Probleme google

Résolu
Bonjour,

j'éprouve un léger problème lors de mes recherches google,
quand je fait une recherche et que je clique sur le lien, ceci me renvoi toujours a cette page : http://mediashifting.com/?search=awdasd&subid=81&key=1a9a25f9e5fcaf9bb426

Merci de votre aide

22 réponses

Résumé de la discussion

Le fil porte sur un problème de redirection lors des recherches Google, où cliquer sur un lien affiche systématiquement une page affiliée mediashifting.com et remet en question la sécurité du navigateur et du système. Des recommandations de sécurité informatique suivent: mettre à jour Internet Explorer/Firefox/Chrome via Windows Update, désinstaller des barres d’outils indésirables, puis lancer des outils de nettoyage comme Malwarebytes et UsbFix. Certaines réponses préconisent d’héberger les rapports de diagnostic sur des services externes avant publication, et d’exécuter les outils dans des sessions isolées pour éviter la propagation de la menace.

Bobot (l’IA à votre service)
  1. hello

    Pour nettoyer les outils utilsés et mieux sécuriser ton pc
    --------------------------------------------------------------

    Je t'invite à suivre ce tutoriel pour le final

    il inclut

    ♦ du nettoyage après desinfection
    ♦ des mises à jour pour combler des failles de securité de logiciels importants non mis à jour

    ▶ et enfin quelques conseils à suivre afin que la protection soit plus efficace

    _________________________________________________

    Telecharge ici : PureRa (par l'editeur de JavaRa)

    Lance-le (clic droit "executer en tant qu'administrateur" pour Vista/7)

    => Configuration

    clique sur "Clean"

    L'outil va faire son scan puis son nettoyage

    à la fin du rapport tu auras une ligne comme ca :

    Total space cleaned: 8140878 bytes

    transmets juste cette ligne , le reste importe peu

    __________________________________________________

    Si nous avons utilisé Defogger et cliqué sur "disable" , tu peux le "reenable"

    __________________________________________________

    ▶ Télécharge DelFix sur ton bureau.

    ▶ Lance le, tape suppression puis valide

    Patiente pendant le scan jusqu'à l'ouverture du rapport.

    ▶ Copie/Colle le contenu du rapport dans ta prochaine réponse.

    Note : Le rapport se trouve également sous C:\DelFix.txt

    tu peux le desinstaller

    ___________________________________________________

    ▶ Télécharge et installe CCleaner (N'installe pas la Yahoo Toolbar) :

    * Lance-le.(clic droit "en tant qu'administrateur" pour Vista/7)

    => Configuration

    fais le nettoyage dans le registre et dans le nettoyeur autant de fois qu'il trouve des choses à l analyse
    __________________________________________________

    Attention : ne pas toucher au PC pendant qu'il travaille !

    ▶ Nettoyage et Défragmentation de tes Disques

    *Nettoyage :

    Clic droit sur "poste de travail"(ordinateur pour vista) ==>"ouvrir" ==>clic droit sur le disque C ==>Propriétés ==>onglet "Général"
    Cliques sur le bouton "nettoyage de disque", OK
    tu le fais pour chacun de tes disques
    ________________________________________________

    *Vérifications des erreurs :

    Clic droit sur "poste de travail"(ordinateur pour vista) ==>"ouvrir" ==>clic droit sur le disque C ==>Propriétés ==>onglet "Outil"
    "Vérifier maintenant", une boîte s'ouvre, cocher les cases :
    -réparer automatiquement les erreurs...
    -rechercher et tenter une récupération...

    --->Démarrer, ok
    Note : s'il te dis de redémarrer ton Pc pour le faire , tu redémarres et tu laisses faire, cela prend un peu de temps c'est normal
    tu le fais pour chacun de tes disques
    ________________________________________________

    ensuite toujours dans le même onglet tu choisis :

    *Défragmentation :
    "défragmenter maintenant", OK
    une boîte s'ouvre, tu sélectionnes le disque à défragmenter, et tu cliques sur "analyser", puis après l'analyse, "défragmenter" . OK
    tu le fais pour chacun de tes disques
    _______________________________________________

    Note : si tu as un utilitaire pour défragmenter , utilises le à la place

    pour ce faire Defraggler est proposé
    _________________________________________________

    ▶ Peux-tu vérifier ta Console Java ? :

    et installer la nouvelle version si besoin est.

    desinstalle les anciennes versions :

    voici pour desinstaller :

    JavaRa

    Décompresse le fichier sur le Bureau (Clic droit > Extraire tout).
    * Double-clique (clic droit "en tant qu'administrateur" pour Vista) sur le répertoire JavaRa.
    * Puis double-clique sur le fichier JavaRa.exe (le exe peut ne pas s'afficher).
    * Choisis Français puis clique sur Select.
    * Clique sur Oui pour confirmer. Laisse travailler et clique ensuite sur OK, puis une deuxième fois sur OK.
    * Ferme l'application.

    Note : tu peux supprimer son rapport dans C:\ sous le nom JavaRa.log.
    _________________________________________________

    ▶ Mets à jour Adobe Reader si ce n'est pas le cas (désinstalle avant la version antérieure)

    et pense à decocher l'installation de McAfee proposée discrêtement
    __________________________________________________

    ▶ Je te conseille si tu n en as pas , afin de mieux securiser ton pc , d'installer un parefeu :

    Online armor ou KERIO ou JETICO ou ZONE ALARM (mettre que le parefeu gratuit) ou COMODO

    https://www.commentcamarche.net/telecharger/securite/16545-online-armor-personal-firewall/
    https://www.01net.com/telecharger/windows/Securite/firewall/fiches/39911.html
    https://forum.pcastuces.com/sujet.asp?f=25&s=35606
    https://www.clubic.com/telecharger-fiche11071-sunbelt-personal-firewall-ex-kerio.html
    https://manuelsdaide.com/contact/
    http://www.open-files.com/forum/index.php?showtopic=29277
    https://www.commentcamarche.net/telecharger/securite/24863-zonealarm/
    ___________________________________________________

    ▶ Tu peux aussi vider ta corbeille,quoi que Ccleaner le fasse tout seul
    _____________________________________________________

    ▶ Si nous avons utilisé MalwareByte's Anti-Malware , vide sa quarantaine :

    * Lance le programme puis clique sur <Quarantaine>.
    * Sélectionne tous les éléments puis clique sur <supprimer>.
    * Quitte le programme.
    ______________________________________________________

    ▶ Idem pour ton antivirus : vide sa quarantaine si ce n'est pas déjà fait
    ______________________________________________________

    ▶ Désactive et réactive la restauration de système, pour cela : suis les instructions du lien :

    Lien XP

    Lien Vista

    Lien Win7

    ▶ Sitôt fait , recrées un point de restoration dit "sain" pour parer à quelques eventuels problêmes dans le futur

    ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~

    Quelques conseils et recommandations pour l'avenir :

    ▶ Passe un coup de MalwareByte's Anti-Malware de temps en temps (1 fois par semaine , suivant l'utilisation que tu fais de ton PC.
    ▶ Utilise aussi tes autres logiciels de protection (scannes antivirus, antispywares...). N'oublie pas de faire les mises à jour avant de les utiliser.
    * Pense aussi à faire une défragmentation de tes disques durs de temps en temps (garde suffisamment d'espace sur C:\ (1/3 de libre pour être à l'aise))
    _____________

    ▶ Pour bien protéger ton PC :
    [1 seul Antivirus] + [1 seul Pare feu] + [Un bon Antispyware] + [Mises à Jour récentes Windows et Logiciels de Protection] + [Utilisation de Firefox -ou autres- (Internet Explorer présente des failles de sécurité qui mettent longtemps avant d'être corrigées mais il faut absolument le conserver pour les mises à jour Windows et Windows live Messenger)]

    Je te conseille d'installer cette extension pour Firefox pour securiser ton surf : WOT
    Je te conseille d'installer cette extension pour Internet Explorer pour securiser ton surf : WOT

    PS : En fait la meilleure des protections c'est toi même : ce que tu fais avec ton PC : où tu surfes, télécharges...ect....
    Les virus utilisent les failles de ton PC pour infecter un système
    à lire aussi
    Et ceci

    sujets intéressants à lire :

    https://www.luanagames.com/index.fr.html
    https://forum.malekal.com/viewtopic.php?t=13629&start=
    https://www.malekal.com/fichiers/projetantimalwares/ProjetAntiMalware-courte.pdf
    http://www.libellules.ch/phpBB2/les-risques-securitaires-du-peer-to-peer-en-10-points-t28947.html
    https://www.commentcamarche.net/faq/13362-mettre-a-jour-son-pc-contre-les-failles-de-securite

    il ne faut jamais accepter l'installation de toobars, adwares, moteurs de recherches lorsqu'on installe un logiciel gratuit.
    Ceux-ci corrompent les navigateurs et dirigent les recherches sur des sites publicitaires, malveillants etc et affichent des pubs intempestives.
    Il ne faut jamais télécharger le logiciel à partir des pubs sur les pages web, ne jamais cliquer sur les liens genre "boostez votre pc" ou
    "avant de télécharger le logiciel, faites un balayage rapide blabla", et éviter les sites de vidéos/séries en streaming dont les vidéos sont parfois piégées
    par des malwares sous la forme de modules complémentaires à installer pour voir la vidéo.

