Aide pour déchiffrer un log GMER

peace -  
jlpjlp Messages postés 52399 Statut Contributeur sécurité -
Bonjour à tous

pourriez-vous m'aider à déchiffré ce log, car je n'y comprend rien :/ merci d'avance et joyeux noel a toutes et tous^^

GMER 1.0.13.12551 - http://www.gmer.net
Rootkit scan 2007-12-24 15:48:15
Windows 5.1.2600 Service Pack 2


---- System - GMER 1.0.13 ----

SSDT \SystemRoot\System32\vsdatant.sys ZwConnectPort
SSDT \SystemRoot\System32\vsdatant.sys ZwCreateFile
SSDT \SystemRoot\System32\vsdatant.sys ZwCreateKey
SSDT \SystemRoot\System32\vsdatant.sys ZwCreatePort
SSDT \SystemRoot\System32\vsdatant.sys ZwCreateProcess
SSDT \SystemRoot\System32\vsdatant.sys ZwCreateProcessEx
SSDT \SystemRoot\System32\vsdatant.sys ZwCreateSection
SSDT A4FC075C ZwCreateThread
SSDT \SystemRoot\System32\vsdatant.sys ZwCreateWaitablePort
SSDT \SystemRoot\System32\vsdatant.sys ZwDeleteFile
SSDT \SystemRoot\System32\vsdatant.sys ZwDeleteKey
SSDT \SystemRoot\System32\vsdatant.sys ZwDeleteValueKey
SSDT \SystemRoot\System32\vsdatant.sys ZwDuplicateObject
SSDT sptd.sys ZwEnumerateKey
SSDT sptd.sys ZwEnumerateValueKey
SSDT \SystemRoot\System32\vsdatant.sys ZwLoadKey
SSDT \SystemRoot\System32\vsdatant.sys ZwOpenFile
SSDT sptd.sys ZwOpenKey
SSDT A4FC0748 ZwOpenProcess
SSDT A4FC074D ZwOpenThread
SSDT sptd.sys ZwQueryKey
SSDT sptd.sys ZwQueryValueKey
SSDT \SystemRoot\System32\vsdatant.sys ZwRenameKey
SSDT \SystemRoot\System32\vsdatant.sys ZwReplaceKey
SSDT \SystemRoot\System32\vsdatant.sys ZwRequestWaitReplyPort
SSDT \SystemRoot\System32\vsdatant.sys ZwRestoreKey
SSDT \SystemRoot\System32\vsdatant.sys ZwSecureConnectPort
SSDT \SystemRoot\System32\vsdatant.sys ZwSetInformationFile
SSDT \SystemRoot\System32\vsdatant.sys ZwSetValueKey
SSDT A4FC0757 ZwTerminateProcess
SSDT \??\D:\WINDOWS\system32\Drivers\uphcleanhlp.sys ZwUnloadKey
SSDT A4FC0752 ZwWriteVirtualMemory

---- Kernel code sections - GMER 1.0.13 ----

.text ntkrnlpa.exe!ZwCallbackReturn + 2C4C 8082CB28 12 Bytes [ 70, 42, 95, A2, 00, A5, 95, ... ]
? D:\WINDOWS\system32\drivers\sptd.sys Le processus ne peut pas accéder au fichier car ce fichier est utilisé par un autre processus.
? srescan.sys Le fichier spécifié est introuvable.
.text USBPORT.SYS!DllUnload B890762C 5 Bytes JMP 8A671770
? System32\Drivers\a6ynt6vq.SYS Le fichier spécifié est introuvable.
? System32\Drivers\a8v04jmg.SYS Le fichier spécifié est introuvable.
? D:\WINDOWS\system32\Drivers\uphcleanhlp.sys Le fichier spécifié est introuvable.

---- User code sections - GMER 1.0.13 ----

.text D:\Program Files\Internet Explorer\IEXPLORE.EXE[2320] USER32.dll!DialogBoxParamW 7E3A5F8F 5 Bytes JMP 4437F2C1 D:\WINDOWS\system32\IEFRAME.dll
.text D:\Program Files\Internet Explorer\IEXPLORE.EXE[2320] USER32.dll!DialogBoxIndirectParamW 7E3B2062 5 Bytes JMP 4451166F D:\WINDOWS\system32\IEFRAME.dll
.text D:\Program Files\Internet Explorer\IEXPLORE.EXE[2320] USER32.dll!MessageBoxIndirectA 7E3BA06A 5 Bytes JMP 445115F0 D:\WINDOWS\system32\IEFRAME.dll
.text D:\Program Files\Internet Explorer\IEXPLORE.EXE[2320] USER32.dll!DialogBoxParamA 7E3BB12C 5 Bytes JMP 44511634 D:\WINDOWS\system32\IEFRAME.dll
.text D:\Program Files\Internet Explorer\IEXPLORE.EXE[2320] USER32.dll!MessageBoxExW 7E3D0750 5 Bytes JMP 4451157C D:\WINDOWS\system32\IEFRAME.dll
.text D:\Program Files\Internet Explorer\IEXPLORE.EXE[2320] USER32.dll!MessageBoxExA 7E3D0774 5 Bytes JMP 445115B6 D:\WINDOWS\system32\IEFRAME.dll
.text D:\Program Files\Internet Explorer\IEXPLORE.EXE[2320] USER32.dll!DialogBoxIndirectParamA 7E3D6CD0 5 Bytes JMP 445116AA D:\WINDOWS\system32\IEFRAME.dll
.text D:\Program Files\Internet Explorer\IEXPLORE.EXE[2320] USER32.dll!MessageBoxIndirectW 7E3E6425 5 Bytes JMP 443A1676 D:\WINDOWS\system32\IEFRAME.dll
.text D:\Program Files\MSN Messenger\msnmsgr.exe[3540] kernel32.dll!SetUnhandledExceptionFilter 7C84467D 5 Bytes JMP 004DE392 D:\Program Files\MSN Messenger\msnmsgr.exe

---- Kernel IAT/EAT - GMER 1.0.13 ----

IAT \SystemRoot\system32\DRIVERS\i8042prt.sys[HAL.dll!READ_PORT_UCHAR] [BA6D457E] sptd.sys
IAT \SystemRoot\system32\DRIVERS\ndiswan.sys[NDIS.SYS!NdisCloseAdapter] 8A758D70
IAT \SystemRoot\system32\DRIVERS\ndiswan.sys[NDIS.SYS!NdisOpenAdapter] 8A758960
IAT \SystemRoot\system32\DRIVERS\ndiswan.sys[NDIS.SYS!NdisDeregisterProtocol] 8A758F40
IAT \SystemRoot\system32\DRIVERS\ndiswan.sys[NDIS.SYS!NdisRegisterProtocol] 8A758770
IAT \SystemRoot\system32\DRIVERS\raspppoe.sys[NDIS.SYS!NdisRegisterProtocol] [A29589D0] \SystemRoot\System32\vsdatant.sys
IAT \SystemRoot\system32\DRIVERS\raspppoe.sys[NDIS.SYS!NdisOpenAdapter] [A2958EF0] \SystemRoot\System32\vsdatant.sys
IAT \SystemRoot\system32\DRIVERS\raspppoe.sys[NDIS.SYS!NdisCloseAdapter] [A2959050] \SystemRoot\System32\vsdatant.sys
IAT \SystemRoot\system32\DRIVERS\raspppoe.sys[NDIS.SYS!NdisDeregisterProtocol] [A2958B40] \SystemRoot\System32\vsdatant.sys
IAT \SystemRoot\system32\DRIVERS\psched.sys[NDIS.SYS!NdisDeregisterProtocol] [A2958B40] \SystemRoot\System32\vsdatant.sys
IAT \SystemRoot\system32\DRIVERS\psched.sys[NDIS.SYS!NdisRegisterProtocol] [A29589D0] \SystemRoot\System32\vsdatant.sys
IAT \SystemRoot\system32\DRIVERS\psched.sys[NDIS.SYS!NdisOpenAdapter] [A2958EF0] \SystemRoot\System32\vsdatant.sys
IAT \SystemRoot\system32\DRIVERS\psched.sys[NDIS.SYS!NdisCloseAdapter] [A2959050] \SystemRoot\System32\vsdatant.sys
IAT \SystemRoot\System32\Drivers\NDProxy.SYS[NDIS.SYS!NdisRegisterProtocol] [A29589D0] \SystemRoot\System32\vsdatant.sys
IAT \SystemRoot\System32\Drivers\NDProxy.SYS[NDIS.SYS!NdisCloseAdapter] [A2959050] \SystemRoot\System32\vsdatant.sys
IAT \SystemRoot\System32\Drivers\NDProxy.SYS[NDIS.SYS!NdisOpenAdapter] [A2958EF0] \SystemRoot\System32\vsdatant.sys
IAT \SystemRoot\System32\Drivers\NDProxy.SYS[NDIS.SYS!NdisDeregisterProtocol] [A2958B40] \SystemRoot\System32\vsdatant.sys
IAT \SystemRoot\system32\DRIVERS\tcpip.sys[NDIS.SYS!NdisCloseAdapter] [A2959050] \SystemRoot\System32\vsdatant.sys
IAT \SystemRoot\system32\DRIVERS\tcpip.sys[NDIS.SYS!NdisOpenAdapter] [A2958EF0] \SystemRoot\System32\vsdatant.sys
IAT \SystemRoot\system32\DRIVERS\tcpip.sys[NDIS.SYS!NdisRegisterProtocol] [A29589D0] \SystemRoot\System32\vsdatant.sys
IAT \SystemRoot\system32\DRIVERS\tcpip.sys[TDI.SYS!TdiRegisterDeviceObject] 8A67C660
IAT \SystemRoot\system32\DRIVERS\netbt.sys[TDI.SYS!TdiRegisterDeviceObject] 8A67C660
IAT \SystemRoot\system32\DRIVERS\wanarp.sys[NDIS.SYS!NdisDeregisterProtocol] [A2958B40] \SystemRoot\System32\vsdatant.sys
IAT \SystemRoot\system32\DRIVERS\wanarp.sys[NDIS.SYS!NdisRegisterProtocol] [A29589D0] \SystemRoot\System32\vsdatant.sys
IAT \SystemRoot\system32\DRIVERS\wanarp.sys[NDIS.SYS!NdisOpenAdapter] [A2958EF0] \SystemRoot\System32\vsdatant.sys
IAT \SystemRoot\system32\DRIVERS\wanarp.sys[NDIS.SYS!NdisCloseAdapter] [A2959050] \SystemRoot\System32\vsdatant.sys

