Redirection recherche google

Bonjour, je crée ce post car mes recherches googles sont a chaque fois redirigées (en passant par firefox ou chrome).
Jai bien évidement fait spybot, malwarebyte, regcleaner mais rien n'y fait.
Je post le rapport de combofix si ca peux aider
((((((((((((((((((((((((((((( Fichiers créés du 2012-01-12 au 2012-02-12 ))))))))))))))))))))))))))))))))))))
.
.
2012-02-12 08:36 . 2012-02-12 08:36 -------- d-----w- c:\users\Default\AppData\Local\temp
2012-02-12 08:15 . 2011-06-09 13:32 1658880 ----a-w- c:\program files (x86)\Mozilla Firefox\extensions\websitelogon@truesuite.com\components\FFXPCOM.dll
2012-02-10 14:38 . 2012-02-10 14:38 -------- d-----w- c:\users\Nico\AppData\Roaming\Malwarebytes
2012-02-10 14:38 . 2012-02-10 14:38 -------- d-----w- c:\programdata\Malwarebytes
2012-02-10 14:38 . 2012-02-10 14:38 -------- d-----w- c:\program files (x86)\Malwarebytes' Anti-Malware
2012-02-10 14:38 . 2011-12-10 14:24 23152 ----a-w- c:\windows\system32\drivers\mbam.sys
2012-02-07 20:24 . 2012-02-07 20:24 -------- d-----w- c:\program files (x86)\AxBx
2012-02-07 20:01 . 2012-02-07 20:01 -------- d-----w- c:\users\Nico\AppData\Roaming\SUPERAntiSpyware.com
2012-02-07 20:01 . 2012-02-07 20:01 -------- d-----w- c:\program files\SUPERAntiSpyware
2012-02-07 20:01 . 2012-02-07 20:01 -------- d-----w- c:\programdata\SUPERAntiSpyware.com
2012-02-06 19:26 . 2012-02-06 19:35 -------- d-----w- c:\program files (x86)\RegCleaner
2012-02-06 19:26 . 2012-02-06 19:37 -------- d-----w- c:\program files (x86)\Spybot - Search & Destroy
2012-02-06 19:12 . 1998-10-29 14:45 306688 ----a-w- c:\windows\IsUninst.exe
2012-02-06 19:11 . 2012-02-06 19:35 -------- d-----w- c:\programdata\Spybot - Search & Destroy
2012-02-04 11:15 . 2012-02-04 11:15 122880 --sha-r- c:\windows\SysWow64\msvcrtw.dll
2012-02-03 10:59 . 2012-01-06 05:15 8602168 ----a-w- c:\programdata\Microsoft\Windows Defender\Definition Updates\{AA61307E-5461-4F51-8D72-50BBE6494486}\mpengine.dll
2012-02-02 18:04 . 2012-02-02 18:04 -------- d-----w- c:\programdata\{A8DA1505-E615-42BB-BB77-74D5CC91FE7E}
2012-01-31 07:28 . 2012-01-31 07:28 -------- d-----w- c:\users\Nico\AppData\Local\Adobe
2012-01-31 07:27 . 2012-01-31 07:27 -------- d-----w- c:\program files (x86)\Common Files\Adobe
2012-01-28 20:22 . 2012-01-31 22:10 -------- d-----w- c:\users\Nico\AppData\Roaming\Skype
2012-01-28 20:22 . 2012-01-28 20:28 -------- d-----r- c:\program files (x86)\Skype
2012-01-28 20:22 . 2012-01-28 20:28 -------- d-----w- c:\programdata\Skype
2012-01-26 18:30 . 2012-01-26 18:31 -------- d-----w- c:\users\Nico\AppData\Roaming\Apple Computer
2012-01-26 18:30 . 2012-01-26 18:30 -------- d-----w- c:\users\Nico\AppData\Local\Apple Computer
2012-01-26 18:30 . 2012-01-26 18:30 -------- dc----w- c:\windows\system32\DRVSTORE
2012-01-26 18:30 . 2009-05-18 12:17 34152 ----a-w- c:\windows\system32\drivers\GEARAspiWDM.sys
2012-01-26 18:30 . 2008-04-17 11:12 126312 ----a-w- c:\windows\system32\GEARAspi64.dll
2012-01-26 18:30 . 2008-04-17 11:12 107368 ----a-w- c:\windows\SysWow64\GEARAspi.dll
2012-01-26 18:29 . 2012-01-26 18:30 -------- d-----w- c:\programdata\{93E26451-CD9A-43A5-A2FA-C42392EA4001}
2012-01-26 18:29 . 2012-01-26 18:30 -------- d-----w- c:\program files\iTunes
2012-01-26 18:29 . 2012-01-26 18:30 -------- d-----w- c:\program files (x86)\iTunes
2012-01-26 18:29 . 2012-01-26 18:29 -------- d-----w- c:\programdata\Apple Computer
2012-01-26 18:29 . 2012-01-26 18:29 -------- d-----w- c:\program files\iPod
2012-01-26 18:29 . 2012-01-26 18:29 -------- d-----w- c:\users\Nico\AppData\Local\Apple
2012-01-26 18:29 . 2012-01-26 18:29 -------- d-----w- c:\program files (x86)\Apple Software Update
2012-01-26 18:29 . 2012-01-26 18:29 -------- d-----w- c:\program files\Common Files\Apple
2012-01-26 18:29 . 2012-01-26 18:29 -------- d-----w- c:\program files\Bonjour
2012-01-26 18:29 . 2012-01-26 18:29 -------- d-----w- c:\program files (x86)\Bonjour
2012-01-26 18:29 . 2012-01-26 18:29 -------- d-----w- c:\program files (x86)\Common Files\Apple
2012-01-26 18:29 . 2012-01-26 18:29 -------- d-----w- c:\programdata\Apple
2012-01-26 09:39 . 2012-01-26 09:39 -------- d-----w- c:\windows\Sun
2012-01-23 13:59 . 2012-01-23 13:59 466944 ----a-w- c:\program files (x86)\Mozilla Firefox\plugins\NPcol400.dll
2012-01-23 13:59 . 2012-01-23 13:59 -------- d-----w- c:\users\Nico\AppData\Roaming\Catalina Marketing France
2012-01-23 13:59 . 2012-01-23 13:59 497880 ----a-w- c:\users\Nico\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Catalina Marketing France\UninstallCouponActivator.exe
2012-01-21 14:35 . 2012-01-21 14:35 -------- d-----w- c:\program files (x86)\Common Files\Java
2012-01-18 17:12 . 2012-01-18 17:12 -------- d-----w- c:\users\Nico\AppData\Roaming\OpenOffice.org
2012-01-18 17:10 . 2012-01-18 17:10 -------- d-----w- c:\program files (x86)\OpenOffice.org 3
2012-01-18 17:10 . 2011-11-10 04:54 472808 ----a-w- c:\windows\SysWow64\deployJava1.dll
2012-01-18 17:10 . 2012-01-21 14:35 -------- d-----w- c:\program files (x86)\Java
2012-01-16 14:22 . 2011-04-11 18:05 23552 ----a-w- c:\windows\system32\vsmon1.dll
2012-01-16 14:21 . 2012-01-16 14:21 -------- d-----w- c:\program files (x86)\Avanquest update
2012-01-16 14:20 . 2012-01-16 16:47 -------- d-----w- c:\users\Nico\AppData\Roaming\Expert PDF 7
2012-01-16 14:20 . 2012-01-16 14:20 -------- d-----w- c:\programdata\Avanquest Software
2012-01-16 14:20 . 2012-01-16 14:21 -------- d-----w- c:\programdata\Avanquest
2012-01-16 14:20 . 2012-01-16 14:20 -------- d-----w- c:\programdata\Expert PDF Jobs
2012-01-16 14:20 . 2012-01-16 14:20 -------- d-----w- c:\programdata\Expert PDF 7
2012-01-16 14:20 . 2012-01-16 14:20 -------- d-----w- c:\program files (x86)\Avanquest
.
.
.
(((((((((((((((((((((((((((((((((( Compte-rendu de Find3M ))))))))))))))))))))))))))))))))))))))))))))))))
.
2012-01-26 23:52 . 2010-11-21 03:27 279656 ------w- c:\windows\system32\MpSigStub.exe
2011-12-20 13:36 . 2011-11-25 14:16 414368 ----a-w- c:\windows\SysWow64\FlashPlayerCPLApp.cpl
2011-12-20 12:46 . 2010-06-24 19:33 18328 ----a-w- c:\programdata\Microsoft\IdentityCRL\production\ppcrlconfig600.dll
2011-11-25 14:22 . 2011-11-25 14:22 31152 ----a-w- c:\windows\system32\drivers\pmxdrv.sys
2011-11-25 14:15 . 2011-11-25 14:15 97792 ----a-w- c:\windows\SysWow64\vcljpg70.bpl
2011-11-25 14:15 . 2011-11-25 14:15 778240 ----a-w- c:\windows\SysWow64\rtl70.bpl
2011-11-25 14:15 . 2011-11-25 14:15 64512 ----a-w- c:\windows\SysWow64\vclsmp70.bpl
2011-11-25 14:15 . 2011-11-25 14:15 52920 ----a-w- c:\windows\SysWow64\ezUPBHook.dll
2011-11-25 14:15 . 2011-11-25 14:15 319872 ----a-w- c:\windows\SysWow64\ezseng.exe
2011-11-25 14:15 . 2011-11-25 14:15 215040 ----a-w- c:\windows\SysWow64\vclx70.bpl
2011-11-25 14:15 . 2011-11-25 14:15 19640 ----a-w- c:\windows\SysWow64\ezMAPIHelper.exe
2011-11-25 14:15 . 2011-11-25 14:15 145592 ----a-w- c:\windows\SysWow64\ezShellStart.exe
2011-11-25 14:15 . 2011-11-25 14:15 1381376 ----a-w- c:\windows\SysWow64\vcl70.bpl
2011-11-25 14:15 . 2011-11-25 14:15 121016 ----a-w- c:\windows\SysWow64\ezUninst.exe
2011-11-25 14:01 . 2011-11-25 14:01 96768 ----a-w- c:\windows\system32\fsutil.exe
2011-11-25 14:01 . 2011-11-25 14:01 74240 ----a-w- c:\windows\SysWow64\fsutil.exe
2011-11-25 14:01 . 2011-11-25 14:01 410496 ----a-w- c:\windows\system32\drivers\iaStorV.sys
2011-11-25 14:01 . 2011-11-25 14:01 27008 ----a-w- c:\windows\system32\drivers\amdxata.sys
2011-11-25 14:01 . 2011-11-25 14:01 2565632 ----a-w- c:\windows\system32\esent.dll
2011-11-25 14:01 . 2011-11-25 14:01 189824 ----a-w- c:\windows\system32\drivers\storport.sys
2011-11-25 14:01 . 2011-11-25 14:01 1699328 ----a-w- c:\windows\SysWow64\esent.dll
2011-11-25 14:01 . 2011-11-25 14:01 166272 ----a-w- c:\windows\system32\drivers\nvstor.sys
2011-11-25 14:01 . 2011-11-25 14:01 1659776 ----a-w- c:\windows\system32\drivers\ntfs.sys
2011-11-25 14:01 . 2011-11-25 14:01 148352 ----a-w- c:\windows\system32\drivers\nvraid.sys
2011-11-25 14:01 . 2011-11-25 14:01 107904 ----a-w- c:\windows\system32\drivers\amdsata.sys
2011-11-25 14:01 . 2011-11-25 14:01 976896 ----a-w- c:\windows\system32\inetcomm.dll
2011-11-25 14:01 . 2011-11-25 14:01 741376 ----a-w- c:\windows\SysWow64\inetcomm.dll
2011-11-25 14:00 . 2011-11-25 14:00 27520 ----a-w- c:\windows\system32\drivers\Diskdump.sys
2011-11-25 14:00 . 2011-11-25 14:00 158208 ----a-w- c:\windows\system32\drivers\mrxsmb.sys
2011-11-25 14:00 . 2011-11-25 14:00 128000 ----a-w- c:\windows\system32\drivers\mrxsmb20.sys
2011-11-25 14:00 . 2011-11-25 14:00 467456 ----a-w- c:\windows\system32\drivers\srv.sys
2011-11-25 14:00 . 2011-11-25 14:00 410112 ----a-w- c:\windows\system32\drivers\srv2.sys
2011-11-25 14:00 . 2011-11-25 14:00 168448 ----a-w- c:\windows\system32\drivers\srvnet.sys
2011-11-25 13:59 . 2011-11-25 13:59 98816 ----a-w- c:\windows\system32\drivers\usbccgp.sys
2011-11-25 13:59 . 2011-11-25 13:59 7936 ----a-w- c:\windows\system32\drivers\usbd.sys
