248 5684 nvsmu (f13618f0cb1e95232f4c2401592a59e9) C:\Windows\system32\DRIVERS\nvsmu.sys
        2011/07/02 22:55:32.0276 5684 nvstor (4520b63899e867f354ee012d34e11536) C:\Windows\system32\drivers\nvstor.sys
        2011/07/02 22:55:32.0304 5684 nvstor32 (3ff57a9a657c9690ecbc8b1e3b6e3979) C:\Windows\system32\DRIVERS\nvstor32.sys
        2011/07/02 22:55:32.0366 5684 nv_agp (5a0983915f02bae73267cc2a041f717d) C:\Windows\system32\DRIVERS\nv_agp.sys
        2011/07/02 22:55:32.0435 5684 ohci1394 (08a70a1f2cdde9bb49b885cb817a66eb) C:\Windows\system32\DRIVERS\ohci1394.sys
        2011/07/02 22:55:32.0505 5684 Parport (2ea877ed5dd9713c5ac74e8ea7348d14) C:\Windows\system32\DRIVERS\parport.sys
        2011/07/02 22:55:32.0537 5684 partmgr (ff4218952b51de44fe910953a3e686b9) C:\Windows\system32\drivers\partmgr.sys
        2011/07/02 22:55:32.0561 5684 Parvdm (eb0a59f29c19b86479d36b35983daadc) C:\Windows\system32\DRIVERS\parvdm.sys
        2011/07/02 22:55:32.0636 5684 pccsmcfd (175cc28dcf819f78caa3fbd44ad9e52a) C:\Windows\system32\DRIVERS\pccsmcfd.sys
        2011/07/02 22:55:32.0675 5684 pci (c858cb77c577780ecc456a892e7e7d0f) C:\Windows\system32\DRIVERS\pci.sys
        2011/07/02 22:55:32.0700 5684 pciide (afe86f419014db4e5593f69ffe26ce0a) C:\Windows\system32\DRIVERS\pciide.sys
        2011/07/02 22:55:32.0726 5684 pcmcia (f396431b31693e71e8a80687ef523506) C:\Windows\system32\DRIVERS\pcmcia.sys
        2011/07/02 22:55:32.0757 5684 pcw (250f6b43d2b613172035c6747aeeb19f) C:\Windows\system32\drivers\pcw.sys
        2011/07/02 22:55:32.0790 5684 PEAUTH (9e0104ba49f4e6973749a02bf41344ed) C:\Windows\system32\drivers\peauth.sys
        2011/07/02 22:55:32.0903 5684 PptpMiniport (631e3e205ad6d86f2aed6a4a8e69f2db) C:\Windows\system32\DRIVERS\raspptp.sys
        2011/07/02 22:55:32.0930 5684 Processor (85b1e3a0c7585bc4aae6899ec6fcf011) C:\Windows\system32\DRIVERS\processr.sys
        2011/07/02 22:55:33.0055 5684 Profos (d90a33660d328a9f587580f0b38c85de) C:\Program Files\Common Files\BitDefender\BitDefender Threat Scanner\profos.sys
        2011/07/02 22:55:33.0233 5684 Psched (6270ccae2a86de6d146529fe55b3246a) C:\Windows\system32\DRIVERS\pacer.sys
        2011/07/02 22:55:33.0274 5684 PSDFilter (628321c8dd76ad369b362b202e655a68) C:\Windows\system32\DRIVERS\psdfilter.sys
        2011/07/02 22:55:33.0304 5684 PSDNServ (79d7117e62709c7690cf3dd55acead37) C:\Windows\system32\DRIVERS\PSDNServ.sys
        2011/07/02 22:55:33.0323 5684 psdvdisk (cae5e82827990cf4bd4a49576bde3a43) C:\Windows\system32\DRIVERS\PSDVdisk.sys
        2011/07/02 22:55:33.0379 5684 ql2300 (ab95ecf1f6659a60ddc166d8315b0751) C:\Windows\system32\DRIVERS\ql2300.sys
        2011/07/02 22:55:33.0431 5684 ql40xx (b4dd51dd25182244b86737dc51af2270) C:\Windows\system32\DRIVERS\ql40xx.sys
        2011/07/02 22:55:33.0458 5684 QWAVEdrv (584078ca1b95ca72df2a27c336f9719d) C:\Windows\system32\drivers\qwavedrv.sys
        2011/07/02 22:55:33.0481 5684 RasAcd (30a81b53c766d0133bb86d234e5556ab) C:\Windows\system32\DRIVERS\rasacd.sys
        2011/07/02 22:55:33.0550 5684 RasAgileVpn (57ec4aef73660166074d8f7f31c0d4fd) C:\Windows\system32\DRIVERS\AgileVpn.sys
        2011/07/02 22:55:33.0625 5684 Rasl2tp (d9f91eafec2815365cbe6d167e4e332a) C:\Windows\system32\DRIVERS\rasl2tp.sys
        2011/07/02 22:55:33.0657 5684 RasPppoe (0fe8b15916307a6ac12bfb6a63e45507) C:\Windows\system32\DRIVERS\raspppoe.sys
        2011/07/02 22:55:33.0688 5684 RasSstp (44101f495a83ea6401d886e7fd70096b) C:\Windows\system32\DRIVERS\rassstp.sys
        2011/07/02 22:55:33.0742 5684 rdbss (835d7e81bf517a3b72384bdcc85e1ce6) C:\Windows\system32\DRIVERS\rdbss.sys
        2011/07/02 22:55:33.0774 5684 rdpbus (0d8f05481cb76e70e1da06ee9f0da9df) C:\Windows\system32\DRIVERS\rdpbus.sys
        2011/07/02 22:55:33.0847 5684 RDPCDD (1e016846895b15a99f9a176a05029075) C:\Windows\system32\DRIVERS\RDPCDD.sys
        2011/07/02 22:55:33.0890 5684 RDPENCDD (5a53ca1598dd4156d44196d200c94b8a) C:\Windows\system32\drivers\rdpencdd.sys
        2011/07/02 22:55:33.0917 5684 RDPREFMP (44b0a53cd4f27d50ed461dae0c0b4e1f) C:\Windows\system32\drivers\rdprefmp.sys
        2011/07/02 22:55:33.0948 5684 RDPWD (801371ba9782282892d00aadb08ee367) C:\Windows\system32\drivers\RDPWD.sys
        2011/07/02 22:55:33.0991 5684 rdyboost (4ea225bf1cf05e158853f30a99ca29a7) C:\Windows\system32\drivers\rdyboost.sys
        2011/07/02 22:55:34.0076 5684 RimUsb (0f6756ef8bda6dfa7be50465c83132bb) C:\Windows\system32\Drivers\RimUsb.sys
        2011/07/02 22:55:34.0126 5684 rspndr (032b0d36ad92b582d869879f5af5b928) C:\Windows\system32\DRIVERS\rspndr.sys
        2011/07/02 22:55:34.0182 5684 RSUSBSTOR (83f7a29b659771e60cd71999ef57aa0c) C:\Windows\system32\Drivers\RtsUStor.sys
        2011/07/02 22:55:34.0322 5684 sbp2port (34ee0c44b724e3e4ce2eff29126de5b5) C:\Windows\system32\DRIVERS\sbp2port.sys
        2011/07/02 22:55:34.0358 5684 scfilter (a95c54b2ac3cc9c73fcdf9e51a1d6b51) C:\Windows\system32\DRIVERS\scfilter.sys
        2011/07/02 22:55:34.0445 5684 secdrv (90a3935d05b494a5a39d37e71f09a677) C:\Windows\system32\drivers\secdrv.sys
        2011/07/02 22:55:34.0496 5684 Serenum (9ad8b8b515e3df6acd4212ef465de2d1) C:\Windows\system32\DRIVERS\serenum.sys
        2011/07/02 22:55:34.0544 5684 Serial (5fb7fcea0490d821f26f39cc5ea3d1e2) C:\Windows\system32\DRIVERS\serial.sys