---- User IAT/EAT - GMER 1.0.13 ----

IAT D:\WINDOWS\Explorer.EXE[2460] @ D:\WINDOWS\system32\ADVAPI32.dll [KERNEL32.dll!GetProcAddress] [5CEA7774] D:\WINDOWS\system32\ShimEng.dll
IAT D:\WINDOWS\Explorer.EXE[2460] @ D:\WINDOWS\system32\RPCRT4.dll [KERNEL32.dll!GetProcAddress] [5CEA7774] D:\WINDOWS\system32\ShimEng.dll
IAT D:\WINDOWS\Explorer.EXE[2460] @ D:\WINDOWS\system32\GDI32.dll [KERNEL32.dll!GetProcAddress] [5CEA7774] D:\WINDOWS\system32\ShimEng.dll
IAT D:\WINDOWS\Explorer.EXE[2460] @ D:\WINDOWS\system32\USER32.dll [KERNEL32.dll!GetProcAddress] [5CEA7774] D:\WINDOWS\system32\ShimEng.dll
IAT D:\WINDOWS\Explorer.EXE[2460] @ D:\WINDOWS\system32\ole32.dll [KERNEL32.dll!GetProcAddress] [5CEA7774] D:\WINDOWS\system32\ShimEng.dll
IAT D:\WINDOWS\Explorer.EXE[2460] @ D:\WINDOWS\system32\SHLWAPI.dll [KERNEL32.dll!GetProcAddress] [5CEA7774] D:\WINDOWS\system32\ShimEng.dll
IAT D:\WINDOWS\Explorer.EXE[2460] @ D:\WINDOWS\system32\CRYPT32.dll [KERNEL32.dll!GetProcAddress] [5CEA7774] D:\WINDOWS\system32\ShimEng.dll
IAT D:\WINDOWS\Explorer.EXE[2460] @ D:\WINDOWS\system32\NETAPI32.dll [KERNEL32.dll!GetProcAddress] [5CEA7774] D:\WINDOWS\system32\ShimEng.dll
IAT D:\WINDOWS\Explorer.EXE[2460] @ D:\WINDOWS\system32\WININET.dll [KERNEL32.dll!GetProcAddress] [5CEA7774] D:\WINDOWS\system32\ShimEng.dll
IAT D:\WINDOWS\Explorer.EXE[2460] @ D:\WINDOWS\system32\SHELL32.dll [KERNEL32.dll!GetProcAddress] [5CEA7774] D:\WINDOWS\system32\ShimEng.dll
IAT D:\WINDOWS\Explorer.EXE[2460] @ D:\WINDOWS\system32\USERENV.dll [KERNEL32.dll!GetProcAddress] [5CEA7774] D:\WINDOWS\system32\ShimEng.dll
IAT D:\WINDOWS\Explorer.EXE[2460] @ D:\WINDOWS\system32\Secur32.dll [KERNEL32.dll!GetProcAddress] [5CEA7774] D:\WINDOWS\system32\ShimEng.dll
IAT D:\WINDOWS\Explorer.EXE[2460] @ D:\WINDOWS\system32\PSAPI.DLL [KERNEL32.dll!GetProcAddress] [5CEA7774] D:\WINDOWS\system32\ShimEng.dll
IAT D:\WINDOWS\Explorer.EXE[2460] @ D:\WINDOWS\system32\WS2_32.dll [KERNEL32.dll!GetProcAddress] [5CEA7774] D:\WINDOWS\system32\ShimEng.dll
IAT D:\WINDOWS\Explorer.EXE[2460] @ D:\WINDOWS\system32\WS2HELP.dll [KERNEL32.dll!GetProcAddress] [5CEA7774] D:\WINDOWS\system32\ShimEng.dll
IAT D:\WINDOWS\Explorer.EXE[2460] @ D:\WINDOWS\system32\iphlpapi.dll [KERNEL32.dll!GetProcAddress] [5CEA7774] D:\WINDOWS\system32\ShimEng.dll

---- Devices - GMER 1.0.13 ----

Device \FileSystem\Ntfs \Ntfs IRP_MJ_CREATE 8A9541E8
Device \FileSystem\Ntfs \Ntfs IRP_MJ_CLOSE 8A9541E8
Device \FileSystem\Ntfs \Ntfs IRP_MJ_READ 8A9541E8
Device \FileSystem\Ntfs \Ntfs IRP_MJ_WRITE 8A9541E8
Device \FileSystem\Ntfs \Ntfs IRP_MJ_QUERY_INFORMATION 8A9541E8
Device \FileSystem\Ntfs \Ntfs IRP_MJ_SET_INFORMATION 8A9541E8
Device \FileSystem\Ntfs \Ntfs IRP_MJ_QUERY_EA 8A9541E8
Device \FileSystem\Ntfs \Ntfs IRP_MJ_SET_EA 8A9541E8
Device \FileSystem\Ntfs \Ntfs IRP_MJ_FLUSH_BUFFERS 8A9541E8
Device \FileSystem\Ntfs \Ntfs IRP_MJ_QUERY_VOLUME_INFORMATION 8A9541E8
Device \FileSystem\Ntfs \Ntfs IRP_MJ_SET_VOLUME_INFORMATION 8A9541E8
Device \FileSystem\Ntfs \Ntfs IRP_MJ_DIRECTORY_CONTROL 8A9541E8
Device \FileSystem\Ntfs \Ntfs IRP_MJ_FILE_SYSTEM_CONTROL 8A9541E8
Device \FileSystem\Ntfs \Ntfs IRP_MJ_DEVICE_CONTROL 8A9541E8
Device \FileSystem\Ntfs \Ntfs IRP_MJ_SHUTDOWN 8A9541E8
Device \FileSystem\Ntfs \Ntfs IRP_MJ_LOCK_CONTROL 8A9541E8
Device \FileSystem\Ntfs \Ntfs IRP_MJ_CLEANUP 8A9541E8
Device \FileSystem\Ntfs \Ntfs IRP_MJ_QUERY_SECURITY 8A9541E8
Device \FileSystem\Ntfs \Ntfs IRP_MJ_SET_SECURITY 8A9541E8
Device \FileSystem\Ntfs \Ntfs IRP_MJ_QUERY_QUOTA 8A9541E8
Device \FileSystem\Ntfs \Ntfs IRP_MJ_SET_QUOTA 8A9541E8
Device \FileSystem\Ntfs \Ntfs IRP_MJ_PNP 8A9541E8

AttachedDevice \FileSystem\Ntfs \Ntfs IRP_MJ_CREATE [BA5C81DE] fltMgr.sys
AttachedDevice \FileSystem\Ntfs \Ntfs IRP_MJ_CREATE_NAMED_PIPE [BA5C81DE] fltMgr.sys
AttachedDevice \FileSystem\Ntfs \Ntfs IRP_MJ_CLOSE [BA5BBF4C] fltMgr.sys
AttachedDevice \FileSystem\Ntfs \Ntfs IRP_MJ_READ [BA5BBF4C] fltMgr.sys
AttachedDevice \FileSystem\Ntfs \Ntfs IRP_MJ_WRITE [BA5BBF4C] fltMgr.sys
AttachedDevice \FileSystem\Ntfs \Ntfs IRP_MJ_QUERY_INFORMATION [BA5BBF4C] fltMgr.sys
AttachedDevice \FileSystem\Ntfs \Ntfs IRP_MJ_SET_INFORMATION [BA5BBF4C] fltMgr.sys
AttachedDevice \FileSystem\Ntfs \Ntfs IRP_MJ_QUERY_EA [BA5BBF4C] fltMgr.sys
AttachedDevice \FileSystem\Ntfs \Ntfs IRP_MJ_SET_EA [BA5BBF4C] fltMgr.sys
AttachedDevice \FileSystem\Ntfs \Ntfs IRP_MJ_FLUSH_BUFFERS [BA5BBF4C] fltMgr.sys
AttachedDevice \FileSystem\Ntfs \Ntfs IRP_MJ_QUERY_VOLUME_INFORMATION [BA5BBF4C] fltMgr.sys
AttachedDevice \FileSystem\Ntfs \Ntfs IRP_MJ_SET_VOLUME_INFORMATION [BA5BBF4C] fltMgr.sys
AttachedDevice \FileSystem\Ntfs \Ntfs IRP_MJ_DIRECTORY_CONTROL [BA5BBF4C] fltMgr.sys
AttachedDevice \FileSystem\Ntfs \Ntfs IRP_MJ_FILE_SYSTEM_CONTROL [BA5C8454] fltMgr.sys
AttachedDevice \FileSystem\Ntfs \Ntfs IRP_MJ_DEVICE_CONTROL [BA5BBF4C] fltMgr.sys
AttachedDevice \FileSystem\Ntfs \Ntfs IRP_MJ_INTERNAL_DEVICE_CONTROL [BA5BBF4C] fltMgr.sys
AttachedDevice \FileSystem\Ntfs \Ntfs IRP_MJ_SHUTDOWN [BA5BBF4C] fltMgr.sys
AttachedDevice \FileSystem\Ntfs \Ntfs IRP_MJ_LOCK_CONTROL [BA5BBF4C] fltMgr.sys
AttachedDevice \FileSystem\Ntfs \Ntfs IRP_MJ_CLEANUP [BA5BBF4C] fltMgr.sys
AttachedDevice \FileSystem\Ntfs \Ntfs IRP_MJ_CREATE_MAILSLOT [BA5C81DE] fltMgr.sys
AttachedDevice \FileSystem\Ntfs \Ntfs IRP_MJ_QUERY_SECURITY [BA5BBF4C] fltMgr.sys
AttachedDevice \FileSystem\Ntfs \Ntfs IRP_MJ_SET_SECURITY [BA5BBF4C] fltMgr.sys
AttachedDevice \FileSystem\Ntfs \Ntfs IRP_MJ_POWER [BA5BBF4C] fltMgr.sys
AttachedDevice \FileSystem\Ntfs \Ntfs IRP_MJ_SYSTEM_CONTROL [BA5BBF4C] fltMgr.sys
AttachedDevice \FileSystem\Ntfs \Ntfs IRP_MJ_DEVICE_CHANGE [BA5BBF4C] fltMgr.sys
AttachedDevice \FileSystem\Ntfs \Ntfs IRP_MJ_QUERY_QUOTA [BA5BBF4C] fltMgr.sys
AttachedDevice \FileSystem\Ntfs \Ntfs IRP_MJ_SET_QUOTA [BA5BBF4C] fltMgr.sys

