Fameux virus "redirection Google"

Fermé
Gosso Messages postés 4 Date d'inscription jeudi 15 novembre 2012 Statut Membre Dernière intervention 24 novembre 2012 - Modifié par Gosso le 15/11/2012 à 19:17
phoceen8 Messages postés 1176 Date d'inscription mardi 9 février 2010 Statut Membre Dernière intervention 1 octobre 2021 - 24 nov. 2012 à 18:41
Bonsoir,

Comme beaucoup, j'ai chopé ce petit virus sympathique ! Du coup je me tourne vers vous pour que vous me veniez en aide. J'ai déjà parcouru le net à la recherche d'une solution et je suis tombé sur un poste de Malekal_Morte que voici :

Salut,

Télécharge et installe Malwarebyte : https://www.malekal.com/tutoriel-malwarebyte-anti-malware/
Mets le à jour, fais un scan rapide, supprime tout et poste le rapport ici.
!!! Malwarebyte doit être à jour avant de faire le scan !!!
Supprime bien ce qui est détecté : bouton supprimer sélection.



puis :

Passe un coup de TDSSKiller : https://forum.malekal.com/viewtopic.php?t=28637&start=
Lire ce qui est écrit au niveau des suppressions/réparation (delete et cure), ne pas supprimer n'importe quoi.
Poste le rapport ici.

puis :

Passe un coup d'aswmbr : https://forum.malekal.com/viewtopic.php?t=31619&start=
Télécharge le et mets le sur ton bureau.
Accepte l'installation des définitions virales d'Avast! et fais un scan.
Quand c'est terminé, fais save logs, ouvre le rapport et poste le ici.
Poste le rapport ici.


J'ai donc scrupuleusement suivi ses conseils ! Voici les rapports, comment puis-je savoir si le virus m'a définitivement plaqué ?

MALWARBYTE
Malwarebytes Anti-Malware (Essai) 1.65.1.1000 
www.malwarebytes.org 

Version de la base de données: v2012.11.14.07 

Windows 7 Service Pack 1 x86 NTFS 
Internet Explorer 8.0.7601.17514 
armelle :: ARMELLE-PC [administrateur] 

Protection: Activé 

14/11/2012 23:43:49 
mbam-log-2012-11-14 (23-43-49).txt 

Type d'examen: Examen rapide 
Options d'examen activées: Mémoire | Démarrage | Registre | Système de fichiers | Heuristique/Extra | Heuristique/Shuriken | PUP | PUM 
Options d'examen désactivées: P2P 
Elément(s) analysé(s): 231491 
Temps écoulé: 13 minute(s), 33 seconde(s) 

Processus mémoire détecté(s): 0 
(Aucun élément nuisible détecté) 

Module(s) mémoire détecté(s): 0 
(Aucun élément nuisible détecté) 

Clé(s) du Registre détectée(s): 0 
(Aucun élément nuisible détecté) 

Valeur(s) du Registre détectée(s): 0 
(Aucun élément nuisible détecté) 

Elément(s) de données du Registre détecté(s): 0 
(Aucun élément nuisible détecté) 

Dossier(s) détecté(s): 0 
(Aucun élément nuisible détecté) 

Fichier(s) détecté(s): 1 
C:\Users\armelle\AppData\Local\Temp\Temp1_Windows Loader v1.9.5.zip\Windows Loader\Windows Loader.exe (RiskWare.Tool.CK) -> Mis en quarantaine et supprimé avec succès. 

(fin)