        2011/07/02 22:55:34.0570 5684 sermouse (79bffb520327ff916a582dfea17aa813) C:\Windows\system32\DRIVERS\sermouse.sys
        2011/07/02 22:55:34.0616 5684 sffdisk (9f976e1eb233df46fce808d9dea3eb9c) C:\Windows\system32\DRIVERS\sffdisk.sys
        2011/07/02 22:55:34.0673 5684 sffp_mmc (932a68ee27833cfd57c1639d375f2731) C:\Windows\system32\DRIVERS\sffp_mmc.sys
        2011/07/02 22:55:34.0692 5684 sffp_sd (4f1e5b0fe7c8050668dbfade8999aefb) C:\Windows\system32\DRIVERS\sffp_sd.sys
        2011/07/02 22:55:34.0709 5684 sfloppy (db96666cc8312ebc45032f30b007a547) C:\Windows\system32\DRIVERS\sfloppy.sys
        2011/07/02 22:55:34.0752 5684 sisagp (2565cac0dc9fe0371bdce60832582b2e) C:\Windows\system32\DRIVERS\sisagp.sys
        2011/07/02 22:55:34.0790 5684 SiSRaid2 (a9f0486851becb6dda1d89d381e71055) C:\Windows\system32\DRIVERS\SiSRaid2.sys
        2011/07/02 22:55:34.0819 5684 SiSRaid4 (3727097b55738e2f554972c3be5bc1aa) C:\Windows\system32\DRIVERS\sisraid4.sys
        2011/07/02 22:55:34.0857 5684 Smb (3e21c083b8a01cb70ba1f09303010fce) C:\Windows\system32\DRIVERS\smb.sys
        2011/07/02 22:55:34.0902 5684 spldr (95cf1ae7527fb70f7816563cbc09d942) C:\Windows\system32\drivers\spldr.sys
        2011/07/02 22:55:35.0005 5684 sptd (cdddec541bc3c96f91ecb48759673505) C:\Windows\system32\Drivers\sptd.sys
        2011/07/02 22:55:35.0006 5684 Suspicious file (NoAccess): C:\Windows\system32\Drivers\sptd.sys. md5: cdddec541bc3c96f91ecb48759673505
        2011/07/02 22:55:35.0012 5684 sptd - detected LockedFile.Multi.Generic (1)
        2011/07/02 22:55:35.0068 5684 srv (c4a027b8c0bd3fc0699f41fa5e9e0c87) C:\Windows\system32\DRIVERS\srv.sys
        2011/07/02 22:55:35.0101 5684 srv2 (414bb592cad8a79649d01f9d94318fb3) C:\Windows\system32\DRIVERS\srv2.sys
        2011/07/02 22:55:35.0129 5684 srvnet (ff207d67700aa18242aaf985d3e7d8f4) C:\Windows\system32\DRIVERS\srvnet.sys
        2011/07/02 22:55:35.0190 5684 sscdbus (92b69020fc480219683d429dca068d71) C:\Windows\system32\DRIVERS\sscdbus.sys
        2011/07/02 22:55:35.0221 5684 sscdmdfl (77a2869d40cc84af711c321f9b0c7a78) C:\Windows\system32\DRIVERS\sscdmdfl.sys
        2011/07/02 22:55:35.0256 5684 sscdmdm (b4255635195a8413fcde7af5b7c4e382) C:\Windows\system32\DRIVERS\sscdmdm.sys
        2011/07/02 22:55:35.0340 5684 stexstor (db32d325c192b801df274bfd12a7e72b) C:\Windows\system32\DRIVERS\stexstor.sys
        2011/07/02 22:55:35.0391 5684 swenum (e58c78a848add9610a4db6d214af5224) C:\Windows\system32\DRIVERS\swenum.sys
        2011/07/02 22:55:35.0503 5684 Tcpip (0158d5e9982e9d6a90dfc802f618e130) C:\Windows\system32\drivers\tcpip.sys
        2011/07/02 22:55:35.0558 5684 TCPIP6 (0158d5e9982e9d6a90dfc802f618e130) C:\Windows\system32\DRIVERS\tcpip.sys
        2011/07/02 22:55:35.0626 5684 tcpipreg (e64444523add154f86567c469bc0b17f) C:\Windows\system32\drivers\tcpipreg.sys
        2011/07/02 22:55:35.0671 5684 TDPIPE (1875c1490d99e70e449e3afae9fcbadf) C:\Windows\system32\drivers\tdpipe.sys
        2011/07/02 22:55:35.0698 5684 TDTCP (7551e91ea999ee9a8e9c331d5a9c31f3) C:\Windows\system32\drivers\tdtcp.sys
        2011/07/02 22:55:35.0732 5684 tdx (cb39e896a2a83702d1737bfd402b3542) C:\Windows\system32\DRIVERS\tdx.sys
        2011/07/02 22:55:35.0761 5684 TermDD (c36f41ee20e6999dbf4b0425963268a5) C:\Windows\system32\DRIVERS\termdd.sys
        2011/07/02 22:55:35.0845 5684 TPkd (2f4e8077febfe11199ee3b011a34cd18) C:\Windows\system32\drivers\TPkd.sys
        2011/07/02 22:55:35.0998 5684 Trufos (b16d66a71de03285e14e9f165b59eda4) C:\Program Files\Common Files\BitDefender\BitDefender Threat Scanner\trufos.sys
        2011/07/02 22:55:36.0175 5684 tssecsrv (98ae6fa07d12cb4ec5cf4a9bfa5f4242) C:\Windows\system32\DRIVERS\tssecsrv.sys
        2011/07/02 22:55:36.0225 5684 tunnel (3e461d890a97f9d4c168f5fda36e1d00) C:\Windows\system32\DRIVERS\tunnel.sys
        2011/07/02 22:55:36.0256 5684 uagp35 (750fbcb269f4d7dd2e420c56b795db6d) C:\Windows\system32\DRIVERS\uagp35.sys
        2011/07/02 22:55:36.0293 5684 UBHelper (f763e070843ee2803de1395002b42938) C:\Windows\system32\drivers\UBHelper.sys
        2011/07/02 22:55:36.0322 5684 udfs (09cc3e16f8e5ee7168e01cf8fcbe061a) C:\Windows\system32\DRIVERS\udfs.sys
        2011/07/02 22:55:36.0364 5684 uliagpkx (44e8048ace47befbfdc2e9be4cbc8880) C:\Windows\system32\DRIVERS\uliagpkx.sys
        2011/07/02 22:55:36.0413 5684 umbus (049b3a50b3d646baeeee9eec9b0668dc) C:\Windows\system32\DRIVERS\umbus.sys
        2011/07/02 22:55:36.0438 5684 UmPass (7550ad0c6998ba1cb4843e920ee0feac) C:\Windows\system32\DRIVERS\umpass.sys
        2011/07/02 22:55:36.0545 5684 USBAAPL (d4fb6ecc60a428564ba8768b0e23c0fc) C:\Windows\system32\Drivers\usbaapl.sys
        2011/07/02 22:55:36.0590 5684 usbaudio (2436a42aab4ad48a9b714e5b0f344627) C:\Windows\system32\drivers\usbaudio.sys
        2011/07/02 22:55:36.0643 5684 usbccgp (c31ae588e403042632dc796cf09e30b0) C:\Windows\system32\DRIVERS\usbccgp.sys
        2011/07/02 22:55:36.0672 5684 usbcir (04ec7cec62ec3b6d9354eee93327fc82) C:\Windows\system32\DRIVERS\usbcir.sys
        2011/07/02 22:55:36.0729 5684 usbehci (e4c436d914768ce965d5e659ba7eebd8) C:\Windows\system32\DRIVERS\usbehci.sys
        2011/07/02 22:55:36.0785 5684 usbhub (bdcd7156ec37448f08633fd899823620) C:\Windows\system32\DRIVERS\usbhub.sys
