Suppression de Mediashifting

Fermé
Theo - 31 janv. 2012 à 13:17
 Theo - 31 janv. 2012 à 18:38
Bonjour,

J'aurais besoin d'aide pour éradiquer cette saleté...

A voir également:

15 réponses

Malekal_morte- Messages postés 180304 Date d'inscription mercredi 17 mai 2006 Statut Modérateur, Contributeur sécurité Dernière intervention 15 décembre 2020 24 631
31 janv. 2012 à 13:27
Salut,

Sauvegarde les données importantes.


Passe un coup de TDSSKiller : https://forum.malekal.com/viewtopic.php?t=28637&start=
Lire ce qui est écrit au niveau des suppressions/réparation (delete et cure), ne pas supprimer n'importe quoi.
Poste le rapport ici.
0
Salut, merci pour la prise en main du malade.
RAS pour TDSSKiller.
Report :
13:24:30.0397 2452 TDSS rootkit removing tool 2.7.8.0 Jan 30 2012 16:39:36
13:24:30.0938 2452 ============================================================
13:24:30.0938 2452 Current date / time: 2012/01/31 13:24:30.0938
13:24:30.0938 2452 SystemInfo:
13:24:30.0938 2452
13:24:30.0938 2452 OS Version: 6.1.7601 ServicePack: 1.0
13:24:30.0938 2452 Product type: Workstation
13:24:30.0938 2452 ComputerName: ZILTIS_T
13:24:30.0938 2452 UserName: Theo
13:24:30.0939 2452 Windows directory: C:\Windows
13:24:30.0939 2452 System windows directory: C:\Windows
13:24:30.0939 2452 Running under WOW64
13:24:30.0939 2452 Processor architecture: Intel x64
13:24:30.0939 2452 Number of processors: 4
13:24:30.0939 2452 Page size: 0x1000
13:24:30.0939 2452 Boot type: Normal boot
13:24:30.0939 2452 ============================================================
13:24:31.0500 2452 Drive \Device\Harddisk0\DR0 - Size: 0x7470C06000 (465.76 Gb), SectorSize: 0x200, Cylinders: 0xED81, SectorsPerTrack: 0x3F, TracksPerCylinder: 0xFF, Type 'K0', Flags 0x00000040
13:24:31.0506 2452 \Device\Harddisk0\DR0:
13:24:31.0507 2452 MBR used
13:24:31.0507 2452 \Device\Harddisk0\DR0\Partition0: MBR, Type 0x7, StartLBA 0xF6A800, BlocksNum 0x32000
13:24:31.0507 2452 \Device\Harddisk0\DR0\Partition1: MBR, Type 0x7, StartLBA 0xF9C800, BlocksNum 0x25B69830
13:24:31.0534 2452 \Device\Harddisk0\DR0\Partition2: MBR, Type 0x7, StartLBA 0x26B07000, BlocksNum 0x1387E800
13:24:31.0610 2452 Initialize success
13:24:31.0610 2452 ============================================================
13:26:12.0700 3632 ============================================================
13:26:12.0700 3632 Scan started
13:26:12.0700 3632 Mode: Manual;
13:26:12.0700 3632 ============================================================
13:26:13.0255 3632 1394ohci (a87d604aea360176311474c87a63bb88) C:\Windows\system32\drivers\1394ohci.sys
13:26:13.0260 3632 1394ohci - ok
13:26:13.0408 3632 ACPI (d81d9e70b8a6dd14d42d7b4efa65d5f2) C:\Windows\system32\drivers\ACPI.sys
13:26:13.0415 3632 ACPI - ok
13:26:13.0520 3632 AcpiPmi (99f8e788246d495ce3794d7e7821d2ca) C:\Windows\system32\drivers\acpipmi.sys
13:26:13.0527 3632 AcpiPmi - ok
13:26:13.0759 3632 adp94xx (2f6b34b83843f0c5118b63ac634f5bf4) C:\Windows\system32\drivers\adp94xx.sys
13:26:13.0777 3632 adp94xx - ok
13:26:13.0879 3632 adpahci (597f78224ee9224ea1a13d6350ced962) C:\Windows\system32\drivers\adpahci.sys
13:26:13.0892 3632 adpahci - ok
13:26:13.0981 3632 adpu320 (e109549c90f62fb570b9540c4b148e54) C:\Windows\system32\drivers\adpu320.sys
13:26:13.0992 3632 adpu320 - ok
13:26:14.0136 3632 AFD (d5b031c308a409a0a576bff4cf083d30) C:\Windows\system32\drivers\afd.sys
13:26:14.0145 3632 AFD - ok
13:26:14.0245 3632 agp440 (608c14dba7299d8cb6ed035a68a15799) C:\Windows\system32\drivers\agp440.sys
13:26:14.0253 3632 agp440 - ok
13:26:14.0361 3632 aliide (5812713a477a3ad7363c7438ca2ee038) C:\Windows\system32\drivers\aliide.sys
13:26:14.0367 3632 aliide - ok
13:26:14.0470 3632 amdide (1ff8b4431c353ce385c875f194924c0c) C:\Windows\system32\drivers\amdide.sys
13:26:14.0476 3632 amdide - ok
13:26:14.0566 3632 AmdK8 (7024f087cff1833a806193ef9d22cda9) C:\Windows\system32\drivers\amdk8.sys
13:26:14.0576 3632 AmdK8 - ok
13:26:14.0667 3632 AmdPPM (1e56388b3fe0d031c44144eb8c4d6217) C:\Windows\system32\drivers\amdppm.sys
13:26:14.0676 3632 AmdPPM - ok
13:26:14.0816 3632 amdsata (d4121ae6d0c0e7e13aa221aa57ef2d49) C:\Windows\system32\drivers\amdsata.sys
13:26:14.0826 3632 amdsata - ok
13:26:14.0942 3632 amdsbs (f67f933e79241ed32ff46a4f29b5120b) C:\Windows\system32\drivers\amdsbs.sys
13:26:14.0953 3632 amdsbs - ok
13:26:15.0063 3632 amdxata (540daf1cea6094886d72126fd7c33048) C:\Windows\system32\drivers\amdxata.sys
13:26:15.0069 3632 amdxata - ok
13:26:15.0222 3632 AppID (89a69c3f2f319b43379399547526d952) C:\Windows\system32\drivers\appid.sys
13:26:15.0229 3632 AppID - ok
13:26:15.0369 3632 arc (c484f8ceb1717c540242531db7845c4e) C:\Windows\system32\drivers\arc.sys
13:26:15.0380 3632 arc - ok
13:26:15.0483 3632 arcsas (019af6924aefe7839f61c830227fe79c) C:\Windows\system32\drivers\arcsas.sys
13:26:15.0491 3632 arcsas - ok
13:26:15.0593 3632 AsyncMac (769765ce2cc62867468cea93969b2242) C:\Windows\system32\DRIVERS\asyncmac.sys
13:26:15.0598 3632 AsyncMac - ok
13:26:15.0709 3632 atapi (02062c0b390b7729edc9e69c680a6f3c) C:\Windows\system32\drivers\atapi.sys
13:26:15.0710 3632 atapi - ok
13:26:15.0867 3632 athr (0acc06fcf46f64ed4f11e57ee461c1f4) C:\Windows\system32\DRIVERS\athrx.sys
13:26:15.0898 3632 athr - ok
13:26:16.0070 3632 avgntflt (aa8f79a1bdfc03b3bc70c44ab00589b4) C:\Windows\system32\DRIVERS\avgntflt.sys
13:26:16.0071 3632 avgntflt - ok
13:26:16.0183 3632 avipbb (f1c9db5f7b2a56a0b29667d22ba540fc) C:\Windows\system32\DRIVERS\avipbb.sys
13:26:16.0193 3632 avipbb - ok
13:26:16.0302 3632 avkmgr (248db59fc86de44d2779f4c7fb1a567d) C:\Windows\system32\DRIVERS\avkmgr.sys
13:26:16.0303 3632 avkmgr - ok
13:26:16.0428 3632 b06bdrv (3e5b191307609f7514148c6832bb0842) C:\Windows\system32\drivers\bxvbda.sys
13:26:16.0446 3632 b06bdrv - ok
13:26:16.0554 3632 b57nd60a (b5ace6968304a3900eeb1ebfd9622df2) C:\Windows\system32\DRIVERS\b57nd60a.sys
13:26:16.0567 3632 b57nd60a - ok
13:26:16.0670 3632 Beep (16a47ce2decc9b099349a5f840654746) C:\Windows\system32\drivers\Beep.sys
13:26:16.0674 3632 Beep - ok
13:26:16.0804 3632 blbdrive (61583ee3c3a17003c4acd0475646b4d3) C:\Windows\system32\drivers\blbdrive.sys
13:26:16.0811 3632 blbdrive - ok
13:26:16.0913 3632 bowser (6c02a83164f5cc0a262f4199f0871cf5) C:\Windows\system32\DRIVERS\bowser.sys
13:26:16.0916 3632 bowser - ok
13:26:17.0009 3632 BrFiltLo (f09eee9edc320b5e1501f749fde686c8) C:\Windows\system32\drivers\BrFiltLo.sys
13:26:17.0014 3632 BrFiltLo - ok
13:26:17.0087 3632 BrFiltUp (b114d3098e9bdb8bea8b053685831be6) C:\Windows\system32\drivers\BrFiltUp.sys
13:26:17.0091 3632 BrFiltUp - ok
13:26:17.0201 3632 Brserid (43bea8d483bf1870f018e2d02e06a5bd) C:\Windows\System32\Drivers\Brserid.sys
13:26:17.0217 3632 Brserid - ok
13:26:17.0312 3632 BrSerWdm (a6eca2151b08a09caceca35c07f05b42) C:\Windows\System32\Drivers\BrSerWdm.sys
13:26:17.0318 3632 BrSerWdm - ok
13:26:17.0412 3632 BrUsbMdm (b79968002c277e869cf38bd22cd61524) C:\Windows\System32\Drivers\BrUsbMdm.sys
13:26:17.0416 3632 BrUsbMdm - ok
13:26:17.0512 3632 BrUsbSer (a87528880231c54e75ea7a44943b38bf) C:\Windows\System32\Drivers\BrUsbSer.sys
13:26:17.0516 3632 BrUsbSer - ok
13:26:17.0623 3632 BthEnum (cf98190a94f62e405c8cb255018b2315) C:\Windows\system32\drivers\BthEnum.sys
13:26:17.0629 3632 BthEnum - ok
13:26:17.0728 3632 BTHMODEM (9da669f11d1f894ab4eb69bf546a42e8) C:\Windows\system32\drivers\bthmodem.sys
13:26:17.0735 3632 BTHMODEM - ok
13:26:17.0822 3632 BthPan (02dd601b708dd0667e1331fa8518e9ff) C:\Windows\system32\DRIVERS\bthpan.sys
13:26:17.0831 3632 BthPan - ok
13:26:17.0934 3632 BTHPORT (64c198198501f7560ee41d8d1efa7952) C:\Windows\System32\Drivers\BTHport.sys
13:26:17.0954 3632 BTHPORT - ok
13:26:18.0056 3632 BTHUSB (f188b7394d81010767b6df3178519a37) C:\Windows\System32\Drivers\BTHUSB.sys
13:26:18.0065 3632 BTHUSB - ok
13:26:18.0174 3632 btusbflt (6e04458e98daf28826482e41a7a62df5) C:\Windows\system32\drivers\btusbflt.sys
13:26:18.0181 3632 btusbflt - ok
13:26:18.0283 3632 btwaudio (4bdbdb86abba924e029fb2683be7c505) C:\Windows\system32\drivers\btwaudio.sys