    ▶ dans le souhait de vouloir desinstaller un antivirus au profit d'un autre , voici quelques liens :

    Desinstaller Avast
    Desinstaller BitDefender
    Desinstaller Norton
    Desinstaller Kaspersky
    Desinstaller AVG

    ou tout en un :

    Désinstallation Antivirus , Parefeu , Antispyware
    _____________

    ▶ Si tu as Vista n'oublie pas de réactiver le controle des comptes des utilisateurs(UAC)
    ___________

    ▶ si nous avons affiché les fichiers cachés , n'oublies pas de les remettre en attribut "caché"

    ▶ Clique sur le menu Demarrer /Panneau de configuration/Options des dossiers/ puis dans l'onglet Affichage
    * - Décoche Afficher les fichiers et dossiers cachés
    * - coche Masquer les extensions des fichiers dont le type est connu
    * - coche Masquer les fichiers protégés du système d'exploitation (recommandé)

    ▶ clique sur Appliquer, puis OK.
    ____________

    Voila,

    Bonne lecture, à bientot , une fois tout ceci fait,

    tu peux mettre le topic en resolu

    Bonne continuation et surtout , prudence et bon surf :)

    1. Franchement, tous va vraiment mieux ! il n'y a plus vraiment de probleme apparent ! merci beaucoup !
      1. voila !

        Malwarebytes Anti-Malware 1.60.0.1800
        www.malwarebytes.org

        Version de la base de données: v2012.01.06.01

        Windows Vista Service Pack 2 x64 NTFS
        Internet Explorer 9.0.8112.16421
        Famille :: PC-FAMILLE [administrateur]

        2012-01-05 20:58:34
        mbam-log-2012-01-05 (20-58-34).txt

        Type d'examen: Examen complet
        Options d'examen activées: Mémoire | Démarrage | Registre | Système de fichiers | Heuristique/Extra | Heuristique/Shuriken | PUP | PUM
        Options d'examen désactivées: P2P
        Elément(s) analysé(s): 379744
        Temps écoulé: 57 minute(s), 40 seconde(s)

        Processus mémoire détecté(s): 0
        (Aucun élément nuisible détecté)

        Module(s) mémoire détecté(s): 0
        (Aucun élément nuisible détecté)

        Clé(s) du Registre détectée(s): 0
        (Aucun élément nuisible détecté)

        Valeur(s) du Registre détectée(s): 0
        (Aucun élément nuisible détecté)

        Elément(s) de données du Registre détecté(s): 0
        (Aucun élément nuisible détecté)

        Dossier(s) détecté(s): 0
        (Aucun élément nuisible détecté)

        Fichier(s) détecté(s): 1
        C:\Kill'em\Quarantine\U.kill'em\800000cb.@ (Backdoor.0Access) -> Mis en quarantaine et supprimé avec succès.

        (fin)
        1. fermer toutes les fenêtres et applications lors de l'installation et de l'analyse.

          ▶ Télécharge ici :

          Malwarebytes

          ▶ Installe le ( choisis bien "francais" ; ne modifie pas les paramètres d'installe ) et mets le à jour .

          relance malwarebytes en suivant scrupuleusement ces consignes :

          ! Déconnecte toi et ferme toutes applications en cours !

          ▶ Lance Malwarebyte's .

          Fais un examen dit "Complet" .

          ▶ Laisse le programme travailler ( et ne rien faire d'autre avec le PC durant le scan ).
          ▶ à la fin tu cliques sur "résultat" .
          ▶ Vérifie que tous les objets infectés soient validés, puis clique sur " suppression " .

          ▶ Note : si il faut redémarrer ton PC pour finir le nettoyage, fais le !

          ▶ Poste le rapport sauvegardé après la suppression des objets infectés (dans l'onglet "rapport/log"de Malwarebytes, le dernier en date)

          1. hello tu l'as fait plusieurs fois ?
            1. Il avait planter la premiere fois alors je les recommencé ... c'est grave :S ?
          2. desinstalle java update 22

            =========================

            ATTENTION !!! : Script personnalisé pour cette machine uniquement , ne pas reproduire !!

            si tu as XP => double clique
            si tu as Vista ou windows 7 => clic droit "executer en tant que...."


            sur OTL.exe pour le lancer.

            ▶Copie la liste qui se trouve en gras ci-dessous,

            ▶ colle-la dans la zone sous "Personnalisation" :


            :processes
            explorer.exe
            iexplore.exe
            firefox.exe
            msnmsgr.exe
            Teatimer.exe

            :OTL
            FF - prefs.js..network.proxy.http: "127.0.0.1"
            FF - prefs.js..network.proxy.http_port: 51455
            FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=: File not found
            O4 - HKU\S-1-5-21-3971761074-295491806-2592085895-1000\..\Run: [AdobeBridge] File not found
            O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\restrictions present
            O7 - HKU\S-1-5-21-3971761074-295491806-2592085895-1000\Software\Policies\Microsoft\Internet Explorer\restrictions present
            O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-1_6_0_22-windows-i586.cab (Java Plug-in 1.6.0_22)
            O16 - DPF: {CAFEEFAC-0016-0000-0022-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-1_6_0_22-windows-i586.cab (Java Plug-in 1.6.0_22)
            O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-1_6_0_22-windows-i586.cab (Java Plug-in 1.6.0_22)
            O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab (Reg Error: Key error.)

            :Reg
            [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
            ""=-

            :Files
            C:\Users\Famille\AppData\Roaming\Mozilla\Firefox\Profiles\fdy0j28v.default\searchplugins\search.xml
            C:\Windows\tasks\At*.job
            C:\Windows\SysWow64\21d7W2y6.com
            C:\Windows\SysWow64\21d7W2y6.com_
            C:\Users\Famille\AppData\Local\{*}

            :commands
            [emptytemp]
            [start explorer]
            [reboot]


            ▶ Clique sur "Correction" pour lancer la suppression.

            ▶ Poste le rapport qui logiquement s'ouvrira tout seul en fin de travail appres le redemarrage.
            1. All processes killed
              ========== PROCESSES ==========
              No active process named explorer.exe was found!
              No active process named iexplore.exe was found!
              No active process named firefox.exe was found!
              No active process named msnmsgr.exe was found!
              No active process named Teatimer.exe was found!
              ========== OTL ==========
              Prefs.js: "127.0.0.1" removed from network.proxy.http
              Prefs.js: 51455 removed from network.proxy.http_port
              Registry key HKEY_LOCAL_MACHINE\Software\MozillaPlugins\@Apple.com/iTunes,version=\ not found.
              Registry value HKEY_USERS\S-1-5-21-3971761074-295491806-2592085895-1000\\Software\Microsoft\Windows\CurrentVersion\Run\\AdobeBridge not found.
              Registry key HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\Internet Explorer\restrictions\ not found.
              Registry key HKEY_USERS\S-1-5-21-3971761074-295491806-2592085895-1000\Software\Policies\Microsoft\Internet Explorer\restrictions\ not found.
              Starting removal of ActiveX control {8AD9C840-044E-11D1-B3E9-00805F499D93}
              Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Distribution Units\{8AD9C840-044E-11D1-B3E9-00805F499D93}\ not found.
              Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{8AD9C840-044E-11D1-B3E9-00805F499D93}\ not found.
              Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{8AD9C840-044E-11D1-B3E9-00805F499D93}\ not found.
              Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{8AD9C840-044E-11D1-B3E9-00805F499D93}\ not found.
              Starting removal of ActiveX control {CAFEEFAC-0016-0000-0022-ABCDEFFEDCBA}
              Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Distribution Units\{CAFEEFAC-0016-0000-0022-ABCDEFFEDCBA}\ not found.
              Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{CAFEEFAC-0016-0000-0022-ABCDEFFEDCBA}\ not found.
              Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{CAFEEFAC-0016-0000-0022-ABCDEFFEDCBA}\ not found.
              Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{CAFEEFAC-0016-0000-0022-ABCDEFFEDCBA}\ not found.
              Starting removal of ActiveX control {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA}
              Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Distribution Units\{CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA}\ not found.
              Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA}\ not found.
              Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA}\ not found.
              Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA}\ not found.
              Starting removal of ActiveX control {E2883E8F-472F-4FB0-9522-AC9BF37916A7}
              Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Distribution Units\{E2883E8F-472F-4FB0-9522-AC9BF37916A7}\ not found.
              Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{E2883E8F-472F-4FB0-9522-AC9BF37916A7}\ not found.
              Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{E2883E8F-472F-4FB0-9522-AC9BF37916A7}\ not found.
              Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{E2883E8F-472F-4FB0-9522-AC9BF37916A7}\ not found.
              ========== REGISTRY ==========
              Registry key HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run not found.
              ========== FILES ==========
              File\Folder C:\Users\Famille\AppData\Roaming\Mozilla\Firefox\Profiles\fdy0j28v.default\searchplugins\search.xml not found.
              File\Folder C:\Windows\tasks\At*.job not found.
              File\Folder C:\Windows\SysWow64\21d7W2y6.com not found.
              File\Folder C:\Windows\SysWow64\21d7W2y6.com_ not found.
              File\Folder C:\Users\Famille\AppData\Local\{*} not found.
              ========== COMMANDS ==========

              [EMPTYTEMP]

              User: All Users

              User: Default
              ->Temp folder emptied: 0 bytes
              ->Temporary Internet Files folder emptied: 0 bytes
              ->Flash cache emptied: 0 bytes

              User: Default User
              ->Temp folder emptied: 0 bytes
              ->Temporary Internet Files folder emptied: 0 bytes
              ->Flash cache emptied: 0 bytes

              User: Famille
              ->Temp folder emptied: 0 bytes
              ->Temporary Internet Files folder emptied: 3112960 bytes
              ->Java cache emptied: 0 bytes
              ->FireFox cache emptied: 0 bytes
              ->Google Chrome cache emptied: 7241910 bytes
              ->Flash cache emptied: 0 bytes

              User: Public
              ->Temp folder emptied: 0 bytes

              %systemdrive% .tmp files removed: 0 bytes
              %systemroot% .tmp files removed: 0 bytes
              %systemroot%\System32 .tmp files removed: 0 bytes
              %systemroot%\System32 (64bit) .tmp files removed: 0 bytes
              %systemroot%\System32\drivers .tmp files removed: 0 bytes
              Windows Temp folder emptied: 0 bytes
              %systemroot%\sysnative\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files folder emptied: 95414333 bytes
              RecycleBin emptied: 5112618 bytes

              Total Files Cleaned = 106,00 mb

              OTL by OldTimer - Version 3.2.31.0 log created on 01042012_220652

              Files\Folders moved on Reboot...

              Registry entries deleted on Reboot...
          3. re

            Télécharge ici :OTL

            ▶ enregistre le sur ton Bureau.

            si tu as XP => double clique
            si tu as Vista ou windows 7 => clic droit "executer en tant que...."


            sur OTL.exe pour le lancer.