2011-11-25 13:59 . 2011-11-25 13:59 52736 ----a-w- c:\windows\system32\drivers\usbehci.sys
2011-11-25 13:59 . 2011-11-25 13:59 343040 ----a-w- c:\windows\system32\drivers\usbhub.sys
2011-11-25 13:59 . 2011-11-25 13:59 325120 ----a-w- c:\windows\system32\drivers\usbport.sys
2011-11-25 13:59 . 2011-11-25 13:59 30720 ----a-w- c:\windows\system32\drivers\usbuhci.sys
2011-11-25 13:59 . 2011-11-25 13:59 25600 ----a-w- c:\windows\system32\drivers\usbohci.sys
2011-11-25 13:59 . 2011-11-25 13:59 2871808 ----a-w- c:\windows\explorer.exe
2011-11-25 13:59 . 2011-11-25 13:59 2616320 ----a-w- c:\windows\SysWow64\explorer.exe
2011-11-25 13:58 . 2011-11-25 13:58 476160 ----a-w- c:\windows\system32\XpsGdiConverter.dll
2011-11-25 13:58 . 2011-11-25 13:58 288256 ----a-w- c:\windows\SysWow64\XpsGdiConverter.dll
2011-11-25 13:58 . 2011-11-25 13:58 30208 ----a-w- c:\windows\system32\dnscacheugc.exe
2011-11-25 13:58 . 2011-11-25 13:58 28672 ----a-w- c:\windows\SysWow64\dnscacheugc.exe
2011-11-25 13:58 . 2011-11-25 13:58 183296 ----a-w- c:\windows\system32\dnsrslvr.dll
2011-11-25 13:58 . 2011-11-25 13:58 46080 ----a-w- c:\windows\system32\atmlib.dll
2011-11-25 13:58 . 2011-11-25 13:58 367616 ----a-w- c:\windows\system32\atmfd.dll
2011-11-25 13:58 . 2011-11-25 13:58 34304 ----a-w- c:\windows\SysWow64\atmlib.dll
2011-11-25 13:58 . 2011-11-25 13:58 294912 ----a-w- c:\windows\SysWow64\atmfd.dll
2011-11-25 13:57 . 2011-11-25 13:57 31232 ----a-w- c:\windows\SysWow64\prevhost.exe
2011-11-25 13:57 . 2011-11-25 13:57 31232 ----a-w- c:\windows\system32\prevhost.exe
2011-11-25 13:57 . 2011-11-25 13:57 1395712 ----a-w- c:\windows\system32\mfc42.dll
2011-11-25 13:57 . 2011-11-25 13:57 1359872 ----a-w- c:\windows\system32\mfc42u.dll
2011-11-25 13:57 . 2011-11-25 13:57 1164288 ----a-w- c:\windows\SysWow64\mfc42u.dll
2011-11-25 13:57 . 2011-11-25 13:57 1137664 ----a-w- c:\windows\SysWow64\mfc42.dll
2011-11-25 13:57 . 2011-11-25 13:57 642944 ----a-w- c:\windows\system32\winload.efi
2011-11-25 13:57 . 2011-11-25 13:57 605552 ----a-w- c:\windows\system32\winload.exe
2011-11-25 13:57 . 2011-11-25 13:57 566208 ----a-w- c:\windows\system32\winresume.efi
2011-11-25 13:57 . 2011-11-25 13:57 518672 ----a-w- c:\windows\system32\winresume.exe
2011-11-25 13:57 . 2011-11-25 13:57 20352 ----a-w- c:\windows\system32\kdusb.dll
2011-11-25 13:57 . 2011-11-25 13:57 19328 ----a-w- c:\windows\system32\kd1394.dll
2011-11-25 13:57 . 2011-11-25 13:57 17792 ----a-w- c:\windows\system32\kdcom.dll
2011-11-25 13:57 . 2011-11-25 13:57 296320 ----a-w- c:\windows\system32\drivers\volsnap.sys
2011-11-25 13:57 . 2011-11-25 13:57 902656 ----a-w- c:\windows\system32\d2d1.dll
2011-11-25 13:57 . 2011-11-25 13:57 739840 ----a-w- c:\windows\SysWow64\d2d1.dll
2011-11-25 13:57 . 2011-11-25 13:57 1544192 ----a-w- c:\windows\system32\DWrite.dll
2011-11-25 13:57 . 2011-11-25 13:57 1139200 ----a-w- c:\windows\system32\FntCache.dll
2011-11-25 13:57 . 2011-11-25 13:57 1076736 ----a-w- c:\windows\SysWow64\DWrite.dll
2011-11-25 13:56 . 2011-11-25 13:56 499200 ----a-w- c:\windows\system32\drivers\afd.sys
2011-11-25 13:56 . 2011-11-25 13:56 800256 ----a-w- c:\windows\system32\usp10.dll
2011-11-25 13:56 . 2011-11-25 13:56 7680 ----a-w- c:\windows\system32\KBDINTAM.DLL
2011-11-25 13:56 . 2011-11-25 13:56 7680 ----a-w- c:\windows\system32\KBDINMAL.DLL
2011-11-25 13:56 . 2011-11-25 13:56 7680 ----a-w- c:\windows\system32\KBDINDEV.DLL
2011-11-25 13:56 . 2011-11-25 13:56 7680 ----a-w- c:\windows\system32\KBDINBEN.DLL
2011-11-25 13:56 . 2011-11-25 13:56 7168 ----a-w- c:\windows\SysWow64\KBDINTAM.DLL
2011-11-25 13:56 . 2011-11-25 13:56 7168 ----a-w- c:\windows\SysWow64\KBDINORI.DLL
2011-11-25 13:56 . 2011-11-25 13:56 7168 ----a-w- c:\windows\SysWow64\KBDINMAR.DLL
2011-11-25 13:56 . 2011-11-25 13:56 7168 ----a-w- c:\windows\SysWow64\KBDINMAL.DLL
2011-11-25 13:56 . 2011-11-25 13:56 7168 ----a-w- c:\windows\SysWow64\KBDINKAN.DLL
2011-11-25 13:56 . 2011-11-25 13:56 7168 ----a-w- c:\windows\SysWow64\KBDINHIN.DLL
2011-11-25 13:56 . 2011-11-25 13:56 7168 ----a-w- c:\windows\SysWow64\KBDINDEV.DLL
2011-11-25 13:56 . 2011-11-25 13:56 7168 ----a-w- c:\windows\SysWow64\KBDINBEN.DLL
2011-11-25 13:56 . 2011-11-25 13:56 7168 ----a-w- c:\windows\system32\KBDINTEL.DLL
2011-11-25 13:56 . 2011-11-25 13:56 7168 ----a-w- c:\windows\system32\KBDINPUN.DLL
2011-11-25 13:56 . 2011-11-25 13:56 7168 ----a-w- c:\windows\system32\KBDINORI.DLL
2011-11-25 13:56 . 2011-11-25 13:56 7168 ----a-w- c:\windows\system32\KBDINMAR.DLL
2011-11-25 13:56 . 2011-11-25 13:56 7168 ----a-w- c:\windows\system32\KBDINKAN.DLL
2011-11-25 13:56 . 2011-11-25 13:56 7168 ----a-w- c:\windows\system32\KBDINHIN.DLL
2011-11-25 13:56 . 2011-11-25 13:56 7168 ----a-w- c:\windows\system32\KBDINGUJ.DLL
2011-11-25 13:56 . 2011-11-25 13:56 7168 ----a-w- c:\windows\system32\KBDINEN.DLL
2011-11-25 13:56 . 2011-11-25 13:56 7168 ----a-w- c:\windows\system32\KBDINBE2.DLL
2011-11-25 13:56 . 2011-11-25 13:56 7168 ----a-w- c:\windows\system32\KBDINBE1.DLL
2011-11-25 13:56 . 2011-11-25 13:56 7168 ----a-w- c:\windows\system32\KBDINASA.DLL
2011-11-25 13:56 . 2011-11-25 13:56 6656 ----a-w- c:\windows\SysWow64\KBDINTEL.DLL
2011-11-25 13:56 . 2011-11-25 13:56 6656 ----a-w- c:\windows\SysWow64\KBDINPUN.DLL
2011-11-25 13:56 . 2011-11-25 13:56 6656 ----a-w- c:\windows\SysWow64\KBDINGUJ.DLL
2011-11-25 13:56 . 2011-11-25 13:56 6656 ----a-w- c:\windows\SysWow64\KBDINBE2.DLL
2011-11-25 13:56 . 2011-11-25 13:56 6656 ----a-w- c:\windows\SysWow64\KBDINBE1.DLL
.
.
((((((((((((((((((((((((((((((((( Points de chargement Reg ))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* les éléments vides & les éléments initiaux légitimes ne sont pas listés
REGEDIT4
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run]
"StartCCC"="c:\program files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" [2011-06-01 336384]
"HP Software Update"="c:\program files (x86)\HP\HP Software Update\HPWuSchd2.exe" [2008-12-08 54576]
"LaunchHPOSIAPP"="c:\program files (x86)\Hewlett-Packard\HP Keyboard\LaunchApp.exe" [2009-04-04 385024]
"Easybits Recovery"="c:\program files (x86)\EasyBits For Kids\ezRecover.exe" [2011-05-17 61112]
"PDF Complete"="c:\program files (x86)\PDF Complete\pdfsty.exe" [2011-05-06 658424]
"vspdfprsrv.exe"="c:\program files (x86)\Avanquest\Expert PDF 7 Professional\vspdfprsrv.exe" [2011-08-26 4566016]
"SunJavaUpdateSched"="c:\program files (x86)\Common Files\Java\Java Update\jusched.exe" [2011-06-09 254696]
"APSDaemon"="c:\program files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe" [2011-11-01 59240]
"iTunesHelper"="c:\program files (x86)\iTunes\iTunesHelper.exe" [2012-01-16 421736]
"Adobe ARM"="c:\program files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2012-01-03 843712]
.
c:\users\Nico\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\
OpenOffice.org 3.3.lnk - c:\program files (x86)\OpenOffice.org 3\program\quickstart.exe [2010-12-13 1198592]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"ConsentPromptBehaviorAdmin"= 0 (0x0)
"ConsentPromptBehaviorUser"= 3 (0x3)
"EnableLUA"= 0 (0x0)
"EnableUIADesktopToggle"= 0 (0x0)
"PromptOnSecureDesktop"= 0 (0x0)
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\explorer]
"EnableShellExecuteHooks"= 1 (0x1)
.
[hkey_local_machine\software\Wow6432Node\microsoft\windows\currentversion\explorer\ShellExecuteHooks]
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows nt\currentversion\drivers32]
"aux"=wdmaud.drv
.
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\session manager]
BootExecute REG_MULTI_SZ autocheck autochk *\0\0sdnclean64.exe
.
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\lsa]
Security Packages REG_MULTI_SZ kerberos msv1_0 schannel wdigest tspkg pku2u livessp
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\!SASCORE]
@=""
.
R2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;c:\windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-03-18 130384]
R2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;c:\windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [2010-03-18 138576]
R2 cvhsvc;Client Virtualization Handler;c:\program files (x86)\Common Files\Microsoft Shared\Virtualization Handler\CVHSVC.EXE [2010-10-20 821664]
R2 gupdate;Service Google Update (gupdate);c:\program files (x86)\Google\Update\GoogleUpdate.exe [2012-01-10 136176]
R2 HP Support Assistant Service;HP Support Assistant Service;c:\program files (x86)\Hewlett-Packard\HP Support Framework\hpsa_service.exe [2011-09-09 86072]
R2 sftlist;Application Virtualization Client;c:\program files (x86)\Microsoft Application Virtualization Client\sftlist.exe [2010-09-14 508264]
R2 UNS;Intel(R) Management and Security Application User Notification Service;c:\program files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe [2011-02-01 2656280]
R3 BBSvc;Bing Bar Update Service;c:\program files (x86)\Microsoft\BingBar\BBSvc.EXE [2011-03-02 183560]