Device \Driver\Tcpip \Device\Ip IRP_MJ_CREATE [A2965C50] vsdatant.sys
Device \Driver\Tcpip \Device\Ip IRP_MJ_CLOSE [A2965C50] vsdatant.sys
Device \Driver\Tcpip \Device\Ip IRP_MJ_DEVICE_CONTROL [A2965C50] vsdatant.sys
Device \Driver\Tcpip \Device\Ip IRP_MJ_INTERNAL_DEVICE_CONTROL [A2965C50] vsdatant.sys
Device \Driver\Tcpip \Device\Ip IRP_MJ_CLEANUP [A2965C50] vsdatant.sys

AttachedDevice \Driver\Tcpip \Device\Ip IRP_MJ_CREATE [BA4BB0F0] kl1.sys
AttachedDevice \Driver\Tcpip \Device\Ip IRP_MJ_CREATE_NAMED_PIPE [BA4BB0F0] kl1.sys
AttachedDevice \Driver\Tcpip \Device\Ip IRP_MJ_CLOSE [BA4BB0F0] kl1.sys
AttachedDevice \Driver\Tcpip \Device\Ip IRP_MJ_READ [BA4BB0F0] kl1.sys
AttachedDevice \Driver\Tcpip \Device\Ip IRP_MJ_WRITE [BA4BB0F0] kl1.sys
AttachedDevice \Driver\Tcpip \Device\Ip IRP_MJ_QUERY_INFORMATION [BA4BB0F0] kl1.sys
AttachedDevice \Driver\Tcpip \Device\Ip IRP_MJ_SET_INFORMATION [BA4BB0F0] kl1.sys
AttachedDevice \Driver\Tcpip \Device\Ip IRP_MJ_QUERY_EA [BA4BB0F0] kl1.sys
AttachedDevice \Driver\Tcpip \Device\Ip IRP_MJ_SET_EA [BA4BB0F0] kl1.sys
AttachedDevice \Driver\Tcpip \Device\Ip IRP_MJ_FLUSH_BUFFERS [BA4BB0F0] kl1.sys
AttachedDevice \Driver\Tcpip \Device\Ip IRP_MJ_QUERY_VOLUME_INFORMATION [BA4BB0F0] kl1.sys
AttachedDevice \Driver\Tcpip \Device\Ip IRP_MJ_SET_VOLUME_INFORMATION [BA4BB0F0] kl1.sys
AttachedDevice \Driver\Tcpip \Device\Ip IRP_MJ_DIRECTORY_CONTROL [BA4BB0F0] kl1.sys
AttachedDevice \Driver\Tcpip \Device\Ip IRP_MJ_FILE_SYSTEM_CONTROL [BA4BB0F0] kl1.sys
AttachedDevice \Driver\Tcpip \Device\Ip IRP_MJ_DEVICE_CONTROL [BA4BB0F0] kl1.sys
AttachedDevice \Driver\Tcpip \Device\Ip IRP_MJ_INTERNAL_DEVICE_CONTROL [BA4BB0F0] kl1.sys
AttachedDevice \Driver\Tcpip \Device\Ip IRP_MJ_SHUTDOWN [BA4BB0F0] kl1.sys
AttachedDevice \Driver\Tcpip \Device\Ip IRP_MJ_LOCK_CONTROL [BA4BB0F0] kl1.sys
AttachedDevice \Driver\Tcpip \Device\Ip IRP_MJ_CLEANUP [BA4BB0F0] kl1.sys
AttachedDevice \Driver\Tcpip \Device\Ip IRP_MJ_CREATE_MAILSLOT [BA4BB0F0] kl1.sys
AttachedDevice \Driver\Tcpip \Device\Ip IRP_MJ_QUERY_SECURITY [BA4BB0F0] kl1.sys
AttachedDevice \Driver\Tcpip \Device\Ip IRP_MJ_SET_SECURITY [BA4BB0F0] kl1.sys
AttachedDevice \Driver\Tcpip \Device\Ip IRP_MJ_POWER [BA4BB0F0] kl1.sys
AttachedDevice \Driver\Tcpip \Device\Ip IRP_MJ_SYSTEM_CONTROL [BA4BB0F0] kl1.sys
AttachedDevice \Driver\Tcpip \Device\Ip IRP_MJ_DEVICE_CHANGE [BA4BB0F0] kl1.sys
AttachedDevice \Driver\Tcpip \Device\Ip IRP_MJ_QUERY_QUOTA [BA4BB0F0] kl1.sys
AttachedDevice \Driver\Tcpip \Device\Ip IRP_MJ_SET_QUOTA [BA4BB0F0] kl1.sys

Device \Driver\usbohci \Device\USBPDO-0 IRP_MJ_CREATE 8A5B4768
Device \Driver\usbohci \Device\USBPDO-0 IRP_MJ_CLOSE 8A5B4768
Device \Driver\usbohci \Device\USBPDO-0 IRP_MJ_DEVICE_CONTROL 8A5B4768
Device \Driver\usbohci \Device\USBPDO-0 IRP_MJ_INTERNAL_DEVICE_CONTROL 8A5B4768
Device \Driver\usbohci \Device\USBPDO-0 IRP_MJ_POWER 8A5B4768
Device \Driver\usbohci \Device\USBPDO-0 IRP_MJ_SYSTEM_CONTROL 8A5B4768
Device \Driver\usbohci \Device\USBPDO-0 IRP_MJ_PNP 8A5B4768
Device \Driver\dmio \Device\DmControl\DmIoDaemon IRP_MJ_CREATE 8A9561E8
Device \Driver\dmio \Device\DmControl\DmIoDaemon IRP_MJ_CLOSE 8A9561E8
Device \Driver\dmio \Device\DmControl\DmIoDaemon IRP_MJ_READ 8A9561E8
Device \Driver\dmio \Device\DmControl\DmIoDaemon IRP_MJ_WRITE 8A9561E8
Device \Driver\dmio \Device\DmControl\DmIoDaemon IRP_MJ_FLUSH_BUFFERS 8A9561E8
Device \Driver\dmio \Device\DmControl\DmIoDaemon IRP_MJ_DEVICE_CONTROL 8A9561E8
Device \Driver\dmio \Device\DmControl\DmIoDaemon IRP_MJ_INTERNAL_DEVICE_CONTROL 8A9561E8
Device \Driver\dmio \Device\DmControl\DmIoDaemon IRP_MJ_SHUTDOWN 8A9561E8
Device \Driver\dmio \Device\DmControl\DmIoDaemon IRP_MJ_POWER 8A9561E8
Device \Driver\dmio \Device\DmControl\DmIoDaemon IRP_MJ_SYSTEM_CONTROL 8A9561E8
Device \Driver\dmio \Device\DmControl\DmIoDaemon IRP_MJ_PNP 8A9561E8
Device \Driver\dmio \Device\DmControl\DmConfig IRP_MJ_CREATE 8A9561E8
Device \Driver\dmio \Device\DmControl\DmConfig IRP_MJ_CLOSE 8A9561E8
Device \Driver\dmio \Device\DmControl\DmConfig IRP_MJ_READ 8A9561E8
Device \Driver\dmio \Device\DmControl\DmConfig IRP_MJ_WRITE 8A9561E8
Device \Driver\dmio \Device\DmControl\DmConfig IRP_MJ_FLUSH_BUFFERS 8A9561E8
Device \Driver\dmio \Device\DmControl\DmConfig IRP_MJ_DEVICE_CONTROL 8A9561E8
Device \Driver\dmio \Device\DmControl\DmConfig IRP_MJ_INTERNAL_DEVICE_CONTROL 8A9561E8
Device \Driver\dmio \Device\DmControl\DmConfig IRP_MJ_SHUTDOWN 8A9561E8
Device \Driver\dmio \Device\DmControl\DmConfig IRP_MJ_POWER 8A9561E8
Device \Driver\dmio \Device\DmControl\DmConfig IRP_MJ_SYSTEM_CONTROL 8A9561E8
Device \Driver\dmio \Device\DmControl\DmConfig IRP_MJ_PNP 8A9561E8
Device \Driver\dmio \Device\DmControl\DmPnP IRP_MJ_CREATE 8A9561E8
Device \Driver\dmio \Device\DmControl\DmPnP IRP_MJ_CLOSE 8A9561E8
Device \Driver\dmio \Device\DmControl\DmPnP IRP_MJ_READ 8A9561E8
Device \Driver\dmio \Device\DmControl\DmPnP IRP_MJ_WRITE 8A9561E8
Device \Driver\dmio \Device\DmControl\DmPnP IRP_MJ_FLUSH_BUFFERS 8A9561E8
Device \Driver\dmio \Device\DmControl\DmPnP IRP_MJ_DEVICE_CONTROL 8A9561E8
Device \Driver\dmio \Device\DmControl\DmPnP IRP_MJ_INTERNAL_DEVICE_CONTROL 8A9561E8
Device \Driver\dmio \Device\DmControl\DmPnP IRP_MJ_SHUTDOWN 8A9561E8
Device \Driver\dmio \Device\DmControl\DmPnP IRP_MJ_POWER 8A9561E8
Device \Driver\dmio \Device\DmControl\DmPnP IRP_MJ_SYSTEM_CONTROL 8A9561E8
Device \Driver\dmio \Device\DmControl\DmPnP IRP_MJ_PNP 8A9561E8
Device \Driver\dmio \Device\DmControl\DmInfo IRP_MJ_CREATE 8A9561E8
Device \Driver\dmio \Device\DmControl\DmInfo IRP_MJ_CLOSE 8A9561E8
Device \Driver\dmio \Device\DmControl\DmInfo IRP_MJ_READ 8A9561E8
Device \Driver\dmio \Device\DmControl\DmInfo IRP_MJ_WRITE 8A9561E8
Device \Driver\dmio \Device\DmControl\DmInfo IRP_MJ_FLUSH_BUFFERS 8A9561E8
Device \Driver\dmio \Device\DmControl\DmInfo IRP_MJ_DEVICE_CONTROL 8A9561E8
Device \Driver\dmio \Device\DmControl\DmInfo IRP_MJ_INTERNAL_DEVICE_CONTROL 8A9561E8
Device \Driver\dmio \Device\DmControl\DmInfo IRP_MJ_SHUTDOWN 8A9561E8
Device \Driver\dmio \Device\DmControl\DmInfo IRP_MJ_POWER 8A9561E8
Device \Driver\dmio \Device\DmControl\DmInfo IRP_MJ_SYSTEM_CONTROL 8A9561E8
Device \Driver\dmio \Device\DmControl\DmInfo IRP_MJ_PNP 8A9561E8
Device \Driver\usbehci \Device\USBPDO-1 IRP_MJ_CREATE 8A66E1E8
Device \Driver\usbehci \Device\USBPDO-1 IRP_MJ_CLOSE 8A66E1E8
Device \Driver\usbehci \Device\USBPDO-1 IRP_MJ_DEVICE_CONTROL 8A66E1E8
Device \Driver\usbehci \Device\USBPDO-1 IRP_MJ_INTERNAL_DEVICE_CONTROL 8A66E1E8
Device \Driver\usbehci \Device\USBPDO-1 IRP_MJ_POWER 8A66E1E8
Device \Driver\usbehci \Device\USBPDO-1 IRP_MJ_SYSTEM_CONTROL 8A66E1E8
Device \Driver\usbehci \Device\USBPDO-1 IRP_MJ_PNP 8A66E1E8
Device \Driver\Tcpip \Device\Tcp IRP_MJ_CREATE [A2965C50] vsdatant.sys
Device \Driver\Tcpip \Device\Tcp IRP_MJ_CLOSE [A2965C50] vsdatant.sys
Device \Driver\Tcpip \Device\Tcp IRP_MJ_DEVICE_CONTROL [A2965C50] vsdatant.sys
Device \Driver\Tcpip \Device\Tcp IRP_MJ_INTERNAL_DEVICE_CONTROL [A2965C50] vsdatant.sys
Device \Driver\Tcpip \Device\Tcp IRP_MJ_CLEANUP [A2965C50] vsdatant.sys