13:26:18.0292 3632 btwaudio - ok
13:26:18.0398 3632 btwavdt (5c849bd7c78791c5cee9f4651d7fe38d) C:\Windows\system32\drivers\btwavdt.sys
13:26:18.0407 3632 btwavdt - ok
13:26:18.0520 3632 btwl2cap (6149301dc3f81d6f9667a3fbac410975) C:\Windows\system32\DRIVERS\btwl2cap.sys
13:26:18.0526 3632 btwl2cap - ok
13:26:18.0609 3632 btwrchid (3e1991afa851a36dc978b0a1b0535c8b) C:\Windows\system32\DRIVERS\btwrchid.sys
13:26:18.0615 3632 btwrchid - ok
13:26:18.0695 3632 cdfs (b8bd2bb284668c84865658c77574381a) C:\Windows\system32\DRIVERS\cdfs.sys
13:26:18.0703 3632 cdfs - ok
13:26:18.0812 3632 cdrom (f036ce71586e93d94dab220d7bdf4416) C:\Windows\system32\DRIVERS\cdrom.sys
13:26:18.0822 3632 cdrom - ok
13:26:18.0945 3632 circlass (d7cd5c4e1b71fa62050515314cfb52cf) C:\Windows\system32\drivers\circlass.sys
13:26:18.0954 3632 circlass - ok
13:26:19.0068 3632 CLFS (fe1ec06f2253f691fe36217c592a0206) C:\Windows\system32\CLFS.sys
13:26:19.0076 3632 CLFS - ok
13:26:19.0197 3632 CmBatt (0840155d0bddf1190f84a663c284bd33) C:\Windows\system32\drivers\CmBatt.sys
13:26:19.0202 3632 CmBatt - ok
13:26:19.0278 3632 cmdide (e19d3f095812725d88f9001985b94edd) C:\Windows\system32\drivers\cmdide.sys
13:26:19.0284 3632 cmdide - ok
13:26:19.0391 3632 CNG (d5fea92400f12412b3922087c09da6a5) C:\Windows\system32\Drivers\cng.sys
13:26:19.0400 3632 CNG - ok
13:26:19.0498 3632 Compbatt (102de219c3f61415f964c88e9085ad14) C:\Windows\system32\drivers\compbatt.sys
13:26:19.0500 3632 Compbatt - ok
13:26:19.0602 3632 CompositeBus (03edb043586cceba243d689bdda370a8) C:\Windows\system32\drivers\CompositeBus.sys
13:26:19.0610 3632 CompositeBus - ok
13:26:19.0718 3632 crcdisk (1c827878a998c18847245fe1f34ee597) C:\Windows\system32\drivers\crcdisk.sys
13:26:19.0725 3632 crcdisk - ok
13:26:19.0876 3632 CSC (54da3dfd29ed9f1619b6f53f3ce55e49) C:\Windows\system32\drivers\csc.sys
13:26:19.0895 3632 CSC - ok
13:26:20.0015 3632 DfsC (9bb2ef44eaa163b29c4a4587887a0fe4) C:\Windows\system32\Drivers\dfsc.sys
13:26:20.0023 3632 DfsC - ok
13:26:20.0123 3632 discache (13096b05847ec78f0977f2c0f79e9ab3) C:\Windows\system32\drivers\discache.sys
13:26:20.0125 3632 discache - ok
13:26:20.0227 3632 Disk (9819eee8b5ea3784ec4af3b137a5244c) C:\Windows\system32\drivers\disk.sys
13:26:20.0229 3632 Disk - ok
13:26:20.0346 3632 drmkaud (9b19f34400d24df84c858a421c205754) C:\Windows\system32\drivers\drmkaud.sys
13:26:20.0350 3632 drmkaud - ok
13:26:20.0374 3632 dump_wmimmc - ok
13:26:20.0495 3632 DXGKrnl (f5bee30450e18e6b83a5012c100616fd) C:\Windows\System32\drivers\dxgkrnl.sys
13:26:20.0520 3632 DXGKrnl - ok
13:26:20.0729 3632 ebdrv (dc5d737f51be844d8c82c695eb17372f) C:\Windows\system32\drivers\evbda.sys
13:26:20.0790 3632 ebdrv - ok
13:26:20.0918 3632 elxstor (0e5da5369a0fcaea12456dd852545184) C:\Windows\system32\drivers\elxstor.sys
13:26:20.0935 3632 elxstor - ok
13:26:21.0014 3632 ErrDev (34a3c54752046e79a126e15c51db409b) C:\Windows\system32\drivers\errdev.sys
13:26:21.0019 3632 ErrDev - ok
13:26:21.0114 3632 ew_hwusbdev - ok
13:26:21.0214 3632 exfat (a510c654ec00c1e9bdd91eeb3a59823b) C:\Windows\system32\drivers\exfat.sys
13:26:21.0226 3632 exfat - ok
13:26:21.0313 3632 fastfat (0adc83218b66a6db380c330836f3e36d) C:\Windows\system32\drivers\fastfat.sys
13:26:21.0324 3632 fastfat - ok
13:26:21.0420 3632 fdc (d765d19cd8ef61f650c384f62fac00ab) C:\Windows\system32\drivers\fdc.sys
13:26:21.0426 3632 fdc - ok
13:26:21.0527 3632 FileInfo (655661be46b5f5f3fd454e2c3095b930) C:\Windows\system32\drivers\fileinfo.sys
13:26:21.0530 3632 FileInfo - ok
13:26:21.0614 3632 Filetrace (5f671ab5bc87eea04ec38a6cd5962a47) C:\Windows\system32\drivers\filetrace.sys
13:26:21.0621 3632 Filetrace - ok
13:26:21.0700 3632 flpydisk (c172a0f53008eaeb8ea33fe10e177af5) C:\Windows\system32\drivers\flpydisk.sys
13:26:21.0706 3632 flpydisk - ok
13:26:21.0810 3632 FltMgr (da6b67270fd9db3697b20fce94950741) C:\Windows\system32\drivers\fltmgr.sys
13:26:21.0826 3632 FltMgr - ok
13:26:21.0930 3632 FsDepends (d43703496149971890703b4b1b723eac) C:\Windows\system32\drivers\FsDepends.sys
13:26:21.0938 3632 FsDepends - ok
13:26:22.0037 3632 Fs_Rec (e95ef8547de20cf0603557c0cf7a9462) C:\Windows\system32\drivers\Fs_Rec.sys
13:26:22.0044 3632 Fs_Rec - ok
13:26:22.0138 3632 fvevol (1f7b25b858fa27015169fe95e54108ed) C:\Windows\system32\DRIVERS\fvevol.sys
13:26:22.0143 3632 fvevol - ok
13:26:22.0238 3632 gagp30kx (8c778d335c9d272cfd3298ab02abe3b6) C:\Windows\system32\drivers\gagp30kx.sys
13:26:22.0246 3632 gagp30kx - ok
13:26:22.0345 3632 hcw85cir (f2523ef6460fc42405b12248338ab2f0) C:\Windows\system32\drivers\hcw85cir.sys
13:26:22.0353 3632 hcw85cir - ok
13:26:22.0459 3632 HdAudAddService (975761c778e33cd22498059b91e7373a) C:\Windows\system32\drivers\HdAudio.sys
13:26:22.0477 3632 HdAudAddService - ok
13:26:22.0574 3632 HDAudBus (97bfed39b6b79eb12cddbfeed51f56bb) C:\Windows\system32\drivers\HDAudBus.sys
13:26:22.0577 3632 HDAudBus - ok
13:26:22.0674 3632 HECIx64 (b6ac71aaa2b10848f57fc49d55a651af) C:\Windows\system32\drivers\HECIx64.sys
13:26:22.0702 3632 HECIx64 - ok
13:26:22.0783 3632 HidBatt (78e86380454a7b10a5eb255dc44a355f) C:\Windows\system32\drivers\HidBatt.sys
13:26:22.0790 3632 HidBatt - ok
13:26:22.0875 3632 HidBth (7fd2a313f7afe5c4dab14798c48dd104) C:\Windows\system32\drivers\hidbth.sys
13:26:22.0883 3632 HidBth - ok
13:26:22.0966 3632 HidIr (0a77d29f311b88cfae3b13f9c1a73825) C:\Windows\system32\drivers\hidir.sys
13:26:22.0975 3632 HidIr - ok
13:26:23.0090 3632 HidUsb (9592090a7e2b61cd582b612b6df70536) C:\Windows\system32\DRIVERS\hidusb.sys
13:26:23.0096 3632 HidUsb - ok
13:26:23.0221 3632 HpSAMD (39d2abcd392f3d8a6dce7b60ae7b8efc) C:\Windows\system32\drivers\HpSAMD.sys
13:26:23.0229 3632 HpSAMD - ok
13:26:23.0350 3632 HTTP (0ea7de1acb728dd5a369fd742d6eee28) C:\Windows\system32\drivers\HTTP.sys
13:26:23.0365 3632 HTTP - ok
13:26:23.0436 3632 huawei_enumerator - ok
13:26:23.0547 3632 hwdatacard - ok
13:26:23.0650 3632 hwpolicy (a5462bd6884960c9dc85ed49d34ff392) C:\Windows\system32\drivers\hwpolicy.sys
13:26:23.0652 3632 hwpolicy - ok
13:26:23.0741 3632 i8042prt (fa55c73d4affa7ee23ac4be53b4592d3) C:\Windows\system32\drivers\i8042prt.sys
13:26:23.0752 3632 i8042prt - ok
13:26:23.0844 3632 iaStor (631fa8935163b01fc0c02966cb3adb92) C:\Windows\system32\drivers\iaStor.sys
13:26:23.0850 3632 iaStor - ok
13:26:23.0984 3632 iaStorV (aaaf44db3bd0b9d1fb6969b23ecc8366) C:\Windows\system32\drivers\iaStorV.sys
13:26:24.0000 3632 iaStorV - ok
13:26:24.0260 3632 igfx (b36e6868cf289040795c1fa0d0feb399) C:\Windows\system32\DRIVERS\igdkmd64.sys
13:26:24.0451 3632 igfx - ok
13:26:24.0551 3632 iirsp (5c18831c61933628f5bb0ea2675b9d21) C:\Windows\system32\drivers\iirsp.sys
13:26:24.0559 3632 iirsp - ok
13:26:24.0679 3632 Impcd (36fdf367a1dabff903e2214023d71368) C:\Windows\system32\drivers\Impcd.sys
13:26:24.0688 3632 Impcd - ok
13:26:24.0840 3632 IntcAzAudAddService (0f144e5f46cb9043004b5e84aa4bca6a) C:\Windows\system32\drivers\RTKVHD64.sys
13:26:24.0886 3632 IntcAzAudAddService - ok
13:26:24.0993 3632 IntcDAud (408b401cd7cdb075c7470b0ff7ba8d0b) C:\Windows\system32\DRIVERS\IntcDAud.sys
13:26:25.0005 3632 IntcDAud - ok
13:26:25.0096 3632 intelide (f00f20e70c6ec3aa366910083a0518aa) C:\Windows\system32\drivers\intelide.sys
13:26:25.0101 3632 intelide - ok
13:26:25.0196 3632 intelppm (ada036632c664caa754079041cf1f8c1) C:\Windows\system32\drivers\intelppm.sys
13:26:25.0199 3632 intelppm - ok
13:26:25.0304 3632 IpFilterDriver (c9f0e1bd74365a8771590e9008d22ab6) C:\Windows\system32\DRIVERS\ipfltdrv.sys
13:26:25.0313 3632 IpFilterDriver - ok
13:26:25.0411 3632 IPMIDRV (0fc1aea580957aa8817b8f305d18ca3a) C:\Windows\system32\drivers\IPMIDrv.sys
13:26:25.0420 3632 IPMIDRV - ok
13:26:25.0515 3632 IPNAT (af9b39a7e7b6caa203b3862582e9f2d0) C:\Windows\system32\drivers\ipnat.sys
13:26:25.0525 3632 IPNAT - ok
13:26:25.0622 3632 IRENUM (3abf5e7213eb28966d55d58b515d5ce9) C:\Windows\system32\drivers\irenum.sys
13:26:25.0627 3632 IRENUM - ok