        2011/07/02 22:55:36.0843 5684 usbohci (eb2d819a639015253c871cda09d91d58) C:\Windows\system32\DRIVERS\usbohci.sys
        2011/07/02 22:55:36.0897 5684 usbprint (797d862fe0875e75c7cc4c1ad7b30252) C:\Windows\system32\DRIVERS\usbprint.sys
        2011/07/02 22:55:36.0951 5684 usbscan (576096ccbc07e7c4ea4f5e6686d6888f) C:\Windows\system32\DRIVERS\usbscan.sys
        2011/07/02 22:55:37.0004 5684 USBSTOR (1c4287739a93594e57e2a9e6a3ed7353) C:\Windows\system32\DRIVERS\USBSTOR.SYS
        2011/07/02 22:55:37.0057 5684 usbuhci (22480bf4e5a09192e5e30ba4dde79fa4) C:\Windows\system32\drivers\usbuhci.sys
        2011/07/02 22:55:37.0099 5684 vdrvroot (a059c4c3edb09e07d21a8e5c0aabd3cb) C:\Windows\system32\DRIVERS\vdrvroot.sys
        2011/07/02 22:55:37.0138 5684 vga (17c408214ea61696cec9c66e388b14f3) C:\Windows\system32\DRIVERS\vgapnp.sys
        2011/07/02 22:55:37.0164 5684 VgaSave (8e38096ad5c8570a6f1570a61e251561) C:\Windows\System32\drivers\vga.sys
        2011/07/02 22:55:37.0193 5684 vhdmp (3be6e1f3a4f1afec8cee0d7883f93583) C:\Windows\system32\DRIVERS\vhdmp.sys
        2011/07/02 22:55:37.0236 5684 viaagp (c829317a37b4bea8f39735d4b076e923) C:\Windows\system32\DRIVERS\viaagp.sys
        2011/07/02 22:55:37.0260 5684 ViaC7 (e02f079a6aa107f06b16549c6e5c7b74) C:\Windows\system32\DRIVERS\viac7.sys
        2011/07/02 22:55:37.0288 5684 viaide (e43574f6a56a0ee11809b48c09e4fd3c) C:\Windows\system32\DRIVERS\viaide.sys
        2011/07/02 22:55:37.0322 5684 volmgr (384e5a2aa49934295171e499f86ba6f3) C:\Windows\system32\DRIVERS\volmgr.sys
        2011/07/02 22:55:37.0355 5684 volmgrx (b5bb72067ddddbbfb04b2f89ff8c3c87) C:\Windows\system32\drivers\volmgrx.sys
        2011/07/02 22:55:37.0382 5684 volsnap (58df9d2481a56edde167e51b334d44fd) C:\Windows\system32\DRIVERS\volsnap.sys
        2011/07/02 22:55:37.0447 5684 vsmraid (9dfa0cc2f8855a04816729651175b631) C:\Windows\system32\DRIVERS\vsmraid.sys
        2011/07/02 22:55:37.0496 5684 vwifibus (90567b1e658001e79d7c8bbd3dde5aa6) C:\Windows\System32\drivers\vwifibus.sys
        2011/07/02 22:55:37.0547 5684 WacomPen (de3721e89c653aa281428c8a69745d90) C:\Windows\system32\DRIVERS\wacompen.sys
        2011/07/02 22:55:37.0577 5684 WANARP (692a712062146e96d28ba0b7d75de31b) C:\Windows\system32\DRIVERS\wanarp.sys
        2011/07/02 22:55:37.0591 5684 Wanarpv6 (692a712062146e96d28ba0b7d75de31b) C:\Windows\system32\DRIVERS\wanarp.sys
        2011/07/02 22:55:37.0686 5684 Wd (1112a9badacb47b7c0bb0392e3158dff) C:\Windows\system32\DRIVERS\wd.sys
        2011/07/02 22:55:37.0716 5684 Wdf01000 (9950e3d0f08141c7e89e64456ae7dc73) C:\Windows\system32\drivers\Wdf01000.sys
        2011/07/02 22:55:37.0790 5684 WfpLwf (8b9a943f3b53861f2bfaf6c186168f79) C:\Windows\system32\DRIVERS\wfplwf.sys
        2011/07/02 22:55:37.0823 5684 WIMMount (5cf95b35e59e2a38023836fff31be64c) C:\Windows\system32\drivers\wimmount.sys
        2011/07/02 22:55:37.0908 5684 WinUsb (30fc6e5448d0cbaaa95280eeef7fedae) C:\Windows\system32\DRIVERS\WinUsb.sys
        2011/07/02 22:55:37.0964 5684 WmiAcpi (0217679b8fca58714c3bf2726d2ca84e) C:\Windows\system32\DRIVERS\wmiacpi.sys
        2011/07/02 22:55:38.0033 5684 ws2ifsl (6db3276587b853bf886b69528fdb048c) C:\Windows\system32\drivers\ws2ifsl.sys
        2011/07/02 22:55:38.0074 5684 WudfPf (6f9b6c0c93232cff47d0f72d6db1d21e) C:\Windows\system32\drivers\WudfPf.sys
        2011/07/02 22:55:38.0102 5684 WUDFRd (f91ff1e51fca30b3c3981db7d5924252) C:\Windows\system32\DRIVERS\WUDFRd.sys
        2011/07/02 22:55:38.0157 5684 MBR (0x1B8) (de1996b5390bac8242e23168f828c750) \Device\Harddisk0\DR0
        2011/07/02 22:55:38.0162 5684 \Device\Harddisk0\DR0 - detected Rootkit.Win32.TDSS.tdl4 (0)
        2011/07/02 22:55:38.0178 5684 MBR (0x1B8) (5fb38429d5d77768867c76dcbdb35194) \Device\Harddisk1\DR1
        2011/07/02 22:55:38.0203 5684 Boot (0x1200) (00f0476b084896bc34510ecbf01e3ff1) \Device\Harddisk0\DR0\Partition0
        2011/07/02 22:55:38.0245 5684 Boot (0x1200) (274577c3e034f74239705cf602bdd237) \Device\Harddisk0\DR0\Partition1
        2011/07/02 22:55:38.0259 5684 Boot (0x1200) (5237f4570a4cec1dd107b1317a1001c8) \Device\Harddisk1\DR1\Partition0
        2011/07/02 22:55:38.0267 5684 ================================================================================
        2011/07/02 22:55:38.0267 5684 Scan finished
        2011/07/02 22:55:38.0267 5684 ================================================================================
        2011/07/02 22:55:38.0281 7916 Detected object count: 2
        2011/07/02 22:55:38.0281 7916 Actual detected object count: 2
        2011/07/02 22:57:46.0748 7916 sptd (cdddec541bc3c96f91ecb48759673505) C:\Windows\system32\Drivers\sptd.sys
        2011/07/02 22:57:46.0748 7916 Suspicious file (NoAccess): C:\Windows\system32\Drivers\sptd.sys. md5: cdddec541bc3c96f91ecb48759673505
        2011/07/02 22:57:46.0753 7916 C:\Windows\system32\Drivers\sptd.sys - copied to quarantine
        2011/07/02 22:57:46.0805 7916 LockedFile.Multi.Generic(sptd) - User select action: Quarantine
        2011/07/02 22:57:46.0811 7916 \Device\Harddisk0\DR0 (Rootkit.Win32.TDSS.tdl4) - will be cured after reboot
        2011/07/02 22:57:46.0812 7916 \Device\Harddisk0\DR0 - ok
        2011/07/02 22:57:46.0813 7916 Rootkit.Win32.TDSS.tdl4(\Device\Harddisk0\DR0) - User select action: Cure