Puis TDDSKILLER, il est long :
<code>
18:11:08.0517 2904 TDSS rootkit removing tool 2.8.15.0 Oct 31 2012 21:47:35
18:11:08.0658 2904 ============================================================
18:11:08.0658 2904 Current date / time: 2012/11/15 18:11:08.0658
18:11:08.0658 2904 SystemInfo:
18:11:08.0658 2904
18:11:08.0659 2904 OS Version: 6.1.7601 ServicePack: 1.0
18:11:08.0659 2904 Product type: Workstation
18:11:08.0659 2904 ComputerName: ARMELLE-PC
18:11:08.0659 2904 UserName: armelle
18:11:08.0659 2904 Windows directory: C:\Windows
18:11:08.0659 2904 System windows directory: C:\Windows
18:11:08.0659 2904 Processor architecture: Intel x86
18:11:08.0659 2904 Number of processors: 4
18:11:08.0659 2904 Page size: 0x1000
18:11:08.0659 2904 Boot type: Normal boot
18:11:08.0659 2904 ============================================================
18:11:10.0655 2904 Drive \Device\Harddisk0\DR0 - Size: 0x7470C06000 (465.76 Gb), SectorSize: 0x200, Cylinders: 0xED81, SectorsPerTrack: 0x3F, TracksPerCylinder: 0xFF, Type 'K0', Flags 0x00000050
18:11:10.0666 2904 Drive \Device\Harddisk1\DR1 - Size: 0xE8E0DB6000 (931.51 Gb), SectorSize: 0x200, Cylinders: 0x1DB01, SectorsPerTrack: 0x3F, TracksPerCylinder: 0xFF, Type 'K0', Flags 0x00000050
18:11:10.0681 2904 Drive \Device\Harddisk6\DR6 - Size: 0x1DE200000 (7.47 Gb), SectorSize: 0x200, Cylinders: 0x3CF, SectorsPerTrack: 0x3F, TracksPerCylinder: 0xFF, Type 'W'
18:11:10.0682 2904 ============================================================
18:11:10.0682 2904 \Device\Harddisk0\DR0:
18:11:10.0682 2904 MBR partitions:
18:11:10.0682 2904 \Device\Harddisk0\DR0\Partition1: MBR, Type 0x7, StartLBA 0x800, BlocksNum 0x32000
18:11:10.0682 2904 \Device\Harddisk0\DR0\Partition2: MBR, Type 0x7, StartLBA 0x32800, BlocksNum 0x3A353000
18:11:10.0682 2904 \Device\Harddisk1\DR1:
18:11:10.0682 2904 MBR partitions:
18:11:10.0682 2904 \Device\Harddisk1\DR1\Partition1: MBR, Type 0x7, StartLBA 0x800, BlocksNum 0x74705800
18:11:10.0682 2904 \Device\Harddisk6\DR6:
18:11:10.0683 2904 MBR partitions:
18:11:10.0683 2904 \Device\Harddisk6\DR6\Partition1: MBR, Type 0xB, StartLBA 0x1F80, BlocksNum 0xEEF080
18:11:10.0683 2904 ============================================================
18:11:10.0716 2904 C: <-> \Device\Harddisk0\DR0\Partition2
18:11:10.0740 2904 K: <-> \Device\Harddisk1\DR1\Partition1
18:11:10.0740 2904 ============================================================
18:11:10.0740 2904 Initialize success
18:11:10.0740 2904 ============================================================
18:11:12.0403 5132 ============================================================
18:11:12.0403 5132 Scan started
18:11:12.0403 5132 Mode: Manual;
18:11:12.0403 5132 ============================================================
18:11:14.0374 5132 ================ Scan system memory ========================
18:11:14.0374 5132 System memory - ok
18:11:14.0375 5132 ================ Scan services =============================
18:11:14.0613 5132 [ 1B133875B8AA8AC48969BD3458AFE9F5 ] 1394ohci C:\Windows\system32\drivers\1394ohci.sys
18:11:14.0622 5132 1394ohci - ok
18:11:14.0700 5132 [ CEA80C80BED809AA0DA6FEBC04733349 ] ACPI C:\Windows\system32\drivers\ACPI.sys
18:11:14.0702 5132 ACPI - ok
18:11:14.0756 5132 [ 1EFBC664ABFF416D1D07DB115DCB264F ] AcpiPmi C:\Windows\system32\drivers\acpipmi.sys
18:11:14.0772 5132 AcpiPmi - ok
18:11:14.0812 5132 adfs - ok
18:11:14.0934 5132 [ 44C00A385CA9DBC1D5CF3781F8C26AEA ] AdobeFlashPlayerUpdateSvc C:\Windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe
18:11:14.0935 5132 AdobeFlashPlayerUpdateSvc - ok
18:11:15.0001 5132 [ 21E785EBD7DC90A06391141AAC7892FB ] adp94xx C:\Windows\system32\DRIVERS\adp94xx.sys
18:11:15.0019 5132 adp94xx - ok
18:11:15.0041 5132 [ 0C676BC278D5B59FF5ABD57BBE9123F2 ] adpahci C:\Windows\system32\DRIVERS\adpahci.sys
18:11:15.0060 5132 adpahci - ok
18:11:15.0074 5132 [ 7C7B5EE4B7B822EC85321FE23A27DB33 ] adpu320 C:\Windows\system32\DRIVERS\adpu320.sys
18:11:15.0081 5132 adpu320 - ok
18:11:15.0110 5132 [ 8B5EEFEEC1E6D1A72A06C526628AD161 ] AeLookupSvc C:\Windows\System32\aelupsvc.dll
18:11:15.0111 5132 AeLookupSvc - ok
18:11:15.0326 5132 [ 9EBBBA55060F786F0FCAA3893BFA2806 ] AFD C:\Windows\system32\drivers\afd.sys
18:11:15.0335 5132 AFD - ok
18:11:15.0401 5132 [ 507812C3054C21CEF746B6EE3D04DD6E ] agp440 C:\Windows\system32\drivers\agp440.sys
18:11:15.0425 5132 agp440 - ok
18:11:15.0587 5132 [ 8B30250D573A8F6B4BD23195160D8707 ] aic78xx C:\Windows\system32\DRIVERS\djsvs.sys
18:11:15.0606 5132 aic78xx - ok
18:11:15.0629 5132 [ 18A54E132947CD98FEA9ACCC57F98F13 ] ALG C:\Windows\System32\alg.exe
18:11:15.0648 5132 ALG - ok
18:11:15.0664 5132 [ 0D40BCF52EA90FC7DF2AEAB6503DEA44 ] aliide C:\Windows\system32\drivers\aliide.sys
18:11:15.0668 5132 aliide - ok
18:11:15.0704 5132 [ 369FC70BDBAA2D13E0E66647E14CECEF ] AMD External Events Utility C:\Windows\system32\atiesrxx.exe
18:11:15.0706 5132 AMD External Events Utility - ok
18:11:15.0738 5132 [ 3C6600A0696E90A463771C7422E23AB5 ] amdagp C:\Windows\system32\drivers\amdagp.sys
18:11:15.0759 5132 amdagp - ok
18:11:15.0769 5132 [ CD5914170297126B6266860198D1D4F0 ] amdide C:\Windows\system32\drivers\amdide.sys
18:11:15.0781 5132 amdide - ok
18:11:15.0832 5132 [ 00DDA200D71BAC534BF56A9DB5DFD666 ] AmdK8 C:\Windows\system32\DRIVERS\amdk8.sys
18:11:15.0862 5132 AmdK8 - ok
18:11:16.0049 5132 [ DA3CF5B94AD09290896E2B73DF6D4173 ] amdkmdag C:\Windows\system32\DRIVERS\atikmdag.sys
18:11:16.0283 5132 amdkmdag - ok
18:11:16.0312 5132 [ 46A3F55772FD2D1526994693AE352579 ] amdkmdap C:\Windows\system32\DRIVERS\atikmpag.sys
18:11:16.0392 5132 amdkmdap - ok
18:11:16.0440 5132 [ 3CBF30F5370FDA40DD3E87DF38EA53B6 ] AmdPPM C:\Windows\system32\DRIVERS\amdppm.sys
18:11:16.0450 5132 AmdPPM - ok
18:11:16.0501 5132 [ D320BF87125326F996D4904FE24300FC ] amdsata C:\Windows\system32\drivers\amdsata.sys
18:11:16.0511 5132 amdsata - ok
18:11:16.0525 5132 [ EA43AF0C423FF267355F74E7A53BDABA ] amdsbs C:\Windows\system32\DRIVERS\amdsbs.sys
18:11:16.0532 5132 amdsbs - ok
18:11:16.0542 5132 [ 46387FB17B086D16DEA267D5BE23A2F2 ] amdxata C:\Windows\system32\drivers\amdxata.sys
18:11:16.0548 5132 amdxata - ok
18:11:16.0699 5132 [ A5BCBAF0477C4869B67E0195AEA4A9CD ] AntiVirSchedulerService C:\Program Files\Avira\AntiVir Desktop\sched.exe
18:11:16.0700 5132 AntiVirSchedulerService - ok
18:11:16.0751 5132 [ 3CCE4AFA4AACDB28E01A148394212186 ] AntiVirService C:\Program Files\Avira\AntiVir Desktop\avguard.exe
18:11:16.0752 5132 AntiVirService - ok
18:11:17.0064 5132 [ 98F481241BA8BBA38AA565BD3BF678F9 ] appdrv01 C:\Windows\system32\Drivers\appdrv01.sys
18:11:17.0175 5132 appdrv01 - ok
18:11:17.0209 5132 appdrvrem01 - ok
18:11:17.0284 5132 [ AEA177F783E20150ACE5383EE368DA19 ] AppID C:\Windows\system32\drivers\appid.sys
18:11:17.0301 5132 AppID - ok
18:11:17.0337 5132 [ 62A9C86CB6085E20DB4823E4E97826F5 ] AppIDSvc C:\Windows\System32\appidsvc.dll
18:11:17.0351 5132 AppIDSvc - ok
18:11:17.0417 5132 [ FB1959012294D6AD43E5304DF65E3C26 ] Appinfo C:\Windows\System32\appinfo.dll
18:11:17.0419 5132 Appinfo - ok
18:11:17.0476 5132 [ A45D184DF6A8803DA13A0B329517A64A ] AppMgmt C:\Windows\System32\appmgmts.dll
18:11:17.0488 5132 AppMgmt - ok
18:11:17.0516 5132 [ 2932004F49677BD84DBC72EDB754FFB3 ] arc C:\Windows\system32\DRIVERS\arc.sys
18:11:17.0525 5132 arc - ok
18:11:17.0536 5132 [ 5D6F36C46FD283AE1B57BD2E9FEB0BC7 ] arcsas C:\Windows\system32\DRIVERS\arcsas.sys
18:11:17.0552 5132 arcsas - ok
18:11:17.0574 5132 [ ADD2ADE1C2B285AB8378D2DAAF991481 ] AsyncMac C:\Windows\system32\DRIVERS\asyncmac.sys
18:11:17.0578 5132 AsyncMac - ok
18:11:17.0615 5132 [ 338C86357871C167A96AB976519BF59E ] atapi C:\Windows\system32\drivers\atapi.sys
18:11:17.0615 5132 atapi - ok
18:11:17.0711 5132 [ 7B4342936A3885CFE18E5D1DF6D55BC5 ] AtiHDAudioService C:\Windows\system32\drivers\AtihdW73.sys
18:11:17.0729 5132 AtiHDAudioService - ok
18:11:17.0834 5132 [ CE3B4E731638D2EF62FCB419BE0D39F0 ] AudioEndpointBuilder C:\Windows\System32\Audiosrv.dll
18:11:17.0837 5132 AudioEndpointBuilder - ok
18:11:17.0867 5132 [ CE3B4E731638D2EF62FCB419BE0D39F0 ] Audiosrv C:\Windows\System32\Audiosrv.dll
18:11:17.0870 5132 Audiosrv - ok
18:11:17.0895 5132 [ 1E4114685DE1FFA9675E09C6A1FB3F4B ] avgntflt C:\Windows\system32\DRIVERS\avgntflt.sys
18:11:17.0904 5132 avgntflt - ok
18:11:17.0951 5132 [ 0F78D3DAE6DEDD99AE54C9491C62ADF2 ] avipbb C:\Windows\system32\DRIVERS\avipbb.sys
18:11:17.0960 5132 avipbb - ok
18:11:18.0007 5132 [ 6E30D02AAC9CAC84F421622E3A2F6178 ] AxInstSV C:\Windows\System32\AxInstSV.dll
18:11:18.0016 5132 AxInstSV - ok
18:11:18.0073 5132 [ 1A231ABEC60FD316EC54C66715543CEC ] b06bdrv C:\Windows\system32\DRIVERS\bxvbdx.sys
18:11:18.0091 5132 b06bdrv - ok
18:11:18.0147 5132 [ BD8869EB9CDE6BBE4508D869929869EE ] b57nd60x C:\Windows\system32\DRIVERS\b57nd60x.sys
18:11:18.0169 5132 b57nd60x - ok
18:11:18.0236 5132 [ EE1E9C3BB8228AE423DD38DB69128E71 ] BDESVC C:\Windows\System32\bdesvc.dll
18:11:18.0246 5132 BDESVC - ok
18:11:18.0256 5132 [ 505506526A9D467307B3C393DEDAF858 ] Beep C:\Windows\system32\drivers\Beep.sys
18:11:18.0261 5132 Beep - ok
18:11:18.0347 5132 [ 1E2BAC209D184BB851E1A187D8A29136 ] BFE C:\Windows\System32\bfe.dll
18:11:18.0350 5132 BFE - ok
18:11:18.0395 5132 [ E585445D5021971FAE10393F0F1C3961 ] BITS C:\Windows\System32\qmgr.dll
18:11:18.0400 5132 BITS - ok
18:11:18.0432 5132 [ 2287078ED48FCFC477B05B20CF38F36F ] blbdrive C:\Windows\system32\DRIVERS\blbdrive.sys
18:11:18.0455 5132 blbdrive - ok
18:11:18.0534 5132 [ 73686FE0B2E0469F89FD2075BE724704 ] Bonjour Service C:\Program Files\Bonjour\mDNSResponder.exe
18:11:18.0536 5132 Bonjour Service - ok
18:11:18.0554 5132 [ 8F2DA3028D5FCBD1A060A3DE64CD6506 ] bowser C:\Windows\system32\DRIVERS\bowser.sys
18:11:18.0560 5132 bowser - ok
18:11:18.0587 5132 [ 9F9ACC7F7CCDE8A15C282D3F88B43309 ] BrFiltLo C:\Windows\system32\DRIVERS\BrFiltLo.sys
18:11:18.0598 5132 BrFiltLo - ok
18:11:18.0616 5132 [ 56801AD62213A41F6497F96DEE83755A ] BrFiltUp C:\Windows\system32\DRIVERS\BrFiltUp.sys
18:11:18.0644 5132 BrFiltUp - ok
18:11:18.0683 5132 [ 3DAA727B5B0A45039B0E1C9A211B8400 ] Browser C:\Windows\System32\browser.dll
18:11:18.0686 5132 Browser - ok
18:11:18.0717 5132 [ 845B8CE732E67F3B4133164868C666EA ] Brserid C:\Windows\System32\Drivers\Brserid.sys
18:11:18.0729 5132 Brserid - ok
18:11:18.0746 5132 [ 203F0B1E73ADADBBB7B7B1FABD901F6B ] BrSerWdm C:\Windows\System32\Drivers\BrSerWdm.sys
18:11:18.0756 5132 BrSerWdm - ok
18:11:18.0773 5132 [ BD456606156BA17E60A04E18016AE54B ] BrUsbMdm C:\Windows\System32\Drivers\BrUsbMdm.sys