R3 GamesAppService;GamesAppService;c:\program files (x86)\WildTangent Games\App\GamesAppService.exe [2010-10-12 206072]
R3 gupdatem;Service Google Update (gupdatem);c:\program files (x86)\Google\Update\GoogleUpdate.exe [2012-01-10 136176]
R3 osppsvc;Office Software Protection Platform;c:\program files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPSVC.EXE [2010-01-09 4925184]
R3 pmxdrv;pmxdrv;c:\windows\system32\drivers\pmxdrv.sys [x]
R3 Sftredir;Sftredir;c:\windows\system32\DRIVERS\Sftredirlh.sys [x]
R3 TsUsbFlt;TsUsbFlt;c:\windows\system32\drivers\tsusbflt.sys [x]
R3 TsUsbGD;Remote Desktop Generic USB Device;c:\windows\system32\drivers\TsUsbGD.sys [x]
R3 USBAAPL64;Apple Mobile USB Driver;c:\windows\system32\Drivers\usbaapl64.sys [x]
R3 WatAdminSvc;Service Windows Activation Technologies;c:\windows\system32\Wat\WatAdminSvc.exe [x]
R4 wlcrasvc;Windows Live Mesh remote connections service;c:\program files\Windows Live\Mesh\wlcrasvc.exe [2010-09-23 57184]
S1 SASDIFSV;SASDIFSV;c:\program files\SUPERAntiSpyware\SASDIFSV64.SYS [2011-07-22 14928]
S1 SASKUTIL;SASKUTIL;c:\program files\SUPERAntiSpyware\SASKUTIL64.SYS [2011-07-12 12368]
S1 vwififlt;Virtual WiFi Filter Driver;c:\windows\system32\DRIVERS\vwififlt.sys [x]
S2 !SASCORE;SAS Core Service;c:\program files\SUPERAntiSpyware\SASCORE64.EXE [2011-08-11 140672]
S2 AdobeARMservice;Adobe Acrobat Update Service;c:\program files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe [2012-01-03 63928]
S2 AESTFilters;Andrea ST Filters Service;c:\program files\IDT\WDM\AESTSr64.exe [2009-03-03 89600]
S2 AMD External Events Utility;AMD External Events Utility;c:\windows\system32\atiesrxx.exe [x]
S2 FPLService;TrueSuiteService;c:\program files (x86)\HP SimplePass 2011\TrueSuiteService.exe [2011-06-09 264008]
S2 HPAuto;HP Auto;c:\program files\Hewlett-Packard\HP Auto\HPAuto.exe [2011-02-17 682040]
S2 HPClientSvc;HP Client Services;c:\program files\Hewlett-Packard\HP Client Services\HPClientServices.exe [2010-10-11 346168]
S2 HPDrvMntSvc.exe;HP Quick Synchronization Service;c:\program files (x86)\Hewlett-Packard\Shared\HPDrvMntSvc.exe [2011-03-28 94264]
S2 jhi_service;Intel(R) Identity Protection Technology Host Interface Service;c:\program files (x86)\Intel\Services\IPT\jhi_service.exe [2011-02-24 212944]
S2 pdfcDispatcher;PDF Document Manager;c:\program files (x86)\PDF Complete\pdfsvc.exe [2011-05-06 1128952]
S3 amdkmdag;amdkmdag;c:\windows\system32\DRIVERS\atikmdag.sys [x]
S3 amdkmdap;amdkmdap;c:\windows\system32\DRIVERS\atikmpag.sys [x]
S3 AtiHDAudioService;ATI Function Driver for HD Audio Service;c:\windows\system32\drivers\AtihdW76.sys [x]
S3 MEIx64;Intel(R) Management Engine Interface;c:\windows\system32\drivers\HECIx64.sys [x]
S3 netr28x;Ralink 802.11n Extensible Wireless Driver;c:\windows\system32\DRIVERS\netr28x.sys [x]
S3 RTL8167;Realtek 8167 NT Driver;c:\windows\system32\DRIVERS\Rt64win7.sys [x]
S3 Sftfs;Sftfs;c:\windows\system32\DRIVERS\Sftfslh.sys [x]
S3 Sftplay;Sftplay;c:\windows\system32\DRIVERS\Sftplaylh.sys [x]
S3 Sftvol;Sftvol;c:\windows\system32\DRIVERS\Sftvollh.sys [x]
S3 sftvsa;Application Virtualization Service Agent;c:\program files (x86)\Microsoft Application Virtualization Client\sftvsa.exe [2010-09-14 219496]
S3 tihub3;TI USB3 Hub Service;c:\windows\system32\drivers\tihub3.sys [x]
S3 tixhci;TI XHCI Service;c:\windows\system32\drivers\tixhci.sys [x]
.
.
--- Autres Services/Pilotes en mémoire ---
.
*NewlyCreated* - WS2IFSL
.
Contenu du dossier 'Tâches planifiées'
.
2012-02-12 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\program files (x86)\Google\Update\GoogleUpdate.exe [2012-01-10 18:01]
.
2012-02-11 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\program files (x86)\Google\Update\GoogleUpdate.exe [2012-01-10 18:01]
.
2012-02-12 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-105630479-56183005-2524406978-1000Core.job
- c:\users\Nico\AppData\Local\Google\Update\GoogleUpdate.exe [2012-02-12 08:17]
.
2012-02-12 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-105630479-56183005-2524406978-1000UA.job
- c:\users\Nico\AppData\Local\Google\Update\GoogleUpdate.exe [2012-02-12 08:17]
.
2012-02-08 c:\windows\Tasks\HPCeeScheduleForNico.job
- c:\program files (x86)\Hewlett-Packard\HP Ceement\HPCEE.exe [2010-09-14 06:15]
.
2012-02-12 c:\windows\Tasks\thgbhtyjvj.job
- c:\windows\system32\rundll32.exe [2009-07-13 01:14]
.
.
--------- x86-64 -----------
.
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"BeatsOSDApp"="c:\program files\IDT\WDM\beats64.exe" [2010-10-21 37888]
"SysTrayApp"="c:\program files\IDT\WDM\sttray64.exe" [2011-06-10 1128448]
"hpsysdrv"="c:\program files (x86)\hewlett-packard\HP odometer\hpsysdrv.exe" [2008-11-20 62768]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows]
"LoadAppInit_DLLs"=0x0
.
------- Examen supplémentaire -------
.
uLocal Page = c:\windows\system32\blank.htm
mLocal Page = c:\windows\SysWOW64\blank.htm
uInternet Settings,ProxyOverride = *.local
TCP: DhcpNameServer = 192.168.1.1
FF - ProfilePath - c:\users\Nico\AppData\Roaming\Mozilla\Firefox\Profiles\tap07plx.default\
FF - prefs.js: browser.startup.homepage - hxxp://www.google.fr
.
- - - - ORPHELINS SUPPRIMES - - - -
.
AddRemove-EasyBits Magic Desktop - c:\windows\system32\ezMDUninstall.exe
AddRemove-{6F44AF95-3CDE-4513-AD3F-6D45F17BF324} - c:\program files (x86)\InstallShield Installation Information\{6F44AF95-3CDE-4513-AD3F-6D45F17BF324}\setup.exe
.
.
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\pdfcDispatcher]
"ImagePath"="c:\program files (x86)\PDF Complete\pdfsvc.exe /startedbyscm:66B66708-40E2BE4D-pdfcService"
.
--------------------- CLES DE REGISTRE BLOQUEES ---------------------
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}]
@Denied: (A 2) (Everyone)
@="FlashBroker"
"LocalizedString"="@c:\\Windows\\SysWOW64\\Macromed\\Flash\\FlashUtil10q_ActiveX.exe,-101"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\Elevation]
"Enabled"=dword:00000001
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\LocalServer32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\FlashUtil10q_ActiveX.exe"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}]
@Denied: (A 2) (Everyone)
@="Shockwave Flash Object"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\InprocServer32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash10q.ocx"
"ThreadingModel"="Apartment"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\MiscStatus]
@="0"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ProgID]
@="ShockwaveFlash.ShockwaveFlash.10"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash10q.ocx, 1"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\TypeLib]
@="{D27CDB6B-AE6D-11cf-96B8-444553540000}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\Version]
@="1.0"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID]
@="ShockwaveFlash.ShockwaveFlash"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}]
@Denied: (A 2) (Everyone)
@="Macromedia Flash Factory Object"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\InprocServer32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash10q.ocx"
"ThreadingModel"="Apartment"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ProgID]
@="FlashFactory.FlashFactory.1"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash10q.ocx, 1"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\TypeLib]
@="{D27CDB6B-AE6D-11cf-96B8-444553540000}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\Version]
@="1.0"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID]
@="FlashFactory.FlashFactory"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}]
@Denied: (A 2) (Everyone)
@="IFlashBroker4"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}\ProxyStubClsid32]
@="{00020424-0000-0000-C000-000000000046}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
"Version"="1.0"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\PCW\Security]
@Denied: (Full) (Everyone)
.
------------------------ Autres processus actifs ------------------------
.
c:\windows\SysWOW64\rundll32.exe
c:\program files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
c:\program files (x86)\Hewlett-Packard\HP Keyboard\ModLEDKey.exe
c:\windows\SysWOW64\ezSharedSvcHost.exe
c:\program files (x86)\Microsoft\BingBar\SeaPort.EXE
c:\program files (x86)\OpenOffice.org 3\program\soffice.exe
c:\program files (x86)\OpenOffice.org 3\program\soffice.bin
c:\program files (x86)\Hewlett-Packard\HP Keyboard\CNYHKEY.exe
c:\program files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe
.
**************************************************************************
.
Heure de fin: 2012-02-12 09:40:34 - La machine a redémarré
ComboFix-quarantined-files.txt 2012-02-12 08:40
.
Avant-CF: 900 965 507 072 octets libres
Après-CF: 900 778 287 104 octets libres
.
- - End Of File - - CA6436F6E31F28EB0EAD7D62755129B1