        merci
        0
        1. Contributeur sécurité
          Ok il est dégagé :-)

          Télécharge AdwCleaner ( d'Xplode ) sur ton bureau.
          Lance le, clique sur [Suppression] puis patiente le temps du nettoyage.
          Une fois le scan fini, un rapport s'ouvrira. Poste moi son contenu dans ta prochaine réponse.

          Note : Le rapport est également sauvegardé sous C:\AdwCleaner[S1].txt

          ~~

          ▶ Télécharge AD-Remover sur ton Bureau : (TeamXScript)

          http://www.teamxscript.org/adremoverTelechargement.html ( Lien officiel )
          OU
          https://www.androidworld.fr/ ( Miroir )

          /!\ Ferme toutes applications en cours /!\

          ▶ Double-clique sur l'icône Ad-remover située sur ton Bureau.
          ▶ Sur la page, clique sur le bouton « Scanner »
          ▶ Confirme le lancement du scan
          ▶ Laisse travailler l'outil.
          ▶ Quand il a fini, un rapport s'ouvrira : ferme le.

          ♦ Pour me transmettre les rapports, utilise le site http://pjjoint.malekal.com
          0
          1. voila le rapport adwcleaner :

            # AdwCleaner v1.317 - Rapport créé le 09/11/2011 à 03:24:23
            # Mis à jour le 06/11/11 à 14h par Xplode
            # Système d'exploitation : Windows 7 Home Premium Service Pack 1 (32 bits)
            # Nom d'utilisateur : melvynou - PC-DE-MARIE (Administrateur)
            # Exécuté depuis : C:\Users\melvynou\Desktop\fix pc\adwcleaner0.exe
            # Option [Suppression]

            ***** [Services] *****

            ***** [Fichiers / Dossiers] *****

            Fichier Supprimé : C:\Program Files\Mozilla Firefox\extensions\wtxpcom@mybrowserbar.com

            ***** [Registre] *****

            Clé Supprimée : HKLM\SOFTWARE\Classes\CLSID\{A7E8C343-7860-4A95-9AA8-AAF30D0F6D1E}
            Clé Supprimée : HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\2796BAE63F1801E277261BA0D77770028F20EEE4

            ***** [Navigateurs] *****

            -\\ Internet Explorer v9.0.8112.16421

            [OK] Le registre ne contient aucune entrée illégitime.

            -\\ Mozilla Firefox v8.0 (fr)

            Profil : su0i9dnx.default
            Fichier : C:\Users\melvynou\AppData\Roaming\Mozilla\Firefox\Profiles\su0i9dnx.default\prefs.js

            Supprimée : user_pref("CT2786678..clientLogIsEnabled", false);
            Supprimée : user_pref("CT2786678..clientLogServiceUrl", "hxxp://clientlog.users.conduit.com/ClientDiagnostics.as[...]
            Supprimée : user_pref("CT2786678..uninstallLogServiceUrl", "hxxp://uninstall.users.conduit.com/Uninstall.asmx/Re[...]
            Supprimée : user_pref("CT2786678.AboutPrivacyUrl", "hxxp://www.conduit.com/privacy/Default.aspx");
            Supprimée : user_pref("CT2786678.CTID", "CT2786678");
            Supprimée : user_pref("CT2786678.CurrentServerDate", "6-5-2011");
            Supprimée : user_pref("CT2786678.DialogsAlignMode", "LTR");
            Supprimée : user_pref("CT2786678.DialogsGetterLastCheckTime", "Fri May 06 2011 20:08:56 GMT+0200");
            Supprimée : user_pref("CT2786678.DownloadReferralCookieData", "");
            Supprimée : user_pref("CT2786678.EMailNotifierPollDate", "Fri May 06 2011 21:18:57 GMT+0200");
            Supprimée : user_pref("CT2786678.FeedLastCount5690698542593514850", 160);
            Supprimée : user_pref("CT2786678.FeedPollDate129301619375443753", "Fri May 06 2011 21:08:57 GMT+0200");
            Supprimée : user_pref("CT2786678.FeedPollDate129301619375443759", "Fri May 06 2011 21:08:57 GMT+0200");
            Supprimée : user_pref("CT2786678.FeedPollDate129301619375444699", "Fri May 06 2011 21:08:57 GMT+0200");
            Supprimée : user_pref("CT2786678.FeedPollDate129301619375444705", "Fri May 06 2011 21:08:56 GMT+0200");
            Supprimée : user_pref("CT2786678.FeedPollDate129301619375444711", "Fri May 06 2011 21:08:56 GMT+0200");
            Supprimée : user_pref("CT2786678.FeedPollDate129301619375444717", "Fri May 06 2011 21:08:56 GMT+0200");
            Supprimée : user_pref("CT2786678.FeedPollDate129301619375444723", "Fri May 06 2011 21:08:58 GMT+0200");
            Supprimée : user_pref("CT2786678.FeedPollDate129301619375444729", "Fri May 06 2011 21:08:56 GMT+0200");
            Supprimée : user_pref("CT2786678.FeedPollDate129301619375444735", "Fri May 06 2011 21:08:58 GMT+0200");
            Supprimée : user_pref("CT2786678.FeedPollDate129301619375444741", "Fri May 06 2011 21:08:57 GMT+0200");
            Supprimée : user_pref("CT2786678.FeedPollDate129301619375444747", "Fri May 06 2011 21:08:58 GMT+0200");
            Supprimée : user_pref("CT2786678.FeedTTL129301619375444699", 10);
            Supprimée : user_pref("CT2786678.FeedTTL129301619375444723", 15);
            Supprimée : user_pref("CT2786678.FeedTTL129301619375444735", 5);
            Supprimée : user_pref("CT2786678.FeedTTL129301619375444747", 5);
            Supprimée : user_pref("CT2786678.FirstServerDate", "6-5-2011");
            Supprimée : user_pref("CT2786678.FirstTime", true);
            Supprimée : user_pref("CT2786678.FirstTimeFF3", true);
            Supprimée : user_pref("CT2786678.FixPageNotFoundErrors", true);
            Supprimée : user_pref("CT2786678.GroupingServerCheckInterval", 1440);
            Supprimée : user_pref("CT2786678.GroupingServiceUrl", "hxxp://grouping.services.conduit.com/");
            Supprimée : user_pref("CT2786678.HasUserGlobalKeys", true);
            Supprimée : user_pref("CT2786678.Initialize", true);
            Supprimée : user_pref("CT2786678.InitializeCommonPrefs", true);
            Supprimée : user_pref("CT2786678.InstallationAndCookieDataSentCount", 1);
            Supprimée : user_pref("CT2786678.InstalledDate", "Fri May 06 2011 20:08:57 GMT+0200");
            Supprimée : user_pref("CT2786678.IsGrouping", false);
            Supprimée : user_pref("CT2786678.IsMulticommunity", false);
            Supprimée : user_pref("CT2786678.IsOpenThankYouPage", true);
            Supprimée : user_pref("CT2786678.IsOpenUninstallPage", true);
            Supprimée : user_pref("CT2786678.LanguagePackLastCheckTime", "Fri May 06 2011 20:08:57 GMT+0200");
            Supprimée : user_pref("CT2786678.LanguagePackReloadIntervalMM", 1440);
            Supprimée : user_pref("CT2786678.LanguagePackServiceUrl", "hxxp://translation.users.conduit.com/Translation.ashx[...]
            Supprimée : user_pref("CT2786678.LastLogin_3.3.3.2", "Fri May 06 2011 20:08:56 GMT+0200");
            Supprimée : user_pref("CT2786678.LatestVersion", "3.3.3.2");
            Supprimée : user_pref("CT2786678.Locale", "en");
            Supprimée : user_pref("CT2786678.MCDetectTooltipHeight", "83");
            Supprimée : user_pref("CT2786678.MCDetectTooltipUrl", "hxxp://@EB_INSTALL_LINK@/rank/tooltip/?version=1");
            Supprimée : user_pref("CT2786678.MCDetectTooltipWidth", "295");
            Supprimée : user_pref("CT2786678.SearchFromAddressBarIsInit", true);
            Supprimée : user_pref("CT2786678.SearchInNewTabEnabled", true);
            Supprimée : user_pref("CT2786678.SearchInNewTabIntervalMM", 1440);
            Supprimée : user_pref("CT2786678.SearchInNewTabLastCheckTime", "Fri May 06 2011 20:08:57 GMT+0200");
            Supprimée : user_pref("CT2786678.SearchInNewTabServiceUrl", "hxxp://newtab.conduit-hosting.com/newtab/?ctid=EB_T[...]
            Supprimée : user_pref("CT2786678.SearchInNewTabUsageUrl", "hxxp://Usage.Hosting.conduit-services.com/UsageServic[...]
            Supprimée : user_pref("CT2786678.SearchInNewTabUserEnabled", false);
            Supprimée : user_pref("CT2786678.ServiceMapLastCheckTime", "Fri May 06 2011 20:08:54 GMT+0200");
            Supprimée : user_pref("CT2786678.SettingsLastCheckTime", "Fri May 06 2011 20:08:54 GMT+0200");
            Supprimée : user_pref("CT2786678.SettingsLastUpdate", "1304004054");
            Supprimée : user_pref("CT2786678.ThirdPartyComponentsInterval", 504);
            Supprimée : user_pref("CT2786678.ThirdPartyComponentsLastCheck", "Fri May 06 2011 20:08:54 GMT+0200");
            Supprimée : user_pref("CT2786678.ThirdPartyComponentsLastUpdate", "1246786978");
            Supprimée : user_pref("CT2786678.TrusteLinkUrl", "hxxp://trust.conduit.com/CT2786678");
            Supprimée : user_pref("CT2786678.UserID", "UN16814223317970719");
            Supprimée : user_pref("CT2786678.WeatherNetwork", "");
            Supprimée : user_pref("CT2786678.WeatherPollDate", "Fri May 06 2011 21:08:59 GMT+0200");
            Supprimée : user_pref("CT2786678.WeatherUnit", "C");
            Supprimée : user_pref("CT2786678.alertChannelId", "1178763");
            Supprimée : user_pref("CT2786678.generalConfigFromLogin", "{\"SocialDomains\":\"social.conduit.com;apps.conduit.[...]
            Supprimée : user_pref("CT2786678.globalFirstTimeInfoLastCheckTime", "Fri May 06 2011 20:08:56 GMT+0200");
            Supprimée : user_pref("CT2786678.isAppTrackingManagerOn", true);
            Supprimée : user_pref("CT2786678.myStuffEnabled", true);
            Supprimée : user_pref("CT2786678.myStuffPublihserMinWidth", 400);
            Supprimée : user_pref("CT2786678.myStuffSearchUrl", "hxxp://Apps.conduit.com/search?q=SEARCH_TERM&SearchSourceOr[...]
            Supprimée : user_pref("CT2786678.myStuffServiceIntervalMM", 1440);
            Supprimée : user_pref("CT2786678.myStuffServiceUrl", "hxxp://mystuff.conduit-services.com/MyStuffService.ashx?Co[...]
            Supprimée : user_pref("CT2786678.testingCtid", "");
            Supprimée : user_pref("CT2786678.toolbarAppMetaDataLastCheckTime", "Fri May 06 2011 20:08:55 GMT+0200");
            Supprimée : user_pref("CT2786678.toolbarContextMenuLastCheckTime", "Fri May 06 2011 20:08:57 GMT+0200");
            Supprimée : user_pref("CT2786678.usagesFlag", 1);