            ▶ => Clique ici pour voir la Configuration

            ▶ Copie et colle le contenu de ce qui suit en gras dans la partie inférieure d'OTL "Personnalisation"

            /md5start
            explorer.exe
            winlogon.exe
            wininit.exe
            /md5stop
            netsvcs
            safebootminimal
            safebootnetwork
            %systemroot%\system32\*.dll /lockedfiles
            %systemroot%\system32\*.ini
            %systemroot%\Tasks\*.*
            %systemroot%\system32\Tasks\*.*
            %systemroot%\system32\drivers\*.sys /lockedfiles
            %systemroot%\System32\config\*.sav
            %systemroot%\system32\config\*.exe /s
            %systemroot%\system32\*.sys
            HKEY_LOCAL_MACHINE\system\currentcontrolset\control\lsa /s
            HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon
            CREATERESTOREPOINT


            ▶ Clic sur Analyse.

            A la fin du scan, le Bloc-Notes va s'ouvrir avec le rapport (OTL.txt).

            Ce fichier est sur ton Bureau (en général C:\Documents and settings\le_nom_de_ta_session\<Bureau ou Desktop>\OTL.txt)

            ▶▶▶ NE LE POSTE PAS SUR LE FORUM (il est trop long)

            heberge OTL.txt et extra.txt sur http://pjjoint.malekal.com et donne les liens
            1. ▶ Téléchargez UsbFix (créé par El Desaparecido) sur votre Bureau.

              ▶ Si votre antivirus affiche une alerte, ignorez-la et désactivez l'antivirus temporairement.
              ▶ Branchez toutes vos sources de données externes à votre PC (clé USB, disque dur externe, etc...) sans les ouvrir.
              ▶ Double cliquez sur UsbFix.exe.

              ▶ Cliquez sur Suppression.
              ▶ Laissez travailler l'outil.

              ▶ À la fin du scan, un rapport va s'afficher, postez-le dans votre prochaine réponse sur le forum.

              ▶ Le rapport est aussi sauvegardé à la racine du disque système ( C:\UsbFix.txt ).
              ▶ Tutoriel vidéo

              1. j'ai un léger probleme avec l'application, quand je l'ouvre une fenetre pop pour me dire que usbfix ne reconnait pas mon systeme d'exploitation, ensuite l'application ouvre et quand je clique sur suppression, il ecrit :
                Line 2786 (file C:/usbfix/go.exe)

                error: variable used without being declared.
              2. je contacte le concepteur
              3. merci :)
            2. j'utilise google chrome alors dois-je quand meme mettre explorer et firefox a jour ?

              oui

              pour internet explorer : windows update et windows live messsenger utilisent son protocole
              1. j'utilise google chrome alors dois-je quand meme mettre explorer et firefox a jour ?

                sinon voici le pre script :

                ¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤ Pre_Script | 2.005 ¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤

                ¤¤¤¤¤ XP | Vista | Seven - 32/64 bits ¤¤¤¤¤

                Mise à jour : 24/12/2011 | 03.10 Par g3n-h@ckm@n
                Utilisateur : Famille (Administrateurs)
                Ordinateur : PC-FAMILLE
                Système d'exploitation : Windows (TM) Vista Home Premium (64 bits)
                Internet Explorer : 8.0.6001.19170
                Mozilla Firefox : 6.0 (fr)

                Switchs possibles :

                processes:: | file:: | folder:: | Registry::
                Driver:: | replace:: | DNS:: | Command::
                txt:: | Host:: | NsLook::
                list:: | IP:: | ADS:: | Kill:: | clean::
                Reboot:: | MBR:: | Fixmbr:: | 40:: | Zip::
                Tray::

                Script : 22:46:26

                ¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤

                Modification du registre effectuée

                ¤

                Supprimé : C:\Users\Famille\21d7W2y6.com
                Supprimé : C:\Users\Famille\AppData\Roaming\mcp.ico

                ¤

                Absent : C:\Recycle.Bin
                Supprimé : C:\Windows\system64

                ¤

                ¤¤¤¤¤¤¤¤¤¤ | Nettoyage disque

                Nettoyage du disque effectué

                ¤

                explorer.exe -> Processus redémarré

                Fin : 22:47:30

                ¤¤¤¤¤¤¤¤¤¤ ( EOF ) ¤¤¤¤¤¤¤¤¤¤
                1. re

                  internet explorer n est pas à jour => à faire
                  firefox n'est pas à jour => à faire

                  =======================

                  desinstalle pdfforge Toolbar

                  ================

                  fais glisser une icone n'importe quel fichier sur Pre_scan , pre_script va apparaitre

                  Lance Pre_script , une page vierge va s'ouvrir.

                  selectionne tout le texte en gras ci-dessous, puis (clic droit/copier ou ctrl+c) :
                  ___________________________________________________
                  Kill::

                  Registry::
                  [HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
                  "4Y3Y0C3AUF7XZDXVXRBFJTE"=-
                  [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
                  "iTunesHelper"=-
                  ""=-
                  [-HKEY_CLASSES_ROOT\CLSID\{B922D405-6D13-4A2B-AE89-08A030DA4402}]
                  [-HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{B922D405-6D13-4A2B-AE89-08A030DA4402}]
                  [-HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\ext\settings\{B922D405-6D13-4A2B-AE89-08A030DA4402}]
                  [-HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\ext\stats\{B922D405-6D13-4A2B-AE89-08A030DA4402}]
                  [HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\URLSearchHooks]
                  "{B922D405-6D13-4A2B-AE89-08A030DA4402}"=-
                  [HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\URLSearchHooks]
                  "{B922D405-6D13-4A2B-AE89-08A030DA4402}"=-
                  [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
                  "{B922D405-6D13-4A2B-AE89-08A030DA4402}"=-
                  [HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser]
                  "{B922D405-6D13-4A2B-AE89-08A030DA4402}"=-
                  [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks]
                  "{B922D405-6D13-4A2B-AE89-08A030DA4402}"=-
                  [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\SharedTaskScheduler]
                  "{B922D405-6D13-4A2B-AE89-08A030DA4402}"=-
                  [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved]
                  "{B922D405-6D13-4A2B-AE89-08A030DA4402}"=-
                  [-HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{2F432386-BB17-45E2-B791-E0DA846AF96F}]
                  [-HKLM\Software\Microsoft\Internet Explorer\SearchScopes\{1054F07C-CDB2-450F-A165-3A341A7E9FF3}]
                  [-HKCU\Software\81091404B3ED83130F29B75E0927C86E]
                  [-HKLM\Software\Application Updater]
                  [-HKLM\Software\pdfforge]
                  [-HKLM\Software\Search Settings]

                  file::
                  C:\Users\Famille\21d7W2y6.com
                  C:\Users\Famille\AppData\Roaming\mcp.ico

                  folder::
                  C:\Recycle.Bin
                  C:\Windows\system64

                  clean::

                  Reboot::

                  ___________________________________________________

                  colle-le ensuite (clic droit/coller ou ctrl+V) dans la page vierge.

                  puis onglet fichier => enregistrer (pas enregistrer sous...) , puis ferme le texte

                  des fenetres noires risquent de clignoter , c'est normal , c'est le programme qui travaille

                  poste Pre_Script.txt qui apparaitra sur le bureau en fin de travail

                  si ton bureau ne reapparait pas => ctrl+alt+supp , gestionnaire des taches => onglet fichier => nouvelle tache puis tape explorer
                  ¤¤¤¤¤¤¤¤¤¤_g3n-h@ckm@n_Developpement_¤¤¤¤¤¤¤¤¤¤
                  ¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤
                  _Pre_Scan_¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤
                  1. oups désolé :S

                    alors voici prescan : https://pjjoint.malekal.com/files.php?id=20111225_p8h8i10d14l14

                    et l'autre :