29 réponses

Résumé de la discussion

La discussion porte sur des redirections des recherches Google provoquées par une infection malveillante affectant Firefox et Chrome, avec un rapport de détection et de nettoyage. Plusieurs outils de sécurité ont été testés, notamment Spybot, Malwarebytes et RegCleaner, puis ComboFix, et des listes détaillant les éléments et programmes suspects aident à identifier l'origine des redirections. L'ensemble des extraits de journaux montre des emplacements et extensions suspectes, ainsi que des entrées de démarrage et des composants Windows susceptibles d'être liés à l'infection. Certaines indications évoquent la suppression d'extensions malveillantes et le nettoyage des éléments de démarrage, avant éventuellement une réinitialisation ou une restauration système pour stabiliser la navigation.

Bobot (l’IA à votre service)
  1. essaie de les désinstaller un par un et voir d'ou vient le problème !

    0
    1. Tu veux que je liste ceux de Firefox ? Les autres navigateurs j'utilise jamais alors ça devrait pas venir de là non ?
      0
      1. il y a peut être un plugin d'un navigateur !

        reste à voir le quel !

        0
        1. 17:56:20.0804 4568 TDSS rootkit removing tool 2.7.11.0 Feb 9 2012 10:12:57
          17:56:20.0961 4568 ============================================================
          17:56:20.0961 4568 Current date / time: 2012/02/12 17:56:20.0961
          17:56:20.0961 4568 SystemInfo:
          17:56:20.0961 4568
          17:56:20.0961 4568 OS Version: 6.1.7601 ServicePack: 1.0
          17:56:20.0961 4568 Product type: Workstation
          17:56:20.0961 4568 ComputerName: NICO-HP
          17:56:20.0961 4568 UserName: Nico
          17:56:20.0961 4568 Windows directory: C:\Windows
          17:56:20.0961 4568 System windows directory: C:\Windows
          17:56:20.0961 4568 Running under WOW64
          17:56:20.0961 4568 Processor architecture: Intel x64
          17:56:20.0961 4568 Number of processors: 4
          17:56:20.0961 4568 Page size: 0x1000
          17:56:20.0961 4568 Boot type: Normal boot
          17:56:20.0961 4568 ============================================================
          17:56:21.0581 4568 Drive \Device\Harddisk0\DR0 - Size: 0xE8E0DB6000 (931.51 Gb), SectorSize: 0x200, Cylinders: 0x1DB01, SectorsPerTrack: 0x3F, TracksPerCylinder: 0xFF, Type 'K0', Flags 0x00000040
          17:56:21.0583 4568 Drive \Device\Harddisk1\DR1 - Size: 0x15D50D00000 (1397.26 Gb), SectorSize: 0x200, Cylinders: 0x2C881, SectorsPerTrack: 0x3F, TracksPerCylinder: 0xFF, Type 'W'
          17:56:21.0584 4568 Drive \Device\Harddisk2\DR2 - Size: 0xF080000 (0.23 Gb), SectorSize: 0x200, Cylinders: 0x1E, SectorsPerTrack: 0x3F, TracksPerCylinder: 0xFF, Type 'W'
          17:56:21.0595 4568 \Device\Harddisk0\DR0:
          17:56:21.0596 4568 MBR used
          17:56:21.0596 4568 \Device\Harddisk0\DR0\Partition0: MBR, Type 0x7, StartLBA 0x800, BlocksNum 0x32000
          17:56:21.0596 4568 \Device\Harddisk0\DR0\Partition1: MBR, Type 0x7, StartLBA 0x32800, BlocksNum 0x72D53800
          17:56:21.0596 4568 \Device\Harddisk0\DR0\Partition2: MBR, Type 0x7, StartLBA 0x72D86000, BlocksNum 0x1980000
          17:56:21.0596 4568 \Device\Harddisk1\DR1:
          17:56:21.0596 4568 MBR used
          17:56:21.0596 4568 \Device\Harddisk1\DR1\Partition0: MBR, Type 0x7, StartLBA 0x800, BlocksNum 0xAEA86000
          17:56:21.0596 4568 \Device\Harddisk2\DR2:
          17:56:21.0597 4568 MBR used
          17:56:21.0597 4568 \Device\Harddisk2\DR2\Partition0: MBR, Type 0xE, StartLBA 0x10, BlocksNum 0x783F0
          17:56:21.0733 4568 Initialize success
          17:56:21.0733 4568 ============================================================
          17:56:28.0919 4840 ============================================================
          17:56:28.0919 4840 Scan started
          17:56:28.0919 4840 Mode: Manual;
          17:56:28.0919 4840 ============================================================
          17:56:30.0093 4840 1394ohci (a87d604aea360176311474c87a63bb88) C:\Windows\system32\drivers\1394ohci.sys
          17:56:30.0096 4840 1394ohci - ok
          17:56:30.0128 4840 ACPI (d81d9e70b8a6dd14d42d7b4efa65d5f2) C:\Windows\system32\drivers\ACPI.sys
          17:56:30.0131 4840 ACPI - ok
          17:56:30.0162 4840 AcpiPmi (99f8e788246d495ce3794d7e7821d2ca) C:\Windows\system32\drivers\acpipmi.sys
          17:56:30.0164 4840 AcpiPmi - ok
          17:56:30.0242 4840 adp94xx (2f6b34b83843f0c5118b63ac634f5bf4) C:\Windows\system32\drivers\adp94xx.sys
          17:56:30.0246 4840 adp94xx - ok
          17:56:30.0287 4840 adpahci (597f78224ee9224ea1a13d6350ced962) C:\Windows\system32\drivers\adpahci.sys
          17:56:30.0291 4840 adpahci - ok
          17:56:30.0307 4840 adpu320 (e109549c90f62fb570b9540c4b148e54) C:\Windows\system32\drivers\adpu320.sys
          17:56:30.0310 4840 adpu320 - ok
          17:56:30.0365 4840 AFD (d5b031c308a409a0a576bff4cf083d30) C:\Windows\system32\drivers\afd.sys
          17:56:30.0367 4840 AFD - ok
          17:56:30.0478 4840 agp440 (608c14dba7299d8cb6ed035a68a15799) C:\Windows\system32\drivers\agp440.sys
          17:56:30.0479 4840 agp440 - ok
          17:56:30.0531 4840 aliide (5812713a477a3ad7363c7438ca2ee038) C:\Windows\system32\drivers\aliide.sys
          17:56:30.0532 4840 aliide - ok
          17:56:30.0564 4840 amdide (1ff8b4431c353ce385c875f194924c0c) C:\Windows\system32\drivers\amdide.sys
          17:56:30.0565 4840 amdide - ok
          17:56:30.0584 4840 AmdK8 (7024f087cff1833a806193ef9d22cda9) C:\Windows\system32\drivers\amdk8.sys
          17:56:30.0585 4840 AmdK8 - ok
          17:56:30.0702 4840 amdkmdag (250d5b746fff9b7d88591ee60b63b3e4) C:\Windows\system32\DRIVERS\atikmdag.sys
          17:56:30.0769 4840 amdkmdag - ok
          17:56:30.0866 4840 amdkmdap (781daec0c3e63950cca53d193582f2e8) C:\Windows\system32\DRIVERS\atikmpag.sys
          17:56:30.0867 4840 amdkmdap - ok
          17:56:30.0897 4840 AmdPPM (1e56388b3fe0d031c44144eb8c4d6217) C:\Windows\system32\drivers\amdppm.sys
          17:56:30.0899 4840 AmdPPM - ok
          17:56:30.0924 4840 amdsata (d4121ae6d0c0e7e13aa221aa57ef2d49) C:\Windows\system32\drivers\amdsata.sys
          17:56:30.0925 4840 amdsata - ok
          17:56:30.0950 4840 amdsbs (f67f933e79241ed32ff46a4f29b5120b) C:\Windows\system32\drivers\amdsbs.sys
          17:56:30.0952 4840 amdsbs - ok
          17:56:30.0969 4840 amdxata (540daf1cea6094886d72126fd7c33048) C:\Windows\system32\drivers\amdxata.sys
          17:56:30.0970 4840 amdxata - ok
          17:56:31.0028 4840 AppID (89a69c3f2f319b43379399547526d952) C:\Windows\system32\drivers\appid.sys
          17:56:31.0029 4840 AppID - ok
          17:56:31.0084 4840 arc (c484f8ceb1717c540242531db7845c4e) C:\Windows\system32\drivers\arc.sys
          17:56:31.0085 4840 arc - ok
          17:56:31.0107 4840 arcsas (019af6924aefe7839f61c830227fe79c) C:\Windows\system32\drivers\arcsas.sys
          17:56:31.0109 4840 arcsas - ok
          17:56:31.0138 4840 AsyncMac (769765ce2cc62867468cea93969b2242) C:\Windows\system32\DRIVERS\asyncmac.sys
          17:56:31.0139 4840 AsyncMac - ok
          17:56:31.0172 4840 atapi (02062c0b390b7729edc9e69c680a6f3c) C:\Windows\system32\drivers\atapi.sys
          17:56:31.0172 4840 atapi - ok
          17:56:31.0199 4840 AtiHDAudioService (cbd14f698def12ee3557604b726cb8eb) C:\Windows\system32\drivers\AtihdW76.sys
          17:56:31.0200 4840 AtiHDAudioService - ok
          17:56:31.0246 4840 b06bdrv (3e5b191307609f7514148c6832bb0842) C:\Windows\system32\drivers\bxvbda.sys
          17:56:31.0250 4840 b06bdrv - ok
          17:56:31.0283 4840 b57nd60a (b5ace6968304a3900eeb1ebfd9622df2) C:\Windows\system32\DRIVERS\b57nd60a.sys
          17:56:31.0286 4840 b57nd60a - ok
          17:56:31.0353 4840 Beep (16a47ce2decc9b099349a5f840654746) C:\Windows\system32\drivers\Beep.sys
          17:56:31.0353 4840 Beep - ok
          17:56:31.0389 4840 blbdrive (61583ee3c3a17003c4acd0475646b4d3) C:\Windows\system32\drivers\blbdrive.sys
          17:56:31.0390 4840 blbdrive - ok
          17:56:31.0422 4840 bowser (6c02a83164f5cc0a262f4199f0871cf5) C:\Windows\system32\DRIVERS\bowser.sys
          17:56:31.0423 4840 bowser - ok
          17:56:31.0451 4840 BrFiltLo (f09eee9edc320b5e1501f749fde686c8) C:\Windows\system32\drivers\BrFiltLo.sys
          17:56:31.0452 4840 BrFiltLo - ok
          17:56:31.0462 4840 BrFiltUp (b114d3098e9bdb8bea8b053685831be6) C:\Windows\system32\drivers\BrFiltUp.sys
          17:56:31.0463 4840 BrFiltUp - ok
          17:56:31.0482 4840 BridgeMP (5c2f352a4e961d72518261257aae204b) C:\Windows\system32\DRIVERS\bridge.sys
          17:56:31.0492 4840 BridgeMP - ok
          17:56:31.0510 4840 Brserid (43bea8d483bf1870f018e2d02e06a5bd) C:\Windows\System32\Drivers\Brserid.sys
          17:56:31.0513 4840 Brserid - ok
          17:56:31.0553 4840 BrSerWdm (a6eca2151b08a09caceca35c07f05b42) C:\Windows\System32\Drivers\BrSerWdm.sys
          17:56:31.0555 4840 BrSerWdm - ok
          17:56:31.0587 4840 BrUsbMdm (b79968002c277e869cf38bd22cd61524) C:\Windows\System32\Drivers\BrUsbMdm.sys
          17:56:31.0587 4840 BrUsbMdm - ok
          17:56:31.0601 4840 BrUsbSer (a87528880231c54e75ea7a44943b38bf) C:\Windows\System32\Drivers\BrUsbSer.sys
          17:56:31.0602 4840 BrUsbSer - ok
          17:56:31.0618 4840 BTHMODEM (9da669f11d1f894ab4eb69bf546a42e8) C:\Windows\system32\drivers\bthmodem.sys
          17:56:31.0619 4840 BTHMODEM - ok
          17:56:31.0657 4840 cdfs (b8bd2bb284668c84865658c77574381a) C:\Windows\system32\DRIVERS\cdfs.sys
          17:56:31.0658 4840 cdfs - ok
          17:56:31.0680 4840 cdrom (f036ce71586e93d94dab220d7bdf4416) C:\Windows\system32\drivers\cdrom.sys
          17:56:31.0680 4840 cdrom - ok
          17:56:31.0716 4840 circlass (d7cd5c4e1b71fa62050515314cfb52cf) C:\Windows\system32\drivers\circlass.sys
          17:56:31.0717 4840 circlass - ok
          17:56:31.0750 4840 CLFS (fe1ec06f2253f691fe36217c592a0206) C:\Windows\system32\CLFS.sys
          17:56:31.0753 4840 CLFS - ok
          17:56:31.0812 4840 CmBatt (0840155d0bddf1190f84a663c284bd33) C:\Windows\system32\drivers\CmBatt.sys
          17:56:31.0813 4840 CmBatt - ok
          17:56:31.0834 4840 cmdide (e19d3f095812725d88f9001985b94edd) C:\Windows\system32\drivers\cmdide.sys
          17:56:31.0835 4840 cmdide - ok
          17:56:31.0888 4840 CNG (c4943b6c962e4b82197542447ad599f4) C:\Windows\system32\Drivers\cng.sys
          17:56:31.0891 4840 CNG - ok
          17:56:31.0925 4840 Compbatt (102de219c3f61415f964c88e9085ad14) C:\Windows\system32\drivers\compbatt.sys
          17:56:31.0926 4840 Compbatt - ok
          17:56:31.0972 4840 CompositeBus (03edb043586cceba243d689bdda370a8) C:\Windows\system32\drivers\CompositeBus.sys
          17:56:31.0972 4840 CompositeBus - ok
          17:56:32.0003 4840 crcdisk (1c827878a998c18847245fe1f34ee597) C:\Windows\system32\drivers\crcdisk.sys