            -\\ Google Chrome v [Impossible d'obtenir la version]

            Fichier : C:\Users\melvynou\AppData\Local\Google\Chrome\User Data\Default\Preferences

            [OK] Le fichier ne contient aucune entrée illégitime.

            *************************

            AdwCleaner[S1].txt - [7913 octets] - [09/11/2011 03:24:23]

            *************************

            Dossier Temporaire : 55 dossier(s)et 23338 fichier(s) supprimés

            ########## EOF - C:\AdwCleaner[S1].txt - [8137 octets] ##########

            et voila le rapport de ad cleaner :

            https://pjjoint.malekal.com/files.php?id=y12h5u12x11i12d12c12v15x6e5o14b9r15d14w7z5r6h6x12p6
            0
            1. Contributeur sécurité
              ok

              ▶ Télécharge MBAM et installe le selon l'emplacement par défaut
              https://www.malwarebytes.com/mwb-download/
              ▶ Effectue la mise à jour et lance Malwarebytes' Anti-Malware

              ▶ ▶ Si tu n''arrive pas à le mettre à jour, télécharge ce fichier , ferme MBAM, et exécute le

              ▶ Clique dans l'onglet du haut "Recherche"
              ▶ Coche l'option "Exécuter un examen complet" puis sur le bouton "Rechercher"
              ▶ Choisis de scanner tous tes disques durs, puis clique sur 'Lancer l'examen"

              A la fin de l'analyse, si MBAM n'a rien trouvé :

              ▶ Clique sur OK, le rapport s'ouvre spontanément

              Si des menaces ont été détectées :

              ▶ Clique sur OK puis "Afficher les résultats"
              ▶ Choisis l'option "Supprimer la sélection"
              ▶ Si MBAM demande le redémarrage de Windows : Clique sur "Oui"
              ▶ Une fois le PC redémarré, le rapport se trouve dans l'onglet "Rapports/Logs"
              ▶ Sinon le rapport s'ouvre automatiquement après la suppression

              Quelque soit le résultat, copie/colle le rapport dans le prochain message
              0
              1. voila le rapport MBAM :

                Malwarebytes' Anti-Malware 1.51.2.1300
                www.malwarebytes.org

                Version de la base de données: 8124

                Windows 6.1.7601 Service Pack 1
                Internet Explorer 9.0.8112.16421

                09/11/2011 20:26:28
                mbam-log-2011-11-09 (20-26-28).txt

                Type d'examen: Examen complet (C:\|D:\|E:\|F:\|G:\|H:\|)
                Elément(s) analysé(s): 583352
                Temps écoulé: 4 heure(s), 34 minute(s), 57 seconde(s)

                Processus mémoire infecté(s): 0
                Module(s) mémoire infecté(s): 0
                Clé(s) du Registre infectée(s): 0
                Valeur(s) du Registre infectée(s): 0
                Elément(s) de données du Registre infecté(s): 0
                Dossier(s) infecté(s): 0
                Fichier(s) infecté(s): 0

                Processus mémoire infecté(s):
                (Aucun élément nuisible détecté)

                Module(s) mémoire infecté(s):
                (Aucun élément nuisible détecté)

                Clé(s) du Registre infectée(s):
                (Aucun élément nuisible détecté)

                Valeur(s) du Registre infectée(s):
                (Aucun élément nuisible détecté)

                Elément(s) de données du Registre infecté(s):
                (Aucun élément nuisible détecté)

                Dossier(s) infecté(s):
                (Aucun élément nuisible détecté)

                Fichier(s) infecté(s):
                (Aucun élément nuisible détecté)
                0
                1. Contributeur sécurité
                  bien refais un zhpdiag pour contrôle :)
                  0
                  1. le raport ZHPdiag :

                    http://pjjoint.malekal.co/files.php?id=ZHPDiag_n6b10y10p14p14x14h7x14m9e14b5h14z13x8v9v8p14m7e12i12
                    0
                    1. Contributeur sécurité
                      ▶ Télécharge ici : ComboFix vers ton bureau

                      ▶ Double-clique sur ComboFix.exe
                      Un "pop-up" va apparaître qui dit que ComboFix est utilisé à vos risques et avec aucune garantie... Clique sur oui pour accepter

                      ♦ Ne touche à rien (souris, clavier) tant que le scan n'est pas terminé, car tu risques de planter ton PC

                      ▶ En fin de scan, il est possible que ComboFix ait besoin de redémarrer le PC pour finaliser la désinfection, laisse-le faire.</gras>
                      ▶ Une fois le scan achevé, un rapport va s''afficher : Poste son contenu

                      Notes:
                      ♦ Le rapport se trouve également là : C:\ComboFix.txt
                      ♦ Tutoriel combofix
                      0
                      1. voila le rapport combofix :