18:11:18.0783 5132 BrUsbMdm - ok
18:11:18.0795 5132 [ AF72ED54503F717A43268B3CC5FAEC2E ] BrUsbSer C:\Windows\System32\Drivers\BrUsbSer.sys
18:11:18.0808 5132 BrUsbSer - ok
18:11:18.0880 5132 [ 2865A5C8E98C70C605F417908CEBB3A4 ] BthEnum C:\Windows\system32\drivers\BthEnum.sys
18:11:18.0891 5132 BthEnum - ok
18:11:18.0905 5132 [ ED3DF7C56CE0084EB2034432FC56565A ] BTHMODEM C:\Windows\system32\DRIVERS\bthmodem.sys
18:11:18.0910 5132 BTHMODEM - ok
18:11:18.0947 5132 [ AD1872E5829E8A2C3B5B4B641C3EAB0E ] BthPan C:\Windows\system32\DRIVERS\bthpan.sys
18:11:18.0970 5132 BthPan - ok
18:11:19.0051 5132 [ 1153DE2E4F5941E10C399CB5592F78A1 ] BTHPORT C:\Windows\System32\Drivers\BTHport.sys
18:11:19.0077 5132 BTHPORT - ok
18:11:19.0116 5132 [ 1DF19C96EEF6C29D1C3E1A8678E07190 ] bthserv C:\Windows\system32\bthserv.dll
18:11:19.0124 5132 bthserv - ok
18:11:19.0175 5132 [ C81E9413A25A439F436B1D4B6A0CF9E9 ] BTHUSB C:\Windows\System32\Drivers\BTHUSB.sys
18:11:19.0191 5132 BTHUSB - ok
18:11:19.0226 5132 [ 77EA11B065E0A8AB902D78145CA51E10 ] cdfs C:\Windows\system32\DRIVERS\cdfs.sys
18:11:19.0236 5132 cdfs - ok
18:11:19.0310 5132 [ BE167ED0FDB9C1FA1133953C18D5A6C9 ] cdrom C:\Windows\system32\drivers\cdrom.sys
18:11:19.0323 5132 cdrom - ok
18:11:19.0389 5132 [ 319C6B309773D063541D01DF8AC6F55F ] CertPropSvc C:\Windows\System32\certprop.dll
18:11:19.0391 5132 CertPropSvc - ok
18:11:19.0430 5132 [ 3FE3FE94A34DF6FB06E6418D0F6A0060 ] circlass C:\Windows\system32\DRIVERS\circlass.sys
18:11:19.0437 5132 circlass - ok
18:11:19.0500 5132 [ 635181E0E9BBF16871BF5380D71DB02D ] CLFS C:\Windows\system32\CLFS.sys
18:11:19.0509 5132 CLFS - ok
18:11:19.0599 5132 [ D88040F816FDA31C3B466F0FA0918F29 ] clr_optimization_v2.0.50727_32 C:\Windows\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe
18:11:19.0638 5132 clr_optimization_v2.0.50727_32 - ok
18:11:19.0755 5132 [ C5A75EB48E2344ABDC162BDA79E16841 ] clr_optimization_v4.0.30319_32 C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe
18:11:19.0758 5132 clr_optimization_v4.0.30319_32 - ok
18:11:19.0802 5132 [ DEA805815E587DAD1DD2C502220B5616 ] CmBatt C:\Windows\system32\DRIVERS\CmBatt.sys
18:11:19.0814 5132 CmBatt - ok
18:11:19.0833 5132 [ C537B1DB64D495B9B4717B4D6D9EDBF2 ] cmdide C:\Windows\system32\drivers\cmdide.sys
18:11:19.0840 5132 cmdide - ok
18:11:19.0890 5132 [ 247B4CE2DAB1160CD422D532D5241E1F ] CNG C:\Windows\system32\Drivers\cng.sys
18:11:19.0906 5132 CNG - ok
18:11:19.0919 5132 [ A6023D3823C37043986713F118A89BEE ] Compbatt C:\Windows\system32\DRIVERS\compbatt.sys
18:11:19.0930 5132 Compbatt - ok
18:11:19.0970 5132 [ CBE8C58A8579CFE5FCCF809E6F114E89 ] CompositeBus C:\Windows\system32\drivers\CompositeBus.sys
18:11:19.0979 5132 CompositeBus - ok
18:11:20.0028 5132 COMSysApp - ok
18:11:20.0046 5132 [ 2C4EBCFC84A9B44F209DFF6C6E6C61D1 ] crcdisk C:\Windows\system32\DRIVERS\crcdisk.sys
18:11:20.0058 5132 crcdisk - ok
18:11:20.0133 5132 [ 96C0E38905CFD788313BE8E11DAE3F2F ] CryptSvc C:\Windows\system32\cryptsvc.dll
18:11:20.0135 5132 CryptSvc - ok
18:11:20.0209 5132 [ 3C2177A897B4CA2788C6FB0C3FD81D4B ] CSC C:\Windows\system32\drivers\csc.sys
18:11:20.0256 5132 CSC - ok
18:11:20.0312 5132 [ 15F93B37F6801943360D9EB42485D5D3 ] CscService C:\Windows\System32\cscsvc.dll
18:11:20.0315 5132 CscService - ok
18:11:20.0347 5132 [ 7660F01D3B38ACA1747E397D21D790AF ] DcomLaunch C:\Windows\system32\rpcss.dll
18:11:20.0351 5132 DcomLaunch - ok
18:11:20.0380 5132 [ 8D6E10A2D9A5EED59562D9B82CF804E1 ] defragsvc C:\Windows\System32\defragsvc.dll
18:11:20.0401 5132 defragsvc - ok
18:11:20.0487 5132 [ F024449C97EC1E464AAFFDA18593DB88 ] DfsC C:\Windows\system32\Drivers\dfsc.sys
18:11:20.0499 5132 DfsC - ok
18:11:20.0646 5132 [ E9E01EB683C132F7FA27CD607B8A2B63 ] Dhcp C:\Windows\system32\dhcpcore.dll
18:11:20.0650 5132 Dhcp - ok
18:11:20.0896 5132 [ 1A050B0274BFB3890703D490F330C0DA ] discache C:\Windows\system32\drivers\discache.sys
18:11:20.0920 5132 discache - ok
18:11:21.0011 5132 [ 565003F326F99802E68CA78F2A68E9FF ] Disk C:\Windows\system32\DRIVERS\disk.sys
18:11:21.0059 5132 Disk - ok
18:11:21.0113 5132 [ 33EF4861F19A0736B11314AAD9AE28D0 ] Dnscache C:\Windows\System32\dnsrslvr.dll
18:11:21.0116 5132 Dnscache - ok
18:11:21.0182 5132 [ 366BA8FB4B7BB7435E3B9EACB3843F67 ] dot3svc C:\Windows\System32\dot3svc.dll
18:11:21.0232 5132 dot3svc - ok
18:11:21.0283 5132 [ 8EC04CA86F1D68DA9E11952EB85973D6 ] DPS C:\Windows\system32\dps.dll
18:11:21.0285 5132 DPS - ok
18:11:21.0318 5132 [ B918E7C5F9BF77202F89E1A9539F2EB4 ] drmkaud C:\Windows\system32\drivers\drmkaud.sys
18:11:21.0325 5132 drmkaud - ok
18:11:21.0433 5132 [ 23F5D28378A160352BA8F817BD8C71CB ] DXGKrnl C:\Windows\System32\drivers\dxgkrnl.sys
18:11:21.0555 5132 DXGKrnl - ok
18:11:21.0596 5132 [ 8600142FA91C1B96367D3300AD0F3F3A ] EapHost C:\Windows\System32\eapsvc.dll
18:11:21.0598 5132 EapHost - ok
18:11:22.0013 5132 [ 024E1B5CAC09731E4D868E64DBFB4AB0 ] ebdrv C:\Windows\system32\DRIVERS\evbdx.sys
18:11:22.0231 5132 ebdrv - ok
18:11:22.0299 5132 [ 81951F51E318AECC2D68559E47485CC4 ] EFS C:\Windows\System32\lsass.exe
18:11:22.0302 5132 EFS - ok
18:11:22.0498 5132 [ A8C362018EFC87BEB013EE28F29C0863 ] ehRecvr C:\Windows\ehome\ehRecvr.exe
18:11:22.0616 5132 ehRecvr - ok
18:11:22.0680 5132 [ D389BFF34F80CAEDE417BF9D1507996A ] ehSched C:\Windows\ehome\ehsched.exe
18:11:22.0708 5132 ehSched - ok
18:11:22.0890 5132 [ 44996A2ADDD2DB7454F2CA40B67D8941 ] ElbyCDIO C:\Windows\system32\Drivers\ElbyCDIO.sys
18:11:22.0906 5132 ElbyCDIO - ok
18:11:23.0056 5132 [ 0ED67910C8C326796FAA00B2BF6D9D3C ] elxstor C:\Windows\system32\DRIVERS\elxstor.sys
18:11:23.0098 5132 elxstor - ok
18:11:23.0167 5132 [ 8FC3208352DD3912C94367A206AB3F11 ] ErrDev C:\Windows\system32\drivers\errdev.sys
18:11:23.0179 5132 ErrDev - ok
18:11:23.0286 5132 [ F6916EFC29D9953D5D0DF06882AE8E16 ] EventSystem C:\Windows\system32\es.dll
18:11:23.0303 5132 EventSystem - ok
18:11:23.0331 5132 [ 2DC9108D74081149CC8B651D3A26207F ] exfat C:\Windows\system32\drivers\exfat.sys
18:11:23.0340 5132 exfat - ok
18:11:23.0376 5132 [ 7E0AB74553476622FB6AE36F73D97D35 ] fastfat C:\Windows\system32\drivers\fastfat.sys
18:11:23.0377 5132 fastfat - ok
18:11:23.0438 5132 [ 967EA5B213E9984CBE270205DF37755B ] Fax C:\Windows\system32\fxssvc.exe
18:11:23.0442 5132 Fax - ok
18:11:23.0484 5132 [ E817A017F82DF2A1F8CFDBDA29388B29 ] fdc C:\Windows\system32\DRIVERS\fdc.sys
18:11:23.0503 5132 fdc - ok
18:11:23.0519 5132 [ F3222C893BD2F5821A0179E5C71E88FB ] fdPHost C:\Windows\system32\fdPHost.dll
18:11:23.0520 5132 fdPHost - ok
18:11:23.0533 5132 [ 7DBE8CBFE79EFBDEB98C9FB08D3A9A5B ] FDResPub C:\Windows\system32\fdrespub.dll
18:11:23.0534 5132 FDResPub - ok
18:11:23.0545 5132 [ 6CF00369C97F3CF563BE99BE983D13D8 ] FileInfo C:\Windows\system32\drivers\fileinfo.sys
18:11:23.0552 5132 FileInfo - ok
18:11:23.0567 5132 [ 42C51DC94C91DA21CB9196EB64C45DB9 ] Filetrace C:\Windows\system32\drivers\filetrace.sys
18:11:23.0572 5132 Filetrace - ok
18:11:23.0640 5132 [ 1F63900E2EB00101B9ACA2B7A870704E ] FLEXnet Licensing Service C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe
18:11:23.0645 5132 FLEXnet Licensing Service - ok
18:11:23.0662 5132 [ 87907AA70CB3C56600F1C2FB8841579B ] flpydisk C:\Windows\system32\DRIVERS\flpydisk.sys
18:11:23.0667 5132 flpydisk - ok
18:11:23.0717 5132 [ 7520EC808E0C35E0EE6F841294316653 ] FltMgr C:\Windows\system32\drivers\fltmgr.sys
18:11:23.0729 5132 FltMgr - ok
18:11:23.0796 5132 [ B3A5EC6B6B6673DB7E87C2BCDBDDC074 ] FontCache C:\Windows\system32\FntCache.dll
18:11:23.0804 5132 FontCache - ok
18:11:23.0875 5132 [ E56F39F6B7FDA0AC77A79B0FD3DE1A2F ] FontCache3.0.0.0 C:\Windows\Microsoft.Net\Framework\v3.0\WPF\PresentationFontCache.exe
18:11:23.0881 5132 FontCache3.0.0.0 - ok
18:11:23.0910 5132 [ 1A16B57943853E598CFF37FE2B8CBF1D ] FsDepends C:\Windows\system32\drivers\FsDepends.sys
18:11:23.0918 5132 FsDepends - ok
18:11:23.0963 5132 [ 7DAE5EBCC80E45D3253F4923DC424D05 ] Fs_Rec C:\Windows\system32\drivers\Fs_Rec.sys
18:11:23.0968 5132 Fs_Rec - ok
18:11:24.0039 5132 [ 8A73E79089B282100B9393B644CB853B ] fvevol C:\Windows\system32\DRIVERS\fvevol.sys
18:11:24.0040 5132 fvevol - ok
18:11:24.0067 5132 [ 65EE0C7A58B65E74AE05637418153938 ] gagp30kx C:\Windows\system32\DRIVERS\gagp30kx.sys
18:11:24.0078 5132 gagp30kx - ok
18:11:24.0130 5132 [ E897EAF5ED6BA41E081060C9B447A673 ] gpsvc C:\Windows\System32\gpsvc.dll
18:11:24.0170 5132 gpsvc - ok
18:11:24.0191 5132 [ C44E3C2BAB6837DB337DDEE7544736DB ] hcw85cir C:\Windows\system32\drivers\hcw85cir.sys
18:11:24.0222 5132 hcw85cir - ok
18:11:24.0303 5132 [ A5EF29D5315111C80A5C1ABAD14C8972 ] HdAudAddService C:\Windows\system32\drivers\HdAudio.sys
18:11:24.0322 5132 HdAudAddService - ok
18:11:24.0339 5132 [ 9036377B8A6C15DC2EEC53E489D159B5 ] HDAudBus C:\Windows\system32\drivers\HDAudBus.sys
18:11:24.0340 5132 HDAudBus - ok
18:11:24.0367 5132 [ 1D58A7F3E11A9731D0EAAAA8405ACC36 ] HidBatt C:\Windows\system32\DRIVERS\HidBatt.sys
18:11:24.0375 5132 HidBatt - ok
18:11:24.0392 5132 [ 89448F40E6DF260C206A193A4683BA78 ] HidBth C:\Windows\system32\DRIVERS\hidbth.sys
18:11:24.0405 5132 HidBth - ok
18:11:24.0432 5132 [ CF50B4CF4A4F229B9F3C08351F99CA5E ] HidIr C:\Windows\system32\DRIVERS\hidir.sys
18:11:24.0445 5132 HidIr - ok
18:11:24.0470 5132 [ 2BC6F6A1992B3A77F5F41432CA6B3B6B ] hidserv C:\Windows\system32\hidserv.dll
18:11:24.0471 5132 hidserv - ok
18:11:24.0537 5132 [ 10C19F8290891AF023EAEC0832E1EB4D ] HidUsb C:\Windows\system32\drivers\hidusb.sys
18:11:24.0550 5132 HidUsb - ok
18:11:24.0598 5132 [ 196B4E3F4CCCC24AF836CE58FACBB699 ] hkmsvc C:\Windows\system32\kmsvc.dll
18:11:24.0599 5132 hkmsvc - ok
18:11:24.0650 5132 [ 6658F4404DE03D75FE3BA09F7ABA6A30 ] HomeGroupListener C:\Windows\system32\ListSvc.dll
18:11:24.0653 5132 HomeGroupListener - ok
18:11:24.0698 5132 [ DBC02D918FFF1CAD628ACBE0C0EAA8E8 ] HomeGroupProvider C:\Windows\system32\provsvc.dll
18:11:24.0701 5132 HomeGroupProvider - ok
18:11:24.0760 5132 [ 295FDC419039090EB8B49FFDBB374549 ] HpSAMD C:\Windows\system32\drivers\HpSAMD.sys
18:11:24.0775 5132 HpSAMD - ok
18:11:24.0834 5132 [ 871917B07A141BFF43D76D8844D48106 ] HTTP C:\Windows\system32\drivers\HTTP.sys
18:11:24.0851 5132 HTTP - ok
18:11:24.0897 5132 [ 0C4E035C7F105F1299258C90886C64C5 ] hwpolicy C:\Windows\system32\drivers\hwpolicy.sys
18:11:24.0898 5132 hwpolicy - ok
18:11:24.0941 5132 [ F151F0BDC47F4A28B1B20A0818EA36D6 ] i8042prt C:\Windows\system32\drivers\i8042prt.sys
18:11:24.0954 5132 i8042prt - ok
18:11:25.0005 5132 [ 5CD5F9A5444E6CDCB0AC89BD62D8B76E ] iaStorV C:\Windows\system32\drivers\iaStorV.sys