13:26:25.0706 3632 isapnp (2f7b28dc3e1183e5eb418df55c204f38) C:\Windows\system32\drivers\isapnp.sys
13:26:25.0712 3632 isapnp - ok
13:26:25.0810 3632 iScsiPrt (d931d7309deb2317035b07c9f9e6b0bd) C:\Windows\system32\drivers\msiscsi.sys
13:26:25.0827 3632 iScsiPrt - ok
13:26:25.0919 3632 kbdclass (bc02336f1cba7dcc7d1213bb588a68a5) C:\Windows\system32\drivers\kbdclass.sys
13:26:25.0928 3632 kbdclass - ok
13:26:26.0031 3632 kbdhid (0705eff5b42a9db58548eec3b26bb484) C:\Windows\system32\drivers\kbdhid.sys
13:26:26.0037 3632 kbdhid - ok
13:26:26.0130 3632 KSecDD (ccd53b5bd33ce0c889e830d839c8b66e) C:\Windows\system32\Drivers\ksecdd.sys
13:26:26.0134 3632 KSecDD - ok
13:26:26.0225 3632 KSecPkg (9ff918a261752c12639e8ad4208d2c2f) C:\Windows\system32\Drivers\ksecpkg.sys
13:26:26.0229 3632 KSecPkg - ok
13:26:26.0321 3632 ksthunk (6869281e78cb31a43e969f06b57347c4) C:\Windows\system32\drivers\ksthunk.sys
13:26:26.0326 3632 ksthunk - ok
13:26:26.0434 3632 L1C (b4a3a05b0f9c81d098b96ab6aa915042) C:\Windows\system32\DRIVERS\L1C62x64.sys
13:26:26.0441 3632 L1C - ok
13:26:26.0554 3632 lltdio (1538831cf8ad2979a04c423779465827) C:\Windows\system32\DRIVERS\lltdio.sys
13:26:26.0561 3632 lltdio - ok
13:26:26.0713 3632 LSI_FC (1a93e54eb0ece102495a51266dcdb6a6) C:\Windows\system32\drivers\lsi_fc.sys
13:26:26.0722 3632 LSI_FC - ok
13:26:26.0826 3632 LSI_SAS (1047184a9fdc8bdbff857175875ee810) C:\Windows\system32\drivers\lsi_sas.sys
13:26:26.0835 3632 LSI_SAS - ok
13:26:26.0941 3632 LSI_SAS2 (30f5c0de1ee8b5bc9306c1f0e4a75f93) C:\Windows\system32\drivers\lsi_sas2.sys
13:26:26.0949 3632 LSI_SAS2 - ok
13:26:27.0055 3632 LSI_SCSI (0504eacaff0d3c8aed161c4b0d369d4a) C:\Windows\system32\drivers\lsi_scsi.sys
13:26:27.0064 3632 LSI_SCSI - ok
13:26:27.0167 3632 luafv (43d0f98e1d56ccddb0d5254cff7b356e) C:\Windows\system32\drivers\luafv.sys
13:26:27.0170 3632 luafv - ok
13:26:27.0258 3632 megasas (a55805f747c6edb6a9080d7c633bd0f4) C:\Windows\system32\drivers\megasas.sys
13:26:27.0265 3632 megasas - ok
13:26:27.0368 3632 MegaSR (baf74ce0072480c3b6b7c13b2a94d6b3) C:\Windows\system32\drivers\MegaSR.sys
13:26:27.0382 3632 MegaSR - ok
13:26:27.0479 3632 Modem (800ba92f7010378b09f9ed9270f07137) C:\Windows\system32\drivers\modem.sys
13:26:27.0480 3632 Modem - ok
13:26:27.0569 3632 monitor (b03d591dc7da45ece20b3b467e6aadaa) C:\Windows\system32\DRIVERS\monitor.sys
13:26:27.0570 3632 monitor - ok
13:26:27.0665 3632 mouclass (7d27ea49f3c1f687d357e77a470aea99) C:\Windows\system32\DRIVERS\mouclass.sys
13:26:27.0673 3632 mouclass - ok
13:26:27.0777 3632 mouhid (d3bf052c40b0c4166d9fd86a4288c1e6) C:\Windows\system32\DRIVERS\mouhid.sys
13:26:27.0783 3632 mouhid - ok
13:26:27.0916 3632 mountmgr (32e7a3d591d671a6df2db515a5cbe0fa) C:\Windows\system32\drivers\mountmgr.sys
13:26:27.0919 3632 mountmgr - ok
13:26:28.0009 3632 mpio (a44b420d30bd56e145d6a2bc8768ec58) C:\Windows\system32\drivers\mpio.sys
13:26:28.0023 3632 mpio - ok
13:26:28.0108 3632 mpsdrv (6c38c9e45ae0ea2fa5e551f2ed5e978f) C:\Windows\system32\drivers\mpsdrv.sys
13:26:28.0117 3632 mpsdrv - ok
13:26:28.0204 3632 MRxDAV (dc722758b8261e1abafd31a3c0a66380) C:\Windows\system32\drivers\mrxdav.sys
13:26:28.0214 3632 MRxDAV - ok
13:26:28.0313 3632 mrxsmb (a5d9106a73dc88564c825d317cac68ac) C:\Windows\system32\DRIVERS\mrxsmb.sys
13:26:28.0317 3632 mrxsmb - ok
13:26:28.0418 3632 mrxsmb10 (d711b3c1d5f42c0c2415687be09fc163) C:\Windows\system32\DRIVERS\mrxsmb10.sys
13:26:28.0424 3632 mrxsmb10 - ok
13:26:28.0514 3632 mrxsmb20 (9423e9d355c8d303e76b8cfbd8a5c30c) C:\Windows\system32\DRIVERS\mrxsmb20.sys
13:26:28.0518 3632 mrxsmb20 - ok
13:26:28.0617 3632 msahci (c25f0bafa182cbca2dd3c851c2e75796) C:\Windows\system32\drivers\msahci.sys
13:26:28.0623 3632 msahci - ok
13:26:28.0727 3632 msdsm (db801a638d011b9633829eb6f663c900) C:\Windows\system32\drivers\msdsm.sys
13:26:28.0738 3632 msdsm - ok
13:26:28.0849 3632 Msfs (aa3fb40e17ce1388fa1bedab50ea8f96) C:\Windows\system32\drivers\Msfs.sys
13:26:28.0851 3632 Msfs - ok
13:26:28.0941 3632 mshidkmdf (f9d215a46a8b9753f61767fa72a20326) C:\Windows\System32\drivers\mshidkmdf.sys
13:26:28.0945 3632 mshidkmdf - ok
13:26:28.0992 3632 msisadrv (d916874bbd4f8b07bfb7fa9b3ccae29d) C:\Windows\system32\drivers\msisadrv.sys
13:26:28.0993 3632 msisadrv - ok
13:26:29.0100 3632 MSKSSRV (49ccf2c4fea34ffad8b1b59d49439366) C:\Windows\system32\drivers\MSKSSRV.sys
13:26:29.0104 3632 MSKSSRV - ok
13:26:29.0207 3632 MSPCLOCK (bdd71ace35a232104ddd349ee70e1ab3) C:\Windows\system32\drivers\MSPCLOCK.sys
13:26:29.0211 3632 MSPCLOCK - ok
13:26:29.0305 3632 MSPQM (4ed981241db27c3383d72092b618a1d0) C:\Windows\system32\drivers\MSPQM.sys
13:26:29.0309 3632 MSPQM - ok
13:26:29.0415 3632 MsRPC (759a9eeb0fa9ed79da1fb7d4ef78866d) C:\Windows\system32\drivers\MsRPC.sys
13:26:29.0422 3632 MsRPC - ok
13:26:29.0504 3632 mssmbios (0eed230e37515a0eaee3c2e1bc97b288) C:\Windows\system32\drivers\mssmbios.sys
13:26:29.0506 3632 mssmbios - ok
13:26:29.0610 3632 MSTEE (2e66f9ecb30b4221a318c92ac2250779) C:\Windows\system32\drivers\MSTEE.sys
13:26:29.0616 3632 MSTEE - ok
13:26:29.0701 3632 MTConfig (7ea404308934e675bffde8edf0757bcd) C:\Windows\system32\drivers\MTConfig.sys
13:26:29.0707 3632 MTConfig - ok
13:26:29.0796 3632 Mup (f9a18612fd3526fe473c1bda678d61c8) C:\Windows\system32\Drivers\mup.sys
13:26:29.0798 3632 Mup - ok
13:26:29.0917 3632 NativeWifiP (1ea3749c4114db3e3161156ffffa6b33) C:\Windows\system32\DRIVERS\nwifi.sys
13:26:29.0932 3632 NativeWifiP - ok
13:26:30.0052 3632 NDIS (79b47fd40d9a817e932f9d26fac0a81c) C:\Windows\system32\drivers\ndis.sys
13:26:30.0069 3632 NDIS - ok
13:26:30.0160 3632 NdisCap (9f9a1f53aad7da4d6fef5bb73ab811ac) C:\Windows\system32\DRIVERS\ndiscap.sys
13:26:30.0166 3632 NdisCap - ok
13:26:30.0256 3632 NdisTapi (30639c932d9fef22b31268fe25a1b6e5) C:\Windows\system32\DRIVERS\ndistapi.sys
13:26:30.0260 3632 NdisTapi - ok
13:26:30.0356 3632 Ndisuio (136185f9fb2cc61e573e676aa5402356) C:\Windows\system32\DRIVERS\ndisuio.sys
13:26:30.0364 3632 Ndisuio - ok
13:26:30.0406 3632 NdisWan (53f7305169863f0a2bddc49e116c2e11) C:\Windows\system32\DRIVERS\ndiswan.sys
13:26:30.0416 3632 NdisWan - ok
13:26:30.0507 3632 NDProxy (015c0d8e0e0421b4cfd48cffe2825879) C:\Windows\system32\drivers\NDProxy.sys
13:26:30.0515 3632 NDProxy - ok
13:26:30.0610 3632 NetBIOS (86743d9f5d2b1048062b14b1d84501c4) C:\Windows\system32\DRIVERS\netbios.sys
13:26:30.0616 3632 NetBIOS - ok
13:26:30.0708 3632 NetBT (09594d1089c523423b32a4229263f068) C:\Windows\system32\DRIVERS\netbt.sys
13:26:30.0712 3632 NetBT - ok
13:26:31.0033 3632 NETw5s64 (4d85a450edef10c38882182753a49aae) C:\Windows\system32\DRIVERS\NETw5s64.sys
13:26:31.0221 3632 NETw5s64 - ok
13:26:31.0319 3632 nfrd960 (77889813be4d166cdab78ddba990da92) C:\Windows\system32\drivers\nfrd960.sys
13:26:31.0327 3632 nfrd960 - ok
13:26:31.0417 3632 Npfs (1e4c4ab5c9b8dd13179bbdc75a2a01f7) C:\Windows\system32\drivers\Npfs.sys
13:26:31.0419 3632 Npfs - ok
13:26:31.0520 3632 NPPTNT2 - ok
13:26:31.0567 3632 nsiproxy (e7f5ae18af4168178a642a9247c63001) C:\Windows\system32\drivers\nsiproxy.sys
13:26:31.0568 3632 nsiproxy - ok
13:26:31.0700 3632 Ntfs (a2f74975097f52a00745f9637451fdd8) C:\Windows\system32\drivers\Ntfs.sys
13:26:31.0729 3632 Ntfs - ok
13:26:31.0816 3632 Null (9899284589f75fa8724ff3d16aed75c1) C:\Windows\system32\drivers\Null.sys
13:26:31.0819 3632 Null - ok
13:26:31.0913 3632 NVHDA (ad37248bd442d41c9a896e53eb8a85ee) C:\Windows\system32\drivers\nvhda64v.sys
13:26:31.0923 3632 NVHDA - ok
13:26:32.0249 3632 nvlddmkm (ca8447574e9dae22250c723819d3ef96) C:\Windows\system32\DRIVERS\nvlddmkm.sys
13:26:32.0582 3632 nvlddmkm - ok
13:26:32.0687 3632 nvraid (0a92cb65770442ed0dc44834632f66ad) C:\Windows\system32\drivers\nvraid.sys
13:26:32.0697 3632 nvraid - ok
13:26:32.0806 3632 nvstor (dab0e87525c10052bf65f06152f37e4a) C:\Windows\system32\drivers\nvstor.sys
13:26:32.0817 3632 nvstor - ok
13:26:32.0917 3632 nv_agp (270d7cd42d6e3979f6dd0146650f0e05) C:\Windows\system32\drivers\nv_agp.sys
13:26:32.0928 3632 nv_agp - ok