                        ComboFix 11-11-14.02 - melvynou 14/11/2011 20:43:22.1.2 - x86
                        Microsoft Windows 7 Édition Familiale Premium 6.1.7601.1.1252.33.1036.18.2815.1373 [GMT 1:00]
                        Lancé depuis: c:\users\melvynou\Desktop\ComboFix.exe
                        AV: BitDefender Antivirus *Disabled/Updated* {982ADE23-275B-0766-37C5-DE01A484098E}
                        FW: BitDefender Pare-feu *Disabled* {A0115F06-6D34-063E-1C9A-77345A574EF5}
                        SP: BitDefender Antispyware *Disabled/Updated* {234B3FC7-0161-08E8-0D75-E573DF034333}
                        SP: Windows Defender *Enabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
                        * Un nouveau point de restauration a été créé
                        .
                        .
                        (((((((((((((((((((((((((((((((((((( Autres suppressions ))))))))))))))))))))))))))))))))))))))))))))))))
                        .
                        .
                        c:\users\melvynou\AppData\Roaming\Adobe\plugs
                        c:\users\melvynou\AppData\Roaming\Adobe\shed
                        c:\users\melvynou\AppData\Roaming\Microsoft\Windows\Recent\Thumbs.db
                        c:\users\yowyow\1234.cpr
                        c:\users\yowyow\Documents\~WRL3780.tmp
                        c:\windows\system32\msvcsv60.dll
                        .
                        .
                        ((((((((((((((((((((((((((((( Fichiers créés du 2011-10-14 au 2011-11-14 ))))))))))))))))))))))))))))))))))))
                        .
                        .
                        2011-11-14 20:01 . 2011-11-14 20:01 -------- d-----w- c:\users\yowyow\AppData\Local\temp
                        2011-11-14 20:01 . 2011-11-14 20:06 -------- d-----w- c:\users\melvynou\AppData\Local\temp
                        2011-11-14 20:01 . 2011-11-14 20:01 -------- d-----w- c:\users\marie\AppData\Local\temp
                        2011-11-11 13:34 . 2011-11-14 12:36 56200 ----a-w- c:\programdata\Microsoft\Windows Defender\Definition Updates\{8C65AB23-51F9-4617-83A0-68E4D4334CEA}\offreg.dll
                        2011-11-11 13:34 . 2011-10-07 03:48 6668624 ----a-w- c:\programdata\Microsoft\Windows Defender\Definition Updates\{8C65AB23-51F9-4617-83A0-68E4D4334CEA}\mpengine.dll
                        2011-11-09 02:33 . 2011-10-01 04:37 708608 ----a-w- c:\program files\Common Files\System\wab32.dll
                        2011-11-09 02:33 . 2011-09-29 16:03 1290608 ----a-w- c:\windows\system32\drivers\tcpip.sys
                        2011-11-09 02:33 . 2011-09-29 03:37 2341888 ----a-w- c:\windows\system32\win32k.sys
                        2011-10-31 21:23 . 2011-10-31 21:26 -------- d-----w- c:\users\melvynou\AppData\Local\WMTools Downloaded Files
                        2011-10-31 21:05 . 2011-10-31 21:05 -------- d-----w- c:\program files\Movie Maker 2.6
                        .
                        .
                        .
                        (((((((((((((((((((((((((((((((((( Compte-rendu de Find3M ))))))))))))))))))))))))))))))))))))))))))))))))
                        .
                        2011-10-07 21:19 . 2011-05-13 19:47 414368 ----a-w- c:\windows\system32\FlashPlayerCPLApp.cpl
                        2011-10-07 20:45 . 2011-10-07 20:45 18328 ----a-w- c:\programdata\Microsoft\IdentityCRL\production\ppcrlconfig600.dll
                        2011-09-01 02:35 . 2011-10-13 01:08 1798144 ----a-w- c:\windows\system32\jscript9.dll
                        2011-09-01 02:28 . 2011-10-13 01:08 1126912 ----a-w- c:\windows\system32\wininet.dll
                        2011-09-01 02:22 . 2011-10-13 01:08 2382848 ----a-w- c:\windows\system32\mshtml.tlb
                        2011-08-31 15:00 . 2011-07-03 13:55 22216 ----a-w- c:\windows\system32\drivers\mbam.sys
                        2011-08-27 04:26 . 2011-10-12 12:32 233472 ----a-w- c:\windows\system32\oleacc.dll
                        2011-08-27 04:26 . 2011-10-12 12:32 571904 ----a-w- c:\windows\system32\oleaut32.dll
                        2011-08-17 04:24 . 2011-10-12 12:32 465408 ----a-w- c:\windows\system32\psisdecd.dll
                        2011-08-17 04:19 . 2011-10-12 12:32 75776 ----a-w- c:\windows\system32\psisrndr.ax
                        2011-11-09 01:06 . 2011-06-27 11:22 134104 ----a-w- c:\program files\mozilla firefox\components\browsercomps.dll
                        .
                        .
                        ((((((((((((((((((((((((((((((((( Points de chargement Reg ))))))))))))))))))))))))))))))))))))))))))))))))
                        .
                        .
                        *Note* les éléments vides & les éléments initiaux légitimes ne sont pas listés
                        REGEDIT4
                        .
                        [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
                        "{9ec204df-0e48-4c32-816e-2e928a4fd9c2}"= "mscoree.dll" [2010-11-05 297808]
                        .
                        [HKEY_CLASSES_ROOT\clsid\{9ec204df-0e48-4c32-816e-2e928a4fd9c2}]
                        [HKEY_CLASSES_ROOT\IEToolbar.Toolbar]
                        .
                        [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\egisPSDP]
                        @="{30A0A3F6-38AC-4C53-BB8B-0D95238E25BA}"
                        [HKEY_CLASSES_ROOT\CLSID\{30A0A3F6-38AC-4C53-BB8B-0D95238E25BA}]
                        2008-07-29 16:52 121392 ----a-w- c:\program files\Acer\Empowering Technology\eDataSecurity\x86\PSDProtect.dll
                        .
                        [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
                        "AutoStartNPSAgent"="c:\program files\Samsung\Samsung New PC Studio\NPSAgent.exe" [2009-03-12 102400]
                        "msnmsgr"="c:\program files\Windows Live\Messenger\msnmsgr.exe" [2011-05-13 4283256]
                        "ProductReg"="c:\program files\Acer\WR_PopUp\ProductReg.exe" [2008-11-17 135168]
                        "WMPNSCFG"="c:\program files\Windows Media Player\WMPNSCFG.exe" [2009-07-14 65024]
                        "DAEMON Tools Lite"="c:\program files\DAEMON Tools Lite\DTLite.exe" [2009-10-30 369200]
                        "Sidebar"="c:\program files\Windows Sidebar\sidebar.exe" [2010-11-20 1174016]
                        .
                        [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
                        "M-Audio Taskbar Icon"="c:\windows\system32\M-AudioTaskBarIcon.exe" [2010-12-07 644104]
                        "QuickTime Task"="c:\program files\QuickTime\QTTask.exe" [2010-11-29 421888]
                        "iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2011-03-07 421160]
                        "BCSSync"="c:\program files\Microsoft Office\Office14\BCSSync.exe" [2010-01-21 91520]
                        "hpqSRMon"="c:\program files\HP\Digital Imaging\bin\hpqSRMon.exe" [2008-07-22 150528]
                        "CanonMyPrinter"="c:\program files\Canon\MyPrinter\BJMyPrt.exe" [2010-03-25 2516296]
                        "CanonSolutionMenuEx"="c:\program files\Canon\Solution Menu EX\CNSEMAIN.EXE" [2010-04-02 1185112]
                        "Adobe ARM"="c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2011-06-06 937920]
                        "Malwarebytes' Anti-Malware (reboot)"="c:\program files\Malwarebytes' Anti-Malware\mbam.exe" [2011-08-31 1047208]
                        .
                        c:\users\marie\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\
                        OneNote 2007 - Capture d'écran et lancement.lnk - c:\program files\Microsoft Office\Office12\ONENOTEM.EXE [N/A]
                        OneNote 2010 - Capture d'écran et lancement.lnk - c:\program files\Microsoft Office\Office14\ONENOTEM.EXE [2010-1-21 226176]
                        OpenOffice.org 3.1.lnk - c:\program files\OpenOffice.org 3\program\quickstart.exe [2009-8-18 384000]
                        .
                        c:\users\melvynou\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\
                        OpenOffice.org 3.1.lnk - c:\program files\OpenOffice.org 3\program\quickstart.exe [2009-8-18 384000]