18:11:25.0019 5132 iaStorV - ok
18:11:25.0137 5132 [ C521D7EB6497BB1AF6AFA89E322FB43C ] idsvc C:\Windows\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\infocard.exe
18:11:25.0254 5132 idsvc - ok
18:11:25.0296 5132 [ 4173FF5708F3236CF25195FECD742915 ] iirsp C:\Windows\system32\DRIVERS\iirsp.sys
18:11:25.0302 5132 iirsp - ok
18:11:25.0350 5132 [ F95622F161474511B8D80D6B093AA610 ] IKEEXT C:\Windows\System32\ikeext.dll
18:11:25.0353 5132 IKEEXT - ok
18:11:25.0394 5132 [ A0F12F2C9BA6C72F3987CE780E77C130 ] intelide C:\Windows\system32\drivers\intelide.sys
18:11:25.0399 5132 intelide - ok
18:11:25.0423 5132 [ 3B514D27BFC4ACCB4037BC6685F766E0 ] intelppm C:\Windows\system32\DRIVERS\intelppm.sys
18:11:25.0424 5132 intelppm - ok
18:11:25.0455 5132 [ ACB364B9075A45C0736E5C47BE5CAE19 ] IPBusEnum C:\Windows\system32\ipbusenum.dll
18:11:25.0471 5132 IPBusEnum - ok
18:11:25.0483 5132 [ 709D1761D3B19A932FF0238EA6D50200 ] IpFilterDriver C:\Windows\system32\DRIVERS\ipfltdrv.sys
18:11:25.0489 5132 IpFilterDriver - ok
18:11:25.0562 5132 [ 4D65A07B795D6674312F879D09AA7663 ] iphlpsvc C:\Windows\System32\iphlpsvc.dll
18:11:25.0565 5132 iphlpsvc - ok
18:11:25.0601 5132 [ 4BD7134618C1D2A27466A099062547BF ] IPMIDRV C:\Windows\system32\drivers\IPMIDrv.sys
18:11:25.0608 5132 IPMIDRV - ok
18:11:25.0626 5132 [ A5FA468D67ABCDAA36264E463A7BB0CD ] IPNAT C:\Windows\system32\drivers\ipnat.sys
18:11:25.0639 5132 IPNAT - ok
18:11:25.0667 5132 [ 42996CFF20A3084A56017B7902307E9F ] IRENUM C:\Windows\system32\drivers\irenum.sys
18:11:25.0676 5132 IRENUM - ok
18:11:25.0685 5132 [ 1F32BB6B38F62F7DF1A7AB7292638A35 ] isapnp C:\Windows\system32\drivers\isapnp.sys
18:11:25.0691 5132 isapnp - ok
18:11:25.0721 5132 [ CB7A9ABB12B8415BCE5D74994C7BA3AE ] iScsiPrt C:\Windows\system32\drivers\msiscsi.sys
18:11:25.0759 5132 iScsiPrt - ok
18:11:25.0840 5132 [ 6ED8D475BF2F950F3262942F630B3A20 ] ISWKL C:\Program Files\CheckPoint\ZAForceField\ISWKL.sys
18:11:25.0854 5132 ISWKL - ok
18:11:25.0881 5132 [ 8A698B79EDF2BA40E42ADD764F43FAA7 ] IswSvc C:\Program Files\CheckPoint\ZAForceField\IswSvc.exe
18:11:25.0884 5132 IswSvc - ok
18:11:25.0915 5132 [ ADEF52CA1AEAE82B50DF86B56413107E ] kbdclass C:\Windows\system32\drivers\kbdclass.sys
18:11:25.0921 5132 kbdclass - ok
18:11:25.0972 5132 [ 9E3CED91863E6EE98C24794D05E27A71 ] kbdhid C:\Windows\system32\drivers\kbdhid.sys
18:11:26.0240 5132 kbdhid - ok
18:11:26.0286 5132 [ 81951F51E318AECC2D68559E47485CC4 ] KeyIso C:\Windows\system32\lsass.exe
18:11:26.0290 5132 KeyIso - ok
18:11:26.0331 5132 [ B7895B4182C0D16F6EFADEB8081E8D36 ] KSecDD C:\Windows\system32\Drivers\ksecdd.sys
18:11:26.0337 5132 KSecDD - ok
18:11:26.0345 5132 [ D30159AC9237519FBC62C6EC247D2D46 ] KSecPkg C:\Windows\system32\Drivers\ksecpkg.sys
18:11:26.0352 5132 KSecPkg - ok
18:11:26.0372 5132 [ 89A7B9CC98D0D80C6F31B91C0A310FCD ] KtmRm C:\Windows\system32\msdtckrm.dll
18:11:26.0386 5132 KtmRm - ok
18:11:26.0480 5132 [ D64AF876D53ECA3668BB97B51B4E70AB ] LanmanServer C:\Windows\system32\srvsvc.dll
18:11:26.0483 5132 LanmanServer - ok
18:11:26.0492 5132 [ 58405E4F68BA8E4057C6E914F326ABA2 ] LanmanWorkstation C:\Windows\System32\wkssvc.dll
18:11:26.0494 5132 LanmanWorkstation - ok
18:11:26.0541 5132 [ F7611EC07349979DA9B0AE1F18CCC7A6 ] lltdio C:\Windows\system32\DRIVERS\lltdio.sys
18:11:26.0556 5132 lltdio - ok
18:11:26.0604 5132 [ 5700673E13A2117FA3B9020C852C01E2 ] lltdsvc C:\Windows\System32\lltdsvc.dll
18:11:26.0626 5132 lltdsvc - ok
18:11:26.0640 5132 [ 55CA01BA19D0006C8F2639B6C045E08B ] lmhosts C:\Windows\System32\lmhsvc.dll
18:11:26.0651 5132 lmhosts - ok
18:11:26.0684 5132 [ EB119A53CCF2ACC000AC71B065B78FEF ] LSI_FC C:\Windows\system32\DRIVERS\lsi_fc.sys
18:11:26.0690 5132 LSI_FC - ok
18:11:26.0708 5132 [ 8ADE1C877256A22E49B75D1CC9161F9C ] LSI_SAS C:\Windows\system32\DRIVERS\lsi_sas.sys
18:11:26.0734 5132 LSI_SAS - ok
18:11:26.0759 5132 [ DC9DC3D3DAA0E276FD2EC262E38B11E9 ] LSI_SAS2 C:\Windows\system32\DRIVERS\lsi_sas2.sys
18:11:26.0769 5132 LSI_SAS2 - ok
18:11:26.0784 5132 [ 0A036C7D7CAB643A7F07135AC47E0524 ] LSI_SCSI C:\Windows\system32\DRIVERS\lsi_scsi.sys
18:11:26.0791 5132 LSI_SCSI - ok
18:11:26.0796 5132 [ 6703E366CC18D3B6E534F5CF7DF39CEE ] luafv C:\Windows\system32\drivers\luafv.sys
18:11:26.0803 5132 luafv - ok
18:11:26.0869 5132 [ 500D089CE760D83DA2B6CBA681AA9949 ] MBAMProtector C:\Windows\system32\drivers\mbam.sys
18:11:26.0880 5132 MBAMProtector - ok
18:11:27.0021 5132 [ 85B16A92B117A5A800032ECD904B86DB ] MBAMScheduler C:\Program Files\Malwarebytes' Anti-Malware\mbamscheduler.exe
18:11:27.0023 5132 MBAMScheduler - ok
18:11:27.0205 5132 [ 20E2469DB709FC675E655CEAA11BE312 ] MBAMService C:\Program Files\Malwarebytes' Anti-Malware\mbamservice.exe
18:11:27.0219 5132 MBAMService - ok
18:11:27.0257 5132 [ BFB9EE8EE977EFE85D1A3105ABEF6DD1 ] Mcx2Svc C:\Windows\system32\Mcx2Svc.dll
18:11:27.0269 5132 Mcx2Svc - ok
18:11:27.0297 5132 [ 0FFF5B045293002AB38EB1FD1FC2FB74 ] megasas C:\Windows\system32\DRIVERS\megasas.sys
18:11:27.0301 5132 megasas - ok
18:11:27.0327 5132 [ DCBAB2920C75F390CAF1D29F675D03D6 ] MegaSR C:\Windows\system32\DRIVERS\MegaSR.sys
18:11:27.0343 5132 MegaSR - ok
18:11:27.0366 5132 [ 146B6F43A673379A3C670E86D89BE5EA ] MMCSS C:\Windows\system32\mmcss.dll
18:11:27.0367 5132 MMCSS - ok
18:11:27.0382 5132 [ F001861E5700EE84E2D4E52C712F4964 ] Modem C:\Windows\system32\drivers\modem.sys
18:11:27.0393 5132 Modem - ok
18:11:27.0421 5132 [ 79D10964DE86B292320E9DFE02282A23 ] monitor C:\Windows\system32\DRIVERS\monitor.sys
18:11:27.0422 5132 monitor - ok
18:11:27.0480 5132 [ FB18CC1D4C2E716B6B903B0AC0CC0609 ] mouclass C:\Windows\system32\drivers\mouclass.sys
18:11:27.0489 5132 mouclass - ok
18:11:27.0516 5132 [ 2C388D2CD01C9042596CF3C8F3C7B24D ] mouhid C:\Windows\system32\DRIVERS\mouhid.sys
18:11:27.0527 5132 mouhid - ok
18:11:27.0563 5132 [ FC8771F45ECCCFD89684E38842539B9B ] mountmgr C:\Windows\system32\drivers\mountmgr.sys
18:11:27.0564 5132 mountmgr - ok
18:11:27.0675 5132 [ 8BE15F71DE6FF33FC56DCDE7B2B9EFE8 ] MozillaMaintenance C:\Program Files\Mozilla Maintenance Service\maintenanceservice.exe
18:11:27.0697 5132 MozillaMaintenance - ok
18:11:27.0743 5132 [ 2D699FB6E89CE0D8DA14ECC03B3EDFE0 ] mpio C:\Windows\system32\drivers\mpio.sys
18:11:27.0755 5132 mpio - ok
18:11:27.0798 5132 [ AD2723A7B53DD1AACAE6AD8C0BFBF4D0 ] mpsdrv C:\Windows\system32\drivers\mpsdrv.sys
18:11:27.0807 5132 mpsdrv - ok
18:11:27.0890 5132 [ 9835584E999D25004E1EE8E5F3E3B881 ] MpsSvc C:\Windows\system32\mpssvc.dll
18:11:27.0894 5132 MpsSvc - ok
18:11:27.0936 5132 [ CEB46AB7C01C9F825F8CC6BABC18166A ] MRxDAV C:\Windows\system32\drivers\mrxdav.sys
18:11:27.0949 5132 MRxDAV - ok
18:11:27.0978 5132 [ 5D16C921E3671636C0EBA3BBAAC5FD25 ] mrxsmb C:\Windows\system32\DRIVERS\mrxsmb.sys
18:11:27.0992 5132 mrxsmb - ok
18:11:28.0028 5132 [ 6D17A4791ACA19328C685D256349FEFC ] mrxsmb10 C:\Windows\system32\DRIVERS\mrxsmb10.sys
18:11:28.0043 5132 mrxsmb10 - ok
18:11:28.0058 5132 [ B81F204D146000BE76651A50670A5E9E ] mrxsmb20 C:\Windows\system32\DRIVERS\mrxsmb20.sys
18:11:28.0065 5132 mrxsmb20 - ok
18:11:28.0090 5132 [ 012C5F4E9349E711E11E0F19A8589F0A ] msahci C:\Windows\system32\drivers\msahci.sys
18:11:28.0104 5132 msahci - ok
18:11:28.0150 5132 [ 55055F8AD8BE27A64C831322A780A228 ] msdsm C:\Windows\system32\drivers\msdsm.sys
18:11:28.0159 5132 msdsm - ok
18:11:28.0178 5132 [ E1BCE74A3BD9902B72599C0192A07E27 ] MSDTC C:\Windows\System32\msdtc.exe
18:11:28.0186 5132 MSDTC - ok
18:11:28.0229 5132 [ DAEFB28E3AF5A76ABCC2C3078C07327F ] Msfs C:\Windows\system32\drivers\Msfs.sys
18:11:28.0241 5132 Msfs - ok
18:11:28.0255 5132 [ 3E1E5767043C5AF9367F0056295E9F84 ] mshidkmdf C:\Windows\System32\drivers\mshidkmdf.sys
18:11:28.0258 5132 mshidkmdf - ok
18:11:28.0296 5132 [ 0A4E5757AE09FA9622E3158CC1AEF114 ] msisadrv C:\Windows\system32\drivers\msisadrv.sys
18:11:28.0305 5132 msisadrv - ok
18:11:28.0349 5132 [ 90F7D9E6B6F27E1A707D4A297F077828 ] MSiSCSI C:\Windows\system32\iscsiexe.dll
18:11:28.0368 5132 MSiSCSI - ok
18:11:28.0371 5132 msiserver - ok
18:11:28.0397 5132 [ 8C0860D6366AAFFB6C5BB9DF9448E631 ] MSKSSRV C:\Windows\system32\drivers\MSKSSRV.sys
18:11:28.0400 5132 MSKSSRV - ok
18:11:28.0420 5132 [ 3EA8B949F963562CEDBB549EAC0C11CE ] MSPCLOCK C:\Windows\system32\drivers\MSPCLOCK.sys
18:11:28.0434 5132 MSPCLOCK - ok
18:11:28.0443 5132 [ F456E973590D663B1073E9C463B40932 ] MSPQM C:\Windows\system32\drivers\MSPQM.sys
18:11:28.0460 5132 MSPQM - ok
18:11:28.0476 5132 [ 0E008FC4819D238C51D7C93E7B41E560 ] MsRPC C:\Windows\system32\drivers\MsRPC.sys
18:11:28.0485 5132 MsRPC - ok
18:11:28.0523 5132 [ FC6B9FF600CC585EA38B12589BD4E246 ] mssmbios C:\Windows\system32\drivers\mssmbios.sys
18:11:28.0523 5132 mssmbios - ok
18:11:28.0541 5132 [ B42C6B921F61A6E55159B8BE6CD54A36 ] MSTEE C:\Windows\system32\drivers\MSTEE.sys
18:11:28.0553 5132 MSTEE - ok
18:11:28.0564 5132 [ 33599130F44E1F34631CEA241DE8AC84 ] MTConfig C:\Windows\system32\DRIVERS\MTConfig.sys
18:11:28.0573 5132 MTConfig - ok
18:11:28.0622 5132 [ CBE71C122434805CB73FFB6619F60598 ] MTsensor C:\Windows\system32\DRIVERS\ASACPI.sys
18:11:28.0627 5132 MTsensor - ok
18:11:28.0642 5132 [ 159FAD02F64E6381758C990F753BCC80 ] Mup C:\Windows\system32\Drivers\mup.sys
18:11:28.0649 5132 Mup - ok
18:11:28.0692 5132 [ 61D57A5D7C6D9AFE10E77DAE6E1B445E ] napagent C:\Windows\system32\qagentRT.dll
18:11:28.0695 5132 napagent - ok
18:11:28.0772 5132 [ 26384429FCD85D83746F63E798AB1480 ] NativeWifiP C:\Windows\system32\DRIVERS\nwifi.sys
18:11:28.0790 5132 NativeWifiP - ok
18:11:28.0833 5132 [ 8C9C922D71F1CD4DEF73F186416B7896 ] NDIS C:\Windows\system32\drivers\ndis.sys
18:11:28.0845 5132 NDIS - ok
18:11:28.0870 5132 [ 0E1787AA6C9191D3D319E8BAFE86F80C ] NdisCap C:\Windows\system32\DRIVERS\ndiscap.sys
18:11:28.0885 5132 NdisCap - ok
18:11:28.0907 5132 [ E4A8AEC125A2E43A9E32AFEEA7C9C888 ] NdisTapi C:\Windows\system32\DRIVERS\ndistapi.sys
18:11:28.0911 5132 NdisTapi - ok
18:11:28.0951 5132 [ D8A65DAFB3EB41CBB622745676FCD072 ] Ndisuio C:\Windows\system32\DRIVERS\ndisuio.sys
18:11:28.0967 5132 Ndisuio - ok
18:11:28.0981 5132 [ 38FBE267E7E6983311179230FACB1017 ] NdisWan C:\Windows\system32\DRIVERS\ndiswan.sys
18:11:28.0994 5132 NdisWan - ok
18:11:29.0007 5132 [ A4BDC541E69674FBFF1A8FF00BE913F2 ] NDProxy C:\Windows\system32\drivers\NDProxy.sys
18:11:29.0015 5132 NDProxy - ok
18:11:29.0025 5132 [ 80B275B1CE3B0E79909DB7B39AF74D51 ] NetBIOS C:\Windows\system32\DRIVERS\netbios.sys
18:11:29.0033 5132 NetBIOS - ok
18:11:29.0089 5132 [ 280122DDCF04B378EDD1AD54D71C1E54 ] NetBT C:\Windows\system32\DRIVERS\netbt.sys