AttachedDevice \Driver\Tcpip \Device\Tcp IRP_MJ_CREATE [BA4BB0F0] kl1.sys
AttachedDevice \Driver\Tcpip \Device\Tcp IRP_MJ_CREATE_NAMED_PIPE [BA4BB0F0] kl1.sys
AttachedDevice \Driver\Tcpip \Device\Tcp IRP_MJ_CLOSE [BA4BB0F0] kl1.sys
AttachedDevice \Driver\Tcpip \Device\Tcp IRP_MJ_READ [BA4BB0F0] kl1.sys
AttachedDevice \Driver\Tcpip \Device\Tcp IRP_MJ_WRITE [BA4BB0F0] kl1.sys
AttachedDevice \Driver\Tcpip \Device\Tcp IRP_MJ_QUERY_INFORMATION [BA4BB0F0] kl1.sys
AttachedDevice \Driver\Tcpip \Device\Tcp IRP_MJ_SET_INFORMATION [BA4BB0F0] kl1.sys
AttachedDevice \Driver\Tcpip \Device\Tcp IRP_MJ_QUERY_EA [BA4BB0F0] kl1.sys
AttachedDevice \Driver\Tcpip \Device\Tcp IRP_MJ_SET_EA [BA4BB0F0] kl1.sys
AttachedDevice \Driver\Tcpip \Device\Tcp IRP_MJ_FLUSH_BUFFERS [BA4BB0F0] kl1.sys
AttachedDevice \Driver\Tcpip \Device\Tcp IRP_MJ_QUERY_VOLUME_INFORMATION [BA4BB0F0] kl1.sys
AttachedDevice \Driver\Tcpip \Device\Tcp IRP_MJ_SET_VOLUME_INFORMATION [BA4BB0F0] kl1.sys
AttachedDevice \Driver\Tcpip \Device\Tcp IRP_MJ_DIRECTORY_CONTROL [BA4BB0F0] kl1.sys
AttachedDevice \Driver\Tcpip \Device\Tcp IRP_MJ_FILE_SYSTEM_CONTROL [BA4BB0F0] kl1.sys
AttachedDevice \Driver\Tcpip \Device\Tcp IRP_MJ_DEVICE_CONTROL [BA4BB0F0] kl1.sys
AttachedDevice \Driver\Tcpip \Device\Tcp IRP_MJ_INTERNAL_DEVICE_CONTROL [BA4BB0F0] kl1.sys
AttachedDevice \Driver\Tcpip \Device\Tcp IRP_MJ_SHUTDOWN [BA4BB0F0] kl1.sys
AttachedDevice \Driver\Tcpip \Device\Tcp IRP_MJ_LOCK_CONTROL [BA4BB0F0] kl1.sys
AttachedDevice \Driver\Tcpip \Device\Tcp IRP_MJ_CLEANUP [BA4BB0F0] kl1.sys
AttachedDevice \Driver\Tcpip \Device\Tcp IRP_MJ_CREATE_MAILSLOT [BA4BB0F0] kl1.sys
AttachedDevice \Driver\Tcpip \Device\Tcp IRP_MJ_QUERY_SECURITY [BA4BB0F0] kl1.sys
AttachedDevice \Driver\Tcpip \Device\Tcp IRP_MJ_SET_SECURITY [BA4BB0F0] kl1.sys
AttachedDevice \Driver\Tcpip \Device\Tcp IRP_MJ_POWER [BA4BB0F0] kl1.sys
AttachedDevice \Driver\Tcpip \Device\Tcp IRP_MJ_SYSTEM_CONTROL [BA4BB0F0] kl1.sys
AttachedDevice \Driver\Tcpip \Device\Tcp IRP_MJ_DEVICE_CHANGE [BA4BB0F0] kl1.sys
AttachedDevice \Driver\Tcpip \Device\Tcp IRP_MJ_QUERY_QUOTA [BA4BB0F0] kl1.sys
AttachedDevice \Driver\Tcpip \Device\Tcp IRP_MJ_SET_QUOTA [BA4BB0F0] kl1.sys