                    01:34:14.0259 3324 TDSS rootkit removing tool 2.6.25.0 Dec 23 2011 14:51:16
                    01:34:14.0494 3324 ============================================================
                    01:34:14.0494 3324 Current date / time: 2011/12/25 01:34:14.0494
                    01:34:14.0494 3324 SystemInfo:
                    01:34:14.0494 3324
                    01:34:14.0494 3324 OS Version: 6.0.6002 ServicePack: 2.0
                    01:34:14.0494 3324 Product type: Workstation
                    01:34:14.0494 3324 ComputerName: PC-FAMILLE
                    01:34:14.0495 3324 UserName: Famille
                    01:34:14.0495 3324 Windows directory: C:\Windows
                    01:34:14.0495 3324 System windows directory: C:\Windows
                    01:34:14.0495 3324 Running under WOW64
                    01:34:14.0495 3324 Processor architecture: Intel x64
                    01:34:14.0495 3324 Number of processors: 2
                    01:34:14.0495 3324 Page size: 0x1000
                    01:34:14.0495 3324 Boot type: Normal boot
                    01:34:14.0495 3324 ============================================================
                    01:34:15.0603 3324 Initialize success
                    01:34:21.0652 3404 ============================================================
                    01:34:21.0652 3404 Scan started
                    01:34:21.0652 3404 Mode: Manual;
                    01:34:21.0652 3404 ============================================================
                    01:34:22.0540 3404 ACPI (1965aaffab07e3fb03c77f81beba3547) C:\Windows\system32\drivers\acpi.sys
                    01:34:22.0546 3404 ACPI - ok
                    01:34:22.0593 3404 adp94xx (f14215e37cf124104575073f782111d2) C:\Windows\system32\drivers\adp94xx.sys
                    01:34:22.0601 3404 adp94xx - ok
                    01:34:22.0619 3404 adpahci (7d05a75e3066861a6610f7ee04ff085c) C:\Windows\system32\drivers\adpahci.sys
                    01:34:22.0624 3404 adpahci - ok
                    01:34:22.0655 3404 adpu160m (820a201fe08a0c345b3bedbc30e1a77c) C:\Windows\system32\drivers\adpu160m.sys
                    01:34:22.0658 3404 adpu160m - ok
                    01:34:22.0694 3404 adpu320 (9b4ab6854559dc168fbb4c24fc52e794) C:\Windows\system32\drivers\adpu320.sys
                    01:34:22.0697 3404 adpu320 - ok
                    01:34:22.0757 3404 AFD (0cc146c4addea45791b18b1e2659f4a9) C:\Windows\system32\drivers\afd.sys
                    01:34:22.0764 3404 AFD - ok
                    01:34:22.0784 3404 agp440 (f6f6793b7f17b550ecfdbd3b229173f7) C:\Windows\system32\drivers\agp440.sys
                    01:34:22.0786 3404 agp440 - ok
                    01:34:22.0819 3404 aic78xx (222cb641b4b8a1d1126f8033f9fd6a00) C:\Windows\system32\drivers\djsvs.sys
                    01:34:22.0821 3404 aic78xx - ok
                    01:34:22.0844 3404 aliide (157d0898d4b73f075ce9fa26b482df98) C:\Windows\system32\drivers\aliide.sys
                    01:34:22.0846 3404 aliide - ok
                    01:34:22.0861 3404 amdide (970fa5059e61e30d25307b99903e991e) C:\Windows\system32\drivers\amdide.sys
                    01:34:22.0863 3404 amdide - ok
                    01:34:22.0894 3404 AmdK8 (cdc3632a3a5ea4dbb83e46076a3165a1) C:\Windows\system32\drivers\amdk8.sys
                    01:34:22.0896 3404 AmdK8 - ok
                    01:34:22.0935 3404 arc (ba8417d4765f3988ff921f30f630e303) C:\Windows\system32\drivers\arc.sys
                    01:34:22.0938 3404 arc - ok
                    01:34:22.0961 3404 arcsas (9d41c435619733b34cc16a511e644b11) C:\Windows\system32\drivers\arcsas.sys
                    01:34:22.0963 3404 arcsas - ok
                    01:34:22.0990 3404 AsyncMac (22d13ff3dafec2a80634752b1eaa2de6) C:\Windows\system32\DRIVERS\asyncmac.sys
                    01:34:22.0992 3404 AsyncMac - ok
                    01:34:23.0030 3404 atapi (e68d9b3a3905619732f7fe039466a623) C:\Windows\system32\drivers\atapi.sys
                    01:34:23.0031 3404 atapi - ok
                    01:34:23.0100 3404 BHDrvx64 (4d7f8401eae7eaa4ef702fa6f4153269) C:\Windows\System32\Drivers\NISx64\1008000.029\BHDrvx64.sys
                    01:34:23.0105 3404 BHDrvx64 - ok
                    01:34:23.0131 3404 blbdrive (79feeb40056683f8f61398d81dda65d2) C:\Windows\system32\drivers\blbdrive.sys
                    01:34:23.0133 3404 blbdrive - ok
                    01:34:23.0178 3404 bowser (2348447a80920b2493a9b582a23e81e1) C:\Windows\system32\DRIVERS\bowser.sys
                    01:34:23.0181 3404 bowser - ok
                    01:34:23.0204 3404 BrFiltLo (f09eee9edc320b5e1501f749fde686c8) C:\Windows\system32\drivers\brfiltlo.sys
                    01:34:23.0206 3404 BrFiltLo - ok
                    01:34:23.0234 3404 BrFiltUp (b114d3098e9bdb8bea8b053685831be6) C:\Windows\system32\drivers\brfiltup.sys
                    01:34:23.0235 3404 BrFiltUp - ok
                    01:34:23.0270 3404 Brserid (f0f0ba4d815be446aa6a4583ca3bca9b) C:\Windows\system32\drivers\brserid.sys
                    01:34:23.0273 3404 Brserid - ok
                    01:34:23.0290 3404 BrSerWdm (a6eca2151b08a09caceca35c07f05b42) C:\Windows\system32\drivers\brserwdm.sys
                    01:34:23.0292 3404 BrSerWdm - ok
                    01:34:23.0314 3404 BrUsbMdm (b79968002c277e869cf38bd22cd61524) C:\Windows\system32\drivers\brusbmdm.sys
                    01:34:23.0315 3404 BrUsbMdm - ok
                    01:34:23.0345 3404 BrUsbSer (a87528880231c54e75ea7a44943b38bf) C:\Windows\system32\drivers\brusbser.sys
                    01:34:23.0346 3404 BrUsbSer - ok
                    01:34:23.0369 3404 BTHMODEM (e0777b34e05f8a82a21856efc900c29f) C:\Windows\system32\drivers\bthmodem.sys
                    01:34:23.0371 3404 BTHMODEM - ok
                    01:34:23.0429 3404 ccHP (1b79efc84b924a6932bb9d2a549de5c9) C:\Windows\System32\Drivers\NISx64\1008000.029\ccHPx64.sys
                    01:34:23.0439 3404 ccHP - ok
                    01:34:23.0451 3404 cdfs (b4d787db8d30793a4d4df9feed18f136) C:\Windows\system32\DRIVERS\cdfs.sys
                    01:34:23.0454 3404 cdfs - ok
                    01:34:23.0487 3404 cdrom (c025aa69be3d0d25c7a2e746ef6f94fc) C:\Windows\system32\DRIVERS\cdrom.sys
                    01:34:23.0489 3404 cdrom - ok
                    01:34:23.0513 3404 circlass (02ea568d498bbdd4ba55bf3fce34d456) C:\Windows\system32\drivers\circlass.sys
                    01:34:23.0515 3404 circlass - ok
                    01:34:23.0551 3404 CLFS (3dca9a18b204939cfb24bea53e31eb48) C:\Windows\system32\CLFS.sys
                    01:34:23.0558 3404 CLFS - ok
                    01:34:23.0603 3404 cmdide (e5d5499a1c50a54b5161296b6afe6192) C:\Windows\system32\drivers\cmdide.sys
                    01:34:23.0605 3404 cmdide - ok
                    01:34:23.0621 3404 Compbatt (7fb8ad01db0eabe60c8a861531a8f431) C:\Windows\system32\drivers\compbatt.sys
                    01:34:23.0623 3404 Compbatt - ok
                    01:34:23.0645 3404 crcdisk (a8585b6412253803ce8efcbd6d6dc15c) C:\Windows\system32\drivers\crcdisk.sys
                    01:34:23.0647 3404 crcdisk - ok
                    01:34:23.0703 3404 DfsC (8b722ba35205c71e7951cdc4cdbade19) C:\Windows\system32\Drivers\dfsc.sys
                    01:34:23.0706 3404 DfsC - ok
                    01:34:23.0729 3404 dgderdrv - ok
                    01:34:23.0788 3404 disk (b0107e40ecdb5fa692ebf832f295d905) C:\Windows\system32\drivers\disk.sys
                    01:34:23.0790 3404 disk - ok
                    01:34:23.0843 3404 drmkaud (f1a78a98cfc2ee02144c6bec945447e6) C:\Windows\system32\drivers\drmkaud.sys
                    01:34:23.0844 3404 drmkaud - ok
                    01:34:23.0893 3404 DXGKrnl (b8e554e502d5123bc111f99d6a2181b4) C:\Windows\System32\drivers\dxgkrnl.sys
                    01:34:23.0907 3404 DXGKrnl - ok
                    01:34:23.0939 3404 E1G60 (264cee7b031a9d6c827f3d0cb031f2fe) C:\Windows\system32\DRIVERS\E1G6032E.sys
                    01:34:23.0942 3404 E1G60 - ok
                    01:34:23.0984 3404 Ecache (5f94962be5a62db6e447ff6470c4f48a) C:\Windows\system32\drivers\ecache.sys
                    01:34:23.0987 3404 Ecache - ok
                    01:34:24.0047 3404 eeCtrl (8ecb5d35f400706016931bd25ae1b554) C:\Program Files (x86)\Common Files\Symantec Shared\EENGINE\eeCtrl64.sys
                    01:34:24.0055 3404 eeCtrl - ok
                    01:34:24.0135 3404 elxstor (c4636d6e10469404ab5308d9fd45ed07) C:\Windows\system32\drivers\elxstor.sys