          17:56:32.0004 4840 crcdisk - ok
          17:56:32.0056 4840 DfsC (9bb2ef44eaa163b29c4a4587887a0fe4) C:\Windows\system32\Drivers\dfsc.sys
          17:56:32.0057 4840 DfsC - ok
          17:56:32.0081 4840 discache (13096b05847ec78f0977f2c0f79e9ab3) C:\Windows\system32\drivers\discache.sys
          17:56:32.0082 4840 discache - ok
          17:56:32.0094 4840 Disk (9819eee8b5ea3784ec4af3b137a5244c) C:\Windows\system32\drivers\disk.sys
          17:56:32.0095 4840 Disk - ok
          17:56:32.0113 4840 drmkaud (9b19f34400d24df84c858a421c205754) C:\Windows\system32\drivers\drmkaud.sys
          17:56:32.0114 4840 drmkaud - ok
          17:56:32.0145 4840 DXGKrnl (f5bee30450e18e6b83a5012c100616fd) C:\Windows\System32\drivers\dxgkrnl.sys
          17:56:32.0149 4840 DXGKrnl - ok
          17:56:32.0203 4840 ebdrv (dc5d737f51be844d8c82c695eb17372f) C:\Windows\system32\drivers\evbda.sys
          17:56:32.0228 4840 ebdrv - ok
          17:56:32.0326 4840 elxstor (0e5da5369a0fcaea12456dd852545184) C:\Windows\system32\drivers\elxstor.sys
          17:56:32.0331 4840 elxstor - ok
          17:56:32.0349 4840 ErrDev (34a3c54752046e79a126e15c51db409b) C:\Windows\system32\drivers\errdev.sys
          17:56:32.0350 4840 ErrDev - ok
          17:56:32.0379 4840 exfat (a510c654ec00c1e9bdd91eeb3a59823b) C:\Windows\system32\drivers\exfat.sys
          17:56:32.0381 4840 exfat - ok
          17:56:32.0428 4840 fastfat (0adc83218b66a6db380c330836f3e36d) C:\Windows\system32\drivers\fastfat.sys
          17:56:32.0429 4840 fastfat - ok
          17:56:32.0446 4840 fdc (d765d19cd8ef61f650c384f62fac00ab) C:\Windows\system32\drivers\fdc.sys
          17:56:32.0447 4840 fdc - ok
          17:56:32.0465 4840 FileInfo (655661be46b5f5f3fd454e2c3095b930) C:\Windows\system32\drivers\fileinfo.sys
          17:56:32.0466 4840 FileInfo - ok
          17:56:32.0516 4840 Filetrace (5f671ab5bc87eea04ec38a6cd5962a47) C:\Windows\system32\drivers\filetrace.sys
          17:56:32.0517 4840 Filetrace - ok
          17:56:32.0550 4840 flpydisk (c172a0f53008eaeb8ea33fe10e177af5) C:\Windows\system32\drivers\flpydisk.sys
          17:56:32.0551 4840 flpydisk - ok
          17:56:32.0572 4840 FltMgr (da6b67270fd9db3697b20fce94950741) C:\Windows\system32\drivers\fltmgr.sys
          17:56:32.0574 4840 FltMgr - ok
          17:56:32.0610 4840 FsDepends (d43703496149971890703b4b1b723eac) C:\Windows\system32\drivers\FsDepends.sys
          17:56:32.0611 4840 FsDepends - ok
          17:56:32.0625 4840 Fs_Rec (e95ef8547de20cf0603557c0cf7a9462) C:\Windows\system32\drivers\Fs_Rec.sys
          17:56:32.0625 4840 Fs_Rec - ok
          17:56:32.0639 4840 fvevol (1f7b25b858fa27015169fe95e54108ed) C:\Windows\system32\DRIVERS\fvevol.sys
          17:56:32.0641 4840 fvevol - ok
          17:56:32.0656 4840 gagp30kx (8c778d335c9d272cfd3298ab02abe3b6) C:\Windows\system32\drivers\gagp30kx.sys
          17:56:32.0657 4840 gagp30kx - ok
          17:56:32.0742 4840 GEARAspiWDM (e403aacf8c7bb11375122d2464560311) C:\Windows\system32\DRIVERS\GEARAspiWDM.sys
          17:56:32.0742 4840 GEARAspiWDM - ok
          17:56:32.0813 4840 hcw85cir (f2523ef6460fc42405b12248338ab2f0) C:\Windows\system32\drivers\hcw85cir.sys
          17:56:32.0814 4840 hcw85cir - ok
          17:56:32.0834 4840 HdAudAddService (975761c778e33cd22498059b91e7373a) C:\Windows\system32\drivers\HdAudio.sys
          17:56:32.0838 4840 HdAudAddService - ok
          17:56:32.0885 4840 HDAudBus (97bfed39b6b79eb12cddbfeed51f56bb) C:\Windows\system32\drivers\HDAudBus.sys
          17:56:32.0885 4840 HDAudBus - ok
          17:56:32.0906 4840 HidBatt (78e86380454a7b10a5eb255dc44a355f) C:\Windows\system32\drivers\HidBatt.sys
          17:56:32.0907 4840 HidBatt - ok
          17:56:32.0960 4840 HidBth (7fd2a313f7afe5c4dab14798c48dd104) C:\Windows\system32\drivers\hidbth.sys
          17:56:32.0961 4840 HidBth - ok
          17:56:32.0986 4840 HidIr (0a77d29f311b88cfae3b13f9c1a73825) C:\Windows\system32\drivers\hidir.sys
          17:56:32.0986 4840 HidIr - ok
          17:56:33.0000 4840 HidUsb (9592090a7e2b61cd582b612b6df70536) C:\Windows\system32\DRIVERS\hidusb.sys
          17:56:33.0001 4840 HidUsb - ok
          17:56:33.0095 4840 HpSAMD (39d2abcd392f3d8a6dce7b60ae7b8efc) C:\Windows\system32\drivers\HpSAMD.sys
          17:56:33.0096 4840 HpSAMD - ok
          17:56:33.0161 4840 HTTP (0ea7de1acb728dd5a369fd742d6eee28) C:\Windows\system32\drivers\HTTP.sys
          17:56:33.0167 4840 HTTP - ok
          17:56:33.0180 4840 hwpolicy (a5462bd6884960c9dc85ed49d34ff392) C:\Windows\system32\drivers\hwpolicy.sys
          17:56:33.0180 4840 hwpolicy - ok
          17:56:33.0219 4840 i8042prt (fa55c73d4affa7ee23ac4be53b4592d3) C:\Windows\system32\drivers\i8042prt.sys
          17:56:33.0220 4840 i8042prt - ok
          17:56:33.0245 4840 iaStor (26cf4275034214ecedd8ec17b0a18a99) C:\Windows\system32\drivers\iaStor.sys
          17:56:33.0248 4840 iaStor - ok
          17:56:33.0269 4840 iaStorV (aaaf44db3bd0b9d1fb6969b23ecc8366) C:\Windows\system32\drivers\iaStorV.sys
          17:56:33.0273 4840 iaStorV - ok
          17:56:33.0372 4840 igfx (a87261ef1546325b559374f5689cf5bc) C:\Windows\system32\DRIVERS\igdkmd64.sys
          17:56:33.0419 4840 igfx - ok
          17:56:33.0451 4840 iirsp (5c18831c61933628f5bb0ea2675b9d21) C:\Windows\system32\drivers\iirsp.sys
          17:56:33.0452 4840 iirsp - ok
          17:56:33.0483 4840 intelide (f00f20e70c6ec3aa366910083a0518aa) C:\Windows\system32\drivers\intelide.sys
          17:56:33.0484 4840 intelide - ok
          17:56:33.0543 4840 intelppm (ada036632c664caa754079041cf1f8c1) C:\Windows\system32\drivers\intelppm.sys
          17:56:33.0543 4840 intelppm - ok
          17:56:33.0580 4840 IpFilterDriver (c9f0e1bd74365a8771590e9008d22ab6) C:\Windows\system32\DRIVERS\ipfltdrv.sys
          17:56:33.0581 4840 IpFilterDriver - ok
          17:56:33.0598 4840 IPMIDRV (0fc1aea580957aa8817b8f305d18ca3a) C:\Windows\system32\drivers\IPMIDrv.sys
          17:56:33.0599 4840 IPMIDRV - ok
          17:56:33.0608 4840 IPNAT (af9b39a7e7b6caa203b3862582e9f2d0) C:\Windows\system32\drivers\ipnat.sys
          17:56:33.0609 4840 IPNAT - ok
          17:56:33.0627 4840 IRENUM (3abf5e7213eb28966d55d58b515d5ce9) C:\Windows\system32\drivers\irenum.sys
          17:56:33.0628 4840 IRENUM - ok
          17:56:33.0691 4840 isapnp (2f7b28dc3e1183e5eb418df55c204f38) C:\Windows\system32\drivers\isapnp.sys
          17:56:33.0692 4840 isapnp - ok
          17:56:33.0736 4840 iScsiPrt (d931d7309deb2317035b07c9f9e6b0bd) C:\Windows\system32\drivers\msiscsi.sys
          17:56:33.0739 4840 iScsiPrt - ok
          17:56:33.0779 4840 kbdclass (bc02336f1cba7dcc7d1213bb588a68a5) C:\Windows\system32\DRIVERS\kbdclass.sys
          17:56:33.0780 4840 kbdclass - ok
          17:56:33.0805 4840 kbdhid (0705eff5b42a9db58548eec3b26bb484) C:\Windows\system32\DRIVERS\kbdhid.sys
          17:56:33.0806 4840 kbdhid - ok
          17:56:33.0841 4840 KSecDD (da1e991a61cfdd755a589e206b97644b) C:\Windows\system32\Drivers\ksecdd.sys
          17:56:33.0842 4840 KSecDD - ok
          17:56:33.0855 4840 KSecPkg (7e33198d956943a4f11a5474c1e9106f) C:\Windows\system32\Drivers\ksecpkg.sys
          17:56:33.0856 4840 KSecPkg - ok
          17:56:33.0877 4840 ksthunk (6869281e78cb31a43e969f06b57347c4) C:\Windows\system32\drivers\ksthunk.sys
          17:56:33.0878 4840 ksthunk - ok
          17:56:33.0928 4840 lltdio (1538831cf8ad2979a04c423779465827) C:\Windows\system32\DRIVERS\lltdio.sys
          17:56:33.0928 4840 lltdio - ok
          17:56:34.0006 4840 LSI_FC (1a93e54eb0ece102495a51266dcdb6a6) C:\Windows\system32\drivers\lsi_fc.sys
          17:56:34.0008 4840 LSI_FC - ok
          17:56:34.0041 4840 LSI_SAS (1047184a9fdc8bdbff857175875ee810) C:\Windows\system32\drivers\lsi_sas.sys
          17:56:34.0042 4840 LSI_SAS - ok
          17:56:34.0059 4840 LSI_SAS2 (30f5c0de1ee8b5bc9306c1f0e4a75f93) C:\Windows\system32\drivers\lsi_sas2.sys
          17:56:34.0060 4840 LSI_SAS2 - ok
          17:56:34.0078 4840 LSI_SCSI (0504eacaff0d3c8aed161c4b0d369d4a) C:\Windows\system32\drivers\lsi_scsi.sys
          17:56:34.0080 4840 LSI_SCSI - ok
          17:56:34.0108 4840 luafv (43d0f98e1d56ccddb0d5254cff7b356e) C:\Windows\system32\drivers\luafv.sys
          17:56:34.0109 4840 luafv - ok
          17:56:34.0126 4840 megasas (a55805f747c6edb6a9080d7c633bd0f4) C:\Windows\system32\drivers\megasas.sys
          17:56:34.0127 4840 megasas - ok
          17:56:34.0178 4840 MegaSR (baf74ce0072480c3b6b7c13b2a94d6b3) C:\Windows\system32\drivers\MegaSR.sys
          17:56:34.0181 4840 MegaSR - ok
          17:56:34.0227 4840 MEIx64 (a6518dcc42f7a6e999bb3bea8fd87567) C:\Windows\system32\drivers\HECIx64.sys
          17:56:34.0228 4840 MEIx64 - ok
          17:56:34.0247 4840 Modem (800ba92f7010378b09f9ed9270f07137) C:\Windows\system32\drivers\modem.sys
          17:56:34.0247 4840 Modem - ok
          17:56:34.0276 4840 monitor (b03d591dc7da45ece20b3b467e6aadaa) C:\Windows\system32\DRIVERS\monitor.sys
          17:56:34.0276 4840 monitor - ok
          17:56:34.0288 4840 mouclass (7d27ea49f3c1f687d357e77a470aea99) C:\Windows\system32\DRIVERS\mouclass.sys
          17:56:34.0289 4840 mouclass - ok
          17:56:34.0316 4840 mouhid (d3bf052c40b0c4166d9fd86a4288c1e6) C:\Windows\system32\DRIVERS\mouhid.sys
          17:56:34.0317 4840 mouhid - ok
          17:56:34.0341 4840 mountmgr (32e7a3d591d671a6df2db515a5cbe0fa) C:\Windows\system32\drivers\mountmgr.sys
          17:56:34.0342 4840 mountmgr - ok
          17:56:34.0374 4840 mpio (a44b420d30bd56e145d6a2bc8768ec58) C:\Windows\system32\drivers\mpio.sys
          17:56:34.0378 4840 mpio - ok
          17:56:34.0417 4840 mpsdrv (6c38c9e45ae0ea2fa5e551f2ed5e978f) C:\Windows\system32\drivers\mpsdrv.sys
          17:56:34.0418 4840 mpsdrv - ok
          17:56:34.0446 4840 MRxDAV (dc722758b8261e1abafd31a3c0a66380) C:\Windows\system32\drivers\mrxdav.sys
          17:56:34.0448 4840 MRxDAV - ok
          17:56:34.0473 4840 mrxsmb (a5d9106a73dc88564c825d317cac68ac) C:\Windows\system32\DRIVERS\mrxsmb.sys
          17:56:34.0473 4840 mrxsmb - ok
          17:56:34.0496 4840 mrxsmb10 (d711b3c1d5f42c0c2415687be09fc163) C:\Windows\system32\DRIVERS\mrxsmb10.sys
          17:56:34.0498 4840 mrxsmb10 - ok
          17:56:34.0515 4840 mrxsmb20 (9423e9d355c8d303e76b8cfbd8a5c30c) C:\Windows\system32\DRIVERS\mrxsmb20.sys
          17:56:34.0516 4840 mrxsmb20 - ok
          17:56:34.0533 4840 msahci (c25f0bafa182cbca2dd3c851c2e75796) C:\Windows\system32\drivers\msahci.sys
          17:56:34.0534 4840 msahci - ok
          17:56:34.0579 4840 msdsm (db801a638d011b9633829eb6f663c900) C:\Windows\system32\drivers\msdsm.sys
          17:56:34.0581 4840 msdsm - ok
          17:56:34.0590 4840 Msfs (aa3fb40e17ce1388fa1bedab50ea8f96) C:\Windows\system32\drivers\Msfs.sys
          17:56:34.0591 4840 Msfs - ok