Device \Driver\Ftdisk \Device\HarddiskVolume1 IRP_MJ_CREATE 8A9C51E8
Device \Driver\Ftdisk \Device\HarddiskVolume1 IRP_MJ_READ 8A9C51E8
Device \Driver\Ftdisk \Device\HarddiskVolume1 IRP_MJ_WRITE 8A9C51E8
Device \Driver\Ftdisk \Device\HarddiskVolume1 IRP_MJ_FLUSH_BUFFERS 8A9C51E8
Device \Driver\Ftdisk \Device\HarddiskVolume1 IRP_MJ_DEVICE_CONTROL 8A9C51E8
Device \Driver\Ftdisk \Device\HarddiskVolume1 IRP_MJ_INTERNAL_DEVICE_CONTROL 8A9C51E8
Device \Driver\Ftdisk \Device\HarddiskVolume1 IRP_MJ_SHUTDOWN 8A9C51E8
Device \Driver\Ftdisk \Device\HarddiskVolume1 IRP_MJ_CLEANUP 8A9C51E8
Device \Driver\Ftdisk \Device\HarddiskVolume1 IRP_MJ_POWER 8A9C51E8
Device \Driver\Ftdisk \Device\HarddiskVolume1 IRP_MJ_SYSTEM_CONTROL 8A9C51E8
Device \Driver\Ftdisk \Device\HarddiskVolume1 IRP_MJ_PNP 8A9C51E8
Device \Driver\Cdrom \Device\CdRom0 IRP_MJ_CREATE 8A5A41E8
Device \Driver\Cdrom \Device\CdRom0 IRP_MJ_CLOSE 8A5A41E8
Device \Driver\Cdrom \Device\CdRom0 IRP_MJ_READ 8A5A41E8
Device \Driver\Cdrom \Device\CdRom0 IRP_MJ_WRITE 8A5A41E8
Device \Driver\Cdrom \Device\CdRom0 IRP_MJ_FLUSH_BUFFERS 8A5A41E8
Device \Driver\Cdrom \Device\CdRom0 IRP_MJ_DEVICE_CONTROL 8A5A41E8
Device \Driver\Cdrom \Device\CdRom0 IRP_MJ_INTERNAL_DEVICE_CONTROL 8A5A41E8
Device \Driver\Cdrom \Device\CdRom0 IRP_MJ_SHUTDOWN 8A5A41E8
Device \Driver\Cdrom \Device\CdRom0 IRP_MJ_POWER 8A5A41E8
Device \Driver\Cdrom \Device\CdRom0 IRP_MJ_SYSTEM_CONTROL 8A5A41E8
Device \Driver\Cdrom \Device\CdRom0 IRP_MJ_PNP 8A5A41E8
Device \Driver\Ftdisk \Device\HarddiskVolume2 IRP_MJ_CREATE 8A9C51E8
Device \Driver\Ftdisk \Device\HarddiskVolume2 IRP_MJ_READ 8A9C51E8
Device \Driver\Ftdisk \Device\HarddiskVolume2 IRP_MJ_WRITE 8A9C51E8
Device \Driver\Ftdisk \Device\HarddiskVolume2 IRP_MJ_FLUSH_BUFFERS 8A9C51E8
Device \Driver\Ftdisk \Device\HarddiskVolume2 IRP_MJ_DEVICE_CONTROL 8A9C51E8
Device \Driver\Ftdisk \Device\HarddiskVolume2 IRP_MJ_INTERNAL_DEVICE_CONTROL 8A9C51E8
Device \Driver\Ftdisk \Device\HarddiskVolume2 IRP_MJ_SHUTDOWN 8A9C51E8
Device \Driver\Ftdisk \Device\HarddiskVolume2 IRP_MJ_CLEANUP 8A9C51E8
Device \Driver\Ftdisk \Device\HarddiskVolume2 IRP_MJ_POWER 8A9C51E8
Device \Driver\Ftdisk \Device\HarddiskVolume2 IRP_MJ_SYSTEM_CONTROL 8A9C51E8
Device \Driver\Ftdisk \Device\HarddiskVolume2 IRP_MJ_PNP 8A9C51E8
Device \Driver\Ftdisk \Device\HarddiskVolume3 IRP_MJ_CREATE 8A9C51E8
Device \Driver\Ftdisk \Device\HarddiskVolume3 IRP_MJ_READ 8A9C51E8
Device \Driver\Ftdisk \Device\HarddiskVolume3 IRP_MJ_WRITE 8A9C51E8
Device \Driver\Ftdisk \Device\HarddiskVolume3 IRP_MJ_FLUSH_BUFFERS 8A9C51E8
Device \Driver\Ftdisk \Device\HarddiskVolume3 IRP_MJ_DEVICE_CONTROL 8A9C51E8
Device \Driver\Ftdisk \Device\HarddiskVolume3 IRP_MJ_INTERNAL_DEVICE_CONTROL 8A9C51E8
Device \Driver\Ftdisk \Device\HarddiskVolume3 IRP_MJ_SHUTDOWN 8A9C51E8
Device \Driver\Ftdisk \Device\HarddiskVolume3 IRP_MJ_CLEANUP 8A9C51E8
Device \Driver\Ftdisk \Device\HarddiskVolume3 IRP_MJ_POWER 8A9C51E8
Device \Driver\Ftdisk \Device\HarddiskVolume3 IRP_MJ_SYSTEM_CONTROL 8A9C51E8
Device \Driver\Ftdisk \Device\HarddiskVolume3 IRP_MJ_PNP 8A9C51E8
Device \Driver\NetBT \Device\NetBT_Tcpip_{C5DCA191-7FAE-4E19-A575-9D2F2854F11E} IRP_MJ_CREATE 88F9D1E8
Device \Driver\NetBT \Device\NetBT_Tcpip_{C5DCA191-7FAE-4E19-A575-9D2F2854F11E} IRP_MJ_CLOSE 88F9D1E8
Device \Driver\NetBT \Device\NetBT_Tcpip_{C5DCA191-7FAE-4E19-A575-9D2F2854F11E} IRP_MJ_DEVICE_CONTROL 88F9D1E8
Device \Driver\NetBT \Device\NetBT_Tcpip_{C5DCA191-7FAE-4E19-A575-9D2F2854F11E} IRP_MJ_INTERNAL_DEVICE_CONTROL 88F9D1E8
Device \Driver\NetBT \Device\NetBT_Tcpip_{C5DCA191-7FAE-4E19-A575-9D2F2854F11E} IRP_MJ_CLEANUP 88F9D1E8
Device \Driver\NetBT \Device\NetBT_Tcpip_{C5DCA191-7FAE-4E19-A575-9D2F2854F11E} IRP_MJ_PNP 88F9D1E8
Device \Driver\Cdrom \Device\CdRom1 IRP_MJ_CREATE 8A5A41E8
Device \Driver\Cdrom \Device\CdRom1 IRP_MJ_CLOSE 8A5A41E8
Device \Driver\Cdrom \Device\CdRom1 IRP_MJ_READ 8A5A41E8
Device \Driver\Cdrom \Device\CdRom1 IRP_MJ_WRITE 8A5A41E8
Device \Driver\Cdrom \Device\CdRom1 IRP_MJ_FLUSH_BUFFERS 8A5A41E8
Device \Driver\Cdrom \Device\CdRom1 IRP_MJ_DEVICE_CONTROL 8A5A41E8
Device \Driver\Cdrom \Device\CdRom1 IRP_MJ_INTERNAL_DEVICE_CONTROL 8A5A41E8
Device \Driver\Cdrom \Device\CdRom1 IRP_MJ_SHUTDOWN 8A5A41E8
Device \Driver\Cdrom \Device\CdRom1 IRP_MJ_POWER 8A5A41E8
Device \Driver\Cdrom \Device\CdRom1 IRP_MJ_SYSTEM_CONTROL 8A5A41E8
Device \Driver\Cdrom \Device\CdRom1 IRP_MJ_PNP 8A5A41E8
Device \Driver\PCI_NTPNP7538 \Device\00000066 IRP_MJ_CREATE [BA6F4B0E] sptd.sys
Device \Driver\PCI_NTPNP7538 \Device\00000066 IRP_MJ_CREATE_NAMED_PIPE [BA6F4B0E] sptd.sys
Device \Driver\PCI_NTPNP7538 \Device\00000066 IRP_MJ_CLOSE [BA6F4B0E] sptd.sys
Device \Driver\PCI_NTPNP7538 \Device\00000066 IRP_MJ_READ [BA6F4B0E] sptd.sys
Device \Driver\PCI_NTPNP7538 \Device\00000066 IRP_MJ_WRITE [BA6F4B0E] sptd.sys
Device \Driver\PCI_NTPNP7538 \Device\00000066 IRP_MJ_QUERY_INFORMATION [BA6F4B0E] sptd.sys
Device \Driver\PCI_NTPNP7538 \Device\00000066 IRP_MJ_SET_INFORMATION [BA6F4B0E] sptd.sys
Device \Driver\PCI_NTPNP7538 \Device\00000066 IRP_MJ_QUERY_EA [BA6F4B0E] sptd.sys
Device \Driver\PCI_NTPNP7538 \Device\00000066 IRP_MJ_SET_EA [BA6F4B0E] sptd.sys
Device \Driver\PCI_NTPNP7538 \Device\00000066 IRP_MJ_FLUSH_BUFFERS [BA6F4B0E] sptd.sys
Device \Driver\PCI_NTPNP7538 \Device\00000066 IRP_MJ_QUERY_VOLUME_INFORMATION [BA6F4B0E] sptd.sys
Device \Driver\PCI_NTPNP7538 \Device\00000066 IRP_MJ_SET_VOLUME_INFORMATION [BA6F4B0E] sptd.sys
Device \Driver\PCI_NTPNP7538 \Device\00000066 IRP_MJ_DIRECTORY_CONTROL [BA6F4B0E] sptd.sys
Device \Driver\PCI_NTPNP7538 \Device\00000066 IRP_MJ_FILE_SYSTEM_CONTROL [BA6F4B0E] sptd.sys
Device \Driver\PCI_NTPNP7538 \Device\00000066 IRP_MJ_DEVICE_CONTROL [BA6F4B0E] sptd.sys
Device \Driver\PCI_NTPNP7538 \Device\00000066 IRP_MJ_INTERNAL_DEVICE_CONTROL [BA6F4B0E] sptd.sys
Device \Driver\PCI_NTPNP7538 \Device\00000066 IRP_MJ_SHUTDOWN [BA6F4B0E] sptd.sys
Device \Driver\PCI_NTPNP7538 \Device\00000066 IRP_MJ_LOCK_CONTROL [BA6F4B0E] sptd.sys
Device \Driver\PCI_NTPNP7538 \Device\00000066 IRP_MJ_CLEANUP [BA6F4B0E] sptd.sys
Device \Driver\PCI_NTPNP7538 \Device\00000066 IRP_MJ_CREATE_MAILSLOT [BA6F4B0E] sptd.sys
Device \Driver\PCI_NTPNP7538 \Device\00000066 IRP_MJ_QUERY_SECURITY [BA6F4B0E] sptd.sys
Device \Driver\PCI_NTPNP7538 \Device\00000066 IRP_MJ_SET_SECURITY [BA6F4B0E] sptd.sys
Device \Driver\PCI_NTPNP7538 \Device\00000066 IRP_MJ_POWER [BA6CDE7A] sptd.sys
Device \Driver\PCI_NTPNP7538 \Device\00000066 IRP_MJ_SYSTEM_CONTROL [BA6F12C8] sptd.sys
Device \Driver\PCI_NTPNP7538 \Device\00000066 IRP_MJ_DEVICE_CHANGE [BA6F4B0E] sptd.sys
Device \Driver\PCI_NTPNP7538 \Device\00000066 IRP_MJ_QUERY_QUOTA [BA6F4B0E] sptd.sys
Device \Driver\PCI_NTPNP7538 \Device\00000066 IRP_MJ_SET_QUOTA [BA6F4B0E] sptd.sys
Device \Driver\PCI_NTPNP7538 \Device\00000066 IRP_MJ_PNP [BA6F2238] sptd.sys
Device \Driver\Cdrom \Device\CdRom2 IRP_MJ_CREATE 8A5A41E8
Device \Driver\Cdrom \Device\CdRom2 IRP_MJ_CLOSE 8A5A41E8
Device \Driver\Cdrom \Device\CdRom2 IRP_MJ_READ 8A5A41E8
Device \Driver\Cdrom \Device\CdRom2 IRP_MJ_WRITE 8A5A41E8
Device \Driver\Cdrom \Device\CdRom2 IRP_MJ_FLUSH_BUFFERS 8A5A41E8
Device \Driver\Cdrom \Device\CdRom2 IRP_MJ_DEVICE_CONTROL 8A5A41E8
Device \Driver\Cdrom \Device\CdRom2 IRP_MJ_INTERNAL_DEVICE_CONTROL 8A5A41E8
Device \Driver\Cdrom \Device\CdRom2 IRP_MJ_SHUTDOWN 8A5A41E8
Device \Driver\Cdrom \Device\CdRom2 IRP_MJ_POWER 8A5A41E8
Device \Driver\Cdrom \Device\CdRom2 IRP_MJ_SYSTEM_CONTROL 8A5A41E8
Device \Driver\Cdrom \Device\CdRom2 IRP_MJ_PNP 8A5A41E8
Device \Driver\PCI_NTPNP7538 \Device\00000067 IRP_MJ_CREATE [BA6F4B0E] sptd.sys
Device \Driver\PCI_NTPNP7538 \Device\00000067 IRP_MJ_CREATE_NAMED_PIPE [BA6F4B0E] sptd.sys
Device \Driver\PCI_NTPNP7538 \Device\00000067 IRP_MJ_CLOSE [BA6F4B0E] sptd.sys
Device \Driver\PCI_NTPNP7538 \Device\00000067 IRP_MJ_READ [BA6F4B0E] sptd.sys
Device \Driver\PCI_NTPNP7538 \Device\00000067 IRP_MJ_WRITE [BA6F4B0E] sptd.sys
Device \Driver\PCI_NTPNP7538 \Device\00000067 IRP_MJ_QUERY_INFORMATION [BA6F4B0E] sptd.sys
Device \Driver\PCI_NTPNP7538 \Device\00000067 IRP_MJ_SET_INFORMATION [BA6F4B0E] sptd.sys
Device \Driver\PCI_NTPNP7538 \Device\00000067 IRP_MJ_QUERY_EA [BA6F4B0E] sptd.sys
Device \Driver\PCI_NTPNP7538 \Device\00000067 IRP_MJ_SET_EA [BA6F4B0E] sptd.sys
Device \Driver\PCI_NTPNP7538 \Device\00000067 IRP_MJ_FLUSH_BUFFERS [BA6F4B0E] sptd.sys
Device \Driver\PCI_NTPNP7538 \Device\00000067 IRP_MJ_QUERY_VOLUME_INFORMATION [BA6F4B0E] sptd.sys
Device \Driver\PCI_NTPNP7538 \Device\00000067 IRP_MJ_SET_VOLUME_INFORMATION [BA6F4B0E] sptd.sys
Device \Driver\PCI_NTPNP7538 \Device\00000067 IRP_MJ_DIRECTORY_CONTROL [BA6F4B0E] sptd.sys
Device \Driver\PCI_NTPNP7538 \Device\00000067 IRP_MJ_FILE_SYSTEM_CONTROL [BA6F4B0E] sptd.sys
Device \Driver\PCI_NTPNP7538 \Device\00000067 IRP_MJ_DEVICE_CONTROL [BA6F4B0E] sptd.sys
Device \Driver\PCI_NTPNP7538 \Device\00000067 IRP_MJ_INTERNAL_DEVICE_CONTROL [BA6F4B0E] sptd.sys
Device \Driver\PCI_NTPNP7538 \Device\00000067 IRP_MJ_SHUTDOWN [BA6F4B0E] sptd.sys
Device \Driver\PCI_NTPNP7538 \Device\00000067 IRP_MJ_LOCK_CONTROL [BA6F4B0E] sptd.sys
Device \Driver\PCI_NTPNP7538 \Device\00000067 IRP_MJ_CLEANUP [BA6F4B0E] sptd.sys
Device \Driver\PCI_NTPNP7538 \Device\00000067 IRP_MJ_CREATE_MAILSLOT [BA6F4B0E] sptd.sys
Device \Driver\PCI_NTPNP7538 \Device\00000067 IRP_MJ_QUERY_SECURITY [BA6F4B0E] sptd.sys
Device \Driver\PCI_NTPNP7538 \Device\00000067 IRP_MJ_SET_SECURITY [BA6F4B0E] sptd.sys
Device \Driver\PCI_NTPNP7538 \Device\00000067 IRP_MJ_POWER [BA6CDE7A] sptd.sys
Device \Driver\PCI_NTPNP7538 \Device\00000067 IRP_MJ_SYSTEM_CONTROL [BA6F12C8] sptd.sys
Device \Driver\PCI_NTPNP7538 \Device\00000067 IRP_MJ_DEVICE_CHANGE [BA6F4B0E] sptd.sys
Device \Driver\PCI_NTPNP7538 \Device\00000067 IRP_MJ_QUERY_QUOTA [BA6F4B0E] sptd.sys
Device \Driver\PCI_NTPNP7538 \Device\00000067 IRP_MJ_SET_QUOTA [BA6F4B0E] sptd.sys
Device \Driver\PCI_NTPNP7538 \Device\00000067 IRP_MJ_PNP [BA6F2238] sptd.sys
Device \Driver\NetBT \Device\NetBt_Wins_Export IRP_MJ_CREATE 88F9D1E8
Device \Driver\NetBT \Device\NetBt_Wins_Export IRP_MJ_CLOSE 88F9D1E8
Device \Driver\NetBT \Device\NetBt_Wins_Export IRP_MJ_DEVICE_CONTROL 88F9D1E8
Device \Driver\NetBT \Device\NetBt_Wins_Export IRP_MJ_INTERNAL_DEVICE_CONTROL 88F9D1E8
Device \Driver\NetBT \Device\NetBt_Wins_Export IRP_MJ_CLEANUP 88F9D1E8
Device \Driver\NetBT \Device\NetBt_Wins_Export IRP_MJ_PNP 88F9D1E8
Device \Driver\NetBT \Device\NetBT_Tcpip_{FAE28FA1-09BC-421F-AA01-7212C5E167D5} IRP_MJ_CREATE 88F9D1E8
Device \Driver\NetBT \Device\NetBT_Tcpip_{FAE28FA1-09BC-421F-AA01-7212C5E167D5} IRP_MJ_CLOSE 88F9D1E8
Device \Driver\NetBT \Device\NetBT_Tcpip_{FAE28FA1-09BC-421F-AA01-7212C5E167D5} IRP_MJ_DEVICE_CONTROL 88F9D1E8
Device \Driver\NetBT \Device\NetBT_Tcpip_{FAE28FA1-09BC-421F-AA01-7212C5E167D5} IRP_MJ_INTERNAL_DEVICE_CONTROL 88F9D1E8
Device \Driver\NetBT \Device\NetBT_Tcpip_{FAE28FA1-09BC-421F-AA01-7212C5E167D5} IRP_MJ_CLEANUP 88F9D1E8
Device \Driver\NetBT \Device\NetBT_Tcpip_{FAE28FA1-09BC-421F-AA01-7212C5E167D5} IRP_MJ_PNP 88F9D1E8
Device \Driver\NetBT \Device\NetbiosSmb IRP_MJ_CREATE 88F9D1E8
Device \Driver\NetBT \Device\NetbiosSmb IRP_MJ_CLOSE 88F9D1E8
Device \Driver\NetBT \Device\NetbiosSmb IRP_MJ_DEVICE_CONTROL 88F9D1E8
Device \Driver\NetBT \Device\NetbiosSmb IRP_MJ_INTERNAL_DEVICE_CONTROL 88F9D1E8
Device \Driver\NetBT \Device\NetbiosSmb IRP_MJ_CLEANUP 88F9D1E8
Device \Driver\NetBT \Device\NetbiosSmb IRP_MJ_PNP 88F9D1E8
Device \Driver\Tcpip \Device\Udp IRP_MJ_CREATE [A2965C50] vsdatant.sys
Device \Driver\Tcpip \Device\Udp IRP_MJ_CLOSE [A2965C50] vsdatant.sys
Device \Driver\Tcpip \Device\Udp IRP_MJ_DEVICE_CONTROL [A2965C50] vsdatant.sys
Device \Driver\Tcpip \Device\Udp IRP_MJ_INTERNAL_DEVICE_CONTROL [A2965C50] vsdatant.sys
Device \Driver\Tcpip \Device\Udp IRP_MJ_CLEANUP [A2965C50] vsdatant.sys