                    01:34:24.0144 3404 elxstor - ok
                    01:34:24.0195 3404 ErrDev (bc3a58e938bb277e46bf4b3003b01abd) C:\Windows\system32\drivers\errdev.sys
                    01:34:24.0196 3404 ErrDev - ok
                    01:34:24.0257 3404 exfat (486844f47b6636044a42454614ed4523) C:\Windows\system32\drivers\exfat.sys
                    01:34:24.0263 3404 exfat - ok
                    01:34:24.0294 3404 fastfat (1a4bee34277784619ddaf0422c0c6e23) C:\Windows\system32\drivers\fastfat.sys
                    01:34:24.0298 3404 fastfat - ok
                    01:34:24.0336 3404 fdc (81b79b6df71fa1d2c6d688d830616e39) C:\Windows\system32\DRIVERS\fdc.sys
                    01:34:24.0338 3404 fdc - ok
                    01:34:24.0372 3404 FileInfo (457b7d1d533e4bd62a99aed9c7bb4c59) C:\Windows\system32\drivers\fileinfo.sys
                    01:34:24.0374 3404 FileInfo - ok
                    01:34:24.0394 3404 Filetrace (d421327fd6efccaf884a54c58e1b0d7f) C:\Windows\system32\drivers\filetrace.sys
                    01:34:24.0397 3404 Filetrace - ok
                    01:34:24.0413 3404 flpydisk (230923ea2b80f79b0f88d90f87b87ebd) C:\Windows\system32\DRIVERS\flpydisk.sys
                    01:34:24.0415 3404 flpydisk - ok
                    01:34:24.0452 3404 FltMgr (e3041bc26d6930d61f42aedb79c91720) C:\Windows\system32\drivers\fltmgr.sys
                    01:34:24.0456 3404 FltMgr - ok
                    01:34:24.0475 3404 Fs_Rec (29d99e860a1ca0a03c6a733fdd0da703) C:\Windows\system32\drivers\Fs_Rec.sys
                    01:34:24.0477 3404 Fs_Rec - ok
                    01:34:24.0500 3404 gagp30kx (c8e416668d3dc2be3d4fe4c79224997f) C:\Windows\system32\drivers\gagp30kx.sys
                    01:34:24.0502 3404 gagp30kx - ok
                    01:34:24.0539 3404 GEARAspiWDM (e403aacf8c7bb11375122d2464560311) C:\Windows\system32\DRIVERS\GEARAspiWDM.sys
                    01:34:24.0540 3404 GEARAspiWDM - ok
                    01:34:24.0628 3404 HDAudBus (f942c5820205f2fb453243edfec82a3d) C:\Windows\system32\DRIVERS\HDAudBus.sys
                    01:34:24.0642 3404 HDAudBus - ok
                    01:34:24.0677 3404 HidBth (b4881c84a180e75b8c25dc1d726c375f) C:\Windows\system32\drivers\hidbth.sys
                    01:34:24.0679 3404 HidBth - ok
                    01:34:24.0698 3404 HidIr (4e77a77e2c986e8f88f996bb3e1ad829) C:\Windows\system32\drivers\hidir.sys
                    01:34:24.0699 3404 HidIr - ok
                    01:34:24.0721 3404 HidUsb (443bdd2d30bb4f00795c797e2cf99edf) C:\Windows\system32\DRIVERS\hidusb.sys
                    01:34:24.0722 3404 HidUsb - ok
                    01:34:24.0764 3404 HpCISSs (d7109a1e6bd2dfdbcba72a6bc626a13b) C:\Windows\system32\drivers\hpcisss.sys
                    01:34:24.0766 3404 HpCISSs - ok
                    01:34:24.0811 3404 HTTP (098f1e4e5c9cb5b0063a959063631610) C:\Windows\system32\drivers\HTTP.sys
                    01:34:24.0820 3404 HTTP - ok
                    01:34:24.0839 3404 i2omp (da94c854cea5fac549d4e1f6e88349e8) C:\Windows\system32\drivers\i2omp.sys
                    01:34:24.0841 3404 i2omp - ok
                    01:34:24.0866 3404 i8042prt (cbb597659a2713ce0c9cc20c88c7591f) C:\Windows\system32\DRIVERS\i8042prt.sys
                    01:34:24.0868 3404 i8042prt - ok
                    01:34:24.0899 3404 iaStorV (3e3bf3627d886736d0b4e90054f929f6) C:\Windows\system32\drivers\iastorv.sys
                    01:34:24.0957 3404 iaStorV - ok
                    01:34:25.0087 3404 IDSVia64 (9a793a1451b5e2cf54b4a33342cb58cf) C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\Definitions\ipsdefs\20091217.002\IDSvia64.sys
                    01:34:25.0097 3404 IDSVia64 - ok
                    01:34:25.0348 3404 igfx (a124c87cd0b39c9e510e138534468383) C:\Windows\system32\DRIVERS\igdkmd64.sys
                    01:34:25.0517 3404 igfx - ok
                    01:34:25.0546 3404 iirsp (8c3951ad2fe886ef76c7b5027c3125d3) C:\Windows\system32\drivers\iirsp.sys
                    01:34:25.0548 3404 iirsp - ok
                    01:34:25.0627 3404 IntcAzAudAddService (1edab7f9b9de4424beccdef950ce2ff0) C:\Windows\system32\drivers\RTKVHD64.sys
                    01:34:25.0661 3404 IntcAzAudAddService - ok
                    01:34:25.0680 3404 intelide (df797a12176f11b2d301c5b234bb200e) C:\Windows\system32\drivers\intelide.sys
                    01:34:25.0682 3404 intelide - ok
                    01:34:25.0696 3404 intelppm (bfd84af32fa1bad6231c4585cb469630) C:\Windows\system32\DRIVERS\intelppm.sys
                    01:34:25.0698 3404 intelppm - ok
                    01:34:25.0740 3404 IpFilterDriver (d8aabc341311e4780d6fce8c73c0ad81) C:\Windows\system32\DRIVERS\ipfltdrv.sys
                    01:34:25.0742 3404 IpFilterDriver - ok
                    01:34:25.0763 3404 IpInIp - ok
                    01:34:25.0788 3404 IPMIDRV (9c2ee2e6e5a7203bfae15c299475ec67) C:\Windows\system32\drivers\ipmidrv.sys
                    01:34:25.0791 3404 IPMIDRV - ok
                    01:34:25.0808 3404 IPNAT (b7e6212f581ea5f6ab0c3a6ceeeb89be) C:\Windows\system32\DRIVERS\ipnat.sys
                    01:34:25.0811 3404 IPNAT - ok
                    01:34:25.0842 3404 IRENUM (8c42ca155343a2f11d29feca67faa88d) C:\Windows\system32\drivers\irenum.sys
                    01:34:25.0843 3404 IRENUM - ok
                    01:34:25.0852 3404 is3srv - ok
                    01:34:25.0872 3404 isapnp (0672bfcedc6fc468a2b0500d81437f4f) C:\Windows\system32\drivers\isapnp.sys
                    01:34:25.0874 3404 isapnp - ok
                    01:34:25.0912 3404 iScsiPrt (e4fdf99599f27ec25d2cf6d754243520) C:\Windows\system32\DRIVERS\msiscsi.sys
                    01:34:25.0917 3404 iScsiPrt - ok
                    01:34:25.0937 3404 iteatapi (63c766cdc609ff8206cb447a65abba4a) C:\Windows\system32\drivers\iteatapi.sys
                    01:34:25.0939 3404 iteatapi - ok
                    01:34:25.0964 3404 iteraid (1281fe73b17664631d12f643cbea3f59) C:\Windows\system32\drivers\iteraid.sys
                    01:34:25.0966 3404 iteraid - ok
                    01:34:25.0987 3404 kbdclass (423696f3ba6472dd17699209b933bc26) C:\Windows\system32\DRIVERS\kbdclass.sys
                    01:34:25.0989 3404 kbdclass - ok
                    01:34:26.0006 3404 kbdhid (dbdf75d51464fbc47d0104ec3d572c05) C:\Windows\system32\DRIVERS\kbdhid.sys
                    01:34:26.0008 3404 kbdhid - ok
                    01:34:26.0049 3404 KSecDD (476e2c1dcea45895994bef11c2a98715) C:\Windows\system32\Drivers\ksecdd.sys
                    01:34:26.0062 3404 KSecDD - ok
                    01:34:26.0087 3404 ksthunk (1d419cf43db29396ecd7113d129d94eb) C:\Windows\system32\drivers\ksthunk.sys
                    01:34:26.0089 3404 ksthunk - ok
                    01:34:26.0130 3404 lltdio (96ece2659b6654c10a0c310ae3a6d02c) C:\Windows\system32\DRIVERS\lltdio.sys
                    01:34:26.0132 3404 lltdio - ok
                    01:34:26.0163 3404 LSI_FC (acbe1af32d3123e330a07bfbc5ec4a9b) C:\Windows\system32\drivers\lsi_fc.sys
                    01:34:26.0165 3404 LSI_FC - ok
                    01:34:26.0236 3404 LSI_SAS (799ffb2fc4729fa46d2157c0065b3525) C:\Windows\system32\drivers\lsi_sas.sys
                    01:34:26.0249 3404 LSI_SAS - ok
                    01:34:26.0305 3404 LSI_SCSI (f445ff1daad8a226366bfaf42551226b) C:\Windows\system32\drivers\lsi_scsi.sys
                    01:34:26.0309 3404 LSI_SCSI - ok
                    01:34:26.0362 3404 luafv (52f87b9cc8932c2a7375c3b2a9be5e3e) C:\Windows\system32\drivers\luafv.sys
                    01:34:26.0366 3404 luafv - ok
                    01:34:26.0772 3404 megasas (5c5cd6aaced32fb26c3fb34b3dcf972f) C:\Windows\system32\drivers\megasas.sys
                    01:34:26.0774 3404 megasas - ok
                    01:34:26.0802 3404 MegaSR (859bc2436b076c77c159ed694acfe8f8) C:\Windows\system32\drivers\megasr.sys
                    01:34:26.0809 3404 MegaSR - ok
                    01:34:26.0841 3404 Modem (59848d5cc74606f0ee7557983bb73c2e) C:\Windows\system32\drivers\modem.sys
                    01:34:26.0842 3404 Modem - ok
                    01:34:26.0865 3404 monitor (c247cc2a57e0a0c8c6dccf7807b3e9e5) C:\Windows\system32\DRIVERS\monitor.sys
                    01:34:26.0866 3404 monitor - ok
                    01:34:26.0885 3404 mouclass (9367304e5e412b120cf5f4ea14e4e4f1) C:\Windows\system32\DRIVERS\mouclass.sys
                    01:34:26.0887 3404 mouclass - ok