13:26:33.0040 3632 ohci1394 (3589478e4b22ce21b41fa1bfc0b8b8a0) C:\Windows\system32\drivers\ohci1394.sys
13:26:33.0049 3632 ohci1394 - ok
13:26:33.0178 3632 Parport (0086431c29c35be1dbc43f52cc273887) C:\Windows\system32\drivers\parport.sys
13:26:33.0187 3632 Parport - ok
13:26:33.0279 3632 partmgr (871eadac56b0a4c6512bbe32753ccf79) C:\Windows\system32\drivers\partmgr.sys
13:26:33.0289 3632 partmgr - ok
13:26:33.0371 3632 pci (94575c0571d1462a0f70bde6bd6ee6b3) C:\Windows\system32\drivers\pci.sys
13:26:33.0376 3632 pci - ok
13:26:33.0474 3632 pciide (b5b8b5ef2e5cb34df8dcf8831e3534fa) C:\Windows\system32\drivers\pciide.sys
13:26:33.0479 3632 pciide - ok
13:26:33.0581 3632 pcmcia (b2e81d4e87ce48589f98cb8c05b01f2f) C:\Windows\system32\drivers\pcmcia.sys
13:26:33.0595 3632 pcmcia - ok
13:26:33.0684 3632 pcw (d6b9c2e1a11a3a4b26a182ffef18f603) C:\Windows\system32\drivers\pcw.sys
13:26:33.0692 3632 pcw - ok
13:26:33.0785 3632 PEAUTH (68769c3356b3be5d1c732c97b9a80d6e) C:\Windows\system32\drivers\peauth.sys
13:26:33.0812 3632 PEAUTH - ok
13:26:33.0953 3632 PptpMiniport (f92a2c41117a11a00be01ca01a7fcde9) C:\Windows\system32\DRIVERS\raspptp.sys
13:26:33.0963 3632 PptpMiniport - ok
13:26:34.0052 3632 Processor (0d922e23c041efb1c3fac2a6f943c9bf) C:\Windows\system32\drivers\processr.sys
13:26:34.0061 3632 Processor - ok
13:26:34.0165 3632 Psched (0557cf5a2556bd58e26384169d72438d) C:\Windows\system32\DRIVERS\pacer.sys
13:26:34.0168 3632 Psched - ok
13:26:34.0260 3632 PxHlpa64 (87b04878a6d59d6c79251dc960c674c1) C:\Windows\system32\Drivers\PxHlpa64.sys
13:26:34.0263 3632 PxHlpa64 - ok
13:26:34.0366 3632 qcfilterSny2k (fd79acb284b6bb288c8826fff72778e9) C:\Windows\system32\DRIVERS\qcfilterSny2k.sys
13:26:34.0367 3632 qcfilterSny2k - ok
13:26:34.0478 3632 qcusbnetsny2k (d4168d8bebcf573b8ffb2a0c09094da3) C:\Windows\system32\DRIVERS\qcusbnetsny2k.sys
13:26:34.0481 3632 qcusbnetsny2k - ok
13:26:34.0567 3632 qcusbsersny2k (3a5625922508a972345f096cb163d55b) C:\Windows\system32\DRIVERS\qcusbserSny2k.sys
13:26:34.0569 3632 qcusbsersny2k - ok
13:26:34.0715 3632 ql2300 (a53a15a11ebfd21077463ee2c7afeef0) C:\Windows\system32\drivers\ql2300.sys
13:26:34.0750 3632 ql2300 - ok
13:26:34.0839 3632 ql40xx (4f6d12b51de1aaeff7dc58c4d75423c8) C:\Windows\system32\drivers\ql40xx.sys
13:26:34.0849 3632 ql40xx - ok
13:26:34.0938 3632 QWAVEdrv (76707bb36430888d9ce9d705398adb6c) C:\Windows\system32\drivers\qwavedrv.sys
13:26:34.0945 3632 QWAVEdrv - ok
13:26:35.0028 3632 RasAcd (5a0da8ad5762fa2d91678a8a01311704) C:\Windows\system32\DRIVERS\rasacd.sys
13:26:35.0032 3632 RasAcd - ok
13:26:35.0123 3632 RasAgileVpn (7ecff9b22276b73f43a99a15a6094e90) C:\Windows\system32\DRIVERS\AgileVpn.sys
13:26:35.0131 3632 RasAgileVpn - ok
13:26:35.0233 3632 Rasl2tp (471815800ae33e6f1c32fb1b97c490ca) C:\Windows\system32\DRIVERS\rasl2tp.sys
13:26:35.0244 3632 Rasl2tp - ok
13:26:35.0347 3632 RasPppoe (855c9b1cd4756c5e9a2aa58a15f58c25) C:\Windows\system32\DRIVERS\raspppoe.sys
13:26:35.0356 3632 RasPppoe - ok
13:26:35.0451 3632 RasSstp (e8b1e447b008d07ff47d016c2b0eeecb) C:\Windows\system32\DRIVERS\rassstp.sys
13:26:35.0461 3632 RasSstp - ok
13:26:35.0563 3632 rdbss (77f665941019a1594d887a74f301fa2f) C:\Windows\system32\DRIVERS\rdbss.sys
13:26:35.0570 3632 rdbss - ok
13:26:35.0610 3632 rdpbus (302da2a0539f2cf54d7c6cc30c1f2d8d) C:\Windows\system32\DRIVERS\rdpbus.sys
13:26:35.0615 3632 rdpbus - ok
13:26:35.0704 3632 RDPCDD (cea6cc257fc9b7715f1c2b4849286d24) C:\Windows\system32\DRIVERS\RDPCDD.sys
13:26:35.0705 3632 RDPCDD - ok
13:26:35.0809 3632 RDPDR (1b6163c503398b23ff8b939c67747683) C:\Windows\system32\drivers\rdpdr.sys
13:26:35.0819 3632 RDPDR - ok
13:26:35.0905 3632 RDPENCDD (bb5971a4f00659529a5c44831af22365) C:\Windows\system32\drivers\rdpencdd.sys
13:26:35.0906 3632 RDPENCDD - ok
13:26:36.0000 3632 RDPREFMP (216f3fa57533d98e1f74ded70113177a) C:\Windows\system32\drivers\rdprefmp.sys
13:26:36.0001 3632 RDPREFMP - ok
13:26:36.0098 3632 RDPWD (15b66c206b5cb095bab980553f38ed23) C:\Windows\system32\drivers\RDPWD.sys
13:26:36.0109 3632 RDPWD - ok
13:26:36.0211 3632 rdyboost (34ed295fa0121c241bfef24764fc4520) C:\Windows\system32\drivers\rdyboost.sys
13:26:36.0215 3632 rdyboost - ok
13:26:36.0331 3632 RFCOMM (3dd798846e2c28102b922c56e71b7932) C:\Windows\system32\DRIVERS\rfcomm.sys
13:26:36.0340 3632 RFCOMM - ok
13:26:36.0434 3632 rimspci (5ca4abd888b602551b59baa26941c167) C:\Windows\system32\drivers\rimssne64.sys
13:26:36.0442 3632 rimspci - ok
13:26:36.0532 3632 risdsnpe (aa7b4ac7cb1281349cd61de067f00d5d) C:\Windows\system32\drivers\risdsne64.sys
13:26:36.0539 3632 risdsnpe - ok
13:26:36.0665 3632 rspndr (ddc86e4f8e7456261e637e3552e804ff) C:\Windows\system32\DRIVERS\rspndr.sys
13:26:36.0673 3632 rspndr - ok
13:26:36.0770 3632 s3cap (e60c0a09f997826c7627b244195ab581) C:\Windows\system32\drivers\vms3cap.sys
13:26:36.0775 3632 s3cap - ok
13:26:36.0887 3632 sbp2port (ac03af3329579fffb455aa2daabbe22b) C:\Windows\system32\drivers\sbp2port.sys
13:26:36.0896 3632 sbp2port - ok
13:26:36.0983 3632 scfilter (253f38d0d7074c02ff8deb9836c97d2b) C:\Windows\system32\DRIVERS\scfilter.sys
13:26:36.0991 3632 scfilter - ok
13:26:37.0105 3632 sdbus (111e0ebc0ad79cb0fa014b907b231cf0) C:\Windows\system32\drivers\sdbus.sys
13:26:37.0115 3632 sdbus - ok
13:26:37.0205 3632 secdrv (3ea8a16169c26afbeb544e0e48421186) C:\Windows\system32\drivers\secdrv.sys
13:26:37.0211 3632 secdrv - ok
13:26:37.0309 3632 Serenum (cb624c0035412af0debec78c41f5ca1b) C:\Windows\system32\drivers\serenum.sys
13:26:37.0314 3632 Serenum - ok
13:26:37.0411 3632 Serial (c1d8e28b2c2adfaec4ba89e9fda69bd6) C:\Windows\system32\drivers\serial.sys
13:26:37.0421 3632 Serial - ok
13:26:37.0509 3632 sermouse (1c545a7d0691cc4a027396535691c3e3) C:\Windows\system32\drivers\sermouse.sys
13:26:37.0514 3632 sermouse - ok
13:26:37.0616 3632 SFEP (70f9c476b62de4f2823e918a6c181ade) C:\Windows\system32\drivers\SFEP.sys
13:26:37.0623 3632 SFEP - ok
13:26:37.0718 3632 sffdisk (a554811bcd09279536440c964ae35bbf) C:\Windows\system32\drivers\sffdisk.sys
13:26:37.0723 3632 sffdisk - ok
13:26:37.0807 3632 sffp_mmc (ff414f0baefeba59bc6c04b3db0b87bf) C:\Windows\system32\drivers\sffp_mmc.sys
13:26:37.0814 3632 sffp_mmc - ok
13:26:37.0905 3632 sffp_sd (dd85b78243a19b59f0637dcf284da63c) C:\Windows\system32\drivers\sffp_sd.sys
13:26:37.0910 3632 sffp_sd - ok
13:26:38.0002 3632 sfloppy (a9d601643a1647211a1ee2ec4e433ff4) C:\Windows\system32\drivers\sfloppy.sys
13:26:38.0007 3632 sfloppy - ok
13:26:38.0109 3632 shpf (c06ccd29f5c15b610237e86f82085e77) C:\Windows\system32\DRIVERS\shpf.sys
13:26:38.0116 3632 shpf - ok
13:26:38.0203 3632 SiSRaid2 (843caf1e5fde1ffd5ff768f23a51e2e1) C:\Windows\system32\drivers\SiSRaid2.sys
13:26:38.0212 3632 SiSRaid2 - ok
13:26:38.0294 3632 SiSRaid4 (6a6c106d42e9ffff8b9fcb4f754f6da4) C:\Windows\system32\drivers\sisraid4.sys
13:26:38.0303 3632 SiSRaid4 - ok
13:26:38.0398 3632 Smb (548260a7b8654e024dc30bf8a7c5baa4) C:\Windows\system32\DRIVERS\smb.sys
13:26:38.0407 3632 Smb - ok
13:26:38.0521 3632 spldr (b9e31e5cacdfe584f34f730a677803f9) C:\Windows\system32\drivers\spldr.sys
13:26:38.0527 3632 spldr - ok
13:26:38.0657 3632 srv (441fba48bff01fdb9d5969ebc1838f0b) C:\Windows\system32\DRIVERS\srv.sys
13:26:38.0676 3632 srv - ok
13:26:38.0771 3632 srv2 (b4adebbf5e3677cce9651e0f01f7cc28) C:\Windows\system32\DRIVERS\srv2.sys
13:26:38.0780 3632 srv2 - ok
13:26:38.0881 3632 srvnet (27e461f0be5bff5fc737328f749538c3) C:\Windows\system32\DRIVERS\srvnet.sys
13:26:38.0885 3632 srvnet - ok
13:26:38.0989 3632 stexstor (f3817967ed533d08327dc73bc4d5542a) C:\Windows\system32\drivers\stexstor.sys
13:26:38.0996 3632 stexstor - ok
13:26:39.0093 3632 storflt (7785dc213270d2fc066538daf94087e7) C:\Windows\system32\drivers\vmstorfl.sys
13:26:39.0095 3632 storflt - ok
13:26:39.0192 3632 storvsc (d34e4943d5ac096c8edeebfd80d76e23) C:\Windows\system32\drivers\storvsc.sys
13:26:39.0199 3632 storvsc - ok
13:26:39.0287 3632 swenum (d01ec09b6711a5f8e7e6564a4d0fbc90) C:\Windows\system32\drivers\swenum.sys
13:26:39.0293 3632 swenum - ok