AttachedDevice \Driver\Tcpip \Device\Udp IRP_MJ_CREATE [BA4BB0F0] kl1.sys
AttachedDevice \Driver\Tcpip \Device\Udp IRP_MJ_CREATE_NAMED_PIPE [BA4BB0F0] kl1.sys
AttachedDevice \Driver\Tcpip \Device\Udp IRP_MJ_CLOSE [BA4BB0F0] kl1.sys
AttachedDevice \Driver\Tcpip \Device\Udp IRP_MJ_READ [BA4BB0F0] kl1.sys
AttachedDevice \Driver\Tcpip \Device\Udp IRP_MJ_WRITE [BA4BB0F0] kl1.sys
AttachedDevice \Driver\Tcpip \Device\Udp IRP_MJ_QUERY_INFORMATION [BA4BB0F0] kl1.sys
AttachedDevice \Driver\Tcpip \Device\Udp IRP_MJ_SET_INFORMATION [BA4BB0F0] kl1.sys
AttachedDevice \Driver\Tcpip \Device\Udp IRP_MJ_QUERY_EA [BA4BB0F0] kl1.sys
AttachedDevice \Driver\Tcpip \Device\Udp IRP_MJ_SET_EA [BA4BB0F0] kl1.sys
AttachedDevice \Driver\Tcpip \Device\Udp IRP_MJ_FLUSH_BUFFERS [BA4BB0F0] kl1.sys
AttachedDevice \Driver\Tcpip \Device\Udp IRP_MJ_QUERY_VOLUME_INFORMATION [BA4BB0F0] kl1.sys
AttachedDevice \Driver\Tcpip \Device\Udp IRP_MJ_SET_VOLUME_INFORMATION [BA4BB0F0] kl1.sys
AttachedDevice \Driver\Tcpip \Device\Udp IRP_MJ_DIRECTORY_CONTROL [BA4BB0F0] kl1.sys
AttachedDevice \Driver\Tcpip \Device\Udp IRP_MJ_FILE_SYSTEM_CONTROL [BA4BB0F0] kl1.sys
AttachedDevice \Driver\Tcpip \Device\Udp IRP_MJ_DEVICE_CONTROL [BA4BB0F0] kl1.sys
AttachedDevice \Driver\Tcpip \Device\Udp IRP_MJ_INTERNAL_DEVICE_CONTROL [BA4BB0F0] kl1.sys
AttachedDevice \Driver\Tcpip \Device\Udp IRP_MJ_SHUTDOWN [BA4BB0F0] kl1.sys
AttachedDevice \Driver\Tcpip \Device\Udp IRP_MJ_LOCK_CONTROL [BA4BB0F0] kl1.sys
AttachedDevice \Driver\Tcpip \Device\Udp IRP_MJ_CLEANUP [BA4BB0F0] kl1.sys
AttachedDevice \Driver\Tcpip \Device\Udp IRP_MJ_CREATE_MAILSLOT [BA4BB0F0] kl1.sys
AttachedDevice \Driver\Tcpip \Device\Udp IRP_MJ_QUERY_SECURITY [BA4BB0F0] kl1.sys
AttachedDevice \Driver\Tcpip \Device\Udp IRP_MJ_SET_SECURITY [BA4BB0F0] kl1.sys
AttachedDevice \Driver\Tcpip \Device\Udp IRP_MJ_POWER [BA4BB0F0] kl1.sys
AttachedDevice \Driver\Tcpip \Device\Udp IRP_MJ_SYSTEM_CONTROL [BA4BB0F0] kl1.sys
AttachedDevice \Driver\Tcpip \Device\Udp IRP_MJ_DEVICE_CHANGE [BA4BB0F0] kl1.sys
AttachedDevice \Driver\Tcpip \Device\Udp IRP_MJ_QUERY_QUOTA [BA4BB0F0] kl1.sys
AttachedDevice \Driver\Tcpip \Device\Udp IRP_MJ_SET_QUOTA [BA4BB0F0] kl1.sys