                        .
                        c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\
                        Adobe Gamma Loader.lnk - c:\program files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe [2010-10-13 110592]
                        .
                        [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
                        "ConsentPromptBehaviorAdmin"= 5 (0x5)
                        "ConsentPromptBehaviorUser"= 3 (0x3)
                        "EnableUIADesktopToggle"= 0 (0x0)
                        .
                        [HKEY_LOCAL_MACHINE\system\currentcontrolset\control\lsa]
                        Security Packages REG_MULTI_SZ kerberos msv1_0 schannel wdigest tspkg pku2u livessp
                        .
                        R2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;c:\windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-03-18 130384]
                        R2 gupdate;Service Google Update (gupdate);c:\program files\Google\Update\GoogleUpdate.exe [2009-10-02 133104]
                        R3 Arrakis3;BitDefender Serveur Arrakis;c:\program files\Common Files\BitDefender\BitDefender Arrakis Server\bin\arrakis3.exe [2009-10-19 183880]
                        R3 BBSvc;Bing Bar Update Service;c:\program files\Microsoft\BingBar\BBSvc.EXE [2011-02-28 183560]
                        R3 EMSUSB2;EMS USB Joypad2;c:\windows\system32\DRIVERS\EMSUSB2.sys [2007-01-03 9728]
                        R3 gupdatem;Service Google Update (gupdatem);c:\program files\Google\Update\GoogleUpdate.exe [2009-10-02 133104]
                        R3 maconfservice;Ma-Config Service;c:\program files\ma-config.com\maconfservice.exe [2009-12-17 243056]
                        R3 Microsoft SharePoint Workspace Audit Service;Microsoft SharePoint Workspace Audit Service;c:\program files\Microsoft Office\Office14\GROOVE.EXE [2010-01-21 30963576]
                        R3 NTIBackupSvc;NTI Backup Now 5 Backup Service;c:\program files\NewTech Infosystems\NTI Backup Now 5\BackupSvc.exe [2008-09-23 50424]
                        R3 osppsvc;Office Software Protection Platform;c:\program files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPSVC.EXE [2010-01-09 4640000]
                        R3 TsUsbFlt;TsUsbFlt;c:\windows\system32\drivers\tsusbflt.sys [2010-11-20 52224]
                        R3 WatAdminSvc;Service Windows Activation Technologies;c:\windows\system32\Wat\WatAdminSvc.exe [2010-05-28 1343400]
                        S0 sptd;sptd;c:\windows\System32\Drivers\sptd.sys [2009-12-07 691696]
                        S1 BdfNdisf;BitDefender Firewall NDIS 6 Filter Driver;c:\windows\system32\DRIVERS\BdfNdisf6.sys [2010-07-16 72784]
                        S1 bdfwfpf;bdfwfpf;c:\program files\Common Files\BitDefender\BitDefender Firewall\bdfwfpf.sys [2010-07-16 79952]
                        S2 Acer HomeMedia Connect Service;Acer HomeMedia Connect Service;c:\program files\Acer Arcade Live\Acer HomeMedia Connect\Kernel\DMS\CLMSServer.exe [2008-05-20 269448]
                        S2 AdobeARMservice;Adobe Acrobat Update Service;c:\program files\Common Files\Adobe\ARM\1.0\armsvc.exe [2011-06-06 64952]
                        S2 BDVEDISK;BDVEDISK;c:\program files\BitDefender\BitDefender 2010\bdvedisk.sys [2010-01-19 85128]
                        S2 ETService;Empowering Technology Service;c:\program files\Acer\Empowering Technology\Service\ETService.exe [2008-10-01 24576]
                        S2 FsUsbExService;FsUsbExService;c:\windows\system32\FsUsbExService.Exe [2009-03-12 233472]
                        S2 NTISchedulerSvc;NTI Backup Now 5 Scheduler Service;c:\program files\NewTech Infosystems\NTI Backup Now 5\SchedulerSvc.exe [2008-09-23 144632]
                        S2 Stereo Service;NVIDIA Stereoscopic 3D Driver Service;c:\program files\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe [2010-01-11 240232]
                        S3 BDFM;BDFM;c:\windows\system32\DRIVERS\bdfm.sys [2010-02-03 153448]
                        S3 FsUsbExDisk;FsUsbExDisk;c:\windows\system32\FsUsbExDisk.SYS [2009-03-05 36608]
                        S3 MAUSBFASTTRACK;Service for M-Audio FastTrack;c:\windows\system32\DRIVERS\MAudioFastTrack.sys [2010-12-07 158344]
                        S3 NVHDA;Service for NVIDIA High Definition Audio Driver;c:\windows\system32\drivers\nvhda32v.sys [2008-03-22 43552]
                        S3 RSUSBSTOR;RtsUStor.Sys Realtek USB Card Reader;c:\windows\system32\Drivers\RtsUStor.sys [2009-09-22 174592]
                        .
                        .
                        --- Autres Services/Pilotes en mémoire ---
                        .
                        *Deregistered* - BDSelfPr
                        .
                        [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
                        HPZ12 REG_MULTI_SZ Pml Driver HPZ12 Net Driver HPZ12
                        bdx REG_MULTI_SZ scan
                        .
                        Contenu du dossier 'Tâches planifiées'
                        .
                        2011-11-14 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
                        - c:\program files\Google\Update\GoogleUpdate.exe [2009-10-02 00:32]
                        .
                        2011-11-14 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
                        - c:\program files\Google\Update\GoogleUpdate.exe [2009-10-02 00:32]
                        .
                        .
                        ------- Examen supplémentaire -------
                        .
                        IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~3\Office14\EXCEL.EXE/3000
                        IE: E&xporter vers Microsoft Excel - c:\progra~1\MICROS~3\Office12\EXCEL.EXE/3000
                        IE: Se&nd to OneNote - c:\progra~1\MICROS~3\Office14\ONBttnIE.dll/105
                        TCP: DhcpNameServer = 212.27.40.241 212.27.40.240
                        FF - ProfilePath - c:\users\melvynou\AppData\Roaming\Mozilla\Firefox\Profiles\su0i9dnx.default\
                        FF - prefs.js: browser.search.selectedEngine - Google
                        FF - prefs.js: browser.startup.homepage - hxxp://fr.start3.mozilla.com/firefox?client=firefox-a&rls=org.mozilla:fr:official
                        .
                        - - - - ORPHELINS SUPPRIMES - - - -
                        .
                        AddRemove-Antares Kantos v1.02 VST & RTAS - c:\progra~1\STEINB~1\VSTPLU~1\Antares\UNWISE.EXE
                        AddRemove-VST to RTAS Adapter - c:\progra~1\STEINB~1\VSTPLU~1\Vst2Rtas\UNWISE.EXE
                        .
                        .
                        .
                        --------------------- CLES DE REGISTRE BLOQUEES ---------------------
                        .
                        [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0000\AllUserSettings]
                        @Denied: (A) (Users)
                        @Denied: (A) (Everyone)
                        @Allowed: (B 1 2 3 4 5) (S-1-5-20)
                        "BlindDial"=dword:00000000
                        .
                        [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0001\AllUserSettings]
                        @Denied: (A) (Users)
                        @Denied: (A) (Everyone)
                        @Allowed: (B 1 2 3 4 5) (S-1-5-20)
                        "BlindDial"=dword:00000000
                        .
                        [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\PCW\Security]
                        @Denied: (Full) (Everyone)
                        .
                        Heure de fin: 2011-11-14 21:26:40
                        ComboFix-quarantined-files.txt 2011-11-14 20:26
                        .
                        Avant-CF: 57 998 123 008 octets libres
                        Après-CF: 73 168 064 512 octets libres
                        .
                        - - End Of File - - CB965E238B3DDC5AA92F6AFAB92235B2
                        0
                        1. Contributeur sécurité
                          Bonsoir