          17:56:34.0611 4840 mshidkmdf (f9d215a46a8b9753f61767fa72a20326) C:\Windows\System32\drivers\mshidkmdf.sys
          17:56:34.0611 4840 mshidkmdf - ok
          17:56:34.0658 4840 msisadrv (d916874bbd4f8b07bfb7fa9b3ccae29d) C:\Windows\system32\drivers\msisadrv.sys
          17:56:34.0658 4840 msisadrv - ok
          17:56:34.0683 4840 MSKSSRV (49ccf2c4fea34ffad8b1b59d49439366) C:\Windows\system32\drivers\MSKSSRV.sys
          17:56:34.0684 4840 MSKSSRV - ok
          17:56:34.0691 4840 MSPCLOCK (bdd71ace35a232104ddd349ee70e1ab3) C:\Windows\system32\drivers\MSPCLOCK.sys
          17:56:34.0692 4840 MSPCLOCK - ok
          17:56:34.0699 4840 MSPQM (4ed981241db27c3383d72092b618a1d0) C:\Windows\system32\drivers\MSPQM.sys
          17:56:34.0699 4840 MSPQM - ok
          17:56:34.0721 4840 MsRPC (759a9eeb0fa9ed79da1fb7d4ef78866d) C:\Windows\system32\drivers\MsRPC.sys
          17:56:34.0723 4840 MsRPC - ok
          17:56:34.0747 4840 mssmbios (0eed230e37515a0eaee3c2e1bc97b288) C:\Windows\system32\drivers\mssmbios.sys
          17:56:34.0747 4840 mssmbios - ok
          17:56:34.0771 4840 MSTEE (2e66f9ecb30b4221a318c92ac2250779) C:\Windows\system32\drivers\MSTEE.sys
          17:56:34.0772 4840 MSTEE - ok
          17:56:34.0791 4840 MTConfig (7ea404308934e675bffde8edf0757bcd) C:\Windows\system32\drivers\MTConfig.sys
          17:56:34.0792 4840 MTConfig - ok
          17:56:34.0809 4840 Mup (f9a18612fd3526fe473c1bda678d61c8) C:\Windows\system32\Drivers\mup.sys
          17:56:34.0810 4840 Mup - ok
          17:56:34.0863 4840 NativeWifiP (1ea3749c4114db3e3161156ffffa6b33) C:\Windows\system32\DRIVERS\nwifi.sys
          17:56:34.0864 4840 NativeWifiP - ok
          17:56:34.0906 4840 NDIS (79b47fd40d9a817e932f9d26fac0a81c) C:\Windows\system32\drivers\ndis.sys
          17:56:34.0913 4840 NDIS - ok
          17:56:34.0921 4840 NdisCap (9f9a1f53aad7da4d6fef5bb73ab811ac) C:\Windows\system32\DRIVERS\ndiscap.sys
          17:56:34.0922 4840 NdisCap - ok
          17:56:34.0941 4840 NdisTapi (30639c932d9fef22b31268fe25a1b6e5) C:\Windows\system32\DRIVERS\ndistapi.sys
          17:56:34.0942 4840 NdisTapi - ok
          17:56:34.0957 4840 Ndisuio (136185f9fb2cc61e573e676aa5402356) C:\Windows\system32\DRIVERS\ndisuio.sys
          17:56:34.0957 4840 Ndisuio - ok
          17:56:34.0989 4840 NdisWan (53f7305169863f0a2bddc49e116c2e11) C:\Windows\system32\DRIVERS\ndiswan.sys
          17:56:34.0990 4840 NdisWan - ok
          17:56:35.0012 4840 NDProxy (015c0d8e0e0421b4cfd48cffe2825879) C:\Windows\system32\drivers\NDProxy.sys
          17:56:35.0013 4840 NDProxy - ok
          17:56:35.0069 4840 NetBIOS (86743d9f5d2b1048062b14b1d84501c4) C:\Windows\system32\DRIVERS\netbios.sys
          17:56:35.0069 4840 NetBIOS - ok
          17:56:35.0087 4840 NetBT (09594d1089c523423b32a4229263f068) C:\Windows\system32\DRIVERS\netbt.sys
          17:56:35.0088 4840 NetBT - ok
          17:56:35.0151 4840 netr28x (8b5d2d7cb0ef5b1967860b8ab742a46c) C:\Windows\system32\DRIVERS\netr28x.sys
          17:56:35.0157 4840 netr28x - ok
          17:56:35.0202 4840 nfrd960 (77889813be4d166cdab78ddba990da92) C:\Windows\system32\drivers\nfrd960.sys
          17:56:35.0203 4840 nfrd960 - ok
          17:56:35.0241 4840 Npfs (1e4c4ab5c9b8dd13179bbdc75a2a01f7) C:\Windows\system32\drivers\Npfs.sys
          17:56:35.0242 4840 Npfs - ok
          17:56:35.0252 4840 nsiproxy (e7f5ae18af4168178a642a9247c63001) C:\Windows\system32\drivers\nsiproxy.sys
          17:56:35.0252 4840 nsiproxy - ok
          17:56:35.0301 4840 Ntfs (a2f74975097f52a00745f9637451fdd8) C:\Windows\system32\drivers\Ntfs.sys
          17:56:35.0314 4840 Ntfs - ok
          17:56:35.0337 4840 Null (9899284589f75fa8724ff3d16aed75c1) C:\Windows\system32\drivers\Null.sys
          17:56:35.0338 4840 Null - ok
          17:56:35.0362 4840 nvraid (0a92cb65770442ed0dc44834632f66ad) C:\Windows\system32\drivers\nvraid.sys
          17:56:35.0364 4840 nvraid - ok
          17:56:35.0398 4840 nvstor (dab0e87525c10052bf65f06152f37e4a) C:\Windows\system32\drivers\nvstor.sys
          17:56:35.0400 4840 nvstor - ok
          17:56:35.0445 4840 nv_agp (270d7cd42d6e3979f6dd0146650f0e05) C:\Windows\system32\drivers\nv_agp.sys
          17:56:35.0446 4840 nv_agp - ok
          17:56:35.0472 4840 ohci1394 (3589478e4b22ce21b41fa1bfc0b8b8a0) C:\Windows\system32\drivers\ohci1394.sys
          17:56:35.0473 4840 ohci1394 - ok
          17:56:35.0505 4840 Parport (0086431c29c35be1dbc43f52cc273887) C:\Windows\system32\drivers\parport.sys
          17:56:35.0506 4840 Parport - ok
          17:56:35.0522 4840 partmgr (871eadac56b0a4c6512bbe32753ccf79) C:\Windows\system32\drivers\partmgr.sys
          17:56:35.0523 4840 partmgr - ok
          17:56:35.0546 4840 pci (94575c0571d1462a0f70bde6bd6ee6b3) C:\Windows\system32\drivers\pci.sys
          17:56:35.0547 4840 pci - ok
          17:56:35.0564 4840 pciide (b5b8b5ef2e5cb34df8dcf8831e3534fa) C:\Windows\system32\drivers\pciide.sys
          17:56:35.0565 4840 pciide - ok
          17:56:35.0600 4840 pcmcia (b2e81d4e87ce48589f98cb8c05b01f2f) C:\Windows\system32\drivers\pcmcia.sys
          17:56:35.0602 4840 pcmcia - ok
          17:56:35.0630 4840 pcw (d6b9c2e1a11a3a4b26a182ffef18f603) C:\Windows\system32\drivers\pcw.sys
          17:56:35.0631 4840 pcw - ok
          17:56:35.0668 4840 PEAUTH (68769c3356b3be5d1c732c97b9a80d6e) C:\Windows\system32\drivers\peauth.sys
          17:56:35.0674 4840 PEAUTH - ok
          17:56:35.0730 4840 pmxdrv (0bee791c7c7ace453c134e73633c497d) C:\Windows\system32\drivers\pmxdrv.sys
          17:56:35.0731 4840 pmxdrv - ok
          17:56:35.0763 4840 PptpMiniport (f92a2c41117a11a00be01ca01a7fcde9) C:\Windows\system32\DRIVERS\raspptp.sys
          17:56:35.0764 4840 PptpMiniport - ok
          17:56:35.0787 4840 Processor (0d922e23c041efb1c3fac2a6f943c9bf) C:\Windows\system32\drivers\processr.sys
          17:56:35.0788 4840 Processor - ok
          17:56:35.0811 4840 Psched (0557cf5a2556bd58e26384169d72438d) C:\Windows\system32\DRIVERS\pacer.sys
          17:56:35.0812 4840 Psched - ok
          17:56:35.0852 4840 ql2300 (a53a15a11ebfd21077463ee2c7afeef0) C:\Windows\system32\drivers\ql2300.sys
          17:56:35.0864 4840 ql2300 - ok
          17:56:35.0898 4840 ql40xx (4f6d12b51de1aaeff7dc58c4d75423c8) C:\Windows\system32\drivers\ql40xx.sys
          17:56:35.0899 4840 ql40xx - ok
          17:56:35.0964 4840 QWAVEdrv (76707bb36430888d9ce9d705398adb6c) C:\Windows\system32\drivers\qwavedrv.sys
          17:56:35.0965 4840 QWAVEdrv - ok
          17:56:35.0995 4840 RasAcd (5a0da8ad5762fa2d91678a8a01311704) C:\Windows\system32\DRIVERS\rasacd.sys
          17:56:35.0996 4840 RasAcd - ok
          17:56:36.0022 4840 RasAgileVpn (7ecff9b22276b73f43a99a15a6094e90) C:\Windows\system32\DRIVERS\AgileVpn.sys
          17:56:36.0023 4840 RasAgileVpn - ok
          17:56:36.0037 4840 Rasl2tp (471815800ae33e6f1c32fb1b97c490ca) C:\Windows\system32\DRIVERS\rasl2tp.sys
          17:56:36.0038 4840 Rasl2tp - ok
          17:56:36.0053 4840 RasPppoe (855c9b1cd4756c5e9a2aa58a15f58c25) C:\Windows\system32\DRIVERS\raspppoe.sys
          17:56:36.0053 4840 RasPppoe - ok
          17:56:36.0069 4840 RasSstp (e8b1e447b008d07ff47d016c2b0eeecb) C:\Windows\system32\DRIVERS\rassstp.sys
          17:56:36.0069 4840 RasSstp - ok
          17:56:36.0105 4840 rdbss (77f665941019a1594d887a74f301fa2f) C:\Windows\system32\DRIVERS\rdbss.sys
          17:56:36.0107 4840 rdbss - ok
          17:56:36.0137 4840 rdpbus (302da2a0539f2cf54d7c6cc30c1f2d8d) C:\Windows\system32\drivers\rdpbus.sys
          17:56:36.0138 4840 rdpbus - ok
          17:56:36.0158 4840 RDPCDD (cea6cc257fc9b7715f1c2b4849286d24) C:\Windows\system32\DRIVERS\RDPCDD.sys
          17:56:36.0158 4840 RDPCDD - ok
          17:56:36.0183 4840 RDPENCDD (bb5971a4f00659529a5c44831af22365) C:\Windows\system32\drivers\rdpencdd.sys
          17:56:36.0183 4840 RDPENCDD - ok
          17:56:36.0202 4840 RDPREFMP (216f3fa57533d98e1f74ded70113177a) C:\Windows\system32\drivers\rdprefmp.sys
          17:56:36.0202 4840 RDPREFMP - ok
          17:56:36.0224 4840 RDPWD (15b66c206b5cb095bab980553f38ed23) C:\Windows\system32\drivers\RDPWD.sys
          17:56:36.0226 4840 RDPWD - ok
          17:56:36.0245 4840 rdyboost (34ed295fa0121c241bfef24764fc4520) C:\Windows\system32\drivers\rdyboost.sys
          17:56:36.0247 4840 rdyboost - ok
          17:56:36.0269 4840 rspndr (ddc86e4f8e7456261e637e3552e804ff) C:\Windows\system32\DRIVERS\rspndr.sys
          17:56:36.0270 4840 rspndr - ok
          17:56:36.0318 4840 RTL8167 (f4c374b1c46de294b573bb43723ac3f6) C:\Windows\system32\DRIVERS\Rt64win7.sys
          17:56:36.0320 4840 RTL8167 - ok
          17:56:36.0365 4840 sbp2port (ac03af3329579fffb455aa2daabbe22b) C:\Windows\system32\drivers\sbp2port.sys
          17:56:36.0367 4840 sbp2port - ok
          17:56:36.0401 4840 scfilter (253f38d0d7074c02ff8deb9836c97d2b) C:\Windows\system32\DRIVERS\scfilter.sys
          17:56:36.0402 4840 scfilter - ok
          17:56:36.0429 4840 secdrv (3ea8a16169c26afbeb544e0e48421186) C:\Windows\system32\drivers\secdrv.sys
          17:56:36.0429 4840 secdrv - ok
          17:56:36.0468 4840 Serenum (cb624c0035412af0debec78c41f5ca1b) C:\Windows\system32\drivers\serenum.sys
          17:56:36.0469 4840 Serenum - ok
          17:56:36.0514 4840 Serial (c1d8e28b2c2adfaec4ba89e9fda69bd6) C:\Windows\system32\drivers\serial.sys
          17:56:36.0516 4840 Serial - ok
          17:56:36.0544 4840 sermouse (1c545a7d0691cc4a027396535691c3e3) C:\Windows\system32\drivers\sermouse.sys
          17:56:36.0544 4840 sermouse - ok
          17:56:36.0586 4840 sffdisk (a554811bcd09279536440c964ae35bbf) C:\Windows\system32\drivers\sffdisk.sys
          17:56:36.0587 4840 sffdisk - ok
          17:56:36.0612 4840 sffp_mmc (ff414f0baefeba59bc6c04b3db0b87bf) C:\Windows\system32\drivers\sffp_mmc.sys
          17:56:36.0613 4840 sffp_mmc - ok
          17:56:36.0626 4840 sffp_sd (dd85b78243a19b59f0637dcf284da63c) C:\Windows\system32\drivers\sffp_sd.sys
          17:56:36.0627 4840 sffp_sd - ok
          17:56:36.0634 4840 sfloppy (a9d601643a1647211a1ee2ec4e433ff4) C:\Windows\system32\drivers\sfloppy.sys
          17:56:36.0634 4840 sfloppy - ok
          17:56:36.0665 4840 Sftfs (a40abfdcb75f835fdf3ce0cc64e4250d) C:\Windows\system32\DRIVERS\Sftfslh.sys
          17:56:36.0669 4840 Sftfs - ok
          17:56:36.0688 4840 Sftplay (411769ed1cb12d2b44217734347bdb7a) C:\Windows\system32\DRIVERS\Sftplaylh.sys
          17:56:36.0689 4840 Sftplay - ok
          17:56:36.0696 4840 Sftredir (a14d0df34bbb00ea94da16193d0c7957) C:\Windows\system32\DRIVERS\Sftredirlh.sys
          17:56:36.0697 4840 Sftredir - ok
          17:56:36.0709 4840 Sftvol (393b22addd89979eb1c60898f51c3648) C:\Windows\system32\DRIVERS\Sftvollh.sys
          17:56:36.0710 4840 Sftvol - ok
          17:56:36.0765 4840 SiSRaid2 (843caf1e5fde1ffd5ff768f23a51e2e1) C:\Windows\system32\drivers\SiSRaid2.sys