Device \Driver\nvata \Device\00000089 IRP_MJ_CREATE 8A9C41E8
Device \Driver\nvata \Device\00000089 IRP_MJ_CREATE_NAMED_PIPE 8A9C41E8
Device \Driver\nvata \Device\00000089 IRP_MJ_CLOSE 8A9C41E8
Device \Driver\nvata \Device\00000089 IRP_MJ_READ 8A9C41E8
Device \Driver\nvata \Device\00000089 IRP_MJ_WRITE 8A9C41E8
Device \Driver\nvata \Device\00000089 IRP_MJ_QUERY_INFORMATION 8A9C41E8
Device \Driver\nvata \Device\00000089 IRP_MJ_SET_INFORMATION 8A9C41E8
Device \Driver\nvata \Device\00000089 IRP_MJ_QUERY_EA 8A9C41E8
Device \Driver\nvata \Device\00000089 IRP_MJ_SET_EA 8A9C41E8
Device \Driver\nvata \Device\00000089 IRP_MJ_FLUSH_BUFFERS 8A9C41
A voir également:

5 réponses

jlpjlp Messages postés 52399 Statut Contributeur sécurité 5 040
 
slt,

explique tes problemes svp

_____________


Fais un clic droit sur ce lien : (IL-MAFIOSO)
http://perso.orange.fr/il.mafioso/Navifix/Navilog1.exe
Enregistrer la cible (du lien) sous... et enregistre-le sur ton bureau.
Ensuite double clique sur navilog1.exe pour lancer l'installation.
Une fois l'installation terminée, le fix s'exécutera automatiquement.
(Si ce n'est pas le cas, double-clique sur le raccourci Navilog1 présent sur le bureau).

Laisse-toi guider. Au menu principal, choisis 1 et valides.
(ne fais pas le choix 2,3 ou 4 sans notre avis/accord)

Patiente jusqu'au message :
*** Analyse Termine le ..... ***
Appuie sur une touche comme demandé, le blocnote va s'ouvrir.
Copie-colle l'intégralité dans une réponse. Referme le blocnote.
Le rapport est en outre sauvegardé à la racine du disque (fixnavi.txt)

_____________


colle un rapport hijackthis

http://www.trendsecure.com/portal/en-US/tools/security_tools/hijackthis/download

manuel :

https://leblogdeclaude.blogspot.com/2006/10/informatique-section-hijackthis.html


Je conseille de renomer Hijackthis, pour contrer une éventuelle infection de Vundo.

ex:Renomme le fichier HijackThis.exe en eden.exe pour cela, fais un clic droit sur le fichier HijackThis.exe et choisis renommer dans la liste

Ensuite avec Explorer créer un dossier c:\hijackthis
Décompresser Hijackthis dans ce dossier.
C'est important pour les sauvegardes."
0
peace
 
slt jpl

merci pour ta reponse voici le rapport navilog1

Search Navipromo version 3.3.8 commencé le 25/12/2007 à 14:54:52,31

!!! Attention,ce rapport peut indiquer des fichiers/programmes légitimes!!!
!!! Postez ce rapport sur le forum pour le faire analyser !!!
!!! Ne lancez pas la partie désinfection sans l'avis d'un spécialiste !!!

Outil exécuté depuis D:\Program Files\navilog1
Mise à jour le 11.12.2007 à 18h00 par IL-MAFIOSO


Microsoft Windows XP [version 5.1.2600]
Internet Explorer : 7.0.5730.11
Système de fichiers : NTFS

Executé en mode normal

*** Recherche Programmes installés ***




*** Recherche dossiers dans D:\WINDOWS ***



*** Recherche dossiers dans D:\Program Files ***



*** Recherche dossiers dans D:\DOCUME~1\ALLUSE~1\APPLIC~1 ***




*** Recherche dossiers dans "D:\Documents and Settings\Administrateur\application data" ***


*** Recherche dossiers dans D:\DOCUME~1\ALLUSE~1\MENUDM~1\PROGRA~1 ***


*** Recherche avec Catchme-rootkit/stealth malware detector par gmer ***
pour + d'infos : http://www.gmer.net

Aucun Fichier trouvé



*** Recherche avec GenericNaviSearch ***
!!! Tous ces résultats peuvent révéler des fichiers légitimes !!!
!!! A vérifier impérativement avant toute suppression manuelle !!!

* Recherche dans D:\WINDOWS\system32 *

Fichiers suspects :

D:\WINDOWS\system32\xpregistry21.exe trouvé !

* Recherche dans "D:\Documents and Settings\Administrateur\local settings\application data" *



*** Recherche fichiers ***




*** Recherche clés spécifiques dans le Registre ***


*** Module de Recherche complémentaire ***
(Recherche fichiers spécifiques)

1)Recherche nouveaux fichiers Instant Access :


2)Recherche Heuristique :

* Dans D:\WINDOWS\system32 :


* Dans "D:\Documents and Settings\Administrateur\local settings\application data" :


3)Recherche Certificats :

Certificat Egroup absent !

4)Recherche fichiers connus :



*** Analyse terminée le 25/12/2007 à 14:57:49,42 ***

ET voici le rapport hijackthis

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 15:03:54, on 25/12/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16574)
Boot mode: Normal