13:26:39.0380 3632 SynTP (2f827bb08cc7f1a17df2ead7b424d731) C:\Windows\system32\DRIVERS\SynTP.sys
13:26:39.0395 3632 SynTP - ok
13:26:39.0556 3632 Tcpip (fc62769e7bff2896035aeed399108162) C:\Windows\system32\drivers\tcpip.sys
13:26:39.0590 3632 Tcpip - ok
13:26:39.0733 3632 TCPIP6 (fc62769e7bff2896035aeed399108162) C:\Windows\system32\DRIVERS\tcpip.sys
13:26:39.0750 3632 TCPIP6 - ok
13:26:39.0843 3632 tcpipreg (df687e3d8836bfb04fcc0615bf15a519) C:\Windows\system32\drivers\tcpipreg.sys
13:26:39.0850 3632 tcpipreg - ok
13:26:39.0955 3632 TDPIPE (3371d21011695b16333a3934340c4e7c) C:\Windows\system32\drivers\tdpipe.sys
13:26:39.0959 3632 TDPIPE - ok
13:26:40.0044 3632 TDTCP (e4245bda3190a582d55ed09e137401a9) C:\Windows\system32\drivers\tdtcp.sys
13:26:40.0049 3632 TDTCP - ok
13:26:40.0138 3632 tdx (ddad5a7ab24d8b65f8d724f5c20fd806) C:\Windows\system32\DRIVERS\tdx.sys
13:26:40.0147 3632 tdx - ok
13:26:40.0246 3632 TermDD (561e7e1f06895d78de991e01dd0fb6e5) C:\Windows\system32\drivers\termdd.sys
13:26:40.0255 3632 TermDD - ok
13:26:40.0371 3632 tssecsrv (ce18b2cdfc837c99e5fae9ca6cba5d30) C:\Windows\system32\DRIVERS\tssecsrv.sys
13:26:40.0378 3632 tssecsrv - ok
13:26:40.0489 3632 TsUsbFlt (d11c783e3ef9a3c52c0ebe83cc5000e9) C:\Windows\system32\drivers\tsusbflt.sys
13:26:40.0499 3632 TsUsbFlt - ok
13:26:40.0600 3632 tunnel (3566a8daafa27af944f5d705eaa64894) C:\Windows\system32\DRIVERS\tunnel.sys
13:26:40.0610 3632 tunnel - ok
13:26:40.0698 3632 uagp35 (b4dd609bd7e282bfc683cec7eaaaad67) C:\Windows\system32\drivers\uagp35.sys
13:26:40.0707 3632 uagp35 - ok
13:26:40.0813 3632 udfs (ff4232a1a64012baa1fd97c7b67df593) C:\Windows\system32\DRIVERS\udfs.sys
13:26:40.0827 3632 udfs - ok
13:26:40.0872 3632 uliagpkx (4bfe1bc28391222894cbf1e7d0e42320) C:\Windows\system32\drivers\uliagpkx.sys
13:26:40.0881 3632 uliagpkx - ok
13:26:40.0985 3632 umbus (dc54a574663a895c8763af0fa1ff7561) C:\Windows\system32\drivers\umbus.sys
13:26:40.0993 3632 umbus - ok
13:26:41.0097 3632 UmPass (b2e8e8cb557b156da5493bbddcc1474d) C:\Windows\system32\drivers\umpass.sys
13:26:41.0102 3632 UmPass - ok
13:26:41.0212 3632 usbccgp (6f1a3157a1c89435352ceb543cdb359c) C:\Windows\system32\DRIVERS\usbccgp.sys
13:26:41.0221 3632 usbccgp - ok
13:26:41.0324 3632 usbcir (af0892a803fdda7492f595368e3b68e7) C:\Windows\system32\drivers\usbcir.sys
13:26:41.0337 3632 usbcir - ok
13:26:41.0435 3632 usbehci (c025055fe7b87701eb042095df1a2d7b) C:\Windows\system32\drivers\usbehci.sys
13:26:41.0442 3632 usbehci - ok
13:26:41.0544 3632 usbhub (287c6c9410b111b68b52ca298f7b8c24) C:\Windows\system32\DRIVERS\usbhub.sys
13:26:41.0551 3632 usbhub - ok
13:26:41.0652 3632 usbohci (9840fc418b4cbd632d3d0a667a725c31) C:\Windows\system32\drivers\usbohci.sys
13:26:41.0658 3632 usbohci - ok
13:26:41.0754 3632 usbprint (73188f58fb384e75c4063d29413cee3d) C:\Windows\system32\DRIVERS\usbprint.sys
13:26:41.0760 3632 usbprint - ok
13:26:41.0846 3632 USBSTOR (fed648b01349a3c8395a5169db5fb7d6) C:\Windows\system32\DRIVERS\USBSTOR.SYS
13:26:41.0849 3632 USBSTOR - ok
13:26:41.0943 3632 usbuhci (62069a34518bcf9c1fd9e74b3f6db7cd) C:\Windows\system32\drivers\usbuhci.sys
13:26:41.0949 3632 usbuhci - ok
13:26:42.0051 3632 usbvideo (454800c2bc7f3927ce030141ee4f4c50) C:\Windows\System32\Drivers\usbvideo.sys
13:26:42.0058 3632 usbvideo - ok
13:26:42.0189 3632 vdrvroot (c5c876ccfc083ff3b128f933823e87bd) C:\Windows\system32\drivers\vdrvroot.sys
13:26:42.0191 3632 vdrvroot - ok
13:26:42.0300 3632 vga (da4da3f5e02943c2dc8c6ed875de68dd) C:\Windows\system32\DRIVERS\vgapnp.sys
13:26:42.0304 3632 vga - ok
13:26:42.0388 3632 VgaSave (53e92a310193cb3c03bea963de7d9cfc) C:\Windows\System32\drivers\vga.sys
13:26:42.0394 3632 VgaSave - ok
13:26:42.0493 3632 vhdmp (2ce2df28c83aeaf30084e1b1eb253cbb) C:\Windows\system32\drivers\vhdmp.sys
13:26:42.0507 3632 vhdmp - ok
13:26:42.0595 3632 viaide (e5689d93ffe4e5d66c0178761240dd54) C:\Windows\system32\drivers\viaide.sys
13:26:42.0599 3632 viaide - ok
13:26:42.0718 3632 vmbus (86ea3e79ae350fea5331a1303054005f) C:\Windows\system32\drivers\vmbus.sys
13:26:42.0728 3632 vmbus - ok
13:26:42.0849 3632 VMBusHID (7de90b48f210d29649380545db45a187) C:\Windows\system32\drivers\VMBusHID.sys
13:26:42.0853 3632 VMBusHID - ok
13:26:42.0877 3632 volmgr (d2aafd421940f640b407aefaaebd91b0) C:\Windows\system32\drivers\volmgr.sys
13:26:42.0879 3632 volmgr - ok
13:26:42.0968 3632 volmgrx (a255814907c89be58b79ef2f189b843b) C:\Windows\system32\drivers\volmgrx.sys
13:26:42.0973 3632 volmgrx - ok
13:26:43.0022 3632 volsnap (0d08d2f3b3ff84e433346669b5e0f639) C:\Windows\system32\drivers\volsnap.sys
13:26:43.0026 3632 volsnap - ok
13:26:43.0121 3632 vsmraid (5e2016ea6ebaca03c04feac5f330d997) C:\Windows\system32\drivers\vsmraid.sys
13:26:43.0129 3632 vsmraid - ok
13:26:43.0229 3632 vwifibus (36d4720b72b5c5d9cb2b9c29e9df67a1) C:\Windows\system32\DRIVERS\vwifibus.sys
13:26:43.0234 3632 vwifibus - ok
13:26:43.0324 3632 vwififlt (6a3d66263414ff0d6fa754c646612f3f) C:\Windows\system32\DRIVERS\vwififlt.sys
13:26:43.0331 3632 vwififlt - ok
13:26:43.0417 3632 vwifimp (6a638fc4bfddc4d9b186c28c91bd1a01) C:\Windows\system32\DRIVERS\vwifimp.sys
13:26:43.0422 3632 vwifimp - ok
13:26:43.0523 3632 WacomPen (4e9440f4f152a7b944cb1663d3935a3e) C:\Windows\system32\drivers\wacompen.sys
13:26:43.0530 3632 WacomPen - ok
13:26:43.0646 3632 WANARP (356afd78a6ed4457169241ac3965230c) C:\Windows\system32\DRIVERS\wanarp.sys
13:26:43.0655 3632 WANARP - ok
13:26:43.0674 3632 Wanarpv6 (356afd78a6ed4457169241ac3965230c) C:\Windows\system32\DRIVERS\wanarp.sys
13:26:43.0675 3632 Wanarpv6 - ok
13:26:43.0795 3632 Wd (72889e16ff12ba0f235467d6091b17dc) C:\Windows\system32\drivers\wd.sys
13:26:43.0801 3632 Wd - ok
13:26:43.0906 3632 WDC_SAM (a3d04ebf5227886029b4532f20d026f7) C:\Windows\system32\DRIVERS\wdcsam64.sys
13:26:43.0911 3632 WDC_SAM - ok
13:26:44.0011 3632 Wdf01000 (441bd2d7b4f98134c3a4f9fa570fd250) C:\Windows\system32\drivers\Wdf01000.sys
13:26:44.0033 3632 Wdf01000 - ok
13:26:44.0150 3632 WfpLwf (611b23304bf067451a9fdee01fbdd725) C:\Windows\system32\DRIVERS\wfplwf.sys
13:26:44.0155 3632 WfpLwf - ok
13:26:44.0259 3632 WIMMount (05ecaec3e4529a7153b3136ceb49f0ec) C:\Windows\system32\drivers\wimmount.sys
13:26:44.0265 3632 WIMMount - ok
13:26:44.0401 3632 WinUsb (fe88b288356e7b47b74b13372add906d) C:\Windows\system32\DRIVERS\WinUSB.sys
13:26:44.0411 3632 WinUsb - ok
13:26:44.0484 3632 WmiAcpi (f6ff8944478594d0e414d3f048f0d778) C:\Windows\system32\drivers\wmiacpi.sys
13:26:44.0486 3632 WmiAcpi - ok
13:26:44.0606 3632 ws2ifsl (6bcc1d7d2fd2453957c5479a32364e52) C:\Windows\system32\drivers\ws2ifsl.sys
13:26:44.0612 3632 ws2ifsl - ok
13:26:44.0740 3632 WudfPf (d3381dc54c34d79b22cee0d65ba91b7c) C:\Windows\system32\drivers\WudfPf.sys
13:26:44.0748 3632 WudfPf - ok
13:26:44.0864 3632 WUDFRd (cf8d590be3373029d57af80914190682) C:\Windows\system32\DRIVERS\WUDFRd.sys
13:26:44.0874 3632 WUDFRd - ok
13:26:44.0931 3632 MBR (0x1B8) (a36c5e4f47e84449ff07ed3517b43a31) \Device\Harddisk0\DR0
13:26:44.0995 3632 \Device\Harddisk0\DR0 - ok
13:26:44.0999 3632 Boot (0x1200) (daa3dcd9f2fa1d0f5af1101a49c55de9) \Device\Harddisk0\DR0\Partition0
13:26:45.0000 3632 \Device\Harddisk0\DR0\Partition0 - ok
13:26:45.0025 3632 Boot (0x1200) (09a0946557cecf243bed7398c77c59db) \Device\Harddisk0\DR0\Partition1
13:26:45.0026 3632 \Device\Harddisk0\DR0\Partition1 - ok
13:26:45.0049 3632 Boot (0x1200) (f4865799fdf498dd679ea56f2063ccda) \Device\Harddisk0\DR0\Partition2
13:26:45.0050 3632 \Device\Harddisk0\DR0\Partition2 - ok
13:26:45.0051 3632 ============================================================
13:26:45.0051 3632 Scan finished
13:26:45.0051 3632 ============================================================
13:26:45.0062 5488 Detected object count: 0
13:26:45.0062 5488 Actual detected object count: 0
0
Malekal_morte- Messages postés 180304 Date d'inscription mercredi 17 mai 2006 Statut Modérateur, Contributeur sécurité Dernière intervention 15 décembre 2020 24 631
31 janv. 2012 à 14:35
OK 64bits...
donc conserv.dll..