18:11:29.0091 5132 NetBT - ok
18:11:29.0100 5132 [ 81951F51E318AECC2D68559E47485CC4 ] Netlogon C:\Windows\system32\lsass.exe
18:11:29.0101 5132 Netlogon - ok
18:11:29.0146 5132 [ 7CCCFCA7510684768DA22092D1FA4DB2 ] Netman C:\Windows\System32\netman.dll
18:11:29.0149 5132 Netman - ok
18:11:29.0161 5132 [ 8C338238C16777A802D6A9211EB2BA50 ] netprofm C:\Windows\System32\netprofm.dll
18:11:29.0165 5132 netprofm - ok
18:11:29.0184 5132 [ F476EC40033CDB91EFBE73EB99B8362D ] NetTcpPortSharing C:\Windows\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\SMSvcHost.exe
18:11:29.0203 5132 NetTcpPortSharing - ok
18:11:29.0248 5132 [ 1D85C4B390B0EE09C7A46B91EFB2C097 ] nfrd960 C:\Windows\system32\DRIVERS\nfrd960.sys
18:11:29.0253 5132 nfrd960 - ok
18:11:29.0308 5132 [ 912084381D30D8B89EC4E293053F4710 ] NlaSvc C:\Windows\System32\nlasvc.dll
18:11:29.0311 5132 NlaSvc - ok
18:11:29.0321 5132 [ 1DB262A9F8C087E8153D89BEF3D2235F ] Npfs C:\Windows\system32\drivers\Npfs.sys
18:11:29.0325 5132 Npfs - ok
18:11:29.0336 5132 [ BA387E955E890C8A88306D9B8D06BF17 ] nsi C:\Windows\system32\nsisvc.dll
18:11:29.0341 5132 nsi - ok
18:11:29.0355 5132 [ E9A0A4D07E53D8FEA2BB8387A3293C58 ] nsiproxy C:\Windows\system32\drivers\nsiproxy.sys
18:11:29.0355 5132 nsiproxy - ok
18:11:29.0431 5132 [ 0D87503986BB3DFED58E343FE39DDE13 ] Ntfs C:\Windows\system32\drivers\Ntfs.sys
18:11:29.0477 5132 Ntfs - ok
18:11:29.0490 5132 [ F9756A98D69098DCA8945D62858A812C ] Null C:\Windows\system32\drivers\Null.sys
18:11:29.0495 5132 Null - ok
18:11:29.0509 5132 [ B3E25EE28883877076E0E1FF877D02E0 ] nvraid C:\Windows\system32\drivers\nvraid.sys
18:11:29.0524 5132 nvraid - ok
18:11:29.0564 5132 [ 4380E59A170D88C4F1022EFF6719A8A4 ] nvstor C:\Windows\system32\drivers\nvstor.sys
18:11:29.0571 5132 nvstor - ok
18:11:29.0611 5132 [ 5A0983915F02BAE73267CC2A041F717D ] nv_agp C:\Windows\system32\drivers\nv_agp.sys
18:11:29.0618 5132 nv_agp - ok
18:11:29.0768 5132 [ 785F487A64950F3CB8E9F16253BA3B7B ] odserv C:\Program Files\Common Files\Microsoft Shared\OFFICE12\ODSERV.EXE
18:11:29.0795 5132 odserv - ok
18:11:29.0828 5132 [ 08A70A1F2CDDE9BB49B885CB817A66EB ] ohci1394 C:\Windows\system32\drivers\ohci1394.sys
18:11:29.0839 5132 ohci1394 - ok
18:11:29.0908 5132 [ 5A432A042DAE460ABE7199B758E8606C ] ose C:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE
18:11:29.0916 5132 ose - ok
18:11:29.0953 5132 [ 82A8521DDC60710C3D3D3E7325209BEC ] p2pimsvc C:\Windows\system32\pnrpsvc.dll
18:11:29.0956 5132 p2pimsvc - ok
18:11:29.0982 5132 [ 59C3DDD501E39E006DAC31BF55150D91 ] p2psvc C:\Windows\system32\p2psvc.dll
18:11:29.0985 5132 p2psvc - ok
18:11:30.0060 5132 [ F5CF06754AE54D9D3353FC9C59BC4E04 ] papycpu2 C:\Windows\System32\DRIVERS\papycpu2.sys
18:11:30.0064 5132 papycpu2 - ok
18:11:30.0114 5132 [ B09A71E8E1E127455F3A2FE83D38851F ] papyjoy C:\Windows\System32\DRIVERS\papyjoy.sys
18:11:30.0117 5132 papyjoy - ok
18:11:30.0145 5132 [ 2EA877ED5DD9713C5AC74E8EA7348D14 ] Parport C:\Windows\system32\DRIVERS\parport.sys
18:11:30.0154 5132 Parport - ok
18:11:30.0186 5132 [ 3F34A1B4C5F6475F320C275E63AFCE9B ] partmgr C:\Windows\system32\drivers\partmgr.sys
18:11:30.0192 5132 partmgr - ok
18:11:30.0204 5132 [ EB0A59F29C19B86479D36B35983DAADC ] Parvdm C:\Windows\system32\DRIVERS\parvdm.sys
18:11:30.0226 5132 Parvdm - ok
18:11:30.0259 5132 [ 358AB7956D3160000726574083DFC8A6 ] PcaSvc C:\Windows\System32\pcasvc.dll
18:11:30.0261 5132 PcaSvc - ok
18:11:30.0276 5132 [ 673E55C3498EB970088E812EA820AA8F ] pci C:\Windows\system32\drivers\pci.sys
18:11:30.0283 5132 pci - ok
18:11:30.0324 5132 [ AFE86F419014DB4E5593F69FFE26CE0A ] pciide C:\Windows\system32\drivers\pciide.sys
18:11:30.0336 5132 pciide - ok
18:11:30.0360 5132 [ F396431B31693E71E8A80687EF523506 ] pcmcia C:\Windows\system32\DRIVERS\pcmcia.sys
18:11:30.0368 5132 pcmcia - ok
18:11:30.0383 5132 [ 250F6B43D2B613172035C6747AEEB19F ] pcw C:\Windows\system32\drivers\pcw.sys
18:11:30.0392 5132 pcw - ok
18:11:30.0442 5132 [ 9E0104BA49F4E6973749A02BF41344ED ] PEAUTH C:\Windows\system32\drivers\peauth.sys
18:11:30.0491 5132 PEAUTH - ok
18:11:30.0563 5132 [ AF4D64D2A57B9772CF3801950B8058A6 ] PeerDistSvc C:\Windows\system32\peerdistsvc.dll
18:11:30.0569 5132 PeerDistSvc - ok
18:11:30.0687 5132 [ 414BBA67A3DED1D28437EB66AEB8A720 ] pla C:\Windows\system32\pla.dll
18:11:30.0741 5132 pla - ok
18:11:30.0836 5132 [ EC7BC28D207DA09E79B3E9FAF8B232CA ] PlugPlay C:\Windows\system32\umpnpmgr.dll
18:11:30.0839 5132 PlugPlay - ok
18:11:30.0886 5132 [ 63FF8572611249931EB16BB8EED6AFC8 ] PNRPAutoReg C:\Windows\system32\pnrpauto.dll
18:11:30.0899 5132 PNRPAutoReg - ok
18:11:30.0921 5132 [ 82A8521DDC60710C3D3D3E7325209BEC ] PNRPsvc C:\Windows\system32\pnrpsvc.dll
18:11:30.0924 5132 PNRPsvc - ok
18:11:30.0987 5132 [ 53946B69BA0836BD95B03759530C81EC ] PolicyAgent C:\Windows\System32\ipsecsvc.dll
18:11:30.0997 5132 PolicyAgent - ok
18:11:31.0010 5132 [ F87D30E72E03D579A5199CCB3831D6EA ] Power C:\Windows\system32\umpo.dll
18:11:31.0013 5132 Power - ok
18:11:31.0064 5132 [ 631E3E205AD6D86F2AED6A4A8E69F2DB ] PptpMiniport C:\Windows\system32\DRIVERS\raspptp.sys
18:11:31.0075 5132 PptpMiniport - ok
18:11:31.0085 5132 [ 85B1E3A0C7585BC4AAE6899EC6FCF011 ] Processor C:\Windows\system32\DRIVERS\processr.sys
18:11:31.0099 5132 Processor - ok
18:11:31.0156 5132 [ CADEFAC453040E370A1BDFF3973BE00D ] ProfSvc C:\Windows\system32\profsvc.dll
18:11:31.0159 5132 ProfSvc - ok
18:11:31.0164 5132 [ 81951F51E318AECC2D68559E47485CC4 ] ProtectedStorage C:\Windows\system32\lsass.exe
18:11:31.0166 5132 ProtectedStorage - ok
18:11:31.0198 5132 [ 6270CCAE2A86DE6D146529FE55B3246A ] Psched C:\Windows\system32\DRIVERS\pacer.sys
18:11:31.0199 5132 Psched - ok
18:11:31.0307 5132 [ AB95ECF1F6659A60DDC166D8315B0751 ] ql2300 C:\Windows\system32\DRIVERS\ql2300.sys
18:11:31.0374 5132 ql2300 - ok
18:11:31.0407 5132 [ B4DD51DD25182244B86737DC51AF2270 ] ql40xx C:\Windows\system32\DRIVERS\ql40xx.sys
18:11:31.0416 5132 ql40xx - ok
18:11:31.0453 5132 [ 31AC809E7707EB580B2BDB760390765A ] QWAVE C:\Windows\system32\qwave.dll
18:11:31.0493 5132 QWAVE - ok
18:11:31.0506 5132 [ 584078CA1B95CA72DF2A27C336F9719D ] QWAVEdrv C:\Windows\system32\drivers\qwavedrv.sys
18:11:31.0519 5132 QWAVEdrv - ok
18:11:31.0532 5132 [ 30A81B53C766D0133BB86D234E5556AB ] RasAcd C:\Windows\system32\DRIVERS\rasacd.sys
18:11:31.0540 5132 RasAcd - ok
18:11:31.0585 5132 [ 57EC4AEF73660166074D8F7F31C0D4FD ] RasAgileVpn C:\Windows\system32\DRIVERS\AgileVpn.sys
18:11:31.0593 5132 RasAgileVpn - ok
18:11:31.0627 5132 [ A60F1839849C0C00739787FD5EC03F13 ] RasAuto C:\Windows\System32\rasauto.dll
18:11:31.0638 5132 RasAuto - ok
18:11:31.0670 5132 [ D9F91EAFEC2815365CBE6D167E4E332A ] Rasl2tp C:\Windows\system32\DRIVERS\rasl2tp.sys
18:11:31.0684 5132 Rasl2tp - ok
18:11:31.0760 5132 [ CB9E04DC05EACF5B9A36CA276D475006 ] RasMan C:\Windows\System32\rasmans.dll
18:11:31.0779 5132 RasMan - ok
18:11:31.0800 5132 [ 0FE8B15916307A6AC12BFB6A63E45507 ] RasPppoe C:\Windows\system32\DRIVERS\raspppoe.sys
18:11:31.0806 5132 RasPppoe - ok
18:11:31.0824 5132 [ 44101F495A83EA6401D886E7FD70096B ] RasSstp C:\Windows\system32\DRIVERS\rassstp.sys
18:11:31.0834 5132 RasSstp - ok
18:11:31.0861 5132 [ D528BC58A489409BA40334EBF96A311B ] rdbss C:\Windows\system32\DRIVERS\rdbss.sys
18:11:31.0877 5132 rdbss - ok
18:11:31.0891 5132 [ 0D8F05481CB76E70E1DA06EE9F0DA9DF ] rdpbus C:\Windows\system32\DRIVERS\rdpbus.sys
18:11:31.0894 5132 rdpbus - ok
18:11:31.0934 5132 [ 23DAE03F29D253AE74C44F99E515F9A1 ] RDPCDD C:\Windows\system32\DRIVERS\RDPCDD.sys
18:11:31.0938 5132 RDPCDD - ok
18:11:31.0990 5132 [ B973FCFC50DC1434E1970A146F7E3885 ] RDPDR C:\Windows\system32\drivers\rdpdr.sys
18:11:31.0998 5132 RDPDR - ok
18:11:32.0038 5132 [ 5A53CA1598DD4156D44196D200C94B8A ] RDPENCDD C:\Windows\system32\drivers\rdpencdd.sys
18:11:32.0039 5132 RDPENCDD - ok
18:11:32.0053 5132 [ 44B0A53CD4F27D50ED461DAE0C0B4E1F ] RDPREFMP C:\Windows\system32\drivers\rdprefmp.sys
18:11:32.0061 5132 RDPREFMP - ok
18:11:32.0186 5132 [ 68A0387F58E226DEEE23D9715955572A ] RdpVideoMiniport C:\Windows\system32\drivers\rdpvideominiport.sys
18:11:32.0229 5132 RdpVideoMiniport - ok
18:11:32.0278 5132 [ F031683E6D1FEA157ABB2FF260B51E61 ] RDPWD C:\Windows\system32\drivers\RDPWD.sys
18:11:32.0293 5132 RDPWD - ok
18:11:32.0350 5132 [ 518395321DC96FE2C9F0E96AC743B656 ] rdyboost C:\Windows\system32\drivers\rdyboost.sys
18:11:32.0359 5132 rdyboost - ok
18:11:32.0412 5132 [ 7B5E1419717FAC363A31CC302895217A ] RemoteAccess C:\Windows\System32\mprdim.dll
18:11:32.0420 5132 RemoteAccess - ok
18:11:32.0447 5132 [ CB9A8683F4EF2BF99E123D79950D7935 ] RemoteRegistry C:\Windows\system32\regsvc.dll
18:11:32.0457 5132 RemoteRegistry - ok
18:11:32.0517 5132 [ CB928D9E6DAF51879DD6BA8D02F01321 ] RFCOMM C:\Windows\system32\DRIVERS\rfcomm.sys
18:11:32.0525 5132 RFCOMM - ok
18:11:32.0558 5132 [ 78D072F35BC45D9E4E1B61895C152234 ] RpcEptMapper C:\Windows\System32\RpcEpMap.dll
18:11:32.0560 5132 RpcEptMapper - ok
18:11:32.0592 5132 [ 94D36C0E44677DD26981D2BFEEF2A29D ] RpcLocator C:\Windows\system32\locator.exe
18:11:32.0607 5132 RpcLocator - ok
18:11:32.0635 5132 [ 7660F01D3B38ACA1747E397D21D790AF ] RpcSs C:\Windows\system32\rpcss.dll
18:11:32.0639 5132 RpcSs - ok
18:11:32.0698 5132 [ 032B0D36AD92B582D869879F5AF5B928 ] rspndr C:\Windows\system32\DRIVERS\rspndr.sys
18:11:32.0720 5132 rspndr - ok
18:11:32.0787 5132 [ 7DFD48E24479B68B258D8770121155A0 ] RTL8167 C:\Windows\system32\DRIVERS\Rt86win7.sys
18:11:32.0794 5132 RTL8167 - ok
18:11:32.0864 5132 [ 7FA7F2E249A5DCBB7970630E15E1F482 ] s3cap C:\Windows\system32\drivers\vms3cap.sys
18:11:32.0871 5132 s3cap - ok
18:11:32.0904 5132 [ 81951F51E318AECC2D68559E47485CC4 ] SamSs C:\Windows\system32\lsass.exe
18:11:32.0906 5132 SamSs - ok
18:11:33.0012 5132 [ 05D860DA1040F111503AC416CCEF2BCA ] sbp2port C:\Windows\system32\drivers\sbp2port.sys
18:11:33.0035 5132 sbp2port - ok
18:11:33.0087 5132 [ 8FC518FFE9519C2631D37515A68009C4 ] SCardSvr C:\Windows\System32\SCardSvr.dll
18:11:33.0123 5132 SCardSvr - ok
18:11:33.0224 5132 [ 20B2751CD4C8F3FD989739CA661B9F30 ] SCDEmu C:\Windows\system32\drivers\SCDEmu.sys
18:11:33.0247 5132 SCDEmu - ok
18:11:33.0286 5132 [ 0693B5EC673E34DC147E195779A4DCF6 ] scfilter C:\Windows\system32\DRIVERS\scfilter.sys
18:11:33.0305 5132 scfilter - ok
18:11:33.0402 5132 [ A04BB13F8A72F8B6E8B4071723E4E336 ] Schedule C:\Windows\system32\schedsvc.dll
18:11:33.0546 5132 Schedule - ok
18:11:33.0575 5132 [ 319C6B309773D063541D01DF8AC6F55F ] SCPolicySvc C:\Windows\System32\certprop.dll
18:11:33.0576 5132 SCPolicySvc - ok