          17:56:36.0766 4840 SiSRaid2 - ok
          17:56:36.0822 4840 SiSRaid4 (6a6c106d42e9ffff8b9fcb4f754f6da4) C:\Windows\system32\drivers\sisraid4.sys
          17:56:36.0823 4840 SiSRaid4 - ok
          17:56:36.0864 4840 Smb (548260a7b8654e024dc30bf8a7c5baa4) C:\Windows\system32\DRIVERS\smb.sys
          17:56:36.0866 4840 Smb - ok
          17:56:36.0886 4840 spldr (b9e31e5cacdfe584f34f730a677803f9) C:\Windows\system32\drivers\spldr.sys
          17:56:36.0886 4840 spldr - ok
          17:56:36.0916 4840 srv (441fba48bff01fdb9d5969ebc1838f0b) C:\Windows\system32\DRIVERS\srv.sys
          17:56:36.0918 4840 srv - ok
          17:56:36.0950 4840 srv2 (b4adebbf5e3677cce9651e0f01f7cc28) C:\Windows\system32\DRIVERS\srv2.sys
          17:56:36.0954 4840 srv2 - ok
          17:56:36.0967 4840 srvnet (27e461f0be5bff5fc737328f749538c3) C:\Windows\system32\DRIVERS\srvnet.sys
          17:56:36.0968 4840 srvnet - ok
          17:56:37.0028 4840 stexstor (f3817967ed533d08327dc73bc4d5542a) C:\Windows\system32\drivers\stexstor.sys
          17:56:37.0029 4840 stexstor - ok
          17:56:37.0053 4840 STHDA (dcc8845692dea3477bcf6ce9d06c711f) C:\Windows\system32\DRIVERS\stwrt64.sys
          17:56:37.0058 4840 STHDA - ok
          17:56:37.0097 4840 swenum (d01ec09b6711a5f8e7e6564a4d0fbc90) C:\Windows\system32\drivers\swenum.sys
          17:56:37.0097 4840 swenum - ok
          17:56:37.0188 4840 Tcpip (fc62769e7bff2896035aeed399108162) C:\Windows\system32\drivers\tcpip.sys
          17:56:37.0203 4840 Tcpip - ok
          17:56:37.0260 4840 TCPIP6 (fc62769e7bff2896035aeed399108162) C:\Windows\system32\DRIVERS\tcpip.sys
          17:56:37.0267 4840 TCPIP6 - ok
          17:56:37.0283 4840 tcpipreg (df687e3d8836bfb04fcc0615bf15a519) C:\Windows\system32\drivers\tcpipreg.sys
          17:56:37.0283 4840 tcpipreg - ok
          17:56:37.0299 4840 TDPIPE (3371d21011695b16333a3934340c4e7c) C:\Windows\system32\drivers\tdpipe.sys
          17:56:37.0299 4840 TDPIPE - ok
          17:56:37.0306 4840 TDTCP (e4245bda3190a582d55ed09e137401a9) C:\Windows\system32\drivers\tdtcp.sys
          17:56:37.0307 4840 TDTCP - ok
          17:56:37.0330 4840 tdx (ddad5a7ab24d8b65f8d724f5c20fd806) C:\Windows\system32\DRIVERS\tdx.sys
          17:56:37.0330 4840 tdx - ok
          17:56:37.0359 4840 TermDD (561e7e1f06895d78de991e01dd0fb6e5) C:\Windows\system32\drivers\termdd.sys
          17:56:37.0359 4840 TermDD - ok
          17:56:37.0389 4840 tihub3 (ff879027c552a37897d107be6cedf6df) C:\Windows\system32\drivers\tihub3.sys
          17:56:37.0390 4840 tihub3 - ok
          17:56:37.0419 4840 tixhci (133c3b4a3e44616f8f571a0ebbef9b74) C:\Windows\system32\drivers\tixhci.sys
          17:56:37.0420 4840 tixhci - ok
          17:56:37.0467 4840 tssecsrv (ce18b2cdfc837c99e5fae9ca6cba5d30) C:\Windows\system32\DRIVERS\tssecsrv.sys
          17:56:37.0468 4840 tssecsrv - ok
          17:56:37.0487 4840 TsUsbFlt (d11c783e3ef9a3c52c0ebe83cc5000e9) C:\Windows\system32\drivers\tsusbflt.sys
          17:56:37.0488 4840 TsUsbFlt - ok
          17:56:37.0510 4840 TsUsbGD (9cc2ccae8a84820eaecb886d477cbcb8) C:\Windows\system32\drivers\TsUsbGD.sys
          17:56:37.0511 4840 TsUsbGD - ok
          17:56:37.0531 4840 tunnel (3566a8daafa27af944f5d705eaa64894) C:\Windows\system32\DRIVERS\tunnel.sys
          17:56:37.0532 4840 tunnel - ok
          17:56:37.0566 4840 uagp35 (b4dd609bd7e282bfc683cec7eaaaad67) C:\Windows\system32\drivers\uagp35.sys
          17:56:37.0567 4840 uagp35 - ok
          17:56:37.0583 4840 udfs (ff4232a1a64012baa1fd97c7b67df593) C:\Windows\system32\DRIVERS\udfs.sys
          17:56:37.0586 4840 udfs - ok
          17:56:37.0633 4840 uliagpkx (4bfe1bc28391222894cbf1e7d0e42320) C:\Windows\system32\drivers\uliagpkx.sys
          17:56:37.0634 4840 uliagpkx - ok
          17:56:37.0655 4840 umbus (dc54a574663a895c8763af0fa1ff7561) C:\Windows\system32\DRIVERS\umbus.sys
          17:56:37.0655 4840 umbus - ok
          17:56:37.0706 4840 UmPass (b2e8e8cb557b156da5493bbddcc1474d) C:\Windows\system32\drivers\umpass.sys
          17:56:37.0707 4840 UmPass - ok
          17:56:37.0757 4840 USBAAPL64 (aa33fc47ed58c34e6e9261e4f850b7eb) C:\Windows\system32\Drivers\usbaapl64.sys
          17:56:37.0758 4840 USBAAPL64 - ok
          17:56:37.0797 4840 usbccgp (6f1a3157a1c89435352ceb543cdb359c) C:\Windows\system32\DRIVERS\usbccgp.sys
          17:56:37.0798 4840 usbccgp - ok
          17:56:37.0820 4840 usbcir (af0892a803fdda7492f595368e3b68e7) C:\Windows\system32\drivers\usbcir.sys
          17:56:37.0821 4840 usbcir - ok
          17:56:37.0857 4840 usbehci (c025055fe7b87701eb042095df1a2d7b) C:\Windows\system32\drivers\usbehci.sys
          17:56:37.0858 4840 usbehci - ok
          17:56:37.0898 4840 usbhub (287c6c9410b111b68b52ca298f7b8c24) C:\Windows\system32\drivers\usbhub.sys
          17:56:37.0906 4840 usbhub - ok
          17:56:37.0976 4840 usbohci (9840fc418b4cbd632d3d0a667a725c31) C:\Windows\system32\drivers\usbohci.sys
          17:56:37.0977 4840 usbohci - ok
          17:56:37.0990 4840 usbprint (73188f58fb384e75c4063d29413cee3d) C:\Windows\system32\DRIVERS\usbprint.sys
          17:56:37.0991 4840 usbprint - ok
          17:56:38.0014 4840 usbscan (aaa2513c8aed8b54b189fd0c6b1634c0) C:\Windows\system32\DRIVERS\usbscan.sys
          17:56:38.0015 4840 usbscan - ok
          17:56:38.0042 4840 USBSTOR (fed648b01349a3c8395a5169db5fb7d6) C:\Windows\system32\DRIVERS\USBSTOR.SYS
          17:56:38.0043 4840 USBSTOR - ok
          17:56:38.0057 4840 usbuhci (62069a34518bcf9c1fd9e74b3f6db7cd) C:\Windows\system32\drivers\usbuhci.sys
          17:56:38.0058 4840 usbuhci - ok
          17:56:38.0082 4840 vdrvroot (c5c876ccfc083ff3b128f933823e87bd) C:\Windows\system32\drivers\vdrvroot.sys
          17:56:38.0083 4840 vdrvroot - ok
          17:56:38.0099 4840 vga (da4da3f5e02943c2dc8c6ed875de68dd) C:\Windows\system32\DRIVERS\vgapnp.sys
          17:56:38.0100 4840 vga - ok
          17:56:38.0116 4840 VgaSave (53e92a310193cb3c03bea963de7d9cfc) C:\Windows\System32\drivers\vga.sys
          17:56:38.0117 4840 VgaSave - ok
          17:56:38.0147 4840 vhdmp (2ce2df28c83aeaf30084e1b1eb253cbb) C:\Windows\system32\drivers\vhdmp.sys
          17:56:38.0149 4840 vhdmp - ok
          17:56:38.0205 4840 viaide (e5689d93ffe4e5d66c0178761240dd54) C:\Windows\system32\drivers\viaide.sys
          17:56:38.0206 4840 viaide - ok
          17:56:38.0243 4840 volmgr (d2aafd421940f640b407aefaaebd91b0) C:\Windows\system32\drivers\volmgr.sys
          17:56:38.0244 4840 volmgr - ok
          17:56:38.0280 4840 volmgrx (a255814907c89be58b79ef2f189b843b) C:\Windows\system32\drivers\volmgrx.sys
          17:56:38.0283 4840 volmgrx - ok
          17:56:38.0298 4840 volsnap (df8126bd41180351a093a3ad2fc8903b) C:\Windows\system32\drivers\volsnap.sys
          17:56:38.0300 4840 volsnap - ok
          17:56:38.0321 4840 vsmraid (5e2016ea6ebaca03c04feac5f330d997) C:\Windows\system32\drivers\vsmraid.sys
          17:56:38.0323 4840 vsmraid - ok
          17:56:38.0352 4840 vwifibus (36d4720b72b5c5d9cb2b9c29e9df67a1) C:\Windows\system32\DRIVERS\vwifibus.sys
          17:56:38.0353 4840 vwifibus - ok
          17:56:38.0379 4840 vwififlt (6a3d66263414ff0d6fa754c646612f3f) C:\Windows\system32\DRIVERS\vwififlt.sys
          17:56:38.0380 4840 vwififlt - ok
          17:56:38.0421 4840 WacomPen (4e9440f4f152a7b944cb1663d3935a3e) C:\Windows\system32\drivers\wacompen.sys
          17:56:38.0427 4840 WacomPen - ok
          17:56:38.0452 4840 WANARP (356afd78a6ed4457169241ac3965230c) C:\Windows\system32\DRIVERS\wanarp.sys
          17:56:38.0453 4840 WANARP - ok
          17:56:38.0455 4840 Wanarpv6 (356afd78a6ed4457169241ac3965230c) C:\Windows\system32\DRIVERS\wanarp.sys
          17:56:38.0455 4840 Wanarpv6 - ok
          17:56:38.0477 4840 Wd (72889e16ff12ba0f235467d6091b17dc) C:\Windows\system32\drivers\wd.sys
          17:56:38.0478 4840 Wd - ok
          17:56:38.0531 4840 Wdf01000 (441bd2d7b4f98134c3a4f9fa570fd250) C:\Windows\system32\drivers\Wdf01000.sys
          17:56:38.0536 4840 Wdf01000 - ok
          17:56:38.0560 4840 WfpLwf (611b23304bf067451a9fdee01fbdd725) C:\Windows\system32\DRIVERS\wfplwf.sys
          17:56:38.0560 4840 WfpLwf - ok
          17:56:38.0591 4840 WIMMount (05ecaec3e4529a7153b3136ceb49f0ec) C:\Windows\system32\drivers\wimmount.sys
          17:56:38.0592 4840 WIMMount - ok
          17:56:38.0688 4840 WinUsb (fe88b288356e7b47b74b13372add906d) C:\Windows\system32\DRIVERS\WinUsb.sys
          17:56:38.0695 4840 WinUsb - ok
          17:56:38.0741 4840 WmiAcpi (f6ff8944478594d0e414d3f048f0d778) C:\Windows\system32\drivers\wmiacpi.sys
          17:56:38.0741 4840 WmiAcpi - ok
          17:56:38.0803 4840 ws2ifsl (6bcc1d7d2fd2453957c5479a32364e52) C:\Windows\system32\drivers\ws2ifsl.sys
          17:56:38.0804 4840 ws2ifsl - ok
          17:56:38.0823 4840 WudfPf (d3381dc54c34d79b22cee0d65ba91b7c) C:\Windows\system32\drivers\WudfPf.sys
          17:56:38.0824 4840 WudfPf - ok
          17:56:38.0861 4840 WUDFRd (cf8d590be3373029d57af80914190682) C:\Windows\system32\DRIVERS\WUDFRd.sys
          17:56:38.0863 4840 WUDFRd - ok
          17:56:38.0881 4840 MBR (0x1B8) (a36c5e4f47e84449ff07ed3517b43a31) \Device\Harddisk0\DR0
          17:56:38.0946 4840 \Device\Harddisk0\DR0 - ok
          17:56:38.0948 4840 MBR (0x1B8) (8f558eb6672622401da993e1e865c861) \Device\Harddisk1\DR1
          17:56:38.0951 4840 \Device\Harddisk1\DR1 - ok
          17:56:38.0958 4840 MBR (0x1B8) (671b81004fdd1588fa9ed1331c9ceca9) \Device\Harddisk2\DR2
          17:56:43.0170 4840 \Device\Harddisk2\DR2 - ok
          17:56:43.0180 4840 Boot (0x1200) (e58d1b349e04366414c05c6ae517369e) \Device\Harddisk0\DR0\Partition0
          17:56:43.0180 4840 \Device\Harddisk0\DR0\Partition0 - ok
          17:56:43.0188 4840 Boot (0x1200) (e1553a18c10a5c23c88d9af12f85cf95) \Device\Harddisk0\DR0\Partition1
          17:56:43.0188 4840 \Device\Harddisk0\DR0\Partition1 - ok
          17:56:43.0220 4840 Boot (0x1200) (48499d71e7c350cb1678fa713ba88030) \Device\Harddisk0\DR0\Partition2
          17:56:43.0251 4840 \Device\Harddisk0\DR0\Partition2 - ok
          17:56:43.0653 4840 Boot (0x1200) (2ce04173f52079fb5f9426798594664a) \Device\Harddisk1\DR1\Partition0
          17:56:43.0654 4840 \Device\Harddisk1\DR1\Partition0 - ok
          17:56:43.0657 4840 Boot (0x1200) (c598fe38a473711ae3b33ade121406b1) \Device\Harddisk2\DR2\Partition0
          17:56:43.0657 4840 \Device\Harddisk2\DR2\Partition0 - ok
          17:56:43.0658 4840 ============================================================
          17:56:43.0658 4840 Scan finished
          17:56:43.0658 4840 ============================================================
          17:56:43.0662 4384 Detected object count: 0
          17:56:43.0662 4384 Actual detected object count: 0
          0
          1. * Télécharge TDSSKiller sur ton bureau :