Sauvegarde tes documents importants.
A lire en entier.


Désactive les logiciels de protection (Antivirus, Antispywares)
En Général, cela se fait par un clic droit sur l'icône de ton antivirus en bas à droite et désactiver protection/agent ou autres.

ensuite :

Télécharge Combofix sUBs : http://download.bleepingcomputer.com/sUBs/ComboFix.exe et sauvegarde le sur ton bureau et pas ailleurs!

Double-clic sur combofix, accepte la licence d'utilisation et laisse toi guider.

Eventuellement, installe la console de récupération comme cela est conseillé

Attends que combofix ait terminé, un rapport sera créé. Poste le rapport.
Si le rapport ne passe pas, envoie le sur ce site : http://pjjoint.malekal.com/
et donne le lien ici :)

Tu as le tutorial sur ce lien pour t'aider : https://www.bleepingcomputer.com/combofix/fr/comment-utiliser-combofix

PS : si Combofix ne se lance pas, renomme le fichier Combofix et retente.

Si pas mieux, tente en mode sans échec sans prise en charge du réseau : Redémarre en mode sans échec, pour cela, redémarre l'ordinateur, avant le logo Windows, tapote sur la touche F8, un menu va apparaître, choisis Mode sans échec et appuye sur la touche entrée du clavier.

Si Combofix émet toujours une alerte sur l'antivirus : Si tu es en mode sans échec continue, si tu es en mode normal et que l'antivirus est bien désactivé. Continue.
Hébergement du rapport : Utilise le site http://pjjoint.malekal.com/ pour envoyer le rapport, donne le lien pjjoint qui pointent vers ce rapport dans un nouveau message.
0
Voila le report combofix :