18:11:33.0617 5132 [ 08236C4BCE5EDD0A0318A438AF28E0F7 ] SDRSVC C:\Windows\System32\SDRSVC.dll
18:11:33.0630 5132 SDRSVC - ok
18:11:33.0706 5132 [ 90A3935D05B494A5A39D37E71F09A677 ] secdrv C:\Windows\system32\drivers\secdrv.sys
18:11:33.0726 5132 secdrv - ok
18:11:33.0804 5132 [ A59B3A4442C52060CC7A85293AA3546F ] seclogon C:\Windows\system32\seclogon.dll
18:11:33.0820 5132 seclogon - ok
18:11:33.0837 5132 [ DCB7FCDCC97F87360F75D77425B81737 ] SENS C:\Windows\System32\sens.dll
18:11:33.0839 5132 SENS - ok
18:11:33.0877 5132 [ 50087FE1EE447009C9CC2997B90DE53F ] SensrSvc C:\Windows\system32\sensrsvc.dll
18:11:33.0889 5132 SensrSvc - ok
18:11:33.0925 5132 [ 9AD8B8B515E3DF6ACD4212EF465DE2D1 ] Serenum C:\Windows\system32\DRIVERS\serenum.sys
18:11:33.0939 5132 Serenum - ok
18:11:33.0992 5132 [ 5FB7FCEA0490D821F26F39CC5EA3D1E2 ] Serial C:\Windows\system32\DRIVERS\serial.sys
18:11:34.0007 5132 Serial - ok
18:11:34.0039 5132 [ 79BFFB520327FF916A582DFEA17AA813 ] sermouse C:\Windows\system32\DRIVERS\sermouse.sys
18:11:34.0051 5132 sermouse - ok
18:11:34.0104 5132 [ 4AE380F39A0032EAB7DD953030B26D28 ] SessionEnv C:\Windows\system32\sessenv.dll
18:11:34.0106 5132 SessionEnv - ok
18:11:34.0153 5132 [ 9F976E1EB233DF46FCE808D9DEA3EB9C ] sffdisk C:\Windows\system32\drivers\sffdisk.sys
18:11:34.0169 5132 sffdisk - ok
18:11:34.0173 5132 [ 932A68EE27833CFD57C1639D375F2731 ] sffp_mmc C:\Windows\system32\drivers\sffp_mmc.sys
18:11:34.0177 5132 sffp_mmc - ok
18:11:34.0183 5132 [ 6D4CCAEDC018F1CF52866BBBAA235982 ] sffp_sd C:\Windows\system32\drivers\sffp_sd.sys
18:11:34.0187 5132 sffp_sd - ok
18:11:34.0222 5132 [ DB96666CC8312EBC45032F30B007A547 ] sfloppy C:\Windows\system32\DRIVERS\sfloppy.sys
18:11:34.0233 5132 sfloppy - ok
18:11:34.0266 5132 [ D1A079A0DE2EA524513B6930C24527A2 ] SharedAccess C:\Windows\System32\ipnathlp.dll
18:11:34.0283 5132 SharedAccess - ok
18:11:34.0347 5132 [ 414DA952A35BF5D50192E28263B40577 ] ShellHWDetection C:\Windows\System32\shsvcs.dll
18:11:34.0350 5132 ShellHWDetection - ok
18:11:34.0364 5132 [ 2565CAC0DC9FE0371BDCE60832582B2E ] sisagp C:\Windows\system32\drivers\sisagp.sys
18:11:34.0377 5132 sisagp - ok
18:11:34.0418 5132 [ A9F0486851BECB6DDA1D89D381E71055 ] SiSRaid2 C:\Windows\system32\DRIVERS\SiSRaid2.sys
18:11:34.0424 5132 SiSRaid2 - ok
18:11:34.0436 5132 [ 3727097B55738E2F554972C3BE5BC1AA ] SiSRaid4 C:\Windows\system32\DRIVERS\sisraid4.sys
18:11:34.0447 5132 SiSRaid4 - ok
18:11:34.0474 5132 [ 3E21C083B8A01CB70BA1F09303010FCE ] Smb C:\Windows\system32\DRIVERS\smb.sys
18:11:34.0489 5132 Smb - ok
18:11:34.0532 5132 [ 6A984831644ECA1A33FFEAE4126F4F37 ] SNMPTRAP C:\Windows\System32\snmptrap.exe
18:11:34.0538 5132 SNMPTRAP - ok
18:11:34.0547 5132 [ 95CF1AE7527FB70F7816563CBC09D942 ] spldr C:\Windows\system32\drivers\spldr.sys
18:11:34.0554 5132 spldr - ok
18:11:34.0603 5132 [ 9AEA093B8F9C37CF45538382CABA2475 ] Spooler C:\Windows\System32\spoolsv.exe
18:11:34.0606 5132 Spooler - ok
18:11:35.0091 5132 [ CF87A1DE791347E75B98885214CED2B8 ] sppsvc C:\Windows\system32\sppsvc.exe
18:11:35.0108 5132 sppsvc - ok
18:11:35.0167 5132 [ B0180B20B065D89232A78A40FE56EAA6 ] sppuinotify C:\Windows\system32\sppuinotify.dll
18:11:35.0185 5132 sppuinotify - ok
18:11:35.0342 5132 [ CDDDEC541BC3C96F91ECB48759673505 ] sptd C:\Windows\system32\Drivers\sptd.sys
18:11:35.0343 5132 Suspicious file (NoAccess): C:\Windows\system32\Drivers\sptd.sys. md5: CDDDEC541BC3C96F91ECB48759673505
18:11:35.0345 5132 sptd ( LockedFile.Multi.Generic ) - warning
18:11:35.0345 5132 sptd - detected LockedFile.Multi.Generic (1)
18:11:35.0414 5132 [ E4C2764065D66EA1D2D3EBC28FE99C46 ] srv C:\Windows\system32\DRIVERS\srv.sys
18:11:35.0486 5132 srv - ok
18:11:35.0548 5132 [ 03F0545BD8D4C77FA0AE1CEEDFCC71AB ] srv2 C:\Windows\system32\DRIVERS\srv2.sys
18:11:35.0664 5132 srv2 - ok
18:11:35.0702 5132 [ BE6BD660CAA6F291AE06A718A4FA8ABC ] srvnet C:\Windows\system32\DRIVERS\srvnet.sys
18:11:35.0734 5132 srvnet - ok
18:11:35.0781 5132 [ D887C9FD02AC9FA880F6E5027A43E118 ] SSDPSRV C:\Windows\System32\ssdpsrv.dll
18:11:35.0786 5132 SSDPSRV - ok
18:11:35.0809 5132 [ A36EE93698802CD899F98BFD553D8185 ] ssmdrv C:\Windows\system32\DRIVERS\ssmdrv.sys
18:11:35.0815 5132 ssmdrv - ok
18:11:35.0829 5132 [ D318F23BE45D5E3A107469EB64815B50 ] SstpSvc C:\Windows\system32\sstpsvc.dll
18:11:35.0839 5132 SstpSvc - ok
18:11:35.0908 5132 Steam Client Service - ok
18:11:35.0940 5132 [ DB32D325C192B801DF274BFD12A7E72B ] stexstor C:\Windows\system32\DRIVERS\stexstor.sys
18:11:35.0954 5132 stexstor - ok
18:11:36.0034 5132 [ E1FB3706030FB4578A0D72C2FC3689E4 ] StiSvc C:\Windows\System32\wiaservc.dll
18:11:36.0072 5132 StiSvc - ok
18:11:36.0081 5132 [ 472AF0311073DCECEAA8FA18BA2BDF89 ] storflt C:\Windows\system32\drivers\vmstorfl.sys
18:11:36.0089 5132 storflt - ok
18:11:36.0129 5132 [ DCAFFD62259E0BDB433DD67B5BB37619 ] storvsc C:\Windows\system32\drivers\storvsc.sys
18:11:36.0138 5132 storvsc - ok
18:11:36.0143 5132 [ E58C78A848ADD9610A4DB6D214AF5224 ] swenum C:\Windows\system32\drivers\swenum.sys
18:11:36.0148 5132 swenum - ok
18:11:36.0348 5132 [ F577910A133A592234EBAAD3F3AFA258 ] SwitchBoard C:\Program Files\Common Files\Adobe\SwitchBoard\SwitchBoard.exe
18:11:36.0374 5132 SwitchBoard - ok
18:11:36.0420 5132 [ A28BD92DF340E57B024BA433165D34D7 ] swprv C:\Windows\System32\swprv.dll
18:11:36.0423 5132 swprv - ok
18:11:36.0436 5132 Synth3dVsc - ok
18:11:36.0532 5132 [ 36650D618CA34C9D357DFD3D89B2C56F ] SysMain C:\Windows\system32\sysmain.dll
18:11:36.0555 5132 SysMain - ok
18:11:36.0596 5132 [ 763FECDC3D30C815FE72DD57936C6CD1 ] TabletInputService C:\Windows\System32\TabSvc.dll
18:11:36.0604 5132 TabletInputService - ok
18:11:36.0651 5132 [ 613BF4820361543956909043A265C6AC ] TapiSrv C:\Windows\System32\tapisrv.dll
18:11:36.0695 5132 TapiSrv - ok
18:11:36.0756 5132 [ B799D9FDB26111737F58288D8DC172D9 ] TBS C:\Windows\System32\tbssvc.dll
18:11:36.0772 5132 TBS - ok
18:11:36.0908 5132 [ A5EBB8F648000E88B7D9390B514976BF ] Tcpip C:\Windows\system32\drivers\tcpip.sys
18:11:37.0072 5132 Tcpip - ok
18:11:37.0200 5132 [ A5EBB8F648000E88B7D9390B514976BF ] TCPIP6 C:\Windows\system32\DRIVERS\tcpip.sys
18:11:37.0206 5132 TCPIP6 - ok
18:11:37.0252 5132 [ CCA24162E055C3714CE5A88B100C64ED ] tcpipreg C:\Windows\system32\drivers\tcpipreg.sys
18:11:37.0258 5132 tcpipreg - ok
18:11:37.0322 5132 [ 1CB91B2BD8F6DD367DFC2EF26FD751B2 ] TDPIPE C:\Windows\system32\drivers\tdpipe.sys
18:11:37.0341 5132 TDPIPE - ok
18:11:37.0383 5132 [ 2C2C5AFE7EE4F620D69C23C0617651A8 ] TDTCP C:\Windows\system32\drivers\tdtcp.sys
18:11:37.0416 5132 TDTCP - ok
18:11:37.0483 5132 [ B459575348C20E8121D6039DA063C704 ] tdx C:\Windows\system32\DRIVERS\tdx.sys
18:11:37.0494 5132 tdx - ok
18:11:37.0572 5132 [ 04DBF4B01EA4BF25A9A3E84AFFAC9B20 ] TermDD C:\Windows\system32\drivers\termdd.sys
18:11:37.0584 5132 TermDD - ok
18:11:37.0626 5132 [ 382C804C92811BE57829D8E550A900E2 ] TermService C:\Windows\System32\termsrv.dll
18:11:37.0635 5132 TermService - ok
18:11:37.0663 5132 [ 42FB6AFD6B79D9FE07381609172E7CA4 ] Themes C:\Windows\system32\themeservice.dll
18:11:37.0666 5132 Themes - ok
18:11:37.0680 5132 [ 146B6F43A673379A3C670E86D89BE5EA ] THREADORDER C:\Windows\system32\mmcss.dll
18:11:37.0682 5132 THREADORDER - ok
18:11:37.0707 5132 [ 4792C0378DB99A9BC2AE2DE6CFFF0C3A ] TrkWks C:\Windows\System32\trkwks.dll
18:11:37.0710 5132 TrkWks - ok
18:11:37.0770 5132 [ 2C49B175AEE1D4364B91B531417FE583 ] TrustedInstaller C:\Windows\servicing\TrustedInstaller.exe
18:11:37.0772 5132 TrustedInstaller - ok
18:11:37.0813 5132 [ 254BB140EEE3C59D6114C1A86B636877 ] tssecsrv C:\Windows\system32\DRIVERS\tssecsrv.sys
18:11:37.0820 5132 tssecsrv - ok
18:11:37.0861 5132 [ FD1D6C73E6333BE727CBCC6054247654 ] TsUsbFlt C:\Windows\system32\drivers\tsusbflt.sys
18:11:37.0873 5132 TsUsbFlt - ok
18:11:37.0876 5132 tsusbhub - ok
18:11:37.0947 5132 [ B2FA25D9B17A68BB93D58B0556E8C90D ] tunnel C:\Windows\system32\DRIVERS\tunnel.sys
18:11:37.0960 5132 tunnel - ok
18:11:37.0993 5132 [ 750FBCB269F4D7DD2E420C56B795DB6D ] uagp35 C:\Windows\system32\DRIVERS\uagp35.sys
18:11:38.0012 5132 uagp35 - ok
18:11:38.0072 5132 [ EE43346C7E4B5E63E54F927BABBB32FF ] udfs C:\Windows\system32\DRIVERS\udfs.sys
18:11:38.0088 5132 udfs - ok
18:11:38.0124 5132 [ 8344FD4FCE927880AA1AA7681D4927E5 ] UI0Detect C:\Windows\system32\UI0Detect.exe
18:11:38.0141 5132 UI0Detect - ok
18:11:38.0188 5132 [ 44E8048ACE47BEFBFDC2E9BE4CBC8880 ] uliagpkx C:\Windows\system32\drivers\uliagpkx.sys
18:11:38.0212 5132 uliagpkx - ok
18:11:38.0504 5132 [ D295BED4B898F0FD999FCFA9B32B071B ] umbus C:\Windows\system32\drivers\umbus.sys
18:11:38.0531 5132 umbus - ok
18:11:38.0576 5132 [ 7550AD0C6998BA1CB4843E920EE0FEAC ] UmPass C:\Windows\system32\DRIVERS\umpass.sys
18:11:38.0584 5132 UmPass - ok
18:11:38.0634 5132 [ 409994A8EACEEE4E328749C0353527A0 ] UmRdpService C:\Windows\System32\umrdp.dll
18:11:38.0638 5132 UmRdpService - ok
18:11:38.0670 5132 [ 833FBB672460EFCE8011D262175FAD33 ] upnphost C:\Windows\System32\upnphost.dll
18:11:38.0674 5132 upnphost - ok
18:11:38.0733 5132 [ BD9C55D7023C5DE374507ACC7A14E2AC ] usbccgp C:\Windows\system32\drivers\usbccgp.sys
18:11:38.0748 5132 usbccgp - ok
18:11:38.0820 5132 [ 04EC7CEC62EC3B6D9354EEE93327FC82 ] usbcir C:\Windows\system32\drivers\usbcir.sys
18:11:38.0830 5132 usbcir - ok
18:11:38.0842 5132 [ F92DE757E4B7CE9C07C5E65423F3AE3B ] usbehci C:\Windows\system32\DRIVERS\usbehci.sys
18:11:38.0853 5132 usbehci - ok
18:11:38.0950 5132 [ 8DC94AEC6A7E644A06135AE7506DC2E9 ] usbhub C:\Windows\system32\DRIVERS\usbhub.sys
18:11:39.0047 5132 usbhub - ok
18:11:39.0100 5132 [ E185D44FAC515A18D9DEDDC23C2CDF44 ] usbohci C:\Windows\system32\drivers\usbohci.sys
18:11:39.0115 5132 usbohci - ok
18:11:39.0198 5132 [ 797D862FE0875E75C7CC4C1AD7B30252 ] usbprint C:\Windows\system32\DRIVERS\usbprint.sys
18:11:39.0238 5132 usbprint - ok
18:11:39.0295 5132 [ F991AB9CC6B908DB552166768176896A ] USBSTOR C:\Windows\system32\DRIVERS\USBSTOR.SYS
18:11:39.0318 5132 USBSTOR - ok
18:11:39.0361 5132 [ 68DF884CF41CDADA664BEB01DAF67E3D ] usbuhci C:\Windows\system32\drivers\usbuhci.sys
18:11:39.0378 5132 usbuhci - ok
18:11:39.0423 5132 [ 081E6E1C91AEC36758902A9F727CD23C ] UxSms C:\Windows\System32\uxsms.dll
18:11:39.0427 5132 UxSms - ok
18:11:39.0465 5132 [ 81951F51E318AECC2D68559E47485CC4 ] VaultSvc C:\Windows\system32\lsass.exe
18:11:39.0468 5132 VaultSvc - ok
18:11:39.0539 5132 [ 94D73B62E458FB56C9CE60AA96D914F9 ] VClone C:\Windows\system32\DRIVERS\VClone.sys
18:11:39.0547 5132 VClone - ok
18:11:39.0592 5132 [ A059C4C3EDB09E07D21A8E5C0AABD3CB ] vdrvroot
A voir également:

2 réponses

phoceen8 Messages postés 1176 Date d'inscription mardi 9 février 2010 Statut Membre Dernière intervention 1 octobre 2021 157
15 nov. 2012 à 19:22
Salut,
Perso je t'aurais conseille un examen MalwareBytes minutieux il est très long mais redoutable là il n'a rien trouvé ou presque (quand je dis redoutable comprendre il est souvent d'une grande utilité pas qu'il est sur à tous les coups ) :)

Sinon télécharges AdwCleaner
Cliques sur Suppression puis postes le rapport ici
On verra si il l'a supprimé, si il ne l'a pas vu je pense qu'il n'est déjà plus là mais voyons ça un scan minutieux de MBAM et ça devrait faire l'affaire

Bon courage :)
0
Gosso Messages postés 4 Date d'inscription jeudi 15 novembre 2012 Statut Membre Dernière intervention 24 novembre 2012
21 nov. 2012 à 08:42
Salut ami Phocéen,

J'ai été très pris ces derniers jours et n'ai pas vu ton message avant hier soir.
J'ai donc suivi tes conseils et lancé un examen minucieux avec MalwareBytes !
Voilà le rapport :

Malwarebytes Anti-Malware (Essai) 1.65.1.1000
www.malwarebytes.org

Version de la base de données: v2012.11.20.04

Windows 7 Service Pack 1 x86 NTFS
Internet Explorer 8.0.7601.17514
armelle :: ARMELLE-PC [administrateur]

Protection: Activé

20/11/2012 23:16:06
mbam-log-2012-11-20 (23-16-06).txt

Type d'examen: Examen complet (C:\|D:\|E:\|F:\|G:\|H:\|I:\|J:\|K:\|L:\|)
Options d'examen activées: Mémoire | Démarrage | Registre | Système de fichiers | Heuristique/Extra | Heuristique/Shuriken | PUP | PUM
Options d'examen désactivées: P2P
Elément(s) analysé(s): 724402
Temps écoulé: 2 heure(s), 59 minute(s), 34 seconde(s)

Processus mémoire détecté(s): 0
(Aucun élément nuisible détecté)

Module(s) mémoire détecté(s): 0
(Aucun élément nuisible détecté)

Clé(s) du Registre détectée(s): 0
(Aucun élément nuisible détecté)

Valeur(s) du Registre détectée(s): 0
(Aucun élément nuisible détecté)

Elément(s) de données du Registre détecté(s): 0
(Aucun élément nuisible détecté)

Dossier(s) détecté(s): 0
(Aucun élément nuisible détecté)

Fichier(s) détecté(s): 3
C:\Users\armelle\Desktop\Adobe.Creative.Suite.5.Master.Collection\keygen.exe (Trojan.Agent.CK) -> Aucune action effectuée.
K:\logiciels\Adobe.Creative.Suite.5.Master.Collection\keygen.exe (Trojan.Agent.CK) -> Aucune action effectuée.
C:\Users\armelle\Downloads\Windows Loader v1.9.5\Windows Loader v1.9.5\Windows Loader\Windows Loader.exe (RiskWare.Tool.CK) -> Mis en quarantaine et supprimé avec succès.

(fin)

Dans le doute j'ai aussi un ADWCleaner ce matin en complément :

# AdwCleaner v2.007 - Rapport créé le 21/11/2012 à 08:29:52
# Mis à jour le 06/11/2012 par Xplode
# Système d'exploitation : Windows 7 Ultimate Service Pack 1 (32 bits)
# Nom d'utilisateur : armelle - ARMELLE-PC
# Mode de démarrage : Normal
# Exécuté depuis : C:\Users\armelle\Desktop\adwcleaner.exe
# Option [Suppression]


***** [Services] *****


***** [Fichiers / Dossiers] *****

Dossier Supprimé : C:\Users\armelle\AppData\Roaming\Mozilla\Firefox\Profiles\0y40zom0.default\extensions\staged

***** [Registre] *****


***** [Navigateurs] *****

-\\ Internet Explorer v8.0.7601.17514

[OK] Le registre ne contient aucune entrée illégitime.

-\\ Mozilla Firefox v16.0.2 (fr)

Nom du profil : default
Fichier : C:\Users\armelle\AppData\Roaming\Mozilla\Firefox\Profiles\0y40zom0.default\prefs.js