                    01:34:26.0900 3404 mouhid (c2c2bd5c5ce5aaf786ddd74b75d2ac69) C:\Windows\system32\DRIVERS\mouhid.sys
                    01:34:26.0905 3404 mouhid - ok
                    01:34:26.0922 3404 MountMgr (11bc9b1e8801b01f7f6adb9ead30019b) C:\Windows\system32\drivers\mountmgr.sys
                    01:34:26.0924 3404 MountMgr - ok
                    01:34:26.0952 3404 mpio (f8276eb8698142884498a528dfea8478) C:\Windows\system32\drivers\mpio.sys
                    01:34:26.0955 3404 mpio - ok
                    01:34:26.0975 3404 mpsdrv (c92b9abdb65a5991e00c28f13491dba2) C:\Windows\system32\drivers\mpsdrv.sys
                    01:34:26.0978 3404 mpsdrv - ok
                    01:34:27.0004 3404 Mraid35x (3c200630a89ef2c0864d515b7a75802e) C:\Windows\system32\drivers\mraid35x.sys
                    01:34:27.0006 3404 Mraid35x - ok
                    01:34:27.0043 3404 MRxDAV (7c1de4aa96dc0c071611f9e7de02a68d) C:\Windows\system32\drivers\mrxdav.sys
                    01:34:27.0046 3404 MRxDAV - ok
                    01:34:27.0092 3404 mrxsmb (1485811b320ff8c7edad1caebb1c6c2b) C:\Windows\system32\DRIVERS\mrxsmb.sys
                    01:34:27.0095 3404 mrxsmb - ok
                    01:34:27.0129 3404 mrxsmb10 (3b929a60c833fc615fd97fba82bc7632) C:\Windows\system32\DRIVERS\mrxsmb10.sys
                    01:34:27.0134 3404 mrxsmb10 - ok
                    01:34:27.0150 3404 mrxsmb20 (c64ab3e1f53b4f5b5bb6d796b2d7bec3) C:\Windows\system32\DRIVERS\mrxsmb20.sys
                    01:34:27.0153 3404 mrxsmb20 - ok
                    01:34:27.0169 3404 msahci (1ac860612b85d8e85ee257d372e39f4d) C:\Windows\system32\drivers\msahci.sys
                    01:34:27.0173 3404 msahci - ok
                    01:34:27.0196 3404 msdsm (264bbb4aaf312a485f0e44b65a6b7202) C:\Windows\system32\drivers\msdsm.sys
                    01:34:27.0199 3404 msdsm - ok
                    01:34:27.0234 3404 Msfs (704f59bfc4512d2bb0146aec31b10a7c) C:\Windows\system32\drivers\Msfs.sys
                    01:34:27.0236 3404 Msfs - ok
                    01:34:27.0247 3404 msisadrv (00ebc952961664780d43dca157e79b27) C:\Windows\system32\drivers\msisadrv.sys
                    01:34:27.0248 3404 msisadrv - ok
                    01:34:27.0272 3404 MSKSSRV (0ea73e498f53b96d83dbfca074ad4cf8) C:\Windows\system32\drivers\MSKSSRV.sys
                    01:34:27.0274 3404 MSKSSRV - ok
                    01:34:27.0300 3404 MSPCLOCK (52e59b7e992a58e740aa63f57edbae8b) C:\Windows\system32\drivers\MSPCLOCK.sys
                    01:34:27.0302 3404 MSPCLOCK - ok
                    01:34:27.0330 3404 MSPQM (49084a75bae043ae02d5b44d02991bb2) C:\Windows\system32\drivers\MSPQM.sys
                    01:34:27.0331 3404 MSPQM - ok
                    01:34:27.0370 3404 MsRPC (dc6ccf440cdede4293db41c37a5060a5) C:\Windows\system32\drivers\MsRPC.sys
                    01:34:27.0376 3404 MsRPC - ok
                    01:34:27.0396 3404 mssmbios (855796e59df77ea93af46f20155bf55b) C:\Windows\system32\DRIVERS\mssmbios.sys
                    01:34:27.0397 3404 mssmbios - ok
                    01:34:27.0450 3404 MSTEE (86d632d75d05d5b7c7c043fa3564ae86) C:\Windows\system32\drivers\MSTEE.sys
                    01:34:27.0451 3404 MSTEE - ok
                    01:34:27.0494 3404 Mup (0cc49f78d8aca0877d885f149084e543) C:\Windows\system32\Drivers\mup.sys
                    01:34:27.0495 3404 Mup - ok
                    01:34:27.0544 3404 NativeWifiP (2007b826c4acd94ae32232b41f0842b9) C:\Windows\system32\DRIVERS\nwifi.sys
                    01:34:27.0548 3404 NativeWifiP - ok
                    01:34:27.0576 3404 NAVENG - ok
                    01:34:27.0584 3404 NAVEX15 - ok
                    01:34:27.0637 3404 NDIS (65950e07329fcee8e6516b17c8d0abb6) C:\Windows\system32\drivers\ndis.sys
                    01:34:27.0646 3404 NDIS - ok
                    01:34:27.0669 3404 NdisTapi (64df698a425478e321981431ac171334) C:\Windows\system32\DRIVERS\ndistapi.sys
                    01:34:27.0671 3404 NdisTapi - ok
                    01:34:27.0691 3404 Ndisuio (8baa43196d7b5bb972c9a6b2bbf61a19) C:\Windows\system32\DRIVERS\ndisuio.sys
                    01:34:27.0692 3404 Ndisuio - ok
                    01:34:27.0739 3404 NdisWan (f8158771905260982ce724076419ef19) C:\Windows\system32\DRIVERS\ndiswan.sys
                    01:34:27.0741 3404 NdisWan - ok
                    01:34:27.0755 3404 NDProxy (9cb77ed7cb72850253e973a2d6afdf49) C:\Windows\system32\drivers\NDProxy.sys
                    01:34:27.0757 3404 NDProxy - ok
                    01:34:27.0774 3404 NetBIOS (a499294f5029a7862adc115bda7371ce) C:\Windows\system32\DRIVERS\netbios.sys
                    01:34:27.0775 3404 NetBIOS - ok
                    01:34:27.0811 3404 netbt (fc2c792ebddc8e28df939d6a92c83d61) C:\Windows\system32\DRIVERS\netbt.sys
                    01:34:27.0814 3404 netbt - ok
                    01:34:27.0854 3404 nfrd960 (4ac08bd6af2df42e0c3196d826c8aea7) C:\Windows\system32\drivers\nfrd960.sys
                    01:34:27.0857 3404 nfrd960 - ok
                    01:34:27.0888 3404 Npfs (b298874f8e0ea93f06ec40aa8d146478) C:\Windows\system32\drivers\Npfs.sys
                    01:34:27.0890 3404 Npfs - ok
                    01:34:27.0903 3404 nsiproxy (1523af19ee8b030ba682f7a53537eaeb) C:\Windows\system32\drivers\nsiproxy.sys
                    01:34:27.0907 3404 nsiproxy - ok
                    01:34:27.0955 3404 Ntfs (bac869dfb98e499ba4d9bb1fb43270e1) C:\Windows\system32\drivers\Ntfs.sys
                    01:34:27.0980 3404 Ntfs - ok
                    01:34:27.0988 3404 Null (dd5d684975352b85b52e3fd5347c20cb) C:\Windows\system32\drivers\Null.sys
                    01:34:27.0990 3404 Null - ok
                    01:34:28.0009 3404 nvraid (2c040b7ada5b06f6facadac8514aa034) C:\Windows\system32\drivers\nvraid.sys
                    01:34:28.0012 3404 nvraid - ok
                    01:34:28.0032 3404 nvstor (f7ea0fe82842d05eda3efdd376dbfdba) C:\Windows\system32\drivers\nvstor.sys
                    01:34:28.0034 3404 nvstor - ok
                    01:34:28.0056 3404 nv_agp (19067ca93075ef4823e3938a686f532f) C:\Windows\system32\drivers\nv_agp.sys
                    01:34:28.0061 3404 nv_agp - ok
                    01:34:28.0069 3404 NwlnkFlt - ok
                    01:34:28.0081 3404 NwlnkFwd - ok
                    01:34:28.0129 3404 ohci1394 (7b58953e2f263421fdbb09a192712a85) C:\Windows\system32\drivers\ohci1394.sys
                    01:34:28.0131 3404 ohci1394 - ok
                    01:34:28.0168 3404 Parport (aecd57f94c887f58919f307c35498ea0) C:\Windows\system32\drivers\parport.sys
                    01:34:28.0171 3404 Parport - ok
                    01:34:28.0201 3404 partmgr (f9b5eda4c17a2be7663f064dbf0fe254) C:\Windows\system32\drivers\partmgr.sys
                    01:34:28.0203 3404 partmgr - ok
                    01:34:28.0287 3404 PCDSRVC{F36B3A4C-F95654BD-06000000}_0 (51209fbdb13a46e05c1b0077a9310264) c:\program files\pc-doctor for windows\pcdsrvc_x64.pkms
                    01:34:28.0325 3404 PCDSRVC{F36B3A4C-F95654BD-06000000}_0 - ok
                    01:34:28.0360 3404 pci (47ab1e0fc9d0e12bb53ba246e3a0906d) C:\Windows\system32\drivers\pci.sys
                    01:34:28.0363 3404 pci - ok
                    01:34:28.0393 3404 pciide (8d618c829034479985a9ed56106cc732) C:\Windows\system32\drivers\pciide.sys
                    01:34:28.0394 3404 pciide - ok
                    01:34:28.0419 3404 pcmcia (037661f3d7c507c9993b7010ceee6288) C:\Windows\system32\drivers\pcmcia.sys
                    01:34:28.0423 3404 pcmcia - ok
                    01:34:28.0457 3404 PEAUTH (58865916f53592a61549b04941bfd80d) C:\Windows\system32\drivers\peauth.sys
                    01:34:28.0469 3404 PEAUTH - ok
                    01:34:28.0550 3404 PptpMiniport (23386e9952025f5f21c368971e2e7301) C:\Windows\system32\DRIVERS\raspptp.sys
                    01:34:28.0553 3404 PptpMiniport - ok
                    01:34:28.0571 3404 Processor (5080e59ecee0bc923f14018803aa7a01) C:\Windows\system32\drivers\processr.sys
                    01:34:28.0573 3404 Processor - ok
                    01:34:28.0610 3404 PSched (c5ab7f0809392d0da027f4a2a81bfa31) C:\Windows\system32\DRIVERS\pacer.sys
                    01:34:28.0613 3404 PSched - ok
                    01:34:28.0662 3404 ql2300 (0b83f4e681062f3839be2ec1d98fd94a) C:\Windows\system32\drivers\ql2300.sys
                    01:34:28.0687 3404 ql2300 - ok
                    01:34:28.0734 3404 ql40xx (e1c80f8d4d1e39ef9595809c1369bf2a) C:\Windows\system32\drivers\ql40xx.sys