Running processes:
D:\WINDOWS\System32\smss.exe
D:\WINDOWS\system32\winlogon.exe
D:\WINDOWS\system32\services.exe
D:\WINDOWS\system32\lsass.exe
D:\WINDOWS\system32\svchost.exe
D:\Program Files\Windows Defender\MsMpEng.exe
D:\WINDOWS\System32\svchost.exe
D:\WINDOWS\system32\ZoneLabs\vsmon.exe
D:\WINDOWS\system32\spoolsv.exe
D:\Program Files\Avira\AntiVir PersonalEdition Classic\avguard.exe
D:\WINDOWS\system32\netdde.exe
D:\WINDOWS\Explorer.EXE
D:\Program Files\Avira\AntiVir PersonalEdition Classic\sched.exe
D:\Program Files\Diskeeper Corporation\Diskeeper\DkService.exe
D:\WINDOWS\system32\E_S00RP1.EXE
D:\WINDOWS\system32\SAgent4.exe
D:\Program Files\Windows Defender\MSASCui.exe
D:\WINDOWS\system32\svchost.exe
D:\Program Files\Java\jre1.6.0_03\bin\jusched.exe
D:\Program Files\UPHClean\uphclean.exe
D:\WINDOWS\system32\rundll32.exe
D:\WINDOWS\system32\wbem\wmiapsrv.exe
D:\Program Files\inKline Global\PC Booster\PCBooster.exe
D:\Program Files\LogMeIn\x86\LogMeInSystray.exe
D:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe
D:\Program Files\Avira\AntiVir PersonalEdition Classic\avgnt.exe
D:\WINDOWS\system32\ctfmon.exe
D:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
D:\Program Files\MSN Messenger\msnmsgr.exe
D:\Program Files\Logitech\SetPoint\SetPoint.exe
D:\Program Files\Fichiers communs\Logishrd\KHAL2\KHALMNPR.EXE
D:\WINDOWS\System32\svchost.exe
D:\Program Files\MSN Messenger\usnsvc.exe
D:\Program Files\Internet Explorer\IEXPLORE.EXE
D:\WINDOWS\system32\cmd.exe
D:\WINDOWS\system32\notepad.exe
D:\Documents and Settings\Administrateur\Bureau\HiJackThis\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.google.be/?gws_rd=ssl
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = https://www.msn.com/fr-fr/?ocid=iehp
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,First Home Page = https://support.microsoft.com/en-US/topic/internet-explorer-downloads-d49e1f0d-571c-9a7b-d97e-be248806ca70
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page =
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
O2 - BHO: Aide pour le lien d'Adobe PDF Reader - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - D:\Program Files\Fichiers communs\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - D:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - D:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - D:\Program Files\Fichiers communs\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O4 - HKLM\..\Run: [Windows Defender] "D:\Program Files\Windows Defender\MSASCui.exe" -hide
O4 - HKLM\..\Run: [SunJavaUpdateSched] "D:\Program Files\Java\jre1.6.0_03\bin\jusched.exe"
O4 - HKLM\..\Run: [NVMixerTray] "D:\Program Files\NVIDIA Corporation\NvMixer\NVMixerTray.exe"
O4 - HKLM\..\Run: [BluetoothAuthenticationAgent] rundll32.exe bthprops.cpl,,BluetoothAuthenticationAgent
O4 - HKLM\..\Run: [PC Booster] D:\Program Files\inKline Global\PC Booster\PCBooster.exe
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE D:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE D:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [LogMeIn GUI] "D:\Program Files\LogMeIn\x86\LogMeInSystray.exe"
O4 - HKLM\..\Run: [ZoneAlarm Client] "D:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe"
O4 - HKLM\..\Run: [avgnt] "D:\Program Files\Avira\AntiVir PersonalEdition Classic\avgnt.exe" /min
O4 - HKLM\..\Run: [Kernel and Hardware Abstraction Layer] KHALMNPR.EXE
O4 - HKLM\..\Run: [Logitech Hardware Abstraction Layer] KHALMNPR.EXE
O4 - HKCU\..\Run: [CTFMON.EXE] D:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [SUPERAntiSpyware] D:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
O4 - HKCU\..\Run: [msnmsgr] "D:\Program Files\MSN Messenger\msnmsgr.exe" /background
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] D:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] D:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
O4 - Global Startup: Logitech SetPoint.lnk = D:\Program Files\Logitech\SetPoint\SetPoint.exe
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - D:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Console Java (Sun) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - D:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O9 - Extra button: (no name) - {85d1f590-48f4-11d9-9669-0800200c9a66} - D:\WINDOWS\bdoscandel.exe
O9 - Extra 'Tools' menuitem: Uninstall BitDefender Online Scanner v8 - {85d1f590-48f4-11d9-9669-0800200c9a66} - D:\WINDOWS\bdoscandel.exe
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - D:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - D:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - D:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - D:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O10 - Unknown file in Winsock LSP: d:\windows\system32\nwprovau.dll
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://download.microsoft.com/download/E/5/6/E5611B10-0D6D-4117-8430-A67417AA88CD/LegitCheckControl.cab
O16 - DPF: {5D86DDB5-BDF9-441B-9E9E-D4730F4EE499} (BDSCANONLINE Control) - http://www.bitdefender.fr/scan_fr/scan8/oscan8.cab
O16 - DPF: {C3F79A2B-B9B4-4A66-B012-3EE46475B072} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/MessengerStatsPAClient.cab56907.cab
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab
O20 - Winlogon Notify: !SASWinLogon - D:\Program Files\SUPERAntiSpyware\SASWINLO.dll
O23 - Service: a-squared Free Service (a2free) - Unknown owner - j:\pack\a-squared free\a2service.exe (file missing)
O23 - Service: AntiVir PersonalEdition Classic Scheduler (AntiVirScheduler) - Avira GmbH - D:\Program Files\Avira\AntiVir PersonalEdition Classic\sched.exe
O23 - Service: AntiVir PersonalEdition Classic Guard (AntiVirService) - Avira GmbH - D:\Program Files\Avira\AntiVir PersonalEdition Classic\avguard.exe
O23 - Service: Diskeeper - Diskeeper Corporation - D:\Program Files\Diskeeper Corporation\Diskeeper\DkService.exe
O23 - Service: EPSON V3 Service2(03) (EPSON_PM_RPCV2_01) - SEIKO EPSON CORPORATION - D:\WINDOWS\system32\E_S00RP1.EXE
O23 - Service: Google Updater Service (gusvc) - Google - D:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: Logitech Bluetooth Service (LBTServ) - Logitech, Inc. - D:\Program Files\Fichiers communs\Logishrd\Bluetooth\LBTServ.exe
O23 - Service: NMIndexingService - Nero AG - D:\Program Files\Fichiers communs\Ahead\Lib\NMIndexingService.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - D:\WINDOWS\system32\nvsvc32.exe
O23 - Service: PC Tools Auxiliary Service (sdAuxService) - PC Tools - D:\Program Files\Spyware Doctor\svcntaux.exe
O23 - Service: PC Tools Security Service (sdCoreService) - PC Tools - D:\Program Files\Spyware Doctor\swdsvc.exe
O23 - Service: StarWind AE Service (StarWindServiceAE) - Rocket Division Software - D:\Program Files\Alcohol Soft\Alcohol 120\StarWind\StarWindServiceAE.exe
O23 - Service: Epson Printer Status Agent4 (StatusAgent4) - SEIKO EPSON CORPORATION - D:\WINDOWS\system32\SAgent4.exe
O23 - Service: TrueVector Internet Monitor (vsmon) - Zone Labs, LLC - D:\WINDOWS\system32\ZoneLabs\vsmon.exe
0
jlpjlp Messages postés 52399 Statut Contributeur sécurité 5 040
 
tu as quoi comme pbs? des pubs? .... explique

analyse ce ficheir sur virus total et colle le rapport: https://www.virustotal.com/gui/



D:\WINDOWS\system32\xpregistry21.exe
0
peace
 
yep jlpjlp dsl pour le retard,

Mais g mon fils qui était à l'hosto pour une opération et g passé la nuit avec lui!!
En tout cas je te remercie pour le coup de main que tu donne^^,

Mon prob est que parfois ma sourit est comme possedé, elle se met a bouger seule sur l'ecran ouvre ma poubelle sans rien faire ensuite,
et des fois elle ne me laisse rien faire lorsque je bouge le curseur elle s'agite et clic n'importe où :/
Que mon pc se met à ramer tout a coup alors que j'ai 2gigas de ram et pas vraiment de grosse application qui tourne genre msn,media player,antivirus, et firewall steam +- 650 700Mg d'apres le gestionnaire d'applic et que lorsque je passe AVG anti-rootkit il me detect un rootkit qui apres suppression et reboot reviens sous un autre noms.

Des fois g la paix quelques jours, apres avoir déconnecter mon pc du net et fait tout les scan en mode sans echec vider tout les fichier temp et tout le tralala, mais le rootkit lui puis sa reviens !! Grrrr

Ensuite, il y a quelque jours le panneau de config de logitech qui apparait en me demandant de changer les piles d'une sourit mx600 alors que j'en ai pas, j'ai la G5 en filiaire et un clavier sans fil EX110 de logitech, donc g pensé a des interférence avec un voisin, j'habite un appartement avec des voisins au-dessus et en-dessous, donc g sécurisé dans les options logitech il y a une option pour securisé la connxion clavier je l'ai activé , la trankil kelkes jours et puis rebellote. Et la je commence à ètre a cour d'inspiration
ah oui encore un pt souci, g une session invité pour certaine occasion, les enfants... lorsque je quitté cette session et que je veux revenir sur mon compte en fermant la session invite mon écran reste noir et je suis obligé re reboot le pc pour avoir mon compte qui est un compte admin.

Voila en te remerciant pour ton aide, ET Bonne Année
0

Vous n’avez pas trouvé la réponse que vous recherchez ?

Posez votre question
jlpjlp Messages postés 52399 Statut Contributeur sécurité 5 040
 
Colle le rapport :
Clean permettra de faire du nettoyage et supprimer des fichiers que des anti-virus et anti-spywares n'ont pas pu trouver. Le logiciel est régulièrement mis à jour, vous devrez donc le re-téléchargé pour obtenir une version plus récente.

 Téléchargez clean.zip, décompressez-le sur votre bureau (clic droit / extraire tout), vous obtenez alors un dossier clean
 Démarrez Windows en mode sans échec : Guide pour redémarrer en mode sans échec
 Ouvrez le dossier clean qui se trouve sur ton bureau, et double-cliquez sur clean.cmd, une fenêtre noire va apparaître pendant un instant, laissez la ouverte jusqu'à ce qu'elle se ferme.
Manuel de clean :
http://kerio.probb.fr/tuto-Clean-h37.html
https://kerio.probb.fr/

________________



colle le rapport d'un scan en ligne
avec un des suivants:


bitdefender en ligne :
http://www.bitdefender.fr/scan_fr/scan8/ie.html

Panda en ligne :
http://pandasoftware.fr

____________

tu as super antispyware + windows defender + spybot + spyware doctor? ca fais beaucoups
garde windos defender et spybot san le tea timer par exemple car tous te font une analyse en temps réel, cela peut faire planter!
0