ComboFix 12-01-30.02 - Theo 31/01/2012 13:38:28.1.4 - x64
Microsoft Windows 7 Professionnel 6.1.7601.1.1252.33.1036.18.3959.2482 [GMT 1:00]
Lancé depuis: c:\users\Theo\Desktop\ComboFix.exe
AV: Avira Desktop *Disabled/Updated* {F67B4DE5-C0B4-6C3F-0EFF-6C83BD5D0C2C}
SP: Avira Desktop *Disabled/Updated* {4D1AAC01-E68E-63B1-344F-57F1C6DA4691}
SP: Windows Defender *Enabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
* Un nouveau point de restauration a été créé
.
.
(((((((((((((((((((((((((((((((((((( Autres suppressions ))))))))))))))))))))))))))))))))))))))))))))))))
.
.
c:\users\Theo\AppData\Local\1cf7f44e\U
c:\users\Theo\AppData\Local\1cf7f44e\U\80000000.@
c:\users\Theo\AppData\Local\1cf7f44e\U\800000cb.@
c:\users\Theo\AppData\Local\1cf7f44e\U\800000cf.@
c:\users\Theo\AppData\Local\1cf7f44e\X
c:\windows\system32\java.exe
c:\windows\SysWow64\ijl11.dll
.
.
((((((((((((((((((((((((((((( Fichiers créés du 2011-12-28 au 2012-01-31 ))))))))))))))))))))))))))))))))))))
.
.
2012-01-31 12:42 . 2012-01-31 12:42 -------- d-----w- c:\users\Default\AppData\Local\temp
2012-01-30 23:35 . 2012-01-30 23:35 -------- d-----w- c:\program files (x86)\Common Files\Java
2012-01-30 23:19 . 2012-01-30 23:19 -------- d-----w- c:\users\Theo\AppData\Roaming\Malwarebytes
2012-01-30 23:19 . 2012-01-30 23:19 -------- d-----w- c:\programdata\Malwarebytes
2012-01-30 23:19 . 2012-01-30 23:19 -------- d-----w- c:\program files (x86)\Malwarebytes' Anti-Malware
2012-01-30 23:19 . 2011-12-10 14:24 23152 ----a-w- c:\windows\system32\drivers\mbam.sys
2012-01-30 22:57 . 2012-01-30 22:57 -------- d-----w- c:\program files (x86)\Ad-Remover
2012-01-30 17:32 . 2012-01-30 23:38 -------- d-----w- C:\ZHP
2012-01-30 17:32 . 2012-01-30 23:38 -------- d-----w- c:\program files (x86)\ZHPDiag
2012-01-30 16:39 . 2011-11-17 06:41 1731920 ----a-w- c:\windows\system32\ntdll.dll
2012-01-30 16:39 . 2011-11-17 05:38 1292080 ----a-w- c:\windows\SysWow64\ntdll.dll
2012-01-30 16:39 . 2011-10-26 05:25 1572864 ----a-w- c:\windows\system32\quartz.dll
2012-01-30 16:39 . 2011-10-26 05:25 366592 ----a-w- c:\windows\system32\qdvd.dll
2012-01-30 16:39 . 2011-10-26 04:32 514560 ----a-w- c:\windows\SysWow64\qdvd.dll
2012-01-30 16:39 . 2011-10-26 04:32 1328128 ----a-w- c:\windows\SysWow64\quartz.dll
2012-01-30 16:39 . 2011-11-19 14:58 77312 ----a-w- c:\windows\system32\packager.dll
2012-01-30 16:39 . 2011-11-19 14:01 67072 ----a-w- c:\windows\SysWow64\packager.dll
2012-01-30 12:52 . 2012-01-30 12:52 69000 ----a-w- c:\programdata\Microsoft\Windows Defender\Definition Updates\{2435ECDF-B2E1-4C96-B8EA-8F58FC2F384F}\offreg.dll
2012-01-30 12:50 . 2012-01-06 05:15 8602168 ----a-w- c:\programdata\Microsoft\Windows Defender\Definition Updates\{2435ECDF-B2E1-4C96-B8EA-8F58FC2F384F}\mpengine.dll
2012-01-30 12:44 . 2012-01-30 12:44 -------- d-----w- c:\users\Theo\AppData\Roaming\f-secure
2012-01-30 12:43 . 2012-01-30 12:43 -------- d-----w- c:\programdata\F-Secure
2012-01-30 12:26 . 2012-01-30 12:26 -------- d-----w- c:\users\Theo\AppData\Local\PackageAware
2012-01-30 10:59 . 2012-01-31 12:41 -------- d-sh--w- c:\users\Theo\AppData\Local\1cf7f44e
2012-01-29 20:07 . 2012-01-29 20:07 237 ----a-w- C:\user.js
2012-01-20 08:45 . 2012-01-20 08:45 626688 ----a-w- c:\program files (x86)\Mozilla Firefox\msvcr80.dll
2012-01-20 08:45 . 2012-01-20 08:45 548864 ----a-w- c:\program files (x86)\Mozilla Firefox\msvcp80.dll
2012-01-20 08:45 . 2012-01-20 08:45 479232 ----a-w- c:\program files (x86)\Mozilla Firefox\msvcm80.dll
2012-01-20 08:45 . 2012-01-20 08:45 43992 ----a-w- c:\program files (x86)\Mozilla Firefox\mozutils.dll
2012-01-15 14:31 . 2012-01-15 14:31 -------- d-----w- c:\users\Theo\AppData\Roaming\Avira
2012-01-15 14:25 . 2011-12-16 08:51 97312 ----a-w- c:\windows\system32\drivers\avgntflt.sys
2012-01-15 14:25 . 2011-12-16 08:51 27760 ----a-w- c:\windows\system32\drivers\avkmgr.sys
2012-01-15 14:25 . 2011-12-16 08:51 130760 ----a-w- c:\windows\system32\drivers\avipbb.sys
2012-01-15 14:25 . 2012-01-15 14:25 -------- d-----w- c:\programdata\Avira
2012-01-15 14:25 . 2012-01-15 14:25 -------- d-----w- c:\program files (x86)\Avira
.
.
.
(((((((((((((((((((((((((((((((((( Compte-rendu de Find3M ))))))))))))))))))))))))))))))))))))))))))))))))
.
2011-12-07 09:39 . 2010-03-12 17:27 279096 ------w- c:\windows\system32\MpSigStub.exe
2011-11-24 04:52 . 2011-12-15 18:54 3145216 ----a-w- c:\windows\system32\win32k.sys
2011-11-10 04:54 . 2010-04-23 04:33 472808 ----a-w- c:\windows\SysWow64\deployJava1.dll
2011-11-05 05:41 . 2011-12-15 19:09 1188864 ----a-w- c:\windows\system32\wininet.dll
2011-11-05 05:32 . 2011-12-15 18:56 2048 ----a-w- c:\windows\system32\tzres.dll
2011-11-05 04:35 . 2011-12-15 19:09 981504 ----a-w- c:\windows\SysWow64\wininet.dll
2011-11-05 04:26 . 2011-12-15 18:56 2048 ----a-w- c:\windows\SysWow64\tzres.dll
2011-11-05 03:32 . 2011-12-15 19:09 1638912 ----a-w- c:\windows\system32\mshtml.tlb
2011-11-05 02:48 . 2011-12-15 19:09 1638912 ----a-w- c:\windows\SysWow64\mshtml.tlb
.
.
((((((((((((((((((((((((((((((((( Points de chargement Reg ))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* les éléments vides & les éléments initiaux légitimes ne sont pas listés
REGEDIT4
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt1]
@="{FB314ED9-A251-47B7-93E1-CDD82E34AF8B}"
[HKEY_CLASSES_ROOT\CLSID\{FB314ED9-A251-47B7-93E1-CDD82E34AF8B}]
2011-02-18 05:12 94208 ----a-w- c:\users\Theo\AppData\Roaming\Dropbox\bin\DropboxExt.14.dll
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt2]
@="{FB314EDA-A251-47B7-93E1-CDD82E34AF8B}"
[HKEY_CLASSES_ROOT\CLSID\{FB314EDA-A251-47B7-93E1-CDD82E34AF8B}]
2011-02-18 05:12 94208 ----a-w- c:\users\Theo\AppData\Roaming\Dropbox\bin\DropboxExt.14.dll
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt3]
@="{FB314EDB-A251-47B7-93E1-CDD82E34AF8B}"
[HKEY_CLASSES_ROOT\CLSID\{FB314EDB-A251-47B7-93E1-CDD82E34AF8B}]
2011-02-18 05:12 94208 ----a-w- c:\users\Theo\AppData\Roaming\Dropbox\bin\DropboxExt.14.dll
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run]
"IAStorIcon"="c:\program files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe" [2009-10-02 284696]
"ISBMgr.exe"="c:\program files (x86)\Sony\ISB Utility\ISBMgr.exe" [2009-08-26 320880]
"Adobe Reader Speed Launcher"="c:\program files (x86)\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2011-06-08 37296]
"Adobe ARM"="c:\program files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2011-03-30 937920]
"avgnt"="c:\program files (x86)\Avira\AntiVir Desktop\avgnt.exe" [2011-12-16 258512]
"SunJavaUpdateSched"="c:\program files (x86)\Common Files\Java\Java Update\jusched.exe" [2011-06-09 254696]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"ConsentPromptBehaviorAdmin"= 5 (0x5)
"ConsentPromptBehaviorUser"= 3 (0x3)
"EnableUIADesktopToggle"= 0 (0x0)
.
[HKEY_CURRENT_USER\software\microsoft\windows nt\currentversion\winlogon]
"Shell"="c:\users\Theo\AppData\Local\1cf7f44e\X"
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\VESWinlogon]
2009-11-30 18:20 98304 ----a-w- c:\windows\System32\VESWinlogon.dll
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows nt\currentversion\drivers32]
"mixer5"=wdmaud.drv
.
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\lsa]
Notification Packages REG_MULTI_SZ scecli c:\program files\Protector Suite\psqlpwd.dll
.
R2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;c:\windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-03-18 130384]
R2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;c:\windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [2010-03-18 138576]
R2 gupdate;Service Google Update (gupdate);c:\program files (x86)\Google\Update\GoogleUpdate.exe [2011-09-16 136176]
R2 Roxio Upnp Server 10;Roxio Upnp Server 10;c:\program files (x86)\Roxio\Digital Home 10\RoxioUpnpService10.exe [2009-08-31 362992]
R3 btusbflt;Bluetooth USB Filter;c:\windows\system32\drivers\btusbflt.sys [x]
R3 btwl2cap;Bluetooth L2CAP Service;c:\windows\system32\DRIVERS\btwl2cap.sys [x]
R3 dump_wmimmc;dump_wmimmc;z:\efusion\BlackShot\system\GameGuard\dump_wmimmc.sys [x]
R3 ew_hwusbdev;Huawei MobileBroadband USB PNP Device;c:\windows\system32\DRIVERS\ew_hwusbdev.sys [x]
R3 gupdatem;Service Google Update (gupdatem);c:\program files (x86)\Google\Update\GoogleUpdate.exe [2011-09-16 136176]
R3 huawei_enumerator;huawei_enumerator;c:\windows\system32\DRIVERS\ew_jubusenum.sys [x]
R3 IntcDAud;Intel(R) Display Audio;c:\windows\system32\DRIVERS\IntcDAud.sys [x]
R3 qcfilterSny2k;Gobi 2000 USB Composite Device Filter Driver(05C6-9225);c:\windows\system32\DRIVERS\qcfilterSny2k.sys [x]
R3 qcusbnetsny2k;Gobi 2000 USB-NDIS miniport(05C6-9225);c:\windows\system32\DRIVERS\qcusbnetsny2k.sys [x]
R3 qcusbsersny2k;Gobi 2000 USB Device for Legacy Serial Communication(05C6-9225);c:\windows\system32\DRIVERS\qcusbserSny2k.sys [x]
R3 Roxio UPnP Renderer 10;Roxio UPnP Renderer 10;c:\program files (x86)\Roxio\Digital Home 10\RoxioUPnPRenderer10.exe [2009-08-31 313840]
R3 TsUsbFlt;TsUsbFlt;c:\windows\system32\drivers\tsusbflt.sys [x]
R3 WatAdminSvc;Service Windows Activation Technologies;c:\windows\system32\Wat\WatAdminSvc.exe [x]
R3 WDC_SAM;WD SCSI Pass Thru driver;c:\windows\system32\DRIVERS\wdcsam64.sys [x]
S0 PxHlpa64;PxHlpa64;c:\windows\System32\Drivers\PxHlpa64.sys [x]
S0 shpf;Sony HDD Protection Filter Driver;c:\windows\system32\DRIVERS\shpf.sys [x]
S1 avkmgr;avkmgr;c:\windows\system32\DRIVERS\avkmgr.sys [x]
S1 vwififlt;Virtual WiFi Filter Driver;c:\windows\system32\DRIVERS\vwififlt.sys [x]
S2 AntiVirSchedulerService;Avira Planificateur;c:\program files (x86)\Avira\AntiVir Desktop\sched.exe [2011-12-16 86224]
S2 IAStorDataMgrSvc;Intel(R) Rapid Storage Technology;c:\program files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe [2009-10-02 13336]
S2 QDLService2kSony;Qualcomm Gobi 2000 Download Service (Sony);c:\program files (x86)\QUALCOMM\QDLService2k\QDLService2kSony.exe [2009-12-03 330488]
S2 rimspci;rimspci;c:\windows\system32\drivers\rimssne64.sys [x]
S2 risdsnpe;risdsnpe;c:\windows\system32\drivers\risdsne64.sys [x]
S2 SampleCollector;VAIO Care Performance Service;c:\program files\Sony\VAIO Care\VCPerfService.exe [2011-01-29 259192]
S2 UNS;Intel(R) Management & Security Application User Notification Service;c:\program files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe [2009-10-01 2314240]
S2 VSNService;VSNService;c:\program files\Sony\VAIO Smart Network\VSNService.exe [2010-08-11 845312]
S3 HECIx64;Intel(R) Management Engine Interface;c:\windows\system32\drivers\HECIx64.sys [x]
S3 Impcd;Impcd;c:\windows\system32\drivers\Impcd.sys [x]
S3 L1C;NDIS Miniport Driver for Atheros AR813x/AR815x PCI-E Ethernet Controller (NDIS 6.20);c:\windows\system32\DRIVERS\L1C62x64.sys [x]
S3 NETw5s64;Pilote de carte Intel(R) Wireless WiFi Link pour Windows 7 64 bits ;c:\windows\system32\DRIVERS\NETw5s64.sys [x]
S3 NVHDA;Service for NVIDIA High Definition Audio Driver;c:\windows\system32\drivers\nvhda64v.sys [x]
S3 SFEP;Sony Firmware Extension Parser;c:\windows\system32\drivers\SFEP.sys [x]
S3 VAIO Power Management;VAIO Power Management;c:\program files\Sony\VAIO Power Management\SPMService.exe [2009-11-30 571248]
S3 VCService;VCService;c:\program files\Sony\VAIO Care\VCService.exe [2011-02-14 44736]
S3 VUAgent;VUAgent;c:\program files\Sony\VAIO Update Common\VUAgent.exe [2011-09-23 1429608]
S3 vwifimp;Microsoft Virtual WiFi Miniport Service;c:\windows\system32\DRIVERS\vwifimp.sys [x]
.
.
--- Autres Services/Pilotes en mémoire ---
.
*NewlyCreated* - 41225749
*Deregistered* - 41225749
.
Contenu du dossier 'Tâches planifiées'
.
2012-01-31 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\program files (x86)\Google\Update\GoogleUpdate.exe [2011-09-16 18:52]
.
2012-01-31 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\program files (x86)\Google\Update\GoogleUpdate.exe [2011-09-16 18:52]
.
2012-01-31 c:\windows\Tasks\SyncBack Clients online.job
- c:\program files (x86)\2BrightSparks\SyncBack\SyncBack.exe [2010-03-14 09:21]
.
2012-01-31 c:\windows\Tasks\SyncBack Compta online.job
- c:\program files (x86)\2BrightSparks\SyncBack\SyncBack.exe [2010-03-14 09:21]
.
.
--------- x86-64 -----------
.
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt1]
@="{FB314ED9-A251-47B7-93E1-CDD82E34AF8B}"
[HKEY_CLASSES_ROOT\CLSID\{FB314ED9-A251-47B7-93E1-CDD82E34AF8B}]
2011-02-18 05:12 97792 ----a-w- c:\users\Theo\AppData\Roaming\Dropbox\bin\DropboxExt64.14.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt2]
@="{FB314EDA-A251-47B7-93E1-CDD82E34AF8B}"
[HKEY_CLASSES_ROOT\CLSID\{FB314EDA-A251-47B7-93E1-CDD82E34AF8B}]
2011-02-18 05:12 97792 ----a-w- c:\users\Theo\AppData\Roaming\Dropbox\bin\DropboxExt64.14.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt3]
@="{FB314EDB-A251-47B7-93E1-CDD82E34AF8B}"
[HKEY_CLASSES_ROOT\CLSID\{FB314EDB-A251-47B7-93E1-CDD82E34AF8B}]
2011-02-18 05:12 97792 ----a-w- c:\users\Theo\AppData\Roaming\Dropbox\bin\DropboxExt64.14.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\UEAFOverlay]
@="{F2F31467-B1AC-4df0-AE79-FD5FA085E22B}"
[HKEY_CLASSES_ROOT\CLSID\{F2F31467-B1AC-4df0-AE79-FD5FA085E22B}]
2009-07-20 13:18 5943048 ----a-w- c:\program files\Protector Suite\farchns.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\UEAFOverlayOpen]
@="{A3E208F7-0E3A-4182-A7A6-B169D5D691AA}"
[HKEY_CLASSES_ROOT\CLSID\{A3E208F7-0E3A-4182-A7A6-B169D5D691AA}]
2009-07-20 13:18 5943048 ----a-w- c:\program files\Protector Suite\farchns.dll
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"RtHDVCpl"="c:\program files\Realtek\Audio\HDA\RAVCpl64.exe" [2009-12-07 9636896]
"PSQLLauncher"="c:\program files\Protector Suite\launcher.exe" [2009-07-20 84744]
"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2010-01-11 16397416]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows]
"LoadAppInit_DLLs"=0x0
.
------- Examen supplémentaire -------
.
uLocal Page = c:\windows\system32\blank.htm
mLocal Page = c:\windows\SysWOW64\blank.htm
IE: E&xport to Microsoft Excel - c:\progra~2\MICROS~1\OFFICE11\EXCEL.EXE/3000
IE: E&xporter vers Microsoft Excel - c:\progra~2\MICROS~1\Office12\EXCEL.EXE/3000
IE: Envoyer au périphérique &Bluetooth... - c:\program files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
IE: Envoyer l'&image au périphérique Bluetooth... - c:\program files\WIDCOMM\Bluetooth Software\btsendto_ie_ctx.htm
TCP: DhcpNameServer = 80.58.61.250 80.58.61.254
FF - ProfilePath - c:\users\Theo\AppData\Roaming\Mozilla\Firefox\Profiles\bivakskl.default\
FF - prefs.js: browser.startup.homepage - www.google.fr
FF - prefs.js: keyword.URL - hxxp://es.search.yahoo.com/search?fr=greentree_ff1&ei=utf-8&ilc=12&type=302398&p=
.
- - - - ORPHELINS SUPPRIMES - - - -
.
SafeBoot-mcmscsvc
SafeBoot-MCODS
HKLM-Run-SynTPEnh - c:\program files (x86)\Synaptics\SynTP\SynTPEnh.exe
.
.
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\SampleCollector]
"ImagePath"="\"c:\program files\Sony\VAIO Care\VCPerfService.exe\" \"/service\" \"/sstates\" \"/sampleinterval=5000\" \"/procinterval=5\" \"/dllinterval=120\" \"/counter=\Processor(_Total)\% Processor Time:1/counter=\PhysicalDisk(_Total)\Disk Bytes/sec:1\" \"/counter=\Network Interface(*)\Bytes Total/sec:1\" \"/expandcounter=\Processor Information(*)\Processor Frequency:1\" \"/expandcounter=\Processor(*)\% Idle Time:1\" \"/expandcounter=\Processor(*)\% C1 Time:1\" \"/expandcounter=\Processor(*)\% C2 Time:1\" \"/expandcounter=\Processor(*)\% C3 Time:1\" \"/expandcounter=\Processor(*)\% Processor Time:1\" \"/directory=c:\programdata\Sony Corporation\VAIO Care\inteldata\""
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\npggsvc]
"ImagePath"="c:\windows\system32\GameMon.des -service"
.
--------------------- CLES DE REGISTRE BLOQUEES ---------------------
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{19114156-8E9A-4D4E-9EE9-17A0E48D3BBB}]
@Denied: (A 2) (Everyone)
@="FlashBroker"
"LocalizedString"="@c:\\Windows\\system32\\Macromed\\Flash\\FlashUtil10c.exe,-101"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{19114156-8E9A-4D4E-9EE9-17A0E48D3BBB}\Elevation]
"Enabled"=dword:00000001
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{19114156-8E9A-4D4E-9EE9-17A0E48D3BBB}\LocalServer32]
@="c:\\Windows\\SysWow64\\Macromed\\Flash\\FlashUtil10c.exe"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{19114156-8E9A-4D4E-9EE9-17A0E48D3BBB}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}]
@Denied: (A 2) (Everyone)
@="Shockwave Flash Object"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\InprocServer32]
@="c:\\Windows\\SysWow64\\Macromed\\Flash\\Flash10c.ocx"
"ThreadingModel"="Apartment"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\MiscStatus]
@="0"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ProgID]
@="ShockwaveFlash.ShockwaveFlash.10"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32]
@="c:\\Windows\\SysWow64\\Macromed\\Flash\\Flash10c.ocx, 1"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\TypeLib]
@="{D27CDB6B-AE6D-11cf-96B8-444553540000}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\Version]
@="1.0"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID]
@="ShockwaveFlash.ShockwaveFlash"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}]
@Denied: (A 2) (Everyone)
@="Macromedia Flash Factory Object"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\InprocServer32]
@="c:\\Windows\\SysWow64\\Macromed\\Flash\\Flash10c.ocx"
"ThreadingModel"="Apartment"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ProgID]
@="FlashFactory.FlashFactory.1"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32]
@="c:\\Windows\\SysWow64\\Macromed\\Flash\\Flash10c.ocx, 1"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\TypeLib]
@="{D27CDB6B-AE6D-11cf-96B8-444553540000}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\Version]
@="1.0"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID]
@="FlashFactory.FlashFactory"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{1D4C8A81-B7AC-460A-8C23-98713C41D6B3}]
@Denied: (A 2) (Everyone)
@="IFlashBroker3"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{1D4C8A81-B7AC-460A-8C23-98713C41D6B3}\ProxyStubClsid32]
@="{00020424-0000-0000-C000-000000000046}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{1D4C8A81-B7AC-460A-8C23-98713C41D6B3}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
"Version"="1.0"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0000\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\PCW\Security]
@Denied: (Full) (Everyone)
.
Heure de fin: 2012-01-31 13:44:03
ComboFix-quarantined-files.txt 2012-01-31 12:44
.
Avant-CF: 277 775 413 248 octets libres
Après-CF: 277 649 915 904 octets libres
.
- - End Of File - - 3A7651E29A0C12660A0E213C7FE6339E
0