Supprimée : user_pref("extensions.aniweather.timeShifted", 283148);
Supprimée : user_pref("extensions.crossriderapp5060.5060.InstallationTime", 1352832446);
Supprimée : user_pref("extensions.crossriderapp5060.5060.active", true);
Supprimée : user_pref("extensions.crossriderapp5060.5060.addressbar", "");
Supprimée : user_pref("extensions.crossriderapp5060.5060.backgroundjs", "\n\n\"undefined\"!=typeof _GPL_BG_NEW&&[...]
Supprimée : user_pref("extensions.crossriderapp5060.5060.backgroundver", 7);
Supprimée : user_pref("extensions.crossriderapp5060.5060.can_run_bg_code", true);
Supprimée : user_pref("extensions.crossriderapp5060.5060.certdomaininstaller", "");
Supprimée : user_pref("extensions.crossriderapp5060.5060.changeprevious", false);
Supprimée : user_pref("extensions.crossriderapp5060.5060.cookie.InstallationTime.expiration", "Fri Feb 01 2030 0[...]
Supprimée : user_pref("extensions.crossriderapp5060.5060.cookie.InstallationTime.value", "1352832446");
Supprimée : user_pref("extensions.crossriderapp5060.5060.cookie._GPL_aoi.expiration", "Fri Feb 01 2030 00:00:00 [...]
Supprimée : user_pref("extensions.crossriderapp5060.5060.cookie._GPL_aoi.value", "1352832446");
Supprimée : user_pref("extensions.crossriderapp5060.5060.cookie._GPL_blocklist.expiration", "Tue Nov 20 2012 23:[...]
Supprimée : user_pref("extensions.crossriderapp5060.5060.cookie._GPL_blocklist.value", "%22nonexistantdomain.com[...]
Supprimée : user_pref("extensions.crossriderapp5060.5060.cookie._GPL_country_code.expiration", "Tue Nov 27 2012 [...]
Supprimée : user_pref("extensions.crossriderapp5060.5060.cookie._GPL_country_code.value", "%22FR%22");
Supprimée : user_pref("extensions.crossriderapp5060.5060.cookie._GPL_crr.expiration", "Fri Feb 01 2030 00:00:00 [...]
Supprimée : user_pref("extensions.crossriderapp5060.5060.cookie._GPL_crr.value", "1353447906");
Supprimée : user_pref("extensions.crossriderapp5060.5060.cookie._GPL_hotfix20111102645.expiration", "Fri Feb 01 [...]
Supprimée : user_pref("extensions.crossriderapp5060.5060.cookie._GPL_hotfix20111102645.value", "%221%22");
Supprimée : user_pref("extensions.crossriderapp5060.5060.cookie._GPL_installer_params.expiration", "Fri Feb 01 2[...]
Supprimée : user_pref("extensions.crossriderapp5060.5060.cookie._GPL_installer_params.value", "%7B%22source_id%2[...]
Supprimée : user_pref("extensions.crossriderapp5060.5060.cookie._GPL_parent_zoneid.expiration", "Fri Feb 01 2030[...]
Supprimée : user_pref("extensions.crossriderapp5060.5060.cookie._GPL_parent_zoneid.value", "%2214019%22");
Supprimée : user_pref("extensions.crossriderapp5060.5060.cookie._GPL_pc_20120828.expiration", "Fri Feb 01 2030 0[...]
Supprimée : user_pref("extensions.crossriderapp5060.5060.cookie._GPL_pc_20120828.value", "1352832668692");
Supprimée : user_pref("extensions.crossriderapp5060.5060.cookie._GPL_product_id.expiration", "Fri Feb 01 2030 00[...]
Supprimée : user_pref("extensions.crossriderapp5060.5060.cookie._GPL_product_id.value", "%221224%22");
Supprimée : user_pref("extensions.crossriderapp5060.5060.cookie._GPL_zoneid.expiration", "Fri Feb 01 2030 00:00:[...]
Supprimée : user_pref("extensions.crossriderapp5060.5060.cookie._GPL_zoneid.value", "%22106125%22");
Supprimée : user_pref("extensions.crossriderapp5060.5060.cookie.dbtest.expiration", "Fri Feb 01 2030 00:00:00 GM[...]
Supprimée : user_pref("extensions.crossriderapp5060.5060.cookie.dbtest.value", "1352832457827");
Supprimée : user_pref("extensions.crossriderapp5060.5060.description", "Savings Sidekick");
Supprimée : user_pref("extensions.crossriderapp5060.5060.domain", "");
Supprimée : user_pref("extensions.crossriderapp5060.5060.enablesearch", false);
Supprimée : user_pref("extensions.crossriderapp5060.5060.fbremoteurl", "");
Supprimée : user_pref("extensions.crossriderapp5060.5060.group", 0);
Supprimée : user_pref("extensions.crossriderapp5060.5060.homepage", "");
Supprimée : user_pref("extensions.crossriderapp5060.5060.iframe", false);
Supprimée : user_pref("extensions.crossriderapp5060.5060.internaldb.Resources_appVer.expiration", "Fri Feb 01 20[...]
Supprimée : user_pref("extensions.crossriderapp5060.5060.internaldb.Resources_appVer.value", "38");
Supprimée : user_pref("extensions.crossriderapp5060.5060.internaldb.Resources_lastVersion.expiration", "Fri Feb [...]
Supprimée : user_pref("extensions.crossriderapp5060.5060.internaldb.Resources_lastVersion.value", "0");
Supprimée : user_pref("extensions.crossriderapp5060.5060.internaldb.Resources_meta.expiration", "Fri Feb 01 2030[...]
Supprimée : user_pref("extensions.crossriderapp5060.5060.internaldb.Resources_meta.value", "%7B%7D");
Supprimée : user_pref("extensions.crossriderapp5060.5060.internaldb.Resources_nextCheck.expiration", "Wed Nov 21[...]
Supprimée : user_pref("extensions.crossriderapp5060.5060.internaldb.Resources_nextCheck.value", "true");
Supprimée : user_pref("extensions.crossriderapp5060.5060.internaldb.Resources_queue.expiration", "Fri Feb 01 203[...]
Supprimée : user_pref("extensions.crossriderapp5060.5060.internaldb.Resources_queue.value", "%7B%7D");
Supprimée : user_pref("extensions.crossriderapp5060.5060.internaldb.Resources_remote_resources.expiration", "Fri[...]
Supprimée : user_pref("extensions.crossriderapp5060.5060.internaldb.Resources_remote_resources.value", "%7B%22re[...]
Supprimée : user_pref("extensions.crossriderapp5060.5060.js", "\n\nif(\"undefined\"!=typeof _GPL_PLUGIN){var _GP[...]
Supprimée : user_pref("extensions.crossriderapp5060.5060.manifesturl", "");
Supprimée : user_pref("extensions.crossriderapp5060.5060.name", "Savings Sidekick");
Supprimée : user_pref("extensions.crossriderapp5060.5060.newtab", "");
Supprimée : user_pref("extensions.crossriderapp5060.5060.opensearch", "");
Supprimée : user_pref("extensions.crossriderapp5060.5060.plugins.plugin_1.code", "appAPI._cr_config={appID:funct[...]
Supprimée : user_pref("extensions.crossriderapp5060.5060.plugins.plugin_1.name", "base");
Supprimée : user_pref("extensions.crossriderapp5060.5060.plugins.plugin_1.ver", 3);
Supprimée : user_pref("extensions.crossriderapp5060.5060.plugins.plugin_1000014.code", "Array.prototype.indexOf|[...]
Supprimée : user_pref("extensions.crossriderapp5060.5060.plugins.plugin_1000014.name", "GPL Plugin (Loader)");
Supprimée : user_pref("extensions.crossriderapp5060.5060.plugins.plugin_1000014.ver", 7);
Supprimée : user_pref("extensions.crossriderapp5060.5060.plugins.plugin_1000015.code", "var _GPL_BG={vars:{},rul[...]
Supprimée : user_pref("extensions.crossriderapp5060.5060.plugins.plugin_1000015.name", "GPL Background (BG)");
Supprimée : user_pref("extensions.crossriderapp5060.5060.plugins.plugin_1000015.ver", 4);
Supprimée : user_pref("extensions.crossriderapp5060.5060.plugins.plugin_13.code", "(function(a){a.selectedText=f[...]
Supprimée : user_pref("extensions.crossriderapp5060.5060.plugins.plugin_13.name", "CrossriderAppUtils");
Supprimée : user_pref("extensions.crossriderapp5060.5060.plugins.plugin_13.ver", 2);
Supprimée : user_pref("extensions.crossriderapp5060.5060.plugins.plugin_14.code", "if(typeof(appAPI)===\"undefin[...]
Supprimée : user_pref("extensions.crossriderapp5060.5060.plugins.plugin_14.name", "CrossriderUtils");
Supprimée : user_pref("extensions.crossriderapp5060.5060.plugins.plugin_14.ver", 2);
Supprimée : user_pref("extensions.crossriderapp5060.5060.plugins.plugin_15.code", "(function(f){var u={};var e=M[...]
Supprimée : user_pref("extensions.crossriderapp5060.5060.plugins.plugin_15.name", "FacebookFFIE");
Supprimée : user_pref("extensions.crossriderapp5060.5060.plugins.plugin_15.ver", 1);
Supprimée : user_pref("extensions.crossriderapp5060.5060.plugins.plugin_16.code", "if((typeof isBackground===\"u[...]
Supprimée : user_pref("extensions.crossriderapp5060.5060.plugins.plugin_16.name", "FFAppAPIWrapper");
Supprimée : user_pref("extensions.crossriderapp5060.5060.plugins.plugin_16.ver", 4);
Supprimée : user_pref("extensions.crossriderapp5060.5060.plugins.plugin_17.code", "if(typeof window!==\"undefine[...]
Supprimée : user_pref("extensions.crossriderapp5060.5060.plugins.plugin_17.name", "jQuery");
Supprimée : user_pref("extensions.crossriderapp5060.5060.plugins.plugin_17.ver", 3);
Supprimée : user_pref("extensions.crossriderapp5060.5060.plugins.plugin_21.code", "var CrossriderDebugManager=(f[...]
Supprimée : user_pref("extensions.crossriderapp5060.5060.plugins.plugin_21.name", "debug");
Supprimée : user_pref("extensions.crossriderapp5060.5060.plugins.plugin_21.ver", 3);
Supprimée : user_pref("extensions.crossriderapp5060.5060.plugins.plugin_22.code", "(function(a){appAPI.queueMana[...]
Supprimée : user_pref("extensions.crossriderapp5060.5060.plugins.plugin_22.name", "resources");
Supprimée : user_pref("extensions.crossriderapp5060.5060.plugins.plugin_22.ver", 2);
Supprimée : user_pref("extensions.crossriderapp5060.5060.plugins.plugin_28.code", "var CrossriderInitializerPlug[...]
Supprimée : user_pref("extensions.crossriderapp5060.5060.plugins.plugin_28.name", "initializer");
Supprimée : user_pref("extensions.crossriderapp5060.5060.plugins.plugin_28.ver", 2);
Supprimée : user_pref("extensions.crossriderapp5060.5060.plugins.plugin_4.code", "/*! jQuery v1.7.1 jquery.com |[...]
Supprimée : user_pref("extensions.crossriderapp5060.5060.plugins.plugin_4.name", "jquery_1_7_1");
Supprimée : user_pref("extensions.crossriderapp5060.5060.plugins.plugin_4.ver", 3);
Supprimée : user_pref("extensions.crossriderapp5060.5060.plugins.plugin_47.code", "(function(){appAPI.ready=func[...]
Supprimée : user_pref("extensions.crossriderapp5060.5060.plugins.plugin_47.name", "resources_background");
Supprimée : user_pref("extensions.crossriderapp5060.5060.plugins.plugin_47.ver", 1);
Supprimée : user_pref("extensions.crossriderapp5060.5060.plugins_lists.plugins_0", "17,14,16,47,1000015");
Supprimée : user_pref("extensions.crossriderapp5060.5060.plugins_lists.plugins_1", "17,14,13,16,15,4,1,21,22,100[...]
Supprimée : user_pref("extensions.crossriderapp5060.5060.pluginsurl", "hxxp://app-static.crossrider.com/plugin/a[...]
Supprimée : user_pref("extensions.crossriderapp5060.5060.pluginsversion", 16);
Supprimée : user_pref("extensions.crossriderapp5060.5060.publisher", "215 Apps");
Supprimée : user_pref("extensions.crossriderapp5060.5060.searchstatus", 0);
Supprimée : user_pref("extensions.crossriderapp5060.5060.setnewtab", false);
Supprimée : user_pref("extensions.crossriderapp5060.5060.settingsurl", "");
Supprimée : user_pref("extensions.crossriderapp5060.5060.thankyou", "");
Supprimée : user_pref("extensions.crossriderapp5060.5060.updateinterval", 360);
Supprimée : user_pref("extensions.crossriderapp5060.5060.ver", 38);
Supprimée : user_pref("extensions.crossriderapp5060.apps", "5060");
Supprimée : user_pref("extensions.crossriderapp5060.bic", "13a46a0ff735b0027b520980c0a86149");
Supprimée : user_pref("extensions.crossriderapp5060.cid", 5060);
Supprimée : user_pref("extensions.crossriderapp5060.firstrun", false);
Supprimée : user_pref("extensions.crossriderapp5060.hadappinstalled", true);
Supprimée : user_pref("extensions.crossriderapp5060.installationdate", 1352832446);
Supprimée : user_pref("extensions.crossriderapp5060.lastcheck", 22557248);
Supprimée : user_pref("extensions.crossriderapp5060.lastcheckitem", 22557513);
Supprimée : user_pref("extensions.crossriderapp5060.modetype", "production");
Supprimée : user_pref("extensions.crossriderapp5060.reportInstall", true);

*************************

AdwCleaner[R1].txt - [12094 octets] - [14/11/2012 18:41:55]
AdwCleaner[R2].txt - [12564 octets] - [21/11/2012 08:29:23]
AdwCleaner[S1].txt - [20739 octets] - [13/11/2012 19:44:03]
AdwCleaner[S2].txt - [12272 octets] - [14/11/2012 18:42:14]
AdwCleaner[S3].txt - [12614 octets] - [21/11/2012 08:29:52]

########## EOF - C:\AdwCleaner[S3].txt - [12675 octets] ##########


Merci à toi et aux autres pour vos éclaircissements futurs
0
phoceen8 Messages postés 1176 Date d'inscription mardi 9 février 2010 Statut Membre Dernière intervention 1 octobre 2021 157
21 nov. 2012 à 17:56
Dans le scan MBAM, il y a deux trojan ou il n'a eu aucune action d'effectuée tu n'as pas pu le supprimer ?
Va voir dans le logiciel dans l'onglet Quarantaine et tu fais Tout supprimer :)
Aussi, je vois pas mal de petits trucs dans AdwCleaner mais rien qui me rappele ce "virus" alors je pense qu'il est définitivement plus là...
Cependant je ne suis pas un pro non plus, donc je m'avance pas trop, est-ce que tu ressens encore les conséquences nocives de ce virus ?
0
Gosso Messages postés 4 Date d'inscription jeudi 15 novembre 2012 Statut Membre Dernière intervention 24 novembre 2012
22 nov. 2012 à 23:48
J'ai supprimé les trojans et après une aprèm' où ça marchait bien, le virus est réapparu !
Bref j'arrive pas à m'en débarrasser :(
0
Gosso Messages postés 4 Date d'inscription jeudi 15 novembre 2012 Statut Membre Dernière intervention 24 novembre 2012
24 nov. 2012 à 10:23
Quelqu'un pour me venir en aide ?
0
kalimusic Messages postés 14014 Date d'inscription samedi 7 novembre 2009 Statut Contributeur sécurité Dernière intervention 20 novembre 2015 3 027
24 nov. 2012 à 11:01
Bonjour,

Le détections de Malwarebytes n'incite pas à l'entraide.
Ta version de Windows n'a sûrement pas été validée de façon officielle.
Idem pour les logiciels de l'éditeur Adobe.

https://www.commentcamarche.net/faq/2981-j-utilise-une-version-piratee-de-windows
https://www.commentcamarche.net/infos/25921-pourquoi-ccm-n-aide-pas-la-contrefacon-numerique-des-logiciels/

Ceci expliquant en grande partie, les problèmes rencontrés.
Les infections ne sont pas du au hasard.

cdt
0
phoceen8 Messages postés 1176 Date d'inscription mardi 9 février 2010 Statut Membre Dernière intervention 1 octobre 2021 157
24 nov. 2012 à 18:41
Dans ce cas je préfere te laisser entre mains de professionnels :)
Bon courage et bonne continuation :)
0