                    01:34:28.0737 3404 ql40xx - ok
                    01:34:28.0761 3404 QWAVEdrv (e8d76edab77ec9c634c27b8eac33adc5) C:\Windows\system32\drivers\qwavedrv.sys
                    01:34:28.0763 3404 QWAVEdrv - ok
                    01:34:28.0776 3404 RasAcd (1013b3b663a56d3ddd784f581c1bd005) C:\Windows\system32\DRIVERS\rasacd.sys
                    01:34:28.0778 3404 RasAcd - ok
                    01:34:28.0816 3404 Rasl2tp (ac7bc4d42a7e558718dfdec599bbfc2c) C:\Windows\system32\DRIVERS\rasl2tp.sys
                    01:34:28.0819 3404 Rasl2tp - ok
                    01:34:28.0854 3404 RasPppoe (4517fbf8b42524afe4ede1de102aae3e) C:\Windows\system32\DRIVERS\raspppoe.sys
                    01:34:28.0856 3404 RasPppoe - ok
                    01:34:28.0891 3404 RasSstp (c6a593b51f34c33e5474539544072527) C:\Windows\system32\DRIVERS\rassstp.sys
                    01:34:28.0894 3404 RasSstp - ok
                    01:34:28.0933 3404 rdbss (322db5c6b55e8d8ee8d6f358b2aaabb1) C:\Windows\system32\DRIVERS\rdbss.sys
                    01:34:28.0938 3404 rdbss - ok
                    01:34:28.0961 3404 RDPCDD (603900cc05f6be65ccbf373800af3716) C:\Windows\system32\DRIVERS\RDPCDD.sys
                    01:34:28.0962 3404 RDPCDD - ok
                    01:34:29.0002 3404 rdpdr (c045d1fb111c28df0d1be8d4bda22c06) C:\Windows\system32\drivers\rdpdr.sys
                    01:34:29.0008 3404 rdpdr - ok
                    01:34:29.0018 3404 RDPENCDD (cab9421daf3d97b33d0d055858e2c3ab) C:\Windows\system32\drivers\rdpencdd.sys
                    01:34:29.0019 3404 RDPENCDD - ok
                    01:34:29.0077 3404 RDPWD (b1d741c87cea8d7282146366cc9c3f81) C:\Windows\system32\drivers\RDPWD.sys
                    01:34:29.0082 3404 RDPWD - ok
                    01:34:29.0137 3404 RimUsb (5790bca445cc40df8b38c2c48608aac2) C:\Windows\system32\Drivers\RimUsb_AMD64.sys
                    01:34:29.0139 3404 RimUsb - ok
                    01:34:29.0177 3404 RimVSerPort (c903d49655b4aae46673f0aaa6be0f58) C:\Windows\system32\DRIVERS\RimSerial_AMD64.sys
                    01:34:29.0179 3404 RimVSerPort - ok
                    01:34:29.0204 3404 ROOTMODEM (6a0cf73b019cbc9255e23c9192ec3702) C:\Windows\system32\Drivers\RootMdm.sys
                    01:34:29.0205 3404 ROOTMODEM - ok
                    01:34:29.0231 3404 rspndr (22a9cb08b1a6707c1550c6bf099aae73) C:\Windows\system32\DRIVERS\rspndr.sys
                    01:34:29.0234 3404 rspndr - ok
                    01:34:29.0271 3404 RTL8169 (d53c84ec99ab4d78a90001e5ce5386ec) C:\Windows\system32\DRIVERS\Rtlh64.sys
                    01:34:29.0275 3404 RTL8169 - ok
                    01:34:29.0306 3404 sbp2port (cd9c693589c60ad59bbbcfb0e524e01b) C:\Windows\system32\drivers\sbp2port.sys
                    01:34:29.0308 3404 sbp2port - ok
                    01:34:29.0353 3404 secdrv (3ea8a16169c26afbeb544e0e48421186) C:\Windows\system32\drivers\secdrv.sys
                    01:34:29.0355 3404 secdrv - ok
                    01:34:29.0383 3404 Serenum (f71bfe7ac6c52273b7c82cbf1bb2a222) C:\Windows\system32\drivers\serenum.sys
                    01:34:29.0385 3404 Serenum - ok
                    01:34:29.0412 3404 Serial (e62fac91ee288db29a9696a9d279929c) C:\Windows\system32\drivers\serial.sys
                    01:34:29.0414 3404 Serial - ok
                    01:34:29.0438 3404 sermouse (a842f04833684bceea7336211be478df) C:\Windows\system32\drivers\sermouse.sys
                    01:34:29.0440 3404 sermouse - ok
                    01:34:29.0472 3404 sffdisk (14d4b4465193a87c127933978e8c4106) C:\Windows\system32\drivers\sffdisk.sys
                    01:34:29.0474 3404 sffdisk - ok
                    01:34:29.0486 3404 sffp_mmc (7073aee3f82f3d598e3825962aa98ab2) C:\Windows\system32\drivers\sffp_mmc.sys
                    01:34:29.0487 3404 sffp_mmc - ok
                    01:34:29.0504 3404 sffp_sd (35e59ebe4a01a0532ed67975161c7b82) C:\Windows\system32\drivers\sffp_sd.sys
                    01:34:29.0506 3404 sffp_sd - ok
                    01:34:29.0523 3404 sfloppy (6b7838c94135768bd455cbdc23e39e5f) C:\Windows\system32\drivers\sfloppy.sys
                    01:34:29.0524 3404 sfloppy - ok
                    01:34:29.0553 3404 SiSRaid2 (7a5de502aeb719d4594c6471060a78b3) C:\Windows\system32\drivers\sisraid2.sys
                    01:34:29.0555 3404 SiSRaid2 - ok
                    01:34:29.0573 3404 SiSRaid4 (3a2f769fab9582bc720e11ea1dfb184d) C:\Windows\system32\drivers\sisraid4.sys
                    01:34:29.0575 3404 SiSRaid4 - ok
                    01:34:29.0610 3404 Smb (290b6f6a0ec4fcdfc90f5cb6d7020473) C:\Windows\system32\DRIVERS\smb.sys
                    01:34:29.0613 3404 Smb - ok
                    01:34:29.0665 3404 spldr (386c3c63f00a7040c7ec5e384217e89d) C:\Windows\system32\drivers\spldr.sys
                    01:34:29.0667 3404 spldr - ok
                    01:34:29.0733 3404 SRTSP (9e399476e5d5e0d3c8822c857a7e9a9a) C:\Windows\System32\Drivers\NISx64\1008000.029\SRTSP64.SYS
                    01:34:29.0742 3404 SRTSP - ok
                    01:34:29.0762 3404 SRTSPX (3d7717b582f0365e75071556936e5a6b) C:\Windows\system32\drivers\NISx64\1008000.029\SRTSPX64.SYS
                    01:34:29.0764 3404 SRTSPX - ok
                    01:34:29.0801 3404 srv (880a57fccb571ebd063d4dd50e93e46d) C:\Windows\system32\DRIVERS\srv.sys
                    01:34:29.0808 3404 srv - ok
                    01:34:29.0847 3404 srv2 (a1ad14a6d7a37891fffeca35ebbb0730) C:\Windows\system32\DRIVERS\srv2.sys
                    01:34:29.0851 3404 srv2 - ok
                    01:34:29.0868 3404 srvnet (4bed62f4fa4d8300973f1151f4c4d8a7) C:\Windows\system32\DRIVERS\srvnet.sys
                    01:34:29.0871 3404 srvnet - ok
                    01:34:29.0909 3404 sscdbus (ed161b91fdf7eaa39469d72d463d5f4e) C:\Windows\system32\DRIVERS\sscdbus.sys
                    01:34:29.0912 3404 sscdbus - ok
                    01:34:29.0931 3404 sscdmdfl (4cb09e77593dbd8d7af33b37375ca715) C:\Windows\system32\DRIVERS\sscdmdfl.sys
                    01:34:29.0932 3404 sscdmdfl - ok
                    01:34:29.0961 3404 sscdmdm (c7b4cf53497a6e5363f3439427663882) C:\Windows\system32\DRIVERS\sscdmdm.sys
                    01:34:29.0964 3404 sscdmdm - ok
                    01:34:30.0001 3404 sscdserd (05ffa552f578e27ab2d41b6828db477f) C:\Windows\system32\DRIVERS\sscdserd.sys
                    01:34:30.0004 3404 sscdserd - ok
                    01:34:30.0034 3404 swenum (8a851ca908b8b974f89c50d2e18d4f0c) C:\Windows\system32\DRIVERS\swenum.sys
                    01:34:30.0036 3404 swenum - ok
                    01:34:30.0064 3404 Symc8xx (2f26a2c6fc96b29beff5d8ed74e6625b) C:\Windows\system32\drivers\symc8xx.sys
                    01:34:30.0067 3404 Symc8xx - ok
                    01:34:30.0090 3404 SYMDNS - ok
                    01:34:30.0138 3404 SymEFA (4f87bb5389a93778ebc363b28271a65b) C:\Windows\system32\drivers\NISx64\1008000.029\SYMEFA64.SYS
                    01:34:30.0145 3404 SymEFA - ok
                    01:34:30.0163 3404 SymEvent (7e4d281982e19abd06728c7ee9ac40a8) C:\Windows\system32\Drivers\SYMEVENT64x86.SYS
                    01:34:30.0166 3404 SymEvent - ok
                    01:34:30.0187 3404 SYMFW (6320bf296b62d324890866a13a296fc0) C:\Windows\System32\Drivers\NISx64\1008000.029\SYMFW.SYS
                    01:34:30.0190 3404 SYMFW - ok
                    01:34:30.0210 3404 SymIM (212bbf5a964513980d5de9397381534f) C:\Windows\system32\DRIVERS\SymIMv.sys
                    01:34:30.0212 3404 SymIM - ok
                    01:34:30.0232 3404 SYMNDISV (21dcc664a1e0af7bf4c8aded8c9ff9d5) C:\Windows\System32\Drivers\NISx64\1008000.029\SYMNDISV.SYS
                    01:34:30.0234 3404 SYMNDISV - ok
                    01:34:30.0243 3404 SYMREDRV - ok
                    01:34:30.0269 3404 SYMTDI (56a1cb71b8bb7ba9c41d2c9706df43cd) C:\Windows\System32\Drivers\NISx64\1008000.029\SYMTDI.SYS
                    01:34:30.0274 3404 SYMTDI - ok
                    01:34:30.0301 3404 Sym_hi (a909667976d3bccd1df813fed517d837) C:\Windows\system32\drivers\sym_hi.sys
                    01:34:30.0303 3404 Sym_hi - ok
                    01:34:30.0329 3404 Sym_u3 (36887b56ec2d98b9c362f6ae4de5b7b0) C:\Windows\system32\drivers\sym_u3.sys
                    01:34:30.0332 3404 Sym_u3 - ok
                    01:34:30.0340 3404 szkg5 - ok
                    01:34:30.0411 3404 Tcpip (2cc45d932bd193cd4117321d469ad6b2) C:\Windows\system32\drivers\tcpip.sys