Vous n’avez pas trouvé la réponse que vous recherchez ?

Posez votre question
Malekal_morte- Messages postés 180304 Date d'inscription mercredi 17 mai 2006 Statut Modérateur, Contributeur sécurité Dernière intervention 15 décembre 2020 24 631
31 janv. 2012 à 15:15
bizarre qu'il se soit foutu dans le shell.

Ca donne quoi ?
0
Symptômes : parfois ouverture d'un onglet dans firefox avec tentative d'ouverture de la page www.mediashifting.com (mais la page ne s'ouvre pas)...

Rien remarqué d'autre mais je préférais demander conseil avant que le machin ne me vérole toute la machine.

Tu vois la suite comment ?
0
Malekal_morte- Messages postés 180304 Date d'inscription mercredi 17 mai 2006 Statut Modérateur, Contributeur sécurité Dernière intervention 15 décembre 2020 24 631
31 janv. 2012 à 15:30
mais ça continue là ?
0
affirmatif...
Ouverture d'un onglet de temps en temps , avec ce message : "Firefox ne peut pas trouver le serveur à l'adresse www.mediashifting.com" avec en dessous le petit blabla pour t'aider a ouvrir la page.
0
Malekal_morte- Messages postés 180304 Date d'inscription mercredi 17 mai 2006 Statut Modérateur, Contributeur sécurité Dernière intervention 15 décembre 2020 24 631
31 janv. 2012 à 15:35
Ce répertoire existe ? : c:\users\Theo\AppData\Local\1cf7f44e\U
Tu peux le vider ?

Tu peux refaire un scan combofix pour voir.
avec les mêmes consignes.
0
niet, le répertoire n'existe pas.

Je relance combofix ?
0
Malekal_morte- Messages postés 180304 Date d'inscription mercredi 17 mai 2006 Statut Modérateur, Contributeur sécurité Dernière intervention 15 décembre 2020 24 631
Modifié par Malekal_morte- le 31/01/2012 à 15:41
n,an attends
0
Malekal_morte- Messages postés 180304 Date d'inscription mercredi 17 mai 2006 Statut Modérateur, Contributeur sécurité Dernière intervention 15 décembre 2020 24 631
31 janv. 2012 à 15:41
Tu peux suivre les indications de cette page pour t'aider : https://www.malekal.com/tutorial-otl/

* Télécharge http://www.geekstogo.com/forum/files/file/398-otl-oldtimers-list-it/ sur ton bureau.
(Sous Vista/Win7, il faut cliquer droit sur OTL et choisir Exécuter en tant qu'administrateur)

* Lance OTL
* Sur OTL, sous Personnalisation, copie-colle le script ci-dessous :
netsvcs
msconfig
safebootminimal
safebootnetwork
activex
drivers32
%ALLUSERSPROFILE%\Application Data\*.
%ALLUSERSPROFILE%\Application Data\*.exe /s
%APPDATA%\*.
%APPDATA%\*.exe /s
%temp%\.exe /s
%SYSTEMDRIVE%\*.exe
%systemroot%\*. /mp /s
%systemroot%\system32\*.dll /lockedfiles
%systemroot%\Tasks\*.job /lockedfiles
%systemroot%\system32\drivers\*.sys /lockedfiles
%systemroot%\System32\config\*.sav
/md5start
explorer.exe
winlogon.exe
wininit.exe
/md5stop
HKEY_LOCAL_MACHINE\SYSTEM\SYSTEM\CurrentControlSet\Services\lanmanserver\parameters /s
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Session Manager\SubSystems /s
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Session Manager\AppCertDlls /s
CREATERESTOREPOINT
nslookup www.google.fr /c
SAVEMBR:0
hklm\software\clients\startmenuinternet|command /rs
hklm\software\clients\startmenuinternet|command /64 /rs

* Clique sur le bouton Analyse.
* Quand le scan est fini, utilise le site http://pjjoint.malekal.com/ pour envoyer le rapport OTL.txt (et Extra.txt si présent), donne le ou les liens pjjoint qui pointent vers ces rapports ici dans un nouveau message.


0
OK un seul report.
Voici le lien :

http://pjjoint.malekal.com/files.php?id=20120131_e9k9i10b14t8
0
J'avais pas vu l'extra...
Lien du report complementaire :

http://pjjoint.malekal.com/files.php?id=20120131_y5f5p8g106
0
Malekal_morte- Messages postés 180304 Date d'inscription mercredi 17 mai 2006 Statut Modérateur, Contributeur sécurité Dernière intervention 15 décembre 2020 24 631
31 janv. 2012 à 17:15
Relance OTL.
o sous Personnalisation, copie_colle le contenu du cadre ci dessous (bien prendre :OTL en début).
Clic Correction, un rapport apparraitra, copie/colle le contenu ici:

[quote]:OTL
[2012/01/30 11:59:31 | 000,000,000 | -HSD | C] -- C:\Users\Theo\AppData\Local\1cf7f44e[/quote]


Je voulais voir si y avait une extension pourri sur Firefox, mais ça ne semble pas être le cas.
Tu peux tester Internet Explorer ?
0
Ok voila le report d'OTL.
Je t'envoie ce message avec IE (ca m'a au moins donner l'occasion de le démarrer...)
Pour l'instant pas d'ouverture d'onglet parasite.

========== OTL ==========
Folder move failed. C:\Users\Theo\AppData\Local\1cf7f44e/\U scheduled to be moved on reboot.
Folder move failed. C:\Users\Theo\AppData\Local\1cf7f44e/ scheduled to be moved on reboot.

OTL by OldTimer - Version 3.2.31.0 log created on 01312012_161718

Files\Folders moved on Reboot...
File\Folder C:\Users\Theo\AppData\Local\1cf7f44e/\U not found!
C:\Users\Theo\AppData\Local\1cf7f44e/ folder moved successfully.

Registry entries deleted on Reboot...
0
Il semblerait que tout soit rentré dans l'ordre.
J'attends ta confirmation suite au dernier report pour cloturer le post.
Vendons pas la peau de l'ours mais un gros merci par avance, rapide efficace, la classe !
0