                          Refais un zhpdiag pour contrôle.

                          A+
                          0
                          1. Contributeur sécurité
                            Désinstalle Daemon Tool Toolbar

                            ~~

                            ▶ Copie tout le texte présent dans la balise code ci-dessous ( tu le sélectionnes avec ta souris / Clique droit dessus et choisis "copier" ou fait Ctrl+C )

                            M3 - MFPP: Plugins - [melvynou] -- C:\Users\melvynou\AppData\Roaming\Mozilla\Firefox\Profiles\su0i9dnx.default\searchplugins\daemon-search.xml    => 
                            O43 - CFD: 15/01/2011 - 20:44:42 - [2043] --H-D- C:\Users\melvynou\AppData\Local\0VpzFCS0mGkGdp    => 
                            O43 - CFD: 15/01/2011 - 20:44:48 - [3211] --H-D- C:\Users\melvynou\AppData\Local\3ZloPh2Tj2u    => 
                            O43 - CFD: 15/01/2011 - 20:44:42 - [2242] --H-D- C:\Users\melvynou\AppData\Local\ogacGfI9maXq7h2    => 
                            O43 - CFD: 15/01/2011 - 20:44:42 - [2043] --H-D- C:\Users\melvynou\AppData\Local\0VpzFCS0mGkGdp    => 
                            O43 - CFD: 15/01/2011 - 20:44:48 - [3211] --H-D- C:\Users\melvynou\AppData\Local\3ZloPh2Tj2u    => 
                            O43 - CFD: 15/01/2011 - 20:44:42 - [2242] --H-D- C:\Users\melvynou\AppData\Local\ogacGfI9maXq7h2    => 
                            O42 - Logiciel: Dealio Toolbar v4.1 - (.Spigot, Inc..) [HKLM] -- {C1F83B10-0BEB-475f-BBA2-E235B02B9826}    => Infection PUP (PUP.Dealio)
                            O43 - CFD: 30/11/2010 - 00:04:24 - [284189] ----D- C:\Users\melvynou\AppData\Local\widestream6 Air    => Infection BT (Adware.SPointer)
                            O43 - CFD: 30/11/2010 - 00:04:24 - [284189] ----D- C:\Users\melvynou\AppData\Local\widestream6 Air    => Infection BT (Adware.SPointer)
                            O81 - IFC: Internet Feature Controls [HKUS\.DEFAULT] [FEATURE_BROWSER_EMULATION] -- svchost.exe    => Infection Rootkit (Rootkit.TDSS)
                            O81 - IFC: Internet Feature Controls [HKUS\S-1-5-18] [FEATURE_BROWSER_EMULATION] -- svchost.exe    => Infection Rootkit (Rootkit.TDSS)
                            [HKLM\Software\Classes\Installer\Features\01B38F1CBEB0f574BB2A2E530BB28962]    => Infection PUP (PUP.Dealio)
                            C:\Users\melvynou\AppData\Local\widestream6 Air    => Infection BT (Adware.SPointer)
                            C:\Users\melvynou\AppData\Local\widestream6 Air    => Infection BT (Adware.SPointer)
                            C:\Users\melvynou\AppData\Roaming\Mozilla\Firefox\Profiles\su0i9dnx.default\Extensions\dttoolbar@toolbarnet.com    => Infection BT (Adware.SmartShopper)
                            M2 - MFEP: prefs.js [melvynou - su0i9dnx.default\DTToolbar@toolbarnet.com] [] DAEMON Tools Toolbar v3.0 (.DT Soft Ltd..)    => Toolbar.DaemonTools
                            M2 - MFEP: prefs.js [melvynou - su0i9dnx.default\{bf7380fa-e3b4-4db2-af3e-9d8783a45bfc}] [] uTorrentBar Community Toolbar v3.8.0.8 (.Conduit Ltd..)    => Toolbar.Conduit
                            O3 - Toolbar: DAEMON Tools Toolbar - {32099AAC-C132-4136-9E9A-4E364A424E17} . (.Pas de propriétaire - ToolBand Module.) -- C:\Program Files\DAEMON Tools Toolbar\DTToolbar.dll
                            O42 - Logiciel: DAEMON Tools Toolbar - (.DT Soft Ltd.) [HKLM] -- DAEMON Tools Toolbar    => Toolbar.DaemonTools
                            O43 - CFD: 07/12/2009 - 03:40:56 - [1927329] ----D- C:\Program Files\DAEMON Tools Toolbar    => Toolbar.DaemonTools
                            [HKLM\Software\Microsoft\Windows\CurrentVersion\Uninstall\daemon tools toolbar]    => Toolbar.DaemonTools
                            [HKCU\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser]:{32099aac-c132-4136-9e9a-4e364a424e17}    => Toolbar.DaemonTools
                            [HKLM\Software\Microsoft\Internet Explorer\Toolbar]:{32099aac-c132-4136-9e9a-4e364a424e17}    => Toolbar.DaemonTools
                            C:\Program Files\DAEMON Tools Toolbar    => Toolbar.DaemonTools
                            EMPTYTEMP
                            EMPTYFLASH
                            


                            ▶ Puis Lance ZHPFix depuis le raccourci du bureau .

                            ▶ Une fois l'outil ZHPFix ouvert , clique sur le bouton [ H ] ( "coller les lignes Helper" ).

                            ▶ Dans l'encadré principal tu verras donc les lignes que tu as copié précédemment apparaitre.

                            ▶ Vérifie que toutes les lignes que je t''ai demandé de copier (et seulement elles) sont dans la fenêtre.

                            ▶ Clique sur le bouton « GO » pour lancer le nettoyage

                            ▶ Copie/Colle le rapport à l''écran dans ton prochain message

                            Note : le rapport se trouve aussi dans C:\ZHP sous le nom de ZHPFix[Rx].txt (où X correspond au numéro du lancement de ZHPFix)

                            Tutoriel : http://forums-fec.be/entraide/viewtopic.php?f=55&t=12
                            0
                            1. et voila le rapport ZHPfix :

                              Rapport de ZHPFix 1.12.3333 par Nicolas Coolman, Update du 02/07/2011
                              Fichier d'export Registre : C:\ZHPExportRegistry-15-11-2011-22-37-23.txt
                              Run by melvynou at 15/11/2011 22:37:23
                              Windows 7 Home Premium Edition, 32-bit Service Pack 1 (Build 7601)
                              Web site : http://www.premiumorange.com/zeb-help-process/zhpfix.html

                              ========== Logiciel(s) ==========
                              ABSENT Uninstall Process: c:\program files\daemon tools toolbar\uninst.exe

                              ========== Clé(s) du Registre ==========
                              SUPPRIME Partiel Software Key: {C1F83B10-0BEB-475f-BBA2-E235B02B9826}
                              SUPPRIME [HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\DAEMON Tools Toolbar]
                              SUPPRIME Key: HKLM\Software\Classes\Installer\Features\01B38F1CBEB0f574BB2A2E530BB28962
                              ABSENT Key: HKLM\Software\Microsoft\Windows\CurrentVersion\Uninstall\daemon tools toolbar

                              ========== Valeur(s) du Registre ==========
                              SUPPRIME IFC: [FEATURE_BROWSER_EMULATION] svchost.exe
                              ABSENT IFC: [FEATURE_BROWSER_EMULATION] svchost.exe
                              SUPPRIME Toolbar: {32099AAC-C132-4136-9E9A-4E364A424E17}
                              SUPPRIME [HKCU\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser]:{32099aac-c132-4136-9e9a-4e364a424e17}
                              ABSENT [HKLM\Software\Microsoft\Internet Explorer\Toolbar]:{32099aac-c132-4136-9e9a-4e364a424e17}

                              ========== Dossier(s) ==========
                              SUPPRIME Folder: C:\Users\melvynou\AppData\Local\0VpzFCS0mGkGdp
                              SUPPRIME Folder: C:\Users\melvynou\AppData\Local\3ZloPh2Tj2u
                              SUPPRIME Folder: C:\Users\melvynou\AppData\Local\ogacGfI9maXq7h2
                              ABSENT C:\Users\melvynou\AppData\Local\0VpzFCS0mGkGdp
                              ABSENT C:\Users\melvynou\AppData\Local\3ZloPh2Tj2u
                              ABSENT C:\Users\melvynou\AppData\Local\ogacGfI9maXq7h2
                              SUPPRIME Folder*: C:\Users\melvynou\AppData\Local\widestream6 Air
                              ABSENT C:\Users\melvynou\AppData\Local\widestream6 Air
                              SUPPRIME Folder: c:\users\melvynou\appdata\roaming\mozilla\firefox\profiles\su0i9dnx.default\extensions\dttoolbar@toolbarnet.com
                              SUPPRIME Folder: C:\Users\melvynou\AppData\Roaming\Mozilla\Firefox\Profiles\su0i9dnx.default\extensions\{bf7380fa-e3b4-4db2-af3e-9d8783a45bfc}
                              SUPPRIME Folder*: C:\Program Files\DAEMON Tools Toolbar
                              SUPPRIME Temporaires Windows: : 87
                              SUPPRIME Flash Cookies: 1677

                              ========== Fichier(s) ==========
                              SUPPRIME c:\users\melvynou\appdata\roaming\mozilla\firefox\profiles\su0i9dnx.default\searchplugins\daemon-search.xml
                              ABSENT Folder/File: c:\users\melvynou\appdata\local\widestream6 air
                              SUPPRIME c:\program files\daemon tools toolbar\dttoolbar.dll
                              ABSENT Folder/File: c:\program files\daemon tools toolbar
                              SUPPRIME Temporaires Windows: : 136
                              SUPPRIME Flash Cookies: 819

                              ========== Récapitulatif ==========
                              4 : Clé(s) du Registre
                              5 : Valeur(s) du Registre
                              13 : Dossier(s)
                              6 : Fichier(s)
                              1 : Logiciel(s)

                              ========== Chemin du fichier rapport ==========
                              C:\Program Files\ZHPDiag\ZHPFixReport.txt

                              End of the scan in 03mn 27s
                              0
                              1. Contributeur sécurité
                                Re,

                                Toujours des soucis ?
                                0
                                1. Et bien a vrai dire plus tellement, j'ai eu quelques problemes avec le nouveau firefox qui me demandait a chaque ouverture d'installer tel ou tel module complémentaire, mais il ne l'a pas fait ce coup ci. Si j'ai un probleme qui survient prochainement je te tiens au courant. En tout cas je te remercie grandement de m'avoir purifié mon PC.
                                  Sinon, que puis je faire pour éviter ce genre de soucis a l'avenir ? mon anti virus n'est pas assez performant ?
                                  0