                    01:34:30.0445 3404 Tcpip - ok
                    01:34:30.0486 3404 Tcpip6 (2cc45d932bd193cd4117321d469ad6b2) C:\Windows\system32\DRIVERS\tcpip.sys
                    01:34:30.0500 3404 Tcpip6 - ok
                    01:34:30.0540 3404 tcpipreg (c7e72a4071ee0200e3c075dacfb2b334) C:\Windows\system32\drivers\tcpipreg.sys
                    01:34:30.0542 3404 tcpipreg - ok
                    01:34:30.0561 3404 TDPIPE (1d8bf4aaa5fb7a2761475781dc1195bc) C:\Windows\system32\drivers\tdpipe.sys
                    01:34:30.0562 3404 TDPIPE - ok
                    01:34:30.0583 3404 TDTCP (7f7e00cdf609df657f4cda02dd1c9bb1) C:\Windows\system32\drivers\tdtcp.sys
                    01:34:30.0585 3404 TDTCP - ok
                    01:34:30.0622 3404 tdx (458919c8c42e398dc4802178d5ffee27) C:\Windows\system32\DRIVERS\tdx.sys
                    01:34:30.0624 3404 tdx - ok
                    01:34:30.0653 3404 TermDD (8c19678d22649ec002ef2282eae92f98) C:\Windows\system32\DRIVERS\termdd.sys
                    01:34:30.0655 3404 TermDD - ok
                    01:34:30.0702 3404 tssecsrv (9e5409cd17c8bef193aad498f3bc2cb8) C:\Windows\system32\DRIVERS\tssecsrv.sys
                    01:34:30.0704 3404 tssecsrv - ok
                    01:34:30.0713 3404 tunmp (89ec74a9e602d16a75a4170511029b3c) C:\Windows\system32\DRIVERS\tunmp.sys
                    01:34:30.0715 3404 tunmp - ok
                    01:34:30.0767 3404 tunnel (30a9b3f45ad081bffc3bcaa9c812b609) C:\Windows\system32\DRIVERS\tunnel.sys
                    01:34:30.0768 3404 tunnel - ok
                    01:34:30.0785 3404 uagp35 (fec266ef401966311744bd0f359f7f56) C:\Windows\system32\drivers\uagp35.sys
                    01:34:30.0787 3404 uagp35 - ok
                    01:34:30.0822 3404 udfs (faf2640a2a76ed03d449e443194c4c34) C:\Windows\system32\DRIVERS\udfs.sys
                    01:34:30.0826 3404 udfs - ok
                    01:34:30.0866 3404 uliagpkx (4ec9447ac3ab462647f60e547208ca00) C:\Windows\system32\drivers\uliagpkx.sys
                    01:34:30.0869 3404 uliagpkx - ok
                    01:34:30.0896 3404 uliahci (697f0446134cdc8f99e69306184fbbb4) C:\Windows\system32\drivers\uliahci.sys
                    01:34:30.0901 3404 uliahci - ok
                    01:34:30.0920 3404 UlSata (31707f09846056651ea2c37858f5ddb0) C:\Windows\system32\drivers\ulsata.sys
                    01:34:30.0923 3404 UlSata - ok
                    01:34:30.0946 3404 ulsata2 (85e5e43ed5b48c8376281bab519271b7) C:\Windows\system32\drivers\ulsata2.sys
                    01:34:30.0950 3404 ulsata2 - ok
                    01:34:30.0974 3404 umbus (46e9a994c4fed537dd951f60b86ad3f4) C:\Windows\system32\DRIVERS\umbus.sys
                    01:34:30.0976 3404 umbus - ok
                    01:34:31.0016 3404 USBAAPL64 (aa33fc47ed58c34e6e9261e4f850b7eb) C:\Windows\system32\Drivers\usbaapl64.sys
                    01:34:31.0018 3404 USBAAPL64 - ok
                    01:34:31.0050 3404 usbccgp (07e3498fc60834219d2356293da0fecc) C:\Windows\system32\DRIVERS\usbccgp.sys
                    01:34:31.0053 3404 usbccgp - ok
                    01:34:31.0077 3404 usbcir (9247f7e0b65852c1f6631480984d6ed2) C:\Windows\system32\drivers\usbcir.sys
                    01:34:31.0080 3404 usbcir - ok
                    01:34:31.0132 3404 usbehci (827e44de934a736ea31e91d353eb126f) C:\Windows\system32\DRIVERS\usbehci.sys
                    01:34:31.0135 3404 usbehci - ok
                    01:34:31.0171 3404 usbhub (bb35cd80a2ececfadc73569b3d70c7d1) C:\Windows\system32\DRIVERS\usbhub.sys
                    01:34:31.0176 3404 usbhub - ok
                    01:34:31.0193 3404 usbohci (eba14ef0c07cec233f1529c698d0d154) C:\Windows\system32\drivers\usbohci.sys
                    01:34:31.0195 3404 usbohci - ok
                    01:34:31.0232 3404 usbprint (28b693b6d31e7b9332c1bdcefef228c1) C:\Windows\system32\DRIVERS\usbprint.sys
                    01:34:31.0234 3404 usbprint - ok
                    01:34:31.0271 3404 USBSTOR (b854c1558fca0c269a38663e8b59b581) C:\Windows\system32\DRIVERS\USBSTOR.SYS
                    01:34:31.0272 3404 USBSTOR - ok
                    01:34:31.0291 3404 usbuhci (b2872cbf9f47316abd0e0c74a1aba507) C:\Windows\system32\DRIVERS\usbuhci.sys
                    01:34:31.0293 3404 usbuhci - ok
                    01:34:31.0331 3404 vga (916b94bcf1e09873fff2d5fb11767bbc) C:\Windows\system32\DRIVERS\vgapnp.sys
                    01:34:31.0333 3404 vga - ok
                    01:34:31.0344 3404 VgaSave (b83ab16b51feda65dd81b8c59d114d63) C:\Windows\System32\drivers\vga.sys
                    01:34:31.0346 3404 VgaSave - ok
                    01:34:31.0364 3404 viaide (8294b6c3fdb6c33f24e150de647ecdaa) C:\Windows\system32\drivers\viaide.sys
                    01:34:31.0366 3404 viaide - ok
                    01:34:31.0392 3404 volmgr (2b7e885ed951519a12c450d24535dfca) C:\Windows\system32\drivers\volmgr.sys
                    01:34:31.0395 3404 volmgr - ok
                    01:34:31.0432 3404 volmgrx (cec5ac15277d75d9e5dec2e1c6eaf877) C:\Windows\system32\drivers\volmgrx.sys
                    01:34:31.0439 3404 volmgrx - ok
                    01:34:31.0477 3404 volsnap (5280aada24ab36b01a84a6424c475c8d) C:\Windows\system32\drivers\volsnap.sys
                    01:34:31.0483 3404 volsnap - ok
                    01:34:31.0507 3404 vsmraid (a68f455ed2673835209318dd61bfbb0e) C:\Windows\system32\drivers\vsmraid.sys
                    01:34:31.0510 3404 vsmraid - ok
                    01:34:31.0553 3404 WacomPen (fef8fe5923fead2cee4dfabfce3393a7) C:\Windows\system32\drivers\wacompen.sys
                    01:34:31.0555 3404 WacomPen - ok
                    01:34:31.0593 3404 Wanarp (b8e7049622300d20ba6d8be0c47c0cfd) C:\Windows\system32\DRIVERS\wanarp.sys
                    01:34:31.0595 3404 Wanarp - ok
                    01:34:31.0601 3404 Wanarpv6 (b8e7049622300d20ba6d8be0c47c0cfd) C:\Windows\system32\DRIVERS\wanarp.sys
                    01:34:31.0603 3404 Wanarpv6 - ok
                    01:34:31.0631 3404 Wd (0c17a0816f65b89e362e682ad5e7266e) C:\Windows\system32\drivers\wd.sys
                    01:34:31.0633 3404 Wd - ok
                    01:34:31.0670 3404 Wdf01000 (d02e7e4567da1e7582fbf6a91144b0df) C:\Windows\system32\drivers\Wdf01000.sys
                    01:34:31.0684 3404 Wdf01000 - ok
                    01:34:31.0756 3404 WmiAcpi (e18aebaaa5a773fe11aa2c70f65320f5) C:\Windows\system32\drivers\wmiacpi.sys
                    01:34:31.0757 3404 WmiAcpi - ok
                    01:34:31.0819 3404 WpdUsb (5e2401b3fc1089c90e081291357371a9) C:\Windows\system32\DRIVERS\wpdusb.sys
                    01:34:31.0820 3404 WpdUsb - ok
                    01:34:31.0845 3404 ws2ifsl (8a900348370e359b6bff6a550e4649e1) C:\Windows\system32\drivers\ws2ifsl.sys
                    01:34:31.0847 3404 ws2ifsl - ok
                    01:34:31.0884 3404 WUDFRd (501a65252617b495c0f1832f908d54d8) C:\Windows\system32\DRIVERS\WUDFRd.sys
                    01:34:31.0887 3404 WUDFRd - ok
                    01:34:31.0901 3404 MBR (0x1B8) (13af81ffe36981a6a5910f5f7a43b4f8) \Device\Harddisk0\DR0
                    01:34:31.0927 3404 \Device\Harddisk0\DR0 ( Rootkit.Win32.TDSS.tdl4 ) - infected
                    01:34:31.0927 3404 \Device\Harddisk0\DR0 - detected Rootkit.Win32.TDSS.tdl4 (0)
                    01:34:31.0931 3404 Boot (0x1200) (83965c4c38da21efa9d7d6b4477be7f4) \Device\Harddisk0\DR0\Partition0
                    01:34:31.0932 3404 \Device\Harddisk0\DR0\Partition0 - ok
                    01:34:31.0945 3404 Boot (0x1200) (addefe7884577aa86d522c961973b52b) \Device\Harddisk0\DR0\Partition1
                    01:34:31.0946 3404 \Device\Harddisk0\DR0\Partition1 - ok
                    01:34:31.0947 3404 ============================================================
                    01:34:31.0947 3404 Scan finished
                    01:34:31.0947 3404 ============================================================
                    01:34:31.0959 4620 Detected object count: 1
                    01:34:31.0959 4620 Actual detected object count: 1
                    01:34:59.0831 4620 \Device\Harddisk0\DR0 ( Rootkit.Win32.TDSS.tdl4 ) - will be cured on reboot
                    01:34:59.0832 4620 \Device\Harddisk0\DR0 - ok
                    01:34:59.0834 4620 \Device\Harddisk0\DR0 ( Rootkit.Win32.TDSS.tdl4 ) - User select action: Cure
                    01:35:06.0592 3980 Deinitialize success
                    • 1
                    • 2