            https://support.kaspersky.com/downloads/utils/tdsskiller.exe

            * Lance le ( Utilisateurs de vista/Seven -> Clic droit puis " Exécuter en tant qu'administrateur " )

            * Clique sur [Start Scan] pour démarrer l'analyse.

            * Si des élements sont trouvés, cliques sur [Continue] puis sur [Reboot Now]

            * Un rapport s'ouvrira au redémarrage du PC.

            * Copie/Colle son contenu dans ta prochaine réponse.

            Note : Le rapport se trouve également sous C:\TDSSKiller.N°deversion_Date_Heure_log.txt.

            note : Si Tdsskiller trouve un fichier nommé "Sptd.sys", tu sélectionnes skip juste pour ce fichier :D

            0
            1. Non pas de point de restauration mais je peux tjs le formater...au pire
              0
              1. pas cool !

                as tu accès à la restauration système ?

                lance une restauration à une date avant de tes problèmes !

                0
                1. J'ai fait le nettoyage mais toujours pas de rapport et pas de changement pour les redirections
                  0
                  1. aide toi de ce tuto pour lancer l'option 2 :

                    Tuto: http://tutoriels-video.zebulon.fr/24-comment-utiliser-smitfraudfix.html

                    0
                    1. Il ne génère pas de rapport, il se ferme après avoir fait le choix 1 et que débute la recherche
                      0
                      1. essaie de lancer cet outil en mode compatibilité :

                        Télécharge Smitfraudfix : (merci a S!RI pour ce petit programme).

                        http://telechargement.zebulon.fr/smitfraudfix.html
                        ou :
                        https://www.commentcamarche.net/?ID=230&module=download#q=SmitFraudFix&cur=1&url=/

                        /!\Utilisateur de Vista et seven : Clique droit sur le logo de smithfarudfix, « exécuter en tant qu'Administrateur »

                        Exécute le, Double click sur Smitfraudfix.exe choisit l'option 1,

                        il va générer un rapport : copie/colle le sur le poste stp.

                        Tuto: http://tutoriels-video.zebulon.fr/24-comment-utiliser-smitfraudfix.html

                        Note :
                        process.exe est détecté par certains antivirus (AntiVir, Dr.Web, Kaspersky Anti-Virus) comme étant un RiskTool. Il ne s'agit pas d'un virus, mais d'un utilitaire destiné à mettre fin à des processus. Mis entre de mauvaises mains, cet utilitaire pourrait arrêter des logiciels de sécurité (Antivirus, Firewall...) d'où l'alerte émise par ces antivirus

                        O.o°*??? Membre, Contributeur sécurité CCMo°.Oø¤º°'°º¤ø

                        O.o°* ??? Réspire à fond, Rédige ton message en bon français et de manière claire.Ca va bien se passer, tu verras, enfin on essaie !!! o°.Oø¤º°'°º¤ø
                        0
                        1. redémarre ton pc,

                          fais quelques recherches pour voir si tu as encore de redirection ;D

                          0
                          1. Rapport de ZHPFix 1.12.3380 par Nicolas Coolman, Update du 05/02/2011
                            Fichier d'export Registre : C:\ZHP\ZHPExportRegistry-2-12-2012-11-47-18 AM.txt
                            Run by Nico at 2/12/2012 11:47:18 AM
                            Windows 7 Home Premium Edition, 64-bit Service Pack 1 (Build 7601)
                            Web site : http://www.premiumorange.com/zeb-help-process/zhpfix.html
                            Web site : http://nicolascoolman.skyrock.com/

                            ========== Logiciel(s) ==========
                            ABSENT Software Key: WTA-4bd5750f-8da2-4cfe-bcd6-fab481df2bec
                            ABSENT Software Key: {B4092C6D-E886-4CB2-BA68-FE5A88D31DE6}_is1

                            ========== Valeur(s) du Registre ==========
                            ABSENT TCPIP:
                            SUPPRIME AAKE KeyValue: C:\Program Files (x86)\Spybot - Search & Destroy 2\SDTray.exe
                            SUPPRIME AAKE KeyValue: C:\Program Files (x86)\Spybot - Search & Destroy 2\SDFSSvc.exe
                            SUPPRIME AAKE KeyValue: C:\Program Files (x86)\Spybot - Search & Destroy 2\SDUpdate.exe
                            SUPPRIME AAKE KeyValue: C:\Program Files (x86)\Spybot - Search & Destroy 2\SDUpdSvc.exe

                            ========== Dossier(s) ==========
                            SUPPRIME Folder: C:\ProgramData\Spybot - Search & Destroy
                            SUPPRIME Folder: C:\Program Files (x86)\Spybot - Search & Destroy
                            SUPPRIME Temporaires Windows: : 72

                            ========== Fichier(s) ==========
                            ABSENT File: c:\program files (x86)\spybot - search & destroy 2\sdtray.exe
                            SUPPRIME Temporaires Windows: : 15

                            ========== Récapitulatif ==========
                            5 : Valeur(s) du Registre
                            3 : Dossier(s)
                            2 : Fichier(s)
                            2 : Logiciel(s)

                            End of clean in 03mn AMs

                            ========== Chemin de fichier rapport ==========
                            C:\ZHP\ZHPFix[R1].txt - 2/12/2012 11:47:18 AM [1449]
                            0
                            1. * Lance ZHPFix via le raccourci sur ton Bureau

                              * Clique sur l'icone représentant la lettre H (« coller les lignes Helper »)
                              Copie et colle les lignes suivantes en gras dans Zhpfix :

                              ----------------------------------------------------------


                              O17 - HKLM\System\CCS\Services\Tcpip\..\{C5FF4228-5F4E-47E9-BB56-B8C6BBAACA89}: DhcpDomain = sgt.automation.net
                              O17 - HKLM\System\CS1\Services\Tcpip\..\{C5FF4228-5F4E-47E9-BB56-B8C6BBAACA89}: DhcpDomain = sgt.automation.net
                              O17 - HKLM\System\CS2\Services\Tcpip\..\{C5FF4228-5F4E-47E9-BB56-B8C6BBAACA89}: DhcpDomain = sgt.automation.net
                              O42 - Logiciel: Bejeweled 3 - (.WildTangent.) [HKLM] -- WTA-4bd5750f-8da2-4cfe-bcd6-fab481df2bec
                              O47 - AAKE:Key Export SP - "C:\Program Files (x86)\Spybot - Search & Destroy 2\SDTray.exe" [Enabled] .(...) -- C:\Program Files (x86)\Spybot - Search & Destroy 2\SDTray.exe (.not file.)
                              O47 - AAKE:Key Export SP - "C:\Program Files (x86)\Spybot - Search & Destroy 2\SDFSSvc.exe" [Enabled] .(...) -- C:\Program Files (x86)\Spybot - Search & Destroy 2\SDFSSvc.exe (.not file.)
                              O47 - AAKE:Key Export SP - "C:\Program Files (x86)\Spybot - Search & Destroy 2\SDUpdate.exe" [Enabled] .(...) -- C:\Program Files (x86)\Spybot - Search & Destroy 2\SDUpdate.exe (.not file.)
                              O47 - AAKE:Key Export SP - "C:\Program Files (x86)\Spybot - Search & Destroy 2\SDUpdSvc.exe" [Enabled] .(...) -- C:\Program Files (x86)\Spybot - Search & Destroy 2\SDUpdSvc.exe (.not file.)
                              O42 - Logiciel: Spybot - Search & Destroy - (.Safer Networking Limited.) [HKLM] -- {B4092C6D-E886-4CB2-BA68-FE5A88D31DE6}_is1 => Safer Networking Limited Spybot - S&D
                              O43 - CFD: 2/6/2012 - 8:35:56 PM - [73.383] ----D- C:\ProgramData\Spybot - Search & Destroy
                              O43 - CFD: 2/6/2012 - 8:37:42 PM - [62.219] ----D- C:\Program Files (x86)\Spybot - Search & Destroy
                              Emptytemp



                              ----------------------------------------------------------

                              - Clique sur le bouton « GO » pour lancer le nettoyage,
                              - Copie/colle la totalité du rapport dans ta prochaine réponse
                              Tuto :

                              http://www.premiumorange.com/zeb-help-process/zhpfix.html
                              0
                              1. Non ça me dit rien du tout !!
                                J'ai pas essayer avec IE juste avec Firefox et Chrome et c'était pareil.
                                0
                                1. connais tu ce site :

                                  Sgt.automation.net ?

                                  si oui, on le laisse !

                                  tes redirection se font avec Firefox ou avec IE aussi ?

                                  0
                                  1. J'avais cru mais en fait non ça me redirige toujours...
                                    0
                                    • 1
                                    • 2